github.com/CycloneDX/sbom-utility@v0.16.0/test/stats/stats-cdx-1-4-sample-xxl-1.json (about)

     1  {
     2      "bomFormat": "CycloneDX",
     3      "specVersion": "1.4",
     4      "serialNumber": "urn:uuid:3b452e6b-34d2-4e6a-84f2-f85585824d6a",
     5      "version": 1,
     6      "metadata": {
     7        "tools": [
     8          {
     9            "name": "scanit",
    10            "vendor": "scans-r-us",
    11            "version": "1.70.0"
    12          },
    13          {
    14            "name": "scanit",
    15            "vendor": "scans-r-us",
    16            "version": "2.20.0"
    17          }
    18        ],
    19        "component": {
    20          "type": "application",
    21          "supplier": {},
    22          "group": "SampApp",
    23          "name": "SampApp",
    24          "version": "9.0.10",
    25          "swid": {
    26            "attachment": {}
    27          },
    28          "pedigree": {},
    29          "evidence": {},
    30          "signature": {
    31            "signature": {
    32              "publicKey": {}
    33            }
    34          },
    35          "modelCard": {
    36            "modelParameters": {
    37              "approach": {}
    38            },
    39            "quantitativeAnalysis": {
    40              "graphics": {}
    41            },
    42            "considerations": {}
    43          }
    44        },
    45        "manufacturer": {},
    46        "supplier": {}
    47      },
    48      "components": [
    49        {
    50          "type": "library",
    51          "bom-ref": "pkg:deb/debian/acl@2.2.53-4?arch=amd64\u0026distro=debian-10\u0026package-id=3fcaa2363534185d",
    52          "supplier": {},
    53          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
    54          "name": "acl",
    55          "version": "2.2.53-4",
    56          "licenses": [
    57            {
    58              "license": {
    59                "id": "GPL-2.0-only"
    60              }
    61            },
    62            {
    63              "license": {
    64                "id": "GPL-2.0-or-later"
    65              }
    66            },
    67            {
    68              "license": {
    69                "id": "LGPL-2.0-or-later"
    70              }
    71            },
    72            {
    73              "license": {
    74                "id": "LGPL-2.1-only"
    75              }
    76            }
    77          ],
    78          "cpe": "cpe:2.3:a:acl:acl:2.2.53-4:*:*:*:*:*:*:*",
    79          "purl": "pkg:deb/debian/acl@2.2.53-4?arch=amd64\u0026distro=debian-10",
    80          "swid": {
    81            "attachment": {}
    82          },
    83          "pedigree": {},
    84          "evidence": {},
    85          "signature": {
    86            "signature": {
    87              "publicKey": {}
    88            }
    89          },
    90          "modelCard": {
    91            "modelParameters": {
    92              "approach": {}
    93            },
    94            "quantitativeAnalysis": {
    95              "graphics": {}
    96            },
    97            "considerations": {}
    98          }
    99        },
   100        {
   101          "type": "library",
   102          "bom-ref": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-10\u0026package-id=3e9282034226b93f",
   103          "supplier": {},
   104          "publisher": "Debian Adduser Developers \u003cadduser@packages.debian.org\u003e",
   105          "name": "adduser",
   106          "version": "3.118",
   107          "licenses": [
   108            {
   109              "license": {
   110                "id": "GPL-2.0-only"
   111              }
   112            }
   113          ],
   114          "cpe": "cpe:2.3:a:adduser:adduser:3.118:*:*:*:*:*:*:*",
   115          "purl": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-10",
   116          "swid": {
   117            "attachment": {}
   118          },
   119          "pedigree": {},
   120          "evidence": {},
   121          "signature": {
   122            "signature": {
   123              "publicKey": {}
   124            }
   125          },
   126          "modelCard": {
   127            "modelParameters": {
   128              "approach": {}
   129            },
   130            "quantitativeAnalysis": {
   131              "graphics": {}
   132            },
   133            "considerations": {}
   134          }
   135        },
   136        {
   137          "type": "library",
   138          "bom-ref": "pkg:deb/debian/apt@1.8.2.2?arch=amd64\u0026distro=debian-10\u0026package-id=a82ef7ad8a96994c",
   139          "supplier": {},
   140          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
   141          "name": "apt",
   142          "version": "1.8.2.2",
   143          "licenses": [
   144            {
   145              "license": {
   146                "id": "GPL-2.0-only"
   147              }
   148            },
   149            {
   150              "license": {
   151                "name": "GPLv2+"
   152              }
   153            }
   154          ],
   155          "cpe": "cpe:2.3:a:apt:apt:1.8.2.2:*:*:*:*:*:*:*",
   156          "purl": "pkg:deb/debian/apt@1.8.2.2?arch=amd64\u0026distro=debian-10",
   157          "swid": {
   158            "attachment": {}
   159          },
   160          "pedigree": {},
   161          "evidence": {},
   162          "signature": {
   163            "signature": {
   164              "publicKey": {}
   165            }
   166          },
   167          "modelCard": {
   168            "modelParameters": {
   169              "approach": {}
   170            },
   171            "quantitativeAnalysis": {
   172              "graphics": {}
   173            },
   174            "considerations": {}
   175          }
   176        },
   177        {
   178          "type": "library",
   179          "bom-ref": "pkg:deb/debian/base-files@10.3+deb10u9?arch=amd64\u0026distro=debian-10\u0026package-id=76e37c6412b31348",
   180          "supplier": {},
   181          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
   182          "name": "base-files",
   183          "version": "10.3+deb10u9",
   184          "licenses": [
   185            {
   186              "license": {
   187                "name": "GPL"
   188              }
   189            }
   190          ],
   191          "cpe": "cpe:2.3:a:base-files:base-files:10.3\\+deb10u9:*:*:*:*:*:*:*",
   192          "purl": "pkg:deb/debian/base-files@10.3+deb10u9?arch=amd64\u0026distro=debian-10",
   193          "swid": {
   194            "attachment": {}
   195          },
   196          "pedigree": {},
   197          "evidence": {},
   198          "signature": {
   199            "signature": {
   200              "publicKey": {}
   201            }
   202          },
   203          "modelCard": {
   204            "modelParameters": {
   205              "approach": {}
   206            },
   207            "quantitativeAnalysis": {
   208              "graphics": {}
   209            },
   210            "considerations": {}
   211          }
   212        },
   213        {
   214          "type": "library",
   215          "bom-ref": "pkg:deb/debian/base-passwd@3.5.46?arch=amd64\u0026distro=debian-10\u0026package-id=8c36ab474a82d3ae",
   216          "supplier": {},
   217          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
   218          "name": "base-passwd",
   219          "version": "3.5.46",
   220          "licenses": [
   221            {
   222              "license": {
   223                "id": "GPL-2.0-only"
   224              }
   225            },
   226            {
   227              "license": {
   228                "name": "PD"
   229              }
   230            }
   231          ],
   232          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.46:*:*:*:*:*:*:*",
   233          "purl": "pkg:deb/debian/base-passwd@3.5.46?arch=amd64\u0026distro=debian-10",
   234          "swid": {
   235            "attachment": {}
   236          },
   237          "pedigree": {},
   238          "evidence": {},
   239          "signature": {
   240            "signature": {
   241              "publicKey": {}
   242            }
   243          },
   244          "modelCard": {
   245            "modelParameters": {
   246              "approach": {}
   247            },
   248            "quantitativeAnalysis": {
   249              "graphics": {}
   250            },
   251            "considerations": {}
   252          }
   253        },
   254        {
   255          "type": "library",
   256          "bom-ref": "pkg:deb/debian/bash@5.0-4?arch=amd64\u0026distro=debian-10\u0026package-id=1307b253f0761292",
   257          "supplier": {},
   258          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
   259          "name": "bash",
   260          "version": "5.0-4",
   261          "licenses": [
   262            {
   263              "license": {
   264                "id": "GPL-3.0-only"
   265              }
   266            }
   267          ],
   268          "cpe": "cpe:2.3:a:bash:bash:5.0-4:*:*:*:*:*:*:*",
   269          "purl": "pkg:deb/debian/bash@5.0-4?arch=amd64\u0026distro=debian-10",
   270          "swid": {
   271            "attachment": {}
   272          },
   273          "pedigree": {},
   274          "evidence": {},
   275          "signature": {
   276            "signature": {
   277              "publicKey": {}
   278            }
   279          },
   280          "modelCard": {
   281            "modelParameters": {
   282              "approach": {}
   283            },
   284            "quantitativeAnalysis": {
   285              "graphics": {}
   286            },
   287            "considerations": {}
   288          }
   289        },
   290        {
   291          "type": "library",
   292          "bom-ref": "pkg:deb/debian/bsdutils@1:2.33.1-0.1?arch=amd64\u0026upstream=util-linux%402.33.1-0.1\u0026distro=debian-10\u0026package-id=344ffe16352c1b24",
   293          "supplier": {},
   294          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
   295          "name": "bsdutils",
   296          "version": "1:2.33.1-0.1",
   297          "licenses": [
   298            {
   299              "license": {
   300                "id": "BSD-2-Clause"
   301              }
   302            },
   303            {
   304              "license": {
   305                "id": "BSD-3-Clause"
   306              }
   307            },
   308            {
   309              "license": {
   310                "id": "BSD-4-Clause"
   311              }
   312            },
   313            {
   314              "license": {
   315                "id": "GPL-2.0-only"
   316              }
   317            },
   318            {
   319              "license": {
   320                "id": "GPL-2.0-or-later"
   321              }
   322            },
   323            {
   324              "license": {
   325                "id": "GPL-3.0-only"
   326              }
   327            },
   328            {
   329              "license": {
   330                "id": "GPL-3.0-or-later"
   331              }
   332            },
   333            {
   334              "license": {
   335                "name": "LGPL"
   336              }
   337            },
   338            {
   339              "license": {
   340                "id": "LGPL-2.0-only"
   341              }
   342            },
   343            {
   344              "license": {
   345                "id": "LGPL-2.0-or-later"
   346              }
   347            },
   348            {
   349              "license": {
   350                "id": "LGPL-2.1-only"
   351              }
   352            },
   353            {
   354              "license": {
   355                "id": "LGPL-2.1-or-later"
   356              }
   357            },
   358            {
   359              "license": {
   360                "id": "LGPL-3.0-only"
   361              }
   362            },
   363            {
   364              "license": {
   365                "id": "LGPL-3.0-or-later"
   366              }
   367            },
   368            {
   369              "license": {
   370                "id": "MIT"
   371              }
   372            },
   373            {
   374              "license": {
   375                "name": "public-domain"
   376              }
   377            }
   378          ],
   379          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.33.1-0.1:*:*:*:*:*:*:*",
   380          "purl": "pkg:deb/debian/bsdutils@1:2.33.1-0.1?arch=amd64\u0026upstream=util-linux%402.33.1-0.1\u0026distro=debian-10",
   381          "swid": {
   382            "attachment": {}
   383          },
   384          "pedigree": {},
   385          "evidence": {},
   386          "signature": {
   387            "signature": {
   388              "publicKey": {}
   389            }
   390          },
   391          "modelCard": {
   392            "modelParameters": {
   393              "approach": {}
   394            },
   395            "quantitativeAnalysis": {
   396              "graphics": {}
   397            },
   398            "considerations": {}
   399          }
   400        },
   401        {
   402          "type": "library",
   403          "bom-ref": "pkg:deb/debian/ca-certificates@20200601~deb10u2?arch=all\u0026distro=debian-10\u0026package-id=596c81a431661de3",
   404          "supplier": {},
   405          "publisher": "Julien Cristau \u003cjcristau@debian.org\u003e",
   406          "name": "ca-certificates",
   407          "version": "20200601~deb10u2",
   408          "licenses": [
   409            {
   410              "license": {
   411                "id": "GPL-2.0-only"
   412              }
   413            },
   414            {
   415              "license": {
   416                "id": "GPL-2.0-or-later"
   417              }
   418            },
   419            {
   420              "license": {
   421                "id": "MPL-2.0"
   422              }
   423            }
   424          ],
   425          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20200601\\~deb10u2:*:*:*:*:*:*:*",
   426          "purl": "pkg:deb/debian/ca-certificates@20200601~deb10u2?arch=all\u0026distro=debian-10",
   427          "swid": {
   428            "attachment": {}
   429          },
   430          "pedigree": {},
   431          "evidence": {},
   432          "signature": {
   433            "signature": {
   434              "publicKey": {}
   435            }
   436          },
   437          "modelCard": {
   438            "modelParameters": {
   439              "approach": {}
   440            },
   441            "quantitativeAnalysis": {
   442              "graphics": {}
   443            },
   444            "considerations": {}
   445          }
   446        },
   447        {
   448          "type": "library",
   449          "bom-ref": "pkg:deb/debian/coreutils@8.30-3?arch=amd64\u0026distro=debian-10\u0026package-id=46b6002891a4d405",
   450          "supplier": {},
   451          "publisher": "Michael Stone \u003cmstone@debian.org\u003e",
   452          "name": "coreutils",
   453          "version": "8.30-3",
   454          "licenses": [
   455            {
   456              "license": {
   457                "id": "GPL-3.0-only"
   458              }
   459            }
   460          ],
   461          "cpe": "cpe:2.3:a:coreutils:coreutils:8.30-3:*:*:*:*:*:*:*",
   462          "purl": "pkg:deb/debian/coreutils@8.30-3?arch=amd64\u0026distro=debian-10",
   463          "swid": {
   464            "attachment": {}
   465          },
   466          "pedigree": {},
   467          "evidence": {},
   468          "signature": {
   469            "signature": {
   470              "publicKey": {}
   471            }
   472          },
   473          "modelCard": {
   474            "modelParameters": {
   475              "approach": {}
   476            },
   477            "quantitativeAnalysis": {
   478              "graphics": {}
   479            },
   480            "considerations": {}
   481          }
   482        },
   483        {
   484          "type": "library",
   485          "bom-ref": "pkg:deb/debian/curl@7.64.0-4+deb10u2?arch=amd64\u0026distro=debian-10\u0026package-id=d0effa75c99b912a",
   486          "supplier": {},
   487          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
   488          "name": "curl",
   489          "version": "7.64.0-4+deb10u2",
   490          "licenses": [
   491            {
   492              "license": {
   493                "id": "BSD-3-Clause"
   494              }
   495            },
   496            {
   497              "license": {
   498                "id": "BSD-4-Clause"
   499              }
   500            },
   501            {
   502              "license": {
   503                "id": "ISC"
   504              }
   505            },
   506            {
   507              "license": {
   508                "id": "curl"
   509              }
   510            },
   511            {
   512              "license": {
   513                "name": "other"
   514              }
   515            },
   516            {
   517              "license": {
   518                "name": "public-domain"
   519              }
   520            }
   521          ],
   522          "cpe": "cpe:2.3:a:curl:curl:7.64.0-4\\+deb10u2:*:*:*:*:*:*:*",
   523          "purl": "pkg:deb/debian/curl@7.64.0-4+deb10u2?arch=amd64\u0026distro=debian-10",
   524          "swid": {
   525            "attachment": {}
   526          },
   527          "pedigree": {},
   528          "evidence": {},
   529          "signature": {
   530            "signature": {
   531              "publicKey": {}
   532            }
   533          },
   534          "modelCard": {
   535            "modelParameters": {
   536              "approach": {}
   537            },
   538            "quantitativeAnalysis": {
   539              "graphics": {}
   540            },
   541            "considerations": {}
   542          }
   543        },
   544        {
   545          "type": "library",
   546          "bom-ref": "pkg:deb/debian/dash@0.5.10.2-5?arch=amd64\u0026distro=debian-10\u0026package-id=567db85af6d6aaf3",
   547          "supplier": {},
   548          "publisher": "Andrej Shadura \u003candrewsh@debian.org\u003e",
   549          "name": "dash",
   550          "version": "0.5.10.2-5",
   551          "licenses": [
   552            {
   553              "license": {
   554                "name": "GPL"
   555              }
   556            }
   557          ],
   558          "cpe": "cpe:2.3:a:dash:dash:0.5.10.2-5:*:*:*:*:*:*:*",
   559          "purl": "pkg:deb/debian/dash@0.5.10.2-5?arch=amd64\u0026distro=debian-10",
   560          "swid": {
   561            "attachment": {}
   562          },
   563          "pedigree": {},
   564          "evidence": {},
   565          "signature": {
   566            "signature": {
   567              "publicKey": {}
   568            }
   569          },
   570          "modelCard": {
   571            "modelParameters": {
   572              "approach": {}
   573            },
   574            "quantitativeAnalysis": {
   575              "graphics": {}
   576            },
   577            "considerations": {}
   578          }
   579        },
   580        {
   581          "type": "library",
   582          "bom-ref": "pkg:deb/debian/debconf@1.5.71?arch=all\u0026distro=debian-10\u0026package-id=9470bfee238208a1",
   583          "supplier": {},
   584          "publisher": "Debconf Developers \u003cdebconf-devel@lists.alioth.debian.org\u003e",
   585          "name": "debconf",
   586          "version": "1.5.71",
   587          "licenses": [
   588            {
   589              "license": {
   590                "id": "BSD-2-Clause"
   591              }
   592            }
   593          ],
   594          "cpe": "cpe:2.3:a:debconf:debconf:1.5.71:*:*:*:*:*:*:*",
   595          "purl": "pkg:deb/debian/debconf@1.5.71?arch=all\u0026distro=debian-10",
   596          "swid": {
   597            "attachment": {}
   598          },
   599          "pedigree": {},
   600          "evidence": {},
   601          "signature": {
   602            "signature": {
   603              "publicKey": {}
   604            }
   605          },
   606          "modelCard": {
   607            "modelParameters": {
   608              "approach": {}
   609            },
   610            "quantitativeAnalysis": {
   611              "graphics": {}
   612            },
   613            "considerations": {}
   614          }
   615        },
   616        {
   617          "type": "library",
   618          "bom-ref": "pkg:deb/debian/debian-archive-keyring@2019.1+deb10u1?arch=all\u0026distro=debian-10\u0026package-id=f9b380da454eddb4",
   619          "supplier": {},
   620          "publisher": "Debian Release Team \u003cpackages@release.debian.org\u003e",
   621          "name": "debian-archive-keyring",
   622          "version": "2019.1+deb10u1",
   623          "licenses": [
   624            {
   625              "license": {
   626                "name": "GPL"
   627              }
   628            }
   629          ],
   630          "cpe": "cpe:2.3:a:debian-archive-keyring:debian-archive-keyring:2019.1\\+deb10u1:*:*:*:*:*:*:*",
   631          "purl": "pkg:deb/debian/debian-archive-keyring@2019.1+deb10u1?arch=all\u0026distro=debian-10",
   632          "swid": {
   633            "attachment": {}
   634          },
   635          "pedigree": {},
   636          "evidence": {},
   637          "signature": {
   638            "signature": {
   639              "publicKey": {}
   640            }
   641          },
   642          "modelCard": {
   643            "modelParameters": {
   644              "approach": {}
   645            },
   646            "quantitativeAnalysis": {
   647              "graphics": {}
   648            },
   649            "considerations": {}
   650          }
   651        },
   652        {
   653          "type": "library",
   654          "bom-ref": "pkg:deb/debian/debianutils@4.8.6.1?arch=amd64\u0026distro=debian-10\u0026package-id=a28bc35fdac63cd4",
   655          "supplier": {},
   656          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
   657          "name": "debianutils",
   658          "version": "4.8.6.1",
   659          "licenses": [
   660            {
   661              "license": {
   662                "name": "GPL"
   663              }
   664            }
   665          ],
   666          "cpe": "cpe:2.3:a:debianutils:debianutils:4.8.6.1:*:*:*:*:*:*:*",
   667          "purl": "pkg:deb/debian/debianutils@4.8.6.1?arch=amd64\u0026distro=debian-10",
   668          "swid": {
   669            "attachment": {}
   670          },
   671          "pedigree": {},
   672          "evidence": {},
   673          "signature": {
   674            "signature": {
   675              "publicKey": {}
   676            }
   677          },
   678          "modelCard": {
   679            "modelParameters": {
   680              "approach": {}
   681            },
   682            "quantitativeAnalysis": {
   683              "graphics": {}
   684            },
   685            "considerations": {}
   686          }
   687        },
   688        {
   689          "type": "library",
   690          "bom-ref": "pkg:deb/debian/diffutils@1:3.7-3?arch=amd64\u0026distro=debian-10\u0026package-id=6d51f5deb90deb06",
   691          "supplier": {},
   692          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
   693          "name": "diffutils",
   694          "version": "1:3.7-3",
   695          "licenses": [
   696            {
   697              "license": {
   698                "name": "GFDL"
   699              }
   700            },
   701            {
   702              "license": {
   703                "name": "GPL"
   704              }
   705            }
   706          ],
   707          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-3:*:*:*:*:*:*:*",
   708          "purl": "pkg:deb/debian/diffutils@1:3.7-3?arch=amd64\u0026distro=debian-10",
   709          "swid": {
   710            "attachment": {}
   711          },
   712          "pedigree": {},
   713          "evidence": {},
   714          "signature": {
   715            "signature": {
   716              "publicKey": {}
   717            }
   718          },
   719          "modelCard": {
   720            "modelParameters": {
   721              "approach": {}
   722            },
   723            "quantitativeAnalysis": {
   724              "graphics": {}
   725            },
   726            "considerations": {}
   727          }
   728        },
   729        {
   730          "type": "library",
   731          "bom-ref": "pkg:deb/debian/dpkg@1.19.7?arch=amd64\u0026distro=debian-10\u0026package-id=826669ee9d8b4b93",
   732          "supplier": {},
   733          "publisher": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e",
   734          "name": "dpkg",
   735          "version": "1.19.7",
   736          "licenses": [
   737            {
   738              "license": {
   739                "id": "BSD-2-Clause"
   740              }
   741            },
   742            {
   743              "license": {
   744                "id": "GPL-2.0-only"
   745              }
   746            },
   747            {
   748              "license": {
   749                "id": "GPL-2.0-or-later"
   750              }
   751            },
   752            {
   753              "license": {
   754                "name": "public-domain-md5"
   755              }
   756            },
   757            {
   758              "license": {
   759                "name": "public-domain-s-s-d"
   760              }
   761            }
   762          ],
   763          "cpe": "cpe:2.3:a:dpkg:dpkg:1.19.7:*:*:*:*:*:*:*",
   764          "purl": "pkg:deb/debian/dpkg@1.19.7?arch=amd64\u0026distro=debian-10",
   765          "swid": {
   766            "attachment": {}
   767          },
   768          "pedigree": {},
   769          "evidence": {},
   770          "signature": {
   771            "signature": {
   772              "publicKey": {}
   773            }
   774          },
   775          "modelCard": {
   776            "modelParameters": {
   777              "approach": {}
   778            },
   779            "quantitativeAnalysis": {
   780              "graphics": {}
   781            },
   782            "considerations": {}
   783          }
   784        },
   785        {
   786          "type": "library",
   787          "bom-ref": "pkg:deb/debian/fdisk@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=743bbe9c435d52f3",
   788          "supplier": {},
   789          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
   790          "name": "fdisk",
   791          "version": "2.33.1-0.1",
   792          "licenses": [
   793            {
   794              "license": {
   795                "id": "BSD-2-Clause"
   796              }
   797            },
   798            {
   799              "license": {
   800                "id": "BSD-3-Clause"
   801              }
   802            },
   803            {
   804              "license": {
   805                "id": "BSD-4-Clause"
   806              }
   807            },
   808            {
   809              "license": {
   810                "id": "GPL-2.0-only"
   811              }
   812            },
   813            {
   814              "license": {
   815                "id": "GPL-2.0-or-later"
   816              }
   817            },
   818            {
   819              "license": {
   820                "id": "GPL-3.0-only"
   821              }
   822            },
   823            {
   824              "license": {
   825                "id": "GPL-3.0-or-later"
   826              }
   827            },
   828            {
   829              "license": {
   830                "name": "LGPL"
   831              }
   832            },
   833            {
   834              "license": {
   835                "id": "LGPL-2.0-only"
   836              }
   837            },
   838            {
   839              "license": {
   840                "id": "LGPL-2.0-or-later"
   841              }
   842            },
   843            {
   844              "license": {
   845                "id": "LGPL-2.1-only"
   846              }
   847            },
   848            {
   849              "license": {
   850                "id": "LGPL-2.1-or-later"
   851              }
   852            },
   853            {
   854              "license": {
   855                "id": "LGPL-3.0-only"
   856              }
   857            },
   858            {
   859              "license": {
   860                "id": "LGPL-3.0-or-later"
   861              }
   862            },
   863            {
   864              "license": {
   865                "id": "MIT"
   866              }
   867            },
   868            {
   869              "license": {
   870                "name": "public-domain"
   871              }
   872            }
   873          ],
   874          "cpe": "cpe:2.3:a:fdisk:fdisk:2.33.1-0.1:*:*:*:*:*:*:*",
   875          "purl": "pkg:deb/debian/fdisk@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
   876          "swid": {
   877            "attachment": {}
   878          },
   879          "pedigree": {},
   880          "evidence": {},
   881          "signature": {
   882            "signature": {
   883              "publicKey": {}
   884            }
   885          },
   886          "modelCard": {
   887            "modelParameters": {
   888              "approach": {}
   889            },
   890            "quantitativeAnalysis": {
   891              "graphics": {}
   892            },
   893            "considerations": {}
   894          }
   895        },
   896        {
   897          "type": "library",
   898          "bom-ref": "pkg:deb/debian/findutils@4.6.0+git+20190209-2?arch=amd64\u0026distro=debian-10\u0026package-id=38adf8ca435355da",
   899          "supplier": {},
   900          "publisher": "Andreas Metzler \u003cametzler@debian.org\u003e",
   901          "name": "findutils",
   902          "version": "4.6.0+git+20190209-2",
   903          "licenses": [
   904            {
   905              "license": {
   906                "id": "GFDL-1.3-only"
   907              }
   908            },
   909            {
   910              "license": {
   911                "id": "GPL-3.0-only"
   912              }
   913            }
   914          ],
   915          "cpe": "cpe:2.3:a:findutils:findutils:4.6.0\\+git\\+20190209-2:*:*:*:*:*:*:*",
   916          "purl": "pkg:deb/debian/findutils@4.6.0+git+20190209-2?arch=amd64\u0026distro=debian-10",
   917          "swid": {
   918            "attachment": {}
   919          },
   920          "pedigree": {},
   921          "evidence": {},
   922          "signature": {
   923            "signature": {
   924              "publicKey": {}
   925            }
   926          },
   927          "modelCard": {
   928            "modelParameters": {
   929              "approach": {}
   930            },
   931            "quantitativeAnalysis": {
   932              "graphics": {}
   933            },
   934            "considerations": {}
   935          }
   936        },
   937        {
   938          "type": "library",
   939          "bom-ref": "pkg:deb/debian/gcc-8-base@8.3.0-6?arch=amd64\u0026upstream=gcc-8\u0026distro=debian-10\u0026package-id=a958e0e726fb519d",
   940          "supplier": {},
   941          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
   942          "name": "gcc-8-base",
   943          "version": "8.3.0-6",
   944          "licenses": [
   945            {
   946              "license": {
   947                "name": "Artistic"
   948              }
   949            },
   950            {
   951              "license": {
   952                "id": "GFDL-1.2-only"
   953              }
   954            },
   955            {
   956              "license": {
   957                "name": "GPL"
   958              }
   959            },
   960            {
   961              "license": {
   962                "id": "GPL-2.0-only"
   963              }
   964            },
   965            {
   966              "license": {
   967                "id": "GPL-3.0-only"
   968              }
   969            },
   970            {
   971              "license": {
   972                "name": "LGPL"
   973              }
   974            }
   975          ],
   976          "cpe": "cpe:2.3:a:gcc-8-base:gcc-8-base:8.3.0-6:*:*:*:*:*:*:*",
   977          "purl": "pkg:deb/debian/gcc-8-base@8.3.0-6?arch=amd64\u0026upstream=gcc-8\u0026distro=debian-10",
   978          "swid": {
   979            "attachment": {}
   980          },
   981          "pedigree": {},
   982          "evidence": {},
   983          "signature": {
   984            "signature": {
   985              "publicKey": {}
   986            }
   987          },
   988          "modelCard": {
   989            "modelParameters": {
   990              "approach": {}
   991            },
   992            "quantitativeAnalysis": {
   993              "graphics": {}
   994            },
   995            "considerations": {}
   996          }
   997        },
   998        {
   999          "type": "library",
  1000          "bom-ref": "pkg:golang/github.com/opencontainers/runc@v1.0.0-rc95?package-id=9da9932a4449cb95",
  1001          "supplier": {},
  1002          "name": "github.com/opencontainers/runc",
  1003          "version": "v1.0.0-rc95",
  1004          "cpe": "cpe:2.3:a:opencontainers:runc:v1.0.0-rc95:*:*:*:*:*:*:*",
  1005          "purl": "pkg:golang/github.com/opencontainers/runc@v1.0.0-rc95",
  1006          "swid": {
  1007            "attachment": {}
  1008          },
  1009          "pedigree": {},
  1010          "evidence": {},
  1011          "signature": {
  1012            "signature": {
  1013              "publicKey": {}
  1014            }
  1015          },
  1016          "modelCard": {
  1017            "modelParameters": {
  1018              "approach": {}
  1019            },
  1020            "quantitativeAnalysis": {
  1021              "graphics": {}
  1022            },
  1023            "considerations": {}
  1024          }
  1025        },
  1026        {
  1027          "type": "library",
  1028          "bom-ref": "pkg:golang/github.com/tianon/gosu@(devel)?package-id=19d52095a2282c58",
  1029          "supplier": {},
  1030          "name": "github.com/tianon/gosu",
  1031          "version": "(devel)",
  1032          "cpe": "cpe:2.3:a:tianon:gosu:\\(devel\\):*:*:*:*:*:*:*",
  1033          "purl": "pkg:golang/github.com/tianon/gosu@(devel)",
  1034          "swid": {
  1035            "attachment": {}
  1036          },
  1037          "pedigree": {},
  1038          "evidence": {},
  1039          "signature": {
  1040            "signature": {
  1041              "publicKey": {}
  1042            }
  1043          },
  1044          "modelCard": {
  1045            "modelParameters": {
  1046              "approach": {}
  1047            },
  1048            "quantitativeAnalysis": {
  1049              "graphics": {}
  1050            },
  1051            "considerations": {}
  1052          }
  1053        },
  1054        {
  1055          "type": "library",
  1056          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20210426230700-d19ff857e887?package-id=a04162bbb33c282d",
  1057          "supplier": {},
  1058          "name": "golang.org/x/sys",
  1059          "version": "v0.0.0-20210426230700-d19ff857e887",
  1060          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20210426230700-d19ff857e887:*:*:*:*:*:*:*",
  1061          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20210426230700-d19ff857e887",
  1062          "swid": {
  1063            "attachment": {}
  1064          },
  1065          "pedigree": {},
  1066          "evidence": {},
  1067          "signature": {
  1068            "signature": {
  1069              "publicKey": {}
  1070            }
  1071          },
  1072          "modelCard": {
  1073            "modelParameters": {
  1074              "approach": {}
  1075            },
  1076            "quantitativeAnalysis": {
  1077              "graphics": {}
  1078            },
  1079            "considerations": {}
  1080          }
  1081        },
  1082        {
  1083          "type": "library",
  1084          "bom-ref": "pkg:deb/debian/gpgv@2.2.12-1+deb10u1?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-10\u0026package-id=1ffde2f3ed358894",
  1085          "supplier": {},
  1086          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  1087          "name": "gpgv",
  1088          "version": "2.2.12-1+deb10u1",
  1089          "licenses": [
  1090            {
  1091              "license": {
  1092                "id": "BSD-3-Clause"
  1093              }
  1094            },
  1095            {
  1096              "license": {
  1097                "id": "CC0-1.0"
  1098              }
  1099            },
  1100            {
  1101              "license": {
  1102                "name": "Expat"
  1103              }
  1104            },
  1105            {
  1106              "license": {
  1107                "id": "GPL-3.0-only"
  1108              }
  1109            },
  1110            {
  1111              "license": {
  1112                "id": "GPL-3.0-or-later"
  1113              }
  1114            },
  1115            {
  1116              "license": {
  1117                "id": "LGPL-2.1-only"
  1118              }
  1119            },
  1120            {
  1121              "license": {
  1122                "id": "LGPL-2.1-or-later"
  1123              }
  1124            },
  1125            {
  1126              "license": {
  1127                "id": "LGPL-3.0-only"
  1128              }
  1129            },
  1130            {
  1131              "license": {
  1132                "id": "LGPL-3.0-or-later"
  1133              }
  1134            },
  1135            {
  1136              "license": {
  1137                "name": "RFC-Reference"
  1138              }
  1139            },
  1140            {
  1141              "license": {
  1142                "name": "TinySCHEME"
  1143              }
  1144            },
  1145            {
  1146              "license": {
  1147                "name": "permissive"
  1148              }
  1149            }
  1150          ],
  1151          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.12-1\\+deb10u1:*:*:*:*:*:*:*",
  1152          "purl": "pkg:deb/debian/gpgv@2.2.12-1+deb10u1?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-10",
  1153          "swid": {
  1154            "attachment": {}
  1155          },
  1156          "pedigree": {},
  1157          "evidence": {},
  1158          "signature": {
  1159            "signature": {
  1160              "publicKey": {}
  1161            }
  1162          },
  1163          "modelCard": {
  1164            "modelParameters": {
  1165              "approach": {}
  1166            },
  1167            "quantitativeAnalysis": {
  1168              "graphics": {}
  1169            },
  1170            "considerations": {}
  1171          }
  1172        },
  1173        {
  1174          "type": "library",
  1175          "bom-ref": "pkg:deb/debian/grep@3.3-1?arch=amd64\u0026distro=debian-10\u0026package-id=e19c01918650b778",
  1176          "supplier": {},
  1177          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
  1178          "name": "grep",
  1179          "version": "3.3-1",
  1180          "licenses": [
  1181            {
  1182              "license": {
  1183                "id": "GPL-3.0-only"
  1184              }
  1185            },
  1186            {
  1187              "license": {
  1188                "id": "GPL-3.0-or-later"
  1189              }
  1190            }
  1191          ],
  1192          "cpe": "cpe:2.3:a:grep:grep:3.3-1:*:*:*:*:*:*:*",
  1193          "purl": "pkg:deb/debian/grep@3.3-1?arch=amd64\u0026distro=debian-10",
  1194          "swid": {
  1195            "attachment": {}
  1196          },
  1197          "pedigree": {},
  1198          "evidence": {},
  1199          "signature": {
  1200            "signature": {
  1201              "publicKey": {}
  1202            }
  1203          },
  1204          "modelCard": {
  1205            "modelParameters": {
  1206              "approach": {}
  1207            },
  1208            "quantitativeAnalysis": {
  1209              "graphics": {}
  1210            },
  1211            "considerations": {}
  1212          }
  1213        },
  1214        {
  1215          "type": "library",
  1216          "bom-ref": "pkg:deb/debian/gzip@1.9-3?arch=amd64\u0026distro=debian-10\u0026package-id=7de3a8e52e2d2e8b",
  1217          "supplier": {},
  1218          "publisher": "Bdale Garbee \u003cbdale@gag.com\u003e",
  1219          "name": "gzip",
  1220          "version": "1.9-3",
  1221          "licenses": [
  1222            {
  1223              "license": {
  1224                "name": "GPL"
  1225              }
  1226            }
  1227          ],
  1228          "cpe": "cpe:2.3:a:gzip:gzip:1.9-3:*:*:*:*:*:*:*",
  1229          "purl": "pkg:deb/debian/gzip@1.9-3?arch=amd64\u0026distro=debian-10",
  1230          "swid": {
  1231            "attachment": {}
  1232          },
  1233          "pedigree": {},
  1234          "evidence": {},
  1235          "signature": {
  1236            "signature": {
  1237              "publicKey": {}
  1238            }
  1239          },
  1240          "modelCard": {
  1241            "modelParameters": {
  1242              "approach": {}
  1243            },
  1244            "quantitativeAnalysis": {
  1245              "graphics": {}
  1246            },
  1247            "considerations": {}
  1248          }
  1249        },
  1250        {
  1251          "type": "library",
  1252          "bom-ref": "pkg:deb/debian/hostname@3.21?arch=amd64\u0026distro=debian-10\u0026package-id=9deb64db83d5e7c0",
  1253          "supplier": {},
  1254          "publisher": "Michael Meskes \u003cmeskes@debian.org\u003e",
  1255          "name": "hostname",
  1256          "version": "3.21",
  1257          "licenses": [
  1258            {
  1259              "license": {
  1260                "id": "GPL-2.0-only"
  1261              }
  1262            }
  1263          ],
  1264          "cpe": "cpe:2.3:a:hostname:hostname:3.21:*:*:*:*:*:*:*",
  1265          "purl": "pkg:deb/debian/hostname@3.21?arch=amd64\u0026distro=debian-10",
  1266          "swid": {
  1267            "attachment": {}
  1268          },
  1269          "pedigree": {},
  1270          "evidence": {},
  1271          "signature": {
  1272            "signature": {
  1273              "publicKey": {}
  1274            }
  1275          },
  1276          "modelCard": {
  1277            "modelParameters": {
  1278              "approach": {}
  1279            },
  1280            "quantitativeAnalysis": {
  1281              "graphics": {}
  1282            },
  1283            "considerations": {}
  1284          }
  1285        },
  1286        {
  1287          "type": "library",
  1288          "bom-ref": "pkg:deb/debian/init-system-helpers@1.56+nmu1?arch=all\u0026distro=debian-10\u0026package-id=7d7ed30b1f37bb0",
  1289          "supplier": {},
  1290          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
  1291          "name": "init-system-helpers",
  1292          "version": "1.56+nmu1",
  1293          "licenses": [
  1294            {
  1295              "license": {
  1296                "id": "BSD-3-Clause"
  1297              }
  1298            },
  1299            {
  1300              "license": {
  1301                "id": "GPL-2.0-only"
  1302              }
  1303            },
  1304            {
  1305              "license": {
  1306                "id": "GPL-2.0-or-later"
  1307              }
  1308            }
  1309          ],
  1310          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.56\\+nmu1:*:*:*:*:*:*:*",
  1311          "purl": "pkg:deb/debian/init-system-helpers@1.56+nmu1?arch=all\u0026distro=debian-10",
  1312          "swid": {
  1313            "attachment": {}
  1314          },
  1315          "pedigree": {},
  1316          "evidence": {},
  1317          "signature": {
  1318            "signature": {
  1319              "publicKey": {}
  1320            }
  1321          },
  1322          "modelCard": {
  1323            "modelParameters": {
  1324              "approach": {}
  1325            },
  1326            "quantitativeAnalysis": {
  1327              "graphics": {}
  1328            },
  1329            "considerations": {}
  1330          }
  1331        },
  1332        {
  1333          "type": "library",
  1334          "bom-ref": "pkg:deb/debian/insserv@1.18.0-2?arch=amd64\u0026distro=debian-10\u0026package-id=2787dc148b5aa2a",
  1335          "supplier": {},
  1336          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
  1337          "name": "insserv",
  1338          "version": "1.18.0-2",
  1339          "licenses": [
  1340            {
  1341              "license": {
  1342                "id": "GPL-2.0-only"
  1343              }
  1344            }
  1345          ],
  1346          "cpe": "cpe:2.3:a:insserv:insserv:1.18.0-2:*:*:*:*:*:*:*",
  1347          "purl": "pkg:deb/debian/insserv@1.18.0-2?arch=amd64\u0026distro=debian-10",
  1348          "swid": {
  1349            "attachment": {}
  1350          },
  1351          "pedigree": {},
  1352          "evidence": {},
  1353          "signature": {
  1354            "signature": {
  1355              "publicKey": {}
  1356            }
  1357          },
  1358          "modelCard": {
  1359            "modelParameters": {
  1360              "approach": {}
  1361            },
  1362            "quantitativeAnalysis": {
  1363              "graphics": {}
  1364            },
  1365            "considerations": {}
  1366          }
  1367        },
  1368        {
  1369          "type": "library",
  1370          "bom-ref": "pkg:deb/debian/jq@1.5+dfsg-2+b1?arch=amd64\u0026upstream=jq%401.5+dfsg-2\u0026distro=debian-10\u0026package-id=9d5f6e4d8476a849",
  1371          "supplier": {},
  1372          "publisher": "ChangZhuo Chen (陳昌倬) \u003cczchen@debian.org\u003e",
  1373          "name": "jq",
  1374          "version": "1.5+dfsg-2+b1",
  1375          "licenses": [
  1376            {
  1377              "license": {
  1378                "id": "Apache-2.0"
  1379              }
  1380            },
  1381            {
  1382              "license": {
  1383                "id": "CC-BY-3.0"
  1384              }
  1385            },
  1386            {
  1387              "license": {
  1388                "name": "Expat"
  1389              }
  1390            },
  1391            {
  1392              "license": {
  1393                "id": "GPL-2.0-only"
  1394              }
  1395            },
  1396            {
  1397              "license": {
  1398                "id": "GPL-2.0-or-later"
  1399              }
  1400            },
  1401            {
  1402              "license": {
  1403                "id": "MIT"
  1404              }
  1405            }
  1406          ],
  1407          "cpe": "cpe:2.3:a:jq:jq:1.5\\+dfsg-2\\+b1:*:*:*:*:*:*:*",
  1408          "purl": "pkg:deb/debian/jq@1.5+dfsg-2+b1?arch=amd64\u0026upstream=jq%401.5+dfsg-2\u0026distro=debian-10",
  1409          "swid": {
  1410            "attachment": {}
  1411          },
  1412          "pedigree": {},
  1413          "evidence": {},
  1414          "signature": {
  1415            "signature": {
  1416              "publicKey": {}
  1417            }
  1418          },
  1419          "modelCard": {
  1420            "modelParameters": {
  1421              "approach": {}
  1422            },
  1423            "quantitativeAnalysis": {
  1424              "graphics": {}
  1425            },
  1426            "considerations": {}
  1427          }
  1428        },
  1429        {
  1430          "type": "library",
  1431          "bom-ref": "pkg:deb/debian/libacl1@2.2.53-4?arch=amd64\u0026upstream=acl\u0026distro=debian-10\u0026package-id=a6d0197dab539e98",
  1432          "supplier": {},
  1433          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
  1434          "name": "libacl1",
  1435          "version": "2.2.53-4",
  1436          "licenses": [
  1437            {
  1438              "license": {
  1439                "id": "GPL-2.0-only"
  1440              }
  1441            },
  1442            {
  1443              "license": {
  1444                "id": "GPL-2.0-or-later"
  1445              }
  1446            },
  1447            {
  1448              "license": {
  1449                "id": "LGPL-2.0-or-later"
  1450              }
  1451            },
  1452            {
  1453              "license": {
  1454                "id": "LGPL-2.1-only"
  1455              }
  1456            }
  1457          ],
  1458          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-4:*:*:*:*:*:*:*",
  1459          "purl": "pkg:deb/debian/libacl1@2.2.53-4?arch=amd64\u0026upstream=acl\u0026distro=debian-10",
  1460          "swid": {
  1461            "attachment": {}
  1462          },
  1463          "pedigree": {},
  1464          "evidence": {},
  1465          "signature": {
  1466            "signature": {
  1467              "publicKey": {}
  1468            }
  1469          },
  1470          "modelCard": {
  1471            "modelParameters": {
  1472              "approach": {}
  1473            },
  1474            "quantitativeAnalysis": {
  1475              "graphics": {}
  1476            },
  1477            "considerations": {}
  1478          }
  1479        },
  1480        {
  1481          "type": "library",
  1482          "bom-ref": "pkg:deb/debian/libapt-pkg5.0@1.8.2.2?arch=amd64\u0026upstream=apt\u0026distro=debian-10\u0026package-id=1ab470673f1aff9d",
  1483          "supplier": {},
  1484          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
  1485          "name": "libapt-pkg5.0",
  1486          "version": "1.8.2.2",
  1487          "licenses": [
  1488            {
  1489              "license": {
  1490                "id": "GPL-2.0-only"
  1491              }
  1492            },
  1493            {
  1494              "license": {
  1495                "name": "GPLv2+"
  1496              }
  1497            }
  1498          ],
  1499          "cpe": "cpe:2.3:a:libapt-pkg5.0:libapt-pkg5.0:1.8.2.2:*:*:*:*:*:*:*",
  1500          "purl": "pkg:deb/debian/libapt-pkg5.0@1.8.2.2?arch=amd64\u0026upstream=apt\u0026distro=debian-10",
  1501          "swid": {
  1502            "attachment": {}
  1503          },
  1504          "pedigree": {},
  1505          "evidence": {},
  1506          "signature": {
  1507            "signature": {
  1508              "publicKey": {}
  1509            }
  1510          },
  1511          "modelCard": {
  1512            "modelParameters": {
  1513              "approach": {}
  1514            },
  1515            "quantitativeAnalysis": {
  1516              "graphics": {}
  1517            },
  1518            "considerations": {}
  1519          }
  1520        },
  1521        {
  1522          "type": "library",
  1523          "bom-ref": "pkg:deb/debian/libattr1@1:2.4.48-4?arch=amd64\u0026upstream=attr\u0026distro=debian-10\u0026package-id=26f28a682fbbe026",
  1524          "supplier": {},
  1525          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
  1526          "name": "libattr1",
  1527          "version": "1:2.4.48-4",
  1528          "licenses": [
  1529            {
  1530              "license": {
  1531                "id": "GPL-2.0-only"
  1532              }
  1533            },
  1534            {
  1535              "license": {
  1536                "id": "GPL-2.0-or-later"
  1537              }
  1538            },
  1539            {
  1540              "license": {
  1541                "id": "LGPL-2.0-or-later"
  1542              }
  1543            },
  1544            {
  1545              "license": {
  1546                "id": "LGPL-2.1-only"
  1547              }
  1548            }
  1549          ],
  1550          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-4:*:*:*:*:*:*:*",
  1551          "purl": "pkg:deb/debian/libattr1@1:2.4.48-4?arch=amd64\u0026upstream=attr\u0026distro=debian-10",
  1552          "swid": {
  1553            "attachment": {}
  1554          },
  1555          "pedigree": {},
  1556          "evidence": {},
  1557          "signature": {
  1558            "signature": {
  1559              "publicKey": {}
  1560            }
  1561          },
  1562          "modelCard": {
  1563            "modelParameters": {
  1564              "approach": {}
  1565            },
  1566            "quantitativeAnalysis": {
  1567              "graphics": {}
  1568            },
  1569            "considerations": {}
  1570          }
  1571        },
  1572        {
  1573          "type": "library",
  1574          "bom-ref": "pkg:deb/debian/libaudit-common@1:2.8.4-3?arch=all\u0026upstream=audit\u0026distro=debian-10\u0026package-id=eacb6fb921d6e85e",
  1575          "supplier": {},
  1576          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
  1577          "name": "libaudit-common",
  1578          "version": "1:2.8.4-3",
  1579          "licenses": [
  1580            {
  1581              "license": {
  1582                "id": "GPL-1.0-only"
  1583              }
  1584            },
  1585            {
  1586              "license": {
  1587                "id": "GPL-2.0-only"
  1588              }
  1589            },
  1590            {
  1591              "license": {
  1592                "id": "LGPL-2.1-only"
  1593              }
  1594            }
  1595          ],
  1596          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:2.8.4-3:*:*:*:*:*:*:*",
  1597          "purl": "pkg:deb/debian/libaudit-common@1:2.8.4-3?arch=all\u0026upstream=audit\u0026distro=debian-10",
  1598          "swid": {
  1599            "attachment": {}
  1600          },
  1601          "pedigree": {},
  1602          "evidence": {},
  1603          "signature": {
  1604            "signature": {
  1605              "publicKey": {}
  1606            }
  1607          },
  1608          "modelCard": {
  1609            "modelParameters": {
  1610              "approach": {}
  1611            },
  1612            "quantitativeAnalysis": {
  1613              "graphics": {}
  1614            },
  1615            "considerations": {}
  1616          }
  1617        },
  1618        {
  1619          "type": "library",
  1620          "bom-ref": "pkg:deb/debian/libaudit1@1:2.8.4-3?arch=amd64\u0026upstream=audit\u0026distro=debian-10\u0026package-id=74f57d9ce0c68d86",
  1621          "supplier": {},
  1622          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
  1623          "name": "libaudit1",
  1624          "version": "1:2.8.4-3",
  1625          "licenses": [
  1626            {
  1627              "license": {
  1628                "id": "GPL-1.0-only"
  1629              }
  1630            },
  1631            {
  1632              "license": {
  1633                "id": "GPL-2.0-only"
  1634              }
  1635            },
  1636            {
  1637              "license": {
  1638                "id": "LGPL-2.1-only"
  1639              }
  1640            }
  1641          ],
  1642          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:2.8.4-3:*:*:*:*:*:*:*",
  1643          "purl": "pkg:deb/debian/libaudit1@1:2.8.4-3?arch=amd64\u0026upstream=audit\u0026distro=debian-10",
  1644          "swid": {
  1645            "attachment": {}
  1646          },
  1647          "pedigree": {},
  1648          "evidence": {},
  1649          "signature": {
  1650            "signature": {
  1651              "publicKey": {}
  1652            }
  1653          },
  1654          "modelCard": {
  1655            "modelParameters": {
  1656              "approach": {}
  1657            },
  1658            "quantitativeAnalysis": {
  1659              "graphics": {}
  1660            },
  1661            "considerations": {}
  1662          }
  1663        },
  1664        {
  1665          "type": "library",
  1666          "bom-ref": "pkg:deb/debian/libblkid1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=c70296289994443b",
  1667          "supplier": {},
  1668          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
  1669          "name": "libblkid1",
  1670          "version": "2.33.1-0.1",
  1671          "licenses": [
  1672            {
  1673              "license": {
  1674                "id": "BSD-2-Clause"
  1675              }
  1676            },
  1677            {
  1678              "license": {
  1679                "id": "BSD-3-Clause"
  1680              }
  1681            },
  1682            {
  1683              "license": {
  1684                "id": "BSD-4-Clause"
  1685              }
  1686            },
  1687            {
  1688              "license": {
  1689                "id": "GPL-2.0-only"
  1690              }
  1691            },
  1692            {
  1693              "license": {
  1694                "id": "GPL-2.0-or-later"
  1695              }
  1696            },
  1697            {
  1698              "license": {
  1699                "id": "GPL-3.0-only"
  1700              }
  1701            },
  1702            {
  1703              "license": {
  1704                "id": "GPL-3.0-or-later"
  1705              }
  1706            },
  1707            {
  1708              "license": {
  1709                "name": "LGPL"
  1710              }
  1711            },
  1712            {
  1713              "license": {
  1714                "id": "LGPL-2.0-only"
  1715              }
  1716            },
  1717            {
  1718              "license": {
  1719                "id": "LGPL-2.0-or-later"
  1720              }
  1721            },
  1722            {
  1723              "license": {
  1724                "id": "LGPL-2.1-only"
  1725              }
  1726            },
  1727            {
  1728              "license": {
  1729                "id": "LGPL-2.1-or-later"
  1730              }
  1731            },
  1732            {
  1733              "license": {
  1734                "id": "LGPL-3.0-only"
  1735              }
  1736            },
  1737            {
  1738              "license": {
  1739                "id": "LGPL-3.0-or-later"
  1740              }
  1741            },
  1742            {
  1743              "license": {
  1744                "id": "MIT"
  1745              }
  1746            },
  1747            {
  1748              "license": {
  1749                "name": "public-domain"
  1750              }
  1751            }
  1752          ],
  1753          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.33.1-0.1:*:*:*:*:*:*:*",
  1754          "purl": "pkg:deb/debian/libblkid1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
  1755          "swid": {
  1756            "attachment": {}
  1757          },
  1758          "pedigree": {},
  1759          "evidence": {},
  1760          "signature": {
  1761            "signature": {
  1762              "publicKey": {}
  1763            }
  1764          },
  1765          "modelCard": {
  1766            "modelParameters": {
  1767              "approach": {}
  1768            },
  1769            "quantitativeAnalysis": {
  1770              "graphics": {}
  1771            },
  1772            "considerations": {}
  1773          }
  1774        },
  1775        {
  1776          "type": "library",
  1777          "bom-ref": "pkg:deb/debian/libbz2-1.0@1.0.6-9.2~deb10u1?arch=amd64\u0026upstream=bzip2\u0026distro=debian-10\u0026package-id=2cf51f0ebe123d92",
  1778          "supplier": {},
  1779          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
  1780          "name": "libbz2-1.0",
  1781          "version": "1.0.6-9.2~deb10u1",
  1782          "licenses": [
  1783            {
  1784              "license": {
  1785                "name": "BSD-variant"
  1786              }
  1787            },
  1788            {
  1789              "license": {
  1790                "id": "GPL-2.0-only"
  1791              }
  1792            }
  1793          ],
  1794          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.6-9.2\\~deb10u1:*:*:*:*:*:*:*",
  1795          "purl": "pkg:deb/debian/libbz2-1.0@1.0.6-9.2~deb10u1?arch=amd64\u0026upstream=bzip2\u0026distro=debian-10",
  1796          "swid": {
  1797            "attachment": {}
  1798          },
  1799          "pedigree": {},
  1800          "evidence": {},
  1801          "signature": {
  1802            "signature": {
  1803              "publicKey": {}
  1804            }
  1805          },
  1806          "modelCard": {
  1807            "modelParameters": {
  1808              "approach": {}
  1809            },
  1810            "quantitativeAnalysis": {
  1811              "graphics": {}
  1812            },
  1813            "considerations": {}
  1814          }
  1815        },
  1816        {
  1817          "type": "library",
  1818          "bom-ref": "pkg:deb/debian/libc-bin@2.28-10?arch=amd64\u0026upstream=glibc\u0026distro=debian-10\u0026package-id=e79c24d81f90a0f7",
  1819          "supplier": {},
  1820          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
  1821          "name": "libc-bin",
  1822          "version": "2.28-10",
  1823          "licenses": [
  1824            {
  1825              "license": {
  1826                "id": "GPL-2.0-only"
  1827              }
  1828            },
  1829            {
  1830              "license": {
  1831                "id": "LGPL-2.1-only"
  1832              }
  1833            }
  1834          ],
  1835          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.28-10:*:*:*:*:*:*:*",
  1836          "purl": "pkg:deb/debian/libc-bin@2.28-10?arch=amd64\u0026upstream=glibc\u0026distro=debian-10",
  1837          "swid": {
  1838            "attachment": {}
  1839          },
  1840          "pedigree": {},
  1841          "evidence": {},
  1842          "signature": {
  1843            "signature": {
  1844              "publicKey": {}
  1845            }
  1846          },
  1847          "modelCard": {
  1848            "modelParameters": {
  1849              "approach": {}
  1850            },
  1851            "quantitativeAnalysis": {
  1852              "graphics": {}
  1853            },
  1854            "considerations": {}
  1855          }
  1856        },
  1857        {
  1858          "type": "library",
  1859          "bom-ref": "pkg:deb/debian/libc6@2.28-10?arch=amd64\u0026upstream=glibc\u0026distro=debian-10\u0026package-id=b5ff55594183baf5",
  1860          "supplier": {},
  1861          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
  1862          "name": "libc6",
  1863          "version": "2.28-10",
  1864          "licenses": [
  1865            {
  1866              "license": {
  1867                "id": "GPL-2.0-only"
  1868              }
  1869            },
  1870            {
  1871              "license": {
  1872                "id": "LGPL-2.1-only"
  1873              }
  1874            }
  1875          ],
  1876          "cpe": "cpe:2.3:a:libc6:libc6:2.28-10:*:*:*:*:*:*:*",
  1877          "purl": "pkg:deb/debian/libc6@2.28-10?arch=amd64\u0026upstream=glibc\u0026distro=debian-10",
  1878          "swid": {
  1879            "attachment": {}
  1880          },
  1881          "pedigree": {},
  1882          "evidence": {},
  1883          "signature": {
  1884            "signature": {
  1885              "publicKey": {}
  1886            }
  1887          },
  1888          "modelCard": {
  1889            "modelParameters": {
  1890              "approach": {}
  1891            },
  1892            "quantitativeAnalysis": {
  1893              "graphics": {}
  1894            },
  1895            "considerations": {}
  1896          }
  1897        },
  1898        {
  1899          "type": "library",
  1900          "bom-ref": "pkg:deb/debian/libcap-ng0@0.7.9-2?arch=amd64\u0026upstream=libcap-ng\u0026distro=debian-10\u0026package-id=801e27b4655082f1",
  1901          "supplier": {},
  1902          "publisher": "Pierre Chifflier \u003cpollux@debian.org\u003e",
  1903          "name": "libcap-ng0",
  1904          "version": "0.7.9-2",
  1905          "licenses": [
  1906            {
  1907              "license": {
  1908                "id": "GPL-2.0-only"
  1909              }
  1910            },
  1911            {
  1912              "license": {
  1913                "id": "GPL-3.0-only"
  1914              }
  1915            },
  1916            {
  1917              "license": {
  1918                "id": "LGPL-2.1-only"
  1919              }
  1920            }
  1921          ],
  1922          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2:*:*:*:*:*:*:*",
  1923          "purl": "pkg:deb/debian/libcap-ng0@0.7.9-2?arch=amd64\u0026upstream=libcap-ng\u0026distro=debian-10",
  1924          "swid": {
  1925            "attachment": {}
  1926          },
  1927          "pedigree": {},
  1928          "evidence": {},
  1929          "signature": {
  1930            "signature": {
  1931              "publicKey": {}
  1932            }
  1933          },
  1934          "modelCard": {
  1935            "modelParameters": {
  1936              "approach": {}
  1937            },
  1938            "quantitativeAnalysis": {
  1939              "graphics": {}
  1940            },
  1941            "considerations": {}
  1942          }
  1943        },
  1944        {
  1945          "type": "library",
  1946          "bom-ref": "pkg:deb/debian/libcom-err2@1.44.5-1+deb10u3?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-10\u0026package-id=c05feef9d71ff201",
  1947          "supplier": {},
  1948          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
  1949          "name": "libcom-err2",
  1950          "version": "1.44.5-1+deb10u3",
  1951          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.44.5-1\\+deb10u3:*:*:*:*:*:*:*",
  1952          "purl": "pkg:deb/debian/libcom-err2@1.44.5-1+deb10u3?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-10",
  1953          "swid": {
  1954            "attachment": {}
  1955          },
  1956          "pedigree": {},
  1957          "evidence": {},
  1958          "signature": {
  1959            "signature": {
  1960              "publicKey": {}
  1961            }
  1962          },
  1963          "modelCard": {
  1964            "modelParameters": {
  1965              "approach": {}
  1966            },
  1967            "quantitativeAnalysis": {
  1968              "graphics": {}
  1969            },
  1970            "considerations": {}
  1971          }
  1972        },
  1973        {
  1974          "type": "library",
  1975          "bom-ref": "pkg:deb/debian/libcurl4@7.64.0-4+deb10u2?arch=amd64\u0026upstream=curl\u0026distro=debian-10\u0026package-id=f545f78b08ad34e8",
  1976          "supplier": {},
  1977          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
  1978          "name": "libcurl4",
  1979          "version": "7.64.0-4+deb10u2",
  1980          "licenses": [
  1981            {
  1982              "license": {
  1983                "id": "BSD-3-Clause"
  1984              }
  1985            },
  1986            {
  1987              "license": {
  1988                "id": "BSD-4-Clause"
  1989              }
  1990            },
  1991            {
  1992              "license": {
  1993                "id": "ISC"
  1994              }
  1995            },
  1996            {
  1997              "license": {
  1998                "id": "curl"
  1999              }
  2000            },
  2001            {
  2002              "license": {
  2003                "name": "other"
  2004              }
  2005            },
  2006            {
  2007              "license": {
  2008                "name": "public-domain"
  2009              }
  2010            }
  2011          ],
  2012          "cpe": "cpe:2.3:a:libcurl4:libcurl4:7.64.0-4\\+deb10u2:*:*:*:*:*:*:*",
  2013          "purl": "pkg:deb/debian/libcurl4@7.64.0-4+deb10u2?arch=amd64\u0026upstream=curl\u0026distro=debian-10",
  2014          "swid": {
  2015            "attachment": {}
  2016          },
  2017          "pedigree": {},
  2018          "evidence": {},
  2019          "signature": {
  2020            "signature": {
  2021              "publicKey": {}
  2022            }
  2023          },
  2024          "modelCard": {
  2025            "modelParameters": {
  2026              "approach": {}
  2027            },
  2028            "quantitativeAnalysis": {
  2029              "graphics": {}
  2030            },
  2031            "considerations": {}
  2032          }
  2033        },
  2034        {
  2035          "type": "library",
  2036          "bom-ref": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.5?arch=amd64\u0026upstream=db5.3\u0026distro=debian-10\u0026package-id=5f1d8daf8bc92e9d",
  2037          "supplier": {},
  2038          "publisher": "Debian Berkeley DB Team \u003cteam+bdb@tracker.debian.org\u003e",
  2039          "name": "libdb5.3",
  2040          "version": "5.3.28+dfsg1-0.5",
  2041          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.5:*:*:*:*:*:*:*",
  2042          "purl": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.5?arch=amd64\u0026upstream=db5.3\u0026distro=debian-10",
  2043          "swid": {
  2044            "attachment": {}
  2045          },
  2046          "pedigree": {},
  2047          "evidence": {},
  2048          "signature": {
  2049            "signature": {
  2050              "publicKey": {}
  2051            }
  2052          },
  2053          "modelCard": {
  2054            "modelParameters": {
  2055              "approach": {}
  2056            },
  2057            "quantitativeAnalysis": {
  2058              "graphics": {}
  2059            },
  2060            "considerations": {}
  2061          }
  2062        },
  2063        {
  2064          "type": "library",
  2065          "bom-ref": "pkg:deb/debian/libdebconfclient0@0.249?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-10\u0026package-id=6872b9d4842b81ec",
  2066          "supplier": {},
  2067          "publisher": "Debian Install System Team \u003cdebian-boot@lists.debian.org\u003e",
  2068          "name": "libdebconfclient0",
  2069          "version": "0.249",
  2070          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.249:*:*:*:*:*:*:*",
  2071          "purl": "pkg:deb/debian/libdebconfclient0@0.249?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-10",
  2072          "swid": {
  2073            "attachment": {}
  2074          },
  2075          "pedigree": {},
  2076          "evidence": {},
  2077          "signature": {
  2078            "signature": {
  2079              "publicKey": {}
  2080            }
  2081          },
  2082          "modelCard": {
  2083            "modelParameters": {
  2084              "approach": {}
  2085            },
  2086            "quantitativeAnalysis": {
  2087              "graphics": {}
  2088            },
  2089            "considerations": {}
  2090          }
  2091        },
  2092        {
  2093          "type": "library",
  2094          "bom-ref": "pkg:deb/debian/libfdisk1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=6c6e62c52a86ba09",
  2095          "supplier": {},
  2096          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
  2097          "name": "libfdisk1",
  2098          "version": "2.33.1-0.1",
  2099          "licenses": [
  2100            {
  2101              "license": {
  2102                "id": "BSD-2-Clause"
  2103              }
  2104            },
  2105            {
  2106              "license": {
  2107                "id": "BSD-3-Clause"
  2108              }
  2109            },
  2110            {
  2111              "license": {
  2112                "id": "BSD-4-Clause"
  2113              }
  2114            },
  2115            {
  2116              "license": {
  2117                "id": "GPL-2.0-only"
  2118              }
  2119            },
  2120            {
  2121              "license": {
  2122                "id": "GPL-2.0-or-later"
  2123              }
  2124            },
  2125            {
  2126              "license": {
  2127                "id": "GPL-3.0-only"
  2128              }
  2129            },
  2130            {
  2131              "license": {
  2132                "id": "GPL-3.0-or-later"
  2133              }
  2134            },
  2135            {
  2136              "license": {
  2137                "name": "LGPL"
  2138              }
  2139            },
  2140            {
  2141              "license": {
  2142                "id": "LGPL-2.0-only"
  2143              }
  2144            },
  2145            {
  2146              "license": {
  2147                "id": "LGPL-2.0-or-later"
  2148              }
  2149            },
  2150            {
  2151              "license": {
  2152                "id": "LGPL-2.1-only"
  2153              }
  2154            },
  2155            {
  2156              "license": {
  2157                "id": "LGPL-2.1-or-later"
  2158              }
  2159            },
  2160            {
  2161              "license": {
  2162                "id": "LGPL-3.0-only"
  2163              }
  2164            },
  2165            {
  2166              "license": {
  2167                "id": "LGPL-3.0-or-later"
  2168              }
  2169            },
  2170            {
  2171              "license": {
  2172                "id": "MIT"
  2173              }
  2174            },
  2175            {
  2176              "license": {
  2177                "name": "public-domain"
  2178              }
  2179            }
  2180          ],
  2181          "cpe": "cpe:2.3:a:libfdisk1:libfdisk1:2.33.1-0.1:*:*:*:*:*:*:*",
  2182          "purl": "pkg:deb/debian/libfdisk1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
  2183          "swid": {
  2184            "attachment": {}
  2185          },
  2186          "pedigree": {},
  2187          "evidence": {},
  2188          "signature": {
  2189            "signature": {
  2190              "publicKey": {}
  2191            }
  2192          },
  2193          "modelCard": {
  2194            "modelParameters": {
  2195              "approach": {}
  2196            },
  2197            "quantitativeAnalysis": {
  2198              "graphics": {}
  2199            },
  2200            "considerations": {}
  2201          }
  2202        },
  2203        {
  2204          "type": "library",
  2205          "bom-ref": "pkg:deb/debian/libffi6@3.2.1-9?arch=amd64\u0026upstream=libffi\u0026distro=debian-10\u0026package-id=40f6d811db6b6459",
  2206          "supplier": {},
  2207          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
  2208          "name": "libffi6",
  2209          "version": "3.2.1-9",
  2210          "licenses": [
  2211            {
  2212              "license": {
  2213                "name": "GPL"
  2214              }
  2215            }
  2216          ],
  2217          "cpe": "cpe:2.3:a:libffi6:libffi6:3.2.1-9:*:*:*:*:*:*:*",
  2218          "purl": "pkg:deb/debian/libffi6@3.2.1-9?arch=amd64\u0026upstream=libffi\u0026distro=debian-10",
  2219          "swid": {
  2220            "attachment": {}
  2221          },
  2222          "pedigree": {},
  2223          "evidence": {},
  2224          "signature": {
  2225            "signature": {
  2226              "publicKey": {}
  2227            }
  2228          },
  2229          "modelCard": {
  2230            "modelParameters": {
  2231              "approach": {}
  2232            },
  2233            "quantitativeAnalysis": {
  2234              "graphics": {}
  2235            },
  2236            "considerations": {}
  2237          }
  2238        },
  2239        {
  2240          "type": "library",
  2241          "bom-ref": "pkg:deb/debian/libgcc1@1:8.3.0-6?arch=amd64\u0026upstream=gcc-8%408.3.0-6\u0026distro=debian-10\u0026package-id=a4ec20e9bb10a790",
  2242          "supplier": {},
  2243          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
  2244          "name": "libgcc1",
  2245          "version": "1:8.3.0-6",
  2246          "licenses": [
  2247            {
  2248              "license": {
  2249                "name": "Artistic"
  2250              }
  2251            },
  2252            {
  2253              "license": {
  2254                "id": "GFDL-1.2-only"
  2255              }
  2256            },
  2257            {
  2258              "license": {
  2259                "name": "GPL"
  2260              }
  2261            },
  2262            {
  2263              "license": {
  2264                "id": "GPL-2.0-only"
  2265              }
  2266            },
  2267            {
  2268              "license": {
  2269                "id": "GPL-3.0-only"
  2270              }
  2271            },
  2272            {
  2273              "license": {
  2274                "name": "LGPL"
  2275              }
  2276            }
  2277          ],
  2278          "cpe": "cpe:2.3:a:libgcc1:libgcc1:1\\:8.3.0-6:*:*:*:*:*:*:*",
  2279          "purl": "pkg:deb/debian/libgcc1@1:8.3.0-6?arch=amd64\u0026upstream=gcc-8%408.3.0-6\u0026distro=debian-10",
  2280          "swid": {
  2281            "attachment": {}
  2282          },
  2283          "pedigree": {},
  2284          "evidence": {},
  2285          "signature": {
  2286            "signature": {
  2287              "publicKey": {}
  2288            }
  2289          },
  2290          "modelCard": {
  2291            "modelParameters": {
  2292              "approach": {}
  2293            },
  2294            "quantitativeAnalysis": {
  2295              "graphics": {}
  2296            },
  2297            "considerations": {}
  2298          }
  2299        },
  2300        {
  2301          "type": "library",
  2302          "bom-ref": "pkg:deb/debian/libgcrypt20@1.8.4-5?arch=amd64\u0026distro=debian-10\u0026package-id=45f715c434cb0ae3",
  2303          "supplier": {},
  2304          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
  2305          "name": "libgcrypt20",
  2306          "version": "1.8.4-5",
  2307          "licenses": [
  2308            {
  2309              "license": {
  2310                "id": "GPL-2.0-only"
  2311              }
  2312            },
  2313            {
  2314              "license": {
  2315                "name": "LGPL"
  2316              }
  2317            }
  2318          ],
  2319          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.4-5:*:*:*:*:*:*:*",
  2320          "purl": "pkg:deb/debian/libgcrypt20@1.8.4-5?arch=amd64\u0026distro=debian-10",
  2321          "swid": {
  2322            "attachment": {}
  2323          },
  2324          "pedigree": {},
  2325          "evidence": {},
  2326          "signature": {
  2327            "signature": {
  2328              "publicKey": {}
  2329            }
  2330          },
  2331          "modelCard": {
  2332            "modelParameters": {
  2333              "approach": {}
  2334            },
  2335            "quantitativeAnalysis": {
  2336              "graphics": {}
  2337            },
  2338            "considerations": {}
  2339          }
  2340        },
  2341        {
  2342          "type": "library",
  2343          "bom-ref": "pkg:deb/debian/libgmp10@2:6.1.2+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=debian-10\u0026package-id=8681d22eff791901",
  2344          "supplier": {},
  2345          "publisher": "Debian Science Team \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e",
  2346          "name": "libgmp10",
  2347          "version": "2:6.1.2+dfsg-4",
  2348          "licenses": [
  2349            {
  2350              "license": {
  2351                "name": "GPL"
  2352              }
  2353            },
  2354            {
  2355              "license": {
  2356                "id": "GPL-2.0-only"
  2357              }
  2358            },
  2359            {
  2360              "license": {
  2361                "id": "GPL-3.0-only"
  2362              }
  2363            },
  2364            {
  2365              "license": {
  2366                "id": "LGPL-3.0-only"
  2367              }
  2368            }
  2369          ],
  2370          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.1.2\\+dfsg-4:*:*:*:*:*:*:*",
  2371          "purl": "pkg:deb/debian/libgmp10@2:6.1.2+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=debian-10",
  2372          "swid": {
  2373            "attachment": {}
  2374          },
  2375          "pedigree": {},
  2376          "evidence": {},
  2377          "signature": {
  2378            "signature": {
  2379              "publicKey": {}
  2380            }
  2381          },
  2382          "modelCard": {
  2383            "modelParameters": {
  2384              "approach": {}
  2385            },
  2386            "quantitativeAnalysis": {
  2387              "graphics": {}
  2388            },
  2389            "considerations": {}
  2390          }
  2391        },
  2392        {
  2393          "type": "library",
  2394          "bom-ref": "pkg:deb/debian/libgnutls30@3.6.7-4+deb10u6?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-10\u0026package-id=1c198be275868dee",
  2395          "supplier": {},
  2396          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
  2397          "name": "libgnutls30",
  2398          "version": "3.6.7-4+deb10u6",
  2399          "licenses": [
  2400            {
  2401              "license": {
  2402                "id": "Apache-2.0"
  2403              }
  2404            },
  2405            {
  2406              "license": {
  2407                "name": "CC0"
  2408              }
  2409            },
  2410            {
  2411              "license": {
  2412                "id": "GFDL-1.3-only"
  2413              }
  2414            },
  2415            {
  2416              "license": {
  2417                "name": "GPL"
  2418              }
  2419            },
  2420            {
  2421              "license": {
  2422                "id": "GPL-3.0-only"
  2423              }
  2424            },
  2425            {
  2426              "license": {
  2427                "name": "GPLv3+"
  2428              }
  2429            },
  2430            {
  2431              "license": {
  2432                "name": "LGPL"
  2433              }
  2434            },
  2435            {
  2436              "license": {
  2437                "id": "LGPL-3.0-only"
  2438              }
  2439            },
  2440            {
  2441              "license": {
  2442                "name": "LGPLv3+_or_GPLv2+"
  2443              }
  2444            },
  2445            {
  2446              "license": {
  2447                "name": "The"
  2448              }
  2449            }
  2450          ],
  2451          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.7-4\\+deb10u6:*:*:*:*:*:*:*",
  2452          "purl": "pkg:deb/debian/libgnutls30@3.6.7-4+deb10u6?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-10",
  2453          "swid": {
  2454            "attachment": {}
  2455          },
  2456          "pedigree": {},
  2457          "evidence": {},
  2458          "signature": {
  2459            "signature": {
  2460              "publicKey": {}
  2461            }
  2462          },
  2463          "modelCard": {
  2464            "modelParameters": {
  2465              "approach": {}
  2466            },
  2467            "quantitativeAnalysis": {
  2468              "graphics": {}
  2469            },
  2470            "considerations": {}
  2471          }
  2472        },
  2473        {
  2474          "type": "library",
  2475          "bom-ref": "pkg:deb/debian/libgpg-error0@1.35-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-10\u0026package-id=e650eaf4629b1d02",
  2476          "supplier": {},
  2477          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  2478          "name": "libgpg-error0",
  2479          "version": "1.35-1",
  2480          "licenses": [
  2481            {
  2482              "license": {
  2483                "id": "BSD-3-Clause"
  2484              }
  2485            },
  2486            {
  2487              "license": {
  2488                "id": "GPL-3.0-only"
  2489              }
  2490            },
  2491            {
  2492              "license": {
  2493                "id": "GPL-3.0-or-later"
  2494              }
  2495            },
  2496            {
  2497              "license": {
  2498                "id": "LGPL-2.1-only"
  2499              }
  2500            },
  2501            {
  2502              "license": {
  2503                "id": "LGPL-2.1-or-later"
  2504              }
  2505            },
  2506            {
  2507              "license": {
  2508                "name": "g10-permissive"
  2509              }
  2510            }
  2511          ],
  2512          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.35-1:*:*:*:*:*:*:*",
  2513          "purl": "pkg:deb/debian/libgpg-error0@1.35-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-10",
  2514          "swid": {
  2515            "attachment": {}
  2516          },
  2517          "pedigree": {},
  2518          "evidence": {},
  2519          "signature": {
  2520            "signature": {
  2521              "publicKey": {}
  2522            }
  2523          },
  2524          "modelCard": {
  2525            "modelParameters": {
  2526              "approach": {}
  2527            },
  2528            "quantitativeAnalysis": {
  2529              "graphics": {}
  2530            },
  2531            "considerations": {}
  2532          }
  2533        },
  2534        {
  2535          "type": "library",
  2536          "bom-ref": "pkg:deb/debian/libgssapi-krb5-2@1.17-3+deb10u1?arch=amd64\u0026upstream=krb5\u0026distro=debian-10\u0026package-id=915cbd691e27493a",
  2537          "supplier": {},
  2538          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
  2539          "name": "libgssapi-krb5-2",
  2540          "version": "1.17-3+deb10u1",
  2541          "licenses": [
  2542            {
  2543              "license": {
  2544                "id": "GPL-2.0-only"
  2545              }
  2546            }
  2547          ],
  2548          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.17-3\\+deb10u1:*:*:*:*:*:*:*",
  2549          "purl": "pkg:deb/debian/libgssapi-krb5-2@1.17-3+deb10u1?arch=amd64\u0026upstream=krb5\u0026distro=debian-10",
  2550          "swid": {
  2551            "attachment": {}
  2552          },
  2553          "pedigree": {},
  2554          "evidence": {},
  2555          "signature": {
  2556            "signature": {
  2557              "publicKey": {}
  2558            }
  2559          },
  2560          "modelCard": {
  2561            "modelParameters": {
  2562              "approach": {}
  2563            },
  2564            "quantitativeAnalysis": {
  2565              "graphics": {}
  2566            },
  2567            "considerations": {}
  2568          }
  2569        },
  2570        {
  2571          "type": "library",
  2572          "bom-ref": "pkg:deb/debian/libhogweed4@3.4.1-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-10\u0026package-id=f512a45c8273c1a3",
  2573          "supplier": {},
  2574          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
  2575          "name": "libhogweed4",
  2576          "version": "3.4.1-1",
  2577          "licenses": [
  2578            {
  2579              "license": {
  2580                "name": "GAP"
  2581              }
  2582            },
  2583            {
  2584              "license": {
  2585                "name": "GPL"
  2586              }
  2587            },
  2588            {
  2589              "license": {
  2590                "id": "GPL-2.0-only"
  2591              }
  2592            },
  2593            {
  2594              "license": {
  2595                "id": "GPL-2.0-or-later"
  2596              }
  2597            },
  2598            {
  2599              "license": {
  2600                "name": "LGPL"
  2601              }
  2602            },
  2603            {
  2604              "license": {
  2605                "id": "LGPL-2.0-only"
  2606              }
  2607            },
  2608            {
  2609              "license": {
  2610                "id": "LGPL-2.0-or-later"
  2611              }
  2612            },
  2613            {
  2614              "license": {
  2615                "id": "LGPL-2.1-or-later"
  2616              }
  2617            },
  2618            {
  2619              "license": {
  2620                "name": "other"
  2621              }
  2622            },
  2623            {
  2624              "license": {
  2625                "name": "public-domain"
  2626              }
  2627            }
  2628          ],
  2629          "cpe": "cpe:2.3:a:libhogweed4:libhogweed4:3.4.1-1:*:*:*:*:*:*:*",
  2630          "purl": "pkg:deb/debian/libhogweed4@3.4.1-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-10",
  2631          "swid": {
  2632            "attachment": {}
  2633          },
  2634          "pedigree": {},
  2635          "evidence": {},
  2636          "signature": {
  2637            "signature": {
  2638              "publicKey": {}
  2639            }
  2640          },
  2641          "modelCard": {
  2642            "modelParameters": {
  2643              "approach": {}
  2644            },
  2645            "quantitativeAnalysis": {
  2646              "graphics": {}
  2647            },
  2648            "considerations": {}
  2649          }
  2650        },
  2651        {
  2652          "type": "library",
  2653          "bom-ref": "pkg:deb/debian/libidn2-0@2.0.5-1+deb10u1?arch=amd64\u0026upstream=libidn2\u0026distro=debian-10\u0026package-id=fb57203f630b9840",
  2654          "supplier": {},
  2655          "publisher": "Debian Libidn team \u003chelp-libidn@gnu.org\u003e",
  2656          "name": "libidn2-0",
  2657          "version": "2.0.5-1+deb10u1",
  2658          "licenses": [
  2659            {
  2660              "license": {
  2661                "id": "GPL-2.0-only"
  2662              }
  2663            },
  2664            {
  2665              "license": {
  2666                "id": "GPL-2.0-or-later"
  2667              }
  2668            },
  2669            {
  2670              "license": {
  2671                "id": "GPL-3.0-only"
  2672              }
  2673            },
  2674            {
  2675              "license": {
  2676                "id": "GPL-3.0-or-later"
  2677              }
  2678            },
  2679            {
  2680              "license": {
  2681                "id": "LGPL-3.0-only"
  2682              }
  2683            },
  2684            {
  2685              "license": {
  2686                "id": "LGPL-3.0-or-later"
  2687              }
  2688            },
  2689            {
  2690              "license": {
  2691                "name": "Unicode"
  2692              }
  2693            }
  2694          ],
  2695          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.0.5-1\\+deb10u1:*:*:*:*:*:*:*",
  2696          "purl": "pkg:deb/debian/libidn2-0@2.0.5-1+deb10u1?arch=amd64\u0026upstream=libidn2\u0026distro=debian-10",
  2697          "swid": {
  2698            "attachment": {}
  2699          },
  2700          "pedigree": {},
  2701          "evidence": {},
  2702          "signature": {
  2703            "signature": {
  2704              "publicKey": {}
  2705            }
  2706          },
  2707          "modelCard": {
  2708            "modelParameters": {
  2709              "approach": {}
  2710            },
  2711            "quantitativeAnalysis": {
  2712              "graphics": {}
  2713            },
  2714            "considerations": {}
  2715          }
  2716        },
  2717        {
  2718          "type": "library",
  2719          "bom-ref": "pkg:deb/debian/libjq1@1.5+dfsg-2+b1?arch=amd64\u0026upstream=jq%401.5+dfsg-2\u0026distro=debian-10\u0026package-id=c98431b078a20aed",
  2720          "supplier": {},
  2721          "publisher": "ChangZhuo Chen (陳昌倬) \u003cczchen@debian.org\u003e",
  2722          "name": "libjq1",
  2723          "version": "1.5+dfsg-2+b1",
  2724          "licenses": [
  2725            {
  2726              "license": {
  2727                "id": "Apache-2.0"
  2728              }
  2729            },
  2730            {
  2731              "license": {
  2732                "id": "CC-BY-3.0"
  2733              }
  2734            },
  2735            {
  2736              "license": {
  2737                "name": "Expat"
  2738              }
  2739            },
  2740            {
  2741              "license": {
  2742                "id": "GPL-2.0-only"
  2743              }
  2744            },
  2745            {
  2746              "license": {
  2747                "id": "GPL-2.0-or-later"
  2748              }
  2749            },
  2750            {
  2751              "license": {
  2752                "id": "MIT"
  2753              }
  2754            }
  2755          ],
  2756          "cpe": "cpe:2.3:a:libjq1:libjq1:1.5\\+dfsg-2\\+b1:*:*:*:*:*:*:*",
  2757          "purl": "pkg:deb/debian/libjq1@1.5+dfsg-2+b1?arch=amd64\u0026upstream=jq%401.5+dfsg-2\u0026distro=debian-10",
  2758          "swid": {
  2759            "attachment": {}
  2760          },
  2761          "pedigree": {},
  2762          "evidence": {},
  2763          "signature": {
  2764            "signature": {
  2765              "publicKey": {}
  2766            }
  2767          },
  2768          "modelCard": {
  2769            "modelParameters": {
  2770              "approach": {}
  2771            },
  2772            "quantitativeAnalysis": {
  2773              "graphics": {}
  2774            },
  2775            "considerations": {}
  2776          }
  2777        },
  2778        {
  2779          "type": "library",
  2780          "bom-ref": "pkg:deb/debian/libk5crypto3@1.17-3+deb10u1?arch=amd64\u0026upstream=krb5\u0026distro=debian-10\u0026package-id=f997918d35a8c2d1",
  2781          "supplier": {},
  2782          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
  2783          "name": "libk5crypto3",
  2784          "version": "1.17-3+deb10u1",
  2785          "licenses": [
  2786            {
  2787              "license": {
  2788                "id": "GPL-2.0-only"
  2789              }
  2790            }
  2791          ],
  2792          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.17-3\\+deb10u1:*:*:*:*:*:*:*",
  2793          "purl": "pkg:deb/debian/libk5crypto3@1.17-3+deb10u1?arch=amd64\u0026upstream=krb5\u0026distro=debian-10",
  2794          "swid": {
  2795            "attachment": {}
  2796          },
  2797          "pedigree": {},
  2798          "evidence": {},
  2799          "signature": {
  2800            "signature": {
  2801              "publicKey": {}
  2802            }
  2803          },
  2804          "modelCard": {
  2805            "modelParameters": {
  2806              "approach": {}
  2807            },
  2808            "quantitativeAnalysis": {
  2809              "graphics": {}
  2810            },
  2811            "considerations": {}
  2812          }
  2813        },
  2814        {
  2815          "type": "library",
  2816          "bom-ref": "pkg:deb/debian/libkeyutils1@1.6-6?arch=amd64\u0026upstream=keyutils\u0026distro=debian-10\u0026package-id=f3eaa7599631bb13",
  2817          "supplier": {},
  2818          "publisher": "Christian Kastner \u003cckk@debian.org\u003e",
  2819          "name": "libkeyutils1",
  2820          "version": "1.6-6",
  2821          "licenses": [
  2822            {
  2823              "license": {
  2824                "id": "GPL-2.0-only"
  2825              }
  2826            },
  2827            {
  2828              "license": {
  2829                "id": "GPL-2.0-or-later"
  2830              }
  2831            },
  2832            {
  2833              "license": {
  2834                "id": "LGPL-2.0-only"
  2835              }
  2836            },
  2837            {
  2838              "license": {
  2839                "id": "LGPL-2.0-or-later"
  2840              }
  2841            }
  2842          ],
  2843          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6-6:*:*:*:*:*:*:*",
  2844          "purl": "pkg:deb/debian/libkeyutils1@1.6-6?arch=amd64\u0026upstream=keyutils\u0026distro=debian-10",
  2845          "swid": {
  2846            "attachment": {}
  2847          },
  2848          "pedigree": {},
  2849          "evidence": {},
  2850          "signature": {
  2851            "signature": {
  2852              "publicKey": {}
  2853            }
  2854          },
  2855          "modelCard": {
  2856            "modelParameters": {
  2857              "approach": {}
  2858            },
  2859            "quantitativeAnalysis": {
  2860              "graphics": {}
  2861            },
  2862            "considerations": {}
  2863          }
  2864        },
  2865        {
  2866          "type": "library",
  2867          "bom-ref": "pkg:deb/debian/libkrb5-3@1.17-3+deb10u1?arch=amd64\u0026upstream=krb5\u0026distro=debian-10\u0026package-id=37df1f951aafc2c0",
  2868          "supplier": {},
  2869          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
  2870          "name": "libkrb5-3",
  2871          "version": "1.17-3+deb10u1",
  2872          "licenses": [
  2873            {
  2874              "license": {
  2875                "id": "GPL-2.0-only"
  2876              }
  2877            }
  2878          ],
  2879          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.17-3\\+deb10u1:*:*:*:*:*:*:*",
  2880          "purl": "pkg:deb/debian/libkrb5-3@1.17-3+deb10u1?arch=amd64\u0026upstream=krb5\u0026distro=debian-10",
  2881          "swid": {
  2882            "attachment": {}
  2883          },
  2884          "pedigree": {},
  2885          "evidence": {},
  2886          "signature": {
  2887            "signature": {
  2888              "publicKey": {}
  2889            }
  2890          },
  2891          "modelCard": {
  2892            "modelParameters": {
  2893              "approach": {}
  2894            },
  2895            "quantitativeAnalysis": {
  2896              "graphics": {}
  2897            },
  2898            "considerations": {}
  2899          }
  2900        },
  2901        {
  2902          "type": "library",
  2903          "bom-ref": "pkg:deb/debian/libkrb5support0@1.17-3+deb10u1?arch=amd64\u0026upstream=krb5\u0026distro=debian-10\u0026package-id=3a2c445f0ccc37e2",
  2904          "supplier": {},
  2905          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
  2906          "name": "libkrb5support0",
  2907          "version": "1.17-3+deb10u1",
  2908          "licenses": [
  2909            {
  2910              "license": {
  2911                "id": "GPL-2.0-only"
  2912              }
  2913            }
  2914          ],
  2915          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.17-3\\+deb10u1:*:*:*:*:*:*:*",
  2916          "purl": "pkg:deb/debian/libkrb5support0@1.17-3+deb10u1?arch=amd64\u0026upstream=krb5\u0026distro=debian-10",
  2917          "swid": {
  2918            "attachment": {}
  2919          },
  2920          "pedigree": {},
  2921          "evidence": {},
  2922          "signature": {
  2923            "signature": {
  2924              "publicKey": {}
  2925            }
  2926          },
  2927          "modelCard": {
  2928            "modelParameters": {
  2929              "approach": {}
  2930            },
  2931            "quantitativeAnalysis": {
  2932              "graphics": {}
  2933            },
  2934            "considerations": {}
  2935          }
  2936        },
  2937        {
  2938          "type": "library",
  2939          "bom-ref": "pkg:deb/debian/libldap-2.4-2@2.4.47+dfsg-3+deb10u6?arch=amd64\u0026upstream=openldap\u0026distro=debian-10\u0026package-id=dd6f13877960c5cd",
  2940          "supplier": {},
  2941          "publisher": "Debian OpenLDAP Maintainers \u003cpkg-openldap-devel@lists.alioth.debian.org\u003e",
  2942          "name": "libldap-2.4-2",
  2943          "version": "2.4.47+dfsg-3+deb10u6",
  2944          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.47\\+dfsg-3\\+deb10u6:*:*:*:*:*:*:*",
  2945          "purl": "pkg:deb/debian/libldap-2.4-2@2.4.47+dfsg-3+deb10u6?arch=amd64\u0026upstream=openldap\u0026distro=debian-10",
  2946          "swid": {
  2947            "attachment": {}
  2948          },
  2949          "pedigree": {},
  2950          "evidence": {},
  2951          "signature": {
  2952            "signature": {
  2953              "publicKey": {}
  2954            }
  2955          },
  2956          "modelCard": {
  2957            "modelParameters": {
  2958              "approach": {}
  2959            },
  2960            "quantitativeAnalysis": {
  2961              "graphics": {}
  2962            },
  2963            "considerations": {}
  2964          }
  2965        },
  2966        {
  2967          "type": "library",
  2968          "bom-ref": "pkg:deb/debian/libldap-common@2.4.47+dfsg-3+deb10u6?arch=all\u0026upstream=openldap\u0026distro=debian-10\u0026package-id=3fbd1c0c811297ae",
  2969          "supplier": {},
  2970          "publisher": "Debian OpenLDAP Maintainers \u003cpkg-openldap-devel@lists.alioth.debian.org\u003e",
  2971          "name": "libldap-common",
  2972          "version": "2.4.47+dfsg-3+deb10u6",
  2973          "cpe": "cpe:2.3:a:libldap-common:libldap-common:2.4.47\\+dfsg-3\\+deb10u6:*:*:*:*:*:*:*",
  2974          "purl": "pkg:deb/debian/libldap-common@2.4.47+dfsg-3+deb10u6?arch=all\u0026upstream=openldap\u0026distro=debian-10",
  2975          "swid": {
  2976            "attachment": {}
  2977          },
  2978          "pedigree": {},
  2979          "evidence": {},
  2980          "signature": {
  2981            "signature": {
  2982              "publicKey": {}
  2983            }
  2984          },
  2985          "modelCard": {
  2986            "modelParameters": {
  2987              "approach": {}
  2988            },
  2989            "quantitativeAnalysis": {
  2990              "graphics": {}
  2991            },
  2992            "considerations": {}
  2993          }
  2994        },
  2995        {
  2996          "type": "library",
  2997          "bom-ref": "pkg:deb/debian/liblz4-1@1.8.3-1+deb10u1?arch=amd64\u0026upstream=lz4\u0026distro=debian-10\u0026package-id=3703c0e5f7c5fec2",
  2998          "supplier": {},
  2999          "publisher": "Nobuhiro Iwamatsu \u003ciwamatsu@debian.org\u003e",
  3000          "name": "liblz4-1",
  3001          "version": "1.8.3-1+deb10u1",
  3002          "licenses": [
  3003            {
  3004              "license": {
  3005                "id": "BSD-2-Clause"
  3006              }
  3007            },
  3008            {
  3009              "license": {
  3010                "id": "GPL-2.0-only"
  3011              }
  3012            },
  3013            {
  3014              "license": {
  3015                "id": "GPL-2.0-or-later"
  3016              }
  3017            }
  3018          ],
  3019          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.8.3-1\\+deb10u1:*:*:*:*:*:*:*",
  3020          "purl": "pkg:deb/debian/liblz4-1@1.8.3-1+deb10u1?arch=amd64\u0026upstream=lz4\u0026distro=debian-10",
  3021          "swid": {
  3022            "attachment": {}
  3023          },
  3024          "pedigree": {},
  3025          "evidence": {},
  3026          "signature": {
  3027            "signature": {
  3028              "publicKey": {}
  3029            }
  3030          },
  3031          "modelCard": {
  3032            "modelParameters": {
  3033              "approach": {}
  3034            },
  3035            "quantitativeAnalysis": {
  3036              "graphics": {}
  3037            },
  3038            "considerations": {}
  3039          }
  3040        },
  3041        {
  3042          "type": "library",
  3043          "bom-ref": "pkg:deb/debian/liblzma5@5.2.4-1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-10\u0026package-id=711120f227a4ca8",
  3044          "supplier": {},
  3045          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
  3046          "name": "liblzma5",
  3047          "version": "5.2.4-1",
  3048          "licenses": [
  3049            {
  3050              "license": {
  3051                "name": "Autoconf"
  3052              }
  3053            },
  3054            {
  3055              "license": {
  3056                "id": "GPL-2.0-only"
  3057              }
  3058            },
  3059            {
  3060              "license": {
  3061                "id": "GPL-2.0-or-later"
  3062              }
  3063            },
  3064            {
  3065              "license": {
  3066                "id": "GPL-3.0-only"
  3067              }
  3068            },
  3069            {
  3070              "license": {
  3071                "id": "LGPL-2.0-only"
  3072              }
  3073            },
  3074            {
  3075              "license": {
  3076                "id": "LGPL-2.1-only"
  3077              }
  3078            },
  3079            {
  3080              "license": {
  3081                "id": "LGPL-2.1-or-later"
  3082              }
  3083            },
  3084            {
  3085              "license": {
  3086                "name": "PD"
  3087              }
  3088            },
  3089            {
  3090              "license": {
  3091                "name": "PD-debian"
  3092              }
  3093            },
  3094            {
  3095              "license": {
  3096                "name": "config-h"
  3097              }
  3098            },
  3099            {
  3100              "license": {
  3101                "name": "noderivs"
  3102              }
  3103            },
  3104            {
  3105              "license": {
  3106                "name": "permissive-fsf"
  3107              }
  3108            },
  3109            {
  3110              "license": {
  3111                "name": "permissive-nowarranty"
  3112              }
  3113            },
  3114            {
  3115              "license": {
  3116                "name": "probably-PD"
  3117              }
  3118            }
  3119          ],
  3120          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.4-1:*:*:*:*:*:*:*",
  3121          "purl": "pkg:deb/debian/liblzma5@5.2.4-1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-10",
  3122          "swid": {
  3123            "attachment": {}
  3124          },
  3125          "pedigree": {},
  3126          "evidence": {},
  3127          "signature": {
  3128            "signature": {
  3129              "publicKey": {}
  3130            }
  3131          },
  3132          "modelCard": {
  3133            "modelParameters": {
  3134              "approach": {}
  3135            },
  3136            "quantitativeAnalysis": {
  3137              "graphics": {}
  3138            },
  3139            "considerations": {}
  3140          }
  3141        },
  3142        {
  3143          "type": "library",
  3144          "bom-ref": "pkg:deb/debian/libmount1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=e7866651c1082fc0",
  3145          "supplier": {},
  3146          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
  3147          "name": "libmount1",
  3148          "version": "2.33.1-0.1",
  3149          "licenses": [
  3150            {
  3151              "license": {
  3152                "id": "BSD-2-Clause"
  3153              }
  3154            },
  3155            {
  3156              "license": {
  3157                "id": "BSD-3-Clause"
  3158              }
  3159            },
  3160            {
  3161              "license": {
  3162                "id": "BSD-4-Clause"
  3163              }
  3164            },
  3165            {
  3166              "license": {
  3167                "id": "GPL-2.0-only"
  3168              }
  3169            },
  3170            {
  3171              "license": {
  3172                "id": "GPL-2.0-or-later"
  3173              }
  3174            },
  3175            {
  3176              "license": {
  3177                "id": "GPL-3.0-only"
  3178              }
  3179            },
  3180            {
  3181              "license": {
  3182                "id": "GPL-3.0-or-later"
  3183              }
  3184            },
  3185            {
  3186              "license": {
  3187                "name": "LGPL"
  3188              }
  3189            },
  3190            {
  3191              "license": {
  3192                "id": "LGPL-2.0-only"
  3193              }
  3194            },
  3195            {
  3196              "license": {
  3197                "id": "LGPL-2.0-or-later"
  3198              }
  3199            },
  3200            {
  3201              "license": {
  3202                "id": "LGPL-2.1-only"
  3203              }
  3204            },
  3205            {
  3206              "license": {
  3207                "id": "LGPL-2.1-or-later"
  3208              }
  3209            },
  3210            {
  3211              "license": {
  3212                "id": "LGPL-3.0-only"
  3213              }
  3214            },
  3215            {
  3216              "license": {
  3217                "id": "LGPL-3.0-or-later"
  3218              }
  3219            },
  3220            {
  3221              "license": {
  3222                "id": "MIT"
  3223              }
  3224            },
  3225            {
  3226              "license": {
  3227                "name": "public-domain"
  3228              }
  3229            }
  3230          ],
  3231          "cpe": "cpe:2.3:a:libmount1:libmount1:2.33.1-0.1:*:*:*:*:*:*:*",
  3232          "purl": "pkg:deb/debian/libmount1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
  3233          "swid": {
  3234            "attachment": {}
  3235          },
  3236          "pedigree": {},
  3237          "evidence": {},
  3238          "signature": {
  3239            "signature": {
  3240              "publicKey": {}
  3241            }
  3242          },
  3243          "modelCard": {
  3244            "modelParameters": {
  3245              "approach": {}
  3246            },
  3247            "quantitativeAnalysis": {
  3248              "graphics": {}
  3249            },
  3250            "considerations": {}
  3251          }
  3252        },
  3253        {
  3254          "type": "library",
  3255          "bom-ref": "pkg:deb/debian/libncurses6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10\u0026package-id=1104b89b3ce7b78c",
  3256          "supplier": {},
  3257          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
  3258          "name": "libncurses6",
  3259          "version": "6.1+20181013-2+deb10u2",
  3260          "cpe": "cpe:2.3:a:libncurses6:libncurses6:6.1\\+20181013-2\\+deb10u2:*:*:*:*:*:*:*",
  3261          "purl": "pkg:deb/debian/libncurses6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10",
  3262          "swid": {
  3263            "attachment": {}
  3264          },
  3265          "pedigree": {},
  3266          "evidence": {},
  3267          "signature": {
  3268            "signature": {
  3269              "publicKey": {}
  3270            }
  3271          },
  3272          "modelCard": {
  3273            "modelParameters": {
  3274              "approach": {}
  3275            },
  3276            "quantitativeAnalysis": {
  3277              "graphics": {}
  3278            },
  3279            "considerations": {}
  3280          }
  3281        },
  3282        {
  3283          "type": "library",
  3284          "bom-ref": "pkg:deb/debian/libncursesw6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10\u0026package-id=71854d05b1ca05ab",
  3285          "supplier": {},
  3286          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
  3287          "name": "libncursesw6",
  3288          "version": "6.1+20181013-2+deb10u2",
  3289          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.1\\+20181013-2\\+deb10u2:*:*:*:*:*:*:*",
  3290          "purl": "pkg:deb/debian/libncursesw6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10",
  3291          "swid": {
  3292            "attachment": {}
  3293          },
  3294          "pedigree": {},
  3295          "evidence": {},
  3296          "signature": {
  3297            "signature": {
  3298              "publicKey": {}
  3299            }
  3300          },
  3301          "modelCard": {
  3302            "modelParameters": {
  3303              "approach": {}
  3304            },
  3305            "quantitativeAnalysis": {
  3306              "graphics": {}
  3307            },
  3308            "considerations": {}
  3309          }
  3310        },
  3311        {
  3312          "type": "library",
  3313          "bom-ref": "pkg:deb/debian/libnettle6@3.4.1-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-10\u0026package-id=9959b995ca1caa9b",
  3314          "supplier": {},
  3315          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
  3316          "name": "libnettle6",
  3317          "version": "3.4.1-1",
  3318          "licenses": [
  3319            {
  3320              "license": {
  3321                "name": "GAP"
  3322              }
  3323            },
  3324            {
  3325              "license": {
  3326                "name": "GPL"
  3327              }
  3328            },
  3329            {
  3330              "license": {
  3331                "id": "GPL-2.0-only"
  3332              }
  3333            },
  3334            {
  3335              "license": {
  3336                "id": "GPL-2.0-or-later"
  3337              }
  3338            },
  3339            {
  3340              "license": {
  3341                "name": "LGPL"
  3342              }
  3343            },
  3344            {
  3345              "license": {
  3346                "id": "LGPL-2.0-only"
  3347              }
  3348            },
  3349            {
  3350              "license": {
  3351                "id": "LGPL-2.0-or-later"
  3352              }
  3353            },
  3354            {
  3355              "license": {
  3356                "id": "LGPL-2.1-or-later"
  3357              }
  3358            },
  3359            {
  3360              "license": {
  3361                "name": "other"
  3362              }
  3363            },
  3364            {
  3365              "license": {
  3366                "name": "public-domain"
  3367              }
  3368            }
  3369          ],
  3370          "cpe": "cpe:2.3:a:libnettle6:libnettle6:3.4.1-1:*:*:*:*:*:*:*",
  3371          "purl": "pkg:deb/debian/libnettle6@3.4.1-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-10",
  3372          "swid": {
  3373            "attachment": {}
  3374          },
  3375          "pedigree": {},
  3376          "evidence": {},
  3377          "signature": {
  3378            "signature": {
  3379              "publicKey": {}
  3380            }
  3381          },
  3382          "modelCard": {
  3383            "modelParameters": {
  3384              "approach": {}
  3385            },
  3386            "quantitativeAnalysis": {
  3387              "graphics": {}
  3388            },
  3389            "considerations": {}
  3390          }
  3391        },
  3392        {
  3393          "type": "library",
  3394          "bom-ref": "pkg:deb/debian/libnghttp2-14@1.36.0-2+deb10u1?arch=amd64\u0026upstream=nghttp2\u0026distro=debian-10\u0026package-id=5390eaa0e24068d",
  3395          "supplier": {},
  3396          "publisher": "Tomasz Buchert \u003ctomasz@debian.org\u003e",
  3397          "name": "libnghttp2-14",
  3398          "version": "1.36.0-2+deb10u1",
  3399          "licenses": [
  3400            {
  3401              "license": {
  3402                "id": "BSD-2-Clause"
  3403              }
  3404            },
  3405            {
  3406              "license": {
  3407                "name": "Expat"
  3408              }
  3409            },
  3410            {
  3411              "license": {
  3412                "id": "GPL-3.0-only"
  3413              }
  3414            },
  3415            {
  3416              "license": {
  3417                "id": "GPL-3.0-or-later"
  3418              }
  3419            },
  3420            {
  3421              "license": {
  3422                "id": "MIT"
  3423              }
  3424            },
  3425            {
  3426              "license": {
  3427                "name": "SIL-OFL-1.1"
  3428              }
  3429            },
  3430            {
  3431              "license": {
  3432                "name": "all-permissive"
  3433              }
  3434            }
  3435          ],
  3436          "cpe": "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.36.0-2\\+deb10u1:*:*:*:*:*:*:*",
  3437          "purl": "pkg:deb/debian/libnghttp2-14@1.36.0-2+deb10u1?arch=amd64\u0026upstream=nghttp2\u0026distro=debian-10",
  3438          "swid": {
  3439            "attachment": {}
  3440          },
  3441          "pedigree": {},
  3442          "evidence": {},
  3443          "signature": {
  3444            "signature": {
  3445              "publicKey": {}
  3446            }
  3447          },
  3448          "modelCard": {
  3449            "modelParameters": {
  3450              "approach": {}
  3451            },
  3452            "quantitativeAnalysis": {
  3453              "graphics": {}
  3454            },
  3455            "considerations": {}
  3456          }
  3457        },
  3458        {
  3459          "type": "library",
  3460          "bom-ref": "pkg:deb/debian/libonig5@6.9.1-1?arch=amd64\u0026upstream=libonig\u0026distro=debian-10\u0026package-id=a95c90e4b31b4d9f",
  3461          "supplier": {},
  3462          "publisher": "Jörg Frings-Fürst \u003cdebian@jff.email\u003e",
  3463          "name": "libonig5",
  3464          "version": "6.9.1-1",
  3465          "licenses": [
  3466            {
  3467              "license": {
  3468                "id": "BSD-2-Clause"
  3469              }
  3470            },
  3471            {
  3472              "license": {
  3473                "id": "GPL-2.0-only"
  3474              }
  3475            },
  3476            {
  3477              "license": {
  3478                "id": "GPL-2.0-or-later"
  3479              }
  3480            }
  3481          ],
  3482          "cpe": "cpe:2.3:a:libonig5:libonig5:6.9.1-1:*:*:*:*:*:*:*",
  3483          "purl": "pkg:deb/debian/libonig5@6.9.1-1?arch=amd64\u0026upstream=libonig\u0026distro=debian-10",
  3484          "swid": {
  3485            "attachment": {}
  3486          },
  3487          "pedigree": {},
  3488          "evidence": {},
  3489          "signature": {
  3490            "signature": {
  3491              "publicKey": {}
  3492            }
  3493          },
  3494          "modelCard": {
  3495            "modelParameters": {
  3496              "approach": {}
  3497            },
  3498            "quantitativeAnalysis": {
  3499              "graphics": {}
  3500            },
  3501            "considerations": {}
  3502          }
  3503        },
  3504        {
  3505          "type": "library",
  3506          "bom-ref": "pkg:deb/debian/libp11-kit0@0.23.15-2+deb10u1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-10\u0026package-id=d609c3d39a184627",
  3507          "supplier": {},
  3508          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
  3509          "name": "libp11-kit0",
  3510          "version": "0.23.15-2+deb10u1",
  3511          "licenses": [
  3512            {
  3513              "license": {
  3514                "id": "BSD-3-Clause"
  3515              }
  3516            },
  3517            {
  3518              "license": {
  3519                "id": "ISC"
  3520              }
  3521            },
  3522            {
  3523              "license": {
  3524                "name": "ISC+IBM"
  3525              }
  3526            },
  3527            {
  3528              "license": {
  3529                "name": "permissive-like-automake-output"
  3530              }
  3531            },
  3532            {
  3533              "license": {
  3534                "name": "same-as-rest-of-p11kit"
  3535              }
  3536            }
  3537          ],
  3538          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.15-2\\+deb10u1:*:*:*:*:*:*:*",
  3539          "purl": "pkg:deb/debian/libp11-kit0@0.23.15-2+deb10u1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-10",
  3540          "swid": {
  3541            "attachment": {}
  3542          },
  3543          "pedigree": {},
  3544          "evidence": {},
  3545          "signature": {
  3546            "signature": {
  3547              "publicKey": {}
  3548            }
  3549          },
  3550          "modelCard": {
  3551            "modelParameters": {
  3552              "approach": {}
  3553            },
  3554            "quantitativeAnalysis": {
  3555              "graphics": {}
  3556            },
  3557            "considerations": {}
  3558          }
  3559        },
  3560        {
  3561          "type": "library",
  3562          "bom-ref": "pkg:deb/debian/libpam-modules@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10\u0026package-id=aab3cfb1d218fd23",
  3563          "supplier": {},
  3564          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
  3565          "name": "libpam-modules",
  3566          "version": "1.3.1-5",
  3567          "licenses": [
  3568            {
  3569              "license": {
  3570                "name": "GPL"
  3571              }
  3572            }
  3573          ],
  3574          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.3.1-5:*:*:*:*:*:*:*",
  3575          "purl": "pkg:deb/debian/libpam-modules@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10",
  3576          "swid": {
  3577            "attachment": {}
  3578          },
  3579          "pedigree": {},
  3580          "evidence": {},
  3581          "signature": {
  3582            "signature": {
  3583              "publicKey": {}
  3584            }
  3585          },
  3586          "modelCard": {
  3587            "modelParameters": {
  3588              "approach": {}
  3589            },
  3590            "quantitativeAnalysis": {
  3591              "graphics": {}
  3592            },
  3593            "considerations": {}
  3594          }
  3595        },
  3596        {
  3597          "type": "library",
  3598          "bom-ref": "pkg:deb/debian/libpam-modules-bin@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10\u0026package-id=12161ce3bab02f2",
  3599          "supplier": {},
  3600          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
  3601          "name": "libpam-modules-bin",
  3602          "version": "1.3.1-5",
  3603          "licenses": [
  3604            {
  3605              "license": {
  3606                "name": "GPL"
  3607              }
  3608            }
  3609          ],
  3610          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.3.1-5:*:*:*:*:*:*:*",
  3611          "purl": "pkg:deb/debian/libpam-modules-bin@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10",
  3612          "swid": {
  3613            "attachment": {}
  3614          },
  3615          "pedigree": {},
  3616          "evidence": {},
  3617          "signature": {
  3618            "signature": {
  3619              "publicKey": {}
  3620            }
  3621          },
  3622          "modelCard": {
  3623            "modelParameters": {
  3624              "approach": {}
  3625            },
  3626            "quantitativeAnalysis": {
  3627              "graphics": {}
  3628            },
  3629            "considerations": {}
  3630          }
  3631        },
  3632        {
  3633          "type": "library",
  3634          "bom-ref": "pkg:deb/debian/libpam-runtime@1.3.1-5?arch=all\u0026upstream=pam\u0026distro=debian-10\u0026package-id=6db7f7079130ac03",
  3635          "supplier": {},
  3636          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
  3637          "name": "libpam-runtime",
  3638          "version": "1.3.1-5",
  3639          "licenses": [
  3640            {
  3641              "license": {
  3642                "name": "GPL"
  3643              }
  3644            }
  3645          ],
  3646          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.3.1-5:*:*:*:*:*:*:*",
  3647          "purl": "pkg:deb/debian/libpam-runtime@1.3.1-5?arch=all\u0026upstream=pam\u0026distro=debian-10",
  3648          "swid": {
  3649            "attachment": {}
  3650          },
  3651          "pedigree": {},
  3652          "evidence": {},
  3653          "signature": {
  3654            "signature": {
  3655              "publicKey": {}
  3656            }
  3657          },
  3658          "modelCard": {
  3659            "modelParameters": {
  3660              "approach": {}
  3661            },
  3662            "quantitativeAnalysis": {
  3663              "graphics": {}
  3664            },
  3665            "considerations": {}
  3666          }
  3667        },
  3668        {
  3669          "type": "library",
  3670          "bom-ref": "pkg:deb/debian/libpam0g@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10\u0026package-id=91c506d4399b261f",
  3671          "supplier": {},
  3672          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
  3673          "name": "libpam0g",
  3674          "version": "1.3.1-5",
  3675          "licenses": [
  3676            {
  3677              "license": {
  3678                "name": "GPL"
  3679              }
  3680            }
  3681          ],
  3682          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.3.1-5:*:*:*:*:*:*:*",
  3683          "purl": "pkg:deb/debian/libpam0g@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10",
  3684          "swid": {
  3685            "attachment": {}
  3686          },
  3687          "pedigree": {},
  3688          "evidence": {},
  3689          "signature": {
  3690            "signature": {
  3691              "publicKey": {}
  3692            }
  3693          },
  3694          "modelCard": {
  3695            "modelParameters": {
  3696              "approach": {}
  3697            },
  3698            "quantitativeAnalysis": {
  3699              "graphics": {}
  3700            },
  3701            "considerations": {}
  3702          }
  3703        },
  3704        {
  3705          "type": "library",
  3706          "bom-ref": "pkg:deb/debian/libpcre3@2:8.39-12?arch=amd64\u0026upstream=pcre3\u0026distro=debian-10\u0026package-id=d463b0783493ae72",
  3707          "supplier": {},
  3708          "publisher": "Matthew Vernon \u003cmatthew@debian.org\u003e",
  3709          "name": "libpcre3",
  3710          "version": "2:8.39-12",
  3711          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-12:*:*:*:*:*:*:*",
  3712          "purl": "pkg:deb/debian/libpcre3@2:8.39-12?arch=amd64\u0026upstream=pcre3\u0026distro=debian-10",
  3713          "swid": {
  3714            "attachment": {}
  3715          },
  3716          "pedigree": {},
  3717          "evidence": {},
  3718          "signature": {
  3719            "signature": {
  3720              "publicKey": {}
  3721            }
  3722          },
  3723          "modelCard": {
  3724            "modelParameters": {
  3725              "approach": {}
  3726            },
  3727            "quantitativeAnalysis": {
  3728              "graphics": {}
  3729            },
  3730            "considerations": {}
  3731          }
  3732        },
  3733        {
  3734          "type": "library",
  3735          "bom-ref": "pkg:deb/debian/libprocps7@2:3.3.15-2?arch=amd64\u0026upstream=procps\u0026distro=debian-10\u0026package-id=12fb64afab9e657e",
  3736          "supplier": {},
  3737          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
  3738          "name": "libprocps7",
  3739          "version": "2:3.3.15-2",
  3740          "licenses": [
  3741            {
  3742              "license": {
  3743                "id": "GPL-2.0-only"
  3744              }
  3745            },
  3746            {
  3747              "license": {
  3748                "id": "GPL-2.0-or-later"
  3749              }
  3750            },
  3751            {
  3752              "license": {
  3753                "id": "LGPL-2.0-only"
  3754              }
  3755            },
  3756            {
  3757              "license": {
  3758                "id": "LGPL-2.0-or-later"
  3759              }
  3760            },
  3761            {
  3762              "license": {
  3763                "id": "LGPL-2.1-only"
  3764              }
  3765            },
  3766            {
  3767              "license": {
  3768                "id": "LGPL-2.1-or-later"
  3769              }
  3770            }
  3771          ],
  3772          "cpe": "cpe:2.3:a:libprocps7:libprocps7:2\\:3.3.15-2:*:*:*:*:*:*:*",
  3773          "purl": "pkg:deb/debian/libprocps7@2:3.3.15-2?arch=amd64\u0026upstream=procps\u0026distro=debian-10",
  3774          "swid": {
  3775            "attachment": {}
  3776          },
  3777          "pedigree": {},
  3778          "evidence": {},
  3779          "signature": {
  3780            "signature": {
  3781              "publicKey": {}
  3782            }
  3783          },
  3784          "modelCard": {
  3785            "modelParameters": {
  3786              "approach": {}
  3787            },
  3788            "quantitativeAnalysis": {
  3789              "graphics": {}
  3790            },
  3791            "considerations": {}
  3792          }
  3793        },
  3794        {
  3795          "type": "library",
  3796          "bom-ref": "pkg:deb/debian/libpsl5@0.20.2-2?arch=amd64\u0026upstream=libpsl\u0026distro=debian-10\u0026package-id=65dd9d04d79d4653",
  3797          "supplier": {},
  3798          "publisher": "Tim Rühsen \u003ctim.ruehsen@gmx.de\u003e",
  3799          "name": "libpsl5",
  3800          "version": "0.20.2-2",
  3801          "licenses": [
  3802            {
  3803              "license": {
  3804                "name": "Chromium"
  3805              }
  3806            },
  3807            {
  3808              "license": {
  3809                "id": "MIT"
  3810              }
  3811            }
  3812          ],
  3813          "cpe": "cpe:2.3:a:libpsl5:libpsl5:0.20.2-2:*:*:*:*:*:*:*",
  3814          "purl": "pkg:deb/debian/libpsl5@0.20.2-2?arch=amd64\u0026upstream=libpsl\u0026distro=debian-10",
  3815          "swid": {
  3816            "attachment": {}
  3817          },
  3818          "pedigree": {},
  3819          "evidence": {},
  3820          "signature": {
  3821            "signature": {
  3822              "publicKey": {}
  3823            }
  3824          },
  3825          "modelCard": {
  3826            "modelParameters": {
  3827              "approach": {}
  3828            },
  3829            "quantitativeAnalysis": {
  3830              "graphics": {}
  3831            },
  3832            "considerations": {}
  3833          }
  3834        },
  3835        {
  3836          "type": "library",
  3837          "bom-ref": "pkg:deb/debian/librtmp1@2.4+20151223.gitfa8646d.1-2?arch=amd64\u0026upstream=rtmpdump\u0026distro=debian-10\u0026package-id=29db333dac4810d3",
  3838          "supplier": {},
  3839          "publisher": "Debian Multimedia Maintainers \u003cdebian-multimedia@lists.debian.org\u003e",
  3840          "name": "librtmp1",
  3841          "version": "2.4+20151223.gitfa8646d.1-2",
  3842          "licenses": [
  3843            {
  3844              "license": {
  3845                "id": "GPL-2.0-only"
  3846              }
  3847            },
  3848            {
  3849              "license": {
  3850                "id": "LGPL-2.1-only"
  3851              }
  3852            }
  3853          ],
  3854          "cpe": "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20151223.gitfa8646d.1-2:*:*:*:*:*:*:*",
  3855          "purl": "pkg:deb/debian/librtmp1@2.4+20151223.gitfa8646d.1-2?arch=amd64\u0026upstream=rtmpdump\u0026distro=debian-10",
  3856          "swid": {
  3857            "attachment": {}
  3858          },
  3859          "pedigree": {},
  3860          "evidence": {},
  3861          "signature": {
  3862            "signature": {
  3863              "publicKey": {}
  3864            }
  3865          },
  3866          "modelCard": {
  3867            "modelParameters": {
  3868              "approach": {}
  3869            },
  3870            "quantitativeAnalysis": {
  3871              "graphics": {}
  3872            },
  3873            "considerations": {}
  3874          }
  3875        },
  3876        {
  3877          "type": "library",
  3878          "bom-ref": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-1+deb10u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-10\u0026package-id=65bf8764cf5e5a05",
  3879          "supplier": {},
  3880          "publisher": "Debian Cyrus Team \u003cteam+cyrus@tracker.debian.org\u003e",
  3881          "name": "libsasl2-2",
  3882          "version": "2.1.27+dfsg-1+deb10u1",
  3883          "licenses": [
  3884            {
  3885              "license": {
  3886                "id": "BSD-4-Clause"
  3887              }
  3888            },
  3889            {
  3890              "license": {
  3891                "id": "GPL-3.0-only"
  3892              }
  3893            },
  3894            {
  3895              "license": {
  3896                "id": "GPL-3.0-or-later"
  3897              }
  3898            }
  3899          ],
  3900          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-1\\+deb10u1:*:*:*:*:*:*:*",
  3901          "purl": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-1+deb10u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-10",
  3902          "swid": {
  3903            "attachment": {}
  3904          },
  3905          "pedigree": {},
  3906          "evidence": {},
  3907          "signature": {
  3908            "signature": {
  3909              "publicKey": {}
  3910            }
  3911          },
  3912          "modelCard": {
  3913            "modelParameters": {
  3914              "approach": {}
  3915            },
  3916            "quantitativeAnalysis": {
  3917              "graphics": {}
  3918            },
  3919            "considerations": {}
  3920          }
  3921        },
  3922        {
  3923          "type": "library",
  3924          "bom-ref": "pkg:deb/debian/libsasl2-modules-db@2.1.27+dfsg-1+deb10u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-10\u0026package-id=e3fafef9649e8076",
  3925          "supplier": {},
  3926          "publisher": "Debian Cyrus Team \u003cteam+cyrus@tracker.debian.org\u003e",
  3927          "name": "libsasl2-modules-db",
  3928          "version": "2.1.27+dfsg-1+deb10u1",
  3929          "licenses": [
  3930            {
  3931              "license": {
  3932                "id": "BSD-4-Clause"
  3933              }
  3934            },
  3935            {
  3936              "license": {
  3937                "id": "GPL-3.0-only"
  3938              }
  3939            },
  3940            {
  3941              "license": {
  3942                "id": "GPL-3.0-or-later"
  3943              }
  3944            }
  3945          ],
  3946          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\+dfsg-1\\+deb10u1:*:*:*:*:*:*:*",
  3947          "purl": "pkg:deb/debian/libsasl2-modules-db@2.1.27+dfsg-1+deb10u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-10",
  3948          "swid": {
  3949            "attachment": {}
  3950          },
  3951          "pedigree": {},
  3952          "evidence": {},
  3953          "signature": {
  3954            "signature": {
  3955              "publicKey": {}
  3956            }
  3957          },
  3958          "modelCard": {
  3959            "modelParameters": {
  3960              "approach": {}
  3961            },
  3962            "quantitativeAnalysis": {
  3963              "graphics": {}
  3964            },
  3965            "considerations": {}
  3966          }
  3967        },
  3968        {
  3969          "type": "library",
  3970          "bom-ref": "pkg:deb/debian/libseccomp2@2.3.3-4?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-10\u0026package-id=b751700bd628a765",
  3971          "supplier": {},
  3972          "publisher": "Kees Cook \u003ckees@debian.org\u003e",
  3973          "name": "libseccomp2",
  3974          "version": "2.3.3-4",
  3975          "licenses": [
  3976            {
  3977              "license": {
  3978                "id": "LGPL-2.1-only"
  3979              }
  3980            }
  3981          ],
  3982          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.3.3-4:*:*:*:*:*:*:*",
  3983          "purl": "pkg:deb/debian/libseccomp2@2.3.3-4?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-10",
  3984          "swid": {
  3985            "attachment": {}
  3986          },
  3987          "pedigree": {},
  3988          "evidence": {},
  3989          "signature": {
  3990            "signature": {
  3991              "publicKey": {}
  3992            }
  3993          },
  3994          "modelCard": {
  3995            "modelParameters": {
  3996              "approach": {}
  3997            },
  3998            "quantitativeAnalysis": {
  3999              "graphics": {}
  4000            },
  4001            "considerations": {}
  4002          }
  4003        },
  4004        {
  4005          "type": "library",
  4006          "bom-ref": "pkg:deb/debian/libselinux1@2.8-1+b1?arch=amd64\u0026upstream=libselinux%402.8-1\u0026distro=debian-10\u0026package-id=123a35c7043b0a0",
  4007          "supplier": {},
  4008          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
  4009          "name": "libselinux1",
  4010          "version": "2.8-1+b1",
  4011          "licenses": [
  4012            {
  4013              "license": {
  4014                "id": "GPL-2.0-only"
  4015              }
  4016            },
  4017            {
  4018              "license": {
  4019                "id": "LGPL-2.1-only"
  4020              }
  4021            }
  4022          ],
  4023          "cpe": "cpe:2.3:a:libselinux1:libselinux1:2.8-1\\+b1:*:*:*:*:*:*:*",
  4024          "purl": "pkg:deb/debian/libselinux1@2.8-1+b1?arch=amd64\u0026upstream=libselinux%402.8-1\u0026distro=debian-10",
  4025          "swid": {
  4026            "attachment": {}
  4027          },
  4028          "pedigree": {},
  4029          "evidence": {},
  4030          "signature": {
  4031            "signature": {
  4032              "publicKey": {}
  4033            }
  4034          },
  4035          "modelCard": {
  4036            "modelParameters": {
  4037              "approach": {}
  4038            },
  4039            "quantitativeAnalysis": {
  4040              "graphics": {}
  4041            },
  4042            "considerations": {}
  4043          }
  4044        },
  4045        {
  4046          "type": "library",
  4047          "bom-ref": "pkg:deb/debian/libsemanage-common@2.8-2?arch=all\u0026upstream=libsemanage\u0026distro=debian-10\u0026package-id=720058c21890c44f",
  4048          "supplier": {},
  4049          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
  4050          "name": "libsemanage-common",
  4051          "version": "2.8-2",
  4052          "licenses": [
  4053            {
  4054              "license": {
  4055                "name": "GPL"
  4056              }
  4057            },
  4058            {
  4059              "license": {
  4060                "name": "LGPL"
  4061              }
  4062            }
  4063          ],
  4064          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:2.8-2:*:*:*:*:*:*:*",
  4065          "purl": "pkg:deb/debian/libsemanage-common@2.8-2?arch=all\u0026upstream=libsemanage\u0026distro=debian-10",
  4066          "swid": {
  4067            "attachment": {}
  4068          },
  4069          "pedigree": {},
  4070          "evidence": {},
  4071          "signature": {
  4072            "signature": {
  4073              "publicKey": {}
  4074            }
  4075          },
  4076          "modelCard": {
  4077            "modelParameters": {
  4078              "approach": {}
  4079            },
  4080            "quantitativeAnalysis": {
  4081              "graphics": {}
  4082            },
  4083            "considerations": {}
  4084          }
  4085        },
  4086        {
  4087          "type": "library",
  4088          "bom-ref": "pkg:deb/debian/libsemanage1@2.8-2?arch=amd64\u0026upstream=libsemanage\u0026distro=debian-10\u0026package-id=cd3c06cc7a1130a4",
  4089          "supplier": {},
  4090          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
  4091          "name": "libsemanage1",
  4092          "version": "2.8-2",
  4093          "licenses": [
  4094            {
  4095              "license": {
  4096                "name": "GPL"
  4097              }
  4098            },
  4099            {
  4100              "license": {
  4101                "name": "LGPL"
  4102              }
  4103            }
  4104          ],
  4105          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:2.8-2:*:*:*:*:*:*:*",
  4106          "purl": "pkg:deb/debian/libsemanage1@2.8-2?arch=amd64\u0026upstream=libsemanage\u0026distro=debian-10",
  4107          "swid": {
  4108            "attachment": {}
  4109          },
  4110          "pedigree": {},
  4111          "evidence": {},
  4112          "signature": {
  4113            "signature": {
  4114              "publicKey": {}
  4115            }
  4116          },
  4117          "modelCard": {
  4118            "modelParameters": {
  4119              "approach": {}
  4120            },
  4121            "quantitativeAnalysis": {
  4122              "graphics": {}
  4123            },
  4124            "considerations": {}
  4125          }
  4126        },
  4127        {
  4128          "type": "library",
  4129          "bom-ref": "pkg:deb/debian/libsepol1@2.8-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-10\u0026package-id=b33fd215afdc5714",
  4130          "supplier": {},
  4131          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
  4132          "name": "libsepol1",
  4133          "version": "2.8-1",
  4134          "licenses": [
  4135            {
  4136              "license": {
  4137                "name": "GPL"
  4138              }
  4139            },
  4140            {
  4141              "license": {
  4142                "name": "LGPL"
  4143              }
  4144            }
  4145          ],
  4146          "cpe": "cpe:2.3:a:libsepol1:libsepol1:2.8-1:*:*:*:*:*:*:*",
  4147          "purl": "pkg:deb/debian/libsepol1@2.8-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-10",
  4148          "swid": {
  4149            "attachment": {}
  4150          },
  4151          "pedigree": {},
  4152          "evidence": {},
  4153          "signature": {
  4154            "signature": {
  4155              "publicKey": {}
  4156            }
  4157          },
  4158          "modelCard": {
  4159            "modelParameters": {
  4160              "approach": {}
  4161            },
  4162            "quantitativeAnalysis": {
  4163              "graphics": {}
  4164            },
  4165            "considerations": {}
  4166          }
  4167        },
  4168        {
  4169          "type": "library",
  4170          "bom-ref": "pkg:deb/debian/libsmartcols1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=fc03f42224a52138",
  4171          "supplier": {},
  4172          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
  4173          "name": "libsmartcols1",
  4174          "version": "2.33.1-0.1",
  4175          "licenses": [
  4176            {
  4177              "license": {
  4178                "id": "BSD-2-Clause"
  4179              }
  4180            },
  4181            {
  4182              "license": {
  4183                "id": "BSD-3-Clause"
  4184              }
  4185            },
  4186            {
  4187              "license": {
  4188                "id": "BSD-4-Clause"
  4189              }
  4190            },
  4191            {
  4192              "license": {
  4193                "id": "GPL-2.0-only"
  4194              }
  4195            },
  4196            {
  4197              "license": {
  4198                "id": "GPL-2.0-or-later"
  4199              }
  4200            },
  4201            {
  4202              "license": {
  4203                "id": "GPL-3.0-only"
  4204              }
  4205            },
  4206            {
  4207              "license": {
  4208                "id": "GPL-3.0-or-later"
  4209              }
  4210            },
  4211            {
  4212              "license": {
  4213                "name": "LGPL"
  4214              }
  4215            },
  4216            {
  4217              "license": {
  4218                "id": "LGPL-2.0-only"
  4219              }
  4220            },
  4221            {
  4222              "license": {
  4223                "id": "LGPL-2.0-or-later"
  4224              }
  4225            },
  4226            {
  4227              "license": {
  4228                "id": "LGPL-2.1-only"
  4229              }
  4230            },
  4231            {
  4232              "license": {
  4233                "id": "LGPL-2.1-or-later"
  4234              }
  4235            },
  4236            {
  4237              "license": {
  4238                "id": "LGPL-3.0-only"
  4239              }
  4240            },
  4241            {
  4242              "license": {
  4243                "id": "LGPL-3.0-or-later"
  4244              }
  4245            },
  4246            {
  4247              "license": {
  4248                "id": "MIT"
  4249              }
  4250            },
  4251            {
  4252              "license": {
  4253                "name": "public-domain"
  4254              }
  4255            }
  4256          ],
  4257          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.33.1-0.1:*:*:*:*:*:*:*",
  4258          "purl": "pkg:deb/debian/libsmartcols1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
  4259          "swid": {
  4260            "attachment": {}
  4261          },
  4262          "pedigree": {},
  4263          "evidence": {},
  4264          "signature": {
  4265            "signature": {
  4266              "publicKey": {}
  4267            }
  4268          },
  4269          "modelCard": {
  4270            "modelParameters": {
  4271              "approach": {}
  4272            },
  4273            "quantitativeAnalysis": {
  4274              "graphics": {}
  4275            },
  4276            "considerations": {}
  4277          }
  4278        },
  4279        {
  4280          "type": "library",
  4281          "bom-ref": "pkg:deb/debian/libssh2-1@1.8.0-2.1?arch=amd64\u0026upstream=libssh2\u0026distro=debian-10\u0026package-id=e6614550b3c1af75",
  4282          "supplier": {},
  4283          "publisher": "Mikhail Gusarov \u003cdottedmag@debian.org\u003e",
  4284          "name": "libssh2-1",
  4285          "version": "1.8.0-2.1",
  4286          "licenses": [
  4287            {
  4288              "license": {
  4289                "name": "BSD3"
  4290              }
  4291            }
  4292          ],
  4293          "cpe": "cpe:2.3:a:libssh2-1:libssh2-1:1.8.0-2.1:*:*:*:*:*:*:*",
  4294          "purl": "pkg:deb/debian/libssh2-1@1.8.0-2.1?arch=amd64\u0026upstream=libssh2\u0026distro=debian-10",
  4295          "swid": {
  4296            "attachment": {}
  4297          },
  4298          "pedigree": {},
  4299          "evidence": {},
  4300          "signature": {
  4301            "signature": {
  4302              "publicKey": {}
  4303            }
  4304          },
  4305          "modelCard": {
  4306            "modelParameters": {
  4307              "approach": {}
  4308            },
  4309            "quantitativeAnalysis": {
  4310              "graphics": {}
  4311            },
  4312            "considerations": {}
  4313          }
  4314        },
  4315        {
  4316          "type": "library",
  4317          "bom-ref": "pkg:deb/debian/libssl1.1@1.1.1d-0+deb10u6?arch=amd64\u0026upstream=openssl\u0026distro=debian-10\u0026package-id=d9b0754ac1e35c28",
  4318          "supplier": {},
  4319          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
  4320          "name": "libssl1.1",
  4321          "version": "1.1.1d-0+deb10u6",
  4322          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1d-0\\+deb10u6:*:*:*:*:*:*:*",
  4323          "purl": "pkg:deb/debian/libssl1.1@1.1.1d-0+deb10u6?arch=amd64\u0026upstream=openssl\u0026distro=debian-10",
  4324          "swid": {
  4325            "attachment": {}
  4326          },
  4327          "pedigree": {},
  4328          "evidence": {},
  4329          "signature": {
  4330            "signature": {
  4331              "publicKey": {}
  4332            }
  4333          },
  4334          "modelCard": {
  4335            "modelParameters": {
  4336              "approach": {}
  4337            },
  4338            "quantitativeAnalysis": {
  4339              "graphics": {}
  4340            },
  4341            "considerations": {}
  4342          }
  4343        },
  4344        {
  4345          "type": "library",
  4346          "bom-ref": "pkg:deb/debian/libstdc++6@8.3.0-6?arch=amd64\u0026upstream=gcc-8\u0026distro=debian-10\u0026package-id=d05459fba83fc410",
  4347          "supplier": {},
  4348          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
  4349          "name": "libstdc++6",
  4350          "version": "8.3.0-6",
  4351          "licenses": [
  4352            {
  4353              "license": {
  4354                "name": "Artistic"
  4355              }
  4356            },
  4357            {
  4358              "license": {
  4359                "id": "GFDL-1.2-only"
  4360              }
  4361            },
  4362            {
  4363              "license": {
  4364                "name": "GPL"
  4365              }
  4366            },
  4367            {
  4368              "license": {
  4369                "id": "GPL-2.0-only"
  4370              }
  4371            },
  4372            {
  4373              "license": {
  4374                "id": "GPL-3.0-only"
  4375              }
  4376            },
  4377            {
  4378              "license": {
  4379                "name": "LGPL"
  4380              }
  4381            }
  4382          ],
  4383          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:8.3.0-6:*:*:*:*:*:*:*",
  4384          "purl": "pkg:deb/debian/libstdc++6@8.3.0-6?arch=amd64\u0026upstream=gcc-8\u0026distro=debian-10",
  4385          "swid": {
  4386            "attachment": {}
  4387          },
  4388          "pedigree": {},
  4389          "evidence": {},
  4390          "signature": {
  4391            "signature": {
  4392              "publicKey": {}
  4393            }
  4394          },
  4395          "modelCard": {
  4396            "modelParameters": {
  4397              "approach": {}
  4398            },
  4399            "quantitativeAnalysis": {
  4400              "graphics": {}
  4401            },
  4402            "considerations": {}
  4403          }
  4404        },
  4405        {
  4406          "type": "library",
  4407          "bom-ref": "pkg:deb/debian/libsystemd0@241-7~deb10u7?arch=amd64\u0026upstream=systemd\u0026distro=debian-10\u0026package-id=a0b3dfe941eedc73",
  4408          "supplier": {},
  4409          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
  4410          "name": "libsystemd0",
  4411          "version": "241-7~deb10u7",
  4412          "licenses": [
  4413            {
  4414              "license": {
  4415                "id": "CC0-1.0"
  4416              }
  4417            },
  4418            {
  4419              "license": {
  4420                "name": "Expat"
  4421              }
  4422            },
  4423            {
  4424              "license": {
  4425                "id": "GPL-2.0-only"
  4426              }
  4427            },
  4428            {
  4429              "license": {
  4430                "id": "GPL-2.0-or-later"
  4431              }
  4432            },
  4433            {
  4434              "license": {
  4435                "id": "LGPL-2.1-only"
  4436              }
  4437            },
  4438            {
  4439              "license": {
  4440                "id": "LGPL-2.1-or-later"
  4441              }
  4442            },
  4443            {
  4444              "license": {
  4445                "name": "public-domain"
  4446              }
  4447            }
  4448          ],
  4449          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:241-7\\~deb10u7:*:*:*:*:*:*:*",
  4450          "purl": "pkg:deb/debian/libsystemd0@241-7~deb10u7?arch=amd64\u0026upstream=systemd\u0026distro=debian-10",
  4451          "swid": {
  4452            "attachment": {}
  4453          },
  4454          "pedigree": {},
  4455          "evidence": {},
  4456          "signature": {
  4457            "signature": {
  4458              "publicKey": {}
  4459            }
  4460          },
  4461          "modelCard": {
  4462            "modelParameters": {
  4463              "approach": {}
  4464            },
  4465            "quantitativeAnalysis": {
  4466              "graphics": {}
  4467            },
  4468            "considerations": {}
  4469          }
  4470        },
  4471        {
  4472          "type": "library",
  4473          "bom-ref": "pkg:deb/debian/libtasn1-6@4.13-3?arch=amd64\u0026distro=debian-10\u0026package-id=692d7710a71ec82b",
  4474          "supplier": {},
  4475          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
  4476          "name": "libtasn1-6",
  4477          "version": "4.13-3",
  4478          "licenses": [
  4479            {
  4480              "license": {
  4481                "id": "GFDL-1.3-only"
  4482              }
  4483            },
  4484            {
  4485              "license": {
  4486                "id": "GPL-3.0-only"
  4487              }
  4488            },
  4489            {
  4490              "license": {
  4491                "name": "LGPL"
  4492              }
  4493            },
  4494            {
  4495              "license": {
  4496                "id": "LGPL-2.1-only"
  4497              }
  4498            }
  4499          ],
  4500          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.13-3:*:*:*:*:*:*:*",
  4501          "purl": "pkg:deb/debian/libtasn1-6@4.13-3?arch=amd64\u0026distro=debian-10",
  4502          "swid": {
  4503            "attachment": {}
  4504          },
  4505          "pedigree": {},
  4506          "evidence": {},
  4507          "signature": {
  4508            "signature": {
  4509              "publicKey": {}
  4510            }
  4511          },
  4512          "modelCard": {
  4513            "modelParameters": {
  4514              "approach": {}
  4515            },
  4516            "quantitativeAnalysis": {
  4517              "graphics": {}
  4518            },
  4519            "considerations": {}
  4520          }
  4521        },
  4522        {
  4523          "type": "library",
  4524          "bom-ref": "pkg:deb/debian/libtinfo6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10\u0026package-id=9e8c05e586cbb968",
  4525          "supplier": {},
  4526          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
  4527          "name": "libtinfo6",
  4528          "version": "6.1+20181013-2+deb10u2",
  4529          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.1\\+20181013-2\\+deb10u2:*:*:*:*:*:*:*",
  4530          "purl": "pkg:deb/debian/libtinfo6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10",
  4531          "swid": {
  4532            "attachment": {}
  4533          },
  4534          "pedigree": {},
  4535          "evidence": {},
  4536          "signature": {
  4537            "signature": {
  4538              "publicKey": {}
  4539            }
  4540          },
  4541          "modelCard": {
  4542            "modelParameters": {
  4543              "approach": {}
  4544            },
  4545            "quantitativeAnalysis": {
  4546              "graphics": {}
  4547            },
  4548            "considerations": {}
  4549          }
  4550        },
  4551        {
  4552          "type": "library",
  4553          "bom-ref": "pkg:deb/debian/libudev1@241-7~deb10u7?arch=amd64\u0026upstream=systemd\u0026distro=debian-10\u0026package-id=b09ff6ad121b7d3",
  4554          "supplier": {},
  4555          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
  4556          "name": "libudev1",
  4557          "version": "241-7~deb10u7",
  4558          "licenses": [
  4559            {
  4560              "license": {
  4561                "id": "CC0-1.0"
  4562              }
  4563            },
  4564            {
  4565              "license": {
  4566                "name": "Expat"
  4567              }
  4568            },
  4569            {
  4570              "license": {
  4571                "id": "GPL-2.0-only"
  4572              }
  4573            },
  4574            {
  4575              "license": {
  4576                "id": "GPL-2.0-or-later"
  4577              }
  4578            },
  4579            {
  4580              "license": {
  4581                "id": "LGPL-2.1-only"
  4582              }
  4583            },
  4584            {
  4585              "license": {
  4586                "id": "LGPL-2.1-or-later"
  4587              }
  4588            },
  4589            {
  4590              "license": {
  4591                "name": "public-domain"
  4592              }
  4593            }
  4594          ],
  4595          "cpe": "cpe:2.3:a:libudev1:libudev1:241-7\\~deb10u7:*:*:*:*:*:*:*",
  4596          "purl": "pkg:deb/debian/libudev1@241-7~deb10u7?arch=amd64\u0026upstream=systemd\u0026distro=debian-10",
  4597          "swid": {
  4598            "attachment": {}
  4599          },
  4600          "pedigree": {},
  4601          "evidence": {},
  4602          "signature": {
  4603            "signature": {
  4604              "publicKey": {}
  4605            }
  4606          },
  4607          "modelCard": {
  4608            "modelParameters": {
  4609              "approach": {}
  4610            },
  4611            "quantitativeAnalysis": {
  4612              "graphics": {}
  4613            },
  4614            "considerations": {}
  4615          }
  4616        },
  4617        {
  4618          "type": "library",
  4619          "bom-ref": "pkg:deb/debian/libunistring2@0.9.10-1?arch=amd64\u0026upstream=libunistring\u0026distro=debian-10\u0026package-id=b394fd46c85f8bb7",
  4620          "supplier": {},
  4621          "publisher": "Jörg Frings-Fürst \u003cdebian@jff.email\u003e",
  4622          "name": "libunistring2",
  4623          "version": "0.9.10-1",
  4624          "licenses": [
  4625            {
  4626              "license": {
  4627                "name": "FreeSoftware"
  4628              }
  4629            },
  4630            {
  4631              "license": {
  4632                "id": "GFDL-1.2-only"
  4633              }
  4634            },
  4635            {
  4636              "license": {
  4637                "name": "GFDL-1.2+"
  4638              }
  4639            },
  4640            {
  4641              "license": {
  4642                "id": "GPL-2.0-only"
  4643              }
  4644            },
  4645            {
  4646              "license": {
  4647                "id": "GPL-2.0-or-later"
  4648              }
  4649            },
  4650            {
  4651              "license": {
  4652                "id": "GPL-3.0-only"
  4653              }
  4654            },
  4655            {
  4656              "license": {
  4657                "id": "GPL-3.0-or-later"
  4658              }
  4659            },
  4660            {
  4661              "license": {
  4662                "id": "LGPL-3.0-only"
  4663              }
  4664            },
  4665            {
  4666              "license": {
  4667                "id": "LGPL-3.0-or-later"
  4668              }
  4669            },
  4670            {
  4671              "license": {
  4672                "id": "MIT"
  4673              }
  4674            }
  4675          ],
  4676          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-1:*:*:*:*:*:*:*",
  4677          "purl": "pkg:deb/debian/libunistring2@0.9.10-1?arch=amd64\u0026upstream=libunistring\u0026distro=debian-10",
  4678          "swid": {
  4679            "attachment": {}
  4680          },
  4681          "pedigree": {},
  4682          "evidence": {},
  4683          "signature": {
  4684            "signature": {
  4685              "publicKey": {}
  4686            }
  4687          },
  4688          "modelCard": {
  4689            "modelParameters": {
  4690              "approach": {}
  4691            },
  4692            "quantitativeAnalysis": {
  4693              "graphics": {}
  4694            },
  4695            "considerations": {}
  4696          }
  4697        },
  4698        {
  4699          "type": "library",
  4700          "bom-ref": "pkg:deb/debian/libuuid1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=69873dc165cbbd6e",
  4701          "supplier": {},
  4702          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
  4703          "name": "libuuid1",
  4704          "version": "2.33.1-0.1",
  4705          "licenses": [
  4706            {
  4707              "license": {
  4708                "id": "BSD-2-Clause"
  4709              }
  4710            },
  4711            {
  4712              "license": {
  4713                "id": "BSD-3-Clause"
  4714              }
  4715            },
  4716            {
  4717              "license": {
  4718                "id": "BSD-4-Clause"
  4719              }
  4720            },
  4721            {
  4722              "license": {
  4723                "id": "GPL-2.0-only"
  4724              }
  4725            },
  4726            {
  4727              "license": {
  4728                "id": "GPL-2.0-or-later"
  4729              }
  4730            },
  4731            {
  4732              "license": {
  4733                "id": "GPL-3.0-only"
  4734              }
  4735            },
  4736            {
  4737              "license": {
  4738                "id": "GPL-3.0-or-later"
  4739              }
  4740            },
  4741            {
  4742              "license": {
  4743                "name": "LGPL"
  4744              }
  4745            },
  4746            {
  4747              "license": {
  4748                "id": "LGPL-2.0-only"
  4749              }
  4750            },
  4751            {
  4752              "license": {
  4753                "id": "LGPL-2.0-or-later"
  4754              }
  4755            },
  4756            {
  4757              "license": {
  4758                "id": "LGPL-2.1-only"
  4759              }
  4760            },
  4761            {
  4762              "license": {
  4763                "id": "LGPL-2.1-or-later"
  4764              }
  4765            },
  4766            {
  4767              "license": {
  4768                "id": "LGPL-3.0-only"
  4769              }
  4770            },
  4771            {
  4772              "license": {
  4773                "id": "LGPL-3.0-or-later"
  4774              }
  4775            },
  4776            {
  4777              "license": {
  4778                "id": "MIT"
  4779              }
  4780            },
  4781            {
  4782              "license": {
  4783                "name": "public-domain"
  4784              }
  4785            }
  4786          ],
  4787          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.33.1-0.1:*:*:*:*:*:*:*",
  4788          "purl": "pkg:deb/debian/libuuid1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
  4789          "swid": {
  4790            "attachment": {}
  4791          },
  4792          "pedigree": {},
  4793          "evidence": {},
  4794          "signature": {
  4795            "signature": {
  4796              "publicKey": {}
  4797            }
  4798          },
  4799          "modelCard": {
  4800            "modelParameters": {
  4801              "approach": {}
  4802            },
  4803            "quantitativeAnalysis": {
  4804              "graphics": {}
  4805            },
  4806            "considerations": {}
  4807          }
  4808        },
  4809        {
  4810          "type": "library",
  4811          "bom-ref": "pkg:deb/debian/libzstd1@1.3.8+dfsg-3+deb10u2?arch=amd64\u0026upstream=libzstd\u0026distro=debian-10\u0026package-id=b90d64adc03a2a50",
  4812          "supplier": {},
  4813          "publisher": "Debian Med Packaging Team \u003cdebian-med-packaging@lists.alioth.debian.org\u003e",
  4814          "name": "libzstd1",
  4815          "version": "1.3.8+dfsg-3+deb10u2",
  4816          "licenses": [
  4817            {
  4818              "license": {
  4819                "id": "BSD-3-Clause"
  4820              }
  4821            },
  4822            {
  4823              "license": {
  4824                "name": "Expat"
  4825              }
  4826            },
  4827            {
  4828              "license": {
  4829                "id": "GPL-2.0-only"
  4830              }
  4831            },
  4832            {
  4833              "license": {
  4834                "id": "GPL-2.0-or-later"
  4835              }
  4836            },
  4837            {
  4838              "license": {
  4839                "id": "Zlib"
  4840              }
  4841            }
  4842          ],
  4843          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.3.8\\+dfsg-3\\+deb10u2:*:*:*:*:*:*:*",
  4844          "purl": "pkg:deb/debian/libzstd1@1.3.8+dfsg-3+deb10u2?arch=amd64\u0026upstream=libzstd\u0026distro=debian-10",
  4845          "swid": {
  4846            "attachment": {}
  4847          },
  4848          "pedigree": {},
  4849          "evidence": {},
  4850          "signature": {
  4851            "signature": {
  4852              "publicKey": {}
  4853            }
  4854          },
  4855          "modelCard": {
  4856            "modelParameters": {
  4857              "approach": {}
  4858            },
  4859            "quantitativeAnalysis": {
  4860              "graphics": {}
  4861            },
  4862            "considerations": {}
  4863          }
  4864        },
  4865        {
  4866          "type": "library",
  4867          "bom-ref": "pkg:deb/debian/login@1:4.5-1.1?arch=amd64\u0026upstream=shadow\u0026distro=debian-10\u0026package-id=98839d2adee55b56",
  4868          "supplier": {},
  4869          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
  4870          "name": "login",
  4871          "version": "1:4.5-1.1",
  4872          "licenses": [
  4873            {
  4874              "license": {
  4875                "id": "GPL-2.0-only"
  4876              }
  4877            }
  4878          ],
  4879          "cpe": "cpe:2.3:a:login:login:1\\:4.5-1.1:*:*:*:*:*:*:*",
  4880          "purl": "pkg:deb/debian/login@1:4.5-1.1?arch=amd64\u0026upstream=shadow\u0026distro=debian-10",
  4881          "swid": {
  4882            "attachment": {}
  4883          },
  4884          "pedigree": {},
  4885          "evidence": {},
  4886          "signature": {
  4887            "signature": {
  4888              "publicKey": {}
  4889            }
  4890          },
  4891          "modelCard": {
  4892            "modelParameters": {
  4893              "approach": {}
  4894            },
  4895            "quantitativeAnalysis": {
  4896              "graphics": {}
  4897            },
  4898            "considerations": {}
  4899          }
  4900        },
  4901        {
  4902          "type": "library",
  4903          "bom-ref": "pkg:deb/debian/lsb-base@10.2019051400?arch=all\u0026upstream=lsb\u0026distro=debian-10\u0026package-id=4986087322566df",
  4904          "supplier": {},
  4905          "publisher": "Debian LSB Team \u003cdebian-lsb@lists.debian.org\u003e",
  4906          "name": "lsb-base",
  4907          "version": "10.2019051400",
  4908          "licenses": [
  4909            {
  4910              "license": {
  4911                "id": "BSD-3-Clause"
  4912              }
  4913            },
  4914            {
  4915              "license": {
  4916                "id": "GPL-2.0-only"
  4917              }
  4918            }
  4919          ],
  4920          "cpe": "cpe:2.3:a:lsb-base:lsb-base:10.2019051400:*:*:*:*:*:*:*",
  4921          "purl": "pkg:deb/debian/lsb-base@10.2019051400?arch=all\u0026upstream=lsb\u0026distro=debian-10",
  4922          "swid": {
  4923            "attachment": {}
  4924          },
  4925          "pedigree": {},
  4926          "evidence": {},
  4927          "signature": {
  4928            "signature": {
  4929              "publicKey": {}
  4930            }
  4931          },
  4932          "modelCard": {
  4933            "modelParameters": {
  4934              "approach": {}
  4935            },
  4936            "quantitativeAnalysis": {
  4937              "graphics": {}
  4938            },
  4939            "considerations": {}
  4940          }
  4941        },
  4942        {
  4943          "type": "library",
  4944          "bom-ref": "pkg:deb/debian/mawk@1.3.3-17+b3?arch=amd64\u0026upstream=mawk%401.3.3-17\u0026distro=debian-10\u0026package-id=2aa71b5a2c22f638",
  4945          "supplier": {},
  4946          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
  4947          "name": "mawk",
  4948          "version": "1.3.3-17+b3",
  4949          "licenses": [
  4950            {
  4951              "license": {
  4952                "id": "GPL-2.0-only"
  4953              }
  4954            }
  4955          ],
  4956          "cpe": "cpe:2.3:a:mawk:mawk:1.3.3-17\\+b3:*:*:*:*:*:*:*",
  4957          "purl": "pkg:deb/debian/mawk@1.3.3-17+b3?arch=amd64\u0026upstream=mawk%401.3.3-17\u0026distro=debian-10",
  4958          "swid": {
  4959            "attachment": {}
  4960          },
  4961          "pedigree": {},
  4962          "evidence": {},
  4963          "signature": {
  4964            "signature": {
  4965              "publicKey": {}
  4966            }
  4967          },
  4968          "modelCard": {
  4969            "modelParameters": {
  4970              "approach": {}
  4971            },
  4972            "quantitativeAnalysis": {
  4973              "graphics": {}
  4974            },
  4975            "considerations": {}
  4976          }
  4977        },
  4978        {
  4979          "type": "library",
  4980          "bom-ref": "pkg:deb/debian/mount@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=d4b73315d7d26098",
  4981          "supplier": {},
  4982          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
  4983          "name": "mount",
  4984          "version": "2.33.1-0.1",
  4985          "licenses": [
  4986            {
  4987              "license": {
  4988                "id": "BSD-2-Clause"
  4989              }
  4990            },
  4991            {
  4992              "license": {
  4993                "id": "BSD-3-Clause"
  4994              }
  4995            },
  4996            {
  4997              "license": {
  4998                "id": "BSD-4-Clause"
  4999              }
  5000            },
  5001            {
  5002              "license": {
  5003                "id": "GPL-2.0-only"
  5004              }
  5005            },
  5006            {
  5007              "license": {
  5008                "id": "GPL-2.0-or-later"
  5009              }
  5010            },
  5011            {
  5012              "license": {
  5013                "id": "GPL-3.0-only"
  5014              }
  5015            },
  5016            {
  5017              "license": {
  5018                "id": "GPL-3.0-or-later"
  5019              }
  5020            },
  5021            {
  5022              "license": {
  5023                "name": "LGPL"
  5024              }
  5025            },
  5026            {
  5027              "license": {
  5028                "id": "LGPL-2.0-only"
  5029              }
  5030            },
  5031            {
  5032              "license": {
  5033                "id": "LGPL-2.0-or-later"
  5034              }
  5035            },
  5036            {
  5037              "license": {
  5038                "id": "LGPL-2.1-only"
  5039              }
  5040            },
  5041            {
  5042              "license": {
  5043                "id": "LGPL-2.1-or-later"
  5044              }
  5045            },
  5046            {
  5047              "license": {
  5048                "id": "LGPL-3.0-only"
  5049              }
  5050            },
  5051            {
  5052              "license": {
  5053                "id": "LGPL-3.0-or-later"
  5054              }
  5055            },
  5056            {
  5057              "license": {
  5058                "id": "MIT"
  5059              }
  5060            },
  5061            {
  5062              "license": {
  5063                "name": "public-domain"
  5064              }
  5065            }
  5066          ],
  5067          "cpe": "cpe:2.3:a:mount:mount:2.33.1-0.1:*:*:*:*:*:*:*",
  5068          "purl": "pkg:deb/debian/mount@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
  5069          "swid": {
  5070            "attachment": {}
  5071          },
  5072          "pedigree": {},
  5073          "evidence": {},
  5074          "signature": {
  5075            "signature": {
  5076              "publicKey": {}
  5077            }
  5078          },
  5079          "modelCard": {
  5080            "modelParameters": {
  5081              "approach": {}
  5082            },
  5083            "quantitativeAnalysis": {
  5084              "graphics": {}
  5085            },
  5086            "considerations": {}
  5087          }
  5088        },
  5089        {
  5090          "type": "library",
  5091          "bom-ref": "pkg:deb/debian/ncurses-base@6.1+20181013-2+deb10u2?arch=all\u0026upstream=ncurses\u0026distro=debian-10\u0026package-id=a9450a198d2ae455",
  5092          "supplier": {},
  5093          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
  5094          "name": "ncurses-base",
  5095          "version": "6.1+20181013-2+deb10u2",
  5096          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.1\\+20181013-2\\+deb10u2:*:*:*:*:*:*:*",
  5097          "purl": "pkg:deb/debian/ncurses-base@6.1+20181013-2+deb10u2?arch=all\u0026upstream=ncurses\u0026distro=debian-10",
  5098          "swid": {
  5099            "attachment": {}
  5100          },
  5101          "pedigree": {},
  5102          "evidence": {},
  5103          "signature": {
  5104            "signature": {
  5105              "publicKey": {}
  5106            }
  5107          },
  5108          "modelCard": {
  5109            "modelParameters": {
  5110              "approach": {}
  5111            },
  5112            "quantitativeAnalysis": {
  5113              "graphics": {}
  5114            },
  5115            "considerations": {}
  5116          }
  5117        },
  5118        {
  5119          "type": "library",
  5120          "bom-ref": "pkg:deb/debian/openssl@1.1.1d-0+deb10u6?arch=amd64\u0026distro=debian-10\u0026package-id=b87eb2b49275b6d9",
  5121          "supplier": {},
  5122          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
  5123          "name": "openssl",
  5124          "version": "1.1.1d-0+deb10u6",
  5125          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1d-0\\+deb10u6:*:*:*:*:*:*:*",
  5126          "purl": "pkg:deb/debian/openssl@1.1.1d-0+deb10u6?arch=amd64\u0026distro=debian-10",
  5127          "swid": {
  5128            "attachment": {}
  5129          },
  5130          "pedigree": {},
  5131          "evidence": {},
  5132          "signature": {
  5133            "signature": {
  5134              "publicKey": {}
  5135            }
  5136          },
  5137          "modelCard": {
  5138            "modelParameters": {
  5139              "approach": {}
  5140            },
  5141            "quantitativeAnalysis": {
  5142              "graphics": {}
  5143            },
  5144            "considerations": {}
  5145          }
  5146        },
  5147        {
  5148          "type": "library",
  5149          "bom-ref": "pkg:deb/debian/passwd@1:4.5-1.1?arch=amd64\u0026upstream=shadow\u0026distro=debian-10\u0026package-id=6a37b96614be0ad8",
  5150          "supplier": {},
  5151          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
  5152          "name": "passwd",
  5153          "version": "1:4.5-1.1",
  5154          "licenses": [
  5155            {
  5156              "license": {
  5157                "id": "GPL-2.0-only"
  5158              }
  5159            }
  5160          ],
  5161          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.5-1.1:*:*:*:*:*:*:*",
  5162          "purl": "pkg:deb/debian/passwd@1:4.5-1.1?arch=amd64\u0026upstream=shadow\u0026distro=debian-10",
  5163          "swid": {
  5164            "attachment": {}
  5165          },
  5166          "pedigree": {},
  5167          "evidence": {},
  5168          "signature": {
  5169            "signature": {
  5170              "publicKey": {}
  5171            }
  5172          },
  5173          "modelCard": {
  5174            "modelParameters": {
  5175              "approach": {}
  5176            },
  5177            "quantitativeAnalysis": {
  5178              "graphics": {}
  5179            },
  5180            "considerations": {}
  5181          }
  5182        },
  5183        {
  5184          "type": "library",
  5185          "bom-ref": "pkg:deb/debian/perl-base@5.28.1-6+deb10u1?arch=amd64\u0026upstream=perl\u0026distro=debian-10\u0026package-id=99c7261aa39b37e1",
  5186          "supplier": {},
  5187          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
  5188          "name": "perl-base",
  5189          "version": "5.28.1-6+deb10u1",
  5190          "licenses": [
  5191            {
  5192              "license": {
  5193                "name": "Artistic"
  5194              }
  5195            },
  5196            {
  5197              "license": {
  5198                "id": "Artistic-2.0"
  5199              }
  5200            },
  5201            {
  5202              "license": {
  5203                "name": "Artistic-dist"
  5204              }
  5205            },
  5206            {
  5207              "license": {
  5208                "id": "BSD-3-Clause"
  5209              }
  5210            },
  5211            {
  5212              "license": {
  5213                "name": "BSD-3-clause-GENERIC"
  5214              }
  5215            },
  5216            {
  5217              "license": {
  5218                "name": "BSD-3-clause-with-weird-numbering"
  5219              }
  5220            },
  5221            {
  5222              "license": {
  5223                "name": "BSD-4-clause-POWERDOG"
  5224              }
  5225            },
  5226            {
  5227              "license": {
  5228                "name": "BZIP"
  5229              }
  5230            },
  5231            {
  5232              "license": {
  5233                "name": "DONT-CHANGE-THE-GPL"
  5234              }
  5235            },
  5236            {
  5237              "license": {
  5238                "name": "Expat"
  5239              }
  5240            },
  5241            {
  5242              "license": {
  5243                "id": "GPL-1.0-only"
  5244              }
  5245            },
  5246            {
  5247              "license": {
  5248                "id": "GPL-1.0-or-later"
  5249              }
  5250            },
  5251            {
  5252              "license": {
  5253                "id": "GPL-2.0-only"
  5254              }
  5255            },
  5256            {
  5257              "license": {
  5258                "id": "GPL-2.0-or-later"
  5259              }
  5260            },
  5261            {
  5262              "license": {
  5263                "name": "GPL-3+-WITH-BISON-EXCEPTION"
  5264              }
  5265            },
  5266            {
  5267              "license": {
  5268                "name": "HSIEH-BSD"
  5269              }
  5270            },
  5271            {
  5272              "license": {
  5273                "name": "HSIEH-DERIVATIVE"
  5274              }
  5275            },
  5276            {
  5277              "license": {
  5278                "id": "LGPL-2.1-only"
  5279              }
  5280            },
  5281            {
  5282              "license": {
  5283                "name": "REGCOMP"
  5284              }
  5285            },
  5286            {
  5287              "license": {
  5288                "name": "REGCOMP,"
  5289              }
  5290            },
  5291            {
  5292              "license": {
  5293                "name": "RRA-KEEP-THIS-NOTICE"
  5294              }
  5295            },
  5296            {
  5297              "license": {
  5298                "name": "S2P"
  5299              }
  5300            },
  5301            {
  5302              "license": {
  5303                "name": "SDBM-PUBLIC-DOMAIN"
  5304              }
  5305            },
  5306            {
  5307              "license": {
  5308                "name": "TEXT-TABS"
  5309              }
  5310            },
  5311            {
  5312              "license": {
  5313                "name": "Unicode"
  5314              }
  5315            },
  5316            {
  5317              "license": {
  5318                "id": "Zlib"
  5319              }
  5320            }
  5321          ],
  5322          "cpe": "cpe:2.3:a:perl-base:perl-base:5.28.1-6\\+deb10u1:*:*:*:*:*:*:*",
  5323          "purl": "pkg:deb/debian/perl-base@5.28.1-6+deb10u1?arch=amd64\u0026upstream=perl\u0026distro=debian-10",
  5324          "swid": {
  5325            "attachment": {}
  5326          },
  5327          "pedigree": {},
  5328          "evidence": {},
  5329          "signature": {
  5330            "signature": {
  5331              "publicKey": {}
  5332            }
  5333          },
  5334          "modelCard": {
  5335            "modelParameters": {
  5336              "approach": {}
  5337            },
  5338            "quantitativeAnalysis": {
  5339              "graphics": {}
  5340            },
  5341            "considerations": {}
  5342          }
  5343        },
  5344        {
  5345          "type": "library",
  5346          "bom-ref": "pkg:deb/debian/procps@2:3.3.15-2?arch=amd64\u0026distro=debian-10\u0026package-id=ecd7f395d1b30af7",
  5347          "supplier": {},
  5348          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
  5349          "name": "procps",
  5350          "version": "2:3.3.15-2",
  5351          "licenses": [
  5352            {
  5353              "license": {
  5354                "id": "GPL-2.0-only"
  5355              }
  5356            },
  5357            {
  5358              "license": {
  5359                "id": "GPL-2.0-or-later"
  5360              }
  5361            },
  5362            {
  5363              "license": {
  5364                "id": "LGPL-2.0-only"
  5365              }
  5366            },
  5367            {
  5368              "license": {
  5369                "id": "LGPL-2.0-or-later"
  5370              }
  5371            },
  5372            {
  5373              "license": {
  5374                "id": "LGPL-2.1-only"
  5375              }
  5376            },
  5377            {
  5378              "license": {
  5379                "id": "LGPL-2.1-or-later"
  5380              }
  5381            }
  5382          ],
  5383          "cpe": "cpe:2.3:a:procps:procps:2\\:3.3.15-2:*:*:*:*:*:*:*",
  5384          "purl": "pkg:deb/debian/procps@2:3.3.15-2?arch=amd64\u0026distro=debian-10",
  5385          "swid": {
  5386            "attachment": {}
  5387          },
  5388          "pedigree": {},
  5389          "evidence": {},
  5390          "signature": {
  5391            "signature": {
  5392              "publicKey": {}
  5393            }
  5394          },
  5395          "modelCard": {
  5396            "modelParameters": {
  5397              "approach": {}
  5398            },
  5399            "quantitativeAnalysis": {
  5400              "graphics": {}
  5401            },
  5402            "considerations": {}
  5403          }
  5404        },
  5405        {
  5406          "type": "library",
  5407          "bom-ref": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-10\u0026package-id=cd24b1a69c7b788a",
  5408          "supplier": {},
  5409          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
  5410          "name": "sed",
  5411          "version": "4.7-1",
  5412          "licenses": [
  5413            {
  5414              "license": {
  5415                "id": "GPL-3.0-only"
  5416              }
  5417            }
  5418          ],
  5419          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
  5420          "purl": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-10",
  5421          "swid": {
  5422            "attachment": {}
  5423          },
  5424          "pedigree": {},
  5425          "evidence": {},
  5426          "signature": {
  5427            "signature": {
  5428              "publicKey": {}
  5429            }
  5430          },
  5431          "modelCard": {
  5432            "modelParameters": {
  5433              "approach": {}
  5434            },
  5435            "quantitativeAnalysis": {
  5436              "graphics": {}
  5437            },
  5438            "considerations": {}
  5439          }
  5440        },
  5441        {
  5442          "type": "library",
  5443          "bom-ref": "pkg:deb/debian/startpar@0.61-1?arch=amd64\u0026distro=debian-10\u0026package-id=bfa1cab592ae4a14",
  5444          "supplier": {},
  5445          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
  5446          "name": "startpar",
  5447          "version": "0.61-1",
  5448          "licenses": [
  5449            {
  5450              "license": {
  5451                "id": "GPL-2.0-only"
  5452              }
  5453            },
  5454            {
  5455              "license": {
  5456                "id": "GPL-2.0-or-later"
  5457              }
  5458            }
  5459          ],
  5460          "cpe": "cpe:2.3:a:startpar:startpar:0.61-1:*:*:*:*:*:*:*",
  5461          "purl": "pkg:deb/debian/startpar@0.61-1?arch=amd64\u0026distro=debian-10",
  5462          "swid": {
  5463            "attachment": {}
  5464          },
  5465          "pedigree": {},
  5466          "evidence": {},
  5467          "signature": {
  5468            "signature": {
  5469              "publicKey": {}
  5470            }
  5471          },
  5472          "modelCard": {
  5473            "modelParameters": {
  5474              "approach": {}
  5475            },
  5476            "quantitativeAnalysis": {
  5477              "graphics": {}
  5478            },
  5479            "considerations": {}
  5480          }
  5481        },
  5482        {
  5483          "type": "library",
  5484          "bom-ref": "pkg:deb/debian/sysv-rc@2.93-8?arch=all\u0026upstream=sysvinit\u0026distro=debian-10\u0026package-id=ea0552f0f86929b5",
  5485          "supplier": {},
  5486          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
  5487          "name": "sysv-rc",
  5488          "version": "2.93-8",
  5489          "licenses": [
  5490            {
  5491              "license": {
  5492                "id": "GPL-2.0-only"
  5493              }
  5494            },
  5495            {
  5496              "license": {
  5497                "id": "GPL-2.0-or-later"
  5498              }
  5499            }
  5500          ],
  5501          "cpe": "cpe:2.3:a:sysv-rc:sysv-rc:2.93-8:*:*:*:*:*:*:*",
  5502          "purl": "pkg:deb/debian/sysv-rc@2.93-8?arch=all\u0026upstream=sysvinit\u0026distro=debian-10",
  5503          "swid": {
  5504            "attachment": {}
  5505          },
  5506          "pedigree": {},
  5507          "evidence": {},
  5508          "signature": {
  5509            "signature": {
  5510              "publicKey": {}
  5511            }
  5512          },
  5513          "modelCard": {
  5514            "modelParameters": {
  5515              "approach": {}
  5516            },
  5517            "quantitativeAnalysis": {
  5518              "graphics": {}
  5519            },
  5520            "considerations": {}
  5521          }
  5522        },
  5523        {
  5524          "type": "library",
  5525          "bom-ref": "pkg:deb/debian/sysvinit-utils@2.93-8?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-10\u0026package-id=9762b89f96a3933c",
  5526          "supplier": {},
  5527          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
  5528          "name": "sysvinit-utils",
  5529          "version": "2.93-8",
  5530          "licenses": [
  5531            {
  5532              "license": {
  5533                "id": "GPL-2.0-only"
  5534              }
  5535            },
  5536            {
  5537              "license": {
  5538                "id": "GPL-2.0-or-later"
  5539              }
  5540            }
  5541          ],
  5542          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.93-8:*:*:*:*:*:*:*",
  5543          "purl": "pkg:deb/debian/sysvinit-utils@2.93-8?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-10",
  5544          "swid": {
  5545            "attachment": {}
  5546          },
  5547          "pedigree": {},
  5548          "evidence": {},
  5549          "signature": {
  5550            "signature": {
  5551              "publicKey": {}
  5552            }
  5553          },
  5554          "modelCard": {
  5555            "modelParameters": {
  5556              "approach": {}
  5557            },
  5558            "quantitativeAnalysis": {
  5559              "graphics": {}
  5560            },
  5561            "considerations": {}
  5562          }
  5563        },
  5564        {
  5565          "type": "library",
  5566          "bom-ref": "pkg:deb/debian/tar@1.30+dfsg-6?arch=amd64\u0026distro=debian-10\u0026package-id=c194088099b2a715",
  5567          "supplier": {},
  5568          "publisher": "Bdale Garbee \u003cbdale@gag.com\u003e",
  5569          "name": "tar",
  5570          "version": "1.30+dfsg-6",
  5571          "licenses": [
  5572            {
  5573              "license": {
  5574                "id": "GPL-2.0-only"
  5575              }
  5576            },
  5577            {
  5578              "license": {
  5579                "id": "GPL-3.0-only"
  5580              }
  5581            }
  5582          ],
  5583          "cpe": "cpe:2.3:a:tar:tar:1.30\\+dfsg-6:*:*:*:*:*:*:*",
  5584          "purl": "pkg:deb/debian/tar@1.30+dfsg-6?arch=amd64\u0026distro=debian-10",
  5585          "swid": {
  5586            "attachment": {}
  5587          },
  5588          "pedigree": {},
  5589          "evidence": {},
  5590          "signature": {
  5591            "signature": {
  5592              "publicKey": {}
  5593            }
  5594          },
  5595          "modelCard": {
  5596            "modelParameters": {
  5597              "approach": {}
  5598            },
  5599            "quantitativeAnalysis": {
  5600              "graphics": {}
  5601            },
  5602            "considerations": {}
  5603          }
  5604        },
  5605        {
  5606          "type": "library",
  5607          "bom-ref": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10\u0026package-id=382d46893fab7c54",
  5608          "supplier": {},
  5609          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
  5610          "name": "tzdata",
  5611          "version": "2021a-0+deb10u1",
  5612          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0\\+deb10u1:*:*:*:*:*:*:*",
  5613          "purl": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10",
  5614          "swid": {
  5615            "attachment": {}
  5616          },
  5617          "pedigree": {},
  5618          "evidence": {},
  5619          "signature": {
  5620            "signature": {
  5621              "publicKey": {}
  5622            }
  5623          },
  5624          "modelCard": {
  5625            "modelParameters": {
  5626              "approach": {}
  5627            },
  5628            "quantitativeAnalysis": {
  5629              "graphics": {}
  5630            },
  5631            "considerations": {}
  5632          }
  5633        },
  5634        {
  5635          "type": "library",
  5636          "bom-ref": "pkg:deb/debian/util-linux@2.33.1-0.1?arch=amd64\u0026distro=debian-10\u0026package-id=cc8d30d3a3bc01b6",
  5637          "supplier": {},
  5638          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
  5639          "name": "util-linux",
  5640          "version": "2.33.1-0.1",
  5641          "licenses": [
  5642            {
  5643              "license": {
  5644                "id": "BSD-2-Clause"
  5645              }
  5646            },
  5647            {
  5648              "license": {
  5649                "id": "BSD-3-Clause"
  5650              }
  5651            },
  5652            {
  5653              "license": {
  5654                "id": "BSD-4-Clause"
  5655              }
  5656            },
  5657            {
  5658              "license": {
  5659                "id": "GPL-2.0-only"
  5660              }
  5661            },
  5662            {
  5663              "license": {
  5664                "id": "GPL-2.0-or-later"
  5665              }
  5666            },
  5667            {
  5668              "license": {
  5669                "id": "GPL-3.0-only"
  5670              }
  5671            },
  5672            {
  5673              "license": {
  5674                "id": "GPL-3.0-or-later"
  5675              }
  5676            },
  5677            {
  5678              "license": {
  5679                "name": "LGPL"
  5680              }
  5681            },
  5682            {
  5683              "license": {
  5684                "id": "LGPL-2.0-only"
  5685              }
  5686            },
  5687            {
  5688              "license": {
  5689                "id": "LGPL-2.0-or-later"
  5690              }
  5691            },
  5692            {
  5693              "license": {
  5694                "id": "LGPL-2.1-only"
  5695              }
  5696            },
  5697            {
  5698              "license": {
  5699                "id": "LGPL-2.1-or-later"
  5700              }
  5701            },
  5702            {
  5703              "license": {
  5704                "id": "LGPL-3.0-only"
  5705              }
  5706            },
  5707            {
  5708              "license": {
  5709                "id": "LGPL-3.0-or-later"
  5710              }
  5711            },
  5712            {
  5713              "license": {
  5714                "id": "MIT"
  5715              }
  5716            },
  5717            {
  5718              "license": {
  5719                "name": "public-domain"
  5720              }
  5721            }
  5722          ],
  5723          "cpe": "cpe:2.3:a:util-linux:util-linux:2.33.1-0.1:*:*:*:*:*:*:*",
  5724          "purl": "pkg:deb/debian/util-linux@2.33.1-0.1?arch=amd64\u0026distro=debian-10",
  5725          "swid": {
  5726            "attachment": {}
  5727          },
  5728          "pedigree": {},
  5729          "evidence": {},
  5730          "signature": {
  5731            "signature": {
  5732              "publicKey": {}
  5733            }
  5734          },
  5735          "modelCard": {
  5736            "modelParameters": {
  5737              "approach": {}
  5738            },
  5739            "quantitativeAnalysis": {
  5740              "graphics": {}
  5741            },
  5742            "considerations": {}
  5743          }
  5744        },
  5745        {
  5746          "type": "library",
  5747          "bom-ref": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-1?arch=amd64\u0026upstream=zlib\u0026distro=debian-10\u0026package-id=462eb7255c2bc918",
  5748          "supplier": {},
  5749          "publisher": "Mark Brown \u003cbroonie@debian.org\u003e",
  5750          "name": "zlib1g",
  5751          "version": "1:1.2.11.dfsg-1",
  5752          "licenses": [
  5753            {
  5754              "license": {
  5755                "id": "Zlib"
  5756              }
  5757            }
  5758          ],
  5759          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-1:*:*:*:*:*:*:*",
  5760          "purl": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-1?arch=amd64\u0026upstream=zlib\u0026distro=debian-10",
  5761          "swid": {
  5762            "attachment": {}
  5763          },
  5764          "pedigree": {},
  5765          "evidence": {},
  5766          "signature": {
  5767            "signature": {
  5768              "publicKey": {}
  5769            }
  5770          },
  5771          "modelCard": {
  5772            "modelParameters": {
  5773              "approach": {}
  5774            },
  5775            "quantitativeAnalysis": {
  5776              "graphics": {}
  5777            },
  5778            "considerations": {}
  5779          }
  5780        },
  5781        {
  5782          "type": "operating-system",
  5783          "supplier": {},
  5784          "name": "debian",
  5785          "version": "10",
  5786          "description": "Debian GNU/Linux 10 (buster)",
  5787          "swid": {
  5788            "tagId": "debian",
  5789            "name": "debian",
  5790            "version": "10",
  5791            "attachment": {}
  5792          },
  5793          "pedigree": {},
  5794          "externalReferences": [
  5795            {
  5796              "url": "https://bugs.debian.org/",
  5797              "type": "issue-tracker"
  5798            },
  5799            {
  5800              "url": "https://www.debian.org/",
  5801              "type": "website"
  5802            },
  5803            {
  5804              "url": "https://www.debian.org/support",
  5805              "comment": "support",
  5806              "type": "other"
  5807            }
  5808          ],
  5809          "evidence": {},
  5810          "signature": {
  5811            "signature": {
  5812              "publicKey": {}
  5813            }
  5814          },
  5815          "modelCard": {
  5816            "modelParameters": {
  5817              "approach": {}
  5818            },
  5819            "quantitativeAnalysis": {
  5820              "graphics": {}
  5821            },
  5822            "considerations": {}
  5823          }
  5824        },
  5825        {
  5826          "type": "library",
  5827          "bom-ref": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-11\u0026package-id=3e9282034226b93f",
  5828          "supplier": {},
  5829          "publisher": "Debian Adduser Developers \u003cadduser@packages.debian.org\u003e",
  5830          "name": "adduser",
  5831          "version": "3.118",
  5832          "licenses": [
  5833            {
  5834              "license": {
  5835                "id": "GPL-2.0-only"
  5836              }
  5837            }
  5838          ],
  5839          "cpe": "cpe:2.3:a:adduser:adduser:3.118:*:*:*:*:*:*:*",
  5840          "purl": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-11",
  5841          "swid": {
  5842            "attachment": {}
  5843          },
  5844          "pedigree": {},
  5845          "evidence": {},
  5846          "signature": {
  5847            "signature": {
  5848              "publicKey": {}
  5849            }
  5850          },
  5851          "modelCard": {
  5852            "modelParameters": {
  5853              "approach": {}
  5854            },
  5855            "quantitativeAnalysis": {
  5856              "graphics": {}
  5857            },
  5858            "considerations": {}
  5859          }
  5860        },
  5861        {
  5862          "type": "library",
  5863          "bom-ref": "pkg:deb/debian/apt@2.2.4?arch=amd64\u0026distro=debian-11\u0026package-id=1cce537379623b25",
  5864          "supplier": {},
  5865          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
  5866          "name": "apt",
  5867          "version": "2.2.4",
  5868          "licenses": [
  5869            {
  5870              "license": {
  5871                "id": "GPL-2.0-only"
  5872              }
  5873            },
  5874            {
  5875              "license": {
  5876                "name": "GPLv2+"
  5877              }
  5878            }
  5879          ],
  5880          "cpe": "cpe:2.3:a:apt:apt:2.2.4:*:*:*:*:*:*:*",
  5881          "purl": "pkg:deb/debian/apt@2.2.4?arch=amd64\u0026distro=debian-11",
  5882          "swid": {
  5883            "attachment": {}
  5884          },
  5885          "pedigree": {},
  5886          "evidence": {},
  5887          "signature": {
  5888            "signature": {
  5889              "publicKey": {}
  5890            }
  5891          },
  5892          "modelCard": {
  5893            "modelParameters": {
  5894              "approach": {}
  5895            },
  5896            "quantitativeAnalysis": {
  5897              "graphics": {}
  5898            },
  5899            "considerations": {}
  5900          }
  5901        },
  5902        {
  5903          "type": "library",
  5904          "bom-ref": "pkg:deb/debian/base-files@11.1+deb11u6?arch=amd64\u0026distro=debian-11\u0026package-id=3c26dd637259b397",
  5905          "supplier": {},
  5906          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
  5907          "name": "base-files",
  5908          "version": "11.1+deb11u6",
  5909          "licenses": [
  5910            {
  5911              "license": {
  5912                "name": "GPL"
  5913              }
  5914            }
  5915          ],
  5916          "cpe": "cpe:2.3:a:base-files:base-files:11.1\\+deb11u6:*:*:*:*:*:*:*",
  5917          "purl": "pkg:deb/debian/base-files@11.1+deb11u6?arch=amd64\u0026distro=debian-11",
  5918          "swid": {
  5919            "attachment": {}
  5920          },
  5921          "pedigree": {},
  5922          "evidence": {},
  5923          "signature": {
  5924            "signature": {
  5925              "publicKey": {}
  5926            }
  5927          },
  5928          "modelCard": {
  5929            "modelParameters": {
  5930              "approach": {}
  5931            },
  5932            "quantitativeAnalysis": {
  5933              "graphics": {}
  5934            },
  5935            "considerations": {}
  5936          }
  5937        },
  5938        {
  5939          "type": "library",
  5940          "bom-ref": "pkg:deb/debian/base-passwd@3.5.51?arch=amd64\u0026distro=debian-11\u0026package-id=7ae3e2ba2e10f31",
  5941          "supplier": {},
  5942          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
  5943          "name": "base-passwd",
  5944          "version": "3.5.51",
  5945          "licenses": [
  5946            {
  5947              "license": {
  5948                "id": "GPL-2.0-only"
  5949              }
  5950            },
  5951            {
  5952              "license": {
  5953                "name": "public-domain"
  5954              }
  5955            }
  5956          ],
  5957          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.51:*:*:*:*:*:*:*",
  5958          "purl": "pkg:deb/debian/base-passwd@3.5.51?arch=amd64\u0026distro=debian-11",
  5959          "swid": {
  5960            "attachment": {}
  5961          },
  5962          "pedigree": {},
  5963          "evidence": {},
  5964          "signature": {
  5965            "signature": {
  5966              "publicKey": {}
  5967            }
  5968          },
  5969          "modelCard": {
  5970            "modelParameters": {
  5971              "approach": {}
  5972            },
  5973            "quantitativeAnalysis": {
  5974              "graphics": {}
  5975            },
  5976            "considerations": {}
  5977          }
  5978        },
  5979        {
  5980          "type": "library",
  5981          "bom-ref": "pkg:deb/debian/bash@5.1-2+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=94b35b4f7d874a43",
  5982          "supplier": {},
  5983          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
  5984          "name": "bash",
  5985          "version": "5.1-2+deb11u1",
  5986          "licenses": [
  5987            {
  5988              "license": {
  5989                "id": "GPL-3.0-only"
  5990              }
  5991            }
  5992          ],
  5993          "cpe": "cpe:2.3:a:bash:bash:5.1-2\\+deb11u1:*:*:*:*:*:*:*",
  5994          "purl": "pkg:deb/debian/bash@5.1-2+deb11u1?arch=amd64\u0026distro=debian-11",
  5995          "swid": {
  5996            "attachment": {}
  5997          },
  5998          "pedigree": {},
  5999          "evidence": {},
  6000          "signature": {
  6001            "signature": {
  6002              "publicKey": {}
  6003            }
  6004          },
  6005          "modelCard": {
  6006            "modelParameters": {
  6007              "approach": {}
  6008            },
  6009            "quantitativeAnalysis": {
  6010              "graphics": {}
  6011            },
  6012            "considerations": {}
  6013          }
  6014        },
  6015        {
  6016          "type": "library",
  6017          "bom-ref": "pkg:deb/debian/bsdutils@1:2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux%402.36.1-8+deb11u1\u0026distro=debian-11\u0026package-id=677e6ace24dce684",
  6018          "supplier": {},
  6019          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
  6020          "name": "bsdutils",
  6021          "version": "1:2.36.1-8+deb11u1",
  6022          "licenses": [
  6023            {
  6024              "license": {
  6025                "id": "BSD-2-Clause"
  6026              }
  6027            },
  6028            {
  6029              "license": {
  6030                "id": "BSD-3-Clause"
  6031              }
  6032            },
  6033            {
  6034              "license": {
  6035                "id": "BSD-4-Clause"
  6036              }
  6037            },
  6038            {
  6039              "license": {
  6040                "id": "GPL-2.0-only"
  6041              }
  6042            },
  6043            {
  6044              "license": {
  6045                "id": "GPL-2.0-or-later"
  6046              }
  6047            },
  6048            {
  6049              "license": {
  6050                "id": "GPL-3.0-only"
  6051              }
  6052            },
  6053            {
  6054              "license": {
  6055                "id": "GPL-3.0-or-later"
  6056              }
  6057            },
  6058            {
  6059              "license": {
  6060                "name": "LGPL"
  6061              }
  6062            },
  6063            {
  6064              "license": {
  6065                "id": "LGPL-2.0-only"
  6066              }
  6067            },
  6068            {
  6069              "license": {
  6070                "id": "LGPL-2.0-or-later"
  6071              }
  6072            },
  6073            {
  6074              "license": {
  6075                "id": "LGPL-2.1-only"
  6076              }
  6077            },
  6078            {
  6079              "license": {
  6080                "id": "LGPL-2.1-or-later"
  6081              }
  6082            },
  6083            {
  6084              "license": {
  6085                "id": "LGPL-3.0-only"
  6086              }
  6087            },
  6088            {
  6089              "license": {
  6090                "id": "LGPL-3.0-or-later"
  6091              }
  6092            },
  6093            {
  6094              "license": {
  6095                "id": "MIT"
  6096              }
  6097            },
  6098            {
  6099              "license": {
  6100                "name": "public-domain"
  6101              }
  6102            }
  6103          ],
  6104          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
  6105          "purl": "pkg:deb/debian/bsdutils@1:2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux%402.36.1-8+deb11u1\u0026distro=debian-11",
  6106          "swid": {
  6107            "attachment": {}
  6108          },
  6109          "pedigree": {},
  6110          "evidence": {},
  6111          "signature": {
  6112            "signature": {
  6113              "publicKey": {}
  6114            }
  6115          },
  6116          "modelCard": {
  6117            "modelParameters": {
  6118              "approach": {}
  6119            },
  6120            "quantitativeAnalysis": {
  6121              "graphics": {}
  6122            },
  6123            "considerations": {}
  6124          }
  6125        },
  6126        {
  6127          "type": "library",
  6128          "bom-ref": "pkg:deb/debian/ca-certificates@20210119?arch=all\u0026distro=debian-11\u0026package-id=6b7e2b0745c43628",
  6129          "supplier": {},
  6130          "publisher": "Julien Cristau \u003cjcristau@debian.org\u003e",
  6131          "name": "ca-certificates",
  6132          "version": "20210119",
  6133          "licenses": [
  6134            {
  6135              "license": {
  6136                "id": "GPL-2.0-only"
  6137              }
  6138            },
  6139            {
  6140              "license": {
  6141                "id": "GPL-2.0-or-later"
  6142              }
  6143            },
  6144            {
  6145              "license": {
  6146                "id": "MPL-2.0"
  6147              }
  6148            }
  6149          ],
  6150          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20210119:*:*:*:*:*:*:*",
  6151          "purl": "pkg:deb/debian/ca-certificates@20210119?arch=all\u0026distro=debian-11",
  6152          "swid": {
  6153            "attachment": {}
  6154          },
  6155          "pedigree": {},
  6156          "evidence": {},
  6157          "signature": {
  6158            "signature": {
  6159              "publicKey": {}
  6160            }
  6161          },
  6162          "modelCard": {
  6163            "modelParameters": {
  6164              "approach": {}
  6165            },
  6166            "quantitativeAnalysis": {
  6167              "graphics": {}
  6168            },
  6169            "considerations": {}
  6170          }
  6171        },
  6172        {
  6173          "type": "library",
  6174          "bom-ref": "pkg:deb/debian/coreutils@8.32-4+b1?arch=amd64\u0026upstream=coreutils%408.32-4\u0026distro=debian-11\u0026package-id=65bac153c492b66e",
  6175          "supplier": {},
  6176          "publisher": "Michael Stone \u003cmstone@debian.org\u003e",
  6177          "name": "coreutils",
  6178          "version": "8.32-4+b1",
  6179          "licenses": [
  6180            {
  6181              "license": {
  6182                "id": "GPL-3.0-only"
  6183              }
  6184            }
  6185          ],
  6186          "cpe": "cpe:2.3:a:coreutils:coreutils:8.32-4\\+b1:*:*:*:*:*:*:*",
  6187          "purl": "pkg:deb/debian/coreutils@8.32-4+b1?arch=amd64\u0026upstream=coreutils%408.32-4\u0026distro=debian-11",
  6188          "swid": {
  6189            "attachment": {}
  6190          },
  6191          "pedigree": {},
  6192          "evidence": {},
  6193          "signature": {
  6194            "signature": {
  6195              "publicKey": {}
  6196            }
  6197          },
  6198          "modelCard": {
  6199            "modelParameters": {
  6200              "approach": {}
  6201            },
  6202            "quantitativeAnalysis": {
  6203              "graphics": {}
  6204            },
  6205            "considerations": {}
  6206          }
  6207        },
  6208        {
  6209          "type": "library",
  6210          "bom-ref": "pkg:deb/debian/curl@7.74.0-1.3+deb11u7?arch=amd64\u0026distro=debian-11\u0026package-id=cfa0e9d1620ffa4d",
  6211          "supplier": {},
  6212          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
  6213          "name": "curl",
  6214          "version": "7.74.0-1.3+deb11u7",
  6215          "licenses": [
  6216            {
  6217              "license": {
  6218                "id": "BSD-3-Clause"
  6219              }
  6220            },
  6221            {
  6222              "license": {
  6223                "id": "BSD-4-Clause"
  6224              }
  6225            },
  6226            {
  6227              "license": {
  6228                "id": "ISC"
  6229              }
  6230            },
  6231            {
  6232              "license": {
  6233                "id": "curl"
  6234              }
  6235            },
  6236            {
  6237              "license": {
  6238                "name": "other"
  6239              }
  6240            },
  6241            {
  6242              "license": {
  6243                "name": "public-domain"
  6244              }
  6245            }
  6246          ],
  6247          "cpe": "cpe:2.3:a:curl:curl:7.74.0-1.3\\+deb11u7:*:*:*:*:*:*:*",
  6248          "purl": "pkg:deb/debian/curl@7.74.0-1.3+deb11u7?arch=amd64\u0026distro=debian-11",
  6249          "swid": {
  6250            "attachment": {}
  6251          },
  6252          "pedigree": {},
  6253          "evidence": {},
  6254          "signature": {
  6255            "signature": {
  6256              "publicKey": {}
  6257            }
  6258          },
  6259          "modelCard": {
  6260            "modelParameters": {
  6261              "approach": {}
  6262            },
  6263            "quantitativeAnalysis": {
  6264              "graphics": {}
  6265            },
  6266            "considerations": {}
  6267          }
  6268        },
  6269        {
  6270          "type": "library",
  6271          "bom-ref": "pkg:deb/debian/dash@0.5.11+git20200708+dd9ef66-5?arch=amd64\u0026distro=debian-11\u0026package-id=19db7775ce4c27be",
  6272          "supplier": {},
  6273          "publisher": "Andrej Shadura \u003candrewsh@debian.org\u003e",
  6274          "name": "dash",
  6275          "version": "0.5.11+git20200708+dd9ef66-5",
  6276          "licenses": [
  6277            {
  6278              "license": {
  6279                "id": "BSD-3-Clause"
  6280              }
  6281            },
  6282            {
  6283              "license": {
  6284                "id": "BSD-3-Clause"
  6285              }
  6286            },
  6287            {
  6288              "license": {
  6289                "name": "Expat"
  6290              }
  6291            },
  6292            {
  6293              "license": {
  6294                "id": "FSFUL"
  6295              }
  6296            },
  6297            {
  6298              "license": {
  6299                "id": "FSFULLR"
  6300              }
  6301            },
  6302            {
  6303              "license": {
  6304                "id": "GPL-2.0-only"
  6305              }
  6306            },
  6307            {
  6308              "license": {
  6309                "id": "GPL-2.0-or-later"
  6310              }
  6311            },
  6312            {
  6313              "license": {
  6314                "name": "public-domain"
  6315              }
  6316            }
  6317          ],
  6318          "cpe": "cpe:2.3:a:dash:dash:0.5.11\\+git20200708\\+dd9ef66-5:*:*:*:*:*:*:*",
  6319          "purl": "pkg:deb/debian/dash@0.5.11+git20200708+dd9ef66-5?arch=amd64\u0026distro=debian-11",
  6320          "swid": {
  6321            "attachment": {}
  6322          },
  6323          "pedigree": {},
  6324          "evidence": {},
  6325          "signature": {
  6326            "signature": {
  6327              "publicKey": {}
  6328            }
  6329          },
  6330          "modelCard": {
  6331            "modelParameters": {
  6332              "approach": {}
  6333            },
  6334            "quantitativeAnalysis": {
  6335              "graphics": {}
  6336            },
  6337            "considerations": {}
  6338          }
  6339        },
  6340        {
  6341          "type": "library",
  6342          "bom-ref": "pkg:deb/debian/debconf@1.5.77?arch=all\u0026distro=debian-11\u0026package-id=99525df5637687bd",
  6343          "supplier": {},
  6344          "publisher": "Debconf Developers \u003cdebconf-devel@lists.alioth.debian.org\u003e",
  6345          "name": "debconf",
  6346          "version": "1.5.77",
  6347          "licenses": [
  6348            {
  6349              "license": {
  6350                "id": "BSD-2-Clause"
  6351              }
  6352            }
  6353          ],
  6354          "cpe": "cpe:2.3:a:debconf:debconf:1.5.77:*:*:*:*:*:*:*",
  6355          "purl": "pkg:deb/debian/debconf@1.5.77?arch=all\u0026distro=debian-11",
  6356          "swid": {
  6357            "attachment": {}
  6358          },
  6359          "pedigree": {},
  6360          "evidence": {},
  6361          "signature": {
  6362            "signature": {
  6363              "publicKey": {}
  6364            }
  6365          },
  6366          "modelCard": {
  6367            "modelParameters": {
  6368              "approach": {}
  6369            },
  6370            "quantitativeAnalysis": {
  6371              "graphics": {}
  6372            },
  6373            "considerations": {}
  6374          }
  6375        },
  6376        {
  6377          "type": "library",
  6378          "bom-ref": "pkg:deb/debian/debian-archive-keyring@2021.1.1?arch=all\u0026distro=debian-11\u0026package-id=f7fcb44a58e72708",
  6379          "supplier": {},
  6380          "publisher": "Debian Release Team \u003cpackages@release.debian.org\u003e",
  6381          "name": "debian-archive-keyring",
  6382          "version": "2021.1.1",
  6383          "licenses": [
  6384            {
  6385              "license": {
  6386                "name": "GPL"
  6387              }
  6388            }
  6389          ],
  6390          "cpe": "cpe:2.3:a:debian-archive-keyring:debian-archive-keyring:2021.1.1:*:*:*:*:*:*:*",
  6391          "purl": "pkg:deb/debian/debian-archive-keyring@2021.1.1?arch=all\u0026distro=debian-11",
  6392          "swid": {
  6393            "attachment": {}
  6394          },
  6395          "pedigree": {},
  6396          "evidence": {},
  6397          "signature": {
  6398            "signature": {
  6399              "publicKey": {}
  6400            }
  6401          },
  6402          "modelCard": {
  6403            "modelParameters": {
  6404              "approach": {}
  6405            },
  6406            "quantitativeAnalysis": {
  6407              "graphics": {}
  6408            },
  6409            "considerations": {}
  6410          }
  6411        },
  6412        {
  6413          "type": "library",
  6414          "bom-ref": "pkg:deb/debian/debianutils@4.11.2?arch=amd64\u0026distro=debian-11\u0026package-id=4cd4f150dae8c295",
  6415          "supplier": {},
  6416          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
  6417          "name": "debianutils",
  6418          "version": "4.11.2",
  6419          "licenses": [
  6420            {
  6421              "license": {
  6422                "id": "GPL-2.0-only"
  6423              }
  6424            }
  6425          ],
  6426          "cpe": "cpe:2.3:a:debianutils:debianutils:4.11.2:*:*:*:*:*:*:*",
  6427          "purl": "pkg:deb/debian/debianutils@4.11.2?arch=amd64\u0026distro=debian-11",
  6428          "swid": {
  6429            "attachment": {}
  6430          },
  6431          "pedigree": {},
  6432          "evidence": {},
  6433          "signature": {
  6434            "signature": {
  6435              "publicKey": {}
  6436            }
  6437          },
  6438          "modelCard": {
  6439            "modelParameters": {
  6440              "approach": {}
  6441            },
  6442            "quantitativeAnalysis": {
  6443              "graphics": {}
  6444            },
  6445            "considerations": {}
  6446          }
  6447        },
  6448        {
  6449          "type": "library",
  6450          "bom-ref": "pkg:deb/debian/diffutils@1:3.7-5?arch=amd64\u0026distro=debian-11\u0026package-id=9133f9a320bf77e1",
  6451          "supplier": {},
  6452          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
  6453          "name": "diffutils",
  6454          "version": "1:3.7-5",
  6455          "licenses": [
  6456            {
  6457              "license": {
  6458                "name": "GFDL"
  6459              }
  6460            },
  6461            {
  6462              "license": {
  6463                "name": "GPL"
  6464              }
  6465            }
  6466          ],
  6467          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-5:*:*:*:*:*:*:*",
  6468          "purl": "pkg:deb/debian/diffutils@1:3.7-5?arch=amd64\u0026distro=debian-11",
  6469          "swid": {
  6470            "attachment": {}
  6471          },
  6472          "pedigree": {},
  6473          "evidence": {},
  6474          "signature": {
  6475            "signature": {
  6476              "publicKey": {}
  6477            }
  6478          },
  6479          "modelCard": {
  6480            "modelParameters": {
  6481              "approach": {}
  6482            },
  6483            "quantitativeAnalysis": {
  6484              "graphics": {}
  6485            },
  6486            "considerations": {}
  6487          }
  6488        },
  6489        {
  6490          "type": "library",
  6491          "bom-ref": "pkg:deb/debian/dirmngr@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=51dda820ce87a9d6",
  6492          "supplier": {},
  6493          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  6494          "name": "dirmngr",
  6495          "version": "2.2.27-2+deb11u2",
  6496          "licenses": [
  6497            {
  6498              "license": {
  6499                "id": "BSD-3-Clause"
  6500              }
  6501            },
  6502            {
  6503              "license": {
  6504                "id": "CC0-1.0"
  6505              }
  6506            },
  6507            {
  6508              "license": {
  6509                "name": "Expat"
  6510              }
  6511            },
  6512            {
  6513              "license": {
  6514                "id": "GPL-3.0-only"
  6515              }
  6516            },
  6517            {
  6518              "license": {
  6519                "id": "GPL-3.0-or-later"
  6520              }
  6521            },
  6522            {
  6523              "license": {
  6524                "id": "LGPL-2.1-only"
  6525              }
  6526            },
  6527            {
  6528              "license": {
  6529                "id": "LGPL-2.1-or-later"
  6530              }
  6531            },
  6532            {
  6533              "license": {
  6534                "id": "LGPL-3.0-only"
  6535              }
  6536            },
  6537            {
  6538              "license": {
  6539                "id": "LGPL-3.0-or-later"
  6540              }
  6541            },
  6542            {
  6543              "license": {
  6544                "name": "RFC-Reference"
  6545              }
  6546            },
  6547            {
  6548              "license": {
  6549                "name": "TinySCHEME"
  6550              }
  6551            },
  6552            {
  6553              "license": {
  6554                "name": "permissive"
  6555              }
  6556            }
  6557          ],
  6558          "cpe": "cpe:2.3:a:dirmngr:dirmngr:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  6559          "purl": "pkg:deb/debian/dirmngr@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
  6560          "swid": {
  6561            "attachment": {}
  6562          },
  6563          "pedigree": {},
  6564          "evidence": {},
  6565          "signature": {
  6566            "signature": {
  6567              "publicKey": {}
  6568            }
  6569          },
  6570          "modelCard": {
  6571            "modelParameters": {
  6572              "approach": {}
  6573            },
  6574            "quantitativeAnalysis": {
  6575              "graphics": {}
  6576            },
  6577            "considerations": {}
  6578          }
  6579        },
  6580        {
  6581          "type": "library",
  6582          "bom-ref": "pkg:deb/debian/dpkg@1.20.12?arch=amd64\u0026distro=debian-11\u0026package-id=3dbbad249b74a866",
  6583          "supplier": {},
  6584          "publisher": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e",
  6585          "name": "dpkg",
  6586          "version": "1.20.12",
  6587          "licenses": [
  6588            {
  6589              "license": {
  6590                "id": "BSD-2-Clause"
  6591              }
  6592            },
  6593            {
  6594              "license": {
  6595                "id": "GPL-2.0-only"
  6596              }
  6597            },
  6598            {
  6599              "license": {
  6600                "id": "GPL-2.0-or-later"
  6601              }
  6602            },
  6603            {
  6604              "license": {
  6605                "name": "public-domain-md5"
  6606              }
  6607            },
  6608            {
  6609              "license": {
  6610                "name": "public-domain-s-s-d"
  6611              }
  6612            }
  6613          ],
  6614          "cpe": "cpe:2.3:a:dpkg:dpkg:1.20.12:*:*:*:*:*:*:*",
  6615          "purl": "pkg:deb/debian/dpkg@1.20.12?arch=amd64\u0026distro=debian-11",
  6616          "swid": {
  6617            "attachment": {}
  6618          },
  6619          "pedigree": {},
  6620          "evidence": {},
  6621          "signature": {
  6622            "signature": {
  6623              "publicKey": {}
  6624            }
  6625          },
  6626          "modelCard": {
  6627            "modelParameters": {
  6628              "approach": {}
  6629            },
  6630            "quantitativeAnalysis": {
  6631              "graphics": {}
  6632            },
  6633            "considerations": {}
  6634          }
  6635        },
  6636        {
  6637          "type": "library",
  6638          "bom-ref": "pkg:deb/debian/e2fsprogs@1.46.2-2?arch=amd64\u0026distro=debian-11\u0026package-id=7c4baa682137e759",
  6639          "supplier": {},
  6640          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
  6641          "name": "e2fsprogs",
  6642          "version": "1.46.2-2",
  6643          "licenses": [
  6644            {
  6645              "license": {
  6646                "id": "GPL-2.0-only"
  6647              }
  6648            },
  6649            {
  6650              "license": {
  6651                "id": "LGPL-2.0-only"
  6652              }
  6653            }
  6654          ],
  6655          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.46.2-2:*:*:*:*:*:*:*",
  6656          "purl": "pkg:deb/debian/e2fsprogs@1.46.2-2?arch=amd64\u0026distro=debian-11",
  6657          "swid": {
  6658            "attachment": {}
  6659          },
  6660          "pedigree": {},
  6661          "evidence": {},
  6662          "signature": {
  6663            "signature": {
  6664              "publicKey": {}
  6665            }
  6666          },
  6667          "modelCard": {
  6668            "modelParameters": {
  6669              "approach": {}
  6670            },
  6671            "quantitativeAnalysis": {
  6672              "graphics": {}
  6673            },
  6674            "considerations": {}
  6675          }
  6676        },
  6677        {
  6678          "type": "library",
  6679          "bom-ref": "pkg:deb/debian/findutils@4.8.0-1?arch=amd64\u0026distro=debian-11\u0026package-id=b503e3d45616f33c",
  6680          "supplier": {},
  6681          "publisher": "Andreas Metzler \u003cametzler@debian.org\u003e",
  6682          "name": "findutils",
  6683          "version": "4.8.0-1",
  6684          "licenses": [
  6685            {
  6686              "license": {
  6687                "id": "GFDL-1.3-only"
  6688              }
  6689            },
  6690            {
  6691              "license": {
  6692                "id": "GPL-3.0-only"
  6693              }
  6694            }
  6695          ],
  6696          "cpe": "cpe:2.3:a:findutils:findutils:4.8.0-1:*:*:*:*:*:*:*",
  6697          "purl": "pkg:deb/debian/findutils@4.8.0-1?arch=amd64\u0026distro=debian-11",
  6698          "swid": {
  6699            "attachment": {}
  6700          },
  6701          "pedigree": {},
  6702          "evidence": {},
  6703          "signature": {
  6704            "signature": {
  6705              "publicKey": {}
  6706            }
  6707          },
  6708          "modelCard": {
  6709            "modelParameters": {
  6710              "approach": {}
  6711            },
  6712            "quantitativeAnalysis": {
  6713              "graphics": {}
  6714            },
  6715            "considerations": {}
  6716          }
  6717        },
  6718        {
  6719          "type": "library",
  6720          "bom-ref": "pkg:deb/debian/gcc-10-base@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=742204f033ae5a1e",
  6721          "supplier": {},
  6722          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
  6723          "name": "gcc-10-base",
  6724          "version": "10.2.1-6",
  6725          "licenses": [
  6726            {
  6727              "license": {
  6728                "name": "Artistic"
  6729              }
  6730            },
  6731            {
  6732              "license": {
  6733                "id": "GFDL-1.2-only"
  6734              }
  6735            },
  6736            {
  6737              "license": {
  6738                "name": "GPL"
  6739              }
  6740            },
  6741            {
  6742              "license": {
  6743                "id": "GPL-2.0-only"
  6744              }
  6745            },
  6746            {
  6747              "license": {
  6748                "id": "GPL-3.0-only"
  6749              }
  6750            },
  6751            {
  6752              "license": {
  6753                "name": "LGPL"
  6754              }
  6755            }
  6756          ],
  6757          "cpe": "cpe:2.3:a:gcc-10-base:gcc-10-base:10.2.1-6:*:*:*:*:*:*:*",
  6758          "purl": "pkg:deb/debian/gcc-10-base@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
  6759          "swid": {
  6760            "attachment": {}
  6761          },
  6762          "pedigree": {},
  6763          "evidence": {},
  6764          "signature": {
  6765            "signature": {
  6766              "publicKey": {}
  6767            }
  6768          },
  6769          "modelCard": {
  6770            "modelParameters": {
  6771              "approach": {}
  6772            },
  6773            "quantitativeAnalysis": {
  6774              "graphics": {}
  6775            },
  6776            "considerations": {}
  6777          }
  6778        },
  6779        {
  6780          "type": "library",
  6781          "bom-ref": "pkg:deb/debian/gcc-9-base@9.3.0-22?arch=amd64\u0026upstream=gcc-9\u0026distro=debian-11\u0026package-id=57c0768e353bbfc8",
  6782          "supplier": {},
  6783          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
  6784          "name": "gcc-9-base",
  6785          "version": "9.3.0-22",
  6786          "licenses": [
  6787            {
  6788              "license": {
  6789                "name": "Artistic"
  6790              }
  6791            },
  6792            {
  6793              "license": {
  6794                "id": "GFDL-1.2-only"
  6795              }
  6796            },
  6797            {
  6798              "license": {
  6799                "name": "GPL"
  6800              }
  6801            },
  6802            {
  6803              "license": {
  6804                "id": "GPL-2.0-only"
  6805              }
  6806            },
  6807            {
  6808              "license": {
  6809                "id": "GPL-3.0-only"
  6810              }
  6811            },
  6812            {
  6813              "license": {
  6814                "name": "LGPL"
  6815              }
  6816            },
  6817            {
  6818              "license": {
  6819                "id": "LGPL-2.1-or-later"
  6820              }
  6821            }
  6822          ],
  6823          "cpe": "cpe:2.3:a:gcc-9-base:gcc-9-base:9.3.0-22:*:*:*:*:*:*:*",
  6824          "purl": "pkg:deb/debian/gcc-9-base@9.3.0-22?arch=amd64\u0026upstream=gcc-9\u0026distro=debian-11",
  6825          "swid": {
  6826            "attachment": {}
  6827          },
  6828          "pedigree": {},
  6829          "evidence": {},
  6830          "signature": {
  6831            "signature": {
  6832              "publicKey": {}
  6833            }
  6834          },
  6835          "modelCard": {
  6836            "modelParameters": {
  6837              "approach": {}
  6838            },
  6839            "quantitativeAnalysis": {
  6840              "graphics": {}
  6841            },
  6842            "considerations": {}
  6843          }
  6844        },
  6845        {
  6846          "type": "library",
  6847          "bom-ref": "pkg:deb/debian/gnupg@2.2.27-2+deb11u2?arch=all\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=2fa645d733f4fb20",
  6848          "supplier": {},
  6849          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  6850          "name": "gnupg",
  6851          "version": "2.2.27-2+deb11u2",
  6852          "licenses": [
  6853            {
  6854              "license": {
  6855                "id": "BSD-3-Clause"
  6856              }
  6857            },
  6858            {
  6859              "license": {
  6860                "id": "CC0-1.0"
  6861              }
  6862            },
  6863            {
  6864              "license": {
  6865                "name": "Expat"
  6866              }
  6867            },
  6868            {
  6869              "license": {
  6870                "id": "GPL-3.0-only"
  6871              }
  6872            },
  6873            {
  6874              "license": {
  6875                "id": "GPL-3.0-or-later"
  6876              }
  6877            },
  6878            {
  6879              "license": {
  6880                "id": "LGPL-2.1-only"
  6881              }
  6882            },
  6883            {
  6884              "license": {
  6885                "id": "LGPL-2.1-or-later"
  6886              }
  6887            },
  6888            {
  6889              "license": {
  6890                "id": "LGPL-3.0-only"
  6891              }
  6892            },
  6893            {
  6894              "license": {
  6895                "id": "LGPL-3.0-or-later"
  6896              }
  6897            },
  6898            {
  6899              "license": {
  6900                "name": "RFC-Reference"
  6901              }
  6902            },
  6903            {
  6904              "license": {
  6905                "name": "TinySCHEME"
  6906              }
  6907            },
  6908            {
  6909              "license": {
  6910                "name": "permissive"
  6911              }
  6912            }
  6913          ],
  6914          "cpe": "cpe:2.3:a:gnupg:gnupg:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  6915          "purl": "pkg:deb/debian/gnupg@2.2.27-2+deb11u2?arch=all\u0026upstream=gnupg2\u0026distro=debian-11",
  6916          "swid": {
  6917            "attachment": {}
  6918          },
  6919          "pedigree": {},
  6920          "evidence": {},
  6921          "signature": {
  6922            "signature": {
  6923              "publicKey": {}
  6924            }
  6925          },
  6926          "modelCard": {
  6927            "modelParameters": {
  6928              "approach": {}
  6929            },
  6930            "quantitativeAnalysis": {
  6931              "graphics": {}
  6932            },
  6933            "considerations": {}
  6934          }
  6935        },
  6936        {
  6937          "type": "library",
  6938          "bom-ref": "pkg:deb/debian/gnupg-l10n@2.2.27-2+deb11u2?arch=all\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=1c8761869d3138a2",
  6939          "supplier": {},
  6940          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  6941          "name": "gnupg-l10n",
  6942          "version": "2.2.27-2+deb11u2",
  6943          "licenses": [
  6944            {
  6945              "license": {
  6946                "id": "BSD-3-Clause"
  6947              }
  6948            },
  6949            {
  6950              "license": {
  6951                "id": "CC0-1.0"
  6952              }
  6953            },
  6954            {
  6955              "license": {
  6956                "name": "Expat"
  6957              }
  6958            },
  6959            {
  6960              "license": {
  6961                "id": "GPL-3.0-only"
  6962              }
  6963            },
  6964            {
  6965              "license": {
  6966                "id": "GPL-3.0-or-later"
  6967              }
  6968            },
  6969            {
  6970              "license": {
  6971                "id": "LGPL-2.1-only"
  6972              }
  6973            },
  6974            {
  6975              "license": {
  6976                "id": "LGPL-2.1-or-later"
  6977              }
  6978            },
  6979            {
  6980              "license": {
  6981                "id": "LGPL-3.0-only"
  6982              }
  6983            },
  6984            {
  6985              "license": {
  6986                "id": "LGPL-3.0-or-later"
  6987              }
  6988            },
  6989            {
  6990              "license": {
  6991                "name": "RFC-Reference"
  6992              }
  6993            },
  6994            {
  6995              "license": {
  6996                "name": "TinySCHEME"
  6997              }
  6998            },
  6999            {
  7000              "license": {
  7001                "name": "permissive"
  7002              }
  7003            }
  7004          ],
  7005          "cpe": "cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  7006          "purl": "pkg:deb/debian/gnupg-l10n@2.2.27-2+deb11u2?arch=all\u0026upstream=gnupg2\u0026distro=debian-11",
  7007          "swid": {
  7008            "attachment": {}
  7009          },
  7010          "pedigree": {},
  7011          "evidence": {},
  7012          "signature": {
  7013            "signature": {
  7014              "publicKey": {}
  7015            }
  7016          },
  7017          "modelCard": {
  7018            "modelParameters": {
  7019              "approach": {}
  7020            },
  7021            "quantitativeAnalysis": {
  7022              "graphics": {}
  7023            },
  7024            "considerations": {}
  7025          }
  7026        },
  7027        {
  7028          "type": "library",
  7029          "bom-ref": "pkg:deb/debian/gnupg-utils@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=d594c552b6ca1112",
  7030          "supplier": {},
  7031          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  7032          "name": "gnupg-utils",
  7033          "version": "2.2.27-2+deb11u2",
  7034          "licenses": [
  7035            {
  7036              "license": {
  7037                "id": "BSD-3-Clause"
  7038              }
  7039            },
  7040            {
  7041              "license": {
  7042                "id": "CC0-1.0"
  7043              }
  7044            },
  7045            {
  7046              "license": {
  7047                "name": "Expat"
  7048              }
  7049            },
  7050            {
  7051              "license": {
  7052                "id": "GPL-3.0-only"
  7053              }
  7054            },
  7055            {
  7056              "license": {
  7057                "id": "GPL-3.0-or-later"
  7058              }
  7059            },
  7060            {
  7061              "license": {
  7062                "id": "LGPL-2.1-only"
  7063              }
  7064            },
  7065            {
  7066              "license": {
  7067                "id": "LGPL-2.1-or-later"
  7068              }
  7069            },
  7070            {
  7071              "license": {
  7072                "id": "LGPL-3.0-only"
  7073              }
  7074            },
  7075            {
  7076              "license": {
  7077                "id": "LGPL-3.0-or-later"
  7078              }
  7079            },
  7080            {
  7081              "license": {
  7082                "name": "RFC-Reference"
  7083              }
  7084            },
  7085            {
  7086              "license": {
  7087                "name": "TinySCHEME"
  7088              }
  7089            },
  7090            {
  7091              "license": {
  7092                "name": "permissive"
  7093              }
  7094            }
  7095          ],
  7096          "cpe": "cpe:2.3:a:gnupg-utils:gnupg-utils:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  7097          "purl": "pkg:deb/debian/gnupg-utils@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
  7098          "swid": {
  7099            "attachment": {}
  7100          },
  7101          "pedigree": {},
  7102          "evidence": {},
  7103          "signature": {
  7104            "signature": {
  7105              "publicKey": {}
  7106            }
  7107          },
  7108          "modelCard": {
  7109            "modelParameters": {
  7110              "approach": {}
  7111            },
  7112            "quantitativeAnalysis": {
  7113              "graphics": {}
  7114            },
  7115            "considerations": {}
  7116          }
  7117        },
  7118        {
  7119          "type": "library",
  7120          "bom-ref": "pkg:deb/debian/gpg@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=182fe2545483a689",
  7121          "supplier": {},
  7122          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  7123          "name": "gpg",
  7124          "version": "2.2.27-2+deb11u2",
  7125          "licenses": [
  7126            {
  7127              "license": {
  7128                "id": "BSD-3-Clause"
  7129              }
  7130            },
  7131            {
  7132              "license": {
  7133                "id": "CC0-1.0"
  7134              }
  7135            },
  7136            {
  7137              "license": {
  7138                "name": "Expat"
  7139              }
  7140            },
  7141            {
  7142              "license": {
  7143                "id": "GPL-3.0-only"
  7144              }
  7145            },
  7146            {
  7147              "license": {
  7148                "id": "GPL-3.0-or-later"
  7149              }
  7150            },
  7151            {
  7152              "license": {
  7153                "id": "LGPL-2.1-only"
  7154              }
  7155            },
  7156            {
  7157              "license": {
  7158                "id": "LGPL-2.1-or-later"
  7159              }
  7160            },
  7161            {
  7162              "license": {
  7163                "id": "LGPL-3.0-only"
  7164              }
  7165            },
  7166            {
  7167              "license": {
  7168                "id": "LGPL-3.0-or-later"
  7169              }
  7170            },
  7171            {
  7172              "license": {
  7173                "name": "RFC-Reference"
  7174              }
  7175            },
  7176            {
  7177              "license": {
  7178                "name": "TinySCHEME"
  7179              }
  7180            },
  7181            {
  7182              "license": {
  7183                "name": "permissive"
  7184              }
  7185            }
  7186          ],
  7187          "cpe": "cpe:2.3:a:gpg:gpg:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  7188          "purl": "pkg:deb/debian/gpg@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
  7189          "swid": {
  7190            "attachment": {}
  7191          },
  7192          "pedigree": {},
  7193          "evidence": {},
  7194          "signature": {
  7195            "signature": {
  7196              "publicKey": {}
  7197            }
  7198          },
  7199          "modelCard": {
  7200            "modelParameters": {
  7201              "approach": {}
  7202            },
  7203            "quantitativeAnalysis": {
  7204              "graphics": {}
  7205            },
  7206            "considerations": {}
  7207          }
  7208        },
  7209        {
  7210          "type": "library",
  7211          "bom-ref": "pkg:deb/debian/gpg-agent@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=af8333b079fd696",
  7212          "supplier": {},
  7213          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  7214          "name": "gpg-agent",
  7215          "version": "2.2.27-2+deb11u2",
  7216          "licenses": [
  7217            {
  7218              "license": {
  7219                "id": "BSD-3-Clause"
  7220              }
  7221            },
  7222            {
  7223              "license": {
  7224                "id": "CC0-1.0"
  7225              }
  7226            },
  7227            {
  7228              "license": {
  7229                "name": "Expat"
  7230              }
  7231            },
  7232            {
  7233              "license": {
  7234                "id": "GPL-3.0-only"
  7235              }
  7236            },
  7237            {
  7238              "license": {
  7239                "id": "GPL-3.0-or-later"
  7240              }
  7241            },
  7242            {
  7243              "license": {
  7244                "id": "LGPL-2.1-only"
  7245              }
  7246            },
  7247            {
  7248              "license": {
  7249                "id": "LGPL-2.1-or-later"
  7250              }
  7251            },
  7252            {
  7253              "license": {
  7254                "id": "LGPL-3.0-only"
  7255              }
  7256            },
  7257            {
  7258              "license": {
  7259                "id": "LGPL-3.0-or-later"
  7260              }
  7261            },
  7262            {
  7263              "license": {
  7264                "name": "RFC-Reference"
  7265              }
  7266            },
  7267            {
  7268              "license": {
  7269                "name": "TinySCHEME"
  7270              }
  7271            },
  7272            {
  7273              "license": {
  7274                "name": "permissive"
  7275              }
  7276            }
  7277          ],
  7278          "cpe": "cpe:2.3:a:gpg-agent:gpg-agent:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  7279          "purl": "pkg:deb/debian/gpg-agent@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
  7280          "swid": {
  7281            "attachment": {}
  7282          },
  7283          "pedigree": {},
  7284          "evidence": {},
  7285          "signature": {
  7286            "signature": {
  7287              "publicKey": {}
  7288            }
  7289          },
  7290          "modelCard": {
  7291            "modelParameters": {
  7292              "approach": {}
  7293            },
  7294            "quantitativeAnalysis": {
  7295              "graphics": {}
  7296            },
  7297            "considerations": {}
  7298          }
  7299        },
  7300        {
  7301          "type": "library",
  7302          "bom-ref": "pkg:deb/debian/gpg-wks-client@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=7e338b8ee49ad1b2",
  7303          "supplier": {},
  7304          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  7305          "name": "gpg-wks-client",
  7306          "version": "2.2.27-2+deb11u2",
  7307          "licenses": [
  7308            {
  7309              "license": {
  7310                "id": "BSD-3-Clause"
  7311              }
  7312            },
  7313            {
  7314              "license": {
  7315                "id": "CC0-1.0"
  7316              }
  7317            },
  7318            {
  7319              "license": {
  7320                "name": "Expat"
  7321              }
  7322            },
  7323            {
  7324              "license": {
  7325                "id": "GPL-3.0-only"
  7326              }
  7327            },
  7328            {
  7329              "license": {
  7330                "id": "GPL-3.0-or-later"
  7331              }
  7332            },
  7333            {
  7334              "license": {
  7335                "id": "LGPL-2.1-only"
  7336              }
  7337            },
  7338            {
  7339              "license": {
  7340                "id": "LGPL-2.1-or-later"
  7341              }
  7342            },
  7343            {
  7344              "license": {
  7345                "id": "LGPL-3.0-only"
  7346              }
  7347            },
  7348            {
  7349              "license": {
  7350                "id": "LGPL-3.0-or-later"
  7351              }
  7352            },
  7353            {
  7354              "license": {
  7355                "name": "RFC-Reference"
  7356              }
  7357            },
  7358            {
  7359              "license": {
  7360                "name": "TinySCHEME"
  7361              }
  7362            },
  7363            {
  7364              "license": {
  7365                "name": "permissive"
  7366              }
  7367            }
  7368          ],
  7369          "cpe": "cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  7370          "purl": "pkg:deb/debian/gpg-wks-client@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
  7371          "swid": {
  7372            "attachment": {}
  7373          },
  7374          "pedigree": {},
  7375          "evidence": {},
  7376          "signature": {
  7377            "signature": {
  7378              "publicKey": {}
  7379            }
  7380          },
  7381          "modelCard": {
  7382            "modelParameters": {
  7383              "approach": {}
  7384            },
  7385            "quantitativeAnalysis": {
  7386              "graphics": {}
  7387            },
  7388            "considerations": {}
  7389          }
  7390        },
  7391        {
  7392          "type": "library",
  7393          "bom-ref": "pkg:deb/debian/gpg-wks-server@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=d8d521443f75f35a",
  7394          "supplier": {},
  7395          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  7396          "name": "gpg-wks-server",
  7397          "version": "2.2.27-2+deb11u2",
  7398          "licenses": [
  7399            {
  7400              "license": {
  7401                "id": "BSD-3-Clause"
  7402              }
  7403            },
  7404            {
  7405              "license": {
  7406                "id": "CC0-1.0"
  7407              }
  7408            },
  7409            {
  7410              "license": {
  7411                "name": "Expat"
  7412              }
  7413            },
  7414            {
  7415              "license": {
  7416                "id": "GPL-3.0-only"
  7417              }
  7418            },
  7419            {
  7420              "license": {
  7421                "id": "GPL-3.0-or-later"
  7422              }
  7423            },
  7424            {
  7425              "license": {
  7426                "id": "LGPL-2.1-only"
  7427              }
  7428            },
  7429            {
  7430              "license": {
  7431                "id": "LGPL-2.1-or-later"
  7432              }
  7433            },
  7434            {
  7435              "license": {
  7436                "id": "LGPL-3.0-only"
  7437              }
  7438            },
  7439            {
  7440              "license": {
  7441                "id": "LGPL-3.0-or-later"
  7442              }
  7443            },
  7444            {
  7445              "license": {
  7446                "name": "RFC-Reference"
  7447              }
  7448            },
  7449            {
  7450              "license": {
  7451                "name": "TinySCHEME"
  7452              }
  7453            },
  7454            {
  7455              "license": {
  7456                "name": "permissive"
  7457              }
  7458            }
  7459          ],
  7460          "cpe": "cpe:2.3:a:gpg-wks-server:gpg-wks-server:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  7461          "purl": "pkg:deb/debian/gpg-wks-server@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
  7462          "swid": {
  7463            "attachment": {}
  7464          },
  7465          "pedigree": {},
  7466          "evidence": {},
  7467          "signature": {
  7468            "signature": {
  7469              "publicKey": {}
  7470            }
  7471          },
  7472          "modelCard": {
  7473            "modelParameters": {
  7474              "approach": {}
  7475            },
  7476            "quantitativeAnalysis": {
  7477              "graphics": {}
  7478            },
  7479            "considerations": {}
  7480          }
  7481        },
  7482        {
  7483          "type": "library",
  7484          "bom-ref": "pkg:deb/debian/gpgconf@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=eb729dbb773068e5",
  7485          "supplier": {},
  7486          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  7487          "name": "gpgconf",
  7488          "version": "2.2.27-2+deb11u2",
  7489          "licenses": [
  7490            {
  7491              "license": {
  7492                "id": "BSD-3-Clause"
  7493              }
  7494            },
  7495            {
  7496              "license": {
  7497                "id": "CC0-1.0"
  7498              }
  7499            },
  7500            {
  7501              "license": {
  7502                "name": "Expat"
  7503              }
  7504            },
  7505            {
  7506              "license": {
  7507                "id": "GPL-3.0-only"
  7508              }
  7509            },
  7510            {
  7511              "license": {
  7512                "id": "GPL-3.0-or-later"
  7513              }
  7514            },
  7515            {
  7516              "license": {
  7517                "id": "LGPL-2.1-only"
  7518              }
  7519            },
  7520            {
  7521              "license": {
  7522                "id": "LGPL-2.1-or-later"
  7523              }
  7524            },
  7525            {
  7526              "license": {
  7527                "id": "LGPL-3.0-only"
  7528              }
  7529            },
  7530            {
  7531              "license": {
  7532                "id": "LGPL-3.0-or-later"
  7533              }
  7534            },
  7535            {
  7536              "license": {
  7537                "name": "RFC-Reference"
  7538              }
  7539            },
  7540            {
  7541              "license": {
  7542                "name": "TinySCHEME"
  7543              }
  7544            },
  7545            {
  7546              "license": {
  7547                "name": "permissive"
  7548              }
  7549            }
  7550          ],
  7551          "cpe": "cpe:2.3:a:gpgconf:gpgconf:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  7552          "purl": "pkg:deb/debian/gpgconf@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
  7553          "swid": {
  7554            "attachment": {}
  7555          },
  7556          "pedigree": {},
  7557          "evidence": {},
  7558          "signature": {
  7559            "signature": {
  7560              "publicKey": {}
  7561            }
  7562          },
  7563          "modelCard": {
  7564            "modelParameters": {
  7565              "approach": {}
  7566            },
  7567            "quantitativeAnalysis": {
  7568              "graphics": {}
  7569            },
  7570            "considerations": {}
  7571          }
  7572        },
  7573        {
  7574          "type": "library",
  7575          "bom-ref": "pkg:deb/debian/gpgsm@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=1ff09262bf4b65d9",
  7576          "supplier": {},
  7577          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  7578          "name": "gpgsm",
  7579          "version": "2.2.27-2+deb11u2",
  7580          "licenses": [
  7581            {
  7582              "license": {
  7583                "id": "BSD-3-Clause"
  7584              }
  7585            },
  7586            {
  7587              "license": {
  7588                "id": "CC0-1.0"
  7589              }
  7590            },
  7591            {
  7592              "license": {
  7593                "name": "Expat"
  7594              }
  7595            },
  7596            {
  7597              "license": {
  7598                "id": "GPL-3.0-only"
  7599              }
  7600            },
  7601            {
  7602              "license": {
  7603                "id": "GPL-3.0-or-later"
  7604              }
  7605            },
  7606            {
  7607              "license": {
  7608                "id": "LGPL-2.1-only"
  7609              }
  7610            },
  7611            {
  7612              "license": {
  7613                "id": "LGPL-2.1-or-later"
  7614              }
  7615            },
  7616            {
  7617              "license": {
  7618                "id": "LGPL-3.0-only"
  7619              }
  7620            },
  7621            {
  7622              "license": {
  7623                "id": "LGPL-3.0-or-later"
  7624              }
  7625            },
  7626            {
  7627              "license": {
  7628                "name": "RFC-Reference"
  7629              }
  7630            },
  7631            {
  7632              "license": {
  7633                "name": "TinySCHEME"
  7634              }
  7635            },
  7636            {
  7637              "license": {
  7638                "name": "permissive"
  7639              }
  7640            }
  7641          ],
  7642          "cpe": "cpe:2.3:a:gpgsm:gpgsm:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  7643          "purl": "pkg:deb/debian/gpgsm@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
  7644          "swid": {
  7645            "attachment": {}
  7646          },
  7647          "pedigree": {},
  7648          "evidence": {},
  7649          "signature": {
  7650            "signature": {
  7651              "publicKey": {}
  7652            }
  7653          },
  7654          "modelCard": {
  7655            "modelParameters": {
  7656              "approach": {}
  7657            },
  7658            "quantitativeAnalysis": {
  7659              "graphics": {}
  7660            },
  7661            "considerations": {}
  7662          }
  7663        },
  7664        {
  7665          "type": "library",
  7666          "bom-ref": "pkg:deb/debian/gpgv@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=b6346590c45ba7ab",
  7667          "supplier": {},
  7668          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  7669          "name": "gpgv",
  7670          "version": "2.2.27-2+deb11u2",
  7671          "licenses": [
  7672            {
  7673              "license": {
  7674                "id": "BSD-3-Clause"
  7675              }
  7676            },
  7677            {
  7678              "license": {
  7679                "id": "CC0-1.0"
  7680              }
  7681            },
  7682            {
  7683              "license": {
  7684                "name": "Expat"
  7685              }
  7686            },
  7687            {
  7688              "license": {
  7689                "id": "GPL-3.0-only"
  7690              }
  7691            },
  7692            {
  7693              "license": {
  7694                "id": "GPL-3.0-or-later"
  7695              }
  7696            },
  7697            {
  7698              "license": {
  7699                "id": "LGPL-2.1-only"
  7700              }
  7701            },
  7702            {
  7703              "license": {
  7704                "id": "LGPL-2.1-or-later"
  7705              }
  7706            },
  7707            {
  7708              "license": {
  7709                "id": "LGPL-3.0-only"
  7710              }
  7711            },
  7712            {
  7713              "license": {
  7714                "id": "LGPL-3.0-or-later"
  7715              }
  7716            },
  7717            {
  7718              "license": {
  7719                "name": "RFC-Reference"
  7720              }
  7721            },
  7722            {
  7723              "license": {
  7724                "name": "TinySCHEME"
  7725              }
  7726            },
  7727            {
  7728              "license": {
  7729                "name": "permissive"
  7730              }
  7731            }
  7732          ],
  7733          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
  7734          "purl": "pkg:deb/debian/gpgv@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
  7735          "swid": {
  7736            "attachment": {}
  7737          },
  7738          "pedigree": {},
  7739          "evidence": {},
  7740          "signature": {
  7741            "signature": {
  7742              "publicKey": {}
  7743            }
  7744          },
  7745          "modelCard": {
  7746            "modelParameters": {
  7747              "approach": {}
  7748            },
  7749            "quantitativeAnalysis": {
  7750              "graphics": {}
  7751            },
  7752            "considerations": {}
  7753          }
  7754        },
  7755        {
  7756          "type": "library",
  7757          "bom-ref": "pkg:deb/debian/grep@3.6-1?arch=amd64\u0026distro=debian-11\u0026package-id=9ed140c6f7959d",
  7758          "supplier": {},
  7759          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
  7760          "name": "grep",
  7761          "version": "3.6-1",
  7762          "licenses": [
  7763            {
  7764              "license": {
  7765                "id": "GPL-3.0-only"
  7766              }
  7767            },
  7768            {
  7769              "license": {
  7770                "id": "GPL-3.0-or-later"
  7771              }
  7772            }
  7773          ],
  7774          "cpe": "cpe:2.3:a:grep:grep:3.6-1:*:*:*:*:*:*:*",
  7775          "purl": "pkg:deb/debian/grep@3.6-1?arch=amd64\u0026distro=debian-11",
  7776          "swid": {
  7777            "attachment": {}
  7778          },
  7779          "pedigree": {},
  7780          "evidence": {},
  7781          "signature": {
  7782            "signature": {
  7783              "publicKey": {}
  7784            }
  7785          },
  7786          "modelCard": {
  7787            "modelParameters": {
  7788              "approach": {}
  7789            },
  7790            "quantitativeAnalysis": {
  7791              "graphics": {}
  7792            },
  7793            "considerations": {}
  7794          }
  7795        },
  7796        {
  7797          "type": "library",
  7798          "bom-ref": "pkg:deb/debian/gzip@1.10-4+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=ade955af6710751d",
  7799          "supplier": {},
  7800          "publisher": "Milan Kupcevic \u003cmilan@debian.org\u003e",
  7801          "name": "gzip",
  7802          "version": "1.10-4+deb11u1",
  7803          "licenses": [
  7804            {
  7805              "license": {
  7806                "name": "FSF-manpages"
  7807              }
  7808            },
  7809            {
  7810              "license": {
  7811                "name": "GFDL-1.3+-no-invariant"
  7812              }
  7813            },
  7814            {
  7815              "license": {
  7816                "name": "GFDL-3"
  7817              }
  7818            },
  7819            {
  7820              "license": {
  7821                "id": "GPL-3.0-only"
  7822              }
  7823            },
  7824            {
  7825              "license": {
  7826                "id": "GPL-3.0-or-later"
  7827              }
  7828            }
  7829          ],
  7830          "cpe": "cpe:2.3:a:gzip:gzip:1.10-4\\+deb11u1:*:*:*:*:*:*:*",
  7831          "purl": "pkg:deb/debian/gzip@1.10-4+deb11u1?arch=amd64\u0026distro=debian-11",
  7832          "swid": {
  7833            "attachment": {}
  7834          },
  7835          "pedigree": {},
  7836          "evidence": {},
  7837          "signature": {
  7838            "signature": {
  7839              "publicKey": {}
  7840            }
  7841          },
  7842          "modelCard": {
  7843            "modelParameters": {
  7844              "approach": {}
  7845            },
  7846            "quantitativeAnalysis": {
  7847              "graphics": {}
  7848            },
  7849            "considerations": {}
  7850          }
  7851        },
  7852        {
  7853          "type": "library",
  7854          "bom-ref": "pkg:deb/debian/hostname@3.23?arch=amd64\u0026distro=debian-11\u0026package-id=fec906d1ab1d9712",
  7855          "supplier": {},
  7856          "publisher": "Michael Meskes \u003cmeskes@debian.org\u003e",
  7857          "name": "hostname",
  7858          "version": "3.23",
  7859          "licenses": [
  7860            {
  7861              "license": {
  7862                "id": "GPL-2.0-only"
  7863              }
  7864            }
  7865          ],
  7866          "cpe": "cpe:2.3:a:hostname:hostname:3.23:*:*:*:*:*:*:*",
  7867          "purl": "pkg:deb/debian/hostname@3.23?arch=amd64\u0026distro=debian-11",
  7868          "swid": {
  7869            "attachment": {}
  7870          },
  7871          "pedigree": {},
  7872          "evidence": {},
  7873          "signature": {
  7874            "signature": {
  7875              "publicKey": {}
  7876            }
  7877          },
  7878          "modelCard": {
  7879            "modelParameters": {
  7880              "approach": {}
  7881            },
  7882            "quantitativeAnalysis": {
  7883              "graphics": {}
  7884            },
  7885            "considerations": {}
  7886          }
  7887        },
  7888        {
  7889          "type": "library",
  7890          "bom-ref": "pkg:deb/debian/influxdb@1.8.10-1?arch=amd64\u0026distro=debian-11\u0026package-id=668a12601e14b1ae",
  7891          "supplier": {},
  7892          "publisher": "support@influxdb.com",
  7893          "name": "influxdb",
  7894          "version": "1.8.10-1",
  7895          "cpe": "cpe:2.3:a:influxdb:influxdb:1.8.10-1:*:*:*:*:*:*:*",
  7896          "purl": "pkg:deb/debian/influxdb@1.8.10-1?arch=amd64\u0026distro=debian-11",
  7897          "swid": {
  7898            "attachment": {}
  7899          },
  7900          "pedigree": {},
  7901          "evidence": {},
  7902          "signature": {
  7903            "signature": {
  7904              "publicKey": {}
  7905            }
  7906          },
  7907          "modelCard": {
  7908            "modelParameters": {
  7909              "approach": {}
  7910            },
  7911            "quantitativeAnalysis": {
  7912              "graphics": {}
  7913            },
  7914            "considerations": {}
  7915          }
  7916        },
  7917        {
  7918          "type": "library",
  7919          "bom-ref": "pkg:deb/debian/init-system-helpers@1.60?arch=all\u0026distro=debian-11\u0026package-id=9853db6c4e48777f",
  7920          "supplier": {},
  7921          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
  7922          "name": "init-system-helpers",
  7923          "version": "1.60",
  7924          "licenses": [
  7925            {
  7926              "license": {
  7927                "id": "BSD-3-Clause"
  7928              }
  7929            },
  7930            {
  7931              "license": {
  7932                "id": "GPL-2.0-only"
  7933              }
  7934            },
  7935            {
  7936              "license": {
  7937                "id": "GPL-2.0-or-later"
  7938              }
  7939            }
  7940          ],
  7941          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.60:*:*:*:*:*:*:*",
  7942          "purl": "pkg:deb/debian/init-system-helpers@1.60?arch=all\u0026distro=debian-11",
  7943          "swid": {
  7944            "attachment": {}
  7945          },
  7946          "pedigree": {},
  7947          "evidence": {},
  7948          "signature": {
  7949            "signature": {
  7950              "publicKey": {}
  7951            }
  7952          },
  7953          "modelCard": {
  7954            "modelParameters": {
  7955              "approach": {}
  7956            },
  7957            "quantitativeAnalysis": {
  7958              "graphics": {}
  7959            },
  7960            "considerations": {}
  7961          }
  7962        },
  7963        {
  7964          "type": "library",
  7965          "bom-ref": "pkg:deb/debian/libacl1@2.2.53-10?arch=amd64\u0026upstream=acl\u0026distro=debian-11\u0026package-id=e26fd10cf6ff246",
  7966          "supplier": {},
  7967          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
  7968          "name": "libacl1",
  7969          "version": "2.2.53-10",
  7970          "licenses": [
  7971            {
  7972              "license": {
  7973                "id": "GPL-2.0-only"
  7974              }
  7975            },
  7976            {
  7977              "license": {
  7978                "id": "GPL-2.0-or-later"
  7979              }
  7980            },
  7981            {
  7982              "license": {
  7983                "id": "LGPL-2.0-or-later"
  7984              }
  7985            },
  7986            {
  7987              "license": {
  7988                "id": "LGPL-2.1-only"
  7989              }
  7990            }
  7991          ],
  7992          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-10:*:*:*:*:*:*:*",
  7993          "purl": "pkg:deb/debian/libacl1@2.2.53-10?arch=amd64\u0026upstream=acl\u0026distro=debian-11",
  7994          "swid": {
  7995            "attachment": {}
  7996          },
  7997          "pedigree": {},
  7998          "evidence": {},
  7999          "signature": {
  8000            "signature": {
  8001              "publicKey": {}
  8002            }
  8003          },
  8004          "modelCard": {
  8005            "modelParameters": {
  8006              "approach": {}
  8007            },
  8008            "quantitativeAnalysis": {
  8009              "graphics": {}
  8010            },
  8011            "considerations": {}
  8012          }
  8013        },
  8014        {
  8015          "type": "library",
  8016          "bom-ref": "pkg:deb/debian/libapt-pkg6.0@2.2.4?arch=amd64\u0026upstream=apt\u0026distro=debian-11\u0026package-id=da442f0998cccf2b",
  8017          "supplier": {},
  8018          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
  8019          "name": "libapt-pkg6.0",
  8020          "version": "2.2.4",
  8021          "licenses": [
  8022            {
  8023              "license": {
  8024                "id": "GPL-2.0-only"
  8025              }
  8026            },
  8027            {
  8028              "license": {
  8029                "name": "GPLv2+"
  8030              }
  8031            }
  8032          ],
  8033          "cpe": "cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.2.4:*:*:*:*:*:*:*",
  8034          "purl": "pkg:deb/debian/libapt-pkg6.0@2.2.4?arch=amd64\u0026upstream=apt\u0026distro=debian-11",
  8035          "swid": {
  8036            "attachment": {}
  8037          },
  8038          "pedigree": {},
  8039          "evidence": {},
  8040          "signature": {
  8041            "signature": {
  8042              "publicKey": {}
  8043            }
  8044          },
  8045          "modelCard": {
  8046            "modelParameters": {
  8047              "approach": {}
  8048            },
  8049            "quantitativeAnalysis": {
  8050              "graphics": {}
  8051            },
  8052            "considerations": {}
  8053          }
  8054        },
  8055        {
  8056          "type": "library",
  8057          "bom-ref": "pkg:deb/debian/libassuan0@2.5.3-7.1?arch=amd64\u0026upstream=libassuan\u0026distro=debian-11\u0026package-id=6de2e25825b06a93",
  8058          "supplier": {},
  8059          "publisher": "Debian GnuPG-Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  8060          "name": "libassuan0",
  8061          "version": "2.5.3-7.1",
  8062          "licenses": [
  8063            {
  8064              "license": {
  8065                "name": "GAP"
  8066              }
  8067            },
  8068            {
  8069              "license": {
  8070                "name": "GAP~FSF"
  8071              }
  8072            },
  8073            {
  8074              "license": {
  8075                "id": "GPL-2.0-only"
  8076              }
  8077            },
  8078            {
  8079              "license": {
  8080                "id": "GPL-2.0-or-later"
  8081              }
  8082            },
  8083            {
  8084              "license": {
  8085                "id": "GPL-3.0-only"
  8086              }
  8087            },
  8088            {
  8089              "license": {
  8090                "id": "GPL-3.0-or-later"
  8091              }
  8092            },
  8093            {
  8094              "license": {
  8095                "id": "LGPL-2.1-only"
  8096              }
  8097            },
  8098            {
  8099              "license": {
  8100                "id": "LGPL-2.1-or-later"
  8101              }
  8102            },
  8103            {
  8104              "license": {
  8105                "id": "LGPL-3.0-only"
  8106              }
  8107            },
  8108            {
  8109              "license": {
  8110                "id": "LGPL-3.0-or-later"
  8111              }
  8112            }
  8113          ],
  8114          "cpe": "cpe:2.3:a:libassuan0:libassuan0:2.5.3-7.1:*:*:*:*:*:*:*",
  8115          "purl": "pkg:deb/debian/libassuan0@2.5.3-7.1?arch=amd64\u0026upstream=libassuan\u0026distro=debian-11",
  8116          "swid": {
  8117            "attachment": {}
  8118          },
  8119          "pedigree": {},
  8120          "evidence": {},
  8121          "signature": {
  8122            "signature": {
  8123              "publicKey": {}
  8124            }
  8125          },
  8126          "modelCard": {
  8127            "modelParameters": {
  8128              "approach": {}
  8129            },
  8130            "quantitativeAnalysis": {
  8131              "graphics": {}
  8132            },
  8133            "considerations": {}
  8134          }
  8135        },
  8136        {
  8137          "type": "library",
  8138          "bom-ref": "pkg:deb/debian/libattr1@1:2.4.48-6?arch=amd64\u0026upstream=attr\u0026distro=debian-11\u0026package-id=254a97dd16e20391",
  8139          "supplier": {},
  8140          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
  8141          "name": "libattr1",
  8142          "version": "1:2.4.48-6",
  8143          "licenses": [
  8144            {
  8145              "license": {
  8146                "id": "GPL-2.0-only"
  8147              }
  8148            },
  8149            {
  8150              "license": {
  8151                "id": "GPL-2.0-or-later"
  8152              }
  8153            },
  8154            {
  8155              "license": {
  8156                "id": "LGPL-2.0-or-later"
  8157              }
  8158            },
  8159            {
  8160              "license": {
  8161                "id": "LGPL-2.1-only"
  8162              }
  8163            }
  8164          ],
  8165          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-6:*:*:*:*:*:*:*",
  8166          "purl": "pkg:deb/debian/libattr1@1:2.4.48-6?arch=amd64\u0026upstream=attr\u0026distro=debian-11",
  8167          "swid": {
  8168            "attachment": {}
  8169          },
  8170          "pedigree": {},
  8171          "evidence": {},
  8172          "signature": {
  8173            "signature": {
  8174              "publicKey": {}
  8175            }
  8176          },
  8177          "modelCard": {
  8178            "modelParameters": {
  8179              "approach": {}
  8180            },
  8181            "quantitativeAnalysis": {
  8182              "graphics": {}
  8183            },
  8184            "considerations": {}
  8185          }
  8186        },
  8187        {
  8188          "type": "library",
  8189          "bom-ref": "pkg:deb/debian/libaudit-common@1:3.0-2?arch=all\u0026upstream=audit\u0026distro=debian-11\u0026package-id=e666dc18886f28ff",
  8190          "supplier": {},
  8191          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
  8192          "name": "libaudit-common",
  8193          "version": "1:3.0-2",
  8194          "licenses": [
  8195            {
  8196              "license": {
  8197                "id": "GPL-1.0-only"
  8198              }
  8199            },
  8200            {
  8201              "license": {
  8202                "id": "GPL-2.0-only"
  8203              }
  8204            },
  8205            {
  8206              "license": {
  8207                "id": "LGPL-2.1-only"
  8208              }
  8209            }
  8210          ],
  8211          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:3.0-2:*:*:*:*:*:*:*",
  8212          "purl": "pkg:deb/debian/libaudit-common@1:3.0-2?arch=all\u0026upstream=audit\u0026distro=debian-11",
  8213          "swid": {
  8214            "attachment": {}
  8215          },
  8216          "pedigree": {},
  8217          "evidence": {},
  8218          "signature": {
  8219            "signature": {
  8220              "publicKey": {}
  8221            }
  8222          },
  8223          "modelCard": {
  8224            "modelParameters": {
  8225              "approach": {}
  8226            },
  8227            "quantitativeAnalysis": {
  8228              "graphics": {}
  8229            },
  8230            "considerations": {}
  8231          }
  8232        },
  8233        {
  8234          "type": "library",
  8235          "bom-ref": "pkg:deb/debian/libaudit1@1:3.0-2?arch=amd64\u0026upstream=audit\u0026distro=debian-11\u0026package-id=ae77fe6c43b7188d",
  8236          "supplier": {},
  8237          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
  8238          "name": "libaudit1",
  8239          "version": "1:3.0-2",
  8240          "licenses": [
  8241            {
  8242              "license": {
  8243                "id": "GPL-1.0-only"
  8244              }
  8245            },
  8246            {
  8247              "license": {
  8248                "id": "GPL-2.0-only"
  8249              }
  8250            },
  8251            {
  8252              "license": {
  8253                "id": "LGPL-2.1-only"
  8254              }
  8255            }
  8256          ],
  8257          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:3.0-2:*:*:*:*:*:*:*",
  8258          "purl": "pkg:deb/debian/libaudit1@1:3.0-2?arch=amd64\u0026upstream=audit\u0026distro=debian-11",
  8259          "swid": {
  8260            "attachment": {}
  8261          },
  8262          "pedigree": {},
  8263          "evidence": {},
  8264          "signature": {
  8265            "signature": {
  8266              "publicKey": {}
  8267            }
  8268          },
  8269          "modelCard": {
  8270            "modelParameters": {
  8271              "approach": {}
  8272            },
  8273            "quantitativeAnalysis": {
  8274              "graphics": {}
  8275            },
  8276            "considerations": {}
  8277          }
  8278        },
  8279        {
  8280          "type": "library",
  8281          "bom-ref": "pkg:deb/debian/libblkid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=f235c9c5cb7b4190",
  8282          "supplier": {},
  8283          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
  8284          "name": "libblkid1",
  8285          "version": "2.36.1-8+deb11u1",
  8286          "licenses": [
  8287            {
  8288              "license": {
  8289                "id": "BSD-2-Clause"
  8290              }
  8291            },
  8292            {
  8293              "license": {
  8294                "id": "BSD-3-Clause"
  8295              }
  8296            },
  8297            {
  8298              "license": {
  8299                "id": "BSD-4-Clause"
  8300              }
  8301            },
  8302            {
  8303              "license": {
  8304                "id": "GPL-2.0-only"
  8305              }
  8306            },
  8307            {
  8308              "license": {
  8309                "id": "GPL-2.0-or-later"
  8310              }
  8311            },
  8312            {
  8313              "license": {
  8314                "id": "GPL-3.0-only"
  8315              }
  8316            },
  8317            {
  8318              "license": {
  8319                "id": "GPL-3.0-or-later"
  8320              }
  8321            },
  8322            {
  8323              "license": {
  8324                "name": "LGPL"
  8325              }
  8326            },
  8327            {
  8328              "license": {
  8329                "id": "LGPL-2.0-only"
  8330              }
  8331            },
  8332            {
  8333              "license": {
  8334                "id": "LGPL-2.0-or-later"
  8335              }
  8336            },
  8337            {
  8338              "license": {
  8339                "id": "LGPL-2.1-only"
  8340              }
  8341            },
  8342            {
  8343              "license": {
  8344                "id": "LGPL-2.1-or-later"
  8345              }
  8346            },
  8347            {
  8348              "license": {
  8349                "id": "LGPL-3.0-only"
  8350              }
  8351            },
  8352            {
  8353              "license": {
  8354                "id": "LGPL-3.0-or-later"
  8355              }
  8356            },
  8357            {
  8358              "license": {
  8359                "id": "MIT"
  8360              }
  8361            },
  8362            {
  8363              "license": {
  8364                "name": "public-domain"
  8365              }
  8366            }
  8367          ],
  8368          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
  8369          "purl": "pkg:deb/debian/libblkid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
  8370          "swid": {
  8371            "attachment": {}
  8372          },
  8373          "pedigree": {},
  8374          "evidence": {},
  8375          "signature": {
  8376            "signature": {
  8377              "publicKey": {}
  8378            }
  8379          },
  8380          "modelCard": {
  8381            "modelParameters": {
  8382              "approach": {}
  8383            },
  8384            "quantitativeAnalysis": {
  8385              "graphics": {}
  8386            },
  8387            "considerations": {}
  8388          }
  8389        },
  8390        {
  8391          "type": "library",
  8392          "bom-ref": "pkg:deb/debian/libbrotli1@1.0.9-2+b2?arch=amd64\u0026upstream=brotli%401.0.9-2\u0026distro=debian-11\u0026package-id=56558463e048d713",
  8393          "supplier": {},
  8394          "publisher": "Tomasz Buchert \u003ctomasz@debian.org\u003e",
  8395          "name": "libbrotli1",
  8396          "version": "1.0.9-2+b2",
  8397          "licenses": [
  8398            {
  8399              "license": {
  8400                "id": "MIT"
  8401              }
  8402            }
  8403          ],
  8404          "cpe": "cpe:2.3:a:libbrotli1:libbrotli1:1.0.9-2\\+b2:*:*:*:*:*:*:*",
  8405          "purl": "pkg:deb/debian/libbrotli1@1.0.9-2+b2?arch=amd64\u0026upstream=brotli%401.0.9-2\u0026distro=debian-11",
  8406          "swid": {
  8407            "attachment": {}
  8408          },
  8409          "pedigree": {},
  8410          "evidence": {},
  8411          "signature": {
  8412            "signature": {
  8413              "publicKey": {}
  8414            }
  8415          },
  8416          "modelCard": {
  8417            "modelParameters": {
  8418              "approach": {}
  8419            },
  8420            "quantitativeAnalysis": {
  8421              "graphics": {}
  8422            },
  8423            "considerations": {}
  8424          }
  8425        },
  8426        {
  8427          "type": "library",
  8428          "bom-ref": "pkg:deb/debian/libbz2-1.0@1.0.8-4?arch=amd64\u0026upstream=bzip2\u0026distro=debian-11\u0026package-id=120fe415369d1784",
  8429          "supplier": {},
  8430          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
  8431          "name": "libbz2-1.0",
  8432          "version": "1.0.8-4",
  8433          "licenses": [
  8434            {
  8435              "license": {
  8436                "name": "BSD-variant"
  8437              }
  8438            },
  8439            {
  8440              "license": {
  8441                "id": "GPL-2.0-only"
  8442              }
  8443            }
  8444          ],
  8445          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-4:*:*:*:*:*:*:*",
  8446          "purl": "pkg:deb/debian/libbz2-1.0@1.0.8-4?arch=amd64\u0026upstream=bzip2\u0026distro=debian-11",
  8447          "swid": {
  8448            "attachment": {}
  8449          },
  8450          "pedigree": {},
  8451          "evidence": {},
  8452          "signature": {
  8453            "signature": {
  8454              "publicKey": {}
  8455            }
  8456          },
  8457          "modelCard": {
  8458            "modelParameters": {
  8459              "approach": {}
  8460            },
  8461            "quantitativeAnalysis": {
  8462              "graphics": {}
  8463            },
  8464            "considerations": {}
  8465          }
  8466        },
  8467        {
  8468          "type": "library",
  8469          "bom-ref": "pkg:deb/debian/libc-bin@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=228ff11572a24b74",
  8470          "supplier": {},
  8471          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
  8472          "name": "libc-bin",
  8473          "version": "2.31-13+deb11u5",
  8474          "licenses": [
  8475            {
  8476              "license": {
  8477                "id": "GPL-2.0-only"
  8478              }
  8479            },
  8480            {
  8481              "license": {
  8482                "id": "LGPL-2.1-only"
  8483              }
  8484            }
  8485          ],
  8486          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
  8487          "purl": "pkg:deb/debian/libc-bin@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
  8488          "swid": {
  8489            "attachment": {}
  8490          },
  8491          "pedigree": {},
  8492          "evidence": {},
  8493          "signature": {
  8494            "signature": {
  8495              "publicKey": {}
  8496            }
  8497          },
  8498          "modelCard": {
  8499            "modelParameters": {
  8500              "approach": {}
  8501            },
  8502            "quantitativeAnalysis": {
  8503              "graphics": {}
  8504            },
  8505            "considerations": {}
  8506          }
  8507        },
  8508        {
  8509          "type": "library",
  8510          "bom-ref": "pkg:deb/debian/libc6@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=abe2c3f30be707e3",
  8511          "supplier": {},
  8512          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
  8513          "name": "libc6",
  8514          "version": "2.31-13+deb11u5",
  8515          "licenses": [
  8516            {
  8517              "license": {
  8518                "id": "GPL-2.0-only"
  8519              }
  8520            },
  8521            {
  8522              "license": {
  8523                "id": "LGPL-2.1-only"
  8524              }
  8525            }
  8526          ],
  8527          "cpe": "cpe:2.3:a:libc6:libc6:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
  8528          "purl": "pkg:deb/debian/libc6@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
  8529          "swid": {
  8530            "attachment": {}
  8531          },
  8532          "pedigree": {},
  8533          "evidence": {},
  8534          "signature": {
  8535            "signature": {
  8536              "publicKey": {}
  8537            }
  8538          },
  8539          "modelCard": {
  8540            "modelParameters": {
  8541              "approach": {}
  8542            },
  8543            "quantitativeAnalysis": {
  8544              "graphics": {}
  8545            },
  8546            "considerations": {}
  8547          }
  8548        },
  8549        {
  8550          "type": "library",
  8551          "bom-ref": "pkg:deb/debian/libcap-ng0@0.7.9-2.2+b1?arch=amd64\u0026upstream=libcap-ng%400.7.9-2.2\u0026distro=debian-11\u0026package-id=77d3f745010c245",
  8552          "supplier": {},
  8553          "publisher": "Pierre Chifflier \u003cpollux@debian.org\u003e",
  8554          "name": "libcap-ng0",
  8555          "version": "0.7.9-2.2+b1",
  8556          "licenses": [
  8557            {
  8558              "license": {
  8559                "id": "GPL-2.0-only"
  8560              }
  8561            },
  8562            {
  8563              "license": {
  8564                "id": "GPL-3.0-only"
  8565              }
  8566            },
  8567            {
  8568              "license": {
  8569                "id": "LGPL-2.1-only"
  8570              }
  8571            }
  8572          ],
  8573          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2.2\\+b1:*:*:*:*:*:*:*",
  8574          "purl": "pkg:deb/debian/libcap-ng0@0.7.9-2.2+b1?arch=amd64\u0026upstream=libcap-ng%400.7.9-2.2\u0026distro=debian-11",
  8575          "swid": {
  8576            "attachment": {}
  8577          },
  8578          "pedigree": {},
  8579          "evidence": {},
  8580          "signature": {
  8581            "signature": {
  8582              "publicKey": {}
  8583            }
  8584          },
  8585          "modelCard": {
  8586            "modelParameters": {
  8587              "approach": {}
  8588            },
  8589            "quantitativeAnalysis": {
  8590              "graphics": {}
  8591            },
  8592            "considerations": {}
  8593          }
  8594        },
  8595        {
  8596          "type": "library",
  8597          "bom-ref": "pkg:deb/debian/libcom-err2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=c3e2285fd362b920",
  8598          "supplier": {},
  8599          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
  8600          "name": "libcom-err2",
  8601          "version": "1.46.2-2",
  8602          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.46.2-2:*:*:*:*:*:*:*",
  8603          "purl": "pkg:deb/debian/libcom-err2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
  8604          "swid": {
  8605            "attachment": {}
  8606          },
  8607          "pedigree": {},
  8608          "evidence": {},
  8609          "signature": {
  8610            "signature": {
  8611              "publicKey": {}
  8612            }
  8613          },
  8614          "modelCard": {
  8615            "modelParameters": {
  8616              "approach": {}
  8617            },
  8618            "quantitativeAnalysis": {
  8619              "graphics": {}
  8620            },
  8621            "considerations": {}
  8622          }
  8623        },
  8624        {
  8625          "type": "library",
  8626          "bom-ref": "pkg:deb/debian/libcrypt1@1:4.4.18-4?arch=amd64\u0026upstream=libxcrypt\u0026distro=debian-11\u0026package-id=4d32f8aeb497b2e2",
  8627          "supplier": {},
  8628          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
  8629          "name": "libcrypt1",
  8630          "version": "1:4.4.18-4",
  8631          "cpe": "cpe:2.3:a:libcrypt1:libcrypt1:1\\:4.4.18-4:*:*:*:*:*:*:*",
  8632          "purl": "pkg:deb/debian/libcrypt1@1:4.4.18-4?arch=amd64\u0026upstream=libxcrypt\u0026distro=debian-11",
  8633          "swid": {
  8634            "attachment": {}
  8635          },
  8636          "pedigree": {},
  8637          "evidence": {},
  8638          "signature": {
  8639            "signature": {
  8640              "publicKey": {}
  8641            }
  8642          },
  8643          "modelCard": {
  8644            "modelParameters": {
  8645              "approach": {}
  8646            },
  8647            "quantitativeAnalysis": {
  8648              "graphics": {}
  8649            },
  8650            "considerations": {}
  8651          }
  8652        },
  8653        {
  8654          "type": "library",
  8655          "bom-ref": "pkg:deb/debian/libcurl4@7.74.0-1.3+deb11u7?arch=amd64\u0026upstream=curl\u0026distro=debian-11\u0026package-id=5ca0f748c3f34f0",
  8656          "supplier": {},
  8657          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
  8658          "name": "libcurl4",
  8659          "version": "7.74.0-1.3+deb11u7",
  8660          "licenses": [
  8661            {
  8662              "license": {
  8663                "id": "BSD-3-Clause"
  8664              }
  8665            },
  8666            {
  8667              "license": {
  8668                "id": "BSD-4-Clause"
  8669              }
  8670            },
  8671            {
  8672              "license": {
  8673                "id": "ISC"
  8674              }
  8675            },
  8676            {
  8677              "license": {
  8678                "id": "curl"
  8679              }
  8680            },
  8681            {
  8682              "license": {
  8683                "name": "other"
  8684              }
  8685            },
  8686            {
  8687              "license": {
  8688                "name": "public-domain"
  8689              }
  8690            }
  8691          ],
  8692          "cpe": "cpe:2.3:a:libcurl4:libcurl4:7.74.0-1.3\\+deb11u7:*:*:*:*:*:*:*",
  8693          "purl": "pkg:deb/debian/libcurl4@7.74.0-1.3+deb11u7?arch=amd64\u0026upstream=curl\u0026distro=debian-11",
  8694          "swid": {
  8695            "attachment": {}
  8696          },
  8697          "pedigree": {},
  8698          "evidence": {},
  8699          "signature": {
  8700            "signature": {
  8701              "publicKey": {}
  8702            }
  8703          },
  8704          "modelCard": {
  8705            "modelParameters": {
  8706              "approach": {}
  8707            },
  8708            "quantitativeAnalysis": {
  8709              "graphics": {}
  8710            },
  8711            "considerations": {}
  8712          }
  8713        },
  8714        {
  8715          "type": "library",
  8716          "bom-ref": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.8?arch=amd64\u0026upstream=db5.3\u0026distro=debian-11\u0026package-id=bd40bf11043e04a6",
  8717          "supplier": {},
  8718          "publisher": "Debian Berkeley DB Team \u003cteam+bdb@tracker.debian.org\u003e",
  8719          "name": "libdb5.3",
  8720          "version": "5.3.28+dfsg1-0.8",
  8721          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.8:*:*:*:*:*:*:*",
  8722          "purl": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.8?arch=amd64\u0026upstream=db5.3\u0026distro=debian-11",
  8723          "swid": {
  8724            "attachment": {}
  8725          },
  8726          "pedigree": {},
  8727          "evidence": {},
  8728          "signature": {
  8729            "signature": {
  8730              "publicKey": {}
  8731            }
  8732          },
  8733          "modelCard": {
  8734            "modelParameters": {
  8735              "approach": {}
  8736            },
  8737            "quantitativeAnalysis": {
  8738              "graphics": {}
  8739            },
  8740            "considerations": {}
  8741          }
  8742        },
  8743        {
  8744          "type": "library",
  8745          "bom-ref": "pkg:deb/debian/libdebconfclient0@0.260?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-11\u0026package-id=f46e6be545ae8a8c",
  8746          "supplier": {},
  8747          "publisher": "Debian Install System Team \u003cdebian-boot@lists.debian.org\u003e",
  8748          "name": "libdebconfclient0",
  8749          "version": "0.260",
  8750          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.260:*:*:*:*:*:*:*",
  8751          "purl": "pkg:deb/debian/libdebconfclient0@0.260?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-11",
  8752          "swid": {
  8753            "attachment": {}
  8754          },
  8755          "pedigree": {},
  8756          "evidence": {},
  8757          "signature": {
  8758            "signature": {
  8759              "publicKey": {}
  8760            }
  8761          },
  8762          "modelCard": {
  8763            "modelParameters": {
  8764              "approach": {}
  8765            },
  8766            "quantitativeAnalysis": {
  8767              "graphics": {}
  8768            },
  8769            "considerations": {}
  8770          }
  8771        },
  8772        {
  8773          "type": "library",
  8774          "bom-ref": "pkg:deb/debian/libext2fs2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=78620e65fcd780c3",
  8775          "supplier": {},
  8776          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
  8777          "name": "libext2fs2",
  8778          "version": "1.46.2-2",
  8779          "licenses": [
  8780            {
  8781              "license": {
  8782                "id": "GPL-2.0-only"
  8783              }
  8784            },
  8785            {
  8786              "license": {
  8787                "id": "LGPL-2.0-only"
  8788              }
  8789            }
  8790          ],
  8791          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.46.2-2:*:*:*:*:*:*:*",
  8792          "purl": "pkg:deb/debian/libext2fs2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
  8793          "swid": {
  8794            "attachment": {}
  8795          },
  8796          "pedigree": {},
  8797          "evidence": {},
  8798          "signature": {
  8799            "signature": {
  8800              "publicKey": {}
  8801            }
  8802          },
  8803          "modelCard": {
  8804            "modelParameters": {
  8805              "approach": {}
  8806            },
  8807            "quantitativeAnalysis": {
  8808              "graphics": {}
  8809            },
  8810            "considerations": {}
  8811          }
  8812        },
  8813        {
  8814          "type": "library",
  8815          "bom-ref": "pkg:deb/debian/libffi7@3.3-6?arch=amd64\u0026upstream=libffi\u0026distro=debian-11\u0026package-id=b76aa1c712147c28",
  8816          "supplier": {},
  8817          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
  8818          "name": "libffi7",
  8819          "version": "3.3-6",
  8820          "licenses": [
  8821            {
  8822              "license": {
  8823                "name": "GPL"
  8824              }
  8825            }
  8826          ],
  8827          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-6:*:*:*:*:*:*:*",
  8828          "purl": "pkg:deb/debian/libffi7@3.3-6?arch=amd64\u0026upstream=libffi\u0026distro=debian-11",
  8829          "swid": {
  8830            "attachment": {}
  8831          },
  8832          "pedigree": {},
  8833          "evidence": {},
  8834          "signature": {
  8835            "signature": {
  8836              "publicKey": {}
  8837            }
  8838          },
  8839          "modelCard": {
  8840            "modelParameters": {
  8841              "approach": {}
  8842            },
  8843            "quantitativeAnalysis": {
  8844              "graphics": {}
  8845            },
  8846            "considerations": {}
  8847          }
  8848        },
  8849        {
  8850          "type": "library",
  8851          "bom-ref": "pkg:deb/debian/libgcc-s1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=ddb4ba0153b59955",
  8852          "supplier": {},
  8853          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
  8854          "name": "libgcc-s1",
  8855          "version": "10.2.1-6",
  8856          "licenses": [
  8857            {
  8858              "license": {
  8859                "name": "Artistic"
  8860              }
  8861            },
  8862            {
  8863              "license": {
  8864                "id": "GFDL-1.2-only"
  8865              }
  8866            },
  8867            {
  8868              "license": {
  8869                "name": "GPL"
  8870              }
  8871            },
  8872            {
  8873              "license": {
  8874                "id": "GPL-2.0-only"
  8875              }
  8876            },
  8877            {
  8878              "license": {
  8879                "id": "GPL-3.0-only"
  8880              }
  8881            },
  8882            {
  8883              "license": {
  8884                "name": "LGPL"
  8885              }
  8886            }
  8887          ],
  8888          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.2.1-6:*:*:*:*:*:*:*",
  8889          "purl": "pkg:deb/debian/libgcc-s1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
  8890          "swid": {
  8891            "attachment": {}
  8892          },
  8893          "pedigree": {},
  8894          "evidence": {},
  8895          "signature": {
  8896            "signature": {
  8897              "publicKey": {}
  8898            }
  8899          },
  8900          "modelCard": {
  8901            "modelParameters": {
  8902              "approach": {}
  8903            },
  8904            "quantitativeAnalysis": {
  8905              "graphics": {}
  8906            },
  8907            "considerations": {}
  8908          }
  8909        },
  8910        {
  8911          "type": "library",
  8912          "bom-ref": "pkg:deb/debian/libgcrypt20@1.8.7-6?arch=amd64\u0026distro=debian-11\u0026package-id=7bc9b7389c934ca8",
  8913          "supplier": {},
  8914          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
  8915          "name": "libgcrypt20",
  8916          "version": "1.8.7-6",
  8917          "licenses": [
  8918            {
  8919              "license": {
  8920                "id": "GPL-2.0-only"
  8921              }
  8922            },
  8923            {
  8924              "license": {
  8925                "name": "LGPL"
  8926              }
  8927            }
  8928          ],
  8929          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.7-6:*:*:*:*:*:*:*",
  8930          "purl": "pkg:deb/debian/libgcrypt20@1.8.7-6?arch=amd64\u0026distro=debian-11",
  8931          "swid": {
  8932            "attachment": {}
  8933          },
  8934          "pedigree": {},
  8935          "evidence": {},
  8936          "signature": {
  8937            "signature": {
  8938              "publicKey": {}
  8939            }
  8940          },
  8941          "modelCard": {
  8942            "modelParameters": {
  8943              "approach": {}
  8944            },
  8945            "quantitativeAnalysis": {
  8946              "graphics": {}
  8947            },
  8948            "considerations": {}
  8949          }
  8950        },
  8951        {
  8952          "type": "library",
  8953          "bom-ref": "pkg:deb/debian/libgmp10@2:6.2.1+dfsg-1+deb11u1?arch=amd64\u0026upstream=gmp\u0026distro=debian-11\u0026package-id=b8566db47d8d4ddc",
  8954          "supplier": {},
  8955          "publisher": "Debian Science Team \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e",
  8956          "name": "libgmp10",
  8957          "version": "2:6.2.1+dfsg-1+deb11u1",
  8958          "licenses": [
  8959            {
  8960              "license": {
  8961                "name": "GPL"
  8962              }
  8963            },
  8964            {
  8965              "license": {
  8966                "id": "GPL-2.0-only"
  8967              }
  8968            },
  8969            {
  8970              "license": {
  8971                "id": "GPL-3.0-only"
  8972              }
  8973            },
  8974            {
  8975              "license": {
  8976                "id": "LGPL-3.0-only"
  8977              }
  8978            }
  8979          ],
  8980          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.1\\+dfsg-1\\+deb11u1:*:*:*:*:*:*:*",
  8981          "purl": "pkg:deb/debian/libgmp10@2:6.2.1+dfsg-1+deb11u1?arch=amd64\u0026upstream=gmp\u0026distro=debian-11",
  8982          "swid": {
  8983            "attachment": {}
  8984          },
  8985          "pedigree": {},
  8986          "evidence": {},
  8987          "signature": {
  8988            "signature": {
  8989              "publicKey": {}
  8990            }
  8991          },
  8992          "modelCard": {
  8993            "modelParameters": {
  8994              "approach": {}
  8995            },
  8996            "quantitativeAnalysis": {
  8997              "graphics": {}
  8998            },
  8999            "considerations": {}
  9000          }
  9001        },
  9002        {
  9003          "type": "library",
  9004          "bom-ref": "pkg:deb/debian/libgnutls30@3.7.1-5+deb11u3?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-11\u0026package-id=7a4a4d471a0c6aed",
  9005          "supplier": {},
  9006          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
  9007          "name": "libgnutls30",
  9008          "version": "3.7.1-5+deb11u3",
  9009          "licenses": [
  9010            {
  9011              "license": {
  9012                "id": "Apache-2.0"
  9013              }
  9014            },
  9015            {
  9016              "license": {
  9017                "id": "BSD-3-Clause"
  9018              }
  9019            },
  9020            {
  9021              "license": {
  9022                "name": "CC0"
  9023              }
  9024            },
  9025            {
  9026              "license": {
  9027                "name": "Expat"
  9028              }
  9029            },
  9030            {
  9031              "license": {
  9032                "id": "GFDL-1.3-only"
  9033              }
  9034            },
  9035            {
  9036              "license": {
  9037                "name": "GPL"
  9038              }
  9039            },
  9040            {
  9041              "license": {
  9042                "id": "GPL-3.0-only"
  9043              }
  9044            },
  9045            {
  9046              "license": {
  9047                "name": "GPLv3+"
  9048              }
  9049            },
  9050            {
  9051              "license": {
  9052                "name": "LGPL"
  9053              }
  9054            },
  9055            {
  9056              "license": {
  9057                "id": "LGPL-3.0-only"
  9058              }
  9059            },
  9060            {
  9061              "license": {
  9062                "name": "LGPLv2.1+"
  9063              }
  9064            },
  9065            {
  9066              "license": {
  9067                "name": "LGPLv3+_or_GPLv2+"
  9068              }
  9069            },
  9070            {
  9071              "license": {
  9072                "name": "The"
  9073              }
  9074            }
  9075          ],
  9076          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.7.1-5\\+deb11u3:*:*:*:*:*:*:*",
  9077          "purl": "pkg:deb/debian/libgnutls30@3.7.1-5+deb11u3?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-11",
  9078          "swid": {
  9079            "attachment": {}
  9080          },
  9081          "pedigree": {},
  9082          "evidence": {},
  9083          "signature": {
  9084            "signature": {
  9085              "publicKey": {}
  9086            }
  9087          },
  9088          "modelCard": {
  9089            "modelParameters": {
  9090              "approach": {}
  9091            },
  9092            "quantitativeAnalysis": {
  9093              "graphics": {}
  9094            },
  9095            "considerations": {}
  9096          }
  9097        },
  9098        {
  9099          "type": "library",
  9100          "bom-ref": "pkg:deb/debian/libgpg-error0@1.38-2?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-11\u0026package-id=2391ec82a95e1b79",
  9101          "supplier": {},
  9102          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
  9103          "name": "libgpg-error0",
  9104          "version": "1.38-2",
  9105          "licenses": [
  9106            {
  9107              "license": {
  9108                "id": "BSD-3-Clause"
  9109              }
  9110            },
  9111            {
  9112              "license": {
  9113                "id": "GPL-3.0-only"
  9114              }
  9115            },
  9116            {
  9117              "license": {
  9118                "id": "GPL-3.0-or-later"
  9119              }
  9120            },
  9121            {
  9122              "license": {
  9123                "id": "LGPL-2.1-only"
  9124              }
  9125            },
  9126            {
  9127              "license": {
  9128                "id": "LGPL-2.1-or-later"
  9129              }
  9130            },
  9131            {
  9132              "license": {
  9133                "name": "g10-permissive"
  9134              }
  9135            }
  9136          ],
  9137          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.38-2:*:*:*:*:*:*:*",
  9138          "purl": "pkg:deb/debian/libgpg-error0@1.38-2?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-11",
  9139          "swid": {
  9140            "attachment": {}
  9141          },
  9142          "pedigree": {},
  9143          "evidence": {},
  9144          "signature": {
  9145            "signature": {
  9146              "publicKey": {}
  9147            }
  9148          },
  9149          "modelCard": {
  9150            "modelParameters": {
  9151              "approach": {}
  9152            },
  9153            "quantitativeAnalysis": {
  9154              "graphics": {}
  9155            },
  9156            "considerations": {}
  9157          }
  9158        },
  9159        {
  9160          "type": "library",
  9161          "bom-ref": "pkg:deb/debian/libgssapi-krb5-2@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=3f685865c7e045c1",
  9162          "supplier": {},
  9163          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
  9164          "name": "libgssapi-krb5-2",
  9165          "version": "1.18.3-6+deb11u3",
  9166          "licenses": [
  9167            {
  9168              "license": {
  9169                "id": "GPL-2.0-only"
  9170              }
  9171            }
  9172          ],
  9173          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
  9174          "purl": "pkg:deb/debian/libgssapi-krb5-2@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
  9175          "swid": {
  9176            "attachment": {}
  9177          },
  9178          "pedigree": {},
  9179          "evidence": {},
  9180          "signature": {
  9181            "signature": {
  9182              "publicKey": {}
  9183            }
  9184          },
  9185          "modelCard": {
  9186            "modelParameters": {
  9187              "approach": {}
  9188            },
  9189            "quantitativeAnalysis": {
  9190              "graphics": {}
  9191            },
  9192            "considerations": {}
  9193          }
  9194        },
  9195        {
  9196          "type": "library",
  9197          "bom-ref": "pkg:deb/debian/libhogweed6@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11\u0026package-id=5e22b39e8cb919f6",
  9198          "supplier": {},
  9199          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
  9200          "name": "libhogweed6",
  9201          "version": "3.7.3-1",
  9202          "licenses": [
  9203            {
  9204              "license": {
  9205                "name": "Expat"
  9206              }
  9207            },
  9208            {
  9209              "license": {
  9210                "name": "GAP"
  9211              }
  9212            },
  9213            {
  9214              "license": {
  9215                "name": "GPL"
  9216              }
  9217            },
  9218            {
  9219              "license": {
  9220                "id": "GPL-2.0-only"
  9221              }
  9222            },
  9223            {
  9224              "license": {
  9225                "id": "GPL-2.0-or-later"
  9226              }
  9227            },
  9228            {
  9229              "license": {
  9230                "id": "GPL-3.0-or-later"
  9231              }
  9232            },
  9233            {
  9234              "license": {
  9235                "name": "LGPL"
  9236              }
  9237            },
  9238            {
  9239              "license": {
  9240                "id": "LGPL-2.0-only"
  9241              }
  9242            },
  9243            {
  9244              "license": {
  9245                "id": "LGPL-2.0-or-later"
  9246              }
  9247            },
  9248            {
  9249              "license": {
  9250                "id": "LGPL-3.0-or-later"
  9251              }
  9252            },
  9253            {
  9254              "license": {
  9255                "name": "public-domain"
  9256              }
  9257            }
  9258          ],
  9259          "cpe": "cpe:2.3:a:libhogweed6:libhogweed6:3.7.3-1:*:*:*:*:*:*:*",
  9260          "purl": "pkg:deb/debian/libhogweed6@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11",
  9261          "swid": {
  9262            "attachment": {}
  9263          },
  9264          "pedigree": {},
  9265          "evidence": {},
  9266          "signature": {
  9267            "signature": {
  9268              "publicKey": {}
  9269            }
  9270          },
  9271          "modelCard": {
  9272            "modelParameters": {
  9273              "approach": {}
  9274            },
  9275            "quantitativeAnalysis": {
  9276              "graphics": {}
  9277            },
  9278            "considerations": {}
  9279          }
  9280        },
  9281        {
  9282          "type": "library",
  9283          "bom-ref": "pkg:deb/debian/libidn2-0@2.3.0-5?arch=amd64\u0026upstream=libidn2\u0026distro=debian-11\u0026package-id=8eb1c8304ad48ef2",
  9284          "supplier": {},
  9285          "publisher": "Debian Libidn team \u003chelp-libidn@gnu.org\u003e",
  9286          "name": "libidn2-0",
  9287          "version": "2.3.0-5",
  9288          "licenses": [
  9289            {
  9290              "license": {
  9291                "id": "GPL-2.0-only"
  9292              }
  9293            },
  9294            {
  9295              "license": {
  9296                "id": "GPL-2.0-or-later"
  9297              }
  9298            },
  9299            {
  9300              "license": {
  9301                "id": "GPL-3.0-only"
  9302              }
  9303            },
  9304            {
  9305              "license": {
  9306                "id": "GPL-3.0-or-later"
  9307              }
  9308            },
  9309            {
  9310              "license": {
  9311                "id": "LGPL-3.0-only"
  9312              }
  9313            },
  9314            {
  9315              "license": {
  9316                "id": "LGPL-3.0-or-later"
  9317              }
  9318            },
  9319            {
  9320              "license": {
  9321                "name": "Unicode"
  9322              }
  9323            }
  9324          ],
  9325          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.3.0-5:*:*:*:*:*:*:*",
  9326          "purl": "pkg:deb/debian/libidn2-0@2.3.0-5?arch=amd64\u0026upstream=libidn2\u0026distro=debian-11",
  9327          "swid": {
  9328            "attachment": {}
  9329          },
  9330          "pedigree": {},
  9331          "evidence": {},
  9332          "signature": {
  9333            "signature": {
  9334              "publicKey": {}
  9335            }
  9336          },
  9337          "modelCard": {
  9338            "modelParameters": {
  9339              "approach": {}
  9340            },
  9341            "quantitativeAnalysis": {
  9342              "graphics": {}
  9343            },
  9344            "considerations": {}
  9345          }
  9346        },
  9347        {
  9348          "type": "library",
  9349          "bom-ref": "pkg:deb/debian/libk5crypto3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=ae9e3b8691722eba",
  9350          "supplier": {},
  9351          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
  9352          "name": "libk5crypto3",
  9353          "version": "1.18.3-6+deb11u3",
  9354          "licenses": [
  9355            {
  9356              "license": {
  9357                "id": "GPL-2.0-only"
  9358              }
  9359            }
  9360          ],
  9361          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
  9362          "purl": "pkg:deb/debian/libk5crypto3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
  9363          "swid": {
  9364            "attachment": {}
  9365          },
  9366          "pedigree": {},
  9367          "evidence": {},
  9368          "signature": {
  9369            "signature": {
  9370              "publicKey": {}
  9371            }
  9372          },
  9373          "modelCard": {
  9374            "modelParameters": {
  9375              "approach": {}
  9376            },
  9377            "quantitativeAnalysis": {
  9378              "graphics": {}
  9379            },
  9380            "considerations": {}
  9381          }
  9382        },
  9383        {
  9384          "type": "library",
  9385          "bom-ref": "pkg:deb/debian/libkeyutils1@1.6.1-2?arch=amd64\u0026upstream=keyutils\u0026distro=debian-11\u0026package-id=308487f5f23bf878",
  9386          "supplier": {},
  9387          "publisher": "Christian Kastner \u003cckk@debian.org\u003e",
  9388          "name": "libkeyutils1",
  9389          "version": "1.6.1-2",
  9390          "licenses": [
  9391            {
  9392              "license": {
  9393                "id": "GPL-2.0-only"
  9394              }
  9395            },
  9396            {
  9397              "license": {
  9398                "id": "GPL-2.0-or-later"
  9399              }
  9400            },
  9401            {
  9402              "license": {
  9403                "id": "LGPL-2.0-only"
  9404              }
  9405            },
  9406            {
  9407              "license": {
  9408                "id": "LGPL-2.0-or-later"
  9409              }
  9410            }
  9411          ],
  9412          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6.1-2:*:*:*:*:*:*:*",
  9413          "purl": "pkg:deb/debian/libkeyutils1@1.6.1-2?arch=amd64\u0026upstream=keyutils\u0026distro=debian-11",
  9414          "swid": {
  9415            "attachment": {}
  9416          },
  9417          "pedigree": {},
  9418          "evidence": {},
  9419          "signature": {
  9420            "signature": {
  9421              "publicKey": {}
  9422            }
  9423          },
  9424          "modelCard": {
  9425            "modelParameters": {
  9426              "approach": {}
  9427            },
  9428            "quantitativeAnalysis": {
  9429              "graphics": {}
  9430            },
  9431            "considerations": {}
  9432          }
  9433        },
  9434        {
  9435          "type": "library",
  9436          "bom-ref": "pkg:deb/debian/libkrb5-3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=8bdffe6652e8e7ef",
  9437          "supplier": {},
  9438          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
  9439          "name": "libkrb5-3",
  9440          "version": "1.18.3-6+deb11u3",
  9441          "licenses": [
  9442            {
  9443              "license": {
  9444                "id": "GPL-2.0-only"
  9445              }
  9446            }
  9447          ],
  9448          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
  9449          "purl": "pkg:deb/debian/libkrb5-3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
  9450          "swid": {
  9451            "attachment": {}
  9452          },
  9453          "pedigree": {},
  9454          "evidence": {},
  9455          "signature": {
  9456            "signature": {
  9457              "publicKey": {}
  9458            }
  9459          },
  9460          "modelCard": {
  9461            "modelParameters": {
  9462              "approach": {}
  9463            },
  9464            "quantitativeAnalysis": {
  9465              "graphics": {}
  9466            },
  9467            "considerations": {}
  9468          }
  9469        },
  9470        {
  9471          "type": "library",
  9472          "bom-ref": "pkg:deb/debian/libkrb5support0@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=471e6243bbbcf8b2",
  9473          "supplier": {},
  9474          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
  9475          "name": "libkrb5support0",
  9476          "version": "1.18.3-6+deb11u3",
  9477          "licenses": [
  9478            {
  9479              "license": {
  9480                "id": "GPL-2.0-only"
  9481              }
  9482            }
  9483          ],
  9484          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
  9485          "purl": "pkg:deb/debian/libkrb5support0@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
  9486          "swid": {
  9487            "attachment": {}
  9488          },
  9489          "pedigree": {},
  9490          "evidence": {},
  9491          "signature": {
  9492            "signature": {
  9493              "publicKey": {}
  9494            }
  9495          },
  9496          "modelCard": {
  9497            "modelParameters": {
  9498              "approach": {}
  9499            },
  9500            "quantitativeAnalysis": {
  9501              "graphics": {}
  9502            },
  9503            "considerations": {}
  9504          }
  9505        },
  9506        {
  9507          "type": "library",
  9508          "bom-ref": "pkg:deb/debian/libksba8@1.5.0-3+deb11u2?arch=amd64\u0026upstream=libksba\u0026distro=debian-11\u0026package-id=5d2c888e571614c7",
  9509          "supplier": {},
  9510          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
  9511          "name": "libksba8",
  9512          "version": "1.5.0-3+deb11u2",
  9513          "licenses": [
  9514            {
  9515              "license": {
  9516                "id": "FSFUL"
  9517              }
  9518            },
  9519            {
  9520              "license": {
  9521                "id": "GPL-3.0-only"
  9522              }
  9523            },
  9524            {
  9525              "license": {
  9526                "id": "LGPL-2.1-or-later"
  9527              }
  9528            }
  9529          ],
  9530          "cpe": "cpe:2.3:a:libksba8:libksba8:1.5.0-3\\+deb11u2:*:*:*:*:*:*:*",
  9531          "purl": "pkg:deb/debian/libksba8@1.5.0-3+deb11u2?arch=amd64\u0026upstream=libksba\u0026distro=debian-11",
  9532          "swid": {
  9533            "attachment": {}
  9534          },
  9535          "pedigree": {},
  9536          "evidence": {},
  9537          "signature": {
  9538            "signature": {
  9539              "publicKey": {}
  9540            }
  9541          },
  9542          "modelCard": {
  9543            "modelParameters": {
  9544              "approach": {}
  9545            },
  9546            "quantitativeAnalysis": {
  9547              "graphics": {}
  9548            },
  9549            "considerations": {}
  9550          }
  9551        },
  9552        {
  9553          "type": "library",
  9554          "bom-ref": "pkg:deb/debian/libldap-2.4-2@2.4.57+dfsg-3+deb11u1?arch=amd64\u0026upstream=openldap\u0026distro=debian-11\u0026package-id=796a192b709a2a2b",
  9555          "supplier": {},
  9556          "publisher": "Debian OpenLDAP Maintainers \u003cpkg-openldap-devel@lists.alioth.debian.org\u003e",
  9557          "name": "libldap-2.4-2",
  9558          "version": "2.4.57+dfsg-3+deb11u1",
  9559          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.57\\+dfsg-3\\+deb11u1:*:*:*:*:*:*:*",
  9560          "purl": "pkg:deb/debian/libldap-2.4-2@2.4.57+dfsg-3+deb11u1?arch=amd64\u0026upstream=openldap\u0026distro=debian-11",
  9561          "swid": {
  9562            "attachment": {}
  9563          },
  9564          "pedigree": {},
  9565          "evidence": {},
  9566          "signature": {
  9567            "signature": {
  9568              "publicKey": {}
  9569            }
  9570          },
  9571          "modelCard": {
  9572            "modelParameters": {
  9573              "approach": {}
  9574            },
  9575            "quantitativeAnalysis": {
  9576              "graphics": {}
  9577            },
  9578            "considerations": {}
  9579          }
  9580        },
  9581        {
  9582          "type": "library",
  9583          "bom-ref": "pkg:deb/debian/liblz4-1@1.9.3-2?arch=amd64\u0026upstream=lz4\u0026distro=debian-11\u0026package-id=b59e208fb7f8bae4",
  9584          "supplier": {},
  9585          "publisher": "Nobuhiro Iwamatsu \u003ciwamatsu@debian.org\u003e",
  9586          "name": "liblz4-1",
  9587          "version": "1.9.3-2",
  9588          "licenses": [
  9589            {
  9590              "license": {
  9591                "id": "BSD-2-Clause"
  9592              }
  9593            },
  9594            {
  9595              "license": {
  9596                "id": "GPL-2.0-only"
  9597              }
  9598            },
  9599            {
  9600              "license": {
  9601                "id": "GPL-2.0-or-later"
  9602              }
  9603            }
  9604          ],
  9605          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.3-2:*:*:*:*:*:*:*",
  9606          "purl": "pkg:deb/debian/liblz4-1@1.9.3-2?arch=amd64\u0026upstream=lz4\u0026distro=debian-11",
  9607          "swid": {
  9608            "attachment": {}
  9609          },
  9610          "pedigree": {},
  9611          "evidence": {},
  9612          "signature": {
  9613            "signature": {
  9614              "publicKey": {}
  9615            }
  9616          },
  9617          "modelCard": {
  9618            "modelParameters": {
  9619              "approach": {}
  9620            },
  9621            "quantitativeAnalysis": {
  9622              "graphics": {}
  9623            },
  9624            "considerations": {}
  9625          }
  9626        },
  9627        {
  9628          "type": "library",
  9629          "bom-ref": "pkg:deb/debian/liblzma5@5.2.5-2.1~deb11u1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-11\u0026package-id=b95662a389d30c72",
  9630          "supplier": {},
  9631          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
  9632          "name": "liblzma5",
  9633          "version": "5.2.5-2.1~deb11u1",
  9634          "licenses": [
  9635            {
  9636              "license": {
  9637                "name": "Autoconf"
  9638              }
  9639            },
  9640            {
  9641              "license": {
  9642                "id": "GPL-2.0-only"
  9643              }
  9644            },
  9645            {
  9646              "license": {
  9647                "id": "GPL-2.0-or-later"
  9648              }
  9649            },
  9650            {
  9651              "license": {
  9652                "id": "GPL-3.0-only"
  9653              }
  9654            },
  9655            {
  9656              "license": {
  9657                "id": "LGPL-2.0-only"
  9658              }
  9659            },
  9660            {
  9661              "license": {
  9662                "id": "LGPL-2.1-only"
  9663              }
  9664            },
  9665            {
  9666              "license": {
  9667                "id": "LGPL-2.1-or-later"
  9668              }
  9669            },
  9670            {
  9671              "license": {
  9672                "name": "PD"
  9673              }
  9674            },
  9675            {
  9676              "license": {
  9677                "name": "PD-debian"
  9678              }
  9679            },
  9680            {
  9681              "license": {
  9682                "name": "config-h"
  9683              }
  9684            },
  9685            {
  9686              "license": {
  9687                "name": "noderivs"
  9688              }
  9689            },
  9690            {
  9691              "license": {
  9692                "name": "permissive-fsf"
  9693              }
  9694            },
  9695            {
  9696              "license": {
  9697                "name": "permissive-nowarranty"
  9698              }
  9699            },
  9700            {
  9701              "license": {
  9702                "name": "probably-PD"
  9703              }
  9704            }
  9705          ],
  9706          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.5-2.1\\~deb11u1:*:*:*:*:*:*:*",
  9707          "purl": "pkg:deb/debian/liblzma5@5.2.5-2.1~deb11u1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-11",
  9708          "swid": {
  9709            "attachment": {}
  9710          },
  9711          "pedigree": {},
  9712          "evidence": {},
  9713          "signature": {
  9714            "signature": {
  9715              "publicKey": {}
  9716            }
  9717          },
  9718          "modelCard": {
  9719            "modelParameters": {
  9720              "approach": {}
  9721            },
  9722            "quantitativeAnalysis": {
  9723              "graphics": {}
  9724            },
  9725            "considerations": {}
  9726          }
  9727        },
  9728        {
  9729          "type": "library",
  9730          "bom-ref": "pkg:deb/debian/libmount1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=afd0c3536366dc2c",
  9731          "supplier": {},
  9732          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
  9733          "name": "libmount1",
  9734          "version": "2.36.1-8+deb11u1",
  9735          "licenses": [
  9736            {
  9737              "license": {
  9738                "id": "BSD-2-Clause"
  9739              }
  9740            },
  9741            {
  9742              "license": {
  9743                "id": "BSD-3-Clause"
  9744              }
  9745            },
  9746            {
  9747              "license": {
  9748                "id": "BSD-4-Clause"
  9749              }
  9750            },
  9751            {
  9752              "license": {
  9753                "id": "GPL-2.0-only"
  9754              }
  9755            },
  9756            {
  9757              "license": {
  9758                "id": "GPL-2.0-or-later"
  9759              }
  9760            },
  9761            {
  9762              "license": {
  9763                "id": "GPL-3.0-only"
  9764              }
  9765            },
  9766            {
  9767              "license": {
  9768                "id": "GPL-3.0-or-later"
  9769              }
  9770            },
  9771            {
  9772              "license": {
  9773                "name": "LGPL"
  9774              }
  9775            },
  9776            {
  9777              "license": {
  9778                "id": "LGPL-2.0-only"
  9779              }
  9780            },
  9781            {
  9782              "license": {
  9783                "id": "LGPL-2.0-or-later"
  9784              }
  9785            },
  9786            {
  9787              "license": {
  9788                "id": "LGPL-2.1-only"
  9789              }
  9790            },
  9791            {
  9792              "license": {
  9793                "id": "LGPL-2.1-or-later"
  9794              }
  9795            },
  9796            {
  9797              "license": {
  9798                "id": "LGPL-3.0-only"
  9799              }
  9800            },
  9801            {
  9802              "license": {
  9803                "id": "LGPL-3.0-or-later"
  9804              }
  9805            },
  9806            {
  9807              "license": {
  9808                "id": "MIT"
  9809              }
  9810            },
  9811            {
  9812              "license": {
  9813                "name": "public-domain"
  9814              }
  9815            }
  9816          ],
  9817          "cpe": "cpe:2.3:a:libmount1:libmount1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
  9818          "purl": "pkg:deb/debian/libmount1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
  9819          "swid": {
  9820            "attachment": {}
  9821          },
  9822          "pedigree": {},
  9823          "evidence": {},
  9824          "signature": {
  9825            "signature": {
  9826              "publicKey": {}
  9827            }
  9828          },
  9829          "modelCard": {
  9830            "modelParameters": {
  9831              "approach": {}
  9832            },
  9833            "quantitativeAnalysis": {
  9834              "graphics": {}
  9835            },
  9836            "considerations": {}
  9837          }
  9838        },
  9839        {
  9840          "type": "library",
  9841          "bom-ref": "pkg:deb/debian/libncursesw6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=9eba19a6d4dcd7de",
  9842          "supplier": {},
  9843          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
  9844          "name": "libncursesw6",
  9845          "version": "6.2+20201114-2",
  9846          "licenses": [
  9847            {
  9848              "license": {
  9849                "id": "BSD-3-Clause"
  9850              }
  9851            },
  9852            {
  9853              "license": {
  9854                "name": "MIT/X11"
  9855              }
  9856            },
  9857            {
  9858              "license": {
  9859                "id": "X11"
  9860              }
  9861            }
  9862          ],
  9863          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.2\\+20201114-2:*:*:*:*:*:*:*",
  9864          "purl": "pkg:deb/debian/libncursesw6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11",
  9865          "swid": {
  9866            "attachment": {}
  9867          },
  9868          "pedigree": {},
  9869          "evidence": {},
  9870          "signature": {
  9871            "signature": {
  9872              "publicKey": {}
  9873            }
  9874          },
  9875          "modelCard": {
  9876            "modelParameters": {
  9877              "approach": {}
  9878            },
  9879            "quantitativeAnalysis": {
  9880              "graphics": {}
  9881            },
  9882            "considerations": {}
  9883          }
  9884        },
  9885        {
  9886          "type": "library",
  9887          "bom-ref": "pkg:deb/debian/libnettle8@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11\u0026package-id=ceff94b390c9bf61",
  9888          "supplier": {},
  9889          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
  9890          "name": "libnettle8",
  9891          "version": "3.7.3-1",
  9892          "licenses": [
  9893            {
  9894              "license": {
  9895                "name": "Expat"
  9896              }
  9897            },
  9898            {
  9899              "license": {
  9900                "name": "GAP"
  9901              }
  9902            },
  9903            {
  9904              "license": {
  9905                "name": "GPL"
  9906              }
  9907            },
  9908            {
  9909              "license": {
  9910                "id": "GPL-2.0-only"
  9911              }
  9912            },
  9913            {
  9914              "license": {
  9915                "id": "GPL-2.0-or-later"
  9916              }
  9917            },
  9918            {
  9919              "license": {
  9920                "id": "GPL-3.0-or-later"
  9921              }
  9922            },
  9923            {
  9924              "license": {
  9925                "name": "LGPL"
  9926              }
  9927            },
  9928            {
  9929              "license": {
  9930                "id": "LGPL-2.0-only"
  9931              }
  9932            },
  9933            {
  9934              "license": {
  9935                "id": "LGPL-2.0-or-later"
  9936              }
  9937            },
  9938            {
  9939              "license": {
  9940                "id": "LGPL-3.0-or-later"
  9941              }
  9942            },
  9943            {
  9944              "license": {
  9945                "name": "public-domain"
  9946              }
  9947            }
  9948          ],
  9949          "cpe": "cpe:2.3:a:libnettle8:libnettle8:3.7.3-1:*:*:*:*:*:*:*",
  9950          "purl": "pkg:deb/debian/libnettle8@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11",
  9951          "swid": {
  9952            "attachment": {}
  9953          },
  9954          "pedigree": {},
  9955          "evidence": {},
  9956          "signature": {
  9957            "signature": {
  9958              "publicKey": {}
  9959            }
  9960          },
  9961          "modelCard": {
  9962            "modelParameters": {
  9963              "approach": {}
  9964            },
  9965            "quantitativeAnalysis": {
  9966              "graphics": {}
  9967            },
  9968            "considerations": {}
  9969          }
  9970        },
  9971        {
  9972          "type": "library",
  9973          "bom-ref": "pkg:deb/debian/libnghttp2-14@1.43.0-1?arch=amd64\u0026upstream=nghttp2\u0026distro=debian-11\u0026package-id=cfb81461ba0ee3f7",
  9974          "supplier": {},
  9975          "publisher": "Tomasz Buchert \u003ctomasz@debian.org\u003e",
  9976          "name": "libnghttp2-14",
  9977          "version": "1.43.0-1",
  9978          "licenses": [
  9979            {
  9980              "license": {
  9981                "id": "BSD-2-Clause"
  9982              }
  9983            },
  9984            {
  9985              "license": {
  9986                "name": "Expat"
  9987              }
  9988            },
  9989            {
  9990              "license": {
  9991                "id": "GPL-3.0-only"
  9992              }
  9993            },
  9994            {
  9995              "license": {
  9996                "id": "GPL-3.0-or-later"
  9997              }
  9998            },
  9999            {
 10000              "license": {
 10001                "id": "MIT"
 10002              }
 10003            },
 10004            {
 10005              "license": {
 10006                "name": "SIL-OFL-1.1"
 10007              }
 10008            },
 10009            {
 10010              "license": {
 10011                "name": "all-permissive"
 10012              }
 10013            }
 10014          ],
 10015          "cpe": "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.43.0-1:*:*:*:*:*:*:*",
 10016          "purl": "pkg:deb/debian/libnghttp2-14@1.43.0-1?arch=amd64\u0026upstream=nghttp2\u0026distro=debian-11",
 10017          "swid": {
 10018            "attachment": {}
 10019          },
 10020          "pedigree": {},
 10021          "evidence": {},
 10022          "signature": {
 10023            "signature": {
 10024              "publicKey": {}
 10025            }
 10026          },
 10027          "modelCard": {
 10028            "modelParameters": {
 10029              "approach": {}
 10030            },
 10031            "quantitativeAnalysis": {
 10032              "graphics": {}
 10033            },
 10034            "considerations": {}
 10035          }
 10036        },
 10037        {
 10038          "type": "library",
 10039          "bom-ref": "pkg:deb/debian/libnpth0@1.6-3?arch=amd64\u0026upstream=npth\u0026distro=debian-11\u0026package-id=8f1b99f450f7926c",
 10040          "supplier": {},
 10041          "publisher": "Eric Dorland \u003ceric@debian.org\u003e",
 10042          "name": "libnpth0",
 10043          "version": "1.6-3",
 10044          "licenses": [
 10045            {
 10046              "license": {
 10047                "id": "LGPL-2.1-only"
 10048              }
 10049            },
 10050            {
 10051              "license": {
 10052                "id": "LGPL-2.1-or-later"
 10053              }
 10054            }
 10055          ],
 10056          "cpe": "cpe:2.3:a:libnpth0:libnpth0:1.6-3:*:*:*:*:*:*:*",
 10057          "purl": "pkg:deb/debian/libnpth0@1.6-3?arch=amd64\u0026upstream=npth\u0026distro=debian-11",
 10058          "swid": {
 10059            "attachment": {}
 10060          },
 10061          "pedigree": {},
 10062          "evidence": {},
 10063          "signature": {
 10064            "signature": {
 10065              "publicKey": {}
 10066            }
 10067          },
 10068          "modelCard": {
 10069            "modelParameters": {
 10070              "approach": {}
 10071            },
 10072            "quantitativeAnalysis": {
 10073              "graphics": {}
 10074            },
 10075            "considerations": {}
 10076          }
 10077        },
 10078        {
 10079          "type": "library",
 10080          "bom-ref": "pkg:deb/debian/libnsl2@1.3.0-2?arch=amd64\u0026upstream=libnsl\u0026distro=debian-11\u0026package-id=fc8ac2f1807436d9",
 10081          "supplier": {},
 10082          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 10083          "name": "libnsl2",
 10084          "version": "1.3.0-2",
 10085          "licenses": [
 10086            {
 10087              "license": {
 10088                "id": "BSD-3-Clause"
 10089              }
 10090            },
 10091            {
 10092              "license": {
 10093                "id": "GPL-2.0-only"
 10094              }
 10095            },
 10096            {
 10097              "license": {
 10098                "name": "GPL-2+-autoconf-exception"
 10099              }
 10100            },
 10101            {
 10102              "license": {
 10103                "name": "GPL-2+-libtool-exception"
 10104              }
 10105            },
 10106            {
 10107              "license": {
 10108                "id": "GPL-3.0-only"
 10109              }
 10110            },
 10111            {
 10112              "license": {
 10113                "name": "GPL-3+-autoconf-exception"
 10114              }
 10115            },
 10116            {
 10117              "license": {
 10118                "id": "LGPL-2.1-only"
 10119              }
 10120            },
 10121            {
 10122              "license": {
 10123                "id": "LGPL-2.1-or-later"
 10124              }
 10125            },
 10126            {
 10127              "license": {
 10128                "id": "MIT"
 10129              }
 10130            },
 10131            {
 10132              "license": {
 10133                "name": "permissive-autoconf-m4"
 10134              }
 10135            },
 10136            {
 10137              "license": {
 10138                "name": "permissive-autoconf-m4-no-warranty"
 10139              }
 10140            },
 10141            {
 10142              "license": {
 10143                "name": "permissive-configure"
 10144              }
 10145            },
 10146            {
 10147              "license": {
 10148                "name": "permissive-fsf"
 10149              }
 10150            },
 10151            {
 10152              "license": {
 10153                "name": "permissive-makefile-in"
 10154              }
 10155            }
 10156          ],
 10157          "cpe": "cpe:2.3:a:libnsl2:libnsl2:1.3.0-2:*:*:*:*:*:*:*",
 10158          "purl": "pkg:deb/debian/libnsl2@1.3.0-2?arch=amd64\u0026upstream=libnsl\u0026distro=debian-11",
 10159          "swid": {
 10160            "attachment": {}
 10161          },
 10162          "pedigree": {},
 10163          "evidence": {},
 10164          "signature": {
 10165            "signature": {
 10166              "publicKey": {}
 10167            }
 10168          },
 10169          "modelCard": {
 10170            "modelParameters": {
 10171              "approach": {}
 10172            },
 10173            "quantitativeAnalysis": {
 10174              "graphics": {}
 10175            },
 10176            "considerations": {}
 10177          }
 10178        },
 10179        {
 10180          "type": "library",
 10181          "bom-ref": "pkg:deb/debian/libp11-kit0@0.23.22-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-11\u0026package-id=a2ce6d1eb48ab956",
 10182          "supplier": {},
 10183          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 10184          "name": "libp11-kit0",
 10185          "version": "0.23.22-1",
 10186          "licenses": [
 10187            {
 10188              "license": {
 10189                "id": "BSD-3-Clause"
 10190              }
 10191            },
 10192            {
 10193              "license": {
 10194                "id": "ISC"
 10195              }
 10196            },
 10197            {
 10198              "license": {
 10199                "name": "ISC+IBM"
 10200              }
 10201            },
 10202            {
 10203              "license": {
 10204                "name": "permissive-like-automake-output"
 10205              }
 10206            },
 10207            {
 10208              "license": {
 10209                "name": "same-as-rest-of-p11kit"
 10210              }
 10211            }
 10212          ],
 10213          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.22-1:*:*:*:*:*:*:*",
 10214          "purl": "pkg:deb/debian/libp11-kit0@0.23.22-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-11",
 10215          "swid": {
 10216            "attachment": {}
 10217          },
 10218          "pedigree": {},
 10219          "evidence": {},
 10220          "signature": {
 10221            "signature": {
 10222              "publicKey": {}
 10223            }
 10224          },
 10225          "modelCard": {
 10226            "modelParameters": {
 10227              "approach": {}
 10228            },
 10229            "quantitativeAnalysis": {
 10230              "graphics": {}
 10231            },
 10232            "considerations": {}
 10233          }
 10234        },
 10235        {
 10236          "type": "library",
 10237          "bom-ref": "pkg:deb/debian/libpam-modules@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11\u0026package-id=903eac5974d73705",
 10238          "supplier": {},
 10239          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 10240          "name": "libpam-modules",
 10241          "version": "1.4.0-9+deb11u1",
 10242          "licenses": [
 10243            {
 10244              "license": {
 10245                "name": "GPL"
 10246              }
 10247            }
 10248          ],
 10249          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
 10250          "purl": "pkg:deb/debian/libpam-modules@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11",
 10251          "swid": {
 10252            "attachment": {}
 10253          },
 10254          "pedigree": {},
 10255          "evidence": {},
 10256          "signature": {
 10257            "signature": {
 10258              "publicKey": {}
 10259            }
 10260          },
 10261          "modelCard": {
 10262            "modelParameters": {
 10263              "approach": {}
 10264            },
 10265            "quantitativeAnalysis": {
 10266              "graphics": {}
 10267            },
 10268            "considerations": {}
 10269          }
 10270        },
 10271        {
 10272          "type": "library",
 10273          "bom-ref": "pkg:deb/debian/libpam-modules-bin@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11\u0026package-id=2dc3f20bb97e020d",
 10274          "supplier": {},
 10275          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 10276          "name": "libpam-modules-bin",
 10277          "version": "1.4.0-9+deb11u1",
 10278          "licenses": [
 10279            {
 10280              "license": {
 10281                "name": "GPL"
 10282              }
 10283            }
 10284          ],
 10285          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
 10286          "purl": "pkg:deb/debian/libpam-modules-bin@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11",
 10287          "swid": {
 10288            "attachment": {}
 10289          },
 10290          "pedigree": {},
 10291          "evidence": {},
 10292          "signature": {
 10293            "signature": {
 10294              "publicKey": {}
 10295            }
 10296          },
 10297          "modelCard": {
 10298            "modelParameters": {
 10299              "approach": {}
 10300            },
 10301            "quantitativeAnalysis": {
 10302              "graphics": {}
 10303            },
 10304            "considerations": {}
 10305          }
 10306        },
 10307        {
 10308          "type": "library",
 10309          "bom-ref": "pkg:deb/debian/libpam-runtime@1.4.0-9+deb11u1?arch=all\u0026upstream=pam\u0026distro=debian-11\u0026package-id=1238d07342abe7a3",
 10310          "supplier": {},
 10311          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 10312          "name": "libpam-runtime",
 10313          "version": "1.4.0-9+deb11u1",
 10314          "licenses": [
 10315            {
 10316              "license": {
 10317                "name": "GPL"
 10318              }
 10319            }
 10320          ],
 10321          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
 10322          "purl": "pkg:deb/debian/libpam-runtime@1.4.0-9+deb11u1?arch=all\u0026upstream=pam\u0026distro=debian-11",
 10323          "swid": {
 10324            "attachment": {}
 10325          },
 10326          "pedigree": {},
 10327          "evidence": {},
 10328          "signature": {
 10329            "signature": {
 10330              "publicKey": {}
 10331            }
 10332          },
 10333          "modelCard": {
 10334            "modelParameters": {
 10335              "approach": {}
 10336            },
 10337            "quantitativeAnalysis": {
 10338              "graphics": {}
 10339            },
 10340            "considerations": {}
 10341          }
 10342        },
 10343        {
 10344          "type": "library",
 10345          "bom-ref": "pkg:deb/debian/libpam0g@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11\u0026package-id=70917c5424d601fa",
 10346          "supplier": {},
 10347          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 10348          "name": "libpam0g",
 10349          "version": "1.4.0-9+deb11u1",
 10350          "licenses": [
 10351            {
 10352              "license": {
 10353                "name": "GPL"
 10354              }
 10355            }
 10356          ],
 10357          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
 10358          "purl": "pkg:deb/debian/libpam0g@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11",
 10359          "swid": {
 10360            "attachment": {}
 10361          },
 10362          "pedigree": {},
 10363          "evidence": {},
 10364          "signature": {
 10365            "signature": {
 10366              "publicKey": {}
 10367            }
 10368          },
 10369          "modelCard": {
 10370            "modelParameters": {
 10371              "approach": {}
 10372            },
 10373            "quantitativeAnalysis": {
 10374              "graphics": {}
 10375            },
 10376            "considerations": {}
 10377          }
 10378        },
 10379        {
 10380          "type": "library",
 10381          "bom-ref": "pkg:deb/debian/libpcre2-8-0@10.36-2+deb11u1?arch=amd64\u0026upstream=pcre2\u0026distro=debian-11\u0026package-id=5d07d7ec308f6bb2",
 10382          "supplier": {},
 10383          "publisher": "Matthew Vernon \u003cmatthew@debian.org\u003e",
 10384          "name": "libpcre2-8-0",
 10385          "version": "10.36-2+deb11u1",
 10386          "cpe": "cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.36-2\\+deb11u1:*:*:*:*:*:*:*",
 10387          "purl": "pkg:deb/debian/libpcre2-8-0@10.36-2+deb11u1?arch=amd64\u0026upstream=pcre2\u0026distro=debian-11",
 10388          "swid": {
 10389            "attachment": {}
 10390          },
 10391          "pedigree": {},
 10392          "evidence": {},
 10393          "signature": {
 10394            "signature": {
 10395              "publicKey": {}
 10396            }
 10397          },
 10398          "modelCard": {
 10399            "modelParameters": {
 10400              "approach": {}
 10401            },
 10402            "quantitativeAnalysis": {
 10403              "graphics": {}
 10404            },
 10405            "considerations": {}
 10406          }
 10407        },
 10408        {
 10409          "type": "library",
 10410          "bom-ref": "pkg:deb/debian/libpcre3@2:8.39-13?arch=amd64\u0026upstream=pcre3\u0026distro=debian-11\u0026package-id=1c1641a0882b431f",
 10411          "supplier": {},
 10412          "publisher": "Matthew Vernon \u003cmatthew@debian.org\u003e",
 10413          "name": "libpcre3",
 10414          "version": "2:8.39-13",
 10415          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-13:*:*:*:*:*:*:*",
 10416          "purl": "pkg:deb/debian/libpcre3@2:8.39-13?arch=amd64\u0026upstream=pcre3\u0026distro=debian-11",
 10417          "swid": {
 10418            "attachment": {}
 10419          },
 10420          "pedigree": {},
 10421          "evidence": {},
 10422          "signature": {
 10423            "signature": {
 10424              "publicKey": {}
 10425            }
 10426          },
 10427          "modelCard": {
 10428            "modelParameters": {
 10429              "approach": {}
 10430            },
 10431            "quantitativeAnalysis": {
 10432              "graphics": {}
 10433            },
 10434            "considerations": {}
 10435          }
 10436        },
 10437        {
 10438          "type": "library",
 10439          "bom-ref": "pkg:deb/debian/libpsl5@0.21.0-1.2?arch=amd64\u0026upstream=libpsl\u0026distro=debian-11\u0026package-id=3409718c91a2d222",
 10440          "supplier": {},
 10441          "publisher": "Tim Rühsen \u003ctim.ruehsen@gmx.de\u003e",
 10442          "name": "libpsl5",
 10443          "version": "0.21.0-1.2",
 10444          "licenses": [
 10445            {
 10446              "license": {
 10447                "name": "Chromium"
 10448              }
 10449            },
 10450            {
 10451              "license": {
 10452                "id": "MIT"
 10453              }
 10454            }
 10455          ],
 10456          "cpe": "cpe:2.3:a:libpsl5:libpsl5:0.21.0-1.2:*:*:*:*:*:*:*",
 10457          "purl": "pkg:deb/debian/libpsl5@0.21.0-1.2?arch=amd64\u0026upstream=libpsl\u0026distro=debian-11",
 10458          "swid": {
 10459            "attachment": {}
 10460          },
 10461          "pedigree": {},
 10462          "evidence": {},
 10463          "signature": {
 10464            "signature": {
 10465              "publicKey": {}
 10466            }
 10467          },
 10468          "modelCard": {
 10469            "modelParameters": {
 10470              "approach": {}
 10471            },
 10472            "quantitativeAnalysis": {
 10473              "graphics": {}
 10474            },
 10475            "considerations": {}
 10476          }
 10477        },
 10478        {
 10479          "type": "library",
 10480          "bom-ref": "pkg:deb/debian/libreadline8@8.1-1?arch=amd64\u0026upstream=readline\u0026distro=debian-11\u0026package-id=348793ec2b579ee6",
 10481          "supplier": {},
 10482          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 10483          "name": "libreadline8",
 10484          "version": "8.1-1",
 10485          "licenses": [
 10486            {
 10487              "license": {
 10488                "name": "GFDL"
 10489              }
 10490            },
 10491            {
 10492              "license": {
 10493                "id": "GPL-3.0-only"
 10494              }
 10495            }
 10496          ],
 10497          "cpe": "cpe:2.3:a:libreadline8:libreadline8:8.1-1:*:*:*:*:*:*:*",
 10498          "purl": "pkg:deb/debian/libreadline8@8.1-1?arch=amd64\u0026upstream=readline\u0026distro=debian-11",
 10499          "swid": {
 10500            "attachment": {}
 10501          },
 10502          "pedigree": {},
 10503          "evidence": {},
 10504          "signature": {
 10505            "signature": {
 10506              "publicKey": {}
 10507            }
 10508          },
 10509          "modelCard": {
 10510            "modelParameters": {
 10511              "approach": {}
 10512            },
 10513            "quantitativeAnalysis": {
 10514              "graphics": {}
 10515            },
 10516            "considerations": {}
 10517          }
 10518        },
 10519        {
 10520          "type": "library",
 10521          "bom-ref": "pkg:deb/debian/librtmp1@2.4+20151223.gitfa8646d.1-2+b2?arch=amd64\u0026upstream=rtmpdump%402.4+20151223.gitfa8646d.1-2\u0026distro=debian-11\u0026package-id=4f5f3212d3812c5d",
 10522          "supplier": {},
 10523          "publisher": "Debian Multimedia Maintainers \u003cdebian-multimedia@lists.debian.org\u003e",
 10524          "name": "librtmp1",
 10525          "version": "2.4+20151223.gitfa8646d.1-2+b2",
 10526          "licenses": [
 10527            {
 10528              "license": {
 10529                "id": "GPL-2.0-only"
 10530              }
 10531            },
 10532            {
 10533              "license": {
 10534                "id": "LGPL-2.1-only"
 10535              }
 10536            }
 10537          ],
 10538          "cpe": "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20151223.gitfa8646d.1-2\\+b2:*:*:*:*:*:*:*",
 10539          "purl": "pkg:deb/debian/librtmp1@2.4+20151223.gitfa8646d.1-2+b2?arch=amd64\u0026upstream=rtmpdump%402.4+20151223.gitfa8646d.1-2\u0026distro=debian-11",
 10540          "swid": {
 10541            "attachment": {}
 10542          },
 10543          "pedigree": {},
 10544          "evidence": {},
 10545          "signature": {
 10546            "signature": {
 10547              "publicKey": {}
 10548            }
 10549          },
 10550          "modelCard": {
 10551            "modelParameters": {
 10552              "approach": {}
 10553            },
 10554            "quantitativeAnalysis": {
 10555              "graphics": {}
 10556            },
 10557            "considerations": {}
 10558          }
 10559        },
 10560        {
 10561          "type": "library",
 10562          "bom-ref": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11\u0026package-id=77ea74a82c5fc951",
 10563          "supplier": {},
 10564          "publisher": "Debian Cyrus Team \u003cteam+cyrus@tracker.debian.org\u003e",
 10565          "name": "libsasl2-2",
 10566          "version": "2.1.27+dfsg-2.1+deb11u1",
 10567          "licenses": [
 10568            {
 10569              "license": {
 10570                "id": "BSD-4-Clause"
 10571              }
 10572            },
 10573            {
 10574              "license": {
 10575                "id": "GPL-3.0-only"
 10576              }
 10577            },
 10578            {
 10579              "license": {
 10580                "id": "GPL-3.0-or-later"
 10581              }
 10582            }
 10583          ],
 10584          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-2.1\\+deb11u1:*:*:*:*:*:*:*",
 10585          "purl": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11",
 10586          "swid": {
 10587            "attachment": {}
 10588          },
 10589          "pedigree": {},
 10590          "evidence": {},
 10591          "signature": {
 10592            "signature": {
 10593              "publicKey": {}
 10594            }
 10595          },
 10596          "modelCard": {
 10597            "modelParameters": {
 10598              "approach": {}
 10599            },
 10600            "quantitativeAnalysis": {
 10601              "graphics": {}
 10602            },
 10603            "considerations": {}
 10604          }
 10605        },
 10606        {
 10607          "type": "library",
 10608          "bom-ref": "pkg:deb/debian/libsasl2-modules-db@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11\u0026package-id=1e10a1d2edb3e77a",
 10609          "supplier": {},
 10610          "publisher": "Debian Cyrus Team \u003cteam+cyrus@tracker.debian.org\u003e",
 10611          "name": "libsasl2-modules-db",
 10612          "version": "2.1.27+dfsg-2.1+deb11u1",
 10613          "licenses": [
 10614            {
 10615              "license": {
 10616                "id": "BSD-4-Clause"
 10617              }
 10618            },
 10619            {
 10620              "license": {
 10621                "id": "GPL-3.0-only"
 10622              }
 10623            },
 10624            {
 10625              "license": {
 10626                "id": "GPL-3.0-or-later"
 10627              }
 10628            }
 10629          ],
 10630          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\+dfsg-2.1\\+deb11u1:*:*:*:*:*:*:*",
 10631          "purl": "pkg:deb/debian/libsasl2-modules-db@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11",
 10632          "swid": {
 10633            "attachment": {}
 10634          },
 10635          "pedigree": {},
 10636          "evidence": {},
 10637          "signature": {
 10638            "signature": {
 10639              "publicKey": {}
 10640            }
 10641          },
 10642          "modelCard": {
 10643            "modelParameters": {
 10644              "approach": {}
 10645            },
 10646            "quantitativeAnalysis": {
 10647              "graphics": {}
 10648            },
 10649            "considerations": {}
 10650          }
 10651        },
 10652        {
 10653          "type": "library",
 10654          "bom-ref": "pkg:deb/debian/libseccomp2@2.5.1-1+deb11u1?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-11\u0026package-id=bb0878d1437830b4",
 10655          "supplier": {},
 10656          "publisher": "Kees Cook \u003ckees@debian.org\u003e",
 10657          "name": "libseccomp2",
 10658          "version": "2.5.1-1+deb11u1",
 10659          "licenses": [
 10660            {
 10661              "license": {
 10662                "id": "LGPL-2.1-only"
 10663              }
 10664            }
 10665          ],
 10666          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.5.1-1\\+deb11u1:*:*:*:*:*:*:*",
 10667          "purl": "pkg:deb/debian/libseccomp2@2.5.1-1+deb11u1?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-11",
 10668          "swid": {
 10669            "attachment": {}
 10670          },
 10671          "pedigree": {},
 10672          "evidence": {},
 10673          "signature": {
 10674            "signature": {
 10675              "publicKey": {}
 10676            }
 10677          },
 10678          "modelCard": {
 10679            "modelParameters": {
 10680              "approach": {}
 10681            },
 10682            "quantitativeAnalysis": {
 10683              "graphics": {}
 10684            },
 10685            "considerations": {}
 10686          }
 10687        },
 10688        {
 10689          "type": "library",
 10690          "bom-ref": "pkg:deb/debian/libselinux1@3.1-3?arch=amd64\u0026upstream=libselinux\u0026distro=debian-11\u0026package-id=bb9d0a1adefb7931",
 10691          "supplier": {},
 10692          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 10693          "name": "libselinux1",
 10694          "version": "3.1-3",
 10695          "licenses": [
 10696            {
 10697              "license": {
 10698                "id": "GPL-2.0-only"
 10699              }
 10700            },
 10701            {
 10702              "license": {
 10703                "id": "LGPL-2.1-only"
 10704              }
 10705            }
 10706          ],
 10707          "cpe": "cpe:2.3:a:libselinux1:libselinux1:3.1-3:*:*:*:*:*:*:*",
 10708          "purl": "pkg:deb/debian/libselinux1@3.1-3?arch=amd64\u0026upstream=libselinux\u0026distro=debian-11",
 10709          "swid": {
 10710            "attachment": {}
 10711          },
 10712          "pedigree": {},
 10713          "evidence": {},
 10714          "signature": {
 10715            "signature": {
 10716              "publicKey": {}
 10717            }
 10718          },
 10719          "modelCard": {
 10720            "modelParameters": {
 10721              "approach": {}
 10722            },
 10723            "quantitativeAnalysis": {
 10724              "graphics": {}
 10725            },
 10726            "considerations": {}
 10727          }
 10728        },
 10729        {
 10730          "type": "library",
 10731          "bom-ref": "pkg:deb/debian/libsemanage-common@3.1-1?arch=all\u0026upstream=libsemanage\u0026distro=debian-11\u0026package-id=f41fe741bd23f493",
 10732          "supplier": {},
 10733          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 10734          "name": "libsemanage-common",
 10735          "version": "3.1-1",
 10736          "licenses": [
 10737            {
 10738              "license": {
 10739                "name": "GPL"
 10740              }
 10741            },
 10742            {
 10743              "license": {
 10744                "name": "LGPL"
 10745              }
 10746            }
 10747          ],
 10748          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:3.1-1:*:*:*:*:*:*:*",
 10749          "purl": "pkg:deb/debian/libsemanage-common@3.1-1?arch=all\u0026upstream=libsemanage\u0026distro=debian-11",
 10750          "swid": {
 10751            "attachment": {}
 10752          },
 10753          "pedigree": {},
 10754          "evidence": {},
 10755          "signature": {
 10756            "signature": {
 10757              "publicKey": {}
 10758            }
 10759          },
 10760          "modelCard": {
 10761            "modelParameters": {
 10762              "approach": {}
 10763            },
 10764            "quantitativeAnalysis": {
 10765              "graphics": {}
 10766            },
 10767            "considerations": {}
 10768          }
 10769        },
 10770        {
 10771          "type": "library",
 10772          "bom-ref": "pkg:deb/debian/libsemanage1@3.1-1+b2?arch=amd64\u0026upstream=libsemanage%403.1-1\u0026distro=debian-11\u0026package-id=fa4813c20a8027a6",
 10773          "supplier": {},
 10774          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 10775          "name": "libsemanage1",
 10776          "version": "3.1-1+b2",
 10777          "licenses": [
 10778            {
 10779              "license": {
 10780                "name": "GPL"
 10781              }
 10782            },
 10783            {
 10784              "license": {
 10785                "name": "LGPL"
 10786              }
 10787            }
 10788          ],
 10789          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:3.1-1\\+b2:*:*:*:*:*:*:*",
 10790          "purl": "pkg:deb/debian/libsemanage1@3.1-1+b2?arch=amd64\u0026upstream=libsemanage%403.1-1\u0026distro=debian-11",
 10791          "swid": {
 10792            "attachment": {}
 10793          },
 10794          "pedigree": {},
 10795          "evidence": {},
 10796          "signature": {
 10797            "signature": {
 10798              "publicKey": {}
 10799            }
 10800          },
 10801          "modelCard": {
 10802            "modelParameters": {
 10803              "approach": {}
 10804            },
 10805            "quantitativeAnalysis": {
 10806              "graphics": {}
 10807            },
 10808            "considerations": {}
 10809          }
 10810        },
 10811        {
 10812          "type": "library",
 10813          "bom-ref": "pkg:deb/debian/libsepol1@3.1-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-11\u0026package-id=cfa6f496d2fd049",
 10814          "supplier": {},
 10815          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 10816          "name": "libsepol1",
 10817          "version": "3.1-1",
 10818          "licenses": [
 10819            {
 10820              "license": {
 10821                "name": "GPL"
 10822              }
 10823            },
 10824            {
 10825              "license": {
 10826                "name": "LGPL"
 10827              }
 10828            }
 10829          ],
 10830          "cpe": "cpe:2.3:a:libsepol1:libsepol1:3.1-1:*:*:*:*:*:*:*",
 10831          "purl": "pkg:deb/debian/libsepol1@3.1-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-11",
 10832          "swid": {
 10833            "attachment": {}
 10834          },
 10835          "pedigree": {},
 10836          "evidence": {},
 10837          "signature": {
 10838            "signature": {
 10839              "publicKey": {}
 10840            }
 10841          },
 10842          "modelCard": {
 10843            "modelParameters": {
 10844              "approach": {}
 10845            },
 10846            "quantitativeAnalysis": {
 10847              "graphics": {}
 10848            },
 10849            "considerations": {}
 10850          }
 10851        },
 10852        {
 10853          "type": "library",
 10854          "bom-ref": "pkg:deb/debian/libsmartcols1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=cf3b22adc552a311",
 10855          "supplier": {},
 10856          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 10857          "name": "libsmartcols1",
 10858          "version": "2.36.1-8+deb11u1",
 10859          "licenses": [
 10860            {
 10861              "license": {
 10862                "id": "BSD-2-Clause"
 10863              }
 10864            },
 10865            {
 10866              "license": {
 10867                "id": "BSD-3-Clause"
 10868              }
 10869            },
 10870            {
 10871              "license": {
 10872                "id": "BSD-4-Clause"
 10873              }
 10874            },
 10875            {
 10876              "license": {
 10877                "id": "GPL-2.0-only"
 10878              }
 10879            },
 10880            {
 10881              "license": {
 10882                "id": "GPL-2.0-or-later"
 10883              }
 10884            },
 10885            {
 10886              "license": {
 10887                "id": "GPL-3.0-only"
 10888              }
 10889            },
 10890            {
 10891              "license": {
 10892                "id": "GPL-3.0-or-later"
 10893              }
 10894            },
 10895            {
 10896              "license": {
 10897                "name": "LGPL"
 10898              }
 10899            },
 10900            {
 10901              "license": {
 10902                "id": "LGPL-2.0-only"
 10903              }
 10904            },
 10905            {
 10906              "license": {
 10907                "id": "LGPL-2.0-or-later"
 10908              }
 10909            },
 10910            {
 10911              "license": {
 10912                "id": "LGPL-2.1-only"
 10913              }
 10914            },
 10915            {
 10916              "license": {
 10917                "id": "LGPL-2.1-or-later"
 10918              }
 10919            },
 10920            {
 10921              "license": {
 10922                "id": "LGPL-3.0-only"
 10923              }
 10924            },
 10925            {
 10926              "license": {
 10927                "id": "LGPL-3.0-or-later"
 10928              }
 10929            },
 10930            {
 10931              "license": {
 10932                "id": "MIT"
 10933              }
 10934            },
 10935            {
 10936              "license": {
 10937                "name": "public-domain"
 10938              }
 10939            }
 10940          ],
 10941          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 10942          "purl": "pkg:deb/debian/libsmartcols1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
 10943          "swid": {
 10944            "attachment": {}
 10945          },
 10946          "pedigree": {},
 10947          "evidence": {},
 10948          "signature": {
 10949            "signature": {
 10950              "publicKey": {}
 10951            }
 10952          },
 10953          "modelCard": {
 10954            "modelParameters": {
 10955              "approach": {}
 10956            },
 10957            "quantitativeAnalysis": {
 10958              "graphics": {}
 10959            },
 10960            "considerations": {}
 10961          }
 10962        },
 10963        {
 10964          "type": "library",
 10965          "bom-ref": "pkg:deb/debian/libsqlite3-0@3.34.1-3?arch=amd64\u0026upstream=sqlite3\u0026distro=debian-11\u0026package-id=373ed1f8b8bffc03",
 10966          "supplier": {},
 10967          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
 10968          "name": "libsqlite3-0",
 10969          "version": "3.34.1-3",
 10970          "licenses": [
 10971            {
 10972              "license": {
 10973                "id": "GPL-2.0-only"
 10974              }
 10975            },
 10976            {
 10977              "license": {
 10978                "id": "GPL-2.0-or-later"
 10979              }
 10980            },
 10981            {
 10982              "license": {
 10983                "name": "public-domain"
 10984              }
 10985            }
 10986          ],
 10987          "cpe": "cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.34.1-3:*:*:*:*:*:*:*",
 10988          "purl": "pkg:deb/debian/libsqlite3-0@3.34.1-3?arch=amd64\u0026upstream=sqlite3\u0026distro=debian-11",
 10989          "swid": {
 10990            "attachment": {}
 10991          },
 10992          "pedigree": {},
 10993          "evidence": {},
 10994          "signature": {
 10995            "signature": {
 10996              "publicKey": {}
 10997            }
 10998          },
 10999          "modelCard": {
 11000            "modelParameters": {
 11001              "approach": {}
 11002            },
 11003            "quantitativeAnalysis": {
 11004              "graphics": {}
 11005            },
 11006            "considerations": {}
 11007          }
 11008        },
 11009        {
 11010          "type": "library",
 11011          "bom-ref": "pkg:deb/debian/libss2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=4ba13b2c11cb0876",
 11012          "supplier": {},
 11013          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 11014          "name": "libss2",
 11015          "version": "1.46.2-2",
 11016          "cpe": "cpe:2.3:a:libss2:libss2:1.46.2-2:*:*:*:*:*:*:*",
 11017          "purl": "pkg:deb/debian/libss2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
 11018          "swid": {
 11019            "attachment": {}
 11020          },
 11021          "pedigree": {},
 11022          "evidence": {},
 11023          "signature": {
 11024            "signature": {
 11025              "publicKey": {}
 11026            }
 11027          },
 11028          "modelCard": {
 11029            "modelParameters": {
 11030              "approach": {}
 11031            },
 11032            "quantitativeAnalysis": {
 11033              "graphics": {}
 11034            },
 11035            "considerations": {}
 11036          }
 11037        },
 11038        {
 11039          "type": "library",
 11040          "bom-ref": "pkg:deb/debian/libssh2-1@1.9.0-2?arch=amd64\u0026upstream=libssh2\u0026distro=debian-11\u0026package-id=7b11dbeecfce2854",
 11041          "supplier": {},
 11042          "publisher": "Nicolas Mora \u003cbabelouest@debian.org\u003e",
 11043          "name": "libssh2-1",
 11044          "version": "1.9.0-2",
 11045          "licenses": [
 11046            {
 11047              "license": {
 11048                "name": "BSD3"
 11049              }
 11050            }
 11051          ],
 11052          "cpe": "cpe:2.3:a:libssh2-1:libssh2-1:1.9.0-2:*:*:*:*:*:*:*",
 11053          "purl": "pkg:deb/debian/libssh2-1@1.9.0-2?arch=amd64\u0026upstream=libssh2\u0026distro=debian-11",
 11054          "swid": {
 11055            "attachment": {}
 11056          },
 11057          "pedigree": {},
 11058          "evidence": {},
 11059          "signature": {
 11060            "signature": {
 11061              "publicKey": {}
 11062            }
 11063          },
 11064          "modelCard": {
 11065            "modelParameters": {
 11066              "approach": {}
 11067            },
 11068            "quantitativeAnalysis": {
 11069              "graphics": {}
 11070            },
 11071            "considerations": {}
 11072          }
 11073        },
 11074        {
 11075          "type": "library",
 11076          "bom-ref": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u4?arch=amd64\u0026upstream=openssl\u0026distro=debian-11\u0026package-id=63a11d0164944054",
 11077          "supplier": {},
 11078          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
 11079          "name": "libssl1.1",
 11080          "version": "1.1.1n-0+deb11u4",
 11081          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1n-0\\+deb11u4:*:*:*:*:*:*:*",
 11082          "purl": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u4?arch=amd64\u0026upstream=openssl\u0026distro=debian-11",
 11083          "swid": {
 11084            "attachment": {}
 11085          },
 11086          "pedigree": {},
 11087          "evidence": {},
 11088          "signature": {
 11089            "signature": {
 11090              "publicKey": {}
 11091            }
 11092          },
 11093          "modelCard": {
 11094            "modelParameters": {
 11095              "approach": {}
 11096            },
 11097            "quantitativeAnalysis": {
 11098              "graphics": {}
 11099            },
 11100            "considerations": {}
 11101          }
 11102        },
 11103        {
 11104          "type": "library",
 11105          "bom-ref": "pkg:deb/debian/libstdc++6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=748369630632944",
 11106          "supplier": {},
 11107          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 11108          "name": "libstdc++6",
 11109          "version": "10.2.1-6",
 11110          "licenses": [
 11111            {
 11112              "license": {
 11113                "name": "Artistic"
 11114              }
 11115            },
 11116            {
 11117              "license": {
 11118                "id": "GFDL-1.2-only"
 11119              }
 11120            },
 11121            {
 11122              "license": {
 11123                "name": "GPL"
 11124              }
 11125            },
 11126            {
 11127              "license": {
 11128                "id": "GPL-2.0-only"
 11129              }
 11130            },
 11131            {
 11132              "license": {
 11133                "id": "GPL-3.0-only"
 11134              }
 11135            },
 11136            {
 11137              "license": {
 11138                "name": "LGPL"
 11139              }
 11140            }
 11141          ],
 11142          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.2.1-6:*:*:*:*:*:*:*",
 11143          "purl": "pkg:deb/debian/libstdc++6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
 11144          "swid": {
 11145            "attachment": {}
 11146          },
 11147          "pedigree": {},
 11148          "evidence": {},
 11149          "signature": {
 11150            "signature": {
 11151              "publicKey": {}
 11152            }
 11153          },
 11154          "modelCard": {
 11155            "modelParameters": {
 11156              "approach": {}
 11157            },
 11158            "quantitativeAnalysis": {
 11159              "graphics": {}
 11160            },
 11161            "considerations": {}
 11162          }
 11163        },
 11164        {
 11165          "type": "library",
 11166          "bom-ref": "pkg:deb/debian/libsystemd0@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11\u0026package-id=4c258dc3b086d634",
 11167          "supplier": {},
 11168          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 11169          "name": "libsystemd0",
 11170          "version": "247.3-7+deb11u1",
 11171          "licenses": [
 11172            {
 11173              "license": {
 11174                "id": "CC0-1.0"
 11175              }
 11176            },
 11177            {
 11178              "license": {
 11179                "name": "Expat"
 11180              }
 11181            },
 11182            {
 11183              "license": {
 11184                "id": "GPL-2.0-only"
 11185              }
 11186            },
 11187            {
 11188              "license": {
 11189                "id": "GPL-2.0-or-later"
 11190              }
 11191            },
 11192            {
 11193              "license": {
 11194                "id": "LGPL-2.1-only"
 11195              }
 11196            },
 11197            {
 11198              "license": {
 11199                "id": "LGPL-2.1-or-later"
 11200              }
 11201            },
 11202            {
 11203              "license": {
 11204                "name": "public-domain"
 11205              }
 11206            }
 11207          ],
 11208          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:247.3-7\\+deb11u1:*:*:*:*:*:*:*",
 11209          "purl": "pkg:deb/debian/libsystemd0@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11",
 11210          "swid": {
 11211            "attachment": {}
 11212          },
 11213          "pedigree": {},
 11214          "evidence": {},
 11215          "signature": {
 11216            "signature": {
 11217              "publicKey": {}
 11218            }
 11219          },
 11220          "modelCard": {
 11221            "modelParameters": {
 11222              "approach": {}
 11223            },
 11224            "quantitativeAnalysis": {
 11225              "graphics": {}
 11226            },
 11227            "considerations": {}
 11228          }
 11229        },
 11230        {
 11231          "type": "library",
 11232          "bom-ref": "pkg:deb/debian/libtasn1-6@4.16.0-2+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=74865cf2744adb90",
 11233          "supplier": {},
 11234          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 11235          "name": "libtasn1-6",
 11236          "version": "4.16.0-2+deb11u1",
 11237          "licenses": [
 11238            {
 11239              "license": {
 11240                "id": "GFDL-1.3-only"
 11241              }
 11242            },
 11243            {
 11244              "license": {
 11245                "id": "GPL-3.0-only"
 11246              }
 11247            },
 11248            {
 11249              "license": {
 11250                "name": "LGPL"
 11251              }
 11252            },
 11253            {
 11254              "license": {
 11255                "id": "LGPL-2.1-only"
 11256              }
 11257            }
 11258          ],
 11259          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2\\+deb11u1:*:*:*:*:*:*:*",
 11260          "purl": "pkg:deb/debian/libtasn1-6@4.16.0-2+deb11u1?arch=amd64\u0026distro=debian-11",
 11261          "swid": {
 11262            "attachment": {}
 11263          },
 11264          "pedigree": {},
 11265          "evidence": {},
 11266          "signature": {
 11267            "signature": {
 11268              "publicKey": {}
 11269            }
 11270          },
 11271          "modelCard": {
 11272            "modelParameters": {
 11273              "approach": {}
 11274            },
 11275            "quantitativeAnalysis": {
 11276              "graphics": {}
 11277            },
 11278            "considerations": {}
 11279          }
 11280        },
 11281        {
 11282          "type": "library",
 11283          "bom-ref": "pkg:deb/debian/libtinfo6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=9e96601b60336037",
 11284          "supplier": {},
 11285          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 11286          "name": "libtinfo6",
 11287          "version": "6.2+20201114-2",
 11288          "licenses": [
 11289            {
 11290              "license": {
 11291                "id": "BSD-3-Clause"
 11292              }
 11293            },
 11294            {
 11295              "license": {
 11296                "name": "MIT/X11"
 11297              }
 11298            },
 11299            {
 11300              "license": {
 11301                "id": "X11"
 11302              }
 11303            }
 11304          ],
 11305          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.2\\+20201114-2:*:*:*:*:*:*:*",
 11306          "purl": "pkg:deb/debian/libtinfo6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11",
 11307          "swid": {
 11308            "attachment": {}
 11309          },
 11310          "pedigree": {},
 11311          "evidence": {},
 11312          "signature": {
 11313            "signature": {
 11314              "publicKey": {}
 11315            }
 11316          },
 11317          "modelCard": {
 11318            "modelParameters": {
 11319              "approach": {}
 11320            },
 11321            "quantitativeAnalysis": {
 11322              "graphics": {}
 11323            },
 11324            "considerations": {}
 11325          }
 11326        },
 11327        {
 11328          "type": "library",
 11329          "bom-ref": "pkg:deb/debian/libtirpc-common@1.3.1-1+deb11u1?arch=all\u0026upstream=libtirpc\u0026distro=debian-11\u0026package-id=3623a1ef0b5b63b9",
 11330          "supplier": {},
 11331          "publisher": "Josue Ortega \u003cjosue@debian.org\u003e",
 11332          "name": "libtirpc-common",
 11333          "version": "1.3.1-1+deb11u1",
 11334          "licenses": [
 11335            {
 11336              "license": {
 11337                "id": "BSD-3-Clause"
 11338              }
 11339            },
 11340            {
 11341              "license": {
 11342                "id": "GPL-2.0-only"
 11343              }
 11344            },
 11345            {
 11346              "license": {
 11347                "id": "LGPL-2.1-only"
 11348              }
 11349            }
 11350          ],
 11351          "cpe": "cpe:2.3:a:libtirpc-common:libtirpc-common:1.3.1-1\\+deb11u1:*:*:*:*:*:*:*",
 11352          "purl": "pkg:deb/debian/libtirpc-common@1.3.1-1+deb11u1?arch=all\u0026upstream=libtirpc\u0026distro=debian-11",
 11353          "swid": {
 11354            "attachment": {}
 11355          },
 11356          "pedigree": {},
 11357          "evidence": {},
 11358          "signature": {
 11359            "signature": {
 11360              "publicKey": {}
 11361            }
 11362          },
 11363          "modelCard": {
 11364            "modelParameters": {
 11365              "approach": {}
 11366            },
 11367            "quantitativeAnalysis": {
 11368              "graphics": {}
 11369            },
 11370            "considerations": {}
 11371          }
 11372        },
 11373        {
 11374          "type": "library",
 11375          "bom-ref": "pkg:deb/debian/libtirpc3@1.3.1-1+deb11u1?arch=amd64\u0026upstream=libtirpc\u0026distro=debian-11\u0026package-id=c7b97f0b9d21e851",
 11376          "supplier": {},
 11377          "publisher": "Josue Ortega \u003cjosue@debian.org\u003e",
 11378          "name": "libtirpc3",
 11379          "version": "1.3.1-1+deb11u1",
 11380          "licenses": [
 11381            {
 11382              "license": {
 11383                "id": "BSD-3-Clause"
 11384              }
 11385            },
 11386            {
 11387              "license": {
 11388                "id": "GPL-2.0-only"
 11389              }
 11390            },
 11391            {
 11392              "license": {
 11393                "id": "LGPL-2.1-only"
 11394              }
 11395            }
 11396          ],
 11397          "cpe": "cpe:2.3:a:libtirpc3:libtirpc3:1.3.1-1\\+deb11u1:*:*:*:*:*:*:*",
 11398          "purl": "pkg:deb/debian/libtirpc3@1.3.1-1+deb11u1?arch=amd64\u0026upstream=libtirpc\u0026distro=debian-11",
 11399          "swid": {
 11400            "attachment": {}
 11401          },
 11402          "pedigree": {},
 11403          "evidence": {},
 11404          "signature": {
 11405            "signature": {
 11406              "publicKey": {}
 11407            }
 11408          },
 11409          "modelCard": {
 11410            "modelParameters": {
 11411              "approach": {}
 11412            },
 11413            "quantitativeAnalysis": {
 11414              "graphics": {}
 11415            },
 11416            "considerations": {}
 11417          }
 11418        },
 11419        {
 11420          "type": "library",
 11421          "bom-ref": "pkg:deb/debian/libudev1@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11\u0026package-id=79c718cff72e218e",
 11422          "supplier": {},
 11423          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 11424          "name": "libudev1",
 11425          "version": "247.3-7+deb11u1",
 11426          "licenses": [
 11427            {
 11428              "license": {
 11429                "id": "CC0-1.0"
 11430              }
 11431            },
 11432            {
 11433              "license": {
 11434                "name": "Expat"
 11435              }
 11436            },
 11437            {
 11438              "license": {
 11439                "id": "GPL-2.0-only"
 11440              }
 11441            },
 11442            {
 11443              "license": {
 11444                "id": "GPL-2.0-or-later"
 11445              }
 11446            },
 11447            {
 11448              "license": {
 11449                "id": "LGPL-2.1-only"
 11450              }
 11451            },
 11452            {
 11453              "license": {
 11454                "id": "LGPL-2.1-or-later"
 11455              }
 11456            },
 11457            {
 11458              "license": {
 11459                "name": "public-domain"
 11460              }
 11461            }
 11462          ],
 11463          "cpe": "cpe:2.3:a:libudev1:libudev1:247.3-7\\+deb11u1:*:*:*:*:*:*:*",
 11464          "purl": "pkg:deb/debian/libudev1@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11",
 11465          "swid": {
 11466            "attachment": {}
 11467          },
 11468          "pedigree": {},
 11469          "evidence": {},
 11470          "signature": {
 11471            "signature": {
 11472              "publicKey": {}
 11473            }
 11474          },
 11475          "modelCard": {
 11476            "modelParameters": {
 11477              "approach": {}
 11478            },
 11479            "quantitativeAnalysis": {
 11480              "graphics": {}
 11481            },
 11482            "considerations": {}
 11483          }
 11484        },
 11485        {
 11486          "type": "library",
 11487          "bom-ref": "pkg:deb/debian/libunistring2@0.9.10-4?arch=amd64\u0026upstream=libunistring\u0026distro=debian-11\u0026package-id=dc7fcfc9dde2b703",
 11488          "supplier": {},
 11489          "publisher": "Jörg Frings-Fürst \u003cdebian@jff.email\u003e",
 11490          "name": "libunistring2",
 11491          "version": "0.9.10-4",
 11492          "licenses": [
 11493            {
 11494              "license": {
 11495                "name": "FreeSoftware"
 11496              }
 11497            },
 11498            {
 11499              "license": {
 11500                "id": "GFDL-1.2-only"
 11501              }
 11502            },
 11503            {
 11504              "license": {
 11505                "name": "GFDL-1.2+"
 11506              }
 11507            },
 11508            {
 11509              "license": {
 11510                "id": "GPL-2.0-only"
 11511              }
 11512            },
 11513            {
 11514              "license": {
 11515                "id": "GPL-2.0-or-later"
 11516              }
 11517            },
 11518            {
 11519              "license": {
 11520                "id": "GPL-3.0-only"
 11521              }
 11522            },
 11523            {
 11524              "license": {
 11525                "id": "GPL-3.0-or-later"
 11526              }
 11527            },
 11528            {
 11529              "license": {
 11530                "id": "LGPL-3.0-only"
 11531              }
 11532            },
 11533            {
 11534              "license": {
 11535                "id": "LGPL-3.0-or-later"
 11536              }
 11537            },
 11538            {
 11539              "license": {
 11540                "id": "MIT"
 11541              }
 11542            }
 11543          ],
 11544          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-4:*:*:*:*:*:*:*",
 11545          "purl": "pkg:deb/debian/libunistring2@0.9.10-4?arch=amd64\u0026upstream=libunistring\u0026distro=debian-11",
 11546          "swid": {
 11547            "attachment": {}
 11548          },
 11549          "pedigree": {},
 11550          "evidence": {},
 11551          "signature": {
 11552            "signature": {
 11553              "publicKey": {}
 11554            }
 11555          },
 11556          "modelCard": {
 11557            "modelParameters": {
 11558              "approach": {}
 11559            },
 11560            "quantitativeAnalysis": {
 11561              "graphics": {}
 11562            },
 11563            "considerations": {}
 11564          }
 11565        },
 11566        {
 11567          "type": "library",
 11568          "bom-ref": "pkg:deb/debian/libuuid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=e87310d3e1426d6c",
 11569          "supplier": {},
 11570          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 11571          "name": "libuuid1",
 11572          "version": "2.36.1-8+deb11u1",
 11573          "licenses": [
 11574            {
 11575              "license": {
 11576                "id": "BSD-2-Clause"
 11577              }
 11578            },
 11579            {
 11580              "license": {
 11581                "id": "BSD-3-Clause"
 11582              }
 11583            },
 11584            {
 11585              "license": {
 11586                "id": "BSD-4-Clause"
 11587              }
 11588            },
 11589            {
 11590              "license": {
 11591                "id": "GPL-2.0-only"
 11592              }
 11593            },
 11594            {
 11595              "license": {
 11596                "id": "GPL-2.0-or-later"
 11597              }
 11598            },
 11599            {
 11600              "license": {
 11601                "id": "GPL-3.0-only"
 11602              }
 11603            },
 11604            {
 11605              "license": {
 11606                "id": "GPL-3.0-or-later"
 11607              }
 11608            },
 11609            {
 11610              "license": {
 11611                "name": "LGPL"
 11612              }
 11613            },
 11614            {
 11615              "license": {
 11616                "id": "LGPL-2.0-only"
 11617              }
 11618            },
 11619            {
 11620              "license": {
 11621                "id": "LGPL-2.0-or-later"
 11622              }
 11623            },
 11624            {
 11625              "license": {
 11626                "id": "LGPL-2.1-only"
 11627              }
 11628            },
 11629            {
 11630              "license": {
 11631                "id": "LGPL-2.1-or-later"
 11632              }
 11633            },
 11634            {
 11635              "license": {
 11636                "id": "LGPL-3.0-only"
 11637              }
 11638            },
 11639            {
 11640              "license": {
 11641                "id": "LGPL-3.0-or-later"
 11642              }
 11643            },
 11644            {
 11645              "license": {
 11646                "id": "MIT"
 11647              }
 11648            },
 11649            {
 11650              "license": {
 11651                "name": "public-domain"
 11652              }
 11653            }
 11654          ],
 11655          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 11656          "purl": "pkg:deb/debian/libuuid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
 11657          "swid": {
 11658            "attachment": {}
 11659          },
 11660          "pedigree": {},
 11661          "evidence": {},
 11662          "signature": {
 11663            "signature": {
 11664              "publicKey": {}
 11665            }
 11666          },
 11667          "modelCard": {
 11668            "modelParameters": {
 11669              "approach": {}
 11670            },
 11671            "quantitativeAnalysis": {
 11672              "graphics": {}
 11673            },
 11674            "considerations": {}
 11675          }
 11676        },
 11677        {
 11678          "type": "library",
 11679          "bom-ref": "pkg:deb/debian/libxxhash0@0.8.0-2?arch=amd64\u0026upstream=xxhash\u0026distro=debian-11\u0026package-id=edc71d7591d40133",
 11680          "supplier": {},
 11681          "publisher": "Norbert Preining \u003cnorbert@preining.info\u003e",
 11682          "name": "libxxhash0",
 11683          "version": "0.8.0-2",
 11684          "licenses": [
 11685            {
 11686              "license": {
 11687                "id": "BSD-2-Clause"
 11688              }
 11689            },
 11690            {
 11691              "license": {
 11692                "id": "GPL-2.0-only"
 11693              }
 11694            }
 11695          ],
 11696          "cpe": "cpe:2.3:a:libxxhash0:libxxhash0:0.8.0-2:*:*:*:*:*:*:*",
 11697          "purl": "pkg:deb/debian/libxxhash0@0.8.0-2?arch=amd64\u0026upstream=xxhash\u0026distro=debian-11",
 11698          "swid": {
 11699            "attachment": {}
 11700          },
 11701          "pedigree": {},
 11702          "evidence": {},
 11703          "signature": {
 11704            "signature": {
 11705              "publicKey": {}
 11706            }
 11707          },
 11708          "modelCard": {
 11709            "modelParameters": {
 11710              "approach": {}
 11711            },
 11712            "quantitativeAnalysis": {
 11713              "graphics": {}
 11714            },
 11715            "considerations": {}
 11716          }
 11717        },
 11718        {
 11719          "type": "library",
 11720          "bom-ref": "pkg:deb/debian/libzstd1@1.4.8+dfsg-2.1?arch=amd64\u0026upstream=libzstd\u0026distro=debian-11\u0026package-id=90e1680def07a674",
 11721          "supplier": {},
 11722          "publisher": "Debian Med Packaging Team \u003cdebian-med-packaging@lists.alioth.debian.org\u003e",
 11723          "name": "libzstd1",
 11724          "version": "1.4.8+dfsg-2.1",
 11725          "licenses": [
 11726            {
 11727              "license": {
 11728                "id": "BSD-3-Clause"
 11729              }
 11730            },
 11731            {
 11732              "license": {
 11733                "name": "Expat"
 11734              }
 11735            },
 11736            {
 11737              "license": {
 11738                "id": "GPL-2.0-only"
 11739              }
 11740            },
 11741            {
 11742              "license": {
 11743                "id": "Zlib"
 11744              }
 11745            }
 11746          ],
 11747          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.8\\+dfsg-2.1:*:*:*:*:*:*:*",
 11748          "purl": "pkg:deb/debian/libzstd1@1.4.8+dfsg-2.1?arch=amd64\u0026upstream=libzstd\u0026distro=debian-11",
 11749          "swid": {
 11750            "attachment": {}
 11751          },
 11752          "pedigree": {},
 11753          "evidence": {},
 11754          "signature": {
 11755            "signature": {
 11756              "publicKey": {}
 11757            }
 11758          },
 11759          "modelCard": {
 11760            "modelParameters": {
 11761              "approach": {}
 11762            },
 11763            "quantitativeAnalysis": {
 11764              "graphics": {}
 11765            },
 11766            "considerations": {}
 11767          }
 11768        },
 11769        {
 11770          "type": "library",
 11771          "bom-ref": "pkg:deb/debian/login@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11\u0026package-id=9cdbb92ea69c08a1",
 11772          "supplier": {},
 11773          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
 11774          "name": "login",
 11775          "version": "1:4.8.1-1",
 11776          "licenses": [
 11777            {
 11778              "license": {
 11779                "id": "GPL-2.0-only"
 11780              }
 11781            }
 11782          ],
 11783          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1:*:*:*:*:*:*:*",
 11784          "purl": "pkg:deb/debian/login@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11",
 11785          "swid": {
 11786            "attachment": {}
 11787          },
 11788          "pedigree": {},
 11789          "evidence": {},
 11790          "signature": {
 11791            "signature": {
 11792              "publicKey": {}
 11793            }
 11794          },
 11795          "modelCard": {
 11796            "modelParameters": {
 11797              "approach": {}
 11798            },
 11799            "quantitativeAnalysis": {
 11800              "graphics": {}
 11801            },
 11802            "considerations": {}
 11803          }
 11804        },
 11805        {
 11806          "type": "library",
 11807          "bom-ref": "pkg:deb/debian/logsave@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=77e8cce6db62952b",
 11808          "supplier": {},
 11809          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 11810          "name": "logsave",
 11811          "version": "1.46.2-2",
 11812          "licenses": [
 11813            {
 11814              "license": {
 11815                "id": "GPL-2.0-only"
 11816              }
 11817            },
 11818            {
 11819              "license": {
 11820                "id": "LGPL-2.0-only"
 11821              }
 11822            }
 11823          ],
 11824          "cpe": "cpe:2.3:a:logsave:logsave:1.46.2-2:*:*:*:*:*:*:*",
 11825          "purl": "pkg:deb/debian/logsave@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
 11826          "swid": {
 11827            "attachment": {}
 11828          },
 11829          "pedigree": {},
 11830          "evidence": {},
 11831          "signature": {
 11832            "signature": {
 11833              "publicKey": {}
 11834            }
 11835          },
 11836          "modelCard": {
 11837            "modelParameters": {
 11838              "approach": {}
 11839            },
 11840            "quantitativeAnalysis": {
 11841              "graphics": {}
 11842            },
 11843            "considerations": {}
 11844          }
 11845        },
 11846        {
 11847          "type": "library",
 11848          "bom-ref": "pkg:deb/debian/lsb-base@11.1.0?arch=all\u0026upstream=lsb\u0026distro=debian-11\u0026package-id=67f43d818d5952cf",
 11849          "supplier": {},
 11850          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
 11851          "name": "lsb-base",
 11852          "version": "11.1.0",
 11853          "licenses": [
 11854            {
 11855              "license": {
 11856                "id": "BSD-3-Clause"
 11857              }
 11858            },
 11859            {
 11860              "license": {
 11861                "id": "GPL-2.0-only"
 11862              }
 11863            }
 11864          ],
 11865          "cpe": "cpe:2.3:a:lsb-base:lsb-base:11.1.0:*:*:*:*:*:*:*",
 11866          "purl": "pkg:deb/debian/lsb-base@11.1.0?arch=all\u0026upstream=lsb\u0026distro=debian-11",
 11867          "swid": {
 11868            "attachment": {}
 11869          },
 11870          "pedigree": {},
 11871          "evidence": {},
 11872          "signature": {
 11873            "signature": {
 11874              "publicKey": {}
 11875            }
 11876          },
 11877          "modelCard": {
 11878            "modelParameters": {
 11879              "approach": {}
 11880            },
 11881            "quantitativeAnalysis": {
 11882              "graphics": {}
 11883            },
 11884            "considerations": {}
 11885          }
 11886        },
 11887        {
 11888          "type": "library",
 11889          "bom-ref": "pkg:deb/debian/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=debian-11\u0026package-id=b91e181aea759ff5",
 11890          "supplier": {},
 11891          "publisher": "Boyuan Yang \u003cbyang@debian.org\u003e",
 11892          "name": "mawk",
 11893          "version": "1.3.4.20200120-2",
 11894          "licenses": [
 11895            {
 11896              "license": {
 11897                "id": "GPL-2.0-only"
 11898              }
 11899            }
 11900          ],
 11901          "cpe": "cpe:2.3:a:mawk:mawk:1.3.4.20200120-2:*:*:*:*:*:*:*",
 11902          "purl": "pkg:deb/debian/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=debian-11",
 11903          "swid": {
 11904            "attachment": {}
 11905          },
 11906          "pedigree": {},
 11907          "evidence": {},
 11908          "signature": {
 11909            "signature": {
 11910              "publicKey": {}
 11911            }
 11912          },
 11913          "modelCard": {
 11914            "modelParameters": {
 11915              "approach": {}
 11916            },
 11917            "quantitativeAnalysis": {
 11918              "graphics": {}
 11919            },
 11920            "considerations": {}
 11921          }
 11922        },
 11923        {
 11924          "type": "library",
 11925          "bom-ref": "pkg:deb/debian/mount@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=c7ff86ae9a8937ca",
 11926          "supplier": {},
 11927          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 11928          "name": "mount",
 11929          "version": "2.36.1-8+deb11u1",
 11930          "licenses": [
 11931            {
 11932              "license": {
 11933                "id": "BSD-2-Clause"
 11934              }
 11935            },
 11936            {
 11937              "license": {
 11938                "id": "BSD-3-Clause"
 11939              }
 11940            },
 11941            {
 11942              "license": {
 11943                "id": "BSD-4-Clause"
 11944              }
 11945            },
 11946            {
 11947              "license": {
 11948                "id": "GPL-2.0-only"
 11949              }
 11950            },
 11951            {
 11952              "license": {
 11953                "id": "GPL-2.0-or-later"
 11954              }
 11955            },
 11956            {
 11957              "license": {
 11958                "id": "GPL-3.0-only"
 11959              }
 11960            },
 11961            {
 11962              "license": {
 11963                "id": "GPL-3.0-or-later"
 11964              }
 11965            },
 11966            {
 11967              "license": {
 11968                "name": "LGPL"
 11969              }
 11970            },
 11971            {
 11972              "license": {
 11973                "id": "LGPL-2.0-only"
 11974              }
 11975            },
 11976            {
 11977              "license": {
 11978                "id": "LGPL-2.0-or-later"
 11979              }
 11980            },
 11981            {
 11982              "license": {
 11983                "id": "LGPL-2.1-only"
 11984              }
 11985            },
 11986            {
 11987              "license": {
 11988                "id": "LGPL-2.1-or-later"
 11989              }
 11990            },
 11991            {
 11992              "license": {
 11993                "id": "LGPL-3.0-only"
 11994              }
 11995            },
 11996            {
 11997              "license": {
 11998                "id": "LGPL-3.0-or-later"
 11999              }
 12000            },
 12001            {
 12002              "license": {
 12003                "id": "MIT"
 12004              }
 12005            },
 12006            {
 12007              "license": {
 12008                "name": "public-domain"
 12009              }
 12010            }
 12011          ],
 12012          "cpe": "cpe:2.3:a:mount:mount:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 12013          "purl": "pkg:deb/debian/mount@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
 12014          "swid": {
 12015            "attachment": {}
 12016          },
 12017          "pedigree": {},
 12018          "evidence": {},
 12019          "signature": {
 12020            "signature": {
 12021              "publicKey": {}
 12022            }
 12023          },
 12024          "modelCard": {
 12025            "modelParameters": {
 12026              "approach": {}
 12027            },
 12028            "quantitativeAnalysis": {
 12029              "graphics": {}
 12030            },
 12031            "considerations": {}
 12032          }
 12033        },
 12034        {
 12035          "type": "library",
 12036          "bom-ref": "pkg:deb/debian/ncurses-base@6.2+20201114-2?arch=all\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=9c2239a948284096",
 12037          "supplier": {},
 12038          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 12039          "name": "ncurses-base",
 12040          "version": "6.2+20201114-2",
 12041          "licenses": [
 12042            {
 12043              "license": {
 12044                "id": "BSD-3-Clause"
 12045              }
 12046            },
 12047            {
 12048              "license": {
 12049                "name": "MIT/X11"
 12050              }
 12051            },
 12052            {
 12053              "license": {
 12054                "id": "X11"
 12055              }
 12056            }
 12057          ],
 12058          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.2\\+20201114-2:*:*:*:*:*:*:*",
 12059          "purl": "pkg:deb/debian/ncurses-base@6.2+20201114-2?arch=all\u0026upstream=ncurses\u0026distro=debian-11",
 12060          "swid": {
 12061            "attachment": {}
 12062          },
 12063          "pedigree": {},
 12064          "evidence": {},
 12065          "signature": {
 12066            "signature": {
 12067              "publicKey": {}
 12068            }
 12069          },
 12070          "modelCard": {
 12071            "modelParameters": {
 12072              "approach": {}
 12073            },
 12074            "quantitativeAnalysis": {
 12075              "graphics": {}
 12076            },
 12077            "considerations": {}
 12078          }
 12079        },
 12080        {
 12081          "type": "library",
 12082          "bom-ref": "pkg:deb/debian/ncurses-bin@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=d98c3c34aac1c97c",
 12083          "supplier": {},
 12084          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 12085          "name": "ncurses-bin",
 12086          "version": "6.2+20201114-2",
 12087          "licenses": [
 12088            {
 12089              "license": {
 12090                "id": "BSD-3-Clause"
 12091              }
 12092            },
 12093            {
 12094              "license": {
 12095                "name": "MIT/X11"
 12096              }
 12097            },
 12098            {
 12099              "license": {
 12100                "id": "X11"
 12101              }
 12102            }
 12103          ],
 12104          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.2\\+20201114-2:*:*:*:*:*:*:*",
 12105          "purl": "pkg:deb/debian/ncurses-bin@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11",
 12106          "swid": {
 12107            "attachment": {}
 12108          },
 12109          "pedigree": {},
 12110          "evidence": {},
 12111          "signature": {
 12112            "signature": {
 12113              "publicKey": {}
 12114            }
 12115          },
 12116          "modelCard": {
 12117            "modelParameters": {
 12118              "approach": {}
 12119            },
 12120            "quantitativeAnalysis": {
 12121              "graphics": {}
 12122            },
 12123            "considerations": {}
 12124          }
 12125        },
 12126        {
 12127          "type": "library",
 12128          "bom-ref": "pkg:deb/debian/netbase@6.3?arch=all\u0026distro=debian-11\u0026package-id=1632ba983c003dc3",
 12129          "supplier": {},
 12130          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
 12131          "name": "netbase",
 12132          "version": "6.3",
 12133          "licenses": [
 12134            {
 12135              "license": {
 12136                "id": "GPL-2.0-only"
 12137              }
 12138            }
 12139          ],
 12140          "cpe": "cpe:2.3:a:netbase:netbase:6.3:*:*:*:*:*:*:*",
 12141          "purl": "pkg:deb/debian/netbase@6.3?arch=all\u0026distro=debian-11",
 12142          "swid": {
 12143            "attachment": {}
 12144          },
 12145          "pedigree": {},
 12146          "evidence": {},
 12147          "signature": {
 12148            "signature": {
 12149              "publicKey": {}
 12150            }
 12151          },
 12152          "modelCard": {
 12153            "modelParameters": {
 12154              "approach": {}
 12155            },
 12156            "quantitativeAnalysis": {
 12157              "graphics": {}
 12158            },
 12159            "considerations": {}
 12160          }
 12161        },
 12162        {
 12163          "type": "library",
 12164          "bom-ref": "pkg:deb/debian/openssl@1.1.1n-0+deb11u4?arch=amd64\u0026distro=debian-11\u0026package-id=a7dc6e66845f14bf",
 12165          "supplier": {},
 12166          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
 12167          "name": "openssl",
 12168          "version": "1.1.1n-0+deb11u4",
 12169          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1n-0\\+deb11u4:*:*:*:*:*:*:*",
 12170          "purl": "pkg:deb/debian/openssl@1.1.1n-0+deb11u4?arch=amd64\u0026distro=debian-11",
 12171          "swid": {
 12172            "attachment": {}
 12173          },
 12174          "pedigree": {},
 12175          "evidence": {},
 12176          "signature": {
 12177            "signature": {
 12178              "publicKey": {}
 12179            }
 12180          },
 12181          "modelCard": {
 12182            "modelParameters": {
 12183              "approach": {}
 12184            },
 12185            "quantitativeAnalysis": {
 12186              "graphics": {}
 12187            },
 12188            "considerations": {}
 12189          }
 12190        },
 12191        {
 12192          "type": "library",
 12193          "bom-ref": "pkg:deb/debian/passwd@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11\u0026package-id=fdca5992b8d73b50",
 12194          "supplier": {},
 12195          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
 12196          "name": "passwd",
 12197          "version": "1:4.8.1-1",
 12198          "licenses": [
 12199            {
 12200              "license": {
 12201                "id": "GPL-2.0-only"
 12202              }
 12203            }
 12204          ],
 12205          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1:*:*:*:*:*:*:*",
 12206          "purl": "pkg:deb/debian/passwd@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11",
 12207          "swid": {
 12208            "attachment": {}
 12209          },
 12210          "pedigree": {},
 12211          "evidence": {},
 12212          "signature": {
 12213            "signature": {
 12214              "publicKey": {}
 12215            }
 12216          },
 12217          "modelCard": {
 12218            "modelParameters": {
 12219              "approach": {}
 12220            },
 12221            "quantitativeAnalysis": {
 12222              "graphics": {}
 12223            },
 12224            "considerations": {}
 12225          }
 12226        },
 12227        {
 12228          "type": "library",
 12229          "bom-ref": "pkg:deb/debian/perl-base@5.32.1-4+deb11u2?arch=amd64\u0026upstream=perl\u0026distro=debian-11\u0026package-id=96ea9246284c94e6",
 12230          "supplier": {},
 12231          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
 12232          "name": "perl-base",
 12233          "version": "5.32.1-4+deb11u2",
 12234          "licenses": [
 12235            {
 12236              "license": {
 12237                "name": "Artistic"
 12238              }
 12239            },
 12240            {
 12241              "license": {
 12242                "id": "Artistic-2.0"
 12243              }
 12244            },
 12245            {
 12246              "license": {
 12247                "name": "Artistic-dist"
 12248              }
 12249            },
 12250            {
 12251              "license": {
 12252                "id": "BSD-3-Clause"
 12253              }
 12254            },
 12255            {
 12256              "license": {
 12257                "name": "BSD-3-clause-GENERIC"
 12258              }
 12259            },
 12260            {
 12261              "license": {
 12262                "name": "BSD-3-clause-with-weird-numbering"
 12263              }
 12264            },
 12265            {
 12266              "license": {
 12267                "name": "BSD-4-clause-POWERDOG"
 12268              }
 12269            },
 12270            {
 12271              "license": {
 12272                "name": "BZIP"
 12273              }
 12274            },
 12275            {
 12276              "license": {
 12277                "name": "DONT-CHANGE-THE-GPL"
 12278              }
 12279            },
 12280            {
 12281              "license": {
 12282                "name": "Expat"
 12283              }
 12284            },
 12285            {
 12286              "license": {
 12287                "id": "GPL-1.0-only"
 12288              }
 12289            },
 12290            {
 12291              "license": {
 12292                "id": "GPL-1.0-or-later"
 12293              }
 12294            },
 12295            {
 12296              "license": {
 12297                "id": "GPL-2.0-only"
 12298              }
 12299            },
 12300            {
 12301              "license": {
 12302                "id": "GPL-2.0-or-later"
 12303              }
 12304            },
 12305            {
 12306              "license": {
 12307                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 12308              }
 12309            },
 12310            {
 12311              "license": {
 12312                "name": "HSIEH-BSD"
 12313              }
 12314            },
 12315            {
 12316              "license": {
 12317                "name": "HSIEH-DERIVATIVE"
 12318              }
 12319            },
 12320            {
 12321              "license": {
 12322                "id": "LGPL-2.1-only"
 12323              }
 12324            },
 12325            {
 12326              "license": {
 12327                "name": "REGCOMP"
 12328              }
 12329            },
 12330            {
 12331              "license": {
 12332                "name": "REGCOMP,"
 12333              }
 12334            },
 12335            {
 12336              "license": {
 12337                "name": "RRA-KEEP-THIS-NOTICE"
 12338              }
 12339            },
 12340            {
 12341              "license": {
 12342                "name": "SDBM-PUBLIC-DOMAIN"
 12343              }
 12344            },
 12345            {
 12346              "license": {
 12347                "name": "TEXT-TABS"
 12348              }
 12349            },
 12350            {
 12351              "license": {
 12352                "name": "Unicode"
 12353              }
 12354            },
 12355            {
 12356              "license": {
 12357                "id": "Zlib"
 12358              }
 12359            }
 12360          ],
 12361          "cpe": "cpe:2.3:a:perl-base:perl-base:5.32.1-4\\+deb11u2:*:*:*:*:*:*:*",
 12362          "purl": "pkg:deb/debian/perl-base@5.32.1-4+deb11u2?arch=amd64\u0026upstream=perl\u0026distro=debian-11",
 12363          "swid": {
 12364            "attachment": {}
 12365          },
 12366          "pedigree": {},
 12367          "evidence": {},
 12368          "signature": {
 12369            "signature": {
 12370              "publicKey": {}
 12371            }
 12372          },
 12373          "modelCard": {
 12374            "modelParameters": {
 12375              "approach": {}
 12376            },
 12377            "quantitativeAnalysis": {
 12378              "graphics": {}
 12379            },
 12380            "considerations": {}
 12381          }
 12382        },
 12383        {
 12384          "type": "library",
 12385          "bom-ref": "pkg:deb/debian/pinentry-curses@1.1.0-4?arch=amd64\u0026upstream=pinentry\u0026distro=debian-11\u0026package-id=97be8369853f993c",
 12386          "supplier": {},
 12387          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
 12388          "name": "pinentry-curses",
 12389          "version": "1.1.0-4",
 12390          "licenses": [
 12391            {
 12392              "license": {
 12393                "id": "GPL-2.0-only"
 12394              }
 12395            },
 12396            {
 12397              "license": {
 12398                "id": "GPL-2.0-or-later"
 12399              }
 12400            },
 12401            {
 12402              "license": {
 12403                "id": "LGPL-3.0-only"
 12404              }
 12405            },
 12406            {
 12407              "license": {
 12408                "id": "LGPL-3.0-or-later"
 12409              }
 12410            },
 12411            {
 12412              "license": {
 12413                "id": "X11"
 12414              }
 12415            }
 12416          ],
 12417          "cpe": "cpe:2.3:a:pinentry-curses:pinentry-curses:1.1.0-4:*:*:*:*:*:*:*",
 12418          "purl": "pkg:deb/debian/pinentry-curses@1.1.0-4?arch=amd64\u0026upstream=pinentry\u0026distro=debian-11",
 12419          "swid": {
 12420            "attachment": {}
 12421          },
 12422          "pedigree": {},
 12423          "evidence": {},
 12424          "signature": {
 12425            "signature": {
 12426              "publicKey": {}
 12427            }
 12428          },
 12429          "modelCard": {
 12430            "modelParameters": {
 12431              "approach": {}
 12432            },
 12433            "quantitativeAnalysis": {
 12434              "graphics": {}
 12435            },
 12436            "considerations": {}
 12437          }
 12438        },
 12439        {
 12440          "type": "library",
 12441          "bom-ref": "pkg:deb/debian/readline-common@8.1-1?arch=all\u0026upstream=readline\u0026distro=debian-11\u0026package-id=1db616197859926a",
 12442          "supplier": {},
 12443          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 12444          "name": "readline-common",
 12445          "version": "8.1-1",
 12446          "licenses": [
 12447            {
 12448              "license": {
 12449                "name": "GFDL"
 12450              }
 12451            },
 12452            {
 12453              "license": {
 12454                "id": "GPL-3.0-only"
 12455              }
 12456            }
 12457          ],
 12458          "cpe": "cpe:2.3:a:readline-common:readline-common:8.1-1:*:*:*:*:*:*:*",
 12459          "purl": "pkg:deb/debian/readline-common@8.1-1?arch=all\u0026upstream=readline\u0026distro=debian-11",
 12460          "swid": {
 12461            "attachment": {}
 12462          },
 12463          "pedigree": {},
 12464          "evidence": {},
 12465          "signature": {
 12466            "signature": {
 12467              "publicKey": {}
 12468            }
 12469          },
 12470          "modelCard": {
 12471            "modelParameters": {
 12472              "approach": {}
 12473            },
 12474            "quantitativeAnalysis": {
 12475              "graphics": {}
 12476            },
 12477            "considerations": {}
 12478          }
 12479        },
 12480        {
 12481          "type": "library",
 12482          "bom-ref": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-11\u0026package-id=cd24b1a69c7b788a",
 12483          "supplier": {},
 12484          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
 12485          "name": "sed",
 12486          "version": "4.7-1",
 12487          "licenses": [
 12488            {
 12489              "license": {
 12490                "id": "GPL-3.0-only"
 12491              }
 12492            }
 12493          ],
 12494          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
 12495          "purl": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-11",
 12496          "swid": {
 12497            "attachment": {}
 12498          },
 12499          "pedigree": {},
 12500          "evidence": {},
 12501          "signature": {
 12502            "signature": {
 12503              "publicKey": {}
 12504            }
 12505          },
 12506          "modelCard": {
 12507            "modelParameters": {
 12508              "approach": {}
 12509            },
 12510            "quantitativeAnalysis": {
 12511              "graphics": {}
 12512            },
 12513            "considerations": {}
 12514          }
 12515        },
 12516        {
 12517          "type": "library",
 12518          "bom-ref": "pkg:deb/debian/sysvinit-utils@2.96-7+deb11u1?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-11\u0026package-id=e0e95f2e10cb825e",
 12519          "supplier": {},
 12520          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
 12521          "name": "sysvinit-utils",
 12522          "version": "2.96-7+deb11u1",
 12523          "licenses": [
 12524            {
 12525              "license": {
 12526                "id": "GPL-2.0-only"
 12527              }
 12528            },
 12529            {
 12530              "license": {
 12531                "id": "GPL-2.0-or-later"
 12532              }
 12533            }
 12534          ],
 12535          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.96-7\\+deb11u1:*:*:*:*:*:*:*",
 12536          "purl": "pkg:deb/debian/sysvinit-utils@2.96-7+deb11u1?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-11",
 12537          "swid": {
 12538            "attachment": {}
 12539          },
 12540          "pedigree": {},
 12541          "evidence": {},
 12542          "signature": {
 12543            "signature": {
 12544              "publicKey": {}
 12545            }
 12546          },
 12547          "modelCard": {
 12548            "modelParameters": {
 12549              "approach": {}
 12550            },
 12551            "quantitativeAnalysis": {
 12552              "graphics": {}
 12553            },
 12554            "considerations": {}
 12555          }
 12556        },
 12557        {
 12558          "type": "library",
 12559          "bom-ref": "pkg:deb/debian/tar@1.34+dfsg-1?arch=amd64\u0026distro=debian-11\u0026package-id=9511efaff0991270",
 12560          "supplier": {},
 12561          "publisher": "Janos Lenart \u003cocsi@debian.org\u003e",
 12562          "name": "tar",
 12563          "version": "1.34+dfsg-1",
 12564          "licenses": [
 12565            {
 12566              "license": {
 12567                "id": "GPL-2.0-only"
 12568              }
 12569            },
 12570            {
 12571              "license": {
 12572                "id": "GPL-3.0-only"
 12573              }
 12574            }
 12575          ],
 12576          "cpe": "cpe:2.3:a:tar:tar:1.34\\+dfsg-1:*:*:*:*:*:*:*",
 12577          "purl": "pkg:deb/debian/tar@1.34+dfsg-1?arch=amd64\u0026distro=debian-11",
 12578          "swid": {
 12579            "attachment": {}
 12580          },
 12581          "pedigree": {},
 12582          "evidence": {},
 12583          "signature": {
 12584            "signature": {
 12585              "publicKey": {}
 12586            }
 12587          },
 12588          "modelCard": {
 12589            "modelParameters": {
 12590              "approach": {}
 12591            },
 12592            "quantitativeAnalysis": {
 12593              "graphics": {}
 12594            },
 12595            "considerations": {}
 12596          }
 12597        },
 12598        {
 12599          "type": "library",
 12600          "bom-ref": "pkg:deb/debian/tzdata@2021a-1+deb11u9?arch=all\u0026distro=debian-11\u0026package-id=5268162de7a3ef0",
 12601          "supplier": {},
 12602          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 12603          "name": "tzdata",
 12604          "version": "2021a-1+deb11u9",
 12605          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-1\\+deb11u9:*:*:*:*:*:*:*",
 12606          "purl": "pkg:deb/debian/tzdata@2021a-1+deb11u9?arch=all\u0026distro=debian-11",
 12607          "swid": {
 12608            "attachment": {}
 12609          },
 12610          "pedigree": {},
 12611          "evidence": {},
 12612          "signature": {
 12613            "signature": {
 12614              "publicKey": {}
 12615            }
 12616          },
 12617          "modelCard": {
 12618            "modelParameters": {
 12619              "approach": {}
 12620            },
 12621            "quantitativeAnalysis": {
 12622              "graphics": {}
 12623            },
 12624            "considerations": {}
 12625          }
 12626        },
 12627        {
 12628          "type": "library",
 12629          "bom-ref": "pkg:deb/debian/util-linux@2.36.1-8+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=b8c872368f65d4a3",
 12630          "supplier": {},
 12631          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 12632          "name": "util-linux",
 12633          "version": "2.36.1-8+deb11u1",
 12634          "licenses": [
 12635            {
 12636              "license": {
 12637                "id": "BSD-2-Clause"
 12638              }
 12639            },
 12640            {
 12641              "license": {
 12642                "id": "BSD-3-Clause"
 12643              }
 12644            },
 12645            {
 12646              "license": {
 12647                "id": "BSD-4-Clause"
 12648              }
 12649            },
 12650            {
 12651              "license": {
 12652                "id": "GPL-2.0-only"
 12653              }
 12654            },
 12655            {
 12656              "license": {
 12657                "id": "GPL-2.0-or-later"
 12658              }
 12659            },
 12660            {
 12661              "license": {
 12662                "id": "GPL-3.0-only"
 12663              }
 12664            },
 12665            {
 12666              "license": {
 12667                "id": "GPL-3.0-or-later"
 12668              }
 12669            },
 12670            {
 12671              "license": {
 12672                "name": "LGPL"
 12673              }
 12674            },
 12675            {
 12676              "license": {
 12677                "id": "LGPL-2.0-only"
 12678              }
 12679            },
 12680            {
 12681              "license": {
 12682                "id": "LGPL-2.0-or-later"
 12683              }
 12684            },
 12685            {
 12686              "license": {
 12687                "id": "LGPL-2.1-only"
 12688              }
 12689            },
 12690            {
 12691              "license": {
 12692                "id": "LGPL-2.1-or-later"
 12693              }
 12694            },
 12695            {
 12696              "license": {
 12697                "id": "LGPL-3.0-only"
 12698              }
 12699            },
 12700            {
 12701              "license": {
 12702                "id": "LGPL-3.0-or-later"
 12703              }
 12704            },
 12705            {
 12706              "license": {
 12707                "id": "MIT"
 12708              }
 12709            },
 12710            {
 12711              "license": {
 12712                "name": "public-domain"
 12713              }
 12714            }
 12715          ],
 12716          "cpe": "cpe:2.3:a:util-linux:util-linux:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 12717          "purl": "pkg:deb/debian/util-linux@2.36.1-8+deb11u1?arch=amd64\u0026distro=debian-11",
 12718          "swid": {
 12719            "attachment": {}
 12720          },
 12721          "pedigree": {},
 12722          "evidence": {},
 12723          "signature": {
 12724            "signature": {
 12725              "publicKey": {}
 12726            }
 12727          },
 12728          "modelCard": {
 12729            "modelParameters": {
 12730              "approach": {}
 12731            },
 12732            "quantitativeAnalysis": {
 12733              "graphics": {}
 12734            },
 12735            "considerations": {}
 12736          }
 12737        },
 12738        {
 12739          "type": "library",
 12740          "bom-ref": "pkg:deb/debian/wget@1.21-1+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=a1c9b0706dcf6d72",
 12741          "supplier": {},
 12742          "publisher": "Noël Köthe \u003cnoel@debian.org\u003e",
 12743          "name": "wget",
 12744          "version": "1.21-1+deb11u1",
 12745          "licenses": [
 12746            {
 12747              "license": {
 12748                "id": "GFDL-1.2-only"
 12749              }
 12750            },
 12751            {
 12752              "license": {
 12753                "id": "GPL-3.0-only"
 12754              }
 12755            }
 12756          ],
 12757          "cpe": "cpe:2.3:a:wget:wget:1.21-1\\+deb11u1:*:*:*:*:*:*:*",
 12758          "purl": "pkg:deb/debian/wget@1.21-1+deb11u1?arch=amd64\u0026distro=debian-11",
 12759          "swid": {
 12760            "attachment": {}
 12761          },
 12762          "pedigree": {},
 12763          "evidence": {},
 12764          "signature": {
 12765            "signature": {
 12766              "publicKey": {}
 12767            }
 12768          },
 12769          "modelCard": {
 12770            "modelParameters": {
 12771              "approach": {}
 12772            },
 12773            "quantitativeAnalysis": {
 12774              "graphics": {}
 12775            },
 12776            "considerations": {}
 12777          }
 12778        },
 12779        {
 12780          "type": "library",
 12781          "bom-ref": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-2+deb11u2?arch=amd64\u0026upstream=zlib\u0026distro=debian-11\u0026package-id=369e996115240b62",
 12782          "supplier": {},
 12783          "publisher": "Mark Brown \u003cbroonie@debian.org\u003e",
 12784          "name": "zlib1g",
 12785          "version": "1:1.2.11.dfsg-2+deb11u2",
 12786          "licenses": [
 12787            {
 12788              "license": {
 12789                "id": "Zlib"
 12790              }
 12791            }
 12792          ],
 12793          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2\\+deb11u2:*:*:*:*:*:*:*",
 12794          "purl": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-2+deb11u2?arch=amd64\u0026upstream=zlib\u0026distro=debian-11",
 12795          "swid": {
 12796            "attachment": {}
 12797          },
 12798          "pedigree": {},
 12799          "evidence": {},
 12800          "signature": {
 12801            "signature": {
 12802              "publicKey": {}
 12803            }
 12804          },
 12805          "modelCard": {
 12806            "modelParameters": {
 12807              "approach": {}
 12808            },
 12809            "quantitativeAnalysis": {
 12810              "graphics": {}
 12811            },
 12812            "considerations": {}
 12813          }
 12814        },
 12815        {
 12816          "type": "operating-system",
 12817          "supplier": {},
 12818          "name": "debian",
 12819          "version": "11",
 12820          "description": "Debian GNU/Linux 11 (bullseye)",
 12821          "swid": {
 12822            "tagId": "debian",
 12823            "name": "debian",
 12824            "version": "11",
 12825            "attachment": {}
 12826          },
 12827          "pedigree": {},
 12828          "externalReferences": [
 12829            {
 12830              "url": "https://bugs.debian.org/",
 12831              "type": "issue-tracker"
 12832            },
 12833            {
 12834              "url": "https://www.debian.org/",
 12835              "type": "website"
 12836            },
 12837            {
 12838              "url": "https://www.debian.org/support",
 12839              "comment": "support",
 12840              "type": "other"
 12841            }
 12842          ],
 12843          "evidence": {},
 12844          "signature": {
 12845            "signature": {
 12846              "publicKey": {}
 12847            }
 12848          },
 12849          "modelCard": {
 12850            "modelParameters": {
 12851              "approach": {}
 12852            },
 12853            "quantitativeAnalysis": {
 12854              "graphics": {}
 12855            },
 12856            "considerations": {}
 12857          }
 12858        },
 12859        {
 12860          "type": "library",
 12861          "bom-ref": "pkg:deb/debian/base-files@10.3+deb10u9?arch=amd64\u0026distro=debian-10\u0026package-id=5aa6e4929bf16696",
 12862          "supplier": {},
 12863          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
 12864          "name": "base-files",
 12865          "version": "10.3+deb10u9",
 12866          "licenses": [
 12867            {
 12868              "license": {
 12869                "name": "GPL"
 12870              }
 12871            }
 12872          ],
 12873          "cpe": "cpe:2.3:a:base-files:base-files:10.3\\+deb10u9:*:*:*:*:*:*:*",
 12874          "purl": "pkg:deb/debian/base-files@10.3+deb10u9?arch=amd64\u0026distro=debian-10",
 12875          "swid": {
 12876            "attachment": {}
 12877          },
 12878          "pedigree": {},
 12879          "evidence": {},
 12880          "signature": {
 12881            "signature": {
 12882              "publicKey": {}
 12883            }
 12884          },
 12885          "modelCard": {
 12886            "modelParameters": {
 12887              "approach": {}
 12888            },
 12889            "quantitativeAnalysis": {
 12890              "graphics": {}
 12891            },
 12892            "considerations": {}
 12893          }
 12894        },
 12895        {
 12896          "type": "library",
 12897          "bom-ref": "pkg:golang/github.com/beorn7/perks@v1.0.1?package-id=cc00b9c8d0ce31ed",
 12898          "supplier": {},
 12899          "name": "github.com/beorn7/perks",
 12900          "version": "v1.0.1",
 12901          "cpe": "cpe:2.3:a:beorn7:perks:v1.0.1:*:*:*:*:*:*:*",
 12902          "purl": "pkg:golang/github.com/beorn7/perks@v1.0.1",
 12903          "swid": {
 12904            "attachment": {}
 12905          },
 12906          "pedigree": {},
 12907          "evidence": {},
 12908          "signature": {
 12909            "signature": {
 12910              "publicKey": {}
 12911            }
 12912          },
 12913          "modelCard": {
 12914            "modelParameters": {
 12915              "approach": {}
 12916            },
 12917            "quantitativeAnalysis": {
 12918              "graphics": {}
 12919            },
 12920            "considerations": {}
 12921          }
 12922        },
 12923        {
 12924          "type": "library",
 12925          "bom-ref": "pkg:golang/github.com/blang/semver@v3.5.1+incompatible?package-id=2dbc1b01df867a6a",
 12926          "supplier": {},
 12927          "name": "github.com/blang/semver",
 12928          "version": "v3.5.1+incompatible",
 12929          "cpe": "cpe:2.3:a:blang:semver:v3.5.1\\+incompatible:*:*:*:*:*:*:*",
 12930          "purl": "pkg:golang/github.com/blang/semver@v3.5.1+incompatible",
 12931          "swid": {
 12932            "attachment": {}
 12933          },
 12934          "pedigree": {},
 12935          "evidence": {},
 12936          "signature": {
 12937            "signature": {
 12938              "publicKey": {}
 12939            }
 12940          },
 12941          "modelCard": {
 12942            "modelParameters": {
 12943              "approach": {}
 12944            },
 12945            "quantitativeAnalysis": {
 12946              "graphics": {}
 12947            },
 12948            "considerations": {}
 12949          }
 12950        },
 12951        {
 12952          "type": "library",
 12953          "bom-ref": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1?package-id=56c8a30e6ed8d12f",
 12954          "supplier": {},
 12955          "name": "github.com/cespare/xxhash/v2",
 12956          "version": "v2.1.1",
 12957          "cpe": "cpe:2.3:a:cespare:xxhash\\/v2:v2.1.1:*:*:*:*:*:*:*",
 12958          "purl": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1",
 12959          "swid": {
 12960            "attachment": {}
 12961          },
 12962          "pedigree": {},
 12963          "evidence": {},
 12964          "signature": {
 12965            "signature": {
 12966              "publicKey": {}
 12967            }
 12968          },
 12969          "modelCard": {
 12970            "modelParameters": {
 12971              "approach": {}
 12972            },
 12973            "quantitativeAnalysis": {
 12974              "graphics": {}
 12975            },
 12976            "considerations": {}
 12977          }
 12978        },
 12979        {
 12980          "type": "library",
 12981          "bom-ref": "pkg:golang/github.com/container-storage-interface/spec@v1.3.0?package-id=59b273222fc08721",
 12982          "supplier": {},
 12983          "name": "github.com/container-storage-interface/spec",
 12984          "version": "v1.3.0",
 12985          "cpe": "cpe:2.3:a:container-storage-interface:spec:v1.3.0:*:*:*:*:*:*:*",
 12986          "purl": "pkg:golang/github.com/container-storage-interface/spec@v1.3.0",
 12987          "swid": {
 12988            "attachment": {}
 12989          },
 12990          "pedigree": {},
 12991          "evidence": {},
 12992          "signature": {
 12993            "signature": {
 12994              "publicKey": {}
 12995            }
 12996          },
 12997          "modelCard": {
 12998            "modelParameters": {
 12999              "approach": {}
 13000            },
 13001            "quantitativeAnalysis": {
 13002              "graphics": {}
 13003            },
 13004            "considerations": {}
 13005          }
 13006        },
 13007        {
 13008          "type": "library",
 13009          "bom-ref": "pkg:golang/github.com/davecgh/go-spew@v1.1.1?package-id=54c8a26e96cd9177",
 13010          "supplier": {},
 13011          "name": "github.com/davecgh/go-spew",
 13012          "version": "v1.1.1",
 13013          "cpe": "cpe:2.3:a:davecgh:go-spew:v1.1.1:*:*:*:*:*:*:*",
 13014          "purl": "pkg:golang/github.com/davecgh/go-spew@v1.1.1",
 13015          "swid": {
 13016            "attachment": {}
 13017          },
 13018          "pedigree": {},
 13019          "evidence": {},
 13020          "signature": {
 13021            "signature": {
 13022              "publicKey": {}
 13023            }
 13024          },
 13025          "modelCard": {
 13026            "modelParameters": {
 13027              "approach": {}
 13028            },
 13029            "quantitativeAnalysis": {
 13030              "graphics": {}
 13031            },
 13032            "considerations": {}
 13033          }
 13034        },
 13035        {
 13036          "type": "library",
 13037          "bom-ref": "pkg:golang/github.com/evanphx/json-patch@v4.9.0+incompatible?package-id=4d5067e77be15976",
 13038          "supplier": {},
 13039          "name": "github.com/evanphx/json-patch",
 13040          "version": "v4.9.0+incompatible",
 13041          "cpe": "cpe:2.3:a:evanphx:json-patch:v4.9.0\\+incompatible:*:*:*:*:*:*:*",
 13042          "purl": "pkg:golang/github.com/evanphx/json-patch@v4.9.0+incompatible",
 13043          "swid": {
 13044            "attachment": {}
 13045          },
 13046          "pedigree": {},
 13047          "evidence": {},
 13048          "signature": {
 13049            "signature": {
 13050              "publicKey": {}
 13051            }
 13052          },
 13053          "modelCard": {
 13054            "modelParameters": {
 13055              "approach": {}
 13056            },
 13057            "quantitativeAnalysis": {
 13058              "graphics": {}
 13059            },
 13060            "considerations": {}
 13061          }
 13062        },
 13063        {
 13064          "type": "library",
 13065          "bom-ref": "pkg:golang/github.com/go-logr/logr@v0.4.0?package-id=6ee9e381920d3d42",
 13066          "supplier": {},
 13067          "name": "github.com/go-logr/logr",
 13068          "version": "v0.4.0",
 13069          "cpe": "cpe:2.3:a:go-logr:logr:v0.4.0:*:*:*:*:*:*:*",
 13070          "purl": "pkg:golang/github.com/go-logr/logr@v0.4.0",
 13071          "swid": {
 13072            "attachment": {}
 13073          },
 13074          "pedigree": {},
 13075          "evidence": {},
 13076          "signature": {
 13077            "signature": {
 13078              "publicKey": {}
 13079            }
 13080          },
 13081          "modelCard": {
 13082            "modelParameters": {
 13083              "approach": {}
 13084            },
 13085            "quantitativeAnalysis": {
 13086              "graphics": {}
 13087            },
 13088            "considerations": {}
 13089          }
 13090        },
 13091        {
 13092          "type": "library",
 13093          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.1?package-id=8c9abae50388b70b",
 13094          "supplier": {},
 13095          "name": "github.com/gogo/protobuf",
 13096          "version": "v1.3.1",
 13097          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.1:*:*:*:*:*:*:*",
 13098          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.1",
 13099          "swid": {
 13100            "attachment": {}
 13101          },
 13102          "pedigree": {},
 13103          "evidence": {},
 13104          "signature": {
 13105            "signature": {
 13106              "publicKey": {}
 13107            }
 13108          },
 13109          "modelCard": {
 13110            "modelParameters": {
 13111              "approach": {}
 13112            },
 13113            "quantitativeAnalysis": {
 13114              "graphics": {}
 13115            },
 13116            "considerations": {}
 13117          }
 13118        },
 13119        {
 13120          "type": "library",
 13121          "bom-ref": "pkg:golang/github.com/golang/groupcache@v0.0.0-20200121045136-8c9f03a8e57e?package-id=d8c82a79a4166105",
 13122          "supplier": {},
 13123          "name": "github.com/golang/groupcache",
 13124          "version": "v0.0.0-20200121045136-8c9f03a8e57e",
 13125          "cpe": "cpe:2.3:a:golang:groupcache:v0.0.0-20200121045136-8c9f03a8e57e:*:*:*:*:*:*:*",
 13126          "purl": "pkg:golang/github.com/golang/groupcache@v0.0.0-20200121045136-8c9f03a8e57e",
 13127          "swid": {
 13128            "attachment": {}
 13129          },
 13130          "pedigree": {},
 13131          "evidence": {},
 13132          "signature": {
 13133            "signature": {
 13134              "publicKey": {}
 13135            }
 13136          },
 13137          "modelCard": {
 13138            "modelParameters": {
 13139              "approach": {}
 13140            },
 13141            "quantitativeAnalysis": {
 13142              "graphics": {}
 13143            },
 13144            "considerations": {}
 13145          }
 13146        },
 13147        {
 13148          "type": "library",
 13149          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.4.3?package-id=e96e1ed4ea928c35",
 13150          "supplier": {},
 13151          "name": "github.com/golang/protobuf",
 13152          "version": "v1.4.3",
 13153          "cpe": "cpe:2.3:a:golang:protobuf:v1.4.3:*:*:*:*:*:*:*",
 13154          "purl": "pkg:golang/github.com/golang/protobuf@v1.4.3",
 13155          "swid": {
 13156            "attachment": {}
 13157          },
 13158          "pedigree": {},
 13159          "evidence": {},
 13160          "signature": {
 13161            "signature": {
 13162              "publicKey": {}
 13163            }
 13164          },
 13165          "modelCard": {
 13166            "modelParameters": {
 13167              "approach": {}
 13168            },
 13169            "quantitativeAnalysis": {
 13170              "graphics": {}
 13171            },
 13172            "considerations": {}
 13173          }
 13174        },
 13175        {
 13176          "type": "library",
 13177          "bom-ref": "pkg:golang/github.com/google/go-cmp@v0.5.4?package-id=7f6c51c43dbb5a29",
 13178          "supplier": {},
 13179          "name": "github.com/google/go-cmp",
 13180          "version": "v0.5.4",
 13181          "cpe": "cpe:2.3:a:google:go-cmp:v0.5.4:*:*:*:*:*:*:*",
 13182          "purl": "pkg:golang/github.com/google/go-cmp@v0.5.4",
 13183          "swid": {
 13184            "attachment": {}
 13185          },
 13186          "pedigree": {},
 13187          "evidence": {},
 13188          "signature": {
 13189            "signature": {
 13190              "publicKey": {}
 13191            }
 13192          },
 13193          "modelCard": {
 13194            "modelParameters": {
 13195              "approach": {}
 13196            },
 13197            "quantitativeAnalysis": {
 13198              "graphics": {}
 13199            },
 13200            "considerations": {}
 13201          }
 13202        },
 13203        {
 13204          "type": "library",
 13205          "bom-ref": "pkg:golang/github.com/google/gofuzz@v1.2.0?package-id=dba323a4fa86b9bf",
 13206          "supplier": {},
 13207          "name": "github.com/google/gofuzz",
 13208          "version": "v1.2.0",
 13209          "cpe": "cpe:2.3:a:google:gofuzz:v1.2.0:*:*:*:*:*:*:*",
 13210          "purl": "pkg:golang/github.com/google/gofuzz@v1.2.0",
 13211          "swid": {
 13212            "attachment": {}
 13213          },
 13214          "pedigree": {},
 13215          "evidence": {},
 13216          "signature": {
 13217            "signature": {
 13218              "publicKey": {}
 13219            }
 13220          },
 13221          "modelCard": {
 13222            "modelParameters": {
 13223              "approach": {}
 13224            },
 13225            "quantitativeAnalysis": {
 13226              "graphics": {}
 13227            },
 13228            "considerations": {}
 13229          }
 13230        },
 13231        {
 13232          "type": "library",
 13233          "bom-ref": "pkg:golang/github.com/google/uuid@v1.1.2?package-id=c78a08959676d86b",
 13234          "supplier": {},
 13235          "name": "github.com/google/uuid",
 13236          "version": "v1.1.2",
 13237          "cpe": "cpe:2.3:a:google:uuid:v1.1.2:*:*:*:*:*:*:*",
 13238          "purl": "pkg:golang/github.com/google/uuid@v1.1.2",
 13239          "swid": {
 13240            "attachment": {}
 13241          },
 13242          "pedigree": {},
 13243          "evidence": {},
 13244          "signature": {
 13245            "signature": {
 13246              "publicKey": {}
 13247            }
 13248          },
 13249          "modelCard": {
 13250            "modelParameters": {
 13251              "approach": {}
 13252            },
 13253            "quantitativeAnalysis": {
 13254              "graphics": {}
 13255            },
 13256            "considerations": {}
 13257          }
 13258        },
 13259        {
 13260          "type": "library",
 13261          "bom-ref": "pkg:golang/github.com/googleapis/gnostic@v0.5.3?package-id=58aceef74759b61e",
 13262          "supplier": {},
 13263          "name": "github.com/googleapis/gnostic",
 13264          "version": "v0.5.3",
 13265          "cpe": "cpe:2.3:a:googleapis:gnostic:v0.5.3:*:*:*:*:*:*:*",
 13266          "purl": "pkg:golang/github.com/googleapis/gnostic@v0.5.3",
 13267          "swid": {
 13268            "attachment": {}
 13269          },
 13270          "pedigree": {},
 13271          "evidence": {},
 13272          "signature": {
 13273            "signature": {
 13274              "publicKey": {}
 13275            }
 13276          },
 13277          "modelCard": {
 13278            "modelParameters": {
 13279              "approach": {}
 13280            },
 13281            "quantitativeAnalysis": {
 13282              "graphics": {}
 13283            },
 13284            "considerations": {}
 13285          }
 13286        },
 13287        {
 13288          "type": "library",
 13289          "bom-ref": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.4?package-id=7000ab09d2435fd1",
 13290          "supplier": {},
 13291          "name": "github.com/hashicorp/golang-lru",
 13292          "version": "v0.5.4",
 13293          "cpe": "cpe:2.3:a:hashicorp:golang-lru:v0.5.4:*:*:*:*:*:*:*",
 13294          "purl": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.4",
 13295          "swid": {
 13296            "attachment": {}
 13297          },
 13298          "pedigree": {},
 13299          "evidence": {},
 13300          "signature": {
 13301            "signature": {
 13302              "publicKey": {}
 13303            }
 13304          },
 13305          "modelCard": {
 13306            "modelParameters": {
 13307              "approach": {}
 13308            },
 13309            "quantitativeAnalysis": {
 13310              "graphics": {}
 13311            },
 13312            "considerations": {}
 13313          }
 13314        },
 13315        {
 13316          "type": "library",
 13317          "bom-ref": "pkg:golang/github.com/imdario/mergo@v0.3.11?package-id=d43a6fa01161fac",
 13318          "supplier": {},
 13319          "name": "github.com/imdario/mergo",
 13320          "version": "v0.3.11",
 13321          "cpe": "cpe:2.3:a:imdario:mergo:v0.3.11:*:*:*:*:*:*:*",
 13322          "purl": "pkg:golang/github.com/imdario/mergo@v0.3.11",
 13323          "swid": {
 13324            "attachment": {}
 13325          },
 13326          "pedigree": {},
 13327          "evidence": {},
 13328          "signature": {
 13329            "signature": {
 13330              "publicKey": {}
 13331            }
 13332          },
 13333          "modelCard": {
 13334            "modelParameters": {
 13335              "approach": {}
 13336            },
 13337            "quantitativeAnalysis": {
 13338              "graphics": {}
 13339            },
 13340            "considerations": {}
 13341          }
 13342        },
 13343        {
 13344          "type": "library",
 13345          "bom-ref": "pkg:golang/github.com/json-iterator/go@v1.1.10?package-id=25c6433399c83a83",
 13346          "supplier": {},
 13347          "name": "github.com/json-iterator/go",
 13348          "version": "v1.1.10",
 13349          "cpe": "cpe:2.3:a:json-iterator:go:v1.1.10:*:*:*:*:*:*:*",
 13350          "purl": "pkg:golang/github.com/json-iterator/go@v1.1.10",
 13351          "swid": {
 13352            "attachment": {}
 13353          },
 13354          "pedigree": {},
 13355          "evidence": {},
 13356          "signature": {
 13357            "signature": {
 13358              "publicKey": {}
 13359            }
 13360          },
 13361          "modelCard": {
 13362            "modelParameters": {
 13363              "approach": {}
 13364            },
 13365            "quantitativeAnalysis": {
 13366              "graphics": {}
 13367            },
 13368            "considerations": {}
 13369          }
 13370        },
 13371        {
 13372          "type": "library",
 13373          "bom-ref": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.9.0?package-id=808ebba8c41ebd2",
 13374          "supplier": {},
 13375          "name": "github.com/kubernetes-csi/csi-lib-utils",
 13376          "version": "v0.9.0",
 13377          "cpe": "cpe:2.3:a:kubernetes-csi:csi-lib-utils:v0.9.0:*:*:*:*:*:*:*",
 13378          "purl": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.9.0",
 13379          "swid": {
 13380            "attachment": {}
 13381          },
 13382          "pedigree": {},
 13383          "evidence": {},
 13384          "signature": {
 13385            "signature": {
 13386              "publicKey": {}
 13387            }
 13388          },
 13389          "modelCard": {
 13390            "modelParameters": {
 13391              "approach": {}
 13392            },
 13393            "quantitativeAnalysis": {
 13394              "graphics": {}
 13395            },
 13396            "considerations": {}
 13397          }
 13398        },
 13399        {
 13400          "type": "library",
 13401          "bom-ref": "pkg:golang/github.com/kubernetes-csi/external-provisioner@(devel)?package-id=bf0d7487d10c658e",
 13402          "supplier": {},
 13403          "name": "github.com/kubernetes-csi/external-provisioner",
 13404          "version": "(devel)",
 13405          "cpe": "cpe:2.3:a:kubernetes-csi:external-provisioner:\\(devel\\):*:*:*:*:*:*:*",
 13406          "purl": "pkg:golang/github.com/kubernetes-csi/external-provisioner@(devel)",
 13407          "swid": {
 13408            "attachment": {}
 13409          },
 13410          "pedigree": {},
 13411          "evidence": {},
 13412          "signature": {
 13413            "signature": {
 13414              "publicKey": {}
 13415            }
 13416          },
 13417          "modelCard": {
 13418            "modelParameters": {
 13419              "approach": {}
 13420            },
 13421            "quantitativeAnalysis": {
 13422              "graphics": {}
 13423            },
 13424            "considerations": {}
 13425          }
 13426        },
 13427        {
 13428          "type": "library",
 13429          "bom-ref": "pkg:golang/github.com/kubernetes-csi/external-snapshotter/client/v3@v3.0.0?package-id=502963f03c832faa",
 13430          "supplier": {},
 13431          "name": "github.com/kubernetes-csi/external-snapshotter/client/v3",
 13432          "version": "v3.0.0",
 13433          "cpe": "cpe:2.3:a:kubernetes-csi:external-snapshotter\\/client\\/v3:v3.0.0:*:*:*:*:*:*:*",
 13434          "purl": "pkg:golang/github.com/kubernetes-csi/external-snapshotter/client/v3@v3.0.0",
 13435          "swid": {
 13436            "attachment": {}
 13437          },
 13438          "pedigree": {},
 13439          "evidence": {},
 13440          "signature": {
 13441            "signature": {
 13442              "publicKey": {}
 13443            }
 13444          },
 13445          "modelCard": {
 13446            "modelParameters": {
 13447              "approach": {}
 13448            },
 13449            "quantitativeAnalysis": {
 13450              "graphics": {}
 13451            },
 13452            "considerations": {}
 13453          }
 13454        },
 13455        {
 13456          "type": "library",
 13457          "bom-ref": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369?package-id=73c6509bc13937d8",
 13458          "supplier": {},
 13459          "name": "github.com/matttproud/golang_protobuf_extensions",
 13460          "version": "v1.0.2-0.20181231171920-c182affec369",
 13461          "cpe": "cpe:2.3:a:matttproud:golang-protobuf-extensions:v1.0.2-0.20181231171920-c182affec369:*:*:*:*:*:*:*",
 13462          "purl": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369",
 13463          "swid": {
 13464            "attachment": {}
 13465          },
 13466          "pedigree": {},
 13467          "evidence": {},
 13468          "signature": {
 13469            "signature": {
 13470              "publicKey": {}
 13471            }
 13472          },
 13473          "modelCard": {
 13474            "modelParameters": {
 13475              "approach": {}
 13476            },
 13477            "quantitativeAnalysis": {
 13478              "graphics": {}
 13479            },
 13480            "considerations": {}
 13481          }
 13482        },
 13483        {
 13484          "type": "library",
 13485          "bom-ref": "pkg:golang/github.com/miekg/dns@v1.1.35?package-id=df6cc70eaed9a153",
 13486          "supplier": {},
 13487          "name": "github.com/miekg/dns",
 13488          "version": "v1.1.35",
 13489          "cpe": "cpe:2.3:a:miekg:dns:v1.1.35:*:*:*:*:*:*:*",
 13490          "purl": "pkg:golang/github.com/miekg/dns@v1.1.35",
 13491          "swid": {
 13492            "attachment": {}
 13493          },
 13494          "pedigree": {},
 13495          "evidence": {},
 13496          "signature": {
 13497            "signature": {
 13498              "publicKey": {}
 13499            }
 13500          },
 13501          "modelCard": {
 13502            "modelParameters": {
 13503              "approach": {}
 13504            },
 13505            "quantitativeAnalysis": {
 13506              "graphics": {}
 13507            },
 13508            "considerations": {}
 13509          }
 13510        },
 13511        {
 13512          "type": "library",
 13513          "bom-ref": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd?package-id=8b4a083d7e787d16",
 13514          "supplier": {},
 13515          "name": "github.com/modern-go/concurrent",
 13516          "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
 13517          "cpe": "cpe:2.3:a:modern-go:concurrent:v0.0.0-20180306012644-bacd9c7ef1dd:*:*:*:*:*:*:*",
 13518          "purl": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd",
 13519          "swid": {
 13520            "attachment": {}
 13521          },
 13522          "pedigree": {},
 13523          "evidence": {},
 13524          "signature": {
 13525            "signature": {
 13526              "publicKey": {}
 13527            }
 13528          },
 13529          "modelCard": {
 13530            "modelParameters": {
 13531              "approach": {}
 13532            },
 13533            "quantitativeAnalysis": {
 13534              "graphics": {}
 13535            },
 13536            "considerations": {}
 13537          }
 13538        },
 13539        {
 13540          "type": "library",
 13541          "bom-ref": "pkg:golang/github.com/modern-go/reflect2@v1.0.1?package-id=44e874caefd7b533",
 13542          "supplier": {},
 13543          "name": "github.com/modern-go/reflect2",
 13544          "version": "v1.0.1",
 13545          "cpe": "cpe:2.3:a:modern-go:reflect2:v1.0.1:*:*:*:*:*:*:*",
 13546          "purl": "pkg:golang/github.com/modern-go/reflect2@v1.0.1",
 13547          "swid": {
 13548            "attachment": {}
 13549          },
 13550          "pedigree": {},
 13551          "evidence": {},
 13552          "signature": {
 13553            "signature": {
 13554              "publicKey": {}
 13555            }
 13556          },
 13557          "modelCard": {
 13558            "modelParameters": {
 13559              "approach": {}
 13560            },
 13561            "quantitativeAnalysis": {
 13562              "graphics": {}
 13563            },
 13564            "considerations": {}
 13565          }
 13566        },
 13567        {
 13568          "type": "library",
 13569          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.9.1?package-id=3502236ee518305f",
 13570          "supplier": {},
 13571          "name": "github.com/pkg/errors",
 13572          "version": "v0.9.1",
 13573          "cpe": "cpe:2.3:a:pkg:errors:v0.9.1:*:*:*:*:*:*:*",
 13574          "purl": "pkg:golang/github.com/pkg/errors@v0.9.1",
 13575          "swid": {
 13576            "attachment": {}
 13577          },
 13578          "pedigree": {},
 13579          "evidence": {},
 13580          "signature": {
 13581            "signature": {
 13582              "publicKey": {}
 13583            }
 13584          },
 13585          "modelCard": {
 13586            "modelParameters": {
 13587              "approach": {}
 13588            },
 13589            "quantitativeAnalysis": {
 13590              "graphics": {}
 13591            },
 13592            "considerations": {}
 13593          }
 13594        },
 13595        {
 13596          "type": "library",
 13597          "bom-ref": "pkg:golang/github.com/prometheus/client_golang@v1.8.0?package-id=2759e7bbe91b3b19",
 13598          "supplier": {},
 13599          "name": "github.com/prometheus/client_golang",
 13600          "version": "v1.8.0",
 13601          "cpe": "cpe:2.3:a:prometheus:client-golang:v1.8.0:*:*:*:*:*:*:*",
 13602          "purl": "pkg:golang/github.com/prometheus/client_golang@v1.8.0",
 13603          "swid": {
 13604            "attachment": {}
 13605          },
 13606          "pedigree": {},
 13607          "evidence": {},
 13608          "signature": {
 13609            "signature": {
 13610              "publicKey": {}
 13611            }
 13612          },
 13613          "modelCard": {
 13614            "modelParameters": {
 13615              "approach": {}
 13616            },
 13617            "quantitativeAnalysis": {
 13618              "graphics": {}
 13619            },
 13620            "considerations": {}
 13621          }
 13622        },
 13623        {
 13624          "type": "library",
 13625          "bom-ref": "pkg:golang/github.com/prometheus/client_model@v0.2.0?package-id=87a7cd7b5b7b2e9c",
 13626          "supplier": {},
 13627          "name": "github.com/prometheus/client_model",
 13628          "version": "v0.2.0",
 13629          "cpe": "cpe:2.3:a:prometheus:client-model:v0.2.0:*:*:*:*:*:*:*",
 13630          "purl": "pkg:golang/github.com/prometheus/client_model@v0.2.0",
 13631          "swid": {
 13632            "attachment": {}
 13633          },
 13634          "pedigree": {},
 13635          "evidence": {},
 13636          "signature": {
 13637            "signature": {
 13638              "publicKey": {}
 13639            }
 13640          },
 13641          "modelCard": {
 13642            "modelParameters": {
 13643              "approach": {}
 13644            },
 13645            "quantitativeAnalysis": {
 13646              "graphics": {}
 13647            },
 13648            "considerations": {}
 13649          }
 13650        },
 13651        {
 13652          "type": "library",
 13653          "bom-ref": "pkg:golang/github.com/prometheus/common@v0.15.0?package-id=43259b2cf12c35e6",
 13654          "supplier": {},
 13655          "name": "github.com/prometheus/common",
 13656          "version": "v0.15.0",
 13657          "cpe": "cpe:2.3:a:prometheus:common:v0.15.0:*:*:*:*:*:*:*",
 13658          "purl": "pkg:golang/github.com/prometheus/common@v0.15.0",
 13659          "swid": {
 13660            "attachment": {}
 13661          },
 13662          "pedigree": {},
 13663          "evidence": {},
 13664          "signature": {
 13665            "signature": {
 13666              "publicKey": {}
 13667            }
 13668          },
 13669          "modelCard": {
 13670            "modelParameters": {
 13671              "approach": {}
 13672            },
 13673            "quantitativeAnalysis": {
 13674              "graphics": {}
 13675            },
 13676            "considerations": {}
 13677          }
 13678        },
 13679        {
 13680          "type": "library",
 13681          "bom-ref": "pkg:golang/github.com/prometheus/procfs@v0.2.0?package-id=1b61f1922fa92dce",
 13682          "supplier": {},
 13683          "name": "github.com/prometheus/procfs",
 13684          "version": "v0.2.0",
 13685          "cpe": "cpe:2.3:a:prometheus:procfs:v0.2.0:*:*:*:*:*:*:*",
 13686          "purl": "pkg:golang/github.com/prometheus/procfs@v0.2.0",
 13687          "swid": {
 13688            "attachment": {}
 13689          },
 13690          "pedigree": {},
 13691          "evidence": {},
 13692          "signature": {
 13693            "signature": {
 13694              "publicKey": {}
 13695            }
 13696          },
 13697          "modelCard": {
 13698            "modelParameters": {
 13699              "approach": {}
 13700            },
 13701            "quantitativeAnalysis": {
 13702              "graphics": {}
 13703            },
 13704            "considerations": {}
 13705          }
 13706        },
 13707        {
 13708          "type": "library",
 13709          "bom-ref": "pkg:golang/github.com/spf13/pflag@v1.0.5?package-id=a9dc68b5a7a5618a",
 13710          "supplier": {},
 13711          "name": "github.com/spf13/pflag",
 13712          "version": "v1.0.5",
 13713          "cpe": "cpe:2.3:a:spf13:pflag:v1.0.5:*:*:*:*:*:*:*",
 13714          "purl": "pkg:golang/github.com/spf13/pflag@v1.0.5",
 13715          "swid": {
 13716            "attachment": {}
 13717          },
 13718          "pedigree": {},
 13719          "evidence": {},
 13720          "signature": {
 13721            "signature": {
 13722              "publicKey": {}
 13723            }
 13724          },
 13725          "modelCard": {
 13726            "modelParameters": {
 13727              "approach": {}
 13728            },
 13729            "quantitativeAnalysis": {
 13730              "graphics": {}
 13731            },
 13732            "considerations": {}
 13733          }
 13734        },
 13735        {
 13736          "type": "library",
 13737          "bom-ref": "pkg:golang/golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9?package-id=d6bedaa573a2fbdd",
 13738          "supplier": {},
 13739          "name": "golang.org/x/crypto",
 13740          "version": "v0.0.0-20201208171446-5f87f3452ae9",
 13741          "cpe": "cpe:2.3:a:golang:x\\/crypto:v0.0.0-20201208171446-5f87f3452ae9:*:*:*:*:*:*:*",
 13742          "purl": "pkg:golang/golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9",
 13743          "swid": {
 13744            "attachment": {}
 13745          },
 13746          "pedigree": {},
 13747          "evidence": {},
 13748          "signature": {
 13749            "signature": {
 13750              "publicKey": {}
 13751            }
 13752          },
 13753          "modelCard": {
 13754            "modelParameters": {
 13755              "approach": {}
 13756            },
 13757            "quantitativeAnalysis": {
 13758              "graphics": {}
 13759            },
 13760            "considerations": {}
 13761          }
 13762        },
 13763        {
 13764          "type": "library",
 13765          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11?package-id=88c18788f0dd2cf5",
 13766          "supplier": {},
 13767          "name": "golang.org/x/net",
 13768          "version": "v0.0.0-20201209123823-ac852fbbde11",
 13769          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20201209123823-ac852fbbde11:*:*:*:*:*:*:*",
 13770          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11",
 13771          "swid": {
 13772            "attachment": {}
 13773          },
 13774          "pedigree": {},
 13775          "evidence": {},
 13776          "signature": {
 13777            "signature": {
 13778              "publicKey": {}
 13779            }
 13780          },
 13781          "modelCard": {
 13782            "modelParameters": {
 13783              "approach": {}
 13784            },
 13785            "quantitativeAnalysis": {
 13786              "graphics": {}
 13787            },
 13788            "considerations": {}
 13789          }
 13790        },
 13791        {
 13792          "type": "library",
 13793          "bom-ref": "pkg:golang/golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5?package-id=29aca0a9e9f75509",
 13794          "supplier": {},
 13795          "name": "golang.org/x/oauth2",
 13796          "version": "v0.0.0-20201208152858-08078c50e5b5",
 13797          "cpe": "cpe:2.3:a:golang:x\\/oauth2:v0.0.0-20201208152858-08078c50e5b5:*:*:*:*:*:*:*",
 13798          "purl": "pkg:golang/golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5",
 13799          "swid": {
 13800            "attachment": {}
 13801          },
 13802          "pedigree": {},
 13803          "evidence": {},
 13804          "signature": {
 13805            "signature": {
 13806              "publicKey": {}
 13807            }
 13808          },
 13809          "modelCard": {
 13810            "modelParameters": {
 13811              "approach": {}
 13812            },
 13813            "quantitativeAnalysis": {
 13814              "graphics": {}
 13815            },
 13816            "considerations": {}
 13817          }
 13818        },
 13819        {
 13820          "type": "library",
 13821          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20201214095126-aec9a390925b?package-id=f5e5e742ba0c32fc",
 13822          "supplier": {},
 13823          "name": "golang.org/x/sys",
 13824          "version": "v0.0.0-20201214095126-aec9a390925b",
 13825          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20201214095126-aec9a390925b:*:*:*:*:*:*:*",
 13826          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20201214095126-aec9a390925b",
 13827          "swid": {
 13828            "attachment": {}
 13829          },
 13830          "pedigree": {},
 13831          "evidence": {},
 13832          "signature": {
 13833            "signature": {
 13834              "publicKey": {}
 13835            }
 13836          },
 13837          "modelCard": {
 13838            "modelParameters": {
 13839              "approach": {}
 13840            },
 13841            "quantitativeAnalysis": {
 13842              "graphics": {}
 13843            },
 13844            "considerations": {}
 13845          }
 13846        },
 13847        {
 13848          "type": "library",
 13849          "bom-ref": "pkg:golang/golang.org/x/term@v0.0.0-20201210144234-2321bbc49cbf?package-id=4b6f181809660169",
 13850          "supplier": {},
 13851          "name": "golang.org/x/term",
 13852          "version": "v0.0.0-20201210144234-2321bbc49cbf",
 13853          "cpe": "cpe:2.3:a:golang:x\\/term:v0.0.0-20201210144234-2321bbc49cbf:*:*:*:*:*:*:*",
 13854          "purl": "pkg:golang/golang.org/x/term@v0.0.0-20201210144234-2321bbc49cbf",
 13855          "swid": {
 13856            "attachment": {}
 13857          },
 13858          "pedigree": {},
 13859          "evidence": {},
 13860          "signature": {
 13861            "signature": {
 13862              "publicKey": {}
 13863            }
 13864          },
 13865          "modelCard": {
 13866            "modelParameters": {
 13867              "approach": {}
 13868            },
 13869            "quantitativeAnalysis": {
 13870              "graphics": {}
 13871            },
 13872            "considerations": {}
 13873          }
 13874        },
 13875        {
 13876          "type": "library",
 13877          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.4?package-id=b57979cfd8ce8a9f",
 13878          "supplier": {},
 13879          "name": "golang.org/x/text",
 13880          "version": "v0.3.4",
 13881          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.4:*:*:*:*:*:*:*",
 13882          "purl": "pkg:golang/golang.org/x/text@v0.3.4",
 13883          "swid": {
 13884            "attachment": {}
 13885          },
 13886          "pedigree": {},
 13887          "evidence": {},
 13888          "signature": {
 13889            "signature": {
 13890              "publicKey": {}
 13891            }
 13892          },
 13893          "modelCard": {
 13894            "modelParameters": {
 13895              "approach": {}
 13896            },
 13897            "quantitativeAnalysis": {
 13898              "graphics": {}
 13899            },
 13900            "considerations": {}
 13901          }
 13902        },
 13903        {
 13904          "type": "library",
 13905          "bom-ref": "pkg:golang/golang.org/x/time@v0.0.0-20201208040808-7e3f01d25324?package-id=f921b3793b3ae1f8",
 13906          "supplier": {},
 13907          "name": "golang.org/x/time",
 13908          "version": "v0.0.0-20201208040808-7e3f01d25324",
 13909          "cpe": "cpe:2.3:a:golang:x\\/time:v0.0.0-20201208040808-7e3f01d25324:*:*:*:*:*:*:*",
 13910          "purl": "pkg:golang/golang.org/x/time@v0.0.0-20201208040808-7e3f01d25324",
 13911          "swid": {
 13912            "attachment": {}
 13913          },
 13914          "pedigree": {},
 13915          "evidence": {},
 13916          "signature": {
 13917            "signature": {
 13918              "publicKey": {}
 13919            }
 13920          },
 13921          "modelCard": {
 13922            "modelParameters": {
 13923              "approach": {}
 13924            },
 13925            "quantitativeAnalysis": {
 13926              "graphics": {}
 13927            },
 13928            "considerations": {}
 13929          }
 13930        },
 13931        {
 13932          "type": "library",
 13933          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20201211151036-40ec1c210f7a?package-id=8f890d9f31987220",
 13934          "supplier": {},
 13935          "name": "google.golang.org/genproto",
 13936          "version": "v0.0.0-20201211151036-40ec1c210f7a",
 13937          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20201211151036-40ec1c210f7a:*:*:*:*:*:*:*",
 13938          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20201211151036-40ec1c210f7a",
 13939          "swid": {
 13940            "attachment": {}
 13941          },
 13942          "pedigree": {},
 13943          "evidence": {},
 13944          "signature": {
 13945            "signature": {
 13946              "publicKey": {}
 13947            }
 13948          },
 13949          "modelCard": {
 13950            "modelParameters": {
 13951              "approach": {}
 13952            },
 13953            "quantitativeAnalysis": {
 13954              "graphics": {}
 13955            },
 13956            "considerations": {}
 13957          }
 13958        },
 13959        {
 13960          "type": "library",
 13961          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.34.0?package-id=dec51d98c24a5ac3",
 13962          "supplier": {},
 13963          "name": "google.golang.org/grpc",
 13964          "version": "v1.34.0",
 13965          "cpe": "cpe:2.3:a:google:grpc:v1.34.0:*:*:*:*:*:*:*",
 13966          "purl": "pkg:golang/google.golang.org/grpc@v1.34.0",
 13967          "swid": {
 13968            "attachment": {}
 13969          },
 13970          "pedigree": {},
 13971          "evidence": {},
 13972          "signature": {
 13973            "signature": {
 13974              "publicKey": {}
 13975            }
 13976          },
 13977          "modelCard": {
 13978            "modelParameters": {
 13979              "approach": {}
 13980            },
 13981            "quantitativeAnalysis": {
 13982              "graphics": {}
 13983            },
 13984            "considerations": {}
 13985          }
 13986        },
 13987        {
 13988          "type": "library",
 13989          "bom-ref": "pkg:golang/google.golang.org/protobuf@v1.25.0?package-id=6ee790d30fc8a19e",
 13990          "supplier": {},
 13991          "name": "google.golang.org/protobuf",
 13992          "version": "v1.25.0",
 13993          "cpe": "cpe:2.3:a:google:protobuf:v1.25.0:*:*:*:*:*:*:*",
 13994          "purl": "pkg:golang/google.golang.org/protobuf@v1.25.0",
 13995          "swid": {
 13996            "attachment": {}
 13997          },
 13998          "pedigree": {},
 13999          "evidence": {},
 14000          "signature": {
 14001            "signature": {
 14002              "publicKey": {}
 14003            }
 14004          },
 14005          "modelCard": {
 14006            "modelParameters": {
 14007              "approach": {}
 14008            },
 14009            "quantitativeAnalysis": {
 14010              "graphics": {}
 14011            },
 14012            "considerations": {}
 14013          }
 14014        },
 14015        {
 14016          "type": "library",
 14017          "bom-ref": "pkg:golang/gopkg.in/inf.v0@v0.9.1?package-id=ef83589b9205b744",
 14018          "supplier": {},
 14019          "name": "gopkg.in/inf.v0",
 14020          "version": "v0.9.1",
 14021          "purl": "pkg:golang/gopkg.in/inf.v0@v0.9.1",
 14022          "swid": {
 14023            "attachment": {}
 14024          },
 14025          "pedigree": {},
 14026          "evidence": {},
 14027          "signature": {
 14028            "signature": {
 14029              "publicKey": {}
 14030            }
 14031          },
 14032          "modelCard": {
 14033            "modelParameters": {
 14034              "approach": {}
 14035            },
 14036            "quantitativeAnalysis": {
 14037              "graphics": {}
 14038            },
 14039            "considerations": {}
 14040          }
 14041        },
 14042        {
 14043          "type": "library",
 14044          "bom-ref": "pkg:golang/gopkg.in/yaml.v2@v2.4.0?package-id=4f65923f7eba7149",
 14045          "supplier": {},
 14046          "name": "gopkg.in/yaml.v2",
 14047          "version": "v2.4.0",
 14048          "purl": "pkg:golang/gopkg.in/yaml.v2@v2.4.0",
 14049          "swid": {
 14050            "attachment": {}
 14051          },
 14052          "pedigree": {},
 14053          "evidence": {},
 14054          "signature": {
 14055            "signature": {
 14056              "publicKey": {}
 14057            }
 14058          },
 14059          "modelCard": {
 14060            "modelParameters": {
 14061              "approach": {}
 14062            },
 14063            "quantitativeAnalysis": {
 14064              "graphics": {}
 14065            },
 14066            "considerations": {}
 14067          }
 14068        },
 14069        {
 14070          "type": "library",
 14071          "bom-ref": "pkg:golang/gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776?package-id=cff0559185b67bd1",
 14072          "supplier": {},
 14073          "name": "gopkg.in/yaml.v3",
 14074          "version": "v3.0.0-20200615113413-eeeca48fe776",
 14075          "purl": "pkg:golang/gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776",
 14076          "swid": {
 14077            "attachment": {}
 14078          },
 14079          "pedigree": {},
 14080          "evidence": {},
 14081          "signature": {
 14082            "signature": {
 14083              "publicKey": {}
 14084            }
 14085          },
 14086          "modelCard": {
 14087            "modelParameters": {
 14088              "approach": {}
 14089            },
 14090            "quantitativeAnalysis": {
 14091              "graphics": {}
 14092            },
 14093            "considerations": {}
 14094          }
 14095        },
 14096        {
 14097          "type": "library",
 14098          "bom-ref": "pkg:golang/k8s.io/api@v0.20.4?package-id=8f70691277a1cc86",
 14099          "supplier": {},
 14100          "name": "k8s.io/api",
 14101          "version": "v0.20.4",
 14102          "purl": "pkg:golang/k8s.io/api@v0.20.4",
 14103          "swid": {
 14104            "attachment": {}
 14105          },
 14106          "pedigree": {},
 14107          "evidence": {},
 14108          "signature": {
 14109            "signature": {
 14110              "publicKey": {}
 14111            }
 14112          },
 14113          "modelCard": {
 14114            "modelParameters": {
 14115              "approach": {}
 14116            },
 14117            "quantitativeAnalysis": {
 14118              "graphics": {}
 14119            },
 14120            "considerations": {}
 14121          }
 14122        },
 14123        {
 14124          "type": "library",
 14125          "bom-ref": "pkg:golang/k8s.io/apimachinery@v0.20.4?package-id=3155793d5e99e63f",
 14126          "supplier": {},
 14127          "name": "k8s.io/apimachinery",
 14128          "version": "v0.20.4",
 14129          "purl": "pkg:golang/k8s.io/apimachinery@v0.20.4",
 14130          "swid": {
 14131            "attachment": {}
 14132          },
 14133          "pedigree": {},
 14134          "evidence": {},
 14135          "signature": {
 14136            "signature": {
 14137              "publicKey": {}
 14138            }
 14139          },
 14140          "modelCard": {
 14141            "modelParameters": {
 14142              "approach": {}
 14143            },
 14144            "quantitativeAnalysis": {
 14145              "graphics": {}
 14146            },
 14147            "considerations": {}
 14148          }
 14149        },
 14150        {
 14151          "type": "library",
 14152          "bom-ref": "pkg:golang/k8s.io/apiserver@v0.20.4?package-id=eb1e3d65012d348d",
 14153          "supplier": {},
 14154          "name": "k8s.io/apiserver",
 14155          "version": "v0.20.4",
 14156          "purl": "pkg:golang/k8s.io/apiserver@v0.20.4",
 14157          "swid": {
 14158            "attachment": {}
 14159          },
 14160          "pedigree": {},
 14161          "evidence": {},
 14162          "signature": {
 14163            "signature": {
 14164              "publicKey": {}
 14165            }
 14166          },
 14167          "modelCard": {
 14168            "modelParameters": {
 14169              "approach": {}
 14170            },
 14171            "quantitativeAnalysis": {
 14172              "graphics": {}
 14173            },
 14174            "considerations": {}
 14175          }
 14176        },
 14177        {
 14178          "type": "library",
 14179          "bom-ref": "pkg:golang/k8s.io/client-go@v0.20.4?package-id=b1ffa8e19573600e",
 14180          "supplier": {},
 14181          "name": "k8s.io/client-go",
 14182          "version": "v0.20.4",
 14183          "purl": "pkg:golang/k8s.io/client-go@v0.20.4",
 14184          "swid": {
 14185            "attachment": {}
 14186          },
 14187          "pedigree": {},
 14188          "evidence": {},
 14189          "signature": {
 14190            "signature": {
 14191              "publicKey": {}
 14192            }
 14193          },
 14194          "modelCard": {
 14195            "modelParameters": {
 14196              "approach": {}
 14197            },
 14198            "quantitativeAnalysis": {
 14199              "graphics": {}
 14200            },
 14201            "considerations": {}
 14202          }
 14203        },
 14204        {
 14205          "type": "library",
 14206          "bom-ref": "pkg:golang/k8s.io/component-base@v0.20.4?package-id=5483a6235a011212",
 14207          "supplier": {},
 14208          "name": "k8s.io/component-base",
 14209          "version": "v0.20.4",
 14210          "purl": "pkg:golang/k8s.io/component-base@v0.20.4",
 14211          "swid": {
 14212            "attachment": {}
 14213          },
 14214          "pedigree": {},
 14215          "evidence": {},
 14216          "signature": {
 14217            "signature": {
 14218              "publicKey": {}
 14219            }
 14220          },
 14221          "modelCard": {
 14222            "modelParameters": {
 14223              "approach": {}
 14224            },
 14225            "quantitativeAnalysis": {
 14226              "graphics": {}
 14227            },
 14228            "considerations": {}
 14229          }
 14230        },
 14231        {
 14232          "type": "library",
 14233          "bom-ref": "pkg:golang/k8s.io/component-helpers@v0.20.4?package-id=23d332f3f6db6ab0",
 14234          "supplier": {},
 14235          "name": "k8s.io/component-helpers",
 14236          "version": "v0.20.4",
 14237          "purl": "pkg:golang/k8s.io/component-helpers@v0.20.4",
 14238          "swid": {
 14239            "attachment": {}
 14240          },
 14241          "pedigree": {},
 14242          "evidence": {},
 14243          "signature": {
 14244            "signature": {
 14245              "publicKey": {}
 14246            }
 14247          },
 14248          "modelCard": {
 14249            "modelParameters": {
 14250              "approach": {}
 14251            },
 14252            "quantitativeAnalysis": {
 14253              "graphics": {}
 14254            },
 14255            "considerations": {}
 14256          }
 14257        },
 14258        {
 14259          "type": "library",
 14260          "bom-ref": "pkg:golang/k8s.io/csi-translation-lib@v0.21.0-alpha.3?package-id=3b3970e274503390",
 14261          "supplier": {},
 14262          "name": "k8s.io/csi-translation-lib",
 14263          "version": "v0.21.0-alpha.3",
 14264          "purl": "pkg:golang/k8s.io/csi-translation-lib@v0.21.0-alpha.3",
 14265          "swid": {
 14266            "attachment": {}
 14267          },
 14268          "pedigree": {},
 14269          "evidence": {},
 14270          "signature": {
 14271            "signature": {
 14272              "publicKey": {}
 14273            }
 14274          },
 14275          "modelCard": {
 14276            "modelParameters": {
 14277              "approach": {}
 14278            },
 14279            "quantitativeAnalysis": {
 14280              "graphics": {}
 14281            },
 14282            "considerations": {}
 14283          }
 14284        },
 14285        {
 14286          "type": "library",
 14287          "bom-ref": "pkg:golang/k8s.io/klog/v2@v2.5.0?package-id=57df0240e9181489",
 14288          "supplier": {},
 14289          "name": "k8s.io/klog/v2",
 14290          "version": "v2.5.0",
 14291          "cpe": "cpe:2.3:a:klog:v2:v2.5.0:*:*:*:*:*:*:*",
 14292          "purl": "pkg:golang/k8s.io/klog/v2@v2.5.0",
 14293          "swid": {
 14294            "attachment": {}
 14295          },
 14296          "pedigree": {},
 14297          "evidence": {},
 14298          "signature": {
 14299            "signature": {
 14300              "publicKey": {}
 14301            }
 14302          },
 14303          "modelCard": {
 14304            "modelParameters": {
 14305              "approach": {}
 14306            },
 14307            "quantitativeAnalysis": {
 14308              "graphics": {}
 14309            },
 14310            "considerations": {}
 14311          }
 14312        },
 14313        {
 14314          "type": "library",
 14315          "bom-ref": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20201113171705-d219536bb9fd?package-id=2608e4c9d5c367be",
 14316          "supplier": {},
 14317          "name": "k8s.io/kube-openapi",
 14318          "version": "v0.0.0-20201113171705-d219536bb9fd",
 14319          "purl": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20201113171705-d219536bb9fd",
 14320          "swid": {
 14321            "attachment": {}
 14322          },
 14323          "pedigree": {},
 14324          "evidence": {},
 14325          "signature": {
 14326            "signature": {
 14327              "publicKey": {}
 14328            }
 14329          },
 14330          "modelCard": {
 14331            "modelParameters": {
 14332              "approach": {}
 14333            },
 14334            "quantitativeAnalysis": {
 14335              "graphics": {}
 14336            },
 14337            "considerations": {}
 14338          }
 14339        },
 14340        {
 14341          "type": "library",
 14342          "bom-ref": "pkg:golang/k8s.io/utils@v0.0.0-20201110183641-67b214c5f920?package-id=c2f84cbbd900bfd8",
 14343          "supplier": {},
 14344          "name": "k8s.io/utils",
 14345          "version": "v0.0.0-20201110183641-67b214c5f920",
 14346          "purl": "pkg:golang/k8s.io/utils@v0.0.0-20201110183641-67b214c5f920",
 14347          "swid": {
 14348            "attachment": {}
 14349          },
 14350          "pedigree": {},
 14351          "evidence": {},
 14352          "signature": {
 14353            "signature": {
 14354              "publicKey": {}
 14355            }
 14356          },
 14357          "modelCard": {
 14358            "modelParameters": {
 14359              "approach": {}
 14360            },
 14361            "quantitativeAnalysis": {
 14362              "graphics": {}
 14363            },
 14364            "considerations": {}
 14365          }
 14366        },
 14367        {
 14368          "type": "library",
 14369          "bom-ref": "pkg:deb/debian/netbase@5.6?arch=all\u0026distro=debian-10\u0026package-id=b55e51dca4eba9a6",
 14370          "supplier": {},
 14371          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
 14372          "name": "netbase",
 14373          "version": "5.6",
 14374          "licenses": [
 14375            {
 14376              "license": {
 14377                "id": "GPL-2.0-only"
 14378              }
 14379            }
 14380          ],
 14381          "cpe": "cpe:2.3:a:netbase:netbase:5.6:*:*:*:*:*:*:*",
 14382          "purl": "pkg:deb/debian/netbase@5.6?arch=all\u0026distro=debian-10",
 14383          "swid": {
 14384            "attachment": {}
 14385          },
 14386          "pedigree": {},
 14387          "evidence": {},
 14388          "signature": {
 14389            "signature": {
 14390              "publicKey": {}
 14391            }
 14392          },
 14393          "modelCard": {
 14394            "modelParameters": {
 14395              "approach": {}
 14396            },
 14397            "quantitativeAnalysis": {
 14398              "graphics": {}
 14399            },
 14400            "considerations": {}
 14401          }
 14402        },
 14403        {
 14404          "type": "library",
 14405          "bom-ref": "pkg:golang/sigs.k8s.io/controller-runtime@v0.7.0?package-id=e4d65b1ab954f0e8",
 14406          "supplier": {},
 14407          "name": "sigs.k8s.io/controller-runtime",
 14408          "version": "v0.7.0",
 14409          "purl": "pkg:golang/sigs.k8s.io/controller-runtime@v0.7.0",
 14410          "swid": {
 14411            "attachment": {}
 14412          },
 14413          "pedigree": {},
 14414          "evidence": {},
 14415          "signature": {
 14416            "signature": {
 14417              "publicKey": {}
 14418            }
 14419          },
 14420          "modelCard": {
 14421            "modelParameters": {
 14422              "approach": {}
 14423            },
 14424            "quantitativeAnalysis": {
 14425              "graphics": {}
 14426            },
 14427            "considerations": {}
 14428          }
 14429        },
 14430        {
 14431          "type": "library",
 14432          "bom-ref": "pkg:golang/sigs.k8s.io/sig-storage-lib-external-provisioner/v6@v6.3.0?package-id=a28ed5f781c23a96",
 14433          "supplier": {},
 14434          "name": "sigs.k8s.io/sig-storage-lib-external-provisioner/v6",
 14435          "version": "v6.3.0",
 14436          "cpe": "cpe:2.3:a:sig-storage-lib-external-provisioner:v6:v6.3.0:*:*:*:*:*:*:*",
 14437          "purl": "pkg:golang/sigs.k8s.io/sig-storage-lib-external-provisioner/v6@v6.3.0",
 14438          "swid": {
 14439            "attachment": {}
 14440          },
 14441          "pedigree": {},
 14442          "evidence": {},
 14443          "signature": {
 14444            "signature": {
 14445              "publicKey": {}
 14446            }
 14447          },
 14448          "modelCard": {
 14449            "modelParameters": {
 14450              "approach": {}
 14451            },
 14452            "quantitativeAnalysis": {
 14453              "graphics": {}
 14454            },
 14455            "considerations": {}
 14456          }
 14457        },
 14458        {
 14459          "type": "library",
 14460          "bom-ref": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.0.2?package-id=2d41a704ecf334e1",
 14461          "supplier": {},
 14462          "name": "sigs.k8s.io/structured-merge-diff/v4",
 14463          "version": "v4.0.2",
 14464          "cpe": "cpe:2.3:a:structured-merge-diff:v4:v4.0.2:*:*:*:*:*:*:*",
 14465          "purl": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.0.2",
 14466          "swid": {
 14467            "attachment": {}
 14468          },
 14469          "pedigree": {},
 14470          "evidence": {},
 14471          "signature": {
 14472            "signature": {
 14473              "publicKey": {}
 14474            }
 14475          },
 14476          "modelCard": {
 14477            "modelParameters": {
 14478              "approach": {}
 14479            },
 14480            "quantitativeAnalysis": {
 14481              "graphics": {}
 14482            },
 14483            "considerations": {}
 14484          }
 14485        },
 14486        {
 14487          "type": "library",
 14488          "bom-ref": "pkg:golang/sigs.k8s.io/yaml@v1.2.0?package-id=e165a82828172177",
 14489          "supplier": {},
 14490          "name": "sigs.k8s.io/yaml",
 14491          "version": "v1.2.0",
 14492          "purl": "pkg:golang/sigs.k8s.io/yaml@v1.2.0",
 14493          "swid": {
 14494            "attachment": {}
 14495          },
 14496          "pedigree": {},
 14497          "evidence": {},
 14498          "signature": {
 14499            "signature": {
 14500              "publicKey": {}
 14501            }
 14502          },
 14503          "modelCard": {
 14504            "modelParameters": {
 14505              "approach": {}
 14506            },
 14507            "quantitativeAnalysis": {
 14508              "graphics": {}
 14509            },
 14510            "considerations": {}
 14511          }
 14512        },
 14513        {
 14514          "type": "library",
 14515          "bom-ref": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10\u0026package-id=9e5b2198bbbd7fb0",
 14516          "supplier": {},
 14517          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 14518          "name": "tzdata",
 14519          "version": "2021a-0+deb10u1",
 14520          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0\\+deb10u1:*:*:*:*:*:*:*",
 14521          "purl": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10",
 14522          "swid": {
 14523            "attachment": {}
 14524          },
 14525          "pedigree": {},
 14526          "evidence": {},
 14527          "signature": {
 14528            "signature": {
 14529              "publicKey": {}
 14530            }
 14531          },
 14532          "modelCard": {
 14533            "modelParameters": {
 14534              "approach": {}
 14535            },
 14536            "quantitativeAnalysis": {
 14537              "graphics": {}
 14538            },
 14539            "considerations": {}
 14540          }
 14541        },
 14542        {
 14543          "type": "operating-system",
 14544          "supplier": {},
 14545          "name": "debian",
 14546          "version": "10",
 14547          "description": "Distroless",
 14548          "swid": {
 14549            "tagId": "debian",
 14550            "name": "debian",
 14551            "version": "10",
 14552            "attachment": {}
 14553          },
 14554          "pedigree": {},
 14555          "externalReferences": [
 14556            {
 14557              "url": "https://github.com/GoogleContainerTools/distroless/issues/new",
 14558              "type": "issue-tracker"
 14559            },
 14560            {
 14561              "url": "https://github.com/GoogleContainerTools/distroless",
 14562              "type": "website"
 14563            },
 14564            {
 14565              "url": "https://github.com/GoogleContainerTools/distroless/blob/master/README.md",
 14566              "comment": "support",
 14567              "type": "other"
 14568            }
 14569          ],
 14570          "evidence": {},
 14571          "signature": {
 14572            "signature": {
 14573              "publicKey": {}
 14574            }
 14575          },
 14576          "modelCard": {
 14577            "modelParameters": {
 14578              "approach": {}
 14579            },
 14580            "quantitativeAnalysis": {
 14581              "graphics": {}
 14582            },
 14583            "considerations": {}
 14584          }
 14585        },
 14586        {
 14587          "type": "library",
 14588          "bom-ref": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04\u0026package-id=69d1980477020fa3",
 14589          "supplier": {},
 14590          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 14591          "name": "adduser",
 14592          "version": "3.118ubuntu2",
 14593          "licenses": [
 14594            {
 14595              "license": {
 14596                "id": "GPL-2.0-only"
 14597              }
 14598            }
 14599          ],
 14600          "cpe": "cpe:2.3:a:adduser:adduser:3.118ubuntu2:*:*:*:*:*:*:*",
 14601          "purl": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04",
 14602          "swid": {
 14603            "attachment": {}
 14604          },
 14605          "pedigree": {},
 14606          "evidence": {},
 14607          "signature": {
 14608            "signature": {
 14609              "publicKey": {}
 14610            }
 14611          },
 14612          "modelCard": {
 14613            "modelParameters": {
 14614              "approach": {}
 14615            },
 14616            "quantitativeAnalysis": {
 14617              "graphics": {}
 14618            },
 14619            "considerations": {}
 14620          }
 14621        },
 14622        {
 14623          "type": "library",
 14624          "bom-ref": "pkg:deb/ubuntu/alsa-topology-conf@1.2.2-1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=9bedfd9c57f4f85e",
 14625          "supplier": {},
 14626          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 14627          "name": "alsa-topology-conf",
 14628          "version": "1.2.2-1",
 14629          "licenses": [
 14630            {
 14631              "license": {
 14632                "id": "BSD-3-Clause"
 14633              }
 14634            }
 14635          ],
 14636          "cpe": "cpe:2.3:a:alsa-topology-conf:alsa-topology-conf:1.2.2-1:*:*:*:*:*:*:*",
 14637          "purl": "pkg:deb/ubuntu/alsa-topology-conf@1.2.2-1?arch=all\u0026distro=ubuntu-20.04",
 14638          "swid": {
 14639            "attachment": {}
 14640          },
 14641          "pedigree": {},
 14642          "evidence": {},
 14643          "signature": {
 14644            "signature": {
 14645              "publicKey": {}
 14646            }
 14647          },
 14648          "modelCard": {
 14649            "modelParameters": {
 14650              "approach": {}
 14651            },
 14652            "quantitativeAnalysis": {
 14653              "graphics": {}
 14654            },
 14655            "considerations": {}
 14656          }
 14657        },
 14658        {
 14659          "type": "library",
 14660          "bom-ref": "pkg:deb/ubuntu/alsa-ucm-conf@1.2.2-1ubuntu0.9?arch=all\u0026distro=ubuntu-20.04\u0026package-id=beddb81d6dea8f2",
 14661          "supplier": {},
 14662          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 14663          "name": "alsa-ucm-conf",
 14664          "version": "1.2.2-1ubuntu0.9",
 14665          "licenses": [
 14666            {
 14667              "license": {
 14668                "id": "BSD-3-Clause"
 14669              }
 14670            }
 14671          ],
 14672          "cpe": "cpe:2.3:a:alsa-ucm-conf:alsa-ucm-conf:1.2.2-1ubuntu0.9:*:*:*:*:*:*:*",
 14673          "purl": "pkg:deb/ubuntu/alsa-ucm-conf@1.2.2-1ubuntu0.9?arch=all\u0026distro=ubuntu-20.04",
 14674          "swid": {
 14675            "attachment": {}
 14676          },
 14677          "pedigree": {},
 14678          "evidence": {},
 14679          "signature": {
 14680            "signature": {
 14681              "publicKey": {}
 14682            }
 14683          },
 14684          "modelCard": {
 14685            "modelParameters": {
 14686              "approach": {}
 14687            },
 14688            "quantitativeAnalysis": {
 14689              "graphics": {}
 14690            },
 14691            "considerations": {}
 14692          }
 14693        },
 14694        {
 14695          "type": "library",
 14696          "bom-ref": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=55988ea1c6f336e3",
 14697          "supplier": {},
 14698          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 14699          "name": "apt",
 14700          "version": "2.0.6",
 14701          "licenses": [
 14702            {
 14703              "license": {
 14704                "id": "GPL-2.0-only"
 14705              }
 14706            },
 14707            {
 14708              "license": {
 14709                "name": "GPLv2+"
 14710              }
 14711            }
 14712          ],
 14713          "cpe": "cpe:2.3:a:apt:apt:2.0.6:*:*:*:*:*:*:*",
 14714          "purl": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04",
 14715          "swid": {
 14716            "attachment": {}
 14717          },
 14718          "pedigree": {},
 14719          "evidence": {},
 14720          "signature": {
 14721            "signature": {
 14722              "publicKey": {}
 14723            }
 14724          },
 14725          "modelCard": {
 14726            "modelParameters": {
 14727              "approach": {}
 14728            },
 14729            "quantitativeAnalysis": {
 14730              "graphics": {}
 14731            },
 14732            "considerations": {}
 14733          }
 14734        },
 14735        {
 14736          "type": "library",
 14737          "bom-ref": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=63c89c28c512e1db",
 14738          "supplier": {},
 14739          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 14740          "name": "base-files",
 14741          "version": "11ubuntu5.4",
 14742          "licenses": [
 14743            {
 14744              "license": {
 14745                "name": "GPL"
 14746              }
 14747            }
 14748          ],
 14749          "cpe": "cpe:2.3:a:base-files:base-files:11ubuntu5.4:*:*:*:*:*:*:*",
 14750          "purl": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04",
 14751          "swid": {
 14752            "attachment": {}
 14753          },
 14754          "pedigree": {},
 14755          "evidence": {},
 14756          "signature": {
 14757            "signature": {
 14758              "publicKey": {}
 14759            }
 14760          },
 14761          "modelCard": {
 14762            "modelParameters": {
 14763              "approach": {}
 14764            },
 14765            "quantitativeAnalysis": {
 14766              "graphics": {}
 14767            },
 14768            "considerations": {}
 14769          }
 14770        },
 14771        {
 14772          "type": "library",
 14773          "bom-ref": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=8b6e494dac6dab09",
 14774          "supplier": {},
 14775          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
 14776          "name": "base-passwd",
 14777          "version": "3.5.47",
 14778          "licenses": [
 14779            {
 14780              "license": {
 14781                "id": "GPL-2.0-only"
 14782              }
 14783            },
 14784            {
 14785              "license": {
 14786                "name": "PD"
 14787              }
 14788            }
 14789          ],
 14790          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.47:*:*:*:*:*:*:*",
 14791          "purl": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04",
 14792          "swid": {
 14793            "attachment": {}
 14794          },
 14795          "pedigree": {},
 14796          "evidence": {},
 14797          "signature": {
 14798            "signature": {
 14799              "publicKey": {}
 14800            }
 14801          },
 14802          "modelCard": {
 14803            "modelParameters": {
 14804              "approach": {}
 14805            },
 14806            "quantitativeAnalysis": {
 14807              "graphics": {}
 14808            },
 14809            "considerations": {}
 14810          }
 14811        },
 14812        {
 14813          "type": "library",
 14814          "bom-ref": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e774a3e87113196b",
 14815          "supplier": {},
 14816          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 14817          "name": "bash",
 14818          "version": "5.0-6ubuntu1.1",
 14819          "licenses": [
 14820            {
 14821              "license": {
 14822                "id": "GPL-3.0-only"
 14823              }
 14824            }
 14825          ],
 14826          "cpe": "cpe:2.3:a:bash:bash:5.0-6ubuntu1.1:*:*:*:*:*:*:*",
 14827          "purl": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04",
 14828          "swid": {
 14829            "attachment": {}
 14830          },
 14831          "pedigree": {},
 14832          "evidence": {},
 14833          "signature": {
 14834            "signature": {
 14835              "publicKey": {}
 14836            }
 14837          },
 14838          "modelCard": {
 14839            "modelParameters": {
 14840              "approach": {}
 14841            },
 14842            "quantitativeAnalysis": {
 14843              "graphics": {}
 14844            },
 14845            "considerations": {}
 14846          }
 14847        },
 14848        {
 14849          "type": "library",
 14850          "bom-ref": "pkg:deb/ubuntu/bind9-dnsutils@1:9.16.1-0ubuntu2.8?arch=amd64\u0026upstream=bind9\u0026distro=ubuntu-20.04\u0026package-id=329a09dac9f80305",
 14851          "supplier": {},
 14852          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 14853          "name": "bind9-dnsutils",
 14854          "version": "1:9.16.1-0ubuntu2.8",
 14855          "licenses": [
 14856            {
 14857              "license": {
 14858                "id": "BSD-2-Clause"
 14859              }
 14860            },
 14861            {
 14862              "license": {
 14863                "id": "BSD-3-Clause"
 14864              }
 14865            },
 14866            {
 14867              "license": {
 14868                "id": "ISC"
 14869              }
 14870            },
 14871            {
 14872              "license": {
 14873                "id": "MPL-2.0"
 14874              }
 14875            }
 14876          ],
 14877          "cpe": "cpe:2.3:a:bind9-dnsutils:bind9-dnsutils:1\\:9.16.1-0ubuntu2.8:*:*:*:*:*:*:*",
 14878          "purl": "pkg:deb/ubuntu/bind9-dnsutils@1:9.16.1-0ubuntu2.8?arch=amd64\u0026upstream=bind9\u0026distro=ubuntu-20.04",
 14879          "swid": {
 14880            "attachment": {}
 14881          },
 14882          "pedigree": {},
 14883          "evidence": {},
 14884          "signature": {
 14885            "signature": {
 14886              "publicKey": {}
 14887            }
 14888          },
 14889          "modelCard": {
 14890            "modelParameters": {
 14891              "approach": {}
 14892            },
 14893            "quantitativeAnalysis": {
 14894              "graphics": {}
 14895            },
 14896            "considerations": {}
 14897          }
 14898        },
 14899        {
 14900          "type": "library",
 14901          "bom-ref": "pkg:deb/ubuntu/bind9-host@1:9.16.1-0ubuntu2.8?arch=amd64\u0026upstream=bind9\u0026distro=ubuntu-20.04\u0026package-id=e908a518aa52cb2f",
 14902          "supplier": {},
 14903          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 14904          "name": "bind9-host",
 14905          "version": "1:9.16.1-0ubuntu2.8",
 14906          "licenses": [
 14907            {
 14908              "license": {
 14909                "id": "BSD-2-Clause"
 14910              }
 14911            },
 14912            {
 14913              "license": {
 14914                "id": "BSD-3-Clause"
 14915              }
 14916            },
 14917            {
 14918              "license": {
 14919                "id": "ISC"
 14920              }
 14921            },
 14922            {
 14923              "license": {
 14924                "id": "MPL-2.0"
 14925              }
 14926            }
 14927          ],
 14928          "cpe": "cpe:2.3:a:bind9-host:bind9-host:1\\:9.16.1-0ubuntu2.8:*:*:*:*:*:*:*",
 14929          "purl": "pkg:deb/ubuntu/bind9-host@1:9.16.1-0ubuntu2.8?arch=amd64\u0026upstream=bind9\u0026distro=ubuntu-20.04",
 14930          "swid": {
 14931            "attachment": {}
 14932          },
 14933          "pedigree": {},
 14934          "evidence": {},
 14935          "signature": {
 14936            "signature": {
 14937              "publicKey": {}
 14938            }
 14939          },
 14940          "modelCard": {
 14941            "modelParameters": {
 14942              "approach": {}
 14943            },
 14944            "quantitativeAnalysis": {
 14945              "graphics": {}
 14946            },
 14947            "considerations": {}
 14948          }
 14949        },
 14950        {
 14951          "type": "library",
 14952          "bom-ref": "pkg:deb/ubuntu/bind9-libs@1:9.16.1-0ubuntu2.8?arch=amd64\u0026upstream=bind9\u0026distro=ubuntu-20.04\u0026package-id=c73106f3649b27ec",
 14953          "supplier": {},
 14954          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 14955          "name": "bind9-libs",
 14956          "version": "1:9.16.1-0ubuntu2.8",
 14957          "licenses": [
 14958            {
 14959              "license": {
 14960                "id": "BSD-2-Clause"
 14961              }
 14962            },
 14963            {
 14964              "license": {
 14965                "id": "BSD-3-Clause"
 14966              }
 14967            },
 14968            {
 14969              "license": {
 14970                "id": "ISC"
 14971              }
 14972            },
 14973            {
 14974              "license": {
 14975                "id": "MPL-2.0"
 14976              }
 14977            }
 14978          ],
 14979          "cpe": "cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.16.1-0ubuntu2.8:*:*:*:*:*:*:*",
 14980          "purl": "pkg:deb/ubuntu/bind9-libs@1:9.16.1-0ubuntu2.8?arch=amd64\u0026upstream=bind9\u0026distro=ubuntu-20.04",
 14981          "swid": {
 14982            "attachment": {}
 14983          },
 14984          "pedigree": {},
 14985          "evidence": {},
 14986          "signature": {
 14987            "signature": {
 14988              "publicKey": {}
 14989            }
 14990          },
 14991          "modelCard": {
 14992            "modelParameters": {
 14993              "approach": {}
 14994            },
 14995            "quantitativeAnalysis": {
 14996              "graphics": {}
 14997            },
 14998            "considerations": {}
 14999          }
 15000        },
 15001        {
 15002          "type": "library",
 15003          "bom-ref": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04\u0026package-id=20018d8de777eda9",
 15004          "supplier": {},
 15005          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15006          "name": "bsdutils",
 15007          "version": "1:2.34-0.1ubuntu9.1",
 15008          "licenses": [
 15009            {
 15010              "license": {
 15011                "id": "BSD-2-Clause"
 15012              }
 15013            },
 15014            {
 15015              "license": {
 15016                "id": "BSD-3-Clause"
 15017              }
 15018            },
 15019            {
 15020              "license": {
 15021                "id": "BSD-4-Clause"
 15022              }
 15023            },
 15024            {
 15025              "license": {
 15026                "id": "GPL-2.0-only"
 15027              }
 15028            },
 15029            {
 15030              "license": {
 15031                "id": "GPL-2.0-or-later"
 15032              }
 15033            },
 15034            {
 15035              "license": {
 15036                "id": "GPL-3.0-only"
 15037              }
 15038            },
 15039            {
 15040              "license": {
 15041                "id": "GPL-3.0-or-later"
 15042              }
 15043            },
 15044            {
 15045              "license": {
 15046                "name": "LGPL"
 15047              }
 15048            },
 15049            {
 15050              "license": {
 15051                "id": "LGPL-2.0-only"
 15052              }
 15053            },
 15054            {
 15055              "license": {
 15056                "id": "LGPL-2.0-or-later"
 15057              }
 15058            },
 15059            {
 15060              "license": {
 15061                "id": "LGPL-2.1-only"
 15062              }
 15063            },
 15064            {
 15065              "license": {
 15066                "id": "LGPL-2.1-or-later"
 15067              }
 15068            },
 15069            {
 15070              "license": {
 15071                "id": "LGPL-3.0-only"
 15072              }
 15073            },
 15074            {
 15075              "license": {
 15076                "id": "LGPL-3.0-or-later"
 15077              }
 15078            },
 15079            {
 15080              "license": {
 15081                "id": "MIT"
 15082              }
 15083            },
 15084            {
 15085              "license": {
 15086                "name": "public-domain"
 15087              }
 15088            }
 15089          ],
 15090          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 15091          "purl": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04",
 15092          "swid": {
 15093            "attachment": {}
 15094          },
 15095          "pedigree": {},
 15096          "evidence": {},
 15097          "signature": {
 15098            "signature": {
 15099              "publicKey": {}
 15100            }
 15101          },
 15102          "modelCard": {
 15103            "modelParameters": {
 15104              "approach": {}
 15105            },
 15106            "quantitativeAnalysis": {
 15107              "graphics": {}
 15108            },
 15109            "considerations": {}
 15110          }
 15111        },
 15112        {
 15113          "type": "library",
 15114          "bom-ref": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=97dab883cac4c956",
 15115          "supplier": {},
 15116          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15117          "name": "bzip2",
 15118          "version": "1.0.8-2",
 15119          "licenses": [
 15120            {
 15121              "license": {
 15122                "name": "BSD-variant"
 15123              }
 15124            },
 15125            {
 15126              "license": {
 15127                "id": "GPL-2.0-only"
 15128              }
 15129            }
 15130          ],
 15131          "cpe": "cpe:2.3:a:bzip2:bzip2:1.0.8-2:*:*:*:*:*:*:*",
 15132          "purl": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04",
 15133          "swid": {
 15134            "attachment": {}
 15135          },
 15136          "pedigree": {},
 15137          "evidence": {},
 15138          "signature": {
 15139            "signature": {
 15140              "publicKey": {}
 15141            }
 15142          },
 15143          "modelCard": {
 15144            "modelParameters": {
 15145              "approach": {}
 15146            },
 15147            "quantitativeAnalysis": {
 15148              "graphics": {}
 15149            },
 15150            "considerations": {}
 15151          }
 15152        },
 15153        {
 15154          "type": "library",
 15155          "bom-ref": "pkg:deb/ubuntu/ca-certificates@20210119~20.04.1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=b34020e11d6f8983",
 15156          "supplier": {},
 15157          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15158          "name": "ca-certificates",
 15159          "version": "20210119~20.04.1",
 15160          "licenses": [
 15161            {
 15162              "license": {
 15163                "id": "GPL-2.0-only"
 15164              }
 15165            },
 15166            {
 15167              "license": {
 15168                "id": "GPL-2.0-or-later"
 15169              }
 15170            },
 15171            {
 15172              "license": {
 15173                "id": "MPL-2.0"
 15174              }
 15175            }
 15176          ],
 15177          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20210119\\~20.04.1:*:*:*:*:*:*:*",
 15178          "purl": "pkg:deb/ubuntu/ca-certificates@20210119~20.04.1?arch=all\u0026distro=ubuntu-20.04",
 15179          "swid": {
 15180            "attachment": {}
 15181          },
 15182          "pedigree": {},
 15183          "evidence": {},
 15184          "signature": {
 15185            "signature": {
 15186              "publicKey": {}
 15187            }
 15188          },
 15189          "modelCard": {
 15190            "modelParameters": {
 15191              "approach": {}
 15192            },
 15193            "quantitativeAnalysis": {
 15194              "graphics": {}
 15195            },
 15196            "considerations": {}
 15197          }
 15198        },
 15199        {
 15200          "type": "library",
 15201          "bom-ref": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f77283ee51e117fa",
 15202          "supplier": {},
 15203          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15204          "name": "coreutils",
 15205          "version": "8.30-3ubuntu2",
 15206          "licenses": [
 15207            {
 15208              "license": {
 15209                "id": "GPL-3.0-only"
 15210              }
 15211            }
 15212          ],
 15213          "cpe": "cpe:2.3:a:coreutils:coreutils:8.30-3ubuntu2:*:*:*:*:*:*:*",
 15214          "purl": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
 15215          "swid": {
 15216            "attachment": {}
 15217          },
 15218          "pedigree": {},
 15219          "evidence": {},
 15220          "signature": {
 15221            "signature": {
 15222              "publicKey": {}
 15223            }
 15224          },
 15225          "modelCard": {
 15226            "modelParameters": {
 15227              "approach": {}
 15228            },
 15229            "quantitativeAnalysis": {
 15230              "graphics": {}
 15231            },
 15232            "considerations": {}
 15233          }
 15234        },
 15235        {
 15236          "type": "library",
 15237          "bom-ref": "pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=123513dd4ae6c6b7",
 15238          "supplier": {},
 15239          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15240          "name": "curl",
 15241          "version": "7.68.0-1ubuntu2.6",
 15242          "licenses": [
 15243            {
 15244              "license": {
 15245                "id": "BSD-3-Clause"
 15246              }
 15247            },
 15248            {
 15249              "license": {
 15250                "id": "BSD-4-Clause"
 15251              }
 15252            },
 15253            {
 15254              "license": {
 15255                "id": "ISC"
 15256              }
 15257            },
 15258            {
 15259              "license": {
 15260                "id": "curl"
 15261              }
 15262            },
 15263            {
 15264              "license": {
 15265                "name": "other"
 15266              }
 15267            },
 15268            {
 15269              "license": {
 15270                "name": "public-domain"
 15271              }
 15272            }
 15273          ],
 15274          "cpe": "cpe:2.3:a:curl:curl:7.68.0-1ubuntu2.6:*:*:*:*:*:*:*",
 15275          "purl": "pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.6?arch=amd64\u0026distro=ubuntu-20.04",
 15276          "swid": {
 15277            "attachment": {}
 15278          },
 15279          "pedigree": {},
 15280          "evidence": {},
 15281          "signature": {
 15282            "signature": {
 15283              "publicKey": {}
 15284            }
 15285          },
 15286          "modelCard": {
 15287            "modelParameters": {
 15288              "approach": {}
 15289            },
 15290            "quantitativeAnalysis": {
 15291              "graphics": {}
 15292            },
 15293            "considerations": {}
 15294          }
 15295        },
 15296        {
 15297          "type": "library",
 15298          "bom-ref": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=fa0f613df8411b7",
 15299          "supplier": {},
 15300          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15301          "name": "dash",
 15302          "version": "0.5.10.2-6",
 15303          "licenses": [
 15304            {
 15305              "license": {
 15306                "name": "GPL"
 15307              }
 15308            }
 15309          ],
 15310          "cpe": "cpe:2.3:a:dash:dash:0.5.10.2-6:*:*:*:*:*:*:*",
 15311          "purl": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04",
 15312          "swid": {
 15313            "attachment": {}
 15314          },
 15315          "pedigree": {},
 15316          "evidence": {},
 15317          "signature": {
 15318            "signature": {
 15319              "publicKey": {}
 15320            }
 15321          },
 15322          "modelCard": {
 15323            "modelParameters": {
 15324              "approach": {}
 15325            },
 15326            "quantitativeAnalysis": {
 15327              "graphics": {}
 15328            },
 15329            "considerations": {}
 15330          }
 15331        },
 15332        {
 15333          "type": "library",
 15334          "bom-ref": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04\u0026package-id=128eb6066f5ec19c",
 15335          "supplier": {},
 15336          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15337          "name": "debconf",
 15338          "version": "1.5.73",
 15339          "licenses": [
 15340            {
 15341              "license": {
 15342                "id": "BSD-2-Clause"
 15343              }
 15344            }
 15345          ],
 15346          "cpe": "cpe:2.3:a:debconf:debconf:1.5.73:*:*:*:*:*:*:*",
 15347          "purl": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04",
 15348          "swid": {
 15349            "attachment": {}
 15350          },
 15351          "pedigree": {},
 15352          "evidence": {},
 15353          "signature": {
 15354            "signature": {
 15355              "publicKey": {}
 15356            }
 15357          },
 15358          "modelCard": {
 15359            "modelParameters": {
 15360              "approach": {}
 15361            },
 15362            "quantitativeAnalysis": {
 15363              "graphics": {}
 15364            },
 15365            "considerations": {}
 15366          }
 15367        },
 15368        {
 15369          "type": "library",
 15370          "bom-ref": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=328b1094024bda26",
 15371          "supplier": {},
 15372          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15373          "name": "debianutils",
 15374          "version": "4.9.1",
 15375          "licenses": [
 15376            {
 15377              "license": {
 15378                "name": "GPL"
 15379              }
 15380            }
 15381          ],
 15382          "cpe": "cpe:2.3:a:debianutils:debianutils:4.9.1:*:*:*:*:*:*:*",
 15383          "purl": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04",
 15384          "swid": {
 15385            "attachment": {}
 15386          },
 15387          "pedigree": {},
 15388          "evidence": {},
 15389          "signature": {
 15390            "signature": {
 15391              "publicKey": {}
 15392            }
 15393          },
 15394          "modelCard": {
 15395            "modelParameters": {
 15396              "approach": {}
 15397            },
 15398            "quantitativeAnalysis": {
 15399              "graphics": {}
 15400            },
 15401            "considerations": {}
 15402          }
 15403        },
 15404        {
 15405          "type": "library",
 15406          "bom-ref": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=d21aefcaf9c9c9b6",
 15407          "supplier": {},
 15408          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15409          "name": "diffutils",
 15410          "version": "1:3.7-3",
 15411          "licenses": [
 15412            {
 15413              "license": {
 15414                "name": "GFDL"
 15415              }
 15416            },
 15417            {
 15418              "license": {
 15419                "name": "GPL"
 15420              }
 15421            }
 15422          ],
 15423          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-3:*:*:*:*:*:*:*",
 15424          "purl": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04",
 15425          "swid": {
 15426            "attachment": {}
 15427          },
 15428          "pedigree": {},
 15429          "evidence": {},
 15430          "signature": {
 15431            "signature": {
 15432              "publicKey": {}
 15433            }
 15434          },
 15435          "modelCard": {
 15436            "modelParameters": {
 15437              "approach": {}
 15438            },
 15439            "quantitativeAnalysis": {
 15440              "graphics": {}
 15441            },
 15442            "considerations": {}
 15443          }
 15444        },
 15445        {
 15446          "type": "library",
 15447          "bom-ref": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=c0d6316be2747294",
 15448          "supplier": {},
 15449          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15450          "name": "dmsetup",
 15451          "version": "2:1.02.167-1ubuntu1",
 15452          "licenses": [
 15453            {
 15454              "license": {
 15455                "id": "BSD-2-Clause"
 15456              }
 15457            },
 15458            {
 15459              "license": {
 15460                "id": "GPL-2.0-only"
 15461              }
 15462            },
 15463            {
 15464              "license": {
 15465                "id": "GPL-2.0-only"
 15466              }
 15467            },
 15468            {
 15469              "license": {
 15470                "id": "GPL-2.0-or-later"
 15471              }
 15472            },
 15473            {
 15474              "license": {
 15475                "id": "LGPL-2.0-only"
 15476              }
 15477            },
 15478            {
 15479              "license": {
 15480                "id": "LGPL-2.1-only"
 15481              }
 15482            }
 15483          ],
 15484          "cpe": "cpe:2.3:a:dmsetup:dmsetup:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
 15485          "purl": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
 15486          "swid": {
 15487            "attachment": {}
 15488          },
 15489          "pedigree": {},
 15490          "evidence": {},
 15491          "signature": {
 15492            "signature": {
 15493              "publicKey": {}
 15494            }
 15495          },
 15496          "modelCard": {
 15497            "modelParameters": {
 15498              "approach": {}
 15499            },
 15500            "quantitativeAnalysis": {
 15501              "graphics": {}
 15502            },
 15503            "considerations": {}
 15504          }
 15505        },
 15506        {
 15507          "type": "library",
 15508          "bom-ref": "pkg:deb/ubuntu/dnsutils@1:9.16.1-0ubuntu2.8?arch=all\u0026upstream=bind9\u0026distro=ubuntu-20.04\u0026package-id=a60d40be4a5d7f4c",
 15509          "supplier": {},
 15510          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15511          "name": "dnsutils",
 15512          "version": "1:9.16.1-0ubuntu2.8",
 15513          "licenses": [
 15514            {
 15515              "license": {
 15516                "id": "BSD-2-Clause"
 15517              }
 15518            },
 15519            {
 15520              "license": {
 15521                "id": "BSD-3-Clause"
 15522              }
 15523            },
 15524            {
 15525              "license": {
 15526                "id": "ISC"
 15527              }
 15528            },
 15529            {
 15530              "license": {
 15531                "id": "MPL-2.0"
 15532              }
 15533            }
 15534          ],
 15535          "cpe": "cpe:2.3:a:dnsutils:dnsutils:1\\:9.16.1-0ubuntu2.8:*:*:*:*:*:*:*",
 15536          "purl": "pkg:deb/ubuntu/dnsutils@1:9.16.1-0ubuntu2.8?arch=all\u0026upstream=bind9\u0026distro=ubuntu-20.04",
 15537          "swid": {
 15538            "attachment": {}
 15539          },
 15540          "pedigree": {},
 15541          "evidence": {},
 15542          "signature": {
 15543            "signature": {
 15544              "publicKey": {}
 15545            }
 15546          },
 15547          "modelCard": {
 15548            "modelParameters": {
 15549              "approach": {}
 15550            },
 15551            "quantitativeAnalysis": {
 15552              "graphics": {}
 15553            },
 15554            "considerations": {}
 15555          }
 15556        },
 15557        {
 15558          "type": "library",
 15559          "bom-ref": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e28aea5c134a7f8",
 15560          "supplier": {},
 15561          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15562          "name": "dpkg",
 15563          "version": "1.19.7ubuntu3",
 15564          "licenses": [
 15565            {
 15566              "license": {
 15567                "id": "BSD-2-Clause"
 15568              }
 15569            },
 15570            {
 15571              "license": {
 15572                "id": "GPL-2.0-only"
 15573              }
 15574            },
 15575            {
 15576              "license": {
 15577                "id": "GPL-2.0-or-later"
 15578              }
 15579            },
 15580            {
 15581              "license": {
 15582                "name": "public-domain-md5"
 15583              }
 15584            },
 15585            {
 15586              "license": {
 15587                "name": "public-domain-s-s-d"
 15588              }
 15589            }
 15590          ],
 15591          "cpe": "cpe:2.3:a:dpkg:dpkg:1.19.7ubuntu3:*:*:*:*:*:*:*",
 15592          "purl": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04",
 15593          "swid": {
 15594            "attachment": {}
 15595          },
 15596          "pedigree": {},
 15597          "evidence": {},
 15598          "signature": {
 15599            "signature": {
 15600              "publicKey": {}
 15601            }
 15602          },
 15603          "modelCard": {
 15604            "modelParameters": {
 15605              "approach": {}
 15606            },
 15607            "quantitativeAnalysis": {
 15608              "graphics": {}
 15609            },
 15610            "considerations": {}
 15611          }
 15612        },
 15613        {
 15614          "type": "library",
 15615          "bom-ref": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=6a037357f3ebf47a",
 15616          "supplier": {},
 15617          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15618          "name": "e2fsprogs",
 15619          "version": "1.45.5-2ubuntu1",
 15620          "licenses": [
 15621            {
 15622              "license": {
 15623                "id": "GPL-2.0-only"
 15624              }
 15625            },
 15626            {
 15627              "license": {
 15628                "id": "LGPL-2.0-only"
 15629              }
 15630            }
 15631          ],
 15632          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 15633          "purl": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 15634          "swid": {
 15635            "attachment": {}
 15636          },
 15637          "pedigree": {},
 15638          "evidence": {},
 15639          "signature": {
 15640            "signature": {
 15641              "publicKey": {}
 15642            }
 15643          },
 15644          "modelCard": {
 15645            "modelParameters": {
 15646              "approach": {}
 15647            },
 15648            "quantitativeAnalysis": {
 15649              "graphics": {}
 15650            },
 15651            "considerations": {}
 15652          }
 15653        },
 15654        {
 15655          "type": "library",
 15656          "bom-ref": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=a57a5f37c7970fe9",
 15657          "supplier": {},
 15658          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15659          "name": "fdisk",
 15660          "version": "2.34-0.1ubuntu9.1",
 15661          "licenses": [
 15662            {
 15663              "license": {
 15664                "id": "BSD-2-Clause"
 15665              }
 15666            },
 15667            {
 15668              "license": {
 15669                "id": "BSD-3-Clause"
 15670              }
 15671            },
 15672            {
 15673              "license": {
 15674                "id": "BSD-4-Clause"
 15675              }
 15676            },
 15677            {
 15678              "license": {
 15679                "id": "GPL-2.0-only"
 15680              }
 15681            },
 15682            {
 15683              "license": {
 15684                "id": "GPL-2.0-or-later"
 15685              }
 15686            },
 15687            {
 15688              "license": {
 15689                "id": "GPL-3.0-only"
 15690              }
 15691            },
 15692            {
 15693              "license": {
 15694                "id": "GPL-3.0-or-later"
 15695              }
 15696            },
 15697            {
 15698              "license": {
 15699                "name": "LGPL"
 15700              }
 15701            },
 15702            {
 15703              "license": {
 15704                "id": "LGPL-2.0-only"
 15705              }
 15706            },
 15707            {
 15708              "license": {
 15709                "id": "LGPL-2.0-or-later"
 15710              }
 15711            },
 15712            {
 15713              "license": {
 15714                "id": "LGPL-2.1-only"
 15715              }
 15716            },
 15717            {
 15718              "license": {
 15719                "id": "LGPL-2.1-or-later"
 15720              }
 15721            },
 15722            {
 15723              "license": {
 15724                "id": "LGPL-3.0-only"
 15725              }
 15726            },
 15727            {
 15728              "license": {
 15729                "id": "LGPL-3.0-or-later"
 15730              }
 15731            },
 15732            {
 15733              "license": {
 15734                "id": "MIT"
 15735              }
 15736            },
 15737            {
 15738              "license": {
 15739                "name": "public-domain"
 15740              }
 15741            }
 15742          ],
 15743          "cpe": "cpe:2.3:a:fdisk:fdisk:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 15744          "purl": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 15745          "swid": {
 15746            "attachment": {}
 15747          },
 15748          "pedigree": {},
 15749          "evidence": {},
 15750          "signature": {
 15751            "signature": {
 15752              "publicKey": {}
 15753            }
 15754          },
 15755          "modelCard": {
 15756            "modelParameters": {
 15757              "approach": {}
 15758            },
 15759            "quantitativeAnalysis": {
 15760              "graphics": {}
 15761            },
 15762            "considerations": {}
 15763          }
 15764        },
 15765        {
 15766          "type": "library",
 15767          "bom-ref": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7f183ce6dc05cfb",
 15768          "supplier": {},
 15769          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15770          "name": "file",
 15771          "version": "1:5.38-4",
 15772          "licenses": [
 15773            {
 15774              "license": {
 15775                "name": "BSD-2-Clause-alike"
 15776              }
 15777            },
 15778            {
 15779              "license": {
 15780                "id": "BSD-2-Clause"
 15781              }
 15782            },
 15783            {
 15784              "license": {
 15785                "name": "BSD-2-Clause-regents"
 15786              }
 15787            },
 15788            {
 15789              "license": {
 15790                "name": "MIT-Old-Style-with-legal-disclaimer-2"
 15791              }
 15792            },
 15793            {
 15794              "license": {
 15795                "name": "public-domain"
 15796              }
 15797            }
 15798          ],
 15799          "cpe": "cpe:2.3:a:file:file:1\\:5.38-4:*:*:*:*:*:*:*",
 15800          "purl": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04",
 15801          "swid": {
 15802            "attachment": {}
 15803          },
 15804          "pedigree": {},
 15805          "evidence": {},
 15806          "signature": {
 15807            "signature": {
 15808              "publicKey": {}
 15809            }
 15810          },
 15811          "modelCard": {
 15812            "modelParameters": {
 15813              "approach": {}
 15814            },
 15815            "quantitativeAnalysis": {
 15816              "graphics": {}
 15817            },
 15818            "considerations": {}
 15819          }
 15820        },
 15821        {
 15822          "type": "library",
 15823          "bom-ref": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=103a5999463b7e08",
 15824          "supplier": {},
 15825          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15826          "name": "findutils",
 15827          "version": "4.7.0-1ubuntu1",
 15828          "licenses": [
 15829            {
 15830              "license": {
 15831                "id": "GFDL-1.3-only"
 15832              }
 15833            },
 15834            {
 15835              "license": {
 15836                "id": "GPL-3.0-only"
 15837              }
 15838            }
 15839          ],
 15840          "cpe": "cpe:2.3:a:findutils:findutils:4.7.0-1ubuntu1:*:*:*:*:*:*:*",
 15841          "purl": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 15842          "swid": {
 15843            "attachment": {}
 15844          },
 15845          "pedigree": {},
 15846          "evidence": {},
 15847          "signature": {
 15848            "signature": {
 15849              "publicKey": {}
 15850            }
 15851          },
 15852          "modelCard": {
 15853            "modelParameters": {
 15854              "approach": {}
 15855            },
 15856            "quantitativeAnalysis": {
 15857              "graphics": {}
 15858            },
 15859            "considerations": {}
 15860          }
 15861        },
 15862        {
 15863          "type": "library",
 15864          "bom-ref": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=a268d6ad2986f239",
 15865          "supplier": {},
 15866          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 15867          "name": "gcc-10-base",
 15868          "version": "10.3.0-1ubuntu1~20.04",
 15869          "licenses": [
 15870            {
 15871              "license": {
 15872                "name": "Artistic"
 15873              }
 15874            },
 15875            {
 15876              "license": {
 15877                "id": "GFDL-1.2-only"
 15878              }
 15879            },
 15880            {
 15881              "license": {
 15882                "name": "GPL"
 15883              }
 15884            },
 15885            {
 15886              "license": {
 15887                "id": "GPL-2.0-only"
 15888              }
 15889            },
 15890            {
 15891              "license": {
 15892                "id": "GPL-3.0-only"
 15893              }
 15894            },
 15895            {
 15896              "license": {
 15897                "name": "LGPL"
 15898              }
 15899            }
 15900          ],
 15901          "cpe": "cpe:2.3:a:gcc-10-base:gcc-10-base:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
 15902          "purl": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
 15903          "swid": {
 15904            "attachment": {}
 15905          },
 15906          "pedigree": {},
 15907          "evidence": {},
 15908          "signature": {
 15909            "signature": {
 15910              "publicKey": {}
 15911            }
 15912          },
 15913          "modelCard": {
 15914            "modelParameters": {
 15915              "approach": {}
 15916            },
 15917            "quantitativeAnalysis": {
 15918              "graphics": {}
 15919            },
 15920            "considerations": {}
 15921          }
 15922        },
 15923        {
 15924          "type": "library",
 15925          "bom-ref": "pkg:golang/github.com/roaringbitmap/roaring@v0.4.18?package-id=d089ae842575f8b2",
 15926          "supplier": {},
 15927          "name": "github.com/RoaringBitmap/roaring",
 15928          "version": "v0.4.18",
 15929          "cpe": "cpe:2.3:a:RoaringBitmap:roaring:v0.4.18:*:*:*:*:*:*:*",
 15930          "purl": "pkg:golang/github.com/RoaringBitmap/roaring@v0.4.18",
 15931          "swid": {
 15932            "attachment": {}
 15933          },
 15934          "pedigree": {},
 15935          "evidence": {},
 15936          "signature": {
 15937            "signature": {
 15938              "publicKey": {}
 15939            }
 15940          },
 15941          "modelCard": {
 15942            "modelParameters": {
 15943              "approach": {}
 15944            },
 15945            "quantitativeAnalysis": {
 15946              "graphics": {}
 15947            },
 15948            "considerations": {}
 15949          }
 15950        },
 15951        {
 15952          "type": "library",
 15953          "bom-ref": "pkg:golang/github.com/beorn7/perks@v1.0.1?package-id=5f85d29eac3ebc25",
 15954          "supplier": {},
 15955          "name": "github.com/beorn7/perks",
 15956          "version": "v1.0.1",
 15957          "cpe": "cpe:2.3:a:beorn7:perks:v1.0.1:*:*:*:*:*:*:*",
 15958          "purl": "pkg:golang/github.com/beorn7/perks@v1.0.1",
 15959          "swid": {
 15960            "attachment": {}
 15961          },
 15962          "pedigree": {},
 15963          "evidence": {},
 15964          "signature": {
 15965            "signature": {
 15966              "publicKey": {}
 15967            }
 15968          },
 15969          "modelCard": {
 15970            "modelParameters": {
 15971              "approach": {}
 15972            },
 15973            "quantitativeAnalysis": {
 15974              "graphics": {}
 15975            },
 15976            "considerations": {}
 15977          }
 15978        },
 15979        {
 15980          "type": "library",
 15981          "bom-ref": "pkg:golang/github.com/c9s/goprocinfo@v0.0.0-20190309065803-0b2ad9ac246b?package-id=24f952dc860a2901",
 15982          "supplier": {},
 15983          "name": "github.com/c9s/goprocinfo",
 15984          "version": "v0.0.0-20190309065803-0b2ad9ac246b",
 15985          "cpe": "cpe:2.3:a:c9s:goprocinfo:v0.0.0-20190309065803-0b2ad9ac246b:*:*:*:*:*:*:*",
 15986          "purl": "pkg:golang/github.com/c9s/goprocinfo@v0.0.0-20190309065803-0b2ad9ac246b",
 15987          "swid": {
 15988            "attachment": {}
 15989          },
 15990          "pedigree": {},
 15991          "evidence": {},
 15992          "signature": {
 15993            "signature": {
 15994              "publicKey": {}
 15995            }
 15996          },
 15997          "modelCard": {
 15998            "modelParameters": {
 15999              "approach": {}
 16000            },
 16001            "quantitativeAnalysis": {
 16002              "graphics": {}
 16003            },
 16004            "considerations": {}
 16005          }
 16006        },
 16007        {
 16008          "type": "library",
 16009          "bom-ref": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.0?package-id=5521606a3929bc2a",
 16010          "supplier": {},
 16011          "name": "github.com/cespare/xxhash/v2",
 16012          "version": "v2.1.0",
 16013          "cpe": "cpe:2.3:a:cespare:xxhash\\/v2:v2.1.0:*:*:*:*:*:*:*",
 16014          "purl": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.0",
 16015          "swid": {
 16016            "attachment": {}
 16017          },
 16018          "pedigree": {},
 16019          "evidence": {},
 16020          "signature": {
 16021            "signature": {
 16022              "publicKey": {}
 16023            }
 16024          },
 16025          "modelCard": {
 16026            "modelParameters": {
 16027              "approach": {}
 16028            },
 16029            "quantitativeAnalysis": {
 16030              "graphics": {}
 16031            },
 16032            "considerations": {}
 16033          }
 16034        },
 16035        {
 16036          "type": "library",
 16037          "bom-ref": "pkg:golang/github.com/container-storage-interface/spec@v1.2.0?package-id=bad6288e8e35d5fc",
 16038          "supplier": {},
 16039          "name": "github.com/container-storage-interface/spec",
 16040          "version": "v1.2.0",
 16041          "cpe": "cpe:2.3:a:container-storage-interface:spec:v1.2.0:*:*:*:*:*:*:*",
 16042          "purl": "pkg:golang/github.com/container-storage-interface/spec@v1.2.0",
 16043          "swid": {
 16044            "attachment": {}
 16045          },
 16046          "pedigree": {},
 16047          "evidence": {},
 16048          "signature": {
 16049            "signature": {
 16050              "publicKey": {}
 16051            }
 16052          },
 16053          "modelCard": {
 16054            "modelParameters": {
 16055              "approach": {}
 16056            },
 16057            "quantitativeAnalysis": {
 16058              "graphics": {}
 16059            },
 16060            "considerations": {}
 16061          }
 16062        },
 16063        {
 16064          "type": "library",
 16065          "bom-ref": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d?package-id=70e130a04c65e383",
 16066          "supplier": {},
 16067          "name": "github.com/cpuguy83/go-md2man/v2",
 16068          "version": "v2.0.0-20190314233015-f79a8a8ca69d",
 16069          "cpe": "cpe:2.3:a:cpuguy83:go-md2man\\/v2:v2.0.0-20190314233015-f79a8a8ca69d:*:*:*:*:*:*:*",
 16070          "purl": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d",
 16071          "swid": {
 16072            "attachment": {}
 16073          },
 16074          "pedigree": {},
 16075          "evidence": {},
 16076          "signature": {
 16077            "signature": {
 16078              "publicKey": {}
 16079            }
 16080          },
 16081          "modelCard": {
 16082            "modelParameters": {
 16083              "approach": {}
 16084            },
 16085            "quantitativeAnalysis": {
 16086              "graphics": {}
 16087            },
 16088            "considerations": {}
 16089          }
 16090        },
 16091        {
 16092          "type": "library",
 16093          "bom-ref": "pkg:golang/github.com/davecgh/go-spew@v1.1.1?package-id=3db79e08ec9be340",
 16094          "supplier": {},
 16095          "name": "github.com/davecgh/go-spew",
 16096          "version": "v1.1.1",
 16097          "cpe": "cpe:2.3:a:davecgh:go-spew:v1.1.1:*:*:*:*:*:*:*",
 16098          "purl": "pkg:golang/github.com/davecgh/go-spew@v1.1.1",
 16099          "swid": {
 16100            "attachment": {}
 16101          },
 16102          "pedigree": {},
 16103          "evidence": {},
 16104          "signature": {
 16105            "signature": {
 16106              "publicKey": {}
 16107            }
 16108          },
 16109          "modelCard": {
 16110            "modelParameters": {
 16111              "approach": {}
 16112            },
 16113            "quantitativeAnalysis": {
 16114              "graphics": {}
 16115            },
 16116            "considerations": {}
 16117          }
 16118        },
 16119        {
 16120          "type": "library",
 16121          "bom-ref": "pkg:golang/github.com/docker/distribution@v2.7.1+incompatible?package-id=1e5eafbca9b9b44c",
 16122          "supplier": {},
 16123          "name": "github.com/docker/distribution",
 16124          "version": "v2.7.1+incompatible",
 16125          "cpe": "cpe:2.3:a:docker:distribution:v2.7.1\\+incompatible:*:*:*:*:*:*:*",
 16126          "purl": "pkg:golang/github.com/docker/distribution@v2.7.1+incompatible",
 16127          "swid": {
 16128            "attachment": {}
 16129          },
 16130          "pedigree": {},
 16131          "evidence": {},
 16132          "signature": {
 16133            "signature": {
 16134              "publicKey": {}
 16135            }
 16136          },
 16137          "modelCard": {
 16138            "modelParameters": {
 16139              "approach": {}
 16140            },
 16141            "quantitativeAnalysis": {
 16142              "graphics": {}
 16143            },
 16144            "considerations": {}
 16145          }
 16146        },
 16147        {
 16148          "type": "library",
 16149          "bom-ref": "pkg:golang/github.com/glycerine/go-unsnap-stream@v0.0.0-20181221182339-f9677308dec2?package-id=53a7508276bd45c2",
 16150          "supplier": {},
 16151          "name": "github.com/glycerine/go-unsnap-stream",
 16152          "version": "v0.0.0-20181221182339-f9677308dec2",
 16153          "cpe": "cpe:2.3:a:glycerine:go-unsnap-stream:v0.0.0-20181221182339-f9677308dec2:*:*:*:*:*:*:*",
 16154          "purl": "pkg:golang/github.com/glycerine/go-unsnap-stream@v0.0.0-20181221182339-f9677308dec2",
 16155          "swid": {
 16156            "attachment": {}
 16157          },
 16158          "pedigree": {},
 16159          "evidence": {},
 16160          "signature": {
 16161            "signature": {
 16162              "publicKey": {}
 16163            }
 16164          },
 16165          "modelCard": {
 16166            "modelParameters": {
 16167              "approach": {}
 16168            },
 16169            "quantitativeAnalysis": {
 16170              "graphics": {}
 16171            },
 16172            "considerations": {}
 16173          }
 16174        },
 16175        {
 16176          "type": "library",
 16177          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.2?package-id=934cf5f83ca33cac",
 16178          "supplier": {},
 16179          "name": "github.com/gogo/protobuf",
 16180          "version": "v1.3.2",
 16181          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.2:*:*:*:*:*:*:*",
 16182          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.2",
 16183          "swid": {
 16184            "attachment": {}
 16185          },
 16186          "pedigree": {},
 16187          "evidence": {},
 16188          "signature": {
 16189            "signature": {
 16190              "publicKey": {}
 16191            }
 16192          },
 16193          "modelCard": {
 16194            "modelParameters": {
 16195              "approach": {}
 16196            },
 16197            "quantitativeAnalysis": {
 16198              "graphics": {}
 16199            },
 16200            "considerations": {}
 16201          }
 16202        },
 16203        {
 16204          "type": "library",
 16205          "bom-ref": "pkg:golang/github.com/golang/groupcache@v0.0.0-20191002201903-404acd9df4cc?package-id=7f2cd7756b0aaa55",
 16206          "supplier": {},
 16207          "name": "github.com/golang/groupcache",
 16208          "version": "v0.0.0-20191002201903-404acd9df4cc",
 16209          "cpe": "cpe:2.3:a:golang:groupcache:v0.0.0-20191002201903-404acd9df4cc:*:*:*:*:*:*:*",
 16210          "purl": "pkg:golang/github.com/golang/groupcache@v0.0.0-20191002201903-404acd9df4cc",
 16211          "swid": {
 16212            "attachment": {}
 16213          },
 16214          "pedigree": {},
 16215          "evidence": {},
 16216          "signature": {
 16217            "signature": {
 16218              "publicKey": {}
 16219            }
 16220          },
 16221          "modelCard": {
 16222            "modelParameters": {
 16223              "approach": {}
 16224            },
 16225            "quantitativeAnalysis": {
 16226              "graphics": {}
 16227            },
 16228            "considerations": {}
 16229          }
 16230        },
 16231        {
 16232          "type": "library",
 16233          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf?package-id=44af7d08ac6deef1",
 16234          "supplier": {},
 16235          "name": "github.com/golang/protobuf",
 16236          "version": "v1.3.3-0.20190920234318-1680a479a2cf",
 16237          "cpe": "cpe:2.3:a:golang:protobuf:v1.3.3-0.20190920234318-1680a479a2cf:*:*:*:*:*:*:*",
 16238          "purl": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf",
 16239          "swid": {
 16240            "attachment": {}
 16241          },
 16242          "pedigree": {},
 16243          "evidence": {},
 16244          "signature": {
 16245            "signature": {
 16246              "publicKey": {}
 16247            }
 16248          },
 16249          "modelCard": {
 16250            "modelParameters": {
 16251              "approach": {}
 16252            },
 16253            "quantitativeAnalysis": {
 16254              "graphics": {}
 16255            },
 16256            "considerations": {}
 16257          }
 16258        },
 16259        {
 16260          "type": "library",
 16261          "bom-ref": "pkg:golang/github.com/golang/snappy@v0.0.1?package-id=324ab41994e42af7",
 16262          "supplier": {},
 16263          "name": "github.com/golang/snappy",
 16264          "version": "v0.0.1",
 16265          "cpe": "cpe:2.3:a:golang:snappy:v0.0.1:*:*:*:*:*:*:*",
 16266          "purl": "pkg:golang/github.com/golang/snappy@v0.0.1",
 16267          "swid": {
 16268            "attachment": {}
 16269          },
 16270          "pedigree": {},
 16271          "evidence": {},
 16272          "signature": {
 16273            "signature": {
 16274              "publicKey": {}
 16275            }
 16276          },
 16277          "modelCard": {
 16278            "modelParameters": {
 16279              "approach": {}
 16280            },
 16281            "quantitativeAnalysis": {
 16282              "graphics": {}
 16283            },
 16284            "considerations": {}
 16285          }
 16286        },
 16287        {
 16288          "type": "library",
 16289          "bom-ref": "pkg:golang/github.com/google/go-cmp@v0.3.0?package-id=34d87a26cf0a41de",
 16290          "supplier": {},
 16291          "name": "github.com/google/go-cmp",
 16292          "version": "v0.3.0",
 16293          "cpe": "cpe:2.3:a:google:go-cmp:v0.3.0:*:*:*:*:*:*:*",
 16294          "purl": "pkg:golang/github.com/google/go-cmp@v0.3.0",
 16295          "swid": {
 16296            "attachment": {}
 16297          },
 16298          "pedigree": {},
 16299          "evidence": {},
 16300          "signature": {
 16301            "signature": {
 16302              "publicKey": {}
 16303            }
 16304          },
 16305          "modelCard": {
 16306            "modelParameters": {
 16307              "approach": {}
 16308            },
 16309            "quantitativeAnalysis": {
 16310              "graphics": {}
 16311            },
 16312            "considerations": {}
 16313          }
 16314        },
 16315        {
 16316          "type": "library",
 16317          "bom-ref": "pkg:golang/github.com/google/gofuzz@v1.1.0?package-id=1f72a36359414328",
 16318          "supplier": {},
 16319          "name": "github.com/google/gofuzz",
 16320          "version": "v1.1.0",
 16321          "cpe": "cpe:2.3:a:google:gofuzz:v1.1.0:*:*:*:*:*:*:*",
 16322          "purl": "pkg:golang/github.com/google/gofuzz@v1.1.0",
 16323          "swid": {
 16324            "attachment": {}
 16325          },
 16326          "pedigree": {},
 16327          "evidence": {},
 16328          "signature": {
 16329            "signature": {
 16330              "publicKey": {}
 16331            }
 16332          },
 16333          "modelCard": {
 16334            "modelParameters": {
 16335              "approach": {}
 16336            },
 16337            "quantitativeAnalysis": {
 16338              "graphics": {}
 16339            },
 16340            "considerations": {}
 16341          }
 16342        },
 16343        {
 16344          "type": "library",
 16345          "bom-ref": "pkg:golang/github.com/googleapis/gnostic@v0.3.1?package-id=ff98de637245c11c",
 16346          "supplier": {},
 16347          "name": "github.com/googleapis/gnostic",
 16348          "version": "v0.3.1",
 16349          "cpe": "cpe:2.3:a:googleapis:gnostic:v0.3.1:*:*:*:*:*:*:*",
 16350          "purl": "pkg:golang/github.com/googleapis/gnostic@v0.3.1",
 16351          "swid": {
 16352            "attachment": {}
 16353          },
 16354          "pedigree": {},
 16355          "evidence": {},
 16356          "signature": {
 16357            "signature": {
 16358              "publicKey": {}
 16359            }
 16360          },
 16361          "modelCard": {
 16362            "modelParameters": {
 16363              "approach": {}
 16364            },
 16365            "quantitativeAnalysis": {
 16366              "graphics": {}
 16367            },
 16368            "considerations": {}
 16369          }
 16370        },
 16371        {
 16372          "type": "library",
 16373          "bom-ref": "pkg:golang/github.com/gorilla/context@v1.1.1?package-id=325bae867d0f762a",
 16374          "supplier": {},
 16375          "name": "github.com/gorilla/context",
 16376          "version": "v1.1.1",
 16377          "cpe": "cpe:2.3:a:gorilla:context:v1.1.1:*:*:*:*:*:*:*",
 16378          "purl": "pkg:golang/github.com/gorilla/context@v1.1.1",
 16379          "swid": {
 16380            "attachment": {}
 16381          },
 16382          "pedigree": {},
 16383          "evidence": {},
 16384          "signature": {
 16385            "signature": {
 16386              "publicKey": {}
 16387            }
 16388          },
 16389          "modelCard": {
 16390            "modelParameters": {
 16391              "approach": {}
 16392            },
 16393            "quantitativeAnalysis": {
 16394              "graphics": {}
 16395            },
 16396            "considerations": {}
 16397          }
 16398        },
 16399        {
 16400          "type": "library",
 16401          "bom-ref": "pkg:golang/github.com/gorilla/handlers@v1.4.2?package-id=798fee4e9a14ffb5",
 16402          "supplier": {},
 16403          "name": "github.com/gorilla/handlers",
 16404          "version": "v1.4.2",
 16405          "cpe": "cpe:2.3:a:gorilla:handlers:v1.4.2:*:*:*:*:*:*:*",
 16406          "purl": "pkg:golang/github.com/gorilla/handlers@v1.4.2",
 16407          "swid": {
 16408            "attachment": {}
 16409          },
 16410          "pedigree": {},
 16411          "evidence": {},
 16412          "signature": {
 16413            "signature": {
 16414              "publicKey": {}
 16415            }
 16416          },
 16417          "modelCard": {
 16418            "modelParameters": {
 16419              "approach": {}
 16420            },
 16421            "quantitativeAnalysis": {
 16422              "graphics": {}
 16423            },
 16424            "considerations": {}
 16425          }
 16426        },
 16427        {
 16428          "type": "library",
 16429          "bom-ref": "pkg:golang/github.com/gorilla/mux@v1.7.3?package-id=1ae947ddc1edb3ab",
 16430          "supplier": {},
 16431          "name": "github.com/gorilla/mux",
 16432          "version": "v1.7.3",
 16433          "cpe": "cpe:2.3:a:gorilla:mux:v1.7.3:*:*:*:*:*:*:*",
 16434          "purl": "pkg:golang/github.com/gorilla/mux@v1.7.3",
 16435          "swid": {
 16436            "attachment": {}
 16437          },
 16438          "pedigree": {},
 16439          "evidence": {},
 16440          "signature": {
 16441            "signature": {
 16442              "publicKey": {}
 16443            }
 16444          },
 16445          "modelCard": {
 16446            "modelParameters": {
 16447              "approach": {}
 16448            },
 16449            "quantitativeAnalysis": {
 16450              "graphics": {}
 16451            },
 16452            "considerations": {}
 16453          }
 16454        },
 16455        {
 16456          "type": "library",
 16457          "bom-ref": "pkg:golang/github.com/gorilla/websocket@v1.4.2?package-id=7f1146c54bea2751",
 16458          "supplier": {},
 16459          "name": "github.com/gorilla/websocket",
 16460          "version": "v1.4.2",
 16461          "cpe": "cpe:2.3:a:gorilla:websocket:v1.4.2:*:*:*:*:*:*:*",
 16462          "purl": "pkg:golang/github.com/gorilla/websocket@v1.4.2",
 16463          "swid": {
 16464            "attachment": {}
 16465          },
 16466          "pedigree": {},
 16467          "evidence": {},
 16468          "signature": {
 16469            "signature": {
 16470              "publicKey": {}
 16471            }
 16472          },
 16473          "modelCard": {
 16474            "modelParameters": {
 16475              "approach": {}
 16476            },
 16477            "quantitativeAnalysis": {
 16478              "graphics": {}
 16479            },
 16480            "considerations": {}
 16481          }
 16482        },
 16483        {
 16484          "type": "library",
 16485          "bom-ref": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.3?package-id=ccffa42c4dbdd4ce",
 16486          "supplier": {},
 16487          "name": "github.com/hashicorp/golang-lru",
 16488          "version": "v0.5.3",
 16489          "cpe": "cpe:2.3:a:hashicorp:golang-lru:v0.5.3:*:*:*:*:*:*:*",
 16490          "purl": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.3",
 16491          "swid": {
 16492            "attachment": {}
 16493          },
 16494          "pedigree": {},
 16495          "evidence": {},
 16496          "signature": {
 16497            "signature": {
 16498              "publicKey": {}
 16499            }
 16500          },
 16501          "modelCard": {
 16502            "modelParameters": {
 16503              "approach": {}
 16504            },
 16505            "quantitativeAnalysis": {
 16506              "graphics": {}
 16507            },
 16508            "considerations": {}
 16509          }
 16510        },
 16511        {
 16512          "type": "library",
 16513          "bom-ref": "pkg:golang/github.com/honestbee/jobq@v1.0.2?package-id=ef29baa163ddbb5e",
 16514          "supplier": {},
 16515          "name": "github.com/honestbee/jobq",
 16516          "version": "v1.0.2",
 16517          "cpe": "cpe:2.3:a:honestbee:jobq:v1.0.2:*:*:*:*:*:*:*",
 16518          "purl": "pkg:golang/github.com/honestbee/jobq@v1.0.2",
 16519          "swid": {
 16520            "attachment": {}
 16521          },
 16522          "pedigree": {},
 16523          "evidence": {},
 16524          "signature": {
 16525            "signature": {
 16526              "publicKey": {}
 16527            }
 16528          },
 16529          "modelCard": {
 16530            "modelParameters": {
 16531              "approach": {}
 16532            },
 16533            "quantitativeAnalysis": {
 16534              "graphics": {}
 16535            },
 16536            "considerations": {}
 16537          }
 16538        },
 16539        {
 16540          "type": "library",
 16541          "bom-ref": "pkg:golang/github.com/imdario/mergo@v0.3.8?package-id=5b692dee7346216f",
 16542          "supplier": {},
 16543          "name": "github.com/imdario/mergo",
 16544          "version": "v0.3.8",
 16545          "cpe": "cpe:2.3:a:imdario:mergo:v0.3.8:*:*:*:*:*:*:*",
 16546          "purl": "pkg:golang/github.com/imdario/mergo@v0.3.8",
 16547          "swid": {
 16548            "attachment": {}
 16549          },
 16550          "pedigree": {},
 16551          "evidence": {},
 16552          "signature": {
 16553            "signature": {
 16554              "publicKey": {}
 16555            }
 16556          },
 16557          "modelCard": {
 16558            "modelParameters": {
 16559              "approach": {}
 16560            },
 16561            "quantitativeAnalysis": {
 16562              "graphics": {}
 16563            },
 16564            "considerations": {}
 16565          }
 16566        },
 16567        {
 16568          "type": "library",
 16569          "bom-ref": "pkg:golang/github.com/jinzhu/copier@v0.0.0-20190924061706-b57f9002281a?package-id=3c7777c5ddb3520e",
 16570          "supplier": {},
 16571          "name": "github.com/jinzhu/copier",
 16572          "version": "v0.0.0-20190924061706-b57f9002281a",
 16573          "cpe": "cpe:2.3:a:jinzhu:copier:v0.0.0-20190924061706-b57f9002281a:*:*:*:*:*:*:*",
 16574          "purl": "pkg:golang/github.com/jinzhu/copier@v0.0.0-20190924061706-b57f9002281a",
 16575          "swid": {
 16576            "attachment": {}
 16577          },
 16578          "pedigree": {},
 16579          "evidence": {},
 16580          "signature": {
 16581            "signature": {
 16582              "publicKey": {}
 16583            }
 16584          },
 16585          "modelCard": {
 16586            "modelParameters": {
 16587              "approach": {}
 16588            },
 16589            "quantitativeAnalysis": {
 16590              "graphics": {}
 16591            },
 16592            "considerations": {}
 16593          }
 16594        },
 16595        {
 16596          "type": "library",
 16597          "bom-ref": "pkg:golang/github.com/json-iterator/go@v1.1.8?package-id=2f8fc2954ce12864",
 16598          "supplier": {},
 16599          "name": "github.com/json-iterator/go",
 16600          "version": "v1.1.8",
 16601          "cpe": "cpe:2.3:a:json-iterator:go:v1.1.8:*:*:*:*:*:*:*",
 16602          "purl": "pkg:golang/github.com/json-iterator/go@v1.1.8",
 16603          "swid": {
 16604            "attachment": {}
 16605          },
 16606          "pedigree": {},
 16607          "evidence": {},
 16608          "signature": {
 16609            "signature": {
 16610              "publicKey": {}
 16611            }
 16612          },
 16613          "modelCard": {
 16614            "modelParameters": {
 16615              "approach": {}
 16616            },
 16617            "quantitativeAnalysis": {
 16618              "graphics": {}
 16619            },
 16620            "considerations": {}
 16621          }
 16622        },
 16623        {
 16624          "type": "library",
 16625          "bom-ref": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.6.1?package-id=a785ad59d51801be",
 16626          "supplier": {},
 16627          "name": "github.com/kubernetes-csi/csi-lib-utils",
 16628          "version": "v0.6.1",
 16629          "cpe": "cpe:2.3:a:kubernetes-csi:csi-lib-utils:v0.6.1:*:*:*:*:*:*:*",
 16630          "purl": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.6.1",
 16631          "swid": {
 16632            "attachment": {}
 16633          },
 16634          "pedigree": {},
 16635          "evidence": {},
 16636          "signature": {
 16637            "signature": {
 16638              "publicKey": {}
 16639            }
 16640          },
 16641          "modelCard": {
 16642            "modelParameters": {
 16643              "approach": {}
 16644            },
 16645            "quantitativeAnalysis": {
 16646              "graphics": {}
 16647            },
 16648            "considerations": {}
 16649          }
 16650        },
 16651        {
 16652          "type": "library",
 16653          "bom-ref": "pkg:golang/github.com/longhorn/backing-image-manager@v0.0.0-20210809125601-48e29abcd637?package-id=525e43f22729f606",
 16654          "supplier": {},
 16655          "name": "github.com/longhorn/backing-image-manager",
 16656          "version": "v0.0.0-20210809125601-48e29abcd637",
 16657          "cpe": "cpe:2.3:a:longhorn:backing-image-manager:v0.0.0-20210809125601-48e29abcd637:*:*:*:*:*:*:*",
 16658          "purl": "pkg:golang/github.com/longhorn/backing-image-manager@v0.0.0-20210809125601-48e29abcd637",
 16659          "swid": {
 16660            "attachment": {}
 16661          },
 16662          "pedigree": {},
 16663          "evidence": {},
 16664          "signature": {
 16665            "signature": {
 16666              "publicKey": {}
 16667            }
 16668          },
 16669          "modelCard": {
 16670            "modelParameters": {
 16671              "approach": {}
 16672            },
 16673            "quantitativeAnalysis": {
 16674              "graphics": {}
 16675            },
 16676            "considerations": {}
 16677          }
 16678        },
 16679        {
 16680          "type": "library",
 16681          "bom-ref": "pkg:golang/github.com/longhorn/backupstore@v0.0.0-20210817080617-8ea3843e6b0d?package-id=7e8c2773e8ca8260",
 16682          "supplier": {},
 16683          "name": "github.com/longhorn/backupstore",
 16684          "version": "v0.0.0-20210817080617-8ea3843e6b0d",
 16685          "cpe": "cpe:2.3:a:longhorn:backupstore:v0.0.0-20210817080617-8ea3843e6b0d:*:*:*:*:*:*:*",
 16686          "purl": "pkg:golang/github.com/longhorn/backupstore@v0.0.0-20210817080617-8ea3843e6b0d",
 16687          "swid": {
 16688            "attachment": {}
 16689          },
 16690          "pedigree": {},
 16691          "evidence": {},
 16692          "signature": {
 16693            "signature": {
 16694              "publicKey": {}
 16695            }
 16696          },
 16697          "modelCard": {
 16698            "modelParameters": {
 16699              "approach": {}
 16700            },
 16701            "quantitativeAnalysis": {
 16702              "graphics": {}
 16703            },
 16704            "considerations": {}
 16705          }
 16706        },
 16707        {
 16708          "type": "library",
 16709          "bom-ref": "pkg:golang/github.com/longhorn/go-iscsi-helper@v0.0.0-20201111045018-ee87992ec536?package-id=bd17f74dcd826f71",
 16710          "supplier": {},
 16711          "name": "github.com/longhorn/go-iscsi-helper",
 16712          "version": "v0.0.0-20201111045018-ee87992ec536",
 16713          "cpe": "cpe:2.3:a:longhorn:go-iscsi-helper:v0.0.0-20201111045018-ee87992ec536:*:*:*:*:*:*:*",
 16714          "purl": "pkg:golang/github.com/longhorn/go-iscsi-helper@v0.0.0-20201111045018-ee87992ec536",
 16715          "swid": {
 16716            "attachment": {}
 16717          },
 16718          "pedigree": {},
 16719          "evidence": {},
 16720          "signature": {
 16721            "signature": {
 16722              "publicKey": {}
 16723            }
 16724          },
 16725          "modelCard": {
 16726            "modelParameters": {
 16727              "approach": {}
 16728            },
 16729            "quantitativeAnalysis": {
 16730              "graphics": {}
 16731            },
 16732            "considerations": {}
 16733          }
 16734        },
 16735        {
 16736          "type": "library",
 16737          "bom-ref": "pkg:golang/github.com/longhorn/longhorn-instance-manager@v0.0.0-20210729081215-50c310f97378?package-id=b87bb53661cac7c3",
 16738          "supplier": {},
 16739          "name": "github.com/longhorn/longhorn-instance-manager",
 16740          "version": "v0.0.0-20210729081215-50c310f97378",
 16741          "cpe": "cpe:2.3:a:longhorn:longhorn-instance-manager:v0.0.0-20210729081215-50c310f97378:*:*:*:*:*:*:*",
 16742          "purl": "pkg:golang/github.com/longhorn/longhorn-instance-manager@v0.0.0-20210729081215-50c310f97378",
 16743          "swid": {
 16744            "attachment": {}
 16745          },
 16746          "pedigree": {},
 16747          "evidence": {},
 16748          "signature": {
 16749            "signature": {
 16750              "publicKey": {}
 16751            }
 16752          },
 16753          "modelCard": {
 16754            "modelParameters": {
 16755              "approach": {}
 16756            },
 16757            "quantitativeAnalysis": {
 16758              "graphics": {}
 16759            },
 16760            "considerations": {}
 16761          }
 16762        },
 16763        {
 16764          "type": "library",
 16765          "bom-ref": "pkg:golang/github.com/longhorn/longhorn-manager@(devel)?package-id=685b701df9ee4ba2",
 16766          "supplier": {},
 16767          "name": "github.com/longhorn/longhorn-manager",
 16768          "version": "(devel)",
 16769          "cpe": "cpe:2.3:a:longhorn:longhorn-manager:\\(devel\\):*:*:*:*:*:*:*",
 16770          "purl": "pkg:golang/github.com/longhorn/longhorn-manager@(devel)",
 16771          "swid": {
 16772            "attachment": {}
 16773          },
 16774          "pedigree": {},
 16775          "evidence": {},
 16776          "signature": {
 16777            "signature": {
 16778              "publicKey": {}
 16779            }
 16780          },
 16781          "modelCard": {
 16782            "modelParameters": {
 16783              "approach": {}
 16784            },
 16785            "quantitativeAnalysis": {
 16786              "graphics": {}
 16787            },
 16788            "considerations": {}
 16789          }
 16790        },
 16791        {
 16792          "type": "library",
 16793          "bom-ref": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.1?package-id=baa43fe250a569f4",
 16794          "supplier": {},
 16795          "name": "github.com/matttproud/golang_protobuf_extensions",
 16796          "version": "v1.0.1",
 16797          "cpe": "cpe:2.3:a:matttproud:golang-protobuf-extensions:v1.0.1:*:*:*:*:*:*:*",
 16798          "purl": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.1",
 16799          "swid": {
 16800            "attachment": {}
 16801          },
 16802          "pedigree": {},
 16803          "evidence": {},
 16804          "signature": {
 16805            "signature": {
 16806              "publicKey": {}
 16807            }
 16808          },
 16809          "modelCard": {
 16810            "modelParameters": {
 16811              "approach": {}
 16812            },
 16813            "quantitativeAnalysis": {
 16814              "graphics": {}
 16815            },
 16816            "considerations": {}
 16817          }
 16818        },
 16819        {
 16820          "type": "library",
 16821          "bom-ref": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd?package-id=d0af01f76410eec4",
 16822          "supplier": {},
 16823          "name": "github.com/modern-go/concurrent",
 16824          "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
 16825          "cpe": "cpe:2.3:a:modern-go:concurrent:v0.0.0-20180306012644-bacd9c7ef1dd:*:*:*:*:*:*:*",
 16826          "purl": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd",
 16827          "swid": {
 16828            "attachment": {}
 16829          },
 16830          "pedigree": {},
 16831          "evidence": {},
 16832          "signature": {
 16833            "signature": {
 16834              "publicKey": {}
 16835            }
 16836          },
 16837          "modelCard": {
 16838            "modelParameters": {
 16839              "approach": {}
 16840            },
 16841            "quantitativeAnalysis": {
 16842              "graphics": {}
 16843            },
 16844            "considerations": {}
 16845          }
 16846        },
 16847        {
 16848          "type": "library",
 16849          "bom-ref": "pkg:golang/github.com/modern-go/reflect2@v1.0.1?package-id=120b5391539ce8dc",
 16850          "supplier": {},
 16851          "name": "github.com/modern-go/reflect2",
 16852          "version": "v1.0.1",
 16853          "cpe": "cpe:2.3:a:modern-go:reflect2:v1.0.1:*:*:*:*:*:*:*",
 16854          "purl": "pkg:golang/github.com/modern-go/reflect2@v1.0.1",
 16855          "swid": {
 16856            "attachment": {}
 16857          },
 16858          "pedigree": {},
 16859          "evidence": {},
 16860          "signature": {
 16861            "signature": {
 16862              "publicKey": {}
 16863            }
 16864          },
 16865          "modelCard": {
 16866            "modelParameters": {
 16867              "approach": {}
 16868            },
 16869            "quantitativeAnalysis": {
 16870              "graphics": {}
 16871            },
 16872            "considerations": {}
 16873          }
 16874        },
 16875        {
 16876          "type": "library",
 16877          "bom-ref": "pkg:golang/github.com/opencontainers/go-digest@v1.0.0-rc1?package-id=de8720f51866f3e5",
 16878          "supplier": {},
 16879          "name": "github.com/opencontainers/go-digest",
 16880          "version": "v1.0.0-rc1",
 16881          "cpe": "cpe:2.3:a:opencontainers:go-digest:v1.0.0-rc1:*:*:*:*:*:*:*",
 16882          "purl": "pkg:golang/github.com/opencontainers/go-digest@v1.0.0-rc1",
 16883          "swid": {
 16884            "attachment": {}
 16885          },
 16886          "pedigree": {},
 16887          "evidence": {},
 16888          "signature": {
 16889            "signature": {
 16890              "publicKey": {}
 16891            }
 16892          },
 16893          "modelCard": {
 16894            "modelParameters": {
 16895              "approach": {}
 16896            },
 16897            "quantitativeAnalysis": {
 16898              "graphics": {}
 16899            },
 16900            "considerations": {}
 16901          }
 16902        },
 16903        {
 16904          "type": "library",
 16905          "bom-ref": "pkg:golang/github.com/philhofer/fwd@v1.0.0?package-id=5704d478ebe07f9b",
 16906          "supplier": {},
 16907          "name": "github.com/philhofer/fwd",
 16908          "version": "v1.0.0",
 16909          "cpe": "cpe:2.3:a:philhofer:fwd:v1.0.0:*:*:*:*:*:*:*",
 16910          "purl": "pkg:golang/github.com/philhofer/fwd@v1.0.0",
 16911          "swid": {
 16912            "attachment": {}
 16913          },
 16914          "pedigree": {},
 16915          "evidence": {},
 16916          "signature": {
 16917            "signature": {
 16918              "publicKey": {}
 16919            }
 16920          },
 16921          "modelCard": {
 16922            "modelParameters": {
 16923              "approach": {}
 16924            },
 16925            "quantitativeAnalysis": {
 16926              "graphics": {}
 16927            },
 16928            "considerations": {}
 16929          }
 16930        },
 16931        {
 16932          "type": "library",
 16933          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.9.1?package-id=8e8eaa5cdac0593c",
 16934          "supplier": {},
 16935          "name": "github.com/pkg/errors",
 16936          "version": "v0.9.1",
 16937          "cpe": "cpe:2.3:a:pkg:errors:v0.9.1:*:*:*:*:*:*:*",
 16938          "purl": "pkg:golang/github.com/pkg/errors@v0.9.1",
 16939          "swid": {
 16940            "attachment": {}
 16941          },
 16942          "pedigree": {},
 16943          "evidence": {},
 16944          "signature": {
 16945            "signature": {
 16946              "publicKey": {}
 16947            }
 16948          },
 16949          "modelCard": {
 16950            "modelParameters": {
 16951              "approach": {}
 16952            },
 16953            "quantitativeAnalysis": {
 16954              "graphics": {}
 16955            },
 16956            "considerations": {}
 16957          }
 16958        },
 16959        {
 16960          "type": "library",
 16961          "bom-ref": "pkg:golang/github.com/prometheus/client_golang@v1.2.1?package-id=d5c8d56e8fe1d61c",
 16962          "supplier": {},
 16963          "name": "github.com/prometheus/client_golang",
 16964          "version": "v1.2.1",
 16965          "cpe": "cpe:2.3:a:prometheus:client-golang:v1.2.1:*:*:*:*:*:*:*",
 16966          "purl": "pkg:golang/github.com/prometheus/client_golang@v1.2.1",
 16967          "swid": {
 16968            "attachment": {}
 16969          },
 16970          "pedigree": {},
 16971          "evidence": {},
 16972          "signature": {
 16973            "signature": {
 16974              "publicKey": {}
 16975            }
 16976          },
 16977          "modelCard": {
 16978            "modelParameters": {
 16979              "approach": {}
 16980            },
 16981            "quantitativeAnalysis": {
 16982              "graphics": {}
 16983            },
 16984            "considerations": {}
 16985          }
 16986        },
 16987        {
 16988          "type": "library",
 16989          "bom-ref": "pkg:golang/github.com/prometheus/client_model@v0.2.0?package-id=6e586fe5dc5bb9fa",
 16990          "supplier": {},
 16991          "name": "github.com/prometheus/client_model",
 16992          "version": "v0.2.0",
 16993          "cpe": "cpe:2.3:a:prometheus:client-model:v0.2.0:*:*:*:*:*:*:*",
 16994          "purl": "pkg:golang/github.com/prometheus/client_model@v0.2.0",
 16995          "swid": {
 16996            "attachment": {}
 16997          },
 16998          "pedigree": {},
 16999          "evidence": {},
 17000          "signature": {
 17001            "signature": {
 17002              "publicKey": {}
 17003            }
 17004          },
 17005          "modelCard": {
 17006            "modelParameters": {
 17007              "approach": {}
 17008            },
 17009            "quantitativeAnalysis": {
 17010              "graphics": {}
 17011            },
 17012            "considerations": {}
 17013          }
 17014        },
 17015        {
 17016          "type": "library",
 17017          "bom-ref": "pkg:golang/github.com/prometheus/common@v0.7.0?package-id=59f97a48a9317019",
 17018          "supplier": {},
 17019          "name": "github.com/prometheus/common",
 17020          "version": "v0.7.0",
 17021          "cpe": "cpe:2.3:a:prometheus:common:v0.7.0:*:*:*:*:*:*:*",
 17022          "purl": "pkg:golang/github.com/prometheus/common@v0.7.0",
 17023          "swid": {
 17024            "attachment": {}
 17025          },
 17026          "pedigree": {},
 17027          "evidence": {},
 17028          "signature": {
 17029            "signature": {
 17030              "publicKey": {}
 17031            }
 17032          },
 17033          "modelCard": {
 17034            "modelParameters": {
 17035              "approach": {}
 17036            },
 17037            "quantitativeAnalysis": {
 17038              "graphics": {}
 17039            },
 17040            "considerations": {}
 17041          }
 17042        },
 17043        {
 17044          "type": "library",
 17045          "bom-ref": "pkg:golang/github.com/prometheus/procfs@v0.0.5?package-id=dcac005325f87b93",
 17046          "supplier": {},
 17047          "name": "github.com/prometheus/procfs",
 17048          "version": "v0.0.5",
 17049          "cpe": "cpe:2.3:a:prometheus:procfs:v0.0.5:*:*:*:*:*:*:*",
 17050          "purl": "pkg:golang/github.com/prometheus/procfs@v0.0.5",
 17051          "swid": {
 17052            "attachment": {}
 17053          },
 17054          "pedigree": {},
 17055          "evidence": {},
 17056          "signature": {
 17057            "signature": {
 17058              "publicKey": {}
 17059            }
 17060          },
 17061          "modelCard": {
 17062            "modelParameters": {
 17063              "approach": {}
 17064            },
 17065            "quantitativeAnalysis": {
 17066              "graphics": {}
 17067            },
 17068            "considerations": {}
 17069          }
 17070        },
 17071        {
 17072          "type": "library",
 17073          "bom-ref": "pkg:golang/github.com/rancher/go-rancher@v0.1.1-0.20190307222549-9756097e5e4c?package-id=1800d99a24efcb3f",
 17074          "supplier": {},
 17075          "name": "github.com/rancher/go-rancher",
 17076          "version": "v0.1.1-0.20190307222549-9756097e5e4c",
 17077          "cpe": "cpe:2.3:a:rancher:go-rancher:v0.1.1-0.20190307222549-9756097e5e4c:*:*:*:*:*:*:*",
 17078          "purl": "pkg:golang/github.com/rancher/go-rancher@v0.1.1-0.20190307222549-9756097e5e4c",
 17079          "swid": {
 17080            "attachment": {}
 17081          },
 17082          "pedigree": {},
 17083          "evidence": {},
 17084          "signature": {
 17085            "signature": {
 17086              "publicKey": {}
 17087            }
 17088          },
 17089          "modelCard": {
 17090            "modelParameters": {
 17091              "approach": {}
 17092            },
 17093            "quantitativeAnalysis": {
 17094              "graphics": {}
 17095            },
 17096            "considerations": {}
 17097          }
 17098        },
 17099        {
 17100          "type": "library",
 17101          "bom-ref": "pkg:golang/github.com/robfig/cron@v1.2.0?package-id=33721f3e8cc20a28",
 17102          "supplier": {},
 17103          "name": "github.com/robfig/cron",
 17104          "version": "v1.2.0",
 17105          "cpe": "cpe:2.3:a:robfig:cron:v1.2.0:*:*:*:*:*:*:*",
 17106          "purl": "pkg:golang/github.com/robfig/cron@v1.2.0",
 17107          "swid": {
 17108            "attachment": {}
 17109          },
 17110          "pedigree": {},
 17111          "evidence": {},
 17112          "signature": {
 17113            "signature": {
 17114              "publicKey": {}
 17115            }
 17116          },
 17117          "modelCard": {
 17118            "modelParameters": {
 17119              "approach": {}
 17120            },
 17121            "quantitativeAnalysis": {
 17122              "graphics": {}
 17123            },
 17124            "considerations": {}
 17125          }
 17126        },
 17127        {
 17128          "type": "library",
 17129          "bom-ref": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1?package-id=d6d74f166ab19eb6",
 17130          "supplier": {},
 17131          "name": "github.com/russross/blackfriday/v2",
 17132          "version": "v2.0.1",
 17133          "cpe": "cpe:2.3:a:russross:blackfriday\\/v2:v2.0.1:*:*:*:*:*:*:*",
 17134          "purl": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1",
 17135          "swid": {
 17136            "attachment": {}
 17137          },
 17138          "pedigree": {},
 17139          "evidence": {},
 17140          "signature": {
 17141            "signature": {
 17142              "publicKey": {}
 17143            }
 17144          },
 17145          "modelCard": {
 17146            "modelParameters": {
 17147              "approach": {}
 17148            },
 17149            "quantitativeAnalysis": {
 17150              "graphics": {}
 17151            },
 17152            "considerations": {}
 17153          }
 17154        },
 17155        {
 17156          "type": "library",
 17157          "bom-ref": "pkg:golang/github.com/satori/go.uuid@v1.2.0?package-id=2d4637bafb0b29d2",
 17158          "supplier": {},
 17159          "name": "github.com/satori/go.uuid",
 17160          "version": "v1.2.0",
 17161          "cpe": "cpe:2.3:a:satori:go.uuid:v1.2.0:*:*:*:*:*:*:*",
 17162          "purl": "pkg:golang/github.com/satori/go.uuid@v1.2.0",
 17163          "swid": {
 17164            "attachment": {}
 17165          },
 17166          "pedigree": {},
 17167          "evidence": {},
 17168          "signature": {
 17169            "signature": {
 17170              "publicKey": {}
 17171            }
 17172          },
 17173          "modelCard": {
 17174            "modelParameters": {
 17175              "approach": {}
 17176            },
 17177            "quantitativeAnalysis": {
 17178              "graphics": {}
 17179            },
 17180            "considerations": {}
 17181          }
 17182        },
 17183        {
 17184          "type": "library",
 17185          "bom-ref": "pkg:golang/github.com/shurcool/sanitized_anchor_name@v1.0.0?package-id=4fef9700f2af07a1",
 17186          "supplier": {},
 17187          "name": "github.com/shurcooL/sanitized_anchor_name",
 17188          "version": "v1.0.0",
 17189          "cpe": "cpe:2.3:a:shurcooL:sanitized-anchor-name:v1.0.0:*:*:*:*:*:*:*",
 17190          "purl": "pkg:golang/github.com/shurcooL/sanitized_anchor_name@v1.0.0",
 17191          "swid": {
 17192            "attachment": {}
 17193          },
 17194          "pedigree": {},
 17195          "evidence": {},
 17196          "signature": {
 17197            "signature": {
 17198              "publicKey": {}
 17199            }
 17200          },
 17201          "modelCard": {
 17202            "modelParameters": {
 17203              "approach": {}
 17204            },
 17205            "quantitativeAnalysis": {
 17206              "graphics": {}
 17207            },
 17208            "considerations": {}
 17209          }
 17210        },
 17211        {
 17212          "type": "library",
 17213          "bom-ref": "pkg:golang/github.com/sirupsen/logrus@v1.4.2?package-id=466e11bf745ece84",
 17214          "supplier": {},
 17215          "name": "github.com/sirupsen/logrus",
 17216          "version": "v1.4.2",
 17217          "cpe": "cpe:2.3:a:sirupsen:logrus:v1.4.2:*:*:*:*:*:*:*",
 17218          "purl": "pkg:golang/github.com/sirupsen/logrus@v1.4.2",
 17219          "swid": {
 17220            "attachment": {}
 17221          },
 17222          "pedigree": {},
 17223          "evidence": {},
 17224          "signature": {
 17225            "signature": {
 17226              "publicKey": {}
 17227            }
 17228          },
 17229          "modelCard": {
 17230            "modelParameters": {
 17231              "approach": {}
 17232            },
 17233            "quantitativeAnalysis": {
 17234              "graphics": {}
 17235            },
 17236            "considerations": {}
 17237          }
 17238        },
 17239        {
 17240          "type": "library",
 17241          "bom-ref": "pkg:golang/github.com/spf13/pflag@v1.0.5?package-id=dbc8ff376b8ba02f",
 17242          "supplier": {},
 17243          "name": "github.com/spf13/pflag",
 17244          "version": "v1.0.5",
 17245          "cpe": "cpe:2.3:a:spf13:pflag:v1.0.5:*:*:*:*:*:*:*",
 17246          "purl": "pkg:golang/github.com/spf13/pflag@v1.0.5",
 17247          "swid": {
 17248            "attachment": {}
 17249          },
 17250          "pedigree": {},
 17251          "evidence": {},
 17252          "signature": {
 17253            "signature": {
 17254              "publicKey": {}
 17255            }
 17256          },
 17257          "modelCard": {
 17258            "modelParameters": {
 17259              "approach": {}
 17260            },
 17261            "quantitativeAnalysis": {
 17262              "graphics": {}
 17263            },
 17264            "considerations": {}
 17265          }
 17266        },
 17267        {
 17268          "type": "library",
 17269          "bom-ref": "pkg:golang/github.com/tinylib/msgp@v1.1.1-0.20190612170807-0573788bc2a8?package-id=e8d752ccadf8b15e",
 17270          "supplier": {},
 17271          "name": "github.com/tinylib/msgp",
 17272          "version": "v1.1.1-0.20190612170807-0573788bc2a8",
 17273          "cpe": "cpe:2.3:a:tinylib:msgp:v1.1.1-0.20190612170807-0573788bc2a8:*:*:*:*:*:*:*",
 17274          "purl": "pkg:golang/github.com/tinylib/msgp@v1.1.1-0.20190612170807-0573788bc2a8",
 17275          "swid": {
 17276            "attachment": {}
 17277          },
 17278          "pedigree": {},
 17279          "evidence": {},
 17280          "signature": {
 17281            "signature": {
 17282              "publicKey": {}
 17283            }
 17284          },
 17285          "modelCard": {
 17286            "modelParameters": {
 17287              "approach": {}
 17288            },
 17289            "quantitativeAnalysis": {
 17290              "graphics": {}
 17291            },
 17292            "considerations": {}
 17293          }
 17294        },
 17295        {
 17296          "type": "library",
 17297          "bom-ref": "pkg:golang/github.com/urfave/cli@v1.22.1?package-id=c10fc4d8849a889",
 17298          "supplier": {},
 17299          "name": "github.com/urfave/cli",
 17300          "version": "v1.22.1",
 17301          "cpe": "cpe:2.3:a:urfave:cli:v1.22.1:*:*:*:*:*:*:*",
 17302          "purl": "pkg:golang/github.com/urfave/cli@v1.22.1",
 17303          "swid": {
 17304            "attachment": {}
 17305          },
 17306          "pedigree": {},
 17307          "evidence": {},
 17308          "signature": {
 17309            "signature": {
 17310              "publicKey": {}
 17311            }
 17312          },
 17313          "modelCard": {
 17314            "modelParameters": {
 17315              "approach": {}
 17316            },
 17317            "quantitativeAnalysis": {
 17318              "graphics": {}
 17319            },
 17320            "considerations": {}
 17321          }
 17322        },
 17323        {
 17324          "type": "library",
 17325          "bom-ref": "pkg:golang/golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9?package-id=6fc14e333bfcd43c",
 17326          "supplier": {},
 17327          "name": "golang.org/x/crypto",
 17328          "version": "v0.0.0-20200622213623-75b288015ac9",
 17329          "cpe": "cpe:2.3:a:golang:x\\/crypto:v0.0.0-20200622213623-75b288015ac9:*:*:*:*:*:*:*",
 17330          "purl": "pkg:golang/golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9",
 17331          "swid": {
 17332            "attachment": {}
 17333          },
 17334          "pedigree": {},
 17335          "evidence": {},
 17336          "signature": {
 17337            "signature": {
 17338              "publicKey": {}
 17339            }
 17340          },
 17341          "modelCard": {
 17342            "modelParameters": {
 17343              "approach": {}
 17344            },
 17345            "quantitativeAnalysis": {
 17346              "graphics": {}
 17347            },
 17348            "considerations": {}
 17349          }
 17350        },
 17351        {
 17352          "type": "library",
 17353          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b?package-id=446ccb24ce95fa50",
 17354          "supplier": {},
 17355          "name": "golang.org/x/net",
 17356          "version": "v0.0.0-20201110031124-69a78807bb2b",
 17357          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20201110031124-69a78807bb2b:*:*:*:*:*:*:*",
 17358          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b",
 17359          "swid": {
 17360            "attachment": {}
 17361          },
 17362          "pedigree": {},
 17363          "evidence": {},
 17364          "signature": {
 17365            "signature": {
 17366              "publicKey": {}
 17367            }
 17368          },
 17369          "modelCard": {
 17370            "modelParameters": {
 17371              "approach": {}
 17372            },
 17373            "quantitativeAnalysis": {
 17374              "graphics": {}
 17375            },
 17376            "considerations": {}
 17377          }
 17378        },
 17379        {
 17380          "type": "library",
 17381          "bom-ref": "pkg:golang/golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45?package-id=8e98cbaad6157e39",
 17382          "supplier": {},
 17383          "name": "golang.org/x/oauth2",
 17384          "version": "v0.0.0-20190604053449-0f29369cfe45",
 17385          "cpe": "cpe:2.3:a:golang:x\\/oauth2:v0.0.0-20190604053449-0f29369cfe45:*:*:*:*:*:*:*",
 17386          "purl": "pkg:golang/golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45",
 17387          "swid": {
 17388            "attachment": {}
 17389          },
 17390          "pedigree": {},
 17391          "evidence": {},
 17392          "signature": {
 17393            "signature": {
 17394              "publicKey": {}
 17395            }
 17396          },
 17397          "modelCard": {
 17398            "modelParameters": {
 17399              "approach": {}
 17400            },
 17401            "quantitativeAnalysis": {
 17402              "graphics": {}
 17403            },
 17404            "considerations": {}
 17405          }
 17406        },
 17407        {
 17408          "type": "library",
 17409          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd?package-id=16c116d250ba5edd",
 17410          "supplier": {},
 17411          "name": "golang.org/x/sys",
 17412          "version": "v0.0.0-20201112073958-5cba982894dd",
 17413          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20201112073958-5cba982894dd:*:*:*:*:*:*:*",
 17414          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20201112073958-5cba982894dd",
 17415          "swid": {
 17416            "attachment": {}
 17417          },
 17418          "pedigree": {},
 17419          "evidence": {},
 17420          "signature": {
 17421            "signature": {
 17422              "publicKey": {}
 17423            }
 17424          },
 17425          "modelCard": {
 17426            "modelParameters": {
 17427              "approach": {}
 17428            },
 17429            "quantitativeAnalysis": {
 17430              "graphics": {}
 17431            },
 17432            "considerations": {}
 17433          }
 17434        },
 17435        {
 17436          "type": "library",
 17437          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.3?package-id=a5f3e8ea2e87c78",
 17438          "supplier": {},
 17439          "name": "golang.org/x/text",
 17440          "version": "v0.3.3",
 17441          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.3:*:*:*:*:*:*:*",
 17442          "purl": "pkg:golang/golang.org/x/text@v0.3.3",
 17443          "swid": {
 17444            "attachment": {}
 17445          },
 17446          "pedigree": {},
 17447          "evidence": {},
 17448          "signature": {
 17449            "signature": {
 17450              "publicKey": {}
 17451            }
 17452          },
 17453          "modelCard": {
 17454            "modelParameters": {
 17455              "approach": {}
 17456            },
 17457            "quantitativeAnalysis": {
 17458              "graphics": {}
 17459            },
 17460            "considerations": {}
 17461          }
 17462        },
 17463        {
 17464          "type": "library",
 17465          "bom-ref": "pkg:golang/golang.org/x/time@v0.0.0-20190921001708-c4c64cad1fd0?package-id=1674d56fc882a7b8",
 17466          "supplier": {},
 17467          "name": "golang.org/x/time",
 17468          "version": "v0.0.0-20190921001708-c4c64cad1fd0",
 17469          "cpe": "cpe:2.3:a:golang:x\\/time:v0.0.0-20190921001708-c4c64cad1fd0:*:*:*:*:*:*:*",
 17470          "purl": "pkg:golang/golang.org/x/time@v0.0.0-20190921001708-c4c64cad1fd0",
 17471          "swid": {
 17472            "attachment": {}
 17473          },
 17474          "pedigree": {},
 17475          "evidence": {},
 17476          "signature": {
 17477            "signature": {
 17478              "publicKey": {}
 17479            }
 17480          },
 17481          "modelCard": {
 17482            "modelParameters": {
 17483              "approach": {}
 17484            },
 17485            "quantitativeAnalysis": {
 17486              "graphics": {}
 17487            },
 17488            "considerations": {}
 17489          }
 17490        },
 17491        {
 17492          "type": "library",
 17493          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20190819201941-24fa4b261c55?package-id=943b37230736746f",
 17494          "supplier": {},
 17495          "name": "google.golang.org/genproto",
 17496          "version": "v0.0.0-20190819201941-24fa4b261c55",
 17497          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20190819201941-24fa4b261c55:*:*:*:*:*:*:*",
 17498          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20190819201941-24fa4b261c55",
 17499          "swid": {
 17500            "attachment": {}
 17501          },
 17502          "pedigree": {},
 17503          "evidence": {},
 17504          "signature": {
 17505            "signature": {
 17506              "publicKey": {}
 17507            }
 17508          },
 17509          "modelCard": {
 17510            "modelParameters": {
 17511              "approach": {}
 17512            },
 17513            "quantitativeAnalysis": {
 17514              "graphics": {}
 17515            },
 17516            "considerations": {}
 17517          }
 17518        },
 17519        {
 17520          "type": "library",
 17521          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.26.0?package-id=1c02cb0d493367c6",
 17522          "supplier": {},
 17523          "name": "google.golang.org/grpc",
 17524          "version": "v1.26.0",
 17525          "cpe": "cpe:2.3:a:google:grpc:v1.26.0:*:*:*:*:*:*:*",
 17526          "purl": "pkg:golang/google.golang.org/grpc@v1.26.0",
 17527          "swid": {
 17528            "attachment": {}
 17529          },
 17530          "pedigree": {},
 17531          "evidence": {},
 17532          "signature": {
 17533            "signature": {
 17534              "publicKey": {}
 17535            }
 17536          },
 17537          "modelCard": {
 17538            "modelParameters": {
 17539              "approach": {}
 17540            },
 17541            "quantitativeAnalysis": {
 17542              "graphics": {}
 17543            },
 17544            "considerations": {}
 17545          }
 17546        },
 17547        {
 17548          "type": "library",
 17549          "bom-ref": "pkg:golang/gopkg.in/inf.v0@v0.9.1?package-id=160b9c2f3c189b2b",
 17550          "supplier": {},
 17551          "name": "gopkg.in/inf.v0",
 17552          "version": "v0.9.1",
 17553          "purl": "pkg:golang/gopkg.in/inf.v0@v0.9.1",
 17554          "swid": {
 17555            "attachment": {}
 17556          },
 17557          "pedigree": {},
 17558          "evidence": {},
 17559          "signature": {
 17560            "signature": {
 17561              "publicKey": {}
 17562            }
 17563          },
 17564          "modelCard": {
 17565            "modelParameters": {
 17566              "approach": {}
 17567            },
 17568            "quantitativeAnalysis": {
 17569              "graphics": {}
 17570            },
 17571            "considerations": {}
 17572          }
 17573        },
 17574        {
 17575          "type": "library",
 17576          "bom-ref": "pkg:golang/gopkg.in/square/go-jose.v2@v2.3.1?package-id=22fdcdb79be95993",
 17577          "supplier": {},
 17578          "name": "gopkg.in/square/go-jose.v2",
 17579          "version": "v2.3.1",
 17580          "purl": "pkg:golang/gopkg.in/square/go-jose.v2@v2.3.1",
 17581          "swid": {
 17582            "attachment": {}
 17583          },
 17584          "pedigree": {},
 17585          "evidence": {},
 17586          "signature": {
 17587            "signature": {
 17588              "publicKey": {}
 17589            }
 17590          },
 17591          "modelCard": {
 17592            "modelParameters": {
 17593              "approach": {}
 17594            },
 17595            "quantitativeAnalysis": {
 17596              "graphics": {}
 17597            },
 17598            "considerations": {}
 17599          }
 17600        },
 17601        {
 17602          "type": "library",
 17603          "bom-ref": "pkg:golang/gopkg.in/yaml.v2@v2.2.8?package-id=8483c8d301d16462",
 17604          "supplier": {},
 17605          "name": "gopkg.in/yaml.v2",
 17606          "version": "v2.2.8",
 17607          "purl": "pkg:golang/gopkg.in/yaml.v2@v2.2.8",
 17608          "swid": {
 17609            "attachment": {}
 17610          },
 17611          "pedigree": {},
 17612          "evidence": {},
 17613          "signature": {
 17614            "signature": {
 17615              "publicKey": {}
 17616            }
 17617          },
 17618          "modelCard": {
 17619            "modelParameters": {
 17620              "approach": {}
 17621            },
 17622            "quantitativeAnalysis": {
 17623              "graphics": {}
 17624            },
 17625            "considerations": {}
 17626          }
 17627        },
 17628        {
 17629          "type": "library",
 17630          "bom-ref": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04\u0026package-id=b3a56223224b45d2",
 17631          "supplier": {},
 17632          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 17633          "name": "gpgv",
 17634          "version": "2.2.19-3ubuntu2.1",
 17635          "licenses": [
 17636            {
 17637              "license": {
 17638                "id": "BSD-3-Clause"
 17639              }
 17640            },
 17641            {
 17642              "license": {
 17643                "id": "CC0-1.0"
 17644              }
 17645            },
 17646            {
 17647              "license": {
 17648                "name": "Expat"
 17649              }
 17650            },
 17651            {
 17652              "license": {
 17653                "id": "GPL-3.0-only"
 17654              }
 17655            },
 17656            {
 17657              "license": {
 17658                "id": "GPL-3.0-or-later"
 17659              }
 17660            },
 17661            {
 17662              "license": {
 17663                "id": "LGPL-2.1-only"
 17664              }
 17665            },
 17666            {
 17667              "license": {
 17668                "id": "LGPL-2.1-or-later"
 17669              }
 17670            },
 17671            {
 17672              "license": {
 17673                "id": "LGPL-3.0-only"
 17674              }
 17675            },
 17676            {
 17677              "license": {
 17678                "id": "LGPL-3.0-or-later"
 17679              }
 17680            },
 17681            {
 17682              "license": {
 17683                "name": "RFC-Reference"
 17684              }
 17685            },
 17686            {
 17687              "license": {
 17688                "name": "TinySCHEME"
 17689              }
 17690            },
 17691            {
 17692              "license": {
 17693                "name": "permissive"
 17694              }
 17695            }
 17696          ],
 17697          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.19-3ubuntu2.1:*:*:*:*:*:*:*",
 17698          "purl": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04",
 17699          "swid": {
 17700            "attachment": {}
 17701          },
 17702          "pedigree": {},
 17703          "evidence": {},
 17704          "signature": {
 17705            "signature": {
 17706              "publicKey": {}
 17707            }
 17708          },
 17709          "modelCard": {
 17710            "modelParameters": {
 17711              "approach": {}
 17712            },
 17713            "quantitativeAnalysis": {
 17714              "graphics": {}
 17715            },
 17716            "considerations": {}
 17717          }
 17718        },
 17719        {
 17720          "type": "library",
 17721          "bom-ref": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7af9af4b90473f",
 17722          "supplier": {},
 17723          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 17724          "name": "grep",
 17725          "version": "3.4-1",
 17726          "licenses": [
 17727            {
 17728              "license": {
 17729                "id": "GPL-3.0-only"
 17730              }
 17731            },
 17732            {
 17733              "license": {
 17734                "id": "GPL-3.0-or-later"
 17735              }
 17736            }
 17737          ],
 17738          "cpe": "cpe:2.3:a:grep:grep:3.4-1:*:*:*:*:*:*:*",
 17739          "purl": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04",
 17740          "swid": {
 17741            "attachment": {}
 17742          },
 17743          "pedigree": {},
 17744          "evidence": {},
 17745          "signature": {
 17746            "signature": {
 17747              "publicKey": {}
 17748            }
 17749          },
 17750          "modelCard": {
 17751            "modelParameters": {
 17752              "approach": {}
 17753            },
 17754            "quantitativeAnalysis": {
 17755              "graphics": {}
 17756            },
 17757            "considerations": {}
 17758          }
 17759        },
 17760        {
 17761          "type": "library",
 17762          "bom-ref": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a9696917d3b9f9fc",
 17763          "supplier": {},
 17764          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 17765          "name": "gzip",
 17766          "version": "1.10-0ubuntu4",
 17767          "licenses": [
 17768            {
 17769              "license": {
 17770                "name": "GPL"
 17771              }
 17772            }
 17773          ],
 17774          "cpe": "cpe:2.3:a:gzip:gzip:1.10-0ubuntu4:*:*:*:*:*:*:*",
 17775          "purl": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04",
 17776          "swid": {
 17777            "attachment": {}
 17778          },
 17779          "pedigree": {},
 17780          "evidence": {},
 17781          "signature": {
 17782            "signature": {
 17783              "publicKey": {}
 17784            }
 17785          },
 17786          "modelCard": {
 17787            "modelParameters": {
 17788              "approach": {}
 17789            },
 17790            "quantitativeAnalysis": {
 17791              "graphics": {}
 17792            },
 17793            "considerations": {}
 17794          }
 17795        },
 17796        {
 17797          "type": "library",
 17798          "bom-ref": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=263dae70cc8e6a4f",
 17799          "supplier": {},
 17800          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 17801          "name": "hostname",
 17802          "version": "3.23",
 17803          "licenses": [
 17804            {
 17805              "license": {
 17806                "id": "GPL-2.0-only"
 17807              }
 17808            }
 17809          ],
 17810          "cpe": "cpe:2.3:a:hostname:hostname:3.23:*:*:*:*:*:*:*",
 17811          "purl": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04",
 17812          "swid": {
 17813            "attachment": {}
 17814          },
 17815          "pedigree": {},
 17816          "evidence": {},
 17817          "signature": {
 17818            "signature": {
 17819              "publicKey": {}
 17820            }
 17821          },
 17822          "modelCard": {
 17823            "modelParameters": {
 17824              "approach": {}
 17825            },
 17826            "quantitativeAnalysis": {
 17827              "graphics": {}
 17828            },
 17829            "considerations": {}
 17830          }
 17831        },
 17832        {
 17833          "type": "library",
 17834          "bom-ref": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04\u0026package-id=b0e335d96f12154d",
 17835          "supplier": {},
 17836          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 17837          "name": "init-system-helpers",
 17838          "version": "1.57",
 17839          "licenses": [
 17840            {
 17841              "license": {
 17842                "id": "BSD-3-Clause"
 17843              }
 17844            },
 17845            {
 17846              "license": {
 17847                "id": "GPL-2.0-only"
 17848              }
 17849            },
 17850            {
 17851              "license": {
 17852                "id": "GPL-2.0-or-later"
 17853              }
 17854            }
 17855          ],
 17856          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.57:*:*:*:*:*:*:*",
 17857          "purl": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04",
 17858          "swid": {
 17859            "attachment": {}
 17860          },
 17861          "pedigree": {},
 17862          "evidence": {},
 17863          "signature": {
 17864            "signature": {
 17865              "publicKey": {}
 17866            }
 17867          },
 17868          "modelCard": {
 17869            "modelParameters": {
 17870              "approach": {}
 17871            },
 17872            "quantitativeAnalysis": {
 17873              "graphics": {}
 17874            },
 17875            "considerations": {}
 17876          }
 17877        },
 17878        {
 17879          "type": "library",
 17880          "bom-ref": "pkg:deb/ubuntu/iproute2@5.5.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f4afda4dc550367c",
 17881          "supplier": {},
 17882          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 17883          "name": "iproute2",
 17884          "version": "5.5.0-1ubuntu1",
 17885          "licenses": [
 17886            {
 17887              "license": {
 17888                "id": "GPL-2.0-only"
 17889              }
 17890            }
 17891          ],
 17892          "cpe": "cpe:2.3:a:iproute2:iproute2:5.5.0-1ubuntu1:*:*:*:*:*:*:*",
 17893          "purl": "pkg:deb/ubuntu/iproute2@5.5.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 17894          "swid": {
 17895            "attachment": {}
 17896          },
 17897          "pedigree": {},
 17898          "evidence": {},
 17899          "signature": {
 17900            "signature": {
 17901              "publicKey": {}
 17902            }
 17903          },
 17904          "modelCard": {
 17905            "modelParameters": {
 17906              "approach": {}
 17907            },
 17908            "quantitativeAnalysis": {
 17909              "graphics": {}
 17910            },
 17911            "considerations": {}
 17912          }
 17913        },
 17914        {
 17915          "type": "library",
 17916          "bom-ref": "pkg:deb/ubuntu/iputils-ping@3:20190709-3?arch=amd64\u0026upstream=iputils\u0026distro=ubuntu-20.04\u0026package-id=83f284daebd0969f",
 17917          "supplier": {},
 17918          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 17919          "name": "iputils-ping",
 17920          "version": "3:20190709-3",
 17921          "licenses": [
 17922            {
 17923              "license": {
 17924                "name": "GPL"
 17925              }
 17926            }
 17927          ],
 17928          "cpe": "cpe:2.3:a:iputils-ping:iputils-ping:3\\:20190709-3:*:*:*:*:*:*:*",
 17929          "purl": "pkg:deb/ubuntu/iputils-ping@3:20190709-3?arch=amd64\u0026upstream=iputils\u0026distro=ubuntu-20.04",
 17930          "swid": {
 17931            "attachment": {}
 17932          },
 17933          "pedigree": {},
 17934          "evidence": {},
 17935          "signature": {
 17936            "signature": {
 17937              "publicKey": {}
 17938            }
 17939          },
 17940          "modelCard": {
 17941            "modelParameters": {
 17942              "approach": {}
 17943            },
 17944            "quantitativeAnalysis": {
 17945              "graphics": {}
 17946            },
 17947            "considerations": {}
 17948          }
 17949        },
 17950        {
 17951          "type": "library",
 17952          "bom-ref": "pkg:golang/k8s.io/api@v0.18.19?package-id=337b0c8ae743e766",
 17953          "supplier": {},
 17954          "name": "k8s.io/api",
 17955          "version": "v0.18.19",
 17956          "purl": "pkg:golang/k8s.io/api@v0.18.19",
 17957          "swid": {
 17958            "attachment": {}
 17959          },
 17960          "pedigree": {},
 17961          "evidence": {},
 17962          "signature": {
 17963            "signature": {
 17964              "publicKey": {}
 17965            }
 17966          },
 17967          "modelCard": {
 17968            "modelParameters": {
 17969              "approach": {}
 17970            },
 17971            "quantitativeAnalysis": {
 17972              "graphics": {}
 17973            },
 17974            "considerations": {}
 17975          }
 17976        },
 17977        {
 17978          "type": "library",
 17979          "bom-ref": "pkg:golang/k8s.io/apiextensions-apiserver@v0.18.19?package-id=ae66a6d3b8562056",
 17980          "supplier": {},
 17981          "name": "k8s.io/apiextensions-apiserver",
 17982          "version": "v0.18.19",
 17983          "purl": "pkg:golang/k8s.io/apiextensions-apiserver@v0.18.19",
 17984          "swid": {
 17985            "attachment": {}
 17986          },
 17987          "pedigree": {},
 17988          "evidence": {},
 17989          "signature": {
 17990            "signature": {
 17991              "publicKey": {}
 17992            }
 17993          },
 17994          "modelCard": {
 17995            "modelParameters": {
 17996              "approach": {}
 17997            },
 17998            "quantitativeAnalysis": {
 17999              "graphics": {}
 18000            },
 18001            "considerations": {}
 18002          }
 18003        },
 18004        {
 18005          "type": "library",
 18006          "bom-ref": "pkg:golang/k8s.io/apimachinery@v0.18.19?package-id=5d26de9c6adafbb5",
 18007          "supplier": {},
 18008          "name": "k8s.io/apimachinery",
 18009          "version": "v0.18.19",
 18010          "purl": "pkg:golang/k8s.io/apimachinery@v0.18.19",
 18011          "swid": {
 18012            "attachment": {}
 18013          },
 18014          "pedigree": {},
 18015          "evidence": {},
 18016          "signature": {
 18017            "signature": {
 18018              "publicKey": {}
 18019            }
 18020          },
 18021          "modelCard": {
 18022            "modelParameters": {
 18023              "approach": {}
 18024            },
 18025            "quantitativeAnalysis": {
 18026              "graphics": {}
 18027            },
 18028            "considerations": {}
 18029          }
 18030        },
 18031        {
 18032          "type": "library",
 18033          "bom-ref": "pkg:golang/k8s.io/apiserver@v0.18.19?package-id=7f17cc418dc57557",
 18034          "supplier": {},
 18035          "name": "k8s.io/apiserver",
 18036          "version": "v0.18.19",
 18037          "purl": "pkg:golang/k8s.io/apiserver@v0.18.19",
 18038          "swid": {
 18039            "attachment": {}
 18040          },
 18041          "pedigree": {},
 18042          "evidence": {},
 18043          "signature": {
 18044            "signature": {
 18045              "publicKey": {}
 18046            }
 18047          },
 18048          "modelCard": {
 18049            "modelParameters": {
 18050              "approach": {}
 18051            },
 18052            "quantitativeAnalysis": {
 18053              "graphics": {}
 18054            },
 18055            "considerations": {}
 18056          }
 18057        },
 18058        {
 18059          "type": "library",
 18060          "bom-ref": "pkg:golang/k8s.io/client-go@v0.18.19?package-id=aa247b01a3d9ad99",
 18061          "supplier": {},
 18062          "name": "k8s.io/client-go",
 18063          "version": "v0.18.19",
 18064          "purl": "pkg:golang/k8s.io/client-go@v0.18.19",
 18065          "swid": {
 18066            "attachment": {}
 18067          },
 18068          "pedigree": {},
 18069          "evidence": {},
 18070          "signature": {
 18071            "signature": {
 18072              "publicKey": {}
 18073            }
 18074          },
 18075          "modelCard": {
 18076            "modelParameters": {
 18077              "approach": {}
 18078            },
 18079            "quantitativeAnalysis": {
 18080              "graphics": {}
 18081            },
 18082            "considerations": {}
 18083          }
 18084        },
 18085        {
 18086          "type": "library",
 18087          "bom-ref": "pkg:golang/k8s.io/component-base@v0.18.19?package-id=bfe87df4dc740d63",
 18088          "supplier": {},
 18089          "name": "k8s.io/component-base",
 18090          "version": "v0.18.19",
 18091          "purl": "pkg:golang/k8s.io/component-base@v0.18.19",
 18092          "swid": {
 18093            "attachment": {}
 18094          },
 18095          "pedigree": {},
 18096          "evidence": {},
 18097          "signature": {
 18098            "signature": {
 18099              "publicKey": {}
 18100            }
 18101          },
 18102          "modelCard": {
 18103            "modelParameters": {
 18104              "approach": {}
 18105            },
 18106            "quantitativeAnalysis": {
 18107              "graphics": {}
 18108            },
 18109            "considerations": {}
 18110          }
 18111        },
 18112        {
 18113          "type": "library",
 18114          "bom-ref": "pkg:golang/k8s.io/klog@v1.0.0?package-id=6b36beaa4b8fb955",
 18115          "supplier": {},
 18116          "name": "k8s.io/klog",
 18117          "version": "v1.0.0",
 18118          "purl": "pkg:golang/k8s.io/klog@v1.0.0",
 18119          "swid": {
 18120            "attachment": {}
 18121          },
 18122          "pedigree": {},
 18123          "evidence": {},
 18124          "signature": {
 18125            "signature": {
 18126              "publicKey": {}
 18127            }
 18128          },
 18129          "modelCard": {
 18130            "modelParameters": {
 18131              "approach": {}
 18132            },
 18133            "quantitativeAnalysis": {
 18134              "graphics": {}
 18135            },
 18136            "considerations": {}
 18137          }
 18138        },
 18139        {
 18140          "type": "library",
 18141          "bom-ref": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20200410145947-61e04a5be9a6?package-id=e3c46d837051ee8f",
 18142          "supplier": {},
 18143          "name": "k8s.io/kube-openapi",
 18144          "version": "v0.0.0-20200410145947-61e04a5be9a6",
 18145          "purl": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20200410145947-61e04a5be9a6",
 18146          "swid": {
 18147            "attachment": {}
 18148          },
 18149          "pedigree": {},
 18150          "evidence": {},
 18151          "signature": {
 18152            "signature": {
 18153              "publicKey": {}
 18154            }
 18155          },
 18156          "modelCard": {
 18157            "modelParameters": {
 18158              "approach": {}
 18159            },
 18160            "quantitativeAnalysis": {
 18161              "graphics": {}
 18162            },
 18163            "considerations": {}
 18164          }
 18165        },
 18166        {
 18167          "type": "library",
 18168          "bom-ref": "pkg:golang/k8s.io/kubernetes@v1.18.19?package-id=79c702d72d73abad",
 18169          "supplier": {},
 18170          "name": "k8s.io/kubernetes",
 18171          "version": "v1.18.19",
 18172          "purl": "pkg:golang/k8s.io/kubernetes@v1.18.19",
 18173          "swid": {
 18174            "attachment": {}
 18175          },
 18176          "pedigree": {},
 18177          "evidence": {},
 18178          "signature": {
 18179            "signature": {
 18180              "publicKey": {}
 18181            }
 18182          },
 18183          "modelCard": {
 18184            "modelParameters": {
 18185              "approach": {}
 18186            },
 18187            "quantitativeAnalysis": {
 18188              "graphics": {}
 18189            },
 18190            "considerations": {}
 18191          }
 18192        },
 18193        {
 18194          "type": "library",
 18195          "bom-ref": "pkg:golang/k8s.io/metrics@v0.18.19?package-id=4a8db5ce35d89963",
 18196          "supplier": {},
 18197          "name": "k8s.io/metrics",
 18198          "version": "v0.18.19",
 18199          "purl": "pkg:golang/k8s.io/metrics@v0.18.19",
 18200          "swid": {
 18201            "attachment": {}
 18202          },
 18203          "pedigree": {},
 18204          "evidence": {},
 18205          "signature": {
 18206            "signature": {
 18207              "publicKey": {}
 18208            }
 18209          },
 18210          "modelCard": {
 18211            "modelParameters": {
 18212              "approach": {}
 18213            },
 18214            "quantitativeAnalysis": {
 18215              "graphics": {}
 18216            },
 18217            "considerations": {}
 18218          }
 18219        },
 18220        {
 18221          "type": "library",
 18222          "bom-ref": "pkg:golang/k8s.io/utils@v0.0.0-20200324210504-a9aa75ae1b89?package-id=ad9c757e4a913b12",
 18223          "supplier": {},
 18224          "name": "k8s.io/utils",
 18225          "version": "v0.0.0-20200324210504-a9aa75ae1b89",
 18226          "purl": "pkg:golang/k8s.io/utils@v0.0.0-20200324210504-a9aa75ae1b89",
 18227          "swid": {
 18228            "attachment": {}
 18229          },
 18230          "pedigree": {},
 18231          "evidence": {},
 18232          "signature": {
 18233            "signature": {
 18234              "publicKey": {}
 18235            }
 18236          },
 18237          "modelCard": {
 18238            "modelParameters": {
 18239              "approach": {}
 18240            },
 18241            "quantitativeAnalysis": {
 18242              "graphics": {}
 18243            },
 18244            "considerations": {}
 18245          }
 18246        },
 18247        {
 18248          "type": "library",
 18249          "bom-ref": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a61b8b47cf58815b",
 18250          "supplier": {},
 18251          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18252          "name": "keyutils",
 18253          "version": "1.6-6ubuntu1",
 18254          "licenses": [
 18255            {
 18256              "license": {
 18257                "id": "GPL-2.0-only"
 18258              }
 18259            },
 18260            {
 18261              "license": {
 18262                "id": "GPL-2.0-or-later"
 18263              }
 18264            },
 18265            {
 18266              "license": {
 18267                "id": "LGPL-2.0-only"
 18268              }
 18269            },
 18270            {
 18271              "license": {
 18272                "id": "LGPL-2.0-or-later"
 18273              }
 18274            }
 18275          ],
 18276          "cpe": "cpe:2.3:a:keyutils:keyutils:1.6-6ubuntu1:*:*:*:*:*:*:*",
 18277          "purl": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 18278          "swid": {
 18279            "attachment": {}
 18280          },
 18281          "pedigree": {},
 18282          "evidence": {},
 18283          "signature": {
 18284            "signature": {
 18285              "publicKey": {}
 18286            }
 18287          },
 18288          "modelCard": {
 18289            "modelParameters": {
 18290              "approach": {}
 18291            },
 18292            "quantitativeAnalysis": {
 18293              "graphics": {}
 18294            },
 18295            "considerations": {}
 18296          }
 18297        },
 18298        {
 18299          "type": "library",
 18300          "bom-ref": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=87ea48972fb4adab",
 18301          "supplier": {},
 18302          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18303          "name": "krb5-locales",
 18304          "version": "1.17-6ubuntu4.1",
 18305          "licenses": [
 18306            {
 18307              "license": {
 18308                "id": "GPL-2.0-only"
 18309              }
 18310            }
 18311          ],
 18312          "cpe": "cpe:2.3:a:krb5-locales:krb5-locales:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 18313          "purl": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 18314          "swid": {
 18315            "attachment": {}
 18316          },
 18317          "pedigree": {},
 18318          "evidence": {},
 18319          "signature": {
 18320            "signature": {
 18321              "publicKey": {}
 18322            }
 18323          },
 18324          "modelCard": {
 18325            "modelParameters": {
 18326              "approach": {}
 18327            },
 18328            "quantitativeAnalysis": {
 18329              "graphics": {}
 18330            },
 18331            "considerations": {}
 18332          }
 18333        },
 18334        {
 18335          "type": "library",
 18336          "bom-ref": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04\u0026package-id=5cec2c2009596050",
 18337          "supplier": {},
 18338          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18339          "name": "libacl1",
 18340          "version": "2.2.53-6",
 18341          "licenses": [
 18342            {
 18343              "license": {
 18344                "id": "GPL-2.0-only"
 18345              }
 18346            },
 18347            {
 18348              "license": {
 18349                "id": "GPL-2.0-or-later"
 18350              }
 18351            },
 18352            {
 18353              "license": {
 18354                "id": "LGPL-2.0-or-later"
 18355              }
 18356            },
 18357            {
 18358              "license": {
 18359                "id": "LGPL-2.1-only"
 18360              }
 18361            }
 18362          ],
 18363          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-6:*:*:*:*:*:*:*",
 18364          "purl": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04",
 18365          "swid": {
 18366            "attachment": {}
 18367          },
 18368          "pedigree": {},
 18369          "evidence": {},
 18370          "signature": {
 18371            "signature": {
 18372              "publicKey": {}
 18373            }
 18374          },
 18375          "modelCard": {
 18376            "modelParameters": {
 18377              "approach": {}
 18378            },
 18379            "quantitativeAnalysis": {
 18380              "graphics": {}
 18381            },
 18382            "considerations": {}
 18383          }
 18384        },
 18385        {
 18386          "type": "library",
 18387          "bom-ref": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04\u0026package-id=864e143f4c606a6c",
 18388          "supplier": {},
 18389          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18390          "name": "libapt-pkg6.0",
 18391          "version": "2.0.6",
 18392          "licenses": [
 18393            {
 18394              "license": {
 18395                "id": "GPL-2.0-only"
 18396              }
 18397            },
 18398            {
 18399              "license": {
 18400                "name": "GPLv2+"
 18401              }
 18402            }
 18403          ],
 18404          "cpe": "cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.0.6:*:*:*:*:*:*:*",
 18405          "purl": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04",
 18406          "swid": {
 18407            "attachment": {}
 18408          },
 18409          "pedigree": {},
 18410          "evidence": {},
 18411          "signature": {
 18412            "signature": {
 18413              "publicKey": {}
 18414            }
 18415          },
 18416          "modelCard": {
 18417            "modelParameters": {
 18418              "approach": {}
 18419            },
 18420            "quantitativeAnalysis": {
 18421              "graphics": {}
 18422            },
 18423            "considerations": {}
 18424          }
 18425        },
 18426        {
 18427          "type": "library",
 18428          "bom-ref": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=915f8cf154d1b7ce",
 18429          "supplier": {},
 18430          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18431          "name": "libasn1-8-heimdal",
 18432          "version": "7.7.0+dfsg-1ubuntu1",
 18433          "licenses": [
 18434            {
 18435              "license": {
 18436                "id": "BSD-3-Clause"
 18437              }
 18438            },
 18439            {
 18440              "license": {
 18441                "id": "GPL-2.0-only"
 18442              }
 18443            },
 18444            {
 18445              "license": {
 18446                "id": "GPL-2.0-or-later"
 18447              }
 18448            },
 18449            {
 18450              "license": {
 18451                "name": "custom"
 18452              }
 18453            }
 18454          ],
 18455          "cpe": "cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 18456          "purl": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 18457          "swid": {
 18458            "attachment": {}
 18459          },
 18460          "pedigree": {},
 18461          "evidence": {},
 18462          "signature": {
 18463            "signature": {
 18464              "publicKey": {}
 18465            }
 18466          },
 18467          "modelCard": {
 18468            "modelParameters": {
 18469              "approach": {}
 18470            },
 18471            "quantitativeAnalysis": {
 18472              "graphics": {}
 18473            },
 18474            "considerations": {}
 18475          }
 18476        },
 18477        {
 18478          "type": "library",
 18479          "bom-ref": "pkg:deb/ubuntu/libasound2@1.2.2-2.1ubuntu2.4?arch=amd64\u0026upstream=alsa-lib\u0026distro=ubuntu-20.04\u0026package-id=32aecebdfc30e11b",
 18480          "supplier": {},
 18481          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18482          "name": "libasound2",
 18483          "version": "1.2.2-2.1ubuntu2.4",
 18484          "licenses": [
 18485            {
 18486              "license": {
 18487                "id": "LGPL-2.1-only"
 18488              }
 18489            },
 18490            {
 18491              "license": {
 18492                "name": "LPGL-2.1+"
 18493              }
 18494            }
 18495          ],
 18496          "cpe": "cpe:2.3:a:libasound2:libasound2:1.2.2-2.1ubuntu2.4:*:*:*:*:*:*:*",
 18497          "purl": "pkg:deb/ubuntu/libasound2@1.2.2-2.1ubuntu2.4?arch=amd64\u0026upstream=alsa-lib\u0026distro=ubuntu-20.04",
 18498          "swid": {
 18499            "attachment": {}
 18500          },
 18501          "pedigree": {},
 18502          "evidence": {},
 18503          "signature": {
 18504            "signature": {
 18505              "publicKey": {}
 18506            }
 18507          },
 18508          "modelCard": {
 18509            "modelParameters": {
 18510              "approach": {}
 18511            },
 18512            "quantitativeAnalysis": {
 18513              "graphics": {}
 18514            },
 18515            "considerations": {}
 18516          }
 18517        },
 18518        {
 18519          "type": "library",
 18520          "bom-ref": "pkg:deb/ubuntu/libasound2-data@1.2.2-2.1ubuntu2.4?arch=all\u0026upstream=alsa-lib\u0026distro=ubuntu-20.04\u0026package-id=57d6fc752e69145d",
 18521          "supplier": {},
 18522          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18523          "name": "libasound2-data",
 18524          "version": "1.2.2-2.1ubuntu2.4",
 18525          "licenses": [
 18526            {
 18527              "license": {
 18528                "id": "LGPL-2.1-only"
 18529              }
 18530            },
 18531            {
 18532              "license": {
 18533                "name": "LPGL-2.1+"
 18534              }
 18535            }
 18536          ],
 18537          "cpe": "cpe:2.3:a:libasound2-data:libasound2-data:1.2.2-2.1ubuntu2.4:*:*:*:*:*:*:*",
 18538          "purl": "pkg:deb/ubuntu/libasound2-data@1.2.2-2.1ubuntu2.4?arch=all\u0026upstream=alsa-lib\u0026distro=ubuntu-20.04",
 18539          "swid": {
 18540            "attachment": {}
 18541          },
 18542          "pedigree": {},
 18543          "evidence": {},
 18544          "signature": {
 18545            "signature": {
 18546              "publicKey": {}
 18547            }
 18548          },
 18549          "modelCard": {
 18550            "modelParameters": {
 18551              "approach": {}
 18552            },
 18553            "quantitativeAnalysis": {
 18554              "graphics": {}
 18555            },
 18556            "considerations": {}
 18557          }
 18558        },
 18559        {
 18560          "type": "library",
 18561          "bom-ref": "pkg:deb/ubuntu/libatm1@1:2.5.1-4?arch=amd64\u0026upstream=linux-atm\u0026distro=ubuntu-20.04\u0026package-id=38fbc3dda7412f50",
 18562          "supplier": {},
 18563          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18564          "name": "libatm1",
 18565          "version": "1:2.5.1-4",
 18566          "licenses": [
 18567            {
 18568              "license": {
 18569                "id": "GPL-2.0-only"
 18570              }
 18571            }
 18572          ],
 18573          "cpe": "cpe:2.3:a:libatm1:libatm1:1\\:2.5.1-4:*:*:*:*:*:*:*",
 18574          "purl": "pkg:deb/ubuntu/libatm1@1:2.5.1-4?arch=amd64\u0026upstream=linux-atm\u0026distro=ubuntu-20.04",
 18575          "swid": {
 18576            "attachment": {}
 18577          },
 18578          "pedigree": {},
 18579          "evidence": {},
 18580          "signature": {
 18581            "signature": {
 18582              "publicKey": {}
 18583            }
 18584          },
 18585          "modelCard": {
 18586            "modelParameters": {
 18587              "approach": {}
 18588            },
 18589            "quantitativeAnalysis": {
 18590              "graphics": {}
 18591            },
 18592            "considerations": {}
 18593          }
 18594        },
 18595        {
 18596          "type": "library",
 18597          "bom-ref": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04\u0026package-id=edf8dd62bd537bd5",
 18598          "supplier": {},
 18599          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18600          "name": "libattr1",
 18601          "version": "1:2.4.48-5",
 18602          "licenses": [
 18603            {
 18604              "license": {
 18605                "id": "GPL-2.0-only"
 18606              }
 18607            },
 18608            {
 18609              "license": {
 18610                "id": "GPL-2.0-or-later"
 18611              }
 18612            },
 18613            {
 18614              "license": {
 18615                "id": "LGPL-2.0-or-later"
 18616              }
 18617            },
 18618            {
 18619              "license": {
 18620                "id": "LGPL-2.1-only"
 18621              }
 18622            }
 18623          ],
 18624          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-5:*:*:*:*:*:*:*",
 18625          "purl": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04",
 18626          "swid": {
 18627            "attachment": {}
 18628          },
 18629          "pedigree": {},
 18630          "evidence": {},
 18631          "signature": {
 18632            "signature": {
 18633              "publicKey": {}
 18634            }
 18635          },
 18636          "modelCard": {
 18637            "modelParameters": {
 18638              "approach": {}
 18639            },
 18640            "quantitativeAnalysis": {
 18641              "graphics": {}
 18642            },
 18643            "considerations": {}
 18644          }
 18645        },
 18646        {
 18647          "type": "library",
 18648          "bom-ref": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=4a463ab850d7c68c",
 18649          "supplier": {},
 18650          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18651          "name": "libaudit-common",
 18652          "version": "1:2.8.5-2ubuntu6",
 18653          "licenses": [
 18654            {
 18655              "license": {
 18656                "id": "GPL-1.0-only"
 18657              }
 18658            },
 18659            {
 18660              "license": {
 18661                "id": "GPL-2.0-only"
 18662              }
 18663            },
 18664            {
 18665              "license": {
 18666                "id": "LGPL-2.1-only"
 18667              }
 18668            }
 18669          ],
 18670          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
 18671          "purl": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04",
 18672          "swid": {
 18673            "attachment": {}
 18674          },
 18675          "pedigree": {},
 18676          "evidence": {},
 18677          "signature": {
 18678            "signature": {
 18679              "publicKey": {}
 18680            }
 18681          },
 18682          "modelCard": {
 18683            "modelParameters": {
 18684              "approach": {}
 18685            },
 18686            "quantitativeAnalysis": {
 18687              "graphics": {}
 18688            },
 18689            "considerations": {}
 18690          }
 18691        },
 18692        {
 18693          "type": "library",
 18694          "bom-ref": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=be9537deb8db616e",
 18695          "supplier": {},
 18696          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18697          "name": "libaudit1",
 18698          "version": "1:2.8.5-2ubuntu6",
 18699          "licenses": [
 18700            {
 18701              "license": {
 18702                "id": "GPL-1.0-only"
 18703              }
 18704            },
 18705            {
 18706              "license": {
 18707                "id": "GPL-2.0-only"
 18708              }
 18709            },
 18710            {
 18711              "license": {
 18712                "id": "LGPL-2.1-only"
 18713              }
 18714            }
 18715          ],
 18716          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
 18717          "purl": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04",
 18718          "swid": {
 18719            "attachment": {}
 18720          },
 18721          "pedigree": {},
 18722          "evidence": {},
 18723          "signature": {
 18724            "signature": {
 18725              "publicKey": {}
 18726            }
 18727          },
 18728          "modelCard": {
 18729            "modelParameters": {
 18730              "approach": {}
 18731            },
 18732            "quantitativeAnalysis": {
 18733              "graphics": {}
 18734            },
 18735            "considerations": {}
 18736          }
 18737        },
 18738        {
 18739          "type": "library",
 18740          "bom-ref": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=e1d6f2e998332d7d",
 18741          "supplier": {},
 18742          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18743          "name": "libblkid1",
 18744          "version": "2.34-0.1ubuntu9.1",
 18745          "licenses": [
 18746            {
 18747              "license": {
 18748                "id": "BSD-2-Clause"
 18749              }
 18750            },
 18751            {
 18752              "license": {
 18753                "id": "BSD-3-Clause"
 18754              }
 18755            },
 18756            {
 18757              "license": {
 18758                "id": "BSD-4-Clause"
 18759              }
 18760            },
 18761            {
 18762              "license": {
 18763                "id": "GPL-2.0-only"
 18764              }
 18765            },
 18766            {
 18767              "license": {
 18768                "id": "GPL-2.0-or-later"
 18769              }
 18770            },
 18771            {
 18772              "license": {
 18773                "id": "GPL-3.0-only"
 18774              }
 18775            },
 18776            {
 18777              "license": {
 18778                "id": "GPL-3.0-or-later"
 18779              }
 18780            },
 18781            {
 18782              "license": {
 18783                "name": "LGPL"
 18784              }
 18785            },
 18786            {
 18787              "license": {
 18788                "id": "LGPL-2.0-only"
 18789              }
 18790            },
 18791            {
 18792              "license": {
 18793                "id": "LGPL-2.0-or-later"
 18794              }
 18795            },
 18796            {
 18797              "license": {
 18798                "id": "LGPL-2.1-only"
 18799              }
 18800            },
 18801            {
 18802              "license": {
 18803                "id": "LGPL-2.1-or-later"
 18804              }
 18805            },
 18806            {
 18807              "license": {
 18808                "id": "LGPL-3.0-only"
 18809              }
 18810            },
 18811            {
 18812              "license": {
 18813                "id": "LGPL-3.0-or-later"
 18814              }
 18815            },
 18816            {
 18817              "license": {
 18818                "id": "MIT"
 18819              }
 18820            },
 18821            {
 18822              "license": {
 18823                "name": "public-domain"
 18824              }
 18825            }
 18826          ],
 18827          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 18828          "purl": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 18829          "swid": {
 18830            "attachment": {}
 18831          },
 18832          "pedigree": {},
 18833          "evidence": {},
 18834          "signature": {
 18835            "signature": {
 18836              "publicKey": {}
 18837            }
 18838          },
 18839          "modelCard": {
 18840            "modelParameters": {
 18841              "approach": {}
 18842            },
 18843            "quantitativeAnalysis": {
 18844              "graphics": {}
 18845            },
 18846            "considerations": {}
 18847          }
 18848        },
 18849        {
 18850          "type": "library",
 18851          "bom-ref": "pkg:deb/ubuntu/libbrotli1@1.0.7-6ubuntu0.1?arch=amd64\u0026upstream=brotli\u0026distro=ubuntu-20.04\u0026package-id=3cfc22417c2e74ac",
 18852          "supplier": {},
 18853          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18854          "name": "libbrotli1",
 18855          "version": "1.0.7-6ubuntu0.1",
 18856          "licenses": [
 18857            {
 18858              "license": {
 18859                "id": "MIT"
 18860              }
 18861            }
 18862          ],
 18863          "cpe": "cpe:2.3:a:libbrotli1:libbrotli1:1.0.7-6ubuntu0.1:*:*:*:*:*:*:*",
 18864          "purl": "pkg:deb/ubuntu/libbrotli1@1.0.7-6ubuntu0.1?arch=amd64\u0026upstream=brotli\u0026distro=ubuntu-20.04",
 18865          "swid": {
 18866            "attachment": {}
 18867          },
 18868          "pedigree": {},
 18869          "evidence": {},
 18870          "signature": {
 18871            "signature": {
 18872              "publicKey": {}
 18873            }
 18874          },
 18875          "modelCard": {
 18876            "modelParameters": {
 18877              "approach": {}
 18878            },
 18879            "quantitativeAnalysis": {
 18880              "graphics": {}
 18881            },
 18882            "considerations": {}
 18883          }
 18884        },
 18885        {
 18886          "type": "library",
 18887          "bom-ref": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04\u0026package-id=88ee716d66a17869",
 18888          "supplier": {},
 18889          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 18890          "name": "libbsd0",
 18891          "version": "0.10.0-1",
 18892          "licenses": [
 18893            {
 18894              "license": {
 18895                "id": "BSD-2-Clause"
 18896              }
 18897            },
 18898            {
 18899              "license": {
 18900                "id": "BSD-2-Clause"
 18901              }
 18902            },
 18903            {
 18904              "license": {
 18905                "name": "BSD-2-clause-author"
 18906              }
 18907            },
 18908            {
 18909              "license": {
 18910                "name": "BSD-2-clause-verbatim"
 18911              }
 18912            },
 18913            {
 18914              "license": {
 18915                "id": "BSD-3-Clause"
 18916              }
 18917            },
 18918            {
 18919              "license": {
 18920                "name": "BSD-3-clause-John-Birrell"
 18921              }
 18922            },
 18923            {
 18924              "license": {
 18925                "name": "BSD-3-clause-Regents"
 18926              }
 18927            },
 18928            {
 18929              "license": {
 18930                "name": "BSD-3-clause-author"
 18931              }
 18932            },
 18933            {
 18934              "license": {
 18935                "name": "BSD-4-clause-Christopher-G-Demetriou"
 18936              }
 18937            },
 18938            {
 18939              "license": {
 18940                "name": "BSD-4-clause-Niels-Provos"
 18941              }
 18942            },
 18943            {
 18944              "license": {
 18945                "name": "BSD-5-clause-Peter-Wemm"
 18946              }
 18947            },
 18948            {
 18949              "license": {
 18950                "id": "Beerware"
 18951              }
 18952            },
 18953            {
 18954              "license": {
 18955                "name": "Expat"
 18956              }
 18957            },
 18958            {
 18959              "license": {
 18960                "id": "ISC"
 18961              }
 18962            },
 18963            {
 18964              "license": {
 18965                "name": "ISC-Original"
 18966              }
 18967            },
 18968            {
 18969              "license": {
 18970                "name": "public-domain"
 18971              }
 18972            },
 18973            {
 18974              "license": {
 18975                "name": "public-domain-Colin-Plumb"
 18976              }
 18977            }
 18978          ],
 18979          "cpe": "cpe:2.3:a:libbsd0:libbsd0:0.10.0-1:*:*:*:*:*:*:*",
 18980          "purl": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04",
 18981          "swid": {
 18982            "attachment": {}
 18983          },
 18984          "pedigree": {},
 18985          "evidence": {},
 18986          "signature": {
 18987            "signature": {
 18988              "publicKey": {}
 18989            }
 18990          },
 18991          "modelCard": {
 18992            "modelParameters": {
 18993              "approach": {}
 18994            },
 18995            "quantitativeAnalysis": {
 18996              "graphics": {}
 18997            },
 18998            "considerations": {}
 18999          }
 19000        },
 19001        {
 19002          "type": "library",
 19003          "bom-ref": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04\u0026package-id=fd8b0edf257b69b7",
 19004          "supplier": {},
 19005          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19006          "name": "libbz2-1.0",
 19007          "version": "1.0.8-2",
 19008          "licenses": [
 19009            {
 19010              "license": {
 19011                "name": "BSD-variant"
 19012              }
 19013            },
 19014            {
 19015              "license": {
 19016                "id": "GPL-2.0-only"
 19017              }
 19018            }
 19019          ],
 19020          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-2:*:*:*:*:*:*:*",
 19021          "purl": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04",
 19022          "swid": {
 19023            "attachment": {}
 19024          },
 19025          "pedigree": {},
 19026          "evidence": {},
 19027          "signature": {
 19028            "signature": {
 19029              "publicKey": {}
 19030            }
 19031          },
 19032          "modelCard": {
 19033            "modelParameters": {
 19034              "approach": {}
 19035            },
 19036            "quantitativeAnalysis": {
 19037              "graphics": {}
 19038            },
 19039            "considerations": {}
 19040          }
 19041        },
 19042        {
 19043          "type": "library",
 19044          "bom-ref": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=256facf7cbb95a65",
 19045          "supplier": {},
 19046          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19047          "name": "libc-bin",
 19048          "version": "2.31-0ubuntu9.2",
 19049          "licenses": [
 19050            {
 19051              "license": {
 19052                "id": "GPL-2.0-only"
 19053              }
 19054            },
 19055            {
 19056              "license": {
 19057                "id": "LGPL-2.1-only"
 19058              }
 19059            }
 19060          ],
 19061          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
 19062          "purl": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
 19063          "swid": {
 19064            "attachment": {}
 19065          },
 19066          "pedigree": {},
 19067          "evidence": {},
 19068          "signature": {
 19069            "signature": {
 19070              "publicKey": {}
 19071            }
 19072          },
 19073          "modelCard": {
 19074            "modelParameters": {
 19075              "approach": {}
 19076            },
 19077            "quantitativeAnalysis": {
 19078              "graphics": {}
 19079            },
 19080            "considerations": {}
 19081          }
 19082        },
 19083        {
 19084          "type": "library",
 19085          "bom-ref": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=2a96b94fa4db214",
 19086          "supplier": {},
 19087          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19088          "name": "libc6",
 19089          "version": "2.31-0ubuntu9.2",
 19090          "licenses": [
 19091            {
 19092              "license": {
 19093                "id": "GPL-2.0-only"
 19094              }
 19095            },
 19096            {
 19097              "license": {
 19098                "id": "LGPL-2.1-only"
 19099              }
 19100            }
 19101          ],
 19102          "cpe": "cpe:2.3:a:libc6:libc6:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
 19103          "purl": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
 19104          "swid": {
 19105            "attachment": {}
 19106          },
 19107          "pedigree": {},
 19108          "evidence": {},
 19109          "signature": {
 19110            "signature": {
 19111              "publicKey": {}
 19112            }
 19113          },
 19114          "modelCard": {
 19115            "modelParameters": {
 19116              "approach": {}
 19117            },
 19118            "quantitativeAnalysis": {
 19119              "graphics": {}
 19120            },
 19121            "considerations": {}
 19122          }
 19123        },
 19124        {
 19125          "type": "library",
 19126          "bom-ref": "pkg:deb/ubuntu/libcanberra0@0.30-7ubuntu1?arch=amd64\u0026upstream=libcanberra\u0026distro=ubuntu-20.04\u0026package-id=a64c0154d7d2f145",
 19127          "supplier": {},
 19128          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19129          "name": "libcanberra0",
 19130          "version": "0.30-7ubuntu1",
 19131          "licenses": [
 19132            {
 19133              "license": {
 19134                "id": "LGPL-2.0-only"
 19135              }
 19136            },
 19137            {
 19138              "license": {
 19139                "id": "LGPL-2.1-only"
 19140              }
 19141            }
 19142          ],
 19143          "cpe": "cpe:2.3:a:libcanberra0:libcanberra0:0.30-7ubuntu1:*:*:*:*:*:*:*",
 19144          "purl": "pkg:deb/ubuntu/libcanberra0@0.30-7ubuntu1?arch=amd64\u0026upstream=libcanberra\u0026distro=ubuntu-20.04",
 19145          "swid": {
 19146            "attachment": {}
 19147          },
 19148          "pedigree": {},
 19149          "evidence": {},
 19150          "signature": {
 19151            "signature": {
 19152              "publicKey": {}
 19153            }
 19154          },
 19155          "modelCard": {
 19156            "modelParameters": {
 19157              "approach": {}
 19158            },
 19159            "quantitativeAnalysis": {
 19160              "graphics": {}
 19161            },
 19162            "considerations": {}
 19163          }
 19164        },
 19165        {
 19166          "type": "library",
 19167          "bom-ref": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04\u0026package-id=57ceb68462a99cb4",
 19168          "supplier": {},
 19169          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19170          "name": "libcap-ng0",
 19171          "version": "0.7.9-2.1build1",
 19172          "licenses": [
 19173            {
 19174              "license": {
 19175                "id": "GPL-2.0-only"
 19176              }
 19177            },
 19178            {
 19179              "license": {
 19180                "id": "GPL-3.0-only"
 19181              }
 19182            },
 19183            {
 19184              "license": {
 19185                "id": "LGPL-2.1-only"
 19186              }
 19187            }
 19188          ],
 19189          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2.1build1:*:*:*:*:*:*:*",
 19190          "purl": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04",
 19191          "swid": {
 19192            "attachment": {}
 19193          },
 19194          "pedigree": {},
 19195          "evidence": {},
 19196          "signature": {
 19197            "signature": {
 19198              "publicKey": {}
 19199            }
 19200          },
 19201          "modelCard": {
 19202            "modelParameters": {
 19203              "approach": {}
 19204            },
 19205            "quantitativeAnalysis": {
 19206              "graphics": {}
 19207            },
 19208            "considerations": {}
 19209          }
 19210        },
 19211        {
 19212          "type": "library",
 19213          "bom-ref": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=682f3e304c127762",
 19214          "supplier": {},
 19215          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19216          "name": "libcap2",
 19217          "version": "1:2.32-1",
 19218          "licenses": [
 19219            {
 19220              "license": {
 19221                "id": "BSD-3-Clause"
 19222              }
 19223            },
 19224            {
 19225              "license": {
 19226                "id": "GPL-2.0-only"
 19227              }
 19228            },
 19229            {
 19230              "license": {
 19231                "id": "GPL-2.0-or-later"
 19232              }
 19233            }
 19234          ],
 19235          "cpe": "cpe:2.3:a:libcap2:libcap2:1\\:2.32-1:*:*:*:*:*:*:*",
 19236          "purl": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04",
 19237          "swid": {
 19238            "attachment": {}
 19239          },
 19240          "pedigree": {},
 19241          "evidence": {},
 19242          "signature": {
 19243            "signature": {
 19244              "publicKey": {}
 19245            }
 19246          },
 19247          "modelCard": {
 19248            "modelParameters": {
 19249              "approach": {}
 19250            },
 19251            "quantitativeAnalysis": {
 19252              "graphics": {}
 19253            },
 19254            "considerations": {}
 19255          }
 19256        },
 19257        {
 19258          "type": "library",
 19259          "bom-ref": "pkg:deb/ubuntu/libcap2-bin@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04\u0026package-id=8f0ae2256856772c",
 19260          "supplier": {},
 19261          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19262          "name": "libcap2-bin",
 19263          "version": "1:2.32-1",
 19264          "licenses": [
 19265            {
 19266              "license": {
 19267                "id": "BSD-3-Clause"
 19268              }
 19269            },
 19270            {
 19271              "license": {
 19272                "id": "GPL-2.0-only"
 19273              }
 19274            },
 19275            {
 19276              "license": {
 19277                "id": "GPL-2.0-or-later"
 19278              }
 19279            }
 19280          ],
 19281          "cpe": "cpe:2.3:a:libcap2-bin:libcap2-bin:1\\:2.32-1:*:*:*:*:*:*:*",
 19282          "purl": "pkg:deb/ubuntu/libcap2-bin@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04",
 19283          "swid": {
 19284            "attachment": {}
 19285          },
 19286          "pedigree": {},
 19287          "evidence": {},
 19288          "signature": {
 19289            "signature": {
 19290              "publicKey": {}
 19291            }
 19292          },
 19293          "modelCard": {
 19294            "modelParameters": {
 19295              "approach": {}
 19296            },
 19297            "quantitativeAnalysis": {
 19298              "graphics": {}
 19299            },
 19300            "considerations": {}
 19301          }
 19302        },
 19303        {
 19304          "type": "library",
 19305          "bom-ref": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=fbaeb4c3d5d0f976",
 19306          "supplier": {},
 19307          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19308          "name": "libcom-err2",
 19309          "version": "1.45.5-2ubuntu1",
 19310          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 19311          "purl": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 19312          "swid": {
 19313            "attachment": {}
 19314          },
 19315          "pedigree": {},
 19316          "evidence": {},
 19317          "signature": {
 19318            "signature": {
 19319              "publicKey": {}
 19320            }
 19321          },
 19322          "modelCard": {
 19323            "modelParameters": {
 19324              "approach": {}
 19325            },
 19326            "quantitativeAnalysis": {
 19327              "graphics": {}
 19328            },
 19329            "considerations": {}
 19330          }
 19331        },
 19332        {
 19333          "type": "library",
 19334          "bom-ref": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04\u0026package-id=8a4302e2e7027353",
 19335          "supplier": {},
 19336          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19337          "name": "libcrypt1",
 19338          "version": "1:4.4.10-10ubuntu4",
 19339          "cpe": "cpe:2.3:a:libcrypt1:libcrypt1:1\\:4.4.10-10ubuntu4:*:*:*:*:*:*:*",
 19340          "purl": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04",
 19341          "swid": {
 19342            "attachment": {}
 19343          },
 19344          "pedigree": {},
 19345          "evidence": {},
 19346          "signature": {
 19347            "signature": {
 19348              "publicKey": {}
 19349            }
 19350          },
 19351          "modelCard": {
 19352            "modelParameters": {
 19353              "approach": {}
 19354            },
 19355            "quantitativeAnalysis": {
 19356              "graphics": {}
 19357            },
 19358            "considerations": {}
 19359          }
 19360        },
 19361        {
 19362          "type": "library",
 19363          "bom-ref": "pkg:deb/ubuntu/libcurl4@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04\u0026package-id=c9dd9bae4f158cd3",
 19364          "supplier": {},
 19365          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19366          "name": "libcurl4",
 19367          "version": "7.68.0-1ubuntu2.6",
 19368          "licenses": [
 19369            {
 19370              "license": {
 19371                "id": "BSD-3-Clause"
 19372              }
 19373            },
 19374            {
 19375              "license": {
 19376                "id": "BSD-4-Clause"
 19377              }
 19378            },
 19379            {
 19380              "license": {
 19381                "id": "ISC"
 19382              }
 19383            },
 19384            {
 19385              "license": {
 19386                "id": "curl"
 19387              }
 19388            },
 19389            {
 19390              "license": {
 19391                "name": "other"
 19392              }
 19393            },
 19394            {
 19395              "license": {
 19396                "name": "public-domain"
 19397              }
 19398            }
 19399          ],
 19400          "cpe": "cpe:2.3:a:libcurl4:libcurl4:7.68.0-1ubuntu2.6:*:*:*:*:*:*:*",
 19401          "purl": "pkg:deb/ubuntu/libcurl4@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04",
 19402          "swid": {
 19403            "attachment": {}
 19404          },
 19405          "pedigree": {},
 19406          "evidence": {},
 19407          "signature": {
 19408            "signature": {
 19409              "publicKey": {}
 19410            }
 19411          },
 19412          "modelCard": {
 19413            "modelParameters": {
 19414              "approach": {}
 19415            },
 19416            "quantitativeAnalysis": {
 19417              "graphics": {}
 19418            },
 19419            "considerations": {}
 19420          }
 19421        },
 19422        {
 19423          "type": "library",
 19424          "bom-ref": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04\u0026package-id=bc84b4da0031640d",
 19425          "supplier": {},
 19426          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19427          "name": "libdb5.3",
 19428          "version": "5.3.28+dfsg1-0.6ubuntu2",
 19429          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.6ubuntu2:*:*:*:*:*:*:*",
 19430          "purl": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04",
 19431          "swid": {
 19432            "attachment": {}
 19433          },
 19434          "pedigree": {},
 19435          "evidence": {},
 19436          "signature": {
 19437            "signature": {
 19438              "publicKey": {}
 19439            }
 19440          },
 19441          "modelCard": {
 19442            "modelParameters": {
 19443              "approach": {}
 19444            },
 19445            "quantitativeAnalysis": {
 19446              "graphics": {}
 19447            },
 19448            "considerations": {}
 19449          }
 19450        },
 19451        {
 19452          "type": "library",
 19453          "bom-ref": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04\u0026package-id=78bbe40d9c2ef9b5",
 19454          "supplier": {},
 19455          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19456          "name": "libdebconfclient0",
 19457          "version": "0.251ubuntu1",
 19458          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.251ubuntu1:*:*:*:*:*:*:*",
 19459          "purl": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04",
 19460          "swid": {
 19461            "attachment": {}
 19462          },
 19463          "pedigree": {},
 19464          "evidence": {},
 19465          "signature": {
 19466            "signature": {
 19467              "publicKey": {}
 19468            }
 19469          },
 19470          "modelCard": {
 19471            "modelParameters": {
 19472              "approach": {}
 19473            },
 19474            "quantitativeAnalysis": {
 19475              "graphics": {}
 19476            },
 19477            "considerations": {}
 19478          }
 19479        },
 19480        {
 19481          "type": "library",
 19482          "bom-ref": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=30b70188951a65f0",
 19483          "supplier": {},
 19484          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19485          "name": "libdevmapper1.02.1",
 19486          "version": "2:1.02.167-1ubuntu1",
 19487          "licenses": [
 19488            {
 19489              "license": {
 19490                "id": "BSD-2-Clause"
 19491              }
 19492            },
 19493            {
 19494              "license": {
 19495                "id": "GPL-2.0-only"
 19496              }
 19497            },
 19498            {
 19499              "license": {
 19500                "id": "GPL-2.0-only"
 19501              }
 19502            },
 19503            {
 19504              "license": {
 19505                "id": "GPL-2.0-or-later"
 19506              }
 19507            },
 19508            {
 19509              "license": {
 19510                "id": "LGPL-2.0-only"
 19511              }
 19512            },
 19513            {
 19514              "license": {
 19515                "id": "LGPL-2.1-only"
 19516              }
 19517            }
 19518          ],
 19519          "cpe": "cpe:2.3:a:libdevmapper1.02.1:libdevmapper1.02.1:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
 19520          "purl": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
 19521          "swid": {
 19522            "attachment": {}
 19523          },
 19524          "pedigree": {},
 19525          "evidence": {},
 19526          "signature": {
 19527            "signature": {
 19528              "publicKey": {}
 19529            }
 19530          },
 19531          "modelCard": {
 19532            "modelParameters": {
 19533              "approach": {}
 19534            },
 19535            "quantitativeAnalysis": {
 19536              "graphics": {}
 19537            },
 19538            "considerations": {}
 19539          }
 19540        },
 19541        {
 19542          "type": "library",
 19543          "bom-ref": "pkg:deb/ubuntu/libedit2@3.1-20191231-1?arch=amd64\u0026upstream=libedit\u0026distro=ubuntu-20.04\u0026package-id=ff7e1552e23080f7",
 19544          "supplier": {},
 19545          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19546          "name": "libedit2",
 19547          "version": "3.1-20191231-1",
 19548          "licenses": [
 19549            {
 19550              "license": {
 19551                "id": "BSD-3-Clause"
 19552              }
 19553            }
 19554          ],
 19555          "cpe": "cpe:2.3:a:libedit2:libedit2:3.1-20191231-1:*:*:*:*:*:*:*",
 19556          "purl": "pkg:deb/ubuntu/libedit2@3.1-20191231-1?arch=amd64\u0026upstream=libedit\u0026distro=ubuntu-20.04",
 19557          "swid": {
 19558            "attachment": {}
 19559          },
 19560          "pedigree": {},
 19561          "evidence": {},
 19562          "signature": {
 19563            "signature": {
 19564              "publicKey": {}
 19565            }
 19566          },
 19567          "modelCard": {
 19568            "modelParameters": {
 19569              "approach": {}
 19570            },
 19571            "quantitativeAnalysis": {
 19572              "graphics": {}
 19573            },
 19574            "considerations": {}
 19575          }
 19576        },
 19577        {
 19578          "type": "library",
 19579          "bom-ref": "pkg:deb/ubuntu/libelf1@0.176-1.1build1?arch=amd64\u0026upstream=elfutils\u0026distro=ubuntu-20.04\u0026package-id=316daaa294f5e8d8",
 19580          "supplier": {},
 19581          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19582          "name": "libelf1",
 19583          "version": "0.176-1.1build1",
 19584          "licenses": [
 19585            {
 19586              "license": {
 19587                "id": "GPL-2.0-only"
 19588              }
 19589            },
 19590            {
 19591              "license": {
 19592                "id": "GPL-3.0-only"
 19593              }
 19594            },
 19595            {
 19596              "license": {
 19597                "name": "LGPL-"
 19598              }
 19599            }
 19600          ],
 19601          "cpe": "cpe:2.3:a:libelf1:libelf1:0.176-1.1build1:*:*:*:*:*:*:*",
 19602          "purl": "pkg:deb/ubuntu/libelf1@0.176-1.1build1?arch=amd64\u0026upstream=elfutils\u0026distro=ubuntu-20.04",
 19603          "swid": {
 19604            "attachment": {}
 19605          },
 19606          "pedigree": {},
 19607          "evidence": {},
 19608          "signature": {
 19609            "signature": {
 19610              "publicKey": {}
 19611            }
 19612          },
 19613          "modelCard": {
 19614            "modelParameters": {
 19615              "approach": {}
 19616            },
 19617            "quantitativeAnalysis": {
 19618              "graphics": {}
 19619            },
 19620            "considerations": {}
 19621          }
 19622        },
 19623        {
 19624          "type": "library",
 19625          "bom-ref": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04\u0026package-id=6b93a7dccfeb49e0",
 19626          "supplier": {},
 19627          "publisher": "Balint Reczey \u003crbalint@ubuntu.com\u003e",
 19628          "name": "libevent-2.1-7",
 19629          "version": "2.1.11-stable-1",
 19630          "licenses": [
 19631            {
 19632              "license": {
 19633                "id": "BSD-2-Clause"
 19634              }
 19635            },
 19636            {
 19637              "license": {
 19638                "name": "BSD-3-Clause~Kitware"
 19639              }
 19640            },
 19641            {
 19642              "license": {
 19643                "id": "BSD-3-Clause"
 19644              }
 19645            },
 19646            {
 19647              "license": {
 19648                "name": "BSL"
 19649              }
 19650            },
 19651            {
 19652              "license": {
 19653                "name": "Expat"
 19654              }
 19655            },
 19656            {
 19657              "license": {
 19658                "id": "FSFUL"
 19659              }
 19660            },
 19661            {
 19662              "license": {
 19663                "id": "FSFULLR"
 19664              }
 19665            },
 19666            {
 19667              "license": {
 19668                "name": "FSFULLR-No-Warranty"
 19669              }
 19670            },
 19671            {
 19672              "license": {
 19673                "id": "GPL-2.0-only"
 19674              }
 19675            },
 19676            {
 19677              "license": {
 19678                "id": "GPL-2.0-or-later"
 19679              }
 19680            },
 19681            {
 19682              "license": {
 19683                "id": "GPL-3.0-only"
 19684              }
 19685            },
 19686            {
 19687              "license": {
 19688                "id": "GPL-3.0-or-later"
 19689              }
 19690            },
 19691            {
 19692              "license": {
 19693                "id": "ISC"
 19694              }
 19695            },
 19696            {
 19697              "license": {
 19698                "id": "curl"
 19699              }
 19700            }
 19701          ],
 19702          "cpe": "cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.11-stable-1:*:*:*:*:*:*:*",
 19703          "purl": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04",
 19704          "swid": {
 19705            "attachment": {}
 19706          },
 19707          "pedigree": {},
 19708          "evidence": {},
 19709          "signature": {
 19710            "signature": {
 19711              "publicKey": {}
 19712            }
 19713          },
 19714          "modelCard": {
 19715            "modelParameters": {
 19716              "approach": {}
 19717            },
 19718            "quantitativeAnalysis": {
 19719              "graphics": {}
 19720            },
 19721            "considerations": {}
 19722          }
 19723        },
 19724        {
 19725          "type": "library",
 19726          "bom-ref": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04\u0026package-id=f3ac75cd161f13c6",
 19727          "supplier": {},
 19728          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19729          "name": "libexpat1",
 19730          "version": "2.2.9-1build1",
 19731          "licenses": [
 19732            {
 19733              "license": {
 19734                "id": "MIT"
 19735              }
 19736            }
 19737          ],
 19738          "cpe": "cpe:2.3:a:libexpat1:libexpat1:2.2.9-1build1:*:*:*:*:*:*:*",
 19739          "purl": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04",
 19740          "swid": {
 19741            "attachment": {}
 19742          },
 19743          "pedigree": {},
 19744          "evidence": {},
 19745          "signature": {
 19746            "signature": {
 19747              "publicKey": {}
 19748            }
 19749          },
 19750          "modelCard": {
 19751            "modelParameters": {
 19752              "approach": {}
 19753            },
 19754            "quantitativeAnalysis": {
 19755              "graphics": {}
 19756            },
 19757            "considerations": {}
 19758          }
 19759        },
 19760        {
 19761          "type": "library",
 19762          "bom-ref": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=ec6113f55e73d1fd",
 19763          "supplier": {},
 19764          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19765          "name": "libext2fs2",
 19766          "version": "1.45.5-2ubuntu1",
 19767          "licenses": [
 19768            {
 19769              "license": {
 19770                "id": "GPL-2.0-only"
 19771              }
 19772            },
 19773            {
 19774              "license": {
 19775                "id": "LGPL-2.0-only"
 19776              }
 19777            }
 19778          ],
 19779          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 19780          "purl": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 19781          "swid": {
 19782            "attachment": {}
 19783          },
 19784          "pedigree": {},
 19785          "evidence": {},
 19786          "signature": {
 19787            "signature": {
 19788              "publicKey": {}
 19789            }
 19790          },
 19791          "modelCard": {
 19792            "modelParameters": {
 19793              "approach": {}
 19794            },
 19795            "quantitativeAnalysis": {
 19796              "graphics": {}
 19797            },
 19798            "considerations": {}
 19799          }
 19800        },
 19801        {
 19802          "type": "library",
 19803          "bom-ref": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=486ce61647644619",
 19804          "supplier": {},
 19805          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19806          "name": "libfdisk1",
 19807          "version": "2.34-0.1ubuntu9.1",
 19808          "licenses": [
 19809            {
 19810              "license": {
 19811                "id": "BSD-2-Clause"
 19812              }
 19813            },
 19814            {
 19815              "license": {
 19816                "id": "BSD-3-Clause"
 19817              }
 19818            },
 19819            {
 19820              "license": {
 19821                "id": "BSD-4-Clause"
 19822              }
 19823            },
 19824            {
 19825              "license": {
 19826                "id": "GPL-2.0-only"
 19827              }
 19828            },
 19829            {
 19830              "license": {
 19831                "id": "GPL-2.0-or-later"
 19832              }
 19833            },
 19834            {
 19835              "license": {
 19836                "id": "GPL-3.0-only"
 19837              }
 19838            },
 19839            {
 19840              "license": {
 19841                "id": "GPL-3.0-or-later"
 19842              }
 19843            },
 19844            {
 19845              "license": {
 19846                "name": "LGPL"
 19847              }
 19848            },
 19849            {
 19850              "license": {
 19851                "id": "LGPL-2.0-only"
 19852              }
 19853            },
 19854            {
 19855              "license": {
 19856                "id": "LGPL-2.0-or-later"
 19857              }
 19858            },
 19859            {
 19860              "license": {
 19861                "id": "LGPL-2.1-only"
 19862              }
 19863            },
 19864            {
 19865              "license": {
 19866                "id": "LGPL-2.1-or-later"
 19867              }
 19868            },
 19869            {
 19870              "license": {
 19871                "id": "LGPL-3.0-only"
 19872              }
 19873            },
 19874            {
 19875              "license": {
 19876                "id": "LGPL-3.0-or-later"
 19877              }
 19878            },
 19879            {
 19880              "license": {
 19881                "id": "MIT"
 19882              }
 19883            },
 19884            {
 19885              "license": {
 19886                "name": "public-domain"
 19887              }
 19888            }
 19889          ],
 19890          "cpe": "cpe:2.3:a:libfdisk1:libfdisk1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 19891          "purl": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 19892          "swid": {
 19893            "attachment": {}
 19894          },
 19895          "pedigree": {},
 19896          "evidence": {},
 19897          "signature": {
 19898            "signature": {
 19899              "publicKey": {}
 19900            }
 19901          },
 19902          "modelCard": {
 19903            "modelParameters": {
 19904              "approach": {}
 19905            },
 19906            "quantitativeAnalysis": {
 19907              "graphics": {}
 19908            },
 19909            "considerations": {}
 19910          }
 19911        },
 19912        {
 19913          "type": "library",
 19914          "bom-ref": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04\u0026package-id=b43b799d45da9d97",
 19915          "supplier": {},
 19916          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19917          "name": "libffi7",
 19918          "version": "3.3-4",
 19919          "licenses": [
 19920            {
 19921              "license": {
 19922                "name": "GPL"
 19923              }
 19924            }
 19925          ],
 19926          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-4:*:*:*:*:*:*:*",
 19927          "purl": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04",
 19928          "swid": {
 19929            "attachment": {}
 19930          },
 19931          "pedigree": {},
 19932          "evidence": {},
 19933          "signature": {
 19934            "signature": {
 19935              "publicKey": {}
 19936            }
 19937          },
 19938          "modelCard": {
 19939            "modelParameters": {
 19940              "approach": {}
 19941            },
 19942            "quantitativeAnalysis": {
 19943              "graphics": {}
 19944            },
 19945            "considerations": {}
 19946          }
 19947        },
 19948        {
 19949          "type": "library",
 19950          "bom-ref": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=f98ce69fd9e55bb8",
 19951          "supplier": {},
 19952          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 19953          "name": "libgcc-s1",
 19954          "version": "10.3.0-1ubuntu1~20.04",
 19955          "licenses": [
 19956            {
 19957              "license": {
 19958                "name": "Artistic"
 19959              }
 19960            },
 19961            {
 19962              "license": {
 19963                "id": "GFDL-1.2-only"
 19964              }
 19965            },
 19966            {
 19967              "license": {
 19968                "name": "GPL"
 19969              }
 19970            },
 19971            {
 19972              "license": {
 19973                "id": "GPL-2.0-only"
 19974              }
 19975            },
 19976            {
 19977              "license": {
 19978                "id": "GPL-3.0-only"
 19979              }
 19980            },
 19981            {
 19982              "license": {
 19983                "name": "LGPL"
 19984              }
 19985            }
 19986          ],
 19987          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
 19988          "purl": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
 19989          "swid": {
 19990            "attachment": {}
 19991          },
 19992          "pedigree": {},
 19993          "evidence": {},
 19994          "signature": {
 19995            "signature": {
 19996              "publicKey": {}
 19997            }
 19998          },
 19999          "modelCard": {
 20000            "modelParameters": {
 20001              "approach": {}
 20002            },
 20003            "quantitativeAnalysis": {
 20004              "graphics": {}
 20005            },
 20006            "considerations": {}
 20007          }
 20008        },
 20009        {
 20010          "type": "library",
 20011          "bom-ref": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=c8a43aa5b28727a1",
 20012          "supplier": {},
 20013          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20014          "name": "libgcrypt20",
 20015          "version": "1.8.5-5ubuntu1",
 20016          "licenses": [
 20017            {
 20018              "license": {
 20019                "id": "GPL-2.0-only"
 20020              }
 20021            },
 20022            {
 20023              "license": {
 20024                "name": "LGPL"
 20025              }
 20026            }
 20027          ],
 20028          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.5-5ubuntu1:*:*:*:*:*:*:*",
 20029          "purl": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 20030          "swid": {
 20031            "attachment": {}
 20032          },
 20033          "pedigree": {},
 20034          "evidence": {},
 20035          "signature": {
 20036            "signature": {
 20037              "publicKey": {}
 20038            }
 20039          },
 20040          "modelCard": {
 20041            "modelParameters": {
 20042              "approach": {}
 20043            },
 20044            "quantitativeAnalysis": {
 20045              "graphics": {}
 20046            },
 20047            "considerations": {}
 20048          }
 20049        },
 20050        {
 20051          "type": "library",
 20052          "bom-ref": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04\u0026package-id=40fc269dcb8b3369",
 20053          "supplier": {},
 20054          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20055          "name": "libgmp10",
 20056          "version": "2:6.2.0+dfsg-4",
 20057          "licenses": [
 20058            {
 20059              "license": {
 20060                "name": "GPL"
 20061              }
 20062            },
 20063            {
 20064              "license": {
 20065                "id": "GPL-2.0-only"
 20066              }
 20067            },
 20068            {
 20069              "license": {
 20070                "id": "GPL-3.0-only"
 20071              }
 20072            },
 20073            {
 20074              "license": {
 20075                "id": "LGPL-3.0-only"
 20076              }
 20077            }
 20078          ],
 20079          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.0\\+dfsg-4:*:*:*:*:*:*:*",
 20080          "purl": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04",
 20081          "swid": {
 20082            "attachment": {}
 20083          },
 20084          "pedigree": {},
 20085          "evidence": {},
 20086          "signature": {
 20087            "signature": {
 20088              "publicKey": {}
 20089            }
 20090          },
 20091          "modelCard": {
 20092            "modelParameters": {
 20093              "approach": {}
 20094            },
 20095            "quantitativeAnalysis": {
 20096              "graphics": {}
 20097            },
 20098            "considerations": {}
 20099          }
 20100        },
 20101        {
 20102          "type": "library",
 20103          "bom-ref": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04\u0026package-id=7490f76da775c6e",
 20104          "supplier": {},
 20105          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20106          "name": "libgnutls30",
 20107          "version": "3.6.13-2ubuntu1.6",
 20108          "licenses": [
 20109            {
 20110              "license": {
 20111                "id": "Apache-2.0"
 20112              }
 20113            },
 20114            {
 20115              "license": {
 20116                "id": "BSD-3-Clause"
 20117              }
 20118            },
 20119            {
 20120              "license": {
 20121                "name": "CC0"
 20122              }
 20123            },
 20124            {
 20125              "license": {
 20126                "name": "Expat"
 20127              }
 20128            },
 20129            {
 20130              "license": {
 20131                "id": "GFDL-1.3-only"
 20132              }
 20133            },
 20134            {
 20135              "license": {
 20136                "name": "GPL"
 20137              }
 20138            },
 20139            {
 20140              "license": {
 20141                "id": "GPL-3.0-only"
 20142              }
 20143            },
 20144            {
 20145              "license": {
 20146                "name": "GPLv3+"
 20147              }
 20148            },
 20149            {
 20150              "license": {
 20151                "name": "LGPL"
 20152              }
 20153            },
 20154            {
 20155              "license": {
 20156                "id": "LGPL-3.0-only"
 20157              }
 20158            },
 20159            {
 20160              "license": {
 20161                "name": "LGPLv2.1+"
 20162              }
 20163            },
 20164            {
 20165              "license": {
 20166                "name": "LGPLv3+_or_GPLv2+"
 20167              }
 20168            },
 20169            {
 20170              "license": {
 20171                "name": "The"
 20172              }
 20173            }
 20174          ],
 20175          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.13-2ubuntu1.6:*:*:*:*:*:*:*",
 20176          "purl": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04",
 20177          "swid": {
 20178            "attachment": {}
 20179          },
 20180          "pedigree": {},
 20181          "evidence": {},
 20182          "signature": {
 20183            "signature": {
 20184              "publicKey": {}
 20185            }
 20186          },
 20187          "modelCard": {
 20188            "modelParameters": {
 20189              "approach": {}
 20190            },
 20191            "quantitativeAnalysis": {
 20192              "graphics": {}
 20193            },
 20194            "considerations": {}
 20195          }
 20196        },
 20197        {
 20198          "type": "library",
 20199          "bom-ref": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04\u0026package-id=37ef62d87edfe03",
 20200          "supplier": {},
 20201          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20202          "name": "libgpg-error0",
 20203          "version": "1.37-1",
 20204          "licenses": [
 20205            {
 20206              "license": {
 20207                "id": "BSD-3-Clause"
 20208              }
 20209            },
 20210            {
 20211              "license": {
 20212                "id": "GPL-3.0-only"
 20213              }
 20214            },
 20215            {
 20216              "license": {
 20217                "id": "GPL-3.0-or-later"
 20218              }
 20219            },
 20220            {
 20221              "license": {
 20222                "id": "LGPL-2.1-only"
 20223              }
 20224            },
 20225            {
 20226              "license": {
 20227                "id": "LGPL-2.1-or-later"
 20228              }
 20229            },
 20230            {
 20231              "license": {
 20232                "name": "g10-permissive"
 20233              }
 20234            }
 20235          ],
 20236          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.37-1:*:*:*:*:*:*:*",
 20237          "purl": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04",
 20238          "swid": {
 20239            "attachment": {}
 20240          },
 20241          "pedigree": {},
 20242          "evidence": {},
 20243          "signature": {
 20244            "signature": {
 20245              "publicKey": {}
 20246            }
 20247          },
 20248          "modelCard": {
 20249            "modelParameters": {
 20250              "approach": {}
 20251            },
 20252            "quantitativeAnalysis": {
 20253              "graphics": {}
 20254            },
 20255            "considerations": {}
 20256          }
 20257        },
 20258        {
 20259          "type": "library",
 20260          "bom-ref": "pkg:deb/ubuntu/libgpm2@1.20.7-5?arch=amd64\u0026upstream=gpm\u0026distro=ubuntu-20.04\u0026package-id=10dc077f92e6ffa8",
 20261          "supplier": {},
 20262          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20263          "name": "libgpm2",
 20264          "version": "1.20.7-5",
 20265          "licenses": [
 20266            {
 20267              "license": {
 20268                "id": "GPL-2.0-only"
 20269              }
 20270            },
 20271            {
 20272              "license": {
 20273                "id": "GPL-2.0-or-later"
 20274              }
 20275            },
 20276            {
 20277              "license": {
 20278                "id": "GPL-3.0-only"
 20279              }
 20280            },
 20281            {
 20282              "license": {
 20283                "id": "GPL-3.0-or-later"
 20284              }
 20285            }
 20286          ],
 20287          "cpe": "cpe:2.3:a:libgpm2:libgpm2:1.20.7-5:*:*:*:*:*:*:*",
 20288          "purl": "pkg:deb/ubuntu/libgpm2@1.20.7-5?arch=amd64\u0026upstream=gpm\u0026distro=ubuntu-20.04",
 20289          "swid": {
 20290            "attachment": {}
 20291          },
 20292          "pedigree": {},
 20293          "evidence": {},
 20294          "signature": {
 20295            "signature": {
 20296              "publicKey": {}
 20297            }
 20298          },
 20299          "modelCard": {
 20300            "modelParameters": {
 20301              "approach": {}
 20302            },
 20303            "quantitativeAnalysis": {
 20304              "graphics": {}
 20305            },
 20306            "considerations": {}
 20307          }
 20308        },
 20309        {
 20310          "type": "library",
 20311          "bom-ref": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=443eafe2785f5a4c",
 20312          "supplier": {},
 20313          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20314          "name": "libgssapi-krb5-2",
 20315          "version": "1.17-6ubuntu4.1",
 20316          "licenses": [
 20317            {
 20318              "license": {
 20319                "id": "GPL-2.0-only"
 20320              }
 20321            }
 20322          ],
 20323          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 20324          "purl": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 20325          "swid": {
 20326            "attachment": {}
 20327          },
 20328          "pedigree": {},
 20329          "evidence": {},
 20330          "signature": {
 20331            "signature": {
 20332              "publicKey": {}
 20333            }
 20334          },
 20335          "modelCard": {
 20336            "modelParameters": {
 20337              "approach": {}
 20338            },
 20339            "quantitativeAnalysis": {
 20340              "graphics": {}
 20341            },
 20342            "considerations": {}
 20343          }
 20344        },
 20345        {
 20346          "type": "library",
 20347          "bom-ref": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=17a37cca2446b615",
 20348          "supplier": {},
 20349          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20350          "name": "libgssapi3-heimdal",
 20351          "version": "7.7.0+dfsg-1ubuntu1",
 20352          "licenses": [
 20353            {
 20354              "license": {
 20355                "id": "BSD-3-Clause"
 20356              }
 20357            },
 20358            {
 20359              "license": {
 20360                "id": "GPL-2.0-only"
 20361              }
 20362            },
 20363            {
 20364              "license": {
 20365                "id": "GPL-2.0-or-later"
 20366              }
 20367            },
 20368            {
 20369              "license": {
 20370                "name": "custom"
 20371              }
 20372            }
 20373          ],
 20374          "cpe": "cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 20375          "purl": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 20376          "swid": {
 20377            "attachment": {}
 20378          },
 20379          "pedigree": {},
 20380          "evidence": {},
 20381          "signature": {
 20382            "signature": {
 20383              "publicKey": {}
 20384            }
 20385          },
 20386          "modelCard": {
 20387            "modelParameters": {
 20388              "approach": {}
 20389            },
 20390            "quantitativeAnalysis": {
 20391              "graphics": {}
 20392            },
 20393            "considerations": {}
 20394          }
 20395        },
 20396        {
 20397          "type": "library",
 20398          "bom-ref": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=98098d582df76b44",
 20399          "supplier": {},
 20400          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20401          "name": "libhcrypto4-heimdal",
 20402          "version": "7.7.0+dfsg-1ubuntu1",
 20403          "licenses": [
 20404            {
 20405              "license": {
 20406                "id": "BSD-3-Clause"
 20407              }
 20408            },
 20409            {
 20410              "license": {
 20411                "id": "GPL-2.0-only"
 20412              }
 20413            },
 20414            {
 20415              "license": {
 20416                "id": "GPL-2.0-or-later"
 20417              }
 20418            },
 20419            {
 20420              "license": {
 20421                "name": "custom"
 20422              }
 20423            }
 20424          ],
 20425          "cpe": "cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 20426          "purl": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 20427          "swid": {
 20428            "attachment": {}
 20429          },
 20430          "pedigree": {},
 20431          "evidence": {},
 20432          "signature": {
 20433            "signature": {
 20434              "publicKey": {}
 20435            }
 20436          },
 20437          "modelCard": {
 20438            "modelParameters": {
 20439              "approach": {}
 20440            },
 20441            "quantitativeAnalysis": {
 20442              "graphics": {}
 20443            },
 20444            "considerations": {}
 20445          }
 20446        },
 20447        {
 20448          "type": "library",
 20449          "bom-ref": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=f8dfc9a84c337835",
 20450          "supplier": {},
 20451          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20452          "name": "libheimbase1-heimdal",
 20453          "version": "7.7.0+dfsg-1ubuntu1",
 20454          "licenses": [
 20455            {
 20456              "license": {
 20457                "id": "BSD-3-Clause"
 20458              }
 20459            },
 20460            {
 20461              "license": {
 20462                "id": "GPL-2.0-only"
 20463              }
 20464            },
 20465            {
 20466              "license": {
 20467                "id": "GPL-2.0-or-later"
 20468              }
 20469            },
 20470            {
 20471              "license": {
 20472                "name": "custom"
 20473              }
 20474            }
 20475          ],
 20476          "cpe": "cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 20477          "purl": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 20478          "swid": {
 20479            "attachment": {}
 20480          },
 20481          "pedigree": {},
 20482          "evidence": {},
 20483          "signature": {
 20484            "signature": {
 20485              "publicKey": {}
 20486            }
 20487          },
 20488          "modelCard": {
 20489            "modelParameters": {
 20490              "approach": {}
 20491            },
 20492            "quantitativeAnalysis": {
 20493              "graphics": {}
 20494            },
 20495            "considerations": {}
 20496          }
 20497        },
 20498        {
 20499          "type": "library",
 20500          "bom-ref": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=9992d88ac7d6e8e3",
 20501          "supplier": {},
 20502          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20503          "name": "libheimntlm0-heimdal",
 20504          "version": "7.7.0+dfsg-1ubuntu1",
 20505          "licenses": [
 20506            {
 20507              "license": {
 20508                "id": "BSD-3-Clause"
 20509              }
 20510            },
 20511            {
 20512              "license": {
 20513                "id": "GPL-2.0-only"
 20514              }
 20515            },
 20516            {
 20517              "license": {
 20518                "id": "GPL-2.0-or-later"
 20519              }
 20520            },
 20521            {
 20522              "license": {
 20523                "name": "custom"
 20524              }
 20525            }
 20526          ],
 20527          "cpe": "cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 20528          "purl": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 20529          "swid": {
 20530            "attachment": {}
 20531          },
 20532          "pedigree": {},
 20533          "evidence": {},
 20534          "signature": {
 20535            "signature": {
 20536              "publicKey": {}
 20537            }
 20538          },
 20539          "modelCard": {
 20540            "modelParameters": {
 20541              "approach": {}
 20542            },
 20543            "quantitativeAnalysis": {
 20544              "graphics": {}
 20545            },
 20546            "considerations": {}
 20547          }
 20548        },
 20549        {
 20550          "type": "library",
 20551          "bom-ref": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3caecccf070e6760",
 20552          "supplier": {},
 20553          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20554          "name": "libhogweed5",
 20555          "version": "3.5.1+really3.5.1-2ubuntu0.2",
 20556          "licenses": [
 20557            {
 20558              "license": {
 20559                "name": "GAP"
 20560              }
 20561            },
 20562            {
 20563              "license": {
 20564                "name": "GPL"
 20565              }
 20566            },
 20567            {
 20568              "license": {
 20569                "id": "GPL-2.0-only"
 20570              }
 20571            },
 20572            {
 20573              "license": {
 20574                "id": "GPL-2.0-or-later"
 20575              }
 20576            },
 20577            {
 20578              "license": {
 20579                "name": "LGPL"
 20580              }
 20581            },
 20582            {
 20583              "license": {
 20584                "id": "LGPL-2.0-only"
 20585              }
 20586            },
 20587            {
 20588              "license": {
 20589                "id": "LGPL-2.0-or-later"
 20590              }
 20591            },
 20592            {
 20593              "license": {
 20594                "id": "LGPL-2.1-or-later"
 20595              }
 20596            },
 20597            {
 20598              "license": {
 20599                "name": "other"
 20600              }
 20601            },
 20602            {
 20603              "license": {
 20604                "name": "public-domain"
 20605              }
 20606            }
 20607          ],
 20608          "cpe": "cpe:2.3:a:libhogweed5:libhogweed5:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
 20609          "purl": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
 20610          "swid": {
 20611            "attachment": {}
 20612          },
 20613          "pedigree": {},
 20614          "evidence": {},
 20615          "signature": {
 20616            "signature": {
 20617              "publicKey": {}
 20618            }
 20619          },
 20620          "modelCard": {
 20621            "modelParameters": {
 20622              "approach": {}
 20623            },
 20624            "quantitativeAnalysis": {
 20625              "graphics": {}
 20626            },
 20627            "considerations": {}
 20628          }
 20629        },
 20630        {
 20631          "type": "library",
 20632          "bom-ref": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=3b0bac5e4e8f23c5",
 20633          "supplier": {},
 20634          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20635          "name": "libhx509-5-heimdal",
 20636          "version": "7.7.0+dfsg-1ubuntu1",
 20637          "licenses": [
 20638            {
 20639              "license": {
 20640                "id": "BSD-3-Clause"
 20641              }
 20642            },
 20643            {
 20644              "license": {
 20645                "id": "GPL-2.0-only"
 20646              }
 20647            },
 20648            {
 20649              "license": {
 20650                "id": "GPL-2.0-or-later"
 20651              }
 20652            },
 20653            {
 20654              "license": {
 20655                "name": "custom"
 20656              }
 20657            }
 20658          ],
 20659          "cpe": "cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 20660          "purl": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 20661          "swid": {
 20662            "attachment": {}
 20663          },
 20664          "pedigree": {},
 20665          "evidence": {},
 20666          "signature": {
 20667            "signature": {
 20668              "publicKey": {}
 20669            }
 20670          },
 20671          "modelCard": {
 20672            "modelParameters": {
 20673              "approach": {}
 20674            },
 20675            "quantitativeAnalysis": {
 20676              "graphics": {}
 20677            },
 20678            "considerations": {}
 20679          }
 20680        },
 20681        {
 20682          "type": "library",
 20683          "bom-ref": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04\u0026package-id=bcf598a9dea4cd38",
 20684          "supplier": {},
 20685          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20686          "name": "libicu66",
 20687          "version": "66.1-2ubuntu2",
 20688          "cpe": "cpe:2.3:a:libicu66:libicu66:66.1-2ubuntu2:*:*:*:*:*:*:*",
 20689          "purl": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04",
 20690          "swid": {
 20691            "attachment": {}
 20692          },
 20693          "pedigree": {},
 20694          "evidence": {},
 20695          "signature": {
 20696            "signature": {
 20697              "publicKey": {}
 20698            }
 20699          },
 20700          "modelCard": {
 20701            "modelParameters": {
 20702              "approach": {}
 20703            },
 20704            "quantitativeAnalysis": {
 20705              "graphics": {}
 20706            },
 20707            "considerations": {}
 20708          }
 20709        },
 20710        {
 20711          "type": "library",
 20712          "bom-ref": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04\u0026package-id=d2a82c3e28413bc1",
 20713          "supplier": {},
 20714          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20715          "name": "libidn2-0",
 20716          "version": "2.2.0-2",
 20717          "licenses": [
 20718            {
 20719              "license": {
 20720                "id": "GPL-2.0-only"
 20721              }
 20722            },
 20723            {
 20724              "license": {
 20725                "id": "GPL-2.0-or-later"
 20726              }
 20727            },
 20728            {
 20729              "license": {
 20730                "id": "GPL-3.0-only"
 20731              }
 20732            },
 20733            {
 20734              "license": {
 20735                "id": "GPL-3.0-or-later"
 20736              }
 20737            },
 20738            {
 20739              "license": {
 20740                "id": "LGPL-3.0-only"
 20741              }
 20742            },
 20743            {
 20744              "license": {
 20745                "id": "LGPL-3.0-or-later"
 20746              }
 20747            },
 20748            {
 20749              "license": {
 20750                "name": "Unicode"
 20751              }
 20752            }
 20753          ],
 20754          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.2.0-2:*:*:*:*:*:*:*",
 20755          "purl": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04",
 20756          "swid": {
 20757            "attachment": {}
 20758          },
 20759          "pedigree": {},
 20760          "evidence": {},
 20761          "signature": {
 20762            "signature": {
 20763              "publicKey": {}
 20764            }
 20765          },
 20766          "modelCard": {
 20767            "modelParameters": {
 20768              "approach": {}
 20769            },
 20770            "quantitativeAnalysis": {
 20771              "graphics": {}
 20772            },
 20773            "considerations": {}
 20774          }
 20775        },
 20776        {
 20777          "type": "library",
 20778          "bom-ref": "pkg:deb/ubuntu/libjson-c4@0.13.1+dfsg-7ubuntu0.3?arch=amd64\u0026upstream=json-c\u0026distro=ubuntu-20.04\u0026package-id=909fcb74540ccf31",
 20779          "supplier": {},
 20780          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20781          "name": "libjson-c4",
 20782          "version": "0.13.1+dfsg-7ubuntu0.3",
 20783          "licenses": [
 20784            {
 20785              "license": {
 20786                "name": "Expat"
 20787              }
 20788            }
 20789          ],
 20790          "cpe": "cpe:2.3:a:libjson-c4:libjson-c4:0.13.1\\+dfsg-7ubuntu0.3:*:*:*:*:*:*:*",
 20791          "purl": "pkg:deb/ubuntu/libjson-c4@0.13.1+dfsg-7ubuntu0.3?arch=amd64\u0026upstream=json-c\u0026distro=ubuntu-20.04",
 20792          "swid": {
 20793            "attachment": {}
 20794          },
 20795          "pedigree": {},
 20796          "evidence": {},
 20797          "signature": {
 20798            "signature": {
 20799              "publicKey": {}
 20800            }
 20801          },
 20802          "modelCard": {
 20803            "modelParameters": {
 20804              "approach": {}
 20805            },
 20806            "quantitativeAnalysis": {
 20807              "graphics": {}
 20808            },
 20809            "considerations": {}
 20810          }
 20811        },
 20812        {
 20813          "type": "library",
 20814          "bom-ref": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=f9479050b59432b4",
 20815          "supplier": {},
 20816          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20817          "name": "libk5crypto3",
 20818          "version": "1.17-6ubuntu4.1",
 20819          "licenses": [
 20820            {
 20821              "license": {
 20822                "id": "GPL-2.0-only"
 20823              }
 20824            }
 20825          ],
 20826          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 20827          "purl": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 20828          "swid": {
 20829            "attachment": {}
 20830          },
 20831          "pedigree": {},
 20832          "evidence": {},
 20833          "signature": {
 20834            "signature": {
 20835              "publicKey": {}
 20836            }
 20837          },
 20838          "modelCard": {
 20839            "modelParameters": {
 20840              "approach": {}
 20841            },
 20842            "quantitativeAnalysis": {
 20843              "graphics": {}
 20844            },
 20845            "considerations": {}
 20846          }
 20847        },
 20848        {
 20849          "type": "library",
 20850          "bom-ref": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04\u0026package-id=e8692427b123ea73",
 20851          "supplier": {},
 20852          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20853          "name": "libkeyutils1",
 20854          "version": "1.6-6ubuntu1",
 20855          "licenses": [
 20856            {
 20857              "license": {
 20858                "id": "GPL-2.0-only"
 20859              }
 20860            },
 20861            {
 20862              "license": {
 20863                "id": "GPL-2.0-or-later"
 20864              }
 20865            },
 20866            {
 20867              "license": {
 20868                "id": "LGPL-2.0-only"
 20869              }
 20870            },
 20871            {
 20872              "license": {
 20873                "id": "LGPL-2.0-or-later"
 20874              }
 20875            }
 20876          ],
 20877          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6-6ubuntu1:*:*:*:*:*:*:*",
 20878          "purl": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04",
 20879          "swid": {
 20880            "attachment": {}
 20881          },
 20882          "pedigree": {},
 20883          "evidence": {},
 20884          "signature": {
 20885            "signature": {
 20886              "publicKey": {}
 20887            }
 20888          },
 20889          "modelCard": {
 20890            "modelParameters": {
 20891              "approach": {}
 20892            },
 20893            "quantitativeAnalysis": {
 20894              "graphics": {}
 20895            },
 20896            "considerations": {}
 20897          }
 20898        },
 20899        {
 20900          "type": "library",
 20901          "bom-ref": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=2beb670b9378498e",
 20902          "supplier": {},
 20903          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20904          "name": "libkrb5-26-heimdal",
 20905          "version": "7.7.0+dfsg-1ubuntu1",
 20906          "licenses": [
 20907            {
 20908              "license": {
 20909                "id": "BSD-3-Clause"
 20910              }
 20911            },
 20912            {
 20913              "license": {
 20914                "id": "GPL-2.0-only"
 20915              }
 20916            },
 20917            {
 20918              "license": {
 20919                "id": "GPL-2.0-or-later"
 20920              }
 20921            },
 20922            {
 20923              "license": {
 20924                "name": "custom"
 20925              }
 20926            }
 20927          ],
 20928          "cpe": "cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 20929          "purl": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 20930          "swid": {
 20931            "attachment": {}
 20932          },
 20933          "pedigree": {},
 20934          "evidence": {},
 20935          "signature": {
 20936            "signature": {
 20937              "publicKey": {}
 20938            }
 20939          },
 20940          "modelCard": {
 20941            "modelParameters": {
 20942              "approach": {}
 20943            },
 20944            "quantitativeAnalysis": {
 20945              "graphics": {}
 20946            },
 20947            "considerations": {}
 20948          }
 20949        },
 20950        {
 20951          "type": "library",
 20952          "bom-ref": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=fdb5970d8394a182",
 20953          "supplier": {},
 20954          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20955          "name": "libkrb5-3",
 20956          "version": "1.17-6ubuntu4.1",
 20957          "licenses": [
 20958            {
 20959              "license": {
 20960                "id": "GPL-2.0-only"
 20961              }
 20962            }
 20963          ],
 20964          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 20965          "purl": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 20966          "swid": {
 20967            "attachment": {}
 20968          },
 20969          "pedigree": {},
 20970          "evidence": {},
 20971          "signature": {
 20972            "signature": {
 20973              "publicKey": {}
 20974            }
 20975          },
 20976          "modelCard": {
 20977            "modelParameters": {
 20978              "approach": {}
 20979            },
 20980            "quantitativeAnalysis": {
 20981              "graphics": {}
 20982            },
 20983            "considerations": {}
 20984          }
 20985        },
 20986        {
 20987          "type": "library",
 20988          "bom-ref": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=a8d21a32e178b211",
 20989          "supplier": {},
 20990          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 20991          "name": "libkrb5support0",
 20992          "version": "1.17-6ubuntu4.1",
 20993          "licenses": [
 20994            {
 20995              "license": {
 20996                "id": "GPL-2.0-only"
 20997              }
 20998            }
 20999          ],
 21000          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 21001          "purl": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 21002          "swid": {
 21003            "attachment": {}
 21004          },
 21005          "pedigree": {},
 21006          "evidence": {},
 21007          "signature": {
 21008            "signature": {
 21009              "publicKey": {}
 21010            }
 21011          },
 21012          "modelCard": {
 21013            "modelParameters": {
 21014              "approach": {}
 21015            },
 21016            "quantitativeAnalysis": {
 21017              "graphics": {}
 21018            },
 21019            "considerations": {}
 21020          }
 21021        },
 21022        {
 21023          "type": "library",
 21024          "bom-ref": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=efdc80a7ae6eae19",
 21025          "supplier": {},
 21026          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21027          "name": "libldap-2.4-2",
 21028          "version": "2.4.49+dfsg-2ubuntu1.8",
 21029          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
 21030          "purl": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04",
 21031          "swid": {
 21032            "attachment": {}
 21033          },
 21034          "pedigree": {},
 21035          "evidence": {},
 21036          "signature": {
 21037            "signature": {
 21038              "publicKey": {}
 21039            }
 21040          },
 21041          "modelCard": {
 21042            "modelParameters": {
 21043              "approach": {}
 21044            },
 21045            "quantitativeAnalysis": {
 21046              "graphics": {}
 21047            },
 21048            "considerations": {}
 21049          }
 21050        },
 21051        {
 21052          "type": "library",
 21053          "bom-ref": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=4d0b88f98b40786b",
 21054          "supplier": {},
 21055          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21056          "name": "libldap-common",
 21057          "version": "2.4.49+dfsg-2ubuntu1.8",
 21058          "cpe": "cpe:2.3:a:libldap-common:libldap-common:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
 21059          "purl": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04",
 21060          "swid": {
 21061            "attachment": {}
 21062          },
 21063          "pedigree": {},
 21064          "evidence": {},
 21065          "signature": {
 21066            "signature": {
 21067              "publicKey": {}
 21068            }
 21069          },
 21070          "modelCard": {
 21071            "modelParameters": {
 21072              "approach": {}
 21073            },
 21074            "quantitativeAnalysis": {
 21075              "graphics": {}
 21076            },
 21077            "considerations": {}
 21078          }
 21079        },
 21080        {
 21081          "type": "library",
 21082          "bom-ref": "pkg:deb/ubuntu/liblmdb0@0.9.24-1?arch=amd64\u0026upstream=lmdb\u0026distro=ubuntu-20.04\u0026package-id=71e23b84a5f4e340",
 21083          "supplier": {},
 21084          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21085          "name": "liblmdb0",
 21086          "version": "0.9.24-1",
 21087          "licenses": [
 21088            {
 21089              "license": {
 21090                "name": "OpenLDAP-2.8"
 21091              }
 21092            }
 21093          ],
 21094          "cpe": "cpe:2.3:a:liblmdb0:liblmdb0:0.9.24-1:*:*:*:*:*:*:*",
 21095          "purl": "pkg:deb/ubuntu/liblmdb0@0.9.24-1?arch=amd64\u0026upstream=lmdb\u0026distro=ubuntu-20.04",
 21096          "swid": {
 21097            "attachment": {}
 21098          },
 21099          "pedigree": {},
 21100          "evidence": {},
 21101          "signature": {
 21102            "signature": {
 21103              "publicKey": {}
 21104            }
 21105          },
 21106          "modelCard": {
 21107            "modelParameters": {
 21108              "approach": {}
 21109            },
 21110            "quantitativeAnalysis": {
 21111              "graphics": {}
 21112            },
 21113            "considerations": {}
 21114          }
 21115        },
 21116        {
 21117          "type": "library",
 21118          "bom-ref": "pkg:deb/ubuntu/libltdl7@2.4.6-14?arch=amd64\u0026upstream=libtool\u0026distro=ubuntu-20.04\u0026package-id=1b90fab6296ba661",
 21119          "supplier": {},
 21120          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21121          "name": "libltdl7",
 21122          "version": "2.4.6-14",
 21123          "licenses": [
 21124            {
 21125              "license": {
 21126                "name": "GFDL"
 21127              }
 21128            },
 21129            {
 21130              "license": {
 21131                "name": "GPL"
 21132              }
 21133            }
 21134          ],
 21135          "cpe": "cpe:2.3:a:libltdl7:libltdl7:2.4.6-14:*:*:*:*:*:*:*",
 21136          "purl": "pkg:deb/ubuntu/libltdl7@2.4.6-14?arch=amd64\u0026upstream=libtool\u0026distro=ubuntu-20.04",
 21137          "swid": {
 21138            "attachment": {}
 21139          },
 21140          "pedigree": {},
 21141          "evidence": {},
 21142          "signature": {
 21143            "signature": {
 21144              "publicKey": {}
 21145            }
 21146          },
 21147          "modelCard": {
 21148            "modelParameters": {
 21149              "approach": {}
 21150            },
 21151            "quantitativeAnalysis": {
 21152              "graphics": {}
 21153            },
 21154            "considerations": {}
 21155          }
 21156        },
 21157        {
 21158          "type": "library",
 21159          "bom-ref": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04\u0026package-id=6f2c431caeb4980a",
 21160          "supplier": {},
 21161          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21162          "name": "liblz4-1",
 21163          "version": "1.9.2-2ubuntu0.20.04.1",
 21164          "licenses": [
 21165            {
 21166              "license": {
 21167                "id": "BSD-2-Clause"
 21168              }
 21169            },
 21170            {
 21171              "license": {
 21172                "id": "GPL-2.0-only"
 21173              }
 21174            },
 21175            {
 21176              "license": {
 21177                "id": "GPL-2.0-or-later"
 21178              }
 21179            }
 21180          ],
 21181          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.2-2ubuntu0.20.04.1:*:*:*:*:*:*:*",
 21182          "purl": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04",
 21183          "swid": {
 21184            "attachment": {}
 21185          },
 21186          "pedigree": {},
 21187          "evidence": {},
 21188          "signature": {
 21189            "signature": {
 21190              "publicKey": {}
 21191            }
 21192          },
 21193          "modelCard": {
 21194            "modelParameters": {
 21195              "approach": {}
 21196            },
 21197            "quantitativeAnalysis": {
 21198              "graphics": {}
 21199            },
 21200            "considerations": {}
 21201          }
 21202        },
 21203        {
 21204          "type": "library",
 21205          "bom-ref": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04\u0026package-id=f1e9f3b6205a664a",
 21206          "supplier": {},
 21207          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21208          "name": "liblzma5",
 21209          "version": "5.2.4-1ubuntu1",
 21210          "licenses": [
 21211            {
 21212              "license": {
 21213                "name": "Autoconf"
 21214              }
 21215            },
 21216            {
 21217              "license": {
 21218                "id": "GPL-2.0-only"
 21219              }
 21220            },
 21221            {
 21222              "license": {
 21223                "id": "GPL-2.0-or-later"
 21224              }
 21225            },
 21226            {
 21227              "license": {
 21228                "id": "GPL-3.0-only"
 21229              }
 21230            },
 21231            {
 21232              "license": {
 21233                "id": "LGPL-2.0-only"
 21234              }
 21235            },
 21236            {
 21237              "license": {
 21238                "id": "LGPL-2.1-only"
 21239              }
 21240            },
 21241            {
 21242              "license": {
 21243                "id": "LGPL-2.1-or-later"
 21244              }
 21245            },
 21246            {
 21247              "license": {
 21248                "name": "PD"
 21249              }
 21250            },
 21251            {
 21252              "license": {
 21253                "name": "PD-debian"
 21254              }
 21255            },
 21256            {
 21257              "license": {
 21258                "name": "config-h"
 21259              }
 21260            },
 21261            {
 21262              "license": {
 21263                "name": "noderivs"
 21264              }
 21265            },
 21266            {
 21267              "license": {
 21268                "name": "permissive-fsf"
 21269              }
 21270            },
 21271            {
 21272              "license": {
 21273                "name": "permissive-nowarranty"
 21274              }
 21275            },
 21276            {
 21277              "license": {
 21278                "name": "probably-PD"
 21279              }
 21280            }
 21281          ],
 21282          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
 21283          "purl": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04",
 21284          "swid": {
 21285            "attachment": {}
 21286          },
 21287          "pedigree": {},
 21288          "evidence": {},
 21289          "signature": {
 21290            "signature": {
 21291              "publicKey": {}
 21292            }
 21293          },
 21294          "modelCard": {
 21295            "modelParameters": {
 21296              "approach": {}
 21297            },
 21298            "quantitativeAnalysis": {
 21299              "graphics": {}
 21300            },
 21301            "considerations": {}
 21302          }
 21303        },
 21304        {
 21305          "type": "library",
 21306          "bom-ref": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=3b4f02792ccf99bb",
 21307          "supplier": {},
 21308          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21309          "name": "libmagic-mgc",
 21310          "version": "1:5.38-4",
 21311          "licenses": [
 21312            {
 21313              "license": {
 21314                "name": "BSD-2-Clause-alike"
 21315              }
 21316            },
 21317            {
 21318              "license": {
 21319                "id": "BSD-2-Clause"
 21320              }
 21321            },
 21322            {
 21323              "license": {
 21324                "name": "BSD-2-Clause-regents"
 21325              }
 21326            },
 21327            {
 21328              "license": {
 21329                "name": "MIT-Old-Style-with-legal-disclaimer-2"
 21330              }
 21331            },
 21332            {
 21333              "license": {
 21334                "name": "public-domain"
 21335              }
 21336            }
 21337          ],
 21338          "cpe": "cpe:2.3:a:libmagic-mgc:libmagic-mgc:1\\:5.38-4:*:*:*:*:*:*:*",
 21339          "purl": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
 21340          "swid": {
 21341            "attachment": {}
 21342          },
 21343          "pedigree": {},
 21344          "evidence": {},
 21345          "signature": {
 21346            "signature": {
 21347              "publicKey": {}
 21348            }
 21349          },
 21350          "modelCard": {
 21351            "modelParameters": {
 21352              "approach": {}
 21353            },
 21354            "quantitativeAnalysis": {
 21355              "graphics": {}
 21356            },
 21357            "considerations": {}
 21358          }
 21359        },
 21360        {
 21361          "type": "library",
 21362          "bom-ref": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=302b8497a938556",
 21363          "supplier": {},
 21364          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21365          "name": "libmagic1",
 21366          "version": "1:5.38-4",
 21367          "licenses": [
 21368            {
 21369              "license": {
 21370                "name": "BSD-2-Clause-alike"
 21371              }
 21372            },
 21373            {
 21374              "license": {
 21375                "id": "BSD-2-Clause"
 21376              }
 21377            },
 21378            {
 21379              "license": {
 21380                "name": "BSD-2-Clause-regents"
 21381              }
 21382            },
 21383            {
 21384              "license": {
 21385                "name": "MIT-Old-Style-with-legal-disclaimer-2"
 21386              }
 21387            },
 21388            {
 21389              "license": {
 21390                "name": "public-domain"
 21391              }
 21392            }
 21393          ],
 21394          "cpe": "cpe:2.3:a:libmagic1:libmagic1:1\\:5.38-4:*:*:*:*:*:*:*",
 21395          "purl": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
 21396          "swid": {
 21397            "attachment": {}
 21398          },
 21399          "pedigree": {},
 21400          "evidence": {},
 21401          "signature": {
 21402            "signature": {
 21403              "publicKey": {}
 21404            }
 21405          },
 21406          "modelCard": {
 21407            "modelParameters": {
 21408              "approach": {}
 21409            },
 21410            "quantitativeAnalysis": {
 21411              "graphics": {}
 21412            },
 21413            "considerations": {}
 21414          }
 21415        },
 21416        {
 21417          "type": "library",
 21418          "bom-ref": "pkg:deb/ubuntu/libmaxminddb0@1.4.2-0ubuntu1.20.04.1?arch=amd64\u0026upstream=libmaxminddb\u0026distro=ubuntu-20.04\u0026package-id=e918b9e4e403338f",
 21419          "supplier": {},
 21420          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21421          "name": "libmaxminddb0",
 21422          "version": "1.4.2-0ubuntu1.20.04.1",
 21423          "licenses": [
 21424            {
 21425              "license": {
 21426                "id": "Apache-2.0"
 21427              }
 21428            },
 21429            {
 21430              "license": {
 21431                "id": "BSD-2-Clause"
 21432              }
 21433            },
 21434            {
 21435              "license": {
 21436                "name": "CC-BY-SA"
 21437              }
 21438            },
 21439            {
 21440              "license": {
 21441                "name": "GPL"
 21442              }
 21443            },
 21444            {
 21445              "license": {
 21446                "id": "GPL-2.0-or-later"
 21447              }
 21448            }
 21449          ],
 21450          "cpe": "cpe:2.3:a:libmaxminddb0:libmaxminddb0:1.4.2-0ubuntu1.20.04.1:*:*:*:*:*:*:*",
 21451          "purl": "pkg:deb/ubuntu/libmaxminddb0@1.4.2-0ubuntu1.20.04.1?arch=amd64\u0026upstream=libmaxminddb\u0026distro=ubuntu-20.04",
 21452          "swid": {
 21453            "attachment": {}
 21454          },
 21455          "pedigree": {},
 21456          "evidence": {},
 21457          "signature": {
 21458            "signature": {
 21459              "publicKey": {}
 21460            }
 21461          },
 21462          "modelCard": {
 21463            "modelParameters": {
 21464              "approach": {}
 21465            },
 21466            "quantitativeAnalysis": {
 21467              "graphics": {}
 21468            },
 21469            "considerations": {}
 21470          }
 21471        },
 21472        {
 21473          "type": "library",
 21474          "bom-ref": "pkg:deb/ubuntu/libmnl0@1.0.4-2?arch=amd64\u0026upstream=libmnl\u0026distro=ubuntu-20.04\u0026package-id=162cfe25074edf0d",
 21475          "supplier": {},
 21476          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21477          "name": "libmnl0",
 21478          "version": "1.0.4-2",
 21479          "licenses": [
 21480            {
 21481              "license": {
 21482                "id": "GPL-2.0-only"
 21483              }
 21484            },
 21485            {
 21486              "license": {
 21487                "id": "GPL-2.0-or-later"
 21488              }
 21489            },
 21490            {
 21491              "license": {
 21492                "id": "LGPL-2.1-only"
 21493              }
 21494            }
 21495          ],
 21496          "cpe": "cpe:2.3:a:libmnl0:libmnl0:1.0.4-2:*:*:*:*:*:*:*",
 21497          "purl": "pkg:deb/ubuntu/libmnl0@1.0.4-2?arch=amd64\u0026upstream=libmnl\u0026distro=ubuntu-20.04",
 21498          "swid": {
 21499            "attachment": {}
 21500          },
 21501          "pedigree": {},
 21502          "evidence": {},
 21503          "signature": {
 21504            "signature": {
 21505              "publicKey": {}
 21506            }
 21507          },
 21508          "modelCard": {
 21509            "modelParameters": {
 21510              "approach": {}
 21511            },
 21512            "quantitativeAnalysis": {
 21513              "graphics": {}
 21514            },
 21515            "considerations": {}
 21516          }
 21517        },
 21518        {
 21519          "type": "library",
 21520          "bom-ref": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=39446194385ebce5",
 21521          "supplier": {},
 21522          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21523          "name": "libmount1",
 21524          "version": "2.34-0.1ubuntu9.1",
 21525          "licenses": [
 21526            {
 21527              "license": {
 21528                "id": "BSD-2-Clause"
 21529              }
 21530            },
 21531            {
 21532              "license": {
 21533                "id": "BSD-3-Clause"
 21534              }
 21535            },
 21536            {
 21537              "license": {
 21538                "id": "BSD-4-Clause"
 21539              }
 21540            },
 21541            {
 21542              "license": {
 21543                "id": "GPL-2.0-only"
 21544              }
 21545            },
 21546            {
 21547              "license": {
 21548                "id": "GPL-2.0-or-later"
 21549              }
 21550            },
 21551            {
 21552              "license": {
 21553                "id": "GPL-3.0-only"
 21554              }
 21555            },
 21556            {
 21557              "license": {
 21558                "id": "GPL-3.0-or-later"
 21559              }
 21560            },
 21561            {
 21562              "license": {
 21563                "name": "LGPL"
 21564              }
 21565            },
 21566            {
 21567              "license": {
 21568                "id": "LGPL-2.0-only"
 21569              }
 21570            },
 21571            {
 21572              "license": {
 21573                "id": "LGPL-2.0-or-later"
 21574              }
 21575            },
 21576            {
 21577              "license": {
 21578                "id": "LGPL-2.1-only"
 21579              }
 21580            },
 21581            {
 21582              "license": {
 21583                "id": "LGPL-2.1-or-later"
 21584              }
 21585            },
 21586            {
 21587              "license": {
 21588                "id": "LGPL-3.0-only"
 21589              }
 21590            },
 21591            {
 21592              "license": {
 21593                "id": "LGPL-3.0-or-later"
 21594              }
 21595            },
 21596            {
 21597              "license": {
 21598                "id": "MIT"
 21599              }
 21600            },
 21601            {
 21602              "license": {
 21603                "name": "public-domain"
 21604              }
 21605            }
 21606          ],
 21607          "cpe": "cpe:2.3:a:libmount1:libmount1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 21608          "purl": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 21609          "swid": {
 21610            "attachment": {}
 21611          },
 21612          "pedigree": {},
 21613          "evidence": {},
 21614          "signature": {
 21615            "signature": {
 21616              "publicKey": {}
 21617            }
 21618          },
 21619          "modelCard": {
 21620            "modelParameters": {
 21621              "approach": {}
 21622            },
 21623            "quantitativeAnalysis": {
 21624              "graphics": {}
 21625            },
 21626            "considerations": {}
 21627          }
 21628        },
 21629        {
 21630          "type": "library",
 21631          "bom-ref": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04\u0026package-id=b45a0d57576ce262",
 21632          "supplier": {},
 21633          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21634          "name": "libmpdec2",
 21635          "version": "2.4.2-3",
 21636          "licenses": [
 21637            {
 21638              "license": {
 21639                "name": "BSD"
 21640              }
 21641            },
 21642            {
 21643              "license": {
 21644                "id": "GPL-2.0-only"
 21645              }
 21646            },
 21647            {
 21648              "license": {
 21649                "id": "GPL-2.0-or-later"
 21650              }
 21651            }
 21652          ],
 21653          "cpe": "cpe:2.3:a:libmpdec2:libmpdec2:2.4.2-3:*:*:*:*:*:*:*",
 21654          "purl": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04",
 21655          "swid": {
 21656            "attachment": {}
 21657          },
 21658          "pedigree": {},
 21659          "evidence": {},
 21660          "signature": {
 21661            "signature": {
 21662              "publicKey": {}
 21663            }
 21664          },
 21665          "modelCard": {
 21666            "modelParameters": {
 21667              "approach": {}
 21668            },
 21669            "quantitativeAnalysis": {
 21670              "graphics": {}
 21671            },
 21672            "considerations": {}
 21673          }
 21674        },
 21675        {
 21676          "type": "library",
 21677          "bom-ref": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=ed8fb166163a75b8",
 21678          "supplier": {},
 21679          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21680          "name": "libncurses6",
 21681          "version": "6.2-0ubuntu2",
 21682          "cpe": "cpe:2.3:a:libncurses6:libncurses6:6.2-0ubuntu2:*:*:*:*:*:*:*",
 21683          "purl": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 21684          "swid": {
 21685            "attachment": {}
 21686          },
 21687          "pedigree": {},
 21688          "evidence": {},
 21689          "signature": {
 21690            "signature": {
 21691              "publicKey": {}
 21692            }
 21693          },
 21694          "modelCard": {
 21695            "modelParameters": {
 21696              "approach": {}
 21697            },
 21698            "quantitativeAnalysis": {
 21699              "graphics": {}
 21700            },
 21701            "considerations": {}
 21702          }
 21703        },
 21704        {
 21705          "type": "library",
 21706          "bom-ref": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=58525ddc073a008a",
 21707          "supplier": {},
 21708          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21709          "name": "libncursesw6",
 21710          "version": "6.2-0ubuntu2",
 21711          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.2-0ubuntu2:*:*:*:*:*:*:*",
 21712          "purl": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 21713          "swid": {
 21714            "attachment": {}
 21715          },
 21716          "pedigree": {},
 21717          "evidence": {},
 21718          "signature": {
 21719            "signature": {
 21720              "publicKey": {}
 21721            }
 21722          },
 21723          "modelCard": {
 21724            "modelParameters": {
 21725              "approach": {}
 21726            },
 21727            "quantitativeAnalysis": {
 21728              "graphics": {}
 21729            },
 21730            "considerations": {}
 21731          }
 21732        },
 21733        {
 21734          "type": "library",
 21735          "bom-ref": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3d185fbd6a7e56f",
 21736          "supplier": {},
 21737          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21738          "name": "libnettle7",
 21739          "version": "3.5.1+really3.5.1-2ubuntu0.2",
 21740          "licenses": [
 21741            {
 21742              "license": {
 21743                "name": "GAP"
 21744              }
 21745            },
 21746            {
 21747              "license": {
 21748                "name": "GPL"
 21749              }
 21750            },
 21751            {
 21752              "license": {
 21753                "id": "GPL-2.0-only"
 21754              }
 21755            },
 21756            {
 21757              "license": {
 21758                "id": "GPL-2.0-or-later"
 21759              }
 21760            },
 21761            {
 21762              "license": {
 21763                "name": "LGPL"
 21764              }
 21765            },
 21766            {
 21767              "license": {
 21768                "id": "LGPL-2.0-only"
 21769              }
 21770            },
 21771            {
 21772              "license": {
 21773                "id": "LGPL-2.0-or-later"
 21774              }
 21775            },
 21776            {
 21777              "license": {
 21778                "id": "LGPL-2.1-or-later"
 21779              }
 21780            },
 21781            {
 21782              "license": {
 21783                "name": "other"
 21784              }
 21785            },
 21786            {
 21787              "license": {
 21788                "name": "public-domain"
 21789              }
 21790            }
 21791          ],
 21792          "cpe": "cpe:2.3:a:libnettle7:libnettle7:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
 21793          "purl": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
 21794          "swid": {
 21795            "attachment": {}
 21796          },
 21797          "pedigree": {},
 21798          "evidence": {},
 21799          "signature": {
 21800            "signature": {
 21801              "publicKey": {}
 21802            }
 21803          },
 21804          "modelCard": {
 21805            "modelParameters": {
 21806              "approach": {}
 21807            },
 21808            "quantitativeAnalysis": {
 21809              "graphics": {}
 21810            },
 21811            "considerations": {}
 21812          }
 21813        },
 21814        {
 21815          "type": "library",
 21816          "bom-ref": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04\u0026package-id=71bd574c47c02b75",
 21817          "supplier": {},
 21818          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21819          "name": "libnfsidmap2",
 21820          "version": "0.25-5.1ubuntu1",
 21821          "cpe": "cpe:2.3:a:libnfsidmap2:libnfsidmap2:0.25-5.1ubuntu1:*:*:*:*:*:*:*",
 21822          "purl": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04",
 21823          "swid": {
 21824            "attachment": {}
 21825          },
 21826          "pedigree": {},
 21827          "evidence": {},
 21828          "signature": {
 21829            "signature": {
 21830              "publicKey": {}
 21831            }
 21832          },
 21833          "modelCard": {
 21834            "modelParameters": {
 21835              "approach": {}
 21836            },
 21837            "quantitativeAnalysis": {
 21838              "graphics": {}
 21839            },
 21840            "considerations": {}
 21841          }
 21842        },
 21843        {
 21844          "type": "library",
 21845          "bom-ref": "pkg:deb/ubuntu/libnghttp2-14@1.40.0-1build1?arch=amd64\u0026upstream=nghttp2\u0026distro=ubuntu-20.04\u0026package-id=c86604c1fa72dd96",
 21846          "supplier": {},
 21847          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21848          "name": "libnghttp2-14",
 21849          "version": "1.40.0-1build1",
 21850          "licenses": [
 21851            {
 21852              "license": {
 21853                "id": "BSD-2-Clause"
 21854              }
 21855            },
 21856            {
 21857              "license": {
 21858                "name": "Expat"
 21859              }
 21860            },
 21861            {
 21862              "license": {
 21863                "id": "GPL-3.0-only"
 21864              }
 21865            },
 21866            {
 21867              "license": {
 21868                "id": "GPL-3.0-or-later"
 21869              }
 21870            },
 21871            {
 21872              "license": {
 21873                "id": "MIT"
 21874              }
 21875            },
 21876            {
 21877              "license": {
 21878                "name": "SIL-OFL-1.1"
 21879              }
 21880            },
 21881            {
 21882              "license": {
 21883                "name": "all-permissive"
 21884              }
 21885            }
 21886          ],
 21887          "cpe": "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.40.0-1build1:*:*:*:*:*:*:*",
 21888          "purl": "pkg:deb/ubuntu/libnghttp2-14@1.40.0-1build1?arch=amd64\u0026upstream=nghttp2\u0026distro=ubuntu-20.04",
 21889          "swid": {
 21890            "attachment": {}
 21891          },
 21892          "pedigree": {},
 21893          "evidence": {},
 21894          "signature": {
 21895            "signature": {
 21896              "publicKey": {}
 21897            }
 21898          },
 21899          "modelCard": {
 21900            "modelParameters": {
 21901              "approach": {}
 21902            },
 21903            "quantitativeAnalysis": {
 21904              "graphics": {}
 21905            },
 21906            "considerations": {}
 21907          }
 21908        },
 21909        {
 21910          "type": "library",
 21911          "bom-ref": "pkg:deb/ubuntu/libogg0@1.3.4-0ubuntu1?arch=amd64\u0026upstream=libogg\u0026distro=ubuntu-20.04\u0026package-id=6611fa67492156e2",
 21912          "supplier": {},
 21913          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21914          "name": "libogg0",
 21915          "version": "1.3.4-0ubuntu1",
 21916          "cpe": "cpe:2.3:a:libogg0:libogg0:1.3.4-0ubuntu1:*:*:*:*:*:*:*",
 21917          "purl": "pkg:deb/ubuntu/libogg0@1.3.4-0ubuntu1?arch=amd64\u0026upstream=libogg\u0026distro=ubuntu-20.04",
 21918          "swid": {
 21919            "attachment": {}
 21920          },
 21921          "pedigree": {},
 21922          "evidence": {},
 21923          "signature": {
 21924            "signature": {
 21925              "publicKey": {}
 21926            }
 21927          },
 21928          "modelCard": {
 21929            "modelParameters": {
 21930              "approach": {}
 21931            },
 21932            "quantitativeAnalysis": {
 21933              "graphics": {}
 21934            },
 21935            "considerations": {}
 21936          }
 21937        },
 21938        {
 21939          "type": "library",
 21940          "bom-ref": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04\u0026package-id=9fc0ca46e6d21557",
 21941          "supplier": {},
 21942          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21943          "name": "libp11-kit0",
 21944          "version": "0.23.20-1ubuntu0.1",
 21945          "licenses": [
 21946            {
 21947              "license": {
 21948                "id": "BSD-3-Clause"
 21949              }
 21950            },
 21951            {
 21952              "license": {
 21953                "id": "ISC"
 21954              }
 21955            },
 21956            {
 21957              "license": {
 21958                "name": "ISC+IBM"
 21959              }
 21960            },
 21961            {
 21962              "license": {
 21963                "name": "permissive-like-automake-output"
 21964              }
 21965            },
 21966            {
 21967              "license": {
 21968                "name": "same-as-rest-of-p11kit"
 21969              }
 21970            }
 21971          ],
 21972          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.20-1ubuntu0.1:*:*:*:*:*:*:*",
 21973          "purl": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04",
 21974          "swid": {
 21975            "attachment": {}
 21976          },
 21977          "pedigree": {},
 21978          "evidence": {},
 21979          "signature": {
 21980            "signature": {
 21981              "publicKey": {}
 21982            }
 21983          },
 21984          "modelCard": {
 21985            "modelParameters": {
 21986              "approach": {}
 21987            },
 21988            "quantitativeAnalysis": {
 21989              "graphics": {}
 21990            },
 21991            "considerations": {}
 21992          }
 21993        },
 21994        {
 21995          "type": "library",
 21996          "bom-ref": "pkg:deb/ubuntu/libpam-cap@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04\u0026package-id=20db44acb7f94535",
 21997          "supplier": {},
 21998          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 21999          "name": "libpam-cap",
 22000          "version": "1:2.32-1",
 22001          "licenses": [
 22002            {
 22003              "license": {
 22004                "id": "BSD-3-Clause"
 22005              }
 22006            },
 22007            {
 22008              "license": {
 22009                "id": "GPL-2.0-only"
 22010              }
 22011            },
 22012            {
 22013              "license": {
 22014                "id": "GPL-2.0-or-later"
 22015              }
 22016            }
 22017          ],
 22018          "cpe": "cpe:2.3:a:libpam-cap:libpam-cap:1\\:2.32-1:*:*:*:*:*:*:*",
 22019          "purl": "pkg:deb/ubuntu/libpam-cap@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04",
 22020          "swid": {
 22021            "attachment": {}
 22022          },
 22023          "pedigree": {},
 22024          "evidence": {},
 22025          "signature": {
 22026            "signature": {
 22027              "publicKey": {}
 22028            }
 22029          },
 22030          "modelCard": {
 22031            "modelParameters": {
 22032              "approach": {}
 22033            },
 22034            "quantitativeAnalysis": {
 22035              "graphics": {}
 22036            },
 22037            "considerations": {}
 22038          }
 22039        },
 22040        {
 22041          "type": "library",
 22042          "bom-ref": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=e7be6c0ad703fc9a",
 22043          "supplier": {},
 22044          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22045          "name": "libpam-modules",
 22046          "version": "1.3.1-5ubuntu4.2",
 22047          "licenses": [
 22048            {
 22049              "license": {
 22050                "name": "GPL"
 22051              }
 22052            }
 22053          ],
 22054          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
 22055          "purl": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
 22056          "swid": {
 22057            "attachment": {}
 22058          },
 22059          "pedigree": {},
 22060          "evidence": {},
 22061          "signature": {
 22062            "signature": {
 22063              "publicKey": {}
 22064            }
 22065          },
 22066          "modelCard": {
 22067            "modelParameters": {
 22068              "approach": {}
 22069            },
 22070            "quantitativeAnalysis": {
 22071              "graphics": {}
 22072            },
 22073            "considerations": {}
 22074          }
 22075        },
 22076        {
 22077          "type": "library",
 22078          "bom-ref": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=7ff667273975da27",
 22079          "supplier": {},
 22080          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22081          "name": "libpam-modules-bin",
 22082          "version": "1.3.1-5ubuntu4.2",
 22083          "licenses": [
 22084            {
 22085              "license": {
 22086                "name": "GPL"
 22087              }
 22088            }
 22089          ],
 22090          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
 22091          "purl": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
 22092          "swid": {
 22093            "attachment": {}
 22094          },
 22095          "pedigree": {},
 22096          "evidence": {},
 22097          "signature": {
 22098            "signature": {
 22099              "publicKey": {}
 22100            }
 22101          },
 22102          "modelCard": {
 22103            "modelParameters": {
 22104              "approach": {}
 22105            },
 22106            "quantitativeAnalysis": {
 22107              "graphics": {}
 22108            },
 22109            "considerations": {}
 22110          }
 22111        },
 22112        {
 22113          "type": "library",
 22114          "bom-ref": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.2?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=47a743e8128a9af6",
 22115          "supplier": {},
 22116          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22117          "name": "libpam-runtime",
 22118          "version": "1.3.1-5ubuntu4.2",
 22119          "licenses": [
 22120            {
 22121              "license": {
 22122                "name": "GPL"
 22123              }
 22124            }
 22125          ],
 22126          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
 22127          "purl": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.2?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04",
 22128          "swid": {
 22129            "attachment": {}
 22130          },
 22131          "pedigree": {},
 22132          "evidence": {},
 22133          "signature": {
 22134            "signature": {
 22135              "publicKey": {}
 22136            }
 22137          },
 22138          "modelCard": {
 22139            "modelParameters": {
 22140              "approach": {}
 22141            },
 22142            "quantitativeAnalysis": {
 22143              "graphics": {}
 22144            },
 22145            "considerations": {}
 22146          }
 22147        },
 22148        {
 22149          "type": "library",
 22150          "bom-ref": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=e57fbdd1e7d57983",
 22151          "supplier": {},
 22152          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22153          "name": "libpam0g",
 22154          "version": "1.3.1-5ubuntu4.2",
 22155          "licenses": [
 22156            {
 22157              "license": {
 22158                "name": "GPL"
 22159              }
 22160            }
 22161          ],
 22162          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
 22163          "purl": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
 22164          "swid": {
 22165            "attachment": {}
 22166          },
 22167          "pedigree": {},
 22168          "evidence": {},
 22169          "signature": {
 22170            "signature": {
 22171              "publicKey": {}
 22172            }
 22173          },
 22174          "modelCard": {
 22175            "modelParameters": {
 22176              "approach": {}
 22177            },
 22178            "quantitativeAnalysis": {
 22179              "graphics": {}
 22180            },
 22181            "considerations": {}
 22182          }
 22183        },
 22184        {
 22185          "type": "library",
 22186          "bom-ref": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04\u0026package-id=ec9eb70008ed8b14",
 22187          "supplier": {},
 22188          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22189          "name": "libpcre2-8-0",
 22190          "version": "10.34-7",
 22191          "cpe": "cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.34-7:*:*:*:*:*:*:*",
 22192          "purl": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04",
 22193          "swid": {
 22194            "attachment": {}
 22195          },
 22196          "pedigree": {},
 22197          "evidence": {},
 22198          "signature": {
 22199            "signature": {
 22200              "publicKey": {}
 22201            }
 22202          },
 22203          "modelCard": {
 22204            "modelParameters": {
 22205              "approach": {}
 22206            },
 22207            "quantitativeAnalysis": {
 22208              "graphics": {}
 22209            },
 22210            "considerations": {}
 22211          }
 22212        },
 22213        {
 22214          "type": "library",
 22215          "bom-ref": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04\u0026package-id=f2af8e66c60a624",
 22216          "supplier": {},
 22217          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22218          "name": "libpcre3",
 22219          "version": "2:8.39-12build1",
 22220          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-12build1:*:*:*:*:*:*:*",
 22221          "purl": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04",
 22222          "swid": {
 22223            "attachment": {}
 22224          },
 22225          "pedigree": {},
 22226          "evidence": {},
 22227          "signature": {
 22228            "signature": {
 22229              "publicKey": {}
 22230            }
 22231          },
 22232          "modelCard": {
 22233            "modelParameters": {
 22234              "approach": {}
 22235            },
 22236            "quantitativeAnalysis": {
 22237              "graphics": {}
 22238            },
 22239            "considerations": {}
 22240          }
 22241        },
 22242        {
 22243          "type": "library",
 22244          "bom-ref": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.2?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04\u0026package-id=1444db6c35de79c6",
 22245          "supplier": {},
 22246          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22247          "name": "libprocps8",
 22248          "version": "2:3.3.16-1ubuntu2.2",
 22249          "licenses": [
 22250            {
 22251              "license": {
 22252                "id": "GPL-2.0-only"
 22253              }
 22254            },
 22255            {
 22256              "license": {
 22257                "id": "GPL-2.0-or-later"
 22258              }
 22259            },
 22260            {
 22261              "license": {
 22262                "id": "LGPL-2.0-only"
 22263              }
 22264            },
 22265            {
 22266              "license": {
 22267                "id": "LGPL-2.0-or-later"
 22268              }
 22269            },
 22270            {
 22271              "license": {
 22272                "id": "LGPL-2.1-only"
 22273              }
 22274            },
 22275            {
 22276              "license": {
 22277                "id": "LGPL-2.1-or-later"
 22278              }
 22279            }
 22280          ],
 22281          "cpe": "cpe:2.3:a:libprocps8:libprocps8:2\\:3.3.16-1ubuntu2.2:*:*:*:*:*:*:*",
 22282          "purl": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.2?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04",
 22283          "swid": {
 22284            "attachment": {}
 22285          },
 22286          "pedigree": {},
 22287          "evidence": {},
 22288          "signature": {
 22289            "signature": {
 22290              "publicKey": {}
 22291            }
 22292          },
 22293          "modelCard": {
 22294            "modelParameters": {
 22295              "approach": {}
 22296            },
 22297            "quantitativeAnalysis": {
 22298              "graphics": {}
 22299            },
 22300            "considerations": {}
 22301          }
 22302        },
 22303        {
 22304          "type": "library",
 22305          "bom-ref": "pkg:deb/ubuntu/libpsl5@0.21.0-1ubuntu1?arch=amd64\u0026upstream=libpsl\u0026distro=ubuntu-20.04\u0026package-id=e77e76f35a3ad192",
 22306          "supplier": {},
 22307          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22308          "name": "libpsl5",
 22309          "version": "0.21.0-1ubuntu1",
 22310          "licenses": [
 22311            {
 22312              "license": {
 22313                "name": "Chromium"
 22314              }
 22315            },
 22316            {
 22317              "license": {
 22318                "id": "MIT"
 22319              }
 22320            }
 22321          ],
 22322          "cpe": "cpe:2.3:a:libpsl5:libpsl5:0.21.0-1ubuntu1:*:*:*:*:*:*:*",
 22323          "purl": "pkg:deb/ubuntu/libpsl5@0.21.0-1ubuntu1?arch=amd64\u0026upstream=libpsl\u0026distro=ubuntu-20.04",
 22324          "swid": {
 22325            "attachment": {}
 22326          },
 22327          "pedigree": {},
 22328          "evidence": {},
 22329          "signature": {
 22330            "signature": {
 22331              "publicKey": {}
 22332            }
 22333          },
 22334          "modelCard": {
 22335            "modelParameters": {
 22336              "approach": {}
 22337            },
 22338            "quantitativeAnalysis": {
 22339              "graphics": {}
 22340            },
 22341            "considerations": {}
 22342          }
 22343        },
 22344        {
 22345          "type": "library",
 22346          "bom-ref": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=b40e3316416bbdaf",
 22347          "supplier": {},
 22348          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22349          "name": "libpython3-stdlib",
 22350          "version": "3.8.2-0ubuntu2",
 22351          "cpe": "cpe:2.3:a:libpython3-stdlib:libpython3-stdlib:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
 22352          "purl": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
 22353          "swid": {
 22354            "attachment": {}
 22355          },
 22356          "pedigree": {},
 22357          "evidence": {},
 22358          "signature": {
 22359            "signature": {
 22360              "publicKey": {}
 22361            }
 22362          },
 22363          "modelCard": {
 22364            "modelParameters": {
 22365              "approach": {}
 22366            },
 22367            "quantitativeAnalysis": {
 22368              "graphics": {}
 22369            },
 22370            "considerations": {}
 22371          }
 22372        },
 22373        {
 22374          "type": "library",
 22375          "bom-ref": "pkg:deb/ubuntu/libpython3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=ad8bdc246bbd4eb3",
 22376          "supplier": {},
 22377          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22378          "name": "libpython3.8",
 22379          "version": "3.8.10-0ubuntu1~20.04",
 22380          "licenses": [
 22381            {
 22382              "license": {
 22383                "name": "By"
 22384              }
 22385            },
 22386            {
 22387              "license": {
 22388                "id": "GPL-2.0-only"
 22389              }
 22390            },
 22391            {
 22392              "license": {
 22393                "name": "Permission"
 22394              }
 22395            },
 22396            {
 22397              "license": {
 22398                "name": "Redistribution"
 22399              }
 22400            },
 22401            {
 22402              "license": {
 22403                "name": "This"
 22404              }
 22405            }
 22406          ],
 22407          "cpe": "cpe:2.3:a:libpython3.8:libpython3.8:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
 22408          "purl": "pkg:deb/ubuntu/libpython3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 22409          "swid": {
 22410            "attachment": {}
 22411          },
 22412          "pedigree": {},
 22413          "evidence": {},
 22414          "signature": {
 22415            "signature": {
 22416              "publicKey": {}
 22417            }
 22418          },
 22419          "modelCard": {
 22420            "modelParameters": {
 22421              "approach": {}
 22422            },
 22423            "quantitativeAnalysis": {
 22424              "graphics": {}
 22425            },
 22426            "considerations": {}
 22427          }
 22428        },
 22429        {
 22430          "type": "library",
 22431          "bom-ref": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=fb58dad98da64e3b",
 22432          "supplier": {},
 22433          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22434          "name": "libpython3.8-minimal",
 22435          "version": "3.8.10-0ubuntu1~20.04",
 22436          "licenses": [
 22437            {
 22438              "license": {
 22439                "name": "By"
 22440              }
 22441            },
 22442            {
 22443              "license": {
 22444                "id": "GPL-2.0-only"
 22445              }
 22446            },
 22447            {
 22448              "license": {
 22449                "name": "Permission"
 22450              }
 22451            },
 22452            {
 22453              "license": {
 22454                "name": "Redistribution"
 22455              }
 22456            },
 22457            {
 22458              "license": {
 22459                "name": "This"
 22460              }
 22461            }
 22462          ],
 22463          "cpe": "cpe:2.3:a:libpython3.8-minimal:libpython3.8-minimal:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
 22464          "purl": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 22465          "swid": {
 22466            "attachment": {}
 22467          },
 22468          "pedigree": {},
 22469          "evidence": {},
 22470          "signature": {
 22471            "signature": {
 22472              "publicKey": {}
 22473            }
 22474          },
 22475          "modelCard": {
 22476            "modelParameters": {
 22477              "approach": {}
 22478            },
 22479            "quantitativeAnalysis": {
 22480              "graphics": {}
 22481            },
 22482            "considerations": {}
 22483          }
 22484        },
 22485        {
 22486          "type": "library",
 22487          "bom-ref": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=54e48e611df3b41d",
 22488          "supplier": {},
 22489          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22490          "name": "libpython3.8-stdlib",
 22491          "version": "3.8.10-0ubuntu1~20.04",
 22492          "licenses": [
 22493            {
 22494              "license": {
 22495                "name": "By"
 22496              }
 22497            },
 22498            {
 22499              "license": {
 22500                "id": "GPL-2.0-only"
 22501              }
 22502            },
 22503            {
 22504              "license": {
 22505                "name": "Permission"
 22506              }
 22507            },
 22508            {
 22509              "license": {
 22510                "name": "Redistribution"
 22511              }
 22512            },
 22513            {
 22514              "license": {
 22515                "name": "This"
 22516              }
 22517            }
 22518          ],
 22519          "cpe": "cpe:2.3:a:libpython3.8-stdlib:libpython3.8-stdlib:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
 22520          "purl": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 22521          "swid": {
 22522            "attachment": {}
 22523          },
 22524          "pedigree": {},
 22525          "evidence": {},
 22526          "signature": {
 22527            "signature": {
 22528              "publicKey": {}
 22529            }
 22530          },
 22531          "modelCard": {
 22532            "modelParameters": {
 22533              "approach": {}
 22534            },
 22535            "quantitativeAnalysis": {
 22536              "graphics": {}
 22537            },
 22538            "considerations": {}
 22539          }
 22540        },
 22541        {
 22542          "type": "library",
 22543          "bom-ref": "pkg:deb/ubuntu/libreadline5@5.2+dfsg-3build3?arch=amd64\u0026upstream=readline5\u0026distro=ubuntu-20.04\u0026package-id=5763fb43bb0ba51a",
 22544          "supplier": {},
 22545          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22546          "name": "libreadline5",
 22547          "version": "5.2+dfsg-3build3",
 22548          "licenses": [
 22549            {
 22550              "license": {
 22551                "id": "GPL-2.0-only"
 22552              }
 22553            }
 22554          ],
 22555          "cpe": "cpe:2.3:a:libreadline5:libreadline5:5.2\\+dfsg-3build3:*:*:*:*:*:*:*",
 22556          "purl": "pkg:deb/ubuntu/libreadline5@5.2+dfsg-3build3?arch=amd64\u0026upstream=readline5\u0026distro=ubuntu-20.04",
 22557          "swid": {
 22558            "attachment": {}
 22559          },
 22560          "pedigree": {},
 22561          "evidence": {},
 22562          "signature": {
 22563            "signature": {
 22564              "publicKey": {}
 22565            }
 22566          },
 22567          "modelCard": {
 22568            "modelParameters": {
 22569              "approach": {}
 22570            },
 22571            "quantitativeAnalysis": {
 22572              "graphics": {}
 22573            },
 22574            "considerations": {}
 22575          }
 22576        },
 22577        {
 22578          "type": "library",
 22579          "bom-ref": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=67b876656fcd9e68",
 22580          "supplier": {},
 22581          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22582          "name": "libreadline8",
 22583          "version": "8.0-4",
 22584          "licenses": [
 22585            {
 22586              "license": {
 22587                "name": "GFDL"
 22588              }
 22589            },
 22590            {
 22591              "license": {
 22592                "id": "GPL-3.0-only"
 22593              }
 22594            }
 22595          ],
 22596          "cpe": "cpe:2.3:a:libreadline8:libreadline8:8.0-4:*:*:*:*:*:*:*",
 22597          "purl": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04",
 22598          "swid": {
 22599            "attachment": {}
 22600          },
 22601          "pedigree": {},
 22602          "evidence": {},
 22603          "signature": {
 22604            "signature": {
 22605              "publicKey": {}
 22606            }
 22607          },
 22608          "modelCard": {
 22609            "modelParameters": {
 22610              "approach": {}
 22611            },
 22612            "quantitativeAnalysis": {
 22613              "graphics": {}
 22614            },
 22615            "considerations": {}
 22616          }
 22617        },
 22618        {
 22619          "type": "library",
 22620          "bom-ref": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=68e35bc456818613",
 22621          "supplier": {},
 22622          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22623          "name": "libroken18-heimdal",
 22624          "version": "7.7.0+dfsg-1ubuntu1",
 22625          "licenses": [
 22626            {
 22627              "license": {
 22628                "id": "BSD-3-Clause"
 22629              }
 22630            },
 22631            {
 22632              "license": {
 22633                "id": "GPL-2.0-only"
 22634              }
 22635            },
 22636            {
 22637              "license": {
 22638                "id": "GPL-2.0-or-later"
 22639              }
 22640            },
 22641            {
 22642              "license": {
 22643                "name": "custom"
 22644              }
 22645            }
 22646          ],
 22647          "cpe": "cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 22648          "purl": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 22649          "swid": {
 22650            "attachment": {}
 22651          },
 22652          "pedigree": {},
 22653          "evidence": {},
 22654          "signature": {
 22655            "signature": {
 22656              "publicKey": {}
 22657            }
 22658          },
 22659          "modelCard": {
 22660            "modelParameters": {
 22661              "approach": {}
 22662            },
 22663            "quantitativeAnalysis": {
 22664              "graphics": {}
 22665            },
 22666            "considerations": {}
 22667          }
 22668        },
 22669        {
 22670          "type": "library",
 22671          "bom-ref": "pkg:deb/ubuntu/librtmp1@2.4+20151223.gitfa8646d.1-2build1?arch=amd64\u0026upstream=rtmpdump\u0026distro=ubuntu-20.04\u0026package-id=ede637f87a4bfd7b",
 22672          "supplier": {},
 22673          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22674          "name": "librtmp1",
 22675          "version": "2.4+20151223.gitfa8646d.1-2build1",
 22676          "licenses": [
 22677            {
 22678              "license": {
 22679                "id": "GPL-2.0-only"
 22680              }
 22681            },
 22682            {
 22683              "license": {
 22684                "id": "LGPL-2.1-only"
 22685              }
 22686            }
 22687          ],
 22688          "cpe": "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20151223.gitfa8646d.1-2build1:*:*:*:*:*:*:*",
 22689          "purl": "pkg:deb/ubuntu/librtmp1@2.4+20151223.gitfa8646d.1-2build1?arch=amd64\u0026upstream=rtmpdump\u0026distro=ubuntu-20.04",
 22690          "swid": {
 22691            "attachment": {}
 22692          },
 22693          "pedigree": {},
 22694          "evidence": {},
 22695          "signature": {
 22696            "signature": {
 22697              "publicKey": {}
 22698            }
 22699          },
 22700          "modelCard": {
 22701            "modelParameters": {
 22702              "approach": {}
 22703            },
 22704            "quantitativeAnalysis": {
 22705              "graphics": {}
 22706            },
 22707            "considerations": {}
 22708          }
 22709        },
 22710        {
 22711          "type": "library",
 22712          "bom-ref": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=374396d82667544d",
 22713          "supplier": {},
 22714          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22715          "name": "libsasl2-2",
 22716          "version": "2.1.27+dfsg-2",
 22717          "licenses": [
 22718            {
 22719              "license": {
 22720                "id": "BSD-4-Clause"
 22721              }
 22722            },
 22723            {
 22724              "license": {
 22725                "id": "GPL-3.0-only"
 22726              }
 22727            },
 22728            {
 22729              "license": {
 22730                "id": "GPL-3.0-or-later"
 22731              }
 22732            }
 22733          ],
 22734          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
 22735          "purl": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
 22736          "swid": {
 22737            "attachment": {}
 22738          },
 22739          "pedigree": {},
 22740          "evidence": {},
 22741          "signature": {
 22742            "signature": {
 22743              "publicKey": {}
 22744            }
 22745          },
 22746          "modelCard": {
 22747            "modelParameters": {
 22748              "approach": {}
 22749            },
 22750            "quantitativeAnalysis": {
 22751              "graphics": {}
 22752            },
 22753            "considerations": {}
 22754          }
 22755        },
 22756        {
 22757          "type": "library",
 22758          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=fb8d278d10c4a3cf",
 22759          "supplier": {},
 22760          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22761          "name": "libsasl2-modules",
 22762          "version": "2.1.27+dfsg-2",
 22763          "licenses": [
 22764            {
 22765              "license": {
 22766                "id": "BSD-4-Clause"
 22767              }
 22768            },
 22769            {
 22770              "license": {
 22771                "id": "GPL-3.0-only"
 22772              }
 22773            },
 22774            {
 22775              "license": {
 22776                "id": "GPL-3.0-or-later"
 22777              }
 22778            }
 22779          ],
 22780          "cpe": "cpe:2.3:a:libsasl2-modules:libsasl2-modules:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
 22781          "purl": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
 22782          "swid": {
 22783            "attachment": {}
 22784          },
 22785          "pedigree": {},
 22786          "evidence": {},
 22787          "signature": {
 22788            "signature": {
 22789              "publicKey": {}
 22790            }
 22791          },
 22792          "modelCard": {
 22793            "modelParameters": {
 22794              "approach": {}
 22795            },
 22796            "quantitativeAnalysis": {
 22797              "graphics": {}
 22798            },
 22799            "considerations": {}
 22800          }
 22801        },
 22802        {
 22803          "type": "library",
 22804          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=63c3c50d36ec1d13",
 22805          "supplier": {},
 22806          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22807          "name": "libsasl2-modules-db",
 22808          "version": "2.1.27+dfsg-2",
 22809          "licenses": [
 22810            {
 22811              "license": {
 22812                "id": "BSD-4-Clause"
 22813              }
 22814            },
 22815            {
 22816              "license": {
 22817                "id": "GPL-3.0-only"
 22818              }
 22819            },
 22820            {
 22821              "license": {
 22822                "id": "GPL-3.0-or-later"
 22823              }
 22824            }
 22825          ],
 22826          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
 22827          "purl": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
 22828          "swid": {
 22829            "attachment": {}
 22830          },
 22831          "pedigree": {},
 22832          "evidence": {},
 22833          "signature": {
 22834            "signature": {
 22835              "publicKey": {}
 22836            }
 22837          },
 22838          "modelCard": {
 22839            "modelParameters": {
 22840              "approach": {}
 22841            },
 22842            "quantitativeAnalysis": {
 22843              "graphics": {}
 22844            },
 22845            "considerations": {}
 22846          }
 22847        },
 22848        {
 22849          "type": "library",
 22850          "bom-ref": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04\u0026package-id=b2fd79b9c242e8e8",
 22851          "supplier": {},
 22852          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22853          "name": "libseccomp2",
 22854          "version": "2.5.1-1ubuntu1~20.04.1",
 22855          "licenses": [
 22856            {
 22857              "license": {
 22858                "id": "LGPL-2.1-only"
 22859              }
 22860            }
 22861          ],
 22862          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.5.1-1ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
 22863          "purl": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04",
 22864          "swid": {
 22865            "attachment": {}
 22866          },
 22867          "pedigree": {},
 22868          "evidence": {},
 22869          "signature": {
 22870            "signature": {
 22871              "publicKey": {}
 22872            }
 22873          },
 22874          "modelCard": {
 22875            "modelParameters": {
 22876              "approach": {}
 22877            },
 22878            "quantitativeAnalysis": {
 22879              "graphics": {}
 22880            },
 22881            "considerations": {}
 22882          }
 22883        },
 22884        {
 22885          "type": "library",
 22886          "bom-ref": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04\u0026package-id=e5d4ae16ac79b901",
 22887          "supplier": {},
 22888          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22889          "name": "libselinux1",
 22890          "version": "3.0-1build2",
 22891          "licenses": [
 22892            {
 22893              "license": {
 22894                "id": "GPL-2.0-only"
 22895              }
 22896            },
 22897            {
 22898              "license": {
 22899                "id": "LGPL-2.1-only"
 22900              }
 22901            }
 22902          ],
 22903          "cpe": "cpe:2.3:a:libselinux1:libselinux1:3.0-1build2:*:*:*:*:*:*:*",
 22904          "purl": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04",
 22905          "swid": {
 22906            "attachment": {}
 22907          },
 22908          "pedigree": {},
 22909          "evidence": {},
 22910          "signature": {
 22911            "signature": {
 22912              "publicKey": {}
 22913            }
 22914          },
 22915          "modelCard": {
 22916            "modelParameters": {
 22917              "approach": {}
 22918            },
 22919            "quantitativeAnalysis": {
 22920              "graphics": {}
 22921            },
 22922            "considerations": {}
 22923          }
 22924        },
 22925        {
 22926          "type": "library",
 22927          "bom-ref": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=4c6cd9f68ce53262",
 22928          "supplier": {},
 22929          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22930          "name": "libsemanage-common",
 22931          "version": "3.0-1build2",
 22932          "licenses": [
 22933            {
 22934              "license": {
 22935                "name": "GPL"
 22936              }
 22937            },
 22938            {
 22939              "license": {
 22940                "name": "LGPL"
 22941              }
 22942            }
 22943          ],
 22944          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:3.0-1build2:*:*:*:*:*:*:*",
 22945          "purl": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
 22946          "swid": {
 22947            "attachment": {}
 22948          },
 22949          "pedigree": {},
 22950          "evidence": {},
 22951          "signature": {
 22952            "signature": {
 22953              "publicKey": {}
 22954            }
 22955          },
 22956          "modelCard": {
 22957            "modelParameters": {
 22958              "approach": {}
 22959            },
 22960            "quantitativeAnalysis": {
 22961              "graphics": {}
 22962            },
 22963            "considerations": {}
 22964          }
 22965        },
 22966        {
 22967          "type": "library",
 22968          "bom-ref": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=963297f19b339026",
 22969          "supplier": {},
 22970          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 22971          "name": "libsemanage1",
 22972          "version": "3.0-1build2",
 22973          "licenses": [
 22974            {
 22975              "license": {
 22976                "name": "GPL"
 22977              }
 22978            },
 22979            {
 22980              "license": {
 22981                "name": "LGPL"
 22982              }
 22983            }
 22984          ],
 22985          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:3.0-1build2:*:*:*:*:*:*:*",
 22986          "purl": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
 22987          "swid": {
 22988            "attachment": {}
 22989          },
 22990          "pedigree": {},
 22991          "evidence": {},
 22992          "signature": {
 22993            "signature": {
 22994              "publicKey": {}
 22995            }
 22996          },
 22997          "modelCard": {
 22998            "modelParameters": {
 22999              "approach": {}
 23000            },
 23001            "quantitativeAnalysis": {
 23002              "graphics": {}
 23003            },
 23004            "considerations": {}
 23005          }
 23006        },
 23007        {
 23008          "type": "library",
 23009          "bom-ref": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04\u0026package-id=991afdd7bf17200c",
 23010          "supplier": {},
 23011          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23012          "name": "libsepol1",
 23013          "version": "3.0-1",
 23014          "licenses": [
 23015            {
 23016              "license": {
 23017                "name": "GPL"
 23018              }
 23019            },
 23020            {
 23021              "license": {
 23022                "name": "LGPL"
 23023              }
 23024            }
 23025          ],
 23026          "cpe": "cpe:2.3:a:libsepol1:libsepol1:3.0-1:*:*:*:*:*:*:*",
 23027          "purl": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04",
 23028          "swid": {
 23029            "attachment": {}
 23030          },
 23031          "pedigree": {},
 23032          "evidence": {},
 23033          "signature": {
 23034            "signature": {
 23035              "publicKey": {}
 23036            }
 23037          },
 23038          "modelCard": {
 23039            "modelParameters": {
 23040              "approach": {}
 23041            },
 23042            "quantitativeAnalysis": {
 23043              "graphics": {}
 23044            },
 23045            "considerations": {}
 23046          }
 23047        },
 23048        {
 23049          "type": "library",
 23050          "bom-ref": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=b47d3a935260c518",
 23051          "supplier": {},
 23052          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23053          "name": "libsmartcols1",
 23054          "version": "2.34-0.1ubuntu9.1",
 23055          "licenses": [
 23056            {
 23057              "license": {
 23058                "id": "BSD-2-Clause"
 23059              }
 23060            },
 23061            {
 23062              "license": {
 23063                "id": "BSD-3-Clause"
 23064              }
 23065            },
 23066            {
 23067              "license": {
 23068                "id": "BSD-4-Clause"
 23069              }
 23070            },
 23071            {
 23072              "license": {
 23073                "id": "GPL-2.0-only"
 23074              }
 23075            },
 23076            {
 23077              "license": {
 23078                "id": "GPL-2.0-or-later"
 23079              }
 23080            },
 23081            {
 23082              "license": {
 23083                "id": "GPL-3.0-only"
 23084              }
 23085            },
 23086            {
 23087              "license": {
 23088                "id": "GPL-3.0-or-later"
 23089              }
 23090            },
 23091            {
 23092              "license": {
 23093                "name": "LGPL"
 23094              }
 23095            },
 23096            {
 23097              "license": {
 23098                "id": "LGPL-2.0-only"
 23099              }
 23100            },
 23101            {
 23102              "license": {
 23103                "id": "LGPL-2.0-or-later"
 23104              }
 23105            },
 23106            {
 23107              "license": {
 23108                "id": "LGPL-2.1-only"
 23109              }
 23110            },
 23111            {
 23112              "license": {
 23113                "id": "LGPL-2.1-or-later"
 23114              }
 23115            },
 23116            {
 23117              "license": {
 23118                "id": "LGPL-3.0-only"
 23119              }
 23120            },
 23121            {
 23122              "license": {
 23123                "id": "LGPL-3.0-or-later"
 23124              }
 23125            },
 23126            {
 23127              "license": {
 23128                "id": "MIT"
 23129              }
 23130            },
 23131            {
 23132              "license": {
 23133                "name": "public-domain"
 23134              }
 23135            }
 23136          ],
 23137          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 23138          "purl": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 23139          "swid": {
 23140            "attachment": {}
 23141          },
 23142          "pedigree": {},
 23143          "evidence": {},
 23144          "signature": {
 23145            "signature": {
 23146              "publicKey": {}
 23147            }
 23148          },
 23149          "modelCard": {
 23150            "modelParameters": {
 23151              "approach": {}
 23152            },
 23153            "quantitativeAnalysis": {
 23154              "graphics": {}
 23155            },
 23156            "considerations": {}
 23157          }
 23158        },
 23159        {
 23160          "type": "library",
 23161          "bom-ref": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04\u0026package-id=a7c7ccf11d3583d1",
 23162          "supplier": {},
 23163          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23164          "name": "libsqlite3-0",
 23165          "version": "3.31.1-4ubuntu0.2",
 23166          "licenses": [
 23167            {
 23168              "license": {
 23169                "id": "GPL-2.0-only"
 23170              }
 23171            },
 23172            {
 23173              "license": {
 23174                "id": "GPL-2.0-or-later"
 23175              }
 23176            },
 23177            {
 23178              "license": {
 23179                "name": "public-domain"
 23180              }
 23181            }
 23182          ],
 23183          "cpe": "cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.31.1-4ubuntu0.2:*:*:*:*:*:*:*",
 23184          "purl": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04",
 23185          "swid": {
 23186            "attachment": {}
 23187          },
 23188          "pedigree": {},
 23189          "evidence": {},
 23190          "signature": {
 23191            "signature": {
 23192              "publicKey": {}
 23193            }
 23194          },
 23195          "modelCard": {
 23196            "modelParameters": {
 23197              "approach": {}
 23198            },
 23199            "quantitativeAnalysis": {
 23200              "graphics": {}
 23201            },
 23202            "considerations": {}
 23203          }
 23204        },
 23205        {
 23206          "type": "library",
 23207          "bom-ref": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4715894cb8165c",
 23208          "supplier": {},
 23209          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23210          "name": "libss2",
 23211          "version": "1.45.5-2ubuntu1",
 23212          "cpe": "cpe:2.3:a:libss2:libss2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 23213          "purl": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 23214          "swid": {
 23215            "attachment": {}
 23216          },
 23217          "pedigree": {},
 23218          "evidence": {},
 23219          "signature": {
 23220            "signature": {
 23221              "publicKey": {}
 23222            }
 23223          },
 23224          "modelCard": {
 23225            "modelParameters": {
 23226              "approach": {}
 23227            },
 23228            "quantitativeAnalysis": {
 23229              "graphics": {}
 23230            },
 23231            "considerations": {}
 23232          }
 23233        },
 23234        {
 23235          "type": "library",
 23236          "bom-ref": "pkg:deb/ubuntu/libssh-4@0.9.3-2ubuntu2.2?arch=amd64\u0026upstream=libssh\u0026distro=ubuntu-20.04\u0026package-id=93df7c2bd7217cc4",
 23237          "supplier": {},
 23238          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23239          "name": "libssh-4",
 23240          "version": "0.9.3-2ubuntu2.2",
 23241          "licenses": [
 23242            {
 23243              "license": {
 23244                "id": "BSD-2-Clause"
 23245              }
 23246            },
 23247            {
 23248              "license": {
 23249                "id": "BSD-3-Clause"
 23250              }
 23251            },
 23252            {
 23253              "license": {
 23254                "id": "LGPL-2.1-only"
 23255              }
 23256            },
 23257            {
 23258              "license": {
 23259                "name": "LGPL-2.1+~OpenSSL"
 23260              }
 23261            },
 23262            {
 23263              "license": {
 23264                "name": "public-domain"
 23265              }
 23266            }
 23267          ],
 23268          "cpe": "cpe:2.3:a:libssh-4:libssh-4:0.9.3-2ubuntu2.2:*:*:*:*:*:*:*",
 23269          "purl": "pkg:deb/ubuntu/libssh-4@0.9.3-2ubuntu2.2?arch=amd64\u0026upstream=libssh\u0026distro=ubuntu-20.04",
 23270          "swid": {
 23271            "attachment": {}
 23272          },
 23273          "pedigree": {},
 23274          "evidence": {},
 23275          "signature": {
 23276            "signature": {
 23277              "publicKey": {}
 23278            }
 23279          },
 23280          "modelCard": {
 23281            "modelParameters": {
 23282              "approach": {}
 23283            },
 23284            "quantitativeAnalysis": {
 23285              "graphics": {}
 23286            },
 23287            "considerations": {}
 23288          }
 23289        },
 23290        {
 23291          "type": "library",
 23292          "bom-ref": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.8?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04\u0026package-id=9228d1481eea75e3",
 23293          "supplier": {},
 23294          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23295          "name": "libssl1.1",
 23296          "version": "1.1.1f-1ubuntu2.8",
 23297          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1f-1ubuntu2.8:*:*:*:*:*:*:*",
 23298          "purl": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.8?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04",
 23299          "swid": {
 23300            "attachment": {}
 23301          },
 23302          "pedigree": {},
 23303          "evidence": {},
 23304          "signature": {
 23305            "signature": {
 23306              "publicKey": {}
 23307            }
 23308          },
 23309          "modelCard": {
 23310            "modelParameters": {
 23311              "approach": {}
 23312            },
 23313            "quantitativeAnalysis": {
 23314              "graphics": {}
 23315            },
 23316            "considerations": {}
 23317          }
 23318        },
 23319        {
 23320          "type": "library",
 23321          "bom-ref": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=241fcb3d9b65153a",
 23322          "supplier": {},
 23323          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23324          "name": "libstdc++6",
 23325          "version": "10.3.0-1ubuntu1~20.04",
 23326          "licenses": [
 23327            {
 23328              "license": {
 23329                "name": "Artistic"
 23330              }
 23331            },
 23332            {
 23333              "license": {
 23334                "id": "GFDL-1.2-only"
 23335              }
 23336            },
 23337            {
 23338              "license": {
 23339                "name": "GPL"
 23340              }
 23341            },
 23342            {
 23343              "license": {
 23344                "id": "GPL-2.0-only"
 23345              }
 23346            },
 23347            {
 23348              "license": {
 23349                "id": "GPL-3.0-only"
 23350              }
 23351            },
 23352            {
 23353              "license": {
 23354                "name": "LGPL"
 23355              }
 23356            }
 23357          ],
 23358          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
 23359          "purl": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
 23360          "swid": {
 23361            "attachment": {}
 23362          },
 23363          "pedigree": {},
 23364          "evidence": {},
 23365          "signature": {
 23366            "signature": {
 23367              "publicKey": {}
 23368            }
 23369          },
 23370          "modelCard": {
 23371            "modelParameters": {
 23372              "approach": {}
 23373            },
 23374            "quantitativeAnalysis": {
 23375              "graphics": {}
 23376            },
 23377            "considerations": {}
 23378          }
 23379        },
 23380        {
 23381          "type": "library",
 23382          "bom-ref": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=72d1f4b2fda6e155",
 23383          "supplier": {},
 23384          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23385          "name": "libsystemd0",
 23386          "version": "245.4-4ubuntu3.11",
 23387          "licenses": [
 23388            {
 23389              "license": {
 23390                "id": "CC0-1.0"
 23391              }
 23392            },
 23393            {
 23394              "license": {
 23395                "name": "Expat"
 23396              }
 23397            },
 23398            {
 23399              "license": {
 23400                "id": "GPL-2.0-only"
 23401              }
 23402            },
 23403            {
 23404              "license": {
 23405                "id": "GPL-2.0-or-later"
 23406              }
 23407            },
 23408            {
 23409              "license": {
 23410                "id": "LGPL-2.1-only"
 23411              }
 23412            },
 23413            {
 23414              "license": {
 23415                "id": "LGPL-2.1-or-later"
 23416              }
 23417            },
 23418            {
 23419              "license": {
 23420                "name": "public-domain"
 23421              }
 23422            }
 23423          ],
 23424          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:245.4-4ubuntu3.11:*:*:*:*:*:*:*",
 23425          "purl": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
 23426          "swid": {
 23427            "attachment": {}
 23428          },
 23429          "pedigree": {},
 23430          "evidence": {},
 23431          "signature": {
 23432            "signature": {
 23433              "publicKey": {}
 23434            }
 23435          },
 23436          "modelCard": {
 23437            "modelParameters": {
 23438              "approach": {}
 23439            },
 23440            "quantitativeAnalysis": {
 23441              "graphics": {}
 23442            },
 23443            "considerations": {}
 23444          }
 23445        },
 23446        {
 23447          "type": "library",
 23448          "bom-ref": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a290c35fc0220ba0",
 23449          "supplier": {},
 23450          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23451          "name": "libtasn1-6",
 23452          "version": "4.16.0-2",
 23453          "licenses": [
 23454            {
 23455              "license": {
 23456                "id": "GFDL-1.3-only"
 23457              }
 23458            },
 23459            {
 23460              "license": {
 23461                "id": "GPL-3.0-only"
 23462              }
 23463            },
 23464            {
 23465              "license": {
 23466                "name": "LGPL"
 23467              }
 23468            },
 23469            {
 23470              "license": {
 23471                "id": "LGPL-2.1-only"
 23472              }
 23473            }
 23474          ],
 23475          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2:*:*:*:*:*:*:*",
 23476          "purl": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04",
 23477          "swid": {
 23478            "attachment": {}
 23479          },
 23480          "pedigree": {},
 23481          "evidence": {},
 23482          "signature": {
 23483            "signature": {
 23484              "publicKey": {}
 23485            }
 23486          },
 23487          "modelCard": {
 23488            "modelParameters": {
 23489              "approach": {}
 23490            },
 23491            "quantitativeAnalysis": {
 23492              "graphics": {}
 23493            },
 23494            "considerations": {}
 23495          }
 23496        },
 23497        {
 23498          "type": "library",
 23499          "bom-ref": "pkg:deb/ubuntu/libtdb1@1.4.2-3build1?arch=amd64\u0026upstream=tdb\u0026distro=ubuntu-20.04\u0026package-id=50ead706c0e76e28",
 23500          "supplier": {},
 23501          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23502          "name": "libtdb1",
 23503          "version": "1.4.2-3build1",
 23504          "licenses": [
 23505            {
 23506              "license": {
 23507                "name": "BSD-3"
 23508              }
 23509            },
 23510            {
 23511              "license": {
 23512                "id": "GPL-3.0-only"
 23513              }
 23514            },
 23515            {
 23516              "license": {
 23517                "id": "GPL-3.0-or-later"
 23518              }
 23519            },
 23520            {
 23521              "license": {
 23522                "id": "ISC"
 23523              }
 23524            },
 23525            {
 23526              "license": {
 23527                "id": "LGPL-3.0-only"
 23528              }
 23529            },
 23530            {
 23531              "license": {
 23532                "id": "LGPL-3.0-or-later"
 23533              }
 23534            },
 23535            {
 23536              "license": {
 23537                "id": "PostgreSQL"
 23538              }
 23539            }
 23540          ],
 23541          "cpe": "cpe:2.3:a:libtdb1:libtdb1:1.4.2-3build1:*:*:*:*:*:*:*",
 23542          "purl": "pkg:deb/ubuntu/libtdb1@1.4.2-3build1?arch=amd64\u0026upstream=tdb\u0026distro=ubuntu-20.04",
 23543          "swid": {
 23544            "attachment": {}
 23545          },
 23546          "pedigree": {},
 23547          "evidence": {},
 23548          "signature": {
 23549            "signature": {
 23550              "publicKey": {}
 23551            }
 23552          },
 23553          "modelCard": {
 23554            "modelParameters": {
 23555              "approach": {}
 23556            },
 23557            "quantitativeAnalysis": {
 23558              "graphics": {}
 23559            },
 23560            "considerations": {}
 23561          }
 23562        },
 23563        {
 23564          "type": "library",
 23565          "bom-ref": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=72ad56d118fefea3",
 23566          "supplier": {},
 23567          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23568          "name": "libtinfo6",
 23569          "version": "6.2-0ubuntu2",
 23570          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.2-0ubuntu2:*:*:*:*:*:*:*",
 23571          "purl": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 23572          "swid": {
 23573            "attachment": {}
 23574          },
 23575          "pedigree": {},
 23576          "evidence": {},
 23577          "signature": {
 23578            "signature": {
 23579              "publicKey": {}
 23580            }
 23581          },
 23582          "modelCard": {
 23583            "modelParameters": {
 23584              "approach": {}
 23585            },
 23586            "quantitativeAnalysis": {
 23587              "graphics": {}
 23588            },
 23589            "considerations": {}
 23590          }
 23591        },
 23592        {
 23593          "type": "library",
 23594          "bom-ref": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=ba22fe8af5722b24",
 23595          "supplier": {},
 23596          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23597          "name": "libtirpc-common",
 23598          "version": "1.2.5-1",
 23599          "licenses": [
 23600            {
 23601              "license": {
 23602                "id": "BSD-3-Clause"
 23603              }
 23604            },
 23605            {
 23606              "license": {
 23607                "id": "GPL-2.0-only"
 23608              }
 23609            },
 23610            {
 23611              "license": {
 23612                "id": "LGPL-2.1-only"
 23613              }
 23614            }
 23615          ],
 23616          "cpe": "cpe:2.3:a:libtirpc-common:libtirpc-common:1.2.5-1:*:*:*:*:*:*:*",
 23617          "purl": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
 23618          "swid": {
 23619            "attachment": {}
 23620          },
 23621          "pedigree": {},
 23622          "evidence": {},
 23623          "signature": {
 23624            "signature": {
 23625              "publicKey": {}
 23626            }
 23627          },
 23628          "modelCard": {
 23629            "modelParameters": {
 23630              "approach": {}
 23631            },
 23632            "quantitativeAnalysis": {
 23633              "graphics": {}
 23634            },
 23635            "considerations": {}
 23636          }
 23637        },
 23638        {
 23639          "type": "library",
 23640          "bom-ref": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=57b2bfa0a8467ab7",
 23641          "supplier": {},
 23642          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23643          "name": "libtirpc3",
 23644          "version": "1.2.5-1",
 23645          "licenses": [
 23646            {
 23647              "license": {
 23648                "id": "BSD-3-Clause"
 23649              }
 23650            },
 23651            {
 23652              "license": {
 23653                "id": "GPL-2.0-only"
 23654              }
 23655            },
 23656            {
 23657              "license": {
 23658                "id": "LGPL-2.1-only"
 23659              }
 23660            }
 23661          ],
 23662          "cpe": "cpe:2.3:a:libtirpc3:libtirpc3:1.2.5-1:*:*:*:*:*:*:*",
 23663          "purl": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
 23664          "swid": {
 23665            "attachment": {}
 23666          },
 23667          "pedigree": {},
 23668          "evidence": {},
 23669          "signature": {
 23670            "signature": {
 23671              "publicKey": {}
 23672            }
 23673          },
 23674          "modelCard": {
 23675            "modelParameters": {
 23676              "approach": {}
 23677            },
 23678            "quantitativeAnalysis": {
 23679              "graphics": {}
 23680            },
 23681            "considerations": {}
 23682          }
 23683        },
 23684        {
 23685          "type": "library",
 23686          "bom-ref": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=28d962536291b482",
 23687          "supplier": {},
 23688          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23689          "name": "libudev1",
 23690          "version": "245.4-4ubuntu3.11",
 23691          "licenses": [
 23692            {
 23693              "license": {
 23694                "id": "CC0-1.0"
 23695              }
 23696            },
 23697            {
 23698              "license": {
 23699                "name": "Expat"
 23700              }
 23701            },
 23702            {
 23703              "license": {
 23704                "id": "GPL-2.0-only"
 23705              }
 23706            },
 23707            {
 23708              "license": {
 23709                "id": "GPL-2.0-or-later"
 23710              }
 23711            },
 23712            {
 23713              "license": {
 23714                "id": "LGPL-2.1-only"
 23715              }
 23716            },
 23717            {
 23718              "license": {
 23719                "id": "LGPL-2.1-or-later"
 23720              }
 23721            },
 23722            {
 23723              "license": {
 23724                "name": "public-domain"
 23725              }
 23726            }
 23727          ],
 23728          "cpe": "cpe:2.3:a:libudev1:libudev1:245.4-4ubuntu3.11:*:*:*:*:*:*:*",
 23729          "purl": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
 23730          "swid": {
 23731            "attachment": {}
 23732          },
 23733          "pedigree": {},
 23734          "evidence": {},
 23735          "signature": {
 23736            "signature": {
 23737              "publicKey": {}
 23738            }
 23739          },
 23740          "modelCard": {
 23741            "modelParameters": {
 23742              "approach": {}
 23743            },
 23744            "quantitativeAnalysis": {
 23745              "graphics": {}
 23746            },
 23747            "considerations": {}
 23748          }
 23749        },
 23750        {
 23751          "type": "library",
 23752          "bom-ref": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04\u0026package-id=3140ffa70dcd9831",
 23753          "supplier": {},
 23754          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23755          "name": "libunistring2",
 23756          "version": "0.9.10-2",
 23757          "licenses": [
 23758            {
 23759              "license": {
 23760                "name": "FreeSoftware"
 23761              }
 23762            },
 23763            {
 23764              "license": {
 23765                "id": "GFDL-1.2-only"
 23766              }
 23767            },
 23768            {
 23769              "license": {
 23770                "name": "GFDL-1.2+"
 23771              }
 23772            },
 23773            {
 23774              "license": {
 23775                "id": "GPL-2.0-only"
 23776              }
 23777            },
 23778            {
 23779              "license": {
 23780                "id": "GPL-2.0-or-later"
 23781              }
 23782            },
 23783            {
 23784              "license": {
 23785                "id": "GPL-3.0-only"
 23786              }
 23787            },
 23788            {
 23789              "license": {
 23790                "id": "GPL-3.0-or-later"
 23791              }
 23792            },
 23793            {
 23794              "license": {
 23795                "id": "LGPL-3.0-only"
 23796              }
 23797            },
 23798            {
 23799              "license": {
 23800                "id": "LGPL-3.0-or-later"
 23801              }
 23802            },
 23803            {
 23804              "license": {
 23805                "id": "MIT"
 23806              }
 23807            }
 23808          ],
 23809          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-2:*:*:*:*:*:*:*",
 23810          "purl": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04",
 23811          "swid": {
 23812            "attachment": {}
 23813          },
 23814          "pedigree": {},
 23815          "evidence": {},
 23816          "signature": {
 23817            "signature": {
 23818              "publicKey": {}
 23819            }
 23820          },
 23821          "modelCard": {
 23822            "modelParameters": {
 23823              "approach": {}
 23824            },
 23825            "quantitativeAnalysis": {
 23826              "graphics": {}
 23827            },
 23828            "considerations": {}
 23829          }
 23830        },
 23831        {
 23832          "type": "library",
 23833          "bom-ref": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=5395a07c00002ea6",
 23834          "supplier": {},
 23835          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23836          "name": "libuuid1",
 23837          "version": "2.34-0.1ubuntu9.1",
 23838          "licenses": [
 23839            {
 23840              "license": {
 23841                "id": "BSD-2-Clause"
 23842              }
 23843            },
 23844            {
 23845              "license": {
 23846                "id": "BSD-3-Clause"
 23847              }
 23848            },
 23849            {
 23850              "license": {
 23851                "id": "BSD-4-Clause"
 23852              }
 23853            },
 23854            {
 23855              "license": {
 23856                "id": "GPL-2.0-only"
 23857              }
 23858            },
 23859            {
 23860              "license": {
 23861                "id": "GPL-2.0-or-later"
 23862              }
 23863            },
 23864            {
 23865              "license": {
 23866                "id": "GPL-3.0-only"
 23867              }
 23868            },
 23869            {
 23870              "license": {
 23871                "id": "GPL-3.0-or-later"
 23872              }
 23873            },
 23874            {
 23875              "license": {
 23876                "name": "LGPL"
 23877              }
 23878            },
 23879            {
 23880              "license": {
 23881                "id": "LGPL-2.0-only"
 23882              }
 23883            },
 23884            {
 23885              "license": {
 23886                "id": "LGPL-2.0-or-later"
 23887              }
 23888            },
 23889            {
 23890              "license": {
 23891                "id": "LGPL-2.1-only"
 23892              }
 23893            },
 23894            {
 23895              "license": {
 23896                "id": "LGPL-2.1-or-later"
 23897              }
 23898            },
 23899            {
 23900              "license": {
 23901                "id": "LGPL-3.0-only"
 23902              }
 23903            },
 23904            {
 23905              "license": {
 23906                "id": "LGPL-3.0-or-later"
 23907              }
 23908            },
 23909            {
 23910              "license": {
 23911                "id": "MIT"
 23912              }
 23913            },
 23914            {
 23915              "license": {
 23916                "name": "public-domain"
 23917              }
 23918            }
 23919          ],
 23920          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 23921          "purl": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 23922          "swid": {
 23923            "attachment": {}
 23924          },
 23925          "pedigree": {},
 23926          "evidence": {},
 23927          "signature": {
 23928            "signature": {
 23929              "publicKey": {}
 23930            }
 23931          },
 23932          "modelCard": {
 23933            "modelParameters": {
 23934              "approach": {}
 23935            },
 23936            "quantitativeAnalysis": {
 23937              "graphics": {}
 23938            },
 23939            "considerations": {}
 23940          }
 23941        },
 23942        {
 23943          "type": "library",
 23944          "bom-ref": "pkg:deb/ubuntu/libuv1@1.34.2-1ubuntu1.3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a5e622ae2f2a04fd",
 23945          "supplier": {},
 23946          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 23947          "name": "libuv1",
 23948          "version": "1.34.2-1ubuntu1.3",
 23949          "licenses": [
 23950            {
 23951              "license": {
 23952                "id": "BSD-1-Clause"
 23953              }
 23954            },
 23955            {
 23956              "license": {
 23957                "id": "BSD-2-Clause"
 23958              }
 23959            },
 23960            {
 23961              "license": {
 23962                "id": "BSD-3-Clause"
 23963              }
 23964            },
 23965            {
 23966              "license": {
 23967                "id": "CC-BY-4.0"
 23968              }
 23969            },
 23970            {
 23971              "license": {
 23972                "name": "Expat"
 23973              }
 23974            },
 23975            {
 23976              "license": {
 23977                "id": "GPL-3.0-only"
 23978              }
 23979            },
 23980            {
 23981              "license": {
 23982                "id": "GPL-3.0-or-later"
 23983              }
 23984            },
 23985            {
 23986              "license": {
 23987                "id": "ISC"
 23988              }
 23989            }
 23990          ],
 23991          "cpe": "cpe:2.3:a:libuv1:libuv1:1.34.2-1ubuntu1.3:*:*:*:*:*:*:*",
 23992          "purl": "pkg:deb/ubuntu/libuv1@1.34.2-1ubuntu1.3?arch=amd64\u0026distro=ubuntu-20.04",
 23993          "swid": {
 23994            "attachment": {}
 23995          },
 23996          "pedigree": {},
 23997          "evidence": {},
 23998          "signature": {
 23999            "signature": {
 24000              "publicKey": {}
 24001            }
 24002          },
 24003          "modelCard": {
 24004            "modelParameters": {
 24005              "approach": {}
 24006            },
 24007            "quantitativeAnalysis": {
 24008              "graphics": {}
 24009            },
 24010            "considerations": {}
 24011          }
 24012        },
 24013        {
 24014          "type": "library",
 24015          "bom-ref": "pkg:deb/ubuntu/libvorbis0a@1.3.6-2ubuntu1?arch=amd64\u0026upstream=libvorbis\u0026distro=ubuntu-20.04\u0026package-id=dfd7443230481b4d",
 24016          "supplier": {},
 24017          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24018          "name": "libvorbis0a",
 24019          "version": "1.3.6-2ubuntu1",
 24020          "licenses": [
 24021            {
 24022              "license": {
 24023                "id": "BSD-3-Clause"
 24024              }
 24025            },
 24026            {
 24027              "license": {
 24028                "name": "RFC-special"
 24029              }
 24030            }
 24031          ],
 24032          "cpe": "cpe:2.3:a:libvorbis0a:libvorbis0a:1.3.6-2ubuntu1:*:*:*:*:*:*:*",
 24033          "purl": "pkg:deb/ubuntu/libvorbis0a@1.3.6-2ubuntu1?arch=amd64\u0026upstream=libvorbis\u0026distro=ubuntu-20.04",
 24034          "swid": {
 24035            "attachment": {}
 24036          },
 24037          "pedigree": {},
 24038          "evidence": {},
 24039          "signature": {
 24040            "signature": {
 24041              "publicKey": {}
 24042            }
 24043          },
 24044          "modelCard": {
 24045            "modelParameters": {
 24046              "approach": {}
 24047            },
 24048            "quantitativeAnalysis": {
 24049              "graphics": {}
 24050            },
 24051            "considerations": {}
 24052          }
 24053        },
 24054        {
 24055          "type": "library",
 24056          "bom-ref": "pkg:deb/ubuntu/libvorbisfile3@1.3.6-2ubuntu1?arch=amd64\u0026upstream=libvorbis\u0026distro=ubuntu-20.04\u0026package-id=804383bb11c2f3f9",
 24057          "supplier": {},
 24058          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24059          "name": "libvorbisfile3",
 24060          "version": "1.3.6-2ubuntu1",
 24061          "licenses": [
 24062            {
 24063              "license": {
 24064                "id": "BSD-3-Clause"
 24065              }
 24066            },
 24067            {
 24068              "license": {
 24069                "name": "RFC-special"
 24070              }
 24071            }
 24072          ],
 24073          "cpe": "cpe:2.3:a:libvorbisfile3:libvorbisfile3:1.3.6-2ubuntu1:*:*:*:*:*:*:*",
 24074          "purl": "pkg:deb/ubuntu/libvorbisfile3@1.3.6-2ubuntu1?arch=amd64\u0026upstream=libvorbis\u0026distro=ubuntu-20.04",
 24075          "swid": {
 24076            "attachment": {}
 24077          },
 24078          "pedigree": {},
 24079          "evidence": {},
 24080          "signature": {
 24081            "signature": {
 24082              "publicKey": {}
 24083            }
 24084          },
 24085          "modelCard": {
 24086            "modelParameters": {
 24087              "approach": {}
 24088            },
 24089            "quantitativeAnalysis": {
 24090              "graphics": {}
 24091            },
 24092            "considerations": {}
 24093          }
 24094        },
 24095        {
 24096          "type": "library",
 24097          "bom-ref": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=7b0e172efdb36a99",
 24098          "supplier": {},
 24099          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24100          "name": "libwind0-heimdal",
 24101          "version": "7.7.0+dfsg-1ubuntu1",
 24102          "licenses": [
 24103            {
 24104              "license": {
 24105                "id": "BSD-3-Clause"
 24106              }
 24107            },
 24108            {
 24109              "license": {
 24110                "id": "GPL-2.0-only"
 24111              }
 24112            },
 24113            {
 24114              "license": {
 24115                "id": "GPL-2.0-or-later"
 24116              }
 24117            },
 24118            {
 24119              "license": {
 24120                "name": "custom"
 24121              }
 24122            }
 24123          ],
 24124          "cpe": "cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 24125          "purl": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 24126          "swid": {
 24127            "attachment": {}
 24128          },
 24129          "pedigree": {},
 24130          "evidence": {},
 24131          "signature": {
 24132            "signature": {
 24133              "publicKey": {}
 24134            }
 24135          },
 24136          "modelCard": {
 24137            "modelParameters": {
 24138              "approach": {}
 24139            },
 24140            "quantitativeAnalysis": {
 24141              "graphics": {}
 24142            },
 24143            "considerations": {}
 24144          }
 24145        },
 24146        {
 24147          "type": "library",
 24148          "bom-ref": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04\u0026package-id=5b14391c61bb94f1",
 24149          "supplier": {},
 24150          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24151          "name": "libwrap0",
 24152          "version": "7.6.q-30",
 24153          "cpe": "cpe:2.3:a:libwrap0:libwrap0:7.6.q-30:*:*:*:*:*:*:*",
 24154          "purl": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04",
 24155          "swid": {
 24156            "attachment": {}
 24157          },
 24158          "pedigree": {},
 24159          "evidence": {},
 24160          "signature": {
 24161            "signature": {
 24162              "publicKey": {}
 24163            }
 24164          },
 24165          "modelCard": {
 24166            "modelParameters": {
 24167              "approach": {}
 24168            },
 24169            "quantitativeAnalysis": {
 24170              "graphics": {}
 24171            },
 24172            "considerations": {}
 24173          }
 24174        },
 24175        {
 24176          "type": "library",
 24177          "bom-ref": "pkg:deb/ubuntu/libxml2@2.9.10+dfsg-5ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=5227ee2e55b78734",
 24178          "supplier": {},
 24179          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24180          "name": "libxml2",
 24181          "version": "2.9.10+dfsg-5ubuntu0.20.04.1",
 24182          "licenses": [
 24183            {
 24184              "license": {
 24185                "id": "ISC"
 24186              }
 24187            },
 24188            {
 24189              "license": {
 24190                "name": "MIT-1"
 24191              }
 24192            }
 24193          ],
 24194          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.10\\+dfsg-5ubuntu0.20.04.1:*:*:*:*:*:*:*",
 24195          "purl": "pkg:deb/ubuntu/libxml2@2.9.10+dfsg-5ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
 24196          "swid": {
 24197            "attachment": {}
 24198          },
 24199          "pedigree": {},
 24200          "evidence": {},
 24201          "signature": {
 24202            "signature": {
 24203              "publicKey": {}
 24204            }
 24205          },
 24206          "modelCard": {
 24207            "modelParameters": {
 24208              "approach": {}
 24209            },
 24210            "quantitativeAnalysis": {
 24211              "graphics": {}
 24212            },
 24213            "considerations": {}
 24214          }
 24215        },
 24216        {
 24217          "type": "library",
 24218          "bom-ref": "pkg:deb/ubuntu/libxtables12@1.8.4-3ubuntu2?arch=amd64\u0026upstream=iptables\u0026distro=ubuntu-20.04\u0026package-id=440c57e95fc3a35c",
 24219          "supplier": {},
 24220          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24221          "name": "libxtables12",
 24222          "version": "1.8.4-3ubuntu2",
 24223          "licenses": [
 24224            {
 24225              "license": {
 24226                "name": "Artistic"
 24227              }
 24228            },
 24229            {
 24230              "license": {
 24231                "id": "GPL-2.0-only"
 24232              }
 24233            },
 24234            {
 24235              "license": {
 24236                "id": "GPL-2.0-or-later"
 24237              }
 24238            },
 24239            {
 24240              "license": {
 24241                "name": "custom"
 24242              }
 24243            }
 24244          ],
 24245          "cpe": "cpe:2.3:a:libxtables12:libxtables12:1.8.4-3ubuntu2:*:*:*:*:*:*:*",
 24246          "purl": "pkg:deb/ubuntu/libxtables12@1.8.4-3ubuntu2?arch=amd64\u0026upstream=iptables\u0026distro=ubuntu-20.04",
 24247          "swid": {
 24248            "attachment": {}
 24249          },
 24250          "pedigree": {},
 24251          "evidence": {},
 24252          "signature": {
 24253            "signature": {
 24254              "publicKey": {}
 24255            }
 24256          },
 24257          "modelCard": {
 24258            "modelParameters": {
 24259              "approach": {}
 24260            },
 24261            "quantitativeAnalysis": {
 24262              "graphics": {}
 24263            },
 24264            "considerations": {}
 24265          }
 24266        },
 24267        {
 24268          "type": "library",
 24269          "bom-ref": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04\u0026package-id=47cff0564e160066",
 24270          "supplier": {},
 24271          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24272          "name": "libzstd1",
 24273          "version": "1.4.4+dfsg-3ubuntu0.1",
 24274          "licenses": [
 24275            {
 24276              "license": {
 24277                "id": "BSD-3-Clause"
 24278              }
 24279            },
 24280            {
 24281              "license": {
 24282                "name": "Expat"
 24283              }
 24284            },
 24285            {
 24286              "license": {
 24287                "id": "GPL-2.0-only"
 24288              }
 24289            },
 24290            {
 24291              "license": {
 24292                "id": "GPL-2.0-or-later"
 24293              }
 24294            },
 24295            {
 24296              "license": {
 24297                "id": "Zlib"
 24298              }
 24299            }
 24300          ],
 24301          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.4\\+dfsg-3ubuntu0.1:*:*:*:*:*:*:*",
 24302          "purl": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04",
 24303          "swid": {
 24304            "attachment": {}
 24305          },
 24306          "pedigree": {},
 24307          "evidence": {},
 24308          "signature": {
 24309            "signature": {
 24310              "publicKey": {}
 24311            }
 24312          },
 24313          "modelCard": {
 24314            "modelParameters": {
 24315              "approach": {}
 24316            },
 24317            "quantitativeAnalysis": {
 24318              "graphics": {}
 24319            },
 24320            "considerations": {}
 24321          }
 24322        },
 24323        {
 24324          "type": "library",
 24325          "bom-ref": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=cb23947502a7c38d",
 24326          "supplier": {},
 24327          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24328          "name": "login",
 24329          "version": "1:4.8.1-1ubuntu5.20.04.1",
 24330          "licenses": [
 24331            {
 24332              "license": {
 24333                "id": "GPL-2.0-only"
 24334              }
 24335            }
 24336          ],
 24337          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
 24338          "purl": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
 24339          "swid": {
 24340            "attachment": {}
 24341          },
 24342          "pedigree": {},
 24343          "evidence": {},
 24344          "signature": {
 24345            "signature": {
 24346              "publicKey": {}
 24347            }
 24348          },
 24349          "modelCard": {
 24350            "modelParameters": {
 24351              "approach": {}
 24352            },
 24353            "quantitativeAnalysis": {
 24354              "graphics": {}
 24355            },
 24356            "considerations": {}
 24357          }
 24358        },
 24359        {
 24360          "type": "library",
 24361          "bom-ref": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4a92556bee4b4f91",
 24362          "supplier": {},
 24363          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24364          "name": "logsave",
 24365          "version": "1.45.5-2ubuntu1",
 24366          "licenses": [
 24367            {
 24368              "license": {
 24369                "id": "GPL-2.0-only"
 24370              }
 24371            },
 24372            {
 24373              "license": {
 24374                "id": "LGPL-2.0-only"
 24375              }
 24376            }
 24377          ],
 24378          "cpe": "cpe:2.3:a:logsave:logsave:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 24379          "purl": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 24380          "swid": {
 24381            "attachment": {}
 24382          },
 24383          "pedigree": {},
 24384          "evidence": {},
 24385          "signature": {
 24386            "signature": {
 24387              "publicKey": {}
 24388            }
 24389          },
 24390          "modelCard": {
 24391            "modelParameters": {
 24392              "approach": {}
 24393            },
 24394            "quantitativeAnalysis": {
 24395              "graphics": {}
 24396            },
 24397            "considerations": {}
 24398          }
 24399        },
 24400        {
 24401          "type": "library",
 24402          "bom-ref": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04\u0026package-id=b76348b7f1282c61",
 24403          "supplier": {},
 24404          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24405          "name": "lsb-base",
 24406          "version": "11.1.0ubuntu2",
 24407          "licenses": [
 24408            {
 24409              "license": {
 24410                "id": "BSD-3-Clause"
 24411              }
 24412            },
 24413            {
 24414              "license": {
 24415                "id": "GPL-2.0-only"
 24416              }
 24417            }
 24418          ],
 24419          "cpe": "cpe:2.3:a:lsb-base:lsb-base:11.1.0ubuntu2:*:*:*:*:*:*:*",
 24420          "purl": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04",
 24421          "swid": {
 24422            "attachment": {}
 24423          },
 24424          "pedigree": {},
 24425          "evidence": {},
 24426          "signature": {
 24427            "signature": {
 24428              "publicKey": {}
 24429            }
 24430          },
 24431          "modelCard": {
 24432            "modelParameters": {
 24433              "approach": {}
 24434            },
 24435            "quantitativeAnalysis": {
 24436              "graphics": {}
 24437            },
 24438            "considerations": {}
 24439          }
 24440        },
 24441        {
 24442          "type": "library",
 24443          "bom-ref": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=435885c82afbf721",
 24444          "supplier": {},
 24445          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24446          "name": "mawk",
 24447          "version": "1.3.4.20200120-2",
 24448          "licenses": [
 24449            {
 24450              "license": {
 24451                "id": "GPL-2.0-only"
 24452              }
 24453            }
 24454          ],
 24455          "cpe": "cpe:2.3:a:mawk:mawk:1.3.4.20200120-2:*:*:*:*:*:*:*",
 24456          "purl": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04",
 24457          "swid": {
 24458            "attachment": {}
 24459          },
 24460          "pedigree": {},
 24461          "evidence": {},
 24462          "signature": {
 24463            "signature": {
 24464              "publicKey": {}
 24465            }
 24466          },
 24467          "modelCard": {
 24468            "modelParameters": {
 24469              "approach": {}
 24470            },
 24471            "quantitativeAnalysis": {
 24472              "graphics": {}
 24473            },
 24474            "considerations": {}
 24475          }
 24476        },
 24477        {
 24478          "type": "library",
 24479          "bom-ref": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=405891a224258a92",
 24480          "supplier": {},
 24481          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24482          "name": "mime-support",
 24483          "version": "3.64ubuntu1",
 24484          "licenses": [
 24485            {
 24486              "license": {
 24487                "name": "Bellcore"
 24488              }
 24489            },
 24490            {
 24491              "license": {
 24492                "name": "ad-hoc"
 24493              }
 24494            }
 24495          ],
 24496          "cpe": "cpe:2.3:a:mime-support:mime-support:3.64ubuntu1:*:*:*:*:*:*:*",
 24497          "purl": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04",
 24498          "swid": {
 24499            "attachment": {}
 24500          },
 24501          "pedigree": {},
 24502          "evidence": {},
 24503          "signature": {
 24504            "signature": {
 24505              "publicKey": {}
 24506            }
 24507          },
 24508          "modelCard": {
 24509            "modelParameters": {
 24510              "approach": {}
 24511            },
 24512            "quantitativeAnalysis": {
 24513              "graphics": {}
 24514            },
 24515            "considerations": {}
 24516          }
 24517        },
 24518        {
 24519          "type": "library",
 24520          "bom-ref": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=fa4ef6b12af7900c",
 24521          "supplier": {},
 24522          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24523          "name": "mount",
 24524          "version": "2.34-0.1ubuntu9.1",
 24525          "licenses": [
 24526            {
 24527              "license": {
 24528                "id": "BSD-2-Clause"
 24529              }
 24530            },
 24531            {
 24532              "license": {
 24533                "id": "BSD-3-Clause"
 24534              }
 24535            },
 24536            {
 24537              "license": {
 24538                "id": "BSD-4-Clause"
 24539              }
 24540            },
 24541            {
 24542              "license": {
 24543                "id": "GPL-2.0-only"
 24544              }
 24545            },
 24546            {
 24547              "license": {
 24548                "id": "GPL-2.0-or-later"
 24549              }
 24550            },
 24551            {
 24552              "license": {
 24553                "id": "GPL-3.0-only"
 24554              }
 24555            },
 24556            {
 24557              "license": {
 24558                "id": "GPL-3.0-or-later"
 24559              }
 24560            },
 24561            {
 24562              "license": {
 24563                "name": "LGPL"
 24564              }
 24565            },
 24566            {
 24567              "license": {
 24568                "id": "LGPL-2.0-only"
 24569              }
 24570            },
 24571            {
 24572              "license": {
 24573                "id": "LGPL-2.0-or-later"
 24574              }
 24575            },
 24576            {
 24577              "license": {
 24578                "id": "LGPL-2.1-only"
 24579              }
 24580            },
 24581            {
 24582              "license": {
 24583                "id": "LGPL-2.1-or-later"
 24584              }
 24585            },
 24586            {
 24587              "license": {
 24588                "id": "LGPL-3.0-only"
 24589              }
 24590            },
 24591            {
 24592              "license": {
 24593                "id": "LGPL-3.0-or-later"
 24594              }
 24595            },
 24596            {
 24597              "license": {
 24598                "id": "MIT"
 24599              }
 24600            },
 24601            {
 24602              "license": {
 24603                "name": "public-domain"
 24604              }
 24605            }
 24606          ],
 24607          "cpe": "cpe:2.3:a:mount:mount:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 24608          "purl": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 24609          "swid": {
 24610            "attachment": {}
 24611          },
 24612          "pedigree": {},
 24613          "evidence": {},
 24614          "signature": {
 24615            "signature": {
 24616              "publicKey": {}
 24617            }
 24618          },
 24619          "modelCard": {
 24620            "modelParameters": {
 24621              "approach": {}
 24622            },
 24623            "quantitativeAnalysis": {
 24624              "graphics": {}
 24625            },
 24626            "considerations": {}
 24627          }
 24628        },
 24629        {
 24630          "type": "library",
 24631          "bom-ref": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d7393defd95e4554",
 24632          "supplier": {},
 24633          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24634          "name": "ncurses-base",
 24635          "version": "6.2-0ubuntu2",
 24636          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.2-0ubuntu2:*:*:*:*:*:*:*",
 24637          "purl": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 24638          "swid": {
 24639            "attachment": {}
 24640          },
 24641          "pedigree": {},
 24642          "evidence": {},
 24643          "signature": {
 24644            "signature": {
 24645              "publicKey": {}
 24646            }
 24647          },
 24648          "modelCard": {
 24649            "modelParameters": {
 24650              "approach": {}
 24651            },
 24652            "quantitativeAnalysis": {
 24653              "graphics": {}
 24654            },
 24655            "considerations": {}
 24656          }
 24657        },
 24658        {
 24659          "type": "library",
 24660          "bom-ref": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d6bdd43961b680f6",
 24661          "supplier": {},
 24662          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24663          "name": "ncurses-bin",
 24664          "version": "6.2-0ubuntu2",
 24665          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.2-0ubuntu2:*:*:*:*:*:*:*",
 24666          "purl": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 24667          "swid": {
 24668            "attachment": {}
 24669          },
 24670          "pedigree": {},
 24671          "evidence": {},
 24672          "signature": {
 24673            "signature": {
 24674              "publicKey": {}
 24675            }
 24676          },
 24677          "modelCard": {
 24678            "modelParameters": {
 24679              "approach": {}
 24680            },
 24681            "quantitativeAnalysis": {
 24682              "graphics": {}
 24683            },
 24684            "considerations": {}
 24685          }
 24686        },
 24687        {
 24688          "type": "library",
 24689          "bom-ref": "pkg:deb/ubuntu/netbase@6.1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=c6847a50307ac1ba",
 24690          "supplier": {},
 24691          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24692          "name": "netbase",
 24693          "version": "6.1",
 24694          "licenses": [
 24695            {
 24696              "license": {
 24697                "id": "GPL-2.0-only"
 24698              }
 24699            }
 24700          ],
 24701          "cpe": "cpe:2.3:a:netbase:netbase:6.1:*:*:*:*:*:*:*",
 24702          "purl": "pkg:deb/ubuntu/netbase@6.1?arch=all\u0026distro=ubuntu-20.04",
 24703          "swid": {
 24704            "attachment": {}
 24705          },
 24706          "pedigree": {},
 24707          "evidence": {},
 24708          "signature": {
 24709            "signature": {
 24710              "publicKey": {}
 24711            }
 24712          },
 24713          "modelCard": {
 24714            "modelParameters": {
 24715              "approach": {}
 24716            },
 24717            "quantitativeAnalysis": {
 24718              "graphics": {}
 24719            },
 24720            "considerations": {}
 24721          }
 24722        },
 24723        {
 24724          "type": "library",
 24725          "bom-ref": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04\u0026package-id=6a00c331080f32b7",
 24726          "supplier": {},
 24727          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24728          "name": "nfs-common",
 24729          "version": "1:1.3.4-2.5ubuntu3.4",
 24730          "licenses": [
 24731            {
 24732              "license": {
 24733                "id": "GPL-2.0-only"
 24734              }
 24735            }
 24736          ],
 24737          "cpe": "cpe:2.3:a:nfs-common:nfs-common:1\\:1.3.4-2.5ubuntu3.4:*:*:*:*:*:*:*",
 24738          "purl": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04",
 24739          "swid": {
 24740            "attachment": {}
 24741          },
 24742          "pedigree": {},
 24743          "evidence": {},
 24744          "signature": {
 24745            "signature": {
 24746              "publicKey": {}
 24747            }
 24748          },
 24749          "modelCard": {
 24750            "modelParameters": {
 24751              "approach": {}
 24752            },
 24753            "quantitativeAnalysis": {
 24754              "graphics": {}
 24755            },
 24756            "considerations": {}
 24757          }
 24758        },
 24759        {
 24760          "type": "library",
 24761          "bom-ref": "pkg:deb/ubuntu/openssl@1.1.1f-1ubuntu2.8?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=5727f60759ec90aa",
 24762          "supplier": {},
 24763          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24764          "name": "openssl",
 24765          "version": "1.1.1f-1ubuntu2.8",
 24766          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1f-1ubuntu2.8:*:*:*:*:*:*:*",
 24767          "purl": "pkg:deb/ubuntu/openssl@1.1.1f-1ubuntu2.8?arch=amd64\u0026distro=ubuntu-20.04",
 24768          "swid": {
 24769            "attachment": {}
 24770          },
 24771          "pedigree": {},
 24772          "evidence": {},
 24773          "signature": {
 24774            "signature": {
 24775              "publicKey": {}
 24776            }
 24777          },
 24778          "modelCard": {
 24779            "modelParameters": {
 24780              "approach": {}
 24781            },
 24782            "quantitativeAnalysis": {
 24783              "graphics": {}
 24784            },
 24785            "considerations": {}
 24786          }
 24787        },
 24788        {
 24789          "type": "library",
 24790          "bom-ref": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=c4a1ed5267891532",
 24791          "supplier": {},
 24792          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24793          "name": "passwd",
 24794          "version": "1:4.8.1-1ubuntu5.20.04.1",
 24795          "licenses": [
 24796            {
 24797              "license": {
 24798                "id": "GPL-2.0-only"
 24799              }
 24800            }
 24801          ],
 24802          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
 24803          "purl": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
 24804          "swid": {
 24805            "attachment": {}
 24806          },
 24807          "pedigree": {},
 24808          "evidence": {},
 24809          "signature": {
 24810            "signature": {
 24811              "publicKey": {}
 24812            }
 24813          },
 24814          "modelCard": {
 24815            "modelParameters": {
 24816              "approach": {}
 24817            },
 24818            "quantitativeAnalysis": {
 24819              "graphics": {}
 24820            },
 24821            "considerations": {}
 24822          }
 24823        },
 24824        {
 24825          "type": "library",
 24826          "bom-ref": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=eab1752e76cf29f",
 24827          "supplier": {},
 24828          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24829          "name": "perl-base",
 24830          "version": "5.30.0-9ubuntu0.2",
 24831          "licenses": [
 24832            {
 24833              "license": {
 24834                "name": "Artistic"
 24835              }
 24836            },
 24837            {
 24838              "license": {
 24839                "id": "Artistic-2.0"
 24840              }
 24841            },
 24842            {
 24843              "license": {
 24844                "name": "Artistic-dist"
 24845              }
 24846            },
 24847            {
 24848              "license": {
 24849                "id": "BSD-3-Clause"
 24850              }
 24851            },
 24852            {
 24853              "license": {
 24854                "name": "BSD-3-clause-GENERIC"
 24855              }
 24856            },
 24857            {
 24858              "license": {
 24859                "name": "BSD-3-clause-with-weird-numbering"
 24860              }
 24861            },
 24862            {
 24863              "license": {
 24864                "name": "BSD-4-clause-POWERDOG"
 24865              }
 24866            },
 24867            {
 24868              "license": {
 24869                "name": "BZIP"
 24870              }
 24871            },
 24872            {
 24873              "license": {
 24874                "name": "DONT-CHANGE-THE-GPL"
 24875              }
 24876            },
 24877            {
 24878              "license": {
 24879                "name": "Expat"
 24880              }
 24881            },
 24882            {
 24883              "license": {
 24884                "id": "GPL-1.0-only"
 24885              }
 24886            },
 24887            {
 24888              "license": {
 24889                "id": "GPL-1.0-or-later"
 24890              }
 24891            },
 24892            {
 24893              "license": {
 24894                "id": "GPL-2.0-only"
 24895              }
 24896            },
 24897            {
 24898              "license": {
 24899                "id": "GPL-2.0-or-later"
 24900              }
 24901            },
 24902            {
 24903              "license": {
 24904                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 24905              }
 24906            },
 24907            {
 24908              "license": {
 24909                "name": "HSIEH-BSD"
 24910              }
 24911            },
 24912            {
 24913              "license": {
 24914                "name": "HSIEH-DERIVATIVE"
 24915              }
 24916            },
 24917            {
 24918              "license": {
 24919                "id": "LGPL-2.1-only"
 24920              }
 24921            },
 24922            {
 24923              "license": {
 24924                "name": "REGCOMP"
 24925              }
 24926            },
 24927            {
 24928              "license": {
 24929                "name": "REGCOMP,"
 24930              }
 24931            },
 24932            {
 24933              "license": {
 24934                "name": "RRA-KEEP-THIS-NOTICE"
 24935              }
 24936            },
 24937            {
 24938              "license": {
 24939                "name": "SDBM-PUBLIC-DOMAIN"
 24940              }
 24941            },
 24942            {
 24943              "license": {
 24944                "name": "TEXT-TABS"
 24945              }
 24946            },
 24947            {
 24948              "license": {
 24949                "name": "Unicode"
 24950              }
 24951            },
 24952            {
 24953              "license": {
 24954                "id": "Zlib"
 24955              }
 24956            }
 24957          ],
 24958          "cpe": "cpe:2.3:a:perl-base:perl-base:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
 24959          "purl": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04",
 24960          "swid": {
 24961            "attachment": {}
 24962          },
 24963          "pedigree": {},
 24964          "evidence": {},
 24965          "signature": {
 24966            "signature": {
 24967              "publicKey": {}
 24968            }
 24969          },
 24970          "modelCard": {
 24971            "modelParameters": {
 24972              "approach": {}
 24973            },
 24974            "quantitativeAnalysis": {
 24975              "graphics": {}
 24976            },
 24977            "considerations": {}
 24978          }
 24979        },
 24980        {
 24981          "type": "library",
 24982          "bom-ref": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f177d21a50776ea7",
 24983          "supplier": {},
 24984          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 24985          "name": "procps",
 24986          "version": "2:3.3.16-1ubuntu2.2",
 24987          "licenses": [
 24988            {
 24989              "license": {
 24990                "id": "GPL-2.0-only"
 24991              }
 24992            },
 24993            {
 24994              "license": {
 24995                "id": "GPL-2.0-or-later"
 24996              }
 24997            },
 24998            {
 24999              "license": {
 25000                "id": "LGPL-2.0-only"
 25001              }
 25002            },
 25003            {
 25004              "license": {
 25005                "id": "LGPL-2.0-or-later"
 25006              }
 25007            },
 25008            {
 25009              "license": {
 25010                "id": "LGPL-2.1-only"
 25011              }
 25012            },
 25013            {
 25014              "license": {
 25015                "id": "LGPL-2.1-or-later"
 25016              }
 25017            }
 25018          ],
 25019          "cpe": "cpe:2.3:a:procps:procps:2\\:3.3.16-1ubuntu2.2:*:*:*:*:*:*:*",
 25020          "purl": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.2?arch=amd64\u0026distro=ubuntu-20.04",
 25021          "swid": {
 25022            "attachment": {}
 25023          },
 25024          "pedigree": {},
 25025          "evidence": {},
 25026          "signature": {
 25027            "signature": {
 25028              "publicKey": {}
 25029            }
 25030          },
 25031          "modelCard": {
 25032            "modelParameters": {
 25033              "approach": {}
 25034            },
 25035            "quantitativeAnalysis": {
 25036              "graphics": {}
 25037            },
 25038            "considerations": {}
 25039          }
 25040        },
 25041        {
 25042          "type": "library",
 25043          "bom-ref": "pkg:deb/ubuntu/publicsuffix@20200303.0012-1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=fe371293cddb3ef3",
 25044          "supplier": {},
 25045          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25046          "name": "publicsuffix",
 25047          "version": "20200303.0012-1",
 25048          "licenses": [
 25049            {
 25050              "license": {
 25051                "name": "CC0"
 25052              }
 25053            },
 25054            {
 25055              "license": {
 25056                "id": "MPL-2.0"
 25057              }
 25058            }
 25059          ],
 25060          "cpe": "cpe:2.3:a:publicsuffix:publicsuffix:20200303.0012-1:*:*:*:*:*:*:*",
 25061          "purl": "pkg:deb/ubuntu/publicsuffix@20200303.0012-1?arch=all\u0026distro=ubuntu-20.04",
 25062          "swid": {
 25063            "attachment": {}
 25064          },
 25065          "pedigree": {},
 25066          "evidence": {},
 25067          "signature": {
 25068            "signature": {
 25069              "publicKey": {}
 25070            }
 25071          },
 25072          "modelCard": {
 25073            "modelParameters": {
 25074              "approach": {}
 25075            },
 25076            "quantitativeAnalysis": {
 25077              "graphics": {}
 25078            },
 25079            "considerations": {}
 25080          }
 25081        },
 25082        {
 25083          "type": "application",
 25084          "bom-ref": "pkg:generic/python@3.8.10?package-id=2fa60a23ba4ecb4c",
 25085          "supplier": {},
 25086          "name": "python",
 25087          "version": "3.8.10",
 25088          "cpe": "cpe:2.3:a:python_software_foundation:python:3.8.10:*:*:*:*:*:*:*",
 25089          "purl": "pkg:generic/python@3.8.10",
 25090          "swid": {
 25091            "attachment": {}
 25092          },
 25093          "pedigree": {},
 25094          "evidence": {},
 25095          "signature": {
 25096            "signature": {
 25097              "publicKey": {}
 25098            }
 25099          },
 25100          "modelCard": {
 25101            "modelParameters": {
 25102              "approach": {}
 25103            },
 25104            "quantitativeAnalysis": {
 25105              "graphics": {}
 25106            },
 25107            "considerations": {}
 25108          }
 25109        },
 25110        {
 25111          "type": "library",
 25112          "bom-ref": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=ca939acbf264771",
 25113          "supplier": {},
 25114          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25115          "name": "python3",
 25116          "version": "3.8.2-0ubuntu2",
 25117          "cpe": "cpe:2.3:a:python3:python3:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
 25118          "purl": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
 25119          "swid": {
 25120            "attachment": {}
 25121          },
 25122          "pedigree": {},
 25123          "evidence": {},
 25124          "signature": {
 25125            "signature": {
 25126              "publicKey": {}
 25127            }
 25128          },
 25129          "modelCard": {
 25130            "modelParameters": {
 25131              "approach": {}
 25132            },
 25133            "quantitativeAnalysis": {
 25134              "graphics": {}
 25135            },
 25136            "considerations": {}
 25137          }
 25138        },
 25139        {
 25140          "type": "library",
 25141          "bom-ref": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=26eebf392e0b02cf",
 25142          "supplier": {},
 25143          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25144          "name": "python3-minimal",
 25145          "version": "3.8.2-0ubuntu2",
 25146          "cpe": "cpe:2.3:a:python3-minimal:python3-minimal:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
 25147          "purl": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
 25148          "swid": {
 25149            "attachment": {}
 25150          },
 25151          "pedigree": {},
 25152          "evidence": {},
 25153          "signature": {
 25154            "signature": {
 25155              "publicKey": {}
 25156            }
 25157          },
 25158          "modelCard": {
 25159            "modelParameters": {
 25160              "approach": {}
 25161            },
 25162            "quantitativeAnalysis": {
 25163              "graphics": {}
 25164            },
 25165            "considerations": {}
 25166          }
 25167        },
 25168        {
 25169          "type": "library",
 25170          "bom-ref": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=b1de928401abc554",
 25171          "supplier": {},
 25172          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25173          "name": "python3.8",
 25174          "version": "3.8.10-0ubuntu1~20.04",
 25175          "licenses": [
 25176            {
 25177              "license": {
 25178                "name": "By"
 25179              }
 25180            },
 25181            {
 25182              "license": {
 25183                "id": "GPL-2.0-only"
 25184              }
 25185            },
 25186            {
 25187              "license": {
 25188                "name": "Permission"
 25189              }
 25190            },
 25191            {
 25192              "license": {
 25193                "name": "Redistribution"
 25194              }
 25195            },
 25196            {
 25197              "license": {
 25198                "name": "This"
 25199              }
 25200            }
 25201          ],
 25202          "cpe": "cpe:2.3:a:python3.8:python3.8:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
 25203          "purl": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026distro=ubuntu-20.04",
 25204          "swid": {
 25205            "attachment": {}
 25206          },
 25207          "pedigree": {},
 25208          "evidence": {},
 25209          "signature": {
 25210            "signature": {
 25211              "publicKey": {}
 25212            }
 25213          },
 25214          "modelCard": {
 25215            "modelParameters": {
 25216              "approach": {}
 25217            },
 25218            "quantitativeAnalysis": {
 25219              "graphics": {}
 25220            },
 25221            "considerations": {}
 25222          }
 25223        },
 25224        {
 25225          "type": "library",
 25226          "bom-ref": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=91fa2bead1762d08",
 25227          "supplier": {},
 25228          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25229          "name": "python3.8-minimal",
 25230          "version": "3.8.10-0ubuntu1~20.04",
 25231          "licenses": [
 25232            {
 25233              "license": {
 25234                "name": "By"
 25235              }
 25236            },
 25237            {
 25238              "license": {
 25239                "id": "GPL-2.0-only"
 25240              }
 25241            },
 25242            {
 25243              "license": {
 25244                "name": "Permission"
 25245              }
 25246            },
 25247            {
 25248              "license": {
 25249                "name": "Redistribution"
 25250              }
 25251            },
 25252            {
 25253              "license": {
 25254                "name": "This"
 25255              }
 25256            }
 25257          ],
 25258          "cpe": "cpe:2.3:a:python3.8-minimal:python3.8-minimal:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
 25259          "purl": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 25260          "swid": {
 25261            "attachment": {}
 25262          },
 25263          "pedigree": {},
 25264          "evidence": {},
 25265          "signature": {
 25266            "signature": {
 25267              "publicKey": {}
 25268            }
 25269          },
 25270          "modelCard": {
 25271            "modelParameters": {
 25272              "approach": {}
 25273            },
 25274            "quantitativeAnalysis": {
 25275              "graphics": {}
 25276            },
 25277            "considerations": {}
 25278          }
 25279        },
 25280        {
 25281          "type": "library",
 25282          "bom-ref": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=34a85b4423ecbe7",
 25283          "supplier": {},
 25284          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25285          "name": "readline-common",
 25286          "version": "8.0-4",
 25287          "licenses": [
 25288            {
 25289              "license": {
 25290                "name": "GFDL"
 25291              }
 25292            },
 25293            {
 25294              "license": {
 25295                "id": "GPL-3.0-only"
 25296              }
 25297            }
 25298          ],
 25299          "cpe": "cpe:2.3:a:readline-common:readline-common:8.0-4:*:*:*:*:*:*:*",
 25300          "purl": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04",
 25301          "swid": {
 25302            "attachment": {}
 25303          },
 25304          "pedigree": {},
 25305          "evidence": {},
 25306          "signature": {
 25307            "signature": {
 25308              "publicKey": {}
 25309            }
 25310          },
 25311          "modelCard": {
 25312            "modelParameters": {
 25313              "approach": {}
 25314            },
 25315            "quantitativeAnalysis": {
 25316              "graphics": {}
 25317            },
 25318            "considerations": {}
 25319          }
 25320        },
 25321        {
 25322          "type": "library",
 25323          "bom-ref": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e98d3334085e4495",
 25324          "supplier": {},
 25325          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25326          "name": "rpcbind",
 25327          "version": "1.2.5-8",
 25328          "licenses": [
 25329            {
 25330              "license": {
 25331                "id": "BSD-3-Clause"
 25332              }
 25333            },
 25334            {
 25335              "license": {
 25336                "id": "BSD-4-Clause"
 25337              }
 25338            },
 25339            {
 25340              "license": {
 25341                "id": "BSD-4-Clause"
 25342              }
 25343            },
 25344            {
 25345              "license": {
 25346                "id": "GPL-2.0-only"
 25347              }
 25348            },
 25349            {
 25350              "license": {
 25351                "id": "GPL-2.0-or-later"
 25352              }
 25353            },
 25354            {
 25355              "license": {
 25356                "id": "GPL-3.0-only"
 25357              }
 25358            },
 25359            {
 25360              "license": {
 25361                "id": "MIT"
 25362              }
 25363            },
 25364            {
 25365              "license": {
 25366                "name": "PERMISSIVE"
 25367              }
 25368            }
 25369          ],
 25370          "cpe": "cpe:2.3:a:rpcbind:rpcbind:1.2.5-8:*:*:*:*:*:*:*",
 25371          "purl": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04",
 25372          "swid": {
 25373            "attachment": {}
 25374          },
 25375          "pedigree": {},
 25376          "evidence": {},
 25377          "signature": {
 25378            "signature": {
 25379              "publicKey": {}
 25380            }
 25381          },
 25382          "modelCard": {
 25383            "modelParameters": {
 25384              "approach": {}
 25385            },
 25386            "quantitativeAnalysis": {
 25387              "graphics": {}
 25388            },
 25389            "considerations": {}
 25390          }
 25391        },
 25392        {
 25393          "type": "library",
 25394          "bom-ref": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=24bbb8989a1870c7",
 25395          "supplier": {},
 25396          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25397          "name": "sed",
 25398          "version": "4.7-1",
 25399          "licenses": [
 25400            {
 25401              "license": {
 25402                "id": "GPL-3.0-only"
 25403              }
 25404            }
 25405          ],
 25406          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
 25407          "purl": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04",
 25408          "swid": {
 25409            "attachment": {}
 25410          },
 25411          "pedigree": {},
 25412          "evidence": {},
 25413          "signature": {
 25414            "signature": {
 25415              "publicKey": {}
 25416            }
 25417          },
 25418          "modelCard": {
 25419            "modelParameters": {
 25420              "approach": {}
 25421            },
 25422            "quantitativeAnalysis": {
 25423              "graphics": {}
 25424            },
 25425            "considerations": {}
 25426          }
 25427        },
 25428        {
 25429          "type": "library",
 25430          "bom-ref": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=7e50cf6ac335106e",
 25431          "supplier": {},
 25432          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25433          "name": "sensible-utils",
 25434          "version": "0.0.12+nmu1",
 25435          "licenses": [
 25436            {
 25437              "license": {
 25438                "name": "All-permissive"
 25439              }
 25440            },
 25441            {
 25442              "license": {
 25443                "id": "GPL-2.0-only"
 25444              }
 25445            },
 25446            {
 25447              "license": {
 25448                "id": "GPL-2.0-or-later"
 25449              }
 25450            },
 25451            {
 25452              "license": {
 25453                "name": "configure"
 25454              }
 25455            },
 25456            {
 25457              "license": {
 25458                "name": "installsh"
 25459              }
 25460            }
 25461          ],
 25462          "cpe": "cpe:2.3:a:sensible-utils:sensible-utils:0.0.12\\+nmu1:*:*:*:*:*:*:*",
 25463          "purl": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04",
 25464          "swid": {
 25465            "attachment": {}
 25466          },
 25467          "pedigree": {},
 25468          "evidence": {},
 25469          "signature": {
 25470            "signature": {
 25471              "publicKey": {}
 25472            }
 25473          },
 25474          "modelCard": {
 25475            "modelParameters": {
 25476              "approach": {}
 25477            },
 25478            "quantitativeAnalysis": {
 25479              "graphics": {}
 25480            },
 25481            "considerations": {}
 25482          }
 25483        },
 25484        {
 25485          "type": "library",
 25486          "bom-ref": "pkg:golang/sigs.k8s.io/structured-merge-diff/v3@v3.0.1?package-id=aabe58be05d8a2fb",
 25487          "supplier": {},
 25488          "name": "sigs.k8s.io/structured-merge-diff/v3",
 25489          "version": "v3.0.1",
 25490          "cpe": "cpe:2.3:a:structured-merge-diff:v3:v3.0.1:*:*:*:*:*:*:*",
 25491          "purl": "pkg:golang/sigs.k8s.io/structured-merge-diff/v3@v3.0.1",
 25492          "swid": {
 25493            "attachment": {}
 25494          },
 25495          "pedigree": {},
 25496          "evidence": {},
 25497          "signature": {
 25498            "signature": {
 25499              "publicKey": {}
 25500            }
 25501          },
 25502          "modelCard": {
 25503            "modelParameters": {
 25504              "approach": {}
 25505            },
 25506            "quantitativeAnalysis": {
 25507              "graphics": {}
 25508            },
 25509            "considerations": {}
 25510          }
 25511        },
 25512        {
 25513          "type": "library",
 25514          "bom-ref": "pkg:golang/sigs.k8s.io/yaml@v1.2.0?package-id=185ad58c0c816b70",
 25515          "supplier": {},
 25516          "name": "sigs.k8s.io/yaml",
 25517          "version": "v1.2.0",
 25518          "purl": "pkg:golang/sigs.k8s.io/yaml@v1.2.0",
 25519          "swid": {
 25520            "attachment": {}
 25521          },
 25522          "pedigree": {},
 25523          "evidence": {},
 25524          "signature": {
 25525            "signature": {
 25526              "publicKey": {}
 25527            }
 25528          },
 25529          "modelCard": {
 25530            "modelParameters": {
 25531              "approach": {}
 25532            },
 25533            "quantitativeAnalysis": {
 25534              "graphics": {}
 25535            },
 25536            "considerations": {}
 25537          }
 25538        },
 25539        {
 25540          "type": "library",
 25541          "bom-ref": "pkg:deb/ubuntu/sound-theme-freedesktop@0.8-2ubuntu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=9f865bbd1b40e79e",
 25542          "supplier": {},
 25543          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25544          "name": "sound-theme-freedesktop",
 25545          "version": "0.8-2ubuntu1",
 25546          "licenses": [
 25547            {
 25548              "license": {
 25549                "id": "CC-BY-3.0"
 25550              }
 25551            },
 25552            {
 25553              "license": {
 25554                "id": "CC-BY-SA-3.0"
 25555              }
 25556            },
 25557            {
 25558              "license": {
 25559                "id": "GPL-2.0-only"
 25560              }
 25561            },
 25562            {
 25563              "license": {
 25564                "id": "GPL-2.0-or-later"
 25565              }
 25566            }
 25567          ],
 25568          "cpe": "cpe:2.3:a:sound-theme-freedesktop:sound-theme-freedesktop:0.8-2ubuntu1:*:*:*:*:*:*:*",
 25569          "purl": "pkg:deb/ubuntu/sound-theme-freedesktop@0.8-2ubuntu1?arch=all\u0026distro=ubuntu-20.04",
 25570          "swid": {
 25571            "attachment": {}
 25572          },
 25573          "pedigree": {},
 25574          "evidence": {},
 25575          "signature": {
 25576            "signature": {
 25577              "publicKey": {}
 25578            }
 25579          },
 25580          "modelCard": {
 25581            "modelParameters": {
 25582              "approach": {}
 25583            },
 25584            "quantitativeAnalysis": {
 25585              "graphics": {}
 25586            },
 25587            "considerations": {}
 25588          }
 25589        },
 25590        {
 25591          "type": "library",
 25592          "bom-ref": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04\u0026package-id=abc451774789c392",
 25593          "supplier": {},
 25594          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25595          "name": "sysvinit-utils",
 25596          "version": "2.96-2.1ubuntu1",
 25597          "licenses": [
 25598            {
 25599              "license": {
 25600                "id": "GPL-2.0-only"
 25601              }
 25602            },
 25603            {
 25604              "license": {
 25605                "id": "GPL-2.0-or-later"
 25606              }
 25607            }
 25608          ],
 25609          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.96-2.1ubuntu1:*:*:*:*:*:*:*",
 25610          "purl": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04",
 25611          "swid": {
 25612            "attachment": {}
 25613          },
 25614          "pedigree": {},
 25615          "evidence": {},
 25616          "signature": {
 25617            "signature": {
 25618              "publicKey": {}
 25619            }
 25620          },
 25621          "modelCard": {
 25622            "modelParameters": {
 25623              "approach": {}
 25624            },
 25625            "quantitativeAnalysis": {
 25626              "graphics": {}
 25627            },
 25628            "considerations": {}
 25629          }
 25630        },
 25631        {
 25632          "type": "library",
 25633          "bom-ref": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=4c6cd0d17cc842e",
 25634          "supplier": {},
 25635          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25636          "name": "tar",
 25637          "version": "1.30+dfsg-7ubuntu0.20.04.1",
 25638          "licenses": [
 25639            {
 25640              "license": {
 25641                "id": "GPL-2.0-only"
 25642              }
 25643            },
 25644            {
 25645              "license": {
 25646                "id": "GPL-3.0-only"
 25647              }
 25648            }
 25649          ],
 25650          "cpe": "cpe:2.3:a:tar:tar:1.30\\+dfsg-7ubuntu0.20.04.1:*:*:*:*:*:*:*",
 25651          "purl": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
 25652          "swid": {
 25653            "attachment": {}
 25654          },
 25655          "pedigree": {},
 25656          "evidence": {},
 25657          "signature": {
 25658            "signature": {
 25659              "publicKey": {}
 25660            }
 25661          },
 25662          "modelCard": {
 25663            "modelParameters": {
 25664              "approach": {}
 25665            },
 25666            "quantitativeAnalysis": {
 25667              "graphics": {}
 25668            },
 25669            "considerations": {}
 25670          }
 25671        },
 25672        {
 25673          "type": "library",
 25674          "bom-ref": "pkg:deb/ubuntu/telnet@0.17-41.2build1?arch=amd64\u0026upstream=netkit-telnet\u0026distro=ubuntu-20.04\u0026package-id=440d9ef0dcd8675e",
 25675          "supplier": {},
 25676          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25677          "name": "telnet",
 25678          "version": "0.17-41.2build1",
 25679          "cpe": "cpe:2.3:a:telnet:telnet:0.17-41.2build1:*:*:*:*:*:*:*",
 25680          "purl": "pkg:deb/ubuntu/telnet@0.17-41.2build1?arch=amd64\u0026upstream=netkit-telnet\u0026distro=ubuntu-20.04",
 25681          "swid": {
 25682            "attachment": {}
 25683          },
 25684          "pedigree": {},
 25685          "evidence": {},
 25686          "signature": {
 25687            "signature": {
 25688              "publicKey": {}
 25689            }
 25690          },
 25691          "modelCard": {
 25692            "modelParameters": {
 25693              "approach": {}
 25694            },
 25695            "quantitativeAnalysis": {
 25696              "graphics": {}
 25697            },
 25698            "considerations": {}
 25699          }
 25700        },
 25701        {
 25702          "type": "library",
 25703          "bom-ref": "pkg:deb/ubuntu/tzdata@2021a-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04\u0026package-id=aaae4a94d26494c0",
 25704          "supplier": {},
 25705          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25706          "name": "tzdata",
 25707          "version": "2021a-0ubuntu0.20.04",
 25708          "licenses": [
 25709            {
 25710              "license": {
 25711                "id": "ICU"
 25712              }
 25713            }
 25714          ],
 25715          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0ubuntu0.20.04:*:*:*:*:*:*:*",
 25716          "purl": "pkg:deb/ubuntu/tzdata@2021a-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04",
 25717          "swid": {
 25718            "attachment": {}
 25719          },
 25720          "pedigree": {},
 25721          "evidence": {},
 25722          "signature": {
 25723            "signature": {
 25724              "publicKey": {}
 25725            }
 25726          },
 25727          "modelCard": {
 25728            "modelParameters": {
 25729              "approach": {}
 25730            },
 25731            "quantitativeAnalysis": {
 25732              "graphics": {}
 25733            },
 25734            "considerations": {}
 25735          }
 25736        },
 25737        {
 25738          "type": "library",
 25739          "bom-ref": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04\u0026package-id=6d2b18ebcbe1dab7",
 25740          "supplier": {},
 25741          "publisher": "Dimitri John Ledkov \u003cdimitri.ledkov@canonical.com\u003e",
 25742          "name": "ubuntu-keyring",
 25743          "version": "2020.02.11.4",
 25744          "licenses": [
 25745            {
 25746              "license": {
 25747                "name": "GPL"
 25748              }
 25749            }
 25750          ],
 25751          "cpe": "cpe:2.3:a:ubuntu-keyring:ubuntu-keyring:2020.02.11.4:*:*:*:*:*:*:*",
 25752          "purl": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04",
 25753          "swid": {
 25754            "attachment": {}
 25755          },
 25756          "pedigree": {},
 25757          "evidence": {},
 25758          "signature": {
 25759            "signature": {
 25760              "publicKey": {}
 25761            }
 25762          },
 25763          "modelCard": {
 25764            "modelParameters": {
 25765              "approach": {}
 25766            },
 25767            "quantitativeAnalysis": {
 25768              "graphics": {}
 25769            },
 25770            "considerations": {}
 25771          }
 25772        },
 25773        {
 25774          "type": "library",
 25775          "bom-ref": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=ab3b8cc8be7b5655",
 25776          "supplier": {},
 25777          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25778          "name": "ucf",
 25779          "version": "3.0038+nmu1",
 25780          "licenses": [
 25781            {
 25782              "license": {
 25783                "id": "GPL-2.0-only"
 25784              }
 25785            }
 25786          ],
 25787          "cpe": "cpe:2.3:a:ucf:ucf:3.0038\\+nmu1:*:*:*:*:*:*:*",
 25788          "purl": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04",
 25789          "swid": {
 25790            "attachment": {}
 25791          },
 25792          "pedigree": {},
 25793          "evidence": {},
 25794          "signature": {
 25795            "signature": {
 25796              "publicKey": {}
 25797            }
 25798          },
 25799          "modelCard": {
 25800            "modelParameters": {
 25801              "approach": {}
 25802            },
 25803            "quantitativeAnalysis": {
 25804              "graphics": {}
 25805            },
 25806            "considerations": {}
 25807          }
 25808        },
 25809        {
 25810          "type": "library",
 25811          "bom-ref": "pkg:deb/ubuntu/unzip@6.0-25ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e34e78f4ed1939d6",
 25812          "supplier": {},
 25813          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25814          "name": "unzip",
 25815          "version": "6.0-25ubuntu1",
 25816          "cpe": "cpe:2.3:a:unzip:unzip:6.0-25ubuntu1:*:*:*:*:*:*:*",
 25817          "purl": "pkg:deb/ubuntu/unzip@6.0-25ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 25818          "swid": {
 25819            "attachment": {}
 25820          },
 25821          "pedigree": {},
 25822          "evidence": {},
 25823          "signature": {
 25824            "signature": {
 25825              "publicKey": {}
 25826            }
 25827          },
 25828          "modelCard": {
 25829            "modelParameters": {
 25830              "approach": {}
 25831            },
 25832            "quantitativeAnalysis": {
 25833              "graphics": {}
 25834            },
 25835            "considerations": {}
 25836          }
 25837        },
 25838        {
 25839          "type": "library",
 25840          "bom-ref": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=33e86bd94ef763b6",
 25841          "supplier": {},
 25842          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25843          "name": "util-linux",
 25844          "version": "2.34-0.1ubuntu9.1",
 25845          "licenses": [
 25846            {
 25847              "license": {
 25848                "id": "BSD-2-Clause"
 25849              }
 25850            },
 25851            {
 25852              "license": {
 25853                "id": "BSD-3-Clause"
 25854              }
 25855            },
 25856            {
 25857              "license": {
 25858                "id": "BSD-4-Clause"
 25859              }
 25860            },
 25861            {
 25862              "license": {
 25863                "id": "GPL-2.0-only"
 25864              }
 25865            },
 25866            {
 25867              "license": {
 25868                "id": "GPL-2.0-or-later"
 25869              }
 25870            },
 25871            {
 25872              "license": {
 25873                "id": "GPL-3.0-only"
 25874              }
 25875            },
 25876            {
 25877              "license": {
 25878                "id": "GPL-3.0-or-later"
 25879              }
 25880            },
 25881            {
 25882              "license": {
 25883                "name": "LGPL"
 25884              }
 25885            },
 25886            {
 25887              "license": {
 25888                "id": "LGPL-2.0-only"
 25889              }
 25890            },
 25891            {
 25892              "license": {
 25893                "id": "LGPL-2.0-or-later"
 25894              }
 25895            },
 25896            {
 25897              "license": {
 25898                "id": "LGPL-2.1-only"
 25899              }
 25900            },
 25901            {
 25902              "license": {
 25903                "id": "LGPL-2.1-or-later"
 25904              }
 25905            },
 25906            {
 25907              "license": {
 25908                "id": "LGPL-3.0-only"
 25909              }
 25910            },
 25911            {
 25912              "license": {
 25913                "id": "LGPL-3.0-or-later"
 25914              }
 25915            },
 25916            {
 25917              "license": {
 25918                "id": "MIT"
 25919              }
 25920            },
 25921            {
 25922              "license": {
 25923                "name": "public-domain"
 25924              }
 25925            }
 25926          ],
 25927          "cpe": "cpe:2.3:a:util-linux:util-linux:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 25928          "purl": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04",
 25929          "swid": {
 25930            "attachment": {}
 25931          },
 25932          "pedigree": {},
 25933          "evidence": {},
 25934          "signature": {
 25935            "signature": {
 25936              "publicKey": {}
 25937            }
 25938          },
 25939          "modelCard": {
 25940            "modelParameters": {
 25941              "approach": {}
 25942            },
 25943            "quantitativeAnalysis": {
 25944              "graphics": {}
 25945            },
 25946            "considerations": {}
 25947          }
 25948        },
 25949        {
 25950          "type": "library",
 25951          "bom-ref": "pkg:deb/ubuntu/vim@2:8.1.2269-1ubuntu5?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f7c20d03c844906d",
 25952          "supplier": {},
 25953          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 25954          "name": "vim",
 25955          "version": "2:8.1.2269-1ubuntu5",
 25956          "licenses": [
 25957            {
 25958              "license": {
 25959                "name": "Apache"
 25960              }
 25961            },
 25962            {
 25963              "license": {
 25964                "id": "Apache-2.0"
 25965              }
 25966            },
 25967            {
 25968              "license": {
 25969                "name": "Artistic"
 25970              }
 25971            },
 25972            {
 25973              "license": {
 25974                "id": "Artistic-1.0"
 25975              }
 25976            },
 25977            {
 25978              "license": {
 25979                "id": "BSD-2-Clause"
 25980              }
 25981            },
 25982            {
 25983              "license": {
 25984                "id": "BSD-3-Clause"
 25985              }
 25986            },
 25987            {
 25988              "license": {
 25989                "name": "Compaq"
 25990              }
 25991            },
 25992            {
 25993              "license": {
 25994                "name": "EDL-1"
 25995              }
 25996            },
 25997            {
 25998              "license": {
 25999                "name": "Expat"
 26000              }
 26001            },
 26002            {
 26003              "license": {
 26004                "id": "GPL-1.0-only"
 26005              }
 26006            },
 26007            {
 26008              "license": {
 26009                "id": "GPL-1.0-or-later"
 26010              }
 26011            },
 26012            {
 26013              "license": {
 26014                "id": "GPL-2.0-only"
 26015              }
 26016            },
 26017            {
 26018              "license": {
 26019                "id": "GPL-2.0-or-later"
 26020              }
 26021            },
 26022            {
 26023              "license": {
 26024                "id": "LGPL-2.1-only"
 26025              }
 26026            },
 26027            {
 26028              "license": {
 26029                "id": "LGPL-2.1-or-later"
 26030              }
 26031            },
 26032            {
 26033              "license": {
 26034                "name": "OPL-1+"
 26035              }
 26036            },
 26037            {
 26038              "license": {
 26039                "name": "SRA"
 26040              }
 26041            },
 26042            {
 26043              "license": {
 26044                "name": "UC"
 26045              }
 26046            },
 26047            {
 26048              "license": {
 26049                "id": "Vim"
 26050              }
 26051            },
 26052            {
 26053              "license": {
 26054                "name": "Vim-Regexp"
 26055              }
 26056            },
 26057            {
 26058              "license": {
 26059                "id": "X11"
 26060              }
 26061            },
 26062            {
 26063              "license": {
 26064                "name": "XPM"
 26065              }
 26066            },
 26067            {
 26068              "license": {
 26069                "name": "public-domain"
 26070              }
 26071            }
 26072          ],
 26073          "cpe": "cpe:2.3:a:vim:vim:2\\:8.1.2269-1ubuntu5:*:*:*:*:*:*:*",
 26074          "purl": "pkg:deb/ubuntu/vim@2:8.1.2269-1ubuntu5?arch=amd64\u0026distro=ubuntu-20.04",
 26075          "swid": {
 26076            "attachment": {}
 26077          },
 26078          "pedigree": {},
 26079          "evidence": {},
 26080          "signature": {
 26081            "signature": {
 26082              "publicKey": {}
 26083            }
 26084          },
 26085          "modelCard": {
 26086            "modelParameters": {
 26087              "approach": {}
 26088            },
 26089            "quantitativeAnalysis": {
 26090              "graphics": {}
 26091            },
 26092            "considerations": {}
 26093          }
 26094        },
 26095        {
 26096          "type": "library",
 26097          "bom-ref": "pkg:deb/ubuntu/vim-common@2:8.1.2269-1ubuntu5?arch=all\u0026upstream=vim\u0026distro=ubuntu-20.04\u0026package-id=b15d5faa156c3d2a",
 26098          "supplier": {},
 26099          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 26100          "name": "vim-common",
 26101          "version": "2:8.1.2269-1ubuntu5",
 26102          "licenses": [
 26103            {
 26104              "license": {
 26105                "name": "Apache"
 26106              }
 26107            },
 26108            {
 26109              "license": {
 26110                "id": "Apache-2.0"
 26111              }
 26112            },
 26113            {
 26114              "license": {
 26115                "name": "Artistic"
 26116              }
 26117            },
 26118            {
 26119              "license": {
 26120                "id": "Artistic-1.0"
 26121              }
 26122            },
 26123            {
 26124              "license": {
 26125                "id": "BSD-2-Clause"
 26126              }
 26127            },
 26128            {
 26129              "license": {
 26130                "id": "BSD-3-Clause"
 26131              }
 26132            },
 26133            {
 26134              "license": {
 26135                "name": "Compaq"
 26136              }
 26137            },
 26138            {
 26139              "license": {
 26140                "name": "EDL-1"
 26141              }
 26142            },
 26143            {
 26144              "license": {
 26145                "name": "Expat"
 26146              }
 26147            },
 26148            {
 26149              "license": {
 26150                "id": "GPL-1.0-only"
 26151              }
 26152            },
 26153            {
 26154              "license": {
 26155                "id": "GPL-1.0-or-later"
 26156              }
 26157            },
 26158            {
 26159              "license": {
 26160                "id": "GPL-2.0-only"
 26161              }
 26162            },
 26163            {
 26164              "license": {
 26165                "id": "GPL-2.0-or-later"
 26166              }
 26167            },
 26168            {
 26169              "license": {
 26170                "id": "LGPL-2.1-only"
 26171              }
 26172            },
 26173            {
 26174              "license": {
 26175                "id": "LGPL-2.1-or-later"
 26176              }
 26177            },
 26178            {
 26179              "license": {
 26180                "name": "OPL-1+"
 26181              }
 26182            },
 26183            {
 26184              "license": {
 26185                "name": "SRA"
 26186              }
 26187            },
 26188            {
 26189              "license": {
 26190                "name": "UC"
 26191              }
 26192            },
 26193            {
 26194              "license": {
 26195                "id": "Vim"
 26196              }
 26197            },
 26198            {
 26199              "license": {
 26200                "name": "Vim-Regexp"
 26201              }
 26202            },
 26203            {
 26204              "license": {
 26205                "id": "X11"
 26206              }
 26207            },
 26208            {
 26209              "license": {
 26210                "name": "XPM"
 26211              }
 26212            },
 26213            {
 26214              "license": {
 26215                "name": "public-domain"
 26216              }
 26217            }
 26218          ],
 26219          "cpe": "cpe:2.3:a:vim-common:vim-common:2\\:8.1.2269-1ubuntu5:*:*:*:*:*:*:*",
 26220          "purl": "pkg:deb/ubuntu/vim-common@2:8.1.2269-1ubuntu5?arch=all\u0026upstream=vim\u0026distro=ubuntu-20.04",
 26221          "swid": {
 26222            "attachment": {}
 26223          },
 26224          "pedigree": {},
 26225          "evidence": {},
 26226          "signature": {
 26227            "signature": {
 26228              "publicKey": {}
 26229            }
 26230          },
 26231          "modelCard": {
 26232            "modelParameters": {
 26233              "approach": {}
 26234            },
 26235            "quantitativeAnalysis": {
 26236              "graphics": {}
 26237            },
 26238            "considerations": {}
 26239          }
 26240        },
 26241        {
 26242          "type": "library",
 26243          "bom-ref": "pkg:deb/ubuntu/vim-runtime@2:8.1.2269-1ubuntu5?arch=all\u0026upstream=vim\u0026distro=ubuntu-20.04\u0026package-id=3af115c3e4b96863",
 26244          "supplier": {},
 26245          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 26246          "name": "vim-runtime",
 26247          "version": "2:8.1.2269-1ubuntu5",
 26248          "licenses": [
 26249            {
 26250              "license": {
 26251                "name": "Apache"
 26252              }
 26253            },
 26254            {
 26255              "license": {
 26256                "id": "Apache-2.0"
 26257              }
 26258            },
 26259            {
 26260              "license": {
 26261                "name": "Artistic"
 26262              }
 26263            },
 26264            {
 26265              "license": {
 26266                "id": "Artistic-1.0"
 26267              }
 26268            },
 26269            {
 26270              "license": {
 26271                "id": "BSD-2-Clause"
 26272              }
 26273            },
 26274            {
 26275              "license": {
 26276                "id": "BSD-3-Clause"
 26277              }
 26278            },
 26279            {
 26280              "license": {
 26281                "name": "Compaq"
 26282              }
 26283            },
 26284            {
 26285              "license": {
 26286                "name": "EDL-1"
 26287              }
 26288            },
 26289            {
 26290              "license": {
 26291                "name": "Expat"
 26292              }
 26293            },
 26294            {
 26295              "license": {
 26296                "id": "GPL-1.0-only"
 26297              }
 26298            },
 26299            {
 26300              "license": {
 26301                "id": "GPL-1.0-or-later"
 26302              }
 26303            },
 26304            {
 26305              "license": {
 26306                "id": "GPL-2.0-only"
 26307              }
 26308            },
 26309            {
 26310              "license": {
 26311                "id": "GPL-2.0-or-later"
 26312              }
 26313            },
 26314            {
 26315              "license": {
 26316                "id": "LGPL-2.1-only"
 26317              }
 26318            },
 26319            {
 26320              "license": {
 26321                "id": "LGPL-2.1-or-later"
 26322              }
 26323            },
 26324            {
 26325              "license": {
 26326                "name": "OPL-1+"
 26327              }
 26328            },
 26329            {
 26330              "license": {
 26331                "name": "SRA"
 26332              }
 26333            },
 26334            {
 26335              "license": {
 26336                "name": "UC"
 26337              }
 26338            },
 26339            {
 26340              "license": {
 26341                "id": "Vim"
 26342              }
 26343            },
 26344            {
 26345              "license": {
 26346                "name": "Vim-Regexp"
 26347              }
 26348            },
 26349            {
 26350              "license": {
 26351                "id": "X11"
 26352              }
 26353            },
 26354            {
 26355              "license": {
 26356                "name": "XPM"
 26357              }
 26358            },
 26359            {
 26360              "license": {
 26361                "name": "public-domain"
 26362              }
 26363            }
 26364          ],
 26365          "cpe": "cpe:2.3:a:vim-runtime:vim-runtime:2\\:8.1.2269-1ubuntu5:*:*:*:*:*:*:*",
 26366          "purl": "pkg:deb/ubuntu/vim-runtime@2:8.1.2269-1ubuntu5?arch=all\u0026upstream=vim\u0026distro=ubuntu-20.04",
 26367          "swid": {
 26368            "attachment": {}
 26369          },
 26370          "pedigree": {},
 26371          "evidence": {},
 26372          "signature": {
 26373            "signature": {
 26374              "publicKey": {}
 26375            }
 26376          },
 26377          "modelCard": {
 26378            "modelParameters": {
 26379              "approach": {}
 26380            },
 26381            "quantitativeAnalysis": {
 26382              "graphics": {}
 26383            },
 26384            "considerations": {}
 26385          }
 26386        },
 26387        {
 26388          "type": "library",
 26389          "bom-ref": "pkg:deb/ubuntu/xfsprogs@5.3.0-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=bbefdc57cc2f7b90",
 26390          "supplier": {},
 26391          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 26392          "name": "xfsprogs",
 26393          "version": "5.3.0-1ubuntu2",
 26394          "licenses": [
 26395            {
 26396              "license": {
 26397                "name": "GPL"
 26398              }
 26399            },
 26400            {
 26401              "license": {
 26402                "id": "LGPL-2.1-only"
 26403              }
 26404            }
 26405          ],
 26406          "cpe": "cpe:2.3:a:xfsprogs:xfsprogs:5.3.0-1ubuntu2:*:*:*:*:*:*:*",
 26407          "purl": "pkg:deb/ubuntu/xfsprogs@5.3.0-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
 26408          "swid": {
 26409            "attachment": {}
 26410          },
 26411          "pedigree": {},
 26412          "evidence": {},
 26413          "signature": {
 26414            "signature": {
 26415              "publicKey": {}
 26416            }
 26417          },
 26418          "modelCard": {
 26419            "modelParameters": {
 26420              "approach": {}
 26421            },
 26422            "quantitativeAnalysis": {
 26423              "graphics": {}
 26424            },
 26425            "considerations": {}
 26426          }
 26427        },
 26428        {
 26429          "type": "library",
 26430          "bom-ref": "pkg:deb/ubuntu/xxd@2:8.1.2269-1ubuntu5?arch=amd64\u0026upstream=vim\u0026distro=ubuntu-20.04\u0026package-id=7bcc1b7cbc0e98d5",
 26431          "supplier": {},
 26432          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 26433          "name": "xxd",
 26434          "version": "2:8.1.2269-1ubuntu5",
 26435          "licenses": [
 26436            {
 26437              "license": {
 26438                "name": "Apache"
 26439              }
 26440            },
 26441            {
 26442              "license": {
 26443                "id": "Apache-2.0"
 26444              }
 26445            },
 26446            {
 26447              "license": {
 26448                "name": "Artistic"
 26449              }
 26450            },
 26451            {
 26452              "license": {
 26453                "id": "Artistic-1.0"
 26454              }
 26455            },
 26456            {
 26457              "license": {
 26458                "id": "BSD-2-Clause"
 26459              }
 26460            },
 26461            {
 26462              "license": {
 26463                "id": "BSD-3-Clause"
 26464              }
 26465            },
 26466            {
 26467              "license": {
 26468                "name": "Compaq"
 26469              }
 26470            },
 26471            {
 26472              "license": {
 26473                "name": "EDL-1"
 26474              }
 26475            },
 26476            {
 26477              "license": {
 26478                "name": "Expat"
 26479              }
 26480            },
 26481            {
 26482              "license": {
 26483                "id": "GPL-1.0-only"
 26484              }
 26485            },
 26486            {
 26487              "license": {
 26488                "id": "GPL-1.0-or-later"
 26489              }
 26490            },
 26491            {
 26492              "license": {
 26493                "id": "GPL-2.0-only"
 26494              }
 26495            },
 26496            {
 26497              "license": {
 26498                "id": "GPL-2.0-or-later"
 26499              }
 26500            },
 26501            {
 26502              "license": {
 26503                "id": "LGPL-2.1-only"
 26504              }
 26505            },
 26506            {
 26507              "license": {
 26508                "id": "LGPL-2.1-or-later"
 26509              }
 26510            },
 26511            {
 26512              "license": {
 26513                "name": "OPL-1+"
 26514              }
 26515            },
 26516            {
 26517              "license": {
 26518                "name": "SRA"
 26519              }
 26520            },
 26521            {
 26522              "license": {
 26523                "name": "UC"
 26524              }
 26525            },
 26526            {
 26527              "license": {
 26528                "id": "Vim"
 26529              }
 26530            },
 26531            {
 26532              "license": {
 26533                "name": "Vim-Regexp"
 26534              }
 26535            },
 26536            {
 26537              "license": {
 26538                "id": "X11"
 26539              }
 26540            },
 26541            {
 26542              "license": {
 26543                "name": "XPM"
 26544              }
 26545            },
 26546            {
 26547              "license": {
 26548                "name": "public-domain"
 26549              }
 26550            }
 26551          ],
 26552          "cpe": "cpe:2.3:a:xxd:xxd:2\\:8.1.2269-1ubuntu5:*:*:*:*:*:*:*",
 26553          "purl": "pkg:deb/ubuntu/xxd@2:8.1.2269-1ubuntu5?arch=amd64\u0026upstream=vim\u0026distro=ubuntu-20.04",
 26554          "swid": {
 26555            "attachment": {}
 26556          },
 26557          "pedigree": {},
 26558          "evidence": {},
 26559          "signature": {
 26560            "signature": {
 26561              "publicKey": {}
 26562            }
 26563          },
 26564          "modelCard": {
 26565            "modelParameters": {
 26566              "approach": {}
 26567            },
 26568            "quantitativeAnalysis": {
 26569              "graphics": {}
 26570            },
 26571            "considerations": {}
 26572          }
 26573        },
 26574        {
 26575          "type": "library",
 26576          "bom-ref": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=46271b3ba3de19b6",
 26577          "supplier": {},
 26578          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 26579          "name": "xz-utils",
 26580          "version": "5.2.4-1ubuntu1",
 26581          "licenses": [
 26582            {
 26583              "license": {
 26584                "name": "Autoconf"
 26585              }
 26586            },
 26587            {
 26588              "license": {
 26589                "id": "GPL-2.0-only"
 26590              }
 26591            },
 26592            {
 26593              "license": {
 26594                "id": "GPL-2.0-or-later"
 26595              }
 26596            },
 26597            {
 26598              "license": {
 26599                "id": "GPL-3.0-only"
 26600              }
 26601            },
 26602            {
 26603              "license": {
 26604                "id": "LGPL-2.0-only"
 26605              }
 26606            },
 26607            {
 26608              "license": {
 26609                "id": "LGPL-2.1-only"
 26610              }
 26611            },
 26612            {
 26613              "license": {
 26614                "id": "LGPL-2.1-or-later"
 26615              }
 26616            },
 26617            {
 26618              "license": {
 26619                "name": "PD"
 26620              }
 26621            },
 26622            {
 26623              "license": {
 26624                "name": "PD-debian"
 26625              }
 26626            },
 26627            {
 26628              "license": {
 26629                "name": "config-h"
 26630              }
 26631            },
 26632            {
 26633              "license": {
 26634                "name": "noderivs"
 26635              }
 26636            },
 26637            {
 26638              "license": {
 26639                "name": "permissive-fsf"
 26640              }
 26641            },
 26642            {
 26643              "license": {
 26644                "name": "permissive-nowarranty"
 26645              }
 26646            },
 26647            {
 26648              "license": {
 26649                "name": "probably-PD"
 26650              }
 26651            }
 26652          ],
 26653          "cpe": "cpe:2.3:a:xz-utils:xz-utils:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
 26654          "purl": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 26655          "swid": {
 26656            "attachment": {}
 26657          },
 26658          "pedigree": {},
 26659          "evidence": {},
 26660          "signature": {
 26661            "signature": {
 26662              "publicKey": {}
 26663            }
 26664          },
 26665          "modelCard": {
 26666            "modelParameters": {
 26667              "approach": {}
 26668            },
 26669            "quantitativeAnalysis": {
 26670              "graphics": {}
 26671            },
 26672            "considerations": {}
 26673          }
 26674        },
 26675        {
 26676          "type": "library",
 26677          "bom-ref": "pkg:deb/ubuntu/zip@3.0-11build1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=849358b990c33a2b",
 26678          "supplier": {},
 26679          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 26680          "name": "zip",
 26681          "version": "3.0-11build1",
 26682          "cpe": "cpe:2.3:a:zip:zip:3.0-11build1:*:*:*:*:*:*:*",
 26683          "purl": "pkg:deb/ubuntu/zip@3.0-11build1?arch=amd64\u0026distro=ubuntu-20.04",
 26684          "swid": {
 26685            "attachment": {}
 26686          },
 26687          "pedigree": {},
 26688          "evidence": {},
 26689          "signature": {
 26690            "signature": {
 26691              "publicKey": {}
 26692            }
 26693          },
 26694          "modelCard": {
 26695            "modelParameters": {
 26696              "approach": {}
 26697            },
 26698            "quantitativeAnalysis": {
 26699              "graphics": {}
 26700            },
 26701            "considerations": {}
 26702          }
 26703        },
 26704        {
 26705          "type": "library",
 26706          "bom-ref": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04\u0026package-id=65361fdd213cfcf7",
 26707          "supplier": {},
 26708          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 26709          "name": "zlib1g",
 26710          "version": "1:1.2.11.dfsg-2ubuntu1.2",
 26711          "licenses": [
 26712            {
 26713              "license": {
 26714                "id": "Zlib"
 26715              }
 26716            }
 26717          ],
 26718          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2ubuntu1.2:*:*:*:*:*:*:*",
 26719          "purl": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04",
 26720          "swid": {
 26721            "attachment": {}
 26722          },
 26723          "pedigree": {},
 26724          "evidence": {},
 26725          "signature": {
 26726            "signature": {
 26727              "publicKey": {}
 26728            }
 26729          },
 26730          "modelCard": {
 26731            "modelParameters": {
 26732              "approach": {}
 26733            },
 26734            "quantitativeAnalysis": {
 26735              "graphics": {}
 26736            },
 26737            "considerations": {}
 26738          }
 26739        },
 26740        {
 26741          "type": "operating-system",
 26742          "supplier": {},
 26743          "name": "ubuntu",
 26744          "version": "20.04",
 26745          "description": "Ubuntu 20.04.3 LTS",
 26746          "swid": {
 26747            "tagId": "ubuntu",
 26748            "name": "ubuntu",
 26749            "version": "20.04",
 26750            "attachment": {}
 26751          },
 26752          "pedigree": {},
 26753          "externalReferences": [
 26754            {
 26755              "url": "https://bugs.launchpad.net/ubuntu/",
 26756              "type": "issue-tracker"
 26757            },
 26758            {
 26759              "url": "https://www.ubuntu.com/",
 26760              "type": "website"
 26761            },
 26762            {
 26763              "url": "https://help.ubuntu.com/",
 26764              "comment": "support",
 26765              "type": "other"
 26766            },
 26767            {
 26768              "url": "https://www.ubuntu.com/legal/terms-and-policies/privacy-policy",
 26769              "comment": "privacyPolicy",
 26770              "type": "other"
 26771            }
 26772          ],
 26773          "evidence": {},
 26774          "signature": {
 26775            "signature": {
 26776              "publicKey": {}
 26777            }
 26778          },
 26779          "modelCard": {
 26780            "modelParameters": {
 26781              "approach": {}
 26782            },
 26783            "quantitativeAnalysis": {
 26784              "graphics": {}
 26785            },
 26786            "considerations": {}
 26787          }
 26788        },
 26789        {
 26790          "type": "library",
 26791          "bom-ref": "pkg:maven/US_export_policy/US_export_policy?package-id=9fc12ca3a2e2eae4",
 26792          "supplier": {},
 26793          "name": "US_export_policy",
 26794          "cpe": "cpe:2.3:a:US-export-policy:US-export-policy:*:*:*:*:*:*:*:*",
 26795          "purl": "pkg:maven/US_export_policy/US_export_policy",
 26796          "swid": {
 26797            "attachment": {}
 26798          },
 26799          "pedigree": {},
 26800          "externalReferences": [
 26801            {
 26802              "type": "build-meta",
 26803              "hashes": [
 26804                {
 26805                  "alg": "SHA-1",
 26806                  "content": "2fcb002cf98fbafecb4fe01976ab172b71411654"
 26807                }
 26808              ]
 26809            }
 26810          ],
 26811          "evidence": {},
 26812          "signature": {
 26813            "signature": {
 26814              "publicKey": {}
 26815            }
 26816          },
 26817          "modelCard": {
 26818            "modelParameters": {
 26819              "approach": {}
 26820            },
 26821            "quantitativeAnalysis": {
 26822              "graphics": {}
 26823            },
 26824            "considerations": {}
 26825          }
 26826        },
 26827        {
 26828          "type": "library",
 26829          "bom-ref": "pkg:maven/US_export_policy/US_export_policy?package-id=502b2a55c42bdec0",
 26830          "supplier": {},
 26831          "name": "US_export_policy",
 26832          "cpe": "cpe:2.3:a:US-export-policy:US-export-policy:*:*:*:*:*:*:*:*",
 26833          "purl": "pkg:maven/US_export_policy/US_export_policy",
 26834          "swid": {
 26835            "attachment": {}
 26836          },
 26837          "pedigree": {},
 26838          "externalReferences": [
 26839            {
 26840              "type": "build-meta",
 26841              "hashes": [
 26842                {
 26843                  "alg": "SHA-1",
 26844                  "content": "2fcb002cf98fbafecb4fe01976ab172b71411654"
 26845                }
 26846              ]
 26847            }
 26848          ],
 26849          "evidence": {},
 26850          "signature": {
 26851            "signature": {
 26852              "publicKey": {}
 26853            }
 26854          },
 26855          "modelCard": {
 26856            "modelParameters": {
 26857              "approach": {}
 26858            },
 26859            "quantitativeAnalysis": {
 26860              "graphics": {}
 26861            },
 26862            "considerations": {}
 26863          }
 26864        },
 26865        {
 26866          "type": "library",
 26867          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=92b19c7750fb559d",
 26868          "supplier": {},
 26869          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 26870          "name": "alpine-baselayout",
 26871          "version": "3.4.0-r0",
 26872          "description": "Alpine base dir structure and init scripts",
 26873          "licenses": [
 26874            {
 26875              "license": {
 26876                "id": "GPL-2.0-only"
 26877              }
 26878            }
 26879          ],
 26880          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.4.0-r0:*:*:*:*:*:*:*",
 26881          "purl": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 26882          "swid": {
 26883            "attachment": {}
 26884          },
 26885          "pedigree": {},
 26886          "externalReferences": [
 26887            {
 26888              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 26889              "type": "distribution"
 26890            }
 26891          ],
 26892          "evidence": {},
 26893          "signature": {
 26894            "signature": {
 26895              "publicKey": {}
 26896            }
 26897          },
 26898          "modelCard": {
 26899            "modelParameters": {
 26900              "approach": {}
 26901            },
 26902            "quantitativeAnalysis": {
 26903              "graphics": {}
 26904            },
 26905            "considerations": {}
 26906          }
 26907        },
 26908        {
 26909          "type": "library",
 26910          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.3\u0026package-id=291d1267b40d636f",
 26911          "supplier": {},
 26912          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 26913          "name": "alpine-baselayout-data",
 26914          "version": "3.4.0-r0",
 26915          "description": "Alpine base dir structure and init scripts",
 26916          "licenses": [
 26917            {
 26918              "license": {
 26919                "id": "GPL-2.0-only"
 26920              }
 26921            }
 26922          ],
 26923          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.4.0-r0:*:*:*:*:*:*:*",
 26924          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.3",
 26925          "swid": {
 26926            "attachment": {}
 26927          },
 26928          "pedigree": {},
 26929          "externalReferences": [
 26930            {
 26931              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 26932              "type": "distribution"
 26933            }
 26934          ],
 26935          "evidence": {},
 26936          "signature": {
 26937            "signature": {
 26938              "publicKey": {}
 26939            }
 26940          },
 26941          "modelCard": {
 26942            "modelParameters": {
 26943              "approach": {}
 26944            },
 26945            "quantitativeAnalysis": {
 26946              "graphics": {}
 26947            },
 26948            "considerations": {}
 26949          }
 26950        },
 26951        {
 26952          "type": "library",
 26953          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2b5e23d349b556cf",
 26954          "supplier": {},
 26955          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 26956          "name": "alpine-keys",
 26957          "version": "2.4-r1",
 26958          "description": "Public keys for Alpine Linux packages",
 26959          "licenses": [
 26960            {
 26961              "license": {
 26962                "id": "MIT"
 26963              }
 26964            }
 26965          ],
 26966          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
 26967          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 26968          "swid": {
 26969            "attachment": {}
 26970          },
 26971          "pedigree": {},
 26972          "externalReferences": [
 26973            {
 26974              "url": "https://alpinelinux.org",
 26975              "type": "distribution"
 26976            }
 26977          ],
 26978          "evidence": {},
 26979          "signature": {
 26980            "signature": {
 26981              "publicKey": {}
 26982            }
 26983          },
 26984          "modelCard": {
 26985            "modelParameters": {
 26986              "approach": {}
 26987            },
 26988            "quantitativeAnalysis": {
 26989              "graphics": {}
 26990            },
 26991            "considerations": {}
 26992          }
 26993        },
 26994        {
 26995          "type": "library",
 26996          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=e5f757b0df1f62bc",
 26997          "supplier": {},
 26998          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 26999          "name": "apk-tools",
 27000          "version": "2.12.10-r1",
 27001          "description": "Alpine Package Keeper - package manager for alpine",
 27002          "licenses": [
 27003            {
 27004              "license": {
 27005                "id": "GPL-2.0-only"
 27006              }
 27007            }
 27008          ],
 27009          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.10-r1:*:*:*:*:*:*:*",
 27010          "purl": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 27011          "swid": {
 27012            "attachment": {}
 27013          },
 27014          "pedigree": {},
 27015          "externalReferences": [
 27016            {
 27017              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
 27018              "type": "distribution"
 27019            }
 27020          ],
 27021          "evidence": {},
 27022          "signature": {
 27023            "signature": {
 27024              "publicKey": {}
 27025            }
 27026          },
 27027          "modelCard": {
 27028            "modelParameters": {
 27029              "approach": {}
 27030            },
 27031            "quantitativeAnalysis": {
 27032              "graphics": {}
 27033            },
 27034            "considerations": {}
 27035          }
 27036        },
 27037        {
 27038          "type": "library",
 27039          "bom-ref": "pkg:apk/alpine/brotli-libs@1.0.9-r9?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.17.3\u0026package-id=b908173dd9145006",
 27040          "supplier": {},
 27041          "publisher": "prspkt \u003cprspkt@protonmail.com\u003e",
 27042          "name": "brotli-libs",
 27043          "version": "1.0.9-r9",
 27044          "description": "Generic lossless compressor (libraries)",
 27045          "licenses": [
 27046            {
 27047              "license": {
 27048                "id": "MIT"
 27049              }
 27050            }
 27051          ],
 27052          "cpe": "cpe:2.3:a:brotli-libs:brotli-libs:1.0.9-r9:*:*:*:*:*:*:*",
 27053          "purl": "pkg:apk/alpine/brotli-libs@1.0.9-r9?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.17.3",
 27054          "swid": {
 27055            "attachment": {}
 27056          },
 27057          "pedigree": {},
 27058          "externalReferences": [
 27059            {
 27060              "url": "https://github.com/google/brotli",
 27061              "type": "distribution"
 27062            }
 27063          ],
 27064          "evidence": {},
 27065          "signature": {
 27066            "signature": {
 27067              "publicKey": {}
 27068            }
 27069          },
 27070          "modelCard": {
 27071            "modelParameters": {
 27072              "approach": {}
 27073            },
 27074            "quantitativeAnalysis": {
 27075              "graphics": {}
 27076            },
 27077            "considerations": {}
 27078          }
 27079        },
 27080        {
 27081          "type": "application",
 27082          "bom-ref": "e6c9486419cbb84e",
 27083          "supplier": {},
 27084          "name": "busybox",
 27085          "version": "1.35.0",
 27086          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
 27087          "swid": {
 27088            "attachment": {}
 27089          },
 27090          "pedigree": {},
 27091          "evidence": {},
 27092          "signature": {
 27093            "signature": {
 27094              "publicKey": {}
 27095            }
 27096          },
 27097          "modelCard": {
 27098            "modelParameters": {
 27099              "approach": {}
 27100            },
 27101            "quantitativeAnalysis": {
 27102              "graphics": {}
 27103            },
 27104            "considerations": {}
 27105          }
 27106        },
 27107        {
 27108          "type": "library",
 27109          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=623d53216342d45e",
 27110          "supplier": {},
 27111          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 27112          "name": "busybox",
 27113          "version": "1.35.0-r29",
 27114          "description": "Size optimized toolbox of many common UNIX utilities",
 27115          "licenses": [
 27116            {
 27117              "license": {
 27118                "id": "GPL-2.0-only"
 27119              }
 27120            }
 27121          ],
 27122          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r29:*:*:*:*:*:*:*",
 27123          "purl": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.3",
 27124          "swid": {
 27125            "attachment": {}
 27126          },
 27127          "pedigree": {},
 27128          "externalReferences": [
 27129            {
 27130              "url": "https://busybox.net/",
 27131              "type": "distribution"
 27132            }
 27133          ],
 27134          "evidence": {},
 27135          "signature": {
 27136            "signature": {
 27137              "publicKey": {}
 27138            }
 27139          },
 27140          "modelCard": {
 27141            "modelParameters": {
 27142              "approach": {}
 27143            },
 27144            "quantitativeAnalysis": {
 27145              "graphics": {}
 27146            },
 27147            "considerations": {}
 27148          }
 27149        },
 27150        {
 27151          "type": "library",
 27152          "bom-ref": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3\u0026package-id=256fc96b4a8c4da8",
 27153          "supplier": {},
 27154          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 27155          "name": "busybox-binsh",
 27156          "version": "1.35.0-r29",
 27157          "description": "busybox ash /bin/sh",
 27158          "licenses": [
 27159            {
 27160              "license": {
 27161                "id": "GPL-2.0-only"
 27162              }
 27163            }
 27164          ],
 27165          "cpe": "cpe:2.3:a:busybox-binsh:busybox-binsh:1.35.0-r29:*:*:*:*:*:*:*",
 27166          "purl": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3",
 27167          "swid": {
 27168            "attachment": {}
 27169          },
 27170          "pedigree": {},
 27171          "externalReferences": [
 27172            {
 27173              "url": "https://busybox.net/",
 27174              "type": "distribution"
 27175            }
 27176          ],
 27177          "evidence": {},
 27178          "signature": {
 27179            "signature": {
 27180              "publicKey": {}
 27181            }
 27182          },
 27183          "modelCard": {
 27184            "modelParameters": {
 27185              "approach": {}
 27186            },
 27187            "quantitativeAnalysis": {
 27188              "graphics": {}
 27189            },
 27190            "considerations": {}
 27191          }
 27192        },
 27193        {
 27194          "type": "library",
 27195          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.3\u0026package-id=b805d823ae624f04",
 27196          "supplier": {},
 27197          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 27198          "name": "ca-certificates-bundle",
 27199          "version": "20220614-r4",
 27200          "description": "Pre generated bundle of Mozilla certificates",
 27201          "licenses": [
 27202            {
 27203              "license": {
 27204                "id": "MPL-2.0"
 27205              }
 27206            },
 27207            {
 27208              "license": {
 27209                "name": "AND"
 27210              }
 27211            },
 27212            {
 27213              "license": {
 27214                "id": "MIT"
 27215              }
 27216            }
 27217          ],
 27218          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r4:*:*:*:*:*:*:*",
 27219          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.3",
 27220          "swid": {
 27221            "attachment": {}
 27222          },
 27223          "pedigree": {},
 27224          "externalReferences": [
 27225            {
 27226              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
 27227              "type": "distribution"
 27228            }
 27229          ],
 27230          "evidence": {},
 27231          "signature": {
 27232            "signature": {
 27233              "publicKey": {}
 27234            }
 27235          },
 27236          "modelCard": {
 27237            "modelParameters": {
 27238              "approach": {}
 27239            },
 27240            "quantitativeAnalysis": {
 27241              "graphics": {}
 27242            },
 27243            "considerations": {}
 27244          }
 27245        },
 27246        {
 27247          "type": "library",
 27248          "bom-ref": "pkg:maven/charsets/charsets?package-id=ac260baeda2f6c16",
 27249          "supplier": {},
 27250          "name": "charsets",
 27251          "cpe": "cpe:2.3:a:charsets:charsets:*:*:*:*:*:*:*:*",
 27252          "purl": "pkg:maven/charsets/charsets",
 27253          "swid": {
 27254            "attachment": {}
 27255          },
 27256          "pedigree": {},
 27257          "externalReferences": [
 27258            {
 27259              "type": "build-meta",
 27260              "hashes": [
 27261                {
 27262                  "alg": "SHA-1",
 27263                  "content": "141875c9bf4e34ae776a45505fc5365a5a1c8180"
 27264                }
 27265              ]
 27266            }
 27267          ],
 27268          "evidence": {},
 27269          "signature": {
 27270            "signature": {
 27271              "publicKey": {}
 27272            }
 27273          },
 27274          "modelCard": {
 27275            "modelParameters": {
 27276              "approach": {}
 27277            },
 27278            "quantitativeAnalysis": {
 27279              "graphics": {}
 27280            },
 27281            "considerations": {}
 27282          }
 27283        },
 27284        {
 27285          "type": "library",
 27286          "bom-ref": "pkg:maven/cldrdata/cldrdata?package-id=aaa36a6b8966b603",
 27287          "supplier": {},
 27288          "name": "cldrdata",
 27289          "cpe": "cpe:2.3:a:cldrdata:cldrdata:*:*:*:*:*:*:*:*",
 27290          "purl": "pkg:maven/cldrdata/cldrdata",
 27291          "swid": {
 27292            "attachment": {}
 27293          },
 27294          "pedigree": {},
 27295          "externalReferences": [
 27296            {
 27297              "type": "build-meta",
 27298              "hashes": [
 27299                {
 27300                  "alg": "SHA-1",
 27301                  "content": "040ba7365dc9db7c7b9a0fd786c6f180e61f62e3"
 27302                }
 27303              ]
 27304            }
 27305          ],
 27306          "evidence": {},
 27307          "signature": {
 27308            "signature": {
 27309              "publicKey": {}
 27310            }
 27311          },
 27312          "modelCard": {
 27313            "modelParameters": {
 27314              "approach": {}
 27315            },
 27316            "quantitativeAnalysis": {
 27317              "graphics": {}
 27318            },
 27319            "considerations": {}
 27320          }
 27321        },
 27322        {
 27323          "type": "library",
 27324          "bom-ref": "pkg:maven/dnsns/dnsns?package-id=af09d0f9bd2e5151",
 27325          "supplier": {},
 27326          "name": "dnsns",
 27327          "cpe": "cpe:2.3:a:dnsns:dnsns:*:*:*:*:*:*:*:*",
 27328          "purl": "pkg:maven/dnsns/dnsns",
 27329          "swid": {
 27330            "attachment": {}
 27331          },
 27332          "pedigree": {},
 27333          "externalReferences": [
 27334            {
 27335              "type": "build-meta",
 27336              "hashes": [
 27337                {
 27338                  "alg": "SHA-1",
 27339                  "content": "3c80b6ce7bfb62d34251421d73d7afb67f06b1e8"
 27340                }
 27341              ]
 27342            }
 27343          ],
 27344          "evidence": {},
 27345          "signature": {
 27346            "signature": {
 27347              "publicKey": {}
 27348            }
 27349          },
 27350          "modelCard": {
 27351            "modelParameters": {
 27352              "approach": {}
 27353            },
 27354            "quantitativeAnalysis": {
 27355              "graphics": {}
 27356            },
 27357            "considerations": {}
 27358          }
 27359        },
 27360        {
 27361          "type": "library",
 27362          "bom-ref": "pkg:apk/alpine/encodings@1.0.6-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=27e4d13f9a311e67",
 27363          "supplier": {},
 27364          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 27365          "name": "encodings",
 27366          "version": "1.0.6-r0",
 27367          "description": "X.org font encoding files",
 27368          "licenses": [
 27369            {
 27370              "license": {
 27371                "name": "custom"
 27372              }
 27373            }
 27374          ],
 27375          "cpe": "cpe:2.3:a:encodings:encodings:1.0.6-r0:*:*:*:*:*:*:*",
 27376          "purl": "pkg:apk/alpine/encodings@1.0.6-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 27377          "swid": {
 27378            "attachment": {}
 27379          },
 27380          "pedigree": {},
 27381          "externalReferences": [
 27382            {
 27383              "url": "http://xorg.freedesktop.org/",
 27384              "type": "distribution"
 27385            }
 27386          ],
 27387          "evidence": {},
 27388          "signature": {
 27389            "signature": {
 27390              "publicKey": {}
 27391            }
 27392          },
 27393          "modelCard": {
 27394            "modelParameters": {
 27395              "approach": {}
 27396            },
 27397            "quantitativeAnalysis": {
 27398              "graphics": {}
 27399            },
 27400            "considerations": {}
 27401          }
 27402        },
 27403        {
 27404          "type": "library",
 27405          "bom-ref": "pkg:maven/org.flywaydb/flyway-commandline@6.5.2?package-id=c6ee0475836854bc",
 27406          "supplier": {},
 27407          "group": "org.flywaydb",
 27408          "name": "flyway-commandline",
 27409          "version": "6.5.2",
 27410          "cpe": "cpe:2.3:a:flyway-commandline:flyway-commandline:6.5.2:*:*:*:*:*:*:*",
 27411          "purl": "pkg:maven/org.flywaydb/flyway-commandline@6.5.2",
 27412          "swid": {
 27413            "attachment": {}
 27414          },
 27415          "pedigree": {},
 27416          "externalReferences": [
 27417            {
 27418              "type": "build-meta",
 27419              "hashes": [
 27420                {
 27421                  "alg": "SHA-1",
 27422                  "content": "268d5988f4c6b951ae19ac32d2700a29ea38b02a"
 27423                }
 27424              ]
 27425            }
 27426          ],
 27427          "evidence": {},
 27428          "signature": {
 27429            "signature": {
 27430              "publicKey": {}
 27431            }
 27432          },
 27433          "modelCard": {
 27434            "modelParameters": {
 27435              "approach": {}
 27436            },
 27437            "quantitativeAnalysis": {
 27438              "graphics": {}
 27439            },
 27440            "considerations": {}
 27441          }
 27442        },
 27443        {
 27444          "type": "library",
 27445          "bom-ref": "pkg:maven/org.flywaydb.enterprise/flyway-commandline@6.5.2?package-id=f00f61c03e76820f",
 27446          "supplier": {},
 27447          "group": "org.flywaydb.enterprise",
 27448          "name": "flyway-commandline",
 27449          "version": "6.5.2",
 27450          "cpe": "cpe:2.3:a:flyway-commandline:flyway-commandline:6.5.2:*:*:*:*:*:*:*",
 27451          "purl": "pkg:maven/org.flywaydb.enterprise/flyway-commandline@6.5.2",
 27452          "swid": {
 27453            "attachment": {}
 27454          },
 27455          "pedigree": {},
 27456          "externalReferences": [
 27457            {
 27458              "type": "build-meta",
 27459              "hashes": [
 27460                {
 27461                  "alg": "SHA-1",
 27462                  "content": "524bbeaeabaf7d5268f12bab1e267bd9c36ffe89"
 27463                }
 27464              ]
 27465            }
 27466          ],
 27467          "evidence": {},
 27468          "signature": {
 27469            "signature": {
 27470              "publicKey": {}
 27471            }
 27472          },
 27473          "modelCard": {
 27474            "modelParameters": {
 27475              "approach": {}
 27476            },
 27477            "quantitativeAnalysis": {
 27478              "graphics": {}
 27479            },
 27480            "considerations": {}
 27481          }
 27482        },
 27483        {
 27484          "type": "library",
 27485          "bom-ref": "pkg:maven/org.flywaydb.pro/flyway-commandline@6.5.2?package-id=9246a63644654103",
 27486          "supplier": {},
 27487          "group": "org.flywaydb.pro",
 27488          "name": "flyway-commandline",
 27489          "version": "6.5.2",
 27490          "cpe": "cpe:2.3:a:flyway-commandline:flyway-commandline:6.5.2:*:*:*:*:*:*:*",
 27491          "purl": "pkg:maven/org.flywaydb.pro/flyway-commandline@6.5.2",
 27492          "swid": {
 27493            "attachment": {}
 27494          },
 27495          "pedigree": {},
 27496          "externalReferences": [
 27497            {
 27498              "type": "build-meta",
 27499              "hashes": [
 27500                {
 27501                  "alg": "SHA-1",
 27502                  "content": "8f52b854dde2be056fdfa17adc953734dcb6cdfc"
 27503                }
 27504              ]
 27505            }
 27506          ],
 27507          "evidence": {},
 27508          "signature": {
 27509            "signature": {
 27510              "publicKey": {}
 27511            }
 27512          },
 27513          "modelCard": {
 27514            "modelParameters": {
 27515              "approach": {}
 27516            },
 27517            "quantitativeAnalysis": {
 27518              "graphics": {}
 27519            },
 27520            "considerations": {}
 27521          }
 27522        },
 27523        {
 27524          "type": "library",
 27525          "bom-ref": "pkg:maven/org.flywaydb/flyway-core@6.5.2?package-id=d9d3038fa2441d9f",
 27526          "supplier": {},
 27527          "group": "org.flywaydb",
 27528          "name": "flyway-core",
 27529          "version": "6.5.2",
 27530          "licenses": [
 27531            {
 27532              "license": {
 27533                "name": "https://flywaydb.org/licenses/flyway-community"
 27534              }
 27535            }
 27536          ],
 27537          "cpe": "cpe:2.3:a:flyway-core:flyway-core:6.5.2:*:*:*:*:*:*:*",
 27538          "purl": "pkg:maven/org.flywaydb/flyway-core@6.5.2",
 27539          "swid": {
 27540            "attachment": {}
 27541          },
 27542          "pedigree": {},
 27543          "externalReferences": [
 27544            {
 27545              "type": "build-meta",
 27546              "hashes": [
 27547                {
 27548                  "alg": "SHA-1",
 27549                  "content": "b278ba02208c39fe601986f313885f27bdeae3b4"
 27550                }
 27551              ]
 27552            }
 27553          ],
 27554          "evidence": {},
 27555          "signature": {
 27556            "signature": {
 27557              "publicKey": {}
 27558            }
 27559          },
 27560          "modelCard": {
 27561            "modelParameters": {
 27562              "approach": {}
 27563            },
 27564            "quantitativeAnalysis": {
 27565              "graphics": {}
 27566            },
 27567            "considerations": {}
 27568          }
 27569        },
 27570        {
 27571          "type": "library",
 27572          "bom-ref": "pkg:maven/org.flywaydb.enterprise/flyway-core@6.5.2?package-id=7ecd86f5bb3aa997",
 27573          "supplier": {},
 27574          "group": "org.flywaydb.enterprise",
 27575          "name": "flyway-core",
 27576          "version": "6.5.2",
 27577          "licenses": [
 27578            {
 27579              "license": {
 27580                "name": "https://flywaydb.org/licenses/flyway-enterprise"
 27581              }
 27582            }
 27583          ],
 27584          "cpe": "cpe:2.3:a:flyway-core:flyway-core:6.5.2:*:*:*:*:*:*:*",
 27585          "purl": "pkg:maven/org.flywaydb.enterprise/flyway-core@6.5.2",
 27586          "swid": {
 27587            "attachment": {}
 27588          },
 27589          "pedigree": {},
 27590          "externalReferences": [
 27591            {
 27592              "type": "build-meta",
 27593              "hashes": [
 27594                {
 27595                  "alg": "SHA-1",
 27596                  "content": "1a031f60991c400c4016192f4554608b7ca84b17"
 27597                }
 27598              ]
 27599            }
 27600          ],
 27601          "evidence": {},
 27602          "signature": {
 27603            "signature": {
 27604              "publicKey": {}
 27605            }
 27606          },
 27607          "modelCard": {
 27608            "modelParameters": {
 27609              "approach": {}
 27610            },
 27611            "quantitativeAnalysis": {
 27612              "graphics": {}
 27613            },
 27614            "considerations": {}
 27615          }
 27616        },
 27617        {
 27618          "type": "library",
 27619          "bom-ref": "pkg:maven/org.flywaydb.pro/flyway-core@6.5.2?package-id=7638a34f08a477e5",
 27620          "supplier": {},
 27621          "group": "org.flywaydb.pro",
 27622          "name": "flyway-core",
 27623          "version": "6.5.2",
 27624          "licenses": [
 27625            {
 27626              "license": {
 27627                "name": "https://flywaydb.org/licenses/flyway-pro"
 27628              }
 27629            }
 27630          ],
 27631          "cpe": "cpe:2.3:a:flyway-core:flyway-core:6.5.2:*:*:*:*:*:*:*",
 27632          "purl": "pkg:maven/org.flywaydb.pro/flyway-core@6.5.2",
 27633          "swid": {
 27634            "attachment": {}
 27635          },
 27636          "pedigree": {},
 27637          "externalReferences": [
 27638            {
 27639              "type": "build-meta",
 27640              "hashes": [
 27641                {
 27642                  "alg": "SHA-1",
 27643                  "content": "a4f690bd53cb4fb812e7a95d5991be43e542a723"
 27644                }
 27645              ]
 27646            }
 27647          ],
 27648          "evidence": {},
 27649          "signature": {
 27650            "signature": {
 27651              "publicKey": {}
 27652            }
 27653          },
 27654          "modelCard": {
 27655            "modelParameters": {
 27656              "approach": {}
 27657            },
 27658            "quantitativeAnalysis": {
 27659              "graphics": {}
 27660            },
 27661            "considerations": {}
 27662          }
 27663        },
 27664        {
 27665          "type": "library",
 27666          "bom-ref": "pkg:apk/alpine/font-dejavu@2.37-r3?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=dcec74118c4e82d9",
 27667          "supplier": {},
 27668          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 27669          "name": "font-dejavu",
 27670          "version": "2.37-r3",
 27671          "description": "Font family based on the Bitstream Vera Fonts with a wider range of characters",
 27672          "licenses": [
 27673            {
 27674              "license": {
 27675                "name": "custom"
 27676              }
 27677            }
 27678          ],
 27679          "cpe": "cpe:2.3:a:font-dejavu:font-dejavu:2.37-r3:*:*:*:*:*:*:*",
 27680          "purl": "pkg:apk/alpine/font-dejavu@2.37-r3?arch=x86_64\u0026distro=alpine-3.17.3",
 27681          "swid": {
 27682            "attachment": {}
 27683          },
 27684          "pedigree": {},
 27685          "externalReferences": [
 27686            {
 27687              "url": "https://dejavu-fonts.github.io/",
 27688              "type": "distribution"
 27689            }
 27690          ],
 27691          "evidence": {},
 27692          "signature": {
 27693            "signature": {
 27694              "publicKey": {}
 27695            }
 27696          },
 27697          "modelCard": {
 27698            "modelParameters": {
 27699              "approach": {}
 27700            },
 27701            "quantitativeAnalysis": {
 27702              "graphics": {}
 27703            },
 27704            "considerations": {}
 27705          }
 27706        },
 27707        {
 27708          "type": "library",
 27709          "bom-ref": "pkg:apk/alpine/fontconfig@2.14.1-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=adae4094ba998368",
 27710          "supplier": {},
 27711          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 27712          "name": "fontconfig",
 27713          "version": "2.14.1-r0",
 27714          "description": "Library for configuring and customizing font access",
 27715          "licenses": [
 27716            {
 27717              "license": {
 27718                "id": "MIT"
 27719              }
 27720            }
 27721          ],
 27722          "cpe": "cpe:2.3:a:fontconfig:fontconfig:2.14.1-r0:*:*:*:*:*:*:*",
 27723          "purl": "pkg:apk/alpine/fontconfig@2.14.1-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 27724          "swid": {
 27725            "attachment": {}
 27726          },
 27727          "pedigree": {},
 27728          "externalReferences": [
 27729            {
 27730              "url": "https://www.freedesktop.org/wiki/Software/fontconfig",
 27731              "type": "distribution"
 27732            }
 27733          ],
 27734          "evidence": {},
 27735          "signature": {
 27736            "signature": {
 27737              "publicKey": {}
 27738            }
 27739          },
 27740          "modelCard": {
 27741            "modelParameters": {
 27742              "approach": {}
 27743            },
 27744            "quantitativeAnalysis": {
 27745              "graphics": {}
 27746            },
 27747            "considerations": {}
 27748          }
 27749        },
 27750        {
 27751          "type": "library",
 27752          "bom-ref": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2b1bfc10343b9080",
 27753          "supplier": {},
 27754          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 27755          "name": "freetype",
 27756          "version": "2.12.1-r0",
 27757          "description": "TrueType font rendering library",
 27758          "licenses": [
 27759            {
 27760              "license": {
 27761                "id": "FTL"
 27762              }
 27763            },
 27764            {
 27765              "license": {
 27766                "id": "GPL-2.0-or-later"
 27767              }
 27768            }
 27769          ],
 27770          "cpe": "cpe:2.3:a:freetype:freetype:2.12.1-r0:*:*:*:*:*:*:*",
 27771          "purl": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 27772          "swid": {
 27773            "attachment": {}
 27774          },
 27775          "pedigree": {},
 27776          "externalReferences": [
 27777            {
 27778              "url": "https://www.freetype.org/",
 27779              "type": "distribution"
 27780            }
 27781          ],
 27782          "evidence": {},
 27783          "signature": {
 27784            "signature": {
 27785              "publicKey": {}
 27786            }
 27787          },
 27788          "modelCard": {
 27789            "modelParameters": {
 27790              "approach": {}
 27791            },
 27792            "quantitativeAnalysis": {
 27793              "graphics": {}
 27794            },
 27795            "considerations": {}
 27796          }
 27797        },
 27798        {
 27799          "type": "library",
 27800          "bom-ref": "pkg:maven/com.google.code.gson/gson@2.8.6?package-id=fc6f3f03c604a664",
 27801          "supplier": {},
 27802          "group": "com.google.code.gson",
 27803          "name": "gson",
 27804          "version": "2.8.6",
 27805          "cpe": "cpe:2.3:a:google:gson:2.8.6:*:*:*:*:*:*:*",
 27806          "purl": "pkg:maven/com.google.code.gson/gson@2.8.6",
 27807          "swid": {
 27808            "attachment": {}
 27809          },
 27810          "pedigree": {},
 27811          "externalReferences": [
 27812            {
 27813              "type": "build-meta",
 27814              "hashes": [
 27815                {
 27816                  "alg": "SHA-1",
 27817                  "content": "9180733b7df8542621dc12e21e87557e8c99b8cb"
 27818                }
 27819              ]
 27820            }
 27821          ],
 27822          "evidence": {},
 27823          "signature": {
 27824            "signature": {
 27825              "publicKey": {}
 27826            }
 27827          },
 27828          "modelCard": {
 27829            "modelParameters": {
 27830              "approach": {}
 27831            },
 27832            "quantitativeAnalysis": {
 27833              "graphics": {}
 27834            },
 27835            "considerations": {}
 27836          }
 27837        },
 27838        {
 27839          "type": "library",
 27840          "bom-ref": "pkg:maven/org.fusesource.hawtjni/hawtjni-runtime@1.17?package-id=ea2a5041dc281db7",
 27841          "supplier": {},
 27842          "group": "org.fusesource.hawtjni",
 27843          "name": "hawtjni-runtime",
 27844          "version": "1.17",
 27845          "cpe": "cpe:2.3:a:hawtjni-runtime:hawtjni-runtime:1.17:*:*:*:*:*:*:*",
 27846          "purl": "pkg:maven/org.fusesource.hawtjni/hawtjni-runtime@1.17",
 27847          "swid": {
 27848            "attachment": {}
 27849          },
 27850          "pedigree": {},
 27851          "evidence": {},
 27852          "signature": {
 27853            "signature": {
 27854              "publicKey": {}
 27855            }
 27856          },
 27857          "modelCard": {
 27858            "modelParameters": {
 27859              "approach": {}
 27860            },
 27861            "quantitativeAnalysis": {
 27862              "graphics": {}
 27863            },
 27864            "considerations": {}
 27865          }
 27866        },
 27867        {
 27868          "type": "library",
 27869          "bom-ref": "pkg:maven/jaccess/jaccess?package-id=597e861ae7234b49",
 27870          "supplier": {},
 27871          "name": "jaccess",
 27872          "cpe": "cpe:2.3:a:jaccess:jaccess:*:*:*:*:*:*:*:*",
 27873          "purl": "pkg:maven/jaccess/jaccess",
 27874          "swid": {
 27875            "attachment": {}
 27876          },
 27877          "pedigree": {},
 27878          "externalReferences": [
 27879            {
 27880              "type": "build-meta",
 27881              "hashes": [
 27882                {
 27883                  "alg": "SHA-1",
 27884                  "content": "4cf0b06ec3ab96c68d48a3b56a6a2b9a939b4a69"
 27885                }
 27886              ]
 27887            }
 27888          ],
 27889          "evidence": {},
 27890          "signature": {
 27891            "signature": {
 27892              "publicKey": {}
 27893            }
 27894          },
 27895          "modelCard": {
 27896            "modelParameters": {
 27897              "approach": {}
 27898            },
 27899            "quantitativeAnalysis": {
 27900              "graphics": {}
 27901            },
 27902            "considerations": {}
 27903          }
 27904        },
 27905        {
 27906          "type": "library",
 27907          "bom-ref": "pkg:maven/org.fusesource.jansi/jansi@1.18?package-id=9bed868f402b2298",
 27908          "supplier": {},
 27909          "group": "org.fusesource.jansi",
 27910          "name": "jansi",
 27911          "version": "1.18",
 27912          "cpe": "cpe:2.3:a:fusesource:jansi:1.18:*:*:*:*:*:*:*",
 27913          "purl": "pkg:maven/org.fusesource.jansi/jansi@1.18",
 27914          "swid": {
 27915            "attachment": {}
 27916          },
 27917          "pedigree": {},
 27918          "evidence": {},
 27919          "signature": {
 27920            "signature": {
 27921              "publicKey": {}
 27922            }
 27923          },
 27924          "modelCard": {
 27925            "modelParameters": {
 27926              "approach": {}
 27927            },
 27928            "quantitativeAnalysis": {
 27929              "graphics": {}
 27930            },
 27931            "considerations": {}
 27932          }
 27933        },
 27934        {
 27935          "type": "library",
 27936          "bom-ref": "pkg:maven/org.fusesource.jansi/jansi-freebsd32@1.8?package-id=e30a6ee31edbdff9",
 27937          "supplier": {},
 27938          "group": "org.fusesource.jansi",
 27939          "name": "jansi-freebsd32",
 27940          "version": "1.8",
 27941          "cpe": "cpe:2.3:a:jansi-freebsd32:jansi-freebsd32:1.8:*:*:*:*:*:*:*",
 27942          "purl": "pkg:maven/org.fusesource.jansi/jansi-freebsd32@1.8",
 27943          "swid": {
 27944            "attachment": {}
 27945          },
 27946          "pedigree": {},
 27947          "evidence": {},
 27948          "signature": {
 27949            "signature": {
 27950              "publicKey": {}
 27951            }
 27952          },
 27953          "modelCard": {
 27954            "modelParameters": {
 27955              "approach": {}
 27956            },
 27957            "quantitativeAnalysis": {
 27958              "graphics": {}
 27959            },
 27960            "considerations": {}
 27961          }
 27962        },
 27963        {
 27964          "type": "library",
 27965          "bom-ref": "pkg:maven/org.fusesource.jansi/jansi-freebsd64@1.8?package-id=e51dba0a02aac9e",
 27966          "supplier": {},
 27967          "group": "org.fusesource.jansi",
 27968          "name": "jansi-freebsd64",
 27969          "version": "1.8",
 27970          "cpe": "cpe:2.3:a:jansi-freebsd64:jansi-freebsd64:1.8:*:*:*:*:*:*:*",
 27971          "purl": "pkg:maven/org.fusesource.jansi/jansi-freebsd64@1.8",
 27972          "swid": {
 27973            "attachment": {}
 27974          },
 27975          "pedigree": {},
 27976          "evidence": {},
 27977          "signature": {
 27978            "signature": {
 27979              "publicKey": {}
 27980            }
 27981          },
 27982          "modelCard": {
 27983            "modelParameters": {
 27984              "approach": {}
 27985            },
 27986            "quantitativeAnalysis": {
 27987              "graphics": {}
 27988            },
 27989            "considerations": {}
 27990          }
 27991        },
 27992        {
 27993          "type": "library",
 27994          "bom-ref": "pkg:maven/org.fusesource.jansi/jansi-linux32@1.8?package-id=e4755ea938ee0286",
 27995          "supplier": {},
 27996          "group": "org.fusesource.jansi",
 27997          "name": "jansi-linux32",
 27998          "version": "1.8",
 27999          "licenses": [
 28000            {
 28001              "license": {
 28002                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 28003              }
 28004            }
 28005          ],
 28006          "cpe": "cpe:2.3:a:fusesource\\,-corp-:jansi-linux32:1.8:*:*:*:*:*:*:*",
 28007          "purl": "pkg:maven/org.fusesource.jansi/jansi-linux32@1.8",
 28008          "swid": {
 28009            "attachment": {}
 28010          },
 28011          "pedigree": {},
 28012          "externalReferences": [
 28013            {
 28014              "type": "build-meta",
 28015              "hashes": [
 28016                {
 28017                  "alg": "SHA-1",
 28018                  "content": "d9205bbcd4b5f9cd1effe752d18f73bd942d783f"
 28019                }
 28020              ]
 28021            }
 28022          ],
 28023          "evidence": {},
 28024          "signature": {
 28025            "signature": {
 28026              "publicKey": {}
 28027            }
 28028          },
 28029          "modelCard": {
 28030            "modelParameters": {
 28031              "approach": {}
 28032            },
 28033            "quantitativeAnalysis": {
 28034              "graphics": {}
 28035            },
 28036            "considerations": {}
 28037          }
 28038        },
 28039        {
 28040          "type": "library",
 28041          "bom-ref": "pkg:maven/org.fusesource.jansi/jansi-linux64@1.8?package-id=2543a23a959b7460",
 28042          "supplier": {},
 28043          "group": "org.fusesource.jansi",
 28044          "name": "jansi-linux64",
 28045          "version": "1.8",
 28046          "cpe": "cpe:2.3:a:jansi-linux64:jansi-linux64:1.8:*:*:*:*:*:*:*",
 28047          "purl": "pkg:maven/org.fusesource.jansi/jansi-linux64@1.8",
 28048          "swid": {
 28049            "attachment": {}
 28050          },
 28051          "pedigree": {},
 28052          "evidence": {},
 28053          "signature": {
 28054            "signature": {
 28055              "publicKey": {}
 28056            }
 28057          },
 28058          "modelCard": {
 28059            "modelParameters": {
 28060              "approach": {}
 28061            },
 28062            "quantitativeAnalysis": {
 28063              "graphics": {}
 28064            },
 28065            "considerations": {}
 28066          }
 28067        },
 28068        {
 28069          "type": "library",
 28070          "bom-ref": "pkg:maven/org.fusesource.jansi/jansi-native@1.8?package-id=c4e9dbb255a7604c",
 28071          "supplier": {},
 28072          "group": "org.fusesource.jansi",
 28073          "name": "jansi-native",
 28074          "version": "1.8",
 28075          "cpe": "cpe:2.3:a:jansi-native:jansi-native:1.8:*:*:*:*:*:*:*",
 28076          "purl": "pkg:maven/org.fusesource.jansi/jansi-native@1.8",
 28077          "swid": {
 28078            "attachment": {}
 28079          },
 28080          "pedigree": {},
 28081          "evidence": {},
 28082          "signature": {
 28083            "signature": {
 28084              "publicKey": {}
 28085            }
 28086          },
 28087          "modelCard": {
 28088            "modelParameters": {
 28089              "approach": {}
 28090            },
 28091            "quantitativeAnalysis": {
 28092              "graphics": {}
 28093            },
 28094            "considerations": {}
 28095          }
 28096        },
 28097        {
 28098          "type": "library",
 28099          "bom-ref": "pkg:maven/org.fusesource.jansi/jansi-osx@1.8?package-id=920592cacba9b51a",
 28100          "supplier": {},
 28101          "group": "org.fusesource.jansi",
 28102          "name": "jansi-osx",
 28103          "version": "1.8",
 28104          "cpe": "cpe:2.3:a:fusesource:jansi-osx:1.8:*:*:*:*:*:*:*",
 28105          "purl": "pkg:maven/org.fusesource.jansi/jansi-osx@1.8",
 28106          "swid": {
 28107            "attachment": {}
 28108          },
 28109          "pedigree": {},
 28110          "evidence": {},
 28111          "signature": {
 28112            "signature": {
 28113              "publicKey": {}
 28114            }
 28115          },
 28116          "modelCard": {
 28117            "modelParameters": {
 28118              "approach": {}
 28119            },
 28120            "quantitativeAnalysis": {
 28121              "graphics": {}
 28122            },
 28123            "considerations": {}
 28124          }
 28125        },
 28126        {
 28127          "type": "library",
 28128          "bom-ref": "pkg:maven/org.fusesource.jansi/jansi-windows32@1.8?package-id=2ae0f5208a8fbec4",
 28129          "supplier": {},
 28130          "group": "org.fusesource.jansi",
 28131          "name": "jansi-windows32",
 28132          "version": "1.8",
 28133          "cpe": "cpe:2.3:a:jansi-windows32:jansi-windows32:1.8:*:*:*:*:*:*:*",
 28134          "purl": "pkg:maven/org.fusesource.jansi/jansi-windows32@1.8",
 28135          "swid": {
 28136            "attachment": {}
 28137          },
 28138          "pedigree": {},
 28139          "evidence": {},
 28140          "signature": {
 28141            "signature": {
 28142              "publicKey": {}
 28143            }
 28144          },
 28145          "modelCard": {
 28146            "modelParameters": {
 28147              "approach": {}
 28148            },
 28149            "quantitativeAnalysis": {
 28150              "graphics": {}
 28151            },
 28152            "considerations": {}
 28153          }
 28154        },
 28155        {
 28156          "type": "library",
 28157          "bom-ref": "pkg:maven/org.fusesource.jansi/jansi-windows64@1.8?package-id=aab81dc393bb54a3",
 28158          "supplier": {},
 28159          "group": "org.fusesource.jansi",
 28160          "name": "jansi-windows64",
 28161          "version": "1.8",
 28162          "cpe": "cpe:2.3:a:jansi-windows64:jansi-windows64:1.8:*:*:*:*:*:*:*",
 28163          "purl": "pkg:maven/org.fusesource.jansi/jansi-windows64@1.8",
 28164          "swid": {
 28165            "attachment": {}
 28166          },
 28167          "pedigree": {},
 28168          "evidence": {},
 28169          "signature": {
 28170            "signature": {
 28171              "publicKey": {}
 28172            }
 28173          },
 28174          "modelCard": {
 28175            "modelParameters": {
 28176              "approach": {}
 28177            },
 28178            "quantitativeAnalysis": {
 28179              "graphics": {}
 28180            },
 28181            "considerations": {}
 28182          }
 28183        },
 28184        {
 28185          "type": "application",
 28186          "bom-ref": "pkg:generic/java@1.8.0_362-b09?package-id=df80297034b58157",
 28187          "supplier": {},
 28188          "name": "java",
 28189          "version": "1.8.0_362-b09",
 28190          "cpe": "cpe:2.3:a:oracle:openjdk:1.8.0_362-b09:*:*:*:*:*:*:*",
 28191          "purl": "pkg:generic/java@1.8.0_362-b09",
 28192          "swid": {
 28193            "attachment": {}
 28194          },
 28195          "pedigree": {},
 28196          "evidence": {},
 28197          "signature": {
 28198            "signature": {
 28199              "publicKey": {}
 28200            }
 28201          },
 28202          "modelCard": {
 28203            "modelParameters": {
 28204              "approach": {}
 28205            },
 28206            "quantitativeAnalysis": {
 28207              "graphics": {}
 28208            },
 28209            "considerations": {}
 28210          }
 28211        },
 28212        {
 28213          "type": "library",
 28214          "bom-ref": "pkg:maven/com.sun/jce@1.8.0_362?package-id=a8c489b1d53d3920",
 28215          "supplier": {},
 28216          "name": "jce",
 28217          "version": "1.8.0_362",
 28218          "cpe": "cpe:2.3:a:oracle-corporation:jce:1.8.0_362:*:*:*:*:*:*:*",
 28219          "purl": "pkg:maven/com.sun/jce@1.8.0_362",
 28220          "swid": {
 28221            "attachment": {}
 28222          },
 28223          "pedigree": {},
 28224          "externalReferences": [
 28225            {
 28226              "type": "build-meta",
 28227              "hashes": [
 28228                {
 28229                  "alg": "SHA-1",
 28230                  "content": "ea30f8fc11602d5de2fc30432e5c489364bb7d2e"
 28231                }
 28232              ]
 28233            }
 28234          ],
 28235          "evidence": {},
 28236          "signature": {
 28237            "signature": {
 28238              "publicKey": {}
 28239            }
 28240          },
 28241          "modelCard": {
 28242            "modelParameters": {
 28243              "approach": {}
 28244            },
 28245            "quantitativeAnalysis": {
 28246              "graphics": {}
 28247            },
 28248            "considerations": {}
 28249          }
 28250        },
 28251        {
 28252          "type": "library",
 28253          "bom-ref": "pkg:maven/jfr/jfr@1.8.0_362?package-id=a79464b21bb17e9e",
 28254          "supplier": {},
 28255          "name": "jfr",
 28256          "version": "1.8.0_362",
 28257          "cpe": "cpe:2.3:a:oracle-corporation:jfr:1.8.0_362:*:*:*:*:*:*:*",
 28258          "purl": "pkg:maven/jfr/jfr@1.8.0_362",
 28259          "swid": {
 28260            "attachment": {}
 28261          },
 28262          "pedigree": {},
 28263          "externalReferences": [
 28264            {
 28265              "type": "build-meta",
 28266              "hashes": [
 28267                {
 28268                  "alg": "SHA-1",
 28269                  "content": "88dbd83bf6b99249cb4a27d94cd9db30eed845d5"
 28270                }
 28271              ]
 28272            }
 28273          ],
 28274          "evidence": {},
 28275          "signature": {
 28276            "signature": {
 28277              "publicKey": {}
 28278            }
 28279          },
 28280          "modelCard": {
 28281            "modelParameters": {
 28282              "approach": {}
 28283            },
 28284            "quantitativeAnalysis": {
 28285              "graphics": {}
 28286            },
 28287            "considerations": {}
 28288          }
 28289        },
 28290        {
 28291          "type": "library",
 28292          "bom-ref": "pkg:maven/jsse/jsse@1.8.0_362?package-id=c373477973ee44a0",
 28293          "supplier": {},
 28294          "name": "jsse",
 28295          "version": "1.8.0_362",
 28296          "cpe": "cpe:2.3:a:oracle-corporation:jsse:1.8.0_362:*:*:*:*:*:*:*",
 28297          "purl": "pkg:maven/jsse/jsse@1.8.0_362",
 28298          "swid": {
 28299            "attachment": {}
 28300          },
 28301          "pedigree": {},
 28302          "externalReferences": [
 28303            {
 28304              "type": "build-meta",
 28305              "hashes": [
 28306                {
 28307                  "alg": "SHA-1",
 28308                  "content": "e2cc27ebb60ca839f44d9794f18450eb23cf44b4"
 28309                }
 28310              ]
 28311            }
 28312          ],
 28313          "evidence": {},
 28314          "signature": {
 28315            "signature": {
 28316              "publicKey": {}
 28317            }
 28318          },
 28319          "modelCard": {
 28320            "modelParameters": {
 28321              "approach": {}
 28322            },
 28323            "quantitativeAnalysis": {
 28324              "graphics": {}
 28325            },
 28326            "considerations": {}
 28327          }
 28328        },
 28329        {
 28330          "type": "library",
 28331          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r4?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.17.3\u0026package-id=60a12fd5038efa61",
 28332          "supplier": {},
 28333          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 28334          "name": "libbz2",
 28335          "version": "1.0.8-r4",
 28336          "description": "Shared library for bz2",
 28337          "licenses": [
 28338            {
 28339              "license": {
 28340                "id": "bzip2-1.0.6"
 28341              }
 28342            }
 28343          ],
 28344          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r4:*:*:*:*:*:*:*",
 28345          "purl": "pkg:apk/alpine/libbz2@1.0.8-r4?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.17.3",
 28346          "swid": {
 28347            "attachment": {}
 28348          },
 28349          "pedigree": {},
 28350          "externalReferences": [
 28351            {
 28352              "url": "https://sourceware.org/bzip2/",
 28353              "type": "distribution"
 28354            }
 28355          ],
 28356          "evidence": {},
 28357          "signature": {
 28358            "signature": {
 28359              "publicKey": {}
 28360            }
 28361          },
 28362          "modelCard": {
 28363            "modelParameters": {
 28364              "approach": {}
 28365            },
 28366            "quantitativeAnalysis": {
 28367              "graphics": {}
 28368            },
 28369            "considerations": {}
 28370          }
 28371        },
 28372        {
 28373          "type": "library",
 28374          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.3\u0026package-id=8126b232e2d3c608",
 28375          "supplier": {},
 28376          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 28377          "name": "libc-utils",
 28378          "version": "0.7.2-r3",
 28379          "description": "Meta package to pull in correct libc",
 28380          "licenses": [
 28381            {
 28382              "license": {
 28383                "id": "BSD-2-Clause"
 28384              }
 28385            },
 28386            {
 28387              "license": {
 28388                "name": "AND"
 28389              }
 28390            },
 28391            {
 28392              "license": {
 28393                "id": "BSD-3-Clause"
 28394              }
 28395            }
 28396          ],
 28397          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
 28398          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.3",
 28399          "swid": {
 28400            "attachment": {}
 28401          },
 28402          "pedigree": {},
 28403          "externalReferences": [
 28404            {
 28405              "url": "https://alpinelinux.org",
 28406              "type": "distribution"
 28407            }
 28408          ],
 28409          "evidence": {},
 28410          "signature": {
 28411            "signature": {
 28412              "publicKey": {}
 28413            }
 28414          },
 28415          "modelCard": {
 28416            "modelParameters": {
 28417              "approach": {}
 28418            },
 28419            "quantitativeAnalysis": {
 28420              "graphics": {}
 28421            },
 28422            "considerations": {}
 28423          }
 28424        },
 28425        {
 28426          "type": "library",
 28427          "bom-ref": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3\u0026package-id=d3084c788891fb28",
 28428          "supplier": {},
 28429          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 28430          "name": "libcrypto3",
 28431          "version": "3.0.8-r3",
 28432          "description": "Crypto library from openssl",
 28433          "licenses": [
 28434            {
 28435              "license": {
 28436                "id": "Apache-2.0"
 28437              }
 28438            }
 28439          ],
 28440          "cpe": "cpe:2.3:a:libcrypto3:libcrypto3:3.0.8-r3:*:*:*:*:*:*:*",
 28441          "purl": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3",
 28442          "swid": {
 28443            "attachment": {}
 28444          },
 28445          "pedigree": {},
 28446          "externalReferences": [
 28447            {
 28448              "url": "https://www.openssl.org/",
 28449              "type": "distribution"
 28450            }
 28451          ],
 28452          "evidence": {},
 28453          "signature": {
 28454            "signature": {
 28455              "publicKey": {}
 28456            }
 28457          },
 28458          "modelCard": {
 28459            "modelParameters": {
 28460              "approach": {}
 28461            },
 28462            "quantitativeAnalysis": {
 28463              "graphics": {}
 28464            },
 28465            "considerations": {}
 28466          }
 28467        },
 28468        {
 28469          "type": "library",
 28470          "bom-ref": "pkg:apk/alpine/libexpat@2.5.0-r0?arch=x86_64\u0026upstream=expat\u0026distro=alpine-3.17.3\u0026package-id=3230d7655464b5cd",
 28471          "supplier": {},
 28472          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 28473          "name": "libexpat",
 28474          "version": "2.5.0-r0",
 28475          "description": "XML Parser library written in C (libraries)",
 28476          "licenses": [
 28477            {
 28478              "license": {
 28479                "id": "MIT"
 28480              }
 28481            }
 28482          ],
 28483          "cpe": "cpe:2.3:a:libexpat:libexpat:2.5.0-r0:*:*:*:*:*:*:*",
 28484          "purl": "pkg:apk/alpine/libexpat@2.5.0-r0?arch=x86_64\u0026upstream=expat\u0026distro=alpine-3.17.3",
 28485          "swid": {
 28486            "attachment": {}
 28487          },
 28488          "pedigree": {},
 28489          "externalReferences": [
 28490            {
 28491              "url": "https://libexpat.github.io/",
 28492              "type": "distribution"
 28493            }
 28494          ],
 28495          "evidence": {},
 28496          "signature": {
 28497            "signature": {
 28498              "publicKey": {}
 28499            }
 28500          },
 28501          "modelCard": {
 28502            "modelParameters": {
 28503              "approach": {}
 28504            },
 28505            "quantitativeAnalysis": {
 28506              "graphics": {}
 28507            },
 28508            "considerations": {}
 28509          }
 28510        },
 28511        {
 28512          "type": "library",
 28513          "bom-ref": "pkg:apk/alpine/libfontenc@1.1.6-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=4b664e9d006f8d78",
 28514          "supplier": {},
 28515          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 28516          "name": "libfontenc",
 28517          "version": "1.1.6-r0",
 28518          "description": "X11 font encoding library",
 28519          "licenses": [
 28520            {
 28521              "license": {
 28522                "id": "MIT"
 28523              }
 28524            }
 28525          ],
 28526          "cpe": "cpe:2.3:a:libfontenc:libfontenc:1.1.6-r0:*:*:*:*:*:*:*",
 28527          "purl": "pkg:apk/alpine/libfontenc@1.1.6-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 28528          "swid": {
 28529            "attachment": {}
 28530          },
 28531          "pedigree": {},
 28532          "externalReferences": [
 28533            {
 28534              "url": "http://xorg.freedesktop.org/",
 28535              "type": "distribution"
 28536            }
 28537          ],
 28538          "evidence": {},
 28539          "signature": {
 28540            "signature": {
 28541              "publicKey": {}
 28542            }
 28543          },
 28544          "modelCard": {
 28545            "modelParameters": {
 28546              "approach": {}
 28547            },
 28548            "quantitativeAnalysis": {
 28549              "graphics": {}
 28550            },
 28551            "considerations": {}
 28552          }
 28553        },
 28554        {
 28555          "type": "library",
 28556          "bom-ref": "pkg:apk/alpine/libpng@1.6.38-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=de4865c94634be51",
 28557          "supplier": {},
 28558          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 28559          "name": "libpng",
 28560          "version": "1.6.38-r0",
 28561          "description": "Portable Network Graphics library",
 28562          "licenses": [
 28563            {
 28564              "license": {
 28565                "id": "Libpng"
 28566              }
 28567            }
 28568          ],
 28569          "cpe": "cpe:2.3:a:libpng:libpng:1.6.38-r0:*:*:*:*:*:*:*",
 28570          "purl": "pkg:apk/alpine/libpng@1.6.38-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 28571          "swid": {
 28572            "attachment": {}
 28573          },
 28574          "pedigree": {},
 28575          "externalReferences": [
 28576            {
 28577              "url": "http://www.libpng.org",
 28578              "type": "distribution"
 28579            }
 28580          ],
 28581          "evidence": {},
 28582          "signature": {
 28583            "signature": {
 28584              "publicKey": {}
 28585            }
 28586          },
 28587          "modelCard": {
 28588            "modelParameters": {
 28589              "approach": {}
 28590            },
 28591            "quantitativeAnalysis": {
 28592              "graphics": {}
 28593            },
 28594            "considerations": {}
 28595          }
 28596        },
 28597        {
 28598          "type": "library",
 28599          "bom-ref": "pkg:apk/alpine/libretls@3.5.2-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=1539d83bb0f27113",
 28600          "supplier": {},
 28601          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 28602          "name": "libretls",
 28603          "version": "3.5.2-r1",
 28604          "description": "port of libtls from libressl to openssl",
 28605          "licenses": [
 28606            {
 28607              "license": {
 28608                "id": "ISC"
 28609              }
 28610            },
 28611            {
 28612              "license": {
 28613                "name": "AND"
 28614              }
 28615            },
 28616            {
 28617              "license": {
 28618                "name": "("
 28619              }
 28620            },
 28621            {
 28622              "license": {
 28623                "id": "BSD-3-Clause"
 28624              }
 28625            },
 28626            {
 28627              "license": {
 28628                "name": "OR"
 28629              }
 28630            },
 28631            {
 28632              "license": {
 28633                "id": "MIT"
 28634              }
 28635            },
 28636            {
 28637              "license": {
 28638                "name": ")"
 28639              }
 28640            }
 28641          ],
 28642          "cpe": "cpe:2.3:a:libretls:libretls:3.5.2-r1:*:*:*:*:*:*:*",
 28643          "purl": "pkg:apk/alpine/libretls@3.5.2-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 28644          "swid": {
 28645            "attachment": {}
 28646          },
 28647          "pedigree": {},
 28648          "externalReferences": [
 28649            {
 28650              "url": "https://git.causal.agency/libretls/",
 28651              "type": "distribution"
 28652            }
 28653          ],
 28654          "evidence": {},
 28655          "signature": {
 28656            "signature": {
 28657              "publicKey": {}
 28658            }
 28659          },
 28660          "modelCard": {
 28661            "modelParameters": {
 28662              "approach": {}
 28663            },
 28664            "quantitativeAnalysis": {
 28665              "graphics": {}
 28666            },
 28667            "considerations": {}
 28668          }
 28669        },
 28670        {
 28671          "type": "library",
 28672          "bom-ref": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3\u0026package-id=2a95f0251fba7a33",
 28673          "supplier": {},
 28674          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 28675          "name": "libssl3",
 28676          "version": "3.0.8-r3",
 28677          "description": "SSL shared libraries",
 28678          "licenses": [
 28679            {
 28680              "license": {
 28681                "id": "Apache-2.0"
 28682              }
 28683            }
 28684          ],
 28685          "cpe": "cpe:2.3:a:libssl3:libssl3:3.0.8-r3:*:*:*:*:*:*:*",
 28686          "purl": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3",
 28687          "swid": {
 28688            "attachment": {}
 28689          },
 28690          "pedigree": {},
 28691          "externalReferences": [
 28692            {
 28693              "url": "https://www.openssl.org/",
 28694              "type": "distribution"
 28695            }
 28696          ],
 28697          "evidence": {},
 28698          "signature": {
 28699            "signature": {
 28700              "publicKey": {}
 28701            }
 28702          },
 28703          "modelCard": {
 28704            "modelParameters": {
 28705              "approach": {}
 28706            },
 28707            "quantitativeAnalysis": {
 28708              "graphics": {}
 28709            },
 28710            "considerations": {}
 28711          }
 28712        },
 28713        {
 28714          "type": "library",
 28715          "bom-ref": "pkg:maven/local_policy/local_policy?package-id=7e5a8ee4262b37db",
 28716          "supplier": {},
 28717          "name": "local_policy",
 28718          "cpe": "cpe:2.3:a:local-policy:local-policy:*:*:*:*:*:*:*:*",
 28719          "purl": "pkg:maven/local_policy/local_policy",
 28720          "swid": {
 28721            "attachment": {}
 28722          },
 28723          "pedigree": {},
 28724          "externalReferences": [
 28725            {
 28726              "type": "build-meta",
 28727              "hashes": [
 28728                {
 28729                  "alg": "SHA-1",
 28730                  "content": "bc70ce9f98d1f3ebcf41bb5e7b92556a5a2d4788"
 28731                }
 28732              ]
 28733            }
 28734          ],
 28735          "evidence": {},
 28736          "signature": {
 28737            "signature": {
 28738              "publicKey": {}
 28739            }
 28740          },
 28741          "modelCard": {
 28742            "modelParameters": {
 28743              "approach": {}
 28744            },
 28745            "quantitativeAnalysis": {
 28746              "graphics": {}
 28747            },
 28748            "considerations": {}
 28749          }
 28750        },
 28751        {
 28752          "type": "library",
 28753          "bom-ref": "pkg:maven/local_policy/local_policy?package-id=6060fa0479e27db5",
 28754          "supplier": {},
 28755          "name": "local_policy",
 28756          "cpe": "cpe:2.3:a:local-policy:local-policy:*:*:*:*:*:*:*:*",
 28757          "purl": "pkg:maven/local_policy/local_policy",
 28758          "swid": {
 28759            "attachment": {}
 28760          },
 28761          "pedigree": {},
 28762          "externalReferences": [
 28763            {
 28764              "type": "build-meta",
 28765              "hashes": [
 28766                {
 28767                  "alg": "SHA-1",
 28768                  "content": "8ab714610f8bf90411dc029a09ecd27c2b60c804"
 28769                }
 28770              ]
 28771            }
 28772          ],
 28773          "evidence": {},
 28774          "signature": {
 28775            "signature": {
 28776              "publicKey": {}
 28777            }
 28778          },
 28779          "modelCard": {
 28780            "modelParameters": {
 28781              "approach": {}
 28782            },
 28783            "quantitativeAnalysis": {
 28784              "graphics": {}
 28785            },
 28786            "considerations": {}
 28787          }
 28788        },
 28789        {
 28790          "type": "library",
 28791          "bom-ref": "pkg:maven/localedata/localedata?package-id=3d9158e219a57e4d",
 28792          "supplier": {},
 28793          "name": "localedata",
 28794          "cpe": "cpe:2.3:a:localedata:localedata:*:*:*:*:*:*:*:*",
 28795          "purl": "pkg:maven/localedata/localedata",
 28796          "swid": {
 28797            "attachment": {}
 28798          },
 28799          "pedigree": {},
 28800          "externalReferences": [
 28801            {
 28802              "type": "build-meta",
 28803              "hashes": [
 28804                {
 28805                  "alg": "SHA-1",
 28806                  "content": "fd7f6a9ee8e6263caca5c369c0bb813702c672c0"
 28807                }
 28808              ]
 28809            }
 28810          ],
 28811          "evidence": {},
 28812          "signature": {
 28813            "signature": {
 28814              "publicKey": {}
 28815            }
 28816          },
 28817          "modelCard": {
 28818            "modelParameters": {
 28819              "approach": {}
 28820            },
 28821            "quantitativeAnalysis": {
 28822              "graphics": {}
 28823            },
 28824            "considerations": {}
 28825          }
 28826        },
 28827        {
 28828          "type": "library",
 28829          "bom-ref": "pkg:maven/management-agent/management-agent?package-id=7defce2ca9e0fee2",
 28830          "supplier": {},
 28831          "name": "management-agent",
 28832          "cpe": "cpe:2.3:a:management-agent:management-agent:*:*:*:*:*:*:*:*",
 28833          "purl": "pkg:maven/management-agent/management-agent",
 28834          "swid": {
 28835            "attachment": {}
 28836          },
 28837          "pedigree": {},
 28838          "externalReferences": [
 28839            {
 28840              "type": "build-meta",
 28841              "hashes": [
 28842                {
 28843                  "alg": "SHA-1",
 28844                  "content": "66e296ac38ffd9d835b2c91f67cde75891e81631"
 28845                }
 28846              ]
 28847            }
 28848          ],
 28849          "evidence": {},
 28850          "signature": {
 28851            "signature": {
 28852              "publicKey": {}
 28853            }
 28854          },
 28855          "modelCard": {
 28856            "modelParameters": {
 28857              "approach": {}
 28858            },
 28859            "quantitativeAnalysis": {
 28860              "graphics": {}
 28861            },
 28862            "considerations": {}
 28863          }
 28864        },
 28865        {
 28866          "type": "library",
 28867          "bom-ref": "pkg:apk/alpine/mkfontscale@1.2.2-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=5556aac06b098482",
 28868          "supplier": {},
 28869          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 28870          "name": "mkfontscale",
 28871          "version": "1.2.2-r1",
 28872          "description": "Scalable font index generator for X",
 28873          "licenses": [
 28874            {
 28875              "license": {
 28876                "id": "MIT"
 28877              }
 28878            }
 28879          ],
 28880          "cpe": "cpe:2.3:a:mkfontscale:mkfontscale:1.2.2-r1:*:*:*:*:*:*:*",
 28881          "purl": "pkg:apk/alpine/mkfontscale@1.2.2-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 28882          "swid": {
 28883            "attachment": {}
 28884          },
 28885          "pedigree": {},
 28886          "externalReferences": [
 28887            {
 28888              "url": "http://xorg.freedesktop.org",
 28889              "type": "distribution"
 28890            }
 28891          ],
 28892          "evidence": {},
 28893          "signature": {
 28894            "signature": {
 28895              "publicKey": {}
 28896            }
 28897          },
 28898          "modelCard": {
 28899            "modelParameters": {
 28900              "approach": {}
 28901            },
 28902            "quantitativeAnalysis": {
 28903              "graphics": {}
 28904            },
 28905            "considerations": {}
 28906          }
 28907        },
 28908        {
 28909          "type": "library",
 28910          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=d9700f02cf26e8b8",
 28911          "supplier": {},
 28912          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 28913          "name": "musl",
 28914          "version": "1.2.3-r4",
 28915          "description": "the musl c library (libc) implementation",
 28916          "licenses": [
 28917            {
 28918              "license": {
 28919                "id": "MIT"
 28920              }
 28921            }
 28922          ],
 28923          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r4:*:*:*:*:*:*:*",
 28924          "purl": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.3",
 28925          "swid": {
 28926            "attachment": {}
 28927          },
 28928          "pedigree": {},
 28929          "externalReferences": [
 28930            {
 28931              "url": "https://musl.libc.org/",
 28932              "type": "distribution"
 28933            }
 28934          ],
 28935          "evidence": {},
 28936          "signature": {
 28937            "signature": {
 28938              "publicKey": {}
 28939            }
 28940          },
 28941          "modelCard": {
 28942            "modelParameters": {
 28943              "approach": {}
 28944            },
 28945            "quantitativeAnalysis": {
 28946              "graphics": {}
 28947            },
 28948            "considerations": {}
 28949          }
 28950        },
 28951        {
 28952          "type": "library",
 28953          "bom-ref": "pkg:apk/alpine/musl-locales@0.1.0-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2711b5f56d3082dd",
 28954          "supplier": {},
 28955          "publisher": "TBK \u003calpine@jjtc.eu\u003e",
 28956          "name": "musl-locales",
 28957          "version": "0.1.0-r0",
 28958          "description": "Locales support for musl",
 28959          "licenses": [
 28960            {
 28961              "license": {
 28962                "id": "LGPL-3.0-only"
 28963              }
 28964            }
 28965          ],
 28966          "cpe": "cpe:2.3:a:musl-locales:musl-locales:0.1.0-r0:*:*:*:*:*:*:*",
 28967          "purl": "pkg:apk/alpine/musl-locales@0.1.0-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 28968          "swid": {
 28969            "attachment": {}
 28970          },
 28971          "pedigree": {},
 28972          "externalReferences": [
 28973            {
 28974              "url": "https://git.adelielinux.org/adelie/musl-locales/-/wikis/home",
 28975              "type": "distribution"
 28976            }
 28977          ],
 28978          "evidence": {},
 28979          "signature": {
 28980            "signature": {
 28981              "publicKey": {}
 28982            }
 28983          },
 28984          "modelCard": {
 28985            "modelParameters": {
 28986              "approach": {}
 28987            },
 28988            "quantitativeAnalysis": {
 28989              "graphics": {}
 28990            },
 28991            "considerations": {}
 28992          }
 28993        },
 28994        {
 28995          "type": "library",
 28996          "bom-ref": "pkg:apk/alpine/musl-locales-lang@0.1.0-r0?arch=x86_64\u0026upstream=musl-locales\u0026distro=alpine-3.17.3\u0026package-id=a5f7a593669f92ef",
 28997          "supplier": {},
 28998          "publisher": "TBK \u003calpine@jjtc.eu\u003e",
 28999          "name": "musl-locales-lang",
 29000          "version": "0.1.0-r0",
 29001          "description": "Languages for package musl-locales",
 29002          "licenses": [
 29003            {
 29004              "license": {
 29005                "id": "MIT"
 29006              }
 29007            }
 29008          ],
 29009          "cpe": "cpe:2.3:a:musl-locales-lang:musl-locales-lang:0.1.0-r0:*:*:*:*:*:*:*",
 29010          "purl": "pkg:apk/alpine/musl-locales-lang@0.1.0-r0?arch=x86_64\u0026upstream=musl-locales\u0026distro=alpine-3.17.3",
 29011          "swid": {
 29012            "attachment": {}
 29013          },
 29014          "pedigree": {},
 29015          "externalReferences": [
 29016            {
 29017              "url": "https://git.adelielinux.org/adelie/musl-locales/-/wikis/home",
 29018              "type": "distribution"
 29019            }
 29020          ],
 29021          "evidence": {},
 29022          "signature": {
 29023            "signature": {
 29024              "publicKey": {}
 29025            }
 29026          },
 29027          "modelCard": {
 29028            "modelParameters": {
 29029              "approach": {}
 29030            },
 29031            "quantitativeAnalysis": {
 29032              "graphics": {}
 29033            },
 29034            "considerations": {}
 29035          }
 29036        },
 29037        {
 29038          "type": "library",
 29039          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.3\u0026package-id=f71ecf5267e6c37b",
 29040          "supplier": {},
 29041          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 29042          "name": "musl-utils",
 29043          "version": "1.2.3-r4",
 29044          "description": "the musl c library (libc) implementation",
 29045          "licenses": [
 29046            {
 29047              "license": {
 29048                "id": "MIT"
 29049              }
 29050            },
 29051            {
 29052              "license": {
 29053                "name": "AND"
 29054              }
 29055            },
 29056            {
 29057              "license": {
 29058                "id": "BSD-2-Clause"
 29059              }
 29060            },
 29061            {
 29062              "license": {
 29063                "name": "AND"
 29064              }
 29065            },
 29066            {
 29067              "license": {
 29068                "id": "GPL-2.0-or-later"
 29069              }
 29070            }
 29071          ],
 29072          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r4:*:*:*:*:*:*:*",
 29073          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.3",
 29074          "swid": {
 29075            "attachment": {}
 29076          },
 29077          "pedigree": {},
 29078          "externalReferences": [
 29079            {
 29080              "url": "https://musl.libc.org/",
 29081              "type": "distribution"
 29082            }
 29083          ],
 29084          "evidence": {},
 29085          "signature": {
 29086            "signature": {
 29087              "publicKey": {}
 29088            }
 29089          },
 29090          "modelCard": {
 29091            "modelParameters": {
 29092              "approach": {}
 29093            },
 29094            "quantitativeAnalysis": {
 29095              "graphics": {}
 29096            },
 29097            "considerations": {}
 29098          }
 29099        },
 29100        {
 29101          "type": "library",
 29102          "bom-ref": "pkg:maven/com.mysql.cj/mysql-connector-java@8.0.17?package-id=7e34b98ca95beea6",
 29103          "supplier": {},
 29104          "name": "mysql-connector-java",
 29105          "version": "8.0.17",
 29106          "cpe": "cpe:2.3:a:mysql-connector-java:mysql-connector-java:8.0.17:*:*:*:*:*:*:*",
 29107          "purl": "pkg:maven/com.mysql.cj/mysql-connector-java@8.0.17",
 29108          "swid": {
 29109            "attachment": {}
 29110          },
 29111          "pedigree": {},
 29112          "externalReferences": [
 29113            {
 29114              "type": "build-meta",
 29115              "hashes": [
 29116                {
 29117                  "alg": "SHA-1",
 29118                  "content": "53da6afdc5f7b45caaa5bc3627028b2041a36cee"
 29119                }
 29120              ]
 29121            }
 29122          ],
 29123          "evidence": {},
 29124          "signature": {
 29125            "signature": {
 29126              "publicKey": {}
 29127            }
 29128          },
 29129          "modelCard": {
 29130            "modelParameters": {
 29131              "approach": {}
 29132            },
 29133            "quantitativeAnalysis": {
 29134              "graphics": {}
 29135            },
 29136            "considerations": {}
 29137          }
 29138        },
 29139        {
 29140          "type": "library",
 29141          "bom-ref": "pkg:maven/nashorn/nashorn@1.8.0_362-b09?package-id=ff4e7f4643e3b763",
 29142          "supplier": {},
 29143          "name": "nashorn",
 29144          "version": "1.8.0_362-b09",
 29145          "cpe": "cpe:2.3:a:oracle-corporation:nashorn:1.8.0_362-b09:*:*:*:*:*:*:*",
 29146          "purl": "pkg:maven/nashorn/nashorn@1.8.0_362-b09",
 29147          "swid": {
 29148            "attachment": {}
 29149          },
 29150          "pedigree": {},
 29151          "externalReferences": [
 29152            {
 29153              "type": "build-meta",
 29154              "hashes": [
 29155                {
 29156                  "alg": "SHA-1",
 29157                  "content": "85cadde4959b1188714a9d6bfde1304027f07e36"
 29158                }
 29159              ]
 29160            }
 29161          ],
 29162          "evidence": {},
 29163          "signature": {
 29164            "signature": {
 29165              "publicKey": {}
 29166            }
 29167          },
 29168          "modelCard": {
 29169            "modelParameters": {
 29170              "approach": {}
 29171            },
 29172            "quantitativeAnalysis": {
 29173              "graphics": {}
 29174            },
 29175            "considerations": {}
 29176          }
 29177        },
 29178        {
 29179          "type": "library",
 29180          "bom-ref": "pkg:maven/resources/resources@1.8.0_362?package-id=8580b1e6a4b5281a",
 29181          "supplier": {},
 29182          "name": "resources",
 29183          "version": "1.8.0_362",
 29184          "cpe": "cpe:2.3:a:oracle-corporation:resources:1.8.0_362:*:*:*:*:*:*:*",
 29185          "purl": "pkg:maven/resources/resources@1.8.0_362",
 29186          "swid": {
 29187            "attachment": {}
 29188          },
 29189          "pedigree": {},
 29190          "externalReferences": [
 29191            {
 29192              "type": "build-meta",
 29193              "hashes": [
 29194                {
 29195                  "alg": "SHA-1",
 29196                  "content": "34d2d9c5b59ee5ff757e7d766837a4f53947b7a1"
 29197                }
 29198              ]
 29199            }
 29200          ],
 29201          "evidence": {},
 29202          "signature": {
 29203            "signature": {
 29204              "publicKey": {}
 29205            }
 29206          },
 29207          "modelCard": {
 29208            "modelParameters": {
 29209              "approach": {}
 29210            },
 29211            "quantitativeAnalysis": {
 29212              "graphics": {}
 29213            },
 29214            "considerations": {}
 29215          }
 29216        },
 29217        {
 29218          "type": "library",
 29219          "bom-ref": "pkg:maven/rt/rt@1.8.0_362?package-id=a9e172c0e0dc2fce",
 29220          "supplier": {},
 29221          "name": "rt",
 29222          "version": "1.8.0_362",
 29223          "cpe": "cpe:2.3:a:oracle-corporation:rt:1.8.0_362:*:*:*:*:*:*:*",
 29224          "purl": "pkg:maven/rt/rt@1.8.0_362",
 29225          "swid": {
 29226            "attachment": {}
 29227          },
 29228          "pedigree": {},
 29229          "externalReferences": [
 29230            {
 29231              "type": "build-meta",
 29232              "hashes": [
 29233                {
 29234                  "alg": "SHA-1",
 29235                  "content": "d85439d089c379805dac978a1e27a9a3e465bb71"
 29236                }
 29237              ]
 29238            }
 29239          ],
 29240          "evidence": {},
 29241          "signature": {
 29242            "signature": {
 29243              "publicKey": {}
 29244            }
 29245          },
 29246          "modelCard": {
 29247            "modelParameters": {
 29248              "approach": {}
 29249            },
 29250            "quantitativeAnalysis": {
 29251              "graphics": {}
 29252            },
 29253            "considerations": {}
 29254          }
 29255        },
 29256        {
 29257          "type": "library",
 29258          "bom-ref": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.3\u0026package-id=e903138d19e85b80",
 29259          "supplier": {},
 29260          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 29261          "name": "scanelf",
 29262          "version": "1.3.5-r1",
 29263          "description": "Scan ELF binaries for stuff",
 29264          "licenses": [
 29265            {
 29266              "license": {
 29267                "id": "GPL-2.0-only"
 29268              }
 29269            }
 29270          ],
 29271          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.5-r1:*:*:*:*:*:*:*",
 29272          "purl": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.3",
 29273          "swid": {
 29274            "attachment": {}
 29275          },
 29276          "pedigree": {},
 29277          "externalReferences": [
 29278            {
 29279              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
 29280              "type": "distribution"
 29281            }
 29282          ],
 29283          "evidence": {},
 29284          "signature": {
 29285            "signature": {
 29286              "publicKey": {}
 29287            }
 29288          },
 29289          "modelCard": {
 29290            "modelParameters": {
 29291              "approach": {}
 29292            },
 29293            "quantitativeAnalysis": {
 29294              "graphics": {}
 29295            },
 29296            "considerations": {}
 29297          }
 29298        },
 29299        {
 29300          "type": "library",
 29301          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3\u0026package-id=b15247aafcd4a647",
 29302          "supplier": {},
 29303          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 29304          "name": "ssl_client",
 29305          "version": "1.35.0-r29",
 29306          "description": "EXternal ssl_client for busybox wget",
 29307          "licenses": [
 29308            {
 29309              "license": {
 29310                "id": "GPL-2.0-only"
 29311              }
 29312            }
 29313          ],
 29314          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r29:*:*:*:*:*:*:*",
 29315          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3",
 29316          "swid": {
 29317            "attachment": {}
 29318          },
 29319          "pedigree": {},
 29320          "externalReferences": [
 29321            {
 29322              "url": "https://busybox.net/",
 29323              "type": "distribution"
 29324            }
 29325          ],
 29326          "evidence": {},
 29327          "signature": {
 29328            "signature": {
 29329              "publicKey": {}
 29330            }
 29331          },
 29332          "modelCard": {
 29333            "modelParameters": {
 29334              "approach": {}
 29335            },
 29336            "quantitativeAnalysis": {
 29337              "graphics": {}
 29338            },
 29339            "considerations": {}
 29340          }
 29341        },
 29342        {
 29343          "type": "library",
 29344          "bom-ref": "pkg:maven/com.sun/sunec@1.8.0_362?package-id=514c2349426dbec0",
 29345          "supplier": {},
 29346          "name": "sunec",
 29347          "version": "1.8.0_362",
 29348          "cpe": "cpe:2.3:a:oracle-corporation:sunec:1.8.0_362:*:*:*:*:*:*:*",
 29349          "purl": "pkg:maven/com.sun/sunec@1.8.0_362",
 29350          "swid": {
 29351            "attachment": {}
 29352          },
 29353          "pedigree": {},
 29354          "externalReferences": [
 29355            {
 29356              "type": "build-meta",
 29357              "hashes": [
 29358                {
 29359                  "alg": "SHA-1",
 29360                  "content": "0a226bea7cf5d3f5bc9ab678f9a0abbbf2836ced"
 29361                }
 29362              ]
 29363            }
 29364          ],
 29365          "evidence": {},
 29366          "signature": {
 29367            "signature": {
 29368              "publicKey": {}
 29369            }
 29370          },
 29371          "modelCard": {
 29372            "modelParameters": {
 29373              "approach": {}
 29374            },
 29375            "quantitativeAnalysis": {
 29376              "graphics": {}
 29377            },
 29378            "considerations": {}
 29379          }
 29380        },
 29381        {
 29382          "type": "library",
 29383          "bom-ref": "pkg:maven/com.sun/sunjce_provider@1.8.0_362?package-id=216feec33fd91c68",
 29384          "supplier": {},
 29385          "name": "sunjce_provider",
 29386          "version": "1.8.0_362",
 29387          "cpe": "cpe:2.3:a:oracle-corporation:sunjce-provider:1.8.0_362:*:*:*:*:*:*:*",
 29388          "purl": "pkg:maven/com.sun/sunjce_provider@1.8.0_362",
 29389          "swid": {
 29390            "attachment": {}
 29391          },
 29392          "pedigree": {},
 29393          "externalReferences": [
 29394            {
 29395              "type": "build-meta",
 29396              "hashes": [
 29397                {
 29398                  "alg": "SHA-1",
 29399                  "content": "5d8e01ee58b00457ce81b3ab7641c7cf49c41fe4"
 29400                }
 29401              ]
 29402            }
 29403          ],
 29404          "evidence": {},
 29405          "signature": {
 29406            "signature": {
 29407              "publicKey": {}
 29408            }
 29409          },
 29410          "modelCard": {
 29411            "modelParameters": {
 29412              "approach": {}
 29413            },
 29414            "quantitativeAnalysis": {
 29415              "graphics": {}
 29416            },
 29417            "considerations": {}
 29418          }
 29419        },
 29420        {
 29421          "type": "library",
 29422          "bom-ref": "pkg:maven/com.sun/sunpkcs11@1.8.0_362?package-id=9814d36df586abb0",
 29423          "supplier": {},
 29424          "name": "sunpkcs11",
 29425          "version": "1.8.0_362",
 29426          "cpe": "cpe:2.3:a:oracle-corporation:sunpkcs11:1.8.0_362:*:*:*:*:*:*:*",
 29427          "purl": "pkg:maven/com.sun/sunpkcs11@1.8.0_362",
 29428          "swid": {
 29429            "attachment": {}
 29430          },
 29431          "pedigree": {},
 29432          "externalReferences": [
 29433            {
 29434              "type": "build-meta",
 29435              "hashes": [
 29436                {
 29437                  "alg": "SHA-1",
 29438                  "content": "bcf85f75350c04e0abc12a15ea7a0325d8131599"
 29439                }
 29440              ]
 29441            }
 29442          ],
 29443          "evidence": {},
 29444          "signature": {
 29445            "signature": {
 29446              "publicKey": {}
 29447            }
 29448          },
 29449          "modelCard": {
 29450            "modelParameters": {
 29451              "approach": {}
 29452            },
 29453            "quantitativeAnalysis": {
 29454              "graphics": {}
 29455            },
 29456            "considerations": {}
 29457          }
 29458        },
 29459        {
 29460          "type": "library",
 29461          "bom-ref": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=7443bdf13c73d18c",
 29462          "supplier": {},
 29463          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 29464          "name": "tzdata",
 29465          "version": "2023c-r0",
 29466          "description": "Timezone data",
 29467          "licenses": [
 29468            {
 29469              "license": {
 29470                "name": "Public-Domain"
 29471              }
 29472            }
 29473          ],
 29474          "cpe": "cpe:2.3:a:tzdata:tzdata:2023c-r0:*:*:*:*:*:*:*",
 29475          "purl": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 29476          "swid": {
 29477            "attachment": {}
 29478          },
 29479          "pedigree": {},
 29480          "externalReferences": [
 29481            {
 29482              "url": "https://www.iana.org/time-zones",
 29483              "type": "distribution"
 29484            }
 29485          ],
 29486          "evidence": {},
 29487          "signature": {
 29488            "signature": {
 29489              "publicKey": {}
 29490            }
 29491          },
 29492          "modelCard": {
 29493            "modelParameters": {
 29494              "approach": {}
 29495            },
 29496            "quantitativeAnalysis": {
 29497              "graphics": {}
 29498            },
 29499            "considerations": {}
 29500          }
 29501        },
 29502        {
 29503          "type": "library",
 29504          "bom-ref": "pkg:maven/zipfs/zipfs@1.8.0_362?package-id=649443e35eb779e0",
 29505          "supplier": {},
 29506          "name": "zipfs",
 29507          "version": "1.8.0_362",
 29508          "cpe": "cpe:2.3:a:oracle-corporation:zipfs:1.8.0_362:*:*:*:*:*:*:*",
 29509          "purl": "pkg:maven/zipfs/zipfs@1.8.0_362",
 29510          "swid": {
 29511            "attachment": {}
 29512          },
 29513          "pedigree": {},
 29514          "externalReferences": [
 29515            {
 29516              "type": "build-meta",
 29517              "hashes": [
 29518                {
 29519                  "alg": "SHA-1",
 29520                  "content": "8826341a6c075308576e50fa5f97c0cdbea0b844"
 29521                }
 29522              ]
 29523            }
 29524          ],
 29525          "evidence": {},
 29526          "signature": {
 29527            "signature": {
 29528              "publicKey": {}
 29529            }
 29530          },
 29531          "modelCard": {
 29532            "modelParameters": {
 29533              "approach": {}
 29534            },
 29535            "quantitativeAnalysis": {
 29536              "graphics": {}
 29537            },
 29538            "considerations": {}
 29539          }
 29540        },
 29541        {
 29542          "type": "library",
 29543          "bom-ref": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=94014313cfcd2b71",
 29544          "supplier": {},
 29545          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 29546          "name": "zlib",
 29547          "version": "1.2.13-r0",
 29548          "description": "A compression/decompression Library",
 29549          "licenses": [
 29550            {
 29551              "license": {
 29552                "id": "Zlib"
 29553              }
 29554            }
 29555          ],
 29556          "cpe": "cpe:2.3:a:zlib:zlib:1.2.13-r0:*:*:*:*:*:*:*",
 29557          "purl": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 29558          "swid": {
 29559            "attachment": {}
 29560          },
 29561          "pedigree": {},
 29562          "externalReferences": [
 29563            {
 29564              "url": "https://zlib.net/",
 29565              "type": "distribution"
 29566            }
 29567          ],
 29568          "evidence": {},
 29569          "signature": {
 29570            "signature": {
 29571              "publicKey": {}
 29572            }
 29573          },
 29574          "modelCard": {
 29575            "modelParameters": {
 29576              "approach": {}
 29577            },
 29578            "quantitativeAnalysis": {
 29579              "graphics": {}
 29580            },
 29581            "considerations": {}
 29582          }
 29583        },
 29584        {
 29585          "type": "operating-system",
 29586          "supplier": {},
 29587          "name": "alpine",
 29588          "version": "3.17.3",
 29589          "description": "Alpine Linux v3.17",
 29590          "swid": {
 29591            "tagId": "alpine",
 29592            "name": "alpine",
 29593            "version": "3.17.3",
 29594            "attachment": {}
 29595          },
 29596          "pedigree": {},
 29597          "externalReferences": [
 29598            {
 29599              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
 29600              "type": "issue-tracker"
 29601            },
 29602            {
 29603              "url": "https://alpinelinux.org/",
 29604              "type": "website"
 29605            }
 29606          ],
 29607          "evidence": {},
 29608          "signature": {
 29609            "signature": {
 29610              "publicKey": {}
 29611            }
 29612          },
 29613          "modelCard": {
 29614            "modelParameters": {
 29615              "approach": {}
 29616            },
 29617            "quantitativeAnalysis": {
 29618              "graphics": {}
 29619            },
 29620            "considerations": {}
 29621          }
 29622        },
 29623        {
 29624          "type": "library",
 29625          "bom-ref": "pkg:maven/US_export_policy/US_export_policy?package-id=9fc12ca3a2e2eae4",
 29626          "supplier": {},
 29627          "name": "US_export_policy",
 29628          "cpe": "cpe:2.3:a:US-export-policy:US-export-policy:*:*:*:*:*:*:*:*",
 29629          "purl": "pkg:maven/US_export_policy/US_export_policy",
 29630          "swid": {
 29631            "attachment": {}
 29632          },
 29633          "pedigree": {},
 29634          "externalReferences": [
 29635            {
 29636              "type": "build-meta",
 29637              "hashes": [
 29638                {
 29639                  "alg": "SHA-1",
 29640                  "content": "2fcb002cf98fbafecb4fe01976ab172b71411654"
 29641                }
 29642              ]
 29643            }
 29644          ],
 29645          "evidence": {},
 29646          "signature": {
 29647            "signature": {
 29648              "publicKey": {}
 29649            }
 29650          },
 29651          "modelCard": {
 29652            "modelParameters": {
 29653              "approach": {}
 29654            },
 29655            "quantitativeAnalysis": {
 29656              "graphics": {}
 29657            },
 29658            "considerations": {}
 29659          }
 29660        },
 29661        {
 29662          "type": "library",
 29663          "bom-ref": "pkg:maven/US_export_policy/US_export_policy?package-id=502b2a55c42bdec0",
 29664          "supplier": {},
 29665          "name": "US_export_policy",
 29666          "cpe": "cpe:2.3:a:US-export-policy:US-export-policy:*:*:*:*:*:*:*:*",
 29667          "purl": "pkg:maven/US_export_policy/US_export_policy",
 29668          "swid": {
 29669            "attachment": {}
 29670          },
 29671          "pedigree": {},
 29672          "externalReferences": [
 29673            {
 29674              "type": "build-meta",
 29675              "hashes": [
 29676                {
 29677                  "alg": "SHA-1",
 29678                  "content": "2fcb002cf98fbafecb4fe01976ab172b71411654"
 29679                }
 29680              ]
 29681            }
 29682          ],
 29683          "evidence": {},
 29684          "signature": {
 29685            "signature": {
 29686              "publicKey": {}
 29687            }
 29688          },
 29689          "modelCard": {
 29690            "modelParameters": {
 29691              "approach": {}
 29692            },
 29693            "quantitativeAnalysis": {
 29694              "graphics": {}
 29695            },
 29696            "considerations": {}
 29697          }
 29698        },
 29699        {
 29700          "type": "library",
 29701          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=92b19c7750fb559d",
 29702          "supplier": {},
 29703          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 29704          "name": "alpine-baselayout",
 29705          "version": "3.4.0-r0",
 29706          "description": "Alpine base dir structure and init scripts",
 29707          "licenses": [
 29708            {
 29709              "license": {
 29710                "id": "GPL-2.0-only"
 29711              }
 29712            }
 29713          ],
 29714          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.4.0-r0:*:*:*:*:*:*:*",
 29715          "purl": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 29716          "swid": {
 29717            "attachment": {}
 29718          },
 29719          "pedigree": {},
 29720          "externalReferences": [
 29721            {
 29722              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 29723              "type": "distribution"
 29724            }
 29725          ],
 29726          "evidence": {},
 29727          "signature": {
 29728            "signature": {
 29729              "publicKey": {}
 29730            }
 29731          },
 29732          "modelCard": {
 29733            "modelParameters": {
 29734              "approach": {}
 29735            },
 29736            "quantitativeAnalysis": {
 29737              "graphics": {}
 29738            },
 29739            "considerations": {}
 29740          }
 29741        },
 29742        {
 29743          "type": "library",
 29744          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.3\u0026package-id=291d1267b40d636f",
 29745          "supplier": {},
 29746          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 29747          "name": "alpine-baselayout-data",
 29748          "version": "3.4.0-r0",
 29749          "description": "Alpine base dir structure and init scripts",
 29750          "licenses": [
 29751            {
 29752              "license": {
 29753                "id": "GPL-2.0-only"
 29754              }
 29755            }
 29756          ],
 29757          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.4.0-r0:*:*:*:*:*:*:*",
 29758          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.3",
 29759          "swid": {
 29760            "attachment": {}
 29761          },
 29762          "pedigree": {},
 29763          "externalReferences": [
 29764            {
 29765              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 29766              "type": "distribution"
 29767            }
 29768          ],
 29769          "evidence": {},
 29770          "signature": {
 29771            "signature": {
 29772              "publicKey": {}
 29773            }
 29774          },
 29775          "modelCard": {
 29776            "modelParameters": {
 29777              "approach": {}
 29778            },
 29779            "quantitativeAnalysis": {
 29780              "graphics": {}
 29781            },
 29782            "considerations": {}
 29783          }
 29784        },
 29785        {
 29786          "type": "library",
 29787          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2b5e23d349b556cf",
 29788          "supplier": {},
 29789          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 29790          "name": "alpine-keys",
 29791          "version": "2.4-r1",
 29792          "description": "Public keys for Alpine Linux packages",
 29793          "licenses": [
 29794            {
 29795              "license": {
 29796                "id": "MIT"
 29797              }
 29798            }
 29799          ],
 29800          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
 29801          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 29802          "swid": {
 29803            "attachment": {}
 29804          },
 29805          "pedigree": {},
 29806          "externalReferences": [
 29807            {
 29808              "url": "https://alpinelinux.org",
 29809              "type": "distribution"
 29810            }
 29811          ],
 29812          "evidence": {},
 29813          "signature": {
 29814            "signature": {
 29815              "publicKey": {}
 29816            }
 29817          },
 29818          "modelCard": {
 29819            "modelParameters": {
 29820              "approach": {}
 29821            },
 29822            "quantitativeAnalysis": {
 29823              "graphics": {}
 29824            },
 29825            "considerations": {}
 29826          }
 29827        },
 29828        {
 29829          "type": "library",
 29830          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=e5f757b0df1f62bc",
 29831          "supplier": {},
 29832          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 29833          "name": "apk-tools",
 29834          "version": "2.12.10-r1",
 29835          "description": "Alpine Package Keeper - package manager for alpine",
 29836          "licenses": [
 29837            {
 29838              "license": {
 29839                "id": "GPL-2.0-only"
 29840              }
 29841            }
 29842          ],
 29843          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.10-r1:*:*:*:*:*:*:*",
 29844          "purl": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 29845          "swid": {
 29846            "attachment": {}
 29847          },
 29848          "pedigree": {},
 29849          "externalReferences": [
 29850            {
 29851              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
 29852              "type": "distribution"
 29853            }
 29854          ],
 29855          "evidence": {},
 29856          "signature": {
 29857            "signature": {
 29858              "publicKey": {}
 29859            }
 29860          },
 29861          "modelCard": {
 29862            "modelParameters": {
 29863              "approach": {}
 29864            },
 29865            "quantitativeAnalysis": {
 29866              "graphics": {}
 29867            },
 29868            "considerations": {}
 29869          }
 29870        },
 29871        {
 29872          "type": "library",
 29873          "bom-ref": "pkg:maven/org.bouncycastle.bcprovider/bcprov-jdk15@1.44?package-id=eeb8b0e5db5f7962",
 29874          "supplier": {},
 29875          "name": "bcprov-jdk15",
 29876          "version": "1.44",
 29877          "cpe": "cpe:2.3:a:bouncycastle-org:bcprov-jdk15:1.44:*:*:*:*:*:*:*",
 29878          "purl": "pkg:maven/org.bouncycastle.bcprovider/bcprov-jdk15@1.44",
 29879          "swid": {
 29880            "attachment": {}
 29881          },
 29882          "pedigree": {},
 29883          "externalReferences": [
 29884            {
 29885              "type": "build-meta",
 29886              "hashes": [
 29887                {
 29888                  "alg": "SHA-1",
 29889                  "content": "63102221970b8471b1dd2a5bfe36fd2ab1f5c516"
 29890                }
 29891              ]
 29892            }
 29893          ],
 29894          "evidence": {},
 29895          "signature": {
 29896            "signature": {
 29897              "publicKey": {}
 29898            }
 29899          },
 29900          "modelCard": {
 29901            "modelParameters": {
 29902              "approach": {}
 29903            },
 29904            "quantitativeAnalysis": {
 29905              "graphics": {}
 29906            },
 29907            "considerations": {}
 29908          }
 29909        },
 29910        {
 29911          "type": "library",
 29912          "bom-ref": "pkg:apk/alpine/brotli-libs@1.0.9-r9?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.17.3\u0026package-id=b908173dd9145006",
 29913          "supplier": {},
 29914          "publisher": "prspkt \u003cprspkt@protonmail.com\u003e",
 29915          "name": "brotli-libs",
 29916          "version": "1.0.9-r9",
 29917          "description": "Generic lossless compressor (libraries)",
 29918          "licenses": [
 29919            {
 29920              "license": {
 29921                "id": "MIT"
 29922              }
 29923            }
 29924          ],
 29925          "cpe": "cpe:2.3:a:brotli-libs:brotli-libs:1.0.9-r9:*:*:*:*:*:*:*",
 29926          "purl": "pkg:apk/alpine/brotli-libs@1.0.9-r9?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.17.3",
 29927          "swid": {
 29928            "attachment": {}
 29929          },
 29930          "pedigree": {},
 29931          "externalReferences": [
 29932            {
 29933              "url": "https://github.com/google/brotli",
 29934              "type": "distribution"
 29935            }
 29936          ],
 29937          "evidence": {},
 29938          "signature": {
 29939            "signature": {
 29940              "publicKey": {}
 29941            }
 29942          },
 29943          "modelCard": {
 29944            "modelParameters": {
 29945              "approach": {}
 29946            },
 29947            "quantitativeAnalysis": {
 29948              "graphics": {}
 29949            },
 29950            "considerations": {}
 29951          }
 29952        },
 29953        {
 29954          "type": "application",
 29955          "bom-ref": "e6c9486419cbb84e",
 29956          "supplier": {},
 29957          "name": "busybox",
 29958          "version": "1.35.0",
 29959          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
 29960          "swid": {
 29961            "attachment": {}
 29962          },
 29963          "pedigree": {},
 29964          "evidence": {},
 29965          "signature": {
 29966            "signature": {
 29967              "publicKey": {}
 29968            }
 29969          },
 29970          "modelCard": {
 29971            "modelParameters": {
 29972              "approach": {}
 29973            },
 29974            "quantitativeAnalysis": {
 29975              "graphics": {}
 29976            },
 29977            "considerations": {}
 29978          }
 29979        },
 29980        {
 29981          "type": "library",
 29982          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=623d53216342d45e",
 29983          "supplier": {},
 29984          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 29985          "name": "busybox",
 29986          "version": "1.35.0-r29",
 29987          "description": "Size optimized toolbox of many common UNIX utilities",
 29988          "licenses": [
 29989            {
 29990              "license": {
 29991                "id": "GPL-2.0-only"
 29992              }
 29993            }
 29994          ],
 29995          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r29:*:*:*:*:*:*:*",
 29996          "purl": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.3",
 29997          "swid": {
 29998            "attachment": {}
 29999          },
 30000          "pedigree": {},
 30001          "externalReferences": [
 30002            {
 30003              "url": "https://busybox.net/",
 30004              "type": "distribution"
 30005            }
 30006          ],
 30007          "evidence": {},
 30008          "signature": {
 30009            "signature": {
 30010              "publicKey": {}
 30011            }
 30012          },
 30013          "modelCard": {
 30014            "modelParameters": {
 30015              "approach": {}
 30016            },
 30017            "quantitativeAnalysis": {
 30018              "graphics": {}
 30019            },
 30020            "considerations": {}
 30021          }
 30022        },
 30023        {
 30024          "type": "library",
 30025          "bom-ref": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3\u0026package-id=256fc96b4a8c4da8",
 30026          "supplier": {},
 30027          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 30028          "name": "busybox-binsh",
 30029          "version": "1.35.0-r29",
 30030          "description": "busybox ash /bin/sh",
 30031          "licenses": [
 30032            {
 30033              "license": {
 30034                "id": "GPL-2.0-only"
 30035              }
 30036            }
 30037          ],
 30038          "cpe": "cpe:2.3:a:busybox-binsh:busybox-binsh:1.35.0-r29:*:*:*:*:*:*:*",
 30039          "purl": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3",
 30040          "swid": {
 30041            "attachment": {}
 30042          },
 30043          "pedigree": {},
 30044          "externalReferences": [
 30045            {
 30046              "url": "https://busybox.net/",
 30047              "type": "distribution"
 30048            }
 30049          ],
 30050          "evidence": {},
 30051          "signature": {
 30052            "signature": {
 30053              "publicKey": {}
 30054            }
 30055          },
 30056          "modelCard": {
 30057            "modelParameters": {
 30058              "approach": {}
 30059            },
 30060            "quantitativeAnalysis": {
 30061              "graphics": {}
 30062            },
 30063            "considerations": {}
 30064          }
 30065        },
 30066        {
 30067          "type": "library",
 30068          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.3\u0026package-id=b805d823ae624f04",
 30069          "supplier": {},
 30070          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 30071          "name": "ca-certificates-bundle",
 30072          "version": "20220614-r4",
 30073          "description": "Pre generated bundle of Mozilla certificates",
 30074          "licenses": [
 30075            {
 30076              "license": {
 30077                "id": "MPL-2.0"
 30078              }
 30079            },
 30080            {
 30081              "license": {
 30082                "name": "AND"
 30083              }
 30084            },
 30085            {
 30086              "license": {
 30087                "id": "MIT"
 30088              }
 30089            }
 30090          ],
 30091          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r4:*:*:*:*:*:*:*",
 30092          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.3",
 30093          "swid": {
 30094            "attachment": {}
 30095          },
 30096          "pedigree": {},
 30097          "externalReferences": [
 30098            {
 30099              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
 30100              "type": "distribution"
 30101            }
 30102          ],
 30103          "evidence": {},
 30104          "signature": {
 30105            "signature": {
 30106              "publicKey": {}
 30107            }
 30108          },
 30109          "modelCard": {
 30110            "modelParameters": {
 30111              "approach": {}
 30112            },
 30113            "quantitativeAnalysis": {
 30114              "graphics": {}
 30115            },
 30116            "considerations": {}
 30117          }
 30118        },
 30119        {
 30120          "type": "library",
 30121          "bom-ref": "pkg:maven/charsets/charsets?package-id=ac260baeda2f6c16",
 30122          "supplier": {},
 30123          "name": "charsets",
 30124          "cpe": "cpe:2.3:a:charsets:charsets:*:*:*:*:*:*:*:*",
 30125          "purl": "pkg:maven/charsets/charsets",
 30126          "swid": {
 30127            "attachment": {}
 30128          },
 30129          "pedigree": {},
 30130          "externalReferences": [
 30131            {
 30132              "type": "build-meta",
 30133              "hashes": [
 30134                {
 30135                  "alg": "SHA-1",
 30136                  "content": "141875c9bf4e34ae776a45505fc5365a5a1c8180"
 30137                }
 30138              ]
 30139            }
 30140          ],
 30141          "evidence": {},
 30142          "signature": {
 30143            "signature": {
 30144              "publicKey": {}
 30145            }
 30146          },
 30147          "modelCard": {
 30148            "modelParameters": {
 30149              "approach": {}
 30150            },
 30151            "quantitativeAnalysis": {
 30152              "graphics": {}
 30153            },
 30154            "considerations": {}
 30155          }
 30156        },
 30157        {
 30158          "type": "library",
 30159          "bom-ref": "pkg:maven/cldrdata/cldrdata?package-id=aaa36a6b8966b603",
 30160          "supplier": {},
 30161          "name": "cldrdata",
 30162          "cpe": "cpe:2.3:a:cldrdata:cldrdata:*:*:*:*:*:*:*:*",
 30163          "purl": "pkg:maven/cldrdata/cldrdata",
 30164          "swid": {
 30165            "attachment": {}
 30166          },
 30167          "pedigree": {},
 30168          "externalReferences": [
 30169            {
 30170              "type": "build-meta",
 30171              "hashes": [
 30172                {
 30173                  "alg": "SHA-1",
 30174                  "content": "040ba7365dc9db7c7b9a0fd786c6f180e61f62e3"
 30175                }
 30176              ]
 30177            }
 30178          ],
 30179          "evidence": {},
 30180          "signature": {
 30181            "signature": {
 30182              "publicKey": {}
 30183            }
 30184          },
 30185          "modelCard": {
 30186            "modelParameters": {
 30187              "approach": {}
 30188            },
 30189            "quantitativeAnalysis": {
 30190              "graphics": {}
 30191            },
 30192            "considerations": {}
 30193          }
 30194        },
 30195        {
 30196          "type": "library",
 30197          "bom-ref": "pkg:maven/commons-pool/commons-pool@1.6?package-id=5d1dcd6c610f5879",
 30198          "supplier": {},
 30199          "group": "commons-pool",
 30200          "name": "commons-pool",
 30201          "version": "1.6",
 30202          "licenses": [
 30203            {
 30204              "license": {
 30205                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 30206              }
 30207            }
 30208          ],
 30209          "cpe": "cpe:2.3:a:apache:commons-pool:1.6:*:*:*:*:*:*:*",
 30210          "purl": "pkg:maven/commons-pool/commons-pool@1.6",
 30211          "swid": {
 30212            "attachment": {}
 30213          },
 30214          "pedigree": {},
 30215          "externalReferences": [
 30216            {
 30217              "type": "build-meta",
 30218              "hashes": [
 30219                {
 30220                  "alg": "SHA-1",
 30221                  "content": "4572d589699f09d866a226a14b7f4323c6d8f040"
 30222                }
 30223              ]
 30224            }
 30225          ],
 30226          "evidence": {},
 30227          "signature": {
 30228            "signature": {
 30229              "publicKey": {}
 30230            }
 30231          },
 30232          "modelCard": {
 30233            "modelParameters": {
 30234              "approach": {}
 30235            },
 30236            "quantitativeAnalysis": {
 30237              "graphics": {}
 30238            },
 30239            "considerations": {}
 30240          }
 30241        },
 30242        {
 30243          "type": "library",
 30244          "bom-ref": "pkg:maven/dnsns/dnsns?package-id=af09d0f9bd2e5151",
 30245          "supplier": {},
 30246          "name": "dnsns",
 30247          "cpe": "cpe:2.3:a:dnsns:dnsns:*:*:*:*:*:*:*:*",
 30248          "purl": "pkg:maven/dnsns/dnsns",
 30249          "swid": {
 30250            "attachment": {}
 30251          },
 30252          "pedigree": {},
 30253          "externalReferences": [
 30254            {
 30255              "type": "build-meta",
 30256              "hashes": [
 30257                {
 30258                  "alg": "SHA-1",
 30259                  "content": "3c80b6ce7bfb62d34251421d73d7afb67f06b1e8"
 30260                }
 30261              ]
 30262            }
 30263          ],
 30264          "evidence": {},
 30265          "signature": {
 30266            "signature": {
 30267              "publicKey": {}
 30268            }
 30269          },
 30270          "modelCard": {
 30271            "modelParameters": {
 30272              "approach": {}
 30273            },
 30274            "quantitativeAnalysis": {
 30275              "graphics": {}
 30276            },
 30277            "considerations": {}
 30278          }
 30279        },
 30280        {
 30281          "type": "library",
 30282          "bom-ref": "pkg:apk/alpine/encodings@1.0.6-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=27e4d13f9a311e67",
 30283          "supplier": {},
 30284          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 30285          "name": "encodings",
 30286          "version": "1.0.6-r0",
 30287          "description": "X.org font encoding files",
 30288          "licenses": [
 30289            {
 30290              "license": {
 30291                "name": "custom"
 30292              }
 30293            }
 30294          ],
 30295          "cpe": "cpe:2.3:a:encodings:encodings:1.0.6-r0:*:*:*:*:*:*:*",
 30296          "purl": "pkg:apk/alpine/encodings@1.0.6-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 30297          "swid": {
 30298            "attachment": {}
 30299          },
 30300          "pedigree": {},
 30301          "externalReferences": [
 30302            {
 30303              "url": "http://xorg.freedesktop.org/",
 30304              "type": "distribution"
 30305            }
 30306          ],
 30307          "evidence": {},
 30308          "signature": {
 30309            "signature": {
 30310              "publicKey": {}
 30311            }
 30312          },
 30313          "modelCard": {
 30314            "modelParameters": {
 30315              "approach": {}
 30316            },
 30317            "quantitativeAnalysis": {
 30318              "graphics": {}
 30319            },
 30320            "considerations": {}
 30321          }
 30322        },
 30323        {
 30324          "type": "library",
 30325          "bom-ref": "pkg:apk/alpine/font-dejavu@2.37-r3?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=dcec74118c4e82d9",
 30326          "supplier": {},
 30327          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 30328          "name": "font-dejavu",
 30329          "version": "2.37-r3",
 30330          "description": "Font family based on the Bitstream Vera Fonts with a wider range of characters",
 30331          "licenses": [
 30332            {
 30333              "license": {
 30334                "name": "custom"
 30335              }
 30336            }
 30337          ],
 30338          "cpe": "cpe:2.3:a:font-dejavu:font-dejavu:2.37-r3:*:*:*:*:*:*:*",
 30339          "purl": "pkg:apk/alpine/font-dejavu@2.37-r3?arch=x86_64\u0026distro=alpine-3.17.3",
 30340          "swid": {
 30341            "attachment": {}
 30342          },
 30343          "pedigree": {},
 30344          "externalReferences": [
 30345            {
 30346              "url": "https://dejavu-fonts.github.io/",
 30347              "type": "distribution"
 30348            }
 30349          ],
 30350          "evidence": {},
 30351          "signature": {
 30352            "signature": {
 30353              "publicKey": {}
 30354            }
 30355          },
 30356          "modelCard": {
 30357            "modelParameters": {
 30358              "approach": {}
 30359            },
 30360            "quantitativeAnalysis": {
 30361              "graphics": {}
 30362            },
 30363            "considerations": {}
 30364          }
 30365        },
 30366        {
 30367          "type": "library",
 30368          "bom-ref": "pkg:apk/alpine/fontconfig@2.14.1-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=adae4094ba998368",
 30369          "supplier": {},
 30370          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 30371          "name": "fontconfig",
 30372          "version": "2.14.1-r0",
 30373          "description": "Library for configuring and customizing font access",
 30374          "licenses": [
 30375            {
 30376              "license": {
 30377                "id": "MIT"
 30378              }
 30379            }
 30380          ],
 30381          "cpe": "cpe:2.3:a:fontconfig:fontconfig:2.14.1-r0:*:*:*:*:*:*:*",
 30382          "purl": "pkg:apk/alpine/fontconfig@2.14.1-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 30383          "swid": {
 30384            "attachment": {}
 30385          },
 30386          "pedigree": {},
 30387          "externalReferences": [
 30388            {
 30389              "url": "https://www.freedesktop.org/wiki/Software/fontconfig",
 30390              "type": "distribution"
 30391            }
 30392          ],
 30393          "evidence": {},
 30394          "signature": {
 30395            "signature": {
 30396              "publicKey": {}
 30397            }
 30398          },
 30399          "modelCard": {
 30400            "modelParameters": {
 30401              "approach": {}
 30402            },
 30403            "quantitativeAnalysis": {
 30404              "graphics": {}
 30405            },
 30406            "considerations": {}
 30407          }
 30408        },
 30409        {
 30410          "type": "library",
 30411          "bom-ref": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2b1bfc10343b9080",
 30412          "supplier": {},
 30413          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 30414          "name": "freetype",
 30415          "version": "2.12.1-r0",
 30416          "description": "TrueType font rendering library",
 30417          "licenses": [
 30418            {
 30419              "license": {
 30420                "id": "FTL"
 30421              }
 30422            },
 30423            {
 30424              "license": {
 30425                "id": "GPL-2.0-or-later"
 30426              }
 30427            }
 30428          ],
 30429          "cpe": "cpe:2.3:a:freetype:freetype:2.12.1-r0:*:*:*:*:*:*:*",
 30430          "purl": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 30431          "swid": {
 30432            "attachment": {}
 30433          },
 30434          "pedigree": {},
 30435          "externalReferences": [
 30436            {
 30437              "url": "https://www.freetype.org/",
 30438              "type": "distribution"
 30439            }
 30440          ],
 30441          "evidence": {},
 30442          "signature": {
 30443            "signature": {
 30444              "publicKey": {}
 30445            }
 30446          },
 30447          "modelCard": {
 30448            "modelParameters": {
 30449              "approach": {}
 30450            },
 30451            "quantitativeAnalysis": {
 30452              "graphics": {}
 30453            },
 30454            "considerations": {}
 30455          }
 30456        },
 30457        {
 30458          "type": "library",
 30459          "bom-ref": "pkg:maven/jaccess/jaccess?package-id=597e861ae7234b49",
 30460          "supplier": {},
 30461          "name": "jaccess",
 30462          "cpe": "cpe:2.3:a:jaccess:jaccess:*:*:*:*:*:*:*:*",
 30463          "purl": "pkg:maven/jaccess/jaccess",
 30464          "swid": {
 30465            "attachment": {}
 30466          },
 30467          "pedigree": {},
 30468          "externalReferences": [
 30469            {
 30470              "type": "build-meta",
 30471              "hashes": [
 30472                {
 30473                  "alg": "SHA-1",
 30474                  "content": "4cf0b06ec3ab96c68d48a3b56a6a2b9a939b4a69"
 30475                }
 30476              ]
 30477            }
 30478          ],
 30479          "evidence": {},
 30480          "signature": {
 30481            "signature": {
 30482              "publicKey": {}
 30483            }
 30484          },
 30485          "modelCard": {
 30486            "modelParameters": {
 30487              "approach": {}
 30488            },
 30489            "quantitativeAnalysis": {
 30490              "graphics": {}
 30491            },
 30492            "considerations": {}
 30493          }
 30494        },
 30495        {
 30496          "type": "library",
 30497          "bom-ref": "pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.11.2?package-id=6f877f8793640384",
 30498          "supplier": {},
 30499          "group": "com.fasterxml.jackson.core",
 30500          "name": "jackson-annotations",
 30501          "version": "2.11.2",
 30502          "licenses": [
 30503            {
 30504              "license": {
 30505                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 30506              }
 30507            }
 30508          ],
 30509          "cpe": "cpe:2.3:a:jackson-annotations:jackson-annotations:2.11.2:*:*:*:*:*:*:*",
 30510          "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.11.2",
 30511          "swid": {
 30512            "attachment": {}
 30513          },
 30514          "pedigree": {},
 30515          "externalReferences": [
 30516            {
 30517              "type": "build-meta",
 30518              "hashes": [
 30519                {
 30520                  "alg": "SHA-1",
 30521                  "content": "0e0a7f61fce3e3eac38a079c11831868269de2ea"
 30522                }
 30523              ]
 30524            }
 30525          ],
 30526          "evidence": {},
 30527          "signature": {
 30528            "signature": {
 30529              "publicKey": {}
 30530            }
 30531          },
 30532          "modelCard": {
 30533            "modelParameters": {
 30534              "approach": {}
 30535            },
 30536            "quantitativeAnalysis": {
 30537              "graphics": {}
 30538            },
 30539            "considerations": {}
 30540          }
 30541        },
 30542        {
 30543          "type": "library",
 30544          "bom-ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.11.2?package-id=c4caf18ffa4b9fb1",
 30545          "supplier": {},
 30546          "group": "com.fasterxml.jackson.core",
 30547          "name": "jackson-core",
 30548          "version": "2.11.2",
 30549          "licenses": [
 30550            {
 30551              "license": {
 30552                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 30553              }
 30554            }
 30555          ],
 30556          "cpe": "cpe:2.3:a:jackson-core:jackson-core:2.11.2:*:*:*:*:*:*:*",
 30557          "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.11.2",
 30558          "swid": {
 30559            "attachment": {}
 30560          },
 30561          "pedigree": {},
 30562          "externalReferences": [
 30563            {
 30564              "type": "build-meta",
 30565              "hashes": [
 30566                {
 30567                  "alg": "SHA-1",
 30568                  "content": "bc022ab0f0c83c07f9c52c5ab9a6a4932b15cc35"
 30569                }
 30570              ]
 30571            }
 30572          ],
 30573          "evidence": {},
 30574          "signature": {
 30575            "signature": {
 30576              "publicKey": {}
 30577            }
 30578          },
 30579          "modelCard": {
 30580            "modelParameters": {
 30581              "approach": {}
 30582            },
 30583            "quantitativeAnalysis": {
 30584              "graphics": {}
 30585            },
 30586            "considerations": {}
 30587          }
 30588        },
 30589        {
 30590          "type": "library",
 30591          "bom-ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.2?package-id=58bfe200ca0eafb4",
 30592          "supplier": {},
 30593          "group": "com.fasterxml.jackson.core",
 30594          "name": "jackson-databind",
 30595          "version": "2.11.2",
 30596          "licenses": [
 30597            {
 30598              "license": {
 30599                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 30600              }
 30601            }
 30602          ],
 30603          "cpe": "cpe:2.3:a:jackson-databind:jackson-databind:2.11.2:*:*:*:*:*:*:*",
 30604          "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.2",
 30605          "swid": {
 30606            "attachment": {}
 30607          },
 30608          "pedigree": {},
 30609          "externalReferences": [
 30610            {
 30611              "type": "build-meta",
 30612              "hashes": [
 30613                {
 30614                  "alg": "SHA-1",
 30615                  "content": "ee08bbd8975dde844307fe8309dfcd5ec7ee129d"
 30616                }
 30617              ]
 30618            }
 30619          ],
 30620          "evidence": {},
 30621          "signature": {
 30622            "signature": {
 30623              "publicKey": {}
 30624            }
 30625          },
 30626          "modelCard": {
 30627            "modelParameters": {
 30628              "approach": {}
 30629            },
 30630            "quantitativeAnalysis": {
 30631              "graphics": {}
 30632            },
 30633            "considerations": {}
 30634          }
 30635        },
 30636        {
 30637          "type": "library",
 30638          "bom-ref": "pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.11.2?package-id=16ab1e33c5947f5b",
 30639          "supplier": {},
 30640          "group": "com.fasterxml.jackson.datatype",
 30641          "name": "jackson-datatype-jdk8",
 30642          "version": "2.11.2",
 30643          "licenses": [
 30644            {
 30645              "license": {
 30646                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 30647              }
 30648            }
 30649          ],
 30650          "cpe": "cpe:2.3:a:jackson-datatype-jdk8:jackson-datatype-jdk8:2.11.2:*:*:*:*:*:*:*",
 30651          "purl": "pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.11.2",
 30652          "swid": {
 30653            "attachment": {}
 30654          },
 30655          "pedigree": {},
 30656          "externalReferences": [
 30657            {
 30658              "type": "build-meta",
 30659              "hashes": [
 30660                {
 30661                  "alg": "SHA-1",
 30662                  "content": "d4c1933a8d62db65c3d5a5cd809511e021a189c0"
 30663                }
 30664              ]
 30665            }
 30666          ],
 30667          "evidence": {},
 30668          "signature": {
 30669            "signature": {
 30670              "publicKey": {}
 30671            }
 30672          },
 30673          "modelCard": {
 30674            "modelParameters": {
 30675              "approach": {}
 30676            },
 30677            "quantitativeAnalysis": {
 30678              "graphics": {}
 30679            },
 30680            "considerations": {}
 30681          }
 30682        },
 30683        {
 30684          "type": "library",
 30685          "bom-ref": "pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.11.2?package-id=2513f03e8793414e",
 30686          "supplier": {},
 30687          "group": "com.fasterxml.jackson.datatype",
 30688          "name": "jackson-datatype-jsr310",
 30689          "version": "2.11.2",
 30690          "licenses": [
 30691            {
 30692              "license": {
 30693                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 30694              }
 30695            }
 30696          ],
 30697          "cpe": "cpe:2.3:a:jackson-datatype-jsr310:jackson-datatype-jsr310:2.11.2:*:*:*:*:*:*:*",
 30698          "purl": "pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.11.2",
 30699          "swid": {
 30700            "attachment": {}
 30701          },
 30702          "pedigree": {},
 30703          "externalReferences": [
 30704            {
 30705              "type": "build-meta",
 30706              "hashes": [
 30707                {
 30708                  "alg": "SHA-1",
 30709                  "content": "e6235e5eb3cf3edd2a95cd0dc96bc48aeb309e8a"
 30710                }
 30711              ]
 30712            }
 30713          ],
 30714          "evidence": {},
 30715          "signature": {
 30716            "signature": {
 30717              "publicKey": {}
 30718            }
 30719          },
 30720          "modelCard": {
 30721            "modelParameters": {
 30722              "approach": {}
 30723            },
 30724            "quantitativeAnalysis": {
 30725              "graphics": {}
 30726            },
 30727            "considerations": {}
 30728          }
 30729        },
 30730        {
 30731          "type": "library",
 30732          "bom-ref": "pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.11.2?package-id=6ac3f07c180fc10f",
 30733          "supplier": {},
 30734          "group": "com.fasterxml.jackson.module",
 30735          "name": "jackson-module-parameter-names",
 30736          "version": "2.11.2",
 30737          "licenses": [
 30738            {
 30739              "license": {
 30740                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 30741              }
 30742            }
 30743          ],
 30744          "cpe": "cpe:2.3:a:jackson-module-parameter-names:jackson-module-parameter-names:2.11.2:*:*:*:*:*:*:*",
 30745          "purl": "pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.11.2",
 30746          "swid": {
 30747            "attachment": {}
 30748          },
 30749          "pedigree": {},
 30750          "externalReferences": [
 30751            {
 30752              "type": "build-meta",
 30753              "hashes": [
 30754                {
 30755                  "alg": "SHA-1",
 30756                  "content": "c0dc526fcef5a3aae0273fc516ecf3505f7a5de8"
 30757                }
 30758              ]
 30759            }
 30760          ],
 30761          "evidence": {},
 30762          "signature": {
 30763            "signature": {
 30764              "publicKey": {}
 30765            }
 30766          },
 30767          "modelCard": {
 30768            "modelParameters": {
 30769              "approach": {}
 30770            },
 30771            "quantitativeAnalysis": {
 30772              "graphics": {}
 30773            },
 30774            "considerations": {}
 30775          }
 30776        },
 30777        {
 30778          "type": "library",
 30779          "bom-ref": "pkg:maven/org.glassfish/jakarta.annotation-api@1.3.5?package-id=3ea11842f320080e",
 30780          "supplier": {},
 30781          "group": "jakarta.annotation",
 30782          "name": "jakarta.annotation-api",
 30783          "version": "1.3.5",
 30784          "licenses": [
 30785            {
 30786              "license": {
 30787                "name": "http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html"
 30788              }
 30789            }
 30790          ],
 30791          "cpe": "cpe:2.3:a:jakarta.annotation-api:jakarta.annotation-api:1.3.5:*:*:*:*:*:*:*",
 30792          "purl": "pkg:maven/org.glassfish/jakarta.annotation-api@1.3.5",
 30793          "swid": {
 30794            "attachment": {}
 30795          },
 30796          "pedigree": {},
 30797          "externalReferences": [
 30798            {
 30799              "type": "build-meta",
 30800              "hashes": [
 30801                {
 30802                  "alg": "SHA-1",
 30803                  "content": "59eb84ee0d616332ff44aba065f3888cf002cd2d"
 30804                }
 30805              ]
 30806            }
 30807          ],
 30808          "evidence": {},
 30809          "signature": {
 30810            "signature": {
 30811              "publicKey": {}
 30812            }
 30813          },
 30814          "modelCard": {
 30815            "modelParameters": {
 30816              "approach": {}
 30817            },
 30818            "quantitativeAnalysis": {
 30819              "graphics": {}
 30820            },
 30821            "considerations": {}
 30822          }
 30823        },
 30824        {
 30825          "type": "library",
 30826          "bom-ref": "pkg:maven/org.glassfish/jakarta.el@3.0.3?package-id=aef265b67043e79d",
 30827          "supplier": {},
 30828          "group": "org.glassfish",
 30829          "name": "jakarta.el",
 30830          "version": "3.0.3",
 30831          "licenses": [
 30832            {
 30833              "license": {
 30834                "name": "http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html"
 30835              }
 30836            }
 30837          ],
 30838          "cpe": "cpe:2.3:a:oracle-corporation:jakarta.el:3.0.3:*:*:*:*:*:*:*",
 30839          "purl": "pkg:maven/org.glassfish/jakarta.el@3.0.3",
 30840          "swid": {
 30841            "attachment": {}
 30842          },
 30843          "pedigree": {},
 30844          "externalReferences": [
 30845            {
 30846              "type": "build-meta",
 30847              "hashes": [
 30848                {
 30849                  "alg": "SHA-1",
 30850                  "content": "dab46ee1ee23f7197c13d7c40fce14817c9017df"
 30851                }
 30852              ]
 30853            }
 30854          ],
 30855          "evidence": {},
 30856          "signature": {
 30857            "signature": {
 30858              "publicKey": {}
 30859            }
 30860          },
 30861          "modelCard": {
 30862            "modelParameters": {
 30863              "approach": {}
 30864            },
 30865            "quantitativeAnalysis": {
 30866              "graphics": {}
 30867            },
 30868            "considerations": {}
 30869          }
 30870        },
 30871        {
 30872          "type": "application",
 30873          "bom-ref": "pkg:generic/java@1.8.0_362-b09?package-id=df80297034b58157",
 30874          "supplier": {},
 30875          "name": "java",
 30876          "version": "1.8.0_362-b09",
 30877          "cpe": "cpe:2.3:a:oracle:openjdk:1.8.0_362-b09:*:*:*:*:*:*:*",
 30878          "purl": "pkg:generic/java@1.8.0_362-b09",
 30879          "swid": {
 30880            "attachment": {}
 30881          },
 30882          "pedigree": {},
 30883          "evidence": {},
 30884          "signature": {
 30885            "signature": {
 30886              "publicKey": {}
 30887            }
 30888          },
 30889          "modelCard": {
 30890            "modelParameters": {
 30891              "approach": {}
 30892            },
 30893            "quantitativeAnalysis": {
 30894              "graphics": {}
 30895            },
 30896            "considerations": {}
 30897          }
 30898        },
 30899        {
 30900          "type": "library",
 30901          "bom-ref": "pkg:maven/com.sun/jce@1.8.0_362?package-id=a8c489b1d53d3920",
 30902          "supplier": {},
 30903          "name": "jce",
 30904          "version": "1.8.0_362",
 30905          "cpe": "cpe:2.3:a:oracle-corporation:jce:1.8.0_362:*:*:*:*:*:*:*",
 30906          "purl": "pkg:maven/com.sun/jce@1.8.0_362",
 30907          "swid": {
 30908            "attachment": {}
 30909          },
 30910          "pedigree": {},
 30911          "externalReferences": [
 30912            {
 30913              "type": "build-meta",
 30914              "hashes": [
 30915                {
 30916                  "alg": "SHA-1",
 30917                  "content": "ea30f8fc11602d5de2fc30432e5c489364bb7d2e"
 30918                }
 30919              ]
 30920            }
 30921          ],
 30922          "evidence": {},
 30923          "signature": {
 30924            "signature": {
 30925              "publicKey": {}
 30926            }
 30927          },
 30928          "modelCard": {
 30929            "modelParameters": {
 30930              "approach": {}
 30931            },
 30932            "quantitativeAnalysis": {
 30933              "graphics": {}
 30934            },
 30935            "considerations": {}
 30936          }
 30937        },
 30938        {
 30939          "type": "library",
 30940          "bom-ref": "pkg:maven/jfr/jfr@1.8.0_362?package-id=a79464b21bb17e9e",
 30941          "supplier": {},
 30942          "name": "jfr",
 30943          "version": "1.8.0_362",
 30944          "cpe": "cpe:2.3:a:oracle-corporation:jfr:1.8.0_362:*:*:*:*:*:*:*",
 30945          "purl": "pkg:maven/jfr/jfr@1.8.0_362",
 30946          "swid": {
 30947            "attachment": {}
 30948          },
 30949          "pedigree": {},
 30950          "externalReferences": [
 30951            {
 30952              "type": "build-meta",
 30953              "hashes": [
 30954                {
 30955                  "alg": "SHA-1",
 30956                  "content": "88dbd83bf6b99249cb4a27d94cd9db30eed845d5"
 30957                }
 30958              ]
 30959            }
 30960          ],
 30961          "evidence": {},
 30962          "signature": {
 30963            "signature": {
 30964              "publicKey": {}
 30965            }
 30966          },
 30967          "modelCard": {
 30968            "modelParameters": {
 30969              "approach": {}
 30970            },
 30971            "quantitativeAnalysis": {
 30972              "graphics": {}
 30973            },
 30974            "considerations": {}
 30975          }
 30976        },
 30977        {
 30978          "type": "library",
 30979          "bom-ref": "pkg:maven/net.jradius/jradius-client@1.1.5?package-id=4f95c6858e195dd3",
 30980          "supplier": {},
 30981          "group": "net.jradius",
 30982          "name": "jradius-client",
 30983          "version": "1.1.5",
 30984          "cpe": "cpe:2.3:a:jradius-client:jradius-client:1.1.5:*:*:*:*:*:*:*",
 30985          "purl": "pkg:maven/net.jradius/jradius-client@1.1.5",
 30986          "swid": {
 30987            "attachment": {}
 30988          },
 30989          "pedigree": {},
 30990          "externalReferences": [
 30991            {
 30992              "type": "build-meta",
 30993              "hashes": [
 30994                {
 30995                  "alg": "SHA-1",
 30996                  "content": "ea5857b29a4447ee6b19e2123b3f83d1a3d23ce2"
 30997                }
 30998              ]
 30999            }
 31000          ],
 31001          "evidence": {},
 31002          "signature": {
 31003            "signature": {
 31004              "publicKey": {}
 31005            }
 31006          },
 31007          "modelCard": {
 31008            "modelParameters": {
 31009              "approach": {}
 31010            },
 31011            "quantitativeAnalysis": {
 31012              "graphics": {}
 31013            },
 31014            "considerations": {}
 31015          }
 31016        },
 31017        {
 31018          "type": "library",
 31019          "bom-ref": "pkg:maven/net.jradius/jradius-core@1.1.5?package-id=16464a48ad9734d0",
 31020          "supplier": {},
 31021          "group": "net.jradius",
 31022          "name": "jradius-core",
 31023          "version": "1.1.5",
 31024          "cpe": "cpe:2.3:a:jradius-core:jradius-core:1.1.5:*:*:*:*:*:*:*",
 31025          "purl": "pkg:maven/net.jradius/jradius-core@1.1.5",
 31026          "swid": {
 31027            "attachment": {}
 31028          },
 31029          "pedigree": {},
 31030          "externalReferences": [
 31031            {
 31032              "type": "build-meta",
 31033              "hashes": [
 31034                {
 31035                  "alg": "SHA-1",
 31036                  "content": "c216654b56044f331290628a2a3d40a0c5d50323"
 31037                }
 31038              ]
 31039            }
 31040          ],
 31041          "evidence": {},
 31042          "signature": {
 31043            "signature": {
 31044              "publicKey": {}
 31045            }
 31046          },
 31047          "modelCard": {
 31048            "modelParameters": {
 31049              "approach": {}
 31050            },
 31051            "quantitativeAnalysis": {
 31052              "graphics": {}
 31053            },
 31054            "considerations": {}
 31055          }
 31056        },
 31057        {
 31058          "type": "library",
 31059          "bom-ref": "pkg:maven/net.jradius/jradius-dictionary@1.1.5?package-id=bbb7ec3937569352",
 31060          "supplier": {},
 31061          "group": "net.jradius",
 31062          "name": "jradius-dictionary",
 31063          "version": "1.1.5",
 31064          "cpe": "cpe:2.3:a:jradius-dictionary:jradius-dictionary:1.1.5:*:*:*:*:*:*:*",
 31065          "purl": "pkg:maven/net.jradius/jradius-dictionary@1.1.5",
 31066          "swid": {
 31067            "attachment": {}
 31068          },
 31069          "pedigree": {},
 31070          "externalReferences": [
 31071            {
 31072              "type": "build-meta",
 31073              "hashes": [
 31074                {
 31075                  "alg": "SHA-1",
 31076                  "content": "a186921802d11779e3ee3adbe54636489dc1dfd3"
 31077                }
 31078              ]
 31079            }
 31080          ],
 31081          "evidence": {},
 31082          "signature": {
 31083            "signature": {
 31084              "publicKey": {}
 31085            }
 31086          },
 31087          "modelCard": {
 31088            "modelParameters": {
 31089              "approach": {}
 31090            },
 31091            "quantitativeAnalysis": {
 31092              "graphics": {}
 31093            },
 31094            "considerations": {}
 31095          }
 31096        },
 31097        {
 31098          "type": "library",
 31099          "bom-ref": "pkg:maven/net.jradius/jradius-extended@1.1.5?package-id=f09f977dbbc1c06a",
 31100          "supplier": {},
 31101          "group": "net.jradius",
 31102          "name": "jradius-extended",
 31103          "version": "1.1.5",
 31104          "cpe": "cpe:2.3:a:jradius-extended:jradius-extended:1.1.5:*:*:*:*:*:*:*",
 31105          "purl": "pkg:maven/net.jradius/jradius-extended@1.1.5",
 31106          "swid": {
 31107            "attachment": {}
 31108          },
 31109          "pedigree": {},
 31110          "externalReferences": [
 31111            {
 31112              "type": "build-meta",
 31113              "hashes": [
 31114                {
 31115                  "alg": "SHA-1",
 31116                  "content": "84497fbb9e5ee80eed68d1e7f560ed45ee247cd9"
 31117                }
 31118              ]
 31119            }
 31120          ],
 31121          "evidence": {},
 31122          "signature": {
 31123            "signature": {
 31124              "publicKey": {}
 31125            }
 31126          },
 31127          "modelCard": {
 31128            "modelParameters": {
 31129              "approach": {}
 31130            },
 31131            "quantitativeAnalysis": {
 31132              "graphics": {}
 31133            },
 31134            "considerations": {}
 31135          }
 31136        },
 31137        {
 31138          "type": "library",
 31139          "bom-ref": "pkg:maven/jsse/jsse@1.8.0_362?package-id=c373477973ee44a0",
 31140          "supplier": {},
 31141          "name": "jsse",
 31142          "version": "1.8.0_362",
 31143          "cpe": "cpe:2.3:a:oracle-corporation:jsse:1.8.0_362:*:*:*:*:*:*:*",
 31144          "purl": "pkg:maven/jsse/jsse@1.8.0_362",
 31145          "swid": {
 31146            "attachment": {}
 31147          },
 31148          "pedigree": {},
 31149          "externalReferences": [
 31150            {
 31151              "type": "build-meta",
 31152              "hashes": [
 31153                {
 31154                  "alg": "SHA-1",
 31155                  "content": "e2cc27ebb60ca839f44d9794f18450eb23cf44b4"
 31156                }
 31157              ]
 31158            }
 31159          ],
 31160          "evidence": {},
 31161          "signature": {
 31162            "signature": {
 31163              "publicKey": {}
 31164            }
 31165          },
 31166          "modelCard": {
 31167            "modelParameters": {
 31168              "approach": {}
 31169            },
 31170            "quantitativeAnalysis": {
 31171              "graphics": {}
 31172            },
 31173            "considerations": {}
 31174          }
 31175        },
 31176        {
 31177          "type": "library",
 31178          "bom-ref": "pkg:maven/org.slf4j/jul-to-slf4j@1.7.30?package-id=6d1332b674916d39",
 31179          "supplier": {},
 31180          "group": "org.slf4j",
 31181          "name": "jul-to-slf4j",
 31182          "version": "1.7.30",
 31183          "cpe": "cpe:2.3:a:jul-to-slf4j:jul-to-slf4j:1.7.30:*:*:*:*:*:*:*",
 31184          "purl": "pkg:maven/org.slf4j/jul-to-slf4j@1.7.30",
 31185          "swid": {
 31186            "attachment": {}
 31187          },
 31188          "pedigree": {},
 31189          "externalReferences": [
 31190            {
 31191              "type": "build-meta",
 31192              "hashes": [
 31193                {
 31194                  "alg": "SHA-1",
 31195                  "content": "d58bebff8cbf70ff52b59208586095f467656c30"
 31196                }
 31197              ]
 31198            }
 31199          ],
 31200          "evidence": {},
 31201          "signature": {
 31202            "signature": {
 31203              "publicKey": {}
 31204            }
 31205          },
 31206          "modelCard": {
 31207            "modelParameters": {
 31208              "approach": {}
 31209            },
 31210            "quantitativeAnalysis": {
 31211              "graphics": {}
 31212            },
 31213            "considerations": {}
 31214          }
 31215        },
 31216        {
 31217          "type": "library",
 31218          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r4?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.17.3\u0026package-id=60a12fd5038efa61",
 31219          "supplier": {},
 31220          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 31221          "name": "libbz2",
 31222          "version": "1.0.8-r4",
 31223          "description": "Shared library for bz2",
 31224          "licenses": [
 31225            {
 31226              "license": {
 31227                "id": "bzip2-1.0.6"
 31228              }
 31229            }
 31230          ],
 31231          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r4:*:*:*:*:*:*:*",
 31232          "purl": "pkg:apk/alpine/libbz2@1.0.8-r4?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.17.3",
 31233          "swid": {
 31234            "attachment": {}
 31235          },
 31236          "pedigree": {},
 31237          "externalReferences": [
 31238            {
 31239              "url": "https://sourceware.org/bzip2/",
 31240              "type": "distribution"
 31241            }
 31242          ],
 31243          "evidence": {},
 31244          "signature": {
 31245            "signature": {
 31246              "publicKey": {}
 31247            }
 31248          },
 31249          "modelCard": {
 31250            "modelParameters": {
 31251              "approach": {}
 31252            },
 31253            "quantitativeAnalysis": {
 31254              "graphics": {}
 31255            },
 31256            "considerations": {}
 31257          }
 31258        },
 31259        {
 31260          "type": "library",
 31261          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.3\u0026package-id=8126b232e2d3c608",
 31262          "supplier": {},
 31263          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 31264          "name": "libc-utils",
 31265          "version": "0.7.2-r3",
 31266          "description": "Meta package to pull in correct libc",
 31267          "licenses": [
 31268            {
 31269              "license": {
 31270                "id": "BSD-2-Clause"
 31271              }
 31272            },
 31273            {
 31274              "license": {
 31275                "name": "AND"
 31276              }
 31277            },
 31278            {
 31279              "license": {
 31280                "id": "BSD-3-Clause"
 31281              }
 31282            }
 31283          ],
 31284          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
 31285          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.3",
 31286          "swid": {
 31287            "attachment": {}
 31288          },
 31289          "pedigree": {},
 31290          "externalReferences": [
 31291            {
 31292              "url": "https://alpinelinux.org",
 31293              "type": "distribution"
 31294            }
 31295          ],
 31296          "evidence": {},
 31297          "signature": {
 31298            "signature": {
 31299              "publicKey": {}
 31300            }
 31301          },
 31302          "modelCard": {
 31303            "modelParameters": {
 31304              "approach": {}
 31305            },
 31306            "quantitativeAnalysis": {
 31307              "graphics": {}
 31308            },
 31309            "considerations": {}
 31310          }
 31311        },
 31312        {
 31313          "type": "library",
 31314          "bom-ref": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3\u0026package-id=d3084c788891fb28",
 31315          "supplier": {},
 31316          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 31317          "name": "libcrypto3",
 31318          "version": "3.0.8-r3",
 31319          "description": "Crypto library from openssl",
 31320          "licenses": [
 31321            {
 31322              "license": {
 31323                "id": "Apache-2.0"
 31324              }
 31325            }
 31326          ],
 31327          "cpe": "cpe:2.3:a:libcrypto3:libcrypto3:3.0.8-r3:*:*:*:*:*:*:*",
 31328          "purl": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3",
 31329          "swid": {
 31330            "attachment": {}
 31331          },
 31332          "pedigree": {},
 31333          "externalReferences": [
 31334            {
 31335              "url": "https://www.openssl.org/",
 31336              "type": "distribution"
 31337            }
 31338          ],
 31339          "evidence": {},
 31340          "signature": {
 31341            "signature": {
 31342              "publicKey": {}
 31343            }
 31344          },
 31345          "modelCard": {
 31346            "modelParameters": {
 31347              "approach": {}
 31348            },
 31349            "quantitativeAnalysis": {
 31350              "graphics": {}
 31351            },
 31352            "considerations": {}
 31353          }
 31354        },
 31355        {
 31356          "type": "library",
 31357          "bom-ref": "pkg:apk/alpine/libexpat@2.5.0-r0?arch=x86_64\u0026upstream=expat\u0026distro=alpine-3.17.3\u0026package-id=3230d7655464b5cd",
 31358          "supplier": {},
 31359          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 31360          "name": "libexpat",
 31361          "version": "2.5.0-r0",
 31362          "description": "XML Parser library written in C (libraries)",
 31363          "licenses": [
 31364            {
 31365              "license": {
 31366                "id": "MIT"
 31367              }
 31368            }
 31369          ],
 31370          "cpe": "cpe:2.3:a:libexpat:libexpat:2.5.0-r0:*:*:*:*:*:*:*",
 31371          "purl": "pkg:apk/alpine/libexpat@2.5.0-r0?arch=x86_64\u0026upstream=expat\u0026distro=alpine-3.17.3",
 31372          "swid": {
 31373            "attachment": {}
 31374          },
 31375          "pedigree": {},
 31376          "externalReferences": [
 31377            {
 31378              "url": "https://libexpat.github.io/",
 31379              "type": "distribution"
 31380            }
 31381          ],
 31382          "evidence": {},
 31383          "signature": {
 31384            "signature": {
 31385              "publicKey": {}
 31386            }
 31387          },
 31388          "modelCard": {
 31389            "modelParameters": {
 31390              "approach": {}
 31391            },
 31392            "quantitativeAnalysis": {
 31393              "graphics": {}
 31394            },
 31395            "considerations": {}
 31396          }
 31397        },
 31398        {
 31399          "type": "library",
 31400          "bom-ref": "pkg:apk/alpine/libfontenc@1.1.6-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=4b664e9d006f8d78",
 31401          "supplier": {},
 31402          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 31403          "name": "libfontenc",
 31404          "version": "1.1.6-r0",
 31405          "description": "X11 font encoding library",
 31406          "licenses": [
 31407            {
 31408              "license": {
 31409                "id": "MIT"
 31410              }
 31411            }
 31412          ],
 31413          "cpe": "cpe:2.3:a:libfontenc:libfontenc:1.1.6-r0:*:*:*:*:*:*:*",
 31414          "purl": "pkg:apk/alpine/libfontenc@1.1.6-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 31415          "swid": {
 31416            "attachment": {}
 31417          },
 31418          "pedigree": {},
 31419          "externalReferences": [
 31420            {
 31421              "url": "http://xorg.freedesktop.org/",
 31422              "type": "distribution"
 31423            }
 31424          ],
 31425          "evidence": {},
 31426          "signature": {
 31427            "signature": {
 31428              "publicKey": {}
 31429            }
 31430          },
 31431          "modelCard": {
 31432            "modelParameters": {
 31433              "approach": {}
 31434            },
 31435            "quantitativeAnalysis": {
 31436              "graphics": {}
 31437            },
 31438            "considerations": {}
 31439          }
 31440        },
 31441        {
 31442          "type": "library",
 31443          "bom-ref": "pkg:apk/alpine/libpng@1.6.38-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=de4865c94634be51",
 31444          "supplier": {},
 31445          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 31446          "name": "libpng",
 31447          "version": "1.6.38-r0",
 31448          "description": "Portable Network Graphics library",
 31449          "licenses": [
 31450            {
 31451              "license": {
 31452                "id": "Libpng"
 31453              }
 31454            }
 31455          ],
 31456          "cpe": "cpe:2.3:a:libpng:libpng:1.6.38-r0:*:*:*:*:*:*:*",
 31457          "purl": "pkg:apk/alpine/libpng@1.6.38-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 31458          "swid": {
 31459            "attachment": {}
 31460          },
 31461          "pedigree": {},
 31462          "externalReferences": [
 31463            {
 31464              "url": "http://www.libpng.org",
 31465              "type": "distribution"
 31466            }
 31467          ],
 31468          "evidence": {},
 31469          "signature": {
 31470            "signature": {
 31471              "publicKey": {}
 31472            }
 31473          },
 31474          "modelCard": {
 31475            "modelParameters": {
 31476              "approach": {}
 31477            },
 31478            "quantitativeAnalysis": {
 31479              "graphics": {}
 31480            },
 31481            "considerations": {}
 31482          }
 31483        },
 31484        {
 31485          "type": "library",
 31486          "bom-ref": "pkg:apk/alpine/libretls@3.5.2-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=1539d83bb0f27113",
 31487          "supplier": {},
 31488          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 31489          "name": "libretls",
 31490          "version": "3.5.2-r1",
 31491          "description": "port of libtls from libressl to openssl",
 31492          "licenses": [
 31493            {
 31494              "license": {
 31495                "id": "ISC"
 31496              }
 31497            },
 31498            {
 31499              "license": {
 31500                "name": "AND"
 31501              }
 31502            },
 31503            {
 31504              "license": {
 31505                "name": "("
 31506              }
 31507            },
 31508            {
 31509              "license": {
 31510                "id": "BSD-3-Clause"
 31511              }
 31512            },
 31513            {
 31514              "license": {
 31515                "name": "OR"
 31516              }
 31517            },
 31518            {
 31519              "license": {
 31520                "id": "MIT"
 31521              }
 31522            },
 31523            {
 31524              "license": {
 31525                "name": ")"
 31526              }
 31527            }
 31528          ],
 31529          "cpe": "cpe:2.3:a:libretls:libretls:3.5.2-r1:*:*:*:*:*:*:*",
 31530          "purl": "pkg:apk/alpine/libretls@3.5.2-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 31531          "swid": {
 31532            "attachment": {}
 31533          },
 31534          "pedigree": {},
 31535          "externalReferences": [
 31536            {
 31537              "url": "https://git.causal.agency/libretls/",
 31538              "type": "distribution"
 31539            }
 31540          ],
 31541          "evidence": {},
 31542          "signature": {
 31543            "signature": {
 31544              "publicKey": {}
 31545            }
 31546          },
 31547          "modelCard": {
 31548            "modelParameters": {
 31549              "approach": {}
 31550            },
 31551            "quantitativeAnalysis": {
 31552              "graphics": {}
 31553            },
 31554            "considerations": {}
 31555          }
 31556        },
 31557        {
 31558          "type": "library",
 31559          "bom-ref": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3\u0026package-id=2a95f0251fba7a33",
 31560          "supplier": {},
 31561          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 31562          "name": "libssl3",
 31563          "version": "3.0.8-r3",
 31564          "description": "SSL shared libraries",
 31565          "licenses": [
 31566            {
 31567              "license": {
 31568                "id": "Apache-2.0"
 31569              }
 31570            }
 31571          ],
 31572          "cpe": "cpe:2.3:a:libssl3:libssl3:3.0.8-r3:*:*:*:*:*:*:*",
 31573          "purl": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3",
 31574          "swid": {
 31575            "attachment": {}
 31576          },
 31577          "pedigree": {},
 31578          "externalReferences": [
 31579            {
 31580              "url": "https://www.openssl.org/",
 31581              "type": "distribution"
 31582            }
 31583          ],
 31584          "evidence": {},
 31585          "signature": {
 31586            "signature": {
 31587              "publicKey": {}
 31588            }
 31589          },
 31590          "modelCard": {
 31591            "modelParameters": {
 31592              "approach": {}
 31593            },
 31594            "quantitativeAnalysis": {
 31595              "graphics": {}
 31596            },
 31597            "considerations": {}
 31598          }
 31599        },
 31600        {
 31601          "type": "library",
 31602          "bom-ref": "pkg:maven/local_policy/local_policy?package-id=7e5a8ee4262b37db",
 31603          "supplier": {},
 31604          "name": "local_policy",
 31605          "cpe": "cpe:2.3:a:local-policy:local-policy:*:*:*:*:*:*:*:*",
 31606          "purl": "pkg:maven/local_policy/local_policy",
 31607          "swid": {
 31608            "attachment": {}
 31609          },
 31610          "pedigree": {},
 31611          "externalReferences": [
 31612            {
 31613              "type": "build-meta",
 31614              "hashes": [
 31615                {
 31616                  "alg": "SHA-1",
 31617                  "content": "bc70ce9f98d1f3ebcf41bb5e7b92556a5a2d4788"
 31618                }
 31619              ]
 31620            }
 31621          ],
 31622          "evidence": {},
 31623          "signature": {
 31624            "signature": {
 31625              "publicKey": {}
 31626            }
 31627          },
 31628          "modelCard": {
 31629            "modelParameters": {
 31630              "approach": {}
 31631            },
 31632            "quantitativeAnalysis": {
 31633              "graphics": {}
 31634            },
 31635            "considerations": {}
 31636          }
 31637        },
 31638        {
 31639          "type": "library",
 31640          "bom-ref": "pkg:maven/local_policy/local_policy?package-id=6060fa0479e27db5",
 31641          "supplier": {},
 31642          "name": "local_policy",
 31643          "cpe": "cpe:2.3:a:local-policy:local-policy:*:*:*:*:*:*:*:*",
 31644          "purl": "pkg:maven/local_policy/local_policy",
 31645          "swid": {
 31646            "attachment": {}
 31647          },
 31648          "pedigree": {},
 31649          "externalReferences": [
 31650            {
 31651              "type": "build-meta",
 31652              "hashes": [
 31653                {
 31654                  "alg": "SHA-1",
 31655                  "content": "8ab714610f8bf90411dc029a09ecd27c2b60c804"
 31656                }
 31657              ]
 31658            }
 31659          ],
 31660          "evidence": {},
 31661          "signature": {
 31662            "signature": {
 31663              "publicKey": {}
 31664            }
 31665          },
 31666          "modelCard": {
 31667            "modelParameters": {
 31668              "approach": {}
 31669            },
 31670            "quantitativeAnalysis": {
 31671              "graphics": {}
 31672            },
 31673            "considerations": {}
 31674          }
 31675        },
 31676        {
 31677          "type": "library",
 31678          "bom-ref": "pkg:maven/localedata/localedata?package-id=3d9158e219a57e4d",
 31679          "supplier": {},
 31680          "name": "localedata",
 31681          "cpe": "cpe:2.3:a:localedata:localedata:*:*:*:*:*:*:*:*",
 31682          "purl": "pkg:maven/localedata/localedata",
 31683          "swid": {
 31684            "attachment": {}
 31685          },
 31686          "pedigree": {},
 31687          "externalReferences": [
 31688            {
 31689              "type": "build-meta",
 31690              "hashes": [
 31691                {
 31692                  "alg": "SHA-1",
 31693                  "content": "fd7f6a9ee8e6263caca5c369c0bb813702c672c0"
 31694                }
 31695              ]
 31696            }
 31697          ],
 31698          "evidence": {},
 31699          "signature": {
 31700            "signature": {
 31701              "publicKey": {}
 31702            }
 31703          },
 31704          "modelCard": {
 31705            "modelParameters": {
 31706              "approach": {}
 31707            },
 31708            "quantitativeAnalysis": {
 31709              "graphics": {}
 31710            },
 31711            "considerations": {}
 31712          }
 31713        },
 31714        {
 31715          "type": "library",
 31716          "bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-api@2.13.3?package-id=51bfc623e5176345",
 31717          "supplier": {},
 31718          "group": "org.apache.logging.log4j",
 31719          "name": "log4j-api",
 31720          "version": "2.13.3",
 31721          "licenses": [
 31722            {
 31723              "license": {
 31724                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 31725              }
 31726            }
 31727          ],
 31728          "cpe": "cpe:2.3:a:apache:log4j-api:2.13.3:*:*:*:*:*:*:*",
 31729          "purl": "pkg:maven/org.apache.logging.log4j/log4j-api@2.13.3",
 31730          "swid": {
 31731            "attachment": {}
 31732          },
 31733          "pedigree": {},
 31734          "externalReferences": [
 31735            {
 31736              "type": "build-meta",
 31737              "hashes": [
 31738                {
 31739                  "alg": "SHA-1",
 31740                  "content": "ec1508160b93d274b1add34419b897bae84c6ca9"
 31741                }
 31742              ]
 31743            }
 31744          ],
 31745          "evidence": {},
 31746          "signature": {
 31747            "signature": {
 31748              "publicKey": {}
 31749            }
 31750          },
 31751          "modelCard": {
 31752            "modelParameters": {
 31753              "approach": {}
 31754            },
 31755            "quantitativeAnalysis": {
 31756              "graphics": {}
 31757            },
 31758            "considerations": {}
 31759          }
 31760        },
 31761        {
 31762          "type": "library",
 31763          "bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.13.3?package-id=bbb819b9ec1260d4",
 31764          "supplier": {},
 31765          "group": "org.apache.logging.log4j",
 31766          "name": "log4j-to-slf4j",
 31767          "version": "2.13.3",
 31768          "licenses": [
 31769            {
 31770              "license": {
 31771                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 31772              }
 31773            }
 31774          ],
 31775          "cpe": "cpe:2.3:a:apache:log4j-to-slf4j:2.13.3:*:*:*:*:*:*:*",
 31776          "purl": "pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.13.3",
 31777          "swid": {
 31778            "attachment": {}
 31779          },
 31780          "pedigree": {},
 31781          "externalReferences": [
 31782            {
 31783              "type": "build-meta",
 31784              "hashes": [
 31785                {
 31786                  "alg": "SHA-1",
 31787                  "content": "966f6fd1af4959d6b12bfa880121d4a2b164f857"
 31788                }
 31789              ]
 31790            }
 31791          ],
 31792          "evidence": {},
 31793          "signature": {
 31794            "signature": {
 31795              "publicKey": {}
 31796            }
 31797          },
 31798          "modelCard": {
 31799            "modelParameters": {
 31800              "approach": {}
 31801            },
 31802            "quantitativeAnalysis": {
 31803              "graphics": {}
 31804            },
 31805            "considerations": {}
 31806          }
 31807        },
 31808        {
 31809          "type": "library",
 31810          "bom-ref": "pkg:maven/logback-classic/logback-classic@1.2.3?package-id=8293ea7bd5e3c0ea",
 31811          "supplier": {},
 31812          "group": "ch.qos.logback",
 31813          "name": "logback-classic",
 31814          "version": "1.2.3",
 31815          "licenses": [
 31816            {
 31817              "license": {
 31818                "name": "http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"
 31819              }
 31820            }
 31821          ],
 31822          "cpe": "cpe:2.3:a:logback-classic:logback-classic:1.2.3:*:*:*:*:*:*:*",
 31823          "purl": "pkg:maven/logback-classic/logback-classic@1.2.3",
 31824          "swid": {
 31825            "attachment": {}
 31826          },
 31827          "pedigree": {},
 31828          "externalReferences": [
 31829            {
 31830              "type": "build-meta",
 31831              "hashes": [
 31832                {
 31833                  "alg": "SHA-1",
 31834                  "content": "7c4f3c474fb2c041d8028740440937705ebb473a"
 31835                }
 31836              ]
 31837            }
 31838          ],
 31839          "evidence": {},
 31840          "signature": {
 31841            "signature": {
 31842              "publicKey": {}
 31843            }
 31844          },
 31845          "modelCard": {
 31846            "modelParameters": {
 31847              "approach": {}
 31848            },
 31849            "quantitativeAnalysis": {
 31850              "graphics": {}
 31851            },
 31852            "considerations": {}
 31853          }
 31854        },
 31855        {
 31856          "type": "library",
 31857          "bom-ref": "pkg:maven/logback-core/logback-core@1.2.3?package-id=e22bdaf71dc66fea",
 31858          "supplier": {},
 31859          "group": "ch.qos.logback",
 31860          "name": "logback-core",
 31861          "version": "1.2.3",
 31862          "licenses": [
 31863            {
 31864              "license": {
 31865                "name": "http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"
 31866              }
 31867            }
 31868          ],
 31869          "cpe": "cpe:2.3:a:logback-core:logback-core:1.2.3:*:*:*:*:*:*:*",
 31870          "purl": "pkg:maven/logback-core/logback-core@1.2.3",
 31871          "swid": {
 31872            "attachment": {}
 31873          },
 31874          "pedigree": {},
 31875          "externalReferences": [
 31876            {
 31877              "type": "build-meta",
 31878              "hashes": [
 31879                {
 31880                  "alg": "SHA-1",
 31881                  "content": "864344400c3d4d92dfeb0a305dc87d953677c03c"
 31882                }
 31883              ]
 31884            }
 31885          ],
 31886          "evidence": {},
 31887          "signature": {
 31888            "signature": {
 31889              "publicKey": {}
 31890            }
 31891          },
 31892          "modelCard": {
 31893            "modelParameters": {
 31894              "approach": {}
 31895            },
 31896            "quantitativeAnalysis": {
 31897              "graphics": {}
 31898            },
 31899            "considerations": {}
 31900          }
 31901        },
 31902        {
 31903          "type": "library",
 31904          "bom-ref": "pkg:maven/management-agent/management-agent?package-id=7defce2ca9e0fee2",
 31905          "supplier": {},
 31906          "name": "management-agent",
 31907          "cpe": "cpe:2.3:a:management-agent:management-agent:*:*:*:*:*:*:*:*",
 31908          "purl": "pkg:maven/management-agent/management-agent",
 31909          "swid": {
 31910            "attachment": {}
 31911          },
 31912          "pedigree": {},
 31913          "externalReferences": [
 31914            {
 31915              "type": "build-meta",
 31916              "hashes": [
 31917                {
 31918                  "alg": "SHA-1",
 31919                  "content": "66e296ac38ffd9d835b2c91f67cde75891e81631"
 31920                }
 31921              ]
 31922            }
 31923          ],
 31924          "evidence": {},
 31925          "signature": {
 31926            "signature": {
 31927              "publicKey": {}
 31928            }
 31929          },
 31930          "modelCard": {
 31931            "modelParameters": {
 31932              "approach": {}
 31933            },
 31934            "quantitativeAnalysis": {
 31935              "graphics": {}
 31936            },
 31937            "considerations": {}
 31938          }
 31939        },
 31940        {
 31941          "type": "library",
 31942          "bom-ref": "pkg:apk/alpine/mkfontscale@1.2.2-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=5556aac06b098482",
 31943          "supplier": {},
 31944          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 31945          "name": "mkfontscale",
 31946          "version": "1.2.2-r1",
 31947          "description": "Scalable font index generator for X",
 31948          "licenses": [
 31949            {
 31950              "license": {
 31951                "id": "MIT"
 31952              }
 31953            }
 31954          ],
 31955          "cpe": "cpe:2.3:a:mkfontscale:mkfontscale:1.2.2-r1:*:*:*:*:*:*:*",
 31956          "purl": "pkg:apk/alpine/mkfontscale@1.2.2-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 31957          "swid": {
 31958            "attachment": {}
 31959          },
 31960          "pedigree": {},
 31961          "externalReferences": [
 31962            {
 31963              "url": "http://xorg.freedesktop.org",
 31964              "type": "distribution"
 31965            }
 31966          ],
 31967          "evidence": {},
 31968          "signature": {
 31969            "signature": {
 31970              "publicKey": {}
 31971            }
 31972          },
 31973          "modelCard": {
 31974            "modelParameters": {
 31975              "approach": {}
 31976            },
 31977            "quantitativeAnalysis": {
 31978              "graphics": {}
 31979            },
 31980            "considerations": {}
 31981          }
 31982        },
 31983        {
 31984          "type": "library",
 31985          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=d9700f02cf26e8b8",
 31986          "supplier": {},
 31987          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 31988          "name": "musl",
 31989          "version": "1.2.3-r4",
 31990          "description": "the musl c library (libc) implementation",
 31991          "licenses": [
 31992            {
 31993              "license": {
 31994                "id": "MIT"
 31995              }
 31996            }
 31997          ],
 31998          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r4:*:*:*:*:*:*:*",
 31999          "purl": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.3",
 32000          "swid": {
 32001            "attachment": {}
 32002          },
 32003          "pedigree": {},
 32004          "externalReferences": [
 32005            {
 32006              "url": "https://musl.libc.org/",
 32007              "type": "distribution"
 32008            }
 32009          ],
 32010          "evidence": {},
 32011          "signature": {
 32012            "signature": {
 32013              "publicKey": {}
 32014            }
 32015          },
 32016          "modelCard": {
 32017            "modelParameters": {
 32018              "approach": {}
 32019            },
 32020            "quantitativeAnalysis": {
 32021              "graphics": {}
 32022            },
 32023            "considerations": {}
 32024          }
 32025        },
 32026        {
 32027          "type": "library",
 32028          "bom-ref": "pkg:apk/alpine/musl-locales@0.1.0-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2711b5f56d3082dd",
 32029          "supplier": {},
 32030          "publisher": "TBK \u003calpine@jjtc.eu\u003e",
 32031          "name": "musl-locales",
 32032          "version": "0.1.0-r0",
 32033          "description": "Locales support for musl",
 32034          "licenses": [
 32035            {
 32036              "license": {
 32037                "id": "LGPL-3.0-only"
 32038              }
 32039            }
 32040          ],
 32041          "cpe": "cpe:2.3:a:musl-locales:musl-locales:0.1.0-r0:*:*:*:*:*:*:*",
 32042          "purl": "pkg:apk/alpine/musl-locales@0.1.0-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 32043          "swid": {
 32044            "attachment": {}
 32045          },
 32046          "pedigree": {},
 32047          "externalReferences": [
 32048            {
 32049              "url": "https://git.adelielinux.org/adelie/musl-locales/-/wikis/home",
 32050              "type": "distribution"
 32051            }
 32052          ],
 32053          "evidence": {},
 32054          "signature": {
 32055            "signature": {
 32056              "publicKey": {}
 32057            }
 32058          },
 32059          "modelCard": {
 32060            "modelParameters": {
 32061              "approach": {}
 32062            },
 32063            "quantitativeAnalysis": {
 32064              "graphics": {}
 32065            },
 32066            "considerations": {}
 32067          }
 32068        },
 32069        {
 32070          "type": "library",
 32071          "bom-ref": "pkg:apk/alpine/musl-locales-lang@0.1.0-r0?arch=x86_64\u0026upstream=musl-locales\u0026distro=alpine-3.17.3\u0026package-id=a5f7a593669f92ef",
 32072          "supplier": {},
 32073          "publisher": "TBK \u003calpine@jjtc.eu\u003e",
 32074          "name": "musl-locales-lang",
 32075          "version": "0.1.0-r0",
 32076          "description": "Languages for package musl-locales",
 32077          "licenses": [
 32078            {
 32079              "license": {
 32080                "id": "MIT"
 32081              }
 32082            }
 32083          ],
 32084          "cpe": "cpe:2.3:a:musl-locales-lang:musl-locales-lang:0.1.0-r0:*:*:*:*:*:*:*",
 32085          "purl": "pkg:apk/alpine/musl-locales-lang@0.1.0-r0?arch=x86_64\u0026upstream=musl-locales\u0026distro=alpine-3.17.3",
 32086          "swid": {
 32087            "attachment": {}
 32088          },
 32089          "pedigree": {},
 32090          "externalReferences": [
 32091            {
 32092              "url": "https://git.adelielinux.org/adelie/musl-locales/-/wikis/home",
 32093              "type": "distribution"
 32094            }
 32095          ],
 32096          "evidence": {},
 32097          "signature": {
 32098            "signature": {
 32099              "publicKey": {}
 32100            }
 32101          },
 32102          "modelCard": {
 32103            "modelParameters": {
 32104              "approach": {}
 32105            },
 32106            "quantitativeAnalysis": {
 32107              "graphics": {}
 32108            },
 32109            "considerations": {}
 32110          }
 32111        },
 32112        {
 32113          "type": "library",
 32114          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.3\u0026package-id=f71ecf5267e6c37b",
 32115          "supplier": {},
 32116          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 32117          "name": "musl-utils",
 32118          "version": "1.2.3-r4",
 32119          "description": "the musl c library (libc) implementation",
 32120          "licenses": [
 32121            {
 32122              "license": {
 32123                "id": "MIT"
 32124              }
 32125            },
 32126            {
 32127              "license": {
 32128                "name": "AND"
 32129              }
 32130            },
 32131            {
 32132              "license": {
 32133                "id": "BSD-2-Clause"
 32134              }
 32135            },
 32136            {
 32137              "license": {
 32138                "name": "AND"
 32139              }
 32140            },
 32141            {
 32142              "license": {
 32143                "id": "GPL-2.0-or-later"
 32144              }
 32145            }
 32146          ],
 32147          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r4:*:*:*:*:*:*:*",
 32148          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.3",
 32149          "swid": {
 32150            "attachment": {}
 32151          },
 32152          "pedigree": {},
 32153          "externalReferences": [
 32154            {
 32155              "url": "https://musl.libc.org/",
 32156              "type": "distribution"
 32157            }
 32158          ],
 32159          "evidence": {},
 32160          "signature": {
 32161            "signature": {
 32162              "publicKey": {}
 32163            }
 32164          },
 32165          "modelCard": {
 32166            "modelParameters": {
 32167              "approach": {}
 32168            },
 32169            "quantitativeAnalysis": {
 32170              "graphics": {}
 32171            },
 32172            "considerations": {}
 32173          }
 32174        },
 32175        {
 32176          "type": "library",
 32177          "bom-ref": "pkg:maven/nashorn/nashorn@1.8.0_362-b09?package-id=ff4e7f4643e3b763",
 32178          "supplier": {},
 32179          "name": "nashorn",
 32180          "version": "1.8.0_362-b09",
 32181          "cpe": "cpe:2.3:a:oracle-corporation:nashorn:1.8.0_362-b09:*:*:*:*:*:*:*",
 32182          "purl": "pkg:maven/nashorn/nashorn@1.8.0_362-b09",
 32183          "swid": {
 32184            "attachment": {}
 32185          },
 32186          "pedigree": {},
 32187          "externalReferences": [
 32188            {
 32189              "type": "build-meta",
 32190              "hashes": [
 32191                {
 32192                  "alg": "SHA-1",
 32193                  "content": "85cadde4959b1188714a9d6bfde1304027f07e36"
 32194                }
 32195              ]
 32196            }
 32197          ],
 32198          "evidence": {},
 32199          "signature": {
 32200            "signature": {
 32201              "publicKey": {}
 32202            }
 32203          },
 32204          "modelCard": {
 32205            "modelParameters": {
 32206              "approach": {}
 32207            },
 32208            "quantitativeAnalysis": {
 32209              "graphics": {}
 32210            },
 32211            "considerations": {}
 32212          }
 32213        },
 32214        {
 32215          "type": "library",
 32216          "bom-ref": "pkg:maven/io.pliant/radius@0.0.1-SNAPSHOT?package-id=a7070334020c9524",
 32217          "supplier": {},
 32218          "group": "io.pliant",
 32219          "name": "radius",
 32220          "version": "0.0.1-SNAPSHOT",
 32221          "cpe": "cpe:2.3:a:springframework:radius:0.0.1-SNAPSHOT:*:*:*:*:*:*:*",
 32222          "purl": "pkg:maven/io.pliant/radius@0.0.1-SNAPSHOT",
 32223          "swid": {
 32224            "attachment": {}
 32225          },
 32226          "pedigree": {},
 32227          "externalReferences": [
 32228            {
 32229              "type": "build-meta",
 32230              "hashes": [
 32231                {
 32232                  "alg": "SHA-1",
 32233                  "content": "c1ece56e9a6941d686d0f57c47774c424873bb28"
 32234                }
 32235              ]
 32236            }
 32237          ],
 32238          "evidence": {},
 32239          "signature": {
 32240            "signature": {
 32241              "publicKey": {}
 32242            }
 32243          },
 32244          "modelCard": {
 32245            "modelParameters": {
 32246              "approach": {}
 32247            },
 32248            "quantitativeAnalysis": {
 32249              "graphics": {}
 32250            },
 32251            "considerations": {}
 32252          }
 32253        },
 32254        {
 32255          "type": "library",
 32256          "bom-ref": "pkg:maven/resources/resources@1.8.0_362?package-id=8580b1e6a4b5281a",
 32257          "supplier": {},
 32258          "name": "resources",
 32259          "version": "1.8.0_362",
 32260          "cpe": "cpe:2.3:a:oracle-corporation:resources:1.8.0_362:*:*:*:*:*:*:*",
 32261          "purl": "pkg:maven/resources/resources@1.8.0_362",
 32262          "swid": {
 32263            "attachment": {}
 32264          },
 32265          "pedigree": {},
 32266          "externalReferences": [
 32267            {
 32268              "type": "build-meta",
 32269              "hashes": [
 32270                {
 32271                  "alg": "SHA-1",
 32272                  "content": "34d2d9c5b59ee5ff757e7d766837a4f53947b7a1"
 32273                }
 32274              ]
 32275            }
 32276          ],
 32277          "evidence": {},
 32278          "signature": {
 32279            "signature": {
 32280              "publicKey": {}
 32281            }
 32282          },
 32283          "modelCard": {
 32284            "modelParameters": {
 32285              "approach": {}
 32286            },
 32287            "quantitativeAnalysis": {
 32288              "graphics": {}
 32289            },
 32290            "considerations": {}
 32291          }
 32292        },
 32293        {
 32294          "type": "library",
 32295          "bom-ref": "pkg:maven/rt/rt@1.8.0_362?package-id=a9e172c0e0dc2fce",
 32296          "supplier": {},
 32297          "name": "rt",
 32298          "version": "1.8.0_362",
 32299          "cpe": "cpe:2.3:a:oracle-corporation:rt:1.8.0_362:*:*:*:*:*:*:*",
 32300          "purl": "pkg:maven/rt/rt@1.8.0_362",
 32301          "swid": {
 32302            "attachment": {}
 32303          },
 32304          "pedigree": {},
 32305          "externalReferences": [
 32306            {
 32307              "type": "build-meta",
 32308              "hashes": [
 32309                {
 32310                  "alg": "SHA-1",
 32311                  "content": "d85439d089c379805dac978a1e27a9a3e465bb71"
 32312                }
 32313              ]
 32314            }
 32315          ],
 32316          "evidence": {},
 32317          "signature": {
 32318            "signature": {
 32319              "publicKey": {}
 32320            }
 32321          },
 32322          "modelCard": {
 32323            "modelParameters": {
 32324              "approach": {}
 32325            },
 32326            "quantitativeAnalysis": {
 32327              "graphics": {}
 32328            },
 32329            "considerations": {}
 32330          }
 32331        },
 32332        {
 32333          "type": "library",
 32334          "bom-ref": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.3\u0026package-id=e903138d19e85b80",
 32335          "supplier": {},
 32336          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 32337          "name": "scanelf",
 32338          "version": "1.3.5-r1",
 32339          "description": "Scan ELF binaries for stuff",
 32340          "licenses": [
 32341            {
 32342              "license": {
 32343                "id": "GPL-2.0-only"
 32344              }
 32345            }
 32346          ],
 32347          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.5-r1:*:*:*:*:*:*:*",
 32348          "purl": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.3",
 32349          "swid": {
 32350            "attachment": {}
 32351          },
 32352          "pedigree": {},
 32353          "externalReferences": [
 32354            {
 32355              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
 32356              "type": "distribution"
 32357            }
 32358          ],
 32359          "evidence": {},
 32360          "signature": {
 32361            "signature": {
 32362              "publicKey": {}
 32363            }
 32364          },
 32365          "modelCard": {
 32366            "modelParameters": {
 32367              "approach": {}
 32368            },
 32369            "quantitativeAnalysis": {
 32370              "graphics": {}
 32371            },
 32372            "considerations": {}
 32373          }
 32374        },
 32375        {
 32376          "type": "library",
 32377          "bom-ref": "pkg:maven/org.slf4j/slf4j-api@1.7.30?package-id=1493fd2bb1976fd5",
 32378          "supplier": {},
 32379          "group": "org.slf4j",
 32380          "name": "slf4j-api",
 32381          "version": "1.7.30",
 32382          "cpe": "cpe:2.3:a:slf4j-api:slf4j-api:1.7.30:*:*:*:*:*:*:*",
 32383          "purl": "pkg:maven/org.slf4j/slf4j-api@1.7.30",
 32384          "swid": {
 32385            "attachment": {}
 32386          },
 32387          "pedigree": {},
 32388          "externalReferences": [
 32389            {
 32390              "type": "build-meta",
 32391              "hashes": [
 32392                {
 32393                  "alg": "SHA-1",
 32394                  "content": "b5a4b6d16ab13e34a88fae84c35cd5d68cac922c"
 32395                }
 32396              ]
 32397            }
 32398          ],
 32399          "evidence": {},
 32400          "signature": {
 32401            "signature": {
 32402              "publicKey": {}
 32403            }
 32404          },
 32405          "modelCard": {
 32406            "modelParameters": {
 32407              "approach": {}
 32408            },
 32409            "quantitativeAnalysis": {
 32410              "graphics": {}
 32411            },
 32412            "considerations": {}
 32413          }
 32414        },
 32415        {
 32416          "type": "library",
 32417          "bom-ref": "pkg:maven/org.yaml/snakeyaml@1.26?package-id=396f43487a82ea23",
 32418          "supplier": {},
 32419          "group": "org.yaml",
 32420          "name": "snakeyaml",
 32421          "version": "1.26",
 32422          "licenses": [
 32423            {
 32424              "license": {
 32425                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 32426              }
 32427            }
 32428          ],
 32429          "cpe": "cpe:2.3:a:snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*",
 32430          "purl": "pkg:maven/org.yaml/snakeyaml@1.26",
 32431          "swid": {
 32432            "attachment": {}
 32433          },
 32434          "pedigree": {},
 32435          "externalReferences": [
 32436            {
 32437              "type": "build-meta",
 32438              "hashes": [
 32439                {
 32440                  "alg": "SHA-1",
 32441                  "content": "a78a8747147d2c5807683e76ec2b633e95c14fe9"
 32442                }
 32443              ]
 32444            }
 32445          ],
 32446          "evidence": {},
 32447          "signature": {
 32448            "signature": {
 32449              "publicKey": {}
 32450            }
 32451          },
 32452          "modelCard": {
 32453            "modelParameters": {
 32454              "approach": {}
 32455            },
 32456            "quantitativeAnalysis": {
 32457              "graphics": {}
 32458            },
 32459            "considerations": {}
 32460          }
 32461        },
 32462        {
 32463          "type": "library",
 32464          "bom-ref": "pkg:maven/spring-aop/spring-aop@5.2.8.RELEASE?package-id=178716ef11b2f332",
 32465          "supplier": {},
 32466          "name": "spring-aop",
 32467          "version": "5.2.8.RELEASE",
 32468          "cpe": "cpe:2.3:a:spring-aop:spring-aop:5.2.8.RELEASE:*:*:*:*:*:*:*",
 32469          "purl": "pkg:maven/spring-aop/spring-aop@5.2.8.RELEASE",
 32470          "swid": {
 32471            "attachment": {}
 32472          },
 32473          "pedigree": {},
 32474          "externalReferences": [
 32475            {
 32476              "type": "build-meta",
 32477              "hashes": [
 32478                {
 32479                  "alg": "SHA-1",
 32480                  "content": "e0e9b4ed80ecde4bad258aaa3f87bf16eb1feecc"
 32481                }
 32482              ]
 32483            }
 32484          ],
 32485          "evidence": {},
 32486          "signature": {
 32487            "signature": {
 32488              "publicKey": {}
 32489            }
 32490          },
 32491          "modelCard": {
 32492            "modelParameters": {
 32493              "approach": {}
 32494            },
 32495            "quantitativeAnalysis": {
 32496              "graphics": {}
 32497            },
 32498            "considerations": {}
 32499          }
 32500        },
 32501        {
 32502          "type": "library",
 32503          "bom-ref": "pkg:maven/spring-beans/spring-beans@5.2.8.RELEASE?package-id=2292c15ebf2a8cfb",
 32504          "supplier": {},
 32505          "name": "spring-beans",
 32506          "version": "5.2.8.RELEASE",
 32507          "cpe": "cpe:2.3:a:spring-beans:spring-beans:5.2.8.RELEASE:*:*:*:*:*:*:*",
 32508          "purl": "pkg:maven/spring-beans/spring-beans@5.2.8.RELEASE",
 32509          "swid": {
 32510            "attachment": {}
 32511          },
 32512          "pedigree": {},
 32513          "externalReferences": [
 32514            {
 32515              "type": "build-meta",
 32516              "hashes": [
 32517                {
 32518                  "alg": "SHA-1",
 32519                  "content": "5cfafc2b0f821bda0b537449a6fdf634b0a666ff"
 32520                }
 32521              ]
 32522            }
 32523          ],
 32524          "evidence": {},
 32525          "signature": {
 32526            "signature": {
 32527              "publicKey": {}
 32528            }
 32529          },
 32530          "modelCard": {
 32531            "modelParameters": {
 32532              "approach": {}
 32533            },
 32534            "quantitativeAnalysis": {
 32535              "graphics": {}
 32536            },
 32537            "considerations": {}
 32538          }
 32539        },
 32540        {
 32541          "type": "library",
 32542          "bom-ref": "pkg:maven/spring-boot/spring-boot@2.3.3.RELEASE?package-id=b2a53df9bb7317f",
 32543          "supplier": {},
 32544          "name": "spring-boot",
 32545          "version": "2.3.3.RELEASE",
 32546          "cpe": "cpe:2.3:a:spring-boot:spring-boot:2.3.3.RELEASE:*:*:*:*:*:*:*",
 32547          "purl": "pkg:maven/spring-boot/spring-boot@2.3.3.RELEASE",
 32548          "swid": {
 32549            "attachment": {}
 32550          },
 32551          "pedigree": {},
 32552          "externalReferences": [
 32553            {
 32554              "type": "build-meta",
 32555              "hashes": [
 32556                {
 32557                  "alg": "SHA-1",
 32558                  "content": "74f0cfae433a6ba6d936c61baa5a5316a688dc22"
 32559                }
 32560              ]
 32561            }
 32562          ],
 32563          "evidence": {},
 32564          "signature": {
 32565            "signature": {
 32566              "publicKey": {}
 32567            }
 32568          },
 32569          "modelCard": {
 32570            "modelParameters": {
 32571              "approach": {}
 32572            },
 32573            "quantitativeAnalysis": {
 32574              "graphics": {}
 32575            },
 32576            "considerations": {}
 32577          }
 32578        },
 32579        {
 32580          "type": "library",
 32581          "bom-ref": "pkg:maven/spring-boot-autoconfigure/spring-boot-autoconfigure@2.3.3.RELEASE?package-id=84e90479d1d7f604",
 32582          "supplier": {},
 32583          "name": "spring-boot-autoconfigure",
 32584          "version": "2.3.3.RELEASE",
 32585          "cpe": "cpe:2.3:a:spring-boot-autoconfigure:spring-boot-autoconfigure:2.3.3.RELEASE:*:*:*:*:*:*:*",
 32586          "purl": "pkg:maven/spring-boot-autoconfigure/spring-boot-autoconfigure@2.3.3.RELEASE",
 32587          "swid": {
 32588            "attachment": {}
 32589          },
 32590          "pedigree": {},
 32591          "externalReferences": [
 32592            {
 32593              "type": "build-meta",
 32594              "hashes": [
 32595                {
 32596                  "alg": "SHA-1",
 32597                  "content": "a1343e09cb6024bb4fbf656ce3cd3d13f12ccbdd"
 32598                }
 32599              ]
 32600            }
 32601          ],
 32602          "evidence": {},
 32603          "signature": {
 32604            "signature": {
 32605              "publicKey": {}
 32606            }
 32607          },
 32608          "modelCard": {
 32609            "modelParameters": {
 32610              "approach": {}
 32611            },
 32612            "quantitativeAnalysis": {
 32613              "graphics": {}
 32614            },
 32615            "considerations": {}
 32616          }
 32617        },
 32618        {
 32619          "type": "library",
 32620          "bom-ref": "pkg:maven/spring-boot-starter/spring-boot-starter@2.3.3.RELEASE?package-id=545b27b1db7fd5c0",
 32621          "supplier": {},
 32622          "name": "spring-boot-starter",
 32623          "version": "2.3.3.RELEASE",
 32624          "cpe": "cpe:2.3:a:spring-boot-starter:spring-boot-starter:2.3.3.RELEASE:*:*:*:*:*:*:*",
 32625          "purl": "pkg:maven/spring-boot-starter/spring-boot-starter@2.3.3.RELEASE",
 32626          "swid": {
 32627            "attachment": {}
 32628          },
 32629          "pedigree": {},
 32630          "externalReferences": [
 32631            {
 32632              "type": "build-meta",
 32633              "hashes": [
 32634                {
 32635                  "alg": "SHA-1",
 32636                  "content": "c9bb3464e83990465b86fb94da3d20f92f036d1e"
 32637                }
 32638              ]
 32639            }
 32640          ],
 32641          "evidence": {},
 32642          "signature": {
 32643            "signature": {
 32644              "publicKey": {}
 32645            }
 32646          },
 32647          "modelCard": {
 32648            "modelParameters": {
 32649              "approach": {}
 32650            },
 32651            "quantitativeAnalysis": {
 32652              "graphics": {}
 32653            },
 32654            "considerations": {}
 32655          }
 32656        },
 32657        {
 32658          "type": "library",
 32659          "bom-ref": "pkg:maven/spring-boot-starter-json/spring-boot-starter-json@2.3.3.RELEASE?package-id=47e435666e868ec",
 32660          "supplier": {},
 32661          "name": "spring-boot-starter-json",
 32662          "version": "2.3.3.RELEASE",
 32663          "cpe": "cpe:2.3:a:spring-boot-starter-json:spring-boot-starter-json:2.3.3.RELEASE:*:*:*:*:*:*:*",
 32664          "purl": "pkg:maven/spring-boot-starter-json/spring-boot-starter-json@2.3.3.RELEASE",
 32665          "swid": {
 32666            "attachment": {}
 32667          },
 32668          "pedigree": {},
 32669          "externalReferences": [
 32670            {
 32671              "type": "build-meta",
 32672              "hashes": [
 32673                {
 32674                  "alg": "SHA-1",
 32675                  "content": "8c40b22a0635989ecc58f35d82fd55445be8822f"
 32676                }
 32677              ]
 32678            }
 32679          ],
 32680          "evidence": {},
 32681          "signature": {
 32682            "signature": {
 32683              "publicKey": {}
 32684            }
 32685          },
 32686          "modelCard": {
 32687            "modelParameters": {
 32688              "approach": {}
 32689            },
 32690            "quantitativeAnalysis": {
 32691              "graphics": {}
 32692            },
 32693            "considerations": {}
 32694          }
 32695        },
 32696        {
 32697          "type": "library",
 32698          "bom-ref": "pkg:maven/spring-boot-starter-logging/spring-boot-starter-logging@2.3.3.RELEASE?package-id=eaf6e7f59659f7ce",
 32699          "supplier": {},
 32700          "name": "spring-boot-starter-logging",
 32701          "version": "2.3.3.RELEASE",
 32702          "cpe": "cpe:2.3:a:spring-boot-starter-logging:spring-boot-starter-logging:2.3.3.RELEASE:*:*:*:*:*:*:*",
 32703          "purl": "pkg:maven/spring-boot-starter-logging/spring-boot-starter-logging@2.3.3.RELEASE",
 32704          "swid": {
 32705            "attachment": {}
 32706          },
 32707          "pedigree": {},
 32708          "externalReferences": [
 32709            {
 32710              "type": "build-meta",
 32711              "hashes": [
 32712                {
 32713                  "alg": "SHA-1",
 32714                  "content": "23523992dd7378fa565b1fc70e19629e8b867ada"
 32715                }
 32716              ]
 32717            }
 32718          ],
 32719          "evidence": {},
 32720          "signature": {
 32721            "signature": {
 32722              "publicKey": {}
 32723            }
 32724          },
 32725          "modelCard": {
 32726            "modelParameters": {
 32727              "approach": {}
 32728            },
 32729            "quantitativeAnalysis": {
 32730              "graphics": {}
 32731            },
 32732            "considerations": {}
 32733          }
 32734        },
 32735        {
 32736          "type": "library",
 32737          "bom-ref": "pkg:maven/spring-boot-starter-tomcat/spring-boot-starter-tomcat@2.3.3.RELEASE?package-id=2fbd990d9ba9f815",
 32738          "supplier": {},
 32739          "name": "spring-boot-starter-tomcat",
 32740          "version": "2.3.3.RELEASE",
 32741          "cpe": "cpe:2.3:a:spring-boot-starter-tomcat:spring-boot-starter-tomcat:2.3.3.RELEASE:*:*:*:*:*:*:*",
 32742          "purl": "pkg:maven/spring-boot-starter-tomcat/spring-boot-starter-tomcat@2.3.3.RELEASE",
 32743          "swid": {
 32744            "attachment": {}
 32745          },
 32746          "pedigree": {},
 32747          "externalReferences": [
 32748            {
 32749              "type": "build-meta",
 32750              "hashes": [
 32751                {
 32752                  "alg": "SHA-1",
 32753                  "content": "542a0aaf0f584d186d9bd052ab10a5cf357a5b39"
 32754                }
 32755              ]
 32756            }
 32757          ],
 32758          "evidence": {},
 32759          "signature": {
 32760            "signature": {
 32761              "publicKey": {}
 32762            }
 32763          },
 32764          "modelCard": {
 32765            "modelParameters": {
 32766              "approach": {}
 32767            },
 32768            "quantitativeAnalysis": {
 32769              "graphics": {}
 32770            },
 32771            "considerations": {}
 32772          }
 32773        },
 32774        {
 32775          "type": "library",
 32776          "bom-ref": "pkg:maven/spring-boot-starter-web/spring-boot-starter-web@2.3.3.RELEASE?package-id=ba00e8c5cd0f40e2",
 32777          "supplier": {},
 32778          "name": "spring-boot-starter-web",
 32779          "version": "2.3.3.RELEASE",
 32780          "cpe": "cpe:2.3:a:spring-boot-starter-web:spring-boot-starter-web:2.3.3.RELEASE:*:*:*:*:*:*:*",
 32781          "purl": "pkg:maven/spring-boot-starter-web/spring-boot-starter-web@2.3.3.RELEASE",
 32782          "swid": {
 32783            "attachment": {}
 32784          },
 32785          "pedigree": {},
 32786          "externalReferences": [
 32787            {
 32788              "type": "build-meta",
 32789              "hashes": [
 32790                {
 32791                  "alg": "SHA-1",
 32792                  "content": "d38db3c19ba4bc114aaa4febfc1d89cd8725822d"
 32793                }
 32794              ]
 32795            }
 32796          ],
 32797          "evidence": {},
 32798          "signature": {
 32799            "signature": {
 32800              "publicKey": {}
 32801            }
 32802          },
 32803          "modelCard": {
 32804            "modelParameters": {
 32805              "approach": {}
 32806            },
 32807            "quantitativeAnalysis": {
 32808              "graphics": {}
 32809            },
 32810            "considerations": {}
 32811          }
 32812        },
 32813        {
 32814          "type": "library",
 32815          "bom-ref": "pkg:maven/spring-context/spring-context@5.2.8.RELEASE?package-id=5bbe73c2d365102e",
 32816          "supplier": {},
 32817          "name": "spring-context",
 32818          "version": "5.2.8.RELEASE",
 32819          "cpe": "cpe:2.3:a:spring-context:spring-context:5.2.8.RELEASE:*:*:*:*:*:*:*",
 32820          "purl": "pkg:maven/spring-context/spring-context@5.2.8.RELEASE",
 32821          "swid": {
 32822            "attachment": {}
 32823          },
 32824          "pedigree": {},
 32825          "externalReferences": [
 32826            {
 32827              "type": "build-meta",
 32828              "hashes": [
 32829                {
 32830                  "alg": "SHA-1",
 32831                  "content": "304d59d6c9fda8bc651fecc8c49748f8259de5ce"
 32832                }
 32833              ]
 32834            }
 32835          ],
 32836          "evidence": {},
 32837          "signature": {
 32838            "signature": {
 32839              "publicKey": {}
 32840            }
 32841          },
 32842          "modelCard": {
 32843            "modelParameters": {
 32844              "approach": {}
 32845            },
 32846            "quantitativeAnalysis": {
 32847              "graphics": {}
 32848            },
 32849            "considerations": {}
 32850          }
 32851        },
 32852        {
 32853          "type": "library",
 32854          "bom-ref": "pkg:maven/spring-core/spring-core@5.2.8.RELEASE?package-id=73ae70e967fad2f4",
 32855          "supplier": {},
 32856          "name": "spring-core",
 32857          "version": "5.2.8.RELEASE",
 32858          "cpe": "cpe:2.3:a:springsource-spring-framework:springsource_spring_framework:5.2.8.RELEASE:*:*:*:*:*:*:*",
 32859          "purl": "pkg:maven/spring-core/spring-core@5.2.8.RELEASE",
 32860          "swid": {
 32861            "attachment": {}
 32862          },
 32863          "pedigree": {},
 32864          "externalReferences": [
 32865            {
 32866              "type": "build-meta",
 32867              "hashes": [
 32868                {
 32869                  "alg": "SHA-1",
 32870                  "content": "35a1654028254abd7cb85799a891de8a0ab9f599"
 32871                }
 32872              ]
 32873            }
 32874          ],
 32875          "evidence": {},
 32876          "signature": {
 32877            "signature": {
 32878              "publicKey": {}
 32879            }
 32880          },
 32881          "modelCard": {
 32882            "modelParameters": {
 32883              "approach": {}
 32884            },
 32885            "quantitativeAnalysis": {
 32886              "graphics": {}
 32887            },
 32888            "considerations": {}
 32889          }
 32890        },
 32891        {
 32892          "type": "library",
 32893          "bom-ref": "pkg:maven/spring-expression/spring-expression@5.2.8.RELEASE?package-id=1d540a3afe78049",
 32894          "supplier": {},
 32895          "name": "spring-expression",
 32896          "version": "5.2.8.RELEASE",
 32897          "cpe": "cpe:2.3:a:spring-expression:spring-expression:5.2.8.RELEASE:*:*:*:*:*:*:*",
 32898          "purl": "pkg:maven/spring-expression/spring-expression@5.2.8.RELEASE",
 32899          "swid": {
 32900            "attachment": {}
 32901          },
 32902          "pedigree": {},
 32903          "externalReferences": [
 32904            {
 32905              "type": "build-meta",
 32906              "hashes": [
 32907                {
 32908                  "alg": "SHA-1",
 32909                  "content": "1b3b5c84e83b450357ae84135e1b47d1b4e5a217"
 32910                }
 32911              ]
 32912            }
 32913          ],
 32914          "evidence": {},
 32915          "signature": {
 32916            "signature": {
 32917              "publicKey": {}
 32918            }
 32919          },
 32920          "modelCard": {
 32921            "modelParameters": {
 32922              "approach": {}
 32923            },
 32924            "quantitativeAnalysis": {
 32925              "graphics": {}
 32926            },
 32927            "considerations": {}
 32928          }
 32929        },
 32930        {
 32931          "type": "library",
 32932          "bom-ref": "pkg:maven/spring-jcl/spring-jcl@5.2.8.RELEASE?package-id=298ee8b304150695",
 32933          "supplier": {},
 32934          "name": "spring-jcl",
 32935          "version": "5.2.8.RELEASE",
 32936          "cpe": "cpe:2.3:a:spring-jcl:spring-jcl:5.2.8.RELEASE:*:*:*:*:*:*:*",
 32937          "purl": "pkg:maven/spring-jcl/spring-jcl@5.2.8.RELEASE",
 32938          "swid": {
 32939            "attachment": {}
 32940          },
 32941          "pedigree": {},
 32942          "externalReferences": [
 32943            {
 32944              "type": "build-meta",
 32945              "hashes": [
 32946                {
 32947                  "alg": "SHA-1",
 32948                  "content": "e18b8dea088cc58fad8fc25ee93f22987dd05d94"
 32949                }
 32950              ]
 32951            }
 32952          ],
 32953          "evidence": {},
 32954          "signature": {
 32955            "signature": {
 32956              "publicKey": {}
 32957            }
 32958          },
 32959          "modelCard": {
 32960            "modelParameters": {
 32961              "approach": {}
 32962            },
 32963            "quantitativeAnalysis": {
 32964              "graphics": {}
 32965            },
 32966            "considerations": {}
 32967          }
 32968        },
 32969        {
 32970          "type": "library",
 32971          "bom-ref": "pkg:maven/spring-web/spring-web@5.2.8.RELEASE?package-id=714bcd33ae878ab5",
 32972          "supplier": {},
 32973          "name": "spring-web",
 32974          "version": "5.2.8.RELEASE",
 32975          "cpe": "cpe:2.3:a:spring-web:spring-web:5.2.8.RELEASE:*:*:*:*:*:*:*",
 32976          "purl": "pkg:maven/spring-web/spring-web@5.2.8.RELEASE",
 32977          "swid": {
 32978            "attachment": {}
 32979          },
 32980          "pedigree": {},
 32981          "externalReferences": [
 32982            {
 32983              "type": "build-meta",
 32984              "hashes": [
 32985                {
 32986                  "alg": "SHA-1",
 32987                  "content": "4f9542d61fff7beb6050e8028dfb6b7c6844c99a"
 32988                }
 32989              ]
 32990            }
 32991          ],
 32992          "evidence": {},
 32993          "signature": {
 32994            "signature": {
 32995              "publicKey": {}
 32996            }
 32997          },
 32998          "modelCard": {
 32999            "modelParameters": {
 33000              "approach": {}
 33001            },
 33002            "quantitativeAnalysis": {
 33003              "graphics": {}
 33004            },
 33005            "considerations": {}
 33006          }
 33007        },
 33008        {
 33009          "type": "library",
 33010          "bom-ref": "pkg:maven/spring-webmvc/spring-webmvc@5.2.8.RELEASE?package-id=b129264f3ecc26f2",
 33011          "supplier": {},
 33012          "name": "spring-webmvc",
 33013          "version": "5.2.8.RELEASE",
 33014          "cpe": "cpe:2.3:a:spring-webmvc:spring-webmvc:5.2.8.RELEASE:*:*:*:*:*:*:*",
 33015          "purl": "pkg:maven/spring-webmvc/spring-webmvc@5.2.8.RELEASE",
 33016          "swid": {
 33017            "attachment": {}
 33018          },
 33019          "pedigree": {},
 33020          "externalReferences": [
 33021            {
 33022              "type": "build-meta",
 33023              "hashes": [
 33024                {
 33025                  "alg": "SHA-1",
 33026                  "content": "9cccf8354a7e031e217681db33f14339200dffcf"
 33027                }
 33028              ]
 33029            }
 33030          ],
 33031          "evidence": {},
 33032          "signature": {
 33033            "signature": {
 33034              "publicKey": {}
 33035            }
 33036          },
 33037          "modelCard": {
 33038            "modelParameters": {
 33039              "approach": {}
 33040            },
 33041            "quantitativeAnalysis": {
 33042              "graphics": {}
 33043            },
 33044            "considerations": {}
 33045          }
 33046        },
 33047        {
 33048          "type": "library",
 33049          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3\u0026package-id=b15247aafcd4a647",
 33050          "supplier": {},
 33051          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 33052          "name": "ssl_client",
 33053          "version": "1.35.0-r29",
 33054          "description": "EXternal ssl_client for busybox wget",
 33055          "licenses": [
 33056            {
 33057              "license": {
 33058                "id": "GPL-2.0-only"
 33059              }
 33060            }
 33061          ],
 33062          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r29:*:*:*:*:*:*:*",
 33063          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3",
 33064          "swid": {
 33065            "attachment": {}
 33066          },
 33067          "pedigree": {},
 33068          "externalReferences": [
 33069            {
 33070              "url": "https://busybox.net/",
 33071              "type": "distribution"
 33072            }
 33073          ],
 33074          "evidence": {},
 33075          "signature": {
 33076            "signature": {
 33077              "publicKey": {}
 33078            }
 33079          },
 33080          "modelCard": {
 33081            "modelParameters": {
 33082              "approach": {}
 33083            },
 33084            "quantitativeAnalysis": {
 33085              "graphics": {}
 33086            },
 33087            "considerations": {}
 33088          }
 33089        },
 33090        {
 33091          "type": "library",
 33092          "bom-ref": "pkg:maven/com.sun/sunec@1.8.0_362?package-id=514c2349426dbec0",
 33093          "supplier": {},
 33094          "name": "sunec",
 33095          "version": "1.8.0_362",
 33096          "cpe": "cpe:2.3:a:oracle-corporation:sunec:1.8.0_362:*:*:*:*:*:*:*",
 33097          "purl": "pkg:maven/com.sun/sunec@1.8.0_362",
 33098          "swid": {
 33099            "attachment": {}
 33100          },
 33101          "pedigree": {},
 33102          "externalReferences": [
 33103            {
 33104              "type": "build-meta",
 33105              "hashes": [
 33106                {
 33107                  "alg": "SHA-1",
 33108                  "content": "0a226bea7cf5d3f5bc9ab678f9a0abbbf2836ced"
 33109                }
 33110              ]
 33111            }
 33112          ],
 33113          "evidence": {},
 33114          "signature": {
 33115            "signature": {
 33116              "publicKey": {}
 33117            }
 33118          },
 33119          "modelCard": {
 33120            "modelParameters": {
 33121              "approach": {}
 33122            },
 33123            "quantitativeAnalysis": {
 33124              "graphics": {}
 33125            },
 33126            "considerations": {}
 33127          }
 33128        },
 33129        {
 33130          "type": "library",
 33131          "bom-ref": "pkg:maven/com.sun/sunjce_provider@1.8.0_362?package-id=216feec33fd91c68",
 33132          "supplier": {},
 33133          "name": "sunjce_provider",
 33134          "version": "1.8.0_362",
 33135          "cpe": "cpe:2.3:a:oracle-corporation:sunjce-provider:1.8.0_362:*:*:*:*:*:*:*",
 33136          "purl": "pkg:maven/com.sun/sunjce_provider@1.8.0_362",
 33137          "swid": {
 33138            "attachment": {}
 33139          },
 33140          "pedigree": {},
 33141          "externalReferences": [
 33142            {
 33143              "type": "build-meta",
 33144              "hashes": [
 33145                {
 33146                  "alg": "SHA-1",
 33147                  "content": "5d8e01ee58b00457ce81b3ab7641c7cf49c41fe4"
 33148                }
 33149              ]
 33150            }
 33151          ],
 33152          "evidence": {},
 33153          "signature": {
 33154            "signature": {
 33155              "publicKey": {}
 33156            }
 33157          },
 33158          "modelCard": {
 33159            "modelParameters": {
 33160              "approach": {}
 33161            },
 33162            "quantitativeAnalysis": {
 33163              "graphics": {}
 33164            },
 33165            "considerations": {}
 33166          }
 33167        },
 33168        {
 33169          "type": "library",
 33170          "bom-ref": "pkg:maven/com.sun/sunpkcs11@1.8.0_362?package-id=9814d36df586abb0",
 33171          "supplier": {},
 33172          "name": "sunpkcs11",
 33173          "version": "1.8.0_362",
 33174          "cpe": "cpe:2.3:a:oracle-corporation:sunpkcs11:1.8.0_362:*:*:*:*:*:*:*",
 33175          "purl": "pkg:maven/com.sun/sunpkcs11@1.8.0_362",
 33176          "swid": {
 33177            "attachment": {}
 33178          },
 33179          "pedigree": {},
 33180          "externalReferences": [
 33181            {
 33182              "type": "build-meta",
 33183              "hashes": [
 33184                {
 33185                  "alg": "SHA-1",
 33186                  "content": "bcf85f75350c04e0abc12a15ea7a0325d8131599"
 33187                }
 33188              ]
 33189            }
 33190          ],
 33191          "evidence": {},
 33192          "signature": {
 33193            "signature": {
 33194              "publicKey": {}
 33195            }
 33196          },
 33197          "modelCard": {
 33198            "modelParameters": {
 33199              "approach": {}
 33200            },
 33201            "quantitativeAnalysis": {
 33202              "graphics": {}
 33203            },
 33204            "considerations": {}
 33205          }
 33206        },
 33207        {
 33208          "type": "library",
 33209          "bom-ref": "pkg:maven/org.apache.tomcat-embed-core/tomcat-embed-core@9.0.37?package-id=1beaf6c676c0209c",
 33210          "supplier": {},
 33211          "name": "tomcat-embed-core",
 33212          "version": "9.0.37",
 33213          "cpe": "cpe:2.3:a:apache:tomcat-embed-core:9.0.37:*:*:*:*:*:*:*",
 33214          "purl": "pkg:maven/org.apache.tomcat-embed-core/tomcat-embed-core@9.0.37",
 33215          "swid": {
 33216            "attachment": {}
 33217          },
 33218          "pedigree": {},
 33219          "externalReferences": [
 33220            {
 33221              "type": "build-meta",
 33222              "hashes": [
 33223                {
 33224                  "alg": "SHA-1",
 33225                  "content": "c3f788de87f17eb57a9e7083736c1820fcbc1046"
 33226                }
 33227              ]
 33228            }
 33229          ],
 33230          "evidence": {},
 33231          "signature": {
 33232            "signature": {
 33233              "publicKey": {}
 33234            }
 33235          },
 33236          "modelCard": {
 33237            "modelParameters": {
 33238              "approach": {}
 33239            },
 33240            "quantitativeAnalysis": {
 33241              "graphics": {}
 33242            },
 33243            "considerations": {}
 33244          }
 33245        },
 33246        {
 33247          "type": "library",
 33248          "bom-ref": "pkg:maven/org.apache.tomcat-embed-websocket/tomcat-embed-websocket@9.0.37?package-id=df2b7c22ab34f638",
 33249          "supplier": {},
 33250          "name": "tomcat-embed-websocket",
 33251          "version": "9.0.37",
 33252          "cpe": "cpe:2.3:a:apache:tomcat-embed-websocket:9.0.37:*:*:*:*:*:*:*",
 33253          "purl": "pkg:maven/org.apache.tomcat-embed-websocket/tomcat-embed-websocket@9.0.37",
 33254          "swid": {
 33255            "attachment": {}
 33256          },
 33257          "pedigree": {},
 33258          "externalReferences": [
 33259            {
 33260              "type": "build-meta",
 33261              "hashes": [
 33262                {
 33263                  "alg": "SHA-1",
 33264                  "content": "ee8b7c9081372bf40c41443c93317145a01e343a"
 33265                }
 33266              ]
 33267            }
 33268          ],
 33269          "evidence": {},
 33270          "signature": {
 33271            "signature": {
 33272              "publicKey": {}
 33273            }
 33274          },
 33275          "modelCard": {
 33276            "modelParameters": {
 33277              "approach": {}
 33278            },
 33279            "quantitativeAnalysis": {
 33280              "graphics": {}
 33281            },
 33282            "considerations": {}
 33283          }
 33284        },
 33285        {
 33286          "type": "library",
 33287          "bom-ref": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=7443bdf13c73d18c",
 33288          "supplier": {},
 33289          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 33290          "name": "tzdata",
 33291          "version": "2023c-r0",
 33292          "description": "Timezone data",
 33293          "licenses": [
 33294            {
 33295              "license": {
 33296                "name": "Public-Domain"
 33297              }
 33298            }
 33299          ],
 33300          "cpe": "cpe:2.3:a:tzdata:tzdata:2023c-r0:*:*:*:*:*:*:*",
 33301          "purl": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 33302          "swid": {
 33303            "attachment": {}
 33304          },
 33305          "pedigree": {},
 33306          "externalReferences": [
 33307            {
 33308              "url": "https://www.iana.org/time-zones",
 33309              "type": "distribution"
 33310            }
 33311          ],
 33312          "evidence": {},
 33313          "signature": {
 33314            "signature": {
 33315              "publicKey": {}
 33316            }
 33317          },
 33318          "modelCard": {
 33319            "modelParameters": {
 33320              "approach": {}
 33321            },
 33322            "quantitativeAnalysis": {
 33323              "graphics": {}
 33324            },
 33325            "considerations": {}
 33326          }
 33327        },
 33328        {
 33329          "type": "library",
 33330          "bom-ref": "pkg:maven/zipfs/zipfs@1.8.0_362?package-id=649443e35eb779e0",
 33331          "supplier": {},
 33332          "name": "zipfs",
 33333          "version": "1.8.0_362",
 33334          "cpe": "cpe:2.3:a:oracle-corporation:zipfs:1.8.0_362:*:*:*:*:*:*:*",
 33335          "purl": "pkg:maven/zipfs/zipfs@1.8.0_362",
 33336          "swid": {
 33337            "attachment": {}
 33338          },
 33339          "pedigree": {},
 33340          "externalReferences": [
 33341            {
 33342              "type": "build-meta",
 33343              "hashes": [
 33344                {
 33345                  "alg": "SHA-1",
 33346                  "content": "8826341a6c075308576e50fa5f97c0cdbea0b844"
 33347                }
 33348              ]
 33349            }
 33350          ],
 33351          "evidence": {},
 33352          "signature": {
 33353            "signature": {
 33354              "publicKey": {}
 33355            }
 33356          },
 33357          "modelCard": {
 33358            "modelParameters": {
 33359              "approach": {}
 33360            },
 33361            "quantitativeAnalysis": {
 33362              "graphics": {}
 33363            },
 33364            "considerations": {}
 33365          }
 33366        },
 33367        {
 33368          "type": "library",
 33369          "bom-ref": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=94014313cfcd2b71",
 33370          "supplier": {},
 33371          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 33372          "name": "zlib",
 33373          "version": "1.2.13-r0",
 33374          "description": "A compression/decompression Library",
 33375          "licenses": [
 33376            {
 33377              "license": {
 33378                "id": "Zlib"
 33379              }
 33380            }
 33381          ],
 33382          "cpe": "cpe:2.3:a:zlib:zlib:1.2.13-r0:*:*:*:*:*:*:*",
 33383          "purl": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 33384          "swid": {
 33385            "attachment": {}
 33386          },
 33387          "pedigree": {},
 33388          "externalReferences": [
 33389            {
 33390              "url": "https://zlib.net/",
 33391              "type": "distribution"
 33392            }
 33393          ],
 33394          "evidence": {},
 33395          "signature": {
 33396            "signature": {
 33397              "publicKey": {}
 33398            }
 33399          },
 33400          "modelCard": {
 33401            "modelParameters": {
 33402              "approach": {}
 33403            },
 33404            "quantitativeAnalysis": {
 33405              "graphics": {}
 33406            },
 33407            "considerations": {}
 33408          }
 33409        },
 33410        {
 33411          "type": "operating-system",
 33412          "supplier": {},
 33413          "name": "alpine",
 33414          "version": "3.17.3",
 33415          "description": "Alpine Linux v3.17",
 33416          "swid": {
 33417            "tagId": "alpine",
 33418            "name": "alpine",
 33419            "version": "3.17.3",
 33420            "attachment": {}
 33421          },
 33422          "pedigree": {},
 33423          "externalReferences": [
 33424            {
 33425              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
 33426              "type": "issue-tracker"
 33427            },
 33428            {
 33429              "url": "https://alpinelinux.org/",
 33430              "type": "website"
 33431            }
 33432          ],
 33433          "evidence": {},
 33434          "signature": {
 33435            "signature": {
 33436              "publicKey": {}
 33437            }
 33438          },
 33439          "modelCard": {
 33440            "modelParameters": {
 33441              "approach": {}
 33442            },
 33443            "quantitativeAnalysis": {
 33444              "graphics": {}
 33445            },
 33446            "considerations": {}
 33447          }
 33448        },
 33449        {
 33450          "type": "library",
 33451          "bom-ref": "pkg:deb/debian/acl@2.2.52-2?arch=amd64\u0026distro=debian-8\u0026package-id=d01cbcd940107486",
 33452          "supplier": {},
 33453          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 33454          "name": "acl",
 33455          "version": "2.2.52-2",
 33456          "licenses": [
 33457            {
 33458              "license": {
 33459                "name": "GPL"
 33460              }
 33461            },
 33462            {
 33463              "license": {
 33464                "id": "LGPL-2.1-only"
 33465              }
 33466            }
 33467          ],
 33468          "cpe": "cpe:2.3:a:acl:acl:2.2.52-2:*:*:*:*:*:*:*",
 33469          "purl": "pkg:deb/debian/acl@2.2.52-2?arch=amd64\u0026distro=debian-8",
 33470          "swid": {
 33471            "attachment": {}
 33472          },
 33473          "pedigree": {},
 33474          "evidence": {},
 33475          "signature": {
 33476            "signature": {
 33477              "publicKey": {}
 33478            }
 33479          },
 33480          "modelCard": {
 33481            "modelParameters": {
 33482              "approach": {}
 33483            },
 33484            "quantitativeAnalysis": {
 33485              "graphics": {}
 33486            },
 33487            "considerations": {}
 33488          }
 33489        },
 33490        {
 33491          "type": "library",
 33492          "bom-ref": "pkg:deb/debian/adduser@3.113+nmu3?arch=all\u0026distro=debian-8\u0026package-id=2213f41dee97684c",
 33493          "supplier": {},
 33494          "publisher": "Debian Adduser Developers \u003cadduser-devel@lists.alioth.debian.org\u003e",
 33495          "name": "adduser",
 33496          "version": "3.113+nmu3",
 33497          "licenses": [
 33498            {
 33499              "license": {
 33500                "id": "GPL-2.0-only"
 33501              }
 33502            }
 33503          ],
 33504          "cpe": "cpe:2.3:a:adduser:adduser:3.113\\+nmu3:*:*:*:*:*:*:*",
 33505          "purl": "pkg:deb/debian/adduser@3.113+nmu3?arch=all\u0026distro=debian-8",
 33506          "swid": {
 33507            "attachment": {}
 33508          },
 33509          "pedigree": {},
 33510          "evidence": {},
 33511          "signature": {
 33512            "signature": {
 33513              "publicKey": {}
 33514            }
 33515          },
 33516          "modelCard": {
 33517            "modelParameters": {
 33518              "approach": {}
 33519            },
 33520            "quantitativeAnalysis": {
 33521              "graphics": {}
 33522            },
 33523            "considerations": {}
 33524          }
 33525        },
 33526        {
 33527          "type": "library",
 33528          "bom-ref": "pkg:deb/debian/apt@1.0.9.8.3?arch=amd64\u0026distro=debian-8\u0026package-id=6116723ce9fc37f9",
 33529          "supplier": {},
 33530          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
 33531          "name": "apt",
 33532          "version": "1.0.9.8.3",
 33533          "licenses": [
 33534            {
 33535              "license": {
 33536                "id": "GPL-2.0-only"
 33537              }
 33538            },
 33539            {
 33540              "license": {
 33541                "name": "GPLv2+"
 33542              }
 33543            }
 33544          ],
 33545          "cpe": "cpe:2.3:a:apt:apt:1.0.9.8.3:*:*:*:*:*:*:*",
 33546          "purl": "pkg:deb/debian/apt@1.0.9.8.3?arch=amd64\u0026distro=debian-8",
 33547          "swid": {
 33548            "attachment": {}
 33549          },
 33550          "pedigree": {},
 33551          "evidence": {},
 33552          "signature": {
 33553            "signature": {
 33554              "publicKey": {}
 33555            }
 33556          },
 33557          "modelCard": {
 33558            "modelParameters": {
 33559              "approach": {}
 33560            },
 33561            "quantitativeAnalysis": {
 33562              "graphics": {}
 33563            },
 33564            "considerations": {}
 33565          }
 33566        },
 33567        {
 33568          "type": "library",
 33569          "bom-ref": "pkg:pypi/argparse@1.2.1?package-id=6b85f84e24c639d9",
 33570          "supplier": {},
 33571          "author": "Steven Bethard \u003csteven.bethard@gmail.com\u003e",
 33572          "name": "argparse",
 33573          "version": "1.2.1",
 33574          "licenses": [
 33575            {
 33576              "license": {
 33577                "name": "Python Software Foundation License"
 33578              }
 33579            }
 33580          ],
 33581          "cpe": "cpe:2.3:a:steven_bethard_project:python-argparse:1.2.1:*:*:*:*:*:*:*",
 33582          "purl": "pkg:pypi/argparse@1.2.1",
 33583          "swid": {
 33584            "attachment": {}
 33585          },
 33586          "pedigree": {},
 33587          "evidence": {},
 33588          "signature": {
 33589            "signature": {
 33590              "publicKey": {}
 33591            }
 33592          },
 33593          "modelCard": {
 33594            "modelParameters": {
 33595              "approach": {}
 33596            },
 33597            "quantitativeAnalysis": {
 33598              "graphics": {}
 33599            },
 33600            "considerations": {}
 33601          }
 33602        },
 33603        {
 33604          "type": "library",
 33605          "bom-ref": "pkg:deb/debian/base-files@8+deb8u5?arch=amd64\u0026distro=debian-8\u0026package-id=e0a9362eb8bed226",
 33606          "supplier": {},
 33607          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
 33608          "name": "base-files",
 33609          "version": "8+deb8u5",
 33610          "licenses": [
 33611            {
 33612              "license": {
 33613                "name": "GPL"
 33614              }
 33615            }
 33616          ],
 33617          "cpe": "cpe:2.3:a:base-files:base-files:8\\+deb8u5:*:*:*:*:*:*:*",
 33618          "purl": "pkg:deb/debian/base-files@8+deb8u5?arch=amd64\u0026distro=debian-8",
 33619          "swid": {
 33620            "attachment": {}
 33621          },
 33622          "pedigree": {},
 33623          "evidence": {},
 33624          "signature": {
 33625            "signature": {
 33626              "publicKey": {}
 33627            }
 33628          },
 33629          "modelCard": {
 33630            "modelParameters": {
 33631              "approach": {}
 33632            },
 33633            "quantitativeAnalysis": {
 33634              "graphics": {}
 33635            },
 33636            "considerations": {}
 33637          }
 33638        },
 33639        {
 33640          "type": "library",
 33641          "bom-ref": "pkg:deb/debian/base-passwd@3.5.37?arch=amd64\u0026distro=debian-8\u0026package-id=dd3169634bd48c60",
 33642          "supplier": {},
 33643          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
 33644          "name": "base-passwd",
 33645          "version": "3.5.37",
 33646          "licenses": [
 33647            {
 33648              "license": {
 33649                "id": "GPL-2.0-only"
 33650              }
 33651            },
 33652            {
 33653              "license": {
 33654                "name": "PD"
 33655              }
 33656            }
 33657          ],
 33658          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.37:*:*:*:*:*:*:*",
 33659          "purl": "pkg:deb/debian/base-passwd@3.5.37?arch=amd64\u0026distro=debian-8",
 33660          "swid": {
 33661            "attachment": {}
 33662          },
 33663          "pedigree": {},
 33664          "evidence": {},
 33665          "signature": {
 33666            "signature": {
 33667              "publicKey": {}
 33668            }
 33669          },
 33670          "modelCard": {
 33671            "modelParameters": {
 33672              "approach": {}
 33673            },
 33674            "quantitativeAnalysis": {
 33675              "graphics": {}
 33676            },
 33677            "considerations": {}
 33678          }
 33679        },
 33680        {
 33681          "type": "library",
 33682          "bom-ref": "pkg:deb/debian/bash@4.3-11+b1?arch=amd64\u0026upstream=bash%404.3-11\u0026distro=debian-8\u0026package-id=3f60e286421223f4",
 33683          "supplier": {},
 33684          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 33685          "name": "bash",
 33686          "version": "4.3-11+b1",
 33687          "licenses": [
 33688            {
 33689              "license": {
 33690                "id": "GPL-3.0-only"
 33691              }
 33692            }
 33693          ],
 33694          "cpe": "cpe:2.3:a:bash:bash:4.3-11\\+b1:*:*:*:*:*:*:*",
 33695          "purl": "pkg:deb/debian/bash@4.3-11+b1?arch=amd64\u0026upstream=bash%404.3-11\u0026distro=debian-8",
 33696          "swid": {
 33697            "attachment": {}
 33698          },
 33699          "pedigree": {},
 33700          "evidence": {},
 33701          "signature": {
 33702            "signature": {
 33703              "publicKey": {}
 33704            }
 33705          },
 33706          "modelCard": {
 33707            "modelParameters": {
 33708              "approach": {}
 33709            },
 33710            "quantitativeAnalysis": {
 33711              "graphics": {}
 33712            },
 33713            "considerations": {}
 33714          }
 33715        },
 33716        {
 33717          "type": "library",
 33718          "bom-ref": "pkg:deb/debian/binutils@2.25-5?arch=amd64\u0026distro=debian-8\u0026package-id=651da55d8d7fcd1d",
 33719          "supplier": {},
 33720          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 33721          "name": "binutils",
 33722          "version": "2.25-5",
 33723          "licenses": [
 33724            {
 33725              "license": {
 33726                "name": "GFDL"
 33727              }
 33728            },
 33729            {
 33730              "license": {
 33731                "name": "GPL"
 33732              }
 33733            },
 33734            {
 33735              "license": {
 33736                "name": "LGPL"
 33737              }
 33738            }
 33739          ],
 33740          "cpe": "cpe:2.3:a:binutils:binutils:2.25-5:*:*:*:*:*:*:*",
 33741          "purl": "pkg:deb/debian/binutils@2.25-5?arch=amd64\u0026distro=debian-8",
 33742          "swid": {
 33743            "attachment": {}
 33744          },
 33745          "pedigree": {},
 33746          "evidence": {},
 33747          "signature": {
 33748            "signature": {
 33749              "publicKey": {}
 33750            }
 33751          },
 33752          "modelCard": {
 33753            "modelParameters": {
 33754              "approach": {}
 33755            },
 33756            "quantitativeAnalysis": {
 33757              "graphics": {}
 33758            },
 33759            "considerations": {}
 33760          }
 33761        },
 33762        {
 33763          "type": "library",
 33764          "bom-ref": "pkg:deb/debian/bsdutils@1:2.25.2-6?arch=amd64\u0026upstream=util-linux%402.25.2-6\u0026distro=debian-8\u0026package-id=6c67f49e7e5543ae",
 33765          "supplier": {},
 33766          "publisher": "Debian util-linux Maintainers \u003cah-util-linux@debian.org\u003e",
 33767          "name": "bsdutils",
 33768          "version": "1:2.25.2-6",
 33769          "licenses": [
 33770            {
 33771              "license": {
 33772                "id": "BSD-2-Clause"
 33773              }
 33774            },
 33775            {
 33776              "license": {
 33777                "id": "BSD-3-Clause"
 33778              }
 33779            },
 33780            {
 33781              "license": {
 33782                "id": "BSD-4-Clause"
 33783              }
 33784            },
 33785            {
 33786              "license": {
 33787                "id": "GPL-2.0-only"
 33788              }
 33789            },
 33790            {
 33791              "license": {
 33792                "id": "GPL-2.0-or-later"
 33793              }
 33794            },
 33795            {
 33796              "license": {
 33797                "id": "GPL-3.0-only"
 33798              }
 33799            },
 33800            {
 33801              "license": {
 33802                "id": "GPL-3.0-or-later"
 33803              }
 33804            },
 33805            {
 33806              "license": {
 33807                "name": "LGPL"
 33808              }
 33809            },
 33810            {
 33811              "license": {
 33812                "id": "LGPL-2.0-only"
 33813              }
 33814            },
 33815            {
 33816              "license": {
 33817                "id": "LGPL-2.0-or-later"
 33818              }
 33819            },
 33820            {
 33821              "license": {
 33822                "id": "LGPL-2.1-only"
 33823              }
 33824            },
 33825            {
 33826              "license": {
 33827                "id": "LGPL-2.1-or-later"
 33828              }
 33829            },
 33830            {
 33831              "license": {
 33832                "id": "LGPL-3.0-only"
 33833              }
 33834            },
 33835            {
 33836              "license": {
 33837                "id": "LGPL-3.0-or-later"
 33838              }
 33839            },
 33840            {
 33841              "license": {
 33842                "id": "MIT"
 33843              }
 33844            },
 33845            {
 33846              "license": {
 33847                "name": "public-domain"
 33848              }
 33849            }
 33850          ],
 33851          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.25.2-6:*:*:*:*:*:*:*",
 33852          "purl": "pkg:deb/debian/bsdutils@1:2.25.2-6?arch=amd64\u0026upstream=util-linux%402.25.2-6\u0026distro=debian-8",
 33853          "swid": {
 33854            "attachment": {}
 33855          },
 33856          "pedigree": {},
 33857          "evidence": {},
 33858          "signature": {
 33859            "signature": {
 33860              "publicKey": {}
 33861            }
 33862          },
 33863          "modelCard": {
 33864            "modelParameters": {
 33865              "approach": {}
 33866            },
 33867            "quantitativeAnalysis": {
 33868              "graphics": {}
 33869            },
 33870            "considerations": {}
 33871          }
 33872        },
 33873        {
 33874          "type": "library",
 33875          "bom-ref": "pkg:deb/debian/bzr@2.6.0+bzr6595-6?arch=all\u0026distro=debian-8\u0026package-id=705d917a84726696",
 33876          "supplier": {},
 33877          "publisher": "Debian Bazaar Maintainers \u003cpkg-bazaar-maint@lists.alioth.debian.org\u003e",
 33878          "name": "bzr",
 33879          "version": "2.6.0+bzr6595-6",
 33880          "licenses": [
 33881            {
 33882              "license": {
 33883                "id": "GPL-2.0-only"
 33884              }
 33885            },
 33886            {
 33887              "license": {
 33888                "id": "GPL-2.0-or-later"
 33889              }
 33890            }
 33891          ],
 33892          "cpe": "cpe:2.3:a:bzr:bzr:2.6.0\\+bzr6595-6:*:*:*:*:*:*:*",
 33893          "purl": "pkg:deb/debian/bzr@2.6.0+bzr6595-6?arch=all\u0026distro=debian-8",
 33894          "swid": {
 33895            "attachment": {}
 33896          },
 33897          "pedigree": {},
 33898          "evidence": {},
 33899          "signature": {
 33900            "signature": {
 33901              "publicKey": {}
 33902            }
 33903          },
 33904          "modelCard": {
 33905            "modelParameters": {
 33906              "approach": {}
 33907            },
 33908            "quantitativeAnalysis": {
 33909              "graphics": {}
 33910            },
 33911            "considerations": {}
 33912          }
 33913        },
 33914        {
 33915          "type": "library",
 33916          "bom-ref": "pkg:pypi/bzr@2.7.0dev1?package-id=d84c807e3405bda1",
 33917          "supplier": {},
 33918          "author": "Canonical Ltd \u003cbazaar@lists.canonical.com\u003e",
 33919          "name": "bzr",
 33920          "version": "2.7.0dev1",
 33921          "licenses": [
 33922            {
 33923              "license": {
 33924                "name": "GNU GPL v2"
 33925              }
 33926            }
 33927          ],
 33928          "cpe": "cpe:2.3:a:canonical_ltd_project:python-bzr:2.7.0dev1:*:*:*:*:*:*:*",
 33929          "purl": "pkg:pypi/bzr@2.7.0dev1",
 33930          "swid": {
 33931            "attachment": {}
 33932          },
 33933          "pedigree": {},
 33934          "evidence": {},
 33935          "signature": {
 33936            "signature": {
 33937              "publicKey": {}
 33938            }
 33939          },
 33940          "modelCard": {
 33941            "modelParameters": {
 33942              "approach": {}
 33943            },
 33944            "quantitativeAnalysis": {
 33945              "graphics": {}
 33946            },
 33947            "considerations": {}
 33948          }
 33949        },
 33950        {
 33951          "type": "library",
 33952          "bom-ref": "pkg:deb/debian/ca-certificates@20141019+deb8u1?arch=all\u0026distro=debian-8\u0026package-id=7d375e1cacd0cdf3",
 33953          "supplier": {},
 33954          "publisher": "Michael Shuler \u003cmichael@pbandjelly.org\u003e",
 33955          "name": "ca-certificates",
 33956          "version": "20141019+deb8u1",
 33957          "licenses": [
 33958            {
 33959              "license": {
 33960                "id": "GPL-2.0-only"
 33961              }
 33962            },
 33963            {
 33964              "license": {
 33965                "id": "GPL-2.0-or-later"
 33966              }
 33967            },
 33968            {
 33969              "license": {
 33970                "id": "MPL-2.0"
 33971              }
 33972            }
 33973          ],
 33974          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20141019\\+deb8u1:*:*:*:*:*:*:*",
 33975          "purl": "pkg:deb/debian/ca-certificates@20141019+deb8u1?arch=all\u0026distro=debian-8",
 33976          "swid": {
 33977            "attachment": {}
 33978          },
 33979          "pedigree": {},
 33980          "evidence": {},
 33981          "signature": {
 33982            "signature": {
 33983              "publicKey": {}
 33984            }
 33985          },
 33986          "modelCard": {
 33987            "modelParameters": {
 33988              "approach": {}
 33989            },
 33990            "quantitativeAnalysis": {
 33991              "graphics": {}
 33992            },
 33993            "considerations": {}
 33994          }
 33995        },
 33996        {
 33997          "type": "library",
 33998          "bom-ref": "pkg:pypi/configobj@5.0.6?package-id=386eb39d2a9f5cad",
 33999          "supplier": {},
 34000          "author": "Rob Dennis, Eli Courtwright (Michael Foord \u0026 Nicola Larosa original maintainers) \u003crdennis+configobj@gmail.com, eli@courtwright.org, fuzzyman@voidspace.co.uk, nico@tekNico.net\u003e",
 34001          "name": "configobj",
 34002          "version": "5.0.6",
 34003          "licenses": [
 34004            {
 34005              "license": {
 34006                "name": "UNKNOWN"
 34007              }
 34008            }
 34009          ],
 34010          "cpe": "cpe:2.3:a:rob_dennis\\,_eli_courtwright_\\(michael_foord_\\\u0026_nicola_larosa_original_maintainers\\)_project:python-configobj:5.0.6:*:*:*:*:*:*:*",
 34011          "purl": "pkg:pypi/configobj@5.0.6",
 34012          "swid": {
 34013            "attachment": {}
 34014          },
 34015          "pedigree": {},
 34016          "evidence": {},
 34017          "signature": {
 34018            "signature": {
 34019              "publicKey": {}
 34020            }
 34021          },
 34022          "modelCard": {
 34023            "modelParameters": {
 34024              "approach": {}
 34025            },
 34026            "quantitativeAnalysis": {
 34027              "graphics": {}
 34028            },
 34029            "considerations": {}
 34030          }
 34031        },
 34032        {
 34033          "type": "library",
 34034          "bom-ref": "pkg:deb/debian/coreutils@8.23-4?arch=amd64\u0026distro=debian-8\u0026package-id=8d3d72c1af50a311",
 34035          "supplier": {},
 34036          "publisher": "Michael Stone \u003cmstone@debian.org\u003e",
 34037          "name": "coreutils",
 34038          "version": "8.23-4",
 34039          "licenses": [
 34040            {
 34041              "license": {
 34042                "id": "GPL-3.0-only"
 34043              }
 34044            }
 34045          ],
 34046          "cpe": "cpe:2.3:a:coreutils:coreutils:8.23-4:*:*:*:*:*:*:*",
 34047          "purl": "pkg:deb/debian/coreutils@8.23-4?arch=amd64\u0026distro=debian-8",
 34048          "swid": {
 34049            "attachment": {}
 34050          },
 34051          "pedigree": {},
 34052          "evidence": {},
 34053          "signature": {
 34054            "signature": {
 34055              "publicKey": {}
 34056            }
 34057          },
 34058          "modelCard": {
 34059            "modelParameters": {
 34060              "approach": {}
 34061            },
 34062            "quantitativeAnalysis": {
 34063              "graphics": {}
 34064            },
 34065            "considerations": {}
 34066          }
 34067        },
 34068        {
 34069          "type": "library",
 34070          "bom-ref": "pkg:deb/debian/cpp@4:4.9.2-2?arch=amd64\u0026upstream=gcc-defaults%401.136\u0026distro=debian-8\u0026package-id=cefe624c8fd55b6",
 34071          "supplier": {},
 34072          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 34073          "name": "cpp",
 34074          "version": "4:4.9.2-2",
 34075          "licenses": [
 34076            {
 34077              "license": {
 34078                "name": "GPL"
 34079              }
 34080            }
 34081          ],
 34082          "cpe": "cpe:2.3:a:cpp:cpp:4\\:4.9.2-2:*:*:*:*:*:*:*",
 34083          "purl": "pkg:deb/debian/cpp@4:4.9.2-2?arch=amd64\u0026upstream=gcc-defaults%401.136\u0026distro=debian-8",
 34084          "swid": {
 34085            "attachment": {}
 34086          },
 34087          "pedigree": {},
 34088          "evidence": {},
 34089          "signature": {
 34090            "signature": {
 34091              "publicKey": {}
 34092            }
 34093          },
 34094          "modelCard": {
 34095            "modelParameters": {
 34096              "approach": {}
 34097            },
 34098            "quantitativeAnalysis": {
 34099              "graphics": {}
 34100            },
 34101            "considerations": {}
 34102          }
 34103        },
 34104        {
 34105          "type": "library",
 34106          "bom-ref": "pkg:deb/debian/cpp-4.9@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=8c116edc1de3a76e",
 34107          "supplier": {},
 34108          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 34109          "name": "cpp-4.9",
 34110          "version": "4.9.2-10",
 34111          "licenses": [
 34112            {
 34113              "license": {
 34114                "name": "Artistic"
 34115              }
 34116            },
 34117            {
 34118              "license": {
 34119                "id": "GFDL-1.2-only"
 34120              }
 34121            },
 34122            {
 34123              "license": {
 34124                "name": "GPL"
 34125              }
 34126            },
 34127            {
 34128              "license": {
 34129                "id": "GPL-2.0-only"
 34130              }
 34131            },
 34132            {
 34133              "license": {
 34134                "id": "GPL-3.0-only"
 34135              }
 34136            }
 34137          ],
 34138          "cpe": "cpe:2.3:a:cpp-4.9:cpp-4.9:4.9.2-10:*:*:*:*:*:*:*",
 34139          "purl": "pkg:deb/debian/cpp-4.9@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 34140          "swid": {
 34141            "attachment": {}
 34142          },
 34143          "pedigree": {},
 34144          "evidence": {},
 34145          "signature": {
 34146            "signature": {
 34147              "publicKey": {}
 34148            }
 34149          },
 34150          "modelCard": {
 34151            "modelParameters": {
 34152              "approach": {}
 34153            },
 34154            "quantitativeAnalysis": {
 34155              "graphics": {}
 34156            },
 34157            "considerations": {}
 34158          }
 34159        },
 34160        {
 34161          "type": "library",
 34162          "bom-ref": "pkg:deb/debian/curl@7.38.0-4+deb8u4?arch=amd64\u0026distro=debian-8\u0026package-id=39884f55094902ce",
 34163          "supplier": {},
 34164          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
 34165          "name": "curl",
 34166          "version": "7.38.0-4+deb8u4",
 34167          "licenses": [
 34168            {
 34169              "license": {
 34170                "id": "BSD-3-Clause"
 34171              }
 34172            },
 34173            {
 34174              "license": {
 34175                "id": "BSD-4-Clause"
 34176              }
 34177            },
 34178            {
 34179              "license": {
 34180                "id": "ISC"
 34181              }
 34182            },
 34183            {
 34184              "license": {
 34185                "id": "curl"
 34186              }
 34187            }
 34188          ],
 34189          "cpe": "cpe:2.3:a:curl:curl:7.38.0-4\\+deb8u4:*:*:*:*:*:*:*",
 34190          "purl": "pkg:deb/debian/curl@7.38.0-4+deb8u4?arch=amd64\u0026distro=debian-8",
 34191          "swid": {
 34192            "attachment": {}
 34193          },
 34194          "pedigree": {},
 34195          "evidence": {},
 34196          "signature": {
 34197            "signature": {
 34198              "publicKey": {}
 34199            }
 34200          },
 34201          "modelCard": {
 34202            "modelParameters": {
 34203              "approach": {}
 34204            },
 34205            "quantitativeAnalysis": {
 34206              "graphics": {}
 34207            },
 34208            "considerations": {}
 34209          }
 34210        },
 34211        {
 34212          "type": "library",
 34213          "bom-ref": "pkg:deb/debian/dash@0.5.7-4+b1?arch=amd64\u0026upstream=dash%400.5.7-4\u0026distro=debian-8\u0026package-id=9ff0e0bb5844af2a",
 34214          "supplier": {},
 34215          "publisher": "Gerrit Pape \u003cpape@smarden.org\u003e",
 34216          "name": "dash",
 34217          "version": "0.5.7-4+b1",
 34218          "licenses": [
 34219            {
 34220              "license": {
 34221                "name": "GPL"
 34222              }
 34223            }
 34224          ],
 34225          "cpe": "cpe:2.3:a:dash:dash:0.5.7-4\\+b1:*:*:*:*:*:*:*",
 34226          "purl": "pkg:deb/debian/dash@0.5.7-4+b1?arch=amd64\u0026upstream=dash%400.5.7-4\u0026distro=debian-8",
 34227          "swid": {
 34228            "attachment": {}
 34229          },
 34230          "pedigree": {},
 34231          "evidence": {},
 34232          "signature": {
 34233            "signature": {
 34234              "publicKey": {}
 34235            }
 34236          },
 34237          "modelCard": {
 34238            "modelParameters": {
 34239              "approach": {}
 34240            },
 34241            "quantitativeAnalysis": {
 34242              "graphics": {}
 34243            },
 34244            "considerations": {}
 34245          }
 34246        },
 34247        {
 34248          "type": "library",
 34249          "bom-ref": "pkg:deb/debian/debconf@1.5.56?arch=all\u0026distro=debian-8\u0026package-id=3585338e532b8fe6",
 34250          "supplier": {},
 34251          "publisher": "Debconf Developers \u003cdebconf-devel@lists.alioth.debian.org\u003e",
 34252          "name": "debconf",
 34253          "version": "1.5.56",
 34254          "licenses": [
 34255            {
 34256              "license": {
 34257                "id": "BSD-2-Clause"
 34258              }
 34259            }
 34260          ],
 34261          "cpe": "cpe:2.3:a:debconf:debconf:1.5.56:*:*:*:*:*:*:*",
 34262          "purl": "pkg:deb/debian/debconf@1.5.56?arch=all\u0026distro=debian-8",
 34263          "swid": {
 34264            "attachment": {}
 34265          },
 34266          "pedigree": {},
 34267          "evidence": {},
 34268          "signature": {
 34269            "signature": {
 34270              "publicKey": {}
 34271            }
 34272          },
 34273          "modelCard": {
 34274            "modelParameters": {
 34275              "approach": {}
 34276            },
 34277            "quantitativeAnalysis": {
 34278              "graphics": {}
 34279            },
 34280            "considerations": {}
 34281          }
 34282        },
 34283        {
 34284          "type": "library",
 34285          "bom-ref": "pkg:deb/debian/debconf-i18n@1.5.56?arch=all\u0026upstream=debconf\u0026distro=debian-8\u0026package-id=fe5e34fadb11162",
 34286          "supplier": {},
 34287          "publisher": "Debconf Developers \u003cdebconf-devel@lists.alioth.debian.org\u003e",
 34288          "name": "debconf-i18n",
 34289          "version": "1.5.56",
 34290          "licenses": [
 34291            {
 34292              "license": {
 34293                "id": "BSD-2-Clause"
 34294              }
 34295            }
 34296          ],
 34297          "cpe": "cpe:2.3:a:debconf-i18n:debconf-i18n:1.5.56:*:*:*:*:*:*:*",
 34298          "purl": "pkg:deb/debian/debconf-i18n@1.5.56?arch=all\u0026upstream=debconf\u0026distro=debian-8",
 34299          "swid": {
 34300            "attachment": {}
 34301          },
 34302          "pedigree": {},
 34303          "evidence": {},
 34304          "signature": {
 34305            "signature": {
 34306              "publicKey": {}
 34307            }
 34308          },
 34309          "modelCard": {
 34310            "modelParameters": {
 34311              "approach": {}
 34312            },
 34313            "quantitativeAnalysis": {
 34314              "graphics": {}
 34315            },
 34316            "considerations": {}
 34317          }
 34318        },
 34319        {
 34320          "type": "library",
 34321          "bom-ref": "pkg:deb/debian/debian-archive-keyring@2014.3?arch=all\u0026distro=debian-8\u0026package-id=bb4ac327b23ce735",
 34322          "supplier": {},
 34323          "publisher": "Debian Release Team \u003cpackages@release.debian.org\u003e",
 34324          "name": "debian-archive-keyring",
 34325          "version": "2014.3",
 34326          "licenses": [
 34327            {
 34328              "license": {
 34329                "name": "GPL"
 34330              }
 34331            }
 34332          ],
 34333          "cpe": "cpe:2.3:a:debian-archive-keyring:debian-archive-keyring:2014.3:*:*:*:*:*:*:*",
 34334          "purl": "pkg:deb/debian/debian-archive-keyring@2014.3?arch=all\u0026distro=debian-8",
 34335          "swid": {
 34336            "attachment": {}
 34337          },
 34338          "pedigree": {},
 34339          "evidence": {},
 34340          "signature": {
 34341            "signature": {
 34342              "publicKey": {}
 34343            }
 34344          },
 34345          "modelCard": {
 34346            "modelParameters": {
 34347              "approach": {}
 34348            },
 34349            "quantitativeAnalysis": {
 34350              "graphics": {}
 34351            },
 34352            "considerations": {}
 34353          }
 34354        },
 34355        {
 34356          "type": "library",
 34357          "bom-ref": "pkg:deb/debian/debianutils@4.4+b1?arch=amd64\u0026upstream=debianutils%404.4\u0026distro=debian-8\u0026package-id=a719b1d74729e3ad",
 34358          "supplier": {},
 34359          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
 34360          "name": "debianutils",
 34361          "version": "4.4+b1",
 34362          "licenses": [
 34363            {
 34364              "license": {
 34365                "name": "GPL"
 34366              }
 34367            }
 34368          ],
 34369          "cpe": "cpe:2.3:a:debianutils:debianutils:4.4\\+b1:*:*:*:*:*:*:*",
 34370          "purl": "pkg:deb/debian/debianutils@4.4+b1?arch=amd64\u0026upstream=debianutils%404.4\u0026distro=debian-8",
 34371          "swid": {
 34372            "attachment": {}
 34373          },
 34374          "pedigree": {},
 34375          "evidence": {},
 34376          "signature": {
 34377            "signature": {
 34378              "publicKey": {}
 34379            }
 34380          },
 34381          "modelCard": {
 34382            "modelParameters": {
 34383              "approach": {}
 34384            },
 34385            "quantitativeAnalysis": {
 34386              "graphics": {}
 34387            },
 34388            "considerations": {}
 34389          }
 34390        },
 34391        {
 34392          "type": "library",
 34393          "bom-ref": "pkg:deb/debian/diffutils@1:3.3-1+b1?arch=amd64\u0026upstream=diffutils%401:3.3-1\u0026distro=debian-8\u0026package-id=2b73dd6dddcdeeed",
 34394          "supplier": {},
 34395          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
 34396          "name": "diffutils",
 34397          "version": "1:3.3-1+b1",
 34398          "licenses": [
 34399            {
 34400              "license": {
 34401                "name": "GFDL"
 34402              }
 34403            },
 34404            {
 34405              "license": {
 34406                "name": "GPL"
 34407              }
 34408            }
 34409          ],
 34410          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.3-1\\+b1:*:*:*:*:*:*:*",
 34411          "purl": "pkg:deb/debian/diffutils@1:3.3-1+b1?arch=amd64\u0026upstream=diffutils%401:3.3-1\u0026distro=debian-8",
 34412          "swid": {
 34413            "attachment": {}
 34414          },
 34415          "pedigree": {},
 34416          "evidence": {},
 34417          "signature": {
 34418            "signature": {
 34419              "publicKey": {}
 34420            }
 34421          },
 34422          "modelCard": {
 34423            "modelParameters": {
 34424              "approach": {}
 34425            },
 34426            "quantitativeAnalysis": {
 34427              "graphics": {}
 34428            },
 34429            "considerations": {}
 34430          }
 34431        },
 34432        {
 34433          "type": "library",
 34434          "bom-ref": "pkg:deb/debian/dmsetup@2:1.02.90-2.2+deb8u1?arch=amd64\u0026upstream=lvm2%402.02.111-2.2+deb8u1\u0026distro=debian-8\u0026package-id=20467f05b72fcf1e",
 34435          "supplier": {},
 34436          "publisher": "Debian LVM Team \u003cpkg-lvm-maintainers@lists.alioth.debian.org\u003e",
 34437          "name": "dmsetup",
 34438          "version": "2:1.02.90-2.2+deb8u1",
 34439          "licenses": [
 34440            {
 34441              "license": {
 34442                "id": "GPL-2.0-only"
 34443              }
 34444            },
 34445            {
 34446              "license": {
 34447                "id": "LGPL-2.1-only"
 34448              }
 34449            }
 34450          ],
 34451          "cpe": "cpe:2.3:a:dmsetup:dmsetup:2\\:1.02.90-2.2\\+deb8u1:*:*:*:*:*:*:*",
 34452          "purl": "pkg:deb/debian/dmsetup@2:1.02.90-2.2+deb8u1?arch=amd64\u0026upstream=lvm2%402.02.111-2.2+deb8u1\u0026distro=debian-8",
 34453          "swid": {
 34454            "attachment": {}
 34455          },
 34456          "pedigree": {},
 34457          "evidence": {},
 34458          "signature": {
 34459            "signature": {
 34460              "publicKey": {}
 34461            }
 34462          },
 34463          "modelCard": {
 34464            "modelParameters": {
 34465              "approach": {}
 34466            },
 34467            "quantitativeAnalysis": {
 34468              "graphics": {}
 34469            },
 34470            "considerations": {}
 34471          }
 34472        },
 34473        {
 34474          "type": "library",
 34475          "bom-ref": "pkg:deb/debian/dpkg@1.17.27?arch=amd64\u0026distro=debian-8\u0026package-id=dc03982c39f35b01",
 34476          "supplier": {},
 34477          "publisher": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e",
 34478          "name": "dpkg",
 34479          "version": "1.17.27",
 34480          "licenses": [
 34481            {
 34482              "license": {
 34483                "id": "BSD-2-Clause"
 34484              }
 34485            },
 34486            {
 34487              "license": {
 34488                "id": "GPL-2.0-only"
 34489              }
 34490            },
 34491            {
 34492              "license": {
 34493                "id": "GPL-2.0-or-later"
 34494              }
 34495            },
 34496            {
 34497              "license": {
 34498                "name": "public-domain"
 34499              }
 34500            }
 34501          ],
 34502          "cpe": "cpe:2.3:a:dpkg:dpkg:1.17.27:*:*:*:*:*:*:*",
 34503          "purl": "pkg:deb/debian/dpkg@1.17.27?arch=amd64\u0026distro=debian-8",
 34504          "swid": {
 34505            "attachment": {}
 34506          },
 34507          "pedigree": {},
 34508          "evidence": {},
 34509          "signature": {
 34510            "signature": {
 34511              "publicKey": {}
 34512            }
 34513          },
 34514          "modelCard": {
 34515            "modelParameters": {
 34516              "approach": {}
 34517            },
 34518            "quantitativeAnalysis": {
 34519              "graphics": {}
 34520            },
 34521            "considerations": {}
 34522          }
 34523        },
 34524        {
 34525          "type": "library",
 34526          "bom-ref": "pkg:deb/debian/e2fslibs@1.42.12-1.1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-8\u0026package-id=20fb2569b8ab55d6",
 34527          "supplier": {},
 34528          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 34529          "name": "e2fslibs",
 34530          "version": "1.42.12-1.1",
 34531          "licenses": [
 34532            {
 34533              "license": {
 34534                "id": "GPL-2.0-only"
 34535              }
 34536            },
 34537            {
 34538              "license": {
 34539                "id": "LGPL-2.0-only"
 34540              }
 34541            }
 34542          ],
 34543          "cpe": "cpe:2.3:a:e2fslibs:e2fslibs:1.42.12-1.1:*:*:*:*:*:*:*",
 34544          "purl": "pkg:deb/debian/e2fslibs@1.42.12-1.1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-8",
 34545          "swid": {
 34546            "attachment": {}
 34547          },
 34548          "pedigree": {},
 34549          "evidence": {},
 34550          "signature": {
 34551            "signature": {
 34552              "publicKey": {}
 34553            }
 34554          },
 34555          "modelCard": {
 34556            "modelParameters": {
 34557              "approach": {}
 34558            },
 34559            "quantitativeAnalysis": {
 34560              "graphics": {}
 34561            },
 34562            "considerations": {}
 34563          }
 34564        },
 34565        {
 34566          "type": "library",
 34567          "bom-ref": "pkg:deb/debian/e2fsprogs@1.42.12-1.1?arch=amd64\u0026distro=debian-8\u0026package-id=deca0c6d1db4190e",
 34568          "supplier": {},
 34569          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 34570          "name": "e2fsprogs",
 34571          "version": "1.42.12-1.1",
 34572          "licenses": [
 34573            {
 34574              "license": {
 34575                "id": "GPL-2.0-only"
 34576              }
 34577            },
 34578            {
 34579              "license": {
 34580                "id": "LGPL-2.0-only"
 34581              }
 34582            }
 34583          ],
 34584          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.42.12-1.1:*:*:*:*:*:*:*",
 34585          "purl": "pkg:deb/debian/e2fsprogs@1.42.12-1.1?arch=amd64\u0026distro=debian-8",
 34586          "swid": {
 34587            "attachment": {}
 34588          },
 34589          "pedigree": {},
 34590          "evidence": {},
 34591          "signature": {
 34592            "signature": {
 34593              "publicKey": {}
 34594            }
 34595          },
 34596          "modelCard": {
 34597            "modelParameters": {
 34598              "approach": {}
 34599            },
 34600            "quantitativeAnalysis": {
 34601              "graphics": {}
 34602            },
 34603            "considerations": {}
 34604          }
 34605        },
 34606        {
 34607          "type": "library",
 34608          "bom-ref": "pkg:deb/debian/findutils@4.4.2-9+b1?arch=amd64\u0026upstream=findutils%404.4.2-9\u0026distro=debian-8\u0026package-id=5e34afa4b431f97",
 34609          "supplier": {},
 34610          "publisher": "Andreas Metzler \u003cametzler@debian.org\u003e",
 34611          "name": "findutils",
 34612          "version": "4.4.2-9+b1",
 34613          "licenses": [
 34614            {
 34615              "license": {
 34616                "id": "GFDL-1.2-only"
 34617              }
 34618            },
 34619            {
 34620              "license": {
 34621                "name": "GPL"
 34622              }
 34623            }
 34624          ],
 34625          "cpe": "cpe:2.3:a:findutils:findutils:4.4.2-9\\+b1:*:*:*:*:*:*:*",
 34626          "purl": "pkg:deb/debian/findutils@4.4.2-9+b1?arch=amd64\u0026upstream=findutils%404.4.2-9\u0026distro=debian-8",
 34627          "swid": {
 34628            "attachment": {}
 34629          },
 34630          "pedigree": {},
 34631          "evidence": {},
 34632          "signature": {
 34633            "signature": {
 34634              "publicKey": {}
 34635            }
 34636          },
 34637          "modelCard": {
 34638            "modelParameters": {
 34639              "approach": {}
 34640            },
 34641            "quantitativeAnalysis": {
 34642              "graphics": {}
 34643            },
 34644            "considerations": {}
 34645          }
 34646        },
 34647        {
 34648          "type": "library",
 34649          "bom-ref": "pkg:deb/debian/g++@4:4.9.2-2?arch=amd64\u0026upstream=gcc-defaults%401.136\u0026distro=debian-8\u0026package-id=ea0e4cb7aa9bd919",
 34650          "supplier": {},
 34651          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 34652          "name": "g++",
 34653          "version": "4:4.9.2-2",
 34654          "licenses": [
 34655            {
 34656              "license": {
 34657                "name": "GPL"
 34658              }
 34659            }
 34660          ],
 34661          "cpe": "cpe:2.3:a:g\\+\\+:g\\+\\+:4\\:4.9.2-2:*:*:*:*:*:*:*",
 34662          "purl": "pkg:deb/debian/g++@4:4.9.2-2?arch=amd64\u0026upstream=gcc-defaults%401.136\u0026distro=debian-8",
 34663          "swid": {
 34664            "attachment": {}
 34665          },
 34666          "pedigree": {},
 34667          "evidence": {},
 34668          "signature": {
 34669            "signature": {
 34670              "publicKey": {}
 34671            }
 34672          },
 34673          "modelCard": {
 34674            "modelParameters": {
 34675              "approach": {}
 34676            },
 34677            "quantitativeAnalysis": {
 34678              "graphics": {}
 34679            },
 34680            "considerations": {}
 34681          }
 34682        },
 34683        {
 34684          "type": "library",
 34685          "bom-ref": "pkg:deb/debian/g++-4.9@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=852fc8585264b110",
 34686          "supplier": {},
 34687          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 34688          "name": "g++-4.9",
 34689          "version": "4.9.2-10",
 34690          "licenses": [
 34691            {
 34692              "license": {
 34693                "name": "Artistic"
 34694              }
 34695            },
 34696            {
 34697              "license": {
 34698                "id": "GFDL-1.2-only"
 34699              }
 34700            },
 34701            {
 34702              "license": {
 34703                "name": "GPL"
 34704              }
 34705            },
 34706            {
 34707              "license": {
 34708                "id": "GPL-2.0-only"
 34709              }
 34710            },
 34711            {
 34712              "license": {
 34713                "id": "GPL-3.0-only"
 34714              }
 34715            }
 34716          ],
 34717          "cpe": "cpe:2.3:a:g\\+\\+-4.9:g\\+\\+-4.9:4.9.2-10:*:*:*:*:*:*:*",
 34718          "purl": "pkg:deb/debian/g++-4.9@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 34719          "swid": {
 34720            "attachment": {}
 34721          },
 34722          "pedigree": {},
 34723          "evidence": {},
 34724          "signature": {
 34725            "signature": {
 34726              "publicKey": {}
 34727            }
 34728          },
 34729          "modelCard": {
 34730            "modelParameters": {
 34731              "approach": {}
 34732            },
 34733            "quantitativeAnalysis": {
 34734              "graphics": {}
 34735            },
 34736            "considerations": {}
 34737          }
 34738        },
 34739        {
 34740          "type": "library",
 34741          "bom-ref": "pkg:deb/debian/gcc@4:4.9.2-2?arch=amd64\u0026upstream=gcc-defaults%401.136\u0026distro=debian-8\u0026package-id=a4b383d94a6da678",
 34742          "supplier": {},
 34743          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 34744          "name": "gcc",
 34745          "version": "4:4.9.2-2",
 34746          "licenses": [
 34747            {
 34748              "license": {
 34749                "name": "GPL"
 34750              }
 34751            }
 34752          ],
 34753          "cpe": "cpe:2.3:a:gcc:gcc:4\\:4.9.2-2:*:*:*:*:*:*:*",
 34754          "purl": "pkg:deb/debian/gcc@4:4.9.2-2?arch=amd64\u0026upstream=gcc-defaults%401.136\u0026distro=debian-8",
 34755          "swid": {
 34756            "attachment": {}
 34757          },
 34758          "pedigree": {},
 34759          "evidence": {},
 34760          "signature": {
 34761            "signature": {
 34762              "publicKey": {}
 34763            }
 34764          },
 34765          "modelCard": {
 34766            "modelParameters": {
 34767              "approach": {}
 34768            },
 34769            "quantitativeAnalysis": {
 34770              "graphics": {}
 34771            },
 34772            "considerations": {}
 34773          }
 34774        },
 34775        {
 34776          "type": "library",
 34777          "bom-ref": "pkg:deb/debian/gcc-4.8-base@4.8.4-1?arch=amd64\u0026upstream=gcc-4.8\u0026distro=debian-8\u0026package-id=f2b1db8d41186097",
 34778          "supplier": {},
 34779          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 34780          "name": "gcc-4.8-base",
 34781          "version": "4.8.4-1",
 34782          "licenses": [
 34783            {
 34784              "license": {
 34785                "name": "Artistic"
 34786              }
 34787            },
 34788            {
 34789              "license": {
 34790                "id": "GFDL-1.2-only"
 34791              }
 34792            },
 34793            {
 34794              "license": {
 34795                "name": "GPL"
 34796              }
 34797            },
 34798            {
 34799              "license": {
 34800                "id": "GPL-2.0-only"
 34801              }
 34802            },
 34803            {
 34804              "license": {
 34805                "id": "GPL-3.0-only"
 34806              }
 34807            }
 34808          ],
 34809          "cpe": "cpe:2.3:a:gcc-4.8-base:gcc-4.8-base:4.8.4-1:*:*:*:*:*:*:*",
 34810          "purl": "pkg:deb/debian/gcc-4.8-base@4.8.4-1?arch=amd64\u0026upstream=gcc-4.8\u0026distro=debian-8",
 34811          "swid": {
 34812            "attachment": {}
 34813          },
 34814          "pedigree": {},
 34815          "evidence": {},
 34816          "signature": {
 34817            "signature": {
 34818              "publicKey": {}
 34819            }
 34820          },
 34821          "modelCard": {
 34822            "modelParameters": {
 34823              "approach": {}
 34824            },
 34825            "quantitativeAnalysis": {
 34826              "graphics": {}
 34827            },
 34828            "considerations": {}
 34829          }
 34830        },
 34831        {
 34832          "type": "library",
 34833          "bom-ref": "pkg:deb/debian/gcc-4.9@4.9.2-10?arch=amd64\u0026distro=debian-8\u0026package-id=c5183e7665160b81",
 34834          "supplier": {},
 34835          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 34836          "name": "gcc-4.9",
 34837          "version": "4.9.2-10",
 34838          "licenses": [
 34839            {
 34840              "license": {
 34841                "name": "Artistic"
 34842              }
 34843            },
 34844            {
 34845              "license": {
 34846                "id": "GFDL-1.2-only"
 34847              }
 34848            },
 34849            {
 34850              "license": {
 34851                "name": "GPL"
 34852              }
 34853            },
 34854            {
 34855              "license": {
 34856                "id": "GPL-2.0-only"
 34857              }
 34858            },
 34859            {
 34860              "license": {
 34861                "id": "GPL-3.0-only"
 34862              }
 34863            }
 34864          ],
 34865          "cpe": "cpe:2.3:a:gcc-4.9:gcc-4.9:4.9.2-10:*:*:*:*:*:*:*",
 34866          "purl": "pkg:deb/debian/gcc-4.9@4.9.2-10?arch=amd64\u0026distro=debian-8",
 34867          "swid": {
 34868            "attachment": {}
 34869          },
 34870          "pedigree": {},
 34871          "evidence": {},
 34872          "signature": {
 34873            "signature": {
 34874              "publicKey": {}
 34875            }
 34876          },
 34877          "modelCard": {
 34878            "modelParameters": {
 34879              "approach": {}
 34880            },
 34881            "quantitativeAnalysis": {
 34882              "graphics": {}
 34883            },
 34884            "considerations": {}
 34885          }
 34886        },
 34887        {
 34888          "type": "library",
 34889          "bom-ref": "pkg:deb/debian/gcc-4.9-base@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=6a3e9c45975292e8",
 34890          "supplier": {},
 34891          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 34892          "name": "gcc-4.9-base",
 34893          "version": "4.9.2-10",
 34894          "licenses": [
 34895            {
 34896              "license": {
 34897                "name": "Artistic"
 34898              }
 34899            },
 34900            {
 34901              "license": {
 34902                "id": "GFDL-1.2-only"
 34903              }
 34904            },
 34905            {
 34906              "license": {
 34907                "name": "GPL"
 34908              }
 34909            },
 34910            {
 34911              "license": {
 34912                "id": "GPL-2.0-only"
 34913              }
 34914            },
 34915            {
 34916              "license": {
 34917                "id": "GPL-3.0-only"
 34918              }
 34919            }
 34920          ],
 34921          "cpe": "cpe:2.3:a:gcc-4.9-base:gcc-4.9-base:4.9.2-10:*:*:*:*:*:*:*",
 34922          "purl": "pkg:deb/debian/gcc-4.9-base@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 34923          "swid": {
 34924            "attachment": {}
 34925          },
 34926          "pedigree": {},
 34927          "evidence": {},
 34928          "signature": {
 34929            "signature": {
 34930              "publicKey": {}
 34931            }
 34932          },
 34933          "modelCard": {
 34934            "modelParameters": {
 34935              "approach": {}
 34936            },
 34937            "quantitativeAnalysis": {
 34938              "graphics": {}
 34939            },
 34940            "considerations": {}
 34941          }
 34942        },
 34943        {
 34944          "type": "library",
 34945          "bom-ref": "pkg:deb/debian/git@1:2.1.4-2.1+deb8u2?arch=amd64\u0026distro=debian-8\u0026package-id=333d6c65f03bf613",
 34946          "supplier": {},
 34947          "publisher": "Gerrit Pape \u003cpape@smarden.org\u003e",
 34948          "name": "git",
 34949          "version": "1:2.1.4-2.1+deb8u2",
 34950          "licenses": [
 34951            {
 34952              "license": {
 34953                "id": "Apache-2.0"
 34954              }
 34955            },
 34956            {
 34957              "license": {
 34958                "name": "Artistic"
 34959              }
 34960            },
 34961            {
 34962              "license": {
 34963                "id": "BSD-2-Clause"
 34964              }
 34965            },
 34966            {
 34967              "license": {
 34968                "name": "Boost"
 34969              }
 34970            },
 34971            {
 34972              "license": {
 34973                "name": "EDL-1.0"
 34974              }
 34975            },
 34976            {
 34977              "license": {
 34978                "name": "Expat"
 34979              }
 34980            },
 34981            {
 34982              "license": {
 34983                "name": "GPL"
 34984              }
 34985            },
 34986            {
 34987              "license": {
 34988                "id": "GPL-1.0-or-later"
 34989              }
 34990            },
 34991            {
 34992              "license": {
 34993                "id": "GPL-2.0-only"
 34994              }
 34995            },
 34996            {
 34997              "license": {
 34998                "id": "GPL-2.0-or-later"
 34999              }
 35000            },
 35001            {
 35002              "license": {
 35003                "id": "ISC"
 35004              }
 35005            },
 35006            {
 35007              "license": {
 35008                "id": "LGPL-2.0-only"
 35009              }
 35010            },
 35011            {
 35012              "license": {
 35013                "id": "LGPL-2.0-or-later"
 35014              }
 35015            },
 35016            {
 35017              "license": {
 35018                "id": "LGPL-2.1-only"
 35019              }
 35020            },
 35021            {
 35022              "license": {
 35023                "id": "LGPL-2.1-or-later"
 35024              }
 35025            },
 35026            {
 35027              "license": {
 35028                "name": "dlmalloc"
 35029              }
 35030            },
 35031            {
 35032              "license": {
 35033                "name": "mingw-runtime"
 35034              }
 35035            }
 35036          ],
 35037          "cpe": "cpe:2.3:a:git:git:1\\:2.1.4-2.1\\+deb8u2:*:*:*:*:*:*:*",
 35038          "purl": "pkg:deb/debian/git@1:2.1.4-2.1+deb8u2?arch=amd64\u0026distro=debian-8",
 35039          "swid": {
 35040            "attachment": {}
 35041          },
 35042          "pedigree": {},
 35043          "evidence": {},
 35044          "signature": {
 35045            "signature": {
 35046              "publicKey": {}
 35047            }
 35048          },
 35049          "modelCard": {
 35050            "modelParameters": {
 35051              "approach": {}
 35052            },
 35053            "quantitativeAnalysis": {
 35054              "graphics": {}
 35055            },
 35056            "considerations": {}
 35057          }
 35058        },
 35059        {
 35060          "type": "library",
 35061          "bom-ref": "pkg:deb/debian/git-man@1:2.1.4-2.1+deb8u2?arch=all\u0026upstream=git\u0026distro=debian-8\u0026package-id=1a5d8f9e88723503",
 35062          "supplier": {},
 35063          "publisher": "Gerrit Pape \u003cpape@smarden.org\u003e",
 35064          "name": "git-man",
 35065          "version": "1:2.1.4-2.1+deb8u2",
 35066          "licenses": [
 35067            {
 35068              "license": {
 35069                "id": "Apache-2.0"
 35070              }
 35071            },
 35072            {
 35073              "license": {
 35074                "name": "Artistic"
 35075              }
 35076            },
 35077            {
 35078              "license": {
 35079                "id": "BSD-2-Clause"
 35080              }
 35081            },
 35082            {
 35083              "license": {
 35084                "name": "Boost"
 35085              }
 35086            },
 35087            {
 35088              "license": {
 35089                "name": "EDL-1.0"
 35090              }
 35091            },
 35092            {
 35093              "license": {
 35094                "name": "Expat"
 35095              }
 35096            },
 35097            {
 35098              "license": {
 35099                "name": "GPL"
 35100              }
 35101            },
 35102            {
 35103              "license": {
 35104                "id": "GPL-1.0-or-later"
 35105              }
 35106            },
 35107            {
 35108              "license": {
 35109                "id": "GPL-2.0-only"
 35110              }
 35111            },
 35112            {
 35113              "license": {
 35114                "id": "GPL-2.0-or-later"
 35115              }
 35116            },
 35117            {
 35118              "license": {
 35119                "id": "ISC"
 35120              }
 35121            },
 35122            {
 35123              "license": {
 35124                "id": "LGPL-2.0-only"
 35125              }
 35126            },
 35127            {
 35128              "license": {
 35129                "id": "LGPL-2.0-or-later"
 35130              }
 35131            },
 35132            {
 35133              "license": {
 35134                "id": "LGPL-2.1-only"
 35135              }
 35136            },
 35137            {
 35138              "license": {
 35139                "id": "LGPL-2.1-or-later"
 35140              }
 35141            },
 35142            {
 35143              "license": {
 35144                "name": "dlmalloc"
 35145              }
 35146            },
 35147            {
 35148              "license": {
 35149                "name": "mingw-runtime"
 35150              }
 35151            }
 35152          ],
 35153          "cpe": "cpe:2.3:a:git-man:git-man:1\\:2.1.4-2.1\\+deb8u2:*:*:*:*:*:*:*",
 35154          "purl": "pkg:deb/debian/git-man@1:2.1.4-2.1+deb8u2?arch=all\u0026upstream=git\u0026distro=debian-8",
 35155          "swid": {
 35156            "attachment": {}
 35157          },
 35158          "pedigree": {},
 35159          "evidence": {},
 35160          "signature": {
 35161            "signature": {
 35162              "publicKey": {}
 35163            }
 35164          },
 35165          "modelCard": {
 35166            "modelParameters": {
 35167              "approach": {}
 35168            },
 35169            "quantitativeAnalysis": {
 35170              "graphics": {}
 35171            },
 35172            "considerations": {}
 35173          }
 35174        },
 35175        {
 35176          "type": "library",
 35177          "bom-ref": "pkg:deb/debian/gnupg@1.4.18-7+deb8u2?arch=amd64\u0026distro=debian-8\u0026package-id=4e5cbcd00d54f90b",
 35178          "supplier": {},
 35179          "publisher": "Debian GnuPG-Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
 35180          "name": "gnupg",
 35181          "version": "1.4.18-7+deb8u2",
 35182          "licenses": [
 35183            {
 35184              "license": {
 35185                "id": "GPL-3.0-only"
 35186              }
 35187            },
 35188            {
 35189              "license": {
 35190                "id": "GPL-3.0-or-later"
 35191              }
 35192            },
 35193            {
 35194              "license": {
 35195                "name": "RFC-Reference"
 35196              }
 35197            }
 35198          ],
 35199          "cpe": "cpe:2.3:a:gnupg:gnupg:1.4.18-7\\+deb8u2:*:*:*:*:*:*:*",
 35200          "purl": "pkg:deb/debian/gnupg@1.4.18-7+deb8u2?arch=amd64\u0026distro=debian-8",
 35201          "swid": {
 35202            "attachment": {}
 35203          },
 35204          "pedigree": {},
 35205          "evidence": {},
 35206          "signature": {
 35207            "signature": {
 35208              "publicKey": {}
 35209            }
 35210          },
 35211          "modelCard": {
 35212            "modelParameters": {
 35213              "approach": {}
 35214            },
 35215            "quantitativeAnalysis": {
 35216              "graphics": {}
 35217            },
 35218            "considerations": {}
 35219          }
 35220        },
 35221        {
 35222          "type": "application",
 35223          "bom-ref": "pkg:generic/go@1.1?package-id=a04282ab6323a758",
 35224          "supplier": {},
 35225          "name": "go",
 35226          "version": "1.1",
 35227          "cpe": "cpe:2.3:a:golang:go:1.1:*:*:*:*:*:*:*",
 35228          "purl": "pkg:generic/go@1.1",
 35229          "swid": {
 35230            "attachment": {}
 35231          },
 35232          "pedigree": {},
 35233          "evidence": {},
 35234          "signature": {
 35235            "signature": {
 35236              "publicKey": {}
 35237            }
 35238          },
 35239          "modelCard": {
 35240            "modelParameters": {
 35241              "approach": {}
 35242            },
 35243            "quantitativeAnalysis": {
 35244              "graphics": {}
 35245            },
 35246            "considerations": {}
 35247          }
 35248        },
 35249        {
 35250          "type": "application",
 35251          "bom-ref": "pkg:generic/go@1.6.3?package-id=2960c10965dd5680",
 35252          "supplier": {},
 35253          "name": "go",
 35254          "version": "1.6.3",
 35255          "cpe": "cpe:2.3:a:go:go:1.6.3:*:*:*:*:*:*:*",
 35256          "purl": "pkg:generic/go@1.6.3",
 35257          "swid": {
 35258            "attachment": {}
 35259          },
 35260          "pedigree": {},
 35261          "evidence": {},
 35262          "signature": {
 35263            "signature": {
 35264              "publicKey": {}
 35265            }
 35266          },
 35267          "modelCard": {
 35268            "modelParameters": {
 35269              "approach": {}
 35270            },
 35271            "quantitativeAnalysis": {
 35272              "graphics": {}
 35273            },
 35274            "considerations": {}
 35275          }
 35276        },
 35277        {
 35278          "type": "library",
 35279          "bom-ref": "pkg:deb/debian/gpgv@1.4.18-7+deb8u2?arch=amd64\u0026upstream=gnupg\u0026distro=debian-8\u0026package-id=445cbc1d3661275f",
 35280          "supplier": {},
 35281          "publisher": "Debian GnuPG-Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
 35282          "name": "gpgv",
 35283          "version": "1.4.18-7+deb8u2",
 35284          "licenses": [
 35285            {
 35286              "license": {
 35287                "id": "GPL-3.0-only"
 35288              }
 35289            },
 35290            {
 35291              "license": {
 35292                "id": "GPL-3.0-or-later"
 35293              }
 35294            },
 35295            {
 35296              "license": {
 35297                "name": "RFC-Reference"
 35298              }
 35299            }
 35300          ],
 35301          "cpe": "cpe:2.3:a:gpgv:gpgv:1.4.18-7\\+deb8u2:*:*:*:*:*:*:*",
 35302          "purl": "pkg:deb/debian/gpgv@1.4.18-7+deb8u2?arch=amd64\u0026upstream=gnupg\u0026distro=debian-8",
 35303          "swid": {
 35304            "attachment": {}
 35305          },
 35306          "pedigree": {},
 35307          "evidence": {},
 35308          "signature": {
 35309            "signature": {
 35310              "publicKey": {}
 35311            }
 35312          },
 35313          "modelCard": {
 35314            "modelParameters": {
 35315              "approach": {}
 35316            },
 35317            "quantitativeAnalysis": {
 35318              "graphics": {}
 35319            },
 35320            "considerations": {}
 35321          }
 35322        },
 35323        {
 35324          "type": "library",
 35325          "bom-ref": "pkg:deb/debian/grep@2.20-4.1?arch=amd64\u0026distro=debian-8\u0026package-id=c0ece23d390de36e",
 35326          "supplier": {},
 35327          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 35328          "name": "grep",
 35329          "version": "2.20-4.1",
 35330          "licenses": [
 35331            {
 35332              "license": {
 35333                "id": "GPL-3.0-only"
 35334              }
 35335            },
 35336            {
 35337              "license": {
 35338                "id": "GPL-3.0-or-later"
 35339              }
 35340            }
 35341          ],
 35342          "cpe": "cpe:2.3:a:grep:grep:2.20-4.1:*:*:*:*:*:*:*",
 35343          "purl": "pkg:deb/debian/grep@2.20-4.1?arch=amd64\u0026distro=debian-8",
 35344          "swid": {
 35345            "attachment": {}
 35346          },
 35347          "pedigree": {},
 35348          "evidence": {},
 35349          "signature": {
 35350            "signature": {
 35351              "publicKey": {}
 35352            }
 35353          },
 35354          "modelCard": {
 35355            "modelParameters": {
 35356              "approach": {}
 35357            },
 35358            "quantitativeAnalysis": {
 35359              "graphics": {}
 35360            },
 35361            "considerations": {}
 35362          }
 35363        },
 35364        {
 35365          "type": "library",
 35366          "bom-ref": "pkg:deb/debian/gzip@1.6-4?arch=amd64\u0026distro=debian-8\u0026package-id=13211c8254512f70",
 35367          "supplier": {},
 35368          "publisher": "Bdale Garbee \u003cbdale@gag.com\u003e",
 35369          "name": "gzip",
 35370          "version": "1.6-4",
 35371          "licenses": [
 35372            {
 35373              "license": {
 35374                "name": "GPL"
 35375              }
 35376            }
 35377          ],
 35378          "cpe": "cpe:2.3:a:gzip:gzip:1.6-4:*:*:*:*:*:*:*",
 35379          "purl": "pkg:deb/debian/gzip@1.6-4?arch=amd64\u0026distro=debian-8",
 35380          "swid": {
 35381            "attachment": {}
 35382          },
 35383          "pedigree": {},
 35384          "evidence": {},
 35385          "signature": {
 35386            "signature": {
 35387              "publicKey": {}
 35388            }
 35389          },
 35390          "modelCard": {
 35391            "modelParameters": {
 35392              "approach": {}
 35393            },
 35394            "quantitativeAnalysis": {
 35395              "graphics": {}
 35396            },
 35397            "considerations": {}
 35398          }
 35399        },
 35400        {
 35401          "type": "library",
 35402          "bom-ref": "pkg:deb/debian/hostname@3.15?arch=amd64\u0026distro=debian-8\u0026package-id=2aae92f55fe108f5",
 35403          "supplier": {},
 35404          "publisher": "Debian Hostname Team \u003chostname-devel@lists.alioth.debian.org\u003e",
 35405          "name": "hostname",
 35406          "version": "3.15",
 35407          "licenses": [
 35408            {
 35409              "license": {
 35410                "id": "GPL-2.0-only"
 35411              }
 35412            }
 35413          ],
 35414          "cpe": "cpe:2.3:a:hostname:hostname:3.15:*:*:*:*:*:*:*",
 35415          "purl": "pkg:deb/debian/hostname@3.15?arch=amd64\u0026distro=debian-8",
 35416          "swid": {
 35417            "attachment": {}
 35418          },
 35419          "pedigree": {},
 35420          "evidence": {},
 35421          "signature": {
 35422            "signature": {
 35423              "publicKey": {}
 35424            }
 35425          },
 35426          "modelCard": {
 35427            "modelParameters": {
 35428              "approach": {}
 35429            },
 35430            "quantitativeAnalysis": {
 35431              "graphics": {}
 35432            },
 35433            "considerations": {}
 35434          }
 35435        },
 35436        {
 35437          "type": "library",
 35438          "bom-ref": "pkg:deb/debian/inetutils-ping@2:1.9.2.39.3a460-3?arch=amd64\u0026upstream=inetutils\u0026distro=debian-8\u0026package-id=e26f03497109ab6e",
 35439          "supplier": {},
 35440          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
 35441          "name": "inetutils-ping",
 35442          "version": "2:1.9.2.39.3a460-3",
 35443          "licenses": [
 35444            {
 35445              "license": {
 35446                "id": "BSD-3-Clause"
 35447              }
 35448            },
 35449            {
 35450              "license": {
 35451                "id": "GFDL-1.3-only"
 35452              }
 35453            },
 35454            {
 35455              "license": {
 35456                "name": "GFDL-1.3+"
 35457              }
 35458            },
 35459            {
 35460              "license": {
 35461                "id": "GPL-3.0-only"
 35462              }
 35463            },
 35464            {
 35465              "license": {
 35466                "id": "GPL-3.0-or-later"
 35467              }
 35468            },
 35469            {
 35470              "license": {
 35471                "id": "MIT"
 35472              }
 35473            },
 35474            {
 35475              "license": {
 35476                "name": "Wietse"
 35477              }
 35478            }
 35479          ],
 35480          "cpe": "cpe:2.3:a:inetutils-ping:inetutils-ping:2\\:1.9.2.39.3a460-3:*:*:*:*:*:*:*",
 35481          "purl": "pkg:deb/debian/inetutils-ping@2:1.9.2.39.3a460-3?arch=amd64\u0026upstream=inetutils\u0026distro=debian-8",
 35482          "swid": {
 35483            "attachment": {}
 35484          },
 35485          "pedigree": {},
 35486          "evidence": {},
 35487          "signature": {
 35488            "signature": {
 35489              "publicKey": {}
 35490            }
 35491          },
 35492          "modelCard": {
 35493            "modelParameters": {
 35494              "approach": {}
 35495            },
 35496            "quantitativeAnalysis": {
 35497              "graphics": {}
 35498            },
 35499            "considerations": {}
 35500          }
 35501        },
 35502        {
 35503          "type": "library",
 35504          "bom-ref": "pkg:deb/debian/init@1.22?arch=amd64\u0026upstream=init-system-helpers\u0026distro=debian-8\u0026package-id=2a612ff33ca16cd6",
 35505          "supplier": {},
 35506          "publisher": "pkg-systemd-maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 35507          "name": "init",
 35508          "version": "1.22",
 35509          "licenses": [
 35510            {
 35511              "license": {
 35512                "name": "BSD"
 35513              }
 35514            },
 35515            {
 35516              "license": {
 35517                "name": "GPL"
 35518              }
 35519            },
 35520            {
 35521              "license": {
 35522                "id": "GPL-3.0-or-later"
 35523              }
 35524            }
 35525          ],
 35526          "cpe": "cpe:2.3:a:init:init:1.22:*:*:*:*:*:*:*",
 35527          "purl": "pkg:deb/debian/init@1.22?arch=amd64\u0026upstream=init-system-helpers\u0026distro=debian-8",
 35528          "swid": {
 35529            "attachment": {}
 35530          },
 35531          "pedigree": {},
 35532          "evidence": {},
 35533          "signature": {
 35534            "signature": {
 35535              "publicKey": {}
 35536            }
 35537          },
 35538          "modelCard": {
 35539            "modelParameters": {
 35540              "approach": {}
 35541            },
 35542            "quantitativeAnalysis": {
 35543              "graphics": {}
 35544            },
 35545            "considerations": {}
 35546          }
 35547        },
 35548        {
 35549          "type": "library",
 35550          "bom-ref": "pkg:deb/debian/initscripts@2.88dsf-59?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-8\u0026package-id=189c5a1949e5b824",
 35551          "supplier": {},
 35552          "publisher": "Debian sysvinit maintainers \u003cpkg-sysvinit-devel@lists.alioth.debian.org\u003e",
 35553          "name": "initscripts",
 35554          "version": "2.88dsf-59",
 35555          "licenses": [
 35556            {
 35557              "license": {
 35558                "id": "GPL-2.0-only"
 35559              }
 35560            }
 35561          ],
 35562          "cpe": "cpe:2.3:a:initscripts:initscripts:2.88dsf-59:*:*:*:*:*:*:*",
 35563          "purl": "pkg:deb/debian/initscripts@2.88dsf-59?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-8",
 35564          "swid": {
 35565            "attachment": {}
 35566          },
 35567          "pedigree": {},
 35568          "evidence": {},
 35569          "signature": {
 35570            "signature": {
 35571              "publicKey": {}
 35572            }
 35573          },
 35574          "modelCard": {
 35575            "modelParameters": {
 35576              "approach": {}
 35577            },
 35578            "quantitativeAnalysis": {
 35579              "graphics": {}
 35580            },
 35581            "considerations": {}
 35582          }
 35583        },
 35584        {
 35585          "type": "library",
 35586          "bom-ref": "pkg:deb/debian/insserv@1.14.0-5?arch=amd64\u0026distro=debian-8\u0026package-id=44b149076caa5906",
 35587          "supplier": {},
 35588          "publisher": "Petter Reinholdtsen \u003cpere@debian.org\u003e",
 35589          "name": "insserv",
 35590          "version": "1.14.0-5",
 35591          "licenses": [
 35592            {
 35593              "license": {
 35594                "id": "GPL-2.0-only"
 35595              }
 35596            }
 35597          ],
 35598          "cpe": "cpe:2.3:a:insserv:insserv:1.14.0-5:*:*:*:*:*:*:*",
 35599          "purl": "pkg:deb/debian/insserv@1.14.0-5?arch=amd64\u0026distro=debian-8",
 35600          "swid": {
 35601            "attachment": {}
 35602          },
 35603          "pedigree": {},
 35604          "evidence": {},
 35605          "signature": {
 35606            "signature": {
 35607              "publicKey": {}
 35608            }
 35609          },
 35610          "modelCard": {
 35611            "modelParameters": {
 35612              "approach": {}
 35613            },
 35614            "quantitativeAnalysis": {
 35615              "graphics": {}
 35616            },
 35617            "considerations": {}
 35618          }
 35619        },
 35620        {
 35621          "type": "library",
 35622          "bom-ref": "pkg:deb/debian/iproute2@3.16.0-2?arch=amd64\u0026distro=debian-8\u0026package-id=6aa9c8c5b9c1096a",
 35623          "supplier": {},
 35624          "publisher": "Debian iproute2 Maintainers \u003cah-iproute@debian.org\u003e",
 35625          "name": "iproute2",
 35626          "version": "3.16.0-2",
 35627          "licenses": [
 35628            {
 35629              "license": {
 35630                "id": "GPL-2.0-only"
 35631              }
 35632            }
 35633          ],
 35634          "cpe": "cpe:2.3:a:iproute2:iproute2:3.16.0-2:*:*:*:*:*:*:*",
 35635          "purl": "pkg:deb/debian/iproute2@3.16.0-2?arch=amd64\u0026distro=debian-8",
 35636          "swid": {
 35637            "attachment": {}
 35638          },
 35639          "pedigree": {},
 35640          "evidence": {},
 35641          "signature": {
 35642            "signature": {
 35643              "publicKey": {}
 35644            }
 35645          },
 35646          "modelCard": {
 35647            "modelParameters": {
 35648              "approach": {}
 35649            },
 35650            "quantitativeAnalysis": {
 35651              "graphics": {}
 35652            },
 35653            "considerations": {}
 35654          }
 35655        },
 35656        {
 35657          "type": "library",
 35658          "bom-ref": "pkg:deb/debian/libacl1@2.2.52-2?arch=amd64\u0026upstream=acl\u0026distro=debian-8\u0026package-id=151113b6ff79b67c",
 35659          "supplier": {},
 35660          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 35661          "name": "libacl1",
 35662          "version": "2.2.52-2",
 35663          "licenses": [
 35664            {
 35665              "license": {
 35666                "name": "GPL"
 35667              }
 35668            },
 35669            {
 35670              "license": {
 35671                "id": "LGPL-2.1-only"
 35672              }
 35673            }
 35674          ],
 35675          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.52-2:*:*:*:*:*:*:*",
 35676          "purl": "pkg:deb/debian/libacl1@2.2.52-2?arch=amd64\u0026upstream=acl\u0026distro=debian-8",
 35677          "swid": {
 35678            "attachment": {}
 35679          },
 35680          "pedigree": {},
 35681          "evidence": {},
 35682          "signature": {
 35683            "signature": {
 35684              "publicKey": {}
 35685            }
 35686          },
 35687          "modelCard": {
 35688            "modelParameters": {
 35689              "approach": {}
 35690            },
 35691            "quantitativeAnalysis": {
 35692              "graphics": {}
 35693            },
 35694            "considerations": {}
 35695          }
 35696        },
 35697        {
 35698          "type": "library",
 35699          "bom-ref": "pkg:deb/debian/libapr1@1.5.1-3?arch=amd64\u0026upstream=apr\u0026distro=debian-8\u0026package-id=3450731935ede838",
 35700          "supplier": {},
 35701          "publisher": "Debian Apache Maintainers \u003cdebian-apache@lists.debian.org\u003e",
 35702          "name": "libapr1",
 35703          "version": "1.5.1-3",
 35704          "licenses": [
 35705            {
 35706              "license": {
 35707                "id": "Apache-2.0"
 35708              }
 35709            }
 35710          ],
 35711          "cpe": "cpe:2.3:a:libapr1:libapr1:1.5.1-3:*:*:*:*:*:*:*",
 35712          "purl": "pkg:deb/debian/libapr1@1.5.1-3?arch=amd64\u0026upstream=apr\u0026distro=debian-8",
 35713          "swid": {
 35714            "attachment": {}
 35715          },
 35716          "pedigree": {},
 35717          "evidence": {},
 35718          "signature": {
 35719            "signature": {
 35720              "publicKey": {}
 35721            }
 35722          },
 35723          "modelCard": {
 35724            "modelParameters": {
 35725              "approach": {}
 35726            },
 35727            "quantitativeAnalysis": {
 35728              "graphics": {}
 35729            },
 35730            "considerations": {}
 35731          }
 35732        },
 35733        {
 35734          "type": "library",
 35735          "bom-ref": "pkg:deb/debian/libaprutil1@1.5.4-1?arch=amd64\u0026upstream=apr-util\u0026distro=debian-8\u0026package-id=b47ba5154c9f64e7",
 35736          "supplier": {},
 35737          "publisher": "Debian Apache Maintainers \u003cdebian-apache@lists.debian.org\u003e",
 35738          "name": "libaprutil1",
 35739          "version": "1.5.4-1",
 35740          "licenses": [
 35741            {
 35742              "license": {
 35743                "id": "Apache-2.0"
 35744              }
 35745            }
 35746          ],
 35747          "cpe": "cpe:2.3:a:libaprutil1:libaprutil1:1.5.4-1:*:*:*:*:*:*:*",
 35748          "purl": "pkg:deb/debian/libaprutil1@1.5.4-1?arch=amd64\u0026upstream=apr-util\u0026distro=debian-8",
 35749          "swid": {
 35750            "attachment": {}
 35751          },
 35752          "pedigree": {},
 35753          "evidence": {},
 35754          "signature": {
 35755            "signature": {
 35756              "publicKey": {}
 35757            }
 35758          },
 35759          "modelCard": {
 35760            "modelParameters": {
 35761              "approach": {}
 35762            },
 35763            "quantitativeAnalysis": {
 35764              "graphics": {}
 35765            },
 35766            "considerations": {}
 35767          }
 35768        },
 35769        {
 35770          "type": "library",
 35771          "bom-ref": "pkg:deb/debian/libapt-pkg4.12@1.0.9.8.3?arch=amd64\u0026upstream=apt\u0026distro=debian-8\u0026package-id=75dcaa516f819e23",
 35772          "supplier": {},
 35773          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
 35774          "name": "libapt-pkg4.12",
 35775          "version": "1.0.9.8.3",
 35776          "licenses": [
 35777            {
 35778              "license": {
 35779                "id": "GPL-2.0-only"
 35780              }
 35781            },
 35782            {
 35783              "license": {
 35784                "name": "GPLv2+"
 35785              }
 35786            }
 35787          ],
 35788          "cpe": "cpe:2.3:a:libapt-pkg4.12:libapt-pkg4.12:1.0.9.8.3:*:*:*:*:*:*:*",
 35789          "purl": "pkg:deb/debian/libapt-pkg4.12@1.0.9.8.3?arch=amd64\u0026upstream=apt\u0026distro=debian-8",
 35790          "swid": {
 35791            "attachment": {}
 35792          },
 35793          "pedigree": {},
 35794          "evidence": {},
 35795          "signature": {
 35796            "signature": {
 35797              "publicKey": {}
 35798            }
 35799          },
 35800          "modelCard": {
 35801            "modelParameters": {
 35802              "approach": {}
 35803            },
 35804            "quantitativeAnalysis": {
 35805              "graphics": {}
 35806            },
 35807            "considerations": {}
 35808          }
 35809        },
 35810        {
 35811          "type": "library",
 35812          "bom-ref": "pkg:deb/debian/libasan1@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=b9e97e61690d7e7d",
 35813          "supplier": {},
 35814          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 35815          "name": "libasan1",
 35816          "version": "4.9.2-10",
 35817          "licenses": [
 35818            {
 35819              "license": {
 35820                "name": "Artistic"
 35821              }
 35822            },
 35823            {
 35824              "license": {
 35825                "id": "GFDL-1.2-only"
 35826              }
 35827            },
 35828            {
 35829              "license": {
 35830                "name": "GPL"
 35831              }
 35832            },
 35833            {
 35834              "license": {
 35835                "id": "GPL-2.0-only"
 35836              }
 35837            },
 35838            {
 35839              "license": {
 35840                "id": "GPL-3.0-only"
 35841              }
 35842            }
 35843          ],
 35844          "cpe": "cpe:2.3:a:libasan1:libasan1:4.9.2-10:*:*:*:*:*:*:*",
 35845          "purl": "pkg:deb/debian/libasan1@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 35846          "swid": {
 35847            "attachment": {}
 35848          },
 35849          "pedigree": {},
 35850          "evidence": {},
 35851          "signature": {
 35852            "signature": {
 35853              "publicKey": {}
 35854            }
 35855          },
 35856          "modelCard": {
 35857            "modelParameters": {
 35858              "approach": {}
 35859            },
 35860            "quantitativeAnalysis": {
 35861              "graphics": {}
 35862            },
 35863            "considerations": {}
 35864          }
 35865        },
 35866        {
 35867          "type": "library",
 35868          "bom-ref": "pkg:deb/debian/libatomic1@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=ded90097c0970e8",
 35869          "supplier": {},
 35870          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 35871          "name": "libatomic1",
 35872          "version": "4.9.2-10",
 35873          "licenses": [
 35874            {
 35875              "license": {
 35876                "name": "Artistic"
 35877              }
 35878            },
 35879            {
 35880              "license": {
 35881                "id": "GFDL-1.2-only"
 35882              }
 35883            },
 35884            {
 35885              "license": {
 35886                "name": "GPL"
 35887              }
 35888            },
 35889            {
 35890              "license": {
 35891                "id": "GPL-2.0-only"
 35892              }
 35893            },
 35894            {
 35895              "license": {
 35896                "id": "GPL-3.0-only"
 35897              }
 35898            }
 35899          ],
 35900          "cpe": "cpe:2.3:a:libatomic1:libatomic1:4.9.2-10:*:*:*:*:*:*:*",
 35901          "purl": "pkg:deb/debian/libatomic1@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 35902          "swid": {
 35903            "attachment": {}
 35904          },
 35905          "pedigree": {},
 35906          "evidence": {},
 35907          "signature": {
 35908            "signature": {
 35909              "publicKey": {}
 35910            }
 35911          },
 35912          "modelCard": {
 35913            "modelParameters": {
 35914              "approach": {}
 35915            },
 35916            "quantitativeAnalysis": {
 35917              "graphics": {}
 35918            },
 35919            "considerations": {}
 35920          }
 35921        },
 35922        {
 35923          "type": "library",
 35924          "bom-ref": "pkg:deb/debian/libattr1@1:2.4.47-2?arch=amd64\u0026upstream=attr\u0026distro=debian-8\u0026package-id=6d85d19a4898b7b9",
 35925          "supplier": {},
 35926          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 35927          "name": "libattr1",
 35928          "version": "1:2.4.47-2",
 35929          "licenses": [
 35930            {
 35931              "license": {
 35932                "id": "GPL-2.0-only"
 35933              }
 35934            },
 35935            {
 35936              "license": {
 35937                "id": "LGPL-2.1-only"
 35938              }
 35939            }
 35940          ],
 35941          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.47-2:*:*:*:*:*:*:*",
 35942          "purl": "pkg:deb/debian/libattr1@1:2.4.47-2?arch=amd64\u0026upstream=attr\u0026distro=debian-8",
 35943          "swid": {
 35944            "attachment": {}
 35945          },
 35946          "pedigree": {},
 35947          "evidence": {},
 35948          "signature": {
 35949            "signature": {
 35950              "publicKey": {}
 35951            }
 35952          },
 35953          "modelCard": {
 35954            "modelParameters": {
 35955              "approach": {}
 35956            },
 35957            "quantitativeAnalysis": {
 35958              "graphics": {}
 35959            },
 35960            "considerations": {}
 35961          }
 35962        },
 35963        {
 35964          "type": "library",
 35965          "bom-ref": "pkg:deb/debian/libaudit-common@1:2.4-1?arch=all\u0026upstream=audit\u0026distro=debian-8\u0026package-id=b0df28c5530499a",
 35966          "supplier": {},
 35967          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
 35968          "name": "libaudit-common",
 35969          "version": "1:2.4-1",
 35970          "licenses": [
 35971            {
 35972              "license": {
 35973                "name": "GPL"
 35974              }
 35975            },
 35976            {
 35977              "license": {
 35978                "id": "LGPL-2.1-only"
 35979              }
 35980            }
 35981          ],
 35982          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:2.4-1:*:*:*:*:*:*:*",
 35983          "purl": "pkg:deb/debian/libaudit-common@1:2.4-1?arch=all\u0026upstream=audit\u0026distro=debian-8",
 35984          "swid": {
 35985            "attachment": {}
 35986          },
 35987          "pedigree": {},
 35988          "evidence": {},
 35989          "signature": {
 35990            "signature": {
 35991              "publicKey": {}
 35992            }
 35993          },
 35994          "modelCard": {
 35995            "modelParameters": {
 35996              "approach": {}
 35997            },
 35998            "quantitativeAnalysis": {
 35999              "graphics": {}
 36000            },
 36001            "considerations": {}
 36002          }
 36003        },
 36004        {
 36005          "type": "library",
 36006          "bom-ref": "pkg:deb/debian/libaudit1@1:2.4-1+b1?arch=amd64\u0026upstream=audit%401:2.4-1\u0026distro=debian-8\u0026package-id=5ba9d23c2a3d68b0",
 36007          "supplier": {},
 36008          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
 36009          "name": "libaudit1",
 36010          "version": "1:2.4-1+b1",
 36011          "licenses": [
 36012            {
 36013              "license": {
 36014                "name": "GPL"
 36015              }
 36016            },
 36017            {
 36018              "license": {
 36019                "id": "LGPL-2.1-only"
 36020              }
 36021            }
 36022          ],
 36023          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:2.4-1\\+b1:*:*:*:*:*:*:*",
 36024          "purl": "pkg:deb/debian/libaudit1@1:2.4-1+b1?arch=amd64\u0026upstream=audit%401:2.4-1\u0026distro=debian-8",
 36025          "swid": {
 36026            "attachment": {}
 36027          },
 36028          "pedigree": {},
 36029          "evidence": {},
 36030          "signature": {
 36031            "signature": {
 36032              "publicKey": {}
 36033            }
 36034          },
 36035          "modelCard": {
 36036            "modelParameters": {
 36037              "approach": {}
 36038            },
 36039            "quantitativeAnalysis": {
 36040              "graphics": {}
 36041            },
 36042            "considerations": {}
 36043          }
 36044        },
 36045        {
 36046          "type": "library",
 36047          "bom-ref": "pkg:deb/debian/libblkid1@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8\u0026package-id=a6e199255405add",
 36048          "supplier": {},
 36049          "publisher": "Debian util-linux Maintainers \u003cah-util-linux@debian.org\u003e",
 36050          "name": "libblkid1",
 36051          "version": "2.25.2-6",
 36052          "licenses": [
 36053            {
 36054              "license": {
 36055                "id": "BSD-2-Clause"
 36056              }
 36057            },
 36058            {
 36059              "license": {
 36060                "id": "BSD-3-Clause"
 36061              }
 36062            },
 36063            {
 36064              "license": {
 36065                "id": "BSD-4-Clause"
 36066              }
 36067            },
 36068            {
 36069              "license": {
 36070                "id": "GPL-2.0-only"
 36071              }
 36072            },
 36073            {
 36074              "license": {
 36075                "id": "GPL-2.0-or-later"
 36076              }
 36077            },
 36078            {
 36079              "license": {
 36080                "id": "GPL-3.0-only"
 36081              }
 36082            },
 36083            {
 36084              "license": {
 36085                "id": "GPL-3.0-or-later"
 36086              }
 36087            },
 36088            {
 36089              "license": {
 36090                "name": "LGPL"
 36091              }
 36092            },
 36093            {
 36094              "license": {
 36095                "id": "LGPL-2.0-only"
 36096              }
 36097            },
 36098            {
 36099              "license": {
 36100                "id": "LGPL-2.0-or-later"
 36101              }
 36102            },
 36103            {
 36104              "license": {
 36105                "id": "LGPL-2.1-only"
 36106              }
 36107            },
 36108            {
 36109              "license": {
 36110                "id": "LGPL-2.1-or-later"
 36111              }
 36112            },
 36113            {
 36114              "license": {
 36115                "id": "LGPL-3.0-only"
 36116              }
 36117            },
 36118            {
 36119              "license": {
 36120                "id": "LGPL-3.0-or-later"
 36121              }
 36122            },
 36123            {
 36124              "license": {
 36125                "id": "MIT"
 36126              }
 36127            },
 36128            {
 36129              "license": {
 36130                "name": "public-domain"
 36131              }
 36132            }
 36133          ],
 36134          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.25.2-6:*:*:*:*:*:*:*",
 36135          "purl": "pkg:deb/debian/libblkid1@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8",
 36136          "swid": {
 36137            "attachment": {}
 36138          },
 36139          "pedigree": {},
 36140          "evidence": {},
 36141          "signature": {
 36142            "signature": {
 36143              "publicKey": {}
 36144            }
 36145          },
 36146          "modelCard": {
 36147            "modelParameters": {
 36148              "approach": {}
 36149            },
 36150            "quantitativeAnalysis": {
 36151              "graphics": {}
 36152            },
 36153            "considerations": {}
 36154          }
 36155        },
 36156        {
 36157          "type": "library",
 36158          "bom-ref": "pkg:deb/debian/libbsd0@0.7.0-2?arch=amd64\u0026upstream=libbsd\u0026distro=debian-8\u0026package-id=7336d8fd0523ab2a",
 36159          "supplier": {},
 36160          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
 36161          "name": "libbsd0",
 36162          "version": "0.7.0-2",
 36163          "cpe": "cpe:2.3:a:libbsd0:libbsd0:0.7.0-2:*:*:*:*:*:*:*",
 36164          "purl": "pkg:deb/debian/libbsd0@0.7.0-2?arch=amd64\u0026upstream=libbsd\u0026distro=debian-8",
 36165          "swid": {
 36166            "attachment": {}
 36167          },
 36168          "pedigree": {},
 36169          "evidence": {},
 36170          "signature": {
 36171            "signature": {
 36172              "publicKey": {}
 36173            }
 36174          },
 36175          "modelCard": {
 36176            "modelParameters": {
 36177              "approach": {}
 36178            },
 36179            "quantitativeAnalysis": {
 36180              "graphics": {}
 36181            },
 36182            "considerations": {}
 36183          }
 36184        },
 36185        {
 36186          "type": "library",
 36187          "bom-ref": "pkg:deb/debian/libbz2-1.0@1.0.6-7+b3?arch=amd64\u0026upstream=bzip2%401.0.6-7\u0026distro=debian-8\u0026package-id=79a805297b8dfbc1",
 36188          "supplier": {},
 36189          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 36190          "name": "libbz2-1.0",
 36191          "version": "1.0.6-7+b3",
 36192          "licenses": [
 36193            {
 36194              "license": {
 36195                "id": "GPL-2.0-only"
 36196              }
 36197            }
 36198          ],
 36199          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.6-7\\+b3:*:*:*:*:*:*:*",
 36200          "purl": "pkg:deb/debian/libbz2-1.0@1.0.6-7+b3?arch=amd64\u0026upstream=bzip2%401.0.6-7\u0026distro=debian-8",
 36201          "swid": {
 36202            "attachment": {}
 36203          },
 36204          "pedigree": {},
 36205          "evidence": {},
 36206          "signature": {
 36207            "signature": {
 36208              "publicKey": {}
 36209            }
 36210          },
 36211          "modelCard": {
 36212            "modelParameters": {
 36213              "approach": {}
 36214            },
 36215            "quantitativeAnalysis": {
 36216              "graphics": {}
 36217            },
 36218            "considerations": {}
 36219          }
 36220        },
 36221        {
 36222          "type": "library",
 36223          "bom-ref": "pkg:deb/debian/libc-bin@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8\u0026package-id=c342c7f98d0fe537",
 36224          "supplier": {},
 36225          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 36226          "name": "libc-bin",
 36227          "version": "2.19-18+deb8u4",
 36228          "licenses": [
 36229            {
 36230              "license": {
 36231                "id": "GPL-2.0-only"
 36232              }
 36233            },
 36234            {
 36235              "license": {
 36236                "id": "LGPL-2.1-only"
 36237              }
 36238            }
 36239          ],
 36240          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.19-18\\+deb8u4:*:*:*:*:*:*:*",
 36241          "purl": "pkg:deb/debian/libc-bin@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8",
 36242          "swid": {
 36243            "attachment": {}
 36244          },
 36245          "pedigree": {},
 36246          "evidence": {},
 36247          "signature": {
 36248            "signature": {
 36249              "publicKey": {}
 36250            }
 36251          },
 36252          "modelCard": {
 36253            "modelParameters": {
 36254              "approach": {}
 36255            },
 36256            "quantitativeAnalysis": {
 36257              "graphics": {}
 36258            },
 36259            "considerations": {}
 36260          }
 36261        },
 36262        {
 36263          "type": "library",
 36264          "bom-ref": "pkg:deb/debian/libc-dev-bin@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8\u0026package-id=1cef0112a3af2f47",
 36265          "supplier": {},
 36266          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 36267          "name": "libc-dev-bin",
 36268          "version": "2.19-18+deb8u4",
 36269          "licenses": [
 36270            {
 36271              "license": {
 36272                "id": "GPL-2.0-only"
 36273              }
 36274            },
 36275            {
 36276              "license": {
 36277                "id": "LGPL-2.1-only"
 36278              }
 36279            }
 36280          ],
 36281          "cpe": "cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.19-18\\+deb8u4:*:*:*:*:*:*:*",
 36282          "purl": "pkg:deb/debian/libc-dev-bin@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8",
 36283          "swid": {
 36284            "attachment": {}
 36285          },
 36286          "pedigree": {},
 36287          "evidence": {},
 36288          "signature": {
 36289            "signature": {
 36290              "publicKey": {}
 36291            }
 36292          },
 36293          "modelCard": {
 36294            "modelParameters": {
 36295              "approach": {}
 36296            },
 36297            "quantitativeAnalysis": {
 36298              "graphics": {}
 36299            },
 36300            "considerations": {}
 36301          }
 36302        },
 36303        {
 36304          "type": "library",
 36305          "bom-ref": "pkg:deb/debian/libc6@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8\u0026package-id=b78cf7813b11d0ec",
 36306          "supplier": {},
 36307          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 36308          "name": "libc6",
 36309          "version": "2.19-18+deb8u4",
 36310          "licenses": [
 36311            {
 36312              "license": {
 36313                "id": "GPL-2.0-only"
 36314              }
 36315            },
 36316            {
 36317              "license": {
 36318                "id": "LGPL-2.1-only"
 36319              }
 36320            }
 36321          ],
 36322          "cpe": "cpe:2.3:a:libc6:libc6:2.19-18\\+deb8u4:*:*:*:*:*:*:*",
 36323          "purl": "pkg:deb/debian/libc6@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8",
 36324          "swid": {
 36325            "attachment": {}
 36326          },
 36327          "pedigree": {},
 36328          "evidence": {},
 36329          "signature": {
 36330            "signature": {
 36331              "publicKey": {}
 36332            }
 36333          },
 36334          "modelCard": {
 36335            "modelParameters": {
 36336              "approach": {}
 36337            },
 36338            "quantitativeAnalysis": {
 36339              "graphics": {}
 36340            },
 36341            "considerations": {}
 36342          }
 36343        },
 36344        {
 36345          "type": "library",
 36346          "bom-ref": "pkg:deb/debian/libc6-dev@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8\u0026package-id=e583b78f2f49a1c7",
 36347          "supplier": {},
 36348          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 36349          "name": "libc6-dev",
 36350          "version": "2.19-18+deb8u4",
 36351          "licenses": [
 36352            {
 36353              "license": {
 36354                "id": "GPL-2.0-only"
 36355              }
 36356            },
 36357            {
 36358              "license": {
 36359                "id": "LGPL-2.1-only"
 36360              }
 36361            }
 36362          ],
 36363          "cpe": "cpe:2.3:a:libc6-dev:libc6-dev:2.19-18\\+deb8u4:*:*:*:*:*:*:*",
 36364          "purl": "pkg:deb/debian/libc6-dev@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8",
 36365          "swid": {
 36366            "attachment": {}
 36367          },
 36368          "pedigree": {},
 36369          "evidence": {},
 36370          "signature": {
 36371            "signature": {
 36372              "publicKey": {}
 36373            }
 36374          },
 36375          "modelCard": {
 36376            "modelParameters": {
 36377              "approach": {}
 36378            },
 36379            "quantitativeAnalysis": {
 36380              "graphics": {}
 36381            },
 36382            "considerations": {}
 36383          }
 36384        },
 36385        {
 36386          "type": "library",
 36387          "bom-ref": "pkg:deb/debian/libcap2@1:2.24-8?arch=amd64\u0026distro=debian-8\u0026package-id=fc42a70f968491e1",
 36388          "supplier": {},
 36389          "publisher": "Christian Kastner \u003cdebian@kvr.at\u003e",
 36390          "name": "libcap2",
 36391          "version": "1:2.24-8",
 36392          "licenses": [
 36393            {
 36394              "license": {
 36395                "id": "BSD-3-Clause"
 36396              }
 36397            },
 36398            {
 36399              "license": {
 36400                "id": "GPL-2.0-only"
 36401              }
 36402            },
 36403            {
 36404              "license": {
 36405                "id": "GPL-2.0-or-later"
 36406              }
 36407            }
 36408          ],
 36409          "cpe": "cpe:2.3:a:libcap2:libcap2:1\\:2.24-8:*:*:*:*:*:*:*",
 36410          "purl": "pkg:deb/debian/libcap2@1:2.24-8?arch=amd64\u0026distro=debian-8",
 36411          "swid": {
 36412            "attachment": {}
 36413          },
 36414          "pedigree": {},
 36415          "evidence": {},
 36416          "signature": {
 36417            "signature": {
 36418              "publicKey": {}
 36419            }
 36420          },
 36421          "modelCard": {
 36422            "modelParameters": {
 36423              "approach": {}
 36424            },
 36425            "quantitativeAnalysis": {
 36426              "graphics": {}
 36427            },
 36428            "considerations": {}
 36429          }
 36430        },
 36431        {
 36432          "type": "library",
 36433          "bom-ref": "pkg:deb/debian/libcap2-bin@1:2.24-8?arch=amd64\u0026upstream=libcap2\u0026distro=debian-8\u0026package-id=65497dd9caa3b78e",
 36434          "supplier": {},
 36435          "publisher": "Christian Kastner \u003cdebian@kvr.at\u003e",
 36436          "name": "libcap2-bin",
 36437          "version": "1:2.24-8",
 36438          "licenses": [
 36439            {
 36440              "license": {
 36441                "id": "BSD-3-Clause"
 36442              }
 36443            },
 36444            {
 36445              "license": {
 36446                "id": "GPL-2.0-only"
 36447              }
 36448            },
 36449            {
 36450              "license": {
 36451                "id": "GPL-2.0-or-later"
 36452              }
 36453            }
 36454          ],
 36455          "cpe": "cpe:2.3:a:libcap2-bin:libcap2-bin:1\\:2.24-8:*:*:*:*:*:*:*",
 36456          "purl": "pkg:deb/debian/libcap2-bin@1:2.24-8?arch=amd64\u0026upstream=libcap2\u0026distro=debian-8",
 36457          "swid": {
 36458            "attachment": {}
 36459          },
 36460          "pedigree": {},
 36461          "evidence": {},
 36462          "signature": {
 36463            "signature": {
 36464              "publicKey": {}
 36465            }
 36466          },
 36467          "modelCard": {
 36468            "modelParameters": {
 36469              "approach": {}
 36470            },
 36471            "quantitativeAnalysis": {
 36472              "graphics": {}
 36473            },
 36474            "considerations": {}
 36475          }
 36476        },
 36477        {
 36478          "type": "library",
 36479          "bom-ref": "pkg:deb/debian/libcilkrts5@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=d94742cdaff2a295",
 36480          "supplier": {},
 36481          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 36482          "name": "libcilkrts5",
 36483          "version": "4.9.2-10",
 36484          "licenses": [
 36485            {
 36486              "license": {
 36487                "name": "Artistic"
 36488              }
 36489            },
 36490            {
 36491              "license": {
 36492                "id": "GFDL-1.2-only"
 36493              }
 36494            },
 36495            {
 36496              "license": {
 36497                "name": "GPL"
 36498              }
 36499            },
 36500            {
 36501              "license": {
 36502                "id": "GPL-2.0-only"
 36503              }
 36504            },
 36505            {
 36506              "license": {
 36507                "id": "GPL-3.0-only"
 36508              }
 36509            }
 36510          ],
 36511          "cpe": "cpe:2.3:a:libcilkrts5:libcilkrts5:4.9.2-10:*:*:*:*:*:*:*",
 36512          "purl": "pkg:deb/debian/libcilkrts5@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 36513          "swid": {
 36514            "attachment": {}
 36515          },
 36516          "pedigree": {},
 36517          "evidence": {},
 36518          "signature": {
 36519            "signature": {
 36520              "publicKey": {}
 36521            }
 36522          },
 36523          "modelCard": {
 36524            "modelParameters": {
 36525              "approach": {}
 36526            },
 36527            "quantitativeAnalysis": {
 36528              "graphics": {}
 36529            },
 36530            "considerations": {}
 36531          }
 36532        },
 36533        {
 36534          "type": "library",
 36535          "bom-ref": "pkg:deb/debian/libcloog-isl4@0.18.2-1+b2?arch=amd64\u0026upstream=cloog%400.18.2-1\u0026distro=debian-8\u0026package-id=d4d0d60fa0494fe2",
 36536          "supplier": {},
 36537          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 36538          "name": "libcloog-isl4",
 36539          "version": "0.18.2-1+b2",
 36540          "licenses": [
 36541            {
 36542              "license": {
 36543                "name": "GFDL"
 36544              }
 36545            },
 36546            {
 36547              "license": {
 36548                "name": "GPL"
 36549              }
 36550            },
 36551            {
 36552              "license": {
 36553                "id": "LGPL-2.0-only"
 36554              }
 36555            },
 36556            {
 36557              "license": {
 36558                "id": "LGPL-2.1-only"
 36559              }
 36560            }
 36561          ],
 36562          "cpe": "cpe:2.3:a:libcloog-isl4:libcloog-isl4:0.18.2-1\\+b2:*:*:*:*:*:*:*",
 36563          "purl": "pkg:deb/debian/libcloog-isl4@0.18.2-1+b2?arch=amd64\u0026upstream=cloog%400.18.2-1\u0026distro=debian-8",
 36564          "swid": {
 36565            "attachment": {}
 36566          },
 36567          "pedigree": {},
 36568          "evidence": {},
 36569          "signature": {
 36570            "signature": {
 36571              "publicKey": {}
 36572            }
 36573          },
 36574          "modelCard": {
 36575            "modelParameters": {
 36576              "approach": {}
 36577            },
 36578            "quantitativeAnalysis": {
 36579              "graphics": {}
 36580            },
 36581            "considerations": {}
 36582          }
 36583        },
 36584        {
 36585          "type": "library",
 36586          "bom-ref": "pkg:deb/debian/libcomerr2@1.42.12-1.1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-8\u0026package-id=fcc8dfa241f7aaf2",
 36587          "supplier": {},
 36588          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 36589          "name": "libcomerr2",
 36590          "version": "1.42.12-1.1",
 36591          "cpe": "cpe:2.3:a:libcomerr2:libcomerr2:1.42.12-1.1:*:*:*:*:*:*:*",
 36592          "purl": "pkg:deb/debian/libcomerr2@1.42.12-1.1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-8",
 36593          "swid": {
 36594            "attachment": {}
 36595          },
 36596          "pedigree": {},
 36597          "evidence": {},
 36598          "signature": {
 36599            "signature": {
 36600              "publicKey": {}
 36601            }
 36602          },
 36603          "modelCard": {
 36604            "modelParameters": {
 36605              "approach": {}
 36606            },
 36607            "quantitativeAnalysis": {
 36608              "graphics": {}
 36609            },
 36610            "considerations": {}
 36611          }
 36612        },
 36613        {
 36614          "type": "library",
 36615          "bom-ref": "pkg:deb/debian/libcryptsetup4@2:1.6.6-5?arch=amd64\u0026upstream=cryptsetup\u0026distro=debian-8\u0026package-id=3fff2fb61dd67bee",
 36616          "supplier": {},
 36617          "publisher": "Debian Cryptsetup Team \u003cpkg-cryptsetup-devel@lists.alioth.debian.org\u003e",
 36618          "name": "libcryptsetup4",
 36619          "version": "2:1.6.6-5",
 36620          "licenses": [
 36621            {
 36622              "license": {
 36623                "id": "GPL-2.0-only"
 36624              }
 36625            },
 36626            {
 36627              "license": {
 36628                "id": "GPL-2.0-or-later"
 36629              }
 36630            }
 36631          ],
 36632          "cpe": "cpe:2.3:a:libcryptsetup4:libcryptsetup4:2\\:1.6.6-5:*:*:*:*:*:*:*",
 36633          "purl": "pkg:deb/debian/libcryptsetup4@2:1.6.6-5?arch=amd64\u0026upstream=cryptsetup\u0026distro=debian-8",
 36634          "swid": {
 36635            "attachment": {}
 36636          },
 36637          "pedigree": {},
 36638          "evidence": {},
 36639          "signature": {
 36640            "signature": {
 36641              "publicKey": {}
 36642            }
 36643          },
 36644          "modelCard": {
 36645            "modelParameters": {
 36646              "approach": {}
 36647            },
 36648            "quantitativeAnalysis": {
 36649              "graphics": {}
 36650            },
 36651            "considerations": {}
 36652          }
 36653        },
 36654        {
 36655          "type": "library",
 36656          "bom-ref": "pkg:deb/debian/libcurl3@7.38.0-4+deb8u4?arch=amd64\u0026upstream=curl\u0026distro=debian-8\u0026package-id=2d856dde1550118d",
 36657          "supplier": {},
 36658          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
 36659          "name": "libcurl3",
 36660          "version": "7.38.0-4+deb8u4",
 36661          "licenses": [
 36662            {
 36663              "license": {
 36664                "id": "BSD-3-Clause"
 36665              }
 36666            },
 36667            {
 36668              "license": {
 36669                "id": "BSD-4-Clause"
 36670              }
 36671            },
 36672            {
 36673              "license": {
 36674                "id": "ISC"
 36675              }
 36676            },
 36677            {
 36678              "license": {
 36679                "id": "curl"
 36680              }
 36681            }
 36682          ],
 36683          "cpe": "cpe:2.3:a:libcurl3:libcurl3:7.38.0-4\\+deb8u4:*:*:*:*:*:*:*",
 36684          "purl": "pkg:deb/debian/libcurl3@7.38.0-4+deb8u4?arch=amd64\u0026upstream=curl\u0026distro=debian-8",
 36685          "swid": {
 36686            "attachment": {}
 36687          },
 36688          "pedigree": {},
 36689          "evidence": {},
 36690          "signature": {
 36691            "signature": {
 36692              "publicKey": {}
 36693            }
 36694          },
 36695          "modelCard": {
 36696            "modelParameters": {
 36697              "approach": {}
 36698            },
 36699            "quantitativeAnalysis": {
 36700              "graphics": {}
 36701            },
 36702            "considerations": {}
 36703          }
 36704        },
 36705        {
 36706          "type": "library",
 36707          "bom-ref": "pkg:deb/debian/libcurl3-gnutls@7.38.0-4+deb8u4?arch=amd64\u0026upstream=curl\u0026distro=debian-8\u0026package-id=5830c56b98f69bbc",
 36708          "supplier": {},
 36709          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
 36710          "name": "libcurl3-gnutls",
 36711          "version": "7.38.0-4+deb8u4",
 36712          "licenses": [
 36713            {
 36714              "license": {
 36715                "id": "BSD-3-Clause"
 36716              }
 36717            },
 36718            {
 36719              "license": {
 36720                "id": "BSD-4-Clause"
 36721              }
 36722            },
 36723            {
 36724              "license": {
 36725                "id": "ISC"
 36726              }
 36727            },
 36728            {
 36729              "license": {
 36730                "id": "curl"
 36731              }
 36732            }
 36733          ],
 36734          "cpe": "cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.38.0-4\\+deb8u4:*:*:*:*:*:*:*",
 36735          "purl": "pkg:deb/debian/libcurl3-gnutls@7.38.0-4+deb8u4?arch=amd64\u0026upstream=curl\u0026distro=debian-8",
 36736          "swid": {
 36737            "attachment": {}
 36738          },
 36739          "pedigree": {},
 36740          "evidence": {},
 36741          "signature": {
 36742            "signature": {
 36743              "publicKey": {}
 36744            }
 36745          },
 36746          "modelCard": {
 36747            "modelParameters": {
 36748              "approach": {}
 36749            },
 36750            "quantitativeAnalysis": {
 36751              "graphics": {}
 36752            },
 36753            "considerations": {}
 36754          }
 36755        },
 36756        {
 36757          "type": "library",
 36758          "bom-ref": "pkg:deb/debian/libdb5.3@5.3.28-9?arch=amd64\u0026upstream=db5.3\u0026distro=debian-8\u0026package-id=87f0a99a4b60cf98",
 36759          "supplier": {},
 36760          "publisher": "Debian Berkeley DB Group \u003cpkg-db-devel@lists.alioth.debian.org\u003e",
 36761          "name": "libdb5.3",
 36762          "version": "5.3.28-9",
 36763          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28-9:*:*:*:*:*:*:*",
 36764          "purl": "pkg:deb/debian/libdb5.3@5.3.28-9?arch=amd64\u0026upstream=db5.3\u0026distro=debian-8",
 36765          "swid": {
 36766            "attachment": {}
 36767          },
 36768          "pedigree": {},
 36769          "evidence": {},
 36770          "signature": {
 36771            "signature": {
 36772              "publicKey": {}
 36773            }
 36774          },
 36775          "modelCard": {
 36776            "modelParameters": {
 36777              "approach": {}
 36778            },
 36779            "quantitativeAnalysis": {
 36780              "graphics": {}
 36781            },
 36782            "considerations": {}
 36783          }
 36784        },
 36785        {
 36786          "type": "library",
 36787          "bom-ref": "pkg:deb/debian/libdebconfclient0@0.192?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-8\u0026package-id=dc8cdc3bf8bdf995",
 36788          "supplier": {},
 36789          "publisher": "Debian Install System Team \u003cdebian-boot@lists.debian.org\u003e",
 36790          "name": "libdebconfclient0",
 36791          "version": "0.192",
 36792          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.192:*:*:*:*:*:*:*",
 36793          "purl": "pkg:deb/debian/libdebconfclient0@0.192?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-8",
 36794          "swid": {
 36795            "attachment": {}
 36796          },
 36797          "pedigree": {},
 36798          "evidence": {},
 36799          "signature": {
 36800            "signature": {
 36801              "publicKey": {}
 36802            }
 36803          },
 36804          "modelCard": {
 36805            "modelParameters": {
 36806              "approach": {}
 36807            },
 36808            "quantitativeAnalysis": {
 36809              "graphics": {}
 36810            },
 36811            "considerations": {}
 36812          }
 36813        },
 36814        {
 36815          "type": "library",
 36816          "bom-ref": "pkg:deb/debian/libdevmapper1.02.1@2:1.02.90-2.2+deb8u1?arch=amd64\u0026upstream=lvm2%402.02.111-2.2+deb8u1\u0026distro=debian-8\u0026package-id=5cfd9da0daf08b97",
 36817          "supplier": {},
 36818          "publisher": "Debian LVM Team \u003cpkg-lvm-maintainers@lists.alioth.debian.org\u003e",
 36819          "name": "libdevmapper1.02.1",
 36820          "version": "2:1.02.90-2.2+deb8u1",
 36821          "licenses": [
 36822            {
 36823              "license": {
 36824                "id": "GPL-2.0-only"
 36825              }
 36826            },
 36827            {
 36828              "license": {
 36829                "id": "LGPL-2.1-only"
 36830              }
 36831            }
 36832          ],
 36833          "cpe": "cpe:2.3:a:libdevmapper1.02.1:libdevmapper1.02.1:2\\:1.02.90-2.2\\+deb8u1:*:*:*:*:*:*:*",
 36834          "purl": "pkg:deb/debian/libdevmapper1.02.1@2:1.02.90-2.2+deb8u1?arch=amd64\u0026upstream=lvm2%402.02.111-2.2+deb8u1\u0026distro=debian-8",
 36835          "swid": {
 36836            "attachment": {}
 36837          },
 36838          "pedigree": {},
 36839          "evidence": {},
 36840          "signature": {
 36841            "signature": {
 36842              "publicKey": {}
 36843            }
 36844          },
 36845          "modelCard": {
 36846            "modelParameters": {
 36847              "approach": {}
 36848            },
 36849            "quantitativeAnalysis": {
 36850              "graphics": {}
 36851            },
 36852            "considerations": {}
 36853          }
 36854        },
 36855        {
 36856          "type": "library",
 36857          "bom-ref": "pkg:deb/debian/libedit2@3.1-20140620-2?arch=amd64\u0026upstream=libedit\u0026distro=debian-8\u0026package-id=ec95c60ef6f2bfe7",
 36858          "supplier": {},
 36859          "publisher": "LLVM Packaging Team \u003cpkg-llvm-team@lists.alioth.debian.org\u003e",
 36860          "name": "libedit2",
 36861          "version": "3.1-20140620-2",
 36862          "cpe": "cpe:2.3:a:libedit2:libedit2:3.1-20140620-2:*:*:*:*:*:*:*",
 36863          "purl": "pkg:deb/debian/libedit2@3.1-20140620-2?arch=amd64\u0026upstream=libedit\u0026distro=debian-8",
 36864          "swid": {
 36865            "attachment": {}
 36866          },
 36867          "pedigree": {},
 36868          "evidence": {},
 36869          "signature": {
 36870            "signature": {
 36871              "publicKey": {}
 36872            }
 36873          },
 36874          "modelCard": {
 36875            "modelParameters": {
 36876              "approach": {}
 36877            },
 36878            "quantitativeAnalysis": {
 36879              "graphics": {}
 36880            },
 36881            "considerations": {}
 36882          }
 36883        },
 36884        {
 36885          "type": "library",
 36886          "bom-ref": "pkg:deb/debian/liberror-perl@0.17-1.1?arch=all\u0026distro=debian-8\u0026package-id=7541cebea355f402",
 36887          "supplier": {},
 36888          "publisher": "Clint Burfoot \u003cclint@burfoot.info\u003e",
 36889          "name": "liberror-perl",
 36890          "version": "0.17-1.1",
 36891          "licenses": [
 36892            {
 36893              "license": {
 36894                "name": "Artistic"
 36895              }
 36896            },
 36897            {
 36898              "license": {
 36899                "name": "GPL"
 36900              }
 36901            }
 36902          ],
 36903          "cpe": "cpe:2.3:a:liberror-perl:liberror-perl:0.17-1.1:*:*:*:*:*:*:*",
 36904          "purl": "pkg:deb/debian/liberror-perl@0.17-1.1?arch=all\u0026distro=debian-8",
 36905          "swid": {
 36906            "attachment": {}
 36907          },
 36908          "pedigree": {},
 36909          "evidence": {},
 36910          "signature": {
 36911            "signature": {
 36912              "publicKey": {}
 36913            }
 36914          },
 36915          "modelCard": {
 36916            "modelParameters": {
 36917              "approach": {}
 36918            },
 36919            "quantitativeAnalysis": {
 36920              "graphics": {}
 36921            },
 36922            "considerations": {}
 36923          }
 36924        },
 36925        {
 36926          "type": "library",
 36927          "bom-ref": "pkg:deb/debian/libexpat1@2.1.0-6+deb8u3?arch=amd64\u0026upstream=expat\u0026distro=debian-8\u0026package-id=16315cb8a9b66a30",
 36928          "supplier": {},
 36929          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
 36930          "name": "libexpat1",
 36931          "version": "2.1.0-6+deb8u3",
 36932          "cpe": "cpe:2.3:a:libexpat1:libexpat1:2.1.0-6\\+deb8u3:*:*:*:*:*:*:*",
 36933          "purl": "pkg:deb/debian/libexpat1@2.1.0-6+deb8u3?arch=amd64\u0026upstream=expat\u0026distro=debian-8",
 36934          "swid": {
 36935            "attachment": {}
 36936          },
 36937          "pedigree": {},
 36938          "evidence": {},
 36939          "signature": {
 36940            "signature": {
 36941              "publicKey": {}
 36942            }
 36943          },
 36944          "modelCard": {
 36945            "modelParameters": {
 36946              "approach": {}
 36947            },
 36948            "quantitativeAnalysis": {
 36949              "graphics": {}
 36950            },
 36951            "considerations": {}
 36952          }
 36953        },
 36954        {
 36955          "type": "library",
 36956          "bom-ref": "pkg:deb/debian/libffi6@3.1-2+b2?arch=amd64\u0026upstream=libffi%403.1-2\u0026distro=debian-8\u0026package-id=d18c45810d011fb1",
 36957          "supplier": {},
 36958          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 36959          "name": "libffi6",
 36960          "version": "3.1-2+b2",
 36961          "licenses": [
 36962            {
 36963              "license": {
 36964                "name": "GPL"
 36965              }
 36966            }
 36967          ],
 36968          "cpe": "cpe:2.3:a:libffi6:libffi6:3.1-2\\+b2:*:*:*:*:*:*:*",
 36969          "purl": "pkg:deb/debian/libffi6@3.1-2+b2?arch=amd64\u0026upstream=libffi%403.1-2\u0026distro=debian-8",
 36970          "swid": {
 36971            "attachment": {}
 36972          },
 36973          "pedigree": {},
 36974          "evidence": {},
 36975          "signature": {
 36976            "signature": {
 36977              "publicKey": {}
 36978            }
 36979          },
 36980          "modelCard": {
 36981            "modelParameters": {
 36982              "approach": {}
 36983            },
 36984            "quantitativeAnalysis": {
 36985              "graphics": {}
 36986            },
 36987            "considerations": {}
 36988          }
 36989        },
 36990        {
 36991          "type": "library",
 36992          "bom-ref": "pkg:deb/debian/libgcc-4.9-dev@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=14e425189ebdf185",
 36993          "supplier": {},
 36994          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 36995          "name": "libgcc-4.9-dev",
 36996          "version": "4.9.2-10",
 36997          "licenses": [
 36998            {
 36999              "license": {
 37000                "name": "Artistic"
 37001              }
 37002            },
 37003            {
 37004              "license": {
 37005                "id": "GFDL-1.2-only"
 37006              }
 37007            },
 37008            {
 37009              "license": {
 37010                "name": "GPL"
 37011              }
 37012            },
 37013            {
 37014              "license": {
 37015                "id": "GPL-2.0-only"
 37016              }
 37017            },
 37018            {
 37019              "license": {
 37020                "id": "GPL-3.0-only"
 37021              }
 37022            }
 37023          ],
 37024          "cpe": "cpe:2.3:a:libgcc-4.9-dev:libgcc-4.9-dev:4.9.2-10:*:*:*:*:*:*:*",
 37025          "purl": "pkg:deb/debian/libgcc-4.9-dev@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 37026          "swid": {
 37027            "attachment": {}
 37028          },
 37029          "pedigree": {},
 37030          "evidence": {},
 37031          "signature": {
 37032            "signature": {
 37033              "publicKey": {}
 37034            }
 37035          },
 37036          "modelCard": {
 37037            "modelParameters": {
 37038              "approach": {}
 37039            },
 37040            "quantitativeAnalysis": {
 37041              "graphics": {}
 37042            },
 37043            "considerations": {}
 37044          }
 37045        },
 37046        {
 37047          "type": "library",
 37048          "bom-ref": "pkg:deb/debian/libgcc1@1:4.9.2-10?arch=amd64\u0026upstream=gcc-4.9%404.9.2-10\u0026distro=debian-8\u0026package-id=5b91df6be89e7540",
 37049          "supplier": {},
 37050          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 37051          "name": "libgcc1",
 37052          "version": "1:4.9.2-10",
 37053          "licenses": [
 37054            {
 37055              "license": {
 37056                "name": "Artistic"
 37057              }
 37058            },
 37059            {
 37060              "license": {
 37061                "id": "GFDL-1.2-only"
 37062              }
 37063            },
 37064            {
 37065              "license": {
 37066                "name": "GPL"
 37067              }
 37068            },
 37069            {
 37070              "license": {
 37071                "id": "GPL-2.0-only"
 37072              }
 37073            },
 37074            {
 37075              "license": {
 37076                "id": "GPL-3.0-only"
 37077              }
 37078            }
 37079          ],
 37080          "cpe": "cpe:2.3:a:libgcc1:libgcc1:1\\:4.9.2-10:*:*:*:*:*:*:*",
 37081          "purl": "pkg:deb/debian/libgcc1@1:4.9.2-10?arch=amd64\u0026upstream=gcc-4.9%404.9.2-10\u0026distro=debian-8",
 37082          "swid": {
 37083            "attachment": {}
 37084          },
 37085          "pedigree": {},
 37086          "evidence": {},
 37087          "signature": {
 37088            "signature": {
 37089              "publicKey": {}
 37090            }
 37091          },
 37092          "modelCard": {
 37093            "modelParameters": {
 37094              "approach": {}
 37095            },
 37096            "quantitativeAnalysis": {
 37097              "graphics": {}
 37098            },
 37099            "considerations": {}
 37100          }
 37101        },
 37102        {
 37103          "type": "library",
 37104          "bom-ref": "pkg:deb/debian/libgcrypt20@1.6.3-2+deb8u2?arch=amd64\u0026distro=debian-8\u0026package-id=c913d2b222b607d5",
 37105          "supplier": {},
 37106          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 37107          "name": "libgcrypt20",
 37108          "version": "1.6.3-2+deb8u2",
 37109          "licenses": [
 37110            {
 37111              "license": {
 37112                "id": "GPL-2.0-only"
 37113              }
 37114            },
 37115            {
 37116              "license": {
 37117                "name": "LGPL"
 37118              }
 37119            }
 37120          ],
 37121          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.6.3-2\\+deb8u2:*:*:*:*:*:*:*",
 37122          "purl": "pkg:deb/debian/libgcrypt20@1.6.3-2+deb8u2?arch=amd64\u0026distro=debian-8",
 37123          "swid": {
 37124            "attachment": {}
 37125          },
 37126          "pedigree": {},
 37127          "evidence": {},
 37128          "signature": {
 37129            "signature": {
 37130              "publicKey": {}
 37131            }
 37132          },
 37133          "modelCard": {
 37134            "modelParameters": {
 37135              "approach": {}
 37136            },
 37137            "quantitativeAnalysis": {
 37138              "graphics": {}
 37139            },
 37140            "considerations": {}
 37141          }
 37142        },
 37143        {
 37144          "type": "library",
 37145          "bom-ref": "pkg:deb/debian/libgdbm3@1.8.3-13.1?arch=amd64\u0026upstream=gdbm\u0026distro=debian-8\u0026package-id=7fd2e05a98901459",
 37146          "supplier": {},
 37147          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 37148          "name": "libgdbm3",
 37149          "version": "1.8.3-13.1",
 37150          "licenses": [
 37151            {
 37152              "license": {
 37153                "id": "GPL-2.0-only"
 37154              }
 37155            }
 37156          ],
 37157          "cpe": "cpe:2.3:a:libgdbm3:libgdbm3:1.8.3-13.1:*:*:*:*:*:*:*",
 37158          "purl": "pkg:deb/debian/libgdbm3@1.8.3-13.1?arch=amd64\u0026upstream=gdbm\u0026distro=debian-8",
 37159          "swid": {
 37160            "attachment": {}
 37161          },
 37162          "pedigree": {},
 37163          "evidence": {},
 37164          "signature": {
 37165            "signature": {
 37166              "publicKey": {}
 37167            }
 37168          },
 37169          "modelCard": {
 37170            "modelParameters": {
 37171              "approach": {}
 37172            },
 37173            "quantitativeAnalysis": {
 37174              "graphics": {}
 37175            },
 37176            "considerations": {}
 37177          }
 37178        },
 37179        {
 37180          "type": "library",
 37181          "bom-ref": "pkg:deb/debian/libgmp10@2:6.0.0+dfsg-6?arch=amd64\u0026upstream=gmp\u0026distro=debian-8\u0026package-id=853cf93a34632342",
 37182          "supplier": {},
 37183          "publisher": "Debian Science Team \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e",
 37184          "name": "libgmp10",
 37185          "version": "2:6.0.0+dfsg-6",
 37186          "licenses": [
 37187            {
 37188              "license": {
 37189                "name": "GPL"
 37190              }
 37191            },
 37192            {
 37193              "license": {
 37194                "id": "GPL-2.0-only"
 37195              }
 37196            },
 37197            {
 37198              "license": {
 37199                "id": "GPL-3.0-only"
 37200              }
 37201            },
 37202            {
 37203              "license": {
 37204                "id": "LGPL-3.0-only"
 37205              }
 37206            }
 37207          ],
 37208          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.0.0\\+dfsg-6:*:*:*:*:*:*:*",
 37209          "purl": "pkg:deb/debian/libgmp10@2:6.0.0+dfsg-6?arch=amd64\u0026upstream=gmp\u0026distro=debian-8",
 37210          "swid": {
 37211            "attachment": {}
 37212          },
 37213          "pedigree": {},
 37214          "evidence": {},
 37215          "signature": {
 37216            "signature": {
 37217              "publicKey": {}
 37218            }
 37219          },
 37220          "modelCard": {
 37221            "modelParameters": {
 37222              "approach": {}
 37223            },
 37224            "quantitativeAnalysis": {
 37225              "graphics": {}
 37226            },
 37227            "considerations": {}
 37228          }
 37229        },
 37230        {
 37231          "type": "library",
 37232          "bom-ref": "pkg:deb/debian/libgnutls-deb0-28@3.3.8-6+deb8u3?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-8\u0026package-id=71062ffec863d768",
 37233          "supplier": {},
 37234          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 37235          "name": "libgnutls-deb0-28",
 37236          "version": "3.3.8-6+deb8u3",
 37237          "licenses": [
 37238            {
 37239              "license": {
 37240                "id": "GFDL-1.3-only"
 37241              }
 37242            },
 37243            {
 37244              "license": {
 37245                "name": "GPL"
 37246              }
 37247            },
 37248            {
 37249              "license": {
 37250                "id": "GPL-3.0-only"
 37251              }
 37252            },
 37253            {
 37254              "license": {
 37255                "name": "GPLv3+"
 37256              }
 37257            },
 37258            {
 37259              "license": {
 37260                "name": "LGPL"
 37261              }
 37262            },
 37263            {
 37264              "license": {
 37265                "id": "LGPL-3.0-only"
 37266              }
 37267            },
 37268            {
 37269              "license": {
 37270                "id": "LGPL-2.1-only"
 37271              }
 37272            },
 37273            {
 37274              "license": {
 37275                "name": "The"
 37276              }
 37277            },
 37278            {
 37279              "license": {
 37280                "name": "nonstandard,"
 37281              }
 37282            }
 37283          ],
 37284          "cpe": "cpe:2.3:a:libgnutls-deb0-28:libgnutls-deb0-28:3.3.8-6\\+deb8u3:*:*:*:*:*:*:*",
 37285          "purl": "pkg:deb/debian/libgnutls-deb0-28@3.3.8-6+deb8u3?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-8",
 37286          "swid": {
 37287            "attachment": {}
 37288          },
 37289          "pedigree": {},
 37290          "evidence": {},
 37291          "signature": {
 37292            "signature": {
 37293              "publicKey": {}
 37294            }
 37295          },
 37296          "modelCard": {
 37297            "modelParameters": {
 37298              "approach": {}
 37299            },
 37300            "quantitativeAnalysis": {
 37301              "graphics": {}
 37302            },
 37303            "considerations": {}
 37304          }
 37305        },
 37306        {
 37307          "type": "library",
 37308          "bom-ref": "pkg:deb/debian/libgomp1@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=98b2222a4c75fa19",
 37309          "supplier": {},
 37310          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 37311          "name": "libgomp1",
 37312          "version": "4.9.2-10",
 37313          "licenses": [
 37314            {
 37315              "license": {
 37316                "name": "Artistic"
 37317              }
 37318            },
 37319            {
 37320              "license": {
 37321                "id": "GFDL-1.2-only"
 37322              }
 37323            },
 37324            {
 37325              "license": {
 37326                "name": "GPL"
 37327              }
 37328            },
 37329            {
 37330              "license": {
 37331                "id": "GPL-2.0-only"
 37332              }
 37333            },
 37334            {
 37335              "license": {
 37336                "id": "GPL-3.0-only"
 37337              }
 37338            }
 37339          ],
 37340          "cpe": "cpe:2.3:a:libgomp1:libgomp1:4.9.2-10:*:*:*:*:*:*:*",
 37341          "purl": "pkg:deb/debian/libgomp1@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 37342          "swid": {
 37343            "attachment": {}
 37344          },
 37345          "pedigree": {},
 37346          "evidence": {},
 37347          "signature": {
 37348            "signature": {
 37349              "publicKey": {}
 37350            }
 37351          },
 37352          "modelCard": {
 37353            "modelParameters": {
 37354              "approach": {}
 37355            },
 37356            "quantitativeAnalysis": {
 37357              "graphics": {}
 37358            },
 37359            "considerations": {}
 37360          }
 37361        },
 37362        {
 37363          "type": "library",
 37364          "bom-ref": "pkg:deb/debian/libgpg-error0@1.17-3?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-8\u0026package-id=b4dc0e02e5febc6f",
 37365          "supplier": {},
 37366          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
 37367          "name": "libgpg-error0",
 37368          "version": "1.17-3",
 37369          "licenses": [
 37370            {
 37371              "license": {
 37372                "name": "GPL-2.1+"
 37373              }
 37374            },
 37375            {
 37376              "license": {
 37377                "id": "LGPL-2.1-only"
 37378              }
 37379            }
 37380          ],
 37381          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.17-3:*:*:*:*:*:*:*",
 37382          "purl": "pkg:deb/debian/libgpg-error0@1.17-3?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-8",
 37383          "swid": {
 37384            "attachment": {}
 37385          },
 37386          "pedigree": {},
 37387          "evidence": {},
 37388          "signature": {
 37389            "signature": {
 37390              "publicKey": {}
 37391            }
 37392          },
 37393          "modelCard": {
 37394            "modelParameters": {
 37395              "approach": {}
 37396            },
 37397            "quantitativeAnalysis": {
 37398              "graphics": {}
 37399            },
 37400            "considerations": {}
 37401          }
 37402        },
 37403        {
 37404          "type": "library",
 37405          "bom-ref": "pkg:deb/debian/libgssapi-krb5-2@1.12.1+dfsg-19+deb8u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-8\u0026package-id=c76f60e0ef2704c0",
 37406          "supplier": {},
 37407          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
 37408          "name": "libgssapi-krb5-2",
 37409          "version": "1.12.1+dfsg-19+deb8u2",
 37410          "licenses": [
 37411            {
 37412              "license": {
 37413                "id": "GPL-2.0-only"
 37414              }
 37415            }
 37416          ],
 37417          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.12.1\\+dfsg-19\\+deb8u2:*:*:*:*:*:*:*",
 37418          "purl": "pkg:deb/debian/libgssapi-krb5-2@1.12.1+dfsg-19+deb8u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-8",
 37419          "swid": {
 37420            "attachment": {}
 37421          },
 37422          "pedigree": {},
 37423          "evidence": {},
 37424          "signature": {
 37425            "signature": {
 37426              "publicKey": {}
 37427            }
 37428          },
 37429          "modelCard": {
 37430            "modelParameters": {
 37431              "approach": {}
 37432            },
 37433            "quantitativeAnalysis": {
 37434              "graphics": {}
 37435            },
 37436            "considerations": {}
 37437          }
 37438        },
 37439        {
 37440          "type": "library",
 37441          "bom-ref": "pkg:deb/debian/libhogweed2@2.7.1-5+deb8u1?arch=amd64\u0026upstream=nettle\u0026distro=debian-8\u0026package-id=7303473c76c98e1e",
 37442          "supplier": {},
 37443          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
 37444          "name": "libhogweed2",
 37445          "version": "2.7.1-5+deb8u1",
 37446          "licenses": [
 37447            {
 37448              "license": {
 37449                "name": "GAP"
 37450              }
 37451            },
 37452            {
 37453              "license": {
 37454                "name": "GPL"
 37455              }
 37456            },
 37457            {
 37458              "license": {
 37459                "id": "GPL-2.0-only"
 37460              }
 37461            },
 37462            {
 37463              "license": {
 37464                "id": "GPL-2.0-or-later"
 37465              }
 37466            },
 37467            {
 37468              "license": {
 37469                "name": "LGPL"
 37470              }
 37471            },
 37472            {
 37473              "license": {
 37474                "id": "LGPL-2.0-only"
 37475              }
 37476            },
 37477            {
 37478              "license": {
 37479                "id": "LGPL-2.0-or-later"
 37480              }
 37481            },
 37482            {
 37483              "license": {
 37484                "id": "LGPL-2.1-or-later"
 37485              }
 37486            },
 37487            {
 37488              "license": {
 37489                "name": "other"
 37490              }
 37491            },
 37492            {
 37493              "license": {
 37494                "name": "public-domain"
 37495              }
 37496            }
 37497          ],
 37498          "cpe": "cpe:2.3:a:libhogweed2:libhogweed2:2.7.1-5\\+deb8u1:*:*:*:*:*:*:*",
 37499          "purl": "pkg:deb/debian/libhogweed2@2.7.1-5+deb8u1?arch=amd64\u0026upstream=nettle\u0026distro=debian-8",
 37500          "swid": {
 37501            "attachment": {}
 37502          },
 37503          "pedigree": {},
 37504          "evidence": {},
 37505          "signature": {
 37506            "signature": {
 37507              "publicKey": {}
 37508            }
 37509          },
 37510          "modelCard": {
 37511            "modelParameters": {
 37512              "approach": {}
 37513            },
 37514            "quantitativeAnalysis": {
 37515              "graphics": {}
 37516            },
 37517            "considerations": {}
 37518          }
 37519        },
 37520        {
 37521          "type": "library",
 37522          "bom-ref": "pkg:deb/debian/libicu52@52.1-8+deb8u3?arch=amd64\u0026upstream=icu\u0026distro=debian-8\u0026package-id=d3b93304b211cea2",
 37523          "supplier": {},
 37524          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
 37525          "name": "libicu52",
 37526          "version": "52.1-8+deb8u3",
 37527          "cpe": "cpe:2.3:a:libicu52:libicu52:52.1-8\\+deb8u3:*:*:*:*:*:*:*",
 37528          "purl": "pkg:deb/debian/libicu52@52.1-8+deb8u3?arch=amd64\u0026upstream=icu\u0026distro=debian-8",
 37529          "swid": {
 37530            "attachment": {}
 37531          },
 37532          "pedigree": {},
 37533          "evidence": {},
 37534          "signature": {
 37535            "signature": {
 37536              "publicKey": {}
 37537            }
 37538          },
 37539          "modelCard": {
 37540            "modelParameters": {
 37541              "approach": {}
 37542            },
 37543            "quantitativeAnalysis": {
 37544              "graphics": {}
 37545            },
 37546            "considerations": {}
 37547          }
 37548        },
 37549        {
 37550          "type": "library",
 37551          "bom-ref": "pkg:deb/debian/libidn11@1.29-1+deb8u1?arch=amd64\u0026upstream=libidn\u0026distro=debian-8\u0026package-id=d7f65a8658225518",
 37552          "supplier": {},
 37553          "publisher": "Debian Libidn Team \u003chelp-libidn@gnu.org\u003e",
 37554          "name": "libidn11",
 37555          "version": "1.29-1+deb8u1",
 37556          "licenses": [
 37557            {
 37558              "license": {
 37559                "name": "GAP"
 37560              }
 37561            },
 37562            {
 37563              "license": {
 37564                "id": "GFDL-1.3-only"
 37565              }
 37566            },
 37567            {
 37568              "license": {
 37569                "name": "GFDL-1.3+"
 37570              }
 37571            },
 37572            {
 37573              "license": {
 37574                "id": "GPL-2.0-only"
 37575              }
 37576            },
 37577            {
 37578              "license": {
 37579                "id": "GPL-3.0-only"
 37580              }
 37581            },
 37582            {
 37583              "license": {
 37584                "id": "GPL-3.0-or-later"
 37585              }
 37586            },
 37587            {
 37588              "license": {
 37589                "id": "LGPL-2.0-only"
 37590              }
 37591            },
 37592            {
 37593              "license": {
 37594                "id": "LGPL-2.1-only"
 37595              }
 37596            },
 37597            {
 37598              "license": {
 37599                "id": "LGPL-2.1-or-later"
 37600              }
 37601            },
 37602            {
 37603              "license": {
 37604                "id": "LGPL-3.0-only"
 37605              }
 37606            },
 37607            {
 37608              "license": {
 37609                "id": "LGPL-3.0-or-later"
 37610              }
 37611            }
 37612          ],
 37613          "cpe": "cpe:2.3:a:libidn11:libidn11:1.29-1\\+deb8u1:*:*:*:*:*:*:*",
 37614          "purl": "pkg:deb/debian/libidn11@1.29-1+deb8u1?arch=amd64\u0026upstream=libidn\u0026distro=debian-8",
 37615          "swid": {
 37616            "attachment": {}
 37617          },
 37618          "pedigree": {},
 37619          "evidence": {},
 37620          "signature": {
 37621            "signature": {
 37622              "publicKey": {}
 37623            }
 37624          },
 37625          "modelCard": {
 37626            "modelParameters": {
 37627              "approach": {}
 37628            },
 37629            "quantitativeAnalysis": {
 37630              "graphics": {}
 37631            },
 37632            "considerations": {}
 37633          }
 37634        },
 37635        {
 37636          "type": "library",
 37637          "bom-ref": "pkg:deb/debian/libisl10@0.12.2-2?arch=amd64\u0026upstream=isl\u0026distro=debian-8\u0026package-id=9f04fbb23dc3ada5",
 37638          "supplier": {},
 37639          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 37640          "name": "libisl10",
 37641          "version": "0.12.2-2",
 37642          "licenses": [
 37643            {
 37644              "license": {
 37645                "name": "2-clause"
 37646              }
 37647            },
 37648            {
 37649              "license": {
 37650                "id": "LGPL-2.0-only"
 37651              }
 37652            },
 37653            {
 37654              "license": {
 37655                "id": "LGPL-2.1-or-later"
 37656              }
 37657            },
 37658            {
 37659              "license": {
 37660                "id": "MIT"
 37661              }
 37662            }
 37663          ],
 37664          "cpe": "cpe:2.3:a:libisl10:libisl10:0.12.2-2:*:*:*:*:*:*:*",
 37665          "purl": "pkg:deb/debian/libisl10@0.12.2-2?arch=amd64\u0026upstream=isl\u0026distro=debian-8",
 37666          "swid": {
 37667            "attachment": {}
 37668          },
 37669          "pedigree": {},
 37670          "evidence": {},
 37671          "signature": {
 37672            "signature": {
 37673              "publicKey": {}
 37674            }
 37675          },
 37676          "modelCard": {
 37677            "modelParameters": {
 37678              "approach": {}
 37679            },
 37680            "quantitativeAnalysis": {
 37681              "graphics": {}
 37682            },
 37683            "considerations": {}
 37684          }
 37685        },
 37686        {
 37687          "type": "library",
 37688          "bom-ref": "pkg:deb/debian/libitm1@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=81b865bab1a506ae",
 37689          "supplier": {},
 37690          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 37691          "name": "libitm1",
 37692          "version": "4.9.2-10",
 37693          "licenses": [
 37694            {
 37695              "license": {
 37696                "name": "Artistic"
 37697              }
 37698            },
 37699            {
 37700              "license": {
 37701                "id": "GFDL-1.2-only"
 37702              }
 37703            },
 37704            {
 37705              "license": {
 37706                "name": "GPL"
 37707              }
 37708            },
 37709            {
 37710              "license": {
 37711                "id": "GPL-2.0-only"
 37712              }
 37713            },
 37714            {
 37715              "license": {
 37716                "id": "GPL-3.0-only"
 37717              }
 37718            }
 37719          ],
 37720          "cpe": "cpe:2.3:a:libitm1:libitm1:4.9.2-10:*:*:*:*:*:*:*",
 37721          "purl": "pkg:deb/debian/libitm1@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 37722          "swid": {
 37723            "attachment": {}
 37724          },
 37725          "pedigree": {},
 37726          "evidence": {},
 37727          "signature": {
 37728            "signature": {
 37729              "publicKey": {}
 37730            }
 37731          },
 37732          "modelCard": {
 37733            "modelParameters": {
 37734              "approach": {}
 37735            },
 37736            "quantitativeAnalysis": {
 37737              "graphics": {}
 37738            },
 37739            "considerations": {}
 37740          }
 37741        },
 37742        {
 37743          "type": "library",
 37744          "bom-ref": "pkg:deb/debian/libjs-excanvas@0.r3-3?arch=all\u0026upstream=explorercanvas\u0026distro=debian-8\u0026package-id=1854497afd74e669",
 37745          "supplier": {},
 37746          "publisher": "Debian Javascript Maintainers \u003cpkg-javascript-devel@lists.alioth.debian.org\u003e",
 37747          "name": "libjs-excanvas",
 37748          "version": "0.r3-3",
 37749          "licenses": [
 37750            {
 37751              "license": {
 37752                "id": "Apache-2.0"
 37753              }
 37754            }
 37755          ],
 37756          "cpe": "cpe:2.3:a:libjs-excanvas:libjs-excanvas:0.r3-3:*:*:*:*:*:*:*",
 37757          "purl": "pkg:deb/debian/libjs-excanvas@0.r3-3?arch=all\u0026upstream=explorercanvas\u0026distro=debian-8",
 37758          "swid": {
 37759            "attachment": {}
 37760          },
 37761          "pedigree": {},
 37762          "evidence": {},
 37763          "signature": {
 37764            "signature": {
 37765              "publicKey": {}
 37766            }
 37767          },
 37768          "modelCard": {
 37769            "modelParameters": {
 37770              "approach": {}
 37771            },
 37772            "quantitativeAnalysis": {
 37773              "graphics": {}
 37774            },
 37775            "considerations": {}
 37776          }
 37777        },
 37778        {
 37779          "type": "library",
 37780          "bom-ref": "pkg:deb/debian/libk5crypto3@1.12.1+dfsg-19+deb8u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-8\u0026package-id=72f52458e62339be",
 37781          "supplier": {},
 37782          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
 37783          "name": "libk5crypto3",
 37784          "version": "1.12.1+dfsg-19+deb8u2",
 37785          "licenses": [
 37786            {
 37787              "license": {
 37788                "id": "GPL-2.0-only"
 37789              }
 37790            }
 37791          ],
 37792          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.12.1\\+dfsg-19\\+deb8u2:*:*:*:*:*:*:*",
 37793          "purl": "pkg:deb/debian/libk5crypto3@1.12.1+dfsg-19+deb8u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-8",
 37794          "swid": {
 37795            "attachment": {}
 37796          },
 37797          "pedigree": {},
 37798          "evidence": {},
 37799          "signature": {
 37800            "signature": {
 37801              "publicKey": {}
 37802            }
 37803          },
 37804          "modelCard": {
 37805            "modelParameters": {
 37806              "approach": {}
 37807            },
 37808            "quantitativeAnalysis": {
 37809              "graphics": {}
 37810            },
 37811            "considerations": {}
 37812          }
 37813        },
 37814        {
 37815          "type": "library",
 37816          "bom-ref": "pkg:deb/debian/libkeyutils1@1.5.9-5+b1?arch=amd64\u0026upstream=keyutils%401.5.9-5\u0026distro=debian-8\u0026package-id=f8db0c9260dbb4cc",
 37817          "supplier": {},
 37818          "publisher": "Christian Kastner \u003cdebian@kvr.at\u003e",
 37819          "name": "libkeyutils1",
 37820          "version": "1.5.9-5+b1",
 37821          "licenses": [
 37822            {
 37823              "license": {
 37824                "id": "GPL-2.0-only"
 37825              }
 37826            },
 37827            {
 37828              "license": {
 37829                "id": "GPL-2.0-or-later"
 37830              }
 37831            },
 37832            {
 37833              "license": {
 37834                "id": "LGPL-2.0-only"
 37835              }
 37836            },
 37837            {
 37838              "license": {
 37839                "id": "LGPL-2.0-or-later"
 37840              }
 37841            }
 37842          ],
 37843          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.5.9-5\\+b1:*:*:*:*:*:*:*",
 37844          "purl": "pkg:deb/debian/libkeyutils1@1.5.9-5+b1?arch=amd64\u0026upstream=keyutils%401.5.9-5\u0026distro=debian-8",
 37845          "swid": {
 37846            "attachment": {}
 37847          },
 37848          "pedigree": {},
 37849          "evidence": {},
 37850          "signature": {
 37851            "signature": {
 37852              "publicKey": {}
 37853            }
 37854          },
 37855          "modelCard": {
 37856            "modelParameters": {
 37857              "approach": {}
 37858            },
 37859            "quantitativeAnalysis": {
 37860              "graphics": {}
 37861            },
 37862            "considerations": {}
 37863          }
 37864        },
 37865        {
 37866          "type": "library",
 37867          "bom-ref": "pkg:deb/debian/libkmod2@18-3?arch=amd64\u0026upstream=kmod\u0026distro=debian-8\u0026package-id=6a918f744f3dead5",
 37868          "supplier": {},
 37869          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
 37870          "name": "libkmod2",
 37871          "version": "18-3",
 37872          "licenses": [
 37873            {
 37874              "license": {
 37875                "id": "GPL-2.0-only"
 37876              }
 37877            }
 37878          ],
 37879          "cpe": "cpe:2.3:a:libkmod2:libkmod2:18-3:*:*:*:*:*:*:*",
 37880          "purl": "pkg:deb/debian/libkmod2@18-3?arch=amd64\u0026upstream=kmod\u0026distro=debian-8",
 37881          "swid": {
 37882            "attachment": {}
 37883          },
 37884          "pedigree": {},
 37885          "evidence": {},
 37886          "signature": {
 37887            "signature": {
 37888              "publicKey": {}
 37889            }
 37890          },
 37891          "modelCard": {
 37892            "modelParameters": {
 37893              "approach": {}
 37894            },
 37895            "quantitativeAnalysis": {
 37896              "graphics": {}
 37897            },
 37898            "considerations": {}
 37899          }
 37900        },
 37901        {
 37902          "type": "library",
 37903          "bom-ref": "pkg:deb/debian/libkrb5-3@1.12.1+dfsg-19+deb8u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-8\u0026package-id=2a2e79411d2ee43d",
 37904          "supplier": {},
 37905          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
 37906          "name": "libkrb5-3",
 37907          "version": "1.12.1+dfsg-19+deb8u2",
 37908          "licenses": [
 37909            {
 37910              "license": {
 37911                "id": "GPL-2.0-only"
 37912              }
 37913            }
 37914          ],
 37915          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.12.1\\+dfsg-19\\+deb8u2:*:*:*:*:*:*:*",
 37916          "purl": "pkg:deb/debian/libkrb5-3@1.12.1+dfsg-19+deb8u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-8",
 37917          "swid": {
 37918            "attachment": {}
 37919          },
 37920          "pedigree": {},
 37921          "evidence": {},
 37922          "signature": {
 37923            "signature": {
 37924              "publicKey": {}
 37925            }
 37926          },
 37927          "modelCard": {
 37928            "modelParameters": {
 37929              "approach": {}
 37930            },
 37931            "quantitativeAnalysis": {
 37932              "graphics": {}
 37933            },
 37934            "considerations": {}
 37935          }
 37936        },
 37937        {
 37938          "type": "library",
 37939          "bom-ref": "pkg:deb/debian/libkrb5support0@1.12.1+dfsg-19+deb8u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-8\u0026package-id=bd3a9ae360e367f7",
 37940          "supplier": {},
 37941          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
 37942          "name": "libkrb5support0",
 37943          "version": "1.12.1+dfsg-19+deb8u2",
 37944          "licenses": [
 37945            {
 37946              "license": {
 37947                "id": "GPL-2.0-only"
 37948              }
 37949            }
 37950          ],
 37951          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.12.1\\+dfsg-19\\+deb8u2:*:*:*:*:*:*:*",
 37952          "purl": "pkg:deb/debian/libkrb5support0@1.12.1+dfsg-19+deb8u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-8",
 37953          "swid": {
 37954            "attachment": {}
 37955          },
 37956          "pedigree": {},
 37957          "evidence": {},
 37958          "signature": {
 37959            "signature": {
 37960              "publicKey": {}
 37961            }
 37962          },
 37963          "modelCard": {
 37964            "modelParameters": {
 37965              "approach": {}
 37966            },
 37967            "quantitativeAnalysis": {
 37968              "graphics": {}
 37969            },
 37970            "considerations": {}
 37971          }
 37972        },
 37973        {
 37974          "type": "library",
 37975          "bom-ref": "pkg:deb/debian/libldap-2.4-2@2.4.40+dfsg-1+deb8u2?arch=amd64\u0026upstream=openldap\u0026distro=debian-8\u0026package-id=f88be8f8c005d39d",
 37976          "supplier": {},
 37977          "publisher": "Debian OpenLDAP Maintainers \u003cpkg-openldap-devel@lists.alioth.debian.org\u003e",
 37978          "name": "libldap-2.4-2",
 37979          "version": "2.4.40+dfsg-1+deb8u2",
 37980          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.40\\+dfsg-1\\+deb8u2:*:*:*:*:*:*:*",
 37981          "purl": "pkg:deb/debian/libldap-2.4-2@2.4.40+dfsg-1+deb8u2?arch=amd64\u0026upstream=openldap\u0026distro=debian-8",
 37982          "swid": {
 37983            "attachment": {}
 37984          },
 37985          "pedigree": {},
 37986          "evidence": {},
 37987          "signature": {
 37988            "signature": {
 37989              "publicKey": {}
 37990            }
 37991          },
 37992          "modelCard": {
 37993            "modelParameters": {
 37994              "approach": {}
 37995            },
 37996            "quantitativeAnalysis": {
 37997              "graphics": {}
 37998            },
 37999            "considerations": {}
 38000          }
 38001        },
 38002        {
 38003          "type": "library",
 38004          "bom-ref": "pkg:deb/debian/liblocale-gettext-perl@1.05-8+b1?arch=amd64\u0026upstream=liblocale-gettext-perl%401.05-8\u0026distro=debian-8\u0026package-id=4ce555c27b8046dc",
 38005          "supplier": {},
 38006          "publisher": "Debian Perl Group \u003cpkg-perl-maintainers@lists.alioth.debian.org\u003e",
 38007          "name": "liblocale-gettext-perl",
 38008          "version": "1.05-8+b1",
 38009          "licenses": [
 38010            {
 38011              "license": {
 38012                "name": "Artistic"
 38013              }
 38014            },
 38015            {
 38016              "license": {
 38017                "id": "GPL-1.0-only"
 38018              }
 38019            },
 38020            {
 38021              "license": {
 38022                "id": "GPL-1.0-or-later"
 38023              }
 38024            }
 38025          ],
 38026          "cpe": "cpe:2.3:a:liblocale-gettext-perl:liblocale-gettext-perl:1.05-8\\+b1:*:*:*:*:*:*:*",
 38027          "purl": "pkg:deb/debian/liblocale-gettext-perl@1.05-8+b1?arch=amd64\u0026upstream=liblocale-gettext-perl%401.05-8\u0026distro=debian-8",
 38028          "swid": {
 38029            "attachment": {}
 38030          },
 38031          "pedigree": {},
 38032          "evidence": {},
 38033          "signature": {
 38034            "signature": {
 38035              "publicKey": {}
 38036            }
 38037          },
 38038          "modelCard": {
 38039            "modelParameters": {
 38040              "approach": {}
 38041            },
 38042            "quantitativeAnalysis": {
 38043              "graphics": {}
 38044            },
 38045            "considerations": {}
 38046          }
 38047        },
 38048        {
 38049          "type": "library",
 38050          "bom-ref": "pkg:deb/debian/liblsan0@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=7a8e04a0a1d56307",
 38051          "supplier": {},
 38052          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 38053          "name": "liblsan0",
 38054          "version": "4.9.2-10",
 38055          "licenses": [
 38056            {
 38057              "license": {
 38058                "name": "Artistic"
 38059              }
 38060            },
 38061            {
 38062              "license": {
 38063                "id": "GFDL-1.2-only"
 38064              }
 38065            },
 38066            {
 38067              "license": {
 38068                "name": "GPL"
 38069              }
 38070            },
 38071            {
 38072              "license": {
 38073                "id": "GPL-2.0-only"
 38074              }
 38075            },
 38076            {
 38077              "license": {
 38078                "id": "GPL-3.0-only"
 38079              }
 38080            }
 38081          ],
 38082          "cpe": "cpe:2.3:a:liblsan0:liblsan0:4.9.2-10:*:*:*:*:*:*:*",
 38083          "purl": "pkg:deb/debian/liblsan0@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 38084          "swid": {
 38085            "attachment": {}
 38086          },
 38087          "pedigree": {},
 38088          "evidence": {},
 38089          "signature": {
 38090            "signature": {
 38091              "publicKey": {}
 38092            }
 38093          },
 38094          "modelCard": {
 38095            "modelParameters": {
 38096              "approach": {}
 38097            },
 38098            "quantitativeAnalysis": {
 38099              "graphics": {}
 38100            },
 38101            "considerations": {}
 38102          }
 38103        },
 38104        {
 38105          "type": "library",
 38106          "bom-ref": "pkg:deb/debian/liblzma5@5.1.1alpha+20120614-2+b3?arch=amd64\u0026upstream=xz-utils%405.1.1alpha+20120614-2\u0026distro=debian-8\u0026package-id=7d02df5b0c5025c5",
 38107          "supplier": {},
 38108          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
 38109          "name": "liblzma5",
 38110          "version": "5.1.1alpha+20120614-2+b3",
 38111          "licenses": [
 38112            {
 38113              "license": {
 38114                "name": "Autoconf"
 38115              }
 38116            },
 38117            {
 38118              "license": {
 38119                "id": "GPL-2.0-only"
 38120              }
 38121            },
 38122            {
 38123              "license": {
 38124                "id": "GPL-2.0-or-later"
 38125              }
 38126            },
 38127            {
 38128              "license": {
 38129                "id": "GPL-3.0-only"
 38130              }
 38131            },
 38132            {
 38133              "license": {
 38134                "id": "LGPL-2.0-only"
 38135              }
 38136            },
 38137            {
 38138              "license": {
 38139                "id": "LGPL-2.1-only"
 38140              }
 38141            },
 38142            {
 38143              "license": {
 38144                "id": "LGPL-2.1-or-later"
 38145              }
 38146            },
 38147            {
 38148              "license": {
 38149                "name": "PD"
 38150              }
 38151            },
 38152            {
 38153              "license": {
 38154                "name": "PD-debian"
 38155              }
 38156            },
 38157            {
 38158              "license": {
 38159                "name": "config-h"
 38160              }
 38161            },
 38162            {
 38163              "license": {
 38164                "name": "noderivs"
 38165              }
 38166            },
 38167            {
 38168              "license": {
 38169                "name": "permissive-fsf"
 38170              }
 38171            },
 38172            {
 38173              "license": {
 38174                "name": "permissive-nowarranty"
 38175              }
 38176            },
 38177            {
 38178              "license": {
 38179                "name": "probably-PD"
 38180              }
 38181            }
 38182          ],
 38183          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.1.1alpha\\+20120614-2\\+b3:*:*:*:*:*:*:*",
 38184          "purl": "pkg:deb/debian/liblzma5@5.1.1alpha+20120614-2+b3?arch=amd64\u0026upstream=xz-utils%405.1.1alpha+20120614-2\u0026distro=debian-8",
 38185          "swid": {
 38186            "attachment": {}
 38187          },
 38188          "pedigree": {},
 38189          "evidence": {},
 38190          "signature": {
 38191            "signature": {
 38192              "publicKey": {}
 38193            }
 38194          },
 38195          "modelCard": {
 38196            "modelParameters": {
 38197              "approach": {}
 38198            },
 38199            "quantitativeAnalysis": {
 38200              "graphics": {}
 38201            },
 38202            "considerations": {}
 38203          }
 38204        },
 38205        {
 38206          "type": "library",
 38207          "bom-ref": "pkg:deb/debian/libmount1@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8\u0026package-id=986739dc167f2421",
 38208          "supplier": {},
 38209          "publisher": "Debian util-linux Maintainers \u003cah-util-linux@debian.org\u003e",
 38210          "name": "libmount1",
 38211          "version": "2.25.2-6",
 38212          "licenses": [
 38213            {
 38214              "license": {
 38215                "id": "BSD-2-Clause"
 38216              }
 38217            },
 38218            {
 38219              "license": {
 38220                "id": "BSD-3-Clause"
 38221              }
 38222            },
 38223            {
 38224              "license": {
 38225                "id": "BSD-4-Clause"
 38226              }
 38227            },
 38228            {
 38229              "license": {
 38230                "id": "GPL-2.0-only"
 38231              }
 38232            },
 38233            {
 38234              "license": {
 38235                "id": "GPL-2.0-or-later"
 38236              }
 38237            },
 38238            {
 38239              "license": {
 38240                "id": "GPL-3.0-only"
 38241              }
 38242            },
 38243            {
 38244              "license": {
 38245                "id": "GPL-3.0-or-later"
 38246              }
 38247            },
 38248            {
 38249              "license": {
 38250                "name": "LGPL"
 38251              }
 38252            },
 38253            {
 38254              "license": {
 38255                "id": "LGPL-2.0-only"
 38256              }
 38257            },
 38258            {
 38259              "license": {
 38260                "id": "LGPL-2.0-or-later"
 38261              }
 38262            },
 38263            {
 38264              "license": {
 38265                "id": "LGPL-2.1-only"
 38266              }
 38267            },
 38268            {
 38269              "license": {
 38270                "id": "LGPL-2.1-or-later"
 38271              }
 38272            },
 38273            {
 38274              "license": {
 38275                "id": "LGPL-3.0-only"
 38276              }
 38277            },
 38278            {
 38279              "license": {
 38280                "id": "LGPL-3.0-or-later"
 38281              }
 38282            },
 38283            {
 38284              "license": {
 38285                "id": "MIT"
 38286              }
 38287            },
 38288            {
 38289              "license": {
 38290                "name": "public-domain"
 38291              }
 38292            }
 38293          ],
 38294          "cpe": "cpe:2.3:a:libmount1:libmount1:2.25.2-6:*:*:*:*:*:*:*",
 38295          "purl": "pkg:deb/debian/libmount1@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8",
 38296          "swid": {
 38297            "attachment": {}
 38298          },
 38299          "pedigree": {},
 38300          "evidence": {},
 38301          "signature": {
 38302            "signature": {
 38303              "publicKey": {}
 38304            }
 38305          },
 38306          "modelCard": {
 38307            "modelParameters": {
 38308              "approach": {}
 38309            },
 38310            "quantitativeAnalysis": {
 38311              "graphics": {}
 38312            },
 38313            "considerations": {}
 38314          }
 38315        },
 38316        {
 38317          "type": "library",
 38318          "bom-ref": "pkg:deb/debian/libmpc3@1.0.2-1?arch=amd64\u0026upstream=mpclib3\u0026distro=debian-8\u0026package-id=575fe53adb300e06",
 38319          "supplier": {},
 38320          "publisher": "Laurent Fousse \u003clfousse@debian.org\u003e",
 38321          "name": "libmpc3",
 38322          "version": "1.0.2-1",
 38323          "licenses": [
 38324            {
 38325              "license": {
 38326                "id": "LGPL-2.1-only"
 38327              }
 38328            }
 38329          ],
 38330          "cpe": "cpe:2.3:a:libmpc3:libmpc3:1.0.2-1:*:*:*:*:*:*:*",
 38331          "purl": "pkg:deb/debian/libmpc3@1.0.2-1?arch=amd64\u0026upstream=mpclib3\u0026distro=debian-8",
 38332          "swid": {
 38333            "attachment": {}
 38334          },
 38335          "pedigree": {},
 38336          "evidence": {},
 38337          "signature": {
 38338            "signature": {
 38339              "publicKey": {}
 38340            }
 38341          },
 38342          "modelCard": {
 38343            "modelParameters": {
 38344              "approach": {}
 38345            },
 38346            "quantitativeAnalysis": {
 38347              "graphics": {}
 38348            },
 38349            "considerations": {}
 38350          }
 38351        },
 38352        {
 38353          "type": "library",
 38354          "bom-ref": "pkg:deb/debian/libmpfr4@3.1.2-2?arch=amd64\u0026upstream=mpfr4\u0026distro=debian-8\u0026package-id=fa704f648700157f",
 38355          "supplier": {},
 38356          "publisher": "Debian QA Group \u003cpackages@qa.debian.org\u003e",
 38357          "name": "libmpfr4",
 38358          "version": "3.1.2-2",
 38359          "licenses": [
 38360            {
 38361              "license": {
 38362                "id": "LGPL-3.0-only"
 38363              }
 38364            }
 38365          ],
 38366          "cpe": "cpe:2.3:a:libmpfr4:libmpfr4:3.1.2-2:*:*:*:*:*:*:*",
 38367          "purl": "pkg:deb/debian/libmpfr4@3.1.2-2?arch=amd64\u0026upstream=mpfr4\u0026distro=debian-8",
 38368          "swid": {
 38369            "attachment": {}
 38370          },
 38371          "pedigree": {},
 38372          "evidence": {},
 38373          "signature": {
 38374            "signature": {
 38375              "publicKey": {}
 38376            }
 38377          },
 38378          "modelCard": {
 38379            "modelParameters": {
 38380              "approach": {}
 38381            },
 38382            "quantitativeAnalysis": {
 38383              "graphics": {}
 38384            },
 38385            "considerations": {}
 38386          }
 38387        },
 38388        {
 38389          "type": "library",
 38390          "bom-ref": "pkg:deb/debian/libncurses5@5.9+20140913-1+b1?arch=amd64\u0026upstream=ncurses%405.9+20140913-1\u0026distro=debian-8\u0026package-id=f45ee8d9abeef235",
 38391          "supplier": {},
 38392          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 38393          "name": "libncurses5",
 38394          "version": "5.9+20140913-1+b1",
 38395          "cpe": "cpe:2.3:a:libncurses5:libncurses5:5.9\\+20140913-1\\+b1:*:*:*:*:*:*:*",
 38396          "purl": "pkg:deb/debian/libncurses5@5.9+20140913-1+b1?arch=amd64\u0026upstream=ncurses%405.9+20140913-1\u0026distro=debian-8",
 38397          "swid": {
 38398            "attachment": {}
 38399          },
 38400          "pedigree": {},
 38401          "evidence": {},
 38402          "signature": {
 38403            "signature": {
 38404              "publicKey": {}
 38405            }
 38406          },
 38407          "modelCard": {
 38408            "modelParameters": {
 38409              "approach": {}
 38410            },
 38411            "quantitativeAnalysis": {
 38412              "graphics": {}
 38413            },
 38414            "considerations": {}
 38415          }
 38416        },
 38417        {
 38418          "type": "library",
 38419          "bom-ref": "pkg:deb/debian/libncursesw5@5.9+20140913-1+b1?arch=amd64\u0026upstream=ncurses%405.9+20140913-1\u0026distro=debian-8\u0026package-id=6d9efa5c2292b5f2",
 38420          "supplier": {},
 38421          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 38422          "name": "libncursesw5",
 38423          "version": "5.9+20140913-1+b1",
 38424          "cpe": "cpe:2.3:a:libncursesw5:libncursesw5:5.9\\+20140913-1\\+b1:*:*:*:*:*:*:*",
 38425          "purl": "pkg:deb/debian/libncursesw5@5.9+20140913-1+b1?arch=amd64\u0026upstream=ncurses%405.9+20140913-1\u0026distro=debian-8",
 38426          "swid": {
 38427            "attachment": {}
 38428          },
 38429          "pedigree": {},
 38430          "evidence": {},
 38431          "signature": {
 38432            "signature": {
 38433              "publicKey": {}
 38434            }
 38435          },
 38436          "modelCard": {
 38437            "modelParameters": {
 38438              "approach": {}
 38439            },
 38440            "quantitativeAnalysis": {
 38441              "graphics": {}
 38442            },
 38443            "considerations": {}
 38444          }
 38445        },
 38446        {
 38447          "type": "library",
 38448          "bom-ref": "pkg:deb/debian/libnettle4@2.7.1-5+deb8u1?arch=amd64\u0026upstream=nettle\u0026distro=debian-8\u0026package-id=7a916d943ead6789",
 38449          "supplier": {},
 38450          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
 38451          "name": "libnettle4",
 38452          "version": "2.7.1-5+deb8u1",
 38453          "licenses": [
 38454            {
 38455              "license": {
 38456                "name": "GAP"
 38457              }
 38458            },
 38459            {
 38460              "license": {
 38461                "name": "GPL"
 38462              }
 38463            },
 38464            {
 38465              "license": {
 38466                "id": "GPL-2.0-only"
 38467              }
 38468            },
 38469            {
 38470              "license": {
 38471                "id": "GPL-2.0-or-later"
 38472              }
 38473            },
 38474            {
 38475              "license": {
 38476                "name": "LGPL"
 38477              }
 38478            },
 38479            {
 38480              "license": {
 38481                "id": "LGPL-2.0-only"
 38482              }
 38483            },
 38484            {
 38485              "license": {
 38486                "id": "LGPL-2.0-or-later"
 38487              }
 38488            },
 38489            {
 38490              "license": {
 38491                "id": "LGPL-2.1-or-later"
 38492              }
 38493            },
 38494            {
 38495              "license": {
 38496                "name": "other"
 38497              }
 38498            },
 38499            {
 38500              "license": {
 38501                "name": "public-domain"
 38502              }
 38503            }
 38504          ],
 38505          "cpe": "cpe:2.3:a:libnettle4:libnettle4:2.7.1-5\\+deb8u1:*:*:*:*:*:*:*",
 38506          "purl": "pkg:deb/debian/libnettle4@2.7.1-5+deb8u1?arch=amd64\u0026upstream=nettle\u0026distro=debian-8",
 38507          "swid": {
 38508            "attachment": {}
 38509          },
 38510          "pedigree": {},
 38511          "evidence": {},
 38512          "signature": {
 38513            "signature": {
 38514              "publicKey": {}
 38515            }
 38516          },
 38517          "modelCard": {
 38518            "modelParameters": {
 38519              "approach": {}
 38520            },
 38521            "quantitativeAnalysis": {
 38522              "graphics": {}
 38523            },
 38524            "considerations": {}
 38525          }
 38526        },
 38527        {
 38528          "type": "library",
 38529          "bom-ref": "pkg:deb/debian/libp11-kit0@0.20.7-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-8\u0026package-id=33ec5cb01a8eacdf",
 38530          "supplier": {},
 38531          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 38532          "name": "libp11-kit0",
 38533          "version": "0.20.7-1",
 38534          "licenses": [
 38535            {
 38536              "license": {
 38537                "id": "BSD-3-Clause"
 38538              }
 38539            },
 38540            {
 38541              "license": {
 38542                "name": "This"
 38543              }
 38544            }
 38545          ],
 38546          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.20.7-1:*:*:*:*:*:*:*",
 38547          "purl": "pkg:deb/debian/libp11-kit0@0.20.7-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-8",
 38548          "swid": {
 38549            "attachment": {}
 38550          },
 38551          "pedigree": {},
 38552          "evidence": {},
 38553          "signature": {
 38554            "signature": {
 38555              "publicKey": {}
 38556            }
 38557          },
 38558          "modelCard": {
 38559            "modelParameters": {
 38560              "approach": {}
 38561            },
 38562            "quantitativeAnalysis": {
 38563              "graphics": {}
 38564            },
 38565            "considerations": {}
 38566          }
 38567        },
 38568        {
 38569          "type": "library",
 38570          "bom-ref": "pkg:deb/debian/libpam-modules@1.1.8-3.1+deb8u1+b1?arch=amd64\u0026upstream=pam%401.1.8-3.1+deb8u1\u0026distro=debian-8\u0026package-id=b2984a1b0fb2d6f0",
 38571          "supplier": {},
 38572          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 38573          "name": "libpam-modules",
 38574          "version": "1.1.8-3.1+deb8u1+b1",
 38575          "licenses": [
 38576            {
 38577              "license": {
 38578                "name": "GPL"
 38579              }
 38580            }
 38581          ],
 38582          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.1.8-3.1\\+deb8u1\\+b1:*:*:*:*:*:*:*",
 38583          "purl": "pkg:deb/debian/libpam-modules@1.1.8-3.1+deb8u1+b1?arch=amd64\u0026upstream=pam%401.1.8-3.1+deb8u1\u0026distro=debian-8",
 38584          "swid": {
 38585            "attachment": {}
 38586          },
 38587          "pedigree": {},
 38588          "evidence": {},
 38589          "signature": {
 38590            "signature": {
 38591              "publicKey": {}
 38592            }
 38593          },
 38594          "modelCard": {
 38595            "modelParameters": {
 38596              "approach": {}
 38597            },
 38598            "quantitativeAnalysis": {
 38599              "graphics": {}
 38600            },
 38601            "considerations": {}
 38602          }
 38603        },
 38604        {
 38605          "type": "library",
 38606          "bom-ref": "pkg:deb/debian/libpam-modules-bin@1.1.8-3.1+deb8u1+b1?arch=amd64\u0026upstream=pam%401.1.8-3.1+deb8u1\u0026distro=debian-8\u0026package-id=96aa873332f50408",
 38607          "supplier": {},
 38608          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 38609          "name": "libpam-modules-bin",
 38610          "version": "1.1.8-3.1+deb8u1+b1",
 38611          "licenses": [
 38612            {
 38613              "license": {
 38614                "name": "GPL"
 38615              }
 38616            }
 38617          ],
 38618          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.1.8-3.1\\+deb8u1\\+b1:*:*:*:*:*:*:*",
 38619          "purl": "pkg:deb/debian/libpam-modules-bin@1.1.8-3.1+deb8u1+b1?arch=amd64\u0026upstream=pam%401.1.8-3.1+deb8u1\u0026distro=debian-8",
 38620          "swid": {
 38621            "attachment": {}
 38622          },
 38623          "pedigree": {},
 38624          "evidence": {},
 38625          "signature": {
 38626            "signature": {
 38627              "publicKey": {}
 38628            }
 38629          },
 38630          "modelCard": {
 38631            "modelParameters": {
 38632              "approach": {}
 38633            },
 38634            "quantitativeAnalysis": {
 38635              "graphics": {}
 38636            },
 38637            "considerations": {}
 38638          }
 38639        },
 38640        {
 38641          "type": "library",
 38642          "bom-ref": "pkg:deb/debian/libpam-runtime@1.1.8-3.1+deb8u1?arch=all\u0026upstream=pam\u0026distro=debian-8\u0026package-id=bc9df2b43fb96d84",
 38643          "supplier": {},
 38644          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 38645          "name": "libpam-runtime",
 38646          "version": "1.1.8-3.1+deb8u1",
 38647          "licenses": [
 38648            {
 38649              "license": {
 38650                "name": "GPL"
 38651              }
 38652            }
 38653          ],
 38654          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.1.8-3.1\\+deb8u1:*:*:*:*:*:*:*",
 38655          "purl": "pkg:deb/debian/libpam-runtime@1.1.8-3.1+deb8u1?arch=all\u0026upstream=pam\u0026distro=debian-8",
 38656          "swid": {
 38657            "attachment": {}
 38658          },
 38659          "pedigree": {},
 38660          "evidence": {},
 38661          "signature": {
 38662            "signature": {
 38663              "publicKey": {}
 38664            }
 38665          },
 38666          "modelCard": {
 38667            "modelParameters": {
 38668              "approach": {}
 38669            },
 38670            "quantitativeAnalysis": {
 38671              "graphics": {}
 38672            },
 38673            "considerations": {}
 38674          }
 38675        },
 38676        {
 38677          "type": "library",
 38678          "bom-ref": "pkg:deb/debian/libpam0g@1.1.8-3.1+deb8u1+b1?arch=amd64\u0026upstream=pam%401.1.8-3.1+deb8u1\u0026distro=debian-8\u0026package-id=dc90e32795f9bd0f",
 38679          "supplier": {},
 38680          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 38681          "name": "libpam0g",
 38682          "version": "1.1.8-3.1+deb8u1+b1",
 38683          "licenses": [
 38684            {
 38685              "license": {
 38686                "name": "GPL"
 38687              }
 38688            }
 38689          ],
 38690          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.1.8-3.1\\+deb8u1\\+b1:*:*:*:*:*:*:*",
 38691          "purl": "pkg:deb/debian/libpam0g@1.1.8-3.1+deb8u1+b1?arch=amd64\u0026upstream=pam%401.1.8-3.1+deb8u1\u0026distro=debian-8",
 38692          "swid": {
 38693            "attachment": {}
 38694          },
 38695          "pedigree": {},
 38696          "evidence": {},
 38697          "signature": {
 38698            "signature": {
 38699              "publicKey": {}
 38700            }
 38701          },
 38702          "modelCard": {
 38703            "modelParameters": {
 38704              "approach": {}
 38705            },
 38706            "quantitativeAnalysis": {
 38707              "graphics": {}
 38708            },
 38709            "considerations": {}
 38710          }
 38711        },
 38712        {
 38713          "type": "library",
 38714          "bom-ref": "pkg:deb/debian/libpcre3@2:8.35-3.3+deb8u4?arch=amd64\u0026upstream=pcre3\u0026distro=debian-8\u0026package-id=229a1fd4bc24dac8",
 38715          "supplier": {},
 38716          "publisher": "Mark Baker \u003cmark@mnb.org.uk\u003e",
 38717          "name": "libpcre3",
 38718          "version": "2:8.35-3.3+deb8u4",
 38719          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.35-3.3\\+deb8u4:*:*:*:*:*:*:*",
 38720          "purl": "pkg:deb/debian/libpcre3@2:8.35-3.3+deb8u4?arch=amd64\u0026upstream=pcre3\u0026distro=debian-8",
 38721          "swid": {
 38722            "attachment": {}
 38723          },
 38724          "pedigree": {},
 38725          "evidence": {},
 38726          "signature": {
 38727            "signature": {
 38728              "publicKey": {}
 38729            }
 38730          },
 38731          "modelCard": {
 38732            "modelParameters": {
 38733              "approach": {}
 38734            },
 38735            "quantitativeAnalysis": {
 38736              "graphics": {}
 38737            },
 38738            "considerations": {}
 38739          }
 38740        },
 38741        {
 38742          "type": "library",
 38743          "bom-ref": "pkg:deb/debian/libprocps3@2:3.3.9-9?arch=amd64\u0026upstream=procps\u0026distro=debian-8\u0026package-id=64628c42729369d7",
 38744          "supplier": {},
 38745          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 38746          "name": "libprocps3",
 38747          "version": "2:3.3.9-9",
 38748          "licenses": [
 38749            {
 38750              "license": {
 38751                "id": "GPL-2.0-only"
 38752              }
 38753            },
 38754            {
 38755              "license": {
 38756                "id": "LGPL-2.0-only"
 38757              }
 38758            }
 38759          ],
 38760          "cpe": "cpe:2.3:a:libprocps3:libprocps3:2\\:3.3.9-9:*:*:*:*:*:*:*",
 38761          "purl": "pkg:deb/debian/libprocps3@2:3.3.9-9?arch=amd64\u0026upstream=procps\u0026distro=debian-8",
 38762          "swid": {
 38763            "attachment": {}
 38764          },
 38765          "pedigree": {},
 38766          "evidence": {},
 38767          "signature": {
 38768            "signature": {
 38769              "publicKey": {}
 38770            }
 38771          },
 38772          "modelCard": {
 38773            "modelParameters": {
 38774              "approach": {}
 38775            },
 38776            "quantitativeAnalysis": {
 38777              "graphics": {}
 38778            },
 38779            "considerations": {}
 38780          }
 38781        },
 38782        {
 38783          "type": "library",
 38784          "bom-ref": "pkg:deb/debian/libpsl0@0.5.1-1?arch=amd64\u0026upstream=libpsl\u0026distro=debian-8\u0026package-id=eab044b7226186e6",
 38785          "supplier": {},
 38786          "publisher": "Tim Rühsen \u003ctim.ruehsen@gmx.de\u003e",
 38787          "name": "libpsl0",
 38788          "version": "0.5.1-1",
 38789          "licenses": [
 38790            {
 38791              "license": {
 38792                "name": "CC0"
 38793              }
 38794            },
 38795            {
 38796              "license": {
 38797                "id": "MIT"
 38798              }
 38799            },
 38800            {
 38801              "license": {
 38802                "id": "MPL-2.0"
 38803              }
 38804            }
 38805          ],
 38806          "cpe": "cpe:2.3:a:libpsl0:libpsl0:0.5.1-1:*:*:*:*:*:*:*",
 38807          "purl": "pkg:deb/debian/libpsl0@0.5.1-1?arch=amd64\u0026upstream=libpsl\u0026distro=debian-8",
 38808          "swid": {
 38809            "attachment": {}
 38810          },
 38811          "pedigree": {},
 38812          "evidence": {},
 38813          "signature": {
 38814            "signature": {
 38815              "publicKey": {}
 38816            }
 38817          },
 38818          "modelCard": {
 38819            "modelParameters": {
 38820              "approach": {}
 38821            },
 38822            "quantitativeAnalysis": {
 38823              "graphics": {}
 38824            },
 38825            "considerations": {}
 38826          }
 38827        },
 38828        {
 38829          "type": "library",
 38830          "bom-ref": "pkg:deb/debian/libpython-stdlib@2.7.9-1?arch=amd64\u0026upstream=python-defaults\u0026distro=debian-8\u0026package-id=c2fa87f45ec3753b",
 38831          "supplier": {},
 38832          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 38833          "name": "libpython-stdlib",
 38834          "version": "2.7.9-1",
 38835          "cpe": "cpe:2.3:a:libpython-stdlib:libpython-stdlib:2.7.9-1:*:*:*:*:*:*:*",
 38836          "purl": "pkg:deb/debian/libpython-stdlib@2.7.9-1?arch=amd64\u0026upstream=python-defaults\u0026distro=debian-8",
 38837          "swid": {
 38838            "attachment": {}
 38839          },
 38840          "pedigree": {},
 38841          "evidence": {},
 38842          "signature": {
 38843            "signature": {
 38844              "publicKey": {}
 38845            }
 38846          },
 38847          "modelCard": {
 38848            "modelParameters": {
 38849              "approach": {}
 38850            },
 38851            "quantitativeAnalysis": {
 38852              "graphics": {}
 38853            },
 38854            "considerations": {}
 38855          }
 38856        },
 38857        {
 38858          "type": "library",
 38859          "bom-ref": "pkg:deb/debian/libpython2.7-minimal@2.7.9-2?arch=amd64\u0026upstream=python2.7\u0026distro=debian-8\u0026package-id=63259999336ff6a4",
 38860          "supplier": {},
 38861          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 38862          "name": "libpython2.7-minimal",
 38863          "version": "2.7.9-2",
 38864          "licenses": [
 38865            {
 38866              "license": {
 38867                "name": "#"
 38868              }
 38869            },
 38870            {
 38871              "license": {
 38872                "id": "Apache-2.0"
 38873              }
 38874            },
 38875            {
 38876              "license": {
 38877                "id": "GPL-2.0-only"
 38878              }
 38879            },
 38880            {
 38881              "license": {
 38882                "name": "Permission"
 38883              }
 38884            },
 38885            {
 38886              "license": {
 38887                "name": "This"
 38888              }
 38889            }
 38890          ],
 38891          "cpe": "cpe:2.3:a:libpython2.7-minimal:libpython2.7-minimal:2.7.9-2:*:*:*:*:*:*:*",
 38892          "purl": "pkg:deb/debian/libpython2.7-minimal@2.7.9-2?arch=amd64\u0026upstream=python2.7\u0026distro=debian-8",
 38893          "swid": {
 38894            "attachment": {}
 38895          },
 38896          "pedigree": {},
 38897          "evidence": {},
 38898          "signature": {
 38899            "signature": {
 38900              "publicKey": {}
 38901            }
 38902          },
 38903          "modelCard": {
 38904            "modelParameters": {
 38905              "approach": {}
 38906            },
 38907            "quantitativeAnalysis": {
 38908              "graphics": {}
 38909            },
 38910            "considerations": {}
 38911          }
 38912        },
 38913        {
 38914          "type": "library",
 38915          "bom-ref": "pkg:deb/debian/libpython2.7-stdlib@2.7.9-2?arch=amd64\u0026upstream=python2.7\u0026distro=debian-8\u0026package-id=eaf3ad8b8de0da62",
 38916          "supplier": {},
 38917          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 38918          "name": "libpython2.7-stdlib",
 38919          "version": "2.7.9-2",
 38920          "licenses": [
 38921            {
 38922              "license": {
 38923                "name": "#"
 38924              }
 38925            },
 38926            {
 38927              "license": {
 38928                "id": "Apache-2.0"
 38929              }
 38930            },
 38931            {
 38932              "license": {
 38933                "id": "GPL-2.0-only"
 38934              }
 38935            },
 38936            {
 38937              "license": {
 38938                "name": "Permission"
 38939              }
 38940            },
 38941            {
 38942              "license": {
 38943                "name": "This"
 38944              }
 38945            }
 38946          ],
 38947          "cpe": "cpe:2.3:a:libpython2.7-stdlib:libpython2.7-stdlib:2.7.9-2:*:*:*:*:*:*:*",
 38948          "purl": "pkg:deb/debian/libpython2.7-stdlib@2.7.9-2?arch=amd64\u0026upstream=python2.7\u0026distro=debian-8",
 38949          "swid": {
 38950            "attachment": {}
 38951          },
 38952          "pedigree": {},
 38953          "evidence": {},
 38954          "signature": {
 38955            "signature": {
 38956              "publicKey": {}
 38957            }
 38958          },
 38959          "modelCard": {
 38960            "modelParameters": {
 38961              "approach": {}
 38962            },
 38963            "quantitativeAnalysis": {
 38964              "graphics": {}
 38965            },
 38966            "considerations": {}
 38967          }
 38968        },
 38969        {
 38970          "type": "library",
 38971          "bom-ref": "pkg:deb/debian/libquadmath0@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=bda2085e3d427d3a",
 38972          "supplier": {},
 38973          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 38974          "name": "libquadmath0",
 38975          "version": "4.9.2-10",
 38976          "licenses": [
 38977            {
 38978              "license": {
 38979                "name": "Artistic"
 38980              }
 38981            },
 38982            {
 38983              "license": {
 38984                "id": "GFDL-1.2-only"
 38985              }
 38986            },
 38987            {
 38988              "license": {
 38989                "name": "GPL"
 38990              }
 38991            },
 38992            {
 38993              "license": {
 38994                "id": "GPL-2.0-only"
 38995              }
 38996            },
 38997            {
 38998              "license": {
 38999                "id": "GPL-3.0-only"
 39000              }
 39001            }
 39002          ],
 39003          "cpe": "cpe:2.3:a:libquadmath0:libquadmath0:4.9.2-10:*:*:*:*:*:*:*",
 39004          "purl": "pkg:deb/debian/libquadmath0@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 39005          "swid": {
 39006            "attachment": {}
 39007          },
 39008          "pedigree": {},
 39009          "evidence": {},
 39010          "signature": {
 39011            "signature": {
 39012              "publicKey": {}
 39013            }
 39014          },
 39015          "modelCard": {
 39016            "modelParameters": {
 39017              "approach": {}
 39018            },
 39019            "quantitativeAnalysis": {
 39020              "graphics": {}
 39021            },
 39022            "considerations": {}
 39023          }
 39024        },
 39025        {
 39026          "type": "library",
 39027          "bom-ref": "pkg:deb/debian/libreadline6@6.3-8+b3?arch=amd64\u0026upstream=readline6%406.3-8\u0026distro=debian-8\u0026package-id=fe33e859854bfe7a",
 39028          "supplier": {},
 39029          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 39030          "name": "libreadline6",
 39031          "version": "6.3-8+b3",
 39032          "licenses": [
 39033            {
 39034              "license": {
 39035                "id": "GPL-3.0-only"
 39036              }
 39037            }
 39038          ],
 39039          "cpe": "cpe:2.3:a:libreadline6:libreadline6:6.3-8\\+b3:*:*:*:*:*:*:*",
 39040          "purl": "pkg:deb/debian/libreadline6@6.3-8+b3?arch=amd64\u0026upstream=readline6%406.3-8\u0026distro=debian-8",
 39041          "swid": {
 39042            "attachment": {}
 39043          },
 39044          "pedigree": {},
 39045          "evidence": {},
 39046          "signature": {
 39047            "signature": {
 39048              "publicKey": {}
 39049            }
 39050          },
 39051          "modelCard": {
 39052            "modelParameters": {
 39053              "approach": {}
 39054            },
 39055            "quantitativeAnalysis": {
 39056              "graphics": {}
 39057            },
 39058            "considerations": {}
 39059          }
 39060        },
 39061        {
 39062          "type": "library",
 39063          "bom-ref": "pkg:deb/debian/librtmp1@2.4+20150115.gita107cef-1?arch=amd64\u0026upstream=rtmpdump\u0026distro=debian-8\u0026package-id=58f9a6c3be9cdc18",
 39064          "supplier": {},
 39065          "publisher": "Debian Multimedia Maintainers \u003cpkg-multimedia-maintainers@lists.alioth.debian.org\u003e",
 39066          "name": "librtmp1",
 39067          "version": "2.4+20150115.gita107cef-1",
 39068          "licenses": [
 39069            {
 39070              "license": {
 39071                "id": "GPL-2.0-only"
 39072              }
 39073            },
 39074            {
 39075              "license": {
 39076                "id": "LGPL-2.1-only"
 39077              }
 39078            }
 39079          ],
 39080          "cpe": "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20150115.gita107cef-1:*:*:*:*:*:*:*",
 39081          "purl": "pkg:deb/debian/librtmp1@2.4+20150115.gita107cef-1?arch=amd64\u0026upstream=rtmpdump\u0026distro=debian-8",
 39082          "swid": {
 39083            "attachment": {}
 39084          },
 39085          "pedigree": {},
 39086          "evidence": {},
 39087          "signature": {
 39088            "signature": {
 39089              "publicKey": {}
 39090            }
 39091          },
 39092          "modelCard": {
 39093            "modelParameters": {
 39094              "approach": {}
 39095            },
 39096            "quantitativeAnalysis": {
 39097              "graphics": {}
 39098            },
 39099            "considerations": {}
 39100          }
 39101        },
 39102        {
 39103          "type": "library",
 39104          "bom-ref": "pkg:deb/debian/libsasl2-2@2.1.26.dfsg1-13+deb8u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-8\u0026package-id=e4601aa0707e435",
 39105          "supplier": {},
 39106          "publisher": "Debian Cyrus SASL Team \u003cpkg-cyrus-sasl2-debian-devel@lists.alioth.debian.org\u003e",
 39107          "name": "libsasl2-2",
 39108          "version": "2.1.26.dfsg1-13+deb8u1",
 39109          "licenses": [
 39110            {
 39111              "license": {
 39112                "id": "BSD-4-Clause"
 39113              }
 39114            },
 39115            {
 39116              "license": {
 39117                "id": "GPL-2.0-only"
 39118              }
 39119            },
 39120            {
 39121              "license": {
 39122                "id": "GPL-2.0-or-later"
 39123              }
 39124            },
 39125            {
 39126              "license": {
 39127                "id": "GPL-3.0-only"
 39128              }
 39129            },
 39130            {
 39131              "license": {
 39132                "id": "GPL-3.0-or-later"
 39133              }
 39134            }
 39135          ],
 39136          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.26.dfsg1-13\\+deb8u1:*:*:*:*:*:*:*",
 39137          "purl": "pkg:deb/debian/libsasl2-2@2.1.26.dfsg1-13+deb8u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-8",
 39138          "swid": {
 39139            "attachment": {}
 39140          },
 39141          "pedigree": {},
 39142          "evidence": {},
 39143          "signature": {
 39144            "signature": {
 39145              "publicKey": {}
 39146            }
 39147          },
 39148          "modelCard": {
 39149            "modelParameters": {
 39150              "approach": {}
 39151            },
 39152            "quantitativeAnalysis": {
 39153              "graphics": {}
 39154            },
 39155            "considerations": {}
 39156          }
 39157        },
 39158        {
 39159          "type": "library",
 39160          "bom-ref": "pkg:deb/debian/libsasl2-modules-db@2.1.26.dfsg1-13+deb8u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-8\u0026package-id=a6169bf3b7454f69",
 39161          "supplier": {},
 39162          "publisher": "Debian Cyrus SASL Team \u003cpkg-cyrus-sasl2-debian-devel@lists.alioth.debian.org\u003e",
 39163          "name": "libsasl2-modules-db",
 39164          "version": "2.1.26.dfsg1-13+deb8u1",
 39165          "licenses": [
 39166            {
 39167              "license": {
 39168                "id": "BSD-4-Clause"
 39169              }
 39170            },
 39171            {
 39172              "license": {
 39173                "id": "GPL-2.0-only"
 39174              }
 39175            },
 39176            {
 39177              "license": {
 39178                "id": "GPL-2.0-or-later"
 39179              }
 39180            },
 39181            {
 39182              "license": {
 39183                "id": "GPL-3.0-only"
 39184              }
 39185            },
 39186            {
 39187              "license": {
 39188                "id": "GPL-3.0-or-later"
 39189              }
 39190            }
 39191          ],
 39192          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.26.dfsg1-13\\+deb8u1:*:*:*:*:*:*:*",
 39193          "purl": "pkg:deb/debian/libsasl2-modules-db@2.1.26.dfsg1-13+deb8u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-8",
 39194          "swid": {
 39195            "attachment": {}
 39196          },
 39197          "pedigree": {},
 39198          "evidence": {},
 39199          "signature": {
 39200            "signature": {
 39201              "publicKey": {}
 39202            }
 39203          },
 39204          "modelCard": {
 39205            "modelParameters": {
 39206              "approach": {}
 39207            },
 39208            "quantitativeAnalysis": {
 39209              "graphics": {}
 39210            },
 39211            "considerations": {}
 39212          }
 39213        },
 39214        {
 39215          "type": "library",
 39216          "bom-ref": "pkg:deb/debian/libselinux1@2.3-2?arch=amd64\u0026upstream=libselinux\u0026distro=debian-8\u0026package-id=c5ff2746e8d2666c",
 39217          "supplier": {},
 39218          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 39219          "name": "libselinux1",
 39220          "version": "2.3-2",
 39221          "licenses": [
 39222            {
 39223              "license": {
 39224                "id": "GPL-2.0-only"
 39225              }
 39226            },
 39227            {
 39228              "license": {
 39229                "id": "LGPL-2.1-only"
 39230              }
 39231            }
 39232          ],
 39233          "cpe": "cpe:2.3:a:libselinux1:libselinux1:2.3-2:*:*:*:*:*:*:*",
 39234          "purl": "pkg:deb/debian/libselinux1@2.3-2?arch=amd64\u0026upstream=libselinux\u0026distro=debian-8",
 39235          "swid": {
 39236            "attachment": {}
 39237          },
 39238          "pedigree": {},
 39239          "evidence": {},
 39240          "signature": {
 39241            "signature": {
 39242              "publicKey": {}
 39243            }
 39244          },
 39245          "modelCard": {
 39246            "modelParameters": {
 39247              "approach": {}
 39248            },
 39249            "quantitativeAnalysis": {
 39250              "graphics": {}
 39251            },
 39252            "considerations": {}
 39253          }
 39254        },
 39255        {
 39256          "type": "library",
 39257          "bom-ref": "pkg:deb/debian/libsemanage-common@2.3-1?arch=all\u0026upstream=libsemanage\u0026distro=debian-8\u0026package-id=58717965385c5d79",
 39258          "supplier": {},
 39259          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 39260          "name": "libsemanage-common",
 39261          "version": "2.3-1",
 39262          "licenses": [
 39263            {
 39264              "license": {
 39265                "name": "GPL"
 39266              }
 39267            },
 39268            {
 39269              "license": {
 39270                "name": "LGPL"
 39271              }
 39272            }
 39273          ],
 39274          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:2.3-1:*:*:*:*:*:*:*",
 39275          "purl": "pkg:deb/debian/libsemanage-common@2.3-1?arch=all\u0026upstream=libsemanage\u0026distro=debian-8",
 39276          "swid": {
 39277            "attachment": {}
 39278          },
 39279          "pedigree": {},
 39280          "evidence": {},
 39281          "signature": {
 39282            "signature": {
 39283              "publicKey": {}
 39284            }
 39285          },
 39286          "modelCard": {
 39287            "modelParameters": {
 39288              "approach": {}
 39289            },
 39290            "quantitativeAnalysis": {
 39291              "graphics": {}
 39292            },
 39293            "considerations": {}
 39294          }
 39295        },
 39296        {
 39297          "type": "library",
 39298          "bom-ref": "pkg:deb/debian/libsemanage1@2.3-1+b1?arch=amd64\u0026upstream=libsemanage%402.3-1\u0026distro=debian-8\u0026package-id=ad4578dab5387f60",
 39299          "supplier": {},
 39300          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 39301          "name": "libsemanage1",
 39302          "version": "2.3-1+b1",
 39303          "licenses": [
 39304            {
 39305              "license": {
 39306                "name": "GPL"
 39307              }
 39308            },
 39309            {
 39310              "license": {
 39311                "name": "LGPL"
 39312              }
 39313            }
 39314          ],
 39315          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:2.3-1\\+b1:*:*:*:*:*:*:*",
 39316          "purl": "pkg:deb/debian/libsemanage1@2.3-1+b1?arch=amd64\u0026upstream=libsemanage%402.3-1\u0026distro=debian-8",
 39317          "swid": {
 39318            "attachment": {}
 39319          },
 39320          "pedigree": {},
 39321          "evidence": {},
 39322          "signature": {
 39323            "signature": {
 39324              "publicKey": {}
 39325            }
 39326          },
 39327          "modelCard": {
 39328            "modelParameters": {
 39329              "approach": {}
 39330            },
 39331            "quantitativeAnalysis": {
 39332              "graphics": {}
 39333            },
 39334            "considerations": {}
 39335          }
 39336        },
 39337        {
 39338          "type": "library",
 39339          "bom-ref": "pkg:deb/debian/libsepol1@2.3-2?arch=amd64\u0026upstream=libsepol\u0026distro=debian-8\u0026package-id=9de354dab38a4dea",
 39340          "supplier": {},
 39341          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 39342          "name": "libsepol1",
 39343          "version": "2.3-2",
 39344          "licenses": [
 39345            {
 39346              "license": {
 39347                "name": "GPL"
 39348              }
 39349            },
 39350            {
 39351              "license": {
 39352                "name": "LGPL"
 39353              }
 39354            }
 39355          ],
 39356          "cpe": "cpe:2.3:a:libsepol1:libsepol1:2.3-2:*:*:*:*:*:*:*",
 39357          "purl": "pkg:deb/debian/libsepol1@2.3-2?arch=amd64\u0026upstream=libsepol\u0026distro=debian-8",
 39358          "swid": {
 39359            "attachment": {}
 39360          },
 39361          "pedigree": {},
 39362          "evidence": {},
 39363          "signature": {
 39364            "signature": {
 39365              "publicKey": {}
 39366            }
 39367          },
 39368          "modelCard": {
 39369            "modelParameters": {
 39370              "approach": {}
 39371            },
 39372            "quantitativeAnalysis": {
 39373              "graphics": {}
 39374            },
 39375            "considerations": {}
 39376          }
 39377        },
 39378        {
 39379          "type": "library",
 39380          "bom-ref": "pkg:deb/debian/libserf-1-1@1.3.8-1?arch=amd64\u0026upstream=serf\u0026distro=debian-8\u0026package-id=cd47cad2fb07c74f",
 39381          "supplier": {},
 39382          "publisher": "Peter Samuelson \u003cpeter@p12n.org\u003e",
 39383          "name": "libserf-1-1",
 39384          "version": "1.3.8-1",
 39385          "licenses": [
 39386            {
 39387              "license": {
 39388                "id": "Apache-2.0"
 39389              }
 39390            }
 39391          ],
 39392          "cpe": "cpe:2.3:a:libserf-1-1:libserf-1-1:1.3.8-1:*:*:*:*:*:*:*",
 39393          "purl": "pkg:deb/debian/libserf-1-1@1.3.8-1?arch=amd64\u0026upstream=serf\u0026distro=debian-8",
 39394          "swid": {
 39395            "attachment": {}
 39396          },
 39397          "pedigree": {},
 39398          "evidence": {},
 39399          "signature": {
 39400            "signature": {
 39401              "publicKey": {}
 39402            }
 39403          },
 39404          "modelCard": {
 39405            "modelParameters": {
 39406              "approach": {}
 39407            },
 39408            "quantitativeAnalysis": {
 39409              "graphics": {}
 39410            },
 39411            "considerations": {}
 39412          }
 39413        },
 39414        {
 39415          "type": "library",
 39416          "bom-ref": "pkg:deb/debian/libslang2@2.3.0-2?arch=amd64\u0026upstream=slang2\u0026distro=debian-8\u0026package-id=91a5f72737b46c64",
 39417          "supplier": {},
 39418          "publisher": "Alastair McKinstry \u003cmckinstry@debian.org\u003e",
 39419          "name": "libslang2",
 39420          "version": "2.3.0-2",
 39421          "licenses": [
 39422            {
 39423              "license": {
 39424                "id": "GPL-2.0-only"
 39425              }
 39426            },
 39427            {
 39428              "license": {
 39429                "id": "GPL-2.0-or-later"
 39430              }
 39431            }
 39432          ],
 39433          "cpe": "cpe:2.3:a:libslang2:libslang2:2.3.0-2:*:*:*:*:*:*:*",
 39434          "purl": "pkg:deb/debian/libslang2@2.3.0-2?arch=amd64\u0026upstream=slang2\u0026distro=debian-8",
 39435          "swid": {
 39436            "attachment": {}
 39437          },
 39438          "pedigree": {},
 39439          "evidence": {},
 39440          "signature": {
 39441            "signature": {
 39442              "publicKey": {}
 39443            }
 39444          },
 39445          "modelCard": {
 39446            "modelParameters": {
 39447              "approach": {}
 39448            },
 39449            "quantitativeAnalysis": {
 39450              "graphics": {}
 39451            },
 39452            "considerations": {}
 39453          }
 39454        },
 39455        {
 39456          "type": "library",
 39457          "bom-ref": "pkg:deb/debian/libsmartcols1@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8\u0026package-id=50cd8428df9b647",
 39458          "supplier": {},
 39459          "publisher": "Debian util-linux Maintainers \u003cah-util-linux@debian.org\u003e",
 39460          "name": "libsmartcols1",
 39461          "version": "2.25.2-6",
 39462          "licenses": [
 39463            {
 39464              "license": {
 39465                "id": "BSD-2-Clause"
 39466              }
 39467            },
 39468            {
 39469              "license": {
 39470                "id": "BSD-3-Clause"
 39471              }
 39472            },
 39473            {
 39474              "license": {
 39475                "id": "BSD-4-Clause"
 39476              }
 39477            },
 39478            {
 39479              "license": {
 39480                "id": "GPL-2.0-only"
 39481              }
 39482            },
 39483            {
 39484              "license": {
 39485                "id": "GPL-2.0-or-later"
 39486              }
 39487            },
 39488            {
 39489              "license": {
 39490                "id": "GPL-3.0-only"
 39491              }
 39492            },
 39493            {
 39494              "license": {
 39495                "id": "GPL-3.0-or-later"
 39496              }
 39497            },
 39498            {
 39499              "license": {
 39500                "name": "LGPL"
 39501              }
 39502            },
 39503            {
 39504              "license": {
 39505                "id": "LGPL-2.0-only"
 39506              }
 39507            },
 39508            {
 39509              "license": {
 39510                "id": "LGPL-2.0-or-later"
 39511              }
 39512            },
 39513            {
 39514              "license": {
 39515                "id": "LGPL-2.1-only"
 39516              }
 39517            },
 39518            {
 39519              "license": {
 39520                "id": "LGPL-2.1-or-later"
 39521              }
 39522            },
 39523            {
 39524              "license": {
 39525                "id": "LGPL-3.0-only"
 39526              }
 39527            },
 39528            {
 39529              "license": {
 39530                "id": "LGPL-3.0-or-later"
 39531              }
 39532            },
 39533            {
 39534              "license": {
 39535                "id": "MIT"
 39536              }
 39537            },
 39538            {
 39539              "license": {
 39540                "name": "public-domain"
 39541              }
 39542            }
 39543          ],
 39544          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.25.2-6:*:*:*:*:*:*:*",
 39545          "purl": "pkg:deb/debian/libsmartcols1@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8",
 39546          "swid": {
 39547            "attachment": {}
 39548          },
 39549          "pedigree": {},
 39550          "evidence": {},
 39551          "signature": {
 39552            "signature": {
 39553              "publicKey": {}
 39554            }
 39555          },
 39556          "modelCard": {
 39557            "modelParameters": {
 39558              "approach": {}
 39559            },
 39560            "quantitativeAnalysis": {
 39561              "graphics": {}
 39562            },
 39563            "considerations": {}
 39564          }
 39565        },
 39566        {
 39567          "type": "library",
 39568          "bom-ref": "pkg:deb/debian/libsqlite3-0@3.8.7.1-1+deb8u1?arch=amd64\u0026upstream=sqlite3\u0026distro=debian-8\u0026package-id=426949d7b03061e7",
 39569          "supplier": {},
 39570          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
 39571          "name": "libsqlite3-0",
 39572          "version": "3.8.7.1-1+deb8u1",
 39573          "licenses": [
 39574            {
 39575              "license": {
 39576                "id": "GPL-2.0-only"
 39577              }
 39578            },
 39579            {
 39580              "license": {
 39581                "id": "GPL-2.0-or-later"
 39582              }
 39583            },
 39584            {
 39585              "license": {
 39586                "name": "public-domain"
 39587              }
 39588            }
 39589          ],
 39590          "cpe": "cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.8.7.1-1\\+deb8u1:*:*:*:*:*:*:*",
 39591          "purl": "pkg:deb/debian/libsqlite3-0@3.8.7.1-1+deb8u1?arch=amd64\u0026upstream=sqlite3\u0026distro=debian-8",
 39592          "swid": {
 39593            "attachment": {}
 39594          },
 39595          "pedigree": {},
 39596          "evidence": {},
 39597          "signature": {
 39598            "signature": {
 39599              "publicKey": {}
 39600            }
 39601          },
 39602          "modelCard": {
 39603            "modelParameters": {
 39604              "approach": {}
 39605            },
 39606            "quantitativeAnalysis": {
 39607              "graphics": {}
 39608            },
 39609            "considerations": {}
 39610          }
 39611        },
 39612        {
 39613          "type": "library",
 39614          "bom-ref": "pkg:deb/debian/libss2@1.42.12-1.1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-8\u0026package-id=f48234c45b702890",
 39615          "supplier": {},
 39616          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 39617          "name": "libss2",
 39618          "version": "1.42.12-1.1",
 39619          "cpe": "cpe:2.3:a:libss2:libss2:1.42.12-1.1:*:*:*:*:*:*:*",
 39620          "purl": "pkg:deb/debian/libss2@1.42.12-1.1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-8",
 39621          "swid": {
 39622            "attachment": {}
 39623          },
 39624          "pedigree": {},
 39625          "evidence": {},
 39626          "signature": {
 39627            "signature": {
 39628              "publicKey": {}
 39629            }
 39630          },
 39631          "modelCard": {
 39632            "modelParameters": {
 39633              "approach": {}
 39634            },
 39635            "quantitativeAnalysis": {
 39636              "graphics": {}
 39637            },
 39638            "considerations": {}
 39639          }
 39640        },
 39641        {
 39642          "type": "library",
 39643          "bom-ref": "pkg:deb/debian/libssh2-1@1.4.3-4.1+deb8u1?arch=amd64\u0026upstream=libssh2\u0026distro=debian-8\u0026package-id=52eb587c773af190",
 39644          "supplier": {},
 39645          "publisher": "Mikhail Gusarov \u003cdottedmag@debian.org\u003e",
 39646          "name": "libssh2-1",
 39647          "version": "1.4.3-4.1+deb8u1",
 39648          "licenses": [
 39649            {
 39650              "license": {
 39651                "name": "BSD"
 39652              }
 39653            }
 39654          ],
 39655          "cpe": "cpe:2.3:a:libssh2-1:libssh2-1:1.4.3-4.1\\+deb8u1:*:*:*:*:*:*:*",
 39656          "purl": "pkg:deb/debian/libssh2-1@1.4.3-4.1+deb8u1?arch=amd64\u0026upstream=libssh2\u0026distro=debian-8",
 39657          "swid": {
 39658            "attachment": {}
 39659          },
 39660          "pedigree": {},
 39661          "evidence": {},
 39662          "signature": {
 39663            "signature": {
 39664              "publicKey": {}
 39665            }
 39666          },
 39667          "modelCard": {
 39668            "modelParameters": {
 39669              "approach": {}
 39670            },
 39671            "quantitativeAnalysis": {
 39672              "graphics": {}
 39673            },
 39674            "considerations": {}
 39675          }
 39676        },
 39677        {
 39678          "type": "library",
 39679          "bom-ref": "pkg:deb/debian/libssl1.0.0@1.0.1t-1+deb8u2?arch=amd64\u0026upstream=openssl\u0026distro=debian-8\u0026package-id=3d4112e19ef721",
 39680          "supplier": {},
 39681          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
 39682          "name": "libssl1.0.0",
 39683          "version": "1.0.1t-1+deb8u2",
 39684          "cpe": "cpe:2.3:a:libssl1.0.0:libssl1.0.0:1.0.1t-1\\+deb8u2:*:*:*:*:*:*:*",
 39685          "purl": "pkg:deb/debian/libssl1.0.0@1.0.1t-1+deb8u2?arch=amd64\u0026upstream=openssl\u0026distro=debian-8",
 39686          "swid": {
 39687            "attachment": {}
 39688          },
 39689          "pedigree": {},
 39690          "evidence": {},
 39691          "signature": {
 39692            "signature": {
 39693              "publicKey": {}
 39694            }
 39695          },
 39696          "modelCard": {
 39697            "modelParameters": {
 39698              "approach": {}
 39699            },
 39700            "quantitativeAnalysis": {
 39701              "graphics": {}
 39702            },
 39703            "considerations": {}
 39704          }
 39705        },
 39706        {
 39707          "type": "library",
 39708          "bom-ref": "pkg:deb/debian/libstdc++-4.9-dev@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=6c70c212dbe75c63",
 39709          "supplier": {},
 39710          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 39711          "name": "libstdc++-4.9-dev",
 39712          "version": "4.9.2-10",
 39713          "licenses": [
 39714            {
 39715              "license": {
 39716                "name": "Artistic"
 39717              }
 39718            },
 39719            {
 39720              "license": {
 39721                "id": "GFDL-1.2-only"
 39722              }
 39723            },
 39724            {
 39725              "license": {
 39726                "name": "GPL"
 39727              }
 39728            },
 39729            {
 39730              "license": {
 39731                "id": "GPL-2.0-only"
 39732              }
 39733            },
 39734            {
 39735              "license": {
 39736                "id": "GPL-3.0-only"
 39737              }
 39738            }
 39739          ],
 39740          "cpe": "cpe:2.3:a:libstdc\\+\\+-4.9-dev:libstdc\\+\\+-4.9-dev:4.9.2-10:*:*:*:*:*:*:*",
 39741          "purl": "pkg:deb/debian/libstdc++-4.9-dev@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 39742          "swid": {
 39743            "attachment": {}
 39744          },
 39745          "pedigree": {},
 39746          "evidence": {},
 39747          "signature": {
 39748            "signature": {
 39749              "publicKey": {}
 39750            }
 39751          },
 39752          "modelCard": {
 39753            "modelParameters": {
 39754              "approach": {}
 39755            },
 39756            "quantitativeAnalysis": {
 39757              "graphics": {}
 39758            },
 39759            "considerations": {}
 39760          }
 39761        },
 39762        {
 39763          "type": "library",
 39764          "bom-ref": "pkg:deb/debian/libstdc++6@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=701cdbd42b16cea2",
 39765          "supplier": {},
 39766          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 39767          "name": "libstdc++6",
 39768          "version": "4.9.2-10",
 39769          "licenses": [
 39770            {
 39771              "license": {
 39772                "name": "Artistic"
 39773              }
 39774            },
 39775            {
 39776              "license": {
 39777                "id": "GFDL-1.2-only"
 39778              }
 39779            },
 39780            {
 39781              "license": {
 39782                "name": "GPL"
 39783              }
 39784            },
 39785            {
 39786              "license": {
 39787                "id": "GPL-2.0-only"
 39788              }
 39789            },
 39790            {
 39791              "license": {
 39792                "id": "GPL-3.0-only"
 39793              }
 39794            }
 39795          ],
 39796          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:4.9.2-10:*:*:*:*:*:*:*",
 39797          "purl": "pkg:deb/debian/libstdc++6@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 39798          "swid": {
 39799            "attachment": {}
 39800          },
 39801          "pedigree": {},
 39802          "evidence": {},
 39803          "signature": {
 39804            "signature": {
 39805              "publicKey": {}
 39806            }
 39807          },
 39808          "modelCard": {
 39809            "modelParameters": {
 39810              "approach": {}
 39811            },
 39812            "quantitativeAnalysis": {
 39813              "graphics": {}
 39814            },
 39815            "considerations": {}
 39816          }
 39817        },
 39818        {
 39819          "type": "library",
 39820          "bom-ref": "pkg:deb/debian/libsvn1@1.8.10-6+deb8u4?arch=amd64\u0026upstream=subversion\u0026distro=debian-8\u0026package-id=4447612b2c72ed8f",
 39821          "supplier": {},
 39822          "publisher": "Peter Samuelson \u003cpeter@p12n.org\u003e",
 39823          "name": "libsvn1",
 39824          "version": "1.8.10-6+deb8u4",
 39825          "licenses": [
 39826            {
 39827              "license": {
 39828                "id": "Apache-2.0"
 39829              }
 39830            },
 39831            {
 39832              "license": {
 39833                "id": "GPL-2.0-only"
 39834              }
 39835            }
 39836          ],
 39837          "cpe": "cpe:2.3:a:libsvn1:libsvn1:1.8.10-6\\+deb8u4:*:*:*:*:*:*:*",
 39838          "purl": "pkg:deb/debian/libsvn1@1.8.10-6+deb8u4?arch=amd64\u0026upstream=subversion\u0026distro=debian-8",
 39839          "swid": {
 39840            "attachment": {}
 39841          },
 39842          "pedigree": {},
 39843          "evidence": {},
 39844          "signature": {
 39845            "signature": {
 39846              "publicKey": {}
 39847            }
 39848          },
 39849          "modelCard": {
 39850            "modelParameters": {
 39851              "approach": {}
 39852            },
 39853            "quantitativeAnalysis": {
 39854              "graphics": {}
 39855            },
 39856            "considerations": {}
 39857          }
 39858        },
 39859        {
 39860          "type": "library",
 39861          "bom-ref": "pkg:deb/debian/libsystemd0@215-17+deb8u4?arch=amd64\u0026upstream=systemd\u0026distro=debian-8\u0026package-id=99fcceb489fc5fe8",
 39862          "supplier": {},
 39863          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 39864          "name": "libsystemd0",
 39865          "version": "215-17+deb8u4",
 39866          "licenses": [
 39867            {
 39868              "license": {
 39869                "name": "Expat"
 39870              }
 39871            },
 39872            {
 39873              "license": {
 39874                "id": "GPL-2.0-only"
 39875              }
 39876            },
 39877            {
 39878              "license": {
 39879                "id": "GPL-2.0-or-later"
 39880              }
 39881            },
 39882            {
 39883              "license": {
 39884                "id": "LGPL-2.1-only"
 39885              }
 39886            },
 39887            {
 39888              "license": {
 39889                "id": "LGPL-2.1-or-later"
 39890              }
 39891            },
 39892            {
 39893              "license": {
 39894                "name": "public-domain"
 39895              }
 39896            }
 39897          ],
 39898          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:215-17\\+deb8u4:*:*:*:*:*:*:*",
 39899          "purl": "pkg:deb/debian/libsystemd0@215-17+deb8u4?arch=amd64\u0026upstream=systemd\u0026distro=debian-8",
 39900          "swid": {
 39901            "attachment": {}
 39902          },
 39903          "pedigree": {},
 39904          "evidence": {},
 39905          "signature": {
 39906            "signature": {
 39907              "publicKey": {}
 39908            }
 39909          },
 39910          "modelCard": {
 39911            "modelParameters": {
 39912              "approach": {}
 39913            },
 39914            "quantitativeAnalysis": {
 39915              "graphics": {}
 39916            },
 39917            "considerations": {}
 39918          }
 39919        },
 39920        {
 39921          "type": "library",
 39922          "bom-ref": "pkg:deb/debian/libtasn1-6@4.2-3+deb8u2?arch=amd64\u0026distro=debian-8\u0026package-id=25b6c1b732baffaf",
 39923          "supplier": {},
 39924          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 39925          "name": "libtasn1-6",
 39926          "version": "4.2-3+deb8u2",
 39927          "licenses": [
 39928            {
 39929              "license": {
 39930                "id": "GFDL-1.3-only"
 39931              }
 39932            },
 39933            {
 39934              "license": {
 39935                "id": "GPL-3.0-only"
 39936              }
 39937            },
 39938            {
 39939              "license": {
 39940                "name": "LGPL"
 39941              }
 39942            },
 39943            {
 39944              "license": {
 39945                "id": "LGPL-2.1-only"
 39946              }
 39947            }
 39948          ],
 39949          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.2-3\\+deb8u2:*:*:*:*:*:*:*",
 39950          "purl": "pkg:deb/debian/libtasn1-6@4.2-3+deb8u2?arch=amd64\u0026distro=debian-8",
 39951          "swid": {
 39952            "attachment": {}
 39953          },
 39954          "pedigree": {},
 39955          "evidence": {},
 39956          "signature": {
 39957            "signature": {
 39958              "publicKey": {}
 39959            }
 39960          },
 39961          "modelCard": {
 39962            "modelParameters": {
 39963              "approach": {}
 39964            },
 39965            "quantitativeAnalysis": {
 39966              "graphics": {}
 39967            },
 39968            "considerations": {}
 39969          }
 39970        },
 39971        {
 39972          "type": "library",
 39973          "bom-ref": "pkg:deb/debian/libtext-charwidth-perl@0.04-7+b3?arch=amd64\u0026upstream=libtext-charwidth-perl%400.04-7\u0026distro=debian-8\u0026package-id=fdb69c382f9e7a54",
 39974          "supplier": {},
 39975          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 39976          "name": "libtext-charwidth-perl",
 39977          "version": "0.04-7+b3",
 39978          "licenses": [
 39979            {
 39980              "license": {
 39981                "name": "Artistic"
 39982              }
 39983            },
 39984            {
 39985              "license": {
 39986                "id": "GPL-2.0-only"
 39987              }
 39988            }
 39989          ],
 39990          "cpe": "cpe:2.3:a:libtext-charwidth-perl:libtext-charwidth-perl:0.04-7\\+b3:*:*:*:*:*:*:*",
 39991          "purl": "pkg:deb/debian/libtext-charwidth-perl@0.04-7+b3?arch=amd64\u0026upstream=libtext-charwidth-perl%400.04-7\u0026distro=debian-8",
 39992          "swid": {
 39993            "attachment": {}
 39994          },
 39995          "pedigree": {},
 39996          "evidence": {},
 39997          "signature": {
 39998            "signature": {
 39999              "publicKey": {}
 40000            }
 40001          },
 40002          "modelCard": {
 40003            "modelParameters": {
 40004              "approach": {}
 40005            },
 40006            "quantitativeAnalysis": {
 40007              "graphics": {}
 40008            },
 40009            "considerations": {}
 40010          }
 40011        },
 40012        {
 40013          "type": "library",
 40014          "bom-ref": "pkg:deb/debian/libtext-iconv-perl@1.7-5+b2?arch=amd64\u0026upstream=libtext-iconv-perl%401.7-5\u0026distro=debian-8\u0026package-id=4154fce9e480403f",
 40015          "supplier": {},
 40016          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 40017          "name": "libtext-iconv-perl",
 40018          "version": "1.7-5+b2",
 40019          "licenses": [
 40020            {
 40021              "license": {
 40022                "name": "Artistic"
 40023              }
 40024            },
 40025            {
 40026              "license": {
 40027                "id": "GPL-2.0-only"
 40028              }
 40029            }
 40030          ],
 40031          "cpe": "cpe:2.3:a:libtext-iconv-perl:libtext-iconv-perl:1.7-5\\+b2:*:*:*:*:*:*:*",
 40032          "purl": "pkg:deb/debian/libtext-iconv-perl@1.7-5+b2?arch=amd64\u0026upstream=libtext-iconv-perl%401.7-5\u0026distro=debian-8",
 40033          "swid": {
 40034            "attachment": {}
 40035          },
 40036          "pedigree": {},
 40037          "evidence": {},
 40038          "signature": {
 40039            "signature": {
 40040              "publicKey": {}
 40041            }
 40042          },
 40043          "modelCard": {
 40044            "modelParameters": {
 40045              "approach": {}
 40046            },
 40047            "quantitativeAnalysis": {
 40048              "graphics": {}
 40049            },
 40050            "considerations": {}
 40051          }
 40052        },
 40053        {
 40054          "type": "library",
 40055          "bom-ref": "pkg:deb/debian/libtext-wrapi18n-perl@0.06-7?arch=all\u0026distro=debian-8\u0026package-id=6104c6da88e81ba1",
 40056          "supplier": {},
 40057          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 40058          "name": "libtext-wrapi18n-perl",
 40059          "version": "0.06-7",
 40060          "licenses": [
 40061            {
 40062              "license": {
 40063                "name": "Artistic"
 40064              }
 40065            },
 40066            {
 40067              "license": {
 40068                "name": "GPL"
 40069              }
 40070            }
 40071          ],
 40072          "cpe": "cpe:2.3:a:libtext-wrapi18n-perl:libtext-wrapi18n-perl:0.06-7:*:*:*:*:*:*:*",
 40073          "purl": "pkg:deb/debian/libtext-wrapi18n-perl@0.06-7?arch=all\u0026distro=debian-8",
 40074          "swid": {
 40075            "attachment": {}
 40076          },
 40077          "pedigree": {},
 40078          "evidence": {},
 40079          "signature": {
 40080            "signature": {
 40081              "publicKey": {}
 40082            }
 40083          },
 40084          "modelCard": {
 40085            "modelParameters": {
 40086              "approach": {}
 40087            },
 40088            "quantitativeAnalysis": {
 40089              "graphics": {}
 40090            },
 40091            "considerations": {}
 40092          }
 40093        },
 40094        {
 40095          "type": "library",
 40096          "bom-ref": "pkg:deb/debian/libtinfo5@5.9+20140913-1+b1?arch=amd64\u0026upstream=ncurses%405.9+20140913-1\u0026distro=debian-8\u0026package-id=e3f56eb9495cb665",
 40097          "supplier": {},
 40098          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 40099          "name": "libtinfo5",
 40100          "version": "5.9+20140913-1+b1",
 40101          "cpe": "cpe:2.3:a:libtinfo5:libtinfo5:5.9\\+20140913-1\\+b1:*:*:*:*:*:*:*",
 40102          "purl": "pkg:deb/debian/libtinfo5@5.9+20140913-1+b1?arch=amd64\u0026upstream=ncurses%405.9+20140913-1\u0026distro=debian-8",
 40103          "swid": {
 40104            "attachment": {}
 40105          },
 40106          "pedigree": {},
 40107          "evidence": {},
 40108          "signature": {
 40109            "signature": {
 40110              "publicKey": {}
 40111            }
 40112          },
 40113          "modelCard": {
 40114            "modelParameters": {
 40115              "approach": {}
 40116            },
 40117            "quantitativeAnalysis": {
 40118              "graphics": {}
 40119            },
 40120            "considerations": {}
 40121          }
 40122        },
 40123        {
 40124          "type": "library",
 40125          "bom-ref": "pkg:deb/debian/libtsan0@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=c46945564e9f752a",
 40126          "supplier": {},
 40127          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 40128          "name": "libtsan0",
 40129          "version": "4.9.2-10",
 40130          "licenses": [
 40131            {
 40132              "license": {
 40133                "name": "Artistic"
 40134              }
 40135            },
 40136            {
 40137              "license": {
 40138                "id": "GFDL-1.2-only"
 40139              }
 40140            },
 40141            {
 40142              "license": {
 40143                "name": "GPL"
 40144              }
 40145            },
 40146            {
 40147              "license": {
 40148                "id": "GPL-2.0-only"
 40149              }
 40150            },
 40151            {
 40152              "license": {
 40153                "id": "GPL-3.0-only"
 40154              }
 40155            }
 40156          ],
 40157          "cpe": "cpe:2.3:a:libtsan0:libtsan0:4.9.2-10:*:*:*:*:*:*:*",
 40158          "purl": "pkg:deb/debian/libtsan0@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 40159          "swid": {
 40160            "attachment": {}
 40161          },
 40162          "pedigree": {},
 40163          "evidence": {},
 40164          "signature": {
 40165            "signature": {
 40166              "publicKey": {}
 40167            }
 40168          },
 40169          "modelCard": {
 40170            "modelParameters": {
 40171              "approach": {}
 40172            },
 40173            "quantitativeAnalysis": {
 40174              "graphics": {}
 40175            },
 40176            "considerations": {}
 40177          }
 40178        },
 40179        {
 40180          "type": "library",
 40181          "bom-ref": "pkg:deb/debian/libubsan0@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8\u0026package-id=d183ee793203cd7c",
 40182          "supplier": {},
 40183          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 40184          "name": "libubsan0",
 40185          "version": "4.9.2-10",
 40186          "licenses": [
 40187            {
 40188              "license": {
 40189                "name": "Artistic"
 40190              }
 40191            },
 40192            {
 40193              "license": {
 40194                "id": "GFDL-1.2-only"
 40195              }
 40196            },
 40197            {
 40198              "license": {
 40199                "name": "GPL"
 40200              }
 40201            },
 40202            {
 40203              "license": {
 40204                "id": "GPL-2.0-only"
 40205              }
 40206            },
 40207            {
 40208              "license": {
 40209                "id": "GPL-3.0-only"
 40210              }
 40211            }
 40212          ],
 40213          "cpe": "cpe:2.3:a:libubsan0:libubsan0:4.9.2-10:*:*:*:*:*:*:*",
 40214          "purl": "pkg:deb/debian/libubsan0@4.9.2-10?arch=amd64\u0026upstream=gcc-4.9\u0026distro=debian-8",
 40215          "swid": {
 40216            "attachment": {}
 40217          },
 40218          "pedigree": {},
 40219          "evidence": {},
 40220          "signature": {
 40221            "signature": {
 40222              "publicKey": {}
 40223            }
 40224          },
 40225          "modelCard": {
 40226            "modelParameters": {
 40227              "approach": {}
 40228            },
 40229            "quantitativeAnalysis": {
 40230              "graphics": {}
 40231            },
 40232            "considerations": {}
 40233          }
 40234        },
 40235        {
 40236          "type": "library",
 40237          "bom-ref": "pkg:deb/debian/libudev1@215-17+deb8u4?arch=amd64\u0026upstream=systemd\u0026distro=debian-8\u0026package-id=ec7cafeeb6a458f0",
 40238          "supplier": {},
 40239          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 40240          "name": "libudev1",
 40241          "version": "215-17+deb8u4",
 40242          "licenses": [
 40243            {
 40244              "license": {
 40245                "name": "Expat"
 40246              }
 40247            },
 40248            {
 40249              "license": {
 40250                "id": "GPL-2.0-only"
 40251              }
 40252            },
 40253            {
 40254              "license": {
 40255                "id": "GPL-2.0-or-later"
 40256              }
 40257            },
 40258            {
 40259              "license": {
 40260                "id": "LGPL-2.1-only"
 40261              }
 40262            },
 40263            {
 40264              "license": {
 40265                "id": "LGPL-2.1-or-later"
 40266              }
 40267            },
 40268            {
 40269              "license": {
 40270                "name": "public-domain"
 40271              }
 40272            }
 40273          ],
 40274          "cpe": "cpe:2.3:a:libudev1:libudev1:215-17\\+deb8u4:*:*:*:*:*:*:*",
 40275          "purl": "pkg:deb/debian/libudev1@215-17+deb8u4?arch=amd64\u0026upstream=systemd\u0026distro=debian-8",
 40276          "swid": {
 40277            "attachment": {}
 40278          },
 40279          "pedigree": {},
 40280          "evidence": {},
 40281          "signature": {
 40282            "signature": {
 40283              "publicKey": {}
 40284            }
 40285          },
 40286          "modelCard": {
 40287            "modelParameters": {
 40288              "approach": {}
 40289            },
 40290            "quantitativeAnalysis": {
 40291              "graphics": {}
 40292            },
 40293            "considerations": {}
 40294          }
 40295        },
 40296        {
 40297          "type": "library",
 40298          "bom-ref": "pkg:deb/debian/libusb-0.1-4@2:0.1.12-25?arch=amd64\u0026upstream=libusb\u0026distro=debian-8\u0026package-id=2d4f1b96214e01b8",
 40299          "supplier": {},
 40300          "publisher": "Aurelien Jarno \u003caurel32@debian.org\u003e",
 40301          "name": "libusb-0.1-4",
 40302          "version": "2:0.1.12-25",
 40303          "licenses": [
 40304            {
 40305              "license": {
 40306                "name": "LGPL"
 40307              }
 40308            }
 40309          ],
 40310          "cpe": "cpe:2.3:a:libusb-0.1-4:libusb-0.1-4:2\\:0.1.12-25:*:*:*:*:*:*:*",
 40311          "purl": "pkg:deb/debian/libusb-0.1-4@2:0.1.12-25?arch=amd64\u0026upstream=libusb\u0026distro=debian-8",
 40312          "swid": {
 40313            "attachment": {}
 40314          },
 40315          "pedigree": {},
 40316          "evidence": {},
 40317          "signature": {
 40318            "signature": {
 40319              "publicKey": {}
 40320            }
 40321          },
 40322          "modelCard": {
 40323            "modelParameters": {
 40324              "approach": {}
 40325            },
 40326            "quantitativeAnalysis": {
 40327              "graphics": {}
 40328            },
 40329            "considerations": {}
 40330          }
 40331        },
 40332        {
 40333          "type": "library",
 40334          "bom-ref": "pkg:deb/debian/libustr-1.0-1@1.0.4-3+b2?arch=amd64\u0026upstream=ustr%401.0.4-3\u0026distro=debian-8\u0026package-id=1be9e21258a2e01b",
 40335          "supplier": {},
 40336          "publisher": "Vaclav Ovsik \u003cvaclav.ovsik@i.cz\u003e",
 40337          "name": "libustr-1.0-1",
 40338          "version": "1.0.4-3+b2",
 40339          "licenses": [
 40340            {
 40341              "license": {
 40342                "id": "BSD-2-Clause"
 40343              }
 40344            },
 40345            {
 40346              "license": {
 40347                "id": "GPL-2.0-only"
 40348              }
 40349            },
 40350            {
 40351              "license": {
 40352                "id": "GPL-2.0-or-later"
 40353              }
 40354            },
 40355            {
 40356              "license": {
 40357                "id": "LGPL-2.0-or-later"
 40358              }
 40359            },
 40360            {
 40361              "license": {
 40362                "id": "LGPL-2.1-only"
 40363              }
 40364            },
 40365            {
 40366              "license": {
 40367                "id": "MIT"
 40368              }
 40369            }
 40370          ],
 40371          "cpe": "cpe:2.3:a:libustr-1.0-1:libustr-1.0-1:1.0.4-3\\+b2:*:*:*:*:*:*:*",
 40372          "purl": "pkg:deb/debian/libustr-1.0-1@1.0.4-3+b2?arch=amd64\u0026upstream=ustr%401.0.4-3\u0026distro=debian-8",
 40373          "swid": {
 40374            "attachment": {}
 40375          },
 40376          "pedigree": {},
 40377          "evidence": {},
 40378          "signature": {
 40379            "signature": {
 40380              "publicKey": {}
 40381            }
 40382          },
 40383          "modelCard": {
 40384            "modelParameters": {
 40385              "approach": {}
 40386            },
 40387            "quantitativeAnalysis": {
 40388              "graphics": {}
 40389            },
 40390            "considerations": {}
 40391          }
 40392        },
 40393        {
 40394          "type": "library",
 40395          "bom-ref": "pkg:deb/debian/libuuid1@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8\u0026package-id=df1e79bc6151d233",
 40396          "supplier": {},
 40397          "publisher": "Debian util-linux Maintainers \u003cah-util-linux@debian.org\u003e",
 40398          "name": "libuuid1",
 40399          "version": "2.25.2-6",
 40400          "licenses": [
 40401            {
 40402              "license": {
 40403                "id": "BSD-2-Clause"
 40404              }
 40405            },
 40406            {
 40407              "license": {
 40408                "id": "BSD-3-Clause"
 40409              }
 40410            },
 40411            {
 40412              "license": {
 40413                "id": "BSD-4-Clause"
 40414              }
 40415            },
 40416            {
 40417              "license": {
 40418                "id": "GPL-2.0-only"
 40419              }
 40420            },
 40421            {
 40422              "license": {
 40423                "id": "GPL-2.0-or-later"
 40424              }
 40425            },
 40426            {
 40427              "license": {
 40428                "id": "GPL-3.0-only"
 40429              }
 40430            },
 40431            {
 40432              "license": {
 40433                "id": "GPL-3.0-or-later"
 40434              }
 40435            },
 40436            {
 40437              "license": {
 40438                "name": "LGPL"
 40439              }
 40440            },
 40441            {
 40442              "license": {
 40443                "id": "LGPL-2.0-only"
 40444              }
 40445            },
 40446            {
 40447              "license": {
 40448                "id": "LGPL-2.0-or-later"
 40449              }
 40450            },
 40451            {
 40452              "license": {
 40453                "id": "LGPL-2.1-only"
 40454              }
 40455            },
 40456            {
 40457              "license": {
 40458                "id": "LGPL-2.1-or-later"
 40459              }
 40460            },
 40461            {
 40462              "license": {
 40463                "id": "LGPL-3.0-only"
 40464              }
 40465            },
 40466            {
 40467              "license": {
 40468                "id": "LGPL-3.0-or-later"
 40469              }
 40470            },
 40471            {
 40472              "license": {
 40473                "id": "MIT"
 40474              }
 40475            },
 40476            {
 40477              "license": {
 40478                "name": "public-domain"
 40479              }
 40480            }
 40481          ],
 40482          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.25.2-6:*:*:*:*:*:*:*",
 40483          "purl": "pkg:deb/debian/libuuid1@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8",
 40484          "swid": {
 40485            "attachment": {}
 40486          },
 40487          "pedigree": {},
 40488          "evidence": {},
 40489          "signature": {
 40490            "signature": {
 40491              "publicKey": {}
 40492            }
 40493          },
 40494          "modelCard": {
 40495            "modelParameters": {
 40496              "approach": {}
 40497            },
 40498            "quantitativeAnalysis": {
 40499              "graphics": {}
 40500            },
 40501            "considerations": {}
 40502          }
 40503        },
 40504        {
 40505          "type": "library",
 40506          "bom-ref": "pkg:deb/debian/linux-libc-dev@3.16.7-ckt25-2+deb8u3?arch=amd64\u0026upstream=linux\u0026distro=debian-8\u0026package-id=a974e6dadad28a4b",
 40507          "supplier": {},
 40508          "publisher": "Debian Kernel Team \u003cdebian-kernel@lists.debian.org\u003e",
 40509          "name": "linux-libc-dev",
 40510          "version": "3.16.7-ckt25-2+deb8u3",
 40511          "licenses": [
 40512            {
 40513              "license": {
 40514                "id": "GPL-2.0-only"
 40515              }
 40516            },
 40517            {
 40518              "license": {
 40519                "name": "Unicode-data"
 40520              }
 40521            },
 40522            {
 40523              "license": {
 40524                "name": "Xen-interface"
 40525              }
 40526            }
 40527          ],
 40528          "cpe": "cpe:2.3:a:linux-libc-dev:linux-libc-dev:3.16.7-ckt25-2\\+deb8u3:*:*:*:*:*:*:*",
 40529          "purl": "pkg:deb/debian/linux-libc-dev@3.16.7-ckt25-2+deb8u3?arch=amd64\u0026upstream=linux\u0026distro=debian-8",
 40530          "swid": {
 40531            "attachment": {}
 40532          },
 40533          "pedigree": {},
 40534          "evidence": {},
 40535          "signature": {
 40536            "signature": {
 40537              "publicKey": {}
 40538            }
 40539          },
 40540          "modelCard": {
 40541            "modelParameters": {
 40542              "approach": {}
 40543            },
 40544            "quantitativeAnalysis": {
 40545              "graphics": {}
 40546            },
 40547            "considerations": {}
 40548          }
 40549        },
 40550        {
 40551          "type": "library",
 40552          "bom-ref": "pkg:deb/debian/login@1:4.2-3+deb8u1?arch=amd64\u0026upstream=shadow\u0026distro=debian-8\u0026package-id=4600df482277da2e",
 40553          "supplier": {},
 40554          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
 40555          "name": "login",
 40556          "version": "1:4.2-3+deb8u1",
 40557          "licenses": [
 40558            {
 40559              "license": {
 40560                "id": "GPL-2.0-only"
 40561              }
 40562            }
 40563          ],
 40564          "cpe": "cpe:2.3:a:login:login:1\\:4.2-3\\+deb8u1:*:*:*:*:*:*:*",
 40565          "purl": "pkg:deb/debian/login@1:4.2-3+deb8u1?arch=amd64\u0026upstream=shadow\u0026distro=debian-8",
 40566          "swid": {
 40567            "attachment": {}
 40568          },
 40569          "pedigree": {},
 40570          "evidence": {},
 40571          "signature": {
 40572            "signature": {
 40573              "publicKey": {}
 40574            }
 40575          },
 40576          "modelCard": {
 40577            "modelParameters": {
 40578              "approach": {}
 40579            },
 40580            "quantitativeAnalysis": {
 40581              "graphics": {}
 40582            },
 40583            "considerations": {}
 40584          }
 40585        },
 40586        {
 40587          "type": "library",
 40588          "bom-ref": "pkg:deb/debian/lsb-base@4.1+debian13+nmu1?arch=all\u0026upstream=lsb\u0026distro=debian-8\u0026package-id=241b727bebb6a760",
 40589          "supplier": {},
 40590          "publisher": "Debian LSB Team \u003cdebian-lsb@lists.debian.org\u003e",
 40591          "name": "lsb-base",
 40592          "version": "4.1+Debian13+nmu1",
 40593          "licenses": [
 40594            {
 40595              "license": {
 40596                "id": "BSD-3-Clause"
 40597              }
 40598            },
 40599            {
 40600              "license": {
 40601                "id": "GPL-2.0-only"
 40602              }
 40603            }
 40604          ],
 40605          "cpe": "cpe:2.3:a:lsb-base:lsb-base:4.1\\+Debian13\\+nmu1:*:*:*:*:*:*:*",
 40606          "purl": "pkg:deb/debian/lsb-base@4.1+Debian13+nmu1?arch=all\u0026upstream=lsb\u0026distro=debian-8",
 40607          "swid": {
 40608            "attachment": {}
 40609          },
 40610          "pedigree": {},
 40611          "evidence": {},
 40612          "signature": {
 40613            "signature": {
 40614              "publicKey": {}
 40615            }
 40616          },
 40617          "modelCard": {
 40618            "modelParameters": {
 40619              "approach": {}
 40620            },
 40621            "quantitativeAnalysis": {
 40622              "graphics": {}
 40623            },
 40624            "considerations": {}
 40625          }
 40626        },
 40627        {
 40628          "type": "library",
 40629          "bom-ref": "pkg:deb/debian/make@4.0-8.1?arch=amd64\u0026upstream=make-dfsg\u0026distro=debian-8\u0026package-id=71c71e8424cb92fc",
 40630          "supplier": {},
 40631          "publisher": "Manoj Srivastava \u003csrivasta@debian.org\u003e",
 40632          "name": "make",
 40633          "version": "4.0-8.1",
 40634          "licenses": [
 40635            {
 40636              "license": {
 40637                "id": "GPL-2.0-only"
 40638              }
 40639            }
 40640          ],
 40641          "cpe": "cpe:2.3:a:make:make:4.0-8.1:*:*:*:*:*:*:*",
 40642          "purl": "pkg:deb/debian/make@4.0-8.1?arch=amd64\u0026upstream=make-dfsg\u0026distro=debian-8",
 40643          "swid": {
 40644            "attachment": {}
 40645          },
 40646          "pedigree": {},
 40647          "evidence": {},
 40648          "signature": {
 40649            "signature": {
 40650              "publicKey": {}
 40651            }
 40652          },
 40653          "modelCard": {
 40654            "modelParameters": {
 40655              "approach": {}
 40656            },
 40657            "quantitativeAnalysis": {
 40658              "graphics": {}
 40659            },
 40660            "considerations": {}
 40661          }
 40662        },
 40663        {
 40664          "type": "library",
 40665          "bom-ref": "pkg:deb/debian/mawk@1.3.3-17?arch=amd64\u0026distro=debian-8\u0026package-id=c2721be686a78626",
 40666          "supplier": {},
 40667          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 40668          "name": "mawk",
 40669          "version": "1.3.3-17",
 40670          "licenses": [
 40671            {
 40672              "license": {
 40673                "id": "GPL-2.0-only"
 40674              }
 40675            }
 40676          ],
 40677          "cpe": "cpe:2.3:a:mawk:mawk:1.3.3-17:*:*:*:*:*:*:*",
 40678          "purl": "pkg:deb/debian/mawk@1.3.3-17?arch=amd64\u0026distro=debian-8",
 40679          "swid": {
 40680            "attachment": {}
 40681          },
 40682          "pedigree": {},
 40683          "evidence": {},
 40684          "signature": {
 40685            "signature": {
 40686              "publicKey": {}
 40687            }
 40688          },
 40689          "modelCard": {
 40690            "modelParameters": {
 40691              "approach": {}
 40692            },
 40693            "quantitativeAnalysis": {
 40694              "graphics": {}
 40695            },
 40696            "considerations": {}
 40697          }
 40698        },
 40699        {
 40700          "type": "library",
 40701          "bom-ref": "pkg:pypi/mercurial@3.1.2?package-id=6aa361de15a9c358",
 40702          "supplier": {},
 40703          "author": "Matt Mackall and many others \u003cmercurial@selenic.com\u003e",
 40704          "name": "mercurial",
 40705          "version": "3.1.2",
 40706          "licenses": [
 40707            {
 40708              "license": {
 40709                "name": "GNU GPLv2 or any later version"
 40710              }
 40711            }
 40712          ],
 40713          "cpe": "cpe:2.3:a:matt_mackall_and_many_others_project:python-mercurial:3.1.2:*:*:*:*:*:*:*",
 40714          "purl": "pkg:pypi/mercurial@3.1.2",
 40715          "swid": {
 40716            "attachment": {}
 40717          },
 40718          "pedigree": {},
 40719          "evidence": {},
 40720          "signature": {
 40721            "signature": {
 40722              "publicKey": {}
 40723            }
 40724          },
 40725          "modelCard": {
 40726            "modelParameters": {
 40727              "approach": {}
 40728            },
 40729            "quantitativeAnalysis": {
 40730              "graphics": {}
 40731            },
 40732            "considerations": {}
 40733          }
 40734        },
 40735        {
 40736          "type": "library",
 40737          "bom-ref": "pkg:deb/debian/mercurial@3.1.2-2+deb8u3?arch=amd64\u0026distro=debian-8\u0026package-id=f4aec0aab1947084",
 40738          "supplier": {},
 40739          "publisher": "Python Applications Packaging Team \u003cpython-apps-team@lists.alioth.debian.org\u003e",
 40740          "name": "mercurial",
 40741          "version": "3.1.2-2+deb8u3",
 40742          "licenses": [
 40743            {
 40744              "license": {
 40745                "id": "GPL-2.0-only"
 40746              }
 40747            },
 40748            {
 40749              "license": {
 40750                "id": "GPL-2.0-or-later"
 40751              }
 40752            }
 40753          ],
 40754          "cpe": "cpe:2.3:a:mercurial:mercurial:3.1.2-2\\+deb8u3:*:*:*:*:*:*:*",
 40755          "purl": "pkg:deb/debian/mercurial@3.1.2-2+deb8u3?arch=amd64\u0026distro=debian-8",
 40756          "swid": {
 40757            "attachment": {}
 40758          },
 40759          "pedigree": {},
 40760          "evidence": {},
 40761          "signature": {
 40762            "signature": {
 40763              "publicKey": {}
 40764            }
 40765          },
 40766          "modelCard": {
 40767            "modelParameters": {
 40768              "approach": {}
 40769            },
 40770            "quantitativeAnalysis": {
 40771              "graphics": {}
 40772            },
 40773            "considerations": {}
 40774          }
 40775        },
 40776        {
 40777          "type": "library",
 40778          "bom-ref": "pkg:deb/debian/mercurial-common@3.1.2-2+deb8u3?arch=all\u0026upstream=mercurial\u0026distro=debian-8\u0026package-id=dfdf59375b6b5854",
 40779          "supplier": {},
 40780          "publisher": "Python Applications Packaging Team \u003cpython-apps-team@lists.alioth.debian.org\u003e",
 40781          "name": "mercurial-common",
 40782          "version": "3.1.2-2+deb8u3",
 40783          "licenses": [
 40784            {
 40785              "license": {
 40786                "id": "GPL-2.0-only"
 40787              }
 40788            },
 40789            {
 40790              "license": {
 40791                "id": "GPL-2.0-or-later"
 40792              }
 40793            }
 40794          ],
 40795          "cpe": "cpe:2.3:a:mercurial-common:mercurial-common:3.1.2-2\\+deb8u3:*:*:*:*:*:*:*",
 40796          "purl": "pkg:deb/debian/mercurial-common@3.1.2-2+deb8u3?arch=all\u0026upstream=mercurial\u0026distro=debian-8",
 40797          "swid": {
 40798            "attachment": {}
 40799          },
 40800          "pedigree": {},
 40801          "evidence": {},
 40802          "signature": {
 40803            "signature": {
 40804              "publicKey": {}
 40805            }
 40806          },
 40807          "modelCard": {
 40808            "modelParameters": {
 40809              "approach": {}
 40810            },
 40811            "quantitativeAnalysis": {
 40812              "graphics": {}
 40813            },
 40814            "considerations": {}
 40815          }
 40816        },
 40817        {
 40818          "type": "library",
 40819          "bom-ref": "pkg:deb/debian/mime-support@3.58?arch=all\u0026distro=debian-8\u0026package-id=9a4964b288ea4812",
 40820          "supplier": {},
 40821          "publisher": "Mime-Support Maintainers \u003cmime-support@plessy.org\u003e",
 40822          "name": "mime-support",
 40823          "version": "3.58",
 40824          "licenses": [
 40825            {
 40826              "license": {
 40827                "name": "Bellcore"
 40828              }
 40829            },
 40830            {
 40831              "license": {
 40832                "name": "ad-hoc"
 40833              }
 40834            }
 40835          ],
 40836          "cpe": "cpe:2.3:a:mime-support:mime-support:3.58:*:*:*:*:*:*:*",
 40837          "purl": "pkg:deb/debian/mime-support@3.58?arch=all\u0026distro=debian-8",
 40838          "swid": {
 40839            "attachment": {}
 40840          },
 40841          "pedigree": {},
 40842          "evidence": {},
 40843          "signature": {
 40844            "signature": {
 40845              "publicKey": {}
 40846            }
 40847          },
 40848          "modelCard": {
 40849            "modelParameters": {
 40850              "approach": {}
 40851            },
 40852            "quantitativeAnalysis": {
 40853              "graphics": {}
 40854            },
 40855            "considerations": {}
 40856          }
 40857        },
 40858        {
 40859          "type": "library",
 40860          "bom-ref": "pkg:deb/debian/mount@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8\u0026package-id=90fb7a2721a16b1a",
 40861          "supplier": {},
 40862          "publisher": "Debian util-linux Maintainers \u003cah-util-linux@debian.org\u003e",
 40863          "name": "mount",
 40864          "version": "2.25.2-6",
 40865          "licenses": [
 40866            {
 40867              "license": {
 40868                "id": "BSD-2-Clause"
 40869              }
 40870            },
 40871            {
 40872              "license": {
 40873                "id": "BSD-3-Clause"
 40874              }
 40875            },
 40876            {
 40877              "license": {
 40878                "id": "BSD-4-Clause"
 40879              }
 40880            },
 40881            {
 40882              "license": {
 40883                "id": "GPL-2.0-only"
 40884              }
 40885            },
 40886            {
 40887              "license": {
 40888                "id": "GPL-2.0-or-later"
 40889              }
 40890            },
 40891            {
 40892              "license": {
 40893                "id": "GPL-3.0-only"
 40894              }
 40895            },
 40896            {
 40897              "license": {
 40898                "id": "GPL-3.0-or-later"
 40899              }
 40900            },
 40901            {
 40902              "license": {
 40903                "name": "LGPL"
 40904              }
 40905            },
 40906            {
 40907              "license": {
 40908                "id": "LGPL-2.0-only"
 40909              }
 40910            },
 40911            {
 40912              "license": {
 40913                "id": "LGPL-2.0-or-later"
 40914              }
 40915            },
 40916            {
 40917              "license": {
 40918                "id": "LGPL-2.1-only"
 40919              }
 40920            },
 40921            {
 40922              "license": {
 40923                "id": "LGPL-2.1-or-later"
 40924              }
 40925            },
 40926            {
 40927              "license": {
 40928                "id": "LGPL-3.0-only"
 40929              }
 40930            },
 40931            {
 40932              "license": {
 40933                "id": "LGPL-3.0-or-later"
 40934              }
 40935            },
 40936            {
 40937              "license": {
 40938                "id": "MIT"
 40939              }
 40940            },
 40941            {
 40942              "license": {
 40943                "name": "public-domain"
 40944              }
 40945            }
 40946          ],
 40947          "cpe": "cpe:2.3:a:mount:mount:2.25.2-6:*:*:*:*:*:*:*",
 40948          "purl": "pkg:deb/debian/mount@2.25.2-6?arch=amd64\u0026upstream=util-linux\u0026distro=debian-8",
 40949          "swid": {
 40950            "attachment": {}
 40951          },
 40952          "pedigree": {},
 40953          "evidence": {},
 40954          "signature": {
 40955            "signature": {
 40956              "publicKey": {}
 40957            }
 40958          },
 40959          "modelCard": {
 40960            "modelParameters": {
 40961              "approach": {}
 40962            },
 40963            "quantitativeAnalysis": {
 40964              "graphics": {}
 40965            },
 40966            "considerations": {}
 40967          }
 40968        },
 40969        {
 40970          "type": "library",
 40971          "bom-ref": "pkg:deb/debian/multiarch-support@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8\u0026package-id=35e909ad2a628488",
 40972          "supplier": {},
 40973          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 40974          "name": "multiarch-support",
 40975          "version": "2.19-18+deb8u4",
 40976          "licenses": [
 40977            {
 40978              "license": {
 40979                "id": "GPL-2.0-only"
 40980              }
 40981            },
 40982            {
 40983              "license": {
 40984                "id": "LGPL-2.1-only"
 40985              }
 40986            }
 40987          ],
 40988          "cpe": "cpe:2.3:a:multiarch-support:multiarch-support:2.19-18\\+deb8u4:*:*:*:*:*:*:*",
 40989          "purl": "pkg:deb/debian/multiarch-support@2.19-18+deb8u4?arch=amd64\u0026upstream=glibc\u0026distro=debian-8",
 40990          "swid": {
 40991            "attachment": {}
 40992          },
 40993          "pedigree": {},
 40994          "evidence": {},
 40995          "signature": {
 40996            "signature": {
 40997              "publicKey": {}
 40998            }
 40999          },
 41000          "modelCard": {
 41001            "modelParameters": {
 41002              "approach": {}
 41003            },
 41004            "quantitativeAnalysis": {
 41005              "graphics": {}
 41006            },
 41007            "considerations": {}
 41008          }
 41009        },
 41010        {
 41011          "type": "library",
 41012          "bom-ref": "pkg:deb/debian/ncurses-base@5.9+20140913-1?arch=all\u0026upstream=ncurses\u0026distro=debian-8\u0026package-id=ca3ead6e6c0d8dda",
 41013          "supplier": {},
 41014          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 41015          "name": "ncurses-base",
 41016          "version": "5.9+20140913-1",
 41017          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:5.9\\+20140913-1:*:*:*:*:*:*:*",
 41018          "purl": "pkg:deb/debian/ncurses-base@5.9+20140913-1?arch=all\u0026upstream=ncurses\u0026distro=debian-8",
 41019          "swid": {
 41020            "attachment": {}
 41021          },
 41022          "pedigree": {},
 41023          "evidence": {},
 41024          "signature": {
 41025            "signature": {
 41026              "publicKey": {}
 41027            }
 41028          },
 41029          "modelCard": {
 41030            "modelParameters": {
 41031              "approach": {}
 41032            },
 41033            "quantitativeAnalysis": {
 41034              "graphics": {}
 41035            },
 41036            "considerations": {}
 41037          }
 41038        },
 41039        {
 41040          "type": "library",
 41041          "bom-ref": "pkg:deb/debian/ncurses-bin@5.9+20140913-1+b1?arch=amd64\u0026upstream=ncurses%405.9+20140913-1\u0026distro=debian-8\u0026package-id=b257abf8b8f25ac",
 41042          "supplier": {},
 41043          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 41044          "name": "ncurses-bin",
 41045          "version": "5.9+20140913-1+b1",
 41046          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:5.9\\+20140913-1\\+b1:*:*:*:*:*:*:*",
 41047          "purl": "pkg:deb/debian/ncurses-bin@5.9+20140913-1+b1?arch=amd64\u0026upstream=ncurses%405.9+20140913-1\u0026distro=debian-8",
 41048          "swid": {
 41049            "attachment": {}
 41050          },
 41051          "pedigree": {},
 41052          "evidence": {},
 41053          "signature": {
 41054            "signature": {
 41055              "publicKey": {}
 41056            }
 41057          },
 41058          "modelCard": {
 41059            "modelParameters": {
 41060              "approach": {}
 41061            },
 41062            "quantitativeAnalysis": {
 41063              "graphics": {}
 41064            },
 41065            "considerations": {}
 41066          }
 41067        },
 41068        {
 41069          "type": "library",
 41070          "bom-ref": "pkg:deb/debian/netbase@5.3?arch=all\u0026distro=debian-8\u0026package-id=d416f257c9c83dd9",
 41071          "supplier": {},
 41072          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
 41073          "name": "netbase",
 41074          "version": "5.3",
 41075          "licenses": [
 41076            {
 41077              "license": {
 41078                "id": "GPL-2.0-only"
 41079              }
 41080            }
 41081          ],
 41082          "cpe": "cpe:2.3:a:netbase:netbase:5.3:*:*:*:*:*:*:*",
 41083          "purl": "pkg:deb/debian/netbase@5.3?arch=all\u0026distro=debian-8",
 41084          "swid": {
 41085            "attachment": {}
 41086          },
 41087          "pedigree": {},
 41088          "evidence": {},
 41089          "signature": {
 41090            "signature": {
 41091              "publicKey": {}
 41092            }
 41093          },
 41094          "modelCard": {
 41095            "modelParameters": {
 41096              "approach": {}
 41097            },
 41098            "quantitativeAnalysis": {
 41099              "graphics": {}
 41100            },
 41101            "considerations": {}
 41102          }
 41103        },
 41104        {
 41105          "type": "library",
 41106          "bom-ref": "pkg:deb/debian/openssh-client@1:6.7p1-5+deb8u3?arch=amd64\u0026upstream=openssh\u0026distro=debian-8\u0026package-id=fa63e9c57a753a3b",
 41107          "supplier": {},
 41108          "publisher": "Debian OpenSSH Maintainers \u003cdebian-ssh@lists.debian.org\u003e",
 41109          "name": "openssh-client",
 41110          "version": "1:6.7p1-5+deb8u3",
 41111          "licenses": [
 41112            {
 41113              "license": {
 41114                "id": "GPL-2.0-only"
 41115              }
 41116            }
 41117          ],
 41118          "cpe": "cpe:2.3:a:openssh-client:openssh-client:1\\:6.7p1-5\\+deb8u3:*:*:*:*:*:*:*",
 41119          "purl": "pkg:deb/debian/openssh-client@1:6.7p1-5+deb8u3?arch=amd64\u0026upstream=openssh\u0026distro=debian-8",
 41120          "swid": {
 41121            "attachment": {}
 41122          },
 41123          "pedigree": {},
 41124          "evidence": {},
 41125          "signature": {
 41126            "signature": {
 41127              "publicKey": {}
 41128            }
 41129          },
 41130          "modelCard": {
 41131            "modelParameters": {
 41132              "approach": {}
 41133            },
 41134            "quantitativeAnalysis": {
 41135              "graphics": {}
 41136            },
 41137            "considerations": {}
 41138          }
 41139        },
 41140        {
 41141          "type": "library",
 41142          "bom-ref": "pkg:deb/debian/openssl@1.0.1t-1+deb8u2?arch=amd64\u0026distro=debian-8\u0026package-id=3bc03d7d02a497ca",
 41143          "supplier": {},
 41144          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
 41145          "name": "openssl",
 41146          "version": "1.0.1t-1+deb8u2",
 41147          "cpe": "cpe:2.3:a:openssl:openssl:1.0.1t-1\\+deb8u2:*:*:*:*:*:*:*",
 41148          "purl": "pkg:deb/debian/openssl@1.0.1t-1+deb8u2?arch=amd64\u0026distro=debian-8",
 41149          "swid": {
 41150            "attachment": {}
 41151          },
 41152          "pedigree": {},
 41153          "evidence": {},
 41154          "signature": {
 41155            "signature": {
 41156              "publicKey": {}
 41157            }
 41158          },
 41159          "modelCard": {
 41160            "modelParameters": {
 41161              "approach": {}
 41162            },
 41163            "quantitativeAnalysis": {
 41164              "graphics": {}
 41165            },
 41166            "considerations": {}
 41167          }
 41168        },
 41169        {
 41170          "type": "library",
 41171          "bom-ref": "pkg:deb/debian/passwd@1:4.2-3+deb8u1?arch=amd64\u0026upstream=shadow\u0026distro=debian-8\u0026package-id=e718c0918f745ac3",
 41172          "supplier": {},
 41173          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
 41174          "name": "passwd",
 41175          "version": "1:4.2-3+deb8u1",
 41176          "licenses": [
 41177            {
 41178              "license": {
 41179                "id": "GPL-2.0-only"
 41180              }
 41181            }
 41182          ],
 41183          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.2-3\\+deb8u1:*:*:*:*:*:*:*",
 41184          "purl": "pkg:deb/debian/passwd@1:4.2-3+deb8u1?arch=amd64\u0026upstream=shadow\u0026distro=debian-8",
 41185          "swid": {
 41186            "attachment": {}
 41187          },
 41188          "pedigree": {},
 41189          "evidence": {},
 41190          "signature": {
 41191            "signature": {
 41192              "publicKey": {}
 41193            }
 41194          },
 41195          "modelCard": {
 41196            "modelParameters": {
 41197              "approach": {}
 41198            },
 41199            "quantitativeAnalysis": {
 41200              "graphics": {}
 41201            },
 41202            "considerations": {}
 41203          }
 41204        },
 41205        {
 41206          "type": "library",
 41207          "bom-ref": "pkg:deb/debian/perl@5.20.2-3+deb8u6?arch=amd64\u0026distro=debian-8\u0026package-id=b90d6f6315dc8769",
 41208          "supplier": {},
 41209          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
 41210          "name": "perl",
 41211          "version": "5.20.2-3+deb8u6",
 41212          "licenses": [
 41213            {
 41214              "license": {
 41215                "name": "Artistic"
 41216              }
 41217            },
 41218            {
 41219              "license": {
 41220                "id": "Artistic-2.0"
 41221              }
 41222            },
 41223            {
 41224              "license": {
 41225                "id": "BSD-3-Clause"
 41226              }
 41227            },
 41228            {
 41229              "license": {
 41230                "name": "BSD-3-clause-GENERIC"
 41231              }
 41232            },
 41233            {
 41234              "license": {
 41235                "id": "BSD-4-Clause"
 41236              }
 41237            },
 41238            {
 41239              "license": {
 41240                "name": "BSD-4-clause-POWERDOG"
 41241              }
 41242            },
 41243            {
 41244              "license": {
 41245                "name": "BZIP"
 41246              }
 41247            },
 41248            {
 41249              "license": {
 41250                "name": "DONT-CHANGE-THE-GPL"
 41251              }
 41252            },
 41253            {
 41254              "license": {
 41255                "name": "Expat"
 41256              }
 41257            },
 41258            {
 41259              "license": {
 41260                "id": "GPL-1.0-only"
 41261              }
 41262            },
 41263            {
 41264              "license": {
 41265                "id": "GPL-1.0-or-later"
 41266              }
 41267            },
 41268            {
 41269              "license": {
 41270                "id": "GPL-2.0-or-later"
 41271              }
 41272            },
 41273            {
 41274              "license": {
 41275                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 41276              }
 41277            },
 41278            {
 41279              "license": {
 41280                "name": "HSIEH-BSD"
 41281              }
 41282            },
 41283            {
 41284              "license": {
 41285                "name": "HSIEH-DERIVATIVE"
 41286              }
 41287            },
 41288            {
 41289              "license": {
 41290                "id": "LGPL-2.1-only"
 41291              }
 41292            },
 41293            {
 41294              "license": {
 41295                "name": "REGCOMP"
 41296              }
 41297            },
 41298            {
 41299              "license": {
 41300                "name": "REGCOMP,"
 41301              }
 41302            },
 41303            {
 41304              "license": {
 41305                "name": "S2P"
 41306              }
 41307            },
 41308            {
 41309              "license": {
 41310                "name": "SDBM-PUBLIC-DOMAIN"
 41311              }
 41312            },
 41313            {
 41314              "license": {
 41315                "name": "TEXT-TABS"
 41316              }
 41317            },
 41318            {
 41319              "license": {
 41320                "name": "Unicode"
 41321              }
 41322            },
 41323            {
 41324              "license": {
 41325                "id": "Zlib"
 41326              }
 41327            }
 41328          ],
 41329          "cpe": "cpe:2.3:a:perl:perl:5.20.2-3\\+deb8u6:*:*:*:*:*:*:*",
 41330          "purl": "pkg:deb/debian/perl@5.20.2-3+deb8u6?arch=amd64\u0026distro=debian-8",
 41331          "swid": {
 41332            "attachment": {}
 41333          },
 41334          "pedigree": {},
 41335          "evidence": {},
 41336          "signature": {
 41337            "signature": {
 41338              "publicKey": {}
 41339            }
 41340          },
 41341          "modelCard": {
 41342            "modelParameters": {
 41343              "approach": {}
 41344            },
 41345            "quantitativeAnalysis": {
 41346              "graphics": {}
 41347            },
 41348            "considerations": {}
 41349          }
 41350        },
 41351        {
 41352          "type": "library",
 41353          "bom-ref": "pkg:deb/debian/perl-base@5.20.2-3+deb8u6?arch=amd64\u0026upstream=perl\u0026distro=debian-8\u0026package-id=a5eb6351cb8b522d",
 41354          "supplier": {},
 41355          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
 41356          "name": "perl-base",
 41357          "version": "5.20.2-3+deb8u6",
 41358          "licenses": [
 41359            {
 41360              "license": {
 41361                "name": "Artistic"
 41362              }
 41363            },
 41364            {
 41365              "license": {
 41366                "id": "Artistic-2.0"
 41367              }
 41368            },
 41369            {
 41370              "license": {
 41371                "id": "BSD-3-Clause"
 41372              }
 41373            },
 41374            {
 41375              "license": {
 41376                "name": "BSD-3-clause-GENERIC"
 41377              }
 41378            },
 41379            {
 41380              "license": {
 41381                "id": "BSD-4-Clause"
 41382              }
 41383            },
 41384            {
 41385              "license": {
 41386                "name": "BSD-4-clause-POWERDOG"
 41387              }
 41388            },
 41389            {
 41390              "license": {
 41391                "name": "BZIP"
 41392              }
 41393            },
 41394            {
 41395              "license": {
 41396                "name": "DONT-CHANGE-THE-GPL"
 41397              }
 41398            },
 41399            {
 41400              "license": {
 41401                "name": "Expat"
 41402              }
 41403            },
 41404            {
 41405              "license": {
 41406                "id": "GPL-1.0-only"
 41407              }
 41408            },
 41409            {
 41410              "license": {
 41411                "id": "GPL-1.0-or-later"
 41412              }
 41413            },
 41414            {
 41415              "license": {
 41416                "id": "GPL-2.0-or-later"
 41417              }
 41418            },
 41419            {
 41420              "license": {
 41421                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 41422              }
 41423            },
 41424            {
 41425              "license": {
 41426                "name": "HSIEH-BSD"
 41427              }
 41428            },
 41429            {
 41430              "license": {
 41431                "name": "HSIEH-DERIVATIVE"
 41432              }
 41433            },
 41434            {
 41435              "license": {
 41436                "id": "LGPL-2.1-only"
 41437              }
 41438            },
 41439            {
 41440              "license": {
 41441                "name": "REGCOMP"
 41442              }
 41443            },
 41444            {
 41445              "license": {
 41446                "name": "REGCOMP,"
 41447              }
 41448            },
 41449            {
 41450              "license": {
 41451                "name": "S2P"
 41452              }
 41453            },
 41454            {
 41455              "license": {
 41456                "name": "SDBM-PUBLIC-DOMAIN"
 41457              }
 41458            },
 41459            {
 41460              "license": {
 41461                "name": "TEXT-TABS"
 41462              }
 41463            },
 41464            {
 41465              "license": {
 41466                "name": "Unicode"
 41467              }
 41468            },
 41469            {
 41470              "license": {
 41471                "id": "Zlib"
 41472              }
 41473            }
 41474          ],
 41475          "cpe": "cpe:2.3:a:perl-base:perl-base:5.20.2-3\\+deb8u6:*:*:*:*:*:*:*",
 41476          "purl": "pkg:deb/debian/perl-base@5.20.2-3+deb8u6?arch=amd64\u0026upstream=perl\u0026distro=debian-8",
 41477          "swid": {
 41478            "attachment": {}
 41479          },
 41480          "pedigree": {},
 41481          "evidence": {},
 41482          "signature": {
 41483            "signature": {
 41484              "publicKey": {}
 41485            }
 41486          },
 41487          "modelCard": {
 41488            "modelParameters": {
 41489              "approach": {}
 41490            },
 41491            "quantitativeAnalysis": {
 41492              "graphics": {}
 41493            },
 41494            "considerations": {}
 41495          }
 41496        },
 41497        {
 41498          "type": "library",
 41499          "bom-ref": "pkg:deb/debian/perl-modules@5.20.2-3+deb8u6?arch=all\u0026upstream=perl\u0026distro=debian-8\u0026package-id=3142b7bb4be49e2d",
 41500          "supplier": {},
 41501          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
 41502          "name": "perl-modules",
 41503          "version": "5.20.2-3+deb8u6",
 41504          "licenses": [
 41505            {
 41506              "license": {
 41507                "name": "Artistic"
 41508              }
 41509            },
 41510            {
 41511              "license": {
 41512                "id": "Artistic-2.0"
 41513              }
 41514            },
 41515            {
 41516              "license": {
 41517                "id": "BSD-3-Clause"
 41518              }
 41519            },
 41520            {
 41521              "license": {
 41522                "name": "BSD-3-clause-GENERIC"
 41523              }
 41524            },
 41525            {
 41526              "license": {
 41527                "id": "BSD-4-Clause"
 41528              }
 41529            },
 41530            {
 41531              "license": {
 41532                "name": "BSD-4-clause-POWERDOG"
 41533              }
 41534            },
 41535            {
 41536              "license": {
 41537                "name": "BZIP"
 41538              }
 41539            },
 41540            {
 41541              "license": {
 41542                "name": "DONT-CHANGE-THE-GPL"
 41543              }
 41544            },
 41545            {
 41546              "license": {
 41547                "name": "Expat"
 41548              }
 41549            },
 41550            {
 41551              "license": {
 41552                "id": "GPL-1.0-only"
 41553              }
 41554            },
 41555            {
 41556              "license": {
 41557                "id": "GPL-1.0-or-later"
 41558              }
 41559            },
 41560            {
 41561              "license": {
 41562                "id": "GPL-2.0-or-later"
 41563              }
 41564            },
 41565            {
 41566              "license": {
 41567                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 41568              }
 41569            },
 41570            {
 41571              "license": {
 41572                "name": "HSIEH-BSD"
 41573              }
 41574            },
 41575            {
 41576              "license": {
 41577                "name": "HSIEH-DERIVATIVE"
 41578              }
 41579            },
 41580            {
 41581              "license": {
 41582                "id": "LGPL-2.1-only"
 41583              }
 41584            },
 41585            {
 41586              "license": {
 41587                "name": "REGCOMP"
 41588              }
 41589            },
 41590            {
 41591              "license": {
 41592                "name": "REGCOMP,"
 41593              }
 41594            },
 41595            {
 41596              "license": {
 41597                "name": "S2P"
 41598              }
 41599            },
 41600            {
 41601              "license": {
 41602                "name": "SDBM-PUBLIC-DOMAIN"
 41603              }
 41604            },
 41605            {
 41606              "license": {
 41607                "name": "TEXT-TABS"
 41608              }
 41609            },
 41610            {
 41611              "license": {
 41612                "name": "Unicode"
 41613              }
 41614            },
 41615            {
 41616              "license": {
 41617                "id": "Zlib"
 41618              }
 41619            }
 41620          ],
 41621          "cpe": "cpe:2.3:a:perl-modules:perl-modules:5.20.2-3\\+deb8u6:*:*:*:*:*:*:*",
 41622          "purl": "pkg:deb/debian/perl-modules@5.20.2-3+deb8u6?arch=all\u0026upstream=perl\u0026distro=debian-8",
 41623          "swid": {
 41624            "attachment": {}
 41625          },
 41626          "pedigree": {},
 41627          "evidence": {},
 41628          "signature": {
 41629            "signature": {
 41630              "publicKey": {}
 41631            }
 41632          },
 41633          "modelCard": {
 41634            "modelParameters": {
 41635              "approach": {}
 41636            },
 41637            "quantitativeAnalysis": {
 41638              "graphics": {}
 41639            },
 41640            "considerations": {}
 41641          }
 41642        },
 41643        {
 41644          "type": "library",
 41645          "bom-ref": "pkg:deb/debian/procps@2:3.3.9-9?arch=amd64\u0026distro=debian-8\u0026package-id=ab14cd9549bd432",
 41646          "supplier": {},
 41647          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 41648          "name": "procps",
 41649          "version": "2:3.3.9-9",
 41650          "licenses": [
 41651            {
 41652              "license": {
 41653                "id": "GPL-2.0-only"
 41654              }
 41655            },
 41656            {
 41657              "license": {
 41658                "id": "LGPL-2.0-only"
 41659              }
 41660            }
 41661          ],
 41662          "cpe": "cpe:2.3:a:procps:procps:2\\:3.3.9-9:*:*:*:*:*:*:*",
 41663          "purl": "pkg:deb/debian/procps@2:3.3.9-9?arch=amd64\u0026distro=debian-8",
 41664          "swid": {
 41665            "attachment": {}
 41666          },
 41667          "pedigree": {},
 41668          "evidence": {},
 41669          "signature": {
 41670            "signature": {
 41671              "publicKey": {}
 41672            }
 41673          },
 41674          "modelCard": {
 41675            "modelParameters": {
 41676              "approach": {}
 41677            },
 41678            "quantitativeAnalysis": {
 41679              "graphics": {}
 41680            },
 41681            "considerations": {}
 41682          }
 41683        },
 41684        {
 41685          "type": "application",
 41686          "bom-ref": "pkg:generic/python@2.7.9?package-id=eacc125eb01aeb12",
 41687          "supplier": {},
 41688          "name": "python",
 41689          "version": "2.7.9",
 41690          "cpe": "cpe:2.3:a:python_software_foundation:python:2.7.9:*:*:*:*:*:*:*",
 41691          "purl": "pkg:generic/python@2.7.9",
 41692          "swid": {
 41693            "attachment": {}
 41694          },
 41695          "pedigree": {},
 41696          "evidence": {},
 41697          "signature": {
 41698            "signature": {
 41699              "publicKey": {}
 41700            }
 41701          },
 41702          "modelCard": {
 41703            "modelParameters": {
 41704              "approach": {}
 41705            },
 41706            "quantitativeAnalysis": {
 41707              "graphics": {}
 41708            },
 41709            "considerations": {}
 41710          }
 41711        },
 41712        {
 41713          "type": "library",
 41714          "bom-ref": "pkg:deb/debian/python@2.7.9-1?arch=amd64\u0026upstream=python-defaults\u0026distro=debian-8\u0026package-id=104d7baa8784e0c0",
 41715          "supplier": {},
 41716          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 41717          "name": "python",
 41718          "version": "2.7.9-1",
 41719          "cpe": "cpe:2.3:a:python:python:2.7.9-1:*:*:*:*:*:*:*",
 41720          "purl": "pkg:deb/debian/python@2.7.9-1?arch=amd64\u0026upstream=python-defaults\u0026distro=debian-8",
 41721          "swid": {
 41722            "attachment": {}
 41723          },
 41724          "pedigree": {},
 41725          "evidence": {},
 41726          "signature": {
 41727            "signature": {
 41728              "publicKey": {}
 41729            }
 41730          },
 41731          "modelCard": {
 41732            "modelParameters": {
 41733              "approach": {}
 41734            },
 41735            "quantitativeAnalysis": {
 41736              "graphics": {}
 41737            },
 41738            "considerations": {}
 41739          }
 41740        },
 41741        {
 41742          "type": "library",
 41743          "bom-ref": "pkg:deb/debian/python-bzrlib@2.6.0+bzr6595-6?arch=amd64\u0026upstream=bzr\u0026distro=debian-8\u0026package-id=cd10fc3ff4355444",
 41744          "supplier": {},
 41745          "publisher": "Debian Bazaar Maintainers \u003cpkg-bazaar-maint@lists.alioth.debian.org\u003e",
 41746          "name": "python-bzrlib",
 41747          "version": "2.6.0+bzr6595-6",
 41748          "licenses": [
 41749            {
 41750              "license": {
 41751                "id": "GPL-2.0-only"
 41752              }
 41753            },
 41754            {
 41755              "license": {
 41756                "id": "GPL-2.0-or-later"
 41757              }
 41758            }
 41759          ],
 41760          "cpe": "cpe:2.3:a:python-bzrlib:python-bzrlib:2.6.0\\+bzr6595-6:*:*:*:*:*:*:*",
 41761          "purl": "pkg:deb/debian/python-bzrlib@2.6.0+bzr6595-6?arch=amd64\u0026upstream=bzr\u0026distro=debian-8",
 41762          "swid": {
 41763            "attachment": {}
 41764          },
 41765          "pedigree": {},
 41766          "evidence": {},
 41767          "signature": {
 41768            "signature": {
 41769              "publicKey": {}
 41770            }
 41771          },
 41772          "modelCard": {
 41773            "modelParameters": {
 41774              "approach": {}
 41775            },
 41776            "quantitativeAnalysis": {
 41777              "graphics": {}
 41778            },
 41779            "considerations": {}
 41780          }
 41781        },
 41782        {
 41783          "type": "library",
 41784          "bom-ref": "pkg:deb/debian/python-configobj@5.0.6-1?arch=all\u0026upstream=configobj\u0026distro=debian-8\u0026package-id=e736a08144a4ffec",
 41785          "supplier": {},
 41786          "publisher": "Debian Python Modules Team \u003cpython-modules-team@lists.alioth.debian.org\u003e",
 41787          "name": "python-configobj",
 41788          "version": "5.0.6-1",
 41789          "licenses": [
 41790            {
 41791              "license": {
 41792                "id": "BSD-3-Clause"
 41793              }
 41794            }
 41795          ],
 41796          "cpe": "cpe:2.3:a:python-configobj:python-configobj:5.0.6-1:*:*:*:*:*:*:*",
 41797          "purl": "pkg:deb/debian/python-configobj@5.0.6-1?arch=all\u0026upstream=configobj\u0026distro=debian-8",
 41798          "swid": {
 41799            "attachment": {}
 41800          },
 41801          "pedigree": {},
 41802          "evidence": {},
 41803          "signature": {
 41804            "signature": {
 41805              "publicKey": {}
 41806            }
 41807          },
 41808          "modelCard": {
 41809            "modelParameters": {
 41810              "approach": {}
 41811            },
 41812            "quantitativeAnalysis": {
 41813              "graphics": {}
 41814            },
 41815            "considerations": {}
 41816          }
 41817        },
 41818        {
 41819          "type": "library",
 41820          "bom-ref": "pkg:deb/debian/python-minimal@2.7.9-1?arch=amd64\u0026upstream=python-defaults\u0026distro=debian-8\u0026package-id=d7505d4d03d180",
 41821          "supplier": {},
 41822          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 41823          "name": "python-minimal",
 41824          "version": "2.7.9-1",
 41825          "cpe": "cpe:2.3:a:python-minimal:python-minimal:2.7.9-1:*:*:*:*:*:*:*",
 41826          "purl": "pkg:deb/debian/python-minimal@2.7.9-1?arch=amd64\u0026upstream=python-defaults\u0026distro=debian-8",
 41827          "swid": {
 41828            "attachment": {}
 41829          },
 41830          "pedigree": {},
 41831          "evidence": {},
 41832          "signature": {
 41833            "signature": {
 41834              "publicKey": {}
 41835            }
 41836          },
 41837          "modelCard": {
 41838            "modelParameters": {
 41839              "approach": {}
 41840            },
 41841            "quantitativeAnalysis": {
 41842              "graphics": {}
 41843            },
 41844            "considerations": {}
 41845          }
 41846        },
 41847        {
 41848          "type": "library",
 41849          "bom-ref": "pkg:deb/debian/python-six@1.8.0-1?arch=all\u0026upstream=six\u0026distro=debian-8\u0026package-id=e0eafbcdb93fdbb2",
 41850          "supplier": {},
 41851          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
 41852          "name": "python-six",
 41853          "version": "1.8.0-1",
 41854          "licenses": [
 41855            {
 41856              "license": {
 41857                "name": "Expat"
 41858              }
 41859            }
 41860          ],
 41861          "cpe": "cpe:2.3:a:python-six:python-six:1.8.0-1:*:*:*:*:*:*:*",
 41862          "purl": "pkg:deb/debian/python-six@1.8.0-1?arch=all\u0026upstream=six\u0026distro=debian-8",
 41863          "swid": {
 41864            "attachment": {}
 41865          },
 41866          "pedigree": {},
 41867          "evidence": {},
 41868          "signature": {
 41869            "signature": {
 41870              "publicKey": {}
 41871            }
 41872          },
 41873          "modelCard": {
 41874            "modelParameters": {
 41875              "approach": {}
 41876            },
 41877            "quantitativeAnalysis": {
 41878              "graphics": {}
 41879            },
 41880            "considerations": {}
 41881          }
 41882        },
 41883        {
 41884          "type": "library",
 41885          "bom-ref": "pkg:deb/debian/python2.7@2.7.9-2?arch=amd64\u0026distro=debian-8\u0026package-id=b0ac297c1ad8ebf7",
 41886          "supplier": {},
 41887          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 41888          "name": "python2.7",
 41889          "version": "2.7.9-2",
 41890          "licenses": [
 41891            {
 41892              "license": {
 41893                "name": "#"
 41894              }
 41895            },
 41896            {
 41897              "license": {
 41898                "id": "Apache-2.0"
 41899              }
 41900            },
 41901            {
 41902              "license": {
 41903                "id": "GPL-2.0-only"
 41904              }
 41905            },
 41906            {
 41907              "license": {
 41908                "name": "Permission"
 41909              }
 41910            },
 41911            {
 41912              "license": {
 41913                "name": "This"
 41914              }
 41915            }
 41916          ],
 41917          "cpe": "cpe:2.3:a:python2.7:python2.7:2.7.9-2:*:*:*:*:*:*:*",
 41918          "purl": "pkg:deb/debian/python2.7@2.7.9-2?arch=amd64\u0026distro=debian-8",
 41919          "swid": {
 41920            "attachment": {}
 41921          },
 41922          "pedigree": {},
 41923          "evidence": {},
 41924          "signature": {
 41925            "signature": {
 41926              "publicKey": {}
 41927            }
 41928          },
 41929          "modelCard": {
 41930            "modelParameters": {
 41931              "approach": {}
 41932            },
 41933            "quantitativeAnalysis": {
 41934              "graphics": {}
 41935            },
 41936            "considerations": {}
 41937          }
 41938        },
 41939        {
 41940          "type": "library",
 41941          "bom-ref": "pkg:deb/debian/python2.7-minimal@2.7.9-2?arch=amd64\u0026upstream=python2.7\u0026distro=debian-8\u0026package-id=6d9cb4f7d630d3d1",
 41942          "supplier": {},
 41943          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 41944          "name": "python2.7-minimal",
 41945          "version": "2.7.9-2",
 41946          "licenses": [
 41947            {
 41948              "license": {
 41949                "name": "#"
 41950              }
 41951            },
 41952            {
 41953              "license": {
 41954                "id": "Apache-2.0"
 41955              }
 41956            },
 41957            {
 41958              "license": {
 41959                "id": "GPL-2.0-only"
 41960              }
 41961            },
 41962            {
 41963              "license": {
 41964                "name": "Permission"
 41965              }
 41966            },
 41967            {
 41968              "license": {
 41969                "name": "This"
 41970              }
 41971            }
 41972          ],
 41973          "cpe": "cpe:2.3:a:python2.7-minimal:python2.7-minimal:2.7.9-2:*:*:*:*:*:*:*",
 41974          "purl": "pkg:deb/debian/python2.7-minimal@2.7.9-2?arch=amd64\u0026upstream=python2.7\u0026distro=debian-8",
 41975          "swid": {
 41976            "attachment": {}
 41977          },
 41978          "pedigree": {},
 41979          "evidence": {},
 41980          "signature": {
 41981            "signature": {
 41982              "publicKey": {}
 41983            }
 41984          },
 41985          "modelCard": {
 41986            "modelParameters": {
 41987              "approach": {}
 41988            },
 41989            "quantitativeAnalysis": {
 41990              "graphics": {}
 41991            },
 41992            "considerations": {}
 41993          }
 41994        },
 41995        {
 41996          "type": "library",
 41997          "bom-ref": "pkg:deb/debian/readline-common@6.3-8?arch=all\u0026upstream=readline6\u0026distro=debian-8\u0026package-id=47429794eb15a36d",
 41998          "supplier": {},
 41999          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 42000          "name": "readline-common",
 42001          "version": "6.3-8",
 42002          "licenses": [
 42003            {
 42004              "license": {
 42005                "id": "GPL-3.0-only"
 42006              }
 42007            }
 42008          ],
 42009          "cpe": "cpe:2.3:a:readline-common:readline-common:6.3-8:*:*:*:*:*:*:*",
 42010          "purl": "pkg:deb/debian/readline-common@6.3-8?arch=all\u0026upstream=readline6\u0026distro=debian-8",
 42011          "swid": {
 42012            "attachment": {}
 42013          },
 42014          "pedigree": {},
 42015          "evidence": {},
 42016          "signature": {
 42017            "signature": {
 42018              "publicKey": {}
 42019            }
 42020          },
 42021          "modelCard": {
 42022            "modelParameters": {
 42023              "approach": {}
 42024            },
 42025            "quantitativeAnalysis": {
 42026              "graphics": {}
 42027            },
 42028            "considerations": {}
 42029          }
 42030        },
 42031        {
 42032          "type": "library",
 42033          "bom-ref": "pkg:deb/debian/sed@4.2.2-4+b1?arch=amd64\u0026upstream=sed%404.2.2-4\u0026distro=debian-8\u0026package-id=fdf4b97bde0d134",
 42034          "supplier": {},
 42035          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
 42036          "name": "sed",
 42037          "version": "4.2.2-4+b1",
 42038          "licenses": [
 42039            {
 42040              "license": {
 42041                "name": "GPL"
 42042              }
 42043            }
 42044          ],
 42045          "cpe": "cpe:2.3:a:sed:sed:4.2.2-4\\+b1:*:*:*:*:*:*:*",
 42046          "purl": "pkg:deb/debian/sed@4.2.2-4+b1?arch=amd64\u0026upstream=sed%404.2.2-4\u0026distro=debian-8",
 42047          "swid": {
 42048            "attachment": {}
 42049          },
 42050          "pedigree": {},
 42051          "evidence": {},
 42052          "signature": {
 42053            "signature": {
 42054              "publicKey": {}
 42055            }
 42056          },
 42057          "modelCard": {
 42058            "modelParameters": {
 42059              "approach": {}
 42060            },
 42061            "quantitativeAnalysis": {
 42062              "graphics": {}
 42063            },
 42064            "considerations": {}
 42065          }
 42066        },
 42067        {
 42068          "type": "library",
 42069          "bom-ref": "pkg:deb/debian/sensible-utils@0.0.9?arch=all\u0026distro=debian-8\u0026package-id=ea4a26855bf17184",
 42070          "supplier": {},
 42071          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 42072          "name": "sensible-utils",
 42073          "version": "0.0.9",
 42074          "licenses": [
 42075            {
 42076              "license": {
 42077                "id": "GPL-2.0-only"
 42078              }
 42079            }
 42080          ],
 42081          "cpe": "cpe:2.3:a:sensible-utils:sensible-utils:0.0.9:*:*:*:*:*:*:*",
 42082          "purl": "pkg:deb/debian/sensible-utils@0.0.9?arch=all\u0026distro=debian-8",
 42083          "swid": {
 42084            "attachment": {}
 42085          },
 42086          "pedigree": {},
 42087          "evidence": {},
 42088          "signature": {
 42089            "signature": {
 42090              "publicKey": {}
 42091            }
 42092          },
 42093          "modelCard": {
 42094            "modelParameters": {
 42095              "approach": {}
 42096            },
 42097            "quantitativeAnalysis": {
 42098              "graphics": {}
 42099            },
 42100            "considerations": {}
 42101          }
 42102        },
 42103        {
 42104          "type": "library",
 42105          "bom-ref": "pkg:pypi/six@1.8.0?package-id=1bcfd52c076d128",
 42106          "supplier": {},
 42107          "author": "Benjamin Peterson \u003cbenjamin@python.org\u003e",
 42108          "name": "six",
 42109          "version": "1.8.0",
 42110          "licenses": [
 42111            {
 42112              "license": {
 42113                "id": "MIT"
 42114              }
 42115            }
 42116          ],
 42117          "cpe": "cpe:2.3:a:benjamin_peterson_project:python-six:1.8.0:*:*:*:*:*:*:*",
 42118          "purl": "pkg:pypi/six@1.8.0",
 42119          "swid": {
 42120            "attachment": {}
 42121          },
 42122          "pedigree": {},
 42123          "evidence": {},
 42124          "signature": {
 42125            "signature": {
 42126              "publicKey": {}
 42127            }
 42128          },
 42129          "modelCard": {
 42130            "modelParameters": {
 42131              "approach": {}
 42132            },
 42133            "quantitativeAnalysis": {
 42134              "graphics": {}
 42135            },
 42136            "considerations": {}
 42137          }
 42138        },
 42139        {
 42140          "type": "library",
 42141          "bom-ref": "pkg:deb/debian/startpar@0.59-3?arch=amd64\u0026distro=debian-8\u0026package-id=a05410db1cb93dee",
 42142          "supplier": {},
 42143          "publisher": "Debian sysvinit maintainers \u003cpkg-sysvinit-devel@lists.alioth.debian.org\u003e",
 42144          "name": "startpar",
 42145          "version": "0.59-3",
 42146          "licenses": [
 42147            {
 42148              "license": {
 42149                "id": "GPL-2.0-only"
 42150              }
 42151            },
 42152            {
 42153              "license": {
 42154                "id": "GPL-2.0-or-later"
 42155              }
 42156            }
 42157          ],
 42158          "cpe": "cpe:2.3:a:startpar:startpar:0.59-3:*:*:*:*:*:*:*",
 42159          "purl": "pkg:deb/debian/startpar@0.59-3?arch=amd64\u0026distro=debian-8",
 42160          "swid": {
 42161            "attachment": {}
 42162          },
 42163          "pedigree": {},
 42164          "evidence": {},
 42165          "signature": {
 42166            "signature": {
 42167              "publicKey": {}
 42168            }
 42169          },
 42170          "modelCard": {
 42171            "modelParameters": {
 42172              "approach": {}
 42173            },
 42174            "quantitativeAnalysis": {
 42175              "graphics": {}
 42176            },
 42177            "considerations": {}
 42178          }
 42179        },
 42180        {
 42181          "type": "library",
 42182          "bom-ref": "pkg:deb/debian/subversion@1.8.10-6+deb8u4?arch=amd64\u0026distro=debian-8\u0026package-id=87fe9dbc637b8af0",
 42183          "supplier": {},
 42184          "publisher": "Peter Samuelson \u003cpeter@p12n.org\u003e",
 42185          "name": "subversion",
 42186          "version": "1.8.10-6+deb8u4",
 42187          "licenses": [
 42188            {
 42189              "license": {
 42190                "id": "Apache-2.0"
 42191              }
 42192            },
 42193            {
 42194              "license": {
 42195                "id": "GPL-2.0-only"
 42196              }
 42197            }
 42198          ],
 42199          "cpe": "cpe:2.3:a:subversion:subversion:1.8.10-6\\+deb8u4:*:*:*:*:*:*:*",
 42200          "purl": "pkg:deb/debian/subversion@1.8.10-6+deb8u4?arch=amd64\u0026distro=debian-8",
 42201          "swid": {
 42202            "attachment": {}
 42203          },
 42204          "pedigree": {},
 42205          "evidence": {},
 42206          "signature": {
 42207            "signature": {
 42208              "publicKey": {}
 42209            }
 42210          },
 42211          "modelCard": {
 42212            "modelParameters": {
 42213              "approach": {}
 42214            },
 42215            "quantitativeAnalysis": {
 42216              "graphics": {}
 42217            },
 42218            "considerations": {}
 42219          }
 42220        },
 42221        {
 42222          "type": "library",
 42223          "bom-ref": "pkg:deb/debian/systemd@215-17+deb8u4?arch=amd64\u0026distro=debian-8\u0026package-id=ff4720b988e68b2f",
 42224          "supplier": {},
 42225          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 42226          "name": "systemd",
 42227          "version": "215-17+deb8u4",
 42228          "licenses": [
 42229            {
 42230              "license": {
 42231                "name": "Expat"
 42232              }
 42233            },
 42234            {
 42235              "license": {
 42236                "id": "GPL-2.0-only"
 42237              }
 42238            },
 42239            {
 42240              "license": {
 42241                "id": "GPL-2.0-or-later"
 42242              }
 42243            },
 42244            {
 42245              "license": {
 42246                "id": "LGPL-2.1-only"
 42247              }
 42248            },
 42249            {
 42250              "license": {
 42251                "id": "LGPL-2.1-or-later"
 42252              }
 42253            },
 42254            {
 42255              "license": {
 42256                "name": "public-domain"
 42257              }
 42258            }
 42259          ],
 42260          "cpe": "cpe:2.3:a:systemd:systemd:215-17\\+deb8u4:*:*:*:*:*:*:*",
 42261          "purl": "pkg:deb/debian/systemd@215-17+deb8u4?arch=amd64\u0026distro=debian-8",
 42262          "swid": {
 42263            "attachment": {}
 42264          },
 42265          "pedigree": {},
 42266          "evidence": {},
 42267          "signature": {
 42268            "signature": {
 42269              "publicKey": {}
 42270            }
 42271          },
 42272          "modelCard": {
 42273            "modelParameters": {
 42274              "approach": {}
 42275            },
 42276            "quantitativeAnalysis": {
 42277              "graphics": {}
 42278            },
 42279            "considerations": {}
 42280          }
 42281        },
 42282        {
 42283          "type": "library",
 42284          "bom-ref": "pkg:deb/debian/systemd-sysv@215-17+deb8u4?arch=amd64\u0026upstream=systemd\u0026distro=debian-8\u0026package-id=74efa300267dd053",
 42285          "supplier": {},
 42286          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 42287          "name": "systemd-sysv",
 42288          "version": "215-17+deb8u4",
 42289          "licenses": [
 42290            {
 42291              "license": {
 42292                "name": "Expat"
 42293              }
 42294            },
 42295            {
 42296              "license": {
 42297                "id": "GPL-2.0-only"
 42298              }
 42299            },
 42300            {
 42301              "license": {
 42302                "id": "GPL-2.0-or-later"
 42303              }
 42304            },
 42305            {
 42306              "license": {
 42307                "id": "LGPL-2.1-only"
 42308              }
 42309            },
 42310            {
 42311              "license": {
 42312                "id": "LGPL-2.1-or-later"
 42313              }
 42314            },
 42315            {
 42316              "license": {
 42317                "name": "public-domain"
 42318              }
 42319            }
 42320          ],
 42321          "cpe": "cpe:2.3:a:systemd-sysv:systemd-sysv:215-17\\+deb8u4:*:*:*:*:*:*:*",
 42322          "purl": "pkg:deb/debian/systemd-sysv@215-17+deb8u4?arch=amd64\u0026upstream=systemd\u0026distro=debian-8",
 42323          "swid": {
 42324            "attachment": {}
 42325          },
 42326          "pedigree": {},
 42327          "evidence": {},
 42328          "signature": {
 42329            "signature": {
 42330              "publicKey": {}
 42331            }
 42332          },
 42333          "modelCard": {
 42334            "modelParameters": {
 42335              "approach": {}
 42336            },
 42337            "quantitativeAnalysis": {
 42338              "graphics": {}
 42339            },
 42340            "considerations": {}
 42341          }
 42342        },
 42343        {
 42344          "type": "library",
 42345          "bom-ref": "pkg:deb/debian/sysv-rc@2.88dsf-59?arch=all\u0026upstream=sysvinit\u0026distro=debian-8\u0026package-id=3d069fbd35864526",
 42346          "supplier": {},
 42347          "publisher": "Debian sysvinit maintainers \u003cpkg-sysvinit-devel@lists.alioth.debian.org\u003e",
 42348          "name": "sysv-rc",
 42349          "version": "2.88dsf-59",
 42350          "licenses": [
 42351            {
 42352              "license": {
 42353                "id": "GPL-2.0-only"
 42354              }
 42355            }
 42356          ],
 42357          "cpe": "cpe:2.3:a:sysv-rc:sysv-rc:2.88dsf-59:*:*:*:*:*:*:*",
 42358          "purl": "pkg:deb/debian/sysv-rc@2.88dsf-59?arch=all\u0026upstream=sysvinit\u0026distro=debian-8",
 42359          "swid": {
 42360            "attachment": {}
 42361          },
 42362          "pedigree": {},
 42363          "evidence": {},
 42364          "signature": {
 42365            "signature": {
 42366              "publicKey": {}
 42367            }
 42368          },
 42369          "modelCard": {
 42370            "modelParameters": {
 42371              "approach": {}
 42372            },
 42373            "quantitativeAnalysis": {
 42374              "graphics": {}
 42375            },
 42376            "considerations": {}
 42377          }
 42378        },
 42379        {
 42380          "type": "library",
 42381          "bom-ref": "pkg:deb/debian/sysvinit-utils@2.88dsf-59?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-8\u0026package-id=9f9ce336cd7efc01",
 42382          "supplier": {},
 42383          "publisher": "Debian sysvinit maintainers \u003cpkg-sysvinit-devel@lists.alioth.debian.org\u003e",
 42384          "name": "sysvinit-utils",
 42385          "version": "2.88dsf-59",
 42386          "licenses": [
 42387            {
 42388              "license": {
 42389                "id": "GPL-2.0-only"
 42390              }
 42391            }
 42392          ],
 42393          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.88dsf-59:*:*:*:*:*:*:*",
 42394          "purl": "pkg:deb/debian/sysvinit-utils@2.88dsf-59?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-8",
 42395          "swid": {
 42396            "attachment": {}
 42397          },
 42398          "pedigree": {},
 42399          "evidence": {},
 42400          "signature": {
 42401            "signature": {
 42402              "publicKey": {}
 42403            }
 42404          },
 42405          "modelCard": {
 42406            "modelParameters": {
 42407              "approach": {}
 42408            },
 42409            "quantitativeAnalysis": {
 42410              "graphics": {}
 42411            },
 42412            "considerations": {}
 42413          }
 42414        },
 42415        {
 42416          "type": "library",
 42417          "bom-ref": "pkg:deb/debian/tar@1.27.1-2+b1?arch=amd64\u0026upstream=tar%401.27.1-2\u0026distro=debian-8\u0026package-id=ead08fd3b3be7347",
 42418          "supplier": {},
 42419          "publisher": "Bdale Garbee \u003cbdale@gag.com\u003e",
 42420          "name": "tar",
 42421          "version": "1.27.1-2+b1",
 42422          "licenses": [
 42423            {
 42424              "license": {
 42425                "id": "GPL-2.0-only"
 42426              }
 42427            },
 42428            {
 42429              "license": {
 42430                "id": "GPL-3.0-only"
 42431              }
 42432            }
 42433          ],
 42434          "cpe": "cpe:2.3:a:tar:tar:1.27.1-2\\+b1:*:*:*:*:*:*:*",
 42435          "purl": "pkg:deb/debian/tar@1.27.1-2+b1?arch=amd64\u0026upstream=tar%401.27.1-2\u0026distro=debian-8",
 42436          "swid": {
 42437            "attachment": {}
 42438          },
 42439          "pedigree": {},
 42440          "evidence": {},
 42441          "signature": {
 42442            "signature": {
 42443              "publicKey": {}
 42444            }
 42445          },
 42446          "modelCard": {
 42447            "modelParameters": {
 42448              "approach": {}
 42449            },
 42450            "quantitativeAnalysis": {
 42451              "graphics": {}
 42452            },
 42453            "considerations": {}
 42454          }
 42455        },
 42456        {
 42457          "type": "library",
 42458          "bom-ref": "pkg:deb/debian/tzdata@2016f-0+deb8u1?arch=all\u0026distro=debian-8\u0026package-id=4beb92da24e5a9f6",
 42459          "supplier": {},
 42460          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 42461          "name": "tzdata",
 42462          "version": "2016f-0+deb8u1",
 42463          "cpe": "cpe:2.3:a:tzdata:tzdata:2016f-0\\+deb8u1:*:*:*:*:*:*:*",
 42464          "purl": "pkg:deb/debian/tzdata@2016f-0+deb8u1?arch=all\u0026distro=debian-8",
 42465          "swid": {
 42466            "attachment": {}
 42467          },
 42468          "pedigree": {},
 42469          "evidence": {},
 42470          "signature": {
 42471            "signature": {
 42472              "publicKey": {}
 42473            }
 42474          },
 42475          "modelCard": {
 42476            "modelParameters": {
 42477              "approach": {}
 42478            },
 42479            "quantitativeAnalysis": {
 42480              "graphics": {}
 42481            },
 42482            "considerations": {}
 42483          }
 42484        },
 42485        {
 42486          "type": "library",
 42487          "bom-ref": "pkg:deb/debian/ucf@3.0030?arch=all\u0026distro=debian-8\u0026package-id=c5577b6da214fa0b",
 42488          "supplier": {},
 42489          "publisher": "Manoj Srivastava \u003csrivasta@debian.org\u003e",
 42490          "name": "ucf",
 42491          "version": "3.0030",
 42492          "licenses": [
 42493            {
 42494              "license": {
 42495                "id": "GPL-2.0-only"
 42496              }
 42497            }
 42498          ],
 42499          "cpe": "cpe:2.3:a:ucf:ucf:3.0030:*:*:*:*:*:*:*",
 42500          "purl": "pkg:deb/debian/ucf@3.0030?arch=all\u0026distro=debian-8",
 42501          "swid": {
 42502            "attachment": {}
 42503          },
 42504          "pedigree": {},
 42505          "evidence": {},
 42506          "signature": {
 42507            "signature": {
 42508              "publicKey": {}
 42509            }
 42510          },
 42511          "modelCard": {
 42512            "modelParameters": {
 42513              "approach": {}
 42514            },
 42515            "quantitativeAnalysis": {
 42516              "graphics": {}
 42517            },
 42518            "considerations": {}
 42519          }
 42520        },
 42521        {
 42522          "type": "library",
 42523          "bom-ref": "pkg:deb/debian/udev@215-17+deb8u4?arch=amd64\u0026upstream=systemd\u0026distro=debian-8\u0026package-id=e19b271aa5145f84",
 42524          "supplier": {},
 42525          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 42526          "name": "udev",
 42527          "version": "215-17+deb8u4",
 42528          "licenses": [
 42529            {
 42530              "license": {
 42531                "name": "Expat"
 42532              }
 42533            },
 42534            {
 42535              "license": {
 42536                "id": "GPL-2.0-only"
 42537              }
 42538            },
 42539            {
 42540              "license": {
 42541                "id": "GPL-2.0-or-later"
 42542              }
 42543            },
 42544            {
 42545              "license": {
 42546                "id": "LGPL-2.1-only"
 42547              }
 42548            },
 42549            {
 42550              "license": {
 42551                "id": "LGPL-2.1-or-later"
 42552              }
 42553            },
 42554            {
 42555              "license": {
 42556                "name": "public-domain"
 42557              }
 42558            }
 42559          ],
 42560          "cpe": "cpe:2.3:a:udev:udev:215-17\\+deb8u4:*:*:*:*:*:*:*",
 42561          "purl": "pkg:deb/debian/udev@215-17+deb8u4?arch=amd64\u0026upstream=systemd\u0026distro=debian-8",
 42562          "swid": {
 42563            "attachment": {}
 42564          },
 42565          "pedigree": {},
 42566          "evidence": {},
 42567          "signature": {
 42568            "signature": {
 42569              "publicKey": {}
 42570            }
 42571          },
 42572          "modelCard": {
 42573            "modelParameters": {
 42574              "approach": {}
 42575            },
 42576            "quantitativeAnalysis": {
 42577              "graphics": {}
 42578            },
 42579            "considerations": {}
 42580          }
 42581        },
 42582        {
 42583          "type": "library",
 42584          "bom-ref": "pkg:deb/debian/util-linux@2.25.2-6?arch=amd64\u0026distro=debian-8\u0026package-id=560f81b9efb68e08",
 42585          "supplier": {},
 42586          "publisher": "Debian util-linux Maintainers \u003cah-util-linux@debian.org\u003e",
 42587          "name": "util-linux",
 42588          "version": "2.25.2-6",
 42589          "licenses": [
 42590            {
 42591              "license": {
 42592                "id": "BSD-2-Clause"
 42593              }
 42594            },
 42595            {
 42596              "license": {
 42597                "id": "BSD-3-Clause"
 42598              }
 42599            },
 42600            {
 42601              "license": {
 42602                "id": "BSD-4-Clause"
 42603              }
 42604            },
 42605            {
 42606              "license": {
 42607                "id": "GPL-2.0-only"
 42608              }
 42609            },
 42610            {
 42611              "license": {
 42612                "id": "GPL-2.0-or-later"
 42613              }
 42614            },
 42615            {
 42616              "license": {
 42617                "id": "GPL-3.0-only"
 42618              }
 42619            },
 42620            {
 42621              "license": {
 42622                "id": "GPL-3.0-or-later"
 42623              }
 42624            },
 42625            {
 42626              "license": {
 42627                "name": "LGPL"
 42628              }
 42629            },
 42630            {
 42631              "license": {
 42632                "id": "LGPL-2.0-only"
 42633              }
 42634            },
 42635            {
 42636              "license": {
 42637                "id": "LGPL-2.0-or-later"
 42638              }
 42639            },
 42640            {
 42641              "license": {
 42642                "id": "LGPL-2.1-only"
 42643              }
 42644            },
 42645            {
 42646              "license": {
 42647                "id": "LGPL-2.1-or-later"
 42648              }
 42649            },
 42650            {
 42651              "license": {
 42652                "id": "LGPL-3.0-only"
 42653              }
 42654            },
 42655            {
 42656              "license": {
 42657                "id": "LGPL-3.0-or-later"
 42658              }
 42659            },
 42660            {
 42661              "license": {
 42662                "id": "MIT"
 42663              }
 42664            },
 42665            {
 42666              "license": {
 42667                "name": "public-domain"
 42668              }
 42669            }
 42670          ],
 42671          "cpe": "cpe:2.3:a:util-linux:util-linux:2.25.2-6:*:*:*:*:*:*:*",
 42672          "purl": "pkg:deb/debian/util-linux@2.25.2-6?arch=amd64\u0026distro=debian-8",
 42673          "swid": {
 42674            "attachment": {}
 42675          },
 42676          "pedigree": {},
 42677          "evidence": {},
 42678          "signature": {
 42679            "signature": {
 42680              "publicKey": {}
 42681            }
 42682          },
 42683          "modelCard": {
 42684            "modelParameters": {
 42685              "approach": {}
 42686            },
 42687            "quantitativeAnalysis": {
 42688              "graphics": {}
 42689            },
 42690            "considerations": {}
 42691          }
 42692        },
 42693        {
 42694          "type": "library",
 42695          "bom-ref": "pkg:deb/debian/wget@1.16-1?arch=amd64\u0026distro=debian-8\u0026package-id=3857718b6e73ebdb",
 42696          "supplier": {},
 42697          "publisher": "Noël Köthe \u003cnoel@debian.org\u003e",
 42698          "name": "wget",
 42699          "version": "1.16-1",
 42700          "licenses": [
 42701            {
 42702              "license": {
 42703                "id": "GFDL-1.2-only"
 42704              }
 42705            },
 42706            {
 42707              "license": {
 42708                "id": "GPL-3.0-only"
 42709              }
 42710            }
 42711          ],
 42712          "cpe": "cpe:2.3:a:wget:wget:1.16-1:*:*:*:*:*:*:*",
 42713          "purl": "pkg:deb/debian/wget@1.16-1?arch=amd64\u0026distro=debian-8",
 42714          "swid": {
 42715            "attachment": {}
 42716          },
 42717          "pedigree": {},
 42718          "evidence": {},
 42719          "signature": {
 42720            "signature": {
 42721              "publicKey": {}
 42722            }
 42723          },
 42724          "modelCard": {
 42725            "modelParameters": {
 42726              "approach": {}
 42727            },
 42728            "quantitativeAnalysis": {
 42729              "graphics": {}
 42730            },
 42731            "considerations": {}
 42732          }
 42733        },
 42734        {
 42735          "type": "library",
 42736          "bom-ref": "pkg:pypi/wsgiref@0.1.2?package-id=f76569cabcd31278",
 42737          "supplier": {},
 42738          "author": "Phillip J. Eby \u003cweb-sig@python.org\u003e",
 42739          "name": "wsgiref",
 42740          "version": "0.1.2",
 42741          "licenses": [
 42742            {
 42743              "license": {
 42744                "name": "PSF or ZPL"
 42745              }
 42746            }
 42747          ],
 42748          "cpe": "cpe:2.3:a:phillip_j__eby_project:python-wsgiref:0.1.2:*:*:*:*:*:*:*",
 42749          "purl": "pkg:pypi/wsgiref@0.1.2",
 42750          "swid": {
 42751            "attachment": {}
 42752          },
 42753          "pedigree": {},
 42754          "evidence": {},
 42755          "signature": {
 42756            "signature": {
 42757              "publicKey": {}
 42758            }
 42759          },
 42760          "modelCard": {
 42761            "modelParameters": {
 42762              "approach": {}
 42763            },
 42764            "quantitativeAnalysis": {
 42765              "graphics": {}
 42766            },
 42767            "considerations": {}
 42768          }
 42769        },
 42770        {
 42771          "type": "library",
 42772          "bom-ref": "pkg:deb/debian/zlib1g@1:1.2.8.dfsg-2+b1?arch=amd64\u0026upstream=zlib%401:1.2.8.dfsg-2\u0026distro=debian-8\u0026package-id=6eb818573a94ca31",
 42773          "supplier": {},
 42774          "publisher": "Mark Brown \u003cbroonie@debian.org\u003e",
 42775          "name": "zlib1g",
 42776          "version": "1:1.2.8.dfsg-2+b1",
 42777          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.8.dfsg-2\\+b1:*:*:*:*:*:*:*",
 42778          "purl": "pkg:deb/debian/zlib1g@1:1.2.8.dfsg-2+b1?arch=amd64\u0026upstream=zlib%401:1.2.8.dfsg-2\u0026distro=debian-8",
 42779          "swid": {
 42780            "attachment": {}
 42781          },
 42782          "pedigree": {},
 42783          "evidence": {},
 42784          "signature": {
 42785            "signature": {
 42786              "publicKey": {}
 42787            }
 42788          },
 42789          "modelCard": {
 42790            "modelParameters": {
 42791              "approach": {}
 42792            },
 42793            "quantitativeAnalysis": {
 42794              "graphics": {}
 42795            },
 42796            "considerations": {}
 42797          }
 42798        },
 42799        {
 42800          "type": "operating-system",
 42801          "supplier": {},
 42802          "name": "debian",
 42803          "version": "8",
 42804          "description": "Debian GNU/Linux 8 (jessie)",
 42805          "swid": {
 42806            "tagId": "debian",
 42807            "name": "debian",
 42808            "version": "8",
 42809            "attachment": {}
 42810          },
 42811          "pedigree": {},
 42812          "externalReferences": [
 42813            {
 42814              "url": "https://bugs.debian.org/",
 42815              "type": "issue-tracker"
 42816            },
 42817            {
 42818              "url": "http://www.debian.org/",
 42819              "type": "website"
 42820            },
 42821            {
 42822              "url": "http://www.debian.org/support",
 42823              "comment": "support",
 42824              "type": "other"
 42825            }
 42826          ],
 42827          "evidence": {},
 42828          "signature": {
 42829            "signature": {
 42830              "publicKey": {}
 42831            }
 42832          },
 42833          "modelCard": {
 42834            "modelParameters": {
 42835              "approach": {}
 42836            },
 42837            "quantitativeAnalysis": {
 42838              "graphics": {}
 42839            },
 42840            "considerations": {}
 42841          }
 42842        },
 42843        {
 42844          "type": "application",
 42845          "bom-ref": "pkg:generic/traefik@1.7.19?package-id=f7a4c93610e4abfd",
 42846          "supplier": {},
 42847          "name": "traefik",
 42848          "version": "1.7.19",
 42849          "cpe": "cpe:2.3:a:traefik:traefik:1.7.19:*:*:*:*:*:*:*",
 42850          "purl": "pkg:generic/traefik@1.7.19",
 42851          "swid": {
 42852            "attachment": {}
 42853          },
 42854          "pedigree": {},
 42855          "evidence": {},
 42856          "signature": {
 42857            "signature": {
 42858              "publicKey": {}
 42859            }
 42860          },
 42861          "modelCard": {
 42862            "modelParameters": {
 42863              "approach": {}
 42864            },
 42865            "quantitativeAnalysis": {
 42866              "graphics": {}
 42867            },
 42868            "considerations": {}
 42869          }
 42870        },
 42871        {
 42872          "type": "library",
 42873          "bom-ref": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04\u0026package-id=69d1980477020fa3",
 42874          "supplier": {},
 42875          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 42876          "name": "adduser",
 42877          "version": "3.118ubuntu2",
 42878          "licenses": [
 42879            {
 42880              "license": {
 42881                "id": "GPL-2.0-only"
 42882              }
 42883            }
 42884          ],
 42885          "cpe": "cpe:2.3:a:adduser:adduser:3.118ubuntu2:*:*:*:*:*:*:*",
 42886          "purl": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04",
 42887          "swid": {
 42888            "attachment": {}
 42889          },
 42890          "pedigree": {},
 42891          "evidence": {},
 42892          "signature": {
 42893            "signature": {
 42894              "publicKey": {}
 42895            }
 42896          },
 42897          "modelCard": {
 42898            "modelParameters": {
 42899              "approach": {}
 42900            },
 42901            "quantitativeAnalysis": {
 42902              "graphics": {}
 42903            },
 42904            "considerations": {}
 42905          }
 42906        },
 42907        {
 42908          "type": "library",
 42909          "bom-ref": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=55988ea1c6f336e3",
 42910          "supplier": {},
 42911          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 42912          "name": "apt",
 42913          "version": "2.0.6",
 42914          "licenses": [
 42915            {
 42916              "license": {
 42917                "id": "GPL-2.0-only"
 42918              }
 42919            },
 42920            {
 42921              "license": {
 42922                "name": "GPLv2+"
 42923              }
 42924            }
 42925          ],
 42926          "cpe": "cpe:2.3:a:apt:apt:2.0.6:*:*:*:*:*:*:*",
 42927          "purl": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04",
 42928          "swid": {
 42929            "attachment": {}
 42930          },
 42931          "pedigree": {},
 42932          "evidence": {},
 42933          "signature": {
 42934            "signature": {
 42935              "publicKey": {}
 42936            }
 42937          },
 42938          "modelCard": {
 42939            "modelParameters": {
 42940              "approach": {}
 42941            },
 42942            "quantitativeAnalysis": {
 42943              "graphics": {}
 42944            },
 42945            "considerations": {}
 42946          }
 42947        },
 42948        {
 42949          "type": "library",
 42950          "bom-ref": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=63c89c28c512e1db",
 42951          "supplier": {},
 42952          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 42953          "name": "base-files",
 42954          "version": "11ubuntu5.4",
 42955          "licenses": [
 42956            {
 42957              "license": {
 42958                "name": "GPL"
 42959              }
 42960            }
 42961          ],
 42962          "cpe": "cpe:2.3:a:base-files:base-files:11ubuntu5.4:*:*:*:*:*:*:*",
 42963          "purl": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04",
 42964          "swid": {
 42965            "attachment": {}
 42966          },
 42967          "pedigree": {},
 42968          "evidence": {},
 42969          "signature": {
 42970            "signature": {
 42971              "publicKey": {}
 42972            }
 42973          },
 42974          "modelCard": {
 42975            "modelParameters": {
 42976              "approach": {}
 42977            },
 42978            "quantitativeAnalysis": {
 42979              "graphics": {}
 42980            },
 42981            "considerations": {}
 42982          }
 42983        },
 42984        {
 42985          "type": "library",
 42986          "bom-ref": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=8b6e494dac6dab09",
 42987          "supplier": {},
 42988          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
 42989          "name": "base-passwd",
 42990          "version": "3.5.47",
 42991          "licenses": [
 42992            {
 42993              "license": {
 42994                "id": "GPL-2.0-only"
 42995              }
 42996            },
 42997            {
 42998              "license": {
 42999                "name": "PD"
 43000              }
 43001            }
 43002          ],
 43003          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.47:*:*:*:*:*:*:*",
 43004          "purl": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04",
 43005          "swid": {
 43006            "attachment": {}
 43007          },
 43008          "pedigree": {},
 43009          "evidence": {},
 43010          "signature": {
 43011            "signature": {
 43012              "publicKey": {}
 43013            }
 43014          },
 43015          "modelCard": {
 43016            "modelParameters": {
 43017              "approach": {}
 43018            },
 43019            "quantitativeAnalysis": {
 43020              "graphics": {}
 43021            },
 43022            "considerations": {}
 43023          }
 43024        },
 43025        {
 43026          "type": "library",
 43027          "bom-ref": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e774a3e87113196b",
 43028          "supplier": {},
 43029          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43030          "name": "bash",
 43031          "version": "5.0-6ubuntu1.1",
 43032          "licenses": [
 43033            {
 43034              "license": {
 43035                "id": "GPL-3.0-only"
 43036              }
 43037            }
 43038          ],
 43039          "cpe": "cpe:2.3:a:bash:bash:5.0-6ubuntu1.1:*:*:*:*:*:*:*",
 43040          "purl": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04",
 43041          "swid": {
 43042            "attachment": {}
 43043          },
 43044          "pedigree": {},
 43045          "evidence": {},
 43046          "signature": {
 43047            "signature": {
 43048              "publicKey": {}
 43049            }
 43050          },
 43051          "modelCard": {
 43052            "modelParameters": {
 43053              "approach": {}
 43054            },
 43055            "quantitativeAnalysis": {
 43056              "graphics": {}
 43057            },
 43058            "considerations": {}
 43059          }
 43060        },
 43061        {
 43062          "type": "library",
 43063          "bom-ref": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04\u0026package-id=20018d8de777eda9",
 43064          "supplier": {},
 43065          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43066          "name": "bsdutils",
 43067          "version": "1:2.34-0.1ubuntu9.1",
 43068          "licenses": [
 43069            {
 43070              "license": {
 43071                "id": "BSD-2-Clause"
 43072              }
 43073            },
 43074            {
 43075              "license": {
 43076                "id": "BSD-3-Clause"
 43077              }
 43078            },
 43079            {
 43080              "license": {
 43081                "id": "BSD-4-Clause"
 43082              }
 43083            },
 43084            {
 43085              "license": {
 43086                "id": "GPL-2.0-only"
 43087              }
 43088            },
 43089            {
 43090              "license": {
 43091                "id": "GPL-2.0-or-later"
 43092              }
 43093            },
 43094            {
 43095              "license": {
 43096                "id": "GPL-3.0-only"
 43097              }
 43098            },
 43099            {
 43100              "license": {
 43101                "id": "GPL-3.0-or-later"
 43102              }
 43103            },
 43104            {
 43105              "license": {
 43106                "name": "LGPL"
 43107              }
 43108            },
 43109            {
 43110              "license": {
 43111                "id": "LGPL-2.0-only"
 43112              }
 43113            },
 43114            {
 43115              "license": {
 43116                "id": "LGPL-2.0-or-later"
 43117              }
 43118            },
 43119            {
 43120              "license": {
 43121                "id": "LGPL-2.1-only"
 43122              }
 43123            },
 43124            {
 43125              "license": {
 43126                "id": "LGPL-2.1-or-later"
 43127              }
 43128            },
 43129            {
 43130              "license": {
 43131                "id": "LGPL-3.0-only"
 43132              }
 43133            },
 43134            {
 43135              "license": {
 43136                "id": "LGPL-3.0-or-later"
 43137              }
 43138            },
 43139            {
 43140              "license": {
 43141                "id": "MIT"
 43142              }
 43143            },
 43144            {
 43145              "license": {
 43146                "name": "public-domain"
 43147              }
 43148            }
 43149          ],
 43150          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 43151          "purl": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04",
 43152          "swid": {
 43153            "attachment": {}
 43154          },
 43155          "pedigree": {},
 43156          "evidence": {},
 43157          "signature": {
 43158            "signature": {
 43159              "publicKey": {}
 43160            }
 43161          },
 43162          "modelCard": {
 43163            "modelParameters": {
 43164              "approach": {}
 43165            },
 43166            "quantitativeAnalysis": {
 43167              "graphics": {}
 43168            },
 43169            "considerations": {}
 43170          }
 43171        },
 43172        {
 43173          "type": "library",
 43174          "bom-ref": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=97dab883cac4c956",
 43175          "supplier": {},
 43176          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43177          "name": "bzip2",
 43178          "version": "1.0.8-2",
 43179          "licenses": [
 43180            {
 43181              "license": {
 43182                "name": "BSD-variant"
 43183              }
 43184            },
 43185            {
 43186              "license": {
 43187                "id": "GPL-2.0-only"
 43188              }
 43189            }
 43190          ],
 43191          "cpe": "cpe:2.3:a:bzip2:bzip2:1.0.8-2:*:*:*:*:*:*:*",
 43192          "purl": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04",
 43193          "swid": {
 43194            "attachment": {}
 43195          },
 43196          "pedigree": {},
 43197          "evidence": {},
 43198          "signature": {
 43199            "signature": {
 43200              "publicKey": {}
 43201            }
 43202          },
 43203          "modelCard": {
 43204            "modelParameters": {
 43205              "approach": {}
 43206            },
 43207            "quantitativeAnalysis": {
 43208              "graphics": {}
 43209            },
 43210            "considerations": {}
 43211          }
 43212        },
 43213        {
 43214          "type": "library",
 43215          "bom-ref": "pkg:deb/ubuntu/ca-certificates@20210119~20.04.2?arch=all\u0026distro=ubuntu-20.04\u0026package-id=283e5b8702c92c66",
 43216          "supplier": {},
 43217          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43218          "name": "ca-certificates",
 43219          "version": "20210119~20.04.2",
 43220          "licenses": [
 43221            {
 43222              "license": {
 43223                "id": "GPL-2.0-only"
 43224              }
 43225            },
 43226            {
 43227              "license": {
 43228                "id": "GPL-2.0-or-later"
 43229              }
 43230            },
 43231            {
 43232              "license": {
 43233                "id": "MPL-2.0"
 43234              }
 43235            }
 43236          ],
 43237          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20210119\\~20.04.2:*:*:*:*:*:*:*",
 43238          "purl": "pkg:deb/ubuntu/ca-certificates@20210119~20.04.2?arch=all\u0026distro=ubuntu-20.04",
 43239          "swid": {
 43240            "attachment": {}
 43241          },
 43242          "pedigree": {},
 43243          "evidence": {},
 43244          "signature": {
 43245            "signature": {
 43246              "publicKey": {}
 43247            }
 43248          },
 43249          "modelCard": {
 43250            "modelParameters": {
 43251              "approach": {}
 43252            },
 43253            "quantitativeAnalysis": {
 43254              "graphics": {}
 43255            },
 43256            "considerations": {}
 43257          }
 43258        },
 43259        {
 43260          "type": "library",
 43261          "bom-ref": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f77283ee51e117fa",
 43262          "supplier": {},
 43263          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43264          "name": "coreutils",
 43265          "version": "8.30-3ubuntu2",
 43266          "licenses": [
 43267            {
 43268              "license": {
 43269                "id": "GPL-3.0-only"
 43270              }
 43271            }
 43272          ],
 43273          "cpe": "cpe:2.3:a:coreutils:coreutils:8.30-3ubuntu2:*:*:*:*:*:*:*",
 43274          "purl": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
 43275          "swid": {
 43276            "attachment": {}
 43277          },
 43278          "pedigree": {},
 43279          "evidence": {},
 43280          "signature": {
 43281            "signature": {
 43282              "publicKey": {}
 43283            }
 43284          },
 43285          "modelCard": {
 43286            "modelParameters": {
 43287              "approach": {}
 43288            },
 43289            "quantitativeAnalysis": {
 43290              "graphics": {}
 43291            },
 43292            "considerations": {}
 43293          }
 43294        },
 43295        {
 43296          "type": "library",
 43297          "bom-ref": "pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.7?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=4413836d2c32d64c",
 43298          "supplier": {},
 43299          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43300          "name": "curl",
 43301          "version": "7.68.0-1ubuntu2.7",
 43302          "licenses": [
 43303            {
 43304              "license": {
 43305                "id": "BSD-3-Clause"
 43306              }
 43307            },
 43308            {
 43309              "license": {
 43310                "id": "BSD-4-Clause"
 43311              }
 43312            },
 43313            {
 43314              "license": {
 43315                "id": "ISC"
 43316              }
 43317            },
 43318            {
 43319              "license": {
 43320                "id": "curl"
 43321              }
 43322            },
 43323            {
 43324              "license": {
 43325                "name": "other"
 43326              }
 43327            },
 43328            {
 43329              "license": {
 43330                "name": "public-domain"
 43331              }
 43332            }
 43333          ],
 43334          "cpe": "cpe:2.3:a:curl:curl:7.68.0-1ubuntu2.7:*:*:*:*:*:*:*",
 43335          "purl": "pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.7?arch=amd64\u0026distro=ubuntu-20.04",
 43336          "swid": {
 43337            "attachment": {}
 43338          },
 43339          "pedigree": {},
 43340          "evidence": {},
 43341          "signature": {
 43342            "signature": {
 43343              "publicKey": {}
 43344            }
 43345          },
 43346          "modelCard": {
 43347            "modelParameters": {
 43348              "approach": {}
 43349            },
 43350            "quantitativeAnalysis": {
 43351              "graphics": {}
 43352            },
 43353            "considerations": {}
 43354          }
 43355        },
 43356        {
 43357          "type": "library",
 43358          "bom-ref": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=fa0f613df8411b7",
 43359          "supplier": {},
 43360          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43361          "name": "dash",
 43362          "version": "0.5.10.2-6",
 43363          "licenses": [
 43364            {
 43365              "license": {
 43366                "name": "GPL"
 43367              }
 43368            }
 43369          ],
 43370          "cpe": "cpe:2.3:a:dash:dash:0.5.10.2-6:*:*:*:*:*:*:*",
 43371          "purl": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04",
 43372          "swid": {
 43373            "attachment": {}
 43374          },
 43375          "pedigree": {},
 43376          "evidence": {},
 43377          "signature": {
 43378            "signature": {
 43379              "publicKey": {}
 43380            }
 43381          },
 43382          "modelCard": {
 43383            "modelParameters": {
 43384              "approach": {}
 43385            },
 43386            "quantitativeAnalysis": {
 43387              "graphics": {}
 43388            },
 43389            "considerations": {}
 43390          }
 43391        },
 43392        {
 43393          "type": "library",
 43394          "bom-ref": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04\u0026package-id=128eb6066f5ec19c",
 43395          "supplier": {},
 43396          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43397          "name": "debconf",
 43398          "version": "1.5.73",
 43399          "licenses": [
 43400            {
 43401              "license": {
 43402                "id": "BSD-2-Clause"
 43403              }
 43404            }
 43405          ],
 43406          "cpe": "cpe:2.3:a:debconf:debconf:1.5.73:*:*:*:*:*:*:*",
 43407          "purl": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04",
 43408          "swid": {
 43409            "attachment": {}
 43410          },
 43411          "pedigree": {},
 43412          "evidence": {},
 43413          "signature": {
 43414            "signature": {
 43415              "publicKey": {}
 43416            }
 43417          },
 43418          "modelCard": {
 43419            "modelParameters": {
 43420              "approach": {}
 43421            },
 43422            "quantitativeAnalysis": {
 43423              "graphics": {}
 43424            },
 43425            "considerations": {}
 43426          }
 43427        },
 43428        {
 43429          "type": "library",
 43430          "bom-ref": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=328b1094024bda26",
 43431          "supplier": {},
 43432          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43433          "name": "debianutils",
 43434          "version": "4.9.1",
 43435          "licenses": [
 43436            {
 43437              "license": {
 43438                "name": "GPL"
 43439              }
 43440            }
 43441          ],
 43442          "cpe": "cpe:2.3:a:debianutils:debianutils:4.9.1:*:*:*:*:*:*:*",
 43443          "purl": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04",
 43444          "swid": {
 43445            "attachment": {}
 43446          },
 43447          "pedigree": {},
 43448          "evidence": {},
 43449          "signature": {
 43450            "signature": {
 43451              "publicKey": {}
 43452            }
 43453          },
 43454          "modelCard": {
 43455            "modelParameters": {
 43456              "approach": {}
 43457            },
 43458            "quantitativeAnalysis": {
 43459              "graphics": {}
 43460            },
 43461            "considerations": {}
 43462          }
 43463        },
 43464        {
 43465          "type": "library",
 43466          "bom-ref": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=d21aefcaf9c9c9b6",
 43467          "supplier": {},
 43468          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43469          "name": "diffutils",
 43470          "version": "1:3.7-3",
 43471          "licenses": [
 43472            {
 43473              "license": {
 43474                "name": "GFDL"
 43475              }
 43476            },
 43477            {
 43478              "license": {
 43479                "name": "GPL"
 43480              }
 43481            }
 43482          ],
 43483          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-3:*:*:*:*:*:*:*",
 43484          "purl": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04",
 43485          "swid": {
 43486            "attachment": {}
 43487          },
 43488          "pedigree": {},
 43489          "evidence": {},
 43490          "signature": {
 43491            "signature": {
 43492              "publicKey": {}
 43493            }
 43494          },
 43495          "modelCard": {
 43496            "modelParameters": {
 43497              "approach": {}
 43498            },
 43499            "quantitativeAnalysis": {
 43500              "graphics": {}
 43501            },
 43502            "considerations": {}
 43503          }
 43504        },
 43505        {
 43506          "type": "library",
 43507          "bom-ref": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=c0d6316be2747294",
 43508          "supplier": {},
 43509          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43510          "name": "dmsetup",
 43511          "version": "2:1.02.167-1ubuntu1",
 43512          "licenses": [
 43513            {
 43514              "license": {
 43515                "id": "BSD-2-Clause"
 43516              }
 43517            },
 43518            {
 43519              "license": {
 43520                "id": "GPL-2.0-only"
 43521              }
 43522            },
 43523            {
 43524              "license": {
 43525                "id": "GPL-2.0-only"
 43526              }
 43527            },
 43528            {
 43529              "license": {
 43530                "id": "GPL-2.0-or-later"
 43531              }
 43532            },
 43533            {
 43534              "license": {
 43535                "id": "LGPL-2.0-only"
 43536              }
 43537            },
 43538            {
 43539              "license": {
 43540                "id": "LGPL-2.1-only"
 43541              }
 43542            }
 43543          ],
 43544          "cpe": "cpe:2.3:a:dmsetup:dmsetup:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
 43545          "purl": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
 43546          "swid": {
 43547            "attachment": {}
 43548          },
 43549          "pedigree": {},
 43550          "evidence": {},
 43551          "signature": {
 43552            "signature": {
 43553              "publicKey": {}
 43554            }
 43555          },
 43556          "modelCard": {
 43557            "modelParameters": {
 43558              "approach": {}
 43559            },
 43560            "quantitativeAnalysis": {
 43561              "graphics": {}
 43562            },
 43563            "considerations": {}
 43564          }
 43565        },
 43566        {
 43567          "type": "library",
 43568          "bom-ref": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e28aea5c134a7f8",
 43569          "supplier": {},
 43570          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43571          "name": "dpkg",
 43572          "version": "1.19.7ubuntu3",
 43573          "licenses": [
 43574            {
 43575              "license": {
 43576                "id": "BSD-2-Clause"
 43577              }
 43578            },
 43579            {
 43580              "license": {
 43581                "id": "GPL-2.0-only"
 43582              }
 43583            },
 43584            {
 43585              "license": {
 43586                "id": "GPL-2.0-or-later"
 43587              }
 43588            },
 43589            {
 43590              "license": {
 43591                "name": "public-domain-md5"
 43592              }
 43593            },
 43594            {
 43595              "license": {
 43596                "name": "public-domain-s-s-d"
 43597              }
 43598            }
 43599          ],
 43600          "cpe": "cpe:2.3:a:dpkg:dpkg:1.19.7ubuntu3:*:*:*:*:*:*:*",
 43601          "purl": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04",
 43602          "swid": {
 43603            "attachment": {}
 43604          },
 43605          "pedigree": {},
 43606          "evidence": {},
 43607          "signature": {
 43608            "signature": {
 43609              "publicKey": {}
 43610            }
 43611          },
 43612          "modelCard": {
 43613            "modelParameters": {
 43614              "approach": {}
 43615            },
 43616            "quantitativeAnalysis": {
 43617              "graphics": {}
 43618            },
 43619            "considerations": {}
 43620          }
 43621        },
 43622        {
 43623          "type": "library",
 43624          "bom-ref": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=6a037357f3ebf47a",
 43625          "supplier": {},
 43626          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43627          "name": "e2fsprogs",
 43628          "version": "1.45.5-2ubuntu1",
 43629          "licenses": [
 43630            {
 43631              "license": {
 43632                "id": "GPL-2.0-only"
 43633              }
 43634            },
 43635            {
 43636              "license": {
 43637                "id": "LGPL-2.0-only"
 43638              }
 43639            }
 43640          ],
 43641          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 43642          "purl": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 43643          "swid": {
 43644            "attachment": {}
 43645          },
 43646          "pedigree": {},
 43647          "evidence": {},
 43648          "signature": {
 43649            "signature": {
 43650              "publicKey": {}
 43651            }
 43652          },
 43653          "modelCard": {
 43654            "modelParameters": {
 43655              "approach": {}
 43656            },
 43657            "quantitativeAnalysis": {
 43658              "graphics": {}
 43659            },
 43660            "considerations": {}
 43661          }
 43662        },
 43663        {
 43664          "type": "library",
 43665          "bom-ref": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=a57a5f37c7970fe9",
 43666          "supplier": {},
 43667          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43668          "name": "fdisk",
 43669          "version": "2.34-0.1ubuntu9.1",
 43670          "licenses": [
 43671            {
 43672              "license": {
 43673                "id": "BSD-2-Clause"
 43674              }
 43675            },
 43676            {
 43677              "license": {
 43678                "id": "BSD-3-Clause"
 43679              }
 43680            },
 43681            {
 43682              "license": {
 43683                "id": "BSD-4-Clause"
 43684              }
 43685            },
 43686            {
 43687              "license": {
 43688                "id": "GPL-2.0-only"
 43689              }
 43690            },
 43691            {
 43692              "license": {
 43693                "id": "GPL-2.0-or-later"
 43694              }
 43695            },
 43696            {
 43697              "license": {
 43698                "id": "GPL-3.0-only"
 43699              }
 43700            },
 43701            {
 43702              "license": {
 43703                "id": "GPL-3.0-or-later"
 43704              }
 43705            },
 43706            {
 43707              "license": {
 43708                "name": "LGPL"
 43709              }
 43710            },
 43711            {
 43712              "license": {
 43713                "id": "LGPL-2.0-only"
 43714              }
 43715            },
 43716            {
 43717              "license": {
 43718                "id": "LGPL-2.0-or-later"
 43719              }
 43720            },
 43721            {
 43722              "license": {
 43723                "id": "LGPL-2.1-only"
 43724              }
 43725            },
 43726            {
 43727              "license": {
 43728                "id": "LGPL-2.1-or-later"
 43729              }
 43730            },
 43731            {
 43732              "license": {
 43733                "id": "LGPL-3.0-only"
 43734              }
 43735            },
 43736            {
 43737              "license": {
 43738                "id": "LGPL-3.0-or-later"
 43739              }
 43740            },
 43741            {
 43742              "license": {
 43743                "id": "MIT"
 43744              }
 43745            },
 43746            {
 43747              "license": {
 43748                "name": "public-domain"
 43749              }
 43750            }
 43751          ],
 43752          "cpe": "cpe:2.3:a:fdisk:fdisk:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 43753          "purl": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 43754          "swid": {
 43755            "attachment": {}
 43756          },
 43757          "pedigree": {},
 43758          "evidence": {},
 43759          "signature": {
 43760            "signature": {
 43761              "publicKey": {}
 43762            }
 43763          },
 43764          "modelCard": {
 43765            "modelParameters": {
 43766              "approach": {}
 43767            },
 43768            "quantitativeAnalysis": {
 43769              "graphics": {}
 43770            },
 43771            "considerations": {}
 43772          }
 43773        },
 43774        {
 43775          "type": "library",
 43776          "bom-ref": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7f183ce6dc05cfb",
 43777          "supplier": {},
 43778          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43779          "name": "file",
 43780          "version": "1:5.38-4",
 43781          "licenses": [
 43782            {
 43783              "license": {
 43784                "name": "BSD-2-Clause-alike"
 43785              }
 43786            },
 43787            {
 43788              "license": {
 43789                "id": "BSD-2-Clause"
 43790              }
 43791            },
 43792            {
 43793              "license": {
 43794                "name": "BSD-2-Clause-regents"
 43795              }
 43796            },
 43797            {
 43798              "license": {
 43799                "name": "MIT-Old-Style-with-legal-disclaimer-2"
 43800              }
 43801            },
 43802            {
 43803              "license": {
 43804                "name": "public-domain"
 43805              }
 43806            }
 43807          ],
 43808          "cpe": "cpe:2.3:a:file:file:1\\:5.38-4:*:*:*:*:*:*:*",
 43809          "purl": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04",
 43810          "swid": {
 43811            "attachment": {}
 43812          },
 43813          "pedigree": {},
 43814          "evidence": {},
 43815          "signature": {
 43816            "signature": {
 43817              "publicKey": {}
 43818            }
 43819          },
 43820          "modelCard": {
 43821            "modelParameters": {
 43822              "approach": {}
 43823            },
 43824            "quantitativeAnalysis": {
 43825              "graphics": {}
 43826            },
 43827            "considerations": {}
 43828          }
 43829        },
 43830        {
 43831          "type": "library",
 43832          "bom-ref": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=103a5999463b7e08",
 43833          "supplier": {},
 43834          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43835          "name": "findutils",
 43836          "version": "4.7.0-1ubuntu1",
 43837          "licenses": [
 43838            {
 43839              "license": {
 43840                "id": "GFDL-1.3-only"
 43841              }
 43842            },
 43843            {
 43844              "license": {
 43845                "id": "GPL-3.0-only"
 43846              }
 43847            }
 43848          ],
 43849          "cpe": "cpe:2.3:a:findutils:findutils:4.7.0-1ubuntu1:*:*:*:*:*:*:*",
 43850          "purl": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 43851          "swid": {
 43852            "attachment": {}
 43853          },
 43854          "pedigree": {},
 43855          "evidence": {},
 43856          "signature": {
 43857            "signature": {
 43858              "publicKey": {}
 43859            }
 43860          },
 43861          "modelCard": {
 43862            "modelParameters": {
 43863              "approach": {}
 43864            },
 43865            "quantitativeAnalysis": {
 43866              "graphics": {}
 43867            },
 43868            "considerations": {}
 43869          }
 43870        },
 43871        {
 43872          "type": "library",
 43873          "bom-ref": "pkg:deb/ubuntu/fuse@2.9.9-3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=3862cd07205c94e",
 43874          "supplier": {},
 43875          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43876          "name": "fuse",
 43877          "version": "2.9.9-3",
 43878          "licenses": [
 43879            {
 43880              "license": {
 43881                "id": "GPL-2.0-only"
 43882              }
 43883            },
 43884            {
 43885              "license": {
 43886                "id": "GPL-2.0-or-later"
 43887              }
 43888            },
 43889            {
 43890              "license": {
 43891                "id": "LGPL-2.0-only"
 43892              }
 43893            }
 43894          ],
 43895          "cpe": "cpe:2.3:a:fuse:fuse:2.9.9-3:*:*:*:*:*:*:*",
 43896          "purl": "pkg:deb/ubuntu/fuse@2.9.9-3?arch=amd64\u0026distro=ubuntu-20.04",
 43897          "swid": {
 43898            "attachment": {}
 43899          },
 43900          "pedigree": {},
 43901          "evidence": {},
 43902          "signature": {
 43903            "signature": {
 43904              "publicKey": {}
 43905            }
 43906          },
 43907          "modelCard": {
 43908            "modelParameters": {
 43909              "approach": {}
 43910            },
 43911            "quantitativeAnalysis": {
 43912              "graphics": {}
 43913            },
 43914            "considerations": {}
 43915          }
 43916        },
 43917        {
 43918          "type": "library",
 43919          "bom-ref": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=a268d6ad2986f239",
 43920          "supplier": {},
 43921          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 43922          "name": "gcc-10-base",
 43923          "version": "10.3.0-1ubuntu1~20.04",
 43924          "licenses": [
 43925            {
 43926              "license": {
 43927                "name": "Artistic"
 43928              }
 43929            },
 43930            {
 43931              "license": {
 43932                "id": "GFDL-1.2-only"
 43933              }
 43934            },
 43935            {
 43936              "license": {
 43937                "name": "GPL"
 43938              }
 43939            },
 43940            {
 43941              "license": {
 43942                "id": "GPL-2.0-only"
 43943              }
 43944            },
 43945            {
 43946              "license": {
 43947                "id": "GPL-3.0-only"
 43948              }
 43949            },
 43950            {
 43951              "license": {
 43952                "name": "LGPL"
 43953              }
 43954            }
 43955          ],
 43956          "cpe": "cpe:2.3:a:gcc-10-base:gcc-10-base:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
 43957          "purl": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
 43958          "swid": {
 43959            "attachment": {}
 43960          },
 43961          "pedigree": {},
 43962          "evidence": {},
 43963          "signature": {
 43964            "signature": {
 43965              "publicKey": {}
 43966            }
 43967          },
 43968          "modelCard": {
 43969            "modelParameters": {
 43970              "approach": {}
 43971            },
 43972            "quantitativeAnalysis": {
 43973              "graphics": {}
 43974            },
 43975            "considerations": {}
 43976          }
 43977        },
 43978        {
 43979          "type": "library",
 43980          "bom-ref": "pkg:golang/github.com/roaringbitmap/roaring@v0.4.18?package-id=44cacb1f0d828fa",
 43981          "supplier": {},
 43982          "name": "github.com/RoaringBitmap/roaring",
 43983          "version": "v0.4.18",
 43984          "cpe": "cpe:2.3:a:RoaringBitmap:roaring:v0.4.18:*:*:*:*:*:*:*",
 43985          "purl": "pkg:golang/github.com/RoaringBitmap/roaring@v0.4.18",
 43986          "swid": {
 43987            "attachment": {}
 43988          },
 43989          "pedigree": {},
 43990          "evidence": {},
 43991          "signature": {
 43992            "signature": {
 43993              "publicKey": {}
 43994            }
 43995          },
 43996          "modelCard": {
 43997            "modelParameters": {
 43998              "approach": {}
 43999            },
 44000            "quantitativeAnalysis": {
 44001              "graphics": {}
 44002            },
 44003            "considerations": {}
 44004          }
 44005        },
 44006        {
 44007          "type": "library",
 44008          "bom-ref": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d?package-id=3545da61f1ea79a",
 44009          "supplier": {},
 44010          "name": "github.com/cpuguy83/go-md2man/v2",
 44011          "version": "v2.0.0-20190314233015-f79a8a8ca69d",
 44012          "cpe": "cpe:2.3:a:cpuguy83:go-md2man\\/v2:v2.0.0-20190314233015-f79a8a8ca69d:*:*:*:*:*:*:*",
 44013          "purl": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d",
 44014          "swid": {
 44015            "attachment": {}
 44016          },
 44017          "pedigree": {},
 44018          "evidence": {},
 44019          "signature": {
 44020            "signature": {
 44021              "publicKey": {}
 44022            }
 44023          },
 44024          "modelCard": {
 44025            "modelParameters": {
 44026              "approach": {}
 44027            },
 44028            "quantitativeAnalysis": {
 44029              "graphics": {}
 44030            },
 44031            "considerations": {}
 44032          }
 44033        },
 44034        {
 44035          "type": "library",
 44036          "bom-ref": "pkg:golang/github.com/glycerine/go-unsnap-stream@v0.0.0-20181221182339-f9677308dec2?package-id=f23e657163a53a94",
 44037          "supplier": {},
 44038          "name": "github.com/glycerine/go-unsnap-stream",
 44039          "version": "v0.0.0-20181221182339-f9677308dec2",
 44040          "cpe": "cpe:2.3:a:glycerine:go-unsnap-stream:v0.0.0-20181221182339-f9677308dec2:*:*:*:*:*:*:*",
 44041          "purl": "pkg:golang/github.com/glycerine/go-unsnap-stream@v0.0.0-20181221182339-f9677308dec2",
 44042          "swid": {
 44043            "attachment": {}
 44044          },
 44045          "pedigree": {},
 44046          "evidence": {},
 44047          "signature": {
 44048            "signature": {
 44049              "publicKey": {}
 44050            }
 44051          },
 44052          "modelCard": {
 44053            "modelParameters": {
 44054              "approach": {}
 44055            },
 44056            "quantitativeAnalysis": {
 44057              "graphics": {}
 44058            },
 44059            "considerations": {}
 44060          }
 44061        },
 44062        {
 44063          "type": "library",
 44064          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.3.2?package-id=6429a79a5d94117",
 44065          "supplier": {},
 44066          "name": "github.com/golang/protobuf",
 44067          "version": "v1.3.2",
 44068          "cpe": "cpe:2.3:a:golang:protobuf:v1.3.2:*:*:*:*:*:*:*",
 44069          "purl": "pkg:golang/github.com/golang/protobuf@v1.3.2",
 44070          "swid": {
 44071            "attachment": {}
 44072          },
 44073          "pedigree": {},
 44074          "evidence": {},
 44075          "signature": {
 44076            "signature": {
 44077              "publicKey": {}
 44078            }
 44079          },
 44080          "modelCard": {
 44081            "modelParameters": {
 44082              "approach": {}
 44083            },
 44084            "quantitativeAnalysis": {
 44085              "graphics": {}
 44086            },
 44087            "considerations": {}
 44088          }
 44089        },
 44090        {
 44091          "type": "library",
 44092          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf?package-id=467cdc3789c0b2e5",
 44093          "supplier": {},
 44094          "name": "github.com/golang/protobuf",
 44095          "version": "v1.3.3-0.20190920234318-1680a479a2cf",
 44096          "cpe": "cpe:2.3:a:golang:protobuf:v1.3.3-0.20190920234318-1680a479a2cf:*:*:*:*:*:*:*",
 44097          "purl": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf",
 44098          "swid": {
 44099            "attachment": {}
 44100          },
 44101          "pedigree": {},
 44102          "evidence": {},
 44103          "signature": {
 44104            "signature": {
 44105              "publicKey": {}
 44106            }
 44107          },
 44108          "modelCard": {
 44109            "modelParameters": {
 44110              "approach": {}
 44111            },
 44112            "quantitativeAnalysis": {
 44113              "graphics": {}
 44114            },
 44115            "considerations": {}
 44116          }
 44117        },
 44118        {
 44119          "type": "library",
 44120          "bom-ref": "pkg:golang/github.com/golang/snappy@v0.0.1?package-id=3188e4faab0b9d08",
 44121          "supplier": {},
 44122          "name": "github.com/golang/snappy",
 44123          "version": "v0.0.1",
 44124          "cpe": "cpe:2.3:a:golang:snappy:v0.0.1:*:*:*:*:*:*:*",
 44125          "purl": "pkg:golang/github.com/golang/snappy@v0.0.1",
 44126          "swid": {
 44127            "attachment": {}
 44128          },
 44129          "pedigree": {},
 44130          "evidence": {},
 44131          "signature": {
 44132            "signature": {
 44133              "publicKey": {}
 44134            }
 44135          },
 44136          "modelCard": {
 44137            "modelParameters": {
 44138              "approach": {}
 44139            },
 44140            "quantitativeAnalysis": {
 44141              "graphics": {}
 44142            },
 44143            "considerations": {}
 44144          }
 44145        },
 44146        {
 44147          "type": "library",
 44148          "bom-ref": "pkg:golang/github.com/grpc-ecosystem/grpc-health-probe@(devel)?package-id=2ee2eb8d871be1ce",
 44149          "supplier": {},
 44150          "name": "github.com/grpc-ecosystem/grpc-health-probe",
 44151          "version": "(devel)",
 44152          "cpe": "cpe:2.3:a:grpc-ecosystem:grpc-health-probe:\\(devel\\):*:*:*:*:*:*:*",
 44153          "purl": "pkg:golang/github.com/grpc-ecosystem/grpc-health-probe@(devel)",
 44154          "swid": {
 44155            "attachment": {}
 44156          },
 44157          "pedigree": {},
 44158          "evidence": {},
 44159          "signature": {
 44160            "signature": {
 44161              "publicKey": {}
 44162            }
 44163          },
 44164          "modelCard": {
 44165            "modelParameters": {
 44166              "approach": {}
 44167            },
 44168            "quantitativeAnalysis": {
 44169              "graphics": {}
 44170            },
 44171            "considerations": {}
 44172          }
 44173        },
 44174        {
 44175          "type": "library",
 44176          "bom-ref": "pkg:golang/github.com/longhorn/longhorn-instance-manager@(devel)?package-id=7b07b64098f99595",
 44177          "supplier": {},
 44178          "name": "github.com/longhorn/longhorn-instance-manager",
 44179          "version": "(devel)",
 44180          "cpe": "cpe:2.3:a:longhorn:longhorn-instance-manager:\\(devel\\):*:*:*:*:*:*:*",
 44181          "purl": "pkg:golang/github.com/longhorn/longhorn-instance-manager@(devel)",
 44182          "swid": {
 44183            "attachment": {}
 44184          },
 44185          "pedigree": {},
 44186          "evidence": {},
 44187          "signature": {
 44188            "signature": {
 44189              "publicKey": {}
 44190            }
 44191          },
 44192          "modelCard": {
 44193            "modelParameters": {
 44194              "approach": {}
 44195            },
 44196            "quantitativeAnalysis": {
 44197              "graphics": {}
 44198            },
 44199            "considerations": {}
 44200          }
 44201        },
 44202        {
 44203          "type": "library",
 44204          "bom-ref": "pkg:golang/github.com/philhofer/fwd@v1.0.0?package-id=2daec666e43b2a6a",
 44205          "supplier": {},
 44206          "name": "github.com/philhofer/fwd",
 44207          "version": "v1.0.0",
 44208          "cpe": "cpe:2.3:a:philhofer:fwd:v1.0.0:*:*:*:*:*:*:*",
 44209          "purl": "pkg:golang/github.com/philhofer/fwd@v1.0.0",
 44210          "swid": {
 44211            "attachment": {}
 44212          },
 44213          "pedigree": {},
 44214          "evidence": {},
 44215          "signature": {
 44216            "signature": {
 44217              "publicKey": {}
 44218            }
 44219          },
 44220          "modelCard": {
 44221            "modelParameters": {
 44222              "approach": {}
 44223            },
 44224            "quantitativeAnalysis": {
 44225              "graphics": {}
 44226            },
 44227            "considerations": {}
 44228          }
 44229        },
 44230        {
 44231          "type": "library",
 44232          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.8.1?package-id=f02e8db37ed0f28a",
 44233          "supplier": {},
 44234          "name": "github.com/pkg/errors",
 44235          "version": "v0.8.1",
 44236          "cpe": "cpe:2.3:a:pkg:errors:v0.8.1:*:*:*:*:*:*:*",
 44237          "purl": "pkg:golang/github.com/pkg/errors@v0.8.1",
 44238          "swid": {
 44239            "attachment": {}
 44240          },
 44241          "pedigree": {},
 44242          "evidence": {},
 44243          "signature": {
 44244            "signature": {
 44245              "publicKey": {}
 44246            }
 44247          },
 44248          "modelCard": {
 44249            "modelParameters": {
 44250              "approach": {}
 44251            },
 44252            "quantitativeAnalysis": {
 44253              "graphics": {}
 44254            },
 44255            "considerations": {}
 44256          }
 44257        },
 44258        {
 44259          "type": "library",
 44260          "bom-ref": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1?package-id=a10a414d879a9d37",
 44261          "supplier": {},
 44262          "name": "github.com/russross/blackfriday/v2",
 44263          "version": "v2.0.1",
 44264          "cpe": "cpe:2.3:a:russross:blackfriday\\/v2:v2.0.1:*:*:*:*:*:*:*",
 44265          "purl": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1",
 44266          "swid": {
 44267            "attachment": {}
 44268          },
 44269          "pedigree": {},
 44270          "evidence": {},
 44271          "signature": {
 44272            "signature": {
 44273              "publicKey": {}
 44274            }
 44275          },
 44276          "modelCard": {
 44277            "modelParameters": {
 44278              "approach": {}
 44279            },
 44280            "quantitativeAnalysis": {
 44281              "graphics": {}
 44282            },
 44283            "considerations": {}
 44284          }
 44285        },
 44286        {
 44287          "type": "library",
 44288          "bom-ref": "pkg:golang/github.com/satori/go.uuid@v1.2.0?package-id=43e046b56b6b8b37",
 44289          "supplier": {},
 44290          "name": "github.com/satori/go.uuid",
 44291          "version": "v1.2.0",
 44292          "cpe": "cpe:2.3:a:satori:go.uuid:v1.2.0:*:*:*:*:*:*:*",
 44293          "purl": "pkg:golang/github.com/satori/go.uuid@v1.2.0",
 44294          "swid": {
 44295            "attachment": {}
 44296          },
 44297          "pedigree": {},
 44298          "evidence": {},
 44299          "signature": {
 44300            "signature": {
 44301              "publicKey": {}
 44302            }
 44303          },
 44304          "modelCard": {
 44305            "modelParameters": {
 44306              "approach": {}
 44307            },
 44308            "quantitativeAnalysis": {
 44309              "graphics": {}
 44310            },
 44311            "considerations": {}
 44312          }
 44313        },
 44314        {
 44315          "type": "library",
 44316          "bom-ref": "pkg:golang/github.com/shurcool/sanitized_anchor_name@v1.0.0?package-id=8541ac88e9e0eedb",
 44317          "supplier": {},
 44318          "name": "github.com/shurcooL/sanitized_anchor_name",
 44319          "version": "v1.0.0",
 44320          "cpe": "cpe:2.3:a:shurcooL:sanitized-anchor-name:v1.0.0:*:*:*:*:*:*:*",
 44321          "purl": "pkg:golang/github.com/shurcooL/sanitized_anchor_name@v1.0.0",
 44322          "swid": {
 44323            "attachment": {}
 44324          },
 44325          "pedigree": {},
 44326          "evidence": {},
 44327          "signature": {
 44328            "signature": {
 44329              "publicKey": {}
 44330            }
 44331          },
 44332          "modelCard": {
 44333            "modelParameters": {
 44334              "approach": {}
 44335            },
 44336            "quantitativeAnalysis": {
 44337              "graphics": {}
 44338            },
 44339            "considerations": {}
 44340          }
 44341        },
 44342        {
 44343          "type": "library",
 44344          "bom-ref": "pkg:golang/github.com/sirupsen/logrus@v1.4.1?package-id=e2e40d17eb9cf8d4",
 44345          "supplier": {},
 44346          "name": "github.com/sirupsen/logrus",
 44347          "version": "v1.4.1",
 44348          "cpe": "cpe:2.3:a:sirupsen:logrus:v1.4.1:*:*:*:*:*:*:*",
 44349          "purl": "pkg:golang/github.com/sirupsen/logrus@v1.4.1",
 44350          "swid": {
 44351            "attachment": {}
 44352          },
 44353          "pedigree": {},
 44354          "evidence": {},
 44355          "signature": {
 44356            "signature": {
 44357              "publicKey": {}
 44358            }
 44359          },
 44360          "modelCard": {
 44361            "modelParameters": {
 44362              "approach": {}
 44363            },
 44364            "quantitativeAnalysis": {
 44365              "graphics": {}
 44366            },
 44367            "considerations": {}
 44368          }
 44369        },
 44370        {
 44371          "type": "library",
 44372          "bom-ref": "pkg:golang/github.com/tinylib/msgp@v1.1.1-0.20190612170807-0573788bc2a8?package-id=3fc3be951cc4f58",
 44373          "supplier": {},
 44374          "name": "github.com/tinylib/msgp",
 44375          "version": "v1.1.1-0.20190612170807-0573788bc2a8",
 44376          "cpe": "cpe:2.3:a:tinylib:msgp:v1.1.1-0.20190612170807-0573788bc2a8:*:*:*:*:*:*:*",
 44377          "purl": "pkg:golang/github.com/tinylib/msgp@v1.1.1-0.20190612170807-0573788bc2a8",
 44378          "swid": {
 44379            "attachment": {}
 44380          },
 44381          "pedigree": {},
 44382          "evidence": {},
 44383          "signature": {
 44384            "signature": {
 44385              "publicKey": {}
 44386            }
 44387          },
 44388          "modelCard": {
 44389            "modelParameters": {
 44390              "approach": {}
 44391            },
 44392            "quantitativeAnalysis": {
 44393              "graphics": {}
 44394            },
 44395            "considerations": {}
 44396          }
 44397        },
 44398        {
 44399          "type": "library",
 44400          "bom-ref": "pkg:golang/github.com/urfave/cli@v1.22.1?package-id=677bdee48c80c60c",
 44401          "supplier": {},
 44402          "name": "github.com/urfave/cli",
 44403          "version": "v1.22.1",
 44404          "cpe": "cpe:2.3:a:urfave:cli:v1.22.1:*:*:*:*:*:*:*",
 44405          "purl": "pkg:golang/github.com/urfave/cli@v1.22.1",
 44406          "swid": {
 44407            "attachment": {}
 44408          },
 44409          "pedigree": {},
 44410          "evidence": {},
 44411          "signature": {
 44412            "signature": {
 44413              "publicKey": {}
 44414            }
 44415          },
 44416          "modelCard": {
 44417            "modelParameters": {
 44418              "approach": {}
 44419            },
 44420            "quantitativeAnalysis": {
 44421              "graphics": {}
 44422            },
 44423            "considerations": {}
 44424          }
 44425        },
 44426        {
 44427          "type": "library",
 44428          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20190522155817-f3200d17e092?package-id=4f1a3cddc7e49204",
 44429          "supplier": {},
 44430          "name": "golang.org/x/net",
 44431          "version": "v0.0.0-20190522155817-f3200d17e092",
 44432          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20190522155817-f3200d17e092:*:*:*:*:*:*:*",
 44433          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20190522155817-f3200d17e092",
 44434          "swid": {
 44435            "attachment": {}
 44436          },
 44437          "pedigree": {},
 44438          "evidence": {},
 44439          "signature": {
 44440            "signature": {
 44441              "publicKey": {}
 44442            }
 44443          },
 44444          "modelCard": {
 44445            "modelParameters": {
 44446              "approach": {}
 44447            },
 44448            "quantitativeAnalysis": {
 44449              "graphics": {}
 44450            },
 44451            "considerations": {}
 44452          }
 44453        },
 44454        {
 44455          "type": "library",
 44456          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20191021144547-ec77196f6094?package-id=dba26920fcd941ca",
 44457          "supplier": {},
 44458          "name": "golang.org/x/net",
 44459          "version": "v0.0.0-20191021144547-ec77196f6094",
 44460          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20191021144547-ec77196f6094:*:*:*:*:*:*:*",
 44461          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20191021144547-ec77196f6094",
 44462          "swid": {
 44463            "attachment": {}
 44464          },
 44465          "pedigree": {},
 44466          "evidence": {},
 44467          "signature": {
 44468            "signature": {
 44469              "publicKey": {}
 44470            }
 44471          },
 44472          "modelCard": {
 44473            "modelParameters": {
 44474              "approach": {}
 44475            },
 44476            "quantitativeAnalysis": {
 44477              "graphics": {}
 44478            },
 44479            "considerations": {}
 44480          }
 44481        },
 44482        {
 44483          "type": "library",
 44484          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20190524152521-dbbf3f1254d4?package-id=e80099fcdef38a3b",
 44485          "supplier": {},
 44486          "name": "golang.org/x/sys",
 44487          "version": "v0.0.0-20190524152521-dbbf3f1254d4",
 44488          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20190524152521-dbbf3f1254d4:*:*:*:*:*:*:*",
 44489          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20190524152521-dbbf3f1254d4",
 44490          "swid": {
 44491            "attachment": {}
 44492          },
 44493          "pedigree": {},
 44494          "evidence": {},
 44495          "signature": {
 44496            "signature": {
 44497              "publicKey": {}
 44498            }
 44499          },
 44500          "modelCard": {
 44501            "modelParameters": {
 44502              "approach": {}
 44503            },
 44504            "quantitativeAnalysis": {
 44505              "graphics": {}
 44506            },
 44507            "considerations": {}
 44508          }
 44509        },
 44510        {
 44511          "type": "library",
 44512          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20191020212454-3e7259c5e7c2?package-id=11cab605143eb4a2",
 44513          "supplier": {},
 44514          "name": "golang.org/x/sys",
 44515          "version": "v0.0.0-20191020212454-3e7259c5e7c2",
 44516          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20191020212454-3e7259c5e7c2:*:*:*:*:*:*:*",
 44517          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20191020212454-3e7259c5e7c2",
 44518          "swid": {
 44519            "attachment": {}
 44520          },
 44521          "pedigree": {},
 44522          "evidence": {},
 44523          "signature": {
 44524            "signature": {
 44525              "publicKey": {}
 44526            }
 44527          },
 44528          "modelCard": {
 44529            "modelParameters": {
 44530              "approach": {}
 44531            },
 44532            "quantitativeAnalysis": {
 44533              "graphics": {}
 44534            },
 44535            "considerations": {}
 44536          }
 44537        },
 44538        {
 44539          "type": "library",
 44540          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.2?package-id=79c19ce62be197dd",
 44541          "supplier": {},
 44542          "name": "golang.org/x/text",
 44543          "version": "v0.3.2",
 44544          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.2:*:*:*:*:*:*:*",
 44545          "purl": "pkg:golang/golang.org/x/text@v0.3.2",
 44546          "swid": {
 44547            "attachment": {}
 44548          },
 44549          "pedigree": {},
 44550          "evidence": {},
 44551          "signature": {
 44552            "signature": {
 44553              "publicKey": {}
 44554            }
 44555          },
 44556          "modelCard": {
 44557            "modelParameters": {
 44558              "approach": {}
 44559            },
 44560            "quantitativeAnalysis": {
 44561              "graphics": {}
 44562            },
 44563            "considerations": {}
 44564          }
 44565        },
 44566        {
 44567          "type": "library",
 44568          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.2?package-id=aed9d4e68940468c",
 44569          "supplier": {},
 44570          "name": "golang.org/x/text",
 44571          "version": "v0.3.2",
 44572          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.2:*:*:*:*:*:*:*",
 44573          "purl": "pkg:golang/golang.org/x/text@v0.3.2",
 44574          "swid": {
 44575            "attachment": {}
 44576          },
 44577          "pedigree": {},
 44578          "evidence": {},
 44579          "signature": {
 44580            "signature": {
 44581              "publicKey": {}
 44582            }
 44583          },
 44584          "modelCard": {
 44585            "modelParameters": {
 44586              "approach": {}
 44587            },
 44588            "quantitativeAnalysis": {
 44589              "graphics": {}
 44590            },
 44591            "considerations": {}
 44592          }
 44593        },
 44594        {
 44595          "type": "library",
 44596          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20180817151627-c66870c02cf8?package-id=7a2668b50b5c5c45",
 44597          "supplier": {},
 44598          "name": "google.golang.org/genproto",
 44599          "version": "v0.0.0-20180817151627-c66870c02cf8",
 44600          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20180817151627-c66870c02cf8:*:*:*:*:*:*:*",
 44601          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20180817151627-c66870c02cf8",
 44602          "swid": {
 44603            "attachment": {}
 44604          },
 44605          "pedigree": {},
 44606          "evidence": {},
 44607          "signature": {
 44608            "signature": {
 44609              "publicKey": {}
 44610            }
 44611          },
 44612          "modelCard": {
 44613            "modelParameters": {
 44614              "approach": {}
 44615            },
 44616            "quantitativeAnalysis": {
 44617              "graphics": {}
 44618            },
 44619            "considerations": {}
 44620          }
 44621        },
 44622        {
 44623          "type": "library",
 44624          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20191009194640-548a555dbc03?package-id=9631f02c5c120cff",
 44625          "supplier": {},
 44626          "name": "google.golang.org/genproto",
 44627          "version": "v0.0.0-20191009194640-548a555dbc03",
 44628          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20191009194640-548a555dbc03:*:*:*:*:*:*:*",
 44629          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20191009194640-548a555dbc03",
 44630          "swid": {
 44631            "attachment": {}
 44632          },
 44633          "pedigree": {},
 44634          "evidence": {},
 44635          "signature": {
 44636            "signature": {
 44637              "publicKey": {}
 44638            }
 44639          },
 44640          "modelCard": {
 44641            "modelParameters": {
 44642              "approach": {}
 44643            },
 44644            "quantitativeAnalysis": {
 44645              "graphics": {}
 44646            },
 44647            "considerations": {}
 44648          }
 44649        },
 44650        {
 44651          "type": "library",
 44652          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.21.0?package-id=2849f9d807035751",
 44653          "supplier": {},
 44654          "name": "google.golang.org/grpc",
 44655          "version": "v1.21.0",
 44656          "cpe": "cpe:2.3:a:google:grpc:v1.21.0:*:*:*:*:*:*:*",
 44657          "purl": "pkg:golang/google.golang.org/grpc@v1.21.0",
 44658          "swid": {
 44659            "attachment": {}
 44660          },
 44661          "pedigree": {},
 44662          "evidence": {},
 44663          "signature": {
 44664            "signature": {
 44665              "publicKey": {}
 44666            }
 44667          },
 44668          "modelCard": {
 44669            "modelParameters": {
 44670              "approach": {}
 44671            },
 44672            "quantitativeAnalysis": {
 44673              "graphics": {}
 44674            },
 44675            "considerations": {}
 44676          }
 44677        },
 44678        {
 44679          "type": "library",
 44680          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.24.0?package-id=54401e81e1c7ca15",
 44681          "supplier": {},
 44682          "name": "google.golang.org/grpc",
 44683          "version": "v1.24.0",
 44684          "cpe": "cpe:2.3:a:google:grpc:v1.24.0:*:*:*:*:*:*:*",
 44685          "purl": "pkg:golang/google.golang.org/grpc@v1.24.0",
 44686          "swid": {
 44687            "attachment": {}
 44688          },
 44689          "pedigree": {},
 44690          "evidence": {},
 44691          "signature": {
 44692            "signature": {
 44693              "publicKey": {}
 44694            }
 44695          },
 44696          "modelCard": {
 44697            "modelParameters": {
 44698              "approach": {}
 44699            },
 44700            "quantitativeAnalysis": {
 44701              "graphics": {}
 44702            },
 44703            "considerations": {}
 44704          }
 44705        },
 44706        {
 44707          "type": "library",
 44708          "bom-ref": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04\u0026package-id=b3a56223224b45d2",
 44709          "supplier": {},
 44710          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 44711          "name": "gpgv",
 44712          "version": "2.2.19-3ubuntu2.1",
 44713          "licenses": [
 44714            {
 44715              "license": {
 44716                "id": "BSD-3-Clause"
 44717              }
 44718            },
 44719            {
 44720              "license": {
 44721                "id": "CC0-1.0"
 44722              }
 44723            },
 44724            {
 44725              "license": {
 44726                "name": "Expat"
 44727              }
 44728            },
 44729            {
 44730              "license": {
 44731                "id": "GPL-3.0-only"
 44732              }
 44733            },
 44734            {
 44735              "license": {
 44736                "id": "GPL-3.0-or-later"
 44737              }
 44738            },
 44739            {
 44740              "license": {
 44741                "id": "LGPL-2.1-only"
 44742              }
 44743            },
 44744            {
 44745              "license": {
 44746                "id": "LGPL-2.1-or-later"
 44747              }
 44748            },
 44749            {
 44750              "license": {
 44751                "id": "LGPL-3.0-only"
 44752              }
 44753            },
 44754            {
 44755              "license": {
 44756                "id": "LGPL-3.0-or-later"
 44757              }
 44758            },
 44759            {
 44760              "license": {
 44761                "name": "RFC-Reference"
 44762              }
 44763            },
 44764            {
 44765              "license": {
 44766                "name": "TinySCHEME"
 44767              }
 44768            },
 44769            {
 44770              "license": {
 44771                "name": "permissive"
 44772              }
 44773            }
 44774          ],
 44775          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.19-3ubuntu2.1:*:*:*:*:*:*:*",
 44776          "purl": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04",
 44777          "swid": {
 44778            "attachment": {}
 44779          },
 44780          "pedigree": {},
 44781          "evidence": {},
 44782          "signature": {
 44783            "signature": {
 44784              "publicKey": {}
 44785            }
 44786          },
 44787          "modelCard": {
 44788            "modelParameters": {
 44789              "approach": {}
 44790            },
 44791            "quantitativeAnalysis": {
 44792              "graphics": {}
 44793            },
 44794            "considerations": {}
 44795          }
 44796        },
 44797        {
 44798          "type": "library",
 44799          "bom-ref": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7af9af4b90473f",
 44800          "supplier": {},
 44801          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 44802          "name": "grep",
 44803          "version": "3.4-1",
 44804          "licenses": [
 44805            {
 44806              "license": {
 44807                "id": "GPL-3.0-only"
 44808              }
 44809            },
 44810            {
 44811              "license": {
 44812                "id": "GPL-3.0-or-later"
 44813              }
 44814            }
 44815          ],
 44816          "cpe": "cpe:2.3:a:grep:grep:3.4-1:*:*:*:*:*:*:*",
 44817          "purl": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04",
 44818          "swid": {
 44819            "attachment": {}
 44820          },
 44821          "pedigree": {},
 44822          "evidence": {},
 44823          "signature": {
 44824            "signature": {
 44825              "publicKey": {}
 44826            }
 44827          },
 44828          "modelCard": {
 44829            "modelParameters": {
 44830              "approach": {}
 44831            },
 44832            "quantitativeAnalysis": {
 44833              "graphics": {}
 44834            },
 44835            "considerations": {}
 44836          }
 44837        },
 44838        {
 44839          "type": "library",
 44840          "bom-ref": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a9696917d3b9f9fc",
 44841          "supplier": {},
 44842          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 44843          "name": "gzip",
 44844          "version": "1.10-0ubuntu4",
 44845          "licenses": [
 44846            {
 44847              "license": {
 44848                "name": "GPL"
 44849              }
 44850            }
 44851          ],
 44852          "cpe": "cpe:2.3:a:gzip:gzip:1.10-0ubuntu4:*:*:*:*:*:*:*",
 44853          "purl": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04",
 44854          "swid": {
 44855            "attachment": {}
 44856          },
 44857          "pedigree": {},
 44858          "evidence": {},
 44859          "signature": {
 44860            "signature": {
 44861              "publicKey": {}
 44862            }
 44863          },
 44864          "modelCard": {
 44865            "modelParameters": {
 44866              "approach": {}
 44867            },
 44868            "quantitativeAnalysis": {
 44869              "graphics": {}
 44870            },
 44871            "considerations": {}
 44872          }
 44873        },
 44874        {
 44875          "type": "library",
 44876          "bom-ref": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=263dae70cc8e6a4f",
 44877          "supplier": {},
 44878          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 44879          "name": "hostname",
 44880          "version": "3.23",
 44881          "licenses": [
 44882            {
 44883              "license": {
 44884                "id": "GPL-2.0-only"
 44885              }
 44886            }
 44887          ],
 44888          "cpe": "cpe:2.3:a:hostname:hostname:3.23:*:*:*:*:*:*:*",
 44889          "purl": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04",
 44890          "swid": {
 44891            "attachment": {}
 44892          },
 44893          "pedigree": {},
 44894          "evidence": {},
 44895          "signature": {
 44896            "signature": {
 44897              "publicKey": {}
 44898            }
 44899          },
 44900          "modelCard": {
 44901            "modelParameters": {
 44902              "approach": {}
 44903            },
 44904            "quantitativeAnalysis": {
 44905              "graphics": {}
 44906            },
 44907            "considerations": {}
 44908          }
 44909        },
 44910        {
 44911          "type": "library",
 44912          "bom-ref": "pkg:deb/ubuntu/ibverbs-providers@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04\u0026package-id=8e9d2de3c937ce3c",
 44913          "supplier": {},
 44914          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 44915          "name": "ibverbs-providers",
 44916          "version": "28.0-1ubuntu1",
 44917          "licenses": [
 44918            {
 44919              "license": {
 44920                "id": "BSD-2-Clause"
 44921              }
 44922            },
 44923            {
 44924              "license": {
 44925                "id": "BSD-3-Clause"
 44926              }
 44927            },
 44928            {
 44929              "license": {
 44930                "name": "BSD-MIT"
 44931              }
 44932            },
 44933            {
 44934              "license": {
 44935                "name": "CC0"
 44936              }
 44937            },
 44938            {
 44939              "license": {
 44940                "id": "CPL-1.0"
 44941              }
 44942            },
 44943            {
 44944              "license": {
 44945                "id": "GPL-2.0-only"
 44946              }
 44947            },
 44948            {
 44949              "license": {
 44950                "id": "GPL-2.0-or-later"
 44951              }
 44952            },
 44953            {
 44954              "license": {
 44955                "id": "MIT"
 44956              }
 44957            }
 44958          ],
 44959          "cpe": "cpe:2.3:a:ibverbs-providers:ibverbs-providers:28.0-1ubuntu1:*:*:*:*:*:*:*",
 44960          "purl": "pkg:deb/ubuntu/ibverbs-providers@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04",
 44961          "swid": {
 44962            "attachment": {}
 44963          },
 44964          "pedigree": {},
 44965          "evidence": {},
 44966          "signature": {
 44967            "signature": {
 44968              "publicKey": {}
 44969            }
 44970          },
 44971          "modelCard": {
 44972            "modelParameters": {
 44973              "approach": {}
 44974            },
 44975            "quantitativeAnalysis": {
 44976              "graphics": {}
 44977            },
 44978            "considerations": {}
 44979          }
 44980        },
 44981        {
 44982          "type": "library",
 44983          "bom-ref": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04\u0026package-id=b0e335d96f12154d",
 44984          "supplier": {},
 44985          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 44986          "name": "init-system-helpers",
 44987          "version": "1.57",
 44988          "licenses": [
 44989            {
 44990              "license": {
 44991                "id": "BSD-3-Clause"
 44992              }
 44993            },
 44994            {
 44995              "license": {
 44996                "id": "GPL-2.0-only"
 44997              }
 44998            },
 44999            {
 45000              "license": {
 45001                "id": "GPL-2.0-or-later"
 45002              }
 45003            }
 45004          ],
 45005          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.57:*:*:*:*:*:*:*",
 45006          "purl": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04",
 45007          "swid": {
 45008            "attachment": {}
 45009          },
 45010          "pedigree": {},
 45011          "evidence": {},
 45012          "signature": {
 45013            "signature": {
 45014              "publicKey": {}
 45015            }
 45016          },
 45017          "modelCard": {
 45018            "modelParameters": {
 45019              "approach": {}
 45020            },
 45021            "quantitativeAnalysis": {
 45022              "graphics": {}
 45023            },
 45024            "considerations": {}
 45025          }
 45026        },
 45027        {
 45028          "type": "library",
 45029          "bom-ref": "pkg:deb/ubuntu/iperf@2.0.13+dfsg1-1build1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=52f5841ee19da566",
 45030          "supplier": {},
 45031          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45032          "name": "iperf",
 45033          "version": "2.0.13+dfsg1-1build1",
 45034          "licenses": [
 45035            {
 45036              "license": {
 45037                "id": "BSD-3-Clause"
 45038              }
 45039            },
 45040            {
 45041              "license": {
 45042                "name": "FSF-something"
 45043              }
 45044            },
 45045            {
 45046              "license": {
 45047                "id": "GPL-2.0-only"
 45048              }
 45049            },
 45050            {
 45051              "license": {
 45052                "id": "GPL-2.0-or-later"
 45053              }
 45054            },
 45055            {
 45056              "license": {
 45057                "name": "GPL-2-WithACException"
 45058              }
 45059            },
 45060            {
 45061              "license": {
 45062                "id": "GPL-3.0-only"
 45063              }
 45064            },
 45065            {
 45066              "license": {
 45067                "name": "GPL-3-WithACException"
 45068              }
 45069            },
 45070            {
 45071              "license": {
 45072                "id": "ISC"
 45073              }
 45074            },
 45075            {
 45076              "license": {
 45077                "id": "LGPL-2.0-only"
 45078              }
 45079            },
 45080            {
 45081              "license": {
 45082                "id": "LGPL-2.0-or-later"
 45083              }
 45084            },
 45085            {
 45086              "license": {
 45087                "id": "MIT"
 45088              }
 45089            }
 45090          ],
 45091          "cpe": "cpe:2.3:a:iperf:iperf:2.0.13\\+dfsg1-1build1:*:*:*:*:*:*:*",
 45092          "purl": "pkg:deb/ubuntu/iperf@2.0.13+dfsg1-1build1?arch=amd64\u0026distro=ubuntu-20.04",
 45093          "swid": {
 45094            "attachment": {}
 45095          },
 45096          "pedigree": {},
 45097          "evidence": {},
 45098          "signature": {
 45099            "signature": {
 45100              "publicKey": {}
 45101            }
 45102          },
 45103          "modelCard": {
 45104            "modelParameters": {
 45105              "approach": {}
 45106            },
 45107            "quantitativeAnalysis": {
 45108              "graphics": {}
 45109            },
 45110            "considerations": {}
 45111          }
 45112        },
 45113        {
 45114          "type": "library",
 45115          "bom-ref": "pkg:deb/ubuntu/iproute2@5.5.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f4afda4dc550367c",
 45116          "supplier": {},
 45117          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45118          "name": "iproute2",
 45119          "version": "5.5.0-1ubuntu1",
 45120          "licenses": [
 45121            {
 45122              "license": {
 45123                "id": "GPL-2.0-only"
 45124              }
 45125            }
 45126          ],
 45127          "cpe": "cpe:2.3:a:iproute2:iproute2:5.5.0-1ubuntu1:*:*:*:*:*:*:*",
 45128          "purl": "pkg:deb/ubuntu/iproute2@5.5.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 45129          "swid": {
 45130            "attachment": {}
 45131          },
 45132          "pedigree": {},
 45133          "evidence": {},
 45134          "signature": {
 45135            "signature": {
 45136              "publicKey": {}
 45137            }
 45138          },
 45139          "modelCard": {
 45140            "modelParameters": {
 45141              "approach": {}
 45142            },
 45143            "quantitativeAnalysis": {
 45144              "graphics": {}
 45145            },
 45146            "considerations": {}
 45147          }
 45148        },
 45149        {
 45150          "type": "library",
 45151          "bom-ref": "pkg:deb/ubuntu/iputils-ping@3:20190709-3?arch=amd64\u0026upstream=iputils\u0026distro=ubuntu-20.04\u0026package-id=83f284daebd0969f",
 45152          "supplier": {},
 45153          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45154          "name": "iputils-ping",
 45155          "version": "3:20190709-3",
 45156          "licenses": [
 45157            {
 45158              "license": {
 45159                "name": "GPL"
 45160              }
 45161            }
 45162          ],
 45163          "cpe": "cpe:2.3:a:iputils-ping:iputils-ping:3\\:20190709-3:*:*:*:*:*:*:*",
 45164          "purl": "pkg:deb/ubuntu/iputils-ping@3:20190709-3?arch=amd64\u0026upstream=iputils\u0026distro=ubuntu-20.04",
 45165          "swid": {
 45166            "attachment": {}
 45167          },
 45168          "pedigree": {},
 45169          "evidence": {},
 45170          "signature": {
 45171            "signature": {
 45172              "publicKey": {}
 45173            }
 45174          },
 45175          "modelCard": {
 45176            "modelParameters": {
 45177              "approach": {}
 45178            },
 45179            "quantitativeAnalysis": {
 45180              "graphics": {}
 45181            },
 45182            "considerations": {}
 45183          }
 45184        },
 45185        {
 45186          "type": "library",
 45187          "bom-ref": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a61b8b47cf58815b",
 45188          "supplier": {},
 45189          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45190          "name": "keyutils",
 45191          "version": "1.6-6ubuntu1",
 45192          "licenses": [
 45193            {
 45194              "license": {
 45195                "id": "GPL-2.0-only"
 45196              }
 45197            },
 45198            {
 45199              "license": {
 45200                "id": "GPL-2.0-or-later"
 45201              }
 45202            },
 45203            {
 45204              "license": {
 45205                "id": "LGPL-2.0-only"
 45206              }
 45207            },
 45208            {
 45209              "license": {
 45210                "id": "LGPL-2.0-or-later"
 45211              }
 45212            }
 45213          ],
 45214          "cpe": "cpe:2.3:a:keyutils:keyutils:1.6-6ubuntu1:*:*:*:*:*:*:*",
 45215          "purl": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 45216          "swid": {
 45217            "attachment": {}
 45218          },
 45219          "pedigree": {},
 45220          "evidence": {},
 45221          "signature": {
 45222            "signature": {
 45223              "publicKey": {}
 45224            }
 45225          },
 45226          "modelCard": {
 45227            "modelParameters": {
 45228              "approach": {}
 45229            },
 45230            "quantitativeAnalysis": {
 45231              "graphics": {}
 45232            },
 45233            "considerations": {}
 45234          }
 45235        },
 45236        {
 45237          "type": "library",
 45238          "bom-ref": "pkg:deb/ubuntu/kmod@27-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e1280bc47493e972",
 45239          "supplier": {},
 45240          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45241          "name": "kmod",
 45242          "version": "27-1ubuntu2",
 45243          "licenses": [
 45244            {
 45245              "license": {
 45246                "id": "GPL-2.0-only"
 45247              }
 45248            }
 45249          ],
 45250          "cpe": "cpe:2.3:a:kmod:kmod:27-1ubuntu2:*:*:*:*:*:*:*",
 45251          "purl": "pkg:deb/ubuntu/kmod@27-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
 45252          "swid": {
 45253            "attachment": {}
 45254          },
 45255          "pedigree": {},
 45256          "evidence": {},
 45257          "signature": {
 45258            "signature": {
 45259              "publicKey": {}
 45260            }
 45261          },
 45262          "modelCard": {
 45263            "modelParameters": {
 45264              "approach": {}
 45265            },
 45266            "quantitativeAnalysis": {
 45267              "graphics": {}
 45268            },
 45269            "considerations": {}
 45270          }
 45271        },
 45272        {
 45273          "type": "library",
 45274          "bom-ref": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=87ea48972fb4adab",
 45275          "supplier": {},
 45276          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45277          "name": "krb5-locales",
 45278          "version": "1.17-6ubuntu4.1",
 45279          "licenses": [
 45280            {
 45281              "license": {
 45282                "id": "GPL-2.0-only"
 45283              }
 45284            }
 45285          ],
 45286          "cpe": "cpe:2.3:a:krb5-locales:krb5-locales:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 45287          "purl": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 45288          "swid": {
 45289            "attachment": {}
 45290          },
 45291          "pedigree": {},
 45292          "evidence": {},
 45293          "signature": {
 45294            "signature": {
 45295              "publicKey": {}
 45296            }
 45297          },
 45298          "modelCard": {
 45299            "modelParameters": {
 45300              "approach": {}
 45301            },
 45302            "quantitativeAnalysis": {
 45303              "graphics": {}
 45304            },
 45305            "considerations": {}
 45306          }
 45307        },
 45308        {
 45309          "type": "library",
 45310          "bom-ref": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04\u0026package-id=5cec2c2009596050",
 45311          "supplier": {},
 45312          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45313          "name": "libacl1",
 45314          "version": "2.2.53-6",
 45315          "licenses": [
 45316            {
 45317              "license": {
 45318                "id": "GPL-2.0-only"
 45319              }
 45320            },
 45321            {
 45322              "license": {
 45323                "id": "GPL-2.0-or-later"
 45324              }
 45325            },
 45326            {
 45327              "license": {
 45328                "id": "LGPL-2.0-or-later"
 45329              }
 45330            },
 45331            {
 45332              "license": {
 45333                "id": "LGPL-2.1-only"
 45334              }
 45335            }
 45336          ],
 45337          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-6:*:*:*:*:*:*:*",
 45338          "purl": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04",
 45339          "swid": {
 45340            "attachment": {}
 45341          },
 45342          "pedigree": {},
 45343          "evidence": {},
 45344          "signature": {
 45345            "signature": {
 45346              "publicKey": {}
 45347            }
 45348          },
 45349          "modelCard": {
 45350            "modelParameters": {
 45351              "approach": {}
 45352            },
 45353            "quantitativeAnalysis": {
 45354              "graphics": {}
 45355            },
 45356            "considerations": {}
 45357          }
 45358        },
 45359        {
 45360          "type": "library",
 45361          "bom-ref": "pkg:deb/ubuntu/libaio1@0.3.112-5?arch=amd64\u0026upstream=libaio\u0026distro=ubuntu-20.04\u0026package-id=f850a0a77c824c95",
 45362          "supplier": {},
 45363          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45364          "name": "libaio1",
 45365          "version": "0.3.112-5",
 45366          "licenses": [
 45367            {
 45368              "license": {
 45369                "id": "LGPL-2.1-only"
 45370              }
 45371            },
 45372            {
 45373              "license": {
 45374                "id": "LGPL-2.1-or-later"
 45375              }
 45376            }
 45377          ],
 45378          "cpe": "cpe:2.3:a:libaio1:libaio1:0.3.112-5:*:*:*:*:*:*:*",
 45379          "purl": "pkg:deb/ubuntu/libaio1@0.3.112-5?arch=amd64\u0026upstream=libaio\u0026distro=ubuntu-20.04",
 45380          "swid": {
 45381            "attachment": {}
 45382          },
 45383          "pedigree": {},
 45384          "evidence": {},
 45385          "signature": {
 45386            "signature": {
 45387              "publicKey": {}
 45388            }
 45389          },
 45390          "modelCard": {
 45391            "modelParameters": {
 45392              "approach": {}
 45393            },
 45394            "quantitativeAnalysis": {
 45395              "graphics": {}
 45396            },
 45397            "considerations": {}
 45398          }
 45399        },
 45400        {
 45401          "type": "library",
 45402          "bom-ref": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04\u0026package-id=864e143f4c606a6c",
 45403          "supplier": {},
 45404          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45405          "name": "libapt-pkg6.0",
 45406          "version": "2.0.6",
 45407          "licenses": [
 45408            {
 45409              "license": {
 45410                "id": "GPL-2.0-only"
 45411              }
 45412            },
 45413            {
 45414              "license": {
 45415                "name": "GPLv2+"
 45416              }
 45417            }
 45418          ],
 45419          "cpe": "cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.0.6:*:*:*:*:*:*:*",
 45420          "purl": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04",
 45421          "swid": {
 45422            "attachment": {}
 45423          },
 45424          "pedigree": {},
 45425          "evidence": {},
 45426          "signature": {
 45427            "signature": {
 45428              "publicKey": {}
 45429            }
 45430          },
 45431          "modelCard": {
 45432            "modelParameters": {
 45433              "approach": {}
 45434            },
 45435            "quantitativeAnalysis": {
 45436              "graphics": {}
 45437            },
 45438            "considerations": {}
 45439          }
 45440        },
 45441        {
 45442          "type": "library",
 45443          "bom-ref": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=915f8cf154d1b7ce",
 45444          "supplier": {},
 45445          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45446          "name": "libasn1-8-heimdal",
 45447          "version": "7.7.0+dfsg-1ubuntu1",
 45448          "licenses": [
 45449            {
 45450              "license": {
 45451                "id": "BSD-3-Clause"
 45452              }
 45453            },
 45454            {
 45455              "license": {
 45456                "id": "GPL-2.0-only"
 45457              }
 45458            },
 45459            {
 45460              "license": {
 45461                "id": "GPL-2.0-or-later"
 45462              }
 45463            },
 45464            {
 45465              "license": {
 45466                "name": "custom"
 45467              }
 45468            }
 45469          ],
 45470          "cpe": "cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 45471          "purl": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 45472          "swid": {
 45473            "attachment": {}
 45474          },
 45475          "pedigree": {},
 45476          "evidence": {},
 45477          "signature": {
 45478            "signature": {
 45479              "publicKey": {}
 45480            }
 45481          },
 45482          "modelCard": {
 45483            "modelParameters": {
 45484              "approach": {}
 45485            },
 45486            "quantitativeAnalysis": {
 45487              "graphics": {}
 45488            },
 45489            "considerations": {}
 45490          }
 45491        },
 45492        {
 45493          "type": "library",
 45494          "bom-ref": "pkg:deb/ubuntu/libatm1@1:2.5.1-4?arch=amd64\u0026upstream=linux-atm\u0026distro=ubuntu-20.04\u0026package-id=38fbc3dda7412f50",
 45495          "supplier": {},
 45496          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45497          "name": "libatm1",
 45498          "version": "1:2.5.1-4",
 45499          "licenses": [
 45500            {
 45501              "license": {
 45502                "id": "GPL-2.0-only"
 45503              }
 45504            }
 45505          ],
 45506          "cpe": "cpe:2.3:a:libatm1:libatm1:1\\:2.5.1-4:*:*:*:*:*:*:*",
 45507          "purl": "pkg:deb/ubuntu/libatm1@1:2.5.1-4?arch=amd64\u0026upstream=linux-atm\u0026distro=ubuntu-20.04",
 45508          "swid": {
 45509            "attachment": {}
 45510          },
 45511          "pedigree": {},
 45512          "evidence": {},
 45513          "signature": {
 45514            "signature": {
 45515              "publicKey": {}
 45516            }
 45517          },
 45518          "modelCard": {
 45519            "modelParameters": {
 45520              "approach": {}
 45521            },
 45522            "quantitativeAnalysis": {
 45523              "graphics": {}
 45524            },
 45525            "considerations": {}
 45526          }
 45527        },
 45528        {
 45529          "type": "library",
 45530          "bom-ref": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04\u0026package-id=edf8dd62bd537bd5",
 45531          "supplier": {},
 45532          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45533          "name": "libattr1",
 45534          "version": "1:2.4.48-5",
 45535          "licenses": [
 45536            {
 45537              "license": {
 45538                "id": "GPL-2.0-only"
 45539              }
 45540            },
 45541            {
 45542              "license": {
 45543                "id": "GPL-2.0-or-later"
 45544              }
 45545            },
 45546            {
 45547              "license": {
 45548                "id": "LGPL-2.0-or-later"
 45549              }
 45550            },
 45551            {
 45552              "license": {
 45553                "id": "LGPL-2.1-only"
 45554              }
 45555            }
 45556          ],
 45557          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-5:*:*:*:*:*:*:*",
 45558          "purl": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04",
 45559          "swid": {
 45560            "attachment": {}
 45561          },
 45562          "pedigree": {},
 45563          "evidence": {},
 45564          "signature": {
 45565            "signature": {
 45566              "publicKey": {}
 45567            }
 45568          },
 45569          "modelCard": {
 45570            "modelParameters": {
 45571              "approach": {}
 45572            },
 45573            "quantitativeAnalysis": {
 45574              "graphics": {}
 45575            },
 45576            "considerations": {}
 45577          }
 45578        },
 45579        {
 45580          "type": "library",
 45581          "bom-ref": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=4a463ab850d7c68c",
 45582          "supplier": {},
 45583          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45584          "name": "libaudit-common",
 45585          "version": "1:2.8.5-2ubuntu6",
 45586          "licenses": [
 45587            {
 45588              "license": {
 45589                "id": "GPL-1.0-only"
 45590              }
 45591            },
 45592            {
 45593              "license": {
 45594                "id": "GPL-2.0-only"
 45595              }
 45596            },
 45597            {
 45598              "license": {
 45599                "id": "LGPL-2.1-only"
 45600              }
 45601            }
 45602          ],
 45603          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
 45604          "purl": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04",
 45605          "swid": {
 45606            "attachment": {}
 45607          },
 45608          "pedigree": {},
 45609          "evidence": {},
 45610          "signature": {
 45611            "signature": {
 45612              "publicKey": {}
 45613            }
 45614          },
 45615          "modelCard": {
 45616            "modelParameters": {
 45617              "approach": {}
 45618            },
 45619            "quantitativeAnalysis": {
 45620              "graphics": {}
 45621            },
 45622            "considerations": {}
 45623          }
 45624        },
 45625        {
 45626          "type": "library",
 45627          "bom-ref": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=be9537deb8db616e",
 45628          "supplier": {},
 45629          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45630          "name": "libaudit1",
 45631          "version": "1:2.8.5-2ubuntu6",
 45632          "licenses": [
 45633            {
 45634              "license": {
 45635                "id": "GPL-1.0-only"
 45636              }
 45637            },
 45638            {
 45639              "license": {
 45640                "id": "GPL-2.0-only"
 45641              }
 45642            },
 45643            {
 45644              "license": {
 45645                "id": "LGPL-2.1-only"
 45646              }
 45647            }
 45648          ],
 45649          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
 45650          "purl": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04",
 45651          "swid": {
 45652            "attachment": {}
 45653          },
 45654          "pedigree": {},
 45655          "evidence": {},
 45656          "signature": {
 45657            "signature": {
 45658              "publicKey": {}
 45659            }
 45660          },
 45661          "modelCard": {
 45662            "modelParameters": {
 45663              "approach": {}
 45664            },
 45665            "quantitativeAnalysis": {
 45666              "graphics": {}
 45667            },
 45668            "considerations": {}
 45669          }
 45670        },
 45671        {
 45672          "type": "library",
 45673          "bom-ref": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=e1d6f2e998332d7d",
 45674          "supplier": {},
 45675          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45676          "name": "libblkid1",
 45677          "version": "2.34-0.1ubuntu9.1",
 45678          "licenses": [
 45679            {
 45680              "license": {
 45681                "id": "BSD-2-Clause"
 45682              }
 45683            },
 45684            {
 45685              "license": {
 45686                "id": "BSD-3-Clause"
 45687              }
 45688            },
 45689            {
 45690              "license": {
 45691                "id": "BSD-4-Clause"
 45692              }
 45693            },
 45694            {
 45695              "license": {
 45696                "id": "GPL-2.0-only"
 45697              }
 45698            },
 45699            {
 45700              "license": {
 45701                "id": "GPL-2.0-or-later"
 45702              }
 45703            },
 45704            {
 45705              "license": {
 45706                "id": "GPL-3.0-only"
 45707              }
 45708            },
 45709            {
 45710              "license": {
 45711                "id": "GPL-3.0-or-later"
 45712              }
 45713            },
 45714            {
 45715              "license": {
 45716                "name": "LGPL"
 45717              }
 45718            },
 45719            {
 45720              "license": {
 45721                "id": "LGPL-2.0-only"
 45722              }
 45723            },
 45724            {
 45725              "license": {
 45726                "id": "LGPL-2.0-or-later"
 45727              }
 45728            },
 45729            {
 45730              "license": {
 45731                "id": "LGPL-2.1-only"
 45732              }
 45733            },
 45734            {
 45735              "license": {
 45736                "id": "LGPL-2.1-or-later"
 45737              }
 45738            },
 45739            {
 45740              "license": {
 45741                "id": "LGPL-3.0-only"
 45742              }
 45743            },
 45744            {
 45745              "license": {
 45746                "id": "LGPL-3.0-or-later"
 45747              }
 45748            },
 45749            {
 45750              "license": {
 45751                "id": "MIT"
 45752              }
 45753            },
 45754            {
 45755              "license": {
 45756                "name": "public-domain"
 45757              }
 45758            }
 45759          ],
 45760          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 45761          "purl": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 45762          "swid": {
 45763            "attachment": {}
 45764          },
 45765          "pedigree": {},
 45766          "evidence": {},
 45767          "signature": {
 45768            "signature": {
 45769              "publicKey": {}
 45770            }
 45771          },
 45772          "modelCard": {
 45773            "modelParameters": {
 45774              "approach": {}
 45775            },
 45776            "quantitativeAnalysis": {
 45777              "graphics": {}
 45778            },
 45779            "considerations": {}
 45780          }
 45781        },
 45782        {
 45783          "type": "library",
 45784          "bom-ref": "pkg:deb/ubuntu/libboost-iostreams1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04\u0026package-id=c10288fd207d7ab9",
 45785          "supplier": {},
 45786          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45787          "name": "libboost-iostreams1.71.0",
 45788          "version": "1.71.0-6ubuntu6",
 45789          "licenses": [
 45790            {
 45791              "license": {
 45792                "id": "Apache-2.0"
 45793              }
 45794            },
 45795            {
 45796              "license": {
 45797                "name": "BSD2"
 45798              }
 45799            },
 45800            {
 45801              "license": {
 45802                "name": "BSD3_DEShaw"
 45803              }
 45804            },
 45805            {
 45806              "license": {
 45807                "name": "BSD3_Google"
 45808              }
 45809            },
 45810            {
 45811              "license": {
 45812                "id": "BSL-1.0"
 45813              }
 45814            },
 45815            {
 45816              "license": {
 45817                "name": "Caramel"
 45818              }
 45819            },
 45820            {
 45821              "license": {
 45822                "name": "CrystalClear"
 45823              }
 45824            },
 45825            {
 45826              "license": {
 45827                "name": "HP"
 45828              }
 45829            },
 45830            {
 45831              "license": {
 45832                "id": "Jam"
 45833              }
 45834            },
 45835            {
 45836              "license": {
 45837                "name": "Kempf"
 45838              }
 45839            },
 45840            {
 45841              "license": {
 45842                "id": "MIT"
 45843              }
 45844            },
 45845            {
 45846              "license": {
 45847                "name": "NIST"
 45848              }
 45849            },
 45850            {
 45851              "license": {
 45852                "name": "OldBoost1"
 45853              }
 45854            },
 45855            {
 45856              "license": {
 45857                "name": "OldBoost2"
 45858              }
 45859            },
 45860            {
 45861              "license": {
 45862                "name": "OldBoost3"
 45863              }
 45864            },
 45865            {
 45866              "license": {
 45867                "name": "Python"
 45868              }
 45869            },
 45870            {
 45871              "license": {
 45872                "name": "SGI"
 45873              }
 45874            },
 45875            {
 45876              "license": {
 45877                "name": "Spencer"
 45878              }
 45879            },
 45880            {
 45881              "license": {
 45882                "id": "Zlib"
 45883              }
 45884            }
 45885          ],
 45886          "cpe": "cpe:2.3:a:libboost-iostreams1.71.0:libboost-iostreams1.71.0:1.71.0-6ubuntu6:*:*:*:*:*:*:*",
 45887          "purl": "pkg:deb/ubuntu/libboost-iostreams1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04",
 45888          "swid": {
 45889            "attachment": {}
 45890          },
 45891          "pedigree": {},
 45892          "evidence": {},
 45893          "signature": {
 45894            "signature": {
 45895              "publicKey": {}
 45896            }
 45897          },
 45898          "modelCard": {
 45899            "modelParameters": {
 45900              "approach": {}
 45901            },
 45902            "quantitativeAnalysis": {
 45903              "graphics": {}
 45904            },
 45905            "considerations": {}
 45906          }
 45907        },
 45908        {
 45909          "type": "library",
 45910          "bom-ref": "pkg:deb/ubuntu/libboost-thread1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04\u0026package-id=7bdbd4008b339d07",
 45911          "supplier": {},
 45912          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 45913          "name": "libboost-thread1.71.0",
 45914          "version": "1.71.0-6ubuntu6",
 45915          "licenses": [
 45916            {
 45917              "license": {
 45918                "id": "Apache-2.0"
 45919              }
 45920            },
 45921            {
 45922              "license": {
 45923                "name": "BSD2"
 45924              }
 45925            },
 45926            {
 45927              "license": {
 45928                "name": "BSD3_DEShaw"
 45929              }
 45930            },
 45931            {
 45932              "license": {
 45933                "name": "BSD3_Google"
 45934              }
 45935            },
 45936            {
 45937              "license": {
 45938                "id": "BSL-1.0"
 45939              }
 45940            },
 45941            {
 45942              "license": {
 45943                "name": "Caramel"
 45944              }
 45945            },
 45946            {
 45947              "license": {
 45948                "name": "CrystalClear"
 45949              }
 45950            },
 45951            {
 45952              "license": {
 45953                "name": "HP"
 45954              }
 45955            },
 45956            {
 45957              "license": {
 45958                "id": "Jam"
 45959              }
 45960            },
 45961            {
 45962              "license": {
 45963                "name": "Kempf"
 45964              }
 45965            },
 45966            {
 45967              "license": {
 45968                "id": "MIT"
 45969              }
 45970            },
 45971            {
 45972              "license": {
 45973                "name": "NIST"
 45974              }
 45975            },
 45976            {
 45977              "license": {
 45978                "name": "OldBoost1"
 45979              }
 45980            },
 45981            {
 45982              "license": {
 45983                "name": "OldBoost2"
 45984              }
 45985            },
 45986            {
 45987              "license": {
 45988                "name": "OldBoost3"
 45989              }
 45990            },
 45991            {
 45992              "license": {
 45993                "name": "Python"
 45994              }
 45995            },
 45996            {
 45997              "license": {
 45998                "name": "SGI"
 45999              }
 46000            },
 46001            {
 46002              "license": {
 46003                "name": "Spencer"
 46004              }
 46005            },
 46006            {
 46007              "license": {
 46008                "id": "Zlib"
 46009              }
 46010            }
 46011          ],
 46012          "cpe": "cpe:2.3:a:libboost-thread1.71.0:libboost-thread1.71.0:1.71.0-6ubuntu6:*:*:*:*:*:*:*",
 46013          "purl": "pkg:deb/ubuntu/libboost-thread1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04",
 46014          "swid": {
 46015            "attachment": {}
 46016          },
 46017          "pedigree": {},
 46018          "evidence": {},
 46019          "signature": {
 46020            "signature": {
 46021              "publicKey": {}
 46022            }
 46023          },
 46024          "modelCard": {
 46025            "modelParameters": {
 46026              "approach": {}
 46027            },
 46028            "quantitativeAnalysis": {
 46029              "graphics": {}
 46030            },
 46031            "considerations": {}
 46032          }
 46033        },
 46034        {
 46035          "type": "library",
 46036          "bom-ref": "pkg:deb/ubuntu/libbrotli1@1.0.7-6ubuntu0.1?arch=amd64\u0026upstream=brotli\u0026distro=ubuntu-20.04\u0026package-id=3cfc22417c2e74ac",
 46037          "supplier": {},
 46038          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46039          "name": "libbrotli1",
 46040          "version": "1.0.7-6ubuntu0.1",
 46041          "licenses": [
 46042            {
 46043              "license": {
 46044                "id": "MIT"
 46045              }
 46046            }
 46047          ],
 46048          "cpe": "cpe:2.3:a:libbrotli1:libbrotli1:1.0.7-6ubuntu0.1:*:*:*:*:*:*:*",
 46049          "purl": "pkg:deb/ubuntu/libbrotli1@1.0.7-6ubuntu0.1?arch=amd64\u0026upstream=brotli\u0026distro=ubuntu-20.04",
 46050          "swid": {
 46051            "attachment": {}
 46052          },
 46053          "pedigree": {},
 46054          "evidence": {},
 46055          "signature": {
 46056            "signature": {
 46057              "publicKey": {}
 46058            }
 46059          },
 46060          "modelCard": {
 46061            "modelParameters": {
 46062              "approach": {}
 46063            },
 46064            "quantitativeAnalysis": {
 46065              "graphics": {}
 46066            },
 46067            "considerations": {}
 46068          }
 46069        },
 46070        {
 46071          "type": "library",
 46072          "bom-ref": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04\u0026package-id=88ee716d66a17869",
 46073          "supplier": {},
 46074          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46075          "name": "libbsd0",
 46076          "version": "0.10.0-1",
 46077          "licenses": [
 46078            {
 46079              "license": {
 46080                "id": "BSD-2-Clause"
 46081              }
 46082            },
 46083            {
 46084              "license": {
 46085                "id": "BSD-2-Clause"
 46086              }
 46087            },
 46088            {
 46089              "license": {
 46090                "name": "BSD-2-clause-author"
 46091              }
 46092            },
 46093            {
 46094              "license": {
 46095                "name": "BSD-2-clause-verbatim"
 46096              }
 46097            },
 46098            {
 46099              "license": {
 46100                "id": "BSD-3-Clause"
 46101              }
 46102            },
 46103            {
 46104              "license": {
 46105                "name": "BSD-3-clause-John-Birrell"
 46106              }
 46107            },
 46108            {
 46109              "license": {
 46110                "name": "BSD-3-clause-Regents"
 46111              }
 46112            },
 46113            {
 46114              "license": {
 46115                "name": "BSD-3-clause-author"
 46116              }
 46117            },
 46118            {
 46119              "license": {
 46120                "name": "BSD-4-clause-Christopher-G-Demetriou"
 46121              }
 46122            },
 46123            {
 46124              "license": {
 46125                "name": "BSD-4-clause-Niels-Provos"
 46126              }
 46127            },
 46128            {
 46129              "license": {
 46130                "name": "BSD-5-clause-Peter-Wemm"
 46131              }
 46132            },
 46133            {
 46134              "license": {
 46135                "id": "Beerware"
 46136              }
 46137            },
 46138            {
 46139              "license": {
 46140                "name": "Expat"
 46141              }
 46142            },
 46143            {
 46144              "license": {
 46145                "id": "ISC"
 46146              }
 46147            },
 46148            {
 46149              "license": {
 46150                "name": "ISC-Original"
 46151              }
 46152            },
 46153            {
 46154              "license": {
 46155                "name": "public-domain"
 46156              }
 46157            },
 46158            {
 46159              "license": {
 46160                "name": "public-domain-Colin-Plumb"
 46161              }
 46162            }
 46163          ],
 46164          "cpe": "cpe:2.3:a:libbsd0:libbsd0:0.10.0-1:*:*:*:*:*:*:*",
 46165          "purl": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04",
 46166          "swid": {
 46167            "attachment": {}
 46168          },
 46169          "pedigree": {},
 46170          "evidence": {},
 46171          "signature": {
 46172            "signature": {
 46173              "publicKey": {}
 46174            }
 46175          },
 46176          "modelCard": {
 46177            "modelParameters": {
 46178              "approach": {}
 46179            },
 46180            "quantitativeAnalysis": {
 46181              "graphics": {}
 46182            },
 46183            "considerations": {}
 46184          }
 46185        },
 46186        {
 46187          "type": "library",
 46188          "bom-ref": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04\u0026package-id=fd8b0edf257b69b7",
 46189          "supplier": {},
 46190          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46191          "name": "libbz2-1.0",
 46192          "version": "1.0.8-2",
 46193          "licenses": [
 46194            {
 46195              "license": {
 46196                "name": "BSD-variant"
 46197              }
 46198            },
 46199            {
 46200              "license": {
 46201                "id": "GPL-2.0-only"
 46202              }
 46203            }
 46204          ],
 46205          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-2:*:*:*:*:*:*:*",
 46206          "purl": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04",
 46207          "swid": {
 46208            "attachment": {}
 46209          },
 46210          "pedigree": {},
 46211          "evidence": {},
 46212          "signature": {
 46213            "signature": {
 46214              "publicKey": {}
 46215            }
 46216          },
 46217          "modelCard": {
 46218            "modelParameters": {
 46219              "approach": {}
 46220            },
 46221            "quantitativeAnalysis": {
 46222              "graphics": {}
 46223            },
 46224            "considerations": {}
 46225          }
 46226        },
 46227        {
 46228          "type": "library",
 46229          "bom-ref": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=256facf7cbb95a65",
 46230          "supplier": {},
 46231          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46232          "name": "libc-bin",
 46233          "version": "2.31-0ubuntu9.2",
 46234          "licenses": [
 46235            {
 46236              "license": {
 46237                "id": "GPL-2.0-only"
 46238              }
 46239            },
 46240            {
 46241              "license": {
 46242                "id": "LGPL-2.1-only"
 46243              }
 46244            }
 46245          ],
 46246          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
 46247          "purl": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
 46248          "swid": {
 46249            "attachment": {}
 46250          },
 46251          "pedigree": {},
 46252          "evidence": {},
 46253          "signature": {
 46254            "signature": {
 46255              "publicKey": {}
 46256            }
 46257          },
 46258          "modelCard": {
 46259            "modelParameters": {
 46260              "approach": {}
 46261            },
 46262            "quantitativeAnalysis": {
 46263              "graphics": {}
 46264            },
 46265            "considerations": {}
 46266          }
 46267        },
 46268        {
 46269          "type": "library",
 46270          "bom-ref": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=2a96b94fa4db214",
 46271          "supplier": {},
 46272          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46273          "name": "libc6",
 46274          "version": "2.31-0ubuntu9.2",
 46275          "licenses": [
 46276            {
 46277              "license": {
 46278                "id": "GPL-2.0-only"
 46279              }
 46280            },
 46281            {
 46282              "license": {
 46283                "id": "LGPL-2.1-only"
 46284              }
 46285            }
 46286          ],
 46287          "cpe": "cpe:2.3:a:libc6:libc6:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
 46288          "purl": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
 46289          "swid": {
 46290            "attachment": {}
 46291          },
 46292          "pedigree": {},
 46293          "evidence": {},
 46294          "signature": {
 46295            "signature": {
 46296              "publicKey": {}
 46297            }
 46298          },
 46299          "modelCard": {
 46300            "modelParameters": {
 46301              "approach": {}
 46302            },
 46303            "quantitativeAnalysis": {
 46304              "graphics": {}
 46305            },
 46306            "considerations": {}
 46307          }
 46308        },
 46309        {
 46310          "type": "library",
 46311          "bom-ref": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04\u0026package-id=57ceb68462a99cb4",
 46312          "supplier": {},
 46313          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46314          "name": "libcap-ng0",
 46315          "version": "0.7.9-2.1build1",
 46316          "licenses": [
 46317            {
 46318              "license": {
 46319                "id": "GPL-2.0-only"
 46320              }
 46321            },
 46322            {
 46323              "license": {
 46324                "id": "GPL-3.0-only"
 46325              }
 46326            },
 46327            {
 46328              "license": {
 46329                "id": "LGPL-2.1-only"
 46330              }
 46331            }
 46332          ],
 46333          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2.1build1:*:*:*:*:*:*:*",
 46334          "purl": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04",
 46335          "swid": {
 46336            "attachment": {}
 46337          },
 46338          "pedigree": {},
 46339          "evidence": {},
 46340          "signature": {
 46341            "signature": {
 46342              "publicKey": {}
 46343            }
 46344          },
 46345          "modelCard": {
 46346            "modelParameters": {
 46347              "approach": {}
 46348            },
 46349            "quantitativeAnalysis": {
 46350              "graphics": {}
 46351            },
 46352            "considerations": {}
 46353          }
 46354        },
 46355        {
 46356          "type": "library",
 46357          "bom-ref": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=682f3e304c127762",
 46358          "supplier": {},
 46359          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46360          "name": "libcap2",
 46361          "version": "1:2.32-1",
 46362          "licenses": [
 46363            {
 46364              "license": {
 46365                "id": "BSD-3-Clause"
 46366              }
 46367            },
 46368            {
 46369              "license": {
 46370                "id": "GPL-2.0-only"
 46371              }
 46372            },
 46373            {
 46374              "license": {
 46375                "id": "GPL-2.0-or-later"
 46376              }
 46377            }
 46378          ],
 46379          "cpe": "cpe:2.3:a:libcap2:libcap2:1\\:2.32-1:*:*:*:*:*:*:*",
 46380          "purl": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04",
 46381          "swid": {
 46382            "attachment": {}
 46383          },
 46384          "pedigree": {},
 46385          "evidence": {},
 46386          "signature": {
 46387            "signature": {
 46388              "publicKey": {}
 46389            }
 46390          },
 46391          "modelCard": {
 46392            "modelParameters": {
 46393              "approach": {}
 46394            },
 46395            "quantitativeAnalysis": {
 46396              "graphics": {}
 46397            },
 46398            "considerations": {}
 46399          }
 46400        },
 46401        {
 46402          "type": "library",
 46403          "bom-ref": "pkg:deb/ubuntu/libcap2-bin@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04\u0026package-id=8f0ae2256856772c",
 46404          "supplier": {},
 46405          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46406          "name": "libcap2-bin",
 46407          "version": "1:2.32-1",
 46408          "licenses": [
 46409            {
 46410              "license": {
 46411                "id": "BSD-3-Clause"
 46412              }
 46413            },
 46414            {
 46415              "license": {
 46416                "id": "GPL-2.0-only"
 46417              }
 46418            },
 46419            {
 46420              "license": {
 46421                "id": "GPL-2.0-or-later"
 46422              }
 46423            }
 46424          ],
 46425          "cpe": "cpe:2.3:a:libcap2-bin:libcap2-bin:1\\:2.32-1:*:*:*:*:*:*:*",
 46426          "purl": "pkg:deb/ubuntu/libcap2-bin@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04",
 46427          "swid": {
 46428            "attachment": {}
 46429          },
 46430          "pedigree": {},
 46431          "evidence": {},
 46432          "signature": {
 46433            "signature": {
 46434              "publicKey": {}
 46435            }
 46436          },
 46437          "modelCard": {
 46438            "modelParameters": {
 46439              "approach": {}
 46440            },
 46441            "quantitativeAnalysis": {
 46442              "graphics": {}
 46443            },
 46444            "considerations": {}
 46445          }
 46446        },
 46447        {
 46448          "type": "library",
 46449          "bom-ref": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=fbaeb4c3d5d0f976",
 46450          "supplier": {},
 46451          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46452          "name": "libcom-err2",
 46453          "version": "1.45.5-2ubuntu1",
 46454          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 46455          "purl": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 46456          "swid": {
 46457            "attachment": {}
 46458          },
 46459          "pedigree": {},
 46460          "evidence": {},
 46461          "signature": {
 46462            "signature": {
 46463              "publicKey": {}
 46464            }
 46465          },
 46466          "modelCard": {
 46467            "modelParameters": {
 46468              "approach": {}
 46469            },
 46470            "quantitativeAnalysis": {
 46471              "graphics": {}
 46472            },
 46473            "considerations": {}
 46474          }
 46475        },
 46476        {
 46477          "type": "library",
 46478          "bom-ref": "pkg:deb/ubuntu/libconfig-general-perl@2.63-1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=da9c7895b5630089",
 46479          "supplier": {},
 46480          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46481          "name": "libconfig-general-perl",
 46482          "version": "2.63-1",
 46483          "licenses": [
 46484            {
 46485              "license": {
 46486                "name": "Artistic"
 46487              }
 46488            },
 46489            {
 46490              "license": {
 46491                "id": "GPL-1.0-only"
 46492              }
 46493            },
 46494            {
 46495              "license": {
 46496                "id": "GPL-1.0-or-later"
 46497              }
 46498            }
 46499          ],
 46500          "cpe": "cpe:2.3:a:libconfig-general-perl:libconfig-general-perl:2.63-1:*:*:*:*:*:*:*",
 46501          "purl": "pkg:deb/ubuntu/libconfig-general-perl@2.63-1?arch=all\u0026distro=ubuntu-20.04",
 46502          "swid": {
 46503            "attachment": {}
 46504          },
 46505          "pedigree": {},
 46506          "evidence": {},
 46507          "signature": {
 46508            "signature": {
 46509              "publicKey": {}
 46510            }
 46511          },
 46512          "modelCard": {
 46513            "modelParameters": {
 46514              "approach": {}
 46515            },
 46516            "quantitativeAnalysis": {
 46517              "graphics": {}
 46518            },
 46519            "considerations": {}
 46520          }
 46521        },
 46522        {
 46523          "type": "library",
 46524          "bom-ref": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04\u0026package-id=8a4302e2e7027353",
 46525          "supplier": {},
 46526          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46527          "name": "libcrypt1",
 46528          "version": "1:4.4.10-10ubuntu4",
 46529          "cpe": "cpe:2.3:a:libcrypt1:libcrypt1:1\\:4.4.10-10ubuntu4:*:*:*:*:*:*:*",
 46530          "purl": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04",
 46531          "swid": {
 46532            "attachment": {}
 46533          },
 46534          "pedigree": {},
 46535          "evidence": {},
 46536          "signature": {
 46537            "signature": {
 46538              "publicKey": {}
 46539            }
 46540          },
 46541          "modelCard": {
 46542            "modelParameters": {
 46543              "approach": {}
 46544            },
 46545            "quantitativeAnalysis": {
 46546              "graphics": {}
 46547            },
 46548            "considerations": {}
 46549          }
 46550        },
 46551        {
 46552          "type": "library",
 46553          "bom-ref": "pkg:deb/ubuntu/libcurl3-gnutls@7.68.0-1ubuntu2.7?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04\u0026package-id=27e1128fdd417121",
 46554          "supplier": {},
 46555          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46556          "name": "libcurl3-gnutls",
 46557          "version": "7.68.0-1ubuntu2.7",
 46558          "licenses": [
 46559            {
 46560              "license": {
 46561                "id": "BSD-3-Clause"
 46562              }
 46563            },
 46564            {
 46565              "license": {
 46566                "id": "BSD-4-Clause"
 46567              }
 46568            },
 46569            {
 46570              "license": {
 46571                "id": "ISC"
 46572              }
 46573            },
 46574            {
 46575              "license": {
 46576                "id": "curl"
 46577              }
 46578            },
 46579            {
 46580              "license": {
 46581                "name": "other"
 46582              }
 46583            },
 46584            {
 46585              "license": {
 46586                "name": "public-domain"
 46587              }
 46588            }
 46589          ],
 46590          "cpe": "cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.68.0-1ubuntu2.7:*:*:*:*:*:*:*",
 46591          "purl": "pkg:deb/ubuntu/libcurl3-gnutls@7.68.0-1ubuntu2.7?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04",
 46592          "swid": {
 46593            "attachment": {}
 46594          },
 46595          "pedigree": {},
 46596          "evidence": {},
 46597          "signature": {
 46598            "signature": {
 46599              "publicKey": {}
 46600            }
 46601          },
 46602          "modelCard": {
 46603            "modelParameters": {
 46604              "approach": {}
 46605            },
 46606            "quantitativeAnalysis": {
 46607              "graphics": {}
 46608            },
 46609            "considerations": {}
 46610          }
 46611        },
 46612        {
 46613          "type": "library",
 46614          "bom-ref": "pkg:deb/ubuntu/libcurl4@7.68.0-1ubuntu2.7?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04\u0026package-id=9b8749d7a48aa2f5",
 46615          "supplier": {},
 46616          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46617          "name": "libcurl4",
 46618          "version": "7.68.0-1ubuntu2.7",
 46619          "licenses": [
 46620            {
 46621              "license": {
 46622                "id": "BSD-3-Clause"
 46623              }
 46624            },
 46625            {
 46626              "license": {
 46627                "id": "BSD-4-Clause"
 46628              }
 46629            },
 46630            {
 46631              "license": {
 46632                "id": "ISC"
 46633              }
 46634            },
 46635            {
 46636              "license": {
 46637                "id": "curl"
 46638              }
 46639            },
 46640            {
 46641              "license": {
 46642                "name": "other"
 46643              }
 46644            },
 46645            {
 46646              "license": {
 46647                "name": "public-domain"
 46648              }
 46649            }
 46650          ],
 46651          "cpe": "cpe:2.3:a:libcurl4:libcurl4:7.68.0-1ubuntu2.7:*:*:*:*:*:*:*",
 46652          "purl": "pkg:deb/ubuntu/libcurl4@7.68.0-1ubuntu2.7?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04",
 46653          "swid": {
 46654            "attachment": {}
 46655          },
 46656          "pedigree": {},
 46657          "evidence": {},
 46658          "signature": {
 46659            "signature": {
 46660              "publicKey": {}
 46661            }
 46662          },
 46663          "modelCard": {
 46664            "modelParameters": {
 46665              "approach": {}
 46666            },
 46667            "quantitativeAnalysis": {
 46668              "graphics": {}
 46669            },
 46670            "considerations": {}
 46671          }
 46672        },
 46673        {
 46674          "type": "library",
 46675          "bom-ref": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04\u0026package-id=bc84b4da0031640d",
 46676          "supplier": {},
 46677          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46678          "name": "libdb5.3",
 46679          "version": "5.3.28+dfsg1-0.6ubuntu2",
 46680          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.6ubuntu2:*:*:*:*:*:*:*",
 46681          "purl": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04",
 46682          "swid": {
 46683            "attachment": {}
 46684          },
 46685          "pedigree": {},
 46686          "evidence": {},
 46687          "signature": {
 46688            "signature": {
 46689              "publicKey": {}
 46690            }
 46691          },
 46692          "modelCard": {
 46693            "modelParameters": {
 46694              "approach": {}
 46695            },
 46696            "quantitativeAnalysis": {
 46697              "graphics": {}
 46698            },
 46699            "considerations": {}
 46700          }
 46701        },
 46702        {
 46703          "type": "library",
 46704          "bom-ref": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04\u0026package-id=78bbe40d9c2ef9b5",
 46705          "supplier": {},
 46706          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46707          "name": "libdebconfclient0",
 46708          "version": "0.251ubuntu1",
 46709          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.251ubuntu1:*:*:*:*:*:*:*",
 46710          "purl": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04",
 46711          "swid": {
 46712            "attachment": {}
 46713          },
 46714          "pedigree": {},
 46715          "evidence": {},
 46716          "signature": {
 46717            "signature": {
 46718              "publicKey": {}
 46719            }
 46720          },
 46721          "modelCard": {
 46722            "modelParameters": {
 46723              "approach": {}
 46724            },
 46725            "quantitativeAnalysis": {
 46726              "graphics": {}
 46727            },
 46728            "considerations": {}
 46729          }
 46730        },
 46731        {
 46732          "type": "library",
 46733          "bom-ref": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=30b70188951a65f0",
 46734          "supplier": {},
 46735          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46736          "name": "libdevmapper1.02.1",
 46737          "version": "2:1.02.167-1ubuntu1",
 46738          "licenses": [
 46739            {
 46740              "license": {
 46741                "id": "BSD-2-Clause"
 46742              }
 46743            },
 46744            {
 46745              "license": {
 46746                "id": "GPL-2.0-only"
 46747              }
 46748            },
 46749            {
 46750              "license": {
 46751                "id": "GPL-2.0-only"
 46752              }
 46753            },
 46754            {
 46755              "license": {
 46756                "id": "GPL-2.0-or-later"
 46757              }
 46758            },
 46759            {
 46760              "license": {
 46761                "id": "LGPL-2.0-only"
 46762              }
 46763            },
 46764            {
 46765              "license": {
 46766                "id": "LGPL-2.1-only"
 46767              }
 46768            }
 46769          ],
 46770          "cpe": "cpe:2.3:a:libdevmapper1.02.1:libdevmapper1.02.1:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
 46771          "purl": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
 46772          "swid": {
 46773            "attachment": {}
 46774          },
 46775          "pedigree": {},
 46776          "evidence": {},
 46777          "signature": {
 46778            "signature": {
 46779              "publicKey": {}
 46780            }
 46781          },
 46782          "modelCard": {
 46783            "modelParameters": {
 46784              "approach": {}
 46785            },
 46786            "quantitativeAnalysis": {
 46787              "graphics": {}
 46788            },
 46789            "considerations": {}
 46790          }
 46791        },
 46792        {
 46793          "type": "library",
 46794          "bom-ref": "pkg:deb/ubuntu/libelf1@0.176-1.1build1?arch=amd64\u0026upstream=elfutils\u0026distro=ubuntu-20.04\u0026package-id=316daaa294f5e8d8",
 46795          "supplier": {},
 46796          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46797          "name": "libelf1",
 46798          "version": "0.176-1.1build1",
 46799          "licenses": [
 46800            {
 46801              "license": {
 46802                "id": "GPL-2.0-only"
 46803              }
 46804            },
 46805            {
 46806              "license": {
 46807                "id": "GPL-3.0-only"
 46808              }
 46809            },
 46810            {
 46811              "license": {
 46812                "name": "LGPL-"
 46813              }
 46814            }
 46815          ],
 46816          "cpe": "cpe:2.3:a:libelf1:libelf1:0.176-1.1build1:*:*:*:*:*:*:*",
 46817          "purl": "pkg:deb/ubuntu/libelf1@0.176-1.1build1?arch=amd64\u0026upstream=elfutils\u0026distro=ubuntu-20.04",
 46818          "swid": {
 46819            "attachment": {}
 46820          },
 46821          "pedigree": {},
 46822          "evidence": {},
 46823          "signature": {
 46824            "signature": {
 46825              "publicKey": {}
 46826            }
 46827          },
 46828          "modelCard": {
 46829            "modelParameters": {
 46830              "approach": {}
 46831            },
 46832            "quantitativeAnalysis": {
 46833              "graphics": {}
 46834            },
 46835            "considerations": {}
 46836          }
 46837        },
 46838        {
 46839          "type": "library",
 46840          "bom-ref": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04\u0026package-id=6b93a7dccfeb49e0",
 46841          "supplier": {},
 46842          "publisher": "Balint Reczey \u003crbalint@ubuntu.com\u003e",
 46843          "name": "libevent-2.1-7",
 46844          "version": "2.1.11-stable-1",
 46845          "licenses": [
 46846            {
 46847              "license": {
 46848                "id": "BSD-2-Clause"
 46849              }
 46850            },
 46851            {
 46852              "license": {
 46853                "name": "BSD-3-Clause~Kitware"
 46854              }
 46855            },
 46856            {
 46857              "license": {
 46858                "id": "BSD-3-Clause"
 46859              }
 46860            },
 46861            {
 46862              "license": {
 46863                "name": "BSL"
 46864              }
 46865            },
 46866            {
 46867              "license": {
 46868                "name": "Expat"
 46869              }
 46870            },
 46871            {
 46872              "license": {
 46873                "id": "FSFUL"
 46874              }
 46875            },
 46876            {
 46877              "license": {
 46878                "id": "FSFULLR"
 46879              }
 46880            },
 46881            {
 46882              "license": {
 46883                "name": "FSFULLR-No-Warranty"
 46884              }
 46885            },
 46886            {
 46887              "license": {
 46888                "id": "GPL-2.0-only"
 46889              }
 46890            },
 46891            {
 46892              "license": {
 46893                "id": "GPL-2.0-or-later"
 46894              }
 46895            },
 46896            {
 46897              "license": {
 46898                "id": "GPL-3.0-only"
 46899              }
 46900            },
 46901            {
 46902              "license": {
 46903                "id": "GPL-3.0-or-later"
 46904              }
 46905            },
 46906            {
 46907              "license": {
 46908                "id": "ISC"
 46909              }
 46910            },
 46911            {
 46912              "license": {
 46913                "id": "curl"
 46914              }
 46915            }
 46916          ],
 46917          "cpe": "cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.11-stable-1:*:*:*:*:*:*:*",
 46918          "purl": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04",
 46919          "swid": {
 46920            "attachment": {}
 46921          },
 46922          "pedigree": {},
 46923          "evidence": {},
 46924          "signature": {
 46925            "signature": {
 46926              "publicKey": {}
 46927            }
 46928          },
 46929          "modelCard": {
 46930            "modelParameters": {
 46931              "approach": {}
 46932            },
 46933            "quantitativeAnalysis": {
 46934              "graphics": {}
 46935            },
 46936            "considerations": {}
 46937          }
 46938        },
 46939        {
 46940          "type": "library",
 46941          "bom-ref": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04\u0026package-id=f3ac75cd161f13c6",
 46942          "supplier": {},
 46943          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46944          "name": "libexpat1",
 46945          "version": "2.2.9-1build1",
 46946          "licenses": [
 46947            {
 46948              "license": {
 46949                "id": "MIT"
 46950              }
 46951            }
 46952          ],
 46953          "cpe": "cpe:2.3:a:libexpat1:libexpat1:2.2.9-1build1:*:*:*:*:*:*:*",
 46954          "purl": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04",
 46955          "swid": {
 46956            "attachment": {}
 46957          },
 46958          "pedigree": {},
 46959          "evidence": {},
 46960          "signature": {
 46961            "signature": {
 46962              "publicKey": {}
 46963            }
 46964          },
 46965          "modelCard": {
 46966            "modelParameters": {
 46967              "approach": {}
 46968            },
 46969            "quantitativeAnalysis": {
 46970              "graphics": {}
 46971            },
 46972            "considerations": {}
 46973          }
 46974        },
 46975        {
 46976          "type": "library",
 46977          "bom-ref": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=ec6113f55e73d1fd",
 46978          "supplier": {},
 46979          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 46980          "name": "libext2fs2",
 46981          "version": "1.45.5-2ubuntu1",
 46982          "licenses": [
 46983            {
 46984              "license": {
 46985                "id": "GPL-2.0-only"
 46986              }
 46987            },
 46988            {
 46989              "license": {
 46990                "id": "LGPL-2.0-only"
 46991              }
 46992            }
 46993          ],
 46994          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 46995          "purl": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 46996          "swid": {
 46997            "attachment": {}
 46998          },
 46999          "pedigree": {},
 47000          "evidence": {},
 47001          "signature": {
 47002            "signature": {
 47003              "publicKey": {}
 47004            }
 47005          },
 47006          "modelCard": {
 47007            "modelParameters": {
 47008              "approach": {}
 47009            },
 47010            "quantitativeAnalysis": {
 47011              "graphics": {}
 47012            },
 47013            "considerations": {}
 47014          }
 47015        },
 47016        {
 47017          "type": "library",
 47018          "bom-ref": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=486ce61647644619",
 47019          "supplier": {},
 47020          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47021          "name": "libfdisk1",
 47022          "version": "2.34-0.1ubuntu9.1",
 47023          "licenses": [
 47024            {
 47025              "license": {
 47026                "id": "BSD-2-Clause"
 47027              }
 47028            },
 47029            {
 47030              "license": {
 47031                "id": "BSD-3-Clause"
 47032              }
 47033            },
 47034            {
 47035              "license": {
 47036                "id": "BSD-4-Clause"
 47037              }
 47038            },
 47039            {
 47040              "license": {
 47041                "id": "GPL-2.0-only"
 47042              }
 47043            },
 47044            {
 47045              "license": {
 47046                "id": "GPL-2.0-or-later"
 47047              }
 47048            },
 47049            {
 47050              "license": {
 47051                "id": "GPL-3.0-only"
 47052              }
 47053            },
 47054            {
 47055              "license": {
 47056                "id": "GPL-3.0-or-later"
 47057              }
 47058            },
 47059            {
 47060              "license": {
 47061                "name": "LGPL"
 47062              }
 47063            },
 47064            {
 47065              "license": {
 47066                "id": "LGPL-2.0-only"
 47067              }
 47068            },
 47069            {
 47070              "license": {
 47071                "id": "LGPL-2.0-or-later"
 47072              }
 47073            },
 47074            {
 47075              "license": {
 47076                "id": "LGPL-2.1-only"
 47077              }
 47078            },
 47079            {
 47080              "license": {
 47081                "id": "LGPL-2.1-or-later"
 47082              }
 47083            },
 47084            {
 47085              "license": {
 47086                "id": "LGPL-3.0-only"
 47087              }
 47088            },
 47089            {
 47090              "license": {
 47091                "id": "LGPL-3.0-or-later"
 47092              }
 47093            },
 47094            {
 47095              "license": {
 47096                "id": "MIT"
 47097              }
 47098            },
 47099            {
 47100              "license": {
 47101                "name": "public-domain"
 47102              }
 47103            }
 47104          ],
 47105          "cpe": "cpe:2.3:a:libfdisk1:libfdisk1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 47106          "purl": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 47107          "swid": {
 47108            "attachment": {}
 47109          },
 47110          "pedigree": {},
 47111          "evidence": {},
 47112          "signature": {
 47113            "signature": {
 47114              "publicKey": {}
 47115            }
 47116          },
 47117          "modelCard": {
 47118            "modelParameters": {
 47119              "approach": {}
 47120            },
 47121            "quantitativeAnalysis": {
 47122              "graphics": {}
 47123            },
 47124            "considerations": {}
 47125          }
 47126        },
 47127        {
 47128          "type": "library",
 47129          "bom-ref": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04\u0026package-id=b43b799d45da9d97",
 47130          "supplier": {},
 47131          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47132          "name": "libffi7",
 47133          "version": "3.3-4",
 47134          "licenses": [
 47135            {
 47136              "license": {
 47137                "name": "GPL"
 47138              }
 47139            }
 47140          ],
 47141          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-4:*:*:*:*:*:*:*",
 47142          "purl": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04",
 47143          "swid": {
 47144            "attachment": {}
 47145          },
 47146          "pedigree": {},
 47147          "evidence": {},
 47148          "signature": {
 47149            "signature": {
 47150              "publicKey": {}
 47151            }
 47152          },
 47153          "modelCard": {
 47154            "modelParameters": {
 47155              "approach": {}
 47156            },
 47157            "quantitativeAnalysis": {
 47158              "graphics": {}
 47159            },
 47160            "considerations": {}
 47161          }
 47162        },
 47163        {
 47164          "type": "library",
 47165          "bom-ref": "pkg:deb/ubuntu/libfuse2@2.9.9-3?arch=amd64\u0026upstream=fuse\u0026distro=ubuntu-20.04\u0026package-id=cb74b48e2705f805",
 47166          "supplier": {},
 47167          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47168          "name": "libfuse2",
 47169          "version": "2.9.9-3",
 47170          "licenses": [
 47171            {
 47172              "license": {
 47173                "id": "GPL-2.0-only"
 47174              }
 47175            },
 47176            {
 47177              "license": {
 47178                "id": "GPL-2.0-or-later"
 47179              }
 47180            },
 47181            {
 47182              "license": {
 47183                "id": "LGPL-2.0-only"
 47184              }
 47185            }
 47186          ],
 47187          "cpe": "cpe:2.3:a:libfuse2:libfuse2:2.9.9-3:*:*:*:*:*:*:*",
 47188          "purl": "pkg:deb/ubuntu/libfuse2@2.9.9-3?arch=amd64\u0026upstream=fuse\u0026distro=ubuntu-20.04",
 47189          "swid": {
 47190            "attachment": {}
 47191          },
 47192          "pedigree": {},
 47193          "evidence": {},
 47194          "signature": {
 47195            "signature": {
 47196              "publicKey": {}
 47197            }
 47198          },
 47199          "modelCard": {
 47200            "modelParameters": {
 47201              "approach": {}
 47202            },
 47203            "quantitativeAnalysis": {
 47204              "graphics": {}
 47205            },
 47206            "considerations": {}
 47207          }
 47208        },
 47209        {
 47210          "type": "library",
 47211          "bom-ref": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=f98ce69fd9e55bb8",
 47212          "supplier": {},
 47213          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47214          "name": "libgcc-s1",
 47215          "version": "10.3.0-1ubuntu1~20.04",
 47216          "licenses": [
 47217            {
 47218              "license": {
 47219                "name": "Artistic"
 47220              }
 47221            },
 47222            {
 47223              "license": {
 47224                "id": "GFDL-1.2-only"
 47225              }
 47226            },
 47227            {
 47228              "license": {
 47229                "name": "GPL"
 47230              }
 47231            },
 47232            {
 47233              "license": {
 47234                "id": "GPL-2.0-only"
 47235              }
 47236            },
 47237            {
 47238              "license": {
 47239                "id": "GPL-3.0-only"
 47240              }
 47241            },
 47242            {
 47243              "license": {
 47244                "name": "LGPL"
 47245              }
 47246            }
 47247          ],
 47248          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
 47249          "purl": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
 47250          "swid": {
 47251            "attachment": {}
 47252          },
 47253          "pedigree": {},
 47254          "evidence": {},
 47255          "signature": {
 47256            "signature": {
 47257              "publicKey": {}
 47258            }
 47259          },
 47260          "modelCard": {
 47261            "modelParameters": {
 47262              "approach": {}
 47263            },
 47264            "quantitativeAnalysis": {
 47265              "graphics": {}
 47266            },
 47267            "considerations": {}
 47268          }
 47269        },
 47270        {
 47271          "type": "library",
 47272          "bom-ref": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=779dc4322dee5841",
 47273          "supplier": {},
 47274          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47275          "name": "libgcrypt20",
 47276          "version": "1.8.5-5ubuntu1.1",
 47277          "licenses": [
 47278            {
 47279              "license": {
 47280                "id": "GPL-2.0-only"
 47281              }
 47282            },
 47283            {
 47284              "license": {
 47285                "name": "LGPL"
 47286              }
 47287            }
 47288          ],
 47289          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.5-5ubuntu1.1:*:*:*:*:*:*:*",
 47290          "purl": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04",
 47291          "swid": {
 47292            "attachment": {}
 47293          },
 47294          "pedigree": {},
 47295          "evidence": {},
 47296          "signature": {
 47297            "signature": {
 47298              "publicKey": {}
 47299            }
 47300          },
 47301          "modelCard": {
 47302            "modelParameters": {
 47303              "approach": {}
 47304            },
 47305            "quantitativeAnalysis": {
 47306              "graphics": {}
 47307            },
 47308            "considerations": {}
 47309          }
 47310        },
 47311        {
 47312          "type": "library",
 47313          "bom-ref": "pkg:deb/ubuntu/libgdbm-compat4@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04\u0026package-id=216492c4d03e5a3b",
 47314          "supplier": {},
 47315          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47316          "name": "libgdbm-compat4",
 47317          "version": "1.18.1-5",
 47318          "licenses": [
 47319            {
 47320              "license": {
 47321                "name": "GFDL-NIV-1.3+"
 47322              }
 47323            },
 47324            {
 47325              "license": {
 47326                "id": "GPL-2.0-only"
 47327              }
 47328            },
 47329            {
 47330              "license": {
 47331                "id": "GPL-2.0-or-later"
 47332              }
 47333            },
 47334            {
 47335              "license": {
 47336                "id": "GPL-3.0-only"
 47337              }
 47338            },
 47339            {
 47340              "license": {
 47341                "id": "GPL-3.0-or-later"
 47342              }
 47343            }
 47344          ],
 47345          "cpe": "cpe:2.3:a:libgdbm-compat4:libgdbm-compat4:1.18.1-5:*:*:*:*:*:*:*",
 47346          "purl": "pkg:deb/ubuntu/libgdbm-compat4@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04",
 47347          "swid": {
 47348            "attachment": {}
 47349          },
 47350          "pedigree": {},
 47351          "evidence": {},
 47352          "signature": {
 47353            "signature": {
 47354              "publicKey": {}
 47355            }
 47356          },
 47357          "modelCard": {
 47358            "modelParameters": {
 47359              "approach": {}
 47360            },
 47361            "quantitativeAnalysis": {
 47362              "graphics": {}
 47363            },
 47364            "considerations": {}
 47365          }
 47366        },
 47367        {
 47368          "type": "library",
 47369          "bom-ref": "pkg:deb/ubuntu/libgdbm6@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04\u0026package-id=e7baa5d6d4faa647",
 47370          "supplier": {},
 47371          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47372          "name": "libgdbm6",
 47373          "version": "1.18.1-5",
 47374          "licenses": [
 47375            {
 47376              "license": {
 47377                "name": "GFDL-NIV-1.3+"
 47378              }
 47379            },
 47380            {
 47381              "license": {
 47382                "id": "GPL-2.0-only"
 47383              }
 47384            },
 47385            {
 47386              "license": {
 47387                "id": "GPL-2.0-or-later"
 47388              }
 47389            },
 47390            {
 47391              "license": {
 47392                "id": "GPL-3.0-only"
 47393              }
 47394            },
 47395            {
 47396              "license": {
 47397                "id": "GPL-3.0-or-later"
 47398              }
 47399            }
 47400          ],
 47401          "cpe": "cpe:2.3:a:libgdbm6:libgdbm6:1.18.1-5:*:*:*:*:*:*:*",
 47402          "purl": "pkg:deb/ubuntu/libgdbm6@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04",
 47403          "swid": {
 47404            "attachment": {}
 47405          },
 47406          "pedigree": {},
 47407          "evidence": {},
 47408          "signature": {
 47409            "signature": {
 47410              "publicKey": {}
 47411            }
 47412          },
 47413          "modelCard": {
 47414            "modelParameters": {
 47415              "approach": {}
 47416            },
 47417            "quantitativeAnalysis": {
 47418              "graphics": {}
 47419            },
 47420            "considerations": {}
 47421          }
 47422        },
 47423        {
 47424          "type": "library",
 47425          "bom-ref": "pkg:deb/ubuntu/libglib2.0-0@2.64.6-1~ubuntu20.04.4?arch=amd64\u0026upstream=glib2.0\u0026distro=ubuntu-20.04\u0026package-id=173f54b9a4ea5bbf",
 47426          "supplier": {},
 47427          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47428          "name": "libglib2.0-0",
 47429          "version": "2.64.6-1~ubuntu20.04.4",
 47430          "licenses": [
 47431            {
 47432              "license": {
 47433                "name": "Expat"
 47434              }
 47435            },
 47436            {
 47437              "license": {
 47438                "id": "GPL-2.0-or-later"
 47439              }
 47440            },
 47441            {
 47442              "license": {
 47443                "name": "LGPL"
 47444              }
 47445            }
 47446          ],
 47447          "cpe": "cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.64.6-1\\~ubuntu20.04.4:*:*:*:*:*:*:*",
 47448          "purl": "pkg:deb/ubuntu/libglib2.0-0@2.64.6-1~ubuntu20.04.4?arch=amd64\u0026upstream=glib2.0\u0026distro=ubuntu-20.04",
 47449          "swid": {
 47450            "attachment": {}
 47451          },
 47452          "pedigree": {},
 47453          "evidence": {},
 47454          "signature": {
 47455            "signature": {
 47456              "publicKey": {}
 47457            }
 47458          },
 47459          "modelCard": {
 47460            "modelParameters": {
 47461              "approach": {}
 47462            },
 47463            "quantitativeAnalysis": {
 47464              "graphics": {}
 47465            },
 47466            "considerations": {}
 47467          }
 47468        },
 47469        {
 47470          "type": "library",
 47471          "bom-ref": "pkg:deb/ubuntu/libglib2.0-data@2.64.6-1~ubuntu20.04.4?arch=all\u0026upstream=glib2.0\u0026distro=ubuntu-20.04\u0026package-id=84c7d5b71baf104a",
 47472          "supplier": {},
 47473          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47474          "name": "libglib2.0-data",
 47475          "version": "2.64.6-1~ubuntu20.04.4",
 47476          "licenses": [
 47477            {
 47478              "license": {
 47479                "name": "Expat"
 47480              }
 47481            },
 47482            {
 47483              "license": {
 47484                "id": "GPL-2.0-or-later"
 47485              }
 47486            },
 47487            {
 47488              "license": {
 47489                "name": "LGPL"
 47490              }
 47491            }
 47492          ],
 47493          "cpe": "cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.64.6-1\\~ubuntu20.04.4:*:*:*:*:*:*:*",
 47494          "purl": "pkg:deb/ubuntu/libglib2.0-data@2.64.6-1~ubuntu20.04.4?arch=all\u0026upstream=glib2.0\u0026distro=ubuntu-20.04",
 47495          "swid": {
 47496            "attachment": {}
 47497          },
 47498          "pedigree": {},
 47499          "evidence": {},
 47500          "signature": {
 47501            "signature": {
 47502              "publicKey": {}
 47503            }
 47504          },
 47505          "modelCard": {
 47506            "modelParameters": {
 47507              "approach": {}
 47508            },
 47509            "quantitativeAnalysis": {
 47510              "graphics": {}
 47511            },
 47512            "considerations": {}
 47513          }
 47514        },
 47515        {
 47516          "type": "library",
 47517          "bom-ref": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04\u0026package-id=40fc269dcb8b3369",
 47518          "supplier": {},
 47519          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47520          "name": "libgmp10",
 47521          "version": "2:6.2.0+dfsg-4",
 47522          "licenses": [
 47523            {
 47524              "license": {
 47525                "name": "GPL"
 47526              }
 47527            },
 47528            {
 47529              "license": {
 47530                "id": "GPL-2.0-only"
 47531              }
 47532            },
 47533            {
 47534              "license": {
 47535                "id": "GPL-3.0-only"
 47536              }
 47537            },
 47538            {
 47539              "license": {
 47540                "id": "LGPL-3.0-only"
 47541              }
 47542            }
 47543          ],
 47544          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.0\\+dfsg-4:*:*:*:*:*:*:*",
 47545          "purl": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04",
 47546          "swid": {
 47547            "attachment": {}
 47548          },
 47549          "pedigree": {},
 47550          "evidence": {},
 47551          "signature": {
 47552            "signature": {
 47553              "publicKey": {}
 47554            }
 47555          },
 47556          "modelCard": {
 47557            "modelParameters": {
 47558              "approach": {}
 47559            },
 47560            "quantitativeAnalysis": {
 47561              "graphics": {}
 47562            },
 47563            "considerations": {}
 47564          }
 47565        },
 47566        {
 47567          "type": "library",
 47568          "bom-ref": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04\u0026package-id=7490f76da775c6e",
 47569          "supplier": {},
 47570          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47571          "name": "libgnutls30",
 47572          "version": "3.6.13-2ubuntu1.6",
 47573          "licenses": [
 47574            {
 47575              "license": {
 47576                "id": "Apache-2.0"
 47577              }
 47578            },
 47579            {
 47580              "license": {
 47581                "id": "BSD-3-Clause"
 47582              }
 47583            },
 47584            {
 47585              "license": {
 47586                "name": "CC0"
 47587              }
 47588            },
 47589            {
 47590              "license": {
 47591                "name": "Expat"
 47592              }
 47593            },
 47594            {
 47595              "license": {
 47596                "id": "GFDL-1.3-only"
 47597              }
 47598            },
 47599            {
 47600              "license": {
 47601                "name": "GPL"
 47602              }
 47603            },
 47604            {
 47605              "license": {
 47606                "id": "GPL-3.0-only"
 47607              }
 47608            },
 47609            {
 47610              "license": {
 47611                "name": "GPLv3+"
 47612              }
 47613            },
 47614            {
 47615              "license": {
 47616                "name": "LGPL"
 47617              }
 47618            },
 47619            {
 47620              "license": {
 47621                "id": "LGPL-3.0-only"
 47622              }
 47623            },
 47624            {
 47625              "license": {
 47626                "name": "LGPLv2.1+"
 47627              }
 47628            },
 47629            {
 47630              "license": {
 47631                "name": "LGPLv3+_or_GPLv2+"
 47632              }
 47633            },
 47634            {
 47635              "license": {
 47636                "name": "The"
 47637              }
 47638            }
 47639          ],
 47640          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.13-2ubuntu1.6:*:*:*:*:*:*:*",
 47641          "purl": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04",
 47642          "swid": {
 47643            "attachment": {}
 47644          },
 47645          "pedigree": {},
 47646          "evidence": {},
 47647          "signature": {
 47648            "signature": {
 47649              "publicKey": {}
 47650            }
 47651          },
 47652          "modelCard": {
 47653            "modelParameters": {
 47654              "approach": {}
 47655            },
 47656            "quantitativeAnalysis": {
 47657              "graphics": {}
 47658            },
 47659            "considerations": {}
 47660          }
 47661        },
 47662        {
 47663          "type": "library",
 47664          "bom-ref": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04\u0026package-id=37ef62d87edfe03",
 47665          "supplier": {},
 47666          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47667          "name": "libgpg-error0",
 47668          "version": "1.37-1",
 47669          "licenses": [
 47670            {
 47671              "license": {
 47672                "id": "BSD-3-Clause"
 47673              }
 47674            },
 47675            {
 47676              "license": {
 47677                "id": "GPL-3.0-only"
 47678              }
 47679            },
 47680            {
 47681              "license": {
 47682                "id": "GPL-3.0-or-later"
 47683              }
 47684            },
 47685            {
 47686              "license": {
 47687                "id": "LGPL-2.1-only"
 47688              }
 47689            },
 47690            {
 47691              "license": {
 47692                "id": "LGPL-2.1-or-later"
 47693              }
 47694            },
 47695            {
 47696              "license": {
 47697                "name": "g10-permissive"
 47698              }
 47699            }
 47700          ],
 47701          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.37-1:*:*:*:*:*:*:*",
 47702          "purl": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04",
 47703          "swid": {
 47704            "attachment": {}
 47705          },
 47706          "pedigree": {},
 47707          "evidence": {},
 47708          "signature": {
 47709            "signature": {
 47710              "publicKey": {}
 47711            }
 47712          },
 47713          "modelCard": {
 47714            "modelParameters": {
 47715              "approach": {}
 47716            },
 47717            "quantitativeAnalysis": {
 47718              "graphics": {}
 47719            },
 47720            "considerations": {}
 47721          }
 47722        },
 47723        {
 47724          "type": "library",
 47725          "bom-ref": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=443eafe2785f5a4c",
 47726          "supplier": {},
 47727          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47728          "name": "libgssapi-krb5-2",
 47729          "version": "1.17-6ubuntu4.1",
 47730          "licenses": [
 47731            {
 47732              "license": {
 47733                "id": "GPL-2.0-only"
 47734              }
 47735            }
 47736          ],
 47737          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 47738          "purl": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 47739          "swid": {
 47740            "attachment": {}
 47741          },
 47742          "pedigree": {},
 47743          "evidence": {},
 47744          "signature": {
 47745            "signature": {
 47746              "publicKey": {}
 47747            }
 47748          },
 47749          "modelCard": {
 47750            "modelParameters": {
 47751              "approach": {}
 47752            },
 47753            "quantitativeAnalysis": {
 47754              "graphics": {}
 47755            },
 47756            "considerations": {}
 47757          }
 47758        },
 47759        {
 47760          "type": "library",
 47761          "bom-ref": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=17a37cca2446b615",
 47762          "supplier": {},
 47763          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47764          "name": "libgssapi3-heimdal",
 47765          "version": "7.7.0+dfsg-1ubuntu1",
 47766          "licenses": [
 47767            {
 47768              "license": {
 47769                "id": "BSD-3-Clause"
 47770              }
 47771            },
 47772            {
 47773              "license": {
 47774                "id": "GPL-2.0-only"
 47775              }
 47776            },
 47777            {
 47778              "license": {
 47779                "id": "GPL-2.0-or-later"
 47780              }
 47781            },
 47782            {
 47783              "license": {
 47784                "name": "custom"
 47785              }
 47786            }
 47787          ],
 47788          "cpe": "cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 47789          "purl": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 47790          "swid": {
 47791            "attachment": {}
 47792          },
 47793          "pedigree": {},
 47794          "evidence": {},
 47795          "signature": {
 47796            "signature": {
 47797              "publicKey": {}
 47798            }
 47799          },
 47800          "modelCard": {
 47801            "modelParameters": {
 47802              "approach": {}
 47803            },
 47804            "quantitativeAnalysis": {
 47805              "graphics": {}
 47806            },
 47807            "considerations": {}
 47808          }
 47809        },
 47810        {
 47811          "type": "library",
 47812          "bom-ref": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=98098d582df76b44",
 47813          "supplier": {},
 47814          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47815          "name": "libhcrypto4-heimdal",
 47816          "version": "7.7.0+dfsg-1ubuntu1",
 47817          "licenses": [
 47818            {
 47819              "license": {
 47820                "id": "BSD-3-Clause"
 47821              }
 47822            },
 47823            {
 47824              "license": {
 47825                "id": "GPL-2.0-only"
 47826              }
 47827            },
 47828            {
 47829              "license": {
 47830                "id": "GPL-2.0-or-later"
 47831              }
 47832            },
 47833            {
 47834              "license": {
 47835                "name": "custom"
 47836              }
 47837            }
 47838          ],
 47839          "cpe": "cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 47840          "purl": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 47841          "swid": {
 47842            "attachment": {}
 47843          },
 47844          "pedigree": {},
 47845          "evidence": {},
 47846          "signature": {
 47847            "signature": {
 47848              "publicKey": {}
 47849            }
 47850          },
 47851          "modelCard": {
 47852            "modelParameters": {
 47853              "approach": {}
 47854            },
 47855            "quantitativeAnalysis": {
 47856              "graphics": {}
 47857            },
 47858            "considerations": {}
 47859          }
 47860        },
 47861        {
 47862          "type": "library",
 47863          "bom-ref": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=f8dfc9a84c337835",
 47864          "supplier": {},
 47865          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47866          "name": "libheimbase1-heimdal",
 47867          "version": "7.7.0+dfsg-1ubuntu1",
 47868          "licenses": [
 47869            {
 47870              "license": {
 47871                "id": "BSD-3-Clause"
 47872              }
 47873            },
 47874            {
 47875              "license": {
 47876                "id": "GPL-2.0-only"
 47877              }
 47878            },
 47879            {
 47880              "license": {
 47881                "id": "GPL-2.0-or-later"
 47882              }
 47883            },
 47884            {
 47885              "license": {
 47886                "name": "custom"
 47887              }
 47888            }
 47889          ],
 47890          "cpe": "cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 47891          "purl": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 47892          "swid": {
 47893            "attachment": {}
 47894          },
 47895          "pedigree": {},
 47896          "evidence": {},
 47897          "signature": {
 47898            "signature": {
 47899              "publicKey": {}
 47900            }
 47901          },
 47902          "modelCard": {
 47903            "modelParameters": {
 47904              "approach": {}
 47905            },
 47906            "quantitativeAnalysis": {
 47907              "graphics": {}
 47908            },
 47909            "considerations": {}
 47910          }
 47911        },
 47912        {
 47913          "type": "library",
 47914          "bom-ref": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=9992d88ac7d6e8e3",
 47915          "supplier": {},
 47916          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47917          "name": "libheimntlm0-heimdal",
 47918          "version": "7.7.0+dfsg-1ubuntu1",
 47919          "licenses": [
 47920            {
 47921              "license": {
 47922                "id": "BSD-3-Clause"
 47923              }
 47924            },
 47925            {
 47926              "license": {
 47927                "id": "GPL-2.0-only"
 47928              }
 47929            },
 47930            {
 47931              "license": {
 47932                "id": "GPL-2.0-or-later"
 47933              }
 47934            },
 47935            {
 47936              "license": {
 47937                "name": "custom"
 47938              }
 47939            }
 47940          ],
 47941          "cpe": "cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 47942          "purl": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 47943          "swid": {
 47944            "attachment": {}
 47945          },
 47946          "pedigree": {},
 47947          "evidence": {},
 47948          "signature": {
 47949            "signature": {
 47950              "publicKey": {}
 47951            }
 47952          },
 47953          "modelCard": {
 47954            "modelParameters": {
 47955              "approach": {}
 47956            },
 47957            "quantitativeAnalysis": {
 47958              "graphics": {}
 47959            },
 47960            "considerations": {}
 47961          }
 47962        },
 47963        {
 47964          "type": "library",
 47965          "bom-ref": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3caecccf070e6760",
 47966          "supplier": {},
 47967          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 47968          "name": "libhogweed5",
 47969          "version": "3.5.1+really3.5.1-2ubuntu0.2",
 47970          "licenses": [
 47971            {
 47972              "license": {
 47973                "name": "GAP"
 47974              }
 47975            },
 47976            {
 47977              "license": {
 47978                "name": "GPL"
 47979              }
 47980            },
 47981            {
 47982              "license": {
 47983                "id": "GPL-2.0-only"
 47984              }
 47985            },
 47986            {
 47987              "license": {
 47988                "id": "GPL-2.0-or-later"
 47989              }
 47990            },
 47991            {
 47992              "license": {
 47993                "name": "LGPL"
 47994              }
 47995            },
 47996            {
 47997              "license": {
 47998                "id": "LGPL-2.0-only"
 47999              }
 48000            },
 48001            {
 48002              "license": {
 48003                "id": "LGPL-2.0-or-later"
 48004              }
 48005            },
 48006            {
 48007              "license": {
 48008                "id": "LGPL-2.1-or-later"
 48009              }
 48010            },
 48011            {
 48012              "license": {
 48013                "name": "other"
 48014              }
 48015            },
 48016            {
 48017              "license": {
 48018                "name": "public-domain"
 48019              }
 48020            }
 48021          ],
 48022          "cpe": "cpe:2.3:a:libhogweed5:libhogweed5:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
 48023          "purl": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
 48024          "swid": {
 48025            "attachment": {}
 48026          },
 48027          "pedigree": {},
 48028          "evidence": {},
 48029          "signature": {
 48030            "signature": {
 48031              "publicKey": {}
 48032            }
 48033          },
 48034          "modelCard": {
 48035            "modelParameters": {
 48036              "approach": {}
 48037            },
 48038            "quantitativeAnalysis": {
 48039              "graphics": {}
 48040            },
 48041            "considerations": {}
 48042          }
 48043        },
 48044        {
 48045          "type": "library",
 48046          "bom-ref": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=3b0bac5e4e8f23c5",
 48047          "supplier": {},
 48048          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48049          "name": "libhx509-5-heimdal",
 48050          "version": "7.7.0+dfsg-1ubuntu1",
 48051          "licenses": [
 48052            {
 48053              "license": {
 48054                "id": "BSD-3-Clause"
 48055              }
 48056            },
 48057            {
 48058              "license": {
 48059                "id": "GPL-2.0-only"
 48060              }
 48061            },
 48062            {
 48063              "license": {
 48064                "id": "GPL-2.0-or-later"
 48065              }
 48066            },
 48067            {
 48068              "license": {
 48069                "name": "custom"
 48070              }
 48071            }
 48072          ],
 48073          "cpe": "cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 48074          "purl": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 48075          "swid": {
 48076            "attachment": {}
 48077          },
 48078          "pedigree": {},
 48079          "evidence": {},
 48080          "signature": {
 48081            "signature": {
 48082              "publicKey": {}
 48083            }
 48084          },
 48085          "modelCard": {
 48086            "modelParameters": {
 48087              "approach": {}
 48088            },
 48089            "quantitativeAnalysis": {
 48090              "graphics": {}
 48091            },
 48092            "considerations": {}
 48093          }
 48094        },
 48095        {
 48096          "type": "library",
 48097          "bom-ref": "pkg:deb/ubuntu/libibverbs1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04\u0026package-id=8a574b9c0296728e",
 48098          "supplier": {},
 48099          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48100          "name": "libibverbs1",
 48101          "version": "28.0-1ubuntu1",
 48102          "licenses": [
 48103            {
 48104              "license": {
 48105                "id": "BSD-2-Clause"
 48106              }
 48107            },
 48108            {
 48109              "license": {
 48110                "id": "BSD-3-Clause"
 48111              }
 48112            },
 48113            {
 48114              "license": {
 48115                "name": "BSD-MIT"
 48116              }
 48117            },
 48118            {
 48119              "license": {
 48120                "name": "CC0"
 48121              }
 48122            },
 48123            {
 48124              "license": {
 48125                "id": "CPL-1.0"
 48126              }
 48127            },
 48128            {
 48129              "license": {
 48130                "id": "GPL-2.0-only"
 48131              }
 48132            },
 48133            {
 48134              "license": {
 48135                "id": "GPL-2.0-or-later"
 48136              }
 48137            },
 48138            {
 48139              "license": {
 48140                "id": "MIT"
 48141              }
 48142            }
 48143          ],
 48144          "cpe": "cpe:2.3:a:libibverbs1:libibverbs1:28.0-1ubuntu1:*:*:*:*:*:*:*",
 48145          "purl": "pkg:deb/ubuntu/libibverbs1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04",
 48146          "swid": {
 48147            "attachment": {}
 48148          },
 48149          "pedigree": {},
 48150          "evidence": {},
 48151          "signature": {
 48152            "signature": {
 48153              "publicKey": {}
 48154            }
 48155          },
 48156          "modelCard": {
 48157            "modelParameters": {
 48158              "approach": {}
 48159            },
 48160            "quantitativeAnalysis": {
 48161              "graphics": {}
 48162            },
 48163            "considerations": {}
 48164          }
 48165        },
 48166        {
 48167          "type": "library",
 48168          "bom-ref": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2.1?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04\u0026package-id=8bc4cbf07b67515",
 48169          "supplier": {},
 48170          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48171          "name": "libicu66",
 48172          "version": "66.1-2ubuntu2.1",
 48173          "cpe": "cpe:2.3:a:libicu66:libicu66:66.1-2ubuntu2.1:*:*:*:*:*:*:*",
 48174          "purl": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2.1?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04",
 48175          "swid": {
 48176            "attachment": {}
 48177          },
 48178          "pedigree": {},
 48179          "evidence": {},
 48180          "signature": {
 48181            "signature": {
 48182              "publicKey": {}
 48183            }
 48184          },
 48185          "modelCard": {
 48186            "modelParameters": {
 48187              "approach": {}
 48188            },
 48189            "quantitativeAnalysis": {
 48190              "graphics": {}
 48191            },
 48192            "considerations": {}
 48193          }
 48194        },
 48195        {
 48196          "type": "library",
 48197          "bom-ref": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04\u0026package-id=d2a82c3e28413bc1",
 48198          "supplier": {},
 48199          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48200          "name": "libidn2-0",
 48201          "version": "2.2.0-2",
 48202          "licenses": [
 48203            {
 48204              "license": {
 48205                "id": "GPL-2.0-only"
 48206              }
 48207            },
 48208            {
 48209              "license": {
 48210                "id": "GPL-2.0-or-later"
 48211              }
 48212            },
 48213            {
 48214              "license": {
 48215                "id": "GPL-3.0-only"
 48216              }
 48217            },
 48218            {
 48219              "license": {
 48220                "id": "GPL-3.0-or-later"
 48221              }
 48222            },
 48223            {
 48224              "license": {
 48225                "id": "LGPL-3.0-only"
 48226              }
 48227            },
 48228            {
 48229              "license": {
 48230                "id": "LGPL-3.0-or-later"
 48231              }
 48232            },
 48233            {
 48234              "license": {
 48235                "name": "Unicode"
 48236              }
 48237            }
 48238          ],
 48239          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.2.0-2:*:*:*:*:*:*:*",
 48240          "purl": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04",
 48241          "swid": {
 48242            "attachment": {}
 48243          },
 48244          "pedigree": {},
 48245          "evidence": {},
 48246          "signature": {
 48247            "signature": {
 48248              "publicKey": {}
 48249            }
 48250          },
 48251          "modelCard": {
 48252            "modelParameters": {
 48253              "approach": {}
 48254            },
 48255            "quantitativeAnalysis": {
 48256              "graphics": {}
 48257            },
 48258            "considerations": {}
 48259          }
 48260        },
 48261        {
 48262          "type": "library",
 48263          "bom-ref": "pkg:deb/ubuntu/libiscsi7@1.18.0-2?arch=amd64\u0026upstream=libiscsi\u0026distro=ubuntu-20.04\u0026package-id=d3404aeee287695b",
 48264          "supplier": {},
 48265          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48266          "name": "libiscsi7",
 48267          "version": "1.18.0-2",
 48268          "licenses": [
 48269            {
 48270              "license": {
 48271                "id": "GPL-2.0-only"
 48272              }
 48273            },
 48274            {
 48275              "license": {
 48276                "id": "GPL-2.0-or-later"
 48277              }
 48278            },
 48279            {
 48280              "license": {
 48281                "id": "GPL-3.0-only"
 48282              }
 48283            },
 48284            {
 48285              "license": {
 48286                "id": "GPL-3.0-or-later"
 48287              }
 48288            },
 48289            {
 48290              "license": {
 48291                "id": "LGPL-2.1-only"
 48292              }
 48293            },
 48294            {
 48295              "license": {
 48296                "id": "LGPL-2.1-or-later"
 48297              }
 48298            },
 48299            {
 48300              "license": {
 48301                "name": "MIT/X11"
 48302              }
 48303            },
 48304            {
 48305              "license": {
 48306                "name": "Public_domain"
 48307              }
 48308            }
 48309          ],
 48310          "cpe": "cpe:2.3:a:libiscsi7:libiscsi7:1.18.0-2:*:*:*:*:*:*:*",
 48311          "purl": "pkg:deb/ubuntu/libiscsi7@1.18.0-2?arch=amd64\u0026upstream=libiscsi\u0026distro=ubuntu-20.04",
 48312          "swid": {
 48313            "attachment": {}
 48314          },
 48315          "pedigree": {},
 48316          "evidence": {},
 48317          "signature": {
 48318            "signature": {
 48319              "publicKey": {}
 48320            }
 48321          },
 48322          "modelCard": {
 48323            "modelParameters": {
 48324              "approach": {}
 48325            },
 48326            "quantitativeAnalysis": {
 48327              "graphics": {}
 48328            },
 48329            "considerations": {}
 48330          }
 48331        },
 48332        {
 48333          "type": "library",
 48334          "bom-ref": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=f9479050b59432b4",
 48335          "supplier": {},
 48336          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48337          "name": "libk5crypto3",
 48338          "version": "1.17-6ubuntu4.1",
 48339          "licenses": [
 48340            {
 48341              "license": {
 48342                "id": "GPL-2.0-only"
 48343              }
 48344            }
 48345          ],
 48346          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 48347          "purl": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 48348          "swid": {
 48349            "attachment": {}
 48350          },
 48351          "pedigree": {},
 48352          "evidence": {},
 48353          "signature": {
 48354            "signature": {
 48355              "publicKey": {}
 48356            }
 48357          },
 48358          "modelCard": {
 48359            "modelParameters": {
 48360              "approach": {}
 48361            },
 48362            "quantitativeAnalysis": {
 48363              "graphics": {}
 48364            },
 48365            "considerations": {}
 48366          }
 48367        },
 48368        {
 48369          "type": "library",
 48370          "bom-ref": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04\u0026package-id=e8692427b123ea73",
 48371          "supplier": {},
 48372          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48373          "name": "libkeyutils1",
 48374          "version": "1.6-6ubuntu1",
 48375          "licenses": [
 48376            {
 48377              "license": {
 48378                "id": "GPL-2.0-only"
 48379              }
 48380            },
 48381            {
 48382              "license": {
 48383                "id": "GPL-2.0-or-later"
 48384              }
 48385            },
 48386            {
 48387              "license": {
 48388                "id": "LGPL-2.0-only"
 48389              }
 48390            },
 48391            {
 48392              "license": {
 48393                "id": "LGPL-2.0-or-later"
 48394              }
 48395            }
 48396          ],
 48397          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6-6ubuntu1:*:*:*:*:*:*:*",
 48398          "purl": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04",
 48399          "swid": {
 48400            "attachment": {}
 48401          },
 48402          "pedigree": {},
 48403          "evidence": {},
 48404          "signature": {
 48405            "signature": {
 48406              "publicKey": {}
 48407            }
 48408          },
 48409          "modelCard": {
 48410            "modelParameters": {
 48411              "approach": {}
 48412            },
 48413            "quantitativeAnalysis": {
 48414              "graphics": {}
 48415            },
 48416            "considerations": {}
 48417          }
 48418        },
 48419        {
 48420          "type": "library",
 48421          "bom-ref": "pkg:deb/ubuntu/libkmod2@27-1ubuntu2?arch=amd64\u0026upstream=kmod\u0026distro=ubuntu-20.04\u0026package-id=9de5f0614e60f8ee",
 48422          "supplier": {},
 48423          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48424          "name": "libkmod2",
 48425          "version": "27-1ubuntu2",
 48426          "licenses": [
 48427            {
 48428              "license": {
 48429                "id": "GPL-2.0-only"
 48430              }
 48431            }
 48432          ],
 48433          "cpe": "cpe:2.3:a:libkmod2:libkmod2:27-1ubuntu2:*:*:*:*:*:*:*",
 48434          "purl": "pkg:deb/ubuntu/libkmod2@27-1ubuntu2?arch=amd64\u0026upstream=kmod\u0026distro=ubuntu-20.04",
 48435          "swid": {
 48436            "attachment": {}
 48437          },
 48438          "pedigree": {},
 48439          "evidence": {},
 48440          "signature": {
 48441            "signature": {
 48442              "publicKey": {}
 48443            }
 48444          },
 48445          "modelCard": {
 48446            "modelParameters": {
 48447              "approach": {}
 48448            },
 48449            "quantitativeAnalysis": {
 48450              "graphics": {}
 48451            },
 48452            "considerations": {}
 48453          }
 48454        },
 48455        {
 48456          "type": "library",
 48457          "bom-ref": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=2beb670b9378498e",
 48458          "supplier": {},
 48459          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48460          "name": "libkrb5-26-heimdal",
 48461          "version": "7.7.0+dfsg-1ubuntu1",
 48462          "licenses": [
 48463            {
 48464              "license": {
 48465                "id": "BSD-3-Clause"
 48466              }
 48467            },
 48468            {
 48469              "license": {
 48470                "id": "GPL-2.0-only"
 48471              }
 48472            },
 48473            {
 48474              "license": {
 48475                "id": "GPL-2.0-or-later"
 48476              }
 48477            },
 48478            {
 48479              "license": {
 48480                "name": "custom"
 48481              }
 48482            }
 48483          ],
 48484          "cpe": "cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 48485          "purl": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 48486          "swid": {
 48487            "attachment": {}
 48488          },
 48489          "pedigree": {},
 48490          "evidence": {},
 48491          "signature": {
 48492            "signature": {
 48493              "publicKey": {}
 48494            }
 48495          },
 48496          "modelCard": {
 48497            "modelParameters": {
 48498              "approach": {}
 48499            },
 48500            "quantitativeAnalysis": {
 48501              "graphics": {}
 48502            },
 48503            "considerations": {}
 48504          }
 48505        },
 48506        {
 48507          "type": "library",
 48508          "bom-ref": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=fdb5970d8394a182",
 48509          "supplier": {},
 48510          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48511          "name": "libkrb5-3",
 48512          "version": "1.17-6ubuntu4.1",
 48513          "licenses": [
 48514            {
 48515              "license": {
 48516                "id": "GPL-2.0-only"
 48517              }
 48518            }
 48519          ],
 48520          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 48521          "purl": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 48522          "swid": {
 48523            "attachment": {}
 48524          },
 48525          "pedigree": {},
 48526          "evidence": {},
 48527          "signature": {
 48528            "signature": {
 48529              "publicKey": {}
 48530            }
 48531          },
 48532          "modelCard": {
 48533            "modelParameters": {
 48534              "approach": {}
 48535            },
 48536            "quantitativeAnalysis": {
 48537              "graphics": {}
 48538            },
 48539            "considerations": {}
 48540          }
 48541        },
 48542        {
 48543          "type": "library",
 48544          "bom-ref": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=a8d21a32e178b211",
 48545          "supplier": {},
 48546          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48547          "name": "libkrb5support0",
 48548          "version": "1.17-6ubuntu4.1",
 48549          "licenses": [
 48550            {
 48551              "license": {
 48552                "id": "GPL-2.0-only"
 48553              }
 48554            }
 48555          ],
 48556          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 48557          "purl": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 48558          "swid": {
 48559            "attachment": {}
 48560          },
 48561          "pedigree": {},
 48562          "evidence": {},
 48563          "signature": {
 48564            "signature": {
 48565              "publicKey": {}
 48566            }
 48567          },
 48568          "modelCard": {
 48569            "modelParameters": {
 48570              "approach": {}
 48571            },
 48572            "quantitativeAnalysis": {
 48573              "graphics": {}
 48574            },
 48575            "considerations": {}
 48576          }
 48577        },
 48578        {
 48579          "type": "library",
 48580          "bom-ref": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=efdc80a7ae6eae19",
 48581          "supplier": {},
 48582          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48583          "name": "libldap-2.4-2",
 48584          "version": "2.4.49+dfsg-2ubuntu1.8",
 48585          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
 48586          "purl": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04",
 48587          "swid": {
 48588            "attachment": {}
 48589          },
 48590          "pedigree": {},
 48591          "evidence": {},
 48592          "signature": {
 48593            "signature": {
 48594              "publicKey": {}
 48595            }
 48596          },
 48597          "modelCard": {
 48598            "modelParameters": {
 48599              "approach": {}
 48600            },
 48601            "quantitativeAnalysis": {
 48602              "graphics": {}
 48603            },
 48604            "considerations": {}
 48605          }
 48606        },
 48607        {
 48608          "type": "library",
 48609          "bom-ref": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=4d0b88f98b40786b",
 48610          "supplier": {},
 48611          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48612          "name": "libldap-common",
 48613          "version": "2.4.49+dfsg-2ubuntu1.8",
 48614          "cpe": "cpe:2.3:a:libldap-common:libldap-common:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
 48615          "purl": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04",
 48616          "swid": {
 48617            "attachment": {}
 48618          },
 48619          "pedigree": {},
 48620          "evidence": {},
 48621          "signature": {
 48622            "signature": {
 48623              "publicKey": {}
 48624            }
 48625          },
 48626          "modelCard": {
 48627            "modelParameters": {
 48628              "approach": {}
 48629            },
 48630            "quantitativeAnalysis": {
 48631              "graphics": {}
 48632            },
 48633            "considerations": {}
 48634          }
 48635        },
 48636        {
 48637          "type": "library",
 48638          "bom-ref": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04\u0026package-id=6f2c431caeb4980a",
 48639          "supplier": {},
 48640          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48641          "name": "liblz4-1",
 48642          "version": "1.9.2-2ubuntu0.20.04.1",
 48643          "licenses": [
 48644            {
 48645              "license": {
 48646                "id": "BSD-2-Clause"
 48647              }
 48648            },
 48649            {
 48650              "license": {
 48651                "id": "GPL-2.0-only"
 48652              }
 48653            },
 48654            {
 48655              "license": {
 48656                "id": "GPL-2.0-or-later"
 48657              }
 48658            }
 48659          ],
 48660          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.2-2ubuntu0.20.04.1:*:*:*:*:*:*:*",
 48661          "purl": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04",
 48662          "swid": {
 48663            "attachment": {}
 48664          },
 48665          "pedigree": {},
 48666          "evidence": {},
 48667          "signature": {
 48668            "signature": {
 48669              "publicKey": {}
 48670            }
 48671          },
 48672          "modelCard": {
 48673            "modelParameters": {
 48674              "approach": {}
 48675            },
 48676            "quantitativeAnalysis": {
 48677              "graphics": {}
 48678            },
 48679            "considerations": {}
 48680          }
 48681        },
 48682        {
 48683          "type": "library",
 48684          "bom-ref": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04\u0026package-id=f1e9f3b6205a664a",
 48685          "supplier": {},
 48686          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48687          "name": "liblzma5",
 48688          "version": "5.2.4-1ubuntu1",
 48689          "licenses": [
 48690            {
 48691              "license": {
 48692                "name": "Autoconf"
 48693              }
 48694            },
 48695            {
 48696              "license": {
 48697                "id": "GPL-2.0-only"
 48698              }
 48699            },
 48700            {
 48701              "license": {
 48702                "id": "GPL-2.0-or-later"
 48703              }
 48704            },
 48705            {
 48706              "license": {
 48707                "id": "GPL-3.0-only"
 48708              }
 48709            },
 48710            {
 48711              "license": {
 48712                "id": "LGPL-2.0-only"
 48713              }
 48714            },
 48715            {
 48716              "license": {
 48717                "id": "LGPL-2.1-only"
 48718              }
 48719            },
 48720            {
 48721              "license": {
 48722                "id": "LGPL-2.1-or-later"
 48723              }
 48724            },
 48725            {
 48726              "license": {
 48727                "name": "PD"
 48728              }
 48729            },
 48730            {
 48731              "license": {
 48732                "name": "PD-debian"
 48733              }
 48734            },
 48735            {
 48736              "license": {
 48737                "name": "config-h"
 48738              }
 48739            },
 48740            {
 48741              "license": {
 48742                "name": "noderivs"
 48743              }
 48744            },
 48745            {
 48746              "license": {
 48747                "name": "permissive-fsf"
 48748              }
 48749            },
 48750            {
 48751              "license": {
 48752                "name": "permissive-nowarranty"
 48753              }
 48754            },
 48755            {
 48756              "license": {
 48757                "name": "probably-PD"
 48758              }
 48759            }
 48760          ],
 48761          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
 48762          "purl": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04",
 48763          "swid": {
 48764            "attachment": {}
 48765          },
 48766          "pedigree": {},
 48767          "evidence": {},
 48768          "signature": {
 48769            "signature": {
 48770              "publicKey": {}
 48771            }
 48772          },
 48773          "modelCard": {
 48774            "modelParameters": {
 48775              "approach": {}
 48776            },
 48777            "quantitativeAnalysis": {
 48778              "graphics": {}
 48779            },
 48780            "considerations": {}
 48781          }
 48782        },
 48783        {
 48784          "type": "library",
 48785          "bom-ref": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=3b4f02792ccf99bb",
 48786          "supplier": {},
 48787          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48788          "name": "libmagic-mgc",
 48789          "version": "1:5.38-4",
 48790          "licenses": [
 48791            {
 48792              "license": {
 48793                "name": "BSD-2-Clause-alike"
 48794              }
 48795            },
 48796            {
 48797              "license": {
 48798                "id": "BSD-2-Clause"
 48799              }
 48800            },
 48801            {
 48802              "license": {
 48803                "name": "BSD-2-Clause-regents"
 48804              }
 48805            },
 48806            {
 48807              "license": {
 48808                "name": "MIT-Old-Style-with-legal-disclaimer-2"
 48809              }
 48810            },
 48811            {
 48812              "license": {
 48813                "name": "public-domain"
 48814              }
 48815            }
 48816          ],
 48817          "cpe": "cpe:2.3:a:libmagic-mgc:libmagic-mgc:1\\:5.38-4:*:*:*:*:*:*:*",
 48818          "purl": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
 48819          "swid": {
 48820            "attachment": {}
 48821          },
 48822          "pedigree": {},
 48823          "evidence": {},
 48824          "signature": {
 48825            "signature": {
 48826              "publicKey": {}
 48827            }
 48828          },
 48829          "modelCard": {
 48830            "modelParameters": {
 48831              "approach": {}
 48832            },
 48833            "quantitativeAnalysis": {
 48834              "graphics": {}
 48835            },
 48836            "considerations": {}
 48837          }
 48838        },
 48839        {
 48840          "type": "library",
 48841          "bom-ref": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=302b8497a938556",
 48842          "supplier": {},
 48843          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48844          "name": "libmagic1",
 48845          "version": "1:5.38-4",
 48846          "licenses": [
 48847            {
 48848              "license": {
 48849                "name": "BSD-2-Clause-alike"
 48850              }
 48851            },
 48852            {
 48853              "license": {
 48854                "id": "BSD-2-Clause"
 48855              }
 48856            },
 48857            {
 48858              "license": {
 48859                "name": "BSD-2-Clause-regents"
 48860              }
 48861            },
 48862            {
 48863              "license": {
 48864                "name": "MIT-Old-Style-with-legal-disclaimer-2"
 48865              }
 48866            },
 48867            {
 48868              "license": {
 48869                "name": "public-domain"
 48870              }
 48871            }
 48872          ],
 48873          "cpe": "cpe:2.3:a:libmagic1:libmagic1:1\\:5.38-4:*:*:*:*:*:*:*",
 48874          "purl": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
 48875          "swid": {
 48876            "attachment": {}
 48877          },
 48878          "pedigree": {},
 48879          "evidence": {},
 48880          "signature": {
 48881            "signature": {
 48882              "publicKey": {}
 48883            }
 48884          },
 48885          "modelCard": {
 48886            "modelParameters": {
 48887              "approach": {}
 48888            },
 48889            "quantitativeAnalysis": {
 48890              "graphics": {}
 48891            },
 48892            "considerations": {}
 48893          }
 48894        },
 48895        {
 48896          "type": "library",
 48897          "bom-ref": "pkg:deb/ubuntu/libmnl0@1.0.4-2?arch=amd64\u0026upstream=libmnl\u0026distro=ubuntu-20.04\u0026package-id=162cfe25074edf0d",
 48898          "supplier": {},
 48899          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48900          "name": "libmnl0",
 48901          "version": "1.0.4-2",
 48902          "licenses": [
 48903            {
 48904              "license": {
 48905                "id": "GPL-2.0-only"
 48906              }
 48907            },
 48908            {
 48909              "license": {
 48910                "id": "GPL-2.0-or-later"
 48911              }
 48912            },
 48913            {
 48914              "license": {
 48915                "id": "LGPL-2.1-only"
 48916              }
 48917            }
 48918          ],
 48919          "cpe": "cpe:2.3:a:libmnl0:libmnl0:1.0.4-2:*:*:*:*:*:*:*",
 48920          "purl": "pkg:deb/ubuntu/libmnl0@1.0.4-2?arch=amd64\u0026upstream=libmnl\u0026distro=ubuntu-20.04",
 48921          "swid": {
 48922            "attachment": {}
 48923          },
 48924          "pedigree": {},
 48925          "evidence": {},
 48926          "signature": {
 48927            "signature": {
 48928              "publicKey": {}
 48929            }
 48930          },
 48931          "modelCard": {
 48932            "modelParameters": {
 48933              "approach": {}
 48934            },
 48935            "quantitativeAnalysis": {
 48936              "graphics": {}
 48937            },
 48938            "considerations": {}
 48939          }
 48940        },
 48941        {
 48942          "type": "library",
 48943          "bom-ref": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=39446194385ebce5",
 48944          "supplier": {},
 48945          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 48946          "name": "libmount1",
 48947          "version": "2.34-0.1ubuntu9.1",
 48948          "licenses": [
 48949            {
 48950              "license": {
 48951                "id": "BSD-2-Clause"
 48952              }
 48953            },
 48954            {
 48955              "license": {
 48956                "id": "BSD-3-Clause"
 48957              }
 48958            },
 48959            {
 48960              "license": {
 48961                "id": "BSD-4-Clause"
 48962              }
 48963            },
 48964            {
 48965              "license": {
 48966                "id": "GPL-2.0-only"
 48967              }
 48968            },
 48969            {
 48970              "license": {
 48971                "id": "GPL-2.0-or-later"
 48972              }
 48973            },
 48974            {
 48975              "license": {
 48976                "id": "GPL-3.0-only"
 48977              }
 48978            },
 48979            {
 48980              "license": {
 48981                "id": "GPL-3.0-or-later"
 48982              }
 48983            },
 48984            {
 48985              "license": {
 48986                "name": "LGPL"
 48987              }
 48988            },
 48989            {
 48990              "license": {
 48991                "id": "LGPL-2.0-only"
 48992              }
 48993            },
 48994            {
 48995              "license": {
 48996                "id": "LGPL-2.0-or-later"
 48997              }
 48998            },
 48999            {
 49000              "license": {
 49001                "id": "LGPL-2.1-only"
 49002              }
 49003            },
 49004            {
 49005              "license": {
 49006                "id": "LGPL-2.1-or-later"
 49007              }
 49008            },
 49009            {
 49010              "license": {
 49011                "id": "LGPL-3.0-only"
 49012              }
 49013            },
 49014            {
 49015              "license": {
 49016                "id": "LGPL-3.0-or-later"
 49017              }
 49018            },
 49019            {
 49020              "license": {
 49021                "id": "MIT"
 49022              }
 49023            },
 49024            {
 49025              "license": {
 49026                "name": "public-domain"
 49027              }
 49028            }
 49029          ],
 49030          "cpe": "cpe:2.3:a:libmount1:libmount1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 49031          "purl": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 49032          "swid": {
 49033            "attachment": {}
 49034          },
 49035          "pedigree": {},
 49036          "evidence": {},
 49037          "signature": {
 49038            "signature": {
 49039              "publicKey": {}
 49040            }
 49041          },
 49042          "modelCard": {
 49043            "modelParameters": {
 49044              "approach": {}
 49045            },
 49046            "quantitativeAnalysis": {
 49047              "graphics": {}
 49048            },
 49049            "considerations": {}
 49050          }
 49051        },
 49052        {
 49053          "type": "library",
 49054          "bom-ref": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04\u0026package-id=b45a0d57576ce262",
 49055          "supplier": {},
 49056          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49057          "name": "libmpdec2",
 49058          "version": "2.4.2-3",
 49059          "licenses": [
 49060            {
 49061              "license": {
 49062                "name": "BSD"
 49063              }
 49064            },
 49065            {
 49066              "license": {
 49067                "id": "GPL-2.0-only"
 49068              }
 49069            },
 49070            {
 49071              "license": {
 49072                "id": "GPL-2.0-or-later"
 49073              }
 49074            }
 49075          ],
 49076          "cpe": "cpe:2.3:a:libmpdec2:libmpdec2:2.4.2-3:*:*:*:*:*:*:*",
 49077          "purl": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04",
 49078          "swid": {
 49079            "attachment": {}
 49080          },
 49081          "pedigree": {},
 49082          "evidence": {},
 49083          "signature": {
 49084            "signature": {
 49085              "publicKey": {}
 49086            }
 49087          },
 49088          "modelCard": {
 49089            "modelParameters": {
 49090              "approach": {}
 49091            },
 49092            "quantitativeAnalysis": {
 49093              "graphics": {}
 49094            },
 49095            "considerations": {}
 49096          }
 49097        },
 49098        {
 49099          "type": "library",
 49100          "bom-ref": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=ed8fb166163a75b8",
 49101          "supplier": {},
 49102          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49103          "name": "libncurses6",
 49104          "version": "6.2-0ubuntu2",
 49105          "cpe": "cpe:2.3:a:libncurses6:libncurses6:6.2-0ubuntu2:*:*:*:*:*:*:*",
 49106          "purl": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 49107          "swid": {
 49108            "attachment": {}
 49109          },
 49110          "pedigree": {},
 49111          "evidence": {},
 49112          "signature": {
 49113            "signature": {
 49114              "publicKey": {}
 49115            }
 49116          },
 49117          "modelCard": {
 49118            "modelParameters": {
 49119              "approach": {}
 49120            },
 49121            "quantitativeAnalysis": {
 49122              "graphics": {}
 49123            },
 49124            "considerations": {}
 49125          }
 49126        },
 49127        {
 49128          "type": "library",
 49129          "bom-ref": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=58525ddc073a008a",
 49130          "supplier": {},
 49131          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49132          "name": "libncursesw6",
 49133          "version": "6.2-0ubuntu2",
 49134          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.2-0ubuntu2:*:*:*:*:*:*:*",
 49135          "purl": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 49136          "swid": {
 49137            "attachment": {}
 49138          },
 49139          "pedigree": {},
 49140          "evidence": {},
 49141          "signature": {
 49142            "signature": {
 49143              "publicKey": {}
 49144            }
 49145          },
 49146          "modelCard": {
 49147            "modelParameters": {
 49148              "approach": {}
 49149            },
 49150            "quantitativeAnalysis": {
 49151              "graphics": {}
 49152            },
 49153            "considerations": {}
 49154          }
 49155        },
 49156        {
 49157          "type": "library",
 49158          "bom-ref": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3d185fbd6a7e56f",
 49159          "supplier": {},
 49160          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49161          "name": "libnettle7",
 49162          "version": "3.5.1+really3.5.1-2ubuntu0.2",
 49163          "licenses": [
 49164            {
 49165              "license": {
 49166                "name": "GAP"
 49167              }
 49168            },
 49169            {
 49170              "license": {
 49171                "name": "GPL"
 49172              }
 49173            },
 49174            {
 49175              "license": {
 49176                "id": "GPL-2.0-only"
 49177              }
 49178            },
 49179            {
 49180              "license": {
 49181                "id": "GPL-2.0-or-later"
 49182              }
 49183            },
 49184            {
 49185              "license": {
 49186                "name": "LGPL"
 49187              }
 49188            },
 49189            {
 49190              "license": {
 49191                "id": "LGPL-2.0-only"
 49192              }
 49193            },
 49194            {
 49195              "license": {
 49196                "id": "LGPL-2.0-or-later"
 49197              }
 49198            },
 49199            {
 49200              "license": {
 49201                "id": "LGPL-2.1-or-later"
 49202              }
 49203            },
 49204            {
 49205              "license": {
 49206                "name": "other"
 49207              }
 49208            },
 49209            {
 49210              "license": {
 49211                "name": "public-domain"
 49212              }
 49213            }
 49214          ],
 49215          "cpe": "cpe:2.3:a:libnettle7:libnettle7:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
 49216          "purl": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
 49217          "swid": {
 49218            "attachment": {}
 49219          },
 49220          "pedigree": {},
 49221          "evidence": {},
 49222          "signature": {
 49223            "signature": {
 49224              "publicKey": {}
 49225            }
 49226          },
 49227          "modelCard": {
 49228            "modelParameters": {
 49229              "approach": {}
 49230            },
 49231            "quantitativeAnalysis": {
 49232              "graphics": {}
 49233            },
 49234            "considerations": {}
 49235          }
 49236        },
 49237        {
 49238          "type": "library",
 49239          "bom-ref": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04\u0026package-id=71bd574c47c02b75",
 49240          "supplier": {},
 49241          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49242          "name": "libnfsidmap2",
 49243          "version": "0.25-5.1ubuntu1",
 49244          "cpe": "cpe:2.3:a:libnfsidmap2:libnfsidmap2:0.25-5.1ubuntu1:*:*:*:*:*:*:*",
 49245          "purl": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04",
 49246          "swid": {
 49247            "attachment": {}
 49248          },
 49249          "pedigree": {},
 49250          "evidence": {},
 49251          "signature": {
 49252            "signature": {
 49253              "publicKey": {}
 49254            }
 49255          },
 49256          "modelCard": {
 49257            "modelParameters": {
 49258              "approach": {}
 49259            },
 49260            "quantitativeAnalysis": {
 49261              "graphics": {}
 49262            },
 49263            "considerations": {}
 49264          }
 49265        },
 49266        {
 49267          "type": "library",
 49268          "bom-ref": "pkg:deb/ubuntu/libnghttp2-14@1.40.0-1build1?arch=amd64\u0026upstream=nghttp2\u0026distro=ubuntu-20.04\u0026package-id=c86604c1fa72dd96",
 49269          "supplier": {},
 49270          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49271          "name": "libnghttp2-14",
 49272          "version": "1.40.0-1build1",
 49273          "licenses": [
 49274            {
 49275              "license": {
 49276                "id": "BSD-2-Clause"
 49277              }
 49278            },
 49279            {
 49280              "license": {
 49281                "name": "Expat"
 49282              }
 49283            },
 49284            {
 49285              "license": {
 49286                "id": "GPL-3.0-only"
 49287              }
 49288            },
 49289            {
 49290              "license": {
 49291                "id": "GPL-3.0-or-later"
 49292              }
 49293            },
 49294            {
 49295              "license": {
 49296                "id": "MIT"
 49297              }
 49298            },
 49299            {
 49300              "license": {
 49301                "name": "SIL-OFL-1.1"
 49302              }
 49303            },
 49304            {
 49305              "license": {
 49306                "name": "all-permissive"
 49307              }
 49308            }
 49309          ],
 49310          "cpe": "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.40.0-1build1:*:*:*:*:*:*:*",
 49311          "purl": "pkg:deb/ubuntu/libnghttp2-14@1.40.0-1build1?arch=amd64\u0026upstream=nghttp2\u0026distro=ubuntu-20.04",
 49312          "swid": {
 49313            "attachment": {}
 49314          },
 49315          "pedigree": {},
 49316          "evidence": {},
 49317          "signature": {
 49318            "signature": {
 49319              "publicKey": {}
 49320            }
 49321          },
 49322          "modelCard": {
 49323            "modelParameters": {
 49324              "approach": {}
 49325            },
 49326            "quantitativeAnalysis": {
 49327              "graphics": {}
 49328            },
 49329            "considerations": {}
 49330          }
 49331        },
 49332        {
 49333          "type": "library",
 49334          "bom-ref": "pkg:deb/ubuntu/libnl-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04\u0026package-id=520a765636f2f20f",
 49335          "supplier": {},
 49336          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49337          "name": "libnl-3-200",
 49338          "version": "3.4.0-1",
 49339          "licenses": [
 49340            {
 49341              "license": {
 49342                "id": "GPL-2.0-only"
 49343              }
 49344            },
 49345            {
 49346              "license": {
 49347                "id": "LGPL-2.1-only"
 49348              }
 49349            }
 49350          ],
 49351          "cpe": "cpe:2.3:a:libnl-3-200:libnl-3-200:3.4.0-1:*:*:*:*:*:*:*",
 49352          "purl": "pkg:deb/ubuntu/libnl-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04",
 49353          "swid": {
 49354            "attachment": {}
 49355          },
 49356          "pedigree": {},
 49357          "evidence": {},
 49358          "signature": {
 49359            "signature": {
 49360              "publicKey": {}
 49361            }
 49362          },
 49363          "modelCard": {
 49364            "modelParameters": {
 49365              "approach": {}
 49366            },
 49367            "quantitativeAnalysis": {
 49368              "graphics": {}
 49369            },
 49370            "considerations": {}
 49371          }
 49372        },
 49373        {
 49374          "type": "library",
 49375          "bom-ref": "pkg:deb/ubuntu/libnl-route-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04\u0026package-id=1a1d9f0f1f34e88b",
 49376          "supplier": {},
 49377          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49378          "name": "libnl-route-3-200",
 49379          "version": "3.4.0-1",
 49380          "licenses": [
 49381            {
 49382              "license": {
 49383                "id": "GPL-2.0-only"
 49384              }
 49385            },
 49386            {
 49387              "license": {
 49388                "id": "LGPL-2.1-only"
 49389              }
 49390            }
 49391          ],
 49392          "cpe": "cpe:2.3:a:libnl-route-3-200:libnl-route-3-200:3.4.0-1:*:*:*:*:*:*:*",
 49393          "purl": "pkg:deb/ubuntu/libnl-route-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04",
 49394          "swid": {
 49395            "attachment": {}
 49396          },
 49397          "pedigree": {},
 49398          "evidence": {},
 49399          "signature": {
 49400            "signature": {
 49401              "publicKey": {}
 49402            }
 49403          },
 49404          "modelCard": {
 49405            "modelParameters": {
 49406              "approach": {}
 49407            },
 49408            "quantitativeAnalysis": {
 49409              "graphics": {}
 49410            },
 49411            "considerations": {}
 49412          }
 49413        },
 49414        {
 49415          "type": "library",
 49416          "bom-ref": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04\u0026package-id=9fc0ca46e6d21557",
 49417          "supplier": {},
 49418          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49419          "name": "libp11-kit0",
 49420          "version": "0.23.20-1ubuntu0.1",
 49421          "licenses": [
 49422            {
 49423              "license": {
 49424                "id": "BSD-3-Clause"
 49425              }
 49426            },
 49427            {
 49428              "license": {
 49429                "id": "ISC"
 49430              }
 49431            },
 49432            {
 49433              "license": {
 49434                "name": "ISC+IBM"
 49435              }
 49436            },
 49437            {
 49438              "license": {
 49439                "name": "permissive-like-automake-output"
 49440              }
 49441            },
 49442            {
 49443              "license": {
 49444                "name": "same-as-rest-of-p11kit"
 49445              }
 49446            }
 49447          ],
 49448          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.20-1ubuntu0.1:*:*:*:*:*:*:*",
 49449          "purl": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04",
 49450          "swid": {
 49451            "attachment": {}
 49452          },
 49453          "pedigree": {},
 49454          "evidence": {},
 49455          "signature": {
 49456            "signature": {
 49457              "publicKey": {}
 49458            }
 49459          },
 49460          "modelCard": {
 49461            "modelParameters": {
 49462              "approach": {}
 49463            },
 49464            "quantitativeAnalysis": {
 49465              "graphics": {}
 49466            },
 49467            "considerations": {}
 49468          }
 49469        },
 49470        {
 49471          "type": "library",
 49472          "bom-ref": "pkg:deb/ubuntu/libpam-cap@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04\u0026package-id=20db44acb7f94535",
 49473          "supplier": {},
 49474          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49475          "name": "libpam-cap",
 49476          "version": "1:2.32-1",
 49477          "licenses": [
 49478            {
 49479              "license": {
 49480                "id": "BSD-3-Clause"
 49481              }
 49482            },
 49483            {
 49484              "license": {
 49485                "id": "GPL-2.0-only"
 49486              }
 49487            },
 49488            {
 49489              "license": {
 49490                "id": "GPL-2.0-or-later"
 49491              }
 49492            }
 49493          ],
 49494          "cpe": "cpe:2.3:a:libpam-cap:libpam-cap:1\\:2.32-1:*:*:*:*:*:*:*",
 49495          "purl": "pkg:deb/ubuntu/libpam-cap@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04",
 49496          "swid": {
 49497            "attachment": {}
 49498          },
 49499          "pedigree": {},
 49500          "evidence": {},
 49501          "signature": {
 49502            "signature": {
 49503              "publicKey": {}
 49504            }
 49505          },
 49506          "modelCard": {
 49507            "modelParameters": {
 49508              "approach": {}
 49509            },
 49510            "quantitativeAnalysis": {
 49511              "graphics": {}
 49512            },
 49513            "considerations": {}
 49514          }
 49515        },
 49516        {
 49517          "type": "library",
 49518          "bom-ref": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=563cd7ffd9ad09e2",
 49519          "supplier": {},
 49520          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49521          "name": "libpam-modules",
 49522          "version": "1.3.1-5ubuntu4.3",
 49523          "licenses": [
 49524            {
 49525              "license": {
 49526                "name": "GPL"
 49527              }
 49528            }
 49529          ],
 49530          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.3.1-5ubuntu4.3:*:*:*:*:*:*:*",
 49531          "purl": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
 49532          "swid": {
 49533            "attachment": {}
 49534          },
 49535          "pedigree": {},
 49536          "evidence": {},
 49537          "signature": {
 49538            "signature": {
 49539              "publicKey": {}
 49540            }
 49541          },
 49542          "modelCard": {
 49543            "modelParameters": {
 49544              "approach": {}
 49545            },
 49546            "quantitativeAnalysis": {
 49547              "graphics": {}
 49548            },
 49549            "considerations": {}
 49550          }
 49551        },
 49552        {
 49553          "type": "library",
 49554          "bom-ref": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=2fef7b748bc46246",
 49555          "supplier": {},
 49556          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49557          "name": "libpam-modules-bin",
 49558          "version": "1.3.1-5ubuntu4.3",
 49559          "licenses": [
 49560            {
 49561              "license": {
 49562                "name": "GPL"
 49563              }
 49564            }
 49565          ],
 49566          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.3.1-5ubuntu4.3:*:*:*:*:*:*:*",
 49567          "purl": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
 49568          "swid": {
 49569            "attachment": {}
 49570          },
 49571          "pedigree": {},
 49572          "evidence": {},
 49573          "signature": {
 49574            "signature": {
 49575              "publicKey": {}
 49576            }
 49577          },
 49578          "modelCard": {
 49579            "modelParameters": {
 49580              "approach": {}
 49581            },
 49582            "quantitativeAnalysis": {
 49583              "graphics": {}
 49584            },
 49585            "considerations": {}
 49586          }
 49587        },
 49588        {
 49589          "type": "library",
 49590          "bom-ref": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.3?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=ee86ac677ddf58c5",
 49591          "supplier": {},
 49592          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49593          "name": "libpam-runtime",
 49594          "version": "1.3.1-5ubuntu4.3",
 49595          "licenses": [
 49596            {
 49597              "license": {
 49598                "name": "GPL"
 49599              }
 49600            }
 49601          ],
 49602          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.3.1-5ubuntu4.3:*:*:*:*:*:*:*",
 49603          "purl": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.3?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04",
 49604          "swid": {
 49605            "attachment": {}
 49606          },
 49607          "pedigree": {},
 49608          "evidence": {},
 49609          "signature": {
 49610            "signature": {
 49611              "publicKey": {}
 49612            }
 49613          },
 49614          "modelCard": {
 49615            "modelParameters": {
 49616              "approach": {}
 49617            },
 49618            "quantitativeAnalysis": {
 49619              "graphics": {}
 49620            },
 49621            "considerations": {}
 49622          }
 49623        },
 49624        {
 49625          "type": "library",
 49626          "bom-ref": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=473c40bcd3d2ef2d",
 49627          "supplier": {},
 49628          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49629          "name": "libpam0g",
 49630          "version": "1.3.1-5ubuntu4.3",
 49631          "licenses": [
 49632            {
 49633              "license": {
 49634                "name": "GPL"
 49635              }
 49636            }
 49637          ],
 49638          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.3.1-5ubuntu4.3:*:*:*:*:*:*:*",
 49639          "purl": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
 49640          "swid": {
 49641            "attachment": {}
 49642          },
 49643          "pedigree": {},
 49644          "evidence": {},
 49645          "signature": {
 49646            "signature": {
 49647              "publicKey": {}
 49648            }
 49649          },
 49650          "modelCard": {
 49651            "modelParameters": {
 49652              "approach": {}
 49653            },
 49654            "quantitativeAnalysis": {
 49655              "graphics": {}
 49656            },
 49657            "considerations": {}
 49658          }
 49659        },
 49660        {
 49661          "type": "library",
 49662          "bom-ref": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04\u0026package-id=ec9eb70008ed8b14",
 49663          "supplier": {},
 49664          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49665          "name": "libpcre2-8-0",
 49666          "version": "10.34-7",
 49667          "cpe": "cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.34-7:*:*:*:*:*:*:*",
 49668          "purl": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04",
 49669          "swid": {
 49670            "attachment": {}
 49671          },
 49672          "pedigree": {},
 49673          "evidence": {},
 49674          "signature": {
 49675            "signature": {
 49676              "publicKey": {}
 49677            }
 49678          },
 49679          "modelCard": {
 49680            "modelParameters": {
 49681              "approach": {}
 49682            },
 49683            "quantitativeAnalysis": {
 49684              "graphics": {}
 49685            },
 49686            "considerations": {}
 49687          }
 49688        },
 49689        {
 49690          "type": "library",
 49691          "bom-ref": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04\u0026package-id=f2af8e66c60a624",
 49692          "supplier": {},
 49693          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49694          "name": "libpcre3",
 49695          "version": "2:8.39-12build1",
 49696          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-12build1:*:*:*:*:*:*:*",
 49697          "purl": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04",
 49698          "swid": {
 49699            "attachment": {}
 49700          },
 49701          "pedigree": {},
 49702          "evidence": {},
 49703          "signature": {
 49704            "signature": {
 49705              "publicKey": {}
 49706            }
 49707          },
 49708          "modelCard": {
 49709            "modelParameters": {
 49710              "approach": {}
 49711            },
 49712            "quantitativeAnalysis": {
 49713              "graphics": {}
 49714            },
 49715            "considerations": {}
 49716          }
 49717        },
 49718        {
 49719          "type": "library",
 49720          "bom-ref": "pkg:deb/ubuntu/libperl5.30@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=8748dda005dfdd96",
 49721          "supplier": {},
 49722          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49723          "name": "libperl5.30",
 49724          "version": "5.30.0-9ubuntu0.2",
 49725          "licenses": [
 49726            {
 49727              "license": {
 49728                "name": "Artistic"
 49729              }
 49730            },
 49731            {
 49732              "license": {
 49733                "id": "Artistic-2.0"
 49734              }
 49735            },
 49736            {
 49737              "license": {
 49738                "name": "Artistic-dist"
 49739              }
 49740            },
 49741            {
 49742              "license": {
 49743                "id": "BSD-3-Clause"
 49744              }
 49745            },
 49746            {
 49747              "license": {
 49748                "name": "BSD-3-clause-GENERIC"
 49749              }
 49750            },
 49751            {
 49752              "license": {
 49753                "name": "BSD-3-clause-with-weird-numbering"
 49754              }
 49755            },
 49756            {
 49757              "license": {
 49758                "name": "BSD-4-clause-POWERDOG"
 49759              }
 49760            },
 49761            {
 49762              "license": {
 49763                "name": "BZIP"
 49764              }
 49765            },
 49766            {
 49767              "license": {
 49768                "name": "DONT-CHANGE-THE-GPL"
 49769              }
 49770            },
 49771            {
 49772              "license": {
 49773                "name": "Expat"
 49774              }
 49775            },
 49776            {
 49777              "license": {
 49778                "id": "GPL-1.0-only"
 49779              }
 49780            },
 49781            {
 49782              "license": {
 49783                "id": "GPL-1.0-or-later"
 49784              }
 49785            },
 49786            {
 49787              "license": {
 49788                "id": "GPL-2.0-only"
 49789              }
 49790            },
 49791            {
 49792              "license": {
 49793                "id": "GPL-2.0-or-later"
 49794              }
 49795            },
 49796            {
 49797              "license": {
 49798                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 49799              }
 49800            },
 49801            {
 49802              "license": {
 49803                "name": "HSIEH-BSD"
 49804              }
 49805            },
 49806            {
 49807              "license": {
 49808                "name": "HSIEH-DERIVATIVE"
 49809              }
 49810            },
 49811            {
 49812              "license": {
 49813                "id": "LGPL-2.1-only"
 49814              }
 49815            },
 49816            {
 49817              "license": {
 49818                "name": "REGCOMP"
 49819              }
 49820            },
 49821            {
 49822              "license": {
 49823                "name": "REGCOMP,"
 49824              }
 49825            },
 49826            {
 49827              "license": {
 49828                "name": "RRA-KEEP-THIS-NOTICE"
 49829              }
 49830            },
 49831            {
 49832              "license": {
 49833                "name": "SDBM-PUBLIC-DOMAIN"
 49834              }
 49835            },
 49836            {
 49837              "license": {
 49838                "name": "TEXT-TABS"
 49839              }
 49840            },
 49841            {
 49842              "license": {
 49843                "name": "Unicode"
 49844              }
 49845            },
 49846            {
 49847              "license": {
 49848                "id": "Zlib"
 49849              }
 49850            }
 49851          ],
 49852          "cpe": "cpe:2.3:a:libperl5.30:libperl5.30:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
 49853          "purl": "pkg:deb/ubuntu/libperl5.30@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04",
 49854          "swid": {
 49855            "attachment": {}
 49856          },
 49857          "pedigree": {},
 49858          "evidence": {},
 49859          "signature": {
 49860            "signature": {
 49861              "publicKey": {}
 49862            }
 49863          },
 49864          "modelCard": {
 49865            "modelParameters": {
 49866              "approach": {}
 49867            },
 49868            "quantitativeAnalysis": {
 49869              "graphics": {}
 49870            },
 49871            "considerations": {}
 49872          }
 49873        },
 49874        {
 49875          "type": "library",
 49876          "bom-ref": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.3?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04\u0026package-id=393a438be5ba5065",
 49877          "supplier": {},
 49878          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49879          "name": "libprocps8",
 49880          "version": "2:3.3.16-1ubuntu2.3",
 49881          "licenses": [
 49882            {
 49883              "license": {
 49884                "id": "GPL-2.0-only"
 49885              }
 49886            },
 49887            {
 49888              "license": {
 49889                "id": "GPL-2.0-or-later"
 49890              }
 49891            },
 49892            {
 49893              "license": {
 49894                "id": "LGPL-2.0-only"
 49895              }
 49896            },
 49897            {
 49898              "license": {
 49899                "id": "LGPL-2.0-or-later"
 49900              }
 49901            },
 49902            {
 49903              "license": {
 49904                "id": "LGPL-2.1-only"
 49905              }
 49906            },
 49907            {
 49908              "license": {
 49909                "id": "LGPL-2.1-or-later"
 49910              }
 49911            }
 49912          ],
 49913          "cpe": "cpe:2.3:a:libprocps8:libprocps8:2\\:3.3.16-1ubuntu2.3:*:*:*:*:*:*:*",
 49914          "purl": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.3?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04",
 49915          "swid": {
 49916            "attachment": {}
 49917          },
 49918          "pedigree": {},
 49919          "evidence": {},
 49920          "signature": {
 49921            "signature": {
 49922              "publicKey": {}
 49923            }
 49924          },
 49925          "modelCard": {
 49926            "modelParameters": {
 49927              "approach": {}
 49928            },
 49929            "quantitativeAnalysis": {
 49930              "graphics": {}
 49931            },
 49932            "considerations": {}
 49933          }
 49934        },
 49935        {
 49936          "type": "library",
 49937          "bom-ref": "pkg:deb/ubuntu/libpsl5@0.21.0-1ubuntu1?arch=amd64\u0026upstream=libpsl\u0026distro=ubuntu-20.04\u0026package-id=e77e76f35a3ad192",
 49938          "supplier": {},
 49939          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49940          "name": "libpsl5",
 49941          "version": "0.21.0-1ubuntu1",
 49942          "licenses": [
 49943            {
 49944              "license": {
 49945                "name": "Chromium"
 49946              }
 49947            },
 49948            {
 49949              "license": {
 49950                "id": "MIT"
 49951              }
 49952            }
 49953          ],
 49954          "cpe": "cpe:2.3:a:libpsl5:libpsl5:0.21.0-1ubuntu1:*:*:*:*:*:*:*",
 49955          "purl": "pkg:deb/ubuntu/libpsl5@0.21.0-1ubuntu1?arch=amd64\u0026upstream=libpsl\u0026distro=ubuntu-20.04",
 49956          "swid": {
 49957            "attachment": {}
 49958          },
 49959          "pedigree": {},
 49960          "evidence": {},
 49961          "signature": {
 49962            "signature": {
 49963              "publicKey": {}
 49964            }
 49965          },
 49966          "modelCard": {
 49967            "modelParameters": {
 49968              "approach": {}
 49969            },
 49970            "quantitativeAnalysis": {
 49971              "graphics": {}
 49972            },
 49973            "considerations": {}
 49974          }
 49975        },
 49976        {
 49977          "type": "library",
 49978          "bom-ref": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=b40e3316416bbdaf",
 49979          "supplier": {},
 49980          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 49981          "name": "libpython3-stdlib",
 49982          "version": "3.8.2-0ubuntu2",
 49983          "cpe": "cpe:2.3:a:libpython3-stdlib:libpython3-stdlib:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
 49984          "purl": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
 49985          "swid": {
 49986            "attachment": {}
 49987          },
 49988          "pedigree": {},
 49989          "evidence": {},
 49990          "signature": {
 49991            "signature": {
 49992              "publicKey": {}
 49993            }
 49994          },
 49995          "modelCard": {
 49996            "modelParameters": {
 49997              "approach": {}
 49998            },
 49999            "quantitativeAnalysis": {
 50000              "graphics": {}
 50001            },
 50002            "considerations": {}
 50003          }
 50004        },
 50005        {
 50006          "type": "library",
 50007          "bom-ref": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04.1?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=33f3278f3c743965",
 50008          "supplier": {},
 50009          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50010          "name": "libpython3.8-minimal",
 50011          "version": "3.8.10-0ubuntu1~20.04.1",
 50012          "licenses": [
 50013            {
 50014              "license": {
 50015                "name": "By"
 50016              }
 50017            },
 50018            {
 50019              "license": {
 50020                "id": "GPL-2.0-only"
 50021              }
 50022            },
 50023            {
 50024              "license": {
 50025                "name": "Permission"
 50026              }
 50027            },
 50028            {
 50029              "license": {
 50030                "name": "Redistribution"
 50031              }
 50032            },
 50033            {
 50034              "license": {
 50035                "name": "This"
 50036              }
 50037            }
 50038          ],
 50039          "cpe": "cpe:2.3:a:libpython3.8-minimal:libpython3.8-minimal:3.8.10-0ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
 50040          "purl": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04.1?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 50041          "swid": {
 50042            "attachment": {}
 50043          },
 50044          "pedigree": {},
 50045          "evidence": {},
 50046          "signature": {
 50047            "signature": {
 50048              "publicKey": {}
 50049            }
 50050          },
 50051          "modelCard": {
 50052            "modelParameters": {
 50053              "approach": {}
 50054            },
 50055            "quantitativeAnalysis": {
 50056              "graphics": {}
 50057            },
 50058            "considerations": {}
 50059          }
 50060        },
 50061        {
 50062          "type": "library",
 50063          "bom-ref": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04.1?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=854ca983dc3a9ffb",
 50064          "supplier": {},
 50065          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50066          "name": "libpython3.8-stdlib",
 50067          "version": "3.8.10-0ubuntu1~20.04.1",
 50068          "licenses": [
 50069            {
 50070              "license": {
 50071                "name": "By"
 50072              }
 50073            },
 50074            {
 50075              "license": {
 50076                "id": "GPL-2.0-only"
 50077              }
 50078            },
 50079            {
 50080              "license": {
 50081                "name": "Permission"
 50082              }
 50083            },
 50084            {
 50085              "license": {
 50086                "name": "Redistribution"
 50087              }
 50088            },
 50089            {
 50090              "license": {
 50091                "name": "This"
 50092              }
 50093            }
 50094          ],
 50095          "cpe": "cpe:2.3:a:libpython3.8-stdlib:libpython3.8-stdlib:3.8.10-0ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
 50096          "purl": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04.1?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 50097          "swid": {
 50098            "attachment": {}
 50099          },
 50100          "pedigree": {},
 50101          "evidence": {},
 50102          "signature": {
 50103            "signature": {
 50104              "publicKey": {}
 50105            }
 50106          },
 50107          "modelCard": {
 50108            "modelParameters": {
 50109              "approach": {}
 50110            },
 50111            "quantitativeAnalysis": {
 50112              "graphics": {}
 50113            },
 50114            "considerations": {}
 50115          }
 50116        },
 50117        {
 50118          "type": "library",
 50119          "bom-ref": "pkg:deb/ubuntu/librados2@15.2.14-0ubuntu0.20.04.1?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04\u0026package-id=7cb91ca8a7b4cce7",
 50120          "supplier": {},
 50121          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50122          "name": "librados2",
 50123          "version": "15.2.14-0ubuntu0.20.04.1",
 50124          "licenses": [
 50125            {
 50126              "license": {
 50127                "id": "APSL-2.0"
 50128              }
 50129            },
 50130            {
 50131              "license": {
 50132                "id": "Apache-2.0"
 50133              }
 50134            },
 50135            {
 50136              "license": {
 50137                "name": "BSD"
 50138              }
 50139            },
 50140            {
 50141              "license": {
 50142                "id": "BSD-2-Clause"
 50143              }
 50144            },
 50145            {
 50146              "license": {
 50147                "id": "BSD-3-Clause"
 50148              }
 50149            },
 50150            {
 50151              "license": {
 50152                "name": "Boost"
 50153              }
 50154            },
 50155            {
 50156              "license": {
 50157                "name": "Boost-Software-License-1.0"
 50158              }
 50159            },
 50160            {
 50161              "license": {
 50162                "id": "CC-BY-SA-3.0"
 50163              }
 50164            },
 50165            {
 50166              "license": {
 50167                "name": "Creative"
 50168              }
 50169            },
 50170            {
 50171              "license": {
 50172                "name": "Expat"
 50173              }
 50174            },
 50175            {
 50176              "license": {
 50177                "id": "GPL-2.0-only"
 50178              }
 50179            },
 50180            {
 50181              "license": {
 50182                "id": "GPL-2.0-or-later"
 50183              }
 50184            },
 50185            {
 50186              "license": {
 50187                "id": "GPL-3.0-only"
 50188              }
 50189            },
 50190            {
 50191              "license": {
 50192                "name": "GPL-3/OpenSSL"
 50193              }
 50194            },
 50195            {
 50196              "license": {
 50197                "id": "GPL-2.0-only"
 50198              }
 50199            },
 50200            {
 50201              "license": {
 50202                "id": "GPL-3.0-only"
 50203              }
 50204            },
 50205            {
 50206              "license": {
 50207                "id": "LGPL-2.0-only"
 50208              }
 50209            },
 50210            {
 50211              "license": {
 50212                "id": "LGPL-2.0-or-later"
 50213              }
 50214            },
 50215            {
 50216              "license": {
 50217                "id": "LGPL-2.1-only"
 50218              }
 50219            },
 50220            {
 50221              "license": {
 50222                "id": "LGPL-2.1-or-later"
 50223              }
 50224            },
 50225            {
 50226              "license": {
 50227                "id": "LGPL-2.0-only"
 50228              }
 50229            },
 50230            {
 50231              "license": {
 50232                "id": "LGPL-2.1-only"
 50233              }
 50234            },
 50235            {
 50236              "license": {
 50237                "id": "MIT"
 50238              }
 50239            },
 50240            {
 50241              "license": {
 50242                "name": "Public"
 50243              }
 50244            },
 50245            {
 50246              "license": {
 50247                "name": "public-domain"
 50248              }
 50249            }
 50250          ],
 50251          "cpe": "cpe:2.3:a:librados2:librados2:15.2.14-0ubuntu0.20.04.1:*:*:*:*:*:*:*",
 50252          "purl": "pkg:deb/ubuntu/librados2@15.2.14-0ubuntu0.20.04.1?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04",
 50253          "swid": {
 50254            "attachment": {}
 50255          },
 50256          "pedigree": {},
 50257          "evidence": {},
 50258          "signature": {
 50259            "signature": {
 50260              "publicKey": {}
 50261            }
 50262          },
 50263          "modelCard": {
 50264            "modelParameters": {
 50265              "approach": {}
 50266            },
 50267            "quantitativeAnalysis": {
 50268              "graphics": {}
 50269            },
 50270            "considerations": {}
 50271          }
 50272        },
 50273        {
 50274          "type": "library",
 50275          "bom-ref": "pkg:deb/ubuntu/librbd1@15.2.14-0ubuntu0.20.04.1?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04\u0026package-id=a8eb84c3f86087ed",
 50276          "supplier": {},
 50277          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50278          "name": "librbd1",
 50279          "version": "15.2.14-0ubuntu0.20.04.1",
 50280          "licenses": [
 50281            {
 50282              "license": {
 50283                "id": "APSL-2.0"
 50284              }
 50285            },
 50286            {
 50287              "license": {
 50288                "id": "Apache-2.0"
 50289              }
 50290            },
 50291            {
 50292              "license": {
 50293                "name": "BSD"
 50294              }
 50295            },
 50296            {
 50297              "license": {
 50298                "id": "BSD-2-Clause"
 50299              }
 50300            },
 50301            {
 50302              "license": {
 50303                "id": "BSD-3-Clause"
 50304              }
 50305            },
 50306            {
 50307              "license": {
 50308                "name": "Boost"
 50309              }
 50310            },
 50311            {
 50312              "license": {
 50313                "name": "Boost-Software-License-1.0"
 50314              }
 50315            },
 50316            {
 50317              "license": {
 50318                "id": "CC-BY-SA-3.0"
 50319              }
 50320            },
 50321            {
 50322              "license": {
 50323                "name": "Creative"
 50324              }
 50325            },
 50326            {
 50327              "license": {
 50328                "name": "Expat"
 50329              }
 50330            },
 50331            {
 50332              "license": {
 50333                "id": "GPL-2.0-only"
 50334              }
 50335            },
 50336            {
 50337              "license": {
 50338                "id": "GPL-2.0-or-later"
 50339              }
 50340            },
 50341            {
 50342              "license": {
 50343                "id": "GPL-3.0-only"
 50344              }
 50345            },
 50346            {
 50347              "license": {
 50348                "name": "GPL-3/OpenSSL"
 50349              }
 50350            },
 50351            {
 50352              "license": {
 50353                "id": "GPL-2.0-only"
 50354              }
 50355            },
 50356            {
 50357              "license": {
 50358                "id": "GPL-3.0-only"
 50359              }
 50360            },
 50361            {
 50362              "license": {
 50363                "id": "LGPL-2.0-only"
 50364              }
 50365            },
 50366            {
 50367              "license": {
 50368                "id": "LGPL-2.0-or-later"
 50369              }
 50370            },
 50371            {
 50372              "license": {
 50373                "id": "LGPL-2.1-only"
 50374              }
 50375            },
 50376            {
 50377              "license": {
 50378                "id": "LGPL-2.1-or-later"
 50379              }
 50380            },
 50381            {
 50382              "license": {
 50383                "id": "LGPL-2.0-only"
 50384              }
 50385            },
 50386            {
 50387              "license": {
 50388                "id": "LGPL-2.1-only"
 50389              }
 50390            },
 50391            {
 50392              "license": {
 50393                "id": "MIT"
 50394              }
 50395            },
 50396            {
 50397              "license": {
 50398                "name": "Public"
 50399              }
 50400            },
 50401            {
 50402              "license": {
 50403                "name": "public-domain"
 50404              }
 50405            }
 50406          ],
 50407          "cpe": "cpe:2.3:a:librbd1:librbd1:15.2.14-0ubuntu0.20.04.1:*:*:*:*:*:*:*",
 50408          "purl": "pkg:deb/ubuntu/librbd1@15.2.14-0ubuntu0.20.04.1?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04",
 50409          "swid": {
 50410            "attachment": {}
 50411          },
 50412          "pedigree": {},
 50413          "evidence": {},
 50414          "signature": {
 50415            "signature": {
 50416              "publicKey": {}
 50417            }
 50418          },
 50419          "modelCard": {
 50420            "modelParameters": {
 50421              "approach": {}
 50422            },
 50423            "quantitativeAnalysis": {
 50424              "graphics": {}
 50425            },
 50426            "considerations": {}
 50427          }
 50428        },
 50429        {
 50430          "type": "library",
 50431          "bom-ref": "pkg:deb/ubuntu/librdmacm1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04\u0026package-id=ba8ceed5ec4f0c95",
 50432          "supplier": {},
 50433          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50434          "name": "librdmacm1",
 50435          "version": "28.0-1ubuntu1",
 50436          "licenses": [
 50437            {
 50438              "license": {
 50439                "id": "BSD-2-Clause"
 50440              }
 50441            },
 50442            {
 50443              "license": {
 50444                "id": "BSD-3-Clause"
 50445              }
 50446            },
 50447            {
 50448              "license": {
 50449                "name": "BSD-MIT"
 50450              }
 50451            },
 50452            {
 50453              "license": {
 50454                "name": "CC0"
 50455              }
 50456            },
 50457            {
 50458              "license": {
 50459                "id": "CPL-1.0"
 50460              }
 50461            },
 50462            {
 50463              "license": {
 50464                "id": "GPL-2.0-only"
 50465              }
 50466            },
 50467            {
 50468              "license": {
 50469                "id": "GPL-2.0-or-later"
 50470              }
 50471            },
 50472            {
 50473              "license": {
 50474                "id": "MIT"
 50475              }
 50476            }
 50477          ],
 50478          "cpe": "cpe:2.3:a:librdmacm1:librdmacm1:28.0-1ubuntu1:*:*:*:*:*:*:*",
 50479          "purl": "pkg:deb/ubuntu/librdmacm1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04",
 50480          "swid": {
 50481            "attachment": {}
 50482          },
 50483          "pedigree": {},
 50484          "evidence": {},
 50485          "signature": {
 50486            "signature": {
 50487              "publicKey": {}
 50488            }
 50489          },
 50490          "modelCard": {
 50491            "modelParameters": {
 50492              "approach": {}
 50493            },
 50494            "quantitativeAnalysis": {
 50495              "graphics": {}
 50496            },
 50497            "considerations": {}
 50498          }
 50499        },
 50500        {
 50501          "type": "library",
 50502          "bom-ref": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=67b876656fcd9e68",
 50503          "supplier": {},
 50504          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50505          "name": "libreadline8",
 50506          "version": "8.0-4",
 50507          "licenses": [
 50508            {
 50509              "license": {
 50510                "name": "GFDL"
 50511              }
 50512            },
 50513            {
 50514              "license": {
 50515                "id": "GPL-3.0-only"
 50516              }
 50517            }
 50518          ],
 50519          "cpe": "cpe:2.3:a:libreadline8:libreadline8:8.0-4:*:*:*:*:*:*:*",
 50520          "purl": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04",
 50521          "swid": {
 50522            "attachment": {}
 50523          },
 50524          "pedigree": {},
 50525          "evidence": {},
 50526          "signature": {
 50527            "signature": {
 50528              "publicKey": {}
 50529            }
 50530          },
 50531          "modelCard": {
 50532            "modelParameters": {
 50533              "approach": {}
 50534            },
 50535            "quantitativeAnalysis": {
 50536              "graphics": {}
 50537            },
 50538            "considerations": {}
 50539          }
 50540        },
 50541        {
 50542          "type": "library",
 50543          "bom-ref": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=68e35bc456818613",
 50544          "supplier": {},
 50545          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50546          "name": "libroken18-heimdal",
 50547          "version": "7.7.0+dfsg-1ubuntu1",
 50548          "licenses": [
 50549            {
 50550              "license": {
 50551                "id": "BSD-3-Clause"
 50552              }
 50553            },
 50554            {
 50555              "license": {
 50556                "id": "GPL-2.0-only"
 50557              }
 50558            },
 50559            {
 50560              "license": {
 50561                "id": "GPL-2.0-or-later"
 50562              }
 50563            },
 50564            {
 50565              "license": {
 50566                "name": "custom"
 50567              }
 50568            }
 50569          ],
 50570          "cpe": "cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 50571          "purl": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 50572          "swid": {
 50573            "attachment": {}
 50574          },
 50575          "pedigree": {},
 50576          "evidence": {},
 50577          "signature": {
 50578            "signature": {
 50579              "publicKey": {}
 50580            }
 50581          },
 50582          "modelCard": {
 50583            "modelParameters": {
 50584              "approach": {}
 50585            },
 50586            "quantitativeAnalysis": {
 50587              "graphics": {}
 50588            },
 50589            "considerations": {}
 50590          }
 50591        },
 50592        {
 50593          "type": "library",
 50594          "bom-ref": "pkg:deb/ubuntu/librtmp1@2.4+20151223.gitfa8646d.1-2build1?arch=amd64\u0026upstream=rtmpdump\u0026distro=ubuntu-20.04\u0026package-id=ede637f87a4bfd7b",
 50595          "supplier": {},
 50596          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50597          "name": "librtmp1",
 50598          "version": "2.4+20151223.gitfa8646d.1-2build1",
 50599          "licenses": [
 50600            {
 50601              "license": {
 50602                "id": "GPL-2.0-only"
 50603              }
 50604            },
 50605            {
 50606              "license": {
 50607                "id": "LGPL-2.1-only"
 50608              }
 50609            }
 50610          ],
 50611          "cpe": "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20151223.gitfa8646d.1-2build1:*:*:*:*:*:*:*",
 50612          "purl": "pkg:deb/ubuntu/librtmp1@2.4+20151223.gitfa8646d.1-2build1?arch=amd64\u0026upstream=rtmpdump\u0026distro=ubuntu-20.04",
 50613          "swid": {
 50614            "attachment": {}
 50615          },
 50616          "pedigree": {},
 50617          "evidence": {},
 50618          "signature": {
 50619            "signature": {
 50620              "publicKey": {}
 50621            }
 50622          },
 50623          "modelCard": {
 50624            "modelParameters": {
 50625              "approach": {}
 50626            },
 50627            "quantitativeAnalysis": {
 50628              "graphics": {}
 50629            },
 50630            "considerations": {}
 50631          }
 50632        },
 50633        {
 50634          "type": "library",
 50635          "bom-ref": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=374396d82667544d",
 50636          "supplier": {},
 50637          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50638          "name": "libsasl2-2",
 50639          "version": "2.1.27+dfsg-2",
 50640          "licenses": [
 50641            {
 50642              "license": {
 50643                "id": "BSD-4-Clause"
 50644              }
 50645            },
 50646            {
 50647              "license": {
 50648                "id": "GPL-3.0-only"
 50649              }
 50650            },
 50651            {
 50652              "license": {
 50653                "id": "GPL-3.0-or-later"
 50654              }
 50655            }
 50656          ],
 50657          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
 50658          "purl": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
 50659          "swid": {
 50660            "attachment": {}
 50661          },
 50662          "pedigree": {},
 50663          "evidence": {},
 50664          "signature": {
 50665            "signature": {
 50666              "publicKey": {}
 50667            }
 50668          },
 50669          "modelCard": {
 50670            "modelParameters": {
 50671              "approach": {}
 50672            },
 50673            "quantitativeAnalysis": {
 50674              "graphics": {}
 50675            },
 50676            "considerations": {}
 50677          }
 50678        },
 50679        {
 50680          "type": "library",
 50681          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=fb8d278d10c4a3cf",
 50682          "supplier": {},
 50683          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50684          "name": "libsasl2-modules",
 50685          "version": "2.1.27+dfsg-2",
 50686          "licenses": [
 50687            {
 50688              "license": {
 50689                "id": "BSD-4-Clause"
 50690              }
 50691            },
 50692            {
 50693              "license": {
 50694                "id": "GPL-3.0-only"
 50695              }
 50696            },
 50697            {
 50698              "license": {
 50699                "id": "GPL-3.0-or-later"
 50700              }
 50701            }
 50702          ],
 50703          "cpe": "cpe:2.3:a:libsasl2-modules:libsasl2-modules:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
 50704          "purl": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
 50705          "swid": {
 50706            "attachment": {}
 50707          },
 50708          "pedigree": {},
 50709          "evidence": {},
 50710          "signature": {
 50711            "signature": {
 50712              "publicKey": {}
 50713            }
 50714          },
 50715          "modelCard": {
 50716            "modelParameters": {
 50717              "approach": {}
 50718            },
 50719            "quantitativeAnalysis": {
 50720              "graphics": {}
 50721            },
 50722            "considerations": {}
 50723          }
 50724        },
 50725        {
 50726          "type": "library",
 50727          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=63c3c50d36ec1d13",
 50728          "supplier": {},
 50729          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50730          "name": "libsasl2-modules-db",
 50731          "version": "2.1.27+dfsg-2",
 50732          "licenses": [
 50733            {
 50734              "license": {
 50735                "id": "BSD-4-Clause"
 50736              }
 50737            },
 50738            {
 50739              "license": {
 50740                "id": "GPL-3.0-only"
 50741              }
 50742            },
 50743            {
 50744              "license": {
 50745                "id": "GPL-3.0-or-later"
 50746              }
 50747            }
 50748          ],
 50749          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
 50750          "purl": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
 50751          "swid": {
 50752            "attachment": {}
 50753          },
 50754          "pedigree": {},
 50755          "evidence": {},
 50756          "signature": {
 50757            "signature": {
 50758              "publicKey": {}
 50759            }
 50760          },
 50761          "modelCard": {
 50762            "modelParameters": {
 50763              "approach": {}
 50764            },
 50765            "quantitativeAnalysis": {
 50766              "graphics": {}
 50767            },
 50768            "considerations": {}
 50769          }
 50770        },
 50771        {
 50772          "type": "library",
 50773          "bom-ref": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04\u0026package-id=b2fd79b9c242e8e8",
 50774          "supplier": {},
 50775          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50776          "name": "libseccomp2",
 50777          "version": "2.5.1-1ubuntu1~20.04.1",
 50778          "licenses": [
 50779            {
 50780              "license": {
 50781                "id": "LGPL-2.1-only"
 50782              }
 50783            }
 50784          ],
 50785          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.5.1-1ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
 50786          "purl": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04",
 50787          "swid": {
 50788            "attachment": {}
 50789          },
 50790          "pedigree": {},
 50791          "evidence": {},
 50792          "signature": {
 50793            "signature": {
 50794              "publicKey": {}
 50795            }
 50796          },
 50797          "modelCard": {
 50798            "modelParameters": {
 50799              "approach": {}
 50800            },
 50801            "quantitativeAnalysis": {
 50802              "graphics": {}
 50803            },
 50804            "considerations": {}
 50805          }
 50806        },
 50807        {
 50808          "type": "library",
 50809          "bom-ref": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04\u0026package-id=e5d4ae16ac79b901",
 50810          "supplier": {},
 50811          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50812          "name": "libselinux1",
 50813          "version": "3.0-1build2",
 50814          "licenses": [
 50815            {
 50816              "license": {
 50817                "id": "GPL-2.0-only"
 50818              }
 50819            },
 50820            {
 50821              "license": {
 50822                "id": "LGPL-2.1-only"
 50823              }
 50824            }
 50825          ],
 50826          "cpe": "cpe:2.3:a:libselinux1:libselinux1:3.0-1build2:*:*:*:*:*:*:*",
 50827          "purl": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04",
 50828          "swid": {
 50829            "attachment": {}
 50830          },
 50831          "pedigree": {},
 50832          "evidence": {},
 50833          "signature": {
 50834            "signature": {
 50835              "publicKey": {}
 50836            }
 50837          },
 50838          "modelCard": {
 50839            "modelParameters": {
 50840              "approach": {}
 50841            },
 50842            "quantitativeAnalysis": {
 50843              "graphics": {}
 50844            },
 50845            "considerations": {}
 50846          }
 50847        },
 50848        {
 50849          "type": "library",
 50850          "bom-ref": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=4c6cd9f68ce53262",
 50851          "supplier": {},
 50852          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50853          "name": "libsemanage-common",
 50854          "version": "3.0-1build2",
 50855          "licenses": [
 50856            {
 50857              "license": {
 50858                "name": "GPL"
 50859              }
 50860            },
 50861            {
 50862              "license": {
 50863                "name": "LGPL"
 50864              }
 50865            }
 50866          ],
 50867          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:3.0-1build2:*:*:*:*:*:*:*",
 50868          "purl": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
 50869          "swid": {
 50870            "attachment": {}
 50871          },
 50872          "pedigree": {},
 50873          "evidence": {},
 50874          "signature": {
 50875            "signature": {
 50876              "publicKey": {}
 50877            }
 50878          },
 50879          "modelCard": {
 50880            "modelParameters": {
 50881              "approach": {}
 50882            },
 50883            "quantitativeAnalysis": {
 50884              "graphics": {}
 50885            },
 50886            "considerations": {}
 50887          }
 50888        },
 50889        {
 50890          "type": "library",
 50891          "bom-ref": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=963297f19b339026",
 50892          "supplier": {},
 50893          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50894          "name": "libsemanage1",
 50895          "version": "3.0-1build2",
 50896          "licenses": [
 50897            {
 50898              "license": {
 50899                "name": "GPL"
 50900              }
 50901            },
 50902            {
 50903              "license": {
 50904                "name": "LGPL"
 50905              }
 50906            }
 50907          ],
 50908          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:3.0-1build2:*:*:*:*:*:*:*",
 50909          "purl": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
 50910          "swid": {
 50911            "attachment": {}
 50912          },
 50913          "pedigree": {},
 50914          "evidence": {},
 50915          "signature": {
 50916            "signature": {
 50917              "publicKey": {}
 50918            }
 50919          },
 50920          "modelCard": {
 50921            "modelParameters": {
 50922              "approach": {}
 50923            },
 50924            "quantitativeAnalysis": {
 50925              "graphics": {}
 50926            },
 50927            "considerations": {}
 50928          }
 50929        },
 50930        {
 50931          "type": "library",
 50932          "bom-ref": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04\u0026package-id=991afdd7bf17200c",
 50933          "supplier": {},
 50934          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50935          "name": "libsepol1",
 50936          "version": "3.0-1",
 50937          "licenses": [
 50938            {
 50939              "license": {
 50940                "name": "GPL"
 50941              }
 50942            },
 50943            {
 50944              "license": {
 50945                "name": "LGPL"
 50946              }
 50947            }
 50948          ],
 50949          "cpe": "cpe:2.3:a:libsepol1:libsepol1:3.0-1:*:*:*:*:*:*:*",
 50950          "purl": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04",
 50951          "swid": {
 50952            "attachment": {}
 50953          },
 50954          "pedigree": {},
 50955          "evidence": {},
 50956          "signature": {
 50957            "signature": {
 50958              "publicKey": {}
 50959            }
 50960          },
 50961          "modelCard": {
 50962            "modelParameters": {
 50963              "approach": {}
 50964            },
 50965            "quantitativeAnalysis": {
 50966              "graphics": {}
 50967            },
 50968            "considerations": {}
 50969          }
 50970        },
 50971        {
 50972          "type": "library",
 50973          "bom-ref": "pkg:deb/ubuntu/libsgutils2-2@1.44-1ubuntu2?arch=amd64\u0026upstream=sg3-utils\u0026distro=ubuntu-20.04\u0026package-id=5eee3420d656cf76",
 50974          "supplier": {},
 50975          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 50976          "name": "libsgutils2-2",
 50977          "version": "1.44-1ubuntu2",
 50978          "licenses": [
 50979            {
 50980              "license": {
 50981                "name": "GPL"
 50982              }
 50983            }
 50984          ],
 50985          "cpe": "cpe:2.3:a:libsgutils2-2:libsgutils2-2:1.44-1ubuntu2:*:*:*:*:*:*:*",
 50986          "purl": "pkg:deb/ubuntu/libsgutils2-2@1.44-1ubuntu2?arch=amd64\u0026upstream=sg3-utils\u0026distro=ubuntu-20.04",
 50987          "swid": {
 50988            "attachment": {}
 50989          },
 50990          "pedigree": {},
 50991          "evidence": {},
 50992          "signature": {
 50993            "signature": {
 50994              "publicKey": {}
 50995            }
 50996          },
 50997          "modelCard": {
 50998            "modelParameters": {
 50999              "approach": {}
 51000            },
 51001            "quantitativeAnalysis": {
 51002              "graphics": {}
 51003            },
 51004            "considerations": {}
 51005          }
 51006        },
 51007        {
 51008          "type": "library",
 51009          "bom-ref": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=b47d3a935260c518",
 51010          "supplier": {},
 51011          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51012          "name": "libsmartcols1",
 51013          "version": "2.34-0.1ubuntu9.1",
 51014          "licenses": [
 51015            {
 51016              "license": {
 51017                "id": "BSD-2-Clause"
 51018              }
 51019            },
 51020            {
 51021              "license": {
 51022                "id": "BSD-3-Clause"
 51023              }
 51024            },
 51025            {
 51026              "license": {
 51027                "id": "BSD-4-Clause"
 51028              }
 51029            },
 51030            {
 51031              "license": {
 51032                "id": "GPL-2.0-only"
 51033              }
 51034            },
 51035            {
 51036              "license": {
 51037                "id": "GPL-2.0-or-later"
 51038              }
 51039            },
 51040            {
 51041              "license": {
 51042                "id": "GPL-3.0-only"
 51043              }
 51044            },
 51045            {
 51046              "license": {
 51047                "id": "GPL-3.0-or-later"
 51048              }
 51049            },
 51050            {
 51051              "license": {
 51052                "name": "LGPL"
 51053              }
 51054            },
 51055            {
 51056              "license": {
 51057                "id": "LGPL-2.0-only"
 51058              }
 51059            },
 51060            {
 51061              "license": {
 51062                "id": "LGPL-2.0-or-later"
 51063              }
 51064            },
 51065            {
 51066              "license": {
 51067                "id": "LGPL-2.1-only"
 51068              }
 51069            },
 51070            {
 51071              "license": {
 51072                "id": "LGPL-2.1-or-later"
 51073              }
 51074            },
 51075            {
 51076              "license": {
 51077                "id": "LGPL-3.0-only"
 51078              }
 51079            },
 51080            {
 51081              "license": {
 51082                "id": "LGPL-3.0-or-later"
 51083              }
 51084            },
 51085            {
 51086              "license": {
 51087                "id": "MIT"
 51088              }
 51089            },
 51090            {
 51091              "license": {
 51092                "name": "public-domain"
 51093              }
 51094            }
 51095          ],
 51096          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 51097          "purl": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 51098          "swid": {
 51099            "attachment": {}
 51100          },
 51101          "pedigree": {},
 51102          "evidence": {},
 51103          "signature": {
 51104            "signature": {
 51105              "publicKey": {}
 51106            }
 51107          },
 51108          "modelCard": {
 51109            "modelParameters": {
 51110              "approach": {}
 51111            },
 51112            "quantitativeAnalysis": {
 51113              "graphics": {}
 51114            },
 51115            "considerations": {}
 51116          }
 51117        },
 51118        {
 51119          "type": "library",
 51120          "bom-ref": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04\u0026package-id=a7c7ccf11d3583d1",
 51121          "supplier": {},
 51122          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51123          "name": "libsqlite3-0",
 51124          "version": "3.31.1-4ubuntu0.2",
 51125          "licenses": [
 51126            {
 51127              "license": {
 51128                "id": "GPL-2.0-only"
 51129              }
 51130            },
 51131            {
 51132              "license": {
 51133                "id": "GPL-2.0-or-later"
 51134              }
 51135            },
 51136            {
 51137              "license": {
 51138                "name": "public-domain"
 51139              }
 51140            }
 51141          ],
 51142          "cpe": "cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.31.1-4ubuntu0.2:*:*:*:*:*:*:*",
 51143          "purl": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04",
 51144          "swid": {
 51145            "attachment": {}
 51146          },
 51147          "pedigree": {},
 51148          "evidence": {},
 51149          "signature": {
 51150            "signature": {
 51151              "publicKey": {}
 51152            }
 51153          },
 51154          "modelCard": {
 51155            "modelParameters": {
 51156              "approach": {}
 51157            },
 51158            "quantitativeAnalysis": {
 51159              "graphics": {}
 51160            },
 51161            "considerations": {}
 51162          }
 51163        },
 51164        {
 51165          "type": "library",
 51166          "bom-ref": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4715894cb8165c",
 51167          "supplier": {},
 51168          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51169          "name": "libss2",
 51170          "version": "1.45.5-2ubuntu1",
 51171          "cpe": "cpe:2.3:a:libss2:libss2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 51172          "purl": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 51173          "swid": {
 51174            "attachment": {}
 51175          },
 51176          "pedigree": {},
 51177          "evidence": {},
 51178          "signature": {
 51179            "signature": {
 51180              "publicKey": {}
 51181            }
 51182          },
 51183          "modelCard": {
 51184            "modelParameters": {
 51185              "approach": {}
 51186            },
 51187            "quantitativeAnalysis": {
 51188              "graphics": {}
 51189            },
 51190            "considerations": {}
 51191          }
 51192        },
 51193        {
 51194          "type": "library",
 51195          "bom-ref": "pkg:deb/ubuntu/libssh-4@0.9.3-2ubuntu2.2?arch=amd64\u0026upstream=libssh\u0026distro=ubuntu-20.04\u0026package-id=93df7c2bd7217cc4",
 51196          "supplier": {},
 51197          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51198          "name": "libssh-4",
 51199          "version": "0.9.3-2ubuntu2.2",
 51200          "licenses": [
 51201            {
 51202              "license": {
 51203                "id": "BSD-2-Clause"
 51204              }
 51205            },
 51206            {
 51207              "license": {
 51208                "id": "BSD-3-Clause"
 51209              }
 51210            },
 51211            {
 51212              "license": {
 51213                "id": "LGPL-2.1-only"
 51214              }
 51215            },
 51216            {
 51217              "license": {
 51218                "name": "LGPL-2.1+~OpenSSL"
 51219              }
 51220            },
 51221            {
 51222              "license": {
 51223                "name": "public-domain"
 51224              }
 51225            }
 51226          ],
 51227          "cpe": "cpe:2.3:a:libssh-4:libssh-4:0.9.3-2ubuntu2.2:*:*:*:*:*:*:*",
 51228          "purl": "pkg:deb/ubuntu/libssh-4@0.9.3-2ubuntu2.2?arch=amd64\u0026upstream=libssh\u0026distro=ubuntu-20.04",
 51229          "swid": {
 51230            "attachment": {}
 51231          },
 51232          "pedigree": {},
 51233          "evidence": {},
 51234          "signature": {
 51235            "signature": {
 51236              "publicKey": {}
 51237            }
 51238          },
 51239          "modelCard": {
 51240            "modelParameters": {
 51241              "approach": {}
 51242            },
 51243            "quantitativeAnalysis": {
 51244              "graphics": {}
 51245            },
 51246            "considerations": {}
 51247          }
 51248        },
 51249        {
 51250          "type": "library",
 51251          "bom-ref": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.9?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04\u0026package-id=3427630da64660c5",
 51252          "supplier": {},
 51253          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51254          "name": "libssl1.1",
 51255          "version": "1.1.1f-1ubuntu2.9",
 51256          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1f-1ubuntu2.9:*:*:*:*:*:*:*",
 51257          "purl": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.9?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04",
 51258          "swid": {
 51259            "attachment": {}
 51260          },
 51261          "pedigree": {},
 51262          "evidence": {},
 51263          "signature": {
 51264            "signature": {
 51265              "publicKey": {}
 51266            }
 51267          },
 51268          "modelCard": {
 51269            "modelParameters": {
 51270              "approach": {}
 51271            },
 51272            "quantitativeAnalysis": {
 51273              "graphics": {}
 51274            },
 51275            "considerations": {}
 51276          }
 51277        },
 51278        {
 51279          "type": "library",
 51280          "bom-ref": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=241fcb3d9b65153a",
 51281          "supplier": {},
 51282          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51283          "name": "libstdc++6",
 51284          "version": "10.3.0-1ubuntu1~20.04",
 51285          "licenses": [
 51286            {
 51287              "license": {
 51288                "name": "Artistic"
 51289              }
 51290            },
 51291            {
 51292              "license": {
 51293                "id": "GFDL-1.2-only"
 51294              }
 51295            },
 51296            {
 51297              "license": {
 51298                "name": "GPL"
 51299              }
 51300            },
 51301            {
 51302              "license": {
 51303                "id": "GPL-2.0-only"
 51304              }
 51305            },
 51306            {
 51307              "license": {
 51308                "id": "GPL-3.0-only"
 51309              }
 51310            },
 51311            {
 51312              "license": {
 51313                "name": "LGPL"
 51314              }
 51315            }
 51316          ],
 51317          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
 51318          "purl": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
 51319          "swid": {
 51320            "attachment": {}
 51321          },
 51322          "pedigree": {},
 51323          "evidence": {},
 51324          "signature": {
 51325            "signature": {
 51326              "publicKey": {}
 51327            }
 51328          },
 51329          "modelCard": {
 51330            "modelParameters": {
 51331              "approach": {}
 51332            },
 51333            "quantitativeAnalysis": {
 51334              "graphics": {}
 51335            },
 51336            "considerations": {}
 51337          }
 51338        },
 51339        {
 51340          "type": "library",
 51341          "bom-ref": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.13?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=cc380da51eb4b1d1",
 51342          "supplier": {},
 51343          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51344          "name": "libsystemd0",
 51345          "version": "245.4-4ubuntu3.13",
 51346          "licenses": [
 51347            {
 51348              "license": {
 51349                "id": "CC0-1.0"
 51350              }
 51351            },
 51352            {
 51353              "license": {
 51354                "name": "Expat"
 51355              }
 51356            },
 51357            {
 51358              "license": {
 51359                "id": "GPL-2.0-only"
 51360              }
 51361            },
 51362            {
 51363              "license": {
 51364                "id": "GPL-2.0-or-later"
 51365              }
 51366            },
 51367            {
 51368              "license": {
 51369                "id": "LGPL-2.1-only"
 51370              }
 51371            },
 51372            {
 51373              "license": {
 51374                "id": "LGPL-2.1-or-later"
 51375              }
 51376            },
 51377            {
 51378              "license": {
 51379                "name": "public-domain"
 51380              }
 51381            }
 51382          ],
 51383          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:245.4-4ubuntu3.13:*:*:*:*:*:*:*",
 51384          "purl": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.13?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
 51385          "swid": {
 51386            "attachment": {}
 51387          },
 51388          "pedigree": {},
 51389          "evidence": {},
 51390          "signature": {
 51391            "signature": {
 51392              "publicKey": {}
 51393            }
 51394          },
 51395          "modelCard": {
 51396            "modelParameters": {
 51397              "approach": {}
 51398            },
 51399            "quantitativeAnalysis": {
 51400              "graphics": {}
 51401            },
 51402            "considerations": {}
 51403          }
 51404        },
 51405        {
 51406          "type": "library",
 51407          "bom-ref": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a290c35fc0220ba0",
 51408          "supplier": {},
 51409          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51410          "name": "libtasn1-6",
 51411          "version": "4.16.0-2",
 51412          "licenses": [
 51413            {
 51414              "license": {
 51415                "id": "GFDL-1.3-only"
 51416              }
 51417            },
 51418            {
 51419              "license": {
 51420                "id": "GPL-3.0-only"
 51421              }
 51422            },
 51423            {
 51424              "license": {
 51425                "name": "LGPL"
 51426              }
 51427            },
 51428            {
 51429              "license": {
 51430                "id": "LGPL-2.1-only"
 51431              }
 51432            }
 51433          ],
 51434          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2:*:*:*:*:*:*:*",
 51435          "purl": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04",
 51436          "swid": {
 51437            "attachment": {}
 51438          },
 51439          "pedigree": {},
 51440          "evidence": {},
 51441          "signature": {
 51442            "signature": {
 51443              "publicKey": {}
 51444            }
 51445          },
 51446          "modelCard": {
 51447            "modelParameters": {
 51448              "approach": {}
 51449            },
 51450            "quantitativeAnalysis": {
 51451              "graphics": {}
 51452            },
 51453            "considerations": {}
 51454          }
 51455        },
 51456        {
 51457          "type": "library",
 51458          "bom-ref": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=72ad56d118fefea3",
 51459          "supplier": {},
 51460          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51461          "name": "libtinfo6",
 51462          "version": "6.2-0ubuntu2",
 51463          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.2-0ubuntu2:*:*:*:*:*:*:*",
 51464          "purl": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 51465          "swid": {
 51466            "attachment": {}
 51467          },
 51468          "pedigree": {},
 51469          "evidence": {},
 51470          "signature": {
 51471            "signature": {
 51472              "publicKey": {}
 51473            }
 51474          },
 51475          "modelCard": {
 51476            "modelParameters": {
 51477              "approach": {}
 51478            },
 51479            "quantitativeAnalysis": {
 51480              "graphics": {}
 51481            },
 51482            "considerations": {}
 51483          }
 51484        },
 51485        {
 51486          "type": "library",
 51487          "bom-ref": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=ba22fe8af5722b24",
 51488          "supplier": {},
 51489          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51490          "name": "libtirpc-common",
 51491          "version": "1.2.5-1",
 51492          "licenses": [
 51493            {
 51494              "license": {
 51495                "id": "BSD-3-Clause"
 51496              }
 51497            },
 51498            {
 51499              "license": {
 51500                "id": "GPL-2.0-only"
 51501              }
 51502            },
 51503            {
 51504              "license": {
 51505                "id": "LGPL-2.1-only"
 51506              }
 51507            }
 51508          ],
 51509          "cpe": "cpe:2.3:a:libtirpc-common:libtirpc-common:1.2.5-1:*:*:*:*:*:*:*",
 51510          "purl": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
 51511          "swid": {
 51512            "attachment": {}
 51513          },
 51514          "pedigree": {},
 51515          "evidence": {},
 51516          "signature": {
 51517            "signature": {
 51518              "publicKey": {}
 51519            }
 51520          },
 51521          "modelCard": {
 51522            "modelParameters": {
 51523              "approach": {}
 51524            },
 51525            "quantitativeAnalysis": {
 51526              "graphics": {}
 51527            },
 51528            "considerations": {}
 51529          }
 51530        },
 51531        {
 51532          "type": "library",
 51533          "bom-ref": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=57b2bfa0a8467ab7",
 51534          "supplier": {},
 51535          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51536          "name": "libtirpc3",
 51537          "version": "1.2.5-1",
 51538          "licenses": [
 51539            {
 51540              "license": {
 51541                "id": "BSD-3-Clause"
 51542              }
 51543            },
 51544            {
 51545              "license": {
 51546                "id": "GPL-2.0-only"
 51547              }
 51548            },
 51549            {
 51550              "license": {
 51551                "id": "LGPL-2.1-only"
 51552              }
 51553            }
 51554          ],
 51555          "cpe": "cpe:2.3:a:libtirpc3:libtirpc3:1.2.5-1:*:*:*:*:*:*:*",
 51556          "purl": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
 51557          "swid": {
 51558            "attachment": {}
 51559          },
 51560          "pedigree": {},
 51561          "evidence": {},
 51562          "signature": {
 51563            "signature": {
 51564              "publicKey": {}
 51565            }
 51566          },
 51567          "modelCard": {
 51568            "modelParameters": {
 51569              "approach": {}
 51570            },
 51571            "quantitativeAnalysis": {
 51572              "graphics": {}
 51573            },
 51574            "considerations": {}
 51575          }
 51576        },
 51577        {
 51578          "type": "library",
 51579          "bom-ref": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.13?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=4b339254fe502057",
 51580          "supplier": {},
 51581          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51582          "name": "libudev1",
 51583          "version": "245.4-4ubuntu3.13",
 51584          "licenses": [
 51585            {
 51586              "license": {
 51587                "id": "CC0-1.0"
 51588              }
 51589            },
 51590            {
 51591              "license": {
 51592                "name": "Expat"
 51593              }
 51594            },
 51595            {
 51596              "license": {
 51597                "id": "GPL-2.0-only"
 51598              }
 51599            },
 51600            {
 51601              "license": {
 51602                "id": "GPL-2.0-or-later"
 51603              }
 51604            },
 51605            {
 51606              "license": {
 51607                "id": "LGPL-2.1-only"
 51608              }
 51609            },
 51610            {
 51611              "license": {
 51612                "id": "LGPL-2.1-or-later"
 51613              }
 51614            },
 51615            {
 51616              "license": {
 51617                "name": "public-domain"
 51618              }
 51619            }
 51620          ],
 51621          "cpe": "cpe:2.3:a:libudev1:libudev1:245.4-4ubuntu3.13:*:*:*:*:*:*:*",
 51622          "purl": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.13?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
 51623          "swid": {
 51624            "attachment": {}
 51625          },
 51626          "pedigree": {},
 51627          "evidence": {},
 51628          "signature": {
 51629            "signature": {
 51630              "publicKey": {}
 51631            }
 51632          },
 51633          "modelCard": {
 51634            "modelParameters": {
 51635              "approach": {}
 51636            },
 51637            "quantitativeAnalysis": {
 51638              "graphics": {}
 51639            },
 51640            "considerations": {}
 51641          }
 51642        },
 51643        {
 51644          "type": "library",
 51645          "bom-ref": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04\u0026package-id=3140ffa70dcd9831",
 51646          "supplier": {},
 51647          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51648          "name": "libunistring2",
 51649          "version": "0.9.10-2",
 51650          "licenses": [
 51651            {
 51652              "license": {
 51653                "name": "FreeSoftware"
 51654              }
 51655            },
 51656            {
 51657              "license": {
 51658                "id": "GFDL-1.2-only"
 51659              }
 51660            },
 51661            {
 51662              "license": {
 51663                "name": "GFDL-1.2+"
 51664              }
 51665            },
 51666            {
 51667              "license": {
 51668                "id": "GPL-2.0-only"
 51669              }
 51670            },
 51671            {
 51672              "license": {
 51673                "id": "GPL-2.0-or-later"
 51674              }
 51675            },
 51676            {
 51677              "license": {
 51678                "id": "GPL-3.0-only"
 51679              }
 51680            },
 51681            {
 51682              "license": {
 51683                "id": "GPL-3.0-or-later"
 51684              }
 51685            },
 51686            {
 51687              "license": {
 51688                "id": "LGPL-3.0-only"
 51689              }
 51690            },
 51691            {
 51692              "license": {
 51693                "id": "LGPL-3.0-or-later"
 51694              }
 51695            },
 51696            {
 51697              "license": {
 51698                "id": "MIT"
 51699              }
 51700            }
 51701          ],
 51702          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-2:*:*:*:*:*:*:*",
 51703          "purl": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04",
 51704          "swid": {
 51705            "attachment": {}
 51706          },
 51707          "pedigree": {},
 51708          "evidence": {},
 51709          "signature": {
 51710            "signature": {
 51711              "publicKey": {}
 51712            }
 51713          },
 51714          "modelCard": {
 51715            "modelParameters": {
 51716              "approach": {}
 51717            },
 51718            "quantitativeAnalysis": {
 51719              "graphics": {}
 51720            },
 51721            "considerations": {}
 51722          }
 51723        },
 51724        {
 51725          "type": "library",
 51726          "bom-ref": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=5395a07c00002ea6",
 51727          "supplier": {},
 51728          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51729          "name": "libuuid1",
 51730          "version": "2.34-0.1ubuntu9.1",
 51731          "licenses": [
 51732            {
 51733              "license": {
 51734                "id": "BSD-2-Clause"
 51735              }
 51736            },
 51737            {
 51738              "license": {
 51739                "id": "BSD-3-Clause"
 51740              }
 51741            },
 51742            {
 51743              "license": {
 51744                "id": "BSD-4-Clause"
 51745              }
 51746            },
 51747            {
 51748              "license": {
 51749                "id": "GPL-2.0-only"
 51750              }
 51751            },
 51752            {
 51753              "license": {
 51754                "id": "GPL-2.0-or-later"
 51755              }
 51756            },
 51757            {
 51758              "license": {
 51759                "id": "GPL-3.0-only"
 51760              }
 51761            },
 51762            {
 51763              "license": {
 51764                "id": "GPL-3.0-or-later"
 51765              }
 51766            },
 51767            {
 51768              "license": {
 51769                "name": "LGPL"
 51770              }
 51771            },
 51772            {
 51773              "license": {
 51774                "id": "LGPL-2.0-only"
 51775              }
 51776            },
 51777            {
 51778              "license": {
 51779                "id": "LGPL-2.0-or-later"
 51780              }
 51781            },
 51782            {
 51783              "license": {
 51784                "id": "LGPL-2.1-only"
 51785              }
 51786            },
 51787            {
 51788              "license": {
 51789                "id": "LGPL-2.1-or-later"
 51790              }
 51791            },
 51792            {
 51793              "license": {
 51794                "id": "LGPL-3.0-only"
 51795              }
 51796            },
 51797            {
 51798              "license": {
 51799                "id": "LGPL-3.0-or-later"
 51800              }
 51801            },
 51802            {
 51803              "license": {
 51804                "id": "MIT"
 51805              }
 51806            },
 51807            {
 51808              "license": {
 51809                "name": "public-domain"
 51810              }
 51811            }
 51812          ],
 51813          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 51814          "purl": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 51815          "swid": {
 51816            "attachment": {}
 51817          },
 51818          "pedigree": {},
 51819          "evidence": {},
 51820          "signature": {
 51821            "signature": {
 51822              "publicKey": {}
 51823            }
 51824          },
 51825          "modelCard": {
 51826            "modelParameters": {
 51827              "approach": {}
 51828            },
 51829            "quantitativeAnalysis": {
 51830              "graphics": {}
 51831            },
 51832            "considerations": {}
 51833          }
 51834        },
 51835        {
 51836          "type": "library",
 51837          "bom-ref": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=7b0e172efdb36a99",
 51838          "supplier": {},
 51839          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51840          "name": "libwind0-heimdal",
 51841          "version": "7.7.0+dfsg-1ubuntu1",
 51842          "licenses": [
 51843            {
 51844              "license": {
 51845                "id": "BSD-3-Clause"
 51846              }
 51847            },
 51848            {
 51849              "license": {
 51850                "id": "GPL-2.0-only"
 51851              }
 51852            },
 51853            {
 51854              "license": {
 51855                "id": "GPL-2.0-or-later"
 51856              }
 51857            },
 51858            {
 51859              "license": {
 51860                "name": "custom"
 51861              }
 51862            }
 51863          ],
 51864          "cpe": "cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 51865          "purl": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 51866          "swid": {
 51867            "attachment": {}
 51868          },
 51869          "pedigree": {},
 51870          "evidence": {},
 51871          "signature": {
 51872            "signature": {
 51873              "publicKey": {}
 51874            }
 51875          },
 51876          "modelCard": {
 51877            "modelParameters": {
 51878              "approach": {}
 51879            },
 51880            "quantitativeAnalysis": {
 51881              "graphics": {}
 51882            },
 51883            "considerations": {}
 51884          }
 51885        },
 51886        {
 51887          "type": "library",
 51888          "bom-ref": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04\u0026package-id=5b14391c61bb94f1",
 51889          "supplier": {},
 51890          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51891          "name": "libwrap0",
 51892          "version": "7.6.q-30",
 51893          "cpe": "cpe:2.3:a:libwrap0:libwrap0:7.6.q-30:*:*:*:*:*:*:*",
 51894          "purl": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04",
 51895          "swid": {
 51896            "attachment": {}
 51897          },
 51898          "pedigree": {},
 51899          "evidence": {},
 51900          "signature": {
 51901            "signature": {
 51902              "publicKey": {}
 51903            }
 51904          },
 51905          "modelCard": {
 51906            "modelParameters": {
 51907              "approach": {}
 51908            },
 51909            "quantitativeAnalysis": {
 51910              "graphics": {}
 51911            },
 51912            "considerations": {}
 51913          }
 51914        },
 51915        {
 51916          "type": "library",
 51917          "bom-ref": "pkg:deb/ubuntu/libxml2@2.9.10+dfsg-5ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=5227ee2e55b78734",
 51918          "supplier": {},
 51919          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51920          "name": "libxml2",
 51921          "version": "2.9.10+dfsg-5ubuntu0.20.04.1",
 51922          "licenses": [
 51923            {
 51924              "license": {
 51925                "id": "ISC"
 51926              }
 51927            },
 51928            {
 51929              "license": {
 51930                "name": "MIT-1"
 51931              }
 51932            }
 51933          ],
 51934          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.10\\+dfsg-5ubuntu0.20.04.1:*:*:*:*:*:*:*",
 51935          "purl": "pkg:deb/ubuntu/libxml2@2.9.10+dfsg-5ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
 51936          "swid": {
 51937            "attachment": {}
 51938          },
 51939          "pedigree": {},
 51940          "evidence": {},
 51941          "signature": {
 51942            "signature": {
 51943              "publicKey": {}
 51944            }
 51945          },
 51946          "modelCard": {
 51947            "modelParameters": {
 51948              "approach": {}
 51949            },
 51950            "quantitativeAnalysis": {
 51951              "graphics": {}
 51952            },
 51953            "considerations": {}
 51954          }
 51955        },
 51956        {
 51957          "type": "library",
 51958          "bom-ref": "pkg:deb/ubuntu/libxtables12@1.8.4-3ubuntu2?arch=amd64\u0026upstream=iptables\u0026distro=ubuntu-20.04\u0026package-id=440c57e95fc3a35c",
 51959          "supplier": {},
 51960          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 51961          "name": "libxtables12",
 51962          "version": "1.8.4-3ubuntu2",
 51963          "licenses": [
 51964            {
 51965              "license": {
 51966                "name": "Artistic"
 51967              }
 51968            },
 51969            {
 51970              "license": {
 51971                "id": "GPL-2.0-only"
 51972              }
 51973            },
 51974            {
 51975              "license": {
 51976                "id": "GPL-2.0-or-later"
 51977              }
 51978            },
 51979            {
 51980              "license": {
 51981                "name": "custom"
 51982              }
 51983            }
 51984          ],
 51985          "cpe": "cpe:2.3:a:libxtables12:libxtables12:1.8.4-3ubuntu2:*:*:*:*:*:*:*",
 51986          "purl": "pkg:deb/ubuntu/libxtables12@1.8.4-3ubuntu2?arch=amd64\u0026upstream=iptables\u0026distro=ubuntu-20.04",
 51987          "swid": {
 51988            "attachment": {}
 51989          },
 51990          "pedigree": {},
 51991          "evidence": {},
 51992          "signature": {
 51993            "signature": {
 51994              "publicKey": {}
 51995            }
 51996          },
 51997          "modelCard": {
 51998            "modelParameters": {
 51999              "approach": {}
 52000            },
 52001            "quantitativeAnalysis": {
 52002              "graphics": {}
 52003            },
 52004            "considerations": {}
 52005          }
 52006        },
 52007        {
 52008          "type": "library",
 52009          "bom-ref": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04\u0026package-id=47cff0564e160066",
 52010          "supplier": {},
 52011          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52012          "name": "libzstd1",
 52013          "version": "1.4.4+dfsg-3ubuntu0.1",
 52014          "licenses": [
 52015            {
 52016              "license": {
 52017                "id": "BSD-3-Clause"
 52018              }
 52019            },
 52020            {
 52021              "license": {
 52022                "name": "Expat"
 52023              }
 52024            },
 52025            {
 52026              "license": {
 52027                "id": "GPL-2.0-only"
 52028              }
 52029            },
 52030            {
 52031              "license": {
 52032                "id": "GPL-2.0-or-later"
 52033              }
 52034            },
 52035            {
 52036              "license": {
 52037                "id": "Zlib"
 52038              }
 52039            }
 52040          ],
 52041          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.4\\+dfsg-3ubuntu0.1:*:*:*:*:*:*:*",
 52042          "purl": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04",
 52043          "swid": {
 52044            "attachment": {}
 52045          },
 52046          "pedigree": {},
 52047          "evidence": {},
 52048          "signature": {
 52049            "signature": {
 52050              "publicKey": {}
 52051            }
 52052          },
 52053          "modelCard": {
 52054            "modelParameters": {
 52055              "approach": {}
 52056            },
 52057            "quantitativeAnalysis": {
 52058              "graphics": {}
 52059            },
 52060            "considerations": {}
 52061          }
 52062        },
 52063        {
 52064          "type": "library",
 52065          "bom-ref": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=cb23947502a7c38d",
 52066          "supplier": {},
 52067          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52068          "name": "login",
 52069          "version": "1:4.8.1-1ubuntu5.20.04.1",
 52070          "licenses": [
 52071            {
 52072              "license": {
 52073                "id": "GPL-2.0-only"
 52074              }
 52075            }
 52076          ],
 52077          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
 52078          "purl": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
 52079          "swid": {
 52080            "attachment": {}
 52081          },
 52082          "pedigree": {},
 52083          "evidence": {},
 52084          "signature": {
 52085            "signature": {
 52086              "publicKey": {}
 52087            }
 52088          },
 52089          "modelCard": {
 52090            "modelParameters": {
 52091              "approach": {}
 52092            },
 52093            "quantitativeAnalysis": {
 52094              "graphics": {}
 52095            },
 52096            "considerations": {}
 52097          }
 52098        },
 52099        {
 52100          "type": "library",
 52101          "bom-ref": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4a92556bee4b4f91",
 52102          "supplier": {},
 52103          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52104          "name": "logsave",
 52105          "version": "1.45.5-2ubuntu1",
 52106          "licenses": [
 52107            {
 52108              "license": {
 52109                "id": "GPL-2.0-only"
 52110              }
 52111            },
 52112            {
 52113              "license": {
 52114                "id": "LGPL-2.0-only"
 52115              }
 52116            }
 52117          ],
 52118          "cpe": "cpe:2.3:a:logsave:logsave:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 52119          "purl": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 52120          "swid": {
 52121            "attachment": {}
 52122          },
 52123          "pedigree": {},
 52124          "evidence": {},
 52125          "signature": {
 52126            "signature": {
 52127              "publicKey": {}
 52128            }
 52129          },
 52130          "modelCard": {
 52131            "modelParameters": {
 52132              "approach": {}
 52133            },
 52134            "quantitativeAnalysis": {
 52135              "graphics": {}
 52136            },
 52137            "considerations": {}
 52138          }
 52139        },
 52140        {
 52141          "type": "library",
 52142          "bom-ref": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04\u0026package-id=b76348b7f1282c61",
 52143          "supplier": {},
 52144          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52145          "name": "lsb-base",
 52146          "version": "11.1.0ubuntu2",
 52147          "licenses": [
 52148            {
 52149              "license": {
 52150                "id": "BSD-3-Clause"
 52151              }
 52152            },
 52153            {
 52154              "license": {
 52155                "id": "GPL-2.0-only"
 52156              }
 52157            }
 52158          ],
 52159          "cpe": "cpe:2.3:a:lsb-base:lsb-base:11.1.0ubuntu2:*:*:*:*:*:*:*",
 52160          "purl": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04",
 52161          "swid": {
 52162            "attachment": {}
 52163          },
 52164          "pedigree": {},
 52165          "evidence": {},
 52166          "signature": {
 52167            "signature": {
 52168              "publicKey": {}
 52169            }
 52170          },
 52171          "modelCard": {
 52172            "modelParameters": {
 52173              "approach": {}
 52174            },
 52175            "quantitativeAnalysis": {
 52176              "graphics": {}
 52177            },
 52178            "considerations": {}
 52179          }
 52180        },
 52181        {
 52182          "type": "library",
 52183          "bom-ref": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=435885c82afbf721",
 52184          "supplier": {},
 52185          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52186          "name": "mawk",
 52187          "version": "1.3.4.20200120-2",
 52188          "licenses": [
 52189            {
 52190              "license": {
 52191                "id": "GPL-2.0-only"
 52192              }
 52193            }
 52194          ],
 52195          "cpe": "cpe:2.3:a:mawk:mawk:1.3.4.20200120-2:*:*:*:*:*:*:*",
 52196          "purl": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04",
 52197          "swid": {
 52198            "attachment": {}
 52199          },
 52200          "pedigree": {},
 52201          "evidence": {},
 52202          "signature": {
 52203            "signature": {
 52204              "publicKey": {}
 52205            }
 52206          },
 52207          "modelCard": {
 52208            "modelParameters": {
 52209              "approach": {}
 52210            },
 52211            "quantitativeAnalysis": {
 52212              "graphics": {}
 52213            },
 52214            "considerations": {}
 52215          }
 52216        },
 52217        {
 52218          "type": "library",
 52219          "bom-ref": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=405891a224258a92",
 52220          "supplier": {},
 52221          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52222          "name": "mime-support",
 52223          "version": "3.64ubuntu1",
 52224          "licenses": [
 52225            {
 52226              "license": {
 52227                "name": "Bellcore"
 52228              }
 52229            },
 52230            {
 52231              "license": {
 52232                "name": "ad-hoc"
 52233              }
 52234            }
 52235          ],
 52236          "cpe": "cpe:2.3:a:mime-support:mime-support:3.64ubuntu1:*:*:*:*:*:*:*",
 52237          "purl": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04",
 52238          "swid": {
 52239            "attachment": {}
 52240          },
 52241          "pedigree": {},
 52242          "evidence": {},
 52243          "signature": {
 52244            "signature": {
 52245              "publicKey": {}
 52246            }
 52247          },
 52248          "modelCard": {
 52249            "modelParameters": {
 52250              "approach": {}
 52251            },
 52252            "quantitativeAnalysis": {
 52253              "graphics": {}
 52254            },
 52255            "considerations": {}
 52256          }
 52257        },
 52258        {
 52259          "type": "library",
 52260          "bom-ref": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=fa4ef6b12af7900c",
 52261          "supplier": {},
 52262          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52263          "name": "mount",
 52264          "version": "2.34-0.1ubuntu9.1",
 52265          "licenses": [
 52266            {
 52267              "license": {
 52268                "id": "BSD-2-Clause"
 52269              }
 52270            },
 52271            {
 52272              "license": {
 52273                "id": "BSD-3-Clause"
 52274              }
 52275            },
 52276            {
 52277              "license": {
 52278                "id": "BSD-4-Clause"
 52279              }
 52280            },
 52281            {
 52282              "license": {
 52283                "id": "GPL-2.0-only"
 52284              }
 52285            },
 52286            {
 52287              "license": {
 52288                "id": "GPL-2.0-or-later"
 52289              }
 52290            },
 52291            {
 52292              "license": {
 52293                "id": "GPL-3.0-only"
 52294              }
 52295            },
 52296            {
 52297              "license": {
 52298                "id": "GPL-3.0-or-later"
 52299              }
 52300            },
 52301            {
 52302              "license": {
 52303                "name": "LGPL"
 52304              }
 52305            },
 52306            {
 52307              "license": {
 52308                "id": "LGPL-2.0-only"
 52309              }
 52310            },
 52311            {
 52312              "license": {
 52313                "id": "LGPL-2.0-or-later"
 52314              }
 52315            },
 52316            {
 52317              "license": {
 52318                "id": "LGPL-2.1-only"
 52319              }
 52320            },
 52321            {
 52322              "license": {
 52323                "id": "LGPL-2.1-or-later"
 52324              }
 52325            },
 52326            {
 52327              "license": {
 52328                "id": "LGPL-3.0-only"
 52329              }
 52330            },
 52331            {
 52332              "license": {
 52333                "id": "LGPL-3.0-or-later"
 52334              }
 52335            },
 52336            {
 52337              "license": {
 52338                "id": "MIT"
 52339              }
 52340            },
 52341            {
 52342              "license": {
 52343                "name": "public-domain"
 52344              }
 52345            }
 52346          ],
 52347          "cpe": "cpe:2.3:a:mount:mount:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 52348          "purl": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 52349          "swid": {
 52350            "attachment": {}
 52351          },
 52352          "pedigree": {},
 52353          "evidence": {},
 52354          "signature": {
 52355            "signature": {
 52356              "publicKey": {}
 52357            }
 52358          },
 52359          "modelCard": {
 52360            "modelParameters": {
 52361              "approach": {}
 52362            },
 52363            "quantitativeAnalysis": {
 52364              "graphics": {}
 52365            },
 52366            "considerations": {}
 52367          }
 52368        },
 52369        {
 52370          "type": "library",
 52371          "bom-ref": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d7393defd95e4554",
 52372          "supplier": {},
 52373          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52374          "name": "ncurses-base",
 52375          "version": "6.2-0ubuntu2",
 52376          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.2-0ubuntu2:*:*:*:*:*:*:*",
 52377          "purl": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 52378          "swid": {
 52379            "attachment": {}
 52380          },
 52381          "pedigree": {},
 52382          "evidence": {},
 52383          "signature": {
 52384            "signature": {
 52385              "publicKey": {}
 52386            }
 52387          },
 52388          "modelCard": {
 52389            "modelParameters": {
 52390              "approach": {}
 52391            },
 52392            "quantitativeAnalysis": {
 52393              "graphics": {}
 52394            },
 52395            "considerations": {}
 52396          }
 52397        },
 52398        {
 52399          "type": "library",
 52400          "bom-ref": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d6bdd43961b680f6",
 52401          "supplier": {},
 52402          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52403          "name": "ncurses-bin",
 52404          "version": "6.2-0ubuntu2",
 52405          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.2-0ubuntu2:*:*:*:*:*:*:*",
 52406          "purl": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 52407          "swid": {
 52408            "attachment": {}
 52409          },
 52410          "pedigree": {},
 52411          "evidence": {},
 52412          "signature": {
 52413            "signature": {
 52414              "publicKey": {}
 52415            }
 52416          },
 52417          "modelCard": {
 52418            "modelParameters": {
 52419              "approach": {}
 52420            },
 52421            "quantitativeAnalysis": {
 52422              "graphics": {}
 52423            },
 52424            "considerations": {}
 52425          }
 52426        },
 52427        {
 52428          "type": "library",
 52429          "bom-ref": "pkg:deb/ubuntu/netbase@6.1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=c6847a50307ac1ba",
 52430          "supplier": {},
 52431          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52432          "name": "netbase",
 52433          "version": "6.1",
 52434          "licenses": [
 52435            {
 52436              "license": {
 52437                "id": "GPL-2.0-only"
 52438              }
 52439            }
 52440          ],
 52441          "cpe": "cpe:2.3:a:netbase:netbase:6.1:*:*:*:*:*:*:*",
 52442          "purl": "pkg:deb/ubuntu/netbase@6.1?arch=all\u0026distro=ubuntu-20.04",
 52443          "swid": {
 52444            "attachment": {}
 52445          },
 52446          "pedigree": {},
 52447          "evidence": {},
 52448          "signature": {
 52449            "signature": {
 52450              "publicKey": {}
 52451            }
 52452          },
 52453          "modelCard": {
 52454            "modelParameters": {
 52455              "approach": {}
 52456            },
 52457            "quantitativeAnalysis": {
 52458              "graphics": {}
 52459            },
 52460            "considerations": {}
 52461          }
 52462        },
 52463        {
 52464          "type": "library",
 52465          "bom-ref": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04\u0026package-id=6a00c331080f32b7",
 52466          "supplier": {},
 52467          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52468          "name": "nfs-common",
 52469          "version": "1:1.3.4-2.5ubuntu3.4",
 52470          "licenses": [
 52471            {
 52472              "license": {
 52473                "id": "GPL-2.0-only"
 52474              }
 52475            }
 52476          ],
 52477          "cpe": "cpe:2.3:a:nfs-common:nfs-common:1\\:1.3.4-2.5ubuntu3.4:*:*:*:*:*:*:*",
 52478          "purl": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04",
 52479          "swid": {
 52480            "attachment": {}
 52481          },
 52482          "pedigree": {},
 52483          "evidence": {},
 52484          "signature": {
 52485            "signature": {
 52486              "publicKey": {}
 52487            }
 52488          },
 52489          "modelCard": {
 52490            "modelParameters": {
 52491              "approach": {}
 52492            },
 52493            "quantitativeAnalysis": {
 52494              "graphics": {}
 52495            },
 52496            "considerations": {}
 52497          }
 52498        },
 52499        {
 52500          "type": "library",
 52501          "bom-ref": "pkg:deb/ubuntu/openssl@1.1.1f-1ubuntu2.9?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=606e5374106f5ebb",
 52502          "supplier": {},
 52503          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52504          "name": "openssl",
 52505          "version": "1.1.1f-1ubuntu2.9",
 52506          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1f-1ubuntu2.9:*:*:*:*:*:*:*",
 52507          "purl": "pkg:deb/ubuntu/openssl@1.1.1f-1ubuntu2.9?arch=amd64\u0026distro=ubuntu-20.04",
 52508          "swid": {
 52509            "attachment": {}
 52510          },
 52511          "pedigree": {},
 52512          "evidence": {},
 52513          "signature": {
 52514            "signature": {
 52515              "publicKey": {}
 52516            }
 52517          },
 52518          "modelCard": {
 52519            "modelParameters": {
 52520              "approach": {}
 52521            },
 52522            "quantitativeAnalysis": {
 52523              "graphics": {}
 52524            },
 52525            "considerations": {}
 52526          }
 52527        },
 52528        {
 52529          "type": "library",
 52530          "bom-ref": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=c4a1ed5267891532",
 52531          "supplier": {},
 52532          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52533          "name": "passwd",
 52534          "version": "1:4.8.1-1ubuntu5.20.04.1",
 52535          "licenses": [
 52536            {
 52537              "license": {
 52538                "id": "GPL-2.0-only"
 52539              }
 52540            }
 52541          ],
 52542          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
 52543          "purl": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
 52544          "swid": {
 52545            "attachment": {}
 52546          },
 52547          "pedigree": {},
 52548          "evidence": {},
 52549          "signature": {
 52550            "signature": {
 52551              "publicKey": {}
 52552            }
 52553          },
 52554          "modelCard": {
 52555            "modelParameters": {
 52556              "approach": {}
 52557            },
 52558            "quantitativeAnalysis": {
 52559              "graphics": {}
 52560            },
 52561            "considerations": {}
 52562          }
 52563        },
 52564        {
 52565          "type": "library",
 52566          "bom-ref": "pkg:deb/ubuntu/perl@5.30.0-9ubuntu0.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=80890d41e31d4ad9",
 52567          "supplier": {},
 52568          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52569          "name": "perl",
 52570          "version": "5.30.0-9ubuntu0.2",
 52571          "licenses": [
 52572            {
 52573              "license": {
 52574                "name": "Artistic"
 52575              }
 52576            },
 52577            {
 52578              "license": {
 52579                "id": "Artistic-2.0"
 52580              }
 52581            },
 52582            {
 52583              "license": {
 52584                "name": "Artistic-dist"
 52585              }
 52586            },
 52587            {
 52588              "license": {
 52589                "id": "BSD-3-Clause"
 52590              }
 52591            },
 52592            {
 52593              "license": {
 52594                "name": "BSD-3-clause-GENERIC"
 52595              }
 52596            },
 52597            {
 52598              "license": {
 52599                "name": "BSD-3-clause-with-weird-numbering"
 52600              }
 52601            },
 52602            {
 52603              "license": {
 52604                "name": "BSD-4-clause-POWERDOG"
 52605              }
 52606            },
 52607            {
 52608              "license": {
 52609                "name": "BZIP"
 52610              }
 52611            },
 52612            {
 52613              "license": {
 52614                "name": "DONT-CHANGE-THE-GPL"
 52615              }
 52616            },
 52617            {
 52618              "license": {
 52619                "name": "Expat"
 52620              }
 52621            },
 52622            {
 52623              "license": {
 52624                "id": "GPL-1.0-only"
 52625              }
 52626            },
 52627            {
 52628              "license": {
 52629                "id": "GPL-1.0-or-later"
 52630              }
 52631            },
 52632            {
 52633              "license": {
 52634                "id": "GPL-2.0-only"
 52635              }
 52636            },
 52637            {
 52638              "license": {
 52639                "id": "GPL-2.0-or-later"
 52640              }
 52641            },
 52642            {
 52643              "license": {
 52644                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 52645              }
 52646            },
 52647            {
 52648              "license": {
 52649                "name": "HSIEH-BSD"
 52650              }
 52651            },
 52652            {
 52653              "license": {
 52654                "name": "HSIEH-DERIVATIVE"
 52655              }
 52656            },
 52657            {
 52658              "license": {
 52659                "id": "LGPL-2.1-only"
 52660              }
 52661            },
 52662            {
 52663              "license": {
 52664                "name": "REGCOMP"
 52665              }
 52666            },
 52667            {
 52668              "license": {
 52669                "name": "REGCOMP,"
 52670              }
 52671            },
 52672            {
 52673              "license": {
 52674                "name": "RRA-KEEP-THIS-NOTICE"
 52675              }
 52676            },
 52677            {
 52678              "license": {
 52679                "name": "SDBM-PUBLIC-DOMAIN"
 52680              }
 52681            },
 52682            {
 52683              "license": {
 52684                "name": "TEXT-TABS"
 52685              }
 52686            },
 52687            {
 52688              "license": {
 52689                "name": "Unicode"
 52690              }
 52691            },
 52692            {
 52693              "license": {
 52694                "id": "Zlib"
 52695              }
 52696            }
 52697          ],
 52698          "cpe": "cpe:2.3:a:perl:perl:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
 52699          "purl": "pkg:deb/ubuntu/perl@5.30.0-9ubuntu0.2?arch=amd64\u0026distro=ubuntu-20.04",
 52700          "swid": {
 52701            "attachment": {}
 52702          },
 52703          "pedigree": {},
 52704          "evidence": {},
 52705          "signature": {
 52706            "signature": {
 52707              "publicKey": {}
 52708            }
 52709          },
 52710          "modelCard": {
 52711            "modelParameters": {
 52712              "approach": {}
 52713            },
 52714            "quantitativeAnalysis": {
 52715              "graphics": {}
 52716            },
 52717            "considerations": {}
 52718          }
 52719        },
 52720        {
 52721          "type": "library",
 52722          "bom-ref": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=eab1752e76cf29f",
 52723          "supplier": {},
 52724          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52725          "name": "perl-base",
 52726          "version": "5.30.0-9ubuntu0.2",
 52727          "licenses": [
 52728            {
 52729              "license": {
 52730                "name": "Artistic"
 52731              }
 52732            },
 52733            {
 52734              "license": {
 52735                "id": "Artistic-2.0"
 52736              }
 52737            },
 52738            {
 52739              "license": {
 52740                "name": "Artistic-dist"
 52741              }
 52742            },
 52743            {
 52744              "license": {
 52745                "id": "BSD-3-Clause"
 52746              }
 52747            },
 52748            {
 52749              "license": {
 52750                "name": "BSD-3-clause-GENERIC"
 52751              }
 52752            },
 52753            {
 52754              "license": {
 52755                "name": "BSD-3-clause-with-weird-numbering"
 52756              }
 52757            },
 52758            {
 52759              "license": {
 52760                "name": "BSD-4-clause-POWERDOG"
 52761              }
 52762            },
 52763            {
 52764              "license": {
 52765                "name": "BZIP"
 52766              }
 52767            },
 52768            {
 52769              "license": {
 52770                "name": "DONT-CHANGE-THE-GPL"
 52771              }
 52772            },
 52773            {
 52774              "license": {
 52775                "name": "Expat"
 52776              }
 52777            },
 52778            {
 52779              "license": {
 52780                "id": "GPL-1.0-only"
 52781              }
 52782            },
 52783            {
 52784              "license": {
 52785                "id": "GPL-1.0-or-later"
 52786              }
 52787            },
 52788            {
 52789              "license": {
 52790                "id": "GPL-2.0-only"
 52791              }
 52792            },
 52793            {
 52794              "license": {
 52795                "id": "GPL-2.0-or-later"
 52796              }
 52797            },
 52798            {
 52799              "license": {
 52800                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 52801              }
 52802            },
 52803            {
 52804              "license": {
 52805                "name": "HSIEH-BSD"
 52806              }
 52807            },
 52808            {
 52809              "license": {
 52810                "name": "HSIEH-DERIVATIVE"
 52811              }
 52812            },
 52813            {
 52814              "license": {
 52815                "id": "LGPL-2.1-only"
 52816              }
 52817            },
 52818            {
 52819              "license": {
 52820                "name": "REGCOMP"
 52821              }
 52822            },
 52823            {
 52824              "license": {
 52825                "name": "REGCOMP,"
 52826              }
 52827            },
 52828            {
 52829              "license": {
 52830                "name": "RRA-KEEP-THIS-NOTICE"
 52831              }
 52832            },
 52833            {
 52834              "license": {
 52835                "name": "SDBM-PUBLIC-DOMAIN"
 52836              }
 52837            },
 52838            {
 52839              "license": {
 52840                "name": "TEXT-TABS"
 52841              }
 52842            },
 52843            {
 52844              "license": {
 52845                "name": "Unicode"
 52846              }
 52847            },
 52848            {
 52849              "license": {
 52850                "id": "Zlib"
 52851              }
 52852            }
 52853          ],
 52854          "cpe": "cpe:2.3:a:perl-base:perl-base:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
 52855          "purl": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04",
 52856          "swid": {
 52857            "attachment": {}
 52858          },
 52859          "pedigree": {},
 52860          "evidence": {},
 52861          "signature": {
 52862            "signature": {
 52863              "publicKey": {}
 52864            }
 52865          },
 52866          "modelCard": {
 52867            "modelParameters": {
 52868              "approach": {}
 52869            },
 52870            "quantitativeAnalysis": {
 52871              "graphics": {}
 52872            },
 52873            "considerations": {}
 52874          }
 52875        },
 52876        {
 52877          "type": "library",
 52878          "bom-ref": "pkg:deb/ubuntu/perl-modules-5.30@5.30.0-9ubuntu0.2?arch=all\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=fb3bcb2d22f50638",
 52879          "supplier": {},
 52880          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 52881          "name": "perl-modules-5.30",
 52882          "version": "5.30.0-9ubuntu0.2",
 52883          "licenses": [
 52884            {
 52885              "license": {
 52886                "name": "Artistic"
 52887              }
 52888            },
 52889            {
 52890              "license": {
 52891                "id": "Artistic-2.0"
 52892              }
 52893            },
 52894            {
 52895              "license": {
 52896                "name": "Artistic-dist"
 52897              }
 52898            },
 52899            {
 52900              "license": {
 52901                "id": "BSD-3-Clause"
 52902              }
 52903            },
 52904            {
 52905              "license": {
 52906                "name": "BSD-3-clause-GENERIC"
 52907              }
 52908            },
 52909            {
 52910              "license": {
 52911                "name": "BSD-3-clause-with-weird-numbering"
 52912              }
 52913            },
 52914            {
 52915              "license": {
 52916                "name": "BSD-4-clause-POWERDOG"
 52917              }
 52918            },
 52919            {
 52920              "license": {
 52921                "name": "BZIP"
 52922              }
 52923            },
 52924            {
 52925              "license": {
 52926                "name": "DONT-CHANGE-THE-GPL"
 52927              }
 52928            },
 52929            {
 52930              "license": {
 52931                "name": "Expat"
 52932              }
 52933            },
 52934            {
 52935              "license": {
 52936                "id": "GPL-1.0-only"
 52937              }
 52938            },
 52939            {
 52940              "license": {
 52941                "id": "GPL-1.0-or-later"
 52942              }
 52943            },
 52944            {
 52945              "license": {
 52946                "id": "GPL-2.0-only"
 52947              }
 52948            },
 52949            {
 52950              "license": {
 52951                "id": "GPL-2.0-or-later"
 52952              }
 52953            },
 52954            {
 52955              "license": {
 52956                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 52957              }
 52958            },
 52959            {
 52960              "license": {
 52961                "name": "HSIEH-BSD"
 52962              }
 52963            },
 52964            {
 52965              "license": {
 52966                "name": "HSIEH-DERIVATIVE"
 52967              }
 52968            },
 52969            {
 52970              "license": {
 52971                "id": "LGPL-2.1-only"
 52972              }
 52973            },
 52974            {
 52975              "license": {
 52976                "name": "REGCOMP"
 52977              }
 52978            },
 52979            {
 52980              "license": {
 52981                "name": "REGCOMP,"
 52982              }
 52983            },
 52984            {
 52985              "license": {
 52986                "name": "RRA-KEEP-THIS-NOTICE"
 52987              }
 52988            },
 52989            {
 52990              "license": {
 52991                "name": "SDBM-PUBLIC-DOMAIN"
 52992              }
 52993            },
 52994            {
 52995              "license": {
 52996                "name": "TEXT-TABS"
 52997              }
 52998            },
 52999            {
 53000              "license": {
 53001                "name": "Unicode"
 53002              }
 53003            },
 53004            {
 53005              "license": {
 53006                "id": "Zlib"
 53007              }
 53008            }
 53009          ],
 53010          "cpe": "cpe:2.3:a:perl-modules-5.30:perl-modules-5.30:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
 53011          "purl": "pkg:deb/ubuntu/perl-modules-5.30@5.30.0-9ubuntu0.2?arch=all\u0026upstream=perl\u0026distro=ubuntu-20.04",
 53012          "swid": {
 53013            "attachment": {}
 53014          },
 53015          "pedigree": {},
 53016          "evidence": {},
 53017          "signature": {
 53018            "signature": {
 53019              "publicKey": {}
 53020            }
 53021          },
 53022          "modelCard": {
 53023            "modelParameters": {
 53024              "approach": {}
 53025            },
 53026            "quantitativeAnalysis": {
 53027              "graphics": {}
 53028            },
 53029            "considerations": {}
 53030          }
 53031        },
 53032        {
 53033          "type": "library",
 53034          "bom-ref": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=1b952d75ffac7280",
 53035          "supplier": {},
 53036          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53037          "name": "procps",
 53038          "version": "2:3.3.16-1ubuntu2.3",
 53039          "licenses": [
 53040            {
 53041              "license": {
 53042                "id": "GPL-2.0-only"
 53043              }
 53044            },
 53045            {
 53046              "license": {
 53047                "id": "GPL-2.0-or-later"
 53048              }
 53049            },
 53050            {
 53051              "license": {
 53052                "id": "LGPL-2.0-only"
 53053              }
 53054            },
 53055            {
 53056              "license": {
 53057                "id": "LGPL-2.0-or-later"
 53058              }
 53059            },
 53060            {
 53061              "license": {
 53062                "id": "LGPL-2.1-only"
 53063              }
 53064            },
 53065            {
 53066              "license": {
 53067                "id": "LGPL-2.1-or-later"
 53068              }
 53069            }
 53070          ],
 53071          "cpe": "cpe:2.3:a:procps:procps:2\\:3.3.16-1ubuntu2.3:*:*:*:*:*:*:*",
 53072          "purl": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.3?arch=amd64\u0026distro=ubuntu-20.04",
 53073          "swid": {
 53074            "attachment": {}
 53075          },
 53076          "pedigree": {},
 53077          "evidence": {},
 53078          "signature": {
 53079            "signature": {
 53080              "publicKey": {}
 53081            }
 53082          },
 53083          "modelCard": {
 53084            "modelParameters": {
 53085              "approach": {}
 53086            },
 53087            "quantitativeAnalysis": {
 53088              "graphics": {}
 53089            },
 53090            "considerations": {}
 53091          }
 53092        },
 53093        {
 53094          "type": "library",
 53095          "bom-ref": "pkg:deb/ubuntu/publicsuffix@20200303.0012-1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=fe371293cddb3ef3",
 53096          "supplier": {},
 53097          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53098          "name": "publicsuffix",
 53099          "version": "20200303.0012-1",
 53100          "licenses": [
 53101            {
 53102              "license": {
 53103                "name": "CC0"
 53104              }
 53105            },
 53106            {
 53107              "license": {
 53108                "id": "MPL-2.0"
 53109              }
 53110            }
 53111          ],
 53112          "cpe": "cpe:2.3:a:publicsuffix:publicsuffix:20200303.0012-1:*:*:*:*:*:*:*",
 53113          "purl": "pkg:deb/ubuntu/publicsuffix@20200303.0012-1?arch=all\u0026distro=ubuntu-20.04",
 53114          "swid": {
 53115            "attachment": {}
 53116          },
 53117          "pedigree": {},
 53118          "evidence": {},
 53119          "signature": {
 53120            "signature": {
 53121              "publicKey": {}
 53122            }
 53123          },
 53124          "modelCard": {
 53125            "modelParameters": {
 53126              "approach": {}
 53127            },
 53128            "quantitativeAnalysis": {
 53129              "graphics": {}
 53130            },
 53131            "considerations": {}
 53132          }
 53133        },
 53134        {
 53135          "type": "application",
 53136          "bom-ref": "pkg:generic/python@3.8.10?package-id=8336df5bcdddc1a4",
 53137          "supplier": {},
 53138          "name": "python",
 53139          "version": "3.8.10",
 53140          "cpe": "cpe:2.3:a:python_software_foundation:python:3.8.10:*:*:*:*:*:*:*",
 53141          "purl": "pkg:generic/python@3.8.10",
 53142          "swid": {
 53143            "attachment": {}
 53144          },
 53145          "pedigree": {},
 53146          "evidence": {},
 53147          "signature": {
 53148            "signature": {
 53149              "publicKey": {}
 53150            }
 53151          },
 53152          "modelCard": {
 53153            "modelParameters": {
 53154              "approach": {}
 53155            },
 53156            "quantitativeAnalysis": {
 53157              "graphics": {}
 53158            },
 53159            "considerations": {}
 53160          }
 53161        },
 53162        {
 53163          "type": "library",
 53164          "bom-ref": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=ca939acbf264771",
 53165          "supplier": {},
 53166          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53167          "name": "python3",
 53168          "version": "3.8.2-0ubuntu2",
 53169          "cpe": "cpe:2.3:a:python3:python3:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
 53170          "purl": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
 53171          "swid": {
 53172            "attachment": {}
 53173          },
 53174          "pedigree": {},
 53175          "evidence": {},
 53176          "signature": {
 53177            "signature": {
 53178              "publicKey": {}
 53179            }
 53180          },
 53181          "modelCard": {
 53182            "modelParameters": {
 53183              "approach": {}
 53184            },
 53185            "quantitativeAnalysis": {
 53186              "graphics": {}
 53187            },
 53188            "considerations": {}
 53189          }
 53190        },
 53191        {
 53192          "type": "library",
 53193          "bom-ref": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=26eebf392e0b02cf",
 53194          "supplier": {},
 53195          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53196          "name": "python3-minimal",
 53197          "version": "3.8.2-0ubuntu2",
 53198          "cpe": "cpe:2.3:a:python3-minimal:python3-minimal:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
 53199          "purl": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
 53200          "swid": {
 53201            "attachment": {}
 53202          },
 53203          "pedigree": {},
 53204          "evidence": {},
 53205          "signature": {
 53206            "signature": {
 53207              "publicKey": {}
 53208            }
 53209          },
 53210          "modelCard": {
 53211            "modelParameters": {
 53212              "approach": {}
 53213            },
 53214            "quantitativeAnalysis": {
 53215              "graphics": {}
 53216            },
 53217            "considerations": {}
 53218          }
 53219        },
 53220        {
 53221          "type": "library",
 53222          "bom-ref": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=fa10b88b12106de4",
 53223          "supplier": {},
 53224          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53225          "name": "python3.8",
 53226          "version": "3.8.10-0ubuntu1~20.04.1",
 53227          "licenses": [
 53228            {
 53229              "license": {
 53230                "name": "By"
 53231              }
 53232            },
 53233            {
 53234              "license": {
 53235                "id": "GPL-2.0-only"
 53236              }
 53237            },
 53238            {
 53239              "license": {
 53240                "name": "Permission"
 53241              }
 53242            },
 53243            {
 53244              "license": {
 53245                "name": "Redistribution"
 53246              }
 53247            },
 53248            {
 53249              "license": {
 53250                "name": "This"
 53251              }
 53252            }
 53253          ],
 53254          "cpe": "cpe:2.3:a:python3.8:python3.8:3.8.10-0ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
 53255          "purl": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
 53256          "swid": {
 53257            "attachment": {}
 53258          },
 53259          "pedigree": {},
 53260          "evidence": {},
 53261          "signature": {
 53262            "signature": {
 53263              "publicKey": {}
 53264            }
 53265          },
 53266          "modelCard": {
 53267            "modelParameters": {
 53268              "approach": {}
 53269            },
 53270            "quantitativeAnalysis": {
 53271              "graphics": {}
 53272            },
 53273            "considerations": {}
 53274          }
 53275        },
 53276        {
 53277          "type": "library",
 53278          "bom-ref": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04.1?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=c228c418b8a875e0",
 53279          "supplier": {},
 53280          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53281          "name": "python3.8-minimal",
 53282          "version": "3.8.10-0ubuntu1~20.04.1",
 53283          "licenses": [
 53284            {
 53285              "license": {
 53286                "name": "By"
 53287              }
 53288            },
 53289            {
 53290              "license": {
 53291                "id": "GPL-2.0-only"
 53292              }
 53293            },
 53294            {
 53295              "license": {
 53296                "name": "Permission"
 53297              }
 53298            },
 53299            {
 53300              "license": {
 53301                "name": "Redistribution"
 53302              }
 53303            },
 53304            {
 53305              "license": {
 53306                "name": "This"
 53307              }
 53308            }
 53309          ],
 53310          "cpe": "cpe:2.3:a:python3.8-minimal:python3.8-minimal:3.8.10-0ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
 53311          "purl": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04.1?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 53312          "swid": {
 53313            "attachment": {}
 53314          },
 53315          "pedigree": {},
 53316          "evidence": {},
 53317          "signature": {
 53318            "signature": {
 53319              "publicKey": {}
 53320            }
 53321          },
 53322          "modelCard": {
 53323            "modelParameters": {
 53324              "approach": {}
 53325            },
 53326            "quantitativeAnalysis": {
 53327              "graphics": {}
 53328            },
 53329            "considerations": {}
 53330          }
 53331        },
 53332        {
 53333          "type": "library",
 53334          "bom-ref": "pkg:deb/ubuntu/qemu-block-extra@1:4.2-3ubuntu6.18?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04\u0026package-id=c61b4f09d823d283",
 53335          "supplier": {},
 53336          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53337          "name": "qemu-block-extra",
 53338          "version": "1:4.2-3ubuntu6.18",
 53339          "licenses": [
 53340            {
 53341              "license": {
 53342                "id": "GPL-2.0-only"
 53343              }
 53344            },
 53345            {
 53346              "license": {
 53347                "id": "LGPL-2.0-only"
 53348              }
 53349            }
 53350          ],
 53351          "cpe": "cpe:2.3:a:qemu-block-extra:qemu-block-extra:1\\:4.2-3ubuntu6.18:*:*:*:*:*:*:*",
 53352          "purl": "pkg:deb/ubuntu/qemu-block-extra@1:4.2-3ubuntu6.18?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04",
 53353          "swid": {
 53354            "attachment": {}
 53355          },
 53356          "pedigree": {},
 53357          "evidence": {},
 53358          "signature": {
 53359            "signature": {
 53360              "publicKey": {}
 53361            }
 53362          },
 53363          "modelCard": {
 53364            "modelParameters": {
 53365              "approach": {}
 53366            },
 53367            "quantitativeAnalysis": {
 53368              "graphics": {}
 53369            },
 53370            "considerations": {}
 53371          }
 53372        },
 53373        {
 53374          "type": "library",
 53375          "bom-ref": "pkg:deb/ubuntu/qemu-utils@1:4.2-3ubuntu6.18?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04\u0026package-id=8bcef6c4d564e481",
 53376          "supplier": {},
 53377          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53378          "name": "qemu-utils",
 53379          "version": "1:4.2-3ubuntu6.18",
 53380          "licenses": [
 53381            {
 53382              "license": {
 53383                "id": "GPL-2.0-only"
 53384              }
 53385            },
 53386            {
 53387              "license": {
 53388                "id": "LGPL-2.0-only"
 53389              }
 53390            }
 53391          ],
 53392          "cpe": "cpe:2.3:a:qemu-utils:qemu-utils:1\\:4.2-3ubuntu6.18:*:*:*:*:*:*:*",
 53393          "purl": "pkg:deb/ubuntu/qemu-utils@1:4.2-3ubuntu6.18?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04",
 53394          "swid": {
 53395            "attachment": {}
 53396          },
 53397          "pedigree": {},
 53398          "evidence": {},
 53399          "signature": {
 53400            "signature": {
 53401              "publicKey": {}
 53402            }
 53403          },
 53404          "modelCard": {
 53405            "modelParameters": {
 53406              "approach": {}
 53407            },
 53408            "quantitativeAnalysis": {
 53409              "graphics": {}
 53410            },
 53411            "considerations": {}
 53412          }
 53413        },
 53414        {
 53415          "type": "library",
 53416          "bom-ref": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=34a85b4423ecbe7",
 53417          "supplier": {},
 53418          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53419          "name": "readline-common",
 53420          "version": "8.0-4",
 53421          "licenses": [
 53422            {
 53423              "license": {
 53424                "name": "GFDL"
 53425              }
 53426            },
 53427            {
 53428              "license": {
 53429                "id": "GPL-3.0-only"
 53430              }
 53431            }
 53432          ],
 53433          "cpe": "cpe:2.3:a:readline-common:readline-common:8.0-4:*:*:*:*:*:*:*",
 53434          "purl": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04",
 53435          "swid": {
 53436            "attachment": {}
 53437          },
 53438          "pedigree": {},
 53439          "evidence": {},
 53440          "signature": {
 53441            "signature": {
 53442              "publicKey": {}
 53443            }
 53444          },
 53445          "modelCard": {
 53446            "modelParameters": {
 53447              "approach": {}
 53448            },
 53449            "quantitativeAnalysis": {
 53450              "graphics": {}
 53451            },
 53452            "considerations": {}
 53453          }
 53454        },
 53455        {
 53456          "type": "library",
 53457          "bom-ref": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e98d3334085e4495",
 53458          "supplier": {},
 53459          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53460          "name": "rpcbind",
 53461          "version": "1.2.5-8",
 53462          "licenses": [
 53463            {
 53464              "license": {
 53465                "id": "BSD-3-Clause"
 53466              }
 53467            },
 53468            {
 53469              "license": {
 53470                "id": "BSD-4-Clause"
 53471              }
 53472            },
 53473            {
 53474              "license": {
 53475                "id": "BSD-4-Clause"
 53476              }
 53477            },
 53478            {
 53479              "license": {
 53480                "id": "GPL-2.0-only"
 53481              }
 53482            },
 53483            {
 53484              "license": {
 53485                "id": "GPL-2.0-or-later"
 53486              }
 53487            },
 53488            {
 53489              "license": {
 53490                "id": "GPL-3.0-only"
 53491              }
 53492            },
 53493            {
 53494              "license": {
 53495                "id": "MIT"
 53496              }
 53497            },
 53498            {
 53499              "license": {
 53500                "name": "PERMISSIVE"
 53501              }
 53502            }
 53503          ],
 53504          "cpe": "cpe:2.3:a:rpcbind:rpcbind:1.2.5-8:*:*:*:*:*:*:*",
 53505          "purl": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04",
 53506          "swid": {
 53507            "attachment": {}
 53508          },
 53509          "pedigree": {},
 53510          "evidence": {},
 53511          "signature": {
 53512            "signature": {
 53513              "publicKey": {}
 53514            }
 53515          },
 53516          "modelCard": {
 53517            "modelParameters": {
 53518              "approach": {}
 53519            },
 53520            "quantitativeAnalysis": {
 53521              "graphics": {}
 53522            },
 53523            "considerations": {}
 53524          }
 53525        },
 53526        {
 53527          "type": "library",
 53528          "bom-ref": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=24bbb8989a1870c7",
 53529          "supplier": {},
 53530          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53531          "name": "sed",
 53532          "version": "4.7-1",
 53533          "licenses": [
 53534            {
 53535              "license": {
 53536                "id": "GPL-3.0-only"
 53537              }
 53538            }
 53539          ],
 53540          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
 53541          "purl": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04",
 53542          "swid": {
 53543            "attachment": {}
 53544          },
 53545          "pedigree": {},
 53546          "evidence": {},
 53547          "signature": {
 53548            "signature": {
 53549              "publicKey": {}
 53550            }
 53551          },
 53552          "modelCard": {
 53553            "modelParameters": {
 53554              "approach": {}
 53555            },
 53556            "quantitativeAnalysis": {
 53557              "graphics": {}
 53558            },
 53559            "considerations": {}
 53560          }
 53561        },
 53562        {
 53563          "type": "library",
 53564          "bom-ref": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=7e50cf6ac335106e",
 53565          "supplier": {},
 53566          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53567          "name": "sensible-utils",
 53568          "version": "0.0.12+nmu1",
 53569          "licenses": [
 53570            {
 53571              "license": {
 53572                "name": "All-permissive"
 53573              }
 53574            },
 53575            {
 53576              "license": {
 53577                "id": "GPL-2.0-only"
 53578              }
 53579            },
 53580            {
 53581              "license": {
 53582                "id": "GPL-2.0-or-later"
 53583              }
 53584            },
 53585            {
 53586              "license": {
 53587                "name": "configure"
 53588              }
 53589            },
 53590            {
 53591              "license": {
 53592                "name": "installsh"
 53593              }
 53594            }
 53595          ],
 53596          "cpe": "cpe:2.3:a:sensible-utils:sensible-utils:0.0.12\\+nmu1:*:*:*:*:*:*:*",
 53597          "purl": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04",
 53598          "swid": {
 53599            "attachment": {}
 53600          },
 53601          "pedigree": {},
 53602          "evidence": {},
 53603          "signature": {
 53604            "signature": {
 53605              "publicKey": {}
 53606            }
 53607          },
 53608          "modelCard": {
 53609            "modelParameters": {
 53610              "approach": {}
 53611            },
 53612            "quantitativeAnalysis": {
 53613              "graphics": {}
 53614            },
 53615            "considerations": {}
 53616          }
 53617        },
 53618        {
 53619          "type": "library",
 53620          "bom-ref": "pkg:deb/ubuntu/sg3-utils@1.44-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=794bb1692a1cfa88",
 53621          "supplier": {},
 53622          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53623          "name": "sg3-utils",
 53624          "version": "1.44-1ubuntu2",
 53625          "licenses": [
 53626            {
 53627              "license": {
 53628                "name": "GPL"
 53629              }
 53630            }
 53631          ],
 53632          "cpe": "cpe:2.3:a:sg3-utils:sg3-utils:1.44-1ubuntu2:*:*:*:*:*:*:*",
 53633          "purl": "pkg:deb/ubuntu/sg3-utils@1.44-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
 53634          "swid": {
 53635            "attachment": {}
 53636          },
 53637          "pedigree": {},
 53638          "evidence": {},
 53639          "signature": {
 53640            "signature": {
 53641              "publicKey": {}
 53642            }
 53643          },
 53644          "modelCard": {
 53645            "modelParameters": {
 53646              "approach": {}
 53647            },
 53648            "quantitativeAnalysis": {
 53649              "graphics": {}
 53650            },
 53651            "considerations": {}
 53652          }
 53653        },
 53654        {
 53655          "type": "library",
 53656          "bom-ref": "pkg:deb/ubuntu/shared-mime-info@1.15-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=c15ede029a3e38cd",
 53657          "supplier": {},
 53658          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53659          "name": "shared-mime-info",
 53660          "version": "1.15-1",
 53661          "licenses": [
 53662            {
 53663              "license": {
 53664                "name": "GPL"
 53665              }
 53666            }
 53667          ],
 53668          "cpe": "cpe:2.3:a:shared-mime-info:shared-mime-info:1.15-1:*:*:*:*:*:*:*",
 53669          "purl": "pkg:deb/ubuntu/shared-mime-info@1.15-1?arch=amd64\u0026distro=ubuntu-20.04",
 53670          "swid": {
 53671            "attachment": {}
 53672          },
 53673          "pedigree": {},
 53674          "evidence": {},
 53675          "signature": {
 53676            "signature": {
 53677              "publicKey": {}
 53678            }
 53679          },
 53680          "modelCard": {
 53681            "modelParameters": {
 53682              "approach": {}
 53683            },
 53684            "quantitativeAnalysis": {
 53685              "graphics": {}
 53686            },
 53687            "considerations": {}
 53688          }
 53689        },
 53690        {
 53691          "type": "library",
 53692          "bom-ref": "pkg:deb/ubuntu/sharutils@1:4.15.2-4build1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e920784bf62009c0",
 53693          "supplier": {},
 53694          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53695          "name": "sharutils",
 53696          "version": "1:4.15.2-4build1",
 53697          "licenses": [
 53698            {
 53699              "license": {
 53700                "name": "GFDL"
 53701              }
 53702            },
 53703            {
 53704              "license": {
 53705                "name": "GPL"
 53706              }
 53707            }
 53708          ],
 53709          "cpe": "cpe:2.3:a:sharutils:sharutils:1\\:4.15.2-4build1:*:*:*:*:*:*:*",
 53710          "purl": "pkg:deb/ubuntu/sharutils@1:4.15.2-4build1?arch=amd64\u0026distro=ubuntu-20.04",
 53711          "swid": {
 53712            "attachment": {}
 53713          },
 53714          "pedigree": {},
 53715          "evidence": {},
 53716          "signature": {
 53717            "signature": {
 53718              "publicKey": {}
 53719            }
 53720          },
 53721          "modelCard": {
 53722            "modelParameters": {
 53723              "approach": {}
 53724            },
 53725            "quantitativeAnalysis": {
 53726              "graphics": {}
 53727            },
 53728            "considerations": {}
 53729          }
 53730        },
 53731        {
 53732          "type": "library",
 53733          "bom-ref": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04\u0026package-id=abc451774789c392",
 53734          "supplier": {},
 53735          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53736          "name": "sysvinit-utils",
 53737          "version": "2.96-2.1ubuntu1",
 53738          "licenses": [
 53739            {
 53740              "license": {
 53741                "id": "GPL-2.0-only"
 53742              }
 53743            },
 53744            {
 53745              "license": {
 53746                "id": "GPL-2.0-or-later"
 53747              }
 53748            }
 53749          ],
 53750          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.96-2.1ubuntu1:*:*:*:*:*:*:*",
 53751          "purl": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04",
 53752          "swid": {
 53753            "attachment": {}
 53754          },
 53755          "pedigree": {},
 53756          "evidence": {},
 53757          "signature": {
 53758            "signature": {
 53759              "publicKey": {}
 53760            }
 53761          },
 53762          "modelCard": {
 53763            "modelParameters": {
 53764              "approach": {}
 53765            },
 53766            "quantitativeAnalysis": {
 53767              "graphics": {}
 53768            },
 53769            "considerations": {}
 53770          }
 53771        },
 53772        {
 53773          "type": "library",
 53774          "bom-ref": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=4c6cd0d17cc842e",
 53775          "supplier": {},
 53776          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53777          "name": "tar",
 53778          "version": "1.30+dfsg-7ubuntu0.20.04.1",
 53779          "licenses": [
 53780            {
 53781              "license": {
 53782                "id": "GPL-2.0-only"
 53783              }
 53784            },
 53785            {
 53786              "license": {
 53787                "id": "GPL-3.0-only"
 53788              }
 53789            }
 53790          ],
 53791          "cpe": "cpe:2.3:a:tar:tar:1.30\\+dfsg-7ubuntu0.20.04.1:*:*:*:*:*:*:*",
 53792          "purl": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
 53793          "swid": {
 53794            "attachment": {}
 53795          },
 53796          "pedigree": {},
 53797          "evidence": {},
 53798          "signature": {
 53799            "signature": {
 53800              "publicKey": {}
 53801            }
 53802          },
 53803          "modelCard": {
 53804            "modelParameters": {
 53805              "approach": {}
 53806            },
 53807            "quantitativeAnalysis": {
 53808              "graphics": {}
 53809            },
 53810            "considerations": {}
 53811          }
 53812        },
 53813        {
 53814          "type": "library",
 53815          "bom-ref": "pkg:deb/ubuntu/telnet@0.17-41.2build1?arch=amd64\u0026upstream=netkit-telnet\u0026distro=ubuntu-20.04\u0026package-id=440d9ef0dcd8675e",
 53816          "supplier": {},
 53817          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53818          "name": "telnet",
 53819          "version": "0.17-41.2build1",
 53820          "cpe": "cpe:2.3:a:telnet:telnet:0.17-41.2build1:*:*:*:*:*:*:*",
 53821          "purl": "pkg:deb/ubuntu/telnet@0.17-41.2build1?arch=amd64\u0026upstream=netkit-telnet\u0026distro=ubuntu-20.04",
 53822          "swid": {
 53823            "attachment": {}
 53824          },
 53825          "pedigree": {},
 53826          "evidence": {},
 53827          "signature": {
 53828            "signature": {
 53829              "publicKey": {}
 53830            }
 53831          },
 53832          "modelCard": {
 53833            "modelParameters": {
 53834              "approach": {}
 53835            },
 53836            "quantitativeAnalysis": {
 53837              "graphics": {}
 53838            },
 53839            "considerations": {}
 53840          }
 53841        },
 53842        {
 53843          "type": "library",
 53844          "bom-ref": "pkg:deb/ubuntu/tgt@1.0.66-68.e042fd?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=7d43bc1090b0757a",
 53845          "supplier": {},
 53846          "publisher": "FUJITA Tomonori \u003cfujita.tomonori@lab.ntt.co.jp\u003e",
 53847          "name": "tgt",
 53848          "version": "1.0.66-68.e042fd",
 53849          "cpe": "cpe:2.3:a:tgt:tgt:1.0.66-68.e042fd:*:*:*:*:*:*:*",
 53850          "purl": "pkg:deb/ubuntu/tgt@1.0.66-68.e042fd?arch=amd64\u0026distro=ubuntu-20.04",
 53851          "swid": {
 53852            "attachment": {}
 53853          },
 53854          "pedigree": {},
 53855          "evidence": {},
 53856          "signature": {
 53857            "signature": {
 53858              "publicKey": {}
 53859            }
 53860          },
 53861          "modelCard": {
 53862            "modelParameters": {
 53863              "approach": {}
 53864            },
 53865            "quantitativeAnalysis": {
 53866              "graphics": {}
 53867            },
 53868            "considerations": {}
 53869          }
 53870        },
 53871        {
 53872          "type": "library",
 53873          "bom-ref": "pkg:deb/ubuntu/tzdata@2021e-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04\u0026package-id=46dc9535301423e0",
 53874          "supplier": {},
 53875          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53876          "name": "tzdata",
 53877          "version": "2021e-0ubuntu0.20.04",
 53878          "licenses": [
 53879            {
 53880              "license": {
 53881                "id": "ICU"
 53882              }
 53883            }
 53884          ],
 53885          "cpe": "cpe:2.3:a:tzdata:tzdata:2021e-0ubuntu0.20.04:*:*:*:*:*:*:*",
 53886          "purl": "pkg:deb/ubuntu/tzdata@2021e-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04",
 53887          "swid": {
 53888            "attachment": {}
 53889          },
 53890          "pedigree": {},
 53891          "evidence": {},
 53892          "signature": {
 53893            "signature": {
 53894              "publicKey": {}
 53895            }
 53896          },
 53897          "modelCard": {
 53898            "modelParameters": {
 53899              "approach": {}
 53900            },
 53901            "quantitativeAnalysis": {
 53902              "graphics": {}
 53903            },
 53904            "considerations": {}
 53905          }
 53906        },
 53907        {
 53908          "type": "library",
 53909          "bom-ref": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04\u0026package-id=6d2b18ebcbe1dab7",
 53910          "supplier": {},
 53911          "publisher": "Dimitri John Ledkov \u003cdimitri.ledkov@canonical.com\u003e",
 53912          "name": "ubuntu-keyring",
 53913          "version": "2020.02.11.4",
 53914          "licenses": [
 53915            {
 53916              "license": {
 53917                "name": "GPL"
 53918              }
 53919            }
 53920          ],
 53921          "cpe": "cpe:2.3:a:ubuntu-keyring:ubuntu-keyring:2020.02.11.4:*:*:*:*:*:*:*",
 53922          "purl": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04",
 53923          "swid": {
 53924            "attachment": {}
 53925          },
 53926          "pedigree": {},
 53927          "evidence": {},
 53928          "signature": {
 53929            "signature": {
 53930              "publicKey": {}
 53931            }
 53932          },
 53933          "modelCard": {
 53934            "modelParameters": {
 53935              "approach": {}
 53936            },
 53937            "quantitativeAnalysis": {
 53938              "graphics": {}
 53939            },
 53940            "considerations": {}
 53941          }
 53942        },
 53943        {
 53944          "type": "library",
 53945          "bom-ref": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=ab3b8cc8be7b5655",
 53946          "supplier": {},
 53947          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53948          "name": "ucf",
 53949          "version": "3.0038+nmu1",
 53950          "licenses": [
 53951            {
 53952              "license": {
 53953                "id": "GPL-2.0-only"
 53954              }
 53955            }
 53956          ],
 53957          "cpe": "cpe:2.3:a:ucf:ucf:3.0038\\+nmu1:*:*:*:*:*:*:*",
 53958          "purl": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04",
 53959          "swid": {
 53960            "attachment": {}
 53961          },
 53962          "pedigree": {},
 53963          "evidence": {},
 53964          "signature": {
 53965            "signature": {
 53966              "publicKey": {}
 53967            }
 53968          },
 53969          "modelCard": {
 53970            "modelParameters": {
 53971              "approach": {}
 53972            },
 53973            "quantitativeAnalysis": {
 53974              "graphics": {}
 53975            },
 53976            "considerations": {}
 53977          }
 53978        },
 53979        {
 53980          "type": "library",
 53981          "bom-ref": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=33e86bd94ef763b6",
 53982          "supplier": {},
 53983          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 53984          "name": "util-linux",
 53985          "version": "2.34-0.1ubuntu9.1",
 53986          "licenses": [
 53987            {
 53988              "license": {
 53989                "id": "BSD-2-Clause"
 53990              }
 53991            },
 53992            {
 53993              "license": {
 53994                "id": "BSD-3-Clause"
 53995              }
 53996            },
 53997            {
 53998              "license": {
 53999                "id": "BSD-4-Clause"
 54000              }
 54001            },
 54002            {
 54003              "license": {
 54004                "id": "GPL-2.0-only"
 54005              }
 54006            },
 54007            {
 54008              "license": {
 54009                "id": "GPL-2.0-or-later"
 54010              }
 54011            },
 54012            {
 54013              "license": {
 54014                "id": "GPL-3.0-only"
 54015              }
 54016            },
 54017            {
 54018              "license": {
 54019                "id": "GPL-3.0-or-later"
 54020              }
 54021            },
 54022            {
 54023              "license": {
 54024                "name": "LGPL"
 54025              }
 54026            },
 54027            {
 54028              "license": {
 54029                "id": "LGPL-2.0-only"
 54030              }
 54031            },
 54032            {
 54033              "license": {
 54034                "id": "LGPL-2.0-or-later"
 54035              }
 54036            },
 54037            {
 54038              "license": {
 54039                "id": "LGPL-2.1-only"
 54040              }
 54041            },
 54042            {
 54043              "license": {
 54044                "id": "LGPL-2.1-or-later"
 54045              }
 54046            },
 54047            {
 54048              "license": {
 54049                "id": "LGPL-3.0-only"
 54050              }
 54051            },
 54052            {
 54053              "license": {
 54054                "id": "LGPL-3.0-or-later"
 54055              }
 54056            },
 54057            {
 54058              "license": {
 54059                "id": "MIT"
 54060              }
 54061            },
 54062            {
 54063              "license": {
 54064                "name": "public-domain"
 54065              }
 54066            }
 54067          ],
 54068          "cpe": "cpe:2.3:a:util-linux:util-linux:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 54069          "purl": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04",
 54070          "swid": {
 54071            "attachment": {}
 54072          },
 54073          "pedigree": {},
 54074          "evidence": {},
 54075          "signature": {
 54076            "signature": {
 54077              "publicKey": {}
 54078            }
 54079          },
 54080          "modelCard": {
 54081            "modelParameters": {
 54082              "approach": {}
 54083            },
 54084            "quantitativeAnalysis": {
 54085              "graphics": {}
 54086            },
 54087            "considerations": {}
 54088          }
 54089        },
 54090        {
 54091          "type": "library",
 54092          "bom-ref": "pkg:deb/ubuntu/wget@1.20.3-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=49aca49f7313affb",
 54093          "supplier": {},
 54094          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 54095          "name": "wget",
 54096          "version": "1.20.3-1ubuntu2",
 54097          "licenses": [
 54098            {
 54099              "license": {
 54100                "id": "GFDL-1.2-only"
 54101              }
 54102            },
 54103            {
 54104              "license": {
 54105                "id": "GPL-3.0-only"
 54106              }
 54107            }
 54108          ],
 54109          "cpe": "cpe:2.3:a:wget:wget:1.20.3-1ubuntu2:*:*:*:*:*:*:*",
 54110          "purl": "pkg:deb/ubuntu/wget@1.20.3-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
 54111          "swid": {
 54112            "attachment": {}
 54113          },
 54114          "pedigree": {},
 54115          "evidence": {},
 54116          "signature": {
 54117            "signature": {
 54118              "publicKey": {}
 54119            }
 54120          },
 54121          "modelCard": {
 54122            "modelParameters": {
 54123              "approach": {}
 54124            },
 54125            "quantitativeAnalysis": {
 54126              "graphics": {}
 54127            },
 54128            "considerations": {}
 54129          }
 54130        },
 54131        {
 54132          "type": "library",
 54133          "bom-ref": "pkg:deb/ubuntu/xdg-user-dirs@0.17-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=6c580aaac3aa6068",
 54134          "supplier": {},
 54135          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 54136          "name": "xdg-user-dirs",
 54137          "version": "0.17-2ubuntu1",
 54138          "licenses": [
 54139            {
 54140              "license": {
 54141                "id": "GPL-2.0-only"
 54142              }
 54143            }
 54144          ],
 54145          "cpe": "cpe:2.3:a:xdg-user-dirs:xdg-user-dirs:0.17-2ubuntu1:*:*:*:*:*:*:*",
 54146          "purl": "pkg:deb/ubuntu/xdg-user-dirs@0.17-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 54147          "swid": {
 54148            "attachment": {}
 54149          },
 54150          "pedigree": {},
 54151          "evidence": {},
 54152          "signature": {
 54153            "signature": {
 54154              "publicKey": {}
 54155            }
 54156          },
 54157          "modelCard": {
 54158            "modelParameters": {
 54159              "approach": {}
 54160            },
 54161            "quantitativeAnalysis": {
 54162              "graphics": {}
 54163            },
 54164            "considerations": {}
 54165          }
 54166        },
 54167        {
 54168          "type": "library",
 54169          "bom-ref": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=46271b3ba3de19b6",
 54170          "supplier": {},
 54171          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 54172          "name": "xz-utils",
 54173          "version": "5.2.4-1ubuntu1",
 54174          "licenses": [
 54175            {
 54176              "license": {
 54177                "name": "Autoconf"
 54178              }
 54179            },
 54180            {
 54181              "license": {
 54182                "id": "GPL-2.0-only"
 54183              }
 54184            },
 54185            {
 54186              "license": {
 54187                "id": "GPL-2.0-or-later"
 54188              }
 54189            },
 54190            {
 54191              "license": {
 54192                "id": "GPL-3.0-only"
 54193              }
 54194            },
 54195            {
 54196              "license": {
 54197                "id": "LGPL-2.0-only"
 54198              }
 54199            },
 54200            {
 54201              "license": {
 54202                "id": "LGPL-2.1-only"
 54203              }
 54204            },
 54205            {
 54206              "license": {
 54207                "id": "LGPL-2.1-or-later"
 54208              }
 54209            },
 54210            {
 54211              "license": {
 54212                "name": "PD"
 54213              }
 54214            },
 54215            {
 54216              "license": {
 54217                "name": "PD-debian"
 54218              }
 54219            },
 54220            {
 54221              "license": {
 54222                "name": "config-h"
 54223              }
 54224            },
 54225            {
 54226              "license": {
 54227                "name": "noderivs"
 54228              }
 54229            },
 54230            {
 54231              "license": {
 54232                "name": "permissive-fsf"
 54233              }
 54234            },
 54235            {
 54236              "license": {
 54237                "name": "permissive-nowarranty"
 54238              }
 54239            },
 54240            {
 54241              "license": {
 54242                "name": "probably-PD"
 54243              }
 54244            }
 54245          ],
 54246          "cpe": "cpe:2.3:a:xz-utils:xz-utils:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
 54247          "purl": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 54248          "swid": {
 54249            "attachment": {}
 54250          },
 54251          "pedigree": {},
 54252          "evidence": {},
 54253          "signature": {
 54254            "signature": {
 54255              "publicKey": {}
 54256            }
 54257          },
 54258          "modelCard": {
 54259            "modelParameters": {
 54260              "approach": {}
 54261            },
 54262            "quantitativeAnalysis": {
 54263              "graphics": {}
 54264            },
 54265            "considerations": {}
 54266          }
 54267        },
 54268        {
 54269          "type": "library",
 54270          "bom-ref": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04\u0026package-id=65361fdd213cfcf7",
 54271          "supplier": {},
 54272          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 54273          "name": "zlib1g",
 54274          "version": "1:1.2.11.dfsg-2ubuntu1.2",
 54275          "licenses": [
 54276            {
 54277              "license": {
 54278                "id": "Zlib"
 54279              }
 54280            }
 54281          ],
 54282          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2ubuntu1.2:*:*:*:*:*:*:*",
 54283          "purl": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04",
 54284          "swid": {
 54285            "attachment": {}
 54286          },
 54287          "pedigree": {},
 54288          "evidence": {},
 54289          "signature": {
 54290            "signature": {
 54291              "publicKey": {}
 54292            }
 54293          },
 54294          "modelCard": {
 54295            "modelParameters": {
 54296              "approach": {}
 54297            },
 54298            "quantitativeAnalysis": {
 54299              "graphics": {}
 54300            },
 54301            "considerations": {}
 54302          }
 54303        },
 54304        {
 54305          "type": "operating-system",
 54306          "supplier": {},
 54307          "name": "ubuntu",
 54308          "version": "20.04",
 54309          "description": "Ubuntu 20.04.3 LTS",
 54310          "swid": {
 54311            "tagId": "ubuntu",
 54312            "name": "ubuntu",
 54313            "version": "20.04",
 54314            "attachment": {}
 54315          },
 54316          "pedigree": {},
 54317          "externalReferences": [
 54318            {
 54319              "url": "https://bugs.launchpad.net/ubuntu/",
 54320              "type": "issue-tracker"
 54321            },
 54322            {
 54323              "url": "https://www.ubuntu.com/",
 54324              "type": "website"
 54325            },
 54326            {
 54327              "url": "https://help.ubuntu.com/",
 54328              "comment": "support",
 54329              "type": "other"
 54330            },
 54331            {
 54332              "url": "https://www.ubuntu.com/legal/terms-and-policies/privacy-policy",
 54333              "comment": "privacyPolicy",
 54334              "type": "other"
 54335            }
 54336          ],
 54337          "evidence": {},
 54338          "signature": {
 54339            "signature": {
 54340              "publicKey": {}
 54341            }
 54342          },
 54343          "modelCard": {
 54344            "modelParameters": {
 54345              "approach": {}
 54346            },
 54347            "quantitativeAnalysis": {
 54348              "graphics": {}
 54349            },
 54350            "considerations": {}
 54351          }
 54352        },
 54353        {
 54354          "type": "library",
 54355          "bom-ref": "pkg:deb/debian/base-files@9.9+deb9u9?arch=amd64\u0026distro=debian-9\u0026package-id=2d7efeebcbea7f90",
 54356          "supplier": {},
 54357          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
 54358          "name": "base-files",
 54359          "version": "9.9+deb9u9",
 54360          "licenses": [
 54361            {
 54362              "license": {
 54363                "name": "GPL"
 54364              }
 54365            }
 54366          ],
 54367          "cpe": "cpe:2.3:a:base-files:base-files:9.9\\+deb9u9:*:*:*:*:*:*:*",
 54368          "purl": "pkg:deb/debian/base-files@9.9+deb9u9?arch=amd64\u0026distro=debian-9",
 54369          "swid": {
 54370            "attachment": {}
 54371          },
 54372          "pedigree": {},
 54373          "evidence": {},
 54374          "signature": {
 54375            "signature": {
 54376              "publicKey": {}
 54377            }
 54378          },
 54379          "modelCard": {
 54380            "modelParameters": {
 54381              "approach": {}
 54382            },
 54383            "quantitativeAnalysis": {
 54384              "graphics": {}
 54385            },
 54386            "considerations": {}
 54387          }
 54388        },
 54389        {
 54390          "type": "library",
 54391          "bom-ref": "pkg:deb/debian/netbase@5.4?arch=all\u0026distro=debian-9\u0026package-id=429157806067bf04",
 54392          "supplier": {},
 54393          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
 54394          "name": "netbase",
 54395          "version": "5.4",
 54396          "licenses": [
 54397            {
 54398              "license": {
 54399                "id": "GPL-2.0-only"
 54400              }
 54401            }
 54402          ],
 54403          "cpe": "cpe:2.3:a:netbase:netbase:5.4:*:*:*:*:*:*:*",
 54404          "purl": "pkg:deb/debian/netbase@5.4?arch=all\u0026distro=debian-9",
 54405          "swid": {
 54406            "attachment": {}
 54407          },
 54408          "pedigree": {},
 54409          "evidence": {},
 54410          "signature": {
 54411            "signature": {
 54412              "publicKey": {}
 54413            }
 54414          },
 54415          "modelCard": {
 54416            "modelParameters": {
 54417              "approach": {}
 54418            },
 54419            "quantitativeAnalysis": {
 54420              "graphics": {}
 54421            },
 54422            "considerations": {}
 54423          }
 54424        },
 54425        {
 54426          "type": "library",
 54427          "bom-ref": "pkg:deb/debian/tzdata@2019a-0+deb9u1?arch=all\u0026distro=debian-9\u0026package-id=adaa0cfde73d8ecb",
 54428          "supplier": {},
 54429          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 54430          "name": "tzdata",
 54431          "version": "2019a-0+deb9u1",
 54432          "cpe": "cpe:2.3:a:tzdata:tzdata:2019a-0\\+deb9u1:*:*:*:*:*:*:*",
 54433          "purl": "pkg:deb/debian/tzdata@2019a-0+deb9u1?arch=all\u0026distro=debian-9",
 54434          "swid": {
 54435            "attachment": {}
 54436          },
 54437          "pedigree": {},
 54438          "evidence": {},
 54439          "signature": {
 54440            "signature": {
 54441              "publicKey": {}
 54442            }
 54443          },
 54444          "modelCard": {
 54445            "modelParameters": {
 54446              "approach": {}
 54447            },
 54448            "quantitativeAnalysis": {
 54449              "graphics": {}
 54450            },
 54451            "considerations": {}
 54452          }
 54453        },
 54454        {
 54455          "type": "operating-system",
 54456          "supplier": {},
 54457          "name": "debian",
 54458          "version": "9",
 54459          "description": "Distroless",
 54460          "swid": {
 54461            "tagId": "debian",
 54462            "name": "debian",
 54463            "version": "9",
 54464            "attachment": {}
 54465          },
 54466          "pedigree": {},
 54467          "externalReferences": [
 54468            {
 54469              "url": "https://github.com/GoogleContainerTools/distroless/issues/new",
 54470              "type": "issue-tracker"
 54471            },
 54472            {
 54473              "url": "https://github.com/GoogleContainerTools/distroless",
 54474              "type": "website"
 54475            },
 54476            {
 54477              "url": "https://github.com/GoogleContainerTools/distroless/blob/master/README.md",
 54478              "comment": "support",
 54479              "type": "other"
 54480            }
 54481          ],
 54482          "evidence": {},
 54483          "signature": {
 54484            "signature": {
 54485              "publicKey": {}
 54486            }
 54487          },
 54488          "modelCard": {
 54489            "modelParameters": {
 54490              "approach": {}
 54491            },
 54492            "quantitativeAnalysis": {
 54493              "graphics": {}
 54494            },
 54495            "considerations": {}
 54496          }
 54497        },
 54498        {
 54499          "type": "library",
 54500          "bom-ref": "pkg:golang/./client?package-id=1a9799338f879587",
 54501          "supplier": {},
 54502          "name": "./client",
 54503          "purl": "pkg:golang/./client",
 54504          "swid": {
 54505            "attachment": {}
 54506          },
 54507          "pedigree": {},
 54508          "evidence": {},
 54509          "signature": {
 54510            "signature": {
 54511              "publicKey": {}
 54512            }
 54513          },
 54514          "modelCard": {
 54515            "modelParameters": {
 54516              "approach": {}
 54517            },
 54518            "quantitativeAnalysis": {
 54519              "graphics": {}
 54520            },
 54521            "considerations": {}
 54522          }
 54523        },
 54524        {
 54525          "type": "library",
 54526          "bom-ref": "pkg:deb/debian/base-files@9.9+deb9u13?arch=amd64\u0026distro=debian-9\u0026package-id=2deefa90829900bb",
 54527          "supplier": {},
 54528          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
 54529          "name": "base-files",
 54530          "version": "9.9+deb9u13",
 54531          "licenses": [
 54532            {
 54533              "license": {
 54534                "name": "GPL"
 54535              }
 54536            }
 54537          ],
 54538          "cpe": "cpe:2.3:a:base-files:base-files:9.9\\+deb9u13:*:*:*:*:*:*:*",
 54539          "purl": "pkg:deb/debian/base-files@9.9+deb9u13?arch=amd64\u0026distro=debian-9",
 54540          "swid": {
 54541            "attachment": {}
 54542          },
 54543          "pedigree": {},
 54544          "evidence": {},
 54545          "signature": {
 54546            "signature": {
 54547              "publicKey": {}
 54548            }
 54549          },
 54550          "modelCard": {
 54551            "modelParameters": {
 54552              "approach": {}
 54553            },
 54554            "quantitativeAnalysis": {
 54555              "graphics": {}
 54556            },
 54557            "considerations": {}
 54558          }
 54559        },
 54560        {
 54561          "type": "library",
 54562          "bom-ref": "pkg:golang/github.com/beorn7/perks@v1.0.1?package-id=b2858f28f03c7bb7",
 54563          "supplier": {},
 54564          "name": "github.com/beorn7/perks",
 54565          "version": "v1.0.1",
 54566          "cpe": "cpe:2.3:a:beorn7:perks:v1.0.1:*:*:*:*:*:*:*",
 54567          "purl": "pkg:golang/github.com/beorn7/perks@v1.0.1",
 54568          "swid": {
 54569            "attachment": {}
 54570          },
 54571          "pedigree": {},
 54572          "evidence": {},
 54573          "signature": {
 54574            "signature": {
 54575              "publicKey": {}
 54576            }
 54577          },
 54578          "modelCard": {
 54579            "modelParameters": {
 54580              "approach": {}
 54581            },
 54582            "quantitativeAnalysis": {
 54583              "graphics": {}
 54584            },
 54585            "considerations": {}
 54586          }
 54587        },
 54588        {
 54589          "type": "library",
 54590          "bom-ref": "pkg:golang/github.com/blang/semver@v3.5.0+incompatible?package-id=b7af6c53df612d68",
 54591          "supplier": {},
 54592          "name": "github.com/blang/semver",
 54593          "version": "v3.5.0+incompatible",
 54594          "cpe": "cpe:2.3:a:blang:semver:v3.5.0\\+incompatible:*:*:*:*:*:*:*",
 54595          "purl": "pkg:golang/github.com/blang/semver@v3.5.0+incompatible",
 54596          "swid": {
 54597            "attachment": {}
 54598          },
 54599          "pedigree": {},
 54600          "evidence": {},
 54601          "signature": {
 54602            "signature": {
 54603              "publicKey": {}
 54604            }
 54605          },
 54606          "modelCard": {
 54607            "modelParameters": {
 54608              "approach": {}
 54609            },
 54610            "quantitativeAnalysis": {
 54611              "graphics": {}
 54612            },
 54613            "considerations": {}
 54614          }
 54615        },
 54616        {
 54617          "type": "library",
 54618          "bom-ref": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1?package-id=f610ec628a212653",
 54619          "supplier": {},
 54620          "name": "github.com/cespare/xxhash/v2",
 54621          "version": "v2.1.1",
 54622          "cpe": "cpe:2.3:a:cespare:xxhash\\/v2:v2.1.1:*:*:*:*:*:*:*",
 54623          "purl": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1",
 54624          "swid": {
 54625            "attachment": {}
 54626          },
 54627          "pedigree": {},
 54628          "evidence": {},
 54629          "signature": {
 54630            "signature": {
 54631              "publicKey": {}
 54632            }
 54633          },
 54634          "modelCard": {
 54635            "modelParameters": {
 54636              "approach": {}
 54637            },
 54638            "quantitativeAnalysis": {
 54639              "graphics": {}
 54640            },
 54641            "considerations": {}
 54642          }
 54643        },
 54644        {
 54645          "type": "library",
 54646          "bom-ref": "pkg:golang/github.com/container-storage-interface/spec@v1.2.0?package-id=84ca2a5f390f8b2",
 54647          "supplier": {},
 54648          "name": "github.com/container-storage-interface/spec",
 54649          "version": "v1.2.0",
 54650          "cpe": "cpe:2.3:a:container-storage-interface:spec:v1.2.0:*:*:*:*:*:*:*",
 54651          "purl": "pkg:golang/github.com/container-storage-interface/spec@v1.2.0",
 54652          "swid": {
 54653            "attachment": {}
 54654          },
 54655          "pedigree": {},
 54656          "evidence": {},
 54657          "signature": {
 54658            "signature": {
 54659              "publicKey": {}
 54660            }
 54661          },
 54662          "modelCard": {
 54663            "modelParameters": {
 54664              "approach": {}
 54665            },
 54666            "quantitativeAnalysis": {
 54667              "graphics": {}
 54668            },
 54669            "considerations": {}
 54670          }
 54671        },
 54672        {
 54673          "type": "library",
 54674          "bom-ref": "pkg:golang/github.com/davecgh/go-spew@v1.1.1?package-id=35f5a9ecd69a9c2f",
 54675          "supplier": {},
 54676          "name": "github.com/davecgh/go-spew",
 54677          "version": "v1.1.1",
 54678          "cpe": "cpe:2.3:a:davecgh:go-spew:v1.1.1:*:*:*:*:*:*:*",
 54679          "purl": "pkg:golang/github.com/davecgh/go-spew@v1.1.1",
 54680          "swid": {
 54681            "attachment": {}
 54682          },
 54683          "pedigree": {},
 54684          "evidence": {},
 54685          "signature": {
 54686            "signature": {
 54687              "publicKey": {}
 54688            }
 54689          },
 54690          "modelCard": {
 54691            "modelParameters": {
 54692              "approach": {}
 54693            },
 54694            "quantitativeAnalysis": {
 54695              "graphics": {}
 54696            },
 54697            "considerations": {}
 54698          }
 54699        },
 54700        {
 54701          "type": "library",
 54702          "bom-ref": "pkg:golang/github.com/go-logr/logr@v0.2.0?package-id=1fe57a955f918200",
 54703          "supplier": {},
 54704          "name": "github.com/go-logr/logr",
 54705          "version": "v0.2.0",
 54706          "cpe": "cpe:2.3:a:go-logr:logr:v0.2.0:*:*:*:*:*:*:*",
 54707          "purl": "pkg:golang/github.com/go-logr/logr@v0.2.0",
 54708          "swid": {
 54709            "attachment": {}
 54710          },
 54711          "pedigree": {},
 54712          "evidence": {},
 54713          "signature": {
 54714            "signature": {
 54715              "publicKey": {}
 54716            }
 54717          },
 54718          "modelCard": {
 54719            "modelParameters": {
 54720              "approach": {}
 54721            },
 54722            "quantitativeAnalysis": {
 54723              "graphics": {}
 54724            },
 54725            "considerations": {}
 54726          }
 54727        },
 54728        {
 54729          "type": "library",
 54730          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.1?package-id=7b351ccea9fbfde7",
 54731          "supplier": {},
 54732          "name": "github.com/gogo/protobuf",
 54733          "version": "v1.3.1",
 54734          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.1:*:*:*:*:*:*:*",
 54735          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.1",
 54736          "swid": {
 54737            "attachment": {}
 54738          },
 54739          "pedigree": {},
 54740          "evidence": {},
 54741          "signature": {
 54742            "signature": {
 54743              "publicKey": {}
 54744            }
 54745          },
 54746          "modelCard": {
 54747            "modelParameters": {
 54748              "approach": {}
 54749            },
 54750            "quantitativeAnalysis": {
 54751              "graphics": {}
 54752            },
 54753            "considerations": {}
 54754          }
 54755        },
 54756        {
 54757          "type": "library",
 54758          "bom-ref": "pkg:golang/github.com/golang/groupcache@v0.0.0-20191227052852-215e87163ea7?package-id=91e4c8d359060983",
 54759          "supplier": {},
 54760          "name": "github.com/golang/groupcache",
 54761          "version": "v0.0.0-20191227052852-215e87163ea7",
 54762          "cpe": "cpe:2.3:a:golang:groupcache:v0.0.0-20191227052852-215e87163ea7:*:*:*:*:*:*:*",
 54763          "purl": "pkg:golang/github.com/golang/groupcache@v0.0.0-20191227052852-215e87163ea7",
 54764          "swid": {
 54765            "attachment": {}
 54766          },
 54767          "pedigree": {},
 54768          "evidence": {},
 54769          "signature": {
 54770            "signature": {
 54771              "publicKey": {}
 54772            }
 54773          },
 54774          "modelCard": {
 54775            "modelParameters": {
 54776              "approach": {}
 54777            },
 54778            "quantitativeAnalysis": {
 54779              "graphics": {}
 54780            },
 54781            "considerations": {}
 54782          }
 54783        },
 54784        {
 54785          "type": "library",
 54786          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.4.2?package-id=3eed8eeebadc1b3f",
 54787          "supplier": {},
 54788          "name": "github.com/golang/protobuf",
 54789          "version": "v1.4.2",
 54790          "cpe": "cpe:2.3:a:golang:protobuf:v1.4.2:*:*:*:*:*:*:*",
 54791          "purl": "pkg:golang/github.com/golang/protobuf@v1.4.2",
 54792          "swid": {
 54793            "attachment": {}
 54794          },
 54795          "pedigree": {},
 54796          "evidence": {},
 54797          "signature": {
 54798            "signature": {
 54799              "publicKey": {}
 54800            }
 54801          },
 54802          "modelCard": {
 54803            "modelParameters": {
 54804              "approach": {}
 54805            },
 54806            "quantitativeAnalysis": {
 54807              "graphics": {}
 54808            },
 54809            "considerations": {}
 54810          }
 54811        },
 54812        {
 54813          "type": "library",
 54814          "bom-ref": "pkg:golang/github.com/google/go-cmp@v0.4.0?package-id=13fef5c3716335f4",
 54815          "supplier": {},
 54816          "name": "github.com/google/go-cmp",
 54817          "version": "v0.4.0",
 54818          "cpe": "cpe:2.3:a:google:go-cmp:v0.4.0:*:*:*:*:*:*:*",
 54819          "purl": "pkg:golang/github.com/google/go-cmp@v0.4.0",
 54820          "swid": {
 54821            "attachment": {}
 54822          },
 54823          "pedigree": {},
 54824          "evidence": {},
 54825          "signature": {
 54826            "signature": {
 54827              "publicKey": {}
 54828            }
 54829          },
 54830          "modelCard": {
 54831            "modelParameters": {
 54832              "approach": {}
 54833            },
 54834            "quantitativeAnalysis": {
 54835              "graphics": {}
 54836            },
 54837            "considerations": {}
 54838          }
 54839        },
 54840        {
 54841          "type": "library",
 54842          "bom-ref": "pkg:golang/github.com/google/gofuzz@v1.1.0?package-id=bbe4819fc04c64f8",
 54843          "supplier": {},
 54844          "name": "github.com/google/gofuzz",
 54845          "version": "v1.1.0",
 54846          "cpe": "cpe:2.3:a:google:gofuzz:v1.1.0:*:*:*:*:*:*:*",
 54847          "purl": "pkg:golang/github.com/google/gofuzz@v1.1.0",
 54848          "swid": {
 54849            "attachment": {}
 54850          },
 54851          "pedigree": {},
 54852          "evidence": {},
 54853          "signature": {
 54854            "signature": {
 54855              "publicKey": {}
 54856            }
 54857          },
 54858          "modelCard": {
 54859            "modelParameters": {
 54860              "approach": {}
 54861            },
 54862            "quantitativeAnalysis": {
 54863              "graphics": {}
 54864            },
 54865            "considerations": {}
 54866          }
 54867        },
 54868        {
 54869          "type": "library",
 54870          "bom-ref": "pkg:golang/github.com/googleapis/gnostic@v0.4.1?package-id=3a602c847d260e4d",
 54871          "supplier": {},
 54872          "name": "github.com/googleapis/gnostic",
 54873          "version": "v0.4.1",
 54874          "cpe": "cpe:2.3:a:googleapis:gnostic:v0.4.1:*:*:*:*:*:*:*",
 54875          "purl": "pkg:golang/github.com/googleapis/gnostic@v0.4.1",
 54876          "swid": {
 54877            "attachment": {}
 54878          },
 54879          "pedigree": {},
 54880          "evidence": {},
 54881          "signature": {
 54882            "signature": {
 54883              "publicKey": {}
 54884            }
 54885          },
 54886          "modelCard": {
 54887            "modelParameters": {
 54888              "approach": {}
 54889            },
 54890            "quantitativeAnalysis": {
 54891              "graphics": {}
 54892            },
 54893            "considerations": {}
 54894          }
 54895        },
 54896        {
 54897          "type": "library",
 54898          "bom-ref": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.1?package-id=7f2ff30da8d70229",
 54899          "supplier": {},
 54900          "name": "github.com/hashicorp/golang-lru",
 54901          "version": "v0.5.1",
 54902          "cpe": "cpe:2.3:a:hashicorp:golang-lru:v0.5.1:*:*:*:*:*:*:*",
 54903          "purl": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.1",
 54904          "swid": {
 54905            "attachment": {}
 54906          },
 54907          "pedigree": {},
 54908          "evidence": {},
 54909          "signature": {
 54910            "signature": {
 54911              "publicKey": {}
 54912            }
 54913          },
 54914          "modelCard": {
 54915            "modelParameters": {
 54916              "approach": {}
 54917            },
 54918            "quantitativeAnalysis": {
 54919              "graphics": {}
 54920            },
 54921            "considerations": {}
 54922          }
 54923        },
 54924        {
 54925          "type": "library",
 54926          "bom-ref": "pkg:golang/github.com/imdario/mergo@v0.3.9?package-id=ec21a75baf165471",
 54927          "supplier": {},
 54928          "name": "github.com/imdario/mergo",
 54929          "version": "v0.3.9",
 54930          "cpe": "cpe:2.3:a:imdario:mergo:v0.3.9:*:*:*:*:*:*:*",
 54931          "purl": "pkg:golang/github.com/imdario/mergo@v0.3.9",
 54932          "swid": {
 54933            "attachment": {}
 54934          },
 54935          "pedigree": {},
 54936          "evidence": {},
 54937          "signature": {
 54938            "signature": {
 54939              "publicKey": {}
 54940            }
 54941          },
 54942          "modelCard": {
 54943            "modelParameters": {
 54944              "approach": {}
 54945            },
 54946            "quantitativeAnalysis": {
 54947              "graphics": {}
 54948            },
 54949            "considerations": {}
 54950          }
 54951        },
 54952        {
 54953          "type": "library",
 54954          "bom-ref": "pkg:golang/github.com/json-iterator/go@v1.1.10?package-id=aa3983286df5176c",
 54955          "supplier": {},
 54956          "name": "github.com/json-iterator/go",
 54957          "version": "v1.1.10",
 54958          "cpe": "cpe:2.3:a:json-iterator:go:v1.1.10:*:*:*:*:*:*:*",
 54959          "purl": "pkg:golang/github.com/json-iterator/go@v1.1.10",
 54960          "swid": {
 54961            "attachment": {}
 54962          },
 54963          "pedigree": {},
 54964          "evidence": {},
 54965          "signature": {
 54966            "signature": {
 54967              "publicKey": {}
 54968            }
 54969          },
 54970          "modelCard": {
 54971            "modelParameters": {
 54972              "approach": {}
 54973            },
 54974            "quantitativeAnalysis": {
 54975              "graphics": {}
 54976            },
 54977            "considerations": {}
 54978          }
 54979        },
 54980        {
 54981          "type": "library",
 54982          "bom-ref": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.8.1?package-id=b87b48e1f4e983fe",
 54983          "supplier": {},
 54984          "name": "github.com/kubernetes-csi/csi-lib-utils",
 54985          "version": "v0.8.1",
 54986          "cpe": "cpe:2.3:a:kubernetes-csi:csi-lib-utils:v0.8.1:*:*:*:*:*:*:*",
 54987          "purl": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.8.1",
 54988          "swid": {
 54989            "attachment": {}
 54990          },
 54991          "pedigree": {},
 54992          "evidence": {},
 54993          "signature": {
 54994            "signature": {
 54995              "publicKey": {}
 54996            }
 54997          },
 54998          "modelCard": {
 54999            "modelParameters": {
 55000              "approach": {}
 55001            },
 55002            "quantitativeAnalysis": {
 55003              "graphics": {}
 55004            },
 55005            "considerations": {}
 55006          }
 55007        },
 55008        {
 55009          "type": "library",
 55010          "bom-ref": "pkg:golang/github.com/kubernetes-csi/external-snapshotter/v3@(devel)?package-id=4eacb460807923af",
 55011          "supplier": {},
 55012          "name": "github.com/kubernetes-csi/external-snapshotter/v3",
 55013          "version": "(devel)",
 55014          "cpe": "cpe:2.3:a:kubernetes-csi:external-snapshotter\\/v3:\\(devel\\):*:*:*:*:*:*:*",
 55015          "purl": "pkg:golang/github.com/kubernetes-csi/external-snapshotter/v3@(devel)",
 55016          "swid": {
 55017            "attachment": {}
 55018          },
 55019          "pedigree": {},
 55020          "evidence": {},
 55021          "signature": {
 55022            "signature": {
 55023              "publicKey": {}
 55024            }
 55025          },
 55026          "modelCard": {
 55027            "modelParameters": {
 55028              "approach": {}
 55029            },
 55030            "quantitativeAnalysis": {
 55031              "graphics": {}
 55032            },
 55033            "considerations": {}
 55034          }
 55035        },
 55036        {
 55037          "type": "library",
 55038          "bom-ref": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369?package-id=30e2f347a5fe9b35",
 55039          "supplier": {},
 55040          "name": "github.com/matttproud/golang_protobuf_extensions",
 55041          "version": "v1.0.2-0.20181231171920-c182affec369",
 55042          "cpe": "cpe:2.3:a:matttproud:golang-protobuf-extensions:v1.0.2-0.20181231171920-c182affec369:*:*:*:*:*:*:*",
 55043          "purl": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369",
 55044          "swid": {
 55045            "attachment": {}
 55046          },
 55047          "pedigree": {},
 55048          "evidence": {},
 55049          "signature": {
 55050            "signature": {
 55051              "publicKey": {}
 55052            }
 55053          },
 55054          "modelCard": {
 55055            "modelParameters": {
 55056              "approach": {}
 55057            },
 55058            "quantitativeAnalysis": {
 55059              "graphics": {}
 55060            },
 55061            "considerations": {}
 55062          }
 55063        },
 55064        {
 55065          "type": "library",
 55066          "bom-ref": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd?package-id=6a3bfbbbdac0acca",
 55067          "supplier": {},
 55068          "name": "github.com/modern-go/concurrent",
 55069          "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
 55070          "cpe": "cpe:2.3:a:modern-go:concurrent:v0.0.0-20180306012644-bacd9c7ef1dd:*:*:*:*:*:*:*",
 55071          "purl": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd",
 55072          "swid": {
 55073            "attachment": {}
 55074          },
 55075          "pedigree": {},
 55076          "evidence": {},
 55077          "signature": {
 55078            "signature": {
 55079              "publicKey": {}
 55080            }
 55081          },
 55082          "modelCard": {
 55083            "modelParameters": {
 55084              "approach": {}
 55085            },
 55086            "quantitativeAnalysis": {
 55087              "graphics": {}
 55088            },
 55089            "considerations": {}
 55090          }
 55091        },
 55092        {
 55093          "type": "library",
 55094          "bom-ref": "pkg:golang/github.com/modern-go/reflect2@v1.0.1?package-id=c30b3c59e7931eee",
 55095          "supplier": {},
 55096          "name": "github.com/modern-go/reflect2",
 55097          "version": "v1.0.1",
 55098          "cpe": "cpe:2.3:a:modern-go:reflect2:v1.0.1:*:*:*:*:*:*:*",
 55099          "purl": "pkg:golang/github.com/modern-go/reflect2@v1.0.1",
 55100          "swid": {
 55101            "attachment": {}
 55102          },
 55103          "pedigree": {},
 55104          "evidence": {},
 55105          "signature": {
 55106            "signature": {
 55107              "publicKey": {}
 55108            }
 55109          },
 55110          "modelCard": {
 55111            "modelParameters": {
 55112              "approach": {}
 55113            },
 55114            "quantitativeAnalysis": {
 55115              "graphics": {}
 55116            },
 55117            "considerations": {}
 55118          }
 55119        },
 55120        {
 55121          "type": "library",
 55122          "bom-ref": "pkg:golang/github.com/prometheus/client_golang@v1.7.1?package-id=bfb05c7f3d9df0bb",
 55123          "supplier": {},
 55124          "name": "github.com/prometheus/client_golang",
 55125          "version": "v1.7.1",
 55126          "cpe": "cpe:2.3:a:prometheus:client-golang:v1.7.1:*:*:*:*:*:*:*",
 55127          "purl": "pkg:golang/github.com/prometheus/client_golang@v1.7.1",
 55128          "swid": {
 55129            "attachment": {}
 55130          },
 55131          "pedigree": {},
 55132          "evidence": {},
 55133          "signature": {
 55134            "signature": {
 55135              "publicKey": {}
 55136            }
 55137          },
 55138          "modelCard": {
 55139            "modelParameters": {
 55140              "approach": {}
 55141            },
 55142            "quantitativeAnalysis": {
 55143              "graphics": {}
 55144            },
 55145            "considerations": {}
 55146          }
 55147        },
 55148        {
 55149          "type": "library",
 55150          "bom-ref": "pkg:golang/github.com/prometheus/client_model@v0.2.0?package-id=c960161c489d87f5",
 55151          "supplier": {},
 55152          "name": "github.com/prometheus/client_model",
 55153          "version": "v0.2.0",
 55154          "cpe": "cpe:2.3:a:prometheus:client-model:v0.2.0:*:*:*:*:*:*:*",
 55155          "purl": "pkg:golang/github.com/prometheus/client_model@v0.2.0",
 55156          "swid": {
 55157            "attachment": {}
 55158          },
 55159          "pedigree": {},
 55160          "evidence": {},
 55161          "signature": {
 55162            "signature": {
 55163              "publicKey": {}
 55164            }
 55165          },
 55166          "modelCard": {
 55167            "modelParameters": {
 55168              "approach": {}
 55169            },
 55170            "quantitativeAnalysis": {
 55171              "graphics": {}
 55172            },
 55173            "considerations": {}
 55174          }
 55175        },
 55176        {
 55177          "type": "library",
 55178          "bom-ref": "pkg:golang/github.com/prometheus/common@v0.10.0?package-id=1bdfd07efad5dced",
 55179          "supplier": {},
 55180          "name": "github.com/prometheus/common",
 55181          "version": "v0.10.0",
 55182          "cpe": "cpe:2.3:a:prometheus:common:v0.10.0:*:*:*:*:*:*:*",
 55183          "purl": "pkg:golang/github.com/prometheus/common@v0.10.0",
 55184          "swid": {
 55185            "attachment": {}
 55186          },
 55187          "pedigree": {},
 55188          "evidence": {},
 55189          "signature": {
 55190            "signature": {
 55191              "publicKey": {}
 55192            }
 55193          },
 55194          "modelCard": {
 55195            "modelParameters": {
 55196              "approach": {}
 55197            },
 55198            "quantitativeAnalysis": {
 55199              "graphics": {}
 55200            },
 55201            "considerations": {}
 55202          }
 55203        },
 55204        {
 55205          "type": "library",
 55206          "bom-ref": "pkg:golang/github.com/prometheus/procfs@v0.1.3?package-id=5bb7250a55c4c829",
 55207          "supplier": {},
 55208          "name": "github.com/prometheus/procfs",
 55209          "version": "v0.1.3",
 55210          "cpe": "cpe:2.3:a:prometheus:procfs:v0.1.3:*:*:*:*:*:*:*",
 55211          "purl": "pkg:golang/github.com/prometheus/procfs@v0.1.3",
 55212          "swid": {
 55213            "attachment": {}
 55214          },
 55215          "pedigree": {},
 55216          "evidence": {},
 55217          "signature": {
 55218            "signature": {
 55219              "publicKey": {}
 55220            }
 55221          },
 55222          "modelCard": {
 55223            "modelParameters": {
 55224              "approach": {}
 55225            },
 55226            "quantitativeAnalysis": {
 55227              "graphics": {}
 55228            },
 55229            "considerations": {}
 55230          }
 55231        },
 55232        {
 55233          "type": "library",
 55234          "bom-ref": "pkg:golang/github.com/spf13/pflag@v1.0.5?package-id=8d92e006437cc6d1",
 55235          "supplier": {},
 55236          "name": "github.com/spf13/pflag",
 55237          "version": "v1.0.5",
 55238          "cpe": "cpe:2.3:a:spf13:pflag:v1.0.5:*:*:*:*:*:*:*",
 55239          "purl": "pkg:golang/github.com/spf13/pflag@v1.0.5",
 55240          "swid": {
 55241            "attachment": {}
 55242          },
 55243          "pedigree": {},
 55244          "evidence": {},
 55245          "signature": {
 55246            "signature": {
 55247              "publicKey": {}
 55248            }
 55249          },
 55250          "modelCard": {
 55251            "modelParameters": {
 55252              "approach": {}
 55253            },
 55254            "quantitativeAnalysis": {
 55255              "graphics": {}
 55256            },
 55257            "considerations": {}
 55258          }
 55259        },
 55260        {
 55261          "type": "library",
 55262          "bom-ref": "pkg:golang/golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9?package-id=9a88f02496ed8716",
 55263          "supplier": {},
 55264          "name": "golang.org/x/crypto",
 55265          "version": "v0.0.0-20200622213623-75b288015ac9",
 55266          "cpe": "cpe:2.3:a:golang:x\\/crypto:v0.0.0-20200622213623-75b288015ac9:*:*:*:*:*:*:*",
 55267          "purl": "pkg:golang/golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9",
 55268          "swid": {
 55269            "attachment": {}
 55270          },
 55271          "pedigree": {},
 55272          "evidence": {},
 55273          "signature": {
 55274            "signature": {
 55275              "publicKey": {}
 55276            }
 55277          },
 55278          "modelCard": {
 55279            "modelParameters": {
 55280              "approach": {}
 55281            },
 55282            "quantitativeAnalysis": {
 55283              "graphics": {}
 55284            },
 55285            "considerations": {}
 55286          }
 55287        },
 55288        {
 55289          "type": "library",
 55290          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20200707034311-ab3426394381?package-id=b9110b0c96b7de83",
 55291          "supplier": {},
 55292          "name": "golang.org/x/net",
 55293          "version": "v0.0.0-20200707034311-ab3426394381",
 55294          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20200707034311-ab3426394381:*:*:*:*:*:*:*",
 55295          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20200707034311-ab3426394381",
 55296          "swid": {
 55297            "attachment": {}
 55298          },
 55299          "pedigree": {},
 55300          "evidence": {},
 55301          "signature": {
 55302            "signature": {
 55303              "publicKey": {}
 55304            }
 55305          },
 55306          "modelCard": {
 55307            "modelParameters": {
 55308              "approach": {}
 55309            },
 55310            "quantitativeAnalysis": {
 55311              "graphics": {}
 55312            },
 55313            "considerations": {}
 55314          }
 55315        },
 55316        {
 55317          "type": "library",
 55318          "bom-ref": "pkg:golang/golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d?package-id=c814ec5a6f8389e0",
 55319          "supplier": {},
 55320          "name": "golang.org/x/oauth2",
 55321          "version": "v0.0.0-20200107190931-bf48bf16ab8d",
 55322          "cpe": "cpe:2.3:a:golang:x\\/oauth2:v0.0.0-20200107190931-bf48bf16ab8d:*:*:*:*:*:*:*",
 55323          "purl": "pkg:golang/golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d",
 55324          "swid": {
 55325            "attachment": {}
 55326          },
 55327          "pedigree": {},
 55328          "evidence": {},
 55329          "signature": {
 55330            "signature": {
 55331              "publicKey": {}
 55332            }
 55333          },
 55334          "modelCard": {
 55335            "modelParameters": {
 55336              "approach": {}
 55337            },
 55338            "quantitativeAnalysis": {
 55339              "graphics": {}
 55340            },
 55341            "considerations": {}
 55342          }
 55343        },
 55344        {
 55345          "type": "library",
 55346          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4?package-id=947af2e93d8d5380",
 55347          "supplier": {},
 55348          "name": "golang.org/x/sys",
 55349          "version": "v0.0.0-20200622214017-ed371f2e16b4",
 55350          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20200622214017-ed371f2e16b4:*:*:*:*:*:*:*",
 55351          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20200622214017-ed371f2e16b4",
 55352          "swid": {
 55353            "attachment": {}
 55354          },
 55355          "pedigree": {},
 55356          "evidence": {},
 55357          "signature": {
 55358            "signature": {
 55359              "publicKey": {}
 55360            }
 55361          },
 55362          "modelCard": {
 55363            "modelParameters": {
 55364              "approach": {}
 55365            },
 55366            "quantitativeAnalysis": {
 55367              "graphics": {}
 55368            },
 55369            "considerations": {}
 55370          }
 55371        },
 55372        {
 55373          "type": "library",
 55374          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.3?package-id=983646a501312145",
 55375          "supplier": {},
 55376          "name": "golang.org/x/text",
 55377          "version": "v0.3.3",
 55378          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.3:*:*:*:*:*:*:*",
 55379          "purl": "pkg:golang/golang.org/x/text@v0.3.3",
 55380          "swid": {
 55381            "attachment": {}
 55382          },
 55383          "pedigree": {},
 55384          "evidence": {},
 55385          "signature": {
 55386            "signature": {
 55387              "publicKey": {}
 55388            }
 55389          },
 55390          "modelCard": {
 55391            "modelParameters": {
 55392              "approach": {}
 55393            },
 55394            "quantitativeAnalysis": {
 55395              "graphics": {}
 55396            },
 55397            "considerations": {}
 55398          }
 55399        },
 55400        {
 55401          "type": "library",
 55402          "bom-ref": "pkg:golang/golang.org/x/time@v0.0.0-20200416051211-89c76fbcd5d1?package-id=159ffb19b6a7c39f",
 55403          "supplier": {},
 55404          "name": "golang.org/x/time",
 55405          "version": "v0.0.0-20200416051211-89c76fbcd5d1",
 55406          "cpe": "cpe:2.3:a:golang:x\\/time:v0.0.0-20200416051211-89c76fbcd5d1:*:*:*:*:*:*:*",
 55407          "purl": "pkg:golang/golang.org/x/time@v0.0.0-20200416051211-89c76fbcd5d1",
 55408          "swid": {
 55409            "attachment": {}
 55410          },
 55411          "pedigree": {},
 55412          "evidence": {},
 55413          "signature": {
 55414            "signature": {
 55415              "publicKey": {}
 55416            }
 55417          },
 55418          "modelCard": {
 55419            "modelParameters": {
 55420              "approach": {}
 55421            },
 55422            "quantitativeAnalysis": {
 55423              "graphics": {}
 55424            },
 55425            "considerations": {}
 55426          }
 55427        },
 55428        {
 55429          "type": "library",
 55430          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20200526211855-cb27e3aa2013?package-id=2ca1f7d8897ff89d",
 55431          "supplier": {},
 55432          "name": "google.golang.org/genproto",
 55433          "version": "v0.0.0-20200526211855-cb27e3aa2013",
 55434          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20200526211855-cb27e3aa2013:*:*:*:*:*:*:*",
 55435          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20200526211855-cb27e3aa2013",
 55436          "swid": {
 55437            "attachment": {}
 55438          },
 55439          "pedigree": {},
 55440          "evidence": {},
 55441          "signature": {
 55442            "signature": {
 55443              "publicKey": {}
 55444            }
 55445          },
 55446          "modelCard": {
 55447            "modelParameters": {
 55448              "approach": {}
 55449            },
 55450            "quantitativeAnalysis": {
 55451              "graphics": {}
 55452            },
 55453            "considerations": {}
 55454          }
 55455        },
 55456        {
 55457          "type": "library",
 55458          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.29.0?package-id=c056dd5e6dd61e24",
 55459          "supplier": {},
 55460          "name": "google.golang.org/grpc",
 55461          "version": "v1.29.0",
 55462          "cpe": "cpe:2.3:a:google:grpc:v1.29.0:*:*:*:*:*:*:*",
 55463          "purl": "pkg:golang/google.golang.org/grpc@v1.29.0",
 55464          "swid": {
 55465            "attachment": {}
 55466          },
 55467          "pedigree": {},
 55468          "evidence": {},
 55469          "signature": {
 55470            "signature": {
 55471              "publicKey": {}
 55472            }
 55473          },
 55474          "modelCard": {
 55475            "modelParameters": {
 55476              "approach": {}
 55477            },
 55478            "quantitativeAnalysis": {
 55479              "graphics": {}
 55480            },
 55481            "considerations": {}
 55482          }
 55483        },
 55484        {
 55485          "type": "library",
 55486          "bom-ref": "pkg:golang/google.golang.org/protobuf@v1.24.0?package-id=b12c716051550c26",
 55487          "supplier": {},
 55488          "name": "google.golang.org/protobuf",
 55489          "version": "v1.24.0",
 55490          "cpe": "cpe:2.3:a:google:protobuf:v1.24.0:*:*:*:*:*:*:*",
 55491          "purl": "pkg:golang/google.golang.org/protobuf@v1.24.0",
 55492          "swid": {
 55493            "attachment": {}
 55494          },
 55495          "pedigree": {},
 55496          "evidence": {},
 55497          "signature": {
 55498            "signature": {
 55499              "publicKey": {}
 55500            }
 55501          },
 55502          "modelCard": {
 55503            "modelParameters": {
 55504              "approach": {}
 55505            },
 55506            "quantitativeAnalysis": {
 55507              "graphics": {}
 55508            },
 55509            "considerations": {}
 55510          }
 55511        },
 55512        {
 55513          "type": "library",
 55514          "bom-ref": "pkg:golang/gopkg.in/inf.v0@v0.9.1?package-id=7faf37cb8fe7c575",
 55515          "supplier": {},
 55516          "name": "gopkg.in/inf.v0",
 55517          "version": "v0.9.1",
 55518          "purl": "pkg:golang/gopkg.in/inf.v0@v0.9.1",
 55519          "swid": {
 55520            "attachment": {}
 55521          },
 55522          "pedigree": {},
 55523          "evidence": {},
 55524          "signature": {
 55525            "signature": {
 55526              "publicKey": {}
 55527            }
 55528          },
 55529          "modelCard": {
 55530            "modelParameters": {
 55531              "approach": {}
 55532            },
 55533            "quantitativeAnalysis": {
 55534              "graphics": {}
 55535            },
 55536            "considerations": {}
 55537          }
 55538        },
 55539        {
 55540          "type": "library",
 55541          "bom-ref": "pkg:golang/gopkg.in/yaml.v2@v2.2.8?package-id=67f9602c247f5d01",
 55542          "supplier": {},
 55543          "name": "gopkg.in/yaml.v2",
 55544          "version": "v2.2.8",
 55545          "purl": "pkg:golang/gopkg.in/yaml.v2@v2.2.8",
 55546          "swid": {
 55547            "attachment": {}
 55548          },
 55549          "pedigree": {},
 55550          "evidence": {},
 55551          "signature": {
 55552            "signature": {
 55553              "publicKey": {}
 55554            }
 55555          },
 55556          "modelCard": {
 55557            "modelParameters": {
 55558              "approach": {}
 55559            },
 55560            "quantitativeAnalysis": {
 55561              "graphics": {}
 55562            },
 55563            "considerations": {}
 55564          }
 55565        },
 55566        {
 55567          "type": "library",
 55568          "bom-ref": "pkg:golang/k8s.io/api@v0.19.0?package-id=99bab8867fc3f21",
 55569          "supplier": {},
 55570          "name": "k8s.io/api",
 55571          "version": "v0.19.0",
 55572          "purl": "pkg:golang/k8s.io/api@v0.19.0",
 55573          "swid": {
 55574            "attachment": {}
 55575          },
 55576          "pedigree": {},
 55577          "evidence": {},
 55578          "signature": {
 55579            "signature": {
 55580              "publicKey": {}
 55581            }
 55582          },
 55583          "modelCard": {
 55584            "modelParameters": {
 55585              "approach": {}
 55586            },
 55587            "quantitativeAnalysis": {
 55588              "graphics": {}
 55589            },
 55590            "considerations": {}
 55591          }
 55592        },
 55593        {
 55594          "type": "library",
 55595          "bom-ref": "pkg:golang/k8s.io/apimachinery@v0.19.0?package-id=5739f00b997b4678",
 55596          "supplier": {},
 55597          "name": "k8s.io/apimachinery",
 55598          "version": "v0.19.0",
 55599          "purl": "pkg:golang/k8s.io/apimachinery@v0.19.0",
 55600          "swid": {
 55601            "attachment": {}
 55602          },
 55603          "pedigree": {},
 55604          "evidence": {},
 55605          "signature": {
 55606            "signature": {
 55607              "publicKey": {}
 55608            }
 55609          },
 55610          "modelCard": {
 55611            "modelParameters": {
 55612              "approach": {}
 55613            },
 55614            "quantitativeAnalysis": {
 55615              "graphics": {}
 55616            },
 55617            "considerations": {}
 55618          }
 55619        },
 55620        {
 55621          "type": "library",
 55622          "bom-ref": "pkg:golang/k8s.io/client-go@v0.19.0?package-id=91a5dbc2f6e0ec33",
 55623          "supplier": {},
 55624          "name": "k8s.io/client-go",
 55625          "version": "v0.19.0",
 55626          "purl": "pkg:golang/k8s.io/client-go@v0.19.0",
 55627          "swid": {
 55628            "attachment": {}
 55629          },
 55630          "pedigree": {},
 55631          "evidence": {},
 55632          "signature": {
 55633            "signature": {
 55634              "publicKey": {}
 55635            }
 55636          },
 55637          "modelCard": {
 55638            "modelParameters": {
 55639              "approach": {}
 55640            },
 55641            "quantitativeAnalysis": {
 55642              "graphics": {}
 55643            },
 55644            "considerations": {}
 55645          }
 55646        },
 55647        {
 55648          "type": "library",
 55649          "bom-ref": "pkg:golang/k8s.io/component-base@v0.19.0?package-id=ee645c8af60815a4",
 55650          "supplier": {},
 55651          "name": "k8s.io/component-base",
 55652          "version": "v0.19.0",
 55653          "purl": "pkg:golang/k8s.io/component-base@v0.19.0",
 55654          "swid": {
 55655            "attachment": {}
 55656          },
 55657          "pedigree": {},
 55658          "evidence": {},
 55659          "signature": {
 55660            "signature": {
 55661              "publicKey": {}
 55662            }
 55663          },
 55664          "modelCard": {
 55665            "modelParameters": {
 55666              "approach": {}
 55667            },
 55668            "quantitativeAnalysis": {
 55669              "graphics": {}
 55670            },
 55671            "considerations": {}
 55672          }
 55673        },
 55674        {
 55675          "type": "library",
 55676          "bom-ref": "pkg:golang/k8s.io/klog@v1.0.0?package-id=a0d734f43b3aeee0",
 55677          "supplier": {},
 55678          "name": "k8s.io/klog",
 55679          "version": "v1.0.0",
 55680          "purl": "pkg:golang/k8s.io/klog@v1.0.0",
 55681          "swid": {
 55682            "attachment": {}
 55683          },
 55684          "pedigree": {},
 55685          "evidence": {},
 55686          "signature": {
 55687            "signature": {
 55688              "publicKey": {}
 55689            }
 55690          },
 55691          "modelCard": {
 55692            "modelParameters": {
 55693              "approach": {}
 55694            },
 55695            "quantitativeAnalysis": {
 55696              "graphics": {}
 55697            },
 55698            "considerations": {}
 55699          }
 55700        },
 55701        {
 55702          "type": "library",
 55703          "bom-ref": "pkg:golang/k8s.io/klog/v2@v2.2.0?package-id=475fbe406f22b864",
 55704          "supplier": {},
 55705          "name": "k8s.io/klog/v2",
 55706          "version": "v2.2.0",
 55707          "cpe": "cpe:2.3:a:klog:v2:v2.2.0:*:*:*:*:*:*:*",
 55708          "purl": "pkg:golang/k8s.io/klog/v2@v2.2.0",
 55709          "swid": {
 55710            "attachment": {}
 55711          },
 55712          "pedigree": {},
 55713          "evidence": {},
 55714          "signature": {
 55715            "signature": {
 55716              "publicKey": {}
 55717            }
 55718          },
 55719          "modelCard": {
 55720            "modelParameters": {
 55721              "approach": {}
 55722            },
 55723            "quantitativeAnalysis": {
 55724              "graphics": {}
 55725            },
 55726            "considerations": {}
 55727          }
 55728        },
 55729        {
 55730          "type": "library",
 55731          "bom-ref": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20200805222855-6aeccd4b50c6?package-id=7099707dd2dbcdac",
 55732          "supplier": {},
 55733          "name": "k8s.io/kube-openapi",
 55734          "version": "v0.0.0-20200805222855-6aeccd4b50c6",
 55735          "purl": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20200805222855-6aeccd4b50c6",
 55736          "swid": {
 55737            "attachment": {}
 55738          },
 55739          "pedigree": {},
 55740          "evidence": {},
 55741          "signature": {
 55742            "signature": {
 55743              "publicKey": {}
 55744            }
 55745          },
 55746          "modelCard": {
 55747            "modelParameters": {
 55748              "approach": {}
 55749            },
 55750            "quantitativeAnalysis": {
 55751              "graphics": {}
 55752            },
 55753            "considerations": {}
 55754          }
 55755        },
 55756        {
 55757          "type": "library",
 55758          "bom-ref": "pkg:golang/k8s.io/utils@v0.0.0-20200729134348-d5654de09c73?package-id=c95e28937c0bf59b",
 55759          "supplier": {},
 55760          "name": "k8s.io/utils",
 55761          "version": "v0.0.0-20200729134348-d5654de09c73",
 55762          "purl": "pkg:golang/k8s.io/utils@v0.0.0-20200729134348-d5654de09c73",
 55763          "swid": {
 55764            "attachment": {}
 55765          },
 55766          "pedigree": {},
 55767          "evidence": {},
 55768          "signature": {
 55769            "signature": {
 55770              "publicKey": {}
 55771            }
 55772          },
 55773          "modelCard": {
 55774            "modelParameters": {
 55775              "approach": {}
 55776            },
 55777            "quantitativeAnalysis": {
 55778              "graphics": {}
 55779            },
 55780            "considerations": {}
 55781          }
 55782        },
 55783        {
 55784          "type": "library",
 55785          "bom-ref": "pkg:deb/debian/netbase@5.4?arch=all\u0026distro=debian-9\u0026package-id=429157806067bf04",
 55786          "supplier": {},
 55787          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
 55788          "name": "netbase",
 55789          "version": "5.4",
 55790          "licenses": [
 55791            {
 55792              "license": {
 55793                "id": "GPL-2.0-only"
 55794              }
 55795            }
 55796          ],
 55797          "cpe": "cpe:2.3:a:netbase:netbase:5.4:*:*:*:*:*:*:*",
 55798          "purl": "pkg:deb/debian/netbase@5.4?arch=all\u0026distro=debian-9",
 55799          "swid": {
 55800            "attachment": {}
 55801          },
 55802          "pedigree": {},
 55803          "evidence": {},
 55804          "signature": {
 55805            "signature": {
 55806              "publicKey": {}
 55807            }
 55808          },
 55809          "modelCard": {
 55810            "modelParameters": {
 55811              "approach": {}
 55812            },
 55813            "quantitativeAnalysis": {
 55814              "graphics": {}
 55815            },
 55816            "considerations": {}
 55817          }
 55818        },
 55819        {
 55820          "type": "library",
 55821          "bom-ref": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.0.1?package-id=c52a6068d608c605",
 55822          "supplier": {},
 55823          "name": "sigs.k8s.io/structured-merge-diff/v4",
 55824          "version": "v4.0.1",
 55825          "cpe": "cpe:2.3:a:structured-merge-diff:v4:v4.0.1:*:*:*:*:*:*:*",
 55826          "purl": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.0.1",
 55827          "swid": {
 55828            "attachment": {}
 55829          },
 55830          "pedigree": {},
 55831          "evidence": {},
 55832          "signature": {
 55833            "signature": {
 55834              "publicKey": {}
 55835            }
 55836          },
 55837          "modelCard": {
 55838            "modelParameters": {
 55839              "approach": {}
 55840            },
 55841            "quantitativeAnalysis": {
 55842              "graphics": {}
 55843            },
 55844            "considerations": {}
 55845          }
 55846        },
 55847        {
 55848          "type": "library",
 55849          "bom-ref": "pkg:golang/sigs.k8s.io/yaml@v1.2.0?package-id=15898ee67729bf04",
 55850          "supplier": {},
 55851          "name": "sigs.k8s.io/yaml",
 55852          "version": "v1.2.0",
 55853          "purl": "pkg:golang/sigs.k8s.io/yaml@v1.2.0",
 55854          "swid": {
 55855            "attachment": {}
 55856          },
 55857          "pedigree": {},
 55858          "evidence": {},
 55859          "signature": {
 55860            "signature": {
 55861              "publicKey": {}
 55862            }
 55863          },
 55864          "modelCard": {
 55865            "modelParameters": {
 55866              "approach": {}
 55867            },
 55868            "quantitativeAnalysis": {
 55869              "graphics": {}
 55870            },
 55871            "considerations": {}
 55872          }
 55873        },
 55874        {
 55875          "type": "library",
 55876          "bom-ref": "pkg:deb/debian/tzdata@2020d-0+deb9u1?arch=all\u0026distro=debian-9\u0026package-id=90a2fa7ec9eec4d9",
 55877          "supplier": {},
 55878          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 55879          "name": "tzdata",
 55880          "version": "2020d-0+deb9u1",
 55881          "cpe": "cpe:2.3:a:tzdata:tzdata:2020d-0\\+deb9u1:*:*:*:*:*:*:*",
 55882          "purl": "pkg:deb/debian/tzdata@2020d-0+deb9u1?arch=all\u0026distro=debian-9",
 55883          "swid": {
 55884            "attachment": {}
 55885          },
 55886          "pedigree": {},
 55887          "evidence": {},
 55888          "signature": {
 55889            "signature": {
 55890              "publicKey": {}
 55891            }
 55892          },
 55893          "modelCard": {
 55894            "modelParameters": {
 55895              "approach": {}
 55896            },
 55897            "quantitativeAnalysis": {
 55898              "graphics": {}
 55899            },
 55900            "considerations": {}
 55901          }
 55902        },
 55903        {
 55904          "type": "operating-system",
 55905          "supplier": {},
 55906          "name": "debian",
 55907          "version": "9",
 55908          "description": "Distroless",
 55909          "swid": {
 55910            "tagId": "debian",
 55911            "name": "debian",
 55912            "version": "9",
 55913            "attachment": {}
 55914          },
 55915          "pedigree": {},
 55916          "externalReferences": [
 55917            {
 55918              "url": "https://github.com/GoogleContainerTools/distroless/issues/new",
 55919              "type": "issue-tracker"
 55920            },
 55921            {
 55922              "url": "https://github.com/GoogleContainerTools/distroless",
 55923              "type": "website"
 55924            },
 55925            {
 55926              "url": "https://github.com/GoogleContainerTools/distroless/blob/master/README.md",
 55927              "comment": "support",
 55928              "type": "other"
 55929            }
 55930          ],
 55931          "evidence": {},
 55932          "signature": {
 55933            "signature": {
 55934              "publicKey": {}
 55935            }
 55936          },
 55937          "modelCard": {
 55938            "modelParameters": {
 55939              "approach": {}
 55940            },
 55941            "quantitativeAnalysis": {
 55942              "graphics": {}
 55943            },
 55944            "considerations": {}
 55945          }
 55946        },
 55947        {
 55948          "type": "application",
 55949          "bom-ref": "5114fa9a1aa0021f",
 55950          "supplier": {},
 55951          "name": "busybox",
 55952          "version": "1.31.1",
 55953          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1:*:*:*:*:*:*:*",
 55954          "swid": {
 55955            "attachment": {}
 55956          },
 55957          "pedigree": {},
 55958          "evidence": {},
 55959          "signature": {
 55960            "signature": {
 55961              "publicKey": {}
 55962            }
 55963          },
 55964          "modelCard": {
 55965            "modelParameters": {
 55966              "approach": {}
 55967            },
 55968            "quantitativeAnalysis": {
 55969              "graphics": {}
 55970            },
 55971            "considerations": {}
 55972          }
 55973        },
 55974        {
 55975          "type": "operating-system",
 55976          "supplier": {},
 55977          "name": "busybox",
 55978          "version": "1.31.1",
 55979          "description": "BusyBox v1.31.1",
 55980          "swid": {
 55981            "tagId": "busybox",
 55982            "name": "busybox",
 55983            "version": "1.31.1",
 55984            "attachment": {}
 55985          },
 55986          "pedigree": {},
 55987          "evidence": {},
 55988          "signature": {
 55989            "signature": {
 55990              "publicKey": {}
 55991            }
 55992          },
 55993          "modelCard": {
 55994            "modelParameters": {
 55995              "approach": {}
 55996            },
 55997            "quantitativeAnalysis": {
 55998              "graphics": {}
 55999            },
 56000            "considerations": {}
 56001          }
 56002        },
 56003        {
 56004          "type": "library",
 56005          "bom-ref": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04\u0026package-id=69d1980477020fa3",
 56006          "supplier": {},
 56007          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56008          "name": "adduser",
 56009          "version": "3.118ubuntu2",
 56010          "licenses": [
 56011            {
 56012              "license": {
 56013                "id": "GPL-2.0-only"
 56014              }
 56015            }
 56016          ],
 56017          "cpe": "cpe:2.3:a:adduser:adduser:3.118ubuntu2:*:*:*:*:*:*:*",
 56018          "purl": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04",
 56019          "swid": {
 56020            "attachment": {}
 56021          },
 56022          "pedigree": {},
 56023          "evidence": {},
 56024          "signature": {
 56025            "signature": {
 56026              "publicKey": {}
 56027            }
 56028          },
 56029          "modelCard": {
 56030            "modelParameters": {
 56031              "approach": {}
 56032            },
 56033            "quantitativeAnalysis": {
 56034              "graphics": {}
 56035            },
 56036            "considerations": {}
 56037          }
 56038        },
 56039        {
 56040          "type": "library",
 56041          "bom-ref": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=55988ea1c6f336e3",
 56042          "supplier": {},
 56043          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56044          "name": "apt",
 56045          "version": "2.0.6",
 56046          "licenses": [
 56047            {
 56048              "license": {
 56049                "id": "GPL-2.0-only"
 56050              }
 56051            },
 56052            {
 56053              "license": {
 56054                "name": "GPLv2+"
 56055              }
 56056            }
 56057          ],
 56058          "cpe": "cpe:2.3:a:apt:apt:2.0.6:*:*:*:*:*:*:*",
 56059          "purl": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04",
 56060          "swid": {
 56061            "attachment": {}
 56062          },
 56063          "pedigree": {},
 56064          "evidence": {},
 56065          "signature": {
 56066            "signature": {
 56067              "publicKey": {}
 56068            }
 56069          },
 56070          "modelCard": {
 56071            "modelParameters": {
 56072              "approach": {}
 56073            },
 56074            "quantitativeAnalysis": {
 56075              "graphics": {}
 56076            },
 56077            "considerations": {}
 56078          }
 56079        },
 56080        {
 56081          "type": "library",
 56082          "bom-ref": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=63c89c28c512e1db",
 56083          "supplier": {},
 56084          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56085          "name": "base-files",
 56086          "version": "11ubuntu5.4",
 56087          "licenses": [
 56088            {
 56089              "license": {
 56090                "name": "GPL"
 56091              }
 56092            }
 56093          ],
 56094          "cpe": "cpe:2.3:a:base-files:base-files:11ubuntu5.4:*:*:*:*:*:*:*",
 56095          "purl": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04",
 56096          "swid": {
 56097            "attachment": {}
 56098          },
 56099          "pedigree": {},
 56100          "evidence": {},
 56101          "signature": {
 56102            "signature": {
 56103              "publicKey": {}
 56104            }
 56105          },
 56106          "modelCard": {
 56107            "modelParameters": {
 56108              "approach": {}
 56109            },
 56110            "quantitativeAnalysis": {
 56111              "graphics": {}
 56112            },
 56113            "considerations": {}
 56114          }
 56115        },
 56116        {
 56117          "type": "library",
 56118          "bom-ref": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=8b6e494dac6dab09",
 56119          "supplier": {},
 56120          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
 56121          "name": "base-passwd",
 56122          "version": "3.5.47",
 56123          "licenses": [
 56124            {
 56125              "license": {
 56126                "id": "GPL-2.0-only"
 56127              }
 56128            },
 56129            {
 56130              "license": {
 56131                "name": "PD"
 56132              }
 56133            }
 56134          ],
 56135          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.47:*:*:*:*:*:*:*",
 56136          "purl": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04",
 56137          "swid": {
 56138            "attachment": {}
 56139          },
 56140          "pedigree": {},
 56141          "evidence": {},
 56142          "signature": {
 56143            "signature": {
 56144              "publicKey": {}
 56145            }
 56146          },
 56147          "modelCard": {
 56148            "modelParameters": {
 56149              "approach": {}
 56150            },
 56151            "quantitativeAnalysis": {
 56152              "graphics": {}
 56153            },
 56154            "considerations": {}
 56155          }
 56156        },
 56157        {
 56158          "type": "library",
 56159          "bom-ref": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e774a3e87113196b",
 56160          "supplier": {},
 56161          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56162          "name": "bash",
 56163          "version": "5.0-6ubuntu1.1",
 56164          "licenses": [
 56165            {
 56166              "license": {
 56167                "id": "GPL-3.0-only"
 56168              }
 56169            }
 56170          ],
 56171          "cpe": "cpe:2.3:a:bash:bash:5.0-6ubuntu1.1:*:*:*:*:*:*:*",
 56172          "purl": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04",
 56173          "swid": {
 56174            "attachment": {}
 56175          },
 56176          "pedigree": {},
 56177          "evidence": {},
 56178          "signature": {
 56179            "signature": {
 56180              "publicKey": {}
 56181            }
 56182          },
 56183          "modelCard": {
 56184            "modelParameters": {
 56185              "approach": {}
 56186            },
 56187            "quantitativeAnalysis": {
 56188              "graphics": {}
 56189            },
 56190            "considerations": {}
 56191          }
 56192        },
 56193        {
 56194          "type": "library",
 56195          "bom-ref": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04\u0026package-id=20018d8de777eda9",
 56196          "supplier": {},
 56197          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56198          "name": "bsdutils",
 56199          "version": "1:2.34-0.1ubuntu9.1",
 56200          "licenses": [
 56201            {
 56202              "license": {
 56203                "id": "BSD-2-Clause"
 56204              }
 56205            },
 56206            {
 56207              "license": {
 56208                "id": "BSD-3-Clause"
 56209              }
 56210            },
 56211            {
 56212              "license": {
 56213                "id": "BSD-4-Clause"
 56214              }
 56215            },
 56216            {
 56217              "license": {
 56218                "id": "GPL-2.0-only"
 56219              }
 56220            },
 56221            {
 56222              "license": {
 56223                "id": "GPL-2.0-or-later"
 56224              }
 56225            },
 56226            {
 56227              "license": {
 56228                "id": "GPL-3.0-only"
 56229              }
 56230            },
 56231            {
 56232              "license": {
 56233                "id": "GPL-3.0-or-later"
 56234              }
 56235            },
 56236            {
 56237              "license": {
 56238                "name": "LGPL"
 56239              }
 56240            },
 56241            {
 56242              "license": {
 56243                "id": "LGPL-2.0-only"
 56244              }
 56245            },
 56246            {
 56247              "license": {
 56248                "id": "LGPL-2.0-or-later"
 56249              }
 56250            },
 56251            {
 56252              "license": {
 56253                "id": "LGPL-2.1-only"
 56254              }
 56255            },
 56256            {
 56257              "license": {
 56258                "id": "LGPL-2.1-or-later"
 56259              }
 56260            },
 56261            {
 56262              "license": {
 56263                "id": "LGPL-3.0-only"
 56264              }
 56265            },
 56266            {
 56267              "license": {
 56268                "id": "LGPL-3.0-or-later"
 56269              }
 56270            },
 56271            {
 56272              "license": {
 56273                "id": "MIT"
 56274              }
 56275            },
 56276            {
 56277              "license": {
 56278                "name": "public-domain"
 56279              }
 56280            }
 56281          ],
 56282          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 56283          "purl": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04",
 56284          "swid": {
 56285            "attachment": {}
 56286          },
 56287          "pedigree": {},
 56288          "evidence": {},
 56289          "signature": {
 56290            "signature": {
 56291              "publicKey": {}
 56292            }
 56293          },
 56294          "modelCard": {
 56295            "modelParameters": {
 56296              "approach": {}
 56297            },
 56298            "quantitativeAnalysis": {
 56299              "graphics": {}
 56300            },
 56301            "considerations": {}
 56302          }
 56303        },
 56304        {
 56305          "type": "library",
 56306          "bom-ref": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=97dab883cac4c956",
 56307          "supplier": {},
 56308          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56309          "name": "bzip2",
 56310          "version": "1.0.8-2",
 56311          "licenses": [
 56312            {
 56313              "license": {
 56314                "name": "BSD-variant"
 56315              }
 56316            },
 56317            {
 56318              "license": {
 56319                "id": "GPL-2.0-only"
 56320              }
 56321            }
 56322          ],
 56323          "cpe": "cpe:2.3:a:bzip2:bzip2:1.0.8-2:*:*:*:*:*:*:*",
 56324          "purl": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04",
 56325          "swid": {
 56326            "attachment": {}
 56327          },
 56328          "pedigree": {},
 56329          "evidence": {},
 56330          "signature": {
 56331            "signature": {
 56332              "publicKey": {}
 56333            }
 56334          },
 56335          "modelCard": {
 56336            "modelParameters": {
 56337              "approach": {}
 56338            },
 56339            "quantitativeAnalysis": {
 56340              "graphics": {}
 56341            },
 56342            "considerations": {}
 56343          }
 56344        },
 56345        {
 56346          "type": "library",
 56347          "bom-ref": "pkg:deb/ubuntu/ca-certificates@20210119~20.04.1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=b34020e11d6f8983",
 56348          "supplier": {},
 56349          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56350          "name": "ca-certificates",
 56351          "version": "20210119~20.04.1",
 56352          "licenses": [
 56353            {
 56354              "license": {
 56355                "id": "GPL-2.0-only"
 56356              }
 56357            },
 56358            {
 56359              "license": {
 56360                "id": "GPL-2.0-or-later"
 56361              }
 56362            },
 56363            {
 56364              "license": {
 56365                "id": "MPL-2.0"
 56366              }
 56367            }
 56368          ],
 56369          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20210119\\~20.04.1:*:*:*:*:*:*:*",
 56370          "purl": "pkg:deb/ubuntu/ca-certificates@20210119~20.04.1?arch=all\u0026distro=ubuntu-20.04",
 56371          "swid": {
 56372            "attachment": {}
 56373          },
 56374          "pedigree": {},
 56375          "evidence": {},
 56376          "signature": {
 56377            "signature": {
 56378              "publicKey": {}
 56379            }
 56380          },
 56381          "modelCard": {
 56382            "modelParameters": {
 56383              "approach": {}
 56384            },
 56385            "quantitativeAnalysis": {
 56386              "graphics": {}
 56387            },
 56388            "considerations": {}
 56389          }
 56390        },
 56391        {
 56392          "type": "library",
 56393          "bom-ref": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f77283ee51e117fa",
 56394          "supplier": {},
 56395          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56396          "name": "coreutils",
 56397          "version": "8.30-3ubuntu2",
 56398          "licenses": [
 56399            {
 56400              "license": {
 56401                "id": "GPL-3.0-only"
 56402              }
 56403            }
 56404          ],
 56405          "cpe": "cpe:2.3:a:coreutils:coreutils:8.30-3ubuntu2:*:*:*:*:*:*:*",
 56406          "purl": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
 56407          "swid": {
 56408            "attachment": {}
 56409          },
 56410          "pedigree": {},
 56411          "evidence": {},
 56412          "signature": {
 56413            "signature": {
 56414              "publicKey": {}
 56415            }
 56416          },
 56417          "modelCard": {
 56418            "modelParameters": {
 56419              "approach": {}
 56420            },
 56421            "quantitativeAnalysis": {
 56422              "graphics": {}
 56423            },
 56424            "considerations": {}
 56425          }
 56426        },
 56427        {
 56428          "type": "library",
 56429          "bom-ref": "pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=123513dd4ae6c6b7",
 56430          "supplier": {},
 56431          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56432          "name": "curl",
 56433          "version": "7.68.0-1ubuntu2.6",
 56434          "licenses": [
 56435            {
 56436              "license": {
 56437                "id": "BSD-3-Clause"
 56438              }
 56439            },
 56440            {
 56441              "license": {
 56442                "id": "BSD-4-Clause"
 56443              }
 56444            },
 56445            {
 56446              "license": {
 56447                "id": "ISC"
 56448              }
 56449            },
 56450            {
 56451              "license": {
 56452                "id": "curl"
 56453              }
 56454            },
 56455            {
 56456              "license": {
 56457                "name": "other"
 56458              }
 56459            },
 56460            {
 56461              "license": {
 56462                "name": "public-domain"
 56463              }
 56464            }
 56465          ],
 56466          "cpe": "cpe:2.3:a:curl:curl:7.68.0-1ubuntu2.6:*:*:*:*:*:*:*",
 56467          "purl": "pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.6?arch=amd64\u0026distro=ubuntu-20.04",
 56468          "swid": {
 56469            "attachment": {}
 56470          },
 56471          "pedigree": {},
 56472          "evidence": {},
 56473          "signature": {
 56474            "signature": {
 56475              "publicKey": {}
 56476            }
 56477          },
 56478          "modelCard": {
 56479            "modelParameters": {
 56480              "approach": {}
 56481            },
 56482            "quantitativeAnalysis": {
 56483              "graphics": {}
 56484            },
 56485            "considerations": {}
 56486          }
 56487        },
 56488        {
 56489          "type": "library",
 56490          "bom-ref": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=fa0f613df8411b7",
 56491          "supplier": {},
 56492          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56493          "name": "dash",
 56494          "version": "0.5.10.2-6",
 56495          "licenses": [
 56496            {
 56497              "license": {
 56498                "name": "GPL"
 56499              }
 56500            }
 56501          ],
 56502          "cpe": "cpe:2.3:a:dash:dash:0.5.10.2-6:*:*:*:*:*:*:*",
 56503          "purl": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04",
 56504          "swid": {
 56505            "attachment": {}
 56506          },
 56507          "pedigree": {},
 56508          "evidence": {},
 56509          "signature": {
 56510            "signature": {
 56511              "publicKey": {}
 56512            }
 56513          },
 56514          "modelCard": {
 56515            "modelParameters": {
 56516              "approach": {}
 56517            },
 56518            "quantitativeAnalysis": {
 56519              "graphics": {}
 56520            },
 56521            "considerations": {}
 56522          }
 56523        },
 56524        {
 56525          "type": "library",
 56526          "bom-ref": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04\u0026package-id=128eb6066f5ec19c",
 56527          "supplier": {},
 56528          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56529          "name": "debconf",
 56530          "version": "1.5.73",
 56531          "licenses": [
 56532            {
 56533              "license": {
 56534                "id": "BSD-2-Clause"
 56535              }
 56536            }
 56537          ],
 56538          "cpe": "cpe:2.3:a:debconf:debconf:1.5.73:*:*:*:*:*:*:*",
 56539          "purl": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04",
 56540          "swid": {
 56541            "attachment": {}
 56542          },
 56543          "pedigree": {},
 56544          "evidence": {},
 56545          "signature": {
 56546            "signature": {
 56547              "publicKey": {}
 56548            }
 56549          },
 56550          "modelCard": {
 56551            "modelParameters": {
 56552              "approach": {}
 56553            },
 56554            "quantitativeAnalysis": {
 56555              "graphics": {}
 56556            },
 56557            "considerations": {}
 56558          }
 56559        },
 56560        {
 56561          "type": "library",
 56562          "bom-ref": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=328b1094024bda26",
 56563          "supplier": {},
 56564          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56565          "name": "debianutils",
 56566          "version": "4.9.1",
 56567          "licenses": [
 56568            {
 56569              "license": {
 56570                "name": "GPL"
 56571              }
 56572            }
 56573          ],
 56574          "cpe": "cpe:2.3:a:debianutils:debianutils:4.9.1:*:*:*:*:*:*:*",
 56575          "purl": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04",
 56576          "swid": {
 56577            "attachment": {}
 56578          },
 56579          "pedigree": {},
 56580          "evidence": {},
 56581          "signature": {
 56582            "signature": {
 56583              "publicKey": {}
 56584            }
 56585          },
 56586          "modelCard": {
 56587            "modelParameters": {
 56588              "approach": {}
 56589            },
 56590            "quantitativeAnalysis": {
 56591              "graphics": {}
 56592            },
 56593            "considerations": {}
 56594          }
 56595        },
 56596        {
 56597          "type": "library",
 56598          "bom-ref": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=d21aefcaf9c9c9b6",
 56599          "supplier": {},
 56600          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56601          "name": "diffutils",
 56602          "version": "1:3.7-3",
 56603          "licenses": [
 56604            {
 56605              "license": {
 56606                "name": "GFDL"
 56607              }
 56608            },
 56609            {
 56610              "license": {
 56611                "name": "GPL"
 56612              }
 56613            }
 56614          ],
 56615          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-3:*:*:*:*:*:*:*",
 56616          "purl": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04",
 56617          "swid": {
 56618            "attachment": {}
 56619          },
 56620          "pedigree": {},
 56621          "evidence": {},
 56622          "signature": {
 56623            "signature": {
 56624              "publicKey": {}
 56625            }
 56626          },
 56627          "modelCard": {
 56628            "modelParameters": {
 56629              "approach": {}
 56630            },
 56631            "quantitativeAnalysis": {
 56632              "graphics": {}
 56633            },
 56634            "considerations": {}
 56635          }
 56636        },
 56637        {
 56638          "type": "library",
 56639          "bom-ref": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=c0d6316be2747294",
 56640          "supplier": {},
 56641          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56642          "name": "dmsetup",
 56643          "version": "2:1.02.167-1ubuntu1",
 56644          "licenses": [
 56645            {
 56646              "license": {
 56647                "id": "BSD-2-Clause"
 56648              }
 56649            },
 56650            {
 56651              "license": {
 56652                "id": "GPL-2.0-only"
 56653              }
 56654            },
 56655            {
 56656              "license": {
 56657                "id": "GPL-2.0-only"
 56658              }
 56659            },
 56660            {
 56661              "license": {
 56662                "id": "GPL-2.0-or-later"
 56663              }
 56664            },
 56665            {
 56666              "license": {
 56667                "id": "LGPL-2.0-only"
 56668              }
 56669            },
 56670            {
 56671              "license": {
 56672                "id": "LGPL-2.1-only"
 56673              }
 56674            }
 56675          ],
 56676          "cpe": "cpe:2.3:a:dmsetup:dmsetup:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
 56677          "purl": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
 56678          "swid": {
 56679            "attachment": {}
 56680          },
 56681          "pedigree": {},
 56682          "evidence": {},
 56683          "signature": {
 56684            "signature": {
 56685              "publicKey": {}
 56686            }
 56687          },
 56688          "modelCard": {
 56689            "modelParameters": {
 56690              "approach": {}
 56691            },
 56692            "quantitativeAnalysis": {
 56693              "graphics": {}
 56694            },
 56695            "considerations": {}
 56696          }
 56697        },
 56698        {
 56699          "type": "library",
 56700          "bom-ref": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e28aea5c134a7f8",
 56701          "supplier": {},
 56702          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56703          "name": "dpkg",
 56704          "version": "1.19.7ubuntu3",
 56705          "licenses": [
 56706            {
 56707              "license": {
 56708                "id": "BSD-2-Clause"
 56709              }
 56710            },
 56711            {
 56712              "license": {
 56713                "id": "GPL-2.0-only"
 56714              }
 56715            },
 56716            {
 56717              "license": {
 56718                "id": "GPL-2.0-or-later"
 56719              }
 56720            },
 56721            {
 56722              "license": {
 56723                "name": "public-domain-md5"
 56724              }
 56725            },
 56726            {
 56727              "license": {
 56728                "name": "public-domain-s-s-d"
 56729              }
 56730            }
 56731          ],
 56732          "cpe": "cpe:2.3:a:dpkg:dpkg:1.19.7ubuntu3:*:*:*:*:*:*:*",
 56733          "purl": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04",
 56734          "swid": {
 56735            "attachment": {}
 56736          },
 56737          "pedigree": {},
 56738          "evidence": {},
 56739          "signature": {
 56740            "signature": {
 56741              "publicKey": {}
 56742            }
 56743          },
 56744          "modelCard": {
 56745            "modelParameters": {
 56746              "approach": {}
 56747            },
 56748            "quantitativeAnalysis": {
 56749              "graphics": {}
 56750            },
 56751            "considerations": {}
 56752          }
 56753        },
 56754        {
 56755          "type": "library",
 56756          "bom-ref": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=6a037357f3ebf47a",
 56757          "supplier": {},
 56758          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56759          "name": "e2fsprogs",
 56760          "version": "1.45.5-2ubuntu1",
 56761          "licenses": [
 56762            {
 56763              "license": {
 56764                "id": "GPL-2.0-only"
 56765              }
 56766            },
 56767            {
 56768              "license": {
 56769                "id": "LGPL-2.0-only"
 56770              }
 56771            }
 56772          ],
 56773          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 56774          "purl": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 56775          "swid": {
 56776            "attachment": {}
 56777          },
 56778          "pedigree": {},
 56779          "evidence": {},
 56780          "signature": {
 56781            "signature": {
 56782              "publicKey": {}
 56783            }
 56784          },
 56785          "modelCard": {
 56786            "modelParameters": {
 56787              "approach": {}
 56788            },
 56789            "quantitativeAnalysis": {
 56790              "graphics": {}
 56791            },
 56792            "considerations": {}
 56793          }
 56794        },
 56795        {
 56796          "type": "library",
 56797          "bom-ref": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=a57a5f37c7970fe9",
 56798          "supplier": {},
 56799          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56800          "name": "fdisk",
 56801          "version": "2.34-0.1ubuntu9.1",
 56802          "licenses": [
 56803            {
 56804              "license": {
 56805                "id": "BSD-2-Clause"
 56806              }
 56807            },
 56808            {
 56809              "license": {
 56810                "id": "BSD-3-Clause"
 56811              }
 56812            },
 56813            {
 56814              "license": {
 56815                "id": "BSD-4-Clause"
 56816              }
 56817            },
 56818            {
 56819              "license": {
 56820                "id": "GPL-2.0-only"
 56821              }
 56822            },
 56823            {
 56824              "license": {
 56825                "id": "GPL-2.0-or-later"
 56826              }
 56827            },
 56828            {
 56829              "license": {
 56830                "id": "GPL-3.0-only"
 56831              }
 56832            },
 56833            {
 56834              "license": {
 56835                "id": "GPL-3.0-or-later"
 56836              }
 56837            },
 56838            {
 56839              "license": {
 56840                "name": "LGPL"
 56841              }
 56842            },
 56843            {
 56844              "license": {
 56845                "id": "LGPL-2.0-only"
 56846              }
 56847            },
 56848            {
 56849              "license": {
 56850                "id": "LGPL-2.0-or-later"
 56851              }
 56852            },
 56853            {
 56854              "license": {
 56855                "id": "LGPL-2.1-only"
 56856              }
 56857            },
 56858            {
 56859              "license": {
 56860                "id": "LGPL-2.1-or-later"
 56861              }
 56862            },
 56863            {
 56864              "license": {
 56865                "id": "LGPL-3.0-only"
 56866              }
 56867            },
 56868            {
 56869              "license": {
 56870                "id": "LGPL-3.0-or-later"
 56871              }
 56872            },
 56873            {
 56874              "license": {
 56875                "id": "MIT"
 56876              }
 56877            },
 56878            {
 56879              "license": {
 56880                "name": "public-domain"
 56881              }
 56882            }
 56883          ],
 56884          "cpe": "cpe:2.3:a:fdisk:fdisk:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 56885          "purl": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 56886          "swid": {
 56887            "attachment": {}
 56888          },
 56889          "pedigree": {},
 56890          "evidence": {},
 56891          "signature": {
 56892            "signature": {
 56893              "publicKey": {}
 56894            }
 56895          },
 56896          "modelCard": {
 56897            "modelParameters": {
 56898              "approach": {}
 56899            },
 56900            "quantitativeAnalysis": {
 56901              "graphics": {}
 56902            },
 56903            "considerations": {}
 56904          }
 56905        },
 56906        {
 56907          "type": "library",
 56908          "bom-ref": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7f183ce6dc05cfb",
 56909          "supplier": {},
 56910          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56911          "name": "file",
 56912          "version": "1:5.38-4",
 56913          "licenses": [
 56914            {
 56915              "license": {
 56916                "name": "BSD-2-Clause-alike"
 56917              }
 56918            },
 56919            {
 56920              "license": {
 56921                "id": "BSD-2-Clause"
 56922              }
 56923            },
 56924            {
 56925              "license": {
 56926                "name": "BSD-2-Clause-regents"
 56927              }
 56928            },
 56929            {
 56930              "license": {
 56931                "name": "MIT-Old-Style-with-legal-disclaimer-2"
 56932              }
 56933            },
 56934            {
 56935              "license": {
 56936                "name": "public-domain"
 56937              }
 56938            }
 56939          ],
 56940          "cpe": "cpe:2.3:a:file:file:1\\:5.38-4:*:*:*:*:*:*:*",
 56941          "purl": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04",
 56942          "swid": {
 56943            "attachment": {}
 56944          },
 56945          "pedigree": {},
 56946          "evidence": {},
 56947          "signature": {
 56948            "signature": {
 56949              "publicKey": {}
 56950            }
 56951          },
 56952          "modelCard": {
 56953            "modelParameters": {
 56954              "approach": {}
 56955            },
 56956            "quantitativeAnalysis": {
 56957              "graphics": {}
 56958            },
 56959            "considerations": {}
 56960          }
 56961        },
 56962        {
 56963          "type": "library",
 56964          "bom-ref": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=103a5999463b7e08",
 56965          "supplier": {},
 56966          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 56967          "name": "findutils",
 56968          "version": "4.7.0-1ubuntu1",
 56969          "licenses": [
 56970            {
 56971              "license": {
 56972                "id": "GFDL-1.3-only"
 56973              }
 56974            },
 56975            {
 56976              "license": {
 56977                "id": "GPL-3.0-only"
 56978              }
 56979            }
 56980          ],
 56981          "cpe": "cpe:2.3:a:findutils:findutils:4.7.0-1ubuntu1:*:*:*:*:*:*:*",
 56982          "purl": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 56983          "swid": {
 56984            "attachment": {}
 56985          },
 56986          "pedigree": {},
 56987          "evidence": {},
 56988          "signature": {
 56989            "signature": {
 56990              "publicKey": {}
 56991            }
 56992          },
 56993          "modelCard": {
 56994            "modelParameters": {
 56995              "approach": {}
 56996            },
 56997            "quantitativeAnalysis": {
 56998              "graphics": {}
 56999            },
 57000            "considerations": {}
 57001          }
 57002        },
 57003        {
 57004          "type": "library",
 57005          "bom-ref": "pkg:deb/ubuntu/fuse@2.9.9-3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=3862cd07205c94e",
 57006          "supplier": {},
 57007          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 57008          "name": "fuse",
 57009          "version": "2.9.9-3",
 57010          "licenses": [
 57011            {
 57012              "license": {
 57013                "id": "GPL-2.0-only"
 57014              }
 57015            },
 57016            {
 57017              "license": {
 57018                "id": "GPL-2.0-or-later"
 57019              }
 57020            },
 57021            {
 57022              "license": {
 57023                "id": "LGPL-2.0-only"
 57024              }
 57025            }
 57026          ],
 57027          "cpe": "cpe:2.3:a:fuse:fuse:2.9.9-3:*:*:*:*:*:*:*",
 57028          "purl": "pkg:deb/ubuntu/fuse@2.9.9-3?arch=amd64\u0026distro=ubuntu-20.04",
 57029          "swid": {
 57030            "attachment": {}
 57031          },
 57032          "pedigree": {},
 57033          "evidence": {},
 57034          "signature": {
 57035            "signature": {
 57036              "publicKey": {}
 57037            }
 57038          },
 57039          "modelCard": {
 57040            "modelParameters": {
 57041              "approach": {}
 57042            },
 57043            "quantitativeAnalysis": {
 57044              "graphics": {}
 57045            },
 57046            "considerations": {}
 57047          }
 57048        },
 57049        {
 57050          "type": "library",
 57051          "bom-ref": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=a268d6ad2986f239",
 57052          "supplier": {},
 57053          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 57054          "name": "gcc-10-base",
 57055          "version": "10.3.0-1ubuntu1~20.04",
 57056          "licenses": [
 57057            {
 57058              "license": {
 57059                "name": "Artistic"
 57060              }
 57061            },
 57062            {
 57063              "license": {
 57064                "id": "GFDL-1.2-only"
 57065              }
 57066            },
 57067            {
 57068              "license": {
 57069                "name": "GPL"
 57070              }
 57071            },
 57072            {
 57073              "license": {
 57074                "id": "GPL-2.0-only"
 57075              }
 57076            },
 57077            {
 57078              "license": {
 57079                "id": "GPL-3.0-only"
 57080              }
 57081            },
 57082            {
 57083              "license": {
 57084                "name": "LGPL"
 57085              }
 57086            }
 57087          ],
 57088          "cpe": "cpe:2.3:a:gcc-10-base:gcc-10-base:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
 57089          "purl": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
 57090          "swid": {
 57091            "attachment": {}
 57092          },
 57093          "pedigree": {},
 57094          "evidence": {},
 57095          "signature": {
 57096            "signature": {
 57097              "publicKey": {}
 57098            }
 57099          },
 57100          "modelCard": {
 57101            "modelParameters": {
 57102              "approach": {}
 57103            },
 57104            "quantitativeAnalysis": {
 57105              "graphics": {}
 57106            },
 57107            "considerations": {}
 57108          }
 57109        },
 57110        {
 57111          "type": "library",
 57112          "bom-ref": "pkg:golang/github.com/roaringbitmap/roaring@v0.4.18?package-id=34176267a645222e",
 57113          "supplier": {},
 57114          "name": "github.com/RoaringBitmap/roaring",
 57115          "version": "v0.4.18",
 57116          "cpe": "cpe:2.3:a:RoaringBitmap:roaring:v0.4.18:*:*:*:*:*:*:*",
 57117          "purl": "pkg:golang/github.com/RoaringBitmap/roaring@v0.4.18",
 57118          "swid": {
 57119            "attachment": {}
 57120          },
 57121          "pedigree": {},
 57122          "evidence": {},
 57123          "signature": {
 57124            "signature": {
 57125              "publicKey": {}
 57126            }
 57127          },
 57128          "modelCard": {
 57129            "modelParameters": {
 57130              "approach": {}
 57131            },
 57132            "quantitativeAnalysis": {
 57133              "graphics": {}
 57134            },
 57135            "considerations": {}
 57136          }
 57137        },
 57138        {
 57139          "type": "library",
 57140          "bom-ref": "pkg:golang/github.com/aws/aws-sdk-go@v1.25.16?package-id=d8b03b75a855c026",
 57141          "supplier": {},
 57142          "name": "github.com/aws/aws-sdk-go",
 57143          "version": "v1.25.16",
 57144          "cpe": "cpe:2.3:a:aws:aws-sdk-go:v1.25.16:*:*:*:*:*:*:*",
 57145          "purl": "pkg:golang/github.com/aws/aws-sdk-go@v1.25.16",
 57146          "swid": {
 57147            "attachment": {}
 57148          },
 57149          "pedigree": {},
 57150          "evidence": {},
 57151          "signature": {
 57152            "signature": {
 57153              "publicKey": {}
 57154            }
 57155          },
 57156          "modelCard": {
 57157            "modelParameters": {
 57158              "approach": {}
 57159            },
 57160            "quantitativeAnalysis": {
 57161              "graphics": {}
 57162            },
 57163            "considerations": {}
 57164          }
 57165        },
 57166        {
 57167          "type": "library",
 57168          "bom-ref": "pkg:golang/github.com/c9s/goprocinfo@v0.0.0-20190309065803-0b2ad9ac246b?package-id=d078bfa34ba3c91a",
 57169          "supplier": {},
 57170          "name": "github.com/c9s/goprocinfo",
 57171          "version": "v0.0.0-20190309065803-0b2ad9ac246b",
 57172          "cpe": "cpe:2.3:a:c9s:goprocinfo:v0.0.0-20190309065803-0b2ad9ac246b:*:*:*:*:*:*:*",
 57173          "purl": "pkg:golang/github.com/c9s/goprocinfo@v0.0.0-20190309065803-0b2ad9ac246b",
 57174          "swid": {
 57175            "attachment": {}
 57176          },
 57177          "pedigree": {},
 57178          "evidence": {},
 57179          "signature": {
 57180            "signature": {
 57181              "publicKey": {}
 57182            }
 57183          },
 57184          "modelCard": {
 57185            "modelParameters": {
 57186              "approach": {}
 57187            },
 57188            "quantitativeAnalysis": {
 57189              "graphics": {}
 57190            },
 57191            "considerations": {}
 57192          }
 57193        },
 57194        {
 57195          "type": "library",
 57196          "bom-ref": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d?package-id=6b636d5ece874db4",
 57197          "supplier": {},
 57198          "name": "github.com/cpuguy83/go-md2man/v2",
 57199          "version": "v2.0.0-20190314233015-f79a8a8ca69d",
 57200          "cpe": "cpe:2.3:a:cpuguy83:go-md2man\\/v2:v2.0.0-20190314233015-f79a8a8ca69d:*:*:*:*:*:*:*",
 57201          "purl": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d",
 57202          "swid": {
 57203            "attachment": {}
 57204          },
 57205          "pedigree": {},
 57206          "evidence": {},
 57207          "signature": {
 57208            "signature": {
 57209              "publicKey": {}
 57210            }
 57211          },
 57212          "modelCard": {
 57213            "modelParameters": {
 57214              "approach": {}
 57215            },
 57216            "quantitativeAnalysis": {
 57217              "graphics": {}
 57218            },
 57219            "considerations": {}
 57220          }
 57221        },
 57222        {
 57223          "type": "library",
 57224          "bom-ref": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d?package-id=f1b1114a949891bc",
 57225          "supplier": {},
 57226          "name": "github.com/cpuguy83/go-md2man/v2",
 57227          "version": "v2.0.0-20190314233015-f79a8a8ca69d",
 57228          "cpe": "cpe:2.3:a:cpuguy83:go-md2man\\/v2:v2.0.0-20190314233015-f79a8a8ca69d:*:*:*:*:*:*:*",
 57229          "purl": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d",
 57230          "swid": {
 57231            "attachment": {}
 57232          },
 57233          "pedigree": {},
 57234          "evidence": {},
 57235          "signature": {
 57236            "signature": {
 57237              "publicKey": {}
 57238            }
 57239          },
 57240          "modelCard": {
 57241            "modelParameters": {
 57242              "approach": {}
 57243            },
 57244            "quantitativeAnalysis": {
 57245              "graphics": {}
 57246            },
 57247            "considerations": {}
 57248          }
 57249        },
 57250        {
 57251          "type": "library",
 57252          "bom-ref": "pkg:golang/github.com/docker/go-units@v0.3.3?package-id=71db3d9c141ba902",
 57253          "supplier": {},
 57254          "name": "github.com/docker/go-units",
 57255          "version": "v0.3.3",
 57256          "cpe": "cpe:2.3:a:docker:go-units:v0.3.3:*:*:*:*:*:*:*",
 57257          "purl": "pkg:golang/github.com/docker/go-units@v0.3.3",
 57258          "swid": {
 57259            "attachment": {}
 57260          },
 57261          "pedigree": {},
 57262          "evidence": {},
 57263          "signature": {
 57264            "signature": {
 57265              "publicKey": {}
 57266            }
 57267          },
 57268          "modelCard": {
 57269            "modelParameters": {
 57270              "approach": {}
 57271            },
 57272            "quantitativeAnalysis": {
 57273              "graphics": {}
 57274            },
 57275            "considerations": {}
 57276          }
 57277        },
 57278        {
 57279          "type": "library",
 57280          "bom-ref": "pkg:golang/github.com/glycerine/go-unsnap-stream@v0.0.0-20181221182339-f9677308dec2?package-id=56d8074cf7177f91",
 57281          "supplier": {},
 57282          "name": "github.com/glycerine/go-unsnap-stream",
 57283          "version": "v0.0.0-20181221182339-f9677308dec2",
 57284          "cpe": "cpe:2.3:a:glycerine:go-unsnap-stream:v0.0.0-20181221182339-f9677308dec2:*:*:*:*:*:*:*",
 57285          "purl": "pkg:golang/github.com/glycerine/go-unsnap-stream@v0.0.0-20181221182339-f9677308dec2",
 57286          "swid": {
 57287            "attachment": {}
 57288          },
 57289          "pedigree": {},
 57290          "evidence": {},
 57291          "signature": {
 57292            "signature": {
 57293              "publicKey": {}
 57294            }
 57295          },
 57296          "modelCard": {
 57297            "modelParameters": {
 57298              "approach": {}
 57299            },
 57300            "quantitativeAnalysis": {
 57301              "graphics": {}
 57302            },
 57303            "considerations": {}
 57304          }
 57305        },
 57306        {
 57307          "type": "library",
 57308          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.3.2?package-id=6429a79a5d94117",
 57309          "supplier": {},
 57310          "name": "github.com/golang/protobuf",
 57311          "version": "v1.3.2",
 57312          "cpe": "cpe:2.3:a:golang:protobuf:v1.3.2:*:*:*:*:*:*:*",
 57313          "purl": "pkg:golang/github.com/golang/protobuf@v1.3.2",
 57314          "swid": {
 57315            "attachment": {}
 57316          },
 57317          "pedigree": {},
 57318          "evidence": {},
 57319          "signature": {
 57320            "signature": {
 57321              "publicKey": {}
 57322            }
 57323          },
 57324          "modelCard": {
 57325            "modelParameters": {
 57326              "approach": {}
 57327            },
 57328            "quantitativeAnalysis": {
 57329              "graphics": {}
 57330            },
 57331            "considerations": {}
 57332          }
 57333        },
 57334        {
 57335          "type": "library",
 57336          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf?package-id=236d77cb45e8b164",
 57337          "supplier": {},
 57338          "name": "github.com/golang/protobuf",
 57339          "version": "v1.3.3-0.20190920234318-1680a479a2cf",
 57340          "cpe": "cpe:2.3:a:golang:protobuf:v1.3.3-0.20190920234318-1680a479a2cf:*:*:*:*:*:*:*",
 57341          "purl": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf",
 57342          "swid": {
 57343            "attachment": {}
 57344          },
 57345          "pedigree": {},
 57346          "evidence": {},
 57347          "signature": {
 57348            "signature": {
 57349              "publicKey": {}
 57350            }
 57351          },
 57352          "modelCard": {
 57353            "modelParameters": {
 57354              "approach": {}
 57355            },
 57356            "quantitativeAnalysis": {
 57357              "graphics": {}
 57358            },
 57359            "considerations": {}
 57360          }
 57361        },
 57362        {
 57363          "type": "library",
 57364          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf?package-id=f55bc79d4a937d1a",
 57365          "supplier": {},
 57366          "name": "github.com/golang/protobuf",
 57367          "version": "v1.3.3-0.20190920234318-1680a479a2cf",
 57368          "cpe": "cpe:2.3:a:golang:protobuf:v1.3.3-0.20190920234318-1680a479a2cf:*:*:*:*:*:*:*",
 57369          "purl": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf",
 57370          "swid": {
 57371            "attachment": {}
 57372          },
 57373          "pedigree": {},
 57374          "evidence": {},
 57375          "signature": {
 57376            "signature": {
 57377              "publicKey": {}
 57378            }
 57379          },
 57380          "modelCard": {
 57381            "modelParameters": {
 57382              "approach": {}
 57383            },
 57384            "quantitativeAnalysis": {
 57385              "graphics": {}
 57386            },
 57387            "considerations": {}
 57388          }
 57389        },
 57390        {
 57391          "type": "library",
 57392          "bom-ref": "pkg:golang/github.com/golang/snappy@v0.0.1?package-id=5837435a06653b52",
 57393          "supplier": {},
 57394          "name": "github.com/golang/snappy",
 57395          "version": "v0.0.1",
 57396          "cpe": "cpe:2.3:a:golang:snappy:v0.0.1:*:*:*:*:*:*:*",
 57397          "purl": "pkg:golang/github.com/golang/snappy@v0.0.1",
 57398          "swid": {
 57399            "attachment": {}
 57400          },
 57401          "pedigree": {},
 57402          "evidence": {},
 57403          "signature": {
 57404            "signature": {
 57405              "publicKey": {}
 57406            }
 57407          },
 57408          "modelCard": {
 57409            "modelParameters": {
 57410              "approach": {}
 57411            },
 57412            "quantitativeAnalysis": {
 57413              "graphics": {}
 57414            },
 57415            "considerations": {}
 57416          }
 57417        },
 57418        {
 57419          "type": "library",
 57420          "bom-ref": "pkg:golang/github.com/gorilla/context@v1.1.1?package-id=8c0080399b7036dc",
 57421          "supplier": {},
 57422          "name": "github.com/gorilla/context",
 57423          "version": "v1.1.1",
 57424          "cpe": "cpe:2.3:a:gorilla:context:v1.1.1:*:*:*:*:*:*:*",
 57425          "purl": "pkg:golang/github.com/gorilla/context@v1.1.1",
 57426          "swid": {
 57427            "attachment": {}
 57428          },
 57429          "pedigree": {},
 57430          "evidence": {},
 57431          "signature": {
 57432            "signature": {
 57433              "publicKey": {}
 57434            }
 57435          },
 57436          "modelCard": {
 57437            "modelParameters": {
 57438              "approach": {}
 57439            },
 57440            "quantitativeAnalysis": {
 57441              "graphics": {}
 57442            },
 57443            "considerations": {}
 57444          }
 57445        },
 57446        {
 57447          "type": "library",
 57448          "bom-ref": "pkg:golang/github.com/gorilla/handlers@v1.4.2?package-id=8027b79e27a696c1",
 57449          "supplier": {},
 57450          "name": "github.com/gorilla/handlers",
 57451          "version": "v1.4.2",
 57452          "cpe": "cpe:2.3:a:gorilla:handlers:v1.4.2:*:*:*:*:*:*:*",
 57453          "purl": "pkg:golang/github.com/gorilla/handlers@v1.4.2",
 57454          "swid": {
 57455            "attachment": {}
 57456          },
 57457          "pedigree": {},
 57458          "evidence": {},
 57459          "signature": {
 57460            "signature": {
 57461              "publicKey": {}
 57462            }
 57463          },
 57464          "modelCard": {
 57465            "modelParameters": {
 57466              "approach": {}
 57467            },
 57468            "quantitativeAnalysis": {
 57469              "graphics": {}
 57470            },
 57471            "considerations": {}
 57472          }
 57473        },
 57474        {
 57475          "type": "library",
 57476          "bom-ref": "pkg:golang/github.com/gorilla/mux@v1.7.3?package-id=dffb849d7867a4be",
 57477          "supplier": {},
 57478          "name": "github.com/gorilla/mux",
 57479          "version": "v1.7.3",
 57480          "cpe": "cpe:2.3:a:gorilla:mux:v1.7.3:*:*:*:*:*:*:*",
 57481          "purl": "pkg:golang/github.com/gorilla/mux@v1.7.3",
 57482          "swid": {
 57483            "attachment": {}
 57484          },
 57485          "pedigree": {},
 57486          "evidence": {},
 57487          "signature": {
 57488            "signature": {
 57489              "publicKey": {}
 57490            }
 57491          },
 57492          "modelCard": {
 57493            "modelParameters": {
 57494              "approach": {}
 57495            },
 57496            "quantitativeAnalysis": {
 57497              "graphics": {}
 57498            },
 57499            "considerations": {}
 57500          }
 57501        },
 57502        {
 57503          "type": "library",
 57504          "bom-ref": "pkg:golang/github.com/gorilla/websocket@v1.4.2?package-id=c357969583400ea6",
 57505          "supplier": {},
 57506          "name": "github.com/gorilla/websocket",
 57507          "version": "v1.4.2",
 57508          "cpe": "cpe:2.3:a:gorilla:websocket:v1.4.2:*:*:*:*:*:*:*",
 57509          "purl": "pkg:golang/github.com/gorilla/websocket@v1.4.2",
 57510          "swid": {
 57511            "attachment": {}
 57512          },
 57513          "pedigree": {},
 57514          "evidence": {},
 57515          "signature": {
 57516            "signature": {
 57517              "publicKey": {}
 57518            }
 57519          },
 57520          "modelCard": {
 57521            "modelParameters": {
 57522              "approach": {}
 57523            },
 57524            "quantitativeAnalysis": {
 57525              "graphics": {}
 57526            },
 57527            "considerations": {}
 57528          }
 57529        },
 57530        {
 57531          "type": "library",
 57532          "bom-ref": "pkg:golang/github.com/grpc-ecosystem/grpc-health-probe@(devel)?package-id=2ee2eb8d871be1ce",
 57533          "supplier": {},
 57534          "name": "github.com/grpc-ecosystem/grpc-health-probe",
 57535          "version": "(devel)",
 57536          "cpe": "cpe:2.3:a:grpc-ecosystem:grpc-health-probe:\\(devel\\):*:*:*:*:*:*:*",
 57537          "purl": "pkg:golang/github.com/grpc-ecosystem/grpc-health-probe@(devel)",
 57538          "swid": {
 57539            "attachment": {}
 57540          },
 57541          "pedigree": {},
 57542          "evidence": {},
 57543          "signature": {
 57544            "signature": {
 57545              "publicKey": {}
 57546            }
 57547          },
 57548          "modelCard": {
 57549            "modelParameters": {
 57550              "approach": {}
 57551            },
 57552            "quantitativeAnalysis": {
 57553              "graphics": {}
 57554            },
 57555            "considerations": {}
 57556          }
 57557        },
 57558        {
 57559          "type": "library",
 57560          "bom-ref": "pkg:golang/github.com/honestbee/jobq@v1.0.2?package-id=a8fd991182d37362",
 57561          "supplier": {},
 57562          "name": "github.com/honestbee/jobq",
 57563          "version": "v1.0.2",
 57564          "cpe": "cpe:2.3:a:honestbee:jobq:v1.0.2:*:*:*:*:*:*:*",
 57565          "purl": "pkg:golang/github.com/honestbee/jobq@v1.0.2",
 57566          "swid": {
 57567            "attachment": {}
 57568          },
 57569          "pedigree": {},
 57570          "evidence": {},
 57571          "signature": {
 57572            "signature": {
 57573              "publicKey": {}
 57574            }
 57575          },
 57576          "modelCard": {
 57577            "modelParameters": {
 57578              "approach": {}
 57579            },
 57580            "quantitativeAnalysis": {
 57581              "graphics": {}
 57582            },
 57583            "considerations": {}
 57584          }
 57585        },
 57586        {
 57587          "type": "library",
 57588          "bom-ref": "pkg:golang/github.com/jmespath/go-jmespath@v0.0.0-20180206201540-c2b33e8439af?package-id=bd9ecaabe79058f9",
 57589          "supplier": {},
 57590          "name": "github.com/jmespath/go-jmespath",
 57591          "version": "v0.0.0-20180206201540-c2b33e8439af",
 57592          "cpe": "cpe:2.3:a:jmespath:go-jmespath:v0.0.0-20180206201540-c2b33e8439af:*:*:*:*:*:*:*",
 57593          "purl": "pkg:golang/github.com/jmespath/go-jmespath@v0.0.0-20180206201540-c2b33e8439af",
 57594          "swid": {
 57595            "attachment": {}
 57596          },
 57597          "pedigree": {},
 57598          "evidence": {},
 57599          "signature": {
 57600            "signature": {
 57601              "publicKey": {}
 57602            }
 57603          },
 57604          "modelCard": {
 57605            "modelParameters": {
 57606              "approach": {}
 57607            },
 57608            "quantitativeAnalysis": {
 57609              "graphics": {}
 57610            },
 57611            "considerations": {}
 57612          }
 57613        },
 57614        {
 57615          "type": "library",
 57616          "bom-ref": "pkg:golang/github.com/longhorn/backupstore@v0.0.0-20210817080617-8ea3843e6b0d?package-id=86bad047f49929a5",
 57617          "supplier": {},
 57618          "name": "github.com/longhorn/backupstore",
 57619          "version": "v0.0.0-20210817080617-8ea3843e6b0d",
 57620          "cpe": "cpe:2.3:a:longhorn:backupstore:v0.0.0-20210817080617-8ea3843e6b0d:*:*:*:*:*:*:*",
 57621          "purl": "pkg:golang/github.com/longhorn/backupstore@v0.0.0-20210817080617-8ea3843e6b0d",
 57622          "swid": {
 57623            "attachment": {}
 57624          },
 57625          "pedigree": {},
 57626          "evidence": {},
 57627          "signature": {
 57628            "signature": {
 57629              "publicKey": {}
 57630            }
 57631          },
 57632          "modelCard": {
 57633            "modelParameters": {
 57634              "approach": {}
 57635            },
 57636            "quantitativeAnalysis": {
 57637              "graphics": {}
 57638            },
 57639            "considerations": {}
 57640          }
 57641        },
 57642        {
 57643          "type": "library",
 57644          "bom-ref": "pkg:golang/github.com/longhorn/go-iscsi-helper@v0.0.0-20210330030558-49a327fb024e?package-id=d30e6df72b1294ec",
 57645          "supplier": {},
 57646          "name": "github.com/longhorn/go-iscsi-helper",
 57647          "version": "v0.0.0-20210330030558-49a327fb024e",
 57648          "cpe": "cpe:2.3:a:longhorn:go-iscsi-helper:v0.0.0-20210330030558-49a327fb024e:*:*:*:*:*:*:*",
 57649          "purl": "pkg:golang/github.com/longhorn/go-iscsi-helper@v0.0.0-20210330030558-49a327fb024e",
 57650          "swid": {
 57651            "attachment": {}
 57652          },
 57653          "pedigree": {},
 57654          "evidence": {},
 57655          "signature": {
 57656            "signature": {
 57657              "publicKey": {}
 57658            }
 57659          },
 57660          "modelCard": {
 57661            "modelParameters": {
 57662              "approach": {}
 57663            },
 57664            "quantitativeAnalysis": {
 57665              "graphics": {}
 57666            },
 57667            "considerations": {}
 57668          }
 57669        },
 57670        {
 57671          "type": "library",
 57672          "bom-ref": "pkg:golang/github.com/longhorn/longhorn-engine@(devel)?package-id=8a83891345529d93",
 57673          "supplier": {},
 57674          "name": "github.com/longhorn/longhorn-engine",
 57675          "version": "(devel)",
 57676          "cpe": "cpe:2.3:a:longhorn:longhorn-engine:\\(devel\\):*:*:*:*:*:*:*",
 57677          "purl": "pkg:golang/github.com/longhorn/longhorn-engine@(devel)",
 57678          "swid": {
 57679            "attachment": {}
 57680          },
 57681          "pedigree": {},
 57682          "evidence": {},
 57683          "signature": {
 57684            "signature": {
 57685              "publicKey": {}
 57686            }
 57687          },
 57688          "modelCard": {
 57689            "modelParameters": {
 57690              "approach": {}
 57691            },
 57692            "quantitativeAnalysis": {
 57693              "graphics": {}
 57694            },
 57695            "considerations": {}
 57696          }
 57697        },
 57698        {
 57699          "type": "library",
 57700          "bom-ref": "pkg:golang/github.com/longhorn/longhorn-instance-manager@(devel)?package-id=2a1446182b15b62f",
 57701          "supplier": {},
 57702          "name": "github.com/longhorn/longhorn-instance-manager",
 57703          "version": "(devel)",
 57704          "cpe": "cpe:2.3:a:longhorn:longhorn-instance-manager:\\(devel\\):*:*:*:*:*:*:*",
 57705          "purl": "pkg:golang/github.com/longhorn/longhorn-instance-manager@(devel)",
 57706          "swid": {
 57707            "attachment": {}
 57708          },
 57709          "pedigree": {},
 57710          "evidence": {},
 57711          "signature": {
 57712            "signature": {
 57713              "publicKey": {}
 57714            }
 57715          },
 57716          "modelCard": {
 57717            "modelParameters": {
 57718              "approach": {}
 57719            },
 57720            "quantitativeAnalysis": {
 57721              "graphics": {}
 57722            },
 57723            "considerations": {}
 57724          }
 57725        },
 57726        {
 57727          "type": "library",
 57728          "bom-ref": "pkg:golang/github.com/longhorn/nsfilelock@v0.0.0-20200723175406-fa7c83ad0003?package-id=d1f54668db13d3da",
 57729          "supplier": {},
 57730          "name": "github.com/longhorn/nsfilelock",
 57731          "version": "v0.0.0-20200723175406-fa7c83ad0003",
 57732          "cpe": "cpe:2.3:a:longhorn:nsfilelock:v0.0.0-20200723175406-fa7c83ad0003:*:*:*:*:*:*:*",
 57733          "purl": "pkg:golang/github.com/longhorn/nsfilelock@v0.0.0-20200723175406-fa7c83ad0003",
 57734          "swid": {
 57735            "attachment": {}
 57736          },
 57737          "pedigree": {},
 57738          "evidence": {},
 57739          "signature": {
 57740            "signature": {
 57741              "publicKey": {}
 57742            }
 57743          },
 57744          "modelCard": {
 57745            "modelParameters": {
 57746              "approach": {}
 57747            },
 57748            "quantitativeAnalysis": {
 57749              "graphics": {}
 57750            },
 57751            "considerations": {}
 57752          }
 57753        },
 57754        {
 57755          "type": "library",
 57756          "bom-ref": "pkg:golang/github.com/longhorn/sparse-tools@v0.0.0-20210729195155-a0fb4226a960?package-id=4172598941363e6b",
 57757          "supplier": {},
 57758          "name": "github.com/longhorn/sparse-tools",
 57759          "version": "v0.0.0-20210729195155-a0fb4226a960",
 57760          "cpe": "cpe:2.3:a:longhorn:sparse-tools:v0.0.0-20210729195155-a0fb4226a960:*:*:*:*:*:*:*",
 57761          "purl": "pkg:golang/github.com/longhorn/sparse-tools@v0.0.0-20210729195155-a0fb4226a960",
 57762          "swid": {
 57763            "attachment": {}
 57764          },
 57765          "pedigree": {},
 57766          "evidence": {},
 57767          "signature": {
 57768            "signature": {
 57769              "publicKey": {}
 57770            }
 57771          },
 57772          "modelCard": {
 57773            "modelParameters": {
 57774              "approach": {}
 57775            },
 57776            "quantitativeAnalysis": {
 57777              "graphics": {}
 57778            },
 57779            "considerations": {}
 57780          }
 57781        },
 57782        {
 57783          "type": "library",
 57784          "bom-ref": "pkg:golang/github.com/mattn/go-runewidth@v0.0.5-0.20181218000649-703b5e6b11ae?package-id=8621cb30c3e0fd25",
 57785          "supplier": {},
 57786          "name": "github.com/mattn/go-runewidth",
 57787          "version": "v0.0.5-0.20181218000649-703b5e6b11ae",
 57788          "cpe": "cpe:2.3:a:mattn:go-runewidth:v0.0.5-0.20181218000649-703b5e6b11ae:*:*:*:*:*:*:*",
 57789          "purl": "pkg:golang/github.com/mattn/go-runewidth@v0.0.5-0.20181218000649-703b5e6b11ae",
 57790          "swid": {
 57791            "attachment": {}
 57792          },
 57793          "pedigree": {},
 57794          "evidence": {},
 57795          "signature": {
 57796            "signature": {
 57797              "publicKey": {}
 57798            }
 57799          },
 57800          "modelCard": {
 57801            "modelParameters": {
 57802              "approach": {}
 57803            },
 57804            "quantitativeAnalysis": {
 57805              "graphics": {}
 57806            },
 57807            "considerations": {}
 57808          }
 57809        },
 57810        {
 57811          "type": "library",
 57812          "bom-ref": "pkg:golang/github.com/moby/moby@v1.11.1?package-id=e5c9272a3028e1b2",
 57813          "supplier": {},
 57814          "name": "github.com/moby/moby",
 57815          "version": "v1.11.1",
 57816          "cpe": "cpe:2.3:a:moby:moby:v1.11.1:*:*:*:*:*:*:*",
 57817          "purl": "pkg:golang/github.com/moby/moby@v1.11.1",
 57818          "swid": {
 57819            "attachment": {}
 57820          },
 57821          "pedigree": {},
 57822          "evidence": {},
 57823          "signature": {
 57824            "signature": {
 57825              "publicKey": {}
 57826            }
 57827          },
 57828          "modelCard": {
 57829            "modelParameters": {
 57830              "approach": {}
 57831            },
 57832            "quantitativeAnalysis": {
 57833              "graphics": {}
 57834            },
 57835            "considerations": {}
 57836          }
 57837        },
 57838        {
 57839          "type": "library",
 57840          "bom-ref": "pkg:golang/github.com/philhofer/fwd@v1.0.0?package-id=3f3e822e0cc35abb",
 57841          "supplier": {},
 57842          "name": "github.com/philhofer/fwd",
 57843          "version": "v1.0.0",
 57844          "cpe": "cpe:2.3:a:philhofer:fwd:v1.0.0:*:*:*:*:*:*:*",
 57845          "purl": "pkg:golang/github.com/philhofer/fwd@v1.0.0",
 57846          "swid": {
 57847            "attachment": {}
 57848          },
 57849          "pedigree": {},
 57850          "evidence": {},
 57851          "signature": {
 57852            "signature": {
 57853              "publicKey": {}
 57854            }
 57855          },
 57856          "modelCard": {
 57857            "modelParameters": {
 57858              "approach": {}
 57859            },
 57860            "quantitativeAnalysis": {
 57861              "graphics": {}
 57862            },
 57863            "considerations": {}
 57864          }
 57865        },
 57866        {
 57867          "type": "library",
 57868          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.8.1?package-id=2a76c1ffd3374736",
 57869          "supplier": {},
 57870          "name": "github.com/pkg/errors",
 57871          "version": "v0.8.1",
 57872          "cpe": "cpe:2.3:a:pkg:errors:v0.8.1:*:*:*:*:*:*:*",
 57873          "purl": "pkg:golang/github.com/pkg/errors@v0.8.1",
 57874          "swid": {
 57875            "attachment": {}
 57876          },
 57877          "pedigree": {},
 57878          "evidence": {},
 57879          "signature": {
 57880            "signature": {
 57881              "publicKey": {}
 57882            }
 57883          },
 57884          "modelCard": {
 57885            "modelParameters": {
 57886              "approach": {}
 57887            },
 57888            "quantitativeAnalysis": {
 57889              "graphics": {}
 57890            },
 57891            "considerations": {}
 57892          }
 57893        },
 57894        {
 57895          "type": "library",
 57896          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.9.1?package-id=9b51cb83ae36e997",
 57897          "supplier": {},
 57898          "name": "github.com/pkg/errors",
 57899          "version": "v0.9.1",
 57900          "cpe": "cpe:2.3:a:pkg:errors:v0.9.1:*:*:*:*:*:*:*",
 57901          "purl": "pkg:golang/github.com/pkg/errors@v0.9.1",
 57902          "swid": {
 57903            "attachment": {}
 57904          },
 57905          "pedigree": {},
 57906          "evidence": {},
 57907          "signature": {
 57908            "signature": {
 57909              "publicKey": {}
 57910            }
 57911          },
 57912          "modelCard": {
 57913            "modelParameters": {
 57914              "approach": {}
 57915            },
 57916            "quantitativeAnalysis": {
 57917              "graphics": {}
 57918            },
 57919            "considerations": {}
 57920          }
 57921        },
 57922        {
 57923          "type": "library",
 57924          "bom-ref": "pkg:golang/github.com/rancher/go-fibmap@v0.0.0-20160418233256-5fc9f8c1ed47?package-id=5b75fb379c8383ee",
 57925          "supplier": {},
 57926          "name": "github.com/rancher/go-fibmap",
 57927          "version": "v0.0.0-20160418233256-5fc9f8c1ed47",
 57928          "cpe": "cpe:2.3:a:rancher:go-fibmap:v0.0.0-20160418233256-5fc9f8c1ed47:*:*:*:*:*:*:*",
 57929          "purl": "pkg:golang/github.com/rancher/go-fibmap@v0.0.0-20160418233256-5fc9f8c1ed47",
 57930          "swid": {
 57931            "attachment": {}
 57932          },
 57933          "pedigree": {},
 57934          "evidence": {},
 57935          "signature": {
 57936            "signature": {
 57937              "publicKey": {}
 57938            }
 57939          },
 57940          "modelCard": {
 57941            "modelParameters": {
 57942              "approach": {}
 57943            },
 57944            "quantitativeAnalysis": {
 57945              "graphics": {}
 57946            },
 57947            "considerations": {}
 57948          }
 57949        },
 57950        {
 57951          "type": "library",
 57952          "bom-ref": "pkg:golang/github.com/rancher/go-rancher@v0.1.1-0.20190307222549-9756097e5e4c?package-id=ea4e2adfba698990",
 57953          "supplier": {},
 57954          "name": "github.com/rancher/go-rancher",
 57955          "version": "v0.1.1-0.20190307222549-9756097e5e4c",
 57956          "cpe": "cpe:2.3:a:rancher:go-rancher:v0.1.1-0.20190307222549-9756097e5e4c:*:*:*:*:*:*:*",
 57957          "purl": "pkg:golang/github.com/rancher/go-rancher@v0.1.1-0.20190307222549-9756097e5e4c",
 57958          "swid": {
 57959            "attachment": {}
 57960          },
 57961          "pedigree": {},
 57962          "evidence": {},
 57963          "signature": {
 57964            "signature": {
 57965              "publicKey": {}
 57966            }
 57967          },
 57968          "modelCard": {
 57969            "modelParameters": {
 57970              "approach": {}
 57971            },
 57972            "quantitativeAnalysis": {
 57973              "graphics": {}
 57974            },
 57975            "considerations": {}
 57976          }
 57977        },
 57978        {
 57979          "type": "library",
 57980          "bom-ref": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1?package-id=74596aa2ccd0104b",
 57981          "supplier": {},
 57982          "name": "github.com/russross/blackfriday/v2",
 57983          "version": "v2.0.1",
 57984          "cpe": "cpe:2.3:a:russross:blackfriday\\/v2:v2.0.1:*:*:*:*:*:*:*",
 57985          "purl": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1",
 57986          "swid": {
 57987            "attachment": {}
 57988          },
 57989          "pedigree": {},
 57990          "evidence": {},
 57991          "signature": {
 57992            "signature": {
 57993              "publicKey": {}
 57994            }
 57995          },
 57996          "modelCard": {
 57997            "modelParameters": {
 57998              "approach": {}
 57999            },
 58000            "quantitativeAnalysis": {
 58001              "graphics": {}
 58002            },
 58003            "considerations": {}
 58004          }
 58005        },
 58006        {
 58007          "type": "library",
 58008          "bom-ref": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1?package-id=a68eb65cb6acb763",
 58009          "supplier": {},
 58010          "name": "github.com/russross/blackfriday/v2",
 58011          "version": "v2.0.1",
 58012          "cpe": "cpe:2.3:a:russross:blackfriday\\/v2:v2.0.1:*:*:*:*:*:*:*",
 58013          "purl": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1",
 58014          "swid": {
 58015            "attachment": {}
 58016          },
 58017          "pedigree": {},
 58018          "evidence": {},
 58019          "signature": {
 58020            "signature": {
 58021              "publicKey": {}
 58022            }
 58023          },
 58024          "modelCard": {
 58025            "modelParameters": {
 58026              "approach": {}
 58027            },
 58028            "quantitativeAnalysis": {
 58029              "graphics": {}
 58030            },
 58031            "considerations": {}
 58032          }
 58033        },
 58034        {
 58035          "type": "library",
 58036          "bom-ref": "pkg:golang/github.com/satori/go.uuid@v1.2.0?package-id=f7e06593f8f8037",
 58037          "supplier": {},
 58038          "name": "github.com/satori/go.uuid",
 58039          "version": "v1.2.0",
 58040          "cpe": "cpe:2.3:a:satori:go.uuid:v1.2.0:*:*:*:*:*:*:*",
 58041          "purl": "pkg:golang/github.com/satori/go.uuid@v1.2.0",
 58042          "swid": {
 58043            "attachment": {}
 58044          },
 58045          "pedigree": {},
 58046          "evidence": {},
 58047          "signature": {
 58048            "signature": {
 58049              "publicKey": {}
 58050            }
 58051          },
 58052          "modelCard": {
 58053            "modelParameters": {
 58054              "approach": {}
 58055            },
 58056            "quantitativeAnalysis": {
 58057              "graphics": {}
 58058            },
 58059            "considerations": {}
 58060          }
 58061        },
 58062        {
 58063          "type": "library",
 58064          "bom-ref": "pkg:golang/github.com/satori/go.uuid@v1.2.0?package-id=27fe1b1a158c8f7a",
 58065          "supplier": {},
 58066          "name": "github.com/satori/go.uuid",
 58067          "version": "v1.2.0",
 58068          "cpe": "cpe:2.3:a:satori:go.uuid:v1.2.0:*:*:*:*:*:*:*",
 58069          "purl": "pkg:golang/github.com/satori/go.uuid@v1.2.0",
 58070          "swid": {
 58071            "attachment": {}
 58072          },
 58073          "pedigree": {},
 58074          "evidence": {},
 58075          "signature": {
 58076            "signature": {
 58077              "publicKey": {}
 58078            }
 58079          },
 58080          "modelCard": {
 58081            "modelParameters": {
 58082              "approach": {}
 58083            },
 58084            "quantitativeAnalysis": {
 58085              "graphics": {}
 58086            },
 58087            "considerations": {}
 58088          }
 58089        },
 58090        {
 58091          "type": "library",
 58092          "bom-ref": "pkg:golang/github.com/shurcool/sanitized_anchor_name@v1.0.0?package-id=edcf26537c93fd2f",
 58093          "supplier": {},
 58094          "name": "github.com/shurcooL/sanitized_anchor_name",
 58095          "version": "v1.0.0",
 58096          "cpe": "cpe:2.3:a:shurcooL:sanitized-anchor-name:v1.0.0:*:*:*:*:*:*:*",
 58097          "purl": "pkg:golang/github.com/shurcooL/sanitized_anchor_name@v1.0.0",
 58098          "swid": {
 58099            "attachment": {}
 58100          },
 58101          "pedigree": {},
 58102          "evidence": {},
 58103          "signature": {
 58104            "signature": {
 58105              "publicKey": {}
 58106            }
 58107          },
 58108          "modelCard": {
 58109            "modelParameters": {
 58110              "approach": {}
 58111            },
 58112            "quantitativeAnalysis": {
 58113              "graphics": {}
 58114            },
 58115            "considerations": {}
 58116          }
 58117        },
 58118        {
 58119          "type": "library",
 58120          "bom-ref": "pkg:golang/github.com/shurcool/sanitized_anchor_name@v1.0.0?package-id=5c742bc94a35bb3",
 58121          "supplier": {},
 58122          "name": "github.com/shurcooL/sanitized_anchor_name",
 58123          "version": "v1.0.0",
 58124          "cpe": "cpe:2.3:a:shurcooL:sanitized-anchor-name:v1.0.0:*:*:*:*:*:*:*",
 58125          "purl": "pkg:golang/github.com/shurcooL/sanitized_anchor_name@v1.0.0",
 58126          "swid": {
 58127            "attachment": {}
 58128          },
 58129          "pedigree": {},
 58130          "evidence": {},
 58131          "signature": {
 58132            "signature": {
 58133              "publicKey": {}
 58134            }
 58135          },
 58136          "modelCard": {
 58137            "modelParameters": {
 58138              "approach": {}
 58139            },
 58140            "quantitativeAnalysis": {
 58141              "graphics": {}
 58142            },
 58143            "considerations": {}
 58144          }
 58145        },
 58146        {
 58147          "type": "library",
 58148          "bom-ref": "pkg:golang/github.com/sirupsen/logrus@v1.4.1?package-id=4fff64256857776",
 58149          "supplier": {},
 58150          "name": "github.com/sirupsen/logrus",
 58151          "version": "v1.4.1",
 58152          "cpe": "cpe:2.3:a:sirupsen:logrus:v1.4.1:*:*:*:*:*:*:*",
 58153          "purl": "pkg:golang/github.com/sirupsen/logrus@v1.4.1",
 58154          "swid": {
 58155            "attachment": {}
 58156          },
 58157          "pedigree": {},
 58158          "evidence": {},
 58159          "signature": {
 58160            "signature": {
 58161              "publicKey": {}
 58162            }
 58163          },
 58164          "modelCard": {
 58165            "modelParameters": {
 58166              "approach": {}
 58167            },
 58168            "quantitativeAnalysis": {
 58169              "graphics": {}
 58170            },
 58171            "considerations": {}
 58172          }
 58173        },
 58174        {
 58175          "type": "library",
 58176          "bom-ref": "pkg:golang/github.com/sirupsen/logrus@v1.8.1?package-id=3005d75bd9444515",
 58177          "supplier": {},
 58178          "name": "github.com/sirupsen/logrus",
 58179          "version": "v1.8.1",
 58180          "cpe": "cpe:2.3:a:sirupsen:logrus:v1.8.1:*:*:*:*:*:*:*",
 58181          "purl": "pkg:golang/github.com/sirupsen/logrus@v1.8.1",
 58182          "swid": {
 58183            "attachment": {}
 58184          },
 58185          "pedigree": {},
 58186          "evidence": {},
 58187          "signature": {
 58188            "signature": {
 58189              "publicKey": {}
 58190            }
 58191          },
 58192          "modelCard": {
 58193            "modelParameters": {
 58194              "approach": {}
 58195            },
 58196            "quantitativeAnalysis": {
 58197              "graphics": {}
 58198            },
 58199            "considerations": {}
 58200          }
 58201        },
 58202        {
 58203          "type": "library",
 58204          "bom-ref": "pkg:golang/github.com/tinylib/msgp@v1.1.1-0.20190612170807-0573788bc2a8?package-id=30ee6e6d1128a1ec",
 58205          "supplier": {},
 58206          "name": "github.com/tinylib/msgp",
 58207          "version": "v1.1.1-0.20190612170807-0573788bc2a8",
 58208          "cpe": "cpe:2.3:a:tinylib:msgp:v1.1.1-0.20190612170807-0573788bc2a8:*:*:*:*:*:*:*",
 58209          "purl": "pkg:golang/github.com/tinylib/msgp@v1.1.1-0.20190612170807-0573788bc2a8",
 58210          "swid": {
 58211            "attachment": {}
 58212          },
 58213          "pedigree": {},
 58214          "evidence": {},
 58215          "signature": {
 58216            "signature": {
 58217              "publicKey": {}
 58218            }
 58219          },
 58220          "modelCard": {
 58221            "modelParameters": {
 58222              "approach": {}
 58223            },
 58224            "quantitativeAnalysis": {
 58225              "graphics": {}
 58226            },
 58227            "considerations": {}
 58228          }
 58229        },
 58230        {
 58231          "type": "library",
 58232          "bom-ref": "pkg:golang/github.com/urfave/cli@v1.22.1?package-id=a60136e79ed3ff0a",
 58233          "supplier": {},
 58234          "name": "github.com/urfave/cli",
 58235          "version": "v1.22.1",
 58236          "cpe": "cpe:2.3:a:urfave:cli:v1.22.1:*:*:*:*:*:*:*",
 58237          "purl": "pkg:golang/github.com/urfave/cli@v1.22.1",
 58238          "swid": {
 58239            "attachment": {}
 58240          },
 58241          "pedigree": {},
 58242          "evidence": {},
 58243          "signature": {
 58244            "signature": {
 58245              "publicKey": {}
 58246            }
 58247          },
 58248          "modelCard": {
 58249            "modelParameters": {
 58250              "approach": {}
 58251            },
 58252            "quantitativeAnalysis": {
 58253              "graphics": {}
 58254            },
 58255            "considerations": {}
 58256          }
 58257        },
 58258        {
 58259          "type": "library",
 58260          "bom-ref": "pkg:golang/github.com/urfave/cli@v1.22.1?package-id=13001d945ae58cae",
 58261          "supplier": {},
 58262          "name": "github.com/urfave/cli",
 58263          "version": "v1.22.1",
 58264          "cpe": "cpe:2.3:a:urfave:cli:v1.22.1:*:*:*:*:*:*:*",
 58265          "purl": "pkg:golang/github.com/urfave/cli@v1.22.1",
 58266          "swid": {
 58267            "attachment": {}
 58268          },
 58269          "pedigree": {},
 58270          "evidence": {},
 58271          "signature": {
 58272            "signature": {
 58273              "publicKey": {}
 58274            }
 58275          },
 58276          "modelCard": {
 58277            "modelParameters": {
 58278              "approach": {}
 58279            },
 58280            "quantitativeAnalysis": {
 58281              "graphics": {}
 58282            },
 58283            "considerations": {}
 58284          }
 58285        },
 58286        {
 58287          "type": "library",
 58288          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20190522155817-f3200d17e092?package-id=6692e3bf85b5516d",
 58289          "supplier": {},
 58290          "name": "golang.org/x/net",
 58291          "version": "v0.0.0-20190522155817-f3200d17e092",
 58292          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20190522155817-f3200d17e092:*:*:*:*:*:*:*",
 58293          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20190522155817-f3200d17e092",
 58294          "swid": {
 58295            "attachment": {}
 58296          },
 58297          "pedigree": {},
 58298          "evidence": {},
 58299          "signature": {
 58300            "signature": {
 58301              "publicKey": {}
 58302            }
 58303          },
 58304          "modelCard": {
 58305            "modelParameters": {
 58306              "approach": {}
 58307            },
 58308            "quantitativeAnalysis": {
 58309              "graphics": {}
 58310            },
 58311            "considerations": {}
 58312          }
 58313        },
 58314        {
 58315          "type": "library",
 58316          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20190522155817-f3200d17e092?package-id=97b953d6daf049e8",
 58317          "supplier": {},
 58318          "name": "golang.org/x/net",
 58319          "version": "v0.0.0-20190522155817-f3200d17e092",
 58320          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20190522155817-f3200d17e092:*:*:*:*:*:*:*",
 58321          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20190522155817-f3200d17e092",
 58322          "swid": {
 58323            "attachment": {}
 58324          },
 58325          "pedigree": {},
 58326          "evidence": {},
 58327          "signature": {
 58328            "signature": {
 58329              "publicKey": {}
 58330            }
 58331          },
 58332          "modelCard": {
 58333            "modelParameters": {
 58334              "approach": {}
 58335            },
 58336            "quantitativeAnalysis": {
 58337              "graphics": {}
 58338            },
 58339            "considerations": {}
 58340          }
 58341        },
 58342        {
 58343          "type": "library",
 58344          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20191021144547-ec77196f6094?package-id=dba26920fcd941ca",
 58345          "supplier": {},
 58346          "name": "golang.org/x/net",
 58347          "version": "v0.0.0-20191021144547-ec77196f6094",
 58348          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20191021144547-ec77196f6094:*:*:*:*:*:*:*",
 58349          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20191021144547-ec77196f6094",
 58350          "swid": {
 58351            "attachment": {}
 58352          },
 58353          "pedigree": {},
 58354          "evidence": {},
 58355          "signature": {
 58356            "signature": {
 58357              "publicKey": {}
 58358            }
 58359          },
 58360          "modelCard": {
 58361            "modelParameters": {
 58362              "approach": {}
 58363            },
 58364            "quantitativeAnalysis": {
 58365              "graphics": {}
 58366            },
 58367            "considerations": {}
 58368          }
 58369        },
 58370        {
 58371          "type": "library",
 58372          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20190524152521-dbbf3f1254d4?package-id=7943c2f7e89d796c",
 58373          "supplier": {},
 58374          "name": "golang.org/x/sys",
 58375          "version": "v0.0.0-20190524152521-dbbf3f1254d4",
 58376          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20190524152521-dbbf3f1254d4:*:*:*:*:*:*:*",
 58377          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20190524152521-dbbf3f1254d4",
 58378          "swid": {
 58379            "attachment": {}
 58380          },
 58381          "pedigree": {},
 58382          "evidence": {},
 58383          "signature": {
 58384            "signature": {
 58385              "publicKey": {}
 58386            }
 58387          },
 58388          "modelCard": {
 58389            "modelParameters": {
 58390              "approach": {}
 58391            },
 58392            "quantitativeAnalysis": {
 58393              "graphics": {}
 58394            },
 58395            "considerations": {}
 58396          }
 58397        },
 58398        {
 58399          "type": "library",
 58400          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20191020212454-3e7259c5e7c2?package-id=11cab605143eb4a2",
 58401          "supplier": {},
 58402          "name": "golang.org/x/sys",
 58403          "version": "v0.0.0-20191020212454-3e7259c5e7c2",
 58404          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20191020212454-3e7259c5e7c2:*:*:*:*:*:*:*",
 58405          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20191020212454-3e7259c5e7c2",
 58406          "swid": {
 58407            "attachment": {}
 58408          },
 58409          "pedigree": {},
 58410          "evidence": {},
 58411          "signature": {
 58412            "signature": {
 58413              "publicKey": {}
 58414            }
 58415          },
 58416          "modelCard": {
 58417            "modelParameters": {
 58418              "approach": {}
 58419            },
 58420            "quantitativeAnalysis": {
 58421              "graphics": {}
 58422            },
 58423            "considerations": {}
 58424          }
 58425        },
 58426        {
 58427          "type": "library",
 58428          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c?package-id=fa1dad70a13f8995",
 58429          "supplier": {},
 58430          "name": "golang.org/x/sys",
 58431          "version": "v0.0.0-20210630005230-0f9fa26af87c",
 58432          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20210630005230-0f9fa26af87c:*:*:*:*:*:*:*",
 58433          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c",
 58434          "swid": {
 58435            "attachment": {}
 58436          },
 58437          "pedigree": {},
 58438          "evidence": {},
 58439          "signature": {
 58440            "signature": {
 58441              "publicKey": {}
 58442            }
 58443          },
 58444          "modelCard": {
 58445            "modelParameters": {
 58446              "approach": {}
 58447            },
 58448            "quantitativeAnalysis": {
 58449              "graphics": {}
 58450            },
 58451            "considerations": {}
 58452          }
 58453        },
 58454        {
 58455          "type": "library",
 58456          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.2?package-id=79c19ce62be197dd",
 58457          "supplier": {},
 58458          "name": "golang.org/x/text",
 58459          "version": "v0.3.2",
 58460          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.2:*:*:*:*:*:*:*",
 58461          "purl": "pkg:golang/golang.org/x/text@v0.3.2",
 58462          "swid": {
 58463            "attachment": {}
 58464          },
 58465          "pedigree": {},
 58466          "evidence": {},
 58467          "signature": {
 58468            "signature": {
 58469              "publicKey": {}
 58470            }
 58471          },
 58472          "modelCard": {
 58473            "modelParameters": {
 58474              "approach": {}
 58475            },
 58476            "quantitativeAnalysis": {
 58477              "graphics": {}
 58478            },
 58479            "considerations": {}
 58480          }
 58481        },
 58482        {
 58483          "type": "library",
 58484          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.2?package-id=26bc6155d2292b0f",
 58485          "supplier": {},
 58486          "name": "golang.org/x/text",
 58487          "version": "v0.3.2",
 58488          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.2:*:*:*:*:*:*:*",
 58489          "purl": "pkg:golang/golang.org/x/text@v0.3.2",
 58490          "swid": {
 58491            "attachment": {}
 58492          },
 58493          "pedigree": {},
 58494          "evidence": {},
 58495          "signature": {
 58496            "signature": {
 58497              "publicKey": {}
 58498            }
 58499          },
 58500          "modelCard": {
 58501            "modelParameters": {
 58502              "approach": {}
 58503            },
 58504            "quantitativeAnalysis": {
 58505              "graphics": {}
 58506            },
 58507            "considerations": {}
 58508          }
 58509        },
 58510        {
 58511          "type": "library",
 58512          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.3?package-id=6ea8fbd4b018a5a0",
 58513          "supplier": {},
 58514          "name": "golang.org/x/text",
 58515          "version": "v0.3.3",
 58516          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.3:*:*:*:*:*:*:*",
 58517          "purl": "pkg:golang/golang.org/x/text@v0.3.3",
 58518          "swid": {
 58519            "attachment": {}
 58520          },
 58521          "pedigree": {},
 58522          "evidence": {},
 58523          "signature": {
 58524            "signature": {
 58525              "publicKey": {}
 58526            }
 58527          },
 58528          "modelCard": {
 58529            "modelParameters": {
 58530              "approach": {}
 58531            },
 58532            "quantitativeAnalysis": {
 58533              "graphics": {}
 58534            },
 58535            "considerations": {}
 58536          }
 58537        },
 58538        {
 58539          "type": "library",
 58540          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20180817151627-c66870c02cf8?package-id=adf6f54509b5bc12",
 58541          "supplier": {},
 58542          "name": "google.golang.org/genproto",
 58543          "version": "v0.0.0-20180817151627-c66870c02cf8",
 58544          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20180817151627-c66870c02cf8:*:*:*:*:*:*:*",
 58545          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20180817151627-c66870c02cf8",
 58546          "swid": {
 58547            "attachment": {}
 58548          },
 58549          "pedigree": {},
 58550          "evidence": {},
 58551          "signature": {
 58552            "signature": {
 58553              "publicKey": {}
 58554            }
 58555          },
 58556          "modelCard": {
 58557            "modelParameters": {
 58558              "approach": {}
 58559            },
 58560            "quantitativeAnalysis": {
 58561              "graphics": {}
 58562            },
 58563            "considerations": {}
 58564          }
 58565        },
 58566        {
 58567          "type": "library",
 58568          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20180817151627-c66870c02cf8?package-id=c0d6544f847ebd01",
 58569          "supplier": {},
 58570          "name": "google.golang.org/genproto",
 58571          "version": "v0.0.0-20180817151627-c66870c02cf8",
 58572          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20180817151627-c66870c02cf8:*:*:*:*:*:*:*",
 58573          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20180817151627-c66870c02cf8",
 58574          "swid": {
 58575            "attachment": {}
 58576          },
 58577          "pedigree": {},
 58578          "evidence": {},
 58579          "signature": {
 58580            "signature": {
 58581              "publicKey": {}
 58582            }
 58583          },
 58584          "modelCard": {
 58585            "modelParameters": {
 58586              "approach": {}
 58587            },
 58588            "quantitativeAnalysis": {
 58589              "graphics": {}
 58590            },
 58591            "considerations": {}
 58592          }
 58593        },
 58594        {
 58595          "type": "library",
 58596          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20191009194640-548a555dbc03?package-id=9631f02c5c120cff",
 58597          "supplier": {},
 58598          "name": "google.golang.org/genproto",
 58599          "version": "v0.0.0-20191009194640-548a555dbc03",
 58600          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20191009194640-548a555dbc03:*:*:*:*:*:*:*",
 58601          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20191009194640-548a555dbc03",
 58602          "swid": {
 58603            "attachment": {}
 58604          },
 58605          "pedigree": {},
 58606          "evidence": {},
 58607          "signature": {
 58608            "signature": {
 58609              "publicKey": {}
 58610            }
 58611          },
 58612          "modelCard": {
 58613            "modelParameters": {
 58614              "approach": {}
 58615            },
 58616            "quantitativeAnalysis": {
 58617              "graphics": {}
 58618            },
 58619            "considerations": {}
 58620          }
 58621        },
 58622        {
 58623          "type": "library",
 58624          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.21.0?package-id=1d354efe3ed788f2",
 58625          "supplier": {},
 58626          "name": "google.golang.org/grpc",
 58627          "version": "v1.21.0",
 58628          "cpe": "cpe:2.3:a:google:grpc:v1.21.0:*:*:*:*:*:*:*",
 58629          "purl": "pkg:golang/google.golang.org/grpc@v1.21.0",
 58630          "swid": {
 58631            "attachment": {}
 58632          },
 58633          "pedigree": {},
 58634          "evidence": {},
 58635          "signature": {
 58636            "signature": {
 58637              "publicKey": {}
 58638            }
 58639          },
 58640          "modelCard": {
 58641            "modelParameters": {
 58642              "approach": {}
 58643            },
 58644            "quantitativeAnalysis": {
 58645              "graphics": {}
 58646            },
 58647            "considerations": {}
 58648          }
 58649        },
 58650        {
 58651          "type": "library",
 58652          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.21.0?package-id=b9f15a7ff3d6fda6",
 58653          "supplier": {},
 58654          "name": "google.golang.org/grpc",
 58655          "version": "v1.21.0",
 58656          "cpe": "cpe:2.3:a:google:grpc:v1.21.0:*:*:*:*:*:*:*",
 58657          "purl": "pkg:golang/google.golang.org/grpc@v1.21.0",
 58658          "swid": {
 58659            "attachment": {}
 58660          },
 58661          "pedigree": {},
 58662          "evidence": {},
 58663          "signature": {
 58664            "signature": {
 58665              "publicKey": {}
 58666            }
 58667          },
 58668          "modelCard": {
 58669            "modelParameters": {
 58670              "approach": {}
 58671            },
 58672            "quantitativeAnalysis": {
 58673              "graphics": {}
 58674            },
 58675            "considerations": {}
 58676          }
 58677        },
 58678        {
 58679          "type": "library",
 58680          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.24.0?package-id=54401e81e1c7ca15",
 58681          "supplier": {},
 58682          "name": "google.golang.org/grpc",
 58683          "version": "v1.24.0",
 58684          "cpe": "cpe:2.3:a:google:grpc:v1.24.0:*:*:*:*:*:*:*",
 58685          "purl": "pkg:golang/google.golang.org/grpc@v1.24.0",
 58686          "swid": {
 58687            "attachment": {}
 58688          },
 58689          "pedigree": {},
 58690          "evidence": {},
 58691          "signature": {
 58692            "signature": {
 58693              "publicKey": {}
 58694            }
 58695          },
 58696          "modelCard": {
 58697            "modelParameters": {
 58698              "approach": {}
 58699            },
 58700            "quantitativeAnalysis": {
 58701              "graphics": {}
 58702            },
 58703            "considerations": {}
 58704          }
 58705        },
 58706        {
 58707          "type": "library",
 58708          "bom-ref": "pkg:golang/gopkg.in/cheggaaa/pb.v2@v2.0.0-20190301131520-f907f6f5dd81?package-id=42d84823e9eebfc4",
 58709          "supplier": {},
 58710          "name": "gopkg.in/cheggaaa/pb.v2",
 58711          "version": "v2.0.0-20190301131520-f907f6f5dd81",
 58712          "purl": "pkg:golang/gopkg.in/cheggaaa/pb.v2@v2.0.0-20190301131520-f907f6f5dd81",
 58713          "swid": {
 58714            "attachment": {}
 58715          },
 58716          "pedigree": {},
 58717          "evidence": {},
 58718          "signature": {
 58719            "signature": {
 58720              "publicKey": {}
 58721            }
 58722          },
 58723          "modelCard": {
 58724            "modelParameters": {
 58725              "approach": {}
 58726            },
 58727            "quantitativeAnalysis": {
 58728              "graphics": {}
 58729            },
 58730            "considerations": {}
 58731          }
 58732        },
 58733        {
 58734          "type": "library",
 58735          "bom-ref": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04\u0026package-id=b3a56223224b45d2",
 58736          "supplier": {},
 58737          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 58738          "name": "gpgv",
 58739          "version": "2.2.19-3ubuntu2.1",
 58740          "licenses": [
 58741            {
 58742              "license": {
 58743                "id": "BSD-3-Clause"
 58744              }
 58745            },
 58746            {
 58747              "license": {
 58748                "id": "CC0-1.0"
 58749              }
 58750            },
 58751            {
 58752              "license": {
 58753                "name": "Expat"
 58754              }
 58755            },
 58756            {
 58757              "license": {
 58758                "id": "GPL-3.0-only"
 58759              }
 58760            },
 58761            {
 58762              "license": {
 58763                "id": "GPL-3.0-or-later"
 58764              }
 58765            },
 58766            {
 58767              "license": {
 58768                "id": "LGPL-2.1-only"
 58769              }
 58770            },
 58771            {
 58772              "license": {
 58773                "id": "LGPL-2.1-or-later"
 58774              }
 58775            },
 58776            {
 58777              "license": {
 58778                "id": "LGPL-3.0-only"
 58779              }
 58780            },
 58781            {
 58782              "license": {
 58783                "id": "LGPL-3.0-or-later"
 58784              }
 58785            },
 58786            {
 58787              "license": {
 58788                "name": "RFC-Reference"
 58789              }
 58790            },
 58791            {
 58792              "license": {
 58793                "name": "TinySCHEME"
 58794              }
 58795            },
 58796            {
 58797              "license": {
 58798                "name": "permissive"
 58799              }
 58800            }
 58801          ],
 58802          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.19-3ubuntu2.1:*:*:*:*:*:*:*",
 58803          "purl": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04",
 58804          "swid": {
 58805            "attachment": {}
 58806          },
 58807          "pedigree": {},
 58808          "evidence": {},
 58809          "signature": {
 58810            "signature": {
 58811              "publicKey": {}
 58812            }
 58813          },
 58814          "modelCard": {
 58815            "modelParameters": {
 58816              "approach": {}
 58817            },
 58818            "quantitativeAnalysis": {
 58819              "graphics": {}
 58820            },
 58821            "considerations": {}
 58822          }
 58823        },
 58824        {
 58825          "type": "library",
 58826          "bom-ref": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7af9af4b90473f",
 58827          "supplier": {},
 58828          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 58829          "name": "grep",
 58830          "version": "3.4-1",
 58831          "licenses": [
 58832            {
 58833              "license": {
 58834                "id": "GPL-3.0-only"
 58835              }
 58836            },
 58837            {
 58838              "license": {
 58839                "id": "GPL-3.0-or-later"
 58840              }
 58841            }
 58842          ],
 58843          "cpe": "cpe:2.3:a:grep:grep:3.4-1:*:*:*:*:*:*:*",
 58844          "purl": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04",
 58845          "swid": {
 58846            "attachment": {}
 58847          },
 58848          "pedigree": {},
 58849          "evidence": {},
 58850          "signature": {
 58851            "signature": {
 58852              "publicKey": {}
 58853            }
 58854          },
 58855          "modelCard": {
 58856            "modelParameters": {
 58857              "approach": {}
 58858            },
 58859            "quantitativeAnalysis": {
 58860              "graphics": {}
 58861            },
 58862            "considerations": {}
 58863          }
 58864        },
 58865        {
 58866          "type": "library",
 58867          "bom-ref": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a9696917d3b9f9fc",
 58868          "supplier": {},
 58869          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 58870          "name": "gzip",
 58871          "version": "1.10-0ubuntu4",
 58872          "licenses": [
 58873            {
 58874              "license": {
 58875                "name": "GPL"
 58876              }
 58877            }
 58878          ],
 58879          "cpe": "cpe:2.3:a:gzip:gzip:1.10-0ubuntu4:*:*:*:*:*:*:*",
 58880          "purl": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04",
 58881          "swid": {
 58882            "attachment": {}
 58883          },
 58884          "pedigree": {},
 58885          "evidence": {},
 58886          "signature": {
 58887            "signature": {
 58888              "publicKey": {}
 58889            }
 58890          },
 58891          "modelCard": {
 58892            "modelParameters": {
 58893              "approach": {}
 58894            },
 58895            "quantitativeAnalysis": {
 58896              "graphics": {}
 58897            },
 58898            "considerations": {}
 58899          }
 58900        },
 58901        {
 58902          "type": "library",
 58903          "bom-ref": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=263dae70cc8e6a4f",
 58904          "supplier": {},
 58905          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 58906          "name": "hostname",
 58907          "version": "3.23",
 58908          "licenses": [
 58909            {
 58910              "license": {
 58911                "id": "GPL-2.0-only"
 58912              }
 58913            }
 58914          ],
 58915          "cpe": "cpe:2.3:a:hostname:hostname:3.23:*:*:*:*:*:*:*",
 58916          "purl": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04",
 58917          "swid": {
 58918            "attachment": {}
 58919          },
 58920          "pedigree": {},
 58921          "evidence": {},
 58922          "signature": {
 58923            "signature": {
 58924              "publicKey": {}
 58925            }
 58926          },
 58927          "modelCard": {
 58928            "modelParameters": {
 58929              "approach": {}
 58930            },
 58931            "quantitativeAnalysis": {
 58932              "graphics": {}
 58933            },
 58934            "considerations": {}
 58935          }
 58936        },
 58937        {
 58938          "type": "library",
 58939          "bom-ref": "pkg:deb/ubuntu/ibverbs-providers@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04\u0026package-id=8e9d2de3c937ce3c",
 58940          "supplier": {},
 58941          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 58942          "name": "ibverbs-providers",
 58943          "version": "28.0-1ubuntu1",
 58944          "licenses": [
 58945            {
 58946              "license": {
 58947                "id": "BSD-2-Clause"
 58948              }
 58949            },
 58950            {
 58951              "license": {
 58952                "id": "BSD-3-Clause"
 58953              }
 58954            },
 58955            {
 58956              "license": {
 58957                "name": "BSD-MIT"
 58958              }
 58959            },
 58960            {
 58961              "license": {
 58962                "name": "CC0"
 58963              }
 58964            },
 58965            {
 58966              "license": {
 58967                "id": "CPL-1.0"
 58968              }
 58969            },
 58970            {
 58971              "license": {
 58972                "id": "GPL-2.0-only"
 58973              }
 58974            },
 58975            {
 58976              "license": {
 58977                "id": "GPL-2.0-or-later"
 58978              }
 58979            },
 58980            {
 58981              "license": {
 58982                "id": "MIT"
 58983              }
 58984            }
 58985          ],
 58986          "cpe": "cpe:2.3:a:ibverbs-providers:ibverbs-providers:28.0-1ubuntu1:*:*:*:*:*:*:*",
 58987          "purl": "pkg:deb/ubuntu/ibverbs-providers@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04",
 58988          "swid": {
 58989            "attachment": {}
 58990          },
 58991          "pedigree": {},
 58992          "evidence": {},
 58993          "signature": {
 58994            "signature": {
 58995              "publicKey": {}
 58996            }
 58997          },
 58998          "modelCard": {
 58999            "modelParameters": {
 59000              "approach": {}
 59001            },
 59002            "quantitativeAnalysis": {
 59003              "graphics": {}
 59004            },
 59005            "considerations": {}
 59006          }
 59007        },
 59008        {
 59009          "type": "library",
 59010          "bom-ref": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04\u0026package-id=b0e335d96f12154d",
 59011          "supplier": {},
 59012          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59013          "name": "init-system-helpers",
 59014          "version": "1.57",
 59015          "licenses": [
 59016            {
 59017              "license": {
 59018                "id": "BSD-3-Clause"
 59019              }
 59020            },
 59021            {
 59022              "license": {
 59023                "id": "GPL-2.0-only"
 59024              }
 59025            },
 59026            {
 59027              "license": {
 59028                "id": "GPL-2.0-or-later"
 59029              }
 59030            }
 59031          ],
 59032          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.57:*:*:*:*:*:*:*",
 59033          "purl": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04",
 59034          "swid": {
 59035            "attachment": {}
 59036          },
 59037          "pedigree": {},
 59038          "evidence": {},
 59039          "signature": {
 59040            "signature": {
 59041              "publicKey": {}
 59042            }
 59043          },
 59044          "modelCard": {
 59045            "modelParameters": {
 59046              "approach": {}
 59047            },
 59048            "quantitativeAnalysis": {
 59049              "graphics": {}
 59050            },
 59051            "considerations": {}
 59052          }
 59053        },
 59054        {
 59055          "type": "library",
 59056          "bom-ref": "pkg:deb/ubuntu/iperf@2.0.13+dfsg1-1build1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=52f5841ee19da566",
 59057          "supplier": {},
 59058          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59059          "name": "iperf",
 59060          "version": "2.0.13+dfsg1-1build1",
 59061          "licenses": [
 59062            {
 59063              "license": {
 59064                "id": "BSD-3-Clause"
 59065              }
 59066            },
 59067            {
 59068              "license": {
 59069                "name": "FSF-something"
 59070              }
 59071            },
 59072            {
 59073              "license": {
 59074                "id": "GPL-2.0-only"
 59075              }
 59076            },
 59077            {
 59078              "license": {
 59079                "id": "GPL-2.0-or-later"
 59080              }
 59081            },
 59082            {
 59083              "license": {
 59084                "name": "GPL-2-WithACException"
 59085              }
 59086            },
 59087            {
 59088              "license": {
 59089                "id": "GPL-3.0-only"
 59090              }
 59091            },
 59092            {
 59093              "license": {
 59094                "name": "GPL-3-WithACException"
 59095              }
 59096            },
 59097            {
 59098              "license": {
 59099                "id": "ISC"
 59100              }
 59101            },
 59102            {
 59103              "license": {
 59104                "id": "LGPL-2.0-only"
 59105              }
 59106            },
 59107            {
 59108              "license": {
 59109                "id": "LGPL-2.0-or-later"
 59110              }
 59111            },
 59112            {
 59113              "license": {
 59114                "id": "MIT"
 59115              }
 59116            }
 59117          ],
 59118          "cpe": "cpe:2.3:a:iperf:iperf:2.0.13\\+dfsg1-1build1:*:*:*:*:*:*:*",
 59119          "purl": "pkg:deb/ubuntu/iperf@2.0.13+dfsg1-1build1?arch=amd64\u0026distro=ubuntu-20.04",
 59120          "swid": {
 59121            "attachment": {}
 59122          },
 59123          "pedigree": {},
 59124          "evidence": {},
 59125          "signature": {
 59126            "signature": {
 59127              "publicKey": {}
 59128            }
 59129          },
 59130          "modelCard": {
 59131            "modelParameters": {
 59132              "approach": {}
 59133            },
 59134            "quantitativeAnalysis": {
 59135              "graphics": {}
 59136            },
 59137            "considerations": {}
 59138          }
 59139        },
 59140        {
 59141          "type": "library",
 59142          "bom-ref": "pkg:deb/ubuntu/iproute2@5.5.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f4afda4dc550367c",
 59143          "supplier": {},
 59144          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59145          "name": "iproute2",
 59146          "version": "5.5.0-1ubuntu1",
 59147          "licenses": [
 59148            {
 59149              "license": {
 59150                "id": "GPL-2.0-only"
 59151              }
 59152            }
 59153          ],
 59154          "cpe": "cpe:2.3:a:iproute2:iproute2:5.5.0-1ubuntu1:*:*:*:*:*:*:*",
 59155          "purl": "pkg:deb/ubuntu/iproute2@5.5.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 59156          "swid": {
 59157            "attachment": {}
 59158          },
 59159          "pedigree": {},
 59160          "evidence": {},
 59161          "signature": {
 59162            "signature": {
 59163              "publicKey": {}
 59164            }
 59165          },
 59166          "modelCard": {
 59167            "modelParameters": {
 59168              "approach": {}
 59169            },
 59170            "quantitativeAnalysis": {
 59171              "graphics": {}
 59172            },
 59173            "considerations": {}
 59174          }
 59175        },
 59176        {
 59177          "type": "library",
 59178          "bom-ref": "pkg:deb/ubuntu/iputils-ping@3:20190709-3?arch=amd64\u0026upstream=iputils\u0026distro=ubuntu-20.04\u0026package-id=83f284daebd0969f",
 59179          "supplier": {},
 59180          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59181          "name": "iputils-ping",
 59182          "version": "3:20190709-3",
 59183          "licenses": [
 59184            {
 59185              "license": {
 59186                "name": "GPL"
 59187              }
 59188            }
 59189          ],
 59190          "cpe": "cpe:2.3:a:iputils-ping:iputils-ping:3\\:20190709-3:*:*:*:*:*:*:*",
 59191          "purl": "pkg:deb/ubuntu/iputils-ping@3:20190709-3?arch=amd64\u0026upstream=iputils\u0026distro=ubuntu-20.04",
 59192          "swid": {
 59193            "attachment": {}
 59194          },
 59195          "pedigree": {},
 59196          "evidence": {},
 59197          "signature": {
 59198            "signature": {
 59199              "publicKey": {}
 59200            }
 59201          },
 59202          "modelCard": {
 59203            "modelParameters": {
 59204              "approach": {}
 59205            },
 59206            "quantitativeAnalysis": {
 59207              "graphics": {}
 59208            },
 59209            "considerations": {}
 59210          }
 59211        },
 59212        {
 59213          "type": "library",
 59214          "bom-ref": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a61b8b47cf58815b",
 59215          "supplier": {},
 59216          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59217          "name": "keyutils",
 59218          "version": "1.6-6ubuntu1",
 59219          "licenses": [
 59220            {
 59221              "license": {
 59222                "id": "GPL-2.0-only"
 59223              }
 59224            },
 59225            {
 59226              "license": {
 59227                "id": "GPL-2.0-or-later"
 59228              }
 59229            },
 59230            {
 59231              "license": {
 59232                "id": "LGPL-2.0-only"
 59233              }
 59234            },
 59235            {
 59236              "license": {
 59237                "id": "LGPL-2.0-or-later"
 59238              }
 59239            }
 59240          ],
 59241          "cpe": "cpe:2.3:a:keyutils:keyutils:1.6-6ubuntu1:*:*:*:*:*:*:*",
 59242          "purl": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 59243          "swid": {
 59244            "attachment": {}
 59245          },
 59246          "pedigree": {},
 59247          "evidence": {},
 59248          "signature": {
 59249            "signature": {
 59250              "publicKey": {}
 59251            }
 59252          },
 59253          "modelCard": {
 59254            "modelParameters": {
 59255              "approach": {}
 59256            },
 59257            "quantitativeAnalysis": {
 59258              "graphics": {}
 59259            },
 59260            "considerations": {}
 59261          }
 59262        },
 59263        {
 59264          "type": "library",
 59265          "bom-ref": "pkg:deb/ubuntu/kmod@27-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e1280bc47493e972",
 59266          "supplier": {},
 59267          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59268          "name": "kmod",
 59269          "version": "27-1ubuntu2",
 59270          "licenses": [
 59271            {
 59272              "license": {
 59273                "id": "GPL-2.0-only"
 59274              }
 59275            }
 59276          ],
 59277          "cpe": "cpe:2.3:a:kmod:kmod:27-1ubuntu2:*:*:*:*:*:*:*",
 59278          "purl": "pkg:deb/ubuntu/kmod@27-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
 59279          "swid": {
 59280            "attachment": {}
 59281          },
 59282          "pedigree": {},
 59283          "evidence": {},
 59284          "signature": {
 59285            "signature": {
 59286              "publicKey": {}
 59287            }
 59288          },
 59289          "modelCard": {
 59290            "modelParameters": {
 59291              "approach": {}
 59292            },
 59293            "quantitativeAnalysis": {
 59294              "graphics": {}
 59295            },
 59296            "considerations": {}
 59297          }
 59298        },
 59299        {
 59300          "type": "library",
 59301          "bom-ref": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=87ea48972fb4adab",
 59302          "supplier": {},
 59303          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59304          "name": "krb5-locales",
 59305          "version": "1.17-6ubuntu4.1",
 59306          "licenses": [
 59307            {
 59308              "license": {
 59309                "id": "GPL-2.0-only"
 59310              }
 59311            }
 59312          ],
 59313          "cpe": "cpe:2.3:a:krb5-locales:krb5-locales:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 59314          "purl": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 59315          "swid": {
 59316            "attachment": {}
 59317          },
 59318          "pedigree": {},
 59319          "evidence": {},
 59320          "signature": {
 59321            "signature": {
 59322              "publicKey": {}
 59323            }
 59324          },
 59325          "modelCard": {
 59326            "modelParameters": {
 59327              "approach": {}
 59328            },
 59329            "quantitativeAnalysis": {
 59330              "graphics": {}
 59331            },
 59332            "considerations": {}
 59333          }
 59334        },
 59335        {
 59336          "type": "library",
 59337          "bom-ref": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04\u0026package-id=5cec2c2009596050",
 59338          "supplier": {},
 59339          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59340          "name": "libacl1",
 59341          "version": "2.2.53-6",
 59342          "licenses": [
 59343            {
 59344              "license": {
 59345                "id": "GPL-2.0-only"
 59346              }
 59347            },
 59348            {
 59349              "license": {
 59350                "id": "GPL-2.0-or-later"
 59351              }
 59352            },
 59353            {
 59354              "license": {
 59355                "id": "LGPL-2.0-or-later"
 59356              }
 59357            },
 59358            {
 59359              "license": {
 59360                "id": "LGPL-2.1-only"
 59361              }
 59362            }
 59363          ],
 59364          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-6:*:*:*:*:*:*:*",
 59365          "purl": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04",
 59366          "swid": {
 59367            "attachment": {}
 59368          },
 59369          "pedigree": {},
 59370          "evidence": {},
 59371          "signature": {
 59372            "signature": {
 59373              "publicKey": {}
 59374            }
 59375          },
 59376          "modelCard": {
 59377            "modelParameters": {
 59378              "approach": {}
 59379            },
 59380            "quantitativeAnalysis": {
 59381              "graphics": {}
 59382            },
 59383            "considerations": {}
 59384          }
 59385        },
 59386        {
 59387          "type": "library",
 59388          "bom-ref": "pkg:deb/ubuntu/libaio1@0.3.112-5?arch=amd64\u0026upstream=libaio\u0026distro=ubuntu-20.04\u0026package-id=f850a0a77c824c95",
 59389          "supplier": {},
 59390          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59391          "name": "libaio1",
 59392          "version": "0.3.112-5",
 59393          "licenses": [
 59394            {
 59395              "license": {
 59396                "id": "LGPL-2.1-only"
 59397              }
 59398            },
 59399            {
 59400              "license": {
 59401                "id": "LGPL-2.1-or-later"
 59402              }
 59403            }
 59404          ],
 59405          "cpe": "cpe:2.3:a:libaio1:libaio1:0.3.112-5:*:*:*:*:*:*:*",
 59406          "purl": "pkg:deb/ubuntu/libaio1@0.3.112-5?arch=amd64\u0026upstream=libaio\u0026distro=ubuntu-20.04",
 59407          "swid": {
 59408            "attachment": {}
 59409          },
 59410          "pedigree": {},
 59411          "evidence": {},
 59412          "signature": {
 59413            "signature": {
 59414              "publicKey": {}
 59415            }
 59416          },
 59417          "modelCard": {
 59418            "modelParameters": {
 59419              "approach": {}
 59420            },
 59421            "quantitativeAnalysis": {
 59422              "graphics": {}
 59423            },
 59424            "considerations": {}
 59425          }
 59426        },
 59427        {
 59428          "type": "library",
 59429          "bom-ref": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04\u0026package-id=864e143f4c606a6c",
 59430          "supplier": {},
 59431          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59432          "name": "libapt-pkg6.0",
 59433          "version": "2.0.6",
 59434          "licenses": [
 59435            {
 59436              "license": {
 59437                "id": "GPL-2.0-only"
 59438              }
 59439            },
 59440            {
 59441              "license": {
 59442                "name": "GPLv2+"
 59443              }
 59444            }
 59445          ],
 59446          "cpe": "cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.0.6:*:*:*:*:*:*:*",
 59447          "purl": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04",
 59448          "swid": {
 59449            "attachment": {}
 59450          },
 59451          "pedigree": {},
 59452          "evidence": {},
 59453          "signature": {
 59454            "signature": {
 59455              "publicKey": {}
 59456            }
 59457          },
 59458          "modelCard": {
 59459            "modelParameters": {
 59460              "approach": {}
 59461            },
 59462            "quantitativeAnalysis": {
 59463              "graphics": {}
 59464            },
 59465            "considerations": {}
 59466          }
 59467        },
 59468        {
 59469          "type": "library",
 59470          "bom-ref": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=915f8cf154d1b7ce",
 59471          "supplier": {},
 59472          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59473          "name": "libasn1-8-heimdal",
 59474          "version": "7.7.0+dfsg-1ubuntu1",
 59475          "licenses": [
 59476            {
 59477              "license": {
 59478                "id": "BSD-3-Clause"
 59479              }
 59480            },
 59481            {
 59482              "license": {
 59483                "id": "GPL-2.0-only"
 59484              }
 59485            },
 59486            {
 59487              "license": {
 59488                "id": "GPL-2.0-or-later"
 59489              }
 59490            },
 59491            {
 59492              "license": {
 59493                "name": "custom"
 59494              }
 59495            }
 59496          ],
 59497          "cpe": "cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 59498          "purl": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 59499          "swid": {
 59500            "attachment": {}
 59501          },
 59502          "pedigree": {},
 59503          "evidence": {},
 59504          "signature": {
 59505            "signature": {
 59506              "publicKey": {}
 59507            }
 59508          },
 59509          "modelCard": {
 59510            "modelParameters": {
 59511              "approach": {}
 59512            },
 59513            "quantitativeAnalysis": {
 59514              "graphics": {}
 59515            },
 59516            "considerations": {}
 59517          }
 59518        },
 59519        {
 59520          "type": "library",
 59521          "bom-ref": "pkg:deb/ubuntu/libatm1@1:2.5.1-4?arch=amd64\u0026upstream=linux-atm\u0026distro=ubuntu-20.04\u0026package-id=38fbc3dda7412f50",
 59522          "supplier": {},
 59523          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59524          "name": "libatm1",
 59525          "version": "1:2.5.1-4",
 59526          "licenses": [
 59527            {
 59528              "license": {
 59529                "id": "GPL-2.0-only"
 59530              }
 59531            }
 59532          ],
 59533          "cpe": "cpe:2.3:a:libatm1:libatm1:1\\:2.5.1-4:*:*:*:*:*:*:*",
 59534          "purl": "pkg:deb/ubuntu/libatm1@1:2.5.1-4?arch=amd64\u0026upstream=linux-atm\u0026distro=ubuntu-20.04",
 59535          "swid": {
 59536            "attachment": {}
 59537          },
 59538          "pedigree": {},
 59539          "evidence": {},
 59540          "signature": {
 59541            "signature": {
 59542              "publicKey": {}
 59543            }
 59544          },
 59545          "modelCard": {
 59546            "modelParameters": {
 59547              "approach": {}
 59548            },
 59549            "quantitativeAnalysis": {
 59550              "graphics": {}
 59551            },
 59552            "considerations": {}
 59553          }
 59554        },
 59555        {
 59556          "type": "library",
 59557          "bom-ref": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04\u0026package-id=edf8dd62bd537bd5",
 59558          "supplier": {},
 59559          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59560          "name": "libattr1",
 59561          "version": "1:2.4.48-5",
 59562          "licenses": [
 59563            {
 59564              "license": {
 59565                "id": "GPL-2.0-only"
 59566              }
 59567            },
 59568            {
 59569              "license": {
 59570                "id": "GPL-2.0-or-later"
 59571              }
 59572            },
 59573            {
 59574              "license": {
 59575                "id": "LGPL-2.0-or-later"
 59576              }
 59577            },
 59578            {
 59579              "license": {
 59580                "id": "LGPL-2.1-only"
 59581              }
 59582            }
 59583          ],
 59584          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-5:*:*:*:*:*:*:*",
 59585          "purl": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04",
 59586          "swid": {
 59587            "attachment": {}
 59588          },
 59589          "pedigree": {},
 59590          "evidence": {},
 59591          "signature": {
 59592            "signature": {
 59593              "publicKey": {}
 59594            }
 59595          },
 59596          "modelCard": {
 59597            "modelParameters": {
 59598              "approach": {}
 59599            },
 59600            "quantitativeAnalysis": {
 59601              "graphics": {}
 59602            },
 59603            "considerations": {}
 59604          }
 59605        },
 59606        {
 59607          "type": "library",
 59608          "bom-ref": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=4a463ab850d7c68c",
 59609          "supplier": {},
 59610          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59611          "name": "libaudit-common",
 59612          "version": "1:2.8.5-2ubuntu6",
 59613          "licenses": [
 59614            {
 59615              "license": {
 59616                "id": "GPL-1.0-only"
 59617              }
 59618            },
 59619            {
 59620              "license": {
 59621                "id": "GPL-2.0-only"
 59622              }
 59623            },
 59624            {
 59625              "license": {
 59626                "id": "LGPL-2.1-only"
 59627              }
 59628            }
 59629          ],
 59630          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
 59631          "purl": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04",
 59632          "swid": {
 59633            "attachment": {}
 59634          },
 59635          "pedigree": {},
 59636          "evidence": {},
 59637          "signature": {
 59638            "signature": {
 59639              "publicKey": {}
 59640            }
 59641          },
 59642          "modelCard": {
 59643            "modelParameters": {
 59644              "approach": {}
 59645            },
 59646            "quantitativeAnalysis": {
 59647              "graphics": {}
 59648            },
 59649            "considerations": {}
 59650          }
 59651        },
 59652        {
 59653          "type": "library",
 59654          "bom-ref": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=be9537deb8db616e",
 59655          "supplier": {},
 59656          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59657          "name": "libaudit1",
 59658          "version": "1:2.8.5-2ubuntu6",
 59659          "licenses": [
 59660            {
 59661              "license": {
 59662                "id": "GPL-1.0-only"
 59663              }
 59664            },
 59665            {
 59666              "license": {
 59667                "id": "GPL-2.0-only"
 59668              }
 59669            },
 59670            {
 59671              "license": {
 59672                "id": "LGPL-2.1-only"
 59673              }
 59674            }
 59675          ],
 59676          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
 59677          "purl": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04",
 59678          "swid": {
 59679            "attachment": {}
 59680          },
 59681          "pedigree": {},
 59682          "evidence": {},
 59683          "signature": {
 59684            "signature": {
 59685              "publicKey": {}
 59686            }
 59687          },
 59688          "modelCard": {
 59689            "modelParameters": {
 59690              "approach": {}
 59691            },
 59692            "quantitativeAnalysis": {
 59693              "graphics": {}
 59694            },
 59695            "considerations": {}
 59696          }
 59697        },
 59698        {
 59699          "type": "library",
 59700          "bom-ref": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=e1d6f2e998332d7d",
 59701          "supplier": {},
 59702          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59703          "name": "libblkid1",
 59704          "version": "2.34-0.1ubuntu9.1",
 59705          "licenses": [
 59706            {
 59707              "license": {
 59708                "id": "BSD-2-Clause"
 59709              }
 59710            },
 59711            {
 59712              "license": {
 59713                "id": "BSD-3-Clause"
 59714              }
 59715            },
 59716            {
 59717              "license": {
 59718                "id": "BSD-4-Clause"
 59719              }
 59720            },
 59721            {
 59722              "license": {
 59723                "id": "GPL-2.0-only"
 59724              }
 59725            },
 59726            {
 59727              "license": {
 59728                "id": "GPL-2.0-or-later"
 59729              }
 59730            },
 59731            {
 59732              "license": {
 59733                "id": "GPL-3.0-only"
 59734              }
 59735            },
 59736            {
 59737              "license": {
 59738                "id": "GPL-3.0-or-later"
 59739              }
 59740            },
 59741            {
 59742              "license": {
 59743                "name": "LGPL"
 59744              }
 59745            },
 59746            {
 59747              "license": {
 59748                "id": "LGPL-2.0-only"
 59749              }
 59750            },
 59751            {
 59752              "license": {
 59753                "id": "LGPL-2.0-or-later"
 59754              }
 59755            },
 59756            {
 59757              "license": {
 59758                "id": "LGPL-2.1-only"
 59759              }
 59760            },
 59761            {
 59762              "license": {
 59763                "id": "LGPL-2.1-or-later"
 59764              }
 59765            },
 59766            {
 59767              "license": {
 59768                "id": "LGPL-3.0-only"
 59769              }
 59770            },
 59771            {
 59772              "license": {
 59773                "id": "LGPL-3.0-or-later"
 59774              }
 59775            },
 59776            {
 59777              "license": {
 59778                "id": "MIT"
 59779              }
 59780            },
 59781            {
 59782              "license": {
 59783                "name": "public-domain"
 59784              }
 59785            }
 59786          ],
 59787          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 59788          "purl": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 59789          "swid": {
 59790            "attachment": {}
 59791          },
 59792          "pedigree": {},
 59793          "evidence": {},
 59794          "signature": {
 59795            "signature": {
 59796              "publicKey": {}
 59797            }
 59798          },
 59799          "modelCard": {
 59800            "modelParameters": {
 59801              "approach": {}
 59802            },
 59803            "quantitativeAnalysis": {
 59804              "graphics": {}
 59805            },
 59806            "considerations": {}
 59807          }
 59808        },
 59809        {
 59810          "type": "library",
 59811          "bom-ref": "pkg:deb/ubuntu/libboost-iostreams1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04\u0026package-id=c10288fd207d7ab9",
 59812          "supplier": {},
 59813          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59814          "name": "libboost-iostreams1.71.0",
 59815          "version": "1.71.0-6ubuntu6",
 59816          "licenses": [
 59817            {
 59818              "license": {
 59819                "id": "Apache-2.0"
 59820              }
 59821            },
 59822            {
 59823              "license": {
 59824                "name": "BSD2"
 59825              }
 59826            },
 59827            {
 59828              "license": {
 59829                "name": "BSD3_DEShaw"
 59830              }
 59831            },
 59832            {
 59833              "license": {
 59834                "name": "BSD3_Google"
 59835              }
 59836            },
 59837            {
 59838              "license": {
 59839                "id": "BSL-1.0"
 59840              }
 59841            },
 59842            {
 59843              "license": {
 59844                "name": "Caramel"
 59845              }
 59846            },
 59847            {
 59848              "license": {
 59849                "name": "CrystalClear"
 59850              }
 59851            },
 59852            {
 59853              "license": {
 59854                "name": "HP"
 59855              }
 59856            },
 59857            {
 59858              "license": {
 59859                "id": "Jam"
 59860              }
 59861            },
 59862            {
 59863              "license": {
 59864                "name": "Kempf"
 59865              }
 59866            },
 59867            {
 59868              "license": {
 59869                "id": "MIT"
 59870              }
 59871            },
 59872            {
 59873              "license": {
 59874                "name": "NIST"
 59875              }
 59876            },
 59877            {
 59878              "license": {
 59879                "name": "OldBoost1"
 59880              }
 59881            },
 59882            {
 59883              "license": {
 59884                "name": "OldBoost2"
 59885              }
 59886            },
 59887            {
 59888              "license": {
 59889                "name": "OldBoost3"
 59890              }
 59891            },
 59892            {
 59893              "license": {
 59894                "name": "Python"
 59895              }
 59896            },
 59897            {
 59898              "license": {
 59899                "name": "SGI"
 59900              }
 59901            },
 59902            {
 59903              "license": {
 59904                "name": "Spencer"
 59905              }
 59906            },
 59907            {
 59908              "license": {
 59909                "id": "Zlib"
 59910              }
 59911            }
 59912          ],
 59913          "cpe": "cpe:2.3:a:libboost-iostreams1.71.0:libboost-iostreams1.71.0:1.71.0-6ubuntu6:*:*:*:*:*:*:*",
 59914          "purl": "pkg:deb/ubuntu/libboost-iostreams1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04",
 59915          "swid": {
 59916            "attachment": {}
 59917          },
 59918          "pedigree": {},
 59919          "evidence": {},
 59920          "signature": {
 59921            "signature": {
 59922              "publicKey": {}
 59923            }
 59924          },
 59925          "modelCard": {
 59926            "modelParameters": {
 59927              "approach": {}
 59928            },
 59929            "quantitativeAnalysis": {
 59930              "graphics": {}
 59931            },
 59932            "considerations": {}
 59933          }
 59934        },
 59935        {
 59936          "type": "library",
 59937          "bom-ref": "pkg:deb/ubuntu/libboost-thread1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04\u0026package-id=7bdbd4008b339d07",
 59938          "supplier": {},
 59939          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 59940          "name": "libboost-thread1.71.0",
 59941          "version": "1.71.0-6ubuntu6",
 59942          "licenses": [
 59943            {
 59944              "license": {
 59945                "id": "Apache-2.0"
 59946              }
 59947            },
 59948            {
 59949              "license": {
 59950                "name": "BSD2"
 59951              }
 59952            },
 59953            {
 59954              "license": {
 59955                "name": "BSD3_DEShaw"
 59956              }
 59957            },
 59958            {
 59959              "license": {
 59960                "name": "BSD3_Google"
 59961              }
 59962            },
 59963            {
 59964              "license": {
 59965                "id": "BSL-1.0"
 59966              }
 59967            },
 59968            {
 59969              "license": {
 59970                "name": "Caramel"
 59971              }
 59972            },
 59973            {
 59974              "license": {
 59975                "name": "CrystalClear"
 59976              }
 59977            },
 59978            {
 59979              "license": {
 59980                "name": "HP"
 59981              }
 59982            },
 59983            {
 59984              "license": {
 59985                "id": "Jam"
 59986              }
 59987            },
 59988            {
 59989              "license": {
 59990                "name": "Kempf"
 59991              }
 59992            },
 59993            {
 59994              "license": {
 59995                "id": "MIT"
 59996              }
 59997            },
 59998            {
 59999              "license": {
 60000                "name": "NIST"
 60001              }
 60002            },
 60003            {
 60004              "license": {
 60005                "name": "OldBoost1"
 60006              }
 60007            },
 60008            {
 60009              "license": {
 60010                "name": "OldBoost2"
 60011              }
 60012            },
 60013            {
 60014              "license": {
 60015                "name": "OldBoost3"
 60016              }
 60017            },
 60018            {
 60019              "license": {
 60020                "name": "Python"
 60021              }
 60022            },
 60023            {
 60024              "license": {
 60025                "name": "SGI"
 60026              }
 60027            },
 60028            {
 60029              "license": {
 60030                "name": "Spencer"
 60031              }
 60032            },
 60033            {
 60034              "license": {
 60035                "id": "Zlib"
 60036              }
 60037            }
 60038          ],
 60039          "cpe": "cpe:2.3:a:libboost-thread1.71.0:libboost-thread1.71.0:1.71.0-6ubuntu6:*:*:*:*:*:*:*",
 60040          "purl": "pkg:deb/ubuntu/libboost-thread1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04",
 60041          "swid": {
 60042            "attachment": {}
 60043          },
 60044          "pedigree": {},
 60045          "evidence": {},
 60046          "signature": {
 60047            "signature": {
 60048              "publicKey": {}
 60049            }
 60050          },
 60051          "modelCard": {
 60052            "modelParameters": {
 60053              "approach": {}
 60054            },
 60055            "quantitativeAnalysis": {
 60056              "graphics": {}
 60057            },
 60058            "considerations": {}
 60059          }
 60060        },
 60061        {
 60062          "type": "library",
 60063          "bom-ref": "pkg:deb/ubuntu/libbrotli1@1.0.7-6ubuntu0.1?arch=amd64\u0026upstream=brotli\u0026distro=ubuntu-20.04\u0026package-id=3cfc22417c2e74ac",
 60064          "supplier": {},
 60065          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60066          "name": "libbrotli1",
 60067          "version": "1.0.7-6ubuntu0.1",
 60068          "licenses": [
 60069            {
 60070              "license": {
 60071                "id": "MIT"
 60072              }
 60073            }
 60074          ],
 60075          "cpe": "cpe:2.3:a:libbrotli1:libbrotli1:1.0.7-6ubuntu0.1:*:*:*:*:*:*:*",
 60076          "purl": "pkg:deb/ubuntu/libbrotli1@1.0.7-6ubuntu0.1?arch=amd64\u0026upstream=brotli\u0026distro=ubuntu-20.04",
 60077          "swid": {
 60078            "attachment": {}
 60079          },
 60080          "pedigree": {},
 60081          "evidence": {},
 60082          "signature": {
 60083            "signature": {
 60084              "publicKey": {}
 60085            }
 60086          },
 60087          "modelCard": {
 60088            "modelParameters": {
 60089              "approach": {}
 60090            },
 60091            "quantitativeAnalysis": {
 60092              "graphics": {}
 60093            },
 60094            "considerations": {}
 60095          }
 60096        },
 60097        {
 60098          "type": "library",
 60099          "bom-ref": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04\u0026package-id=88ee716d66a17869",
 60100          "supplier": {},
 60101          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60102          "name": "libbsd0",
 60103          "version": "0.10.0-1",
 60104          "licenses": [
 60105            {
 60106              "license": {
 60107                "id": "BSD-2-Clause"
 60108              }
 60109            },
 60110            {
 60111              "license": {
 60112                "id": "BSD-2-Clause"
 60113              }
 60114            },
 60115            {
 60116              "license": {
 60117                "name": "BSD-2-clause-author"
 60118              }
 60119            },
 60120            {
 60121              "license": {
 60122                "name": "BSD-2-clause-verbatim"
 60123              }
 60124            },
 60125            {
 60126              "license": {
 60127                "id": "BSD-3-Clause"
 60128              }
 60129            },
 60130            {
 60131              "license": {
 60132                "name": "BSD-3-clause-John-Birrell"
 60133              }
 60134            },
 60135            {
 60136              "license": {
 60137                "name": "BSD-3-clause-Regents"
 60138              }
 60139            },
 60140            {
 60141              "license": {
 60142                "name": "BSD-3-clause-author"
 60143              }
 60144            },
 60145            {
 60146              "license": {
 60147                "name": "BSD-4-clause-Christopher-G-Demetriou"
 60148              }
 60149            },
 60150            {
 60151              "license": {
 60152                "name": "BSD-4-clause-Niels-Provos"
 60153              }
 60154            },
 60155            {
 60156              "license": {
 60157                "name": "BSD-5-clause-Peter-Wemm"
 60158              }
 60159            },
 60160            {
 60161              "license": {
 60162                "id": "Beerware"
 60163              }
 60164            },
 60165            {
 60166              "license": {
 60167                "name": "Expat"
 60168              }
 60169            },
 60170            {
 60171              "license": {
 60172                "id": "ISC"
 60173              }
 60174            },
 60175            {
 60176              "license": {
 60177                "name": "ISC-Original"
 60178              }
 60179            },
 60180            {
 60181              "license": {
 60182                "name": "public-domain"
 60183              }
 60184            },
 60185            {
 60186              "license": {
 60187                "name": "public-domain-Colin-Plumb"
 60188              }
 60189            }
 60190          ],
 60191          "cpe": "cpe:2.3:a:libbsd0:libbsd0:0.10.0-1:*:*:*:*:*:*:*",
 60192          "purl": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04",
 60193          "swid": {
 60194            "attachment": {}
 60195          },
 60196          "pedigree": {},
 60197          "evidence": {},
 60198          "signature": {
 60199            "signature": {
 60200              "publicKey": {}
 60201            }
 60202          },
 60203          "modelCard": {
 60204            "modelParameters": {
 60205              "approach": {}
 60206            },
 60207            "quantitativeAnalysis": {
 60208              "graphics": {}
 60209            },
 60210            "considerations": {}
 60211          }
 60212        },
 60213        {
 60214          "type": "library",
 60215          "bom-ref": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04\u0026package-id=fd8b0edf257b69b7",
 60216          "supplier": {},
 60217          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60218          "name": "libbz2-1.0",
 60219          "version": "1.0.8-2",
 60220          "licenses": [
 60221            {
 60222              "license": {
 60223                "name": "BSD-variant"
 60224              }
 60225            },
 60226            {
 60227              "license": {
 60228                "id": "GPL-2.0-only"
 60229              }
 60230            }
 60231          ],
 60232          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-2:*:*:*:*:*:*:*",
 60233          "purl": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04",
 60234          "swid": {
 60235            "attachment": {}
 60236          },
 60237          "pedigree": {},
 60238          "evidence": {},
 60239          "signature": {
 60240            "signature": {
 60241              "publicKey": {}
 60242            }
 60243          },
 60244          "modelCard": {
 60245            "modelParameters": {
 60246              "approach": {}
 60247            },
 60248            "quantitativeAnalysis": {
 60249              "graphics": {}
 60250            },
 60251            "considerations": {}
 60252          }
 60253        },
 60254        {
 60255          "type": "library",
 60256          "bom-ref": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=256facf7cbb95a65",
 60257          "supplier": {},
 60258          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60259          "name": "libc-bin",
 60260          "version": "2.31-0ubuntu9.2",
 60261          "licenses": [
 60262            {
 60263              "license": {
 60264                "id": "GPL-2.0-only"
 60265              }
 60266            },
 60267            {
 60268              "license": {
 60269                "id": "LGPL-2.1-only"
 60270              }
 60271            }
 60272          ],
 60273          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
 60274          "purl": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
 60275          "swid": {
 60276            "attachment": {}
 60277          },
 60278          "pedigree": {},
 60279          "evidence": {},
 60280          "signature": {
 60281            "signature": {
 60282              "publicKey": {}
 60283            }
 60284          },
 60285          "modelCard": {
 60286            "modelParameters": {
 60287              "approach": {}
 60288            },
 60289            "quantitativeAnalysis": {
 60290              "graphics": {}
 60291            },
 60292            "considerations": {}
 60293          }
 60294        },
 60295        {
 60296          "type": "library",
 60297          "bom-ref": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=2a96b94fa4db214",
 60298          "supplier": {},
 60299          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60300          "name": "libc6",
 60301          "version": "2.31-0ubuntu9.2",
 60302          "licenses": [
 60303            {
 60304              "license": {
 60305                "id": "GPL-2.0-only"
 60306              }
 60307            },
 60308            {
 60309              "license": {
 60310                "id": "LGPL-2.1-only"
 60311              }
 60312            }
 60313          ],
 60314          "cpe": "cpe:2.3:a:libc6:libc6:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
 60315          "purl": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
 60316          "swid": {
 60317            "attachment": {}
 60318          },
 60319          "pedigree": {},
 60320          "evidence": {},
 60321          "signature": {
 60322            "signature": {
 60323              "publicKey": {}
 60324            }
 60325          },
 60326          "modelCard": {
 60327            "modelParameters": {
 60328              "approach": {}
 60329            },
 60330            "quantitativeAnalysis": {
 60331              "graphics": {}
 60332            },
 60333            "considerations": {}
 60334          }
 60335        },
 60336        {
 60337          "type": "library",
 60338          "bom-ref": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04\u0026package-id=57ceb68462a99cb4",
 60339          "supplier": {},
 60340          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60341          "name": "libcap-ng0",
 60342          "version": "0.7.9-2.1build1",
 60343          "licenses": [
 60344            {
 60345              "license": {
 60346                "id": "GPL-2.0-only"
 60347              }
 60348            },
 60349            {
 60350              "license": {
 60351                "id": "GPL-3.0-only"
 60352              }
 60353            },
 60354            {
 60355              "license": {
 60356                "id": "LGPL-2.1-only"
 60357              }
 60358            }
 60359          ],
 60360          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2.1build1:*:*:*:*:*:*:*",
 60361          "purl": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04",
 60362          "swid": {
 60363            "attachment": {}
 60364          },
 60365          "pedigree": {},
 60366          "evidence": {},
 60367          "signature": {
 60368            "signature": {
 60369              "publicKey": {}
 60370            }
 60371          },
 60372          "modelCard": {
 60373            "modelParameters": {
 60374              "approach": {}
 60375            },
 60376            "quantitativeAnalysis": {
 60377              "graphics": {}
 60378            },
 60379            "considerations": {}
 60380          }
 60381        },
 60382        {
 60383          "type": "library",
 60384          "bom-ref": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=682f3e304c127762",
 60385          "supplier": {},
 60386          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60387          "name": "libcap2",
 60388          "version": "1:2.32-1",
 60389          "licenses": [
 60390            {
 60391              "license": {
 60392                "id": "BSD-3-Clause"
 60393              }
 60394            },
 60395            {
 60396              "license": {
 60397                "id": "GPL-2.0-only"
 60398              }
 60399            },
 60400            {
 60401              "license": {
 60402                "id": "GPL-2.0-or-later"
 60403              }
 60404            }
 60405          ],
 60406          "cpe": "cpe:2.3:a:libcap2:libcap2:1\\:2.32-1:*:*:*:*:*:*:*",
 60407          "purl": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04",
 60408          "swid": {
 60409            "attachment": {}
 60410          },
 60411          "pedigree": {},
 60412          "evidence": {},
 60413          "signature": {
 60414            "signature": {
 60415              "publicKey": {}
 60416            }
 60417          },
 60418          "modelCard": {
 60419            "modelParameters": {
 60420              "approach": {}
 60421            },
 60422            "quantitativeAnalysis": {
 60423              "graphics": {}
 60424            },
 60425            "considerations": {}
 60426          }
 60427        },
 60428        {
 60429          "type": "library",
 60430          "bom-ref": "pkg:deb/ubuntu/libcap2-bin@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04\u0026package-id=8f0ae2256856772c",
 60431          "supplier": {},
 60432          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60433          "name": "libcap2-bin",
 60434          "version": "1:2.32-1",
 60435          "licenses": [
 60436            {
 60437              "license": {
 60438                "id": "BSD-3-Clause"
 60439              }
 60440            },
 60441            {
 60442              "license": {
 60443                "id": "GPL-2.0-only"
 60444              }
 60445            },
 60446            {
 60447              "license": {
 60448                "id": "GPL-2.0-or-later"
 60449              }
 60450            }
 60451          ],
 60452          "cpe": "cpe:2.3:a:libcap2-bin:libcap2-bin:1\\:2.32-1:*:*:*:*:*:*:*",
 60453          "purl": "pkg:deb/ubuntu/libcap2-bin@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04",
 60454          "swid": {
 60455            "attachment": {}
 60456          },
 60457          "pedigree": {},
 60458          "evidence": {},
 60459          "signature": {
 60460            "signature": {
 60461              "publicKey": {}
 60462            }
 60463          },
 60464          "modelCard": {
 60465            "modelParameters": {
 60466              "approach": {}
 60467            },
 60468            "quantitativeAnalysis": {
 60469              "graphics": {}
 60470            },
 60471            "considerations": {}
 60472          }
 60473        },
 60474        {
 60475          "type": "library",
 60476          "bom-ref": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=fbaeb4c3d5d0f976",
 60477          "supplier": {},
 60478          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60479          "name": "libcom-err2",
 60480          "version": "1.45.5-2ubuntu1",
 60481          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 60482          "purl": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 60483          "swid": {
 60484            "attachment": {}
 60485          },
 60486          "pedigree": {},
 60487          "evidence": {},
 60488          "signature": {
 60489            "signature": {
 60490              "publicKey": {}
 60491            }
 60492          },
 60493          "modelCard": {
 60494            "modelParameters": {
 60495              "approach": {}
 60496            },
 60497            "quantitativeAnalysis": {
 60498              "graphics": {}
 60499            },
 60500            "considerations": {}
 60501          }
 60502        },
 60503        {
 60504          "type": "library",
 60505          "bom-ref": "pkg:deb/ubuntu/libconfig-general-perl@2.63-1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=da9c7895b5630089",
 60506          "supplier": {},
 60507          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60508          "name": "libconfig-general-perl",
 60509          "version": "2.63-1",
 60510          "licenses": [
 60511            {
 60512              "license": {
 60513                "name": "Artistic"
 60514              }
 60515            },
 60516            {
 60517              "license": {
 60518                "id": "GPL-1.0-only"
 60519              }
 60520            },
 60521            {
 60522              "license": {
 60523                "id": "GPL-1.0-or-later"
 60524              }
 60525            }
 60526          ],
 60527          "cpe": "cpe:2.3:a:libconfig-general-perl:libconfig-general-perl:2.63-1:*:*:*:*:*:*:*",
 60528          "purl": "pkg:deb/ubuntu/libconfig-general-perl@2.63-1?arch=all\u0026distro=ubuntu-20.04",
 60529          "swid": {
 60530            "attachment": {}
 60531          },
 60532          "pedigree": {},
 60533          "evidence": {},
 60534          "signature": {
 60535            "signature": {
 60536              "publicKey": {}
 60537            }
 60538          },
 60539          "modelCard": {
 60540            "modelParameters": {
 60541              "approach": {}
 60542            },
 60543            "quantitativeAnalysis": {
 60544              "graphics": {}
 60545            },
 60546            "considerations": {}
 60547          }
 60548        },
 60549        {
 60550          "type": "library",
 60551          "bom-ref": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04\u0026package-id=8a4302e2e7027353",
 60552          "supplier": {},
 60553          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60554          "name": "libcrypt1",
 60555          "version": "1:4.4.10-10ubuntu4",
 60556          "cpe": "cpe:2.3:a:libcrypt1:libcrypt1:1\\:4.4.10-10ubuntu4:*:*:*:*:*:*:*",
 60557          "purl": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04",
 60558          "swid": {
 60559            "attachment": {}
 60560          },
 60561          "pedigree": {},
 60562          "evidence": {},
 60563          "signature": {
 60564            "signature": {
 60565              "publicKey": {}
 60566            }
 60567          },
 60568          "modelCard": {
 60569            "modelParameters": {
 60570              "approach": {}
 60571            },
 60572            "quantitativeAnalysis": {
 60573              "graphics": {}
 60574            },
 60575            "considerations": {}
 60576          }
 60577        },
 60578        {
 60579          "type": "library",
 60580          "bom-ref": "pkg:deb/ubuntu/libcurl3-gnutls@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04\u0026package-id=823f387cfa54f312",
 60581          "supplier": {},
 60582          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60583          "name": "libcurl3-gnutls",
 60584          "version": "7.68.0-1ubuntu2.6",
 60585          "licenses": [
 60586            {
 60587              "license": {
 60588                "id": "BSD-3-Clause"
 60589              }
 60590            },
 60591            {
 60592              "license": {
 60593                "id": "BSD-4-Clause"
 60594              }
 60595            },
 60596            {
 60597              "license": {
 60598                "id": "ISC"
 60599              }
 60600            },
 60601            {
 60602              "license": {
 60603                "id": "curl"
 60604              }
 60605            },
 60606            {
 60607              "license": {
 60608                "name": "other"
 60609              }
 60610            },
 60611            {
 60612              "license": {
 60613                "name": "public-domain"
 60614              }
 60615            }
 60616          ],
 60617          "cpe": "cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.68.0-1ubuntu2.6:*:*:*:*:*:*:*",
 60618          "purl": "pkg:deb/ubuntu/libcurl3-gnutls@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04",
 60619          "swid": {
 60620            "attachment": {}
 60621          },
 60622          "pedigree": {},
 60623          "evidence": {},
 60624          "signature": {
 60625            "signature": {
 60626              "publicKey": {}
 60627            }
 60628          },
 60629          "modelCard": {
 60630            "modelParameters": {
 60631              "approach": {}
 60632            },
 60633            "quantitativeAnalysis": {
 60634              "graphics": {}
 60635            },
 60636            "considerations": {}
 60637          }
 60638        },
 60639        {
 60640          "type": "library",
 60641          "bom-ref": "pkg:deb/ubuntu/libcurl4@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04\u0026package-id=c9dd9bae4f158cd3",
 60642          "supplier": {},
 60643          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60644          "name": "libcurl4",
 60645          "version": "7.68.0-1ubuntu2.6",
 60646          "licenses": [
 60647            {
 60648              "license": {
 60649                "id": "BSD-3-Clause"
 60650              }
 60651            },
 60652            {
 60653              "license": {
 60654                "id": "BSD-4-Clause"
 60655              }
 60656            },
 60657            {
 60658              "license": {
 60659                "id": "ISC"
 60660              }
 60661            },
 60662            {
 60663              "license": {
 60664                "id": "curl"
 60665              }
 60666            },
 60667            {
 60668              "license": {
 60669                "name": "other"
 60670              }
 60671            },
 60672            {
 60673              "license": {
 60674                "name": "public-domain"
 60675              }
 60676            }
 60677          ],
 60678          "cpe": "cpe:2.3:a:libcurl4:libcurl4:7.68.0-1ubuntu2.6:*:*:*:*:*:*:*",
 60679          "purl": "pkg:deb/ubuntu/libcurl4@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04",
 60680          "swid": {
 60681            "attachment": {}
 60682          },
 60683          "pedigree": {},
 60684          "evidence": {},
 60685          "signature": {
 60686            "signature": {
 60687              "publicKey": {}
 60688            }
 60689          },
 60690          "modelCard": {
 60691            "modelParameters": {
 60692              "approach": {}
 60693            },
 60694            "quantitativeAnalysis": {
 60695              "graphics": {}
 60696            },
 60697            "considerations": {}
 60698          }
 60699        },
 60700        {
 60701          "type": "library",
 60702          "bom-ref": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04\u0026package-id=bc84b4da0031640d",
 60703          "supplier": {},
 60704          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60705          "name": "libdb5.3",
 60706          "version": "5.3.28+dfsg1-0.6ubuntu2",
 60707          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.6ubuntu2:*:*:*:*:*:*:*",
 60708          "purl": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04",
 60709          "swid": {
 60710            "attachment": {}
 60711          },
 60712          "pedigree": {},
 60713          "evidence": {},
 60714          "signature": {
 60715            "signature": {
 60716              "publicKey": {}
 60717            }
 60718          },
 60719          "modelCard": {
 60720            "modelParameters": {
 60721              "approach": {}
 60722            },
 60723            "quantitativeAnalysis": {
 60724              "graphics": {}
 60725            },
 60726            "considerations": {}
 60727          }
 60728        },
 60729        {
 60730          "type": "library",
 60731          "bom-ref": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04\u0026package-id=78bbe40d9c2ef9b5",
 60732          "supplier": {},
 60733          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60734          "name": "libdebconfclient0",
 60735          "version": "0.251ubuntu1",
 60736          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.251ubuntu1:*:*:*:*:*:*:*",
 60737          "purl": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04",
 60738          "swid": {
 60739            "attachment": {}
 60740          },
 60741          "pedigree": {},
 60742          "evidence": {},
 60743          "signature": {
 60744            "signature": {
 60745              "publicKey": {}
 60746            }
 60747          },
 60748          "modelCard": {
 60749            "modelParameters": {
 60750              "approach": {}
 60751            },
 60752            "quantitativeAnalysis": {
 60753              "graphics": {}
 60754            },
 60755            "considerations": {}
 60756          }
 60757        },
 60758        {
 60759          "type": "library",
 60760          "bom-ref": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=30b70188951a65f0",
 60761          "supplier": {},
 60762          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60763          "name": "libdevmapper1.02.1",
 60764          "version": "2:1.02.167-1ubuntu1",
 60765          "licenses": [
 60766            {
 60767              "license": {
 60768                "id": "BSD-2-Clause"
 60769              }
 60770            },
 60771            {
 60772              "license": {
 60773                "id": "GPL-2.0-only"
 60774              }
 60775            },
 60776            {
 60777              "license": {
 60778                "id": "GPL-2.0-only"
 60779              }
 60780            },
 60781            {
 60782              "license": {
 60783                "id": "GPL-2.0-or-later"
 60784              }
 60785            },
 60786            {
 60787              "license": {
 60788                "id": "LGPL-2.0-only"
 60789              }
 60790            },
 60791            {
 60792              "license": {
 60793                "id": "LGPL-2.1-only"
 60794              }
 60795            }
 60796          ],
 60797          "cpe": "cpe:2.3:a:libdevmapper1.02.1:libdevmapper1.02.1:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
 60798          "purl": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
 60799          "swid": {
 60800            "attachment": {}
 60801          },
 60802          "pedigree": {},
 60803          "evidence": {},
 60804          "signature": {
 60805            "signature": {
 60806              "publicKey": {}
 60807            }
 60808          },
 60809          "modelCard": {
 60810            "modelParameters": {
 60811              "approach": {}
 60812            },
 60813            "quantitativeAnalysis": {
 60814              "graphics": {}
 60815            },
 60816            "considerations": {}
 60817          }
 60818        },
 60819        {
 60820          "type": "library",
 60821          "bom-ref": "pkg:deb/ubuntu/libelf1@0.176-1.1build1?arch=amd64\u0026upstream=elfutils\u0026distro=ubuntu-20.04\u0026package-id=316daaa294f5e8d8",
 60822          "supplier": {},
 60823          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60824          "name": "libelf1",
 60825          "version": "0.176-1.1build1",
 60826          "licenses": [
 60827            {
 60828              "license": {
 60829                "id": "GPL-2.0-only"
 60830              }
 60831            },
 60832            {
 60833              "license": {
 60834                "id": "GPL-3.0-only"
 60835              }
 60836            },
 60837            {
 60838              "license": {
 60839                "name": "LGPL-"
 60840              }
 60841            }
 60842          ],
 60843          "cpe": "cpe:2.3:a:libelf1:libelf1:0.176-1.1build1:*:*:*:*:*:*:*",
 60844          "purl": "pkg:deb/ubuntu/libelf1@0.176-1.1build1?arch=amd64\u0026upstream=elfutils\u0026distro=ubuntu-20.04",
 60845          "swid": {
 60846            "attachment": {}
 60847          },
 60848          "pedigree": {},
 60849          "evidence": {},
 60850          "signature": {
 60851            "signature": {
 60852              "publicKey": {}
 60853            }
 60854          },
 60855          "modelCard": {
 60856            "modelParameters": {
 60857              "approach": {}
 60858            },
 60859            "quantitativeAnalysis": {
 60860              "graphics": {}
 60861            },
 60862            "considerations": {}
 60863          }
 60864        },
 60865        {
 60866          "type": "library",
 60867          "bom-ref": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04\u0026package-id=6b93a7dccfeb49e0",
 60868          "supplier": {},
 60869          "publisher": "Balint Reczey \u003crbalint@ubuntu.com\u003e",
 60870          "name": "libevent-2.1-7",
 60871          "version": "2.1.11-stable-1",
 60872          "licenses": [
 60873            {
 60874              "license": {
 60875                "id": "BSD-2-Clause"
 60876              }
 60877            },
 60878            {
 60879              "license": {
 60880                "name": "BSD-3-Clause~Kitware"
 60881              }
 60882            },
 60883            {
 60884              "license": {
 60885                "id": "BSD-3-Clause"
 60886              }
 60887            },
 60888            {
 60889              "license": {
 60890                "name": "BSL"
 60891              }
 60892            },
 60893            {
 60894              "license": {
 60895                "name": "Expat"
 60896              }
 60897            },
 60898            {
 60899              "license": {
 60900                "id": "FSFUL"
 60901              }
 60902            },
 60903            {
 60904              "license": {
 60905                "id": "FSFULLR"
 60906              }
 60907            },
 60908            {
 60909              "license": {
 60910                "name": "FSFULLR-No-Warranty"
 60911              }
 60912            },
 60913            {
 60914              "license": {
 60915                "id": "GPL-2.0-only"
 60916              }
 60917            },
 60918            {
 60919              "license": {
 60920                "id": "GPL-2.0-or-later"
 60921              }
 60922            },
 60923            {
 60924              "license": {
 60925                "id": "GPL-3.0-only"
 60926              }
 60927            },
 60928            {
 60929              "license": {
 60930                "id": "GPL-3.0-or-later"
 60931              }
 60932            },
 60933            {
 60934              "license": {
 60935                "id": "ISC"
 60936              }
 60937            },
 60938            {
 60939              "license": {
 60940                "id": "curl"
 60941              }
 60942            }
 60943          ],
 60944          "cpe": "cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.11-stable-1:*:*:*:*:*:*:*",
 60945          "purl": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04",
 60946          "swid": {
 60947            "attachment": {}
 60948          },
 60949          "pedigree": {},
 60950          "evidence": {},
 60951          "signature": {
 60952            "signature": {
 60953              "publicKey": {}
 60954            }
 60955          },
 60956          "modelCard": {
 60957            "modelParameters": {
 60958              "approach": {}
 60959            },
 60960            "quantitativeAnalysis": {
 60961              "graphics": {}
 60962            },
 60963            "considerations": {}
 60964          }
 60965        },
 60966        {
 60967          "type": "library",
 60968          "bom-ref": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04\u0026package-id=f3ac75cd161f13c6",
 60969          "supplier": {},
 60970          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 60971          "name": "libexpat1",
 60972          "version": "2.2.9-1build1",
 60973          "licenses": [
 60974            {
 60975              "license": {
 60976                "id": "MIT"
 60977              }
 60978            }
 60979          ],
 60980          "cpe": "cpe:2.3:a:libexpat1:libexpat1:2.2.9-1build1:*:*:*:*:*:*:*",
 60981          "purl": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04",
 60982          "swid": {
 60983            "attachment": {}
 60984          },
 60985          "pedigree": {},
 60986          "evidence": {},
 60987          "signature": {
 60988            "signature": {
 60989              "publicKey": {}
 60990            }
 60991          },
 60992          "modelCard": {
 60993            "modelParameters": {
 60994              "approach": {}
 60995            },
 60996            "quantitativeAnalysis": {
 60997              "graphics": {}
 60998            },
 60999            "considerations": {}
 61000          }
 61001        },
 61002        {
 61003          "type": "library",
 61004          "bom-ref": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=ec6113f55e73d1fd",
 61005          "supplier": {},
 61006          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61007          "name": "libext2fs2",
 61008          "version": "1.45.5-2ubuntu1",
 61009          "licenses": [
 61010            {
 61011              "license": {
 61012                "id": "GPL-2.0-only"
 61013              }
 61014            },
 61015            {
 61016              "license": {
 61017                "id": "LGPL-2.0-only"
 61018              }
 61019            }
 61020          ],
 61021          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 61022          "purl": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 61023          "swid": {
 61024            "attachment": {}
 61025          },
 61026          "pedigree": {},
 61027          "evidence": {},
 61028          "signature": {
 61029            "signature": {
 61030              "publicKey": {}
 61031            }
 61032          },
 61033          "modelCard": {
 61034            "modelParameters": {
 61035              "approach": {}
 61036            },
 61037            "quantitativeAnalysis": {
 61038              "graphics": {}
 61039            },
 61040            "considerations": {}
 61041          }
 61042        },
 61043        {
 61044          "type": "library",
 61045          "bom-ref": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=486ce61647644619",
 61046          "supplier": {},
 61047          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61048          "name": "libfdisk1",
 61049          "version": "2.34-0.1ubuntu9.1",
 61050          "licenses": [
 61051            {
 61052              "license": {
 61053                "id": "BSD-2-Clause"
 61054              }
 61055            },
 61056            {
 61057              "license": {
 61058                "id": "BSD-3-Clause"
 61059              }
 61060            },
 61061            {
 61062              "license": {
 61063                "id": "BSD-4-Clause"
 61064              }
 61065            },
 61066            {
 61067              "license": {
 61068                "id": "GPL-2.0-only"
 61069              }
 61070            },
 61071            {
 61072              "license": {
 61073                "id": "GPL-2.0-or-later"
 61074              }
 61075            },
 61076            {
 61077              "license": {
 61078                "id": "GPL-3.0-only"
 61079              }
 61080            },
 61081            {
 61082              "license": {
 61083                "id": "GPL-3.0-or-later"
 61084              }
 61085            },
 61086            {
 61087              "license": {
 61088                "name": "LGPL"
 61089              }
 61090            },
 61091            {
 61092              "license": {
 61093                "id": "LGPL-2.0-only"
 61094              }
 61095            },
 61096            {
 61097              "license": {
 61098                "id": "LGPL-2.0-or-later"
 61099              }
 61100            },
 61101            {
 61102              "license": {
 61103                "id": "LGPL-2.1-only"
 61104              }
 61105            },
 61106            {
 61107              "license": {
 61108                "id": "LGPL-2.1-or-later"
 61109              }
 61110            },
 61111            {
 61112              "license": {
 61113                "id": "LGPL-3.0-only"
 61114              }
 61115            },
 61116            {
 61117              "license": {
 61118                "id": "LGPL-3.0-or-later"
 61119              }
 61120            },
 61121            {
 61122              "license": {
 61123                "id": "MIT"
 61124              }
 61125            },
 61126            {
 61127              "license": {
 61128                "name": "public-domain"
 61129              }
 61130            }
 61131          ],
 61132          "cpe": "cpe:2.3:a:libfdisk1:libfdisk1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 61133          "purl": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 61134          "swid": {
 61135            "attachment": {}
 61136          },
 61137          "pedigree": {},
 61138          "evidence": {},
 61139          "signature": {
 61140            "signature": {
 61141              "publicKey": {}
 61142            }
 61143          },
 61144          "modelCard": {
 61145            "modelParameters": {
 61146              "approach": {}
 61147            },
 61148            "quantitativeAnalysis": {
 61149              "graphics": {}
 61150            },
 61151            "considerations": {}
 61152          }
 61153        },
 61154        {
 61155          "type": "library",
 61156          "bom-ref": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04\u0026package-id=b43b799d45da9d97",
 61157          "supplier": {},
 61158          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61159          "name": "libffi7",
 61160          "version": "3.3-4",
 61161          "licenses": [
 61162            {
 61163              "license": {
 61164                "name": "GPL"
 61165              }
 61166            }
 61167          ],
 61168          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-4:*:*:*:*:*:*:*",
 61169          "purl": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04",
 61170          "swid": {
 61171            "attachment": {}
 61172          },
 61173          "pedigree": {},
 61174          "evidence": {},
 61175          "signature": {
 61176            "signature": {
 61177              "publicKey": {}
 61178            }
 61179          },
 61180          "modelCard": {
 61181            "modelParameters": {
 61182              "approach": {}
 61183            },
 61184            "quantitativeAnalysis": {
 61185              "graphics": {}
 61186            },
 61187            "considerations": {}
 61188          }
 61189        },
 61190        {
 61191          "type": "library",
 61192          "bom-ref": "pkg:deb/ubuntu/libfuse2@2.9.9-3?arch=amd64\u0026upstream=fuse\u0026distro=ubuntu-20.04\u0026package-id=cb74b48e2705f805",
 61193          "supplier": {},
 61194          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61195          "name": "libfuse2",
 61196          "version": "2.9.9-3",
 61197          "licenses": [
 61198            {
 61199              "license": {
 61200                "id": "GPL-2.0-only"
 61201              }
 61202            },
 61203            {
 61204              "license": {
 61205                "id": "GPL-2.0-or-later"
 61206              }
 61207            },
 61208            {
 61209              "license": {
 61210                "id": "LGPL-2.0-only"
 61211              }
 61212            }
 61213          ],
 61214          "cpe": "cpe:2.3:a:libfuse2:libfuse2:2.9.9-3:*:*:*:*:*:*:*",
 61215          "purl": "pkg:deb/ubuntu/libfuse2@2.9.9-3?arch=amd64\u0026upstream=fuse\u0026distro=ubuntu-20.04",
 61216          "swid": {
 61217            "attachment": {}
 61218          },
 61219          "pedigree": {},
 61220          "evidence": {},
 61221          "signature": {
 61222            "signature": {
 61223              "publicKey": {}
 61224            }
 61225          },
 61226          "modelCard": {
 61227            "modelParameters": {
 61228              "approach": {}
 61229            },
 61230            "quantitativeAnalysis": {
 61231              "graphics": {}
 61232            },
 61233            "considerations": {}
 61234          }
 61235        },
 61236        {
 61237          "type": "library",
 61238          "bom-ref": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=f98ce69fd9e55bb8",
 61239          "supplier": {},
 61240          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61241          "name": "libgcc-s1",
 61242          "version": "10.3.0-1ubuntu1~20.04",
 61243          "licenses": [
 61244            {
 61245              "license": {
 61246                "name": "Artistic"
 61247              }
 61248            },
 61249            {
 61250              "license": {
 61251                "id": "GFDL-1.2-only"
 61252              }
 61253            },
 61254            {
 61255              "license": {
 61256                "name": "GPL"
 61257              }
 61258            },
 61259            {
 61260              "license": {
 61261                "id": "GPL-2.0-only"
 61262              }
 61263            },
 61264            {
 61265              "license": {
 61266                "id": "GPL-3.0-only"
 61267              }
 61268            },
 61269            {
 61270              "license": {
 61271                "name": "LGPL"
 61272              }
 61273            }
 61274          ],
 61275          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
 61276          "purl": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
 61277          "swid": {
 61278            "attachment": {}
 61279          },
 61280          "pedigree": {},
 61281          "evidence": {},
 61282          "signature": {
 61283            "signature": {
 61284              "publicKey": {}
 61285            }
 61286          },
 61287          "modelCard": {
 61288            "modelParameters": {
 61289              "approach": {}
 61290            },
 61291            "quantitativeAnalysis": {
 61292              "graphics": {}
 61293            },
 61294            "considerations": {}
 61295          }
 61296        },
 61297        {
 61298          "type": "library",
 61299          "bom-ref": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=c8a43aa5b28727a1",
 61300          "supplier": {},
 61301          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61302          "name": "libgcrypt20",
 61303          "version": "1.8.5-5ubuntu1",
 61304          "licenses": [
 61305            {
 61306              "license": {
 61307                "id": "GPL-2.0-only"
 61308              }
 61309            },
 61310            {
 61311              "license": {
 61312                "name": "LGPL"
 61313              }
 61314            }
 61315          ],
 61316          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.5-5ubuntu1:*:*:*:*:*:*:*",
 61317          "purl": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 61318          "swid": {
 61319            "attachment": {}
 61320          },
 61321          "pedigree": {},
 61322          "evidence": {},
 61323          "signature": {
 61324            "signature": {
 61325              "publicKey": {}
 61326            }
 61327          },
 61328          "modelCard": {
 61329            "modelParameters": {
 61330              "approach": {}
 61331            },
 61332            "quantitativeAnalysis": {
 61333              "graphics": {}
 61334            },
 61335            "considerations": {}
 61336          }
 61337        },
 61338        {
 61339          "type": "library",
 61340          "bom-ref": "pkg:deb/ubuntu/libgdbm-compat4@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04\u0026package-id=216492c4d03e5a3b",
 61341          "supplier": {},
 61342          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61343          "name": "libgdbm-compat4",
 61344          "version": "1.18.1-5",
 61345          "licenses": [
 61346            {
 61347              "license": {
 61348                "name": "GFDL-NIV-1.3+"
 61349              }
 61350            },
 61351            {
 61352              "license": {
 61353                "id": "GPL-2.0-only"
 61354              }
 61355            },
 61356            {
 61357              "license": {
 61358                "id": "GPL-2.0-or-later"
 61359              }
 61360            },
 61361            {
 61362              "license": {
 61363                "id": "GPL-3.0-only"
 61364              }
 61365            },
 61366            {
 61367              "license": {
 61368                "id": "GPL-3.0-or-later"
 61369              }
 61370            }
 61371          ],
 61372          "cpe": "cpe:2.3:a:libgdbm-compat4:libgdbm-compat4:1.18.1-5:*:*:*:*:*:*:*",
 61373          "purl": "pkg:deb/ubuntu/libgdbm-compat4@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04",
 61374          "swid": {
 61375            "attachment": {}
 61376          },
 61377          "pedigree": {},
 61378          "evidence": {},
 61379          "signature": {
 61380            "signature": {
 61381              "publicKey": {}
 61382            }
 61383          },
 61384          "modelCard": {
 61385            "modelParameters": {
 61386              "approach": {}
 61387            },
 61388            "quantitativeAnalysis": {
 61389              "graphics": {}
 61390            },
 61391            "considerations": {}
 61392          }
 61393        },
 61394        {
 61395          "type": "library",
 61396          "bom-ref": "pkg:deb/ubuntu/libgdbm6@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04\u0026package-id=e7baa5d6d4faa647",
 61397          "supplier": {},
 61398          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61399          "name": "libgdbm6",
 61400          "version": "1.18.1-5",
 61401          "licenses": [
 61402            {
 61403              "license": {
 61404                "name": "GFDL-NIV-1.3+"
 61405              }
 61406            },
 61407            {
 61408              "license": {
 61409                "id": "GPL-2.0-only"
 61410              }
 61411            },
 61412            {
 61413              "license": {
 61414                "id": "GPL-2.0-or-later"
 61415              }
 61416            },
 61417            {
 61418              "license": {
 61419                "id": "GPL-3.0-only"
 61420              }
 61421            },
 61422            {
 61423              "license": {
 61424                "id": "GPL-3.0-or-later"
 61425              }
 61426            }
 61427          ],
 61428          "cpe": "cpe:2.3:a:libgdbm6:libgdbm6:1.18.1-5:*:*:*:*:*:*:*",
 61429          "purl": "pkg:deb/ubuntu/libgdbm6@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04",
 61430          "swid": {
 61431            "attachment": {}
 61432          },
 61433          "pedigree": {},
 61434          "evidence": {},
 61435          "signature": {
 61436            "signature": {
 61437              "publicKey": {}
 61438            }
 61439          },
 61440          "modelCard": {
 61441            "modelParameters": {
 61442              "approach": {}
 61443            },
 61444            "quantitativeAnalysis": {
 61445              "graphics": {}
 61446            },
 61447            "considerations": {}
 61448          }
 61449        },
 61450        {
 61451          "type": "library",
 61452          "bom-ref": "pkg:deb/ubuntu/libglib2.0-0@2.64.6-1~ubuntu20.04.4?arch=amd64\u0026upstream=glib2.0\u0026distro=ubuntu-20.04\u0026package-id=173f54b9a4ea5bbf",
 61453          "supplier": {},
 61454          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61455          "name": "libglib2.0-0",
 61456          "version": "2.64.6-1~ubuntu20.04.4",
 61457          "licenses": [
 61458            {
 61459              "license": {
 61460                "name": "Expat"
 61461              }
 61462            },
 61463            {
 61464              "license": {
 61465                "id": "GPL-2.0-or-later"
 61466              }
 61467            },
 61468            {
 61469              "license": {
 61470                "name": "LGPL"
 61471              }
 61472            }
 61473          ],
 61474          "cpe": "cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.64.6-1\\~ubuntu20.04.4:*:*:*:*:*:*:*",
 61475          "purl": "pkg:deb/ubuntu/libglib2.0-0@2.64.6-1~ubuntu20.04.4?arch=amd64\u0026upstream=glib2.0\u0026distro=ubuntu-20.04",
 61476          "swid": {
 61477            "attachment": {}
 61478          },
 61479          "pedigree": {},
 61480          "evidence": {},
 61481          "signature": {
 61482            "signature": {
 61483              "publicKey": {}
 61484            }
 61485          },
 61486          "modelCard": {
 61487            "modelParameters": {
 61488              "approach": {}
 61489            },
 61490            "quantitativeAnalysis": {
 61491              "graphics": {}
 61492            },
 61493            "considerations": {}
 61494          }
 61495        },
 61496        {
 61497          "type": "library",
 61498          "bom-ref": "pkg:deb/ubuntu/libglib2.0-data@2.64.6-1~ubuntu20.04.4?arch=all\u0026upstream=glib2.0\u0026distro=ubuntu-20.04\u0026package-id=84c7d5b71baf104a",
 61499          "supplier": {},
 61500          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61501          "name": "libglib2.0-data",
 61502          "version": "2.64.6-1~ubuntu20.04.4",
 61503          "licenses": [
 61504            {
 61505              "license": {
 61506                "name": "Expat"
 61507              }
 61508            },
 61509            {
 61510              "license": {
 61511                "id": "GPL-2.0-or-later"
 61512              }
 61513            },
 61514            {
 61515              "license": {
 61516                "name": "LGPL"
 61517              }
 61518            }
 61519          ],
 61520          "cpe": "cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.64.6-1\\~ubuntu20.04.4:*:*:*:*:*:*:*",
 61521          "purl": "pkg:deb/ubuntu/libglib2.0-data@2.64.6-1~ubuntu20.04.4?arch=all\u0026upstream=glib2.0\u0026distro=ubuntu-20.04",
 61522          "swid": {
 61523            "attachment": {}
 61524          },
 61525          "pedigree": {},
 61526          "evidence": {},
 61527          "signature": {
 61528            "signature": {
 61529              "publicKey": {}
 61530            }
 61531          },
 61532          "modelCard": {
 61533            "modelParameters": {
 61534              "approach": {}
 61535            },
 61536            "quantitativeAnalysis": {
 61537              "graphics": {}
 61538            },
 61539            "considerations": {}
 61540          }
 61541        },
 61542        {
 61543          "type": "library",
 61544          "bom-ref": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04\u0026package-id=40fc269dcb8b3369",
 61545          "supplier": {},
 61546          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61547          "name": "libgmp10",
 61548          "version": "2:6.2.0+dfsg-4",
 61549          "licenses": [
 61550            {
 61551              "license": {
 61552                "name": "GPL"
 61553              }
 61554            },
 61555            {
 61556              "license": {
 61557                "id": "GPL-2.0-only"
 61558              }
 61559            },
 61560            {
 61561              "license": {
 61562                "id": "GPL-3.0-only"
 61563              }
 61564            },
 61565            {
 61566              "license": {
 61567                "id": "LGPL-3.0-only"
 61568              }
 61569            }
 61570          ],
 61571          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.0\\+dfsg-4:*:*:*:*:*:*:*",
 61572          "purl": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04",
 61573          "swid": {
 61574            "attachment": {}
 61575          },
 61576          "pedigree": {},
 61577          "evidence": {},
 61578          "signature": {
 61579            "signature": {
 61580              "publicKey": {}
 61581            }
 61582          },
 61583          "modelCard": {
 61584            "modelParameters": {
 61585              "approach": {}
 61586            },
 61587            "quantitativeAnalysis": {
 61588              "graphics": {}
 61589            },
 61590            "considerations": {}
 61591          }
 61592        },
 61593        {
 61594          "type": "library",
 61595          "bom-ref": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04\u0026package-id=7490f76da775c6e",
 61596          "supplier": {},
 61597          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61598          "name": "libgnutls30",
 61599          "version": "3.6.13-2ubuntu1.6",
 61600          "licenses": [
 61601            {
 61602              "license": {
 61603                "id": "Apache-2.0"
 61604              }
 61605            },
 61606            {
 61607              "license": {
 61608                "id": "BSD-3-Clause"
 61609              }
 61610            },
 61611            {
 61612              "license": {
 61613                "name": "CC0"
 61614              }
 61615            },
 61616            {
 61617              "license": {
 61618                "name": "Expat"
 61619              }
 61620            },
 61621            {
 61622              "license": {
 61623                "id": "GFDL-1.3-only"
 61624              }
 61625            },
 61626            {
 61627              "license": {
 61628                "name": "GPL"
 61629              }
 61630            },
 61631            {
 61632              "license": {
 61633                "id": "GPL-3.0-only"
 61634              }
 61635            },
 61636            {
 61637              "license": {
 61638                "name": "GPLv3+"
 61639              }
 61640            },
 61641            {
 61642              "license": {
 61643                "name": "LGPL"
 61644              }
 61645            },
 61646            {
 61647              "license": {
 61648                "id": "LGPL-3.0-only"
 61649              }
 61650            },
 61651            {
 61652              "license": {
 61653                "name": "LGPLv2.1+"
 61654              }
 61655            },
 61656            {
 61657              "license": {
 61658                "name": "LGPLv3+_or_GPLv2+"
 61659              }
 61660            },
 61661            {
 61662              "license": {
 61663                "name": "The"
 61664              }
 61665            }
 61666          ],
 61667          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.13-2ubuntu1.6:*:*:*:*:*:*:*",
 61668          "purl": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04",
 61669          "swid": {
 61670            "attachment": {}
 61671          },
 61672          "pedigree": {},
 61673          "evidence": {},
 61674          "signature": {
 61675            "signature": {
 61676              "publicKey": {}
 61677            }
 61678          },
 61679          "modelCard": {
 61680            "modelParameters": {
 61681              "approach": {}
 61682            },
 61683            "quantitativeAnalysis": {
 61684              "graphics": {}
 61685            },
 61686            "considerations": {}
 61687          }
 61688        },
 61689        {
 61690          "type": "library",
 61691          "bom-ref": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04\u0026package-id=37ef62d87edfe03",
 61692          "supplier": {},
 61693          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61694          "name": "libgpg-error0",
 61695          "version": "1.37-1",
 61696          "licenses": [
 61697            {
 61698              "license": {
 61699                "id": "BSD-3-Clause"
 61700              }
 61701            },
 61702            {
 61703              "license": {
 61704                "id": "GPL-3.0-only"
 61705              }
 61706            },
 61707            {
 61708              "license": {
 61709                "id": "GPL-3.0-or-later"
 61710              }
 61711            },
 61712            {
 61713              "license": {
 61714                "id": "LGPL-2.1-only"
 61715              }
 61716            },
 61717            {
 61718              "license": {
 61719                "id": "LGPL-2.1-or-later"
 61720              }
 61721            },
 61722            {
 61723              "license": {
 61724                "name": "g10-permissive"
 61725              }
 61726            }
 61727          ],
 61728          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.37-1:*:*:*:*:*:*:*",
 61729          "purl": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04",
 61730          "swid": {
 61731            "attachment": {}
 61732          },
 61733          "pedigree": {},
 61734          "evidence": {},
 61735          "signature": {
 61736            "signature": {
 61737              "publicKey": {}
 61738            }
 61739          },
 61740          "modelCard": {
 61741            "modelParameters": {
 61742              "approach": {}
 61743            },
 61744            "quantitativeAnalysis": {
 61745              "graphics": {}
 61746            },
 61747            "considerations": {}
 61748          }
 61749        },
 61750        {
 61751          "type": "library",
 61752          "bom-ref": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=443eafe2785f5a4c",
 61753          "supplier": {},
 61754          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61755          "name": "libgssapi-krb5-2",
 61756          "version": "1.17-6ubuntu4.1",
 61757          "licenses": [
 61758            {
 61759              "license": {
 61760                "id": "GPL-2.0-only"
 61761              }
 61762            }
 61763          ],
 61764          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 61765          "purl": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 61766          "swid": {
 61767            "attachment": {}
 61768          },
 61769          "pedigree": {},
 61770          "evidence": {},
 61771          "signature": {
 61772            "signature": {
 61773              "publicKey": {}
 61774            }
 61775          },
 61776          "modelCard": {
 61777            "modelParameters": {
 61778              "approach": {}
 61779            },
 61780            "quantitativeAnalysis": {
 61781              "graphics": {}
 61782            },
 61783            "considerations": {}
 61784          }
 61785        },
 61786        {
 61787          "type": "library",
 61788          "bom-ref": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=17a37cca2446b615",
 61789          "supplier": {},
 61790          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61791          "name": "libgssapi3-heimdal",
 61792          "version": "7.7.0+dfsg-1ubuntu1",
 61793          "licenses": [
 61794            {
 61795              "license": {
 61796                "id": "BSD-3-Clause"
 61797              }
 61798            },
 61799            {
 61800              "license": {
 61801                "id": "GPL-2.0-only"
 61802              }
 61803            },
 61804            {
 61805              "license": {
 61806                "id": "GPL-2.0-or-later"
 61807              }
 61808            },
 61809            {
 61810              "license": {
 61811                "name": "custom"
 61812              }
 61813            }
 61814          ],
 61815          "cpe": "cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 61816          "purl": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 61817          "swid": {
 61818            "attachment": {}
 61819          },
 61820          "pedigree": {},
 61821          "evidence": {},
 61822          "signature": {
 61823            "signature": {
 61824              "publicKey": {}
 61825            }
 61826          },
 61827          "modelCard": {
 61828            "modelParameters": {
 61829              "approach": {}
 61830            },
 61831            "quantitativeAnalysis": {
 61832              "graphics": {}
 61833            },
 61834            "considerations": {}
 61835          }
 61836        },
 61837        {
 61838          "type": "library",
 61839          "bom-ref": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=98098d582df76b44",
 61840          "supplier": {},
 61841          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61842          "name": "libhcrypto4-heimdal",
 61843          "version": "7.7.0+dfsg-1ubuntu1",
 61844          "licenses": [
 61845            {
 61846              "license": {
 61847                "id": "BSD-3-Clause"
 61848              }
 61849            },
 61850            {
 61851              "license": {
 61852                "id": "GPL-2.0-only"
 61853              }
 61854            },
 61855            {
 61856              "license": {
 61857                "id": "GPL-2.0-or-later"
 61858              }
 61859            },
 61860            {
 61861              "license": {
 61862                "name": "custom"
 61863              }
 61864            }
 61865          ],
 61866          "cpe": "cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 61867          "purl": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 61868          "swid": {
 61869            "attachment": {}
 61870          },
 61871          "pedigree": {},
 61872          "evidence": {},
 61873          "signature": {
 61874            "signature": {
 61875              "publicKey": {}
 61876            }
 61877          },
 61878          "modelCard": {
 61879            "modelParameters": {
 61880              "approach": {}
 61881            },
 61882            "quantitativeAnalysis": {
 61883              "graphics": {}
 61884            },
 61885            "considerations": {}
 61886          }
 61887        },
 61888        {
 61889          "type": "library",
 61890          "bom-ref": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=f8dfc9a84c337835",
 61891          "supplier": {},
 61892          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61893          "name": "libheimbase1-heimdal",
 61894          "version": "7.7.0+dfsg-1ubuntu1",
 61895          "licenses": [
 61896            {
 61897              "license": {
 61898                "id": "BSD-3-Clause"
 61899              }
 61900            },
 61901            {
 61902              "license": {
 61903                "id": "GPL-2.0-only"
 61904              }
 61905            },
 61906            {
 61907              "license": {
 61908                "id": "GPL-2.0-or-later"
 61909              }
 61910            },
 61911            {
 61912              "license": {
 61913                "name": "custom"
 61914              }
 61915            }
 61916          ],
 61917          "cpe": "cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 61918          "purl": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 61919          "swid": {
 61920            "attachment": {}
 61921          },
 61922          "pedigree": {},
 61923          "evidence": {},
 61924          "signature": {
 61925            "signature": {
 61926              "publicKey": {}
 61927            }
 61928          },
 61929          "modelCard": {
 61930            "modelParameters": {
 61931              "approach": {}
 61932            },
 61933            "quantitativeAnalysis": {
 61934              "graphics": {}
 61935            },
 61936            "considerations": {}
 61937          }
 61938        },
 61939        {
 61940          "type": "library",
 61941          "bom-ref": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=9992d88ac7d6e8e3",
 61942          "supplier": {},
 61943          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61944          "name": "libheimntlm0-heimdal",
 61945          "version": "7.7.0+dfsg-1ubuntu1",
 61946          "licenses": [
 61947            {
 61948              "license": {
 61949                "id": "BSD-3-Clause"
 61950              }
 61951            },
 61952            {
 61953              "license": {
 61954                "id": "GPL-2.0-only"
 61955              }
 61956            },
 61957            {
 61958              "license": {
 61959                "id": "GPL-2.0-or-later"
 61960              }
 61961            },
 61962            {
 61963              "license": {
 61964                "name": "custom"
 61965              }
 61966            }
 61967          ],
 61968          "cpe": "cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 61969          "purl": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 61970          "swid": {
 61971            "attachment": {}
 61972          },
 61973          "pedigree": {},
 61974          "evidence": {},
 61975          "signature": {
 61976            "signature": {
 61977              "publicKey": {}
 61978            }
 61979          },
 61980          "modelCard": {
 61981            "modelParameters": {
 61982              "approach": {}
 61983            },
 61984            "quantitativeAnalysis": {
 61985              "graphics": {}
 61986            },
 61987            "considerations": {}
 61988          }
 61989        },
 61990        {
 61991          "type": "library",
 61992          "bom-ref": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3caecccf070e6760",
 61993          "supplier": {},
 61994          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 61995          "name": "libhogweed5",
 61996          "version": "3.5.1+really3.5.1-2ubuntu0.2",
 61997          "licenses": [
 61998            {
 61999              "license": {
 62000                "name": "GAP"
 62001              }
 62002            },
 62003            {
 62004              "license": {
 62005                "name": "GPL"
 62006              }
 62007            },
 62008            {
 62009              "license": {
 62010                "id": "GPL-2.0-only"
 62011              }
 62012            },
 62013            {
 62014              "license": {
 62015                "id": "GPL-2.0-or-later"
 62016              }
 62017            },
 62018            {
 62019              "license": {
 62020                "name": "LGPL"
 62021              }
 62022            },
 62023            {
 62024              "license": {
 62025                "id": "LGPL-2.0-only"
 62026              }
 62027            },
 62028            {
 62029              "license": {
 62030                "id": "LGPL-2.0-or-later"
 62031              }
 62032            },
 62033            {
 62034              "license": {
 62035                "id": "LGPL-2.1-or-later"
 62036              }
 62037            },
 62038            {
 62039              "license": {
 62040                "name": "other"
 62041              }
 62042            },
 62043            {
 62044              "license": {
 62045                "name": "public-domain"
 62046              }
 62047            }
 62048          ],
 62049          "cpe": "cpe:2.3:a:libhogweed5:libhogweed5:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
 62050          "purl": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
 62051          "swid": {
 62052            "attachment": {}
 62053          },
 62054          "pedigree": {},
 62055          "evidence": {},
 62056          "signature": {
 62057            "signature": {
 62058              "publicKey": {}
 62059            }
 62060          },
 62061          "modelCard": {
 62062            "modelParameters": {
 62063              "approach": {}
 62064            },
 62065            "quantitativeAnalysis": {
 62066              "graphics": {}
 62067            },
 62068            "considerations": {}
 62069          }
 62070        },
 62071        {
 62072          "type": "library",
 62073          "bom-ref": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=3b0bac5e4e8f23c5",
 62074          "supplier": {},
 62075          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62076          "name": "libhx509-5-heimdal",
 62077          "version": "7.7.0+dfsg-1ubuntu1",
 62078          "licenses": [
 62079            {
 62080              "license": {
 62081                "id": "BSD-3-Clause"
 62082              }
 62083            },
 62084            {
 62085              "license": {
 62086                "id": "GPL-2.0-only"
 62087              }
 62088            },
 62089            {
 62090              "license": {
 62091                "id": "GPL-2.0-or-later"
 62092              }
 62093            },
 62094            {
 62095              "license": {
 62096                "name": "custom"
 62097              }
 62098            }
 62099          ],
 62100          "cpe": "cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 62101          "purl": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 62102          "swid": {
 62103            "attachment": {}
 62104          },
 62105          "pedigree": {},
 62106          "evidence": {},
 62107          "signature": {
 62108            "signature": {
 62109              "publicKey": {}
 62110            }
 62111          },
 62112          "modelCard": {
 62113            "modelParameters": {
 62114              "approach": {}
 62115            },
 62116            "quantitativeAnalysis": {
 62117              "graphics": {}
 62118            },
 62119            "considerations": {}
 62120          }
 62121        },
 62122        {
 62123          "type": "library",
 62124          "bom-ref": "pkg:deb/ubuntu/libibverbs1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04\u0026package-id=8a574b9c0296728e",
 62125          "supplier": {},
 62126          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62127          "name": "libibverbs1",
 62128          "version": "28.0-1ubuntu1",
 62129          "licenses": [
 62130            {
 62131              "license": {
 62132                "id": "BSD-2-Clause"
 62133              }
 62134            },
 62135            {
 62136              "license": {
 62137                "id": "BSD-3-Clause"
 62138              }
 62139            },
 62140            {
 62141              "license": {
 62142                "name": "BSD-MIT"
 62143              }
 62144            },
 62145            {
 62146              "license": {
 62147                "name": "CC0"
 62148              }
 62149            },
 62150            {
 62151              "license": {
 62152                "id": "CPL-1.0"
 62153              }
 62154            },
 62155            {
 62156              "license": {
 62157                "id": "GPL-2.0-only"
 62158              }
 62159            },
 62160            {
 62161              "license": {
 62162                "id": "GPL-2.0-or-later"
 62163              }
 62164            },
 62165            {
 62166              "license": {
 62167                "id": "MIT"
 62168              }
 62169            }
 62170          ],
 62171          "cpe": "cpe:2.3:a:libibverbs1:libibverbs1:28.0-1ubuntu1:*:*:*:*:*:*:*",
 62172          "purl": "pkg:deb/ubuntu/libibverbs1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04",
 62173          "swid": {
 62174            "attachment": {}
 62175          },
 62176          "pedigree": {},
 62177          "evidence": {},
 62178          "signature": {
 62179            "signature": {
 62180              "publicKey": {}
 62181            }
 62182          },
 62183          "modelCard": {
 62184            "modelParameters": {
 62185              "approach": {}
 62186            },
 62187            "quantitativeAnalysis": {
 62188              "graphics": {}
 62189            },
 62190            "considerations": {}
 62191          }
 62192        },
 62193        {
 62194          "type": "library",
 62195          "bom-ref": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04\u0026package-id=bcf598a9dea4cd38",
 62196          "supplier": {},
 62197          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62198          "name": "libicu66",
 62199          "version": "66.1-2ubuntu2",
 62200          "cpe": "cpe:2.3:a:libicu66:libicu66:66.1-2ubuntu2:*:*:*:*:*:*:*",
 62201          "purl": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04",
 62202          "swid": {
 62203            "attachment": {}
 62204          },
 62205          "pedigree": {},
 62206          "evidence": {},
 62207          "signature": {
 62208            "signature": {
 62209              "publicKey": {}
 62210            }
 62211          },
 62212          "modelCard": {
 62213            "modelParameters": {
 62214              "approach": {}
 62215            },
 62216            "quantitativeAnalysis": {
 62217              "graphics": {}
 62218            },
 62219            "considerations": {}
 62220          }
 62221        },
 62222        {
 62223          "type": "library",
 62224          "bom-ref": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04\u0026package-id=d2a82c3e28413bc1",
 62225          "supplier": {},
 62226          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62227          "name": "libidn2-0",
 62228          "version": "2.2.0-2",
 62229          "licenses": [
 62230            {
 62231              "license": {
 62232                "id": "GPL-2.0-only"
 62233              }
 62234            },
 62235            {
 62236              "license": {
 62237                "id": "GPL-2.0-or-later"
 62238              }
 62239            },
 62240            {
 62241              "license": {
 62242                "id": "GPL-3.0-only"
 62243              }
 62244            },
 62245            {
 62246              "license": {
 62247                "id": "GPL-3.0-or-later"
 62248              }
 62249            },
 62250            {
 62251              "license": {
 62252                "id": "LGPL-3.0-only"
 62253              }
 62254            },
 62255            {
 62256              "license": {
 62257                "id": "LGPL-3.0-or-later"
 62258              }
 62259            },
 62260            {
 62261              "license": {
 62262                "name": "Unicode"
 62263              }
 62264            }
 62265          ],
 62266          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.2.0-2:*:*:*:*:*:*:*",
 62267          "purl": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04",
 62268          "swid": {
 62269            "attachment": {}
 62270          },
 62271          "pedigree": {},
 62272          "evidence": {},
 62273          "signature": {
 62274            "signature": {
 62275              "publicKey": {}
 62276            }
 62277          },
 62278          "modelCard": {
 62279            "modelParameters": {
 62280              "approach": {}
 62281            },
 62282            "quantitativeAnalysis": {
 62283              "graphics": {}
 62284            },
 62285            "considerations": {}
 62286          }
 62287        },
 62288        {
 62289          "type": "library",
 62290          "bom-ref": "pkg:deb/ubuntu/libiscsi7@1.18.0-2?arch=amd64\u0026upstream=libiscsi\u0026distro=ubuntu-20.04\u0026package-id=d3404aeee287695b",
 62291          "supplier": {},
 62292          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62293          "name": "libiscsi7",
 62294          "version": "1.18.0-2",
 62295          "licenses": [
 62296            {
 62297              "license": {
 62298                "id": "GPL-2.0-only"
 62299              }
 62300            },
 62301            {
 62302              "license": {
 62303                "id": "GPL-2.0-or-later"
 62304              }
 62305            },
 62306            {
 62307              "license": {
 62308                "id": "GPL-3.0-only"
 62309              }
 62310            },
 62311            {
 62312              "license": {
 62313                "id": "GPL-3.0-or-later"
 62314              }
 62315            },
 62316            {
 62317              "license": {
 62318                "id": "LGPL-2.1-only"
 62319              }
 62320            },
 62321            {
 62322              "license": {
 62323                "id": "LGPL-2.1-or-later"
 62324              }
 62325            },
 62326            {
 62327              "license": {
 62328                "name": "MIT/X11"
 62329              }
 62330            },
 62331            {
 62332              "license": {
 62333                "name": "Public_domain"
 62334              }
 62335            }
 62336          ],
 62337          "cpe": "cpe:2.3:a:libiscsi7:libiscsi7:1.18.0-2:*:*:*:*:*:*:*",
 62338          "purl": "pkg:deb/ubuntu/libiscsi7@1.18.0-2?arch=amd64\u0026upstream=libiscsi\u0026distro=ubuntu-20.04",
 62339          "swid": {
 62340            "attachment": {}
 62341          },
 62342          "pedigree": {},
 62343          "evidence": {},
 62344          "signature": {
 62345            "signature": {
 62346              "publicKey": {}
 62347            }
 62348          },
 62349          "modelCard": {
 62350            "modelParameters": {
 62351              "approach": {}
 62352            },
 62353            "quantitativeAnalysis": {
 62354              "graphics": {}
 62355            },
 62356            "considerations": {}
 62357          }
 62358        },
 62359        {
 62360          "type": "library",
 62361          "bom-ref": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=f9479050b59432b4",
 62362          "supplier": {},
 62363          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62364          "name": "libk5crypto3",
 62365          "version": "1.17-6ubuntu4.1",
 62366          "licenses": [
 62367            {
 62368              "license": {
 62369                "id": "GPL-2.0-only"
 62370              }
 62371            }
 62372          ],
 62373          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 62374          "purl": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 62375          "swid": {
 62376            "attachment": {}
 62377          },
 62378          "pedigree": {},
 62379          "evidence": {},
 62380          "signature": {
 62381            "signature": {
 62382              "publicKey": {}
 62383            }
 62384          },
 62385          "modelCard": {
 62386            "modelParameters": {
 62387              "approach": {}
 62388            },
 62389            "quantitativeAnalysis": {
 62390              "graphics": {}
 62391            },
 62392            "considerations": {}
 62393          }
 62394        },
 62395        {
 62396          "type": "library",
 62397          "bom-ref": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04\u0026package-id=e8692427b123ea73",
 62398          "supplier": {},
 62399          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62400          "name": "libkeyutils1",
 62401          "version": "1.6-6ubuntu1",
 62402          "licenses": [
 62403            {
 62404              "license": {
 62405                "id": "GPL-2.0-only"
 62406              }
 62407            },
 62408            {
 62409              "license": {
 62410                "id": "GPL-2.0-or-later"
 62411              }
 62412            },
 62413            {
 62414              "license": {
 62415                "id": "LGPL-2.0-only"
 62416              }
 62417            },
 62418            {
 62419              "license": {
 62420                "id": "LGPL-2.0-or-later"
 62421              }
 62422            }
 62423          ],
 62424          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6-6ubuntu1:*:*:*:*:*:*:*",
 62425          "purl": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04",
 62426          "swid": {
 62427            "attachment": {}
 62428          },
 62429          "pedigree": {},
 62430          "evidence": {},
 62431          "signature": {
 62432            "signature": {
 62433              "publicKey": {}
 62434            }
 62435          },
 62436          "modelCard": {
 62437            "modelParameters": {
 62438              "approach": {}
 62439            },
 62440            "quantitativeAnalysis": {
 62441              "graphics": {}
 62442            },
 62443            "considerations": {}
 62444          }
 62445        },
 62446        {
 62447          "type": "library",
 62448          "bom-ref": "pkg:deb/ubuntu/libkmod2@27-1ubuntu2?arch=amd64\u0026upstream=kmod\u0026distro=ubuntu-20.04\u0026package-id=9de5f0614e60f8ee",
 62449          "supplier": {},
 62450          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62451          "name": "libkmod2",
 62452          "version": "27-1ubuntu2",
 62453          "licenses": [
 62454            {
 62455              "license": {
 62456                "id": "GPL-2.0-only"
 62457              }
 62458            }
 62459          ],
 62460          "cpe": "cpe:2.3:a:libkmod2:libkmod2:27-1ubuntu2:*:*:*:*:*:*:*",
 62461          "purl": "pkg:deb/ubuntu/libkmod2@27-1ubuntu2?arch=amd64\u0026upstream=kmod\u0026distro=ubuntu-20.04",
 62462          "swid": {
 62463            "attachment": {}
 62464          },
 62465          "pedigree": {},
 62466          "evidence": {},
 62467          "signature": {
 62468            "signature": {
 62469              "publicKey": {}
 62470            }
 62471          },
 62472          "modelCard": {
 62473            "modelParameters": {
 62474              "approach": {}
 62475            },
 62476            "quantitativeAnalysis": {
 62477              "graphics": {}
 62478            },
 62479            "considerations": {}
 62480          }
 62481        },
 62482        {
 62483          "type": "library",
 62484          "bom-ref": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=2beb670b9378498e",
 62485          "supplier": {},
 62486          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62487          "name": "libkrb5-26-heimdal",
 62488          "version": "7.7.0+dfsg-1ubuntu1",
 62489          "licenses": [
 62490            {
 62491              "license": {
 62492                "id": "BSD-3-Clause"
 62493              }
 62494            },
 62495            {
 62496              "license": {
 62497                "id": "GPL-2.0-only"
 62498              }
 62499            },
 62500            {
 62501              "license": {
 62502                "id": "GPL-2.0-or-later"
 62503              }
 62504            },
 62505            {
 62506              "license": {
 62507                "name": "custom"
 62508              }
 62509            }
 62510          ],
 62511          "cpe": "cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 62512          "purl": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 62513          "swid": {
 62514            "attachment": {}
 62515          },
 62516          "pedigree": {},
 62517          "evidence": {},
 62518          "signature": {
 62519            "signature": {
 62520              "publicKey": {}
 62521            }
 62522          },
 62523          "modelCard": {
 62524            "modelParameters": {
 62525              "approach": {}
 62526            },
 62527            "quantitativeAnalysis": {
 62528              "graphics": {}
 62529            },
 62530            "considerations": {}
 62531          }
 62532        },
 62533        {
 62534          "type": "library",
 62535          "bom-ref": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=fdb5970d8394a182",
 62536          "supplier": {},
 62537          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62538          "name": "libkrb5-3",
 62539          "version": "1.17-6ubuntu4.1",
 62540          "licenses": [
 62541            {
 62542              "license": {
 62543                "id": "GPL-2.0-only"
 62544              }
 62545            }
 62546          ],
 62547          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 62548          "purl": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 62549          "swid": {
 62550            "attachment": {}
 62551          },
 62552          "pedigree": {},
 62553          "evidence": {},
 62554          "signature": {
 62555            "signature": {
 62556              "publicKey": {}
 62557            }
 62558          },
 62559          "modelCard": {
 62560            "modelParameters": {
 62561              "approach": {}
 62562            },
 62563            "quantitativeAnalysis": {
 62564              "graphics": {}
 62565            },
 62566            "considerations": {}
 62567          }
 62568        },
 62569        {
 62570          "type": "library",
 62571          "bom-ref": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=a8d21a32e178b211",
 62572          "supplier": {},
 62573          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62574          "name": "libkrb5support0",
 62575          "version": "1.17-6ubuntu4.1",
 62576          "licenses": [
 62577            {
 62578              "license": {
 62579                "id": "GPL-2.0-only"
 62580              }
 62581            }
 62582          ],
 62583          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
 62584          "purl": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
 62585          "swid": {
 62586            "attachment": {}
 62587          },
 62588          "pedigree": {},
 62589          "evidence": {},
 62590          "signature": {
 62591            "signature": {
 62592              "publicKey": {}
 62593            }
 62594          },
 62595          "modelCard": {
 62596            "modelParameters": {
 62597              "approach": {}
 62598            },
 62599            "quantitativeAnalysis": {
 62600              "graphics": {}
 62601            },
 62602            "considerations": {}
 62603          }
 62604        },
 62605        {
 62606          "type": "library",
 62607          "bom-ref": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=efdc80a7ae6eae19",
 62608          "supplier": {},
 62609          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62610          "name": "libldap-2.4-2",
 62611          "version": "2.4.49+dfsg-2ubuntu1.8",
 62612          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
 62613          "purl": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04",
 62614          "swid": {
 62615            "attachment": {}
 62616          },
 62617          "pedigree": {},
 62618          "evidence": {},
 62619          "signature": {
 62620            "signature": {
 62621              "publicKey": {}
 62622            }
 62623          },
 62624          "modelCard": {
 62625            "modelParameters": {
 62626              "approach": {}
 62627            },
 62628            "quantitativeAnalysis": {
 62629              "graphics": {}
 62630            },
 62631            "considerations": {}
 62632          }
 62633        },
 62634        {
 62635          "type": "library",
 62636          "bom-ref": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=4d0b88f98b40786b",
 62637          "supplier": {},
 62638          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62639          "name": "libldap-common",
 62640          "version": "2.4.49+dfsg-2ubuntu1.8",
 62641          "cpe": "cpe:2.3:a:libldap-common:libldap-common:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
 62642          "purl": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04",
 62643          "swid": {
 62644            "attachment": {}
 62645          },
 62646          "pedigree": {},
 62647          "evidence": {},
 62648          "signature": {
 62649            "signature": {
 62650              "publicKey": {}
 62651            }
 62652          },
 62653          "modelCard": {
 62654            "modelParameters": {
 62655              "approach": {}
 62656            },
 62657            "quantitativeAnalysis": {
 62658              "graphics": {}
 62659            },
 62660            "considerations": {}
 62661          }
 62662        },
 62663        {
 62664          "type": "library",
 62665          "bom-ref": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04\u0026package-id=6f2c431caeb4980a",
 62666          "supplier": {},
 62667          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62668          "name": "liblz4-1",
 62669          "version": "1.9.2-2ubuntu0.20.04.1",
 62670          "licenses": [
 62671            {
 62672              "license": {
 62673                "id": "BSD-2-Clause"
 62674              }
 62675            },
 62676            {
 62677              "license": {
 62678                "id": "GPL-2.0-only"
 62679              }
 62680            },
 62681            {
 62682              "license": {
 62683                "id": "GPL-2.0-or-later"
 62684              }
 62685            }
 62686          ],
 62687          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.2-2ubuntu0.20.04.1:*:*:*:*:*:*:*",
 62688          "purl": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04",
 62689          "swid": {
 62690            "attachment": {}
 62691          },
 62692          "pedigree": {},
 62693          "evidence": {},
 62694          "signature": {
 62695            "signature": {
 62696              "publicKey": {}
 62697            }
 62698          },
 62699          "modelCard": {
 62700            "modelParameters": {
 62701              "approach": {}
 62702            },
 62703            "quantitativeAnalysis": {
 62704              "graphics": {}
 62705            },
 62706            "considerations": {}
 62707          }
 62708        },
 62709        {
 62710          "type": "library",
 62711          "bom-ref": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04\u0026package-id=f1e9f3b6205a664a",
 62712          "supplier": {},
 62713          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62714          "name": "liblzma5",
 62715          "version": "5.2.4-1ubuntu1",
 62716          "licenses": [
 62717            {
 62718              "license": {
 62719                "name": "Autoconf"
 62720              }
 62721            },
 62722            {
 62723              "license": {
 62724                "id": "GPL-2.0-only"
 62725              }
 62726            },
 62727            {
 62728              "license": {
 62729                "id": "GPL-2.0-or-later"
 62730              }
 62731            },
 62732            {
 62733              "license": {
 62734                "id": "GPL-3.0-only"
 62735              }
 62736            },
 62737            {
 62738              "license": {
 62739                "id": "LGPL-2.0-only"
 62740              }
 62741            },
 62742            {
 62743              "license": {
 62744                "id": "LGPL-2.1-only"
 62745              }
 62746            },
 62747            {
 62748              "license": {
 62749                "id": "LGPL-2.1-or-later"
 62750              }
 62751            },
 62752            {
 62753              "license": {
 62754                "name": "PD"
 62755              }
 62756            },
 62757            {
 62758              "license": {
 62759                "name": "PD-debian"
 62760              }
 62761            },
 62762            {
 62763              "license": {
 62764                "name": "config-h"
 62765              }
 62766            },
 62767            {
 62768              "license": {
 62769                "name": "noderivs"
 62770              }
 62771            },
 62772            {
 62773              "license": {
 62774                "name": "permissive-fsf"
 62775              }
 62776            },
 62777            {
 62778              "license": {
 62779                "name": "permissive-nowarranty"
 62780              }
 62781            },
 62782            {
 62783              "license": {
 62784                "name": "probably-PD"
 62785              }
 62786            }
 62787          ],
 62788          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
 62789          "purl": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04",
 62790          "swid": {
 62791            "attachment": {}
 62792          },
 62793          "pedigree": {},
 62794          "evidence": {},
 62795          "signature": {
 62796            "signature": {
 62797              "publicKey": {}
 62798            }
 62799          },
 62800          "modelCard": {
 62801            "modelParameters": {
 62802              "approach": {}
 62803            },
 62804            "quantitativeAnalysis": {
 62805              "graphics": {}
 62806            },
 62807            "considerations": {}
 62808          }
 62809        },
 62810        {
 62811          "type": "library",
 62812          "bom-ref": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=3b4f02792ccf99bb",
 62813          "supplier": {},
 62814          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62815          "name": "libmagic-mgc",
 62816          "version": "1:5.38-4",
 62817          "licenses": [
 62818            {
 62819              "license": {
 62820                "name": "BSD-2-Clause-alike"
 62821              }
 62822            },
 62823            {
 62824              "license": {
 62825                "id": "BSD-2-Clause"
 62826              }
 62827            },
 62828            {
 62829              "license": {
 62830                "name": "BSD-2-Clause-regents"
 62831              }
 62832            },
 62833            {
 62834              "license": {
 62835                "name": "MIT-Old-Style-with-legal-disclaimer-2"
 62836              }
 62837            },
 62838            {
 62839              "license": {
 62840                "name": "public-domain"
 62841              }
 62842            }
 62843          ],
 62844          "cpe": "cpe:2.3:a:libmagic-mgc:libmagic-mgc:1\\:5.38-4:*:*:*:*:*:*:*",
 62845          "purl": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
 62846          "swid": {
 62847            "attachment": {}
 62848          },
 62849          "pedigree": {},
 62850          "evidence": {},
 62851          "signature": {
 62852            "signature": {
 62853              "publicKey": {}
 62854            }
 62855          },
 62856          "modelCard": {
 62857            "modelParameters": {
 62858              "approach": {}
 62859            },
 62860            "quantitativeAnalysis": {
 62861              "graphics": {}
 62862            },
 62863            "considerations": {}
 62864          }
 62865        },
 62866        {
 62867          "type": "library",
 62868          "bom-ref": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=302b8497a938556",
 62869          "supplier": {},
 62870          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62871          "name": "libmagic1",
 62872          "version": "1:5.38-4",
 62873          "licenses": [
 62874            {
 62875              "license": {
 62876                "name": "BSD-2-Clause-alike"
 62877              }
 62878            },
 62879            {
 62880              "license": {
 62881                "id": "BSD-2-Clause"
 62882              }
 62883            },
 62884            {
 62885              "license": {
 62886                "name": "BSD-2-Clause-regents"
 62887              }
 62888            },
 62889            {
 62890              "license": {
 62891                "name": "MIT-Old-Style-with-legal-disclaimer-2"
 62892              }
 62893            },
 62894            {
 62895              "license": {
 62896                "name": "public-domain"
 62897              }
 62898            }
 62899          ],
 62900          "cpe": "cpe:2.3:a:libmagic1:libmagic1:1\\:5.38-4:*:*:*:*:*:*:*",
 62901          "purl": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
 62902          "swid": {
 62903            "attachment": {}
 62904          },
 62905          "pedigree": {},
 62906          "evidence": {},
 62907          "signature": {
 62908            "signature": {
 62909              "publicKey": {}
 62910            }
 62911          },
 62912          "modelCard": {
 62913            "modelParameters": {
 62914              "approach": {}
 62915            },
 62916            "quantitativeAnalysis": {
 62917              "graphics": {}
 62918            },
 62919            "considerations": {}
 62920          }
 62921        },
 62922        {
 62923          "type": "library",
 62924          "bom-ref": "pkg:deb/ubuntu/libmnl0@1.0.4-2?arch=amd64\u0026upstream=libmnl\u0026distro=ubuntu-20.04\u0026package-id=162cfe25074edf0d",
 62925          "supplier": {},
 62926          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62927          "name": "libmnl0",
 62928          "version": "1.0.4-2",
 62929          "licenses": [
 62930            {
 62931              "license": {
 62932                "id": "GPL-2.0-only"
 62933              }
 62934            },
 62935            {
 62936              "license": {
 62937                "id": "GPL-2.0-or-later"
 62938              }
 62939            },
 62940            {
 62941              "license": {
 62942                "id": "LGPL-2.1-only"
 62943              }
 62944            }
 62945          ],
 62946          "cpe": "cpe:2.3:a:libmnl0:libmnl0:1.0.4-2:*:*:*:*:*:*:*",
 62947          "purl": "pkg:deb/ubuntu/libmnl0@1.0.4-2?arch=amd64\u0026upstream=libmnl\u0026distro=ubuntu-20.04",
 62948          "swid": {
 62949            "attachment": {}
 62950          },
 62951          "pedigree": {},
 62952          "evidence": {},
 62953          "signature": {
 62954            "signature": {
 62955              "publicKey": {}
 62956            }
 62957          },
 62958          "modelCard": {
 62959            "modelParameters": {
 62960              "approach": {}
 62961            },
 62962            "quantitativeAnalysis": {
 62963              "graphics": {}
 62964            },
 62965            "considerations": {}
 62966          }
 62967        },
 62968        {
 62969          "type": "library",
 62970          "bom-ref": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=39446194385ebce5",
 62971          "supplier": {},
 62972          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 62973          "name": "libmount1",
 62974          "version": "2.34-0.1ubuntu9.1",
 62975          "licenses": [
 62976            {
 62977              "license": {
 62978                "id": "BSD-2-Clause"
 62979              }
 62980            },
 62981            {
 62982              "license": {
 62983                "id": "BSD-3-Clause"
 62984              }
 62985            },
 62986            {
 62987              "license": {
 62988                "id": "BSD-4-Clause"
 62989              }
 62990            },
 62991            {
 62992              "license": {
 62993                "id": "GPL-2.0-only"
 62994              }
 62995            },
 62996            {
 62997              "license": {
 62998                "id": "GPL-2.0-or-later"
 62999              }
 63000            },
 63001            {
 63002              "license": {
 63003                "id": "GPL-3.0-only"
 63004              }
 63005            },
 63006            {
 63007              "license": {
 63008                "id": "GPL-3.0-or-later"
 63009              }
 63010            },
 63011            {
 63012              "license": {
 63013                "name": "LGPL"
 63014              }
 63015            },
 63016            {
 63017              "license": {
 63018                "id": "LGPL-2.0-only"
 63019              }
 63020            },
 63021            {
 63022              "license": {
 63023                "id": "LGPL-2.0-or-later"
 63024              }
 63025            },
 63026            {
 63027              "license": {
 63028                "id": "LGPL-2.1-only"
 63029              }
 63030            },
 63031            {
 63032              "license": {
 63033                "id": "LGPL-2.1-or-later"
 63034              }
 63035            },
 63036            {
 63037              "license": {
 63038                "id": "LGPL-3.0-only"
 63039              }
 63040            },
 63041            {
 63042              "license": {
 63043                "id": "LGPL-3.0-or-later"
 63044              }
 63045            },
 63046            {
 63047              "license": {
 63048                "id": "MIT"
 63049              }
 63050            },
 63051            {
 63052              "license": {
 63053                "name": "public-domain"
 63054              }
 63055            }
 63056          ],
 63057          "cpe": "cpe:2.3:a:libmount1:libmount1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 63058          "purl": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 63059          "swid": {
 63060            "attachment": {}
 63061          },
 63062          "pedigree": {},
 63063          "evidence": {},
 63064          "signature": {
 63065            "signature": {
 63066              "publicKey": {}
 63067            }
 63068          },
 63069          "modelCard": {
 63070            "modelParameters": {
 63071              "approach": {}
 63072            },
 63073            "quantitativeAnalysis": {
 63074              "graphics": {}
 63075            },
 63076            "considerations": {}
 63077          }
 63078        },
 63079        {
 63080          "type": "library",
 63081          "bom-ref": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04\u0026package-id=b45a0d57576ce262",
 63082          "supplier": {},
 63083          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63084          "name": "libmpdec2",
 63085          "version": "2.4.2-3",
 63086          "licenses": [
 63087            {
 63088              "license": {
 63089                "name": "BSD"
 63090              }
 63091            },
 63092            {
 63093              "license": {
 63094                "id": "GPL-2.0-only"
 63095              }
 63096            },
 63097            {
 63098              "license": {
 63099                "id": "GPL-2.0-or-later"
 63100              }
 63101            }
 63102          ],
 63103          "cpe": "cpe:2.3:a:libmpdec2:libmpdec2:2.4.2-3:*:*:*:*:*:*:*",
 63104          "purl": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04",
 63105          "swid": {
 63106            "attachment": {}
 63107          },
 63108          "pedigree": {},
 63109          "evidence": {},
 63110          "signature": {
 63111            "signature": {
 63112              "publicKey": {}
 63113            }
 63114          },
 63115          "modelCard": {
 63116            "modelParameters": {
 63117              "approach": {}
 63118            },
 63119            "quantitativeAnalysis": {
 63120              "graphics": {}
 63121            },
 63122            "considerations": {}
 63123          }
 63124        },
 63125        {
 63126          "type": "library",
 63127          "bom-ref": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=ed8fb166163a75b8",
 63128          "supplier": {},
 63129          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63130          "name": "libncurses6",
 63131          "version": "6.2-0ubuntu2",
 63132          "cpe": "cpe:2.3:a:libncurses6:libncurses6:6.2-0ubuntu2:*:*:*:*:*:*:*",
 63133          "purl": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 63134          "swid": {
 63135            "attachment": {}
 63136          },
 63137          "pedigree": {},
 63138          "evidence": {},
 63139          "signature": {
 63140            "signature": {
 63141              "publicKey": {}
 63142            }
 63143          },
 63144          "modelCard": {
 63145            "modelParameters": {
 63146              "approach": {}
 63147            },
 63148            "quantitativeAnalysis": {
 63149              "graphics": {}
 63150            },
 63151            "considerations": {}
 63152          }
 63153        },
 63154        {
 63155          "type": "library",
 63156          "bom-ref": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=58525ddc073a008a",
 63157          "supplier": {},
 63158          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63159          "name": "libncursesw6",
 63160          "version": "6.2-0ubuntu2",
 63161          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.2-0ubuntu2:*:*:*:*:*:*:*",
 63162          "purl": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 63163          "swid": {
 63164            "attachment": {}
 63165          },
 63166          "pedigree": {},
 63167          "evidence": {},
 63168          "signature": {
 63169            "signature": {
 63170              "publicKey": {}
 63171            }
 63172          },
 63173          "modelCard": {
 63174            "modelParameters": {
 63175              "approach": {}
 63176            },
 63177            "quantitativeAnalysis": {
 63178              "graphics": {}
 63179            },
 63180            "considerations": {}
 63181          }
 63182        },
 63183        {
 63184          "type": "library",
 63185          "bom-ref": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3d185fbd6a7e56f",
 63186          "supplier": {},
 63187          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63188          "name": "libnettle7",
 63189          "version": "3.5.1+really3.5.1-2ubuntu0.2",
 63190          "licenses": [
 63191            {
 63192              "license": {
 63193                "name": "GAP"
 63194              }
 63195            },
 63196            {
 63197              "license": {
 63198                "name": "GPL"
 63199              }
 63200            },
 63201            {
 63202              "license": {
 63203                "id": "GPL-2.0-only"
 63204              }
 63205            },
 63206            {
 63207              "license": {
 63208                "id": "GPL-2.0-or-later"
 63209              }
 63210            },
 63211            {
 63212              "license": {
 63213                "name": "LGPL"
 63214              }
 63215            },
 63216            {
 63217              "license": {
 63218                "id": "LGPL-2.0-only"
 63219              }
 63220            },
 63221            {
 63222              "license": {
 63223                "id": "LGPL-2.0-or-later"
 63224              }
 63225            },
 63226            {
 63227              "license": {
 63228                "id": "LGPL-2.1-or-later"
 63229              }
 63230            },
 63231            {
 63232              "license": {
 63233                "name": "other"
 63234              }
 63235            },
 63236            {
 63237              "license": {
 63238                "name": "public-domain"
 63239              }
 63240            }
 63241          ],
 63242          "cpe": "cpe:2.3:a:libnettle7:libnettle7:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
 63243          "purl": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
 63244          "swid": {
 63245            "attachment": {}
 63246          },
 63247          "pedigree": {},
 63248          "evidence": {},
 63249          "signature": {
 63250            "signature": {
 63251              "publicKey": {}
 63252            }
 63253          },
 63254          "modelCard": {
 63255            "modelParameters": {
 63256              "approach": {}
 63257            },
 63258            "quantitativeAnalysis": {
 63259              "graphics": {}
 63260            },
 63261            "considerations": {}
 63262          }
 63263        },
 63264        {
 63265          "type": "library",
 63266          "bom-ref": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04\u0026package-id=71bd574c47c02b75",
 63267          "supplier": {},
 63268          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63269          "name": "libnfsidmap2",
 63270          "version": "0.25-5.1ubuntu1",
 63271          "cpe": "cpe:2.3:a:libnfsidmap2:libnfsidmap2:0.25-5.1ubuntu1:*:*:*:*:*:*:*",
 63272          "purl": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04",
 63273          "swid": {
 63274            "attachment": {}
 63275          },
 63276          "pedigree": {},
 63277          "evidence": {},
 63278          "signature": {
 63279            "signature": {
 63280              "publicKey": {}
 63281            }
 63282          },
 63283          "modelCard": {
 63284            "modelParameters": {
 63285              "approach": {}
 63286            },
 63287            "quantitativeAnalysis": {
 63288              "graphics": {}
 63289            },
 63290            "considerations": {}
 63291          }
 63292        },
 63293        {
 63294          "type": "library",
 63295          "bom-ref": "pkg:deb/ubuntu/libnghttp2-14@1.40.0-1build1?arch=amd64\u0026upstream=nghttp2\u0026distro=ubuntu-20.04\u0026package-id=c86604c1fa72dd96",
 63296          "supplier": {},
 63297          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63298          "name": "libnghttp2-14",
 63299          "version": "1.40.0-1build1",
 63300          "licenses": [
 63301            {
 63302              "license": {
 63303                "id": "BSD-2-Clause"
 63304              }
 63305            },
 63306            {
 63307              "license": {
 63308                "name": "Expat"
 63309              }
 63310            },
 63311            {
 63312              "license": {
 63313                "id": "GPL-3.0-only"
 63314              }
 63315            },
 63316            {
 63317              "license": {
 63318                "id": "GPL-3.0-or-later"
 63319              }
 63320            },
 63321            {
 63322              "license": {
 63323                "id": "MIT"
 63324              }
 63325            },
 63326            {
 63327              "license": {
 63328                "name": "SIL-OFL-1.1"
 63329              }
 63330            },
 63331            {
 63332              "license": {
 63333                "name": "all-permissive"
 63334              }
 63335            }
 63336          ],
 63337          "cpe": "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.40.0-1build1:*:*:*:*:*:*:*",
 63338          "purl": "pkg:deb/ubuntu/libnghttp2-14@1.40.0-1build1?arch=amd64\u0026upstream=nghttp2\u0026distro=ubuntu-20.04",
 63339          "swid": {
 63340            "attachment": {}
 63341          },
 63342          "pedigree": {},
 63343          "evidence": {},
 63344          "signature": {
 63345            "signature": {
 63346              "publicKey": {}
 63347            }
 63348          },
 63349          "modelCard": {
 63350            "modelParameters": {
 63351              "approach": {}
 63352            },
 63353            "quantitativeAnalysis": {
 63354              "graphics": {}
 63355            },
 63356            "considerations": {}
 63357          }
 63358        },
 63359        {
 63360          "type": "library",
 63361          "bom-ref": "pkg:deb/ubuntu/libnl-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04\u0026package-id=520a765636f2f20f",
 63362          "supplier": {},
 63363          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63364          "name": "libnl-3-200",
 63365          "version": "3.4.0-1",
 63366          "licenses": [
 63367            {
 63368              "license": {
 63369                "id": "GPL-2.0-only"
 63370              }
 63371            },
 63372            {
 63373              "license": {
 63374                "id": "LGPL-2.1-only"
 63375              }
 63376            }
 63377          ],
 63378          "cpe": "cpe:2.3:a:libnl-3-200:libnl-3-200:3.4.0-1:*:*:*:*:*:*:*",
 63379          "purl": "pkg:deb/ubuntu/libnl-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04",
 63380          "swid": {
 63381            "attachment": {}
 63382          },
 63383          "pedigree": {},
 63384          "evidence": {},
 63385          "signature": {
 63386            "signature": {
 63387              "publicKey": {}
 63388            }
 63389          },
 63390          "modelCard": {
 63391            "modelParameters": {
 63392              "approach": {}
 63393            },
 63394            "quantitativeAnalysis": {
 63395              "graphics": {}
 63396            },
 63397            "considerations": {}
 63398          }
 63399        },
 63400        {
 63401          "type": "library",
 63402          "bom-ref": "pkg:deb/ubuntu/libnl-route-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04\u0026package-id=1a1d9f0f1f34e88b",
 63403          "supplier": {},
 63404          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63405          "name": "libnl-route-3-200",
 63406          "version": "3.4.0-1",
 63407          "licenses": [
 63408            {
 63409              "license": {
 63410                "id": "GPL-2.0-only"
 63411              }
 63412            },
 63413            {
 63414              "license": {
 63415                "id": "LGPL-2.1-only"
 63416              }
 63417            }
 63418          ],
 63419          "cpe": "cpe:2.3:a:libnl-route-3-200:libnl-route-3-200:3.4.0-1:*:*:*:*:*:*:*",
 63420          "purl": "pkg:deb/ubuntu/libnl-route-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04",
 63421          "swid": {
 63422            "attachment": {}
 63423          },
 63424          "pedigree": {},
 63425          "evidence": {},
 63426          "signature": {
 63427            "signature": {
 63428              "publicKey": {}
 63429            }
 63430          },
 63431          "modelCard": {
 63432            "modelParameters": {
 63433              "approach": {}
 63434            },
 63435            "quantitativeAnalysis": {
 63436              "graphics": {}
 63437            },
 63438            "considerations": {}
 63439          }
 63440        },
 63441        {
 63442          "type": "library",
 63443          "bom-ref": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04\u0026package-id=9fc0ca46e6d21557",
 63444          "supplier": {},
 63445          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63446          "name": "libp11-kit0",
 63447          "version": "0.23.20-1ubuntu0.1",
 63448          "licenses": [
 63449            {
 63450              "license": {
 63451                "id": "BSD-3-Clause"
 63452              }
 63453            },
 63454            {
 63455              "license": {
 63456                "id": "ISC"
 63457              }
 63458            },
 63459            {
 63460              "license": {
 63461                "name": "ISC+IBM"
 63462              }
 63463            },
 63464            {
 63465              "license": {
 63466                "name": "permissive-like-automake-output"
 63467              }
 63468            },
 63469            {
 63470              "license": {
 63471                "name": "same-as-rest-of-p11kit"
 63472              }
 63473            }
 63474          ],
 63475          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.20-1ubuntu0.1:*:*:*:*:*:*:*",
 63476          "purl": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04",
 63477          "swid": {
 63478            "attachment": {}
 63479          },
 63480          "pedigree": {},
 63481          "evidence": {},
 63482          "signature": {
 63483            "signature": {
 63484              "publicKey": {}
 63485            }
 63486          },
 63487          "modelCard": {
 63488            "modelParameters": {
 63489              "approach": {}
 63490            },
 63491            "quantitativeAnalysis": {
 63492              "graphics": {}
 63493            },
 63494            "considerations": {}
 63495          }
 63496        },
 63497        {
 63498          "type": "library",
 63499          "bom-ref": "pkg:deb/ubuntu/libpam-cap@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04\u0026package-id=20db44acb7f94535",
 63500          "supplier": {},
 63501          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63502          "name": "libpam-cap",
 63503          "version": "1:2.32-1",
 63504          "licenses": [
 63505            {
 63506              "license": {
 63507                "id": "BSD-3-Clause"
 63508              }
 63509            },
 63510            {
 63511              "license": {
 63512                "id": "GPL-2.0-only"
 63513              }
 63514            },
 63515            {
 63516              "license": {
 63517                "id": "GPL-2.0-or-later"
 63518              }
 63519            }
 63520          ],
 63521          "cpe": "cpe:2.3:a:libpam-cap:libpam-cap:1\\:2.32-1:*:*:*:*:*:*:*",
 63522          "purl": "pkg:deb/ubuntu/libpam-cap@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04",
 63523          "swid": {
 63524            "attachment": {}
 63525          },
 63526          "pedigree": {},
 63527          "evidence": {},
 63528          "signature": {
 63529            "signature": {
 63530              "publicKey": {}
 63531            }
 63532          },
 63533          "modelCard": {
 63534            "modelParameters": {
 63535              "approach": {}
 63536            },
 63537            "quantitativeAnalysis": {
 63538              "graphics": {}
 63539            },
 63540            "considerations": {}
 63541          }
 63542        },
 63543        {
 63544          "type": "library",
 63545          "bom-ref": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=e7be6c0ad703fc9a",
 63546          "supplier": {},
 63547          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63548          "name": "libpam-modules",
 63549          "version": "1.3.1-5ubuntu4.2",
 63550          "licenses": [
 63551            {
 63552              "license": {
 63553                "name": "GPL"
 63554              }
 63555            }
 63556          ],
 63557          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
 63558          "purl": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
 63559          "swid": {
 63560            "attachment": {}
 63561          },
 63562          "pedigree": {},
 63563          "evidence": {},
 63564          "signature": {
 63565            "signature": {
 63566              "publicKey": {}
 63567            }
 63568          },
 63569          "modelCard": {
 63570            "modelParameters": {
 63571              "approach": {}
 63572            },
 63573            "quantitativeAnalysis": {
 63574              "graphics": {}
 63575            },
 63576            "considerations": {}
 63577          }
 63578        },
 63579        {
 63580          "type": "library",
 63581          "bom-ref": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=7ff667273975da27",
 63582          "supplier": {},
 63583          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63584          "name": "libpam-modules-bin",
 63585          "version": "1.3.1-5ubuntu4.2",
 63586          "licenses": [
 63587            {
 63588              "license": {
 63589                "name": "GPL"
 63590              }
 63591            }
 63592          ],
 63593          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
 63594          "purl": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
 63595          "swid": {
 63596            "attachment": {}
 63597          },
 63598          "pedigree": {},
 63599          "evidence": {},
 63600          "signature": {
 63601            "signature": {
 63602              "publicKey": {}
 63603            }
 63604          },
 63605          "modelCard": {
 63606            "modelParameters": {
 63607              "approach": {}
 63608            },
 63609            "quantitativeAnalysis": {
 63610              "graphics": {}
 63611            },
 63612            "considerations": {}
 63613          }
 63614        },
 63615        {
 63616          "type": "library",
 63617          "bom-ref": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.2?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=47a743e8128a9af6",
 63618          "supplier": {},
 63619          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63620          "name": "libpam-runtime",
 63621          "version": "1.3.1-5ubuntu4.2",
 63622          "licenses": [
 63623            {
 63624              "license": {
 63625                "name": "GPL"
 63626              }
 63627            }
 63628          ],
 63629          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
 63630          "purl": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.2?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04",
 63631          "swid": {
 63632            "attachment": {}
 63633          },
 63634          "pedigree": {},
 63635          "evidence": {},
 63636          "signature": {
 63637            "signature": {
 63638              "publicKey": {}
 63639            }
 63640          },
 63641          "modelCard": {
 63642            "modelParameters": {
 63643              "approach": {}
 63644            },
 63645            "quantitativeAnalysis": {
 63646              "graphics": {}
 63647            },
 63648            "considerations": {}
 63649          }
 63650        },
 63651        {
 63652          "type": "library",
 63653          "bom-ref": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=e57fbdd1e7d57983",
 63654          "supplier": {},
 63655          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63656          "name": "libpam0g",
 63657          "version": "1.3.1-5ubuntu4.2",
 63658          "licenses": [
 63659            {
 63660              "license": {
 63661                "name": "GPL"
 63662              }
 63663            }
 63664          ],
 63665          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
 63666          "purl": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
 63667          "swid": {
 63668            "attachment": {}
 63669          },
 63670          "pedigree": {},
 63671          "evidence": {},
 63672          "signature": {
 63673            "signature": {
 63674              "publicKey": {}
 63675            }
 63676          },
 63677          "modelCard": {
 63678            "modelParameters": {
 63679              "approach": {}
 63680            },
 63681            "quantitativeAnalysis": {
 63682              "graphics": {}
 63683            },
 63684            "considerations": {}
 63685          }
 63686        },
 63687        {
 63688          "type": "library",
 63689          "bom-ref": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04\u0026package-id=ec9eb70008ed8b14",
 63690          "supplier": {},
 63691          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63692          "name": "libpcre2-8-0",
 63693          "version": "10.34-7",
 63694          "cpe": "cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.34-7:*:*:*:*:*:*:*",
 63695          "purl": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04",
 63696          "swid": {
 63697            "attachment": {}
 63698          },
 63699          "pedigree": {},
 63700          "evidence": {},
 63701          "signature": {
 63702            "signature": {
 63703              "publicKey": {}
 63704            }
 63705          },
 63706          "modelCard": {
 63707            "modelParameters": {
 63708              "approach": {}
 63709            },
 63710            "quantitativeAnalysis": {
 63711              "graphics": {}
 63712            },
 63713            "considerations": {}
 63714          }
 63715        },
 63716        {
 63717          "type": "library",
 63718          "bom-ref": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04\u0026package-id=f2af8e66c60a624",
 63719          "supplier": {},
 63720          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63721          "name": "libpcre3",
 63722          "version": "2:8.39-12build1",
 63723          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-12build1:*:*:*:*:*:*:*",
 63724          "purl": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04",
 63725          "swid": {
 63726            "attachment": {}
 63727          },
 63728          "pedigree": {},
 63729          "evidence": {},
 63730          "signature": {
 63731            "signature": {
 63732              "publicKey": {}
 63733            }
 63734          },
 63735          "modelCard": {
 63736            "modelParameters": {
 63737              "approach": {}
 63738            },
 63739            "quantitativeAnalysis": {
 63740              "graphics": {}
 63741            },
 63742            "considerations": {}
 63743          }
 63744        },
 63745        {
 63746          "type": "library",
 63747          "bom-ref": "pkg:deb/ubuntu/libperl5.30@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=8748dda005dfdd96",
 63748          "supplier": {},
 63749          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63750          "name": "libperl5.30",
 63751          "version": "5.30.0-9ubuntu0.2",
 63752          "licenses": [
 63753            {
 63754              "license": {
 63755                "name": "Artistic"
 63756              }
 63757            },
 63758            {
 63759              "license": {
 63760                "id": "Artistic-2.0"
 63761              }
 63762            },
 63763            {
 63764              "license": {
 63765                "name": "Artistic-dist"
 63766              }
 63767            },
 63768            {
 63769              "license": {
 63770                "id": "BSD-3-Clause"
 63771              }
 63772            },
 63773            {
 63774              "license": {
 63775                "name": "BSD-3-clause-GENERIC"
 63776              }
 63777            },
 63778            {
 63779              "license": {
 63780                "name": "BSD-3-clause-with-weird-numbering"
 63781              }
 63782            },
 63783            {
 63784              "license": {
 63785                "name": "BSD-4-clause-POWERDOG"
 63786              }
 63787            },
 63788            {
 63789              "license": {
 63790                "name": "BZIP"
 63791              }
 63792            },
 63793            {
 63794              "license": {
 63795                "name": "DONT-CHANGE-THE-GPL"
 63796              }
 63797            },
 63798            {
 63799              "license": {
 63800                "name": "Expat"
 63801              }
 63802            },
 63803            {
 63804              "license": {
 63805                "id": "GPL-1.0-only"
 63806              }
 63807            },
 63808            {
 63809              "license": {
 63810                "id": "GPL-1.0-or-later"
 63811              }
 63812            },
 63813            {
 63814              "license": {
 63815                "id": "GPL-2.0-only"
 63816              }
 63817            },
 63818            {
 63819              "license": {
 63820                "id": "GPL-2.0-or-later"
 63821              }
 63822            },
 63823            {
 63824              "license": {
 63825                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 63826              }
 63827            },
 63828            {
 63829              "license": {
 63830                "name": "HSIEH-BSD"
 63831              }
 63832            },
 63833            {
 63834              "license": {
 63835                "name": "HSIEH-DERIVATIVE"
 63836              }
 63837            },
 63838            {
 63839              "license": {
 63840                "id": "LGPL-2.1-only"
 63841              }
 63842            },
 63843            {
 63844              "license": {
 63845                "name": "REGCOMP"
 63846              }
 63847            },
 63848            {
 63849              "license": {
 63850                "name": "REGCOMP,"
 63851              }
 63852            },
 63853            {
 63854              "license": {
 63855                "name": "RRA-KEEP-THIS-NOTICE"
 63856              }
 63857            },
 63858            {
 63859              "license": {
 63860                "name": "SDBM-PUBLIC-DOMAIN"
 63861              }
 63862            },
 63863            {
 63864              "license": {
 63865                "name": "TEXT-TABS"
 63866              }
 63867            },
 63868            {
 63869              "license": {
 63870                "name": "Unicode"
 63871              }
 63872            },
 63873            {
 63874              "license": {
 63875                "id": "Zlib"
 63876              }
 63877            }
 63878          ],
 63879          "cpe": "cpe:2.3:a:libperl5.30:libperl5.30:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
 63880          "purl": "pkg:deb/ubuntu/libperl5.30@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04",
 63881          "swid": {
 63882            "attachment": {}
 63883          },
 63884          "pedigree": {},
 63885          "evidence": {},
 63886          "signature": {
 63887            "signature": {
 63888              "publicKey": {}
 63889            }
 63890          },
 63891          "modelCard": {
 63892            "modelParameters": {
 63893              "approach": {}
 63894            },
 63895            "quantitativeAnalysis": {
 63896              "graphics": {}
 63897            },
 63898            "considerations": {}
 63899          }
 63900        },
 63901        {
 63902          "type": "library",
 63903          "bom-ref": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.2?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04\u0026package-id=1444db6c35de79c6",
 63904          "supplier": {},
 63905          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63906          "name": "libprocps8",
 63907          "version": "2:3.3.16-1ubuntu2.2",
 63908          "licenses": [
 63909            {
 63910              "license": {
 63911                "id": "GPL-2.0-only"
 63912              }
 63913            },
 63914            {
 63915              "license": {
 63916                "id": "GPL-2.0-or-later"
 63917              }
 63918            },
 63919            {
 63920              "license": {
 63921                "id": "LGPL-2.0-only"
 63922              }
 63923            },
 63924            {
 63925              "license": {
 63926                "id": "LGPL-2.0-or-later"
 63927              }
 63928            },
 63929            {
 63930              "license": {
 63931                "id": "LGPL-2.1-only"
 63932              }
 63933            },
 63934            {
 63935              "license": {
 63936                "id": "LGPL-2.1-or-later"
 63937              }
 63938            }
 63939          ],
 63940          "cpe": "cpe:2.3:a:libprocps8:libprocps8:2\\:3.3.16-1ubuntu2.2:*:*:*:*:*:*:*",
 63941          "purl": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.2?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04",
 63942          "swid": {
 63943            "attachment": {}
 63944          },
 63945          "pedigree": {},
 63946          "evidence": {},
 63947          "signature": {
 63948            "signature": {
 63949              "publicKey": {}
 63950            }
 63951          },
 63952          "modelCard": {
 63953            "modelParameters": {
 63954              "approach": {}
 63955            },
 63956            "quantitativeAnalysis": {
 63957              "graphics": {}
 63958            },
 63959            "considerations": {}
 63960          }
 63961        },
 63962        {
 63963          "type": "library",
 63964          "bom-ref": "pkg:deb/ubuntu/libpsl5@0.21.0-1ubuntu1?arch=amd64\u0026upstream=libpsl\u0026distro=ubuntu-20.04\u0026package-id=e77e76f35a3ad192",
 63965          "supplier": {},
 63966          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 63967          "name": "libpsl5",
 63968          "version": "0.21.0-1ubuntu1",
 63969          "licenses": [
 63970            {
 63971              "license": {
 63972                "name": "Chromium"
 63973              }
 63974            },
 63975            {
 63976              "license": {
 63977                "id": "MIT"
 63978              }
 63979            }
 63980          ],
 63981          "cpe": "cpe:2.3:a:libpsl5:libpsl5:0.21.0-1ubuntu1:*:*:*:*:*:*:*",
 63982          "purl": "pkg:deb/ubuntu/libpsl5@0.21.0-1ubuntu1?arch=amd64\u0026upstream=libpsl\u0026distro=ubuntu-20.04",
 63983          "swid": {
 63984            "attachment": {}
 63985          },
 63986          "pedigree": {},
 63987          "evidence": {},
 63988          "signature": {
 63989            "signature": {
 63990              "publicKey": {}
 63991            }
 63992          },
 63993          "modelCard": {
 63994            "modelParameters": {
 63995              "approach": {}
 63996            },
 63997            "quantitativeAnalysis": {
 63998              "graphics": {}
 63999            },
 64000            "considerations": {}
 64001          }
 64002        },
 64003        {
 64004          "type": "library",
 64005          "bom-ref": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=b40e3316416bbdaf",
 64006          "supplier": {},
 64007          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64008          "name": "libpython3-stdlib",
 64009          "version": "3.8.2-0ubuntu2",
 64010          "cpe": "cpe:2.3:a:libpython3-stdlib:libpython3-stdlib:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
 64011          "purl": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
 64012          "swid": {
 64013            "attachment": {}
 64014          },
 64015          "pedigree": {},
 64016          "evidence": {},
 64017          "signature": {
 64018            "signature": {
 64019              "publicKey": {}
 64020            }
 64021          },
 64022          "modelCard": {
 64023            "modelParameters": {
 64024              "approach": {}
 64025            },
 64026            "quantitativeAnalysis": {
 64027              "graphics": {}
 64028            },
 64029            "considerations": {}
 64030          }
 64031        },
 64032        {
 64033          "type": "library",
 64034          "bom-ref": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=fb58dad98da64e3b",
 64035          "supplier": {},
 64036          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64037          "name": "libpython3.8-minimal",
 64038          "version": "3.8.10-0ubuntu1~20.04",
 64039          "licenses": [
 64040            {
 64041              "license": {
 64042                "name": "By"
 64043              }
 64044            },
 64045            {
 64046              "license": {
 64047                "id": "GPL-2.0-only"
 64048              }
 64049            },
 64050            {
 64051              "license": {
 64052                "name": "Permission"
 64053              }
 64054            },
 64055            {
 64056              "license": {
 64057                "name": "Redistribution"
 64058              }
 64059            },
 64060            {
 64061              "license": {
 64062                "name": "This"
 64063              }
 64064            }
 64065          ],
 64066          "cpe": "cpe:2.3:a:libpython3.8-minimal:libpython3.8-minimal:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
 64067          "purl": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 64068          "swid": {
 64069            "attachment": {}
 64070          },
 64071          "pedigree": {},
 64072          "evidence": {},
 64073          "signature": {
 64074            "signature": {
 64075              "publicKey": {}
 64076            }
 64077          },
 64078          "modelCard": {
 64079            "modelParameters": {
 64080              "approach": {}
 64081            },
 64082            "quantitativeAnalysis": {
 64083              "graphics": {}
 64084            },
 64085            "considerations": {}
 64086          }
 64087        },
 64088        {
 64089          "type": "library",
 64090          "bom-ref": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=54e48e611df3b41d",
 64091          "supplier": {},
 64092          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64093          "name": "libpython3.8-stdlib",
 64094          "version": "3.8.10-0ubuntu1~20.04",
 64095          "licenses": [
 64096            {
 64097              "license": {
 64098                "name": "By"
 64099              }
 64100            },
 64101            {
 64102              "license": {
 64103                "id": "GPL-2.0-only"
 64104              }
 64105            },
 64106            {
 64107              "license": {
 64108                "name": "Permission"
 64109              }
 64110            },
 64111            {
 64112              "license": {
 64113                "name": "Redistribution"
 64114              }
 64115            },
 64116            {
 64117              "license": {
 64118                "name": "This"
 64119              }
 64120            }
 64121          ],
 64122          "cpe": "cpe:2.3:a:libpython3.8-stdlib:libpython3.8-stdlib:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
 64123          "purl": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 64124          "swid": {
 64125            "attachment": {}
 64126          },
 64127          "pedigree": {},
 64128          "evidence": {},
 64129          "signature": {
 64130            "signature": {
 64131              "publicKey": {}
 64132            }
 64133          },
 64134          "modelCard": {
 64135            "modelParameters": {
 64136              "approach": {}
 64137            },
 64138            "quantitativeAnalysis": {
 64139              "graphics": {}
 64140            },
 64141            "considerations": {}
 64142          }
 64143        },
 64144        {
 64145          "type": "library",
 64146          "bom-ref": "pkg:deb/ubuntu/librados2@15.2.13-0ubuntu0.20.04.2?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04\u0026package-id=d33d75bf7d793b3a",
 64147          "supplier": {},
 64148          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64149          "name": "librados2",
 64150          "version": "15.2.13-0ubuntu0.20.04.2",
 64151          "licenses": [
 64152            {
 64153              "license": {
 64154                "id": "APSL-2.0"
 64155              }
 64156            },
 64157            {
 64158              "license": {
 64159                "id": "Apache-2.0"
 64160              }
 64161            },
 64162            {
 64163              "license": {
 64164                "name": "BSD"
 64165              }
 64166            },
 64167            {
 64168              "license": {
 64169                "id": "BSD-2-Clause"
 64170              }
 64171            },
 64172            {
 64173              "license": {
 64174                "id": "BSD-3-Clause"
 64175              }
 64176            },
 64177            {
 64178              "license": {
 64179                "name": "Boost"
 64180              }
 64181            },
 64182            {
 64183              "license": {
 64184                "name": "Boost-Software-License-1.0"
 64185              }
 64186            },
 64187            {
 64188              "license": {
 64189                "id": "CC-BY-SA-3.0"
 64190              }
 64191            },
 64192            {
 64193              "license": {
 64194                "name": "Creative"
 64195              }
 64196            },
 64197            {
 64198              "license": {
 64199                "name": "Expat"
 64200              }
 64201            },
 64202            {
 64203              "license": {
 64204                "id": "GPL-2.0-only"
 64205              }
 64206            },
 64207            {
 64208              "license": {
 64209                "id": "GPL-2.0-or-later"
 64210              }
 64211            },
 64212            {
 64213              "license": {
 64214                "id": "GPL-3.0-only"
 64215              }
 64216            },
 64217            {
 64218              "license": {
 64219                "name": "GPL-3/OpenSSL"
 64220              }
 64221            },
 64222            {
 64223              "license": {
 64224                "id": "GPL-2.0-only"
 64225              }
 64226            },
 64227            {
 64228              "license": {
 64229                "id": "GPL-3.0-only"
 64230              }
 64231            },
 64232            {
 64233              "license": {
 64234                "id": "LGPL-2.0-only"
 64235              }
 64236            },
 64237            {
 64238              "license": {
 64239                "id": "LGPL-2.0-or-later"
 64240              }
 64241            },
 64242            {
 64243              "license": {
 64244                "id": "LGPL-2.1-only"
 64245              }
 64246            },
 64247            {
 64248              "license": {
 64249                "id": "LGPL-2.1-or-later"
 64250              }
 64251            },
 64252            {
 64253              "license": {
 64254                "id": "LGPL-2.0-only"
 64255              }
 64256            },
 64257            {
 64258              "license": {
 64259                "id": "LGPL-2.1-only"
 64260              }
 64261            },
 64262            {
 64263              "license": {
 64264                "id": "MIT"
 64265              }
 64266            },
 64267            {
 64268              "license": {
 64269                "name": "Public"
 64270              }
 64271            },
 64272            {
 64273              "license": {
 64274                "name": "public-domain"
 64275              }
 64276            }
 64277          ],
 64278          "cpe": "cpe:2.3:a:librados2:librados2:15.2.13-0ubuntu0.20.04.2:*:*:*:*:*:*:*",
 64279          "purl": "pkg:deb/ubuntu/librados2@15.2.13-0ubuntu0.20.04.2?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04",
 64280          "swid": {
 64281            "attachment": {}
 64282          },
 64283          "pedigree": {},
 64284          "evidence": {},
 64285          "signature": {
 64286            "signature": {
 64287              "publicKey": {}
 64288            }
 64289          },
 64290          "modelCard": {
 64291            "modelParameters": {
 64292              "approach": {}
 64293            },
 64294            "quantitativeAnalysis": {
 64295              "graphics": {}
 64296            },
 64297            "considerations": {}
 64298          }
 64299        },
 64300        {
 64301          "type": "library",
 64302          "bom-ref": "pkg:deb/ubuntu/librbd1@15.2.13-0ubuntu0.20.04.2?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04\u0026package-id=db5742e3f45350c8",
 64303          "supplier": {},
 64304          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64305          "name": "librbd1",
 64306          "version": "15.2.13-0ubuntu0.20.04.2",
 64307          "licenses": [
 64308            {
 64309              "license": {
 64310                "id": "APSL-2.0"
 64311              }
 64312            },
 64313            {
 64314              "license": {
 64315                "id": "Apache-2.0"
 64316              }
 64317            },
 64318            {
 64319              "license": {
 64320                "name": "BSD"
 64321              }
 64322            },
 64323            {
 64324              "license": {
 64325                "id": "BSD-2-Clause"
 64326              }
 64327            },
 64328            {
 64329              "license": {
 64330                "id": "BSD-3-Clause"
 64331              }
 64332            },
 64333            {
 64334              "license": {
 64335                "name": "Boost"
 64336              }
 64337            },
 64338            {
 64339              "license": {
 64340                "name": "Boost-Software-License-1.0"
 64341              }
 64342            },
 64343            {
 64344              "license": {
 64345                "id": "CC-BY-SA-3.0"
 64346              }
 64347            },
 64348            {
 64349              "license": {
 64350                "name": "Creative"
 64351              }
 64352            },
 64353            {
 64354              "license": {
 64355                "name": "Expat"
 64356              }
 64357            },
 64358            {
 64359              "license": {
 64360                "id": "GPL-2.0-only"
 64361              }
 64362            },
 64363            {
 64364              "license": {
 64365                "id": "GPL-2.0-or-later"
 64366              }
 64367            },
 64368            {
 64369              "license": {
 64370                "id": "GPL-3.0-only"
 64371              }
 64372            },
 64373            {
 64374              "license": {
 64375                "name": "GPL-3/OpenSSL"
 64376              }
 64377            },
 64378            {
 64379              "license": {
 64380                "id": "GPL-2.0-only"
 64381              }
 64382            },
 64383            {
 64384              "license": {
 64385                "id": "GPL-3.0-only"
 64386              }
 64387            },
 64388            {
 64389              "license": {
 64390                "id": "LGPL-2.0-only"
 64391              }
 64392            },
 64393            {
 64394              "license": {
 64395                "id": "LGPL-2.0-or-later"
 64396              }
 64397            },
 64398            {
 64399              "license": {
 64400                "id": "LGPL-2.1-only"
 64401              }
 64402            },
 64403            {
 64404              "license": {
 64405                "id": "LGPL-2.1-or-later"
 64406              }
 64407            },
 64408            {
 64409              "license": {
 64410                "id": "LGPL-2.0-only"
 64411              }
 64412            },
 64413            {
 64414              "license": {
 64415                "id": "LGPL-2.1-only"
 64416              }
 64417            },
 64418            {
 64419              "license": {
 64420                "id": "MIT"
 64421              }
 64422            },
 64423            {
 64424              "license": {
 64425                "name": "Public"
 64426              }
 64427            },
 64428            {
 64429              "license": {
 64430                "name": "public-domain"
 64431              }
 64432            }
 64433          ],
 64434          "cpe": "cpe:2.3:a:librbd1:librbd1:15.2.13-0ubuntu0.20.04.2:*:*:*:*:*:*:*",
 64435          "purl": "pkg:deb/ubuntu/librbd1@15.2.13-0ubuntu0.20.04.2?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04",
 64436          "swid": {
 64437            "attachment": {}
 64438          },
 64439          "pedigree": {},
 64440          "evidence": {},
 64441          "signature": {
 64442            "signature": {
 64443              "publicKey": {}
 64444            }
 64445          },
 64446          "modelCard": {
 64447            "modelParameters": {
 64448              "approach": {}
 64449            },
 64450            "quantitativeAnalysis": {
 64451              "graphics": {}
 64452            },
 64453            "considerations": {}
 64454          }
 64455        },
 64456        {
 64457          "type": "library",
 64458          "bom-ref": "pkg:deb/ubuntu/librdmacm1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04\u0026package-id=ba8ceed5ec4f0c95",
 64459          "supplier": {},
 64460          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64461          "name": "librdmacm1",
 64462          "version": "28.0-1ubuntu1",
 64463          "licenses": [
 64464            {
 64465              "license": {
 64466                "id": "BSD-2-Clause"
 64467              }
 64468            },
 64469            {
 64470              "license": {
 64471                "id": "BSD-3-Clause"
 64472              }
 64473            },
 64474            {
 64475              "license": {
 64476                "name": "BSD-MIT"
 64477              }
 64478            },
 64479            {
 64480              "license": {
 64481                "name": "CC0"
 64482              }
 64483            },
 64484            {
 64485              "license": {
 64486                "id": "CPL-1.0"
 64487              }
 64488            },
 64489            {
 64490              "license": {
 64491                "id": "GPL-2.0-only"
 64492              }
 64493            },
 64494            {
 64495              "license": {
 64496                "id": "GPL-2.0-or-later"
 64497              }
 64498            },
 64499            {
 64500              "license": {
 64501                "id": "MIT"
 64502              }
 64503            }
 64504          ],
 64505          "cpe": "cpe:2.3:a:librdmacm1:librdmacm1:28.0-1ubuntu1:*:*:*:*:*:*:*",
 64506          "purl": "pkg:deb/ubuntu/librdmacm1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04",
 64507          "swid": {
 64508            "attachment": {}
 64509          },
 64510          "pedigree": {},
 64511          "evidence": {},
 64512          "signature": {
 64513            "signature": {
 64514              "publicKey": {}
 64515            }
 64516          },
 64517          "modelCard": {
 64518            "modelParameters": {
 64519              "approach": {}
 64520            },
 64521            "quantitativeAnalysis": {
 64522              "graphics": {}
 64523            },
 64524            "considerations": {}
 64525          }
 64526        },
 64527        {
 64528          "type": "library",
 64529          "bom-ref": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=67b876656fcd9e68",
 64530          "supplier": {},
 64531          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64532          "name": "libreadline8",
 64533          "version": "8.0-4",
 64534          "licenses": [
 64535            {
 64536              "license": {
 64537                "name": "GFDL"
 64538              }
 64539            },
 64540            {
 64541              "license": {
 64542                "id": "GPL-3.0-only"
 64543              }
 64544            }
 64545          ],
 64546          "cpe": "cpe:2.3:a:libreadline8:libreadline8:8.0-4:*:*:*:*:*:*:*",
 64547          "purl": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04",
 64548          "swid": {
 64549            "attachment": {}
 64550          },
 64551          "pedigree": {},
 64552          "evidence": {},
 64553          "signature": {
 64554            "signature": {
 64555              "publicKey": {}
 64556            }
 64557          },
 64558          "modelCard": {
 64559            "modelParameters": {
 64560              "approach": {}
 64561            },
 64562            "quantitativeAnalysis": {
 64563              "graphics": {}
 64564            },
 64565            "considerations": {}
 64566          }
 64567        },
 64568        {
 64569          "type": "library",
 64570          "bom-ref": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=68e35bc456818613",
 64571          "supplier": {},
 64572          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64573          "name": "libroken18-heimdal",
 64574          "version": "7.7.0+dfsg-1ubuntu1",
 64575          "licenses": [
 64576            {
 64577              "license": {
 64578                "id": "BSD-3-Clause"
 64579              }
 64580            },
 64581            {
 64582              "license": {
 64583                "id": "GPL-2.0-only"
 64584              }
 64585            },
 64586            {
 64587              "license": {
 64588                "id": "GPL-2.0-or-later"
 64589              }
 64590            },
 64591            {
 64592              "license": {
 64593                "name": "custom"
 64594              }
 64595            }
 64596          ],
 64597          "cpe": "cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 64598          "purl": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 64599          "swid": {
 64600            "attachment": {}
 64601          },
 64602          "pedigree": {},
 64603          "evidence": {},
 64604          "signature": {
 64605            "signature": {
 64606              "publicKey": {}
 64607            }
 64608          },
 64609          "modelCard": {
 64610            "modelParameters": {
 64611              "approach": {}
 64612            },
 64613            "quantitativeAnalysis": {
 64614              "graphics": {}
 64615            },
 64616            "considerations": {}
 64617          }
 64618        },
 64619        {
 64620          "type": "library",
 64621          "bom-ref": "pkg:deb/ubuntu/librtmp1@2.4+20151223.gitfa8646d.1-2build1?arch=amd64\u0026upstream=rtmpdump\u0026distro=ubuntu-20.04\u0026package-id=ede637f87a4bfd7b",
 64622          "supplier": {},
 64623          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64624          "name": "librtmp1",
 64625          "version": "2.4+20151223.gitfa8646d.1-2build1",
 64626          "licenses": [
 64627            {
 64628              "license": {
 64629                "id": "GPL-2.0-only"
 64630              }
 64631            },
 64632            {
 64633              "license": {
 64634                "id": "LGPL-2.1-only"
 64635              }
 64636            }
 64637          ],
 64638          "cpe": "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20151223.gitfa8646d.1-2build1:*:*:*:*:*:*:*",
 64639          "purl": "pkg:deb/ubuntu/librtmp1@2.4+20151223.gitfa8646d.1-2build1?arch=amd64\u0026upstream=rtmpdump\u0026distro=ubuntu-20.04",
 64640          "swid": {
 64641            "attachment": {}
 64642          },
 64643          "pedigree": {},
 64644          "evidence": {},
 64645          "signature": {
 64646            "signature": {
 64647              "publicKey": {}
 64648            }
 64649          },
 64650          "modelCard": {
 64651            "modelParameters": {
 64652              "approach": {}
 64653            },
 64654            "quantitativeAnalysis": {
 64655              "graphics": {}
 64656            },
 64657            "considerations": {}
 64658          }
 64659        },
 64660        {
 64661          "type": "library",
 64662          "bom-ref": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=374396d82667544d",
 64663          "supplier": {},
 64664          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64665          "name": "libsasl2-2",
 64666          "version": "2.1.27+dfsg-2",
 64667          "licenses": [
 64668            {
 64669              "license": {
 64670                "id": "BSD-4-Clause"
 64671              }
 64672            },
 64673            {
 64674              "license": {
 64675                "id": "GPL-3.0-only"
 64676              }
 64677            },
 64678            {
 64679              "license": {
 64680                "id": "GPL-3.0-or-later"
 64681              }
 64682            }
 64683          ],
 64684          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
 64685          "purl": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
 64686          "swid": {
 64687            "attachment": {}
 64688          },
 64689          "pedigree": {},
 64690          "evidence": {},
 64691          "signature": {
 64692            "signature": {
 64693              "publicKey": {}
 64694            }
 64695          },
 64696          "modelCard": {
 64697            "modelParameters": {
 64698              "approach": {}
 64699            },
 64700            "quantitativeAnalysis": {
 64701              "graphics": {}
 64702            },
 64703            "considerations": {}
 64704          }
 64705        },
 64706        {
 64707          "type": "library",
 64708          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=fb8d278d10c4a3cf",
 64709          "supplier": {},
 64710          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64711          "name": "libsasl2-modules",
 64712          "version": "2.1.27+dfsg-2",
 64713          "licenses": [
 64714            {
 64715              "license": {
 64716                "id": "BSD-4-Clause"
 64717              }
 64718            },
 64719            {
 64720              "license": {
 64721                "id": "GPL-3.0-only"
 64722              }
 64723            },
 64724            {
 64725              "license": {
 64726                "id": "GPL-3.0-or-later"
 64727              }
 64728            }
 64729          ],
 64730          "cpe": "cpe:2.3:a:libsasl2-modules:libsasl2-modules:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
 64731          "purl": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
 64732          "swid": {
 64733            "attachment": {}
 64734          },
 64735          "pedigree": {},
 64736          "evidence": {},
 64737          "signature": {
 64738            "signature": {
 64739              "publicKey": {}
 64740            }
 64741          },
 64742          "modelCard": {
 64743            "modelParameters": {
 64744              "approach": {}
 64745            },
 64746            "quantitativeAnalysis": {
 64747              "graphics": {}
 64748            },
 64749            "considerations": {}
 64750          }
 64751        },
 64752        {
 64753          "type": "library",
 64754          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=63c3c50d36ec1d13",
 64755          "supplier": {},
 64756          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64757          "name": "libsasl2-modules-db",
 64758          "version": "2.1.27+dfsg-2",
 64759          "licenses": [
 64760            {
 64761              "license": {
 64762                "id": "BSD-4-Clause"
 64763              }
 64764            },
 64765            {
 64766              "license": {
 64767                "id": "GPL-3.0-only"
 64768              }
 64769            },
 64770            {
 64771              "license": {
 64772                "id": "GPL-3.0-or-later"
 64773              }
 64774            }
 64775          ],
 64776          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
 64777          "purl": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
 64778          "swid": {
 64779            "attachment": {}
 64780          },
 64781          "pedigree": {},
 64782          "evidence": {},
 64783          "signature": {
 64784            "signature": {
 64785              "publicKey": {}
 64786            }
 64787          },
 64788          "modelCard": {
 64789            "modelParameters": {
 64790              "approach": {}
 64791            },
 64792            "quantitativeAnalysis": {
 64793              "graphics": {}
 64794            },
 64795            "considerations": {}
 64796          }
 64797        },
 64798        {
 64799          "type": "library",
 64800          "bom-ref": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04\u0026package-id=b2fd79b9c242e8e8",
 64801          "supplier": {},
 64802          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64803          "name": "libseccomp2",
 64804          "version": "2.5.1-1ubuntu1~20.04.1",
 64805          "licenses": [
 64806            {
 64807              "license": {
 64808                "id": "LGPL-2.1-only"
 64809              }
 64810            }
 64811          ],
 64812          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.5.1-1ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
 64813          "purl": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04",
 64814          "swid": {
 64815            "attachment": {}
 64816          },
 64817          "pedigree": {},
 64818          "evidence": {},
 64819          "signature": {
 64820            "signature": {
 64821              "publicKey": {}
 64822            }
 64823          },
 64824          "modelCard": {
 64825            "modelParameters": {
 64826              "approach": {}
 64827            },
 64828            "quantitativeAnalysis": {
 64829              "graphics": {}
 64830            },
 64831            "considerations": {}
 64832          }
 64833        },
 64834        {
 64835          "type": "library",
 64836          "bom-ref": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04\u0026package-id=e5d4ae16ac79b901",
 64837          "supplier": {},
 64838          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64839          "name": "libselinux1",
 64840          "version": "3.0-1build2",
 64841          "licenses": [
 64842            {
 64843              "license": {
 64844                "id": "GPL-2.0-only"
 64845              }
 64846            },
 64847            {
 64848              "license": {
 64849                "id": "LGPL-2.1-only"
 64850              }
 64851            }
 64852          ],
 64853          "cpe": "cpe:2.3:a:libselinux1:libselinux1:3.0-1build2:*:*:*:*:*:*:*",
 64854          "purl": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04",
 64855          "swid": {
 64856            "attachment": {}
 64857          },
 64858          "pedigree": {},
 64859          "evidence": {},
 64860          "signature": {
 64861            "signature": {
 64862              "publicKey": {}
 64863            }
 64864          },
 64865          "modelCard": {
 64866            "modelParameters": {
 64867              "approach": {}
 64868            },
 64869            "quantitativeAnalysis": {
 64870              "graphics": {}
 64871            },
 64872            "considerations": {}
 64873          }
 64874        },
 64875        {
 64876          "type": "library",
 64877          "bom-ref": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=4c6cd9f68ce53262",
 64878          "supplier": {},
 64879          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64880          "name": "libsemanage-common",
 64881          "version": "3.0-1build2",
 64882          "licenses": [
 64883            {
 64884              "license": {
 64885                "name": "GPL"
 64886              }
 64887            },
 64888            {
 64889              "license": {
 64890                "name": "LGPL"
 64891              }
 64892            }
 64893          ],
 64894          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:3.0-1build2:*:*:*:*:*:*:*",
 64895          "purl": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
 64896          "swid": {
 64897            "attachment": {}
 64898          },
 64899          "pedigree": {},
 64900          "evidence": {},
 64901          "signature": {
 64902            "signature": {
 64903              "publicKey": {}
 64904            }
 64905          },
 64906          "modelCard": {
 64907            "modelParameters": {
 64908              "approach": {}
 64909            },
 64910            "quantitativeAnalysis": {
 64911              "graphics": {}
 64912            },
 64913            "considerations": {}
 64914          }
 64915        },
 64916        {
 64917          "type": "library",
 64918          "bom-ref": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=963297f19b339026",
 64919          "supplier": {},
 64920          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64921          "name": "libsemanage1",
 64922          "version": "3.0-1build2",
 64923          "licenses": [
 64924            {
 64925              "license": {
 64926                "name": "GPL"
 64927              }
 64928            },
 64929            {
 64930              "license": {
 64931                "name": "LGPL"
 64932              }
 64933            }
 64934          ],
 64935          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:3.0-1build2:*:*:*:*:*:*:*",
 64936          "purl": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
 64937          "swid": {
 64938            "attachment": {}
 64939          },
 64940          "pedigree": {},
 64941          "evidence": {},
 64942          "signature": {
 64943            "signature": {
 64944              "publicKey": {}
 64945            }
 64946          },
 64947          "modelCard": {
 64948            "modelParameters": {
 64949              "approach": {}
 64950            },
 64951            "quantitativeAnalysis": {
 64952              "graphics": {}
 64953            },
 64954            "considerations": {}
 64955          }
 64956        },
 64957        {
 64958          "type": "library",
 64959          "bom-ref": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04\u0026package-id=991afdd7bf17200c",
 64960          "supplier": {},
 64961          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 64962          "name": "libsepol1",
 64963          "version": "3.0-1",
 64964          "licenses": [
 64965            {
 64966              "license": {
 64967                "name": "GPL"
 64968              }
 64969            },
 64970            {
 64971              "license": {
 64972                "name": "LGPL"
 64973              }
 64974            }
 64975          ],
 64976          "cpe": "cpe:2.3:a:libsepol1:libsepol1:3.0-1:*:*:*:*:*:*:*",
 64977          "purl": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04",
 64978          "swid": {
 64979            "attachment": {}
 64980          },
 64981          "pedigree": {},
 64982          "evidence": {},
 64983          "signature": {
 64984            "signature": {
 64985              "publicKey": {}
 64986            }
 64987          },
 64988          "modelCard": {
 64989            "modelParameters": {
 64990              "approach": {}
 64991            },
 64992            "quantitativeAnalysis": {
 64993              "graphics": {}
 64994            },
 64995            "considerations": {}
 64996          }
 64997        },
 64998        {
 64999          "type": "library",
 65000          "bom-ref": "pkg:deb/ubuntu/libsgutils2-2@1.44-1ubuntu2?arch=amd64\u0026upstream=sg3-utils\u0026distro=ubuntu-20.04\u0026package-id=5eee3420d656cf76",
 65001          "supplier": {},
 65002          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65003          "name": "libsgutils2-2",
 65004          "version": "1.44-1ubuntu2",
 65005          "licenses": [
 65006            {
 65007              "license": {
 65008                "name": "GPL"
 65009              }
 65010            }
 65011          ],
 65012          "cpe": "cpe:2.3:a:libsgutils2-2:libsgutils2-2:1.44-1ubuntu2:*:*:*:*:*:*:*",
 65013          "purl": "pkg:deb/ubuntu/libsgutils2-2@1.44-1ubuntu2?arch=amd64\u0026upstream=sg3-utils\u0026distro=ubuntu-20.04",
 65014          "swid": {
 65015            "attachment": {}
 65016          },
 65017          "pedigree": {},
 65018          "evidence": {},
 65019          "signature": {
 65020            "signature": {
 65021              "publicKey": {}
 65022            }
 65023          },
 65024          "modelCard": {
 65025            "modelParameters": {
 65026              "approach": {}
 65027            },
 65028            "quantitativeAnalysis": {
 65029              "graphics": {}
 65030            },
 65031            "considerations": {}
 65032          }
 65033        },
 65034        {
 65035          "type": "library",
 65036          "bom-ref": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=b47d3a935260c518",
 65037          "supplier": {},
 65038          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65039          "name": "libsmartcols1",
 65040          "version": "2.34-0.1ubuntu9.1",
 65041          "licenses": [
 65042            {
 65043              "license": {
 65044                "id": "BSD-2-Clause"
 65045              }
 65046            },
 65047            {
 65048              "license": {
 65049                "id": "BSD-3-Clause"
 65050              }
 65051            },
 65052            {
 65053              "license": {
 65054                "id": "BSD-4-Clause"
 65055              }
 65056            },
 65057            {
 65058              "license": {
 65059                "id": "GPL-2.0-only"
 65060              }
 65061            },
 65062            {
 65063              "license": {
 65064                "id": "GPL-2.0-or-later"
 65065              }
 65066            },
 65067            {
 65068              "license": {
 65069                "id": "GPL-3.0-only"
 65070              }
 65071            },
 65072            {
 65073              "license": {
 65074                "id": "GPL-3.0-or-later"
 65075              }
 65076            },
 65077            {
 65078              "license": {
 65079                "name": "LGPL"
 65080              }
 65081            },
 65082            {
 65083              "license": {
 65084                "id": "LGPL-2.0-only"
 65085              }
 65086            },
 65087            {
 65088              "license": {
 65089                "id": "LGPL-2.0-or-later"
 65090              }
 65091            },
 65092            {
 65093              "license": {
 65094                "id": "LGPL-2.1-only"
 65095              }
 65096            },
 65097            {
 65098              "license": {
 65099                "id": "LGPL-2.1-or-later"
 65100              }
 65101            },
 65102            {
 65103              "license": {
 65104                "id": "LGPL-3.0-only"
 65105              }
 65106            },
 65107            {
 65108              "license": {
 65109                "id": "LGPL-3.0-or-later"
 65110              }
 65111            },
 65112            {
 65113              "license": {
 65114                "id": "MIT"
 65115              }
 65116            },
 65117            {
 65118              "license": {
 65119                "name": "public-domain"
 65120              }
 65121            }
 65122          ],
 65123          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 65124          "purl": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 65125          "swid": {
 65126            "attachment": {}
 65127          },
 65128          "pedigree": {},
 65129          "evidence": {},
 65130          "signature": {
 65131            "signature": {
 65132              "publicKey": {}
 65133            }
 65134          },
 65135          "modelCard": {
 65136            "modelParameters": {
 65137              "approach": {}
 65138            },
 65139            "quantitativeAnalysis": {
 65140              "graphics": {}
 65141            },
 65142            "considerations": {}
 65143          }
 65144        },
 65145        {
 65146          "type": "library",
 65147          "bom-ref": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04\u0026package-id=a7c7ccf11d3583d1",
 65148          "supplier": {},
 65149          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65150          "name": "libsqlite3-0",
 65151          "version": "3.31.1-4ubuntu0.2",
 65152          "licenses": [
 65153            {
 65154              "license": {
 65155                "id": "GPL-2.0-only"
 65156              }
 65157            },
 65158            {
 65159              "license": {
 65160                "id": "GPL-2.0-or-later"
 65161              }
 65162            },
 65163            {
 65164              "license": {
 65165                "name": "public-domain"
 65166              }
 65167            }
 65168          ],
 65169          "cpe": "cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.31.1-4ubuntu0.2:*:*:*:*:*:*:*",
 65170          "purl": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04",
 65171          "swid": {
 65172            "attachment": {}
 65173          },
 65174          "pedigree": {},
 65175          "evidence": {},
 65176          "signature": {
 65177            "signature": {
 65178              "publicKey": {}
 65179            }
 65180          },
 65181          "modelCard": {
 65182            "modelParameters": {
 65183              "approach": {}
 65184            },
 65185            "quantitativeAnalysis": {
 65186              "graphics": {}
 65187            },
 65188            "considerations": {}
 65189          }
 65190        },
 65191        {
 65192          "type": "library",
 65193          "bom-ref": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4715894cb8165c",
 65194          "supplier": {},
 65195          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65196          "name": "libss2",
 65197          "version": "1.45.5-2ubuntu1",
 65198          "cpe": "cpe:2.3:a:libss2:libss2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 65199          "purl": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 65200          "swid": {
 65201            "attachment": {}
 65202          },
 65203          "pedigree": {},
 65204          "evidence": {},
 65205          "signature": {
 65206            "signature": {
 65207              "publicKey": {}
 65208            }
 65209          },
 65210          "modelCard": {
 65211            "modelParameters": {
 65212              "approach": {}
 65213            },
 65214            "quantitativeAnalysis": {
 65215              "graphics": {}
 65216            },
 65217            "considerations": {}
 65218          }
 65219        },
 65220        {
 65221          "type": "library",
 65222          "bom-ref": "pkg:deb/ubuntu/libssh-4@0.9.3-2ubuntu2.2?arch=amd64\u0026upstream=libssh\u0026distro=ubuntu-20.04\u0026package-id=93df7c2bd7217cc4",
 65223          "supplier": {},
 65224          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65225          "name": "libssh-4",
 65226          "version": "0.9.3-2ubuntu2.2",
 65227          "licenses": [
 65228            {
 65229              "license": {
 65230                "id": "BSD-2-Clause"
 65231              }
 65232            },
 65233            {
 65234              "license": {
 65235                "id": "BSD-3-Clause"
 65236              }
 65237            },
 65238            {
 65239              "license": {
 65240                "id": "LGPL-2.1-only"
 65241              }
 65242            },
 65243            {
 65244              "license": {
 65245                "name": "LGPL-2.1+~OpenSSL"
 65246              }
 65247            },
 65248            {
 65249              "license": {
 65250                "name": "public-domain"
 65251              }
 65252            }
 65253          ],
 65254          "cpe": "cpe:2.3:a:libssh-4:libssh-4:0.9.3-2ubuntu2.2:*:*:*:*:*:*:*",
 65255          "purl": "pkg:deb/ubuntu/libssh-4@0.9.3-2ubuntu2.2?arch=amd64\u0026upstream=libssh\u0026distro=ubuntu-20.04",
 65256          "swid": {
 65257            "attachment": {}
 65258          },
 65259          "pedigree": {},
 65260          "evidence": {},
 65261          "signature": {
 65262            "signature": {
 65263              "publicKey": {}
 65264            }
 65265          },
 65266          "modelCard": {
 65267            "modelParameters": {
 65268              "approach": {}
 65269            },
 65270            "quantitativeAnalysis": {
 65271              "graphics": {}
 65272            },
 65273            "considerations": {}
 65274          }
 65275        },
 65276        {
 65277          "type": "library",
 65278          "bom-ref": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.8?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04\u0026package-id=9228d1481eea75e3",
 65279          "supplier": {},
 65280          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65281          "name": "libssl1.1",
 65282          "version": "1.1.1f-1ubuntu2.8",
 65283          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1f-1ubuntu2.8:*:*:*:*:*:*:*",
 65284          "purl": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.8?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04",
 65285          "swid": {
 65286            "attachment": {}
 65287          },
 65288          "pedigree": {},
 65289          "evidence": {},
 65290          "signature": {
 65291            "signature": {
 65292              "publicKey": {}
 65293            }
 65294          },
 65295          "modelCard": {
 65296            "modelParameters": {
 65297              "approach": {}
 65298            },
 65299            "quantitativeAnalysis": {
 65300              "graphics": {}
 65301            },
 65302            "considerations": {}
 65303          }
 65304        },
 65305        {
 65306          "type": "library",
 65307          "bom-ref": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=241fcb3d9b65153a",
 65308          "supplier": {},
 65309          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65310          "name": "libstdc++6",
 65311          "version": "10.3.0-1ubuntu1~20.04",
 65312          "licenses": [
 65313            {
 65314              "license": {
 65315                "name": "Artistic"
 65316              }
 65317            },
 65318            {
 65319              "license": {
 65320                "id": "GFDL-1.2-only"
 65321              }
 65322            },
 65323            {
 65324              "license": {
 65325                "name": "GPL"
 65326              }
 65327            },
 65328            {
 65329              "license": {
 65330                "id": "GPL-2.0-only"
 65331              }
 65332            },
 65333            {
 65334              "license": {
 65335                "id": "GPL-3.0-only"
 65336              }
 65337            },
 65338            {
 65339              "license": {
 65340                "name": "LGPL"
 65341              }
 65342            }
 65343          ],
 65344          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
 65345          "purl": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
 65346          "swid": {
 65347            "attachment": {}
 65348          },
 65349          "pedigree": {},
 65350          "evidence": {},
 65351          "signature": {
 65352            "signature": {
 65353              "publicKey": {}
 65354            }
 65355          },
 65356          "modelCard": {
 65357            "modelParameters": {
 65358              "approach": {}
 65359            },
 65360            "quantitativeAnalysis": {
 65361              "graphics": {}
 65362            },
 65363            "considerations": {}
 65364          }
 65365        },
 65366        {
 65367          "type": "library",
 65368          "bom-ref": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=72d1f4b2fda6e155",
 65369          "supplier": {},
 65370          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65371          "name": "libsystemd0",
 65372          "version": "245.4-4ubuntu3.11",
 65373          "licenses": [
 65374            {
 65375              "license": {
 65376                "id": "CC0-1.0"
 65377              }
 65378            },
 65379            {
 65380              "license": {
 65381                "name": "Expat"
 65382              }
 65383            },
 65384            {
 65385              "license": {
 65386                "id": "GPL-2.0-only"
 65387              }
 65388            },
 65389            {
 65390              "license": {
 65391                "id": "GPL-2.0-or-later"
 65392              }
 65393            },
 65394            {
 65395              "license": {
 65396                "id": "LGPL-2.1-only"
 65397              }
 65398            },
 65399            {
 65400              "license": {
 65401                "id": "LGPL-2.1-or-later"
 65402              }
 65403            },
 65404            {
 65405              "license": {
 65406                "name": "public-domain"
 65407              }
 65408            }
 65409          ],
 65410          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:245.4-4ubuntu3.11:*:*:*:*:*:*:*",
 65411          "purl": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
 65412          "swid": {
 65413            "attachment": {}
 65414          },
 65415          "pedigree": {},
 65416          "evidence": {},
 65417          "signature": {
 65418            "signature": {
 65419              "publicKey": {}
 65420            }
 65421          },
 65422          "modelCard": {
 65423            "modelParameters": {
 65424              "approach": {}
 65425            },
 65426            "quantitativeAnalysis": {
 65427              "graphics": {}
 65428            },
 65429            "considerations": {}
 65430          }
 65431        },
 65432        {
 65433          "type": "library",
 65434          "bom-ref": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a290c35fc0220ba0",
 65435          "supplier": {},
 65436          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65437          "name": "libtasn1-6",
 65438          "version": "4.16.0-2",
 65439          "licenses": [
 65440            {
 65441              "license": {
 65442                "id": "GFDL-1.3-only"
 65443              }
 65444            },
 65445            {
 65446              "license": {
 65447                "id": "GPL-3.0-only"
 65448              }
 65449            },
 65450            {
 65451              "license": {
 65452                "name": "LGPL"
 65453              }
 65454            },
 65455            {
 65456              "license": {
 65457                "id": "LGPL-2.1-only"
 65458              }
 65459            }
 65460          ],
 65461          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2:*:*:*:*:*:*:*",
 65462          "purl": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04",
 65463          "swid": {
 65464            "attachment": {}
 65465          },
 65466          "pedigree": {},
 65467          "evidence": {},
 65468          "signature": {
 65469            "signature": {
 65470              "publicKey": {}
 65471            }
 65472          },
 65473          "modelCard": {
 65474            "modelParameters": {
 65475              "approach": {}
 65476            },
 65477            "quantitativeAnalysis": {
 65478              "graphics": {}
 65479            },
 65480            "considerations": {}
 65481          }
 65482        },
 65483        {
 65484          "type": "library",
 65485          "bom-ref": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=72ad56d118fefea3",
 65486          "supplier": {},
 65487          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65488          "name": "libtinfo6",
 65489          "version": "6.2-0ubuntu2",
 65490          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.2-0ubuntu2:*:*:*:*:*:*:*",
 65491          "purl": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 65492          "swid": {
 65493            "attachment": {}
 65494          },
 65495          "pedigree": {},
 65496          "evidence": {},
 65497          "signature": {
 65498            "signature": {
 65499              "publicKey": {}
 65500            }
 65501          },
 65502          "modelCard": {
 65503            "modelParameters": {
 65504              "approach": {}
 65505            },
 65506            "quantitativeAnalysis": {
 65507              "graphics": {}
 65508            },
 65509            "considerations": {}
 65510          }
 65511        },
 65512        {
 65513          "type": "library",
 65514          "bom-ref": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=ba22fe8af5722b24",
 65515          "supplier": {},
 65516          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65517          "name": "libtirpc-common",
 65518          "version": "1.2.5-1",
 65519          "licenses": [
 65520            {
 65521              "license": {
 65522                "id": "BSD-3-Clause"
 65523              }
 65524            },
 65525            {
 65526              "license": {
 65527                "id": "GPL-2.0-only"
 65528              }
 65529            },
 65530            {
 65531              "license": {
 65532                "id": "LGPL-2.1-only"
 65533              }
 65534            }
 65535          ],
 65536          "cpe": "cpe:2.3:a:libtirpc-common:libtirpc-common:1.2.5-1:*:*:*:*:*:*:*",
 65537          "purl": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
 65538          "swid": {
 65539            "attachment": {}
 65540          },
 65541          "pedigree": {},
 65542          "evidence": {},
 65543          "signature": {
 65544            "signature": {
 65545              "publicKey": {}
 65546            }
 65547          },
 65548          "modelCard": {
 65549            "modelParameters": {
 65550              "approach": {}
 65551            },
 65552            "quantitativeAnalysis": {
 65553              "graphics": {}
 65554            },
 65555            "considerations": {}
 65556          }
 65557        },
 65558        {
 65559          "type": "library",
 65560          "bom-ref": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=57b2bfa0a8467ab7",
 65561          "supplier": {},
 65562          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65563          "name": "libtirpc3",
 65564          "version": "1.2.5-1",
 65565          "licenses": [
 65566            {
 65567              "license": {
 65568                "id": "BSD-3-Clause"
 65569              }
 65570            },
 65571            {
 65572              "license": {
 65573                "id": "GPL-2.0-only"
 65574              }
 65575            },
 65576            {
 65577              "license": {
 65578                "id": "LGPL-2.1-only"
 65579              }
 65580            }
 65581          ],
 65582          "cpe": "cpe:2.3:a:libtirpc3:libtirpc3:1.2.5-1:*:*:*:*:*:*:*",
 65583          "purl": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
 65584          "swid": {
 65585            "attachment": {}
 65586          },
 65587          "pedigree": {},
 65588          "evidence": {},
 65589          "signature": {
 65590            "signature": {
 65591              "publicKey": {}
 65592            }
 65593          },
 65594          "modelCard": {
 65595            "modelParameters": {
 65596              "approach": {}
 65597            },
 65598            "quantitativeAnalysis": {
 65599              "graphics": {}
 65600            },
 65601            "considerations": {}
 65602          }
 65603        },
 65604        {
 65605          "type": "library",
 65606          "bom-ref": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=28d962536291b482",
 65607          "supplier": {},
 65608          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65609          "name": "libudev1",
 65610          "version": "245.4-4ubuntu3.11",
 65611          "licenses": [
 65612            {
 65613              "license": {
 65614                "id": "CC0-1.0"
 65615              }
 65616            },
 65617            {
 65618              "license": {
 65619                "name": "Expat"
 65620              }
 65621            },
 65622            {
 65623              "license": {
 65624                "id": "GPL-2.0-only"
 65625              }
 65626            },
 65627            {
 65628              "license": {
 65629                "id": "GPL-2.0-or-later"
 65630              }
 65631            },
 65632            {
 65633              "license": {
 65634                "id": "LGPL-2.1-only"
 65635              }
 65636            },
 65637            {
 65638              "license": {
 65639                "id": "LGPL-2.1-or-later"
 65640              }
 65641            },
 65642            {
 65643              "license": {
 65644                "name": "public-domain"
 65645              }
 65646            }
 65647          ],
 65648          "cpe": "cpe:2.3:a:libudev1:libudev1:245.4-4ubuntu3.11:*:*:*:*:*:*:*",
 65649          "purl": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
 65650          "swid": {
 65651            "attachment": {}
 65652          },
 65653          "pedigree": {},
 65654          "evidence": {},
 65655          "signature": {
 65656            "signature": {
 65657              "publicKey": {}
 65658            }
 65659          },
 65660          "modelCard": {
 65661            "modelParameters": {
 65662              "approach": {}
 65663            },
 65664            "quantitativeAnalysis": {
 65665              "graphics": {}
 65666            },
 65667            "considerations": {}
 65668          }
 65669        },
 65670        {
 65671          "type": "library",
 65672          "bom-ref": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04\u0026package-id=3140ffa70dcd9831",
 65673          "supplier": {},
 65674          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65675          "name": "libunistring2",
 65676          "version": "0.9.10-2",
 65677          "licenses": [
 65678            {
 65679              "license": {
 65680                "name": "FreeSoftware"
 65681              }
 65682            },
 65683            {
 65684              "license": {
 65685                "id": "GFDL-1.2-only"
 65686              }
 65687            },
 65688            {
 65689              "license": {
 65690                "name": "GFDL-1.2+"
 65691              }
 65692            },
 65693            {
 65694              "license": {
 65695                "id": "GPL-2.0-only"
 65696              }
 65697            },
 65698            {
 65699              "license": {
 65700                "id": "GPL-2.0-or-later"
 65701              }
 65702            },
 65703            {
 65704              "license": {
 65705                "id": "GPL-3.0-only"
 65706              }
 65707            },
 65708            {
 65709              "license": {
 65710                "id": "GPL-3.0-or-later"
 65711              }
 65712            },
 65713            {
 65714              "license": {
 65715                "id": "LGPL-3.0-only"
 65716              }
 65717            },
 65718            {
 65719              "license": {
 65720                "id": "LGPL-3.0-or-later"
 65721              }
 65722            },
 65723            {
 65724              "license": {
 65725                "id": "MIT"
 65726              }
 65727            }
 65728          ],
 65729          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-2:*:*:*:*:*:*:*",
 65730          "purl": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04",
 65731          "swid": {
 65732            "attachment": {}
 65733          },
 65734          "pedigree": {},
 65735          "evidence": {},
 65736          "signature": {
 65737            "signature": {
 65738              "publicKey": {}
 65739            }
 65740          },
 65741          "modelCard": {
 65742            "modelParameters": {
 65743              "approach": {}
 65744            },
 65745            "quantitativeAnalysis": {
 65746              "graphics": {}
 65747            },
 65748            "considerations": {}
 65749          }
 65750        },
 65751        {
 65752          "type": "library",
 65753          "bom-ref": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=5395a07c00002ea6",
 65754          "supplier": {},
 65755          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65756          "name": "libuuid1",
 65757          "version": "2.34-0.1ubuntu9.1",
 65758          "licenses": [
 65759            {
 65760              "license": {
 65761                "id": "BSD-2-Clause"
 65762              }
 65763            },
 65764            {
 65765              "license": {
 65766                "id": "BSD-3-Clause"
 65767              }
 65768            },
 65769            {
 65770              "license": {
 65771                "id": "BSD-4-Clause"
 65772              }
 65773            },
 65774            {
 65775              "license": {
 65776                "id": "GPL-2.0-only"
 65777              }
 65778            },
 65779            {
 65780              "license": {
 65781                "id": "GPL-2.0-or-later"
 65782              }
 65783            },
 65784            {
 65785              "license": {
 65786                "id": "GPL-3.0-only"
 65787              }
 65788            },
 65789            {
 65790              "license": {
 65791                "id": "GPL-3.0-or-later"
 65792              }
 65793            },
 65794            {
 65795              "license": {
 65796                "name": "LGPL"
 65797              }
 65798            },
 65799            {
 65800              "license": {
 65801                "id": "LGPL-2.0-only"
 65802              }
 65803            },
 65804            {
 65805              "license": {
 65806                "id": "LGPL-2.0-or-later"
 65807              }
 65808            },
 65809            {
 65810              "license": {
 65811                "id": "LGPL-2.1-only"
 65812              }
 65813            },
 65814            {
 65815              "license": {
 65816                "id": "LGPL-2.1-or-later"
 65817              }
 65818            },
 65819            {
 65820              "license": {
 65821                "id": "LGPL-3.0-only"
 65822              }
 65823            },
 65824            {
 65825              "license": {
 65826                "id": "LGPL-3.0-or-later"
 65827              }
 65828            },
 65829            {
 65830              "license": {
 65831                "id": "MIT"
 65832              }
 65833            },
 65834            {
 65835              "license": {
 65836                "name": "public-domain"
 65837              }
 65838            }
 65839          ],
 65840          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 65841          "purl": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 65842          "swid": {
 65843            "attachment": {}
 65844          },
 65845          "pedigree": {},
 65846          "evidence": {},
 65847          "signature": {
 65848            "signature": {
 65849              "publicKey": {}
 65850            }
 65851          },
 65852          "modelCard": {
 65853            "modelParameters": {
 65854              "approach": {}
 65855            },
 65856            "quantitativeAnalysis": {
 65857              "graphics": {}
 65858            },
 65859            "considerations": {}
 65860          }
 65861        },
 65862        {
 65863          "type": "library",
 65864          "bom-ref": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=7b0e172efdb36a99",
 65865          "supplier": {},
 65866          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65867          "name": "libwind0-heimdal",
 65868          "version": "7.7.0+dfsg-1ubuntu1",
 65869          "licenses": [
 65870            {
 65871              "license": {
 65872                "id": "BSD-3-Clause"
 65873              }
 65874            },
 65875            {
 65876              "license": {
 65877                "id": "GPL-2.0-only"
 65878              }
 65879            },
 65880            {
 65881              "license": {
 65882                "id": "GPL-2.0-or-later"
 65883              }
 65884            },
 65885            {
 65886              "license": {
 65887                "name": "custom"
 65888              }
 65889            }
 65890          ],
 65891          "cpe": "cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
 65892          "purl": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
 65893          "swid": {
 65894            "attachment": {}
 65895          },
 65896          "pedigree": {},
 65897          "evidence": {},
 65898          "signature": {
 65899            "signature": {
 65900              "publicKey": {}
 65901            }
 65902          },
 65903          "modelCard": {
 65904            "modelParameters": {
 65905              "approach": {}
 65906            },
 65907            "quantitativeAnalysis": {
 65908              "graphics": {}
 65909            },
 65910            "considerations": {}
 65911          }
 65912        },
 65913        {
 65914          "type": "library",
 65915          "bom-ref": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04\u0026package-id=5b14391c61bb94f1",
 65916          "supplier": {},
 65917          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65918          "name": "libwrap0",
 65919          "version": "7.6.q-30",
 65920          "cpe": "cpe:2.3:a:libwrap0:libwrap0:7.6.q-30:*:*:*:*:*:*:*",
 65921          "purl": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04",
 65922          "swid": {
 65923            "attachment": {}
 65924          },
 65925          "pedigree": {},
 65926          "evidence": {},
 65927          "signature": {
 65928            "signature": {
 65929              "publicKey": {}
 65930            }
 65931          },
 65932          "modelCard": {
 65933            "modelParameters": {
 65934              "approach": {}
 65935            },
 65936            "quantitativeAnalysis": {
 65937              "graphics": {}
 65938            },
 65939            "considerations": {}
 65940          }
 65941        },
 65942        {
 65943          "type": "library",
 65944          "bom-ref": "pkg:deb/ubuntu/libxml2@2.9.10+dfsg-5ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=5227ee2e55b78734",
 65945          "supplier": {},
 65946          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65947          "name": "libxml2",
 65948          "version": "2.9.10+dfsg-5ubuntu0.20.04.1",
 65949          "licenses": [
 65950            {
 65951              "license": {
 65952                "id": "ISC"
 65953              }
 65954            },
 65955            {
 65956              "license": {
 65957                "name": "MIT-1"
 65958              }
 65959            }
 65960          ],
 65961          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.10\\+dfsg-5ubuntu0.20.04.1:*:*:*:*:*:*:*",
 65962          "purl": "pkg:deb/ubuntu/libxml2@2.9.10+dfsg-5ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
 65963          "swid": {
 65964            "attachment": {}
 65965          },
 65966          "pedigree": {},
 65967          "evidence": {},
 65968          "signature": {
 65969            "signature": {
 65970              "publicKey": {}
 65971            }
 65972          },
 65973          "modelCard": {
 65974            "modelParameters": {
 65975              "approach": {}
 65976            },
 65977            "quantitativeAnalysis": {
 65978              "graphics": {}
 65979            },
 65980            "considerations": {}
 65981          }
 65982        },
 65983        {
 65984          "type": "library",
 65985          "bom-ref": "pkg:deb/ubuntu/libxtables12@1.8.4-3ubuntu2?arch=amd64\u0026upstream=iptables\u0026distro=ubuntu-20.04\u0026package-id=440c57e95fc3a35c",
 65986          "supplier": {},
 65987          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 65988          "name": "libxtables12",
 65989          "version": "1.8.4-3ubuntu2",
 65990          "licenses": [
 65991            {
 65992              "license": {
 65993                "name": "Artistic"
 65994              }
 65995            },
 65996            {
 65997              "license": {
 65998                "id": "GPL-2.0-only"
 65999              }
 66000            },
 66001            {
 66002              "license": {
 66003                "id": "GPL-2.0-or-later"
 66004              }
 66005            },
 66006            {
 66007              "license": {
 66008                "name": "custom"
 66009              }
 66010            }
 66011          ],
 66012          "cpe": "cpe:2.3:a:libxtables12:libxtables12:1.8.4-3ubuntu2:*:*:*:*:*:*:*",
 66013          "purl": "pkg:deb/ubuntu/libxtables12@1.8.4-3ubuntu2?arch=amd64\u0026upstream=iptables\u0026distro=ubuntu-20.04",
 66014          "swid": {
 66015            "attachment": {}
 66016          },
 66017          "pedigree": {},
 66018          "evidence": {},
 66019          "signature": {
 66020            "signature": {
 66021              "publicKey": {}
 66022            }
 66023          },
 66024          "modelCard": {
 66025            "modelParameters": {
 66026              "approach": {}
 66027            },
 66028            "quantitativeAnalysis": {
 66029              "graphics": {}
 66030            },
 66031            "considerations": {}
 66032          }
 66033        },
 66034        {
 66035          "type": "library",
 66036          "bom-ref": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04\u0026package-id=47cff0564e160066",
 66037          "supplier": {},
 66038          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66039          "name": "libzstd1",
 66040          "version": "1.4.4+dfsg-3ubuntu0.1",
 66041          "licenses": [
 66042            {
 66043              "license": {
 66044                "id": "BSD-3-Clause"
 66045              }
 66046            },
 66047            {
 66048              "license": {
 66049                "name": "Expat"
 66050              }
 66051            },
 66052            {
 66053              "license": {
 66054                "id": "GPL-2.0-only"
 66055              }
 66056            },
 66057            {
 66058              "license": {
 66059                "id": "GPL-2.0-or-later"
 66060              }
 66061            },
 66062            {
 66063              "license": {
 66064                "id": "Zlib"
 66065              }
 66066            }
 66067          ],
 66068          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.4\\+dfsg-3ubuntu0.1:*:*:*:*:*:*:*",
 66069          "purl": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04",
 66070          "swid": {
 66071            "attachment": {}
 66072          },
 66073          "pedigree": {},
 66074          "evidence": {},
 66075          "signature": {
 66076            "signature": {
 66077              "publicKey": {}
 66078            }
 66079          },
 66080          "modelCard": {
 66081            "modelParameters": {
 66082              "approach": {}
 66083            },
 66084            "quantitativeAnalysis": {
 66085              "graphics": {}
 66086            },
 66087            "considerations": {}
 66088          }
 66089        },
 66090        {
 66091          "type": "library",
 66092          "bom-ref": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=cb23947502a7c38d",
 66093          "supplier": {},
 66094          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66095          "name": "login",
 66096          "version": "1:4.8.1-1ubuntu5.20.04.1",
 66097          "licenses": [
 66098            {
 66099              "license": {
 66100                "id": "GPL-2.0-only"
 66101              }
 66102            }
 66103          ],
 66104          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
 66105          "purl": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
 66106          "swid": {
 66107            "attachment": {}
 66108          },
 66109          "pedigree": {},
 66110          "evidence": {},
 66111          "signature": {
 66112            "signature": {
 66113              "publicKey": {}
 66114            }
 66115          },
 66116          "modelCard": {
 66117            "modelParameters": {
 66118              "approach": {}
 66119            },
 66120            "quantitativeAnalysis": {
 66121              "graphics": {}
 66122            },
 66123            "considerations": {}
 66124          }
 66125        },
 66126        {
 66127          "type": "library",
 66128          "bom-ref": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4a92556bee4b4f91",
 66129          "supplier": {},
 66130          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66131          "name": "logsave",
 66132          "version": "1.45.5-2ubuntu1",
 66133          "licenses": [
 66134            {
 66135              "license": {
 66136                "id": "GPL-2.0-only"
 66137              }
 66138            },
 66139            {
 66140              "license": {
 66141                "id": "LGPL-2.0-only"
 66142              }
 66143            }
 66144          ],
 66145          "cpe": "cpe:2.3:a:logsave:logsave:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
 66146          "purl": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
 66147          "swid": {
 66148            "attachment": {}
 66149          },
 66150          "pedigree": {},
 66151          "evidence": {},
 66152          "signature": {
 66153            "signature": {
 66154              "publicKey": {}
 66155            }
 66156          },
 66157          "modelCard": {
 66158            "modelParameters": {
 66159              "approach": {}
 66160            },
 66161            "quantitativeAnalysis": {
 66162              "graphics": {}
 66163            },
 66164            "considerations": {}
 66165          }
 66166        },
 66167        {
 66168          "type": "library",
 66169          "bom-ref": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04\u0026package-id=b76348b7f1282c61",
 66170          "supplier": {},
 66171          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66172          "name": "lsb-base",
 66173          "version": "11.1.0ubuntu2",
 66174          "licenses": [
 66175            {
 66176              "license": {
 66177                "id": "BSD-3-Clause"
 66178              }
 66179            },
 66180            {
 66181              "license": {
 66182                "id": "GPL-2.0-only"
 66183              }
 66184            }
 66185          ],
 66186          "cpe": "cpe:2.3:a:lsb-base:lsb-base:11.1.0ubuntu2:*:*:*:*:*:*:*",
 66187          "purl": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04",
 66188          "swid": {
 66189            "attachment": {}
 66190          },
 66191          "pedigree": {},
 66192          "evidence": {},
 66193          "signature": {
 66194            "signature": {
 66195              "publicKey": {}
 66196            }
 66197          },
 66198          "modelCard": {
 66199            "modelParameters": {
 66200              "approach": {}
 66201            },
 66202            "quantitativeAnalysis": {
 66203              "graphics": {}
 66204            },
 66205            "considerations": {}
 66206          }
 66207        },
 66208        {
 66209          "type": "library",
 66210          "bom-ref": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=435885c82afbf721",
 66211          "supplier": {},
 66212          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66213          "name": "mawk",
 66214          "version": "1.3.4.20200120-2",
 66215          "licenses": [
 66216            {
 66217              "license": {
 66218                "id": "GPL-2.0-only"
 66219              }
 66220            }
 66221          ],
 66222          "cpe": "cpe:2.3:a:mawk:mawk:1.3.4.20200120-2:*:*:*:*:*:*:*",
 66223          "purl": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04",
 66224          "swid": {
 66225            "attachment": {}
 66226          },
 66227          "pedigree": {},
 66228          "evidence": {},
 66229          "signature": {
 66230            "signature": {
 66231              "publicKey": {}
 66232            }
 66233          },
 66234          "modelCard": {
 66235            "modelParameters": {
 66236              "approach": {}
 66237            },
 66238            "quantitativeAnalysis": {
 66239              "graphics": {}
 66240            },
 66241            "considerations": {}
 66242          }
 66243        },
 66244        {
 66245          "type": "library",
 66246          "bom-ref": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=405891a224258a92",
 66247          "supplier": {},
 66248          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66249          "name": "mime-support",
 66250          "version": "3.64ubuntu1",
 66251          "licenses": [
 66252            {
 66253              "license": {
 66254                "name": "Bellcore"
 66255              }
 66256            },
 66257            {
 66258              "license": {
 66259                "name": "ad-hoc"
 66260              }
 66261            }
 66262          ],
 66263          "cpe": "cpe:2.3:a:mime-support:mime-support:3.64ubuntu1:*:*:*:*:*:*:*",
 66264          "purl": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04",
 66265          "swid": {
 66266            "attachment": {}
 66267          },
 66268          "pedigree": {},
 66269          "evidence": {},
 66270          "signature": {
 66271            "signature": {
 66272              "publicKey": {}
 66273            }
 66274          },
 66275          "modelCard": {
 66276            "modelParameters": {
 66277              "approach": {}
 66278            },
 66279            "quantitativeAnalysis": {
 66280              "graphics": {}
 66281            },
 66282            "considerations": {}
 66283          }
 66284        },
 66285        {
 66286          "type": "library",
 66287          "bom-ref": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=fa4ef6b12af7900c",
 66288          "supplier": {},
 66289          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66290          "name": "mount",
 66291          "version": "2.34-0.1ubuntu9.1",
 66292          "licenses": [
 66293            {
 66294              "license": {
 66295                "id": "BSD-2-Clause"
 66296              }
 66297            },
 66298            {
 66299              "license": {
 66300                "id": "BSD-3-Clause"
 66301              }
 66302            },
 66303            {
 66304              "license": {
 66305                "id": "BSD-4-Clause"
 66306              }
 66307            },
 66308            {
 66309              "license": {
 66310                "id": "GPL-2.0-only"
 66311              }
 66312            },
 66313            {
 66314              "license": {
 66315                "id": "GPL-2.0-or-later"
 66316              }
 66317            },
 66318            {
 66319              "license": {
 66320                "id": "GPL-3.0-only"
 66321              }
 66322            },
 66323            {
 66324              "license": {
 66325                "id": "GPL-3.0-or-later"
 66326              }
 66327            },
 66328            {
 66329              "license": {
 66330                "name": "LGPL"
 66331              }
 66332            },
 66333            {
 66334              "license": {
 66335                "id": "LGPL-2.0-only"
 66336              }
 66337            },
 66338            {
 66339              "license": {
 66340                "id": "LGPL-2.0-or-later"
 66341              }
 66342            },
 66343            {
 66344              "license": {
 66345                "id": "LGPL-2.1-only"
 66346              }
 66347            },
 66348            {
 66349              "license": {
 66350                "id": "LGPL-2.1-or-later"
 66351              }
 66352            },
 66353            {
 66354              "license": {
 66355                "id": "LGPL-3.0-only"
 66356              }
 66357            },
 66358            {
 66359              "license": {
 66360                "id": "LGPL-3.0-or-later"
 66361              }
 66362            },
 66363            {
 66364              "license": {
 66365                "id": "MIT"
 66366              }
 66367            },
 66368            {
 66369              "license": {
 66370                "name": "public-domain"
 66371              }
 66372            }
 66373          ],
 66374          "cpe": "cpe:2.3:a:mount:mount:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 66375          "purl": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
 66376          "swid": {
 66377            "attachment": {}
 66378          },
 66379          "pedigree": {},
 66380          "evidence": {},
 66381          "signature": {
 66382            "signature": {
 66383              "publicKey": {}
 66384            }
 66385          },
 66386          "modelCard": {
 66387            "modelParameters": {
 66388              "approach": {}
 66389            },
 66390            "quantitativeAnalysis": {
 66391              "graphics": {}
 66392            },
 66393            "considerations": {}
 66394          }
 66395        },
 66396        {
 66397          "type": "library",
 66398          "bom-ref": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d7393defd95e4554",
 66399          "supplier": {},
 66400          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66401          "name": "ncurses-base",
 66402          "version": "6.2-0ubuntu2",
 66403          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.2-0ubuntu2:*:*:*:*:*:*:*",
 66404          "purl": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 66405          "swid": {
 66406            "attachment": {}
 66407          },
 66408          "pedigree": {},
 66409          "evidence": {},
 66410          "signature": {
 66411            "signature": {
 66412              "publicKey": {}
 66413            }
 66414          },
 66415          "modelCard": {
 66416            "modelParameters": {
 66417              "approach": {}
 66418            },
 66419            "quantitativeAnalysis": {
 66420              "graphics": {}
 66421            },
 66422            "considerations": {}
 66423          }
 66424        },
 66425        {
 66426          "type": "library",
 66427          "bom-ref": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d6bdd43961b680f6",
 66428          "supplier": {},
 66429          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66430          "name": "ncurses-bin",
 66431          "version": "6.2-0ubuntu2",
 66432          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.2-0ubuntu2:*:*:*:*:*:*:*",
 66433          "purl": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
 66434          "swid": {
 66435            "attachment": {}
 66436          },
 66437          "pedigree": {},
 66438          "evidence": {},
 66439          "signature": {
 66440            "signature": {
 66441              "publicKey": {}
 66442            }
 66443          },
 66444          "modelCard": {
 66445            "modelParameters": {
 66446              "approach": {}
 66447            },
 66448            "quantitativeAnalysis": {
 66449              "graphics": {}
 66450            },
 66451            "considerations": {}
 66452          }
 66453        },
 66454        {
 66455          "type": "library",
 66456          "bom-ref": "pkg:deb/ubuntu/netbase@6.1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=c6847a50307ac1ba",
 66457          "supplier": {},
 66458          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66459          "name": "netbase",
 66460          "version": "6.1",
 66461          "licenses": [
 66462            {
 66463              "license": {
 66464                "id": "GPL-2.0-only"
 66465              }
 66466            }
 66467          ],
 66468          "cpe": "cpe:2.3:a:netbase:netbase:6.1:*:*:*:*:*:*:*",
 66469          "purl": "pkg:deb/ubuntu/netbase@6.1?arch=all\u0026distro=ubuntu-20.04",
 66470          "swid": {
 66471            "attachment": {}
 66472          },
 66473          "pedigree": {},
 66474          "evidence": {},
 66475          "signature": {
 66476            "signature": {
 66477              "publicKey": {}
 66478            }
 66479          },
 66480          "modelCard": {
 66481            "modelParameters": {
 66482              "approach": {}
 66483            },
 66484            "quantitativeAnalysis": {
 66485              "graphics": {}
 66486            },
 66487            "considerations": {}
 66488          }
 66489        },
 66490        {
 66491          "type": "library",
 66492          "bom-ref": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04\u0026package-id=6a00c331080f32b7",
 66493          "supplier": {},
 66494          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66495          "name": "nfs-common",
 66496          "version": "1:1.3.4-2.5ubuntu3.4",
 66497          "licenses": [
 66498            {
 66499              "license": {
 66500                "id": "GPL-2.0-only"
 66501              }
 66502            }
 66503          ],
 66504          "cpe": "cpe:2.3:a:nfs-common:nfs-common:1\\:1.3.4-2.5ubuntu3.4:*:*:*:*:*:*:*",
 66505          "purl": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04",
 66506          "swid": {
 66507            "attachment": {}
 66508          },
 66509          "pedigree": {},
 66510          "evidence": {},
 66511          "signature": {
 66512            "signature": {
 66513              "publicKey": {}
 66514            }
 66515          },
 66516          "modelCard": {
 66517            "modelParameters": {
 66518              "approach": {}
 66519            },
 66520            "quantitativeAnalysis": {
 66521              "graphics": {}
 66522            },
 66523            "considerations": {}
 66524          }
 66525        },
 66526        {
 66527          "type": "library",
 66528          "bom-ref": "pkg:deb/ubuntu/openssl@1.1.1f-1ubuntu2.8?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=5727f60759ec90aa",
 66529          "supplier": {},
 66530          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66531          "name": "openssl",
 66532          "version": "1.1.1f-1ubuntu2.8",
 66533          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1f-1ubuntu2.8:*:*:*:*:*:*:*",
 66534          "purl": "pkg:deb/ubuntu/openssl@1.1.1f-1ubuntu2.8?arch=amd64\u0026distro=ubuntu-20.04",
 66535          "swid": {
 66536            "attachment": {}
 66537          },
 66538          "pedigree": {},
 66539          "evidence": {},
 66540          "signature": {
 66541            "signature": {
 66542              "publicKey": {}
 66543            }
 66544          },
 66545          "modelCard": {
 66546            "modelParameters": {
 66547              "approach": {}
 66548            },
 66549            "quantitativeAnalysis": {
 66550              "graphics": {}
 66551            },
 66552            "considerations": {}
 66553          }
 66554        },
 66555        {
 66556          "type": "library",
 66557          "bom-ref": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=c4a1ed5267891532",
 66558          "supplier": {},
 66559          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66560          "name": "passwd",
 66561          "version": "1:4.8.1-1ubuntu5.20.04.1",
 66562          "licenses": [
 66563            {
 66564              "license": {
 66565                "id": "GPL-2.0-only"
 66566              }
 66567            }
 66568          ],
 66569          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
 66570          "purl": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
 66571          "swid": {
 66572            "attachment": {}
 66573          },
 66574          "pedigree": {},
 66575          "evidence": {},
 66576          "signature": {
 66577            "signature": {
 66578              "publicKey": {}
 66579            }
 66580          },
 66581          "modelCard": {
 66582            "modelParameters": {
 66583              "approach": {}
 66584            },
 66585            "quantitativeAnalysis": {
 66586              "graphics": {}
 66587            },
 66588            "considerations": {}
 66589          }
 66590        },
 66591        {
 66592          "type": "library",
 66593          "bom-ref": "pkg:deb/ubuntu/perl@5.30.0-9ubuntu0.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=80890d41e31d4ad9",
 66594          "supplier": {},
 66595          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66596          "name": "perl",
 66597          "version": "5.30.0-9ubuntu0.2",
 66598          "licenses": [
 66599            {
 66600              "license": {
 66601                "name": "Artistic"
 66602              }
 66603            },
 66604            {
 66605              "license": {
 66606                "id": "Artistic-2.0"
 66607              }
 66608            },
 66609            {
 66610              "license": {
 66611                "name": "Artistic-dist"
 66612              }
 66613            },
 66614            {
 66615              "license": {
 66616                "id": "BSD-3-Clause"
 66617              }
 66618            },
 66619            {
 66620              "license": {
 66621                "name": "BSD-3-clause-GENERIC"
 66622              }
 66623            },
 66624            {
 66625              "license": {
 66626                "name": "BSD-3-clause-with-weird-numbering"
 66627              }
 66628            },
 66629            {
 66630              "license": {
 66631                "name": "BSD-4-clause-POWERDOG"
 66632              }
 66633            },
 66634            {
 66635              "license": {
 66636                "name": "BZIP"
 66637              }
 66638            },
 66639            {
 66640              "license": {
 66641                "name": "DONT-CHANGE-THE-GPL"
 66642              }
 66643            },
 66644            {
 66645              "license": {
 66646                "name": "Expat"
 66647              }
 66648            },
 66649            {
 66650              "license": {
 66651                "id": "GPL-1.0-only"
 66652              }
 66653            },
 66654            {
 66655              "license": {
 66656                "id": "GPL-1.0-or-later"
 66657              }
 66658            },
 66659            {
 66660              "license": {
 66661                "id": "GPL-2.0-only"
 66662              }
 66663            },
 66664            {
 66665              "license": {
 66666                "id": "GPL-2.0-or-later"
 66667              }
 66668            },
 66669            {
 66670              "license": {
 66671                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 66672              }
 66673            },
 66674            {
 66675              "license": {
 66676                "name": "HSIEH-BSD"
 66677              }
 66678            },
 66679            {
 66680              "license": {
 66681                "name": "HSIEH-DERIVATIVE"
 66682              }
 66683            },
 66684            {
 66685              "license": {
 66686                "id": "LGPL-2.1-only"
 66687              }
 66688            },
 66689            {
 66690              "license": {
 66691                "name": "REGCOMP"
 66692              }
 66693            },
 66694            {
 66695              "license": {
 66696                "name": "REGCOMP,"
 66697              }
 66698            },
 66699            {
 66700              "license": {
 66701                "name": "RRA-KEEP-THIS-NOTICE"
 66702              }
 66703            },
 66704            {
 66705              "license": {
 66706                "name": "SDBM-PUBLIC-DOMAIN"
 66707              }
 66708            },
 66709            {
 66710              "license": {
 66711                "name": "TEXT-TABS"
 66712              }
 66713            },
 66714            {
 66715              "license": {
 66716                "name": "Unicode"
 66717              }
 66718            },
 66719            {
 66720              "license": {
 66721                "id": "Zlib"
 66722              }
 66723            }
 66724          ],
 66725          "cpe": "cpe:2.3:a:perl:perl:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
 66726          "purl": "pkg:deb/ubuntu/perl@5.30.0-9ubuntu0.2?arch=amd64\u0026distro=ubuntu-20.04",
 66727          "swid": {
 66728            "attachment": {}
 66729          },
 66730          "pedigree": {},
 66731          "evidence": {},
 66732          "signature": {
 66733            "signature": {
 66734              "publicKey": {}
 66735            }
 66736          },
 66737          "modelCard": {
 66738            "modelParameters": {
 66739              "approach": {}
 66740            },
 66741            "quantitativeAnalysis": {
 66742              "graphics": {}
 66743            },
 66744            "considerations": {}
 66745          }
 66746        },
 66747        {
 66748          "type": "library",
 66749          "bom-ref": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=eab1752e76cf29f",
 66750          "supplier": {},
 66751          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66752          "name": "perl-base",
 66753          "version": "5.30.0-9ubuntu0.2",
 66754          "licenses": [
 66755            {
 66756              "license": {
 66757                "name": "Artistic"
 66758              }
 66759            },
 66760            {
 66761              "license": {
 66762                "id": "Artistic-2.0"
 66763              }
 66764            },
 66765            {
 66766              "license": {
 66767                "name": "Artistic-dist"
 66768              }
 66769            },
 66770            {
 66771              "license": {
 66772                "id": "BSD-3-Clause"
 66773              }
 66774            },
 66775            {
 66776              "license": {
 66777                "name": "BSD-3-clause-GENERIC"
 66778              }
 66779            },
 66780            {
 66781              "license": {
 66782                "name": "BSD-3-clause-with-weird-numbering"
 66783              }
 66784            },
 66785            {
 66786              "license": {
 66787                "name": "BSD-4-clause-POWERDOG"
 66788              }
 66789            },
 66790            {
 66791              "license": {
 66792                "name": "BZIP"
 66793              }
 66794            },
 66795            {
 66796              "license": {
 66797                "name": "DONT-CHANGE-THE-GPL"
 66798              }
 66799            },
 66800            {
 66801              "license": {
 66802                "name": "Expat"
 66803              }
 66804            },
 66805            {
 66806              "license": {
 66807                "id": "GPL-1.0-only"
 66808              }
 66809            },
 66810            {
 66811              "license": {
 66812                "id": "GPL-1.0-or-later"
 66813              }
 66814            },
 66815            {
 66816              "license": {
 66817                "id": "GPL-2.0-only"
 66818              }
 66819            },
 66820            {
 66821              "license": {
 66822                "id": "GPL-2.0-or-later"
 66823              }
 66824            },
 66825            {
 66826              "license": {
 66827                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 66828              }
 66829            },
 66830            {
 66831              "license": {
 66832                "name": "HSIEH-BSD"
 66833              }
 66834            },
 66835            {
 66836              "license": {
 66837                "name": "HSIEH-DERIVATIVE"
 66838              }
 66839            },
 66840            {
 66841              "license": {
 66842                "id": "LGPL-2.1-only"
 66843              }
 66844            },
 66845            {
 66846              "license": {
 66847                "name": "REGCOMP"
 66848              }
 66849            },
 66850            {
 66851              "license": {
 66852                "name": "REGCOMP,"
 66853              }
 66854            },
 66855            {
 66856              "license": {
 66857                "name": "RRA-KEEP-THIS-NOTICE"
 66858              }
 66859            },
 66860            {
 66861              "license": {
 66862                "name": "SDBM-PUBLIC-DOMAIN"
 66863              }
 66864            },
 66865            {
 66866              "license": {
 66867                "name": "TEXT-TABS"
 66868              }
 66869            },
 66870            {
 66871              "license": {
 66872                "name": "Unicode"
 66873              }
 66874            },
 66875            {
 66876              "license": {
 66877                "id": "Zlib"
 66878              }
 66879            }
 66880          ],
 66881          "cpe": "cpe:2.3:a:perl-base:perl-base:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
 66882          "purl": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04",
 66883          "swid": {
 66884            "attachment": {}
 66885          },
 66886          "pedigree": {},
 66887          "evidence": {},
 66888          "signature": {
 66889            "signature": {
 66890              "publicKey": {}
 66891            }
 66892          },
 66893          "modelCard": {
 66894            "modelParameters": {
 66895              "approach": {}
 66896            },
 66897            "quantitativeAnalysis": {
 66898              "graphics": {}
 66899            },
 66900            "considerations": {}
 66901          }
 66902        },
 66903        {
 66904          "type": "library",
 66905          "bom-ref": "pkg:deb/ubuntu/perl-modules-5.30@5.30.0-9ubuntu0.2?arch=all\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=fb3bcb2d22f50638",
 66906          "supplier": {},
 66907          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 66908          "name": "perl-modules-5.30",
 66909          "version": "5.30.0-9ubuntu0.2",
 66910          "licenses": [
 66911            {
 66912              "license": {
 66913                "name": "Artistic"
 66914              }
 66915            },
 66916            {
 66917              "license": {
 66918                "id": "Artistic-2.0"
 66919              }
 66920            },
 66921            {
 66922              "license": {
 66923                "name": "Artistic-dist"
 66924              }
 66925            },
 66926            {
 66927              "license": {
 66928                "id": "BSD-3-Clause"
 66929              }
 66930            },
 66931            {
 66932              "license": {
 66933                "name": "BSD-3-clause-GENERIC"
 66934              }
 66935            },
 66936            {
 66937              "license": {
 66938                "name": "BSD-3-clause-with-weird-numbering"
 66939              }
 66940            },
 66941            {
 66942              "license": {
 66943                "name": "BSD-4-clause-POWERDOG"
 66944              }
 66945            },
 66946            {
 66947              "license": {
 66948                "name": "BZIP"
 66949              }
 66950            },
 66951            {
 66952              "license": {
 66953                "name": "DONT-CHANGE-THE-GPL"
 66954              }
 66955            },
 66956            {
 66957              "license": {
 66958                "name": "Expat"
 66959              }
 66960            },
 66961            {
 66962              "license": {
 66963                "id": "GPL-1.0-only"
 66964              }
 66965            },
 66966            {
 66967              "license": {
 66968                "id": "GPL-1.0-or-later"
 66969              }
 66970            },
 66971            {
 66972              "license": {
 66973                "id": "GPL-2.0-only"
 66974              }
 66975            },
 66976            {
 66977              "license": {
 66978                "id": "GPL-2.0-or-later"
 66979              }
 66980            },
 66981            {
 66982              "license": {
 66983                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 66984              }
 66985            },
 66986            {
 66987              "license": {
 66988                "name": "HSIEH-BSD"
 66989              }
 66990            },
 66991            {
 66992              "license": {
 66993                "name": "HSIEH-DERIVATIVE"
 66994              }
 66995            },
 66996            {
 66997              "license": {
 66998                "id": "LGPL-2.1-only"
 66999              }
 67000            },
 67001            {
 67002              "license": {
 67003                "name": "REGCOMP"
 67004              }
 67005            },
 67006            {
 67007              "license": {
 67008                "name": "REGCOMP,"
 67009              }
 67010            },
 67011            {
 67012              "license": {
 67013                "name": "RRA-KEEP-THIS-NOTICE"
 67014              }
 67015            },
 67016            {
 67017              "license": {
 67018                "name": "SDBM-PUBLIC-DOMAIN"
 67019              }
 67020            },
 67021            {
 67022              "license": {
 67023                "name": "TEXT-TABS"
 67024              }
 67025            },
 67026            {
 67027              "license": {
 67028                "name": "Unicode"
 67029              }
 67030            },
 67031            {
 67032              "license": {
 67033                "id": "Zlib"
 67034              }
 67035            }
 67036          ],
 67037          "cpe": "cpe:2.3:a:perl-modules-5.30:perl-modules-5.30:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
 67038          "purl": "pkg:deb/ubuntu/perl-modules-5.30@5.30.0-9ubuntu0.2?arch=all\u0026upstream=perl\u0026distro=ubuntu-20.04",
 67039          "swid": {
 67040            "attachment": {}
 67041          },
 67042          "pedigree": {},
 67043          "evidence": {},
 67044          "signature": {
 67045            "signature": {
 67046              "publicKey": {}
 67047            }
 67048          },
 67049          "modelCard": {
 67050            "modelParameters": {
 67051              "approach": {}
 67052            },
 67053            "quantitativeAnalysis": {
 67054              "graphics": {}
 67055            },
 67056            "considerations": {}
 67057          }
 67058        },
 67059        {
 67060          "type": "library",
 67061          "bom-ref": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f177d21a50776ea7",
 67062          "supplier": {},
 67063          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67064          "name": "procps",
 67065          "version": "2:3.3.16-1ubuntu2.2",
 67066          "licenses": [
 67067            {
 67068              "license": {
 67069                "id": "GPL-2.0-only"
 67070              }
 67071            },
 67072            {
 67073              "license": {
 67074                "id": "GPL-2.0-or-later"
 67075              }
 67076            },
 67077            {
 67078              "license": {
 67079                "id": "LGPL-2.0-only"
 67080              }
 67081            },
 67082            {
 67083              "license": {
 67084                "id": "LGPL-2.0-or-later"
 67085              }
 67086            },
 67087            {
 67088              "license": {
 67089                "id": "LGPL-2.1-only"
 67090              }
 67091            },
 67092            {
 67093              "license": {
 67094                "id": "LGPL-2.1-or-later"
 67095              }
 67096            }
 67097          ],
 67098          "cpe": "cpe:2.3:a:procps:procps:2\\:3.3.16-1ubuntu2.2:*:*:*:*:*:*:*",
 67099          "purl": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.2?arch=amd64\u0026distro=ubuntu-20.04",
 67100          "swid": {
 67101            "attachment": {}
 67102          },
 67103          "pedigree": {},
 67104          "evidence": {},
 67105          "signature": {
 67106            "signature": {
 67107              "publicKey": {}
 67108            }
 67109          },
 67110          "modelCard": {
 67111            "modelParameters": {
 67112              "approach": {}
 67113            },
 67114            "quantitativeAnalysis": {
 67115              "graphics": {}
 67116            },
 67117            "considerations": {}
 67118          }
 67119        },
 67120        {
 67121          "type": "library",
 67122          "bom-ref": "pkg:deb/ubuntu/publicsuffix@20200303.0012-1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=fe371293cddb3ef3",
 67123          "supplier": {},
 67124          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67125          "name": "publicsuffix",
 67126          "version": "20200303.0012-1",
 67127          "licenses": [
 67128            {
 67129              "license": {
 67130                "name": "CC0"
 67131              }
 67132            },
 67133            {
 67134              "license": {
 67135                "id": "MPL-2.0"
 67136              }
 67137            }
 67138          ],
 67139          "cpe": "cpe:2.3:a:publicsuffix:publicsuffix:20200303.0012-1:*:*:*:*:*:*:*",
 67140          "purl": "pkg:deb/ubuntu/publicsuffix@20200303.0012-1?arch=all\u0026distro=ubuntu-20.04",
 67141          "swid": {
 67142            "attachment": {}
 67143          },
 67144          "pedigree": {},
 67145          "evidence": {},
 67146          "signature": {
 67147            "signature": {
 67148              "publicKey": {}
 67149            }
 67150          },
 67151          "modelCard": {
 67152            "modelParameters": {
 67153              "approach": {}
 67154            },
 67155            "quantitativeAnalysis": {
 67156              "graphics": {}
 67157            },
 67158            "considerations": {}
 67159          }
 67160        },
 67161        {
 67162          "type": "application",
 67163          "bom-ref": "pkg:generic/python@3.8.10?package-id=ed46688c3a0df6db",
 67164          "supplier": {},
 67165          "name": "python",
 67166          "version": "3.8.10",
 67167          "cpe": "cpe:2.3:a:python_software_foundation:python:3.8.10:*:*:*:*:*:*:*",
 67168          "purl": "pkg:generic/python@3.8.10",
 67169          "swid": {
 67170            "attachment": {}
 67171          },
 67172          "pedigree": {},
 67173          "evidence": {},
 67174          "signature": {
 67175            "signature": {
 67176              "publicKey": {}
 67177            }
 67178          },
 67179          "modelCard": {
 67180            "modelParameters": {
 67181              "approach": {}
 67182            },
 67183            "quantitativeAnalysis": {
 67184              "graphics": {}
 67185            },
 67186            "considerations": {}
 67187          }
 67188        },
 67189        {
 67190          "type": "library",
 67191          "bom-ref": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=ca939acbf264771",
 67192          "supplier": {},
 67193          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67194          "name": "python3",
 67195          "version": "3.8.2-0ubuntu2",
 67196          "cpe": "cpe:2.3:a:python3:python3:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
 67197          "purl": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
 67198          "swid": {
 67199            "attachment": {}
 67200          },
 67201          "pedigree": {},
 67202          "evidence": {},
 67203          "signature": {
 67204            "signature": {
 67205              "publicKey": {}
 67206            }
 67207          },
 67208          "modelCard": {
 67209            "modelParameters": {
 67210              "approach": {}
 67211            },
 67212            "quantitativeAnalysis": {
 67213              "graphics": {}
 67214            },
 67215            "considerations": {}
 67216          }
 67217        },
 67218        {
 67219          "type": "library",
 67220          "bom-ref": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=26eebf392e0b02cf",
 67221          "supplier": {},
 67222          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67223          "name": "python3-minimal",
 67224          "version": "3.8.2-0ubuntu2",
 67225          "cpe": "cpe:2.3:a:python3-minimal:python3-minimal:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
 67226          "purl": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
 67227          "swid": {
 67228            "attachment": {}
 67229          },
 67230          "pedigree": {},
 67231          "evidence": {},
 67232          "signature": {
 67233            "signature": {
 67234              "publicKey": {}
 67235            }
 67236          },
 67237          "modelCard": {
 67238            "modelParameters": {
 67239              "approach": {}
 67240            },
 67241            "quantitativeAnalysis": {
 67242              "graphics": {}
 67243            },
 67244            "considerations": {}
 67245          }
 67246        },
 67247        {
 67248          "type": "library",
 67249          "bom-ref": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=b1de928401abc554",
 67250          "supplier": {},
 67251          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67252          "name": "python3.8",
 67253          "version": "3.8.10-0ubuntu1~20.04",
 67254          "licenses": [
 67255            {
 67256              "license": {
 67257                "name": "By"
 67258              }
 67259            },
 67260            {
 67261              "license": {
 67262                "id": "GPL-2.0-only"
 67263              }
 67264            },
 67265            {
 67266              "license": {
 67267                "name": "Permission"
 67268              }
 67269            },
 67270            {
 67271              "license": {
 67272                "name": "Redistribution"
 67273              }
 67274            },
 67275            {
 67276              "license": {
 67277                "name": "This"
 67278              }
 67279            }
 67280          ],
 67281          "cpe": "cpe:2.3:a:python3.8:python3.8:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
 67282          "purl": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026distro=ubuntu-20.04",
 67283          "swid": {
 67284            "attachment": {}
 67285          },
 67286          "pedigree": {},
 67287          "evidence": {},
 67288          "signature": {
 67289            "signature": {
 67290              "publicKey": {}
 67291            }
 67292          },
 67293          "modelCard": {
 67294            "modelParameters": {
 67295              "approach": {}
 67296            },
 67297            "quantitativeAnalysis": {
 67298              "graphics": {}
 67299            },
 67300            "considerations": {}
 67301          }
 67302        },
 67303        {
 67304          "type": "library",
 67305          "bom-ref": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=91fa2bead1762d08",
 67306          "supplier": {},
 67307          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67308          "name": "python3.8-minimal",
 67309          "version": "3.8.10-0ubuntu1~20.04",
 67310          "licenses": [
 67311            {
 67312              "license": {
 67313                "name": "By"
 67314              }
 67315            },
 67316            {
 67317              "license": {
 67318                "id": "GPL-2.0-only"
 67319              }
 67320            },
 67321            {
 67322              "license": {
 67323                "name": "Permission"
 67324              }
 67325            },
 67326            {
 67327              "license": {
 67328                "name": "Redistribution"
 67329              }
 67330            },
 67331            {
 67332              "license": {
 67333                "name": "This"
 67334              }
 67335            }
 67336          ],
 67337          "cpe": "cpe:2.3:a:python3.8-minimal:python3.8-minimal:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
 67338          "purl": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
 67339          "swid": {
 67340            "attachment": {}
 67341          },
 67342          "pedigree": {},
 67343          "evidence": {},
 67344          "signature": {
 67345            "signature": {
 67346              "publicKey": {}
 67347            }
 67348          },
 67349          "modelCard": {
 67350            "modelParameters": {
 67351              "approach": {}
 67352            },
 67353            "quantitativeAnalysis": {
 67354              "graphics": {}
 67355            },
 67356            "considerations": {}
 67357          }
 67358        },
 67359        {
 67360          "type": "library",
 67361          "bom-ref": "pkg:deb/ubuntu/qemu-block-extra@1:4.2-3ubuntu6.17?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04\u0026package-id=f2ce7313d353bf0d",
 67362          "supplier": {},
 67363          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67364          "name": "qemu-block-extra",
 67365          "version": "1:4.2-3ubuntu6.17",
 67366          "licenses": [
 67367            {
 67368              "license": {
 67369                "id": "GPL-2.0-only"
 67370              }
 67371            },
 67372            {
 67373              "license": {
 67374                "id": "LGPL-2.0-only"
 67375              }
 67376            }
 67377          ],
 67378          "cpe": "cpe:2.3:a:qemu-block-extra:qemu-block-extra:1\\:4.2-3ubuntu6.17:*:*:*:*:*:*:*",
 67379          "purl": "pkg:deb/ubuntu/qemu-block-extra@1:4.2-3ubuntu6.17?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04",
 67380          "swid": {
 67381            "attachment": {}
 67382          },
 67383          "pedigree": {},
 67384          "evidence": {},
 67385          "signature": {
 67386            "signature": {
 67387              "publicKey": {}
 67388            }
 67389          },
 67390          "modelCard": {
 67391            "modelParameters": {
 67392              "approach": {}
 67393            },
 67394            "quantitativeAnalysis": {
 67395              "graphics": {}
 67396            },
 67397            "considerations": {}
 67398          }
 67399        },
 67400        {
 67401          "type": "library",
 67402          "bom-ref": "pkg:deb/ubuntu/qemu-utils@1:4.2-3ubuntu6.17?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04\u0026package-id=fd8d39c65bc83889",
 67403          "supplier": {},
 67404          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67405          "name": "qemu-utils",
 67406          "version": "1:4.2-3ubuntu6.17",
 67407          "licenses": [
 67408            {
 67409              "license": {
 67410                "id": "GPL-2.0-only"
 67411              }
 67412            },
 67413            {
 67414              "license": {
 67415                "id": "LGPL-2.0-only"
 67416              }
 67417            }
 67418          ],
 67419          "cpe": "cpe:2.3:a:qemu-utils:qemu-utils:1\\:4.2-3ubuntu6.17:*:*:*:*:*:*:*",
 67420          "purl": "pkg:deb/ubuntu/qemu-utils@1:4.2-3ubuntu6.17?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04",
 67421          "swid": {
 67422            "attachment": {}
 67423          },
 67424          "pedigree": {},
 67425          "evidence": {},
 67426          "signature": {
 67427            "signature": {
 67428              "publicKey": {}
 67429            }
 67430          },
 67431          "modelCard": {
 67432            "modelParameters": {
 67433              "approach": {}
 67434            },
 67435            "quantitativeAnalysis": {
 67436              "graphics": {}
 67437            },
 67438            "considerations": {}
 67439          }
 67440        },
 67441        {
 67442          "type": "library",
 67443          "bom-ref": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=34a85b4423ecbe7",
 67444          "supplier": {},
 67445          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67446          "name": "readline-common",
 67447          "version": "8.0-4",
 67448          "licenses": [
 67449            {
 67450              "license": {
 67451                "name": "GFDL"
 67452              }
 67453            },
 67454            {
 67455              "license": {
 67456                "id": "GPL-3.0-only"
 67457              }
 67458            }
 67459          ],
 67460          "cpe": "cpe:2.3:a:readline-common:readline-common:8.0-4:*:*:*:*:*:*:*",
 67461          "purl": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04",
 67462          "swid": {
 67463            "attachment": {}
 67464          },
 67465          "pedigree": {},
 67466          "evidence": {},
 67467          "signature": {
 67468            "signature": {
 67469              "publicKey": {}
 67470            }
 67471          },
 67472          "modelCard": {
 67473            "modelParameters": {
 67474              "approach": {}
 67475            },
 67476            "quantitativeAnalysis": {
 67477              "graphics": {}
 67478            },
 67479            "considerations": {}
 67480          }
 67481        },
 67482        {
 67483          "type": "library",
 67484          "bom-ref": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e98d3334085e4495",
 67485          "supplier": {},
 67486          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67487          "name": "rpcbind",
 67488          "version": "1.2.5-8",
 67489          "licenses": [
 67490            {
 67491              "license": {
 67492                "id": "BSD-3-Clause"
 67493              }
 67494            },
 67495            {
 67496              "license": {
 67497                "id": "BSD-4-Clause"
 67498              }
 67499            },
 67500            {
 67501              "license": {
 67502                "id": "BSD-4-Clause"
 67503              }
 67504            },
 67505            {
 67506              "license": {
 67507                "id": "GPL-2.0-only"
 67508              }
 67509            },
 67510            {
 67511              "license": {
 67512                "id": "GPL-2.0-or-later"
 67513              }
 67514            },
 67515            {
 67516              "license": {
 67517                "id": "GPL-3.0-only"
 67518              }
 67519            },
 67520            {
 67521              "license": {
 67522                "id": "MIT"
 67523              }
 67524            },
 67525            {
 67526              "license": {
 67527                "name": "PERMISSIVE"
 67528              }
 67529            }
 67530          ],
 67531          "cpe": "cpe:2.3:a:rpcbind:rpcbind:1.2.5-8:*:*:*:*:*:*:*",
 67532          "purl": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04",
 67533          "swid": {
 67534            "attachment": {}
 67535          },
 67536          "pedigree": {},
 67537          "evidence": {},
 67538          "signature": {
 67539            "signature": {
 67540              "publicKey": {}
 67541            }
 67542          },
 67543          "modelCard": {
 67544            "modelParameters": {
 67545              "approach": {}
 67546            },
 67547            "quantitativeAnalysis": {
 67548              "graphics": {}
 67549            },
 67550            "considerations": {}
 67551          }
 67552        },
 67553        {
 67554          "type": "library",
 67555          "bom-ref": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=24bbb8989a1870c7",
 67556          "supplier": {},
 67557          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67558          "name": "sed",
 67559          "version": "4.7-1",
 67560          "licenses": [
 67561            {
 67562              "license": {
 67563                "id": "GPL-3.0-only"
 67564              }
 67565            }
 67566          ],
 67567          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
 67568          "purl": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04",
 67569          "swid": {
 67570            "attachment": {}
 67571          },
 67572          "pedigree": {},
 67573          "evidence": {},
 67574          "signature": {
 67575            "signature": {
 67576              "publicKey": {}
 67577            }
 67578          },
 67579          "modelCard": {
 67580            "modelParameters": {
 67581              "approach": {}
 67582            },
 67583            "quantitativeAnalysis": {
 67584              "graphics": {}
 67585            },
 67586            "considerations": {}
 67587          }
 67588        },
 67589        {
 67590          "type": "library",
 67591          "bom-ref": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=7e50cf6ac335106e",
 67592          "supplier": {},
 67593          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67594          "name": "sensible-utils",
 67595          "version": "0.0.12+nmu1",
 67596          "licenses": [
 67597            {
 67598              "license": {
 67599                "name": "All-permissive"
 67600              }
 67601            },
 67602            {
 67603              "license": {
 67604                "id": "GPL-2.0-only"
 67605              }
 67606            },
 67607            {
 67608              "license": {
 67609                "id": "GPL-2.0-or-later"
 67610              }
 67611            },
 67612            {
 67613              "license": {
 67614                "name": "configure"
 67615              }
 67616            },
 67617            {
 67618              "license": {
 67619                "name": "installsh"
 67620              }
 67621            }
 67622          ],
 67623          "cpe": "cpe:2.3:a:sensible-utils:sensible-utils:0.0.12\\+nmu1:*:*:*:*:*:*:*",
 67624          "purl": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04",
 67625          "swid": {
 67626            "attachment": {}
 67627          },
 67628          "pedigree": {},
 67629          "evidence": {},
 67630          "signature": {
 67631            "signature": {
 67632              "publicKey": {}
 67633            }
 67634          },
 67635          "modelCard": {
 67636            "modelParameters": {
 67637              "approach": {}
 67638            },
 67639            "quantitativeAnalysis": {
 67640              "graphics": {}
 67641            },
 67642            "considerations": {}
 67643          }
 67644        },
 67645        {
 67646          "type": "library",
 67647          "bom-ref": "pkg:deb/ubuntu/sg3-utils@1.44-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=794bb1692a1cfa88",
 67648          "supplier": {},
 67649          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67650          "name": "sg3-utils",
 67651          "version": "1.44-1ubuntu2",
 67652          "licenses": [
 67653            {
 67654              "license": {
 67655                "name": "GPL"
 67656              }
 67657            }
 67658          ],
 67659          "cpe": "cpe:2.3:a:sg3-utils:sg3-utils:1.44-1ubuntu2:*:*:*:*:*:*:*",
 67660          "purl": "pkg:deb/ubuntu/sg3-utils@1.44-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
 67661          "swid": {
 67662            "attachment": {}
 67663          },
 67664          "pedigree": {},
 67665          "evidence": {},
 67666          "signature": {
 67667            "signature": {
 67668              "publicKey": {}
 67669            }
 67670          },
 67671          "modelCard": {
 67672            "modelParameters": {
 67673              "approach": {}
 67674            },
 67675            "quantitativeAnalysis": {
 67676              "graphics": {}
 67677            },
 67678            "considerations": {}
 67679          }
 67680        },
 67681        {
 67682          "type": "library",
 67683          "bom-ref": "pkg:deb/ubuntu/shared-mime-info@1.15-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=c15ede029a3e38cd",
 67684          "supplier": {},
 67685          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67686          "name": "shared-mime-info",
 67687          "version": "1.15-1",
 67688          "licenses": [
 67689            {
 67690              "license": {
 67691                "name": "GPL"
 67692              }
 67693            }
 67694          ],
 67695          "cpe": "cpe:2.3:a:shared-mime-info:shared-mime-info:1.15-1:*:*:*:*:*:*:*",
 67696          "purl": "pkg:deb/ubuntu/shared-mime-info@1.15-1?arch=amd64\u0026distro=ubuntu-20.04",
 67697          "swid": {
 67698            "attachment": {}
 67699          },
 67700          "pedigree": {},
 67701          "evidence": {},
 67702          "signature": {
 67703            "signature": {
 67704              "publicKey": {}
 67705            }
 67706          },
 67707          "modelCard": {
 67708            "modelParameters": {
 67709              "approach": {}
 67710            },
 67711            "quantitativeAnalysis": {
 67712              "graphics": {}
 67713            },
 67714            "considerations": {}
 67715          }
 67716        },
 67717        {
 67718          "type": "library",
 67719          "bom-ref": "pkg:deb/ubuntu/sharutils@1:4.15.2-4build1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e920784bf62009c0",
 67720          "supplier": {},
 67721          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67722          "name": "sharutils",
 67723          "version": "1:4.15.2-4build1",
 67724          "licenses": [
 67725            {
 67726              "license": {
 67727                "name": "GFDL"
 67728              }
 67729            },
 67730            {
 67731              "license": {
 67732                "name": "GPL"
 67733              }
 67734            }
 67735          ],
 67736          "cpe": "cpe:2.3:a:sharutils:sharutils:1\\:4.15.2-4build1:*:*:*:*:*:*:*",
 67737          "purl": "pkg:deb/ubuntu/sharutils@1:4.15.2-4build1?arch=amd64\u0026distro=ubuntu-20.04",
 67738          "swid": {
 67739            "attachment": {}
 67740          },
 67741          "pedigree": {},
 67742          "evidence": {},
 67743          "signature": {
 67744            "signature": {
 67745              "publicKey": {}
 67746            }
 67747          },
 67748          "modelCard": {
 67749            "modelParameters": {
 67750              "approach": {}
 67751            },
 67752            "quantitativeAnalysis": {
 67753              "graphics": {}
 67754            },
 67755            "considerations": {}
 67756          }
 67757        },
 67758        {
 67759          "type": "library",
 67760          "bom-ref": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04\u0026package-id=abc451774789c392",
 67761          "supplier": {},
 67762          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67763          "name": "sysvinit-utils",
 67764          "version": "2.96-2.1ubuntu1",
 67765          "licenses": [
 67766            {
 67767              "license": {
 67768                "id": "GPL-2.0-only"
 67769              }
 67770            },
 67771            {
 67772              "license": {
 67773                "id": "GPL-2.0-or-later"
 67774              }
 67775            }
 67776          ],
 67777          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.96-2.1ubuntu1:*:*:*:*:*:*:*",
 67778          "purl": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04",
 67779          "swid": {
 67780            "attachment": {}
 67781          },
 67782          "pedigree": {},
 67783          "evidence": {},
 67784          "signature": {
 67785            "signature": {
 67786              "publicKey": {}
 67787            }
 67788          },
 67789          "modelCard": {
 67790            "modelParameters": {
 67791              "approach": {}
 67792            },
 67793            "quantitativeAnalysis": {
 67794              "graphics": {}
 67795            },
 67796            "considerations": {}
 67797          }
 67798        },
 67799        {
 67800          "type": "library",
 67801          "bom-ref": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=4c6cd0d17cc842e",
 67802          "supplier": {},
 67803          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67804          "name": "tar",
 67805          "version": "1.30+dfsg-7ubuntu0.20.04.1",
 67806          "licenses": [
 67807            {
 67808              "license": {
 67809                "id": "GPL-2.0-only"
 67810              }
 67811            },
 67812            {
 67813              "license": {
 67814                "id": "GPL-3.0-only"
 67815              }
 67816            }
 67817          ],
 67818          "cpe": "cpe:2.3:a:tar:tar:1.30\\+dfsg-7ubuntu0.20.04.1:*:*:*:*:*:*:*",
 67819          "purl": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
 67820          "swid": {
 67821            "attachment": {}
 67822          },
 67823          "pedigree": {},
 67824          "evidence": {},
 67825          "signature": {
 67826            "signature": {
 67827              "publicKey": {}
 67828            }
 67829          },
 67830          "modelCard": {
 67831            "modelParameters": {
 67832              "approach": {}
 67833            },
 67834            "quantitativeAnalysis": {
 67835              "graphics": {}
 67836            },
 67837            "considerations": {}
 67838          }
 67839        },
 67840        {
 67841          "type": "library",
 67842          "bom-ref": "pkg:deb/ubuntu/telnet@0.17-41.2build1?arch=amd64\u0026upstream=netkit-telnet\u0026distro=ubuntu-20.04\u0026package-id=440d9ef0dcd8675e",
 67843          "supplier": {},
 67844          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67845          "name": "telnet",
 67846          "version": "0.17-41.2build1",
 67847          "cpe": "cpe:2.3:a:telnet:telnet:0.17-41.2build1:*:*:*:*:*:*:*",
 67848          "purl": "pkg:deb/ubuntu/telnet@0.17-41.2build1?arch=amd64\u0026upstream=netkit-telnet\u0026distro=ubuntu-20.04",
 67849          "swid": {
 67850            "attachment": {}
 67851          },
 67852          "pedigree": {},
 67853          "evidence": {},
 67854          "signature": {
 67855            "signature": {
 67856              "publicKey": {}
 67857            }
 67858          },
 67859          "modelCard": {
 67860            "modelParameters": {
 67861              "approach": {}
 67862            },
 67863            "quantitativeAnalysis": {
 67864              "graphics": {}
 67865            },
 67866            "considerations": {}
 67867          }
 67868        },
 67869        {
 67870          "type": "library",
 67871          "bom-ref": "pkg:deb/ubuntu/tgt@1.0.66-68.e042fd?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=c8ab64462d876a0c",
 67872          "supplier": {},
 67873          "publisher": "FUJITA Tomonori \u003cfujita.tomonori@lab.ntt.co.jp\u003e",
 67874          "name": "tgt",
 67875          "version": "1.0.66-68.e042fd",
 67876          "cpe": "cpe:2.3:a:tgt:tgt:1.0.66-68.e042fd:*:*:*:*:*:*:*",
 67877          "purl": "pkg:deb/ubuntu/tgt@1.0.66-68.e042fd?arch=amd64\u0026distro=ubuntu-20.04",
 67878          "swid": {
 67879            "attachment": {}
 67880          },
 67881          "pedigree": {},
 67882          "evidence": {},
 67883          "signature": {
 67884            "signature": {
 67885              "publicKey": {}
 67886            }
 67887          },
 67888          "modelCard": {
 67889            "modelParameters": {
 67890              "approach": {}
 67891            },
 67892            "quantitativeAnalysis": {
 67893              "graphics": {}
 67894            },
 67895            "considerations": {}
 67896          }
 67897        },
 67898        {
 67899          "type": "library",
 67900          "bom-ref": "pkg:deb/ubuntu/tzdata@2021a-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04\u0026package-id=aaae4a94d26494c0",
 67901          "supplier": {},
 67902          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67903          "name": "tzdata",
 67904          "version": "2021a-0ubuntu0.20.04",
 67905          "licenses": [
 67906            {
 67907              "license": {
 67908                "id": "ICU"
 67909              }
 67910            }
 67911          ],
 67912          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0ubuntu0.20.04:*:*:*:*:*:*:*",
 67913          "purl": "pkg:deb/ubuntu/tzdata@2021a-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04",
 67914          "swid": {
 67915            "attachment": {}
 67916          },
 67917          "pedigree": {},
 67918          "evidence": {},
 67919          "signature": {
 67920            "signature": {
 67921              "publicKey": {}
 67922            }
 67923          },
 67924          "modelCard": {
 67925            "modelParameters": {
 67926              "approach": {}
 67927            },
 67928            "quantitativeAnalysis": {
 67929              "graphics": {}
 67930            },
 67931            "considerations": {}
 67932          }
 67933        },
 67934        {
 67935          "type": "library",
 67936          "bom-ref": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04\u0026package-id=6d2b18ebcbe1dab7",
 67937          "supplier": {},
 67938          "publisher": "Dimitri John Ledkov \u003cdimitri.ledkov@canonical.com\u003e",
 67939          "name": "ubuntu-keyring",
 67940          "version": "2020.02.11.4",
 67941          "licenses": [
 67942            {
 67943              "license": {
 67944                "name": "GPL"
 67945              }
 67946            }
 67947          ],
 67948          "cpe": "cpe:2.3:a:ubuntu-keyring:ubuntu-keyring:2020.02.11.4:*:*:*:*:*:*:*",
 67949          "purl": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04",
 67950          "swid": {
 67951            "attachment": {}
 67952          },
 67953          "pedigree": {},
 67954          "evidence": {},
 67955          "signature": {
 67956            "signature": {
 67957              "publicKey": {}
 67958            }
 67959          },
 67960          "modelCard": {
 67961            "modelParameters": {
 67962              "approach": {}
 67963            },
 67964            "quantitativeAnalysis": {
 67965              "graphics": {}
 67966            },
 67967            "considerations": {}
 67968          }
 67969        },
 67970        {
 67971          "type": "library",
 67972          "bom-ref": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=ab3b8cc8be7b5655",
 67973          "supplier": {},
 67974          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 67975          "name": "ucf",
 67976          "version": "3.0038+nmu1",
 67977          "licenses": [
 67978            {
 67979              "license": {
 67980                "id": "GPL-2.0-only"
 67981              }
 67982            }
 67983          ],
 67984          "cpe": "cpe:2.3:a:ucf:ucf:3.0038\\+nmu1:*:*:*:*:*:*:*",
 67985          "purl": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04",
 67986          "swid": {
 67987            "attachment": {}
 67988          },
 67989          "pedigree": {},
 67990          "evidence": {},
 67991          "signature": {
 67992            "signature": {
 67993              "publicKey": {}
 67994            }
 67995          },
 67996          "modelCard": {
 67997            "modelParameters": {
 67998              "approach": {}
 67999            },
 68000            "quantitativeAnalysis": {
 68001              "graphics": {}
 68002            },
 68003            "considerations": {}
 68004          }
 68005        },
 68006        {
 68007          "type": "library",
 68008          "bom-ref": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=33e86bd94ef763b6",
 68009          "supplier": {},
 68010          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 68011          "name": "util-linux",
 68012          "version": "2.34-0.1ubuntu9.1",
 68013          "licenses": [
 68014            {
 68015              "license": {
 68016                "id": "BSD-2-Clause"
 68017              }
 68018            },
 68019            {
 68020              "license": {
 68021                "id": "BSD-3-Clause"
 68022              }
 68023            },
 68024            {
 68025              "license": {
 68026                "id": "BSD-4-Clause"
 68027              }
 68028            },
 68029            {
 68030              "license": {
 68031                "id": "GPL-2.0-only"
 68032              }
 68033            },
 68034            {
 68035              "license": {
 68036                "id": "GPL-2.0-or-later"
 68037              }
 68038            },
 68039            {
 68040              "license": {
 68041                "id": "GPL-3.0-only"
 68042              }
 68043            },
 68044            {
 68045              "license": {
 68046                "id": "GPL-3.0-or-later"
 68047              }
 68048            },
 68049            {
 68050              "license": {
 68051                "name": "LGPL"
 68052              }
 68053            },
 68054            {
 68055              "license": {
 68056                "id": "LGPL-2.0-only"
 68057              }
 68058            },
 68059            {
 68060              "license": {
 68061                "id": "LGPL-2.0-or-later"
 68062              }
 68063            },
 68064            {
 68065              "license": {
 68066                "id": "LGPL-2.1-only"
 68067              }
 68068            },
 68069            {
 68070              "license": {
 68071                "id": "LGPL-2.1-or-later"
 68072              }
 68073            },
 68074            {
 68075              "license": {
 68076                "id": "LGPL-3.0-only"
 68077              }
 68078            },
 68079            {
 68080              "license": {
 68081                "id": "LGPL-3.0-or-later"
 68082              }
 68083            },
 68084            {
 68085              "license": {
 68086                "id": "MIT"
 68087              }
 68088            },
 68089            {
 68090              "license": {
 68091                "name": "public-domain"
 68092              }
 68093            }
 68094          ],
 68095          "cpe": "cpe:2.3:a:util-linux:util-linux:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
 68096          "purl": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04",
 68097          "swid": {
 68098            "attachment": {}
 68099          },
 68100          "pedigree": {},
 68101          "evidence": {},
 68102          "signature": {
 68103            "signature": {
 68104              "publicKey": {}
 68105            }
 68106          },
 68107          "modelCard": {
 68108            "modelParameters": {
 68109              "approach": {}
 68110            },
 68111            "quantitativeAnalysis": {
 68112              "graphics": {}
 68113            },
 68114            "considerations": {}
 68115          }
 68116        },
 68117        {
 68118          "type": "library",
 68119          "bom-ref": "pkg:deb/ubuntu/wget@1.20.3-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=2fee01aeba885b76",
 68120          "supplier": {},
 68121          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 68122          "name": "wget",
 68123          "version": "1.20.3-1ubuntu1",
 68124          "licenses": [
 68125            {
 68126              "license": {
 68127                "id": "GFDL-1.2-only"
 68128              }
 68129            },
 68130            {
 68131              "license": {
 68132                "id": "GPL-3.0-only"
 68133              }
 68134            }
 68135          ],
 68136          "cpe": "cpe:2.3:a:wget:wget:1.20.3-1ubuntu1:*:*:*:*:*:*:*",
 68137          "purl": "pkg:deb/ubuntu/wget@1.20.3-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 68138          "swid": {
 68139            "attachment": {}
 68140          },
 68141          "pedigree": {},
 68142          "evidence": {},
 68143          "signature": {
 68144            "signature": {
 68145              "publicKey": {}
 68146            }
 68147          },
 68148          "modelCard": {
 68149            "modelParameters": {
 68150              "approach": {}
 68151            },
 68152            "quantitativeAnalysis": {
 68153              "graphics": {}
 68154            },
 68155            "considerations": {}
 68156          }
 68157        },
 68158        {
 68159          "type": "library",
 68160          "bom-ref": "pkg:deb/ubuntu/xdg-user-dirs@0.17-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=6c580aaac3aa6068",
 68161          "supplier": {},
 68162          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 68163          "name": "xdg-user-dirs",
 68164          "version": "0.17-2ubuntu1",
 68165          "licenses": [
 68166            {
 68167              "license": {
 68168                "id": "GPL-2.0-only"
 68169              }
 68170            }
 68171          ],
 68172          "cpe": "cpe:2.3:a:xdg-user-dirs:xdg-user-dirs:0.17-2ubuntu1:*:*:*:*:*:*:*",
 68173          "purl": "pkg:deb/ubuntu/xdg-user-dirs@0.17-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 68174          "swid": {
 68175            "attachment": {}
 68176          },
 68177          "pedigree": {},
 68178          "evidence": {},
 68179          "signature": {
 68180            "signature": {
 68181              "publicKey": {}
 68182            }
 68183          },
 68184          "modelCard": {
 68185            "modelParameters": {
 68186              "approach": {}
 68187            },
 68188            "quantitativeAnalysis": {
 68189              "graphics": {}
 68190            },
 68191            "considerations": {}
 68192          }
 68193        },
 68194        {
 68195          "type": "library",
 68196          "bom-ref": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=46271b3ba3de19b6",
 68197          "supplier": {},
 68198          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 68199          "name": "xz-utils",
 68200          "version": "5.2.4-1ubuntu1",
 68201          "licenses": [
 68202            {
 68203              "license": {
 68204                "name": "Autoconf"
 68205              }
 68206            },
 68207            {
 68208              "license": {
 68209                "id": "GPL-2.0-only"
 68210              }
 68211            },
 68212            {
 68213              "license": {
 68214                "id": "GPL-2.0-or-later"
 68215              }
 68216            },
 68217            {
 68218              "license": {
 68219                "id": "GPL-3.0-only"
 68220              }
 68221            },
 68222            {
 68223              "license": {
 68224                "id": "LGPL-2.0-only"
 68225              }
 68226            },
 68227            {
 68228              "license": {
 68229                "id": "LGPL-2.1-only"
 68230              }
 68231            },
 68232            {
 68233              "license": {
 68234                "id": "LGPL-2.1-or-later"
 68235              }
 68236            },
 68237            {
 68238              "license": {
 68239                "name": "PD"
 68240              }
 68241            },
 68242            {
 68243              "license": {
 68244                "name": "PD-debian"
 68245              }
 68246            },
 68247            {
 68248              "license": {
 68249                "name": "config-h"
 68250              }
 68251            },
 68252            {
 68253              "license": {
 68254                "name": "noderivs"
 68255              }
 68256            },
 68257            {
 68258              "license": {
 68259                "name": "permissive-fsf"
 68260              }
 68261            },
 68262            {
 68263              "license": {
 68264                "name": "permissive-nowarranty"
 68265              }
 68266            },
 68267            {
 68268              "license": {
 68269                "name": "probably-PD"
 68270              }
 68271            }
 68272          ],
 68273          "cpe": "cpe:2.3:a:xz-utils:xz-utils:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
 68274          "purl": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
 68275          "swid": {
 68276            "attachment": {}
 68277          },
 68278          "pedigree": {},
 68279          "evidence": {},
 68280          "signature": {
 68281            "signature": {
 68282              "publicKey": {}
 68283            }
 68284          },
 68285          "modelCard": {
 68286            "modelParameters": {
 68287              "approach": {}
 68288            },
 68289            "quantitativeAnalysis": {
 68290              "graphics": {}
 68291            },
 68292            "considerations": {}
 68293          }
 68294        },
 68295        {
 68296          "type": "library",
 68297          "bom-ref": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04\u0026package-id=65361fdd213cfcf7",
 68298          "supplier": {},
 68299          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
 68300          "name": "zlib1g",
 68301          "version": "1:1.2.11.dfsg-2ubuntu1.2",
 68302          "licenses": [
 68303            {
 68304              "license": {
 68305                "id": "Zlib"
 68306              }
 68307            }
 68308          ],
 68309          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2ubuntu1.2:*:*:*:*:*:*:*",
 68310          "purl": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04",
 68311          "swid": {
 68312            "attachment": {}
 68313          },
 68314          "pedigree": {},
 68315          "evidence": {},
 68316          "signature": {
 68317            "signature": {
 68318              "publicKey": {}
 68319            }
 68320          },
 68321          "modelCard": {
 68322            "modelParameters": {
 68323              "approach": {}
 68324            },
 68325            "quantitativeAnalysis": {
 68326              "graphics": {}
 68327            },
 68328            "considerations": {}
 68329          }
 68330        },
 68331        {
 68332          "type": "operating-system",
 68333          "supplier": {},
 68334          "name": "ubuntu",
 68335          "version": "20.04",
 68336          "description": "Ubuntu 20.04.3 LTS",
 68337          "swid": {
 68338            "tagId": "ubuntu",
 68339            "name": "ubuntu",
 68340            "version": "20.04",
 68341            "attachment": {}
 68342          },
 68343          "pedigree": {},
 68344          "externalReferences": [
 68345            {
 68346              "url": "https://bugs.launchpad.net/ubuntu/",
 68347              "type": "issue-tracker"
 68348            },
 68349            {
 68350              "url": "https://www.ubuntu.com/",
 68351              "type": "website"
 68352            },
 68353            {
 68354              "url": "https://help.ubuntu.com/",
 68355              "comment": "support",
 68356              "type": "other"
 68357            },
 68358            {
 68359              "url": "https://www.ubuntu.com/legal/terms-and-policies/privacy-policy",
 68360              "comment": "privacyPolicy",
 68361              "type": "other"
 68362            }
 68363          ],
 68364          "evidence": {},
 68365          "signature": {
 68366            "signature": {
 68367              "publicKey": {}
 68368            }
 68369          },
 68370          "modelCard": {
 68371            "modelParameters": {
 68372              "approach": {}
 68373            },
 68374            "quantitativeAnalysis": {
 68375              "graphics": {}
 68376            },
 68377            "considerations": {}
 68378          }
 68379        },
 68380        {
 68381          "type": "library",
 68382          "bom-ref": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-11\u0026package-id=3e9282034226b93f",
 68383          "supplier": {},
 68384          "publisher": "Debian Adduser Developers \u003cadduser@packages.debian.org\u003e",
 68385          "name": "adduser",
 68386          "version": "3.118",
 68387          "licenses": [
 68388            {
 68389              "license": {
 68390                "id": "GPL-2.0-only"
 68391              }
 68392            }
 68393          ],
 68394          "cpe": "cpe:2.3:a:adduser:adduser:3.118:*:*:*:*:*:*:*",
 68395          "purl": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-11",
 68396          "swid": {
 68397            "attachment": {}
 68398          },
 68399          "pedigree": {},
 68400          "evidence": {},
 68401          "signature": {
 68402            "signature": {
 68403              "publicKey": {}
 68404            }
 68405          },
 68406          "modelCard": {
 68407            "modelParameters": {
 68408              "approach": {}
 68409            },
 68410            "quantitativeAnalysis": {
 68411              "graphics": {}
 68412            },
 68413            "considerations": {}
 68414          }
 68415        },
 68416        {
 68417          "type": "library",
 68418          "bom-ref": "pkg:deb/debian/apt@2.2.4?arch=amd64\u0026distro=debian-11\u0026package-id=1cce537379623b25",
 68419          "supplier": {},
 68420          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
 68421          "name": "apt",
 68422          "version": "2.2.4",
 68423          "licenses": [
 68424            {
 68425              "license": {
 68426                "id": "GPL-2.0-only"
 68427              }
 68428            },
 68429            {
 68430              "license": {
 68431                "name": "GPLv2+"
 68432              }
 68433            }
 68434          ],
 68435          "cpe": "cpe:2.3:a:apt:apt:2.2.4:*:*:*:*:*:*:*",
 68436          "purl": "pkg:deb/debian/apt@2.2.4?arch=amd64\u0026distro=debian-11",
 68437          "swid": {
 68438            "attachment": {}
 68439          },
 68440          "pedigree": {},
 68441          "evidence": {},
 68442          "signature": {
 68443            "signature": {
 68444              "publicKey": {}
 68445            }
 68446          },
 68447          "modelCard": {
 68448            "modelParameters": {
 68449              "approach": {}
 68450            },
 68451            "quantitativeAnalysis": {
 68452              "graphics": {}
 68453            },
 68454            "considerations": {}
 68455          }
 68456        },
 68457        {
 68458          "type": "library",
 68459          "bom-ref": "pkg:deb/debian/base-files@11.1+deb11u6?arch=amd64\u0026distro=debian-11\u0026package-id=3c26dd637259b397",
 68460          "supplier": {},
 68461          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
 68462          "name": "base-files",
 68463          "version": "11.1+deb11u6",
 68464          "licenses": [
 68465            {
 68466              "license": {
 68467                "name": "GPL"
 68468              }
 68469            }
 68470          ],
 68471          "cpe": "cpe:2.3:a:base-files:base-files:11.1\\+deb11u6:*:*:*:*:*:*:*",
 68472          "purl": "pkg:deb/debian/base-files@11.1+deb11u6?arch=amd64\u0026distro=debian-11",
 68473          "swid": {
 68474            "attachment": {}
 68475          },
 68476          "pedigree": {},
 68477          "evidence": {},
 68478          "signature": {
 68479            "signature": {
 68480              "publicKey": {}
 68481            }
 68482          },
 68483          "modelCard": {
 68484            "modelParameters": {
 68485              "approach": {}
 68486            },
 68487            "quantitativeAnalysis": {
 68488              "graphics": {}
 68489            },
 68490            "considerations": {}
 68491          }
 68492        },
 68493        {
 68494          "type": "library",
 68495          "bom-ref": "pkg:deb/debian/base-passwd@3.5.51?arch=amd64\u0026distro=debian-11\u0026package-id=7ae3e2ba2e10f31",
 68496          "supplier": {},
 68497          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
 68498          "name": "base-passwd",
 68499          "version": "3.5.51",
 68500          "licenses": [
 68501            {
 68502              "license": {
 68503                "id": "GPL-2.0-only"
 68504              }
 68505            },
 68506            {
 68507              "license": {
 68508                "name": "public-domain"
 68509              }
 68510            }
 68511          ],
 68512          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.51:*:*:*:*:*:*:*",
 68513          "purl": "pkg:deb/debian/base-passwd@3.5.51?arch=amd64\u0026distro=debian-11",
 68514          "swid": {
 68515            "attachment": {}
 68516          },
 68517          "pedigree": {},
 68518          "evidence": {},
 68519          "signature": {
 68520            "signature": {
 68521              "publicKey": {}
 68522            }
 68523          },
 68524          "modelCard": {
 68525            "modelParameters": {
 68526              "approach": {}
 68527            },
 68528            "quantitativeAnalysis": {
 68529              "graphics": {}
 68530            },
 68531            "considerations": {}
 68532          }
 68533        },
 68534        {
 68535          "type": "library",
 68536          "bom-ref": "pkg:deb/debian/bash@5.1-2+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=94b35b4f7d874a43",
 68537          "supplier": {},
 68538          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 68539          "name": "bash",
 68540          "version": "5.1-2+deb11u1",
 68541          "licenses": [
 68542            {
 68543              "license": {
 68544                "id": "GPL-3.0-only"
 68545              }
 68546            }
 68547          ],
 68548          "cpe": "cpe:2.3:a:bash:bash:5.1-2\\+deb11u1:*:*:*:*:*:*:*",
 68549          "purl": "pkg:deb/debian/bash@5.1-2+deb11u1?arch=amd64\u0026distro=debian-11",
 68550          "swid": {
 68551            "attachment": {}
 68552          },
 68553          "pedigree": {},
 68554          "evidence": {},
 68555          "signature": {
 68556            "signature": {
 68557              "publicKey": {}
 68558            }
 68559          },
 68560          "modelCard": {
 68561            "modelParameters": {
 68562              "approach": {}
 68563            },
 68564            "quantitativeAnalysis": {
 68565              "graphics": {}
 68566            },
 68567            "considerations": {}
 68568          }
 68569        },
 68570        {
 68571          "type": "library",
 68572          "bom-ref": "pkg:deb/debian/bsdutils@1:2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux%402.36.1-8+deb11u1\u0026distro=debian-11\u0026package-id=677e6ace24dce684",
 68573          "supplier": {},
 68574          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 68575          "name": "bsdutils",
 68576          "version": "1:2.36.1-8+deb11u1",
 68577          "licenses": [
 68578            {
 68579              "license": {
 68580                "id": "BSD-2-Clause"
 68581              }
 68582            },
 68583            {
 68584              "license": {
 68585                "id": "BSD-3-Clause"
 68586              }
 68587            },
 68588            {
 68589              "license": {
 68590                "id": "BSD-4-Clause"
 68591              }
 68592            },
 68593            {
 68594              "license": {
 68595                "id": "GPL-2.0-only"
 68596              }
 68597            },
 68598            {
 68599              "license": {
 68600                "id": "GPL-2.0-or-later"
 68601              }
 68602            },
 68603            {
 68604              "license": {
 68605                "id": "GPL-3.0-only"
 68606              }
 68607            },
 68608            {
 68609              "license": {
 68610                "id": "GPL-3.0-or-later"
 68611              }
 68612            },
 68613            {
 68614              "license": {
 68615                "name": "LGPL"
 68616              }
 68617            },
 68618            {
 68619              "license": {
 68620                "id": "LGPL-2.0-only"
 68621              }
 68622            },
 68623            {
 68624              "license": {
 68625                "id": "LGPL-2.0-or-later"
 68626              }
 68627            },
 68628            {
 68629              "license": {
 68630                "id": "LGPL-2.1-only"
 68631              }
 68632            },
 68633            {
 68634              "license": {
 68635                "id": "LGPL-2.1-or-later"
 68636              }
 68637            },
 68638            {
 68639              "license": {
 68640                "id": "LGPL-3.0-only"
 68641              }
 68642            },
 68643            {
 68644              "license": {
 68645                "id": "LGPL-3.0-or-later"
 68646              }
 68647            },
 68648            {
 68649              "license": {
 68650                "id": "MIT"
 68651              }
 68652            },
 68653            {
 68654              "license": {
 68655                "name": "public-domain"
 68656              }
 68657            }
 68658          ],
 68659          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 68660          "purl": "pkg:deb/debian/bsdutils@1:2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux%402.36.1-8+deb11u1\u0026distro=debian-11",
 68661          "swid": {
 68662            "attachment": {}
 68663          },
 68664          "pedigree": {},
 68665          "evidence": {},
 68666          "signature": {
 68667            "signature": {
 68668              "publicKey": {}
 68669            }
 68670          },
 68671          "modelCard": {
 68672            "modelParameters": {
 68673              "approach": {}
 68674            },
 68675            "quantitativeAnalysis": {
 68676              "graphics": {}
 68677            },
 68678            "considerations": {}
 68679          }
 68680        },
 68681        {
 68682          "type": "library",
 68683          "bom-ref": "pkg:deb/debian/ca-certificates@20210119?arch=all\u0026distro=debian-11\u0026package-id=6b7e2b0745c43628",
 68684          "supplier": {},
 68685          "publisher": "Julien Cristau \u003cjcristau@debian.org\u003e",
 68686          "name": "ca-certificates",
 68687          "version": "20210119",
 68688          "licenses": [
 68689            {
 68690              "license": {
 68691                "id": "GPL-2.0-only"
 68692              }
 68693            },
 68694            {
 68695              "license": {
 68696                "id": "GPL-2.0-or-later"
 68697              }
 68698            },
 68699            {
 68700              "license": {
 68701                "id": "MPL-2.0"
 68702              }
 68703            }
 68704          ],
 68705          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20210119:*:*:*:*:*:*:*",
 68706          "purl": "pkg:deb/debian/ca-certificates@20210119?arch=all\u0026distro=debian-11",
 68707          "swid": {
 68708            "attachment": {}
 68709          },
 68710          "pedigree": {},
 68711          "evidence": {},
 68712          "signature": {
 68713            "signature": {
 68714              "publicKey": {}
 68715            }
 68716          },
 68717          "modelCard": {
 68718            "modelParameters": {
 68719              "approach": {}
 68720            },
 68721            "quantitativeAnalysis": {
 68722              "graphics": {}
 68723            },
 68724            "considerations": {}
 68725          }
 68726        },
 68727        {
 68728          "type": "library",
 68729          "bom-ref": "pkg:deb/debian/coreutils@8.32-4+b1?arch=amd64\u0026upstream=coreutils%408.32-4\u0026distro=debian-11\u0026package-id=65bac153c492b66e",
 68730          "supplier": {},
 68731          "publisher": "Michael Stone \u003cmstone@debian.org\u003e",
 68732          "name": "coreutils",
 68733          "version": "8.32-4+b1",
 68734          "licenses": [
 68735            {
 68736              "license": {
 68737                "id": "GPL-3.0-only"
 68738              }
 68739            }
 68740          ],
 68741          "cpe": "cpe:2.3:a:coreutils:coreutils:8.32-4\\+b1:*:*:*:*:*:*:*",
 68742          "purl": "pkg:deb/debian/coreutils@8.32-4+b1?arch=amd64\u0026upstream=coreutils%408.32-4\u0026distro=debian-11",
 68743          "swid": {
 68744            "attachment": {}
 68745          },
 68746          "pedigree": {},
 68747          "evidence": {},
 68748          "signature": {
 68749            "signature": {
 68750              "publicKey": {}
 68751            }
 68752          },
 68753          "modelCard": {
 68754            "modelParameters": {
 68755              "approach": {}
 68756            },
 68757            "quantitativeAnalysis": {
 68758              "graphics": {}
 68759            },
 68760            "considerations": {}
 68761          }
 68762        },
 68763        {
 68764          "type": "library",
 68765          "bom-ref": "pkg:deb/debian/curl@7.74.0-1.3+deb11u7?arch=amd64\u0026distro=debian-11\u0026package-id=cfa0e9d1620ffa4d",
 68766          "supplier": {},
 68767          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
 68768          "name": "curl",
 68769          "version": "7.74.0-1.3+deb11u7",
 68770          "licenses": [
 68771            {
 68772              "license": {
 68773                "id": "BSD-3-Clause"
 68774              }
 68775            },
 68776            {
 68777              "license": {
 68778                "id": "BSD-4-Clause"
 68779              }
 68780            },
 68781            {
 68782              "license": {
 68783                "id": "ISC"
 68784              }
 68785            },
 68786            {
 68787              "license": {
 68788                "id": "curl"
 68789              }
 68790            },
 68791            {
 68792              "license": {
 68793                "name": "other"
 68794              }
 68795            },
 68796            {
 68797              "license": {
 68798                "name": "public-domain"
 68799              }
 68800            }
 68801          ],
 68802          "cpe": "cpe:2.3:a:curl:curl:7.74.0-1.3\\+deb11u7:*:*:*:*:*:*:*",
 68803          "purl": "pkg:deb/debian/curl@7.74.0-1.3+deb11u7?arch=amd64\u0026distro=debian-11",
 68804          "swid": {
 68805            "attachment": {}
 68806          },
 68807          "pedigree": {},
 68808          "evidence": {},
 68809          "signature": {
 68810            "signature": {
 68811              "publicKey": {}
 68812            }
 68813          },
 68814          "modelCard": {
 68815            "modelParameters": {
 68816              "approach": {}
 68817            },
 68818            "quantitativeAnalysis": {
 68819              "graphics": {}
 68820            },
 68821            "considerations": {}
 68822          }
 68823        },
 68824        {
 68825          "type": "library",
 68826          "bom-ref": "pkg:deb/debian/dash@0.5.11+git20200708+dd9ef66-5?arch=amd64\u0026distro=debian-11\u0026package-id=19db7775ce4c27be",
 68827          "supplier": {},
 68828          "publisher": "Andrej Shadura \u003candrewsh@debian.org\u003e",
 68829          "name": "dash",
 68830          "version": "0.5.11+git20200708+dd9ef66-5",
 68831          "licenses": [
 68832            {
 68833              "license": {
 68834                "id": "BSD-3-Clause"
 68835              }
 68836            },
 68837            {
 68838              "license": {
 68839                "id": "BSD-3-Clause"
 68840              }
 68841            },
 68842            {
 68843              "license": {
 68844                "name": "Expat"
 68845              }
 68846            },
 68847            {
 68848              "license": {
 68849                "id": "FSFUL"
 68850              }
 68851            },
 68852            {
 68853              "license": {
 68854                "id": "FSFULLR"
 68855              }
 68856            },
 68857            {
 68858              "license": {
 68859                "id": "GPL-2.0-only"
 68860              }
 68861            },
 68862            {
 68863              "license": {
 68864                "id": "GPL-2.0-or-later"
 68865              }
 68866            },
 68867            {
 68868              "license": {
 68869                "name": "public-domain"
 68870              }
 68871            }
 68872          ],
 68873          "cpe": "cpe:2.3:a:dash:dash:0.5.11\\+git20200708\\+dd9ef66-5:*:*:*:*:*:*:*",
 68874          "purl": "pkg:deb/debian/dash@0.5.11+git20200708+dd9ef66-5?arch=amd64\u0026distro=debian-11",
 68875          "swid": {
 68876            "attachment": {}
 68877          },
 68878          "pedigree": {},
 68879          "evidence": {},
 68880          "signature": {
 68881            "signature": {
 68882              "publicKey": {}
 68883            }
 68884          },
 68885          "modelCard": {
 68886            "modelParameters": {
 68887              "approach": {}
 68888            },
 68889            "quantitativeAnalysis": {
 68890              "graphics": {}
 68891            },
 68892            "considerations": {}
 68893          }
 68894        },
 68895        {
 68896          "type": "library",
 68897          "bom-ref": "pkg:deb/debian/debconf@1.5.77?arch=all\u0026distro=debian-11\u0026package-id=99525df5637687bd",
 68898          "supplier": {},
 68899          "publisher": "Debconf Developers \u003cdebconf-devel@lists.alioth.debian.org\u003e",
 68900          "name": "debconf",
 68901          "version": "1.5.77",
 68902          "licenses": [
 68903            {
 68904              "license": {
 68905                "id": "BSD-2-Clause"
 68906              }
 68907            }
 68908          ],
 68909          "cpe": "cpe:2.3:a:debconf:debconf:1.5.77:*:*:*:*:*:*:*",
 68910          "purl": "pkg:deb/debian/debconf@1.5.77?arch=all\u0026distro=debian-11",
 68911          "swid": {
 68912            "attachment": {}
 68913          },
 68914          "pedigree": {},
 68915          "evidence": {},
 68916          "signature": {
 68917            "signature": {
 68918              "publicKey": {}
 68919            }
 68920          },
 68921          "modelCard": {
 68922            "modelParameters": {
 68923              "approach": {}
 68924            },
 68925            "quantitativeAnalysis": {
 68926              "graphics": {}
 68927            },
 68928            "considerations": {}
 68929          }
 68930        },
 68931        {
 68932          "type": "library",
 68933          "bom-ref": "pkg:deb/debian/debian-archive-keyring@2021.1.1?arch=all\u0026distro=debian-11\u0026package-id=f7fcb44a58e72708",
 68934          "supplier": {},
 68935          "publisher": "Debian Release Team \u003cpackages@release.debian.org\u003e",
 68936          "name": "debian-archive-keyring",
 68937          "version": "2021.1.1",
 68938          "licenses": [
 68939            {
 68940              "license": {
 68941                "name": "GPL"
 68942              }
 68943            }
 68944          ],
 68945          "cpe": "cpe:2.3:a:debian-archive-keyring:debian-archive-keyring:2021.1.1:*:*:*:*:*:*:*",
 68946          "purl": "pkg:deb/debian/debian-archive-keyring@2021.1.1?arch=all\u0026distro=debian-11",
 68947          "swid": {
 68948            "attachment": {}
 68949          },
 68950          "pedigree": {},
 68951          "evidence": {},
 68952          "signature": {
 68953            "signature": {
 68954              "publicKey": {}
 68955            }
 68956          },
 68957          "modelCard": {
 68958            "modelParameters": {
 68959              "approach": {}
 68960            },
 68961            "quantitativeAnalysis": {
 68962              "graphics": {}
 68963            },
 68964            "considerations": {}
 68965          }
 68966        },
 68967        {
 68968          "type": "library",
 68969          "bom-ref": "pkg:deb/debian/debianutils@4.11.2?arch=amd64\u0026distro=debian-11\u0026package-id=4cd4f150dae8c295",
 68970          "supplier": {},
 68971          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
 68972          "name": "debianutils",
 68973          "version": "4.11.2",
 68974          "licenses": [
 68975            {
 68976              "license": {
 68977                "id": "GPL-2.0-only"
 68978              }
 68979            }
 68980          ],
 68981          "cpe": "cpe:2.3:a:debianutils:debianutils:4.11.2:*:*:*:*:*:*:*",
 68982          "purl": "pkg:deb/debian/debianutils@4.11.2?arch=amd64\u0026distro=debian-11",
 68983          "swid": {
 68984            "attachment": {}
 68985          },
 68986          "pedigree": {},
 68987          "evidence": {},
 68988          "signature": {
 68989            "signature": {
 68990              "publicKey": {}
 68991            }
 68992          },
 68993          "modelCard": {
 68994            "modelParameters": {
 68995              "approach": {}
 68996            },
 68997            "quantitativeAnalysis": {
 68998              "graphics": {}
 68999            },
 69000            "considerations": {}
 69001          }
 69002        },
 69003        {
 69004          "type": "library",
 69005          "bom-ref": "pkg:deb/debian/diffutils@1:3.7-5?arch=amd64\u0026distro=debian-11\u0026package-id=9133f9a320bf77e1",
 69006          "supplier": {},
 69007          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
 69008          "name": "diffutils",
 69009          "version": "1:3.7-5",
 69010          "licenses": [
 69011            {
 69012              "license": {
 69013                "name": "GFDL"
 69014              }
 69015            },
 69016            {
 69017              "license": {
 69018                "name": "GPL"
 69019              }
 69020            }
 69021          ],
 69022          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-5:*:*:*:*:*:*:*",
 69023          "purl": "pkg:deb/debian/diffutils@1:3.7-5?arch=amd64\u0026distro=debian-11",
 69024          "swid": {
 69025            "attachment": {}
 69026          },
 69027          "pedigree": {},
 69028          "evidence": {},
 69029          "signature": {
 69030            "signature": {
 69031              "publicKey": {}
 69032            }
 69033          },
 69034          "modelCard": {
 69035            "modelParameters": {
 69036              "approach": {}
 69037            },
 69038            "quantitativeAnalysis": {
 69039              "graphics": {}
 69040            },
 69041            "considerations": {}
 69042          }
 69043        },
 69044        {
 69045          "type": "library",
 69046          "bom-ref": "pkg:deb/debian/dpkg@1.20.12?arch=amd64\u0026distro=debian-11\u0026package-id=3dbbad249b74a866",
 69047          "supplier": {},
 69048          "publisher": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e",
 69049          "name": "dpkg",
 69050          "version": "1.20.12",
 69051          "licenses": [
 69052            {
 69053              "license": {
 69054                "id": "BSD-2-Clause"
 69055              }
 69056            },
 69057            {
 69058              "license": {
 69059                "id": "GPL-2.0-only"
 69060              }
 69061            },
 69062            {
 69063              "license": {
 69064                "id": "GPL-2.0-or-later"
 69065              }
 69066            },
 69067            {
 69068              "license": {
 69069                "name": "public-domain-md5"
 69070              }
 69071            },
 69072            {
 69073              "license": {
 69074                "name": "public-domain-s-s-d"
 69075              }
 69076            }
 69077          ],
 69078          "cpe": "cpe:2.3:a:dpkg:dpkg:1.20.12:*:*:*:*:*:*:*",
 69079          "purl": "pkg:deb/debian/dpkg@1.20.12?arch=amd64\u0026distro=debian-11",
 69080          "swid": {
 69081            "attachment": {}
 69082          },
 69083          "pedigree": {},
 69084          "evidence": {},
 69085          "signature": {
 69086            "signature": {
 69087              "publicKey": {}
 69088            }
 69089          },
 69090          "modelCard": {
 69091            "modelParameters": {
 69092              "approach": {}
 69093            },
 69094            "quantitativeAnalysis": {
 69095              "graphics": {}
 69096            },
 69097            "considerations": {}
 69098          }
 69099        },
 69100        {
 69101          "type": "library",
 69102          "bom-ref": "pkg:deb/debian/e2fsprogs@1.46.2-2?arch=amd64\u0026distro=debian-11\u0026package-id=7c4baa682137e759",
 69103          "supplier": {},
 69104          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 69105          "name": "e2fsprogs",
 69106          "version": "1.46.2-2",
 69107          "licenses": [
 69108            {
 69109              "license": {
 69110                "id": "GPL-2.0-only"
 69111              }
 69112            },
 69113            {
 69114              "license": {
 69115                "id": "LGPL-2.0-only"
 69116              }
 69117            }
 69118          ],
 69119          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.46.2-2:*:*:*:*:*:*:*",
 69120          "purl": "pkg:deb/debian/e2fsprogs@1.46.2-2?arch=amd64\u0026distro=debian-11",
 69121          "swid": {
 69122            "attachment": {}
 69123          },
 69124          "pedigree": {},
 69125          "evidence": {},
 69126          "signature": {
 69127            "signature": {
 69128              "publicKey": {}
 69129            }
 69130          },
 69131          "modelCard": {
 69132            "modelParameters": {
 69133              "approach": {}
 69134            },
 69135            "quantitativeAnalysis": {
 69136              "graphics": {}
 69137            },
 69138            "considerations": {}
 69139          }
 69140        },
 69141        {
 69142          "type": "library",
 69143          "bom-ref": "pkg:deb/debian/findutils@4.8.0-1?arch=amd64\u0026distro=debian-11\u0026package-id=b503e3d45616f33c",
 69144          "supplier": {},
 69145          "publisher": "Andreas Metzler \u003cametzler@debian.org\u003e",
 69146          "name": "findutils",
 69147          "version": "4.8.0-1",
 69148          "licenses": [
 69149            {
 69150              "license": {
 69151                "id": "GFDL-1.3-only"
 69152              }
 69153            },
 69154            {
 69155              "license": {
 69156                "id": "GPL-3.0-only"
 69157              }
 69158            }
 69159          ],
 69160          "cpe": "cpe:2.3:a:findutils:findutils:4.8.0-1:*:*:*:*:*:*:*",
 69161          "purl": "pkg:deb/debian/findutils@4.8.0-1?arch=amd64\u0026distro=debian-11",
 69162          "swid": {
 69163            "attachment": {}
 69164          },
 69165          "pedigree": {},
 69166          "evidence": {},
 69167          "signature": {
 69168            "signature": {
 69169              "publicKey": {}
 69170            }
 69171          },
 69172          "modelCard": {
 69173            "modelParameters": {
 69174              "approach": {}
 69175            },
 69176            "quantitativeAnalysis": {
 69177              "graphics": {}
 69178            },
 69179            "considerations": {}
 69180          }
 69181        },
 69182        {
 69183          "type": "library",
 69184          "bom-ref": "pkg:deb/debian/fontconfig-config@2.13.1-4.2?arch=all\u0026upstream=fontconfig\u0026distro=debian-11\u0026package-id=4cbb1169d85c98",
 69185          "supplier": {},
 69186          "publisher": "Debian freedesktop.org maintainers \u003cpkg-freedesktop-maintainers@lists.alioth.debian.org\u003e",
 69187          "name": "fontconfig-config",
 69188          "version": "2.13.1-4.2",
 69189          "cpe": "cpe:2.3:a:fontconfig-config:fontconfig-config:2.13.1-4.2:*:*:*:*:*:*:*",
 69190          "purl": "pkg:deb/debian/fontconfig-config@2.13.1-4.2?arch=all\u0026upstream=fontconfig\u0026distro=debian-11",
 69191          "swid": {
 69192            "attachment": {}
 69193          },
 69194          "pedigree": {},
 69195          "evidence": {},
 69196          "signature": {
 69197            "signature": {
 69198              "publicKey": {}
 69199            }
 69200          },
 69201          "modelCard": {
 69202            "modelParameters": {
 69203              "approach": {}
 69204            },
 69205            "quantitativeAnalysis": {
 69206              "graphics": {}
 69207            },
 69208            "considerations": {}
 69209          }
 69210        },
 69211        {
 69212          "type": "library",
 69213          "bom-ref": "pkg:deb/debian/fonts-dejavu-core@2.37-2?arch=all\u0026upstream=fonts-dejavu\u0026distro=debian-11\u0026package-id=6c1e339e269277ec",
 69214          "supplier": {},
 69215          "publisher": "Debian Fonts Task Force \u003cdebian-fonts@lists.debian.org\u003e",
 69216          "name": "fonts-dejavu-core",
 69217          "version": "2.37-2",
 69218          "licenses": [
 69219            {
 69220              "license": {
 69221                "id": "GPL-2.0-only"
 69222              }
 69223            },
 69224            {
 69225              "license": {
 69226                "id": "GPL-2.0-or-later"
 69227              }
 69228            },
 69229            {
 69230              "license": {
 69231                "id": "Bitstream-Vera"
 69232              }
 69233            }
 69234          ],
 69235          "cpe": "cpe:2.3:a:fonts-dejavu-core:fonts-dejavu-core:2.37-2:*:*:*:*:*:*:*",
 69236          "purl": "pkg:deb/debian/fonts-dejavu-core@2.37-2?arch=all\u0026upstream=fonts-dejavu\u0026distro=debian-11",
 69237          "swid": {
 69238            "attachment": {}
 69239          },
 69240          "pedigree": {},
 69241          "evidence": {},
 69242          "signature": {
 69243            "signature": {
 69244              "publicKey": {}
 69245            }
 69246          },
 69247          "modelCard": {
 69248            "modelParameters": {
 69249              "approach": {}
 69250            },
 69251            "quantitativeAnalysis": {
 69252              "graphics": {}
 69253            },
 69254            "considerations": {}
 69255          }
 69256        },
 69257        {
 69258          "type": "library",
 69259          "bom-ref": "pkg:deb/debian/gcc-10-base@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=742204f033ae5a1e",
 69260          "supplier": {},
 69261          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 69262          "name": "gcc-10-base",
 69263          "version": "10.2.1-6",
 69264          "licenses": [
 69265            {
 69266              "license": {
 69267                "name": "Artistic"
 69268              }
 69269            },
 69270            {
 69271              "license": {
 69272                "id": "GFDL-1.2-only"
 69273              }
 69274            },
 69275            {
 69276              "license": {
 69277                "name": "GPL"
 69278              }
 69279            },
 69280            {
 69281              "license": {
 69282                "id": "GPL-2.0-only"
 69283              }
 69284            },
 69285            {
 69286              "license": {
 69287                "id": "GPL-3.0-only"
 69288              }
 69289            },
 69290            {
 69291              "license": {
 69292                "name": "LGPL"
 69293              }
 69294            }
 69295          ],
 69296          "cpe": "cpe:2.3:a:gcc-10-base:gcc-10-base:10.2.1-6:*:*:*:*:*:*:*",
 69297          "purl": "pkg:deb/debian/gcc-10-base@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
 69298          "swid": {
 69299            "attachment": {}
 69300          },
 69301          "pedigree": {},
 69302          "evidence": {},
 69303          "signature": {
 69304            "signature": {
 69305              "publicKey": {}
 69306            }
 69307          },
 69308          "modelCard": {
 69309            "modelParameters": {
 69310              "approach": {}
 69311            },
 69312            "quantitativeAnalysis": {
 69313              "graphics": {}
 69314            },
 69315            "considerations": {}
 69316          }
 69317        },
 69318        {
 69319          "type": "library",
 69320          "bom-ref": "pkg:deb/debian/gcc-9-base@9.3.0-22?arch=amd64\u0026upstream=gcc-9\u0026distro=debian-11\u0026package-id=57c0768e353bbfc8",
 69321          "supplier": {},
 69322          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 69323          "name": "gcc-9-base",
 69324          "version": "9.3.0-22",
 69325          "licenses": [
 69326            {
 69327              "license": {
 69328                "name": "Artistic"
 69329              }
 69330            },
 69331            {
 69332              "license": {
 69333                "id": "GFDL-1.2-only"
 69334              }
 69335            },
 69336            {
 69337              "license": {
 69338                "name": "GPL"
 69339              }
 69340            },
 69341            {
 69342              "license": {
 69343                "id": "GPL-2.0-only"
 69344              }
 69345            },
 69346            {
 69347              "license": {
 69348                "id": "GPL-3.0-only"
 69349              }
 69350            },
 69351            {
 69352              "license": {
 69353                "name": "LGPL"
 69354              }
 69355            },
 69356            {
 69357              "license": {
 69358                "id": "LGPL-2.1-or-later"
 69359              }
 69360            }
 69361          ],
 69362          "cpe": "cpe:2.3:a:gcc-9-base:gcc-9-base:9.3.0-22:*:*:*:*:*:*:*",
 69363          "purl": "pkg:deb/debian/gcc-9-base@9.3.0-22?arch=amd64\u0026upstream=gcc-9\u0026distro=debian-11",
 69364          "swid": {
 69365            "attachment": {}
 69366          },
 69367          "pedigree": {},
 69368          "evidence": {},
 69369          "signature": {
 69370            "signature": {
 69371              "publicKey": {}
 69372            }
 69373          },
 69374          "modelCard": {
 69375            "modelParameters": {
 69376              "approach": {}
 69377            },
 69378            "quantitativeAnalysis": {
 69379              "graphics": {}
 69380            },
 69381            "considerations": {}
 69382          }
 69383        },
 69384        {
 69385          "type": "library",
 69386          "bom-ref": "pkg:deb/debian/gettext-base@0.21-4?arch=amd64\u0026upstream=gettext\u0026distro=debian-11\u0026package-id=19929d95b155bf28",
 69387          "supplier": {},
 69388          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
 69389          "name": "gettext-base",
 69390          "version": "0.21-4",
 69391          "licenses": [
 69392            {
 69393              "license": {
 69394                "name": "GFDL"
 69395              }
 69396            },
 69397            {
 69398              "license": {
 69399                "name": "GPL"
 69400              }
 69401            },
 69402            {
 69403              "license": {
 69404                "name": "LGPL"
 69405              }
 69406            }
 69407          ],
 69408          "cpe": "cpe:2.3:a:gettext-base:gettext-base:0.21-4:*:*:*:*:*:*:*",
 69409          "purl": "pkg:deb/debian/gettext-base@0.21-4?arch=amd64\u0026upstream=gettext\u0026distro=debian-11",
 69410          "swid": {
 69411            "attachment": {}
 69412          },
 69413          "pedigree": {},
 69414          "evidence": {},
 69415          "signature": {
 69416            "signature": {
 69417              "publicKey": {}
 69418            }
 69419          },
 69420          "modelCard": {
 69421            "modelParameters": {
 69422              "approach": {}
 69423            },
 69424            "quantitativeAnalysis": {
 69425              "graphics": {}
 69426            },
 69427            "considerations": {}
 69428          }
 69429        },
 69430        {
 69431          "type": "library",
 69432          "bom-ref": "pkg:golang/github.com/burntsushi/toml@v1.2.1?package-id=4993a0ceaabfa89",
 69433          "supplier": {},
 69434          "name": "github.com/BurntSushi/toml",
 69435          "version": "v1.2.1",
 69436          "cpe": "cpe:2.3:a:BurntSushi:toml:v1.2.1:*:*:*:*:*:*:*",
 69437          "purl": "pkg:golang/github.com/BurntSushi/toml@v1.2.1",
 69438          "swid": {
 69439            "attachment": {}
 69440          },
 69441          "pedigree": {},
 69442          "evidence": {},
 69443          "signature": {
 69444            "signature": {
 69445              "publicKey": {}
 69446            }
 69447          },
 69448          "modelCard": {
 69449            "modelParameters": {
 69450              "approach": {}
 69451            },
 69452            "quantitativeAnalysis": {
 69453              "graphics": {}
 69454            },
 69455            "considerations": {}
 69456          }
 69457        },
 69458        {
 69459          "type": "library",
 69460          "bom-ref": "pkg:golang/github.com/masterminds/goutils@v1.1.1?package-id=ea2fd87e5c6b0bda",
 69461          "supplier": {},
 69462          "name": "github.com/Masterminds/goutils",
 69463          "version": "v1.1.1",
 69464          "cpe": "cpe:2.3:a:Masterminds:goutils:v1.1.1:*:*:*:*:*:*:*",
 69465          "purl": "pkg:golang/github.com/Masterminds/goutils@v1.1.1",
 69466          "swid": {
 69467            "attachment": {}
 69468          },
 69469          "pedigree": {},
 69470          "evidence": {},
 69471          "signature": {
 69472            "signature": {
 69473              "publicKey": {}
 69474            }
 69475          },
 69476          "modelCard": {
 69477            "modelParameters": {
 69478              "approach": {}
 69479            },
 69480            "quantitativeAnalysis": {
 69481              "graphics": {}
 69482            },
 69483            "considerations": {}
 69484          }
 69485        },
 69486        {
 69487          "type": "library",
 69488          "bom-ref": "pkg:golang/github.com/masterminds/semver/v3@v3.2.0?package-id=acdf5909fa386e8c",
 69489          "supplier": {},
 69490          "name": "github.com/Masterminds/semver/v3",
 69491          "version": "v3.2.0",
 69492          "cpe": "cpe:2.3:a:Masterminds:semver\\/v3:v3.2.0:*:*:*:*:*:*:*",
 69493          "purl": "pkg:golang/github.com/Masterminds/semver/v3@v3.2.0",
 69494          "swid": {
 69495            "attachment": {}
 69496          },
 69497          "pedigree": {},
 69498          "evidence": {},
 69499          "signature": {
 69500            "signature": {
 69501              "publicKey": {}
 69502            }
 69503          },
 69504          "modelCard": {
 69505            "modelParameters": {
 69506              "approach": {}
 69507            },
 69508            "quantitativeAnalysis": {
 69509              "graphics": {}
 69510            },
 69511            "considerations": {}
 69512          }
 69513        },
 69514        {
 69515          "type": "library",
 69516          "bom-ref": "pkg:golang/github.com/masterminds/sprig/v3@v3.2.3?package-id=9577e423600de01f",
 69517          "supplier": {},
 69518          "name": "github.com/Masterminds/sprig/v3",
 69519          "version": "v3.2.3",
 69520          "cpe": "cpe:2.3:a:Masterminds:sprig\\/v3:v3.2.3:*:*:*:*:*:*:*",
 69521          "purl": "pkg:golang/github.com/Masterminds/sprig/v3@v3.2.3",
 69522          "swid": {
 69523            "attachment": {}
 69524          },
 69525          "pedigree": {},
 69526          "evidence": {},
 69527          "signature": {
 69528            "signature": {
 69529              "publicKey": {}
 69530            }
 69531          },
 69532          "modelCard": {
 69533            "modelParameters": {
 69534              "approach": {}
 69535            },
 69536            "quantitativeAnalysis": {
 69537              "graphics": {}
 69538            },
 69539            "considerations": {}
 69540          }
 69541        },
 69542        {
 69543          "type": "library",
 69544          "bom-ref": "pkg:golang/github.com/containerd/containerd@v1.6.18?package-id=31596a8a7b418bf6",
 69545          "supplier": {},
 69546          "name": "github.com/containerd/containerd",
 69547          "version": "v1.6.18",
 69548          "cpe": "cpe:2.3:a:containerd:containerd:v1.6.18:*:*:*:*:*:*:*",
 69549          "purl": "pkg:golang/github.com/containerd/containerd@v1.6.18",
 69550          "swid": {
 69551            "attachment": {}
 69552          },
 69553          "pedigree": {},
 69554          "evidence": {},
 69555          "signature": {
 69556            "signature": {
 69557              "publicKey": {}
 69558            }
 69559          },
 69560          "modelCard": {
 69561            "modelParameters": {
 69562              "approach": {}
 69563            },
 69564            "quantitativeAnalysis": {
 69565              "graphics": {}
 69566            },
 69567            "considerations": {}
 69568          }
 69569        },
 69570        {
 69571          "type": "library",
 69572          "bom-ref": "pkg:golang/github.com/daviddengcn/go-colortext@v1.0.0?package-id=82d258407d30e9c7",
 69573          "supplier": {},
 69574          "name": "github.com/daviddengcn/go-colortext",
 69575          "version": "v1.0.0",
 69576          "cpe": "cpe:2.3:a:daviddengcn:go-colortext:v1.0.0:*:*:*:*:*:*:*",
 69577          "purl": "pkg:golang/github.com/daviddengcn/go-colortext@v1.0.0",
 69578          "swid": {
 69579            "attachment": {}
 69580          },
 69581          "pedigree": {},
 69582          "evidence": {},
 69583          "signature": {
 69584            "signature": {
 69585              "publicKey": {}
 69586            }
 69587          },
 69588          "modelCard": {
 69589            "modelParameters": {
 69590              "approach": {}
 69591            },
 69592            "quantitativeAnalysis": {
 69593              "graphics": {}
 69594            },
 69595            "considerations": {}
 69596          }
 69597        },
 69598        {
 69599          "type": "library",
 69600          "bom-ref": "pkg:golang/github.com/docker/docker@v23.0.3+incompatible?package-id=b089572c8ed99592",
 69601          "supplier": {},
 69602          "name": "github.com/docker/docker",
 69603          "version": "v23.0.3+incompatible",
 69604          "cpe": "cpe:2.3:a:docker:docker:v23.0.3\\+incompatible:*:*:*:*:*:*:*",
 69605          "purl": "pkg:golang/github.com/docker/docker@v23.0.3+incompatible",
 69606          "swid": {
 69607            "attachment": {}
 69608          },
 69609          "pedigree": {},
 69610          "evidence": {},
 69611          "signature": {
 69612            "signature": {
 69613              "publicKey": {}
 69614            }
 69615          },
 69616          "modelCard": {
 69617            "modelParameters": {
 69618              "approach": {}
 69619            },
 69620            "quantitativeAnalysis": {
 69621              "graphics": {}
 69622            },
 69623            "considerations": {}
 69624          }
 69625        },
 69626        {
 69627          "type": "library",
 69628          "bom-ref": "pkg:golang/github.com/docker/go-connections@v0.4.0?package-id=a8defa009bf0f86e",
 69629          "supplier": {},
 69630          "name": "github.com/docker/go-connections",
 69631          "version": "v0.4.0",
 69632          "cpe": "cpe:2.3:a:docker:go-connections:v0.4.0:*:*:*:*:*:*:*",
 69633          "purl": "pkg:golang/github.com/docker/go-connections@v0.4.0",
 69634          "swid": {
 69635            "attachment": {}
 69636          },
 69637          "pedigree": {},
 69638          "evidence": {},
 69639          "signature": {
 69640            "signature": {
 69641              "publicKey": {}
 69642            }
 69643          },
 69644          "modelCard": {
 69645            "modelParameters": {
 69646              "approach": {}
 69647            },
 69648            "quantitativeAnalysis": {
 69649              "graphics": {}
 69650            },
 69651            "considerations": {}
 69652          }
 69653        },
 69654        {
 69655          "type": "library",
 69656          "bom-ref": "pkg:golang/github.com/docker/go-units@v0.5.0?package-id=d532d3e73230f49",
 69657          "supplier": {},
 69658          "name": "github.com/docker/go-units",
 69659          "version": "v0.5.0",
 69660          "cpe": "cpe:2.3:a:docker:go-units:v0.5.0:*:*:*:*:*:*:*",
 69661          "purl": "pkg:golang/github.com/docker/go-units@v0.5.0",
 69662          "swid": {
 69663            "attachment": {}
 69664          },
 69665          "pedigree": {},
 69666          "evidence": {},
 69667          "signature": {
 69668            "signature": {
 69669              "publicKey": {}
 69670            }
 69671          },
 69672          "modelCard": {
 69673            "modelParameters": {
 69674              "approach": {}
 69675            },
 69676            "quantitativeAnalysis": {
 69677              "graphics": {}
 69678            },
 69679            "considerations": {}
 69680          }
 69681        },
 69682        {
 69683          "type": "library",
 69684          "bom-ref": "pkg:golang/github.com/fsouza/go-dockerclient@v1.9.7?package-id=7ef0e9cf0f6c74c8",
 69685          "supplier": {},
 69686          "name": "github.com/fsouza/go-dockerclient",
 69687          "version": "v1.9.7",
 69688          "cpe": "cpe:2.3:a:fsouza:go-dockerclient:v1.9.7:*:*:*:*:*:*:*",
 69689          "purl": "pkg:golang/github.com/fsouza/go-dockerclient@v1.9.7",
 69690          "swid": {
 69691            "attachment": {}
 69692          },
 69693          "pedigree": {},
 69694          "evidence": {},
 69695          "signature": {
 69696            "signature": {
 69697              "publicKey": {}
 69698            }
 69699          },
 69700          "modelCard": {
 69701            "modelParameters": {
 69702              "approach": {}
 69703            },
 69704            "quantitativeAnalysis": {
 69705              "graphics": {}
 69706            },
 69707            "considerations": {}
 69708          }
 69709        },
 69710        {
 69711          "type": "library",
 69712          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.2?package-id=6c71296d126a9acf",
 69713          "supplier": {},
 69714          "name": "github.com/gogo/protobuf",
 69715          "version": "v1.3.2",
 69716          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.2:*:*:*:*:*:*:*",
 69717          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.2",
 69718          "swid": {
 69719            "attachment": {}
 69720          },
 69721          "pedigree": {},
 69722          "evidence": {},
 69723          "signature": {
 69724            "signature": {
 69725              "publicKey": {}
 69726            }
 69727          },
 69728          "modelCard": {
 69729            "modelParameters": {
 69730              "approach": {}
 69731            },
 69732            "quantitativeAnalysis": {
 69733              "graphics": {}
 69734            },
 69735            "considerations": {}
 69736          }
 69737        },
 69738        {
 69739          "type": "library",
 69740          "bom-ref": "pkg:golang/github.com/google/uuid@v1.2.0?package-id=93206d2d4782844c",
 69741          "supplier": {},
 69742          "name": "github.com/google/uuid",
 69743          "version": "v1.2.0",
 69744          "cpe": "cpe:2.3:a:google:uuid:v1.2.0:*:*:*:*:*:*:*",
 69745          "purl": "pkg:golang/github.com/google/uuid@v1.2.0",
 69746          "swid": {
 69747            "attachment": {}
 69748          },
 69749          "pedigree": {},
 69750          "evidence": {},
 69751          "signature": {
 69752            "signature": {
 69753              "publicKey": {}
 69754            }
 69755          },
 69756          "modelCard": {
 69757            "modelParameters": {
 69758              "approach": {}
 69759            },
 69760            "quantitativeAnalysis": {
 69761              "graphics": {}
 69762            },
 69763            "considerations": {}
 69764          }
 69765        },
 69766        {
 69767          "type": "library",
 69768          "bom-ref": "pkg:golang/github.com/huandu/xstrings@v1.3.3?package-id=8449d07c71119b5a",
 69769          "supplier": {},
 69770          "name": "github.com/huandu/xstrings",
 69771          "version": "v1.3.3",
 69772          "cpe": "cpe:2.3:a:huandu:xstrings:v1.3.3:*:*:*:*:*:*:*",
 69773          "purl": "pkg:golang/github.com/huandu/xstrings@v1.3.3",
 69774          "swid": {
 69775            "attachment": {}
 69776          },
 69777          "pedigree": {},
 69778          "evidence": {},
 69779          "signature": {
 69780            "signature": {
 69781              "publicKey": {}
 69782            }
 69783          },
 69784          "modelCard": {
 69785            "modelParameters": {
 69786              "approach": {}
 69787            },
 69788            "quantitativeAnalysis": {
 69789              "graphics": {}
 69790            },
 69791            "considerations": {}
 69792          }
 69793        },
 69794        {
 69795          "type": "library",
 69796          "bom-ref": "pkg:golang/github.com/imdario/mergo@v0.3.12?package-id=259d03a78797d6b1",
 69797          "supplier": {},
 69798          "name": "github.com/imdario/mergo",
 69799          "version": "v0.3.12",
 69800          "cpe": "cpe:2.3:a:imdario:mergo:v0.3.12:*:*:*:*:*:*:*",
 69801          "purl": "pkg:golang/github.com/imdario/mergo@v0.3.12",
 69802          "swid": {
 69803            "attachment": {}
 69804          },
 69805          "pedigree": {},
 69806          "evidence": {},
 69807          "signature": {
 69808            "signature": {
 69809              "publicKey": {}
 69810            }
 69811          },
 69812          "modelCard": {
 69813            "modelParameters": {
 69814              "approach": {}
 69815            },
 69816            "quantitativeAnalysis": {
 69817              "graphics": {}
 69818            },
 69819            "considerations": {}
 69820          }
 69821        },
 69822        {
 69823          "type": "library",
 69824          "bom-ref": "pkg:golang/github.com/klauspost/compress@v1.11.13?package-id=ad69a215bd9e4ce",
 69825          "supplier": {},
 69826          "name": "github.com/klauspost/compress",
 69827          "version": "v1.11.13",
 69828          "cpe": "cpe:2.3:a:klauspost:compress:v1.11.13:*:*:*:*:*:*:*",
 69829          "purl": "pkg:golang/github.com/klauspost/compress@v1.11.13",
 69830          "swid": {
 69831            "attachment": {}
 69832          },
 69833          "pedigree": {},
 69834          "evidence": {},
 69835          "signature": {
 69836            "signature": {
 69837              "publicKey": {}
 69838            }
 69839          },
 69840          "modelCard": {
 69841            "modelParameters": {
 69842              "approach": {}
 69843            },
 69844            "quantitativeAnalysis": {
 69845              "graphics": {}
 69846            },
 69847            "considerations": {}
 69848          }
 69849        },
 69850        {
 69851          "type": "library",
 69852          "bom-ref": "pkg:golang/github.com/mitchellh/copystructure@v1.0.0?package-id=c5b785530a468dd7",
 69853          "supplier": {},
 69854          "name": "github.com/mitchellh/copystructure",
 69855          "version": "v1.0.0",
 69856          "cpe": "cpe:2.3:a:mitchellh:copystructure:v1.0.0:*:*:*:*:*:*:*",
 69857          "purl": "pkg:golang/github.com/mitchellh/copystructure@v1.0.0",
 69858          "swid": {
 69859            "attachment": {}
 69860          },
 69861          "pedigree": {},
 69862          "evidence": {},
 69863          "signature": {
 69864            "signature": {
 69865              "publicKey": {}
 69866            }
 69867          },
 69868          "modelCard": {
 69869            "modelParameters": {
 69870              "approach": {}
 69871            },
 69872            "quantitativeAnalysis": {
 69873              "graphics": {}
 69874            },
 69875            "considerations": {}
 69876          }
 69877        },
 69878        {
 69879          "type": "library",
 69880          "bom-ref": "pkg:golang/github.com/mitchellh/reflectwalk@v1.0.0?package-id=b5e57cc0ac507923",
 69881          "supplier": {},
 69882          "name": "github.com/mitchellh/reflectwalk",
 69883          "version": "v1.0.0",
 69884          "cpe": "cpe:2.3:a:mitchellh:reflectwalk:v1.0.0:*:*:*:*:*:*:*",
 69885          "purl": "pkg:golang/github.com/mitchellh/reflectwalk@v1.0.0",
 69886          "swid": {
 69887            "attachment": {}
 69888          },
 69889          "pedigree": {},
 69890          "evidence": {},
 69891          "signature": {
 69892            "signature": {
 69893              "publicKey": {}
 69894            }
 69895          },
 69896          "modelCard": {
 69897            "modelParameters": {
 69898              "approach": {}
 69899            },
 69900            "quantitativeAnalysis": {
 69901              "graphics": {}
 69902            },
 69903            "considerations": {}
 69904          }
 69905        },
 69906        {
 69907          "type": "library",
 69908          "bom-ref": "pkg:golang/github.com/moby/patternmatcher@v0.5.0?package-id=95549b63cdd672a3",
 69909          "supplier": {},
 69910          "name": "github.com/moby/patternmatcher",
 69911          "version": "v0.5.0",
 69912          "cpe": "cpe:2.3:a:moby:patternmatcher:v0.5.0:*:*:*:*:*:*:*",
 69913          "purl": "pkg:golang/github.com/moby/patternmatcher@v0.5.0",
 69914          "swid": {
 69915            "attachment": {}
 69916          },
 69917          "pedigree": {},
 69918          "evidence": {},
 69919          "signature": {
 69920            "signature": {
 69921              "publicKey": {}
 69922            }
 69923          },
 69924          "modelCard": {
 69925            "modelParameters": {
 69926              "approach": {}
 69927            },
 69928            "quantitativeAnalysis": {
 69929              "graphics": {}
 69930            },
 69931            "considerations": {}
 69932          }
 69933        },
 69934        {
 69935          "type": "library",
 69936          "bom-ref": "pkg:golang/github.com/moby/sys/sequential@v0.5.0?package-id=17d1d688de0e526a",
 69937          "supplier": {},
 69938          "name": "github.com/moby/sys/sequential",
 69939          "version": "v0.5.0",
 69940          "cpe": "cpe:2.3:a:moby:sys\\/sequential:v0.5.0:*:*:*:*:*:*:*",
 69941          "purl": "pkg:golang/github.com/moby/sys/sequential@v0.5.0",
 69942          "swid": {
 69943            "attachment": {}
 69944          },
 69945          "pedigree": {},
 69946          "evidence": {},
 69947          "signature": {
 69948            "signature": {
 69949              "publicKey": {}
 69950            }
 69951          },
 69952          "modelCard": {
 69953            "modelParameters": {
 69954              "approach": {}
 69955            },
 69956            "quantitativeAnalysis": {
 69957              "graphics": {}
 69958            },
 69959            "considerations": {}
 69960          }
 69961        },
 69962        {
 69963          "type": "library",
 69964          "bom-ref": "pkg:golang/github.com/moby/term@v0.0.0-20210619224110-3f7ff695adc6?package-id=f4c3fc41981972d",
 69965          "supplier": {},
 69966          "name": "github.com/moby/term",
 69967          "version": "v0.0.0-20210619224110-3f7ff695adc6",
 69968          "cpe": "cpe:2.3:a:moby:term:v0.0.0-20210619224110-3f7ff695adc6:*:*:*:*:*:*:*",
 69969          "purl": "pkg:golang/github.com/moby/term@v0.0.0-20210619224110-3f7ff695adc6",
 69970          "swid": {
 69971            "attachment": {}
 69972          },
 69973          "pedigree": {},
 69974          "evidence": {},
 69975          "signature": {
 69976            "signature": {
 69977              "publicKey": {}
 69978            }
 69979          },
 69980          "modelCard": {
 69981            "modelParameters": {
 69982              "approach": {}
 69983            },
 69984            "quantitativeAnalysis": {
 69985              "graphics": {}
 69986            },
 69987            "considerations": {}
 69988          }
 69989        },
 69990        {
 69991          "type": "library",
 69992          "bom-ref": "pkg:golang/github.com/morikuni/aec@v1.0.0?package-id=5cf4a6555fb2fc94",
 69993          "supplier": {},
 69994          "name": "github.com/morikuni/aec",
 69995          "version": "v1.0.0",
 69996          "cpe": "cpe:2.3:a:morikuni:aec:v1.0.0:*:*:*:*:*:*:*",
 69997          "purl": "pkg:golang/github.com/morikuni/aec@v1.0.0",
 69998          "swid": {
 69999            "attachment": {}
 70000          },
 70001          "pedigree": {},
 70002          "evidence": {},
 70003          "signature": {
 70004            "signature": {
 70005              "publicKey": {}
 70006            }
 70007          },
 70008          "modelCard": {
 70009            "modelParameters": {
 70010              "approach": {}
 70011            },
 70012            "quantitativeAnalysis": {
 70013              "graphics": {}
 70014            },
 70015            "considerations": {}
 70016          }
 70017        },
 70018        {
 70019          "type": "library",
 70020          "bom-ref": "pkg:golang/github.com/nginx-proxy/docker-gen@v0.0.0-20230418052149-902b12d786e8?package-id=4a7d0b506880ec78",
 70021          "supplier": {},
 70022          "name": "github.com/nginx-proxy/docker-gen",
 70023          "version": "v0.0.0-20230418052149-902b12d786e8",
 70024          "cpe": "cpe:2.3:a:nginx-proxy:docker-gen:v0.0.0-20230418052149-902b12d786e8:*:*:*:*:*:*:*",
 70025          "purl": "pkg:golang/github.com/nginx-proxy/docker-gen@v0.0.0-20230418052149-902b12d786e8",
 70026          "swid": {
 70027            "attachment": {}
 70028          },
 70029          "pedigree": {},
 70030          "evidence": {},
 70031          "signature": {
 70032            "signature": {
 70033              "publicKey": {}
 70034            }
 70035          },
 70036          "modelCard": {
 70037            "modelParameters": {
 70038              "approach": {}
 70039            },
 70040            "quantitativeAnalysis": {
 70041              "graphics": {}
 70042            },
 70043            "considerations": {}
 70044          }
 70045        },
 70046        {
 70047          "type": "library",
 70048          "bom-ref": "pkg:golang/github.com/nginxproxy/forego@v0.0.0-20210608192909-d75f7045feff?package-id=8231cf0aeaef9de5",
 70049          "supplier": {},
 70050          "name": "github.com/nginxproxy/forego",
 70051          "version": "v0.0.0-20210608192909-d75f7045feff",
 70052          "cpe": "cpe:2.3:a:nginxproxy:forego:v0.0.0-20210608192909-d75f7045feff:*:*:*:*:*:*:*",
 70053          "purl": "pkg:golang/github.com/nginxproxy/forego@v0.0.0-20210608192909-d75f7045feff",
 70054          "swid": {
 70055            "attachment": {}
 70056          },
 70057          "pedigree": {},
 70058          "evidence": {},
 70059          "signature": {
 70060            "signature": {
 70061              "publicKey": {}
 70062            }
 70063          },
 70064          "modelCard": {
 70065            "modelParameters": {
 70066              "approach": {}
 70067            },
 70068            "quantitativeAnalysis": {
 70069              "graphics": {}
 70070            },
 70071            "considerations": {}
 70072          }
 70073        },
 70074        {
 70075          "type": "library",
 70076          "bom-ref": "pkg:golang/github.com/opencontainers/go-digest@v1.0.0?package-id=803e8a92d934af59",
 70077          "supplier": {},
 70078          "name": "github.com/opencontainers/go-digest",
 70079          "version": "v1.0.0",
 70080          "cpe": "cpe:2.3:a:opencontainers:go-digest:v1.0.0:*:*:*:*:*:*:*",
 70081          "purl": "pkg:golang/github.com/opencontainers/go-digest@v1.0.0",
 70082          "swid": {
 70083            "attachment": {}
 70084          },
 70085          "pedigree": {},
 70086          "evidence": {},
 70087          "signature": {
 70088            "signature": {
 70089              "publicKey": {}
 70090            }
 70091          },
 70092          "modelCard": {
 70093            "modelParameters": {
 70094              "approach": {}
 70095            },
 70096            "quantitativeAnalysis": {
 70097              "graphics": {}
 70098            },
 70099            "considerations": {}
 70100          }
 70101        },
 70102        {
 70103          "type": "library",
 70104          "bom-ref": "pkg:golang/github.com/opencontainers/image-spec@v1.0.3-0.20211202183452-c5a74bcca799?package-id=fa812ac66b7816f0",
 70105          "supplier": {},
 70106          "name": "github.com/opencontainers/image-spec",
 70107          "version": "v1.0.3-0.20211202183452-c5a74bcca799",
 70108          "cpe": "cpe:2.3:a:opencontainers:image-spec:v1.0.3-0.20211202183452-c5a74bcca799:*:*:*:*:*:*:*",
 70109          "purl": "pkg:golang/github.com/opencontainers/image-spec@v1.0.3-0.20211202183452-c5a74bcca799",
 70110          "swid": {
 70111            "attachment": {}
 70112          },
 70113          "pedigree": {},
 70114          "evidence": {},
 70115          "signature": {
 70116            "signature": {
 70117              "publicKey": {}
 70118            }
 70119          },
 70120          "modelCard": {
 70121            "modelParameters": {
 70122              "approach": {}
 70123            },
 70124            "quantitativeAnalysis": {
 70125              "graphics": {}
 70126            },
 70127            "considerations": {}
 70128          }
 70129        },
 70130        {
 70131          "type": "library",
 70132          "bom-ref": "pkg:golang/github.com/opencontainers/runc@v1.1.5?package-id=5d4cc056642b19a0",
 70133          "supplier": {},
 70134          "name": "github.com/opencontainers/runc",
 70135          "version": "v1.1.5",
 70136          "cpe": "cpe:2.3:a:opencontainers:runc:v1.1.5:*:*:*:*:*:*:*",
 70137          "purl": "pkg:golang/github.com/opencontainers/runc@v1.1.5",
 70138          "swid": {
 70139            "attachment": {}
 70140          },
 70141          "pedigree": {},
 70142          "evidence": {},
 70143          "signature": {
 70144            "signature": {
 70145              "publicKey": {}
 70146            }
 70147          },
 70148          "modelCard": {
 70149            "modelParameters": {
 70150              "approach": {}
 70151            },
 70152            "quantitativeAnalysis": {
 70153              "graphics": {}
 70154            },
 70155            "considerations": {}
 70156          }
 70157        },
 70158        {
 70159          "type": "library",
 70160          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.9.1?package-id=2ed7122b49866153",
 70161          "supplier": {},
 70162          "name": "github.com/pkg/errors",
 70163          "version": "v0.9.1",
 70164          "cpe": "cpe:2.3:a:pkg:errors:v0.9.1:*:*:*:*:*:*:*",
 70165          "purl": "pkg:golang/github.com/pkg/errors@v0.9.1",
 70166          "swid": {
 70167            "attachment": {}
 70168          },
 70169          "pedigree": {},
 70170          "evidence": {},
 70171          "signature": {
 70172            "signature": {
 70173              "publicKey": {}
 70174            }
 70175          },
 70176          "modelCard": {
 70177            "modelParameters": {
 70178              "approach": {}
 70179            },
 70180            "quantitativeAnalysis": {
 70181              "graphics": {}
 70182            },
 70183            "considerations": {}
 70184          }
 70185        },
 70186        {
 70187          "type": "library",
 70188          "bom-ref": "pkg:golang/github.com/shopspring/decimal@v1.2.0?package-id=79cdbc7ed43490e4",
 70189          "supplier": {},
 70190          "name": "github.com/shopspring/decimal",
 70191          "version": "v1.2.0",
 70192          "cpe": "cpe:2.3:a:shopspring:decimal:v1.2.0:*:*:*:*:*:*:*",
 70193          "purl": "pkg:golang/github.com/shopspring/decimal@v1.2.0",
 70194          "swid": {
 70195            "attachment": {}
 70196          },
 70197          "pedigree": {},
 70198          "evidence": {},
 70199          "signature": {
 70200            "signature": {
 70201              "publicKey": {}
 70202            }
 70203          },
 70204          "modelCard": {
 70205            "modelParameters": {
 70206              "approach": {}
 70207            },
 70208            "quantitativeAnalysis": {
 70209              "graphics": {}
 70210            },
 70211            "considerations": {}
 70212          }
 70213        },
 70214        {
 70215          "type": "library",
 70216          "bom-ref": "pkg:golang/github.com/sirupsen/logrus@v1.8.1?package-id=18f489688140621d",
 70217          "supplier": {},
 70218          "name": "github.com/sirupsen/logrus",
 70219          "version": "v1.8.1",
 70220          "cpe": "cpe:2.3:a:sirupsen:logrus:v1.8.1:*:*:*:*:*:*:*",
 70221          "purl": "pkg:golang/github.com/sirupsen/logrus@v1.8.1",
 70222          "swid": {
 70223            "attachment": {}
 70224          },
 70225          "pedigree": {},
 70226          "evidence": {},
 70227          "signature": {
 70228            "signature": {
 70229              "publicKey": {}
 70230            }
 70231          },
 70232          "modelCard": {
 70233            "modelParameters": {
 70234              "approach": {}
 70235            },
 70236            "quantitativeAnalysis": {
 70237              "graphics": {}
 70238            },
 70239            "considerations": {}
 70240          }
 70241        },
 70242        {
 70243          "type": "library",
 70244          "bom-ref": "pkg:golang/github.com/spf13/cast@v1.3.1?package-id=c9839d61d6c844bd",
 70245          "supplier": {},
 70246          "name": "github.com/spf13/cast",
 70247          "version": "v1.3.1",
 70248          "cpe": "cpe:2.3:a:spf13:cast:v1.3.1:*:*:*:*:*:*:*",
 70249          "purl": "pkg:golang/github.com/spf13/cast@v1.3.1",
 70250          "swid": {
 70251            "attachment": {}
 70252          },
 70253          "pedigree": {},
 70254          "evidence": {},
 70255          "signature": {
 70256            "signature": {
 70257              "publicKey": {}
 70258            }
 70259          },
 70260          "modelCard": {
 70261            "modelParameters": {
 70262              "approach": {}
 70263            },
 70264            "quantitativeAnalysis": {
 70265              "graphics": {}
 70266            },
 70267            "considerations": {}
 70268          }
 70269        },
 70270        {
 70271          "type": "library",
 70272          "bom-ref": "pkg:golang/github.com/subosito/gotenv@v1.2.0?package-id=2bbfe34873caa650",
 70273          "supplier": {},
 70274          "name": "github.com/subosito/gotenv",
 70275          "version": "v1.2.0",
 70276          "cpe": "cpe:2.3:a:subosito:gotenv:v1.2.0:*:*:*:*:*:*:*",
 70277          "purl": "pkg:golang/github.com/subosito/gotenv@v1.2.0",
 70278          "swid": {
 70279            "attachment": {}
 70280          },
 70281          "pedigree": {},
 70282          "evidence": {},
 70283          "signature": {
 70284            "signature": {
 70285              "publicKey": {}
 70286            }
 70287          },
 70288          "modelCard": {
 70289            "modelParameters": {
 70290              "approach": {}
 70291            },
 70292            "quantitativeAnalysis": {
 70293              "graphics": {}
 70294            },
 70295            "considerations": {}
 70296          }
 70297        },
 70298        {
 70299          "type": "library",
 70300          "bom-ref": "pkg:golang/golang.org/x/crypto@v0.3.0?package-id=438a788894c5abd3",
 70301          "supplier": {},
 70302          "name": "golang.org/x/crypto",
 70303          "version": "v0.3.0",
 70304          "cpe": "cpe:2.3:a:golang:x\\/crypto:v0.3.0:*:*:*:*:*:*:*",
 70305          "purl": "pkg:golang/golang.org/x/crypto@v0.3.0",
 70306          "swid": {
 70307            "attachment": {}
 70308          },
 70309          "pedigree": {},
 70310          "evidence": {},
 70311          "signature": {
 70312            "signature": {
 70313              "publicKey": {}
 70314            }
 70315          },
 70316          "modelCard": {
 70317            "modelParameters": {
 70318              "approach": {}
 70319            },
 70320            "quantitativeAnalysis": {
 70321              "graphics": {}
 70322            },
 70323            "considerations": {}
 70324          }
 70325        },
 70326        {
 70327          "type": "library",
 70328          "bom-ref": "pkg:golang/golang.org/x/sys@v0.6.0?package-id=2a224142d0d15f8a",
 70329          "supplier": {},
 70330          "name": "golang.org/x/sys",
 70331          "version": "v0.6.0",
 70332          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.6.0:*:*:*:*:*:*:*",
 70333          "purl": "pkg:golang/golang.org/x/sys@v0.6.0",
 70334          "swid": {
 70335            "attachment": {}
 70336          },
 70337          "pedigree": {},
 70338          "evidence": {},
 70339          "signature": {
 70340            "signature": {
 70341              "publicKey": {}
 70342            }
 70343          },
 70344          "modelCard": {
 70345            "modelParameters": {
 70346              "approach": {}
 70347            },
 70348            "quantitativeAnalysis": {
 70349              "graphics": {}
 70350            },
 70351            "considerations": {}
 70352          }
 70353        },
 70354        {
 70355          "type": "library",
 70356          "bom-ref": "pkg:deb/debian/gpgv@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=b6346590c45ba7ab",
 70357          "supplier": {},
 70358          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
 70359          "name": "gpgv",
 70360          "version": "2.2.27-2+deb11u2",
 70361          "licenses": [
 70362            {
 70363              "license": {
 70364                "id": "BSD-3-Clause"
 70365              }
 70366            },
 70367            {
 70368              "license": {
 70369                "id": "CC0-1.0"
 70370              }
 70371            },
 70372            {
 70373              "license": {
 70374                "name": "Expat"
 70375              }
 70376            },
 70377            {
 70378              "license": {
 70379                "id": "GPL-3.0-only"
 70380              }
 70381            },
 70382            {
 70383              "license": {
 70384                "id": "GPL-3.0-or-later"
 70385              }
 70386            },
 70387            {
 70388              "license": {
 70389                "id": "LGPL-2.1-only"
 70390              }
 70391            },
 70392            {
 70393              "license": {
 70394                "id": "LGPL-2.1-or-later"
 70395              }
 70396            },
 70397            {
 70398              "license": {
 70399                "id": "LGPL-3.0-only"
 70400              }
 70401            },
 70402            {
 70403              "license": {
 70404                "id": "LGPL-3.0-or-later"
 70405              }
 70406            },
 70407            {
 70408              "license": {
 70409                "name": "RFC-Reference"
 70410              }
 70411            },
 70412            {
 70413              "license": {
 70414                "name": "TinySCHEME"
 70415              }
 70416            },
 70417            {
 70418              "license": {
 70419                "name": "permissive"
 70420              }
 70421            }
 70422          ],
 70423          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
 70424          "purl": "pkg:deb/debian/gpgv@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
 70425          "swid": {
 70426            "attachment": {}
 70427          },
 70428          "pedigree": {},
 70429          "evidence": {},
 70430          "signature": {
 70431            "signature": {
 70432              "publicKey": {}
 70433            }
 70434          },
 70435          "modelCard": {
 70436            "modelParameters": {
 70437              "approach": {}
 70438            },
 70439            "quantitativeAnalysis": {
 70440              "graphics": {}
 70441            },
 70442            "considerations": {}
 70443          }
 70444        },
 70445        {
 70446          "type": "library",
 70447          "bom-ref": "pkg:deb/debian/grep@3.6-1?arch=amd64\u0026distro=debian-11\u0026package-id=9ed140c6f7959d",
 70448          "supplier": {},
 70449          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 70450          "name": "grep",
 70451          "version": "3.6-1",
 70452          "licenses": [
 70453            {
 70454              "license": {
 70455                "id": "GPL-3.0-only"
 70456              }
 70457            },
 70458            {
 70459              "license": {
 70460                "id": "GPL-3.0-or-later"
 70461              }
 70462            }
 70463          ],
 70464          "cpe": "cpe:2.3:a:grep:grep:3.6-1:*:*:*:*:*:*:*",
 70465          "purl": "pkg:deb/debian/grep@3.6-1?arch=amd64\u0026distro=debian-11",
 70466          "swid": {
 70467            "attachment": {}
 70468          },
 70469          "pedigree": {},
 70470          "evidence": {},
 70471          "signature": {
 70472            "signature": {
 70473              "publicKey": {}
 70474            }
 70475          },
 70476          "modelCard": {
 70477            "modelParameters": {
 70478              "approach": {}
 70479            },
 70480            "quantitativeAnalysis": {
 70481              "graphics": {}
 70482            },
 70483            "considerations": {}
 70484          }
 70485        },
 70486        {
 70487          "type": "library",
 70488          "bom-ref": "pkg:deb/debian/gzip@1.10-4+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=ade955af6710751d",
 70489          "supplier": {},
 70490          "publisher": "Milan Kupcevic \u003cmilan@debian.org\u003e",
 70491          "name": "gzip",
 70492          "version": "1.10-4+deb11u1",
 70493          "licenses": [
 70494            {
 70495              "license": {
 70496                "name": "FSF-manpages"
 70497              }
 70498            },
 70499            {
 70500              "license": {
 70501                "name": "GFDL-1.3+-no-invariant"
 70502              }
 70503            },
 70504            {
 70505              "license": {
 70506                "name": "GFDL-3"
 70507              }
 70508            },
 70509            {
 70510              "license": {
 70511                "id": "GPL-3.0-only"
 70512              }
 70513            },
 70514            {
 70515              "license": {
 70516                "id": "GPL-3.0-or-later"
 70517              }
 70518            }
 70519          ],
 70520          "cpe": "cpe:2.3:a:gzip:gzip:1.10-4\\+deb11u1:*:*:*:*:*:*:*",
 70521          "purl": "pkg:deb/debian/gzip@1.10-4+deb11u1?arch=amd64\u0026distro=debian-11",
 70522          "swid": {
 70523            "attachment": {}
 70524          },
 70525          "pedigree": {},
 70526          "evidence": {},
 70527          "signature": {
 70528            "signature": {
 70529              "publicKey": {}
 70530            }
 70531          },
 70532          "modelCard": {
 70533            "modelParameters": {
 70534              "approach": {}
 70535            },
 70536            "quantitativeAnalysis": {
 70537              "graphics": {}
 70538            },
 70539            "considerations": {}
 70540          }
 70541        },
 70542        {
 70543          "type": "library",
 70544          "bom-ref": "pkg:deb/debian/hostname@3.23?arch=amd64\u0026distro=debian-11\u0026package-id=fec906d1ab1d9712",
 70545          "supplier": {},
 70546          "publisher": "Michael Meskes \u003cmeskes@debian.org\u003e",
 70547          "name": "hostname",
 70548          "version": "3.23",
 70549          "licenses": [
 70550            {
 70551              "license": {
 70552                "id": "GPL-2.0-only"
 70553              }
 70554            }
 70555          ],
 70556          "cpe": "cpe:2.3:a:hostname:hostname:3.23:*:*:*:*:*:*:*",
 70557          "purl": "pkg:deb/debian/hostname@3.23?arch=amd64\u0026distro=debian-11",
 70558          "swid": {
 70559            "attachment": {}
 70560          },
 70561          "pedigree": {},
 70562          "evidence": {},
 70563          "signature": {
 70564            "signature": {
 70565              "publicKey": {}
 70566            }
 70567          },
 70568          "modelCard": {
 70569            "modelParameters": {
 70570              "approach": {}
 70571            },
 70572            "quantitativeAnalysis": {
 70573              "graphics": {}
 70574            },
 70575            "considerations": {}
 70576          }
 70577        },
 70578        {
 70579          "type": "library",
 70580          "bom-ref": "pkg:deb/debian/init-system-helpers@1.60?arch=all\u0026distro=debian-11\u0026package-id=9853db6c4e48777f",
 70581          "supplier": {},
 70582          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 70583          "name": "init-system-helpers",
 70584          "version": "1.60",
 70585          "licenses": [
 70586            {
 70587              "license": {
 70588                "id": "BSD-3-Clause"
 70589              }
 70590            },
 70591            {
 70592              "license": {
 70593                "id": "GPL-2.0-only"
 70594              }
 70595            },
 70596            {
 70597              "license": {
 70598                "id": "GPL-2.0-or-later"
 70599              }
 70600            }
 70601          ],
 70602          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.60:*:*:*:*:*:*:*",
 70603          "purl": "pkg:deb/debian/init-system-helpers@1.60?arch=all\u0026distro=debian-11",
 70604          "swid": {
 70605            "attachment": {}
 70606          },
 70607          "pedigree": {},
 70608          "evidence": {},
 70609          "signature": {
 70610            "signature": {
 70611              "publicKey": {}
 70612            }
 70613          },
 70614          "modelCard": {
 70615            "modelParameters": {
 70616              "approach": {}
 70617            },
 70618            "quantitativeAnalysis": {
 70619              "graphics": {}
 70620            },
 70621            "considerations": {}
 70622          }
 70623        },
 70624        {
 70625          "type": "library",
 70626          "bom-ref": "pkg:deb/debian/libacl1@2.2.53-10?arch=amd64\u0026upstream=acl\u0026distro=debian-11\u0026package-id=e26fd10cf6ff246",
 70627          "supplier": {},
 70628          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
 70629          "name": "libacl1",
 70630          "version": "2.2.53-10",
 70631          "licenses": [
 70632            {
 70633              "license": {
 70634                "id": "GPL-2.0-only"
 70635              }
 70636            },
 70637            {
 70638              "license": {
 70639                "id": "GPL-2.0-or-later"
 70640              }
 70641            },
 70642            {
 70643              "license": {
 70644                "id": "LGPL-2.0-or-later"
 70645              }
 70646            },
 70647            {
 70648              "license": {
 70649                "id": "LGPL-2.1-only"
 70650              }
 70651            }
 70652          ],
 70653          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-10:*:*:*:*:*:*:*",
 70654          "purl": "pkg:deb/debian/libacl1@2.2.53-10?arch=amd64\u0026upstream=acl\u0026distro=debian-11",
 70655          "swid": {
 70656            "attachment": {}
 70657          },
 70658          "pedigree": {},
 70659          "evidence": {},
 70660          "signature": {
 70661            "signature": {
 70662              "publicKey": {}
 70663            }
 70664          },
 70665          "modelCard": {
 70666            "modelParameters": {
 70667              "approach": {}
 70668            },
 70669            "quantitativeAnalysis": {
 70670              "graphics": {}
 70671            },
 70672            "considerations": {}
 70673          }
 70674        },
 70675        {
 70676          "type": "library",
 70677          "bom-ref": "pkg:deb/debian/libapt-pkg6.0@2.2.4?arch=amd64\u0026upstream=apt\u0026distro=debian-11\u0026package-id=da442f0998cccf2b",
 70678          "supplier": {},
 70679          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
 70680          "name": "libapt-pkg6.0",
 70681          "version": "2.2.4",
 70682          "licenses": [
 70683            {
 70684              "license": {
 70685                "id": "GPL-2.0-only"
 70686              }
 70687            },
 70688            {
 70689              "license": {
 70690                "name": "GPLv2+"
 70691              }
 70692            }
 70693          ],
 70694          "cpe": "cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.2.4:*:*:*:*:*:*:*",
 70695          "purl": "pkg:deb/debian/libapt-pkg6.0@2.2.4?arch=amd64\u0026upstream=apt\u0026distro=debian-11",
 70696          "swid": {
 70697            "attachment": {}
 70698          },
 70699          "pedigree": {},
 70700          "evidence": {},
 70701          "signature": {
 70702            "signature": {
 70703              "publicKey": {}
 70704            }
 70705          },
 70706          "modelCard": {
 70707            "modelParameters": {
 70708              "approach": {}
 70709            },
 70710            "quantitativeAnalysis": {
 70711              "graphics": {}
 70712            },
 70713            "considerations": {}
 70714          }
 70715        },
 70716        {
 70717          "type": "library",
 70718          "bom-ref": "pkg:deb/debian/libattr1@1:2.4.48-6?arch=amd64\u0026upstream=attr\u0026distro=debian-11\u0026package-id=254a97dd16e20391",
 70719          "supplier": {},
 70720          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
 70721          "name": "libattr1",
 70722          "version": "1:2.4.48-6",
 70723          "licenses": [
 70724            {
 70725              "license": {
 70726                "id": "GPL-2.0-only"
 70727              }
 70728            },
 70729            {
 70730              "license": {
 70731                "id": "GPL-2.0-or-later"
 70732              }
 70733            },
 70734            {
 70735              "license": {
 70736                "id": "LGPL-2.0-or-later"
 70737              }
 70738            },
 70739            {
 70740              "license": {
 70741                "id": "LGPL-2.1-only"
 70742              }
 70743            }
 70744          ],
 70745          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-6:*:*:*:*:*:*:*",
 70746          "purl": "pkg:deb/debian/libattr1@1:2.4.48-6?arch=amd64\u0026upstream=attr\u0026distro=debian-11",
 70747          "swid": {
 70748            "attachment": {}
 70749          },
 70750          "pedigree": {},
 70751          "evidence": {},
 70752          "signature": {
 70753            "signature": {
 70754              "publicKey": {}
 70755            }
 70756          },
 70757          "modelCard": {
 70758            "modelParameters": {
 70759              "approach": {}
 70760            },
 70761            "quantitativeAnalysis": {
 70762              "graphics": {}
 70763            },
 70764            "considerations": {}
 70765          }
 70766        },
 70767        {
 70768          "type": "library",
 70769          "bom-ref": "pkg:deb/debian/libaudit-common@1:3.0-2?arch=all\u0026upstream=audit\u0026distro=debian-11\u0026package-id=e666dc18886f28ff",
 70770          "supplier": {},
 70771          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
 70772          "name": "libaudit-common",
 70773          "version": "1:3.0-2",
 70774          "licenses": [
 70775            {
 70776              "license": {
 70777                "id": "GPL-1.0-only"
 70778              }
 70779            },
 70780            {
 70781              "license": {
 70782                "id": "GPL-2.0-only"
 70783              }
 70784            },
 70785            {
 70786              "license": {
 70787                "id": "LGPL-2.1-only"
 70788              }
 70789            }
 70790          ],
 70791          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:3.0-2:*:*:*:*:*:*:*",
 70792          "purl": "pkg:deb/debian/libaudit-common@1:3.0-2?arch=all\u0026upstream=audit\u0026distro=debian-11",
 70793          "swid": {
 70794            "attachment": {}
 70795          },
 70796          "pedigree": {},
 70797          "evidence": {},
 70798          "signature": {
 70799            "signature": {
 70800              "publicKey": {}
 70801            }
 70802          },
 70803          "modelCard": {
 70804            "modelParameters": {
 70805              "approach": {}
 70806            },
 70807            "quantitativeAnalysis": {
 70808              "graphics": {}
 70809            },
 70810            "considerations": {}
 70811          }
 70812        },
 70813        {
 70814          "type": "library",
 70815          "bom-ref": "pkg:deb/debian/libaudit1@1:3.0-2?arch=amd64\u0026upstream=audit\u0026distro=debian-11\u0026package-id=ae77fe6c43b7188d",
 70816          "supplier": {},
 70817          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
 70818          "name": "libaudit1",
 70819          "version": "1:3.0-2",
 70820          "licenses": [
 70821            {
 70822              "license": {
 70823                "id": "GPL-1.0-only"
 70824              }
 70825            },
 70826            {
 70827              "license": {
 70828                "id": "GPL-2.0-only"
 70829              }
 70830            },
 70831            {
 70832              "license": {
 70833                "id": "LGPL-2.1-only"
 70834              }
 70835            }
 70836          ],
 70837          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:3.0-2:*:*:*:*:*:*:*",
 70838          "purl": "pkg:deb/debian/libaudit1@1:3.0-2?arch=amd64\u0026upstream=audit\u0026distro=debian-11",
 70839          "swid": {
 70840            "attachment": {}
 70841          },
 70842          "pedigree": {},
 70843          "evidence": {},
 70844          "signature": {
 70845            "signature": {
 70846              "publicKey": {}
 70847            }
 70848          },
 70849          "modelCard": {
 70850            "modelParameters": {
 70851              "approach": {}
 70852            },
 70853            "quantitativeAnalysis": {
 70854              "graphics": {}
 70855            },
 70856            "considerations": {}
 70857          }
 70858        },
 70859        {
 70860          "type": "library",
 70861          "bom-ref": "pkg:deb/debian/libblkid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=f235c9c5cb7b4190",
 70862          "supplier": {},
 70863          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 70864          "name": "libblkid1",
 70865          "version": "2.36.1-8+deb11u1",
 70866          "licenses": [
 70867            {
 70868              "license": {
 70869                "id": "BSD-2-Clause"
 70870              }
 70871            },
 70872            {
 70873              "license": {
 70874                "id": "BSD-3-Clause"
 70875              }
 70876            },
 70877            {
 70878              "license": {
 70879                "id": "BSD-4-Clause"
 70880              }
 70881            },
 70882            {
 70883              "license": {
 70884                "id": "GPL-2.0-only"
 70885              }
 70886            },
 70887            {
 70888              "license": {
 70889                "id": "GPL-2.0-or-later"
 70890              }
 70891            },
 70892            {
 70893              "license": {
 70894                "id": "GPL-3.0-only"
 70895              }
 70896            },
 70897            {
 70898              "license": {
 70899                "id": "GPL-3.0-or-later"
 70900              }
 70901            },
 70902            {
 70903              "license": {
 70904                "name": "LGPL"
 70905              }
 70906            },
 70907            {
 70908              "license": {
 70909                "id": "LGPL-2.0-only"
 70910              }
 70911            },
 70912            {
 70913              "license": {
 70914                "id": "LGPL-2.0-or-later"
 70915              }
 70916            },
 70917            {
 70918              "license": {
 70919                "id": "LGPL-2.1-only"
 70920              }
 70921            },
 70922            {
 70923              "license": {
 70924                "id": "LGPL-2.1-or-later"
 70925              }
 70926            },
 70927            {
 70928              "license": {
 70929                "id": "LGPL-3.0-only"
 70930              }
 70931            },
 70932            {
 70933              "license": {
 70934                "id": "LGPL-3.0-or-later"
 70935              }
 70936            },
 70937            {
 70938              "license": {
 70939                "id": "MIT"
 70940              }
 70941            },
 70942            {
 70943              "license": {
 70944                "name": "public-domain"
 70945              }
 70946            }
 70947          ],
 70948          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 70949          "purl": "pkg:deb/debian/libblkid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
 70950          "swid": {
 70951            "attachment": {}
 70952          },
 70953          "pedigree": {},
 70954          "evidence": {},
 70955          "signature": {
 70956            "signature": {
 70957              "publicKey": {}
 70958            }
 70959          },
 70960          "modelCard": {
 70961            "modelParameters": {
 70962              "approach": {}
 70963            },
 70964            "quantitativeAnalysis": {
 70965              "graphics": {}
 70966            },
 70967            "considerations": {}
 70968          }
 70969        },
 70970        {
 70971          "type": "library",
 70972          "bom-ref": "pkg:deb/debian/libbrotli1@1.0.9-2+b2?arch=amd64\u0026upstream=brotli%401.0.9-2\u0026distro=debian-11\u0026package-id=56558463e048d713",
 70973          "supplier": {},
 70974          "publisher": "Tomasz Buchert \u003ctomasz@debian.org\u003e",
 70975          "name": "libbrotli1",
 70976          "version": "1.0.9-2+b2",
 70977          "licenses": [
 70978            {
 70979              "license": {
 70980                "id": "MIT"
 70981              }
 70982            }
 70983          ],
 70984          "cpe": "cpe:2.3:a:libbrotli1:libbrotli1:1.0.9-2\\+b2:*:*:*:*:*:*:*",
 70985          "purl": "pkg:deb/debian/libbrotli1@1.0.9-2+b2?arch=amd64\u0026upstream=brotli%401.0.9-2\u0026distro=debian-11",
 70986          "swid": {
 70987            "attachment": {}
 70988          },
 70989          "pedigree": {},
 70990          "evidence": {},
 70991          "signature": {
 70992            "signature": {
 70993              "publicKey": {}
 70994            }
 70995          },
 70996          "modelCard": {
 70997            "modelParameters": {
 70998              "approach": {}
 70999            },
 71000            "quantitativeAnalysis": {
 71001              "graphics": {}
 71002            },
 71003            "considerations": {}
 71004          }
 71005        },
 71006        {
 71007          "type": "library",
 71008          "bom-ref": "pkg:deb/debian/libbsd0@0.11.3-1?arch=amd64\u0026upstream=libbsd\u0026distro=debian-11\u0026package-id=19b310b25a33fc08",
 71009          "supplier": {},
 71010          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
 71011          "name": "libbsd0",
 71012          "version": "0.11.3-1",
 71013          "licenses": [
 71014            {
 71015              "license": {
 71016                "id": "BSD-2-Clause"
 71017              }
 71018            },
 71019            {
 71020              "license": {
 71021                "id": "BSD-2-Clause"
 71022              }
 71023            },
 71024            {
 71025              "license": {
 71026                "name": "BSD-2-clause-author"
 71027              }
 71028            },
 71029            {
 71030              "license": {
 71031                "name": "BSD-2-clause-verbatim"
 71032              }
 71033            },
 71034            {
 71035              "license": {
 71036                "id": "BSD-3-Clause"
 71037              }
 71038            },
 71039            {
 71040              "license": {
 71041                "name": "BSD-3-clause-John-Birrell"
 71042              }
 71043            },
 71044            {
 71045              "license": {
 71046                "name": "BSD-3-clause-Regents"
 71047              }
 71048            },
 71049            {
 71050              "license": {
 71051                "name": "BSD-3-clause-author"
 71052              }
 71053            },
 71054            {
 71055              "license": {
 71056                "name": "BSD-4-clause-Christopher-G-Demetriou"
 71057              }
 71058            },
 71059            {
 71060              "license": {
 71061                "name": "BSD-4-clause-Niels-Provos"
 71062              }
 71063            },
 71064            {
 71065              "license": {
 71066                "name": "BSD-5-clause-Peter-Wemm"
 71067              }
 71068            },
 71069            {
 71070              "license": {
 71071                "id": "Beerware"
 71072              }
 71073            },
 71074            {
 71075              "license": {
 71076                "name": "Expat"
 71077              }
 71078            },
 71079            {
 71080              "license": {
 71081                "id": "ISC"
 71082              }
 71083            },
 71084            {
 71085              "license": {
 71086                "name": "ISC-Original"
 71087              }
 71088            },
 71089            {
 71090              "license": {
 71091                "name": "public-domain"
 71092              }
 71093            }
 71094          ],
 71095          "cpe": "cpe:2.3:a:libbsd0:libbsd0:0.11.3-1:*:*:*:*:*:*:*",
 71096          "purl": "pkg:deb/debian/libbsd0@0.11.3-1?arch=amd64\u0026upstream=libbsd\u0026distro=debian-11",
 71097          "swid": {
 71098            "attachment": {}
 71099          },
 71100          "pedigree": {},
 71101          "evidence": {},
 71102          "signature": {
 71103            "signature": {
 71104              "publicKey": {}
 71105            }
 71106          },
 71107          "modelCard": {
 71108            "modelParameters": {
 71109              "approach": {}
 71110            },
 71111            "quantitativeAnalysis": {
 71112              "graphics": {}
 71113            },
 71114            "considerations": {}
 71115          }
 71116        },
 71117        {
 71118          "type": "library",
 71119          "bom-ref": "pkg:deb/debian/libbz2-1.0@1.0.8-4?arch=amd64\u0026upstream=bzip2\u0026distro=debian-11\u0026package-id=120fe415369d1784",
 71120          "supplier": {},
 71121          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 71122          "name": "libbz2-1.0",
 71123          "version": "1.0.8-4",
 71124          "licenses": [
 71125            {
 71126              "license": {
 71127                "name": "BSD-variant"
 71128              }
 71129            },
 71130            {
 71131              "license": {
 71132                "id": "GPL-2.0-only"
 71133              }
 71134            }
 71135          ],
 71136          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-4:*:*:*:*:*:*:*",
 71137          "purl": "pkg:deb/debian/libbz2-1.0@1.0.8-4?arch=amd64\u0026upstream=bzip2\u0026distro=debian-11",
 71138          "swid": {
 71139            "attachment": {}
 71140          },
 71141          "pedigree": {},
 71142          "evidence": {},
 71143          "signature": {
 71144            "signature": {
 71145              "publicKey": {}
 71146            }
 71147          },
 71148          "modelCard": {
 71149            "modelParameters": {
 71150              "approach": {}
 71151            },
 71152            "quantitativeAnalysis": {
 71153              "graphics": {}
 71154            },
 71155            "considerations": {}
 71156          }
 71157        },
 71158        {
 71159          "type": "library",
 71160          "bom-ref": "pkg:deb/debian/libc-bin@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=228ff11572a24b74",
 71161          "supplier": {},
 71162          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 71163          "name": "libc-bin",
 71164          "version": "2.31-13+deb11u5",
 71165          "licenses": [
 71166            {
 71167              "license": {
 71168                "id": "GPL-2.0-only"
 71169              }
 71170            },
 71171            {
 71172              "license": {
 71173                "id": "LGPL-2.1-only"
 71174              }
 71175            }
 71176          ],
 71177          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
 71178          "purl": "pkg:deb/debian/libc-bin@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
 71179          "swid": {
 71180            "attachment": {}
 71181          },
 71182          "pedigree": {},
 71183          "evidence": {},
 71184          "signature": {
 71185            "signature": {
 71186              "publicKey": {}
 71187            }
 71188          },
 71189          "modelCard": {
 71190            "modelParameters": {
 71191              "approach": {}
 71192            },
 71193            "quantitativeAnalysis": {
 71194              "graphics": {}
 71195            },
 71196            "considerations": {}
 71197          }
 71198        },
 71199        {
 71200          "type": "library",
 71201          "bom-ref": "pkg:deb/debian/libc6@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=abe2c3f30be707e3",
 71202          "supplier": {},
 71203          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 71204          "name": "libc6",
 71205          "version": "2.31-13+deb11u5",
 71206          "licenses": [
 71207            {
 71208              "license": {
 71209                "id": "GPL-2.0-only"
 71210              }
 71211            },
 71212            {
 71213              "license": {
 71214                "id": "LGPL-2.1-only"
 71215              }
 71216            }
 71217          ],
 71218          "cpe": "cpe:2.3:a:libc6:libc6:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
 71219          "purl": "pkg:deb/debian/libc6@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
 71220          "swid": {
 71221            "attachment": {}
 71222          },
 71223          "pedigree": {},
 71224          "evidence": {},
 71225          "signature": {
 71226            "signature": {
 71227              "publicKey": {}
 71228            }
 71229          },
 71230          "modelCard": {
 71231            "modelParameters": {
 71232              "approach": {}
 71233            },
 71234            "quantitativeAnalysis": {
 71235              "graphics": {}
 71236            },
 71237            "considerations": {}
 71238          }
 71239        },
 71240        {
 71241          "type": "library",
 71242          "bom-ref": "pkg:deb/debian/libcap-ng0@0.7.9-2.2+b1?arch=amd64\u0026upstream=libcap-ng%400.7.9-2.2\u0026distro=debian-11\u0026package-id=77d3f745010c245",
 71243          "supplier": {},
 71244          "publisher": "Pierre Chifflier \u003cpollux@debian.org\u003e",
 71245          "name": "libcap-ng0",
 71246          "version": "0.7.9-2.2+b1",
 71247          "licenses": [
 71248            {
 71249              "license": {
 71250                "id": "GPL-2.0-only"
 71251              }
 71252            },
 71253            {
 71254              "license": {
 71255                "id": "GPL-3.0-only"
 71256              }
 71257            },
 71258            {
 71259              "license": {
 71260                "id": "LGPL-2.1-only"
 71261              }
 71262            }
 71263          ],
 71264          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2.2\\+b1:*:*:*:*:*:*:*",
 71265          "purl": "pkg:deb/debian/libcap-ng0@0.7.9-2.2+b1?arch=amd64\u0026upstream=libcap-ng%400.7.9-2.2\u0026distro=debian-11",
 71266          "swid": {
 71267            "attachment": {}
 71268          },
 71269          "pedigree": {},
 71270          "evidence": {},
 71271          "signature": {
 71272            "signature": {
 71273              "publicKey": {}
 71274            }
 71275          },
 71276          "modelCard": {
 71277            "modelParameters": {
 71278              "approach": {}
 71279            },
 71280            "quantitativeAnalysis": {
 71281              "graphics": {}
 71282            },
 71283            "considerations": {}
 71284          }
 71285        },
 71286        {
 71287          "type": "library",
 71288          "bom-ref": "pkg:deb/debian/libcom-err2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=c3e2285fd362b920",
 71289          "supplier": {},
 71290          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 71291          "name": "libcom-err2",
 71292          "version": "1.46.2-2",
 71293          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.46.2-2:*:*:*:*:*:*:*",
 71294          "purl": "pkg:deb/debian/libcom-err2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
 71295          "swid": {
 71296            "attachment": {}
 71297          },
 71298          "pedigree": {},
 71299          "evidence": {},
 71300          "signature": {
 71301            "signature": {
 71302              "publicKey": {}
 71303            }
 71304          },
 71305          "modelCard": {
 71306            "modelParameters": {
 71307              "approach": {}
 71308            },
 71309            "quantitativeAnalysis": {
 71310              "graphics": {}
 71311            },
 71312            "considerations": {}
 71313          }
 71314        },
 71315        {
 71316          "type": "library",
 71317          "bom-ref": "pkg:deb/debian/libcrypt1@1:4.4.18-4?arch=amd64\u0026upstream=libxcrypt\u0026distro=debian-11\u0026package-id=4d32f8aeb497b2e2",
 71318          "supplier": {},
 71319          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
 71320          "name": "libcrypt1",
 71321          "version": "1:4.4.18-4",
 71322          "cpe": "cpe:2.3:a:libcrypt1:libcrypt1:1\\:4.4.18-4:*:*:*:*:*:*:*",
 71323          "purl": "pkg:deb/debian/libcrypt1@1:4.4.18-4?arch=amd64\u0026upstream=libxcrypt\u0026distro=debian-11",
 71324          "swid": {
 71325            "attachment": {}
 71326          },
 71327          "pedigree": {},
 71328          "evidence": {},
 71329          "signature": {
 71330            "signature": {
 71331              "publicKey": {}
 71332            }
 71333          },
 71334          "modelCard": {
 71335            "modelParameters": {
 71336              "approach": {}
 71337            },
 71338            "quantitativeAnalysis": {
 71339              "graphics": {}
 71340            },
 71341            "considerations": {}
 71342          }
 71343        },
 71344        {
 71345          "type": "library",
 71346          "bom-ref": "pkg:deb/debian/libcurl4@7.74.0-1.3+deb11u7?arch=amd64\u0026upstream=curl\u0026distro=debian-11\u0026package-id=5ca0f748c3f34f0",
 71347          "supplier": {},
 71348          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
 71349          "name": "libcurl4",
 71350          "version": "7.74.0-1.3+deb11u7",
 71351          "licenses": [
 71352            {
 71353              "license": {
 71354                "id": "BSD-3-Clause"
 71355              }
 71356            },
 71357            {
 71358              "license": {
 71359                "id": "BSD-4-Clause"
 71360              }
 71361            },
 71362            {
 71363              "license": {
 71364                "id": "ISC"
 71365              }
 71366            },
 71367            {
 71368              "license": {
 71369                "id": "curl"
 71370              }
 71371            },
 71372            {
 71373              "license": {
 71374                "name": "other"
 71375              }
 71376            },
 71377            {
 71378              "license": {
 71379                "name": "public-domain"
 71380              }
 71381            }
 71382          ],
 71383          "cpe": "cpe:2.3:a:libcurl4:libcurl4:7.74.0-1.3\\+deb11u7:*:*:*:*:*:*:*",
 71384          "purl": "pkg:deb/debian/libcurl4@7.74.0-1.3+deb11u7?arch=amd64\u0026upstream=curl\u0026distro=debian-11",
 71385          "swid": {
 71386            "attachment": {}
 71387          },
 71388          "pedigree": {},
 71389          "evidence": {},
 71390          "signature": {
 71391            "signature": {
 71392              "publicKey": {}
 71393            }
 71394          },
 71395          "modelCard": {
 71396            "modelParameters": {
 71397              "approach": {}
 71398            },
 71399            "quantitativeAnalysis": {
 71400              "graphics": {}
 71401            },
 71402            "considerations": {}
 71403          }
 71404        },
 71405        {
 71406          "type": "library",
 71407          "bom-ref": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.8?arch=amd64\u0026upstream=db5.3\u0026distro=debian-11\u0026package-id=bd40bf11043e04a6",
 71408          "supplier": {},
 71409          "publisher": "Debian Berkeley DB Team \u003cteam+bdb@tracker.debian.org\u003e",
 71410          "name": "libdb5.3",
 71411          "version": "5.3.28+dfsg1-0.8",
 71412          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.8:*:*:*:*:*:*:*",
 71413          "purl": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.8?arch=amd64\u0026upstream=db5.3\u0026distro=debian-11",
 71414          "swid": {
 71415            "attachment": {}
 71416          },
 71417          "pedigree": {},
 71418          "evidence": {},
 71419          "signature": {
 71420            "signature": {
 71421              "publicKey": {}
 71422            }
 71423          },
 71424          "modelCard": {
 71425            "modelParameters": {
 71426              "approach": {}
 71427            },
 71428            "quantitativeAnalysis": {
 71429              "graphics": {}
 71430            },
 71431            "considerations": {}
 71432          }
 71433        },
 71434        {
 71435          "type": "library",
 71436          "bom-ref": "pkg:deb/debian/libdebconfclient0@0.260?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-11\u0026package-id=f46e6be545ae8a8c",
 71437          "supplier": {},
 71438          "publisher": "Debian Install System Team \u003cdebian-boot@lists.debian.org\u003e",
 71439          "name": "libdebconfclient0",
 71440          "version": "0.260",
 71441          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.260:*:*:*:*:*:*:*",
 71442          "purl": "pkg:deb/debian/libdebconfclient0@0.260?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-11",
 71443          "swid": {
 71444            "attachment": {}
 71445          },
 71446          "pedigree": {},
 71447          "evidence": {},
 71448          "signature": {
 71449            "signature": {
 71450              "publicKey": {}
 71451            }
 71452          },
 71453          "modelCard": {
 71454            "modelParameters": {
 71455              "approach": {}
 71456            },
 71457            "quantitativeAnalysis": {
 71458              "graphics": {}
 71459            },
 71460            "considerations": {}
 71461          }
 71462        },
 71463        {
 71464          "type": "library",
 71465          "bom-ref": "pkg:deb/debian/libdeflate0@1.7-1?arch=amd64\u0026upstream=libdeflate\u0026distro=debian-11\u0026package-id=6d2c83972d64bdfd",
 71466          "supplier": {},
 71467          "publisher": "Debian Med Packaging Team \u003cdebian-med-packaging@lists.alioth.debian.org\u003e",
 71468          "name": "libdeflate0",
 71469          "version": "1.7-1",
 71470          "licenses": [
 71471            {
 71472              "license": {
 71473                "name": "Expat"
 71474              }
 71475            }
 71476          ],
 71477          "cpe": "cpe:2.3:a:libdeflate0:libdeflate0:1.7-1:*:*:*:*:*:*:*",
 71478          "purl": "pkg:deb/debian/libdeflate0@1.7-1?arch=amd64\u0026upstream=libdeflate\u0026distro=debian-11",
 71479          "swid": {
 71480            "attachment": {}
 71481          },
 71482          "pedigree": {},
 71483          "evidence": {},
 71484          "signature": {
 71485            "signature": {
 71486              "publicKey": {}
 71487            }
 71488          },
 71489          "modelCard": {
 71490            "modelParameters": {
 71491              "approach": {}
 71492            },
 71493            "quantitativeAnalysis": {
 71494              "graphics": {}
 71495            },
 71496            "considerations": {}
 71497          }
 71498        },
 71499        {
 71500          "type": "library",
 71501          "bom-ref": "pkg:deb/debian/libexpat1@2.2.10-2+deb11u5?arch=amd64\u0026upstream=expat\u0026distro=debian-11\u0026package-id=a3394c6f61c6d6ab",
 71502          "supplier": {},
 71503          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
 71504          "name": "libexpat1",
 71505          "version": "2.2.10-2+deb11u5",
 71506          "licenses": [
 71507            {
 71508              "license": {
 71509                "id": "MIT"
 71510              }
 71511            }
 71512          ],
 71513          "cpe": "cpe:2.3:a:libexpat1:libexpat1:2.2.10-2\\+deb11u5:*:*:*:*:*:*:*",
 71514          "purl": "pkg:deb/debian/libexpat1@2.2.10-2+deb11u5?arch=amd64\u0026upstream=expat\u0026distro=debian-11",
 71515          "swid": {
 71516            "attachment": {}
 71517          },
 71518          "pedigree": {},
 71519          "evidence": {},
 71520          "signature": {
 71521            "signature": {
 71522              "publicKey": {}
 71523            }
 71524          },
 71525          "modelCard": {
 71526            "modelParameters": {
 71527              "approach": {}
 71528            },
 71529            "quantitativeAnalysis": {
 71530              "graphics": {}
 71531            },
 71532            "considerations": {}
 71533          }
 71534        },
 71535        {
 71536          "type": "library",
 71537          "bom-ref": "pkg:deb/debian/libext2fs2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=78620e65fcd780c3",
 71538          "supplier": {},
 71539          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 71540          "name": "libext2fs2",
 71541          "version": "1.46.2-2",
 71542          "licenses": [
 71543            {
 71544              "license": {
 71545                "id": "GPL-2.0-only"
 71546              }
 71547            },
 71548            {
 71549              "license": {
 71550                "id": "LGPL-2.0-only"
 71551              }
 71552            }
 71553          ],
 71554          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.46.2-2:*:*:*:*:*:*:*",
 71555          "purl": "pkg:deb/debian/libext2fs2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
 71556          "swid": {
 71557            "attachment": {}
 71558          },
 71559          "pedigree": {},
 71560          "evidence": {},
 71561          "signature": {
 71562            "signature": {
 71563              "publicKey": {}
 71564            }
 71565          },
 71566          "modelCard": {
 71567            "modelParameters": {
 71568              "approach": {}
 71569            },
 71570            "quantitativeAnalysis": {
 71571              "graphics": {}
 71572            },
 71573            "considerations": {}
 71574          }
 71575        },
 71576        {
 71577          "type": "library",
 71578          "bom-ref": "pkg:deb/debian/libffi7@3.3-6?arch=amd64\u0026upstream=libffi\u0026distro=debian-11\u0026package-id=b76aa1c712147c28",
 71579          "supplier": {},
 71580          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 71581          "name": "libffi7",
 71582          "version": "3.3-6",
 71583          "licenses": [
 71584            {
 71585              "license": {
 71586                "name": "GPL"
 71587              }
 71588            }
 71589          ],
 71590          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-6:*:*:*:*:*:*:*",
 71591          "purl": "pkg:deb/debian/libffi7@3.3-6?arch=amd64\u0026upstream=libffi\u0026distro=debian-11",
 71592          "swid": {
 71593            "attachment": {}
 71594          },
 71595          "pedigree": {},
 71596          "evidence": {},
 71597          "signature": {
 71598            "signature": {
 71599              "publicKey": {}
 71600            }
 71601          },
 71602          "modelCard": {
 71603            "modelParameters": {
 71604              "approach": {}
 71605            },
 71606            "quantitativeAnalysis": {
 71607              "graphics": {}
 71608            },
 71609            "considerations": {}
 71610          }
 71611        },
 71612        {
 71613          "type": "library",
 71614          "bom-ref": "pkg:deb/debian/libfontconfig1@2.13.1-4.2?arch=amd64\u0026upstream=fontconfig\u0026distro=debian-11\u0026package-id=f0e377aa1de8214e",
 71615          "supplier": {},
 71616          "publisher": "Debian freedesktop.org maintainers \u003cpkg-freedesktop-maintainers@lists.alioth.debian.org\u003e",
 71617          "name": "libfontconfig1",
 71618          "version": "2.13.1-4.2",
 71619          "cpe": "cpe:2.3:a:libfontconfig1:libfontconfig1:2.13.1-4.2:*:*:*:*:*:*:*",
 71620          "purl": "pkg:deb/debian/libfontconfig1@2.13.1-4.2?arch=amd64\u0026upstream=fontconfig\u0026distro=debian-11",
 71621          "swid": {
 71622            "attachment": {}
 71623          },
 71624          "pedigree": {},
 71625          "evidence": {},
 71626          "signature": {
 71627            "signature": {
 71628              "publicKey": {}
 71629            }
 71630          },
 71631          "modelCard": {
 71632            "modelParameters": {
 71633              "approach": {}
 71634            },
 71635            "quantitativeAnalysis": {
 71636              "graphics": {}
 71637            },
 71638            "considerations": {}
 71639          }
 71640        },
 71641        {
 71642          "type": "library",
 71643          "bom-ref": "pkg:deb/debian/libfreetype6@2.10.4+dfsg-1+deb11u1?arch=amd64\u0026upstream=freetype\u0026distro=debian-11\u0026package-id=55f5893ecb8315bb",
 71644          "supplier": {},
 71645          "publisher": "Hugh McMaster \u003chugh.mcmaster@outlook.com\u003e",
 71646          "name": "libfreetype6",
 71647          "version": "2.10.4+dfsg-1+deb11u1",
 71648          "licenses": [
 71649            {
 71650              "license": {
 71651                "id": "Apache-2.0"
 71652              }
 71653            },
 71654            {
 71655              "license": {
 71656                "id": "BSD-3-Clause"
 71657              }
 71658            },
 71659            {
 71660              "license": {
 71661                "id": "FSFAP"
 71662              }
 71663            },
 71664            {
 71665              "license": {
 71666                "id": "FSFUL"
 71667              }
 71668            },
 71669            {
 71670              "license": {
 71671                "id": "FSFULLR"
 71672              }
 71673            },
 71674            {
 71675              "license": {
 71676                "id": "FTL"
 71677              }
 71678            },
 71679            {
 71680              "license": {
 71681                "id": "GPL-2.0-only"
 71682              }
 71683            },
 71684            {
 71685              "license": {
 71686                "id": "GPL-2.0-or-later"
 71687              }
 71688            },
 71689            {
 71690              "license": {
 71691                "id": "GPL-3.0-only"
 71692              }
 71693            },
 71694            {
 71695              "license": {
 71696                "id": "GPL-3.0-or-later"
 71697              }
 71698            },
 71699            {
 71700              "license": {
 71701                "id": "MIT"
 71702              }
 71703            },
 71704            {
 71705              "license": {
 71706                "id": "OFL-1.1"
 71707              }
 71708            },
 71709            {
 71710              "license": {
 71711                "name": "OpenGroup-BSD-like"
 71712              }
 71713            },
 71714            {
 71715              "license": {
 71716                "name": "Permissive"
 71717              }
 71718            },
 71719            {
 71720              "license": {
 71721                "name": "Public-Domain"
 71722              }
 71723            },
 71724            {
 71725              "license": {
 71726                "id": "Zlib"
 71727              }
 71728            }
 71729          ],
 71730          "cpe": "cpe:2.3:a:libfreetype6:libfreetype6:2.10.4\\+dfsg-1\\+deb11u1:*:*:*:*:*:*:*",
 71731          "purl": "pkg:deb/debian/libfreetype6@2.10.4+dfsg-1+deb11u1?arch=amd64\u0026upstream=freetype\u0026distro=debian-11",
 71732          "swid": {
 71733            "attachment": {}
 71734          },
 71735          "pedigree": {},
 71736          "evidence": {},
 71737          "signature": {
 71738            "signature": {
 71739              "publicKey": {}
 71740            }
 71741          },
 71742          "modelCard": {
 71743            "modelParameters": {
 71744              "approach": {}
 71745            },
 71746            "quantitativeAnalysis": {
 71747              "graphics": {}
 71748            },
 71749            "considerations": {}
 71750          }
 71751        },
 71752        {
 71753          "type": "library",
 71754          "bom-ref": "pkg:deb/debian/libgcc-s1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=ddb4ba0153b59955",
 71755          "supplier": {},
 71756          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 71757          "name": "libgcc-s1",
 71758          "version": "10.2.1-6",
 71759          "licenses": [
 71760            {
 71761              "license": {
 71762                "name": "Artistic"
 71763              }
 71764            },
 71765            {
 71766              "license": {
 71767                "id": "GFDL-1.2-only"
 71768              }
 71769            },
 71770            {
 71771              "license": {
 71772                "name": "GPL"
 71773              }
 71774            },
 71775            {
 71776              "license": {
 71777                "id": "GPL-2.0-only"
 71778              }
 71779            },
 71780            {
 71781              "license": {
 71782                "id": "GPL-3.0-only"
 71783              }
 71784            },
 71785            {
 71786              "license": {
 71787                "name": "LGPL"
 71788              }
 71789            }
 71790          ],
 71791          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.2.1-6:*:*:*:*:*:*:*",
 71792          "purl": "pkg:deb/debian/libgcc-s1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
 71793          "swid": {
 71794            "attachment": {}
 71795          },
 71796          "pedigree": {},
 71797          "evidence": {},
 71798          "signature": {
 71799            "signature": {
 71800              "publicKey": {}
 71801            }
 71802          },
 71803          "modelCard": {
 71804            "modelParameters": {
 71805              "approach": {}
 71806            },
 71807            "quantitativeAnalysis": {
 71808              "graphics": {}
 71809            },
 71810            "considerations": {}
 71811          }
 71812        },
 71813        {
 71814          "type": "library",
 71815          "bom-ref": "pkg:deb/debian/libgcrypt20@1.8.7-6?arch=amd64\u0026distro=debian-11\u0026package-id=7bc9b7389c934ca8",
 71816          "supplier": {},
 71817          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 71818          "name": "libgcrypt20",
 71819          "version": "1.8.7-6",
 71820          "licenses": [
 71821            {
 71822              "license": {
 71823                "id": "GPL-2.0-only"
 71824              }
 71825            },
 71826            {
 71827              "license": {
 71828                "name": "LGPL"
 71829              }
 71830            }
 71831          ],
 71832          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.7-6:*:*:*:*:*:*:*",
 71833          "purl": "pkg:deb/debian/libgcrypt20@1.8.7-6?arch=amd64\u0026distro=debian-11",
 71834          "swid": {
 71835            "attachment": {}
 71836          },
 71837          "pedigree": {},
 71838          "evidence": {},
 71839          "signature": {
 71840            "signature": {
 71841              "publicKey": {}
 71842            }
 71843          },
 71844          "modelCard": {
 71845            "modelParameters": {
 71846              "approach": {}
 71847            },
 71848            "quantitativeAnalysis": {
 71849              "graphics": {}
 71850            },
 71851            "considerations": {}
 71852          }
 71853        },
 71854        {
 71855          "type": "library",
 71856          "bom-ref": "pkg:deb/debian/libgd3@2.3.0-2?arch=amd64\u0026upstream=libgd2\u0026distro=debian-11\u0026package-id=2b8f05c459f3fd23",
 71857          "supplier": {},
 71858          "publisher": "GD Team \u003cteam+gd@tracker.debian.org\u003e",
 71859          "name": "libgd3",
 71860          "version": "2.3.0-2",
 71861          "licenses": [
 71862            {
 71863              "license": {
 71864                "id": "BSD-3-Clause"
 71865              }
 71866            },
 71867            {
 71868              "license": {
 71869                "name": "GAP~Makefile.in"
 71870              }
 71871            },
 71872            {
 71873              "license": {
 71874                "name": "GAP~configure"
 71875              }
 71876            },
 71877            {
 71878              "license": {
 71879                "id": "GD"
 71880              }
 71881            },
 71882            {
 71883              "license": {
 71884                "id": "GPL-2.0-only"
 71885              }
 71886            },
 71887            {
 71888              "license": {
 71889                "id": "GPL-2.0-or-later"
 71890              }
 71891            },
 71892            {
 71893              "license": {
 71894                "id": "HPND"
 71895              }
 71896            },
 71897            {
 71898              "license": {
 71899                "id": "MIT"
 71900              }
 71901            },
 71902            {
 71903              "license": {
 71904                "name": "WEBP"
 71905              }
 71906            },
 71907            {
 71908              "license": {
 71909                "name": "XFIG"
 71910              }
 71911            }
 71912          ],
 71913          "cpe": "cpe:2.3:a:libgd3:libgd3:2.3.0-2:*:*:*:*:*:*:*",
 71914          "purl": "pkg:deb/debian/libgd3@2.3.0-2?arch=amd64\u0026upstream=libgd2\u0026distro=debian-11",
 71915          "swid": {
 71916            "attachment": {}
 71917          },
 71918          "pedigree": {},
 71919          "evidence": {},
 71920          "signature": {
 71921            "signature": {
 71922              "publicKey": {}
 71923            }
 71924          },
 71925          "modelCard": {
 71926            "modelParameters": {
 71927              "approach": {}
 71928            },
 71929            "quantitativeAnalysis": {
 71930              "graphics": {}
 71931            },
 71932            "considerations": {}
 71933          }
 71934        },
 71935        {
 71936          "type": "library",
 71937          "bom-ref": "pkg:deb/debian/libgeoip1@1.6.12-7?arch=amd64\u0026upstream=geoip\u0026distro=debian-11\u0026package-id=bf7ae46036b453be",
 71938          "supplier": {},
 71939          "publisher": "Patrick Matthäi \u003cpmatthaei@debian.org\u003e",
 71940          "name": "libgeoip1",
 71941          "version": "1.6.12-7",
 71942          "licenses": [
 71943            {
 71944              "license": {
 71945                "id": "ISC"
 71946              }
 71947            },
 71948            {
 71949              "license": {
 71950                "id": "LGPL-2.1-only"
 71951              }
 71952            },
 71953            {
 71954              "license": {
 71955                "id": "LGPL-2.1-or-later"
 71956              }
 71957            }
 71958          ],
 71959          "cpe": "cpe:2.3:a:libgeoip1:libgeoip1:1.6.12-7:*:*:*:*:*:*:*",
 71960          "purl": "pkg:deb/debian/libgeoip1@1.6.12-7?arch=amd64\u0026upstream=geoip\u0026distro=debian-11",
 71961          "swid": {
 71962            "attachment": {}
 71963          },
 71964          "pedigree": {},
 71965          "evidence": {},
 71966          "signature": {
 71967            "signature": {
 71968              "publicKey": {}
 71969            }
 71970          },
 71971          "modelCard": {
 71972            "modelParameters": {
 71973              "approach": {}
 71974            },
 71975            "quantitativeAnalysis": {
 71976              "graphics": {}
 71977            },
 71978            "considerations": {}
 71979          }
 71980        },
 71981        {
 71982          "type": "library",
 71983          "bom-ref": "pkg:deb/debian/libgmp10@2:6.2.1+dfsg-1+deb11u1?arch=amd64\u0026upstream=gmp\u0026distro=debian-11\u0026package-id=b8566db47d8d4ddc",
 71984          "supplier": {},
 71985          "publisher": "Debian Science Team \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e",
 71986          "name": "libgmp10",
 71987          "version": "2:6.2.1+dfsg-1+deb11u1",
 71988          "licenses": [
 71989            {
 71990              "license": {
 71991                "name": "GPL"
 71992              }
 71993            },
 71994            {
 71995              "license": {
 71996                "id": "GPL-2.0-only"
 71997              }
 71998            },
 71999            {
 72000              "license": {
 72001                "id": "GPL-3.0-only"
 72002              }
 72003            },
 72004            {
 72005              "license": {
 72006                "id": "LGPL-3.0-only"
 72007              }
 72008            }
 72009          ],
 72010          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.1\\+dfsg-1\\+deb11u1:*:*:*:*:*:*:*",
 72011          "purl": "pkg:deb/debian/libgmp10@2:6.2.1+dfsg-1+deb11u1?arch=amd64\u0026upstream=gmp\u0026distro=debian-11",
 72012          "swid": {
 72013            "attachment": {}
 72014          },
 72015          "pedigree": {},
 72016          "evidence": {},
 72017          "signature": {
 72018            "signature": {
 72019              "publicKey": {}
 72020            }
 72021          },
 72022          "modelCard": {
 72023            "modelParameters": {
 72024              "approach": {}
 72025            },
 72026            "quantitativeAnalysis": {
 72027              "graphics": {}
 72028            },
 72029            "considerations": {}
 72030          }
 72031        },
 72032        {
 72033          "type": "library",
 72034          "bom-ref": "pkg:deb/debian/libgnutls30@3.7.1-5+deb11u3?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-11\u0026package-id=7a4a4d471a0c6aed",
 72035          "supplier": {},
 72036          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 72037          "name": "libgnutls30",
 72038          "version": "3.7.1-5+deb11u3",
 72039          "licenses": [
 72040            {
 72041              "license": {
 72042                "id": "Apache-2.0"
 72043              }
 72044            },
 72045            {
 72046              "license": {
 72047                "id": "BSD-3-Clause"
 72048              }
 72049            },
 72050            {
 72051              "license": {
 72052                "name": "CC0"
 72053              }
 72054            },
 72055            {
 72056              "license": {
 72057                "name": "Expat"
 72058              }
 72059            },
 72060            {
 72061              "license": {
 72062                "id": "GFDL-1.3-only"
 72063              }
 72064            },
 72065            {
 72066              "license": {
 72067                "name": "GPL"
 72068              }
 72069            },
 72070            {
 72071              "license": {
 72072                "id": "GPL-3.0-only"
 72073              }
 72074            },
 72075            {
 72076              "license": {
 72077                "name": "GPLv3+"
 72078              }
 72079            },
 72080            {
 72081              "license": {
 72082                "name": "LGPL"
 72083              }
 72084            },
 72085            {
 72086              "license": {
 72087                "id": "LGPL-3.0-only"
 72088              }
 72089            },
 72090            {
 72091              "license": {
 72092                "name": "LGPLv2.1+"
 72093              }
 72094            },
 72095            {
 72096              "license": {
 72097                "name": "LGPLv3+_or_GPLv2+"
 72098              }
 72099            },
 72100            {
 72101              "license": {
 72102                "name": "The"
 72103              }
 72104            }
 72105          ],
 72106          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.7.1-5\\+deb11u3:*:*:*:*:*:*:*",
 72107          "purl": "pkg:deb/debian/libgnutls30@3.7.1-5+deb11u3?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-11",
 72108          "swid": {
 72109            "attachment": {}
 72110          },
 72111          "pedigree": {},
 72112          "evidence": {},
 72113          "signature": {
 72114            "signature": {
 72115              "publicKey": {}
 72116            }
 72117          },
 72118          "modelCard": {
 72119            "modelParameters": {
 72120              "approach": {}
 72121            },
 72122            "quantitativeAnalysis": {
 72123              "graphics": {}
 72124            },
 72125            "considerations": {}
 72126          }
 72127        },
 72128        {
 72129          "type": "library",
 72130          "bom-ref": "pkg:deb/debian/libgpg-error0@1.38-2?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-11\u0026package-id=2391ec82a95e1b79",
 72131          "supplier": {},
 72132          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
 72133          "name": "libgpg-error0",
 72134          "version": "1.38-2",
 72135          "licenses": [
 72136            {
 72137              "license": {
 72138                "id": "BSD-3-Clause"
 72139              }
 72140            },
 72141            {
 72142              "license": {
 72143                "id": "GPL-3.0-only"
 72144              }
 72145            },
 72146            {
 72147              "license": {
 72148                "id": "GPL-3.0-or-later"
 72149              }
 72150            },
 72151            {
 72152              "license": {
 72153                "id": "LGPL-2.1-only"
 72154              }
 72155            },
 72156            {
 72157              "license": {
 72158                "id": "LGPL-2.1-or-later"
 72159              }
 72160            },
 72161            {
 72162              "license": {
 72163                "name": "g10-permissive"
 72164              }
 72165            }
 72166          ],
 72167          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.38-2:*:*:*:*:*:*:*",
 72168          "purl": "pkg:deb/debian/libgpg-error0@1.38-2?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-11",
 72169          "swid": {
 72170            "attachment": {}
 72171          },
 72172          "pedigree": {},
 72173          "evidence": {},
 72174          "signature": {
 72175            "signature": {
 72176              "publicKey": {}
 72177            }
 72178          },
 72179          "modelCard": {
 72180            "modelParameters": {
 72181              "approach": {}
 72182            },
 72183            "quantitativeAnalysis": {
 72184              "graphics": {}
 72185            },
 72186            "considerations": {}
 72187          }
 72188        },
 72189        {
 72190          "type": "library",
 72191          "bom-ref": "pkg:deb/debian/libgssapi-krb5-2@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=3f685865c7e045c1",
 72192          "supplier": {},
 72193          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
 72194          "name": "libgssapi-krb5-2",
 72195          "version": "1.18.3-6+deb11u3",
 72196          "licenses": [
 72197            {
 72198              "license": {
 72199                "id": "GPL-2.0-only"
 72200              }
 72201            }
 72202          ],
 72203          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
 72204          "purl": "pkg:deb/debian/libgssapi-krb5-2@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
 72205          "swid": {
 72206            "attachment": {}
 72207          },
 72208          "pedigree": {},
 72209          "evidence": {},
 72210          "signature": {
 72211            "signature": {
 72212              "publicKey": {}
 72213            }
 72214          },
 72215          "modelCard": {
 72216            "modelParameters": {
 72217              "approach": {}
 72218            },
 72219            "quantitativeAnalysis": {
 72220              "graphics": {}
 72221            },
 72222            "considerations": {}
 72223          }
 72224        },
 72225        {
 72226          "type": "library",
 72227          "bom-ref": "pkg:deb/debian/libhogweed6@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11\u0026package-id=5e22b39e8cb919f6",
 72228          "supplier": {},
 72229          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
 72230          "name": "libhogweed6",
 72231          "version": "3.7.3-1",
 72232          "licenses": [
 72233            {
 72234              "license": {
 72235                "name": "Expat"
 72236              }
 72237            },
 72238            {
 72239              "license": {
 72240                "name": "GAP"
 72241              }
 72242            },
 72243            {
 72244              "license": {
 72245                "name": "GPL"
 72246              }
 72247            },
 72248            {
 72249              "license": {
 72250                "id": "GPL-2.0-only"
 72251              }
 72252            },
 72253            {
 72254              "license": {
 72255                "id": "GPL-2.0-or-later"
 72256              }
 72257            },
 72258            {
 72259              "license": {
 72260                "id": "GPL-3.0-or-later"
 72261              }
 72262            },
 72263            {
 72264              "license": {
 72265                "name": "LGPL"
 72266              }
 72267            },
 72268            {
 72269              "license": {
 72270                "id": "LGPL-2.0-only"
 72271              }
 72272            },
 72273            {
 72274              "license": {
 72275                "id": "LGPL-2.0-or-later"
 72276              }
 72277            },
 72278            {
 72279              "license": {
 72280                "id": "LGPL-3.0-or-later"
 72281              }
 72282            },
 72283            {
 72284              "license": {
 72285                "name": "public-domain"
 72286              }
 72287            }
 72288          ],
 72289          "cpe": "cpe:2.3:a:libhogweed6:libhogweed6:3.7.3-1:*:*:*:*:*:*:*",
 72290          "purl": "pkg:deb/debian/libhogweed6@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11",
 72291          "swid": {
 72292            "attachment": {}
 72293          },
 72294          "pedigree": {},
 72295          "evidence": {},
 72296          "signature": {
 72297            "signature": {
 72298              "publicKey": {}
 72299            }
 72300          },
 72301          "modelCard": {
 72302            "modelParameters": {
 72303              "approach": {}
 72304            },
 72305            "quantitativeAnalysis": {
 72306              "graphics": {}
 72307            },
 72308            "considerations": {}
 72309          }
 72310        },
 72311        {
 72312          "type": "library",
 72313          "bom-ref": "pkg:deb/debian/libicu67@67.1-7?arch=amd64\u0026upstream=icu\u0026distro=debian-11\u0026package-id=52bb142f2f6f57d4",
 72314          "supplier": {},
 72315          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
 72316          "name": "libicu67",
 72317          "version": "67.1-7",
 72318          "cpe": "cpe:2.3:a:libicu67:libicu67:67.1-7:*:*:*:*:*:*:*",
 72319          "purl": "pkg:deb/debian/libicu67@67.1-7?arch=amd64\u0026upstream=icu\u0026distro=debian-11",
 72320          "swid": {
 72321            "attachment": {}
 72322          },
 72323          "pedigree": {},
 72324          "evidence": {},
 72325          "signature": {
 72326            "signature": {
 72327              "publicKey": {}
 72328            }
 72329          },
 72330          "modelCard": {
 72331            "modelParameters": {
 72332              "approach": {}
 72333            },
 72334            "quantitativeAnalysis": {
 72335              "graphics": {}
 72336            },
 72337            "considerations": {}
 72338          }
 72339        },
 72340        {
 72341          "type": "library",
 72342          "bom-ref": "pkg:deb/debian/libidn2-0@2.3.0-5?arch=amd64\u0026upstream=libidn2\u0026distro=debian-11\u0026package-id=8eb1c8304ad48ef2",
 72343          "supplier": {},
 72344          "publisher": "Debian Libidn team \u003chelp-libidn@gnu.org\u003e",
 72345          "name": "libidn2-0",
 72346          "version": "2.3.0-5",
 72347          "licenses": [
 72348            {
 72349              "license": {
 72350                "id": "GPL-2.0-only"
 72351              }
 72352            },
 72353            {
 72354              "license": {
 72355                "id": "GPL-2.0-or-later"
 72356              }
 72357            },
 72358            {
 72359              "license": {
 72360                "id": "GPL-3.0-only"
 72361              }
 72362            },
 72363            {
 72364              "license": {
 72365                "id": "GPL-3.0-or-later"
 72366              }
 72367            },
 72368            {
 72369              "license": {
 72370                "id": "LGPL-3.0-only"
 72371              }
 72372            },
 72373            {
 72374              "license": {
 72375                "id": "LGPL-3.0-or-later"
 72376              }
 72377            },
 72378            {
 72379              "license": {
 72380                "name": "Unicode"
 72381              }
 72382            }
 72383          ],
 72384          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.3.0-5:*:*:*:*:*:*:*",
 72385          "purl": "pkg:deb/debian/libidn2-0@2.3.0-5?arch=amd64\u0026upstream=libidn2\u0026distro=debian-11",
 72386          "swid": {
 72387            "attachment": {}
 72388          },
 72389          "pedigree": {},
 72390          "evidence": {},
 72391          "signature": {
 72392            "signature": {
 72393              "publicKey": {}
 72394            }
 72395          },
 72396          "modelCard": {
 72397            "modelParameters": {
 72398              "approach": {}
 72399            },
 72400            "quantitativeAnalysis": {
 72401              "graphics": {}
 72402            },
 72403            "considerations": {}
 72404          }
 72405        },
 72406        {
 72407          "type": "library",
 72408          "bom-ref": "pkg:maven/libintl/libintl@0.21?package-id=a29ca26c5c907c8",
 72409          "supplier": {},
 72410          "name": "libintl",
 72411          "version": "0.21",
 72412          "cpe": "cpe:2.3:a:libintl:libintl:0.21:*:*:*:*:*:*:*",
 72413          "purl": "pkg:maven/libintl/libintl@0.21",
 72414          "swid": {
 72415            "attachment": {}
 72416          },
 72417          "pedigree": {},
 72418          "externalReferences": [
 72419            {
 72420              "type": "build-meta",
 72421              "hashes": [
 72422                {
 72423                  "alg": "SHA-1",
 72424                  "content": "568f3f90c3d6aced58de033a3547ccd2e4e088e8"
 72425                }
 72426              ]
 72427            }
 72428          ],
 72429          "evidence": {},
 72430          "signature": {
 72431            "signature": {
 72432              "publicKey": {}
 72433            }
 72434          },
 72435          "modelCard": {
 72436            "modelParameters": {
 72437              "approach": {}
 72438            },
 72439            "quantitativeAnalysis": {
 72440              "graphics": {}
 72441            },
 72442            "considerations": {}
 72443          }
 72444        },
 72445        {
 72446          "type": "library",
 72447          "bom-ref": "pkg:deb/debian/libjbig0@2.1-3.1+b2?arch=amd64\u0026upstream=jbigkit%402.1-3.1\u0026distro=debian-11\u0026package-id=ccf2e13886894508",
 72448          "supplier": {},
 72449          "publisher": "Michael van der Kolff \u003cmvanderkolff@gmail.com\u003e",
 72450          "name": "libjbig0",
 72451          "version": "2.1-3.1+b2",
 72452          "licenses": [
 72453            {
 72454              "license": {
 72455                "id": "GPL-2.0-only"
 72456              }
 72457            },
 72458            {
 72459              "license": {
 72460                "id": "GPL-2.0-or-later"
 72461              }
 72462            }
 72463          ],
 72464          "cpe": "cpe:2.3:a:libjbig0:libjbig0:2.1-3.1\\+b2:*:*:*:*:*:*:*",
 72465          "purl": "pkg:deb/debian/libjbig0@2.1-3.1+b2?arch=amd64\u0026upstream=jbigkit%402.1-3.1\u0026distro=debian-11",
 72466          "swid": {
 72467            "attachment": {}
 72468          },
 72469          "pedigree": {},
 72470          "evidence": {},
 72471          "signature": {
 72472            "signature": {
 72473              "publicKey": {}
 72474            }
 72475          },
 72476          "modelCard": {
 72477            "modelParameters": {
 72478              "approach": {}
 72479            },
 72480            "quantitativeAnalysis": {
 72481              "graphics": {}
 72482            },
 72483            "considerations": {}
 72484          }
 72485        },
 72486        {
 72487          "type": "library",
 72488          "bom-ref": "pkg:deb/debian/libjpeg62-turbo@1:2.0.6-4?arch=amd64\u0026upstream=libjpeg-turbo\u0026distro=debian-11\u0026package-id=2e17533511143831",
 72489          "supplier": {},
 72490          "publisher": "Ondřej Surý \u003condrej@debian.org\u003e",
 72491          "name": "libjpeg62-turbo",
 72492          "version": "1:2.0.6-4",
 72493          "licenses": [
 72494            {
 72495              "license": {
 72496                "name": "BSD-3"
 72497              }
 72498            },
 72499            {
 72500              "license": {
 72501                "name": "BSD-BY-LC-NE"
 72502              }
 72503            },
 72504            {
 72505              "license": {
 72506                "name": "Expat"
 72507              }
 72508            },
 72509            {
 72510              "license": {
 72511                "id": "NTP"
 72512              }
 72513            },
 72514            {
 72515              "license": {
 72516                "id": "Zlib"
 72517              }
 72518            }
 72519          ],
 72520          "cpe": "cpe:2.3:a:libjpeg62-turbo:libjpeg62-turbo:1\\:2.0.6-4:*:*:*:*:*:*:*",
 72521          "purl": "pkg:deb/debian/libjpeg62-turbo@1:2.0.6-4?arch=amd64\u0026upstream=libjpeg-turbo\u0026distro=debian-11",
 72522          "swid": {
 72523            "attachment": {}
 72524          },
 72525          "pedigree": {},
 72526          "evidence": {},
 72527          "signature": {
 72528            "signature": {
 72529              "publicKey": {}
 72530            }
 72531          },
 72532          "modelCard": {
 72533            "modelParameters": {
 72534              "approach": {}
 72535            },
 72536            "quantitativeAnalysis": {
 72537              "graphics": {}
 72538            },
 72539            "considerations": {}
 72540          }
 72541        },
 72542        {
 72543          "type": "library",
 72544          "bom-ref": "pkg:deb/debian/libk5crypto3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=ae9e3b8691722eba",
 72545          "supplier": {},
 72546          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
 72547          "name": "libk5crypto3",
 72548          "version": "1.18.3-6+deb11u3",
 72549          "licenses": [
 72550            {
 72551              "license": {
 72552                "id": "GPL-2.0-only"
 72553              }
 72554            }
 72555          ],
 72556          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
 72557          "purl": "pkg:deb/debian/libk5crypto3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
 72558          "swid": {
 72559            "attachment": {}
 72560          },
 72561          "pedigree": {},
 72562          "evidence": {},
 72563          "signature": {
 72564            "signature": {
 72565              "publicKey": {}
 72566            }
 72567          },
 72568          "modelCard": {
 72569            "modelParameters": {
 72570              "approach": {}
 72571            },
 72572            "quantitativeAnalysis": {
 72573              "graphics": {}
 72574            },
 72575            "considerations": {}
 72576          }
 72577        },
 72578        {
 72579          "type": "library",
 72580          "bom-ref": "pkg:deb/debian/libkeyutils1@1.6.1-2?arch=amd64\u0026upstream=keyutils\u0026distro=debian-11\u0026package-id=308487f5f23bf878",
 72581          "supplier": {},
 72582          "publisher": "Christian Kastner \u003cckk@debian.org\u003e",
 72583          "name": "libkeyutils1",
 72584          "version": "1.6.1-2",
 72585          "licenses": [
 72586            {
 72587              "license": {
 72588                "id": "GPL-2.0-only"
 72589              }
 72590            },
 72591            {
 72592              "license": {
 72593                "id": "GPL-2.0-or-later"
 72594              }
 72595            },
 72596            {
 72597              "license": {
 72598                "id": "LGPL-2.0-only"
 72599              }
 72600            },
 72601            {
 72602              "license": {
 72603                "id": "LGPL-2.0-or-later"
 72604              }
 72605            }
 72606          ],
 72607          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6.1-2:*:*:*:*:*:*:*",
 72608          "purl": "pkg:deb/debian/libkeyutils1@1.6.1-2?arch=amd64\u0026upstream=keyutils\u0026distro=debian-11",
 72609          "swid": {
 72610            "attachment": {}
 72611          },
 72612          "pedigree": {},
 72613          "evidence": {},
 72614          "signature": {
 72615            "signature": {
 72616              "publicKey": {}
 72617            }
 72618          },
 72619          "modelCard": {
 72620            "modelParameters": {
 72621              "approach": {}
 72622            },
 72623            "quantitativeAnalysis": {
 72624              "graphics": {}
 72625            },
 72626            "considerations": {}
 72627          }
 72628        },
 72629        {
 72630          "type": "library",
 72631          "bom-ref": "pkg:deb/debian/libkrb5-3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=8bdffe6652e8e7ef",
 72632          "supplier": {},
 72633          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
 72634          "name": "libkrb5-3",
 72635          "version": "1.18.3-6+deb11u3",
 72636          "licenses": [
 72637            {
 72638              "license": {
 72639                "id": "GPL-2.0-only"
 72640              }
 72641            }
 72642          ],
 72643          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
 72644          "purl": "pkg:deb/debian/libkrb5-3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
 72645          "swid": {
 72646            "attachment": {}
 72647          },
 72648          "pedigree": {},
 72649          "evidence": {},
 72650          "signature": {
 72651            "signature": {
 72652              "publicKey": {}
 72653            }
 72654          },
 72655          "modelCard": {
 72656            "modelParameters": {
 72657              "approach": {}
 72658            },
 72659            "quantitativeAnalysis": {
 72660              "graphics": {}
 72661            },
 72662            "considerations": {}
 72663          }
 72664        },
 72665        {
 72666          "type": "library",
 72667          "bom-ref": "pkg:deb/debian/libkrb5support0@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=471e6243bbbcf8b2",
 72668          "supplier": {},
 72669          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
 72670          "name": "libkrb5support0",
 72671          "version": "1.18.3-6+deb11u3",
 72672          "licenses": [
 72673            {
 72674              "license": {
 72675                "id": "GPL-2.0-only"
 72676              }
 72677            }
 72678          ],
 72679          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
 72680          "purl": "pkg:deb/debian/libkrb5support0@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
 72681          "swid": {
 72682            "attachment": {}
 72683          },
 72684          "pedigree": {},
 72685          "evidence": {},
 72686          "signature": {
 72687            "signature": {
 72688              "publicKey": {}
 72689            }
 72690          },
 72691          "modelCard": {
 72692            "modelParameters": {
 72693              "approach": {}
 72694            },
 72695            "quantitativeAnalysis": {
 72696              "graphics": {}
 72697            },
 72698            "considerations": {}
 72699          }
 72700        },
 72701        {
 72702          "type": "library",
 72703          "bom-ref": "pkg:deb/debian/libldap-2.4-2@2.4.57+dfsg-3+deb11u1?arch=amd64\u0026upstream=openldap\u0026distro=debian-11\u0026package-id=796a192b709a2a2b",
 72704          "supplier": {},
 72705          "publisher": "Debian OpenLDAP Maintainers \u003cpkg-openldap-devel@lists.alioth.debian.org\u003e",
 72706          "name": "libldap-2.4-2",
 72707          "version": "2.4.57+dfsg-3+deb11u1",
 72708          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.57\\+dfsg-3\\+deb11u1:*:*:*:*:*:*:*",
 72709          "purl": "pkg:deb/debian/libldap-2.4-2@2.4.57+dfsg-3+deb11u1?arch=amd64\u0026upstream=openldap\u0026distro=debian-11",
 72710          "swid": {
 72711            "attachment": {}
 72712          },
 72713          "pedigree": {},
 72714          "evidence": {},
 72715          "signature": {
 72716            "signature": {
 72717              "publicKey": {}
 72718            }
 72719          },
 72720          "modelCard": {
 72721            "modelParameters": {
 72722              "approach": {}
 72723            },
 72724            "quantitativeAnalysis": {
 72725              "graphics": {}
 72726            },
 72727            "considerations": {}
 72728          }
 72729        },
 72730        {
 72731          "type": "library",
 72732          "bom-ref": "pkg:deb/debian/liblz4-1@1.9.3-2?arch=amd64\u0026upstream=lz4\u0026distro=debian-11\u0026package-id=b59e208fb7f8bae4",
 72733          "supplier": {},
 72734          "publisher": "Nobuhiro Iwamatsu \u003ciwamatsu@debian.org\u003e",
 72735          "name": "liblz4-1",
 72736          "version": "1.9.3-2",
 72737          "licenses": [
 72738            {
 72739              "license": {
 72740                "id": "BSD-2-Clause"
 72741              }
 72742            },
 72743            {
 72744              "license": {
 72745                "id": "GPL-2.0-only"
 72746              }
 72747            },
 72748            {
 72749              "license": {
 72750                "id": "GPL-2.0-or-later"
 72751              }
 72752            }
 72753          ],
 72754          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.3-2:*:*:*:*:*:*:*",
 72755          "purl": "pkg:deb/debian/liblz4-1@1.9.3-2?arch=amd64\u0026upstream=lz4\u0026distro=debian-11",
 72756          "swid": {
 72757            "attachment": {}
 72758          },
 72759          "pedigree": {},
 72760          "evidence": {},
 72761          "signature": {
 72762            "signature": {
 72763              "publicKey": {}
 72764            }
 72765          },
 72766          "modelCard": {
 72767            "modelParameters": {
 72768              "approach": {}
 72769            },
 72770            "quantitativeAnalysis": {
 72771              "graphics": {}
 72772            },
 72773            "considerations": {}
 72774          }
 72775        },
 72776        {
 72777          "type": "library",
 72778          "bom-ref": "pkg:deb/debian/liblzma5@5.2.5-2.1~deb11u1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-11\u0026package-id=b95662a389d30c72",
 72779          "supplier": {},
 72780          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
 72781          "name": "liblzma5",
 72782          "version": "5.2.5-2.1~deb11u1",
 72783          "licenses": [
 72784            {
 72785              "license": {
 72786                "name": "Autoconf"
 72787              }
 72788            },
 72789            {
 72790              "license": {
 72791                "id": "GPL-2.0-only"
 72792              }
 72793            },
 72794            {
 72795              "license": {
 72796                "id": "GPL-2.0-or-later"
 72797              }
 72798            },
 72799            {
 72800              "license": {
 72801                "id": "GPL-3.0-only"
 72802              }
 72803            },
 72804            {
 72805              "license": {
 72806                "id": "LGPL-2.0-only"
 72807              }
 72808            },
 72809            {
 72810              "license": {
 72811                "id": "LGPL-2.1-only"
 72812              }
 72813            },
 72814            {
 72815              "license": {
 72816                "id": "LGPL-2.1-or-later"
 72817              }
 72818            },
 72819            {
 72820              "license": {
 72821                "name": "PD"
 72822              }
 72823            },
 72824            {
 72825              "license": {
 72826                "name": "PD-debian"
 72827              }
 72828            },
 72829            {
 72830              "license": {
 72831                "name": "config-h"
 72832              }
 72833            },
 72834            {
 72835              "license": {
 72836                "name": "noderivs"
 72837              }
 72838            },
 72839            {
 72840              "license": {
 72841                "name": "permissive-fsf"
 72842              }
 72843            },
 72844            {
 72845              "license": {
 72846                "name": "permissive-nowarranty"
 72847              }
 72848            },
 72849            {
 72850              "license": {
 72851                "name": "probably-PD"
 72852              }
 72853            }
 72854          ],
 72855          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.5-2.1\\~deb11u1:*:*:*:*:*:*:*",
 72856          "purl": "pkg:deb/debian/liblzma5@5.2.5-2.1~deb11u1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-11",
 72857          "swid": {
 72858            "attachment": {}
 72859          },
 72860          "pedigree": {},
 72861          "evidence": {},
 72862          "signature": {
 72863            "signature": {
 72864              "publicKey": {}
 72865            }
 72866          },
 72867          "modelCard": {
 72868            "modelParameters": {
 72869              "approach": {}
 72870            },
 72871            "quantitativeAnalysis": {
 72872              "graphics": {}
 72873            },
 72874            "considerations": {}
 72875          }
 72876        },
 72877        {
 72878          "type": "library",
 72879          "bom-ref": "pkg:deb/debian/libmd0@1.0.3-3?arch=amd64\u0026upstream=libmd\u0026distro=debian-11\u0026package-id=331d8d42d5fc0777",
 72880          "supplier": {},
 72881          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
 72882          "name": "libmd0",
 72883          "version": "1.0.3-3",
 72884          "licenses": [
 72885            {
 72886              "license": {
 72887                "id": "BSD-2-Clause"
 72888              }
 72889            },
 72890            {
 72891              "license": {
 72892                "id": "BSD-2-Clause"
 72893              }
 72894            },
 72895            {
 72896              "license": {
 72897                "id": "BSD-3-Clause"
 72898              }
 72899            },
 72900            {
 72901              "license": {
 72902                "name": "BSD-3-clause-Aaron-D-Gifford"
 72903              }
 72904            },
 72905            {
 72906              "license": {
 72907                "id": "Beerware"
 72908              }
 72909            },
 72910            {
 72911              "license": {
 72912                "id": "ISC"
 72913              }
 72914            },
 72915            {
 72916              "license": {
 72917                "name": "public-domain-md4"
 72918              }
 72919            },
 72920            {
 72921              "license": {
 72922                "name": "public-domain-md5"
 72923              }
 72924            },
 72925            {
 72926              "license": {
 72927                "name": "public-domain-sha1"
 72928              }
 72929            }
 72930          ],
 72931          "cpe": "cpe:2.3:a:libmd0:libmd0:1.0.3-3:*:*:*:*:*:*:*",
 72932          "purl": "pkg:deb/debian/libmd0@1.0.3-3?arch=amd64\u0026upstream=libmd\u0026distro=debian-11",
 72933          "swid": {
 72934            "attachment": {}
 72935          },
 72936          "pedigree": {},
 72937          "evidence": {},
 72938          "signature": {
 72939            "signature": {
 72940              "publicKey": {}
 72941            }
 72942          },
 72943          "modelCard": {
 72944            "modelParameters": {
 72945              "approach": {}
 72946            },
 72947            "quantitativeAnalysis": {
 72948              "graphics": {}
 72949            },
 72950            "considerations": {}
 72951          }
 72952        },
 72953        {
 72954          "type": "library",
 72955          "bom-ref": "pkg:deb/debian/libmount1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=afd0c3536366dc2c",
 72956          "supplier": {},
 72957          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 72958          "name": "libmount1",
 72959          "version": "2.36.1-8+deb11u1",
 72960          "licenses": [
 72961            {
 72962              "license": {
 72963                "id": "BSD-2-Clause"
 72964              }
 72965            },
 72966            {
 72967              "license": {
 72968                "id": "BSD-3-Clause"
 72969              }
 72970            },
 72971            {
 72972              "license": {
 72973                "id": "BSD-4-Clause"
 72974              }
 72975            },
 72976            {
 72977              "license": {
 72978                "id": "GPL-2.0-only"
 72979              }
 72980            },
 72981            {
 72982              "license": {
 72983                "id": "GPL-2.0-or-later"
 72984              }
 72985            },
 72986            {
 72987              "license": {
 72988                "id": "GPL-3.0-only"
 72989              }
 72990            },
 72991            {
 72992              "license": {
 72993                "id": "GPL-3.0-or-later"
 72994              }
 72995            },
 72996            {
 72997              "license": {
 72998                "name": "LGPL"
 72999              }
 73000            },
 73001            {
 73002              "license": {
 73003                "id": "LGPL-2.0-only"
 73004              }
 73005            },
 73006            {
 73007              "license": {
 73008                "id": "LGPL-2.0-or-later"
 73009              }
 73010            },
 73011            {
 73012              "license": {
 73013                "id": "LGPL-2.1-only"
 73014              }
 73015            },
 73016            {
 73017              "license": {
 73018                "id": "LGPL-2.1-or-later"
 73019              }
 73020            },
 73021            {
 73022              "license": {
 73023                "id": "LGPL-3.0-only"
 73024              }
 73025            },
 73026            {
 73027              "license": {
 73028                "id": "LGPL-3.0-or-later"
 73029              }
 73030            },
 73031            {
 73032              "license": {
 73033                "id": "MIT"
 73034              }
 73035            },
 73036            {
 73037              "license": {
 73038                "name": "public-domain"
 73039              }
 73040            }
 73041          ],
 73042          "cpe": "cpe:2.3:a:libmount1:libmount1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 73043          "purl": "pkg:deb/debian/libmount1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
 73044          "swid": {
 73045            "attachment": {}
 73046          },
 73047          "pedigree": {},
 73048          "evidence": {},
 73049          "signature": {
 73050            "signature": {
 73051              "publicKey": {}
 73052            }
 73053          },
 73054          "modelCard": {
 73055            "modelParameters": {
 73056              "approach": {}
 73057            },
 73058            "quantitativeAnalysis": {
 73059              "graphics": {}
 73060            },
 73061            "considerations": {}
 73062          }
 73063        },
 73064        {
 73065          "type": "library",
 73066          "bom-ref": "pkg:deb/debian/libnettle8@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11\u0026package-id=ceff94b390c9bf61",
 73067          "supplier": {},
 73068          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
 73069          "name": "libnettle8",
 73070          "version": "3.7.3-1",
 73071          "licenses": [
 73072            {
 73073              "license": {
 73074                "name": "Expat"
 73075              }
 73076            },
 73077            {
 73078              "license": {
 73079                "name": "GAP"
 73080              }
 73081            },
 73082            {
 73083              "license": {
 73084                "name": "GPL"
 73085              }
 73086            },
 73087            {
 73088              "license": {
 73089                "id": "GPL-2.0-only"
 73090              }
 73091            },
 73092            {
 73093              "license": {
 73094                "id": "GPL-2.0-or-later"
 73095              }
 73096            },
 73097            {
 73098              "license": {
 73099                "id": "GPL-3.0-or-later"
 73100              }
 73101            },
 73102            {
 73103              "license": {
 73104                "name": "LGPL"
 73105              }
 73106            },
 73107            {
 73108              "license": {
 73109                "id": "LGPL-2.0-only"
 73110              }
 73111            },
 73112            {
 73113              "license": {
 73114                "id": "LGPL-2.0-or-later"
 73115              }
 73116            },
 73117            {
 73118              "license": {
 73119                "id": "LGPL-3.0-or-later"
 73120              }
 73121            },
 73122            {
 73123              "license": {
 73124                "name": "public-domain"
 73125              }
 73126            }
 73127          ],
 73128          "cpe": "cpe:2.3:a:libnettle8:libnettle8:3.7.3-1:*:*:*:*:*:*:*",
 73129          "purl": "pkg:deb/debian/libnettle8@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11",
 73130          "swid": {
 73131            "attachment": {}
 73132          },
 73133          "pedigree": {},
 73134          "evidence": {},
 73135          "signature": {
 73136            "signature": {
 73137              "publicKey": {}
 73138            }
 73139          },
 73140          "modelCard": {
 73141            "modelParameters": {
 73142              "approach": {}
 73143            },
 73144            "quantitativeAnalysis": {
 73145              "graphics": {}
 73146            },
 73147            "considerations": {}
 73148          }
 73149        },
 73150        {
 73151          "type": "library",
 73152          "bom-ref": "pkg:deb/debian/libnghttp2-14@1.43.0-1?arch=amd64\u0026upstream=nghttp2\u0026distro=debian-11\u0026package-id=cfb81461ba0ee3f7",
 73153          "supplier": {},
 73154          "publisher": "Tomasz Buchert \u003ctomasz@debian.org\u003e",
 73155          "name": "libnghttp2-14",
 73156          "version": "1.43.0-1",
 73157          "licenses": [
 73158            {
 73159              "license": {
 73160                "id": "BSD-2-Clause"
 73161              }
 73162            },
 73163            {
 73164              "license": {
 73165                "name": "Expat"
 73166              }
 73167            },
 73168            {
 73169              "license": {
 73170                "id": "GPL-3.0-only"
 73171              }
 73172            },
 73173            {
 73174              "license": {
 73175                "id": "GPL-3.0-or-later"
 73176              }
 73177            },
 73178            {
 73179              "license": {
 73180                "id": "MIT"
 73181              }
 73182            },
 73183            {
 73184              "license": {
 73185                "name": "SIL-OFL-1.1"
 73186              }
 73187            },
 73188            {
 73189              "license": {
 73190                "name": "all-permissive"
 73191              }
 73192            }
 73193          ],
 73194          "cpe": "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.43.0-1:*:*:*:*:*:*:*",
 73195          "purl": "pkg:deb/debian/libnghttp2-14@1.43.0-1?arch=amd64\u0026upstream=nghttp2\u0026distro=debian-11",
 73196          "swid": {
 73197            "attachment": {}
 73198          },
 73199          "pedigree": {},
 73200          "evidence": {},
 73201          "signature": {
 73202            "signature": {
 73203              "publicKey": {}
 73204            }
 73205          },
 73206          "modelCard": {
 73207            "modelParameters": {
 73208              "approach": {}
 73209            },
 73210            "quantitativeAnalysis": {
 73211              "graphics": {}
 73212            },
 73213            "considerations": {}
 73214          }
 73215        },
 73216        {
 73217          "type": "library",
 73218          "bom-ref": "pkg:deb/debian/libnsl2@1.3.0-2?arch=amd64\u0026upstream=libnsl\u0026distro=debian-11\u0026package-id=fc8ac2f1807436d9",
 73219          "supplier": {},
 73220          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 73221          "name": "libnsl2",
 73222          "version": "1.3.0-2",
 73223          "licenses": [
 73224            {
 73225              "license": {
 73226                "id": "BSD-3-Clause"
 73227              }
 73228            },
 73229            {
 73230              "license": {
 73231                "id": "GPL-2.0-only"
 73232              }
 73233            },
 73234            {
 73235              "license": {
 73236                "name": "GPL-2+-autoconf-exception"
 73237              }
 73238            },
 73239            {
 73240              "license": {
 73241                "name": "GPL-2+-libtool-exception"
 73242              }
 73243            },
 73244            {
 73245              "license": {
 73246                "id": "GPL-3.0-only"
 73247              }
 73248            },
 73249            {
 73250              "license": {
 73251                "name": "GPL-3+-autoconf-exception"
 73252              }
 73253            },
 73254            {
 73255              "license": {
 73256                "id": "LGPL-2.1-only"
 73257              }
 73258            },
 73259            {
 73260              "license": {
 73261                "id": "LGPL-2.1-or-later"
 73262              }
 73263            },
 73264            {
 73265              "license": {
 73266                "id": "MIT"
 73267              }
 73268            },
 73269            {
 73270              "license": {
 73271                "name": "permissive-autoconf-m4"
 73272              }
 73273            },
 73274            {
 73275              "license": {
 73276                "name": "permissive-autoconf-m4-no-warranty"
 73277              }
 73278            },
 73279            {
 73280              "license": {
 73281                "name": "permissive-configure"
 73282              }
 73283            },
 73284            {
 73285              "license": {
 73286                "name": "permissive-fsf"
 73287              }
 73288            },
 73289            {
 73290              "license": {
 73291                "name": "permissive-makefile-in"
 73292              }
 73293            }
 73294          ],
 73295          "cpe": "cpe:2.3:a:libnsl2:libnsl2:1.3.0-2:*:*:*:*:*:*:*",
 73296          "purl": "pkg:deb/debian/libnsl2@1.3.0-2?arch=amd64\u0026upstream=libnsl\u0026distro=debian-11",
 73297          "swid": {
 73298            "attachment": {}
 73299          },
 73300          "pedigree": {},
 73301          "evidence": {},
 73302          "signature": {
 73303            "signature": {
 73304              "publicKey": {}
 73305            }
 73306          },
 73307          "modelCard": {
 73308            "modelParameters": {
 73309              "approach": {}
 73310            },
 73311            "quantitativeAnalysis": {
 73312              "graphics": {}
 73313            },
 73314            "considerations": {}
 73315          }
 73316        },
 73317        {
 73318          "type": "library",
 73319          "bom-ref": "pkg:deb/debian/libp11-kit0@0.23.22-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-11\u0026package-id=a2ce6d1eb48ab956",
 73320          "supplier": {},
 73321          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 73322          "name": "libp11-kit0",
 73323          "version": "0.23.22-1",
 73324          "licenses": [
 73325            {
 73326              "license": {
 73327                "id": "BSD-3-Clause"
 73328              }
 73329            },
 73330            {
 73331              "license": {
 73332                "id": "ISC"
 73333              }
 73334            },
 73335            {
 73336              "license": {
 73337                "name": "ISC+IBM"
 73338              }
 73339            },
 73340            {
 73341              "license": {
 73342                "name": "permissive-like-automake-output"
 73343              }
 73344            },
 73345            {
 73346              "license": {
 73347                "name": "same-as-rest-of-p11kit"
 73348              }
 73349            }
 73350          ],
 73351          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.22-1:*:*:*:*:*:*:*",
 73352          "purl": "pkg:deb/debian/libp11-kit0@0.23.22-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-11",
 73353          "swid": {
 73354            "attachment": {}
 73355          },
 73356          "pedigree": {},
 73357          "evidence": {},
 73358          "signature": {
 73359            "signature": {
 73360              "publicKey": {}
 73361            }
 73362          },
 73363          "modelCard": {
 73364            "modelParameters": {
 73365              "approach": {}
 73366            },
 73367            "quantitativeAnalysis": {
 73368              "graphics": {}
 73369            },
 73370            "considerations": {}
 73371          }
 73372        },
 73373        {
 73374          "type": "library",
 73375          "bom-ref": "pkg:deb/debian/libpam-modules@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11\u0026package-id=903eac5974d73705",
 73376          "supplier": {},
 73377          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 73378          "name": "libpam-modules",
 73379          "version": "1.4.0-9+deb11u1",
 73380          "licenses": [
 73381            {
 73382              "license": {
 73383                "name": "GPL"
 73384              }
 73385            }
 73386          ],
 73387          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
 73388          "purl": "pkg:deb/debian/libpam-modules@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11",
 73389          "swid": {
 73390            "attachment": {}
 73391          },
 73392          "pedigree": {},
 73393          "evidence": {},
 73394          "signature": {
 73395            "signature": {
 73396              "publicKey": {}
 73397            }
 73398          },
 73399          "modelCard": {
 73400            "modelParameters": {
 73401              "approach": {}
 73402            },
 73403            "quantitativeAnalysis": {
 73404              "graphics": {}
 73405            },
 73406            "considerations": {}
 73407          }
 73408        },
 73409        {
 73410          "type": "library",
 73411          "bom-ref": "pkg:deb/debian/libpam-modules-bin@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11\u0026package-id=2dc3f20bb97e020d",
 73412          "supplier": {},
 73413          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 73414          "name": "libpam-modules-bin",
 73415          "version": "1.4.0-9+deb11u1",
 73416          "licenses": [
 73417            {
 73418              "license": {
 73419                "name": "GPL"
 73420              }
 73421            }
 73422          ],
 73423          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
 73424          "purl": "pkg:deb/debian/libpam-modules-bin@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11",
 73425          "swid": {
 73426            "attachment": {}
 73427          },
 73428          "pedigree": {},
 73429          "evidence": {},
 73430          "signature": {
 73431            "signature": {
 73432              "publicKey": {}
 73433            }
 73434          },
 73435          "modelCard": {
 73436            "modelParameters": {
 73437              "approach": {}
 73438            },
 73439            "quantitativeAnalysis": {
 73440              "graphics": {}
 73441            },
 73442            "considerations": {}
 73443          }
 73444        },
 73445        {
 73446          "type": "library",
 73447          "bom-ref": "pkg:deb/debian/libpam-runtime@1.4.0-9+deb11u1?arch=all\u0026upstream=pam\u0026distro=debian-11\u0026package-id=1238d07342abe7a3",
 73448          "supplier": {},
 73449          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 73450          "name": "libpam-runtime",
 73451          "version": "1.4.0-9+deb11u1",
 73452          "licenses": [
 73453            {
 73454              "license": {
 73455                "name": "GPL"
 73456              }
 73457            }
 73458          ],
 73459          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
 73460          "purl": "pkg:deb/debian/libpam-runtime@1.4.0-9+deb11u1?arch=all\u0026upstream=pam\u0026distro=debian-11",
 73461          "swid": {
 73462            "attachment": {}
 73463          },
 73464          "pedigree": {},
 73465          "evidence": {},
 73466          "signature": {
 73467            "signature": {
 73468              "publicKey": {}
 73469            }
 73470          },
 73471          "modelCard": {
 73472            "modelParameters": {
 73473              "approach": {}
 73474            },
 73475            "quantitativeAnalysis": {
 73476              "graphics": {}
 73477            },
 73478            "considerations": {}
 73479          }
 73480        },
 73481        {
 73482          "type": "library",
 73483          "bom-ref": "pkg:deb/debian/libpam0g@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11\u0026package-id=70917c5424d601fa",
 73484          "supplier": {},
 73485          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
 73486          "name": "libpam0g",
 73487          "version": "1.4.0-9+deb11u1",
 73488          "licenses": [
 73489            {
 73490              "license": {
 73491                "name": "GPL"
 73492              }
 73493            }
 73494          ],
 73495          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
 73496          "purl": "pkg:deb/debian/libpam0g@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11",
 73497          "swid": {
 73498            "attachment": {}
 73499          },
 73500          "pedigree": {},
 73501          "evidence": {},
 73502          "signature": {
 73503            "signature": {
 73504              "publicKey": {}
 73505            }
 73506          },
 73507          "modelCard": {
 73508            "modelParameters": {
 73509              "approach": {}
 73510            },
 73511            "quantitativeAnalysis": {
 73512              "graphics": {}
 73513            },
 73514            "considerations": {}
 73515          }
 73516        },
 73517        {
 73518          "type": "library",
 73519          "bom-ref": "pkg:deb/debian/libpcre2-8-0@10.36-2+deb11u1?arch=amd64\u0026upstream=pcre2\u0026distro=debian-11\u0026package-id=5d07d7ec308f6bb2",
 73520          "supplier": {},
 73521          "publisher": "Matthew Vernon \u003cmatthew@debian.org\u003e",
 73522          "name": "libpcre2-8-0",
 73523          "version": "10.36-2+deb11u1",
 73524          "cpe": "cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.36-2\\+deb11u1:*:*:*:*:*:*:*",
 73525          "purl": "pkg:deb/debian/libpcre2-8-0@10.36-2+deb11u1?arch=amd64\u0026upstream=pcre2\u0026distro=debian-11",
 73526          "swid": {
 73527            "attachment": {}
 73528          },
 73529          "pedigree": {},
 73530          "evidence": {},
 73531          "signature": {
 73532            "signature": {
 73533              "publicKey": {}
 73534            }
 73535          },
 73536          "modelCard": {
 73537            "modelParameters": {
 73538              "approach": {}
 73539            },
 73540            "quantitativeAnalysis": {
 73541              "graphics": {}
 73542            },
 73543            "considerations": {}
 73544          }
 73545        },
 73546        {
 73547          "type": "library",
 73548          "bom-ref": "pkg:deb/debian/libpcre3@2:8.39-13?arch=amd64\u0026upstream=pcre3\u0026distro=debian-11\u0026package-id=1c1641a0882b431f",
 73549          "supplier": {},
 73550          "publisher": "Matthew Vernon \u003cmatthew@debian.org\u003e",
 73551          "name": "libpcre3",
 73552          "version": "2:8.39-13",
 73553          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-13:*:*:*:*:*:*:*",
 73554          "purl": "pkg:deb/debian/libpcre3@2:8.39-13?arch=amd64\u0026upstream=pcre3\u0026distro=debian-11",
 73555          "swid": {
 73556            "attachment": {}
 73557          },
 73558          "pedigree": {},
 73559          "evidence": {},
 73560          "signature": {
 73561            "signature": {
 73562              "publicKey": {}
 73563            }
 73564          },
 73565          "modelCard": {
 73566            "modelParameters": {
 73567              "approach": {}
 73568            },
 73569            "quantitativeAnalysis": {
 73570              "graphics": {}
 73571            },
 73572            "considerations": {}
 73573          }
 73574        },
 73575        {
 73576          "type": "library",
 73577          "bom-ref": "pkg:deb/debian/libpng16-16@1.6.37-3?arch=amd64\u0026upstream=libpng1.6\u0026distro=debian-11\u0026package-id=9821c1ad36f085c7",
 73578          "supplier": {},
 73579          "publisher": "Maintainers of libpng1.6 packages \u003clibpng1.6@packages.debian.org\u003e",
 73580          "name": "libpng16-16",
 73581          "version": "1.6.37-3",
 73582          "licenses": [
 73583            {
 73584              "license": {
 73585                "id": "Apache-2.0"
 73586              }
 73587            },
 73588            {
 73589              "license": {
 73590                "id": "BSD-3-Clause"
 73591              }
 73592            },
 73593            {
 73594              "license": {
 73595                "name": "BSD-like-with-advertising-clause"
 73596              }
 73597            },
 73598            {
 73599              "license": {
 73600                "id": "GPL-2.0-only"
 73601              }
 73602            },
 73603            {
 73604              "license": {
 73605                "id": "GPL-2.0-or-later"
 73606              }
 73607            },
 73608            {
 73609              "license": {
 73610                "name": "expat"
 73611              }
 73612            },
 73613            {
 73614              "license": {
 73615                "id": "Libpng"
 73616              }
 73617            }
 73618          ],
 73619          "cpe": "cpe:2.3:a:libpng16-16:libpng16-16:1.6.37-3:*:*:*:*:*:*:*",
 73620          "purl": "pkg:deb/debian/libpng16-16@1.6.37-3?arch=amd64\u0026upstream=libpng1.6\u0026distro=debian-11",
 73621          "swid": {
 73622            "attachment": {}
 73623          },
 73624          "pedigree": {},
 73625          "evidence": {},
 73626          "signature": {
 73627            "signature": {
 73628              "publicKey": {}
 73629            }
 73630          },
 73631          "modelCard": {
 73632            "modelParameters": {
 73633              "approach": {}
 73634            },
 73635            "quantitativeAnalysis": {
 73636              "graphics": {}
 73637            },
 73638            "considerations": {}
 73639          }
 73640        },
 73641        {
 73642          "type": "library",
 73643          "bom-ref": "pkg:deb/debian/libpsl5@0.21.0-1.2?arch=amd64\u0026upstream=libpsl\u0026distro=debian-11\u0026package-id=3409718c91a2d222",
 73644          "supplier": {},
 73645          "publisher": "Tim Rühsen \u003ctim.ruehsen@gmx.de\u003e",
 73646          "name": "libpsl5",
 73647          "version": "0.21.0-1.2",
 73648          "licenses": [
 73649            {
 73650              "license": {
 73651                "name": "Chromium"
 73652              }
 73653            },
 73654            {
 73655              "license": {
 73656                "id": "MIT"
 73657              }
 73658            }
 73659          ],
 73660          "cpe": "cpe:2.3:a:libpsl5:libpsl5:0.21.0-1.2:*:*:*:*:*:*:*",
 73661          "purl": "pkg:deb/debian/libpsl5@0.21.0-1.2?arch=amd64\u0026upstream=libpsl\u0026distro=debian-11",
 73662          "swid": {
 73663            "attachment": {}
 73664          },
 73665          "pedigree": {},
 73666          "evidence": {},
 73667          "signature": {
 73668            "signature": {
 73669              "publicKey": {}
 73670            }
 73671          },
 73672          "modelCard": {
 73673            "modelParameters": {
 73674              "approach": {}
 73675            },
 73676            "quantitativeAnalysis": {
 73677              "graphics": {}
 73678            },
 73679            "considerations": {}
 73680          }
 73681        },
 73682        {
 73683          "type": "library",
 73684          "bom-ref": "pkg:deb/debian/libreadline8@8.1-1?arch=amd64\u0026upstream=readline\u0026distro=debian-11\u0026package-id=348793ec2b579ee6",
 73685          "supplier": {},
 73686          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 73687          "name": "libreadline8",
 73688          "version": "8.1-1",
 73689          "licenses": [
 73690            {
 73691              "license": {
 73692                "name": "GFDL"
 73693              }
 73694            },
 73695            {
 73696              "license": {
 73697                "id": "GPL-3.0-only"
 73698              }
 73699            }
 73700          ],
 73701          "cpe": "cpe:2.3:a:libreadline8:libreadline8:8.1-1:*:*:*:*:*:*:*",
 73702          "purl": "pkg:deb/debian/libreadline8@8.1-1?arch=amd64\u0026upstream=readline\u0026distro=debian-11",
 73703          "swid": {
 73704            "attachment": {}
 73705          },
 73706          "pedigree": {},
 73707          "evidence": {},
 73708          "signature": {
 73709            "signature": {
 73710              "publicKey": {}
 73711            }
 73712          },
 73713          "modelCard": {
 73714            "modelParameters": {
 73715              "approach": {}
 73716            },
 73717            "quantitativeAnalysis": {
 73718              "graphics": {}
 73719            },
 73720            "considerations": {}
 73721          }
 73722        },
 73723        {
 73724          "type": "library",
 73725          "bom-ref": "pkg:deb/debian/librtmp1@2.4+20151223.gitfa8646d.1-2+b2?arch=amd64\u0026upstream=rtmpdump%402.4+20151223.gitfa8646d.1-2\u0026distro=debian-11\u0026package-id=4f5f3212d3812c5d",
 73726          "supplier": {},
 73727          "publisher": "Debian Multimedia Maintainers \u003cdebian-multimedia@lists.debian.org\u003e",
 73728          "name": "librtmp1",
 73729          "version": "2.4+20151223.gitfa8646d.1-2+b2",
 73730          "licenses": [
 73731            {
 73732              "license": {
 73733                "id": "GPL-2.0-only"
 73734              }
 73735            },
 73736            {
 73737              "license": {
 73738                "id": "LGPL-2.1-only"
 73739              }
 73740            }
 73741          ],
 73742          "cpe": "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20151223.gitfa8646d.1-2\\+b2:*:*:*:*:*:*:*",
 73743          "purl": "pkg:deb/debian/librtmp1@2.4+20151223.gitfa8646d.1-2+b2?arch=amd64\u0026upstream=rtmpdump%402.4+20151223.gitfa8646d.1-2\u0026distro=debian-11",
 73744          "swid": {
 73745            "attachment": {}
 73746          },
 73747          "pedigree": {},
 73748          "evidence": {},
 73749          "signature": {
 73750            "signature": {
 73751              "publicKey": {}
 73752            }
 73753          },
 73754          "modelCard": {
 73755            "modelParameters": {
 73756              "approach": {}
 73757            },
 73758            "quantitativeAnalysis": {
 73759              "graphics": {}
 73760            },
 73761            "considerations": {}
 73762          }
 73763        },
 73764        {
 73765          "type": "library",
 73766          "bom-ref": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11\u0026package-id=77ea74a82c5fc951",
 73767          "supplier": {},
 73768          "publisher": "Debian Cyrus Team \u003cteam+cyrus@tracker.debian.org\u003e",
 73769          "name": "libsasl2-2",
 73770          "version": "2.1.27+dfsg-2.1+deb11u1",
 73771          "licenses": [
 73772            {
 73773              "license": {
 73774                "id": "BSD-4-Clause"
 73775              }
 73776            },
 73777            {
 73778              "license": {
 73779                "id": "GPL-3.0-only"
 73780              }
 73781            },
 73782            {
 73783              "license": {
 73784                "id": "GPL-3.0-or-later"
 73785              }
 73786            }
 73787          ],
 73788          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-2.1\\+deb11u1:*:*:*:*:*:*:*",
 73789          "purl": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11",
 73790          "swid": {
 73791            "attachment": {}
 73792          },
 73793          "pedigree": {},
 73794          "evidence": {},
 73795          "signature": {
 73796            "signature": {
 73797              "publicKey": {}
 73798            }
 73799          },
 73800          "modelCard": {
 73801            "modelParameters": {
 73802              "approach": {}
 73803            },
 73804            "quantitativeAnalysis": {
 73805              "graphics": {}
 73806            },
 73807            "considerations": {}
 73808          }
 73809        },
 73810        {
 73811          "type": "library",
 73812          "bom-ref": "pkg:deb/debian/libsasl2-modules-db@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11\u0026package-id=1e10a1d2edb3e77a",
 73813          "supplier": {},
 73814          "publisher": "Debian Cyrus Team \u003cteam+cyrus@tracker.debian.org\u003e",
 73815          "name": "libsasl2-modules-db",
 73816          "version": "2.1.27+dfsg-2.1+deb11u1",
 73817          "licenses": [
 73818            {
 73819              "license": {
 73820                "id": "BSD-4-Clause"
 73821              }
 73822            },
 73823            {
 73824              "license": {
 73825                "id": "GPL-3.0-only"
 73826              }
 73827            },
 73828            {
 73829              "license": {
 73830                "id": "GPL-3.0-or-later"
 73831              }
 73832            }
 73833          ],
 73834          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\+dfsg-2.1\\+deb11u1:*:*:*:*:*:*:*",
 73835          "purl": "pkg:deb/debian/libsasl2-modules-db@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11",
 73836          "swid": {
 73837            "attachment": {}
 73838          },
 73839          "pedigree": {},
 73840          "evidence": {},
 73841          "signature": {
 73842            "signature": {
 73843              "publicKey": {}
 73844            }
 73845          },
 73846          "modelCard": {
 73847            "modelParameters": {
 73848              "approach": {}
 73849            },
 73850            "quantitativeAnalysis": {
 73851              "graphics": {}
 73852            },
 73853            "considerations": {}
 73854          }
 73855        },
 73856        {
 73857          "type": "library",
 73858          "bom-ref": "pkg:deb/debian/libseccomp2@2.5.1-1+deb11u1?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-11\u0026package-id=bb0878d1437830b4",
 73859          "supplier": {},
 73860          "publisher": "Kees Cook \u003ckees@debian.org\u003e",
 73861          "name": "libseccomp2",
 73862          "version": "2.5.1-1+deb11u1",
 73863          "licenses": [
 73864            {
 73865              "license": {
 73866                "id": "LGPL-2.1-only"
 73867              }
 73868            }
 73869          ],
 73870          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.5.1-1\\+deb11u1:*:*:*:*:*:*:*",
 73871          "purl": "pkg:deb/debian/libseccomp2@2.5.1-1+deb11u1?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-11",
 73872          "swid": {
 73873            "attachment": {}
 73874          },
 73875          "pedigree": {},
 73876          "evidence": {},
 73877          "signature": {
 73878            "signature": {
 73879              "publicKey": {}
 73880            }
 73881          },
 73882          "modelCard": {
 73883            "modelParameters": {
 73884              "approach": {}
 73885            },
 73886            "quantitativeAnalysis": {
 73887              "graphics": {}
 73888            },
 73889            "considerations": {}
 73890          }
 73891        },
 73892        {
 73893          "type": "library",
 73894          "bom-ref": "pkg:deb/debian/libselinux1@3.1-3?arch=amd64\u0026upstream=libselinux\u0026distro=debian-11\u0026package-id=bb9d0a1adefb7931",
 73895          "supplier": {},
 73896          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 73897          "name": "libselinux1",
 73898          "version": "3.1-3",
 73899          "licenses": [
 73900            {
 73901              "license": {
 73902                "id": "GPL-2.0-only"
 73903              }
 73904            },
 73905            {
 73906              "license": {
 73907                "id": "LGPL-2.1-only"
 73908              }
 73909            }
 73910          ],
 73911          "cpe": "cpe:2.3:a:libselinux1:libselinux1:3.1-3:*:*:*:*:*:*:*",
 73912          "purl": "pkg:deb/debian/libselinux1@3.1-3?arch=amd64\u0026upstream=libselinux\u0026distro=debian-11",
 73913          "swid": {
 73914            "attachment": {}
 73915          },
 73916          "pedigree": {},
 73917          "evidence": {},
 73918          "signature": {
 73919            "signature": {
 73920              "publicKey": {}
 73921            }
 73922          },
 73923          "modelCard": {
 73924            "modelParameters": {
 73925              "approach": {}
 73926            },
 73927            "quantitativeAnalysis": {
 73928              "graphics": {}
 73929            },
 73930            "considerations": {}
 73931          }
 73932        },
 73933        {
 73934          "type": "library",
 73935          "bom-ref": "pkg:deb/debian/libsemanage-common@3.1-1?arch=all\u0026upstream=libsemanage\u0026distro=debian-11\u0026package-id=f41fe741bd23f493",
 73936          "supplier": {},
 73937          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 73938          "name": "libsemanage-common",
 73939          "version": "3.1-1",
 73940          "licenses": [
 73941            {
 73942              "license": {
 73943                "name": "GPL"
 73944              }
 73945            },
 73946            {
 73947              "license": {
 73948                "name": "LGPL"
 73949              }
 73950            }
 73951          ],
 73952          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:3.1-1:*:*:*:*:*:*:*",
 73953          "purl": "pkg:deb/debian/libsemanage-common@3.1-1?arch=all\u0026upstream=libsemanage\u0026distro=debian-11",
 73954          "swid": {
 73955            "attachment": {}
 73956          },
 73957          "pedigree": {},
 73958          "evidence": {},
 73959          "signature": {
 73960            "signature": {
 73961              "publicKey": {}
 73962            }
 73963          },
 73964          "modelCard": {
 73965            "modelParameters": {
 73966              "approach": {}
 73967            },
 73968            "quantitativeAnalysis": {
 73969              "graphics": {}
 73970            },
 73971            "considerations": {}
 73972          }
 73973        },
 73974        {
 73975          "type": "library",
 73976          "bom-ref": "pkg:deb/debian/libsemanage1@3.1-1+b2?arch=amd64\u0026upstream=libsemanage%403.1-1\u0026distro=debian-11\u0026package-id=fa4813c20a8027a6",
 73977          "supplier": {},
 73978          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 73979          "name": "libsemanage1",
 73980          "version": "3.1-1+b2",
 73981          "licenses": [
 73982            {
 73983              "license": {
 73984                "name": "GPL"
 73985              }
 73986            },
 73987            {
 73988              "license": {
 73989                "name": "LGPL"
 73990              }
 73991            }
 73992          ],
 73993          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:3.1-1\\+b2:*:*:*:*:*:*:*",
 73994          "purl": "pkg:deb/debian/libsemanage1@3.1-1+b2?arch=amd64\u0026upstream=libsemanage%403.1-1\u0026distro=debian-11",
 73995          "swid": {
 73996            "attachment": {}
 73997          },
 73998          "pedigree": {},
 73999          "evidence": {},
 74000          "signature": {
 74001            "signature": {
 74002              "publicKey": {}
 74003            }
 74004          },
 74005          "modelCard": {
 74006            "modelParameters": {
 74007              "approach": {}
 74008            },
 74009            "quantitativeAnalysis": {
 74010              "graphics": {}
 74011            },
 74012            "considerations": {}
 74013          }
 74014        },
 74015        {
 74016          "type": "library",
 74017          "bom-ref": "pkg:deb/debian/libsepol1@3.1-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-11\u0026package-id=cfa6f496d2fd049",
 74018          "supplier": {},
 74019          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
 74020          "name": "libsepol1",
 74021          "version": "3.1-1",
 74022          "licenses": [
 74023            {
 74024              "license": {
 74025                "name": "GPL"
 74026              }
 74027            },
 74028            {
 74029              "license": {
 74030                "name": "LGPL"
 74031              }
 74032            }
 74033          ],
 74034          "cpe": "cpe:2.3:a:libsepol1:libsepol1:3.1-1:*:*:*:*:*:*:*",
 74035          "purl": "pkg:deb/debian/libsepol1@3.1-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-11",
 74036          "swid": {
 74037            "attachment": {}
 74038          },
 74039          "pedigree": {},
 74040          "evidence": {},
 74041          "signature": {
 74042            "signature": {
 74043              "publicKey": {}
 74044            }
 74045          },
 74046          "modelCard": {
 74047            "modelParameters": {
 74048              "approach": {}
 74049            },
 74050            "quantitativeAnalysis": {
 74051              "graphics": {}
 74052            },
 74053            "considerations": {}
 74054          }
 74055        },
 74056        {
 74057          "type": "library",
 74058          "bom-ref": "pkg:deb/debian/libsmartcols1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=cf3b22adc552a311",
 74059          "supplier": {},
 74060          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 74061          "name": "libsmartcols1",
 74062          "version": "2.36.1-8+deb11u1",
 74063          "licenses": [
 74064            {
 74065              "license": {
 74066                "id": "BSD-2-Clause"
 74067              }
 74068            },
 74069            {
 74070              "license": {
 74071                "id": "BSD-3-Clause"
 74072              }
 74073            },
 74074            {
 74075              "license": {
 74076                "id": "BSD-4-Clause"
 74077              }
 74078            },
 74079            {
 74080              "license": {
 74081                "id": "GPL-2.0-only"
 74082              }
 74083            },
 74084            {
 74085              "license": {
 74086                "id": "GPL-2.0-or-later"
 74087              }
 74088            },
 74089            {
 74090              "license": {
 74091                "id": "GPL-3.0-only"
 74092              }
 74093            },
 74094            {
 74095              "license": {
 74096                "id": "GPL-3.0-or-later"
 74097              }
 74098            },
 74099            {
 74100              "license": {
 74101                "name": "LGPL"
 74102              }
 74103            },
 74104            {
 74105              "license": {
 74106                "id": "LGPL-2.0-only"
 74107              }
 74108            },
 74109            {
 74110              "license": {
 74111                "id": "LGPL-2.0-or-later"
 74112              }
 74113            },
 74114            {
 74115              "license": {
 74116                "id": "LGPL-2.1-only"
 74117              }
 74118            },
 74119            {
 74120              "license": {
 74121                "id": "LGPL-2.1-or-later"
 74122              }
 74123            },
 74124            {
 74125              "license": {
 74126                "id": "LGPL-3.0-only"
 74127              }
 74128            },
 74129            {
 74130              "license": {
 74131                "id": "LGPL-3.0-or-later"
 74132              }
 74133            },
 74134            {
 74135              "license": {
 74136                "id": "MIT"
 74137              }
 74138            },
 74139            {
 74140              "license": {
 74141                "name": "public-domain"
 74142              }
 74143            }
 74144          ],
 74145          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 74146          "purl": "pkg:deb/debian/libsmartcols1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
 74147          "swid": {
 74148            "attachment": {}
 74149          },
 74150          "pedigree": {},
 74151          "evidence": {},
 74152          "signature": {
 74153            "signature": {
 74154              "publicKey": {}
 74155            }
 74156          },
 74157          "modelCard": {
 74158            "modelParameters": {
 74159              "approach": {}
 74160            },
 74161            "quantitativeAnalysis": {
 74162              "graphics": {}
 74163            },
 74164            "considerations": {}
 74165          }
 74166        },
 74167        {
 74168          "type": "library",
 74169          "bom-ref": "pkg:deb/debian/libss2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=4ba13b2c11cb0876",
 74170          "supplier": {},
 74171          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 74172          "name": "libss2",
 74173          "version": "1.46.2-2",
 74174          "cpe": "cpe:2.3:a:libss2:libss2:1.46.2-2:*:*:*:*:*:*:*",
 74175          "purl": "pkg:deb/debian/libss2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
 74176          "swid": {
 74177            "attachment": {}
 74178          },
 74179          "pedigree": {},
 74180          "evidence": {},
 74181          "signature": {
 74182            "signature": {
 74183              "publicKey": {}
 74184            }
 74185          },
 74186          "modelCard": {
 74187            "modelParameters": {
 74188              "approach": {}
 74189            },
 74190            "quantitativeAnalysis": {
 74191              "graphics": {}
 74192            },
 74193            "considerations": {}
 74194          }
 74195        },
 74196        {
 74197          "type": "library",
 74198          "bom-ref": "pkg:deb/debian/libssh2-1@1.9.0-2?arch=amd64\u0026upstream=libssh2\u0026distro=debian-11\u0026package-id=7b11dbeecfce2854",
 74199          "supplier": {},
 74200          "publisher": "Nicolas Mora \u003cbabelouest@debian.org\u003e",
 74201          "name": "libssh2-1",
 74202          "version": "1.9.0-2",
 74203          "licenses": [
 74204            {
 74205              "license": {
 74206                "name": "BSD3"
 74207              }
 74208            }
 74209          ],
 74210          "cpe": "cpe:2.3:a:libssh2-1:libssh2-1:1.9.0-2:*:*:*:*:*:*:*",
 74211          "purl": "pkg:deb/debian/libssh2-1@1.9.0-2?arch=amd64\u0026upstream=libssh2\u0026distro=debian-11",
 74212          "swid": {
 74213            "attachment": {}
 74214          },
 74215          "pedigree": {},
 74216          "evidence": {},
 74217          "signature": {
 74218            "signature": {
 74219              "publicKey": {}
 74220            }
 74221          },
 74222          "modelCard": {
 74223            "modelParameters": {
 74224              "approach": {}
 74225            },
 74226            "quantitativeAnalysis": {
 74227              "graphics": {}
 74228            },
 74229            "considerations": {}
 74230          }
 74231        },
 74232        {
 74233          "type": "library",
 74234          "bom-ref": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u4?arch=amd64\u0026upstream=openssl\u0026distro=debian-11\u0026package-id=63a11d0164944054",
 74235          "supplier": {},
 74236          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
 74237          "name": "libssl1.1",
 74238          "version": "1.1.1n-0+deb11u4",
 74239          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1n-0\\+deb11u4:*:*:*:*:*:*:*",
 74240          "purl": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u4?arch=amd64\u0026upstream=openssl\u0026distro=debian-11",
 74241          "swid": {
 74242            "attachment": {}
 74243          },
 74244          "pedigree": {},
 74245          "evidence": {},
 74246          "signature": {
 74247            "signature": {
 74248              "publicKey": {}
 74249            }
 74250          },
 74251          "modelCard": {
 74252            "modelParameters": {
 74253              "approach": {}
 74254            },
 74255            "quantitativeAnalysis": {
 74256              "graphics": {}
 74257            },
 74258            "considerations": {}
 74259          }
 74260        },
 74261        {
 74262          "type": "library",
 74263          "bom-ref": "pkg:deb/debian/libstdc++6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=748369630632944",
 74264          "supplier": {},
 74265          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
 74266          "name": "libstdc++6",
 74267          "version": "10.2.1-6",
 74268          "licenses": [
 74269            {
 74270              "license": {
 74271                "name": "Artistic"
 74272              }
 74273            },
 74274            {
 74275              "license": {
 74276                "id": "GFDL-1.2-only"
 74277              }
 74278            },
 74279            {
 74280              "license": {
 74281                "name": "GPL"
 74282              }
 74283            },
 74284            {
 74285              "license": {
 74286                "id": "GPL-2.0-only"
 74287              }
 74288            },
 74289            {
 74290              "license": {
 74291                "id": "GPL-3.0-only"
 74292              }
 74293            },
 74294            {
 74295              "license": {
 74296                "name": "LGPL"
 74297              }
 74298            }
 74299          ],
 74300          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.2.1-6:*:*:*:*:*:*:*",
 74301          "purl": "pkg:deb/debian/libstdc++6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
 74302          "swid": {
 74303            "attachment": {}
 74304          },
 74305          "pedigree": {},
 74306          "evidence": {},
 74307          "signature": {
 74308            "signature": {
 74309              "publicKey": {}
 74310            }
 74311          },
 74312          "modelCard": {
 74313            "modelParameters": {
 74314              "approach": {}
 74315            },
 74316            "quantitativeAnalysis": {
 74317              "graphics": {}
 74318            },
 74319            "considerations": {}
 74320          }
 74321        },
 74322        {
 74323          "type": "library",
 74324          "bom-ref": "pkg:deb/debian/libsystemd0@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11\u0026package-id=4c258dc3b086d634",
 74325          "supplier": {},
 74326          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 74327          "name": "libsystemd0",
 74328          "version": "247.3-7+deb11u1",
 74329          "licenses": [
 74330            {
 74331              "license": {
 74332                "id": "CC0-1.0"
 74333              }
 74334            },
 74335            {
 74336              "license": {
 74337                "name": "Expat"
 74338              }
 74339            },
 74340            {
 74341              "license": {
 74342                "id": "GPL-2.0-only"
 74343              }
 74344            },
 74345            {
 74346              "license": {
 74347                "id": "GPL-2.0-or-later"
 74348              }
 74349            },
 74350            {
 74351              "license": {
 74352                "id": "LGPL-2.1-only"
 74353              }
 74354            },
 74355            {
 74356              "license": {
 74357                "id": "LGPL-2.1-or-later"
 74358              }
 74359            },
 74360            {
 74361              "license": {
 74362                "name": "public-domain"
 74363              }
 74364            }
 74365          ],
 74366          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:247.3-7\\+deb11u1:*:*:*:*:*:*:*",
 74367          "purl": "pkg:deb/debian/libsystemd0@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11",
 74368          "swid": {
 74369            "attachment": {}
 74370          },
 74371          "pedigree": {},
 74372          "evidence": {},
 74373          "signature": {
 74374            "signature": {
 74375              "publicKey": {}
 74376            }
 74377          },
 74378          "modelCard": {
 74379            "modelParameters": {
 74380              "approach": {}
 74381            },
 74382            "quantitativeAnalysis": {
 74383              "graphics": {}
 74384            },
 74385            "considerations": {}
 74386          }
 74387        },
 74388        {
 74389          "type": "library",
 74390          "bom-ref": "pkg:deb/debian/libtasn1-6@4.16.0-2+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=74865cf2744adb90",
 74391          "supplier": {},
 74392          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
 74393          "name": "libtasn1-6",
 74394          "version": "4.16.0-2+deb11u1",
 74395          "licenses": [
 74396            {
 74397              "license": {
 74398                "id": "GFDL-1.3-only"
 74399              }
 74400            },
 74401            {
 74402              "license": {
 74403                "id": "GPL-3.0-only"
 74404              }
 74405            },
 74406            {
 74407              "license": {
 74408                "name": "LGPL"
 74409              }
 74410            },
 74411            {
 74412              "license": {
 74413                "id": "LGPL-2.1-only"
 74414              }
 74415            }
 74416          ],
 74417          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2\\+deb11u1:*:*:*:*:*:*:*",
 74418          "purl": "pkg:deb/debian/libtasn1-6@4.16.0-2+deb11u1?arch=amd64\u0026distro=debian-11",
 74419          "swid": {
 74420            "attachment": {}
 74421          },
 74422          "pedigree": {},
 74423          "evidence": {},
 74424          "signature": {
 74425            "signature": {
 74426              "publicKey": {}
 74427            }
 74428          },
 74429          "modelCard": {
 74430            "modelParameters": {
 74431              "approach": {}
 74432            },
 74433            "quantitativeAnalysis": {
 74434              "graphics": {}
 74435            },
 74436            "considerations": {}
 74437          }
 74438        },
 74439        {
 74440          "type": "library",
 74441          "bom-ref": "pkg:deb/debian/libtiff5@4.2.0-1+deb11u4?arch=amd64\u0026upstream=tiff\u0026distro=debian-11\u0026package-id=c261f1af2b842cce",
 74442          "supplier": {},
 74443          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
 74444          "name": "libtiff5",
 74445          "version": "4.2.0-1+deb11u4",
 74446          "licenses": [
 74447            {
 74448              "license": {
 74449                "name": "Hylafax"
 74450              }
 74451            }
 74452          ],
 74453          "cpe": "cpe:2.3:a:libtiff5:libtiff5:4.2.0-1\\+deb11u4:*:*:*:*:*:*:*",
 74454          "purl": "pkg:deb/debian/libtiff5@4.2.0-1+deb11u4?arch=amd64\u0026upstream=tiff\u0026distro=debian-11",
 74455          "swid": {
 74456            "attachment": {}
 74457          },
 74458          "pedigree": {},
 74459          "evidence": {},
 74460          "signature": {
 74461            "signature": {
 74462              "publicKey": {}
 74463            }
 74464          },
 74465          "modelCard": {
 74466            "modelParameters": {
 74467              "approach": {}
 74468            },
 74469            "quantitativeAnalysis": {
 74470              "graphics": {}
 74471            },
 74472            "considerations": {}
 74473          }
 74474        },
 74475        {
 74476          "type": "library",
 74477          "bom-ref": "pkg:deb/debian/libtinfo6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=9e96601b60336037",
 74478          "supplier": {},
 74479          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 74480          "name": "libtinfo6",
 74481          "version": "6.2+20201114-2",
 74482          "licenses": [
 74483            {
 74484              "license": {
 74485                "id": "BSD-3-Clause"
 74486              }
 74487            },
 74488            {
 74489              "license": {
 74490                "name": "MIT/X11"
 74491              }
 74492            },
 74493            {
 74494              "license": {
 74495                "id": "X11"
 74496              }
 74497            }
 74498          ],
 74499          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.2\\+20201114-2:*:*:*:*:*:*:*",
 74500          "purl": "pkg:deb/debian/libtinfo6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11",
 74501          "swid": {
 74502            "attachment": {}
 74503          },
 74504          "pedigree": {},
 74505          "evidence": {},
 74506          "signature": {
 74507            "signature": {
 74508              "publicKey": {}
 74509            }
 74510          },
 74511          "modelCard": {
 74512            "modelParameters": {
 74513              "approach": {}
 74514            },
 74515            "quantitativeAnalysis": {
 74516              "graphics": {}
 74517            },
 74518            "considerations": {}
 74519          }
 74520        },
 74521        {
 74522          "type": "library",
 74523          "bom-ref": "pkg:deb/debian/libtirpc-common@1.3.1-1+deb11u1?arch=all\u0026upstream=libtirpc\u0026distro=debian-11\u0026package-id=3623a1ef0b5b63b9",
 74524          "supplier": {},
 74525          "publisher": "Josue Ortega \u003cjosue@debian.org\u003e",
 74526          "name": "libtirpc-common",
 74527          "version": "1.3.1-1+deb11u1",
 74528          "licenses": [
 74529            {
 74530              "license": {
 74531                "id": "BSD-3-Clause"
 74532              }
 74533            },
 74534            {
 74535              "license": {
 74536                "id": "GPL-2.0-only"
 74537              }
 74538            },
 74539            {
 74540              "license": {
 74541                "id": "LGPL-2.1-only"
 74542              }
 74543            }
 74544          ],
 74545          "cpe": "cpe:2.3:a:libtirpc-common:libtirpc-common:1.3.1-1\\+deb11u1:*:*:*:*:*:*:*",
 74546          "purl": "pkg:deb/debian/libtirpc-common@1.3.1-1+deb11u1?arch=all\u0026upstream=libtirpc\u0026distro=debian-11",
 74547          "swid": {
 74548            "attachment": {}
 74549          },
 74550          "pedigree": {},
 74551          "evidence": {},
 74552          "signature": {
 74553            "signature": {
 74554              "publicKey": {}
 74555            }
 74556          },
 74557          "modelCard": {
 74558            "modelParameters": {
 74559              "approach": {}
 74560            },
 74561            "quantitativeAnalysis": {
 74562              "graphics": {}
 74563            },
 74564            "considerations": {}
 74565          }
 74566        },
 74567        {
 74568          "type": "library",
 74569          "bom-ref": "pkg:deb/debian/libtirpc3@1.3.1-1+deb11u1?arch=amd64\u0026upstream=libtirpc\u0026distro=debian-11\u0026package-id=c7b97f0b9d21e851",
 74570          "supplier": {},
 74571          "publisher": "Josue Ortega \u003cjosue@debian.org\u003e",
 74572          "name": "libtirpc3",
 74573          "version": "1.3.1-1+deb11u1",
 74574          "licenses": [
 74575            {
 74576              "license": {
 74577                "id": "BSD-3-Clause"
 74578              }
 74579            },
 74580            {
 74581              "license": {
 74582                "id": "GPL-2.0-only"
 74583              }
 74584            },
 74585            {
 74586              "license": {
 74587                "id": "LGPL-2.1-only"
 74588              }
 74589            }
 74590          ],
 74591          "cpe": "cpe:2.3:a:libtirpc3:libtirpc3:1.3.1-1\\+deb11u1:*:*:*:*:*:*:*",
 74592          "purl": "pkg:deb/debian/libtirpc3@1.3.1-1+deb11u1?arch=amd64\u0026upstream=libtirpc\u0026distro=debian-11",
 74593          "swid": {
 74594            "attachment": {}
 74595          },
 74596          "pedigree": {},
 74597          "evidence": {},
 74598          "signature": {
 74599            "signature": {
 74600              "publicKey": {}
 74601            }
 74602          },
 74603          "modelCard": {
 74604            "modelParameters": {
 74605              "approach": {}
 74606            },
 74607            "quantitativeAnalysis": {
 74608              "graphics": {}
 74609            },
 74610            "considerations": {}
 74611          }
 74612        },
 74613        {
 74614          "type": "library",
 74615          "bom-ref": "pkg:deb/debian/libudev1@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11\u0026package-id=79c718cff72e218e",
 74616          "supplier": {},
 74617          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
 74618          "name": "libudev1",
 74619          "version": "247.3-7+deb11u1",
 74620          "licenses": [
 74621            {
 74622              "license": {
 74623                "id": "CC0-1.0"
 74624              }
 74625            },
 74626            {
 74627              "license": {
 74628                "name": "Expat"
 74629              }
 74630            },
 74631            {
 74632              "license": {
 74633                "id": "GPL-2.0-only"
 74634              }
 74635            },
 74636            {
 74637              "license": {
 74638                "id": "GPL-2.0-or-later"
 74639              }
 74640            },
 74641            {
 74642              "license": {
 74643                "id": "LGPL-2.1-only"
 74644              }
 74645            },
 74646            {
 74647              "license": {
 74648                "id": "LGPL-2.1-or-later"
 74649              }
 74650            },
 74651            {
 74652              "license": {
 74653                "name": "public-domain"
 74654              }
 74655            }
 74656          ],
 74657          "cpe": "cpe:2.3:a:libudev1:libudev1:247.3-7\\+deb11u1:*:*:*:*:*:*:*",
 74658          "purl": "pkg:deb/debian/libudev1@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11",
 74659          "swid": {
 74660            "attachment": {}
 74661          },
 74662          "pedigree": {},
 74663          "evidence": {},
 74664          "signature": {
 74665            "signature": {
 74666              "publicKey": {}
 74667            }
 74668          },
 74669          "modelCard": {
 74670            "modelParameters": {
 74671              "approach": {}
 74672            },
 74673            "quantitativeAnalysis": {
 74674              "graphics": {}
 74675            },
 74676            "considerations": {}
 74677          }
 74678        },
 74679        {
 74680          "type": "library",
 74681          "bom-ref": "pkg:deb/debian/libunistring2@0.9.10-4?arch=amd64\u0026upstream=libunistring\u0026distro=debian-11\u0026package-id=dc7fcfc9dde2b703",
 74682          "supplier": {},
 74683          "publisher": "Jörg Frings-Fürst \u003cdebian@jff.email\u003e",
 74684          "name": "libunistring2",
 74685          "version": "0.9.10-4",
 74686          "licenses": [
 74687            {
 74688              "license": {
 74689                "name": "FreeSoftware"
 74690              }
 74691            },
 74692            {
 74693              "license": {
 74694                "id": "GFDL-1.2-only"
 74695              }
 74696            },
 74697            {
 74698              "license": {
 74699                "name": "GFDL-1.2+"
 74700              }
 74701            },
 74702            {
 74703              "license": {
 74704                "id": "GPL-2.0-only"
 74705              }
 74706            },
 74707            {
 74708              "license": {
 74709                "id": "GPL-2.0-or-later"
 74710              }
 74711            },
 74712            {
 74713              "license": {
 74714                "id": "GPL-3.0-only"
 74715              }
 74716            },
 74717            {
 74718              "license": {
 74719                "id": "GPL-3.0-or-later"
 74720              }
 74721            },
 74722            {
 74723              "license": {
 74724                "id": "LGPL-3.0-only"
 74725              }
 74726            },
 74727            {
 74728              "license": {
 74729                "id": "LGPL-3.0-or-later"
 74730              }
 74731            },
 74732            {
 74733              "license": {
 74734                "id": "MIT"
 74735              }
 74736            }
 74737          ],
 74738          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-4:*:*:*:*:*:*:*",
 74739          "purl": "pkg:deb/debian/libunistring2@0.9.10-4?arch=amd64\u0026upstream=libunistring\u0026distro=debian-11",
 74740          "swid": {
 74741            "attachment": {}
 74742          },
 74743          "pedigree": {},
 74744          "evidence": {},
 74745          "signature": {
 74746            "signature": {
 74747              "publicKey": {}
 74748            }
 74749          },
 74750          "modelCard": {
 74751            "modelParameters": {
 74752              "approach": {}
 74753            },
 74754            "quantitativeAnalysis": {
 74755              "graphics": {}
 74756            },
 74757            "considerations": {}
 74758          }
 74759        },
 74760        {
 74761          "type": "library",
 74762          "bom-ref": "pkg:deb/debian/libuuid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=e87310d3e1426d6c",
 74763          "supplier": {},
 74764          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 74765          "name": "libuuid1",
 74766          "version": "2.36.1-8+deb11u1",
 74767          "licenses": [
 74768            {
 74769              "license": {
 74770                "id": "BSD-2-Clause"
 74771              }
 74772            },
 74773            {
 74774              "license": {
 74775                "id": "BSD-3-Clause"
 74776              }
 74777            },
 74778            {
 74779              "license": {
 74780                "id": "BSD-4-Clause"
 74781              }
 74782            },
 74783            {
 74784              "license": {
 74785                "id": "GPL-2.0-only"
 74786              }
 74787            },
 74788            {
 74789              "license": {
 74790                "id": "GPL-2.0-or-later"
 74791              }
 74792            },
 74793            {
 74794              "license": {
 74795                "id": "GPL-3.0-only"
 74796              }
 74797            },
 74798            {
 74799              "license": {
 74800                "id": "GPL-3.0-or-later"
 74801              }
 74802            },
 74803            {
 74804              "license": {
 74805                "name": "LGPL"
 74806              }
 74807            },
 74808            {
 74809              "license": {
 74810                "id": "LGPL-2.0-only"
 74811              }
 74812            },
 74813            {
 74814              "license": {
 74815                "id": "LGPL-2.0-or-later"
 74816              }
 74817            },
 74818            {
 74819              "license": {
 74820                "id": "LGPL-2.1-only"
 74821              }
 74822            },
 74823            {
 74824              "license": {
 74825                "id": "LGPL-2.1-or-later"
 74826              }
 74827            },
 74828            {
 74829              "license": {
 74830                "id": "LGPL-3.0-only"
 74831              }
 74832            },
 74833            {
 74834              "license": {
 74835                "id": "LGPL-3.0-or-later"
 74836              }
 74837            },
 74838            {
 74839              "license": {
 74840                "id": "MIT"
 74841              }
 74842            },
 74843            {
 74844              "license": {
 74845                "name": "public-domain"
 74846              }
 74847            }
 74848          ],
 74849          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 74850          "purl": "pkg:deb/debian/libuuid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
 74851          "swid": {
 74852            "attachment": {}
 74853          },
 74854          "pedigree": {},
 74855          "evidence": {},
 74856          "signature": {
 74857            "signature": {
 74858              "publicKey": {}
 74859            }
 74860          },
 74861          "modelCard": {
 74862            "modelParameters": {
 74863              "approach": {}
 74864            },
 74865            "quantitativeAnalysis": {
 74866              "graphics": {}
 74867            },
 74868            "considerations": {}
 74869          }
 74870        },
 74871        {
 74872          "type": "library",
 74873          "bom-ref": "pkg:deb/debian/libwebp6@0.6.1-2.1?arch=amd64\u0026upstream=libwebp\u0026distro=debian-11\u0026package-id=88ca886298d7e0b",
 74874          "supplier": {},
 74875          "publisher": "Jeff Breidenbach \u003cjab@debian.org\u003e",
 74876          "name": "libwebp6",
 74877          "version": "0.6.1-2.1",
 74878          "licenses": [
 74879            {
 74880              "license": {
 74881                "id": "Apache-2.0"
 74882              }
 74883            }
 74884          ],
 74885          "cpe": "cpe:2.3:a:libwebp6:libwebp6:0.6.1-2.1:*:*:*:*:*:*:*",
 74886          "purl": "pkg:deb/debian/libwebp6@0.6.1-2.1?arch=amd64\u0026upstream=libwebp\u0026distro=debian-11",
 74887          "swid": {
 74888            "attachment": {}
 74889          },
 74890          "pedigree": {},
 74891          "evidence": {},
 74892          "signature": {
 74893            "signature": {
 74894              "publicKey": {}
 74895            }
 74896          },
 74897          "modelCard": {
 74898            "modelParameters": {
 74899              "approach": {}
 74900            },
 74901            "quantitativeAnalysis": {
 74902              "graphics": {}
 74903            },
 74904            "considerations": {}
 74905          }
 74906        },
 74907        {
 74908          "type": "library",
 74909          "bom-ref": "pkg:deb/debian/libx11-6@2:1.7.2-1?arch=amd64\u0026upstream=libx11\u0026distro=debian-11\u0026package-id=ce4e2010925a4939",
 74910          "supplier": {},
 74911          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
 74912          "name": "libx11-6",
 74913          "version": "2:1.7.2-1",
 74914          "cpe": "cpe:2.3:a:libx11-6:libx11-6:2\\:1.7.2-1:*:*:*:*:*:*:*",
 74915          "purl": "pkg:deb/debian/libx11-6@2:1.7.2-1?arch=amd64\u0026upstream=libx11\u0026distro=debian-11",
 74916          "swid": {
 74917            "attachment": {}
 74918          },
 74919          "pedigree": {},
 74920          "evidence": {},
 74921          "signature": {
 74922            "signature": {
 74923              "publicKey": {}
 74924            }
 74925          },
 74926          "modelCard": {
 74927            "modelParameters": {
 74928              "approach": {}
 74929            },
 74930            "quantitativeAnalysis": {
 74931              "graphics": {}
 74932            },
 74933            "considerations": {}
 74934          }
 74935        },
 74936        {
 74937          "type": "library",
 74938          "bom-ref": "pkg:deb/debian/libx11-data@2:1.7.2-1?arch=all\u0026upstream=libx11\u0026distro=debian-11\u0026package-id=8defa9b2d11078dc",
 74939          "supplier": {},
 74940          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
 74941          "name": "libx11-data",
 74942          "version": "2:1.7.2-1",
 74943          "cpe": "cpe:2.3:a:libx11-data:libx11-data:2\\:1.7.2-1:*:*:*:*:*:*:*",
 74944          "purl": "pkg:deb/debian/libx11-data@2:1.7.2-1?arch=all\u0026upstream=libx11\u0026distro=debian-11",
 74945          "swid": {
 74946            "attachment": {}
 74947          },
 74948          "pedigree": {},
 74949          "evidence": {},
 74950          "signature": {
 74951            "signature": {
 74952              "publicKey": {}
 74953            }
 74954          },
 74955          "modelCard": {
 74956            "modelParameters": {
 74957              "approach": {}
 74958            },
 74959            "quantitativeAnalysis": {
 74960              "graphics": {}
 74961            },
 74962            "considerations": {}
 74963          }
 74964        },
 74965        {
 74966          "type": "library",
 74967          "bom-ref": "pkg:deb/debian/libxau6@1:1.0.9-1?arch=amd64\u0026upstream=libxau\u0026distro=debian-11\u0026package-id=e6c254c1e56081d8",
 74968          "supplier": {},
 74969          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
 74970          "name": "libxau6",
 74971          "version": "1:1.0.9-1",
 74972          "cpe": "cpe:2.3:a:libxau6:libxau6:1\\:1.0.9-1:*:*:*:*:*:*:*",
 74973          "purl": "pkg:deb/debian/libxau6@1:1.0.9-1?arch=amd64\u0026upstream=libxau\u0026distro=debian-11",
 74974          "swid": {
 74975            "attachment": {}
 74976          },
 74977          "pedigree": {},
 74978          "evidence": {},
 74979          "signature": {
 74980            "signature": {
 74981              "publicKey": {}
 74982            }
 74983          },
 74984          "modelCard": {
 74985            "modelParameters": {
 74986              "approach": {}
 74987            },
 74988            "quantitativeAnalysis": {
 74989              "graphics": {}
 74990            },
 74991            "considerations": {}
 74992          }
 74993        },
 74994        {
 74995          "type": "library",
 74996          "bom-ref": "pkg:deb/debian/libxcb1@1.14-3?arch=amd64\u0026upstream=libxcb\u0026distro=debian-11\u0026package-id=9281d5ec3fb0ebd8",
 74997          "supplier": {},
 74998          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
 74999          "name": "libxcb1",
 75000          "version": "1.14-3",
 75001          "cpe": "cpe:2.3:a:libxcb1:libxcb1:1.14-3:*:*:*:*:*:*:*",
 75002          "purl": "pkg:deb/debian/libxcb1@1.14-3?arch=amd64\u0026upstream=libxcb\u0026distro=debian-11",
 75003          "swid": {
 75004            "attachment": {}
 75005          },
 75006          "pedigree": {},
 75007          "evidence": {},
 75008          "signature": {
 75009            "signature": {
 75010              "publicKey": {}
 75011            }
 75012          },
 75013          "modelCard": {
 75014            "modelParameters": {
 75015              "approach": {}
 75016            },
 75017            "quantitativeAnalysis": {
 75018              "graphics": {}
 75019            },
 75020            "considerations": {}
 75021          }
 75022        },
 75023        {
 75024          "type": "library",
 75025          "bom-ref": "pkg:deb/debian/libxdmcp6@1:1.1.2-3?arch=amd64\u0026upstream=libxdmcp\u0026distro=debian-11\u0026package-id=4005b45e460ecaca",
 75026          "supplier": {},
 75027          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
 75028          "name": "libxdmcp6",
 75029          "version": "1:1.1.2-3",
 75030          "cpe": "cpe:2.3:a:libxdmcp6:libxdmcp6:1\\:1.1.2-3:*:*:*:*:*:*:*",
 75031          "purl": "pkg:deb/debian/libxdmcp6@1:1.1.2-3?arch=amd64\u0026upstream=libxdmcp\u0026distro=debian-11",
 75032          "swid": {
 75033            "attachment": {}
 75034          },
 75035          "pedigree": {},
 75036          "evidence": {},
 75037          "signature": {
 75038            "signature": {
 75039              "publicKey": {}
 75040            }
 75041          },
 75042          "modelCard": {
 75043            "modelParameters": {
 75044              "approach": {}
 75045            },
 75046            "quantitativeAnalysis": {
 75047              "graphics": {}
 75048            },
 75049            "considerations": {}
 75050          }
 75051        },
 75052        {
 75053          "type": "library",
 75054          "bom-ref": "pkg:deb/debian/libxml2@2.9.10+dfsg-6.7+deb11u3?arch=amd64\u0026distro=debian-11\u0026package-id=17dda21225ad6175",
 75055          "supplier": {},
 75056          "publisher": "Debian XML/SGML Group \u003cdebian-xml-sgml-pkgs@lists.alioth.debian.org\u003e",
 75057          "name": "libxml2",
 75058          "version": "2.9.10+dfsg-6.7+deb11u3",
 75059          "licenses": [
 75060            {
 75061              "license": {
 75062                "id": "ISC"
 75063              }
 75064            },
 75065            {
 75066              "license": {
 75067                "name": "MIT-1"
 75068              }
 75069            }
 75070          ],
 75071          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.10\\+dfsg-6.7\\+deb11u3:*:*:*:*:*:*:*",
 75072          "purl": "pkg:deb/debian/libxml2@2.9.10+dfsg-6.7+deb11u3?arch=amd64\u0026distro=debian-11",
 75073          "swid": {
 75074            "attachment": {}
 75075          },
 75076          "pedigree": {},
 75077          "evidence": {},
 75078          "signature": {
 75079            "signature": {
 75080              "publicKey": {}
 75081            }
 75082          },
 75083          "modelCard": {
 75084            "modelParameters": {
 75085              "approach": {}
 75086            },
 75087            "quantitativeAnalysis": {
 75088              "graphics": {}
 75089            },
 75090            "considerations": {}
 75091          }
 75092        },
 75093        {
 75094          "type": "library",
 75095          "bom-ref": "pkg:deb/debian/libxpm4@1:3.5.12-1?arch=amd64\u0026upstream=libxpm\u0026distro=debian-11\u0026package-id=a013468ed5f68ed3",
 75096          "supplier": {},
 75097          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
 75098          "name": "libxpm4",
 75099          "version": "1:3.5.12-1",
 75100          "cpe": "cpe:2.3:a:libxpm4:libxpm4:1\\:3.5.12-1:*:*:*:*:*:*:*",
 75101          "purl": "pkg:deb/debian/libxpm4@1:3.5.12-1?arch=amd64\u0026upstream=libxpm\u0026distro=debian-11",
 75102          "swid": {
 75103            "attachment": {}
 75104          },
 75105          "pedigree": {},
 75106          "evidence": {},
 75107          "signature": {
 75108            "signature": {
 75109              "publicKey": {}
 75110            }
 75111          },
 75112          "modelCard": {
 75113            "modelParameters": {
 75114              "approach": {}
 75115            },
 75116            "quantitativeAnalysis": {
 75117              "graphics": {}
 75118            },
 75119            "considerations": {}
 75120          }
 75121        },
 75122        {
 75123          "type": "library",
 75124          "bom-ref": "pkg:deb/debian/libxslt1.1@1.1.34-4+deb11u1?arch=amd64\u0026upstream=libxslt\u0026distro=debian-11\u0026package-id=ee58630377288c70",
 75125          "supplier": {},
 75126          "publisher": "Debian XML/SGML Group \u003cdebian-xml-sgml-pkgs@lists.alioth.debian.org\u003e",
 75127          "name": "libxslt1.1",
 75128          "version": "1.1.34-4+deb11u1",
 75129          "cpe": "cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.34-4\\+deb11u1:*:*:*:*:*:*:*",
 75130          "purl": "pkg:deb/debian/libxslt1.1@1.1.34-4+deb11u1?arch=amd64\u0026upstream=libxslt\u0026distro=debian-11",
 75131          "swid": {
 75132            "attachment": {}
 75133          },
 75134          "pedigree": {},
 75135          "evidence": {},
 75136          "signature": {
 75137            "signature": {
 75138              "publicKey": {}
 75139            }
 75140          },
 75141          "modelCard": {
 75142            "modelParameters": {
 75143              "approach": {}
 75144            },
 75145            "quantitativeAnalysis": {
 75146              "graphics": {}
 75147            },
 75148            "considerations": {}
 75149          }
 75150        },
 75151        {
 75152          "type": "library",
 75153          "bom-ref": "pkg:deb/debian/libxxhash0@0.8.0-2?arch=amd64\u0026upstream=xxhash\u0026distro=debian-11\u0026package-id=edc71d7591d40133",
 75154          "supplier": {},
 75155          "publisher": "Norbert Preining \u003cnorbert@preining.info\u003e",
 75156          "name": "libxxhash0",
 75157          "version": "0.8.0-2",
 75158          "licenses": [
 75159            {
 75160              "license": {
 75161                "id": "BSD-2-Clause"
 75162              }
 75163            },
 75164            {
 75165              "license": {
 75166                "id": "GPL-2.0-only"
 75167              }
 75168            }
 75169          ],
 75170          "cpe": "cpe:2.3:a:libxxhash0:libxxhash0:0.8.0-2:*:*:*:*:*:*:*",
 75171          "purl": "pkg:deb/debian/libxxhash0@0.8.0-2?arch=amd64\u0026upstream=xxhash\u0026distro=debian-11",
 75172          "swid": {
 75173            "attachment": {}
 75174          },
 75175          "pedigree": {},
 75176          "evidence": {},
 75177          "signature": {
 75178            "signature": {
 75179              "publicKey": {}
 75180            }
 75181          },
 75182          "modelCard": {
 75183            "modelParameters": {
 75184              "approach": {}
 75185            },
 75186            "quantitativeAnalysis": {
 75187              "graphics": {}
 75188            },
 75189            "considerations": {}
 75190          }
 75191        },
 75192        {
 75193          "type": "library",
 75194          "bom-ref": "pkg:deb/debian/libzstd1@1.4.8+dfsg-2.1?arch=amd64\u0026upstream=libzstd\u0026distro=debian-11\u0026package-id=90e1680def07a674",
 75195          "supplier": {},
 75196          "publisher": "Debian Med Packaging Team \u003cdebian-med-packaging@lists.alioth.debian.org\u003e",
 75197          "name": "libzstd1",
 75198          "version": "1.4.8+dfsg-2.1",
 75199          "licenses": [
 75200            {
 75201              "license": {
 75202                "id": "BSD-3-Clause"
 75203              }
 75204            },
 75205            {
 75206              "license": {
 75207                "name": "Expat"
 75208              }
 75209            },
 75210            {
 75211              "license": {
 75212                "id": "GPL-2.0-only"
 75213              }
 75214            },
 75215            {
 75216              "license": {
 75217                "id": "Zlib"
 75218              }
 75219            }
 75220          ],
 75221          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.8\\+dfsg-2.1:*:*:*:*:*:*:*",
 75222          "purl": "pkg:deb/debian/libzstd1@1.4.8+dfsg-2.1?arch=amd64\u0026upstream=libzstd\u0026distro=debian-11",
 75223          "swid": {
 75224            "attachment": {}
 75225          },
 75226          "pedigree": {},
 75227          "evidence": {},
 75228          "signature": {
 75229            "signature": {
 75230              "publicKey": {}
 75231            }
 75232          },
 75233          "modelCard": {
 75234            "modelParameters": {
 75235              "approach": {}
 75236            },
 75237            "quantitativeAnalysis": {
 75238              "graphics": {}
 75239            },
 75240            "considerations": {}
 75241          }
 75242        },
 75243        {
 75244          "type": "library",
 75245          "bom-ref": "pkg:deb/debian/login@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11\u0026package-id=9cdbb92ea69c08a1",
 75246          "supplier": {},
 75247          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
 75248          "name": "login",
 75249          "version": "1:4.8.1-1",
 75250          "licenses": [
 75251            {
 75252              "license": {
 75253                "id": "GPL-2.0-only"
 75254              }
 75255            }
 75256          ],
 75257          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1:*:*:*:*:*:*:*",
 75258          "purl": "pkg:deb/debian/login@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11",
 75259          "swid": {
 75260            "attachment": {}
 75261          },
 75262          "pedigree": {},
 75263          "evidence": {},
 75264          "signature": {
 75265            "signature": {
 75266              "publicKey": {}
 75267            }
 75268          },
 75269          "modelCard": {
 75270            "modelParameters": {
 75271              "approach": {}
 75272            },
 75273            "quantitativeAnalysis": {
 75274              "graphics": {}
 75275            },
 75276            "considerations": {}
 75277          }
 75278        },
 75279        {
 75280          "type": "library",
 75281          "bom-ref": "pkg:deb/debian/logsave@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=77e8cce6db62952b",
 75282          "supplier": {},
 75283          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
 75284          "name": "logsave",
 75285          "version": "1.46.2-2",
 75286          "licenses": [
 75287            {
 75288              "license": {
 75289                "id": "GPL-2.0-only"
 75290              }
 75291            },
 75292            {
 75293              "license": {
 75294                "id": "LGPL-2.0-only"
 75295              }
 75296            }
 75297          ],
 75298          "cpe": "cpe:2.3:a:logsave:logsave:1.46.2-2:*:*:*:*:*:*:*",
 75299          "purl": "pkg:deb/debian/logsave@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
 75300          "swid": {
 75301            "attachment": {}
 75302          },
 75303          "pedigree": {},
 75304          "evidence": {},
 75305          "signature": {
 75306            "signature": {
 75307              "publicKey": {}
 75308            }
 75309          },
 75310          "modelCard": {
 75311            "modelParameters": {
 75312              "approach": {}
 75313            },
 75314            "quantitativeAnalysis": {
 75315              "graphics": {}
 75316            },
 75317            "considerations": {}
 75318          }
 75319        },
 75320        {
 75321          "type": "library",
 75322          "bom-ref": "pkg:deb/debian/lsb-base@11.1.0?arch=all\u0026upstream=lsb\u0026distro=debian-11\u0026package-id=67f43d818d5952cf",
 75323          "supplier": {},
 75324          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
 75325          "name": "lsb-base",
 75326          "version": "11.1.0",
 75327          "licenses": [
 75328            {
 75329              "license": {
 75330                "id": "BSD-3-Clause"
 75331              }
 75332            },
 75333            {
 75334              "license": {
 75335                "id": "GPL-2.0-only"
 75336              }
 75337            }
 75338          ],
 75339          "cpe": "cpe:2.3:a:lsb-base:lsb-base:11.1.0:*:*:*:*:*:*:*",
 75340          "purl": "pkg:deb/debian/lsb-base@11.1.0?arch=all\u0026upstream=lsb\u0026distro=debian-11",
 75341          "swid": {
 75342            "attachment": {}
 75343          },
 75344          "pedigree": {},
 75345          "evidence": {},
 75346          "signature": {
 75347            "signature": {
 75348              "publicKey": {}
 75349            }
 75350          },
 75351          "modelCard": {
 75352            "modelParameters": {
 75353              "approach": {}
 75354            },
 75355            "quantitativeAnalysis": {
 75356              "graphics": {}
 75357            },
 75358            "considerations": {}
 75359          }
 75360        },
 75361        {
 75362          "type": "library",
 75363          "bom-ref": "pkg:deb/debian/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=debian-11\u0026package-id=b91e181aea759ff5",
 75364          "supplier": {},
 75365          "publisher": "Boyuan Yang \u003cbyang@debian.org\u003e",
 75366          "name": "mawk",
 75367          "version": "1.3.4.20200120-2",
 75368          "licenses": [
 75369            {
 75370              "license": {
 75371                "id": "GPL-2.0-only"
 75372              }
 75373            }
 75374          ],
 75375          "cpe": "cpe:2.3:a:mawk:mawk:1.3.4.20200120-2:*:*:*:*:*:*:*",
 75376          "purl": "pkg:deb/debian/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=debian-11",
 75377          "swid": {
 75378            "attachment": {}
 75379          },
 75380          "pedigree": {},
 75381          "evidence": {},
 75382          "signature": {
 75383            "signature": {
 75384              "publicKey": {}
 75385            }
 75386          },
 75387          "modelCard": {
 75388            "modelParameters": {
 75389              "approach": {}
 75390            },
 75391            "quantitativeAnalysis": {
 75392              "graphics": {}
 75393            },
 75394            "considerations": {}
 75395          }
 75396        },
 75397        {
 75398          "type": "library",
 75399          "bom-ref": "pkg:deb/debian/mount@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=c7ff86ae9a8937ca",
 75400          "supplier": {},
 75401          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 75402          "name": "mount",
 75403          "version": "2.36.1-8+deb11u1",
 75404          "licenses": [
 75405            {
 75406              "license": {
 75407                "id": "BSD-2-Clause"
 75408              }
 75409            },
 75410            {
 75411              "license": {
 75412                "id": "BSD-3-Clause"
 75413              }
 75414            },
 75415            {
 75416              "license": {
 75417                "id": "BSD-4-Clause"
 75418              }
 75419            },
 75420            {
 75421              "license": {
 75422                "id": "GPL-2.0-only"
 75423              }
 75424            },
 75425            {
 75426              "license": {
 75427                "id": "GPL-2.0-or-later"
 75428              }
 75429            },
 75430            {
 75431              "license": {
 75432                "id": "GPL-3.0-only"
 75433              }
 75434            },
 75435            {
 75436              "license": {
 75437                "id": "GPL-3.0-or-later"
 75438              }
 75439            },
 75440            {
 75441              "license": {
 75442                "name": "LGPL"
 75443              }
 75444            },
 75445            {
 75446              "license": {
 75447                "id": "LGPL-2.0-only"
 75448              }
 75449            },
 75450            {
 75451              "license": {
 75452                "id": "LGPL-2.0-or-later"
 75453              }
 75454            },
 75455            {
 75456              "license": {
 75457                "id": "LGPL-2.1-only"
 75458              }
 75459            },
 75460            {
 75461              "license": {
 75462                "id": "LGPL-2.1-or-later"
 75463              }
 75464            },
 75465            {
 75466              "license": {
 75467                "id": "LGPL-3.0-only"
 75468              }
 75469            },
 75470            {
 75471              "license": {
 75472                "id": "LGPL-3.0-or-later"
 75473              }
 75474            },
 75475            {
 75476              "license": {
 75477                "id": "MIT"
 75478              }
 75479            },
 75480            {
 75481              "license": {
 75482                "name": "public-domain"
 75483              }
 75484            }
 75485          ],
 75486          "cpe": "cpe:2.3:a:mount:mount:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 75487          "purl": "pkg:deb/debian/mount@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
 75488          "swid": {
 75489            "attachment": {}
 75490          },
 75491          "pedigree": {},
 75492          "evidence": {},
 75493          "signature": {
 75494            "signature": {
 75495              "publicKey": {}
 75496            }
 75497          },
 75498          "modelCard": {
 75499            "modelParameters": {
 75500              "approach": {}
 75501            },
 75502            "quantitativeAnalysis": {
 75503              "graphics": {}
 75504            },
 75505            "considerations": {}
 75506          }
 75507        },
 75508        {
 75509          "type": "library",
 75510          "bom-ref": "pkg:deb/debian/ncurses-base@6.2+20201114-2?arch=all\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=9c2239a948284096",
 75511          "supplier": {},
 75512          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 75513          "name": "ncurses-base",
 75514          "version": "6.2+20201114-2",
 75515          "licenses": [
 75516            {
 75517              "license": {
 75518                "id": "BSD-3-Clause"
 75519              }
 75520            },
 75521            {
 75522              "license": {
 75523                "name": "MIT/X11"
 75524              }
 75525            },
 75526            {
 75527              "license": {
 75528                "id": "X11"
 75529              }
 75530            }
 75531          ],
 75532          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.2\\+20201114-2:*:*:*:*:*:*:*",
 75533          "purl": "pkg:deb/debian/ncurses-base@6.2+20201114-2?arch=all\u0026upstream=ncurses\u0026distro=debian-11",
 75534          "swid": {
 75535            "attachment": {}
 75536          },
 75537          "pedigree": {},
 75538          "evidence": {},
 75539          "signature": {
 75540            "signature": {
 75541              "publicKey": {}
 75542            }
 75543          },
 75544          "modelCard": {
 75545            "modelParameters": {
 75546              "approach": {}
 75547            },
 75548            "quantitativeAnalysis": {
 75549              "graphics": {}
 75550            },
 75551            "considerations": {}
 75552          }
 75553        },
 75554        {
 75555          "type": "library",
 75556          "bom-ref": "pkg:deb/debian/ncurses-bin@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=d98c3c34aac1c97c",
 75557          "supplier": {},
 75558          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
 75559          "name": "ncurses-bin",
 75560          "version": "6.2+20201114-2",
 75561          "licenses": [
 75562            {
 75563              "license": {
 75564                "id": "BSD-3-Clause"
 75565              }
 75566            },
 75567            {
 75568              "license": {
 75569                "name": "MIT/X11"
 75570              }
 75571            },
 75572            {
 75573              "license": {
 75574                "id": "X11"
 75575              }
 75576            }
 75577          ],
 75578          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.2\\+20201114-2:*:*:*:*:*:*:*",
 75579          "purl": "pkg:deb/debian/ncurses-bin@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11",
 75580          "swid": {
 75581            "attachment": {}
 75582          },
 75583          "pedigree": {},
 75584          "evidence": {},
 75585          "signature": {
 75586            "signature": {
 75587              "publicKey": {}
 75588            }
 75589          },
 75590          "modelCard": {
 75591            "modelParameters": {
 75592              "approach": {}
 75593            },
 75594            "quantitativeAnalysis": {
 75595              "graphics": {}
 75596            },
 75597            "considerations": {}
 75598          }
 75599        },
 75600        {
 75601          "type": "library",
 75602          "bom-ref": "pkg:deb/debian/nginx@1.23.4-1~bullseye?arch=amd64\u0026distro=debian-11\u0026package-id=79d4a6aea547c9",
 75603          "supplier": {},
 75604          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 75605          "name": "nginx",
 75606          "version": "1.23.4-1~bullseye",
 75607          "cpe": "cpe:2.3:a:nginx:nginx:1.23.4-1\\~bullseye:*:*:*:*:*:*:*",
 75608          "purl": "pkg:deb/debian/nginx@1.23.4-1~bullseye?arch=amd64\u0026distro=debian-11",
 75609          "swid": {
 75610            "attachment": {}
 75611          },
 75612          "pedigree": {},
 75613          "evidence": {},
 75614          "signature": {
 75615            "signature": {
 75616              "publicKey": {}
 75617            }
 75618          },
 75619          "modelCard": {
 75620            "modelParameters": {
 75621              "approach": {}
 75622            },
 75623            "quantitativeAnalysis": {
 75624              "graphics": {}
 75625            },
 75626            "considerations": {}
 75627          }
 75628        },
 75629        {
 75630          "type": "library",
 75631          "bom-ref": "pkg:deb/debian/nginx-module-geoip@1.23.4-1~bullseye?arch=amd64\u0026distro=debian-11\u0026package-id=c1f730ea113243e9",
 75632          "supplier": {},
 75633          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 75634          "name": "nginx-module-geoip",
 75635          "version": "1.23.4-1~bullseye",
 75636          "cpe": "cpe:2.3:a:nginx-module-geoip:nginx-module-geoip:1.23.4-1\\~bullseye:*:*:*:*:*:*:*",
 75637          "purl": "pkg:deb/debian/nginx-module-geoip@1.23.4-1~bullseye?arch=amd64\u0026distro=debian-11",
 75638          "swid": {
 75639            "attachment": {}
 75640          },
 75641          "pedigree": {},
 75642          "evidence": {},
 75643          "signature": {
 75644            "signature": {
 75645              "publicKey": {}
 75646            }
 75647          },
 75648          "modelCard": {
 75649            "modelParameters": {
 75650              "approach": {}
 75651            },
 75652            "quantitativeAnalysis": {
 75653              "graphics": {}
 75654            },
 75655            "considerations": {}
 75656          }
 75657        },
 75658        {
 75659          "type": "library",
 75660          "bom-ref": "pkg:deb/debian/nginx-module-image-filter@1.23.4-1~bullseye?arch=amd64\u0026distro=debian-11\u0026package-id=2ba5e104d0cb31ba",
 75661          "supplier": {},
 75662          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 75663          "name": "nginx-module-image-filter",
 75664          "version": "1.23.4-1~bullseye",
 75665          "cpe": "cpe:2.3:a:nginx-module-image-filter:nginx-module-image-filter:1.23.4-1\\~bullseye:*:*:*:*:*:*:*",
 75666          "purl": "pkg:deb/debian/nginx-module-image-filter@1.23.4-1~bullseye?arch=amd64\u0026distro=debian-11",
 75667          "swid": {
 75668            "attachment": {}
 75669          },
 75670          "pedigree": {},
 75671          "evidence": {},
 75672          "signature": {
 75673            "signature": {
 75674              "publicKey": {}
 75675            }
 75676          },
 75677          "modelCard": {
 75678            "modelParameters": {
 75679              "approach": {}
 75680            },
 75681            "quantitativeAnalysis": {
 75682              "graphics": {}
 75683            },
 75684            "considerations": {}
 75685          }
 75686        },
 75687        {
 75688          "type": "library",
 75689          "bom-ref": "pkg:deb/debian/nginx-module-njs@1.23.4+0.7.11-1~bullseye?arch=amd64\u0026distro=debian-11\u0026package-id=3855065ec7a87a23",
 75690          "supplier": {},
 75691          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 75692          "name": "nginx-module-njs",
 75693          "version": "1.23.4+0.7.11-1~bullseye",
 75694          "cpe": "cpe:2.3:a:nginx-module-njs:nginx-module-njs:1.23.4\\+0.7.11-1\\~bullseye:*:*:*:*:*:*:*",
 75695          "purl": "pkg:deb/debian/nginx-module-njs@1.23.4+0.7.11-1~bullseye?arch=amd64\u0026distro=debian-11",
 75696          "swid": {
 75697            "attachment": {}
 75698          },
 75699          "pedigree": {},
 75700          "evidence": {},
 75701          "signature": {
 75702            "signature": {
 75703              "publicKey": {}
 75704            }
 75705          },
 75706          "modelCard": {
 75707            "modelParameters": {
 75708              "approach": {}
 75709            },
 75710            "quantitativeAnalysis": {
 75711              "graphics": {}
 75712            },
 75713            "considerations": {}
 75714          }
 75715        },
 75716        {
 75717          "type": "library",
 75718          "bom-ref": "pkg:deb/debian/nginx-module-xslt@1.23.4-1~bullseye?arch=amd64\u0026distro=debian-11\u0026package-id=4812f46b471902fd",
 75719          "supplier": {},
 75720          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 75721          "name": "nginx-module-xslt",
 75722          "version": "1.23.4-1~bullseye",
 75723          "cpe": "cpe:2.3:a:nginx-module-xslt:nginx-module-xslt:1.23.4-1\\~bullseye:*:*:*:*:*:*:*",
 75724          "purl": "pkg:deb/debian/nginx-module-xslt@1.23.4-1~bullseye?arch=amd64\u0026distro=debian-11",
 75725          "swid": {
 75726            "attachment": {}
 75727          },
 75728          "pedigree": {},
 75729          "evidence": {},
 75730          "signature": {
 75731            "signature": {
 75732              "publicKey": {}
 75733            }
 75734          },
 75735          "modelCard": {
 75736            "modelParameters": {
 75737              "approach": {}
 75738            },
 75739            "quantitativeAnalysis": {
 75740              "graphics": {}
 75741            },
 75742            "considerations": {}
 75743          }
 75744        },
 75745        {
 75746          "type": "library",
 75747          "bom-ref": "pkg:deb/debian/openssl@1.1.1n-0+deb11u4?arch=amd64\u0026distro=debian-11\u0026package-id=a7dc6e66845f14bf",
 75748          "supplier": {},
 75749          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
 75750          "name": "openssl",
 75751          "version": "1.1.1n-0+deb11u4",
 75752          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1n-0\\+deb11u4:*:*:*:*:*:*:*",
 75753          "purl": "pkg:deb/debian/openssl@1.1.1n-0+deb11u4?arch=amd64\u0026distro=debian-11",
 75754          "swid": {
 75755            "attachment": {}
 75756          },
 75757          "pedigree": {},
 75758          "evidence": {},
 75759          "signature": {
 75760            "signature": {
 75761              "publicKey": {}
 75762            }
 75763          },
 75764          "modelCard": {
 75765            "modelParameters": {
 75766              "approach": {}
 75767            },
 75768            "quantitativeAnalysis": {
 75769              "graphics": {}
 75770            },
 75771            "considerations": {}
 75772          }
 75773        },
 75774        {
 75775          "type": "library",
 75776          "bom-ref": "pkg:deb/debian/passwd@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11\u0026package-id=fdca5992b8d73b50",
 75777          "supplier": {},
 75778          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
 75779          "name": "passwd",
 75780          "version": "1:4.8.1-1",
 75781          "licenses": [
 75782            {
 75783              "license": {
 75784                "id": "GPL-2.0-only"
 75785              }
 75786            }
 75787          ],
 75788          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1:*:*:*:*:*:*:*",
 75789          "purl": "pkg:deb/debian/passwd@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11",
 75790          "swid": {
 75791            "attachment": {}
 75792          },
 75793          "pedigree": {},
 75794          "evidence": {},
 75795          "signature": {
 75796            "signature": {
 75797              "publicKey": {}
 75798            }
 75799          },
 75800          "modelCard": {
 75801            "modelParameters": {
 75802              "approach": {}
 75803            },
 75804            "quantitativeAnalysis": {
 75805              "graphics": {}
 75806            },
 75807            "considerations": {}
 75808          }
 75809        },
 75810        {
 75811          "type": "library",
 75812          "bom-ref": "pkg:deb/debian/perl-base@5.32.1-4+deb11u2?arch=amd64\u0026upstream=perl\u0026distro=debian-11\u0026package-id=96ea9246284c94e6",
 75813          "supplier": {},
 75814          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
 75815          "name": "perl-base",
 75816          "version": "5.32.1-4+deb11u2",
 75817          "licenses": [
 75818            {
 75819              "license": {
 75820                "name": "Artistic"
 75821              }
 75822            },
 75823            {
 75824              "license": {
 75825                "id": "Artistic-2.0"
 75826              }
 75827            },
 75828            {
 75829              "license": {
 75830                "name": "Artistic-dist"
 75831              }
 75832            },
 75833            {
 75834              "license": {
 75835                "id": "BSD-3-Clause"
 75836              }
 75837            },
 75838            {
 75839              "license": {
 75840                "name": "BSD-3-clause-GENERIC"
 75841              }
 75842            },
 75843            {
 75844              "license": {
 75845                "name": "BSD-3-clause-with-weird-numbering"
 75846              }
 75847            },
 75848            {
 75849              "license": {
 75850                "name": "BSD-4-clause-POWERDOG"
 75851              }
 75852            },
 75853            {
 75854              "license": {
 75855                "name": "BZIP"
 75856              }
 75857            },
 75858            {
 75859              "license": {
 75860                "name": "DONT-CHANGE-THE-GPL"
 75861              }
 75862            },
 75863            {
 75864              "license": {
 75865                "name": "Expat"
 75866              }
 75867            },
 75868            {
 75869              "license": {
 75870                "id": "GPL-1.0-only"
 75871              }
 75872            },
 75873            {
 75874              "license": {
 75875                "id": "GPL-1.0-or-later"
 75876              }
 75877            },
 75878            {
 75879              "license": {
 75880                "id": "GPL-2.0-only"
 75881              }
 75882            },
 75883            {
 75884              "license": {
 75885                "id": "GPL-2.0-or-later"
 75886              }
 75887            },
 75888            {
 75889              "license": {
 75890                "name": "GPL-3+-WITH-BISON-EXCEPTION"
 75891              }
 75892            },
 75893            {
 75894              "license": {
 75895                "name": "HSIEH-BSD"
 75896              }
 75897            },
 75898            {
 75899              "license": {
 75900                "name": "HSIEH-DERIVATIVE"
 75901              }
 75902            },
 75903            {
 75904              "license": {
 75905                "id": "LGPL-2.1-only"
 75906              }
 75907            },
 75908            {
 75909              "license": {
 75910                "name": "REGCOMP"
 75911              }
 75912            },
 75913            {
 75914              "license": {
 75915                "name": "REGCOMP,"
 75916              }
 75917            },
 75918            {
 75919              "license": {
 75920                "name": "RRA-KEEP-THIS-NOTICE"
 75921              }
 75922            },
 75923            {
 75924              "license": {
 75925                "name": "SDBM-PUBLIC-DOMAIN"
 75926              }
 75927            },
 75928            {
 75929              "license": {
 75930                "name": "TEXT-TABS"
 75931              }
 75932            },
 75933            {
 75934              "license": {
 75935                "name": "Unicode"
 75936              }
 75937            },
 75938            {
 75939              "license": {
 75940                "id": "Zlib"
 75941              }
 75942            }
 75943          ],
 75944          "cpe": "cpe:2.3:a:perl-base:perl-base:5.32.1-4\\+deb11u2:*:*:*:*:*:*:*",
 75945          "purl": "pkg:deb/debian/perl-base@5.32.1-4+deb11u2?arch=amd64\u0026upstream=perl\u0026distro=debian-11",
 75946          "swid": {
 75947            "attachment": {}
 75948          },
 75949          "pedigree": {},
 75950          "evidence": {},
 75951          "signature": {
 75952            "signature": {
 75953              "publicKey": {}
 75954            }
 75955          },
 75956          "modelCard": {
 75957            "modelParameters": {
 75958              "approach": {}
 75959            },
 75960            "quantitativeAnalysis": {
 75961              "graphics": {}
 75962            },
 75963            "considerations": {}
 75964          }
 75965        },
 75966        {
 75967          "type": "library",
 75968          "bom-ref": "pkg:deb/debian/readline-common@8.1-1?arch=all\u0026upstream=readline\u0026distro=debian-11\u0026package-id=1db616197859926a",
 75969          "supplier": {},
 75970          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
 75971          "name": "readline-common",
 75972          "version": "8.1-1",
 75973          "licenses": [
 75974            {
 75975              "license": {
 75976                "name": "GFDL"
 75977              }
 75978            },
 75979            {
 75980              "license": {
 75981                "id": "GPL-3.0-only"
 75982              }
 75983            }
 75984          ],
 75985          "cpe": "cpe:2.3:a:readline-common:readline-common:8.1-1:*:*:*:*:*:*:*",
 75986          "purl": "pkg:deb/debian/readline-common@8.1-1?arch=all\u0026upstream=readline\u0026distro=debian-11",
 75987          "swid": {
 75988            "attachment": {}
 75989          },
 75990          "pedigree": {},
 75991          "evidence": {},
 75992          "signature": {
 75993            "signature": {
 75994              "publicKey": {}
 75995            }
 75996          },
 75997          "modelCard": {
 75998            "modelParameters": {
 75999              "approach": {}
 76000            },
 76001            "quantitativeAnalysis": {
 76002              "graphics": {}
 76003            },
 76004            "considerations": {}
 76005          }
 76006        },
 76007        {
 76008          "type": "library",
 76009          "bom-ref": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-11\u0026package-id=cd24b1a69c7b788a",
 76010          "supplier": {},
 76011          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
 76012          "name": "sed",
 76013          "version": "4.7-1",
 76014          "licenses": [
 76015            {
 76016              "license": {
 76017                "id": "GPL-3.0-only"
 76018              }
 76019            }
 76020          ],
 76021          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
 76022          "purl": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-11",
 76023          "swid": {
 76024            "attachment": {}
 76025          },
 76026          "pedigree": {},
 76027          "evidence": {},
 76028          "signature": {
 76029            "signature": {
 76030              "publicKey": {}
 76031            }
 76032          },
 76033          "modelCard": {
 76034            "modelParameters": {
 76035              "approach": {}
 76036            },
 76037            "quantitativeAnalysis": {
 76038              "graphics": {}
 76039            },
 76040            "considerations": {}
 76041          }
 76042        },
 76043        {
 76044          "type": "library",
 76045          "bom-ref": "pkg:deb/debian/sensible-utils@0.0.14?arch=all\u0026distro=debian-11\u0026package-id=56274a0c1bc0afa2",
 76046          "supplier": {},
 76047          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
 76048          "name": "sensible-utils",
 76049          "version": "0.0.14",
 76050          "licenses": [
 76051            {
 76052              "license": {
 76053                "name": "All-permissive"
 76054              }
 76055            },
 76056            {
 76057              "license": {
 76058                "id": "GPL-2.0-only"
 76059              }
 76060            },
 76061            {
 76062              "license": {
 76063                "id": "GPL-2.0-or-later"
 76064              }
 76065            },
 76066            {
 76067              "license": {
 76068                "name": "configure"
 76069              }
 76070            },
 76071            {
 76072              "license": {
 76073                "name": "installsh"
 76074              }
 76075            }
 76076          ],
 76077          "cpe": "cpe:2.3:a:sensible-utils:sensible-utils:0.0.14:*:*:*:*:*:*:*",
 76078          "purl": "pkg:deb/debian/sensible-utils@0.0.14?arch=all\u0026distro=debian-11",
 76079          "swid": {
 76080            "attachment": {}
 76081          },
 76082          "pedigree": {},
 76083          "evidence": {},
 76084          "signature": {
 76085            "signature": {
 76086              "publicKey": {}
 76087            }
 76088          },
 76089          "modelCard": {
 76090            "modelParameters": {
 76091              "approach": {}
 76092            },
 76093            "quantitativeAnalysis": {
 76094              "graphics": {}
 76095            },
 76096            "considerations": {}
 76097          }
 76098        },
 76099        {
 76100          "type": "library",
 76101          "bom-ref": "pkg:deb/debian/sysvinit-utils@2.96-7+deb11u1?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-11\u0026package-id=e0e95f2e10cb825e",
 76102          "supplier": {},
 76103          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
 76104          "name": "sysvinit-utils",
 76105          "version": "2.96-7+deb11u1",
 76106          "licenses": [
 76107            {
 76108              "license": {
 76109                "id": "GPL-2.0-only"
 76110              }
 76111            },
 76112            {
 76113              "license": {
 76114                "id": "GPL-2.0-or-later"
 76115              }
 76116            }
 76117          ],
 76118          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.96-7\\+deb11u1:*:*:*:*:*:*:*",
 76119          "purl": "pkg:deb/debian/sysvinit-utils@2.96-7+deb11u1?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-11",
 76120          "swid": {
 76121            "attachment": {}
 76122          },
 76123          "pedigree": {},
 76124          "evidence": {},
 76125          "signature": {
 76126            "signature": {
 76127              "publicKey": {}
 76128            }
 76129          },
 76130          "modelCard": {
 76131            "modelParameters": {
 76132              "approach": {}
 76133            },
 76134            "quantitativeAnalysis": {
 76135              "graphics": {}
 76136            },
 76137            "considerations": {}
 76138          }
 76139        },
 76140        {
 76141          "type": "library",
 76142          "bom-ref": "pkg:deb/debian/tar@1.34+dfsg-1?arch=amd64\u0026distro=debian-11\u0026package-id=9511efaff0991270",
 76143          "supplier": {},
 76144          "publisher": "Janos Lenart \u003cocsi@debian.org\u003e",
 76145          "name": "tar",
 76146          "version": "1.34+dfsg-1",
 76147          "licenses": [
 76148            {
 76149              "license": {
 76150                "id": "GPL-2.0-only"
 76151              }
 76152            },
 76153            {
 76154              "license": {
 76155                "id": "GPL-3.0-only"
 76156              }
 76157            }
 76158          ],
 76159          "cpe": "cpe:2.3:a:tar:tar:1.34\\+dfsg-1:*:*:*:*:*:*:*",
 76160          "purl": "pkg:deb/debian/tar@1.34+dfsg-1?arch=amd64\u0026distro=debian-11",
 76161          "swid": {
 76162            "attachment": {}
 76163          },
 76164          "pedigree": {},
 76165          "evidence": {},
 76166          "signature": {
 76167            "signature": {
 76168              "publicKey": {}
 76169            }
 76170          },
 76171          "modelCard": {
 76172            "modelParameters": {
 76173              "approach": {}
 76174            },
 76175            "quantitativeAnalysis": {
 76176              "graphics": {}
 76177            },
 76178            "considerations": {}
 76179          }
 76180        },
 76181        {
 76182          "type": "library",
 76183          "bom-ref": "pkg:deb/debian/tzdata@2021a-1+deb11u9?arch=all\u0026distro=debian-11\u0026package-id=5268162de7a3ef0",
 76184          "supplier": {},
 76185          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
 76186          "name": "tzdata",
 76187          "version": "2021a-1+deb11u9",
 76188          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-1\\+deb11u9:*:*:*:*:*:*:*",
 76189          "purl": "pkg:deb/debian/tzdata@2021a-1+deb11u9?arch=all\u0026distro=debian-11",
 76190          "swid": {
 76191            "attachment": {}
 76192          },
 76193          "pedigree": {},
 76194          "evidence": {},
 76195          "signature": {
 76196            "signature": {
 76197              "publicKey": {}
 76198            }
 76199          },
 76200          "modelCard": {
 76201            "modelParameters": {
 76202              "approach": {}
 76203            },
 76204            "quantitativeAnalysis": {
 76205              "graphics": {}
 76206            },
 76207            "considerations": {}
 76208          }
 76209        },
 76210        {
 76211          "type": "library",
 76212          "bom-ref": "pkg:deb/debian/ucf@3.0043?arch=all\u0026distro=debian-11\u0026package-id=dfbd4fe9d1f6c201",
 76213          "supplier": {},
 76214          "publisher": "Manoj Srivastava \u003csrivasta@debian.org\u003e",
 76215          "name": "ucf",
 76216          "version": "3.0043",
 76217          "licenses": [
 76218            {
 76219              "license": {
 76220                "id": "GPL-2.0-only"
 76221              }
 76222            }
 76223          ],
 76224          "cpe": "cpe:2.3:a:ucf:ucf:3.0043:*:*:*:*:*:*:*",
 76225          "purl": "pkg:deb/debian/ucf@3.0043?arch=all\u0026distro=debian-11",
 76226          "swid": {
 76227            "attachment": {}
 76228          },
 76229          "pedigree": {},
 76230          "evidence": {},
 76231          "signature": {
 76232            "signature": {
 76233              "publicKey": {}
 76234            }
 76235          },
 76236          "modelCard": {
 76237            "modelParameters": {
 76238              "approach": {}
 76239            },
 76240            "quantitativeAnalysis": {
 76241              "graphics": {}
 76242            },
 76243            "considerations": {}
 76244          }
 76245        },
 76246        {
 76247          "type": "library",
 76248          "bom-ref": "pkg:deb/debian/util-linux@2.36.1-8+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=b8c872368f65d4a3",
 76249          "supplier": {},
 76250          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
 76251          "name": "util-linux",
 76252          "version": "2.36.1-8+deb11u1",
 76253          "licenses": [
 76254            {
 76255              "license": {
 76256                "id": "BSD-2-Clause"
 76257              }
 76258            },
 76259            {
 76260              "license": {
 76261                "id": "BSD-3-Clause"
 76262              }
 76263            },
 76264            {
 76265              "license": {
 76266                "id": "BSD-4-Clause"
 76267              }
 76268            },
 76269            {
 76270              "license": {
 76271                "id": "GPL-2.0-only"
 76272              }
 76273            },
 76274            {
 76275              "license": {
 76276                "id": "GPL-2.0-or-later"
 76277              }
 76278            },
 76279            {
 76280              "license": {
 76281                "id": "GPL-3.0-only"
 76282              }
 76283            },
 76284            {
 76285              "license": {
 76286                "id": "GPL-3.0-or-later"
 76287              }
 76288            },
 76289            {
 76290              "license": {
 76291                "name": "LGPL"
 76292              }
 76293            },
 76294            {
 76295              "license": {
 76296                "id": "LGPL-2.0-only"
 76297              }
 76298            },
 76299            {
 76300              "license": {
 76301                "id": "LGPL-2.0-or-later"
 76302              }
 76303            },
 76304            {
 76305              "license": {
 76306                "id": "LGPL-2.1-only"
 76307              }
 76308            },
 76309            {
 76310              "license": {
 76311                "id": "LGPL-2.1-or-later"
 76312              }
 76313            },
 76314            {
 76315              "license": {
 76316                "id": "LGPL-3.0-only"
 76317              }
 76318            },
 76319            {
 76320              "license": {
 76321                "id": "LGPL-3.0-or-later"
 76322              }
 76323            },
 76324            {
 76325              "license": {
 76326                "id": "MIT"
 76327              }
 76328            },
 76329            {
 76330              "license": {
 76331                "name": "public-domain"
 76332              }
 76333            }
 76334          ],
 76335          "cpe": "cpe:2.3:a:util-linux:util-linux:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
 76336          "purl": "pkg:deb/debian/util-linux@2.36.1-8+deb11u1?arch=amd64\u0026distro=debian-11",
 76337          "swid": {
 76338            "attachment": {}
 76339          },
 76340          "pedigree": {},
 76341          "evidence": {},
 76342          "signature": {
 76343            "signature": {
 76344              "publicKey": {}
 76345            }
 76346          },
 76347          "modelCard": {
 76348            "modelParameters": {
 76349              "approach": {}
 76350            },
 76351            "quantitativeAnalysis": {
 76352              "graphics": {}
 76353            },
 76354            "considerations": {}
 76355          }
 76356        },
 76357        {
 76358          "type": "library",
 76359          "bom-ref": "pkg:deb/debian/wget@1.21-1+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=a1c9b0706dcf6d72",
 76360          "supplier": {},
 76361          "publisher": "Noël Köthe \u003cnoel@debian.org\u003e",
 76362          "name": "wget",
 76363          "version": "1.21-1+deb11u1",
 76364          "licenses": [
 76365            {
 76366              "license": {
 76367                "id": "GFDL-1.2-only"
 76368              }
 76369            },
 76370            {
 76371              "license": {
 76372                "id": "GPL-3.0-only"
 76373              }
 76374            }
 76375          ],
 76376          "cpe": "cpe:2.3:a:wget:wget:1.21-1\\+deb11u1:*:*:*:*:*:*:*",
 76377          "purl": "pkg:deb/debian/wget@1.21-1+deb11u1?arch=amd64\u0026distro=debian-11",
 76378          "swid": {
 76379            "attachment": {}
 76380          },
 76381          "pedigree": {},
 76382          "evidence": {},
 76383          "signature": {
 76384            "signature": {
 76385              "publicKey": {}
 76386            }
 76387          },
 76388          "modelCard": {
 76389            "modelParameters": {
 76390              "approach": {}
 76391            },
 76392            "quantitativeAnalysis": {
 76393              "graphics": {}
 76394            },
 76395            "considerations": {}
 76396          }
 76397        },
 76398        {
 76399          "type": "library",
 76400          "bom-ref": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-2+deb11u2?arch=amd64\u0026upstream=zlib\u0026distro=debian-11\u0026package-id=369e996115240b62",
 76401          "supplier": {},
 76402          "publisher": "Mark Brown \u003cbroonie@debian.org\u003e",
 76403          "name": "zlib1g",
 76404          "version": "1:1.2.11.dfsg-2+deb11u2",
 76405          "licenses": [
 76406            {
 76407              "license": {
 76408                "id": "Zlib"
 76409              }
 76410            }
 76411          ],
 76412          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2\\+deb11u2:*:*:*:*:*:*:*",
 76413          "purl": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-2+deb11u2?arch=amd64\u0026upstream=zlib\u0026distro=debian-11",
 76414          "swid": {
 76415            "attachment": {}
 76416          },
 76417          "pedigree": {},
 76418          "evidence": {},
 76419          "signature": {
 76420            "signature": {
 76421              "publicKey": {}
 76422            }
 76423          },
 76424          "modelCard": {
 76425            "modelParameters": {
 76426              "approach": {}
 76427            },
 76428            "quantitativeAnalysis": {
 76429              "graphics": {}
 76430            },
 76431            "considerations": {}
 76432          }
 76433        },
 76434        {
 76435          "type": "operating-system",
 76436          "supplier": {},
 76437          "name": "debian",
 76438          "version": "11",
 76439          "description": "Debian GNU/Linux 11 (bullseye)",
 76440          "swid": {
 76441            "tagId": "debian",
 76442            "name": "debian",
 76443            "version": "11",
 76444            "attachment": {}
 76445          },
 76446          "pedigree": {},
 76447          "externalReferences": [
 76448            {
 76449              "url": "https://bugs.debian.org/",
 76450              "type": "issue-tracker"
 76451            },
 76452            {
 76453              "url": "https://www.debian.org/",
 76454              "type": "website"
 76455            },
 76456            {
 76457              "url": "https://www.debian.org/support",
 76458              "comment": "support",
 76459              "type": "other"
 76460            }
 76461          ],
 76462          "evidence": {},
 76463          "signature": {
 76464            "signature": {
 76465              "publicKey": {}
 76466            }
 76467          },
 76468          "modelCard": {
 76469            "modelParameters": {
 76470              "approach": {}
 76471            },
 76472            "quantitativeAnalysis": {
 76473              "graphics": {}
 76474            },
 76475            "considerations": {}
 76476          }
 76477        },
 76478        {
 76479          "type": "library",
 76480          "bom-ref": "pkg:maven/org.hdrhistogram/HdrHistogram@2.1.9?package-id=983c05baf5cfe11f",
 76481          "supplier": {},
 76482          "group": "org.hdrhistogram",
 76483          "name": "HdrHistogram",
 76484          "version": "2.1.9",
 76485          "licenses": [
 76486            {
 76487              "license": {
 76488                "name": "http://creativecommons.org/publicdomain/zero/1.0/"
 76489              }
 76490            }
 76491          ],
 76492          "cpe": "cpe:2.3:a:HdrHistogram:HdrHistogram:2.1.9:*:*:*:*:*:*:*",
 76493          "purl": "pkg:maven/org.hdrhistogram/HdrHistogram@2.1.9",
 76494          "swid": {
 76495            "attachment": {}
 76496          },
 76497          "pedigree": {},
 76498          "externalReferences": [
 76499            {
 76500              "type": "build-meta",
 76501              "hashes": [
 76502                {
 76503                  "alg": "SHA-1",
 76504                  "content": "e4631ce165eb400edecfa32e03d3f1be53dee754"
 76505                }
 76506              ]
 76507            }
 76508          ],
 76509          "evidence": {},
 76510          "signature": {
 76511            "signature": {
 76512              "publicKey": {}
 76513            }
 76514          },
 76515          "modelCard": {
 76516            "modelParameters": {
 76517              "approach": {}
 76518            },
 76519            "quantitativeAnalysis": {
 76520              "graphics": {}
 76521            },
 76522            "considerations": {}
 76523          }
 76524        },
 76525        {
 76526          "type": "library",
 76527          "bom-ref": "pkg:maven/com.zaxxer/HikariCP@3.2.0?package-id=5d3fad45be7dfbfe",
 76528          "supplier": {},
 76529          "group": "com.zaxxer",
 76530          "name": "HikariCP",
 76531          "version": "3.2.0",
 76532          "licenses": [
 76533            {
 76534              "license": {
 76535                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 76536              }
 76537            }
 76538          ],
 76539          "cpe": "cpe:2.3:a:HikariCP:HikariCP:3.2.0:*:*:*:*:*:*:*",
 76540          "purl": "pkg:maven/com.zaxxer/HikariCP@3.2.0",
 76541          "swid": {
 76542            "attachment": {}
 76543          },
 76544          "pedigree": {},
 76545          "externalReferences": [
 76546            {
 76547              "type": "build-meta",
 76548              "hashes": [
 76549                {
 76550                  "alg": "SHA-1",
 76551                  "content": "6c66db1c636ee90beb4c65fe34abd8ba9396bca6"
 76552                }
 76553              ]
 76554            }
 76555          ],
 76556          "evidence": {},
 76557          "signature": {
 76558            "signature": {
 76559              "publicKey": {}
 76560            }
 76561          },
 76562          "modelCard": {
 76563            "modelParameters": {
 76564              "approach": {}
 76565            },
 76566            "quantitativeAnalysis": {
 76567              "graphics": {}
 76568            },
 76569            "considerations": {}
 76570          }
 76571        },
 76572        {
 76573          "type": "library",
 76574          "bom-ref": "pkg:maven/com.googlecode.javaewah/JavaEWAH@1.1.13?package-id=ceea76f1e9b80ff8",
 76575          "supplier": {},
 76576          "group": "com.googlecode.javaewah",
 76577          "name": "JavaEWAH",
 76578          "version": "1.1.13",
 76579          "licenses": [
 76580            {
 76581              "license": {
 76582                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 76583              }
 76584            }
 76585          ],
 76586          "cpe": "cpe:2.3:a:googlecode:JavaEWAH:1.1.13:*:*:*:*:*:*:*",
 76587          "purl": "pkg:maven/com.googlecode.javaewah/JavaEWAH@1.1.13",
 76588          "swid": {
 76589            "attachment": {}
 76590          },
 76591          "pedigree": {},
 76592          "externalReferences": [
 76593            {
 76594              "type": "build-meta",
 76595              "hashes": [
 76596                {
 76597                  "alg": "SHA-1",
 76598                  "content": "32cd724a42dc73f99ca08453d11a4bb83e0034c7"
 76599                }
 76600              ]
 76601            }
 76602          ],
 76603          "evidence": {},
 76604          "signature": {
 76605            "signature": {
 76606              "publicKey": {}
 76607            }
 76608          },
 76609          "modelCard": {
 76610            "modelParameters": {
 76611              "approach": {}
 76612            },
 76613            "quantitativeAnalysis": {
 76614              "graphics": {}
 76615            },
 76616            "considerations": {}
 76617          }
 76618        },
 76619        {
 76620          "type": "library",
 76621          "bom-ref": "pkg:maven/org.latencyutils/LatencyUtils@2.0.3?package-id=e087331436031421",
 76622          "supplier": {},
 76623          "group": "org.latencyutils",
 76624          "name": "LatencyUtils",
 76625          "version": "2.0.3",
 76626          "cpe": "cpe:2.3:a:LatencyUtils:LatencyUtils:2.0.3:*:*:*:*:*:*:*",
 76627          "purl": "pkg:maven/org.latencyutils/LatencyUtils@2.0.3",
 76628          "swid": {
 76629            "attachment": {}
 76630          },
 76631          "pedigree": {},
 76632          "externalReferences": [
 76633            {
 76634              "type": "build-meta",
 76635              "hashes": [
 76636                {
 76637                  "alg": "SHA-1",
 76638                  "content": "769c0b82cb2421c8256300e907298a9410a2a3d3"
 76639                }
 76640              ]
 76641            }
 76642          ],
 76643          "evidence": {},
 76644          "signature": {
 76645            "signature": {
 76646              "publicKey": {}
 76647            }
 76648          },
 76649          "modelCard": {
 76650            "modelParameters": {
 76651              "approach": {}
 76652            },
 76653            "quantitativeAnalysis": {
 76654              "graphics": {}
 76655            },
 76656            "considerations": {}
 76657          }
 76658        },
 76659        {
 76660          "type": "library",
 76661          "bom-ref": "pkg:maven/US_export_policy/US_export_policy?package-id=9fc12ca3a2e2eae4",
 76662          "supplier": {},
 76663          "name": "US_export_policy",
 76664          "cpe": "cpe:2.3:a:US-export-policy:US-export-policy:*:*:*:*:*:*:*:*",
 76665          "purl": "pkg:maven/US_export_policy/US_export_policy",
 76666          "swid": {
 76667            "attachment": {}
 76668          },
 76669          "pedigree": {},
 76670          "externalReferences": [
 76671            {
 76672              "type": "build-meta",
 76673              "hashes": [
 76674                {
 76675                  "alg": "SHA-1",
 76676                  "content": "2fcb002cf98fbafecb4fe01976ab172b71411654"
 76677                }
 76678              ]
 76679            }
 76680          ],
 76681          "evidence": {},
 76682          "signature": {
 76683            "signature": {
 76684              "publicKey": {}
 76685            }
 76686          },
 76687          "modelCard": {
 76688            "modelParameters": {
 76689              "approach": {}
 76690            },
 76691            "quantitativeAnalysis": {
 76692              "graphics": {}
 76693            },
 76694            "considerations": {}
 76695          }
 76696        },
 76697        {
 76698          "type": "library",
 76699          "bom-ref": "pkg:maven/US_export_policy/US_export_policy?package-id=502b2a55c42bdec0",
 76700          "supplier": {},
 76701          "name": "US_export_policy",
 76702          "cpe": "cpe:2.3:a:US-export-policy:US-export-policy:*:*:*:*:*:*:*:*",
 76703          "purl": "pkg:maven/US_export_policy/US_export_policy",
 76704          "swid": {
 76705            "attachment": {}
 76706          },
 76707          "pedigree": {},
 76708          "externalReferences": [
 76709            {
 76710              "type": "build-meta",
 76711              "hashes": [
 76712                {
 76713                  "alg": "SHA-1",
 76714                  "content": "2fcb002cf98fbafecb4fe01976ab172b71411654"
 76715                }
 76716              ]
 76717            }
 76718          ],
 76719          "evidence": {},
 76720          "signature": {
 76721            "signature": {
 76722              "publicKey": {}
 76723            }
 76724          },
 76725          "modelCard": {
 76726            "modelParameters": {
 76727              "approach": {}
 76728            },
 76729            "quantitativeAnalysis": {
 76730              "graphics": {}
 76731            },
 76732            "considerations": {}
 76733          }
 76734        },
 76735        {
 76736          "type": "library",
 76737          "bom-ref": "pkg:maven/com.sun/activation@1.1?package-id=7c6676b816125c4a",
 76738          "supplier": {},
 76739          "name": "activation",
 76740          "version": "1.1",
 76741          "cpe": "cpe:2.3:a:sun-microsystems\\,-inc-:activation:1.1:*:*:*:*:*:*:*",
 76742          "purl": "pkg:maven/com.sun/activation@1.1",
 76743          "swid": {
 76744            "attachment": {}
 76745          },
 76746          "pedigree": {},
 76747          "externalReferences": [
 76748            {
 76749              "type": "build-meta",
 76750              "hashes": [
 76751                {
 76752                  "alg": "SHA-1",
 76753                  "content": "e6cb541461c2834bdea3eb920f1884d1eb508b50"
 76754                }
 76755              ]
 76756            }
 76757          ],
 76758          "evidence": {},
 76759          "signature": {
 76760            "signature": {
 76761              "publicKey": {}
 76762            }
 76763          },
 76764          "modelCard": {
 76765            "modelParameters": {
 76766              "approach": {}
 76767            },
 76768            "quantitativeAnalysis": {
 76769              "graphics": {}
 76770            },
 76771            "considerations": {}
 76772          }
 76773        },
 76774        {
 76775          "type": "library",
 76776          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=92b19c7750fb559d",
 76777          "supplier": {},
 76778          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 76779          "name": "alpine-baselayout",
 76780          "version": "3.4.0-r0",
 76781          "description": "Alpine base dir structure and init scripts",
 76782          "licenses": [
 76783            {
 76784              "license": {
 76785                "id": "GPL-2.0-only"
 76786              }
 76787            }
 76788          ],
 76789          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.4.0-r0:*:*:*:*:*:*:*",
 76790          "purl": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 76791          "swid": {
 76792            "attachment": {}
 76793          },
 76794          "pedigree": {},
 76795          "externalReferences": [
 76796            {
 76797              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 76798              "type": "distribution"
 76799            }
 76800          ],
 76801          "evidence": {},
 76802          "signature": {
 76803            "signature": {
 76804              "publicKey": {}
 76805            }
 76806          },
 76807          "modelCard": {
 76808            "modelParameters": {
 76809              "approach": {}
 76810            },
 76811            "quantitativeAnalysis": {
 76812              "graphics": {}
 76813            },
 76814            "considerations": {}
 76815          }
 76816        },
 76817        {
 76818          "type": "library",
 76819          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.3\u0026package-id=291d1267b40d636f",
 76820          "supplier": {},
 76821          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 76822          "name": "alpine-baselayout-data",
 76823          "version": "3.4.0-r0",
 76824          "description": "Alpine base dir structure and init scripts",
 76825          "licenses": [
 76826            {
 76827              "license": {
 76828                "id": "GPL-2.0-only"
 76829              }
 76830            }
 76831          ],
 76832          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.4.0-r0:*:*:*:*:*:*:*",
 76833          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.3",
 76834          "swid": {
 76835            "attachment": {}
 76836          },
 76837          "pedigree": {},
 76838          "externalReferences": [
 76839            {
 76840              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 76841              "type": "distribution"
 76842            }
 76843          ],
 76844          "evidence": {},
 76845          "signature": {
 76846            "signature": {
 76847              "publicKey": {}
 76848            }
 76849          },
 76850          "modelCard": {
 76851            "modelParameters": {
 76852              "approach": {}
 76853            },
 76854            "quantitativeAnalysis": {
 76855              "graphics": {}
 76856            },
 76857            "considerations": {}
 76858          }
 76859        },
 76860        {
 76861          "type": "library",
 76862          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2b5e23d349b556cf",
 76863          "supplier": {},
 76864          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 76865          "name": "alpine-keys",
 76866          "version": "2.4-r1",
 76867          "description": "Public keys for Alpine Linux packages",
 76868          "licenses": [
 76869            {
 76870              "license": {
 76871                "id": "MIT"
 76872              }
 76873            }
 76874          ],
 76875          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
 76876          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 76877          "swid": {
 76878            "attachment": {}
 76879          },
 76880          "pedigree": {},
 76881          "externalReferences": [
 76882            {
 76883              "url": "https://alpinelinux.org",
 76884              "type": "distribution"
 76885            }
 76886          ],
 76887          "evidence": {},
 76888          "signature": {
 76889            "signature": {
 76890              "publicKey": {}
 76891            }
 76892          },
 76893          "modelCard": {
 76894            "modelParameters": {
 76895              "approach": {}
 76896            },
 76897            "quantitativeAnalysis": {
 76898              "graphics": {}
 76899            },
 76900            "considerations": {}
 76901          }
 76902        },
 76903        {
 76904          "type": "library",
 76905          "bom-ref": "pkg:maven/com.rabbitmq/amqp-client@5.4.3?package-id=194ff004c9048bbf",
 76906          "supplier": {},
 76907          "group": "com.rabbitmq",
 76908          "name": "amqp-client",
 76909          "version": "5.4.3",
 76910          "licenses": [
 76911            {
 76912              "license": {
 76913                "name": "http://www.apache.org/licenses/LICENSE-2.0.html, http://www.gnu.org/licenses/gpl-2.0.txt, http://www.mozilla.org/MPL/MPL-1.1.txt"
 76914              }
 76915            }
 76916          ],
 76917          "cpe": "cpe:2.3:a:amqp-working-group-\\(www-amqp-org\\):amqp-client:5.4.3:*:*:*:*:*:*:*",
 76918          "purl": "pkg:maven/com.rabbitmq/amqp-client@5.4.3",
 76919          "swid": {
 76920            "attachment": {}
 76921          },
 76922          "pedigree": {},
 76923          "externalReferences": [
 76924            {
 76925              "type": "build-meta",
 76926              "hashes": [
 76927                {
 76928                  "alg": "SHA-1",
 76929                  "content": "9bede47bcd205e93f422adf4923892e31a640239"
 76930                }
 76931              ]
 76932            }
 76933          ],
 76934          "evidence": {},
 76935          "signature": {
 76936            "signature": {
 76937              "publicKey": {}
 76938            }
 76939          },
 76940          "modelCard": {
 76941            "modelParameters": {
 76942              "approach": {}
 76943            },
 76944            "quantitativeAnalysis": {
 76945              "graphics": {}
 76946            },
 76947            "considerations": {}
 76948          }
 76949        },
 76950        {
 76951          "type": "library",
 76952          "bom-ref": "pkg:maven/com.google.code.findbugs/annotations@3.0.1?package-id=b28c5754898a18a1",
 76953          "supplier": {},
 76954          "group": "com.google.code.findbugs",
 76955          "name": "annotations",
 76956          "version": "3.0.1",
 76957          "licenses": [
 76958            {
 76959              "license": {
 76960                "name": "http://www.gnu.org/licenses/lgpl.html"
 76961              }
 76962            }
 76963          ],
 76964          "cpe": "cpe:2.3:a:annotations:annotations:3.0.1:*:*:*:*:*:*:*",
 76965          "purl": "pkg:maven/com.google.code.findbugs/annotations@3.0.1",
 76966          "swid": {
 76967            "attachment": {}
 76968          },
 76969          "pedigree": {},
 76970          "externalReferences": [
 76971            {
 76972              "type": "build-meta",
 76973              "hashes": [
 76974                {
 76975                  "alg": "SHA-1",
 76976                  "content": "fc019a2216218990d64dfe756e7aa20f0069dea2"
 76977                }
 76978              ]
 76979            }
 76980          ],
 76981          "evidence": {},
 76982          "signature": {
 76983            "signature": {
 76984              "publicKey": {}
 76985            }
 76986          },
 76987          "modelCard": {
 76988            "modelParameters": {
 76989              "approach": {}
 76990            },
 76991            "quantitativeAnalysis": {
 76992              "graphics": {}
 76993            },
 76994            "considerations": {}
 76995          }
 76996        },
 76997        {
 76998          "type": "library",
 76999          "bom-ref": "pkg:maven/antlr/antlr@2.7.7?package-id=8c2ab51ddf98c10d",
 77000          "supplier": {},
 77001          "name": "antlr",
 77002          "version": "2.7.7",
 77003          "cpe": "cpe:2.3:a:antlr:antlr:2.7.7:*:*:*:*:*:*:*",
 77004          "purl": "pkg:maven/antlr/antlr@2.7.7",
 77005          "swid": {
 77006            "attachment": {}
 77007          },
 77008          "pedigree": {},
 77009          "externalReferences": [
 77010            {
 77011              "type": "build-meta",
 77012              "hashes": [
 77013                {
 77014                  "alg": "SHA-1",
 77015                  "content": "83cd2cd674a217ade95a4bb83a8a14f351f48bd0"
 77016                }
 77017              ]
 77018            }
 77019          ],
 77020          "evidence": {},
 77021          "signature": {
 77022            "signature": {
 77023              "publicKey": {}
 77024            }
 77025          },
 77026          "modelCard": {
 77027            "modelParameters": {
 77028              "approach": {}
 77029            },
 77030            "quantitativeAnalysis": {
 77031              "graphics": {}
 77032            },
 77033            "considerations": {}
 77034          }
 77035        },
 77036        {
 77037          "type": "library",
 77038          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=e5f757b0df1f62bc",
 77039          "supplier": {},
 77040          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 77041          "name": "apk-tools",
 77042          "version": "2.12.10-r1",
 77043          "description": "Alpine Package Keeper - package manager for alpine",
 77044          "licenses": [
 77045            {
 77046              "license": {
 77047                "id": "GPL-2.0-only"
 77048              }
 77049            }
 77050          ],
 77051          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.10-r1:*:*:*:*:*:*:*",
 77052          "purl": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 77053          "swid": {
 77054            "attachment": {}
 77055          },
 77056          "pedigree": {},
 77057          "externalReferences": [
 77058            {
 77059              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
 77060              "type": "distribution"
 77061            }
 77062          ],
 77063          "evidence": {},
 77064          "signature": {
 77065            "signature": {
 77066              "publicKey": {}
 77067            }
 77068          },
 77069          "modelCard": {
 77070            "modelParameters": {
 77071              "approach": {}
 77072            },
 77073            "quantitativeAnalysis": {
 77074              "graphics": {}
 77075            },
 77076            "considerations": {}
 77077          }
 77078        },
 77079        {
 77080          "type": "library",
 77081          "bom-ref": "pkg:maven/org.aspectj.weaver/aspectjweaver@1.9.4?package-id=c015668d2c0ae088",
 77082          "supplier": {},
 77083          "name": "aspectjweaver",
 77084          "version": "1.9.4",
 77085          "cpe": "cpe:2.3:a:https\\:\\/\\/www-eclipse-org\\/aspectj\\/:aspectjweaver:1.9.4:*:*:*:*:*:*:*",
 77086          "purl": "pkg:maven/org.aspectj.weaver/aspectjweaver@1.9.4",
 77087          "swid": {
 77088            "attachment": {}
 77089          },
 77090          "pedigree": {},
 77091          "externalReferences": [
 77092            {
 77093              "type": "build-meta",
 77094              "hashes": [
 77095                {
 77096                  "alg": "SHA-1",
 77097                  "content": "9205229878f3d62fbd3a32a0fb6be2d6ad8589a9"
 77098                }
 77099              ]
 77100            }
 77101          ],
 77102          "evidence": {},
 77103          "signature": {
 77104            "signature": {
 77105              "publicKey": {}
 77106            }
 77107          },
 77108          "modelCard": {
 77109            "modelParameters": {
 77110              "approach": {}
 77111            },
 77112            "quantitativeAnalysis": {
 77113              "graphics": {}
 77114            },
 77115            "considerations": {}
 77116          }
 77117        },
 77118        {
 77119          "type": "library",
 77120          "bom-ref": "pkg:maven/io.pliant/backend@0.0.1-SNAPSHOT?package-id=67988932272db66c",
 77121          "supplier": {},
 77122          "group": "io.pliant",
 77123          "name": "backend",
 77124          "version": "0.0.1-SNAPSHOT",
 77125          "cpe": "cpe:2.3:a:springframework:backend:0.0.1-SNAPSHOT:*:*:*:*:*:*:*",
 77126          "purl": "pkg:maven/io.pliant/backend@0.0.1-SNAPSHOT",
 77127          "swid": {
 77128            "attachment": {}
 77129          },
 77130          "pedigree": {},
 77131          "externalReferences": [
 77132            {
 77133              "type": "build-meta",
 77134              "hashes": [
 77135                {
 77136                  "alg": "SHA-1",
 77137                  "content": "855c02bdc72ebb23574d410bba62f6822e2b1a23"
 77138                }
 77139              ]
 77140            }
 77141          ],
 77142          "evidence": {},
 77143          "signature": {
 77144            "signature": {
 77145              "publicKey": {}
 77146            }
 77147          },
 77148          "modelCard": {
 77149            "modelParameters": {
 77150              "approach": {}
 77151            },
 77152            "quantitativeAnalysis": {
 77153              "graphics": {}
 77154            },
 77155            "considerations": {}
 77156          }
 77157        },
 77158        {
 77159          "type": "library",
 77160          "bom-ref": "pkg:maven/org.bouncycastle.bcpkix/bcpkix-jdk15on@1.60?package-id=b4035ad272f28fea",
 77161          "supplier": {},
 77162          "name": "bcpkix-jdk15on",
 77163          "version": "1.60",
 77164          "cpe": "cpe:2.3:a:bouncycastle-org:bcpkix-jdk15on:1.60:*:*:*:*:*:*:*",
 77165          "purl": "pkg:maven/org.bouncycastle.bcpkix/bcpkix-jdk15on@1.60",
 77166          "swid": {
 77167            "attachment": {}
 77168          },
 77169          "pedigree": {},
 77170          "externalReferences": [
 77171            {
 77172              "type": "build-meta",
 77173              "hashes": [
 77174                {
 77175                  "alg": "SHA-1",
 77176                  "content": "d0c46320fbc07be3a24eb13a56cee4e3d38e0c75"
 77177                }
 77178              ]
 77179            }
 77180          ],
 77181          "evidence": {},
 77182          "signature": {
 77183            "signature": {
 77184              "publicKey": {}
 77185            }
 77186          },
 77187          "modelCard": {
 77188            "modelParameters": {
 77189              "approach": {}
 77190            },
 77191            "quantitativeAnalysis": {
 77192              "graphics": {}
 77193            },
 77194            "considerations": {}
 77195          }
 77196        },
 77197        {
 77198          "type": "library",
 77199          "bom-ref": "pkg:maven/org.bouncycastle.bcproviderext/bcprov-ext-jdk15on@1.60?package-id=9d4b0a7e88e46879",
 77200          "supplier": {},
 77201          "name": "bcprov-ext-jdk15on",
 77202          "version": "1.60",
 77203          "cpe": "cpe:2.3:a:bcprov-ext-jdk15on:bcprov-ext-jdk15on:1.60:*:*:*:*:*:*:*",
 77204          "purl": "pkg:maven/org.bouncycastle.bcproviderext/bcprov-ext-jdk15on@1.60",
 77205          "swid": {
 77206            "attachment": {}
 77207          },
 77208          "pedigree": {},
 77209          "externalReferences": [
 77210            {
 77211              "type": "build-meta",
 77212              "hashes": [
 77213                {
 77214                  "alg": "SHA-1",
 77215                  "content": "0faea4c950bbfa6e8882830f0266bc9185755d37"
 77216                }
 77217              ]
 77218            }
 77219          ],
 77220          "evidence": {},
 77221          "signature": {
 77222            "signature": {
 77223              "publicKey": {}
 77224            }
 77225          },
 77226          "modelCard": {
 77227            "modelParameters": {
 77228              "approach": {}
 77229            },
 77230            "quantitativeAnalysis": {
 77231              "graphics": {}
 77232            },
 77233            "considerations": {}
 77234          }
 77235        },
 77236        {
 77237          "type": "library",
 77238          "bom-ref": "pkg:maven/org.bouncycastle.bcprovider/bcprov-jdk15on@1.64?package-id=ff0833697a95bd24",
 77239          "supplier": {},
 77240          "name": "bcprov-jdk15on",
 77241          "version": "1.64",
 77242          "cpe": "cpe:2.3:a:bouncycastle-org:bcprov-jdk15on:1.64:*:*:*:*:*:*:*",
 77243          "purl": "pkg:maven/org.bouncycastle.bcprovider/bcprov-jdk15on@1.64",
 77244          "swid": {
 77245            "attachment": {}
 77246          },
 77247          "pedigree": {},
 77248          "externalReferences": [
 77249            {
 77250              "type": "build-meta",
 77251              "hashes": [
 77252                {
 77253                  "alg": "SHA-1",
 77254                  "content": "1467dac1b787b5ad2a18201c0c281df69882259e"
 77255                }
 77256              ]
 77257            }
 77258          ],
 77259          "evidence": {},
 77260          "signature": {
 77261            "signature": {
 77262              "publicKey": {}
 77263            }
 77264          },
 77265          "modelCard": {
 77266            "modelParameters": {
 77267              "approach": {}
 77268            },
 77269            "quantitativeAnalysis": {
 77270              "graphics": {}
 77271            },
 77272            "considerations": {}
 77273          }
 77274        },
 77275        {
 77276          "type": "library",
 77277          "bom-ref": "pkg:maven/com.infradna.tool/bridge-method-annotation@1.13?package-id=875d69917e8f1fc1",
 77278          "supplier": {},
 77279          "group": "com.infradna.tool",
 77280          "name": "bridge-method-annotation",
 77281          "version": "1.13",
 77282          "cpe": "cpe:2.3:a:bridge-method-annotation:bridge-method-annotation:1.13:*:*:*:*:*:*:*",
 77283          "purl": "pkg:maven/com.infradna.tool/bridge-method-annotation@1.13",
 77284          "swid": {
 77285            "attachment": {}
 77286          },
 77287          "pedigree": {},
 77288          "externalReferences": [
 77289            {
 77290              "type": "build-meta",
 77291              "hashes": [
 77292                {
 77293                  "alg": "SHA-1",
 77294                  "content": "18cdce50cde6f54ee5390d0907384f72183ff0fe"
 77295                }
 77296              ]
 77297            }
 77298          ],
 77299          "evidence": {},
 77300          "signature": {
 77301            "signature": {
 77302              "publicKey": {}
 77303            }
 77304          },
 77305          "modelCard": {
 77306            "modelParameters": {
 77307              "approach": {}
 77308            },
 77309            "quantitativeAnalysis": {
 77310              "graphics": {}
 77311            },
 77312            "considerations": {}
 77313          }
 77314        },
 77315        {
 77316          "type": "library",
 77317          "bom-ref": "pkg:apk/alpine/brotli-libs@1.0.9-r9?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.17.3\u0026package-id=b908173dd9145006",
 77318          "supplier": {},
 77319          "publisher": "prspkt \u003cprspkt@protonmail.com\u003e",
 77320          "name": "brotli-libs",
 77321          "version": "1.0.9-r9",
 77322          "description": "Generic lossless compressor (libraries)",
 77323          "licenses": [
 77324            {
 77325              "license": {
 77326                "id": "MIT"
 77327              }
 77328            }
 77329          ],
 77330          "cpe": "cpe:2.3:a:brotli-libs:brotli-libs:1.0.9-r9:*:*:*:*:*:*:*",
 77331          "purl": "pkg:apk/alpine/brotli-libs@1.0.9-r9?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.17.3",
 77332          "swid": {
 77333            "attachment": {}
 77334          },
 77335          "pedigree": {},
 77336          "externalReferences": [
 77337            {
 77338              "url": "https://github.com/google/brotli",
 77339              "type": "distribution"
 77340            }
 77341          ],
 77342          "evidence": {},
 77343          "signature": {
 77344            "signature": {
 77345              "publicKey": {}
 77346            }
 77347          },
 77348          "modelCard": {
 77349            "modelParameters": {
 77350              "approach": {}
 77351            },
 77352            "quantitativeAnalysis": {
 77353              "graphics": {}
 77354            },
 77355            "considerations": {}
 77356          }
 77357        },
 77358        {
 77359          "type": "library",
 77360          "bom-ref": "pkg:maven/com.aayushatharva.brotli4j/brotli4j@1.8.0?package-id=74d7ede7c7c2e20d",
 77361          "supplier": {},
 77362          "group": "com.aayushatharva.brotli4j",
 77363          "name": "brotli4j",
 77364          "version": "1.8.0",
 77365          "cpe": "cpe:2.3:a:aayushatharva:brotli4j:1.8.0:*:*:*:*:*:*:*",
 77366          "purl": "pkg:maven/com.aayushatharva.brotli4j/brotli4j@1.8.0",
 77367          "swid": {
 77368            "attachment": {}
 77369          },
 77370          "pedigree": {},
 77371          "externalReferences": [
 77372            {
 77373              "type": "build-meta",
 77374              "hashes": [
 77375                {
 77376                  "alg": "SHA-1",
 77377                  "content": "2bc52df23c9aed6aaaf63156fa9a4f7beca80f56"
 77378                }
 77379              ]
 77380            }
 77381          ],
 77382          "evidence": {},
 77383          "signature": {
 77384            "signature": {
 77385              "publicKey": {}
 77386            }
 77387          },
 77388          "modelCard": {
 77389            "modelParameters": {
 77390              "approach": {}
 77391            },
 77392            "quantitativeAnalysis": {
 77393              "graphics": {}
 77394            },
 77395            "considerations": {}
 77396          }
 77397        },
 77398        {
 77399          "type": "library",
 77400          "bom-ref": "pkg:maven/bsh/bsh@2.0b6?package-id=389c0c0206dc0128",
 77401          "supplier": {},
 77402          "name": "bsh",
 77403          "version": "2.0b6",
 77404          "cpe": "cpe:2.3:a:pat-niemeyer-\\(pat\\@pat-net\\):bsh:2.0b6:*:*:*:*:*:*:*",
 77405          "purl": "pkg:maven/bsh/bsh@2.0b6",
 77406          "swid": {
 77407            "attachment": {}
 77408          },
 77409          "pedigree": {},
 77410          "externalReferences": [
 77411            {
 77412              "type": "build-meta",
 77413              "hashes": [
 77414                {
 77415                  "alg": "SHA-1",
 77416                  "content": "fb418f9b33a0b951e9a2978b4b6ee93b2707e72f"
 77417                }
 77418              ]
 77419            }
 77420          ],
 77421          "evidence": {},
 77422          "signature": {
 77423            "signature": {
 77424              "publicKey": {}
 77425            }
 77426          },
 77427          "modelCard": {
 77428            "modelParameters": {
 77429              "approach": {}
 77430            },
 77431            "quantitativeAnalysis": {
 77432              "graphics": {}
 77433            },
 77434            "considerations": {}
 77435          }
 77436        },
 77437        {
 77438          "type": "library",
 77439          "bom-ref": "pkg:maven/com.github.fge.btf/btf@1.2?package-id=eb3245ad9e46961d",
 77440          "supplier": {},
 77441          "name": "btf",
 77442          "version": "1.2",
 77443          "cpe": "cpe:2.3:a:github:btf:1.2:*:*:*:*:*:*:*",
 77444          "purl": "pkg:maven/com.github.fge.btf/btf@1.2",
 77445          "swid": {
 77446            "attachment": {}
 77447          },
 77448          "pedigree": {},
 77449          "externalReferences": [
 77450            {
 77451              "type": "build-meta",
 77452              "hashes": [
 77453                {
 77454                  "alg": "SHA-1",
 77455                  "content": "9e66651022eb86301b348d57e6f59459effc343b"
 77456                }
 77457              ]
 77458            }
 77459          ],
 77460          "evidence": {},
 77461          "signature": {
 77462            "signature": {
 77463              "publicKey": {}
 77464            }
 77465          },
 77466          "modelCard": {
 77467            "modelParameters": {
 77468              "approach": {}
 77469            },
 77470            "quantitativeAnalysis": {
 77471              "graphics": {}
 77472            },
 77473            "considerations": {}
 77474          }
 77475        },
 77476        {
 77477          "type": "application",
 77478          "bom-ref": "e6c9486419cbb84e",
 77479          "supplier": {},
 77480          "name": "busybox",
 77481          "version": "1.35.0",
 77482          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
 77483          "swid": {
 77484            "attachment": {}
 77485          },
 77486          "pedigree": {},
 77487          "evidence": {},
 77488          "signature": {
 77489            "signature": {
 77490              "publicKey": {}
 77491            }
 77492          },
 77493          "modelCard": {
 77494            "modelParameters": {
 77495              "approach": {}
 77496            },
 77497            "quantitativeAnalysis": {
 77498              "graphics": {}
 77499            },
 77500            "considerations": {}
 77501          }
 77502        },
 77503        {
 77504          "type": "library",
 77505          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=623d53216342d45e",
 77506          "supplier": {},
 77507          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 77508          "name": "busybox",
 77509          "version": "1.35.0-r29",
 77510          "description": "Size optimized toolbox of many common UNIX utilities",
 77511          "licenses": [
 77512            {
 77513              "license": {
 77514                "id": "GPL-2.0-only"
 77515              }
 77516            }
 77517          ],
 77518          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r29:*:*:*:*:*:*:*",
 77519          "purl": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.3",
 77520          "swid": {
 77521            "attachment": {}
 77522          },
 77523          "pedigree": {},
 77524          "externalReferences": [
 77525            {
 77526              "url": "https://busybox.net/",
 77527              "type": "distribution"
 77528            }
 77529          ],
 77530          "evidence": {},
 77531          "signature": {
 77532            "signature": {
 77533              "publicKey": {}
 77534            }
 77535          },
 77536          "modelCard": {
 77537            "modelParameters": {
 77538              "approach": {}
 77539            },
 77540            "quantitativeAnalysis": {
 77541              "graphics": {}
 77542            },
 77543            "considerations": {}
 77544          }
 77545        },
 77546        {
 77547          "type": "library",
 77548          "bom-ref": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3\u0026package-id=256fc96b4a8c4da8",
 77549          "supplier": {},
 77550          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 77551          "name": "busybox-binsh",
 77552          "version": "1.35.0-r29",
 77553          "description": "busybox ash /bin/sh",
 77554          "licenses": [
 77555            {
 77556              "license": {
 77557                "id": "GPL-2.0-only"
 77558              }
 77559            }
 77560          ],
 77561          "cpe": "cpe:2.3:a:busybox-binsh:busybox-binsh:1.35.0-r29:*:*:*:*:*:*:*",
 77562          "purl": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3",
 77563          "swid": {
 77564            "attachment": {}
 77565          },
 77566          "pedigree": {},
 77567          "externalReferences": [
 77568            {
 77569              "url": "https://busybox.net/",
 77570              "type": "distribution"
 77571            }
 77572          ],
 77573          "evidence": {},
 77574          "signature": {
 77575            "signature": {
 77576              "publicKey": {}
 77577            }
 77578          },
 77579          "modelCard": {
 77580            "modelParameters": {
 77581              "approach": {}
 77582            },
 77583            "quantitativeAnalysis": {
 77584              "graphics": {}
 77585            },
 77586            "considerations": {}
 77587          }
 77588        },
 77589        {
 77590          "type": "library",
 77591          "bom-ref": "pkg:maven/net.bytebuddy/byte-buddy-dep@1.9.12?package-id=71240cd0480f4edd",
 77592          "supplier": {},
 77593          "group": "net.bytebuddy",
 77594          "name": "byte-buddy-dep",
 77595          "version": "1.9.12",
 77596          "licenses": [
 77597            {
 77598              "license": {
 77599                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 77600              }
 77601            }
 77602          ],
 77603          "cpe": "cpe:2.3:a:byte-buddy-dep:byte-buddy-dep:1.9.12:*:*:*:*:*:*:*",
 77604          "purl": "pkg:maven/net.bytebuddy/byte-buddy-dep@1.9.12",
 77605          "swid": {
 77606            "attachment": {}
 77607          },
 77608          "pedigree": {},
 77609          "externalReferences": [
 77610            {
 77611              "type": "build-meta",
 77612              "hashes": [
 77613                {
 77614                  "alg": "SHA-1",
 77615                  "content": "39050dbbd36862ea87eb9a64158854b04619ccd6"
 77616                }
 77617              ]
 77618            }
 77619          ],
 77620          "evidence": {},
 77621          "signature": {
 77622            "signature": {
 77623              "publicKey": {}
 77624            }
 77625          },
 77626          "modelCard": {
 77627            "modelParameters": {
 77628              "approach": {}
 77629            },
 77630            "quantitativeAnalysis": {
 77631              "graphics": {}
 77632            },
 77633            "considerations": {}
 77634          }
 77635        },
 77636        {
 77637          "type": "library",
 77638          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.3\u0026package-id=b805d823ae624f04",
 77639          "supplier": {},
 77640          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 77641          "name": "ca-certificates-bundle",
 77642          "version": "20220614-r4",
 77643          "description": "Pre generated bundle of Mozilla certificates",
 77644          "licenses": [
 77645            {
 77646              "license": {
 77647                "id": "MPL-2.0"
 77648              }
 77649            },
 77650            {
 77651              "license": {
 77652                "name": "AND"
 77653              }
 77654            },
 77655            {
 77656              "license": {
 77657                "id": "MIT"
 77658              }
 77659            }
 77660          ],
 77661          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r4:*:*:*:*:*:*:*",
 77662          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.3",
 77663          "swid": {
 77664            "attachment": {}
 77665          },
 77666          "pedigree": {},
 77667          "externalReferences": [
 77668            {
 77669              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
 77670              "type": "distribution"
 77671            }
 77672          ],
 77673          "evidence": {},
 77674          "signature": {
 77675            "signature": {
 77676              "publicKey": {}
 77677            }
 77678          },
 77679          "modelCard": {
 77680            "modelParameters": {
 77681              "approach": {}
 77682            },
 77683            "quantitativeAnalysis": {
 77684              "graphics": {}
 77685            },
 77686            "considerations": {}
 77687          }
 77688        },
 77689        {
 77690          "type": "library",
 77691          "bom-ref": "pkg:maven/org.cache2k/cache2k-api@1.2.1.Final?package-id=9828dfa75b8f6a49",
 77692          "supplier": {},
 77693          "group": "org.cache2k",
 77694          "name": "cache2k-api",
 77695          "version": "1.2.1.Final",
 77696          "cpe": "cpe:2.3:a:headissue-gmbh\\,-munich:cache2k-api:1.2.1.Final:*:*:*:*:*:*:*",
 77697          "purl": "pkg:maven/org.cache2k/cache2k-api@1.2.1.Final",
 77698          "swid": {
 77699            "attachment": {}
 77700          },
 77701          "pedigree": {},
 77702          "externalReferences": [
 77703            {
 77704              "type": "build-meta",
 77705              "hashes": [
 77706                {
 77707                  "alg": "SHA-1",
 77708                  "content": "9d11fefc7a357c91830bec9894fbc38af06edbe7"
 77709                }
 77710              ]
 77711            }
 77712          ],
 77713          "evidence": {},
 77714          "signature": {
 77715            "signature": {
 77716              "publicKey": {}
 77717            }
 77718          },
 77719          "modelCard": {
 77720            "modelParameters": {
 77721              "approach": {}
 77722            },
 77723            "quantitativeAnalysis": {
 77724              "graphics": {}
 77725            },
 77726            "considerations": {}
 77727          }
 77728        },
 77729        {
 77730          "type": "library",
 77731          "bom-ref": "pkg:maven/org.cache2k/cache2k-core@1.2.1.Final?package-id=371119275e0b3915",
 77732          "supplier": {},
 77733          "group": "org.cache2k",
 77734          "name": "cache2k-core",
 77735          "version": "1.2.1.Final",
 77736          "cpe": "cpe:2.3:a:headissue-gmbh\\,-munich:cache2k-core:1.2.1.Final:*:*:*:*:*:*:*",
 77737          "purl": "pkg:maven/org.cache2k/cache2k-core@1.2.1.Final",
 77738          "swid": {
 77739            "attachment": {}
 77740          },
 77741          "pedigree": {},
 77742          "externalReferences": [
 77743            {
 77744              "type": "build-meta",
 77745              "hashes": [
 77746                {
 77747                  "alg": "SHA-1",
 77748                  "content": "1b2c5304b1467c592c0242003a6d7d0e6751b874"
 77749                }
 77750              ]
 77751            }
 77752          ],
 77753          "evidence": {},
 77754          "signature": {
 77755            "signature": {
 77756              "publicKey": {}
 77757            }
 77758          },
 77759          "modelCard": {
 77760            "modelParameters": {
 77761              "approach": {}
 77762            },
 77763            "quantitativeAnalysis": {
 77764              "graphics": {}
 77765            },
 77766            "considerations": {}
 77767          }
 77768        },
 77769        {
 77770          "type": "library",
 77771          "bom-ref": "pkg:maven/org.cache2k/cache2k-spring@1.2.1.Final?package-id=5473dbdf6266f9b3",
 77772          "supplier": {},
 77773          "group": "org.cache2k",
 77774          "name": "cache2k-spring",
 77775          "version": "1.2.1.Final",
 77776          "cpe": "cpe:2.3:a:headissue-gmbh\\,-munich:cache2k-spring:1.2.1.Final:*:*:*:*:*:*:*",
 77777          "purl": "pkg:maven/org.cache2k/cache2k-spring@1.2.1.Final",
 77778          "swid": {
 77779            "attachment": {}
 77780          },
 77781          "pedigree": {},
 77782          "externalReferences": [
 77783            {
 77784              "type": "build-meta",
 77785              "hashes": [
 77786                {
 77787                  "alg": "SHA-1",
 77788                  "content": "8f9749f4b7b54c7f4e00e1ef58a834c64583b913"
 77789                }
 77790              ]
 77791            }
 77792          ],
 77793          "evidence": {},
 77794          "signature": {
 77795            "signature": {
 77796              "publicKey": {}
 77797            }
 77798          },
 77799          "modelCard": {
 77800            "modelParameters": {
 77801              "approach": {}
 77802            },
 77803            "quantitativeAnalysis": {
 77804              "graphics": {}
 77805            },
 77806            "considerations": {}
 77807          }
 77808        },
 77809        {
 77810          "type": "library",
 77811          "bom-ref": "pkg:maven/charsets/charsets?package-id=ac260baeda2f6c16",
 77812          "supplier": {},
 77813          "name": "charsets",
 77814          "cpe": "cpe:2.3:a:charsets:charsets:*:*:*:*:*:*:*:*",
 77815          "purl": "pkg:maven/charsets/charsets",
 77816          "swid": {
 77817            "attachment": {}
 77818          },
 77819          "pedigree": {},
 77820          "externalReferences": [
 77821            {
 77822              "type": "build-meta",
 77823              "hashes": [
 77824                {
 77825                  "alg": "SHA-1",
 77826                  "content": "141875c9bf4e34ae776a45505fc5365a5a1c8180"
 77827                }
 77828              ]
 77829            }
 77830          ],
 77831          "evidence": {},
 77832          "signature": {
 77833            "signature": {
 77834              "publicKey": {}
 77835            }
 77836          },
 77837          "modelCard": {
 77838            "modelParameters": {
 77839              "approach": {}
 77840            },
 77841            "quantitativeAnalysis": {
 77842              "graphics": {}
 77843            },
 77844            "considerations": {}
 77845          }
 77846        },
 77847        {
 77848          "type": "library",
 77849          "bom-ref": "pkg:maven/com.fasterxml/classmate@1.4.0?package-id=5f52335c23e8e55e",
 77850          "supplier": {},
 77851          "group": "com.fasterxml",
 77852          "name": "classmate",
 77853          "version": "1.4.0",
 77854          "licenses": [
 77855            {
 77856              "license": {
 77857                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 77858              }
 77859            }
 77860          ],
 77861          "cpe": "cpe:2.3:a:fasterxml-com:classmate:1.4.0:*:*:*:*:*:*:*",
 77862          "purl": "pkg:maven/com.fasterxml/classmate@1.4.0",
 77863          "swid": {
 77864            "attachment": {}
 77865          },
 77866          "pedigree": {},
 77867          "externalReferences": [
 77868            {
 77869              "type": "build-meta",
 77870              "hashes": [
 77871                {
 77872                  "alg": "SHA-1",
 77873                  "content": "291658ac2ce2476256c7115943652c0accb5c857"
 77874                }
 77875              ]
 77876            }
 77877          ],
 77878          "evidence": {},
 77879          "signature": {
 77880            "signature": {
 77881              "publicKey": {}
 77882            }
 77883          },
 77884          "modelCard": {
 77885            "modelParameters": {
 77886              "approach": {}
 77887            },
 77888            "quantitativeAnalysis": {
 77889              "graphics": {}
 77890            },
 77891            "considerations": {}
 77892          }
 77893        },
 77894        {
 77895          "type": "library",
 77896          "bom-ref": "pkg:maven/cldrdata/cldrdata?package-id=aaa36a6b8966b603",
 77897          "supplier": {},
 77898          "name": "cldrdata",
 77899          "cpe": "cpe:2.3:a:cldrdata:cldrdata:*:*:*:*:*:*:*:*",
 77900          "purl": "pkg:maven/cldrdata/cldrdata",
 77901          "swid": {
 77902            "attachment": {}
 77903          },
 77904          "pedigree": {},
 77905          "externalReferences": [
 77906            {
 77907              "type": "build-meta",
 77908              "hashes": [
 77909                {
 77910                  "alg": "SHA-1",
 77911                  "content": "040ba7365dc9db7c7b9a0fd786c6f180e61f62e3"
 77912                }
 77913              ]
 77914            }
 77915          ],
 77916          "evidence": {},
 77917          "signature": {
 77918            "signature": {
 77919              "publicKey": {}
 77920            }
 77921          },
 77922          "modelCard": {
 77923            "modelParameters": {
 77924              "approach": {}
 77925            },
 77926            "quantitativeAnalysis": {
 77927              "graphics": {}
 77928            },
 77929            "considerations": {}
 77930          }
 77931        },
 77932        {
 77933          "type": "library",
 77934          "bom-ref": "pkg:maven/com.mysema.codegen/codegen@0.6.8?package-id=b70cbe993954d6e3",
 77935          "supplier": {},
 77936          "group": "com.mysema.codegen",
 77937          "name": "codegen",
 77938          "version": "0.6.8",
 77939          "cpe": "cpe:2.3:a:codegen:codegen:0.6.8:*:*:*:*:*:*:*",
 77940          "purl": "pkg:maven/com.mysema.codegen/codegen@0.6.8",
 77941          "swid": {
 77942            "attachment": {}
 77943          },
 77944          "pedigree": {},
 77945          "externalReferences": [
 77946            {
 77947              "type": "build-meta",
 77948              "hashes": [
 77949                {
 77950                  "alg": "SHA-1",
 77951                  "content": "a94cea356af04d10e89f04f38ce746f1d5ac8359"
 77952                }
 77953              ]
 77954            }
 77955          ],
 77956          "evidence": {},
 77957          "signature": {
 77958            "signature": {
 77959              "publicKey": {}
 77960            }
 77961          },
 77962          "modelCard": {
 77963            "modelParameters": {
 77964              "approach": {}
 77965            },
 77966            "quantitativeAnalysis": {
 77967              "graphics": {}
 77968            },
 77969            "considerations": {}
 77970          }
 77971        },
 77972        {
 77973          "type": "library",
 77974          "bom-ref": "pkg:maven/commons-beanutils/commons-beanutils@1.9.3?package-id=26fd3e34e4b37111",
 77975          "supplier": {},
 77976          "group": "commons-beanutils",
 77977          "name": "commons-beanutils",
 77978          "version": "1.9.3",
 77979          "licenses": [
 77980            {
 77981              "license": {
 77982                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 77983              }
 77984            }
 77985          ],
 77986          "cpe": "cpe:2.3:a:apache:commons-beanutils:1.9.3:*:*:*:*:*:*:*",
 77987          "purl": "pkg:maven/commons-beanutils/commons-beanutils@1.9.3",
 77988          "swid": {
 77989            "attachment": {}
 77990          },
 77991          "pedigree": {},
 77992          "externalReferences": [
 77993            {
 77994              "type": "build-meta",
 77995              "hashes": [
 77996                {
 77997                  "alg": "SHA-1",
 77998                  "content": "c845703de334ddc6b4b3cd26835458cb1cba1f3d"
 77999                }
 78000              ]
 78001            }
 78002          ],
 78003          "evidence": {},
 78004          "signature": {
 78005            "signature": {
 78006              "publicKey": {}
 78007            }
 78008          },
 78009          "modelCard": {
 78010            "modelParameters": {
 78011              "approach": {}
 78012            },
 78013            "quantitativeAnalysis": {
 78014              "graphics": {}
 78015            },
 78016            "considerations": {}
 78017          }
 78018        },
 78019        {
 78020          "type": "library",
 78021          "bom-ref": "pkg:maven/commons-codec/commons-codec@1.11?package-id=17b50a69d5c58e38",
 78022          "supplier": {},
 78023          "group": "commons-codec",
 78024          "name": "commons-codec",
 78025          "version": "1.11",
 78026          "licenses": [
 78027            {
 78028              "license": {
 78029                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 78030              }
 78031            }
 78032          ],
 78033          "cpe": "cpe:2.3:a:apache:commons-codec:1.11:*:*:*:*:*:*:*",
 78034          "purl": "pkg:maven/commons-codec/commons-codec@1.11",
 78035          "swid": {
 78036            "attachment": {}
 78037          },
 78038          "pedigree": {},
 78039          "externalReferences": [
 78040            {
 78041              "type": "build-meta",
 78042              "hashes": [
 78043                {
 78044                  "alg": "SHA-1",
 78045                  "content": "3acb4705652e16236558f0f4f2192cc33c3bd189"
 78046                }
 78047              ]
 78048            }
 78049          ],
 78050          "evidence": {},
 78051          "signature": {
 78052            "signature": {
 78053              "publicKey": {}
 78054            }
 78055          },
 78056          "modelCard": {
 78057            "modelParameters": {
 78058              "approach": {}
 78059            },
 78060            "quantitativeAnalysis": {
 78061              "graphics": {}
 78062            },
 78063            "considerations": {}
 78064          }
 78065        },
 78066        {
 78067          "type": "library",
 78068          "bom-ref": "pkg:maven/org.apache.commons/commons-collections4@4.2?package-id=2abcb73b5d293b8",
 78069          "supplier": {},
 78070          "group": "org.apache.commons",
 78071          "name": "commons-collections4",
 78072          "version": "4.2",
 78073          "licenses": [
 78074            {
 78075              "license": {
 78076                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 78077              }
 78078            }
 78079          ],
 78080          "cpe": "cpe:2.3:a:apache:commons-collections4:4.2:*:*:*:*:*:*:*",
 78081          "purl": "pkg:maven/org.apache.commons/commons-collections4@4.2",
 78082          "swid": {
 78083            "attachment": {}
 78084          },
 78085          "pedigree": {},
 78086          "externalReferences": [
 78087            {
 78088              "type": "build-meta",
 78089              "hashes": [
 78090                {
 78091                  "alg": "SHA-1",
 78092                  "content": "54ebea0a5b653d3c680131e73fe807bb8f78c4ed"
 78093                }
 78094              ]
 78095            }
 78096          ],
 78097          "evidence": {},
 78098          "signature": {
 78099            "signature": {
 78100              "publicKey": {}
 78101            }
 78102          },
 78103          "modelCard": {
 78104            "modelParameters": {
 78105              "approach": {}
 78106            },
 78107            "quantitativeAnalysis": {
 78108              "graphics": {}
 78109            },
 78110            "considerations": {}
 78111          }
 78112        },
 78113        {
 78114          "type": "library",
 78115          "bom-ref": "pkg:maven/org.apache.commons/commons-compress@1.20?package-id=be3ee49b810912f0",
 78116          "supplier": {},
 78117          "group": "org.apache.commons",
 78118          "name": "commons-compress",
 78119          "version": "1.20",
 78120          "licenses": [
 78121            {
 78122              "license": {
 78123                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 78124              }
 78125            }
 78126          ],
 78127          "cpe": "cpe:2.3:a:apache:commons-compress:1.20:*:*:*:*:*:*:*",
 78128          "purl": "pkg:maven/org.apache.commons/commons-compress@1.20",
 78129          "swid": {
 78130            "attachment": {}
 78131          },
 78132          "pedigree": {},
 78133          "externalReferences": [
 78134            {
 78135              "type": "build-meta",
 78136              "hashes": [
 78137                {
 78138                  "alg": "SHA-1",
 78139                  "content": "b8df472b31e1f17c232d2ad78ceb1c84e00c641b"
 78140                }
 78141              ]
 78142            }
 78143          ],
 78144          "evidence": {},
 78145          "signature": {
 78146            "signature": {
 78147              "publicKey": {}
 78148            }
 78149          },
 78150          "modelCard": {
 78151            "modelParameters": {
 78152              "approach": {}
 78153            },
 78154            "quantitativeAnalysis": {
 78155              "graphics": {}
 78156            },
 78157            "considerations": {}
 78158          }
 78159        },
 78160        {
 78161          "type": "library",
 78162          "bom-ref": "pkg:maven/org.apache/commons-httpclient@3.1?package-id=be8e2d4fb76bbbcf",
 78163          "supplier": {},
 78164          "name": "commons-httpclient",
 78165          "version": "3.1",
 78166          "cpe": "cpe:2.3:a:apache:commons-httpclient:3.1:*:*:*:*:*:*:*",
 78167          "purl": "pkg:maven/org.apache/commons-httpclient@3.1",
 78168          "swid": {
 78169            "attachment": {}
 78170          },
 78171          "pedigree": {},
 78172          "externalReferences": [
 78173            {
 78174              "type": "build-meta",
 78175              "hashes": [
 78176                {
 78177                  "alg": "SHA-1",
 78178                  "content": "964cd74171f427720480efdec40a7c7f6e58426a"
 78179                }
 78180              ]
 78181            }
 78182          ],
 78183          "evidence": {},
 78184          "signature": {
 78185            "signature": {
 78186              "publicKey": {}
 78187            }
 78188          },
 78189          "modelCard": {
 78190            "modelParameters": {
 78191              "approach": {}
 78192            },
 78193            "quantitativeAnalysis": {
 78194              "graphics": {}
 78195            },
 78196            "considerations": {}
 78197          }
 78198        },
 78199        {
 78200          "type": "library",
 78201          "bom-ref": "pkg:maven/commons-io/commons-io@2.5?package-id=9e405ca97dd23de8",
 78202          "supplier": {},
 78203          "group": "commons-io",
 78204          "name": "commons-io",
 78205          "version": "2.5",
 78206          "cpe": "cpe:2.3:a:apache:commons-io:2.5:*:*:*:*:*:*:*",
 78207          "purl": "pkg:maven/commons-io/commons-io@2.5",
 78208          "swid": {
 78209            "attachment": {}
 78210          },
 78211          "pedigree": {},
 78212          "evidence": {},
 78213          "signature": {
 78214            "signature": {
 78215              "publicKey": {}
 78216            }
 78217          },
 78218          "modelCard": {
 78219            "modelParameters": {
 78220              "approach": {}
 78221            },
 78222            "quantitativeAnalysis": {
 78223              "graphics": {}
 78224            },
 78225            "considerations": {}
 78226          }
 78227        },
 78228        {
 78229          "type": "library",
 78230          "bom-ref": "pkg:maven/commons-io/commons-io@2.6?package-id=b9ec56511a393978",
 78231          "supplier": {},
 78232          "group": "commons-io",
 78233          "name": "commons-io",
 78234          "version": "2.6",
 78235          "licenses": [
 78236            {
 78237              "license": {
 78238                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 78239              }
 78240            }
 78241          ],
 78242          "cpe": "cpe:2.3:a:apache:commons-io:2.6:*:*:*:*:*:*:*",
 78243          "purl": "pkg:maven/commons-io/commons-io@2.6",
 78244          "swid": {
 78245            "attachment": {}
 78246          },
 78247          "pedigree": {},
 78248          "externalReferences": [
 78249            {
 78250              "type": "build-meta",
 78251              "hashes": [
 78252                {
 78253                  "alg": "SHA-1",
 78254                  "content": "815893df5f31da2ece4040fe0a12fd44b577afaf"
 78255                }
 78256              ]
 78257            }
 78258          ],
 78259          "evidence": {},
 78260          "signature": {
 78261            "signature": {
 78262              "publicKey": {}
 78263            }
 78264          },
 78265          "modelCard": {
 78266            "modelParameters": {
 78267              "approach": {}
 78268            },
 78269            "quantitativeAnalysis": {
 78270              "graphics": {}
 78271            },
 78272            "considerations": {}
 78273          }
 78274        },
 78275        {
 78276          "type": "library",
 78277          "bom-ref": "pkg:maven/commons-lang/commons-lang@2.6?package-id=dc522c721e0b1b30",
 78278          "supplier": {},
 78279          "group": "commons-lang",
 78280          "name": "commons-lang",
 78281          "version": "2.6",
 78282          "licenses": [
 78283            {
 78284              "license": {
 78285                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 78286              }
 78287            }
 78288          ],
 78289          "cpe": "cpe:2.3:a:apache:commons-lang:2.6:*:*:*:*:*:*:*",
 78290          "purl": "pkg:maven/commons-lang/commons-lang@2.6",
 78291          "swid": {
 78292            "attachment": {}
 78293          },
 78294          "pedigree": {},
 78295          "externalReferences": [
 78296            {
 78297              "type": "build-meta",
 78298              "hashes": [
 78299                {
 78300                  "alg": "SHA-1",
 78301                  "content": "0ce1edb914c94ebc388f086c6827e8bdeec71ac2"
 78302                }
 78303              ]
 78304            }
 78305          ],
 78306          "evidence": {},
 78307          "signature": {
 78308            "signature": {
 78309              "publicKey": {}
 78310            }
 78311          },
 78312          "modelCard": {
 78313            "modelParameters": {
 78314              "approach": {}
 78315            },
 78316            "quantitativeAnalysis": {
 78317              "graphics": {}
 78318            },
 78319            "considerations": {}
 78320          }
 78321        },
 78322        {
 78323          "type": "library",
 78324          "bom-ref": "pkg:maven/org.apache.commons/commons-lang3@3.7?package-id=9cda9deeea99d491",
 78325          "supplier": {},
 78326          "group": "org.apache.commons",
 78327          "name": "commons-lang3",
 78328          "version": "3.7",
 78329          "licenses": [
 78330            {
 78331              "license": {
 78332                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 78333              }
 78334            }
 78335          ],
 78336          "cpe": "cpe:2.3:a:apache:commons-lang3:3.7:*:*:*:*:*:*:*",
 78337          "purl": "pkg:maven/org.apache.commons/commons-lang3@3.7",
 78338          "swid": {
 78339            "attachment": {}
 78340          },
 78341          "pedigree": {},
 78342          "externalReferences": [
 78343            {
 78344              "type": "build-meta",
 78345              "hashes": [
 78346                {
 78347                  "alg": "SHA-1",
 78348                  "content": "557edd918fd41f9260963583ebf5a61a43a6b423"
 78349                }
 78350              ]
 78351            }
 78352          ],
 78353          "evidence": {},
 78354          "signature": {
 78355            "signature": {
 78356              "publicKey": {}
 78357            }
 78358          },
 78359          "modelCard": {
 78360            "modelParameters": {
 78361              "approach": {}
 78362            },
 78363            "quantitativeAnalysis": {
 78364              "graphics": {}
 78365            },
 78366            "considerations": {}
 78367          }
 78368        },
 78369        {
 78370          "type": "library",
 78371          "bom-ref": "pkg:maven/commons-logging/commons-logging@1.2?package-id=f42504d9b121ac04",
 78372          "supplier": {},
 78373          "group": "commons-logging",
 78374          "name": "commons-logging",
 78375          "version": "1.2",
 78376          "licenses": [
 78377            {
 78378              "license": {
 78379                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 78380              }
 78381            }
 78382          ],
 78383          "cpe": "cpe:2.3:a:apache:commons-logging:1.2:*:*:*:*:*:*:*",
 78384          "purl": "pkg:maven/commons-logging/commons-logging@1.2",
 78385          "swid": {
 78386            "attachment": {}
 78387          },
 78388          "pedigree": {},
 78389          "externalReferences": [
 78390            {
 78391              "type": "build-meta",
 78392              "hashes": [
 78393                {
 78394                  "alg": "SHA-1",
 78395                  "content": "4bfc12adfe4842bf07b657f0369c4cb522955686"
 78396                }
 78397              ]
 78398            }
 78399          ],
 78400          "evidence": {},
 78401          "signature": {
 78402            "signature": {
 78403              "publicKey": {}
 78404            }
 78405          },
 78406          "modelCard": {
 78407            "modelParameters": {
 78408              "approach": {}
 78409            },
 78410            "quantitativeAnalysis": {
 78411              "graphics": {}
 78412            },
 78413            "considerations": {}
 78414          }
 78415        },
 78416        {
 78417          "type": "library",
 78418          "bom-ref": "pkg:maven/org.apache.commons/commons-text@1.9?package-id=96f01ea672809cd",
 78419          "supplier": {},
 78420          "group": "org.apache.commons",
 78421          "name": "commons-text",
 78422          "version": "1.9",
 78423          "licenses": [
 78424            {
 78425              "license": {
 78426                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 78427              }
 78428            }
 78429          ],
 78430          "cpe": "cpe:2.3:a:apache:commons-text:1.9:*:*:*:*:*:*:*",
 78431          "purl": "pkg:maven/org.apache.commons/commons-text@1.9",
 78432          "swid": {
 78433            "attachment": {}
 78434          },
 78435          "pedigree": {},
 78436          "externalReferences": [
 78437            {
 78438              "type": "build-meta",
 78439              "hashes": [
 78440                {
 78441                  "alg": "SHA-1",
 78442                  "content": "ba6ac8c2807490944a0a27f6f8e68fb5ed2e80e2"
 78443                }
 78444              ]
 78445            }
 78446          ],
 78447          "evidence": {},
 78448          "signature": {
 78449            "signature": {
 78450              "publicKey": {}
 78451            }
 78452          },
 78453          "modelCard": {
 78454            "modelParameters": {
 78455              "approach": {}
 78456            },
 78457            "quantitativeAnalysis": {
 78458              "graphics": {}
 78459            },
 78460            "considerations": {}
 78461          }
 78462        },
 78463        {
 78464          "type": "library",
 78465          "bom-ref": "pkg:maven/com.squareup.retrofit2/converter-moshi@2.6.2?package-id=cc66af638a6cff9f",
 78466          "supplier": {},
 78467          "group": "com.squareup.retrofit2",
 78468          "name": "converter-moshi",
 78469          "version": "2.6.2",
 78470          "cpe": "cpe:2.3:a:converter-moshi:converter-moshi:2.6.2:*:*:*:*:*:*:*",
 78471          "purl": "pkg:maven/com.squareup.retrofit2/converter-moshi@2.6.2",
 78472          "swid": {
 78473            "attachment": {}
 78474          },
 78475          "pedigree": {},
 78476          "externalReferences": [
 78477            {
 78478              "type": "build-meta",
 78479              "hashes": [
 78480                {
 78481                  "alg": "SHA-1",
 78482                  "content": "c365cc8246059e866eb42862240fc8c03bd15076"
 78483                }
 78484              ]
 78485            }
 78486          ],
 78487          "evidence": {},
 78488          "signature": {
 78489            "signature": {
 78490              "publicKey": {}
 78491            }
 78492          },
 78493          "modelCard": {
 78494            "modelParameters": {
 78495              "approach": {}
 78496            },
 78497            "quantitativeAnalysis": {
 78498              "graphics": {}
 78499            },
 78500            "considerations": {}
 78501          }
 78502        },
 78503        {
 78504          "type": "library",
 78505          "bom-ref": "pkg:maven/dnsns/dnsns?package-id=af09d0f9bd2e5151",
 78506          "supplier": {},
 78507          "name": "dnsns",
 78508          "cpe": "cpe:2.3:a:dnsns:dnsns:*:*:*:*:*:*:*:*",
 78509          "purl": "pkg:maven/dnsns/dnsns",
 78510          "swid": {
 78511            "attachment": {}
 78512          },
 78513          "pedigree": {},
 78514          "externalReferences": [
 78515            {
 78516              "type": "build-meta",
 78517              "hashes": [
 78518                {
 78519                  "alg": "SHA-1",
 78520                  "content": "3c80b6ce7bfb62d34251421d73d7afb67f06b1e8"
 78521                }
 78522              ]
 78523            }
 78524          ],
 78525          "evidence": {},
 78526          "signature": {
 78527            "signature": {
 78528              "publicKey": {}
 78529            }
 78530          },
 78531          "modelCard": {
 78532            "modelParameters": {
 78533              "approach": {}
 78534            },
 78535            "quantitativeAnalysis": {
 78536              "graphics": {}
 78537            },
 78538            "considerations": {}
 78539          }
 78540        },
 78541        {
 78542          "type": "library",
 78543          "bom-ref": "pkg:maven/dom4j/dom4j@2.1.1?package-id=743d5798a1d52607",
 78544          "supplier": {},
 78545          "name": "dom4j",
 78546          "version": "2.1.1",
 78547          "cpe": "cpe:2.3:a:dom4j:dom4j:2.1.1:*:*:*:*:*:*:*",
 78548          "purl": "pkg:maven/dom4j/dom4j@2.1.1",
 78549          "swid": {
 78550            "attachment": {}
 78551          },
 78552          "pedigree": {},
 78553          "externalReferences": [
 78554            {
 78555              "type": "build-meta",
 78556              "hashes": [
 78557                {
 78558                  "alg": "SHA-1",
 78559                  "content": "3dce5dbb3571aa820c677fadd8349bfa8f00c199"
 78560                }
 78561              ]
 78562            }
 78563          ],
 78564          "evidence": {},
 78565          "signature": {
 78566            "signature": {
 78567              "publicKey": {}
 78568            }
 78569          },
 78570          "modelCard": {
 78571            "modelParameters": {
 78572              "approach": {}
 78573            },
 78574            "quantitativeAnalysis": {
 78575              "graphics": {}
 78576            },
 78577            "considerations": {}
 78578          }
 78579        },
 78580        {
 78581          "type": "library",
 78582          "bom-ref": "pkg:maven/org.eclipse.jdt.core.compiler.batch/ecj@4.3.1?package-id=46a6cd894b50be50",
 78583          "supplier": {},
 78584          "name": "ecj",
 78585          "version": "4.3.1",
 78586          "cpe": "cpe:2.3:a:compiler:compiler:4.3.1:*:*:*:*:*:*:*",
 78587          "purl": "pkg:maven/org.eclipse.jdt.core.compiler.batch/ecj@4.3.1",
 78588          "swid": {
 78589            "attachment": {}
 78590          },
 78591          "pedigree": {},
 78592          "externalReferences": [
 78593            {
 78594              "type": "build-meta",
 78595              "hashes": [
 78596                {
 78597                  "alg": "SHA-1",
 78598                  "content": "21582b0e662b9e54fc6f0f2721d36f753ce7c58c"
 78599                }
 78600              ]
 78601            }
 78602          ],
 78603          "evidence": {},
 78604          "signature": {
 78605            "signature": {
 78606              "publicKey": {}
 78607            }
 78608          },
 78609          "modelCard": {
 78610            "modelParameters": {
 78611              "approach": {}
 78612            },
 78613            "quantitativeAnalysis": {
 78614              "graphics": {}
 78615            },
 78616            "considerations": {}
 78617          }
 78618        },
 78619        {
 78620          "type": "library",
 78621          "bom-ref": "pkg:maven/net.i2p.crypto/eddsa@0.3.0?package-id=3b4ef3ea92c0b16a",
 78622          "supplier": {},
 78623          "group": "net.i2p.crypto",
 78624          "name": "eddsa",
 78625          "version": "0.3.0",
 78626          "licenses": [
 78627            {
 78628              "license": {
 78629                "name": "https://creativecommons.org/publicdomain/zero/1.0/"
 78630              }
 78631            }
 78632          ],
 78633          "cpe": "cpe:2.3:a:crypto:eddsa:0.3.0:*:*:*:*:*:*:*",
 78634          "purl": "pkg:maven/net.i2p.crypto/eddsa@0.3.0",
 78635          "swid": {
 78636            "attachment": {}
 78637          },
 78638          "pedigree": {},
 78639          "externalReferences": [
 78640            {
 78641              "type": "build-meta",
 78642              "hashes": [
 78643                {
 78644                  "alg": "SHA-1",
 78645                  "content": "1901c8d4d8bffb7d79027686cfb91e704217c3e1"
 78646                }
 78647              ]
 78648            }
 78649          ],
 78650          "evidence": {},
 78651          "signature": {
 78652            "signature": {
 78653              "publicKey": {}
 78654            }
 78655          },
 78656          "modelCard": {
 78657            "modelParameters": {
 78658              "approach": {}
 78659            },
 78660            "quantitativeAnalysis": {
 78661              "graphics": {}
 78662            },
 78663            "considerations": {}
 78664          }
 78665        },
 78666        {
 78667          "type": "library",
 78668          "bom-ref": "pkg:apk/alpine/encodings@1.0.6-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=27e4d13f9a311e67",
 78669          "supplier": {},
 78670          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 78671          "name": "encodings",
 78672          "version": "1.0.6-r0",
 78673          "description": "X.org font encoding files",
 78674          "licenses": [
 78675            {
 78676              "license": {
 78677                "name": "custom"
 78678              }
 78679            }
 78680          ],
 78681          "cpe": "cpe:2.3:a:encodings:encodings:1.0.6-r0:*:*:*:*:*:*:*",
 78682          "purl": "pkg:apk/alpine/encodings@1.0.6-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 78683          "swid": {
 78684            "attachment": {}
 78685          },
 78686          "pedigree": {},
 78687          "externalReferences": [
 78688            {
 78689              "url": "http://xorg.freedesktop.org/",
 78690              "type": "distribution"
 78691            }
 78692          ],
 78693          "evidence": {},
 78694          "signature": {
 78695            "signature": {
 78696              "publicKey": {}
 78697            }
 78698          },
 78699          "modelCard": {
 78700            "modelParameters": {
 78701              "approach": {}
 78702            },
 78703            "quantitativeAnalysis": {
 78704              "graphics": {}
 78705            },
 78706            "considerations": {}
 78707          }
 78708        },
 78709        {
 78710          "type": "library",
 78711          "bom-ref": "pkg:maven/org.owasp.esapi/esapi@2.2.0.0?package-id=98db94ee0639931f",
 78712          "supplier": {},
 78713          "group": "org.owasp.esapi",
 78714          "name": "esapi",
 78715          "version": "2.2.0.0",
 78716          "cpe": "cpe:2.3:a:open-web-application-security-project-\\(owasp\\):esapi:2.2.0.0:*:*:*:*:*:*:*",
 78717          "purl": "pkg:maven/org.owasp.esapi/esapi@2.2.0.0",
 78718          "swid": {
 78719            "attachment": {}
 78720          },
 78721          "pedigree": {},
 78722          "externalReferences": [
 78723            {
 78724              "type": "build-meta",
 78725              "hashes": [
 78726                {
 78727                  "alg": "SHA-1",
 78728                  "content": "721cbbf80e2bf1cc3d87d4a791e4c7bc827fca95"
 78729                }
 78730              ]
 78731            }
 78732          ],
 78733          "evidence": {},
 78734          "signature": {
 78735            "signature": {
 78736              "publicKey": {}
 78737            }
 78738          },
 78739          "modelCard": {
 78740            "modelParameters": {
 78741              "approach": {}
 78742            },
 78743            "quantitativeAnalysis": {
 78744              "graphics": {}
 78745            },
 78746            "considerations": {}
 78747          }
 78748        },
 78749        {
 78750          "type": "library",
 78751          "bom-ref": "pkg:apk/alpine/font-dejavu@2.37-r3?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=dcec74118c4e82d9",
 78752          "supplier": {},
 78753          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 78754          "name": "font-dejavu",
 78755          "version": "2.37-r3",
 78756          "description": "Font family based on the Bitstream Vera Fonts with a wider range of characters",
 78757          "licenses": [
 78758            {
 78759              "license": {
 78760                "name": "custom"
 78761              }
 78762            }
 78763          ],
 78764          "cpe": "cpe:2.3:a:font-dejavu:font-dejavu:2.37-r3:*:*:*:*:*:*:*",
 78765          "purl": "pkg:apk/alpine/font-dejavu@2.37-r3?arch=x86_64\u0026distro=alpine-3.17.3",
 78766          "swid": {
 78767            "attachment": {}
 78768          },
 78769          "pedigree": {},
 78770          "externalReferences": [
 78771            {
 78772              "url": "https://dejavu-fonts.github.io/",
 78773              "type": "distribution"
 78774            }
 78775          ],
 78776          "evidence": {},
 78777          "signature": {
 78778            "signature": {
 78779              "publicKey": {}
 78780            }
 78781          },
 78782          "modelCard": {
 78783            "modelParameters": {
 78784              "approach": {}
 78785            },
 78786            "quantitativeAnalysis": {
 78787              "graphics": {}
 78788            },
 78789            "considerations": {}
 78790          }
 78791        },
 78792        {
 78793          "type": "library",
 78794          "bom-ref": "pkg:apk/alpine/fontconfig@2.14.1-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=adae4094ba998368",
 78795          "supplier": {},
 78796          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 78797          "name": "fontconfig",
 78798          "version": "2.14.1-r0",
 78799          "description": "Library for configuring and customizing font access",
 78800          "licenses": [
 78801            {
 78802              "license": {
 78803                "id": "MIT"
 78804              }
 78805            }
 78806          ],
 78807          "cpe": "cpe:2.3:a:fontconfig:fontconfig:2.14.1-r0:*:*:*:*:*:*:*",
 78808          "purl": "pkg:apk/alpine/fontconfig@2.14.1-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 78809          "swid": {
 78810            "attachment": {}
 78811          },
 78812          "pedigree": {},
 78813          "externalReferences": [
 78814            {
 78815              "url": "https://www.freedesktop.org/wiki/Software/fontconfig",
 78816              "type": "distribution"
 78817            }
 78818          ],
 78819          "evidence": {},
 78820          "signature": {
 78821            "signature": {
 78822              "publicKey": {}
 78823            }
 78824          },
 78825          "modelCard": {
 78826            "modelParameters": {
 78827              "approach": {}
 78828            },
 78829            "quantitativeAnalysis": {
 78830              "graphics": {}
 78831            },
 78832            "considerations": {}
 78833          }
 78834        },
 78835        {
 78836          "type": "library",
 78837          "bom-ref": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2b1bfc10343b9080",
 78838          "supplier": {},
 78839          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 78840          "name": "freetype",
 78841          "version": "2.12.1-r0",
 78842          "description": "TrueType font rendering library",
 78843          "licenses": [
 78844            {
 78845              "license": {
 78846                "id": "FTL"
 78847              }
 78848            },
 78849            {
 78850              "license": {
 78851                "id": "GPL-2.0-or-later"
 78852              }
 78853            }
 78854          ],
 78855          "cpe": "cpe:2.3:a:freetype:freetype:2.12.1-r0:*:*:*:*:*:*:*",
 78856          "purl": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 78857          "swid": {
 78858            "attachment": {}
 78859          },
 78860          "pedigree": {},
 78861          "externalReferences": [
 78862            {
 78863              "url": "https://www.freetype.org/",
 78864              "type": "distribution"
 78865            }
 78866          ],
 78867          "evidence": {},
 78868          "signature": {
 78869            "signature": {
 78870              "publicKey": {}
 78871            }
 78872          },
 78873          "modelCard": {
 78874            "modelParameters": {
 78875              "approach": {}
 78876            },
 78877            "quantitativeAnalysis": {
 78878              "graphics": {}
 78879            },
 78880            "considerations": {}
 78881          }
 78882        },
 78883        {
 78884          "type": "library",
 78885          "bom-ref": "pkg:maven/com.google.http-client.google-http-client/google-http-client@1.24.1?package-id=45483e18f68f3115",
 78886          "supplier": {},
 78887          "name": "google-http-client",
 78888          "version": "1.24.1",
 78889          "licenses": [
 78890            {
 78891              "license": {
 78892                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 78893              }
 78894            }
 78895          ],
 78896          "cpe": "cpe:2.3:a:google-http-client:google-http-client:1.24.1:*:*:*:*:*:*:*",
 78897          "purl": "pkg:maven/com.google.http-client.google-http-client/google-http-client@1.24.1",
 78898          "swid": {
 78899            "attachment": {}
 78900          },
 78901          "pedigree": {},
 78902          "externalReferences": [
 78903            {
 78904              "type": "build-meta",
 78905              "hashes": [
 78906                {
 78907                  "alg": "SHA-1",
 78908                  "content": "396eac8d3fb1332675f82b208f48a469d64f3b4a"
 78909                }
 78910              ]
 78911            }
 78912          ],
 78913          "evidence": {},
 78914          "signature": {
 78915            "signature": {
 78916              "publicKey": {}
 78917            }
 78918          },
 78919          "modelCard": {
 78920            "modelParameters": {
 78921              "approach": {}
 78922            },
 78923            "quantitativeAnalysis": {
 78924              "graphics": {}
 78925            },
 78926            "considerations": {}
 78927          }
 78928        },
 78929        {
 78930          "type": "library",
 78931          "bom-ref": "pkg:maven/com.google.http-client/google-http-client-xml@1.24.1?package-id=96fa27fc1ea5dae9",
 78932          "supplier": {},
 78933          "name": "google-http-client-xml",
 78934          "version": "1.24.1",
 78935          "cpe": "cpe:2.3:a:google-http-client-xml:google-http-client-xml:1.24.1:*:*:*:*:*:*:*",
 78936          "purl": "pkg:maven/com.google.http-client/google-http-client-xml@1.24.1",
 78937          "swid": {
 78938            "attachment": {}
 78939          },
 78940          "pedigree": {},
 78941          "externalReferences": [
 78942            {
 78943              "type": "build-meta",
 78944              "hashes": [
 78945                {
 78946                  "alg": "SHA-1",
 78947                  "content": "c7c75f64a2ea224c947e5f447f7c75a43060ee2d"
 78948                }
 78949              ]
 78950            }
 78951          ],
 78952          "evidence": {},
 78953          "signature": {
 78954            "signature": {
 78955              "publicKey": {}
 78956            }
 78957          },
 78958          "modelCard": {
 78959            "modelParameters": {
 78960              "approach": {}
 78961            },
 78962            "quantitativeAnalysis": {
 78963              "graphics": {}
 78964            },
 78965            "considerations": {}
 78966          }
 78967        },
 78968        {
 78969          "type": "library",
 78970          "bom-ref": "pkg:maven/com.google.guava/guava@20.0?package-id=f9ee9d60dcaeccfd",
 78971          "supplier": {},
 78972          "group": "com.google.guava",
 78973          "name": "guava",
 78974          "version": "20.0",
 78975          "licenses": [
 78976            {
 78977              "license": {
 78978                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 78979              }
 78980            }
 78981          ],
 78982          "cpe": "cpe:2.3:a:google:guava:20.0:*:*:*:*:*:*:*",
 78983          "purl": "pkg:maven/com.google.guava/guava@20.0",
 78984          "swid": {
 78985            "attachment": {}
 78986          },
 78987          "pedigree": {},
 78988          "externalReferences": [
 78989            {
 78990              "type": "build-meta",
 78991              "hashes": [
 78992                {
 78993                  "alg": "SHA-1",
 78994                  "content": "89507701249388e1ed5ddcf8c41f4ce1be7831ef"
 78995                }
 78996              ]
 78997            }
 78998          ],
 78999          "evidence": {},
 79000          "signature": {
 79001            "signature": {
 79002              "publicKey": {}
 79003            }
 79004          },
 79005          "modelCard": {
 79006            "modelParameters": {
 79007              "approach": {}
 79008            },
 79009            "quantitativeAnalysis": {
 79010              "graphics": {}
 79011            },
 79012            "considerations": {}
 79013          }
 79014        },
 79015        {
 79016          "type": "library",
 79017          "bom-ref": "pkg:maven/org.hibernate.common.hibernate-commons-annotations/hibernate-commons-annotations@5.0.4.Final?package-id=8874a1fcf7910a0a",
 79018          "supplier": {},
 79019          "name": "hibernate-commons-annotations",
 79020          "version": "5.0.4.Final",
 79021          "cpe": "cpe:2.3:a:hibernate-commons-annotations:hibernate-commons-annotations:5.0.4.Final:*:*:*:*:*:*:*",
 79022          "purl": "pkg:maven/org.hibernate.common.hibernate-commons-annotations/hibernate-commons-annotations@5.0.4.Final",
 79023          "swid": {
 79024            "attachment": {}
 79025          },
 79026          "pedigree": {},
 79027          "externalReferences": [
 79028            {
 79029              "type": "build-meta",
 79030              "hashes": [
 79031                {
 79032                  "alg": "SHA-1",
 79033                  "content": "965a18fdf939ee75e41f7918532d37b3a8350535"
 79034                }
 79035              ]
 79036            }
 79037          ],
 79038          "evidence": {},
 79039          "signature": {
 79040            "signature": {
 79041              "publicKey": {}
 79042            }
 79043          },
 79044          "modelCard": {
 79045            "modelParameters": {
 79046              "approach": {}
 79047            },
 79048            "quantitativeAnalysis": {
 79049              "graphics": {}
 79050            },
 79051            "considerations": {}
 79052          }
 79053        },
 79054        {
 79055          "type": "library",
 79056          "bom-ref": "pkg:maven/org.hibernate.orm.core/hibernate-core@5.3.10.Final?package-id=76fb19d442aabaf7",
 79057          "supplier": {},
 79058          "name": "hibernate-core",
 79059          "version": "5.3.10.Final",
 79060          "cpe": "cpe:2.3:a:hibernate-core:hibernate-core:5.3.10.Final:*:*:*:*:*:*:*",
 79061          "purl": "pkg:maven/org.hibernate.orm.core/hibernate-core@5.3.10.Final",
 79062          "swid": {
 79063            "attachment": {}
 79064          },
 79065          "pedigree": {},
 79066          "externalReferences": [
 79067            {
 79068              "type": "build-meta",
 79069              "hashes": [
 79070                {
 79071                  "alg": "SHA-1",
 79072                  "content": "e608b854325005edbf43cb2b6041fdafd3f2eb57"
 79073                }
 79074              ]
 79075            }
 79076          ],
 79077          "evidence": {},
 79078          "signature": {
 79079            "signature": {
 79080              "publicKey": {}
 79081            }
 79082          },
 79083          "modelCard": {
 79084            "modelParameters": {
 79085              "approach": {}
 79086            },
 79087            "quantitativeAnalysis": {
 79088              "graphics": {}
 79089            },
 79090            "considerations": {}
 79091          }
 79092        },
 79093        {
 79094          "type": "library",
 79095          "bom-ref": "pkg:maven/org.hibernate.orm.envers/hibernate-envers@5.3.10.Final?package-id=c7e65c6a06724e7b",
 79096          "supplier": {},
 79097          "name": "hibernate-envers",
 79098          "version": "5.3.10.Final",
 79099          "cpe": "cpe:2.3:a:hibernate-envers:hibernate-envers:5.3.10.Final:*:*:*:*:*:*:*",
 79100          "purl": "pkg:maven/org.hibernate.orm.envers/hibernate-envers@5.3.10.Final",
 79101          "swid": {
 79102            "attachment": {}
 79103          },
 79104          "pedigree": {},
 79105          "externalReferences": [
 79106            {
 79107              "type": "build-meta",
 79108              "hashes": [
 79109                {
 79110                  "alg": "SHA-1",
 79111                  "content": "33d0e999e7be1ca503719a6243107b090b6cbae7"
 79112                }
 79113              ]
 79114            }
 79115          ],
 79116          "evidence": {},
 79117          "signature": {
 79118            "signature": {
 79119              "publicKey": {}
 79120            }
 79121          },
 79122          "modelCard": {
 79123            "modelParameters": {
 79124              "approach": {}
 79125            },
 79126            "quantitativeAnalysis": {
 79127              "graphics": {}
 79128            },
 79129            "considerations": {}
 79130          }
 79131        },
 79132        {
 79133          "type": "library",
 79134          "bom-ref": "pkg:maven/org.hibernate.validator/hibernate-validator@6.0.16.Final?package-id=ebb3a7984b2ff463",
 79135          "supplier": {},
 79136          "group": "org.hibernate.validator",
 79137          "name": "hibernate-validator",
 79138          "version": "6.0.16.Final",
 79139          "licenses": [
 79140            {
 79141              "license": {
 79142                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 79143              }
 79144            }
 79145          ],
 79146          "cpe": "cpe:2.3:a:hibernate-validator:hibernate-validator:6.0.16.Final:*:*:*:*:*:*:*",
 79147          "purl": "pkg:maven/org.hibernate.validator/hibernate-validator@6.0.16.Final",
 79148          "swid": {
 79149            "attachment": {}
 79150          },
 79151          "pedigree": {},
 79152          "externalReferences": [
 79153            {
 79154              "type": "build-meta",
 79155              "hashes": [
 79156                {
 79157                  "alg": "SHA-1",
 79158                  "content": "ad9557c558972093c0567a2a1f224f318c00f650"
 79159                }
 79160              ]
 79161            }
 79162          ],
 79163          "evidence": {},
 79164          "signature": {
 79165            "signature": {
 79166              "publicKey": {}
 79167            }
 79168          },
 79169          "modelCard": {
 79170            "modelParameters": {
 79171              "approach": {}
 79172            },
 79173            "quantitativeAnalysis": {
 79174              "graphics": {}
 79175            },
 79176            "considerations": {}
 79177          }
 79178        },
 79179        {
 79180          "type": "library",
 79181          "bom-ref": "pkg:maven/org.apache.httpcomponents/httpclient@4.5.8?package-id=80dbcc392fa69a69",
 79182          "supplier": {},
 79183          "group": "org.apache.httpcomponents",
 79184          "name": "httpclient",
 79185          "version": "4.5.8",
 79186          "cpe": "cpe:2.3:a:apache:httpclient:4.5.8:*:*:*:*:*:*:*",
 79187          "purl": "pkg:maven/org.apache.httpcomponents/httpclient@4.5.8",
 79188          "swid": {
 79189            "attachment": {}
 79190          },
 79191          "pedigree": {},
 79192          "externalReferences": [
 79193            {
 79194              "type": "build-meta",
 79195              "hashes": [
 79196                {
 79197                  "alg": "SHA-1",
 79198                  "content": "c27c9d6f15435dc2b6947112027b418b0eef32b9"
 79199                }
 79200              ]
 79201            }
 79202          ],
 79203          "evidence": {},
 79204          "signature": {
 79205            "signature": {
 79206              "publicKey": {}
 79207            }
 79208          },
 79209          "modelCard": {
 79210            "modelParameters": {
 79211              "approach": {}
 79212            },
 79213            "quantitativeAnalysis": {
 79214              "graphics": {}
 79215            },
 79216            "considerations": {}
 79217          }
 79218        },
 79219        {
 79220          "type": "library",
 79221          "bom-ref": "pkg:maven/org.apache.httpcomponents/httpcore@4.4.11?package-id=9e2e9f0a698d8684",
 79222          "supplier": {},
 79223          "group": "org.apache.httpcomponents",
 79224          "name": "httpcore",
 79225          "version": "4.4.11",
 79226          "cpe": "cpe:2.3:a:apache:httpcore:4.4.11:*:*:*:*:*:*:*",
 79227          "purl": "pkg:maven/org.apache.httpcomponents/httpcore@4.4.11",
 79228          "swid": {
 79229            "attachment": {}
 79230          },
 79231          "pedigree": {},
 79232          "externalReferences": [
 79233            {
 79234              "type": "build-meta",
 79235              "hashes": [
 79236                {
 79237                  "alg": "SHA-1",
 79238                  "content": "de748cf874e4e193b42eceea9fe5574fabb9d4df"
 79239                }
 79240              ]
 79241            }
 79242          ],
 79243          "evidence": {},
 79244          "signature": {
 79245            "signature": {
 79246              "publicKey": {}
 79247            }
 79248          },
 79249          "modelCard": {
 79250            "modelParameters": {
 79251              "approach": {}
 79252            },
 79253            "quantitativeAnalysis": {
 79254              "graphics": {}
 79255            },
 79256            "considerations": {}
 79257          }
 79258        },
 79259        {
 79260          "type": "library",
 79261          "bom-ref": "pkg:maven/io.pliant/ilflow-model@1.0.2?package-id=2656768ef6e7ec05",
 79262          "supplier": {},
 79263          "group": "io.pliant",
 79264          "name": "ilflow-model",
 79265          "version": "1.0.2",
 79266          "cpe": "cpe:2.3:a:ilflow-model:ilflow-model:1.0.2:*:*:*:*:*:*:*",
 79267          "purl": "pkg:maven/io.pliant/ilflow-model@1.0.2",
 79268          "swid": {
 79269            "attachment": {}
 79270          },
 79271          "pedigree": {},
 79272          "externalReferences": [
 79273            {
 79274              "type": "build-meta",
 79275              "hashes": [
 79276                {
 79277                  "alg": "SHA-1",
 79278                  "content": "7460dfcf13e7f115c5deabc36721e610cba077c0"
 79279                }
 79280              ]
 79281            }
 79282          ],
 79283          "evidence": {},
 79284          "signature": {
 79285            "signature": {
 79286              "publicKey": {}
 79287            }
 79288          },
 79289          "modelCard": {
 79290            "modelParameters": {
 79291              "approach": {}
 79292            },
 79293            "quantitativeAnalysis": {
 79294              "graphics": {}
 79295            },
 79296            "considerations": {}
 79297          }
 79298        },
 79299        {
 79300          "type": "library",
 79301          "bom-ref": "pkg:maven/org.influxdb/influxdb-java@2.17?package-id=a970ff7f89c57ca3",
 79302          "supplier": {},
 79303          "group": "org.influxdb",
 79304          "name": "influxdb-java",
 79305          "version": "2.17",
 79306          "cpe": "cpe:2.3:a:influxdb-java:influxdb-java:2.17:*:*:*:*:*:*:*",
 79307          "purl": "pkg:maven/org.influxdb/influxdb-java@2.17",
 79308          "swid": {
 79309            "attachment": {}
 79310          },
 79311          "pedigree": {},
 79312          "externalReferences": [
 79313            {
 79314              "type": "build-meta",
 79315              "hashes": [
 79316                {
 79317                  "alg": "SHA-1",
 79318                  "content": "625a30f370953efd43c251394efa58b389dbc283"
 79319                }
 79320              ]
 79321            }
 79322          ],
 79323          "evidence": {},
 79324          "signature": {
 79325            "signature": {
 79326              "publicKey": {}
 79327            }
 79328          },
 79329          "modelCard": {
 79330            "modelParameters": {
 79331              "approach": {}
 79332            },
 79333            "quantitativeAnalysis": {
 79334              "graphics": {}
 79335            },
 79336            "considerations": {}
 79337          }
 79338        },
 79339        {
 79340          "type": "library",
 79341          "bom-ref": "pkg:maven/jaccess/jaccess?package-id=597e861ae7234b49",
 79342          "supplier": {},
 79343          "name": "jaccess",
 79344          "cpe": "cpe:2.3:a:jaccess:jaccess:*:*:*:*:*:*:*:*",
 79345          "purl": "pkg:maven/jaccess/jaccess",
 79346          "swid": {
 79347            "attachment": {}
 79348          },
 79349          "pedigree": {},
 79350          "externalReferences": [
 79351            {
 79352              "type": "build-meta",
 79353              "hashes": [
 79354                {
 79355                  "alg": "SHA-1",
 79356                  "content": "4cf0b06ec3ab96c68d48a3b56a6a2b9a939b4a69"
 79357                }
 79358              ]
 79359            }
 79360          ],
 79361          "evidence": {},
 79362          "signature": {
 79363            "signature": {
 79364              "publicKey": {}
 79365            }
 79366          },
 79367          "modelCard": {
 79368            "modelParameters": {
 79369              "approach": {}
 79370            },
 79371            "quantitativeAnalysis": {
 79372              "graphics": {}
 79373            },
 79374            "considerations": {}
 79375          }
 79376        },
 79377        {
 79378          "type": "library",
 79379          "bom-ref": "pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.14.0?package-id=bc63e5f055dca09d",
 79380          "supplier": {},
 79381          "group": "com.fasterxml.jackson.core",
 79382          "name": "jackson-annotations",
 79383          "version": "2.14.0",
 79384          "licenses": [
 79385            {
 79386              "license": {
 79387                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 79388              }
 79389            }
 79390          ],
 79391          "cpe": "cpe:2.3:a:jackson-annotations:jackson-annotations:2.14.0:*:*:*:*:*:*:*",
 79392          "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.14.0",
 79393          "swid": {
 79394            "attachment": {}
 79395          },
 79396          "pedigree": {},
 79397          "externalReferences": [
 79398            {
 79399              "type": "build-meta",
 79400              "hashes": [
 79401                {
 79402                  "alg": "SHA-1",
 79403                  "content": "fb7afb3c9c8ea363a9c88ea9c0a7177cf2fbd369"
 79404                }
 79405              ]
 79406            }
 79407          ],
 79408          "evidence": {},
 79409          "signature": {
 79410            "signature": {
 79411              "publicKey": {}
 79412            }
 79413          },
 79414          "modelCard": {
 79415            "modelParameters": {
 79416              "approach": {}
 79417            },
 79418            "quantitativeAnalysis": {
 79419              "graphics": {}
 79420            },
 79421            "considerations": {}
 79422          }
 79423        },
 79424        {
 79425          "type": "library",
 79426          "bom-ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.14.0?package-id=71479e864ea5ec89",
 79427          "supplier": {},
 79428          "group": "com.fasterxml.jackson.core",
 79429          "name": "jackson-core",
 79430          "version": "2.14.0",
 79431          "licenses": [
 79432            {
 79433              "license": {
 79434                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 79435              }
 79436            }
 79437          ],
 79438          "cpe": "cpe:2.3:a:jackson-core:jackson-core:2.14.0:*:*:*:*:*:*:*",
 79439          "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.14.0",
 79440          "swid": {
 79441            "attachment": {}
 79442          },
 79443          "pedigree": {},
 79444          "externalReferences": [
 79445            {
 79446              "type": "build-meta",
 79447              "hashes": [
 79448                {
 79449                  "alg": "SHA-1",
 79450                  "content": "49d219171d6af643e061e9e1baaaf6a6a067918d"
 79451                }
 79452              ]
 79453            }
 79454          ],
 79455          "evidence": {},
 79456          "signature": {
 79457            "signature": {
 79458              "publicKey": {}
 79459            }
 79460          },
 79461          "modelCard": {
 79462            "modelParameters": {
 79463              "approach": {}
 79464            },
 79465            "quantitativeAnalysis": {
 79466              "graphics": {}
 79467            },
 79468            "considerations": {}
 79469          }
 79470        },
 79471        {
 79472          "type": "library",
 79473          "bom-ref": "pkg:maven/jackson-core-asl/jackson-core-asl@1.9.13?package-id=d29f366696775ad5",
 79474          "supplier": {},
 79475          "name": "jackson-core-asl",
 79476          "version": "1.9.13",
 79477          "licenses": [
 79478            {
 79479              "license": {
 79480                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 79481              }
 79482            }
 79483          ],
 79484          "cpe": "cpe:2.3:a:http\\:\\/\\/www-ietf-org\\/rfc\\/rfc4627-txt:jackson-core-asl:1.9.13:*:*:*:*:*:*:*",
 79485          "purl": "pkg:maven/jackson-core-asl/jackson-core-asl@1.9.13",
 79486          "swid": {
 79487            "attachment": {}
 79488          },
 79489          "pedigree": {},
 79490          "externalReferences": [
 79491            {
 79492              "type": "build-meta",
 79493              "hashes": [
 79494                {
 79495                  "alg": "SHA-1",
 79496                  "content": "3c304d70f42f832e0a86d45bd437f692129299a4"
 79497                }
 79498              ]
 79499            }
 79500          ],
 79501          "evidence": {},
 79502          "signature": {
 79503            "signature": {
 79504              "publicKey": {}
 79505            }
 79506          },
 79507          "modelCard": {
 79508            "modelParameters": {
 79509              "approach": {}
 79510            },
 79511            "quantitativeAnalysis": {
 79512              "graphics": {}
 79513            },
 79514            "considerations": {}
 79515          }
 79516        },
 79517        {
 79518          "type": "library",
 79519          "bom-ref": "pkg:maven/com.github.fge.jackson-coreutils/jackson-coreutils@1.8?package-id=2a0df958a429ce8e",
 79520          "supplier": {},
 79521          "name": "jackson-coreutils",
 79522          "version": "1.8",
 79523          "cpe": "cpe:2.3:a:jackson-coreutils:jackson-coreutils:1.8:*:*:*:*:*:*:*",
 79524          "purl": "pkg:maven/com.github.fge.jackson-coreutils/jackson-coreutils@1.8",
 79525          "swid": {
 79526            "attachment": {}
 79527          },
 79528          "pedigree": {},
 79529          "externalReferences": [
 79530            {
 79531              "type": "build-meta",
 79532              "hashes": [
 79533                {
 79534                  "alg": "SHA-1",
 79535                  "content": "491a6e1130a180c153df9f2b7aabd7a700282c67"
 79536                }
 79537              ]
 79538            }
 79539          ],
 79540          "evidence": {},
 79541          "signature": {
 79542            "signature": {
 79543              "publicKey": {}
 79544            }
 79545          },
 79546          "modelCard": {
 79547            "modelParameters": {
 79548              "approach": {}
 79549            },
 79550            "quantitativeAnalysis": {
 79551              "graphics": {}
 79552            },
 79553            "considerations": {}
 79554          }
 79555        },
 79556        {
 79557          "type": "library",
 79558          "bom-ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.0?package-id=24154c0b158f21c4",
 79559          "supplier": {},
 79560          "group": "com.fasterxml.jackson.core",
 79561          "name": "jackson-databind",
 79562          "version": "2.14.0",
 79563          "licenses": [
 79564            {
 79565              "license": {
 79566                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 79567              }
 79568            }
 79569          ],
 79570          "cpe": "cpe:2.3:a:jackson-databind:jackson-databind:2.14.0:*:*:*:*:*:*:*",
 79571          "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.0",
 79572          "swid": {
 79573            "attachment": {}
 79574          },
 79575          "pedigree": {},
 79576          "externalReferences": [
 79577            {
 79578              "type": "build-meta",
 79579              "hashes": [
 79580                {
 79581                  "alg": "SHA-1",
 79582                  "content": "513b8ca3fea0352ceebe4d0bbeea527ab343dc1a"
 79583                }
 79584              ]
 79585            }
 79586          ],
 79587          "evidence": {},
 79588          "signature": {
 79589            "signature": {
 79590              "publicKey": {}
 79591            }
 79592          },
 79593          "modelCard": {
 79594            "modelParameters": {
 79595              "approach": {}
 79596            },
 79597            "quantitativeAnalysis": {
 79598              "graphics": {}
 79599            },
 79600            "considerations": {}
 79601          }
 79602        },
 79603        {
 79604          "type": "library",
 79605          "bom-ref": "pkg:maven/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml@2.14.0?package-id=a855701c60c0ea0e",
 79606          "supplier": {},
 79607          "group": "com.fasterxml.jackson.dataformat",
 79608          "name": "jackson-dataformat-yaml",
 79609          "version": "2.14.0",
 79610          "licenses": [
 79611            {
 79612              "license": {
 79613                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 79614              }
 79615            }
 79616          ],
 79617          "cpe": "cpe:2.3:a:jackson-dataformat-yaml:jackson-dataformat-yaml:2.14.0:*:*:*:*:*:*:*",
 79618          "purl": "pkg:maven/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml@2.14.0",
 79619          "swid": {
 79620            "attachment": {}
 79621          },
 79622          "pedigree": {},
 79623          "externalReferences": [
 79624            {
 79625              "type": "build-meta",
 79626              "hashes": [
 79627                {
 79628                  "alg": "SHA-1",
 79629                  "content": "06c635ef06d3e4e72a7e9868da41ffa1a0f98d28"
 79630                }
 79631              ]
 79632            }
 79633          ],
 79634          "evidence": {},
 79635          "signature": {
 79636            "signature": {
 79637              "publicKey": {}
 79638            }
 79639          },
 79640          "modelCard": {
 79641            "modelParameters": {
 79642              "approach": {}
 79643            },
 79644            "quantitativeAnalysis": {
 79645              "graphics": {}
 79646            },
 79647            "considerations": {}
 79648          }
 79649        },
 79650        {
 79651          "type": "library",
 79652          "bom-ref": "pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.14.0?package-id=40c03a1c78342cad",
 79653          "supplier": {},
 79654          "group": "com.fasterxml.jackson.datatype",
 79655          "name": "jackson-datatype-jdk8",
 79656          "version": "2.14.0",
 79657          "licenses": [
 79658            {
 79659              "license": {
 79660                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 79661              }
 79662            }
 79663          ],
 79664          "cpe": "cpe:2.3:a:jackson-datatype-jdk8:jackson-datatype-jdk8:2.14.0:*:*:*:*:*:*:*",
 79665          "purl": "pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.14.0",
 79666          "swid": {
 79667            "attachment": {}
 79668          },
 79669          "pedigree": {},
 79670          "externalReferences": [
 79671            {
 79672              "type": "build-meta",
 79673              "hashes": [
 79674                {
 79675                  "alg": "SHA-1",
 79676                  "content": "6b8da24a0da4266ed7ddea7ea46594fd50900323"
 79677                }
 79678              ]
 79679            }
 79680          ],
 79681          "evidence": {},
 79682          "signature": {
 79683            "signature": {
 79684              "publicKey": {}
 79685            }
 79686          },
 79687          "modelCard": {
 79688            "modelParameters": {
 79689              "approach": {}
 79690            },
 79691            "quantitativeAnalysis": {
 79692              "graphics": {}
 79693            },
 79694            "considerations": {}
 79695          }
 79696        },
 79697        {
 79698          "type": "library",
 79699          "bom-ref": "pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.14.0?package-id=45d264da0f5e492f",
 79700          "supplier": {},
 79701          "group": "com.fasterxml.jackson.datatype",
 79702          "name": "jackson-datatype-jsr310",
 79703          "version": "2.14.0",
 79704          "licenses": [
 79705            {
 79706              "license": {
 79707                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 79708              }
 79709            }
 79710          ],
 79711          "cpe": "cpe:2.3:a:jackson-datatype-jsr310:jackson-datatype-jsr310:2.14.0:*:*:*:*:*:*:*",
 79712          "purl": "pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.14.0",
 79713          "swid": {
 79714            "attachment": {}
 79715          },
 79716          "pedigree": {},
 79717          "externalReferences": [
 79718            {
 79719              "type": "build-meta",
 79720              "hashes": [
 79721                {
 79722                  "alg": "SHA-1",
 79723                  "content": "171c5831341883b1cebbbf5aafba62c0fca33b95"
 79724                }
 79725              ]
 79726            }
 79727          ],
 79728          "evidence": {},
 79729          "signature": {
 79730            "signature": {
 79731              "publicKey": {}
 79732            }
 79733          },
 79734          "modelCard": {
 79735            "modelParameters": {
 79736              "approach": {}
 79737            },
 79738            "quantitativeAnalysis": {
 79739              "graphics": {}
 79740            },
 79741            "considerations": {}
 79742          }
 79743        },
 79744        {
 79745          "type": "library",
 79746          "bom-ref": "pkg:maven/jackson-mapper-asl/jackson-mapper-asl@1.9.13?package-id=9b0409db19b4e22a",
 79747          "supplier": {},
 79748          "name": "jackson-mapper-asl",
 79749          "version": "1.9.13",
 79750          "licenses": [
 79751            {
 79752              "license": {
 79753                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 79754              }
 79755            }
 79756          ],
 79757          "cpe": "cpe:2.3:a:http\\:\\/\\/fasterxml-com:jackson-mapper-asl:1.9.13:*:*:*:*:*:*:*",
 79758          "purl": "pkg:maven/jackson-mapper-asl/jackson-mapper-asl@1.9.13",
 79759          "swid": {
 79760            "attachment": {}
 79761          },
 79762          "pedigree": {},
 79763          "externalReferences": [
 79764            {
 79765              "type": "build-meta",
 79766              "hashes": [
 79767                {
 79768                  "alg": "SHA-1",
 79769                  "content": "1ee2f2bed0e5dd29d1cb155a166e6f8d50bbddb7"
 79770                }
 79771              ]
 79772            }
 79773          ],
 79774          "evidence": {},
 79775          "signature": {
 79776            "signature": {
 79777              "publicKey": {}
 79778            }
 79779          },
 79780          "modelCard": {
 79781            "modelParameters": {
 79782              "approach": {}
 79783            },
 79784            "quantitativeAnalysis": {
 79785              "graphics": {}
 79786            },
 79787            "considerations": {}
 79788          }
 79789        },
 79790        {
 79791          "type": "library",
 79792          "bom-ref": "pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.14.0?package-id=d44595f51ca521bc",
 79793          "supplier": {},
 79794          "group": "com.fasterxml.jackson.module",
 79795          "name": "jackson-module-parameter-names",
 79796          "version": "2.14.0",
 79797          "licenses": [
 79798            {
 79799              "license": {
 79800                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 79801              }
 79802            }
 79803          ],
 79804          "cpe": "cpe:2.3:a:jackson-module-parameter-names:jackson-module-parameter-names:2.14.0:*:*:*:*:*:*:*",
 79805          "purl": "pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.14.0",
 79806          "swid": {
 79807            "attachment": {}
 79808          },
 79809          "pedigree": {},
 79810          "externalReferences": [
 79811            {
 79812              "type": "build-meta",
 79813              "hashes": [
 79814                {
 79815                  "alg": "SHA-1",
 79816                  "content": "e17e2fdc2dbbe802d953686a9aa2c5257a2b2fd1"
 79817                }
 79818              ]
 79819            }
 79820          ],
 79821          "evidence": {},
 79822          "signature": {
 79823            "signature": {
 79824              "publicKey": {}
 79825            }
 79826          },
 79827          "modelCard": {
 79828            "modelParameters": {
 79829              "approach": {}
 79830            },
 79831            "quantitativeAnalysis": {
 79832              "graphics": {}
 79833            },
 79834            "considerations": {}
 79835          }
 79836        },
 79837        {
 79838          "type": "library",
 79839          "bom-ref": "pkg:maven/org.jboss/jandex@2.0.5.Final?package-id=3b54acb4db8c9c88",
 79840          "supplier": {},
 79841          "group": "org.jboss",
 79842          "name": "jandex",
 79843          "version": "2.0.5.Final",
 79844          "licenses": [
 79845            {
 79846              "license": {
 79847                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 79848              }
 79849            }
 79850          ],
 79851          "cpe": "cpe:2.3:a:jboss-by-red-hat:jandex:2.0.5.Final:*:*:*:*:*:*:*",
 79852          "purl": "pkg:maven/org.jboss/jandex@2.0.5.Final",
 79853          "swid": {
 79854            "attachment": {}
 79855          },
 79856          "pedigree": {},
 79857          "externalReferences": [
 79858            {
 79859              "type": "build-meta",
 79860              "hashes": [
 79861                {
 79862                  "alg": "SHA-1",
 79863                  "content": "7060f67764565b9ee9d467e3ed0cb8a9c601b23a"
 79864                }
 79865              ]
 79866            }
 79867          ],
 79868          "evidence": {},
 79869          "signature": {
 79870            "signature": {
 79871              "publicKey": {}
 79872            }
 79873          },
 79874          "modelCard": {
 79875            "modelParameters": {
 79876              "approach": {}
 79877            },
 79878            "quantitativeAnalysis": {
 79879              "graphics": {}
 79880            },
 79881            "considerations": {}
 79882          }
 79883        },
 79884        {
 79885          "type": "application",
 79886          "bom-ref": "pkg:generic/java@1.8.0_362-b09?package-id=df80297034b58157",
 79887          "supplier": {},
 79888          "name": "java",
 79889          "version": "1.8.0_362-b09",
 79890          "cpe": "cpe:2.3:a:oracle:openjdk:1.8.0_362-b09:*:*:*:*:*:*:*",
 79891          "purl": "pkg:generic/java@1.8.0_362-b09",
 79892          "swid": {
 79893            "attachment": {}
 79894          },
 79895          "pedigree": {},
 79896          "evidence": {},
 79897          "signature": {
 79898            "signature": {
 79899              "publicKey": {}
 79900            }
 79901          },
 79902          "modelCard": {
 79903            "modelParameters": {
 79904              "approach": {}
 79905            },
 79906            "quantitativeAnalysis": {
 79907              "graphics": {}
 79908            },
 79909            "considerations": {}
 79910          }
 79911        },
 79912        {
 79913          "type": "library",
 79914          "bom-ref": "pkg:maven/org.javassist/javassist@3.23.2-GA?package-id=3f941ac2ab917b73",
 79915          "supplier": {},
 79916          "group": "org.javassist",
 79917          "name": "javassist",
 79918          "version": "3.23.2-GA",
 79919          "licenses": [
 79920            {
 79921              "license": {
 79922                "name": "http://www.mozilla.org/MPL/MPL-1.1.html, http://www.gnu.org/licenses/lgpl-2.1.html, http://www.apache.org/licenses/"
 79923              }
 79924            }
 79925          ],
 79926          "cpe": "cpe:2.3:a:shigeru-chiba\\,-www-javassist-org:javassist:3.23.2-GA:*:*:*:*:*:*:*",
 79927          "purl": "pkg:maven/org.javassist/javassist@3.23.2-GA",
 79928          "swid": {
 79929            "attachment": {}
 79930          },
 79931          "pedigree": {},
 79932          "externalReferences": [
 79933            {
 79934              "type": "build-meta",
 79935              "hashes": [
 79936                {
 79937                  "alg": "SHA-1",
 79938                  "content": "c5afe660a95e87ceb518e4f5cf02f5c56b547683"
 79939                }
 79940              ]
 79941            }
 79942          ],
 79943          "evidence": {},
 79944          "signature": {
 79945            "signature": {
 79946              "publicKey": {}
 79947            }
 79948          },
 79949          "modelCard": {
 79950            "modelParameters": {
 79951              "approach": {}
 79952            },
 79953            "quantitativeAnalysis": {
 79954              "graphics": {}
 79955            },
 79956            "considerations": {}
 79957          }
 79958        },
 79959        {
 79960          "type": "library",
 79961          "bom-ref": "pkg:maven/com.sun/javax.activation-api@1.2.0?package-id=44695ad4c4a14e64",
 79962          "supplier": {},
 79963          "group": "javax.activation",
 79964          "name": "javax.activation-api",
 79965          "version": "1.2.0",
 79966          "licenses": [
 79967            {
 79968              "license": {
 79969                "name": "https://github.com/javaee/activation/blob/master/LICENSE.txt"
 79970              }
 79971            }
 79972          ],
 79973          "cpe": "cpe:2.3:a:javax.activation-api:javax.activation-api:1.2.0:*:*:*:*:*:*:*",
 79974          "purl": "pkg:maven/com.sun/javax.activation-api@1.2.0",
 79975          "swid": {
 79976            "attachment": {}
 79977          },
 79978          "pedigree": {},
 79979          "externalReferences": [
 79980            {
 79981              "type": "build-meta",
 79982              "hashes": [
 79983                {
 79984                  "alg": "SHA-1",
 79985                  "content": "85262acf3ca9816f9537ca47d5adeabaead7cb16"
 79986                }
 79987              ]
 79988            }
 79989          ],
 79990          "evidence": {},
 79991          "signature": {
 79992            "signature": {
 79993              "publicKey": {}
 79994            }
 79995          },
 79996          "modelCard": {
 79997            "modelParameters": {
 79998              "approach": {}
 79999            },
 80000            "quantitativeAnalysis": {
 80001              "graphics": {}
 80002            },
 80003            "considerations": {}
 80004          }
 80005        },
 80006        {
 80007          "type": "library",
 80008          "bom-ref": "pkg:maven/org.glassfish/javax.annotation-api@1.3.2?package-id=20bd801f6cf7b7a6",
 80009          "supplier": {},
 80010          "group": "javax.annotation",
 80011          "name": "javax.annotation-api",
 80012          "version": "1.3.2",
 80013          "licenses": [
 80014            {
 80015              "license": {
 80016                "name": "https://github.com/javaee/javax.annotation/blob/master/LICENSE"
 80017              }
 80018            }
 80019          ],
 80020          "cpe": "cpe:2.3:a:javax.annotation-api:javax.annotation-api:1.3.2:*:*:*:*:*:*:*",
 80021          "purl": "pkg:maven/org.glassfish/javax.annotation-api@1.3.2",
 80022          "swid": {
 80023            "attachment": {}
 80024          },
 80025          "pedigree": {},
 80026          "externalReferences": [
 80027            {
 80028              "type": "build-meta",
 80029              "hashes": [
 80030                {
 80031                  "alg": "SHA-1",
 80032                  "content": "934c04d3cfef185a8008e7bf34331b79730a9d43"
 80033                }
 80034              ]
 80035            }
 80036          ],
 80037          "evidence": {},
 80038          "signature": {
 80039            "signature": {
 80040              "publicKey": {}
 80041            }
 80042          },
 80043          "modelCard": {
 80044            "modelParameters": {
 80045              "approach": {}
 80046            },
 80047            "quantitativeAnalysis": {
 80048              "graphics": {}
 80049            },
 80050            "considerations": {}
 80051          }
 80052        },
 80053        {
 80054          "type": "library",
 80055          "bom-ref": "pkg:maven/com.oracle/javax.persistence-api@2.2?package-id=155945b0674da452",
 80056          "supplier": {},
 80057          "group": "javax.persistence",
 80058          "name": "javax.persistence-api",
 80059          "version": "2.2",
 80060          "licenses": [
 80061            {
 80062              "license": {
 80063                "name": "http://www.eclipse.org/legal/epl-v10.html, http://www.eclipse.org/org/documents/edl-v10.php"
 80064              }
 80065            }
 80066          ],
 80067          "cpe": "cpe:2.3:a:javax.persistence-api:javax.persistence-api:2.2:*:*:*:*:*:*:*",
 80068          "purl": "pkg:maven/com.oracle/javax.persistence-api@2.2",
 80069          "swid": {
 80070            "attachment": {}
 80071          },
 80072          "pedigree": {},
 80073          "externalReferences": [
 80074            {
 80075              "type": "build-meta",
 80076              "hashes": [
 80077                {
 80078                  "alg": "SHA-1",
 80079                  "content": "25665ac8c0b62f50e6488173233239120fc52c96"
 80080                }
 80081              ]
 80082            }
 80083          ],
 80084          "evidence": {},
 80085          "signature": {
 80086            "signature": {
 80087              "publicKey": {}
 80088            }
 80089          },
 80090          "modelCard": {
 80091            "modelParameters": {
 80092              "approach": {}
 80093            },
 80094            "quantitativeAnalysis": {
 80095              "graphics": {}
 80096            },
 80097            "considerations": {}
 80098          }
 80099        },
 80100        {
 80101          "type": "library",
 80102          "bom-ref": "pkg:maven/org.glassfish/javax.transaction-api@1.3?package-id=714e2ad1cde0a927",
 80103          "supplier": {},
 80104          "group": "javax.transaction",
 80105          "name": "javax.transaction-api",
 80106          "version": "1.3",
 80107          "licenses": [
 80108            {
 80109              "license": {
 80110                "name": "https://github.com/javaee/javax.transaction/blob/master/LICENSE"
 80111              }
 80112            }
 80113          ],
 80114          "cpe": "cpe:2.3:a:javax.transaction-api:javax.transaction-api:1.3:*:*:*:*:*:*:*",
 80115          "purl": "pkg:maven/org.glassfish/javax.transaction-api@1.3",
 80116          "swid": {
 80117            "attachment": {}
 80118          },
 80119          "pedigree": {},
 80120          "externalReferences": [
 80121            {
 80122              "type": "build-meta",
 80123              "hashes": [
 80124                {
 80125                  "alg": "SHA-1",
 80126                  "content": "e006adf5cf3cca2181d16bd640ecb80148ec0fce"
 80127                }
 80128              ]
 80129            }
 80130          ],
 80131          "evidence": {},
 80132          "signature": {
 80133            "signature": {
 80134              "publicKey": {}
 80135            }
 80136          },
 80137          "modelCard": {
 80138            "modelParameters": {
 80139              "approach": {}
 80140            },
 80141            "quantitativeAnalysis": {
 80142              "graphics": {}
 80143            },
 80144            "considerations": {}
 80145          }
 80146        },
 80147        {
 80148          "type": "library",
 80149          "bom-ref": "pkg:maven/org.glassfish/jaxb-api@2.3.1?package-id=e7520f737bf4c7ed",
 80150          "supplier": {},
 80151          "group": "javax.xml.bind",
 80152          "name": "jaxb-api",
 80153          "version": "2.3.1",
 80154          "licenses": [
 80155            {
 80156              "license": {
 80157                "name": "https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1"
 80158              }
 80159            }
 80160          ],
 80161          "cpe": "cpe:2.3:a:oracle-corporation:jaxb-api:2.3.1:*:*:*:*:*:*:*",
 80162          "purl": "pkg:maven/org.glassfish/jaxb-api@2.3.1",
 80163          "swid": {
 80164            "attachment": {}
 80165          },
 80166          "pedigree": {},
 80167          "externalReferences": [
 80168            {
 80169              "type": "build-meta",
 80170              "hashes": [
 80171                {
 80172                  "alg": "SHA-1",
 80173                  "content": "8531ad5ac454cc2deb9d4d32c40c4d7451939b5d"
 80174                }
 80175              ]
 80176            }
 80177          ],
 80178          "evidence": {},
 80179          "signature": {
 80180            "signature": {
 80181              "publicKey": {}
 80182            }
 80183          },
 80184          "modelCard": {
 80185            "modelParameters": {
 80186              "approach": {}
 80187            },
 80188            "quantitativeAnalysis": {
 80189              "graphics": {}
 80190            },
 80191            "considerations": {}
 80192          }
 80193        },
 80194        {
 80195          "type": "library",
 80196          "bom-ref": "pkg:maven/org.jboss.logging/jboss-logging@3.3.2.Final?package-id=8f624e9189ec70d9",
 80197          "supplier": {},
 80198          "group": "org.jboss.logging",
 80199          "name": "jboss-logging",
 80200          "version": "3.3.2.Final",
 80201          "licenses": [
 80202            {
 80203              "license": {
 80204                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 80205              }
 80206            }
 80207          ],
 80208          "cpe": "cpe:2.3:a:jboss-by-red-hat:jboss-logging:3.3.2.Final:*:*:*:*:*:*:*",
 80209          "purl": "pkg:maven/org.jboss.logging/jboss-logging@3.3.2.Final",
 80210          "swid": {
 80211            "attachment": {}
 80212          },
 80213          "pedigree": {},
 80214          "externalReferences": [
 80215            {
 80216              "type": "build-meta",
 80217              "hashes": [
 80218                {
 80219                  "alg": "SHA-1",
 80220                  "content": "3789d00e859632e6c6206adc0c71625559e6e3b0"
 80221                }
 80222              ]
 80223            }
 80224          ],
 80225          "evidence": {},
 80226          "signature": {
 80227            "signature": {
 80228              "publicKey": {}
 80229            }
 80230          },
 80231          "modelCard": {
 80232            "modelParameters": {
 80233              "approach": {}
 80234            },
 80235            "quantitativeAnalysis": {
 80236              "graphics": {}
 80237            },
 80238            "considerations": {}
 80239          }
 80240        },
 80241        {
 80242          "type": "library",
 80243          "bom-ref": "pkg:maven/com.sun/jce@1.8.0_362?package-id=a8c489b1d53d3920",
 80244          "supplier": {},
 80245          "name": "jce",
 80246          "version": "1.8.0_362",
 80247          "cpe": "cpe:2.3:a:oracle-corporation:jce:1.8.0_362:*:*:*:*:*:*:*",
 80248          "purl": "pkg:maven/com.sun/jce@1.8.0_362",
 80249          "swid": {
 80250            "attachment": {}
 80251          },
 80252          "pedigree": {},
 80253          "externalReferences": [
 80254            {
 80255              "type": "build-meta",
 80256              "hashes": [
 80257                {
 80258                  "alg": "SHA-1",
 80259                  "content": "ea30f8fc11602d5de2fc30432e5c489364bb7d2e"
 80260                }
 80261              ]
 80262            }
 80263          ],
 80264          "evidence": {},
 80265          "signature": {
 80266            "signature": {
 80267              "publicKey": {}
 80268            }
 80269          },
 80270          "modelCard": {
 80271            "modelParameters": {
 80272              "approach": {}
 80273            },
 80274            "quantitativeAnalysis": {
 80275              "graphics": {}
 80276            },
 80277            "considerations": {}
 80278          }
 80279        },
 80280        {
 80281          "type": "library",
 80282          "bom-ref": "pkg:maven/jcip-annotations/jcip-annotations@1.0?package-id=c978132a9e3cfedc",
 80283          "supplier": {},
 80284          "name": "jcip-annotations",
 80285          "version": "1.0",
 80286          "cpe": "cpe:2.3:a:jcip-annotations:jcip-annotations:1.0:*:*:*:*:*:*:*",
 80287          "purl": "pkg:maven/jcip-annotations/jcip-annotations@1.0",
 80288          "swid": {
 80289            "attachment": {}
 80290          },
 80291          "pedigree": {},
 80292          "externalReferences": [
 80293            {
 80294              "type": "build-meta",
 80295              "hashes": [
 80296                {
 80297                  "alg": "SHA-1",
 80298                  "content": "afba4942caaeaf46aab0b976afd57cc7c181467e"
 80299                }
 80300              ]
 80301            }
 80302          ],
 80303          "evidence": {},
 80304          "signature": {
 80305            "signature": {
 80306              "publicKey": {}
 80307            }
 80308          },
 80309          "modelCard": {
 80310            "modelParameters": {
 80311              "approach": {}
 80312            },
 80313            "quantitativeAnalysis": {
 80314              "graphics": {}
 80315            },
 80316            "considerations": {}
 80317          }
 80318        },
 80319        {
 80320          "type": "library",
 80321          "bom-ref": "pkg:maven/org.slf4j/jcl-over-slf4j@1.7.26?package-id=d1b661229f7b1b57",
 80322          "supplier": {},
 80323          "group": "org.slf4j",
 80324          "name": "jcl-over-slf4j",
 80325          "version": "1.7.26",
 80326          "cpe": "cpe:2.3:a:jcl-over-slf4j:jcl-over-slf4j:1.7.26:*:*:*:*:*:*:*",
 80327          "purl": "pkg:maven/org.slf4j/jcl-over-slf4j@1.7.26",
 80328          "swid": {
 80329            "attachment": {}
 80330          },
 80331          "pedigree": {},
 80332          "externalReferences": [
 80333            {
 80334              "type": "build-meta",
 80335              "hashes": [
 80336                {
 80337                  "alg": "SHA-1",
 80338                  "content": "33fbc2d93de829fa5e263c5ce97f5eab8f57d53e"
 80339                }
 80340              ]
 80341            }
 80342          ],
 80343          "evidence": {},
 80344          "signature": {
 80345            "signature": {
 80346              "publicKey": {}
 80347            }
 80348          },
 80349          "modelCard": {
 80350            "modelParameters": {
 80351              "approach": {}
 80352            },
 80353            "quantitativeAnalysis": {
 80354              "graphics": {}
 80355            },
 80356            "considerations": {}
 80357          }
 80358        },
 80359        {
 80360          "type": "library",
 80361          "bom-ref": "pkg:maven/org.jctools/jctools-core@2.1.1?package-id=1e89c60aec5b2395",
 80362          "supplier": {},
 80363          "group": "org.jctools",
 80364          "name": "jctools-core",
 80365          "version": "2.1.1",
 80366          "cpe": "cpe:2.3:a:jctools-core:jctools-core:2.1.1:*:*:*:*:*:*:*",
 80367          "purl": "pkg:maven/org.jctools/jctools-core@2.1.1",
 80368          "swid": {
 80369            "attachment": {}
 80370          },
 80371          "pedigree": {},
 80372          "evidence": {},
 80373          "signature": {
 80374            "signature": {
 80375              "publicKey": {}
 80376            }
 80377          },
 80378          "modelCard": {
 80379            "modelParameters": {
 80380              "approach": {}
 80381            },
 80382            "quantitativeAnalysis": {
 80383              "graphics": {}
 80384            },
 80385            "considerations": {}
 80386          }
 80387        },
 80388        {
 80389          "type": "library",
 80390          "bom-ref": "pkg:maven/jdo-api/jdo-api@3.0.1?package-id=976ac26c8b36ff43",
 80391          "supplier": {},
 80392          "name": "jdo-api",
 80393          "version": "3.0.1",
 80394          "licenses": [
 80395            {
 80396              "license": {
 80397                "name": "http://www.apache.org/licenses/LICENSE-2.0.html"
 80398              }
 80399            }
 80400          ],
 80401          "cpe": "cpe:2.3:a:apache-software-foundation:jdo-api:3.0.1:*:*:*:*:*:*:*",
 80402          "purl": "pkg:maven/jdo-api/jdo-api@3.0.1",
 80403          "swid": {
 80404            "attachment": {}
 80405          },
 80406          "pedigree": {},
 80407          "externalReferences": [
 80408            {
 80409              "type": "build-meta",
 80410              "hashes": [
 80411                {
 80412                  "alg": "SHA-1",
 80413                  "content": "058e7a538e020b73871e232eeb064835fd98a492"
 80414                }
 80415              ]
 80416            }
 80417          ],
 80418          "evidence": {},
 80419          "signature": {
 80420            "signature": {
 80421              "publicKey": {}
 80422            }
 80423          },
 80424          "modelCard": {
 80425            "modelParameters": {
 80426              "approach": {}
 80427            },
 80428            "quantitativeAnalysis": {
 80429              "graphics": {}
 80430            },
 80431            "considerations": {}
 80432          }
 80433        },
 80434        {
 80435          "type": "library",
 80436          "bom-ref": "pkg:maven/jfr/jfr@1.8.0_362?package-id=a79464b21bb17e9e",
 80437          "supplier": {},
 80438          "name": "jfr",
 80439          "version": "1.8.0_362",
 80440          "cpe": "cpe:2.3:a:oracle-corporation:jfr:1.8.0_362:*:*:*:*:*:*:*",
 80441          "purl": "pkg:maven/jfr/jfr@1.8.0_362",
 80442          "swid": {
 80443            "attachment": {}
 80444          },
 80445          "pedigree": {},
 80446          "externalReferences": [
 80447            {
 80448              "type": "build-meta",
 80449              "hashes": [
 80450                {
 80451                  "alg": "SHA-1",
 80452                  "content": "88dbd83bf6b99249cb4a27d94cd9db30eed845d5"
 80453                }
 80454              ]
 80455            }
 80456          ],
 80457          "evidence": {},
 80458          "signature": {
 80459            "signature": {
 80460              "publicKey": {}
 80461            }
 80462          },
 80463          "modelCard": {
 80464            "modelParameters": {
 80465              "approach": {}
 80466            },
 80467            "quantitativeAnalysis": {
 80468              "graphics": {}
 80469            },
 80470            "considerations": {}
 80471          }
 80472        },
 80473        {
 80474          "type": "library",
 80475          "bom-ref": "pkg:maven/org.joda/joda-time@2.10.2?package-id=1dfc2e94aeebb351",
 80476          "supplier": {},
 80477          "group": "joda-time",
 80478          "name": "joda-time",
 80479          "version": "2.10.2",
 80480          "licenses": [
 80481            {
 80482              "license": {
 80483                "name": "Apache 2.0"
 80484              }
 80485            }
 80486          ],
 80487          "cpe": "cpe:2.3:a:joda-time:joda-time:2.10.2:*:*:*:*:*:*:*",
 80488          "purl": "pkg:maven/org.joda/joda-time@2.10.2",
 80489          "swid": {
 80490            "attachment": {}
 80491          },
 80492          "pedigree": {},
 80493          "externalReferences": [
 80494            {
 80495              "type": "build-meta",
 80496              "hashes": [
 80497                {
 80498                  "alg": "SHA-1",
 80499                  "content": "a079fc39ccc3de02acdeb7117443e5d9bd431687"
 80500                }
 80501              ]
 80502            }
 80503          ],
 80504          "evidence": {},
 80505          "signature": {
 80506            "signature": {
 80507              "publicKey": {}
 80508            }
 80509          },
 80510          "modelCard": {
 80511            "modelParameters": {
 80512              "approach": {}
 80513            },
 80514            "quantitativeAnalysis": {
 80515              "graphics": {}
 80516            },
 80517            "considerations": {}
 80518          }
 80519        },
 80520        {
 80521          "type": "library",
 80522          "bom-ref": "pkg:maven/net.sf.jopt-simple/jopt-simple@5.0.3?package-id=8cbe0c529f0357d",
 80523          "supplier": {},
 80524          "group": "net.sf.jopt-simple",
 80525          "name": "jopt-simple",
 80526          "version": "5.0.3",
 80527          "licenses": [
 80528            {
 80529              "license": {
 80530                "name": "http://www.opensource.org/licenses/mit-license.php"
 80531              }
 80532            }
 80533          ],
 80534          "cpe": "cpe:2.3:a:jopt-simple:jopt-simple:5.0.3:*:*:*:*:*:*:*",
 80535          "purl": "pkg:maven/net.sf.jopt-simple/jopt-simple@5.0.3",
 80536          "swid": {
 80537            "attachment": {}
 80538          },
 80539          "pedigree": {},
 80540          "externalReferences": [
 80541            {
 80542              "type": "build-meta",
 80543              "hashes": [
 80544                {
 80545                  "alg": "SHA-1",
 80546                  "content": "cdd846cfc4e0f7eefafc02c0f5dce32b9303aa2a"
 80547                }
 80548              ]
 80549            }
 80550          ],
 80551          "evidence": {},
 80552          "signature": {
 80553            "signature": {
 80554              "publicKey": {}
 80555            }
 80556          },
 80557          "modelCard": {
 80558            "modelParameters": {
 80559              "approach": {}
 80560            },
 80561            "quantitativeAnalysis": {
 80562              "graphics": {}
 80563            },
 80564            "considerations": {}
 80565          }
 80566        },
 80567        {
 80568          "type": "library",
 80569          "bom-ref": "pkg:maven/com.github.java-json-tools.json-schema-core/json-schema-core@1.2.8?package-id=1a535dbb910c0719",
 80570          "supplier": {},
 80571          "name": "json-schema-core",
 80572          "version": "1.2.8",
 80573          "cpe": "cpe:2.3:a:json-schema-core:json-schema-core:1.2.8:*:*:*:*:*:*:*",
 80574          "purl": "pkg:maven/com.github.java-json-tools.json-schema-core/json-schema-core@1.2.8",
 80575          "swid": {
 80576            "attachment": {}
 80577          },
 80578          "pedigree": {},
 80579          "externalReferences": [
 80580            {
 80581              "type": "build-meta",
 80582              "hashes": [
 80583                {
 80584                  "alg": "SHA-1",
 80585                  "content": "5164416f08168ced34e02d870cb958db42b61b5f"
 80586                }
 80587              ]
 80588            }
 80589          ],
 80590          "evidence": {},
 80591          "signature": {
 80592            "signature": {
 80593              "publicKey": {}
 80594            }
 80595          },
 80596          "modelCard": {
 80597            "modelParameters": {
 80598              "approach": {}
 80599            },
 80600            "quantitativeAnalysis": {
 80601              "graphics": {}
 80602            },
 80603            "considerations": {}
 80604          }
 80605        },
 80606        {
 80607          "type": "library",
 80608          "bom-ref": "pkg:maven/com.github.java-json-tools.json-schema-validator/json-schema-validator@2.2.8?package-id=fc52a0f66aec0ff8",
 80609          "supplier": {},
 80610          "name": "json-schema-validator",
 80611          "version": "2.2.8",
 80612          "cpe": "cpe:2.3:a:json-schema-validator:json-schema-validator:2.2.8:*:*:*:*:*:*:*",
 80613          "purl": "pkg:maven/com.github.java-json-tools.json-schema-validator/json-schema-validator@2.2.8",
 80614          "swid": {
 80615            "attachment": {}
 80616          },
 80617          "pedigree": {},
 80618          "externalReferences": [
 80619            {
 80620              "type": "build-meta",
 80621              "hashes": [
 80622                {
 80623                  "alg": "SHA-1",
 80624                  "content": "b577aa61af5731102ed6044a6f01cfa10499e370"
 80625                }
 80626              ]
 80627            }
 80628          ],
 80629          "evidence": {},
 80630          "signature": {
 80631            "signature": {
 80632              "publicKey": {}
 80633            }
 80634          },
 80635          "modelCard": {
 80636            "modelParameters": {
 80637              "approach": {}
 80638            },
 80639            "quantitativeAnalysis": {
 80640              "graphics": {}
 80641            },
 80642            "considerations": {}
 80643          }
 80644        },
 80645        {
 80646          "type": "library",
 80647          "bom-ref": "pkg:maven/com.google.code.findbugs/jsr305@3.0.1?package-id=314015e8b6517faa",
 80648          "supplier": {},
 80649          "group": "com.google.code.findbugs",
 80650          "name": "jsr305",
 80651          "version": "3.0.1",
 80652          "cpe": "cpe:2.3:a:findbugs:jsr305:3.0.1:*:*:*:*:*:*:*",
 80653          "purl": "pkg:maven/com.google.code.findbugs/jsr305@3.0.1",
 80654          "swid": {
 80655            "attachment": {}
 80656          },
 80657          "pedigree": {},
 80658          "evidence": {},
 80659          "signature": {
 80660            "signature": {
 80661              "publicKey": {}
 80662            }
 80663          },
 80664          "modelCard": {
 80665            "modelParameters": {
 80666              "approach": {}
 80667            },
 80668            "quantitativeAnalysis": {
 80669              "graphics": {}
 80670            },
 80671            "considerations": {}
 80672          }
 80673        },
 80674        {
 80675          "type": "library",
 80676          "bom-ref": "pkg:maven/com.google.code.findbugs/jsr305@3.0.1?package-id=aff6c37de2e9097c",
 80677          "supplier": {},
 80678          "group": "com.google.code.findbugs",
 80679          "name": "jsr305",
 80680          "version": "3.0.1",
 80681          "licenses": [
 80682            {
 80683              "license": {
 80684                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 80685              }
 80686            }
 80687          ],
 80688          "cpe": "cpe:2.3:a:findbugs:jsr305:3.0.1:*:*:*:*:*:*:*",
 80689          "purl": "pkg:maven/com.google.code.findbugs/jsr305@3.0.1",
 80690          "swid": {
 80691            "attachment": {}
 80692          },
 80693          "pedigree": {},
 80694          "externalReferences": [
 80695            {
 80696              "type": "build-meta",
 80697              "hashes": [
 80698                {
 80699                  "alg": "SHA-1",
 80700                  "content": "f7be08ec23c21485b9b5a1cf1654c2ec8c58168d"
 80701                }
 80702              ]
 80703            }
 80704          ],
 80705          "evidence": {},
 80706          "signature": {
 80707            "signature": {
 80708              "publicKey": {}
 80709            }
 80710          },
 80711          "modelCard": {
 80712            "modelParameters": {
 80713              "approach": {}
 80714            },
 80715            "quantitativeAnalysis": {
 80716              "graphics": {}
 80717            },
 80718            "considerations": {}
 80719          }
 80720        },
 80721        {
 80722          "type": "library",
 80723          "bom-ref": "pkg:maven/jsse/jsse@1.8.0_362?package-id=c373477973ee44a0",
 80724          "supplier": {},
 80725          "name": "jsse",
 80726          "version": "1.8.0_362",
 80727          "cpe": "cpe:2.3:a:oracle-corporation:jsse:1.8.0_362:*:*:*:*:*:*:*",
 80728          "purl": "pkg:maven/jsse/jsse@1.8.0_362",
 80729          "swid": {
 80730            "attachment": {}
 80731          },
 80732          "pedigree": {},
 80733          "externalReferences": [
 80734            {
 80735              "type": "build-meta",
 80736              "hashes": [
 80737                {
 80738                  "alg": "SHA-1",
 80739                  "content": "e2cc27ebb60ca839f44d9794f18450eb23cf44b4"
 80740                }
 80741              ]
 80742            }
 80743          ],
 80744          "evidence": {},
 80745          "signature": {
 80746            "signature": {
 80747              "publicKey": {}
 80748            }
 80749          },
 80750          "modelCard": {
 80751            "modelParameters": {
 80752              "approach": {}
 80753            },
 80754            "quantitativeAnalysis": {
 80755              "graphics": {}
 80756            },
 80757            "considerations": {}
 80758          }
 80759        },
 80760        {
 80761          "type": "library",
 80762          "bom-ref": "pkg:maven/jta/jta@1.1?package-id=dfc49ad702ec5160",
 80763          "supplier": {},
 80764          "name": "jta",
 80765          "version": "1.1",
 80766          "cpe": "cpe:2.3:a:sun-microsystems\\,-inc-:jta:1.1:*:*:*:*:*:*:*",
 80767          "purl": "pkg:maven/jta/jta@1.1",
 80768          "swid": {
 80769            "attachment": {}
 80770          },
 80771          "pedigree": {},
 80772          "externalReferences": [
 80773            {
 80774              "type": "build-meta",
 80775              "hashes": [
 80776                {
 80777                  "alg": "SHA-1",
 80778                  "content": "2ca09f0b36ca7d71b762e14ea2ff09d5eac57558"
 80779                }
 80780              ]
 80781            }
 80782          ],
 80783          "evidence": {},
 80784          "signature": {
 80785            "signature": {
 80786              "publicKey": {}
 80787            }
 80788          },
 80789          "modelCard": {
 80790            "modelParameters": {
 80791              "approach": {}
 80792            },
 80793            "quantitativeAnalysis": {
 80794              "graphics": {}
 80795            },
 80796            "considerations": {}
 80797          }
 80798        },
 80799        {
 80800          "type": "library",
 80801          "bom-ref": "pkg:maven/org.slf4j/jul-to-slf4j@1.7.26?package-id=efc03a1563ee22aa",
 80802          "supplier": {},
 80803          "group": "org.slf4j",
 80804          "name": "jul-to-slf4j",
 80805          "version": "1.7.26",
 80806          "cpe": "cpe:2.3:a:jul-to-slf4j:jul-to-slf4j:1.7.26:*:*:*:*:*:*:*",
 80807          "purl": "pkg:maven/org.slf4j/jul-to-slf4j@1.7.26",
 80808          "swid": {
 80809            "attachment": {}
 80810          },
 80811          "pedigree": {},
 80812          "externalReferences": [
 80813            {
 80814              "type": "build-meta",
 80815              "hashes": [
 80816                {
 80817                  "alg": "SHA-1",
 80818                  "content": "8031352b2bb0a49e67818bf04c027aa92e645d5c"
 80819                }
 80820              ]
 80821            }
 80822          ],
 80823          "evidence": {},
 80824          "signature": {
 80825            "signature": {
 80826              "publicKey": {}
 80827            }
 80828          },
 80829          "modelCard": {
 80830            "modelParameters": {
 80831              "approach": {}
 80832            },
 80833            "quantitativeAnalysis": {
 80834              "graphics": {}
 80835            },
 80836            "considerations": {}
 80837          }
 80838        },
 80839        {
 80840          "type": "library",
 80841          "bom-ref": "pkg:maven/io.lettuce/lettuce-core@5.1.6.RELEASE?package-id=46e9909fcd49becd",
 80842          "supplier": {},
 80843          "group": "io.lettuce",
 80844          "name": "lettuce-core",
 80845          "version": "5.1.6.RELEASE",
 80846          "cpe": "cpe:2.3:a:lettuce-core:lettuce-core:5.1.6.RELEASE:*:*:*:*:*:*:*",
 80847          "purl": "pkg:maven/io.lettuce/lettuce-core@5.1.6.RELEASE",
 80848          "swid": {
 80849            "attachment": {}
 80850          },
 80851          "pedigree": {},
 80852          "externalReferences": [
 80853            {
 80854              "type": "build-meta",
 80855              "hashes": [
 80856                {
 80857                  "alg": "SHA-1",
 80858                  "content": "2ce6481aa829475c32adc57067cf7563a1f7dd8f"
 80859                }
 80860              ]
 80861            }
 80862          ],
 80863          "evidence": {},
 80864          "signature": {
 80865            "signature": {
 80866              "publicKey": {}
 80867            }
 80868          },
 80869          "modelCard": {
 80870            "modelParameters": {
 80871              "approach": {}
 80872            },
 80873            "quantitativeAnalysis": {
 80874              "graphics": {}
 80875            },
 80876            "considerations": {}
 80877          }
 80878        },
 80879        {
 80880          "type": "library",
 80881          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r4?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.17.3\u0026package-id=60a12fd5038efa61",
 80882          "supplier": {},
 80883          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 80884          "name": "libbz2",
 80885          "version": "1.0.8-r4",
 80886          "description": "Shared library for bz2",
 80887          "licenses": [
 80888            {
 80889              "license": {
 80890                "id": "bzip2-1.0.6"
 80891              }
 80892            }
 80893          ],
 80894          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r4:*:*:*:*:*:*:*",
 80895          "purl": "pkg:apk/alpine/libbz2@1.0.8-r4?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.17.3",
 80896          "swid": {
 80897            "attachment": {}
 80898          },
 80899          "pedigree": {},
 80900          "externalReferences": [
 80901            {
 80902              "url": "https://sourceware.org/bzip2/",
 80903              "type": "distribution"
 80904            }
 80905          ],
 80906          "evidence": {},
 80907          "signature": {
 80908            "signature": {
 80909              "publicKey": {}
 80910            }
 80911          },
 80912          "modelCard": {
 80913            "modelParameters": {
 80914              "approach": {}
 80915            },
 80916            "quantitativeAnalysis": {
 80917              "graphics": {}
 80918            },
 80919            "considerations": {}
 80920          }
 80921        },
 80922        {
 80923          "type": "library",
 80924          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.3\u0026package-id=8126b232e2d3c608",
 80925          "supplier": {},
 80926          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 80927          "name": "libc-utils",
 80928          "version": "0.7.2-r3",
 80929          "description": "Meta package to pull in correct libc",
 80930          "licenses": [
 80931            {
 80932              "license": {
 80933                "id": "BSD-2-Clause"
 80934              }
 80935            },
 80936            {
 80937              "license": {
 80938                "name": "AND"
 80939              }
 80940            },
 80941            {
 80942              "license": {
 80943                "id": "BSD-3-Clause"
 80944              }
 80945            }
 80946          ],
 80947          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
 80948          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.3",
 80949          "swid": {
 80950            "attachment": {}
 80951          },
 80952          "pedigree": {},
 80953          "externalReferences": [
 80954            {
 80955              "url": "https://alpinelinux.org",
 80956              "type": "distribution"
 80957            }
 80958          ],
 80959          "evidence": {},
 80960          "signature": {
 80961            "signature": {
 80962              "publicKey": {}
 80963            }
 80964          },
 80965          "modelCard": {
 80966            "modelParameters": {
 80967              "approach": {}
 80968            },
 80969            "quantitativeAnalysis": {
 80970              "graphics": {}
 80971            },
 80972            "considerations": {}
 80973          }
 80974        },
 80975        {
 80976          "type": "library",
 80977          "bom-ref": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3\u0026package-id=d3084c788891fb28",
 80978          "supplier": {},
 80979          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 80980          "name": "libcrypto3",
 80981          "version": "3.0.8-r3",
 80982          "description": "Crypto library from openssl",
 80983          "licenses": [
 80984            {
 80985              "license": {
 80986                "id": "Apache-2.0"
 80987              }
 80988            }
 80989          ],
 80990          "cpe": "cpe:2.3:a:libcrypto3:libcrypto3:3.0.8-r3:*:*:*:*:*:*:*",
 80991          "purl": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3",
 80992          "swid": {
 80993            "attachment": {}
 80994          },
 80995          "pedigree": {},
 80996          "externalReferences": [
 80997            {
 80998              "url": "https://www.openssl.org/",
 80999              "type": "distribution"
 81000            }
 81001          ],
 81002          "evidence": {},
 81003          "signature": {
 81004            "signature": {
 81005              "publicKey": {}
 81006            }
 81007          },
 81008          "modelCard": {
 81009            "modelParameters": {
 81010              "approach": {}
 81011            },
 81012            "quantitativeAnalysis": {
 81013              "graphics": {}
 81014            },
 81015            "considerations": {}
 81016          }
 81017        },
 81018        {
 81019          "type": "library",
 81020          "bom-ref": "pkg:apk/alpine/libexpat@2.5.0-r0?arch=x86_64\u0026upstream=expat\u0026distro=alpine-3.17.3\u0026package-id=3230d7655464b5cd",
 81021          "supplier": {},
 81022          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 81023          "name": "libexpat",
 81024          "version": "2.5.0-r0",
 81025          "description": "XML Parser library written in C (libraries)",
 81026          "licenses": [
 81027            {
 81028              "license": {
 81029                "id": "MIT"
 81030              }
 81031            }
 81032          ],
 81033          "cpe": "cpe:2.3:a:libexpat:libexpat:2.5.0-r0:*:*:*:*:*:*:*",
 81034          "purl": "pkg:apk/alpine/libexpat@2.5.0-r0?arch=x86_64\u0026upstream=expat\u0026distro=alpine-3.17.3",
 81035          "swid": {
 81036            "attachment": {}
 81037          },
 81038          "pedigree": {},
 81039          "externalReferences": [
 81040            {
 81041              "url": "https://libexpat.github.io/",
 81042              "type": "distribution"
 81043            }
 81044          ],
 81045          "evidence": {},
 81046          "signature": {
 81047            "signature": {
 81048              "publicKey": {}
 81049            }
 81050          },
 81051          "modelCard": {
 81052            "modelParameters": {
 81053              "approach": {}
 81054            },
 81055            "quantitativeAnalysis": {
 81056              "graphics": {}
 81057            },
 81058            "considerations": {}
 81059          }
 81060        },
 81061        {
 81062          "type": "library",
 81063          "bom-ref": "pkg:apk/alpine/libfontenc@1.1.6-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=4b664e9d006f8d78",
 81064          "supplier": {},
 81065          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 81066          "name": "libfontenc",
 81067          "version": "1.1.6-r0",
 81068          "description": "X11 font encoding library",
 81069          "licenses": [
 81070            {
 81071              "license": {
 81072                "id": "MIT"
 81073              }
 81074            }
 81075          ],
 81076          "cpe": "cpe:2.3:a:libfontenc:libfontenc:1.1.6-r0:*:*:*:*:*:*:*",
 81077          "purl": "pkg:apk/alpine/libfontenc@1.1.6-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 81078          "swid": {
 81079            "attachment": {}
 81080          },
 81081          "pedigree": {},
 81082          "externalReferences": [
 81083            {
 81084              "url": "http://xorg.freedesktop.org/",
 81085              "type": "distribution"
 81086            }
 81087          ],
 81088          "evidence": {},
 81089          "signature": {
 81090            "signature": {
 81091              "publicKey": {}
 81092            }
 81093          },
 81094          "modelCard": {
 81095            "modelParameters": {
 81096              "approach": {}
 81097            },
 81098            "quantitativeAnalysis": {
 81099              "graphics": {}
 81100            },
 81101            "considerations": {}
 81102          }
 81103        },
 81104        {
 81105          "type": "library",
 81106          "bom-ref": "pkg:apk/alpine/libgcc@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.3\u0026package-id=4dbb63d06d9618e9",
 81107          "supplier": {},
 81108          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 81109          "name": "libgcc",
 81110          "version": "12.2.1_git20220924-r4",
 81111          "description": "GNU C compiler runtime libraries",
 81112          "licenses": [
 81113            {
 81114              "license": {
 81115                "id": "GPL-2.0-or-later"
 81116              }
 81117            },
 81118            {
 81119              "license": {
 81120                "id": "LGPL-2.1-or-later"
 81121              }
 81122            }
 81123          ],
 81124          "cpe": "cpe:2.3:a:libgcc:libgcc:12.2.1_git20220924-r4:*:*:*:*:*:*:*",
 81125          "purl": "pkg:apk/alpine/libgcc@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.3",
 81126          "swid": {
 81127            "attachment": {}
 81128          },
 81129          "pedigree": {},
 81130          "externalReferences": [
 81131            {
 81132              "url": "https://gcc.gnu.org",
 81133              "type": "distribution"
 81134            }
 81135          ],
 81136          "evidence": {},
 81137          "signature": {
 81138            "signature": {
 81139              "publicKey": {}
 81140            }
 81141          },
 81142          "modelCard": {
 81143            "modelParameters": {
 81144              "approach": {}
 81145            },
 81146            "quantitativeAnalysis": {
 81147              "graphics": {}
 81148            },
 81149            "considerations": {}
 81150          }
 81151        },
 81152        {
 81153          "type": "library",
 81154          "bom-ref": "pkg:maven/com.googlecode.libphonenumber/libphonenumber@8.0.0?package-id=b82e4d8fbff64d95",
 81155          "supplier": {},
 81156          "group": "com.googlecode.libphonenumber",
 81157          "name": "libphonenumber",
 81158          "version": "8.0.0",
 81159          "licenses": [
 81160            {
 81161              "license": {
 81162                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 81163              }
 81164            }
 81165          ],
 81166          "cpe": "cpe:2.3:a:libphonenumber:libphonenumber:8.0.0:*:*:*:*:*:*:*",
 81167          "purl": "pkg:maven/com.googlecode.libphonenumber/libphonenumber@8.0.0",
 81168          "swid": {
 81169            "attachment": {}
 81170          },
 81171          "pedigree": {},
 81172          "externalReferences": [
 81173            {
 81174              "type": "build-meta",
 81175              "hashes": [
 81176                {
 81177                  "alg": "SHA-1",
 81178                  "content": "ce021971974ee6a26572e43eaba7edf184c3c63d"
 81179                }
 81180              ]
 81181            }
 81182          ],
 81183          "evidence": {},
 81184          "signature": {
 81185            "signature": {
 81186              "publicKey": {}
 81187            }
 81188          },
 81189          "modelCard": {
 81190            "modelParameters": {
 81191              "approach": {}
 81192            },
 81193            "quantitativeAnalysis": {
 81194              "graphics": {}
 81195            },
 81196            "considerations": {}
 81197          }
 81198        },
 81199        {
 81200          "type": "library",
 81201          "bom-ref": "pkg:apk/alpine/libpng@1.6.38-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=de4865c94634be51",
 81202          "supplier": {},
 81203          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 81204          "name": "libpng",
 81205          "version": "1.6.38-r0",
 81206          "description": "Portable Network Graphics library",
 81207          "licenses": [
 81208            {
 81209              "license": {
 81210                "id": "Libpng"
 81211              }
 81212            }
 81213          ],
 81214          "cpe": "cpe:2.3:a:libpng:libpng:1.6.38-r0:*:*:*:*:*:*:*",
 81215          "purl": "pkg:apk/alpine/libpng@1.6.38-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 81216          "swid": {
 81217            "attachment": {}
 81218          },
 81219          "pedigree": {},
 81220          "externalReferences": [
 81221            {
 81222              "url": "http://www.libpng.org",
 81223              "type": "distribution"
 81224            }
 81225          ],
 81226          "evidence": {},
 81227          "signature": {
 81228            "signature": {
 81229              "publicKey": {}
 81230            }
 81231          },
 81232          "modelCard": {
 81233            "modelParameters": {
 81234              "approach": {}
 81235            },
 81236            "quantitativeAnalysis": {
 81237              "graphics": {}
 81238            },
 81239            "considerations": {}
 81240          }
 81241        },
 81242        {
 81243          "type": "library",
 81244          "bom-ref": "pkg:apk/alpine/libretls@3.5.2-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=1539d83bb0f27113",
 81245          "supplier": {},
 81246          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 81247          "name": "libretls",
 81248          "version": "3.5.2-r1",
 81249          "description": "port of libtls from libressl to openssl",
 81250          "licenses": [
 81251            {
 81252              "license": {
 81253                "id": "ISC"
 81254              }
 81255            },
 81256            {
 81257              "license": {
 81258                "name": "AND"
 81259              }
 81260            },
 81261            {
 81262              "license": {
 81263                "name": "("
 81264              }
 81265            },
 81266            {
 81267              "license": {
 81268                "id": "BSD-3-Clause"
 81269              }
 81270            },
 81271            {
 81272              "license": {
 81273                "name": "OR"
 81274              }
 81275            },
 81276            {
 81277              "license": {
 81278                "id": "MIT"
 81279              }
 81280            },
 81281            {
 81282              "license": {
 81283                "name": ")"
 81284              }
 81285            }
 81286          ],
 81287          "cpe": "cpe:2.3:a:libretls:libretls:3.5.2-r1:*:*:*:*:*:*:*",
 81288          "purl": "pkg:apk/alpine/libretls@3.5.2-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 81289          "swid": {
 81290            "attachment": {}
 81291          },
 81292          "pedigree": {},
 81293          "externalReferences": [
 81294            {
 81295              "url": "https://git.causal.agency/libretls/",
 81296              "type": "distribution"
 81297            }
 81298          ],
 81299          "evidence": {},
 81300          "signature": {
 81301            "signature": {
 81302              "publicKey": {}
 81303            }
 81304          },
 81305          "modelCard": {
 81306            "modelParameters": {
 81307              "approach": {}
 81308            },
 81309            "quantitativeAnalysis": {
 81310              "graphics": {}
 81311            },
 81312            "considerations": {}
 81313          }
 81314        },
 81315        {
 81316          "type": "library",
 81317          "bom-ref": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3\u0026package-id=2a95f0251fba7a33",
 81318          "supplier": {},
 81319          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 81320          "name": "libssl3",
 81321          "version": "3.0.8-r3",
 81322          "description": "SSL shared libraries",
 81323          "licenses": [
 81324            {
 81325              "license": {
 81326                "id": "Apache-2.0"
 81327              }
 81328            }
 81329          ],
 81330          "cpe": "cpe:2.3:a:libssl3:libssl3:3.0.8-r3:*:*:*:*:*:*:*",
 81331          "purl": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3",
 81332          "swid": {
 81333            "attachment": {}
 81334          },
 81335          "pedigree": {},
 81336          "externalReferences": [
 81337            {
 81338              "url": "https://www.openssl.org/",
 81339              "type": "distribution"
 81340            }
 81341          ],
 81342          "evidence": {},
 81343          "signature": {
 81344            "signature": {
 81345              "publicKey": {}
 81346            }
 81347          },
 81348          "modelCard": {
 81349            "modelParameters": {
 81350              "approach": {}
 81351            },
 81352            "quantitativeAnalysis": {
 81353              "graphics": {}
 81354            },
 81355            "considerations": {}
 81356          }
 81357        },
 81358        {
 81359          "type": "library",
 81360          "bom-ref": "pkg:apk/alpine/libstdc++@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.3\u0026package-id=3c33807c48d3ddd2",
 81361          "supplier": {},
 81362          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
 81363          "name": "libstdc++",
 81364          "version": "12.2.1_git20220924-r4",
 81365          "description": "GNU C++ standard runtime library",
 81366          "licenses": [
 81367            {
 81368              "license": {
 81369                "id": "GPL-2.0-or-later"
 81370              }
 81371            },
 81372            {
 81373              "license": {
 81374                "id": "LGPL-2.1-or-later"
 81375              }
 81376            }
 81377          ],
 81378          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:12.2.1_git20220924-r4:*:*:*:*:*:*:*",
 81379          "purl": "pkg:apk/alpine/libstdc++@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.3",
 81380          "swid": {
 81381            "attachment": {}
 81382          },
 81383          "pedigree": {},
 81384          "externalReferences": [
 81385            {
 81386              "url": "https://gcc.gnu.org",
 81387              "type": "distribution"
 81388            }
 81389          ],
 81390          "evidence": {},
 81391          "signature": {
 81392            "signature": {
 81393              "publicKey": {}
 81394            }
 81395          },
 81396          "modelCard": {
 81397            "modelParameters": {
 81398              "approach": {}
 81399            },
 81400            "quantitativeAnalysis": {
 81401              "graphics": {}
 81402            },
 81403            "considerations": {}
 81404          }
 81405        },
 81406        {
 81407          "type": "library",
 81408          "bom-ref": "pkg:maven/local_policy/local_policy?package-id=7e5a8ee4262b37db",
 81409          "supplier": {},
 81410          "name": "local_policy",
 81411          "cpe": "cpe:2.3:a:local-policy:local-policy:*:*:*:*:*:*:*:*",
 81412          "purl": "pkg:maven/local_policy/local_policy",
 81413          "swid": {
 81414            "attachment": {}
 81415          },
 81416          "pedigree": {},
 81417          "externalReferences": [
 81418            {
 81419              "type": "build-meta",
 81420              "hashes": [
 81421                {
 81422                  "alg": "SHA-1",
 81423                  "content": "bc70ce9f98d1f3ebcf41bb5e7b92556a5a2d4788"
 81424                }
 81425              ]
 81426            }
 81427          ],
 81428          "evidence": {},
 81429          "signature": {
 81430            "signature": {
 81431              "publicKey": {}
 81432            }
 81433          },
 81434          "modelCard": {
 81435            "modelParameters": {
 81436              "approach": {}
 81437            },
 81438            "quantitativeAnalysis": {
 81439              "graphics": {}
 81440            },
 81441            "considerations": {}
 81442          }
 81443        },
 81444        {
 81445          "type": "library",
 81446          "bom-ref": "pkg:maven/local_policy/local_policy?package-id=6060fa0479e27db5",
 81447          "supplier": {},
 81448          "name": "local_policy",
 81449          "cpe": "cpe:2.3:a:local-policy:local-policy:*:*:*:*:*:*:*:*",
 81450          "purl": "pkg:maven/local_policy/local_policy",
 81451          "swid": {
 81452            "attachment": {}
 81453          },
 81454          "pedigree": {},
 81455          "externalReferences": [
 81456            {
 81457              "type": "build-meta",
 81458              "hashes": [
 81459                {
 81460                  "alg": "SHA-1",
 81461                  "content": "8ab714610f8bf90411dc029a09ecd27c2b60c804"
 81462                }
 81463              ]
 81464            }
 81465          ],
 81466          "evidence": {},
 81467          "signature": {
 81468            "signature": {
 81469              "publicKey": {}
 81470            }
 81471          },
 81472          "modelCard": {
 81473            "modelParameters": {
 81474              "approach": {}
 81475            },
 81476            "quantitativeAnalysis": {
 81477              "graphics": {}
 81478            },
 81479            "considerations": {}
 81480          }
 81481        },
 81482        {
 81483          "type": "library",
 81484          "bom-ref": "pkg:maven/localedata/localedata?package-id=3d9158e219a57e4d",
 81485          "supplier": {},
 81486          "name": "localedata",
 81487          "cpe": "cpe:2.3:a:localedata:localedata:*:*:*:*:*:*:*:*",
 81488          "purl": "pkg:maven/localedata/localedata",
 81489          "swid": {
 81490            "attachment": {}
 81491          },
 81492          "pedigree": {},
 81493          "externalReferences": [
 81494            {
 81495              "type": "build-meta",
 81496              "hashes": [
 81497                {
 81498                  "alg": "SHA-1",
 81499                  "content": "fd7f6a9ee8e6263caca5c369c0bb813702c672c0"
 81500                }
 81501              ]
 81502            }
 81503          ],
 81504          "evidence": {},
 81505          "signature": {
 81506            "signature": {
 81507              "publicKey": {}
 81508            }
 81509          },
 81510          "modelCard": {
 81511            "modelParameters": {
 81512              "approach": {}
 81513            },
 81514            "quantitativeAnalysis": {
 81515              "graphics": {}
 81516            },
 81517            "considerations": {}
 81518          }
 81519        },
 81520        {
 81521          "type": "library",
 81522          "bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-api@2.11.2?package-id=f5b8c58ab6cffd91",
 81523          "supplier": {},
 81524          "group": "org.apache.logging.log4j",
 81525          "name": "log4j-api",
 81526          "version": "2.11.2",
 81527          "licenses": [
 81528            {
 81529              "license": {
 81530                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 81531              }
 81532            }
 81533          ],
 81534          "cpe": "cpe:2.3:a:apache:log4j-api:2.11.2:*:*:*:*:*:*:*",
 81535          "purl": "pkg:maven/org.apache.logging.log4j/log4j-api@2.11.2",
 81536          "swid": {
 81537            "attachment": {}
 81538          },
 81539          "pedigree": {},
 81540          "externalReferences": [
 81541            {
 81542              "type": "build-meta",
 81543              "hashes": [
 81544                {
 81545                  "alg": "SHA-1",
 81546                  "content": "f5e9a2ffca496057d6891a3de65128efc636e26e"
 81547                }
 81548              ]
 81549            }
 81550          ],
 81551          "evidence": {},
 81552          "signature": {
 81553            "signature": {
 81554              "publicKey": {}
 81555            }
 81556          },
 81557          "modelCard": {
 81558            "modelParameters": {
 81559              "approach": {}
 81560            },
 81561            "quantitativeAnalysis": {
 81562              "graphics": {}
 81563            },
 81564            "considerations": {}
 81565          }
 81566        },
 81567        {
 81568          "type": "library",
 81569          "bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.11.2?package-id=d9b1e3bf17e10c2d",
 81570          "supplier": {},
 81571          "group": "org.apache.logging.log4j",
 81572          "name": "log4j-to-slf4j",
 81573          "version": "2.11.2",
 81574          "licenses": [
 81575            {
 81576              "license": {
 81577                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
 81578              }
 81579            }
 81580          ],
 81581          "cpe": "cpe:2.3:a:apache:log4j-to-slf4j:2.11.2:*:*:*:*:*:*:*",
 81582          "purl": "pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.11.2",
 81583          "swid": {
 81584            "attachment": {}
 81585          },
 81586          "pedigree": {},
 81587          "externalReferences": [
 81588            {
 81589              "type": "build-meta",
 81590              "hashes": [
 81591                {
 81592                  "alg": "SHA-1",
 81593                  "content": "6d37bf7b046c0ce2669f26b99365a2cfa45c4c18"
 81594                }
 81595              ]
 81596            }
 81597          ],
 81598          "evidence": {},
 81599          "signature": {
 81600            "signature": {
 81601              "publicKey": {}
 81602            }
 81603          },
 81604          "modelCard": {
 81605            "modelParameters": {
 81606              "approach": {}
 81607            },
 81608            "quantitativeAnalysis": {
 81609              "graphics": {}
 81610            },
 81611            "considerations": {}
 81612          }
 81613        },
 81614        {
 81615          "type": "library",
 81616          "bom-ref": "pkg:maven/logback-classic/logback-classic@1.2.3?package-id=ad06064a9a2cebb",
 81617          "supplier": {},
 81618          "group": "ch.qos.logback",
 81619          "name": "logback-classic",
 81620          "version": "1.2.3",
 81621          "licenses": [
 81622            {
 81623              "license": {
 81624                "name": "http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"
 81625              }
 81626            }
 81627          ],
 81628          "cpe": "cpe:2.3:a:logback-classic:logback-classic:1.2.3:*:*:*:*:*:*:*",
 81629          "purl": "pkg:maven/logback-classic/logback-classic@1.2.3",
 81630          "swid": {
 81631            "attachment": {}
 81632          },
 81633          "pedigree": {},
 81634          "externalReferences": [
 81635            {
 81636              "type": "build-meta",
 81637              "hashes": [
 81638                {
 81639                  "alg": "SHA-1",
 81640                  "content": "7c4f3c474fb2c041d8028740440937705ebb473a"
 81641                }
 81642              ]
 81643            }
 81644          ],
 81645          "evidence": {},
 81646          "signature": {
 81647            "signature": {
 81648              "publicKey": {}
 81649            }
 81650          },
 81651          "modelCard": {
 81652            "modelParameters": {
 81653              "approach": {}
 81654            },
 81655            "quantitativeAnalysis": {
 81656              "graphics": {}
 81657            },
 81658            "considerations": {}
 81659          }
 81660        },
 81661        {
 81662          "type": "library",
 81663          "bom-ref": "pkg:maven/logback-core/logback-core@1.2.3?package-id=ef82ee19623a3120",
 81664          "supplier": {},
 81665          "group": "ch.qos.logback",
 81666          "name": "logback-core",
 81667          "version": "1.2.3",
 81668          "licenses": [
 81669            {
 81670              "license": {
 81671                "name": "http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"
 81672              }
 81673            }
 81674          ],
 81675          "cpe": "cpe:2.3:a:logback-core:logback-core:1.2.3:*:*:*:*:*:*:*",
 81676          "purl": "pkg:maven/logback-core/logback-core@1.2.3",
 81677          "swid": {
 81678            "attachment": {}
 81679          },
 81680          "pedigree": {},
 81681          "externalReferences": [
 81682            {
 81683              "type": "build-meta",
 81684              "hashes": [
 81685                {
 81686                  "alg": "SHA-1",
 81687                  "content": "864344400c3d4d92dfeb0a305dc87d953677c03c"
 81688                }
 81689              ]
 81690            }
 81691          ],
 81692          "evidence": {},
 81693          "signature": {
 81694            "signature": {
 81695              "publicKey": {}
 81696            }
 81697          },
 81698          "modelCard": {
 81699            "modelParameters": {
 81700              "approach": {}
 81701            },
 81702            "quantitativeAnalysis": {
 81703              "graphics": {}
 81704            },
 81705            "considerations": {}
 81706          }
 81707        },
 81708        {
 81709          "type": "library",
 81710          "bom-ref": "pkg:maven/com.squareup.okhttp3/logging-interceptor@3.14.4?package-id=2a00eb19bdc4a32d",
 81711          "supplier": {},
 81712          "group": "com.squareup.okhttp3",
 81713          "name": "logging-interceptor",
 81714          "version": "3.14.4",
 81715          "cpe": "cpe:2.3:a:logging-interceptor:logging-interceptor:3.14.4:*:*:*:*:*:*:*",
 81716          "purl": "pkg:maven/com.squareup.okhttp3/logging-interceptor@3.14.4",
 81717          "swid": {
 81718            "attachment": {}
 81719          },
 81720          "pedigree": {},
 81721          "externalReferences": [
 81722            {
 81723              "type": "build-meta",
 81724              "hashes": [
 81725                {
 81726                  "alg": "SHA-1",
 81727                  "content": "cc6f517fec0ea087ce2b0d8463b2bc2bc3793231"
 81728                }
 81729              ]
 81730            }
 81731          ],
 81732          "evidence": {},
 81733          "signature": {
 81734            "signature": {
 81735              "publicKey": {}
 81736            }
 81737          },
 81738          "modelCard": {
 81739            "modelParameters": {
 81740              "approach": {}
 81741            },
 81742            "quantitativeAnalysis": {
 81743              "graphics": {}
 81744            },
 81745            "considerations": {}
 81746          }
 81747        },
 81748        {
 81749          "type": "library",
 81750          "bom-ref": "pkg:maven/lombok/lombok@1.18.8?package-id=ab91ec026c318e6e",
 81751          "supplier": {},
 81752          "name": "lombok",
 81753          "version": "1.18.8",
 81754          "cpe": "cpe:2.3:a:lombok:lombok:1.18.8:*:*:*:*:*:*:*",
 81755          "purl": "pkg:maven/lombok/lombok@1.18.8",
 81756          "swid": {
 81757            "attachment": {}
 81758          },
 81759          "pedigree": {},
 81760          "externalReferences": [
 81761            {
 81762              "type": "build-meta",
 81763              "hashes": [
 81764                {
 81765                  "alg": "SHA-1",
 81766                  "content": "448003bc1b234aac04b58e27d7755c12c3ec4236"
 81767                }
 81768              ]
 81769            }
 81770          ],
 81771          "evidence": {},
 81772          "signature": {
 81773            "signature": {
 81774              "publicKey": {}
 81775            }
 81776          },
 81777          "modelCard": {
 81778            "modelParameters": {
 81779              "approach": {}
 81780            },
 81781            "quantitativeAnalysis": {
 81782              "graphics": {}
 81783            },
 81784            "considerations": {}
 81785          }
 81786        },
 81787        {
 81788          "type": "library",
 81789          "bom-ref": "pkg:maven/com.sun/mailapi@1.4.3?package-id=6e6806fbaba2063d",
 81790          "supplier": {},
 81791          "group": "javax.mail",
 81792          "name": "mailapi",
 81793          "version": "1.4.3",
 81794          "licenses": [
 81795            {
 81796              "license": {
 81797                "name": "http://www.sun.com/cddl, https://glassfish.dev.java.net/public/CDDL+GPL.html"
 81798              }
 81799            }
 81800          ],
 81801          "cpe": "cpe:2.3:a:sun-microsystems\\,-inc-:mailapi:1.4.3:*:*:*:*:*:*:*",
 81802          "purl": "pkg:maven/com.sun/mailapi@1.4.3",
 81803          "swid": {
 81804            "attachment": {}
 81805          },
 81806          "pedigree": {},
 81807          "externalReferences": [
 81808            {
 81809              "type": "build-meta",
 81810              "hashes": [
 81811                {
 81812                  "alg": "SHA-1",
 81813                  "content": "124600e35d9031da50e5f67661ffa741541f8f6a"
 81814                }
 81815              ]
 81816            }
 81817          ],
 81818          "evidence": {},
 81819          "signature": {
 81820            "signature": {
 81821              "publicKey": {}
 81822            }
 81823          },
 81824          "modelCard": {
 81825            "modelParameters": {
 81826              "approach": {}
 81827            },
 81828            "quantitativeAnalysis": {
 81829              "graphics": {}
 81830            },
 81831            "considerations": {}
 81832          }
 81833        },
 81834        {
 81835          "type": "library",
 81836          "bom-ref": "pkg:maven/management-agent/management-agent?package-id=7defce2ca9e0fee2",
 81837          "supplier": {},
 81838          "name": "management-agent",
 81839          "cpe": "cpe:2.3:a:management-agent:management-agent:*:*:*:*:*:*:*:*",
 81840          "purl": "pkg:maven/management-agent/management-agent",
 81841          "swid": {
 81842            "attachment": {}
 81843          },
 81844          "pedigree": {},
 81845          "externalReferences": [
 81846            {
 81847              "type": "build-meta",
 81848              "hashes": [
 81849                {
 81850                  "alg": "SHA-1",
 81851                  "content": "66e296ac38ffd9d835b2c91f67cde75891e81631"
 81852                }
 81853              ]
 81854            }
 81855          ],
 81856          "evidence": {},
 81857          "signature": {
 81858            "signature": {
 81859              "publicKey": {}
 81860            }
 81861          },
 81862          "modelCard": {
 81863            "modelParameters": {
 81864              "approach": {}
 81865            },
 81866            "quantitativeAnalysis": {
 81867              "graphics": {}
 81868            },
 81869            "considerations": {}
 81870          }
 81871        },
 81872        {
 81873          "type": "library",
 81874          "bom-ref": "pkg:maven/org.mapstruct/mapstruct@1.2.0.Final?package-id=7a50c835c69f0972",
 81875          "supplier": {},
 81876          "group": "org.mapstruct",
 81877          "name": "mapstruct",
 81878          "version": "1.2.0.Final",
 81879          "licenses": [
 81880            {
 81881              "license": {
 81882                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 81883              }
 81884            }
 81885          ],
 81886          "cpe": "cpe:2.3:a:mapstruct:mapstruct:1.2.0.Final:*:*:*:*:*:*:*",
 81887          "purl": "pkg:maven/org.mapstruct/mapstruct@1.2.0.Final",
 81888          "swid": {
 81889            "attachment": {}
 81890          },
 81891          "pedigree": {},
 81892          "externalReferences": [
 81893            {
 81894              "type": "build-meta",
 81895              "hashes": [
 81896                {
 81897                  "alg": "SHA-1",
 81898                  "content": "8609d6eb044e9f6c73cb24c8f2f4ed5c72a249c7"
 81899                }
 81900              ]
 81901            }
 81902          ],
 81903          "evidence": {},
 81904          "signature": {
 81905            "signature": {
 81906              "publicKey": {}
 81907            }
 81908          },
 81909          "modelCard": {
 81910            "modelParameters": {
 81911              "approach": {}
 81912            },
 81913            "quantitativeAnalysis": {
 81914              "graphics": {}
 81915            },
 81916            "considerations": {}
 81917          }
 81918        },
 81919        {
 81920          "type": "library",
 81921          "bom-ref": "pkg:maven/com.mchange/mchange-commons-java@0.2.11?package-id=afa04d632f553a74",
 81922          "supplier": {},
 81923          "name": "mchange-commons-java",
 81924          "version": "0.2.11",
 81925          "cpe": "cpe:2.3:a:mchange-commons-java:mchange-commons-java:0.2.11:*:*:*:*:*:*:*",
 81926          "purl": "pkg:maven/com.mchange/mchange-commons-java@0.2.11",
 81927          "swid": {
 81928            "attachment": {}
 81929          },
 81930          "pedigree": {},
 81931          "externalReferences": [
 81932            {
 81933              "type": "build-meta",
 81934              "hashes": [
 81935                {
 81936                  "alg": "SHA-1",
 81937                  "content": "2a6a6c1fe25f28f5a073171956ce6250813467ef"
 81938                }
 81939              ]
 81940            }
 81941          ],
 81942          "evidence": {},
 81943          "signature": {
 81944            "signature": {
 81945              "publicKey": {}
 81946            }
 81947          },
 81948          "modelCard": {
 81949            "modelParameters": {
 81950              "approach": {}
 81951            },
 81952            "quantitativeAnalysis": {
 81953              "graphics": {}
 81954            },
 81955            "considerations": {}
 81956          }
 81957        },
 81958        {
 81959          "type": "library",
 81960          "bom-ref": "pkg:maven/io.micrometer%23micrometer-core/micrometer-core@1.1.4?package-id=ccc0210511a01c7b",
 81961          "supplier": {},
 81962          "name": "micrometer-core",
 81963          "version": "1.1.4",
 81964          "cpe": "cpe:2.3:a:micrometer\\#micrometer-core:micrometer-core:1.1.4:*:*:*:*:*:*:*",
 81965          "purl": "pkg:maven/io.micrometer%23micrometer-core/micrometer-core@1.1.4",
 81966          "swid": {
 81967            "attachment": {}
 81968          },
 81969          "pedigree": {},
 81970          "externalReferences": [
 81971            {
 81972              "type": "build-meta",
 81973              "hashes": [
 81974                {
 81975                  "alg": "SHA-1",
 81976                  "content": "96eabfe2343a4a4676d215b2122cbbc4d4b6af9b"
 81977                }
 81978              ]
 81979            }
 81980          ],
 81981          "evidence": {},
 81982          "signature": {
 81983            "signature": {
 81984              "publicKey": {}
 81985            }
 81986          },
 81987          "modelCard": {
 81988            "modelParameters": {
 81989              "approach": {}
 81990            },
 81991            "quantitativeAnalysis": {
 81992              "graphics": {}
 81993            },
 81994            "considerations": {}
 81995          }
 81996        },
 81997        {
 81998          "type": "library",
 81999          "bom-ref": "pkg:maven/io.micrometer%23micrometer-registry-prometheus/micrometer-registry-prometheus@1.1.4?package-id=2165dbdf90c3f3fe",
 82000          "supplier": {},
 82001          "name": "micrometer-registry-prometheus",
 82002          "version": "1.1.4",
 82003          "cpe": "cpe:2.3:a:micrometer\\#micrometer-registry-prometheus:micrometer-registry-prometheus:1.1.4:*:*:*:*:*:*:*",
 82004          "purl": "pkg:maven/io.micrometer%23micrometer-registry-prometheus/micrometer-registry-prometheus@1.1.4",
 82005          "swid": {
 82006            "attachment": {}
 82007          },
 82008          "pedigree": {},
 82009          "externalReferences": [
 82010            {
 82011              "type": "build-meta",
 82012              "hashes": [
 82013                {
 82014                  "alg": "SHA-1",
 82015                  "content": "d93021c4f8e9efcb18bc0da79527bf39a0a41bd6"
 82016                }
 82017              ]
 82018            }
 82019          ],
 82020          "evidence": {},
 82021          "signature": {
 82022            "signature": {
 82023              "publicKey": {}
 82024            }
 82025          },
 82026          "modelCard": {
 82027            "modelParameters": {
 82028              "approach": {}
 82029            },
 82030            "quantitativeAnalysis": {
 82031              "graphics": {}
 82032            },
 82033            "considerations": {}
 82034          }
 82035        },
 82036        {
 82037          "type": "library",
 82038          "bom-ref": "pkg:maven/minio/minio@6.0.10?package-id=fcb144a93a782cf8",
 82039          "supplier": {},
 82040          "name": "minio",
 82041          "version": "6.0.10",
 82042          "cpe": "cpe:2.3:a:minio:minio:6.0.10:*:*:*:*:*:*:*",
 82043          "purl": "pkg:maven/minio/minio@6.0.10",
 82044          "swid": {
 82045            "attachment": {}
 82046          },
 82047          "pedigree": {},
 82048          "externalReferences": [
 82049            {
 82050              "type": "build-meta",
 82051              "hashes": [
 82052                {
 82053                  "alg": "SHA-1",
 82054                  "content": "cb7a02912350946087f19b0e4fb24d8ee83db66c"
 82055                }
 82056              ]
 82057            }
 82058          ],
 82059          "evidence": {},
 82060          "signature": {
 82061            "signature": {
 82062              "publicKey": {}
 82063            }
 82064          },
 82065          "modelCard": {
 82066            "modelParameters": {
 82067              "approach": {}
 82068            },
 82069            "quantitativeAnalysis": {
 82070              "graphics": {}
 82071            },
 82072            "considerations": {}
 82073          }
 82074        },
 82075        {
 82076          "type": "library",
 82077          "bom-ref": "pkg:apk/alpine/mkfontscale@1.2.2-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=5556aac06b098482",
 82078          "supplier": {},
 82079          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 82080          "name": "mkfontscale",
 82081          "version": "1.2.2-r1",
 82082          "description": "Scalable font index generator for X",
 82083          "licenses": [
 82084            {
 82085              "license": {
 82086                "id": "MIT"
 82087              }
 82088            }
 82089          ],
 82090          "cpe": "cpe:2.3:a:mkfontscale:mkfontscale:1.2.2-r1:*:*:*:*:*:*:*",
 82091          "purl": "pkg:apk/alpine/mkfontscale@1.2.2-r1?arch=x86_64\u0026distro=alpine-3.17.3",
 82092          "swid": {
 82093            "attachment": {}
 82094          },
 82095          "pedigree": {},
 82096          "externalReferences": [
 82097            {
 82098              "url": "http://xorg.freedesktop.org",
 82099              "type": "distribution"
 82100            }
 82101          ],
 82102          "evidence": {},
 82103          "signature": {
 82104            "signature": {
 82105              "publicKey": {}
 82106            }
 82107          },
 82108          "modelCard": {
 82109            "modelParameters": {
 82110              "approach": {}
 82111            },
 82112            "quantitativeAnalysis": {
 82113              "graphics": {}
 82114            },
 82115            "considerations": {}
 82116          }
 82117        },
 82118        {
 82119          "type": "library",
 82120          "bom-ref": "pkg:maven/com.squareup.moshi/moshi@1.8.0?package-id=8eb943c78a7fb2d3",
 82121          "supplier": {},
 82122          "group": "com.squareup.moshi",
 82123          "name": "moshi",
 82124          "version": "1.8.0",
 82125          "cpe": "cpe:2.3:a:squareup:moshi:1.8.0:*:*:*:*:*:*:*",
 82126          "purl": "pkg:maven/com.squareup.moshi/moshi@1.8.0",
 82127          "swid": {
 82128            "attachment": {}
 82129          },
 82130          "pedigree": {},
 82131          "externalReferences": [
 82132            {
 82133              "type": "build-meta",
 82134              "hashes": [
 82135                {
 82136                  "alg": "SHA-1",
 82137                  "content": "752e7b187599d3ccb174d00ba7235e29add736be"
 82138                }
 82139              ]
 82140            }
 82141          ],
 82142          "evidence": {},
 82143          "signature": {
 82144            "signature": {
 82145              "publicKey": {}
 82146            }
 82147          },
 82148          "modelCard": {
 82149            "modelParameters": {
 82150              "approach": {}
 82151            },
 82152            "quantitativeAnalysis": {
 82153              "graphics": {}
 82154            },
 82155            "considerations": {}
 82156          }
 82157        },
 82158        {
 82159          "type": "library",
 82160          "bom-ref": "pkg:maven/com.github.fge.msg-simple/msg-simple@1.1?package-id=94bbe4cd347987a8",
 82161          "supplier": {},
 82162          "name": "msg-simple",
 82163          "version": "1.1",
 82164          "cpe": "cpe:2.3:a:msg-simple:msg-simple:1.1:*:*:*:*:*:*:*",
 82165          "purl": "pkg:maven/com.github.fge.msg-simple/msg-simple@1.1",
 82166          "swid": {
 82167            "attachment": {}
 82168          },
 82169          "pedigree": {},
 82170          "externalReferences": [
 82171            {
 82172              "type": "build-meta",
 82173              "hashes": [
 82174                {
 82175                  "alg": "SHA-1",
 82176                  "content": "f261263e13dd4cfa93cc6b83f1f58f619097a2c4"
 82177                }
 82178              ]
 82179            }
 82180          ],
 82181          "evidence": {},
 82182          "signature": {
 82183            "signature": {
 82184              "publicKey": {}
 82185            }
 82186          },
 82187          "modelCard": {
 82188            "modelParameters": {
 82189              "approach": {}
 82190            },
 82191            "quantitativeAnalysis": {
 82192              "graphics": {}
 82193            },
 82194            "considerations": {}
 82195          }
 82196        },
 82197        {
 82198          "type": "library",
 82199          "bom-ref": "pkg:maven/org.msgpack/msgpack-core@0.8.18?package-id=d3b0e6957095fda3",
 82200          "supplier": {},
 82201          "name": "msgpack-core",
 82202          "version": "0.8.18",
 82203          "cpe": "cpe:2.3:a:msgpack-core:msgpack-core:0.8.18:*:*:*:*:*:*:*",
 82204          "purl": "pkg:maven/org.msgpack/msgpack-core@0.8.18",
 82205          "swid": {
 82206            "attachment": {}
 82207          },
 82208          "pedigree": {},
 82209          "externalReferences": [
 82210            {
 82211              "type": "build-meta",
 82212              "hashes": [
 82213                {
 82214                  "alg": "SHA-1",
 82215                  "content": "759d77cdc372da2f40db977aafbecfd160a3ff0d"
 82216                }
 82217              ]
 82218            }
 82219          ],
 82220          "evidence": {},
 82221          "signature": {
 82222            "signature": {
 82223              "publicKey": {}
 82224            }
 82225          },
 82226          "modelCard": {
 82227            "modelParameters": {
 82228              "approach": {}
 82229            },
 82230            "quantitativeAnalysis": {
 82231              "graphics": {}
 82232            },
 82233            "considerations": {}
 82234          }
 82235        },
 82236        {
 82237          "type": "library",
 82238          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=d9700f02cf26e8b8",
 82239          "supplier": {},
 82240          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 82241          "name": "musl",
 82242          "version": "1.2.3-r4",
 82243          "description": "the musl c library (libc) implementation",
 82244          "licenses": [
 82245            {
 82246              "license": {
 82247                "id": "MIT"
 82248              }
 82249            }
 82250          ],
 82251          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r4:*:*:*:*:*:*:*",
 82252          "purl": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.3",
 82253          "swid": {
 82254            "attachment": {}
 82255          },
 82256          "pedigree": {},
 82257          "externalReferences": [
 82258            {
 82259              "url": "https://musl.libc.org/",
 82260              "type": "distribution"
 82261            }
 82262          ],
 82263          "evidence": {},
 82264          "signature": {
 82265            "signature": {
 82266              "publicKey": {}
 82267            }
 82268          },
 82269          "modelCard": {
 82270            "modelParameters": {
 82271              "approach": {}
 82272            },
 82273            "quantitativeAnalysis": {
 82274              "graphics": {}
 82275            },
 82276            "considerations": {}
 82277          }
 82278        },
 82279        {
 82280          "type": "library",
 82281          "bom-ref": "pkg:apk/alpine/musl-locales@0.1.0-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2711b5f56d3082dd",
 82282          "supplier": {},
 82283          "publisher": "TBK \u003calpine@jjtc.eu\u003e",
 82284          "name": "musl-locales",
 82285          "version": "0.1.0-r0",
 82286          "description": "Locales support for musl",
 82287          "licenses": [
 82288            {
 82289              "license": {
 82290                "id": "LGPL-3.0-only"
 82291              }
 82292            }
 82293          ],
 82294          "cpe": "cpe:2.3:a:musl-locales:musl-locales:0.1.0-r0:*:*:*:*:*:*:*",
 82295          "purl": "pkg:apk/alpine/musl-locales@0.1.0-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 82296          "swid": {
 82297            "attachment": {}
 82298          },
 82299          "pedigree": {},
 82300          "externalReferences": [
 82301            {
 82302              "url": "https://git.adelielinux.org/adelie/musl-locales/-/wikis/home",
 82303              "type": "distribution"
 82304            }
 82305          ],
 82306          "evidence": {},
 82307          "signature": {
 82308            "signature": {
 82309              "publicKey": {}
 82310            }
 82311          },
 82312          "modelCard": {
 82313            "modelParameters": {
 82314              "approach": {}
 82315            },
 82316            "quantitativeAnalysis": {
 82317              "graphics": {}
 82318            },
 82319            "considerations": {}
 82320          }
 82321        },
 82322        {
 82323          "type": "library",
 82324          "bom-ref": "pkg:apk/alpine/musl-locales-lang@0.1.0-r0?arch=x86_64\u0026upstream=musl-locales\u0026distro=alpine-3.17.3\u0026package-id=a5f7a593669f92ef",
 82325          "supplier": {},
 82326          "publisher": "TBK \u003calpine@jjtc.eu\u003e",
 82327          "name": "musl-locales-lang",
 82328          "version": "0.1.0-r0",
 82329          "description": "Languages for package musl-locales",
 82330          "licenses": [
 82331            {
 82332              "license": {
 82333                "id": "MIT"
 82334              }
 82335            }
 82336          ],
 82337          "cpe": "cpe:2.3:a:musl-locales-lang:musl-locales-lang:0.1.0-r0:*:*:*:*:*:*:*",
 82338          "purl": "pkg:apk/alpine/musl-locales-lang@0.1.0-r0?arch=x86_64\u0026upstream=musl-locales\u0026distro=alpine-3.17.3",
 82339          "swid": {
 82340            "attachment": {}
 82341          },
 82342          "pedigree": {},
 82343          "externalReferences": [
 82344            {
 82345              "url": "https://git.adelielinux.org/adelie/musl-locales/-/wikis/home",
 82346              "type": "distribution"
 82347            }
 82348          ],
 82349          "evidence": {},
 82350          "signature": {
 82351            "signature": {
 82352              "publicKey": {}
 82353            }
 82354          },
 82355          "modelCard": {
 82356            "modelParameters": {
 82357              "approach": {}
 82358            },
 82359            "quantitativeAnalysis": {
 82360              "graphics": {}
 82361            },
 82362            "considerations": {}
 82363          }
 82364        },
 82365        {
 82366          "type": "library",
 82367          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.3\u0026package-id=f71ecf5267e6c37b",
 82368          "supplier": {},
 82369          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 82370          "name": "musl-utils",
 82371          "version": "1.2.3-r4",
 82372          "description": "the musl c library (libc) implementation",
 82373          "licenses": [
 82374            {
 82375              "license": {
 82376                "id": "MIT"
 82377              }
 82378            },
 82379            {
 82380              "license": {
 82381                "name": "AND"
 82382              }
 82383            },
 82384            {
 82385              "license": {
 82386                "id": "BSD-2-Clause"
 82387              }
 82388            },
 82389            {
 82390              "license": {
 82391                "name": "AND"
 82392              }
 82393            },
 82394            {
 82395              "license": {
 82396                "id": "GPL-2.0-or-later"
 82397              }
 82398            }
 82399          ],
 82400          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r4:*:*:*:*:*:*:*",
 82401          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.3",
 82402          "swid": {
 82403            "attachment": {}
 82404          },
 82405          "pedigree": {},
 82406          "externalReferences": [
 82407            {
 82408              "url": "https://musl.libc.org/",
 82409              "type": "distribution"
 82410            }
 82411          ],
 82412          "evidence": {},
 82413          "signature": {
 82414            "signature": {
 82415              "publicKey": {}
 82416            }
 82417          },
 82418          "modelCard": {
 82419            "modelParameters": {
 82420              "approach": {}
 82421            },
 82422            "quantitativeAnalysis": {
 82423              "graphics": {}
 82424            },
 82425            "considerations": {}
 82426          }
 82427        },
 82428        {
 82429          "type": "library",
 82430          "bom-ref": "pkg:maven/com.mysema.commons/mysema-commons-lang@0.2.4?package-id=ca757d3681d8b371",
 82431          "supplier": {},
 82432          "group": "com.mysema.commons",
 82433          "name": "mysema-commons-lang",
 82434          "version": "0.2.4",
 82435          "cpe": "cpe:2.3:a:mysema-commons-lang:mysema-commons-lang:0.2.4:*:*:*:*:*:*:*",
 82436          "purl": "pkg:maven/com.mysema.commons/mysema-commons-lang@0.2.4",
 82437          "swid": {
 82438            "attachment": {}
 82439          },
 82440          "pedigree": {},
 82441          "externalReferences": [
 82442            {
 82443              "type": "build-meta",
 82444              "hashes": [
 82445                {
 82446                  "alg": "SHA-1",
 82447                  "content": "d09c8489d54251a6c22fbce804bdd4a070557317"
 82448                }
 82449              ]
 82450            }
 82451          ],
 82452          "evidence": {},
 82453          "signature": {
 82454            "signature": {
 82455              "publicKey": {}
 82456            }
 82457          },
 82458          "modelCard": {
 82459            "modelParameters": {
 82460              "approach": {}
 82461            },
 82462            "quantitativeAnalysis": {
 82463              "graphics": {}
 82464            },
 82465            "considerations": {}
 82466          }
 82467        },
 82468        {
 82469          "type": "library",
 82470          "bom-ref": "pkg:maven/com.mysql.cj/mysql-connector-java@8.0.16?package-id=87023fda3dd7994a",
 82471          "supplier": {},
 82472          "name": "mysql-connector-java",
 82473          "version": "8.0.16",
 82474          "cpe": "cpe:2.3:a:mysql-connector-java:mysql-connector-java:8.0.16:*:*:*:*:*:*:*",
 82475          "purl": "pkg:maven/com.mysql.cj/mysql-connector-java@8.0.16",
 82476          "swid": {
 82477            "attachment": {}
 82478          },
 82479          "pedigree": {},
 82480          "externalReferences": [
 82481            {
 82482              "type": "build-meta",
 82483              "hashes": [
 82484                {
 82485                  "alg": "SHA-1",
 82486                  "content": "06088b7a25188ab4b3ab865422a8ec77ade29236"
 82487                }
 82488              ]
 82489            }
 82490          ],
 82491          "evidence": {},
 82492          "signature": {
 82493            "signature": {
 82494              "publicKey": {}
 82495            }
 82496          },
 82497          "modelCard": {
 82498            "modelParameters": {
 82499              "approach": {}
 82500            },
 82501            "quantitativeAnalysis": {
 82502              "graphics": {}
 82503            },
 82504            "considerations": {}
 82505          }
 82506        },
 82507        {
 82508          "type": "library",
 82509          "bom-ref": "pkg:maven/nashorn/nashorn@1.8.0_362-b09?package-id=ff4e7f4643e3b763",
 82510          "supplier": {},
 82511          "name": "nashorn",
 82512          "version": "1.8.0_362-b09",
 82513          "cpe": "cpe:2.3:a:oracle-corporation:nashorn:1.8.0_362-b09:*:*:*:*:*:*:*",
 82514          "purl": "pkg:maven/nashorn/nashorn@1.8.0_362-b09",
 82515          "swid": {
 82516            "attachment": {}
 82517          },
 82518          "pedigree": {},
 82519          "externalReferences": [
 82520            {
 82521              "type": "build-meta",
 82522              "hashes": [
 82523                {
 82524                  "alg": "SHA-1",
 82525                  "content": "85cadde4959b1188714a9d6bfde1304027f07e36"
 82526                }
 82527              ]
 82528            }
 82529          ],
 82530          "evidence": {},
 82531          "signature": {
 82532            "signature": {
 82533              "publicKey": {}
 82534            }
 82535          },
 82536          "modelCard": {
 82537            "modelParameters": {
 82538              "approach": {}
 82539            },
 82540            "quantitativeAnalysis": {
 82541              "graphics": {}
 82542            },
 82543            "considerations": {}
 82544          }
 82545        },
 82546        {
 82547          "type": "library",
 82548          "bom-ref": "pkg:maven/com.aayushatharva.brotli4j/native-linux-x86_64@1.8.0?package-id=e5ee98086c12cac9",
 82549          "supplier": {},
 82550          "group": "com.aayushatharva.brotli4j",
 82551          "name": "native-linux-x86_64",
 82552          "version": "1.8.0",
 82553          "cpe": "cpe:2.3:a:native-linux-x86-64:native-linux-x86-64:1.8.0:*:*:*:*:*:*:*",
 82554          "purl": "pkg:maven/com.aayushatharva.brotli4j/native-linux-x86_64@1.8.0",
 82555          "swid": {
 82556            "attachment": {}
 82557          },
 82558          "pedigree": {},
 82559          "externalReferences": [
 82560            {
 82561              "type": "build-meta",
 82562              "hashes": [
 82563                {
 82564                  "alg": "SHA-1",
 82565                  "content": "add74b11206e3a6ff14c7405718a0b61abae9a75"
 82566                }
 82567              ]
 82568            }
 82569          ],
 82570          "evidence": {},
 82571          "signature": {
 82572            "signature": {
 82573              "publicKey": {}
 82574            }
 82575          },
 82576          "modelCard": {
 82577            "modelParameters": {
 82578              "approach": {}
 82579            },
 82580            "quantitativeAnalysis": {
 82581              "graphics": {}
 82582            },
 82583            "considerations": {}
 82584          }
 82585        },
 82586        {
 82587          "type": "library",
 82588          "bom-ref": "pkg:maven/io.netty/netty-buffer@4.1.36.Final?package-id=a9bb5bb445fbc318",
 82589          "supplier": {},
 82590          "group": "io.netty",
 82591          "name": "netty-buffer",
 82592          "version": "4.1.36.Final",
 82593          "licenses": [
 82594            {
 82595              "license": {
 82596                "name": "http://www.apache.org/licenses/LICENSE-2.0"
 82597              }
 82598            }
 82599          ],
 82600          "cpe": "cpe:2.3:a:netty-project:netty-buffer:4.1.36.Final:*:*:*:*:*:*:*",
 82601          "purl": "pkg:maven/io.netty/netty-buffer@4.1.36.Final",
 82602          "swid": {
 82603            "attachment": {}
 82604          },
 82605          "pedigree": {},
 82606          "externalReferences": [
 82607            {
 82608              "type": "build-meta",
 82609              "hashes": [
 82610                {
 82611                  "alg": "SHA-1",
 82612                  "content": "7f2db0921dd57df4db076229830ab09bba713aeb"
 82613                }
 82614              ]
 82615            }
 82616          ],
 82617          "evidence": {},
 82618          "signature": {
 82619            "signature": {
 82620              "publicKey": {}
 82621            }
 82622          },
 82623          "modelCard": {
 82624            "modelParameters": {
 82625              "approach": {}
 82626            },
 82627            "quantitativeAnalysis": {
 82628              "graphics": {}
 82629            },
 82630            "considerations": {}
 82631          }
 82632        },
 82633        {
 82634          "type": "library",
 82635          "bom-ref": "pkg:maven/io.netty/netty-codec@4.1.36.Final?package-id=b9ddfe5a6c41b46a",
 82636          "supplier": {},
 82637          "group": "io.netty",
 82638          "name": "netty-codec",
 82639          "version": "4.1.36.Final",
 82640          "licenses": [
 82641            {
 82642              "license": {
 82643                "name": "http://www.apache.org/licenses/LICENSE-2.0"
 82644              }
 82645            }
 82646          ],
 82647          "cpe": "cpe:2.3:a:netty-project:netty-codec:4.1.36.Final:*:*:*:*:*:*:*",
 82648          "purl": "pkg:maven/io.netty/netty-codec@4.1.36.Final",
 82649          "swid": {
 82650            "attachment": {}
 82651          },
 82652          "pedigree": {},
 82653          "externalReferences": [
 82654            {
 82655              "type": "build-meta",
 82656              "hashes": [
 82657                {
 82658                  "alg": "SHA-1",
 82659                  "content": "8462116d327bb3d1ec24258071f2e7345a73dbfc"
 82660                }
 82661              ]
 82662            }
 82663          ],
 82664          "evidence": {},
 82665          "signature": {
 82666            "signature": {
 82667              "publicKey": {}
 82668            }
 82669          },
 82670          "modelCard": {
 82671            "modelParameters": {
 82672              "approach": {}
 82673            },
 82674            "quantitativeAnalysis": {
 82675              "graphics": {}
 82676            },
 82677            "considerations": {}
 82678          }
 82679        },
 82680        {
 82681          "type": "library",
 82682          "bom-ref": "pkg:maven/io.netty/netty-common@4.1.36.Final?package-id=4fedc371f6835980",
 82683          "supplier": {},
 82684          "group": "io.netty",
 82685          "name": "netty-common",
 82686          "version": "4.1.36.Final",
 82687          "licenses": [
 82688            {
 82689              "license": {
 82690                "name": "http://www.apache.org/licenses/LICENSE-2.0"
 82691              }
 82692            }
 82693          ],
 82694          "cpe": "cpe:2.3:a:netty-project:netty-common:4.1.36.Final:*:*:*:*:*:*:*",
 82695          "purl": "pkg:maven/io.netty/netty-common@4.1.36.Final",
 82696          "swid": {
 82697            "attachment": {}
 82698          },
 82699          "pedigree": {},
 82700          "externalReferences": [
 82701            {
 82702              "type": "build-meta",
 82703              "hashes": [
 82704                {
 82705                  "alg": "SHA-1",
 82706                  "content": "f6f38fde652a70ea579897edc80e52353e487ae6"
 82707                }
 82708              ]
 82709            }
 82710          ],
 82711          "evidence": {},
 82712          "signature": {
 82713            "signature": {
 82714              "publicKey": {}
 82715            }
 82716          },
 82717          "modelCard": {
 82718            "modelParameters": {
 82719              "approach": {}
 82720            },
 82721            "quantitativeAnalysis": {
 82722              "graphics": {}
 82723            },
 82724            "considerations": {}
 82725          }
 82726        },
 82727        {
 82728          "type": "library",
 82729          "bom-ref": "pkg:maven/io.netty/netty-handler@4.1.36.Final?package-id=70b0afab5f3932a1",
 82730          "supplier": {},
 82731          "group": "io.netty",
 82732          "name": "netty-handler",
 82733          "version": "4.1.36.Final",
 82734          "licenses": [
 82735            {
 82736              "license": {
 82737                "name": "http://www.apache.org/licenses/LICENSE-2.0"
 82738              }
 82739            }
 82740          ],
 82741          "cpe": "cpe:2.3:a:netty-handler:netty-handler:4.1.36.Final:*:*:*:*:*:*:*",
 82742          "purl": "pkg:maven/io.netty/netty-handler@4.1.36.Final",
 82743          "swid": {
 82744            "attachment": {}
 82745          },
 82746          "pedigree": {},
 82747          "externalReferences": [
 82748            {
 82749              "type": "build-meta",
 82750              "hashes": [
 82751                {
 82752                  "alg": "SHA-1",
 82753                  "content": "1c38a5920a10c01b1cce4cdc964447ec76abf1b5"
 82754                }
 82755              ]
 82756            }
 82757          ],
 82758          "evidence": {},
 82759          "signature": {
 82760            "signature": {
 82761              "publicKey": {}
 82762            }
 82763          },
 82764          "modelCard": {
 82765            "modelParameters": {
 82766              "approach": {}
 82767            },
 82768            "quantitativeAnalysis": {
 82769              "graphics": {}
 82770            },
 82771            "considerations": {}
 82772          }
 82773        },
 82774        {
 82775          "type": "library",
 82776          "bom-ref": "pkg:maven/io.netty/netty-resolver@4.1.36.Final?package-id=a82008d74dd2c81c",
 82777          "supplier": {},
 82778          "group": "io.netty",
 82779          "name": "netty-resolver",
 82780          "version": "4.1.36.Final",
 82781          "licenses": [
 82782            {
 82783              "license": {
 82784                "name": "http://www.apache.org/licenses/LICENSE-2.0"
 82785              }
 82786            }
 82787          ],
 82788          "cpe": "cpe:2.3:a:netty-resolver:netty-resolver:4.1.36.Final:*:*:*:*:*:*:*",
 82789          "purl": "pkg:maven/io.netty/netty-resolver@4.1.36.Final",
 82790          "swid": {
 82791            "attachment": {}
 82792          },
 82793          "pedigree": {},
 82794          "externalReferences": [
 82795            {
 82796              "type": "build-meta",
 82797              "hashes": [
 82798                {
 82799                  "alg": "SHA-1",
 82800                  "content": "e4d243fbf4e6837fa294f892bf97149e18129100"
 82801                }
 82802              ]
 82803            }
 82804          ],
 82805          "evidence": {},
 82806          "signature": {
 82807            "signature": {
 82808              "publicKey": {}
 82809            }
 82810          },
 82811          "modelCard": {
 82812            "modelParameters": {
 82813              "approach": {}
 82814            },
 82815            "quantitativeAnalysis": {
 82816              "graphics": {}
 82817            },
 82818            "considerations": {}
 82819          }
 82820        },
 82821        {
 82822          "type": "library",
 82823          "bom-ref": "pkg:maven/io.netty/netty-transport@4.1.36.Final?package-id=eae6562d50f1c7e0",
 82824          "supplier": {},
 82825          "group": "io.netty",
 82826          "name": "netty-transport",
 82827          "version": "4.1.36.Final",
 82828          "licenses": [
 82829            {
 82830              "license": {
 82831                "name": "http://www.apache.org/licenses/LICENSE-2.0"
 82832              }
 82833            }
 82834          ],
 82835          "cpe": "cpe:2.3:a:netty-transport:netty-transport:4.1.36.Final:*:*:*:*:*:*:*",
 82836          "purl": "pkg:maven/io.netty/netty-transport@4.1.36.Final",
 82837          "swid": {
 82838            "attachment": {}
 82839          },
 82840          "pedigree": {},
 82841          "externalReferences": [
 82842            {
 82843              "type": "build-meta",
 82844              "hashes": [
 82845                {
 82846                  "alg": "SHA-1",
 82847                  "content": "8546e6be47be587acab86bbd106ca023678f07d9"
 82848                }
 82849              ]
 82850            }
 82851          ],
 82852          "evidence": {},
 82853          "signature": {
 82854            "signature": {
 82855              "publicKey": {}
 82856            }
 82857          },
 82858          "modelCard": {
 82859            "modelParameters": {
 82860              "approach": {}
 82861            },
 82862            "quantitativeAnalysis": {
 82863              "graphics": {}
 82864            },
 82865            "considerations": {}
 82866          }
 82867        },
 82868        {
 82869          "type": "library",
 82870          "bom-ref": "pkg:maven/com.narupley/not-going-to-be-commons-ssl@0.3.20?package-id=9a518042b6c8e721",
 82871          "supplier": {},
 82872          "group": "com.narupley",
 82873          "name": "not-going-to-be-commons-ssl",
 82874          "version": "0.3.20",
 82875          "cpe": "cpe:2.3:a:not-going-to-be-commons-ssl:not-going-to-be-commons-ssl:0.3.20:*:*:*:*:*:*:*",
 82876          "purl": "pkg:maven/com.narupley/not-going-to-be-commons-ssl@0.3.20",
 82877          "swid": {
 82878            "attachment": {}
 82879          },
 82880          "pedigree": {},
 82881          "externalReferences": [
 82882            {
 82883              "type": "build-meta",
 82884              "hashes": [
 82885                {
 82886                  "alg": "SHA-1",
 82887                  "content": "7502c294b7fea7abbd171a7df15fed3bdb1e368c"
 82888                }
 82889              ]
 82890            }
 82891          ],
 82892          "evidence": {},
 82893          "signature": {
 82894            "signature": {
 82895              "publicKey": {}
 82896            }
 82897          },
 82898          "modelCard": {
 82899            "modelParameters": {
 82900              "approach": {}
 82901            },
 82902            "quantitativeAnalysis": {
 82903              "graphics": {}
 82904            },
 82905            "considerations": {}
 82906          }
 82907        },
 82908        {
 82909          "type": "library",
 82910          "bom-ref": "pkg:maven/com.squareup.okhttp3/okhttp@3.14.4?package-id=23c40bcc187e27fc",
 82911          "supplier": {},
 82912          "group": "com.squareup.okhttp3",
 82913          "name": "okhttp",
 82914          "version": "3.14.4",
 82915          "cpe": "cpe:2.3:a:squareup:okhttp:3.14.4:*:*:*:*:*:*:*",
 82916          "purl": "pkg:maven/com.squareup.okhttp3/okhttp@3.14.4",
 82917          "swid": {
 82918            "attachment": {}
 82919          },
 82920          "pedigree": {},
 82921          "externalReferences": [
 82922            {
 82923              "type": "build-meta",
 82924              "hashes": [
 82925                {
 82926                  "alg": "SHA-1",
 82927                  "content": "4f6f76315e70d9af39a1125dc6ff7145e26e3040"
 82928                }
 82929              ]
 82930            }
 82931          ],
 82932          "evidence": {},
 82933          "signature": {
 82934            "signature": {
 82935              "publicKey": {}
 82936            }
 82937          },
 82938          "modelCard": {
 82939            "modelParameters": {
 82940              "approach": {}
 82941            },
 82942            "quantitativeAnalysis": {
 82943              "graphics": {}
 82944            },
 82945            "considerations": {}
 82946          }
 82947        },
 82948        {
 82949          "type": "library",
 82950          "bom-ref": "pkg:maven/com.squareup.okio/okio@1.17.2?package-id=4337d80b6f1956cf",
 82951          "supplier": {},
 82952          "group": "com.squareup.okio",
 82953          "name": "okio",
 82954          "version": "1.17.2",
 82955          "cpe": "cpe:2.3:a:squareup:okio:1.17.2:*:*:*:*:*:*:*",
 82956          "purl": "pkg:maven/com.squareup.okio/okio@1.17.2",
 82957          "swid": {
 82958            "attachment": {}
 82959          },
 82960          "pedigree": {},
 82961          "externalReferences": [
 82962            {
 82963              "type": "build-meta",
 82964              "hashes": [
 82965                {
 82966                  "alg": "SHA-1",
 82967                  "content": "78c7820b205002da4d2d137f6f312bd64b3d6049"
 82968                }
 82969              ]
 82970            }
 82971          ],
 82972          "evidence": {},
 82973          "signature": {
 82974            "signature": {
 82975              "publicKey": {}
 82976            }
 82977          },
 82978          "modelCard": {
 82979            "modelParameters": {
 82980              "approach": {}
 82981            },
 82982            "quantitativeAnalysis": {
 82983              "graphics": {}
 82984            },
 82985            "considerations": {}
 82986          }
 82987        },
 82988        {
 82989          "type": "library",
 82990          "bom-ref": "pkg:maven/org.opensaml/opensaml@2.6.6?package-id=4a274fe72cc9d6cf",
 82991          "supplier": {},
 82992          "group": "org.opensaml",
 82993          "name": "opensaml",
 82994          "version": "2.6.6",
 82995          "cpe": "cpe:2.3:a:www-opensaml-org:opensaml:2.6.6:*:*:*:*:*:*:*",
 82996          "purl": "pkg:maven/org.opensaml/opensaml@2.6.6",
 82997          "swid": {
 82998            "attachment": {}
 82999          },
 83000          "pedigree": {},
 83001          "externalReferences": [
 83002            {
 83003              "type": "build-meta",
 83004              "hashes": [
 83005                {
 83006                  "alg": "SHA-1",
 83007                  "content": "2d2ea39a37920fa1c21330b5730619703421e839"
 83008                }
 83009              ]
 83010            }
 83011          ],
 83012          "evidence": {},
 83013          "signature": {
 83014            "signature": {
 83015              "publicKey": {}
 83016            }
 83017          },
 83018          "modelCard": {
 83019            "modelParameters": {
 83020              "approach": {}
 83021            },
 83022            "quantitativeAnalysis": {
 83023              "graphics": {}
 83024            },
 83025            "considerations": {}
 83026          }
 83027        },
 83028        {
 83029          "type": "library",
 83030          "bom-ref": "pkg:maven/org.opensaml/openws@1.5.6?package-id=8d9c40aa3753a22a",
 83031          "supplier": {},
 83032          "group": "org.opensaml",
 83033          "name": "openws",
 83034          "version": "1.5.6",
 83035          "cpe": "cpe:2.3:a:world-wide-web-consortium-\\(w3c\\):openws:1.5.6:*:*:*:*:*:*:*",
 83036          "purl": "pkg:maven/org.opensaml/openws@1.5.6",
 83037          "swid": {
 83038            "attachment": {}
 83039          },
 83040          "pedigree": {},
 83041          "externalReferences": [
 83042            {
 83043              "type": "build-meta",
 83044              "hashes": [
 83045                {
 83046                  "alg": "SHA-1",
 83047                  "content": "53c9e39201fb588b42ea4059fa062ced76acba01"
 83048                }
 83049              ]
 83050            }
 83051          ],
 83052          "evidence": {},
 83053          "signature": {
 83054            "signature": {
 83055              "publicKey": {}
 83056            }
 83057          },
 83058          "modelCard": {
 83059            "modelParameters": {
 83060              "approach": {}
 83061            },
 83062            "quantitativeAnalysis": {
 83063              "graphics": {}
 83064            },
 83065            "considerations": {}
 83066          }
 83067        },
 83068        {
 83069          "type": "library",
 83070          "bom-ref": "pkg:maven/org.eclipse.jgit/org.eclipse.jgit@5.13.1.202206130422-r?package-id=9714452b7fbcfb43",
 83071          "supplier": {},
 83072          "group": "org.eclipse.jgit",
 83073          "name": "org.eclipse.jgit",
 83074          "version": "5.13.1.202206130422-r",
 83075          "cpe": "cpe:2.3:a:eclipse-org---jgit:org.eclipse.jgit:5.13.1.202206130422-r:*:*:*:*:*:*:*",
 83076          "purl": "pkg:maven/org.eclipse.jgit/org.eclipse.jgit@5.13.1.202206130422-r",
 83077          "swid": {
 83078            "attachment": {}
 83079          },
 83080          "pedigree": {},
 83081          "externalReferences": [
 83082            {
 83083              "type": "build-meta",
 83084              "hashes": [
 83085                {
 83086                  "alg": "SHA-1",
 83087                  "content": "841d1ae74e4bc77ac7d4b106f15d0468dc7ac7f2"
 83088                }
 83089              ]
 83090            }
 83091          ],
 83092          "evidence": {},
 83093          "signature": {
 83094            "signature": {
 83095              "publicKey": {}
 83096            }
 83097          },
 83098          "modelCard": {
 83099            "modelParameters": {
 83100              "approach": {}
 83101            },
 83102            "quantitativeAnalysis": {
 83103              "graphics": {}
 83104            },
 83105            "considerations": {}
 83106          }
 83107        },
 83108        {
 83109          "type": "library",
 83110          "bom-ref": "pkg:maven/org.eclipse.jgit/org.eclipse.jgit.ssh.apache@5.13.1.202206130422-r?package-id=85d3061f76a668a4",
 83111          "supplier": {},
 83112          "group": "org.eclipse.jgit",
 83113          "name": "org.eclipse.jgit.ssh.apache",
 83114          "version": "5.13.1.202206130422-r",
 83115          "cpe": "cpe:2.3:a:apache:org.eclipse.jgit.ssh.apache:5.13.1.202206130422-r:*:*:*:*:*:*:*",
 83116          "purl": "pkg:maven/org.eclipse.jgit/org.eclipse.jgit.ssh.apache@5.13.1.202206130422-r",
 83117          "swid": {
 83118            "attachment": {}
 83119          },
 83120          "pedigree": {},
 83121          "externalReferences": [
 83122            {
 83123              "type": "build-meta",
 83124              "hashes": [
 83125                {
 83126                  "alg": "SHA-1",
 83127                  "content": "7c6b09b55dc9a3325a92ae81b45161a76f083ae5"
 83128                }
 83129              ]
 83130            }
 83131          ],
 83132          "evidence": {},
 83133          "signature": {
 83134            "signature": {
 83135              "publicKey": {}
 83136            }
 83137          },
 83138          "modelCard": {
 83139            "modelParameters": {
 83140              "approach": {}
 83141            },
 83142            "quantitativeAnalysis": {
 83143              "graphics": {}
 83144            },
 83145            "considerations": {}
 83146          }
 83147        },
 83148        {
 83149          "type": "library",
 83150          "bom-ref": "pkg:maven/org.pcollections/pcollections@3.0.3?package-id=e478f8055b5234ad",
 83151          "supplier": {},
 83152          "group": "org.pcollections",
 83153          "name": "pcollections",
 83154          "version": "3.0.3",
 83155          "cpe": "cpe:2.3:a:pcollections:pcollections:3.0.3:*:*:*:*:*:*:*",
 83156          "purl": "pkg:maven/org.pcollections/pcollections@3.0.3",
 83157          "swid": {
 83158            "attachment": {}
 83159          },
 83160          "pedigree": {},
 83161          "evidence": {},
 83162          "signature": {
 83163            "signature": {
 83164              "publicKey": {}
 83165            }
 83166          },
 83167          "modelCard": {
 83168            "modelParameters": {
 83169              "approach": {}
 83170            },
 83171            "quantitativeAnalysis": {
 83172              "graphics": {}
 83173            },
 83174            "considerations": {}
 83175          }
 83176        },
 83177        {
 83178          "type": "library",
 83179          "bom-ref": "pkg:maven/org.quartz-scheduler/quartz@2.3.0?package-id=823d2b12e5e6644d",
 83180          "supplier": {},
 83181          "group": "org.quartz-scheduler",
 83182          "name": "quartz",
 83183          "version": "2.3.0",
 83184          "licenses": [
 83185            {
 83186              "license": {
 83187                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 83188              }
 83189            }
 83190          ],
 83191          "cpe": "cpe:2.3:a:quartz-scheduler:quartz:2.3.0:*:*:*:*:*:*:*",
 83192          "purl": "pkg:maven/org.quartz-scheduler/quartz@2.3.0",
 83193          "swid": {
 83194            "attachment": {}
 83195          },
 83196          "pedigree": {},
 83197          "externalReferences": [
 83198            {
 83199              "type": "build-meta",
 83200              "hashes": [
 83201                {
 83202                  "alg": "SHA-1",
 83203                  "content": "a090397102a12f6241177c5d501835334bb7662a"
 83204                }
 83205              ]
 83206            }
 83207          ],
 83208          "evidence": {},
 83209          "signature": {
 83210            "signature": {
 83211              "publicKey": {}
 83212            }
 83213          },
 83214          "modelCard": {
 83215            "modelParameters": {
 83216              "approach": {}
 83217            },
 83218            "quantitativeAnalysis": {
 83219              "graphics": {}
 83220            },
 83221            "considerations": {}
 83222          }
 83223        },
 83224        {
 83225          "type": "library",
 83226          "bom-ref": "pkg:maven/com.querydsl/querydsl-apt@4.1.4?package-id=e06cff1c1262978a",
 83227          "supplier": {},
 83228          "group": "com.querydsl",
 83229          "name": "querydsl-apt",
 83230          "version": "4.1.4",
 83231          "licenses": [
 83232            {
 83233              "license": {
 83234                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 83235              }
 83236            }
 83237          ],
 83238          "cpe": "cpe:2.3:a:querydsl-apt:querydsl-apt:4.1.4:*:*:*:*:*:*:*",
 83239          "purl": "pkg:maven/com.querydsl/querydsl-apt@4.1.4",
 83240          "swid": {
 83241            "attachment": {}
 83242          },
 83243          "pedigree": {},
 83244          "externalReferences": [
 83245            {
 83246              "type": "build-meta",
 83247              "hashes": [
 83248                {
 83249                  "alg": "SHA-1",
 83250                  "content": "51e33839a6b124d975bb0e7f909652024eed9f3a"
 83251                }
 83252              ]
 83253            }
 83254          ],
 83255          "evidence": {},
 83256          "signature": {
 83257            "signature": {
 83258              "publicKey": {}
 83259            }
 83260          },
 83261          "modelCard": {
 83262            "modelParameters": {
 83263              "approach": {}
 83264            },
 83265            "quantitativeAnalysis": {
 83266              "graphics": {}
 83267            },
 83268            "considerations": {}
 83269          }
 83270        },
 83271        {
 83272          "type": "library",
 83273          "bom-ref": "pkg:maven/com.querydsl/querydsl-codegen@4.1.4?package-id=1a3db74ac1cb54ea",
 83274          "supplier": {},
 83275          "group": "com.querydsl",
 83276          "name": "querydsl-codegen",
 83277          "version": "4.1.4",
 83278          "licenses": [
 83279            {
 83280              "license": {
 83281                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 83282              }
 83283            }
 83284          ],
 83285          "cpe": "cpe:2.3:a:querydsl-codegen:querydsl-codegen:4.1.4:*:*:*:*:*:*:*",
 83286          "purl": "pkg:maven/com.querydsl/querydsl-codegen@4.1.4",
 83287          "swid": {
 83288            "attachment": {}
 83289          },
 83290          "pedigree": {},
 83291          "externalReferences": [
 83292            {
 83293              "type": "build-meta",
 83294              "hashes": [
 83295                {
 83296                  "alg": "SHA-1",
 83297                  "content": "e67a1c8822a501bfeb174922246e430a7ccd6780"
 83298                }
 83299              ]
 83300            }
 83301          ],
 83302          "evidence": {},
 83303          "signature": {
 83304            "signature": {
 83305              "publicKey": {}
 83306            }
 83307          },
 83308          "modelCard": {
 83309            "modelParameters": {
 83310              "approach": {}
 83311            },
 83312            "quantitativeAnalysis": {
 83313              "graphics": {}
 83314            },
 83315            "considerations": {}
 83316          }
 83317        },
 83318        {
 83319          "type": "library",
 83320          "bom-ref": "pkg:maven/com.querydsl/querydsl-core@4.2.1?package-id=1af52076afe0efb6",
 83321          "supplier": {},
 83322          "group": "com.querydsl",
 83323          "name": "querydsl-core",
 83324          "version": "4.2.1",
 83325          "licenses": [
 83326            {
 83327              "license": {
 83328                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 83329              }
 83330            }
 83331          ],
 83332          "cpe": "cpe:2.3:a:querydsl-core:querydsl-core:4.2.1:*:*:*:*:*:*:*",
 83333          "purl": "pkg:maven/com.querydsl/querydsl-core@4.2.1",
 83334          "swid": {
 83335            "attachment": {}
 83336          },
 83337          "pedigree": {},
 83338          "externalReferences": [
 83339            {
 83340              "type": "build-meta",
 83341              "hashes": [
 83342                {
 83343                  "alg": "SHA-1",
 83344                  "content": "ae5b6f2cb28184f19afc1f915fc1e45bf732ffc5"
 83345                }
 83346              ]
 83347            }
 83348          ],
 83349          "evidence": {},
 83350          "signature": {
 83351            "signature": {
 83352              "publicKey": {}
 83353            }
 83354          },
 83355          "modelCard": {
 83356            "modelParameters": {
 83357              "approach": {}
 83358            },
 83359            "quantitativeAnalysis": {
 83360              "graphics": {}
 83361            },
 83362            "considerations": {}
 83363          }
 83364        },
 83365        {
 83366          "type": "library",
 83367          "bom-ref": "pkg:maven/com.querydsl/querydsl-jpa@4.1.4?package-id=a30c56a382fb0415",
 83368          "supplier": {},
 83369          "group": "com.querydsl",
 83370          "name": "querydsl-jpa",
 83371          "version": "4.1.4",
 83372          "licenses": [
 83373            {
 83374              "license": {
 83375                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 83376              }
 83377            }
 83378          ],
 83379          "cpe": "cpe:2.3:a:querydsl-jpa:querydsl-jpa:4.1.4:*:*:*:*:*:*:*",
 83380          "purl": "pkg:maven/com.querydsl/querydsl-jpa@4.1.4",
 83381          "swid": {
 83382            "attachment": {}
 83383          },
 83384          "pedigree": {},
 83385          "externalReferences": [
 83386            {
 83387              "type": "build-meta",
 83388              "hashes": [
 83389                {
 83390                  "alg": "SHA-1",
 83391                  "content": "b5f7d287efb716f1a9f9b102cab933c0202e119d"
 83392                }
 83393              ]
 83394            }
 83395          ],
 83396          "evidence": {},
 83397          "signature": {
 83398            "signature": {
 83399              "publicKey": {}
 83400            }
 83401          },
 83402          "modelCard": {
 83403            "modelParameters": {
 83404              "approach": {}
 83405            },
 83406            "quantitativeAnalysis": {
 83407              "graphics": {}
 83408            },
 83409            "considerations": {}
 83410          }
 83411        },
 83412        {
 83413          "type": "library",
 83414          "bom-ref": "pkg:maven/org.reactivestreams.reactive-streams/reactive-streams@1.0.2?package-id=66eacb86daf558b7",
 83415          "supplier": {},
 83416          "name": "reactive-streams",
 83417          "version": "1.0.2",
 83418          "cpe": "cpe:2.3:a:reactive-streams:reactive-streams:1.0.2:*:*:*:*:*:*:*",
 83419          "purl": "pkg:maven/org.reactivestreams.reactive-streams/reactive-streams@1.0.2",
 83420          "swid": {
 83421            "attachment": {}
 83422          },
 83423          "pedigree": {},
 83424          "externalReferences": [
 83425            {
 83426              "type": "build-meta",
 83427              "hashes": [
 83428                {
 83429                  "alg": "SHA-1",
 83430                  "content": "323964c36556eb0e6209f65c1cef72b53b461ab8"
 83431                }
 83432              ]
 83433            }
 83434          ],
 83435          "evidence": {},
 83436          "signature": {
 83437            "signature": {
 83438              "publicKey": {}
 83439            }
 83440          },
 83441          "modelCard": {
 83442            "modelParameters": {
 83443              "approach": {}
 83444            },
 83445            "quantitativeAnalysis": {
 83446              "graphics": {}
 83447            },
 83448            "considerations": {}
 83449          }
 83450        },
 83451        {
 83452          "type": "library",
 83453          "bom-ref": "pkg:maven/io.projectreactor.reactor-core/reactor-core@3.2.9.RELEASE?package-id=e4c6c62940026de0",
 83454          "supplier": {},
 83455          "name": "reactor-core",
 83456          "version": "3.2.9.RELEASE",
 83457          "cpe": "cpe:2.3:a:projectreactor:reactor-core:3.2.9.RELEASE:*:*:*:*:*:*:*",
 83458          "purl": "pkg:maven/io.projectreactor.reactor-core/reactor-core@3.2.9.RELEASE",
 83459          "swid": {
 83460            "attachment": {}
 83461          },
 83462          "pedigree": {},
 83463          "externalReferences": [
 83464            {
 83465              "type": "build-meta",
 83466              "hashes": [
 83467                {
 83468                  "alg": "SHA-1",
 83469                  "content": "a4c759ef932c530eaaad73e2544739bee9530903"
 83470                }
 83471              ]
 83472            }
 83473          ],
 83474          "evidence": {},
 83475          "signature": {
 83476            "signature": {
 83477              "publicKey": {}
 83478            }
 83479          },
 83480          "modelCard": {
 83481            "modelParameters": {
 83482              "approach": {}
 83483            },
 83484            "quantitativeAnalysis": {
 83485              "graphics": {}
 83486            },
 83487            "considerations": {}
 83488          }
 83489        },
 83490        {
 83491          "type": "library",
 83492          "bom-ref": "pkg:maven/org.reflections/reflections@0.9.9?package-id=12b13f6278fda317",
 83493          "supplier": {},
 83494          "group": "org.reflections",
 83495          "name": "reflections",
 83496          "version": "0.9.9",
 83497          "cpe": "cpe:2.3:a:reflections:reflections:0.9.9:*:*:*:*:*:*:*",
 83498          "purl": "pkg:maven/org.reflections/reflections@0.9.9",
 83499          "swid": {
 83500            "attachment": {}
 83501          },
 83502          "pedigree": {},
 83503          "externalReferences": [
 83504            {
 83505              "type": "build-meta",
 83506              "hashes": [
 83507                {
 83508                  "alg": "SHA-1",
 83509                  "content": "0296d8adb2f22a38025f44b45cac89835ff0bbaf"
 83510                }
 83511              ]
 83512            }
 83513          ],
 83514          "evidence": {},
 83515          "signature": {
 83516            "signature": {
 83517              "publicKey": {}
 83518            }
 83519          },
 83520          "modelCard": {
 83521            "modelParameters": {
 83522              "approach": {}
 83523            },
 83524            "quantitativeAnalysis": {
 83525              "graphics": {}
 83526            },
 83527            "considerations": {}
 83528          }
 83529        },
 83530        {
 83531          "type": "library",
 83532          "bom-ref": "pkg:maven/resources/resources@1.8.0_362?package-id=8580b1e6a4b5281a",
 83533          "supplier": {},
 83534          "name": "resources",
 83535          "version": "1.8.0_362",
 83536          "cpe": "cpe:2.3:a:oracle-corporation:resources:1.8.0_362:*:*:*:*:*:*:*",
 83537          "purl": "pkg:maven/resources/resources@1.8.0_362",
 83538          "swid": {
 83539            "attachment": {}
 83540          },
 83541          "pedigree": {},
 83542          "externalReferences": [
 83543            {
 83544              "type": "build-meta",
 83545              "hashes": [
 83546                {
 83547                  "alg": "SHA-1",
 83548                  "content": "34d2d9c5b59ee5ff757e7d766837a4f53947b7a1"
 83549                }
 83550              ]
 83551            }
 83552          ],
 83553          "evidence": {},
 83554          "signature": {
 83555            "signature": {
 83556              "publicKey": {}
 83557            }
 83558          },
 83559          "modelCard": {
 83560            "modelParameters": {
 83561              "approach": {}
 83562            },
 83563            "quantitativeAnalysis": {
 83564              "graphics": {}
 83565            },
 83566            "considerations": {}
 83567          }
 83568        },
 83569        {
 83570          "type": "library",
 83571          "bom-ref": "pkg:maven/com.squareup.retrofit2/retrofit@2.6.2?package-id=d605abe81c88db5",
 83572          "supplier": {},
 83573          "group": "com.squareup.retrofit2",
 83574          "name": "retrofit",
 83575          "version": "2.6.2",
 83576          "cpe": "cpe:2.3:a:retrofit2:retrofit:2.6.2:*:*:*:*:*:*:*",
 83577          "purl": "pkg:maven/com.squareup.retrofit2/retrofit@2.6.2",
 83578          "swid": {
 83579            "attachment": {}
 83580          },
 83581          "pedigree": {},
 83582          "externalReferences": [
 83583            {
 83584              "type": "build-meta",
 83585              "hashes": [
 83586                {
 83587                  "alg": "SHA-1",
 83588                  "content": "b51e9cf3b25a2f4116612d368d1aeba671fe1533"
 83589                }
 83590              ]
 83591            }
 83592          ],
 83593          "evidence": {},
 83594          "signature": {
 83595            "signature": {
 83596              "publicKey": {}
 83597            }
 83598          },
 83599          "modelCard": {
 83600            "modelParameters": {
 83601              "approach": {}
 83602            },
 83603            "quantitativeAnalysis": {
 83604              "graphics": {}
 83605            },
 83606            "considerations": {}
 83607          }
 83608        },
 83609        {
 83610          "type": "library",
 83611          "bom-ref": "pkg:maven/org.mozilla.javascript.tools.shell.Main/rhino@1.7R4?package-id=f9f178fb0f7041d6",
 83612          "supplier": {},
 83613          "name": "rhino",
 83614          "version": "1.7R4",
 83615          "cpe": "cpe:2.3:a:mozilla-foundation:javascript:1.7R4:*:*:*:*:*:*:*",
 83616          "purl": "pkg:maven/org.mozilla.javascript.tools.shell.Main/rhino@1.7R4",
 83617          "swid": {
 83618            "attachment": {}
 83619          },
 83620          "pedigree": {},
 83621          "externalReferences": [
 83622            {
 83623              "type": "build-meta",
 83624              "hashes": [
 83625                {
 83626                  "alg": "SHA-1",
 83627                  "content": "e982f2136574b9a423186fbaeaaa98dc3e5a5288"
 83628                }
 83629              ]
 83630            }
 83631          ],
 83632          "evidence": {},
 83633          "signature": {
 83634            "signature": {
 83635              "publicKey": {}
 83636            }
 83637          },
 83638          "modelCard": {
 83639            "modelParameters": {
 83640              "approach": {}
 83641            },
 83642            "quantitativeAnalysis": {
 83643              "graphics": {}
 83644            },
 83645            "considerations": {}
 83646          }
 83647        },
 83648        {
 83649          "type": "library",
 83650          "bom-ref": "pkg:maven/rt/rt@1.8.0_362?package-id=a9e172c0e0dc2fce",
 83651          "supplier": {},
 83652          "name": "rt",
 83653          "version": "1.8.0_362",
 83654          "cpe": "cpe:2.3:a:oracle-corporation:rt:1.8.0_362:*:*:*:*:*:*:*",
 83655          "purl": "pkg:maven/rt/rt@1.8.0_362",
 83656          "swid": {
 83657            "attachment": {}
 83658          },
 83659          "pedigree": {},
 83660          "externalReferences": [
 83661            {
 83662              "type": "build-meta",
 83663              "hashes": [
 83664                {
 83665                  "alg": "SHA-1",
 83666                  "content": "d85439d089c379805dac978a1e27a9a3e465bb71"
 83667                }
 83668              ]
 83669            }
 83670          ],
 83671          "evidence": {},
 83672          "signature": {
 83673            "signature": {
 83674              "publicKey": {}
 83675            }
 83676          },
 83677          "modelCard": {
 83678            "modelParameters": {
 83679              "approach": {}
 83680            },
 83681            "quantitativeAnalysis": {
 83682              "graphics": {}
 83683            },
 83684            "considerations": {}
 83685          }
 83686        },
 83687        {
 83688          "type": "library",
 83689          "bom-ref": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.3\u0026package-id=e903138d19e85b80",
 83690          "supplier": {},
 83691          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 83692          "name": "scanelf",
 83693          "version": "1.3.5-r1",
 83694          "description": "Scan ELF binaries for stuff",
 83695          "licenses": [
 83696            {
 83697              "license": {
 83698                "id": "GPL-2.0-only"
 83699              }
 83700            }
 83701          ],
 83702          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.5-r1:*:*:*:*:*:*:*",
 83703          "purl": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.3",
 83704          "swid": {
 83705            "attachment": {}
 83706          },
 83707          "pedigree": {},
 83708          "externalReferences": [
 83709            {
 83710              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
 83711              "type": "distribution"
 83712            }
 83713          ],
 83714          "evidence": {},
 83715          "signature": {
 83716            "signature": {
 83717              "publicKey": {}
 83718            }
 83719          },
 83720          "modelCard": {
 83721            "modelParameters": {
 83722              "approach": {}
 83723            },
 83724            "quantitativeAnalysis": {
 83725              "graphics": {}
 83726            },
 83727            "considerations": {}
 83728          }
 83729        },
 83730        {
 83731          "type": "library",
 83732          "bom-ref": "pkg:maven/org.apache.xml.serializer/serializer@2.7.2?package-id=59b2a0c9a9a5329b",
 83733          "supplier": {},
 83734          "name": "serializer",
 83735          "version": "2.7.2",
 83736          "cpe": "cpe:2.3:a:apache:serializer:2.7.2:*:*:*:*:*:*:*",
 83737          "purl": "pkg:maven/org.apache.xml.serializer/serializer@2.7.2",
 83738          "swid": {
 83739            "attachment": {}
 83740          },
 83741          "pedigree": {},
 83742          "externalReferences": [
 83743            {
 83744              "type": "build-meta",
 83745              "hashes": [
 83746                {
 83747                  "alg": "SHA-1",
 83748                  "content": "24247f3bb052ee068971393bdb83e04512bb1c3c"
 83749                }
 83750              ]
 83751            }
 83752          ],
 83753          "evidence": {},
 83754          "signature": {
 83755            "signature": {
 83756              "publicKey": {}
 83757            }
 83758          },
 83759          "modelCard": {
 83760            "modelParameters": {
 83761              "approach": {}
 83762            },
 83763            "quantitativeAnalysis": {
 83764              "graphics": {}
 83765            },
 83766            "considerations": {}
 83767          }
 83768        },
 83769        {
 83770          "type": "library",
 83771          "bom-ref": "pkg:maven/io.prometheus/simpleclient@0.5.0?package-id=37c0d287a233523d",
 83772          "supplier": {},
 83773          "group": "io.prometheus",
 83774          "name": "simpleclient",
 83775          "version": "0.5.0",
 83776          "licenses": [
 83777            {
 83778              "license": {
 83779                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 83780              }
 83781            }
 83782          ],
 83783          "cpe": "cpe:2.3:a:simpleclient:simpleclient:0.5.0:*:*:*:*:*:*:*",
 83784          "purl": "pkg:maven/io.prometheus/simpleclient@0.5.0",
 83785          "swid": {
 83786            "attachment": {}
 83787          },
 83788          "pedigree": {},
 83789          "externalReferences": [
 83790            {
 83791              "type": "build-meta",
 83792              "hashes": [
 83793                {
 83794                  "alg": "SHA-1",
 83795                  "content": "fbbfe2300098798e3d23f93b7b14befeceacf512"
 83796                }
 83797              ]
 83798            }
 83799          ],
 83800          "evidence": {},
 83801          "signature": {
 83802            "signature": {
 83803              "publicKey": {}
 83804            }
 83805          },
 83806          "modelCard": {
 83807            "modelParameters": {
 83808              "approach": {}
 83809            },
 83810            "quantitativeAnalysis": {
 83811              "graphics": {}
 83812            },
 83813            "considerations": {}
 83814          }
 83815        },
 83816        {
 83817          "type": "library",
 83818          "bom-ref": "pkg:maven/io.prometheus/simpleclient_common@0.5.0?package-id=433f46df6c895ff7",
 83819          "supplier": {},
 83820          "group": "io.prometheus",
 83821          "name": "simpleclient_common",
 83822          "version": "0.5.0",
 83823          "licenses": [
 83824            {
 83825              "license": {
 83826                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 83827              }
 83828            }
 83829          ],
 83830          "cpe": "cpe:2.3:a:simpleclient-common:simpleclient-common:0.5.0:*:*:*:*:*:*:*",
 83831          "purl": "pkg:maven/io.prometheus/simpleclient_common@0.5.0",
 83832          "swid": {
 83833            "attachment": {}
 83834          },
 83835          "pedigree": {},
 83836          "externalReferences": [
 83837            {
 83838              "type": "build-meta",
 83839              "hashes": [
 83840                {
 83841                  "alg": "SHA-1",
 83842                  "content": "bfd93082d7cf85c0543c2ccc286b96c817d1090c"
 83843                }
 83844              ]
 83845            }
 83846          ],
 83847          "evidence": {},
 83848          "signature": {
 83849            "signature": {
 83850              "publicKey": {}
 83851            }
 83852          },
 83853          "modelCard": {
 83854            "modelParameters": {
 83855              "approach": {}
 83856            },
 83857            "quantitativeAnalysis": {
 83858              "graphics": {}
 83859            },
 83860            "considerations": {}
 83861          }
 83862        },
 83863        {
 83864          "type": "library",
 83865          "bom-ref": "pkg:maven/org.slf4j/slf4j-api@1.7.26?package-id=d03c2fb80cd9cdf2",
 83866          "supplier": {},
 83867          "group": "org.slf4j",
 83868          "name": "slf4j-api",
 83869          "version": "1.7.26",
 83870          "cpe": "cpe:2.3:a:slf4j-api:slf4j-api:1.7.26:*:*:*:*:*:*:*",
 83871          "purl": "pkg:maven/org.slf4j/slf4j-api@1.7.26",
 83872          "swid": {
 83873            "attachment": {}
 83874          },
 83875          "pedigree": {},
 83876          "externalReferences": [
 83877            {
 83878              "type": "build-meta",
 83879              "hashes": [
 83880                {
 83881                  "alg": "SHA-1",
 83882                  "content": "77100a62c2e6f04b53977b9f541044d7d722693d"
 83883                }
 83884              ]
 83885            }
 83886          ],
 83887          "evidence": {},
 83888          "signature": {
 83889            "signature": {
 83890              "publicKey": {}
 83891            }
 83892          },
 83893          "modelCard": {
 83894            "modelParameters": {
 83895              "approach": {}
 83896            },
 83897            "quantitativeAnalysis": {
 83898              "graphics": {}
 83899            },
 83900            "considerations": {}
 83901          }
 83902        },
 83903        {
 83904          "type": "library",
 83905          "bom-ref": "pkg:maven/org.yaml/snakeyaml@1.33?package-id=843db7ee7d03cb77",
 83906          "supplier": {},
 83907          "group": "org.yaml",
 83908          "name": "snakeyaml",
 83909          "version": "1.33",
 83910          "licenses": [
 83911            {
 83912              "license": {
 83913                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 83914              }
 83915            }
 83916          ],
 83917          "cpe": "cpe:2.3:a:snakeyaml:snakeyaml:1.33:*:*:*:*:*:*:*",
 83918          "purl": "pkg:maven/org.yaml/snakeyaml@1.33",
 83919          "swid": {
 83920            "attachment": {}
 83921          },
 83922          "pedigree": {},
 83923          "externalReferences": [
 83924            {
 83925              "type": "build-meta",
 83926              "hashes": [
 83927                {
 83928                  "alg": "SHA-1",
 83929                  "content": "2cd0a87ff7df953f810c344bdf2fe3340b954c69"
 83930                }
 83931              ]
 83932            }
 83933          ],
 83934          "evidence": {},
 83935          "signature": {
 83936            "signature": {
 83937              "publicKey": {}
 83938            }
 83939          },
 83940          "modelCard": {
 83941            "modelParameters": {
 83942              "approach": {}
 83943            },
 83944            "quantitativeAnalysis": {
 83945              "graphics": {}
 83946            },
 83947            "considerations": {}
 83948          }
 83949        },
 83950        {
 83951          "type": "library",
 83952          "bom-ref": "pkg:maven/org.springframework.amqp/spring-amqp@2.1.6.RELEASE?package-id=c49dde10135e38cf",
 83953          "supplier": {},
 83954          "name": "spring-amqp",
 83955          "version": "2.1.6.RELEASE",
 83956          "cpe": "cpe:2.3:a:pivotal-software\\,-inc-:spring-amqp:2.1.6.RELEASE:*:*:*:*:*:*:*",
 83957          "purl": "pkg:maven/org.springframework.amqp/spring-amqp@2.1.6.RELEASE",
 83958          "swid": {
 83959            "attachment": {}
 83960          },
 83961          "pedigree": {},
 83962          "externalReferences": [
 83963            {
 83964              "type": "build-meta",
 83965              "hashes": [
 83966                {
 83967                  "alg": "SHA-1",
 83968                  "content": "417ef0e927476b20ebfad56d7759fd661493f905"
 83969                }
 83970              ]
 83971            }
 83972          ],
 83973          "evidence": {},
 83974          "signature": {
 83975            "signature": {
 83976              "publicKey": {}
 83977            }
 83978          },
 83979          "modelCard": {
 83980            "modelParameters": {
 83981              "approach": {}
 83982            },
 83983            "quantitativeAnalysis": {
 83984              "graphics": {}
 83985            },
 83986            "considerations": {}
 83987          }
 83988        },
 83989        {
 83990          "type": "library",
 83991          "bom-ref": "pkg:maven/spring-aop/spring-aop@5.1.7.RELEASE?package-id=34fcc113d8231dbc",
 83992          "supplier": {},
 83993          "name": "spring-aop",
 83994          "version": "5.1.7.RELEASE",
 83995          "cpe": "cpe:2.3:a:spring-aop:spring-aop:5.1.7.RELEASE:*:*:*:*:*:*:*",
 83996          "purl": "pkg:maven/spring-aop/spring-aop@5.1.7.RELEASE",
 83997          "swid": {
 83998            "attachment": {}
 83999          },
 84000          "pedigree": {},
 84001          "externalReferences": [
 84002            {
 84003              "type": "build-meta",
 84004              "hashes": [
 84005                {
 84006                  "alg": "SHA-1",
 84007                  "content": "8138b5e3dd01d514741de35d7f5050599c617509"
 84008                }
 84009              ]
 84010            }
 84011          ],
 84012          "evidence": {},
 84013          "signature": {
 84014            "signature": {
 84015              "publicKey": {}
 84016            }
 84017          },
 84018          "modelCard": {
 84019            "modelParameters": {
 84020              "approach": {}
 84021            },
 84022            "quantitativeAnalysis": {
 84023              "graphics": {}
 84024            },
 84025            "considerations": {}
 84026          }
 84027        },
 84028        {
 84029          "type": "library",
 84030          "bom-ref": "pkg:maven/spring-aspects/spring-aspects@5.1.7.RELEASE?package-id=69f2c1884df01188",
 84031          "supplier": {},
 84032          "name": "spring-aspects",
 84033          "version": "5.1.7.RELEASE",
 84034          "cpe": "cpe:2.3:a:spring-aspects:spring-aspects:5.1.7.RELEASE:*:*:*:*:*:*:*",
 84035          "purl": "pkg:maven/spring-aspects/spring-aspects@5.1.7.RELEASE",
 84036          "swid": {
 84037            "attachment": {}
 84038          },
 84039          "pedigree": {},
 84040          "externalReferences": [
 84041            {
 84042              "type": "build-meta",
 84043              "hashes": [
 84044                {
 84045                  "alg": "SHA-1",
 84046                  "content": "15309277b9a18c8dae21272be3e57b69a67c41f6"
 84047                }
 84048              ]
 84049            }
 84050          ],
 84051          "evidence": {},
 84052          "signature": {
 84053            "signature": {
 84054              "publicKey": {}
 84055            }
 84056          },
 84057          "modelCard": {
 84058            "modelParameters": {
 84059              "approach": {}
 84060            },
 84061            "quantitativeAnalysis": {
 84062              "graphics": {}
 84063            },
 84064            "considerations": {}
 84065          }
 84066        },
 84067        {
 84068          "type": "library",
 84069          "bom-ref": "pkg:maven/spring-beans/spring-beans@5.1.7.RELEASE?package-id=59e773d20428458a",
 84070          "supplier": {},
 84071          "name": "spring-beans",
 84072          "version": "5.1.7.RELEASE",
 84073          "cpe": "cpe:2.3:a:spring-beans:spring-beans:5.1.7.RELEASE:*:*:*:*:*:*:*",
 84074          "purl": "pkg:maven/spring-beans/spring-beans@5.1.7.RELEASE",
 84075          "swid": {
 84076            "attachment": {}
 84077          },
 84078          "pedigree": {},
 84079          "externalReferences": [
 84080            {
 84081              "type": "build-meta",
 84082              "hashes": [
 84083                {
 84084                  "alg": "SHA-1",
 84085                  "content": "14cd651e4aa3514e75710c9450c7a0c89413e63f"
 84086                }
 84087              ]
 84088            }
 84089          ],
 84090          "evidence": {},
 84091          "signature": {
 84092            "signature": {
 84093              "publicKey": {}
 84094            }
 84095          },
 84096          "modelCard": {
 84097            "modelParameters": {
 84098              "approach": {}
 84099            },
 84100            "quantitativeAnalysis": {
 84101              "graphics": {}
 84102            },
 84103            "considerations": {}
 84104          }
 84105        },
 84106        {
 84107          "type": "library",
 84108          "bom-ref": "pkg:maven/spring-boot/spring-boot@2.1.5.RELEASE?package-id=d560b45d698835a4",
 84109          "supplier": {},
 84110          "name": "spring-boot",
 84111          "version": "2.1.5.RELEASE",
 84112          "cpe": "cpe:2.3:a:spring-boot:spring-boot:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84113          "purl": "pkg:maven/spring-boot/spring-boot@2.1.5.RELEASE",
 84114          "swid": {
 84115            "attachment": {}
 84116          },
 84117          "pedigree": {},
 84118          "externalReferences": [
 84119            {
 84120              "type": "build-meta",
 84121              "hashes": [
 84122                {
 84123                  "alg": "SHA-1",
 84124                  "content": "939061a385b4e30e115978d78a7412fb984674df"
 84125                }
 84126              ]
 84127            }
 84128          ],
 84129          "evidence": {},
 84130          "signature": {
 84131            "signature": {
 84132              "publicKey": {}
 84133            }
 84134          },
 84135          "modelCard": {
 84136            "modelParameters": {
 84137              "approach": {}
 84138            },
 84139            "quantitativeAnalysis": {
 84140              "graphics": {}
 84141            },
 84142            "considerations": {}
 84143          }
 84144        },
 84145        {
 84146          "type": "library",
 84147          "bom-ref": "pkg:maven/spring-boot-actuator/spring-boot-actuator@2.1.5.RELEASE?package-id=b99ebb8a82d732de",
 84148          "supplier": {},
 84149          "name": "spring-boot-actuator",
 84150          "version": "2.1.5.RELEASE",
 84151          "cpe": "cpe:2.3:a:spring-boot-actuator:spring-boot-actuator:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84152          "purl": "pkg:maven/spring-boot-actuator/spring-boot-actuator@2.1.5.RELEASE",
 84153          "swid": {
 84154            "attachment": {}
 84155          },
 84156          "pedigree": {},
 84157          "externalReferences": [
 84158            {
 84159              "type": "build-meta",
 84160              "hashes": [
 84161                {
 84162                  "alg": "SHA-1",
 84163                  "content": "eccd3c70cfbe9534db19fbdd6cbf86fab884c3c0"
 84164                }
 84165              ]
 84166            }
 84167          ],
 84168          "evidence": {},
 84169          "signature": {
 84170            "signature": {
 84171              "publicKey": {}
 84172            }
 84173          },
 84174          "modelCard": {
 84175            "modelParameters": {
 84176              "approach": {}
 84177            },
 84178            "quantitativeAnalysis": {
 84179              "graphics": {}
 84180            },
 84181            "considerations": {}
 84182          }
 84183        },
 84184        {
 84185          "type": "library",
 84186          "bom-ref": "pkg:maven/spring-boot-actuator-autoconfigure/spring-boot-actuator-autoconfigure@2.1.5.RELEASE?package-id=2368594ea9a8feff",
 84187          "supplier": {},
 84188          "name": "spring-boot-actuator-autoconfigure",
 84189          "version": "2.1.5.RELEASE",
 84190          "cpe": "cpe:2.3:a:spring-boot-actuator-autoconfigure:spring-boot-actuator-autoconfigure:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84191          "purl": "pkg:maven/spring-boot-actuator-autoconfigure/spring-boot-actuator-autoconfigure@2.1.5.RELEASE",
 84192          "swid": {
 84193            "attachment": {}
 84194          },
 84195          "pedigree": {},
 84196          "externalReferences": [
 84197            {
 84198              "type": "build-meta",
 84199              "hashes": [
 84200                {
 84201                  "alg": "SHA-1",
 84202                  "content": "4e6774d2f4a70e62092dbaace39190f8b1df8083"
 84203                }
 84204              ]
 84205            }
 84206          ],
 84207          "evidence": {},
 84208          "signature": {
 84209            "signature": {
 84210              "publicKey": {}
 84211            }
 84212          },
 84213          "modelCard": {
 84214            "modelParameters": {
 84215              "approach": {}
 84216            },
 84217            "quantitativeAnalysis": {
 84218              "graphics": {}
 84219            },
 84220            "considerations": {}
 84221          }
 84222        },
 84223        {
 84224          "type": "library",
 84225          "bom-ref": "pkg:maven/spring-boot-autoconfigure/spring-boot-autoconfigure@2.1.5.RELEASE?package-id=64083cd147bd2053",
 84226          "supplier": {},
 84227          "name": "spring-boot-autoconfigure",
 84228          "version": "2.1.5.RELEASE",
 84229          "cpe": "cpe:2.3:a:spring-boot-autoconfigure:spring-boot-autoconfigure:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84230          "purl": "pkg:maven/spring-boot-autoconfigure/spring-boot-autoconfigure@2.1.5.RELEASE",
 84231          "swid": {
 84232            "attachment": {}
 84233          },
 84234          "pedigree": {},
 84235          "externalReferences": [
 84236            {
 84237              "type": "build-meta",
 84238              "hashes": [
 84239                {
 84240                  "alg": "SHA-1",
 84241                  "content": "69ae2819b295603563b95f79abae53f2631c5b94"
 84242                }
 84243              ]
 84244            }
 84245          ],
 84246          "evidence": {},
 84247          "signature": {
 84248            "signature": {
 84249              "publicKey": {}
 84250            }
 84251          },
 84252          "modelCard": {
 84253            "modelParameters": {
 84254              "approach": {}
 84255            },
 84256            "quantitativeAnalysis": {
 84257              "graphics": {}
 84258            },
 84259            "considerations": {}
 84260          }
 84261        },
 84262        {
 84263          "type": "library",
 84264          "bom-ref": "pkg:maven/spring-boot-starter/spring-boot-starter@2.1.5.RELEASE?package-id=9d7c93d5c690d94b",
 84265          "supplier": {},
 84266          "name": "spring-boot-starter",
 84267          "version": "2.1.5.RELEASE",
 84268          "cpe": "cpe:2.3:a:spring-boot-starter:spring-boot-starter:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84269          "purl": "pkg:maven/spring-boot-starter/spring-boot-starter@2.1.5.RELEASE",
 84270          "swid": {
 84271            "attachment": {}
 84272          },
 84273          "pedigree": {},
 84274          "externalReferences": [
 84275            {
 84276              "type": "build-meta",
 84277              "hashes": [
 84278                {
 84279                  "alg": "SHA-1",
 84280                  "content": "74952d169c2da56f7794b3a88508e52005bb8f36"
 84281                }
 84282              ]
 84283            }
 84284          ],
 84285          "evidence": {},
 84286          "signature": {
 84287            "signature": {
 84288              "publicKey": {}
 84289            }
 84290          },
 84291          "modelCard": {
 84292            "modelParameters": {
 84293              "approach": {}
 84294            },
 84295            "quantitativeAnalysis": {
 84296              "graphics": {}
 84297            },
 84298            "considerations": {}
 84299          }
 84300        },
 84301        {
 84302          "type": "library",
 84303          "bom-ref": "pkg:maven/spring-boot-starter-actuator/spring-boot-starter-actuator@2.1.5.RELEASE?package-id=aeb3ccb03e88cea",
 84304          "supplier": {},
 84305          "name": "spring-boot-starter-actuator",
 84306          "version": "2.1.5.RELEASE",
 84307          "cpe": "cpe:2.3:a:spring-boot-starter-actuator:spring-boot-starter-actuator:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84308          "purl": "pkg:maven/spring-boot-starter-actuator/spring-boot-starter-actuator@2.1.5.RELEASE",
 84309          "swid": {
 84310            "attachment": {}
 84311          },
 84312          "pedigree": {},
 84313          "externalReferences": [
 84314            {
 84315              "type": "build-meta",
 84316              "hashes": [
 84317                {
 84318                  "alg": "SHA-1",
 84319                  "content": "4abebc4ec0ee87155bfa8daf6a9d63366308e58a"
 84320                }
 84321              ]
 84322            }
 84323          ],
 84324          "evidence": {},
 84325          "signature": {
 84326            "signature": {
 84327              "publicKey": {}
 84328            }
 84329          },
 84330          "modelCard": {
 84331            "modelParameters": {
 84332              "approach": {}
 84333            },
 84334            "quantitativeAnalysis": {
 84335              "graphics": {}
 84336            },
 84337            "considerations": {}
 84338          }
 84339        },
 84340        {
 84341          "type": "library",
 84342          "bom-ref": "pkg:maven/spring-boot-starter-amqp/spring-boot-starter-amqp@2.1.5.RELEASE?package-id=9709370a3232f34e",
 84343          "supplier": {},
 84344          "name": "spring-boot-starter-amqp",
 84345          "version": "2.1.5.RELEASE",
 84346          "cpe": "cpe:2.3:a:spring-boot-starter-amqp:spring-boot-starter-amqp:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84347          "purl": "pkg:maven/spring-boot-starter-amqp/spring-boot-starter-amqp@2.1.5.RELEASE",
 84348          "swid": {
 84349            "attachment": {}
 84350          },
 84351          "pedigree": {},
 84352          "externalReferences": [
 84353            {
 84354              "type": "build-meta",
 84355              "hashes": [
 84356                {
 84357                  "alg": "SHA-1",
 84358                  "content": "3124c5e7dc556a80f47c2d7353b42d09748e252f"
 84359                }
 84360              ]
 84361            }
 84362          ],
 84363          "evidence": {},
 84364          "signature": {
 84365            "signature": {
 84366              "publicKey": {}
 84367            }
 84368          },
 84369          "modelCard": {
 84370            "modelParameters": {
 84371              "approach": {}
 84372            },
 84373            "quantitativeAnalysis": {
 84374              "graphics": {}
 84375            },
 84376            "considerations": {}
 84377          }
 84378        },
 84379        {
 84380          "type": "library",
 84381          "bom-ref": "pkg:maven/spring-boot-starter-aop/spring-boot-starter-aop@2.1.5.RELEASE?package-id=dbe0e8a9b73fe9fc",
 84382          "supplier": {},
 84383          "name": "spring-boot-starter-aop",
 84384          "version": "2.1.5.RELEASE",
 84385          "cpe": "cpe:2.3:a:spring-boot-starter-aop:spring-boot-starter-aop:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84386          "purl": "pkg:maven/spring-boot-starter-aop/spring-boot-starter-aop@2.1.5.RELEASE",
 84387          "swid": {
 84388            "attachment": {}
 84389          },
 84390          "pedigree": {},
 84391          "externalReferences": [
 84392            {
 84393              "type": "build-meta",
 84394              "hashes": [
 84395                {
 84396                  "alg": "SHA-1",
 84397                  "content": "464cfb573009e724ea76ca404f106b1b19e759ff"
 84398                }
 84399              ]
 84400            }
 84401          ],
 84402          "evidence": {},
 84403          "signature": {
 84404            "signature": {
 84405              "publicKey": {}
 84406            }
 84407          },
 84408          "modelCard": {
 84409            "modelParameters": {
 84410              "approach": {}
 84411            },
 84412            "quantitativeAnalysis": {
 84413              "graphics": {}
 84414            },
 84415            "considerations": {}
 84416          }
 84417        },
 84418        {
 84419          "type": "library",
 84420          "bom-ref": "pkg:maven/spring-boot-starter-cache/spring-boot-starter-cache@2.1.5.RELEASE?package-id=85f7a2c096afefbf",
 84421          "supplier": {},
 84422          "name": "spring-boot-starter-cache",
 84423          "version": "2.1.5.RELEASE",
 84424          "cpe": "cpe:2.3:a:spring-boot-starter-cache:spring-boot-starter-cache:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84425          "purl": "pkg:maven/spring-boot-starter-cache/spring-boot-starter-cache@2.1.5.RELEASE",
 84426          "swid": {
 84427            "attachment": {}
 84428          },
 84429          "pedigree": {},
 84430          "externalReferences": [
 84431            {
 84432              "type": "build-meta",
 84433              "hashes": [
 84434                {
 84435                  "alg": "SHA-1",
 84436                  "content": "ffb4deb388f567c434d589fd04234ccacda0cfd1"
 84437                }
 84438              ]
 84439            }
 84440          ],
 84441          "evidence": {},
 84442          "signature": {
 84443            "signature": {
 84444              "publicKey": {}
 84445            }
 84446          },
 84447          "modelCard": {
 84448            "modelParameters": {
 84449              "approach": {}
 84450            },
 84451            "quantitativeAnalysis": {
 84452              "graphics": {}
 84453            },
 84454            "considerations": {}
 84455          }
 84456        },
 84457        {
 84458          "type": "library",
 84459          "bom-ref": "pkg:maven/spring-boot-starter-data-jpa/spring-boot-starter-data-jpa@2.1.5.RELEASE?package-id=509b8297be16e061",
 84460          "supplier": {},
 84461          "name": "spring-boot-starter-data-jpa",
 84462          "version": "2.1.5.RELEASE",
 84463          "cpe": "cpe:2.3:a:spring-boot-starter-data-jpa:spring-boot-starter-data-jpa:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84464          "purl": "pkg:maven/spring-boot-starter-data-jpa/spring-boot-starter-data-jpa@2.1.5.RELEASE",
 84465          "swid": {
 84466            "attachment": {}
 84467          },
 84468          "pedigree": {},
 84469          "externalReferences": [
 84470            {
 84471              "type": "build-meta",
 84472              "hashes": [
 84473                {
 84474                  "alg": "SHA-1",
 84475                  "content": "f33f69b3744d07f832db6ab48eab227ccde9e922"
 84476                }
 84477              ]
 84478            }
 84479          ],
 84480          "evidence": {},
 84481          "signature": {
 84482            "signature": {
 84483              "publicKey": {}
 84484            }
 84485          },
 84486          "modelCard": {
 84487            "modelParameters": {
 84488              "approach": {}
 84489            },
 84490            "quantitativeAnalysis": {
 84491              "graphics": {}
 84492            },
 84493            "considerations": {}
 84494          }
 84495        },
 84496        {
 84497          "type": "library",
 84498          "bom-ref": "pkg:maven/spring-boot-starter-data-redis/spring-boot-starter-data-redis@2.1.5.RELEASE?package-id=d55335ce80b155e1",
 84499          "supplier": {},
 84500          "name": "spring-boot-starter-data-redis",
 84501          "version": "2.1.5.RELEASE",
 84502          "cpe": "cpe:2.3:a:spring-boot-starter-data-redis:spring-boot-starter-data-redis:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84503          "purl": "pkg:maven/spring-boot-starter-data-redis/spring-boot-starter-data-redis@2.1.5.RELEASE",
 84504          "swid": {
 84505            "attachment": {}
 84506          },
 84507          "pedigree": {},
 84508          "externalReferences": [
 84509            {
 84510              "type": "build-meta",
 84511              "hashes": [
 84512                {
 84513                  "alg": "SHA-1",
 84514                  "content": "dc37913654c023b1a55ed51555ceee22717081ed"
 84515                }
 84516              ]
 84517            }
 84518          ],
 84519          "evidence": {},
 84520          "signature": {
 84521            "signature": {
 84522              "publicKey": {}
 84523            }
 84524          },
 84525          "modelCard": {
 84526            "modelParameters": {
 84527              "approach": {}
 84528            },
 84529            "quantitativeAnalysis": {
 84530              "graphics": {}
 84531            },
 84532            "considerations": {}
 84533          }
 84534        },
 84535        {
 84536          "type": "library",
 84537          "bom-ref": "pkg:maven/spring-boot-starter-jdbc/spring-boot-starter-jdbc@2.1.5.RELEASE?package-id=2322bb9412931751",
 84538          "supplier": {},
 84539          "name": "spring-boot-starter-jdbc",
 84540          "version": "2.1.5.RELEASE",
 84541          "cpe": "cpe:2.3:a:spring-boot-starter-jdbc:spring-boot-starter-jdbc:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84542          "purl": "pkg:maven/spring-boot-starter-jdbc/spring-boot-starter-jdbc@2.1.5.RELEASE",
 84543          "swid": {
 84544            "attachment": {}
 84545          },
 84546          "pedigree": {},
 84547          "externalReferences": [
 84548            {
 84549              "type": "build-meta",
 84550              "hashes": [
 84551                {
 84552                  "alg": "SHA-1",
 84553                  "content": "6f187e708a47b0d37552a01292ce649a97a0059d"
 84554                }
 84555              ]
 84556            }
 84557          ],
 84558          "evidence": {},
 84559          "signature": {
 84560            "signature": {
 84561              "publicKey": {}
 84562            }
 84563          },
 84564          "modelCard": {
 84565            "modelParameters": {
 84566              "approach": {}
 84567            },
 84568            "quantitativeAnalysis": {
 84569              "graphics": {}
 84570            },
 84571            "considerations": {}
 84572          }
 84573        },
 84574        {
 84575          "type": "library",
 84576          "bom-ref": "pkg:maven/spring-boot-starter-json/spring-boot-starter-json@2.1.5.RELEASE?package-id=290ee6d8696bce66",
 84577          "supplier": {},
 84578          "name": "spring-boot-starter-json",
 84579          "version": "2.1.5.RELEASE",
 84580          "cpe": "cpe:2.3:a:spring-boot-starter-json:spring-boot-starter-json:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84581          "purl": "pkg:maven/spring-boot-starter-json/spring-boot-starter-json@2.1.5.RELEASE",
 84582          "swid": {
 84583            "attachment": {}
 84584          },
 84585          "pedigree": {},
 84586          "externalReferences": [
 84587            {
 84588              "type": "build-meta",
 84589              "hashes": [
 84590                {
 84591                  "alg": "SHA-1",
 84592                  "content": "0cf880b4a4713b2a1aea21f929df718a0260aa29"
 84593                }
 84594              ]
 84595            }
 84596          ],
 84597          "evidence": {},
 84598          "signature": {
 84599            "signature": {
 84600              "publicKey": {}
 84601            }
 84602          },
 84603          "modelCard": {
 84604            "modelParameters": {
 84605              "approach": {}
 84606            },
 84607            "quantitativeAnalysis": {
 84608              "graphics": {}
 84609            },
 84610            "considerations": {}
 84611          }
 84612        },
 84613        {
 84614          "type": "library",
 84615          "bom-ref": "pkg:maven/spring-boot-starter-logging/spring-boot-starter-logging@2.1.5.RELEASE?package-id=b650fbda28b7dfdc",
 84616          "supplier": {},
 84617          "name": "spring-boot-starter-logging",
 84618          "version": "2.1.5.RELEASE",
 84619          "cpe": "cpe:2.3:a:spring-boot-starter-logging:spring-boot-starter-logging:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84620          "purl": "pkg:maven/spring-boot-starter-logging/spring-boot-starter-logging@2.1.5.RELEASE",
 84621          "swid": {
 84622            "attachment": {}
 84623          },
 84624          "pedigree": {},
 84625          "externalReferences": [
 84626            {
 84627              "type": "build-meta",
 84628              "hashes": [
 84629                {
 84630                  "alg": "SHA-1",
 84631                  "content": "b4fe11fb0e606b67b9fb2bd9ae4fe65b484445dd"
 84632                }
 84633              ]
 84634            }
 84635          ],
 84636          "evidence": {},
 84637          "signature": {
 84638            "signature": {
 84639              "publicKey": {}
 84640            }
 84641          },
 84642          "modelCard": {
 84643            "modelParameters": {
 84644              "approach": {}
 84645            },
 84646            "quantitativeAnalysis": {
 84647              "graphics": {}
 84648            },
 84649            "considerations": {}
 84650          }
 84651        },
 84652        {
 84653          "type": "library",
 84654          "bom-ref": "pkg:maven/spring-boot-starter-security/spring-boot-starter-security@2.1.5.RELEASE?package-id=63ae7300b170ad68",
 84655          "supplier": {},
 84656          "name": "spring-boot-starter-security",
 84657          "version": "2.1.5.RELEASE",
 84658          "cpe": "cpe:2.3:a:spring-boot-starter-security:spring-boot-starter-security:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84659          "purl": "pkg:maven/spring-boot-starter-security/spring-boot-starter-security@2.1.5.RELEASE",
 84660          "swid": {
 84661            "attachment": {}
 84662          },
 84663          "pedigree": {},
 84664          "externalReferences": [
 84665            {
 84666              "type": "build-meta",
 84667              "hashes": [
 84668                {
 84669                  "alg": "SHA-1",
 84670                  "content": "6c4509c39b8c7347e8226905b40071933ecde5e8"
 84671                }
 84672              ]
 84673            }
 84674          ],
 84675          "evidence": {},
 84676          "signature": {
 84677            "signature": {
 84678              "publicKey": {}
 84679            }
 84680          },
 84681          "modelCard": {
 84682            "modelParameters": {
 84683              "approach": {}
 84684            },
 84685            "quantitativeAnalysis": {
 84686              "graphics": {}
 84687            },
 84688            "considerations": {}
 84689          }
 84690        },
 84691        {
 84692          "type": "library",
 84693          "bom-ref": "pkg:maven/spring-boot-starter-tomcat/spring-boot-starter-tomcat@2.1.5.RELEASE?package-id=99b8fab8cc100899",
 84694          "supplier": {},
 84695          "name": "spring-boot-starter-tomcat",
 84696          "version": "2.1.5.RELEASE",
 84697          "cpe": "cpe:2.3:a:spring-boot-starter-tomcat:spring-boot-starter-tomcat:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84698          "purl": "pkg:maven/spring-boot-starter-tomcat/spring-boot-starter-tomcat@2.1.5.RELEASE",
 84699          "swid": {
 84700            "attachment": {}
 84701          },
 84702          "pedigree": {},
 84703          "externalReferences": [
 84704            {
 84705              "type": "build-meta",
 84706              "hashes": [
 84707                {
 84708                  "alg": "SHA-1",
 84709                  "content": "49de1c20ea6b8c6920d0a66329f9bf980e4498eb"
 84710                }
 84711              ]
 84712            }
 84713          ],
 84714          "evidence": {},
 84715          "signature": {
 84716            "signature": {
 84717              "publicKey": {}
 84718            }
 84719          },
 84720          "modelCard": {
 84721            "modelParameters": {
 84722              "approach": {}
 84723            },
 84724            "quantitativeAnalysis": {
 84725              "graphics": {}
 84726            },
 84727            "considerations": {}
 84728          }
 84729        },
 84730        {
 84731          "type": "library",
 84732          "bom-ref": "pkg:maven/spring-boot-starter-web/spring-boot-starter-web@2.1.5.RELEASE?package-id=f7f46f0be5d3d0ff",
 84733          "supplier": {},
 84734          "name": "spring-boot-starter-web",
 84735          "version": "2.1.5.RELEASE",
 84736          "cpe": "cpe:2.3:a:spring-boot-starter-web:spring-boot-starter-web:2.1.5.RELEASE:*:*:*:*:*:*:*",
 84737          "purl": "pkg:maven/spring-boot-starter-web/spring-boot-starter-web@2.1.5.RELEASE",
 84738          "swid": {
 84739            "attachment": {}
 84740          },
 84741          "pedigree": {},
 84742          "externalReferences": [
 84743            {
 84744              "type": "build-meta",
 84745              "hashes": [
 84746                {
 84747                  "alg": "SHA-1",
 84748                  "content": "d46494b46a626cbd8f253066a2d7413412efc908"
 84749                }
 84750              ]
 84751            }
 84752          ],
 84753          "evidence": {},
 84754          "signature": {
 84755            "signature": {
 84756              "publicKey": {}
 84757            }
 84758          },
 84759          "modelCard": {
 84760            "modelParameters": {
 84761              "approach": {}
 84762            },
 84763            "quantitativeAnalysis": {
 84764              "graphics": {}
 84765            },
 84766            "considerations": {}
 84767          }
 84768        },
 84769        {
 84770          "type": "library",
 84771          "bom-ref": "pkg:maven/spring-context/spring-context@5.1.7.RELEASE?package-id=3663d23aca4d10a",
 84772          "supplier": {},
 84773          "name": "spring-context",
 84774          "version": "5.1.7.RELEASE",
 84775          "cpe": "cpe:2.3:a:spring-context:spring-context:5.1.7.RELEASE:*:*:*:*:*:*:*",
 84776          "purl": "pkg:maven/spring-context/spring-context@5.1.7.RELEASE",
 84777          "swid": {
 84778            "attachment": {}
 84779          },
 84780          "pedigree": {},
 84781          "externalReferences": [
 84782            {
 84783              "type": "build-meta",
 84784              "hashes": [
 84785                {
 84786                  "alg": "SHA-1",
 84787                  "content": "b4154d41a70c56eeca42974825fe64a8576642dd"
 84788                }
 84789              ]
 84790            }
 84791          ],
 84792          "evidence": {},
 84793          "signature": {
 84794            "signature": {
 84795              "publicKey": {}
 84796            }
 84797          },
 84798          "modelCard": {
 84799            "modelParameters": {
 84800              "approach": {}
 84801            },
 84802            "quantitativeAnalysis": {
 84803              "graphics": {}
 84804            },
 84805            "considerations": {}
 84806          }
 84807        },
 84808        {
 84809          "type": "library",
 84810          "bom-ref": "pkg:maven/spring-context-support/spring-context-support@5.1.7.RELEASE?package-id=1df07f7ad60d218b",
 84811          "supplier": {},
 84812          "name": "spring-context-support",
 84813          "version": "5.1.7.RELEASE",
 84814          "cpe": "cpe:2.3:a:spring-context-support:spring-context-support:5.1.7.RELEASE:*:*:*:*:*:*:*",
 84815          "purl": "pkg:maven/spring-context-support/spring-context-support@5.1.7.RELEASE",
 84816          "swid": {
 84817            "attachment": {}
 84818          },
 84819          "pedigree": {},
 84820          "externalReferences": [
 84821            {
 84822              "type": "build-meta",
 84823              "hashes": [
 84824                {
 84825                  "alg": "SHA-1",
 84826                  "content": "416607b257f10065fb8d77ba27b047e719e5634d"
 84827                }
 84828              ]
 84829            }
 84830          ],
 84831          "evidence": {},
 84832          "signature": {
 84833            "signature": {
 84834              "publicKey": {}
 84835            }
 84836          },
 84837          "modelCard": {
 84838            "modelParameters": {
 84839              "approach": {}
 84840            },
 84841            "quantitativeAnalysis": {
 84842              "graphics": {}
 84843            },
 84844            "considerations": {}
 84845          }
 84846        },
 84847        {
 84848          "type": "library",
 84849          "bom-ref": "pkg:maven/spring-core/spring-core@5.1.7.RELEASE?package-id=e2e70c5bb2da4d78",
 84850          "supplier": {},
 84851          "name": "spring-core",
 84852          "version": "5.1.7.RELEASE",
 84853          "cpe": "cpe:2.3:a:springsource-spring-framework:springsource_spring_framework:5.1.7.RELEASE:*:*:*:*:*:*:*",
 84854          "purl": "pkg:maven/spring-core/spring-core@5.1.7.RELEASE",
 84855          "swid": {
 84856            "attachment": {}
 84857          },
 84858          "pedigree": {},
 84859          "externalReferences": [
 84860            {
 84861              "type": "build-meta",
 84862              "hashes": [
 84863                {
 84864                  "alg": "SHA-1",
 84865                  "content": "280f821b9ed4dad9993f1d551d6e86557092ae58"
 84866                }
 84867              ]
 84868            }
 84869          ],
 84870          "evidence": {},
 84871          "signature": {
 84872            "signature": {
 84873              "publicKey": {}
 84874            }
 84875          },
 84876          "modelCard": {
 84877            "modelParameters": {
 84878              "approach": {}
 84879            },
 84880            "quantitativeAnalysis": {
 84881              "graphics": {}
 84882            },
 84883            "considerations": {}
 84884          }
 84885        },
 84886        {
 84887          "type": "library",
 84888          "bom-ref": "pkg:maven/org.springframework.data/spring-data-commons@2.1.8.RELEASE?package-id=61540a4adb043633",
 84889          "supplier": {},
 84890          "group": "org.springframework.data",
 84891          "name": "spring-data-commons",
 84892          "version": "2.1.8.RELEASE",
 84893          "cpe": "cpe:2.3:a:spring-data-commons:spring-data-commons:2.1.8.RELEASE:*:*:*:*:*:*:*",
 84894          "purl": "pkg:maven/org.springframework.data/spring-data-commons@2.1.8.RELEASE",
 84895          "swid": {
 84896            "attachment": {}
 84897          },
 84898          "pedigree": {},
 84899          "externalReferences": [
 84900            {
 84901              "type": "build-meta",
 84902              "hashes": [
 84903                {
 84904                  "alg": "SHA-1",
 84905                  "content": "0d68b9a9850ee21319469c40bdbdfe4eaaf29557"
 84906                }
 84907              ]
 84908            }
 84909          ],
 84910          "evidence": {},
 84911          "signature": {
 84912            "signature": {
 84913              "publicKey": {}
 84914            }
 84915          },
 84916          "modelCard": {
 84917            "modelParameters": {
 84918              "approach": {}
 84919            },
 84920            "quantitativeAnalysis": {
 84921              "graphics": {}
 84922            },
 84923            "considerations": {}
 84924          }
 84925        },
 84926        {
 84927          "type": "library",
 84928          "bom-ref": "pkg:maven/org.springframework.data/spring-data-jpa@2.1.8.RELEASE?package-id=36776c8a81ec28a4",
 84929          "supplier": {},
 84930          "group": "org.springframework.data",
 84931          "name": "spring-data-jpa",
 84932          "version": "2.1.8.RELEASE",
 84933          "cpe": "cpe:2.3:a:spring-data-jpa:spring-data-jpa:2.1.8.RELEASE:*:*:*:*:*:*:*",
 84934          "purl": "pkg:maven/org.springframework.data/spring-data-jpa@2.1.8.RELEASE",
 84935          "swid": {
 84936            "attachment": {}
 84937          },
 84938          "pedigree": {},
 84939          "externalReferences": [
 84940            {
 84941              "type": "build-meta",
 84942              "hashes": [
 84943                {
 84944                  "alg": "SHA-1",
 84945                  "content": "385ab53309b4f0dfb317c4753fe853821ff15c08"
 84946                }
 84947              ]
 84948            }
 84949          ],
 84950          "evidence": {},
 84951          "signature": {
 84952            "signature": {
 84953              "publicKey": {}
 84954            }
 84955          },
 84956          "modelCard": {
 84957            "modelParameters": {
 84958              "approach": {}
 84959            },
 84960            "quantitativeAnalysis": {
 84961              "graphics": {}
 84962            },
 84963            "considerations": {}
 84964          }
 84965        },
 84966        {
 84967          "type": "library",
 84968          "bom-ref": "pkg:maven/org.springframework.data/spring-data-keyvalue@2.1.8.RELEASE?package-id=999e0a6ad491d87f",
 84969          "supplier": {},
 84970          "group": "org.springframework.data",
 84971          "name": "spring-data-keyvalue",
 84972          "version": "2.1.8.RELEASE",
 84973          "cpe": "cpe:2.3:a:spring-data-keyvalue:spring-data-keyvalue:2.1.8.RELEASE:*:*:*:*:*:*:*",
 84974          "purl": "pkg:maven/org.springframework.data/spring-data-keyvalue@2.1.8.RELEASE",
 84975          "swid": {
 84976            "attachment": {}
 84977          },
 84978          "pedigree": {},
 84979          "externalReferences": [
 84980            {
 84981              "type": "build-meta",
 84982              "hashes": [
 84983                {
 84984                  "alg": "SHA-1",
 84985                  "content": "d4cf8dc519f6a9debd4ba2d7857210208acffddf"
 84986                }
 84987              ]
 84988            }
 84989          ],
 84990          "evidence": {},
 84991          "signature": {
 84992            "signature": {
 84993              "publicKey": {}
 84994            }
 84995          },
 84996          "modelCard": {
 84997            "modelParameters": {
 84998              "approach": {}
 84999            },
 85000            "quantitativeAnalysis": {
 85001              "graphics": {}
 85002            },
 85003            "considerations": {}
 85004          }
 85005        },
 85006        {
 85007          "type": "library",
 85008          "bom-ref": "pkg:maven/org.springframework.data/spring-data-redis@2.1.8.RELEASE?package-id=25a4452fd30dfa76",
 85009          "supplier": {},
 85010          "group": "org.springframework.data",
 85011          "name": "spring-data-redis",
 85012          "version": "2.1.8.RELEASE",
 85013          "cpe": "cpe:2.3:a:spring-data-redis:spring-data-redis:2.1.8.RELEASE:*:*:*:*:*:*:*",
 85014          "purl": "pkg:maven/org.springframework.data/spring-data-redis@2.1.8.RELEASE",
 85015          "swid": {
 85016            "attachment": {}
 85017          },
 85018          "pedigree": {},
 85019          "externalReferences": [
 85020            {
 85021              "type": "build-meta",
 85022              "hashes": [
 85023                {
 85024                  "alg": "SHA-1",
 85025                  "content": "f30e626079055dfbd0cb2fd5515f12ee02bf65e3"
 85026                }
 85027              ]
 85028            }
 85029          ],
 85030          "evidence": {},
 85031          "signature": {
 85032            "signature": {
 85033              "publicKey": {}
 85034            }
 85035          },
 85036          "modelCard": {
 85037            "modelParameters": {
 85038              "approach": {}
 85039            },
 85040            "quantitativeAnalysis": {
 85041              "graphics": {}
 85042            },
 85043            "considerations": {}
 85044          }
 85045        },
 85046        {
 85047          "type": "library",
 85048          "bom-ref": "pkg:maven/spring-expression/spring-expression@5.1.7.RELEASE?package-id=950bd06ccacb1a9d",
 85049          "supplier": {},
 85050          "name": "spring-expression",
 85051          "version": "5.1.7.RELEASE",
 85052          "cpe": "cpe:2.3:a:spring-expression:spring-expression:5.1.7.RELEASE:*:*:*:*:*:*:*",
 85053          "purl": "pkg:maven/spring-expression/spring-expression@5.1.7.RELEASE",
 85054          "swid": {
 85055            "attachment": {}
 85056          },
 85057          "pedigree": {},
 85058          "externalReferences": [
 85059            {
 85060              "type": "build-meta",
 85061              "hashes": [
 85062                {
 85063                  "alg": "SHA-1",
 85064                  "content": "7b47446553c83a5a7323d647f5c1793106b2948c"
 85065                }
 85066              ]
 85067            }
 85068          ],
 85069          "evidence": {},
 85070          "signature": {
 85071            "signature": {
 85072              "publicKey": {}
 85073            }
 85074          },
 85075          "modelCard": {
 85076            "modelParameters": {
 85077              "approach": {}
 85078            },
 85079            "quantitativeAnalysis": {
 85080              "graphics": {}
 85081            },
 85082            "considerations": {}
 85083          }
 85084        },
 85085        {
 85086          "type": "library",
 85087          "bom-ref": "pkg:maven/spring-jcl/spring-jcl@5.1.7.RELEASE?package-id=828e0c2abb1e88e",
 85088          "supplier": {},
 85089          "name": "spring-jcl",
 85090          "version": "5.1.7.RELEASE",
 85091          "cpe": "cpe:2.3:a:spring-jcl:spring-jcl:5.1.7.RELEASE:*:*:*:*:*:*:*",
 85092          "purl": "pkg:maven/spring-jcl/spring-jcl@5.1.7.RELEASE",
 85093          "swid": {
 85094            "attachment": {}
 85095          },
 85096          "pedigree": {},
 85097          "externalReferences": [
 85098            {
 85099              "type": "build-meta",
 85100              "hashes": [
 85101                {
 85102                  "alg": "SHA-1",
 85103                  "content": "6b14bfb9ae41ca1bc604fe2e78f4a6efa3d67002"
 85104                }
 85105              ]
 85106            }
 85107          ],
 85108          "evidence": {},
 85109          "signature": {
 85110            "signature": {
 85111              "publicKey": {}
 85112            }
 85113          },
 85114          "modelCard": {
 85115            "modelParameters": {
 85116              "approach": {}
 85117            },
 85118            "quantitativeAnalysis": {
 85119              "graphics": {}
 85120            },
 85121            "considerations": {}
 85122          }
 85123        },
 85124        {
 85125          "type": "library",
 85126          "bom-ref": "pkg:maven/spring-jdbc/spring-jdbc@5.1.7.RELEASE?package-id=3bff6b9f4bd175bd",
 85127          "supplier": {},
 85128          "name": "spring-jdbc",
 85129          "version": "5.1.7.RELEASE",
 85130          "cpe": "cpe:2.3:a:spring-jdbc:spring-jdbc:5.1.7.RELEASE:*:*:*:*:*:*:*",
 85131          "purl": "pkg:maven/spring-jdbc/spring-jdbc@5.1.7.RELEASE",
 85132          "swid": {
 85133            "attachment": {}
 85134          },
 85135          "pedigree": {},
 85136          "externalReferences": [
 85137            {
 85138              "type": "build-meta",
 85139              "hashes": [
 85140                {
 85141                  "alg": "SHA-1",
 85142                  "content": "d00069664e066c4021fa3de167ad755e4148f340"
 85143                }
 85144              ]
 85145            }
 85146          ],
 85147          "evidence": {},
 85148          "signature": {
 85149            "signature": {
 85150              "publicKey": {}
 85151            }
 85152          },
 85153          "modelCard": {
 85154            "modelParameters": {
 85155              "approach": {}
 85156            },
 85157            "quantitativeAnalysis": {
 85158              "graphics": {}
 85159            },
 85160            "considerations": {}
 85161          }
 85162        },
 85163        {
 85164          "type": "library",
 85165          "bom-ref": "pkg:maven/spring-ldap-core/spring-ldap-core@2.3.2.RELEASE?package-id=87044ed96b3619c",
 85166          "supplier": {},
 85167          "name": "spring-ldap-core",
 85168          "version": "2.3.2.RELEASE",
 85169          "cpe": "cpe:2.3:a:spring-ldap-core:spring-ldap-core:2.3.2.RELEASE:*:*:*:*:*:*:*",
 85170          "purl": "pkg:maven/spring-ldap-core/spring-ldap-core@2.3.2.RELEASE",
 85171          "swid": {
 85172            "attachment": {}
 85173          },
 85174          "pedigree": {},
 85175          "externalReferences": [
 85176            {
 85177              "type": "build-meta",
 85178              "hashes": [
 85179                {
 85180                  "alg": "SHA-1",
 85181                  "content": "08bd3457711b1746af93daa0aa04c9fc886569b1"
 85182                }
 85183              ]
 85184            }
 85185          ],
 85186          "evidence": {},
 85187          "signature": {
 85188            "signature": {
 85189              "publicKey": {}
 85190            }
 85191          },
 85192          "modelCard": {
 85193            "modelParameters": {
 85194              "approach": {}
 85195            },
 85196            "quantitativeAnalysis": {
 85197              "graphics": {}
 85198            },
 85199            "considerations": {}
 85200          }
 85201        },
 85202        {
 85203          "type": "library",
 85204          "bom-ref": "pkg:maven/spring-messaging/spring-messaging@5.1.7.RELEASE?package-id=1e17b6b8c40b1803",
 85205          "supplier": {},
 85206          "name": "spring-messaging",
 85207          "version": "5.1.7.RELEASE",
 85208          "cpe": "cpe:2.3:a:spring-messaging:spring-messaging:5.1.7.RELEASE:*:*:*:*:*:*:*",
 85209          "purl": "pkg:maven/spring-messaging/spring-messaging@5.1.7.RELEASE",
 85210          "swid": {
 85211            "attachment": {}
 85212          },
 85213          "pedigree": {},
 85214          "externalReferences": [
 85215            {
 85216              "type": "build-meta",
 85217              "hashes": [
 85218                {
 85219                  "alg": "SHA-1",
 85220                  "content": "d110c80cc074228cb6993e16b4b3c98b6cfe7bea"
 85221                }
 85222              ]
 85223            }
 85224          ],
 85225          "evidence": {},
 85226          "signature": {
 85227            "signature": {
 85228              "publicKey": {}
 85229            }
 85230          },
 85231          "modelCard": {
 85232            "modelParameters": {
 85233              "approach": {}
 85234            },
 85235            "quantitativeAnalysis": {
 85236              "graphics": {}
 85237            },
 85238            "considerations": {}
 85239          }
 85240        },
 85241        {
 85242          "type": "library",
 85243          "bom-ref": "pkg:maven/spring-orm/spring-orm@5.1.7.RELEASE?package-id=7e1920f867642469",
 85244          "supplier": {},
 85245          "name": "spring-orm",
 85246          "version": "5.1.7.RELEASE",
 85247          "cpe": "cpe:2.3:a:spring-orm:spring-orm:5.1.7.RELEASE:*:*:*:*:*:*:*",
 85248          "purl": "pkg:maven/spring-orm/spring-orm@5.1.7.RELEASE",
 85249          "swid": {
 85250            "attachment": {}
 85251          },
 85252          "pedigree": {},
 85253          "externalReferences": [
 85254            {
 85255              "type": "build-meta",
 85256              "hashes": [
 85257                {
 85258                  "alg": "SHA-1",
 85259                  "content": "1e532795f730814b07961fbf5f14e14bd2507fcd"
 85260                }
 85261              ]
 85262            }
 85263          ],
 85264          "evidence": {},
 85265          "signature": {
 85266            "signature": {
 85267              "publicKey": {}
 85268            }
 85269          },
 85270          "modelCard": {
 85271            "modelParameters": {
 85272              "approach": {}
 85273            },
 85274            "quantitativeAnalysis": {
 85275              "graphics": {}
 85276            },
 85277            "considerations": {}
 85278          }
 85279        },
 85280        {
 85281          "type": "library",
 85282          "bom-ref": "pkg:maven/spring-oxm/spring-oxm@5.1.7.RELEASE?package-id=ab0e6299ebfeaa96",
 85283          "supplier": {},
 85284          "name": "spring-oxm",
 85285          "version": "5.1.7.RELEASE",
 85286          "cpe": "cpe:2.3:a:spring-oxm:spring-oxm:5.1.7.RELEASE:*:*:*:*:*:*:*",
 85287          "purl": "pkg:maven/spring-oxm/spring-oxm@5.1.7.RELEASE",
 85288          "swid": {
 85289            "attachment": {}
 85290          },
 85291          "pedigree": {},
 85292          "externalReferences": [
 85293            {
 85294              "type": "build-meta",
 85295              "hashes": [
 85296                {
 85297                  "alg": "SHA-1",
 85298                  "content": "5436d5d6d56b70768d296ca691d37c533429fea0"
 85299                }
 85300              ]
 85301            }
 85302          ],
 85303          "evidence": {},
 85304          "signature": {
 85305            "signature": {
 85306              "publicKey": {}
 85307            }
 85308          },
 85309          "modelCard": {
 85310            "modelParameters": {
 85311              "approach": {}
 85312            },
 85313            "quantitativeAnalysis": {
 85314              "graphics": {}
 85315            },
 85316            "considerations": {}
 85317          }
 85318        },
 85319        {
 85320          "type": "library",
 85321          "bom-ref": "pkg:maven/org.springframework.plugin/spring-plugin-core@1.2.0.RELEASE?package-id=f73ba8ef184cbc83",
 85322          "supplier": {},
 85323          "group": "org.springframework.plugin",
 85324          "name": "spring-plugin-core",
 85325          "version": "1.2.0.RELEASE",
 85326          "cpe": "cpe:2.3:a:spring-plugin-core:spring-plugin-core:1.2.0.RELEASE:*:*:*:*:*:*:*",
 85327          "purl": "pkg:maven/org.springframework.plugin/spring-plugin-core@1.2.0.RELEASE",
 85328          "swid": {
 85329            "attachment": {}
 85330          },
 85331          "pedigree": {},
 85332          "externalReferences": [
 85333            {
 85334              "type": "build-meta",
 85335              "hashes": [
 85336                {
 85337                  "alg": "SHA-1",
 85338                  "content": "f380e7760032e7d929184f8ad8a33716b75c0657"
 85339                }
 85340              ]
 85341            }
 85342          ],
 85343          "evidence": {},
 85344          "signature": {
 85345            "signature": {
 85346              "publicKey": {}
 85347            }
 85348          },
 85349          "modelCard": {
 85350            "modelParameters": {
 85351              "approach": {}
 85352            },
 85353            "quantitativeAnalysis": {
 85354              "graphics": {}
 85355            },
 85356            "considerations": {}
 85357          }
 85358        },
 85359        {
 85360          "type": "library",
 85361          "bom-ref": "pkg:maven/org.springframework.plugin/spring-plugin-metadata@1.2.0.RELEASE?package-id=b8b705216f28f326",
 85362          "supplier": {},
 85363          "group": "org.springframework.plugin",
 85364          "name": "spring-plugin-metadata",
 85365          "version": "1.2.0.RELEASE",
 85366          "cpe": "cpe:2.3:a:spring-plugin-metadata:spring-plugin-metadata:1.2.0.RELEASE:*:*:*:*:*:*:*",
 85367          "purl": "pkg:maven/org.springframework.plugin/spring-plugin-metadata@1.2.0.RELEASE",
 85368          "swid": {
 85369            "attachment": {}
 85370          },
 85371          "pedigree": {},
 85372          "externalReferences": [
 85373            {
 85374              "type": "build-meta",
 85375              "hashes": [
 85376                {
 85377                  "alg": "SHA-1",
 85378                  "content": "97223fc496b6cab31602eedbd4202aa4fff0d44f"
 85379                }
 85380              ]
 85381            }
 85382          ],
 85383          "evidence": {},
 85384          "signature": {
 85385            "signature": {
 85386              "publicKey": {}
 85387            }
 85388          },
 85389          "modelCard": {
 85390            "modelParameters": {
 85391              "approach": {}
 85392            },
 85393            "quantitativeAnalysis": {
 85394              "graphics": {}
 85395            },
 85396            "considerations": {}
 85397          }
 85398        },
 85399        {
 85400          "type": "library",
 85401          "bom-ref": "pkg:maven/org.springframework.amqp/spring-rabbit@2.1.6.RELEASE?package-id=ff7f017ca72ea29",
 85402          "supplier": {},
 85403          "name": "spring-rabbit",
 85404          "version": "2.1.6.RELEASE",
 85405          "cpe": "cpe:2.3:a:pivotal-software\\,-inc-:spring-rabbit:2.1.6.RELEASE:*:*:*:*:*:*:*",
 85406          "purl": "pkg:maven/org.springframework.amqp/spring-rabbit@2.1.6.RELEASE",
 85407          "swid": {
 85408            "attachment": {}
 85409          },
 85410          "pedigree": {},
 85411          "externalReferences": [
 85412            {
 85413              "type": "build-meta",
 85414              "hashes": [
 85415                {
 85416                  "alg": "SHA-1",
 85417                  "content": "8e9e1ad93bb39d4ffeccf374636f34a6d6a8c4bb"
 85418                }
 85419              ]
 85420            }
 85421          ],
 85422          "evidence": {},
 85423          "signature": {
 85424            "signature": {
 85425              "publicKey": {}
 85426            }
 85427          },
 85428          "modelCard": {
 85429            "modelParameters": {
 85430              "approach": {}
 85431            },
 85432            "quantitativeAnalysis": {
 85433              "graphics": {}
 85434            },
 85435            "considerations": {}
 85436          }
 85437        },
 85438        {
 85439          "type": "library",
 85440          "bom-ref": "pkg:maven/org.springframework.retry/spring-retry@1.2.3.BUILD-SNAPSHOT?package-id=a29549912e50940c",
 85441          "supplier": {},
 85442          "group": "org.springframework.retry",
 85443          "name": "spring-retry",
 85444          "version": "1.2.3.BUILD-SNAPSHOT",
 85445          "cpe": "cpe:2.3:a:springframework:spring-retry:1.2.3.BUILD-SNAPSHOT:*:*:*:*:*:*:*",
 85446          "purl": "pkg:maven/org.springframework.retry/spring-retry@1.2.3.BUILD-SNAPSHOT",
 85447          "swid": {
 85448            "attachment": {}
 85449          },
 85450          "pedigree": {},
 85451          "externalReferences": [
 85452            {
 85453              "type": "build-meta",
 85454              "hashes": [
 85455                {
 85456                  "alg": "SHA-1",
 85457                  "content": "e5a1e629b2743dc7bbe4a8d07ebe9ff6c3b816ce"
 85458                }
 85459              ]
 85460            }
 85461          ],
 85462          "evidence": {},
 85463          "signature": {
 85464            "signature": {
 85465              "publicKey": {}
 85466            }
 85467          },
 85468          "modelCard": {
 85469            "modelParameters": {
 85470              "approach": {}
 85471            },
 85472            "quantitativeAnalysis": {
 85473              "graphics": {}
 85474            },
 85475            "considerations": {}
 85476          }
 85477        },
 85478        {
 85479          "type": "library",
 85480          "bom-ref": "pkg:maven/spring-security-config/spring-security-config@5.1.5.RELEASE?package-id=d5ffa1e8a9a00297",
 85481          "supplier": {},
 85482          "name": "spring-security-config",
 85483          "version": "5.1.5.RELEASE",
 85484          "cpe": "cpe:2.3:a:spring-security-config:spring-security-config:5.1.5.RELEASE:*:*:*:*:*:*:*",
 85485          "purl": "pkg:maven/spring-security-config/spring-security-config@5.1.5.RELEASE",
 85486          "swid": {
 85487            "attachment": {}
 85488          },
 85489          "pedigree": {},
 85490          "externalReferences": [
 85491            {
 85492              "type": "build-meta",
 85493              "hashes": [
 85494                {
 85495                  "alg": "SHA-1",
 85496                  "content": "5b2b4421b0440683f4c253804a1f430094cc2980"
 85497                }
 85498              ]
 85499            }
 85500          ],
 85501          "evidence": {},
 85502          "signature": {
 85503            "signature": {
 85504              "publicKey": {}
 85505            }
 85506          },
 85507          "modelCard": {
 85508            "modelParameters": {
 85509              "approach": {}
 85510            },
 85511            "quantitativeAnalysis": {
 85512              "graphics": {}
 85513            },
 85514            "considerations": {}
 85515          }
 85516        },
 85517        {
 85518          "type": "library",
 85519          "bom-ref": "pkg:maven/spring-security-core/spring-security-core@5.1.5.RELEASE?package-id=dddbe07ab3e84b52",
 85520          "supplier": {},
 85521          "name": "spring-security-core",
 85522          "version": "5.1.5.RELEASE",
 85523          "cpe": "cpe:2.3:a:spring-security-core:spring-security-core:5.1.5.RELEASE:*:*:*:*:*:*:*",
 85524          "purl": "pkg:maven/spring-security-core/spring-security-core@5.1.5.RELEASE",
 85525          "swid": {
 85526            "attachment": {}
 85527          },
 85528          "pedigree": {},
 85529          "externalReferences": [
 85530            {
 85531              "type": "build-meta",
 85532              "hashes": [
 85533                {
 85534                  "alg": "SHA-1",
 85535                  "content": "574d3da85383c09bd5970fe8a3b42756755702bf"
 85536                }
 85537              ]
 85538            }
 85539          ],
 85540          "evidence": {},
 85541          "signature": {
 85542            "signature": {
 85543              "publicKey": {}
 85544            }
 85545          },
 85546          "modelCard": {
 85547            "modelParameters": {
 85548              "approach": {}
 85549            },
 85550            "quantitativeAnalysis": {
 85551              "graphics": {}
 85552            },
 85553            "considerations": {}
 85554          }
 85555        },
 85556        {
 85557          "type": "library",
 85558          "bom-ref": "pkg:maven/org.springframework.security/spring-security-jwt@1.0.10.RELEASE?package-id=f791dcbcca14cdfe",
 85559          "supplier": {},
 85560          "group": "org.springframework.security",
 85561          "name": "spring-security-jwt",
 85562          "version": "1.0.10.RELEASE",
 85563          "cpe": "cpe:2.3:a:spring-security-jwt:spring-security-jwt:1.0.10.RELEASE:*:*:*:*:*:*:*",
 85564          "purl": "pkg:maven/org.springframework.security/spring-security-jwt@1.0.10.RELEASE",
 85565          "swid": {
 85566            "attachment": {}
 85567          },
 85568          "pedigree": {},
 85569          "externalReferences": [
 85570            {
 85571              "type": "build-meta",
 85572              "hashes": [
 85573                {
 85574                  "alg": "SHA-1",
 85575                  "content": "19a1ca7a83e9d263a31af5f529da460f8f863451"
 85576                }
 85577              ]
 85578            }
 85579          ],
 85580          "evidence": {},
 85581          "signature": {
 85582            "signature": {
 85583              "publicKey": {}
 85584            }
 85585          },
 85586          "modelCard": {
 85587            "modelParameters": {
 85588              "approach": {}
 85589            },
 85590            "quantitativeAnalysis": {
 85591              "graphics": {}
 85592            },
 85593            "considerations": {}
 85594          }
 85595        },
 85596        {
 85597          "type": "library",
 85598          "bom-ref": "pkg:maven/spring-security-ldap/spring-security-ldap@5.1.5.RELEASE?package-id=24639cc141b1114e",
 85599          "supplier": {},
 85600          "name": "spring-security-ldap",
 85601          "version": "5.1.5.RELEASE",
 85602          "cpe": "cpe:2.3:a:spring-security-ldap:spring-security-ldap:5.1.5.RELEASE:*:*:*:*:*:*:*",
 85603          "purl": "pkg:maven/spring-security-ldap/spring-security-ldap@5.1.5.RELEASE",
 85604          "swid": {
 85605            "attachment": {}
 85606          },
 85607          "pedigree": {},
 85608          "externalReferences": [
 85609            {
 85610              "type": "build-meta",
 85611              "hashes": [
 85612                {
 85613                  "alg": "SHA-1",
 85614                  "content": "ca4c3cc0583a61d8628638df11f34ad1d6b080cd"
 85615                }
 85616              ]
 85617            }
 85618          ],
 85619          "evidence": {},
 85620          "signature": {
 85621            "signature": {
 85622              "publicKey": {}
 85623            }
 85624          },
 85625          "modelCard": {
 85626            "modelParameters": {
 85627              "approach": {}
 85628            },
 85629            "quantitativeAnalysis": {
 85630              "graphics": {}
 85631            },
 85632            "considerations": {}
 85633          }
 85634        },
 85635        {
 85636          "type": "library",
 85637          "bom-ref": "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.3.5.RELEASE?package-id=11c49786f6c6b18f",
 85638          "supplier": {},
 85639          "group": "org.springframework.security.oauth",
 85640          "name": "spring-security-oauth2",
 85641          "version": "2.3.5.RELEASE",
 85642          "cpe": "cpe:2.3:a:spring-security-oauth2:spring-security-oauth2:2.3.5.RELEASE:*:*:*:*:*:*:*",
 85643          "purl": "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.3.5.RELEASE",
 85644          "swid": {
 85645            "attachment": {}
 85646          },
 85647          "pedigree": {},
 85648          "externalReferences": [
 85649            {
 85650              "type": "build-meta",
 85651              "hashes": [
 85652                {
 85653                  "alg": "SHA-1",
 85654                  "content": "7969f5363398d6d3788bef1740b2ab9509043d51"
 85655                }
 85656              ]
 85657            }
 85658          ],
 85659          "evidence": {},
 85660          "signature": {
 85661            "signature": {
 85662              "publicKey": {}
 85663            }
 85664          },
 85665          "modelCard": {
 85666            "modelParameters": {
 85667              "approach": {}
 85668            },
 85669            "quantitativeAnalysis": {
 85670              "graphics": {}
 85671            },
 85672            "considerations": {}
 85673          }
 85674        },
 85675        {
 85676          "type": "library",
 85677          "bom-ref": "pkg:maven/spring-security-saml2-core/spring-security-saml2-core@1.0.10.RELEASE?package-id=d147a4f6dd7f603f",
 85678          "supplier": {},
 85679          "name": "spring-security-saml2-core",
 85680          "version": "1.0.10.RELEASE",
 85681          "cpe": "cpe:2.3:a:spring-security-saml2-core:spring-security-saml2-core:1.0.10.RELEASE:*:*:*:*:*:*:*",
 85682          "purl": "pkg:maven/spring-security-saml2-core/spring-security-saml2-core@1.0.10.RELEASE",
 85683          "swid": {
 85684            "attachment": {}
 85685          },
 85686          "pedigree": {},
 85687          "externalReferences": [
 85688            {
 85689              "type": "build-meta",
 85690              "hashes": [
 85691                {
 85692                  "alg": "SHA-1",
 85693                  "content": "875e3d97cdab9169b2b2318d3f9f2ff587f31b09"
 85694                }
 85695              ]
 85696            }
 85697          ],
 85698          "evidence": {},
 85699          "signature": {
 85700            "signature": {
 85701              "publicKey": {}
 85702            }
 85703          },
 85704          "modelCard": {
 85705            "modelParameters": {
 85706              "approach": {}
 85707            },
 85708            "quantitativeAnalysis": {
 85709              "graphics": {}
 85710            },
 85711            "considerations": {}
 85712          }
 85713        },
 85714        {
 85715          "type": "library",
 85716          "bom-ref": "pkg:maven/spring-security-web/spring-security-web@5.1.5.RELEASE?package-id=517e3a2cb3946d05",
 85717          "supplier": {},
 85718          "name": "spring-security-web",
 85719          "version": "5.1.5.RELEASE",
 85720          "cpe": "cpe:2.3:a:spring-security-web:spring-security-web:5.1.5.RELEASE:*:*:*:*:*:*:*",
 85721          "purl": "pkg:maven/spring-security-web/spring-security-web@5.1.5.RELEASE",
 85722          "swid": {
 85723            "attachment": {}
 85724          },
 85725          "pedigree": {},
 85726          "externalReferences": [
 85727            {
 85728              "type": "build-meta",
 85729              "hashes": [
 85730                {
 85731                  "alg": "SHA-1",
 85732                  "content": "6183275812460a301a31216e2061afa4929a5f39"
 85733                }
 85734              ]
 85735            }
 85736          ],
 85737          "evidence": {},
 85738          "signature": {
 85739            "signature": {
 85740              "publicKey": {}
 85741            }
 85742          },
 85743          "modelCard": {
 85744            "modelParameters": {
 85745              "approach": {}
 85746            },
 85747            "quantitativeAnalysis": {
 85748              "graphics": {}
 85749            },
 85750            "considerations": {}
 85751          }
 85752        },
 85753        {
 85754          "type": "library",
 85755          "bom-ref": "pkg:maven/spring-tx/spring-tx@5.1.7.RELEASE?package-id=560e8f8126caab11",
 85756          "supplier": {},
 85757          "name": "spring-tx",
 85758          "version": "5.1.7.RELEASE",
 85759          "cpe": "cpe:2.3:a:spring-tx:spring-tx:5.1.7.RELEASE:*:*:*:*:*:*:*",
 85760          "purl": "pkg:maven/spring-tx/spring-tx@5.1.7.RELEASE",
 85761          "swid": {
 85762            "attachment": {}
 85763          },
 85764          "pedigree": {},
 85765          "externalReferences": [
 85766            {
 85767              "type": "build-meta",
 85768              "hashes": [
 85769                {
 85770                  "alg": "SHA-1",
 85771                  "content": "d437d5d353312d94206b469b43e203eba1bdcec6"
 85772                }
 85773              ]
 85774            }
 85775          ],
 85776          "evidence": {},
 85777          "signature": {
 85778            "signature": {
 85779              "publicKey": {}
 85780            }
 85781          },
 85782          "modelCard": {
 85783            "modelParameters": {
 85784              "approach": {}
 85785            },
 85786            "quantitativeAnalysis": {
 85787              "graphics": {}
 85788            },
 85789            "considerations": {}
 85790          }
 85791        },
 85792        {
 85793          "type": "library",
 85794          "bom-ref": "pkg:maven/spring-web/spring-web@5.1.7.RELEASE?package-id=93d105a2f610168a",
 85795          "supplier": {},
 85796          "name": "spring-web",
 85797          "version": "5.1.7.RELEASE",
 85798          "cpe": "cpe:2.3:a:spring-web:spring-web:5.1.7.RELEASE:*:*:*:*:*:*:*",
 85799          "purl": "pkg:maven/spring-web/spring-web@5.1.7.RELEASE",
 85800          "swid": {
 85801            "attachment": {}
 85802          },
 85803          "pedigree": {},
 85804          "externalReferences": [
 85805            {
 85806              "type": "build-meta",
 85807              "hashes": [
 85808                {
 85809                  "alg": "SHA-1",
 85810                  "content": "595dd528ec66eccc6cf4375ea3b56f3605fa1d1f"
 85811                }
 85812              ]
 85813            }
 85814          ],
 85815          "evidence": {},
 85816          "signature": {
 85817            "signature": {
 85818              "publicKey": {}
 85819            }
 85820          },
 85821          "modelCard": {
 85822            "modelParameters": {
 85823              "approach": {}
 85824            },
 85825            "quantitativeAnalysis": {
 85826              "graphics": {}
 85827            },
 85828            "considerations": {}
 85829          }
 85830        },
 85831        {
 85832          "type": "library",
 85833          "bom-ref": "pkg:maven/spring-webmvc/spring-webmvc@5.1.7.RELEASE?package-id=9db104f3357e6737",
 85834          "supplier": {},
 85835          "name": "spring-webmvc",
 85836          "version": "5.1.7.RELEASE",
 85837          "cpe": "cpe:2.3:a:spring-webmvc:spring-webmvc:5.1.7.RELEASE:*:*:*:*:*:*:*",
 85838          "purl": "pkg:maven/spring-webmvc/spring-webmvc@5.1.7.RELEASE",
 85839          "swid": {
 85840            "attachment": {}
 85841          },
 85842          "pedigree": {},
 85843          "externalReferences": [
 85844            {
 85845              "type": "build-meta",
 85846              "hashes": [
 85847                {
 85848                  "alg": "SHA-1",
 85849                  "content": "686326ff513bf4e852b3ee359cf741d92ab82cfe"
 85850                }
 85851              ]
 85852            }
 85853          ],
 85854          "evidence": {},
 85855          "signature": {
 85856            "signature": {
 85857              "publicKey": {}
 85858            }
 85859          },
 85860          "modelCard": {
 85861            "modelParameters": {
 85862              "approach": {}
 85863            },
 85864            "quantitativeAnalysis": {
 85865              "graphics": {}
 85866            },
 85867            "considerations": {}
 85868          }
 85869        },
 85870        {
 85871          "type": "library",
 85872          "bom-ref": "pkg:maven/springfox-bean-validators/springfox-bean-validators@2.9.2?package-id=f488eb90adc06a0d",
 85873          "supplier": {},
 85874          "name": "springfox-bean-validators",
 85875          "version": "2.9.2",
 85876          "cpe": "cpe:2.3:a:springfox-bean-validators:springfox-bean-validators:2.9.2:*:*:*:*:*:*:*",
 85877          "purl": "pkg:maven/springfox-bean-validators/springfox-bean-validators@2.9.2",
 85878          "swid": {
 85879            "attachment": {}
 85880          },
 85881          "pedigree": {},
 85882          "externalReferences": [
 85883            {
 85884              "type": "build-meta",
 85885              "hashes": [
 85886                {
 85887                  "alg": "SHA-1",
 85888                  "content": "b3faf1ce16918ffc9c3b9932855dd667ab390b95"
 85889                }
 85890              ]
 85891            }
 85892          ],
 85893          "evidence": {},
 85894          "signature": {
 85895            "signature": {
 85896              "publicKey": {}
 85897            }
 85898          },
 85899          "modelCard": {
 85900            "modelParameters": {
 85901              "approach": {}
 85902            },
 85903            "quantitativeAnalysis": {
 85904              "graphics": {}
 85905            },
 85906            "considerations": {}
 85907          }
 85908        },
 85909        {
 85910          "type": "library",
 85911          "bom-ref": "pkg:maven/springfox-core/springfox-core@2.9.2?package-id=25c2843a60149cea",
 85912          "supplier": {},
 85913          "name": "springfox-core",
 85914          "version": "2.9.2",
 85915          "cpe": "cpe:2.3:a:springfox-core:springfox-core:2.9.2:*:*:*:*:*:*:*",
 85916          "purl": "pkg:maven/springfox-core/springfox-core@2.9.2",
 85917          "swid": {
 85918            "attachment": {}
 85919          },
 85920          "pedigree": {},
 85921          "externalReferences": [
 85922            {
 85923              "type": "build-meta",
 85924              "hashes": [
 85925                {
 85926                  "alg": "SHA-1",
 85927                  "content": "2e26f58939c594fb5c958c3a1c7bedf83d2f2702"
 85928                }
 85929              ]
 85930            }
 85931          ],
 85932          "evidence": {},
 85933          "signature": {
 85934            "signature": {
 85935              "publicKey": {}
 85936            }
 85937          },
 85938          "modelCard": {
 85939            "modelParameters": {
 85940              "approach": {}
 85941            },
 85942            "quantitativeAnalysis": {
 85943              "graphics": {}
 85944            },
 85945            "considerations": {}
 85946          }
 85947        },
 85948        {
 85949          "type": "library",
 85950          "bom-ref": "pkg:maven/springfox-schema/springfox-schema@2.9.2?package-id=68ccc25090bbe7c1",
 85951          "supplier": {},
 85952          "name": "springfox-schema",
 85953          "version": "2.9.2",
 85954          "cpe": "cpe:2.3:a:springfox-schema:springfox-schema:2.9.2:*:*:*:*:*:*:*",
 85955          "purl": "pkg:maven/springfox-schema/springfox-schema@2.9.2",
 85956          "swid": {
 85957            "attachment": {}
 85958          },
 85959          "pedigree": {},
 85960          "externalReferences": [
 85961            {
 85962              "type": "build-meta",
 85963              "hashes": [
 85964                {
 85965                  "alg": "SHA-1",
 85966                  "content": "e268f38774b16bb51a92ccaef0dcf3dc651c0cee"
 85967                }
 85968              ]
 85969            }
 85970          ],
 85971          "evidence": {},
 85972          "signature": {
 85973            "signature": {
 85974              "publicKey": {}
 85975            }
 85976          },
 85977          "modelCard": {
 85978            "modelParameters": {
 85979              "approach": {}
 85980            },
 85981            "quantitativeAnalysis": {
 85982              "graphics": {}
 85983            },
 85984            "considerations": {}
 85985          }
 85986        },
 85987        {
 85988          "type": "library",
 85989          "bom-ref": "pkg:maven/springfox-spi/springfox-spi@2.9.2?package-id=10b131435db493c9",
 85990          "supplier": {},
 85991          "name": "springfox-spi",
 85992          "version": "2.9.2",
 85993          "cpe": "cpe:2.3:a:springfox-spi:springfox-spi:2.9.2:*:*:*:*:*:*:*",
 85994          "purl": "pkg:maven/springfox-spi/springfox-spi@2.9.2",
 85995          "swid": {
 85996            "attachment": {}
 85997          },
 85998          "pedigree": {},
 85999          "externalReferences": [
 86000            {
 86001              "type": "build-meta",
 86002              "hashes": [
 86003                {
 86004                  "alg": "SHA-1",
 86005                  "content": "6ac686190a6ceaccdae8b50d03b0501d144a6666"
 86006                }
 86007              ]
 86008            }
 86009          ],
 86010          "evidence": {},
 86011          "signature": {
 86012            "signature": {
 86013              "publicKey": {}
 86014            }
 86015          },
 86016          "modelCard": {
 86017            "modelParameters": {
 86018              "approach": {}
 86019            },
 86020            "quantitativeAnalysis": {
 86021              "graphics": {}
 86022            },
 86023            "considerations": {}
 86024          }
 86025        },
 86026        {
 86027          "type": "library",
 86028          "bom-ref": "pkg:maven/springfox-spring-web/springfox-spring-web@2.9.2?package-id=7a092b4ce21c62e1",
 86029          "supplier": {},
 86030          "name": "springfox-spring-web",
 86031          "version": "2.9.2",
 86032          "cpe": "cpe:2.3:a:springfox-spring-web:springfox-spring-web:2.9.2:*:*:*:*:*:*:*",
 86033          "purl": "pkg:maven/springfox-spring-web/springfox-spring-web@2.9.2",
 86034          "swid": {
 86035            "attachment": {}
 86036          },
 86037          "pedigree": {},
 86038          "externalReferences": [
 86039            {
 86040              "type": "build-meta",
 86041              "hashes": [
 86042                {
 86043                  "alg": "SHA-1",
 86044                  "content": "ed2ed714a6cba8804d00f80f0534901e4c7a3211"
 86045                }
 86046              ]
 86047            }
 86048          ],
 86049          "evidence": {},
 86050          "signature": {
 86051            "signature": {
 86052              "publicKey": {}
 86053            }
 86054          },
 86055          "modelCard": {
 86056            "modelParameters": {
 86057              "approach": {}
 86058            },
 86059            "quantitativeAnalysis": {
 86060              "graphics": {}
 86061            },
 86062            "considerations": {}
 86063          }
 86064        },
 86065        {
 86066          "type": "library",
 86067          "bom-ref": "pkg:maven/springfox-swagger-common/springfox-swagger-common@2.9.2?package-id=9451fca5755a6504",
 86068          "supplier": {},
 86069          "name": "springfox-swagger-common",
 86070          "version": "2.9.2",
 86071          "cpe": "cpe:2.3:a:springfox-swagger-common:springfox-swagger-common:2.9.2:*:*:*:*:*:*:*",
 86072          "purl": "pkg:maven/springfox-swagger-common/springfox-swagger-common@2.9.2",
 86073          "swid": {
 86074            "attachment": {}
 86075          },
 86076          "pedigree": {},
 86077          "externalReferences": [
 86078            {
 86079              "type": "build-meta",
 86080              "hashes": [
 86081                {
 86082                  "alg": "SHA-1",
 86083                  "content": "b38a41b3044af80cb7f41f67be5d158c9f6491ec"
 86084                }
 86085              ]
 86086            }
 86087          ],
 86088          "evidence": {},
 86089          "signature": {
 86090            "signature": {
 86091              "publicKey": {}
 86092            }
 86093          },
 86094          "modelCard": {
 86095            "modelParameters": {
 86096              "approach": {}
 86097            },
 86098            "quantitativeAnalysis": {
 86099              "graphics": {}
 86100            },
 86101            "considerations": {}
 86102          }
 86103        },
 86104        {
 86105          "type": "library",
 86106          "bom-ref": "pkg:maven/springfox-swagger-ui/springfox-swagger-ui@2.9.2?package-id=474ec0947481ed6f",
 86107          "supplier": {},
 86108          "name": "springfox-swagger-ui",
 86109          "version": "2.9.2",
 86110          "cpe": "cpe:2.3:a:springfox-swagger-ui:springfox-swagger-ui:2.9.2:*:*:*:*:*:*:*",
 86111          "purl": "pkg:maven/springfox-swagger-ui/springfox-swagger-ui@2.9.2",
 86112          "swid": {
 86113            "attachment": {}
 86114          },
 86115          "pedigree": {},
 86116          "externalReferences": [
 86117            {
 86118              "type": "build-meta",
 86119              "hashes": [
 86120                {
 86121                  "alg": "SHA-1",
 86122                  "content": "d542382a88ff3ea8d4032c28b2b0325797fada7d"
 86123                }
 86124              ]
 86125            }
 86126          ],
 86127          "evidence": {},
 86128          "signature": {
 86129            "signature": {
 86130              "publicKey": {}
 86131            }
 86132          },
 86133          "modelCard": {
 86134            "modelParameters": {
 86135              "approach": {}
 86136            },
 86137            "quantitativeAnalysis": {
 86138              "graphics": {}
 86139            },
 86140            "considerations": {}
 86141          }
 86142        },
 86143        {
 86144          "type": "library",
 86145          "bom-ref": "pkg:maven/springfox-swagger2/springfox-swagger2@2.9.2?package-id=d5191f533c474b8b",
 86146          "supplier": {},
 86147          "name": "springfox-swagger2",
 86148          "version": "2.9.2",
 86149          "cpe": "cpe:2.3:a:springfox-swagger2:springfox-swagger2:2.9.2:*:*:*:*:*:*:*",
 86150          "purl": "pkg:maven/springfox-swagger2/springfox-swagger2@2.9.2",
 86151          "swid": {
 86152            "attachment": {}
 86153          },
 86154          "pedigree": {},
 86155          "externalReferences": [
 86156            {
 86157              "type": "build-meta",
 86158              "hashes": [
 86159                {
 86160                  "alg": "SHA-1",
 86161                  "content": "362676bc7f4c6f9f1d568741becab0dfc198c898"
 86162                }
 86163              ]
 86164            }
 86165          ],
 86166          "evidence": {},
 86167          "signature": {
 86168            "signature": {
 86169              "publicKey": {}
 86170            }
 86171          },
 86172          "modelCard": {
 86173            "modelParameters": {
 86174              "approach": {}
 86175            },
 86176            "quantitativeAnalysis": {
 86177              "graphics": {}
 86178            },
 86179            "considerations": {}
 86180          }
 86181        },
 86182        {
 86183          "type": "library",
 86184          "bom-ref": "pkg:maven/org.apache.sshd/sshd-common@2.9.2?package-id=958c6545f196a307",
 86185          "supplier": {},
 86186          "group": "org.apache.sshd",
 86187          "name": "sshd-common",
 86188          "version": "2.9.2",
 86189          "cpe": "cpe:2.3:a:apache:sshd-common:2.9.2:*:*:*:*:*:*:*",
 86190          "purl": "pkg:maven/org.apache.sshd/sshd-common@2.9.2",
 86191          "swid": {
 86192            "attachment": {}
 86193          },
 86194          "pedigree": {},
 86195          "externalReferences": [
 86196            {
 86197              "type": "build-meta",
 86198              "hashes": [
 86199                {
 86200                  "alg": "SHA-1",
 86201                  "content": "9671e971cf1f05d221c0a86cecc165d88156c8ed"
 86202                }
 86203              ]
 86204            }
 86205          ],
 86206          "evidence": {},
 86207          "signature": {
 86208            "signature": {
 86209              "publicKey": {}
 86210            }
 86211          },
 86212          "modelCard": {
 86213            "modelParameters": {
 86214              "approach": {}
 86215            },
 86216            "quantitativeAnalysis": {
 86217              "graphics": {}
 86218            },
 86219            "considerations": {}
 86220          }
 86221        },
 86222        {
 86223          "type": "library",
 86224          "bom-ref": "pkg:maven/org.apache.sshd/sshd-core@2.9.2?package-id=b55bf3b984df053f",
 86225          "supplier": {},
 86226          "group": "org.apache.sshd",
 86227          "name": "sshd-core",
 86228          "version": "2.9.2",
 86229          "cpe": "cpe:2.3:a:apache:sshd-core:2.9.2:*:*:*:*:*:*:*",
 86230          "purl": "pkg:maven/org.apache.sshd/sshd-core@2.9.2",
 86231          "swid": {
 86232            "attachment": {}
 86233          },
 86234          "pedigree": {},
 86235          "externalReferences": [
 86236            {
 86237              "type": "build-meta",
 86238              "hashes": [
 86239                {
 86240                  "alg": "SHA-1",
 86241                  "content": "cca012d0214f0540dc00903b8f5f731280ca6dfc"
 86242                }
 86243              ]
 86244            }
 86245          ],
 86246          "evidence": {},
 86247          "signature": {
 86248            "signature": {
 86249              "publicKey": {}
 86250            }
 86251          },
 86252          "modelCard": {
 86253            "modelParameters": {
 86254              "approach": {}
 86255            },
 86256            "quantitativeAnalysis": {
 86257              "graphics": {}
 86258            },
 86259            "considerations": {}
 86260          }
 86261        },
 86262        {
 86263          "type": "library",
 86264          "bom-ref": "pkg:maven/org.apache.sshd/sshd-sftp@2.7.0?package-id=93e0d7e052b9e284",
 86265          "supplier": {},
 86266          "group": "org.apache.sshd",
 86267          "name": "sshd-sftp",
 86268          "version": "2.7.0",
 86269          "licenses": [
 86270            {
 86271              "license": {
 86272                "name": "https://www.apache.org/licenses/LICENSE-2.0"
 86273              }
 86274            }
 86275          ],
 86276          "cpe": "cpe:2.3:a:apache:sshd-sftp:2.7.0:*:*:*:*:*:*:*",
 86277          "purl": "pkg:maven/org.apache.sshd/sshd-sftp@2.7.0",
 86278          "swid": {
 86279            "attachment": {}
 86280          },
 86281          "pedigree": {},
 86282          "externalReferences": [
 86283            {
 86284              "type": "build-meta",
 86285              "hashes": [
 86286                {
 86287                  "alg": "SHA-1",
 86288                  "content": "0c9eff7145e20b338c1dd6aca36ba93ed7c0147c"
 86289                }
 86290              ]
 86291            }
 86292          ],
 86293          "evidence": {},
 86294          "signature": {
 86295            "signature": {
 86296              "publicKey": {}
 86297            }
 86298          },
 86299          "modelCard": {
 86300            "modelParameters": {
 86301              "approach": {}
 86302            },
 86303            "quantitativeAnalysis": {
 86304              "graphics": {}
 86305            },
 86306            "considerations": {}
 86307          }
 86308        },
 86309        {
 86310          "type": "library",
 86311          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3\u0026package-id=b15247aafcd4a647",
 86312          "supplier": {},
 86313          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 86314          "name": "ssl_client",
 86315          "version": "1.35.0-r29",
 86316          "description": "EXternal ssl_client for busybox wget",
 86317          "licenses": [
 86318            {
 86319              "license": {
 86320                "id": "GPL-2.0-only"
 86321              }
 86322            }
 86323          ],
 86324          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r29:*:*:*:*:*:*:*",
 86325          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3",
 86326          "swid": {
 86327            "attachment": {}
 86328          },
 86329          "pedigree": {},
 86330          "externalReferences": [
 86331            {
 86332              "url": "https://busybox.net/",
 86333              "type": "distribution"
 86334            }
 86335          ],
 86336          "evidence": {},
 86337          "signature": {
 86338            "signature": {
 86339              "publicKey": {}
 86340            }
 86341          },
 86342          "modelCard": {
 86343            "modelParameters": {
 86344              "approach": {}
 86345            },
 86346            "quantitativeAnalysis": {
 86347              "graphics": {}
 86348            },
 86349            "considerations": {}
 86350          }
 86351        },
 86352        {
 86353          "type": "library",
 86354          "bom-ref": "pkg:maven/com.sun/sunec@1.8.0_362?package-id=514c2349426dbec0",
 86355          "supplier": {},
 86356          "name": "sunec",
 86357          "version": "1.8.0_362",
 86358          "cpe": "cpe:2.3:a:oracle-corporation:sunec:1.8.0_362:*:*:*:*:*:*:*",
 86359          "purl": "pkg:maven/com.sun/sunec@1.8.0_362",
 86360          "swid": {
 86361            "attachment": {}
 86362          },
 86363          "pedigree": {},
 86364          "externalReferences": [
 86365            {
 86366              "type": "build-meta",
 86367              "hashes": [
 86368                {
 86369                  "alg": "SHA-1",
 86370                  "content": "0a226bea7cf5d3f5bc9ab678f9a0abbbf2836ced"
 86371                }
 86372              ]
 86373            }
 86374          ],
 86375          "evidence": {},
 86376          "signature": {
 86377            "signature": {
 86378              "publicKey": {}
 86379            }
 86380          },
 86381          "modelCard": {
 86382            "modelParameters": {
 86383              "approach": {}
 86384            },
 86385            "quantitativeAnalysis": {
 86386              "graphics": {}
 86387            },
 86388            "considerations": {}
 86389          }
 86390        },
 86391        {
 86392          "type": "library",
 86393          "bom-ref": "pkg:maven/com.sun/sunjce_provider@1.8.0_362?package-id=216feec33fd91c68",
 86394          "supplier": {},
 86395          "name": "sunjce_provider",
 86396          "version": "1.8.0_362",
 86397          "cpe": "cpe:2.3:a:oracle-corporation:sunjce-provider:1.8.0_362:*:*:*:*:*:*:*",
 86398          "purl": "pkg:maven/com.sun/sunjce_provider@1.8.0_362",
 86399          "swid": {
 86400            "attachment": {}
 86401          },
 86402          "pedigree": {},
 86403          "externalReferences": [
 86404            {
 86405              "type": "build-meta",
 86406              "hashes": [
 86407                {
 86408                  "alg": "SHA-1",
 86409                  "content": "5d8e01ee58b00457ce81b3ab7641c7cf49c41fe4"
 86410                }
 86411              ]
 86412            }
 86413          ],
 86414          "evidence": {},
 86415          "signature": {
 86416            "signature": {
 86417              "publicKey": {}
 86418            }
 86419          },
 86420          "modelCard": {
 86421            "modelParameters": {
 86422              "approach": {}
 86423            },
 86424            "quantitativeAnalysis": {
 86425              "graphics": {}
 86426            },
 86427            "considerations": {}
 86428          }
 86429        },
 86430        {
 86431          "type": "library",
 86432          "bom-ref": "pkg:maven/com.sun/sunpkcs11@1.8.0_362?package-id=9814d36df586abb0",
 86433          "supplier": {},
 86434          "name": "sunpkcs11",
 86435          "version": "1.8.0_362",
 86436          "cpe": "cpe:2.3:a:oracle-corporation:sunpkcs11:1.8.0_362:*:*:*:*:*:*:*",
 86437          "purl": "pkg:maven/com.sun/sunpkcs11@1.8.0_362",
 86438          "swid": {
 86439            "attachment": {}
 86440          },
 86441          "pedigree": {},
 86442          "externalReferences": [
 86443            {
 86444              "type": "build-meta",
 86445              "hashes": [
 86446                {
 86447                  "alg": "SHA-1",
 86448                  "content": "bcf85f75350c04e0abc12a15ea7a0325d8131599"
 86449                }
 86450              ]
 86451            }
 86452          ],
 86453          "evidence": {},
 86454          "signature": {
 86455            "signature": {
 86456              "publicKey": {}
 86457            }
 86458          },
 86459          "modelCard": {
 86460            "modelParameters": {
 86461              "approach": {}
 86462            },
 86463            "quantitativeAnalysis": {
 86464              "graphics": {}
 86465            },
 86466            "considerations": {}
 86467          }
 86468        },
 86469        {
 86470          "type": "library",
 86471          "bom-ref": "pkg:maven/io.swagger/swagger-annotations@1.5.20?package-id=e89aa63cc87f8d71",
 86472          "supplier": {},
 86473          "group": "io.swagger",
 86474          "name": "swagger-annotations",
 86475          "version": "1.5.20",
 86476          "licenses": [
 86477            {
 86478              "license": {
 86479                "name": "http://www.apache.org/licenses/LICENSE-2.0.html"
 86480              }
 86481            }
 86482          ],
 86483          "cpe": "cpe:2.3:a:swagger-annotations:swagger-annotations:1.5.20:*:*:*:*:*:*:*",
 86484          "purl": "pkg:maven/io.swagger/swagger-annotations@1.5.20",
 86485          "swid": {
 86486            "attachment": {}
 86487          },
 86488          "pedigree": {},
 86489          "externalReferences": [
 86490            {
 86491              "type": "build-meta",
 86492              "hashes": [
 86493                {
 86494                  "alg": "SHA-1",
 86495                  "content": "16051f93ce11ca489a5313775d825f82fcc2cd6c"
 86496                }
 86497              ]
 86498            }
 86499          ],
 86500          "evidence": {},
 86501          "signature": {
 86502            "signature": {
 86503              "publicKey": {}
 86504            }
 86505          },
 86506          "modelCard": {
 86507            "modelParameters": {
 86508              "approach": {}
 86509            },
 86510            "quantitativeAnalysis": {
 86511              "graphics": {}
 86512            },
 86513            "considerations": {}
 86514          }
 86515        },
 86516        {
 86517          "type": "library",
 86518          "bom-ref": "pkg:maven/io.swagger/swagger-models@1.5.20?package-id=15018d9ee70a1a6a",
 86519          "supplier": {},
 86520          "group": "io.swagger",
 86521          "name": "swagger-models",
 86522          "version": "1.5.20",
 86523          "licenses": [
 86524            {
 86525              "license": {
 86526                "name": "http://www.apache.org/licenses/LICENSE-2.0.html"
 86527              }
 86528            }
 86529          ],
 86530          "cpe": "cpe:2.3:a:swagger-models:swagger-models:1.5.20:*:*:*:*:*:*:*",
 86531          "purl": "pkg:maven/io.swagger/swagger-models@1.5.20",
 86532          "swid": {
 86533            "attachment": {}
 86534          },
 86535          "pedigree": {},
 86536          "externalReferences": [
 86537            {
 86538              "type": "build-meta",
 86539              "hashes": [
 86540                {
 86541                  "alg": "SHA-1",
 86542                  "content": "fb3a23bad80c5ed84db9dd150db2cba699531458"
 86543                }
 86544              ]
 86545            }
 86546          ],
 86547          "evidence": {},
 86548          "signature": {
 86549            "signature": {
 86550              "publicKey": {}
 86551            }
 86552          },
 86553          "modelCard": {
 86554            "modelParameters": {
 86555              "approach": {}
 86556            },
 86557            "quantitativeAnalysis": {
 86558              "graphics": {}
 86559            },
 86560            "considerations": {}
 86561          }
 86562        },
 86563        {
 86564          "type": "library",
 86565          "bom-ref": "pkg:maven/com.cloudbees/syslog-java-client@1.1.7?package-id=fe5f0f7fb5c74ceb",
 86566          "supplier": {},
 86567          "group": "com.cloudbees",
 86568          "name": "syslog-java-client",
 86569          "version": "1.1.7",
 86570          "licenses": [
 86571            {
 86572              "license": {
 86573                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 86574              }
 86575            }
 86576          ],
 86577          "cpe": "cpe:2.3:a:syslog-java-client:syslog-java-client:1.1.7:*:*:*:*:*:*:*",
 86578          "purl": "pkg:maven/com.cloudbees/syslog-java-client@1.1.7",
 86579          "swid": {
 86580            "attachment": {}
 86581          },
 86582          "pedigree": {},
 86583          "externalReferences": [
 86584            {
 86585              "type": "build-meta",
 86586              "hashes": [
 86587                {
 86588                  "alg": "SHA-1",
 86589                  "content": "6ba4901c24dca556168bffb0901d694ac50ec001"
 86590                }
 86591              ]
 86592            }
 86593          ],
 86594          "evidence": {},
 86595          "signature": {
 86596            "signature": {
 86597              "publicKey": {}
 86598            }
 86599          },
 86600          "modelCard": {
 86601            "modelParameters": {
 86602              "approach": {}
 86603            },
 86604            "quantitativeAnalysis": {
 86605              "graphics": {}
 86606            },
 86607            "considerations": {}
 86608          }
 86609        },
 86610        {
 86611          "type": "library",
 86612          "bom-ref": "pkg:maven/tomcat-embed-core/tomcat-embed-core@9.0.19?package-id=33d2dac97873d51b",
 86613          "supplier": {},
 86614          "name": "tomcat-embed-core",
 86615          "version": "9.0.19",
 86616          "cpe": "cpe:2.3:a:apache-software-foundation:tomcat-embed-core:9.0.19:*:*:*:*:*:*:*",
 86617          "purl": "pkg:maven/tomcat-embed-core/tomcat-embed-core@9.0.19",
 86618          "swid": {
 86619            "attachment": {}
 86620          },
 86621          "pedigree": {},
 86622          "externalReferences": [
 86623            {
 86624              "type": "build-meta",
 86625              "hashes": [
 86626                {
 86627                  "alg": "SHA-1",
 86628                  "content": "56e42e12bf92b713befd0700430f7c5c0af68d49"
 86629                }
 86630              ]
 86631            }
 86632          ],
 86633          "evidence": {},
 86634          "signature": {
 86635            "signature": {
 86636              "publicKey": {}
 86637            }
 86638          },
 86639          "modelCard": {
 86640            "modelParameters": {
 86641              "approach": {}
 86642            },
 86643            "quantitativeAnalysis": {
 86644              "graphics": {}
 86645            },
 86646            "considerations": {}
 86647          }
 86648        },
 86649        {
 86650          "type": "library",
 86651          "bom-ref": "pkg:maven/tomcat-embed-el/tomcat-embed-el@9.0.19?package-id=cd2853c430aec202",
 86652          "supplier": {},
 86653          "name": "tomcat-embed-el",
 86654          "version": "9.0.19",
 86655          "cpe": "cpe:2.3:a:apache-software-foundation:tomcat-embed-el:9.0.19:*:*:*:*:*:*:*",
 86656          "purl": "pkg:maven/tomcat-embed-el/tomcat-embed-el@9.0.19",
 86657          "swid": {
 86658            "attachment": {}
 86659          },
 86660          "pedigree": {},
 86661          "externalReferences": [
 86662            {
 86663              "type": "build-meta",
 86664              "hashes": [
 86665                {
 86666                  "alg": "SHA-1",
 86667                  "content": "6145f2cd11c7df4ad9463637087c0f7e8e673394"
 86668                }
 86669              ]
 86670            }
 86671          ],
 86672          "evidence": {},
 86673          "signature": {
 86674            "signature": {
 86675              "publicKey": {}
 86676            }
 86677          },
 86678          "modelCard": {
 86679            "modelParameters": {
 86680              "approach": {}
 86681            },
 86682            "quantitativeAnalysis": {
 86683              "graphics": {}
 86684            },
 86685            "considerations": {}
 86686          }
 86687        },
 86688        {
 86689          "type": "library",
 86690          "bom-ref": "pkg:maven/tomcat-embed-websocket/tomcat-embed-websocket@9.0.19?package-id=e5ccc678a9e73aa6",
 86691          "supplier": {},
 86692          "name": "tomcat-embed-websocket",
 86693          "version": "9.0.19",
 86694          "cpe": "cpe:2.3:a:apache-software-foundation:tomcat-embed-websocket:9.0.19:*:*:*:*:*:*:*",
 86695          "purl": "pkg:maven/tomcat-embed-websocket/tomcat-embed-websocket@9.0.19",
 86696          "swid": {
 86697            "attachment": {}
 86698          },
 86699          "pedigree": {},
 86700          "externalReferences": [
 86701            {
 86702              "type": "build-meta",
 86703              "hashes": [
 86704                {
 86705                  "alg": "SHA-1",
 86706                  "content": "dee79022818f490203f4901f5651f3233aee14db"
 86707                }
 86708              ]
 86709            }
 86710          ],
 86711          "evidence": {},
 86712          "signature": {
 86713            "signature": {
 86714              "publicKey": {}
 86715            }
 86716          },
 86717          "modelCard": {
 86718            "modelParameters": {
 86719              "approach": {}
 86720            },
 86721            "quantitativeAnalysis": {
 86722              "graphics": {}
 86723            },
 86724            "considerations": {}
 86725          }
 86726        },
 86727        {
 86728          "type": "library",
 86729          "bom-ref": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=7443bdf13c73d18c",
 86730          "supplier": {},
 86731          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 86732          "name": "tzdata",
 86733          "version": "2023c-r0",
 86734          "description": "Timezone data",
 86735          "licenses": [
 86736            {
 86737              "license": {
 86738                "name": "Public-Domain"
 86739              }
 86740            }
 86741          ],
 86742          "cpe": "cpe:2.3:a:tzdata:tzdata:2023c-r0:*:*:*:*:*:*:*",
 86743          "purl": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 86744          "swid": {
 86745            "attachment": {}
 86746          },
 86747          "pedigree": {},
 86748          "externalReferences": [
 86749            {
 86750              "url": "https://www.iana.org/time-zones",
 86751              "type": "distribution"
 86752            }
 86753          ],
 86754          "evidence": {},
 86755          "signature": {
 86756            "signature": {
 86757              "publicKey": {}
 86758            }
 86759          },
 86760          "modelCard": {
 86761            "modelParameters": {
 86762              "approach": {}
 86763            },
 86764            "quantitativeAnalysis": {
 86765              "graphics": {}
 86766            },
 86767            "considerations": {}
 86768          }
 86769        },
 86770        {
 86771          "type": "library",
 86772          "bom-ref": "pkg:maven/com.github.fge.uri-template/uri-template@0.9?package-id=3efcc5659df7c3df",
 86773          "supplier": {},
 86774          "name": "uri-template",
 86775          "version": "0.9",
 86776          "cpe": "cpe:2.3:a:uri-template:uri-template:0.9:*:*:*:*:*:*:*",
 86777          "purl": "pkg:maven/com.github.fge.uri-template/uri-template@0.9",
 86778          "swid": {
 86779            "attachment": {}
 86780          },
 86781          "pedigree": {},
 86782          "externalReferences": [
 86783            {
 86784              "type": "build-meta",
 86785              "hashes": [
 86786                {
 86787                  "alg": "SHA-1",
 86788                  "content": "ab1ad5804d3c7d640f21059085df5be340e97929"
 86789                }
 86790              ]
 86791            }
 86792          ],
 86793          "evidence": {},
 86794          "signature": {
 86795            "signature": {
 86796              "publicKey": {}
 86797            }
 86798          },
 86799          "modelCard": {
 86800            "modelParameters": {
 86801              "approach": {}
 86802            },
 86803            "quantitativeAnalysis": {
 86804              "graphics": {}
 86805            },
 86806            "considerations": {}
 86807          }
 86808        },
 86809        {
 86810          "type": "library",
 86811          "bom-ref": "pkg:maven/validation-api/validation-api@2.0.1.Final?package-id=4129ab5791a4fb3",
 86812          "supplier": {},
 86813          "group": "javax.validation",
 86814          "name": "validation-api",
 86815          "version": "2.0.1.Final",
 86816          "licenses": [
 86817            {
 86818              "license": {
 86819                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 86820              }
 86821            }
 86822          ],
 86823          "cpe": "cpe:2.3:a:validation-api:validation-api:2.0.1.Final:*:*:*:*:*:*:*",
 86824          "purl": "pkg:maven/validation-api/validation-api@2.0.1.Final",
 86825          "swid": {
 86826            "attachment": {}
 86827          },
 86828          "pedigree": {},
 86829          "externalReferences": [
 86830            {
 86831              "type": "build-meta",
 86832              "hashes": [
 86833                {
 86834                  "alg": "SHA-1",
 86835                  "content": "cb855558e6271b1b32e716d24cb85c7f583ce09e"
 86836                }
 86837              ]
 86838            }
 86839          ],
 86840          "evidence": {},
 86841          "signature": {
 86842            "signature": {
 86843              "publicKey": {}
 86844            }
 86845          },
 86846          "modelCard": {
 86847            "modelParameters": {
 86848              "approach": {}
 86849            },
 86850            "quantitativeAnalysis": {
 86851              "graphics": {}
 86852            },
 86853            "considerations": {}
 86854          }
 86855        },
 86856        {
 86857          "type": "library",
 86858          "bom-ref": "pkg:maven/org.apache.velocity/velocity-engine-core@2.0?package-id=465873a66ccbe167",
 86859          "supplier": {},
 86860          "group": "org.apache.velocity",
 86861          "name": "velocity-engine-core",
 86862          "version": "2.0",
 86863          "cpe": "cpe:2.3:a:apache:velocity-engine-core:2.0:*:*:*:*:*:*:*",
 86864          "purl": "pkg:maven/org.apache.velocity/velocity-engine-core@2.0",
 86865          "swid": {
 86866            "attachment": {}
 86867          },
 86868          "pedigree": {},
 86869          "externalReferences": [
 86870            {
 86871              "type": "build-meta",
 86872              "hashes": [
 86873                {
 86874                  "alg": "SHA-1",
 86875                  "content": "6e5f29e1237b1764a4ce769feeffb85b0b19cfa7"
 86876                }
 86877              ]
 86878            }
 86879          ],
 86880          "evidence": {},
 86881          "signature": {
 86882            "signature": {
 86883              "publicKey": {}
 86884            }
 86885          },
 86886          "modelCard": {
 86887            "modelParameters": {
 86888              "approach": {}
 86889            },
 86890            "quantitativeAnalysis": {
 86891              "graphics": {}
 86892            },
 86893            "considerations": {}
 86894          }
 86895        },
 86896        {
 86897          "type": "library",
 86898          "bom-ref": "pkg:maven/org.apache.regexp/xalan@2.7.2?package-id=94d309c35f3c271f",
 86899          "supplier": {},
 86900          "name": "xalan",
 86901          "version": "2.7.2",
 86902          "cpe": "cpe:2.3:a:apache:regexp:2.7.2:*:*:*:*:*:*:*",
 86903          "purl": "pkg:maven/org.apache.regexp/xalan@2.7.2",
 86904          "swid": {
 86905            "attachment": {}
 86906          },
 86907          "pedigree": {},
 86908          "externalReferences": [
 86909            {
 86910              "type": "build-meta",
 86911              "hashes": [
 86912                {
 86913                  "alg": "SHA-1",
 86914                  "content": "d55d3f02a56ec4c25695fe67e1334ff8c2ecea23"
 86915                }
 86916              ]
 86917            }
 86918          ],
 86919          "evidence": {},
 86920          "signature": {
 86921            "signature": {
 86922              "publicKey": {}
 86923            }
 86924          },
 86925          "modelCard": {
 86926            "modelParameters": {
 86927              "approach": {}
 86928            },
 86929            "quantitativeAnalysis": {
 86930              "graphics": {}
 86931            },
 86932            "considerations": {}
 86933          }
 86934        },
 86935        {
 86936          "type": "library",
 86937          "bom-ref": "pkg:maven/org.apache.xerces.xni/xercesImpl@2.12.0?package-id=645b9f1316e533ef",
 86938          "supplier": {},
 86939          "name": "xercesImpl",
 86940          "version": "2.12.0",
 86941          "cpe": "cpe:2.3:a:apache:xercesImpl:2.12.0:*:*:*:*:*:*:*",
 86942          "purl": "pkg:maven/org.apache.xerces.xni/xercesImpl@2.12.0",
 86943          "swid": {
 86944            "attachment": {}
 86945          },
 86946          "pedigree": {},
 86947          "externalReferences": [
 86948            {
 86949              "type": "build-meta",
 86950              "hashes": [
 86951                {
 86952                  "alg": "SHA-1",
 86953                  "content": "f02c844149fd306601f20e0b34853a670bef7fa2"
 86954                }
 86955              ]
 86956            }
 86957          ],
 86958          "evidence": {},
 86959          "signature": {
 86960            "signature": {
 86961              "publicKey": {}
 86962            }
 86963          },
 86964          "modelCard": {
 86965            "modelParameters": {
 86966              "approach": {}
 86967            },
 86968            "quantitativeAnalysis": {
 86969              "graphics": {}
 86970            },
 86971            "considerations": {}
 86972          }
 86973        },
 86974        {
 86975          "type": "library",
 86976          "bom-ref": "pkg:maven/org.apache.xmlcommons.Version/xml-apis@1.4.01?package-id=c149efa9295bd2ad",
 86977          "supplier": {},
 86978          "name": "xml-apis",
 86979          "version": "1.4.01",
 86980          "cpe": "cpe:2.3:a:apache:xmlcommons:1.4.01:*:*:*:*:*:*:*",
 86981          "purl": "pkg:maven/org.apache.xmlcommons.Version/xml-apis@1.4.01",
 86982          "swid": {
 86983            "attachment": {}
 86984          },
 86985          "pedigree": {},
 86986          "externalReferences": [
 86987            {
 86988              "type": "build-meta",
 86989              "hashes": [
 86990                {
 86991                  "alg": "SHA-1",
 86992                  "content": "3789d9fada2d3d458c4ba2de349d48780f381ee3"
 86993                }
 86994              ]
 86995            }
 86996          ],
 86997          "evidence": {},
 86998          "signature": {
 86999            "signature": {
 87000              "publicKey": {}
 87001            }
 87002          },
 87003          "modelCard": {
 87004            "modelParameters": {
 87005              "approach": {}
 87006            },
 87007            "quantitativeAnalysis": {
 87008              "graphics": {}
 87009            },
 87010            "considerations": {}
 87011          }
 87012        },
 87013        {
 87014          "type": "library",
 87015          "bom-ref": "pkg:maven/org.apache.santuario/xmlsec@1.5.8?package-id=21c5f40e8df93bae",
 87016          "supplier": {},
 87017          "group": "org.apache.santuario",
 87018          "name": "xmlsec",
 87019          "version": "1.5.8",
 87020          "licenses": [
 87021            {
 87022              "license": {
 87023                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
 87024              }
 87025            }
 87026          ],
 87027          "cpe": "cpe:2.3:a:apache:xmlsec:1.5.8:*:*:*:*:*:*:*",
 87028          "purl": "pkg:maven/org.apache.santuario/xmlsec@1.5.8",
 87029          "swid": {
 87030            "attachment": {}
 87031          },
 87032          "pedigree": {},
 87033          "externalReferences": [
 87034            {
 87035              "type": "build-meta",
 87036              "hashes": [
 87037                {
 87038                  "alg": "SHA-1",
 87039                  "content": "d0b5e51f571069a86c9578ec15d6d7f9da8c0e76"
 87040                }
 87041              ]
 87042            }
 87043          ],
 87044          "evidence": {},
 87045          "signature": {
 87046            "signature": {
 87047              "publicKey": {}
 87048            }
 87049          },
 87050          "modelCard": {
 87051            "modelParameters": {
 87052              "approach": {}
 87053            },
 87054            "quantitativeAnalysis": {
 87055              "graphics": {}
 87056            },
 87057            "considerations": {}
 87058          }
 87059        },
 87060        {
 87061          "type": "library",
 87062          "bom-ref": "pkg:maven/org.opensaml/xmltooling@1.4.6?package-id=2984577e743bd1d7",
 87063          "supplier": {},
 87064          "group": "org.opensaml",
 87065          "name": "xmltooling",
 87066          "version": "1.4.6",
 87067          "cpe": "cpe:2.3:a:world-wide-web-consortium-\\(w3c\\):xmltooling:1.4.6:*:*:*:*:*:*:*",
 87068          "purl": "pkg:maven/org.opensaml/xmltooling@1.4.6",
 87069          "swid": {
 87070            "attachment": {}
 87071          },
 87072          "pedigree": {},
 87073          "externalReferences": [
 87074            {
 87075              "type": "build-meta",
 87076              "hashes": [
 87077                {
 87078                  "alg": "SHA-1",
 87079                  "content": "6fd85523ede1bd431de1099b822ee55d4d08b7ea"
 87080                }
 87081              ]
 87082            }
 87083          ],
 87084          "evidence": {},
 87085          "signature": {
 87086            "signature": {
 87087              "publicKey": {}
 87088            }
 87089          },
 87090          "modelCard": {
 87091            "modelParameters": {
 87092              "approach": {}
 87093            },
 87094            "quantitativeAnalysis": {
 87095              "graphics": {}
 87096            },
 87097            "considerations": {}
 87098          }
 87099        },
 87100        {
 87101          "type": "library",
 87102          "bom-ref": "pkg:maven/org.jaxen/xom@1.2.10?package-id=870b998e44787398",
 87103          "supplier": {},
 87104          "name": "xom",
 87105          "version": "1.2.10",
 87106          "cpe": "cpe:2.3:a:elliotte-rusty-harold:xom:1.2.10:*:*:*:*:*:*:*",
 87107          "purl": "pkg:maven/org.jaxen/xom@1.2.10",
 87108          "swid": {
 87109            "attachment": {}
 87110          },
 87111          "pedigree": {},
 87112          "externalReferences": [
 87113            {
 87114              "type": "build-meta",
 87115              "hashes": [
 87116                {
 87117                  "alg": "SHA-1",
 87118                  "content": "4165e25bef19aad134f6498cc277110b9bc5e52b"
 87119                }
 87120              ]
 87121            }
 87122          ],
 87123          "evidence": {},
 87124          "signature": {
 87125            "signature": {
 87126              "publicKey": {}
 87127            }
 87128          },
 87129          "modelCard": {
 87130            "modelParameters": {
 87131              "approach": {}
 87132            },
 87133            "quantitativeAnalysis": {
 87134              "graphics": {}
 87135            },
 87136            "considerations": {}
 87137          }
 87138        },
 87139        {
 87140          "type": "library",
 87141          "bom-ref": "pkg:maven/xpp3/xpp3@1.1.4c?package-id=8468e86ac9b50905",
 87142          "supplier": {},
 87143          "name": "xpp3",
 87144          "version": "1.1.4c",
 87145          "cpe": "cpe:2.3:a:xpp3:xpp3:1.1.4c:*:*:*:*:*:*:*",
 87146          "purl": "pkg:maven/xpp3/xpp3@1.1.4c",
 87147          "swid": {
 87148            "attachment": {}
 87149          },
 87150          "pedigree": {},
 87151          "externalReferences": [
 87152            {
 87153              "type": "build-meta",
 87154              "hashes": [
 87155                {
 87156                  "alg": "SHA-1",
 87157                  "content": "9b988ea84b9e4e9f1874e390ce099b8ac12cfff5"
 87158                }
 87159              ]
 87160            }
 87161          ],
 87162          "evidence": {},
 87163          "signature": {
 87164            "signature": {
 87165              "publicKey": {}
 87166            }
 87167          },
 87168          "modelCard": {
 87169            "modelParameters": {
 87170              "approach": {}
 87171            },
 87172            "quantitativeAnalysis": {
 87173              "graphics": {}
 87174            },
 87175            "considerations": {}
 87176          }
 87177        },
 87178        {
 87179          "type": "library",
 87180          "bom-ref": "pkg:maven/zipfs/zipfs@1.8.0_362?package-id=649443e35eb779e0",
 87181          "supplier": {},
 87182          "name": "zipfs",
 87183          "version": "1.8.0_362",
 87184          "cpe": "cpe:2.3:a:oracle-corporation:zipfs:1.8.0_362:*:*:*:*:*:*:*",
 87185          "purl": "pkg:maven/zipfs/zipfs@1.8.0_362",
 87186          "swid": {
 87187            "attachment": {}
 87188          },
 87189          "pedigree": {},
 87190          "externalReferences": [
 87191            {
 87192              "type": "build-meta",
 87193              "hashes": [
 87194                {
 87195                  "alg": "SHA-1",
 87196                  "content": "8826341a6c075308576e50fa5f97c0cdbea0b844"
 87197                }
 87198              ]
 87199            }
 87200          ],
 87201          "evidence": {},
 87202          "signature": {
 87203            "signature": {
 87204              "publicKey": {}
 87205            }
 87206          },
 87207          "modelCard": {
 87208            "modelParameters": {
 87209              "approach": {}
 87210            },
 87211            "quantitativeAnalysis": {
 87212              "graphics": {}
 87213            },
 87214            "considerations": {}
 87215          }
 87216        },
 87217        {
 87218          "type": "library",
 87219          "bom-ref": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=94014313cfcd2b71",
 87220          "supplier": {},
 87221          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 87222          "name": "zlib",
 87223          "version": "1.2.13-r0",
 87224          "description": "A compression/decompression Library",
 87225          "licenses": [
 87226            {
 87227              "license": {
 87228                "id": "Zlib"
 87229              }
 87230            }
 87231          ],
 87232          "cpe": "cpe:2.3:a:zlib:zlib:1.2.13-r0:*:*:*:*:*:*:*",
 87233          "purl": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.3",
 87234          "swid": {
 87235            "attachment": {}
 87236          },
 87237          "pedigree": {},
 87238          "externalReferences": [
 87239            {
 87240              "url": "https://zlib.net/",
 87241              "type": "distribution"
 87242            }
 87243          ],
 87244          "evidence": {},
 87245          "signature": {
 87246            "signature": {
 87247              "publicKey": {}
 87248            }
 87249          },
 87250          "modelCard": {
 87251            "modelParameters": {
 87252              "approach": {}
 87253            },
 87254            "quantitativeAnalysis": {
 87255              "graphics": {}
 87256            },
 87257            "considerations": {}
 87258          }
 87259        },
 87260        {
 87261          "type": "operating-system",
 87262          "supplier": {},
 87263          "name": "alpine",
 87264          "version": "3.17.3",
 87265          "description": "Alpine Linux v3.17",
 87266          "swid": {
 87267            "tagId": "alpine",
 87268            "name": "alpine",
 87269            "version": "3.17.3",
 87270            "attachment": {}
 87271          },
 87272          "pedigree": {},
 87273          "externalReferences": [
 87274            {
 87275              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
 87276              "type": "issue-tracker"
 87277            },
 87278            {
 87279              "url": "https://alpinelinux.org/",
 87280              "type": "website"
 87281            }
 87282          ],
 87283          "evidence": {},
 87284          "signature": {
 87285            "signature": {
 87286              "publicKey": {}
 87287            }
 87288          },
 87289          "modelCard": {
 87290            "modelParameters": {
 87291              "approach": {}
 87292            },
 87293            "quantitativeAnalysis": {
 87294              "graphics": {}
 87295            },
 87296            "considerations": {}
 87297          }
 87298        },
 87299        {
 87300          "type": "library",
 87301          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r7?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=67989f19e27ea0ca",
 87302          "supplier": {},
 87303          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 87304          "name": "alpine-baselayout",
 87305          "version": "3.2.0-r7",
 87306          "description": "Alpine base dir structure and init scripts",
 87307          "licenses": [
 87308            {
 87309              "license": {
 87310                "id": "GPL-2.0-only"
 87311              }
 87312            }
 87313          ],
 87314          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r7:*:*:*:*:*:*:*",
 87315          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r7?arch=x86_64\u0026distro=alpine-3.12.3",
 87316          "swid": {
 87317            "attachment": {}
 87318          },
 87319          "pedigree": {},
 87320          "externalReferences": [
 87321            {
 87322              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 87323              "type": "distribution"
 87324            }
 87325          ],
 87326          "evidence": {},
 87327          "signature": {
 87328            "signature": {
 87329              "publicKey": {}
 87330            }
 87331          },
 87332          "modelCard": {
 87333            "modelParameters": {
 87334              "approach": {}
 87335            },
 87336            "quantitativeAnalysis": {
 87337              "graphics": {}
 87338            },
 87339            "considerations": {}
 87340          }
 87341        },
 87342        {
 87343          "type": "library",
 87344          "bom-ref": "pkg:apk/alpine/alpine-keys@2.2-r0?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=6e76b2cc6bf8236",
 87345          "supplier": {},
 87346          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 87347          "name": "alpine-keys",
 87348          "version": "2.2-r0",
 87349          "description": "Public keys for Alpine Linux packages",
 87350          "licenses": [
 87351            {
 87352              "license": {
 87353                "id": "MIT"
 87354              }
 87355            }
 87356          ],
 87357          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.2-r0:*:*:*:*:*:*:*",
 87358          "purl": "pkg:apk/alpine/alpine-keys@2.2-r0?arch=x86_64\u0026distro=alpine-3.12.3",
 87359          "swid": {
 87360            "attachment": {}
 87361          },
 87362          "pedigree": {},
 87363          "externalReferences": [
 87364            {
 87365              "url": "https://alpinelinux.org",
 87366              "type": "distribution"
 87367            }
 87368          ],
 87369          "evidence": {},
 87370          "signature": {
 87371            "signature": {
 87372              "publicKey": {}
 87373            }
 87374          },
 87375          "modelCard": {
 87376            "modelParameters": {
 87377              "approach": {}
 87378            },
 87379            "quantitativeAnalysis": {
 87380              "graphics": {}
 87381            },
 87382            "considerations": {}
 87383          }
 87384        },
 87385        {
 87386          "type": "library",
 87387          "bom-ref": "pkg:apk/alpine/apk-tools@2.10.5-r1?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=4c5552e9bb4204e",
 87388          "supplier": {},
 87389          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 87390          "name": "apk-tools",
 87391          "version": "2.10.5-r1",
 87392          "description": "Alpine Package Keeper - package manager for alpine",
 87393          "licenses": [
 87394            {
 87395              "license": {
 87396                "id": "GPL-2.0-only"
 87397              }
 87398            }
 87399          ],
 87400          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.10.5-r1:*:*:*:*:*:*:*",
 87401          "purl": "pkg:apk/alpine/apk-tools@2.10.5-r1?arch=x86_64\u0026distro=alpine-3.12.3",
 87402          "swid": {
 87403            "attachment": {}
 87404          },
 87405          "pedigree": {},
 87406          "externalReferences": [
 87407            {
 87408              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
 87409              "type": "distribution"
 87410            }
 87411          ],
 87412          "evidence": {},
 87413          "signature": {
 87414            "signature": {
 87415              "publicKey": {}
 87416            }
 87417          },
 87418          "modelCard": {
 87419            "modelParameters": {
 87420              "approach": {}
 87421            },
 87422            "quantitativeAnalysis": {
 87423              "graphics": {}
 87424            },
 87425            "considerations": {}
 87426          }
 87427        },
 87428        {
 87429          "type": "library",
 87430          "bom-ref": "pkg:apk/alpine/bash@5.0.17-r0?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=9550803fa7ca62f3",
 87431          "supplier": {},
 87432          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 87433          "name": "bash",
 87434          "version": "5.0.17-r0",
 87435          "description": "The GNU Bourne Again shell",
 87436          "licenses": [
 87437            {
 87438              "license": {
 87439                "id": "GPL-3.0-or-later"
 87440              }
 87441            }
 87442          ],
 87443          "cpe": "cpe:2.3:a:bash:bash:5.0.17-r0:*:*:*:*:*:*:*",
 87444          "purl": "pkg:apk/alpine/bash@5.0.17-r0?arch=x86_64\u0026distro=alpine-3.12.3",
 87445          "swid": {
 87446            "attachment": {}
 87447          },
 87448          "pedigree": {},
 87449          "externalReferences": [
 87450            {
 87451              "url": "https://www.gnu.org/software/bash/bash.html",
 87452              "type": "distribution"
 87453            }
 87454          ],
 87455          "evidence": {},
 87456          "signature": {
 87457            "signature": {
 87458              "publicKey": {}
 87459            }
 87460          },
 87461          "modelCard": {
 87462            "modelParameters": {
 87463              "approach": {}
 87464            },
 87465            "quantitativeAnalysis": {
 87466              "graphics": {}
 87467            },
 87468            "considerations": {}
 87469          }
 87470        },
 87471        {
 87472          "type": "application",
 87473          "bom-ref": "789317c78087a0ae",
 87474          "supplier": {},
 87475          "name": "busybox",
 87476          "version": "1.31.1",
 87477          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1:*:*:*:*:*:*:*",
 87478          "swid": {
 87479            "attachment": {}
 87480          },
 87481          "pedigree": {},
 87482          "evidence": {},
 87483          "signature": {
 87484            "signature": {
 87485              "publicKey": {}
 87486            }
 87487          },
 87488          "modelCard": {
 87489            "modelParameters": {
 87490              "approach": {}
 87491            },
 87492            "quantitativeAnalysis": {
 87493              "graphics": {}
 87494            },
 87495            "considerations": {}
 87496          }
 87497        },
 87498        {
 87499          "type": "library",
 87500          "bom-ref": "pkg:apk/alpine/busybox@1.31.1-r19?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=9d15fb154d2c566a",
 87501          "supplier": {},
 87502          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 87503          "name": "busybox",
 87504          "version": "1.31.1-r19",
 87505          "description": "Size optimized toolbox of many common UNIX utilities",
 87506          "licenses": [
 87507            {
 87508              "license": {
 87509                "id": "GPL-2.0-only"
 87510              }
 87511            }
 87512          ],
 87513          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1-r19:*:*:*:*:*:*:*",
 87514          "purl": "pkg:apk/alpine/busybox@1.31.1-r19?arch=x86_64\u0026distro=alpine-3.12.3",
 87515          "swid": {
 87516            "attachment": {}
 87517          },
 87518          "pedigree": {},
 87519          "externalReferences": [
 87520            {
 87521              "url": "https://busybox.net/",
 87522              "type": "distribution"
 87523            }
 87524          ],
 87525          "evidence": {},
 87526          "signature": {
 87527            "signature": {
 87528              "publicKey": {}
 87529            }
 87530          },
 87531          "modelCard": {
 87532            "modelParameters": {
 87533              "approach": {}
 87534            },
 87535            "quantitativeAnalysis": {
 87536              "graphics": {}
 87537            },
 87538            "considerations": {}
 87539          }
 87540        },
 87541        {
 87542          "type": "library",
 87543          "bom-ref": "pkg:apk/alpine/ca-certificates@20191127-r4?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=4bb545c9ae4f6af6",
 87544          "supplier": {},
 87545          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 87546          "name": "ca-certificates",
 87547          "version": "20191127-r4",
 87548          "description": "Common CA certificates PEM files from Mozilla",
 87549          "licenses": [
 87550            {
 87551              "license": {
 87552                "id": "MPL-2.0"
 87553              }
 87554            },
 87555            {
 87556              "license": {
 87557                "id": "GPL-2.0-or-later"
 87558              }
 87559            }
 87560          ],
 87561          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20191127-r4:*:*:*:*:*:*:*",
 87562          "purl": "pkg:apk/alpine/ca-certificates@20191127-r4?arch=x86_64\u0026distro=alpine-3.12.3",
 87563          "swid": {
 87564            "attachment": {}
 87565          },
 87566          "pedigree": {},
 87567          "externalReferences": [
 87568            {
 87569              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
 87570              "type": "distribution"
 87571            }
 87572          ],
 87573          "evidence": {},
 87574          "signature": {
 87575            "signature": {
 87576              "publicKey": {}
 87577            }
 87578          },
 87579          "modelCard": {
 87580            "modelParameters": {
 87581              "approach": {}
 87582            },
 87583            "quantitativeAnalysis": {
 87584              "graphics": {}
 87585            },
 87586            "considerations": {}
 87587          }
 87588        },
 87589        {
 87590          "type": "library",
 87591          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20191127-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.12.3\u0026package-id=6e690f8d65703244",
 87592          "supplier": {},
 87593          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 87594          "name": "ca-certificates-bundle",
 87595          "version": "20191127-r4",
 87596          "description": "Pre generated bundle of Mozilla certificates",
 87597          "licenses": [
 87598            {
 87599              "license": {
 87600                "id": "MPL-2.0"
 87601              }
 87602            },
 87603            {
 87604              "license": {
 87605                "id": "GPL-2.0-or-later"
 87606              }
 87607            }
 87608          ],
 87609          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20191127-r4:*:*:*:*:*:*:*",
 87610          "purl": "pkg:apk/alpine/ca-certificates-bundle@20191127-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.12.3",
 87611          "swid": {
 87612            "attachment": {}
 87613          },
 87614          "pedigree": {},
 87615          "externalReferences": [
 87616            {
 87617              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
 87618              "type": "distribution"
 87619            }
 87620          ],
 87621          "evidence": {},
 87622          "signature": {
 87623            "signature": {
 87624              "publicKey": {}
 87625            }
 87626          },
 87627          "modelCard": {
 87628            "modelParameters": {
 87629              "approach": {}
 87630            },
 87631            "quantitativeAnalysis": {
 87632              "graphics": {}
 87633            },
 87634            "considerations": {}
 87635          }
 87636        },
 87637        {
 87638          "type": "library",
 87639          "bom-ref": "pkg:golang/cloud.google.com/go@v0.38.0?package-id=e20e033881c587a7",
 87640          "supplier": {},
 87641          "name": "cloud.google.com/go",
 87642          "version": "v0.38.0",
 87643          "purl": "pkg:golang/cloud.google.com/go@v0.38.0",
 87644          "swid": {
 87645            "attachment": {}
 87646          },
 87647          "pedigree": {},
 87648          "evidence": {},
 87649          "signature": {
 87650            "signature": {
 87651              "publicKey": {}
 87652            }
 87653          },
 87654          "modelCard": {
 87655            "modelParameters": {
 87656              "approach": {}
 87657            },
 87658            "quantitativeAnalysis": {
 87659              "graphics": {}
 87660            },
 87661            "considerations": {}
 87662          }
 87663        },
 87664        {
 87665          "type": "library",
 87666          "bom-ref": "pkg:apk/alpine/expat@2.2.9-r1?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=bf0a72cfd53a89d5",
 87667          "supplier": {},
 87668          "publisher": "Carlo Landmeter \u003cclandmeter@gmail.com\u003e",
 87669          "name": "expat",
 87670          "version": "2.2.9-r1",
 87671          "description": "An XML Parser library written in C",
 87672          "licenses": [
 87673            {
 87674              "license": {
 87675                "id": "MIT"
 87676              }
 87677            }
 87678          ],
 87679          "cpe": "cpe:2.3:a:expat:expat:2.2.9-r1:*:*:*:*:*:*:*",
 87680          "purl": "pkg:apk/alpine/expat@2.2.9-r1?arch=x86_64\u0026distro=alpine-3.12.3",
 87681          "swid": {
 87682            "attachment": {}
 87683          },
 87684          "pedigree": {},
 87685          "externalReferences": [
 87686            {
 87687              "url": "http://www.libexpat.org/",
 87688              "type": "distribution"
 87689            }
 87690          ],
 87691          "evidence": {},
 87692          "signature": {
 87693            "signature": {
 87694              "publicKey": {}
 87695            }
 87696          },
 87697          "modelCard": {
 87698            "modelParameters": {
 87699              "approach": {}
 87700            },
 87701            "quantitativeAnalysis": {
 87702              "graphics": {}
 87703            },
 87704            "considerations": {}
 87705          }
 87706        },
 87707        {
 87708          "type": "library",
 87709          "bom-ref": "pkg:apk/alpine/git@2.26.2-r0?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=33bb492f7dd7f2c5",
 87710          "supplier": {},
 87711          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 87712          "name": "git",
 87713          "version": "2.26.2-r0",
 87714          "description": "Distributed version control system",
 87715          "licenses": [
 87716            {
 87717              "license": {
 87718                "id": "GPL-2.0-or-later"
 87719              }
 87720            }
 87721          ],
 87722          "cpe": "cpe:2.3:a:git-scm:git:2.26.2-r0:*:*:*:*:*:*:*",
 87723          "purl": "pkg:apk/alpine/git@2.26.2-r0?arch=x86_64\u0026distro=alpine-3.12.3",
 87724          "swid": {
 87725            "attachment": {}
 87726          },
 87727          "pedigree": {},
 87728          "externalReferences": [
 87729            {
 87730              "url": "https://www.git-scm.com/",
 87731              "type": "distribution"
 87732            }
 87733          ],
 87734          "evidence": {},
 87735          "signature": {
 87736            "signature": {
 87737              "publicKey": {}
 87738            }
 87739          },
 87740          "modelCard": {
 87741            "modelParameters": {
 87742              "approach": {}
 87743            },
 87744            "quantitativeAnalysis": {
 87745              "graphics": {}
 87746            },
 87747            "considerations": {}
 87748          }
 87749        },
 87750        {
 87751          "type": "library",
 87752          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest@v0.9.0?package-id=8b4c0a92645ae94",
 87753          "supplier": {},
 87754          "name": "github.com/Azure/go-autorest/autorest",
 87755          "version": "v0.9.0",
 87756          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest:v0.9.0:*:*:*:*:*:*:*",
 87757          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest@v0.9.0",
 87758          "swid": {
 87759            "attachment": {}
 87760          },
 87761          "pedigree": {},
 87762          "evidence": {},
 87763          "signature": {
 87764            "signature": {
 87765              "publicKey": {}
 87766            }
 87767          },
 87768          "modelCard": {
 87769            "modelParameters": {
 87770              "approach": {}
 87771            },
 87772            "quantitativeAnalysis": {
 87773              "graphics": {}
 87774            },
 87775            "considerations": {}
 87776          }
 87777        },
 87778        {
 87779          "type": "library",
 87780          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest/adal@v0.5.0?package-id=d50ecb2d6ee87a06",
 87781          "supplier": {},
 87782          "name": "github.com/Azure/go-autorest/autorest/adal",
 87783          "version": "v0.5.0",
 87784          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest\\/adal:v0.5.0:*:*:*:*:*:*:*",
 87785          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest/adal@v0.5.0",
 87786          "swid": {
 87787            "attachment": {}
 87788          },
 87789          "pedigree": {},
 87790          "evidence": {},
 87791          "signature": {
 87792            "signature": {
 87793              "publicKey": {}
 87794            }
 87795          },
 87796          "modelCard": {
 87797            "modelParameters": {
 87798              "approach": {}
 87799            },
 87800            "quantitativeAnalysis": {
 87801              "graphics": {}
 87802            },
 87803            "considerations": {}
 87804          }
 87805        },
 87806        {
 87807          "type": "library",
 87808          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest/date@v0.1.0?package-id=51fcd7a77b4fb4fc",
 87809          "supplier": {},
 87810          "name": "github.com/Azure/go-autorest/autorest/date",
 87811          "version": "v0.1.0",
 87812          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest\\/date:v0.1.0:*:*:*:*:*:*:*",
 87813          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest/date@v0.1.0",
 87814          "swid": {
 87815            "attachment": {}
 87816          },
 87817          "pedigree": {},
 87818          "evidence": {},
 87819          "signature": {
 87820            "signature": {
 87821              "publicKey": {}
 87822            }
 87823          },
 87824          "modelCard": {
 87825            "modelParameters": {
 87826              "approach": {}
 87827            },
 87828            "quantitativeAnalysis": {
 87829              "graphics": {}
 87830            },
 87831            "considerations": {}
 87832          }
 87833        },
 87834        {
 87835          "type": "library",
 87836          "bom-ref": "pkg:golang/github.com/azure/go-autorest/logger@v0.1.0?package-id=18dca5cc653b488f",
 87837          "supplier": {},
 87838          "name": "github.com/Azure/go-autorest/logger",
 87839          "version": "v0.1.0",
 87840          "cpe": "cpe:2.3:a:Azure:go-autorest\\/logger:v0.1.0:*:*:*:*:*:*:*",
 87841          "purl": "pkg:golang/github.com/Azure/go-autorest/logger@v0.1.0",
 87842          "swid": {
 87843            "attachment": {}
 87844          },
 87845          "pedigree": {},
 87846          "evidence": {},
 87847          "signature": {
 87848            "signature": {
 87849              "publicKey": {}
 87850            }
 87851          },
 87852          "modelCard": {
 87853            "modelParameters": {
 87854              "approach": {}
 87855            },
 87856            "quantitativeAnalysis": {
 87857              "graphics": {}
 87858            },
 87859            "considerations": {}
 87860          }
 87861        },
 87862        {
 87863          "type": "library",
 87864          "bom-ref": "pkg:golang/github.com/azure/go-autorest/tracing@v0.5.0?package-id=146b9cf7ca1bec51",
 87865          "supplier": {},
 87866          "name": "github.com/Azure/go-autorest/tracing",
 87867          "version": "v0.5.0",
 87868          "cpe": "cpe:2.3:a:Azure:go-autorest\\/tracing:v0.5.0:*:*:*:*:*:*:*",
 87869          "purl": "pkg:golang/github.com/Azure/go-autorest/tracing@v0.5.0",
 87870          "swid": {
 87871            "attachment": {}
 87872          },
 87873          "pedigree": {},
 87874          "evidence": {},
 87875          "signature": {
 87876            "signature": {
 87877              "publicKey": {}
 87878            }
 87879          },
 87880          "modelCard": {
 87881            "modelParameters": {
 87882              "approach": {}
 87883            },
 87884            "quantitativeAnalysis": {
 87885              "graphics": {}
 87886            },
 87887            "considerations": {}
 87888          }
 87889        },
 87890        {
 87891          "type": "library",
 87892          "bom-ref": "pkg:golang/github.com/burntsushi/toml@v0.3.1?package-id=bfc5dd2c6ff230d4",
 87893          "supplier": {},
 87894          "name": "github.com/BurntSushi/toml",
 87895          "version": "v0.3.1",
 87896          "cpe": "cpe:2.3:a:BurntSushi:toml:v0.3.1:*:*:*:*:*:*:*",
 87897          "purl": "pkg:golang/github.com/BurntSushi/toml@v0.3.1",
 87898          "swid": {
 87899            "attachment": {}
 87900          },
 87901          "pedigree": {},
 87902          "evidence": {},
 87903          "signature": {
 87904            "signature": {
 87905              "publicKey": {}
 87906            }
 87907          },
 87908          "modelCard": {
 87909            "modelParameters": {
 87910              "approach": {}
 87911            },
 87912            "quantitativeAnalysis": {
 87913              "graphics": {}
 87914            },
 87915            "considerations": {}
 87916          }
 87917        },
 87918        {
 87919          "type": "library",
 87920          "bom-ref": "pkg:golang/github.com/makenowjust/heredoc@v0.0.0-20170808103936-bb23615498cd?package-id=2510362caece34ad",
 87921          "supplier": {},
 87922          "name": "github.com/MakeNowJust/heredoc",
 87923          "version": "v0.0.0-20170808103936-bb23615498cd",
 87924          "cpe": "cpe:2.3:a:MakeNowJust:heredoc:v0.0.0-20170808103936-bb23615498cd:*:*:*:*:*:*:*",
 87925          "purl": "pkg:golang/github.com/MakeNowJust/heredoc@v0.0.0-20170808103936-bb23615498cd",
 87926          "swid": {
 87927            "attachment": {}
 87928          },
 87929          "pedigree": {},
 87930          "evidence": {},
 87931          "signature": {
 87932            "signature": {
 87933              "publicKey": {}
 87934            }
 87935          },
 87936          "modelCard": {
 87937            "modelParameters": {
 87938              "approach": {}
 87939            },
 87940            "quantitativeAnalysis": {
 87941              "graphics": {}
 87942            },
 87943            "considerations": {}
 87944          }
 87945        },
 87946        {
 87947          "type": "library",
 87948          "bom-ref": "pkg:golang/github.com/masterminds/goutils@v1.1.0?package-id=6ece83c3ae6f761",
 87949          "supplier": {},
 87950          "name": "github.com/Masterminds/goutils",
 87951          "version": "v1.1.0",
 87952          "cpe": "cpe:2.3:a:Masterminds:goutils:v1.1.0:*:*:*:*:*:*:*",
 87953          "purl": "pkg:golang/github.com/Masterminds/goutils@v1.1.0",
 87954          "swid": {
 87955            "attachment": {}
 87956          },
 87957          "pedigree": {},
 87958          "evidence": {},
 87959          "signature": {
 87960            "signature": {
 87961              "publicKey": {}
 87962            }
 87963          },
 87964          "modelCard": {
 87965            "modelParameters": {
 87966              "approach": {}
 87967            },
 87968            "quantitativeAnalysis": {
 87969              "graphics": {}
 87970            },
 87971            "considerations": {}
 87972          }
 87973        },
 87974        {
 87975          "type": "library",
 87976          "bom-ref": "pkg:golang/github.com/masterminds/semver/v3@v3.1.0?package-id=a55f077566d53cb9",
 87977          "supplier": {},
 87978          "name": "github.com/Masterminds/semver/v3",
 87979          "version": "v3.1.0",
 87980          "cpe": "cpe:2.3:a:Masterminds:semver\\/v3:v3.1.0:*:*:*:*:*:*:*",
 87981          "purl": "pkg:golang/github.com/Masterminds/semver/v3@v3.1.0",
 87982          "swid": {
 87983            "attachment": {}
 87984          },
 87985          "pedigree": {},
 87986          "evidence": {},
 87987          "signature": {
 87988            "signature": {
 87989              "publicKey": {}
 87990            }
 87991          },
 87992          "modelCard": {
 87993            "modelParameters": {
 87994              "approach": {}
 87995            },
 87996            "quantitativeAnalysis": {
 87997              "graphics": {}
 87998            },
 87999            "considerations": {}
 88000          }
 88001        },
 88002        {
 88003          "type": "library",
 88004          "bom-ref": "pkg:golang/github.com/masterminds/sprig/v3@v3.1.0?package-id=83a05b6428fe7e40",
 88005          "supplier": {},
 88006          "name": "github.com/Masterminds/sprig/v3",
 88007          "version": "v3.1.0",
 88008          "cpe": "cpe:2.3:a:Masterminds:sprig\\/v3:v3.1.0:*:*:*:*:*:*:*",
 88009          "purl": "pkg:golang/github.com/Masterminds/sprig/v3@v3.1.0",
 88010          "swid": {
 88011            "attachment": {}
 88012          },
 88013          "pedigree": {},
 88014          "evidence": {},
 88015          "signature": {
 88016            "signature": {
 88017              "publicKey": {}
 88018            }
 88019          },
 88020          "modelCard": {
 88021            "modelParameters": {
 88022              "approach": {}
 88023            },
 88024            "quantitativeAnalysis": {
 88025              "graphics": {}
 88026            },
 88027            "considerations": {}
 88028          }
 88029        },
 88030        {
 88031          "type": "library",
 88032          "bom-ref": "pkg:golang/github.com/masterminds/squirrel@v1.4.0?package-id=6867cd48f0d701da",
 88033          "supplier": {},
 88034          "name": "github.com/Masterminds/squirrel",
 88035          "version": "v1.4.0",
 88036          "cpe": "cpe:2.3:a:Masterminds:squirrel:v1.4.0:*:*:*:*:*:*:*",
 88037          "purl": "pkg:golang/github.com/Masterminds/squirrel@v1.4.0",
 88038          "swid": {
 88039            "attachment": {}
 88040          },
 88041          "pedigree": {},
 88042          "evidence": {},
 88043          "signature": {
 88044            "signature": {
 88045              "publicKey": {}
 88046            }
 88047          },
 88048          "modelCard": {
 88049            "modelParameters": {
 88050              "approach": {}
 88051            },
 88052            "quantitativeAnalysis": {
 88053              "graphics": {}
 88054            },
 88055            "considerations": {}
 88056          }
 88057        },
 88058        {
 88059          "type": "library",
 88060          "bom-ref": "pkg:golang/github.com/masterminds/vcs@v1.13.1?package-id=870356f01e890aa5",
 88061          "supplier": {},
 88062          "name": "github.com/Masterminds/vcs",
 88063          "version": "v1.13.1",
 88064          "cpe": "cpe:2.3:a:Masterminds:vcs:v1.13.1:*:*:*:*:*:*:*",
 88065          "purl": "pkg:golang/github.com/Masterminds/vcs@v1.13.1",
 88066          "swid": {
 88067            "attachment": {}
 88068          },
 88069          "pedigree": {},
 88070          "evidence": {},
 88071          "signature": {
 88072            "signature": {
 88073              "publicKey": {}
 88074            }
 88075          },
 88076          "modelCard": {
 88077            "modelParameters": {
 88078              "approach": {}
 88079            },
 88080            "quantitativeAnalysis": {
 88081              "graphics": {}
 88082            },
 88083            "considerations": {}
 88084          }
 88085        },
 88086        {
 88087          "type": "library",
 88088          "bom-ref": "pkg:golang/github.com/puerkitobio/purell@v1.1.1?package-id=f009bfc549ddfa6c",
 88089          "supplier": {},
 88090          "name": "github.com/PuerkitoBio/purell",
 88091          "version": "v1.1.1",
 88092          "cpe": "cpe:2.3:a:PuerkitoBio:purell:v1.1.1:*:*:*:*:*:*:*",
 88093          "purl": "pkg:golang/github.com/PuerkitoBio/purell@v1.1.1",
 88094          "swid": {
 88095            "attachment": {}
 88096          },
 88097          "pedigree": {},
 88098          "evidence": {},
 88099          "signature": {
 88100            "signature": {
 88101              "publicKey": {}
 88102            }
 88103          },
 88104          "modelCard": {
 88105            "modelParameters": {
 88106              "approach": {}
 88107            },
 88108            "quantitativeAnalysis": {
 88109              "graphics": {}
 88110            },
 88111            "considerations": {}
 88112          }
 88113        },
 88114        {
 88115          "type": "library",
 88116          "bom-ref": "pkg:golang/github.com/puerkitobio/urlesc@v0.0.0-20170810143723-de5bf2ad4578?package-id=22da1df624ef85e3",
 88117          "supplier": {},
 88118          "name": "github.com/PuerkitoBio/urlesc",
 88119          "version": "v0.0.0-20170810143723-de5bf2ad4578",
 88120          "cpe": "cpe:2.3:a:PuerkitoBio:urlesc:v0.0.0-20170810143723-de5bf2ad4578:*:*:*:*:*:*:*",
 88121          "purl": "pkg:golang/github.com/PuerkitoBio/urlesc@v0.0.0-20170810143723-de5bf2ad4578",
 88122          "swid": {
 88123            "attachment": {}
 88124          },
 88125          "pedigree": {},
 88126          "evidence": {},
 88127          "signature": {
 88128            "signature": {
 88129              "publicKey": {}
 88130            }
 88131          },
 88132          "modelCard": {
 88133            "modelParameters": {
 88134              "approach": {}
 88135            },
 88136            "quantitativeAnalysis": {
 88137              "graphics": {}
 88138            },
 88139            "considerations": {}
 88140          }
 88141        },
 88142        {
 88143          "type": "library",
 88144          "bom-ref": "pkg:golang/github.com/asaskevich/govalidator@v0.0.0-20200428143746-21a406dcc535?package-id=5ea52d6cfa29edb8",
 88145          "supplier": {},
 88146          "name": "github.com/asaskevich/govalidator",
 88147          "version": "v0.0.0-20200428143746-21a406dcc535",
 88148          "cpe": "cpe:2.3:a:asaskevich:govalidator:v0.0.0-20200428143746-21a406dcc535:*:*:*:*:*:*:*",
 88149          "purl": "pkg:golang/github.com/asaskevich/govalidator@v0.0.0-20200428143746-21a406dcc535",
 88150          "swid": {
 88151            "attachment": {}
 88152          },
 88153          "pedigree": {},
 88154          "evidence": {},
 88155          "signature": {
 88156            "signature": {
 88157              "publicKey": {}
 88158            }
 88159          },
 88160          "modelCard": {
 88161            "modelParameters": {
 88162              "approach": {}
 88163            },
 88164            "quantitativeAnalysis": {
 88165              "graphics": {}
 88166            },
 88167            "considerations": {}
 88168          }
 88169        },
 88170        {
 88171          "type": "library",
 88172          "bom-ref": "pkg:golang/github.com/beorn7/perks@v1.0.1?package-id=24183bb6fe49950",
 88173          "supplier": {},
 88174          "name": "github.com/beorn7/perks",
 88175          "version": "v1.0.1",
 88176          "cpe": "cpe:2.3:a:beorn7:perks:v1.0.1:*:*:*:*:*:*:*",
 88177          "purl": "pkg:golang/github.com/beorn7/perks@v1.0.1",
 88178          "swid": {
 88179            "attachment": {}
 88180          },
 88181          "pedigree": {},
 88182          "evidence": {},
 88183          "signature": {
 88184            "signature": {
 88185              "publicKey": {}
 88186            }
 88187          },
 88188          "modelCard": {
 88189            "modelParameters": {
 88190              "approach": {}
 88191            },
 88192            "quantitativeAnalysis": {
 88193              "graphics": {}
 88194            },
 88195            "considerations": {}
 88196          }
 88197        },
 88198        {
 88199          "type": "library",
 88200          "bom-ref": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1?package-id=7a09deaf9d6568f1",
 88201          "supplier": {},
 88202          "name": "github.com/cespare/xxhash/v2",
 88203          "version": "v2.1.1",
 88204          "cpe": "cpe:2.3:a:cespare:xxhash\\/v2:v2.1.1:*:*:*:*:*:*:*",
 88205          "purl": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1",
 88206          "swid": {
 88207            "attachment": {}
 88208          },
 88209          "pedigree": {},
 88210          "evidence": {},
 88211          "signature": {
 88212            "signature": {
 88213              "publicKey": {}
 88214            }
 88215          },
 88216          "modelCard": {
 88217            "modelParameters": {
 88218              "approach": {}
 88219            },
 88220            "quantitativeAnalysis": {
 88221              "graphics": {}
 88222            },
 88223            "considerations": {}
 88224          }
 88225        },
 88226        {
 88227          "type": "library",
 88228          "bom-ref": "pkg:golang/github.com/containerd/containerd@v1.3.4?package-id=4def39645041d506",
 88229          "supplier": {},
 88230          "name": "github.com/containerd/containerd",
 88231          "version": "v1.3.4",
 88232          "cpe": "cpe:2.3:a:containerd:containerd:v1.3.4:*:*:*:*:*:*:*",
 88233          "purl": "pkg:golang/github.com/containerd/containerd@v1.3.4",
 88234          "swid": {
 88235            "attachment": {}
 88236          },
 88237          "pedigree": {},
 88238          "evidence": {},
 88239          "signature": {
 88240            "signature": {
 88241              "publicKey": {}
 88242            }
 88243          },
 88244          "modelCard": {
 88245            "modelParameters": {
 88246              "approach": {}
 88247            },
 88248            "quantitativeAnalysis": {
 88249              "graphics": {}
 88250            },
 88251            "considerations": {}
 88252          }
 88253        },
 88254        {
 88255          "type": "library",
 88256          "bom-ref": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0?package-id=11dcc47f71d038e4",
 88257          "supplier": {},
 88258          "name": "github.com/cpuguy83/go-md2man/v2",
 88259          "version": "v2.0.0",
 88260          "cpe": "cpe:2.3:a:cpuguy83:go-md2man\\/v2:v2.0.0:*:*:*:*:*:*:*",
 88261          "purl": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0",
 88262          "swid": {
 88263            "attachment": {}
 88264          },
 88265          "pedigree": {},
 88266          "evidence": {},
 88267          "signature": {
 88268            "signature": {
 88269              "publicKey": {}
 88270            }
 88271          },
 88272          "modelCard": {
 88273            "modelParameters": {
 88274              "approach": {}
 88275            },
 88276            "quantitativeAnalysis": {
 88277              "graphics": {}
 88278            },
 88279            "considerations": {}
 88280          }
 88281        },
 88282        {
 88283          "type": "library",
 88284          "bom-ref": "pkg:golang/github.com/cyphar/filepath-securejoin@v0.2.2?package-id=4191bfc18707f31f",
 88285          "supplier": {},
 88286          "name": "github.com/cyphar/filepath-securejoin",
 88287          "version": "v0.2.2",
 88288          "cpe": "cpe:2.3:a:cyphar:filepath-securejoin:v0.2.2:*:*:*:*:*:*:*",
 88289          "purl": "pkg:golang/github.com/cyphar/filepath-securejoin@v0.2.2",
 88290          "swid": {
 88291            "attachment": {}
 88292          },
 88293          "pedigree": {},
 88294          "evidence": {},
 88295          "signature": {
 88296            "signature": {
 88297              "publicKey": {}
 88298            }
 88299          },
 88300          "modelCard": {
 88301            "modelParameters": {
 88302              "approach": {}
 88303            },
 88304            "quantitativeAnalysis": {
 88305              "graphics": {}
 88306            },
 88307            "considerations": {}
 88308          }
 88309        },
 88310        {
 88311          "type": "library",
 88312          "bom-ref": "pkg:golang/github.com/davecgh/go-spew@v1.1.1?package-id=c4c6917d3797faef",
 88313          "supplier": {},
 88314          "name": "github.com/davecgh/go-spew",
 88315          "version": "v1.1.1",
 88316          "cpe": "cpe:2.3:a:davecgh:go-spew:v1.1.1:*:*:*:*:*:*:*",
 88317          "purl": "pkg:golang/github.com/davecgh/go-spew@v1.1.1",
 88318          "swid": {
 88319            "attachment": {}
 88320          },
 88321          "pedigree": {},
 88322          "evidence": {},
 88323          "signature": {
 88324            "signature": {
 88325              "publicKey": {}
 88326            }
 88327          },
 88328          "modelCard": {
 88329            "modelParameters": {
 88330              "approach": {}
 88331            },
 88332            "quantitativeAnalysis": {
 88333              "graphics": {}
 88334            },
 88335            "considerations": {}
 88336          }
 88337        },
 88338        {
 88339          "type": "library",
 88340          "bom-ref": "pkg:golang/github.com/deislabs/oras@v0.8.1?package-id=5a04878e7de4c48b",
 88341          "supplier": {},
 88342          "name": "github.com/deislabs/oras",
 88343          "version": "v0.8.1",
 88344          "cpe": "cpe:2.3:a:deislabs:oras:v0.8.1:*:*:*:*:*:*:*",
 88345          "purl": "pkg:golang/github.com/deislabs/oras@v0.8.1",
 88346          "swid": {
 88347            "attachment": {}
 88348          },
 88349          "pedigree": {},
 88350          "evidence": {},
 88351          "signature": {
 88352            "signature": {
 88353              "publicKey": {}
 88354            }
 88355          },
 88356          "modelCard": {
 88357            "modelParameters": {
 88358              "approach": {}
 88359            },
 88360            "quantitativeAnalysis": {
 88361              "graphics": {}
 88362            },
 88363            "considerations": {}
 88364          }
 88365        },
 88366        {
 88367          "type": "library",
 88368          "bom-ref": "pkg:golang/github.com/dgrijalva/jwt-go@v3.2.0+incompatible?package-id=5edf16c6160c9a8f",
 88369          "supplier": {},
 88370          "name": "github.com/dgrijalva/jwt-go",
 88371          "version": "v3.2.0+incompatible",
 88372          "cpe": "cpe:2.3:a:dgrijalva:jwt-go:v3.2.0\\+incompatible:*:*:*:*:*:*:*",
 88373          "purl": "pkg:golang/github.com/dgrijalva/jwt-go@v3.2.0+incompatible",
 88374          "swid": {
 88375            "attachment": {}
 88376          },
 88377          "pedigree": {},
 88378          "evidence": {},
 88379          "signature": {
 88380            "signature": {
 88381              "publicKey": {}
 88382            }
 88383          },
 88384          "modelCard": {
 88385            "modelParameters": {
 88386              "approach": {}
 88387            },
 88388            "quantitativeAnalysis": {
 88389              "graphics": {}
 88390            },
 88391            "considerations": {}
 88392          }
 88393        },
 88394        {
 88395          "type": "library",
 88396          "bom-ref": "pkg:golang/github.com/docker/cli@v0.0.0-20200130152716-5d0cf8839492?package-id=476ec4b51514b0de",
 88397          "supplier": {},
 88398          "name": "github.com/docker/cli",
 88399          "version": "v0.0.0-20200130152716-5d0cf8839492",
 88400          "cpe": "cpe:2.3:a:docker:cli:v0.0.0-20200130152716-5d0cf8839492:*:*:*:*:*:*:*",
 88401          "purl": "pkg:golang/github.com/docker/cli@v0.0.0-20200130152716-5d0cf8839492",
 88402          "swid": {
 88403            "attachment": {}
 88404          },
 88405          "pedigree": {},
 88406          "evidence": {},
 88407          "signature": {
 88408            "signature": {
 88409              "publicKey": {}
 88410            }
 88411          },
 88412          "modelCard": {
 88413            "modelParameters": {
 88414              "approach": {}
 88415            },
 88416            "quantitativeAnalysis": {
 88417              "graphics": {}
 88418            },
 88419            "considerations": {}
 88420          }
 88421        },
 88422        {
 88423          "type": "library",
 88424          "bom-ref": "pkg:golang/github.com/docker/distribution@v0.0.0-20191216044856-a8371794149d?package-id=aefc6d8d0d675f44",
 88425          "supplier": {},
 88426          "name": "github.com/docker/distribution",
 88427          "version": "v0.0.0-20191216044856-a8371794149d",
 88428          "cpe": "cpe:2.3:a:docker:distribution:v0.0.0-20191216044856-a8371794149d:*:*:*:*:*:*:*",
 88429          "purl": "pkg:golang/github.com/docker/distribution@v0.0.0-20191216044856-a8371794149d",
 88430          "swid": {
 88431            "attachment": {}
 88432          },
 88433          "pedigree": {},
 88434          "evidence": {},
 88435          "signature": {
 88436            "signature": {
 88437              "publicKey": {}
 88438            }
 88439          },
 88440          "modelCard": {
 88441            "modelParameters": {
 88442              "approach": {}
 88443            },
 88444            "quantitativeAnalysis": {
 88445              "graphics": {}
 88446            },
 88447            "considerations": {}
 88448          }
 88449        },
 88450        {
 88451          "type": "library",
 88452          "bom-ref": "pkg:golang/github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce?package-id=6f4fd2008b841991",
 88453          "supplier": {},
 88454          "name": "github.com/docker/docker",
 88455          "version": "v1.4.2-0.20200203170920-46ec8731fbce",
 88456          "cpe": "cpe:2.3:a:docker:docker:v1.4.2-0.20200203170920-46ec8731fbce:*:*:*:*:*:*:*",
 88457          "purl": "pkg:golang/github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce",
 88458          "swid": {
 88459            "attachment": {}
 88460          },
 88461          "pedigree": {},
 88462          "evidence": {},
 88463          "signature": {
 88464            "signature": {
 88465              "publicKey": {}
 88466            }
 88467          },
 88468          "modelCard": {
 88469            "modelParameters": {
 88470              "approach": {}
 88471            },
 88472            "quantitativeAnalysis": {
 88473              "graphics": {}
 88474            },
 88475            "considerations": {}
 88476          }
 88477        },
 88478        {
 88479          "type": "library",
 88480          "bom-ref": "pkg:golang/github.com/docker/docker-credential-helpers@v0.6.3?package-id=adfc4339fbc7737d",
 88481          "supplier": {},
 88482          "name": "github.com/docker/docker-credential-helpers",
 88483          "version": "v0.6.3",
 88484          "cpe": "cpe:2.3:a:docker:docker-credential-helpers:v0.6.3:*:*:*:*:*:*:*",
 88485          "purl": "pkg:golang/github.com/docker/docker-credential-helpers@v0.6.3",
 88486          "swid": {
 88487            "attachment": {}
 88488          },
 88489          "pedigree": {},
 88490          "evidence": {},
 88491          "signature": {
 88492            "signature": {
 88493              "publicKey": {}
 88494            }
 88495          },
 88496          "modelCard": {
 88497            "modelParameters": {
 88498              "approach": {}
 88499            },
 88500            "quantitativeAnalysis": {
 88501              "graphics": {}
 88502            },
 88503            "considerations": {}
 88504          }
 88505        },
 88506        {
 88507          "type": "library",
 88508          "bom-ref": "pkg:golang/github.com/docker/go-connections@v0.4.0?package-id=401377c8001f1b9d",
 88509          "supplier": {},
 88510          "name": "github.com/docker/go-connections",
 88511          "version": "v0.4.0",
 88512          "cpe": "cpe:2.3:a:docker:go-connections:v0.4.0:*:*:*:*:*:*:*",
 88513          "purl": "pkg:golang/github.com/docker/go-connections@v0.4.0",
 88514          "swid": {
 88515            "attachment": {}
 88516          },
 88517          "pedigree": {},
 88518          "evidence": {},
 88519          "signature": {
 88520            "signature": {
 88521              "publicKey": {}
 88522            }
 88523          },
 88524          "modelCard": {
 88525            "modelParameters": {
 88526              "approach": {}
 88527            },
 88528            "quantitativeAnalysis": {
 88529              "graphics": {}
 88530            },
 88531            "considerations": {}
 88532          }
 88533        },
 88534        {
 88535          "type": "library",
 88536          "bom-ref": "pkg:golang/github.com/docker/go-metrics@v0.0.0-20180209012529-399ea8c73916?package-id=a8f9f0c8861f087",
 88537          "supplier": {},
 88538          "name": "github.com/docker/go-metrics",
 88539          "version": "v0.0.0-20180209012529-399ea8c73916",
 88540          "cpe": "cpe:2.3:a:docker:go-metrics:v0.0.0-20180209012529-399ea8c73916:*:*:*:*:*:*:*",
 88541          "purl": "pkg:golang/github.com/docker/go-metrics@v0.0.0-20180209012529-399ea8c73916",
 88542          "swid": {
 88543            "attachment": {}
 88544          },
 88545          "pedigree": {},
 88546          "evidence": {},
 88547          "signature": {
 88548            "signature": {
 88549              "publicKey": {}
 88550            }
 88551          },
 88552          "modelCard": {
 88553            "modelParameters": {
 88554              "approach": {}
 88555            },
 88556            "quantitativeAnalysis": {
 88557              "graphics": {}
 88558            },
 88559            "considerations": {}
 88560          }
 88561        },
 88562        {
 88563          "type": "library",
 88564          "bom-ref": "pkg:golang/github.com/docker/go-units@v0.4.0?package-id=a544384c6c9cf30a",
 88565          "supplier": {},
 88566          "name": "github.com/docker/go-units",
 88567          "version": "v0.4.0",
 88568          "cpe": "cpe:2.3:a:docker:go-units:v0.4.0:*:*:*:*:*:*:*",
 88569          "purl": "pkg:golang/github.com/docker/go-units@v0.4.0",
 88570          "swid": {
 88571            "attachment": {}
 88572          },
 88573          "pedigree": {},
 88574          "evidence": {},
 88575          "signature": {
 88576            "signature": {
 88577              "publicKey": {}
 88578            }
 88579          },
 88580          "modelCard": {
 88581            "modelParameters": {
 88582              "approach": {}
 88583            },
 88584            "quantitativeAnalysis": {
 88585              "graphics": {}
 88586            },
 88587            "considerations": {}
 88588          }
 88589        },
 88590        {
 88591          "type": "library",
 88592          "bom-ref": "pkg:golang/github.com/docker/spdystream@v0.0.0-20160310174837-449fdfce4d96?package-id=e2a4b0b454263f38",
 88593          "supplier": {},
 88594          "name": "github.com/docker/spdystream",
 88595          "version": "v0.0.0-20160310174837-449fdfce4d96",
 88596          "cpe": "cpe:2.3:a:docker:spdystream:v0.0.0-20160310174837-449fdfce4d96:*:*:*:*:*:*:*",
 88597          "purl": "pkg:golang/github.com/docker/spdystream@v0.0.0-20160310174837-449fdfce4d96",
 88598          "swid": {
 88599            "attachment": {}
 88600          },
 88601          "pedigree": {},
 88602          "evidence": {},
 88603          "signature": {
 88604            "signature": {
 88605              "publicKey": {}
 88606            }
 88607          },
 88608          "modelCard": {
 88609            "modelParameters": {
 88610              "approach": {}
 88611            },
 88612            "quantitativeAnalysis": {
 88613              "graphics": {}
 88614            },
 88615            "considerations": {}
 88616          }
 88617        },
 88618        {
 88619          "type": "library",
 88620          "bom-ref": "pkg:golang/github.com/emicklei/go-restful@v2.9.5+incompatible?package-id=99766c751f0d17f5",
 88621          "supplier": {},
 88622          "name": "github.com/emicklei/go-restful",
 88623          "version": "v2.9.5+incompatible",
 88624          "cpe": "cpe:2.3:a:emicklei:go-restful:v2.9.5\\+incompatible:*:*:*:*:*:*:*",
 88625          "purl": "pkg:golang/github.com/emicklei/go-restful@v2.9.5+incompatible",
 88626          "swid": {
 88627            "attachment": {}
 88628          },
 88629          "pedigree": {},
 88630          "evidence": {},
 88631          "signature": {
 88632            "signature": {
 88633              "publicKey": {}
 88634            }
 88635          },
 88636          "modelCard": {
 88637            "modelParameters": {
 88638              "approach": {}
 88639            },
 88640            "quantitativeAnalysis": {
 88641              "graphics": {}
 88642            },
 88643            "considerations": {}
 88644          }
 88645        },
 88646        {
 88647          "type": "library",
 88648          "bom-ref": "pkg:golang/github.com/evanphx/json-patch@v0.0.0-20200808040245-162e5629780b?package-id=11410e4b9242bbe9",
 88649          "supplier": {},
 88650          "name": "github.com/evanphx/json-patch",
 88651          "version": "v0.0.0-20200808040245-162e5629780b",
 88652          "cpe": "cpe:2.3:a:evanphx:json-patch:v0.0.0-20200808040245-162e5629780b:*:*:*:*:*:*:*",
 88653          "purl": "pkg:golang/github.com/evanphx/json-patch@v0.0.0-20200808040245-162e5629780b",
 88654          "swid": {
 88655            "attachment": {}
 88656          },
 88657          "pedigree": {},
 88658          "evidence": {},
 88659          "signature": {
 88660            "signature": {
 88661              "publicKey": {}
 88662            }
 88663          },
 88664          "modelCard": {
 88665            "modelParameters": {
 88666              "approach": {}
 88667            },
 88668            "quantitativeAnalysis": {
 88669              "graphics": {}
 88670            },
 88671            "considerations": {}
 88672          }
 88673        },
 88674        {
 88675          "type": "library",
 88676          "bom-ref": "pkg:golang/github.com/exponent-io/jsonpath@v0.0.0-20151013193312-d6023ce2651d?package-id=855ca912711649f9",
 88677          "supplier": {},
 88678          "name": "github.com/exponent-io/jsonpath",
 88679          "version": "v0.0.0-20151013193312-d6023ce2651d",
 88680          "cpe": "cpe:2.3:a:exponent-io:jsonpath:v0.0.0-20151013193312-d6023ce2651d:*:*:*:*:*:*:*",
 88681          "purl": "pkg:golang/github.com/exponent-io/jsonpath@v0.0.0-20151013193312-d6023ce2651d",
 88682          "swid": {
 88683            "attachment": {}
 88684          },
 88685          "pedigree": {},
 88686          "evidence": {},
 88687          "signature": {
 88688            "signature": {
 88689              "publicKey": {}
 88690            }
 88691          },
 88692          "modelCard": {
 88693            "modelParameters": {
 88694              "approach": {}
 88695            },
 88696            "quantitativeAnalysis": {
 88697              "graphics": {}
 88698            },
 88699            "considerations": {}
 88700          }
 88701        },
 88702        {
 88703          "type": "library",
 88704          "bom-ref": "pkg:golang/github.com/fatih/color@v1.7.0?package-id=46ba6fbdd76d34a2",
 88705          "supplier": {},
 88706          "name": "github.com/fatih/color",
 88707          "version": "v1.7.0",
 88708          "cpe": "cpe:2.3:a:fatih:color:v1.7.0:*:*:*:*:*:*:*",
 88709          "purl": "pkg:golang/github.com/fatih/color@v1.7.0",
 88710          "swid": {
 88711            "attachment": {}
 88712          },
 88713          "pedigree": {},
 88714          "evidence": {},
 88715          "signature": {
 88716            "signature": {
 88717              "publicKey": {}
 88718            }
 88719          },
 88720          "modelCard": {
 88721            "modelParameters": {
 88722              "approach": {}
 88723            },
 88724            "quantitativeAnalysis": {
 88725              "graphics": {}
 88726            },
 88727            "considerations": {}
 88728          }
 88729        },
 88730        {
 88731          "type": "library",
 88732          "bom-ref": "pkg:golang/github.com/ghodss/yaml@v1.0.0?package-id=37e43c3bde928ffe",
 88733          "supplier": {},
 88734          "name": "github.com/ghodss/yaml",
 88735          "version": "v1.0.0",
 88736          "cpe": "cpe:2.3:a:ghodss:yaml:v1.0.0:*:*:*:*:*:*:*",
 88737          "purl": "pkg:golang/github.com/ghodss/yaml@v1.0.0",
 88738          "swid": {
 88739            "attachment": {}
 88740          },
 88741          "pedigree": {},
 88742          "evidence": {},
 88743          "signature": {
 88744            "signature": {
 88745              "publicKey": {}
 88746            }
 88747          },
 88748          "modelCard": {
 88749            "modelParameters": {
 88750              "approach": {}
 88751            },
 88752            "quantitativeAnalysis": {
 88753              "graphics": {}
 88754            },
 88755            "considerations": {}
 88756          }
 88757        },
 88758        {
 88759          "type": "library",
 88760          "bom-ref": "pkg:golang/github.com/go-openapi/jsonpointer@v0.19.3?package-id=c374975e46504249",
 88761          "supplier": {},
 88762          "name": "github.com/go-openapi/jsonpointer",
 88763          "version": "v0.19.3",
 88764          "cpe": "cpe:2.3:a:go-openapi:jsonpointer:v0.19.3:*:*:*:*:*:*:*",
 88765          "purl": "pkg:golang/github.com/go-openapi/jsonpointer@v0.19.3",
 88766          "swid": {
 88767            "attachment": {}
 88768          },
 88769          "pedigree": {},
 88770          "evidence": {},
 88771          "signature": {
 88772            "signature": {
 88773              "publicKey": {}
 88774            }
 88775          },
 88776          "modelCard": {
 88777            "modelParameters": {
 88778              "approach": {}
 88779            },
 88780            "quantitativeAnalysis": {
 88781              "graphics": {}
 88782            },
 88783            "considerations": {}
 88784          }
 88785        },
 88786        {
 88787          "type": "library",
 88788          "bom-ref": "pkg:golang/github.com/go-openapi/jsonreference@v0.19.3?package-id=37a7bef783d238fc",
 88789          "supplier": {},
 88790          "name": "github.com/go-openapi/jsonreference",
 88791          "version": "v0.19.3",
 88792          "cpe": "cpe:2.3:a:go-openapi:jsonreference:v0.19.3:*:*:*:*:*:*:*",
 88793          "purl": "pkg:golang/github.com/go-openapi/jsonreference@v0.19.3",
 88794          "swid": {
 88795            "attachment": {}
 88796          },
 88797          "pedigree": {},
 88798          "evidence": {},
 88799          "signature": {
 88800            "signature": {
 88801              "publicKey": {}
 88802            }
 88803          },
 88804          "modelCard": {
 88805            "modelParameters": {
 88806              "approach": {}
 88807            },
 88808            "quantitativeAnalysis": {
 88809              "graphics": {}
 88810            },
 88811            "considerations": {}
 88812          }
 88813        },
 88814        {
 88815          "type": "library",
 88816          "bom-ref": "pkg:golang/github.com/go-openapi/spec@v0.19.3?package-id=fd40c51903e65e35",
 88817          "supplier": {},
 88818          "name": "github.com/go-openapi/spec",
 88819          "version": "v0.19.3",
 88820          "cpe": "cpe:2.3:a:go-openapi:spec:v0.19.3:*:*:*:*:*:*:*",
 88821          "purl": "pkg:golang/github.com/go-openapi/spec@v0.19.3",
 88822          "swid": {
 88823            "attachment": {}
 88824          },
 88825          "pedigree": {},
 88826          "evidence": {},
 88827          "signature": {
 88828            "signature": {
 88829              "publicKey": {}
 88830            }
 88831          },
 88832          "modelCard": {
 88833            "modelParameters": {
 88834              "approach": {}
 88835            },
 88836            "quantitativeAnalysis": {
 88837              "graphics": {}
 88838            },
 88839            "considerations": {}
 88840          }
 88841        },
 88842        {
 88843          "type": "library",
 88844          "bom-ref": "pkg:golang/github.com/go-openapi/swag@v0.19.5?package-id=64dc8e89beecf1b7",
 88845          "supplier": {},
 88846          "name": "github.com/go-openapi/swag",
 88847          "version": "v0.19.5",
 88848          "cpe": "cpe:2.3:a:go-openapi:swag:v0.19.5:*:*:*:*:*:*:*",
 88849          "purl": "pkg:golang/github.com/go-openapi/swag@v0.19.5",
 88850          "swid": {
 88851            "attachment": {}
 88852          },
 88853          "pedigree": {},
 88854          "evidence": {},
 88855          "signature": {
 88856            "signature": {
 88857              "publicKey": {}
 88858            }
 88859          },
 88860          "modelCard": {
 88861            "modelParameters": {
 88862              "approach": {}
 88863            },
 88864            "quantitativeAnalysis": {
 88865              "graphics": {}
 88866            },
 88867            "considerations": {}
 88868          }
 88869        },
 88870        {
 88871          "type": "library",
 88872          "bom-ref": "pkg:golang/github.com/gobwas/glob@v0.2.3?package-id=15bb363964d5523b",
 88873          "supplier": {},
 88874          "name": "github.com/gobwas/glob",
 88875          "version": "v0.2.3",
 88876          "cpe": "cpe:2.3:a:gobwas:glob:v0.2.3:*:*:*:*:*:*:*",
 88877          "purl": "pkg:golang/github.com/gobwas/glob@v0.2.3",
 88878          "swid": {
 88879            "attachment": {}
 88880          },
 88881          "pedigree": {},
 88882          "evidence": {},
 88883          "signature": {
 88884            "signature": {
 88885              "publicKey": {}
 88886            }
 88887          },
 88888          "modelCard": {
 88889            "modelParameters": {
 88890              "approach": {}
 88891            },
 88892            "quantitativeAnalysis": {
 88893              "graphics": {}
 88894            },
 88895            "considerations": {}
 88896          }
 88897        },
 88898        {
 88899          "type": "library",
 88900          "bom-ref": "pkg:golang/github.com/gofrs/flock@v0.7.1?package-id=6e91c07413be5ce4",
 88901          "supplier": {},
 88902          "name": "github.com/gofrs/flock",
 88903          "version": "v0.7.1",
 88904          "cpe": "cpe:2.3:a:gofrs:flock:v0.7.1:*:*:*:*:*:*:*",
 88905          "purl": "pkg:golang/github.com/gofrs/flock@v0.7.1",
 88906          "swid": {
 88907            "attachment": {}
 88908          },
 88909          "pedigree": {},
 88910          "evidence": {},
 88911          "signature": {
 88912            "signature": {
 88913              "publicKey": {}
 88914            }
 88915          },
 88916          "modelCard": {
 88917            "modelParameters": {
 88918              "approach": {}
 88919            },
 88920            "quantitativeAnalysis": {
 88921              "graphics": {}
 88922            },
 88923            "considerations": {}
 88924          }
 88925        },
 88926        {
 88927          "type": "library",
 88928          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.1?package-id=f2ddbb14d4f5b4f0",
 88929          "supplier": {},
 88930          "name": "github.com/gogo/protobuf",
 88931          "version": "v1.3.1",
 88932          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.1:*:*:*:*:*:*:*",
 88933          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.1",
 88934          "swid": {
 88935            "attachment": {}
 88936          },
 88937          "pedigree": {},
 88938          "evidence": {},
 88939          "signature": {
 88940            "signature": {
 88941              "publicKey": {}
 88942            }
 88943          },
 88944          "modelCard": {
 88945            "modelParameters": {
 88946              "approach": {}
 88947            },
 88948            "quantitativeAnalysis": {
 88949              "graphics": {}
 88950            },
 88951            "considerations": {}
 88952          }
 88953        },
 88954        {
 88955          "type": "library",
 88956          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.3.2?package-id=693ebcbd80943130",
 88957          "supplier": {},
 88958          "name": "github.com/golang/protobuf",
 88959          "version": "v1.3.2",
 88960          "cpe": "cpe:2.3:a:golang:protobuf:v1.3.2:*:*:*:*:*:*:*",
 88961          "purl": "pkg:golang/github.com/golang/protobuf@v1.3.2",
 88962          "swid": {
 88963            "attachment": {}
 88964          },
 88965          "pedigree": {},
 88966          "evidence": {},
 88967          "signature": {
 88968            "signature": {
 88969              "publicKey": {}
 88970            }
 88971          },
 88972          "modelCard": {
 88973            "modelParameters": {
 88974              "approach": {}
 88975            },
 88976            "quantitativeAnalysis": {
 88977              "graphics": {}
 88978            },
 88979            "considerations": {}
 88980          }
 88981        },
 88982        {
 88983          "type": "library",
 88984          "bom-ref": "pkg:golang/github.com/google/btree@v1.0.0?package-id=24537bef0c70e5f2",
 88985          "supplier": {},
 88986          "name": "github.com/google/btree",
 88987          "version": "v1.0.0",
 88988          "cpe": "cpe:2.3:a:google:btree:v1.0.0:*:*:*:*:*:*:*",
 88989          "purl": "pkg:golang/github.com/google/btree@v1.0.0",
 88990          "swid": {
 88991            "attachment": {}
 88992          },
 88993          "pedigree": {},
 88994          "evidence": {},
 88995          "signature": {
 88996            "signature": {
 88997              "publicKey": {}
 88998            }
 88999          },
 89000          "modelCard": {
 89001            "modelParameters": {
 89002              "approach": {}
 89003            },
 89004            "quantitativeAnalysis": {
 89005              "graphics": {}
 89006            },
 89007            "considerations": {}
 89008          }
 89009        },
 89010        {
 89011          "type": "library",
 89012          "bom-ref": "pkg:golang/github.com/google/go-cmp@v0.4.0?package-id=6edc5edf6ea64449",
 89013          "supplier": {},
 89014          "name": "github.com/google/go-cmp",
 89015          "version": "v0.4.0",
 89016          "cpe": "cpe:2.3:a:google:go-cmp:v0.4.0:*:*:*:*:*:*:*",
 89017          "purl": "pkg:golang/github.com/google/go-cmp@v0.4.0",
 89018          "swid": {
 89019            "attachment": {}
 89020          },
 89021          "pedigree": {},
 89022          "evidence": {},
 89023          "signature": {
 89024            "signature": {
 89025              "publicKey": {}
 89026            }
 89027          },
 89028          "modelCard": {
 89029            "modelParameters": {
 89030              "approach": {}
 89031            },
 89032            "quantitativeAnalysis": {
 89033              "graphics": {}
 89034            },
 89035            "considerations": {}
 89036          }
 89037        },
 89038        {
 89039          "type": "library",
 89040          "bom-ref": "pkg:golang/github.com/google/gofuzz@v1.1.0?package-id=e8cb1e4783d145f4",
 89041          "supplier": {},
 89042          "name": "github.com/google/gofuzz",
 89043          "version": "v1.1.0",
 89044          "cpe": "cpe:2.3:a:google:gofuzz:v1.1.0:*:*:*:*:*:*:*",
 89045          "purl": "pkg:golang/github.com/google/gofuzz@v1.1.0",
 89046          "swid": {
 89047            "attachment": {}
 89048          },
 89049          "pedigree": {},
 89050          "evidence": {},
 89051          "signature": {
 89052            "signature": {
 89053              "publicKey": {}
 89054            }
 89055          },
 89056          "modelCard": {
 89057            "modelParameters": {
 89058              "approach": {}
 89059            },
 89060            "quantitativeAnalysis": {
 89061              "graphics": {}
 89062            },
 89063            "considerations": {}
 89064          }
 89065        },
 89066        {
 89067          "type": "library",
 89068          "bom-ref": "pkg:golang/github.com/google/uuid@v1.1.1?package-id=d749125f8f9c7f66",
 89069          "supplier": {},
 89070          "name": "github.com/google/uuid",
 89071          "version": "v1.1.1",
 89072          "cpe": "cpe:2.3:a:google:uuid:v1.1.1:*:*:*:*:*:*:*",
 89073          "purl": "pkg:golang/github.com/google/uuid@v1.1.1",
 89074          "swid": {
 89075            "attachment": {}
 89076          },
 89077          "pedigree": {},
 89078          "evidence": {},
 89079          "signature": {
 89080            "signature": {
 89081              "publicKey": {}
 89082            }
 89083          },
 89084          "modelCard": {
 89085            "modelParameters": {
 89086              "approach": {}
 89087            },
 89088            "quantitativeAnalysis": {
 89089              "graphics": {}
 89090            },
 89091            "considerations": {}
 89092          }
 89093        },
 89094        {
 89095          "type": "library",
 89096          "bom-ref": "pkg:golang/github.com/googleapis/gnostic@v0.1.0?package-id=2f032810c1efc912",
 89097          "supplier": {},
 89098          "name": "github.com/googleapis/gnostic",
 89099          "version": "v0.1.0",
 89100          "cpe": "cpe:2.3:a:googleapis:gnostic:v0.1.0:*:*:*:*:*:*:*",
 89101          "purl": "pkg:golang/github.com/googleapis/gnostic@v0.1.0",
 89102          "swid": {
 89103            "attachment": {}
 89104          },
 89105          "pedigree": {},
 89106          "evidence": {},
 89107          "signature": {
 89108            "signature": {
 89109              "publicKey": {}
 89110            }
 89111          },
 89112          "modelCard": {
 89113            "modelParameters": {
 89114              "approach": {}
 89115            },
 89116            "quantitativeAnalysis": {
 89117              "graphics": {}
 89118            },
 89119            "considerations": {}
 89120          }
 89121        },
 89122        {
 89123          "type": "library",
 89124          "bom-ref": "pkg:golang/github.com/gophercloud/gophercloud@v0.1.0?package-id=545e01323ba9d0a6",
 89125          "supplier": {},
 89126          "name": "github.com/gophercloud/gophercloud",
 89127          "version": "v0.1.0",
 89128          "cpe": "cpe:2.3:a:gophercloud:gophercloud:v0.1.0:*:*:*:*:*:*:*",
 89129          "purl": "pkg:golang/github.com/gophercloud/gophercloud@v0.1.0",
 89130          "swid": {
 89131            "attachment": {}
 89132          },
 89133          "pedigree": {},
 89134          "evidence": {},
 89135          "signature": {
 89136            "signature": {
 89137              "publicKey": {}
 89138            }
 89139          },
 89140          "modelCard": {
 89141            "modelParameters": {
 89142              "approach": {}
 89143            },
 89144            "quantitativeAnalysis": {
 89145              "graphics": {}
 89146            },
 89147            "considerations": {}
 89148          }
 89149        },
 89150        {
 89151          "type": "library",
 89152          "bom-ref": "pkg:golang/github.com/gorilla/mux@v1.7.3?package-id=3ed8f77a1ef65bb2",
 89153          "supplier": {},
 89154          "name": "github.com/gorilla/mux",
 89155          "version": "v1.7.3",
 89156          "cpe": "cpe:2.3:a:gorilla:mux:v1.7.3:*:*:*:*:*:*:*",
 89157          "purl": "pkg:golang/github.com/gorilla/mux@v1.7.3",
 89158          "swid": {
 89159            "attachment": {}
 89160          },
 89161          "pedigree": {},
 89162          "evidence": {},
 89163          "signature": {
 89164            "signature": {
 89165              "publicKey": {}
 89166            }
 89167          },
 89168          "modelCard": {
 89169            "modelParameters": {
 89170              "approach": {}
 89171            },
 89172            "quantitativeAnalysis": {
 89173              "graphics": {}
 89174            },
 89175            "considerations": {}
 89176          }
 89177        },
 89178        {
 89179          "type": "library",
 89180          "bom-ref": "pkg:golang/github.com/gosuri/uitable@v0.0.4?package-id=4e15baaa10211d28",
 89181          "supplier": {},
 89182          "name": "github.com/gosuri/uitable",
 89183          "version": "v0.0.4",
 89184          "cpe": "cpe:2.3:a:gosuri:uitable:v0.0.4:*:*:*:*:*:*:*",
 89185          "purl": "pkg:golang/github.com/gosuri/uitable@v0.0.4",
 89186          "swid": {
 89187            "attachment": {}
 89188          },
 89189          "pedigree": {},
 89190          "evidence": {},
 89191          "signature": {
 89192            "signature": {
 89193              "publicKey": {}
 89194            }
 89195          },
 89196          "modelCard": {
 89197            "modelParameters": {
 89198              "approach": {}
 89199            },
 89200            "quantitativeAnalysis": {
 89201              "graphics": {}
 89202            },
 89203            "considerations": {}
 89204          }
 89205        },
 89206        {
 89207          "type": "library",
 89208          "bom-ref": "pkg:golang/github.com/gregjones/httpcache@v0.0.0-20180305231024-9cad4c3443a7?package-id=b34b5e371f2a7e13",
 89209          "supplier": {},
 89210          "name": "github.com/gregjones/httpcache",
 89211          "version": "v0.0.0-20180305231024-9cad4c3443a7",
 89212          "cpe": "cpe:2.3:a:gregjones:httpcache:v0.0.0-20180305231024-9cad4c3443a7:*:*:*:*:*:*:*",
 89213          "purl": "pkg:golang/github.com/gregjones/httpcache@v0.0.0-20180305231024-9cad4c3443a7",
 89214          "swid": {
 89215            "attachment": {}
 89216          },
 89217          "pedigree": {},
 89218          "evidence": {},
 89219          "signature": {
 89220            "signature": {
 89221              "publicKey": {}
 89222            }
 89223          },
 89224          "modelCard": {
 89225            "modelParameters": {
 89226              "approach": {}
 89227            },
 89228            "quantitativeAnalysis": {
 89229              "graphics": {}
 89230            },
 89231            "considerations": {}
 89232          }
 89233        },
 89234        {
 89235          "type": "library",
 89236          "bom-ref": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.1?package-id=955d2379ea653ab2",
 89237          "supplier": {},
 89238          "name": "github.com/hashicorp/golang-lru",
 89239          "version": "v0.5.1",
 89240          "cpe": "cpe:2.3:a:hashicorp:golang-lru:v0.5.1:*:*:*:*:*:*:*",
 89241          "purl": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.1",
 89242          "swid": {
 89243            "attachment": {}
 89244          },
 89245          "pedigree": {},
 89246          "evidence": {},
 89247          "signature": {
 89248            "signature": {
 89249              "publicKey": {}
 89250            }
 89251          },
 89252          "modelCard": {
 89253            "modelParameters": {
 89254              "approach": {}
 89255            },
 89256            "quantitativeAnalysis": {
 89257              "graphics": {}
 89258            },
 89259            "considerations": {}
 89260          }
 89261        },
 89262        {
 89263          "type": "library",
 89264          "bom-ref": "pkg:golang/github.com/huandu/xstrings@v1.3.1?package-id=e0d67433ced7504c",
 89265          "supplier": {},
 89266          "name": "github.com/huandu/xstrings",
 89267          "version": "v1.3.1",
 89268          "cpe": "cpe:2.3:a:huandu:xstrings:v1.3.1:*:*:*:*:*:*:*",
 89269          "purl": "pkg:golang/github.com/huandu/xstrings@v1.3.1",
 89270          "swid": {
 89271            "attachment": {}
 89272          },
 89273          "pedigree": {},
 89274          "evidence": {},
 89275          "signature": {
 89276            "signature": {
 89277              "publicKey": {}
 89278            }
 89279          },
 89280          "modelCard": {
 89281            "modelParameters": {
 89282              "approach": {}
 89283            },
 89284            "quantitativeAnalysis": {
 89285              "graphics": {}
 89286            },
 89287            "considerations": {}
 89288          }
 89289        },
 89290        {
 89291          "type": "library",
 89292          "bom-ref": "pkg:golang/github.com/imdario/mergo@v0.3.8?package-id=4c6a073ec69b1f51",
 89293          "supplier": {},
 89294          "name": "github.com/imdario/mergo",
 89295          "version": "v0.3.8",
 89296          "cpe": "cpe:2.3:a:imdario:mergo:v0.3.8:*:*:*:*:*:*:*",
 89297          "purl": "pkg:golang/github.com/imdario/mergo@v0.3.8",
 89298          "swid": {
 89299            "attachment": {}
 89300          },
 89301          "pedigree": {},
 89302          "evidence": {},
 89303          "signature": {
 89304            "signature": {
 89305              "publicKey": {}
 89306            }
 89307          },
 89308          "modelCard": {
 89309            "modelParameters": {
 89310              "approach": {}
 89311            },
 89312            "quantitativeAnalysis": {
 89313              "graphics": {}
 89314            },
 89315            "considerations": {}
 89316          }
 89317        },
 89318        {
 89319          "type": "library",
 89320          "bom-ref": "pkg:golang/github.com/jmoiron/sqlx@v1.2.0?package-id=950cef018bb65ca1",
 89321          "supplier": {},
 89322          "name": "github.com/jmoiron/sqlx",
 89323          "version": "v1.2.0",
 89324          "cpe": "cpe:2.3:a:jmoiron:sqlx:v1.2.0:*:*:*:*:*:*:*",
 89325          "purl": "pkg:golang/github.com/jmoiron/sqlx@v1.2.0",
 89326          "swid": {
 89327            "attachment": {}
 89328          },
 89329          "pedigree": {},
 89330          "evidence": {},
 89331          "signature": {
 89332            "signature": {
 89333              "publicKey": {}
 89334            }
 89335          },
 89336          "modelCard": {
 89337            "modelParameters": {
 89338              "approach": {}
 89339            },
 89340            "quantitativeAnalysis": {
 89341              "graphics": {}
 89342            },
 89343            "considerations": {}
 89344          }
 89345        },
 89346        {
 89347          "type": "library",
 89348          "bom-ref": "pkg:golang/github.com/json-iterator/go@v1.1.8?package-id=90b3fb402ed6cac5",
 89349          "supplier": {},
 89350          "name": "github.com/json-iterator/go",
 89351          "version": "v1.1.8",
 89352          "cpe": "cpe:2.3:a:json-iterator:go:v1.1.8:*:*:*:*:*:*:*",
 89353          "purl": "pkg:golang/github.com/json-iterator/go@v1.1.8",
 89354          "swid": {
 89355            "attachment": {}
 89356          },
 89357          "pedigree": {},
 89358          "evidence": {},
 89359          "signature": {
 89360            "signature": {
 89361              "publicKey": {}
 89362            }
 89363          },
 89364          "modelCard": {
 89365            "modelParameters": {
 89366              "approach": {}
 89367            },
 89368            "quantitativeAnalysis": {
 89369              "graphics": {}
 89370            },
 89371            "considerations": {}
 89372          }
 89373        },
 89374        {
 89375          "type": "library",
 89376          "bom-ref": "pkg:golang/github.com/lann/builder@v0.0.0-20180802200727-47ae307949d0?package-id=3ba0378987ce6b3c",
 89377          "supplier": {},
 89378          "name": "github.com/lann/builder",
 89379          "version": "v0.0.0-20180802200727-47ae307949d0",
 89380          "cpe": "cpe:2.3:a:lann:builder:v0.0.0-20180802200727-47ae307949d0:*:*:*:*:*:*:*",
 89381          "purl": "pkg:golang/github.com/lann/builder@v0.0.0-20180802200727-47ae307949d0",
 89382          "swid": {
 89383            "attachment": {}
 89384          },
 89385          "pedigree": {},
 89386          "evidence": {},
 89387          "signature": {
 89388            "signature": {
 89389              "publicKey": {}
 89390            }
 89391          },
 89392          "modelCard": {
 89393            "modelParameters": {
 89394              "approach": {}
 89395            },
 89396            "quantitativeAnalysis": {
 89397              "graphics": {}
 89398            },
 89399            "considerations": {}
 89400          }
 89401        },
 89402        {
 89403          "type": "library",
 89404          "bom-ref": "pkg:golang/github.com/lann/ps@v0.0.0-20150810152359-62de8c46ede0?package-id=94ee67d53405b20e",
 89405          "supplier": {},
 89406          "name": "github.com/lann/ps",
 89407          "version": "v0.0.0-20150810152359-62de8c46ede0",
 89408          "cpe": "cpe:2.3:a:lann:ps:v0.0.0-20150810152359-62de8c46ede0:*:*:*:*:*:*:*",
 89409          "purl": "pkg:golang/github.com/lann/ps@v0.0.0-20150810152359-62de8c46ede0",
 89410          "swid": {
 89411            "attachment": {}
 89412          },
 89413          "pedigree": {},
 89414          "evidence": {},
 89415          "signature": {
 89416            "signature": {
 89417              "publicKey": {}
 89418            }
 89419          },
 89420          "modelCard": {
 89421            "modelParameters": {
 89422              "approach": {}
 89423            },
 89424            "quantitativeAnalysis": {
 89425              "graphics": {}
 89426            },
 89427            "considerations": {}
 89428          }
 89429        },
 89430        {
 89431          "type": "library",
 89432          "bom-ref": "pkg:golang/github.com/lib/pq@v1.7.0?package-id=29048bcaa06fd5cb",
 89433          "supplier": {},
 89434          "name": "github.com/lib/pq",
 89435          "version": "v1.7.0",
 89436          "cpe": "cpe:2.3:a:lib:pq:v1.7.0:*:*:*:*:*:*:*",
 89437          "purl": "pkg:golang/github.com/lib/pq@v1.7.0",
 89438          "swid": {
 89439            "attachment": {}
 89440          },
 89441          "pedigree": {},
 89442          "evidence": {},
 89443          "signature": {
 89444            "signature": {
 89445              "publicKey": {}
 89446            }
 89447          },
 89448          "modelCard": {
 89449            "modelParameters": {
 89450              "approach": {}
 89451            },
 89452            "quantitativeAnalysis": {
 89453              "graphics": {}
 89454            },
 89455            "considerations": {}
 89456          }
 89457        },
 89458        {
 89459          "type": "library",
 89460          "bom-ref": "pkg:golang/github.com/liggitt/tabwriter@v0.0.0-20181228230101-89fcab3d43de?package-id=4284a02581000966",
 89461          "supplier": {},
 89462          "name": "github.com/liggitt/tabwriter",
 89463          "version": "v0.0.0-20181228230101-89fcab3d43de",
 89464          "cpe": "cpe:2.3:a:liggitt:tabwriter:v0.0.0-20181228230101-89fcab3d43de:*:*:*:*:*:*:*",
 89465          "purl": "pkg:golang/github.com/liggitt/tabwriter@v0.0.0-20181228230101-89fcab3d43de",
 89466          "swid": {
 89467            "attachment": {}
 89468          },
 89469          "pedigree": {},
 89470          "evidence": {},
 89471          "signature": {
 89472            "signature": {
 89473              "publicKey": {}
 89474            }
 89475          },
 89476          "modelCard": {
 89477            "modelParameters": {
 89478              "approach": {}
 89479            },
 89480            "quantitativeAnalysis": {
 89481              "graphics": {}
 89482            },
 89483            "considerations": {}
 89484          }
 89485        },
 89486        {
 89487          "type": "library",
 89488          "bom-ref": "pkg:golang/github.com/mailru/easyjson@v0.7.0?package-id=5bc9458db0d5883d",
 89489          "supplier": {},
 89490          "name": "github.com/mailru/easyjson",
 89491          "version": "v0.7.0",
 89492          "cpe": "cpe:2.3:a:mailru:easyjson:v0.7.0:*:*:*:*:*:*:*",
 89493          "purl": "pkg:golang/github.com/mailru/easyjson@v0.7.0",
 89494          "swid": {
 89495            "attachment": {}
 89496          },
 89497          "pedigree": {},
 89498          "evidence": {},
 89499          "signature": {
 89500            "signature": {
 89501              "publicKey": {}
 89502            }
 89503          },
 89504          "modelCard": {
 89505            "modelParameters": {
 89506              "approach": {}
 89507            },
 89508            "quantitativeAnalysis": {
 89509              "graphics": {}
 89510            },
 89511            "considerations": {}
 89512          }
 89513        },
 89514        {
 89515          "type": "library",
 89516          "bom-ref": "pkg:golang/github.com/mattn/go-colorable@v0.0.9?package-id=338523bb3704243b",
 89517          "supplier": {},
 89518          "name": "github.com/mattn/go-colorable",
 89519          "version": "v0.0.9",
 89520          "cpe": "cpe:2.3:a:mattn:go-colorable:v0.0.9:*:*:*:*:*:*:*",
 89521          "purl": "pkg:golang/github.com/mattn/go-colorable@v0.0.9",
 89522          "swid": {
 89523            "attachment": {}
 89524          },
 89525          "pedigree": {},
 89526          "evidence": {},
 89527          "signature": {
 89528            "signature": {
 89529              "publicKey": {}
 89530            }
 89531          },
 89532          "modelCard": {
 89533            "modelParameters": {
 89534              "approach": {}
 89535            },
 89536            "quantitativeAnalysis": {
 89537              "graphics": {}
 89538            },
 89539            "considerations": {}
 89540          }
 89541        },
 89542        {
 89543          "type": "library",
 89544          "bom-ref": "pkg:golang/github.com/mattn/go-isatty@v0.0.4?package-id=f4e9143a2a1f9767",
 89545          "supplier": {},
 89546          "name": "github.com/mattn/go-isatty",
 89547          "version": "v0.0.4",
 89548          "cpe": "cpe:2.3:a:mattn:go-isatty:v0.0.4:*:*:*:*:*:*:*",
 89549          "purl": "pkg:golang/github.com/mattn/go-isatty@v0.0.4",
 89550          "swid": {
 89551            "attachment": {}
 89552          },
 89553          "pedigree": {},
 89554          "evidence": {},
 89555          "signature": {
 89556            "signature": {
 89557              "publicKey": {}
 89558            }
 89559          },
 89560          "modelCard": {
 89561            "modelParameters": {
 89562              "approach": {}
 89563            },
 89564            "quantitativeAnalysis": {
 89565              "graphics": {}
 89566            },
 89567            "considerations": {}
 89568          }
 89569        },
 89570        {
 89571          "type": "library",
 89572          "bom-ref": "pkg:golang/github.com/mattn/go-runewidth@v0.0.4?package-id=603d5436319dff06",
 89573          "supplier": {},
 89574          "name": "github.com/mattn/go-runewidth",
 89575          "version": "v0.0.4",
 89576          "cpe": "cpe:2.3:a:mattn:go-runewidth:v0.0.4:*:*:*:*:*:*:*",
 89577          "purl": "pkg:golang/github.com/mattn/go-runewidth@v0.0.4",
 89578          "swid": {
 89579            "attachment": {}
 89580          },
 89581          "pedigree": {},
 89582          "evidence": {},
 89583          "signature": {
 89584            "signature": {
 89585              "publicKey": {}
 89586            }
 89587          },
 89588          "modelCard": {
 89589            "modelParameters": {
 89590              "approach": {}
 89591            },
 89592            "quantitativeAnalysis": {
 89593              "graphics": {}
 89594            },
 89595            "considerations": {}
 89596          }
 89597        },
 89598        {
 89599          "type": "library",
 89600          "bom-ref": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.1?package-id=e4e57eb52e73e4bc",
 89601          "supplier": {},
 89602          "name": "github.com/matttproud/golang_protobuf_extensions",
 89603          "version": "v1.0.1",
 89604          "cpe": "cpe:2.3:a:matttproud:golang-protobuf-extensions:v1.0.1:*:*:*:*:*:*:*",
 89605          "purl": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.1",
 89606          "swid": {
 89607            "attachment": {}
 89608          },
 89609          "pedigree": {},
 89610          "evidence": {},
 89611          "signature": {
 89612            "signature": {
 89613              "publicKey": {}
 89614            }
 89615          },
 89616          "modelCard": {
 89617            "modelParameters": {
 89618              "approach": {}
 89619            },
 89620            "quantitativeAnalysis": {
 89621              "graphics": {}
 89622            },
 89623            "considerations": {}
 89624          }
 89625        },
 89626        {
 89627          "type": "library",
 89628          "bom-ref": "pkg:golang/github.com/mitchellh/copystructure@v1.0.0?package-id=b79db778880a7e5e",
 89629          "supplier": {},
 89630          "name": "github.com/mitchellh/copystructure",
 89631          "version": "v1.0.0",
 89632          "cpe": "cpe:2.3:a:mitchellh:copystructure:v1.0.0:*:*:*:*:*:*:*",
 89633          "purl": "pkg:golang/github.com/mitchellh/copystructure@v1.0.0",
 89634          "swid": {
 89635            "attachment": {}
 89636          },
 89637          "pedigree": {},
 89638          "evidence": {},
 89639          "signature": {
 89640            "signature": {
 89641              "publicKey": {}
 89642            }
 89643          },
 89644          "modelCard": {
 89645            "modelParameters": {
 89646              "approach": {}
 89647            },
 89648            "quantitativeAnalysis": {
 89649              "graphics": {}
 89650            },
 89651            "considerations": {}
 89652          }
 89653        },
 89654        {
 89655          "type": "library",
 89656          "bom-ref": "pkg:golang/github.com/mitchellh/go-wordwrap@v1.0.0?package-id=c2e2d654d01da6d1",
 89657          "supplier": {},
 89658          "name": "github.com/mitchellh/go-wordwrap",
 89659          "version": "v1.0.0",
 89660          "cpe": "cpe:2.3:a:mitchellh:go-wordwrap:v1.0.0:*:*:*:*:*:*:*",
 89661          "purl": "pkg:golang/github.com/mitchellh/go-wordwrap@v1.0.0",
 89662          "swid": {
 89663            "attachment": {}
 89664          },
 89665          "pedigree": {},
 89666          "evidence": {},
 89667          "signature": {
 89668            "signature": {
 89669              "publicKey": {}
 89670            }
 89671          },
 89672          "modelCard": {
 89673            "modelParameters": {
 89674              "approach": {}
 89675            },
 89676            "quantitativeAnalysis": {
 89677              "graphics": {}
 89678            },
 89679            "considerations": {}
 89680          }
 89681        },
 89682        {
 89683          "type": "library",
 89684          "bom-ref": "pkg:golang/github.com/mitchellh/reflectwalk@v1.0.0?package-id=7c2eeff12b9815b8",
 89685          "supplier": {},
 89686          "name": "github.com/mitchellh/reflectwalk",
 89687          "version": "v1.0.0",
 89688          "cpe": "cpe:2.3:a:mitchellh:reflectwalk:v1.0.0:*:*:*:*:*:*:*",
 89689          "purl": "pkg:golang/github.com/mitchellh/reflectwalk@v1.0.0",
 89690          "swid": {
 89691            "attachment": {}
 89692          },
 89693          "pedigree": {},
 89694          "evidence": {},
 89695          "signature": {
 89696            "signature": {
 89697              "publicKey": {}
 89698            }
 89699          },
 89700          "modelCard": {
 89701            "modelParameters": {
 89702              "approach": {}
 89703            },
 89704            "quantitativeAnalysis": {
 89705              "graphics": {}
 89706            },
 89707            "considerations": {}
 89708          }
 89709        },
 89710        {
 89711          "type": "library",
 89712          "bom-ref": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd?package-id=d4063210c47eb7c9",
 89713          "supplier": {},
 89714          "name": "github.com/modern-go/concurrent",
 89715          "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
 89716          "cpe": "cpe:2.3:a:modern-go:concurrent:v0.0.0-20180306012644-bacd9c7ef1dd:*:*:*:*:*:*:*",
 89717          "purl": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd",
 89718          "swid": {
 89719            "attachment": {}
 89720          },
 89721          "pedigree": {},
 89722          "evidence": {},
 89723          "signature": {
 89724            "signature": {
 89725              "publicKey": {}
 89726            }
 89727          },
 89728          "modelCard": {
 89729            "modelParameters": {
 89730              "approach": {}
 89731            },
 89732            "quantitativeAnalysis": {
 89733              "graphics": {}
 89734            },
 89735            "considerations": {}
 89736          }
 89737        },
 89738        {
 89739          "type": "library",
 89740          "bom-ref": "pkg:golang/github.com/modern-go/reflect2@v1.0.1?package-id=6525366eee7f697a",
 89741          "supplier": {},
 89742          "name": "github.com/modern-go/reflect2",
 89743          "version": "v1.0.1",
 89744          "cpe": "cpe:2.3:a:modern-go:reflect2:v1.0.1:*:*:*:*:*:*:*",
 89745          "purl": "pkg:golang/github.com/modern-go/reflect2@v1.0.1",
 89746          "swid": {
 89747            "attachment": {}
 89748          },
 89749          "pedigree": {},
 89750          "evidence": {},
 89751          "signature": {
 89752            "signature": {
 89753              "publicKey": {}
 89754            }
 89755          },
 89756          "modelCard": {
 89757            "modelParameters": {
 89758              "approach": {}
 89759            },
 89760            "quantitativeAnalysis": {
 89761              "graphics": {}
 89762            },
 89763            "considerations": {}
 89764          }
 89765        },
 89766        {
 89767          "type": "library",
 89768          "bom-ref": "pkg:golang/github.com/morikuni/aec@v1.0.0?package-id=4c26cd5dbd10e995",
 89769          "supplier": {},
 89770          "name": "github.com/morikuni/aec",
 89771          "version": "v1.0.0",
 89772          "cpe": "cpe:2.3:a:morikuni:aec:v1.0.0:*:*:*:*:*:*:*",
 89773          "purl": "pkg:golang/github.com/morikuni/aec@v1.0.0",
 89774          "swid": {
 89775            "attachment": {}
 89776          },
 89777          "pedigree": {},
 89778          "evidence": {},
 89779          "signature": {
 89780            "signature": {
 89781              "publicKey": {}
 89782            }
 89783          },
 89784          "modelCard": {
 89785            "modelParameters": {
 89786              "approach": {}
 89787            },
 89788            "quantitativeAnalysis": {
 89789              "graphics": {}
 89790            },
 89791            "considerations": {}
 89792          }
 89793        },
 89794        {
 89795          "type": "library",
 89796          "bom-ref": "pkg:golang/github.com/opencontainers/go-digest@v1.0.0?package-id=3d395124c43fbb1c",
 89797          "supplier": {},
 89798          "name": "github.com/opencontainers/go-digest",
 89799          "version": "v1.0.0",
 89800          "cpe": "cpe:2.3:a:opencontainers:go-digest:v1.0.0:*:*:*:*:*:*:*",
 89801          "purl": "pkg:golang/github.com/opencontainers/go-digest@v1.0.0",
 89802          "swid": {
 89803            "attachment": {}
 89804          },
 89805          "pedigree": {},
 89806          "evidence": {},
 89807          "signature": {
 89808            "signature": {
 89809              "publicKey": {}
 89810            }
 89811          },
 89812          "modelCard": {
 89813            "modelParameters": {
 89814              "approach": {}
 89815            },
 89816            "quantitativeAnalysis": {
 89817              "graphics": {}
 89818            },
 89819            "considerations": {}
 89820          }
 89821        },
 89822        {
 89823          "type": "library",
 89824          "bom-ref": "pkg:golang/github.com/opencontainers/image-spec@v1.0.1?package-id=608cc80b44552a2f",
 89825          "supplier": {},
 89826          "name": "github.com/opencontainers/image-spec",
 89827          "version": "v1.0.1",
 89828          "cpe": "cpe:2.3:a:opencontainers:image-spec:v1.0.1:*:*:*:*:*:*:*",
 89829          "purl": "pkg:golang/github.com/opencontainers/image-spec@v1.0.1",
 89830          "swid": {
 89831            "attachment": {}
 89832          },
 89833          "pedigree": {},
 89834          "evidence": {},
 89835          "signature": {
 89836            "signature": {
 89837              "publicKey": {}
 89838            }
 89839          },
 89840          "modelCard": {
 89841            "modelParameters": {
 89842              "approach": {}
 89843            },
 89844            "quantitativeAnalysis": {
 89845              "graphics": {}
 89846            },
 89847            "considerations": {}
 89848          }
 89849        },
 89850        {
 89851          "type": "library",
 89852          "bom-ref": "pkg:golang/github.com/opencontainers/runc@v0.1.1?package-id=6e68f8f14ba49e6d",
 89853          "supplier": {},
 89854          "name": "github.com/opencontainers/runc",
 89855          "version": "v0.1.1",
 89856          "cpe": "cpe:2.3:a:opencontainers:runc:v0.1.1:*:*:*:*:*:*:*",
 89857          "purl": "pkg:golang/github.com/opencontainers/runc@v0.1.1",
 89858          "swid": {
 89859            "attachment": {}
 89860          },
 89861          "pedigree": {},
 89862          "evidence": {},
 89863          "signature": {
 89864            "signature": {
 89865              "publicKey": {}
 89866            }
 89867          },
 89868          "modelCard": {
 89869            "modelParameters": {
 89870              "approach": {}
 89871            },
 89872            "quantitativeAnalysis": {
 89873              "graphics": {}
 89874            },
 89875            "considerations": {}
 89876          }
 89877        },
 89878        {
 89879          "type": "library",
 89880          "bom-ref": "pkg:golang/github.com/peterbourgon/diskv@v2.0.1+incompatible?package-id=f180f8d475b1762a",
 89881          "supplier": {},
 89882          "name": "github.com/peterbourgon/diskv",
 89883          "version": "v2.0.1+incompatible",
 89884          "cpe": "cpe:2.3:a:peterbourgon:diskv:v2.0.1\\+incompatible:*:*:*:*:*:*:*",
 89885          "purl": "pkg:golang/github.com/peterbourgon/diskv@v2.0.1+incompatible",
 89886          "swid": {
 89887            "attachment": {}
 89888          },
 89889          "pedigree": {},
 89890          "evidence": {},
 89891          "signature": {
 89892            "signature": {
 89893              "publicKey": {}
 89894            }
 89895          },
 89896          "modelCard": {
 89897            "modelParameters": {
 89898              "approach": {}
 89899            },
 89900            "quantitativeAnalysis": {
 89901              "graphics": {}
 89902            },
 89903            "considerations": {}
 89904          }
 89905        },
 89906        {
 89907          "type": "library",
 89908          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.9.1?package-id=102b1c5e6aa8e52c",
 89909          "supplier": {},
 89910          "name": "github.com/pkg/errors",
 89911          "version": "v0.9.1",
 89912          "cpe": "cpe:2.3:a:pkg:errors:v0.9.1:*:*:*:*:*:*:*",
 89913          "purl": "pkg:golang/github.com/pkg/errors@v0.9.1",
 89914          "swid": {
 89915            "attachment": {}
 89916          },
 89917          "pedigree": {},
 89918          "evidence": {},
 89919          "signature": {
 89920            "signature": {
 89921              "publicKey": {}
 89922            }
 89923          },
 89924          "modelCard": {
 89925            "modelParameters": {
 89926              "approach": {}
 89927            },
 89928            "quantitativeAnalysis": {
 89929              "graphics": {}
 89930            },
 89931            "considerations": {}
 89932          }
 89933        },
 89934        {
 89935          "type": "library",
 89936          "bom-ref": "pkg:golang/github.com/prometheus/client_golang@v1.3.0?package-id=4ce5afa6e17e6a4b",
 89937          "supplier": {},
 89938          "name": "github.com/prometheus/client_golang",
 89939          "version": "v1.3.0",
 89940          "cpe": "cpe:2.3:a:prometheus:client-golang:v1.3.0:*:*:*:*:*:*:*",
 89941          "purl": "pkg:golang/github.com/prometheus/client_golang@v1.3.0",
 89942          "swid": {
 89943            "attachment": {}
 89944          },
 89945          "pedigree": {},
 89946          "evidence": {},
 89947          "signature": {
 89948            "signature": {
 89949              "publicKey": {}
 89950            }
 89951          },
 89952          "modelCard": {
 89953            "modelParameters": {
 89954              "approach": {}
 89955            },
 89956            "quantitativeAnalysis": {
 89957              "graphics": {}
 89958            },
 89959            "considerations": {}
 89960          }
 89961        },
 89962        {
 89963          "type": "library",
 89964          "bom-ref": "pkg:golang/github.com/prometheus/client_model@v0.2.0?package-id=9c09ccb8224905fd",
 89965          "supplier": {},
 89966          "name": "github.com/prometheus/client_model",
 89967          "version": "v0.2.0",
 89968          "cpe": "cpe:2.3:a:prometheus:client-model:v0.2.0:*:*:*:*:*:*:*",
 89969          "purl": "pkg:golang/github.com/prometheus/client_model@v0.2.0",
 89970          "swid": {
 89971            "attachment": {}
 89972          },
 89973          "pedigree": {},
 89974          "evidence": {},
 89975          "signature": {
 89976            "signature": {
 89977              "publicKey": {}
 89978            }
 89979          },
 89980          "modelCard": {
 89981            "modelParameters": {
 89982              "approach": {}
 89983            },
 89984            "quantitativeAnalysis": {
 89985              "graphics": {}
 89986            },
 89987            "considerations": {}
 89988          }
 89989        },
 89990        {
 89991          "type": "library",
 89992          "bom-ref": "pkg:golang/github.com/prometheus/common@v0.7.0?package-id=97929d5ab3d4069a",
 89993          "supplier": {},
 89994          "name": "github.com/prometheus/common",
 89995          "version": "v0.7.0",
 89996          "cpe": "cpe:2.3:a:prometheus:common:v0.7.0:*:*:*:*:*:*:*",
 89997          "purl": "pkg:golang/github.com/prometheus/common@v0.7.0",
 89998          "swid": {
 89999            "attachment": {}
 90000          },
 90001          "pedigree": {},
 90002          "evidence": {},
 90003          "signature": {
 90004            "signature": {
 90005              "publicKey": {}
 90006            }
 90007          },
 90008          "modelCard": {
 90009            "modelParameters": {
 90010              "approach": {}
 90011            },
 90012            "quantitativeAnalysis": {
 90013              "graphics": {}
 90014            },
 90015            "considerations": {}
 90016          }
 90017        },
 90018        {
 90019          "type": "library",
 90020          "bom-ref": "pkg:golang/github.com/prometheus/procfs@v0.0.8?package-id=f8d659e140f23dbb",
 90021          "supplier": {},
 90022          "name": "github.com/prometheus/procfs",
 90023          "version": "v0.0.8",
 90024          "cpe": "cpe:2.3:a:prometheus:procfs:v0.0.8:*:*:*:*:*:*:*",
 90025          "purl": "pkg:golang/github.com/prometheus/procfs@v0.0.8",
 90026          "swid": {
 90027            "attachment": {}
 90028          },
 90029          "pedigree": {},
 90030          "evidence": {},
 90031          "signature": {
 90032            "signature": {
 90033              "publicKey": {}
 90034            }
 90035          },
 90036          "modelCard": {
 90037            "modelParameters": {
 90038              "approach": {}
 90039            },
 90040            "quantitativeAnalysis": {
 90041              "graphics": {}
 90042            },
 90043            "considerations": {}
 90044          }
 90045        },
 90046        {
 90047          "type": "library",
 90048          "bom-ref": "pkg:golang/github.com/rubenv/sql-migrate@v0.0.0-20200616145509-8d140a17f351?package-id=fbda4ca2903bee0b",
 90049          "supplier": {},
 90050          "name": "github.com/rubenv/sql-migrate",
 90051          "version": "v0.0.0-20200616145509-8d140a17f351",
 90052          "cpe": "cpe:2.3:a:rubenv:sql-migrate:v0.0.0-20200616145509-8d140a17f351:*:*:*:*:*:*:*",
 90053          "purl": "pkg:golang/github.com/rubenv/sql-migrate@v0.0.0-20200616145509-8d140a17f351",
 90054          "swid": {
 90055            "attachment": {}
 90056          },
 90057          "pedigree": {},
 90058          "evidence": {},
 90059          "signature": {
 90060            "signature": {
 90061              "publicKey": {}
 90062            }
 90063          },
 90064          "modelCard": {
 90065            "modelParameters": {
 90066              "approach": {}
 90067            },
 90068            "quantitativeAnalysis": {
 90069              "graphics": {}
 90070            },
 90071            "considerations": {}
 90072          }
 90073        },
 90074        {
 90075          "type": "library",
 90076          "bom-ref": "pkg:golang/github.com/russross/blackfriday@v1.5.2?package-id=fc0b3d6163405b4f",
 90077          "supplier": {},
 90078          "name": "github.com/russross/blackfriday",
 90079          "version": "v1.5.2",
 90080          "cpe": "cpe:2.3:a:russross:blackfriday:v1.5.2:*:*:*:*:*:*:*",
 90081          "purl": "pkg:golang/github.com/russross/blackfriday@v1.5.2",
 90082          "swid": {
 90083            "attachment": {}
 90084          },
 90085          "pedigree": {},
 90086          "evidence": {},
 90087          "signature": {
 90088            "signature": {
 90089              "publicKey": {}
 90090            }
 90091          },
 90092          "modelCard": {
 90093            "modelParameters": {
 90094              "approach": {}
 90095            },
 90096            "quantitativeAnalysis": {
 90097              "graphics": {}
 90098            },
 90099            "considerations": {}
 90100          }
 90101        },
 90102        {
 90103          "type": "library",
 90104          "bom-ref": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1?package-id=1df03569e90eeca",
 90105          "supplier": {},
 90106          "name": "github.com/russross/blackfriday/v2",
 90107          "version": "v2.0.1",
 90108          "cpe": "cpe:2.3:a:russross:blackfriday\\/v2:v2.0.1:*:*:*:*:*:*:*",
 90109          "purl": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1",
 90110          "swid": {
 90111            "attachment": {}
 90112          },
 90113          "pedigree": {},
 90114          "evidence": {},
 90115          "signature": {
 90116            "signature": {
 90117              "publicKey": {}
 90118            }
 90119          },
 90120          "modelCard": {
 90121            "modelParameters": {
 90122              "approach": {}
 90123            },
 90124            "quantitativeAnalysis": {
 90125              "graphics": {}
 90126            },
 90127            "considerations": {}
 90128          }
 90129        },
 90130        {
 90131          "type": "library",
 90132          "bom-ref": "pkg:golang/github.com/shurcool/sanitized_anchor_name@v1.0.0?package-id=824c8bf29aaa0bf",
 90133          "supplier": {},
 90134          "name": "github.com/shurcooL/sanitized_anchor_name",
 90135          "version": "v1.0.0",
 90136          "cpe": "cpe:2.3:a:shurcooL:sanitized-anchor-name:v1.0.0:*:*:*:*:*:*:*",
 90137          "purl": "pkg:golang/github.com/shurcooL/sanitized_anchor_name@v1.0.0",
 90138          "swid": {
 90139            "attachment": {}
 90140          },
 90141          "pedigree": {},
 90142          "evidence": {},
 90143          "signature": {
 90144            "signature": {
 90145              "publicKey": {}
 90146            }
 90147          },
 90148          "modelCard": {
 90149            "modelParameters": {
 90150              "approach": {}
 90151            },
 90152            "quantitativeAnalysis": {
 90153              "graphics": {}
 90154            },
 90155            "considerations": {}
 90156          }
 90157        },
 90158        {
 90159          "type": "library",
 90160          "bom-ref": "pkg:golang/github.com/sirupsen/logrus@v1.6.0?package-id=5c9e749be42cd006",
 90161          "supplier": {},
 90162          "name": "github.com/sirupsen/logrus",
 90163          "version": "v1.6.0",
 90164          "cpe": "cpe:2.3:a:sirupsen:logrus:v1.6.0:*:*:*:*:*:*:*",
 90165          "purl": "pkg:golang/github.com/sirupsen/logrus@v1.6.0",
 90166          "swid": {
 90167            "attachment": {}
 90168          },
 90169          "pedigree": {},
 90170          "evidence": {},
 90171          "signature": {
 90172            "signature": {
 90173              "publicKey": {}
 90174            }
 90175          },
 90176          "modelCard": {
 90177            "modelParameters": {
 90178              "approach": {}
 90179            },
 90180            "quantitativeAnalysis": {
 90181              "graphics": {}
 90182            },
 90183            "considerations": {}
 90184          }
 90185        },
 90186        {
 90187          "type": "library",
 90188          "bom-ref": "pkg:golang/github.com/spf13/cast@v1.3.1?package-id=806d619579bf025c",
 90189          "supplier": {},
 90190          "name": "github.com/spf13/cast",
 90191          "version": "v1.3.1",
 90192          "cpe": "cpe:2.3:a:spf13:cast:v1.3.1:*:*:*:*:*:*:*",
 90193          "purl": "pkg:golang/github.com/spf13/cast@v1.3.1",
 90194          "swid": {
 90195            "attachment": {}
 90196          },
 90197          "pedigree": {},
 90198          "evidence": {},
 90199          "signature": {
 90200            "signature": {
 90201              "publicKey": {}
 90202            }
 90203          },
 90204          "modelCard": {
 90205            "modelParameters": {
 90206              "approach": {}
 90207            },
 90208            "quantitativeAnalysis": {
 90209              "graphics": {}
 90210            },
 90211            "considerations": {}
 90212          }
 90213        },
 90214        {
 90215          "type": "library",
 90216          "bom-ref": "pkg:golang/github.com/spf13/cobra@v1.0.0?package-id=21d3cbdd4f97b2ac",
 90217          "supplier": {},
 90218          "name": "github.com/spf13/cobra",
 90219          "version": "v1.0.0",
 90220          "cpe": "cpe:2.3:a:spf13:cobra:v1.0.0:*:*:*:*:*:*:*",
 90221          "purl": "pkg:golang/github.com/spf13/cobra@v1.0.0",
 90222          "swid": {
 90223            "attachment": {}
 90224          },
 90225          "pedigree": {},
 90226          "evidence": {},
 90227          "signature": {
 90228            "signature": {
 90229              "publicKey": {}
 90230            }
 90231          },
 90232          "modelCard": {
 90233            "modelParameters": {
 90234              "approach": {}
 90235            },
 90236            "quantitativeAnalysis": {
 90237              "graphics": {}
 90238            },
 90239            "considerations": {}
 90240          }
 90241        },
 90242        {
 90243          "type": "library",
 90244          "bom-ref": "pkg:golang/github.com/spf13/pflag@v1.0.5?package-id=cc02bb94a228303",
 90245          "supplier": {},
 90246          "name": "github.com/spf13/pflag",
 90247          "version": "v1.0.5",
 90248          "cpe": "cpe:2.3:a:spf13:pflag:v1.0.5:*:*:*:*:*:*:*",
 90249          "purl": "pkg:golang/github.com/spf13/pflag@v1.0.5",
 90250          "swid": {
 90251            "attachment": {}
 90252          },
 90253          "pedigree": {},
 90254          "evidence": {},
 90255          "signature": {
 90256            "signature": {
 90257              "publicKey": {}
 90258            }
 90259          },
 90260          "modelCard": {
 90261            "modelParameters": {
 90262              "approach": {}
 90263            },
 90264            "quantitativeAnalysis": {
 90265              "graphics": {}
 90266            },
 90267            "considerations": {}
 90268          }
 90269        },
 90270        {
 90271          "type": "library",
 90272          "bom-ref": "pkg:golang/github.com/xeipuuv/gojsonpointer@v0.0.0-20180127040702-4e3ac2762d5f?package-id=6ca8572748c57f09",
 90273          "supplier": {},
 90274          "name": "github.com/xeipuuv/gojsonpointer",
 90275          "version": "v0.0.0-20180127040702-4e3ac2762d5f",
 90276          "cpe": "cpe:2.3:a:xeipuuv:gojsonpointer:v0.0.0-20180127040702-4e3ac2762d5f:*:*:*:*:*:*:*",
 90277          "purl": "pkg:golang/github.com/xeipuuv/gojsonpointer@v0.0.0-20180127040702-4e3ac2762d5f",
 90278          "swid": {
 90279            "attachment": {}
 90280          },
 90281          "pedigree": {},
 90282          "evidence": {},
 90283          "signature": {
 90284            "signature": {
 90285              "publicKey": {}
 90286            }
 90287          },
 90288          "modelCard": {
 90289            "modelParameters": {
 90290              "approach": {}
 90291            },
 90292            "quantitativeAnalysis": {
 90293              "graphics": {}
 90294            },
 90295            "considerations": {}
 90296          }
 90297        },
 90298        {
 90299          "type": "library",
 90300          "bom-ref": "pkg:golang/github.com/xeipuuv/gojsonreference@v0.0.0-20180127040603-bd5ef7bd5415?package-id=c4c6001829e8943d",
 90301          "supplier": {},
 90302          "name": "github.com/xeipuuv/gojsonreference",
 90303          "version": "v0.0.0-20180127040603-bd5ef7bd5415",
 90304          "cpe": "cpe:2.3:a:xeipuuv:gojsonreference:v0.0.0-20180127040603-bd5ef7bd5415:*:*:*:*:*:*:*",
 90305          "purl": "pkg:golang/github.com/xeipuuv/gojsonreference@v0.0.0-20180127040603-bd5ef7bd5415",
 90306          "swid": {
 90307            "attachment": {}
 90308          },
 90309          "pedigree": {},
 90310          "evidence": {},
 90311          "signature": {
 90312            "signature": {
 90313              "publicKey": {}
 90314            }
 90315          },
 90316          "modelCard": {
 90317            "modelParameters": {
 90318              "approach": {}
 90319            },
 90320            "quantitativeAnalysis": {
 90321              "graphics": {}
 90322            },
 90323            "considerations": {}
 90324          }
 90325        },
 90326        {
 90327          "type": "library",
 90328          "bom-ref": "pkg:golang/github.com/xeipuuv/gojsonschema@v1.2.0?package-id=31cea7f4e379e9ad",
 90329          "supplier": {},
 90330          "name": "github.com/xeipuuv/gojsonschema",
 90331          "version": "v1.2.0",
 90332          "cpe": "cpe:2.3:a:xeipuuv:gojsonschema:v1.2.0:*:*:*:*:*:*:*",
 90333          "purl": "pkg:golang/github.com/xeipuuv/gojsonschema@v1.2.0",
 90334          "swid": {
 90335            "attachment": {}
 90336          },
 90337          "pedigree": {},
 90338          "evidence": {},
 90339          "signature": {
 90340            "signature": {
 90341              "publicKey": {}
 90342            }
 90343          },
 90344          "modelCard": {
 90345            "modelParameters": {
 90346              "approach": {}
 90347            },
 90348            "quantitativeAnalysis": {
 90349              "graphics": {}
 90350            },
 90351            "considerations": {}
 90352          }
 90353        },
 90354        {
 90355          "type": "library",
 90356          "bom-ref": "pkg:golang/golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9?package-id=6f16680a8e939f14",
 90357          "supplier": {},
 90358          "name": "golang.org/x/crypto",
 90359          "version": "v0.0.0-20200622213623-75b288015ac9",
 90360          "cpe": "cpe:2.3:a:golang:x\\/crypto:v0.0.0-20200622213623-75b288015ac9:*:*:*:*:*:*:*",
 90361          "purl": "pkg:golang/golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9",
 90362          "swid": {
 90363            "attachment": {}
 90364          },
 90365          "pedigree": {},
 90366          "evidence": {},
 90367          "signature": {
 90368            "signature": {
 90369              "publicKey": {}
 90370            }
 90371          },
 90372          "modelCard": {
 90373            "modelParameters": {
 90374              "approach": {}
 90375            },
 90376            "quantitativeAnalysis": {
 90377              "graphics": {}
 90378            },
 90379            "considerations": {}
 90380          }
 90381        },
 90382        {
 90383          "type": "library",
 90384          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9?package-id=df6af06ebba77f9a",
 90385          "supplier": {},
 90386          "name": "golang.org/x/net",
 90387          "version": "v0.0.0-20191004110552-13f9640d40b9",
 90388          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20191004110552-13f9640d40b9:*:*:*:*:*:*:*",
 90389          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9",
 90390          "swid": {
 90391            "attachment": {}
 90392          },
 90393          "pedigree": {},
 90394          "evidence": {},
 90395          "signature": {
 90396            "signature": {
 90397              "publicKey": {}
 90398            }
 90399          },
 90400          "modelCard": {
 90401            "modelParameters": {
 90402              "approach": {}
 90403            },
 90404            "quantitativeAnalysis": {
 90405              "graphics": {}
 90406            },
 90407            "considerations": {}
 90408          }
 90409        },
 90410        {
 90411          "type": "library",
 90412          "bom-ref": "pkg:golang/golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45?package-id=864fef5fbb9e7778",
 90413          "supplier": {},
 90414          "name": "golang.org/x/oauth2",
 90415          "version": "v0.0.0-20190604053449-0f29369cfe45",
 90416          "cpe": "cpe:2.3:a:golang:x\\/oauth2:v0.0.0-20190604053449-0f29369cfe45:*:*:*:*:*:*:*",
 90417          "purl": "pkg:golang/golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45",
 90418          "swid": {
 90419            "attachment": {}
 90420          },
 90421          "pedigree": {},
 90422          "evidence": {},
 90423          "signature": {
 90424            "signature": {
 90425              "publicKey": {}
 90426            }
 90427          },
 90428          "modelCard": {
 90429            "modelParameters": {
 90430              "approach": {}
 90431            },
 90432            "quantitativeAnalysis": {
 90433              "graphics": {}
 90434            },
 90435            "considerations": {}
 90436          }
 90437        },
 90438        {
 90439          "type": "library",
 90440          "bom-ref": "pkg:golang/golang.org/x/sync@v0.0.0-20190911185100-cd5d95a43a6e?package-id=3a999ee2cbc90b4d",
 90441          "supplier": {},
 90442          "name": "golang.org/x/sync",
 90443          "version": "v0.0.0-20190911185100-cd5d95a43a6e",
 90444          "cpe": "cpe:2.3:a:golang:x\\/sync:v0.0.0-20190911185100-cd5d95a43a6e:*:*:*:*:*:*:*",
 90445          "purl": "pkg:golang/golang.org/x/sync@v0.0.0-20190911185100-cd5d95a43a6e",
 90446          "swid": {
 90447            "attachment": {}
 90448          },
 90449          "pedigree": {},
 90450          "evidence": {},
 90451          "signature": {
 90452            "signature": {
 90453              "publicKey": {}
 90454            }
 90455          },
 90456          "modelCard": {
 90457            "modelParameters": {
 90458              "approach": {}
 90459            },
 90460            "quantitativeAnalysis": {
 90461              "graphics": {}
 90462            },
 90463            "considerations": {}
 90464          }
 90465        },
 90466        {
 90467          "type": "library",
 90468          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20191220142924-d4481acd189f?package-id=f220849ef208274c",
 90469          "supplier": {},
 90470          "name": "golang.org/x/sys",
 90471          "version": "v0.0.0-20191220142924-d4481acd189f",
 90472          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20191220142924-d4481acd189f:*:*:*:*:*:*:*",
 90473          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20191220142924-d4481acd189f",
 90474          "swid": {
 90475            "attachment": {}
 90476          },
 90477          "pedigree": {},
 90478          "evidence": {},
 90479          "signature": {
 90480            "signature": {
 90481              "publicKey": {}
 90482            }
 90483          },
 90484          "modelCard": {
 90485            "modelParameters": {
 90486              "approach": {}
 90487            },
 90488            "quantitativeAnalysis": {
 90489              "graphics": {}
 90490            },
 90491            "considerations": {}
 90492          }
 90493        },
 90494        {
 90495          "type": "library",
 90496          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.2?package-id=72619b0ef5d4cc04",
 90497          "supplier": {},
 90498          "name": "golang.org/x/text",
 90499          "version": "v0.3.2",
 90500          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.2:*:*:*:*:*:*:*",
 90501          "purl": "pkg:golang/golang.org/x/text@v0.3.2",
 90502          "swid": {
 90503            "attachment": {}
 90504          },
 90505          "pedigree": {},
 90506          "evidence": {},
 90507          "signature": {
 90508            "signature": {
 90509              "publicKey": {}
 90510            }
 90511          },
 90512          "modelCard": {
 90513            "modelParameters": {
 90514              "approach": {}
 90515            },
 90516            "quantitativeAnalysis": {
 90517              "graphics": {}
 90518            },
 90519            "considerations": {}
 90520          }
 90521        },
 90522        {
 90523          "type": "library",
 90524          "bom-ref": "pkg:golang/golang.org/x/time@v0.0.0-20191024005414-555d28b269f0?package-id=68947e4210d05ce0",
 90525          "supplier": {},
 90526          "name": "golang.org/x/time",
 90527          "version": "v0.0.0-20191024005414-555d28b269f0",
 90528          "cpe": "cpe:2.3:a:golang:x\\/time:v0.0.0-20191024005414-555d28b269f0:*:*:*:*:*:*:*",
 90529          "purl": "pkg:golang/golang.org/x/time@v0.0.0-20191024005414-555d28b269f0",
 90530          "swid": {
 90531            "attachment": {}
 90532          },
 90533          "pedigree": {},
 90534          "evidence": {},
 90535          "signature": {
 90536            "signature": {
 90537              "publicKey": {}
 90538            }
 90539          },
 90540          "modelCard": {
 90541            "modelParameters": {
 90542              "approach": {}
 90543            },
 90544            "quantitativeAnalysis": {
 90545              "graphics": {}
 90546            },
 90547            "considerations": {}
 90548          }
 90549        },
 90550        {
 90551          "type": "library",
 90552          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20190819201941-24fa4b261c55?package-id=6c5380edc7772a97",
 90553          "supplier": {},
 90554          "name": "google.golang.org/genproto",
 90555          "version": "v0.0.0-20190819201941-24fa4b261c55",
 90556          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20190819201941-24fa4b261c55:*:*:*:*:*:*:*",
 90557          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20190819201941-24fa4b261c55",
 90558          "swid": {
 90559            "attachment": {}
 90560          },
 90561          "pedigree": {},
 90562          "evidence": {},
 90563          "signature": {
 90564            "signature": {
 90565              "publicKey": {}
 90566            }
 90567          },
 90568          "modelCard": {
 90569            "modelParameters": {
 90570              "approach": {}
 90571            },
 90572            "quantitativeAnalysis": {
 90573              "graphics": {}
 90574            },
 90575            "considerations": {}
 90576          }
 90577        },
 90578        {
 90579          "type": "library",
 90580          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.27.0?package-id=8cff90cd28a7d631",
 90581          "supplier": {},
 90582          "name": "google.golang.org/grpc",
 90583          "version": "v1.27.0",
 90584          "cpe": "cpe:2.3:a:google:grpc:v1.27.0:*:*:*:*:*:*:*",
 90585          "purl": "pkg:golang/google.golang.org/grpc@v1.27.0",
 90586          "swid": {
 90587            "attachment": {}
 90588          },
 90589          "pedigree": {},
 90590          "evidence": {},
 90591          "signature": {
 90592            "signature": {
 90593              "publicKey": {}
 90594            }
 90595          },
 90596          "modelCard": {
 90597            "modelParameters": {
 90598              "approach": {}
 90599            },
 90600            "quantitativeAnalysis": {
 90601              "graphics": {}
 90602            },
 90603            "considerations": {}
 90604          }
 90605        },
 90606        {
 90607          "type": "library",
 90608          "bom-ref": "pkg:golang/gopkg.in/gorp.v1@v1.7.2?package-id=e28a0d024b534fe5",
 90609          "supplier": {},
 90610          "name": "gopkg.in/gorp.v1",
 90611          "version": "v1.7.2",
 90612          "purl": "pkg:golang/gopkg.in/gorp.v1@v1.7.2",
 90613          "swid": {
 90614            "attachment": {}
 90615          },
 90616          "pedigree": {},
 90617          "evidence": {},
 90618          "signature": {
 90619            "signature": {
 90620              "publicKey": {}
 90621            }
 90622          },
 90623          "modelCard": {
 90624            "modelParameters": {
 90625              "approach": {}
 90626            },
 90627            "quantitativeAnalysis": {
 90628              "graphics": {}
 90629            },
 90630            "considerations": {}
 90631          }
 90632        },
 90633        {
 90634          "type": "library",
 90635          "bom-ref": "pkg:golang/gopkg.in/inf.v0@v0.9.1?package-id=c5d35fbd347bd49c",
 90636          "supplier": {},
 90637          "name": "gopkg.in/inf.v0",
 90638          "version": "v0.9.1",
 90639          "purl": "pkg:golang/gopkg.in/inf.v0@v0.9.1",
 90640          "swid": {
 90641            "attachment": {}
 90642          },
 90643          "pedigree": {},
 90644          "evidence": {},
 90645          "signature": {
 90646            "signature": {
 90647              "publicKey": {}
 90648            }
 90649          },
 90650          "modelCard": {
 90651            "modelParameters": {
 90652              "approach": {}
 90653            },
 90654            "quantitativeAnalysis": {
 90655              "graphics": {}
 90656            },
 90657            "considerations": {}
 90658          }
 90659        },
 90660        {
 90661          "type": "library",
 90662          "bom-ref": "pkg:golang/gopkg.in/yaml.v2@v2.2.8?package-id=5697cb299b21a70a",
 90663          "supplier": {},
 90664          "name": "gopkg.in/yaml.v2",
 90665          "version": "v2.2.8",
 90666          "purl": "pkg:golang/gopkg.in/yaml.v2@v2.2.8",
 90667          "swid": {
 90668            "attachment": {}
 90669          },
 90670          "pedigree": {},
 90671          "evidence": {},
 90672          "signature": {
 90673            "signature": {
 90674              "publicKey": {}
 90675            }
 90676          },
 90677          "modelCard": {
 90678            "modelParameters": {
 90679              "approach": {}
 90680            },
 90681            "quantitativeAnalysis": {
 90682              "graphics": {}
 90683            },
 90684            "considerations": {}
 90685          }
 90686        },
 90687        {
 90688          "type": "library",
 90689          "bom-ref": "pkg:golang/helm.sh/helm/v3@(devel)?package-id=8cca756e0b9d3751",
 90690          "supplier": {},
 90691          "name": "helm.sh/helm/v3",
 90692          "version": "(devel)",
 90693          "cpe": "cpe:2.3:a:helm:v3:\\(devel\\):*:*:*:*:*:*:*",
 90694          "purl": "pkg:golang/helm.sh/helm/v3@(devel)",
 90695          "swid": {
 90696            "attachment": {}
 90697          },
 90698          "pedigree": {},
 90699          "evidence": {},
 90700          "signature": {
 90701            "signature": {
 90702              "publicKey": {}
 90703            }
 90704          },
 90705          "modelCard": {
 90706            "modelParameters": {
 90707              "approach": {}
 90708            },
 90709            "quantitativeAnalysis": {
 90710              "graphics": {}
 90711            },
 90712            "considerations": {}
 90713          }
 90714        },
 90715        {
 90716          "type": "library",
 90717          "bom-ref": "pkg:apk/alpine/jq@1.6-r1?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=dd4b3b7bf6f7ade6",
 90718          "supplier": {},
 90719          "publisher": "Johannes Matheis \u003cjomat+alpinebuild@jmt.gr\u003e",
 90720          "name": "jq",
 90721          "version": "1.6-r1",
 90722          "description": "A lightweight and flexible command-line JSON processor",
 90723          "licenses": [
 90724            {
 90725              "license": {
 90726                "id": "MIT"
 90727              }
 90728            }
 90729          ],
 90730          "cpe": "cpe:2.3:a:jq:jq:1.6-r1:*:*:*:*:*:*:*",
 90731          "purl": "pkg:apk/alpine/jq@1.6-r1?arch=x86_64\u0026distro=alpine-3.12.3",
 90732          "swid": {
 90733            "attachment": {}
 90734          },
 90735          "pedigree": {},
 90736          "externalReferences": [
 90737            {
 90738              "url": "https://stedolan.github.io/jq/",
 90739              "type": "distribution"
 90740            }
 90741          ],
 90742          "evidence": {},
 90743          "signature": {
 90744            "signature": {
 90745              "publicKey": {}
 90746            }
 90747          },
 90748          "modelCard": {
 90749            "modelParameters": {
 90750              "approach": {}
 90751            },
 90752            "quantitativeAnalysis": {
 90753              "graphics": {}
 90754            },
 90755            "considerations": {}
 90756          }
 90757        },
 90758        {
 90759          "type": "library",
 90760          "bom-ref": "pkg:golang/k8s.io/api@v0.18.8?package-id=b0698b0101c356c5",
 90761          "supplier": {},
 90762          "name": "k8s.io/api",
 90763          "version": "v0.18.8",
 90764          "purl": "pkg:golang/k8s.io/api@v0.18.8",
 90765          "swid": {
 90766            "attachment": {}
 90767          },
 90768          "pedigree": {},
 90769          "evidence": {},
 90770          "signature": {
 90771            "signature": {
 90772              "publicKey": {}
 90773            }
 90774          },
 90775          "modelCard": {
 90776            "modelParameters": {
 90777              "approach": {}
 90778            },
 90779            "quantitativeAnalysis": {
 90780              "graphics": {}
 90781            },
 90782            "considerations": {}
 90783          }
 90784        },
 90785        {
 90786          "type": "library",
 90787          "bom-ref": "pkg:golang/k8s.io/apiextensions-apiserver@v0.18.8?package-id=17671b73f5e1045e",
 90788          "supplier": {},
 90789          "name": "k8s.io/apiextensions-apiserver",
 90790          "version": "v0.18.8",
 90791          "purl": "pkg:golang/k8s.io/apiextensions-apiserver@v0.18.8",
 90792          "swid": {
 90793            "attachment": {}
 90794          },
 90795          "pedigree": {},
 90796          "evidence": {},
 90797          "signature": {
 90798            "signature": {
 90799              "publicKey": {}
 90800            }
 90801          },
 90802          "modelCard": {
 90803            "modelParameters": {
 90804              "approach": {}
 90805            },
 90806            "quantitativeAnalysis": {
 90807              "graphics": {}
 90808            },
 90809            "considerations": {}
 90810          }
 90811        },
 90812        {
 90813          "type": "library",
 90814          "bom-ref": "pkg:golang/k8s.io/apimachinery@v0.18.8?package-id=18ff1b6b83d3407f",
 90815          "supplier": {},
 90816          "name": "k8s.io/apimachinery",
 90817          "version": "v0.18.8",
 90818          "purl": "pkg:golang/k8s.io/apimachinery@v0.18.8",
 90819          "swid": {
 90820            "attachment": {}
 90821          },
 90822          "pedigree": {},
 90823          "evidence": {},
 90824          "signature": {
 90825            "signature": {
 90826              "publicKey": {}
 90827            }
 90828          },
 90829          "modelCard": {
 90830            "modelParameters": {
 90831              "approach": {}
 90832            },
 90833            "quantitativeAnalysis": {
 90834              "graphics": {}
 90835            },
 90836            "considerations": {}
 90837          }
 90838        },
 90839        {
 90840          "type": "library",
 90841          "bom-ref": "pkg:golang/k8s.io/cli-runtime@v0.18.8?package-id=9893070409893d83",
 90842          "supplier": {},
 90843          "name": "k8s.io/cli-runtime",
 90844          "version": "v0.18.8",
 90845          "purl": "pkg:golang/k8s.io/cli-runtime@v0.18.8",
 90846          "swid": {
 90847            "attachment": {}
 90848          },
 90849          "pedigree": {},
 90850          "evidence": {},
 90851          "signature": {
 90852            "signature": {
 90853              "publicKey": {}
 90854            }
 90855          },
 90856          "modelCard": {
 90857            "modelParameters": {
 90858              "approach": {}
 90859            },
 90860            "quantitativeAnalysis": {
 90861              "graphics": {}
 90862            },
 90863            "considerations": {}
 90864          }
 90865        },
 90866        {
 90867          "type": "library",
 90868          "bom-ref": "pkg:golang/k8s.io/client-go@v0.18.8?package-id=7e25bd763452932c",
 90869          "supplier": {},
 90870          "name": "k8s.io/client-go",
 90871          "version": "v0.18.8",
 90872          "purl": "pkg:golang/k8s.io/client-go@v0.18.8",
 90873          "swid": {
 90874            "attachment": {}
 90875          },
 90876          "pedigree": {},
 90877          "evidence": {},
 90878          "signature": {
 90879            "signature": {
 90880              "publicKey": {}
 90881            }
 90882          },
 90883          "modelCard": {
 90884            "modelParameters": {
 90885              "approach": {}
 90886            },
 90887            "quantitativeAnalysis": {
 90888              "graphics": {}
 90889            },
 90890            "considerations": {}
 90891          }
 90892        },
 90893        {
 90894          "type": "library",
 90895          "bom-ref": "pkg:golang/k8s.io/component-base@v0.18.8?package-id=bb2e5c0357bcfba0",
 90896          "supplier": {},
 90897          "name": "k8s.io/component-base",
 90898          "version": "v0.18.8",
 90899          "purl": "pkg:golang/k8s.io/component-base@v0.18.8",
 90900          "swid": {
 90901            "attachment": {}
 90902          },
 90903          "pedigree": {},
 90904          "evidence": {},
 90905          "signature": {
 90906            "signature": {
 90907              "publicKey": {}
 90908            }
 90909          },
 90910          "modelCard": {
 90911            "modelParameters": {
 90912              "approach": {}
 90913            },
 90914            "quantitativeAnalysis": {
 90915              "graphics": {}
 90916            },
 90917            "considerations": {}
 90918          }
 90919        },
 90920        {
 90921          "type": "library",
 90922          "bom-ref": "pkg:golang/k8s.io/klog@v1.0.0?package-id=2613f10a60c8aa02",
 90923          "supplier": {},
 90924          "name": "k8s.io/klog",
 90925          "version": "v1.0.0",
 90926          "purl": "pkg:golang/k8s.io/klog@v1.0.0",
 90927          "swid": {
 90928            "attachment": {}
 90929          },
 90930          "pedigree": {},
 90931          "evidence": {},
 90932          "signature": {
 90933            "signature": {
 90934              "publicKey": {}
 90935            }
 90936          },
 90937          "modelCard": {
 90938            "modelParameters": {
 90939              "approach": {}
 90940            },
 90941            "quantitativeAnalysis": {
 90942              "graphics": {}
 90943            },
 90944            "considerations": {}
 90945          }
 90946        },
 90947        {
 90948          "type": "library",
 90949          "bom-ref": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20200410145947-61e04a5be9a6?package-id=564031336a193a1d",
 90950          "supplier": {},
 90951          "name": "k8s.io/kube-openapi",
 90952          "version": "v0.0.0-20200410145947-61e04a5be9a6",
 90953          "purl": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20200410145947-61e04a5be9a6",
 90954          "swid": {
 90955            "attachment": {}
 90956          },
 90957          "pedigree": {},
 90958          "evidence": {},
 90959          "signature": {
 90960            "signature": {
 90961              "publicKey": {}
 90962            }
 90963          },
 90964          "modelCard": {
 90965            "modelParameters": {
 90966              "approach": {}
 90967            },
 90968            "quantitativeAnalysis": {
 90969              "graphics": {}
 90970            },
 90971            "considerations": {}
 90972          }
 90973        },
 90974        {
 90975          "type": "library",
 90976          "bom-ref": "pkg:golang/k8s.io/kubectl@v0.18.8?package-id=2a37badb4c76f7d8",
 90977          "supplier": {},
 90978          "name": "k8s.io/kubectl",
 90979          "version": "v0.18.8",
 90980          "purl": "pkg:golang/k8s.io/kubectl@v0.18.8",
 90981          "swid": {
 90982            "attachment": {}
 90983          },
 90984          "pedigree": {},
 90985          "evidence": {},
 90986          "signature": {
 90987            "signature": {
 90988              "publicKey": {}
 90989            }
 90990          },
 90991          "modelCard": {
 90992            "modelParameters": {
 90993              "approach": {}
 90994            },
 90995            "quantitativeAnalysis": {
 90996              "graphics": {}
 90997            },
 90998            "considerations": {}
 90999          }
 91000        },
 91001        {
 91002          "type": "library",
 91003          "bom-ref": "pkg:golang/k8s.io/utils@v0.0.0-20200324210504-a9aa75ae1b89?package-id=c23ec0a50a56a2cc",
 91004          "supplier": {},
 91005          "name": "k8s.io/utils",
 91006          "version": "v0.0.0-20200324210504-a9aa75ae1b89",
 91007          "purl": "pkg:golang/k8s.io/utils@v0.0.0-20200324210504-a9aa75ae1b89",
 91008          "swid": {
 91009            "attachment": {}
 91010          },
 91011          "pedigree": {},
 91012          "evidence": {},
 91013          "signature": {
 91014            "signature": {
 91015              "publicKey": {}
 91016            }
 91017          },
 91018          "modelCard": {
 91019            "modelParameters": {
 91020              "approach": {}
 91021            },
 91022            "quantitativeAnalysis": {
 91023              "graphics": {}
 91024            },
 91025            "considerations": {}
 91026          }
 91027        },
 91028        {
 91029          "type": "library",
 91030          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.12.3\u0026package-id=cf75e8a6d9cf09fc",
 91031          "supplier": {},
 91032          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91033          "name": "libc-utils",
 91034          "version": "0.7.2-r3",
 91035          "description": "Meta package to pull in correct libc",
 91036          "licenses": [
 91037            {
 91038              "license": {
 91039                "id": "BSD-2-Clause"
 91040              }
 91041            },
 91042            {
 91043              "license": {
 91044                "name": "AND"
 91045              }
 91046            },
 91047            {
 91048              "license": {
 91049                "id": "BSD-3-Clause"
 91050              }
 91051            }
 91052          ],
 91053          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
 91054          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.12.3",
 91055          "swid": {
 91056            "attachment": {}
 91057          },
 91058          "pedigree": {},
 91059          "externalReferences": [
 91060            {
 91061              "url": "https://alpinelinux.org",
 91062              "type": "distribution"
 91063            }
 91064          ],
 91065          "evidence": {},
 91066          "signature": {
 91067            "signature": {
 91068              "publicKey": {}
 91069            }
 91070          },
 91071          "modelCard": {
 91072            "modelParameters": {
 91073              "approach": {}
 91074            },
 91075            "quantitativeAnalysis": {
 91076              "graphics": {}
 91077            },
 91078            "considerations": {}
 91079          }
 91080        },
 91081        {
 91082          "type": "library",
 91083          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1i-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.12.3\u0026package-id=6271821c8b7c7c09",
 91084          "supplier": {},
 91085          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
 91086          "name": "libcrypto1.1",
 91087          "version": "1.1.1i-r0",
 91088          "description": "Crypto library from openssl",
 91089          "licenses": [
 91090            {
 91091              "license": {
 91092                "id": "OpenSSL"
 91093              }
 91094            }
 91095          ],
 91096          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1i-r0:*:*:*:*:*:*:*",
 91097          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1i-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.12.3",
 91098          "swid": {
 91099            "attachment": {}
 91100          },
 91101          "pedigree": {},
 91102          "externalReferences": [
 91103            {
 91104              "url": "https://www.openssl.org/",
 91105              "type": "distribution"
 91106            }
 91107          ],
 91108          "evidence": {},
 91109          "signature": {
 91110            "signature": {
 91111              "publicKey": {}
 91112            }
 91113          },
 91114          "modelCard": {
 91115            "modelParameters": {
 91116              "approach": {}
 91117            },
 91118            "quantitativeAnalysis": {
 91119              "graphics": {}
 91120            },
 91121            "considerations": {}
 91122          }
 91123        },
 91124        {
 91125          "type": "library",
 91126          "bom-ref": "pkg:apk/alpine/libcurl@7.69.1-r3?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.12.3\u0026package-id=6ce8e0dea97be3aa",
 91127          "supplier": {},
 91128          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91129          "name": "libcurl",
 91130          "version": "7.69.1-r3",
 91131          "description": "The multiprotocol file transfer library",
 91132          "licenses": [
 91133            {
 91134              "license": {
 91135                "id": "MIT"
 91136              }
 91137            }
 91138          ],
 91139          "cpe": "cpe:2.3:a:libcurl:libcurl:7.69.1-r3:*:*:*:*:*:*:*",
 91140          "purl": "pkg:apk/alpine/libcurl@7.69.1-r3?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.12.3",
 91141          "swid": {
 91142            "attachment": {}
 91143          },
 91144          "pedigree": {},
 91145          "externalReferences": [
 91146            {
 91147              "url": "https://curl.haxx.se/",
 91148              "type": "distribution"
 91149            }
 91150          ],
 91151          "evidence": {},
 91152          "signature": {
 91153            "signature": {
 91154              "publicKey": {}
 91155            }
 91156          },
 91157          "modelCard": {
 91158            "modelParameters": {
 91159              "approach": {}
 91160            },
 91161            "quantitativeAnalysis": {
 91162              "graphics": {}
 91163            },
 91164            "considerations": {}
 91165          }
 91166        },
 91167        {
 91168          "type": "library",
 91169          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1i-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.12.3\u0026package-id=c069963e74f2daaf",
 91170          "supplier": {},
 91171          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
 91172          "name": "libssl1.1",
 91173          "version": "1.1.1i-r0",
 91174          "description": "SSL shared libraries",
 91175          "licenses": [
 91176            {
 91177              "license": {
 91178                "id": "OpenSSL"
 91179              }
 91180            }
 91181          ],
 91182          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1i-r0:*:*:*:*:*:*:*",
 91183          "purl": "pkg:apk/alpine/libssl1.1@1.1.1i-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.12.3",
 91184          "swid": {
 91185            "attachment": {}
 91186          },
 91187          "pedigree": {},
 91188          "externalReferences": [
 91189            {
 91190              "url": "https://www.openssl.org/",
 91191              "type": "distribution"
 91192            }
 91193          ],
 91194          "evidence": {},
 91195          "signature": {
 91196            "signature": {
 91197              "publicKey": {}
 91198            }
 91199          },
 91200          "modelCard": {
 91201            "modelParameters": {
 91202              "approach": {}
 91203            },
 91204            "quantitativeAnalysis": {
 91205              "graphics": {}
 91206            },
 91207            "considerations": {}
 91208          }
 91209        },
 91210        {
 91211          "type": "library",
 91212          "bom-ref": "pkg:apk/alpine/libtls-standalone@2.9.1-r1?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=9af7ecda8019fe5b",
 91213          "supplier": {},
 91214          "name": "libtls-standalone",
 91215          "version": "2.9.1-r1",
 91216          "description": "libtls extricated from libressl sources",
 91217          "licenses": [
 91218            {
 91219              "license": {
 91220                "id": "ISC"
 91221              }
 91222            }
 91223          ],
 91224          "cpe": "cpe:2.3:a:libtls-standalone:libtls-standalone:2.9.1-r1:*:*:*:*:*:*:*",
 91225          "purl": "pkg:apk/alpine/libtls-standalone@2.9.1-r1?arch=x86_64\u0026distro=alpine-3.12.3",
 91226          "swid": {
 91227            "attachment": {}
 91228          },
 91229          "pedigree": {},
 91230          "externalReferences": [
 91231            {
 91232              "url": "https://www.libressl.org/",
 91233              "type": "distribution"
 91234            }
 91235          ],
 91236          "evidence": {},
 91237          "signature": {
 91238            "signature": {
 91239              "publicKey": {}
 91240            }
 91241          },
 91242          "modelCard": {
 91243            "modelParameters": {
 91244              "approach": {}
 91245            },
 91246            "quantitativeAnalysis": {
 91247              "graphics": {}
 91248            },
 91249            "considerations": {}
 91250          }
 91251        },
 91252        {
 91253          "type": "library",
 91254          "bom-ref": "pkg:apk/alpine/musl@1.1.24-r10?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=b175c867938729b3",
 91255          "supplier": {},
 91256          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 91257          "name": "musl",
 91258          "version": "1.1.24-r10",
 91259          "description": "the musl c library (libc) implementation",
 91260          "licenses": [
 91261            {
 91262              "license": {
 91263                "id": "MIT"
 91264              }
 91265            }
 91266          ],
 91267          "cpe": "cpe:2.3:a:musl-libc:musl:1.1.24-r10:*:*:*:*:*:*:*",
 91268          "purl": "pkg:apk/alpine/musl@1.1.24-r10?arch=x86_64\u0026distro=alpine-3.12.3",
 91269          "swid": {
 91270            "attachment": {}
 91271          },
 91272          "pedigree": {},
 91273          "externalReferences": [
 91274            {
 91275              "url": "https://musl.libc.org/",
 91276              "type": "distribution"
 91277            }
 91278          ],
 91279          "evidence": {},
 91280          "signature": {
 91281            "signature": {
 91282              "publicKey": {}
 91283            }
 91284          },
 91285          "modelCard": {
 91286            "modelParameters": {
 91287              "approach": {}
 91288            },
 91289            "quantitativeAnalysis": {
 91290              "graphics": {}
 91291            },
 91292            "considerations": {}
 91293          }
 91294        },
 91295        {
 91296          "type": "library",
 91297          "bom-ref": "pkg:apk/alpine/musl-utils@1.1.24-r10?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.12.3\u0026package-id=c72909332d6dca2b",
 91298          "supplier": {},
 91299          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 91300          "name": "musl-utils",
 91301          "version": "1.1.24-r10",
 91302          "description": "the musl c library (libc) implementation",
 91303          "licenses": [
 91304            {
 91305              "license": {
 91306                "id": "MIT"
 91307              }
 91308            },
 91309            {
 91310              "license": {
 91311                "name": "BSD"
 91312              }
 91313            },
 91314            {
 91315              "license": {
 91316                "id": "GPL-2.0-or-later"
 91317              }
 91318            }
 91319          ],
 91320          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.1.24-r10:*:*:*:*:*:*:*",
 91321          "purl": "pkg:apk/alpine/musl-utils@1.1.24-r10?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.12.3",
 91322          "swid": {
 91323            "attachment": {}
 91324          },
 91325          "pedigree": {},
 91326          "externalReferences": [
 91327            {
 91328              "url": "https://musl.libc.org/",
 91329              "type": "distribution"
 91330            }
 91331          ],
 91332          "evidence": {},
 91333          "signature": {
 91334            "signature": {
 91335              "publicKey": {}
 91336            }
 91337          },
 91338          "modelCard": {
 91339            "modelParameters": {
 91340              "approach": {}
 91341            },
 91342            "quantitativeAnalysis": {
 91343              "graphics": {}
 91344            },
 91345            "considerations": {}
 91346          }
 91347        },
 91348        {
 91349          "type": "library",
 91350          "bom-ref": "pkg:apk/alpine/ncurses-libs@6.2_p20200523-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.12.3\u0026package-id=3cee05dd78fd3a9",
 91351          "supplier": {},
 91352          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91353          "name": "ncurses-libs",
 91354          "version": "6.2_p20200523-r0",
 91355          "description": "Ncurses libraries",
 91356          "licenses": [
 91357            {
 91358              "license": {
 91359                "id": "MIT"
 91360              }
 91361            }
 91362          ],
 91363          "cpe": "cpe:2.3:a:ncurses-libs:ncurses-libs:6.2_p20200523-r0:*:*:*:*:*:*:*",
 91364          "purl": "pkg:apk/alpine/ncurses-libs@6.2_p20200523-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.12.3",
 91365          "swid": {
 91366            "attachment": {}
 91367          },
 91368          "pedigree": {},
 91369          "externalReferences": [
 91370            {
 91371              "url": "https://invisible-island.net/ncurses/",
 91372              "type": "distribution"
 91373            }
 91374          ],
 91375          "evidence": {},
 91376          "signature": {
 91377            "signature": {
 91378              "publicKey": {}
 91379            }
 91380          },
 91381          "modelCard": {
 91382            "modelParameters": {
 91383              "approach": {}
 91384            },
 91385            "quantitativeAnalysis": {
 91386              "graphics": {}
 91387            },
 91388            "considerations": {}
 91389          }
 91390        },
 91391        {
 91392          "type": "library",
 91393          "bom-ref": "pkg:apk/alpine/ncurses-terminfo-base@6.2_p20200523-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.12.3\u0026package-id=547b64a20933491c",
 91394          "supplier": {},
 91395          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91396          "name": "ncurses-terminfo-base",
 91397          "version": "6.2_p20200523-r0",
 91398          "description": "Descriptions of common terminals",
 91399          "licenses": [
 91400            {
 91401              "license": {
 91402                "id": "MIT"
 91403              }
 91404            }
 91405          ],
 91406          "cpe": "cpe:2.3:a:ncurses-terminfo-base:ncurses-terminfo-base:6.2_p20200523-r0:*:*:*:*:*:*:*",
 91407          "purl": "pkg:apk/alpine/ncurses-terminfo-base@6.2_p20200523-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.12.3",
 91408          "swid": {
 91409            "attachment": {}
 91410          },
 91411          "pedigree": {},
 91412          "externalReferences": [
 91413            {
 91414              "url": "https://invisible-island.net/ncurses/",
 91415              "type": "distribution"
 91416            }
 91417          ],
 91418          "evidence": {},
 91419          "signature": {
 91420            "signature": {
 91421              "publicKey": {}
 91422            }
 91423          },
 91424          "modelCard": {
 91425            "modelParameters": {
 91426              "approach": {}
 91427            },
 91428            "quantitativeAnalysis": {
 91429              "graphics": {}
 91430            },
 91431            "considerations": {}
 91432          }
 91433        },
 91434        {
 91435          "type": "library",
 91436          "bom-ref": "pkg:apk/alpine/nghttp2-libs@1.41.0-r0?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.12.3\u0026package-id=320f51b358072602",
 91437          "supplier": {},
 91438          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
 91439          "name": "nghttp2-libs",
 91440          "version": "1.41.0-r0",
 91441          "description": "Experimental HTTP/2 client, server and proxy (libraries)",
 91442          "licenses": [
 91443            {
 91444              "license": {
 91445                "id": "MIT"
 91446              }
 91447            }
 91448          ],
 91449          "cpe": "cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.41.0-r0:*:*:*:*:*:*:*",
 91450          "purl": "pkg:apk/alpine/nghttp2-libs@1.41.0-r0?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.12.3",
 91451          "swid": {
 91452            "attachment": {}
 91453          },
 91454          "pedigree": {},
 91455          "externalReferences": [
 91456            {
 91457              "url": "https://nghttp2.org",
 91458              "type": "distribution"
 91459            }
 91460          ],
 91461          "evidence": {},
 91462          "signature": {
 91463            "signature": {
 91464              "publicKey": {}
 91465            }
 91466          },
 91467          "modelCard": {
 91468            "modelParameters": {
 91469              "approach": {}
 91470            },
 91471            "quantitativeAnalysis": {
 91472              "graphics": {}
 91473            },
 91474            "considerations": {}
 91475          }
 91476        },
 91477        {
 91478          "type": "library",
 91479          "bom-ref": "pkg:apk/alpine/oniguruma@6.9.5-r2?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=653325f1f2f055c3",
 91480          "supplier": {},
 91481          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
 91482          "name": "oniguruma",
 91483          "version": "6.9.5-r2",
 91484          "description": "a regular expressions library",
 91485          "licenses": [
 91486            {
 91487              "license": {
 91488                "id": "BSD-2-Clause"
 91489              }
 91490            }
 91491          ],
 91492          "cpe": "cpe:2.3:a:oniguruma:oniguruma:6.9.5-r2:*:*:*:*:*:*:*",
 91493          "purl": "pkg:apk/alpine/oniguruma@6.9.5-r2?arch=x86_64\u0026distro=alpine-3.12.3",
 91494          "swid": {
 91495            "attachment": {}
 91496          },
 91497          "pedigree": {},
 91498          "externalReferences": [
 91499            {
 91500              "url": "https://github.com/kkos/oniguruma",
 91501              "type": "distribution"
 91502            }
 91503          ],
 91504          "evidence": {},
 91505          "signature": {
 91506            "signature": {
 91507              "publicKey": {}
 91508            }
 91509          },
 91510          "modelCard": {
 91511            "modelParameters": {
 91512              "approach": {}
 91513            },
 91514            "quantitativeAnalysis": {
 91515              "graphics": {}
 91516            },
 91517            "considerations": {}
 91518          }
 91519        },
 91520        {
 91521          "type": "library",
 91522          "bom-ref": "pkg:apk/alpine/pcre2@10.35-r0?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=b6ee8aeafd6e35c1",
 91523          "supplier": {},
 91524          "publisher": "Jakub Jirutka \u003cjakub@jirutka.cz\u003e",
 91525          "name": "pcre2",
 91526          "version": "10.35-r0",
 91527          "description": "Perl-compatible regular expression library",
 91528          "licenses": [
 91529            {
 91530              "license": {
 91531                "id": "BSD-3-Clause"
 91532              }
 91533            }
 91534          ],
 91535          "cpe": "cpe:2.3:a:pcre2:pcre2:10.35-r0:*:*:*:*:*:*:*",
 91536          "purl": "pkg:apk/alpine/pcre2@10.35-r0?arch=x86_64\u0026distro=alpine-3.12.3",
 91537          "swid": {
 91538            "attachment": {}
 91539          },
 91540          "pedigree": {},
 91541          "externalReferences": [
 91542            {
 91543              "url": "https://pcre.org/",
 91544              "type": "distribution"
 91545            }
 91546          ],
 91547          "evidence": {},
 91548          "signature": {
 91549            "signature": {
 91550              "publicKey": {}
 91551            }
 91552          },
 91553          "modelCard": {
 91554            "modelParameters": {
 91555              "approach": {}
 91556            },
 91557            "quantitativeAnalysis": {
 91558              "graphics": {}
 91559            },
 91560            "considerations": {}
 91561          }
 91562        },
 91563        {
 91564          "type": "library",
 91565          "bom-ref": "pkg:apk/alpine/readline@8.0.4-r0?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=e9edfd215d1e9b8a",
 91566          "supplier": {},
 91567          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91568          "name": "readline",
 91569          "version": "8.0.4-r0",
 91570          "description": "GNU readline library",
 91571          "licenses": [
 91572            {
 91573              "license": {
 91574                "id": "GPL-2.0-or-later"
 91575              }
 91576            }
 91577          ],
 91578          "cpe": "cpe:2.3:a:readline:readline:8.0.4-r0:*:*:*:*:*:*:*",
 91579          "purl": "pkg:apk/alpine/readline@8.0.4-r0?arch=x86_64\u0026distro=alpine-3.12.3",
 91580          "swid": {
 91581            "attachment": {}
 91582          },
 91583          "pedigree": {},
 91584          "externalReferences": [
 91585            {
 91586              "url": "https://tiswww.cwru.edu/php/chet/readline/rltop.html",
 91587              "type": "distribution"
 91588            }
 91589          ],
 91590          "evidence": {},
 91591          "signature": {
 91592            "signature": {
 91593              "publicKey": {}
 91594            }
 91595          },
 91596          "modelCard": {
 91597            "modelParameters": {
 91598              "approach": {}
 91599            },
 91600            "quantitativeAnalysis": {
 91601              "graphics": {}
 91602            },
 91603            "considerations": {}
 91604          }
 91605        },
 91606        {
 91607          "type": "library",
 91608          "bom-ref": "pkg:apk/alpine/scanelf@1.2.6-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.12.3\u0026package-id=6bb4b607de5648aa",
 91609          "supplier": {},
 91610          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91611          "name": "scanelf",
 91612          "version": "1.2.6-r0",
 91613          "description": "Scan ELF binaries for stuff",
 91614          "licenses": [
 91615            {
 91616              "license": {
 91617                "id": "GPL-2.0-only"
 91618              }
 91619            }
 91620          ],
 91621          "cpe": "cpe:2.3:a:scanelf:scanelf:1.2.6-r0:*:*:*:*:*:*:*",
 91622          "purl": "pkg:apk/alpine/scanelf@1.2.6-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.12.3",
 91623          "swid": {
 91624            "attachment": {}
 91625          },
 91626          "pedigree": {},
 91627          "externalReferences": [
 91628            {
 91629              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
 91630              "type": "distribution"
 91631            }
 91632          ],
 91633          "evidence": {},
 91634          "signature": {
 91635            "signature": {
 91636              "publicKey": {}
 91637            }
 91638          },
 91639          "modelCard": {
 91640            "modelParameters": {
 91641              "approach": {}
 91642            },
 91643            "quantitativeAnalysis": {
 91644              "graphics": {}
 91645            },
 91646            "considerations": {}
 91647          }
 91648        },
 91649        {
 91650          "type": "library",
 91651          "bom-ref": "pkg:golang/sigs.k8s.io/kustomize@v2.0.3+incompatible?package-id=5e86a13cfd22449c",
 91652          "supplier": {},
 91653          "name": "sigs.k8s.io/kustomize",
 91654          "version": "v2.0.3+incompatible",
 91655          "purl": "pkg:golang/sigs.k8s.io/kustomize@v2.0.3+incompatible",
 91656          "swid": {
 91657            "attachment": {}
 91658          },
 91659          "pedigree": {},
 91660          "evidence": {},
 91661          "signature": {
 91662            "signature": {
 91663              "publicKey": {}
 91664            }
 91665          },
 91666          "modelCard": {
 91667            "modelParameters": {
 91668              "approach": {}
 91669            },
 91670            "quantitativeAnalysis": {
 91671              "graphics": {}
 91672            },
 91673            "considerations": {}
 91674          }
 91675        },
 91676        {
 91677          "type": "library",
 91678          "bom-ref": "pkg:golang/sigs.k8s.io/structured-merge-diff/v3@v3.0.0?package-id=7f68668ec95d7d9f",
 91679          "supplier": {},
 91680          "name": "sigs.k8s.io/structured-merge-diff/v3",
 91681          "version": "v3.0.0",
 91682          "cpe": "cpe:2.3:a:structured-merge-diff:v3:v3.0.0:*:*:*:*:*:*:*",
 91683          "purl": "pkg:golang/sigs.k8s.io/structured-merge-diff/v3@v3.0.0",
 91684          "swid": {
 91685            "attachment": {}
 91686          },
 91687          "pedigree": {},
 91688          "evidence": {},
 91689          "signature": {
 91690            "signature": {
 91691              "publicKey": {}
 91692            }
 91693          },
 91694          "modelCard": {
 91695            "modelParameters": {
 91696              "approach": {}
 91697            },
 91698            "quantitativeAnalysis": {
 91699              "graphics": {}
 91700            },
 91701            "considerations": {}
 91702          }
 91703        },
 91704        {
 91705          "type": "library",
 91706          "bom-ref": "pkg:golang/sigs.k8s.io/yaml@v1.2.0?package-id=15e61f12fee92a76",
 91707          "supplier": {},
 91708          "name": "sigs.k8s.io/yaml",
 91709          "version": "v1.2.0",
 91710          "purl": "pkg:golang/sigs.k8s.io/yaml@v1.2.0",
 91711          "swid": {
 91712            "attachment": {}
 91713          },
 91714          "pedigree": {},
 91715          "evidence": {},
 91716          "signature": {
 91717            "signature": {
 91718              "publicKey": {}
 91719            }
 91720          },
 91721          "modelCard": {
 91722            "modelParameters": {
 91723              "approach": {}
 91724            },
 91725            "quantitativeAnalysis": {
 91726              "graphics": {}
 91727            },
 91728            "considerations": {}
 91729          }
 91730        },
 91731        {
 91732          "type": "library",
 91733          "bom-ref": "pkg:apk/alpine/ssl_client@1.31.1-r19?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.12.3\u0026package-id=4c890ecde6fd366f",
 91734          "supplier": {},
 91735          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91736          "name": "ssl_client",
 91737          "version": "1.31.1-r19",
 91738          "description": "EXternal ssl_client for busybox wget",
 91739          "licenses": [
 91740            {
 91741              "license": {
 91742                "id": "GPL-2.0-only"
 91743              }
 91744            }
 91745          ],
 91746          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.31.1-r19:*:*:*:*:*:*:*",
 91747          "purl": "pkg:apk/alpine/ssl_client@1.31.1-r19?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.12.3",
 91748          "swid": {
 91749            "attachment": {}
 91750          },
 91751          "pedigree": {},
 91752          "externalReferences": [
 91753            {
 91754              "url": "https://busybox.net/",
 91755              "type": "distribution"
 91756            }
 91757          ],
 91758          "evidence": {},
 91759          "signature": {
 91760            "signature": {
 91761              "publicKey": {}
 91762            }
 91763          },
 91764          "modelCard": {
 91765            "modelParameters": {
 91766              "approach": {}
 91767            },
 91768            "quantitativeAnalysis": {
 91769              "graphics": {}
 91770            },
 91771            "considerations": {}
 91772          }
 91773        },
 91774        {
 91775          "type": "library",
 91776          "bom-ref": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.12.3\u0026package-id=e5b843eacba99f13",
 91777          "supplier": {},
 91778          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91779          "name": "zlib",
 91780          "version": "1.2.11-r3",
 91781          "description": "A compression/decompression Library",
 91782          "licenses": [
 91783            {
 91784              "license": {
 91785                "id": "Zlib"
 91786              }
 91787            }
 91788          ],
 91789          "cpe": "cpe:2.3:a:zlib:zlib:1.2.11-r3:*:*:*:*:*:*:*",
 91790          "purl": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.12.3",
 91791          "swid": {
 91792            "attachment": {}
 91793          },
 91794          "pedigree": {},
 91795          "externalReferences": [
 91796            {
 91797              "url": "https://zlib.net/",
 91798              "type": "distribution"
 91799            }
 91800          ],
 91801          "evidence": {},
 91802          "signature": {
 91803            "signature": {
 91804              "publicKey": {}
 91805            }
 91806          },
 91807          "modelCard": {
 91808            "modelParameters": {
 91809              "approach": {}
 91810            },
 91811            "quantitativeAnalysis": {
 91812              "graphics": {}
 91813            },
 91814            "considerations": {}
 91815          }
 91816        },
 91817        {
 91818          "type": "operating-system",
 91819          "supplier": {},
 91820          "name": "alpine",
 91821          "version": "3.12.3",
 91822          "description": "Alpine Linux v3.12",
 91823          "swid": {
 91824            "tagId": "alpine",
 91825            "name": "alpine",
 91826            "version": "3.12.3",
 91827            "attachment": {}
 91828          },
 91829          "pedigree": {},
 91830          "externalReferences": [
 91831            {
 91832              "url": "https://bugs.alpinelinux.org/",
 91833              "type": "issue-tracker"
 91834            },
 91835            {
 91836              "url": "https://alpinelinux.org/",
 91837              "type": "website"
 91838            }
 91839          ],
 91840          "evidence": {},
 91841          "signature": {
 91842            "signature": {
 91843              "publicKey": {}
 91844            }
 91845          },
 91846          "modelCard": {
 91847            "modelParameters": {
 91848              "approach": {}
 91849            },
 91850            "quantitativeAnalysis": {
 91851              "graphics": {}
 91852            },
 91853            "considerations": {}
 91854          }
 91855        },
 91856        {
 91857          "type": "library",
 91858          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r8?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=c5e44a14019195cd",
 91859          "supplier": {},
 91860          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91861          "name": "alpine-baselayout",
 91862          "version": "3.2.0-r8",
 91863          "description": "Alpine base dir structure and init scripts",
 91864          "licenses": [
 91865            {
 91866              "license": {
 91867                "id": "GPL-2.0-only"
 91868              }
 91869            }
 91870          ],
 91871          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r8:*:*:*:*:*:*:*",
 91872          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r8?arch=x86_64\u0026distro=alpine-3.13.5",
 91873          "swid": {
 91874            "attachment": {}
 91875          },
 91876          "pedigree": {},
 91877          "externalReferences": [
 91878            {
 91879              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 91880              "type": "distribution"
 91881            }
 91882          ],
 91883          "evidence": {},
 91884          "signature": {
 91885            "signature": {
 91886              "publicKey": {}
 91887            }
 91888          },
 91889          "modelCard": {
 91890            "modelParameters": {
 91891              "approach": {}
 91892            },
 91893            "quantitativeAnalysis": {
 91894              "graphics": {}
 91895            },
 91896            "considerations": {}
 91897          }
 91898        },
 91899        {
 91900          "type": "library",
 91901          "bom-ref": "pkg:apk/alpine/alpine-keys@2.2-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=aadfc7a0590baa16",
 91902          "supplier": {},
 91903          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91904          "name": "alpine-keys",
 91905          "version": "2.2-r0",
 91906          "description": "Public keys for Alpine Linux packages",
 91907          "licenses": [
 91908            {
 91909              "license": {
 91910                "id": "MIT"
 91911              }
 91912            }
 91913          ],
 91914          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.2-r0:*:*:*:*:*:*:*",
 91915          "purl": "pkg:apk/alpine/alpine-keys@2.2-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 91916          "swid": {
 91917            "attachment": {}
 91918          },
 91919          "pedigree": {},
 91920          "externalReferences": [
 91921            {
 91922              "url": "https://alpinelinux.org",
 91923              "type": "distribution"
 91924            }
 91925          ],
 91926          "evidence": {},
 91927          "signature": {
 91928            "signature": {
 91929              "publicKey": {}
 91930            }
 91931          },
 91932          "modelCard": {
 91933            "modelParameters": {
 91934              "approach": {}
 91935            },
 91936            "quantitativeAnalysis": {
 91937              "graphics": {}
 91938            },
 91939            "considerations": {}
 91940          }
 91941        },
 91942        {
 91943          "type": "library",
 91944          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.5-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=e7f0e3239fffe6f9",
 91945          "supplier": {},
 91946          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91947          "name": "apk-tools",
 91948          "version": "2.12.5-r0",
 91949          "description": "Alpine Package Keeper - package manager for alpine",
 91950          "licenses": [
 91951            {
 91952              "license": {
 91953                "id": "GPL-2.0-only"
 91954              }
 91955            }
 91956          ],
 91957          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.5-r0:*:*:*:*:*:*:*",
 91958          "purl": "pkg:apk/alpine/apk-tools@2.12.5-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 91959          "swid": {
 91960            "attachment": {}
 91961          },
 91962          "pedigree": {},
 91963          "externalReferences": [
 91964            {
 91965              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
 91966              "type": "distribution"
 91967            }
 91968          ],
 91969          "evidence": {},
 91970          "signature": {
 91971            "signature": {
 91972              "publicKey": {}
 91973            }
 91974          },
 91975          "modelCard": {
 91976            "modelParameters": {
 91977              "approach": {}
 91978            },
 91979            "quantitativeAnalysis": {
 91980              "graphics": {}
 91981            },
 91982            "considerations": {}
 91983          }
 91984        },
 91985        {
 91986          "type": "library",
 91987          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.7-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=81ec58d624db5659",
 91988          "supplier": {},
 91989          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 91990          "name": "apk-tools",
 91991          "version": "2.12.7-r0",
 91992          "description": "Alpine Package Keeper - package manager for alpine",
 91993          "licenses": [
 91994            {
 91995              "license": {
 91996                "id": "GPL-2.0-only"
 91997              }
 91998            }
 91999          ],
 92000          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.7-r0:*:*:*:*:*:*:*",
 92001          "purl": "pkg:apk/alpine/apk-tools@2.12.7-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 92002          "swid": {
 92003            "attachment": {}
 92004          },
 92005          "pedigree": {},
 92006          "externalReferences": [
 92007            {
 92008              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
 92009              "type": "distribution"
 92010            }
 92011          ],
 92012          "evidence": {},
 92013          "signature": {
 92014            "signature": {
 92015              "publicKey": {}
 92016            }
 92017          },
 92018          "modelCard": {
 92019            "modelParameters": {
 92020              "approach": {}
 92021            },
 92022            "quantitativeAnalysis": {
 92023              "graphics": {}
 92024            },
 92025            "considerations": {}
 92026          }
 92027        },
 92028        {
 92029          "type": "library",
 92030          "bom-ref": "pkg:apk/alpine/bash@5.1.0-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=c8f196fb75899b15",
 92031          "supplier": {},
 92032          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92033          "name": "bash",
 92034          "version": "5.1.0-r0",
 92035          "description": "The GNU Bourne Again shell",
 92036          "licenses": [
 92037            {
 92038              "license": {
 92039                "id": "GPL-3.0-or-later"
 92040              }
 92041            }
 92042          ],
 92043          "cpe": "cpe:2.3:a:bash:bash:5.1.0-r0:*:*:*:*:*:*:*",
 92044          "purl": "pkg:apk/alpine/bash@5.1.0-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 92045          "swid": {
 92046            "attachment": {}
 92047          },
 92048          "pedigree": {},
 92049          "externalReferences": [
 92050            {
 92051              "url": "https://www.gnu.org/software/bash/bash.html",
 92052              "type": "distribution"
 92053            }
 92054          ],
 92055          "evidence": {},
 92056          "signature": {
 92057            "signature": {
 92058              "publicKey": {}
 92059            }
 92060          },
 92061          "modelCard": {
 92062            "modelParameters": {
 92063              "approach": {}
 92064            },
 92065            "quantitativeAnalysis": {
 92066              "graphics": {}
 92067            },
 92068            "considerations": {}
 92069          }
 92070        },
 92071        {
 92072          "type": "library",
 92073          "bom-ref": "pkg:apk/alpine/brotli-libs@1.0.9-r3?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.13.5\u0026package-id=f8b723be9d28adf0",
 92074          "supplier": {},
 92075          "publisher": "prspkt \u003cprspkt@protonmail.com\u003e",
 92076          "name": "brotli-libs",
 92077          "version": "1.0.9-r3",
 92078          "description": "Generic lossless compressor (libraries)",
 92079          "licenses": [
 92080            {
 92081              "license": {
 92082                "id": "MIT"
 92083              }
 92084            }
 92085          ],
 92086          "cpe": "cpe:2.3:a:brotli-libs:brotli-libs:1.0.9-r3:*:*:*:*:*:*:*",
 92087          "purl": "pkg:apk/alpine/brotli-libs@1.0.9-r3?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.13.5",
 92088          "swid": {
 92089            "attachment": {}
 92090          },
 92091          "pedigree": {},
 92092          "externalReferences": [
 92093            {
 92094              "url": "https://github.com/google/brotli",
 92095              "type": "distribution"
 92096            }
 92097          ],
 92098          "evidence": {},
 92099          "signature": {
 92100            "signature": {
 92101              "publicKey": {}
 92102            }
 92103          },
 92104          "modelCard": {
 92105            "modelParameters": {
 92106              "approach": {}
 92107            },
 92108            "quantitativeAnalysis": {
 92109              "graphics": {}
 92110            },
 92111            "considerations": {}
 92112          }
 92113        },
 92114        {
 92115          "type": "application",
 92116          "bom-ref": "6049906247657ef3",
 92117          "supplier": {},
 92118          "name": "busybox",
 92119          "version": "1.32.1",
 92120          "cpe": "cpe:2.3:a:busybox:busybox:1.32.1:*:*:*:*:*:*:*",
 92121          "swid": {
 92122            "attachment": {}
 92123          },
 92124          "pedigree": {},
 92125          "evidence": {},
 92126          "signature": {
 92127            "signature": {
 92128              "publicKey": {}
 92129            }
 92130          },
 92131          "modelCard": {
 92132            "modelParameters": {
 92133              "approach": {}
 92134            },
 92135            "quantitativeAnalysis": {
 92136              "graphics": {}
 92137            },
 92138            "considerations": {}
 92139          }
 92140        },
 92141        {
 92142          "type": "library",
 92143          "bom-ref": "pkg:apk/alpine/busybox@1.32.1-r6?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=84555abe7eb6a0e6",
 92144          "supplier": {},
 92145          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92146          "name": "busybox",
 92147          "version": "1.32.1-r6",
 92148          "description": "Size optimized toolbox of many common UNIX utilities",
 92149          "licenses": [
 92150            {
 92151              "license": {
 92152                "id": "GPL-2.0-only"
 92153              }
 92154            }
 92155          ],
 92156          "cpe": "cpe:2.3:a:busybox:busybox:1.32.1-r6:*:*:*:*:*:*:*",
 92157          "purl": "pkg:apk/alpine/busybox@1.32.1-r6?arch=x86_64\u0026distro=alpine-3.13.5",
 92158          "swid": {
 92159            "attachment": {}
 92160          },
 92161          "pedigree": {},
 92162          "externalReferences": [
 92163            {
 92164              "url": "https://busybox.net/",
 92165              "type": "distribution"
 92166            }
 92167          ],
 92168          "evidence": {},
 92169          "signature": {
 92170            "signature": {
 92171              "publicKey": {}
 92172            }
 92173          },
 92174          "modelCard": {
 92175            "modelParameters": {
 92176              "approach": {}
 92177            },
 92178            "quantitativeAnalysis": {
 92179              "graphics": {}
 92180            },
 92181            "considerations": {}
 92182          }
 92183        },
 92184        {
 92185          "type": "library",
 92186          "bom-ref": "pkg:apk/alpine/ca-certificates@20191127-r5?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=afdd3bf86bcfaf05",
 92187          "supplier": {},
 92188          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92189          "name": "ca-certificates",
 92190          "version": "20191127-r5",
 92191          "description": "Common CA certificates PEM files from Mozilla",
 92192          "licenses": [
 92193            {
 92194              "license": {
 92195                "id": "MPL-2.0"
 92196              }
 92197            },
 92198            {
 92199              "license": {
 92200                "name": "AND"
 92201              }
 92202            },
 92203            {
 92204              "license": {
 92205                "id": "MIT"
 92206              }
 92207            }
 92208          ],
 92209          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20191127-r5:*:*:*:*:*:*:*",
 92210          "purl": "pkg:apk/alpine/ca-certificates@20191127-r5?arch=x86_64\u0026distro=alpine-3.13.5",
 92211          "swid": {
 92212            "attachment": {}
 92213          },
 92214          "pedigree": {},
 92215          "externalReferences": [
 92216            {
 92217              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
 92218              "type": "distribution"
 92219            }
 92220          ],
 92221          "evidence": {},
 92222          "signature": {
 92223            "signature": {
 92224              "publicKey": {}
 92225            }
 92226          },
 92227          "modelCard": {
 92228            "modelParameters": {
 92229              "approach": {}
 92230            },
 92231            "quantitativeAnalysis": {
 92232              "graphics": {}
 92233            },
 92234            "considerations": {}
 92235          }
 92236        },
 92237        {
 92238          "type": "library",
 92239          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20191127-r5?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.13.5\u0026package-id=4ae90c75dcbc0a45",
 92240          "supplier": {},
 92241          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92242          "name": "ca-certificates-bundle",
 92243          "version": "20191127-r5",
 92244          "description": "Pre generated bundle of Mozilla certificates",
 92245          "licenses": [
 92246            {
 92247              "license": {
 92248                "id": "MPL-2.0"
 92249              }
 92250            },
 92251            {
 92252              "license": {
 92253                "name": "AND"
 92254              }
 92255            },
 92256            {
 92257              "license": {
 92258                "id": "MIT"
 92259              }
 92260            }
 92261          ],
 92262          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20191127-r5:*:*:*:*:*:*:*",
 92263          "purl": "pkg:apk/alpine/ca-certificates-bundle@20191127-r5?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.13.5",
 92264          "swid": {
 92265            "attachment": {}
 92266          },
 92267          "pedigree": {},
 92268          "externalReferences": [
 92269            {
 92270              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
 92271              "type": "distribution"
 92272            }
 92273          ],
 92274          "evidence": {},
 92275          "signature": {
 92276            "signature": {
 92277              "publicKey": {}
 92278            }
 92279          },
 92280          "modelCard": {
 92281            "modelParameters": {
 92282              "approach": {}
 92283            },
 92284            "quantitativeAnalysis": {
 92285              "graphics": {}
 92286            },
 92287            "considerations": {}
 92288          }
 92289        },
 92290        {
 92291          "type": "library",
 92292          "bom-ref": "pkg:apk/alpine/curl@7.76.1-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=594f8252b125e54b",
 92293          "supplier": {},
 92294          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92295          "name": "curl",
 92296          "version": "7.76.1-r0",
 92297          "description": "URL retrival utility and library",
 92298          "licenses": [
 92299            {
 92300              "license": {
 92301                "id": "MIT"
 92302              }
 92303            }
 92304          ],
 92305          "cpe": "cpe:2.3:a:curl:curl:7.76.1-r0:*:*:*:*:*:*:*",
 92306          "purl": "pkg:apk/alpine/curl@7.76.1-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 92307          "swid": {
 92308            "attachment": {}
 92309          },
 92310          "pedigree": {},
 92311          "externalReferences": [
 92312            {
 92313              "url": "https://curl.se/",
 92314              "type": "distribution"
 92315            }
 92316          ],
 92317          "evidence": {},
 92318          "signature": {
 92319            "signature": {
 92320              "publicKey": {}
 92321            }
 92322          },
 92323          "modelCard": {
 92324            "modelParameters": {
 92325              "approach": {}
 92326            },
 92327            "quantitativeAnalysis": {
 92328              "graphics": {}
 92329            },
 92330            "considerations": {}
 92331          }
 92332        },
 92333        {
 92334          "type": "library",
 92335          "bom-ref": "pkg:apk/alpine/curl@7.78.0-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=6bc80f31aae45fed",
 92336          "supplier": {},
 92337          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92338          "name": "curl",
 92339          "version": "7.78.0-r0",
 92340          "description": "URL retrival utility and library",
 92341          "licenses": [
 92342            {
 92343              "license": {
 92344                "id": "MIT"
 92345              }
 92346            }
 92347          ],
 92348          "cpe": "cpe:2.3:a:curl:curl:7.78.0-r0:*:*:*:*:*:*:*",
 92349          "purl": "pkg:apk/alpine/curl@7.78.0-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 92350          "swid": {
 92351            "attachment": {}
 92352          },
 92353          "pedigree": {},
 92354          "externalReferences": [
 92355            {
 92356              "url": "https://curl.se/",
 92357              "type": "distribution"
 92358            }
 92359          ],
 92360          "evidence": {},
 92361          "signature": {
 92362            "signature": {
 92363              "publicKey": {}
 92364            }
 92365          },
 92366          "modelCard": {
 92367            "modelParameters": {
 92368              "approach": {}
 92369            },
 92370            "quantitativeAnalysis": {
 92371              "graphics": {}
 92372            },
 92373            "considerations": {}
 92374          }
 92375        },
 92376        {
 92377          "type": "library",
 92378          "bom-ref": "pkg:apk/alpine/freetype@2.10.4-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=ef1c7a11954e1490",
 92379          "supplier": {},
 92380          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 92381          "name": "freetype",
 92382          "version": "2.10.4-r1",
 92383          "description": "TrueType font rendering library",
 92384          "licenses": [
 92385            {
 92386              "license": {
 92387                "id": "FTL"
 92388              }
 92389            },
 92390            {
 92391              "license": {
 92392                "id": "GPL-2.0-or-later"
 92393              }
 92394            }
 92395          ],
 92396          "cpe": "cpe:2.3:a:freetype:freetype:2.10.4-r1:*:*:*:*:*:*:*",
 92397          "purl": "pkg:apk/alpine/freetype@2.10.4-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 92398          "swid": {
 92399            "attachment": {}
 92400          },
 92401          "pedigree": {},
 92402          "externalReferences": [
 92403            {
 92404              "url": "https://www.freetype.org/",
 92405              "type": "distribution"
 92406            }
 92407          ],
 92408          "evidence": {},
 92409          "signature": {
 92410            "signature": {
 92411              "publicKey": {}
 92412            }
 92413          },
 92414          "modelCard": {
 92415            "modelParameters": {
 92416              "approach": {}
 92417            },
 92418            "quantitativeAnalysis": {
 92419              "graphics": {}
 92420            },
 92421            "considerations": {}
 92422          }
 92423        },
 92424        {
 92425          "type": "library",
 92426          "bom-ref": "pkg:apk/alpine/geoip@1.6.12-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=b5366200f228bcce",
 92427          "supplier": {},
 92428          "publisher": "Leonardo Arena \u003crnalrd@alpinelinux.org\u003e",
 92429          "name": "geoip",
 92430          "version": "1.6.12-r1",
 92431          "description": "Lookup countries by IP addresses",
 92432          "licenses": [
 92433            {
 92434              "license": {
 92435                "name": "GPL"
 92436              }
 92437            }
 92438          ],
 92439          "cpe": "cpe:2.3:a:geoip:geoip:1.6.12-r1:*:*:*:*:*:*:*",
 92440          "purl": "pkg:apk/alpine/geoip@1.6.12-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 92441          "swid": {
 92442            "attachment": {}
 92443          },
 92444          "pedigree": {},
 92445          "externalReferences": [
 92446            {
 92447              "url": "http://www.maxmind.com/app/ip-location",
 92448              "type": "distribution"
 92449            }
 92450          ],
 92451          "evidence": {},
 92452          "signature": {
 92453            "signature": {
 92454              "publicKey": {}
 92455            }
 92456          },
 92457          "modelCard": {
 92458            "modelParameters": {
 92459              "approach": {}
 92460            },
 92461            "quantitativeAnalysis": {
 92462              "graphics": {}
 92463            },
 92464            "considerations": {}
 92465          }
 92466        },
 92467        {
 92468          "type": "library",
 92469          "bom-ref": "pkg:apk/alpine/gettext@0.20.2-r2?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=5ea95df7371cfb98",
 92470          "supplier": {},
 92471          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 92472          "name": "gettext",
 92473          "version": "0.20.2-r2",
 92474          "description": "GNU locale utilities",
 92475          "licenses": [
 92476            {
 92477              "license": {
 92478                "id": "GPL-3.0-or-later"
 92479              }
 92480            },
 92481            {
 92482              "license": {
 92483                "name": "AND"
 92484              }
 92485            },
 92486            {
 92487              "license": {
 92488                "id": "LGPL-2.1-or-later"
 92489              }
 92490            },
 92491            {
 92492              "license": {
 92493                "name": "AND"
 92494              }
 92495            },
 92496            {
 92497              "license": {
 92498                "id": "MIT"
 92499              }
 92500            }
 92501          ],
 92502          "cpe": "cpe:2.3:a:gettext:gettext:0.20.2-r2:*:*:*:*:*:*:*",
 92503          "purl": "pkg:apk/alpine/gettext@0.20.2-r2?arch=x86_64\u0026distro=alpine-3.13.5",
 92504          "swid": {
 92505            "attachment": {}
 92506          },
 92507          "pedigree": {},
 92508          "externalReferences": [
 92509            {
 92510              "url": "https://www.gnu.org/software/gettext/gettext.html",
 92511              "type": "distribution"
 92512            }
 92513          ],
 92514          "evidence": {},
 92515          "signature": {
 92516            "signature": {
 92517              "publicKey": {}
 92518            }
 92519          },
 92520          "modelCard": {
 92521            "modelParameters": {
 92522              "approach": {}
 92523            },
 92524            "quantitativeAnalysis": {
 92525              "graphics": {}
 92526            },
 92527            "considerations": {}
 92528          }
 92529        },
 92530        {
 92531          "type": "library",
 92532          "bom-ref": "pkg:apk/alpine/gettext-libs@0.20.2-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.13.5\u0026package-id=13207aee5960055b",
 92533          "supplier": {},
 92534          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 92535          "name": "gettext-libs",
 92536          "version": "0.20.2-r2",
 92537          "description": "GNU locale utilities (libraries)",
 92538          "licenses": [
 92539            {
 92540              "license": {
 92541                "id": "GPL-3.0-or-later"
 92542              }
 92543            },
 92544            {
 92545              "license": {
 92546                "name": "AND"
 92547              }
 92548            },
 92549            {
 92550              "license": {
 92551                "id": "LGPL-2.1-or-later"
 92552              }
 92553            },
 92554            {
 92555              "license": {
 92556                "name": "AND"
 92557              }
 92558            },
 92559            {
 92560              "license": {
 92561                "id": "MIT"
 92562              }
 92563            }
 92564          ],
 92565          "cpe": "cpe:2.3:a:gettext-libs:gettext-libs:0.20.2-r2:*:*:*:*:*:*:*",
 92566          "purl": "pkg:apk/alpine/gettext-libs@0.20.2-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.13.5",
 92567          "swid": {
 92568            "attachment": {}
 92569          },
 92570          "pedigree": {},
 92571          "externalReferences": [
 92572            {
 92573              "url": "https://www.gnu.org/software/gettext/gettext.html",
 92574              "type": "distribution"
 92575            }
 92576          ],
 92577          "evidence": {},
 92578          "signature": {
 92579            "signature": {
 92580              "publicKey": {}
 92581            }
 92582          },
 92583          "modelCard": {
 92584            "modelParameters": {
 92585              "approach": {}
 92586            },
 92587            "quantitativeAnalysis": {
 92588              "graphics": {}
 92589            },
 92590            "considerations": {}
 92591          }
 92592        },
 92593        {
 92594          "type": "library",
 92595          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.13.5\u0026package-id=bc796917d10753a0",
 92596          "supplier": {},
 92597          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92598          "name": "libbz2",
 92599          "version": "1.0.8-r1",
 92600          "description": "Shared library for bz2",
 92601          "licenses": [
 92602            {
 92603              "license": {
 92604                "id": "bzip2-1.0.6"
 92605              }
 92606            }
 92607          ],
 92608          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r1:*:*:*:*:*:*:*",
 92609          "purl": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.13.5",
 92610          "swid": {
 92611            "attachment": {}
 92612          },
 92613          "pedigree": {},
 92614          "externalReferences": [
 92615            {
 92616              "url": "http://sources.redhat.com/bzip2",
 92617              "type": "distribution"
 92618            }
 92619          ],
 92620          "evidence": {},
 92621          "signature": {
 92622            "signature": {
 92623              "publicKey": {}
 92624            }
 92625          },
 92626          "modelCard": {
 92627            "modelParameters": {
 92628              "approach": {}
 92629            },
 92630            "quantitativeAnalysis": {
 92631              "graphics": {}
 92632            },
 92633            "considerations": {}
 92634          }
 92635        },
 92636        {
 92637          "type": "library",
 92638          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.13.5\u0026package-id=53ae97b3879b4d06",
 92639          "supplier": {},
 92640          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92641          "name": "libc-utils",
 92642          "version": "0.7.2-r3",
 92643          "description": "Meta package to pull in correct libc",
 92644          "licenses": [
 92645            {
 92646              "license": {
 92647                "id": "BSD-2-Clause"
 92648              }
 92649            },
 92650            {
 92651              "license": {
 92652                "name": "AND"
 92653              }
 92654            },
 92655            {
 92656              "license": {
 92657                "id": "BSD-3-Clause"
 92658              }
 92659            }
 92660          ],
 92661          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
 92662          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.13.5",
 92663          "swid": {
 92664            "attachment": {}
 92665          },
 92666          "pedigree": {},
 92667          "externalReferences": [
 92668            {
 92669              "url": "https://alpinelinux.org",
 92670              "type": "distribution"
 92671            }
 92672          ],
 92673          "evidence": {},
 92674          "signature": {
 92675            "signature": {
 92676              "publicKey": {}
 92677            }
 92678          },
 92679          "modelCard": {
 92680            "modelParameters": {
 92681              "approach": {}
 92682            },
 92683            "quantitativeAnalysis": {
 92684              "graphics": {}
 92685            },
 92686            "considerations": {}
 92687          }
 92688        },
 92689        {
 92690          "type": "library",
 92691          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1k-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.13.5\u0026package-id=37f45c75d121652e",
 92692          "supplier": {},
 92693          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
 92694          "name": "libcrypto1.1",
 92695          "version": "1.1.1k-r0",
 92696          "description": "Crypto library from openssl",
 92697          "licenses": [
 92698            {
 92699              "license": {
 92700                "id": "OpenSSL"
 92701              }
 92702            }
 92703          ],
 92704          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1k-r0:*:*:*:*:*:*:*",
 92705          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1k-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.13.5",
 92706          "swid": {
 92707            "attachment": {}
 92708          },
 92709          "pedigree": {},
 92710          "externalReferences": [
 92711            {
 92712              "url": "https://www.openssl.org/",
 92713              "type": "distribution"
 92714            }
 92715          ],
 92716          "evidence": {},
 92717          "signature": {
 92718            "signature": {
 92719              "publicKey": {}
 92720            }
 92721          },
 92722          "modelCard": {
 92723            "modelParameters": {
 92724              "approach": {}
 92725            },
 92726            "quantitativeAnalysis": {
 92727              "graphics": {}
 92728            },
 92729            "considerations": {}
 92730          }
 92731        },
 92732        {
 92733          "type": "library",
 92734          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.13.5\u0026package-id=b051a1265f1942a",
 92735          "supplier": {},
 92736          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
 92737          "name": "libcrypto1.1",
 92738          "version": "1.1.1l-r0",
 92739          "description": "Crypto library from openssl",
 92740          "licenses": [
 92741            {
 92742              "license": {
 92743                "id": "OpenSSL"
 92744              }
 92745            }
 92746          ],
 92747          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1l-r0:*:*:*:*:*:*:*",
 92748          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.13.5",
 92749          "swid": {
 92750            "attachment": {}
 92751          },
 92752          "pedigree": {},
 92753          "externalReferences": [
 92754            {
 92755              "url": "https://www.openssl.org/",
 92756              "type": "distribution"
 92757            }
 92758          ],
 92759          "evidence": {},
 92760          "signature": {
 92761            "signature": {
 92762              "publicKey": {}
 92763            }
 92764          },
 92765          "modelCard": {
 92766            "modelParameters": {
 92767              "approach": {}
 92768            },
 92769            "quantitativeAnalysis": {
 92770              "graphics": {}
 92771            },
 92772            "considerations": {}
 92773          }
 92774        },
 92775        {
 92776          "type": "library",
 92777          "bom-ref": "pkg:apk/alpine/libcurl@7.76.1-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.13.5\u0026package-id=f2f368fb77e616a0",
 92778          "supplier": {},
 92779          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92780          "name": "libcurl",
 92781          "version": "7.76.1-r0",
 92782          "description": "The multiprotocol file transfer library",
 92783          "licenses": [
 92784            {
 92785              "license": {
 92786                "id": "MIT"
 92787              }
 92788            }
 92789          ],
 92790          "cpe": "cpe:2.3:a:libcurl:libcurl:7.76.1-r0:*:*:*:*:*:*:*",
 92791          "purl": "pkg:apk/alpine/libcurl@7.76.1-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.13.5",
 92792          "swid": {
 92793            "attachment": {}
 92794          },
 92795          "pedigree": {},
 92796          "externalReferences": [
 92797            {
 92798              "url": "https://curl.se/",
 92799              "type": "distribution"
 92800            }
 92801          ],
 92802          "evidence": {},
 92803          "signature": {
 92804            "signature": {
 92805              "publicKey": {}
 92806            }
 92807          },
 92808          "modelCard": {
 92809            "modelParameters": {
 92810              "approach": {}
 92811            },
 92812            "quantitativeAnalysis": {
 92813              "graphics": {}
 92814            },
 92815            "considerations": {}
 92816          }
 92817        },
 92818        {
 92819          "type": "library",
 92820          "bom-ref": "pkg:apk/alpine/libcurl@7.78.0-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.13.5\u0026package-id=7f8ba0e9b7d85bc1",
 92821          "supplier": {},
 92822          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92823          "name": "libcurl",
 92824          "version": "7.78.0-r0",
 92825          "description": "The multiprotocol file transfer library",
 92826          "licenses": [
 92827            {
 92828              "license": {
 92829                "id": "MIT"
 92830              }
 92831            }
 92832          ],
 92833          "cpe": "cpe:2.3:a:libcurl:libcurl:7.78.0-r0:*:*:*:*:*:*:*",
 92834          "purl": "pkg:apk/alpine/libcurl@7.78.0-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.13.5",
 92835          "swid": {
 92836            "attachment": {}
 92837          },
 92838          "pedigree": {},
 92839          "externalReferences": [
 92840            {
 92841              "url": "https://curl.se/",
 92842              "type": "distribution"
 92843            }
 92844          ],
 92845          "evidence": {},
 92846          "signature": {
 92847            "signature": {
 92848              "publicKey": {}
 92849            }
 92850          },
 92851          "modelCard": {
 92852            "modelParameters": {
 92853              "approach": {}
 92854            },
 92855            "quantitativeAnalysis": {
 92856              "graphics": {}
 92857            },
 92858            "considerations": {}
 92859          }
 92860        },
 92861        {
 92862          "type": "library",
 92863          "bom-ref": "pkg:apk/alpine/libedit@20191231.3.1-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=c65a8cacb0933cde",
 92864          "supplier": {},
 92865          "publisher": "Drew DeVault \u003csir@cmpwn.com\u003e",
 92866          "name": "libedit",
 92867          "version": "20191231.3.1-r1",
 92868          "description": "BSD line editing library",
 92869          "licenses": [
 92870            {
 92871              "license": {
 92872                "id": "BSD-3-Clause"
 92873              }
 92874            }
 92875          ],
 92876          "cpe": "cpe:2.3:a:libedit:libedit:20191231.3.1-r1:*:*:*:*:*:*:*",
 92877          "purl": "pkg:apk/alpine/libedit@20191231.3.1-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 92878          "swid": {
 92879            "attachment": {}
 92880          },
 92881          "pedigree": {},
 92882          "externalReferences": [
 92883            {
 92884              "url": "https://www.thrysoee.dk/editline",
 92885              "type": "distribution"
 92886            }
 92887          ],
 92888          "evidence": {},
 92889          "signature": {
 92890            "signature": {
 92891              "publicKey": {}
 92892            }
 92893          },
 92894          "modelCard": {
 92895            "modelParameters": {
 92896              "approach": {}
 92897            },
 92898            "quantitativeAnalysis": {
 92899              "graphics": {}
 92900            },
 92901            "considerations": {}
 92902          }
 92903        },
 92904        {
 92905          "type": "library",
 92906          "bom-ref": "pkg:apk/alpine/libgcrypt@1.8.7-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=758c7d9c858219e1",
 92907          "supplier": {},
 92908          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92909          "name": "libgcrypt",
 92910          "version": "1.8.7-r0",
 92911          "description": "general purpose crypto library based on the code used in GnuPG",
 92912          "licenses": [
 92913            {
 92914              "license": {
 92915                "id": "LGPL-2.1-or-later"
 92916              }
 92917            }
 92918          ],
 92919          "cpe": "cpe:2.3:a:libgcrypt:libgcrypt:1.8.7-r0:*:*:*:*:*:*:*",
 92920          "purl": "pkg:apk/alpine/libgcrypt@1.8.7-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 92921          "swid": {
 92922            "attachment": {}
 92923          },
 92924          "pedigree": {},
 92925          "externalReferences": [
 92926            {
 92927              "url": "https://www.gnupg.org/",
 92928              "type": "distribution"
 92929            }
 92930          ],
 92931          "evidence": {},
 92932          "signature": {
 92933            "signature": {
 92934              "publicKey": {}
 92935            }
 92936          },
 92937          "modelCard": {
 92938            "modelParameters": {
 92939              "approach": {}
 92940            },
 92941            "quantitativeAnalysis": {
 92942              "graphics": {}
 92943            },
 92944            "considerations": {}
 92945          }
 92946        },
 92947        {
 92948          "type": "library",
 92949          "bom-ref": "pkg:apk/alpine/libgcrypt@1.8.8-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=f1f39defa21c00dd",
 92950          "supplier": {},
 92951          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 92952          "name": "libgcrypt",
 92953          "version": "1.8.8-r0",
 92954          "description": "general purpose crypto library based on the code used in GnuPG",
 92955          "licenses": [
 92956            {
 92957              "license": {
 92958                "id": "LGPL-2.1-or-later"
 92959              }
 92960            }
 92961          ],
 92962          "cpe": "cpe:2.3:a:libgcrypt:libgcrypt:1.8.8-r0:*:*:*:*:*:*:*",
 92963          "purl": "pkg:apk/alpine/libgcrypt@1.8.8-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 92964          "swid": {
 92965            "attachment": {}
 92966          },
 92967          "pedigree": {},
 92968          "externalReferences": [
 92969            {
 92970              "url": "https://www.gnupg.org/",
 92971              "type": "distribution"
 92972            }
 92973          ],
 92974          "evidence": {},
 92975          "signature": {
 92976            "signature": {
 92977              "publicKey": {}
 92978            }
 92979          },
 92980          "modelCard": {
 92981            "modelParameters": {
 92982              "approach": {}
 92983            },
 92984            "quantitativeAnalysis": {
 92985              "graphics": {}
 92986            },
 92987            "considerations": {}
 92988          }
 92989        },
 92990        {
 92991          "type": "library",
 92992          "bom-ref": "pkg:apk/alpine/libgd@2.3.0-r2?arch=x86_64\u0026upstream=gd\u0026distro=alpine-3.13.5\u0026package-id=dca5ab210643b806",
 92993          "supplier": {},
 92994          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 92995          "name": "libgd",
 92996          "version": "2.3.0-r2",
 92997          "description": "Library for the dynamic creation of images by programmers (libraries)",
 92998          "licenses": [
 92999            {
 93000              "license": {
 93001                "name": "custom"
 93002              }
 93003            }
 93004          ],
 93005          "cpe": "cpe:2.3:a:libgd:libgd:2.3.0-r2:*:*:*:*:*:*:*",
 93006          "purl": "pkg:apk/alpine/libgd@2.3.0-r2?arch=x86_64\u0026upstream=gd\u0026distro=alpine-3.13.5",
 93007          "swid": {
 93008            "attachment": {}
 93009          },
 93010          "pedigree": {},
 93011          "externalReferences": [
 93012            {
 93013              "url": "https://libgd.github.io/",
 93014              "type": "distribution"
 93015            }
 93016          ],
 93017          "evidence": {},
 93018          "signature": {
 93019            "signature": {
 93020              "publicKey": {}
 93021            }
 93022          },
 93023          "modelCard": {
 93024            "modelParameters": {
 93025              "approach": {}
 93026            },
 93027            "quantitativeAnalysis": {
 93028              "graphics": {}
 93029            },
 93030            "considerations": {}
 93031          }
 93032        },
 93033        {
 93034          "type": "library",
 93035          "bom-ref": "pkg:apk/alpine/libgomp@10.2.1_pre1-r3?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.13.5\u0026package-id=fd2b68ad9f457c2c",
 93036          "supplier": {},
 93037          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 93038          "name": "libgomp",
 93039          "version": "10.2.1_pre1-r3",
 93040          "description": "GCC shared-memory parallel programming API library",
 93041          "licenses": [
 93042            {
 93043              "license": {
 93044                "id": "GPL-2.0-or-later"
 93045              }
 93046            },
 93047            {
 93048              "license": {
 93049                "id": "LGPL-2.1-or-later"
 93050              }
 93051            }
 93052          ],
 93053          "cpe": "cpe:2.3:a:libgomp:libgomp:10.2.1_pre1-r3:*:*:*:*:*:*:*",
 93054          "purl": "pkg:apk/alpine/libgomp@10.2.1_pre1-r3?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.13.5",
 93055          "swid": {
 93056            "attachment": {}
 93057          },
 93058          "pedigree": {},
 93059          "externalReferences": [
 93060            {
 93061              "url": "https://gcc.gnu.org",
 93062              "type": "distribution"
 93063            }
 93064          ],
 93065          "evidence": {},
 93066          "signature": {
 93067            "signature": {
 93068              "publicKey": {}
 93069            }
 93070          },
 93071          "modelCard": {
 93072            "modelParameters": {
 93073              "approach": {}
 93074            },
 93075            "quantitativeAnalysis": {
 93076              "graphics": {}
 93077            },
 93078            "considerations": {}
 93079          }
 93080        },
 93081        {
 93082          "type": "library",
 93083          "bom-ref": "pkg:apk/alpine/libgpg-error@1.41-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=d702c6bc3dfae7cc",
 93084          "supplier": {},
 93085          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 93086          "name": "libgpg-error",
 93087          "version": "1.41-r0",
 93088          "description": "Support library for libgcrypt",
 93089          "licenses": [
 93090            {
 93091              "license": {
 93092                "id": "GPL-2.0-or-later"
 93093              }
 93094            },
 93095            {
 93096              "license": {
 93097                "id": "LGPL-2.1-or-later"
 93098              }
 93099            }
 93100          ],
 93101          "cpe": "cpe:2.3:a:libgpg-error:libgpg-error:1.41-r0:*:*:*:*:*:*:*",
 93102          "purl": "pkg:apk/alpine/libgpg-error@1.41-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 93103          "swid": {
 93104            "attachment": {}
 93105          },
 93106          "pedigree": {},
 93107          "externalReferences": [
 93108            {
 93109              "url": "https://www.gnupg.org/",
 93110              "type": "distribution"
 93111            }
 93112          ],
 93113          "evidence": {},
 93114          "signature": {
 93115            "signature": {
 93116              "publicKey": {}
 93117            }
 93118          },
 93119          "modelCard": {
 93120            "modelParameters": {
 93121              "approach": {}
 93122            },
 93123            "quantitativeAnalysis": {
 93124              "graphics": {}
 93125            },
 93126            "considerations": {}
 93127          }
 93128        },
 93129        {
 93130          "type": "library",
 93131          "bom-ref": "pkg:apk/alpine/libintl@0.20.2-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.13.5\u0026package-id=1e6aa12e29b590cd",
 93132          "supplier": {},
 93133          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 93134          "name": "libintl",
 93135          "version": "0.20.2-r2",
 93136          "description": "GNU gettext runtime library",
 93137          "licenses": [
 93138            {
 93139              "license": {
 93140                "id": "LGPL-2.1-or-later"
 93141              }
 93142            }
 93143          ],
 93144          "cpe": "cpe:2.3:a:libintl:libintl:0.20.2-r2:*:*:*:*:*:*:*",
 93145          "purl": "pkg:apk/alpine/libintl@0.20.2-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.13.5",
 93146          "swid": {
 93147            "attachment": {}
 93148          },
 93149          "pedigree": {},
 93150          "externalReferences": [
 93151            {
 93152              "url": "https://www.gnu.org/software/gettext/gettext.html",
 93153              "type": "distribution"
 93154            }
 93155          ],
 93156          "evidence": {},
 93157          "signature": {
 93158            "signature": {
 93159              "publicKey": {}
 93160            }
 93161          },
 93162          "modelCard": {
 93163            "modelParameters": {
 93164              "approach": {}
 93165            },
 93166            "quantitativeAnalysis": {
 93167              "graphics": {}
 93168            },
 93169            "considerations": {}
 93170          }
 93171        },
 93172        {
 93173          "type": "library",
 93174          "bom-ref": "pkg:apk/alpine/libjpeg-turbo@2.1.0-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=4e1707d434b328ac",
 93175          "supplier": {},
 93176          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 93177          "name": "libjpeg-turbo",
 93178          "version": "2.1.0-r0",
 93179          "description": "Accelerated baseline JPEG compression and decompression library",
 93180          "licenses": [
 93181            {
 93182              "license": {
 93183                "id": "BSD-3-Clause"
 93184              }
 93185            },
 93186            {
 93187              "license": {
 93188                "id": "IJG"
 93189              }
 93190            },
 93191            {
 93192              "license": {
 93193                "id": "Zlib"
 93194              }
 93195            }
 93196          ],
 93197          "cpe": "cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:2.1.0-r0:*:*:*:*:*:*:*",
 93198          "purl": "pkg:apk/alpine/libjpeg-turbo@2.1.0-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 93199          "swid": {
 93200            "attachment": {}
 93201          },
 93202          "pedigree": {},
 93203          "externalReferences": [
 93204            {
 93205              "url": "https://libjpeg-turbo.org/",
 93206              "type": "distribution"
 93207            }
 93208          ],
 93209          "evidence": {},
 93210          "signature": {
 93211            "signature": {
 93212              "publicKey": {}
 93213            }
 93214          },
 93215          "modelCard": {
 93216            "modelParameters": {
 93217              "approach": {}
 93218            },
 93219            "quantitativeAnalysis": {
 93220              "graphics": {}
 93221            },
 93222            "considerations": {}
 93223          }
 93224        },
 93225        {
 93226          "type": "library",
 93227          "bom-ref": "pkg:apk/alpine/libpng@1.6.37-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=c4241db8c2dcd1d1",
 93228          "supplier": {},
 93229          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 93230          "name": "libpng",
 93231          "version": "1.6.37-r1",
 93232          "description": "Portable Network Graphics library",
 93233          "licenses": [
 93234            {
 93235              "license": {
 93236                "id": "Libpng"
 93237              }
 93238            }
 93239          ],
 93240          "cpe": "cpe:2.3:a:libpng:libpng:1.6.37-r1:*:*:*:*:*:*:*",
 93241          "purl": "pkg:apk/alpine/libpng@1.6.37-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 93242          "swid": {
 93243            "attachment": {}
 93244          },
 93245          "pedigree": {},
 93246          "externalReferences": [
 93247            {
 93248              "url": "http://www.libpng.org",
 93249              "type": "distribution"
 93250            }
 93251          ],
 93252          "evidence": {},
 93253          "signature": {
 93254            "signature": {
 93255              "publicKey": {}
 93256            }
 93257          },
 93258          "modelCard": {
 93259            "modelParameters": {
 93260              "approach": {}
 93261            },
 93262            "quantitativeAnalysis": {
 93263              "graphics": {}
 93264            },
 93265            "considerations": {}
 93266          }
 93267        },
 93268        {
 93269          "type": "library",
 93270          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1k-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.13.5\u0026package-id=d2e66149161a385f",
 93271          "supplier": {},
 93272          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
 93273          "name": "libssl1.1",
 93274          "version": "1.1.1k-r0",
 93275          "description": "SSL shared libraries",
 93276          "licenses": [
 93277            {
 93278              "license": {
 93279                "id": "OpenSSL"
 93280              }
 93281            }
 93282          ],
 93283          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1k-r0:*:*:*:*:*:*:*",
 93284          "purl": "pkg:apk/alpine/libssl1.1@1.1.1k-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.13.5",
 93285          "swid": {
 93286            "attachment": {}
 93287          },
 93288          "pedigree": {},
 93289          "externalReferences": [
 93290            {
 93291              "url": "https://www.openssl.org/",
 93292              "type": "distribution"
 93293            }
 93294          ],
 93295          "evidence": {},
 93296          "signature": {
 93297            "signature": {
 93298              "publicKey": {}
 93299            }
 93300          },
 93301          "modelCard": {
 93302            "modelParameters": {
 93303              "approach": {}
 93304            },
 93305            "quantitativeAnalysis": {
 93306              "graphics": {}
 93307            },
 93308            "considerations": {}
 93309          }
 93310        },
 93311        {
 93312          "type": "library",
 93313          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.13.5\u0026package-id=1546b930bc3e40b5",
 93314          "supplier": {},
 93315          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
 93316          "name": "libssl1.1",
 93317          "version": "1.1.1l-r0",
 93318          "description": "SSL shared libraries",
 93319          "licenses": [
 93320            {
 93321              "license": {
 93322                "id": "OpenSSL"
 93323              }
 93324            }
 93325          ],
 93326          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1l-r0:*:*:*:*:*:*:*",
 93327          "purl": "pkg:apk/alpine/libssl1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.13.5",
 93328          "swid": {
 93329            "attachment": {}
 93330          },
 93331          "pedigree": {},
 93332          "externalReferences": [
 93333            {
 93334              "url": "https://www.openssl.org/",
 93335              "type": "distribution"
 93336            }
 93337          ],
 93338          "evidence": {},
 93339          "signature": {
 93340            "signature": {
 93341              "publicKey": {}
 93342            }
 93343          },
 93344          "modelCard": {
 93345            "modelParameters": {
 93346              "approach": {}
 93347            },
 93348            "quantitativeAnalysis": {
 93349              "graphics": {}
 93350            },
 93351            "considerations": {}
 93352          }
 93353        },
 93354        {
 93355          "type": "library",
 93356          "bom-ref": "pkg:apk/alpine/libtls-standalone@2.9.1-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=d76a1512572882c1",
 93357          "supplier": {},
 93358          "name": "libtls-standalone",
 93359          "version": "2.9.1-r1",
 93360          "description": "libtls extricated from libressl sources",
 93361          "licenses": [
 93362            {
 93363              "license": {
 93364                "id": "ISC"
 93365              }
 93366            }
 93367          ],
 93368          "cpe": "cpe:2.3:a:libtls-standalone:libtls-standalone:2.9.1-r1:*:*:*:*:*:*:*",
 93369          "purl": "pkg:apk/alpine/libtls-standalone@2.9.1-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 93370          "swid": {
 93371            "attachment": {}
 93372          },
 93373          "pedigree": {},
 93374          "externalReferences": [
 93375            {
 93376              "url": "https://www.libressl.org/",
 93377              "type": "distribution"
 93378            }
 93379          ],
 93380          "evidence": {},
 93381          "signature": {
 93382            "signature": {
 93383              "publicKey": {}
 93384            }
 93385          },
 93386          "modelCard": {
 93387            "modelParameters": {
 93388              "approach": {}
 93389            },
 93390            "quantitativeAnalysis": {
 93391              "graphics": {}
 93392            },
 93393            "considerations": {}
 93394          }
 93395        },
 93396        {
 93397          "type": "library",
 93398          "bom-ref": "pkg:apk/alpine/libunistring@0.9.10-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=7914eb2e08b1511b",
 93399          "supplier": {},
 93400          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 93401          "name": "libunistring",
 93402          "version": "0.9.10-r0",
 93403          "description": "Library for manipulating Unicode strings and C strings",
 93404          "licenses": [
 93405            {
 93406              "license": {
 93407                "id": "GPL-2.0-or-later"
 93408              }
 93409            },
 93410            {
 93411              "license": {
 93412                "name": "OR"
 93413              }
 93414            },
 93415            {
 93416              "license": {
 93417                "id": "LGPL-3.0-or-later"
 93418              }
 93419            }
 93420          ],
 93421          "cpe": "cpe:2.3:a:libunistring:libunistring:0.9.10-r0:*:*:*:*:*:*:*",
 93422          "purl": "pkg:apk/alpine/libunistring@0.9.10-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 93423          "swid": {
 93424            "attachment": {}
 93425          },
 93426          "pedigree": {},
 93427          "externalReferences": [
 93428            {
 93429              "url": "https://www.gnu.org/software/libunistring/",
 93430              "type": "distribution"
 93431            }
 93432          ],
 93433          "evidence": {},
 93434          "signature": {
 93435            "signature": {
 93436              "publicKey": {}
 93437            }
 93438          },
 93439          "modelCard": {
 93440            "modelParameters": {
 93441              "approach": {}
 93442            },
 93443            "quantitativeAnalysis": {
 93444              "graphics": {}
 93445            },
 93446            "considerations": {}
 93447          }
 93448        },
 93449        {
 93450          "type": "library",
 93451          "bom-ref": "pkg:apk/alpine/libwebp@1.1.0-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=1dc7c42adcfa771a",
 93452          "supplier": {},
 93453          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 93454          "name": "libwebp",
 93455          "version": "1.1.0-r0",
 93456          "description": "Libraries for working with WebP images",
 93457          "licenses": [
 93458            {
 93459              "license": {
 93460                "id": "BSD-3-Clause"
 93461              }
 93462            }
 93463          ],
 93464          "cpe": "cpe:2.3:a:libwebp:libwebp:1.1.0-r0:*:*:*:*:*:*:*",
 93465          "purl": "pkg:apk/alpine/libwebp@1.1.0-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 93466          "swid": {
 93467            "attachment": {}
 93468          },
 93469          "pedigree": {},
 93470          "externalReferences": [
 93471            {
 93472              "url": "https://developers.google.com/speed/webp",
 93473              "type": "distribution"
 93474            }
 93475          ],
 93476          "evidence": {},
 93477          "signature": {
 93478            "signature": {
 93479              "publicKey": {}
 93480            }
 93481          },
 93482          "modelCard": {
 93483            "modelParameters": {
 93484              "approach": {}
 93485            },
 93486            "quantitativeAnalysis": {
 93487              "graphics": {}
 93488            },
 93489            "considerations": {}
 93490          }
 93491        },
 93492        {
 93493          "type": "library",
 93494          "bom-ref": "pkg:apk/alpine/libxml2@2.9.10-r6?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=24e0d1d6f8c7e64c",
 93495          "supplier": {},
 93496          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 93497          "name": "libxml2",
 93498          "version": "2.9.10-r6",
 93499          "description": "XML parsing library, version 2",
 93500          "licenses": [
 93501            {
 93502              "license": {
 93503                "id": "MIT"
 93504              }
 93505            }
 93506          ],
 93507          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.10-r6:*:*:*:*:*:*:*",
 93508          "purl": "pkg:apk/alpine/libxml2@2.9.10-r6?arch=x86_64\u0026distro=alpine-3.13.5",
 93509          "swid": {
 93510            "attachment": {}
 93511          },
 93512          "pedigree": {},
 93513          "externalReferences": [
 93514            {
 93515              "url": "http://www.xmlsoft.org/",
 93516              "type": "distribution"
 93517            }
 93518          ],
 93519          "evidence": {},
 93520          "signature": {
 93521            "signature": {
 93522              "publicKey": {}
 93523            }
 93524          },
 93525          "modelCard": {
 93526            "modelParameters": {
 93527              "approach": {}
 93528            },
 93529            "quantitativeAnalysis": {
 93530              "graphics": {}
 93531            },
 93532            "considerations": {}
 93533          }
 93534        },
 93535        {
 93536          "type": "library",
 93537          "bom-ref": "pkg:apk/alpine/libxml2@2.9.12-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=e316c933dcb97f36",
 93538          "supplier": {},
 93539          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
 93540          "name": "libxml2",
 93541          "version": "2.9.12-r0",
 93542          "description": "XML parsing library, version 2",
 93543          "licenses": [
 93544            {
 93545              "license": {
 93546                "id": "MIT"
 93547              }
 93548            }
 93549          ],
 93550          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.12-r0:*:*:*:*:*:*:*",
 93551          "purl": "pkg:apk/alpine/libxml2@2.9.12-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 93552          "swid": {
 93553            "attachment": {}
 93554          },
 93555          "pedigree": {},
 93556          "externalReferences": [
 93557            {
 93558              "url": "http://www.xmlsoft.org/",
 93559              "type": "distribution"
 93560            }
 93561          ],
 93562          "evidence": {},
 93563          "signature": {
 93564            "signature": {
 93565              "publicKey": {}
 93566            }
 93567          },
 93568          "modelCard": {
 93569            "modelParameters": {
 93570              "approach": {}
 93571            },
 93572            "quantitativeAnalysis": {
 93573              "graphics": {}
 93574            },
 93575            "considerations": {}
 93576          }
 93577        },
 93578        {
 93579          "type": "library",
 93580          "bom-ref": "pkg:apk/alpine/libxslt@1.1.34-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=95149928a7bb02e3",
 93581          "supplier": {},
 93582          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 93583          "name": "libxslt",
 93584          "version": "1.1.34-r0",
 93585          "description": "XML stylesheet transformation library",
 93586          "licenses": [
 93587            {
 93588              "license": {
 93589                "name": "custom"
 93590              }
 93591            }
 93592          ],
 93593          "cpe": "cpe:2.3:a:libxslt:libxslt:1.1.34-r0:*:*:*:*:*:*:*",
 93594          "purl": "pkg:apk/alpine/libxslt@1.1.34-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 93595          "swid": {
 93596            "attachment": {}
 93597          },
 93598          "pedigree": {},
 93599          "externalReferences": [
 93600            {
 93601              "url": "http://xmlsoft.org/XSLT/",
 93602              "type": "distribution"
 93603            }
 93604          ],
 93605          "evidence": {},
 93606          "signature": {
 93607            "signature": {
 93608              "publicKey": {}
 93609            }
 93610          },
 93611          "modelCard": {
 93612            "modelParameters": {
 93613              "approach": {}
 93614            },
 93615            "quantitativeAnalysis": {
 93616              "graphics": {}
 93617            },
 93618            "considerations": {}
 93619          }
 93620        },
 93621        {
 93622          "type": "library",
 93623          "bom-ref": "pkg:apk/alpine/linux-pam@1.5.1-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=85a1c23d2cf80298",
 93624          "supplier": {},
 93625          "publisher": "Rasmus Thomsen \u003coss@cogitri.dev\u003e",
 93626          "name": "linux-pam",
 93627          "version": "1.5.1-r0",
 93628          "description": "Linux PAM (Pluggable Authentication Modules for Linux)",
 93629          "licenses": [
 93630            {
 93631              "license": {
 93632                "id": "BSD-3-Clause"
 93633              }
 93634            }
 93635          ],
 93636          "cpe": "cpe:2.3:a:linux-pam:linux-pam:1.5.1-r0:*:*:*:*:*:*:*",
 93637          "purl": "pkg:apk/alpine/linux-pam@1.5.1-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 93638          "swid": {
 93639            "attachment": {}
 93640          },
 93641          "pedigree": {},
 93642          "externalReferences": [
 93643            {
 93644              "url": "https://www.kernel.org/pub/linux/libs/pam",
 93645              "type": "distribution"
 93646            }
 93647          ],
 93648          "evidence": {},
 93649          "signature": {
 93650            "signature": {
 93651              "publicKey": {}
 93652            }
 93653          },
 93654          "modelCard": {
 93655            "modelParameters": {
 93656              "approach": {}
 93657            },
 93658            "quantitativeAnalysis": {
 93659              "graphics": {}
 93660            },
 93661            "considerations": {}
 93662          }
 93663        },
 93664        {
 93665          "type": "library",
 93666          "bom-ref": "pkg:apk/alpine/musl@1.2.2-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=ebf0aac8ad7bc0ad",
 93667          "supplier": {},
 93668          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 93669          "name": "musl",
 93670          "version": "1.2.2-r0",
 93671          "description": "the musl c library (libc) implementation",
 93672          "licenses": [
 93673            {
 93674              "license": {
 93675                "id": "MIT"
 93676              }
 93677            }
 93678          ],
 93679          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.2-r0:*:*:*:*:*:*:*",
 93680          "purl": "pkg:apk/alpine/musl@1.2.2-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 93681          "swid": {
 93682            "attachment": {}
 93683          },
 93684          "pedigree": {},
 93685          "externalReferences": [
 93686            {
 93687              "url": "https://musl.libc.org/",
 93688              "type": "distribution"
 93689            }
 93690          ],
 93691          "evidence": {},
 93692          "signature": {
 93693            "signature": {
 93694              "publicKey": {}
 93695            }
 93696          },
 93697          "modelCard": {
 93698            "modelParameters": {
 93699              "approach": {}
 93700            },
 93701            "quantitativeAnalysis": {
 93702              "graphics": {}
 93703            },
 93704            "considerations": {}
 93705          }
 93706        },
 93707        {
 93708          "type": "library",
 93709          "bom-ref": "pkg:apk/alpine/musl@1.2.2-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=eab82b935703f0f8",
 93710          "supplier": {},
 93711          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 93712          "name": "musl",
 93713          "version": "1.2.2-r1",
 93714          "description": "the musl c library (libc) implementation",
 93715          "licenses": [
 93716            {
 93717              "license": {
 93718                "id": "MIT"
 93719              }
 93720            }
 93721          ],
 93722          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.2-r1:*:*:*:*:*:*:*",
 93723          "purl": "pkg:apk/alpine/musl@1.2.2-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 93724          "swid": {
 93725            "attachment": {}
 93726          },
 93727          "pedigree": {},
 93728          "externalReferences": [
 93729            {
 93730              "url": "https://musl.libc.org/",
 93731              "type": "distribution"
 93732            }
 93733          ],
 93734          "evidence": {},
 93735          "signature": {
 93736            "signature": {
 93737              "publicKey": {}
 93738            }
 93739          },
 93740          "modelCard": {
 93741            "modelParameters": {
 93742              "approach": {}
 93743            },
 93744            "quantitativeAnalysis": {
 93745              "graphics": {}
 93746            },
 93747            "considerations": {}
 93748          }
 93749        },
 93750        {
 93751          "type": "library",
 93752          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.2-r0?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.13.5\u0026package-id=759b8e0aaa865907",
 93753          "supplier": {},
 93754          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 93755          "name": "musl-utils",
 93756          "version": "1.2.2-r0",
 93757          "description": "the musl c library (libc) implementation",
 93758          "licenses": [
 93759            {
 93760              "license": {
 93761                "id": "MIT"
 93762              }
 93763            },
 93764            {
 93765              "license": {
 93766                "name": "BSD"
 93767              }
 93768            },
 93769            {
 93770              "license": {
 93771                "id": "GPL-2.0-or-later"
 93772              }
 93773            }
 93774          ],
 93775          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.2-r0:*:*:*:*:*:*:*",
 93776          "purl": "pkg:apk/alpine/musl-utils@1.2.2-r0?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.13.5",
 93777          "swid": {
 93778            "attachment": {}
 93779          },
 93780          "pedigree": {},
 93781          "externalReferences": [
 93782            {
 93783              "url": "https://musl.libc.org/",
 93784              "type": "distribution"
 93785            }
 93786          ],
 93787          "evidence": {},
 93788          "signature": {
 93789            "signature": {
 93790              "publicKey": {}
 93791            }
 93792          },
 93793          "modelCard": {
 93794            "modelParameters": {
 93795              "approach": {}
 93796            },
 93797            "quantitativeAnalysis": {
 93798              "graphics": {}
 93799            },
 93800            "considerations": {}
 93801          }
 93802        },
 93803        {
 93804          "type": "library",
 93805          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.2-r1?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.13.5\u0026package-id=bb0380eaa3ae2379",
 93806          "supplier": {},
 93807          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
 93808          "name": "musl-utils",
 93809          "version": "1.2.2-r1",
 93810          "description": "the musl c library (libc) implementation",
 93811          "licenses": [
 93812            {
 93813              "license": {
 93814                "id": "MIT"
 93815              }
 93816            },
 93817            {
 93818              "license": {
 93819                "name": "BSD"
 93820              }
 93821            },
 93822            {
 93823              "license": {
 93824                "id": "GPL-2.0-or-later"
 93825              }
 93826            }
 93827          ],
 93828          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.2-r1:*:*:*:*:*:*:*",
 93829          "purl": "pkg:apk/alpine/musl-utils@1.2.2-r1?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.13.5",
 93830          "swid": {
 93831            "attachment": {}
 93832          },
 93833          "pedigree": {},
 93834          "externalReferences": [
 93835            {
 93836              "url": "https://musl.libc.org/",
 93837              "type": "distribution"
 93838            }
 93839          ],
 93840          "evidence": {},
 93841          "signature": {
 93842            "signature": {
 93843              "publicKey": {}
 93844            }
 93845          },
 93846          "modelCard": {
 93847            "modelParameters": {
 93848              "approach": {}
 93849            },
 93850            "quantitativeAnalysis": {
 93851              "graphics": {}
 93852            },
 93853            "considerations": {}
 93854          }
 93855        },
 93856        {
 93857          "type": "library",
 93858          "bom-ref": "pkg:apk/alpine/ncurses-libs@6.2_p20210109-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.13.5\u0026package-id=9e4fff99afda3647",
 93859          "supplier": {},
 93860          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 93861          "name": "ncurses-libs",
 93862          "version": "6.2_p20210109-r0",
 93863          "description": "Ncurses libraries",
 93864          "licenses": [
 93865            {
 93866              "license": {
 93867                "id": "MIT"
 93868              }
 93869            }
 93870          ],
 93871          "cpe": "cpe:2.3:a:ncurses-libs:ncurses-libs:6.2_p20210109-r0:*:*:*:*:*:*:*",
 93872          "purl": "pkg:apk/alpine/ncurses-libs@6.2_p20210109-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.13.5",
 93873          "swid": {
 93874            "attachment": {}
 93875          },
 93876          "pedigree": {},
 93877          "externalReferences": [
 93878            {
 93879              "url": "https://invisible-island.net/ncurses/",
 93880              "type": "distribution"
 93881            }
 93882          ],
 93883          "evidence": {},
 93884          "signature": {
 93885            "signature": {
 93886              "publicKey": {}
 93887            }
 93888          },
 93889          "modelCard": {
 93890            "modelParameters": {
 93891              "approach": {}
 93892            },
 93893            "quantitativeAnalysis": {
 93894              "graphics": {}
 93895            },
 93896            "considerations": {}
 93897          }
 93898        },
 93899        {
 93900          "type": "library",
 93901          "bom-ref": "pkg:apk/alpine/ncurses-terminfo-base@6.2_p20210109-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.13.5\u0026package-id=45a9204a753c7aa",
 93902          "supplier": {},
 93903          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 93904          "name": "ncurses-terminfo-base",
 93905          "version": "6.2_p20210109-r0",
 93906          "description": "Descriptions of common terminals",
 93907          "licenses": [
 93908            {
 93909              "license": {
 93910                "id": "MIT"
 93911              }
 93912            }
 93913          ],
 93914          "cpe": "cpe:2.3:a:ncurses-terminfo-base:ncurses-terminfo-base:6.2_p20210109-r0:*:*:*:*:*:*:*",
 93915          "purl": "pkg:apk/alpine/ncurses-terminfo-base@6.2_p20210109-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.13.5",
 93916          "swid": {
 93917            "attachment": {}
 93918          },
 93919          "pedigree": {},
 93920          "externalReferences": [
 93921            {
 93922              "url": "https://invisible-island.net/ncurses/",
 93923              "type": "distribution"
 93924            }
 93925          ],
 93926          "evidence": {},
 93927          "signature": {
 93928            "signature": {
 93929              "publicKey": {}
 93930            }
 93931          },
 93932          "modelCard": {
 93933            "modelParameters": {
 93934              "approach": {}
 93935            },
 93936            "quantitativeAnalysis": {
 93937              "graphics": {}
 93938            },
 93939            "considerations": {}
 93940          }
 93941        },
 93942        {
 93943          "type": "library",
 93944          "bom-ref": "pkg:apk/alpine/nghttp2-libs@1.42.0-r1?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.13.5\u0026package-id=717b6d07573df96a",
 93945          "supplier": {},
 93946          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
 93947          "name": "nghttp2-libs",
 93948          "version": "1.42.0-r1",
 93949          "description": "Experimental HTTP/2 client, server and proxy (libraries)",
 93950          "licenses": [
 93951            {
 93952              "license": {
 93953                "id": "MIT"
 93954              }
 93955            }
 93956          ],
 93957          "cpe": "cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.42.0-r1:*:*:*:*:*:*:*",
 93958          "purl": "pkg:apk/alpine/nghttp2-libs@1.42.0-r1?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.13.5",
 93959          "swid": {
 93960            "attachment": {}
 93961          },
 93962          "pedigree": {},
 93963          "externalReferences": [
 93964            {
 93965              "url": "https://nghttp2.org",
 93966              "type": "distribution"
 93967            }
 93968          ],
 93969          "evidence": {},
 93970          "signature": {
 93971            "signature": {
 93972              "publicKey": {}
 93973            }
 93974          },
 93975          "modelCard": {
 93976            "modelParameters": {
 93977              "approach": {}
 93978            },
 93979            "quantitativeAnalysis": {
 93980              "graphics": {}
 93981            },
 93982            "considerations": {}
 93983          }
 93984        },
 93985        {
 93986          "type": "library",
 93987          "bom-ref": "pkg:apk/alpine/nginx@1.20.1-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=b521f5e7843d593a",
 93988          "supplier": {},
 93989          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 93990          "name": "nginx",
 93991          "version": "1.20.1-r1",
 93992          "description": "High performance web server",
 93993          "licenses": [
 93994            {
 93995              "license": {
 93996                "name": "2-clause"
 93997              }
 93998            },
 93999            {
 94000              "license": {
 94001                "name": "BSD-like"
 94002              }
 94003            },
 94004            {
 94005              "license": {
 94006                "name": "license"
 94007              }
 94008            }
 94009          ],
 94010          "cpe": "cpe:2.3:a:nginx:nginx:1.20.1-r1:*:*:*:*:*:*:*",
 94011          "purl": "pkg:apk/alpine/nginx@1.20.1-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 94012          "swid": {
 94013            "attachment": {}
 94014          },
 94015          "pedigree": {},
 94016          "externalReferences": [
 94017            {
 94018              "url": "https://nginx.org/",
 94019              "type": "distribution"
 94020            }
 94021          ],
 94022          "evidence": {},
 94023          "signature": {
 94024            "signature": {
 94025              "publicKey": {}
 94026            }
 94027          },
 94028          "modelCard": {
 94029            "modelParameters": {
 94030              "approach": {}
 94031            },
 94032            "quantitativeAnalysis": {
 94033              "graphics": {}
 94034            },
 94035            "considerations": {}
 94036          }
 94037        },
 94038        {
 94039          "type": "library",
 94040          "bom-ref": "pkg:apk/alpine/nginx-module-geoip@1.20.1-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=23c0e193c6cd0fe9",
 94041          "supplier": {},
 94042          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 94043          "name": "nginx-module-geoip",
 94044          "version": "1.20.1-r1",
 94045          "description": "nginx GeoIP dynamic modules",
 94046          "licenses": [
 94047            {
 94048              "license": {
 94049                "name": "2-clause"
 94050              }
 94051            },
 94052            {
 94053              "license": {
 94054                "name": "BSD-like"
 94055              }
 94056            },
 94057            {
 94058              "license": {
 94059                "name": "license"
 94060              }
 94061            }
 94062          ],
 94063          "cpe": "cpe:2.3:a:nginx-module-geoip:nginx-module-geoip:1.20.1-r1:*:*:*:*:*:*:*",
 94064          "purl": "pkg:apk/alpine/nginx-module-geoip@1.20.1-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 94065          "swid": {
 94066            "attachment": {}
 94067          },
 94068          "pedigree": {},
 94069          "externalReferences": [
 94070            {
 94071              "url": "https://nginx.org/",
 94072              "type": "distribution"
 94073            }
 94074          ],
 94075          "evidence": {},
 94076          "signature": {
 94077            "signature": {
 94078              "publicKey": {}
 94079            }
 94080          },
 94081          "modelCard": {
 94082            "modelParameters": {
 94083              "approach": {}
 94084            },
 94085            "quantitativeAnalysis": {
 94086              "graphics": {}
 94087            },
 94088            "considerations": {}
 94089          }
 94090        },
 94091        {
 94092          "type": "library",
 94093          "bom-ref": "pkg:apk/alpine/nginx-module-image-filter@1.20.1-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=3bde08feb00296da",
 94094          "supplier": {},
 94095          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 94096          "name": "nginx-module-image-filter",
 94097          "version": "1.20.1-r1",
 94098          "description": "nginx image filter dynamic module",
 94099          "licenses": [
 94100            {
 94101              "license": {
 94102                "name": "2-clause"
 94103              }
 94104            },
 94105            {
 94106              "license": {
 94107                "name": "BSD-like"
 94108              }
 94109            },
 94110            {
 94111              "license": {
 94112                "name": "license"
 94113              }
 94114            }
 94115          ],
 94116          "cpe": "cpe:2.3:a:nginx-module-image-filter:nginx-module-image-filter:1.20.1-r1:*:*:*:*:*:*:*",
 94117          "purl": "pkg:apk/alpine/nginx-module-image-filter@1.20.1-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 94118          "swid": {
 94119            "attachment": {}
 94120          },
 94121          "pedigree": {},
 94122          "externalReferences": [
 94123            {
 94124              "url": "https://nginx.org/",
 94125              "type": "distribution"
 94126            }
 94127          ],
 94128          "evidence": {},
 94129          "signature": {
 94130            "signature": {
 94131              "publicKey": {}
 94132            }
 94133          },
 94134          "modelCard": {
 94135            "modelParameters": {
 94136              "approach": {}
 94137            },
 94138            "quantitativeAnalysis": {
 94139              "graphics": {}
 94140            },
 94141            "considerations": {}
 94142          }
 94143        },
 94144        {
 94145          "type": "library",
 94146          "bom-ref": "pkg:apk/alpine/nginx-module-njs@1.20.1.0.5.3-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=53146381f90120c3",
 94147          "supplier": {},
 94148          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 94149          "name": "nginx-module-njs",
 94150          "version": "1.20.1.0.5.3-r1",
 94151          "description": "nginx njs dynamic modules",
 94152          "licenses": [
 94153            {
 94154              "license": {
 94155                "name": "2-clause"
 94156              }
 94157            },
 94158            {
 94159              "license": {
 94160                "name": "BSD-like"
 94161              }
 94162            },
 94163            {
 94164              "license": {
 94165                "name": "license"
 94166              }
 94167            }
 94168          ],
 94169          "cpe": "cpe:2.3:a:nginx-module-njs:nginx-module-njs:1.20.1.0.5.3-r1:*:*:*:*:*:*:*",
 94170          "purl": "pkg:apk/alpine/nginx-module-njs@1.20.1.0.5.3-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 94171          "swid": {
 94172            "attachment": {}
 94173          },
 94174          "pedigree": {},
 94175          "externalReferences": [
 94176            {
 94177              "url": "https://nginx.org/",
 94178              "type": "distribution"
 94179            }
 94180          ],
 94181          "evidence": {},
 94182          "signature": {
 94183            "signature": {
 94184              "publicKey": {}
 94185            }
 94186          },
 94187          "modelCard": {
 94188            "modelParameters": {
 94189              "approach": {}
 94190            },
 94191            "quantitativeAnalysis": {
 94192              "graphics": {}
 94193            },
 94194            "considerations": {}
 94195          }
 94196        },
 94197        {
 94198          "type": "library",
 94199          "bom-ref": "pkg:apk/alpine/nginx-module-xslt@1.20.1-r1?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=9d551094455adebc",
 94200          "supplier": {},
 94201          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
 94202          "name": "nginx-module-xslt",
 94203          "version": "1.20.1-r1",
 94204          "description": "nginx xslt dynamic module",
 94205          "licenses": [
 94206            {
 94207              "license": {
 94208                "name": "2-clause"
 94209              }
 94210            },
 94211            {
 94212              "license": {
 94213                "name": "BSD-like"
 94214              }
 94215            },
 94216            {
 94217              "license": {
 94218                "name": "license"
 94219              }
 94220            }
 94221          ],
 94222          "cpe": "cpe:2.3:a:nginx-module-xslt:nginx-module-xslt:1.20.1-r1:*:*:*:*:*:*:*",
 94223          "purl": "pkg:apk/alpine/nginx-module-xslt@1.20.1-r1?arch=x86_64\u0026distro=alpine-3.13.5",
 94224          "swid": {
 94225            "attachment": {}
 94226          },
 94227          "pedigree": {},
 94228          "externalReferences": [
 94229            {
 94230              "url": "https://nginx.org/",
 94231              "type": "distribution"
 94232            }
 94233          ],
 94234          "evidence": {},
 94235          "signature": {
 94236            "signature": {
 94237              "publicKey": {}
 94238            }
 94239          },
 94240          "modelCard": {
 94241            "modelParameters": {
 94242              "approach": {}
 94243            },
 94244            "quantitativeAnalysis": {
 94245              "graphics": {}
 94246            },
 94247            "considerations": {}
 94248          }
 94249        },
 94250        {
 94251          "type": "library",
 94252          "bom-ref": "pkg:apk/alpine/pcre@8.44-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=2e6863ba37b5e6d0",
 94253          "supplier": {},
 94254          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 94255          "name": "pcre",
 94256          "version": "8.44-r0",
 94257          "description": "Perl-compatible regular expression library",
 94258          "licenses": [
 94259            {
 94260              "license": {
 94261                "id": "BSD-3-Clause"
 94262              }
 94263            }
 94264          ],
 94265          "cpe": "cpe:2.3:a:pcre:pcre:8.44-r0:*:*:*:*:*:*:*",
 94266          "purl": "pkg:apk/alpine/pcre@8.44-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 94267          "swid": {
 94268            "attachment": {}
 94269          },
 94270          "pedigree": {},
 94271          "externalReferences": [
 94272            {
 94273              "url": "http://pcre.sourceforge.net",
 94274              "type": "distribution"
 94275            }
 94276          ],
 94277          "evidence": {},
 94278          "signature": {
 94279            "signature": {
 94280              "publicKey": {}
 94281            }
 94282          },
 94283          "modelCard": {
 94284            "modelParameters": {
 94285              "approach": {}
 94286            },
 94287            "quantitativeAnalysis": {
 94288              "graphics": {}
 94289            },
 94290            "considerations": {}
 94291          }
 94292        },
 94293        {
 94294          "type": "library",
 94295          "bom-ref": "pkg:apk/alpine/readline@8.1.0-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=650143688d8c6f53",
 94296          "supplier": {},
 94297          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 94298          "name": "readline",
 94299          "version": "8.1.0-r0",
 94300          "description": "GNU readline library",
 94301          "licenses": [
 94302            {
 94303              "license": {
 94304                "id": "GPL-2.0-or-later"
 94305              }
 94306            }
 94307          ],
 94308          "cpe": "cpe:2.3:a:readline:readline:8.1.0-r0:*:*:*:*:*:*:*",
 94309          "purl": "pkg:apk/alpine/readline@8.1.0-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 94310          "swid": {
 94311            "attachment": {}
 94312          },
 94313          "pedigree": {},
 94314          "externalReferences": [
 94315            {
 94316              "url": "https://tiswww.cwru.edu/php/chet/readline/rltop.html",
 94317              "type": "distribution"
 94318            }
 94319          ],
 94320          "evidence": {},
 94321          "signature": {
 94322            "signature": {
 94323              "publicKey": {}
 94324            }
 94325          },
 94326          "modelCard": {
 94327            "modelParameters": {
 94328              "approach": {}
 94329            },
 94330            "quantitativeAnalysis": {
 94331              "graphics": {}
 94332            },
 94333            "considerations": {}
 94334          }
 94335        },
 94336        {
 94337          "type": "library",
 94338          "bom-ref": "pkg:apk/alpine/scanelf@1.2.8-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.13.5\u0026package-id=4b489a34e8162952",
 94339          "supplier": {},
 94340          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 94341          "name": "scanelf",
 94342          "version": "1.2.8-r0",
 94343          "description": "Scan ELF binaries for stuff",
 94344          "licenses": [
 94345            {
 94346              "license": {
 94347                "id": "GPL-2.0-only"
 94348              }
 94349            }
 94350          ],
 94351          "cpe": "cpe:2.3:a:scanelf:scanelf:1.2.8-r0:*:*:*:*:*:*:*",
 94352          "purl": "pkg:apk/alpine/scanelf@1.2.8-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.13.5",
 94353          "swid": {
 94354            "attachment": {}
 94355          },
 94356          "pedigree": {},
 94357          "externalReferences": [
 94358            {
 94359              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
 94360              "type": "distribution"
 94361            }
 94362          ],
 94363          "evidence": {},
 94364          "signature": {
 94365            "signature": {
 94366              "publicKey": {}
 94367            }
 94368          },
 94369          "modelCard": {
 94370            "modelParameters": {
 94371              "approach": {}
 94372            },
 94373            "quantitativeAnalysis": {
 94374              "graphics": {}
 94375            },
 94376            "considerations": {}
 94377          }
 94378        },
 94379        {
 94380          "type": "library",
 94381          "bom-ref": "pkg:apk/alpine/shadow@4.8.1-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=61f7be8e0de9f105",
 94382          "supplier": {},
 94383          "publisher": "Stuart Cardall \u003cdeveloper@it-offshore.co.uk\u003e",
 94384          "name": "shadow",
 94385          "version": "4.8.1-r0",
 94386          "description": "PAM-using login and passwd utilities (usermod, useradd, ...)",
 94387          "licenses": [
 94388            {
 94389              "license": {
 94390                "id": "BSD-3-Clause"
 94391              }
 94392            }
 94393          ],
 94394          "cpe": "cpe:2.3:a:shadow:shadow:4.8.1-r0:*:*:*:*:*:*:*",
 94395          "purl": "pkg:apk/alpine/shadow@4.8.1-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 94396          "swid": {
 94397            "attachment": {}
 94398          },
 94399          "pedigree": {},
 94400          "externalReferences": [
 94401            {
 94402              "url": "http://pkg-shadow.alioth.debian.org/",
 94403              "type": "distribution"
 94404            }
 94405          ],
 94406          "evidence": {},
 94407          "signature": {
 94408            "signature": {
 94409              "publicKey": {}
 94410            }
 94411          },
 94412          "modelCard": {
 94413            "modelParameters": {
 94414              "approach": {}
 94415            },
 94416            "quantitativeAnalysis": {
 94417              "graphics": {}
 94418            },
 94419            "considerations": {}
 94420          }
 94421        },
 94422        {
 94423          "type": "library",
 94424          "bom-ref": "pkg:apk/alpine/ssl_client@1.32.1-r6?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.13.5\u0026package-id=be9d756fc1c9db07",
 94425          "supplier": {},
 94426          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 94427          "name": "ssl_client",
 94428          "version": "1.32.1-r6",
 94429          "description": "EXternal ssl_client for busybox wget",
 94430          "licenses": [
 94431            {
 94432              "license": {
 94433                "id": "GPL-2.0-only"
 94434              }
 94435            }
 94436          ],
 94437          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.32.1-r6:*:*:*:*:*:*:*",
 94438          "purl": "pkg:apk/alpine/ssl_client@1.32.1-r6?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.13.5",
 94439          "swid": {
 94440            "attachment": {}
 94441          },
 94442          "pedigree": {},
 94443          "externalReferences": [
 94444            {
 94445              "url": "https://busybox.net/",
 94446              "type": "distribution"
 94447            }
 94448          ],
 94449          "evidence": {},
 94450          "signature": {
 94451            "signature": {
 94452              "publicKey": {}
 94453            }
 94454          },
 94455          "modelCard": {
 94456            "modelParameters": {
 94457              "approach": {}
 94458            },
 94459            "quantitativeAnalysis": {
 94460              "graphics": {}
 94461            },
 94462            "considerations": {}
 94463          }
 94464        },
 94465        {
 94466          "type": "library",
 94467          "bom-ref": "pkg:apk/alpine/tzdata@2021a-r0?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=78f80616fe162871",
 94468          "supplier": {},
 94469          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 94470          "name": "tzdata",
 94471          "version": "2021a-r0",
 94472          "description": "Timezone data",
 94473          "licenses": [
 94474            {
 94475              "license": {
 94476                "name": "Public-Domain"
 94477              }
 94478            }
 94479          ],
 94480          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-r0:*:*:*:*:*:*:*",
 94481          "purl": "pkg:apk/alpine/tzdata@2021a-r0?arch=x86_64\u0026distro=alpine-3.13.5",
 94482          "swid": {
 94483            "attachment": {}
 94484          },
 94485          "pedigree": {},
 94486          "externalReferences": [
 94487            {
 94488              "url": "https://www.iana.org/time-zones",
 94489              "type": "distribution"
 94490            }
 94491          ],
 94492          "evidence": {},
 94493          "signature": {
 94494            "signature": {
 94495              "publicKey": {}
 94496            }
 94497          },
 94498          "modelCard": {
 94499            "modelParameters": {
 94500              "approach": {}
 94501            },
 94502            "quantitativeAnalysis": {
 94503              "graphics": {}
 94504            },
 94505            "considerations": {}
 94506          }
 94507        },
 94508        {
 94509          "type": "library",
 94510          "bom-ref": "pkg:apk/alpine/xz-libs@5.2.5-r0?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.13.5\u0026package-id=6df0db01fa27b2da",
 94511          "supplier": {},
 94512          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 94513          "name": "xz-libs",
 94514          "version": "5.2.5-r0",
 94515          "description": "Library and CLI tools for XZ and LZMA compressed files (libraries)",
 94516          "licenses": [
 94517            {
 94518              "license": {
 94519                "id": "GPL-2.0-or-later"
 94520              }
 94521            },
 94522            {
 94523              "license": {
 94524                "name": "AND"
 94525              }
 94526            },
 94527            {
 94528              "license": {
 94529                "name": "Public-Domain"
 94530              }
 94531            },
 94532            {
 94533              "license": {
 94534                "name": "AND"
 94535              }
 94536            },
 94537            {
 94538              "license": {
 94539                "id": "LGPL-2.1-or-later"
 94540              }
 94541            }
 94542          ],
 94543          "cpe": "cpe:2.3:a:xz-libs:xz-libs:5.2.5-r0:*:*:*:*:*:*:*",
 94544          "purl": "pkg:apk/alpine/xz-libs@5.2.5-r0?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.13.5",
 94545          "swid": {
 94546            "attachment": {}
 94547          },
 94548          "pedigree": {},
 94549          "externalReferences": [
 94550            {
 94551              "url": "https://tukaani.org/xz",
 94552              "type": "distribution"
 94553            }
 94554          ],
 94555          "evidence": {},
 94556          "signature": {
 94557            "signature": {
 94558              "publicKey": {}
 94559            }
 94560          },
 94561          "modelCard": {
 94562            "modelParameters": {
 94563              "approach": {}
 94564            },
 94565            "quantitativeAnalysis": {
 94566              "graphics": {}
 94567            },
 94568            "considerations": {}
 94569          }
 94570        },
 94571        {
 94572          "type": "library",
 94573          "bom-ref": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.13.5\u0026package-id=573d473e139c9775",
 94574          "supplier": {},
 94575          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 94576          "name": "zlib",
 94577          "version": "1.2.11-r3",
 94578          "description": "A compression/decompression Library",
 94579          "licenses": [
 94580            {
 94581              "license": {
 94582                "id": "Zlib"
 94583              }
 94584            }
 94585          ],
 94586          "cpe": "cpe:2.3:a:zlib:zlib:1.2.11-r3:*:*:*:*:*:*:*",
 94587          "purl": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.13.5",
 94588          "swid": {
 94589            "attachment": {}
 94590          },
 94591          "pedigree": {},
 94592          "externalReferences": [
 94593            {
 94594              "url": "https://zlib.net/",
 94595              "type": "distribution"
 94596            }
 94597          ],
 94598          "evidence": {},
 94599          "signature": {
 94600            "signature": {
 94601              "publicKey": {}
 94602            }
 94603          },
 94604          "modelCard": {
 94605            "modelParameters": {
 94606              "approach": {}
 94607            },
 94608            "quantitativeAnalysis": {
 94609              "graphics": {}
 94610            },
 94611            "considerations": {}
 94612          }
 94613        },
 94614        {
 94615          "type": "operating-system",
 94616          "supplier": {},
 94617          "name": "alpine",
 94618          "version": "3.13.5",
 94619          "description": "Alpine Linux v3.13",
 94620          "swid": {
 94621            "tagId": "alpine",
 94622            "name": "alpine",
 94623            "version": "3.13.5",
 94624            "attachment": {}
 94625          },
 94626          "pedigree": {},
 94627          "externalReferences": [
 94628            {
 94629              "url": "https://bugs.alpinelinux.org/",
 94630              "type": "issue-tracker"
 94631            },
 94632            {
 94633              "url": "https://alpinelinux.org/",
 94634              "type": "website"
 94635            }
 94636          ],
 94637          "evidence": {},
 94638          "signature": {
 94639            "signature": {
 94640              "publicKey": {}
 94641            }
 94642          },
 94643          "modelCard": {
 94644            "modelParameters": {
 94645              "approach": {}
 94646            },
 94647            "quantitativeAnalysis": {
 94648              "graphics": {}
 94649            },
 94650            "considerations": {}
 94651          }
 94652        },
 94653        {
 94654          "type": "library",
 94655          "bom-ref": "pkg:npm/%40colors/colors@1.5.0?package-id=1e63eea14f4d61ef",
 94656          "supplier": {},
 94657          "author": "DABH",
 94658          "name": "@colors/colors",
 94659          "version": "1.5.0",
 94660          "description": "get colors in your node.js console",
 94661          "licenses": [
 94662            {
 94663              "license": {
 94664                "id": "MIT"
 94665              }
 94666            }
 94667          ],
 94668          "cpe": "cpe:2.3:a:\\@colors\\/colors:\\@colors\\/colors:1.5.0:*:*:*:*:*:*:*",
 94669          "purl": "pkg:npm/%40colors/colors@1.5.0",
 94670          "swid": {
 94671            "attachment": {}
 94672          },
 94673          "pedigree": {},
 94674          "externalReferences": [
 94675            {
 94676              "url": "http://github.com/DABH/colors.js.git",
 94677              "type": "distribution"
 94678            },
 94679            {
 94680              "url": "https://github.com/DABH/colors.js",
 94681              "type": "website"
 94682            }
 94683          ],
 94684          "evidence": {},
 94685          "signature": {
 94686            "signature": {
 94687              "publicKey": {}
 94688            }
 94689          },
 94690          "modelCard": {
 94691            "modelParameters": {
 94692              "approach": {}
 94693            },
 94694            "quantitativeAnalysis": {
 94695              "graphics": {}
 94696            },
 94697            "considerations": {}
 94698          }
 94699        },
 94700        {
 94701          "type": "library",
 94702          "bom-ref": "pkg:npm/%40gar/promisify@1.1.3?package-id=6fab079a7c06c1de",
 94703          "supplier": {},
 94704          "author": "Gar \u003cgar+npm@danger.computer\u003e",
 94705          "name": "@gar/promisify",
 94706          "version": "1.1.3",
 94707          "description": "Promisify an entire class or object",
 94708          "licenses": [
 94709            {
 94710              "license": {
 94711                "id": "MIT"
 94712              }
 94713            }
 94714          ],
 94715          "cpe": "cpe:2.3:a:\\@gar\\/promisify:\\@gar\\/promisify:1.1.3:*:*:*:*:*:*:*",
 94716          "purl": "pkg:npm/%40gar/promisify@1.1.3",
 94717          "swid": {
 94718            "attachment": {}
 94719          },
 94720          "pedigree": {},
 94721          "externalReferences": [
 94722            {
 94723              "url": "https://github.com/wraithgar/gar-promisify.git",
 94724              "type": "distribution"
 94725            }
 94726          ],
 94727          "evidence": {},
 94728          "signature": {
 94729            "signature": {
 94730              "publicKey": {}
 94731            }
 94732          },
 94733          "modelCard": {
 94734            "modelParameters": {
 94735              "approach": {}
 94736            },
 94737            "quantitativeAnalysis": {
 94738              "graphics": {}
 94739            },
 94740            "considerations": {}
 94741          }
 94742        },
 94743        {
 94744          "type": "library",
 94745          "bom-ref": "pkg:npm/%40isaacs/string-locale-compare@1.1.0?package-id=fbe0dcb344723a67",
 94746          "supplier": {},
 94747          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
 94748          "name": "@isaacs/string-locale-compare",
 94749          "version": "1.1.0",
 94750          "description": "Compare strings with Intl.Collator if available, falling back to String.localeCompare otherwise",
 94751          "licenses": [
 94752            {
 94753              "license": {
 94754                "id": "ISC"
 94755              }
 94756            }
 94757          ],
 94758          "cpe": "cpe:2.3:a:\\@isaacs\\/string-locale-compare:\\@isaacs\\/string-locale-compare:1.1.0:*:*:*:*:*:*:*",
 94759          "purl": "pkg:npm/%40isaacs/string-locale-compare@1.1.0",
 94760          "swid": {
 94761            "attachment": {}
 94762          },
 94763          "pedigree": {},
 94764          "externalReferences": [
 94765            {
 94766              "url": "git+https://github.com/isaacs/string-locale-compare",
 94767              "type": "distribution"
 94768            }
 94769          ],
 94770          "evidence": {},
 94771          "signature": {
 94772            "signature": {
 94773              "publicKey": {}
 94774            }
 94775          },
 94776          "modelCard": {
 94777            "modelParameters": {
 94778              "approach": {}
 94779            },
 94780            "quantitativeAnalysis": {
 94781              "graphics": {}
 94782            },
 94783            "considerations": {}
 94784          }
 94785        },
 94786        {
 94787          "type": "library",
 94788          "bom-ref": "pkg:npm/%40my-scope/package-a@0.0.0?package-id=9e7e5553c3ebce03",
 94789          "supplier": {},
 94790          "name": "@my-scope/package-a",
 94791          "version": "0.0.0",
 94792          "licenses": [
 94793            {
 94794              "license": {
 94795                "id": "MIT"
 94796              }
 94797            }
 94798          ],
 94799          "cpe": "cpe:2.3:a:\\@my-scope\\/package-a:\\@my-scope\\/package-a:0.0.0:*:*:*:*:*:*:*",
 94800          "purl": "pkg:npm/%40my-scope/package-a@0.0.0",
 94801          "swid": {
 94802            "attachment": {}
 94803          },
 94804          "pedigree": {},
 94805          "evidence": {},
 94806          "signature": {
 94807            "signature": {
 94808              "publicKey": {}
 94809            }
 94810          },
 94811          "modelCard": {
 94812            "modelParameters": {
 94813              "approach": {}
 94814            },
 94815            "quantitativeAnalysis": {
 94816              "graphics": {}
 94817            },
 94818            "considerations": {}
 94819          }
 94820        },
 94821        {
 94822          "type": "library",
 94823          "bom-ref": "pkg:npm/%40my-scope/package-b@0.0.0?package-id=9abfa6541a414f95",
 94824          "supplier": {},
 94825          "name": "@my-scope/package-b",
 94826          "version": "0.0.0",
 94827          "licenses": [
 94828            {
 94829              "license": {
 94830                "id": "MIT"
 94831              }
 94832            }
 94833          ],
 94834          "cpe": "cpe:2.3:a:\\@my-scope\\/package-b:\\@my-scope\\/package-b:0.0.0:*:*:*:*:*:*:*",
 94835          "purl": "pkg:npm/%40my-scope/package-b@0.0.0",
 94836          "swid": {
 94837            "attachment": {}
 94838          },
 94839          "pedigree": {},
 94840          "evidence": {},
 94841          "signature": {
 94842            "signature": {
 94843              "publicKey": {}
 94844            }
 94845          },
 94846          "modelCard": {
 94847            "modelParameters": {
 94848              "approach": {}
 94849            },
 94850            "quantitativeAnalysis": {
 94851              "graphics": {}
 94852            },
 94853            "considerations": {}
 94854          }
 94855        },
 94856        {
 94857          "type": "library",
 94858          "bom-ref": "pkg:npm/%40npmcli/arborist@5.6.3?package-id=60e008e2ceb94218",
 94859          "supplier": {},
 94860          "author": "GitHub Inc.",
 94861          "name": "@npmcli/arborist",
 94862          "version": "5.6.3",
 94863          "description": "Manage node_modules trees",
 94864          "licenses": [
 94865            {
 94866              "license": {
 94867                "id": "ISC"
 94868              }
 94869            }
 94870          ],
 94871          "cpe": "cpe:2.3:a:\\@npmcli\\/arborist:\\@npmcli\\/arborist:5.6.3:*:*:*:*:*:*:*",
 94872          "purl": "pkg:npm/%40npmcli/arborist@5.6.3",
 94873          "swid": {
 94874            "attachment": {}
 94875          },
 94876          "pedigree": {},
 94877          "externalReferences": [
 94878            {
 94879              "url": "https://github.com/npm/cli.git",
 94880              "type": "distribution"
 94881            }
 94882          ],
 94883          "evidence": {},
 94884          "signature": {
 94885            "signature": {
 94886              "publicKey": {}
 94887            }
 94888          },
 94889          "modelCard": {
 94890            "modelParameters": {
 94891              "approach": {}
 94892            },
 94893            "quantitativeAnalysis": {
 94894              "graphics": {}
 94895            },
 94896            "considerations": {}
 94897          }
 94898        },
 94899        {
 94900          "type": "library",
 94901          "bom-ref": "pkg:npm/%40npmcli/ci-detect@2.0.0?package-id=8a40a38b900bcf1d",
 94902          "supplier": {},
 94903          "author": "GitHub Inc.",
 94904          "name": "@npmcli/ci-detect",
 94905          "version": "2.0.0",
 94906          "description": "Detect what kind of CI environment the program is in",
 94907          "licenses": [
 94908            {
 94909              "license": {
 94910                "id": "ISC"
 94911              }
 94912            }
 94913          ],
 94914          "cpe": "cpe:2.3:a:\\@npmcli\\/ci-detect:\\@npmcli\\/ci-detect:2.0.0:*:*:*:*:*:*:*",
 94915          "purl": "pkg:npm/%40npmcli/ci-detect@2.0.0",
 94916          "swid": {
 94917            "attachment": {}
 94918          },
 94919          "pedigree": {},
 94920          "externalReferences": [
 94921            {
 94922              "url": "git+https://github.com/npm/ci-detect.git",
 94923              "type": "distribution"
 94924            }
 94925          ],
 94926          "evidence": {},
 94927          "signature": {
 94928            "signature": {
 94929              "publicKey": {}
 94930            }
 94931          },
 94932          "modelCard": {
 94933            "modelParameters": {
 94934              "approach": {}
 94935            },
 94936            "quantitativeAnalysis": {
 94937              "graphics": {}
 94938            },
 94939            "considerations": {}
 94940          }
 94941        },
 94942        {
 94943          "type": "library",
 94944          "bom-ref": "pkg:npm/%40npmcli/config@4.2.2?package-id=a02559bafd837882",
 94945          "supplier": {},
 94946          "author": "GitHub Inc.",
 94947          "name": "@npmcli/config",
 94948          "version": "4.2.2",
 94949          "description": "Configuration management for the npm cli",
 94950          "licenses": [
 94951            {
 94952              "license": {
 94953                "id": "ISC"
 94954              }
 94955            }
 94956          ],
 94957          "cpe": "cpe:2.3:a:\\@npmcli\\/config:\\@npmcli\\/config:4.2.2:*:*:*:*:*:*:*",
 94958          "purl": "pkg:npm/%40npmcli/config@4.2.2",
 94959          "swid": {
 94960            "attachment": {}
 94961          },
 94962          "pedigree": {},
 94963          "externalReferences": [
 94964            {
 94965              "url": "https://github.com/npm/config.git",
 94966              "type": "distribution"
 94967            }
 94968          ],
 94969          "evidence": {},
 94970          "signature": {
 94971            "signature": {
 94972              "publicKey": {}
 94973            }
 94974          },
 94975          "modelCard": {
 94976            "modelParameters": {
 94977              "approach": {}
 94978            },
 94979            "quantitativeAnalysis": {
 94980              "graphics": {}
 94981            },
 94982            "considerations": {}
 94983          }
 94984        },
 94985        {
 94986          "type": "library",
 94987          "bom-ref": "pkg:npm/%40npmcli/disparity-colors@2.0.0?package-id=3e63715f5300a753",
 94988          "supplier": {},
 94989          "author": "GitHub Inc.",
 94990          "name": "@npmcli/disparity-colors",
 94991          "version": "2.0.0",
 94992          "description": "Colorizes unified diff output",
 94993          "licenses": [
 94994            {
 94995              "license": {
 94996                "id": "ISC"
 94997              }
 94998            }
 94999          ],
 95000          "cpe": "cpe:2.3:a:\\@npmcli\\/disparity-colors:\\@npmcli\\/disparity-colors:2.0.0:*:*:*:*:*:*:*",
 95001          "purl": "pkg:npm/%40npmcli/disparity-colors@2.0.0",
 95002          "swid": {
 95003            "attachment": {}
 95004          },
 95005          "pedigree": {},
 95006          "externalReferences": [
 95007            {
 95008              "url": "https://github.com/npm/disparity-colors.git",
 95009              "type": "distribution"
 95010            }
 95011          ],
 95012          "evidence": {},
 95013          "signature": {
 95014            "signature": {
 95015              "publicKey": {}
 95016            }
 95017          },
 95018          "modelCard": {
 95019            "modelParameters": {
 95020              "approach": {}
 95021            },
 95022            "quantitativeAnalysis": {
 95023              "graphics": {}
 95024            },
 95025            "considerations": {}
 95026          }
 95027        },
 95028        {
 95029          "type": "library",
 95030          "bom-ref": "pkg:npm/%40npmcli/fs@2.1.2?package-id=cd19a20b4774187f",
 95031          "supplier": {},
 95032          "author": "GitHub Inc.",
 95033          "name": "@npmcli/fs",
 95034          "version": "2.1.2",
 95035          "description": "filesystem utilities for the npm cli",
 95036          "licenses": [
 95037            {
 95038              "license": {
 95039                "id": "ISC"
 95040              }
 95041            }
 95042          ],
 95043          "cpe": "cpe:2.3:a:\\@npmcli\\/fs:\\@npmcli\\/fs:2.1.2:*:*:*:*:*:*:*",
 95044          "purl": "pkg:npm/%40npmcli/fs@2.1.2",
 95045          "swid": {
 95046            "attachment": {}
 95047          },
 95048          "pedigree": {},
 95049          "externalReferences": [
 95050            {
 95051              "url": "https://github.com/npm/fs.git",
 95052              "type": "distribution"
 95053            }
 95054          ],
 95055          "evidence": {},
 95056          "signature": {
 95057            "signature": {
 95058              "publicKey": {}
 95059            }
 95060          },
 95061          "modelCard": {
 95062            "modelParameters": {
 95063              "approach": {}
 95064            },
 95065            "quantitativeAnalysis": {
 95066              "graphics": {}
 95067            },
 95068            "considerations": {}
 95069          }
 95070        },
 95071        {
 95072          "type": "library",
 95073          "bom-ref": "pkg:npm/%40npmcli/git@3.0.2?package-id=34b16cf601f612a9",
 95074          "supplier": {},
 95075          "author": "GitHub Inc.",
 95076          "name": "@npmcli/git",
 95077          "version": "3.0.2",
 95078          "description": "a util for spawning git from npm CLI contexts",
 95079          "licenses": [
 95080            {
 95081              "license": {
 95082                "id": "ISC"
 95083              }
 95084            }
 95085          ],
 95086          "cpe": "cpe:2.3:a:\\@npmcli\\/git:\\@npmcli\\/git:3.0.2:*:*:*:*:*:*:*",
 95087          "purl": "pkg:npm/%40npmcli/git@3.0.2",
 95088          "swid": {
 95089            "attachment": {}
 95090          },
 95091          "pedigree": {},
 95092          "externalReferences": [
 95093            {
 95094              "url": "https://github.com/npm/git.git",
 95095              "type": "distribution"
 95096            }
 95097          ],
 95098          "evidence": {},
 95099          "signature": {
 95100            "signature": {
 95101              "publicKey": {}
 95102            }
 95103          },
 95104          "modelCard": {
 95105            "modelParameters": {
 95106              "approach": {}
 95107            },
 95108            "quantitativeAnalysis": {
 95109              "graphics": {}
 95110            },
 95111            "considerations": {}
 95112          }
 95113        },
 95114        {
 95115          "type": "library",
 95116          "bom-ref": "pkg:npm/%40npmcli/installed-package-contents@1.0.7?package-id=8562f58f85ba40df",
 95117          "supplier": {},
 95118          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
 95119          "name": "@npmcli/installed-package-contents",
 95120          "version": "1.0.7",
 95121          "description": "Get the list of files installed in a package in node_modules, including bundled dependencies",
 95122          "licenses": [
 95123            {
 95124              "license": {
 95125                "id": "ISC"
 95126              }
 95127            }
 95128          ],
 95129          "cpe": "cpe:2.3:a:\\@npmcli\\/installed-package-contents:\\@npmcli\\/installed-package-contents:1.0.7:*:*:*:*:*:*:*",
 95130          "purl": "pkg:npm/%40npmcli/installed-package-contents@1.0.7",
 95131          "swid": {
 95132            "attachment": {}
 95133          },
 95134          "pedigree": {},
 95135          "externalReferences": [
 95136            {
 95137              "url": "git+https://github.com/npm/installed-package-contents",
 95138              "type": "distribution"
 95139            }
 95140          ],
 95141          "evidence": {},
 95142          "signature": {
 95143            "signature": {
 95144              "publicKey": {}
 95145            }
 95146          },
 95147          "modelCard": {
 95148            "modelParameters": {
 95149              "approach": {}
 95150            },
 95151            "quantitativeAnalysis": {
 95152              "graphics": {}
 95153            },
 95154            "considerations": {}
 95155          }
 95156        },
 95157        {
 95158          "type": "library",
 95159          "bom-ref": "pkg:npm/%40npmcli/map-workspaces@2.0.4?package-id=471052449bb417cb",
 95160          "supplier": {},
 95161          "author": "GitHub Inc.",
 95162          "name": "@npmcli/map-workspaces",
 95163          "version": "2.0.4",
 95164          "description": "Retrieves a name:pathname Map for a given workspaces config",
 95165          "licenses": [
 95166            {
 95167              "license": {
 95168                "id": "ISC"
 95169              }
 95170            }
 95171          ],
 95172          "cpe": "cpe:2.3:a:\\@npmcli\\/map-workspaces:\\@npmcli\\/map-workspaces:2.0.4:*:*:*:*:*:*:*",
 95173          "purl": "pkg:npm/%40npmcli/map-workspaces@2.0.4",
 95174          "swid": {
 95175            "attachment": {}
 95176          },
 95177          "pedigree": {},
 95178          "externalReferences": [
 95179            {
 95180              "url": "https://github.com/npm/map-workspaces.git",
 95181              "type": "distribution"
 95182            }
 95183          ],
 95184          "evidence": {},
 95185          "signature": {
 95186            "signature": {
 95187              "publicKey": {}
 95188            }
 95189          },
 95190          "modelCard": {
 95191            "modelParameters": {
 95192              "approach": {}
 95193            },
 95194            "quantitativeAnalysis": {
 95195              "graphics": {}
 95196            },
 95197            "considerations": {}
 95198          }
 95199        },
 95200        {
 95201          "type": "library",
 95202          "bom-ref": "pkg:npm/%40npmcli/metavuln-calculator@3.1.1?package-id=5a94ed44a78625cd",
 95203          "supplier": {},
 95204          "author": "GitHub Inc.",
 95205          "name": "@npmcli/metavuln-calculator",
 95206          "version": "3.1.1",
 95207          "description": "Calculate meta-vulnerabilities from package security advisories",
 95208          "licenses": [
 95209            {
 95210              "license": {
 95211                "id": "ISC"
 95212              }
 95213            }
 95214          ],
 95215          "cpe": "cpe:2.3:a:\\@npmcli\\/metavuln-calculator:\\@npmcli\\/metavuln-calculator:3.1.1:*:*:*:*:*:*:*",
 95216          "purl": "pkg:npm/%40npmcli/metavuln-calculator@3.1.1",
 95217          "swid": {
 95218            "attachment": {}
 95219          },
 95220          "pedigree": {},
 95221          "externalReferences": [
 95222            {
 95223              "url": "https://github.com/npm/metavuln-calculator.git",
 95224              "type": "distribution"
 95225            }
 95226          ],
 95227          "evidence": {},
 95228          "signature": {
 95229            "signature": {
 95230              "publicKey": {}
 95231            }
 95232          },
 95233          "modelCard": {
 95234            "modelParameters": {
 95235              "approach": {}
 95236            },
 95237            "quantitativeAnalysis": {
 95238              "graphics": {}
 95239            },
 95240            "considerations": {}
 95241          }
 95242        },
 95243        {
 95244          "type": "library",
 95245          "bom-ref": "pkg:npm/%40npmcli/move-file@2.0.1?package-id=76e6ffad7033dea3",
 95246          "supplier": {},
 95247          "author": "GitHub Inc.",
 95248          "name": "@npmcli/move-file",
 95249          "version": "2.0.1",
 95250          "description": "move a file (fork of move-file)",
 95251          "licenses": [
 95252            {
 95253              "license": {
 95254                "id": "MIT"
 95255              }
 95256            }
 95257          ],
 95258          "cpe": "cpe:2.3:a:\\@npmcli\\/move-file:\\@npmcli\\/move-file:2.0.1:*:*:*:*:*:*:*",
 95259          "purl": "pkg:npm/%40npmcli/move-file@2.0.1",
 95260          "swid": {
 95261            "attachment": {}
 95262          },
 95263          "pedigree": {},
 95264          "externalReferences": [
 95265            {
 95266              "url": "https://github.com/npm/move-file.git",
 95267              "type": "distribution"
 95268            }
 95269          ],
 95270          "evidence": {},
 95271          "signature": {
 95272            "signature": {
 95273              "publicKey": {}
 95274            }
 95275          },
 95276          "modelCard": {
 95277            "modelParameters": {
 95278              "approach": {}
 95279            },
 95280            "quantitativeAnalysis": {
 95281              "graphics": {}
 95282            },
 95283            "considerations": {}
 95284          }
 95285        },
 95286        {
 95287          "type": "library",
 95288          "bom-ref": "pkg:npm/%40npmcli/name-from-folder@1.0.1?package-id=bda8c8030d6b515f",
 95289          "supplier": {},
 95290          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
 95291          "name": "@npmcli/name-from-folder",
 95292          "version": "1.0.1",
 95293          "description": "Get the package name from a folder path",
 95294          "licenses": [
 95295            {
 95296              "license": {
 95297                "id": "ISC"
 95298              }
 95299            }
 95300          ],
 95301          "cpe": "cpe:2.3:a:\\@npmcli\\/name-from-folder:\\@npmcli\\/name-from-folder:1.0.1:*:*:*:*:*:*:*",
 95302          "purl": "pkg:npm/%40npmcli/name-from-folder@1.0.1",
 95303          "swid": {
 95304            "attachment": {}
 95305          },
 95306          "pedigree": {},
 95307          "externalReferences": [
 95308            {
 95309              "url": "git+https://github.com/npm/name-from-folder",
 95310              "type": "distribution"
 95311            }
 95312          ],
 95313          "evidence": {},
 95314          "signature": {
 95315            "signature": {
 95316              "publicKey": {}
 95317            }
 95318          },
 95319          "modelCard": {
 95320            "modelParameters": {
 95321              "approach": {}
 95322            },
 95323            "quantitativeAnalysis": {
 95324              "graphics": {}
 95325            },
 95326            "considerations": {}
 95327          }
 95328        },
 95329        {
 95330          "type": "library",
 95331          "bom-ref": "pkg:npm/%40npmcli/node-gyp@2.0.0?package-id=c9fb094d61d2ac04",
 95332          "supplier": {},
 95333          "author": "GitHub Inc.",
 95334          "name": "@npmcli/node-gyp",
 95335          "version": "2.0.0",
 95336          "description": "Tools for dealing with node-gyp packages",
 95337          "licenses": [
 95338            {
 95339              "license": {
 95340                "id": "ISC"
 95341              }
 95342            }
 95343          ],
 95344          "cpe": "cpe:2.3:a:\\@npmcli\\/node-gyp:\\@npmcli\\/node-gyp:2.0.0:*:*:*:*:*:*:*",
 95345          "purl": "pkg:npm/%40npmcli/node-gyp@2.0.0",
 95346          "swid": {
 95347            "attachment": {}
 95348          },
 95349          "pedigree": {},
 95350          "externalReferences": [
 95351            {
 95352              "url": "https://github.com/npm/node-gyp.git",
 95353              "type": "distribution"
 95354            }
 95355          ],
 95356          "evidence": {},
 95357          "signature": {
 95358            "signature": {
 95359              "publicKey": {}
 95360            }
 95361          },
 95362          "modelCard": {
 95363            "modelParameters": {
 95364              "approach": {}
 95365            },
 95366            "quantitativeAnalysis": {
 95367              "graphics": {}
 95368            },
 95369            "considerations": {}
 95370          }
 95371        },
 95372        {
 95373          "type": "library",
 95374          "bom-ref": "pkg:npm/%40npmcli/package-json@2.0.0?package-id=63189c571859bb1a",
 95375          "supplier": {},
 95376          "author": "GitHub Inc.",
 95377          "name": "@npmcli/package-json",
 95378          "version": "2.0.0",
 95379          "description": "Programmatic API to update package.json",
 95380          "licenses": [
 95381            {
 95382              "license": {
 95383                "id": "ISC"
 95384              }
 95385            }
 95386          ],
 95387          "cpe": "cpe:2.3:a:\\@npmcli\\/package-json:\\@npmcli\\/package-json:2.0.0:*:*:*:*:*:*:*",
 95388          "purl": "pkg:npm/%40npmcli/package-json@2.0.0",
 95389          "swid": {
 95390            "attachment": {}
 95391          },
 95392          "pedigree": {},
 95393          "externalReferences": [
 95394            {
 95395              "url": "https://github.com/npm/package-json.git",
 95396              "type": "distribution"
 95397            }
 95398          ],
 95399          "evidence": {},
 95400          "signature": {
 95401            "signature": {
 95402              "publicKey": {}
 95403            }
 95404          },
 95405          "modelCard": {
 95406            "modelParameters": {
 95407              "approach": {}
 95408            },
 95409            "quantitativeAnalysis": {
 95410              "graphics": {}
 95411            },
 95412            "considerations": {}
 95413          }
 95414        },
 95415        {
 95416          "type": "library",
 95417          "bom-ref": "pkg:npm/%40npmcli/promise-spawn@3.0.0?package-id=426c6e033be010cb",
 95418          "supplier": {},
 95419          "author": "GitHub Inc.",
 95420          "name": "@npmcli/promise-spawn",
 95421          "version": "3.0.0",
 95422          "description": "spawn processes the way the npm cli likes to do",
 95423          "licenses": [
 95424            {
 95425              "license": {
 95426                "id": "ISC"
 95427              }
 95428            }
 95429          ],
 95430          "cpe": "cpe:2.3:a:\\@npmcli\\/promise-spawn:\\@npmcli\\/promise-spawn:3.0.0:*:*:*:*:*:*:*",
 95431          "purl": "pkg:npm/%40npmcli/promise-spawn@3.0.0",
 95432          "swid": {
 95433            "attachment": {}
 95434          },
 95435          "pedigree": {},
 95436          "externalReferences": [
 95437            {
 95438              "url": "https://github.com/npm/promise-spawn.git",
 95439              "type": "distribution"
 95440            }
 95441          ],
 95442          "evidence": {},
 95443          "signature": {
 95444            "signature": {
 95445              "publicKey": {}
 95446            }
 95447          },
 95448          "modelCard": {
 95449            "modelParameters": {
 95450              "approach": {}
 95451            },
 95452            "quantitativeAnalysis": {
 95453              "graphics": {}
 95454            },
 95455            "considerations": {}
 95456          }
 95457        },
 95458        {
 95459          "type": "library",
 95460          "bom-ref": "pkg:npm/%40npmcli/query@1.2.0?package-id=e71e78476048755c",
 95461          "supplier": {},
 95462          "author": "GitHub Inc.",
 95463          "name": "@npmcli/query",
 95464          "version": "1.2.0",
 95465          "description": "npm query parser and tools",
 95466          "licenses": [
 95467            {
 95468              "license": {
 95469                "id": "ISC"
 95470              }
 95471            }
 95472          ],
 95473          "cpe": "cpe:2.3:a:\\@npmcli\\/query:\\@npmcli\\/query:1.2.0:*:*:*:*:*:*:*",
 95474          "purl": "pkg:npm/%40npmcli/query@1.2.0",
 95475          "swid": {
 95476            "attachment": {}
 95477          },
 95478          "pedigree": {},
 95479          "externalReferences": [
 95480            {
 95481              "url": "https://github.com/npm/query.git",
 95482              "type": "distribution"
 95483            }
 95484          ],
 95485          "evidence": {},
 95486          "signature": {
 95487            "signature": {
 95488              "publicKey": {}
 95489            }
 95490          },
 95491          "modelCard": {
 95492            "modelParameters": {
 95493              "approach": {}
 95494            },
 95495            "quantitativeAnalysis": {
 95496              "graphics": {}
 95497            },
 95498            "considerations": {}
 95499          }
 95500        },
 95501        {
 95502          "type": "library",
 95503          "bom-ref": "pkg:npm/%40npmcli/run-script@4.2.1?package-id=a13d191f5a0789d1",
 95504          "supplier": {},
 95505          "author": "GitHub Inc.",
 95506          "name": "@npmcli/run-script",
 95507          "version": "4.2.1",
 95508          "description": "Run a lifecycle script for a package (descendant of npm-lifecycle)",
 95509          "licenses": [
 95510            {
 95511              "license": {
 95512                "id": "ISC"
 95513              }
 95514            }
 95515          ],
 95516          "cpe": "cpe:2.3:a:\\@npmcli\\/run-script:\\@npmcli\\/run-script:4.2.1:*:*:*:*:*:*:*",
 95517          "purl": "pkg:npm/%40npmcli/run-script@4.2.1",
 95518          "swid": {
 95519            "attachment": {}
 95520          },
 95521          "pedigree": {},
 95522          "externalReferences": [
 95523            {
 95524              "url": "https://github.com/npm/run-script.git",
 95525              "type": "distribution"
 95526            }
 95527          ],
 95528          "evidence": {},
 95529          "signature": {
 95530            "signature": {
 95531              "publicKey": {}
 95532            }
 95533          },
 95534          "modelCard": {
 95535            "modelParameters": {
 95536              "approach": {}
 95537            },
 95538            "quantitativeAnalysis": {
 95539              "graphics": {}
 95540            },
 95541            "considerations": {}
 95542          }
 95543        },
 95544        {
 95545          "type": "library",
 95546          "bom-ref": "pkg:npm/%40tootallnate/once@2.0.0?package-id=5edbc75b01ae9167",
 95547          "supplier": {},
 95548          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
 95549          "name": "@tootallnate/once",
 95550          "version": "2.0.0",
 95551          "description": "Creates a Promise that waits for a single event",
 95552          "licenses": [
 95553            {
 95554              "license": {
 95555                "id": "MIT"
 95556              }
 95557            }
 95558          ],
 95559          "cpe": "cpe:2.3:a:\\@tootallnate\\/once:\\@tootallnate\\/once:2.0.0:*:*:*:*:*:*:*",
 95560          "purl": "pkg:npm/%40tootallnate/once@2.0.0",
 95561          "swid": {
 95562            "attachment": {}
 95563          },
 95564          "pedigree": {},
 95565          "externalReferences": [
 95566            {
 95567              "url": "git://github.com/TooTallNate/once.git",
 95568              "type": "distribution"
 95569            }
 95570          ],
 95571          "evidence": {},
 95572          "signature": {
 95573            "signature": {
 95574              "publicKey": {}
 95575            }
 95576          },
 95577          "modelCard": {
 95578            "modelParameters": {
 95579              "approach": {}
 95580            },
 95581            "quantitativeAnalysis": {
 95582              "graphics": {}
 95583            },
 95584            "considerations": {}
 95585          }
 95586        },
 95587        {
 95588          "type": "library",
 95589          "bom-ref": "pkg:npm/%40yarnpkg/lockfile@1.1.0?package-id=1791c7462cb920e",
 95590          "supplier": {},
 95591          "name": "@yarnpkg/lockfile",
 95592          "version": "1.1.0",
 95593          "description": "The parser/stringifier for Yarn lockfiles.",
 95594          "licenses": [
 95595            {
 95596              "license": {
 95597                "id": "BSD-2-Clause"
 95598              }
 95599            }
 95600          ],
 95601          "cpe": "cpe:2.3:a:\\@yarnpkg\\/lockfile:\\@yarnpkg\\/lockfile:1.1.0:*:*:*:*:*:*:*",
 95602          "purl": "pkg:npm/%40yarnpkg/lockfile@1.1.0",
 95603          "swid": {
 95604            "attachment": {}
 95605          },
 95606          "pedigree": {},
 95607          "externalReferences": [
 95608            {
 95609              "url": "https://github.com/yarnpkg/yarn/blob/master/packages/lockfile",
 95610              "type": "distribution"
 95611            }
 95612          ],
 95613          "evidence": {},
 95614          "signature": {
 95615            "signature": {
 95616              "publicKey": {}
 95617            }
 95618          },
 95619          "modelCard": {
 95620            "modelParameters": {
 95621              "approach": {}
 95622            },
 95623            "quantitativeAnalysis": {
 95624              "graphics": {}
 95625            },
 95626            "considerations": {}
 95627          }
 95628        },
 95629        {
 95630          "type": "library",
 95631          "bom-ref": "pkg:npm/%40zxing/text-encoding@0.9.0?package-id=25493195cc8981a3",
 95632          "supplier": {},
 95633          "author": "Joshua Bell \u003cinexorabletash@gmail.com\u003e",
 95634          "name": "@zxing/text-encoding",
 95635          "version": "0.9.0",
 95636          "description": "Polyfill for the Encoding Living Standard's API.",
 95637          "licenses": [
 95638            {
 95639              "license": {
 95640                "name": "(Unlicense OR Apache-2.0)"
 95641              }
 95642            }
 95643          ],
 95644          "cpe": "cpe:2.3:a:\\@zxing\\/text-encoding:\\@zxing\\/text-encoding:0.9.0:*:*:*:*:*:*:*",
 95645          "purl": "pkg:npm/%40zxing/text-encoding@0.9.0",
 95646          "swid": {
 95647            "attachment": {}
 95648          },
 95649          "pedigree": {},
 95650          "externalReferences": [
 95651            {
 95652              "url": "https://github.com/zxing-js/text-encoding.git",
 95653              "type": "distribution"
 95654            },
 95655            {
 95656              "url": "https://github.com/inexorabletash/text-encoding",
 95657              "type": "website"
 95658            }
 95659          ],
 95660          "evidence": {},
 95661          "signature": {
 95662            "signature": {
 95663              "publicKey": {}
 95664            }
 95665          },
 95666          "modelCard": {
 95667            "modelParameters": {
 95668              "approach": {}
 95669            },
 95670            "quantitativeAnalysis": {
 95671              "graphics": {}
 95672            },
 95673            "considerations": {}
 95674          }
 95675        },
 95676        {
 95677          "type": "library",
 95678          "bom-ref": "pkg:npm/abbrev@1.1.1?package-id=98be1cad3f4d1d11",
 95679          "supplier": {},
 95680          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
 95681          "name": "abbrev",
 95682          "version": "1.1.1",
 95683          "description": "Like ruby's abbrev module, but in js",
 95684          "licenses": [
 95685            {
 95686              "license": {
 95687                "id": "ISC"
 95688              }
 95689            }
 95690          ],
 95691          "cpe": "cpe:2.3:a:abbrev:abbrev:1.1.1:*:*:*:*:*:*:*",
 95692          "purl": "pkg:npm/abbrev@1.1.1",
 95693          "swid": {
 95694            "attachment": {}
 95695          },
 95696          "pedigree": {},
 95697          "externalReferences": [
 95698            {
 95699              "url": "http://github.com/isaacs/abbrev-js",
 95700              "type": "distribution"
 95701            }
 95702          ],
 95703          "evidence": {},
 95704          "signature": {
 95705            "signature": {
 95706              "publicKey": {}
 95707            }
 95708          },
 95709          "modelCard": {
 95710            "modelParameters": {
 95711              "approach": {}
 95712            },
 95713            "quantitativeAnalysis": {
 95714              "graphics": {}
 95715            },
 95716            "considerations": {}
 95717          }
 95718        },
 95719        {
 95720          "type": "library",
 95721          "bom-ref": "pkg:npm/accepts@1.3.8?package-id=b001a70346b0612b",
 95722          "supplier": {},
 95723          "name": "accepts",
 95724          "version": "1.3.8",
 95725          "description": "Higher-level content negotiation",
 95726          "licenses": [
 95727            {
 95728              "license": {
 95729                "id": "MIT"
 95730              }
 95731            }
 95732          ],
 95733          "cpe": "cpe:2.3:a:accepts:accepts:1.3.8:*:*:*:*:*:*:*",
 95734          "purl": "pkg:npm/accepts@1.3.8",
 95735          "swid": {
 95736            "attachment": {}
 95737          },
 95738          "pedigree": {},
 95739          "externalReferences": [
 95740            {
 95741              "url": "jshttp/accepts",
 95742              "type": "distribution"
 95743            }
 95744          ],
 95745          "evidence": {},
 95746          "signature": {
 95747            "signature": {
 95748              "publicKey": {}
 95749            }
 95750          },
 95751          "modelCard": {
 95752            "modelParameters": {
 95753              "approach": {}
 95754            },
 95755            "quantitativeAnalysis": {
 95756              "graphics": {}
 95757            },
 95758            "considerations": {}
 95759          }
 95760        },
 95761        {
 95762          "type": "library",
 95763          "bom-ref": "pkg:npm/agent-base@6.0.2?package-id=4b0b5c9ee7d8fc08",
 95764          "supplier": {},
 95765          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
 95766          "name": "agent-base",
 95767          "version": "6.0.2",
 95768          "description": "Turn a function into an `http.Agent` instance",
 95769          "licenses": [
 95770            {
 95771              "license": {
 95772                "id": "MIT"
 95773              }
 95774            }
 95775          ],
 95776          "cpe": "cpe:2.3:a:TooTallNate:agent-base:6.0.2:*:*:*:*:*:*:*",
 95777          "purl": "pkg:npm/agent-base@6.0.2",
 95778          "swid": {
 95779            "attachment": {}
 95780          },
 95781          "pedigree": {},
 95782          "externalReferences": [
 95783            {
 95784              "url": "git://github.com/TooTallNate/node-agent-base.git",
 95785              "type": "distribution"
 95786            }
 95787          ],
 95788          "evidence": {},
 95789          "signature": {
 95790            "signature": {
 95791              "publicKey": {}
 95792            }
 95793          },
 95794          "modelCard": {
 95795            "modelParameters": {
 95796              "approach": {}
 95797            },
 95798            "quantitativeAnalysis": {
 95799              "graphics": {}
 95800            },
 95801            "considerations": {}
 95802          }
 95803        },
 95804        {
 95805          "type": "library",
 95806          "bom-ref": "pkg:npm/agentkeepalive@4.2.1?package-id=37fa9bcd67324d6e",
 95807          "supplier": {},
 95808          "author": "fengmk2 \u003cfengmk2@gmail.com\u003e (https://fengmk2.com)",
 95809          "name": "agentkeepalive",
 95810          "version": "4.2.1",
 95811          "description": "Missing keepalive http.Agent",
 95812          "licenses": [
 95813            {
 95814              "license": {
 95815                "id": "MIT"
 95816              }
 95817            }
 95818          ],
 95819          "cpe": "cpe:2.3:a:agentkeepalive:agentkeepalive:4.2.1:*:*:*:*:*:*:*",
 95820          "purl": "pkg:npm/agentkeepalive@4.2.1",
 95821          "swid": {
 95822            "attachment": {}
 95823          },
 95824          "pedigree": {},
 95825          "externalReferences": [
 95826            {
 95827              "url": "git://github.com/node-modules/agentkeepalive.git",
 95828              "type": "distribution"
 95829            }
 95830          ],
 95831          "evidence": {},
 95832          "signature": {
 95833            "signature": {
 95834              "publicKey": {}
 95835            }
 95836          },
 95837          "modelCard": {
 95838            "modelParameters": {
 95839              "approach": {}
 95840            },
 95841            "quantitativeAnalysis": {
 95842              "graphics": {}
 95843            },
 95844            "considerations": {}
 95845          }
 95846        },
 95847        {
 95848          "type": "library",
 95849          "bom-ref": "pkg:npm/aggregate-error@3.1.0?package-id=b1b74a520919b83f",
 95850          "supplier": {},
 95851          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
 95852          "name": "aggregate-error",
 95853          "version": "3.1.0",
 95854          "description": "Create an error from multiple errors",
 95855          "licenses": [
 95856            {
 95857              "license": {
 95858                "id": "MIT"
 95859              }
 95860            }
 95861          ],
 95862          "cpe": "cpe:2.3:a:aggregate-error:aggregate-error:3.1.0:*:*:*:*:*:*:*",
 95863          "purl": "pkg:npm/aggregate-error@3.1.0",
 95864          "swid": {
 95865            "attachment": {}
 95866          },
 95867          "pedigree": {},
 95868          "externalReferences": [
 95869            {
 95870              "url": "sindresorhus/aggregate-error",
 95871              "type": "distribution"
 95872            }
 95873          ],
 95874          "evidence": {},
 95875          "signature": {
 95876            "signature": {
 95877              "publicKey": {}
 95878            }
 95879          },
 95880          "modelCard": {
 95881            "modelParameters": {
 95882              "approach": {}
 95883            },
 95884            "quantitativeAnalysis": {
 95885              "graphics": {}
 95886            },
 95887            "considerations": {}
 95888          }
 95889        },
 95890        {
 95891          "type": "library",
 95892          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=61eac5ce8105d394",
 95893          "supplier": {},
 95894          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 95895          "name": "alpine-baselayout",
 95896          "version": "3.2.0-r23",
 95897          "description": "Alpine base dir structure and init scripts",
 95898          "licenses": [
 95899            {
 95900              "license": {
 95901                "id": "GPL-2.0-only"
 95902              }
 95903            }
 95904          ],
 95905          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r23:*:*:*:*:*:*:*",
 95906          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5",
 95907          "swid": {
 95908            "attachment": {}
 95909          },
 95910          "pedigree": {},
 95911          "externalReferences": [
 95912            {
 95913              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 95914              "type": "distribution"
 95915            }
 95916          ],
 95917          "evidence": {},
 95918          "signature": {
 95919            "signature": {
 95920              "publicKey": {}
 95921            }
 95922          },
 95923          "modelCard": {
 95924            "modelParameters": {
 95925              "approach": {}
 95926            },
 95927            "quantitativeAnalysis": {
 95928              "graphics": {}
 95929            },
 95930            "considerations": {}
 95931          }
 95932        },
 95933        {
 95934          "type": "library",
 95935          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5\u0026package-id=e8c6fcc3a282ed4f",
 95936          "supplier": {},
 95937          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 95938          "name": "alpine-baselayout-data",
 95939          "version": "3.2.0-r23",
 95940          "description": "Alpine base dir structure and init scripts",
 95941          "licenses": [
 95942            {
 95943              "license": {
 95944                "id": "GPL-2.0-only"
 95945              }
 95946            }
 95947          ],
 95948          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.2.0-r23:*:*:*:*:*:*:*",
 95949          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5",
 95950          "swid": {
 95951            "attachment": {}
 95952          },
 95953          "pedigree": {},
 95954          "externalReferences": [
 95955            {
 95956              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
 95957              "type": "distribution"
 95958            }
 95959          ],
 95960          "evidence": {},
 95961          "signature": {
 95962            "signature": {
 95963              "publicKey": {}
 95964            }
 95965          },
 95966          "modelCard": {
 95967            "modelParameters": {
 95968              "approach": {}
 95969            },
 95970            "quantitativeAnalysis": {
 95971              "graphics": {}
 95972            },
 95973            "considerations": {}
 95974          }
 95975        },
 95976        {
 95977          "type": "library",
 95978          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=82d183eb300978cc",
 95979          "supplier": {},
 95980          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 95981          "name": "alpine-keys",
 95982          "version": "2.4-r1",
 95983          "description": "Public keys for Alpine Linux packages",
 95984          "licenses": [
 95985            {
 95986              "license": {
 95987                "id": "MIT"
 95988              }
 95989            }
 95990          ],
 95991          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
 95992          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5",
 95993          "swid": {
 95994            "attachment": {}
 95995          },
 95996          "pedigree": {},
 95997          "externalReferences": [
 95998            {
 95999              "url": "https://alpinelinux.org",
 96000              "type": "distribution"
 96001            }
 96002          ],
 96003          "evidence": {},
 96004          "signature": {
 96005            "signature": {
 96006              "publicKey": {}
 96007            }
 96008          },
 96009          "modelCard": {
 96010            "modelParameters": {
 96011              "approach": {}
 96012            },
 96013            "quantitativeAnalysis": {
 96014              "graphics": {}
 96015            },
 96016            "considerations": {}
 96017          }
 96018        },
 96019        {
 96020          "type": "library",
 96021          "bom-ref": "pkg:npm/ansi-regex@5.0.1?package-id=fe78ee8372cda3ef",
 96022          "supplier": {},
 96023          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
 96024          "name": "ansi-regex",
 96025          "version": "5.0.1",
 96026          "description": "Regular expression for matching ANSI escape codes",
 96027          "licenses": [
 96028            {
 96029              "license": {
 96030                "id": "MIT"
 96031              }
 96032            }
 96033          ],
 96034          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:5.0.1:*:*:*:*:*:*:*",
 96035          "purl": "pkg:npm/ansi-regex@5.0.1",
 96036          "swid": {
 96037            "attachment": {}
 96038          },
 96039          "pedigree": {},
 96040          "externalReferences": [
 96041            {
 96042              "url": "chalk/ansi-regex",
 96043              "type": "distribution"
 96044            }
 96045          ],
 96046          "evidence": {},
 96047          "signature": {
 96048            "signature": {
 96049              "publicKey": {}
 96050            }
 96051          },
 96052          "modelCard": {
 96053            "modelParameters": {
 96054              "approach": {}
 96055            },
 96056            "quantitativeAnalysis": {
 96057              "graphics": {}
 96058            },
 96059            "considerations": {}
 96060          }
 96061        },
 96062        {
 96063          "type": "library",
 96064          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=e3f310fd74532509",
 96065          "supplier": {},
 96066          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
 96067          "name": "ansi-styles",
 96068          "version": "4.3.0",
 96069          "description": "ANSI escape codes for styling strings in the terminal",
 96070          "licenses": [
 96071            {
 96072              "license": {
 96073                "id": "MIT"
 96074              }
 96075            }
 96076          ],
 96077          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
 96078          "purl": "pkg:npm/ansi-styles@4.3.0",
 96079          "swid": {
 96080            "attachment": {}
 96081          },
 96082          "pedigree": {},
 96083          "externalReferences": [
 96084            {
 96085              "url": "chalk/ansi-styles",
 96086              "type": "distribution"
 96087            }
 96088          ],
 96089          "evidence": {},
 96090          "signature": {
 96091            "signature": {
 96092              "publicKey": {}
 96093            }
 96094          },
 96095          "modelCard": {
 96096            "modelParameters": {
 96097              "approach": {}
 96098            },
 96099            "quantitativeAnalysis": {
 96100              "graphics": {}
 96101            },
 96102            "considerations": {}
 96103          }
 96104        },
 96105        {
 96106          "type": "library",
 96107          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=6fa84f08aad36ac8",
 96108          "supplier": {},
 96109          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
 96110          "name": "ansi-styles",
 96111          "version": "4.3.0",
 96112          "description": "ANSI escape codes for styling strings in the terminal",
 96113          "licenses": [
 96114            {
 96115              "license": {
 96116                "id": "MIT"
 96117              }
 96118            }
 96119          ],
 96120          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
 96121          "purl": "pkg:npm/ansi-styles@4.3.0",
 96122          "swid": {
 96123            "attachment": {}
 96124          },
 96125          "pedigree": {},
 96126          "externalReferences": [
 96127            {
 96128              "url": "chalk/ansi-styles",
 96129              "type": "distribution"
 96130            }
 96131          ],
 96132          "evidence": {},
 96133          "signature": {
 96134            "signature": {
 96135              "publicKey": {}
 96136            }
 96137          },
 96138          "modelCard": {
 96139            "modelParameters": {
 96140              "approach": {}
 96141            },
 96142            "quantitativeAnalysis": {
 96143              "graphics": {}
 96144            },
 96145            "considerations": {}
 96146          }
 96147        },
 96148        {
 96149          "type": "library",
 96150          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=42d502b764a37310",
 96151          "supplier": {},
 96152          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 96153          "name": "apk-tools",
 96154          "version": "2.12.9-r3",
 96155          "description": "Alpine Package Keeper - package manager for alpine",
 96156          "licenses": [
 96157            {
 96158              "license": {
 96159                "id": "GPL-2.0-only"
 96160              }
 96161            }
 96162          ],
 96163          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.9-r3:*:*:*:*:*:*:*",
 96164          "purl": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5",
 96165          "swid": {
 96166            "attachment": {}
 96167          },
 96168          "pedigree": {},
 96169          "externalReferences": [
 96170            {
 96171              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
 96172              "type": "distribution"
 96173            }
 96174          ],
 96175          "evidence": {},
 96176          "signature": {
 96177            "signature": {
 96178              "publicKey": {}
 96179            }
 96180          },
 96181          "modelCard": {
 96182            "modelParameters": {
 96183              "approach": {}
 96184            },
 96185            "quantitativeAnalysis": {
 96186              "graphics": {}
 96187            },
 96188            "considerations": {}
 96189          }
 96190        },
 96191        {
 96192          "type": "library",
 96193          "bom-ref": "pkg:npm/aproba@2.0.0?package-id=d11111a04d810227",
 96194          "supplier": {},
 96195          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
 96196          "name": "aproba",
 96197          "version": "2.0.0",
 96198          "description": "A ridiculously light-weight argument validator (now browser friendly)",
 96199          "licenses": [
 96200            {
 96201              "license": {
 96202                "id": "ISC"
 96203              }
 96204            }
 96205          ],
 96206          "cpe": "cpe:2.3:a:aproba:aproba:2.0.0:*:*:*:*:*:*:*",
 96207          "purl": "pkg:npm/aproba@2.0.0",
 96208          "swid": {
 96209            "attachment": {}
 96210          },
 96211          "pedigree": {},
 96212          "externalReferences": [
 96213            {
 96214              "url": "https://github.com/iarna/aproba",
 96215              "type": "distribution"
 96216            },
 96217            {
 96218              "url": "https://github.com/iarna/aproba",
 96219              "type": "website"
 96220            }
 96221          ],
 96222          "evidence": {},
 96223          "signature": {
 96224            "signature": {
 96225              "publicKey": {}
 96226            }
 96227          },
 96228          "modelCard": {
 96229            "modelParameters": {
 96230              "approach": {}
 96231            },
 96232            "quantitativeAnalysis": {
 96233              "graphics": {}
 96234            },
 96235            "considerations": {}
 96236          }
 96237        },
 96238        {
 96239          "type": "library",
 96240          "bom-ref": "pkg:npm/archy@1.0.0?package-id=a1e7fd77fec54095",
 96241          "supplier": {},
 96242          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
 96243          "name": "archy",
 96244          "version": "1.0.0",
 96245          "description": "render nested hierarchies `npm ls` style with unicode pipes",
 96246          "licenses": [
 96247            {
 96248              "license": {
 96249                "id": "MIT"
 96250              }
 96251            }
 96252          ],
 96253          "cpe": "cpe:2.3:a:substack:archy:1.0.0:*:*:*:*:*:*:*",
 96254          "purl": "pkg:npm/archy@1.0.0",
 96255          "swid": {
 96256            "attachment": {}
 96257          },
 96258          "pedigree": {},
 96259          "externalReferences": [
 96260            {
 96261              "url": "http://github.com/substack/node-archy.git",
 96262              "type": "distribution"
 96263            }
 96264          ],
 96265          "evidence": {},
 96266          "signature": {
 96267            "signature": {
 96268              "publicKey": {}
 96269            }
 96270          },
 96271          "modelCard": {
 96272            "modelParameters": {
 96273              "approach": {}
 96274            },
 96275            "quantitativeAnalysis": {
 96276              "graphics": {}
 96277            },
 96278            "considerations": {}
 96279          }
 96280        },
 96281        {
 96282          "type": "library",
 96283          "bom-ref": "pkg:npm/are-we-there-yet@3.0.1?package-id=d7ea73c2e385c95d",
 96284          "supplier": {},
 96285          "author": "GitHub Inc.",
 96286          "name": "are-we-there-yet",
 96287          "version": "3.0.1",
 96288          "description": "Keep track of the overall completion of many disparate processes",
 96289          "licenses": [
 96290            {
 96291              "license": {
 96292                "id": "ISC"
 96293              }
 96294            }
 96295          ],
 96296          "cpe": "cpe:2.3:a:are-we-there-yet:are-we-there-yet:3.0.1:*:*:*:*:*:*:*",
 96297          "purl": "pkg:npm/are-we-there-yet@3.0.1",
 96298          "swid": {
 96299            "attachment": {}
 96300          },
 96301          "pedigree": {},
 96302          "externalReferences": [
 96303            {
 96304              "url": "https://github.com/npm/are-we-there-yet.git",
 96305              "type": "distribution"
 96306            },
 96307            {
 96308              "url": "https://github.com/npm/are-we-there-yet",
 96309              "type": "website"
 96310            }
 96311          ],
 96312          "evidence": {},
 96313          "signature": {
 96314            "signature": {
 96315              "publicKey": {}
 96316            }
 96317          },
 96318          "modelCard": {
 96319            "modelParameters": {
 96320              "approach": {}
 96321            },
 96322            "quantitativeAnalysis": {
 96323              "graphics": {}
 96324            },
 96325            "considerations": {}
 96326          }
 96327        },
 96328        {
 96329          "type": "library",
 96330          "bom-ref": "pkg:npm/array-flatten@1.1.1?package-id=169fa984c33ff9f6",
 96331          "supplier": {},
 96332          "author": "Blake Embrey \u003chello@blakeembrey.com\u003e (http://blakeembrey.me)",
 96333          "name": "array-flatten",
 96334          "version": "1.1.1",
 96335          "description": "Flatten an array of nested arrays into a single flat array",
 96336          "licenses": [
 96337            {
 96338              "license": {
 96339                "id": "MIT"
 96340              }
 96341            }
 96342          ],
 96343          "cpe": "cpe:2.3:a:array-flatten:array-flatten:1.1.1:*:*:*:*:*:*:*",
 96344          "purl": "pkg:npm/array-flatten@1.1.1",
 96345          "swid": {
 96346            "attachment": {}
 96347          },
 96348          "pedigree": {},
 96349          "externalReferences": [
 96350            {
 96351              "url": "git://github.com/blakeembrey/array-flatten.git",
 96352              "type": "distribution"
 96353            },
 96354            {
 96355              "url": "https://github.com/blakeembrey/array-flatten",
 96356              "type": "website"
 96357            }
 96358          ],
 96359          "evidence": {},
 96360          "signature": {
 96361            "signature": {
 96362              "publicKey": {}
 96363            }
 96364          },
 96365          "modelCard": {
 96366            "modelParameters": {
 96367              "approach": {}
 96368            },
 96369            "quantitativeAnalysis": {
 96370              "graphics": {}
 96371            },
 96372            "considerations": {}
 96373          }
 96374        },
 96375        {
 96376          "type": "library",
 96377          "bom-ref": "pkg:npm/asap@2.0.6?package-id=4069b89e24646503",
 96378          "supplier": {},
 96379          "name": "asap",
 96380          "version": "2.0.6",
 96381          "description": "High-priority task queue for Node.js and browsers",
 96382          "licenses": [
 96383            {
 96384              "license": {
 96385                "id": "MIT"
 96386              }
 96387            }
 96388          ],
 96389          "cpe": "cpe:2.3:a:kriskowal:asap:2.0.6:*:*:*:*:*:*:*",
 96390          "purl": "pkg:npm/asap@2.0.6",
 96391          "swid": {
 96392            "attachment": {}
 96393          },
 96394          "pedigree": {},
 96395          "externalReferences": [
 96396            {
 96397              "url": "https://github.com/kriskowal/asap.git",
 96398              "type": "distribution"
 96399            }
 96400          ],
 96401          "evidence": {},
 96402          "signature": {
 96403            "signature": {
 96404              "publicKey": {}
 96405            }
 96406          },
 96407          "modelCard": {
 96408            "modelParameters": {
 96409              "approach": {}
 96410            },
 96411            "quantitativeAnalysis": {
 96412              "graphics": {}
 96413            },
 96414            "considerations": {}
 96415          }
 96416        },
 96417        {
 96418          "type": "library",
 96419          "bom-ref": "pkg:npm/asn1.js@5.4.1?package-id=e24b6ffc41aa39e5",
 96420          "supplier": {},
 96421          "author": "Fedor Indutny",
 96422          "name": "asn1.js",
 96423          "version": "5.4.1",
 96424          "description": "ASN.1 encoder and decoder",
 96425          "licenses": [
 96426            {
 96427              "license": {
 96428                "id": "MIT"
 96429              }
 96430            }
 96431          ],
 96432          "cpe": "cpe:2.3:a:asn1.js:asn1.js:5.4.1:*:*:*:*:*:*:*",
 96433          "purl": "pkg:npm/asn1.js@5.4.1",
 96434          "swid": {
 96435            "attachment": {}
 96436          },
 96437          "pedigree": {},
 96438          "externalReferences": [
 96439            {
 96440              "url": "git@github.com:indutny/asn1.js",
 96441              "type": "distribution"
 96442            },
 96443            {
 96444              "url": "https://github.com/indutny/asn1.js",
 96445              "type": "website"
 96446            }
 96447          ],
 96448          "evidence": {},
 96449          "signature": {
 96450            "signature": {
 96451              "publicKey": {}
 96452            }
 96453          },
 96454          "modelCard": {
 96455            "modelParameters": {
 96456              "approach": {}
 96457            },
 96458            "quantitativeAnalysis": {
 96459              "graphics": {}
 96460            },
 96461            "considerations": {}
 96462          }
 96463        },
 96464        {
 96465          "type": "library",
 96466          "bom-ref": "pkg:npm/async@3.2.4?package-id=231b7b86b151b693",
 96467          "supplier": {},
 96468          "author": "Caolan McMahon",
 96469          "name": "async",
 96470          "version": "3.2.4",
 96471          "description": "Higher-order functions and common patterns for asynchronous code",
 96472          "licenses": [
 96473            {
 96474              "license": {
 96475                "id": "MIT"
 96476              }
 96477            }
 96478          ],
 96479          "cpe": "cpe:2.3:a:caolan:async:3.2.4:*:*:*:*:*:*:*",
 96480          "purl": "pkg:npm/async@3.2.4",
 96481          "swid": {
 96482            "attachment": {}
 96483          },
 96484          "pedigree": {},
 96485          "externalReferences": [
 96486            {
 96487              "url": "https://github.com/caolan/async.git",
 96488              "type": "distribution"
 96489            },
 96490            {
 96491              "url": "https://caolan.github.io/async/",
 96492              "type": "website"
 96493            }
 96494          ],
 96495          "evidence": {},
 96496          "signature": {
 96497            "signature": {
 96498              "publicKey": {}
 96499            }
 96500          },
 96501          "modelCard": {
 96502            "modelParameters": {
 96503              "approach": {}
 96504            },
 96505            "quantitativeAnalysis": {
 96506              "graphics": {}
 96507            },
 96508            "considerations": {}
 96509          }
 96510        },
 96511        {
 96512          "type": "library",
 96513          "bom-ref": "pkg:npm/at-least-node@1.0.0?package-id=f0f009eb01eee759",
 96514          "supplier": {},
 96515          "author": "Ryan Zimmerman \u003copensrc@ryanzim.com\u003e",
 96516          "name": "at-least-node",
 96517          "version": "1.0.0",
 96518          "description": "Lightweight Node.js version sniffing/comparison",
 96519          "licenses": [
 96520            {
 96521              "license": {
 96522                "id": "ISC"
 96523              }
 96524            }
 96525          ],
 96526          "cpe": "cpe:2.3:a:at-least-node:at-least-node:1.0.0:*:*:*:*:*:*:*",
 96527          "purl": "pkg:npm/at-least-node@1.0.0",
 96528          "swid": {
 96529            "attachment": {}
 96530          },
 96531          "pedigree": {},
 96532          "externalReferences": [
 96533            {
 96534              "url": "git+https://github.com/RyanZim/at-least-node.git",
 96535              "type": "distribution"
 96536            },
 96537            {
 96538              "url": "https://github.com/RyanZim/at-least-node#readme",
 96539              "type": "website"
 96540            }
 96541          ],
 96542          "evidence": {},
 96543          "signature": {
 96544            "signature": {
 96545              "publicKey": {}
 96546            }
 96547          },
 96548          "modelCard": {
 96549            "modelParameters": {
 96550              "approach": {}
 96551            },
 96552            "quantitativeAnalysis": {
 96553              "graphics": {}
 96554            },
 96555            "considerations": {}
 96556          }
 96557        },
 96558        {
 96559          "type": "library",
 96560          "bom-ref": "pkg:npm/available-typed-arrays@1.0.5?package-id=8a70c8639b21c4d5",
 96561          "supplier": {},
 96562          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
 96563          "name": "available-typed-arrays",
 96564          "version": "1.0.5",
 96565          "description": "Returns an array of Typed Array names that are available in the current environment",
 96566          "licenses": [
 96567            {
 96568              "license": {
 96569                "id": "MIT"
 96570              }
 96571            }
 96572          ],
 96573          "cpe": "cpe:2.3:a:available-typed-arrays:available-typed-arrays:1.0.5:*:*:*:*:*:*:*",
 96574          "purl": "pkg:npm/available-typed-arrays@1.0.5",
 96575          "swid": {
 96576            "attachment": {}
 96577          },
 96578          "pedigree": {},
 96579          "externalReferences": [
 96580            {
 96581              "url": "git+https://github.com/inspect-js/available-typed-arrays.git",
 96582              "type": "distribution"
 96583            },
 96584            {
 96585              "url": "https://github.com/inspect-js/available-typed-arrays#readme",
 96586              "type": "website"
 96587            }
 96588          ],
 96589          "evidence": {},
 96590          "signature": {
 96591            "signature": {
 96592              "publicKey": {}
 96593            }
 96594          },
 96595          "modelCard": {
 96596            "modelParameters": {
 96597              "approach": {}
 96598            },
 96599            "quantitativeAnalysis": {
 96600              "graphics": {}
 96601            },
 96602            "considerations": {}
 96603          }
 96604        },
 96605        {
 96606          "type": "library",
 96607          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=c15b2106d0ae19d4",
 96608          "supplier": {},
 96609          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
 96610          "name": "balanced-match",
 96611          "version": "1.0.2",
 96612          "description": "Match balanced character pairs, like \"{\" and \"}\"",
 96613          "licenses": [
 96614            {
 96615              "license": {
 96616                "id": "MIT"
 96617              }
 96618            }
 96619          ],
 96620          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
 96621          "purl": "pkg:npm/balanced-match@1.0.2",
 96622          "swid": {
 96623            "attachment": {}
 96624          },
 96625          "pedigree": {},
 96626          "externalReferences": [
 96627            {
 96628              "url": "git://github.com/juliangruber/balanced-match.git",
 96629              "type": "distribution"
 96630            },
 96631            {
 96632              "url": "https://github.com/juliangruber/balanced-match",
 96633              "type": "website"
 96634            }
 96635          ],
 96636          "evidence": {},
 96637          "signature": {
 96638            "signature": {
 96639              "publicKey": {}
 96640            }
 96641          },
 96642          "modelCard": {
 96643            "modelParameters": {
 96644              "approach": {}
 96645            },
 96646            "quantitativeAnalysis": {
 96647              "graphics": {}
 96648            },
 96649            "considerations": {}
 96650          }
 96651        },
 96652        {
 96653          "type": "library",
 96654          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=6ce660a02f86f891",
 96655          "supplier": {},
 96656          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
 96657          "name": "balanced-match",
 96658          "version": "1.0.2",
 96659          "description": "Match balanced character pairs, like \"{\" and \"}\"",
 96660          "licenses": [
 96661            {
 96662              "license": {
 96663                "id": "MIT"
 96664              }
 96665            }
 96666          ],
 96667          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
 96668          "purl": "pkg:npm/balanced-match@1.0.2",
 96669          "swid": {
 96670            "attachment": {}
 96671          },
 96672          "pedigree": {},
 96673          "externalReferences": [
 96674            {
 96675              "url": "git://github.com/juliangruber/balanced-match.git",
 96676              "type": "distribution"
 96677            },
 96678            {
 96679              "url": "https://github.com/juliangruber/balanced-match",
 96680              "type": "website"
 96681            }
 96682          ],
 96683          "evidence": {},
 96684          "signature": {
 96685            "signature": {
 96686              "publicKey": {}
 96687            }
 96688          },
 96689          "modelCard": {
 96690            "modelParameters": {
 96691              "approach": {}
 96692            },
 96693            "quantitativeAnalysis": {
 96694              "graphics": {}
 96695            },
 96696            "considerations": {}
 96697          }
 96698        },
 96699        {
 96700          "type": "library",
 96701          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=8db1f18b661f67ae",
 96702          "supplier": {},
 96703          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
 96704          "name": "balanced-match",
 96705          "version": "1.0.2",
 96706          "description": "Match balanced character pairs, like \"{\" and \"}\"",
 96707          "licenses": [
 96708            {
 96709              "license": {
 96710                "id": "MIT"
 96711              }
 96712            }
 96713          ],
 96714          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
 96715          "purl": "pkg:npm/balanced-match@1.0.2",
 96716          "swid": {
 96717            "attachment": {}
 96718          },
 96719          "pedigree": {},
 96720          "externalReferences": [
 96721            {
 96722              "url": "git://github.com/juliangruber/balanced-match.git",
 96723              "type": "distribution"
 96724            },
 96725            {
 96726              "url": "https://github.com/juliangruber/balanced-match",
 96727              "type": "website"
 96728            }
 96729          ],
 96730          "evidence": {},
 96731          "signature": {
 96732            "signature": {
 96733              "publicKey": {}
 96734            }
 96735          },
 96736          "modelCard": {
 96737            "modelParameters": {
 96738              "approach": {}
 96739            },
 96740            "quantitativeAnalysis": {
 96741              "graphics": {}
 96742            },
 96743            "considerations": {}
 96744          }
 96745        },
 96746        {
 96747          "type": "library",
 96748          "bom-ref": "pkg:npm/basic-auth@2.0.1?package-id=b97bc397c5348d06",
 96749          "supplier": {},
 96750          "name": "basic-auth",
 96751          "version": "2.0.1",
 96752          "description": "node.js basic auth parser",
 96753          "licenses": [
 96754            {
 96755              "license": {
 96756                "id": "MIT"
 96757              }
 96758            }
 96759          ],
 96760          "cpe": "cpe:2.3:a:basic-auth:basic-auth:2.0.1:*:*:*:*:*:*:*",
 96761          "purl": "pkg:npm/basic-auth@2.0.1",
 96762          "swid": {
 96763            "attachment": {}
 96764          },
 96765          "pedigree": {},
 96766          "externalReferences": [
 96767            {
 96768              "url": "jshttp/basic-auth",
 96769              "type": "distribution"
 96770            }
 96771          ],
 96772          "evidence": {},
 96773          "signature": {
 96774            "signature": {
 96775              "publicKey": {}
 96776            }
 96777          },
 96778          "modelCard": {
 96779            "modelParameters": {
 96780              "approach": {}
 96781            },
 96782            "quantitativeAnalysis": {
 96783              "graphics": {}
 96784            },
 96785            "considerations": {}
 96786          }
 96787        },
 96788        {
 96789          "type": "library",
 96790          "bom-ref": "pkg:npm/bin-links@3.0.3?package-id=605ade84572e7fb",
 96791          "supplier": {},
 96792          "author": "GitHub Inc.",
 96793          "name": "bin-links",
 96794          "version": "3.0.3",
 96795          "description": "JavaScript package binary linker",
 96796          "licenses": [
 96797            {
 96798              "license": {
 96799                "id": "ISC"
 96800              }
 96801            }
 96802          ],
 96803          "cpe": "cpe:2.3:a:bin-links:bin-links:3.0.3:*:*:*:*:*:*:*",
 96804          "purl": "pkg:npm/bin-links@3.0.3",
 96805          "swid": {
 96806            "attachment": {}
 96807          },
 96808          "pedigree": {},
 96809          "externalReferences": [
 96810            {
 96811              "url": "https://github.com/npm/bin-links.git",
 96812              "type": "distribution"
 96813            }
 96814          ],
 96815          "evidence": {},
 96816          "signature": {
 96817            "signature": {
 96818              "publicKey": {}
 96819            }
 96820          },
 96821          "modelCard": {
 96822            "modelParameters": {
 96823              "approach": {}
 96824            },
 96825            "quantitativeAnalysis": {
 96826              "graphics": {}
 96827            },
 96828            "considerations": {}
 96829          }
 96830        },
 96831        {
 96832          "type": "library",
 96833          "bom-ref": "pkg:npm/binary-extensions@2.2.0?package-id=2ddda84d3ad7f3e1",
 96834          "supplier": {},
 96835          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
 96836          "name": "binary-extensions",
 96837          "version": "2.2.0",
 96838          "description": "List of binary file extensions",
 96839          "licenses": [
 96840            {
 96841              "license": {
 96842                "id": "MIT"
 96843              }
 96844            }
 96845          ],
 96846          "cpe": "cpe:2.3:a:binary-extensions:binary-extensions:2.2.0:*:*:*:*:*:*:*",
 96847          "purl": "pkg:npm/binary-extensions@2.2.0",
 96848          "swid": {
 96849            "attachment": {}
 96850          },
 96851          "pedigree": {},
 96852          "externalReferences": [
 96853            {
 96854              "url": "sindresorhus/binary-extensions",
 96855              "type": "distribution"
 96856            }
 96857          ],
 96858          "evidence": {},
 96859          "signature": {
 96860            "signature": {
 96861              "publicKey": {}
 96862            }
 96863          },
 96864          "modelCard": {
 96865            "modelParameters": {
 96866              "approach": {}
 96867            },
 96868            "quantitativeAnalysis": {
 96869              "graphics": {}
 96870            },
 96871            "considerations": {}
 96872          }
 96873        },
 96874        {
 96875          "type": "library",
 96876          "bom-ref": "pkg:npm/block-stream2@2.1.0?package-id=d2c19c703777584a",
 96877          "supplier": {},
 96878          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
 96879          "name": "block-stream2",
 96880          "version": "2.1.0",
 96881          "description": "transform input into equally-sized blocks of output",
 96882          "licenses": [
 96883            {
 96884              "license": {
 96885                "id": "MIT"
 96886              }
 96887            }
 96888          ],
 96889          "cpe": "cpe:2.3:a:block-stream2:block-stream2:2.1.0:*:*:*:*:*:*:*",
 96890          "purl": "pkg:npm/block-stream2@2.1.0",
 96891          "swid": {
 96892            "attachment": {}
 96893          },
 96894          "pedigree": {},
 96895          "externalReferences": [
 96896            {
 96897              "url": "git://github.com/substack/block-stream2.git",
 96898              "type": "distribution"
 96899            },
 96900            {
 96901              "url": "https://github.com/substack/block-stream2",
 96902              "type": "website"
 96903            }
 96904          ],
 96905          "evidence": {},
 96906          "signature": {
 96907            "signature": {
 96908              "publicKey": {}
 96909            }
 96910          },
 96911          "modelCard": {
 96912            "modelParameters": {
 96913              "approach": {}
 96914            },
 96915            "quantitativeAnalysis": {
 96916              "graphics": {}
 96917            },
 96918            "considerations": {}
 96919          }
 96920        },
 96921        {
 96922          "type": "library",
 96923          "bom-ref": "pkg:npm/bn.js@4.12.0?package-id=b7cc9dec877d11de",
 96924          "supplier": {},
 96925          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
 96926          "name": "bn.js",
 96927          "version": "4.12.0",
 96928          "description": "Big number implementation in pure javascript",
 96929          "licenses": [
 96930            {
 96931              "license": {
 96932                "id": "MIT"
 96933              }
 96934            }
 96935          ],
 96936          "cpe": "cpe:2.3:a:indutny:bn.js:4.12.0:*:*:*:*:*:*:*",
 96937          "purl": "pkg:npm/bn.js@4.12.0",
 96938          "swid": {
 96939            "attachment": {}
 96940          },
 96941          "pedigree": {},
 96942          "externalReferences": [
 96943            {
 96944              "url": "git@github.com:indutny/bn.js",
 96945              "type": "distribution"
 96946            },
 96947            {
 96948              "url": "https://github.com/indutny/bn.js",
 96949              "type": "website"
 96950            }
 96951          ],
 96952          "evidence": {},
 96953          "signature": {
 96954            "signature": {
 96955              "publicKey": {}
 96956            }
 96957          },
 96958          "modelCard": {
 96959            "modelParameters": {
 96960              "approach": {}
 96961            },
 96962            "quantitativeAnalysis": {
 96963              "graphics": {}
 96964            },
 96965            "considerations": {}
 96966          }
 96967        },
 96968        {
 96969          "type": "library",
 96970          "bom-ref": "pkg:npm/bn.js@4.12.0?package-id=9a6181db4cf59c1b",
 96971          "supplier": {},
 96972          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
 96973          "name": "bn.js",
 96974          "version": "4.12.0",
 96975          "description": "Big number implementation in pure javascript",
 96976          "licenses": [
 96977            {
 96978              "license": {
 96979                "id": "MIT"
 96980              }
 96981            }
 96982          ],
 96983          "cpe": "cpe:2.3:a:indutny:bn.js:4.12.0:*:*:*:*:*:*:*",
 96984          "purl": "pkg:npm/bn.js@4.12.0",
 96985          "swid": {
 96986            "attachment": {}
 96987          },
 96988          "pedigree": {},
 96989          "externalReferences": [
 96990            {
 96991              "url": "git@github.com:indutny/bn.js",
 96992              "type": "distribution"
 96993            },
 96994            {
 96995              "url": "https://github.com/indutny/bn.js",
 96996              "type": "website"
 96997            }
 96998          ],
 96999          "evidence": {},
 97000          "signature": {
 97001            "signature": {
 97002              "publicKey": {}
 97003            }
 97004          },
 97005          "modelCard": {
 97006            "modelParameters": {
 97007              "approach": {}
 97008            },
 97009            "quantitativeAnalysis": {
 97010              "graphics": {}
 97011            },
 97012            "considerations": {}
 97013          }
 97014        },
 97015        {
 97016          "type": "library",
 97017          "bom-ref": "pkg:npm/bn.js@4.12.0?package-id=ef164bc414528c24",
 97018          "supplier": {},
 97019          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
 97020          "name": "bn.js",
 97021          "version": "4.12.0",
 97022          "description": "Big number implementation in pure javascript",
 97023          "licenses": [
 97024            {
 97025              "license": {
 97026                "id": "MIT"
 97027              }
 97028            }
 97029          ],
 97030          "cpe": "cpe:2.3:a:indutny:bn.js:4.12.0:*:*:*:*:*:*:*",
 97031          "purl": "pkg:npm/bn.js@4.12.0",
 97032          "swid": {
 97033            "attachment": {}
 97034          },
 97035          "pedigree": {},
 97036          "externalReferences": [
 97037            {
 97038              "url": "git@github.com:indutny/bn.js",
 97039              "type": "distribution"
 97040            },
 97041            {
 97042              "url": "https://github.com/indutny/bn.js",
 97043              "type": "website"
 97044            }
 97045          ],
 97046          "evidence": {},
 97047          "signature": {
 97048            "signature": {
 97049              "publicKey": {}
 97050            }
 97051          },
 97052          "modelCard": {
 97053            "modelParameters": {
 97054              "approach": {}
 97055            },
 97056            "quantitativeAnalysis": {
 97057              "graphics": {}
 97058            },
 97059            "considerations": {}
 97060          }
 97061        },
 97062        {
 97063          "type": "library",
 97064          "bom-ref": "pkg:npm/bn.js@4.12.0?package-id=1812fdbf5163e0d8",
 97065          "supplier": {},
 97066          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
 97067          "name": "bn.js",
 97068          "version": "4.12.0",
 97069          "description": "Big number implementation in pure javascript",
 97070          "licenses": [
 97071            {
 97072              "license": {
 97073                "id": "MIT"
 97074              }
 97075            }
 97076          ],
 97077          "cpe": "cpe:2.3:a:indutny:bn.js:4.12.0:*:*:*:*:*:*:*",
 97078          "purl": "pkg:npm/bn.js@4.12.0",
 97079          "swid": {
 97080            "attachment": {}
 97081          },
 97082          "pedigree": {},
 97083          "externalReferences": [
 97084            {
 97085              "url": "git@github.com:indutny/bn.js",
 97086              "type": "distribution"
 97087            },
 97088            {
 97089              "url": "https://github.com/indutny/bn.js",
 97090              "type": "website"
 97091            }
 97092          ],
 97093          "evidence": {},
 97094          "signature": {
 97095            "signature": {
 97096              "publicKey": {}
 97097            }
 97098          },
 97099          "modelCard": {
 97100            "modelParameters": {
 97101              "approach": {}
 97102            },
 97103            "quantitativeAnalysis": {
 97104              "graphics": {}
 97105            },
 97106            "considerations": {}
 97107          }
 97108        },
 97109        {
 97110          "type": "library",
 97111          "bom-ref": "pkg:npm/bn.js@4.12.0?package-id=56b497d806150816",
 97112          "supplier": {},
 97113          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
 97114          "name": "bn.js",
 97115          "version": "4.12.0",
 97116          "description": "Big number implementation in pure javascript",
 97117          "licenses": [
 97118            {
 97119              "license": {
 97120                "id": "MIT"
 97121              }
 97122            }
 97123          ],
 97124          "cpe": "cpe:2.3:a:indutny:bn.js:4.12.0:*:*:*:*:*:*:*",
 97125          "purl": "pkg:npm/bn.js@4.12.0",
 97126          "swid": {
 97127            "attachment": {}
 97128          },
 97129          "pedigree": {},
 97130          "externalReferences": [
 97131            {
 97132              "url": "git@github.com:indutny/bn.js",
 97133              "type": "distribution"
 97134            },
 97135            {
 97136              "url": "https://github.com/indutny/bn.js",
 97137              "type": "website"
 97138            }
 97139          ],
 97140          "evidence": {},
 97141          "signature": {
 97142            "signature": {
 97143              "publicKey": {}
 97144            }
 97145          },
 97146          "modelCard": {
 97147            "modelParameters": {
 97148              "approach": {}
 97149            },
 97150            "quantitativeAnalysis": {
 97151              "graphics": {}
 97152            },
 97153            "considerations": {}
 97154          }
 97155        },
 97156        {
 97157          "type": "library",
 97158          "bom-ref": "pkg:npm/bn.js@4.12.0?package-id=e3d9363f1d2c98ee",
 97159          "supplier": {},
 97160          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
 97161          "name": "bn.js",
 97162          "version": "4.12.0",
 97163          "description": "Big number implementation in pure javascript",
 97164          "licenses": [
 97165            {
 97166              "license": {
 97167                "id": "MIT"
 97168              }
 97169            }
 97170          ],
 97171          "cpe": "cpe:2.3:a:indutny:bn.js:4.12.0:*:*:*:*:*:*:*",
 97172          "purl": "pkg:npm/bn.js@4.12.0",
 97173          "swid": {
 97174            "attachment": {}
 97175          },
 97176          "pedigree": {},
 97177          "externalReferences": [
 97178            {
 97179              "url": "git@github.com:indutny/bn.js",
 97180              "type": "distribution"
 97181            },
 97182            {
 97183              "url": "https://github.com/indutny/bn.js",
 97184              "type": "website"
 97185            }
 97186          ],
 97187          "evidence": {},
 97188          "signature": {
 97189            "signature": {
 97190              "publicKey": {}
 97191            }
 97192          },
 97193          "modelCard": {
 97194            "modelParameters": {
 97195              "approach": {}
 97196            },
 97197            "quantitativeAnalysis": {
 97198              "graphics": {}
 97199            },
 97200            "considerations": {}
 97201          }
 97202        },
 97203        {
 97204          "type": "library",
 97205          "bom-ref": "pkg:npm/bn.js@5.2.1?package-id=8f983475c76cf9b2",
 97206          "supplier": {},
 97207          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
 97208          "name": "bn.js",
 97209          "version": "5.2.1",
 97210          "description": "Big number implementation in pure javascript",
 97211          "licenses": [
 97212            {
 97213              "license": {
 97214                "id": "MIT"
 97215              }
 97216            }
 97217          ],
 97218          "cpe": "cpe:2.3:a:indutny:bn.js:5.2.1:*:*:*:*:*:*:*",
 97219          "purl": "pkg:npm/bn.js@5.2.1",
 97220          "swid": {
 97221            "attachment": {}
 97222          },
 97223          "pedigree": {},
 97224          "externalReferences": [
 97225            {
 97226              "url": "git@github.com:indutny/bn.js",
 97227              "type": "distribution"
 97228            },
 97229            {
 97230              "url": "https://github.com/indutny/bn.js",
 97231              "type": "website"
 97232            }
 97233          ],
 97234          "evidence": {},
 97235          "signature": {
 97236            "signature": {
 97237              "publicKey": {}
 97238            }
 97239          },
 97240          "modelCard": {
 97241            "modelParameters": {
 97242              "approach": {}
 97243            },
 97244            "quantitativeAnalysis": {
 97245              "graphics": {}
 97246            },
 97247            "considerations": {}
 97248          }
 97249        },
 97250        {
 97251          "type": "library",
 97252          "bom-ref": "pkg:npm/body-parser@1.18.3?package-id=b284a1ea89619936",
 97253          "supplier": {},
 97254          "name": "body-parser",
 97255          "version": "1.18.3",
 97256          "description": "Node.js body parsing middleware",
 97257          "licenses": [
 97258            {
 97259              "license": {
 97260                "id": "MIT"
 97261              }
 97262            }
 97263          ],
 97264          "cpe": "cpe:2.3:a:body-parser:body-parser:1.18.3:*:*:*:*:*:*:*",
 97265          "purl": "pkg:npm/body-parser@1.18.3",
 97266          "swid": {
 97267            "attachment": {}
 97268          },
 97269          "pedigree": {},
 97270          "externalReferences": [
 97271            {
 97272              "url": "expressjs/body-parser",
 97273              "type": "distribution"
 97274            }
 97275          ],
 97276          "evidence": {},
 97277          "signature": {
 97278            "signature": {
 97279              "publicKey": {}
 97280            }
 97281          },
 97282          "modelCard": {
 97283            "modelParameters": {
 97284              "approach": {}
 97285            },
 97286            "quantitativeAnalysis": {
 97287              "graphics": {}
 97288            },
 97289            "considerations": {}
 97290          }
 97291        },
 97292        {
 97293          "type": "library",
 97294          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=a36ca63616a6d457",
 97295          "supplier": {},
 97296          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
 97297          "name": "brace-expansion",
 97298          "version": "1.1.11",
 97299          "description": "Brace expansion as known from sh/bash",
 97300          "licenses": [
 97301            {
 97302              "license": {
 97303                "id": "MIT"
 97304              }
 97305            }
 97306          ],
 97307          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
 97308          "purl": "pkg:npm/brace-expansion@1.1.11",
 97309          "swid": {
 97310            "attachment": {}
 97311          },
 97312          "pedigree": {},
 97313          "externalReferences": [
 97314            {
 97315              "url": "git://github.com/juliangruber/brace-expansion.git",
 97316              "type": "distribution"
 97317            },
 97318            {
 97319              "url": "https://github.com/juliangruber/brace-expansion",
 97320              "type": "website"
 97321            }
 97322          ],
 97323          "evidence": {},
 97324          "signature": {
 97325            "signature": {
 97326              "publicKey": {}
 97327            }
 97328          },
 97329          "modelCard": {
 97330            "modelParameters": {
 97331              "approach": {}
 97332            },
 97333            "quantitativeAnalysis": {
 97334              "graphics": {}
 97335            },
 97336            "considerations": {}
 97337          }
 97338        },
 97339        {
 97340          "type": "library",
 97341          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=8aefa0d5bf7ea5ce",
 97342          "supplier": {},
 97343          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
 97344          "name": "brace-expansion",
 97345          "version": "1.1.11",
 97346          "description": "Brace expansion as known from sh/bash",
 97347          "licenses": [
 97348            {
 97349              "license": {
 97350                "id": "MIT"
 97351              }
 97352            }
 97353          ],
 97354          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
 97355          "purl": "pkg:npm/brace-expansion@1.1.11",
 97356          "swid": {
 97357            "attachment": {}
 97358          },
 97359          "pedigree": {},
 97360          "externalReferences": [
 97361            {
 97362              "url": "git://github.com/juliangruber/brace-expansion.git",
 97363              "type": "distribution"
 97364            },
 97365            {
 97366              "url": "https://github.com/juliangruber/brace-expansion",
 97367              "type": "website"
 97368            }
 97369          ],
 97370          "evidence": {},
 97371          "signature": {
 97372            "signature": {
 97373              "publicKey": {}
 97374            }
 97375          },
 97376          "modelCard": {
 97377            "modelParameters": {
 97378              "approach": {}
 97379            },
 97380            "quantitativeAnalysis": {
 97381              "graphics": {}
 97382            },
 97383            "considerations": {}
 97384          }
 97385        },
 97386        {
 97387          "type": "library",
 97388          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=72bb9632b6da1747",
 97389          "supplier": {},
 97390          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
 97391          "name": "brace-expansion",
 97392          "version": "1.1.11",
 97393          "description": "Brace expansion as known from sh/bash",
 97394          "licenses": [
 97395            {
 97396              "license": {
 97397                "id": "MIT"
 97398              }
 97399            }
 97400          ],
 97401          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
 97402          "purl": "pkg:npm/brace-expansion@1.1.11",
 97403          "swid": {
 97404            "attachment": {}
 97405          },
 97406          "pedigree": {},
 97407          "externalReferences": [
 97408            {
 97409              "url": "git://github.com/juliangruber/brace-expansion.git",
 97410              "type": "distribution"
 97411            },
 97412            {
 97413              "url": "https://github.com/juliangruber/brace-expansion",
 97414              "type": "website"
 97415            }
 97416          ],
 97417          "evidence": {},
 97418          "signature": {
 97419            "signature": {
 97420              "publicKey": {}
 97421            }
 97422          },
 97423          "modelCard": {
 97424            "modelParameters": {
 97425              "approach": {}
 97426            },
 97427            "quantitativeAnalysis": {
 97428              "graphics": {}
 97429            },
 97430            "considerations": {}
 97431          }
 97432        },
 97433        {
 97434          "type": "library",
 97435          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=1bc35b4fad6ec801",
 97436          "supplier": {},
 97437          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
 97438          "name": "brace-expansion",
 97439          "version": "1.1.11",
 97440          "description": "Brace expansion as known from sh/bash",
 97441          "licenses": [
 97442            {
 97443              "license": {
 97444                "id": "MIT"
 97445              }
 97446            }
 97447          ],
 97448          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
 97449          "purl": "pkg:npm/brace-expansion@1.1.11",
 97450          "swid": {
 97451            "attachment": {}
 97452          },
 97453          "pedigree": {},
 97454          "externalReferences": [
 97455            {
 97456              "url": "git://github.com/juliangruber/brace-expansion.git",
 97457              "type": "distribution"
 97458            },
 97459            {
 97460              "url": "https://github.com/juliangruber/brace-expansion",
 97461              "type": "website"
 97462            }
 97463          ],
 97464          "evidence": {},
 97465          "signature": {
 97466            "signature": {
 97467              "publicKey": {}
 97468            }
 97469          },
 97470          "modelCard": {
 97471            "modelParameters": {
 97472              "approach": {}
 97473            },
 97474            "quantitativeAnalysis": {
 97475              "graphics": {}
 97476            },
 97477            "considerations": {}
 97478          }
 97479        },
 97480        {
 97481          "type": "library",
 97482          "bom-ref": "pkg:npm/brace-expansion@2.0.1?package-id=70d44e2ab0a06da3",
 97483          "supplier": {},
 97484          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
 97485          "name": "brace-expansion",
 97486          "version": "2.0.1",
 97487          "description": "Brace expansion as known from sh/bash",
 97488          "licenses": [
 97489            {
 97490              "license": {
 97491                "id": "MIT"
 97492              }
 97493            }
 97494          ],
 97495          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:2.0.1:*:*:*:*:*:*:*",
 97496          "purl": "pkg:npm/brace-expansion@2.0.1",
 97497          "swid": {
 97498            "attachment": {}
 97499          },
 97500          "pedigree": {},
 97501          "externalReferences": [
 97502            {
 97503              "url": "git://github.com/juliangruber/brace-expansion.git",
 97504              "type": "distribution"
 97505            },
 97506            {
 97507              "url": "https://github.com/juliangruber/brace-expansion",
 97508              "type": "website"
 97509            }
 97510          ],
 97511          "evidence": {},
 97512          "signature": {
 97513            "signature": {
 97514              "publicKey": {}
 97515            }
 97516          },
 97517          "modelCard": {
 97518            "modelParameters": {
 97519              "approach": {}
 97520            },
 97521            "quantitativeAnalysis": {
 97522              "graphics": {}
 97523            },
 97524            "considerations": {}
 97525          }
 97526        },
 97527        {
 97528          "type": "library",
 97529          "bom-ref": "pkg:npm/braces@3.0.2?package-id=6296411936542cc5",
 97530          "supplier": {},
 97531          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
 97532          "name": "braces",
 97533          "version": "3.0.2",
 97534          "description": "Bash-like brace expansion, implemented in JavaScript. Safer than other brace expansion libs, with complete support for the Bash 4.3 braces specification, without sacrificing speed.",
 97535          "licenses": [
 97536            {
 97537              "license": {
 97538                "id": "MIT"
 97539              }
 97540            }
 97541          ],
 97542          "cpe": "cpe:2.3:a:micromatch:braces:3.0.2:*:*:*:*:*:*:*",
 97543          "purl": "pkg:npm/braces@3.0.2",
 97544          "swid": {
 97545            "attachment": {}
 97546          },
 97547          "pedigree": {},
 97548          "externalReferences": [
 97549            {
 97550              "url": "micromatch/braces",
 97551              "type": "distribution"
 97552            },
 97553            {
 97554              "url": "https://github.com/micromatch/braces",
 97555              "type": "website"
 97556            }
 97557          ],
 97558          "evidence": {},
 97559          "signature": {
 97560            "signature": {
 97561              "publicKey": {}
 97562            }
 97563          },
 97564          "modelCard": {
 97565            "modelParameters": {
 97566              "approach": {}
 97567            },
 97568            "quantitativeAnalysis": {
 97569              "graphics": {}
 97570            },
 97571            "considerations": {}
 97572          }
 97573        },
 97574        {
 97575          "type": "library",
 97576          "bom-ref": "pkg:npm/brorand@1.1.0?package-id=f48182ca4553c290",
 97577          "supplier": {},
 97578          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
 97579          "name": "brorand",
 97580          "version": "1.1.0",
 97581          "description": "Random number generator for browsers and node.js",
 97582          "licenses": [
 97583            {
 97584              "license": {
 97585                "id": "MIT"
 97586              }
 97587            }
 97588          ],
 97589          "cpe": "cpe:2.3:a:brorand:brorand:1.1.0:*:*:*:*:*:*:*",
 97590          "purl": "pkg:npm/brorand@1.1.0",
 97591          "swid": {
 97592            "attachment": {}
 97593          },
 97594          "pedigree": {},
 97595          "externalReferences": [
 97596            {
 97597              "url": "git@github.com:indutny/brorand",
 97598              "type": "distribution"
 97599            },
 97600            {
 97601              "url": "https://github.com/indutny/brorand",
 97602              "type": "website"
 97603            }
 97604          ],
 97605          "evidence": {},
 97606          "signature": {
 97607            "signature": {
 97608              "publicKey": {}
 97609            }
 97610          },
 97611          "modelCard": {
 97612            "modelParameters": {
 97613              "approach": {}
 97614            },
 97615            "quantitativeAnalysis": {
 97616              "graphics": {}
 97617            },
 97618            "considerations": {}
 97619          }
 97620        },
 97621        {
 97622          "type": "library",
 97623          "bom-ref": "pkg:npm/browser-or-node@1.3.0?package-id=871fc8e9e0f20338",
 97624          "supplier": {},
 97625          "author": "Dineshkumar Pandiyan \u003cflexdinesh@gmail.com\u003e",
 97626          "name": "browser-or-node",
 97627          "version": "1.3.0",
 97628          "description": "Check where the code is running in the browser or node.js",
 97629          "licenses": [
 97630            {
 97631              "license": {
 97632                "id": "MIT"
 97633              }
 97634            }
 97635          ],
 97636          "cpe": "cpe:2.3:a:browser-or-node:browser-or-node:1.3.0:*:*:*:*:*:*:*",
 97637          "purl": "pkg:npm/browser-or-node@1.3.0",
 97638          "swid": {
 97639            "attachment": {}
 97640          },
 97641          "pedigree": {},
 97642          "externalReferences": [
 97643            {
 97644              "url": "git+https://github.com/flexdinesh/browser-or-node.git",
 97645              "type": "distribution"
 97646            },
 97647            {
 97648              "url": "https://github.com/flexdinesh/browser-or-node#readme",
 97649              "type": "website"
 97650            }
 97651          ],
 97652          "evidence": {},
 97653          "signature": {
 97654            "signature": {
 97655              "publicKey": {}
 97656            }
 97657          },
 97658          "modelCard": {
 97659            "modelParameters": {
 97660              "approach": {}
 97661            },
 97662            "quantitativeAnalysis": {
 97663              "graphics": {}
 97664            },
 97665            "considerations": {}
 97666          }
 97667        },
 97668        {
 97669          "type": "library",
 97670          "bom-ref": "pkg:npm/browserify-aes@1.2.0?package-id=5e801493623d1f3c",
 97671          "supplier": {},
 97672          "name": "browserify-aes",
 97673          "version": "1.2.0",
 97674          "description": "aes, for browserify",
 97675          "licenses": [
 97676            {
 97677              "license": {
 97678                "id": "MIT"
 97679              }
 97680            }
 97681          ],
 97682          "cpe": "cpe:2.3:a:crypto-browserify:browserify-aes:1.2.0:*:*:*:*:*:*:*",
 97683          "purl": "pkg:npm/browserify-aes@1.2.0",
 97684          "swid": {
 97685            "attachment": {}
 97686          },
 97687          "pedigree": {},
 97688          "externalReferences": [
 97689            {
 97690              "url": "git://github.com/crypto-browserify/browserify-aes.git",
 97691              "type": "distribution"
 97692            },
 97693            {
 97694              "url": "https://github.com/crypto-browserify/browserify-aes",
 97695              "type": "website"
 97696            }
 97697          ],
 97698          "evidence": {},
 97699          "signature": {
 97700            "signature": {
 97701              "publicKey": {}
 97702            }
 97703          },
 97704          "modelCard": {
 97705            "modelParameters": {
 97706              "approach": {}
 97707            },
 97708            "quantitativeAnalysis": {
 97709              "graphics": {}
 97710            },
 97711            "considerations": {}
 97712          }
 97713        },
 97714        {
 97715          "type": "library",
 97716          "bom-ref": "pkg:npm/browserify-cipher@1.0.1?package-id=df1417ae7c08da05",
 97717          "supplier": {},
 97718          "author": "Calvin Metcalf \u003ccalvin.metcalf@gmail.com\u003e",
 97719          "name": "browserify-cipher",
 97720          "version": "1.0.1",
 97721          "description": "ciphers for the browser",
 97722          "licenses": [
 97723            {
 97724              "license": {
 97725                "id": "MIT"
 97726              }
 97727            }
 97728          ],
 97729          "cpe": "cpe:2.3:a:browserify-cipher:browserify-cipher:1.0.1:*:*:*:*:*:*:*",
 97730          "purl": "pkg:npm/browserify-cipher@1.0.1",
 97731          "swid": {
 97732            "attachment": {}
 97733          },
 97734          "pedigree": {},
 97735          "externalReferences": [
 97736            {
 97737              "url": "git@github.com:crypto-browserify/browserify-cipher.git",
 97738              "type": "distribution"
 97739            }
 97740          ],
 97741          "evidence": {},
 97742          "signature": {
 97743            "signature": {
 97744              "publicKey": {}
 97745            }
 97746          },
 97747          "modelCard": {
 97748            "modelParameters": {
 97749              "approach": {}
 97750            },
 97751            "quantitativeAnalysis": {
 97752              "graphics": {}
 97753            },
 97754            "considerations": {}
 97755          }
 97756        },
 97757        {
 97758          "type": "library",
 97759          "bom-ref": "pkg:npm/browserify-des@1.0.2?package-id=bd4a1c66d02aab0a",
 97760          "supplier": {},
 97761          "author": "Calvin Metcalf \u003ccalvin.metcalf@gmail.com\u003e",
 97762          "name": "browserify-des",
 97763          "version": "1.0.2",
 97764          "licenses": [
 97765            {
 97766              "license": {
 97767                "id": "MIT"
 97768              }
 97769            }
 97770          ],
 97771          "cpe": "cpe:2.3:a:crypto-browserify:browserify-des:1.0.2:*:*:*:*:*:*:*",
 97772          "purl": "pkg:npm/browserify-des@1.0.2",
 97773          "swid": {
 97774            "attachment": {}
 97775          },
 97776          "pedigree": {},
 97777          "externalReferences": [
 97778            {
 97779              "url": "git+https://github.com/crypto-browserify/browserify-des.git",
 97780              "type": "distribution"
 97781            },
 97782            {
 97783              "url": "https://github.com/crypto-browserify/browserify-des#readme",
 97784              "type": "website"
 97785            }
 97786          ],
 97787          "evidence": {},
 97788          "signature": {
 97789            "signature": {
 97790              "publicKey": {}
 97791            }
 97792          },
 97793          "modelCard": {
 97794            "modelParameters": {
 97795              "approach": {}
 97796            },
 97797            "quantitativeAnalysis": {
 97798              "graphics": {}
 97799            },
 97800            "considerations": {}
 97801          }
 97802        },
 97803        {
 97804          "type": "library",
 97805          "bom-ref": "pkg:npm/browserify-rsa@4.1.0?package-id=b4e2a75bbccfc0c5",
 97806          "supplier": {},
 97807          "name": "browserify-rsa",
 97808          "version": "4.1.0",
 97809          "description": "RSA for browserify",
 97810          "licenses": [
 97811            {
 97812              "license": {
 97813                "id": "MIT"
 97814              }
 97815            }
 97816          ],
 97817          "cpe": "cpe:2.3:a:browserify-rsa:browserify-rsa:4.1.0:*:*:*:*:*:*:*",
 97818          "purl": "pkg:npm/browserify-rsa@4.1.0",
 97819          "swid": {
 97820            "attachment": {}
 97821          },
 97822          "pedigree": {},
 97823          "externalReferences": [
 97824            {
 97825              "url": "https://github.com:crypto-browserify/browserify-rsa.git",
 97826              "type": "distribution"
 97827            }
 97828          ],
 97829          "evidence": {},
 97830          "signature": {
 97831            "signature": {
 97832              "publicKey": {}
 97833            }
 97834          },
 97835          "modelCard": {
 97836            "modelParameters": {
 97837              "approach": {}
 97838            },
 97839            "quantitativeAnalysis": {
 97840              "graphics": {}
 97841            },
 97842            "considerations": {}
 97843          }
 97844        },
 97845        {
 97846          "type": "library",
 97847          "bom-ref": "pkg:npm/browserify-sign@4.2.1?package-id=1368dcd508361dfe",
 97848          "supplier": {},
 97849          "name": "browserify-sign",
 97850          "version": "4.2.1",
 97851          "description": "adds node crypto signing for browsers",
 97852          "licenses": [
 97853            {
 97854              "license": {
 97855                "id": "ISC"
 97856              }
 97857            }
 97858          ],
 97859          "cpe": "cpe:2.3:a:crypto-browserify:browserify-sign:4.2.1:*:*:*:*:*:*:*",
 97860          "purl": "pkg:npm/browserify-sign@4.2.1",
 97861          "swid": {
 97862            "attachment": {}
 97863          },
 97864          "pedigree": {},
 97865          "externalReferences": [
 97866            {
 97867              "url": "https://github.com/crypto-browserify/browserify-sign.git",
 97868              "type": "distribution"
 97869            }
 97870          ],
 97871          "evidence": {},
 97872          "signature": {
 97873            "signature": {
 97874              "publicKey": {}
 97875            }
 97876          },
 97877          "modelCard": {
 97878            "modelParameters": {
 97879              "approach": {}
 97880            },
 97881            "quantitativeAnalysis": {
 97882              "graphics": {}
 97883            },
 97884            "considerations": {}
 97885          }
 97886        },
 97887        {
 97888          "type": "library",
 97889          "bom-ref": "pkg:npm/buffer-crc32@0.2.13?package-id=4fd48942dbfa2289",
 97890          "supplier": {},
 97891          "author": "Brian J. Brennan \u003cbrianloveswords@gmail.com\u003e",
 97892          "name": "buffer-crc32",
 97893          "version": "0.2.13",
 97894          "description": "A pure javascript CRC32 algorithm that plays nice with binary data",
 97895          "licenses": [
 97896            {
 97897              "license": {
 97898                "id": "MIT"
 97899              }
 97900            }
 97901          ],
 97902          "cpe": "cpe:2.3:a:brianloveswords:buffer-crc32:0.2.13:*:*:*:*:*:*:*",
 97903          "purl": "pkg:npm/buffer-crc32@0.2.13",
 97904          "swid": {
 97905            "attachment": {}
 97906          },
 97907          "pedigree": {},
 97908          "externalReferences": [
 97909            {
 97910              "url": "git://github.com/brianloveswords/buffer-crc32.git",
 97911              "type": "distribution"
 97912            },
 97913            {
 97914              "url": "https://github.com/brianloveswords/buffer-crc32",
 97915              "type": "website"
 97916            }
 97917          ],
 97918          "evidence": {},
 97919          "signature": {
 97920            "signature": {
 97921              "publicKey": {}
 97922            }
 97923          },
 97924          "modelCard": {
 97925            "modelParameters": {
 97926              "approach": {}
 97927            },
 97928            "quantitativeAnalysis": {
 97929              "graphics": {}
 97930            },
 97931            "considerations": {}
 97932          }
 97933        },
 97934        {
 97935          "type": "library",
 97936          "bom-ref": "pkg:npm/buffer-xor@1.0.3?package-id=daae2522a22e7a4b",
 97937          "supplier": {},
 97938          "author": "Daniel Cousens",
 97939          "name": "buffer-xor",
 97940          "version": "1.0.3",
 97941          "description": "A simple module for bitwise-xor on buffers",
 97942          "licenses": [
 97943            {
 97944              "license": {
 97945                "id": "MIT"
 97946              }
 97947            }
 97948          ],
 97949          "cpe": "cpe:2.3:a:crypto-browserify:buffer-xor:1.0.3:*:*:*:*:*:*:*",
 97950          "purl": "pkg:npm/buffer-xor@1.0.3",
 97951          "swid": {
 97952            "attachment": {}
 97953          },
 97954          "pedigree": {},
 97955          "externalReferences": [
 97956            {
 97957              "url": "https://github.com/crypto-browserify/buffer-xor.git",
 97958              "type": "distribution"
 97959            },
 97960            {
 97961              "url": "https://github.com/crypto-browserify/buffer-xor",
 97962              "type": "website"
 97963            }
 97964          ],
 97965          "evidence": {},
 97966          "signature": {
 97967            "signature": {
 97968              "publicKey": {}
 97969            }
 97970          },
 97971          "modelCard": {
 97972            "modelParameters": {
 97973              "approach": {}
 97974            },
 97975            "quantitativeAnalysis": {
 97976              "graphics": {}
 97977            },
 97978            "considerations": {}
 97979          }
 97980        },
 97981        {
 97982          "type": "library",
 97983          "bom-ref": "pkg:npm/builtins@5.0.1?package-id=af6ac207a0c6926d",
 97984          "supplier": {},
 97985          "name": "builtins",
 97986          "version": "5.0.1",
 97987          "description": "List of node.js builtin modules",
 97988          "licenses": [
 97989            {
 97990              "license": {
 97991                "id": "MIT"
 97992              }
 97993            }
 97994          ],
 97995          "cpe": "cpe:2.3:a:builtins:builtins:5.0.1:*:*:*:*:*:*:*",
 97996          "purl": "pkg:npm/builtins@5.0.1",
 97997          "swid": {
 97998            "attachment": {}
 97999          },
 98000          "pedigree": {},
 98001          "externalReferences": [
 98002            {
 98003              "url": "juliangruber/builtins",
 98004              "type": "distribution"
 98005            }
 98006          ],
 98007          "evidence": {},
 98008          "signature": {
 98009            "signature": {
 98010              "publicKey": {}
 98011            }
 98012          },
 98013          "modelCard": {
 98014            "modelParameters": {
 98015              "approach": {}
 98016            },
 98017            "quantitativeAnalysis": {
 98018              "graphics": {}
 98019            },
 98020            "considerations": {}
 98021          }
 98022        },
 98023        {
 98024          "type": "application",
 98025          "bom-ref": "e14718c64f5147f4",
 98026          "supplier": {},
 98027          "name": "busybox",
 98028          "version": "1.35.0",
 98029          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
 98030          "swid": {
 98031            "attachment": {}
 98032          },
 98033          "pedigree": {},
 98034          "evidence": {},
 98035          "signature": {
 98036            "signature": {
 98037              "publicKey": {}
 98038            }
 98039          },
 98040          "modelCard": {
 98041            "modelParameters": {
 98042              "approach": {}
 98043            },
 98044            "quantitativeAnalysis": {
 98045              "graphics": {}
 98046            },
 98047            "considerations": {}
 98048          }
 98049        },
 98050        {
 98051          "type": "library",
 98052          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=4b48ef6f6b983526",
 98053          "supplier": {},
 98054          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
 98055          "name": "busybox",
 98056          "version": "1.35.0-r17",
 98057          "description": "Size optimized toolbox of many common UNIX utilities",
 98058          "licenses": [
 98059            {
 98060              "license": {
 98061                "id": "GPL-2.0-only"
 98062              }
 98063            }
 98064          ],
 98065          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r17:*:*:*:*:*:*:*",
 98066          "purl": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5",
 98067          "swid": {
 98068            "attachment": {}
 98069          },
 98070          "pedigree": {},
 98071          "externalReferences": [
 98072            {
 98073              "url": "https://busybox.net/",
 98074              "type": "distribution"
 98075            }
 98076          ],
 98077          "evidence": {},
 98078          "signature": {
 98079            "signature": {
 98080              "publicKey": {}
 98081            }
 98082          },
 98083          "modelCard": {
 98084            "modelParameters": {
 98085              "approach": {}
 98086            },
 98087            "quantitativeAnalysis": {
 98088              "graphics": {}
 98089            },
 98090            "considerations": {}
 98091          }
 98092        },
 98093        {
 98094          "type": "library",
 98095          "bom-ref": "pkg:npm/bytes@3.0.0?package-id=576903a3803d92be",
 98096          "supplier": {},
 98097          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
 98098          "name": "bytes",
 98099          "version": "3.0.0",
 98100          "description": "Utility to parse a string bytes to bytes and vice-versa",
 98101          "licenses": [
 98102            {
 98103              "license": {
 98104                "id": "MIT"
 98105              }
 98106            }
 98107          ],
 98108          "cpe": "cpe:2.3:a:bytes:bytes:3.0.0:*:*:*:*:*:*:*",
 98109          "purl": "pkg:npm/bytes@3.0.0",
 98110          "swid": {
 98111            "attachment": {}
 98112          },
 98113          "pedigree": {},
 98114          "externalReferences": [
 98115            {
 98116              "url": "visionmedia/bytes.js",
 98117              "type": "distribution"
 98118            }
 98119          ],
 98120          "evidence": {},
 98121          "signature": {
 98122            "signature": {
 98123              "publicKey": {}
 98124            }
 98125          },
 98126          "modelCard": {
 98127            "modelParameters": {
 98128              "approach": {}
 98129            },
 98130            "quantitativeAnalysis": {
 98131              "graphics": {}
 98132            },
 98133            "considerations": {}
 98134          }
 98135        },
 98136        {
 98137          "type": "library",
 98138          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5\u0026package-id=30622a1848b22bca",
 98139          "supplier": {},
 98140          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
 98141          "name": "ca-certificates-bundle",
 98142          "version": "20220614-r0",
 98143          "description": "Pre generated bundle of Mozilla certificates",
 98144          "licenses": [
 98145            {
 98146              "license": {
 98147                "id": "MPL-2.0"
 98148              }
 98149            },
 98150            {
 98151              "license": {
 98152                "name": "AND"
 98153              }
 98154            },
 98155            {
 98156              "license": {
 98157                "id": "MIT"
 98158              }
 98159            }
 98160          ],
 98161          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
 98162          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5",
 98163          "swid": {
 98164            "attachment": {}
 98165          },
 98166          "pedigree": {},
 98167          "externalReferences": [
 98168            {
 98169              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
 98170              "type": "distribution"
 98171            }
 98172          ],
 98173          "evidence": {},
 98174          "signature": {
 98175            "signature": {
 98176              "publicKey": {}
 98177            }
 98178          },
 98179          "modelCard": {
 98180            "modelParameters": {
 98181              "approach": {}
 98182            },
 98183            "quantitativeAnalysis": {
 98184              "graphics": {}
 98185            },
 98186            "considerations": {}
 98187          }
 98188        },
 98189        {
 98190          "type": "library",
 98191          "bom-ref": "pkg:npm/cacache@16.1.3?package-id=4e055fb1e595c11",
 98192          "supplier": {},
 98193          "author": "GitHub Inc.",
 98194          "name": "cacache",
 98195          "version": "16.1.3",
 98196          "description": "Fast, fault-tolerant, cross-platform, disk-based, data-agnostic, content-addressable cache.",
 98197          "licenses": [
 98198            {
 98199              "license": {
 98200                "id": "ISC"
 98201              }
 98202            }
 98203          ],
 98204          "cpe": "cpe:2.3:a:cacache:cacache:16.1.3:*:*:*:*:*:*:*",
 98205          "purl": "pkg:npm/cacache@16.1.3",
 98206          "swid": {
 98207            "attachment": {}
 98208          },
 98209          "pedigree": {},
 98210          "externalReferences": [
 98211            {
 98212              "url": "https://github.com/npm/cacache.git",
 98213              "type": "distribution"
 98214            }
 98215          ],
 98216          "evidence": {},
 98217          "signature": {
 98218            "signature": {
 98219              "publicKey": {}
 98220            }
 98221          },
 98222          "modelCard": {
 98223            "modelParameters": {
 98224              "approach": {}
 98225            },
 98226            "quantitativeAnalysis": {
 98227              "graphics": {}
 98228            },
 98229            "considerations": {}
 98230          }
 98231        },
 98232        {
 98233          "type": "library",
 98234          "bom-ref": "pkg:npm/call-bind@1.0.2?package-id=6c35bdb69bd830b5",
 98235          "supplier": {},
 98236          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
 98237          "name": "call-bind",
 98238          "version": "1.0.2",
 98239          "description": "Robustly `.call.bind()` a function",
 98240          "licenses": [
 98241            {
 98242              "license": {
 98243                "id": "MIT"
 98244              }
 98245            }
 98246          ],
 98247          "cpe": "cpe:2.3:a:call-bind:call-bind:1.0.2:*:*:*:*:*:*:*",
 98248          "purl": "pkg:npm/call-bind@1.0.2",
 98249          "swid": {
 98250            "attachment": {}
 98251          },
 98252          "pedigree": {},
 98253          "externalReferences": [
 98254            {
 98255              "url": "git+https://github.com/ljharb/call-bind.git",
 98256              "type": "distribution"
 98257            },
 98258            {
 98259              "url": "https://github.com/ljharb/call-bind#readme",
 98260              "type": "website"
 98261            }
 98262          ],
 98263          "evidence": {},
 98264          "signature": {
 98265            "signature": {
 98266              "publicKey": {}
 98267            }
 98268          },
 98269          "modelCard": {
 98270            "modelParameters": {
 98271              "approach": {}
 98272            },
 98273            "quantitativeAnalysis": {
 98274              "graphics": {}
 98275            },
 98276            "considerations": {}
 98277          }
 98278        },
 98279        {
 98280          "type": "library",
 98281          "bom-ref": "pkg:npm/chalk@4.1.2?package-id=b12178723b56594f",
 98282          "supplier": {},
 98283          "name": "chalk",
 98284          "version": "4.1.2",
 98285          "description": "Terminal string styling done right",
 98286          "licenses": [
 98287            {
 98288              "license": {
 98289                "id": "MIT"
 98290              }
 98291            }
 98292          ],
 98293          "cpe": "cpe:2.3:a:chalk:chalk:4.1.2:*:*:*:*:*:*:*",
 98294          "purl": "pkg:npm/chalk@4.1.2",
 98295          "swid": {
 98296            "attachment": {}
 98297          },
 98298          "pedigree": {},
 98299          "externalReferences": [
 98300            {
 98301              "url": "chalk/chalk",
 98302              "type": "distribution"
 98303            }
 98304          ],
 98305          "evidence": {},
 98306          "signature": {
 98307            "signature": {
 98308              "publicKey": {}
 98309            }
 98310          },
 98311          "modelCard": {
 98312            "modelParameters": {
 98313              "approach": {}
 98314            },
 98315            "quantitativeAnalysis": {
 98316              "graphics": {}
 98317            },
 98318            "considerations": {}
 98319          }
 98320        },
 98321        {
 98322          "type": "library",
 98323          "bom-ref": "pkg:npm/chalk@4.1.2?package-id=c4d02229c2164ed6",
 98324          "supplier": {},
 98325          "name": "chalk",
 98326          "version": "4.1.2",
 98327          "description": "Terminal string styling done right",
 98328          "licenses": [
 98329            {
 98330              "license": {
 98331                "id": "MIT"
 98332              }
 98333            }
 98334          ],
 98335          "cpe": "cpe:2.3:a:chalk:chalk:4.1.2:*:*:*:*:*:*:*",
 98336          "purl": "pkg:npm/chalk@4.1.2",
 98337          "swid": {
 98338            "attachment": {}
 98339          },
 98340          "pedigree": {},
 98341          "externalReferences": [
 98342            {
 98343              "url": "chalk/chalk",
 98344              "type": "distribution"
 98345            }
 98346          ],
 98347          "evidence": {},
 98348          "signature": {
 98349            "signature": {
 98350              "publicKey": {}
 98351            }
 98352          },
 98353          "modelCard": {
 98354            "modelParameters": {
 98355              "approach": {}
 98356            },
 98357            "quantitativeAnalysis": {
 98358              "graphics": {}
 98359            },
 98360            "considerations": {}
 98361          }
 98362        },
 98363        {
 98364          "type": "library",
 98365          "bom-ref": "pkg:npm/chownr@1.1.4?package-id=332c2f28052efe07",
 98366          "supplier": {},
 98367          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
 98368          "name": "chownr",
 98369          "version": "1.1.4",
 98370          "description": "like `chown -R`",
 98371          "licenses": [
 98372            {
 98373              "license": {
 98374                "id": "ISC"
 98375              }
 98376            }
 98377          ],
 98378          "cpe": "cpe:2.3:a:chownr:chownr:1.1.4:*:*:*:*:*:*:*",
 98379          "purl": "pkg:npm/chownr@1.1.4",
 98380          "swid": {
 98381            "attachment": {}
 98382          },
 98383          "pedigree": {},
 98384          "externalReferences": [
 98385            {
 98386              "url": "git://github.com/isaacs/chownr.git",
 98387              "type": "distribution"
 98388            }
 98389          ],
 98390          "evidence": {},
 98391          "signature": {
 98392            "signature": {
 98393              "publicKey": {}
 98394            }
 98395          },
 98396          "modelCard": {
 98397            "modelParameters": {
 98398              "approach": {}
 98399            },
 98400            "quantitativeAnalysis": {
 98401              "graphics": {}
 98402            },
 98403            "considerations": {}
 98404          }
 98405        },
 98406        {
 98407          "type": "library",
 98408          "bom-ref": "pkg:npm/chownr@2.0.0?package-id=b5088c57ceda122f",
 98409          "supplier": {},
 98410          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
 98411          "name": "chownr",
 98412          "version": "2.0.0",
 98413          "description": "like `chown -R`",
 98414          "licenses": [
 98415            {
 98416              "license": {
 98417                "id": "ISC"
 98418              }
 98419            }
 98420          ],
 98421          "cpe": "cpe:2.3:a:chownr:chownr:2.0.0:*:*:*:*:*:*:*",
 98422          "purl": "pkg:npm/chownr@2.0.0",
 98423          "swid": {
 98424            "attachment": {}
 98425          },
 98426          "pedigree": {},
 98427          "externalReferences": [
 98428            {
 98429              "url": "git://github.com/isaacs/chownr.git",
 98430              "type": "distribution"
 98431            }
 98432          ],
 98433          "evidence": {},
 98434          "signature": {
 98435            "signature": {
 98436              "publicKey": {}
 98437            }
 98438          },
 98439          "modelCard": {
 98440            "modelParameters": {
 98441              "approach": {}
 98442            },
 98443            "quantitativeAnalysis": {
 98444              "graphics": {}
 98445            },
 98446            "considerations": {}
 98447          }
 98448        },
 98449        {
 98450          "type": "library",
 98451          "bom-ref": "pkg:npm/ci-info@2.0.0?package-id=18501884f4a6d64c",
 98452          "supplier": {},
 98453          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
 98454          "name": "ci-info",
 98455          "version": "2.0.0",
 98456          "description": "Get details about the current Continuous Integration environment",
 98457          "licenses": [
 98458            {
 98459              "license": {
 98460                "id": "MIT"
 98461              }
 98462            }
 98463          ],
 98464          "cpe": "cpe:2.3:a:ci-info:ci-info:2.0.0:*:*:*:*:*:*:*",
 98465          "purl": "pkg:npm/ci-info@2.0.0",
 98466          "swid": {
 98467            "attachment": {}
 98468          },
 98469          "pedigree": {},
 98470          "externalReferences": [
 98471            {
 98472              "url": "https://github.com/watson/ci-info.git",
 98473              "type": "distribution"
 98474            },
 98475            {
 98476              "url": "https://github.com/watson/ci-info",
 98477              "type": "website"
 98478            }
 98479          ],
 98480          "evidence": {},
 98481          "signature": {
 98482            "signature": {
 98483              "publicKey": {}
 98484            }
 98485          },
 98486          "modelCard": {
 98487            "modelParameters": {
 98488              "approach": {}
 98489            },
 98490            "quantitativeAnalysis": {
 98491              "graphics": {}
 98492            },
 98493            "considerations": {}
 98494          }
 98495        },
 98496        {
 98497          "type": "library",
 98498          "bom-ref": "pkg:npm/cidr-regex@3.1.1?package-id=be2d165b38649e26",
 98499          "supplier": {},
 98500          "author": "silverwind \u003cme@silverwind.io\u003e",
 98501          "name": "cidr-regex",
 98502          "version": "3.1.1",
 98503          "description": "Regular expression for matching IP addresses in CIDR notation",
 98504          "licenses": [
 98505            {
 98506              "license": {
 98507                "id": "BSD-2-Clause"
 98508              }
 98509            }
 98510          ],
 98511          "cpe": "cpe:2.3:a:cidr-regex:cidr-regex:3.1.1:*:*:*:*:*:*:*",
 98512          "purl": "pkg:npm/cidr-regex@3.1.1",
 98513          "swid": {
 98514            "attachment": {}
 98515          },
 98516          "pedigree": {},
 98517          "externalReferences": [
 98518            {
 98519              "url": "silverwind/cidr-regex",
 98520              "type": "distribution"
 98521            }
 98522          ],
 98523          "evidence": {},
 98524          "signature": {
 98525            "signature": {
 98526              "publicKey": {}
 98527            }
 98528          },
 98529          "modelCard": {
 98530            "modelParameters": {
 98531              "approach": {}
 98532            },
 98533            "quantitativeAnalysis": {
 98534              "graphics": {}
 98535            },
 98536            "considerations": {}
 98537          }
 98538        },
 98539        {
 98540          "type": "library",
 98541          "bom-ref": "pkg:npm/cipher-base@1.0.4?package-id=6346d0af22616b20",
 98542          "supplier": {},
 98543          "author": "Calvin Metcalf \u003ccalvin.metcalf@gmail.com\u003e",
 98544          "name": "cipher-base",
 98545          "version": "1.0.4",
 98546          "description": "abstract base class for crypto-streams",
 98547          "licenses": [
 98548            {
 98549              "license": {
 98550                "id": "MIT"
 98551              }
 98552            }
 98553          ],
 98554          "cpe": "cpe:2.3:a:crypto-browserify:cipher-base:1.0.4:*:*:*:*:*:*:*",
 98555          "purl": "pkg:npm/cipher-base@1.0.4",
 98556          "swid": {
 98557            "attachment": {}
 98558          },
 98559          "pedigree": {},
 98560          "externalReferences": [
 98561            {
 98562              "url": "git+https://github.com/crypto-browserify/cipher-base.git",
 98563              "type": "distribution"
 98564            },
 98565            {
 98566              "url": "https://github.com/crypto-browserify/cipher-base#readme",
 98567              "type": "website"
 98568            }
 98569          ],
 98570          "evidence": {},
 98571          "signature": {
 98572            "signature": {
 98573              "publicKey": {}
 98574            }
 98575          },
 98576          "modelCard": {
 98577            "modelParameters": {
 98578              "approach": {}
 98579            },
 98580            "quantitativeAnalysis": {
 98581              "graphics": {}
 98582            },
 98583            "considerations": {}
 98584          }
 98585        },
 98586        {
 98587          "type": "library",
 98588          "bom-ref": "pkg:npm/clean-stack@2.2.0?package-id=9a5c51e7acb4b115",
 98589          "supplier": {},
 98590          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
 98591          "name": "clean-stack",
 98592          "version": "2.2.0",
 98593          "description": "Clean up error stack traces",
 98594          "licenses": [
 98595            {
 98596              "license": {
 98597                "id": "MIT"
 98598              }
 98599            }
 98600          ],
 98601          "cpe": "cpe:2.3:a:clean-stack:clean-stack:2.2.0:*:*:*:*:*:*:*",
 98602          "purl": "pkg:npm/clean-stack@2.2.0",
 98603          "swid": {
 98604            "attachment": {}
 98605          },
 98606          "pedigree": {},
 98607          "externalReferences": [
 98608            {
 98609              "url": "sindresorhus/clean-stack",
 98610              "type": "distribution"
 98611            }
 98612          ],
 98613          "evidence": {},
 98614          "signature": {
 98615            "signature": {
 98616              "publicKey": {}
 98617            }
 98618          },
 98619          "modelCard": {
 98620            "modelParameters": {
 98621              "approach": {}
 98622            },
 98623            "quantitativeAnalysis": {
 98624              "graphics": {}
 98625            },
 98626            "considerations": {}
 98627          }
 98628        },
 98629        {
 98630          "type": "library",
 98631          "bom-ref": "pkg:npm/cli-columns@4.0.0?package-id=61a1dfb277c2e6f7",
 98632          "supplier": {},
 98633          "author": "Shannon Moeller \u003cme@shannonmoeller\u003e (http://shannonmoeller.com)",
 98634          "name": "cli-columns",
 98635          "version": "4.0.0",
 98636          "description": "Columnated lists for the CLI.",
 98637          "licenses": [
 98638            {
 98639              "license": {
 98640                "id": "MIT"
 98641              }
 98642            }
 98643          ],
 98644          "cpe": "cpe:2.3:a:shannonmoeller:cli-columns:4.0.0:*:*:*:*:*:*:*",
 98645          "purl": "pkg:npm/cli-columns@4.0.0",
 98646          "swid": {
 98647            "attachment": {}
 98648          },
 98649          "pedigree": {},
 98650          "externalReferences": [
 98651            {
 98652              "url": "shannonmoeller/cli-columns",
 98653              "type": "distribution"
 98654            },
 98655            {
 98656              "url": "https://github.com/shannonmoeller/cli-columns#readme",
 98657              "type": "website"
 98658            }
 98659          ],
 98660          "evidence": {},
 98661          "signature": {
 98662            "signature": {
 98663              "publicKey": {}
 98664            }
 98665          },
 98666          "modelCard": {
 98667            "modelParameters": {
 98668              "approach": {}
 98669            },
 98670            "quantitativeAnalysis": {
 98671              "graphics": {}
 98672            },
 98673            "considerations": {}
 98674          }
 98675        },
 98676        {
 98677          "type": "library",
 98678          "bom-ref": "pkg:npm/cli-table3@0.6.2?package-id=c77ee2194bd52f3d",
 98679          "supplier": {},
 98680          "author": "James Talmage",
 98681          "name": "cli-table3",
 98682          "version": "0.6.2",
 98683          "description": "Pretty unicode tables for the command line. Based on the original cli-table.",
 98684          "licenses": [
 98685            {
 98686              "license": {
 98687                "id": "MIT"
 98688              }
 98689            }
 98690          ],
 98691          "cpe": "cpe:2.3:a:cli-table3:cli-table3:0.6.2:*:*:*:*:*:*:*",
 98692          "purl": "pkg:npm/cli-table3@0.6.2",
 98693          "swid": {
 98694            "attachment": {}
 98695          },
 98696          "pedigree": {},
 98697          "externalReferences": [
 98698            {
 98699              "url": "https://github.com/cli-table/cli-table3.git",
 98700              "type": "distribution"
 98701            },
 98702            {
 98703              "url": "https://github.com/cli-table/cli-table3",
 98704              "type": "website"
 98705            }
 98706          ],
 98707          "evidence": {},
 98708          "signature": {
 98709            "signature": {
 98710              "publicKey": {}
 98711            }
 98712          },
 98713          "modelCard": {
 98714            "modelParameters": {
 98715              "approach": {}
 98716            },
 98717            "quantitativeAnalysis": {
 98718              "graphics": {}
 98719            },
 98720            "considerations": {}
 98721          }
 98722        },
 98723        {
 98724          "type": "library",
 98725          "bom-ref": "pkg:npm/clone@1.0.4?package-id=44b571b36478d30c",
 98726          "supplier": {},
 98727          "author": "Paul Vorbach \u003cpaul@vorba.ch\u003e (http://paul.vorba.ch/)",
 98728          "name": "clone",
 98729          "version": "1.0.4",
 98730          "description": "deep cloning of objects and arrays",
 98731          "licenses": [
 98732            {
 98733              "license": {
 98734                "id": "MIT"
 98735              }
 98736            }
 98737          ],
 98738          "cpe": "cpe:2.3:a:clone:clone:1.0.4:*:*:*:*:*:*:*",
 98739          "purl": "pkg:npm/clone@1.0.4",
 98740          "swid": {
 98741            "attachment": {}
 98742          },
 98743          "pedigree": {},
 98744          "externalReferences": [
 98745            {
 98746              "url": "git://github.com/pvorb/node-clone.git",
 98747              "type": "distribution"
 98748            }
 98749          ],
 98750          "evidence": {},
 98751          "signature": {
 98752            "signature": {
 98753              "publicKey": {}
 98754            }
 98755          },
 98756          "modelCard": {
 98757            "modelParameters": {
 98758              "approach": {}
 98759            },
 98760            "quantitativeAnalysis": {
 98761              "graphics": {}
 98762            },
 98763            "considerations": {}
 98764          }
 98765        },
 98766        {
 98767          "type": "library",
 98768          "bom-ref": "pkg:npm/cmd-shim@5.0.0?package-id=6701e31fdf422502",
 98769          "supplier": {},
 98770          "author": "GitHub Inc.",
 98771          "name": "cmd-shim",
 98772          "version": "5.0.0",
 98773          "description": "Used in npm for command line application support",
 98774          "licenses": [
 98775            {
 98776              "license": {
 98777                "id": "ISC"
 98778              }
 98779            }
 98780          ],
 98781          "cpe": "cpe:2.3:a:cmd-shim:cmd-shim:5.0.0:*:*:*:*:*:*:*",
 98782          "purl": "pkg:npm/cmd-shim@5.0.0",
 98783          "swid": {
 98784            "attachment": {}
 98785          },
 98786          "pedigree": {},
 98787          "externalReferences": [
 98788            {
 98789              "url": "https://github.com/npm/cmd-shim.git",
 98790              "type": "distribution"
 98791            }
 98792          ],
 98793          "evidence": {},
 98794          "signature": {
 98795            "signature": {
 98796              "publicKey": {}
 98797            }
 98798          },
 98799          "modelCard": {
 98800            "modelParameters": {
 98801              "approach": {}
 98802            },
 98803            "quantitativeAnalysis": {
 98804              "graphics": {}
 98805            },
 98806            "considerations": {}
 98807          }
 98808        },
 98809        {
 98810          "type": "library",
 98811          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=2be936aafe32cf82",
 98812          "supplier": {},
 98813          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
 98814          "name": "color-convert",
 98815          "version": "2.0.1",
 98816          "description": "Plain color conversion functions",
 98817          "licenses": [
 98818            {
 98819              "license": {
 98820                "id": "MIT"
 98821              }
 98822            }
 98823          ],
 98824          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
 98825          "purl": "pkg:npm/color-convert@2.0.1",
 98826          "swid": {
 98827            "attachment": {}
 98828          },
 98829          "pedigree": {},
 98830          "externalReferences": [
 98831            {
 98832              "url": "Qix-/color-convert",
 98833              "type": "distribution"
 98834            }
 98835          ],
 98836          "evidence": {},
 98837          "signature": {
 98838            "signature": {
 98839              "publicKey": {}
 98840            }
 98841          },
 98842          "modelCard": {
 98843            "modelParameters": {
 98844              "approach": {}
 98845            },
 98846            "quantitativeAnalysis": {
 98847              "graphics": {}
 98848            },
 98849            "considerations": {}
 98850          }
 98851        },
 98852        {
 98853          "type": "library",
 98854          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=1c1920af9ce590",
 98855          "supplier": {},
 98856          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
 98857          "name": "color-convert",
 98858          "version": "2.0.1",
 98859          "description": "Plain color conversion functions",
 98860          "licenses": [
 98861            {
 98862              "license": {
 98863                "id": "MIT"
 98864              }
 98865            }
 98866          ],
 98867          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
 98868          "purl": "pkg:npm/color-convert@2.0.1",
 98869          "swid": {
 98870            "attachment": {}
 98871          },
 98872          "pedigree": {},
 98873          "externalReferences": [
 98874            {
 98875              "url": "Qix-/color-convert",
 98876              "type": "distribution"
 98877            }
 98878          ],
 98879          "evidence": {},
 98880          "signature": {
 98881            "signature": {
 98882              "publicKey": {}
 98883            }
 98884          },
 98885          "modelCard": {
 98886            "modelParameters": {
 98887              "approach": {}
 98888            },
 98889            "quantitativeAnalysis": {
 98890              "graphics": {}
 98891            },
 98892            "considerations": {}
 98893          }
 98894        },
 98895        {
 98896          "type": "library",
 98897          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=b14fd2e37cdab40f",
 98898          "supplier": {},
 98899          "author": "DY \u003cdfcreative@gmail.com\u003e",
 98900          "name": "color-name",
 98901          "version": "1.1.4",
 98902          "description": "A list of color names and its values",
 98903          "licenses": [
 98904            {
 98905              "license": {
 98906                "id": "MIT"
 98907              }
 98908            }
 98909          ],
 98910          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
 98911          "purl": "pkg:npm/color-name@1.1.4",
 98912          "swid": {
 98913            "attachment": {}
 98914          },
 98915          "pedigree": {},
 98916          "externalReferences": [
 98917            {
 98918              "url": "git@github.com:colorjs/color-name.git",
 98919              "type": "distribution"
 98920            },
 98921            {
 98922              "url": "https://github.com/colorjs/color-name",
 98923              "type": "website"
 98924            }
 98925          ],
 98926          "evidence": {},
 98927          "signature": {
 98928            "signature": {
 98929              "publicKey": {}
 98930            }
 98931          },
 98932          "modelCard": {
 98933            "modelParameters": {
 98934              "approach": {}
 98935            },
 98936            "quantitativeAnalysis": {
 98937              "graphics": {}
 98938            },
 98939            "considerations": {}
 98940          }
 98941        },
 98942        {
 98943          "type": "library",
 98944          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=c3dbe87bc1017b67",
 98945          "supplier": {},
 98946          "author": "DY \u003cdfcreative@gmail.com\u003e",
 98947          "name": "color-name",
 98948          "version": "1.1.4",
 98949          "description": "A list of color names and its values",
 98950          "licenses": [
 98951            {
 98952              "license": {
 98953                "id": "MIT"
 98954              }
 98955            }
 98956          ],
 98957          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
 98958          "purl": "pkg:npm/color-name@1.1.4",
 98959          "swid": {
 98960            "attachment": {}
 98961          },
 98962          "pedigree": {},
 98963          "externalReferences": [
 98964            {
 98965              "url": "git@github.com:colorjs/color-name.git",
 98966              "type": "distribution"
 98967            },
 98968            {
 98969              "url": "https://github.com/colorjs/color-name",
 98970              "type": "website"
 98971            }
 98972          ],
 98973          "evidence": {},
 98974          "signature": {
 98975            "signature": {
 98976              "publicKey": {}
 98977            }
 98978          },
 98979          "modelCard": {
 98980            "modelParameters": {
 98981              "approach": {}
 98982            },
 98983            "quantitativeAnalysis": {
 98984              "graphics": {}
 98985            },
 98986            "considerations": {}
 98987          }
 98988        },
 98989        {
 98990          "type": "library",
 98991          "bom-ref": "pkg:npm/color-support@1.1.3?package-id=33c3f3c0dd43aff8",
 98992          "supplier": {},
 98993          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
 98994          "name": "color-support",
 98995          "version": "1.1.3",
 98996          "description": "A module which will endeavor to guess your terminal's level of color support.",
 98997          "licenses": [
 98998            {
 98999              "license": {
 99000                "id": "ISC"
 99001              }
 99002            }
 99003          ],
 99004          "cpe": "cpe:2.3:a:color-support:color-support:1.1.3:*:*:*:*:*:*:*",
 99005          "purl": "pkg:npm/color-support@1.1.3",
 99006          "swid": {
 99007            "attachment": {}
 99008          },
 99009          "pedigree": {},
 99010          "externalReferences": [
 99011            {
 99012              "url": "git+https://github.com/isaacs/color-support.git",
 99013              "type": "distribution"
 99014            }
 99015          ],
 99016          "evidence": {},
 99017          "signature": {
 99018            "signature": {
 99019              "publicKey": {}
 99020            }
 99021          },
 99022          "modelCard": {
 99023            "modelParameters": {
 99024              "approach": {}
 99025            },
 99026            "quantitativeAnalysis": {
 99027              "graphics": {}
 99028            },
 99029            "considerations": {}
 99030          }
 99031        },
 99032        {
 99033          "type": "library",
 99034          "bom-ref": "pkg:npm/columnify@1.6.0?package-id=fc90187aad4a6027",
 99035          "supplier": {},
 99036          "author": "Tim Oxley",
 99037          "name": "columnify",
 99038          "version": "1.6.0",
 99039          "description": "Render data in text columns. Supports in-column text-wrap.",
 99040          "licenses": [
 99041            {
 99042              "license": {
 99043                "id": "MIT"
 99044              }
 99045            }
 99046          ],
 99047          "cpe": "cpe:2.3:a:columnify:columnify:1.6.0:*:*:*:*:*:*:*",
 99048          "purl": "pkg:npm/columnify@1.6.0",
 99049          "swid": {
 99050            "attachment": {}
 99051          },
 99052          "pedigree": {},
 99053          "externalReferences": [
 99054            {
 99055              "url": "git://github.com/timoxley/columnify.git",
 99056              "type": "distribution"
 99057            },
 99058            {
 99059              "url": "https://github.com/timoxley/columnify",
 99060              "type": "website"
 99061            }
 99062          ],
 99063          "evidence": {},
 99064          "signature": {
 99065            "signature": {
 99066              "publicKey": {}
 99067            }
 99068          },
 99069          "modelCard": {
 99070            "modelParameters": {
 99071              "approach": {}
 99072            },
 99073            "quantitativeAnalysis": {
 99074              "graphics": {}
 99075            },
 99076            "considerations": {}
 99077          }
 99078        },
 99079        {
 99080          "type": "library",
 99081          "bom-ref": "pkg:npm/common-ancestor-path@1.0.1?package-id=4296edf5ae5437c0",
 99082          "supplier": {},
 99083          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
 99084          "name": "common-ancestor-path",
 99085          "version": "1.0.1",
 99086          "description": "Find the common ancestor of 2 or more paths on Windows or Unix",
 99087          "licenses": [
 99088            {
 99089              "license": {
 99090                "id": "ISC"
 99091              }
 99092            }
 99093          ],
 99094          "cpe": "cpe:2.3:a:common-ancestor-path:common-ancestor-path:1.0.1:*:*:*:*:*:*:*",
 99095          "purl": "pkg:npm/common-ancestor-path@1.0.1",
 99096          "swid": {
 99097            "attachment": {}
 99098          },
 99099          "pedigree": {},
 99100          "externalReferences": [
 99101            {
 99102              "url": "git+https://github.com/isaacs/common-ancestor-path",
 99103              "type": "distribution"
 99104            }
 99105          ],
 99106          "evidence": {},
 99107          "signature": {
 99108            "signature": {
 99109              "publicKey": {}
 99110            }
 99111          },
 99112          "modelCard": {
 99113            "modelParameters": {
 99114              "approach": {}
 99115            },
 99116            "quantitativeAnalysis": {
 99117              "graphics": {}
 99118            },
 99119            "considerations": {}
 99120          }
 99121        },
 99122        {
 99123          "type": "library",
 99124          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=bdf14b65a5715b98",
 99125          "supplier": {},
 99126          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
 99127          "name": "concat-map",
 99128          "version": "0.0.1",
 99129          "description": "concatenative mapdashery",
 99130          "licenses": [
 99131            {
 99132              "license": {
 99133                "id": "MIT"
 99134              }
 99135            }
 99136          ],
 99137          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
 99138          "purl": "pkg:npm/concat-map@0.0.1",
 99139          "swid": {
 99140            "attachment": {}
 99141          },
 99142          "pedigree": {},
 99143          "externalReferences": [
 99144            {
 99145              "url": "git://github.com/substack/node-concat-map.git",
 99146              "type": "distribution"
 99147            }
 99148          ],
 99149          "evidence": {},
 99150          "signature": {
 99151            "signature": {
 99152              "publicKey": {}
 99153            }
 99154          },
 99155          "modelCard": {
 99156            "modelParameters": {
 99157              "approach": {}
 99158            },
 99159            "quantitativeAnalysis": {
 99160              "graphics": {}
 99161            },
 99162            "considerations": {}
 99163          }
 99164        },
 99165        {
 99166          "type": "library",
 99167          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=c15f78c7f9b9bab",
 99168          "supplier": {},
 99169          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
 99170          "name": "concat-map",
 99171          "version": "0.0.1",
 99172          "description": "concatenative mapdashery",
 99173          "licenses": [
 99174            {
 99175              "license": {
 99176                "id": "MIT"
 99177              }
 99178            }
 99179          ],
 99180          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
 99181          "purl": "pkg:npm/concat-map@0.0.1",
 99182          "swid": {
 99183            "attachment": {}
 99184          },
 99185          "pedigree": {},
 99186          "externalReferences": [
 99187            {
 99188              "url": "git://github.com/substack/node-concat-map.git",
 99189              "type": "distribution"
 99190            }
 99191          ],
 99192          "evidence": {},
 99193          "signature": {
 99194            "signature": {
 99195              "publicKey": {}
 99196            }
 99197          },
 99198          "modelCard": {
 99199            "modelParameters": {
 99200              "approach": {}
 99201            },
 99202            "quantitativeAnalysis": {
 99203              "graphics": {}
 99204            },
 99205            "considerations": {}
 99206          }
 99207        },
 99208        {
 99209          "type": "library",
 99210          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=c45208cf5ec4e0c1",
 99211          "supplier": {},
 99212          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
 99213          "name": "concat-map",
 99214          "version": "0.0.1",
 99215          "description": "concatenative mapdashery",
 99216          "licenses": [
 99217            {
 99218              "license": {
 99219                "id": "MIT"
 99220              }
 99221            }
 99222          ],
 99223          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
 99224          "purl": "pkg:npm/concat-map@0.0.1",
 99225          "swid": {
 99226            "attachment": {}
 99227          },
 99228          "pedigree": {},
 99229          "externalReferences": [
 99230            {
 99231              "url": "git://github.com/substack/node-concat-map.git",
 99232              "type": "distribution"
 99233            }
 99234          ],
 99235          "evidence": {},
 99236          "signature": {
 99237            "signature": {
 99238              "publicKey": {}
 99239            }
 99240          },
 99241          "modelCard": {
 99242            "modelParameters": {
 99243              "approach": {}
 99244            },
 99245            "quantitativeAnalysis": {
 99246              "graphics": {}
 99247            },
 99248            "considerations": {}
 99249          }
 99250        },
 99251        {
 99252          "type": "library",
 99253          "bom-ref": "pkg:npm/console-control-strings@1.1.0?package-id=f5b1c468fcf0a37a",
 99254          "supplier": {},
 99255          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
 99256          "name": "console-control-strings",
 99257          "version": "1.1.0",
 99258          "description": "A library of cross-platform tested terminal/console command strings for doing things like color and cursor positioning.  This is a subset of both ansi and vt100.  All control codes included work on both Windows \u0026 Unix-like OSes, except where noted.",
 99259          "licenses": [
 99260            {
 99261              "license": {
 99262                "id": "ISC"
 99263              }
 99264            }
 99265          ],
 99266          "cpe": "cpe:2.3:a:console-control-strings:console-control-strings:1.1.0:*:*:*:*:*:*:*",
 99267          "purl": "pkg:npm/console-control-strings@1.1.0",
 99268          "swid": {
 99269            "attachment": {}
 99270          },
 99271          "pedigree": {},
 99272          "externalReferences": [
 99273            {
 99274              "url": "https://github.com/iarna/console-control-strings",
 99275              "type": "distribution"
 99276            }
 99277          ],
 99278          "evidence": {},
 99279          "signature": {
 99280            "signature": {
 99281              "publicKey": {}
 99282            }
 99283          },
 99284          "modelCard": {
 99285            "modelParameters": {
 99286              "approach": {}
 99287            },
 99288            "quantitativeAnalysis": {
 99289              "graphics": {}
 99290            },
 99291            "considerations": {}
 99292          }
 99293        },
 99294        {
 99295          "type": "library",
 99296          "bom-ref": "pkg:npm/content-disposition@0.5.2?package-id=78de68818c5e5be7",
 99297          "supplier": {},
 99298          "name": "content-disposition",
 99299          "version": "0.5.2",
 99300          "description": "Create and parse Content-Disposition header",
 99301          "licenses": [
 99302            {
 99303              "license": {
 99304                "id": "MIT"
 99305              }
 99306            }
 99307          ],
 99308          "cpe": "cpe:2.3:a:content-disposition:content-disposition:0.5.2:*:*:*:*:*:*:*",
 99309          "purl": "pkg:npm/content-disposition@0.5.2",
 99310          "swid": {
 99311            "attachment": {}
 99312          },
 99313          "pedigree": {},
 99314          "externalReferences": [
 99315            {
 99316              "url": "jshttp/content-disposition",
 99317              "type": "distribution"
 99318            }
 99319          ],
 99320          "evidence": {},
 99321          "signature": {
 99322            "signature": {
 99323              "publicKey": {}
 99324            }
 99325          },
 99326          "modelCard": {
 99327            "modelParameters": {
 99328              "approach": {}
 99329            },
 99330            "quantitativeAnalysis": {
 99331              "graphics": {}
 99332            },
 99333            "considerations": {}
 99334          }
 99335        },
 99336        {
 99337          "type": "library",
 99338          "bom-ref": "pkg:npm/content-type@1.0.5?package-id=adbc2d3e176aeaa7",
 99339          "supplier": {},
 99340          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
 99341          "name": "content-type",
 99342          "version": "1.0.5",
 99343          "description": "Create and parse HTTP Content-Type header",
 99344          "licenses": [
 99345            {
 99346              "license": {
 99347                "id": "MIT"
 99348              }
 99349            }
 99350          ],
 99351          "cpe": "cpe:2.3:a:content-type:content-type:1.0.5:*:*:*:*:*:*:*",
 99352          "purl": "pkg:npm/content-type@1.0.5",
 99353          "swid": {
 99354            "attachment": {}
 99355          },
 99356          "pedigree": {},
 99357          "externalReferences": [
 99358            {
 99359              "url": "jshttp/content-type",
 99360              "type": "distribution"
 99361            }
 99362          ],
 99363          "evidence": {},
 99364          "signature": {
 99365            "signature": {
 99366              "publicKey": {}
 99367            }
 99368          },
 99369          "modelCard": {
 99370            "modelParameters": {
 99371              "approach": {}
 99372            },
 99373            "quantitativeAnalysis": {
 99374              "graphics": {}
 99375            },
 99376            "considerations": {}
 99377          }
 99378        },
 99379        {
 99380          "type": "library",
 99381          "bom-ref": "pkg:npm/cookie@0.3.1?package-id=b346f101b9b48dd3",
 99382          "supplier": {},
 99383          "author": "Roman Shtylman \u003cshtylman@gmail.com\u003e",
 99384          "name": "cookie",
 99385          "version": "0.3.1",
 99386          "description": "HTTP server cookie parsing and serialization",
 99387          "licenses": [
 99388            {
 99389              "license": {
 99390                "id": "MIT"
 99391              }
 99392            }
 99393          ],
 99394          "cpe": "cpe:2.3:a:cookie:cookie:0.3.1:*:*:*:*:*:*:*",
 99395          "purl": "pkg:npm/cookie@0.3.1",
 99396          "swid": {
 99397            "attachment": {}
 99398          },
 99399          "pedigree": {},
 99400          "externalReferences": [
 99401            {
 99402              "url": "jshttp/cookie",
 99403              "type": "distribution"
 99404            }
 99405          ],
 99406          "evidence": {},
 99407          "signature": {
 99408            "signature": {
 99409              "publicKey": {}
 99410            }
 99411          },
 99412          "modelCard": {
 99413            "modelParameters": {
 99414              "approach": {}
 99415            },
 99416            "quantitativeAnalysis": {
 99417              "graphics": {}
 99418            },
 99419            "considerations": {}
 99420          }
 99421        },
 99422        {
 99423          "type": "library",
 99424          "bom-ref": "pkg:npm/cookie-signature@1.0.6?package-id=679e26b17ad72290",
 99425          "supplier": {},
 99426          "author": "TJ Holowaychuk \u003ctj@learnboost.com\u003e",
 99427          "name": "cookie-signature",
 99428          "version": "1.0.6",
 99429          "description": "Sign and unsign cookies",
 99430          "licenses": [
 99431            {
 99432              "license": {
 99433                "id": "MIT"
 99434              }
 99435            }
 99436          ],
 99437          "cpe": "cpe:2.3:a:cookie-signature:cookie-signature:1.0.6:*:*:*:*:*:*:*",
 99438          "purl": "pkg:npm/cookie-signature@1.0.6",
 99439          "swid": {
 99440            "attachment": {}
 99441          },
 99442          "pedigree": {},
 99443          "externalReferences": [
 99444            {
 99445              "url": "https://github.com/visionmedia/node-cookie-signature.git",
 99446              "type": "distribution"
 99447            }
 99448          ],
 99449          "evidence": {},
 99450          "signature": {
 99451            "signature": {
 99452              "publicKey": {}
 99453            }
 99454          },
 99455          "modelCard": {
 99456            "modelParameters": {
 99457              "approach": {}
 99458            },
 99459            "quantitativeAnalysis": {
 99460              "graphics": {}
 99461            },
 99462            "considerations": {}
 99463          }
 99464        },
 99465        {
 99466          "type": "library",
 99467          "bom-ref": "pkg:npm/corepack@0.17.0?package-id=9d78c3bef9c05db3",
 99468          "supplier": {},
 99469          "name": "corepack",
 99470          "version": "0.17.0",
 99471          "licenses": [
 99472            {
 99473              "license": {
 99474                "id": "MIT"
 99475              }
 99476            }
 99477          ],
 99478          "cpe": "cpe:2.3:a:corepack:corepack:0.17.0:*:*:*:*:*:*:*",
 99479          "purl": "pkg:npm/corepack@0.17.0",
 99480          "swid": {
 99481            "attachment": {}
 99482          },
 99483          "pedigree": {},
 99484          "externalReferences": [
 99485            {
 99486              "url": "https://github.com/nodejs/corepack.git",
 99487              "type": "distribution"
 99488            },
 99489            {
 99490              "url": "https://github.com/nodejs/corepack#readme",
 99491              "type": "website"
 99492            }
 99493          ],
 99494          "evidence": {},
 99495          "signature": {
 99496            "signature": {
 99497              "publicKey": {}
 99498            }
 99499          },
 99500          "modelCard": {
 99501            "modelParameters": {
 99502              "approach": {}
 99503            },
 99504            "quantitativeAnalysis": {
 99505              "graphics": {}
 99506            },
 99507            "considerations": {}
 99508          }
 99509        },
 99510        {
 99511          "type": "library",
 99512          "bom-ref": "pkg:npm/create-ecdh@4.0.4?package-id=b45460e0331583b4",
 99513          "supplier": {},
 99514          "author": "Calvin Metcalf",
 99515          "name": "create-ecdh",
 99516          "version": "4.0.4",
 99517          "description": "createECDH but browserifiable",
 99518          "licenses": [
 99519            {
 99520              "license": {
 99521                "id": "MIT"
 99522              }
 99523            }
 99524          ],
 99525          "cpe": "cpe:2.3:a:crypto-browserify:create-ecdh:4.0.4:*:*:*:*:*:*:*",
 99526          "purl": "pkg:npm/create-ecdh@4.0.4",
 99527          "swid": {
 99528            "attachment": {}
 99529          },
 99530          "pedigree": {},
 99531          "externalReferences": [
 99532            {
 99533              "url": "https://github.com/crypto-browserify/createECDH.git",
 99534              "type": "distribution"
 99535            },
 99536            {
 99537              "url": "https://github.com/crypto-browserify/createECDH",
 99538              "type": "website"
 99539            }
 99540          ],
 99541          "evidence": {},
 99542          "signature": {
 99543            "signature": {
 99544              "publicKey": {}
 99545            }
 99546          },
 99547          "modelCard": {
 99548            "modelParameters": {
 99549              "approach": {}
 99550            },
 99551            "quantitativeAnalysis": {
 99552              "graphics": {}
 99553            },
 99554            "considerations": {}
 99555          }
 99556        },
 99557        {
 99558          "type": "library",
 99559          "bom-ref": "pkg:npm/create-hash@1.2.0?package-id=f28df9aa357fdb38",
 99560          "supplier": {},
 99561          "name": "create-hash",
 99562          "version": "1.2.0",
 99563          "description": "create hashes for browserify",
 99564          "licenses": [
 99565            {
 99566              "license": {
 99567                "id": "MIT"
 99568              }
 99569            }
 99570          ],
 99571          "cpe": "cpe:2.3:a:crypto-browserify:create-hash:1.2.0:*:*:*:*:*:*:*",
 99572          "purl": "pkg:npm/create-hash@1.2.0",
 99573          "swid": {
 99574            "attachment": {}
 99575          },
 99576          "pedigree": {},
 99577          "externalReferences": [
 99578            {
 99579              "url": "git@github.com:crypto-browserify/createHash.git",
 99580              "type": "distribution"
 99581            },
 99582            {
 99583              "url": "https://github.com/crypto-browserify/createHash",
 99584              "type": "website"
 99585            }
 99586          ],
 99587          "evidence": {},
 99588          "signature": {
 99589            "signature": {
 99590              "publicKey": {}
 99591            }
 99592          },
 99593          "modelCard": {
 99594            "modelParameters": {
 99595              "approach": {}
 99596            },
 99597            "quantitativeAnalysis": {
 99598              "graphics": {}
 99599            },
 99600            "considerations": {}
 99601          }
 99602        },
 99603        {
 99604          "type": "library",
 99605          "bom-ref": "pkg:npm/create-hmac@1.1.7?package-id=71a8c4e54b7ee449",
 99606          "supplier": {},
 99607          "name": "create-hmac",
 99608          "version": "1.1.7",
 99609          "description": "node style hmacs in the browser",
 99610          "licenses": [
 99611            {
 99612              "license": {
 99613                "id": "MIT"
 99614              }
 99615            }
 99616          ],
 99617          "cpe": "cpe:2.3:a:crypto-browserify:create-hmac:1.1.7:*:*:*:*:*:*:*",
 99618          "purl": "pkg:npm/create-hmac@1.1.7",
 99619          "swid": {
 99620            "attachment": {}
 99621          },
 99622          "pedigree": {},
 99623          "externalReferences": [
 99624            {
 99625              "url": "https://github.com/crypto-browserify/createHmac.git",
 99626              "type": "distribution"
 99627            },
 99628            {
 99629              "url": "https://github.com/crypto-browserify/createHmac",
 99630              "type": "website"
 99631            }
 99632          ],
 99633          "evidence": {},
 99634          "signature": {
 99635            "signature": {
 99636              "publicKey": {}
 99637            }
 99638          },
 99639          "modelCard": {
 99640            "modelParameters": {
 99641              "approach": {}
 99642            },
 99643            "quantitativeAnalysis": {
 99644              "graphics": {}
 99645            },
 99646            "considerations": {}
 99647          }
 99648        },
 99649        {
 99650          "type": "library",
 99651          "bom-ref": "pkg:npm/cross-spawn@6.0.5?package-id=31d0427bcaf3eed4",
 99652          "supplier": {},
 99653          "author": "André Cruz \u003candre@moxy.studio\u003e",
 99654          "name": "cross-spawn",
 99655          "version": "6.0.5",
 99656          "description": "Cross platform child_process#spawn and child_process#spawnSync",
 99657          "licenses": [
 99658            {
 99659              "license": {
 99660                "id": "MIT"
 99661              }
 99662            }
 99663          ],
 99664          "cpe": "cpe:2.3:a:cross-spawn:cross-spawn:6.0.5:*:*:*:*:*:*:*",
 99665          "purl": "pkg:npm/cross-spawn@6.0.5",
 99666          "swid": {
 99667            "attachment": {}
 99668          },
 99669          "pedigree": {},
 99670          "externalReferences": [
 99671            {
 99672              "url": "git@github.com:moxystudio/node-cross-spawn.git",
 99673              "type": "distribution"
 99674            },
 99675            {
 99676              "url": "https://github.com/moxystudio/node-cross-spawn",
 99677              "type": "website"
 99678            }
 99679          ],
 99680          "evidence": {},
 99681          "signature": {
 99682            "signature": {
 99683              "publicKey": {}
 99684            }
 99685          },
 99686          "modelCard": {
 99687            "modelParameters": {
 99688              "approach": {}
 99689            },
 99690            "quantitativeAnalysis": {
 99691              "graphics": {}
 99692            },
 99693            "considerations": {}
 99694          }
 99695        },
 99696        {
 99697          "type": "library",
 99698          "bom-ref": "pkg:npm/crypto-browserify@3.12.0?package-id=ec5ba9013e6e2fd2",
 99699          "supplier": {},
 99700          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (dominictarr.com)",
 99701          "name": "crypto-browserify",
 99702          "version": "3.12.0",
 99703          "description": "implementation of crypto for the browser",
 99704          "licenses": [
 99705            {
 99706              "license": {
 99707                "id": "MIT"
 99708              }
 99709            }
 99710          ],
 99711          "cpe": "cpe:2.3:a:crypto-browserify:crypto-browserify:3.12.0:*:*:*:*:*:*:*",
 99712          "purl": "pkg:npm/crypto-browserify@3.12.0",
 99713          "swid": {
 99714            "attachment": {}
 99715          },
 99716          "pedigree": {},
 99717          "externalReferences": [
 99718            {
 99719              "url": "git://github.com/crypto-browserify/crypto-browserify.git",
 99720              "type": "distribution"
 99721            },
 99722            {
 99723              "url": "https://github.com/crypto-browserify/crypto-browserify",
 99724              "type": "website"
 99725            }
 99726          ],
 99727          "evidence": {},
 99728          "signature": {
 99729            "signature": {
 99730              "publicKey": {}
 99731            }
 99732          },
 99733          "modelCard": {
 99734            "modelParameters": {
 99735              "approach": {}
 99736            },
 99737            "quantitativeAnalysis": {
 99738              "graphics": {}
 99739            },
 99740            "considerations": {}
 99741          }
 99742        },
 99743        {
 99744          "type": "library",
 99745          "bom-ref": "pkg:npm/cssesc@3.0.0?package-id=91a6a74efc4b88ba",
 99746          "supplier": {},
 99747          "author": "Mathias Bynens (https://mathiasbynens.be/)",
 99748          "name": "cssesc",
 99749          "version": "3.0.0",
 99750          "description": "A JavaScript library for escaping CSS strings and identifiers while generating the shortest possible ASCII-only output.",
 99751          "licenses": [
 99752            {
 99753              "license": {
 99754                "id": "MIT"
 99755              }
 99756            }
 99757          ],
 99758          "cpe": "cpe:2.3:a:mathiasbynens:cssesc:3.0.0:*:*:*:*:*:*:*",
 99759          "purl": "pkg:npm/cssesc@3.0.0",
 99760          "swid": {
 99761            "attachment": {}
 99762          },
 99763          "pedigree": {},
 99764          "externalReferences": [
 99765            {
 99766              "url": "https://github.com/mathiasbynens/cssesc.git",
 99767              "type": "distribution"
 99768            },
 99769            {
 99770              "url": "https://mths.be/cssesc",
 99771              "type": "website"
 99772            }
 99773          ],
 99774          "evidence": {},
 99775          "signature": {
 99776            "signature": {
 99777              "publicKey": {}
 99778            }
 99779          },
 99780          "modelCard": {
 99781            "modelParameters": {
 99782              "approach": {}
 99783            },
 99784            "quantitativeAnalysis": {
 99785              "graphics": {}
 99786            },
 99787            "considerations": {}
 99788          }
 99789        },
 99790        {
 99791          "type": "library",
 99792          "bom-ref": "pkg:npm/debug@2.6.9?package-id=189dbf0c8c397194",
 99793          "supplier": {},
 99794          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
 99795          "name": "debug",
 99796          "version": "2.6.9",
 99797          "description": "small debugging utility",
 99798          "licenses": [
 99799            {
 99800              "license": {
 99801                "id": "MIT"
 99802              }
 99803            }
 99804          ],
 99805          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
 99806          "purl": "pkg:npm/debug@2.6.9",
 99807          "swid": {
 99808            "attachment": {}
 99809          },
 99810          "pedigree": {},
 99811          "externalReferences": [
 99812            {
 99813              "url": "git://github.com/visionmedia/debug.git",
 99814              "type": "distribution"
 99815            }
 99816          ],
 99817          "evidence": {},
 99818          "signature": {
 99819            "signature": {
 99820              "publicKey": {}
 99821            }
 99822          },
 99823          "modelCard": {
 99824            "modelParameters": {
 99825              "approach": {}
 99826            },
 99827            "quantitativeAnalysis": {
 99828              "graphics": {}
 99829            },
 99830            "considerations": {}
 99831          }
 99832        },
 99833        {
 99834          "type": "library",
 99835          "bom-ref": "pkg:npm/debug@4.3.4?package-id=744fe4d31961f128",
 99836          "supplier": {},
 99837          "author": "Josh Junon \u003cjosh.junon@protonmail.com\u003e",
 99838          "name": "debug",
 99839          "version": "4.3.4",
 99840          "description": "Lightweight debugging utility for Node.js and the browser",
 99841          "licenses": [
 99842            {
 99843              "license": {
 99844                "id": "MIT"
 99845              }
 99846            }
 99847          ],
 99848          "cpe": "cpe:2.3:a:debug-js:debug:4.3.4:*:*:*:*:*:*:*",
 99849          "purl": "pkg:npm/debug@4.3.4",
 99850          "swid": {
 99851            "attachment": {}
 99852          },
 99853          "pedigree": {},
 99854          "externalReferences": [
 99855            {
 99856              "url": "git://github.com/debug-js/debug.git",
 99857              "type": "distribution"
 99858            }
 99859          ],
 99860          "evidence": {},
 99861          "signature": {
 99862            "signature": {
 99863              "publicKey": {}
 99864            }
 99865          },
 99866          "modelCard": {
 99867            "modelParameters": {
 99868              "approach": {}
 99869            },
 99870            "quantitativeAnalysis": {
 99871              "graphics": {}
 99872            },
 99873            "considerations": {}
 99874          }
 99875        },
 99876        {
 99877          "type": "library",
 99878          "bom-ref": "pkg:npm/debuglog@1.0.1?package-id=de8cab91bb3727ee",
 99879          "supplier": {},
 99880          "author": "Sam Roberts \u003csam@strongloop.com\u003e",
 99881          "name": "debuglog",
 99882          "version": "1.0.1",
 99883          "description": "backport of util.debuglog from node v0.11",
 99884          "licenses": [
 99885            {
 99886              "license": {
 99887                "id": "MIT"
 99888              }
 99889            }
 99890          ],
 99891          "cpe": "cpe:2.3:a:sam-github:debuglog:1.0.1:*:*:*:*:*:*:*",
 99892          "purl": "pkg:npm/debuglog@1.0.1",
 99893          "swid": {
 99894            "attachment": {}
 99895          },
 99896          "pedigree": {},
 99897          "externalReferences": [
 99898            {
 99899              "url": "https://github.com/sam-github/node-debuglog.git",
 99900              "type": "distribution"
 99901            }
 99902          ],
 99903          "evidence": {},
 99904          "signature": {
 99905            "signature": {
 99906              "publicKey": {}
 99907            }
 99908          },
 99909          "modelCard": {
 99910            "modelParameters": {
 99911              "approach": {}
 99912            },
 99913            "quantitativeAnalysis": {
 99914              "graphics": {}
 99915            },
 99916            "considerations": {}
 99917          }
 99918        },
 99919        {
 99920          "type": "library",
 99921          "bom-ref": "pkg:npm/decode-uri-component@0.2.2?package-id=31befa3a8dff8fe1",
 99922          "supplier": {},
 99923          "author": "Sam Verschueren \u003csam.verschueren@gmail.com\u003e (github.com/SamVerschueren)",
 99924          "name": "decode-uri-component",
 99925          "version": "0.2.2",
 99926          "description": "A better decodeURIComponent",
 99927          "licenses": [
 99928            {
 99929              "license": {
 99930                "id": "MIT"
 99931              }
 99932            }
 99933          ],
 99934          "cpe": "cpe:2.3:a:decode-uri-component:decode-uri-component:0.2.2:*:*:*:*:*:*:*",
 99935          "purl": "pkg:npm/decode-uri-component@0.2.2",
 99936          "swid": {
 99937            "attachment": {}
 99938          },
 99939          "pedigree": {},
 99940          "externalReferences": [
 99941            {
 99942              "url": "SamVerschueren/decode-uri-component",
 99943              "type": "distribution"
 99944            }
 99945          ],
 99946          "evidence": {},
 99947          "signature": {
 99948            "signature": {
 99949              "publicKey": {}
 99950            }
 99951          },
 99952          "modelCard": {
 99953            "modelParameters": {
 99954              "approach": {}
 99955            },
 99956            "quantitativeAnalysis": {
 99957              "graphics": {}
 99958            },
 99959            "considerations": {}
 99960          }
 99961        },
 99962        {
 99963          "type": "library",
 99964          "bom-ref": "pkg:npm/defaults@1.0.3?package-id=539a687773af61fe",
 99965          "supplier": {},
 99966          "author": "Elijah Insua \u003ctmpvar@gmail.com\u003e",
 99967          "name": "defaults",
 99968          "version": "1.0.3",
 99969          "description": "merge single level defaults over a config object",
 99970          "licenses": [
 99971            {
 99972              "license": {
 99973                "id": "MIT"
 99974              }
 99975            }
 99976          ],
 99977          "cpe": "cpe:2.3:a:defaults:defaults:1.0.3:*:*:*:*:*:*:*",
 99978          "purl": "pkg:npm/defaults@1.0.3",
 99979          "swid": {
 99980            "attachment": {}
 99981          },
 99982          "pedigree": {},
 99983          "externalReferences": [
 99984            {
 99985              "url": "git://github.com/tmpvar/defaults.git",
 99986              "type": "distribution"
 99987            }
 99988          ],
 99989          "evidence": {},
 99990          "signature": {
 99991            "signature": {
 99992              "publicKey": {}
 99993            }
 99994          },
 99995          "modelCard": {
 99996            "modelParameters": {
 99997              "approach": {}
 99998            },
 99999            "quantitativeAnalysis": {
100000              "graphics": {}
100001            },
100002            "considerations": {}
100003          }
100004        },
100005        {
100006          "type": "library",
100007          "bom-ref": "pkg:npm/delegates@1.0.0?package-id=ed0c22d60c260f5c",
100008          "supplier": {},
100009          "name": "delegates",
100010          "version": "1.0.0",
100011          "description": "delegate methods and accessors to another property",
100012          "licenses": [
100013            {
100014              "license": {
100015                "id": "MIT"
100016              }
100017            }
100018          ],
100019          "cpe": "cpe:2.3:a:delegates:delegates:1.0.0:*:*:*:*:*:*:*",
100020          "purl": "pkg:npm/delegates@1.0.0",
100021          "swid": {
100022            "attachment": {}
100023          },
100024          "pedigree": {},
100025          "externalReferences": [
100026            {
100027              "url": "visionmedia/node-delegates",
100028              "type": "distribution"
100029            }
100030          ],
100031          "evidence": {},
100032          "signature": {
100033            "signature": {
100034              "publicKey": {}
100035            }
100036          },
100037          "modelCard": {
100038            "modelParameters": {
100039              "approach": {}
100040            },
100041            "quantitativeAnalysis": {
100042              "graphics": {}
100043            },
100044            "considerations": {}
100045          }
100046        },
100047        {
100048          "type": "library",
100049          "bom-ref": "pkg:npm/depd@1.1.2?package-id=8f51ca0c72f74b81",
100050          "supplier": {},
100051          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
100052          "name": "depd",
100053          "version": "1.1.2",
100054          "description": "Deprecate all the things",
100055          "licenses": [
100056            {
100057              "license": {
100058                "id": "MIT"
100059              }
100060            }
100061          ],
100062          "cpe": "cpe:2.3:a:depd:depd:1.1.2:*:*:*:*:*:*:*",
100063          "purl": "pkg:npm/depd@1.1.2",
100064          "swid": {
100065            "attachment": {}
100066          },
100067          "pedigree": {},
100068          "externalReferences": [
100069            {
100070              "url": "dougwilson/nodejs-depd",
100071              "type": "distribution"
100072            }
100073          ],
100074          "evidence": {},
100075          "signature": {
100076            "signature": {
100077              "publicKey": {}
100078            }
100079          },
100080          "modelCard": {
100081            "modelParameters": {
100082              "approach": {}
100083            },
100084            "quantitativeAnalysis": {
100085              "graphics": {}
100086            },
100087            "considerations": {}
100088          }
100089        },
100090        {
100091          "type": "library",
100092          "bom-ref": "pkg:npm/depd@1.1.2?package-id=88f59320de2b0d4a",
100093          "supplier": {},
100094          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
100095          "name": "depd",
100096          "version": "1.1.2",
100097          "description": "Deprecate all the things",
100098          "licenses": [
100099            {
100100              "license": {
100101                "id": "MIT"
100102              }
100103            }
100104          ],
100105          "cpe": "cpe:2.3:a:depd:depd:1.1.2:*:*:*:*:*:*:*",
100106          "purl": "pkg:npm/depd@1.1.2",
100107          "swid": {
100108            "attachment": {}
100109          },
100110          "pedigree": {},
100111          "externalReferences": [
100112            {
100113              "url": "dougwilson/nodejs-depd",
100114              "type": "distribution"
100115            }
100116          ],
100117          "evidence": {},
100118          "signature": {
100119            "signature": {
100120              "publicKey": {}
100121            }
100122          },
100123          "modelCard": {
100124            "modelParameters": {
100125              "approach": {}
100126            },
100127            "quantitativeAnalysis": {
100128              "graphics": {}
100129            },
100130            "considerations": {}
100131          }
100132        },
100133        {
100134          "type": "library",
100135          "bom-ref": "pkg:npm/des.js@1.0.1?package-id=c07ba0bda793e86e",
100136          "supplier": {},
100137          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
100138          "name": "des.js",
100139          "version": "1.0.1",
100140          "description": "DES implementation",
100141          "licenses": [
100142            {
100143              "license": {
100144                "id": "MIT"
100145              }
100146            }
100147          ],
100148          "cpe": "cpe:2.3:a:indutny:des.js:1.0.1:*:*:*:*:*:*:*",
100149          "purl": "pkg:npm/des.js@1.0.1",
100150          "swid": {
100151            "attachment": {}
100152          },
100153          "pedigree": {},
100154          "externalReferences": [
100155            {
100156              "url": "git+ssh://git@github.com/indutny/des.js.git",
100157              "type": "distribution"
100158            },
100159            {
100160              "url": "https://github.com/indutny/des.js#readme",
100161              "type": "website"
100162            }
100163          ],
100164          "evidence": {},
100165          "signature": {
100166            "signature": {
100167              "publicKey": {}
100168            }
100169          },
100170          "modelCard": {
100171            "modelParameters": {
100172              "approach": {}
100173            },
100174            "quantitativeAnalysis": {
100175              "graphics": {}
100176            },
100177            "considerations": {}
100178          }
100179        },
100180        {
100181          "type": "library",
100182          "bom-ref": "pkg:npm/destroy@1.0.4?package-id=7a46d2c188b90042",
100183          "supplier": {},
100184          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
100185          "name": "destroy",
100186          "version": "1.0.4",
100187          "description": "destroy a stream if possible",
100188          "licenses": [
100189            {
100190              "license": {
100191                "id": "MIT"
100192              }
100193            }
100194          ],
100195          "cpe": "cpe:2.3:a:destroy:destroy:1.0.4:*:*:*:*:*:*:*",
100196          "purl": "pkg:npm/destroy@1.0.4",
100197          "swid": {
100198            "attachment": {}
100199          },
100200          "pedigree": {},
100201          "externalReferences": [
100202            {
100203              "url": "stream-utils/destroy",
100204              "type": "distribution"
100205            }
100206          ],
100207          "evidence": {},
100208          "signature": {
100209            "signature": {
100210              "publicKey": {}
100211            }
100212          },
100213          "modelCard": {
100214            "modelParameters": {
100215              "approach": {}
100216            },
100217            "quantitativeAnalysis": {
100218              "graphics": {}
100219            },
100220            "considerations": {}
100221          }
100222        },
100223        {
100224          "type": "library",
100225          "bom-ref": "pkg:npm/dezalgo@1.0.4?package-id=d8ccca0e738815bf",
100226          "supplier": {},
100227          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
100228          "name": "dezalgo",
100229          "version": "1.0.4",
100230          "description": "Contain async insanity so that the dark pony lord doesn't eat souls",
100231          "licenses": [
100232            {
100233              "license": {
100234                "id": "ISC"
100235              }
100236            }
100237          ],
100238          "cpe": "cpe:2.3:a:dezalgo:dezalgo:1.0.4:*:*:*:*:*:*:*",
100239          "purl": "pkg:npm/dezalgo@1.0.4",
100240          "swid": {
100241            "attachment": {}
100242          },
100243          "pedigree": {},
100244          "externalReferences": [
100245            {
100246              "url": "https://github.com/npm/dezalgo",
100247              "type": "distribution"
100248            },
100249            {
100250              "url": "https://github.com/npm/dezalgo",
100251              "type": "website"
100252            }
100253          ],
100254          "evidence": {},
100255          "signature": {
100256            "signature": {
100257              "publicKey": {}
100258            }
100259          },
100260          "modelCard": {
100261            "modelParameters": {
100262              "approach": {}
100263            },
100264            "quantitativeAnalysis": {
100265              "graphics": {}
100266            },
100267            "considerations": {}
100268          }
100269        },
100270        {
100271          "type": "library",
100272          "bom-ref": "pkg:npm/diff@5.1.0?package-id=d6e2c2128602c71d",
100273          "supplier": {},
100274          "name": "diff",
100275          "version": "5.1.0",
100276          "description": "A javascript text diff implementation.",
100277          "licenses": [
100278            {
100279              "license": {
100280                "id": "BSD-3-Clause"
100281              }
100282            }
100283          ],
100284          "cpe": "cpe:2.3:a:kpdecker:diff:5.1.0:*:*:*:*:*:*:*",
100285          "purl": "pkg:npm/diff@5.1.0",
100286          "swid": {
100287            "attachment": {}
100288          },
100289          "pedigree": {},
100290          "externalReferences": [
100291            {
100292              "url": "git://github.com/kpdecker/jsdiff.git",
100293              "type": "distribution"
100294            }
100295          ],
100296          "evidence": {},
100297          "signature": {
100298            "signature": {
100299              "publicKey": {}
100300            }
100301          },
100302          "modelCard": {
100303            "modelParameters": {
100304              "approach": {}
100305            },
100306            "quantitativeAnalysis": {
100307              "graphics": {}
100308            },
100309            "considerations": {}
100310          }
100311        },
100312        {
100313          "type": "library",
100314          "bom-ref": "pkg:npm/diffie-hellman@5.0.3?package-id=62f60ea67b969d1c",
100315          "supplier": {},
100316          "author": "Calvin Metcalf",
100317          "name": "diffie-hellman",
100318          "version": "5.0.3",
100319          "description": "pure js diffie-hellman",
100320          "licenses": [
100321            {
100322              "license": {
100323                "id": "MIT"
100324              }
100325            }
100326          ],
100327          "cpe": "cpe:2.3:a:crypto-browserify:diffie-hellman:5.0.3:*:*:*:*:*:*:*",
100328          "purl": "pkg:npm/diffie-hellman@5.0.3",
100329          "swid": {
100330            "attachment": {}
100331          },
100332          "pedigree": {},
100333          "externalReferences": [
100334            {
100335              "url": "https://github.com/crypto-browserify/diffie-hellman.git",
100336              "type": "distribution"
100337            },
100338            {
100339              "url": "https://github.com/crypto-browserify/diffie-hellman",
100340              "type": "website"
100341            }
100342          ],
100343          "evidence": {},
100344          "signature": {
100345            "signature": {
100346              "publicKey": {}
100347            }
100348          },
100349          "modelCard": {
100350            "modelParameters": {
100351              "approach": {}
100352            },
100353            "quantitativeAnalysis": {
100354              "graphics": {}
100355            },
100356            "considerations": {}
100357          }
100358        },
100359        {
100360          "type": "library",
100361          "bom-ref": "pkg:npm/ee-first@1.1.1?package-id=e237c873e14ffd47",
100362          "supplier": {},
100363          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
100364          "name": "ee-first",
100365          "version": "1.1.1",
100366          "description": "return the first event in a set of ee/event pairs",
100367          "licenses": [
100368            {
100369              "license": {
100370                "id": "MIT"
100371              }
100372            }
100373          ],
100374          "cpe": "cpe:2.3:a:ee-first:ee-first:1.1.1:*:*:*:*:*:*:*",
100375          "purl": "pkg:npm/ee-first@1.1.1",
100376          "swid": {
100377            "attachment": {}
100378          },
100379          "pedigree": {},
100380          "externalReferences": [
100381            {
100382              "url": "jonathanong/ee-first",
100383              "type": "distribution"
100384            }
100385          ],
100386          "evidence": {},
100387          "signature": {
100388            "signature": {
100389              "publicKey": {}
100390            }
100391          },
100392          "modelCard": {
100393            "modelParameters": {
100394              "approach": {}
100395            },
100396            "quantitativeAnalysis": {
100397              "graphics": {}
100398            },
100399            "considerations": {}
100400          }
100401        },
100402        {
100403          "type": "library",
100404          "bom-ref": "pkg:npm/elliptic@6.5.4?package-id=8a118c20590b0861",
100405          "supplier": {},
100406          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
100407          "name": "elliptic",
100408          "version": "6.5.4",
100409          "description": "EC cryptography",
100410          "licenses": [
100411            {
100412              "license": {
100413                "id": "MIT"
100414              }
100415            }
100416          ],
100417          "cpe": "cpe:2.3:a:elliptic:elliptic:6.5.4:*:*:*:*:*:*:*",
100418          "purl": "pkg:npm/elliptic@6.5.4",
100419          "swid": {
100420            "attachment": {}
100421          },
100422          "pedigree": {},
100423          "externalReferences": [
100424            {
100425              "url": "git@github.com:indutny/elliptic",
100426              "type": "distribution"
100427            },
100428            {
100429              "url": "https://github.com/indutny/elliptic",
100430              "type": "website"
100431            }
100432          ],
100433          "evidence": {},
100434          "signature": {
100435            "signature": {
100436              "publicKey": {}
100437            }
100438          },
100439          "modelCard": {
100440            "modelParameters": {
100441              "approach": {}
100442            },
100443            "quantitativeAnalysis": {
100444              "graphics": {}
100445            },
100446            "considerations": {}
100447          }
100448        },
100449        {
100450          "type": "library",
100451          "bom-ref": "pkg:npm/emoji-regex@8.0.0?package-id=6bb38678688ed46f",
100452          "supplier": {},
100453          "author": "Mathias Bynens (https://mathiasbynens.be/)",
100454          "name": "emoji-regex",
100455          "version": "8.0.0",
100456          "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
100457          "licenses": [
100458            {
100459              "license": {
100460                "id": "MIT"
100461              }
100462            }
100463          ],
100464          "cpe": "cpe:2.3:a:mathiasbynens:emoji-regex:8.0.0:*:*:*:*:*:*:*",
100465          "purl": "pkg:npm/emoji-regex@8.0.0",
100466          "swid": {
100467            "attachment": {}
100468          },
100469          "pedigree": {},
100470          "externalReferences": [
100471            {
100472              "url": "https://github.com/mathiasbynens/emoji-regex.git",
100473              "type": "distribution"
100474            },
100475            {
100476              "url": "https://mths.be/emoji-regex",
100477              "type": "website"
100478            }
100479          ],
100480          "evidence": {},
100481          "signature": {
100482            "signature": {
100483              "publicKey": {}
100484            }
100485          },
100486          "modelCard": {
100487            "modelParameters": {
100488              "approach": {}
100489            },
100490            "quantitativeAnalysis": {
100491              "graphics": {}
100492            },
100493            "considerations": {}
100494          }
100495        },
100496        {
100497          "type": "library",
100498          "bom-ref": "pkg:npm/encodeurl@1.0.2?package-id=ca5122f9d292a60f",
100499          "supplier": {},
100500          "name": "encodeurl",
100501          "version": "1.0.2",
100502          "description": "Encode a URL to a percent-encoded form, excluding already-encoded sequences",
100503          "licenses": [
100504            {
100505              "license": {
100506                "id": "MIT"
100507              }
100508            }
100509          ],
100510          "cpe": "cpe:2.3:a:encodeurl:encodeurl:1.0.2:*:*:*:*:*:*:*",
100511          "purl": "pkg:npm/encodeurl@1.0.2",
100512          "swid": {
100513            "attachment": {}
100514          },
100515          "pedigree": {},
100516          "externalReferences": [
100517            {
100518              "url": "pillarjs/encodeurl",
100519              "type": "distribution"
100520            }
100521          ],
100522          "evidence": {},
100523          "signature": {
100524            "signature": {
100525              "publicKey": {}
100526            }
100527          },
100528          "modelCard": {
100529            "modelParameters": {
100530              "approach": {}
100531            },
100532            "quantitativeAnalysis": {
100533              "graphics": {}
100534            },
100535            "considerations": {}
100536          }
100537        },
100538        {
100539          "type": "library",
100540          "bom-ref": "pkg:npm/encoding@0.1.13?package-id=e65b6a429cd40212",
100541          "supplier": {},
100542          "author": "Andris Reinman",
100543          "name": "encoding",
100544          "version": "0.1.13",
100545          "description": "Convert encodings, uses iconv-lite",
100546          "licenses": [
100547            {
100548              "license": {
100549                "id": "MIT"
100550              }
100551            }
100552          ],
100553          "cpe": "cpe:2.3:a:encoding:encoding:0.1.13:*:*:*:*:*:*:*",
100554          "purl": "pkg:npm/encoding@0.1.13",
100555          "swid": {
100556            "attachment": {}
100557          },
100558          "pedigree": {},
100559          "externalReferences": [
100560            {
100561              "url": "https://github.com/andris9/encoding.git",
100562              "type": "distribution"
100563            }
100564          ],
100565          "evidence": {},
100566          "signature": {
100567            "signature": {
100568              "publicKey": {}
100569            }
100570          },
100571          "modelCard": {
100572            "modelParameters": {
100573              "approach": {}
100574            },
100575            "quantitativeAnalysis": {
100576              "graphics": {}
100577            },
100578            "considerations": {}
100579          }
100580        },
100581        {
100582          "type": "library",
100583          "bom-ref": "pkg:npm/env-paths@2.2.1?package-id=d14634fe75802cac",
100584          "supplier": {},
100585          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
100586          "name": "env-paths",
100587          "version": "2.2.1",
100588          "description": "Get paths for storing things like data, config, cache, etc",
100589          "licenses": [
100590            {
100591              "license": {
100592                "id": "MIT"
100593              }
100594            }
100595          ],
100596          "cpe": "cpe:2.3:a:env-paths:env-paths:2.2.1:*:*:*:*:*:*:*",
100597          "purl": "pkg:npm/env-paths@2.2.1",
100598          "swid": {
100599            "attachment": {}
100600          },
100601          "pedigree": {},
100602          "externalReferences": [
100603            {
100604              "url": "sindresorhus/env-paths",
100605              "type": "distribution"
100606            }
100607          ],
100608          "evidence": {},
100609          "signature": {
100610            "signature": {
100611              "publicKey": {}
100612            }
100613          },
100614          "modelCard": {
100615            "modelParameters": {
100616              "approach": {}
100617            },
100618            "quantitativeAnalysis": {
100619              "graphics": {}
100620            },
100621            "considerations": {}
100622          }
100623        },
100624        {
100625          "type": "library",
100626          "bom-ref": "pkg:npm/err-code@2.0.3?package-id=60b62094686938a4",
100627          "supplier": {},
100628          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
100629          "name": "err-code",
100630          "version": "2.0.3",
100631          "description": "Create an error with a code",
100632          "licenses": [
100633            {
100634              "license": {
100635                "id": "MIT"
100636              }
100637            }
100638          ],
100639          "cpe": "cpe:2.3:a:IndigoUnited:err-code:2.0.3:*:*:*:*:*:*:*",
100640          "purl": "pkg:npm/err-code@2.0.3",
100641          "swid": {
100642            "attachment": {}
100643          },
100644          "pedigree": {},
100645          "externalReferences": [
100646            {
100647              "url": "git://github.com/IndigoUnited/js-err-code.git",
100648              "type": "distribution"
100649            }
100650          ],
100651          "evidence": {},
100652          "signature": {
100653            "signature": {
100654              "publicKey": {}
100655            }
100656          },
100657          "modelCard": {
100658            "modelParameters": {
100659              "approach": {}
100660            },
100661            "quantitativeAnalysis": {
100662              "graphics": {}
100663            },
100664            "considerations": {}
100665          }
100666        },
100667        {
100668          "type": "library",
100669          "bom-ref": "pkg:npm/es6-error@4.1.1?package-id=816b6827010746b5",
100670          "supplier": {},
100671          "author": "Ben Youngblood",
100672          "name": "es6-error",
100673          "version": "4.1.1",
100674          "description": "Easily-extendable error for use with ES6 classes",
100675          "licenses": [
100676            {
100677              "license": {
100678                "id": "MIT"
100679              }
100680            }
100681          ],
100682          "cpe": "cpe:2.3:a:bjyoungblood:es6-error:4.1.1:*:*:*:*:*:*:*",
100683          "purl": "pkg:npm/es6-error@4.1.1",
100684          "swid": {
100685            "attachment": {}
100686          },
100687          "pedigree": {},
100688          "externalReferences": [
100689            {
100690              "url": "https://github.com/bjyoungblood/es6-error.git",
100691              "type": "distribution"
100692            },
100693            {
100694              "url": "https://github.com/bjyoungblood/es6-error",
100695              "type": "website"
100696            }
100697          ],
100698          "evidence": {},
100699          "signature": {
100700            "signature": {
100701              "publicKey": {}
100702            }
100703          },
100704          "modelCard": {
100705            "modelParameters": {
100706              "approach": {}
100707            },
100708            "quantitativeAnalysis": {
100709              "graphics": {}
100710            },
100711            "considerations": {}
100712          }
100713        },
100714        {
100715          "type": "library",
100716          "bom-ref": "pkg:npm/escape-html@1.0.3?package-id=29b06dd1d0ba635a",
100717          "supplier": {},
100718          "name": "escape-html",
100719          "version": "1.0.3",
100720          "description": "Escape string for use in HTML",
100721          "licenses": [
100722            {
100723              "license": {
100724                "id": "MIT"
100725              }
100726            }
100727          ],
100728          "cpe": "cpe:2.3:a:escape-html:escape-html:1.0.3:*:*:*:*:*:*:*",
100729          "purl": "pkg:npm/escape-html@1.0.3",
100730          "swid": {
100731            "attachment": {}
100732          },
100733          "pedigree": {},
100734          "externalReferences": [
100735            {
100736              "url": "component/escape-html",
100737              "type": "distribution"
100738            }
100739          ],
100740          "evidence": {},
100741          "signature": {
100742            "signature": {
100743              "publicKey": {}
100744            }
100745          },
100746          "modelCard": {
100747            "modelParameters": {
100748              "approach": {}
100749            },
100750            "quantitativeAnalysis": {
100751              "graphics": {}
100752            },
100753            "considerations": {}
100754          }
100755        },
100756        {
100757          "type": "library",
100758          "bom-ref": "pkg:npm/etag@1.8.1?package-id=9151d174424b86ef",
100759          "supplier": {},
100760          "name": "etag",
100761          "version": "1.8.1",
100762          "description": "Create simple HTTP ETags",
100763          "licenses": [
100764            {
100765              "license": {
100766                "id": "MIT"
100767              }
100768            }
100769          ],
100770          "cpe": "cpe:2.3:a:etag:etag:1.8.1:*:*:*:*:*:*:*",
100771          "purl": "pkg:npm/etag@1.8.1",
100772          "swid": {
100773            "attachment": {}
100774          },
100775          "pedigree": {},
100776          "externalReferences": [
100777            {
100778              "url": "jshttp/etag",
100779              "type": "distribution"
100780            }
100781          ],
100782          "evidence": {},
100783          "signature": {
100784            "signature": {
100785              "publicKey": {}
100786            }
100787          },
100788          "modelCard": {
100789            "modelParameters": {
100790              "approach": {}
100791            },
100792            "quantitativeAnalysis": {
100793              "graphics": {}
100794            },
100795            "considerations": {}
100796          }
100797        },
100798        {
100799          "type": "library",
100800          "bom-ref": "pkg:npm/evp_bytestokey@1.0.3?package-id=bde275f3f158817",
100801          "supplier": {},
100802          "author": "Calvin Metcalf \u003ccalvin.metcalf@gmail.com\u003e",
100803          "name": "evp_bytestokey",
100804          "version": "1.0.3",
100805          "description": "The insecure key derivation algorithm from OpenSSL",
100806          "licenses": [
100807            {
100808              "license": {
100809                "id": "MIT"
100810              }
100811            }
100812          ],
100813          "cpe": "cpe:2.3:a:crypto-browserify:evp-bytestokey:1.0.3:*:*:*:*:*:*:*",
100814          "purl": "pkg:npm/evp_bytestokey@1.0.3",
100815          "swid": {
100816            "attachment": {}
100817          },
100818          "pedigree": {},
100819          "externalReferences": [
100820            {
100821              "url": "https://github.com/crypto-browserify/EVP_BytesToKey.git",
100822              "type": "distribution"
100823            },
100824            {
100825              "url": "https://github.com/crypto-browserify/EVP_BytesToKey",
100826              "type": "website"
100827            }
100828          ],
100829          "evidence": {},
100830          "signature": {
100831            "signature": {
100832              "publicKey": {}
100833            }
100834          },
100835          "modelCard": {
100836            "modelParameters": {
100837              "approach": {}
100838            },
100839            "quantitativeAnalysis": {
100840              "graphics": {}
100841            },
100842            "considerations": {}
100843          }
100844        },
100845        {
100846          "type": "library",
100847          "bom-ref": "pkg:npm/express@4.16.4?package-id=7d091d958d9b922e",
100848          "supplier": {},
100849          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
100850          "name": "express",
100851          "version": "4.16.4",
100852          "description": "Fast, unopinionated, minimalist web framework",
100853          "licenses": [
100854            {
100855              "license": {
100856                "id": "MIT"
100857              }
100858            }
100859          ],
100860          "cpe": "cpe:2.3:a:express:express:4.16.4:*:*:*:*:*:*:*",
100861          "purl": "pkg:npm/express@4.16.4",
100862          "swid": {
100863            "attachment": {}
100864          },
100865          "pedigree": {},
100866          "externalReferences": [
100867            {
100868              "url": "expressjs/express",
100869              "type": "distribution"
100870            },
100871            {
100872              "url": "http://expressjs.com/",
100873              "type": "website"
100874            }
100875          ],
100876          "evidence": {},
100877          "signature": {
100878            "signature": {
100879              "publicKey": {}
100880            }
100881          },
100882          "modelCard": {
100883            "modelParameters": {
100884              "approach": {}
100885            },
100886            "quantitativeAnalysis": {
100887              "graphics": {}
100888            },
100889            "considerations": {}
100890          }
100891        },
100892        {
100893          "type": "library",
100894          "bom-ref": "pkg:npm/fast-xml-parser@4.2.2?package-id=5ddb8e3ae31f723e",
100895          "supplier": {},
100896          "author": "Amit Gupta (https://amitkumargupta.work/)",
100897          "name": "fast-xml-parser",
100898          "version": "4.2.2",
100899          "description": "Validate XML, Parse XML, Build XML without C/C++ based libraries",
100900          "licenses": [
100901            {
100902              "license": {
100903                "id": "MIT"
100904              }
100905            }
100906          ],
100907          "cpe": "cpe:2.3:a:NaturalIntelligence:fast-xml-parser:4.2.2:*:*:*:*:*:*:*",
100908          "purl": "pkg:npm/fast-xml-parser@4.2.2",
100909          "swid": {
100910            "attachment": {}
100911          },
100912          "pedigree": {},
100913          "externalReferences": [
100914            {
100915              "url": "https://github.com/NaturalIntelligence/fast-xml-parser",
100916              "type": "distribution"
100917            }
100918          ],
100919          "evidence": {},
100920          "signature": {
100921            "signature": {
100922              "publicKey": {}
100923            }
100924          },
100925          "modelCard": {
100926            "modelParameters": {
100927              "approach": {}
100928            },
100929            "quantitativeAnalysis": {
100930              "graphics": {}
100931            },
100932            "considerations": {}
100933          }
100934        },
100935        {
100936          "type": "library",
100937          "bom-ref": "pkg:npm/fastest-levenshtein@1.0.12?package-id=f703cf6832613e31",
100938          "supplier": {},
100939          "author": "Kasper U. Weihe",
100940          "name": "fastest-levenshtein",
100941          "version": "1.0.12",
100942          "description": "Fastest Levenshtein distance implementation in JS.",
100943          "licenses": [
100944            {
100945              "license": {
100946                "id": "MIT"
100947              }
100948            }
100949          ],
100950          "cpe": "cpe:2.3:a:fastest-levenshtein:fastest-levenshtein:1.0.12:*:*:*:*:*:*:*",
100951          "purl": "pkg:npm/fastest-levenshtein@1.0.12",
100952          "swid": {
100953            "attachment": {}
100954          },
100955          "pedigree": {},
100956          "externalReferences": [
100957            {
100958              "url": "git+https://github.com/ka-weihe/fastest-levenshtein.git",
100959              "type": "distribution"
100960            },
100961            {
100962              "url": "https://github.com/ka-weihe/fastest-levenshtein#README",
100963              "type": "website"
100964            }
100965          ],
100966          "evidence": {},
100967          "signature": {
100968            "signature": {
100969              "publicKey": {}
100970            }
100971          },
100972          "modelCard": {
100973            "modelParameters": {
100974              "approach": {}
100975            },
100976            "quantitativeAnalysis": {
100977              "graphics": {}
100978            },
100979            "considerations": {}
100980          }
100981        },
100982        {
100983          "type": "library",
100984          "bom-ref": "pkg:npm/fill-range@7.0.1?package-id=a4b7b1d7cebfd2b1",
100985          "supplier": {},
100986          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
100987          "name": "fill-range",
100988          "version": "7.0.1",
100989          "description": "Fill in a range of numbers or letters, optionally passing an increment or `step` to use, or create a regex-compatible range with `options.toRegex`",
100990          "licenses": [
100991            {
100992              "license": {
100993                "id": "MIT"
100994              }
100995            }
100996          ],
100997          "cpe": "cpe:2.3:a:jonschlinkert:fill-range:7.0.1:*:*:*:*:*:*:*",
100998          "purl": "pkg:npm/fill-range@7.0.1",
100999          "swid": {
101000            "attachment": {}
101001          },
101002          "pedigree": {},
101003          "externalReferences": [
101004            {
101005              "url": "jonschlinkert/fill-range",
101006              "type": "distribution"
101007            },
101008            {
101009              "url": "https://github.com/jonschlinkert/fill-range",
101010              "type": "website"
101011            }
101012          ],
101013          "evidence": {},
101014          "signature": {
101015            "signature": {
101016              "publicKey": {}
101017            }
101018          },
101019          "modelCard": {
101020            "modelParameters": {
101021              "approach": {}
101022            },
101023            "quantitativeAnalysis": {
101024              "graphics": {}
101025            },
101026            "considerations": {}
101027          }
101028        },
101029        {
101030          "type": "library",
101031          "bom-ref": "pkg:npm/filter-obj@1.1.0?package-id=213a98227edaa009",
101032          "supplier": {},
101033          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
101034          "name": "filter-obj",
101035          "version": "1.1.0",
101036          "description": "Filter object keys and values into a new object",
101037          "licenses": [
101038            {
101039              "license": {
101040                "id": "MIT"
101041              }
101042            }
101043          ],
101044          "cpe": "cpe:2.3:a:filter-obj:filter-obj:1.1.0:*:*:*:*:*:*:*",
101045          "purl": "pkg:npm/filter-obj@1.1.0",
101046          "swid": {
101047            "attachment": {}
101048          },
101049          "pedigree": {},
101050          "externalReferences": [
101051            {
101052              "url": "sindresorhus/filter-obj",
101053              "type": "distribution"
101054            }
101055          ],
101056          "evidence": {},
101057          "signature": {
101058            "signature": {
101059              "publicKey": {}
101060            }
101061          },
101062          "modelCard": {
101063            "modelParameters": {
101064              "approach": {}
101065            },
101066            "quantitativeAnalysis": {
101067              "graphics": {}
101068            },
101069            "considerations": {}
101070          }
101071        },
101072        {
101073          "type": "library",
101074          "bom-ref": "pkg:npm/finalhandler@1.1.1?package-id=f0968412c48fe760",
101075          "supplier": {},
101076          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
101077          "name": "finalhandler",
101078          "version": "1.1.1",
101079          "description": "Node.js final http responder",
101080          "licenses": [
101081            {
101082              "license": {
101083                "id": "MIT"
101084              }
101085            }
101086          ],
101087          "cpe": "cpe:2.3:a:finalhandler:finalhandler:1.1.1:*:*:*:*:*:*:*",
101088          "purl": "pkg:npm/finalhandler@1.1.1",
101089          "swid": {
101090            "attachment": {}
101091          },
101092          "pedigree": {},
101093          "externalReferences": [
101094            {
101095              "url": "pillarjs/finalhandler",
101096              "type": "distribution"
101097            }
101098          ],
101099          "evidence": {},
101100          "signature": {
101101            "signature": {
101102              "publicKey": {}
101103            }
101104          },
101105          "modelCard": {
101106            "modelParameters": {
101107              "approach": {}
101108            },
101109            "quantitativeAnalysis": {
101110              "graphics": {}
101111            },
101112            "considerations": {}
101113          }
101114        },
101115        {
101116          "type": "library",
101117          "bom-ref": "pkg:npm/find-yarn-workspace-root@2.0.0?package-id=a79b79a711a6c960",
101118          "supplier": {},
101119          "author": "Square, Inc.",
101120          "name": "find-yarn-workspace-root",
101121          "version": "2.0.0",
101122          "description": "Algorithm for finding the root of a yarn workspace, extracted from yarnpkg.com",
101123          "licenses": [
101124            {
101125              "license": {
101126                "id": "Apache-2.0"
101127              }
101128            }
101129          ],
101130          "cpe": "cpe:2.3:a:find-yarn-workspace-root:find-yarn-workspace-root:2.0.0:*:*:*:*:*:*:*",
101131          "purl": "pkg:npm/find-yarn-workspace-root@2.0.0",
101132          "swid": {
101133            "attachment": {}
101134          },
101135          "pedigree": {},
101136          "externalReferences": [
101137            {
101138              "url": "https://github.com/square/find-yarn-workspace-root.git",
101139              "type": "distribution"
101140            }
101141          ],
101142          "evidence": {},
101143          "signature": {
101144            "signature": {
101145              "publicKey": {}
101146            }
101147          },
101148          "modelCard": {
101149            "modelParameters": {
101150              "approach": {}
101151            },
101152            "quantitativeAnalysis": {
101153              "graphics": {}
101154            },
101155            "considerations": {}
101156          }
101157        },
101158        {
101159          "type": "library",
101160          "bom-ref": "pkg:npm/for-each@0.3.3?package-id=a909d4a653a0711c",
101161          "supplier": {},
101162          "author": "Raynos \u003craynos2@gmail.com\u003e",
101163          "name": "for-each",
101164          "version": "0.3.3",
101165          "description": "A better forEach",
101166          "licenses": [
101167            {
101168              "license": {
101169                "id": "MIT"
101170              }
101171            }
101172          ],
101173          "cpe": "cpe:2.3:a:for-each:for-each:0.3.3:*:*:*:*:*:*:*",
101174          "purl": "pkg:npm/for-each@0.3.3",
101175          "swid": {
101176            "attachment": {}
101177          },
101178          "pedigree": {},
101179          "externalReferences": [
101180            {
101181              "url": "git://github.com/Raynos/for-each.git",
101182              "type": "distribution"
101183            },
101184            {
101185              "url": "https://github.com/Raynos/for-each",
101186              "type": "website"
101187            }
101188          ],
101189          "evidence": {},
101190          "signature": {
101191            "signature": {
101192              "publicKey": {}
101193            }
101194          },
101195          "modelCard": {
101196            "modelParameters": {
101197              "approach": {}
101198            },
101199            "quantitativeAnalysis": {
101200              "graphics": {}
101201            },
101202            "considerations": {}
101203          }
101204        },
101205        {
101206          "type": "library",
101207          "bom-ref": "pkg:npm/forwarded@0.2.0?package-id=e2cd353a11409247",
101208          "supplier": {},
101209          "name": "forwarded",
101210          "version": "0.2.0",
101211          "description": "Parse HTTP X-Forwarded-For header",
101212          "licenses": [
101213            {
101214              "license": {
101215                "id": "MIT"
101216              }
101217            }
101218          ],
101219          "cpe": "cpe:2.3:a:forwarded:forwarded:0.2.0:*:*:*:*:*:*:*",
101220          "purl": "pkg:npm/forwarded@0.2.0",
101221          "swid": {
101222            "attachment": {}
101223          },
101224          "pedigree": {},
101225          "externalReferences": [
101226            {
101227              "url": "jshttp/forwarded",
101228              "type": "distribution"
101229            }
101230          ],
101231          "evidence": {},
101232          "signature": {
101233            "signature": {
101234              "publicKey": {}
101235            }
101236          },
101237          "modelCard": {
101238            "modelParameters": {
101239              "approach": {}
101240            },
101241            "quantitativeAnalysis": {
101242              "graphics": {}
101243            },
101244            "considerations": {}
101245          }
101246        },
101247        {
101248          "type": "library",
101249          "bom-ref": "pkg:npm/fresh@0.5.2?package-id=7080d1485688188f",
101250          "supplier": {},
101251          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
101252          "name": "fresh",
101253          "version": "0.5.2",
101254          "description": "HTTP response freshness testing",
101255          "licenses": [
101256            {
101257              "license": {
101258                "id": "MIT"
101259              }
101260            }
101261          ],
101262          "cpe": "cpe:2.3:a:fresh:fresh:0.5.2:*:*:*:*:*:*:*",
101263          "purl": "pkg:npm/fresh@0.5.2",
101264          "swid": {
101265            "attachment": {}
101266          },
101267          "pedigree": {},
101268          "externalReferences": [
101269            {
101270              "url": "jshttp/fresh",
101271              "type": "distribution"
101272            }
101273          ],
101274          "evidence": {},
101275          "signature": {
101276            "signature": {
101277              "publicKey": {}
101278            }
101279          },
101280          "modelCard": {
101281            "modelParameters": {
101282              "approach": {}
101283            },
101284            "quantitativeAnalysis": {
101285              "graphics": {}
101286            },
101287            "considerations": {}
101288          }
101289        },
101290        {
101291          "type": "library",
101292          "bom-ref": "pkg:npm/fs-extra@8.1.0?package-id=fd32f6ef9252a576",
101293          "supplier": {},
101294          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
101295          "name": "fs-extra",
101296          "version": "8.1.0",
101297          "description": "fs-extra contains methods that aren't included in the vanilla Node.js fs package. Such as mkdir -p, cp -r, and rm -rf.",
101298          "licenses": [
101299            {
101300              "license": {
101301                "id": "MIT"
101302              }
101303            }
101304          ],
101305          "cpe": "cpe:2.3:a:jprichardson:fs-extra:8.1.0:*:*:*:*:*:*:*",
101306          "purl": "pkg:npm/fs-extra@8.1.0",
101307          "swid": {
101308            "attachment": {}
101309          },
101310          "pedigree": {},
101311          "externalReferences": [
101312            {
101313              "url": "https://github.com/jprichardson/node-fs-extra",
101314              "type": "distribution"
101315            },
101316            {
101317              "url": "https://github.com/jprichardson/node-fs-extra",
101318              "type": "website"
101319            }
101320          ],
101321          "evidence": {},
101322          "signature": {
101323            "signature": {
101324              "publicKey": {}
101325            }
101326          },
101327          "modelCard": {
101328            "modelParameters": {
101329              "approach": {}
101330            },
101331            "quantitativeAnalysis": {
101332              "graphics": {}
101333            },
101334            "considerations": {}
101335          }
101336        },
101337        {
101338          "type": "library",
101339          "bom-ref": "pkg:npm/fs-extra@9.1.0?package-id=c7b63630e3cca57a",
101340          "supplier": {},
101341          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
101342          "name": "fs-extra",
101343          "version": "9.1.0",
101344          "description": "fs-extra contains methods that aren't included in the vanilla Node.js fs package. Such as recursive mkdir, copy, and remove.",
101345          "licenses": [
101346            {
101347              "license": {
101348                "id": "MIT"
101349              }
101350            }
101351          ],
101352          "cpe": "cpe:2.3:a:jprichardson:fs-extra:9.1.0:*:*:*:*:*:*:*",
101353          "purl": "pkg:npm/fs-extra@9.1.0",
101354          "swid": {
101355            "attachment": {}
101356          },
101357          "pedigree": {},
101358          "externalReferences": [
101359            {
101360              "url": "https://github.com/jprichardson/node-fs-extra",
101361              "type": "distribution"
101362            },
101363            {
101364              "url": "https://github.com/jprichardson/node-fs-extra",
101365              "type": "website"
101366            }
101367          ],
101368          "evidence": {},
101369          "signature": {
101370            "signature": {
101371              "publicKey": {}
101372            }
101373          },
101374          "modelCard": {
101375            "modelParameters": {
101376              "approach": {}
101377            },
101378            "quantitativeAnalysis": {
101379              "graphics": {}
101380            },
101381            "considerations": {}
101382          }
101383        },
101384        {
101385          "type": "library",
101386          "bom-ref": "pkg:npm/fs-minipass@2.1.0?package-id=398fbbb28fb7e1f4",
101387          "supplier": {},
101388          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101389          "name": "fs-minipass",
101390          "version": "2.1.0",
101391          "description": "fs read and write streams based on minipass",
101392          "licenses": [
101393            {
101394              "license": {
101395                "id": "ISC"
101396              }
101397            }
101398          ],
101399          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:2.1.0:*:*:*:*:*:*:*",
101400          "purl": "pkg:npm/fs-minipass@2.1.0",
101401          "swid": {
101402            "attachment": {}
101403          },
101404          "pedigree": {},
101405          "externalReferences": [
101406            {
101407              "url": "git+https://github.com/npm/fs-minipass.git",
101408              "type": "distribution"
101409            },
101410            {
101411              "url": "https://github.com/npm/fs-minipass#readme",
101412              "type": "website"
101413            }
101414          ],
101415          "evidence": {},
101416          "signature": {
101417            "signature": {
101418              "publicKey": {}
101419            }
101420          },
101421          "modelCard": {
101422            "modelParameters": {
101423              "approach": {}
101424            },
101425            "quantitativeAnalysis": {
101426              "graphics": {}
101427            },
101428            "considerations": {}
101429          }
101430        },
101431        {
101432          "type": "library",
101433          "bom-ref": "pkg:npm/fs-minipass@2.1.0?package-id=f1b7ae0257cf54f0",
101434          "supplier": {},
101435          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101436          "name": "fs-minipass",
101437          "version": "2.1.0",
101438          "description": "fs read and write streams based on minipass",
101439          "licenses": [
101440            {
101441              "license": {
101442                "id": "ISC"
101443              }
101444            }
101445          ],
101446          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:2.1.0:*:*:*:*:*:*:*",
101447          "purl": "pkg:npm/fs-minipass@2.1.0",
101448          "swid": {
101449            "attachment": {}
101450          },
101451          "pedigree": {},
101452          "externalReferences": [
101453            {
101454              "url": "git+https://github.com/npm/fs-minipass.git",
101455              "type": "distribution"
101456            },
101457            {
101458              "url": "https://github.com/npm/fs-minipass#readme",
101459              "type": "website"
101460            }
101461          ],
101462          "evidence": {},
101463          "signature": {
101464            "signature": {
101465              "publicKey": {}
101466            }
101467          },
101468          "modelCard": {
101469            "modelParameters": {
101470              "approach": {}
101471            },
101472            "quantitativeAnalysis": {
101473              "graphics": {}
101474            },
101475            "considerations": {}
101476          }
101477        },
101478        {
101479          "type": "library",
101480          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=21800424481533b1",
101481          "supplier": {},
101482          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101483          "name": "fs.realpath",
101484          "version": "1.0.0",
101485          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
101486          "licenses": [
101487            {
101488              "license": {
101489                "id": "ISC"
101490              }
101491            }
101492          ],
101493          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
101494          "purl": "pkg:npm/fs.realpath@1.0.0",
101495          "swid": {
101496            "attachment": {}
101497          },
101498          "pedigree": {},
101499          "externalReferences": [
101500            {
101501              "url": "git+https://github.com/isaacs/fs.realpath.git",
101502              "type": "distribution"
101503            }
101504          ],
101505          "evidence": {},
101506          "signature": {
101507            "signature": {
101508              "publicKey": {}
101509            }
101510          },
101511          "modelCard": {
101512            "modelParameters": {
101513              "approach": {}
101514            },
101515            "quantitativeAnalysis": {
101516              "graphics": {}
101517            },
101518            "considerations": {}
101519          }
101520        },
101521        {
101522          "type": "library",
101523          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=816b388b95d77c82",
101524          "supplier": {},
101525          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101526          "name": "fs.realpath",
101527          "version": "1.0.0",
101528          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
101529          "licenses": [
101530            {
101531              "license": {
101532                "id": "ISC"
101533              }
101534            }
101535          ],
101536          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
101537          "purl": "pkg:npm/fs.realpath@1.0.0",
101538          "swid": {
101539            "attachment": {}
101540          },
101541          "pedigree": {},
101542          "externalReferences": [
101543            {
101544              "url": "git+https://github.com/isaacs/fs.realpath.git",
101545              "type": "distribution"
101546            }
101547          ],
101548          "evidence": {},
101549          "signature": {
101550            "signature": {
101551              "publicKey": {}
101552            }
101553          },
101554          "modelCard": {
101555            "modelParameters": {
101556              "approach": {}
101557            },
101558            "quantitativeAnalysis": {
101559              "graphics": {}
101560            },
101561            "considerations": {}
101562          }
101563        },
101564        {
101565          "type": "library",
101566          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=65729748c227165e",
101567          "supplier": {},
101568          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101569          "name": "fs.realpath",
101570          "version": "1.0.0",
101571          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
101572          "licenses": [
101573            {
101574              "license": {
101575                "id": "ISC"
101576              }
101577            }
101578          ],
101579          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
101580          "purl": "pkg:npm/fs.realpath@1.0.0",
101581          "swid": {
101582            "attachment": {}
101583          },
101584          "pedigree": {},
101585          "externalReferences": [
101586            {
101587              "url": "git+https://github.com/isaacs/fs.realpath.git",
101588              "type": "distribution"
101589            }
101590          ],
101591          "evidence": {},
101592          "signature": {
101593            "signature": {
101594              "publicKey": {}
101595            }
101596          },
101597          "modelCard": {
101598            "modelParameters": {
101599              "approach": {}
101600            },
101601            "quantitativeAnalysis": {
101602              "graphics": {}
101603            },
101604            "considerations": {}
101605          }
101606        },
101607        {
101608          "type": "library",
101609          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=44648bf09db15f6c",
101610          "supplier": {},
101611          "author": "Raynos \u003craynos2@gmail.com\u003e",
101612          "name": "function-bind",
101613          "version": "1.1.1",
101614          "description": "Implementation of Function.prototype.bind",
101615          "licenses": [
101616            {
101617              "license": {
101618                "id": "MIT"
101619              }
101620            }
101621          ],
101622          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
101623          "purl": "pkg:npm/function-bind@1.1.1",
101624          "swid": {
101625            "attachment": {}
101626          },
101627          "pedigree": {},
101628          "externalReferences": [
101629            {
101630              "url": "git://github.com/Raynos/function-bind.git",
101631              "type": "distribution"
101632            },
101633            {
101634              "url": "https://github.com/Raynos/function-bind",
101635              "type": "website"
101636            }
101637          ],
101638          "evidence": {},
101639          "signature": {
101640            "signature": {
101641              "publicKey": {}
101642            }
101643          },
101644          "modelCard": {
101645            "modelParameters": {
101646              "approach": {}
101647            },
101648            "quantitativeAnalysis": {
101649              "graphics": {}
101650            },
101651            "considerations": {}
101652          }
101653        },
101654        {
101655          "type": "library",
101656          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=7bd79c8f88820292",
101657          "supplier": {},
101658          "author": "Raynos \u003craynos2@gmail.com\u003e",
101659          "name": "function-bind",
101660          "version": "1.1.1",
101661          "description": "Implementation of Function.prototype.bind",
101662          "licenses": [
101663            {
101664              "license": {
101665                "id": "MIT"
101666              }
101667            }
101668          ],
101669          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
101670          "purl": "pkg:npm/function-bind@1.1.1",
101671          "swid": {
101672            "attachment": {}
101673          },
101674          "pedigree": {},
101675          "externalReferences": [
101676            {
101677              "url": "git://github.com/Raynos/function-bind.git",
101678              "type": "distribution"
101679            },
101680            {
101681              "url": "https://github.com/Raynos/function-bind",
101682              "type": "website"
101683            }
101684          ],
101685          "evidence": {},
101686          "signature": {
101687            "signature": {
101688              "publicKey": {}
101689            }
101690          },
101691          "modelCard": {
101692            "modelParameters": {
101693              "approach": {}
101694            },
101695            "quantitativeAnalysis": {
101696              "graphics": {}
101697            },
101698            "considerations": {}
101699          }
101700        },
101701        {
101702          "type": "library",
101703          "bom-ref": "pkg:npm/gauge@4.0.4?package-id=fc4632a6e143d550",
101704          "supplier": {},
101705          "author": "GitHub Inc.",
101706          "name": "gauge",
101707          "version": "4.0.4",
101708          "description": "A terminal based horizontal gauge",
101709          "licenses": [
101710            {
101711              "license": {
101712                "id": "ISC"
101713              }
101714            }
101715          ],
101716          "cpe": "cpe:2.3:a:gauge:gauge:4.0.4:*:*:*:*:*:*:*",
101717          "purl": "pkg:npm/gauge@4.0.4",
101718          "swid": {
101719            "attachment": {}
101720          },
101721          "pedigree": {},
101722          "externalReferences": [
101723            {
101724              "url": "https://github.com/npm/gauge.git",
101725              "type": "distribution"
101726            },
101727            {
101728              "url": "https://github.com/npm/gauge",
101729              "type": "website"
101730            }
101731          ],
101732          "evidence": {},
101733          "signature": {
101734            "signature": {
101735              "publicKey": {}
101736            }
101737          },
101738          "modelCard": {
101739            "modelParameters": {
101740              "approach": {}
101741            },
101742            "quantitativeAnalysis": {
101743              "graphics": {}
101744            },
101745            "considerations": {}
101746          }
101747        },
101748        {
101749          "type": "library",
101750          "bom-ref": "pkg:npm/get-intrinsic@1.2.0?package-id=6ad275eae612456f",
101751          "supplier": {},
101752          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
101753          "name": "get-intrinsic",
101754          "version": "1.2.0",
101755          "description": "Get and robustly cache all JS language-level intrinsics at first require time",
101756          "licenses": [
101757            {
101758              "license": {
101759                "id": "MIT"
101760              }
101761            }
101762          ],
101763          "cpe": "cpe:2.3:a:get-intrinsic:get-intrinsic:1.2.0:*:*:*:*:*:*:*",
101764          "purl": "pkg:npm/get-intrinsic@1.2.0",
101765          "swid": {
101766            "attachment": {}
101767          },
101768          "pedigree": {},
101769          "externalReferences": [
101770            {
101771              "url": "git+https://github.com/ljharb/get-intrinsic.git",
101772              "type": "distribution"
101773            },
101774            {
101775              "url": "https://github.com/ljharb/get-intrinsic#readme",
101776              "type": "website"
101777            }
101778          ],
101779          "evidence": {},
101780          "signature": {
101781            "signature": {
101782              "publicKey": {}
101783            }
101784          },
101785          "modelCard": {
101786            "modelParameters": {
101787              "approach": {}
101788            },
101789            "quantitativeAnalysis": {
101790              "graphics": {}
101791            },
101792            "considerations": {}
101793          }
101794        },
101795        {
101796          "type": "library",
101797          "bom-ref": "pkg:npm/glob@7.2.3?package-id=b961e222f6e54786",
101798          "supplier": {},
101799          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101800          "name": "glob",
101801          "version": "7.2.3",
101802          "description": "a little globber",
101803          "licenses": [
101804            {
101805              "license": {
101806                "id": "ISC"
101807              }
101808            }
101809          ],
101810          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
101811          "purl": "pkg:npm/glob@7.2.3",
101812          "swid": {
101813            "attachment": {}
101814          },
101815          "pedigree": {},
101816          "externalReferences": [
101817            {
101818              "url": "git://github.com/isaacs/node-glob.git",
101819              "type": "distribution"
101820            }
101821          ],
101822          "evidence": {},
101823          "signature": {
101824            "signature": {
101825              "publicKey": {}
101826            }
101827          },
101828          "modelCard": {
101829            "modelParameters": {
101830              "approach": {}
101831            },
101832            "quantitativeAnalysis": {
101833              "graphics": {}
101834            },
101835            "considerations": {}
101836          }
101837        },
101838        {
101839          "type": "library",
101840          "bom-ref": "pkg:npm/glob@7.2.3?package-id=37af2473a85a6fa0",
101841          "supplier": {},
101842          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101843          "name": "glob",
101844          "version": "7.2.3",
101845          "description": "a little globber",
101846          "licenses": [
101847            {
101848              "license": {
101849                "id": "ISC"
101850              }
101851            }
101852          ],
101853          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
101854          "purl": "pkg:npm/glob@7.2.3",
101855          "swid": {
101856            "attachment": {}
101857          },
101858          "pedigree": {},
101859          "externalReferences": [
101860            {
101861              "url": "git://github.com/isaacs/node-glob.git",
101862              "type": "distribution"
101863            }
101864          ],
101865          "evidence": {},
101866          "signature": {
101867            "signature": {
101868              "publicKey": {}
101869            }
101870          },
101871          "modelCard": {
101872            "modelParameters": {
101873              "approach": {}
101874            },
101875            "quantitativeAnalysis": {
101876              "graphics": {}
101877            },
101878            "considerations": {}
101879          }
101880        },
101881        {
101882          "type": "library",
101883          "bom-ref": "pkg:npm/glob@7.2.3?package-id=93342fc8b69cf007",
101884          "supplier": {},
101885          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101886          "name": "glob",
101887          "version": "7.2.3",
101888          "description": "a little globber",
101889          "licenses": [
101890            {
101891              "license": {
101892                "id": "ISC"
101893              }
101894            }
101895          ],
101896          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
101897          "purl": "pkg:npm/glob@7.2.3",
101898          "swid": {
101899            "attachment": {}
101900          },
101901          "pedigree": {},
101902          "externalReferences": [
101903            {
101904              "url": "git://github.com/isaacs/node-glob.git",
101905              "type": "distribution"
101906            }
101907          ],
101908          "evidence": {},
101909          "signature": {
101910            "signature": {
101911              "publicKey": {}
101912            }
101913          },
101914          "modelCard": {
101915            "modelParameters": {
101916              "approach": {}
101917            },
101918            "quantitativeAnalysis": {
101919              "graphics": {}
101920            },
101921            "considerations": {}
101922          }
101923        },
101924        {
101925          "type": "library",
101926          "bom-ref": "pkg:npm/glob@7.2.3?package-id=27f74d4e19b8aa02",
101927          "supplier": {},
101928          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101929          "name": "glob",
101930          "version": "7.2.3",
101931          "description": "a little globber",
101932          "licenses": [
101933            {
101934              "license": {
101935                "id": "ISC"
101936              }
101937            }
101938          ],
101939          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
101940          "purl": "pkg:npm/glob@7.2.3",
101941          "swid": {
101942            "attachment": {}
101943          },
101944          "pedigree": {},
101945          "externalReferences": [
101946            {
101947              "url": "git://github.com/isaacs/node-glob.git",
101948              "type": "distribution"
101949            }
101950          ],
101951          "evidence": {},
101952          "signature": {
101953            "signature": {
101954              "publicKey": {}
101955            }
101956          },
101957          "modelCard": {
101958            "modelParameters": {
101959              "approach": {}
101960            },
101961            "quantitativeAnalysis": {
101962              "graphics": {}
101963            },
101964            "considerations": {}
101965          }
101966        },
101967        {
101968          "type": "library",
101969          "bom-ref": "pkg:npm/glob@8.0.3?package-id=f9282babaa70cabf",
101970          "supplier": {},
101971          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
101972          "name": "glob",
101973          "version": "8.0.3",
101974          "description": "a little globber",
101975          "licenses": [
101976            {
101977              "license": {
101978                "id": "ISC"
101979              }
101980            }
101981          ],
101982          "cpe": "cpe:2.3:a:isaacs:glob:8.0.3:*:*:*:*:*:*:*",
101983          "purl": "pkg:npm/glob@8.0.3",
101984          "swid": {
101985            "attachment": {}
101986          },
101987          "pedigree": {},
101988          "externalReferences": [
101989            {
101990              "url": "git://github.com/isaacs/node-glob.git",
101991              "type": "distribution"
101992            }
101993          ],
101994          "evidence": {},
101995          "signature": {
101996            "signature": {
101997              "publicKey": {}
101998            }
101999          },
102000          "modelCard": {
102001            "modelParameters": {
102002              "approach": {}
102003            },
102004            "quantitativeAnalysis": {
102005              "graphics": {}
102006            },
102007            "considerations": {}
102008          }
102009        },
102010        {
102011          "type": "library",
102012          "bom-ref": "pkg:npm/gopd@1.0.1?package-id=6a8f68198c946199",
102013          "supplier": {},
102014          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
102015          "name": "gopd",
102016          "version": "1.0.1",
102017          "description": "`Object.getOwnPropertyDescriptor`, but accounts for IE's broken implementation.",
102018          "licenses": [
102019            {
102020              "license": {
102021                "id": "MIT"
102022              }
102023            }
102024          ],
102025          "cpe": "cpe:2.3:a:ljharb:gopd:1.0.1:*:*:*:*:*:*:*",
102026          "purl": "pkg:npm/gopd@1.0.1",
102027          "swid": {
102028            "attachment": {}
102029          },
102030          "pedigree": {},
102031          "externalReferences": [
102032            {
102033              "url": "git+https://github.com/ljharb/gopd.git",
102034              "type": "distribution"
102035            },
102036            {
102037              "url": "https://github.com/ljharb/gopd#readme",
102038              "type": "website"
102039            }
102040          ],
102041          "evidence": {},
102042          "signature": {
102043            "signature": {
102044              "publicKey": {}
102045            }
102046          },
102047          "modelCard": {
102048            "modelParameters": {
102049              "approach": {}
102050            },
102051            "quantitativeAnalysis": {
102052              "graphics": {}
102053            },
102054            "considerations": {}
102055          }
102056        },
102057        {
102058          "type": "library",
102059          "bom-ref": "pkg:npm/graceful-fs@4.2.10?package-id=9591c6b5bd9602cc",
102060          "supplier": {},
102061          "name": "graceful-fs",
102062          "version": "4.2.10",
102063          "description": "A drop-in replacement for fs, making various improvements.",
102064          "licenses": [
102065            {
102066              "license": {
102067                "id": "ISC"
102068              }
102069            }
102070          ],
102071          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.10:*:*:*:*:*:*:*",
102072          "purl": "pkg:npm/graceful-fs@4.2.10",
102073          "swid": {
102074            "attachment": {}
102075          },
102076          "pedigree": {},
102077          "externalReferences": [
102078            {
102079              "url": "https://github.com/isaacs/node-graceful-fs",
102080              "type": "distribution"
102081            }
102082          ],
102083          "evidence": {},
102084          "signature": {
102085            "signature": {
102086              "publicKey": {}
102087            }
102088          },
102089          "modelCard": {
102090            "modelParameters": {
102091              "approach": {}
102092            },
102093            "quantitativeAnalysis": {
102094              "graphics": {}
102095            },
102096            "considerations": {}
102097          }
102098        },
102099        {
102100          "type": "library",
102101          "bom-ref": "pkg:npm/graceful-fs@4.2.11?package-id=6884b756b75e8e9c",
102102          "supplier": {},
102103          "name": "graceful-fs",
102104          "version": "4.2.11",
102105          "description": "A drop-in replacement for fs, making various improvements.",
102106          "licenses": [
102107            {
102108              "license": {
102109                "id": "ISC"
102110              }
102111            }
102112          ],
102113          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.11:*:*:*:*:*:*:*",
102114          "purl": "pkg:npm/graceful-fs@4.2.11",
102115          "swid": {
102116            "attachment": {}
102117          },
102118          "pedigree": {},
102119          "externalReferences": [
102120            {
102121              "url": "https://github.com/isaacs/node-graceful-fs",
102122              "type": "distribution"
102123            }
102124          ],
102125          "evidence": {},
102126          "signature": {
102127            "signature": {
102128              "publicKey": {}
102129            }
102130          },
102131          "modelCard": {
102132            "modelParameters": {
102133              "approach": {}
102134            },
102135            "quantitativeAnalysis": {
102136              "graphics": {}
102137            },
102138            "considerations": {}
102139          }
102140        },
102141        {
102142          "type": "library",
102143          "bom-ref": "pkg:npm/graceful-fs@4.2.11?package-id=bef9b71aa253a928",
102144          "supplier": {},
102145          "name": "graceful-fs",
102146          "version": "4.2.11",
102147          "description": "A drop-in replacement for fs, making various improvements.",
102148          "licenses": [
102149            {
102150              "license": {
102151                "id": "ISC"
102152              }
102153            }
102154          ],
102155          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.11:*:*:*:*:*:*:*",
102156          "purl": "pkg:npm/graceful-fs@4.2.11",
102157          "swid": {
102158            "attachment": {}
102159          },
102160          "pedigree": {},
102161          "externalReferences": [
102162            {
102163              "url": "https://github.com/isaacs/node-graceful-fs",
102164              "type": "distribution"
102165            }
102166          ],
102167          "evidence": {},
102168          "signature": {
102169            "signature": {
102170              "publicKey": {}
102171            }
102172          },
102173          "modelCard": {
102174            "modelParameters": {
102175              "approach": {}
102176            },
102177            "quantitativeAnalysis": {
102178              "graphics": {}
102179            },
102180            "considerations": {}
102181          }
102182        },
102183        {
102184          "type": "library",
102185          "bom-ref": "pkg:npm/has@1.0.3?package-id=57072cf8ae347274",
102186          "supplier": {},
102187          "author": "Thiago de Arruda \u003ctpadilha84@gmail.com\u003e",
102188          "name": "has",
102189          "version": "1.0.3",
102190          "description": "Object.prototype.hasOwnProperty.call shortcut",
102191          "licenses": [
102192            {
102193              "license": {
102194                "id": "MIT"
102195              }
102196            }
102197          ],
102198          "cpe": "cpe:2.3:a:tarruda:has:1.0.3:*:*:*:*:*:*:*",
102199          "purl": "pkg:npm/has@1.0.3",
102200          "swid": {
102201            "attachment": {}
102202          },
102203          "pedigree": {},
102204          "externalReferences": [
102205            {
102206              "url": "git://github.com/tarruda/has.git",
102207              "type": "distribution"
102208            },
102209            {
102210              "url": "https://github.com/tarruda/has",
102211              "type": "website"
102212            }
102213          ],
102214          "evidence": {},
102215          "signature": {
102216            "signature": {
102217              "publicKey": {}
102218            }
102219          },
102220          "modelCard": {
102221            "modelParameters": {
102222              "approach": {}
102223            },
102224            "quantitativeAnalysis": {
102225              "graphics": {}
102226            },
102227            "considerations": {}
102228          }
102229        },
102230        {
102231          "type": "library",
102232          "bom-ref": "pkg:npm/has@1.0.3?package-id=63cdb16663093af0",
102233          "supplier": {},
102234          "author": "Thiago de Arruda \u003ctpadilha84@gmail.com\u003e",
102235          "name": "has",
102236          "version": "1.0.3",
102237          "description": "Object.prototype.hasOwnProperty.call shortcut",
102238          "licenses": [
102239            {
102240              "license": {
102241                "id": "MIT"
102242              }
102243            }
102244          ],
102245          "cpe": "cpe:2.3:a:tarruda:has:1.0.3:*:*:*:*:*:*:*",
102246          "purl": "pkg:npm/has@1.0.3",
102247          "swid": {
102248            "attachment": {}
102249          },
102250          "pedigree": {},
102251          "externalReferences": [
102252            {
102253              "url": "git://github.com/tarruda/has.git",
102254              "type": "distribution"
102255            },
102256            {
102257              "url": "https://github.com/tarruda/has",
102258              "type": "website"
102259            }
102260          ],
102261          "evidence": {},
102262          "signature": {
102263            "signature": {
102264              "publicKey": {}
102265            }
102266          },
102267          "modelCard": {
102268            "modelParameters": {
102269              "approach": {}
102270            },
102271            "quantitativeAnalysis": {
102272              "graphics": {}
102273            },
102274            "considerations": {}
102275          }
102276        },
102277        {
102278          "type": "library",
102279          "bom-ref": "pkg:npm/has-flag@4.0.0?package-id=1ac717b55f99f4f2",
102280          "supplier": {},
102281          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
102282          "name": "has-flag",
102283          "version": "4.0.0",
102284          "description": "Check if argv has a specific flag",
102285          "licenses": [
102286            {
102287              "license": {
102288                "id": "MIT"
102289              }
102290            }
102291          ],
102292          "cpe": "cpe:2.3:a:has-flag:has-flag:4.0.0:*:*:*:*:*:*:*",
102293          "purl": "pkg:npm/has-flag@4.0.0",
102294          "swid": {
102295            "attachment": {}
102296          },
102297          "pedigree": {},
102298          "externalReferences": [
102299            {
102300              "url": "sindresorhus/has-flag",
102301              "type": "distribution"
102302            }
102303          ],
102304          "evidence": {},
102305          "signature": {
102306            "signature": {
102307              "publicKey": {}
102308            }
102309          },
102310          "modelCard": {
102311            "modelParameters": {
102312              "approach": {}
102313            },
102314            "quantitativeAnalysis": {
102315              "graphics": {}
102316            },
102317            "considerations": {}
102318          }
102319        },
102320        {
102321          "type": "library",
102322          "bom-ref": "pkg:npm/has-flag@4.0.0?package-id=1fd68902b403ef41",
102323          "supplier": {},
102324          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
102325          "name": "has-flag",
102326          "version": "4.0.0",
102327          "description": "Check if argv has a specific flag",
102328          "licenses": [
102329            {
102330              "license": {
102331                "id": "MIT"
102332              }
102333            }
102334          ],
102335          "cpe": "cpe:2.3:a:has-flag:has-flag:4.0.0:*:*:*:*:*:*:*",
102336          "purl": "pkg:npm/has-flag@4.0.0",
102337          "swid": {
102338            "attachment": {}
102339          },
102340          "pedigree": {},
102341          "externalReferences": [
102342            {
102343              "url": "sindresorhus/has-flag",
102344              "type": "distribution"
102345            }
102346          ],
102347          "evidence": {},
102348          "signature": {
102349            "signature": {
102350              "publicKey": {}
102351            }
102352          },
102353          "modelCard": {
102354            "modelParameters": {
102355              "approach": {}
102356            },
102357            "quantitativeAnalysis": {
102358              "graphics": {}
102359            },
102360            "considerations": {}
102361          }
102362        },
102363        {
102364          "type": "library",
102365          "bom-ref": "pkg:npm/has-symbols@1.0.3?package-id=89a634f5c4a5077e",
102366          "supplier": {},
102367          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
102368          "name": "has-symbols",
102369          "version": "1.0.3",
102370          "description": "Determine if the JS environment has Symbol support. Supports spec, or shams.",
102371          "licenses": [
102372            {
102373              "license": {
102374                "id": "MIT"
102375              }
102376            }
102377          ],
102378          "cpe": "cpe:2.3:a:has-symbols:has-symbols:1.0.3:*:*:*:*:*:*:*",
102379          "purl": "pkg:npm/has-symbols@1.0.3",
102380          "swid": {
102381            "attachment": {}
102382          },
102383          "pedigree": {},
102384          "externalReferences": [
102385            {
102386              "url": "git://github.com/inspect-js/has-symbols.git",
102387              "type": "distribution"
102388            },
102389            {
102390              "url": "https://github.com/ljharb/has-symbols#readme",
102391              "type": "website"
102392            }
102393          ],
102394          "evidence": {},
102395          "signature": {
102396            "signature": {
102397              "publicKey": {}
102398            }
102399          },
102400          "modelCard": {
102401            "modelParameters": {
102402              "approach": {}
102403            },
102404            "quantitativeAnalysis": {
102405              "graphics": {}
102406            },
102407            "considerations": {}
102408          }
102409        },
102410        {
102411          "type": "library",
102412          "bom-ref": "pkg:npm/has-tostringtag@1.0.0?package-id=fac89d8a93be8f61",
102413          "supplier": {},
102414          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
102415          "name": "has-tostringtag",
102416          "version": "1.0.0",
102417          "description": "Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.",
102418          "licenses": [
102419            {
102420              "license": {
102421                "id": "MIT"
102422              }
102423            }
102424          ],
102425          "cpe": "cpe:2.3:a:has-tostringtag:has-tostringtag:1.0.0:*:*:*:*:*:*:*",
102426          "purl": "pkg:npm/has-tostringtag@1.0.0",
102427          "swid": {
102428            "attachment": {}
102429          },
102430          "pedigree": {},
102431          "externalReferences": [
102432            {
102433              "url": "git+https://github.com/inspect-js/has-tostringtag.git",
102434              "type": "distribution"
102435            },
102436            {
102437              "url": "https://github.com/inspect-js/has-tostringtag#readme",
102438              "type": "website"
102439            }
102440          ],
102441          "evidence": {},
102442          "signature": {
102443            "signature": {
102444              "publicKey": {}
102445            }
102446          },
102447          "modelCard": {
102448            "modelParameters": {
102449              "approach": {}
102450            },
102451            "quantitativeAnalysis": {
102452              "graphics": {}
102453            },
102454            "considerations": {}
102455          }
102456        },
102457        {
102458          "type": "library",
102459          "bom-ref": "pkg:npm/has-unicode@2.0.1?package-id=28dbbd6e7951181f",
102460          "supplier": {},
102461          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
102462          "name": "has-unicode",
102463          "version": "2.0.1",
102464          "description": "Try to guess if your terminal supports unicode",
102465          "licenses": [
102466            {
102467              "license": {
102468                "id": "ISC"
102469              }
102470            }
102471          ],
102472          "cpe": "cpe:2.3:a:has-unicode:has-unicode:2.0.1:*:*:*:*:*:*:*",
102473          "purl": "pkg:npm/has-unicode@2.0.1",
102474          "swid": {
102475            "attachment": {}
102476          },
102477          "pedigree": {},
102478          "externalReferences": [
102479            {
102480              "url": "https://github.com/iarna/has-unicode",
102481              "type": "distribution"
102482            },
102483            {
102484              "url": "https://github.com/iarna/has-unicode",
102485              "type": "website"
102486            }
102487          ],
102488          "evidence": {},
102489          "signature": {
102490            "signature": {
102491              "publicKey": {}
102492            }
102493          },
102494          "modelCard": {
102495            "modelParameters": {
102496              "approach": {}
102497            },
102498            "quantitativeAnalysis": {
102499              "graphics": {}
102500            },
102501            "considerations": {}
102502          }
102503        },
102504        {
102505          "type": "library",
102506          "bom-ref": "pkg:npm/hash-base@3.1.0?package-id=2368971ed9141685",
102507          "supplier": {},
102508          "author": "Kirill Fomichev \u003cfanatid@ya.ru\u003e (https://github.com/fanatid)",
102509          "name": "hash-base",
102510          "version": "3.1.0",
102511          "description": "abstract base class for hash-streams",
102512          "licenses": [
102513            {
102514              "license": {
102515                "id": "MIT"
102516              }
102517            }
102518          ],
102519          "cpe": "cpe:2.3:a:crypto-browserify:hash-base:3.1.0:*:*:*:*:*:*:*",
102520          "purl": "pkg:npm/hash-base@3.1.0",
102521          "swid": {
102522            "attachment": {}
102523          },
102524          "pedigree": {},
102525          "externalReferences": [
102526            {
102527              "url": "https://github.com/crypto-browserify/hash-base.git",
102528              "type": "distribution"
102529            },
102530            {
102531              "url": "https://github.com/crypto-browserify/hash-base",
102532              "type": "website"
102533            }
102534          ],
102535          "evidence": {},
102536          "signature": {
102537            "signature": {
102538              "publicKey": {}
102539            }
102540          },
102541          "modelCard": {
102542            "modelParameters": {
102543              "approach": {}
102544            },
102545            "quantitativeAnalysis": {
102546              "graphics": {}
102547            },
102548            "considerations": {}
102549          }
102550        },
102551        {
102552          "type": "library",
102553          "bom-ref": "pkg:npm/hash.js@1.1.7?package-id=51265ac9ee812bcd",
102554          "supplier": {},
102555          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
102556          "name": "hash.js",
102557          "version": "1.1.7",
102558          "description": "Various hash functions that could be run by both browser and node",
102559          "licenses": [
102560            {
102561              "license": {
102562                "id": "MIT"
102563              }
102564            }
102565          ],
102566          "cpe": "cpe:2.3:a:hash.js:hash.js:1.1.7:*:*:*:*:*:*:*",
102567          "purl": "pkg:npm/hash.js@1.1.7",
102568          "swid": {
102569            "attachment": {}
102570          },
102571          "pedigree": {},
102572          "externalReferences": [
102573            {
102574              "url": "git@github.com:indutny/hash.js",
102575              "type": "distribution"
102576            },
102577            {
102578              "url": "https://github.com/indutny/hash.js",
102579              "type": "website"
102580            }
102581          ],
102582          "evidence": {},
102583          "signature": {
102584            "signature": {
102585              "publicKey": {}
102586            }
102587          },
102588          "modelCard": {
102589            "modelParameters": {
102590              "approach": {}
102591            },
102592            "quantitativeAnalysis": {
102593              "graphics": {}
102594            },
102595            "considerations": {}
102596          }
102597        },
102598        {
102599          "type": "library",
102600          "bom-ref": "pkg:npm/hmac-drbg@1.0.1?package-id=c47be7a2219b59a8",
102601          "supplier": {},
102602          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
102603          "name": "hmac-drbg",
102604          "version": "1.0.1",
102605          "description": "Deterministic random bit generator (hmac)",
102606          "licenses": [
102607            {
102608              "license": {
102609                "id": "MIT"
102610              }
102611            }
102612          ],
102613          "cpe": "cpe:2.3:a:hmac-drbg:hmac-drbg:1.0.1:*:*:*:*:*:*:*",
102614          "purl": "pkg:npm/hmac-drbg@1.0.1",
102615          "swid": {
102616            "attachment": {}
102617          },
102618          "pedigree": {},
102619          "externalReferences": [
102620            {
102621              "url": "git+ssh://git@github.com/indutny/hmac-drbg.git",
102622              "type": "distribution"
102623            },
102624            {
102625              "url": "https://github.com/indutny/hmac-drbg#readme",
102626              "type": "website"
102627            }
102628          ],
102629          "evidence": {},
102630          "signature": {
102631            "signature": {
102632              "publicKey": {}
102633            }
102634          },
102635          "modelCard": {
102636            "modelParameters": {
102637              "approach": {}
102638            },
102639            "quantitativeAnalysis": {
102640              "graphics": {}
102641            },
102642            "considerations": {}
102643          }
102644        },
102645        {
102646          "type": "library",
102647          "bom-ref": "pkg:npm/hosted-git-info@5.2.1?package-id=daac03af08cd11f6",
102648          "supplier": {},
102649          "author": "GitHub Inc.",
102650          "name": "hosted-git-info",
102651          "version": "5.2.1",
102652          "description": "Provides metadata and conversions from repository urls for GitHub, Bitbucket and GitLab",
102653          "licenses": [
102654            {
102655              "license": {
102656                "id": "ISC"
102657              }
102658            }
102659          ],
102660          "cpe": "cpe:2.3:a:hosted-git-info:hosted-git-info:5.2.1:*:*:*:*:*:*:*",
102661          "purl": "pkg:npm/hosted-git-info@5.2.1",
102662          "swid": {
102663            "attachment": {}
102664          },
102665          "pedigree": {},
102666          "externalReferences": [
102667            {
102668              "url": "https://github.com/npm/hosted-git-info.git",
102669              "type": "distribution"
102670            },
102671            {
102672              "url": "https://github.com/npm/hosted-git-info",
102673              "type": "website"
102674            }
102675          ],
102676          "evidence": {},
102677          "signature": {
102678            "signature": {
102679              "publicKey": {}
102680            }
102681          },
102682          "modelCard": {
102683            "modelParameters": {
102684              "approach": {}
102685            },
102686            "quantitativeAnalysis": {
102687              "graphics": {}
102688            },
102689            "considerations": {}
102690          }
102691        },
102692        {
102693          "type": "library",
102694          "bom-ref": "pkg:npm/http-cache-semantics@4.1.1?package-id=916aa3ebe914a835",
102695          "supplier": {},
102696          "author": "Kornel Lesiński \u003ckornel@geekhood.net\u003e (https://kornel.ski/)",
102697          "name": "http-cache-semantics",
102698          "version": "4.1.1",
102699          "description": "Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies",
102700          "licenses": [
102701            {
102702              "license": {
102703                "id": "BSD-2-Clause"
102704              }
102705            }
102706          ],
102707          "cpe": "cpe:2.3:a:http-cache-semantics:http-cache-semantics:4.1.1:*:*:*:*:*:*:*",
102708          "purl": "pkg:npm/http-cache-semantics@4.1.1",
102709          "swid": {
102710            "attachment": {}
102711          },
102712          "pedigree": {},
102713          "externalReferences": [
102714            {
102715              "url": "https://github.com/kornelski/http-cache-semantics.git",
102716              "type": "distribution"
102717            }
102718          ],
102719          "evidence": {},
102720          "signature": {
102721            "signature": {
102722              "publicKey": {}
102723            }
102724          },
102725          "modelCard": {
102726            "modelParameters": {
102727              "approach": {}
102728            },
102729            "quantitativeAnalysis": {
102730              "graphics": {}
102731            },
102732            "considerations": {}
102733          }
102734        },
102735        {
102736          "type": "library",
102737          "bom-ref": "pkg:npm/http-errors@1.6.3?package-id=d1068a65d773e5c4",
102738          "supplier": {},
102739          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
102740          "name": "http-errors",
102741          "version": "1.6.3",
102742          "description": "Create HTTP error objects",
102743          "licenses": [
102744            {
102745              "license": {
102746                "id": "MIT"
102747              }
102748            }
102749          ],
102750          "cpe": "cpe:2.3:a:http-errors:http-errors:1.6.3:*:*:*:*:*:*:*",
102751          "purl": "pkg:npm/http-errors@1.6.3",
102752          "swid": {
102753            "attachment": {}
102754          },
102755          "pedigree": {},
102756          "externalReferences": [
102757            {
102758              "url": "jshttp/http-errors",
102759              "type": "distribution"
102760            }
102761          ],
102762          "evidence": {},
102763          "signature": {
102764            "signature": {
102765              "publicKey": {}
102766            }
102767          },
102768          "modelCard": {
102769            "modelParameters": {
102770              "approach": {}
102771            },
102772            "quantitativeAnalysis": {
102773              "graphics": {}
102774            },
102775            "considerations": {}
102776          }
102777        },
102778        {
102779          "type": "library",
102780          "bom-ref": "pkg:npm/http-proxy-agent@5.0.0?package-id=af3d467415b1e643",
102781          "supplier": {},
102782          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
102783          "name": "http-proxy-agent",
102784          "version": "5.0.0",
102785          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTP",
102786          "licenses": [
102787            {
102788              "license": {
102789                "id": "MIT"
102790              }
102791            }
102792          ],
102793          "cpe": "cpe:2.3:a:http-proxy-agent:http-proxy-agent:5.0.0:*:*:*:*:*:*:*",
102794          "purl": "pkg:npm/http-proxy-agent@5.0.0",
102795          "swid": {
102796            "attachment": {}
102797          },
102798          "pedigree": {},
102799          "externalReferences": [
102800            {
102801              "url": "git://github.com/TooTallNate/node-http-proxy-agent.git",
102802              "type": "distribution"
102803            }
102804          ],
102805          "evidence": {},
102806          "signature": {
102807            "signature": {
102808              "publicKey": {}
102809            }
102810          },
102811          "modelCard": {
102812            "modelParameters": {
102813              "approach": {}
102814            },
102815            "quantitativeAnalysis": {
102816              "graphics": {}
102817            },
102818            "considerations": {}
102819          }
102820        },
102821        {
102822          "type": "library",
102823          "bom-ref": "pkg:npm/https-proxy-agent@5.0.1?package-id=b2694aac4dc305de",
102824          "supplier": {},
102825          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
102826          "name": "https-proxy-agent",
102827          "version": "5.0.1",
102828          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
102829          "licenses": [
102830            {
102831              "license": {
102832                "id": "MIT"
102833              }
102834            }
102835          ],
102836          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:5.0.1:*:*:*:*:*:*:*",
102837          "purl": "pkg:npm/https-proxy-agent@5.0.1",
102838          "swid": {
102839            "attachment": {}
102840          },
102841          "pedigree": {},
102842          "externalReferences": [
102843            {
102844              "url": "git://github.com/TooTallNate/node-https-proxy-agent.git",
102845              "type": "distribution"
102846            }
102847          ],
102848          "evidence": {},
102849          "signature": {
102850            "signature": {
102851              "publicKey": {}
102852            }
102853          },
102854          "modelCard": {
102855            "modelParameters": {
102856              "approach": {}
102857            },
102858            "quantitativeAnalysis": {
102859              "graphics": {}
102860            },
102861            "considerations": {}
102862          }
102863        },
102864        {
102865          "type": "library",
102866          "bom-ref": "pkg:npm/humanize-ms@1.2.1?package-id=d773c44dd2f9a86d",
102867          "supplier": {},
102868          "author": "dead-horse \u003cdead_horse@qq.com\u003e (http://deadhorse.me)",
102869          "name": "humanize-ms",
102870          "version": "1.2.1",
102871          "description": "transform humanize time to ms",
102872          "licenses": [
102873            {
102874              "license": {
102875                "id": "MIT"
102876              }
102877            }
102878          ],
102879          "cpe": "cpe:2.3:a:node-modules:humanize-ms:1.2.1:*:*:*:*:*:*:*",
102880          "purl": "pkg:npm/humanize-ms@1.2.1",
102881          "swid": {
102882            "attachment": {}
102883          },
102884          "pedigree": {},
102885          "externalReferences": [
102886            {
102887              "url": "https://github.com/node-modules/humanize-ms",
102888              "type": "distribution"
102889            }
102890          ],
102891          "evidence": {},
102892          "signature": {
102893            "signature": {
102894              "publicKey": {}
102895            }
102896          },
102897          "modelCard": {
102898            "modelParameters": {
102899              "approach": {}
102900            },
102901            "quantitativeAnalysis": {
102902              "graphics": {}
102903            },
102904            "considerations": {}
102905          }
102906        },
102907        {
102908          "type": "library",
102909          "bom-ref": "pkg:npm/iconv-lite@0.4.23?package-id=5056a816beaa3c8b",
102910          "supplier": {},
102911          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
102912          "name": "iconv-lite",
102913          "version": "0.4.23",
102914          "description": "Convert character encodings in pure javascript.",
102915          "licenses": [
102916            {
102917              "license": {
102918                "id": "MIT"
102919              }
102920            }
102921          ],
102922          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.4.23:*:*:*:*:*:*:*",
102923          "purl": "pkg:npm/iconv-lite@0.4.23",
102924          "swid": {
102925            "attachment": {}
102926          },
102927          "pedigree": {},
102928          "externalReferences": [
102929            {
102930              "url": "git://github.com/ashtuchkin/iconv-lite.git",
102931              "type": "distribution"
102932            },
102933            {
102934              "url": "https://github.com/ashtuchkin/iconv-lite",
102935              "type": "website"
102936            }
102937          ],
102938          "evidence": {},
102939          "signature": {
102940            "signature": {
102941              "publicKey": {}
102942            }
102943          },
102944          "modelCard": {
102945            "modelParameters": {
102946              "approach": {}
102947            },
102948            "quantitativeAnalysis": {
102949              "graphics": {}
102950            },
102951            "considerations": {}
102952          }
102953        },
102954        {
102955          "type": "library",
102956          "bom-ref": "pkg:npm/iconv-lite@0.6.3?package-id=fc4965fa5a86a9c9",
102957          "supplier": {},
102958          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
102959          "name": "iconv-lite",
102960          "version": "0.6.3",
102961          "description": "Convert character encodings in pure javascript.",
102962          "licenses": [
102963            {
102964              "license": {
102965                "id": "MIT"
102966              }
102967            }
102968          ],
102969          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.6.3:*:*:*:*:*:*:*",
102970          "purl": "pkg:npm/iconv-lite@0.6.3",
102971          "swid": {
102972            "attachment": {}
102973          },
102974          "pedigree": {},
102975          "externalReferences": [
102976            {
102977              "url": "git://github.com/ashtuchkin/iconv-lite.git",
102978              "type": "distribution"
102979            },
102980            {
102981              "url": "https://github.com/ashtuchkin/iconv-lite",
102982              "type": "website"
102983            }
102984          ],
102985          "evidence": {},
102986          "signature": {
102987            "signature": {
102988              "publicKey": {}
102989            }
102990          },
102991          "modelCard": {
102992            "modelParameters": {
102993              "approach": {}
102994            },
102995            "quantitativeAnalysis": {
102996              "graphics": {}
102997            },
102998            "considerations": {}
102999          }
103000        },
103001        {
103002          "type": "library",
103003          "bom-ref": "pkg:npm/ignore-walk@5.0.1?package-id=39d6166153eb8a8",
103004          "supplier": {},
103005          "author": "GitHub Inc.",
103006          "name": "ignore-walk",
103007          "version": "5.0.1",
103008          "description": "Nested/recursive `.gitignore`/`.npmignore` parsing and filtering.",
103009          "licenses": [
103010            {
103011              "license": {
103012                "id": "ISC"
103013              }
103014            }
103015          ],
103016          "cpe": "cpe:2.3:a:ignore-walk:ignore-walk:5.0.1:*:*:*:*:*:*:*",
103017          "purl": "pkg:npm/ignore-walk@5.0.1",
103018          "swid": {
103019            "attachment": {}
103020          },
103021          "pedigree": {},
103022          "externalReferences": [
103023            {
103024              "url": "https://github.com/npm/ignore-walk.git",
103025              "type": "distribution"
103026            }
103027          ],
103028          "evidence": {},
103029          "signature": {
103030            "signature": {
103031              "publicKey": {}
103032            }
103033          },
103034          "modelCard": {
103035            "modelParameters": {
103036              "approach": {}
103037            },
103038            "quantitativeAnalysis": {
103039              "graphics": {}
103040            },
103041            "considerations": {}
103042          }
103043        },
103044        {
103045          "type": "library",
103046          "bom-ref": "pkg:npm/imurmurhash@0.1.4?package-id=6444b4b295dc6bb1",
103047          "supplier": {},
103048          "author": "Jens Taylor \u003cjensyt@gmail.com\u003e (https://github.com/homebrewing)",
103049          "name": "imurmurhash",
103050          "version": "0.1.4",
103051          "description": "An incremental implementation of MurmurHash3",
103052          "licenses": [
103053            {
103054              "license": {
103055                "id": "MIT"
103056              }
103057            }
103058          ],
103059          "cpe": "cpe:2.3:a:imurmurhash:imurmurhash:0.1.4:*:*:*:*:*:*:*",
103060          "purl": "pkg:npm/imurmurhash@0.1.4",
103061          "swid": {
103062            "attachment": {}
103063          },
103064          "pedigree": {},
103065          "externalReferences": [
103066            {
103067              "url": "https://github.com/jensyt/imurmurhash-js",
103068              "type": "distribution"
103069            },
103070            {
103071              "url": "https://github.com/jensyt/imurmurhash-js",
103072              "type": "website"
103073            }
103074          ],
103075          "evidence": {},
103076          "signature": {
103077            "signature": {
103078              "publicKey": {}
103079            }
103080          },
103081          "modelCard": {
103082            "modelParameters": {
103083              "approach": {}
103084            },
103085            "quantitativeAnalysis": {
103086              "graphics": {}
103087            },
103088            "considerations": {}
103089          }
103090        },
103091        {
103092          "type": "library",
103093          "bom-ref": "pkg:npm/indent-string@4.0.0?package-id=9c9aada4281114e7",
103094          "supplier": {},
103095          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
103096          "name": "indent-string",
103097          "version": "4.0.0",
103098          "description": "Indent each line in a string",
103099          "licenses": [
103100            {
103101              "license": {
103102                "id": "MIT"
103103              }
103104            }
103105          ],
103106          "cpe": "cpe:2.3:a:indent-string:indent-string:4.0.0:*:*:*:*:*:*:*",
103107          "purl": "pkg:npm/indent-string@4.0.0",
103108          "swid": {
103109            "attachment": {}
103110          },
103111          "pedigree": {},
103112          "externalReferences": [
103113            {
103114              "url": "sindresorhus/indent-string",
103115              "type": "distribution"
103116            }
103117          ],
103118          "evidence": {},
103119          "signature": {
103120            "signature": {
103121              "publicKey": {}
103122            }
103123          },
103124          "modelCard": {
103125            "modelParameters": {
103126              "approach": {}
103127            },
103128            "quantitativeAnalysis": {
103129              "graphics": {}
103130            },
103131            "considerations": {}
103132          }
103133        },
103134        {
103135          "type": "library",
103136          "bom-ref": "pkg:npm/infer-owner@1.0.4?package-id=70041214f8f231ae",
103137          "supplier": {},
103138          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
103139          "name": "infer-owner",
103140          "version": "1.0.4",
103141          "description": "Infer the owner of a path based on the owner of its nearest existing parent",
103142          "licenses": [
103143            {
103144              "license": {
103145                "id": "ISC"
103146              }
103147            }
103148          ],
103149          "cpe": "cpe:2.3:a:infer-owner:infer-owner:1.0.4:*:*:*:*:*:*:*",
103150          "purl": "pkg:npm/infer-owner@1.0.4",
103151          "swid": {
103152            "attachment": {}
103153          },
103154          "pedigree": {},
103155          "externalReferences": [
103156            {
103157              "url": "https://github.com/npm/infer-owner",
103158              "type": "distribution"
103159            }
103160          ],
103161          "evidence": {},
103162          "signature": {
103163            "signature": {
103164              "publicKey": {}
103165            }
103166          },
103167          "modelCard": {
103168            "modelParameters": {
103169              "approach": {}
103170            },
103171            "quantitativeAnalysis": {
103172              "graphics": {}
103173            },
103174            "considerations": {}
103175          }
103176        },
103177        {
103178          "type": "library",
103179          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=59c3c8a2d2437082",
103180          "supplier": {},
103181          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
103182          "name": "inflight",
103183          "version": "1.0.6",
103184          "description": "Add callbacks to requests in flight to avoid async duplication",
103185          "licenses": [
103186            {
103187              "license": {
103188                "id": "ISC"
103189              }
103190            }
103191          ],
103192          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
103193          "purl": "pkg:npm/inflight@1.0.6",
103194          "swid": {
103195            "attachment": {}
103196          },
103197          "pedigree": {},
103198          "externalReferences": [
103199            {
103200              "url": "https://github.com/npm/inflight.git",
103201              "type": "distribution"
103202            },
103203            {
103204              "url": "https://github.com/isaacs/inflight",
103205              "type": "website"
103206            }
103207          ],
103208          "evidence": {},
103209          "signature": {
103210            "signature": {
103211              "publicKey": {}
103212            }
103213          },
103214          "modelCard": {
103215            "modelParameters": {
103216              "approach": {}
103217            },
103218            "quantitativeAnalysis": {
103219              "graphics": {}
103220            },
103221            "considerations": {}
103222          }
103223        },
103224        {
103225          "type": "library",
103226          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=23270e8079f4dffc",
103227          "supplier": {},
103228          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
103229          "name": "inflight",
103230          "version": "1.0.6",
103231          "description": "Add callbacks to requests in flight to avoid async duplication",
103232          "licenses": [
103233            {
103234              "license": {
103235                "id": "ISC"
103236              }
103237            }
103238          ],
103239          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
103240          "purl": "pkg:npm/inflight@1.0.6",
103241          "swid": {
103242            "attachment": {}
103243          },
103244          "pedigree": {},
103245          "externalReferences": [
103246            {
103247              "url": "https://github.com/npm/inflight.git",
103248              "type": "distribution"
103249            },
103250            {
103251              "url": "https://github.com/isaacs/inflight",
103252              "type": "website"
103253            }
103254          ],
103255          "evidence": {},
103256          "signature": {
103257            "signature": {
103258              "publicKey": {}
103259            }
103260          },
103261          "modelCard": {
103262            "modelParameters": {
103263              "approach": {}
103264            },
103265            "quantitativeAnalysis": {
103266              "graphics": {}
103267            },
103268            "considerations": {}
103269          }
103270        },
103271        {
103272          "type": "library",
103273          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=f9bd5cf95258dad4",
103274          "supplier": {},
103275          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
103276          "name": "inflight",
103277          "version": "1.0.6",
103278          "description": "Add callbacks to requests in flight to avoid async duplication",
103279          "licenses": [
103280            {
103281              "license": {
103282                "id": "ISC"
103283              }
103284            }
103285          ],
103286          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
103287          "purl": "pkg:npm/inflight@1.0.6",
103288          "swid": {
103289            "attachment": {}
103290          },
103291          "pedigree": {},
103292          "externalReferences": [
103293            {
103294              "url": "https://github.com/npm/inflight.git",
103295              "type": "distribution"
103296            },
103297            {
103298              "url": "https://github.com/isaacs/inflight",
103299              "type": "website"
103300            }
103301          ],
103302          "evidence": {},
103303          "signature": {
103304            "signature": {
103305              "publicKey": {}
103306            }
103307          },
103308          "modelCard": {
103309            "modelParameters": {
103310              "approach": {}
103311            },
103312            "quantitativeAnalysis": {
103313              "graphics": {}
103314            },
103315            "considerations": {}
103316          }
103317        },
103318        {
103319          "type": "library",
103320          "bom-ref": "pkg:npm/inherits@2.0.3?package-id=1bb44148e405c144",
103321          "supplier": {},
103322          "name": "inherits",
103323          "version": "2.0.3",
103324          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
103325          "licenses": [
103326            {
103327              "license": {
103328                "id": "ISC"
103329              }
103330            }
103331          ],
103332          "cpe": "cpe:2.3:a:inherits:inherits:2.0.3:*:*:*:*:*:*:*",
103333          "purl": "pkg:npm/inherits@2.0.3",
103334          "swid": {
103335            "attachment": {}
103336          },
103337          "pedigree": {},
103338          "externalReferences": [
103339            {
103340              "url": "git://github.com/isaacs/inherits",
103341              "type": "distribution"
103342            }
103343          ],
103344          "evidence": {},
103345          "signature": {
103346            "signature": {
103347              "publicKey": {}
103348            }
103349          },
103350          "modelCard": {
103351            "modelParameters": {
103352              "approach": {}
103353            },
103354            "quantitativeAnalysis": {
103355              "graphics": {}
103356            },
103357            "considerations": {}
103358          }
103359        },
103360        {
103361          "type": "library",
103362          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=2aa76eeeb4a32e94",
103363          "supplier": {},
103364          "name": "inherits",
103365          "version": "2.0.4",
103366          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
103367          "licenses": [
103368            {
103369              "license": {
103370                "id": "ISC"
103371              }
103372            }
103373          ],
103374          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
103375          "purl": "pkg:npm/inherits@2.0.4",
103376          "swid": {
103377            "attachment": {}
103378          },
103379          "pedigree": {},
103380          "externalReferences": [
103381            {
103382              "url": "git://github.com/isaacs/inherits",
103383              "type": "distribution"
103384            }
103385          ],
103386          "evidence": {},
103387          "signature": {
103388            "signature": {
103389              "publicKey": {}
103390            }
103391          },
103392          "modelCard": {
103393            "modelParameters": {
103394              "approach": {}
103395            },
103396            "quantitativeAnalysis": {
103397              "graphics": {}
103398            },
103399            "considerations": {}
103400          }
103401        },
103402        {
103403          "type": "library",
103404          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=87186ec358a4a58b",
103405          "supplier": {},
103406          "name": "inherits",
103407          "version": "2.0.4",
103408          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
103409          "licenses": [
103410            {
103411              "license": {
103412                "id": "ISC"
103413              }
103414            }
103415          ],
103416          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
103417          "purl": "pkg:npm/inherits@2.0.4",
103418          "swid": {
103419            "attachment": {}
103420          },
103421          "pedigree": {},
103422          "externalReferences": [
103423            {
103424              "url": "git://github.com/isaacs/inherits",
103425              "type": "distribution"
103426            }
103427          ],
103428          "evidence": {},
103429          "signature": {
103430            "signature": {
103431              "publicKey": {}
103432            }
103433          },
103434          "modelCard": {
103435            "modelParameters": {
103436              "approach": {}
103437            },
103438            "quantitativeAnalysis": {
103439              "graphics": {}
103440            },
103441            "considerations": {}
103442          }
103443        },
103444        {
103445          "type": "library",
103446          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=d9fff24231d5d55b",
103447          "supplier": {},
103448          "name": "inherits",
103449          "version": "2.0.4",
103450          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
103451          "licenses": [
103452            {
103453              "license": {
103454                "id": "ISC"
103455              }
103456            }
103457          ],
103458          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
103459          "purl": "pkg:npm/inherits@2.0.4",
103460          "swid": {
103461            "attachment": {}
103462          },
103463          "pedigree": {},
103464          "externalReferences": [
103465            {
103466              "url": "git://github.com/isaacs/inherits",
103467              "type": "distribution"
103468            }
103469          ],
103470          "evidence": {},
103471          "signature": {
103472            "signature": {
103473              "publicKey": {}
103474            }
103475          },
103476          "modelCard": {
103477            "modelParameters": {
103478              "approach": {}
103479            },
103480            "quantitativeAnalysis": {
103481              "graphics": {}
103482            },
103483            "considerations": {}
103484          }
103485        },
103486        {
103487          "type": "library",
103488          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=cc4e01efa051a048",
103489          "supplier": {},
103490          "name": "inherits",
103491          "version": "2.0.4",
103492          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
103493          "licenses": [
103494            {
103495              "license": {
103496                "id": "ISC"
103497              }
103498            }
103499          ],
103500          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
103501          "purl": "pkg:npm/inherits@2.0.4",
103502          "swid": {
103503            "attachment": {}
103504          },
103505          "pedigree": {},
103506          "externalReferences": [
103507            {
103508              "url": "git://github.com/isaacs/inherits",
103509              "type": "distribution"
103510            }
103511          ],
103512          "evidence": {},
103513          "signature": {
103514            "signature": {
103515              "publicKey": {}
103516            }
103517          },
103518          "modelCard": {
103519            "modelParameters": {
103520              "approach": {}
103521            },
103522            "quantitativeAnalysis": {
103523              "graphics": {}
103524            },
103525            "considerations": {}
103526          }
103527        },
103528        {
103529          "type": "library",
103530          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=4329afdb061a9b57",
103531          "supplier": {},
103532          "name": "inherits",
103533          "version": "2.0.4",
103534          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
103535          "licenses": [
103536            {
103537              "license": {
103538                "id": "ISC"
103539              }
103540            }
103541          ],
103542          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
103543          "purl": "pkg:npm/inherits@2.0.4",
103544          "swid": {
103545            "attachment": {}
103546          },
103547          "pedigree": {},
103548          "externalReferences": [
103549            {
103550              "url": "git://github.com/isaacs/inherits",
103551              "type": "distribution"
103552            }
103553          ],
103554          "evidence": {},
103555          "signature": {
103556            "signature": {
103557              "publicKey": {}
103558            }
103559          },
103560          "modelCard": {
103561            "modelParameters": {
103562              "approach": {}
103563            },
103564            "quantitativeAnalysis": {
103565              "graphics": {}
103566            },
103567            "considerations": {}
103568          }
103569        },
103570        {
103571          "type": "library",
103572          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=f84cce1a2468e7",
103573          "supplier": {},
103574          "name": "inherits",
103575          "version": "2.0.4",
103576          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
103577          "licenses": [
103578            {
103579              "license": {
103580                "id": "ISC"
103581              }
103582            }
103583          ],
103584          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
103585          "purl": "pkg:npm/inherits@2.0.4",
103586          "swid": {
103587            "attachment": {}
103588          },
103589          "pedigree": {},
103590          "externalReferences": [
103591            {
103592              "url": "git://github.com/isaacs/inherits",
103593              "type": "distribution"
103594            }
103595          ],
103596          "evidence": {},
103597          "signature": {
103598            "signature": {
103599              "publicKey": {}
103600            }
103601          },
103602          "modelCard": {
103603            "modelParameters": {
103604              "approach": {}
103605            },
103606            "quantitativeAnalysis": {
103607              "graphics": {}
103608            },
103609            "considerations": {}
103610          }
103611        },
103612        {
103613          "type": "library",
103614          "bom-ref": "pkg:npm/ini@3.0.1?package-id=143d409d5161792",
103615          "supplier": {},
103616          "author": "GitHub Inc.",
103617          "name": "ini",
103618          "version": "3.0.1",
103619          "description": "An ini encoder/decoder for node",
103620          "licenses": [
103621            {
103622              "license": {
103623                "id": "ISC"
103624              }
103625            }
103626          ],
103627          "cpe": "cpe:2.3:a:ini:ini:3.0.1:*:*:*:*:*:*:*",
103628          "purl": "pkg:npm/ini@3.0.1",
103629          "swid": {
103630            "attachment": {}
103631          },
103632          "pedigree": {},
103633          "externalReferences": [
103634            {
103635              "url": "https://github.com/npm/ini.git",
103636              "type": "distribution"
103637            }
103638          ],
103639          "evidence": {},
103640          "signature": {
103641            "signature": {
103642              "publicKey": {}
103643            }
103644          },
103645          "modelCard": {
103646            "modelParameters": {
103647              "approach": {}
103648            },
103649            "quantitativeAnalysis": {
103650              "graphics": {}
103651            },
103652            "considerations": {}
103653          }
103654        },
103655        {
103656          "type": "library",
103657          "bom-ref": "pkg:npm/init-package-json@3.0.2?package-id=6836db1e46d935b6",
103658          "supplier": {},
103659          "author": "GitHub Inc.",
103660          "name": "init-package-json",
103661          "version": "3.0.2",
103662          "description": "A node module to get your node module started",
103663          "licenses": [
103664            {
103665              "license": {
103666                "id": "ISC"
103667              }
103668            }
103669          ],
103670          "cpe": "cpe:2.3:a:init-package-json:init-package-json:3.0.2:*:*:*:*:*:*:*",
103671          "purl": "pkg:npm/init-package-json@3.0.2",
103672          "swid": {
103673            "attachment": {}
103674          },
103675          "pedigree": {},
103676          "externalReferences": [
103677            {
103678              "url": "https://github.com/npm/init-package-json.git",
103679              "type": "distribution"
103680            }
103681          ],
103682          "evidence": {},
103683          "signature": {
103684            "signature": {
103685              "publicKey": {}
103686            }
103687          },
103688          "modelCard": {
103689            "modelParameters": {
103690              "approach": {}
103691            },
103692            "quantitativeAnalysis": {
103693              "graphics": {}
103694            },
103695            "considerations": {}
103696          }
103697        },
103698        {
103699          "type": "library",
103700          "bom-ref": "pkg:npm/interpret@1.4.0?package-id=38cd7b71098275d",
103701          "supplier": {},
103702          "author": "Gulp Team \u003cteam@gulpjs.com\u003e (http://gulpjs.com/)",
103703          "name": "interpret",
103704          "version": "1.4.0",
103705          "description": "A dictionary of file extensions and associated module loaders.",
103706          "licenses": [
103707            {
103708              "license": {
103709                "id": "MIT"
103710              }
103711            }
103712          ],
103713          "cpe": "cpe:2.3:a:interpret:interpret:1.4.0:*:*:*:*:*:*:*",
103714          "purl": "pkg:npm/interpret@1.4.0",
103715          "swid": {
103716            "attachment": {}
103717          },
103718          "pedigree": {},
103719          "externalReferences": [
103720            {
103721              "url": "gulpjs/interpret",
103722              "type": "distribution"
103723            }
103724          ],
103725          "evidence": {},
103726          "signature": {
103727            "signature": {
103728              "publicKey": {}
103729            }
103730          },
103731          "modelCard": {
103732            "modelParameters": {
103733              "approach": {}
103734            },
103735            "quantitativeAnalysis": {
103736              "graphics": {}
103737            },
103738            "considerations": {}
103739          }
103740        },
103741        {
103742          "type": "library",
103743          "bom-ref": "pkg:npm/ip@2.0.0?package-id=218d1c05ea387b3c",
103744          "supplier": {},
103745          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
103746          "name": "ip",
103747          "version": "2.0.0",
103748          "licenses": [
103749            {
103750              "license": {
103751                "id": "MIT"
103752              }
103753            }
103754          ],
103755          "cpe": "cpe:2.3:a:indutny:ip:2.0.0:*:*:*:*:*:*:*",
103756          "purl": "pkg:npm/ip@2.0.0",
103757          "swid": {
103758            "attachment": {}
103759          },
103760          "pedigree": {},
103761          "externalReferences": [
103762            {
103763              "url": "http://github.com/indutny/node-ip.git",
103764              "type": "distribution"
103765            },
103766            {
103767              "url": "https://github.com/indutny/node-ip",
103768              "type": "website"
103769            }
103770          ],
103771          "evidence": {},
103772          "signature": {
103773            "signature": {
103774              "publicKey": {}
103775            }
103776          },
103777          "modelCard": {
103778            "modelParameters": {
103779              "approach": {}
103780            },
103781            "quantitativeAnalysis": {
103782              "graphics": {}
103783            },
103784            "considerations": {}
103785          }
103786        },
103787        {
103788          "type": "library",
103789          "bom-ref": "pkg:npm/ip-regex@4.3.0?package-id=ce63365b733beafc",
103790          "supplier": {},
103791          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
103792          "name": "ip-regex",
103793          "version": "4.3.0",
103794          "description": "Regular expression for matching IP addresses (IPv4 \u0026 IPv6)",
103795          "licenses": [
103796            {
103797              "license": {
103798                "id": "MIT"
103799              }
103800            }
103801          ],
103802          "cpe": "cpe:2.3:a:ip-regex:ip-regex:4.3.0:*:*:*:*:*:*:*",
103803          "purl": "pkg:npm/ip-regex@4.3.0",
103804          "swid": {
103805            "attachment": {}
103806          },
103807          "pedigree": {},
103808          "externalReferences": [
103809            {
103810              "url": "sindresorhus/ip-regex",
103811              "type": "distribution"
103812            }
103813          ],
103814          "evidence": {},
103815          "signature": {
103816            "signature": {
103817              "publicKey": {}
103818            }
103819          },
103820          "modelCard": {
103821            "modelParameters": {
103822              "approach": {}
103823            },
103824            "quantitativeAnalysis": {
103825              "graphics": {}
103826            },
103827            "considerations": {}
103828          }
103829        },
103830        {
103831          "type": "library",
103832          "bom-ref": "pkg:npm/ipaddr.js@1.9.1?package-id=a456707d5d548a77",
103833          "supplier": {},
103834          "author": "whitequark \u003cwhitequark@whitequark.org\u003e",
103835          "name": "ipaddr.js",
103836          "version": "1.9.1",
103837          "description": "A library for manipulating IPv4 and IPv6 addresses in JavaScript.",
103838          "licenses": [
103839            {
103840              "license": {
103841                "id": "MIT"
103842              }
103843            }
103844          ],
103845          "cpe": "cpe:2.3:a:whitequark:ipaddr.js:1.9.1:*:*:*:*:*:*:*",
103846          "purl": "pkg:npm/ipaddr.js@1.9.1",
103847          "swid": {
103848            "attachment": {}
103849          },
103850          "pedigree": {},
103851          "externalReferences": [
103852            {
103853              "url": "git://github.com/whitequark/ipaddr.js",
103854              "type": "distribution"
103855            }
103856          ],
103857          "evidence": {},
103858          "signature": {
103859            "signature": {
103860              "publicKey": {}
103861            }
103862          },
103863          "modelCard": {
103864            "modelParameters": {
103865              "approach": {}
103866            },
103867            "quantitativeAnalysis": {
103868              "graphics": {}
103869            },
103870            "considerations": {}
103871          }
103872        },
103873        {
103874          "type": "library",
103875          "bom-ref": "pkg:npm/ipaddr.js@2.0.1?package-id=53fa4f36e1904499",
103876          "supplier": {},
103877          "author": "whitequark \u003cwhitequark@whitequark.org\u003e",
103878          "name": "ipaddr.js",
103879          "version": "2.0.1",
103880          "description": "A library for manipulating IPv4 and IPv6 addresses in JavaScript.",
103881          "licenses": [
103882            {
103883              "license": {
103884                "id": "MIT"
103885              }
103886            }
103887          ],
103888          "cpe": "cpe:2.3:a:whitequark:ipaddr.js:2.0.1:*:*:*:*:*:*:*",
103889          "purl": "pkg:npm/ipaddr.js@2.0.1",
103890          "swid": {
103891            "attachment": {}
103892          },
103893          "pedigree": {},
103894          "externalReferences": [
103895            {
103896              "url": "git://github.com/whitequark/ipaddr.js",
103897              "type": "distribution"
103898            }
103899          ],
103900          "evidence": {},
103901          "signature": {
103902            "signature": {
103903              "publicKey": {}
103904            }
103905          },
103906          "modelCard": {
103907            "modelParameters": {
103908              "approach": {}
103909            },
103910            "quantitativeAnalysis": {
103911              "graphics": {}
103912            },
103913            "considerations": {}
103914          }
103915        },
103916        {
103917          "type": "library",
103918          "bom-ref": "pkg:npm/is-arguments@1.1.1?package-id=ad7c195ab0c46bce",
103919          "supplier": {},
103920          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
103921          "name": "is-arguments",
103922          "version": "1.1.1",
103923          "description": "Is this an arguments object? It's a harder question than you think.",
103924          "licenses": [
103925            {
103926              "license": {
103927                "id": "MIT"
103928              }
103929            }
103930          ],
103931          "cpe": "cpe:2.3:a:is-arguments:is-arguments:1.1.1:*:*:*:*:*:*:*",
103932          "purl": "pkg:npm/is-arguments@1.1.1",
103933          "swid": {
103934            "attachment": {}
103935          },
103936          "pedigree": {},
103937          "externalReferences": [
103938            {
103939              "url": "git://github.com/inspect-js/is-arguments.git",
103940              "type": "distribution"
103941            },
103942            {
103943              "url": "https://github.com/inspect-js/is-arguments",
103944              "type": "website"
103945            }
103946          ],
103947          "evidence": {},
103948          "signature": {
103949            "signature": {
103950              "publicKey": {}
103951            }
103952          },
103953          "modelCard": {
103954            "modelParameters": {
103955              "approach": {}
103956            },
103957            "quantitativeAnalysis": {
103958              "graphics": {}
103959            },
103960            "considerations": {}
103961          }
103962        },
103963        {
103964          "type": "library",
103965          "bom-ref": "pkg:npm/is-callable@1.2.7?package-id=c4c51f6896fbf70",
103966          "supplier": {},
103967          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
103968          "name": "is-callable",
103969          "version": "1.2.7",
103970          "description": "Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.",
103971          "licenses": [
103972            {
103973              "license": {
103974                "id": "MIT"
103975              }
103976            }
103977          ],
103978          "cpe": "cpe:2.3:a:is-callable:is-callable:1.2.7:*:*:*:*:*:*:*",
103979          "purl": "pkg:npm/is-callable@1.2.7",
103980          "swid": {
103981            "attachment": {}
103982          },
103983          "pedigree": {},
103984          "externalReferences": [
103985            {
103986              "url": "git://github.com/inspect-js/is-callable.git",
103987              "type": "distribution"
103988            }
103989          ],
103990          "evidence": {},
103991          "signature": {
103992            "signature": {
103993              "publicKey": {}
103994            }
103995          },
103996          "modelCard": {
103997            "modelParameters": {
103998              "approach": {}
103999            },
104000            "quantitativeAnalysis": {
104001              "graphics": {}
104002            },
104003            "considerations": {}
104004          }
104005        },
104006        {
104007          "type": "library",
104008          "bom-ref": "pkg:npm/is-ci@2.0.0?package-id=d53a8a10260fddcf",
104009          "supplier": {},
104010          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
104011          "name": "is-ci",
104012          "version": "2.0.0",
104013          "description": "Detect if the current environment is a CI server",
104014          "licenses": [
104015            {
104016              "license": {
104017                "id": "MIT"
104018              }
104019            }
104020          ],
104021          "cpe": "cpe:2.3:a:watson:is-ci:2.0.0:*:*:*:*:*:*:*",
104022          "purl": "pkg:npm/is-ci@2.0.0",
104023          "swid": {
104024            "attachment": {}
104025          },
104026          "pedigree": {},
104027          "externalReferences": [
104028            {
104029              "url": "https://github.com/watson/is-ci.git",
104030              "type": "distribution"
104031            },
104032            {
104033              "url": "https://github.com/watson/is-ci",
104034              "type": "website"
104035            }
104036          ],
104037          "evidence": {},
104038          "signature": {
104039            "signature": {
104040              "publicKey": {}
104041            }
104042          },
104043          "modelCard": {
104044            "modelParameters": {
104045              "approach": {}
104046            },
104047            "quantitativeAnalysis": {
104048              "graphics": {}
104049            },
104050            "considerations": {}
104051          }
104052        },
104053        {
104054          "type": "library",
104055          "bom-ref": "pkg:npm/is-cidr@4.0.2?package-id=b7267695f8ce1238",
104056          "supplier": {},
104057          "author": "silverwind \u003cme@silverwind.io\u003e",
104058          "name": "is-cidr",
104059          "version": "4.0.2",
104060          "description": "Check if a string is an IP address in CIDR notation",
104061          "licenses": [
104062            {
104063              "license": {
104064                "id": "BSD-2-Clause"
104065              }
104066            }
104067          ],
104068          "cpe": "cpe:2.3:a:is-cidr:is-cidr:4.0.2:*:*:*:*:*:*:*",
104069          "purl": "pkg:npm/is-cidr@4.0.2",
104070          "swid": {
104071            "attachment": {}
104072          },
104073          "pedigree": {},
104074          "externalReferences": [
104075            {
104076              "url": "silverwind/is-cidr",
104077              "type": "distribution"
104078            }
104079          ],
104080          "evidence": {},
104081          "signature": {
104082            "signature": {
104083              "publicKey": {}
104084            }
104085          },
104086          "modelCard": {
104087            "modelParameters": {
104088              "approach": {}
104089            },
104090            "quantitativeAnalysis": {
104091              "graphics": {}
104092            },
104093            "considerations": {}
104094          }
104095        },
104096        {
104097          "type": "library",
104098          "bom-ref": "pkg:npm/is-core-module@2.10.0?package-id=22642820ec847015",
104099          "supplier": {},
104100          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
104101          "name": "is-core-module",
104102          "version": "2.10.0",
104103          "description": "Is this specifier a node.js core module?",
104104          "licenses": [
104105            {
104106              "license": {
104107                "id": "MIT"
104108              }
104109            }
104110          ],
104111          "cpe": "cpe:2.3:a:is-core-module:is-core-module:2.10.0:*:*:*:*:*:*:*",
104112          "purl": "pkg:npm/is-core-module@2.10.0",
104113          "swid": {
104114            "attachment": {}
104115          },
104116          "pedigree": {},
104117          "externalReferences": [
104118            {
104119              "url": "git+https://github.com/inspect-js/is-core-module.git",
104120              "type": "distribution"
104121            },
104122            {
104123              "url": "https://github.com/inspect-js/is-core-module",
104124              "type": "website"
104125            }
104126          ],
104127          "evidence": {},
104128          "signature": {
104129            "signature": {
104130              "publicKey": {}
104131            }
104132          },
104133          "modelCard": {
104134            "modelParameters": {
104135              "approach": {}
104136            },
104137            "quantitativeAnalysis": {
104138              "graphics": {}
104139            },
104140            "considerations": {}
104141          }
104142        },
104143        {
104144          "type": "library",
104145          "bom-ref": "pkg:npm/is-core-module@2.12.0?package-id=29c3156cba89f8b",
104146          "supplier": {},
104147          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
104148          "name": "is-core-module",
104149          "version": "2.12.0",
104150          "description": "Is this specifier a node.js core module?",
104151          "licenses": [
104152            {
104153              "license": {
104154                "id": "MIT"
104155              }
104156            }
104157          ],
104158          "cpe": "cpe:2.3:a:is-core-module:is-core-module:2.12.0:*:*:*:*:*:*:*",
104159          "purl": "pkg:npm/is-core-module@2.12.0",
104160          "swid": {
104161            "attachment": {}
104162          },
104163          "pedigree": {},
104164          "externalReferences": [
104165            {
104166              "url": "git+https://github.com/inspect-js/is-core-module.git",
104167              "type": "distribution"
104168            },
104169            {
104170              "url": "https://github.com/inspect-js/is-core-module",
104171              "type": "website"
104172            }
104173          ],
104174          "evidence": {},
104175          "signature": {
104176            "signature": {
104177              "publicKey": {}
104178            }
104179          },
104180          "modelCard": {
104181            "modelParameters": {
104182              "approach": {}
104183            },
104184            "quantitativeAnalysis": {
104185              "graphics": {}
104186            },
104187            "considerations": {}
104188          }
104189        },
104190        {
104191          "type": "library",
104192          "bom-ref": "pkg:npm/is-docker@2.2.1?package-id=209eb400a1af69e7",
104193          "supplier": {},
104194          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
104195          "name": "is-docker",
104196          "version": "2.2.1",
104197          "description": "Check if the process is running inside a Docker container",
104198          "licenses": [
104199            {
104200              "license": {
104201                "id": "MIT"
104202              }
104203            }
104204          ],
104205          "cpe": "cpe:2.3:a:is-docker:is-docker:2.2.1:*:*:*:*:*:*:*",
104206          "purl": "pkg:npm/is-docker@2.2.1",
104207          "swid": {
104208            "attachment": {}
104209          },
104210          "pedigree": {},
104211          "externalReferences": [
104212            {
104213              "url": "sindresorhus/is-docker",
104214              "type": "distribution"
104215            }
104216          ],
104217          "evidence": {},
104218          "signature": {
104219            "signature": {
104220              "publicKey": {}
104221            }
104222          },
104223          "modelCard": {
104224            "modelParameters": {
104225              "approach": {}
104226            },
104227            "quantitativeAnalysis": {
104228              "graphics": {}
104229            },
104230            "considerations": {}
104231          }
104232        },
104233        {
104234          "type": "library",
104235          "bom-ref": "pkg:npm/is-fullwidth-code-point@3.0.0?package-id=f89f6ce8e80b50d",
104236          "supplier": {},
104237          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
104238          "name": "is-fullwidth-code-point",
104239          "version": "3.0.0",
104240          "description": "Check if the character represented by a given Unicode code point is fullwidth",
104241          "licenses": [
104242            {
104243              "license": {
104244                "id": "MIT"
104245              }
104246            }
104247          ],
104248          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:3.0.0:*:*:*:*:*:*:*",
104249          "purl": "pkg:npm/is-fullwidth-code-point@3.0.0",
104250          "swid": {
104251            "attachment": {}
104252          },
104253          "pedigree": {},
104254          "externalReferences": [
104255            {
104256              "url": "sindresorhus/is-fullwidth-code-point",
104257              "type": "distribution"
104258            }
104259          ],
104260          "evidence": {},
104261          "signature": {
104262            "signature": {
104263              "publicKey": {}
104264            }
104265          },
104266          "modelCard": {
104267            "modelParameters": {
104268              "approach": {}
104269            },
104270            "quantitativeAnalysis": {
104271              "graphics": {}
104272            },
104273            "considerations": {}
104274          }
104275        },
104276        {
104277          "type": "library",
104278          "bom-ref": "pkg:npm/is-generator-function@1.0.10?package-id=bed7e4245a0f50fa",
104279          "supplier": {},
104280          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
104281          "name": "is-generator-function",
104282          "version": "1.0.10",
104283          "description": "Determine if a function is a native generator function.",
104284          "licenses": [
104285            {
104286              "license": {
104287                "id": "MIT"
104288              }
104289            }
104290          ],
104291          "cpe": "cpe:2.3:a:is-generator-function:is-generator-function:1.0.10:*:*:*:*:*:*:*",
104292          "purl": "pkg:npm/is-generator-function@1.0.10",
104293          "swid": {
104294            "attachment": {}
104295          },
104296          "pedigree": {},
104297          "externalReferences": [
104298            {
104299              "url": "git://github.com/inspect-js/is-generator-function.git",
104300              "type": "distribution"
104301            }
104302          ],
104303          "evidence": {},
104304          "signature": {
104305            "signature": {
104306              "publicKey": {}
104307            }
104308          },
104309          "modelCard": {
104310            "modelParameters": {
104311              "approach": {}
104312            },
104313            "quantitativeAnalysis": {
104314              "graphics": {}
104315            },
104316            "considerations": {}
104317          }
104318        },
104319        {
104320          "type": "library",
104321          "bom-ref": "pkg:npm/is-lambda@1.0.1?package-id=841af64487227951",
104322          "supplier": {},
104323          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
104324          "name": "is-lambda",
104325          "version": "1.0.1",
104326          "description": "Detect if your code is running on an AWS Lambda server",
104327          "licenses": [
104328            {
104329              "license": {
104330                "id": "MIT"
104331              }
104332            }
104333          ],
104334          "cpe": "cpe:2.3:a:is-lambda:is-lambda:1.0.1:*:*:*:*:*:*:*",
104335          "purl": "pkg:npm/is-lambda@1.0.1",
104336          "swid": {
104337            "attachment": {}
104338          },
104339          "pedigree": {},
104340          "externalReferences": [
104341            {
104342              "url": "https://github.com/watson/is-lambda.git",
104343              "type": "distribution"
104344            },
104345            {
104346              "url": "https://github.com/watson/is-lambda",
104347              "type": "website"
104348            }
104349          ],
104350          "evidence": {},
104351          "signature": {
104352            "signature": {
104353              "publicKey": {}
104354            }
104355          },
104356          "modelCard": {
104357            "modelParameters": {
104358              "approach": {}
104359            },
104360            "quantitativeAnalysis": {
104361              "graphics": {}
104362            },
104363            "considerations": {}
104364          }
104365        },
104366        {
104367          "type": "library",
104368          "bom-ref": "pkg:npm/is-number@7.0.0?package-id=b9bf8faca6627c38",
104369          "supplier": {},
104370          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
104371          "name": "is-number",
104372          "version": "7.0.0",
104373          "description": "Returns true if a number or string value is a finite number. Useful for regex matches, parsing, user input, etc.",
104374          "licenses": [
104375            {
104376              "license": {
104377                "id": "MIT"
104378              }
104379            }
104380          ],
104381          "cpe": "cpe:2.3:a:jonschlinkert:is-number:7.0.0:*:*:*:*:*:*:*",
104382          "purl": "pkg:npm/is-number@7.0.0",
104383          "swid": {
104384            "attachment": {}
104385          },
104386          "pedigree": {},
104387          "externalReferences": [
104388            {
104389              "url": "jonschlinkert/is-number",
104390              "type": "distribution"
104391            },
104392            {
104393              "url": "https://github.com/jonschlinkert/is-number",
104394              "type": "website"
104395            }
104396          ],
104397          "evidence": {},
104398          "signature": {
104399            "signature": {
104400              "publicKey": {}
104401            }
104402          },
104403          "modelCard": {
104404            "modelParameters": {
104405              "approach": {}
104406            },
104407            "quantitativeAnalysis": {
104408              "graphics": {}
104409            },
104410            "considerations": {}
104411          }
104412        },
104413        {
104414          "type": "library",
104415          "bom-ref": "pkg:npm/is-typed-array@1.1.10?package-id=d331ef17d0a77286",
104416          "supplier": {},
104417          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
104418          "name": "is-typed-array",
104419          "version": "1.1.10",
104420          "description": "Is this value a JS Typed Array? This module works cross-realm/iframe, does not depend on `instanceof` or mutable properties, and despite ES6 Symbol.toStringTag.",
104421          "licenses": [
104422            {
104423              "license": {
104424                "id": "MIT"
104425              }
104426            }
104427          ],
104428          "cpe": "cpe:2.3:a:is-typed-array:is-typed-array:1.1.10:*:*:*:*:*:*:*",
104429          "purl": "pkg:npm/is-typed-array@1.1.10",
104430          "swid": {
104431            "attachment": {}
104432          },
104433          "pedigree": {},
104434          "externalReferences": [
104435            {
104436              "url": "git://github.com/inspect-js/is-typed-array.git",
104437              "type": "distribution"
104438            }
104439          ],
104440          "evidence": {},
104441          "signature": {
104442            "signature": {
104443              "publicKey": {}
104444            }
104445          },
104446          "modelCard": {
104447            "modelParameters": {
104448              "approach": {}
104449            },
104450            "quantitativeAnalysis": {
104451              "graphics": {}
104452            },
104453            "considerations": {}
104454          }
104455        },
104456        {
104457          "type": "library",
104458          "bom-ref": "pkg:npm/is-wsl@2.2.0?package-id=d1f1ff9c32e5f112",
104459          "supplier": {},
104460          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
104461          "name": "is-wsl",
104462          "version": "2.2.0",
104463          "description": "Check if the process is running inside Windows Subsystem for Linux (Bash on Windows)",
104464          "licenses": [
104465            {
104466              "license": {
104467                "id": "MIT"
104468              }
104469            }
104470          ],
104471          "cpe": "cpe:2.3:a:is-wsl:is-wsl:2.2.0:*:*:*:*:*:*:*",
104472          "purl": "pkg:npm/is-wsl@2.2.0",
104473          "swid": {
104474            "attachment": {}
104475          },
104476          "pedigree": {},
104477          "externalReferences": [
104478            {
104479              "url": "sindresorhus/is-wsl",
104480              "type": "distribution"
104481            }
104482          ],
104483          "evidence": {},
104484          "signature": {
104485            "signature": {
104486              "publicKey": {}
104487            }
104488          },
104489          "modelCard": {
104490            "modelParameters": {
104491              "approach": {}
104492            },
104493            "quantitativeAnalysis": {
104494              "graphics": {}
104495            },
104496            "considerations": {}
104497          }
104498        },
104499        {
104500          "type": "library",
104501          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=cac2857ecac9cad9",
104502          "supplier": {},
104503          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
104504          "name": "isexe",
104505          "version": "2.0.0",
104506          "description": "Minimal module to check if a file is executable.",
104507          "licenses": [
104508            {
104509              "license": {
104510                "id": "ISC"
104511              }
104512            }
104513          ],
104514          "cpe": "cpe:2.3:a:isaacs:isexe:2.0.0:*:*:*:*:*:*:*",
104515          "purl": "pkg:npm/isexe@2.0.0",
104516          "swid": {
104517            "attachment": {}
104518          },
104519          "pedigree": {},
104520          "externalReferences": [
104521            {
104522              "url": "git+https://github.com/isaacs/isexe.git",
104523              "type": "distribution"
104524            },
104525            {
104526              "url": "https://github.com/isaacs/isexe#readme",
104527              "type": "website"
104528            }
104529          ],
104530          "evidence": {},
104531          "signature": {
104532            "signature": {
104533              "publicKey": {}
104534            }
104535          },
104536          "modelCard": {
104537            "modelParameters": {
104538              "approach": {}
104539            },
104540            "quantitativeAnalysis": {
104541              "graphics": {}
104542            },
104543            "considerations": {}
104544          }
104545        },
104546        {
104547          "type": "library",
104548          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=d6d80f55303e9359",
104549          "supplier": {},
104550          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
104551          "name": "isexe",
104552          "version": "2.0.0",
104553          "description": "Minimal module to check if a file is executable.",
104554          "licenses": [
104555            {
104556              "license": {
104557                "id": "ISC"
104558              }
104559            }
104560          ],
104561          "cpe": "cpe:2.3:a:isaacs:isexe:2.0.0:*:*:*:*:*:*:*",
104562          "purl": "pkg:npm/isexe@2.0.0",
104563          "swid": {
104564            "attachment": {}
104565          },
104566          "pedigree": {},
104567          "externalReferences": [
104568            {
104569              "url": "git+https://github.com/isaacs/isexe.git",
104570              "type": "distribution"
104571            },
104572            {
104573              "url": "https://github.com/isaacs/isexe#readme",
104574              "type": "website"
104575            }
104576          ],
104577          "evidence": {},
104578          "signature": {
104579            "signature": {
104580              "publicKey": {}
104581            }
104582          },
104583          "modelCard": {
104584            "modelParameters": {
104585              "approach": {}
104586            },
104587            "quantitativeAnalysis": {
104588              "graphics": {}
104589            },
104590            "considerations": {}
104591          }
104592        },
104593        {
104594          "type": "library",
104595          "bom-ref": "pkg:npm/json-parse-even-better-errors@2.3.1?package-id=abf07f33abe9247b",
104596          "supplier": {},
104597          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
104598          "name": "json-parse-even-better-errors",
104599          "version": "2.3.1",
104600          "description": "JSON.parse with context information on error",
104601          "licenses": [
104602            {
104603              "license": {
104604                "id": "MIT"
104605              }
104606            }
104607          ],
104608          "cpe": "cpe:2.3:a:json-parse-even-better-errors:json-parse-even-better-errors:2.3.1:*:*:*:*:*:*:*",
104609          "purl": "pkg:npm/json-parse-even-better-errors@2.3.1",
104610          "swid": {
104611            "attachment": {}
104612          },
104613          "pedigree": {},
104614          "externalReferences": [
104615            {
104616              "url": "https://github.com/npm/json-parse-even-better-errors",
104617              "type": "distribution"
104618            }
104619          ],
104620          "evidence": {},
104621          "signature": {
104622            "signature": {
104623              "publicKey": {}
104624            }
104625          },
104626          "modelCard": {
104627            "modelParameters": {
104628              "approach": {}
104629            },
104630            "quantitativeAnalysis": {
104631              "graphics": {}
104632            },
104633            "considerations": {}
104634          }
104635        },
104636        {
104637          "type": "library",
104638          "bom-ref": "pkg:npm/json-stream@1.0.0?package-id=1d1cbbfe09ed72b0",
104639          "supplier": {},
104640          "author": "Maciej Małecki \u003cme@mmalecki.com\u003e",
104641          "name": "json-stream",
104642          "version": "1.0.0",
104643          "description": "New line-delimeted JSON parser with a stream interface",
104644          "licenses": [
104645            {
104646              "license": {
104647                "id": "MIT"
104648              }
104649            }
104650          ],
104651          "cpe": "cpe:2.3:a:json-stream:json-stream:1.0.0:*:*:*:*:*:*:*",
104652          "purl": "pkg:npm/json-stream@1.0.0",
104653          "swid": {
104654            "attachment": {}
104655          },
104656          "pedigree": {},
104657          "externalReferences": [
104658            {
104659              "url": "https://github.com/mmalecki/json-stream.git",
104660              "type": "distribution"
104661            }
104662          ],
104663          "evidence": {},
104664          "signature": {
104665            "signature": {
104666              "publicKey": {}
104667            }
104668          },
104669          "modelCard": {
104670            "modelParameters": {
104671              "approach": {}
104672            },
104673            "quantitativeAnalysis": {
104674              "graphics": {}
104675            },
104676            "considerations": {}
104677          }
104678        },
104679        {
104680          "type": "library",
104681          "bom-ref": "pkg:npm/json-stringify-nice@1.1.4?package-id=e53e3b4efad53e7c",
104682          "supplier": {},
104683          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
104684          "name": "json-stringify-nice",
104685          "version": "1.1.4",
104686          "description": "Stringify an object sorting scalars before objects, and defaulting to 2-space indent",
104687          "licenses": [
104688            {
104689              "license": {
104690                "id": "ISC"
104691              }
104692            }
104693          ],
104694          "cpe": "cpe:2.3:a:json-stringify-nice:json-stringify-nice:1.1.4:*:*:*:*:*:*:*",
104695          "purl": "pkg:npm/json-stringify-nice@1.1.4",
104696          "swid": {
104697            "attachment": {}
104698          },
104699          "pedigree": {},
104700          "externalReferences": [
104701            {
104702              "url": "https://github.com/isaacs/json-stringify-nice",
104703              "type": "distribution"
104704            }
104705          ],
104706          "evidence": {},
104707          "signature": {
104708            "signature": {
104709              "publicKey": {}
104710            }
104711          },
104712          "modelCard": {
104713            "modelParameters": {
104714              "approach": {}
104715            },
104716            "quantitativeAnalysis": {
104717              "graphics": {}
104718            },
104719            "considerations": {}
104720          }
104721        },
104722        {
104723          "type": "library",
104724          "bom-ref": "pkg:npm/jsonfile@4.0.0?package-id=4cfeca6860892aa8",
104725          "supplier": {},
104726          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
104727          "name": "jsonfile",
104728          "version": "4.0.0",
104729          "description": "Easily read/write JSON files.",
104730          "licenses": [
104731            {
104732              "license": {
104733                "id": "MIT"
104734              }
104735            }
104736          ],
104737          "cpe": "cpe:2.3:a:jsonfile:jsonfile:4.0.0:*:*:*:*:*:*:*",
104738          "purl": "pkg:npm/jsonfile@4.0.0",
104739          "swid": {
104740            "attachment": {}
104741          },
104742          "pedigree": {},
104743          "externalReferences": [
104744            {
104745              "url": "git@github.com:jprichardson/node-jsonfile.git",
104746              "type": "distribution"
104747            }
104748          ],
104749          "evidence": {},
104750          "signature": {
104751            "signature": {
104752              "publicKey": {}
104753            }
104754          },
104755          "modelCard": {
104756            "modelParameters": {
104757              "approach": {}
104758            },
104759            "quantitativeAnalysis": {
104760              "graphics": {}
104761            },
104762            "considerations": {}
104763          }
104764        },
104765        {
104766          "type": "library",
104767          "bom-ref": "pkg:npm/jsonfile@6.1.0?package-id=614799bcf64038a",
104768          "supplier": {},
104769          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
104770          "name": "jsonfile",
104771          "version": "6.1.0",
104772          "description": "Easily read/write JSON files.",
104773          "licenses": [
104774            {
104775              "license": {
104776                "id": "MIT"
104777              }
104778            }
104779          ],
104780          "cpe": "cpe:2.3:a:jsonfile:jsonfile:6.1.0:*:*:*:*:*:*:*",
104781          "purl": "pkg:npm/jsonfile@6.1.0",
104782          "swid": {
104783            "attachment": {}
104784          },
104785          "pedigree": {},
104786          "externalReferences": [
104787            {
104788              "url": "git@github.com:jprichardson/node-jsonfile.git",
104789              "type": "distribution"
104790            }
104791          ],
104792          "evidence": {},
104793          "signature": {
104794            "signature": {
104795              "publicKey": {}
104796            }
104797          },
104798          "modelCard": {
104799            "modelParameters": {
104800              "approach": {}
104801            },
104802            "quantitativeAnalysis": {
104803              "graphics": {}
104804            },
104805            "considerations": {}
104806          }
104807        },
104808        {
104809          "type": "library",
104810          "bom-ref": "pkg:npm/jsonparse@1.3.1?package-id=4ac9c9dc14c89718",
104811          "supplier": {},
104812          "author": "Tim Caswell \u003ctim@creationix.com\u003e",
104813          "name": "jsonparse",
104814          "version": "1.3.1",
104815          "description": "This is a pure-js JSON streaming parser for node.js",
104816          "licenses": [
104817            {
104818              "license": {
104819                "id": "MIT"
104820              }
104821            }
104822          ],
104823          "cpe": "cpe:2.3:a:creationix:jsonparse:1.3.1:*:*:*:*:*:*:*",
104824          "purl": "pkg:npm/jsonparse@1.3.1",
104825          "swid": {
104826            "attachment": {}
104827          },
104828          "pedigree": {},
104829          "externalReferences": [
104830            {
104831              "url": "http://github.com/creationix/jsonparse.git",
104832              "type": "distribution"
104833            }
104834          ],
104835          "evidence": {},
104836          "signature": {
104837            "signature": {
104838              "publicKey": {}
104839            }
104840          },
104841          "modelCard": {
104842            "modelParameters": {
104843              "approach": {}
104844            },
104845            "quantitativeAnalysis": {
104846              "graphics": {}
104847            },
104848            "considerations": {}
104849          }
104850        },
104851        {
104852          "type": "library",
104853          "bom-ref": "pkg:npm/just-diff@5.1.1?package-id=ce66f628f594c549",
104854          "supplier": {},
104855          "author": "Angus Croll",
104856          "name": "just-diff",
104857          "version": "5.1.1",
104858          "description": "Return an object representing the diffs between two objects. Supports jsonPatch protocol",
104859          "licenses": [
104860            {
104861              "license": {
104862                "id": "MIT"
104863              }
104864            }
104865          ],
104866          "cpe": "cpe:2.3:a:just-diff:just-diff:5.1.1:*:*:*:*:*:*:*",
104867          "purl": "pkg:npm/just-diff@5.1.1",
104868          "swid": {
104869            "attachment": {}
104870          },
104871          "pedigree": {},
104872          "externalReferences": [
104873            {
104874              "url": "https://github.com/angus-c/just",
104875              "type": "distribution"
104876            }
104877          ],
104878          "evidence": {},
104879          "signature": {
104880            "signature": {
104881              "publicKey": {}
104882            }
104883          },
104884          "modelCard": {
104885            "modelParameters": {
104886              "approach": {}
104887            },
104888            "quantitativeAnalysis": {
104889              "graphics": {}
104890            },
104891            "considerations": {}
104892          }
104893        },
104894        {
104895          "type": "library",
104896          "bom-ref": "pkg:npm/just-diff-apply@5.4.1?package-id=11dfc45c877cf5ba",
104897          "supplier": {},
104898          "author": "Angus Croll",
104899          "name": "just-diff-apply",
104900          "version": "5.4.1",
104901          "description": "Apply a diff to an object. Optionally supports jsonPatch protocol",
104902          "licenses": [
104903            {
104904              "license": {
104905                "id": "MIT"
104906              }
104907            }
104908          ],
104909          "cpe": "cpe:2.3:a:just-diff-apply:just-diff-apply:5.4.1:*:*:*:*:*:*:*",
104910          "purl": "pkg:npm/just-diff-apply@5.4.1",
104911          "swid": {
104912            "attachment": {}
104913          },
104914          "pedigree": {},
104915          "externalReferences": [
104916            {
104917              "url": "https://github.com/angus-c/just",
104918              "type": "distribution"
104919            }
104920          ],
104921          "evidence": {},
104922          "signature": {
104923            "signature": {
104924              "publicKey": {}
104925            }
104926          },
104927          "modelCard": {
104928            "modelParameters": {
104929              "approach": {}
104930            },
104931            "quantitativeAnalysis": {
104932              "graphics": {}
104933            },
104934            "considerations": {}
104935          }
104936        },
104937        {
104938          "type": "library",
104939          "bom-ref": "pkg:npm/klaw-sync@6.0.0?package-id=5665374c65e3d05d",
104940          "supplier": {},
104941          "author": "Mani Maghsoudlou",
104942          "name": "klaw-sync",
104943          "version": "6.0.0",
104944          "description": "Recursive, synchronous, and fast file system walker",
104945          "licenses": [
104946            {
104947              "license": {
104948                "id": "MIT"
104949              }
104950            }
104951          ],
104952          "cpe": "cpe:2.3:a:klaw-sync:klaw-sync:6.0.0:*:*:*:*:*:*:*",
104953          "purl": "pkg:npm/klaw-sync@6.0.0",
104954          "swid": {
104955            "attachment": {}
104956          },
104957          "pedigree": {},
104958          "externalReferences": [
104959            {
104960              "url": "git+https://github.com/manidlou/node-klaw-sync.git",
104961              "type": "distribution"
104962            },
104963            {
104964              "url": "https://github.com/manidlou/node-klaw-sync#readme",
104965              "type": "website"
104966            }
104967          ],
104968          "evidence": {},
104969          "signature": {
104970            "signature": {
104971              "publicKey": {}
104972            }
104973          },
104974          "modelCard": {
104975            "modelParameters": {
104976              "approach": {}
104977            },
104978            "quantitativeAnalysis": {
104979              "graphics": {}
104980            },
104981            "considerations": {}
104982          }
104983        },
104984        {
104985          "type": "library",
104986          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5\u0026package-id=2abd3b45f6fa4702",
104987          "supplier": {},
104988          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
104989          "name": "libc-utils",
104990          "version": "0.7.2-r3",
104991          "description": "Meta package to pull in correct libc",
104992          "licenses": [
104993            {
104994              "license": {
104995                "id": "BSD-2-Clause"
104996              }
104997            },
104998            {
104999              "license": {
105000                "name": "AND"
105001              }
105002            },
105003            {
105004              "license": {
105005                "id": "BSD-3-Clause"
105006              }
105007            }
105008          ],
105009          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
105010          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5",
105011          "swid": {
105012            "attachment": {}
105013          },
105014          "pedigree": {},
105015          "externalReferences": [
105016            {
105017              "url": "https://alpinelinux.org",
105018              "type": "distribution"
105019            }
105020          ],
105021          "evidence": {},
105022          "signature": {
105023            "signature": {
105024              "publicKey": {}
105025            }
105026          },
105027          "modelCard": {
105028            "modelParameters": {
105029              "approach": {}
105030            },
105031            "quantitativeAnalysis": {
105032              "graphics": {}
105033            },
105034            "considerations": {}
105035          }
105036        },
105037        {
105038          "type": "library",
105039          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=13bc051822a24e8d",
105040          "supplier": {},
105041          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
105042          "name": "libcrypto1.1",
105043          "version": "1.1.1t-r2",
105044          "description": "Crypto library from openssl",
105045          "licenses": [
105046            {
105047              "license": {
105048                "id": "OpenSSL"
105049              }
105050            }
105051          ],
105052          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1t-r2:*:*:*:*:*:*:*",
105053          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
105054          "swid": {
105055            "attachment": {}
105056          },
105057          "pedigree": {},
105058          "externalReferences": [
105059            {
105060              "url": "https://www.openssl.org/",
105061              "type": "distribution"
105062            }
105063          ],
105064          "evidence": {},
105065          "signature": {
105066            "signature": {
105067              "publicKey": {}
105068            }
105069          },
105070          "modelCard": {
105071            "modelParameters": {
105072              "approach": {}
105073            },
105074            "quantitativeAnalysis": {
105075              "graphics": {}
105076            },
105077            "considerations": {}
105078          }
105079        },
105080        {
105081          "type": "library",
105082          "bom-ref": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=d2886381f1e7cdb2",
105083          "supplier": {},
105084          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
105085          "name": "libgcc",
105086          "version": "11.2.1_git20220219-r2",
105087          "description": "GNU C compiler runtime libraries",
105088          "licenses": [
105089            {
105090              "license": {
105091                "id": "GPL-2.0-or-later"
105092              }
105093            },
105094            {
105095              "license": {
105096                "id": "LGPL-2.1-or-later"
105097              }
105098            }
105099          ],
105100          "cpe": "cpe:2.3:a:libgcc:libgcc:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
105101          "purl": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
105102          "swid": {
105103            "attachment": {}
105104          },
105105          "pedigree": {},
105106          "externalReferences": [
105107            {
105108              "url": "https://gcc.gnu.org",
105109              "type": "distribution"
105110            }
105111          ],
105112          "evidence": {},
105113          "signature": {
105114            "signature": {
105115              "publicKey": {}
105116            }
105117          },
105118          "modelCard": {
105119            "modelParameters": {
105120              "approach": {}
105121            },
105122            "quantitativeAnalysis": {
105123              "graphics": {}
105124            },
105125            "considerations": {}
105126          }
105127        },
105128        {
105129          "type": "library",
105130          "bom-ref": "pkg:npm/libnpmaccess@6.0.4?package-id=f3410b3d946e1c4d",
105131          "supplier": {},
105132          "author": "GitHub Inc.",
105133          "name": "libnpmaccess",
105134          "version": "6.0.4",
105135          "description": "programmatic library for `npm access` commands",
105136          "licenses": [
105137            {
105138              "license": {
105139                "id": "ISC"
105140              }
105141            }
105142          ],
105143          "cpe": "cpe:2.3:a:libnpmaccess:libnpmaccess:6.0.4:*:*:*:*:*:*:*",
105144          "purl": "pkg:npm/libnpmaccess@6.0.4",
105145          "swid": {
105146            "attachment": {}
105147          },
105148          "pedigree": {},
105149          "externalReferences": [
105150            {
105151              "url": "https://github.com/npm/cli.git",
105152              "type": "distribution"
105153            },
105154            {
105155              "url": "https://npmjs.com/package/libnpmaccess",
105156              "type": "website"
105157            }
105158          ],
105159          "evidence": {},
105160          "signature": {
105161            "signature": {
105162              "publicKey": {}
105163            }
105164          },
105165          "modelCard": {
105166            "modelParameters": {
105167              "approach": {}
105168            },
105169            "quantitativeAnalysis": {
105170              "graphics": {}
105171            },
105172            "considerations": {}
105173          }
105174        },
105175        {
105176          "type": "library",
105177          "bom-ref": "pkg:npm/libnpmdiff@4.0.5?package-id=ce3262e2c08529ea",
105178          "supplier": {},
105179          "author": "GitHub Inc.",
105180          "name": "libnpmdiff",
105181          "version": "4.0.5",
105182          "description": "The registry diff",
105183          "licenses": [
105184            {
105185              "license": {
105186                "id": "ISC"
105187              }
105188            }
105189          ],
105190          "cpe": "cpe:2.3:a:libnpmdiff:libnpmdiff:4.0.5:*:*:*:*:*:*:*",
105191          "purl": "pkg:npm/libnpmdiff@4.0.5",
105192          "swid": {
105193            "attachment": {}
105194          },
105195          "pedigree": {},
105196          "externalReferences": [
105197            {
105198              "url": "https://github.com/npm/cli.git",
105199              "type": "distribution"
105200            }
105201          ],
105202          "evidence": {},
105203          "signature": {
105204            "signature": {
105205              "publicKey": {}
105206            }
105207          },
105208          "modelCard": {
105209            "modelParameters": {
105210              "approach": {}
105211            },
105212            "quantitativeAnalysis": {
105213              "graphics": {}
105214            },
105215            "considerations": {}
105216          }
105217        },
105218        {
105219          "type": "library",
105220          "bom-ref": "pkg:npm/libnpmexec@4.0.14?package-id=902cc2f16bb11ffc",
105221          "supplier": {},
105222          "author": "GitHub Inc.",
105223          "name": "libnpmexec",
105224          "version": "4.0.14",
105225          "description": "npm exec (npx) programmatic API",
105226          "licenses": [
105227            {
105228              "license": {
105229                "id": "ISC"
105230              }
105231            }
105232          ],
105233          "cpe": "cpe:2.3:a:libnpmexec:libnpmexec:4.0.14:*:*:*:*:*:*:*",
105234          "purl": "pkg:npm/libnpmexec@4.0.14",
105235          "swid": {
105236            "attachment": {}
105237          },
105238          "pedigree": {},
105239          "externalReferences": [
105240            {
105241              "url": "https://github.com/npm/cli.git",
105242              "type": "distribution"
105243            }
105244          ],
105245          "evidence": {},
105246          "signature": {
105247            "signature": {
105248              "publicKey": {}
105249            }
105250          },
105251          "modelCard": {
105252            "modelParameters": {
105253              "approach": {}
105254            },
105255            "quantitativeAnalysis": {
105256              "graphics": {}
105257            },
105258            "considerations": {}
105259          }
105260        },
105261        {
105262          "type": "library",
105263          "bom-ref": "pkg:npm/libnpmfund@3.0.5?package-id=201ebcb5d992fa75",
105264          "supplier": {},
105265          "author": "GitHub Inc.",
105266          "name": "libnpmfund",
105267          "version": "3.0.5",
105268          "description": "Programmatic API for npm fund",
105269          "licenses": [
105270            {
105271              "license": {
105272                "id": "ISC"
105273              }
105274            }
105275          ],
105276          "cpe": "cpe:2.3:a:libnpmfund:libnpmfund:3.0.5:*:*:*:*:*:*:*",
105277          "purl": "pkg:npm/libnpmfund@3.0.5",
105278          "swid": {
105279            "attachment": {}
105280          },
105281          "pedigree": {},
105282          "externalReferences": [
105283            {
105284              "url": "https://github.com/npm/cli.git",
105285              "type": "distribution"
105286            }
105287          ],
105288          "evidence": {},
105289          "signature": {
105290            "signature": {
105291              "publicKey": {}
105292            }
105293          },
105294          "modelCard": {
105295            "modelParameters": {
105296              "approach": {}
105297            },
105298            "quantitativeAnalysis": {
105299              "graphics": {}
105300            },
105301            "considerations": {}
105302          }
105303        },
105304        {
105305          "type": "library",
105306          "bom-ref": "pkg:npm/libnpmhook@8.0.4?package-id=5679bee9e2f7003c",
105307          "supplier": {},
105308          "author": "GitHub Inc.",
105309          "name": "libnpmhook",
105310          "version": "8.0.4",
105311          "description": "programmatic API for managing npm registry hooks",
105312          "licenses": [
105313            {
105314              "license": {
105315                "id": "ISC"
105316              }
105317            }
105318          ],
105319          "cpe": "cpe:2.3:a:libnpmhook:libnpmhook:8.0.4:*:*:*:*:*:*:*",
105320          "purl": "pkg:npm/libnpmhook@8.0.4",
105321          "swid": {
105322            "attachment": {}
105323          },
105324          "pedigree": {},
105325          "externalReferences": [
105326            {
105327              "url": "https://github.com/npm/cli.git",
105328              "type": "distribution"
105329            }
105330          ],
105331          "evidence": {},
105332          "signature": {
105333            "signature": {
105334              "publicKey": {}
105335            }
105336          },
105337          "modelCard": {
105338            "modelParameters": {
105339              "approach": {}
105340            },
105341            "quantitativeAnalysis": {
105342              "graphics": {}
105343            },
105344            "considerations": {}
105345          }
105346        },
105347        {
105348          "type": "library",
105349          "bom-ref": "pkg:npm/libnpmorg@4.0.4?package-id=80c945656f22ba9d",
105350          "supplier": {},
105351          "author": "GitHub Inc.",
105352          "name": "libnpmorg",
105353          "version": "4.0.4",
105354          "description": "Programmatic api for `npm org` commands",
105355          "licenses": [
105356            {
105357              "license": {
105358                "id": "ISC"
105359              }
105360            }
105361          ],
105362          "cpe": "cpe:2.3:a:libnpmorg:libnpmorg:4.0.4:*:*:*:*:*:*:*",
105363          "purl": "pkg:npm/libnpmorg@4.0.4",
105364          "swid": {
105365            "attachment": {}
105366          },
105367          "pedigree": {},
105368          "externalReferences": [
105369            {
105370              "url": "https://github.com/npm/cli.git",
105371              "type": "distribution"
105372            },
105373            {
105374              "url": "https://npmjs.com/package/libnpmorg",
105375              "type": "website"
105376            }
105377          ],
105378          "evidence": {},
105379          "signature": {
105380            "signature": {
105381              "publicKey": {}
105382            }
105383          },
105384          "modelCard": {
105385            "modelParameters": {
105386              "approach": {}
105387            },
105388            "quantitativeAnalysis": {
105389              "graphics": {}
105390            },
105391            "considerations": {}
105392          }
105393        },
105394        {
105395          "type": "library",
105396          "bom-ref": "pkg:npm/libnpmpack@4.1.3?package-id=62f6985b14d7de3e",
105397          "supplier": {},
105398          "author": "GitHub Inc.",
105399          "name": "libnpmpack",
105400          "version": "4.1.3",
105401          "description": "Programmatic API for the bits behind npm pack",
105402          "licenses": [
105403            {
105404              "license": {
105405                "id": "ISC"
105406              }
105407            }
105408          ],
105409          "cpe": "cpe:2.3:a:libnpmpack:libnpmpack:4.1.3:*:*:*:*:*:*:*",
105410          "purl": "pkg:npm/libnpmpack@4.1.3",
105411          "swid": {
105412            "attachment": {}
105413          },
105414          "pedigree": {},
105415          "externalReferences": [
105416            {
105417              "url": "https://github.com/npm/cli.git",
105418              "type": "distribution"
105419            },
105420            {
105421              "url": "https://npmjs.com/package/libnpmpack",
105422              "type": "website"
105423            }
105424          ],
105425          "evidence": {},
105426          "signature": {
105427            "signature": {
105428              "publicKey": {}
105429            }
105430          },
105431          "modelCard": {
105432            "modelParameters": {
105433              "approach": {}
105434            },
105435            "quantitativeAnalysis": {
105436              "graphics": {}
105437            },
105438            "considerations": {}
105439          }
105440        },
105441        {
105442          "type": "library",
105443          "bom-ref": "pkg:npm/libnpmpublish@6.0.5?package-id=a970d9d2bf422a57",
105444          "supplier": {},
105445          "author": "GitHub Inc.",
105446          "name": "libnpmpublish",
105447          "version": "6.0.5",
105448          "description": "Programmatic API for the bits behind npm publish and unpublish",
105449          "licenses": [
105450            {
105451              "license": {
105452                "id": "ISC"
105453              }
105454            }
105455          ],
105456          "cpe": "cpe:2.3:a:libnpmpublish:libnpmpublish:6.0.5:*:*:*:*:*:*:*",
105457          "purl": "pkg:npm/libnpmpublish@6.0.5",
105458          "swid": {
105459            "attachment": {}
105460          },
105461          "pedigree": {},
105462          "externalReferences": [
105463            {
105464              "url": "https://github.com/npm/cli.git",
105465              "type": "distribution"
105466            },
105467            {
105468              "url": "https://npmjs.com/package/libnpmpublish",
105469              "type": "website"
105470            }
105471          ],
105472          "evidence": {},
105473          "signature": {
105474            "signature": {
105475              "publicKey": {}
105476            }
105477          },
105478          "modelCard": {
105479            "modelParameters": {
105480              "approach": {}
105481            },
105482            "quantitativeAnalysis": {
105483              "graphics": {}
105484            },
105485            "considerations": {}
105486          }
105487        },
105488        {
105489          "type": "library",
105490          "bom-ref": "pkg:npm/libnpmsearch@5.0.4?package-id=e3666452dd7e585d",
105491          "supplier": {},
105492          "author": "GitHub Inc.",
105493          "name": "libnpmsearch",
105494          "version": "5.0.4",
105495          "description": "Programmatic API for searching in npm and compatible registries.",
105496          "licenses": [
105497            {
105498              "license": {
105499                "id": "ISC"
105500              }
105501            }
105502          ],
105503          "cpe": "cpe:2.3:a:libnpmsearch:libnpmsearch:5.0.4:*:*:*:*:*:*:*",
105504          "purl": "pkg:npm/libnpmsearch@5.0.4",
105505          "swid": {
105506            "attachment": {}
105507          },
105508          "pedigree": {},
105509          "externalReferences": [
105510            {
105511              "url": "https://github.com/npm/cli.git",
105512              "type": "distribution"
105513            },
105514            {
105515              "url": "https://npmjs.com/package/libnpmsearch",
105516              "type": "website"
105517            }
105518          ],
105519          "evidence": {},
105520          "signature": {
105521            "signature": {
105522              "publicKey": {}
105523            }
105524          },
105525          "modelCard": {
105526            "modelParameters": {
105527              "approach": {}
105528            },
105529            "quantitativeAnalysis": {
105530              "graphics": {}
105531            },
105532            "considerations": {}
105533          }
105534        },
105535        {
105536          "type": "library",
105537          "bom-ref": "pkg:npm/libnpmteam@4.0.4?package-id=95c3c29c4dcd60d1",
105538          "supplier": {},
105539          "author": "GitHub Inc.",
105540          "name": "libnpmteam",
105541          "version": "4.0.4",
105542          "description": "npm Team management APIs",
105543          "licenses": [
105544            {
105545              "license": {
105546                "id": "ISC"
105547              }
105548            }
105549          ],
105550          "cpe": "cpe:2.3:a:libnpmteam:libnpmteam:4.0.4:*:*:*:*:*:*:*",
105551          "purl": "pkg:npm/libnpmteam@4.0.4",
105552          "swid": {
105553            "attachment": {}
105554          },
105555          "pedigree": {},
105556          "externalReferences": [
105557            {
105558              "url": "https://github.com/npm/cli.git",
105559              "type": "distribution"
105560            },
105561            {
105562              "url": "https://npmjs.com/package/libnpmteam",
105563              "type": "website"
105564            }
105565          ],
105566          "evidence": {},
105567          "signature": {
105568            "signature": {
105569              "publicKey": {}
105570            }
105571          },
105572          "modelCard": {
105573            "modelParameters": {
105574              "approach": {}
105575            },
105576            "quantitativeAnalysis": {
105577              "graphics": {}
105578            },
105579            "considerations": {}
105580          }
105581        },
105582        {
105583          "type": "library",
105584          "bom-ref": "pkg:npm/libnpmversion@3.0.7?package-id=9ace162e3f4ca294",
105585          "supplier": {},
105586          "author": "GitHub Inc.",
105587          "name": "libnpmversion",
105588          "version": "3.0.7",
105589          "description": "library to do the things that 'npm version' does",
105590          "licenses": [
105591            {
105592              "license": {
105593                "id": "ISC"
105594              }
105595            }
105596          ],
105597          "cpe": "cpe:2.3:a:libnpmversion:libnpmversion:3.0.7:*:*:*:*:*:*:*",
105598          "purl": "pkg:npm/libnpmversion@3.0.7",
105599          "swid": {
105600            "attachment": {}
105601          },
105602          "pedigree": {},
105603          "externalReferences": [
105604            {
105605              "url": "https://github.com/npm/cli.git",
105606              "type": "distribution"
105607            }
105608          ],
105609          "evidence": {},
105610          "signature": {
105611            "signature": {
105612              "publicKey": {}
105613            }
105614          },
105615          "modelCard": {
105616            "modelParameters": {
105617              "approach": {}
105618            },
105619            "quantitativeAnalysis": {
105620              "graphics": {}
105621            },
105622            "considerations": {}
105623          }
105624        },
105625        {
105626          "type": "library",
105627          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=609cb94e63dc06dd",
105628          "supplier": {},
105629          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
105630          "name": "libssl1.1",
105631          "version": "1.1.1t-r2",
105632          "description": "SSL shared libraries",
105633          "licenses": [
105634            {
105635              "license": {
105636                "id": "OpenSSL"
105637              }
105638            }
105639          ],
105640          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1t-r2:*:*:*:*:*:*:*",
105641          "purl": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
105642          "swid": {
105643            "attachment": {}
105644          },
105645          "pedigree": {},
105646          "externalReferences": [
105647            {
105648              "url": "https://www.openssl.org/",
105649              "type": "distribution"
105650            }
105651          ],
105652          "evidence": {},
105653          "signature": {
105654            "signature": {
105655              "publicKey": {}
105656            }
105657          },
105658          "modelCard": {
105659            "modelParameters": {
105660              "approach": {}
105661            },
105662            "quantitativeAnalysis": {
105663              "graphics": {}
105664            },
105665            "considerations": {}
105666          }
105667        },
105668        {
105669          "type": "library",
105670          "bom-ref": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=9913678ca8fd323d",
105671          "supplier": {},
105672          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
105673          "name": "libstdc++",
105674          "version": "11.2.1_git20220219-r2",
105675          "description": "GNU C++ standard runtime library",
105676          "licenses": [
105677            {
105678              "license": {
105679                "id": "GPL-2.0-or-later"
105680              }
105681            },
105682            {
105683              "license": {
105684                "id": "LGPL-2.1-or-later"
105685              }
105686            }
105687          ],
105688          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
105689          "purl": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
105690          "swid": {
105691            "attachment": {}
105692          },
105693          "pedigree": {},
105694          "externalReferences": [
105695            {
105696              "url": "https://gcc.gnu.org",
105697              "type": "distribution"
105698            }
105699          ],
105700          "evidence": {},
105701          "signature": {
105702            "signature": {
105703              "publicKey": {}
105704            }
105705          },
105706          "modelCard": {
105707            "modelParameters": {
105708              "approach": {}
105709            },
105710            "quantitativeAnalysis": {
105711              "graphics": {}
105712            },
105713            "considerations": {}
105714          }
105715        },
105716        {
105717          "type": "library",
105718          "bom-ref": "pkg:npm/lodash@4.17.21?package-id=75dfb844472e21c2",
105719          "supplier": {},
105720          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e",
105721          "name": "lodash",
105722          "version": "4.17.21",
105723          "description": "Lodash modular utilities.",
105724          "licenses": [
105725            {
105726              "license": {
105727                "id": "MIT"
105728              }
105729            }
105730          ],
105731          "cpe": "cpe:2.3:a:lodash:lodash:4.17.21:*:*:*:*:*:*:*",
105732          "purl": "pkg:npm/lodash@4.17.21",
105733          "swid": {
105734            "attachment": {}
105735          },
105736          "pedigree": {},
105737          "externalReferences": [
105738            {
105739              "url": "lodash/lodash",
105740              "type": "distribution"
105741            },
105742            {
105743              "url": "https://lodash.com/",
105744              "type": "website"
105745            }
105746          ],
105747          "evidence": {},
105748          "signature": {
105749            "signature": {
105750              "publicKey": {}
105751            }
105752          },
105753          "modelCard": {
105754            "modelParameters": {
105755              "approach": {}
105756            },
105757            "quantitativeAnalysis": {
105758              "graphics": {}
105759            },
105760            "considerations": {}
105761          }
105762        },
105763        {
105764          "type": "library",
105765          "bom-ref": "pkg:npm/lru-cache@6.0.0?package-id=a9db11b8d6d48a85",
105766          "supplier": {},
105767          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
105768          "name": "lru-cache",
105769          "version": "6.0.0",
105770          "description": "A cache object that deletes the least-recently-used items.",
105771          "licenses": [
105772            {
105773              "license": {
105774                "id": "ISC"
105775              }
105776            }
105777          ],
105778          "cpe": "cpe:2.3:a:lru-cache:lru-cache:6.0.0:*:*:*:*:*:*:*",
105779          "purl": "pkg:npm/lru-cache@6.0.0",
105780          "swid": {
105781            "attachment": {}
105782          },
105783          "pedigree": {},
105784          "externalReferences": [
105785            {
105786              "url": "git://github.com/isaacs/node-lru-cache.git",
105787              "type": "distribution"
105788            }
105789          ],
105790          "evidence": {},
105791          "signature": {
105792            "signature": {
105793              "publicKey": {}
105794            }
105795          },
105796          "modelCard": {
105797            "modelParameters": {
105798              "approach": {}
105799            },
105800            "quantitativeAnalysis": {
105801              "graphics": {}
105802            },
105803            "considerations": {}
105804          }
105805        },
105806        {
105807          "type": "library",
105808          "bom-ref": "pkg:npm/lru-cache@7.13.2?package-id=be5c7dc6ddace7cd",
105809          "supplier": {},
105810          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
105811          "name": "lru-cache",
105812          "version": "7.13.2",
105813          "description": "A cache object that deletes the least-recently-used items.",
105814          "licenses": [
105815            {
105816              "license": {
105817                "id": "ISC"
105818              }
105819            }
105820          ],
105821          "cpe": "cpe:2.3:a:lru-cache:lru-cache:7.13.2:*:*:*:*:*:*:*",
105822          "purl": "pkg:npm/lru-cache@7.13.2",
105823          "swid": {
105824            "attachment": {}
105825          },
105826          "pedigree": {},
105827          "externalReferences": [
105828            {
105829              "url": "git://github.com/isaacs/node-lru-cache.git",
105830              "type": "distribution"
105831            }
105832          ],
105833          "evidence": {},
105834          "signature": {
105835            "signature": {
105836              "publicKey": {}
105837            }
105838          },
105839          "modelCard": {
105840            "modelParameters": {
105841              "approach": {}
105842            },
105843            "quantitativeAnalysis": {
105844              "graphics": {}
105845            },
105846            "considerations": {}
105847          }
105848        },
105849        {
105850          "type": "library",
105851          "bom-ref": "pkg:npm/make-fetch-happen@10.2.1?package-id=d230079dee920278",
105852          "supplier": {},
105853          "author": "GitHub Inc.",
105854          "name": "make-fetch-happen",
105855          "version": "10.2.1",
105856          "description": "Opinionated, caching, retrying fetch client",
105857          "licenses": [
105858            {
105859              "license": {
105860                "id": "ISC"
105861              }
105862            }
105863          ],
105864          "cpe": "cpe:2.3:a:make-fetch-happen:make-fetch-happen:10.2.1:*:*:*:*:*:*:*",
105865          "purl": "pkg:npm/make-fetch-happen@10.2.1",
105866          "swid": {
105867            "attachment": {}
105868          },
105869          "pedigree": {},
105870          "externalReferences": [
105871            {
105872              "url": "https://github.com/npm/make-fetch-happen.git",
105873              "type": "distribution"
105874            }
105875          ],
105876          "evidence": {},
105877          "signature": {
105878            "signature": {
105879              "publicKey": {}
105880            }
105881          },
105882          "modelCard": {
105883            "modelParameters": {
105884              "approach": {}
105885            },
105886            "quantitativeAnalysis": {
105887              "graphics": {}
105888            },
105889            "considerations": {}
105890          }
105891        },
105892        {
105893          "type": "library",
105894          "bom-ref": "pkg:npm/md5.js@1.3.5?package-id=ddaf7ffca1d5ef2",
105895          "supplier": {},
105896          "author": "Kirill Fomichev \u003cfanatid@ya.ru\u003e (https://github.com/fanatid)",
105897          "name": "md5.js",
105898          "version": "1.3.5",
105899          "description": "node style md5 on pure JavaScript",
105900          "licenses": [
105901            {
105902              "license": {
105903                "id": "MIT"
105904              }
105905            }
105906          ],
105907          "cpe": "cpe:2.3:a:crypto-browserify:md5.js:1.3.5:*:*:*:*:*:*:*",
105908          "purl": "pkg:npm/md5.js@1.3.5",
105909          "swid": {
105910            "attachment": {}
105911          },
105912          "pedigree": {},
105913          "externalReferences": [
105914            {
105915              "url": "https://github.com/crypto-browserify/md5.js.git",
105916              "type": "distribution"
105917            },
105918            {
105919              "url": "https://github.com/crypto-browserify/md5.js",
105920              "type": "website"
105921            }
105922          ],
105923          "evidence": {},
105924          "signature": {
105925            "signature": {
105926              "publicKey": {}
105927            }
105928          },
105929          "modelCard": {
105930            "modelParameters": {
105931              "approach": {}
105932            },
105933            "quantitativeAnalysis": {
105934              "graphics": {}
105935            },
105936            "considerations": {}
105937          }
105938        },
105939        {
105940          "type": "library",
105941          "bom-ref": "pkg:npm/media-typer@0.3.0?package-id=edc1220ee5504fb4",
105942          "supplier": {},
105943          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
105944          "name": "media-typer",
105945          "version": "0.3.0",
105946          "description": "Simple RFC 6838 media type parser and formatter",
105947          "licenses": [
105948            {
105949              "license": {
105950                "id": "MIT"
105951              }
105952            }
105953          ],
105954          "cpe": "cpe:2.3:a:media-typer:media-typer:0.3.0:*:*:*:*:*:*:*",
105955          "purl": "pkg:npm/media-typer@0.3.0",
105956          "swid": {
105957            "attachment": {}
105958          },
105959          "pedigree": {},
105960          "externalReferences": [
105961            {
105962              "url": "jshttp/media-typer",
105963              "type": "distribution"
105964            }
105965          ],
105966          "evidence": {},
105967          "signature": {
105968            "signature": {
105969              "publicKey": {}
105970            }
105971          },
105972          "modelCard": {
105973            "modelParameters": {
105974              "approach": {}
105975            },
105976            "quantitativeAnalysis": {
105977              "graphics": {}
105978            },
105979            "considerations": {}
105980          }
105981        },
105982        {
105983          "type": "library",
105984          "bom-ref": "pkg:npm/merge-descriptors@1.0.1?package-id=24f38b1ffa4b7603",
105985          "supplier": {},
105986          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
105987          "name": "merge-descriptors",
105988          "version": "1.0.1",
105989          "description": "Merge objects using descriptors",
105990          "licenses": [
105991            {
105992              "license": {
105993                "id": "MIT"
105994              }
105995            }
105996          ],
105997          "cpe": "cpe:2.3:a:merge-descriptors:merge-descriptors:1.0.1:*:*:*:*:*:*:*",
105998          "purl": "pkg:npm/merge-descriptors@1.0.1",
105999          "swid": {
106000            "attachment": {}
106001          },
106002          "pedigree": {},
106003          "externalReferences": [
106004            {
106005              "url": "component/merge-descriptors",
106006              "type": "distribution"
106007            }
106008          ],
106009          "evidence": {},
106010          "signature": {
106011            "signature": {
106012              "publicKey": {}
106013            }
106014          },
106015          "modelCard": {
106016            "modelParameters": {
106017              "approach": {}
106018            },
106019            "quantitativeAnalysis": {
106020              "graphics": {}
106021            },
106022            "considerations": {}
106023          }
106024        },
106025        {
106026          "type": "library",
106027          "bom-ref": "pkg:npm/methods@1.1.2?package-id=9b85a46f19a1f1aa",
106028          "supplier": {},
106029          "name": "methods",
106030          "version": "1.1.2",
106031          "description": "HTTP methods that node supports",
106032          "licenses": [
106033            {
106034              "license": {
106035                "id": "MIT"
106036              }
106037            }
106038          ],
106039          "cpe": "cpe:2.3:a:methods:methods:1.1.2:*:*:*:*:*:*:*",
106040          "purl": "pkg:npm/methods@1.1.2",
106041          "swid": {
106042            "attachment": {}
106043          },
106044          "pedigree": {},
106045          "externalReferences": [
106046            {
106047              "url": "jshttp/methods",
106048              "type": "distribution"
106049            }
106050          ],
106051          "evidence": {},
106052          "signature": {
106053            "signature": {
106054              "publicKey": {}
106055            }
106056          },
106057          "modelCard": {
106058            "modelParameters": {
106059              "approach": {}
106060            },
106061            "quantitativeAnalysis": {
106062              "graphics": {}
106063            },
106064            "considerations": {}
106065          }
106066        },
106067        {
106068          "type": "library",
106069          "bom-ref": "pkg:npm/micromatch@4.0.5?package-id=b4a84104978015d0",
106070          "supplier": {},
106071          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
106072          "name": "micromatch",
106073          "version": "4.0.5",
106074          "description": "Glob matching for javascript/node.js. A replacement and faster alternative to minimatch and multimatch.",
106075          "licenses": [
106076            {
106077              "license": {
106078                "id": "MIT"
106079              }
106080            }
106081          ],
106082          "cpe": "cpe:2.3:a:micromatch:micromatch:4.0.5:*:*:*:*:*:*:*",
106083          "purl": "pkg:npm/micromatch@4.0.5",
106084          "swid": {
106085            "attachment": {}
106086          },
106087          "pedigree": {},
106088          "externalReferences": [
106089            {
106090              "url": "micromatch/micromatch",
106091              "type": "distribution"
106092            },
106093            {
106094              "url": "https://github.com/micromatch/micromatch",
106095              "type": "website"
106096            }
106097          ],
106098          "evidence": {},
106099          "signature": {
106100            "signature": {
106101              "publicKey": {}
106102            }
106103          },
106104          "modelCard": {
106105            "modelParameters": {
106106              "approach": {}
106107            },
106108            "quantitativeAnalysis": {
106109              "graphics": {}
106110            },
106111            "considerations": {}
106112          }
106113        },
106114        {
106115          "type": "library",
106116          "bom-ref": "pkg:npm/miller-rabin@4.0.1?package-id=4b5cf7edde29d056",
106117          "supplier": {},
106118          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
106119          "name": "miller-rabin",
106120          "version": "4.0.1",
106121          "description": "Miller Rabin algorithm for primality test",
106122          "licenses": [
106123            {
106124              "license": {
106125                "id": "MIT"
106126              }
106127            }
106128          ],
106129          "cpe": "cpe:2.3:a:miller-rabin:miller-rabin:4.0.1:*:*:*:*:*:*:*",
106130          "purl": "pkg:npm/miller-rabin@4.0.1",
106131          "swid": {
106132            "attachment": {}
106133          },
106134          "pedigree": {},
106135          "externalReferences": [
106136            {
106137              "url": "git@github.com:indutny/miller-rabin",
106138              "type": "distribution"
106139            },
106140            {
106141              "url": "https://github.com/indutny/miller-rabin",
106142              "type": "website"
106143            }
106144          ],
106145          "evidence": {},
106146          "signature": {
106147            "signature": {
106148              "publicKey": {}
106149            }
106150          },
106151          "modelCard": {
106152            "modelParameters": {
106153              "approach": {}
106154            },
106155            "quantitativeAnalysis": {
106156              "graphics": {}
106157            },
106158            "considerations": {}
106159          }
106160        },
106161        {
106162          "type": "library",
106163          "bom-ref": "pkg:npm/mime@1.4.1?package-id=b9a146d2dbc31576",
106164          "supplier": {},
106165          "author": "Robert Kieffer \u003crobert@broofa.com\u003e (http://github.com/broofa)",
106166          "name": "mime",
106167          "version": "1.4.1",
106168          "description": "A comprehensive library for mime-type mapping",
106169          "licenses": [
106170            {
106171              "license": {
106172                "id": "MIT"
106173              }
106174            }
106175          ],
106176          "cpe": "cpe:2.3:a:broofa:mime:1.4.1:*:*:*:*:*:*:*",
106177          "purl": "pkg:npm/mime@1.4.1",
106178          "swid": {
106179            "attachment": {}
106180          },
106181          "pedigree": {},
106182          "externalReferences": [
106183            {
106184              "url": "https://github.com/broofa/node-mime",
106185              "type": "distribution"
106186            }
106187          ],
106188          "evidence": {},
106189          "signature": {
106190            "signature": {
106191              "publicKey": {}
106192            }
106193          },
106194          "modelCard": {
106195            "modelParameters": {
106196              "approach": {}
106197            },
106198            "quantitativeAnalysis": {
106199              "graphics": {}
106200            },
106201            "considerations": {}
106202          }
106203        },
106204        {
106205          "type": "library",
106206          "bom-ref": "pkg:npm/mime-db@1.52.0?package-id=9e5bf4e4d5cc60c1",
106207          "supplier": {},
106208          "name": "mime-db",
106209          "version": "1.52.0",
106210          "description": "Media Type Database",
106211          "licenses": [
106212            {
106213              "license": {
106214                "id": "MIT"
106215              }
106216            }
106217          ],
106218          "cpe": "cpe:2.3:a:mime-db:mime-db:1.52.0:*:*:*:*:*:*:*",
106219          "purl": "pkg:npm/mime-db@1.52.0",
106220          "swid": {
106221            "attachment": {}
106222          },
106223          "pedigree": {},
106224          "externalReferences": [
106225            {
106226              "url": "jshttp/mime-db",
106227              "type": "distribution"
106228            }
106229          ],
106230          "evidence": {},
106231          "signature": {
106232            "signature": {
106233              "publicKey": {}
106234            }
106235          },
106236          "modelCard": {
106237            "modelParameters": {
106238              "approach": {}
106239            },
106240            "quantitativeAnalysis": {
106241              "graphics": {}
106242            },
106243            "considerations": {}
106244          }
106245        },
106246        {
106247          "type": "library",
106248          "bom-ref": "pkg:npm/mime-types@2.1.35?package-id=32ba3cb42be13b7a",
106249          "supplier": {},
106250          "name": "mime-types",
106251          "version": "2.1.35",
106252          "description": "The ultimate javascript content-type utility.",
106253          "licenses": [
106254            {
106255              "license": {
106256                "id": "MIT"
106257              }
106258            }
106259          ],
106260          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.35:*:*:*:*:*:*:*",
106261          "purl": "pkg:npm/mime-types@2.1.35",
106262          "swid": {
106263            "attachment": {}
106264          },
106265          "pedigree": {},
106266          "externalReferences": [
106267            {
106268              "url": "jshttp/mime-types",
106269              "type": "distribution"
106270            }
106271          ],
106272          "evidence": {},
106273          "signature": {
106274            "signature": {
106275              "publicKey": {}
106276            }
106277          },
106278          "modelCard": {
106279            "modelParameters": {
106280              "approach": {}
106281            },
106282            "quantitativeAnalysis": {
106283              "graphics": {}
106284            },
106285            "considerations": {}
106286          }
106287        },
106288        {
106289          "type": "library",
106290          "bom-ref": "pkg:npm/minimalistic-assert@1.0.1?package-id=d8672eb71813326d",
106291          "supplier": {},
106292          "name": "minimalistic-assert",
106293          "version": "1.0.1",
106294          "description": "minimalistic-assert ===",
106295          "licenses": [
106296            {
106297              "license": {
106298                "id": "ISC"
106299              }
106300            }
106301          ],
106302          "cpe": "cpe:2.3:a:minimalistic-assert:minimalistic-assert:1.0.1:*:*:*:*:*:*:*",
106303          "purl": "pkg:npm/minimalistic-assert@1.0.1",
106304          "swid": {
106305            "attachment": {}
106306          },
106307          "pedigree": {},
106308          "externalReferences": [
106309            {
106310              "url": "https://github.com/calvinmetcalf/minimalistic-assert.git",
106311              "type": "distribution"
106312            },
106313            {
106314              "url": "https://github.com/calvinmetcalf/minimalistic-assert",
106315              "type": "website"
106316            }
106317          ],
106318          "evidence": {},
106319          "signature": {
106320            "signature": {
106321              "publicKey": {}
106322            }
106323          },
106324          "modelCard": {
106325            "modelParameters": {
106326              "approach": {}
106327            },
106328            "quantitativeAnalysis": {
106329              "graphics": {}
106330            },
106331            "considerations": {}
106332          }
106333        },
106334        {
106335          "type": "library",
106336          "bom-ref": "pkg:npm/minimalistic-crypto-utils@1.0.1?package-id=be5542e945ab4684",
106337          "supplier": {},
106338          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
106339          "name": "minimalistic-crypto-utils",
106340          "version": "1.0.1",
106341          "description": "Minimalistic tools for JS crypto modules",
106342          "licenses": [
106343            {
106344              "license": {
106345                "id": "MIT"
106346              }
106347            }
106348          ],
106349          "cpe": "cpe:2.3:a:minimalistic-crypto-utils:minimalistic-crypto-utils:1.0.1:*:*:*:*:*:*:*",
106350          "purl": "pkg:npm/minimalistic-crypto-utils@1.0.1",
106351          "swid": {
106352            "attachment": {}
106353          },
106354          "pedigree": {},
106355          "externalReferences": [
106356            {
106357              "url": "git+ssh://git@github.com/indutny/minimalistic-crypto-utils.git",
106358              "type": "distribution"
106359            },
106360            {
106361              "url": "https://github.com/indutny/minimalistic-crypto-utils#readme",
106362              "type": "website"
106363            }
106364          ],
106365          "evidence": {},
106366          "signature": {
106367            "signature": {
106368              "publicKey": {}
106369            }
106370          },
106371          "modelCard": {
106372            "modelParameters": {
106373              "approach": {}
106374            },
106375            "quantitativeAnalysis": {
106376              "graphics": {}
106377            },
106378            "considerations": {}
106379          }
106380        },
106381        {
106382          "type": "library",
106383          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=32b47b032f3721ab",
106384          "supplier": {},
106385          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
106386          "name": "minimatch",
106387          "version": "3.1.2",
106388          "description": "a glob matcher in javascript",
106389          "licenses": [
106390            {
106391              "license": {
106392                "id": "ISC"
106393              }
106394            }
106395          ],
106396          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
106397          "purl": "pkg:npm/minimatch@3.1.2",
106398          "swid": {
106399            "attachment": {}
106400          },
106401          "pedigree": {},
106402          "externalReferences": [
106403            {
106404              "url": "git://github.com/isaacs/minimatch.git",
106405              "type": "distribution"
106406            }
106407          ],
106408          "evidence": {},
106409          "signature": {
106410            "signature": {
106411              "publicKey": {}
106412            }
106413          },
106414          "modelCard": {
106415            "modelParameters": {
106416              "approach": {}
106417            },
106418            "quantitativeAnalysis": {
106419              "graphics": {}
106420            },
106421            "considerations": {}
106422          }
106423        },
106424        {
106425          "type": "library",
106426          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=7392185ecbfd5435",
106427          "supplier": {},
106428          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
106429          "name": "minimatch",
106430          "version": "3.1.2",
106431          "description": "a glob matcher in javascript",
106432          "licenses": [
106433            {
106434              "license": {
106435                "id": "ISC"
106436              }
106437            }
106438          ],
106439          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
106440          "purl": "pkg:npm/minimatch@3.1.2",
106441          "swid": {
106442            "attachment": {}
106443          },
106444          "pedigree": {},
106445          "externalReferences": [
106446            {
106447              "url": "git://github.com/isaacs/minimatch.git",
106448              "type": "distribution"
106449            }
106450          ],
106451          "evidence": {},
106452          "signature": {
106453            "signature": {
106454              "publicKey": {}
106455            }
106456          },
106457          "modelCard": {
106458            "modelParameters": {
106459              "approach": {}
106460            },
106461            "quantitativeAnalysis": {
106462              "graphics": {}
106463            },
106464            "considerations": {}
106465          }
106466        },
106467        {
106468          "type": "library",
106469          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=3a6089330eaf3563",
106470          "supplier": {},
106471          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
106472          "name": "minimatch",
106473          "version": "3.1.2",
106474          "description": "a glob matcher in javascript",
106475          "licenses": [
106476            {
106477              "license": {
106478                "id": "ISC"
106479              }
106480            }
106481          ],
106482          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
106483          "purl": "pkg:npm/minimatch@3.1.2",
106484          "swid": {
106485            "attachment": {}
106486          },
106487          "pedigree": {},
106488          "externalReferences": [
106489            {
106490              "url": "git://github.com/isaacs/minimatch.git",
106491              "type": "distribution"
106492            }
106493          ],
106494          "evidence": {},
106495          "signature": {
106496            "signature": {
106497              "publicKey": {}
106498            }
106499          },
106500          "modelCard": {
106501            "modelParameters": {
106502              "approach": {}
106503            },
106504            "quantitativeAnalysis": {
106505              "graphics": {}
106506            },
106507            "considerations": {}
106508          }
106509        },
106510        {
106511          "type": "library",
106512          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=4a815c2235402e8f",
106513          "supplier": {},
106514          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
106515          "name": "minimatch",
106516          "version": "3.1.2",
106517          "description": "a glob matcher in javascript",
106518          "licenses": [
106519            {
106520              "license": {
106521                "id": "ISC"
106522              }
106523            }
106524          ],
106525          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
106526          "purl": "pkg:npm/minimatch@3.1.2",
106527          "swid": {
106528            "attachment": {}
106529          },
106530          "pedigree": {},
106531          "externalReferences": [
106532            {
106533              "url": "git://github.com/isaacs/minimatch.git",
106534              "type": "distribution"
106535            }
106536          ],
106537          "evidence": {},
106538          "signature": {
106539            "signature": {
106540              "publicKey": {}
106541            }
106542          },
106543          "modelCard": {
106544            "modelParameters": {
106545              "approach": {}
106546            },
106547            "quantitativeAnalysis": {
106548              "graphics": {}
106549            },
106550            "considerations": {}
106551          }
106552        },
106553        {
106554          "type": "library",
106555          "bom-ref": "pkg:npm/minimatch@5.1.0?package-id=7bf8dbc1a2543e83",
106556          "supplier": {},
106557          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
106558          "name": "minimatch",
106559          "version": "5.1.0",
106560          "description": "a glob matcher in javascript",
106561          "licenses": [
106562            {
106563              "license": {
106564                "id": "ISC"
106565              }
106566            }
106567          ],
106568          "cpe": "cpe:2.3:a:minimatch:minimatch:5.1.0:*:*:*:*:*:*:*",
106569          "purl": "pkg:npm/minimatch@5.1.0",
106570          "swid": {
106571            "attachment": {}
106572          },
106573          "pedigree": {},
106574          "externalReferences": [
106575            {
106576              "url": "git://github.com/isaacs/minimatch.git",
106577              "type": "distribution"
106578            }
106579          ],
106580          "evidence": {},
106581          "signature": {
106582            "signature": {
106583              "publicKey": {}
106584            }
106585          },
106586          "modelCard": {
106587            "modelParameters": {
106588              "approach": {}
106589            },
106590            "quantitativeAnalysis": {
106591              "graphics": {}
106592            },
106593            "considerations": {}
106594          }
106595        },
106596        {
106597          "type": "library",
106598          "bom-ref": "pkg:npm/minimist@1.2.8?package-id=685b487bfc99270d",
106599          "supplier": {},
106600          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
106601          "name": "minimist",
106602          "version": "1.2.8",
106603          "description": "parse argument options",
106604          "licenses": [
106605            {
106606              "license": {
106607                "id": "MIT"
106608              }
106609            }
106610          ],
106611          "cpe": "cpe:2.3:a:minimistjs:minimist:1.2.8:*:*:*:*:*:*:*",
106612          "purl": "pkg:npm/minimist@1.2.8",
106613          "swid": {
106614            "attachment": {}
106615          },
106616          "pedigree": {},
106617          "externalReferences": [
106618            {
106619              "url": "git://github.com/minimistjs/minimist.git",
106620              "type": "distribution"
106621            },
106622            {
106623              "url": "https://github.com/minimistjs/minimist",
106624              "type": "website"
106625            }
106626          ],
106627          "evidence": {},
106628          "signature": {
106629            "signature": {
106630              "publicKey": {}
106631            }
106632          },
106633          "modelCard": {
106634            "modelParameters": {
106635              "approach": {}
106636            },
106637            "quantitativeAnalysis": {
106638              "graphics": {}
106639            },
106640            "considerations": {}
106641          }
106642        },
106643        {
106644          "type": "library",
106645          "bom-ref": "pkg:npm/minimist@1.2.8?package-id=b5346d2efe922f83",
106646          "supplier": {},
106647          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
106648          "name": "minimist",
106649          "version": "1.2.8",
106650          "description": "parse argument options",
106651          "licenses": [
106652            {
106653              "license": {
106654                "id": "MIT"
106655              }
106656            }
106657          ],
106658          "cpe": "cpe:2.3:a:minimistjs:minimist:1.2.8:*:*:*:*:*:*:*",
106659          "purl": "pkg:npm/minimist@1.2.8",
106660          "swid": {
106661            "attachment": {}
106662          },
106663          "pedigree": {},
106664          "externalReferences": [
106665            {
106666              "url": "git://github.com/minimistjs/minimist.git",
106667              "type": "distribution"
106668            },
106669            {
106670              "url": "https://github.com/minimistjs/minimist",
106671              "type": "website"
106672            }
106673          ],
106674          "evidence": {},
106675          "signature": {
106676            "signature": {
106677              "publicKey": {}
106678            }
106679          },
106680          "modelCard": {
106681            "modelParameters": {
106682              "approach": {}
106683            },
106684            "quantitativeAnalysis": {
106685              "graphics": {}
106686            },
106687            "considerations": {}
106688          }
106689        },
106690        {
106691          "type": "library",
106692          "bom-ref": "pkg:npm/minio@7.0.33?package-id=7f471798ead20140",
106693          "supplier": {},
106694          "author": "MinIO, Inc. (https://min.io)",
106695          "name": "minio",
106696          "version": "7.0.33",
106697          "description": "S3 Compatible Cloud Storage client",
106698          "licenses": [
106699            {
106700              "license": {
106701                "id": "Apache-2.0"
106702              }
106703            }
106704          ],
106705          "cpe": "cpe:2.3:a:minio:minio:7.0.33:*:*:*:*:*:*:*",
106706          "purl": "pkg:npm/minio@7.0.33",
106707          "swid": {
106708            "attachment": {}
106709          },
106710          "pedigree": {},
106711          "externalReferences": [
106712            {
106713              "url": "git+https://github.com/minio/minio-js.git",
106714              "type": "distribution"
106715            },
106716            {
106717              "url": "https://github.com/minio/minio-js#readme",
106718              "type": "website"
106719            }
106720          ],
106721          "evidence": {},
106722          "signature": {
106723            "signature": {
106724              "publicKey": {}
106725            }
106726          },
106727          "modelCard": {
106728            "modelParameters": {
106729              "approach": {}
106730            },
106731            "quantitativeAnalysis": {
106732              "graphics": {}
106733            },
106734            "considerations": {}
106735          }
106736        },
106737        {
106738          "type": "library",
106739          "bom-ref": "pkg:npm/minipass@3.3.4?package-id=b613ca6e3e5e1fdb",
106740          "supplier": {},
106741          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
106742          "name": "minipass",
106743          "version": "3.3.4",
106744          "description": "minimal implementation of a PassThrough stream",
106745          "licenses": [
106746            {
106747              "license": {
106748                "id": "ISC"
106749              }
106750            }
106751          ],
106752          "cpe": "cpe:2.3:a:minipass:minipass:3.3.4:*:*:*:*:*:*:*",
106753          "purl": "pkg:npm/minipass@3.3.4",
106754          "swid": {
106755            "attachment": {}
106756          },
106757          "pedigree": {},
106758          "externalReferences": [
106759            {
106760              "url": "git+https://github.com/isaacs/minipass.git",
106761              "type": "distribution"
106762            }
106763          ],
106764          "evidence": {},
106765          "signature": {
106766            "signature": {
106767              "publicKey": {}
106768            }
106769          },
106770          "modelCard": {
106771            "modelParameters": {
106772              "approach": {}
106773            },
106774            "quantitativeAnalysis": {
106775              "graphics": {}
106776            },
106777            "considerations": {}
106778          }
106779        },
106780        {
106781          "type": "library",
106782          "bom-ref": "pkg:npm/minipass@3.3.6?package-id=155d37b12b10bb25",
106783          "supplier": {},
106784          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
106785          "name": "minipass",
106786          "version": "3.3.6",
106787          "description": "minimal implementation of a PassThrough stream",
106788          "licenses": [
106789            {
106790              "license": {
106791                "id": "ISC"
106792              }
106793            }
106794          ],
106795          "cpe": "cpe:2.3:a:minipass:minipass:3.3.6:*:*:*:*:*:*:*",
106796          "purl": "pkg:npm/minipass@3.3.6",
106797          "swid": {
106798            "attachment": {}
106799          },
106800          "pedigree": {},
106801          "externalReferences": [
106802            {
106803              "url": "git+https://github.com/isaacs/minipass.git",
106804              "type": "distribution"
106805            }
106806          ],
106807          "evidence": {},
106808          "signature": {
106809            "signature": {
106810              "publicKey": {}
106811            }
106812          },
106813          "modelCard": {
106814            "modelParameters": {
106815              "approach": {}
106816            },
106817            "quantitativeAnalysis": {
106818              "graphics": {}
106819            },
106820            "considerations": {}
106821          }
106822        },
106823        {
106824          "type": "library",
106825          "bom-ref": "pkg:npm/minipass-collect@1.0.2?package-id=48596b1d4dbb4f19",
106826          "supplier": {},
106827          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
106828          "name": "minipass-collect",
106829          "version": "1.0.2",
106830          "description": "A Minipass stream that collects all the data into a single chunk",
106831          "licenses": [
106832            {
106833              "license": {
106834                "id": "ISC"
106835              }
106836            }
106837          ],
106838          "cpe": "cpe:2.3:a:minipass-collect:minipass-collect:1.0.2:*:*:*:*:*:*:*",
106839          "purl": "pkg:npm/minipass-collect@1.0.2",
106840          "swid": {
106841            "attachment": {}
106842          },
106843          "pedigree": {},
106844          "evidence": {},
106845          "signature": {
106846            "signature": {
106847              "publicKey": {}
106848            }
106849          },
106850          "modelCard": {
106851            "modelParameters": {
106852              "approach": {}
106853            },
106854            "quantitativeAnalysis": {
106855              "graphics": {}
106856            },
106857            "considerations": {}
106858          }
106859        },
106860        {
106861          "type": "library",
106862          "bom-ref": "pkg:npm/minipass-fetch@2.1.1?package-id=1efc5437ba452e1d",
106863          "supplier": {},
106864          "author": "GitHub Inc.",
106865          "name": "minipass-fetch",
106866          "version": "2.1.1",
106867          "description": "An implementation of window.fetch in Node.js using Minipass streams",
106868          "licenses": [
106869            {
106870              "license": {
106871                "id": "MIT"
106872              }
106873            }
106874          ],
106875          "cpe": "cpe:2.3:a:minipass-fetch:minipass-fetch:2.1.1:*:*:*:*:*:*:*",
106876          "purl": "pkg:npm/minipass-fetch@2.1.1",
106877          "swid": {
106878            "attachment": {}
106879          },
106880          "pedigree": {},
106881          "externalReferences": [
106882            {
106883              "url": "https://github.com/npm/minipass-fetch.git",
106884              "type": "distribution"
106885            }
106886          ],
106887          "evidence": {},
106888          "signature": {
106889            "signature": {
106890              "publicKey": {}
106891            }
106892          },
106893          "modelCard": {
106894            "modelParameters": {
106895              "approach": {}
106896            },
106897            "quantitativeAnalysis": {
106898              "graphics": {}
106899            },
106900            "considerations": {}
106901          }
106902        },
106903        {
106904          "type": "library",
106905          "bom-ref": "pkg:npm/minipass-flush@1.0.5?package-id=f00a260926226ede",
106906          "supplier": {},
106907          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
106908          "name": "minipass-flush",
106909          "version": "1.0.5",
106910          "description": "A Minipass stream that calls a flush function before emitting 'end'",
106911          "licenses": [
106912            {
106913              "license": {
106914                "id": "ISC"
106915              }
106916            }
106917          ],
106918          "cpe": "cpe:2.3:a:minipass-flush:minipass-flush:1.0.5:*:*:*:*:*:*:*",
106919          "purl": "pkg:npm/minipass-flush@1.0.5",
106920          "swid": {
106921            "attachment": {}
106922          },
106923          "pedigree": {},
106924          "externalReferences": [
106925            {
106926              "url": "git+https://github.com/isaacs/minipass-flush.git",
106927              "type": "distribution"
106928            }
106929          ],
106930          "evidence": {},
106931          "signature": {
106932            "signature": {
106933              "publicKey": {}
106934            }
106935          },
106936          "modelCard": {
106937            "modelParameters": {
106938              "approach": {}
106939            },
106940            "quantitativeAnalysis": {
106941              "graphics": {}
106942            },
106943            "considerations": {}
106944          }
106945        },
106946        {
106947          "type": "library",
106948          "bom-ref": "pkg:npm/minipass-json-stream@1.0.1?package-id=43ed818882788b6b",
106949          "supplier": {},
106950          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
106951          "name": "minipass-json-stream",
106952          "version": "1.0.1",
106953          "description": "Like JSONStream, but using Minipass streams",
106954          "licenses": [
106955            {
106956              "license": {
106957                "id": "MIT"
106958              }
106959            }
106960          ],
106961          "cpe": "cpe:2.3:a:minipass-json-stream:minipass-json-stream:1.0.1:*:*:*:*:*:*:*",
106962          "purl": "pkg:npm/minipass-json-stream@1.0.1",
106963          "swid": {
106964            "attachment": {}
106965          },
106966          "pedigree": {},
106967          "externalReferences": [
106968            {
106969              "url": "git+https://github.com/npm/minipass-json-stream.git",
106970              "type": "distribution"
106971            }
106972          ],
106973          "evidence": {},
106974          "signature": {
106975            "signature": {
106976              "publicKey": {}
106977            }
106978          },
106979          "modelCard": {
106980            "modelParameters": {
106981              "approach": {}
106982            },
106983            "quantitativeAnalysis": {
106984              "graphics": {}
106985            },
106986            "considerations": {}
106987          }
106988        },
106989        {
106990          "type": "library",
106991          "bom-ref": "pkg:npm/minipass-pipeline@1.2.4?package-id=891713a52fe6cc27",
106992          "supplier": {},
106993          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
106994          "name": "minipass-pipeline",
106995          "version": "1.2.4",
106996          "description": "create a pipeline of streams using Minipass",
106997          "licenses": [
106998            {
106999              "license": {
107000                "id": "ISC"
107001              }
107002            }
107003          ],
107004          "cpe": "cpe:2.3:a:minipass-pipeline:minipass-pipeline:1.2.4:*:*:*:*:*:*:*",
107005          "purl": "pkg:npm/minipass-pipeline@1.2.4",
107006          "swid": {
107007            "attachment": {}
107008          },
107009          "pedigree": {},
107010          "evidence": {},
107011          "signature": {
107012            "signature": {
107013              "publicKey": {}
107014            }
107015          },
107016          "modelCard": {
107017            "modelParameters": {
107018              "approach": {}
107019            },
107020            "quantitativeAnalysis": {
107021              "graphics": {}
107022            },
107023            "considerations": {}
107024          }
107025        },
107026        {
107027          "type": "library",
107028          "bom-ref": "pkg:npm/minipass-sized@1.0.3?package-id=cd4842c35733398b",
107029          "supplier": {},
107030          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
107031          "name": "minipass-sized",
107032          "version": "1.0.3",
107033          "description": "A Minipass stream that raises an error if you get a different number of bytes than expected",
107034          "licenses": [
107035            {
107036              "license": {
107037                "id": "ISC"
107038              }
107039            }
107040          ],
107041          "cpe": "cpe:2.3:a:minipass-sized:minipass-sized:1.0.3:*:*:*:*:*:*:*",
107042          "purl": "pkg:npm/minipass-sized@1.0.3",
107043          "swid": {
107044            "attachment": {}
107045          },
107046          "pedigree": {},
107047          "externalReferences": [
107048            {
107049              "url": "git+https://github.com/isaacs/minipass-sized.git",
107050              "type": "distribution"
107051            }
107052          ],
107053          "evidence": {},
107054          "signature": {
107055            "signature": {
107056              "publicKey": {}
107057            }
107058          },
107059          "modelCard": {
107060            "modelParameters": {
107061              "approach": {}
107062            },
107063            "quantitativeAnalysis": {
107064              "graphics": {}
107065            },
107066            "considerations": {}
107067          }
107068        },
107069        {
107070          "type": "library",
107071          "bom-ref": "pkg:npm/minizlib@2.1.2?package-id=a651644b4f6a3e3",
107072          "supplier": {},
107073          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
107074          "name": "minizlib",
107075          "version": "2.1.2",
107076          "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
107077          "licenses": [
107078            {
107079              "license": {
107080                "id": "MIT"
107081              }
107082            }
107083          ],
107084          "cpe": "cpe:2.3:a:minizlib:minizlib:2.1.2:*:*:*:*:*:*:*",
107085          "purl": "pkg:npm/minizlib@2.1.2",
107086          "swid": {
107087            "attachment": {}
107088          },
107089          "pedigree": {},
107090          "externalReferences": [
107091            {
107092              "url": "git+https://github.com/isaacs/minizlib.git",
107093              "type": "distribution"
107094            }
107095          ],
107096          "evidence": {},
107097          "signature": {
107098            "signature": {
107099              "publicKey": {}
107100            }
107101          },
107102          "modelCard": {
107103            "modelParameters": {
107104              "approach": {}
107105            },
107106            "quantitativeAnalysis": {
107107              "graphics": {}
107108            },
107109            "considerations": {}
107110          }
107111        },
107112        {
107113          "type": "library",
107114          "bom-ref": "pkg:npm/minizlib@2.1.2?package-id=7bb75b451bb46790",
107115          "supplier": {},
107116          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
107117          "name": "minizlib",
107118          "version": "2.1.2",
107119          "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
107120          "licenses": [
107121            {
107122              "license": {
107123                "id": "MIT"
107124              }
107125            }
107126          ],
107127          "cpe": "cpe:2.3:a:minizlib:minizlib:2.1.2:*:*:*:*:*:*:*",
107128          "purl": "pkg:npm/minizlib@2.1.2",
107129          "swid": {
107130            "attachment": {}
107131          },
107132          "pedigree": {},
107133          "externalReferences": [
107134            {
107135              "url": "git+https://github.com/isaacs/minizlib.git",
107136              "type": "distribution"
107137            }
107138          ],
107139          "evidence": {},
107140          "signature": {
107141            "signature": {
107142              "publicKey": {}
107143            }
107144          },
107145          "modelCard": {
107146            "modelParameters": {
107147              "approach": {}
107148            },
107149            "quantitativeAnalysis": {
107150              "graphics": {}
107151            },
107152            "considerations": {}
107153          }
107154        },
107155        {
107156          "type": "library",
107157          "bom-ref": "pkg:npm/mkdirp@0.5.6?package-id=652fb6b912e95935",
107158          "supplier": {},
107159          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
107160          "name": "mkdirp",
107161          "version": "0.5.6",
107162          "description": "Recursively mkdir, like `mkdir -p`",
107163          "licenses": [
107164            {
107165              "license": {
107166                "id": "MIT"
107167              }
107168            }
107169          ],
107170          "cpe": "cpe:2.3:a:substack:mkdirp:0.5.6:*:*:*:*:*:*:*",
107171          "purl": "pkg:npm/mkdirp@0.5.6",
107172          "swid": {
107173            "attachment": {}
107174          },
107175          "pedigree": {},
107176          "externalReferences": [
107177            {
107178              "url": "https://github.com/substack/node-mkdirp.git",
107179              "type": "distribution"
107180            }
107181          ],
107182          "evidence": {},
107183          "signature": {
107184            "signature": {
107185              "publicKey": {}
107186            }
107187          },
107188          "modelCard": {
107189            "modelParameters": {
107190              "approach": {}
107191            },
107192            "quantitativeAnalysis": {
107193              "graphics": {}
107194            },
107195            "considerations": {}
107196          }
107197        },
107198        {
107199          "type": "library",
107200          "bom-ref": "pkg:npm/mkdirp@1.0.4?package-id=9695628e211e131d",
107201          "supplier": {},
107202          "name": "mkdirp",
107203          "version": "1.0.4",
107204          "description": "Recursively mkdir, like `mkdir -p`",
107205          "licenses": [
107206            {
107207              "license": {
107208                "id": "MIT"
107209              }
107210            }
107211          ],
107212          "cpe": "cpe:2.3:a:isaacs:mkdirp:1.0.4:*:*:*:*:*:*:*",
107213          "purl": "pkg:npm/mkdirp@1.0.4",
107214          "swid": {
107215            "attachment": {}
107216          },
107217          "pedigree": {},
107218          "externalReferences": [
107219            {
107220              "url": "https://github.com/isaacs/node-mkdirp.git",
107221              "type": "distribution"
107222            }
107223          ],
107224          "evidence": {},
107225          "signature": {
107226            "signature": {
107227              "publicKey": {}
107228            }
107229          },
107230          "modelCard": {
107231            "modelParameters": {
107232              "approach": {}
107233            },
107234            "quantitativeAnalysis": {
107235              "graphics": {}
107236            },
107237            "considerations": {}
107238          }
107239        },
107240        {
107241          "type": "library",
107242          "bom-ref": "pkg:npm/mkdirp-infer-owner@2.0.0?package-id=cd2840516db98e09",
107243          "supplier": {},
107244          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
107245          "name": "mkdirp-infer-owner",
107246          "version": "2.0.0",
107247          "description": "mkdirp, but chown to the owner of the containing folder if possible and necessary",
107248          "licenses": [
107249            {
107250              "license": {
107251                "id": "ISC"
107252              }
107253            }
107254          ],
107255          "cpe": "cpe:2.3:a:mkdirp-infer-owner:mkdirp-infer-owner:2.0.0:*:*:*:*:*:*:*",
107256          "purl": "pkg:npm/mkdirp-infer-owner@2.0.0",
107257          "swid": {
107258            "attachment": {}
107259          },
107260          "pedigree": {},
107261          "externalReferences": [
107262            {
107263              "url": "git+https://github.com/isaacs/mkdirp-infer-owner",
107264              "type": "distribution"
107265            }
107266          ],
107267          "evidence": {},
107268          "signature": {
107269            "signature": {
107270              "publicKey": {}
107271            }
107272          },
107273          "modelCard": {
107274            "modelParameters": {
107275              "approach": {}
107276            },
107277            "quantitativeAnalysis": {
107278              "graphics": {}
107279            },
107280            "considerations": {}
107281          }
107282        },
107283        {
107284          "type": "library",
107285          "bom-ref": "pkg:npm/monorepo-symlink-test@0.0.0?package-id=fb8f3eb0b123561e",
107286          "supplier": {},
107287          "name": "monorepo-symlink-test",
107288          "version": "0.0.0",
107289          "licenses": [
107290            {
107291              "license": {
107292                "id": "MIT"
107293              }
107294            }
107295          ],
107296          "cpe": "cpe:2.3:a:monorepo-symlink-test:monorepo-symlink-test:0.0.0:*:*:*:*:*:*:*",
107297          "purl": "pkg:npm/monorepo-symlink-test@0.0.0",
107298          "swid": {
107299            "attachment": {}
107300          },
107301          "pedigree": {},
107302          "evidence": {},
107303          "signature": {
107304            "signature": {
107305              "publicKey": {}
107306            }
107307          },
107308          "modelCard": {
107309            "modelParameters": {
107310              "approach": {}
107311            },
107312            "quantitativeAnalysis": {
107313              "graphics": {}
107314            },
107315            "considerations": {}
107316          }
107317        },
107318        {
107319          "type": "library",
107320          "bom-ref": "pkg:npm/morgan@1.9.1?package-id=85eceee62a69b591",
107321          "supplier": {},
107322          "name": "morgan",
107323          "version": "1.9.1",
107324          "description": "HTTP request logger middleware for node.js",
107325          "licenses": [
107326            {
107327              "license": {
107328                "id": "MIT"
107329              }
107330            }
107331          ],
107332          "cpe": "cpe:2.3:a:morgan:morgan:1.9.1:*:*:*:*:*:*:*",
107333          "purl": "pkg:npm/morgan@1.9.1",
107334          "swid": {
107335            "attachment": {}
107336          },
107337          "pedigree": {},
107338          "externalReferences": [
107339            {
107340              "url": "expressjs/morgan",
107341              "type": "distribution"
107342            }
107343          ],
107344          "evidence": {},
107345          "signature": {
107346            "signature": {
107347              "publicKey": {}
107348            }
107349          },
107350          "modelCard": {
107351            "modelParameters": {
107352              "approach": {}
107353            },
107354            "quantitativeAnalysis": {
107355              "graphics": {}
107356            },
107357            "considerations": {}
107358          }
107359        },
107360        {
107361          "type": "library",
107362          "bom-ref": "pkg:npm/ms@2.0.0?package-id=5a1105814fc945d6",
107363          "supplier": {},
107364          "name": "ms",
107365          "version": "2.0.0",
107366          "description": "Tiny milisecond conversion utility",
107367          "licenses": [
107368            {
107369              "license": {
107370                "id": "MIT"
107371              }
107372            }
107373          ],
107374          "cpe": "cpe:2.3:a:ms:ms:2.0.0:*:*:*:*:*:*:*",
107375          "purl": "pkg:npm/ms@2.0.0",
107376          "swid": {
107377            "attachment": {}
107378          },
107379          "pedigree": {},
107380          "externalReferences": [
107381            {
107382              "url": "zeit/ms",
107383              "type": "distribution"
107384            }
107385          ],
107386          "evidence": {},
107387          "signature": {
107388            "signature": {
107389              "publicKey": {}
107390            }
107391          },
107392          "modelCard": {
107393            "modelParameters": {
107394              "approach": {}
107395            },
107396            "quantitativeAnalysis": {
107397              "graphics": {}
107398            },
107399            "considerations": {}
107400          }
107401        },
107402        {
107403          "type": "library",
107404          "bom-ref": "pkg:npm/ms@2.1.2?package-id=baab6160abc8414d",
107405          "supplier": {},
107406          "name": "ms",
107407          "version": "2.1.2",
107408          "description": "Tiny millisecond conversion utility",
107409          "licenses": [
107410            {
107411              "license": {
107412                "id": "MIT"
107413              }
107414            }
107415          ],
107416          "cpe": "cpe:2.3:a:ms:ms:2.1.2:*:*:*:*:*:*:*",
107417          "purl": "pkg:npm/ms@2.1.2",
107418          "swid": {
107419            "attachment": {}
107420          },
107421          "pedigree": {},
107422          "externalReferences": [
107423            {
107424              "url": "zeit/ms",
107425              "type": "distribution"
107426            }
107427          ],
107428          "evidence": {},
107429          "signature": {
107430            "signature": {
107431              "publicKey": {}
107432            }
107433          },
107434          "modelCard": {
107435            "modelParameters": {
107436              "approach": {}
107437            },
107438            "quantitativeAnalysis": {
107439              "graphics": {}
107440            },
107441            "considerations": {}
107442          }
107443        },
107444        {
107445          "type": "library",
107446          "bom-ref": "pkg:npm/ms@2.1.3?package-id=56db25c219fa0f4e",
107447          "supplier": {},
107448          "name": "ms",
107449          "version": "2.1.3",
107450          "description": "Tiny millisecond conversion utility",
107451          "licenses": [
107452            {
107453              "license": {
107454                "id": "MIT"
107455              }
107456            }
107457          ],
107458          "cpe": "cpe:2.3:a:ms:ms:2.1.3:*:*:*:*:*:*:*",
107459          "purl": "pkg:npm/ms@2.1.3",
107460          "swid": {
107461            "attachment": {}
107462          },
107463          "pedigree": {},
107464          "externalReferences": [
107465            {
107466              "url": "vercel/ms",
107467              "type": "distribution"
107468            }
107469          ],
107470          "evidence": {},
107471          "signature": {
107472            "signature": {
107473              "publicKey": {}
107474            }
107475          },
107476          "modelCard": {
107477            "modelParameters": {
107478              "approach": {}
107479            },
107480            "quantitativeAnalysis": {
107481              "graphics": {}
107482            },
107483            "considerations": {}
107484          }
107485        },
107486        {
107487          "type": "library",
107488          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=24c6089b81ca7d19",
107489          "supplier": {},
107490          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
107491          "name": "musl",
107492          "version": "1.2.3-r2",
107493          "description": "the musl c library (libc) implementation",
107494          "licenses": [
107495            {
107496              "license": {
107497                "id": "MIT"
107498              }
107499            }
107500          ],
107501          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r2:*:*:*:*:*:*:*",
107502          "purl": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5",
107503          "swid": {
107504            "attachment": {}
107505          },
107506          "pedigree": {},
107507          "externalReferences": [
107508            {
107509              "url": "https://musl.libc.org/",
107510              "type": "distribution"
107511            }
107512          ],
107513          "evidence": {},
107514          "signature": {
107515            "signature": {
107516              "publicKey": {}
107517            }
107518          },
107519          "modelCard": {
107520            "modelParameters": {
107521              "approach": {}
107522            },
107523            "quantitativeAnalysis": {
107524              "graphics": {}
107525            },
107526            "considerations": {}
107527          }
107528        },
107529        {
107530          "type": "library",
107531          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5\u0026package-id=d33c14d727ae74d1",
107532          "supplier": {},
107533          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
107534          "name": "musl-utils",
107535          "version": "1.2.3-r2",
107536          "description": "the musl c library (libc) implementation",
107537          "licenses": [
107538            {
107539              "license": {
107540                "id": "MIT"
107541              }
107542            },
107543            {
107544              "license": {
107545                "name": "BSD"
107546              }
107547            },
107548            {
107549              "license": {
107550                "id": "GPL-2.0-or-later"
107551              }
107552            }
107553          ],
107554          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r2:*:*:*:*:*:*:*",
107555          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5",
107556          "swid": {
107557            "attachment": {}
107558          },
107559          "pedigree": {},
107560          "externalReferences": [
107561            {
107562              "url": "https://musl.libc.org/",
107563              "type": "distribution"
107564            }
107565          ],
107566          "evidence": {},
107567          "signature": {
107568            "signature": {
107569              "publicKey": {}
107570            }
107571          },
107572          "modelCard": {
107573            "modelParameters": {
107574              "approach": {}
107575            },
107576            "quantitativeAnalysis": {
107577              "graphics": {}
107578            },
107579            "considerations": {}
107580          }
107581        },
107582        {
107583          "type": "library",
107584          "bom-ref": "pkg:npm/mute-stream@0.0.8?package-id=b093eec725f75ac9",
107585          "supplier": {},
107586          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
107587          "name": "mute-stream",
107588          "version": "0.0.8",
107589          "description": "Bytes go in, but they don't come out (when muted).",
107590          "licenses": [
107591            {
107592              "license": {
107593                "id": "ISC"
107594              }
107595            }
107596          ],
107597          "cpe": "cpe:2.3:a:mute-stream:mute-stream:0.0.8:*:*:*:*:*:*:*",
107598          "purl": "pkg:npm/mute-stream@0.0.8",
107599          "swid": {
107600            "attachment": {}
107601          },
107602          "pedigree": {},
107603          "externalReferences": [
107604            {
107605              "url": "git://github.com/isaacs/mute-stream",
107606              "type": "distribution"
107607            }
107608          ],
107609          "evidence": {},
107610          "signature": {
107611            "signature": {
107612              "publicKey": {}
107613            }
107614          },
107615          "modelCard": {
107616            "modelParameters": {
107617              "approach": {}
107618            },
107619            "quantitativeAnalysis": {
107620              "graphics": {}
107621            },
107622            "considerations": {}
107623          }
107624        },
107625        {
107626          "type": "library",
107627          "bom-ref": "pkg:npm/mylib@0.0.0?package-id=9b8da0f44b3dbc2",
107628          "supplier": {},
107629          "name": "mylib",
107630          "version": "0.0.0",
107631          "licenses": [
107632            {
107633              "license": {
107634                "id": "ISC"
107635              }
107636            }
107637          ],
107638          "cpe": "cpe:2.3:a:mylib:mylib:0.0.0:*:*:*:*:*:*:*",
107639          "purl": "pkg:npm/mylib@0.0.0",
107640          "swid": {
107641            "attachment": {}
107642          },
107643          "pedigree": {},
107644          "evidence": {},
107645          "signature": {
107646            "signature": {
107647              "publicKey": {}
107648            }
107649          },
107650          "modelCard": {
107651            "modelParameters": {
107652              "approach": {}
107653            },
107654            "quantitativeAnalysis": {
107655              "graphics": {}
107656            },
107657            "considerations": {}
107658          }
107659        },
107660        {
107661          "type": "library",
107662          "bom-ref": "pkg:npm/negotiator@0.6.3?package-id=87cc6cb502ab228a",
107663          "supplier": {},
107664          "name": "negotiator",
107665          "version": "0.6.3",
107666          "description": "HTTP content negotiation",
107667          "licenses": [
107668            {
107669              "license": {
107670                "id": "MIT"
107671              }
107672            }
107673          ],
107674          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.3:*:*:*:*:*:*:*",
107675          "purl": "pkg:npm/negotiator@0.6.3",
107676          "swid": {
107677            "attachment": {}
107678          },
107679          "pedigree": {},
107680          "externalReferences": [
107681            {
107682              "url": "jshttp/negotiator",
107683              "type": "distribution"
107684            }
107685          ],
107686          "evidence": {},
107687          "signature": {
107688            "signature": {
107689              "publicKey": {}
107690            }
107691          },
107692          "modelCard": {
107693            "modelParameters": {
107694              "approach": {}
107695            },
107696            "quantitativeAnalysis": {
107697              "graphics": {}
107698            },
107699            "considerations": {}
107700          }
107701        },
107702        {
107703          "type": "library",
107704          "bom-ref": "pkg:npm/negotiator@0.6.3?package-id=9f94722cfe2aef45",
107705          "supplier": {},
107706          "name": "negotiator",
107707          "version": "0.6.3",
107708          "description": "HTTP content negotiation",
107709          "licenses": [
107710            {
107711              "license": {
107712                "id": "MIT"
107713              }
107714            }
107715          ],
107716          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.3:*:*:*:*:*:*:*",
107717          "purl": "pkg:npm/negotiator@0.6.3",
107718          "swid": {
107719            "attachment": {}
107720          },
107721          "pedigree": {},
107722          "externalReferences": [
107723            {
107724              "url": "jshttp/negotiator",
107725              "type": "distribution"
107726            }
107727          ],
107728          "evidence": {},
107729          "signature": {
107730            "signature": {
107731              "publicKey": {}
107732            }
107733          },
107734          "modelCard": {
107735            "modelParameters": {
107736              "approach": {}
107737            },
107738            "quantitativeAnalysis": {
107739              "graphics": {}
107740            },
107741            "considerations": {}
107742          }
107743        },
107744        {
107745          "type": "library",
107746          "bom-ref": "pkg:npm/nice-try@1.0.5?package-id=91cc5f7fcf4b2e5a",
107747          "supplier": {},
107748          "name": "nice-try",
107749          "version": "1.0.5",
107750          "description": "Tries to execute a function and discards any error that occurs",
107751          "licenses": [
107752            {
107753              "license": {
107754                "id": "MIT"
107755              }
107756            }
107757          ],
107758          "cpe": "cpe:2.3:a:electerious:nice-try:1.0.5:*:*:*:*:*:*:*",
107759          "purl": "pkg:npm/nice-try@1.0.5",
107760          "swid": {
107761            "attachment": {}
107762          },
107763          "pedigree": {},
107764          "externalReferences": [
107765            {
107766              "url": "https://github.com/electerious/nice-try.git",
107767              "type": "distribution"
107768            },
107769            {
107770              "url": "https://github.com/electerious/nice-try",
107771              "type": "website"
107772            }
107773          ],
107774          "evidence": {},
107775          "signature": {
107776            "signature": {
107777              "publicKey": {}
107778            }
107779          },
107780          "modelCard": {
107781            "modelParameters": {
107782              "approach": {}
107783            },
107784            "quantitativeAnalysis": {
107785              "graphics": {}
107786            },
107787            "considerations": {}
107788          }
107789        },
107790        {
107791          "type": "application",
107792          "bom-ref": "pkg:generic/node@16.20.0?package-id=c3df0c8aa56599a1",
107793          "supplier": {},
107794          "name": "node",
107795          "version": "16.20.0",
107796          "cpe": "cpe:2.3:a:nodejs:node.js:16.20.0:*:*:*:*:*:*:*",
107797          "purl": "pkg:generic/node@16.20.0",
107798          "swid": {
107799            "attachment": {}
107800          },
107801          "pedigree": {},
107802          "evidence": {},
107803          "signature": {
107804            "signature": {
107805              "publicKey": {}
107806            }
107807          },
107808          "modelCard": {
107809            "modelParameters": {
107810              "approach": {}
107811            },
107812            "quantitativeAnalysis": {
107813              "graphics": {}
107814            },
107815            "considerations": {}
107816          }
107817        },
107818        {
107819          "type": "library",
107820          "bom-ref": "pkg:npm/node-gyp@9.1.0?package-id=594531fb28fce181",
107821          "supplier": {},
107822          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://tootallnate.net)",
107823          "name": "node-gyp",
107824          "version": "9.1.0",
107825          "description": "Node.js native addon build tool",
107826          "licenses": [
107827            {
107828              "license": {
107829                "id": "MIT"
107830              }
107831            }
107832          ],
107833          "cpe": "cpe:2.3:a:node-gyp:node-gyp:9.1.0:*:*:*:*:*:*:*",
107834          "purl": "pkg:npm/node-gyp@9.1.0",
107835          "swid": {
107836            "attachment": {}
107837          },
107838          "pedigree": {},
107839          "externalReferences": [
107840            {
107841              "url": "git://github.com/nodejs/node-gyp.git",
107842              "type": "distribution"
107843            }
107844          ],
107845          "evidence": {},
107846          "signature": {
107847            "signature": {
107848              "publicKey": {}
107849            }
107850          },
107851          "modelCard": {
107852            "modelParameters": {
107853              "approach": {}
107854            },
107855            "quantitativeAnalysis": {
107856              "graphics": {}
107857            },
107858            "considerations": {}
107859          }
107860        },
107861        {
107862          "type": "library",
107863          "bom-ref": "pkg:npm/nopt@5.0.0?package-id=16f8d211f06e4fc1",
107864          "supplier": {},
107865          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
107866          "name": "nopt",
107867          "version": "5.0.0",
107868          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
107869          "licenses": [
107870            {
107871              "license": {
107872                "id": "ISC"
107873              }
107874            }
107875          ],
107876          "cpe": "cpe:2.3:a:nopt:nopt:5.0.0:*:*:*:*:*:*:*",
107877          "purl": "pkg:npm/nopt@5.0.0",
107878          "swid": {
107879            "attachment": {}
107880          },
107881          "pedigree": {},
107882          "externalReferences": [
107883            {
107884              "url": "https://github.com/npm/nopt.git",
107885              "type": "distribution"
107886            }
107887          ],
107888          "evidence": {},
107889          "signature": {
107890            "signature": {
107891              "publicKey": {}
107892            }
107893          },
107894          "modelCard": {
107895            "modelParameters": {
107896              "approach": {}
107897            },
107898            "quantitativeAnalysis": {
107899              "graphics": {}
107900            },
107901            "considerations": {}
107902          }
107903        },
107904        {
107905          "type": "library",
107906          "bom-ref": "pkg:npm/nopt@6.0.0?package-id=2da699f46c59247",
107907          "supplier": {},
107908          "author": "GitHub Inc.",
107909          "name": "nopt",
107910          "version": "6.0.0",
107911          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
107912          "licenses": [
107913            {
107914              "license": {
107915                "id": "ISC"
107916              }
107917            }
107918          ],
107919          "cpe": "cpe:2.3:a:nopt:nopt:6.0.0:*:*:*:*:*:*:*",
107920          "purl": "pkg:npm/nopt@6.0.0",
107921          "swid": {
107922            "attachment": {}
107923          },
107924          "pedigree": {},
107925          "externalReferences": [
107926            {
107927              "url": "https://github.com/npm/nopt.git",
107928              "type": "distribution"
107929            }
107930          ],
107931          "evidence": {},
107932          "signature": {
107933            "signature": {
107934              "publicKey": {}
107935            }
107936          },
107937          "modelCard": {
107938            "modelParameters": {
107939              "approach": {}
107940            },
107941            "quantitativeAnalysis": {
107942              "graphics": {}
107943            },
107944            "considerations": {}
107945          }
107946        },
107947        {
107948          "type": "library",
107949          "bom-ref": "pkg:npm/normalize-package-data@4.0.1?package-id=f65ac6113e729b71",
107950          "supplier": {},
107951          "author": "GitHub Inc.",
107952          "name": "normalize-package-data",
107953          "version": "4.0.1",
107954          "description": "Normalizes data that can be found in package.json files.",
107955          "licenses": [
107956            {
107957              "license": {
107958                "id": "BSD-2-Clause"
107959              }
107960            }
107961          ],
107962          "cpe": "cpe:2.3:a:normalize-package-data:normalize-package-data:4.0.1:*:*:*:*:*:*:*",
107963          "purl": "pkg:npm/normalize-package-data@4.0.1",
107964          "swid": {
107965            "attachment": {}
107966          },
107967          "pedigree": {},
107968          "externalReferences": [
107969            {
107970              "url": "https://github.com/npm/normalize-package-data.git",
107971              "type": "distribution"
107972            }
107973          ],
107974          "evidence": {},
107975          "signature": {
107976            "signature": {
107977              "publicKey": {}
107978            }
107979          },
107980          "modelCard": {
107981            "modelParameters": {
107982              "approach": {}
107983            },
107984            "quantitativeAnalysis": {
107985              "graphics": {}
107986            },
107987            "considerations": {}
107988          }
107989        },
107990        {
107991          "type": "library",
107992          "bom-ref": "pkg:npm/npm@8.19.4?package-id=3a7215c0f0fd939a",
107993          "supplier": {},
107994          "author": "GitHub Inc.",
107995          "name": "npm",
107996          "version": "8.19.4",
107997          "description": "a package manager for JavaScript",
107998          "licenses": [
107999            {
108000              "license": {
108001                "id": "Artistic-2.0"
108002              }
108003            }
108004          ],
108005          "cpe": "cpe:2.3:a:npm:npm:8.19.4:*:*:*:*:*:*:*",
108006          "purl": "pkg:npm/npm@8.19.4",
108007          "swid": {
108008            "attachment": {}
108009          },
108010          "pedigree": {},
108011          "externalReferences": [
108012            {
108013              "url": "https://github.com/npm/cli.git",
108014              "type": "distribution"
108015            },
108016            {
108017              "url": "https://docs.npmjs.com/",
108018              "type": "website"
108019            }
108020          ],
108021          "evidence": {},
108022          "signature": {
108023            "signature": {
108024              "publicKey": {}
108025            }
108026          },
108027          "modelCard": {
108028            "modelParameters": {
108029              "approach": {}
108030            },
108031            "quantitativeAnalysis": {
108032              "graphics": {}
108033            },
108034            "considerations": {}
108035          }
108036        },
108037        {
108038          "type": "library",
108039          "bom-ref": "pkg:npm/npm-audit-report@3.0.0?package-id=838d59a41103d415",
108040          "supplier": {},
108041          "author": "GitHub Inc.",
108042          "name": "npm-audit-report",
108043          "version": "3.0.0",
108044          "description": "Given a response from the npm security api, render it into a variety of security reports",
108045          "licenses": [
108046            {
108047              "license": {
108048                "id": "ISC"
108049              }
108050            }
108051          ],
108052          "cpe": "cpe:2.3:a:npm-audit-report:npm-audit-report:3.0.0:*:*:*:*:*:*:*",
108053          "purl": "pkg:npm/npm-audit-report@3.0.0",
108054          "swid": {
108055            "attachment": {}
108056          },
108057          "pedigree": {},
108058          "externalReferences": [
108059            {
108060              "url": "https://github.com/npm/npm-audit-report.git",
108061              "type": "distribution"
108062            },
108063            {
108064              "url": "https://github.com/npm/npm-audit-report#readme",
108065              "type": "website"
108066            }
108067          ],
108068          "evidence": {},
108069          "signature": {
108070            "signature": {
108071              "publicKey": {}
108072            }
108073          },
108074          "modelCard": {
108075            "modelParameters": {
108076              "approach": {}
108077            },
108078            "quantitativeAnalysis": {
108079              "graphics": {}
108080            },
108081            "considerations": {}
108082          }
108083        },
108084        {
108085          "type": "library",
108086          "bom-ref": "pkg:npm/npm-bundled@1.1.2?package-id=d3fc92546524f1a0",
108087          "supplier": {},
108088          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
108089          "name": "npm-bundled",
108090          "version": "1.1.2",
108091          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
108092          "licenses": [
108093            {
108094              "license": {
108095                "id": "ISC"
108096              }
108097            }
108098          ],
108099          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:1.1.2:*:*:*:*:*:*:*",
108100          "purl": "pkg:npm/npm-bundled@1.1.2",
108101          "swid": {
108102            "attachment": {}
108103          },
108104          "pedigree": {},
108105          "externalReferences": [
108106            {
108107              "url": "git+https://github.com/npm/npm-bundled.git",
108108              "type": "distribution"
108109            }
108110          ],
108111          "evidence": {},
108112          "signature": {
108113            "signature": {
108114              "publicKey": {}
108115            }
108116          },
108117          "modelCard": {
108118            "modelParameters": {
108119              "approach": {}
108120            },
108121            "quantitativeAnalysis": {
108122              "graphics": {}
108123            },
108124            "considerations": {}
108125          }
108126        },
108127        {
108128          "type": "library",
108129          "bom-ref": "pkg:npm/npm-bundled@2.0.1?package-id=4342e4ccfcb927ca",
108130          "supplier": {},
108131          "author": "GitHub Inc.",
108132          "name": "npm-bundled",
108133          "version": "2.0.1",
108134          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
108135          "licenses": [
108136            {
108137              "license": {
108138                "id": "ISC"
108139              }
108140            }
108141          ],
108142          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:2.0.1:*:*:*:*:*:*:*",
108143          "purl": "pkg:npm/npm-bundled@2.0.1",
108144          "swid": {
108145            "attachment": {}
108146          },
108147          "pedigree": {},
108148          "externalReferences": [
108149            {
108150              "url": "https://github.com/npm/npm-bundled.git",
108151              "type": "distribution"
108152            }
108153          ],
108154          "evidence": {},
108155          "signature": {
108156            "signature": {
108157              "publicKey": {}
108158            }
108159          },
108160          "modelCard": {
108161            "modelParameters": {
108162              "approach": {}
108163            },
108164            "quantitativeAnalysis": {
108165              "graphics": {}
108166            },
108167            "considerations": {}
108168          }
108169        },
108170        {
108171          "type": "library",
108172          "bom-ref": "pkg:npm/npm-init@0.0.0?package-id=e58118b5aaeeedd7",
108173          "supplier": {},
108174          "name": "npm-init",
108175          "version": "0.0.0",
108176          "description": "an initter you init wit, innit?",
108177          "licenses": [
108178            {
108179              "license": {
108180                "name": "BSD"
108181              }
108182            }
108183          ],
108184          "cpe": "cpe:2.3:a:npm-init:npm-init:0.0.0:*:*:*:*:*:*:*",
108185          "purl": "pkg:npm/npm-init@0.0.0",
108186          "swid": {
108187            "attachment": {}
108188          },
108189          "pedigree": {},
108190          "evidence": {},
108191          "signature": {
108192            "signature": {
108193              "publicKey": {}
108194            }
108195          },
108196          "modelCard": {
108197            "modelParameters": {
108198              "approach": {}
108199            },
108200            "quantitativeAnalysis": {
108201              "graphics": {}
108202            },
108203            "considerations": {}
108204          }
108205        },
108206        {
108207          "type": "library",
108208          "bom-ref": "pkg:npm/npm-install-checks@5.0.0?package-id=ea3011565b04383b",
108209          "supplier": {},
108210          "author": "GitHub Inc.",
108211          "name": "npm-install-checks",
108212          "version": "5.0.0",
108213          "description": "Check the engines and platform fields in package.json",
108214          "licenses": [
108215            {
108216              "license": {
108217                "id": "BSD-2-Clause"
108218              }
108219            }
108220          ],
108221          "cpe": "cpe:2.3:a:npm-install-checks:npm-install-checks:5.0.0:*:*:*:*:*:*:*",
108222          "purl": "pkg:npm/npm-install-checks@5.0.0",
108223          "swid": {
108224            "attachment": {}
108225          },
108226          "pedigree": {},
108227          "externalReferences": [
108228            {
108229              "url": "https://github.com/npm/npm-install-checks.git",
108230              "type": "distribution"
108231            }
108232          ],
108233          "evidence": {},
108234          "signature": {
108235            "signature": {
108236              "publicKey": {}
108237            }
108238          },
108239          "modelCard": {
108240            "modelParameters": {
108241              "approach": {}
108242            },
108243            "quantitativeAnalysis": {
108244              "graphics": {}
108245            },
108246            "considerations": {}
108247          }
108248        },
108249        {
108250          "type": "library",
108251          "bom-ref": "pkg:npm/npm-normalize-package-bin@1.0.1?package-id=7cccc2d8907ef9bb",
108252          "supplier": {},
108253          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
108254          "name": "npm-normalize-package-bin",
108255          "version": "1.0.1",
108256          "description": "Turn any flavor of allowable package.json bin into a normalized object",
108257          "licenses": [
108258            {
108259              "license": {
108260                "id": "ISC"
108261              }
108262            }
108263          ],
108264          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:1.0.1:*:*:*:*:*:*:*",
108265          "purl": "pkg:npm/npm-normalize-package-bin@1.0.1",
108266          "swid": {
108267            "attachment": {}
108268          },
108269          "pedigree": {},
108270          "externalReferences": [
108271            {
108272              "url": "git+https://github.com/npm/npm-normalize-package-bin",
108273              "type": "distribution"
108274            }
108275          ],
108276          "evidence": {},
108277          "signature": {
108278            "signature": {
108279              "publicKey": {}
108280            }
108281          },
108282          "modelCard": {
108283            "modelParameters": {
108284              "approach": {}
108285            },
108286            "quantitativeAnalysis": {
108287              "graphics": {}
108288            },
108289            "considerations": {}
108290          }
108291        },
108292        {
108293          "type": "library",
108294          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=3b502df6a54faf04",
108295          "supplier": {},
108296          "author": "GitHub Inc.",
108297          "name": "npm-normalize-package-bin",
108298          "version": "2.0.0",
108299          "description": "Turn any flavor of allowable package.json bin into a normalized object",
108300          "licenses": [
108301            {
108302              "license": {
108303                "id": "ISC"
108304              }
108305            }
108306          ],
108307          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
108308          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
108309          "swid": {
108310            "attachment": {}
108311          },
108312          "pedigree": {},
108313          "externalReferences": [
108314            {
108315              "url": "https://github.com/npm/npm-normalize-package-bin.git",
108316              "type": "distribution"
108317            }
108318          ],
108319          "evidence": {},
108320          "signature": {
108321            "signature": {
108322              "publicKey": {}
108323            }
108324          },
108325          "modelCard": {
108326            "modelParameters": {
108327              "approach": {}
108328            },
108329            "quantitativeAnalysis": {
108330              "graphics": {}
108331            },
108332            "considerations": {}
108333          }
108334        },
108335        {
108336          "type": "library",
108337          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=cb496c88bc54cdd7",
108338          "supplier": {},
108339          "author": "GitHub Inc.",
108340          "name": "npm-normalize-package-bin",
108341          "version": "2.0.0",
108342          "description": "Turn any flavor of allowable package.json bin into a normalized object",
108343          "licenses": [
108344            {
108345              "license": {
108346                "id": "ISC"
108347              }
108348            }
108349          ],
108350          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
108351          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
108352          "swid": {
108353            "attachment": {}
108354          },
108355          "pedigree": {},
108356          "externalReferences": [
108357            {
108358              "url": "https://github.com/npm/npm-normalize-package-bin.git",
108359              "type": "distribution"
108360            }
108361          ],
108362          "evidence": {},
108363          "signature": {
108364            "signature": {
108365              "publicKey": {}
108366            }
108367          },
108368          "modelCard": {
108369            "modelParameters": {
108370              "approach": {}
108371            },
108372            "quantitativeAnalysis": {
108373              "graphics": {}
108374            },
108375            "considerations": {}
108376          }
108377        },
108378        {
108379          "type": "library",
108380          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=3675dcedd841f8b6",
108381          "supplier": {},
108382          "author": "GitHub Inc.",
108383          "name": "npm-normalize-package-bin",
108384          "version": "2.0.0",
108385          "description": "Turn any flavor of allowable package.json bin into a normalized object",
108386          "licenses": [
108387            {
108388              "license": {
108389                "id": "ISC"
108390              }
108391            }
108392          ],
108393          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
108394          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
108395          "swid": {
108396            "attachment": {}
108397          },
108398          "pedigree": {},
108399          "externalReferences": [
108400            {
108401              "url": "https://github.com/npm/npm-normalize-package-bin.git",
108402              "type": "distribution"
108403            }
108404          ],
108405          "evidence": {},
108406          "signature": {
108407            "signature": {
108408              "publicKey": {}
108409            }
108410          },
108411          "modelCard": {
108412            "modelParameters": {
108413              "approach": {}
108414            },
108415            "quantitativeAnalysis": {
108416              "graphics": {}
108417            },
108418            "considerations": {}
108419          }
108420        },
108421        {
108422          "type": "library",
108423          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=a6c4eec149dbad2b",
108424          "supplier": {},
108425          "author": "GitHub Inc.",
108426          "name": "npm-normalize-package-bin",
108427          "version": "2.0.0",
108428          "description": "Turn any flavor of allowable package.json bin into a normalized object",
108429          "licenses": [
108430            {
108431              "license": {
108432                "id": "ISC"
108433              }
108434            }
108435          ],
108436          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
108437          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
108438          "swid": {
108439            "attachment": {}
108440          },
108441          "pedigree": {},
108442          "externalReferences": [
108443            {
108444              "url": "https://github.com/npm/npm-normalize-package-bin.git",
108445              "type": "distribution"
108446            }
108447          ],
108448          "evidence": {},
108449          "signature": {
108450            "signature": {
108451              "publicKey": {}
108452            }
108453          },
108454          "modelCard": {
108455            "modelParameters": {
108456              "approach": {}
108457            },
108458            "quantitativeAnalysis": {
108459              "graphics": {}
108460            },
108461            "considerations": {}
108462          }
108463        },
108464        {
108465          "type": "library",
108466          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=b373bbb7c439b789",
108467          "supplier": {},
108468          "author": "GitHub Inc.",
108469          "name": "npm-normalize-package-bin",
108470          "version": "2.0.0",
108471          "description": "Turn any flavor of allowable package.json bin into a normalized object",
108472          "licenses": [
108473            {
108474              "license": {
108475                "id": "ISC"
108476              }
108477            }
108478          ],
108479          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
108480          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
108481          "swid": {
108482            "attachment": {}
108483          },
108484          "pedigree": {},
108485          "externalReferences": [
108486            {
108487              "url": "https://github.com/npm/npm-normalize-package-bin.git",
108488              "type": "distribution"
108489            }
108490          ],
108491          "evidence": {},
108492          "signature": {
108493            "signature": {
108494              "publicKey": {}
108495            }
108496          },
108497          "modelCard": {
108498            "modelParameters": {
108499              "approach": {}
108500            },
108501            "quantitativeAnalysis": {
108502              "graphics": {}
108503            },
108504            "considerations": {}
108505          }
108506        },
108507        {
108508          "type": "library",
108509          "bom-ref": "pkg:npm/npm-package-arg@9.1.0?package-id=30ebe98710a08c64",
108510          "supplier": {},
108511          "author": "GitHub Inc.",
108512          "name": "npm-package-arg",
108513          "version": "9.1.0",
108514          "description": "Parse the things that can be arguments to `npm install`",
108515          "licenses": [
108516            {
108517              "license": {
108518                "id": "ISC"
108519              }
108520            }
108521          ],
108522          "cpe": "cpe:2.3:a:npm-package-arg:npm-package-arg:9.1.0:*:*:*:*:*:*:*",
108523          "purl": "pkg:npm/npm-package-arg@9.1.0",
108524          "swid": {
108525            "attachment": {}
108526          },
108527          "pedigree": {},
108528          "externalReferences": [
108529            {
108530              "url": "https://github.com/npm/npm-package-arg.git",
108531              "type": "distribution"
108532            },
108533            {
108534              "url": "https://github.com/npm/npm-package-arg",
108535              "type": "website"
108536            }
108537          ],
108538          "evidence": {},
108539          "signature": {
108540            "signature": {
108541              "publicKey": {}
108542            }
108543          },
108544          "modelCard": {
108545            "modelParameters": {
108546              "approach": {}
108547            },
108548            "quantitativeAnalysis": {
108549              "graphics": {}
108550            },
108551            "considerations": {}
108552          }
108553        },
108554        {
108555          "type": "library",
108556          "bom-ref": "pkg:npm/npm-packlist@5.1.3?package-id=e87ec46a213d7a87",
108557          "supplier": {},
108558          "author": "GitHub Inc.",
108559          "name": "npm-packlist",
108560          "version": "5.1.3",
108561          "description": "Get a list of the files to add from a folder into an npm package",
108562          "licenses": [
108563            {
108564              "license": {
108565                "id": "ISC"
108566              }
108567            }
108568          ],
108569          "cpe": "cpe:2.3:a:npm-packlist:npm-packlist:5.1.3:*:*:*:*:*:*:*",
108570          "purl": "pkg:npm/npm-packlist@5.1.3",
108571          "swid": {
108572            "attachment": {}
108573          },
108574          "pedigree": {},
108575          "externalReferences": [
108576            {
108577              "url": "https://github.com/npm/npm-packlist.git",
108578              "type": "distribution"
108579            }
108580          ],
108581          "evidence": {},
108582          "signature": {
108583            "signature": {
108584              "publicKey": {}
108585            }
108586          },
108587          "modelCard": {
108588            "modelParameters": {
108589              "approach": {}
108590            },
108591            "quantitativeAnalysis": {
108592              "graphics": {}
108593            },
108594            "considerations": {}
108595          }
108596        },
108597        {
108598          "type": "library",
108599          "bom-ref": "pkg:npm/npm-pick-manifest@7.0.2?package-id=a9dc194030f7ba31",
108600          "supplier": {},
108601          "author": "GitHub Inc.",
108602          "name": "npm-pick-manifest",
108603          "version": "7.0.2",
108604          "description": "Resolves a matching manifest from a package metadata document according to standard npm semver resolution rules.",
108605          "licenses": [
108606            {
108607              "license": {
108608                "id": "ISC"
108609              }
108610            }
108611          ],
108612          "cpe": "cpe:2.3:a:npm-pick-manifest:npm-pick-manifest:7.0.2:*:*:*:*:*:*:*",
108613          "purl": "pkg:npm/npm-pick-manifest@7.0.2",
108614          "swid": {
108615            "attachment": {}
108616          },
108617          "pedigree": {},
108618          "externalReferences": [
108619            {
108620              "url": "https://github.com/npm/npm-pick-manifest.git",
108621              "type": "distribution"
108622            }
108623          ],
108624          "evidence": {},
108625          "signature": {
108626            "signature": {
108627              "publicKey": {}
108628            }
108629          },
108630          "modelCard": {
108631            "modelParameters": {
108632              "approach": {}
108633            },
108634            "quantitativeAnalysis": {
108635              "graphics": {}
108636            },
108637            "considerations": {}
108638          }
108639        },
108640        {
108641          "type": "library",
108642          "bom-ref": "pkg:npm/npm-profile@6.2.1?package-id=4b7db9f7ec8bd8ec",
108643          "supplier": {},
108644          "author": "GitHub Inc.",
108645          "name": "npm-profile",
108646          "version": "6.2.1",
108647          "description": "Library for updating an npmjs.com profile",
108648          "licenses": [
108649            {
108650              "license": {
108651                "id": "ISC"
108652              }
108653            }
108654          ],
108655          "cpe": "cpe:2.3:a:npm-profile:npm-profile:6.2.1:*:*:*:*:*:*:*",
108656          "purl": "pkg:npm/npm-profile@6.2.1",
108657          "swid": {
108658            "attachment": {}
108659          },
108660          "pedigree": {},
108661          "externalReferences": [
108662            {
108663              "url": "https://github.com/npm/npm-profile.git",
108664              "type": "distribution"
108665            }
108666          ],
108667          "evidence": {},
108668          "signature": {
108669            "signature": {
108670              "publicKey": {}
108671            }
108672          },
108673          "modelCard": {
108674            "modelParameters": {
108675              "approach": {}
108676            },
108677            "quantitativeAnalysis": {
108678              "graphics": {}
108679            },
108680            "considerations": {}
108681          }
108682        },
108683        {
108684          "type": "library",
108685          "bom-ref": "pkg:npm/npm-registry-fetch@13.3.1?package-id=4a24a52ce2bed90",
108686          "supplier": {},
108687          "author": "GitHub Inc.",
108688          "name": "npm-registry-fetch",
108689          "version": "13.3.1",
108690          "description": "Fetch-based http client for use with npm registry APIs",
108691          "licenses": [
108692            {
108693              "license": {
108694                "id": "ISC"
108695              }
108696            }
108697          ],
108698          "cpe": "cpe:2.3:a:npm-registry-fetch:npm-registry-fetch:13.3.1:*:*:*:*:*:*:*",
108699          "purl": "pkg:npm/npm-registry-fetch@13.3.1",
108700          "swid": {
108701            "attachment": {}
108702          },
108703          "pedigree": {},
108704          "externalReferences": [
108705            {
108706              "url": "https://github.com/npm/npm-registry-fetch.git",
108707              "type": "distribution"
108708            }
108709          ],
108710          "evidence": {},
108711          "signature": {
108712            "signature": {
108713              "publicKey": {}
108714            }
108715          },
108716          "modelCard": {
108717            "modelParameters": {
108718              "approach": {}
108719            },
108720            "quantitativeAnalysis": {
108721              "graphics": {}
108722            },
108723            "considerations": {}
108724          }
108725        },
108726        {
108727          "type": "library",
108728          "bom-ref": "pkg:npm/npm-user-validate@1.0.1?package-id=6154858fa52c8fec",
108729          "supplier": {},
108730          "author": "Robert Kowalski \u003crok@kowalski.gd\u003e",
108731          "name": "npm-user-validate",
108732          "version": "1.0.1",
108733          "description": "User validations for npm",
108734          "licenses": [
108735            {
108736              "license": {
108737                "id": "BSD-2-Clause"
108738              }
108739            }
108740          ],
108741          "cpe": "cpe:2.3:a:npm-user-validate:npm-user-validate:1.0.1:*:*:*:*:*:*:*",
108742          "purl": "pkg:npm/npm-user-validate@1.0.1",
108743          "swid": {
108744            "attachment": {}
108745          },
108746          "pedigree": {},
108747          "externalReferences": [
108748            {
108749              "url": "git://github.com/npm/npm-user-validate.git",
108750              "type": "distribution"
108751            }
108752          ],
108753          "evidence": {},
108754          "signature": {
108755            "signature": {
108756              "publicKey": {}
108757            }
108758          },
108759          "modelCard": {
108760            "modelParameters": {
108761              "approach": {}
108762            },
108763            "quantitativeAnalysis": {
108764              "graphics": {}
108765            },
108766            "considerations": {}
108767          }
108768        },
108769        {
108770          "type": "library",
108771          "bom-ref": "pkg:npm/npmlog@6.0.2?package-id=e1d7f39551f111f",
108772          "supplier": {},
108773          "author": "GitHub Inc.",
108774          "name": "npmlog",
108775          "version": "6.0.2",
108776          "description": "logger for npm",
108777          "licenses": [
108778            {
108779              "license": {
108780                "id": "ISC"
108781              }
108782            }
108783          ],
108784          "cpe": "cpe:2.3:a:npmlog:npmlog:6.0.2:*:*:*:*:*:*:*",
108785          "purl": "pkg:npm/npmlog@6.0.2",
108786          "swid": {
108787            "attachment": {}
108788          },
108789          "pedigree": {},
108790          "externalReferences": [
108791            {
108792              "url": "https://github.com/npm/npmlog.git",
108793              "type": "distribution"
108794            }
108795          ],
108796          "evidence": {},
108797          "signature": {
108798            "signature": {
108799              "publicKey": {}
108800            }
108801          },
108802          "modelCard": {
108803            "modelParameters": {
108804              "approach": {}
108805            },
108806            "quantitativeAnalysis": {
108807              "graphics": {}
108808            },
108809            "considerations": {}
108810          }
108811        },
108812        {
108813          "type": "library",
108814          "bom-ref": "pkg:npm/on-finished@2.3.0?package-id=10e3e142a47fe504",
108815          "supplier": {},
108816          "name": "on-finished",
108817          "version": "2.3.0",
108818          "description": "Execute a callback when a request closes, finishes, or errors",
108819          "licenses": [
108820            {
108821              "license": {
108822                "id": "MIT"
108823              }
108824            }
108825          ],
108826          "cpe": "cpe:2.3:a:on-finished:on-finished:2.3.0:*:*:*:*:*:*:*",
108827          "purl": "pkg:npm/on-finished@2.3.0",
108828          "swid": {
108829            "attachment": {}
108830          },
108831          "pedigree": {},
108832          "externalReferences": [
108833            {
108834              "url": "jshttp/on-finished",
108835              "type": "distribution"
108836            }
108837          ],
108838          "evidence": {},
108839          "signature": {
108840            "signature": {
108841              "publicKey": {}
108842            }
108843          },
108844          "modelCard": {
108845            "modelParameters": {
108846              "approach": {}
108847            },
108848            "quantitativeAnalysis": {
108849              "graphics": {}
108850            },
108851            "considerations": {}
108852          }
108853        },
108854        {
108855          "type": "library",
108856          "bom-ref": "pkg:npm/on-headers@1.0.2?package-id=53ef10f5b722581e",
108857          "supplier": {},
108858          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
108859          "name": "on-headers",
108860          "version": "1.0.2",
108861          "description": "Execute a listener when a response is about to write headers",
108862          "licenses": [
108863            {
108864              "license": {
108865                "id": "MIT"
108866              }
108867            }
108868          ],
108869          "cpe": "cpe:2.3:a:on-headers:on-headers:1.0.2:*:*:*:*:*:*:*",
108870          "purl": "pkg:npm/on-headers@1.0.2",
108871          "swid": {
108872            "attachment": {}
108873          },
108874          "pedigree": {},
108875          "externalReferences": [
108876            {
108877              "url": "jshttp/on-headers",
108878              "type": "distribution"
108879            }
108880          ],
108881          "evidence": {},
108882          "signature": {
108883            "signature": {
108884              "publicKey": {}
108885            }
108886          },
108887          "modelCard": {
108888            "modelParameters": {
108889              "approach": {}
108890            },
108891            "quantitativeAnalysis": {
108892              "graphics": {}
108893            },
108894            "considerations": {}
108895          }
108896        },
108897        {
108898          "type": "library",
108899          "bom-ref": "pkg:npm/once@1.4.0?package-id=2bfb1efabaee8e52",
108900          "supplier": {},
108901          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
108902          "name": "once",
108903          "version": "1.4.0",
108904          "description": "Run a function exactly one time",
108905          "licenses": [
108906            {
108907              "license": {
108908                "id": "ISC"
108909              }
108910            }
108911          ],
108912          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
108913          "purl": "pkg:npm/once@1.4.0",
108914          "swid": {
108915            "attachment": {}
108916          },
108917          "pedigree": {},
108918          "externalReferences": [
108919            {
108920              "url": "git://github.com/isaacs/once",
108921              "type": "distribution"
108922            }
108923          ],
108924          "evidence": {},
108925          "signature": {
108926            "signature": {
108927              "publicKey": {}
108928            }
108929          },
108930          "modelCard": {
108931            "modelParameters": {
108932              "approach": {}
108933            },
108934            "quantitativeAnalysis": {
108935              "graphics": {}
108936            },
108937            "considerations": {}
108938          }
108939        },
108940        {
108941          "type": "library",
108942          "bom-ref": "pkg:npm/once@1.4.0?package-id=cb60b60d8364446d",
108943          "supplier": {},
108944          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
108945          "name": "once",
108946          "version": "1.4.0",
108947          "description": "Run a function exactly one time",
108948          "licenses": [
108949            {
108950              "license": {
108951                "id": "ISC"
108952              }
108953            }
108954          ],
108955          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
108956          "purl": "pkg:npm/once@1.4.0",
108957          "swid": {
108958            "attachment": {}
108959          },
108960          "pedigree": {},
108961          "externalReferences": [
108962            {
108963              "url": "git://github.com/isaacs/once",
108964              "type": "distribution"
108965            }
108966          ],
108967          "evidence": {},
108968          "signature": {
108969            "signature": {
108970              "publicKey": {}
108971            }
108972          },
108973          "modelCard": {
108974            "modelParameters": {
108975              "approach": {}
108976            },
108977            "quantitativeAnalysis": {
108978              "graphics": {}
108979            },
108980            "considerations": {}
108981          }
108982        },
108983        {
108984          "type": "library",
108985          "bom-ref": "pkg:npm/once@1.4.0?package-id=931b0bd981a31418",
108986          "supplier": {},
108987          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
108988          "name": "once",
108989          "version": "1.4.0",
108990          "description": "Run a function exactly one time",
108991          "licenses": [
108992            {
108993              "license": {
108994                "id": "ISC"
108995              }
108996            }
108997          ],
108998          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
108999          "purl": "pkg:npm/once@1.4.0",
109000          "swid": {
109001            "attachment": {}
109002          },
109003          "pedigree": {},
109004          "externalReferences": [
109005            {
109006              "url": "git://github.com/isaacs/once",
109007              "type": "distribution"
109008            }
109009          ],
109010          "evidence": {},
109011          "signature": {
109012            "signature": {
109013              "publicKey": {}
109014            }
109015          },
109016          "modelCard": {
109017            "modelParameters": {
109018              "approach": {}
109019            },
109020            "quantitativeAnalysis": {
109021              "graphics": {}
109022            },
109023            "considerations": {}
109024          }
109025        },
109026        {
109027          "type": "library",
109028          "bom-ref": "pkg:npm/open@7.4.2?package-id=cac9c84b55c0ecbc",
109029          "supplier": {},
109030          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
109031          "name": "open",
109032          "version": "7.4.2",
109033          "description": "Open stuff like URLs, files, executables. Cross-platform.",
109034          "licenses": [
109035            {
109036              "license": {
109037                "id": "MIT"
109038              }
109039            }
109040          ],
109041          "cpe": "cpe:2.3:a:open:open:7.4.2:*:*:*:*:*:*:*",
109042          "purl": "pkg:npm/open@7.4.2",
109043          "swid": {
109044            "attachment": {}
109045          },
109046          "pedigree": {},
109047          "externalReferences": [
109048            {
109049              "url": "sindresorhus/open",
109050              "type": "distribution"
109051            }
109052          ],
109053          "evidence": {},
109054          "signature": {
109055            "signature": {
109056              "publicKey": {}
109057            }
109058          },
109059          "modelCard": {
109060            "modelParameters": {
109061              "approach": {}
109062            },
109063            "quantitativeAnalysis": {
109064              "graphics": {}
109065            },
109066            "considerations": {}
109067          }
109068        },
109069        {
109070          "type": "library",
109071          "bom-ref": "pkg:npm/opener@1.5.2?package-id=44a3614f9f359ab5",
109072          "supplier": {},
109073          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me/)",
109074          "name": "opener",
109075          "version": "1.5.2",
109076          "description": "Opens stuff, like webpages and files and executables, cross-platform",
109077          "licenses": [
109078            {
109079              "license": {
109080                "name": "(WTFPL OR MIT)"
109081              }
109082            }
109083          ],
109084          "cpe": "cpe:2.3:a:opener:opener:1.5.2:*:*:*:*:*:*:*",
109085          "purl": "pkg:npm/opener@1.5.2",
109086          "swid": {
109087            "attachment": {}
109088          },
109089          "pedigree": {},
109090          "externalReferences": [
109091            {
109092              "url": "domenic/opener",
109093              "type": "distribution"
109094            }
109095          ],
109096          "evidence": {},
109097          "signature": {
109098            "signature": {
109099              "publicKey": {}
109100            }
109101          },
109102          "modelCard": {
109103            "modelParameters": {
109104              "approach": {}
109105            },
109106            "quantitativeAnalysis": {
109107              "graphics": {}
109108            },
109109            "considerations": {}
109110          }
109111        },
109112        {
109113          "type": "library",
109114          "bom-ref": "pkg:npm/os-tmpdir@1.0.2?package-id=b7a6f5a292a474b9",
109115          "supplier": {},
109116          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
109117          "name": "os-tmpdir",
109118          "version": "1.0.2",
109119          "description": "Node.js os.tmpdir() ponyfill",
109120          "licenses": [
109121            {
109122              "license": {
109123                "id": "MIT"
109124              }
109125            }
109126          ],
109127          "cpe": "cpe:2.3:a:os-tmpdir:os-tmpdir:1.0.2:*:*:*:*:*:*:*",
109128          "purl": "pkg:npm/os-tmpdir@1.0.2",
109129          "swid": {
109130            "attachment": {}
109131          },
109132          "pedigree": {},
109133          "externalReferences": [
109134            {
109135              "url": "sindresorhus/os-tmpdir",
109136              "type": "distribution"
109137            }
109138          ],
109139          "evidence": {},
109140          "signature": {
109141            "signature": {
109142              "publicKey": {}
109143            }
109144          },
109145          "modelCard": {
109146            "modelParameters": {
109147              "approach": {}
109148            },
109149            "quantitativeAnalysis": {
109150              "graphics": {}
109151            },
109152            "considerations": {}
109153          }
109154        },
109155        {
109156          "type": "library",
109157          "bom-ref": "pkg:npm/p-map@4.0.0?package-id=1c07a8cbe4bd91d5",
109158          "supplier": {},
109159          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
109160          "name": "p-map",
109161          "version": "4.0.0",
109162          "description": "Map over promises concurrently",
109163          "licenses": [
109164            {
109165              "license": {
109166                "id": "MIT"
109167              }
109168            }
109169          ],
109170          "cpe": "cpe:2.3:a:p-map:p-map:4.0.0:*:*:*:*:*:*:*",
109171          "purl": "pkg:npm/p-map@4.0.0",
109172          "swid": {
109173            "attachment": {}
109174          },
109175          "pedigree": {},
109176          "externalReferences": [
109177            {
109178              "url": "sindresorhus/p-map",
109179              "type": "distribution"
109180            }
109181          ],
109182          "evidence": {},
109183          "signature": {
109184            "signature": {
109185              "publicKey": {}
109186            }
109187          },
109188          "modelCard": {
109189            "modelParameters": {
109190              "approach": {}
109191            },
109192            "quantitativeAnalysis": {
109193              "graphics": {}
109194            },
109195            "considerations": {}
109196          }
109197        },
109198        {
109199          "type": "library",
109200          "bom-ref": "pkg:npm/pacote@13.6.2?package-id=481670a57d8719a5",
109201          "supplier": {},
109202          "author": "GitHub Inc.",
109203          "name": "pacote",
109204          "version": "13.6.2",
109205          "description": "JavaScript package downloader",
109206          "licenses": [
109207            {
109208              "license": {
109209                "id": "ISC"
109210              }
109211            }
109212          ],
109213          "cpe": "cpe:2.3:a:pacote:pacote:13.6.2:*:*:*:*:*:*:*",
109214          "purl": "pkg:npm/pacote@13.6.2",
109215          "swid": {
109216            "attachment": {}
109217          },
109218          "pedigree": {},
109219          "externalReferences": [
109220            {
109221              "url": "https://github.com/npm/pacote.git",
109222              "type": "distribution"
109223            }
109224          ],
109225          "evidence": {},
109226          "signature": {
109227            "signature": {
109228              "publicKey": {}
109229            }
109230          },
109231          "modelCard": {
109232            "modelParameters": {
109233              "approach": {}
109234            },
109235            "quantitativeAnalysis": {
109236              "graphics": {}
109237            },
109238            "considerations": {}
109239          }
109240        },
109241        {
109242          "type": "library",
109243          "bom-ref": "pkg:npm/parse-asn1@5.1.6?package-id=5ce85831fd167d7",
109244          "supplier": {},
109245          "name": "parse-asn1",
109246          "version": "5.1.6",
109247          "description": "utility library for parsing asn1 files for use with browserify-sign.",
109248          "licenses": [
109249            {
109250              "license": {
109251                "id": "ISC"
109252              }
109253            }
109254          ],
109255          "cpe": "cpe:2.3:a:crypto-browserify:parse-asn1:5.1.6:*:*:*:*:*:*:*",
109256          "purl": "pkg:npm/parse-asn1@5.1.6",
109257          "swid": {
109258            "attachment": {}
109259          },
109260          "pedigree": {},
109261          "externalReferences": [
109262            {
109263              "url": "git://github.com/crypto-browserify/parse-asn1.git",
109264              "type": "distribution"
109265            }
109266          ],
109267          "evidence": {},
109268          "signature": {
109269            "signature": {
109270              "publicKey": {}
109271            }
109272          },
109273          "modelCard": {
109274            "modelParameters": {
109275              "approach": {}
109276            },
109277            "quantitativeAnalysis": {
109278              "graphics": {}
109279            },
109280            "considerations": {}
109281          }
109282        },
109283        {
109284          "type": "library",
109285          "bom-ref": "pkg:npm/parse-conflict-json@2.0.2?package-id=94638d4f43f17ad7",
109286          "supplier": {},
109287          "author": "GitHub Inc.",
109288          "name": "parse-conflict-json",
109289          "version": "2.0.2",
109290          "description": "Parse a JSON string that has git merge conflicts, resolving if possible",
109291          "licenses": [
109292            {
109293              "license": {
109294                "id": "ISC"
109295              }
109296            }
109297          ],
109298          "cpe": "cpe:2.3:a:parse-conflict-json:parse-conflict-json:2.0.2:*:*:*:*:*:*:*",
109299          "purl": "pkg:npm/parse-conflict-json@2.0.2",
109300          "swid": {
109301            "attachment": {}
109302          },
109303          "pedigree": {},
109304          "externalReferences": [
109305            {
109306              "url": "https://github.com/npm/parse-conflict-json.git",
109307              "type": "distribution"
109308            }
109309          ],
109310          "evidence": {},
109311          "signature": {
109312            "signature": {
109313              "publicKey": {}
109314            }
109315          },
109316          "modelCard": {
109317            "modelParameters": {
109318              "approach": {}
109319            },
109320            "quantitativeAnalysis": {
109321              "graphics": {}
109322            },
109323            "considerations": {}
109324          }
109325        },
109326        {
109327          "type": "library",
109328          "bom-ref": "pkg:npm/parseurl@1.3.3?package-id=5a8f19386b323f4b",
109329          "supplier": {},
109330          "name": "parseurl",
109331          "version": "1.3.3",
109332          "description": "parse a url with memoization",
109333          "licenses": [
109334            {
109335              "license": {
109336                "id": "MIT"
109337              }
109338            }
109339          ],
109340          "cpe": "cpe:2.3:a:parseurl:parseurl:1.3.3:*:*:*:*:*:*:*",
109341          "purl": "pkg:npm/parseurl@1.3.3",
109342          "swid": {
109343            "attachment": {}
109344          },
109345          "pedigree": {},
109346          "externalReferences": [
109347            {
109348              "url": "pillarjs/parseurl",
109349              "type": "distribution"
109350            }
109351          ],
109352          "evidence": {},
109353          "signature": {
109354            "signature": {
109355              "publicKey": {}
109356            }
109357          },
109358          "modelCard": {
109359            "modelParameters": {
109360              "approach": {}
109361            },
109362            "quantitativeAnalysis": {
109363              "graphics": {}
109364            },
109365            "considerations": {}
109366          }
109367        },
109368        {
109369          "type": "library",
109370          "bom-ref": "pkg:npm/patch-package@6.5.1?package-id=a613cee4f6b8f328",
109371          "supplier": {},
109372          "author": "David Sheldrick",
109373          "name": "patch-package",
109374          "version": "6.5.1",
109375          "description": "Fix broken node modules with no fuss",
109376          "licenses": [
109377            {
109378              "license": {
109379                "id": "MIT"
109380              }
109381            }
109382          ],
109383          "cpe": "cpe:2.3:a:patch-package:patch-package:6.5.1:*:*:*:*:*:*:*",
109384          "purl": "pkg:npm/patch-package@6.5.1",
109385          "swid": {
109386            "attachment": {}
109387          },
109388          "pedigree": {},
109389          "externalReferences": [
109390            {
109391              "url": "github:ds300/patch-package",
109392              "type": "distribution"
109393            }
109394          ],
109395          "evidence": {},
109396          "signature": {
109397            "signature": {
109398              "publicKey": {}
109399            }
109400          },
109401          "modelCard": {
109402            "modelParameters": {
109403              "approach": {}
109404            },
109405            "quantitativeAnalysis": {
109406              "graphics": {}
109407            },
109408            "considerations": {}
109409          }
109410        },
109411        {
109412          "type": "library",
109413          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=ed58648f2f773bd9",
109414          "supplier": {},
109415          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
109416          "name": "path-is-absolute",
109417          "version": "1.0.1",
109418          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
109419          "licenses": [
109420            {
109421              "license": {
109422                "id": "MIT"
109423              }
109424            }
109425          ],
109426          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
109427          "purl": "pkg:npm/path-is-absolute@1.0.1",
109428          "swid": {
109429            "attachment": {}
109430          },
109431          "pedigree": {},
109432          "externalReferences": [
109433            {
109434              "url": "sindresorhus/path-is-absolute",
109435              "type": "distribution"
109436            }
109437          ],
109438          "evidence": {},
109439          "signature": {
109440            "signature": {
109441              "publicKey": {}
109442            }
109443          },
109444          "modelCard": {
109445            "modelParameters": {
109446              "approach": {}
109447            },
109448            "quantitativeAnalysis": {
109449              "graphics": {}
109450            },
109451            "considerations": {}
109452          }
109453        },
109454        {
109455          "type": "library",
109456          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=b1cc9415e263e4c1",
109457          "supplier": {},
109458          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
109459          "name": "path-is-absolute",
109460          "version": "1.0.1",
109461          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
109462          "licenses": [
109463            {
109464              "license": {
109465                "id": "MIT"
109466              }
109467            }
109468          ],
109469          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
109470          "purl": "pkg:npm/path-is-absolute@1.0.1",
109471          "swid": {
109472            "attachment": {}
109473          },
109474          "pedigree": {},
109475          "externalReferences": [
109476            {
109477              "url": "sindresorhus/path-is-absolute",
109478              "type": "distribution"
109479            }
109480          ],
109481          "evidence": {},
109482          "signature": {
109483            "signature": {
109484              "publicKey": {}
109485            }
109486          },
109487          "modelCard": {
109488            "modelParameters": {
109489              "approach": {}
109490            },
109491            "quantitativeAnalysis": {
109492              "graphics": {}
109493            },
109494            "considerations": {}
109495          }
109496        },
109497        {
109498          "type": "library",
109499          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=70cf293874d995a2",
109500          "supplier": {},
109501          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
109502          "name": "path-is-absolute",
109503          "version": "1.0.1",
109504          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
109505          "licenses": [
109506            {
109507              "license": {
109508                "id": "MIT"
109509              }
109510            }
109511          ],
109512          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
109513          "purl": "pkg:npm/path-is-absolute@1.0.1",
109514          "swid": {
109515            "attachment": {}
109516          },
109517          "pedigree": {},
109518          "externalReferences": [
109519            {
109520              "url": "sindresorhus/path-is-absolute",
109521              "type": "distribution"
109522            }
109523          ],
109524          "evidence": {},
109525          "signature": {
109526            "signature": {
109527              "publicKey": {}
109528            }
109529          },
109530          "modelCard": {
109531            "modelParameters": {
109532              "approach": {}
109533            },
109534            "quantitativeAnalysis": {
109535              "graphics": {}
109536            },
109537            "considerations": {}
109538          }
109539        },
109540        {
109541          "type": "library",
109542          "bom-ref": "pkg:npm/path-key@2.0.1?package-id=e01a57d830c83983",
109543          "supplier": {},
109544          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
109545          "name": "path-key",
109546          "version": "2.0.1",
109547          "description": "Get the PATH environment variable key cross-platform",
109548          "licenses": [
109549            {
109550              "license": {
109551                "id": "MIT"
109552              }
109553            }
109554          ],
109555          "cpe": "cpe:2.3:a:path-key:path-key:2.0.1:*:*:*:*:*:*:*",
109556          "purl": "pkg:npm/path-key@2.0.1",
109557          "swid": {
109558            "attachment": {}
109559          },
109560          "pedigree": {},
109561          "externalReferences": [
109562            {
109563              "url": "sindresorhus/path-key",
109564              "type": "distribution"
109565            }
109566          ],
109567          "evidence": {},
109568          "signature": {
109569            "signature": {
109570              "publicKey": {}
109571            }
109572          },
109573          "modelCard": {
109574            "modelParameters": {
109575              "approach": {}
109576            },
109577            "quantitativeAnalysis": {
109578              "graphics": {}
109579            },
109580            "considerations": {}
109581          }
109582        },
109583        {
109584          "type": "library",
109585          "bom-ref": "pkg:npm/path-parse@1.0.7?package-id=a9f85aa88ec56175",
109586          "supplier": {},
109587          "author": "Javier Blanco \u003chttp://jbgutierrez.info\u003e",
109588          "name": "path-parse",
109589          "version": "1.0.7",
109590          "description": "Node.js path.parse() ponyfill",
109591          "licenses": [
109592            {
109593              "license": {
109594                "id": "MIT"
109595              }
109596            }
109597          ],
109598          "cpe": "cpe:2.3:a:jbgutierrez:path-parse:1.0.7:*:*:*:*:*:*:*",
109599          "purl": "pkg:npm/path-parse@1.0.7",
109600          "swid": {
109601            "attachment": {}
109602          },
109603          "pedigree": {},
109604          "externalReferences": [
109605            {
109606              "url": "https://github.com/jbgutierrez/path-parse.git",
109607              "type": "distribution"
109608            },
109609            {
109610              "url": "https://github.com/jbgutierrez/path-parse#readme",
109611              "type": "website"
109612            }
109613          ],
109614          "evidence": {},
109615          "signature": {
109616            "signature": {
109617              "publicKey": {}
109618            }
109619          },
109620          "modelCard": {
109621            "modelParameters": {
109622              "approach": {}
109623            },
109624            "quantitativeAnalysis": {
109625              "graphics": {}
109626            },
109627            "considerations": {}
109628          }
109629        },
109630        {
109631          "type": "library",
109632          "bom-ref": "pkg:npm/path-to-regexp@0.1.7?package-id=ccbe7b36b309edc1",
109633          "supplier": {},
109634          "name": "path-to-regexp",
109635          "version": "0.1.7",
109636          "description": "Express style path to RegExp utility",
109637          "licenses": [
109638            {
109639              "license": {
109640                "id": "MIT"
109641              }
109642            }
109643          ],
109644          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:0.1.7:*:*:*:*:*:*:*",
109645          "purl": "pkg:npm/path-to-regexp@0.1.7",
109646          "swid": {
109647            "attachment": {}
109648          },
109649          "pedigree": {},
109650          "externalReferences": [
109651            {
109652              "url": "https://github.com/component/path-to-regexp.git",
109653              "type": "distribution"
109654            }
109655          ],
109656          "evidence": {},
109657          "signature": {
109658            "signature": {
109659              "publicKey": {}
109660            }
109661          },
109662          "modelCard": {
109663            "modelParameters": {
109664              "approach": {}
109665            },
109666            "quantitativeAnalysis": {
109667              "graphics": {}
109668            },
109669            "considerations": {}
109670          }
109671        },
109672        {
109673          "type": "library",
109674          "bom-ref": "pkg:npm/pbkdf2@3.1.2?package-id=dd947b9d9f9422f1",
109675          "supplier": {},
109676          "author": "Daniel Cousens",
109677          "name": "pbkdf2",
109678          "version": "3.1.2",
109679          "description": "This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()",
109680          "licenses": [
109681            {
109682              "license": {
109683                "id": "MIT"
109684              }
109685            }
109686          ],
109687          "cpe": "cpe:2.3:a:crypto-browserify:pbkdf2:3.1.2:*:*:*:*:*:*:*",
109688          "purl": "pkg:npm/pbkdf2@3.1.2",
109689          "swid": {
109690            "attachment": {}
109691          },
109692          "pedigree": {},
109693          "externalReferences": [
109694            {
109695              "url": "https://github.com/crypto-browserify/pbkdf2.git",
109696              "type": "distribution"
109697            },
109698            {
109699              "url": "https://github.com/crypto-browserify/pbkdf2",
109700              "type": "website"
109701            }
109702          ],
109703          "evidence": {},
109704          "signature": {
109705            "signature": {
109706              "publicKey": {}
109707            }
109708          },
109709          "modelCard": {
109710            "modelParameters": {
109711              "approach": {}
109712            },
109713            "quantitativeAnalysis": {
109714              "graphics": {}
109715            },
109716            "considerations": {}
109717          }
109718        },
109719        {
109720          "type": "library",
109721          "bom-ref": "pkg:npm/picomatch@2.3.1?package-id=1fd35f4a1fffa2f7",
109722          "supplier": {},
109723          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
109724          "name": "picomatch",
109725          "version": "2.3.1",
109726          "description": "Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.",
109727          "licenses": [
109728            {
109729              "license": {
109730                "id": "MIT"
109731              }
109732            }
109733          ],
109734          "cpe": "cpe:2.3:a:micromatch:picomatch:2.3.1:*:*:*:*:*:*:*",
109735          "purl": "pkg:npm/picomatch@2.3.1",
109736          "swid": {
109737            "attachment": {}
109738          },
109739          "pedigree": {},
109740          "externalReferences": [
109741            {
109742              "url": "micromatch/picomatch",
109743              "type": "distribution"
109744            },
109745            {
109746              "url": "https://github.com/micromatch/picomatch",
109747              "type": "website"
109748            }
109749          ],
109750          "evidence": {},
109751          "signature": {
109752            "signature": {
109753              "publicKey": {}
109754            }
109755          },
109756          "modelCard": {
109757            "modelParameters": {
109758              "approach": {}
109759            },
109760            "quantitativeAnalysis": {
109761              "graphics": {}
109762            },
109763            "considerations": {}
109764          }
109765        },
109766        {
109767          "type": "library",
109768          "bom-ref": "pkg:npm/pliant-worker-nodejs-config@0.0.0?package-id=8b53ecded2554ed0",
109769          "supplier": {},
109770          "name": "pliant-worker-nodejs-config",
109771          "version": "0.0.0",
109772          "cpe": "cpe:2.3:a:pliant-worker-nodejs-config:pliant-worker-nodejs-config:0.0.0:*:*:*:*:*:*:*",
109773          "purl": "pkg:npm/pliant-worker-nodejs-config@0.0.0",
109774          "swid": {
109775            "attachment": {}
109776          },
109777          "pedigree": {},
109778          "evidence": {},
109779          "signature": {
109780            "signature": {
109781              "publicKey": {}
109782            }
109783          },
109784          "modelCard": {
109785            "modelParameters": {
109786              "approach": {}
109787            },
109788            "quantitativeAnalysis": {
109789              "graphics": {}
109790            },
109791            "considerations": {}
109792          }
109793        },
109794        {
109795          "type": "library",
109796          "bom-ref": "pkg:npm/postcss-selector-parser@6.0.10?package-id=29dd6871004e9325",
109797          "supplier": {},
109798          "name": "postcss-selector-parser",
109799          "version": "6.0.10",
109800          "licenses": [
109801            {
109802              "license": {
109803                "id": "MIT"
109804              }
109805            }
109806          ],
109807          "cpe": "cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:6.0.10:*:*:*:*:*:*:*",
109808          "purl": "pkg:npm/postcss-selector-parser@6.0.10",
109809          "swid": {
109810            "attachment": {}
109811          },
109812          "pedigree": {},
109813          "externalReferences": [
109814            {
109815              "url": "postcss/postcss-selector-parser",
109816              "type": "distribution"
109817            },
109818            {
109819              "url": "https://github.com/postcss/postcss-selector-parser",
109820              "type": "website"
109821            }
109822          ],
109823          "evidence": {},
109824          "signature": {
109825            "signature": {
109826              "publicKey": {}
109827            }
109828          },
109829          "modelCard": {
109830            "modelParameters": {
109831              "approach": {}
109832            },
109833            "quantitativeAnalysis": {
109834              "graphics": {}
109835            },
109836            "considerations": {}
109837          }
109838        },
109839        {
109840          "type": "library",
109841          "bom-ref": "pkg:npm/proc-log@2.0.1?package-id=a4591425ab5edc60",
109842          "supplier": {},
109843          "author": "GitHub Inc.",
109844          "name": "proc-log",
109845          "version": "2.0.1",
109846          "description": "just emit 'log' events on the process object",
109847          "licenses": [
109848            {
109849              "license": {
109850                "id": "ISC"
109851              }
109852            }
109853          ],
109854          "cpe": "cpe:2.3:a:proc-log:proc-log:2.0.1:*:*:*:*:*:*:*",
109855          "purl": "pkg:npm/proc-log@2.0.1",
109856          "swid": {
109857            "attachment": {}
109858          },
109859          "pedigree": {},
109860          "externalReferences": [
109861            {
109862              "url": "https://github.com/npm/proc-log.git",
109863              "type": "distribution"
109864            }
109865          ],
109866          "evidence": {},
109867          "signature": {
109868            "signature": {
109869              "publicKey": {}
109870            }
109871          },
109872          "modelCard": {
109873            "modelParameters": {
109874              "approach": {}
109875            },
109876            "quantitativeAnalysis": {
109877              "graphics": {}
109878            },
109879            "considerations": {}
109880          }
109881        },
109882        {
109883          "type": "library",
109884          "bom-ref": "pkg:npm/promise-all-reject-late@1.0.1?package-id=7b92ff8460614d4f",
109885          "supplier": {},
109886          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
109887          "name": "promise-all-reject-late",
109888          "version": "1.0.1",
109889          "description": "Like Promise.all, but save rejections until all promises are resolved",
109890          "licenses": [
109891            {
109892              "license": {
109893                "id": "ISC"
109894              }
109895            }
109896          ],
109897          "cpe": "cpe:2.3:a:promise-all-reject-late:promise-all-reject-late:1.0.1:*:*:*:*:*:*:*",
109898          "purl": "pkg:npm/promise-all-reject-late@1.0.1",
109899          "swid": {
109900            "attachment": {}
109901          },
109902          "pedigree": {},
109903          "evidence": {},
109904          "signature": {
109905            "signature": {
109906              "publicKey": {}
109907            }
109908          },
109909          "modelCard": {
109910            "modelParameters": {
109911              "approach": {}
109912            },
109913            "quantitativeAnalysis": {
109914              "graphics": {}
109915            },
109916            "considerations": {}
109917          }
109918        },
109919        {
109920          "type": "library",
109921          "bom-ref": "pkg:npm/promise-call-limit@1.0.1?package-id=2b0b41bd7b0aa502",
109922          "supplier": {},
109923          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
109924          "name": "promise-call-limit",
109925          "version": "1.0.1",
109926          "description": "Call an array of promise-returning functions, restricting concurrency to a specified limit.",
109927          "licenses": [
109928            {
109929              "license": {
109930                "id": "ISC"
109931              }
109932            }
109933          ],
109934          "cpe": "cpe:2.3:a:promise-call-limit:promise-call-limit:1.0.1:*:*:*:*:*:*:*",
109935          "purl": "pkg:npm/promise-call-limit@1.0.1",
109936          "swid": {
109937            "attachment": {}
109938          },
109939          "pedigree": {},
109940          "externalReferences": [
109941            {
109942              "url": "git+https://github.com/isaacs/promise-call-limit",
109943              "type": "distribution"
109944            }
109945          ],
109946          "evidence": {},
109947          "signature": {
109948            "signature": {
109949              "publicKey": {}
109950            }
109951          },
109952          "modelCard": {
109953            "modelParameters": {
109954              "approach": {}
109955            },
109956            "quantitativeAnalysis": {
109957              "graphics": {}
109958            },
109959            "considerations": {}
109960          }
109961        },
109962        {
109963          "type": "library",
109964          "bom-ref": "pkg:npm/promise-inflight@1.0.1?package-id=8ae6caef1e6290fe",
109965          "supplier": {},
109966          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
109967          "name": "promise-inflight",
109968          "version": "1.0.1",
109969          "description": "One promise for multiple requests in flight to avoid async duplication",
109970          "licenses": [
109971            {
109972              "license": {
109973                "id": "ISC"
109974              }
109975            }
109976          ],
109977          "cpe": "cpe:2.3:a:promise-inflight:promise-inflight:1.0.1:*:*:*:*:*:*:*",
109978          "purl": "pkg:npm/promise-inflight@1.0.1",
109979          "swid": {
109980            "attachment": {}
109981          },
109982          "pedigree": {},
109983          "externalReferences": [
109984            {
109985              "url": "git+https://github.com/iarna/promise-inflight.git",
109986              "type": "distribution"
109987            },
109988            {
109989              "url": "https://github.com/iarna/promise-inflight#readme",
109990              "type": "website"
109991            }
109992          ],
109993          "evidence": {},
109994          "signature": {
109995            "signature": {
109996              "publicKey": {}
109997            }
109998          },
109999          "modelCard": {
110000            "modelParameters": {
110001              "approach": {}
110002            },
110003            "quantitativeAnalysis": {
110004              "graphics": {}
110005            },
110006            "considerations": {}
110007          }
110008        },
110009        {
110010          "type": "library",
110011          "bom-ref": "pkg:npm/promise-retry@2.0.1?package-id=7d483cd4a8ed637e",
110012          "supplier": {},
110013          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
110014          "name": "promise-retry",
110015          "version": "2.0.1",
110016          "description": "Retries a function that returns a promise, leveraging the power of the retry module.",
110017          "licenses": [
110018            {
110019              "license": {
110020                "id": "MIT"
110021              }
110022            }
110023          ],
110024          "cpe": "cpe:2.3:a:promise-retry:promise-retry:2.0.1:*:*:*:*:*:*:*",
110025          "purl": "pkg:npm/promise-retry@2.0.1",
110026          "swid": {
110027            "attachment": {}
110028          },
110029          "pedigree": {},
110030          "externalReferences": [
110031            {
110032              "url": "git://github.com/IndigoUnited/node-promise-retry.git",
110033              "type": "distribution"
110034            }
110035          ],
110036          "evidence": {},
110037          "signature": {
110038            "signature": {
110039              "publicKey": {}
110040            }
110041          },
110042          "modelCard": {
110043            "modelParameters": {
110044              "approach": {}
110045            },
110046            "quantitativeAnalysis": {
110047              "graphics": {}
110048            },
110049            "considerations": {}
110050          }
110051        },
110052        {
110053          "type": "library",
110054          "bom-ref": "pkg:npm/promzard@0.3.0?package-id=33cefe299422041",
110055          "supplier": {},
110056          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
110057          "name": "promzard",
110058          "version": "0.3.0",
110059          "description": "prompting wizardly",
110060          "licenses": [
110061            {
110062              "license": {
110063                "id": "ISC"
110064              }
110065            }
110066          ],
110067          "cpe": "cpe:2.3:a:promzard:promzard:0.3.0:*:*:*:*:*:*:*",
110068          "purl": "pkg:npm/promzard@0.3.0",
110069          "swid": {
110070            "attachment": {}
110071          },
110072          "pedigree": {},
110073          "externalReferences": [
110074            {
110075              "url": "git://github.com/isaacs/promzard",
110076              "type": "distribution"
110077            }
110078          ],
110079          "evidence": {},
110080          "signature": {
110081            "signature": {
110082              "publicKey": {}
110083            }
110084          },
110085          "modelCard": {
110086            "modelParameters": {
110087              "approach": {}
110088            },
110089            "quantitativeAnalysis": {
110090              "graphics": {}
110091            },
110092            "considerations": {}
110093          }
110094        },
110095        {
110096          "type": "library",
110097          "bom-ref": "pkg:npm/proxy-addr@2.0.7?package-id=53c4580aea322e7e",
110098          "supplier": {},
110099          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
110100          "name": "proxy-addr",
110101          "version": "2.0.7",
110102          "description": "Determine address of proxied request",
110103          "licenses": [
110104            {
110105              "license": {
110106                "id": "MIT"
110107              }
110108            }
110109          ],
110110          "cpe": "cpe:2.3:a:proxy-addr:proxy-addr:2.0.7:*:*:*:*:*:*:*",
110111          "purl": "pkg:npm/proxy-addr@2.0.7",
110112          "swid": {
110113            "attachment": {}
110114          },
110115          "pedigree": {},
110116          "externalReferences": [
110117            {
110118              "url": "jshttp/proxy-addr",
110119              "type": "distribution"
110120            }
110121          ],
110122          "evidence": {},
110123          "signature": {
110124            "signature": {
110125              "publicKey": {}
110126            }
110127          },
110128          "modelCard": {
110129            "modelParameters": {
110130              "approach": {}
110131            },
110132            "quantitativeAnalysis": {
110133              "graphics": {}
110134            },
110135            "considerations": {}
110136          }
110137        },
110138        {
110139          "type": "library",
110140          "bom-ref": "pkg:npm/public-encrypt@4.0.3?package-id=acd9c5c1e4b65dd2",
110141          "supplier": {},
110142          "author": "Calvin Metcalf",
110143          "name": "public-encrypt",
110144          "version": "4.0.3",
110145          "description": "browserify version of publicEncrypt \u0026 privateDecrypt",
110146          "licenses": [
110147            {
110148              "license": {
110149                "id": "MIT"
110150              }
110151            }
110152          ],
110153          "cpe": "cpe:2.3:a:crypto-browserify:public-encrypt:4.0.3:*:*:*:*:*:*:*",
110154          "purl": "pkg:npm/public-encrypt@4.0.3",
110155          "swid": {
110156            "attachment": {}
110157          },
110158          "pedigree": {},
110159          "externalReferences": [
110160            {
110161              "url": "https://github.com/crypto-browserify/publicEncrypt.git",
110162              "type": "distribution"
110163            },
110164            {
110165              "url": "https://github.com/crypto-browserify/publicEncrypt",
110166              "type": "website"
110167            }
110168          ],
110169          "evidence": {},
110170          "signature": {
110171            "signature": {
110172              "publicKey": {}
110173            }
110174          },
110175          "modelCard": {
110176            "modelParameters": {
110177              "approach": {}
110178            },
110179            "quantitativeAnalysis": {
110180              "graphics": {}
110181            },
110182            "considerations": {}
110183          }
110184        },
110185        {
110186          "type": "library",
110187          "bom-ref": "pkg:npm/qrcode-terminal@0.12.0?package-id=83c91f496595f73",
110188          "supplier": {},
110189          "name": "qrcode-terminal",
110190          "version": "0.12.0",
110191          "description": "QRCodes, in the terminal",
110192          "licenses": [
110193            {
110194              "license": {
110195                "name": "Apache 2.0"
110196              }
110197            }
110198          ],
110199          "cpe": "cpe:2.3:a:qrcode-terminal:qrcode-terminal:0.12.0:*:*:*:*:*:*:*",
110200          "purl": "pkg:npm/qrcode-terminal@0.12.0",
110201          "swid": {
110202            "attachment": {}
110203          },
110204          "pedigree": {},
110205          "externalReferences": [
110206            {
110207              "url": "https://github.com/gtanner/qrcode-terminal",
110208              "type": "distribution"
110209            },
110210            {
110211              "url": "https://github.com/gtanner/qrcode-terminal",
110212              "type": "website"
110213            }
110214          ],
110215          "evidence": {},
110216          "signature": {
110217            "signature": {
110218              "publicKey": {}
110219            }
110220          },
110221          "modelCard": {
110222            "modelParameters": {
110223              "approach": {}
110224            },
110225            "quantitativeAnalysis": {
110226              "graphics": {}
110227            },
110228            "considerations": {}
110229          }
110230        },
110231        {
110232          "type": "library",
110233          "bom-ref": "pkg:npm/qs@6.5.2?package-id=8a6e990df3bbe823",
110234          "supplier": {},
110235          "name": "qs",
110236          "version": "6.5.2",
110237          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
110238          "licenses": [
110239            {
110240              "license": {
110241                "id": "BSD-3-Clause"
110242              }
110243            }
110244          ],
110245          "cpe": "cpe:2.3:a:ljharb:qs:6.5.2:*:*:*:*:*:*:*",
110246          "purl": "pkg:npm/qs@6.5.2",
110247          "swid": {
110248            "attachment": {}
110249          },
110250          "pedigree": {},
110251          "externalReferences": [
110252            {
110253              "url": "https://github.com/ljharb/qs.git",
110254              "type": "distribution"
110255            },
110256            {
110257              "url": "https://github.com/ljharb/qs",
110258              "type": "website"
110259            }
110260          ],
110261          "evidence": {},
110262          "signature": {
110263            "signature": {
110264              "publicKey": {}
110265            }
110266          },
110267          "modelCard": {
110268            "modelParameters": {
110269              "approach": {}
110270            },
110271            "quantitativeAnalysis": {
110272              "graphics": {}
110273            },
110274            "considerations": {}
110275          }
110276        },
110277        {
110278          "type": "library",
110279          "bom-ref": "pkg:npm/query-string@7.1.3?package-id=269bef40e0177f9f",
110280          "supplier": {},
110281          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
110282          "name": "query-string",
110283          "version": "7.1.3",
110284          "description": "Parse and stringify URL query strings",
110285          "licenses": [
110286            {
110287              "license": {
110288                "id": "MIT"
110289              }
110290            }
110291          ],
110292          "cpe": "cpe:2.3:a:query-string:query-string:7.1.3:*:*:*:*:*:*:*",
110293          "purl": "pkg:npm/query-string@7.1.3",
110294          "swid": {
110295            "attachment": {}
110296          },
110297          "pedigree": {},
110298          "externalReferences": [
110299            {
110300              "url": "sindresorhus/query-string",
110301              "type": "distribution"
110302            }
110303          ],
110304          "evidence": {},
110305          "signature": {
110306            "signature": {
110307              "publicKey": {}
110308            }
110309          },
110310          "modelCard": {
110311            "modelParameters": {
110312              "approach": {}
110313            },
110314            "quantitativeAnalysis": {
110315              "graphics": {}
110316            },
110317            "considerations": {}
110318          }
110319        },
110320        {
110321          "type": "library",
110322          "bom-ref": "pkg:npm/randombytes@2.1.0?package-id=e552b57eba8b1bf1",
110323          "supplier": {},
110324          "name": "randombytes",
110325          "version": "2.1.0",
110326          "description": "random bytes from browserify stand alone",
110327          "licenses": [
110328            {
110329              "license": {
110330                "id": "MIT"
110331              }
110332            }
110333          ],
110334          "cpe": "cpe:2.3:a:crypto-browserify:randombytes:2.1.0:*:*:*:*:*:*:*",
110335          "purl": "pkg:npm/randombytes@2.1.0",
110336          "swid": {
110337            "attachment": {}
110338          },
110339          "pedigree": {},
110340          "externalReferences": [
110341            {
110342              "url": "git@github.com:crypto-browserify/randombytes.git",
110343              "type": "distribution"
110344            },
110345            {
110346              "url": "https://github.com/crypto-browserify/randombytes",
110347              "type": "website"
110348            }
110349          ],
110350          "evidence": {},
110351          "signature": {
110352            "signature": {
110353              "publicKey": {}
110354            }
110355          },
110356          "modelCard": {
110357            "modelParameters": {
110358              "approach": {}
110359            },
110360            "quantitativeAnalysis": {
110361              "graphics": {}
110362            },
110363            "considerations": {}
110364          }
110365        },
110366        {
110367          "type": "library",
110368          "bom-ref": "pkg:npm/randomfill@1.0.4?package-id=1821ca9f4bd12848",
110369          "supplier": {},
110370          "name": "randomfill",
110371          "version": "1.0.4",
110372          "description": "random fill from browserify stand alone",
110373          "licenses": [
110374            {
110375              "license": {
110376                "id": "MIT"
110377              }
110378            }
110379          ],
110380          "cpe": "cpe:2.3:a:crypto-browserify:randomfill:1.0.4:*:*:*:*:*:*:*",
110381          "purl": "pkg:npm/randomfill@1.0.4",
110382          "swid": {
110383            "attachment": {}
110384          },
110385          "pedigree": {},
110386          "externalReferences": [
110387            {
110388              "url": "https://github.com/crypto-browserify/randomfill.git",
110389              "type": "distribution"
110390            },
110391            {
110392              "url": "https://github.com/crypto-browserify/randomfill",
110393              "type": "website"
110394            }
110395          ],
110396          "evidence": {},
110397          "signature": {
110398            "signature": {
110399              "publicKey": {}
110400            }
110401          },
110402          "modelCard": {
110403            "modelParameters": {
110404              "approach": {}
110405            },
110406            "quantitativeAnalysis": {
110407              "graphics": {}
110408            },
110409            "considerations": {}
110410          }
110411        },
110412        {
110413          "type": "library",
110414          "bom-ref": "pkg:npm/range-parser@1.2.1?package-id=4426c7b6b8b9fe0c",
110415          "supplier": {},
110416          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
110417          "name": "range-parser",
110418          "version": "1.2.1",
110419          "description": "Range header field string parser",
110420          "licenses": [
110421            {
110422              "license": {
110423                "id": "MIT"
110424              }
110425            }
110426          ],
110427          "cpe": "cpe:2.3:a:range-parser:range-parser:1.2.1:*:*:*:*:*:*:*",
110428          "purl": "pkg:npm/range-parser@1.2.1",
110429          "swid": {
110430            "attachment": {}
110431          },
110432          "pedigree": {},
110433          "externalReferences": [
110434            {
110435              "url": "jshttp/range-parser",
110436              "type": "distribution"
110437            }
110438          ],
110439          "evidence": {},
110440          "signature": {
110441            "signature": {
110442              "publicKey": {}
110443            }
110444          },
110445          "modelCard": {
110446            "modelParameters": {
110447              "approach": {}
110448            },
110449            "quantitativeAnalysis": {
110450              "graphics": {}
110451            },
110452            "considerations": {}
110453          }
110454        },
110455        {
110456          "type": "library",
110457          "bom-ref": "pkg:npm/raw-body@2.3.3?package-id=c72a71e2075f827c",
110458          "supplier": {},
110459          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
110460          "name": "raw-body",
110461          "version": "2.3.3",
110462          "description": "Get and validate the raw body of a readable stream.",
110463          "licenses": [
110464            {
110465              "license": {
110466                "id": "MIT"
110467              }
110468            }
110469          ],
110470          "cpe": "cpe:2.3:a:raw-body:raw-body:2.3.3:*:*:*:*:*:*:*",
110471          "purl": "pkg:npm/raw-body@2.3.3",
110472          "swid": {
110473            "attachment": {}
110474          },
110475          "pedigree": {},
110476          "externalReferences": [
110477            {
110478              "url": "stream-utils/raw-body",
110479              "type": "distribution"
110480            }
110481          ],
110482          "evidence": {},
110483          "signature": {
110484            "signature": {
110485              "publicKey": {}
110486            }
110487          },
110488          "modelCard": {
110489            "modelParameters": {
110490              "approach": {}
110491            },
110492            "quantitativeAnalysis": {
110493              "graphics": {}
110494            },
110495            "considerations": {}
110496          }
110497        },
110498        {
110499          "type": "library",
110500          "bom-ref": "pkg:npm/read@1.0.7?package-id=cf65e05575a1a15",
110501          "supplier": {},
110502          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
110503          "name": "read",
110504          "version": "1.0.7",
110505          "description": "read(1) for node programs",
110506          "licenses": [
110507            {
110508              "license": {
110509                "id": "ISC"
110510              }
110511            }
110512          ],
110513          "cpe": "cpe:2.3:a:isaacs:read:1.0.7:*:*:*:*:*:*:*",
110514          "purl": "pkg:npm/read@1.0.7",
110515          "swid": {
110516            "attachment": {}
110517          },
110518          "pedigree": {},
110519          "externalReferences": [
110520            {
110521              "url": "git://github.com/isaacs/read.git",
110522              "type": "distribution"
110523            }
110524          ],
110525          "evidence": {},
110526          "signature": {
110527            "signature": {
110528              "publicKey": {}
110529            }
110530          },
110531          "modelCard": {
110532            "modelParameters": {
110533              "approach": {}
110534            },
110535            "quantitativeAnalysis": {
110536              "graphics": {}
110537            },
110538            "considerations": {}
110539          }
110540        },
110541        {
110542          "type": "library",
110543          "bom-ref": "pkg:npm/read-cmd-shim@3.0.0?package-id=4b927be3f703982b",
110544          "supplier": {},
110545          "author": "GitHub Inc.",
110546          "name": "read-cmd-shim",
110547          "version": "3.0.0",
110548          "description": "Figure out what a cmd-shim is pointing at. This acts as the equivalent of fs.readlink.",
110549          "licenses": [
110550            {
110551              "license": {
110552                "id": "ISC"
110553              }
110554            }
110555          ],
110556          "cpe": "cpe:2.3:a:read-cmd-shim:read-cmd-shim:3.0.0:*:*:*:*:*:*:*",
110557          "purl": "pkg:npm/read-cmd-shim@3.0.0",
110558          "swid": {
110559            "attachment": {}
110560          },
110561          "pedigree": {},
110562          "externalReferences": [
110563            {
110564              "url": "https://github.com/npm/read-cmd-shim.git",
110565              "type": "distribution"
110566            },
110567            {
110568              "url": "https://github.com/npm/read-cmd-shim#readme",
110569              "type": "website"
110570            }
110571          ],
110572          "evidence": {},
110573          "signature": {
110574            "signature": {
110575              "publicKey": {}
110576            }
110577          },
110578          "modelCard": {
110579            "modelParameters": {
110580              "approach": {}
110581            },
110582            "quantitativeAnalysis": {
110583              "graphics": {}
110584            },
110585            "considerations": {}
110586          }
110587        },
110588        {
110589          "type": "library",
110590          "bom-ref": "pkg:npm/read-package-json@5.0.2?package-id=d15e27cd5cddf2b4",
110591          "supplier": {},
110592          "author": "GitHub Inc.",
110593          "name": "read-package-json",
110594          "version": "5.0.2",
110595          "description": "The thing npm uses to read package.json files with semantics and defaults and validation",
110596          "licenses": [
110597            {
110598              "license": {
110599                "id": "ISC"
110600              }
110601            }
110602          ],
110603          "cpe": "cpe:2.3:a:read-package-json:read-package-json:5.0.2:*:*:*:*:*:*:*",
110604          "purl": "pkg:npm/read-package-json@5.0.2",
110605          "swid": {
110606            "attachment": {}
110607          },
110608          "pedigree": {},
110609          "externalReferences": [
110610            {
110611              "url": "https://github.com/npm/read-package-json.git",
110612              "type": "distribution"
110613            }
110614          ],
110615          "evidence": {},
110616          "signature": {
110617            "signature": {
110618              "publicKey": {}
110619            }
110620          },
110621          "modelCard": {
110622            "modelParameters": {
110623              "approach": {}
110624            },
110625            "quantitativeAnalysis": {
110626              "graphics": {}
110627            },
110628            "considerations": {}
110629          }
110630        },
110631        {
110632          "type": "library",
110633          "bom-ref": "pkg:npm/read-package-json-fast@2.0.3?package-id=bb9e08c93f4b4c89",
110634          "supplier": {},
110635          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
110636          "name": "read-package-json-fast",
110637          "version": "2.0.3",
110638          "description": "Like read-package-json, but faster",
110639          "licenses": [
110640            {
110641              "license": {
110642                "id": "ISC"
110643              }
110644            }
110645          ],
110646          "cpe": "cpe:2.3:a:read-package-json-fast:read-package-json-fast:2.0.3:*:*:*:*:*:*:*",
110647          "purl": "pkg:npm/read-package-json-fast@2.0.3",
110648          "swid": {
110649            "attachment": {}
110650          },
110651          "pedigree": {},
110652          "externalReferences": [
110653            {
110654              "url": "git+https://github.com/npm/read-package-json-fast.git",
110655              "type": "distribution"
110656            }
110657          ],
110658          "evidence": {},
110659          "signature": {
110660            "signature": {
110661              "publicKey": {}
110662            }
110663          },
110664          "modelCard": {
110665            "modelParameters": {
110666              "approach": {}
110667            },
110668            "quantitativeAnalysis": {
110669              "graphics": {}
110670            },
110671            "considerations": {}
110672          }
110673        },
110674        {
110675          "type": "library",
110676          "bom-ref": "pkg:npm/readable-stream@3.6.0?package-id=32d9c32dd3126020",
110677          "supplier": {},
110678          "name": "readable-stream",
110679          "version": "3.6.0",
110680          "description": "Streams3, a user-land copy of the stream library from Node.js",
110681          "licenses": [
110682            {
110683              "license": {
110684                "id": "MIT"
110685              }
110686            }
110687          ],
110688          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.0:*:*:*:*:*:*:*",
110689          "purl": "pkg:npm/readable-stream@3.6.0",
110690          "swid": {
110691            "attachment": {}
110692          },
110693          "pedigree": {},
110694          "externalReferences": [
110695            {
110696              "url": "git://github.com/nodejs/readable-stream",
110697              "type": "distribution"
110698            }
110699          ],
110700          "evidence": {},
110701          "signature": {
110702            "signature": {
110703              "publicKey": {}
110704            }
110705          },
110706          "modelCard": {
110707            "modelParameters": {
110708              "approach": {}
110709            },
110710            "quantitativeAnalysis": {
110711              "graphics": {}
110712            },
110713            "considerations": {}
110714          }
110715        },
110716        {
110717          "type": "library",
110718          "bom-ref": "pkg:npm/readable-stream@3.6.2?package-id=58c37a95ac33b693",
110719          "supplier": {},
110720          "name": "readable-stream",
110721          "version": "3.6.2",
110722          "description": "Streams3, a user-land copy of the stream library from Node.js",
110723          "licenses": [
110724            {
110725              "license": {
110726                "id": "MIT"
110727              }
110728            }
110729          ],
110730          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.2:*:*:*:*:*:*:*",
110731          "purl": "pkg:npm/readable-stream@3.6.2",
110732          "swid": {
110733            "attachment": {}
110734          },
110735          "pedigree": {},
110736          "externalReferences": [
110737            {
110738              "url": "git://github.com/nodejs/readable-stream",
110739              "type": "distribution"
110740            }
110741          ],
110742          "evidence": {},
110743          "signature": {
110744            "signature": {
110745              "publicKey": {}
110746            }
110747          },
110748          "modelCard": {
110749            "modelParameters": {
110750              "approach": {}
110751            },
110752            "quantitativeAnalysis": {
110753              "graphics": {}
110754            },
110755            "considerations": {}
110756          }
110757        },
110758        {
110759          "type": "library",
110760          "bom-ref": "pkg:npm/readdir-scoped-modules@1.1.0?package-id=33ac24742869be8b",
110761          "supplier": {},
110762          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
110763          "name": "readdir-scoped-modules",
110764          "version": "1.1.0",
110765          "description": "Like `fs.readdir` but handling `@org/module` dirs as if they were a single entry.",
110766          "licenses": [
110767            {
110768              "license": {
110769                "id": "ISC"
110770              }
110771            }
110772          ],
110773          "cpe": "cpe:2.3:a:readdir-scoped-modules:readdir-scoped-modules:1.1.0:*:*:*:*:*:*:*",
110774          "purl": "pkg:npm/readdir-scoped-modules@1.1.0",
110775          "swid": {
110776            "attachment": {}
110777          },
110778          "pedigree": {},
110779          "externalReferences": [
110780            {
110781              "url": "https://github.com/npm/readdir-scoped-modules",
110782              "type": "distribution"
110783            },
110784            {
110785              "url": "https://github.com/npm/readdir-scoped-modules",
110786              "type": "website"
110787            }
110788          ],
110789          "evidence": {},
110790          "signature": {
110791            "signature": {
110792              "publicKey": {}
110793            }
110794          },
110795          "modelCard": {
110796            "modelParameters": {
110797              "approach": {}
110798            },
110799            "quantitativeAnalysis": {
110800              "graphics": {}
110801            },
110802            "considerations": {}
110803          }
110804        },
110805        {
110806          "type": "library",
110807          "bom-ref": "pkg:npm/rechoir@0.6.2?package-id=53838672dfe51f36",
110808          "supplier": {},
110809          "author": "Tyler Kellen (http://goingslowly.com/)",
110810          "name": "rechoir",
110811          "version": "0.6.2",
110812          "description": "Require any supported file as a node module.",
110813          "licenses": [
110814            {
110815              "license": {
110816                "id": "MIT"
110817              }
110818            }
110819          ],
110820          "cpe": "cpe:2.3:a:rechoir:rechoir:0.6.2:*:*:*:*:*:*:*",
110821          "purl": "pkg:npm/rechoir@0.6.2",
110822          "swid": {
110823            "attachment": {}
110824          },
110825          "pedigree": {},
110826          "externalReferences": [
110827            {
110828              "url": "git://github.com/tkellen/node-rechoir.git",
110829              "type": "distribution"
110830            },
110831            {
110832              "url": "https://github.com/tkellen/node-rechoir",
110833              "type": "website"
110834            }
110835          ],
110836          "evidence": {},
110837          "signature": {
110838            "signature": {
110839              "publicKey": {}
110840            }
110841          },
110842          "modelCard": {
110843            "modelParameters": {
110844              "approach": {}
110845            },
110846            "quantitativeAnalysis": {
110847              "graphics": {}
110848            },
110849            "considerations": {}
110850          }
110851        },
110852        {
110853          "type": "library",
110854          "bom-ref": "pkg:npm/resolve@1.22.2?package-id=19b4e65863eb740f",
110855          "supplier": {},
110856          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
110857          "name": "resolve",
110858          "version": "1.22.2",
110859          "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
110860          "licenses": [
110861            {
110862              "license": {
110863                "id": "MIT"
110864              }
110865            }
110866          ],
110867          "cpe": "cpe:2.3:a:browserify:resolve:1.22.2:*:*:*:*:*:*:*",
110868          "purl": "pkg:npm/resolve@1.22.2",
110869          "swid": {
110870            "attachment": {}
110871          },
110872          "pedigree": {},
110873          "externalReferences": [
110874            {
110875              "url": "git://github.com/browserify/resolve.git",
110876              "type": "distribution"
110877            }
110878          ],
110879          "evidence": {},
110880          "signature": {
110881            "signature": {
110882              "publicKey": {}
110883            }
110884          },
110885          "modelCard": {
110886            "modelParameters": {
110887              "approach": {}
110888            },
110889            "quantitativeAnalysis": {
110890              "graphics": {}
110891            },
110892            "considerations": {}
110893          }
110894        },
110895        {
110896          "type": "library",
110897          "bom-ref": "pkg:npm/retry@0.12.0?package-id=c3f319915fd297ec",
110898          "supplier": {},
110899          "author": "Tim Koschützki \u003ctim@debuggable.com\u003e (http://debuggable.com/)",
110900          "name": "retry",
110901          "version": "0.12.0",
110902          "description": "Abstraction for exponential and custom retry strategies for failed operations.",
110903          "licenses": [
110904            {
110905              "license": {
110906                "id": "MIT"
110907              }
110908            }
110909          ],
110910          "cpe": "cpe:2.3:a:tim-kos:retry:0.12.0:*:*:*:*:*:*:*",
110911          "purl": "pkg:npm/retry@0.12.0",
110912          "swid": {
110913            "attachment": {}
110914          },
110915          "pedigree": {},
110916          "externalReferences": [
110917            {
110918              "url": "git://github.com/tim-kos/node-retry.git",
110919              "type": "distribution"
110920            },
110921            {
110922              "url": "https://github.com/tim-kos/node-retry",
110923              "type": "website"
110924            }
110925          ],
110926          "evidence": {},
110927          "signature": {
110928            "signature": {
110929              "publicKey": {}
110930            }
110931          },
110932          "modelCard": {
110933            "modelParameters": {
110934              "approach": {}
110935            },
110936            "quantitativeAnalysis": {
110937              "graphics": {}
110938            },
110939            "considerations": {}
110940          }
110941        },
110942        {
110943          "type": "library",
110944          "bom-ref": "pkg:npm/rimraf@2.7.1?package-id=bd4097ab94b14450",
110945          "supplier": {},
110946          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
110947          "name": "rimraf",
110948          "version": "2.7.1",
110949          "description": "A deep deletion module for node (like `rm -rf`)",
110950          "licenses": [
110951            {
110952              "license": {
110953                "id": "ISC"
110954              }
110955            }
110956          ],
110957          "cpe": "cpe:2.3:a:isaacs:rimraf:2.7.1:*:*:*:*:*:*:*",
110958          "purl": "pkg:npm/rimraf@2.7.1",
110959          "swid": {
110960            "attachment": {}
110961          },
110962          "pedigree": {},
110963          "externalReferences": [
110964            {
110965              "url": "git://github.com/isaacs/rimraf.git",
110966              "type": "distribution"
110967            }
110968          ],
110969          "evidence": {},
110970          "signature": {
110971            "signature": {
110972              "publicKey": {}
110973            }
110974          },
110975          "modelCard": {
110976            "modelParameters": {
110977              "approach": {}
110978            },
110979            "quantitativeAnalysis": {
110980              "graphics": {}
110981            },
110982            "considerations": {}
110983          }
110984        },
110985        {
110986          "type": "library",
110987          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=92690f32c123c49b",
110988          "supplier": {},
110989          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
110990          "name": "rimraf",
110991          "version": "3.0.2",
110992          "description": "A deep deletion module for node (like `rm -rf`)",
110993          "licenses": [
110994            {
110995              "license": {
110996                "id": "ISC"
110997              }
110998            }
110999          ],
111000          "cpe": "cpe:2.3:a:isaacs:rimraf:3.0.2:*:*:*:*:*:*:*",
111001          "purl": "pkg:npm/rimraf@3.0.2",
111002          "swid": {
111003            "attachment": {}
111004          },
111005          "pedigree": {},
111006          "externalReferences": [
111007            {
111008              "url": "git://github.com/isaacs/rimraf.git",
111009              "type": "distribution"
111010            }
111011          ],
111012          "evidence": {},
111013          "signature": {
111014            "signature": {
111015              "publicKey": {}
111016            }
111017          },
111018          "modelCard": {
111019            "modelParameters": {
111020              "approach": {}
111021            },
111022            "quantitativeAnalysis": {
111023              "graphics": {}
111024            },
111025            "considerations": {}
111026          }
111027        },
111028        {
111029          "type": "library",
111030          "bom-ref": "pkg:npm/ripemd160@2.0.2?package-id=7f7356c79fe65cee",
111031          "supplier": {},
111032          "name": "ripemd160",
111033          "version": "2.0.2",
111034          "description": "Compute ripemd160 of bytes or strings.",
111035          "licenses": [
111036            {
111037              "license": {
111038                "id": "MIT"
111039              }
111040            }
111041          ],
111042          "cpe": "cpe:2.3:a:crypto-browserify:ripemd160:2.0.2:*:*:*:*:*:*:*",
111043          "purl": "pkg:npm/ripemd160@2.0.2",
111044          "swid": {
111045            "attachment": {}
111046          },
111047          "pedigree": {},
111048          "externalReferences": [
111049            {
111050              "url": "https://github.com/crypto-browserify/ripemd160",
111051              "type": "distribution"
111052            }
111053          ],
111054          "evidence": {},
111055          "signature": {
111056            "signature": {
111057              "publicKey": {}
111058            }
111059          },
111060          "modelCard": {
111061            "modelParameters": {
111062              "approach": {}
111063            },
111064            "quantitativeAnalysis": {
111065              "graphics": {}
111066            },
111067            "considerations": {}
111068          }
111069        },
111070        {
111071          "type": "library",
111072          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=2726b88c81e31063",
111073          "supplier": {},
111074          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
111075          "name": "safe-buffer",
111076          "version": "5.1.2",
111077          "description": "Safer Node.js Buffer API",
111078          "licenses": [
111079            {
111080              "license": {
111081                "id": "MIT"
111082              }
111083            }
111084          ],
111085          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
111086          "purl": "pkg:npm/safe-buffer@5.1.2",
111087          "swid": {
111088            "attachment": {}
111089          },
111090          "pedigree": {},
111091          "externalReferences": [
111092            {
111093              "url": "git://github.com/feross/safe-buffer.git",
111094              "type": "distribution"
111095            },
111096            {
111097              "url": "https://github.com/feross/safe-buffer",
111098              "type": "website"
111099            }
111100          ],
111101          "evidence": {},
111102          "signature": {
111103            "signature": {
111104              "publicKey": {}
111105            }
111106          },
111107          "modelCard": {
111108            "modelParameters": {
111109              "approach": {}
111110            },
111111            "quantitativeAnalysis": {
111112              "graphics": {}
111113            },
111114            "considerations": {}
111115          }
111116        },
111117        {
111118          "type": "library",
111119          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=edf513d3ab46bee",
111120          "supplier": {},
111121          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
111122          "name": "safe-buffer",
111123          "version": "5.2.1",
111124          "description": "Safer Node.js Buffer API",
111125          "licenses": [
111126            {
111127              "license": {
111128                "id": "MIT"
111129              }
111130            }
111131          ],
111132          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
111133          "purl": "pkg:npm/safe-buffer@5.2.1",
111134          "swid": {
111135            "attachment": {}
111136          },
111137          "pedigree": {},
111138          "externalReferences": [
111139            {
111140              "url": "git://github.com/feross/safe-buffer.git",
111141              "type": "distribution"
111142            },
111143            {
111144              "url": "https://github.com/feross/safe-buffer",
111145              "type": "website"
111146            }
111147          ],
111148          "evidence": {},
111149          "signature": {
111150            "signature": {
111151              "publicKey": {}
111152            }
111153          },
111154          "modelCard": {
111155            "modelParameters": {
111156              "approach": {}
111157            },
111158            "quantitativeAnalysis": {
111159              "graphics": {}
111160            },
111161            "considerations": {}
111162          }
111163        },
111164        {
111165          "type": "library",
111166          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=695bd3e67dfc1bca",
111167          "supplier": {},
111168          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
111169          "name": "safe-buffer",
111170          "version": "5.2.1",
111171          "description": "Safer Node.js Buffer API",
111172          "licenses": [
111173            {
111174              "license": {
111175                "id": "MIT"
111176              }
111177            }
111178          ],
111179          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
111180          "purl": "pkg:npm/safe-buffer@5.2.1",
111181          "swid": {
111182            "attachment": {}
111183          },
111184          "pedigree": {},
111185          "externalReferences": [
111186            {
111187              "url": "git://github.com/feross/safe-buffer.git",
111188              "type": "distribution"
111189            },
111190            {
111191              "url": "https://github.com/feross/safe-buffer",
111192              "type": "website"
111193            }
111194          ],
111195          "evidence": {},
111196          "signature": {
111197            "signature": {
111198              "publicKey": {}
111199            }
111200          },
111201          "modelCard": {
111202            "modelParameters": {
111203              "approach": {}
111204            },
111205            "quantitativeAnalysis": {
111206              "graphics": {}
111207            },
111208            "considerations": {}
111209          }
111210        },
111211        {
111212          "type": "library",
111213          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=61ae351303bc44d5",
111214          "supplier": {},
111215          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
111216          "name": "safe-buffer",
111217          "version": "5.2.1",
111218          "description": "Safer Node.js Buffer API",
111219          "licenses": [
111220            {
111221              "license": {
111222                "id": "MIT"
111223              }
111224            }
111225          ],
111226          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
111227          "purl": "pkg:npm/safe-buffer@5.2.1",
111228          "swid": {
111229            "attachment": {}
111230          },
111231          "pedigree": {},
111232          "externalReferences": [
111233            {
111234              "url": "git://github.com/feross/safe-buffer.git",
111235              "type": "distribution"
111236            },
111237            {
111238              "url": "https://github.com/feross/safe-buffer",
111239              "type": "website"
111240            }
111241          ],
111242          "evidence": {},
111243          "signature": {
111244            "signature": {
111245              "publicKey": {}
111246            }
111247          },
111248          "modelCard": {
111249            "modelParameters": {
111250              "approach": {}
111251            },
111252            "quantitativeAnalysis": {
111253              "graphics": {}
111254            },
111255            "considerations": {}
111256          }
111257        },
111258        {
111259          "type": "library",
111260          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=e39228a786cd5fee",
111261          "supplier": {},
111262          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
111263          "name": "safe-buffer",
111264          "version": "5.2.1",
111265          "description": "Safer Node.js Buffer API",
111266          "licenses": [
111267            {
111268              "license": {
111269                "id": "MIT"
111270              }
111271            }
111272          ],
111273          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
111274          "purl": "pkg:npm/safe-buffer@5.2.1",
111275          "swid": {
111276            "attachment": {}
111277          },
111278          "pedigree": {},
111279          "externalReferences": [
111280            {
111281              "url": "git://github.com/feross/safe-buffer.git",
111282              "type": "distribution"
111283            },
111284            {
111285              "url": "https://github.com/feross/safe-buffer",
111286              "type": "website"
111287            }
111288          ],
111289          "evidence": {},
111290          "signature": {
111291            "signature": {
111292              "publicKey": {}
111293            }
111294          },
111295          "modelCard": {
111296            "modelParameters": {
111297              "approach": {}
111298            },
111299            "quantitativeAnalysis": {
111300              "graphics": {}
111301            },
111302            "considerations": {}
111303          }
111304        },
111305        {
111306          "type": "library",
111307          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=4ab2220d3f3f4961",
111308          "supplier": {},
111309          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
111310          "name": "safer-buffer",
111311          "version": "2.1.2",
111312          "description": "Modern Buffer API polyfill without footguns",
111313          "licenses": [
111314            {
111315              "license": {
111316                "id": "MIT"
111317              }
111318            }
111319          ],
111320          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
111321          "purl": "pkg:npm/safer-buffer@2.1.2",
111322          "swid": {
111323            "attachment": {}
111324          },
111325          "pedigree": {},
111326          "externalReferences": [
111327            {
111328              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
111329              "type": "distribution"
111330            }
111331          ],
111332          "evidence": {},
111333          "signature": {
111334            "signature": {
111335              "publicKey": {}
111336            }
111337          },
111338          "modelCard": {
111339            "modelParameters": {
111340              "approach": {}
111341            },
111342            "quantitativeAnalysis": {
111343              "graphics": {}
111344            },
111345            "considerations": {}
111346          }
111347        },
111348        {
111349          "type": "library",
111350          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=cc287d73489b4567",
111351          "supplier": {},
111352          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
111353          "name": "safer-buffer",
111354          "version": "2.1.2",
111355          "description": "Modern Buffer API polyfill without footguns",
111356          "licenses": [
111357            {
111358              "license": {
111359                "id": "MIT"
111360              }
111361            }
111362          ],
111363          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
111364          "purl": "pkg:npm/safer-buffer@2.1.2",
111365          "swid": {
111366            "attachment": {}
111367          },
111368          "pedigree": {},
111369          "externalReferences": [
111370            {
111371              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
111372              "type": "distribution"
111373            }
111374          ],
111375          "evidence": {},
111376          "signature": {
111377            "signature": {
111378              "publicKey": {}
111379            }
111380          },
111381          "modelCard": {
111382            "modelParameters": {
111383              "approach": {}
111384            },
111385            "quantitativeAnalysis": {
111386              "graphics": {}
111387            },
111388            "considerations": {}
111389          }
111390        },
111391        {
111392          "type": "library",
111393          "bom-ref": "pkg:npm/sax@1.2.4?package-id=d02182db0df4dd12",
111394          "supplier": {},
111395          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
111396          "name": "sax",
111397          "version": "1.2.4",
111398          "description": "An evented streaming XML parser in JavaScript",
111399          "licenses": [
111400            {
111401              "license": {
111402                "id": "ISC"
111403              }
111404            }
111405          ],
111406          "cpe": "cpe:2.3:a:isaacs:sax:1.2.4:*:*:*:*:*:*:*",
111407          "purl": "pkg:npm/sax@1.2.4",
111408          "swid": {
111409            "attachment": {}
111410          },
111411          "pedigree": {},
111412          "externalReferences": [
111413            {
111414              "url": "git://github.com/isaacs/sax-js.git",
111415              "type": "distribution"
111416            }
111417          ],
111418          "evidence": {},
111419          "signature": {
111420            "signature": {
111421              "publicKey": {}
111422            }
111423          },
111424          "modelCard": {
111425            "modelParameters": {
111426              "approach": {}
111427            },
111428            "quantitativeAnalysis": {
111429              "graphics": {}
111430            },
111431            "considerations": {}
111432          }
111433        },
111434        {
111435          "type": "library",
111436          "bom-ref": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5\u0026package-id=206fdb47b3e980eb",
111437          "supplier": {},
111438          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
111439          "name": "scanelf",
111440          "version": "1.3.4-r0",
111441          "description": "Scan ELF binaries for stuff",
111442          "licenses": [
111443            {
111444              "license": {
111445                "id": "GPL-2.0-only"
111446              }
111447            }
111448          ],
111449          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.4-r0:*:*:*:*:*:*:*",
111450          "purl": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5",
111451          "swid": {
111452            "attachment": {}
111453          },
111454          "pedigree": {},
111455          "externalReferences": [
111456            {
111457              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
111458              "type": "distribution"
111459            }
111460          ],
111461          "evidence": {},
111462          "signature": {
111463            "signature": {
111464              "publicKey": {}
111465            }
111466          },
111467          "modelCard": {
111468            "modelParameters": {
111469              "approach": {}
111470            },
111471            "quantitativeAnalysis": {
111472              "graphics": {}
111473            },
111474            "considerations": {}
111475          }
111476        },
111477        {
111478          "type": "library",
111479          "bom-ref": "pkg:npm/semver@5.7.1?package-id=c8156fd8ac442494",
111480          "supplier": {},
111481          "name": "semver",
111482          "version": "5.7.1",
111483          "description": "The semantic version parser used by npm.",
111484          "licenses": [
111485            {
111486              "license": {
111487                "id": "ISC"
111488              }
111489            }
111490          ],
111491          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
111492          "purl": "pkg:npm/semver@5.7.1",
111493          "swid": {
111494            "attachment": {}
111495          },
111496          "pedigree": {},
111497          "externalReferences": [
111498            {
111499              "url": "https://github.com/npm/node-semver",
111500              "type": "distribution"
111501            }
111502          ],
111503          "evidence": {},
111504          "signature": {
111505            "signature": {
111506              "publicKey": {}
111507            }
111508          },
111509          "modelCard": {
111510            "modelParameters": {
111511              "approach": {}
111512            },
111513            "quantitativeAnalysis": {
111514              "graphics": {}
111515            },
111516            "considerations": {}
111517          }
111518        },
111519        {
111520          "type": "library",
111521          "bom-ref": "pkg:npm/semver@7.3.7?package-id=73e16bb8e099774",
111522          "supplier": {},
111523          "author": "GitHub Inc.",
111524          "name": "semver",
111525          "version": "7.3.7",
111526          "description": "The semantic version parser used by npm.",
111527          "licenses": [
111528            {
111529              "license": {
111530                "id": "ISC"
111531              }
111532            }
111533          ],
111534          "cpe": "cpe:2.3:a:semver:semver:7.3.7:*:*:*:*:*:*:*",
111535          "purl": "pkg:npm/semver@7.3.7",
111536          "swid": {
111537            "attachment": {}
111538          },
111539          "pedigree": {},
111540          "externalReferences": [
111541            {
111542              "url": "https://github.com/npm/node-semver.git",
111543              "type": "distribution"
111544            }
111545          ],
111546          "evidence": {},
111547          "signature": {
111548            "signature": {
111549              "publicKey": {}
111550            }
111551          },
111552          "modelCard": {
111553            "modelParameters": {
111554              "approach": {}
111555            },
111556            "quantitativeAnalysis": {
111557              "graphics": {}
111558            },
111559            "considerations": {}
111560          }
111561        },
111562        {
111563          "type": "library",
111564          "bom-ref": "pkg:npm/send@0.16.2?package-id=6aacb6d4db077764",
111565          "supplier": {},
111566          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
111567          "name": "send",
111568          "version": "0.16.2",
111569          "description": "Better streaming static file server with Range and conditional-GET support",
111570          "licenses": [
111571            {
111572              "license": {
111573                "id": "MIT"
111574              }
111575            }
111576          ],
111577          "cpe": "cpe:2.3:a:send:send:0.16.2:*:*:*:*:*:*:*",
111578          "purl": "pkg:npm/send@0.16.2",
111579          "swid": {
111580            "attachment": {}
111581          },
111582          "pedigree": {},
111583          "externalReferences": [
111584            {
111585              "url": "pillarjs/send",
111586              "type": "distribution"
111587            }
111588          ],
111589          "evidence": {},
111590          "signature": {
111591            "signature": {
111592              "publicKey": {}
111593            }
111594          },
111595          "modelCard": {
111596            "modelParameters": {
111597              "approach": {}
111598            },
111599            "quantitativeAnalysis": {
111600              "graphics": {}
111601            },
111602            "considerations": {}
111603          }
111604        },
111605        {
111606          "type": "library",
111607          "bom-ref": "pkg:npm/serve-static@1.13.2?package-id=2085513853dda1c3",
111608          "supplier": {},
111609          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
111610          "name": "serve-static",
111611          "version": "1.13.2",
111612          "description": "Serve static files",
111613          "licenses": [
111614            {
111615              "license": {
111616                "id": "MIT"
111617              }
111618            }
111619          ],
111620          "cpe": "cpe:2.3:a:serve-static:serve-static:1.13.2:*:*:*:*:*:*:*",
111621          "purl": "pkg:npm/serve-static@1.13.2",
111622          "swid": {
111623            "attachment": {}
111624          },
111625          "pedigree": {},
111626          "externalReferences": [
111627            {
111628              "url": "expressjs/serve-static",
111629              "type": "distribution"
111630            }
111631          ],
111632          "evidence": {},
111633          "signature": {
111634            "signature": {
111635              "publicKey": {}
111636            }
111637          },
111638          "modelCard": {
111639            "modelParameters": {
111640              "approach": {}
111641            },
111642            "quantitativeAnalysis": {
111643              "graphics": {}
111644            },
111645            "considerations": {}
111646          }
111647        },
111648        {
111649          "type": "library",
111650          "bom-ref": "pkg:npm/set-blocking@2.0.0?package-id=bac85cbb844de9c9",
111651          "supplier": {},
111652          "author": "Ben Coe \u003cben@npmjs.com\u003e",
111653          "name": "set-blocking",
111654          "version": "2.0.0",
111655          "description": "set blocking stdio and stderr ensuring that terminal output does not truncate",
111656          "licenses": [
111657            {
111658              "license": {
111659                "id": "ISC"
111660              }
111661            }
111662          ],
111663          "cpe": "cpe:2.3:a:set-blocking:set-blocking:2.0.0:*:*:*:*:*:*:*",
111664          "purl": "pkg:npm/set-blocking@2.0.0",
111665          "swid": {
111666            "attachment": {}
111667          },
111668          "pedigree": {},
111669          "externalReferences": [
111670            {
111671              "url": "git+https://github.com/yargs/set-blocking.git",
111672              "type": "distribution"
111673            },
111674            {
111675              "url": "https://github.com/yargs/set-blocking#readme",
111676              "type": "website"
111677            }
111678          ],
111679          "evidence": {},
111680          "signature": {
111681            "signature": {
111682              "publicKey": {}
111683            }
111684          },
111685          "modelCard": {
111686            "modelParameters": {
111687              "approach": {}
111688            },
111689            "quantitativeAnalysis": {
111690              "graphics": {}
111691            },
111692            "considerations": {}
111693          }
111694        },
111695        {
111696          "type": "library",
111697          "bom-ref": "pkg:npm/setprototypeof@1.1.0?package-id=5f62b122fce97102",
111698          "supplier": {},
111699          "author": "Wes Todd",
111700          "name": "setprototypeof",
111701          "version": "1.1.0",
111702          "description": "A small polyfill for Object.setprototypeof",
111703          "licenses": [
111704            {
111705              "license": {
111706                "id": "ISC"
111707              }
111708            }
111709          ],
111710          "cpe": "cpe:2.3:a:setprototypeof:setprototypeof:1.1.0:*:*:*:*:*:*:*",
111711          "purl": "pkg:npm/setprototypeof@1.1.0",
111712          "swid": {
111713            "attachment": {}
111714          },
111715          "pedigree": {},
111716          "externalReferences": [
111717            {
111718              "url": "https://github.com/wesleytodd/setprototypeof.git",
111719              "type": "distribution"
111720            },
111721            {
111722              "url": "https://github.com/wesleytodd/setprototypeof",
111723              "type": "website"
111724            }
111725          ],
111726          "evidence": {},
111727          "signature": {
111728            "signature": {
111729              "publicKey": {}
111730            }
111731          },
111732          "modelCard": {
111733            "modelParameters": {
111734              "approach": {}
111735            },
111736            "quantitativeAnalysis": {
111737              "graphics": {}
111738            },
111739            "considerations": {}
111740          }
111741        },
111742        {
111743          "type": "library",
111744          "bom-ref": "pkg:npm/sha.js@2.4.11?package-id=a1de2d056381c798",
111745          "supplier": {},
111746          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (dominictarr.com)",
111747          "name": "sha.js",
111748          "version": "2.4.11",
111749          "description": "Streamable SHA hashes in pure javascript",
111750          "licenses": [
111751            {
111752              "license": {
111753                "name": "(MIT AND BSD-3-Clause)"
111754              }
111755            }
111756          ],
111757          "cpe": "cpe:2.3:a:crypto-browserify:sha.js:2.4.11:*:*:*:*:*:*:*",
111758          "purl": "pkg:npm/sha.js@2.4.11",
111759          "swid": {
111760            "attachment": {}
111761          },
111762          "pedigree": {},
111763          "externalReferences": [
111764            {
111765              "url": "git://github.com/crypto-browserify/sha.js.git",
111766              "type": "distribution"
111767            },
111768            {
111769              "url": "https://github.com/crypto-browserify/sha.js",
111770              "type": "website"
111771            }
111772          ],
111773          "evidence": {},
111774          "signature": {
111775            "signature": {
111776              "publicKey": {}
111777            }
111778          },
111779          "modelCard": {
111780            "modelParameters": {
111781              "approach": {}
111782            },
111783            "quantitativeAnalysis": {
111784              "graphics": {}
111785            },
111786            "considerations": {}
111787          }
111788        },
111789        {
111790          "type": "library",
111791          "bom-ref": "pkg:npm/shebang-command@1.2.0?package-id=fffd86fb9033b83c",
111792          "supplier": {},
111793          "author": "Kevin Martensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
111794          "name": "shebang-command",
111795          "version": "1.2.0",
111796          "description": "Get the command from a shebang",
111797          "licenses": [
111798            {
111799              "license": {
111800                "id": "MIT"
111801              }
111802            }
111803          ],
111804          "cpe": "cpe:2.3:a:shebang-command:shebang-command:1.2.0:*:*:*:*:*:*:*",
111805          "purl": "pkg:npm/shebang-command@1.2.0",
111806          "swid": {
111807            "attachment": {}
111808          },
111809          "pedigree": {},
111810          "externalReferences": [
111811            {
111812              "url": "kevva/shebang-command",
111813              "type": "distribution"
111814            }
111815          ],
111816          "evidence": {},
111817          "signature": {
111818            "signature": {
111819              "publicKey": {}
111820            }
111821          },
111822          "modelCard": {
111823            "modelParameters": {
111824              "approach": {}
111825            },
111826            "quantitativeAnalysis": {
111827              "graphics": {}
111828            },
111829            "considerations": {}
111830          }
111831        },
111832        {
111833          "type": "library",
111834          "bom-ref": "pkg:npm/shebang-regex@1.0.0?package-id=2ce4c4e2034ccaff",
111835          "supplier": {},
111836          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
111837          "name": "shebang-regex",
111838          "version": "1.0.0",
111839          "description": "Regular expression for matching a shebang",
111840          "licenses": [
111841            {
111842              "license": {
111843                "id": "MIT"
111844              }
111845            }
111846          ],
111847          "cpe": "cpe:2.3:a:shebang-regex:shebang-regex:1.0.0:*:*:*:*:*:*:*",
111848          "purl": "pkg:npm/shebang-regex@1.0.0",
111849          "swid": {
111850            "attachment": {}
111851          },
111852          "pedigree": {},
111853          "externalReferences": [
111854            {
111855              "url": "sindresorhus/shebang-regex",
111856              "type": "distribution"
111857            }
111858          ],
111859          "evidence": {},
111860          "signature": {
111861            "signature": {
111862              "publicKey": {}
111863            }
111864          },
111865          "modelCard": {
111866            "modelParameters": {
111867              "approach": {}
111868            },
111869            "quantitativeAnalysis": {
111870              "graphics": {}
111871            },
111872            "considerations": {}
111873          }
111874        },
111875        {
111876          "type": "library",
111877          "bom-ref": "pkg:npm/shelljs@0.8.5?package-id=52f75ec88cb09ea7",
111878          "supplier": {},
111879          "name": "shelljs",
111880          "version": "0.8.5",
111881          "description": "Portable Unix shell commands for Node.js",
111882          "licenses": [
111883            {
111884              "license": {
111885                "id": "BSD-3-Clause"
111886              }
111887            }
111888          ],
111889          "cpe": "cpe:2.3:a:shelljs:shelljs:0.8.5:*:*:*:*:*:*:*",
111890          "purl": "pkg:npm/shelljs@0.8.5",
111891          "swid": {
111892            "attachment": {}
111893          },
111894          "pedigree": {},
111895          "externalReferences": [
111896            {
111897              "url": "git://github.com/shelljs/shelljs.git",
111898              "type": "distribution"
111899            },
111900            {
111901              "url": "http://github.com/shelljs/shelljs",
111902              "type": "website"
111903            }
111904          ],
111905          "evidence": {},
111906          "signature": {
111907            "signature": {
111908              "publicKey": {}
111909            }
111910          },
111911          "modelCard": {
111912            "modelParameters": {
111913              "approach": {}
111914            },
111915            "quantitativeAnalysis": {
111916              "graphics": {}
111917            },
111918            "considerations": {}
111919          }
111920        },
111921        {
111922          "type": "library",
111923          "bom-ref": "pkg:npm/signal-exit@3.0.7?package-id=998659694cba1dfd",
111924          "supplier": {},
111925          "author": "Ben Coe \u003cben@npmjs.com\u003e",
111926          "name": "signal-exit",
111927          "version": "3.0.7",
111928          "description": "when you want to fire an event no matter how a process exits.",
111929          "licenses": [
111930            {
111931              "license": {
111932                "id": "ISC"
111933              }
111934            }
111935          ],
111936          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.7:*:*:*:*:*:*:*",
111937          "purl": "pkg:npm/signal-exit@3.0.7",
111938          "swid": {
111939            "attachment": {}
111940          },
111941          "pedigree": {},
111942          "externalReferences": [
111943            {
111944              "url": "https://github.com/tapjs/signal-exit.git",
111945              "type": "distribution"
111946            },
111947            {
111948              "url": "https://github.com/tapjs/signal-exit",
111949              "type": "website"
111950            }
111951          ],
111952          "evidence": {},
111953          "signature": {
111954            "signature": {
111955              "publicKey": {}
111956            }
111957          },
111958          "modelCard": {
111959            "modelParameters": {
111960              "approach": {}
111961            },
111962            "quantitativeAnalysis": {
111963              "graphics": {}
111964            },
111965            "considerations": {}
111966          }
111967        },
111968        {
111969          "type": "library",
111970          "bom-ref": "pkg:npm/slash@2.0.0?package-id=eaf393e0f3ea2ae5",
111971          "supplier": {},
111972          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
111973          "name": "slash",
111974          "version": "2.0.0",
111975          "description": "Convert Windows backslash paths to slash paths",
111976          "licenses": [
111977            {
111978              "license": {
111979                "id": "MIT"
111980              }
111981            }
111982          ],
111983          "cpe": "cpe:2.3:a:slash:slash:2.0.0:*:*:*:*:*:*:*",
111984          "purl": "pkg:npm/slash@2.0.0",
111985          "swid": {
111986            "attachment": {}
111987          },
111988          "pedigree": {},
111989          "externalReferences": [
111990            {
111991              "url": "sindresorhus/slash",
111992              "type": "distribution"
111993            }
111994          ],
111995          "evidence": {},
111996          "signature": {
111997            "signature": {
111998              "publicKey": {}
111999            }
112000          },
112001          "modelCard": {
112002            "modelParameters": {
112003              "approach": {}
112004            },
112005            "quantitativeAnalysis": {
112006              "graphics": {}
112007            },
112008            "considerations": {}
112009          }
112010        },
112011        {
112012          "type": "library",
112013          "bom-ref": "pkg:npm/smart-buffer@4.2.0?package-id=ad322c124ae3043c",
112014          "supplier": {},
112015          "author": "Josh Glazebrook",
112016          "name": "smart-buffer",
112017          "version": "4.2.0",
112018          "description": "smart-buffer is a Buffer wrapper that adds automatic read \u0026 write offset tracking, string operations, data insertions, and more.",
112019          "licenses": [
112020            {
112021              "license": {
112022                "id": "MIT"
112023              }
112024            }
112025          ],
112026          "cpe": "cpe:2.3:a:JoshGlazebrook:smart-buffer:4.2.0:*:*:*:*:*:*:*",
112027          "purl": "pkg:npm/smart-buffer@4.2.0",
112028          "swid": {
112029            "attachment": {}
112030          },
112031          "pedigree": {},
112032          "externalReferences": [
112033            {
112034              "url": "https://github.com/JoshGlazebrook/smart-buffer.git",
112035              "type": "distribution"
112036            },
112037            {
112038              "url": "https://github.com/JoshGlazebrook/smart-buffer/",
112039              "type": "website"
112040            }
112041          ],
112042          "evidence": {},
112043          "signature": {
112044            "signature": {
112045              "publicKey": {}
112046            }
112047          },
112048          "modelCard": {
112049            "modelParameters": {
112050              "approach": {}
112051            },
112052            "quantitativeAnalysis": {
112053              "graphics": {}
112054            },
112055            "considerations": {}
112056          }
112057        },
112058        {
112059          "type": "library",
112060          "bom-ref": "pkg:npm/socks@2.7.0?package-id=267f6eb3d489a8eb",
112061          "supplier": {},
112062          "author": "Josh Glazebrook",
112063          "name": "socks",
112064          "version": "2.7.0",
112065          "description": "Fully featured SOCKS proxy client supporting SOCKSv4, SOCKSv4a, and SOCKSv5. Includes Bind and Associate functionality.",
112066          "licenses": [
112067            {
112068              "license": {
112069                "id": "MIT"
112070              }
112071            }
112072          ],
112073          "cpe": "cpe:2.3:a:JoshGlazebrook:socks:2.7.0:*:*:*:*:*:*:*",
112074          "purl": "pkg:npm/socks@2.7.0",
112075          "swid": {
112076            "attachment": {}
112077          },
112078          "pedigree": {},
112079          "externalReferences": [
112080            {
112081              "url": "https://github.com/JoshGlazebrook/socks.git",
112082              "type": "distribution"
112083            },
112084            {
112085              "url": "https://github.com/JoshGlazebrook/socks/",
112086              "type": "website"
112087            }
112088          ],
112089          "evidence": {},
112090          "signature": {
112091            "signature": {
112092              "publicKey": {}
112093            }
112094          },
112095          "modelCard": {
112096            "modelParameters": {
112097              "approach": {}
112098            },
112099            "quantitativeAnalysis": {
112100              "graphics": {}
112101            },
112102            "considerations": {}
112103          }
112104        },
112105        {
112106          "type": "library",
112107          "bom-ref": "pkg:npm/socks-proxy-agent@7.0.0?package-id=8dc0e605920052a1",
112108          "supplier": {},
112109          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
112110          "name": "socks-proxy-agent",
112111          "version": "7.0.0",
112112          "description": "A SOCKS proxy `http.Agent` implementation for HTTP and HTTPS",
112113          "licenses": [
112114            {
112115              "license": {
112116                "id": "MIT"
112117              }
112118            }
112119          ],
112120          "cpe": "cpe:2.3:a:socks-proxy-agent:socks-proxy-agent:7.0.0:*:*:*:*:*:*:*",
112121          "purl": "pkg:npm/socks-proxy-agent@7.0.0",
112122          "swid": {
112123            "attachment": {}
112124          },
112125          "pedigree": {},
112126          "externalReferences": [
112127            {
112128              "url": "git://github.com/TooTallNate/node-socks-proxy-agent.git",
112129              "type": "distribution"
112130            },
112131            {
112132              "url": "https://github.com/TooTallNate/node-socks-proxy-agent#readme",
112133              "type": "website"
112134            }
112135          ],
112136          "evidence": {},
112137          "signature": {
112138            "signature": {
112139              "publicKey": {}
112140            }
112141          },
112142          "modelCard": {
112143            "modelParameters": {
112144              "approach": {}
112145            },
112146            "quantitativeAnalysis": {
112147              "graphics": {}
112148            },
112149            "considerations": {}
112150          }
112151        },
112152        {
112153          "type": "library",
112154          "bom-ref": "pkg:npm/spdx-correct@3.1.1?package-id=d6b0214947e454eb",
112155          "supplier": {},
112156          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
112157          "name": "spdx-correct",
112158          "version": "3.1.1",
112159          "description": "correct invalid SPDX expressions",
112160          "licenses": [
112161            {
112162              "license": {
112163                "id": "Apache-2.0"
112164              }
112165            }
112166          ],
112167          "cpe": "cpe:2.3:a:spdx-correct:spdx-correct:3.1.1:*:*:*:*:*:*:*",
112168          "purl": "pkg:npm/spdx-correct@3.1.1",
112169          "swid": {
112170            "attachment": {}
112171          },
112172          "pedigree": {},
112173          "externalReferences": [
112174            {
112175              "url": "jslicense/spdx-correct.js",
112176              "type": "distribution"
112177            }
112178          ],
112179          "evidence": {},
112180          "signature": {
112181            "signature": {
112182              "publicKey": {}
112183            }
112184          },
112185          "modelCard": {
112186            "modelParameters": {
112187              "approach": {}
112188            },
112189            "quantitativeAnalysis": {
112190              "graphics": {}
112191            },
112192            "considerations": {}
112193          }
112194        },
112195        {
112196          "type": "library",
112197          "bom-ref": "pkg:npm/spdx-exceptions@2.3.0?package-id=22aa1fb7c596c6c7",
112198          "supplier": {},
112199          "author": "The Linux Foundation",
112200          "name": "spdx-exceptions",
112201          "version": "2.3.0",
112202          "description": "list of SPDX standard license exceptions",
112203          "licenses": [
112204            {
112205              "license": {
112206                "id": "CC-BY-3.0"
112207              }
112208            }
112209          ],
112210          "cpe": "cpe:2.3:a:spdx-exceptions:spdx-exceptions:2.3.0:*:*:*:*:*:*:*",
112211          "purl": "pkg:npm/spdx-exceptions@2.3.0",
112212          "swid": {
112213            "attachment": {}
112214          },
112215          "pedigree": {},
112216          "externalReferences": [
112217            {
112218              "url": "kemitchell/spdx-exceptions.json",
112219              "type": "distribution"
112220            }
112221          ],
112222          "evidence": {},
112223          "signature": {
112224            "signature": {
112225              "publicKey": {}
112226            }
112227          },
112228          "modelCard": {
112229            "modelParameters": {
112230              "approach": {}
112231            },
112232            "quantitativeAnalysis": {
112233              "graphics": {}
112234            },
112235            "considerations": {}
112236          }
112237        },
112238        {
112239          "type": "library",
112240          "bom-ref": "pkg:npm/spdx-expression-parse@3.0.1?package-id=78c73c9b189e2783",
112241          "supplier": {},
112242          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
112243          "name": "spdx-expression-parse",
112244          "version": "3.0.1",
112245          "description": "parse SPDX license expressions",
112246          "licenses": [
112247            {
112248              "license": {
112249                "id": "MIT"
112250              }
112251            }
112252          ],
112253          "cpe": "cpe:2.3:a:spdx-expression-parse:spdx-expression-parse:3.0.1:*:*:*:*:*:*:*",
112254          "purl": "pkg:npm/spdx-expression-parse@3.0.1",
112255          "swid": {
112256            "attachment": {}
112257          },
112258          "pedigree": {},
112259          "externalReferences": [
112260            {
112261              "url": "jslicense/spdx-expression-parse.js",
112262              "type": "distribution"
112263            }
112264          ],
112265          "evidence": {},
112266          "signature": {
112267            "signature": {
112268              "publicKey": {}
112269            }
112270          },
112271          "modelCard": {
112272            "modelParameters": {
112273              "approach": {}
112274            },
112275            "quantitativeAnalysis": {
112276              "graphics": {}
112277            },
112278            "considerations": {}
112279          }
112280        },
112281        {
112282          "type": "library",
112283          "bom-ref": "pkg:npm/spdx-license-ids@3.0.11?package-id=6530ac28616ec508",
112284          "supplier": {},
112285          "author": "Shinnosuke Watanabe (https://github.com/shinnn)",
112286          "name": "spdx-license-ids",
112287          "version": "3.0.11",
112288          "description": "A list of SPDX license identifiers",
112289          "licenses": [
112290            {
112291              "license": {
112292                "id": "CC0-1.0"
112293              }
112294            }
112295          ],
112296          "cpe": "cpe:2.3:a:spdx-license-ids:spdx-license-ids:3.0.11:*:*:*:*:*:*:*",
112297          "purl": "pkg:npm/spdx-license-ids@3.0.11",
112298          "swid": {
112299            "attachment": {}
112300          },
112301          "pedigree": {},
112302          "externalReferences": [
112303            {
112304              "url": "jslicense/spdx-license-ids",
112305              "type": "distribution"
112306            }
112307          ],
112308          "evidence": {},
112309          "signature": {
112310            "signature": {
112311              "publicKey": {}
112312            }
112313          },
112314          "modelCard": {
112315            "modelParameters": {
112316              "approach": {}
112317            },
112318            "quantitativeAnalysis": {
112319              "graphics": {}
112320            },
112321            "considerations": {}
112322          }
112323        },
112324        {
112325          "type": "library",
112326          "bom-ref": "pkg:npm/split-on-first@1.1.0?package-id=9078f4eb65562991",
112327          "supplier": {},
112328          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
112329          "name": "split-on-first",
112330          "version": "1.1.0",
112331          "description": "Split a string on the first occurance of a given separator",
112332          "licenses": [
112333            {
112334              "license": {
112335                "id": "MIT"
112336              }
112337            }
112338          ],
112339          "cpe": "cpe:2.3:a:split-on-first:split-on-first:1.1.0:*:*:*:*:*:*:*",
112340          "purl": "pkg:npm/split-on-first@1.1.0",
112341          "swid": {
112342            "attachment": {}
112343          },
112344          "pedigree": {},
112345          "externalReferences": [
112346            {
112347              "url": "sindresorhus/split-on-first",
112348              "type": "distribution"
112349            }
112350          ],
112351          "evidence": {},
112352          "signature": {
112353            "signature": {
112354              "publicKey": {}
112355            }
112356          },
112357          "modelCard": {
112358            "modelParameters": {
112359              "approach": {}
112360            },
112361            "quantitativeAnalysis": {
112362              "graphics": {}
112363            },
112364            "considerations": {}
112365          }
112366        },
112367        {
112368          "type": "library",
112369          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5\u0026package-id=674d1e2fba4d633a",
112370          "supplier": {},
112371          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
112372          "name": "ssl_client",
112373          "version": "1.35.0-r17",
112374          "description": "EXternal ssl_client for busybox wget",
112375          "licenses": [
112376            {
112377              "license": {
112378                "id": "GPL-2.0-only"
112379              }
112380            }
112381          ],
112382          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r17:*:*:*:*:*:*:*",
112383          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5",
112384          "swid": {
112385            "attachment": {}
112386          },
112387          "pedigree": {},
112388          "externalReferences": [
112389            {
112390              "url": "https://busybox.net/",
112391              "type": "distribution"
112392            }
112393          ],
112394          "evidence": {},
112395          "signature": {
112396            "signature": {
112397              "publicKey": {}
112398            }
112399          },
112400          "modelCard": {
112401            "modelParameters": {
112402              "approach": {}
112403            },
112404            "quantitativeAnalysis": {
112405              "graphics": {}
112406            },
112407            "considerations": {}
112408          }
112409        },
112410        {
112411          "type": "library",
112412          "bom-ref": "pkg:npm/ssri@9.0.1?package-id=49986701356bf646",
112413          "supplier": {},
112414          "author": "GitHub Inc.",
112415          "name": "ssri",
112416          "version": "9.0.1",
112417          "description": "Standard Subresource Integrity library -- parses, serializes, generates, and verifies integrity metadata according to the SRI spec.",
112418          "licenses": [
112419            {
112420              "license": {
112421                "id": "ISC"
112422              }
112423            }
112424          ],
112425          "cpe": "cpe:2.3:a:ssri:ssri:9.0.1:*:*:*:*:*:*:*",
112426          "purl": "pkg:npm/ssri@9.0.1",
112427          "swid": {
112428            "attachment": {}
112429          },
112430          "pedigree": {},
112431          "externalReferences": [
112432            {
112433              "url": "https://github.com/npm/ssri.git",
112434              "type": "distribution"
112435            }
112436          ],
112437          "evidence": {},
112438          "signature": {
112439            "signature": {
112440              "publicKey": {}
112441            }
112442          },
112443          "modelCard": {
112444            "modelParameters": {
112445              "approach": {}
112446            },
112447            "quantitativeAnalysis": {
112448              "graphics": {}
112449            },
112450            "considerations": {}
112451          }
112452        },
112453        {
112454          "type": "library",
112455          "bom-ref": "pkg:npm/statuses@1.4.0?package-id=1492f259b23a7535",
112456          "supplier": {},
112457          "name": "statuses",
112458          "version": "1.4.0",
112459          "description": "HTTP status utility",
112460          "licenses": [
112461            {
112462              "license": {
112463                "id": "MIT"
112464              }
112465            }
112466          ],
112467          "cpe": "cpe:2.3:a:statuses:statuses:1.4.0:*:*:*:*:*:*:*",
112468          "purl": "pkg:npm/statuses@1.4.0",
112469          "swid": {
112470            "attachment": {}
112471          },
112472          "pedigree": {},
112473          "externalReferences": [
112474            {
112475              "url": "jshttp/statuses",
112476              "type": "distribution"
112477            }
112478          ],
112479          "evidence": {},
112480          "signature": {
112481            "signature": {
112482              "publicKey": {}
112483            }
112484          },
112485          "modelCard": {
112486            "modelParameters": {
112487              "approach": {}
112488            },
112489            "quantitativeAnalysis": {
112490              "graphics": {}
112491            },
112492            "considerations": {}
112493          }
112494        },
112495        {
112496          "type": "library",
112497          "bom-ref": "pkg:npm/strict-uri-encode@2.0.0?package-id=b7d67cfb18e7450a",
112498          "supplier": {},
112499          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
112500          "name": "strict-uri-encode",
112501          "version": "2.0.0",
112502          "description": "A stricter URI encode adhering to RFC 3986",
112503          "licenses": [
112504            {
112505              "license": {
112506                "id": "MIT"
112507              }
112508            }
112509          ],
112510          "cpe": "cpe:2.3:a:strict-uri-encode:strict-uri-encode:2.0.0:*:*:*:*:*:*:*",
112511          "purl": "pkg:npm/strict-uri-encode@2.0.0",
112512          "swid": {
112513            "attachment": {}
112514          },
112515          "pedigree": {},
112516          "externalReferences": [
112517            {
112518              "url": "kevva/strict-uri-encode",
112519              "type": "distribution"
112520            }
112521          ],
112522          "evidence": {},
112523          "signature": {
112524            "signature": {
112525              "publicKey": {}
112526            }
112527          },
112528          "modelCard": {
112529            "modelParameters": {
112530              "approach": {}
112531            },
112532            "quantitativeAnalysis": {
112533              "graphics": {}
112534            },
112535            "considerations": {}
112536          }
112537        },
112538        {
112539          "type": "library",
112540          "bom-ref": "pkg:npm/string-width@4.2.3?package-id=c50e61a77e3ea809",
112541          "supplier": {},
112542          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
112543          "name": "string-width",
112544          "version": "4.2.3",
112545          "description": "Get the visual width of a string - the number of columns required to display it",
112546          "licenses": [
112547            {
112548              "license": {
112549                "id": "MIT"
112550              }
112551            }
112552          ],
112553          "cpe": "cpe:2.3:a:string-width:string-width:4.2.3:*:*:*:*:*:*:*",
112554          "purl": "pkg:npm/string-width@4.2.3",
112555          "swid": {
112556            "attachment": {}
112557          },
112558          "pedigree": {},
112559          "externalReferences": [
112560            {
112561              "url": "sindresorhus/string-width",
112562              "type": "distribution"
112563            }
112564          ],
112565          "evidence": {},
112566          "signature": {
112567            "signature": {
112568              "publicKey": {}
112569            }
112570          },
112571          "modelCard": {
112572            "modelParameters": {
112573              "approach": {}
112574            },
112575            "quantitativeAnalysis": {
112576              "graphics": {}
112577            },
112578            "considerations": {}
112579          }
112580        },
112581        {
112582          "type": "library",
112583          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=ca8af4aa6b41ca75",
112584          "supplier": {},
112585          "name": "string_decoder",
112586          "version": "1.3.0",
112587          "description": "The string_decoder module from Node core",
112588          "licenses": [
112589            {
112590              "license": {
112591                "id": "MIT"
112592              }
112593            }
112594          ],
112595          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
112596          "purl": "pkg:npm/string_decoder@1.3.0",
112597          "swid": {
112598            "attachment": {}
112599          },
112600          "pedigree": {},
112601          "externalReferences": [
112602            {
112603              "url": "git://github.com/nodejs/string_decoder.git",
112604              "type": "distribution"
112605            },
112606            {
112607              "url": "https://github.com/nodejs/string_decoder",
112608              "type": "website"
112609            }
112610          ],
112611          "evidence": {},
112612          "signature": {
112613            "signature": {
112614              "publicKey": {}
112615            }
112616          },
112617          "modelCard": {
112618            "modelParameters": {
112619              "approach": {}
112620            },
112621            "quantitativeAnalysis": {
112622              "graphics": {}
112623            },
112624            "considerations": {}
112625          }
112626        },
112627        {
112628          "type": "library",
112629          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=4416d34ed115d469",
112630          "supplier": {},
112631          "name": "string_decoder",
112632          "version": "1.3.0",
112633          "description": "The string_decoder module from Node core",
112634          "licenses": [
112635            {
112636              "license": {
112637                "id": "MIT"
112638              }
112639            }
112640          ],
112641          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
112642          "purl": "pkg:npm/string_decoder@1.3.0",
112643          "swid": {
112644            "attachment": {}
112645          },
112646          "pedigree": {},
112647          "externalReferences": [
112648            {
112649              "url": "git://github.com/nodejs/string_decoder.git",
112650              "type": "distribution"
112651            },
112652            {
112653              "url": "https://github.com/nodejs/string_decoder",
112654              "type": "website"
112655            }
112656          ],
112657          "evidence": {},
112658          "signature": {
112659            "signature": {
112660              "publicKey": {}
112661            }
112662          },
112663          "modelCard": {
112664            "modelParameters": {
112665              "approach": {}
112666            },
112667            "quantitativeAnalysis": {
112668              "graphics": {}
112669            },
112670            "considerations": {}
112671          }
112672        },
112673        {
112674          "type": "library",
112675          "bom-ref": "pkg:npm/strip-ansi@6.0.1?package-id=5ec73c7d72940ceb",
112676          "supplier": {},
112677          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
112678          "name": "strip-ansi",
112679          "version": "6.0.1",
112680          "description": "Strip ANSI escape codes from a string",
112681          "licenses": [
112682            {
112683              "license": {
112684                "id": "MIT"
112685              }
112686            }
112687          ],
112688          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:6.0.1:*:*:*:*:*:*:*",
112689          "purl": "pkg:npm/strip-ansi@6.0.1",
112690          "swid": {
112691            "attachment": {}
112692          },
112693          "pedigree": {},
112694          "externalReferences": [
112695            {
112696              "url": "chalk/strip-ansi",
112697              "type": "distribution"
112698            }
112699          ],
112700          "evidence": {},
112701          "signature": {
112702            "signature": {
112703              "publicKey": {}
112704            }
112705          },
112706          "modelCard": {
112707            "modelParameters": {
112708              "approach": {}
112709            },
112710            "quantitativeAnalysis": {
112711              "graphics": {}
112712            },
112713            "considerations": {}
112714          }
112715        },
112716        {
112717          "type": "library",
112718          "bom-ref": "pkg:npm/strnum@1.0.5?package-id=c3c9931116de06dd",
112719          "supplier": {},
112720          "author": "Amit Gupta (https://amitkumargupta.work/)",
112721          "name": "strnum",
112722          "version": "1.0.5",
112723          "description": "Parse String to Number based on configuration",
112724          "licenses": [
112725            {
112726              "license": {
112727                "id": "MIT"
112728              }
112729            }
112730          ],
112731          "cpe": "cpe:2.3:a:NaturalIntelligence:strnum:1.0.5:*:*:*:*:*:*:*",
112732          "purl": "pkg:npm/strnum@1.0.5",
112733          "swid": {
112734            "attachment": {}
112735          },
112736          "pedigree": {},
112737          "externalReferences": [
112738            {
112739              "url": "https://github.com/NaturalIntelligence/strnum",
112740              "type": "distribution"
112741            }
112742          ],
112743          "evidence": {},
112744          "signature": {
112745            "signature": {
112746              "publicKey": {}
112747            }
112748          },
112749          "modelCard": {
112750            "modelParameters": {
112751              "approach": {}
112752            },
112753            "quantitativeAnalysis": {
112754              "graphics": {}
112755            },
112756            "considerations": {}
112757          }
112758        },
112759        {
112760          "type": "library",
112761          "bom-ref": "pkg:npm/supports-color@7.2.0?package-id=4c97deb16c788c95",
112762          "supplier": {},
112763          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
112764          "name": "supports-color",
112765          "version": "7.2.0",
112766          "description": "Detect whether a terminal supports color",
112767          "licenses": [
112768            {
112769              "license": {
112770                "id": "MIT"
112771              }
112772            }
112773          ],
112774          "cpe": "cpe:2.3:a:supports-color:supports-color:7.2.0:*:*:*:*:*:*:*",
112775          "purl": "pkg:npm/supports-color@7.2.0",
112776          "swid": {
112777            "attachment": {}
112778          },
112779          "pedigree": {},
112780          "externalReferences": [
112781            {
112782              "url": "chalk/supports-color",
112783              "type": "distribution"
112784            }
112785          ],
112786          "evidence": {},
112787          "signature": {
112788            "signature": {
112789              "publicKey": {}
112790            }
112791          },
112792          "modelCard": {
112793            "modelParameters": {
112794              "approach": {}
112795            },
112796            "quantitativeAnalysis": {
112797              "graphics": {}
112798            },
112799            "considerations": {}
112800          }
112801        },
112802        {
112803          "type": "library",
112804          "bom-ref": "pkg:npm/supports-color@7.2.0?package-id=7fc54f33952b6e18",
112805          "supplier": {},
112806          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
112807          "name": "supports-color",
112808          "version": "7.2.0",
112809          "description": "Detect whether a terminal supports color",
112810          "licenses": [
112811            {
112812              "license": {
112813                "id": "MIT"
112814              }
112815            }
112816          ],
112817          "cpe": "cpe:2.3:a:supports-color:supports-color:7.2.0:*:*:*:*:*:*:*",
112818          "purl": "pkg:npm/supports-color@7.2.0",
112819          "swid": {
112820            "attachment": {}
112821          },
112822          "pedigree": {},
112823          "externalReferences": [
112824            {
112825              "url": "chalk/supports-color",
112826              "type": "distribution"
112827            }
112828          ],
112829          "evidence": {},
112830          "signature": {
112831            "signature": {
112832              "publicKey": {}
112833            }
112834          },
112835          "modelCard": {
112836            "modelParameters": {
112837              "approach": {}
112838            },
112839            "quantitativeAnalysis": {
112840              "graphics": {}
112841            },
112842            "considerations": {}
112843          }
112844        },
112845        {
112846          "type": "library",
112847          "bom-ref": "pkg:npm/supports-preserve-symlinks-flag@1.0.0?package-id=63de1d09c9944553",
112848          "supplier": {},
112849          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
112850          "name": "supports-preserve-symlinks-flag",
112851          "version": "1.0.0",
112852          "description": "Determine if the current node version supports the `--preserve-symlinks` flag.",
112853          "licenses": [
112854            {
112855              "license": {
112856                "id": "MIT"
112857              }
112858            }
112859          ],
112860          "cpe": "cpe:2.3:a:supports-preserve-symlinks-flag:supports-preserve-symlinks-flag:1.0.0:*:*:*:*:*:*:*",
112861          "purl": "pkg:npm/supports-preserve-symlinks-flag@1.0.0",
112862          "swid": {
112863            "attachment": {}
112864          },
112865          "pedigree": {},
112866          "externalReferences": [
112867            {
112868              "url": "git+https://github.com/inspect-js/node-supports-preserve-symlinks-flag.git",
112869              "type": "distribution"
112870            },
112871            {
112872              "url": "https://github.com/inspect-js/node-supports-preserve-symlinks-flag#readme",
112873              "type": "website"
112874            }
112875          ],
112876          "evidence": {},
112877          "signature": {
112878            "signature": {
112879              "publicKey": {}
112880            }
112881          },
112882          "modelCard": {
112883            "modelParameters": {
112884              "approach": {}
112885            },
112886            "quantitativeAnalysis": {
112887              "graphics": {}
112888            },
112889            "considerations": {}
112890          }
112891        },
112892        {
112893          "type": "library",
112894          "bom-ref": "pkg:npm/tar@5.0.11?package-id=d8c4bfab58684e14",
112895          "supplier": {},
112896          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
112897          "name": "tar",
112898          "version": "5.0.11",
112899          "description": "tar for node",
112900          "licenses": [
112901            {
112902              "license": {
112903                "id": "ISC"
112904              }
112905            }
112906          ],
112907          "cpe": "cpe:2.3:a:npm:tar:5.0.11:*:*:*:*:*:*:*",
112908          "purl": "pkg:npm/tar@5.0.11",
112909          "swid": {
112910            "attachment": {}
112911          },
112912          "pedigree": {},
112913          "externalReferences": [
112914            {
112915              "url": "https://github.com/npm/node-tar.git",
112916              "type": "distribution"
112917            }
112918          ],
112919          "evidence": {},
112920          "signature": {
112921            "signature": {
112922              "publicKey": {}
112923            }
112924          },
112925          "modelCard": {
112926            "modelParameters": {
112927              "approach": {}
112928            },
112929            "quantitativeAnalysis": {
112930              "graphics": {}
112931            },
112932            "considerations": {}
112933          }
112934        },
112935        {
112936          "type": "library",
112937          "bom-ref": "pkg:npm/tar@6.1.11?package-id=97823590d9da9c9f",
112938          "supplier": {},
112939          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
112940          "name": "tar",
112941          "version": "6.1.11",
112942          "description": "tar for node",
112943          "licenses": [
112944            {
112945              "license": {
112946                "id": "ISC"
112947              }
112948            }
112949          ],
112950          "cpe": "cpe:2.3:a:npm:tar:6.1.11:*:*:*:*:*:*:*",
112951          "purl": "pkg:npm/tar@6.1.11",
112952          "swid": {
112953            "attachment": {}
112954          },
112955          "pedigree": {},
112956          "externalReferences": [
112957            {
112958              "url": "https://github.com/npm/node-tar.git",
112959              "type": "distribution"
112960            }
112961          ],
112962          "evidence": {},
112963          "signature": {
112964            "signature": {
112965              "publicKey": {}
112966            }
112967          },
112968          "modelCard": {
112969            "modelParameters": {
112970              "approach": {}
112971            },
112972            "quantitativeAnalysis": {
112973              "graphics": {}
112974            },
112975            "considerations": {}
112976          }
112977        },
112978        {
112979          "type": "library",
112980          "bom-ref": "pkg:npm/text-table@0.2.0?package-id=a124be9ad599668f",
112981          "supplier": {},
112982          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
112983          "name": "text-table",
112984          "version": "0.2.0",
112985          "description": "borderless text tables with alignment",
112986          "licenses": [
112987            {
112988              "license": {
112989                "id": "MIT"
112990              }
112991            }
112992          ],
112993          "cpe": "cpe:2.3:a:text-table:text-table:0.2.0:*:*:*:*:*:*:*",
112994          "purl": "pkg:npm/text-table@0.2.0",
112995          "swid": {
112996            "attachment": {}
112997          },
112998          "pedigree": {},
112999          "externalReferences": [
113000            {
113001              "url": "git://github.com/substack/text-table.git",
113002              "type": "distribution"
113003            },
113004            {
113005              "url": "https://github.com/substack/text-table",
113006              "type": "website"
113007            }
113008          ],
113009          "evidence": {},
113010          "signature": {
113011            "signature": {
113012              "publicKey": {}
113013            }
113014          },
113015          "modelCard": {
113016            "modelParameters": {
113017              "approach": {}
113018            },
113019            "quantitativeAnalysis": {
113020              "graphics": {}
113021            },
113022            "considerations": {}
113023          }
113024        },
113025        {
113026          "type": "library",
113027          "bom-ref": "pkg:npm/through2@3.0.2?package-id=c9d63645e4d241f4",
113028          "supplier": {},
113029          "author": "Rod Vagg \u003cr@va.gg\u003e (https://github.com/rvagg)",
113030          "name": "through2",
113031          "version": "3.0.2",
113032          "description": "A tiny wrapper around Node.js streams.Transform (Streams2/3) to avoid explicit subclassing noise",
113033          "licenses": [
113034            {
113035              "license": {
113036                "id": "MIT"
113037              }
113038            }
113039          ],
113040          "cpe": "cpe:2.3:a:through2:through2:3.0.2:*:*:*:*:*:*:*",
113041          "purl": "pkg:npm/through2@3.0.2",
113042          "swid": {
113043            "attachment": {}
113044          },
113045          "pedigree": {},
113046          "externalReferences": [
113047            {
113048              "url": "https://github.com/rvagg/through2.git",
113049              "type": "distribution"
113050            }
113051          ],
113052          "evidence": {},
113053          "signature": {
113054            "signature": {
113055              "publicKey": {}
113056            }
113057          },
113058          "modelCard": {
113059            "modelParameters": {
113060              "approach": {}
113061            },
113062            "quantitativeAnalysis": {
113063              "graphics": {}
113064            },
113065            "considerations": {}
113066          }
113067        },
113068        {
113069          "type": "library",
113070          "bom-ref": "pkg:npm/tiny-relative-date@1.3.0?package-id=bc2a707c455ba496",
113071          "supplier": {},
113072          "author": "Joseph Wynn \u003cjoseph@wildlyinaccurate.com\u003e (https://wildlyinaccurate.com/)",
113073          "name": "tiny-relative-date",
113074          "version": "1.3.0",
113075          "description": "Tiny function that provides relative, human-readable dates.",
113076          "licenses": [
113077            {
113078              "license": {
113079                "id": "MIT"
113080              }
113081            }
113082          ],
113083          "cpe": "cpe:2.3:a:tiny-relative-date:tiny-relative-date:1.3.0:*:*:*:*:*:*:*",
113084          "purl": "pkg:npm/tiny-relative-date@1.3.0",
113085          "swid": {
113086            "attachment": {}
113087          },
113088          "pedigree": {},
113089          "externalReferences": [
113090            {
113091              "url": "https://github.com/wildlyinaccurate/relative-date.git",
113092              "type": "distribution"
113093            }
113094          ],
113095          "evidence": {},
113096          "signature": {
113097            "signature": {
113098              "publicKey": {}
113099            }
113100          },
113101          "modelCard": {
113102            "modelParameters": {
113103              "approach": {}
113104            },
113105            "quantitativeAnalysis": {
113106              "graphics": {}
113107            },
113108            "considerations": {}
113109          }
113110        },
113111        {
113112          "type": "library",
113113          "bom-ref": "pkg:npm/tmp@0.0.33?package-id=2d9105ed84cc1ba8",
113114          "supplier": {},
113115          "author": "KARASZI István \u003cgithub@spam.raszi.hu\u003e (http://raszi.hu/)",
113116          "name": "tmp",
113117          "version": "0.0.33",
113118          "description": "Temporary file and directory creator",
113119          "licenses": [
113120            {
113121              "license": {
113122                "id": "MIT"
113123              }
113124            }
113125          ],
113126          "cpe": "cpe:2.3:a:raszi:tmp:0.0.33:*:*:*:*:*:*:*",
113127          "purl": "pkg:npm/tmp@0.0.33",
113128          "swid": {
113129            "attachment": {}
113130          },
113131          "pedigree": {},
113132          "externalReferences": [
113133            {
113134              "url": "raszi/node-tmp",
113135              "type": "distribution"
113136            },
113137            {
113138              "url": "http://github.com/raszi/node-tmp",
113139              "type": "website"
113140            }
113141          ],
113142          "evidence": {},
113143          "signature": {
113144            "signature": {
113145              "publicKey": {}
113146            }
113147          },
113148          "modelCard": {
113149            "modelParameters": {
113150              "approach": {}
113151            },
113152            "quantitativeAnalysis": {
113153              "graphics": {}
113154            },
113155            "considerations": {}
113156          }
113157        },
113158        {
113159          "type": "library",
113160          "bom-ref": "pkg:npm/to-regex-range@5.0.1?package-id=c4db027f11f76276",
113161          "supplier": {},
113162          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
113163          "name": "to-regex-range",
113164          "version": "5.0.1",
113165          "description": "Pass two numbers, get a regex-compatible source string for matching ranges. Validated against more than 2.78 million test assertions.",
113166          "licenses": [
113167            {
113168              "license": {
113169                "id": "MIT"
113170              }
113171            }
113172          ],
113173          "cpe": "cpe:2.3:a:to-regex-range:to-regex-range:5.0.1:*:*:*:*:*:*:*",
113174          "purl": "pkg:npm/to-regex-range@5.0.1",
113175          "swid": {
113176            "attachment": {}
113177          },
113178          "pedigree": {},
113179          "externalReferences": [
113180            {
113181              "url": "micromatch/to-regex-range",
113182              "type": "distribution"
113183            },
113184            {
113185              "url": "https://github.com/micromatch/to-regex-range",
113186              "type": "website"
113187            }
113188          ],
113189          "evidence": {},
113190          "signature": {
113191            "signature": {
113192              "publicKey": {}
113193            }
113194          },
113195          "modelCard": {
113196            "modelParameters": {
113197              "approach": {}
113198            },
113199            "quantitativeAnalysis": {
113200              "graphics": {}
113201            },
113202            "considerations": {}
113203          }
113204        },
113205        {
113206          "type": "library",
113207          "bom-ref": "pkg:npm/treeverse@2.0.0?package-id=283d5c0745aa3ce7",
113208          "supplier": {},
113209          "author": "GitHub Inc.",
113210          "name": "treeverse",
113211          "version": "2.0.0",
113212          "description": "Walk any kind of tree structure depth- or breadth-first. Supports promises and advanced map-reduce operations with a very small API.",
113213          "licenses": [
113214            {
113215              "license": {
113216                "id": "ISC"
113217              }
113218            }
113219          ],
113220          "cpe": "cpe:2.3:a:treeverse:treeverse:2.0.0:*:*:*:*:*:*:*",
113221          "purl": "pkg:npm/treeverse@2.0.0",
113222          "swid": {
113223            "attachment": {}
113224          },
113225          "pedigree": {},
113226          "externalReferences": [
113227            {
113228              "url": "https://github.com/npm/treeverse.git",
113229              "type": "distribution"
113230            }
113231          ],
113232          "evidence": {},
113233          "signature": {
113234            "signature": {
113235              "publicKey": {}
113236            }
113237          },
113238          "modelCard": {
113239            "modelParameters": {
113240              "approach": {}
113241            },
113242            "quantitativeAnalysis": {
113243              "graphics": {}
113244            },
113245            "considerations": {}
113246          }
113247        },
113248        {
113249          "type": "library",
113250          "bom-ref": "pkg:npm/type-is@1.6.18?package-id=5bdf50fc9a89514f",
113251          "supplier": {},
113252          "name": "type-is",
113253          "version": "1.6.18",
113254          "description": "Infer the content-type of a request.",
113255          "licenses": [
113256            {
113257              "license": {
113258                "id": "MIT"
113259              }
113260            }
113261          ],
113262          "cpe": "cpe:2.3:a:type-is:type-is:1.6.18:*:*:*:*:*:*:*",
113263          "purl": "pkg:npm/type-is@1.6.18",
113264          "swid": {
113265            "attachment": {}
113266          },
113267          "pedigree": {},
113268          "externalReferences": [
113269            {
113270              "url": "jshttp/type-is",
113271              "type": "distribution"
113272            }
113273          ],
113274          "evidence": {},
113275          "signature": {
113276            "signature": {
113277              "publicKey": {}
113278            }
113279          },
113280          "modelCard": {
113281            "modelParameters": {
113282              "approach": {}
113283            },
113284            "quantitativeAnalysis": {
113285              "graphics": {}
113286            },
113287            "considerations": {}
113288          }
113289        },
113290        {
113291          "type": "library",
113292          "bom-ref": "pkg:npm/unique-filename@2.0.1?package-id=ddbea63cf5bc0343",
113293          "supplier": {},
113294          "author": "GitHub Inc.",
113295          "name": "unique-filename",
113296          "version": "2.0.1",
113297          "description": "Generate a unique filename for use in temporary directories or caches.",
113298          "licenses": [
113299            {
113300              "license": {
113301                "id": "ISC"
113302              }
113303            }
113304          ],
113305          "cpe": "cpe:2.3:a:unique-filename:unique-filename:2.0.1:*:*:*:*:*:*:*",
113306          "purl": "pkg:npm/unique-filename@2.0.1",
113307          "swid": {
113308            "attachment": {}
113309          },
113310          "pedigree": {},
113311          "externalReferences": [
113312            {
113313              "url": "https://github.com/npm/unique-filename.git",
113314              "type": "distribution"
113315            },
113316            {
113317              "url": "https://github.com/iarna/unique-filename",
113318              "type": "website"
113319            }
113320          ],
113321          "evidence": {},
113322          "signature": {
113323            "signature": {
113324              "publicKey": {}
113325            }
113326          },
113327          "modelCard": {
113328            "modelParameters": {
113329              "approach": {}
113330            },
113331            "quantitativeAnalysis": {
113332              "graphics": {}
113333            },
113334            "considerations": {}
113335          }
113336        },
113337        {
113338          "type": "library",
113339          "bom-ref": "pkg:npm/unique-slug@3.0.0?package-id=a61e6b90d7850f42",
113340          "supplier": {},
113341          "author": "GitHub Inc.",
113342          "name": "unique-slug",
113343          "version": "3.0.0",
113344          "description": "Generate a unique character string suitible for use in files and URLs.",
113345          "licenses": [
113346            {
113347              "license": {
113348                "id": "ISC"
113349              }
113350            }
113351          ],
113352          "cpe": "cpe:2.3:a:unique-slug:unique-slug:3.0.0:*:*:*:*:*:*:*",
113353          "purl": "pkg:npm/unique-slug@3.0.0",
113354          "swid": {
113355            "attachment": {}
113356          },
113357          "pedigree": {},
113358          "externalReferences": [
113359            {
113360              "url": "https://github.com/npm/unique-slug.git",
113361              "type": "distribution"
113362            }
113363          ],
113364          "evidence": {},
113365          "signature": {
113366            "signature": {
113367              "publicKey": {}
113368            }
113369          },
113370          "modelCard": {
113371            "modelParameters": {
113372              "approach": {}
113373            },
113374            "quantitativeAnalysis": {
113375              "graphics": {}
113376            },
113377            "considerations": {}
113378          }
113379        },
113380        {
113381          "type": "library",
113382          "bom-ref": "pkg:npm/universalify@0.1.2?package-id=69eed8a5747afb4f",
113383          "supplier": {},
113384          "author": "Ryan Zimmerman \u003copensrc@ryanzim.com\u003e",
113385          "name": "universalify",
113386          "version": "0.1.2",
113387          "description": "Make a callback- or promise-based function support both promises and callbacks.",
113388          "licenses": [
113389            {
113390              "license": {
113391                "id": "MIT"
113392              }
113393            }
113394          ],
113395          "cpe": "cpe:2.3:a:universalify:universalify:0.1.2:*:*:*:*:*:*:*",
113396          "purl": "pkg:npm/universalify@0.1.2",
113397          "swid": {
113398            "attachment": {}
113399          },
113400          "pedigree": {},
113401          "externalReferences": [
113402            {
113403              "url": "git+https://github.com/RyanZim/universalify.git",
113404              "type": "distribution"
113405            },
113406            {
113407              "url": "https://github.com/RyanZim/universalify#readme",
113408              "type": "website"
113409            }
113410          ],
113411          "evidence": {},
113412          "signature": {
113413            "signature": {
113414              "publicKey": {}
113415            }
113416          },
113417          "modelCard": {
113418            "modelParameters": {
113419              "approach": {}
113420            },
113421            "quantitativeAnalysis": {
113422              "graphics": {}
113423            },
113424            "considerations": {}
113425          }
113426        },
113427        {
113428          "type": "library",
113429          "bom-ref": "pkg:npm/universalify@2.0.0?package-id=3e639cd947ec6ac2",
113430          "supplier": {},
113431          "author": "Ryan Zimmerman \u003copensrc@ryanzim.com\u003e",
113432          "name": "universalify",
113433          "version": "2.0.0",
113434          "description": "Make a callback- or promise-based function support both promises and callbacks.",
113435          "licenses": [
113436            {
113437              "license": {
113438                "id": "MIT"
113439              }
113440            }
113441          ],
113442          "cpe": "cpe:2.3:a:universalify:universalify:2.0.0:*:*:*:*:*:*:*",
113443          "purl": "pkg:npm/universalify@2.0.0",
113444          "swid": {
113445            "attachment": {}
113446          },
113447          "pedigree": {},
113448          "externalReferences": [
113449            {
113450              "url": "git+https://github.com/RyanZim/universalify.git",
113451              "type": "distribution"
113452            },
113453            {
113454              "url": "https://github.com/RyanZim/universalify#readme",
113455              "type": "website"
113456            }
113457          ],
113458          "evidence": {},
113459          "signature": {
113460            "signature": {
113461              "publicKey": {}
113462            }
113463          },
113464          "modelCard": {
113465            "modelParameters": {
113466              "approach": {}
113467            },
113468            "quantitativeAnalysis": {
113469              "graphics": {}
113470            },
113471            "considerations": {}
113472          }
113473        },
113474        {
113475          "type": "library",
113476          "bom-ref": "pkg:npm/unpipe@1.0.0?package-id=c584cebc0a9824f4",
113477          "supplier": {},
113478          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
113479          "name": "unpipe",
113480          "version": "1.0.0",
113481          "description": "Unpipe a stream from all destinations",
113482          "licenses": [
113483            {
113484              "license": {
113485                "id": "MIT"
113486              }
113487            }
113488          ],
113489          "cpe": "cpe:2.3:a:unpipe:unpipe:1.0.0:*:*:*:*:*:*:*",
113490          "purl": "pkg:npm/unpipe@1.0.0",
113491          "swid": {
113492            "attachment": {}
113493          },
113494          "pedigree": {},
113495          "externalReferences": [
113496            {
113497              "url": "stream-utils/unpipe",
113498              "type": "distribution"
113499            }
113500          ],
113501          "evidence": {},
113502          "signature": {
113503            "signature": {
113504              "publicKey": {}
113505            }
113506          },
113507          "modelCard": {
113508            "modelParameters": {
113509              "approach": {}
113510            },
113511            "quantitativeAnalysis": {
113512              "graphics": {}
113513            },
113514            "considerations": {}
113515          }
113516        },
113517        {
113518          "type": "library",
113519          "bom-ref": "pkg:npm/util@0.12.5?package-id=c6cd72c14d2409e5",
113520          "supplier": {},
113521          "author": "Joyent (http://www.joyent.com)",
113522          "name": "util",
113523          "version": "0.12.5",
113524          "description": "Node.js's util module for all engines",
113525          "licenses": [
113526            {
113527              "license": {
113528                "id": "MIT"
113529              }
113530            }
113531          ],
113532          "cpe": "cpe:2.3:a:browserify:util:0.12.5:*:*:*:*:*:*:*",
113533          "purl": "pkg:npm/util@0.12.5",
113534          "swid": {
113535            "attachment": {}
113536          },
113537          "pedigree": {},
113538          "externalReferences": [
113539            {
113540              "url": "git://github.com/browserify/node-util",
113541              "type": "distribution"
113542            },
113543            {
113544              "url": "https://github.com/browserify/node-util",
113545              "type": "website"
113546            }
113547          ],
113548          "evidence": {},
113549          "signature": {
113550            "signature": {
113551              "publicKey": {}
113552            }
113553          },
113554          "modelCard": {
113555            "modelParameters": {
113556              "approach": {}
113557            },
113558            "quantitativeAnalysis": {
113559              "graphics": {}
113560            },
113561            "considerations": {}
113562          }
113563        },
113564        {
113565          "type": "library",
113566          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=ecf076cf26fe73d0",
113567          "supplier": {},
113568          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
113569          "name": "util-deprecate",
113570          "version": "1.0.2",
113571          "description": "The Node.js `util.deprecate()` function with browser support",
113572          "licenses": [
113573            {
113574              "license": {
113575                "id": "MIT"
113576              }
113577            }
113578          ],
113579          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
113580          "purl": "pkg:npm/util-deprecate@1.0.2",
113581          "swid": {
113582            "attachment": {}
113583          },
113584          "pedigree": {},
113585          "externalReferences": [
113586            {
113587              "url": "git://github.com/TooTallNate/util-deprecate.git",
113588              "type": "distribution"
113589            },
113590            {
113591              "url": "https://github.com/TooTallNate/util-deprecate",
113592              "type": "website"
113593            }
113594          ],
113595          "evidence": {},
113596          "signature": {
113597            "signature": {
113598              "publicKey": {}
113599            }
113600          },
113601          "modelCard": {
113602            "modelParameters": {
113603              "approach": {}
113604            },
113605            "quantitativeAnalysis": {
113606              "graphics": {}
113607            },
113608            "considerations": {}
113609          }
113610        },
113611        {
113612          "type": "library",
113613          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=78a196ea3de81330",
113614          "supplier": {},
113615          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
113616          "name": "util-deprecate",
113617          "version": "1.0.2",
113618          "description": "The Node.js `util.deprecate()` function with browser support",
113619          "licenses": [
113620            {
113621              "license": {
113622                "id": "MIT"
113623              }
113624            }
113625          ],
113626          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
113627          "purl": "pkg:npm/util-deprecate@1.0.2",
113628          "swid": {
113629            "attachment": {}
113630          },
113631          "pedigree": {},
113632          "externalReferences": [
113633            {
113634              "url": "git://github.com/TooTallNate/util-deprecate.git",
113635              "type": "distribution"
113636            },
113637            {
113638              "url": "https://github.com/TooTallNate/util-deprecate",
113639              "type": "website"
113640            }
113641          ],
113642          "evidence": {},
113643          "signature": {
113644            "signature": {
113645              "publicKey": {}
113646            }
113647          },
113648          "modelCard": {
113649            "modelParameters": {
113650              "approach": {}
113651            },
113652            "quantitativeAnalysis": {
113653              "graphics": {}
113654            },
113655            "considerations": {}
113656          }
113657        },
113658        {
113659          "type": "library",
113660          "bom-ref": "pkg:npm/utils-merge@1.0.1?package-id=62471f9f4fe7cedd",
113661          "supplier": {},
113662          "author": "Jared Hanson \u003cjaredhanson@gmail.com\u003e (http://www.jaredhanson.net/)",
113663          "name": "utils-merge",
113664          "version": "1.0.1",
113665          "description": "merge() utility function",
113666          "licenses": [
113667            {
113668              "license": {
113669                "id": "MIT"
113670              }
113671            }
113672          ],
113673          "cpe": "cpe:2.3:a:jaredhanson:utils-merge:1.0.1:*:*:*:*:*:*:*",
113674          "purl": "pkg:npm/utils-merge@1.0.1",
113675          "swid": {
113676            "attachment": {}
113677          },
113678          "pedigree": {},
113679          "externalReferences": [
113680            {
113681              "url": "git://github.com/jaredhanson/utils-merge.git",
113682              "type": "distribution"
113683            }
113684          ],
113685          "evidence": {},
113686          "signature": {
113687            "signature": {
113688              "publicKey": {}
113689            }
113690          },
113691          "modelCard": {
113692            "modelParameters": {
113693              "approach": {}
113694            },
113695            "quantitativeAnalysis": {
113696              "graphics": {}
113697            },
113698            "considerations": {}
113699          }
113700        },
113701        {
113702          "type": "library",
113703          "bom-ref": "pkg:npm/uuid@3.4.0?package-id=3a7981c4b1d9183e",
113704          "supplier": {},
113705          "name": "uuid",
113706          "version": "3.4.0",
113707          "description": "RFC4122 (v1, v4, and v5) UUIDs",
113708          "licenses": [
113709            {
113710              "license": {
113711                "id": "MIT"
113712              }
113713            }
113714          ],
113715          "cpe": "cpe:2.3:a:uuidjs:uuid:3.4.0:*:*:*:*:*:*:*",
113716          "purl": "pkg:npm/uuid@3.4.0",
113717          "swid": {
113718            "attachment": {}
113719          },
113720          "pedigree": {},
113721          "externalReferences": [
113722            {
113723              "url": "https://github.com/uuidjs/uuid.git",
113724              "type": "distribution"
113725            }
113726          ],
113727          "evidence": {},
113728          "signature": {
113729            "signature": {
113730              "publicKey": {}
113731            }
113732          },
113733          "modelCard": {
113734            "modelParameters": {
113735              "approach": {}
113736            },
113737            "quantitativeAnalysis": {
113738              "graphics": {}
113739            },
113740            "considerations": {}
113741          }
113742        },
113743        {
113744          "type": "library",
113745          "bom-ref": "pkg:npm/validate-npm-package-license@3.0.4?package-id=fa90b625ec15ead",
113746          "supplier": {},
113747          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
113748          "name": "validate-npm-package-license",
113749          "version": "3.0.4",
113750          "description": "Give me a string and I'll tell you if it's a valid npm package license string",
113751          "licenses": [
113752            {
113753              "license": {
113754                "id": "Apache-2.0"
113755              }
113756            }
113757          ],
113758          "cpe": "cpe:2.3:a:validate-npm-package-license:validate-npm-package-license:3.0.4:*:*:*:*:*:*:*",
113759          "purl": "pkg:npm/validate-npm-package-license@3.0.4",
113760          "swid": {
113761            "attachment": {}
113762          },
113763          "pedigree": {},
113764          "externalReferences": [
113765            {
113766              "url": "kemitchell/validate-npm-package-license.js",
113767              "type": "distribution"
113768            }
113769          ],
113770          "evidence": {},
113771          "signature": {
113772            "signature": {
113773              "publicKey": {}
113774            }
113775          },
113776          "modelCard": {
113777            "modelParameters": {
113778              "approach": {}
113779            },
113780            "quantitativeAnalysis": {
113781              "graphics": {}
113782            },
113783            "considerations": {}
113784          }
113785        },
113786        {
113787          "type": "library",
113788          "bom-ref": "pkg:npm/validate-npm-package-name@4.0.0?package-id=dc3a9f2b7a700330",
113789          "supplier": {},
113790          "author": "GitHub Inc.",
113791          "name": "validate-npm-package-name",
113792          "version": "4.0.0",
113793          "description": "Give me a string and I'll tell you if it's a valid npm package name",
113794          "licenses": [
113795            {
113796              "license": {
113797                "id": "ISC"
113798              }
113799            }
113800          ],
113801          "cpe": "cpe:2.3:a:validate-npm-package-name:validate-npm-package-name:4.0.0:*:*:*:*:*:*:*",
113802          "purl": "pkg:npm/validate-npm-package-name@4.0.0",
113803          "swid": {
113804            "attachment": {}
113805          },
113806          "pedigree": {},
113807          "externalReferences": [
113808            {
113809              "url": "https://github.com/npm/validate-npm-package-name.git",
113810              "type": "distribution"
113811            },
113812            {
113813              "url": "https://github.com/npm/validate-npm-package-name",
113814              "type": "website"
113815            }
113816          ],
113817          "evidence": {},
113818          "signature": {
113819            "signature": {
113820              "publicKey": {}
113821            }
113822          },
113823          "modelCard": {
113824            "modelParameters": {
113825              "approach": {}
113826            },
113827            "quantitativeAnalysis": {
113828              "graphics": {}
113829            },
113830            "considerations": {}
113831          }
113832        },
113833        {
113834          "type": "library",
113835          "bom-ref": "pkg:npm/vary@1.1.2?package-id=7021c84ca0665099",
113836          "supplier": {},
113837          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
113838          "name": "vary",
113839          "version": "1.1.2",
113840          "description": "Manipulate the HTTP Vary header",
113841          "licenses": [
113842            {
113843              "license": {
113844                "id": "MIT"
113845              }
113846            }
113847          ],
113848          "cpe": "cpe:2.3:a:vary:vary:1.1.2:*:*:*:*:*:*:*",
113849          "purl": "pkg:npm/vary@1.1.2",
113850          "swid": {
113851            "attachment": {}
113852          },
113853          "pedigree": {},
113854          "externalReferences": [
113855            {
113856              "url": "jshttp/vary",
113857              "type": "distribution"
113858            }
113859          ],
113860          "evidence": {},
113861          "signature": {
113862            "signature": {
113863              "publicKey": {}
113864            }
113865          },
113866          "modelCard": {
113867            "modelParameters": {
113868              "approach": {}
113869            },
113870            "quantitativeAnalysis": {
113871              "graphics": {}
113872            },
113873            "considerations": {}
113874          }
113875        },
113876        {
113877          "type": "library",
113878          "bom-ref": "pkg:npm/walk-up-path@1.0.0?package-id=9a8dd6f20b12184f",
113879          "supplier": {},
113880          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
113881          "name": "walk-up-path",
113882          "version": "1.0.0",
113883          "description": "Given a path string, return a generator that walks up the path, emitting each dirname.",
113884          "licenses": [
113885            {
113886              "license": {
113887                "id": "ISC"
113888              }
113889            }
113890          ],
113891          "cpe": "cpe:2.3:a:walk-up-path:walk-up-path:1.0.0:*:*:*:*:*:*:*",
113892          "purl": "pkg:npm/walk-up-path@1.0.0",
113893          "swid": {
113894            "attachment": {}
113895          },
113896          "pedigree": {},
113897          "externalReferences": [
113898            {
113899              "url": "git+https://github.com/isaacs/walk-up-path",
113900              "type": "distribution"
113901            }
113902          ],
113903          "evidence": {},
113904          "signature": {
113905            "signature": {
113906              "publicKey": {}
113907            }
113908          },
113909          "modelCard": {
113910            "modelParameters": {
113911              "approach": {}
113912            },
113913            "quantitativeAnalysis": {
113914              "graphics": {}
113915            },
113916            "considerations": {}
113917          }
113918        },
113919        {
113920          "type": "library",
113921          "bom-ref": "pkg:npm/wcwidth@1.0.1?package-id=ee54c63162090e16",
113922          "supplier": {},
113923          "author": "Tim Oxley",
113924          "name": "wcwidth",
113925          "version": "1.0.1",
113926          "description": "Port of C's wcwidth() and wcswidth()",
113927          "licenses": [
113928            {
113929              "license": {
113930                "id": "MIT"
113931              }
113932            }
113933          ],
113934          "cpe": "cpe:2.3:a:timoxley:wcwidth:1.0.1:*:*:*:*:*:*:*",
113935          "purl": "pkg:npm/wcwidth@1.0.1",
113936          "swid": {
113937            "attachment": {}
113938          },
113939          "pedigree": {},
113940          "externalReferences": [
113941            {
113942              "url": "git+https://github.com/timoxley/wcwidth.git",
113943              "type": "distribution"
113944            },
113945            {
113946              "url": "https://github.com/timoxley/wcwidth#readme",
113947              "type": "website"
113948            }
113949          ],
113950          "evidence": {},
113951          "signature": {
113952            "signature": {
113953              "publicKey": {}
113954            }
113955          },
113956          "modelCard": {
113957            "modelParameters": {
113958              "approach": {}
113959            },
113960            "quantitativeAnalysis": {
113961              "graphics": {}
113962            },
113963            "considerations": {}
113964          }
113965        },
113966        {
113967          "type": "library",
113968          "bom-ref": "pkg:npm/web-encoding@1.1.5?package-id=b39ba08eff5d79dd",
113969          "supplier": {},
113970          "author": "Irakli Gozalishvili \u003cdev@gozala.io\u003e",
113971          "name": "web-encoding",
113972          "version": "1.1.5",
113973          "description": "TextEncoder and TextDecoder APIs from Encoding Standard APIs in a universal package",
113974          "licenses": [
113975            {
113976              "license": {
113977                "id": "MIT"
113978              }
113979            }
113980          ],
113981          "cpe": "cpe:2.3:a:web-encoding:web-encoding:1.1.5:*:*:*:*:*:*:*",
113982          "purl": "pkg:npm/web-encoding@1.1.5",
113983          "swid": {
113984            "attachment": {}
113985          },
113986          "pedigree": {},
113987          "externalReferences": [
113988            {
113989              "url": "https://github.com/gozala/web-encoding",
113990              "type": "website"
113991            }
113992          ],
113993          "evidence": {},
113994          "signature": {
113995            "signature": {
113996              "publicKey": {}
113997            }
113998          },
113999          "modelCard": {
114000            "modelParameters": {
114001              "approach": {}
114002            },
114003            "quantitativeAnalysis": {
114004              "graphics": {}
114005            },
114006            "considerations": {}
114007          }
114008        },
114009        {
114010          "type": "library",
114011          "bom-ref": "pkg:npm/which@1.3.1?package-id=8e09a57185e656b5",
114012          "supplier": {},
114013          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
114014          "name": "which",
114015          "version": "1.3.1",
114016          "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
114017          "licenses": [
114018            {
114019              "license": {
114020                "id": "ISC"
114021              }
114022            }
114023          ],
114024          "cpe": "cpe:2.3:a:isaacs:which:1.3.1:*:*:*:*:*:*:*",
114025          "purl": "pkg:npm/which@1.3.1",
114026          "swid": {
114027            "attachment": {}
114028          },
114029          "pedigree": {},
114030          "externalReferences": [
114031            {
114032              "url": "git://github.com/isaacs/node-which.git",
114033              "type": "distribution"
114034            }
114035          ],
114036          "evidence": {},
114037          "signature": {
114038            "signature": {
114039              "publicKey": {}
114040            }
114041          },
114042          "modelCard": {
114043            "modelParameters": {
114044              "approach": {}
114045            },
114046            "quantitativeAnalysis": {
114047              "graphics": {}
114048            },
114049            "considerations": {}
114050          }
114051        },
114052        {
114053          "type": "library",
114054          "bom-ref": "pkg:npm/which@2.0.2?package-id=1d2beaa974655b97",
114055          "supplier": {},
114056          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
114057          "name": "which",
114058          "version": "2.0.2",
114059          "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
114060          "licenses": [
114061            {
114062              "license": {
114063                "id": "ISC"
114064              }
114065            }
114066          ],
114067          "cpe": "cpe:2.3:a:isaacs:which:2.0.2:*:*:*:*:*:*:*",
114068          "purl": "pkg:npm/which@2.0.2",
114069          "swid": {
114070            "attachment": {}
114071          },
114072          "pedigree": {},
114073          "externalReferences": [
114074            {
114075              "url": "git://github.com/isaacs/node-which.git",
114076              "type": "distribution"
114077            }
114078          ],
114079          "evidence": {},
114080          "signature": {
114081            "signature": {
114082              "publicKey": {}
114083            }
114084          },
114085          "modelCard": {
114086            "modelParameters": {
114087              "approach": {}
114088            },
114089            "quantitativeAnalysis": {
114090              "graphics": {}
114091            },
114092            "considerations": {}
114093          }
114094        },
114095        {
114096          "type": "library",
114097          "bom-ref": "pkg:npm/which-typed-array@1.1.9?package-id=dbe8c85dce455ad6",
114098          "supplier": {},
114099          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
114100          "name": "which-typed-array",
114101          "version": "1.1.9",
114102          "description": "Which kind of Typed Array is this JavaScript value? Works cross-realm, without `instanceof`, and despite Symbol.toStringTag.",
114103          "licenses": [
114104            {
114105              "license": {
114106                "id": "MIT"
114107              }
114108            }
114109          ],
114110          "cpe": "cpe:2.3:a:which-typed-array:which-typed-array:1.1.9:*:*:*:*:*:*:*",
114111          "purl": "pkg:npm/which-typed-array@1.1.9",
114112          "swid": {
114113            "attachment": {}
114114          },
114115          "pedigree": {},
114116          "externalReferences": [
114117            {
114118              "url": "git://github.com/inspect-js/which-typed-array.git",
114119              "type": "distribution"
114120            }
114121          ],
114122          "evidence": {},
114123          "signature": {
114124            "signature": {
114125              "publicKey": {}
114126            }
114127          },
114128          "modelCard": {
114129            "modelParameters": {
114130              "approach": {}
114131            },
114132            "quantitativeAnalysis": {
114133              "graphics": {}
114134            },
114135            "considerations": {}
114136          }
114137        },
114138        {
114139          "type": "library",
114140          "bom-ref": "pkg:npm/wide-align@1.1.5?package-id=f0bd5200e29a21be",
114141          "supplier": {},
114142          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
114143          "name": "wide-align",
114144          "version": "1.1.5",
114145          "description": "A wide-character aware text alignment function for use on the console or with fixed width fonts.",
114146          "licenses": [
114147            {
114148              "license": {
114149                "id": "ISC"
114150              }
114151            }
114152          ],
114153          "cpe": "cpe:2.3:a:wide-align:wide-align:1.1.5:*:*:*:*:*:*:*",
114154          "purl": "pkg:npm/wide-align@1.1.5",
114155          "swid": {
114156            "attachment": {}
114157          },
114158          "pedigree": {},
114159          "externalReferences": [
114160            {
114161              "url": "https://github.com/iarna/wide-align",
114162              "type": "distribution"
114163            }
114164          ],
114165          "evidence": {},
114166          "signature": {
114167            "signature": {
114168              "publicKey": {}
114169            }
114170          },
114171          "modelCard": {
114172            "modelParameters": {
114173              "approach": {}
114174            },
114175            "quantitativeAnalysis": {
114176              "graphics": {}
114177            },
114178            "considerations": {}
114179          }
114180        },
114181        {
114182          "type": "library",
114183          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=88b7c304022dd8b8",
114184          "supplier": {},
114185          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
114186          "name": "wrappy",
114187          "version": "1.0.2",
114188          "description": "Callback wrapping utility",
114189          "licenses": [
114190            {
114191              "license": {
114192                "id": "ISC"
114193              }
114194            }
114195          ],
114196          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
114197          "purl": "pkg:npm/wrappy@1.0.2",
114198          "swid": {
114199            "attachment": {}
114200          },
114201          "pedigree": {},
114202          "externalReferences": [
114203            {
114204              "url": "https://github.com/npm/wrappy",
114205              "type": "distribution"
114206            },
114207            {
114208              "url": "https://github.com/npm/wrappy",
114209              "type": "website"
114210            }
114211          ],
114212          "evidence": {},
114213          "signature": {
114214            "signature": {
114215              "publicKey": {}
114216            }
114217          },
114218          "modelCard": {
114219            "modelParameters": {
114220              "approach": {}
114221            },
114222            "quantitativeAnalysis": {
114223              "graphics": {}
114224            },
114225            "considerations": {}
114226          }
114227        },
114228        {
114229          "type": "library",
114230          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=76aba5d70ffb4efb",
114231          "supplier": {},
114232          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
114233          "name": "wrappy",
114234          "version": "1.0.2",
114235          "description": "Callback wrapping utility",
114236          "licenses": [
114237            {
114238              "license": {
114239                "id": "ISC"
114240              }
114241            }
114242          ],
114243          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
114244          "purl": "pkg:npm/wrappy@1.0.2",
114245          "swid": {
114246            "attachment": {}
114247          },
114248          "pedigree": {},
114249          "externalReferences": [
114250            {
114251              "url": "https://github.com/npm/wrappy",
114252              "type": "distribution"
114253            },
114254            {
114255              "url": "https://github.com/npm/wrappy",
114256              "type": "website"
114257            }
114258          ],
114259          "evidence": {},
114260          "signature": {
114261            "signature": {
114262              "publicKey": {}
114263            }
114264          },
114265          "modelCard": {
114266            "modelParameters": {
114267              "approach": {}
114268            },
114269            "quantitativeAnalysis": {
114270              "graphics": {}
114271            },
114272            "considerations": {}
114273          }
114274        },
114275        {
114276          "type": "library",
114277          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=ed5926f6f76e646b",
114278          "supplier": {},
114279          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
114280          "name": "wrappy",
114281          "version": "1.0.2",
114282          "description": "Callback wrapping utility",
114283          "licenses": [
114284            {
114285              "license": {
114286                "id": "ISC"
114287              }
114288            }
114289          ],
114290          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
114291          "purl": "pkg:npm/wrappy@1.0.2",
114292          "swid": {
114293            "attachment": {}
114294          },
114295          "pedigree": {},
114296          "externalReferences": [
114297            {
114298              "url": "https://github.com/npm/wrappy",
114299              "type": "distribution"
114300            },
114301            {
114302              "url": "https://github.com/npm/wrappy",
114303              "type": "website"
114304            }
114305          ],
114306          "evidence": {},
114307          "signature": {
114308            "signature": {
114309              "publicKey": {}
114310            }
114311          },
114312          "modelCard": {
114313            "modelParameters": {
114314              "approach": {}
114315            },
114316            "quantitativeAnalysis": {
114317              "graphics": {}
114318            },
114319            "considerations": {}
114320          }
114321        },
114322        {
114323          "type": "library",
114324          "bom-ref": "pkg:npm/write-file-atomic@4.0.2?package-id=401a0baef0d4f8db",
114325          "supplier": {},
114326          "author": "GitHub Inc.",
114327          "name": "write-file-atomic",
114328          "version": "4.0.2",
114329          "description": "Write files in an atomic fashion w/configurable ownership",
114330          "licenses": [
114331            {
114332              "license": {
114333                "id": "ISC"
114334              }
114335            }
114336          ],
114337          "cpe": "cpe:2.3:a:write-file-atomic:write-file-atomic:4.0.2:*:*:*:*:*:*:*",
114338          "purl": "pkg:npm/write-file-atomic@4.0.2",
114339          "swid": {
114340            "attachment": {}
114341          },
114342          "pedigree": {},
114343          "externalReferences": [
114344            {
114345              "url": "https://github.com/npm/write-file-atomic.git",
114346              "type": "distribution"
114347            },
114348            {
114349              "url": "https://github.com/npm/write-file-atomic",
114350              "type": "website"
114351            }
114352          ],
114353          "evidence": {},
114354          "signature": {
114355            "signature": {
114356              "publicKey": {}
114357            }
114358          },
114359          "modelCard": {
114360            "modelParameters": {
114361              "approach": {}
114362            },
114363            "quantitativeAnalysis": {
114364              "graphics": {}
114365            },
114366            "considerations": {}
114367          }
114368        },
114369        {
114370          "type": "library",
114371          "bom-ref": "pkg:npm/xml@1.0.1?package-id=e28f883b3dca5ec8",
114372          "supplier": {},
114373          "author": "Dylan Greene (https://github.com/dylang)",
114374          "name": "xml",
114375          "version": "1.0.1",
114376          "description": "Fast and simple xml generator. Supports attributes, CDATA, etc. Includes tests and examples.",
114377          "licenses": [
114378            {
114379              "license": {
114380                "id": "MIT"
114381              }
114382            }
114383          ],
114384          "cpe": "cpe:2.3:a:dylang:xml:1.0.1:*:*:*:*:*:*:*",
114385          "purl": "pkg:npm/xml@1.0.1",
114386          "swid": {
114387            "attachment": {}
114388          },
114389          "pedigree": {},
114390          "externalReferences": [
114391            {
114392              "url": "http://github.com/dylang/node-xml",
114393              "type": "distribution"
114394            },
114395            {
114396              "url": "http://github.com/dylang/node-xml",
114397              "type": "website"
114398            }
114399          ],
114400          "evidence": {},
114401          "signature": {
114402            "signature": {
114403              "publicKey": {}
114404            }
114405          },
114406          "modelCard": {
114407            "modelParameters": {
114408              "approach": {}
114409            },
114410            "quantitativeAnalysis": {
114411              "graphics": {}
114412            },
114413            "considerations": {}
114414          }
114415        },
114416        {
114417          "type": "library",
114418          "bom-ref": "pkg:npm/xml2js@0.4.23?package-id=cea6836bf65243ea",
114419          "supplier": {},
114420          "author": "Marek Kubica \u003cmarek@xivilization.net\u003e (https://xivilization.net)",
114421          "name": "xml2js",
114422          "version": "0.4.23",
114423          "description": "Simple XML to JavaScript object converter.",
114424          "licenses": [
114425            {
114426              "license": {
114427                "id": "MIT"
114428              }
114429            }
114430          ],
114431          "cpe": "cpe:2.3:a:Leonidas-from-XIV:xml2js:0.4.23:*:*:*:*:*:*:*",
114432          "purl": "pkg:npm/xml2js@0.4.23",
114433          "swid": {
114434            "attachment": {}
114435          },
114436          "pedigree": {},
114437          "externalReferences": [
114438            {
114439              "url": "https://github.com/Leonidas-from-XIV/node-xml2js.git",
114440              "type": "distribution"
114441            },
114442            {
114443              "url": "https://github.com/Leonidas-from-XIV/node-xml2js",
114444              "type": "website"
114445            }
114446          ],
114447          "evidence": {},
114448          "signature": {
114449            "signature": {
114450              "publicKey": {}
114451            }
114452          },
114453          "modelCard": {
114454            "modelParameters": {
114455              "approach": {}
114456            },
114457            "quantitativeAnalysis": {
114458              "graphics": {}
114459            },
114460            "considerations": {}
114461          }
114462        },
114463        {
114464          "type": "library",
114465          "bom-ref": "pkg:npm/xmlbuilder@11.0.1?package-id=b2ed598d8a366a07",
114466          "supplier": {},
114467          "author": "Ozgur Ozcitak \u003coozcitak@gmail.com\u003e",
114468          "name": "xmlbuilder",
114469          "version": "11.0.1",
114470          "description": "An XML builder for node.js",
114471          "licenses": [
114472            {
114473              "license": {
114474                "id": "MIT"
114475              }
114476            }
114477          ],
114478          "cpe": "cpe:2.3:a:xmlbuilder:xmlbuilder:11.0.1:*:*:*:*:*:*:*",
114479          "purl": "pkg:npm/xmlbuilder@11.0.1",
114480          "swid": {
114481            "attachment": {}
114482          },
114483          "pedigree": {},
114484          "externalReferences": [
114485            {
114486              "url": "git://github.com/oozcitak/xmlbuilder-js.git",
114487              "type": "distribution"
114488            },
114489            {
114490              "url": "http://github.com/oozcitak/xmlbuilder-js",
114491              "type": "website"
114492            }
114493          ],
114494          "evidence": {},
114495          "signature": {
114496            "signature": {
114497              "publicKey": {}
114498            }
114499          },
114500          "modelCard": {
114501            "modelParameters": {
114502              "approach": {}
114503            },
114504            "quantitativeAnalysis": {
114505              "graphics": {}
114506            },
114507            "considerations": {}
114508          }
114509        },
114510        {
114511          "type": "library",
114512          "bom-ref": "pkg:npm/yallist@4.0.0?package-id=c5b3d2829d8d6201",
114513          "supplier": {},
114514          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
114515          "name": "yallist",
114516          "version": "4.0.0",
114517          "description": "Yet Another Linked List",
114518          "licenses": [
114519            {
114520              "license": {
114521                "id": "ISC"
114522              }
114523            }
114524          ],
114525          "cpe": "cpe:2.3:a:yallist:yallist:4.0.0:*:*:*:*:*:*:*",
114526          "purl": "pkg:npm/yallist@4.0.0",
114527          "swid": {
114528            "attachment": {}
114529          },
114530          "pedigree": {},
114531          "externalReferences": [
114532            {
114533              "url": "git+https://github.com/isaacs/yallist.git",
114534              "type": "distribution"
114535            }
114536          ],
114537          "evidence": {},
114538          "signature": {
114539            "signature": {
114540              "publicKey": {}
114541            }
114542          },
114543          "modelCard": {
114544            "modelParameters": {
114545              "approach": {}
114546            },
114547            "quantitativeAnalysis": {
114548              "graphics": {}
114549            },
114550            "considerations": {}
114551          }
114552        },
114553        {
114554          "type": "library",
114555          "bom-ref": "pkg:npm/yallist@4.0.0?package-id=962f7b1d680d2d52",
114556          "supplier": {},
114557          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
114558          "name": "yallist",
114559          "version": "4.0.0",
114560          "description": "Yet Another Linked List",
114561          "licenses": [
114562            {
114563              "license": {
114564                "id": "ISC"
114565              }
114566            }
114567          ],
114568          "cpe": "cpe:2.3:a:yallist:yallist:4.0.0:*:*:*:*:*:*:*",
114569          "purl": "pkg:npm/yallist@4.0.0",
114570          "swid": {
114571            "attachment": {}
114572          },
114573          "pedigree": {},
114574          "externalReferences": [
114575            {
114576              "url": "git+https://github.com/isaacs/yallist.git",
114577              "type": "distribution"
114578            }
114579          ],
114580          "evidence": {},
114581          "signature": {
114582            "signature": {
114583              "publicKey": {}
114584            }
114585          },
114586          "modelCard": {
114587            "modelParameters": {
114588              "approach": {}
114589            },
114590            "quantitativeAnalysis": {
114591              "graphics": {}
114592            },
114593            "considerations": {}
114594          }
114595        },
114596        {
114597          "type": "library",
114598          "bom-ref": "pkg:npm/yaml@1.10.2?package-id=b9b443c37bc128d1",
114599          "supplier": {},
114600          "author": "Eemeli Aro \u003ceemeli@gmail.com\u003e",
114601          "name": "yaml",
114602          "version": "1.10.2",
114603          "description": "JavaScript parser and stringifier for YAML",
114604          "licenses": [
114605            {
114606              "license": {
114607                "id": "ISC"
114608              }
114609            }
114610          ],
114611          "cpe": "cpe:2.3:a:yaml:yaml:1.10.2:*:*:*:*:*:*:*",
114612          "purl": "pkg:npm/yaml@1.10.2",
114613          "swid": {
114614            "attachment": {}
114615          },
114616          "pedigree": {},
114617          "externalReferences": [
114618            {
114619              "url": "github:eemeli/yaml",
114620              "type": "distribution"
114621            },
114622            {
114623              "url": "https://eemeli.org/yaml/v1/",
114624              "type": "website"
114625            }
114626          ],
114627          "evidence": {},
114628          "signature": {
114629            "signature": {
114630              "publicKey": {}
114631            }
114632          },
114633          "modelCard": {
114634            "modelParameters": {
114635              "approach": {}
114636            },
114637            "quantitativeAnalysis": {
114638              "graphics": {}
114639            },
114640            "considerations": {}
114641          }
114642        },
114643        {
114644          "type": "library",
114645          "bom-ref": "pkg:npm/yarn@1.22.19?package-id=f2b974a78000b26b",
114646          "supplier": {},
114647          "name": "yarn",
114648          "version": "1.22.19",
114649          "description": "📦🐈 Fast, reliable, and secure dependency management.",
114650          "licenses": [
114651            {
114652              "license": {
114653                "id": "BSD-2-Clause"
114654              }
114655            }
114656          ],
114657          "cpe": "cpe:2.3:a:yarn:yarn:1.22.19:*:*:*:*:*:*:*",
114658          "purl": "pkg:npm/yarn@1.22.19",
114659          "swid": {
114660            "attachment": {}
114661          },
114662          "pedigree": {},
114663          "externalReferences": [
114664            {
114665              "url": "yarnpkg/yarn",
114666              "type": "distribution"
114667            }
114668          ],
114669          "evidence": {},
114670          "signature": {
114671            "signature": {
114672              "publicKey": {}
114673            }
114674          },
114675          "modelCard": {
114676            "modelParameters": {
114677              "approach": {}
114678            },
114679            "quantitativeAnalysis": {
114680              "graphics": {}
114681            },
114682            "considerations": {}
114683          }
114684        },
114685        {
114686          "type": "library",
114687          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=75f0d92f695b4303",
114688          "supplier": {},
114689          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
114690          "name": "zlib",
114691          "version": "1.2.12-r3",
114692          "description": "A compression/decompression Library",
114693          "licenses": [
114694            {
114695              "license": {
114696                "id": "Zlib"
114697              }
114698            }
114699          ],
114700          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
114701          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5",
114702          "swid": {
114703            "attachment": {}
114704          },
114705          "pedigree": {},
114706          "externalReferences": [
114707            {
114708              "url": "https://zlib.net/",
114709              "type": "distribution"
114710            }
114711          ],
114712          "evidence": {},
114713          "signature": {
114714            "signature": {
114715              "publicKey": {}
114716            }
114717          },
114718          "modelCard": {
114719            "modelParameters": {
114720              "approach": {}
114721            },
114722            "quantitativeAnalysis": {
114723              "graphics": {}
114724            },
114725            "considerations": {}
114726          }
114727        },
114728        {
114729          "type": "operating-system",
114730          "supplier": {},
114731          "name": "alpine",
114732          "version": "3.16.5",
114733          "description": "Alpine Linux v3.16",
114734          "swid": {
114735            "tagId": "alpine",
114736            "name": "alpine",
114737            "version": "3.16.5",
114738            "attachment": {}
114739          },
114740          "pedigree": {},
114741          "externalReferences": [
114742            {
114743              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
114744              "type": "issue-tracker"
114745            },
114746            {
114747              "url": "https://alpinelinux.org/",
114748              "type": "website"
114749            }
114750          ],
114751          "evidence": {},
114752          "signature": {
114753            "signature": {
114754              "publicKey": {}
114755            }
114756          },
114757          "modelCard": {
114758            "modelParameters": {
114759              "approach": {}
114760            },
114761            "quantitativeAnalysis": {
114762              "graphics": {}
114763            },
114764            "considerations": {}
114765          }
114766        },
114767        {
114768          "type": "library",
114769          "bom-ref": "pkg:npm/%40colors/colors@1.5.0?package-id=1e63eea14f4d61ef",
114770          "supplier": {},
114771          "author": "DABH",
114772          "name": "@colors/colors",
114773          "version": "1.5.0",
114774          "description": "get colors in your node.js console",
114775          "licenses": [
114776            {
114777              "license": {
114778                "id": "MIT"
114779              }
114780            }
114781          ],
114782          "cpe": "cpe:2.3:a:\\@colors\\/colors:\\@colors\\/colors:1.5.0:*:*:*:*:*:*:*",
114783          "purl": "pkg:npm/%40colors/colors@1.5.0",
114784          "swid": {
114785            "attachment": {}
114786          },
114787          "pedigree": {},
114788          "externalReferences": [
114789            {
114790              "url": "http://github.com/DABH/colors.js.git",
114791              "type": "distribution"
114792            },
114793            {
114794              "url": "https://github.com/DABH/colors.js",
114795              "type": "website"
114796            }
114797          ],
114798          "evidence": {},
114799          "signature": {
114800            "signature": {
114801              "publicKey": {}
114802            }
114803          },
114804          "modelCard": {
114805            "modelParameters": {
114806              "approach": {}
114807            },
114808            "quantitativeAnalysis": {
114809              "graphics": {}
114810            },
114811            "considerations": {}
114812          }
114813        },
114814        {
114815          "type": "library",
114816          "bom-ref": "pkg:npm/%40gar/promisify@1.1.3?package-id=6fab079a7c06c1de",
114817          "supplier": {},
114818          "author": "Gar \u003cgar+npm@danger.computer\u003e",
114819          "name": "@gar/promisify",
114820          "version": "1.1.3",
114821          "description": "Promisify an entire class or object",
114822          "licenses": [
114823            {
114824              "license": {
114825                "id": "MIT"
114826              }
114827            }
114828          ],
114829          "cpe": "cpe:2.3:a:\\@gar\\/promisify:\\@gar\\/promisify:1.1.3:*:*:*:*:*:*:*",
114830          "purl": "pkg:npm/%40gar/promisify@1.1.3",
114831          "swid": {
114832            "attachment": {}
114833          },
114834          "pedigree": {},
114835          "externalReferences": [
114836            {
114837              "url": "https://github.com/wraithgar/gar-promisify.git",
114838              "type": "distribution"
114839            }
114840          ],
114841          "evidence": {},
114842          "signature": {
114843            "signature": {
114844              "publicKey": {}
114845            }
114846          },
114847          "modelCard": {
114848            "modelParameters": {
114849              "approach": {}
114850            },
114851            "quantitativeAnalysis": {
114852              "graphics": {}
114853            },
114854            "considerations": {}
114855          }
114856        },
114857        {
114858          "type": "library",
114859          "bom-ref": "pkg:npm/%40isaacs/string-locale-compare@1.1.0?package-id=fbe0dcb344723a67",
114860          "supplier": {},
114861          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
114862          "name": "@isaacs/string-locale-compare",
114863          "version": "1.1.0",
114864          "description": "Compare strings with Intl.Collator if available, falling back to String.localeCompare otherwise",
114865          "licenses": [
114866            {
114867              "license": {
114868                "id": "ISC"
114869              }
114870            }
114871          ],
114872          "cpe": "cpe:2.3:a:\\@isaacs\\/string-locale-compare:\\@isaacs\\/string-locale-compare:1.1.0:*:*:*:*:*:*:*",
114873          "purl": "pkg:npm/%40isaacs/string-locale-compare@1.1.0",
114874          "swid": {
114875            "attachment": {}
114876          },
114877          "pedigree": {},
114878          "externalReferences": [
114879            {
114880              "url": "git+https://github.com/isaacs/string-locale-compare",
114881              "type": "distribution"
114882            }
114883          ],
114884          "evidence": {},
114885          "signature": {
114886            "signature": {
114887              "publicKey": {}
114888            }
114889          },
114890          "modelCard": {
114891            "modelParameters": {
114892              "approach": {}
114893            },
114894            "quantitativeAnalysis": {
114895              "graphics": {}
114896            },
114897            "considerations": {}
114898          }
114899        },
114900        {
114901          "type": "library",
114902          "bom-ref": "pkg:npm/%40npmcli/arborist@5.6.3?package-id=60e008e2ceb94218",
114903          "supplier": {},
114904          "author": "GitHub Inc.",
114905          "name": "@npmcli/arborist",
114906          "version": "5.6.3",
114907          "description": "Manage node_modules trees",
114908          "licenses": [
114909            {
114910              "license": {
114911                "id": "ISC"
114912              }
114913            }
114914          ],
114915          "cpe": "cpe:2.3:a:\\@npmcli\\/arborist:\\@npmcli\\/arborist:5.6.3:*:*:*:*:*:*:*",
114916          "purl": "pkg:npm/%40npmcli/arborist@5.6.3",
114917          "swid": {
114918            "attachment": {}
114919          },
114920          "pedigree": {},
114921          "externalReferences": [
114922            {
114923              "url": "https://github.com/npm/cli.git",
114924              "type": "distribution"
114925            }
114926          ],
114927          "evidence": {},
114928          "signature": {
114929            "signature": {
114930              "publicKey": {}
114931            }
114932          },
114933          "modelCard": {
114934            "modelParameters": {
114935              "approach": {}
114936            },
114937            "quantitativeAnalysis": {
114938              "graphics": {}
114939            },
114940            "considerations": {}
114941          }
114942        },
114943        {
114944          "type": "library",
114945          "bom-ref": "pkg:npm/%40npmcli/ci-detect@2.0.0?package-id=8a40a38b900bcf1d",
114946          "supplier": {},
114947          "author": "GitHub Inc.",
114948          "name": "@npmcli/ci-detect",
114949          "version": "2.0.0",
114950          "description": "Detect what kind of CI environment the program is in",
114951          "licenses": [
114952            {
114953              "license": {
114954                "id": "ISC"
114955              }
114956            }
114957          ],
114958          "cpe": "cpe:2.3:a:\\@npmcli\\/ci-detect:\\@npmcli\\/ci-detect:2.0.0:*:*:*:*:*:*:*",
114959          "purl": "pkg:npm/%40npmcli/ci-detect@2.0.0",
114960          "swid": {
114961            "attachment": {}
114962          },
114963          "pedigree": {},
114964          "externalReferences": [
114965            {
114966              "url": "git+https://github.com/npm/ci-detect.git",
114967              "type": "distribution"
114968            }
114969          ],
114970          "evidence": {},
114971          "signature": {
114972            "signature": {
114973              "publicKey": {}
114974            }
114975          },
114976          "modelCard": {
114977            "modelParameters": {
114978              "approach": {}
114979            },
114980            "quantitativeAnalysis": {
114981              "graphics": {}
114982            },
114983            "considerations": {}
114984          }
114985        },
114986        {
114987          "type": "library",
114988          "bom-ref": "pkg:npm/%40npmcli/config@4.2.2?package-id=a02559bafd837882",
114989          "supplier": {},
114990          "author": "GitHub Inc.",
114991          "name": "@npmcli/config",
114992          "version": "4.2.2",
114993          "description": "Configuration management for the npm cli",
114994          "licenses": [
114995            {
114996              "license": {
114997                "id": "ISC"
114998              }
114999            }
115000          ],
115001          "cpe": "cpe:2.3:a:\\@npmcli\\/config:\\@npmcli\\/config:4.2.2:*:*:*:*:*:*:*",
115002          "purl": "pkg:npm/%40npmcli/config@4.2.2",
115003          "swid": {
115004            "attachment": {}
115005          },
115006          "pedigree": {},
115007          "externalReferences": [
115008            {
115009              "url": "https://github.com/npm/config.git",
115010              "type": "distribution"
115011            }
115012          ],
115013          "evidence": {},
115014          "signature": {
115015            "signature": {
115016              "publicKey": {}
115017            }
115018          },
115019          "modelCard": {
115020            "modelParameters": {
115021              "approach": {}
115022            },
115023            "quantitativeAnalysis": {
115024              "graphics": {}
115025            },
115026            "considerations": {}
115027          }
115028        },
115029        {
115030          "type": "library",
115031          "bom-ref": "pkg:npm/%40npmcli/disparity-colors@2.0.0?package-id=3e63715f5300a753",
115032          "supplier": {},
115033          "author": "GitHub Inc.",
115034          "name": "@npmcli/disparity-colors",
115035          "version": "2.0.0",
115036          "description": "Colorizes unified diff output",
115037          "licenses": [
115038            {
115039              "license": {
115040                "id": "ISC"
115041              }
115042            }
115043          ],
115044          "cpe": "cpe:2.3:a:\\@npmcli\\/disparity-colors:\\@npmcli\\/disparity-colors:2.0.0:*:*:*:*:*:*:*",
115045          "purl": "pkg:npm/%40npmcli/disparity-colors@2.0.0",
115046          "swid": {
115047            "attachment": {}
115048          },
115049          "pedigree": {},
115050          "externalReferences": [
115051            {
115052              "url": "https://github.com/npm/disparity-colors.git",
115053              "type": "distribution"
115054            }
115055          ],
115056          "evidence": {},
115057          "signature": {
115058            "signature": {
115059              "publicKey": {}
115060            }
115061          },
115062          "modelCard": {
115063            "modelParameters": {
115064              "approach": {}
115065            },
115066            "quantitativeAnalysis": {
115067              "graphics": {}
115068            },
115069            "considerations": {}
115070          }
115071        },
115072        {
115073          "type": "library",
115074          "bom-ref": "pkg:npm/%40npmcli/fs@2.1.2?package-id=cd19a20b4774187f",
115075          "supplier": {},
115076          "author": "GitHub Inc.",
115077          "name": "@npmcli/fs",
115078          "version": "2.1.2",
115079          "description": "filesystem utilities for the npm cli",
115080          "licenses": [
115081            {
115082              "license": {
115083                "id": "ISC"
115084              }
115085            }
115086          ],
115087          "cpe": "cpe:2.3:a:\\@npmcli\\/fs:\\@npmcli\\/fs:2.1.2:*:*:*:*:*:*:*",
115088          "purl": "pkg:npm/%40npmcli/fs@2.1.2",
115089          "swid": {
115090            "attachment": {}
115091          },
115092          "pedigree": {},
115093          "externalReferences": [
115094            {
115095              "url": "https://github.com/npm/fs.git",
115096              "type": "distribution"
115097            }
115098          ],
115099          "evidence": {},
115100          "signature": {
115101            "signature": {
115102              "publicKey": {}
115103            }
115104          },
115105          "modelCard": {
115106            "modelParameters": {
115107              "approach": {}
115108            },
115109            "quantitativeAnalysis": {
115110              "graphics": {}
115111            },
115112            "considerations": {}
115113          }
115114        },
115115        {
115116          "type": "library",
115117          "bom-ref": "pkg:npm/%40npmcli/git@3.0.2?package-id=34b16cf601f612a9",
115118          "supplier": {},
115119          "author": "GitHub Inc.",
115120          "name": "@npmcli/git",
115121          "version": "3.0.2",
115122          "description": "a util for spawning git from npm CLI contexts",
115123          "licenses": [
115124            {
115125              "license": {
115126                "id": "ISC"
115127              }
115128            }
115129          ],
115130          "cpe": "cpe:2.3:a:\\@npmcli\\/git:\\@npmcli\\/git:3.0.2:*:*:*:*:*:*:*",
115131          "purl": "pkg:npm/%40npmcli/git@3.0.2",
115132          "swid": {
115133            "attachment": {}
115134          },
115135          "pedigree": {},
115136          "externalReferences": [
115137            {
115138              "url": "https://github.com/npm/git.git",
115139              "type": "distribution"
115140            }
115141          ],
115142          "evidence": {},
115143          "signature": {
115144            "signature": {
115145              "publicKey": {}
115146            }
115147          },
115148          "modelCard": {
115149            "modelParameters": {
115150              "approach": {}
115151            },
115152            "quantitativeAnalysis": {
115153              "graphics": {}
115154            },
115155            "considerations": {}
115156          }
115157        },
115158        {
115159          "type": "library",
115160          "bom-ref": "pkg:npm/%40npmcli/installed-package-contents@1.0.7?package-id=8562f58f85ba40df",
115161          "supplier": {},
115162          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
115163          "name": "@npmcli/installed-package-contents",
115164          "version": "1.0.7",
115165          "description": "Get the list of files installed in a package in node_modules, including bundled dependencies",
115166          "licenses": [
115167            {
115168              "license": {
115169                "id": "ISC"
115170              }
115171            }
115172          ],
115173          "cpe": "cpe:2.3:a:\\@npmcli\\/installed-package-contents:\\@npmcli\\/installed-package-contents:1.0.7:*:*:*:*:*:*:*",
115174          "purl": "pkg:npm/%40npmcli/installed-package-contents@1.0.7",
115175          "swid": {
115176            "attachment": {}
115177          },
115178          "pedigree": {},
115179          "externalReferences": [
115180            {
115181              "url": "git+https://github.com/npm/installed-package-contents",
115182              "type": "distribution"
115183            }
115184          ],
115185          "evidence": {},
115186          "signature": {
115187            "signature": {
115188              "publicKey": {}
115189            }
115190          },
115191          "modelCard": {
115192            "modelParameters": {
115193              "approach": {}
115194            },
115195            "quantitativeAnalysis": {
115196              "graphics": {}
115197            },
115198            "considerations": {}
115199          }
115200        },
115201        {
115202          "type": "library",
115203          "bom-ref": "pkg:npm/%40npmcli/map-workspaces@2.0.4?package-id=471052449bb417cb",
115204          "supplier": {},
115205          "author": "GitHub Inc.",
115206          "name": "@npmcli/map-workspaces",
115207          "version": "2.0.4",
115208          "description": "Retrieves a name:pathname Map for a given workspaces config",
115209          "licenses": [
115210            {
115211              "license": {
115212                "id": "ISC"
115213              }
115214            }
115215          ],
115216          "cpe": "cpe:2.3:a:\\@npmcli\\/map-workspaces:\\@npmcli\\/map-workspaces:2.0.4:*:*:*:*:*:*:*",
115217          "purl": "pkg:npm/%40npmcli/map-workspaces@2.0.4",
115218          "swid": {
115219            "attachment": {}
115220          },
115221          "pedigree": {},
115222          "externalReferences": [
115223            {
115224              "url": "https://github.com/npm/map-workspaces.git",
115225              "type": "distribution"
115226            }
115227          ],
115228          "evidence": {},
115229          "signature": {
115230            "signature": {
115231              "publicKey": {}
115232            }
115233          },
115234          "modelCard": {
115235            "modelParameters": {
115236              "approach": {}
115237            },
115238            "quantitativeAnalysis": {
115239              "graphics": {}
115240            },
115241            "considerations": {}
115242          }
115243        },
115244        {
115245          "type": "library",
115246          "bom-ref": "pkg:npm/%40npmcli/metavuln-calculator@3.1.1?package-id=5a94ed44a78625cd",
115247          "supplier": {},
115248          "author": "GitHub Inc.",
115249          "name": "@npmcli/metavuln-calculator",
115250          "version": "3.1.1",
115251          "description": "Calculate meta-vulnerabilities from package security advisories",
115252          "licenses": [
115253            {
115254              "license": {
115255                "id": "ISC"
115256              }
115257            }
115258          ],
115259          "cpe": "cpe:2.3:a:\\@npmcli\\/metavuln-calculator:\\@npmcli\\/metavuln-calculator:3.1.1:*:*:*:*:*:*:*",
115260          "purl": "pkg:npm/%40npmcli/metavuln-calculator@3.1.1",
115261          "swid": {
115262            "attachment": {}
115263          },
115264          "pedigree": {},
115265          "externalReferences": [
115266            {
115267              "url": "https://github.com/npm/metavuln-calculator.git",
115268              "type": "distribution"
115269            }
115270          ],
115271          "evidence": {},
115272          "signature": {
115273            "signature": {
115274              "publicKey": {}
115275            }
115276          },
115277          "modelCard": {
115278            "modelParameters": {
115279              "approach": {}
115280            },
115281            "quantitativeAnalysis": {
115282              "graphics": {}
115283            },
115284            "considerations": {}
115285          }
115286        },
115287        {
115288          "type": "library",
115289          "bom-ref": "pkg:npm/%40npmcli/move-file@2.0.1?package-id=76e6ffad7033dea3",
115290          "supplier": {},
115291          "author": "GitHub Inc.",
115292          "name": "@npmcli/move-file",
115293          "version": "2.0.1",
115294          "description": "move a file (fork of move-file)",
115295          "licenses": [
115296            {
115297              "license": {
115298                "id": "MIT"
115299              }
115300            }
115301          ],
115302          "cpe": "cpe:2.3:a:\\@npmcli\\/move-file:\\@npmcli\\/move-file:2.0.1:*:*:*:*:*:*:*",
115303          "purl": "pkg:npm/%40npmcli/move-file@2.0.1",
115304          "swid": {
115305            "attachment": {}
115306          },
115307          "pedigree": {},
115308          "externalReferences": [
115309            {
115310              "url": "https://github.com/npm/move-file.git",
115311              "type": "distribution"
115312            }
115313          ],
115314          "evidence": {},
115315          "signature": {
115316            "signature": {
115317              "publicKey": {}
115318            }
115319          },
115320          "modelCard": {
115321            "modelParameters": {
115322              "approach": {}
115323            },
115324            "quantitativeAnalysis": {
115325              "graphics": {}
115326            },
115327            "considerations": {}
115328          }
115329        },
115330        {
115331          "type": "library",
115332          "bom-ref": "pkg:npm/%40npmcli/name-from-folder@1.0.1?package-id=bda8c8030d6b515f",
115333          "supplier": {},
115334          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
115335          "name": "@npmcli/name-from-folder",
115336          "version": "1.0.1",
115337          "description": "Get the package name from a folder path",
115338          "licenses": [
115339            {
115340              "license": {
115341                "id": "ISC"
115342              }
115343            }
115344          ],
115345          "cpe": "cpe:2.3:a:\\@npmcli\\/name-from-folder:\\@npmcli\\/name-from-folder:1.0.1:*:*:*:*:*:*:*",
115346          "purl": "pkg:npm/%40npmcli/name-from-folder@1.0.1",
115347          "swid": {
115348            "attachment": {}
115349          },
115350          "pedigree": {},
115351          "externalReferences": [
115352            {
115353              "url": "git+https://github.com/npm/name-from-folder",
115354              "type": "distribution"
115355            }
115356          ],
115357          "evidence": {},
115358          "signature": {
115359            "signature": {
115360              "publicKey": {}
115361            }
115362          },
115363          "modelCard": {
115364            "modelParameters": {
115365              "approach": {}
115366            },
115367            "quantitativeAnalysis": {
115368              "graphics": {}
115369            },
115370            "considerations": {}
115371          }
115372        },
115373        {
115374          "type": "library",
115375          "bom-ref": "pkg:npm/%40npmcli/node-gyp@2.0.0?package-id=c9fb094d61d2ac04",
115376          "supplier": {},
115377          "author": "GitHub Inc.",
115378          "name": "@npmcli/node-gyp",
115379          "version": "2.0.0",
115380          "description": "Tools for dealing with node-gyp packages",
115381          "licenses": [
115382            {
115383              "license": {
115384                "id": "ISC"
115385              }
115386            }
115387          ],
115388          "cpe": "cpe:2.3:a:\\@npmcli\\/node-gyp:\\@npmcli\\/node-gyp:2.0.0:*:*:*:*:*:*:*",
115389          "purl": "pkg:npm/%40npmcli/node-gyp@2.0.0",
115390          "swid": {
115391            "attachment": {}
115392          },
115393          "pedigree": {},
115394          "externalReferences": [
115395            {
115396              "url": "https://github.com/npm/node-gyp.git",
115397              "type": "distribution"
115398            }
115399          ],
115400          "evidence": {},
115401          "signature": {
115402            "signature": {
115403              "publicKey": {}
115404            }
115405          },
115406          "modelCard": {
115407            "modelParameters": {
115408              "approach": {}
115409            },
115410            "quantitativeAnalysis": {
115411              "graphics": {}
115412            },
115413            "considerations": {}
115414          }
115415        },
115416        {
115417          "type": "library",
115418          "bom-ref": "pkg:npm/%40npmcli/package-json@2.0.0?package-id=63189c571859bb1a",
115419          "supplier": {},
115420          "author": "GitHub Inc.",
115421          "name": "@npmcli/package-json",
115422          "version": "2.0.0",
115423          "description": "Programmatic API to update package.json",
115424          "licenses": [
115425            {
115426              "license": {
115427                "id": "ISC"
115428              }
115429            }
115430          ],
115431          "cpe": "cpe:2.3:a:\\@npmcli\\/package-json:\\@npmcli\\/package-json:2.0.0:*:*:*:*:*:*:*",
115432          "purl": "pkg:npm/%40npmcli/package-json@2.0.0",
115433          "swid": {
115434            "attachment": {}
115435          },
115436          "pedigree": {},
115437          "externalReferences": [
115438            {
115439              "url": "https://github.com/npm/package-json.git",
115440              "type": "distribution"
115441            }
115442          ],
115443          "evidence": {},
115444          "signature": {
115445            "signature": {
115446              "publicKey": {}
115447            }
115448          },
115449          "modelCard": {
115450            "modelParameters": {
115451              "approach": {}
115452            },
115453            "quantitativeAnalysis": {
115454              "graphics": {}
115455            },
115456            "considerations": {}
115457          }
115458        },
115459        {
115460          "type": "library",
115461          "bom-ref": "pkg:npm/%40npmcli/promise-spawn@3.0.0?package-id=426c6e033be010cb",
115462          "supplier": {},
115463          "author": "GitHub Inc.",
115464          "name": "@npmcli/promise-spawn",
115465          "version": "3.0.0",
115466          "description": "spawn processes the way the npm cli likes to do",
115467          "licenses": [
115468            {
115469              "license": {
115470                "id": "ISC"
115471              }
115472            }
115473          ],
115474          "cpe": "cpe:2.3:a:\\@npmcli\\/promise-spawn:\\@npmcli\\/promise-spawn:3.0.0:*:*:*:*:*:*:*",
115475          "purl": "pkg:npm/%40npmcli/promise-spawn@3.0.0",
115476          "swid": {
115477            "attachment": {}
115478          },
115479          "pedigree": {},
115480          "externalReferences": [
115481            {
115482              "url": "https://github.com/npm/promise-spawn.git",
115483              "type": "distribution"
115484            }
115485          ],
115486          "evidence": {},
115487          "signature": {
115488            "signature": {
115489              "publicKey": {}
115490            }
115491          },
115492          "modelCard": {
115493            "modelParameters": {
115494              "approach": {}
115495            },
115496            "quantitativeAnalysis": {
115497              "graphics": {}
115498            },
115499            "considerations": {}
115500          }
115501        },
115502        {
115503          "type": "library",
115504          "bom-ref": "pkg:npm/%40npmcli/query@1.2.0?package-id=e71e78476048755c",
115505          "supplier": {},
115506          "author": "GitHub Inc.",
115507          "name": "@npmcli/query",
115508          "version": "1.2.0",
115509          "description": "npm query parser and tools",
115510          "licenses": [
115511            {
115512              "license": {
115513                "id": "ISC"
115514              }
115515            }
115516          ],
115517          "cpe": "cpe:2.3:a:\\@npmcli\\/query:\\@npmcli\\/query:1.2.0:*:*:*:*:*:*:*",
115518          "purl": "pkg:npm/%40npmcli/query@1.2.0",
115519          "swid": {
115520            "attachment": {}
115521          },
115522          "pedigree": {},
115523          "externalReferences": [
115524            {
115525              "url": "https://github.com/npm/query.git",
115526              "type": "distribution"
115527            }
115528          ],
115529          "evidence": {},
115530          "signature": {
115531            "signature": {
115532              "publicKey": {}
115533            }
115534          },
115535          "modelCard": {
115536            "modelParameters": {
115537              "approach": {}
115538            },
115539            "quantitativeAnalysis": {
115540              "graphics": {}
115541            },
115542            "considerations": {}
115543          }
115544        },
115545        {
115546          "type": "library",
115547          "bom-ref": "pkg:npm/%40npmcli/run-script@4.2.1?package-id=a13d191f5a0789d1",
115548          "supplier": {},
115549          "author": "GitHub Inc.",
115550          "name": "@npmcli/run-script",
115551          "version": "4.2.1",
115552          "description": "Run a lifecycle script for a package (descendant of npm-lifecycle)",
115553          "licenses": [
115554            {
115555              "license": {
115556                "id": "ISC"
115557              }
115558            }
115559          ],
115560          "cpe": "cpe:2.3:a:\\@npmcli\\/run-script:\\@npmcli\\/run-script:4.2.1:*:*:*:*:*:*:*",
115561          "purl": "pkg:npm/%40npmcli/run-script@4.2.1",
115562          "swid": {
115563            "attachment": {}
115564          },
115565          "pedigree": {},
115566          "externalReferences": [
115567            {
115568              "url": "https://github.com/npm/run-script.git",
115569              "type": "distribution"
115570            }
115571          ],
115572          "evidence": {},
115573          "signature": {
115574            "signature": {
115575              "publicKey": {}
115576            }
115577          },
115578          "modelCard": {
115579            "modelParameters": {
115580              "approach": {}
115581            },
115582            "quantitativeAnalysis": {
115583              "graphics": {}
115584            },
115585            "considerations": {}
115586          }
115587        },
115588        {
115589          "type": "library",
115590          "bom-ref": "pkg:npm/%40tootallnate/once@2.0.0?package-id=5edbc75b01ae9167",
115591          "supplier": {},
115592          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
115593          "name": "@tootallnate/once",
115594          "version": "2.0.0",
115595          "description": "Creates a Promise that waits for a single event",
115596          "licenses": [
115597            {
115598              "license": {
115599                "id": "MIT"
115600              }
115601            }
115602          ],
115603          "cpe": "cpe:2.3:a:\\@tootallnate\\/once:\\@tootallnate\\/once:2.0.0:*:*:*:*:*:*:*",
115604          "purl": "pkg:npm/%40tootallnate/once@2.0.0",
115605          "swid": {
115606            "attachment": {}
115607          },
115608          "pedigree": {},
115609          "externalReferences": [
115610            {
115611              "url": "git://github.com/TooTallNate/once.git",
115612              "type": "distribution"
115613            }
115614          ],
115615          "evidence": {},
115616          "signature": {
115617            "signature": {
115618              "publicKey": {}
115619            }
115620          },
115621          "modelCard": {
115622            "modelParameters": {
115623              "approach": {}
115624            },
115625            "quantitativeAnalysis": {
115626              "graphics": {}
115627            },
115628            "considerations": {}
115629          }
115630        },
115631        {
115632          "type": "library",
115633          "bom-ref": "pkg:npm/abbrev@1.1.1?package-id=98be1cad3f4d1d11",
115634          "supplier": {},
115635          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
115636          "name": "abbrev",
115637          "version": "1.1.1",
115638          "description": "Like ruby's abbrev module, but in js",
115639          "licenses": [
115640            {
115641              "license": {
115642                "id": "ISC"
115643              }
115644            }
115645          ],
115646          "cpe": "cpe:2.3:a:abbrev:abbrev:1.1.1:*:*:*:*:*:*:*",
115647          "purl": "pkg:npm/abbrev@1.1.1",
115648          "swid": {
115649            "attachment": {}
115650          },
115651          "pedigree": {},
115652          "externalReferences": [
115653            {
115654              "url": "http://github.com/isaacs/abbrev-js",
115655              "type": "distribution"
115656            }
115657          ],
115658          "evidence": {},
115659          "signature": {
115660            "signature": {
115661              "publicKey": {}
115662            }
115663          },
115664          "modelCard": {
115665            "modelParameters": {
115666              "approach": {}
115667            },
115668            "quantitativeAnalysis": {
115669              "graphics": {}
115670            },
115671            "considerations": {}
115672          }
115673        },
115674        {
115675          "type": "library",
115676          "bom-ref": "pkg:npm/addon-mqws@1.0.0?package-id=fa085fd946d6629c",
115677          "supplier": {},
115678          "name": "addon-mqws",
115679          "version": "1.0.0",
115680          "description": "addon-mqws",
115681          "cpe": "cpe:2.3:a:addon-mqws:addon-mqws:1.0.0:*:*:*:*:*:*:*",
115682          "purl": "pkg:npm/addon-mqws@1.0.0",
115683          "swid": {
115684            "attachment": {}
115685          },
115686          "pedigree": {},
115687          "evidence": {},
115688          "signature": {
115689            "signature": {
115690              "publicKey": {}
115691            }
115692          },
115693          "modelCard": {
115694            "modelParameters": {
115695              "approach": {}
115696            },
115697            "quantitativeAnalysis": {
115698              "graphics": {}
115699            },
115700            "considerations": {}
115701          }
115702        },
115703        {
115704          "type": "library",
115705          "bom-ref": "pkg:npm/agent-base@6.0.2?package-id=4b0b5c9ee7d8fc08",
115706          "supplier": {},
115707          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
115708          "name": "agent-base",
115709          "version": "6.0.2",
115710          "description": "Turn a function into an `http.Agent` instance",
115711          "licenses": [
115712            {
115713              "license": {
115714                "id": "MIT"
115715              }
115716            }
115717          ],
115718          "cpe": "cpe:2.3:a:TooTallNate:agent-base:6.0.2:*:*:*:*:*:*:*",
115719          "purl": "pkg:npm/agent-base@6.0.2",
115720          "swid": {
115721            "attachment": {}
115722          },
115723          "pedigree": {},
115724          "externalReferences": [
115725            {
115726              "url": "git://github.com/TooTallNate/node-agent-base.git",
115727              "type": "distribution"
115728            }
115729          ],
115730          "evidence": {},
115731          "signature": {
115732            "signature": {
115733              "publicKey": {}
115734            }
115735          },
115736          "modelCard": {
115737            "modelParameters": {
115738              "approach": {}
115739            },
115740            "quantitativeAnalysis": {
115741              "graphics": {}
115742            },
115743            "considerations": {}
115744          }
115745        },
115746        {
115747          "type": "library",
115748          "bom-ref": "pkg:npm/agentkeepalive@4.2.1?package-id=37fa9bcd67324d6e",
115749          "supplier": {},
115750          "author": "fengmk2 \u003cfengmk2@gmail.com\u003e (https://fengmk2.com)",
115751          "name": "agentkeepalive",
115752          "version": "4.2.1",
115753          "description": "Missing keepalive http.Agent",
115754          "licenses": [
115755            {
115756              "license": {
115757                "id": "MIT"
115758              }
115759            }
115760          ],
115761          "cpe": "cpe:2.3:a:agentkeepalive:agentkeepalive:4.2.1:*:*:*:*:*:*:*",
115762          "purl": "pkg:npm/agentkeepalive@4.2.1",
115763          "swid": {
115764            "attachment": {}
115765          },
115766          "pedigree": {},
115767          "externalReferences": [
115768            {
115769              "url": "git://github.com/node-modules/agentkeepalive.git",
115770              "type": "distribution"
115771            }
115772          ],
115773          "evidence": {},
115774          "signature": {
115775            "signature": {
115776              "publicKey": {}
115777            }
115778          },
115779          "modelCard": {
115780            "modelParameters": {
115781              "approach": {}
115782            },
115783            "quantitativeAnalysis": {
115784              "graphics": {}
115785            },
115786            "considerations": {}
115787          }
115788        },
115789        {
115790          "type": "library",
115791          "bom-ref": "pkg:npm/aggregate-error@3.1.0?package-id=b1b74a520919b83f",
115792          "supplier": {},
115793          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
115794          "name": "aggregate-error",
115795          "version": "3.1.0",
115796          "description": "Create an error from multiple errors",
115797          "licenses": [
115798            {
115799              "license": {
115800                "id": "MIT"
115801              }
115802            }
115803          ],
115804          "cpe": "cpe:2.3:a:aggregate-error:aggregate-error:3.1.0:*:*:*:*:*:*:*",
115805          "purl": "pkg:npm/aggregate-error@3.1.0",
115806          "swid": {
115807            "attachment": {}
115808          },
115809          "pedigree": {},
115810          "externalReferences": [
115811            {
115812              "url": "sindresorhus/aggregate-error",
115813              "type": "distribution"
115814            }
115815          ],
115816          "evidence": {},
115817          "signature": {
115818            "signature": {
115819              "publicKey": {}
115820            }
115821          },
115822          "modelCard": {
115823            "modelParameters": {
115824              "approach": {}
115825            },
115826            "quantitativeAnalysis": {
115827              "graphics": {}
115828            },
115829            "considerations": {}
115830          }
115831        },
115832        {
115833          "type": "library",
115834          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=61eac5ce8105d394",
115835          "supplier": {},
115836          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
115837          "name": "alpine-baselayout",
115838          "version": "3.2.0-r23",
115839          "description": "Alpine base dir structure and init scripts",
115840          "licenses": [
115841            {
115842              "license": {
115843                "id": "GPL-2.0-only"
115844              }
115845            }
115846          ],
115847          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r23:*:*:*:*:*:*:*",
115848          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5",
115849          "swid": {
115850            "attachment": {}
115851          },
115852          "pedigree": {},
115853          "externalReferences": [
115854            {
115855              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
115856              "type": "distribution"
115857            }
115858          ],
115859          "evidence": {},
115860          "signature": {
115861            "signature": {
115862              "publicKey": {}
115863            }
115864          },
115865          "modelCard": {
115866            "modelParameters": {
115867              "approach": {}
115868            },
115869            "quantitativeAnalysis": {
115870              "graphics": {}
115871            },
115872            "considerations": {}
115873          }
115874        },
115875        {
115876          "type": "library",
115877          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5\u0026package-id=e8c6fcc3a282ed4f",
115878          "supplier": {},
115879          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
115880          "name": "alpine-baselayout-data",
115881          "version": "3.2.0-r23",
115882          "description": "Alpine base dir structure and init scripts",
115883          "licenses": [
115884            {
115885              "license": {
115886                "id": "GPL-2.0-only"
115887              }
115888            }
115889          ],
115890          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.2.0-r23:*:*:*:*:*:*:*",
115891          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5",
115892          "swid": {
115893            "attachment": {}
115894          },
115895          "pedigree": {},
115896          "externalReferences": [
115897            {
115898              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
115899              "type": "distribution"
115900            }
115901          ],
115902          "evidence": {},
115903          "signature": {
115904            "signature": {
115905              "publicKey": {}
115906            }
115907          },
115908          "modelCard": {
115909            "modelParameters": {
115910              "approach": {}
115911            },
115912            "quantitativeAnalysis": {
115913              "graphics": {}
115914            },
115915            "considerations": {}
115916          }
115917        },
115918        {
115919          "type": "library",
115920          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=82d183eb300978cc",
115921          "supplier": {},
115922          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
115923          "name": "alpine-keys",
115924          "version": "2.4-r1",
115925          "description": "Public keys for Alpine Linux packages",
115926          "licenses": [
115927            {
115928              "license": {
115929                "id": "MIT"
115930              }
115931            }
115932          ],
115933          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
115934          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5",
115935          "swid": {
115936            "attachment": {}
115937          },
115938          "pedigree": {},
115939          "externalReferences": [
115940            {
115941              "url": "https://alpinelinux.org",
115942              "type": "distribution"
115943            }
115944          ],
115945          "evidence": {},
115946          "signature": {
115947            "signature": {
115948              "publicKey": {}
115949            }
115950          },
115951          "modelCard": {
115952            "modelParameters": {
115953              "approach": {}
115954            },
115955            "quantitativeAnalysis": {
115956              "graphics": {}
115957            },
115958            "considerations": {}
115959          }
115960        },
115961        {
115962          "type": "library",
115963          "bom-ref": "pkg:npm/ansi-regex@5.0.1?package-id=fe78ee8372cda3ef",
115964          "supplier": {},
115965          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
115966          "name": "ansi-regex",
115967          "version": "5.0.1",
115968          "description": "Regular expression for matching ANSI escape codes",
115969          "licenses": [
115970            {
115971              "license": {
115972                "id": "MIT"
115973              }
115974            }
115975          ],
115976          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:5.0.1:*:*:*:*:*:*:*",
115977          "purl": "pkg:npm/ansi-regex@5.0.1",
115978          "swid": {
115979            "attachment": {}
115980          },
115981          "pedigree": {},
115982          "externalReferences": [
115983            {
115984              "url": "chalk/ansi-regex",
115985              "type": "distribution"
115986            }
115987          ],
115988          "evidence": {},
115989          "signature": {
115990            "signature": {
115991              "publicKey": {}
115992            }
115993          },
115994          "modelCard": {
115995            "modelParameters": {
115996              "approach": {}
115997            },
115998            "quantitativeAnalysis": {
115999              "graphics": {}
116000            },
116001            "considerations": {}
116002          }
116003        },
116004        {
116005          "type": "library",
116006          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=e3f310fd74532509",
116007          "supplier": {},
116008          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
116009          "name": "ansi-styles",
116010          "version": "4.3.0",
116011          "description": "ANSI escape codes for styling strings in the terminal",
116012          "licenses": [
116013            {
116014              "license": {
116015                "id": "MIT"
116016              }
116017            }
116018          ],
116019          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
116020          "purl": "pkg:npm/ansi-styles@4.3.0",
116021          "swid": {
116022            "attachment": {}
116023          },
116024          "pedigree": {},
116025          "externalReferences": [
116026            {
116027              "url": "chalk/ansi-styles",
116028              "type": "distribution"
116029            }
116030          ],
116031          "evidence": {},
116032          "signature": {
116033            "signature": {
116034              "publicKey": {}
116035            }
116036          },
116037          "modelCard": {
116038            "modelParameters": {
116039              "approach": {}
116040            },
116041            "quantitativeAnalysis": {
116042              "graphics": {}
116043            },
116044            "considerations": {}
116045          }
116046        },
116047        {
116048          "type": "library",
116049          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=42d502b764a37310",
116050          "supplier": {},
116051          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
116052          "name": "apk-tools",
116053          "version": "2.12.9-r3",
116054          "description": "Alpine Package Keeper - package manager for alpine",
116055          "licenses": [
116056            {
116057              "license": {
116058                "id": "GPL-2.0-only"
116059              }
116060            }
116061          ],
116062          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.9-r3:*:*:*:*:*:*:*",
116063          "purl": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5",
116064          "swid": {
116065            "attachment": {}
116066          },
116067          "pedigree": {},
116068          "externalReferences": [
116069            {
116070              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
116071              "type": "distribution"
116072            }
116073          ],
116074          "evidence": {},
116075          "signature": {
116076            "signature": {
116077              "publicKey": {}
116078            }
116079          },
116080          "modelCard": {
116081            "modelParameters": {
116082              "approach": {}
116083            },
116084            "quantitativeAnalysis": {
116085              "graphics": {}
116086            },
116087            "considerations": {}
116088          }
116089        },
116090        {
116091          "type": "library",
116092          "bom-ref": "pkg:npm/aproba@2.0.0?package-id=d11111a04d810227",
116093          "supplier": {},
116094          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
116095          "name": "aproba",
116096          "version": "2.0.0",
116097          "description": "A ridiculously light-weight argument validator (now browser friendly)",
116098          "licenses": [
116099            {
116100              "license": {
116101                "id": "ISC"
116102              }
116103            }
116104          ],
116105          "cpe": "cpe:2.3:a:aproba:aproba:2.0.0:*:*:*:*:*:*:*",
116106          "purl": "pkg:npm/aproba@2.0.0",
116107          "swid": {
116108            "attachment": {}
116109          },
116110          "pedigree": {},
116111          "externalReferences": [
116112            {
116113              "url": "https://github.com/iarna/aproba",
116114              "type": "distribution"
116115            },
116116            {
116117              "url": "https://github.com/iarna/aproba",
116118              "type": "website"
116119            }
116120          ],
116121          "evidence": {},
116122          "signature": {
116123            "signature": {
116124              "publicKey": {}
116125            }
116126          },
116127          "modelCard": {
116128            "modelParameters": {
116129              "approach": {}
116130            },
116131            "quantitativeAnalysis": {
116132              "graphics": {}
116133            },
116134            "considerations": {}
116135          }
116136        },
116137        {
116138          "type": "library",
116139          "bom-ref": "pkg:npm/archy@1.0.0?package-id=a1e7fd77fec54095",
116140          "supplier": {},
116141          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
116142          "name": "archy",
116143          "version": "1.0.0",
116144          "description": "render nested hierarchies `npm ls` style with unicode pipes",
116145          "licenses": [
116146            {
116147              "license": {
116148                "id": "MIT"
116149              }
116150            }
116151          ],
116152          "cpe": "cpe:2.3:a:substack:archy:1.0.0:*:*:*:*:*:*:*",
116153          "purl": "pkg:npm/archy@1.0.0",
116154          "swid": {
116155            "attachment": {}
116156          },
116157          "pedigree": {},
116158          "externalReferences": [
116159            {
116160              "url": "http://github.com/substack/node-archy.git",
116161              "type": "distribution"
116162            }
116163          ],
116164          "evidence": {},
116165          "signature": {
116166            "signature": {
116167              "publicKey": {}
116168            }
116169          },
116170          "modelCard": {
116171            "modelParameters": {
116172              "approach": {}
116173            },
116174            "quantitativeAnalysis": {
116175              "graphics": {}
116176            },
116177            "considerations": {}
116178          }
116179        },
116180        {
116181          "type": "library",
116182          "bom-ref": "pkg:npm/are-we-there-yet@3.0.1?package-id=d7ea73c2e385c95d",
116183          "supplier": {},
116184          "author": "GitHub Inc.",
116185          "name": "are-we-there-yet",
116186          "version": "3.0.1",
116187          "description": "Keep track of the overall completion of many disparate processes",
116188          "licenses": [
116189            {
116190              "license": {
116191                "id": "ISC"
116192              }
116193            }
116194          ],
116195          "cpe": "cpe:2.3:a:are-we-there-yet:are-we-there-yet:3.0.1:*:*:*:*:*:*:*",
116196          "purl": "pkg:npm/are-we-there-yet@3.0.1",
116197          "swid": {
116198            "attachment": {}
116199          },
116200          "pedigree": {},
116201          "externalReferences": [
116202            {
116203              "url": "https://github.com/npm/are-we-there-yet.git",
116204              "type": "distribution"
116205            },
116206            {
116207              "url": "https://github.com/npm/are-we-there-yet",
116208              "type": "website"
116209            }
116210          ],
116211          "evidence": {},
116212          "signature": {
116213            "signature": {
116214              "publicKey": {}
116215            }
116216          },
116217          "modelCard": {
116218            "modelParameters": {
116219              "approach": {}
116220            },
116221            "quantitativeAnalysis": {
116222              "graphics": {}
116223            },
116224            "considerations": {}
116225          }
116226        },
116227        {
116228          "type": "library",
116229          "bom-ref": "pkg:npm/asap@2.0.6?package-id=4069b89e24646503",
116230          "supplier": {},
116231          "name": "asap",
116232          "version": "2.0.6",
116233          "description": "High-priority task queue for Node.js and browsers",
116234          "licenses": [
116235            {
116236              "license": {
116237                "id": "MIT"
116238              }
116239            }
116240          ],
116241          "cpe": "cpe:2.3:a:kriskowal:asap:2.0.6:*:*:*:*:*:*:*",
116242          "purl": "pkg:npm/asap@2.0.6",
116243          "swid": {
116244            "attachment": {}
116245          },
116246          "pedigree": {},
116247          "externalReferences": [
116248            {
116249              "url": "https://github.com/kriskowal/asap.git",
116250              "type": "distribution"
116251            }
116252          ],
116253          "evidence": {},
116254          "signature": {
116255            "signature": {
116256              "publicKey": {}
116257            }
116258          },
116259          "modelCard": {
116260            "modelParameters": {
116261              "approach": {}
116262            },
116263            "quantitativeAnalysis": {
116264              "graphics": {}
116265            },
116266            "considerations": {}
116267          }
116268        },
116269        {
116270          "type": "library",
116271          "bom-ref": "pkg:npm/async-limiter@1.0.1?package-id=4f5d33b9cb28984b",
116272          "supplier": {},
116273          "name": "async-limiter",
116274          "version": "1.0.1",
116275          "description": "asynchronous function queue with adjustable concurrency",
116276          "licenses": [
116277            {
116278              "license": {
116279                "id": "MIT"
116280              }
116281            }
116282          ],
116283          "cpe": "cpe:2.3:a:async-limiter:async-limiter:1.0.1:*:*:*:*:*:*:*",
116284          "purl": "pkg:npm/async-limiter@1.0.1",
116285          "swid": {
116286            "attachment": {}
116287          },
116288          "pedigree": {},
116289          "externalReferences": [
116290            {
116291              "url": "https://github.com/strml/async-limiter.git",
116292              "type": "distribution"
116293            }
116294          ],
116295          "evidence": {},
116296          "signature": {
116297            "signature": {
116298              "publicKey": {}
116299            }
116300          },
116301          "modelCard": {
116302            "modelParameters": {
116303              "approach": {}
116304            },
116305            "quantitativeAnalysis": {
116306              "graphics": {}
116307            },
116308            "considerations": {}
116309          }
116310        },
116311        {
116312          "type": "library",
116313          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=c15b2106d0ae19d4",
116314          "supplier": {},
116315          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
116316          "name": "balanced-match",
116317          "version": "1.0.2",
116318          "description": "Match balanced character pairs, like \"{\" and \"}\"",
116319          "licenses": [
116320            {
116321              "license": {
116322                "id": "MIT"
116323              }
116324            }
116325          ],
116326          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
116327          "purl": "pkg:npm/balanced-match@1.0.2",
116328          "swid": {
116329            "attachment": {}
116330          },
116331          "pedigree": {},
116332          "externalReferences": [
116333            {
116334              "url": "git://github.com/juliangruber/balanced-match.git",
116335              "type": "distribution"
116336            },
116337            {
116338              "url": "https://github.com/juliangruber/balanced-match",
116339              "type": "website"
116340            }
116341          ],
116342          "evidence": {},
116343          "signature": {
116344            "signature": {
116345              "publicKey": {}
116346            }
116347          },
116348          "modelCard": {
116349            "modelParameters": {
116350              "approach": {}
116351            },
116352            "quantitativeAnalysis": {
116353              "graphics": {}
116354            },
116355            "considerations": {}
116356          }
116357        },
116358        {
116359          "type": "library",
116360          "bom-ref": "pkg:npm/bin-links@3.0.3?package-id=605ade84572e7fb",
116361          "supplier": {},
116362          "author": "GitHub Inc.",
116363          "name": "bin-links",
116364          "version": "3.0.3",
116365          "description": "JavaScript package binary linker",
116366          "licenses": [
116367            {
116368              "license": {
116369                "id": "ISC"
116370              }
116371            }
116372          ],
116373          "cpe": "cpe:2.3:a:bin-links:bin-links:3.0.3:*:*:*:*:*:*:*",
116374          "purl": "pkg:npm/bin-links@3.0.3",
116375          "swid": {
116376            "attachment": {}
116377          },
116378          "pedigree": {},
116379          "externalReferences": [
116380            {
116381              "url": "https://github.com/npm/bin-links.git",
116382              "type": "distribution"
116383            }
116384          ],
116385          "evidence": {},
116386          "signature": {
116387            "signature": {
116388              "publicKey": {}
116389            }
116390          },
116391          "modelCard": {
116392            "modelParameters": {
116393              "approach": {}
116394            },
116395            "quantitativeAnalysis": {
116396              "graphics": {}
116397            },
116398            "considerations": {}
116399          }
116400        },
116401        {
116402          "type": "library",
116403          "bom-ref": "pkg:npm/binary-extensions@2.2.0?package-id=2ddda84d3ad7f3e1",
116404          "supplier": {},
116405          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
116406          "name": "binary-extensions",
116407          "version": "2.2.0",
116408          "description": "List of binary file extensions",
116409          "licenses": [
116410            {
116411              "license": {
116412                "id": "MIT"
116413              }
116414            }
116415          ],
116416          "cpe": "cpe:2.3:a:binary-extensions:binary-extensions:2.2.0:*:*:*:*:*:*:*",
116417          "purl": "pkg:npm/binary-extensions@2.2.0",
116418          "swid": {
116419            "attachment": {}
116420          },
116421          "pedigree": {},
116422          "externalReferences": [
116423            {
116424              "url": "sindresorhus/binary-extensions",
116425              "type": "distribution"
116426            }
116427          ],
116428          "evidence": {},
116429          "signature": {
116430            "signature": {
116431              "publicKey": {}
116432            }
116433          },
116434          "modelCard": {
116435            "modelParameters": {
116436              "approach": {}
116437            },
116438            "quantitativeAnalysis": {
116439              "graphics": {}
116440            },
116441            "considerations": {}
116442          }
116443        },
116444        {
116445          "type": "library",
116446          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=a36ca63616a6d457",
116447          "supplier": {},
116448          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
116449          "name": "brace-expansion",
116450          "version": "1.1.11",
116451          "description": "Brace expansion as known from sh/bash",
116452          "licenses": [
116453            {
116454              "license": {
116455                "id": "MIT"
116456              }
116457            }
116458          ],
116459          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
116460          "purl": "pkg:npm/brace-expansion@1.1.11",
116461          "swid": {
116462            "attachment": {}
116463          },
116464          "pedigree": {},
116465          "externalReferences": [
116466            {
116467              "url": "git://github.com/juliangruber/brace-expansion.git",
116468              "type": "distribution"
116469            },
116470            {
116471              "url": "https://github.com/juliangruber/brace-expansion",
116472              "type": "website"
116473            }
116474          ],
116475          "evidence": {},
116476          "signature": {
116477            "signature": {
116478              "publicKey": {}
116479            }
116480          },
116481          "modelCard": {
116482            "modelParameters": {
116483              "approach": {}
116484            },
116485            "quantitativeAnalysis": {
116486              "graphics": {}
116487            },
116488            "considerations": {}
116489          }
116490        },
116491        {
116492          "type": "library",
116493          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=8aefa0d5bf7ea5ce",
116494          "supplier": {},
116495          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
116496          "name": "brace-expansion",
116497          "version": "1.1.11",
116498          "description": "Brace expansion as known from sh/bash",
116499          "licenses": [
116500            {
116501              "license": {
116502                "id": "MIT"
116503              }
116504            }
116505          ],
116506          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
116507          "purl": "pkg:npm/brace-expansion@1.1.11",
116508          "swid": {
116509            "attachment": {}
116510          },
116511          "pedigree": {},
116512          "externalReferences": [
116513            {
116514              "url": "git://github.com/juliangruber/brace-expansion.git",
116515              "type": "distribution"
116516            },
116517            {
116518              "url": "https://github.com/juliangruber/brace-expansion",
116519              "type": "website"
116520            }
116521          ],
116522          "evidence": {},
116523          "signature": {
116524            "signature": {
116525              "publicKey": {}
116526            }
116527          },
116528          "modelCard": {
116529            "modelParameters": {
116530              "approach": {}
116531            },
116532            "quantitativeAnalysis": {
116533              "graphics": {}
116534            },
116535            "considerations": {}
116536          }
116537        },
116538        {
116539          "type": "library",
116540          "bom-ref": "pkg:npm/brace-expansion@2.0.1?package-id=70d44e2ab0a06da3",
116541          "supplier": {},
116542          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
116543          "name": "brace-expansion",
116544          "version": "2.0.1",
116545          "description": "Brace expansion as known from sh/bash",
116546          "licenses": [
116547            {
116548              "license": {
116549                "id": "MIT"
116550              }
116551            }
116552          ],
116553          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:2.0.1:*:*:*:*:*:*:*",
116554          "purl": "pkg:npm/brace-expansion@2.0.1",
116555          "swid": {
116556            "attachment": {}
116557          },
116558          "pedigree": {},
116559          "externalReferences": [
116560            {
116561              "url": "git://github.com/juliangruber/brace-expansion.git",
116562              "type": "distribution"
116563            },
116564            {
116565              "url": "https://github.com/juliangruber/brace-expansion",
116566              "type": "website"
116567            }
116568          ],
116569          "evidence": {},
116570          "signature": {
116571            "signature": {
116572              "publicKey": {}
116573            }
116574          },
116575          "modelCard": {
116576            "modelParameters": {
116577              "approach": {}
116578            },
116579            "quantitativeAnalysis": {
116580              "graphics": {}
116581            },
116582            "considerations": {}
116583          }
116584        },
116585        {
116586          "type": "library",
116587          "bom-ref": "pkg:npm/buffer-equal-constant-time@1.0.1?package-id=10d782a173248da8",
116588          "supplier": {},
116589          "author": "GoInstant Inc., a salesforce.com company",
116590          "name": "buffer-equal-constant-time",
116591          "version": "1.0.1",
116592          "description": "Constant-time comparison of Buffers",
116593          "licenses": [
116594            {
116595              "license": {
116596                "id": "BSD-3-Clause"
116597              }
116598            }
116599          ],
116600          "cpe": "cpe:2.3:a:buffer-equal-constant-time:buffer-equal-constant-time:1.0.1:*:*:*:*:*:*:*",
116601          "purl": "pkg:npm/buffer-equal-constant-time@1.0.1",
116602          "swid": {
116603            "attachment": {}
116604          },
116605          "pedigree": {},
116606          "externalReferences": [
116607            {
116608              "url": "git@github.com:goinstant/buffer-equal-constant-time.git",
116609              "type": "distribution"
116610            }
116611          ],
116612          "evidence": {},
116613          "signature": {
116614            "signature": {
116615              "publicKey": {}
116616            }
116617          },
116618          "modelCard": {
116619            "modelParameters": {
116620              "approach": {}
116621            },
116622            "quantitativeAnalysis": {
116623              "graphics": {}
116624            },
116625            "considerations": {}
116626          }
116627        },
116628        {
116629          "type": "library",
116630          "bom-ref": "pkg:npm/builtins@5.0.1?package-id=af6ac207a0c6926d",
116631          "supplier": {},
116632          "name": "builtins",
116633          "version": "5.0.1",
116634          "description": "List of node.js builtin modules",
116635          "licenses": [
116636            {
116637              "license": {
116638                "id": "MIT"
116639              }
116640            }
116641          ],
116642          "cpe": "cpe:2.3:a:builtins:builtins:5.0.1:*:*:*:*:*:*:*",
116643          "purl": "pkg:npm/builtins@5.0.1",
116644          "swid": {
116645            "attachment": {}
116646          },
116647          "pedigree": {},
116648          "externalReferences": [
116649            {
116650              "url": "juliangruber/builtins",
116651              "type": "distribution"
116652            }
116653          ],
116654          "evidence": {},
116655          "signature": {
116656            "signature": {
116657              "publicKey": {}
116658            }
116659          },
116660          "modelCard": {
116661            "modelParameters": {
116662              "approach": {}
116663            },
116664            "quantitativeAnalysis": {
116665              "graphics": {}
116666            },
116667            "considerations": {}
116668          }
116669        },
116670        {
116671          "type": "application",
116672          "bom-ref": "e14718c64f5147f4",
116673          "supplier": {},
116674          "name": "busybox",
116675          "version": "1.35.0",
116676          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
116677          "swid": {
116678            "attachment": {}
116679          },
116680          "pedigree": {},
116681          "evidence": {},
116682          "signature": {
116683            "signature": {
116684              "publicKey": {}
116685            }
116686          },
116687          "modelCard": {
116688            "modelParameters": {
116689              "approach": {}
116690            },
116691            "quantitativeAnalysis": {
116692              "graphics": {}
116693            },
116694            "considerations": {}
116695          }
116696        },
116697        {
116698          "type": "library",
116699          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=4b48ef6f6b983526",
116700          "supplier": {},
116701          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
116702          "name": "busybox",
116703          "version": "1.35.0-r17",
116704          "description": "Size optimized toolbox of many common UNIX utilities",
116705          "licenses": [
116706            {
116707              "license": {
116708                "id": "GPL-2.0-only"
116709              }
116710            }
116711          ],
116712          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r17:*:*:*:*:*:*:*",
116713          "purl": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5",
116714          "swid": {
116715            "attachment": {}
116716          },
116717          "pedigree": {},
116718          "externalReferences": [
116719            {
116720              "url": "https://busybox.net/",
116721              "type": "distribution"
116722            }
116723          ],
116724          "evidence": {},
116725          "signature": {
116726            "signature": {
116727              "publicKey": {}
116728            }
116729          },
116730          "modelCard": {
116731            "modelParameters": {
116732              "approach": {}
116733            },
116734            "quantitativeAnalysis": {
116735              "graphics": {}
116736            },
116737            "considerations": {}
116738          }
116739        },
116740        {
116741          "type": "library",
116742          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5\u0026package-id=30622a1848b22bca",
116743          "supplier": {},
116744          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
116745          "name": "ca-certificates-bundle",
116746          "version": "20220614-r0",
116747          "description": "Pre generated bundle of Mozilla certificates",
116748          "licenses": [
116749            {
116750              "license": {
116751                "id": "MPL-2.0"
116752              }
116753            },
116754            {
116755              "license": {
116756                "name": "AND"
116757              }
116758            },
116759            {
116760              "license": {
116761                "id": "MIT"
116762              }
116763            }
116764          ],
116765          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
116766          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5",
116767          "swid": {
116768            "attachment": {}
116769          },
116770          "pedigree": {},
116771          "externalReferences": [
116772            {
116773              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
116774              "type": "distribution"
116775            }
116776          ],
116777          "evidence": {},
116778          "signature": {
116779            "signature": {
116780              "publicKey": {}
116781            }
116782          },
116783          "modelCard": {
116784            "modelParameters": {
116785              "approach": {}
116786            },
116787            "quantitativeAnalysis": {
116788              "graphics": {}
116789            },
116790            "considerations": {}
116791          }
116792        },
116793        {
116794          "type": "library",
116795          "bom-ref": "pkg:npm/cacache@16.1.3?package-id=4e055fb1e595c11",
116796          "supplier": {},
116797          "author": "GitHub Inc.",
116798          "name": "cacache",
116799          "version": "16.1.3",
116800          "description": "Fast, fault-tolerant, cross-platform, disk-based, data-agnostic, content-addressable cache.",
116801          "licenses": [
116802            {
116803              "license": {
116804                "id": "ISC"
116805              }
116806            }
116807          ],
116808          "cpe": "cpe:2.3:a:cacache:cacache:16.1.3:*:*:*:*:*:*:*",
116809          "purl": "pkg:npm/cacache@16.1.3",
116810          "swid": {
116811            "attachment": {}
116812          },
116813          "pedigree": {},
116814          "externalReferences": [
116815            {
116816              "url": "https://github.com/npm/cacache.git",
116817              "type": "distribution"
116818            }
116819          ],
116820          "evidence": {},
116821          "signature": {
116822            "signature": {
116823              "publicKey": {}
116824            }
116825          },
116826          "modelCard": {
116827            "modelParameters": {
116828              "approach": {}
116829            },
116830            "quantitativeAnalysis": {
116831              "graphics": {}
116832            },
116833            "considerations": {}
116834          }
116835        },
116836        {
116837          "type": "library",
116838          "bom-ref": "pkg:npm/chalk@4.1.2?package-id=b12178723b56594f",
116839          "supplier": {},
116840          "name": "chalk",
116841          "version": "4.1.2",
116842          "description": "Terminal string styling done right",
116843          "licenses": [
116844            {
116845              "license": {
116846                "id": "MIT"
116847              }
116848            }
116849          ],
116850          "cpe": "cpe:2.3:a:chalk:chalk:4.1.2:*:*:*:*:*:*:*",
116851          "purl": "pkg:npm/chalk@4.1.2",
116852          "swid": {
116853            "attachment": {}
116854          },
116855          "pedigree": {},
116856          "externalReferences": [
116857            {
116858              "url": "chalk/chalk",
116859              "type": "distribution"
116860            }
116861          ],
116862          "evidence": {},
116863          "signature": {
116864            "signature": {
116865              "publicKey": {}
116866            }
116867          },
116868          "modelCard": {
116869            "modelParameters": {
116870              "approach": {}
116871            },
116872            "quantitativeAnalysis": {
116873              "graphics": {}
116874            },
116875            "considerations": {}
116876          }
116877        },
116878        {
116879          "type": "library",
116880          "bom-ref": "pkg:npm/chownr@2.0.0?package-id=b5088c57ceda122f",
116881          "supplier": {},
116882          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
116883          "name": "chownr",
116884          "version": "2.0.0",
116885          "description": "like `chown -R`",
116886          "licenses": [
116887            {
116888              "license": {
116889                "id": "ISC"
116890              }
116891            }
116892          ],
116893          "cpe": "cpe:2.3:a:chownr:chownr:2.0.0:*:*:*:*:*:*:*",
116894          "purl": "pkg:npm/chownr@2.0.0",
116895          "swid": {
116896            "attachment": {}
116897          },
116898          "pedigree": {},
116899          "externalReferences": [
116900            {
116901              "url": "git://github.com/isaacs/chownr.git",
116902              "type": "distribution"
116903            }
116904          ],
116905          "evidence": {},
116906          "signature": {
116907            "signature": {
116908              "publicKey": {}
116909            }
116910          },
116911          "modelCard": {
116912            "modelParameters": {
116913              "approach": {}
116914            },
116915            "quantitativeAnalysis": {
116916              "graphics": {}
116917            },
116918            "considerations": {}
116919          }
116920        },
116921        {
116922          "type": "library",
116923          "bom-ref": "pkg:npm/cidr-regex@3.1.1?package-id=be2d165b38649e26",
116924          "supplier": {},
116925          "author": "silverwind \u003cme@silverwind.io\u003e",
116926          "name": "cidr-regex",
116927          "version": "3.1.1",
116928          "description": "Regular expression for matching IP addresses in CIDR notation",
116929          "licenses": [
116930            {
116931              "license": {
116932                "id": "BSD-2-Clause"
116933              }
116934            }
116935          ],
116936          "cpe": "cpe:2.3:a:cidr-regex:cidr-regex:3.1.1:*:*:*:*:*:*:*",
116937          "purl": "pkg:npm/cidr-regex@3.1.1",
116938          "swid": {
116939            "attachment": {}
116940          },
116941          "pedigree": {},
116942          "externalReferences": [
116943            {
116944              "url": "silverwind/cidr-regex",
116945              "type": "distribution"
116946            }
116947          ],
116948          "evidence": {},
116949          "signature": {
116950            "signature": {
116951              "publicKey": {}
116952            }
116953          },
116954          "modelCard": {
116955            "modelParameters": {
116956              "approach": {}
116957            },
116958            "quantitativeAnalysis": {
116959              "graphics": {}
116960            },
116961            "considerations": {}
116962          }
116963        },
116964        {
116965          "type": "library",
116966          "bom-ref": "pkg:npm/clean-stack@2.2.0?package-id=9a5c51e7acb4b115",
116967          "supplier": {},
116968          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
116969          "name": "clean-stack",
116970          "version": "2.2.0",
116971          "description": "Clean up error stack traces",
116972          "licenses": [
116973            {
116974              "license": {
116975                "id": "MIT"
116976              }
116977            }
116978          ],
116979          "cpe": "cpe:2.3:a:clean-stack:clean-stack:2.2.0:*:*:*:*:*:*:*",
116980          "purl": "pkg:npm/clean-stack@2.2.0",
116981          "swid": {
116982            "attachment": {}
116983          },
116984          "pedigree": {},
116985          "externalReferences": [
116986            {
116987              "url": "sindresorhus/clean-stack",
116988              "type": "distribution"
116989            }
116990          ],
116991          "evidence": {},
116992          "signature": {
116993            "signature": {
116994              "publicKey": {}
116995            }
116996          },
116997          "modelCard": {
116998            "modelParameters": {
116999              "approach": {}
117000            },
117001            "quantitativeAnalysis": {
117002              "graphics": {}
117003            },
117004            "considerations": {}
117005          }
117006        },
117007        {
117008          "type": "library",
117009          "bom-ref": "pkg:npm/cli-columns@4.0.0?package-id=61a1dfb277c2e6f7",
117010          "supplier": {},
117011          "author": "Shannon Moeller \u003cme@shannonmoeller\u003e (http://shannonmoeller.com)",
117012          "name": "cli-columns",
117013          "version": "4.0.0",
117014          "description": "Columnated lists for the CLI.",
117015          "licenses": [
117016            {
117017              "license": {
117018                "id": "MIT"
117019              }
117020            }
117021          ],
117022          "cpe": "cpe:2.3:a:shannonmoeller:cli-columns:4.0.0:*:*:*:*:*:*:*",
117023          "purl": "pkg:npm/cli-columns@4.0.0",
117024          "swid": {
117025            "attachment": {}
117026          },
117027          "pedigree": {},
117028          "externalReferences": [
117029            {
117030              "url": "shannonmoeller/cli-columns",
117031              "type": "distribution"
117032            },
117033            {
117034              "url": "https://github.com/shannonmoeller/cli-columns#readme",
117035              "type": "website"
117036            }
117037          ],
117038          "evidence": {},
117039          "signature": {
117040            "signature": {
117041              "publicKey": {}
117042            }
117043          },
117044          "modelCard": {
117045            "modelParameters": {
117046              "approach": {}
117047            },
117048            "quantitativeAnalysis": {
117049              "graphics": {}
117050            },
117051            "considerations": {}
117052          }
117053        },
117054        {
117055          "type": "library",
117056          "bom-ref": "pkg:npm/cli-table3@0.6.2?package-id=c77ee2194bd52f3d",
117057          "supplier": {},
117058          "author": "James Talmage",
117059          "name": "cli-table3",
117060          "version": "0.6.2",
117061          "description": "Pretty unicode tables for the command line. Based on the original cli-table.",
117062          "licenses": [
117063            {
117064              "license": {
117065                "id": "MIT"
117066              }
117067            }
117068          ],
117069          "cpe": "cpe:2.3:a:cli-table3:cli-table3:0.6.2:*:*:*:*:*:*:*",
117070          "purl": "pkg:npm/cli-table3@0.6.2",
117071          "swid": {
117072            "attachment": {}
117073          },
117074          "pedigree": {},
117075          "externalReferences": [
117076            {
117077              "url": "https://github.com/cli-table/cli-table3.git",
117078              "type": "distribution"
117079            },
117080            {
117081              "url": "https://github.com/cli-table/cli-table3",
117082              "type": "website"
117083            }
117084          ],
117085          "evidence": {},
117086          "signature": {
117087            "signature": {
117088              "publicKey": {}
117089            }
117090          },
117091          "modelCard": {
117092            "modelParameters": {
117093              "approach": {}
117094            },
117095            "quantitativeAnalysis": {
117096              "graphics": {}
117097            },
117098            "considerations": {}
117099          }
117100        },
117101        {
117102          "type": "library",
117103          "bom-ref": "pkg:npm/clone@1.0.4?package-id=44b571b36478d30c",
117104          "supplier": {},
117105          "author": "Paul Vorbach \u003cpaul@vorba.ch\u003e (http://paul.vorba.ch/)",
117106          "name": "clone",
117107          "version": "1.0.4",
117108          "description": "deep cloning of objects and arrays",
117109          "licenses": [
117110            {
117111              "license": {
117112                "id": "MIT"
117113              }
117114            }
117115          ],
117116          "cpe": "cpe:2.3:a:clone:clone:1.0.4:*:*:*:*:*:*:*",
117117          "purl": "pkg:npm/clone@1.0.4",
117118          "swid": {
117119            "attachment": {}
117120          },
117121          "pedigree": {},
117122          "externalReferences": [
117123            {
117124              "url": "git://github.com/pvorb/node-clone.git",
117125              "type": "distribution"
117126            }
117127          ],
117128          "evidence": {},
117129          "signature": {
117130            "signature": {
117131              "publicKey": {}
117132            }
117133          },
117134          "modelCard": {
117135            "modelParameters": {
117136              "approach": {}
117137            },
117138            "quantitativeAnalysis": {
117139              "graphics": {}
117140            },
117141            "considerations": {}
117142          }
117143        },
117144        {
117145          "type": "library",
117146          "bom-ref": "pkg:npm/cmd-shim@5.0.0?package-id=6701e31fdf422502",
117147          "supplier": {},
117148          "author": "GitHub Inc.",
117149          "name": "cmd-shim",
117150          "version": "5.0.0",
117151          "description": "Used in npm for command line application support",
117152          "licenses": [
117153            {
117154              "license": {
117155                "id": "ISC"
117156              }
117157            }
117158          ],
117159          "cpe": "cpe:2.3:a:cmd-shim:cmd-shim:5.0.0:*:*:*:*:*:*:*",
117160          "purl": "pkg:npm/cmd-shim@5.0.0",
117161          "swid": {
117162            "attachment": {}
117163          },
117164          "pedigree": {},
117165          "externalReferences": [
117166            {
117167              "url": "https://github.com/npm/cmd-shim.git",
117168              "type": "distribution"
117169            }
117170          ],
117171          "evidence": {},
117172          "signature": {
117173            "signature": {
117174              "publicKey": {}
117175            }
117176          },
117177          "modelCard": {
117178            "modelParameters": {
117179              "approach": {}
117180            },
117181            "quantitativeAnalysis": {
117182              "graphics": {}
117183            },
117184            "considerations": {}
117185          }
117186        },
117187        {
117188          "type": "library",
117189          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=2be936aafe32cf82",
117190          "supplier": {},
117191          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
117192          "name": "color-convert",
117193          "version": "2.0.1",
117194          "description": "Plain color conversion functions",
117195          "licenses": [
117196            {
117197              "license": {
117198                "id": "MIT"
117199              }
117200            }
117201          ],
117202          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
117203          "purl": "pkg:npm/color-convert@2.0.1",
117204          "swid": {
117205            "attachment": {}
117206          },
117207          "pedigree": {},
117208          "externalReferences": [
117209            {
117210              "url": "Qix-/color-convert",
117211              "type": "distribution"
117212            }
117213          ],
117214          "evidence": {},
117215          "signature": {
117216            "signature": {
117217              "publicKey": {}
117218            }
117219          },
117220          "modelCard": {
117221            "modelParameters": {
117222              "approach": {}
117223            },
117224            "quantitativeAnalysis": {
117225              "graphics": {}
117226            },
117227            "considerations": {}
117228          }
117229        },
117230        {
117231          "type": "library",
117232          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=b14fd2e37cdab40f",
117233          "supplier": {},
117234          "author": "DY \u003cdfcreative@gmail.com\u003e",
117235          "name": "color-name",
117236          "version": "1.1.4",
117237          "description": "A list of color names and its values",
117238          "licenses": [
117239            {
117240              "license": {
117241                "id": "MIT"
117242              }
117243            }
117244          ],
117245          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
117246          "purl": "pkg:npm/color-name@1.1.4",
117247          "swid": {
117248            "attachment": {}
117249          },
117250          "pedigree": {},
117251          "externalReferences": [
117252            {
117253              "url": "git@github.com:colorjs/color-name.git",
117254              "type": "distribution"
117255            },
117256            {
117257              "url": "https://github.com/colorjs/color-name",
117258              "type": "website"
117259            }
117260          ],
117261          "evidence": {},
117262          "signature": {
117263            "signature": {
117264              "publicKey": {}
117265            }
117266          },
117267          "modelCard": {
117268            "modelParameters": {
117269              "approach": {}
117270            },
117271            "quantitativeAnalysis": {
117272              "graphics": {}
117273            },
117274            "considerations": {}
117275          }
117276        },
117277        {
117278          "type": "library",
117279          "bom-ref": "pkg:npm/color-support@1.1.3?package-id=33c3f3c0dd43aff8",
117280          "supplier": {},
117281          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
117282          "name": "color-support",
117283          "version": "1.1.3",
117284          "description": "A module which will endeavor to guess your terminal's level of color support.",
117285          "licenses": [
117286            {
117287              "license": {
117288                "id": "ISC"
117289              }
117290            }
117291          ],
117292          "cpe": "cpe:2.3:a:color-support:color-support:1.1.3:*:*:*:*:*:*:*",
117293          "purl": "pkg:npm/color-support@1.1.3",
117294          "swid": {
117295            "attachment": {}
117296          },
117297          "pedigree": {},
117298          "externalReferences": [
117299            {
117300              "url": "git+https://github.com/isaacs/color-support.git",
117301              "type": "distribution"
117302            }
117303          ],
117304          "evidence": {},
117305          "signature": {
117306            "signature": {
117307              "publicKey": {}
117308            }
117309          },
117310          "modelCard": {
117311            "modelParameters": {
117312              "approach": {}
117313            },
117314            "quantitativeAnalysis": {
117315              "graphics": {}
117316            },
117317            "considerations": {}
117318          }
117319        },
117320        {
117321          "type": "library",
117322          "bom-ref": "pkg:npm/columnify@1.6.0?package-id=fc90187aad4a6027",
117323          "supplier": {},
117324          "author": "Tim Oxley",
117325          "name": "columnify",
117326          "version": "1.6.0",
117327          "description": "Render data in text columns. Supports in-column text-wrap.",
117328          "licenses": [
117329            {
117330              "license": {
117331                "id": "MIT"
117332              }
117333            }
117334          ],
117335          "cpe": "cpe:2.3:a:columnify:columnify:1.6.0:*:*:*:*:*:*:*",
117336          "purl": "pkg:npm/columnify@1.6.0",
117337          "swid": {
117338            "attachment": {}
117339          },
117340          "pedigree": {},
117341          "externalReferences": [
117342            {
117343              "url": "git://github.com/timoxley/columnify.git",
117344              "type": "distribution"
117345            },
117346            {
117347              "url": "https://github.com/timoxley/columnify",
117348              "type": "website"
117349            }
117350          ],
117351          "evidence": {},
117352          "signature": {
117353            "signature": {
117354              "publicKey": {}
117355            }
117356          },
117357          "modelCard": {
117358            "modelParameters": {
117359              "approach": {}
117360            },
117361            "quantitativeAnalysis": {
117362              "graphics": {}
117363            },
117364            "considerations": {}
117365          }
117366        },
117367        {
117368          "type": "library",
117369          "bom-ref": "pkg:npm/common-ancestor-path@1.0.1?package-id=4296edf5ae5437c0",
117370          "supplier": {},
117371          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
117372          "name": "common-ancestor-path",
117373          "version": "1.0.1",
117374          "description": "Find the common ancestor of 2 or more paths on Windows or Unix",
117375          "licenses": [
117376            {
117377              "license": {
117378                "id": "ISC"
117379              }
117380            }
117381          ],
117382          "cpe": "cpe:2.3:a:common-ancestor-path:common-ancestor-path:1.0.1:*:*:*:*:*:*:*",
117383          "purl": "pkg:npm/common-ancestor-path@1.0.1",
117384          "swid": {
117385            "attachment": {}
117386          },
117387          "pedigree": {},
117388          "externalReferences": [
117389            {
117390              "url": "git+https://github.com/isaacs/common-ancestor-path",
117391              "type": "distribution"
117392            }
117393          ],
117394          "evidence": {},
117395          "signature": {
117396            "signature": {
117397              "publicKey": {}
117398            }
117399          },
117400          "modelCard": {
117401            "modelParameters": {
117402              "approach": {}
117403            },
117404            "quantitativeAnalysis": {
117405              "graphics": {}
117406            },
117407            "considerations": {}
117408          }
117409        },
117410        {
117411          "type": "library",
117412          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=bdf14b65a5715b98",
117413          "supplier": {},
117414          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
117415          "name": "concat-map",
117416          "version": "0.0.1",
117417          "description": "concatenative mapdashery",
117418          "licenses": [
117419            {
117420              "license": {
117421                "id": "MIT"
117422              }
117423            }
117424          ],
117425          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
117426          "purl": "pkg:npm/concat-map@0.0.1",
117427          "swid": {
117428            "attachment": {}
117429          },
117430          "pedigree": {},
117431          "externalReferences": [
117432            {
117433              "url": "git://github.com/substack/node-concat-map.git",
117434              "type": "distribution"
117435            }
117436          ],
117437          "evidence": {},
117438          "signature": {
117439            "signature": {
117440              "publicKey": {}
117441            }
117442          },
117443          "modelCard": {
117444            "modelParameters": {
117445              "approach": {}
117446            },
117447            "quantitativeAnalysis": {
117448              "graphics": {}
117449            },
117450            "considerations": {}
117451          }
117452        },
117453        {
117454          "type": "library",
117455          "bom-ref": "pkg:npm/console-control-strings@1.1.0?package-id=f5b1c468fcf0a37a",
117456          "supplier": {},
117457          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
117458          "name": "console-control-strings",
117459          "version": "1.1.0",
117460          "description": "A library of cross-platform tested terminal/console command strings for doing things like color and cursor positioning.  This is a subset of both ansi and vt100.  All control codes included work on both Windows \u0026 Unix-like OSes, except where noted.",
117461          "licenses": [
117462            {
117463              "license": {
117464                "id": "ISC"
117465              }
117466            }
117467          ],
117468          "cpe": "cpe:2.3:a:console-control-strings:console-control-strings:1.1.0:*:*:*:*:*:*:*",
117469          "purl": "pkg:npm/console-control-strings@1.1.0",
117470          "swid": {
117471            "attachment": {}
117472          },
117473          "pedigree": {},
117474          "externalReferences": [
117475            {
117476              "url": "https://github.com/iarna/console-control-strings",
117477              "type": "distribution"
117478            }
117479          ],
117480          "evidence": {},
117481          "signature": {
117482            "signature": {
117483              "publicKey": {}
117484            }
117485          },
117486          "modelCard": {
117487            "modelParameters": {
117488              "approach": {}
117489            },
117490            "quantitativeAnalysis": {
117491              "graphics": {}
117492            },
117493            "considerations": {}
117494          }
117495        },
117496        {
117497          "type": "library",
117498          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=b29494ec5df233dd",
117499          "supplier": {},
117500          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
117501          "name": "core-util-is",
117502          "version": "1.0.2",
117503          "description": "The `util.is*` functions introduced in Node v0.12.",
117504          "licenses": [
117505            {
117506              "license": {
117507                "id": "MIT"
117508              }
117509            }
117510          ],
117511          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
117512          "purl": "pkg:npm/core-util-is@1.0.2",
117513          "swid": {
117514            "attachment": {}
117515          },
117516          "pedigree": {},
117517          "externalReferences": [
117518            {
117519              "url": "git://github.com/isaacs/core-util-is",
117520              "type": "distribution"
117521            }
117522          ],
117523          "evidence": {},
117524          "signature": {
117525            "signature": {
117526              "publicKey": {}
117527            }
117528          },
117529          "modelCard": {
117530            "modelParameters": {
117531              "approach": {}
117532            },
117533            "quantitativeAnalysis": {
117534              "graphics": {}
117535            },
117536            "considerations": {}
117537          }
117538        },
117539        {
117540          "type": "library",
117541          "bom-ref": "pkg:npm/corepack@0.17.0?package-id=9d78c3bef9c05db3",
117542          "supplier": {},
117543          "name": "corepack",
117544          "version": "0.17.0",
117545          "licenses": [
117546            {
117547              "license": {
117548                "id": "MIT"
117549              }
117550            }
117551          ],
117552          "cpe": "cpe:2.3:a:corepack:corepack:0.17.0:*:*:*:*:*:*:*",
117553          "purl": "pkg:npm/corepack@0.17.0",
117554          "swid": {
117555            "attachment": {}
117556          },
117557          "pedigree": {},
117558          "externalReferences": [
117559            {
117560              "url": "https://github.com/nodejs/corepack.git",
117561              "type": "distribution"
117562            },
117563            {
117564              "url": "https://github.com/nodejs/corepack#readme",
117565              "type": "website"
117566            }
117567          ],
117568          "evidence": {},
117569          "signature": {
117570            "signature": {
117571              "publicKey": {}
117572            }
117573          },
117574          "modelCard": {
117575            "modelParameters": {
117576              "approach": {}
117577            },
117578            "quantitativeAnalysis": {
117579              "graphics": {}
117580            },
117581            "considerations": {}
117582          }
117583        },
117584        {
117585          "type": "library",
117586          "bom-ref": "pkg:npm/cssesc@3.0.0?package-id=91a6a74efc4b88ba",
117587          "supplier": {},
117588          "author": "Mathias Bynens (https://mathiasbynens.be/)",
117589          "name": "cssesc",
117590          "version": "3.0.0",
117591          "description": "A JavaScript library for escaping CSS strings and identifiers while generating the shortest possible ASCII-only output.",
117592          "licenses": [
117593            {
117594              "license": {
117595                "id": "MIT"
117596              }
117597            }
117598          ],
117599          "cpe": "cpe:2.3:a:mathiasbynens:cssesc:3.0.0:*:*:*:*:*:*:*",
117600          "purl": "pkg:npm/cssesc@3.0.0",
117601          "swid": {
117602            "attachment": {}
117603          },
117604          "pedigree": {},
117605          "externalReferences": [
117606            {
117607              "url": "https://github.com/mathiasbynens/cssesc.git",
117608              "type": "distribution"
117609            },
117610            {
117611              "url": "https://mths.be/cssesc",
117612              "type": "website"
117613            }
117614          ],
117615          "evidence": {},
117616          "signature": {
117617            "signature": {
117618              "publicKey": {}
117619            }
117620          },
117621          "modelCard": {
117622            "modelParameters": {
117623              "approach": {}
117624            },
117625            "quantitativeAnalysis": {
117626              "graphics": {}
117627            },
117628            "considerations": {}
117629          }
117630        },
117631        {
117632          "type": "library",
117633          "bom-ref": "pkg:npm/debug@4.3.4?package-id=744fe4d31961f128",
117634          "supplier": {},
117635          "author": "Josh Junon \u003cjosh.junon@protonmail.com\u003e",
117636          "name": "debug",
117637          "version": "4.3.4",
117638          "description": "Lightweight debugging utility for Node.js and the browser",
117639          "licenses": [
117640            {
117641              "license": {
117642                "id": "MIT"
117643              }
117644            }
117645          ],
117646          "cpe": "cpe:2.3:a:debug-js:debug:4.3.4:*:*:*:*:*:*:*",
117647          "purl": "pkg:npm/debug@4.3.4",
117648          "swid": {
117649            "attachment": {}
117650          },
117651          "pedigree": {},
117652          "externalReferences": [
117653            {
117654              "url": "git://github.com/debug-js/debug.git",
117655              "type": "distribution"
117656            }
117657          ],
117658          "evidence": {},
117659          "signature": {
117660            "signature": {
117661              "publicKey": {}
117662            }
117663          },
117664          "modelCard": {
117665            "modelParameters": {
117666              "approach": {}
117667            },
117668            "quantitativeAnalysis": {
117669              "graphics": {}
117670            },
117671            "considerations": {}
117672          }
117673        },
117674        {
117675          "type": "library",
117676          "bom-ref": "pkg:npm/debuglog@1.0.1?package-id=de8cab91bb3727ee",
117677          "supplier": {},
117678          "author": "Sam Roberts \u003csam@strongloop.com\u003e",
117679          "name": "debuglog",
117680          "version": "1.0.1",
117681          "description": "backport of util.debuglog from node v0.11",
117682          "licenses": [
117683            {
117684              "license": {
117685                "id": "MIT"
117686              }
117687            }
117688          ],
117689          "cpe": "cpe:2.3:a:sam-github:debuglog:1.0.1:*:*:*:*:*:*:*",
117690          "purl": "pkg:npm/debuglog@1.0.1",
117691          "swid": {
117692            "attachment": {}
117693          },
117694          "pedigree": {},
117695          "externalReferences": [
117696            {
117697              "url": "https://github.com/sam-github/node-debuglog.git",
117698              "type": "distribution"
117699            }
117700          ],
117701          "evidence": {},
117702          "signature": {
117703            "signature": {
117704              "publicKey": {}
117705            }
117706          },
117707          "modelCard": {
117708            "modelParameters": {
117709              "approach": {}
117710            },
117711            "quantitativeAnalysis": {
117712              "graphics": {}
117713            },
117714            "considerations": {}
117715          }
117716        },
117717        {
117718          "type": "library",
117719          "bom-ref": "pkg:npm/defaults@1.0.3?package-id=539a687773af61fe",
117720          "supplier": {},
117721          "author": "Elijah Insua \u003ctmpvar@gmail.com\u003e",
117722          "name": "defaults",
117723          "version": "1.0.3",
117724          "description": "merge single level defaults over a config object",
117725          "licenses": [
117726            {
117727              "license": {
117728                "id": "MIT"
117729              }
117730            }
117731          ],
117732          "cpe": "cpe:2.3:a:defaults:defaults:1.0.3:*:*:*:*:*:*:*",
117733          "purl": "pkg:npm/defaults@1.0.3",
117734          "swid": {
117735            "attachment": {}
117736          },
117737          "pedigree": {},
117738          "externalReferences": [
117739            {
117740              "url": "git://github.com/tmpvar/defaults.git",
117741              "type": "distribution"
117742            }
117743          ],
117744          "evidence": {},
117745          "signature": {
117746            "signature": {
117747              "publicKey": {}
117748            }
117749          },
117750          "modelCard": {
117751            "modelParameters": {
117752              "approach": {}
117753            },
117754            "quantitativeAnalysis": {
117755              "graphics": {}
117756            },
117757            "considerations": {}
117758          }
117759        },
117760        {
117761          "type": "library",
117762          "bom-ref": "pkg:npm/delegates@1.0.0?package-id=ed0c22d60c260f5c",
117763          "supplier": {},
117764          "name": "delegates",
117765          "version": "1.0.0",
117766          "description": "delegate methods and accessors to another property",
117767          "licenses": [
117768            {
117769              "license": {
117770                "id": "MIT"
117771              }
117772            }
117773          ],
117774          "cpe": "cpe:2.3:a:delegates:delegates:1.0.0:*:*:*:*:*:*:*",
117775          "purl": "pkg:npm/delegates@1.0.0",
117776          "swid": {
117777            "attachment": {}
117778          },
117779          "pedigree": {},
117780          "externalReferences": [
117781            {
117782              "url": "visionmedia/node-delegates",
117783              "type": "distribution"
117784            }
117785          ],
117786          "evidence": {},
117787          "signature": {
117788            "signature": {
117789              "publicKey": {}
117790            }
117791          },
117792          "modelCard": {
117793            "modelParameters": {
117794              "approach": {}
117795            },
117796            "quantitativeAnalysis": {
117797              "graphics": {}
117798            },
117799            "considerations": {}
117800          }
117801        },
117802        {
117803          "type": "library",
117804          "bom-ref": "pkg:npm/depd@1.1.2?package-id=8f51ca0c72f74b81",
117805          "supplier": {},
117806          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
117807          "name": "depd",
117808          "version": "1.1.2",
117809          "description": "Deprecate all the things",
117810          "licenses": [
117811            {
117812              "license": {
117813                "id": "MIT"
117814              }
117815            }
117816          ],
117817          "cpe": "cpe:2.3:a:depd:depd:1.1.2:*:*:*:*:*:*:*",
117818          "purl": "pkg:npm/depd@1.1.2",
117819          "swid": {
117820            "attachment": {}
117821          },
117822          "pedigree": {},
117823          "externalReferences": [
117824            {
117825              "url": "dougwilson/nodejs-depd",
117826              "type": "distribution"
117827            }
117828          ],
117829          "evidence": {},
117830          "signature": {
117831            "signature": {
117832              "publicKey": {}
117833            }
117834          },
117835          "modelCard": {
117836            "modelParameters": {
117837              "approach": {}
117838            },
117839            "quantitativeAnalysis": {
117840              "graphics": {}
117841            },
117842            "considerations": {}
117843          }
117844        },
117845        {
117846          "type": "library",
117847          "bom-ref": "pkg:npm/dezalgo@1.0.4?package-id=d8ccca0e738815bf",
117848          "supplier": {},
117849          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
117850          "name": "dezalgo",
117851          "version": "1.0.4",
117852          "description": "Contain async insanity so that the dark pony lord doesn't eat souls",
117853          "licenses": [
117854            {
117855              "license": {
117856                "id": "ISC"
117857              }
117858            }
117859          ],
117860          "cpe": "cpe:2.3:a:dezalgo:dezalgo:1.0.4:*:*:*:*:*:*:*",
117861          "purl": "pkg:npm/dezalgo@1.0.4",
117862          "swid": {
117863            "attachment": {}
117864          },
117865          "pedigree": {},
117866          "externalReferences": [
117867            {
117868              "url": "https://github.com/npm/dezalgo",
117869              "type": "distribution"
117870            },
117871            {
117872              "url": "https://github.com/npm/dezalgo",
117873              "type": "website"
117874            }
117875          ],
117876          "evidence": {},
117877          "signature": {
117878            "signature": {
117879              "publicKey": {}
117880            }
117881          },
117882          "modelCard": {
117883            "modelParameters": {
117884              "approach": {}
117885            },
117886            "quantitativeAnalysis": {
117887              "graphics": {}
117888            },
117889            "considerations": {}
117890          }
117891        },
117892        {
117893          "type": "library",
117894          "bom-ref": "pkg:npm/diff@5.1.0?package-id=d6e2c2128602c71d",
117895          "supplier": {},
117896          "name": "diff",
117897          "version": "5.1.0",
117898          "description": "A javascript text diff implementation.",
117899          "licenses": [
117900            {
117901              "license": {
117902                "id": "BSD-3-Clause"
117903              }
117904            }
117905          ],
117906          "cpe": "cpe:2.3:a:kpdecker:diff:5.1.0:*:*:*:*:*:*:*",
117907          "purl": "pkg:npm/diff@5.1.0",
117908          "swid": {
117909            "attachment": {}
117910          },
117911          "pedigree": {},
117912          "externalReferences": [
117913            {
117914              "url": "git://github.com/kpdecker/jsdiff.git",
117915              "type": "distribution"
117916            }
117917          ],
117918          "evidence": {},
117919          "signature": {
117920            "signature": {
117921              "publicKey": {}
117922            }
117923          },
117924          "modelCard": {
117925            "modelParameters": {
117926              "approach": {}
117927            },
117928            "quantitativeAnalysis": {
117929              "graphics": {}
117930            },
117931            "considerations": {}
117932          }
117933        },
117934        {
117935          "type": "library",
117936          "bom-ref": "pkg:npm/duplexify@3.7.1?package-id=b65a8a6ad2a9c8bb",
117937          "supplier": {},
117938          "author": "Mathias Buus",
117939          "name": "duplexify",
117940          "version": "3.7.1",
117941          "description": "Turn a writable and readable stream into a streams2 duplex stream with support for async initialization and streams1/streams2 input",
117942          "licenses": [
117943            {
117944              "license": {
117945                "id": "MIT"
117946              }
117947            }
117948          ],
117949          "cpe": "cpe:2.3:a:duplexify:duplexify:3.7.1:*:*:*:*:*:*:*",
117950          "purl": "pkg:npm/duplexify@3.7.1",
117951          "swid": {
117952            "attachment": {}
117953          },
117954          "pedigree": {},
117955          "externalReferences": [
117956            {
117957              "url": "git://github.com/mafintosh/duplexify",
117958              "type": "distribution"
117959            },
117960            {
117961              "url": "https://github.com/mafintosh/duplexify",
117962              "type": "website"
117963            }
117964          ],
117965          "evidence": {},
117966          "signature": {
117967            "signature": {
117968              "publicKey": {}
117969            }
117970          },
117971          "modelCard": {
117972            "modelParameters": {
117973              "approach": {}
117974            },
117975            "quantitativeAnalysis": {
117976              "graphics": {}
117977            },
117978            "considerations": {}
117979          }
117980        },
117981        {
117982          "type": "library",
117983          "bom-ref": "pkg:npm/ecdsa-sig-formatter@1.0.11?package-id=641fb1a75989c2b9",
117984          "supplier": {},
117985          "author": "D2L Corporation",
117986          "name": "ecdsa-sig-formatter",
117987          "version": "1.0.11",
117988          "description": "Translate ECDSA signatures between ASN.1/DER and JOSE-style concatenation",
117989          "licenses": [
117990            {
117991              "license": {
117992                "id": "Apache-2.0"
117993              }
117994            }
117995          ],
117996          "cpe": "cpe:2.3:a:ecdsa-sig-formatter:ecdsa-sig-formatter:1.0.11:*:*:*:*:*:*:*",
117997          "purl": "pkg:npm/ecdsa-sig-formatter@1.0.11",
117998          "swid": {
117999            "attachment": {}
118000          },
118001          "pedigree": {},
118002          "externalReferences": [
118003            {
118004              "url": "git+ssh://git@github.com/Brightspace/node-ecdsa-sig-formatter.git",
118005              "type": "distribution"
118006            },
118007            {
118008              "url": "https://github.com/Brightspace/node-ecdsa-sig-formatter#readme",
118009              "type": "website"
118010            }
118011          ],
118012          "evidence": {},
118013          "signature": {
118014            "signature": {
118015              "publicKey": {}
118016            }
118017          },
118018          "modelCard": {
118019            "modelParameters": {
118020              "approach": {}
118021            },
118022            "quantitativeAnalysis": {
118023              "graphics": {}
118024            },
118025            "considerations": {}
118026          }
118027        },
118028        {
118029          "type": "library",
118030          "bom-ref": "pkg:npm/emoji-regex@8.0.0?package-id=6bb38678688ed46f",
118031          "supplier": {},
118032          "author": "Mathias Bynens (https://mathiasbynens.be/)",
118033          "name": "emoji-regex",
118034          "version": "8.0.0",
118035          "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
118036          "licenses": [
118037            {
118038              "license": {
118039                "id": "MIT"
118040              }
118041            }
118042          ],
118043          "cpe": "cpe:2.3:a:mathiasbynens:emoji-regex:8.0.0:*:*:*:*:*:*:*",
118044          "purl": "pkg:npm/emoji-regex@8.0.0",
118045          "swid": {
118046            "attachment": {}
118047          },
118048          "pedigree": {},
118049          "externalReferences": [
118050            {
118051              "url": "https://github.com/mathiasbynens/emoji-regex.git",
118052              "type": "distribution"
118053            },
118054            {
118055              "url": "https://mths.be/emoji-regex",
118056              "type": "website"
118057            }
118058          ],
118059          "evidence": {},
118060          "signature": {
118061            "signature": {
118062              "publicKey": {}
118063            }
118064          },
118065          "modelCard": {
118066            "modelParameters": {
118067              "approach": {}
118068            },
118069            "quantitativeAnalysis": {
118070              "graphics": {}
118071            },
118072            "considerations": {}
118073          }
118074        },
118075        {
118076          "type": "library",
118077          "bom-ref": "pkg:npm/encoding@0.1.13?package-id=e65b6a429cd40212",
118078          "supplier": {},
118079          "author": "Andris Reinman",
118080          "name": "encoding",
118081          "version": "0.1.13",
118082          "description": "Convert encodings, uses iconv-lite",
118083          "licenses": [
118084            {
118085              "license": {
118086                "id": "MIT"
118087              }
118088            }
118089          ],
118090          "cpe": "cpe:2.3:a:encoding:encoding:0.1.13:*:*:*:*:*:*:*",
118091          "purl": "pkg:npm/encoding@0.1.13",
118092          "swid": {
118093            "attachment": {}
118094          },
118095          "pedigree": {},
118096          "externalReferences": [
118097            {
118098              "url": "https://github.com/andris9/encoding.git",
118099              "type": "distribution"
118100            }
118101          ],
118102          "evidence": {},
118103          "signature": {
118104            "signature": {
118105              "publicKey": {}
118106            }
118107          },
118108          "modelCard": {
118109            "modelParameters": {
118110              "approach": {}
118111            },
118112            "quantitativeAnalysis": {
118113              "graphics": {}
118114            },
118115            "considerations": {}
118116          }
118117        },
118118        {
118119          "type": "library",
118120          "bom-ref": "pkg:npm/end-of-stream@1.4.4?package-id=aad6fd45daea5639",
118121          "supplier": {},
118122          "author": "Mathias Buus \u003cmathiasbuus@gmail.com\u003e",
118123          "name": "end-of-stream",
118124          "version": "1.4.4",
118125          "description": "Call a callback when a readable/writable/duplex stream has completed or failed.",
118126          "licenses": [
118127            {
118128              "license": {
118129                "id": "MIT"
118130              }
118131            }
118132          ],
118133          "cpe": "cpe:2.3:a:end-of-stream:end-of-stream:1.4.4:*:*:*:*:*:*:*",
118134          "purl": "pkg:npm/end-of-stream@1.4.4",
118135          "swid": {
118136            "attachment": {}
118137          },
118138          "pedigree": {},
118139          "externalReferences": [
118140            {
118141              "url": "git://github.com/mafintosh/end-of-stream.git",
118142              "type": "distribution"
118143            },
118144            {
118145              "url": "https://github.com/mafintosh/end-of-stream",
118146              "type": "website"
118147            }
118148          ],
118149          "evidence": {},
118150          "signature": {
118151            "signature": {
118152              "publicKey": {}
118153            }
118154          },
118155          "modelCard": {
118156            "modelParameters": {
118157              "approach": {}
118158            },
118159            "quantitativeAnalysis": {
118160              "graphics": {}
118161            },
118162            "considerations": {}
118163          }
118164        },
118165        {
118166          "type": "library",
118167          "bom-ref": "pkg:npm/env-paths@2.2.1?package-id=d14634fe75802cac",
118168          "supplier": {},
118169          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
118170          "name": "env-paths",
118171          "version": "2.2.1",
118172          "description": "Get paths for storing things like data, config, cache, etc",
118173          "licenses": [
118174            {
118175              "license": {
118176                "id": "MIT"
118177              }
118178            }
118179          ],
118180          "cpe": "cpe:2.3:a:env-paths:env-paths:2.2.1:*:*:*:*:*:*:*",
118181          "purl": "pkg:npm/env-paths@2.2.1",
118182          "swid": {
118183            "attachment": {}
118184          },
118185          "pedigree": {},
118186          "externalReferences": [
118187            {
118188              "url": "sindresorhus/env-paths",
118189              "type": "distribution"
118190            }
118191          ],
118192          "evidence": {},
118193          "signature": {
118194            "signature": {
118195              "publicKey": {}
118196            }
118197          },
118198          "modelCard": {
118199            "modelParameters": {
118200              "approach": {}
118201            },
118202            "quantitativeAnalysis": {
118203              "graphics": {}
118204            },
118205            "considerations": {}
118206          }
118207        },
118208        {
118209          "type": "library",
118210          "bom-ref": "pkg:npm/err-code@2.0.3?package-id=60b62094686938a4",
118211          "supplier": {},
118212          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
118213          "name": "err-code",
118214          "version": "2.0.3",
118215          "description": "Create an error with a code",
118216          "licenses": [
118217            {
118218              "license": {
118219                "id": "MIT"
118220              }
118221            }
118222          ],
118223          "cpe": "cpe:2.3:a:IndigoUnited:err-code:2.0.3:*:*:*:*:*:*:*",
118224          "purl": "pkg:npm/err-code@2.0.3",
118225          "swid": {
118226            "attachment": {}
118227          },
118228          "pedigree": {},
118229          "externalReferences": [
118230            {
118231              "url": "git://github.com/IndigoUnited/js-err-code.git",
118232              "type": "distribution"
118233            }
118234          ],
118235          "evidence": {},
118236          "signature": {
118237            "signature": {
118238              "publicKey": {}
118239            }
118240          },
118241          "modelCard": {
118242            "modelParameters": {
118243              "approach": {}
118244            },
118245            "quantitativeAnalysis": {
118246              "graphics": {}
118247            },
118248            "considerations": {}
118249          }
118250        },
118251        {
118252          "type": "library",
118253          "bom-ref": "pkg:npm/fastest-levenshtein@1.0.12?package-id=f703cf6832613e31",
118254          "supplier": {},
118255          "author": "Kasper U. Weihe",
118256          "name": "fastest-levenshtein",
118257          "version": "1.0.12",
118258          "description": "Fastest Levenshtein distance implementation in JS.",
118259          "licenses": [
118260            {
118261              "license": {
118262                "id": "MIT"
118263              }
118264            }
118265          ],
118266          "cpe": "cpe:2.3:a:fastest-levenshtein:fastest-levenshtein:1.0.12:*:*:*:*:*:*:*",
118267          "purl": "pkg:npm/fastest-levenshtein@1.0.12",
118268          "swid": {
118269            "attachment": {}
118270          },
118271          "pedigree": {},
118272          "externalReferences": [
118273            {
118274              "url": "git+https://github.com/ka-weihe/fastest-levenshtein.git",
118275              "type": "distribution"
118276            },
118277            {
118278              "url": "https://github.com/ka-weihe/fastest-levenshtein#README",
118279              "type": "website"
118280            }
118281          ],
118282          "evidence": {},
118283          "signature": {
118284            "signature": {
118285              "publicKey": {}
118286            }
118287          },
118288          "modelCard": {
118289            "modelParameters": {
118290              "approach": {}
118291            },
118292            "quantitativeAnalysis": {
118293              "graphics": {}
118294            },
118295            "considerations": {}
118296          }
118297        },
118298        {
118299          "type": "library",
118300          "bom-ref": "pkg:npm/fs-minipass@2.1.0?package-id=398fbbb28fb7e1f4",
118301          "supplier": {},
118302          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
118303          "name": "fs-minipass",
118304          "version": "2.1.0",
118305          "description": "fs read and write streams based on minipass",
118306          "licenses": [
118307            {
118308              "license": {
118309                "id": "ISC"
118310              }
118311            }
118312          ],
118313          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:2.1.0:*:*:*:*:*:*:*",
118314          "purl": "pkg:npm/fs-minipass@2.1.0",
118315          "swid": {
118316            "attachment": {}
118317          },
118318          "pedigree": {},
118319          "externalReferences": [
118320            {
118321              "url": "git+https://github.com/npm/fs-minipass.git",
118322              "type": "distribution"
118323            },
118324            {
118325              "url": "https://github.com/npm/fs-minipass#readme",
118326              "type": "website"
118327            }
118328          ],
118329          "evidence": {},
118330          "signature": {
118331            "signature": {
118332              "publicKey": {}
118333            }
118334          },
118335          "modelCard": {
118336            "modelParameters": {
118337              "approach": {}
118338            },
118339            "quantitativeAnalysis": {
118340              "graphics": {}
118341            },
118342            "considerations": {}
118343          }
118344        },
118345        {
118346          "type": "library",
118347          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=21800424481533b1",
118348          "supplier": {},
118349          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
118350          "name": "fs.realpath",
118351          "version": "1.0.0",
118352          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
118353          "licenses": [
118354            {
118355              "license": {
118356                "id": "ISC"
118357              }
118358            }
118359          ],
118360          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
118361          "purl": "pkg:npm/fs.realpath@1.0.0",
118362          "swid": {
118363            "attachment": {}
118364          },
118365          "pedigree": {},
118366          "externalReferences": [
118367            {
118368              "url": "git+https://github.com/isaacs/fs.realpath.git",
118369              "type": "distribution"
118370            }
118371          ],
118372          "evidence": {},
118373          "signature": {
118374            "signature": {
118375              "publicKey": {}
118376            }
118377          },
118378          "modelCard": {
118379            "modelParameters": {
118380              "approach": {}
118381            },
118382            "quantitativeAnalysis": {
118383              "graphics": {}
118384            },
118385            "considerations": {}
118386          }
118387        },
118388        {
118389          "type": "library",
118390          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=44648bf09db15f6c",
118391          "supplier": {},
118392          "author": "Raynos \u003craynos2@gmail.com\u003e",
118393          "name": "function-bind",
118394          "version": "1.1.1",
118395          "description": "Implementation of Function.prototype.bind",
118396          "licenses": [
118397            {
118398              "license": {
118399                "id": "MIT"
118400              }
118401            }
118402          ],
118403          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
118404          "purl": "pkg:npm/function-bind@1.1.1",
118405          "swid": {
118406            "attachment": {}
118407          },
118408          "pedigree": {},
118409          "externalReferences": [
118410            {
118411              "url": "git://github.com/Raynos/function-bind.git",
118412              "type": "distribution"
118413            },
118414            {
118415              "url": "https://github.com/Raynos/function-bind",
118416              "type": "website"
118417            }
118418          ],
118419          "evidence": {},
118420          "signature": {
118421            "signature": {
118422              "publicKey": {}
118423            }
118424          },
118425          "modelCard": {
118426            "modelParameters": {
118427              "approach": {}
118428            },
118429            "quantitativeAnalysis": {
118430              "graphics": {}
118431            },
118432            "considerations": {}
118433          }
118434        },
118435        {
118436          "type": "library",
118437          "bom-ref": "pkg:npm/gauge@4.0.4?package-id=fc4632a6e143d550",
118438          "supplier": {},
118439          "author": "GitHub Inc.",
118440          "name": "gauge",
118441          "version": "4.0.4",
118442          "description": "A terminal based horizontal gauge",
118443          "licenses": [
118444            {
118445              "license": {
118446                "id": "ISC"
118447              }
118448            }
118449          ],
118450          "cpe": "cpe:2.3:a:gauge:gauge:4.0.4:*:*:*:*:*:*:*",
118451          "purl": "pkg:npm/gauge@4.0.4",
118452          "swid": {
118453            "attachment": {}
118454          },
118455          "pedigree": {},
118456          "externalReferences": [
118457            {
118458              "url": "https://github.com/npm/gauge.git",
118459              "type": "distribution"
118460            },
118461            {
118462              "url": "https://github.com/npm/gauge",
118463              "type": "website"
118464            }
118465          ],
118466          "evidence": {},
118467          "signature": {
118468            "signature": {
118469              "publicKey": {}
118470            }
118471          },
118472          "modelCard": {
118473            "modelParameters": {
118474              "approach": {}
118475            },
118476            "quantitativeAnalysis": {
118477              "graphics": {}
118478            },
118479            "considerations": {}
118480          }
118481        },
118482        {
118483          "type": "library",
118484          "bom-ref": "pkg:npm/glob@7.2.3?package-id=b961e222f6e54786",
118485          "supplier": {},
118486          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
118487          "name": "glob",
118488          "version": "7.2.3",
118489          "description": "a little globber",
118490          "licenses": [
118491            {
118492              "license": {
118493                "id": "ISC"
118494              }
118495            }
118496          ],
118497          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
118498          "purl": "pkg:npm/glob@7.2.3",
118499          "swid": {
118500            "attachment": {}
118501          },
118502          "pedigree": {},
118503          "externalReferences": [
118504            {
118505              "url": "git://github.com/isaacs/node-glob.git",
118506              "type": "distribution"
118507            }
118508          ],
118509          "evidence": {},
118510          "signature": {
118511            "signature": {
118512              "publicKey": {}
118513            }
118514          },
118515          "modelCard": {
118516            "modelParameters": {
118517              "approach": {}
118518            },
118519            "quantitativeAnalysis": {
118520              "graphics": {}
118521            },
118522            "considerations": {}
118523          }
118524        },
118525        {
118526          "type": "library",
118527          "bom-ref": "pkg:npm/glob@7.2.3?package-id=37af2473a85a6fa0",
118528          "supplier": {},
118529          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
118530          "name": "glob",
118531          "version": "7.2.3",
118532          "description": "a little globber",
118533          "licenses": [
118534            {
118535              "license": {
118536                "id": "ISC"
118537              }
118538            }
118539          ],
118540          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
118541          "purl": "pkg:npm/glob@7.2.3",
118542          "swid": {
118543            "attachment": {}
118544          },
118545          "pedigree": {},
118546          "externalReferences": [
118547            {
118548              "url": "git://github.com/isaacs/node-glob.git",
118549              "type": "distribution"
118550            }
118551          ],
118552          "evidence": {},
118553          "signature": {
118554            "signature": {
118555              "publicKey": {}
118556            }
118557          },
118558          "modelCard": {
118559            "modelParameters": {
118560              "approach": {}
118561            },
118562            "quantitativeAnalysis": {
118563              "graphics": {}
118564            },
118565            "considerations": {}
118566          }
118567        },
118568        {
118569          "type": "library",
118570          "bom-ref": "pkg:npm/glob@8.0.3?package-id=f9282babaa70cabf",
118571          "supplier": {},
118572          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
118573          "name": "glob",
118574          "version": "8.0.3",
118575          "description": "a little globber",
118576          "licenses": [
118577            {
118578              "license": {
118579                "id": "ISC"
118580              }
118581            }
118582          ],
118583          "cpe": "cpe:2.3:a:isaacs:glob:8.0.3:*:*:*:*:*:*:*",
118584          "purl": "pkg:npm/glob@8.0.3",
118585          "swid": {
118586            "attachment": {}
118587          },
118588          "pedigree": {},
118589          "externalReferences": [
118590            {
118591              "url": "git://github.com/isaacs/node-glob.git",
118592              "type": "distribution"
118593            }
118594          ],
118595          "evidence": {},
118596          "signature": {
118597            "signature": {
118598              "publicKey": {}
118599            }
118600          },
118601          "modelCard": {
118602            "modelParameters": {
118603              "approach": {}
118604            },
118605            "quantitativeAnalysis": {
118606              "graphics": {}
118607            },
118608            "considerations": {}
118609          }
118610        },
118611        {
118612          "type": "library",
118613          "bom-ref": "pkg:npm/graceful-fs@4.2.10?package-id=9591c6b5bd9602cc",
118614          "supplier": {},
118615          "name": "graceful-fs",
118616          "version": "4.2.10",
118617          "description": "A drop-in replacement for fs, making various improvements.",
118618          "licenses": [
118619            {
118620              "license": {
118621                "id": "ISC"
118622              }
118623            }
118624          ],
118625          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.10:*:*:*:*:*:*:*",
118626          "purl": "pkg:npm/graceful-fs@4.2.10",
118627          "swid": {
118628            "attachment": {}
118629          },
118630          "pedigree": {},
118631          "externalReferences": [
118632            {
118633              "url": "https://github.com/isaacs/node-graceful-fs",
118634              "type": "distribution"
118635            }
118636          ],
118637          "evidence": {},
118638          "signature": {
118639            "signature": {
118640              "publicKey": {}
118641            }
118642          },
118643          "modelCard": {
118644            "modelParameters": {
118645              "approach": {}
118646            },
118647            "quantitativeAnalysis": {
118648              "graphics": {}
118649            },
118650            "considerations": {}
118651          }
118652        },
118653        {
118654          "type": "library",
118655          "bom-ref": "pkg:npm/has@1.0.3?package-id=57072cf8ae347274",
118656          "supplier": {},
118657          "author": "Thiago de Arruda \u003ctpadilha84@gmail.com\u003e",
118658          "name": "has",
118659          "version": "1.0.3",
118660          "description": "Object.prototype.hasOwnProperty.call shortcut",
118661          "licenses": [
118662            {
118663              "license": {
118664                "id": "MIT"
118665              }
118666            }
118667          ],
118668          "cpe": "cpe:2.3:a:tarruda:has:1.0.3:*:*:*:*:*:*:*",
118669          "purl": "pkg:npm/has@1.0.3",
118670          "swid": {
118671            "attachment": {}
118672          },
118673          "pedigree": {},
118674          "externalReferences": [
118675            {
118676              "url": "git://github.com/tarruda/has.git",
118677              "type": "distribution"
118678            },
118679            {
118680              "url": "https://github.com/tarruda/has",
118681              "type": "website"
118682            }
118683          ],
118684          "evidence": {},
118685          "signature": {
118686            "signature": {
118687              "publicKey": {}
118688            }
118689          },
118690          "modelCard": {
118691            "modelParameters": {
118692              "approach": {}
118693            },
118694            "quantitativeAnalysis": {
118695              "graphics": {}
118696            },
118697            "considerations": {}
118698          }
118699        },
118700        {
118701          "type": "library",
118702          "bom-ref": "pkg:npm/has-flag@4.0.0?package-id=1ac717b55f99f4f2",
118703          "supplier": {},
118704          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
118705          "name": "has-flag",
118706          "version": "4.0.0",
118707          "description": "Check if argv has a specific flag",
118708          "licenses": [
118709            {
118710              "license": {
118711                "id": "MIT"
118712              }
118713            }
118714          ],
118715          "cpe": "cpe:2.3:a:has-flag:has-flag:4.0.0:*:*:*:*:*:*:*",
118716          "purl": "pkg:npm/has-flag@4.0.0",
118717          "swid": {
118718            "attachment": {}
118719          },
118720          "pedigree": {},
118721          "externalReferences": [
118722            {
118723              "url": "sindresorhus/has-flag",
118724              "type": "distribution"
118725            }
118726          ],
118727          "evidence": {},
118728          "signature": {
118729            "signature": {
118730              "publicKey": {}
118731            }
118732          },
118733          "modelCard": {
118734            "modelParameters": {
118735              "approach": {}
118736            },
118737            "quantitativeAnalysis": {
118738              "graphics": {}
118739            },
118740            "considerations": {}
118741          }
118742        },
118743        {
118744          "type": "library",
118745          "bom-ref": "pkg:npm/has-unicode@2.0.1?package-id=28dbbd6e7951181f",
118746          "supplier": {},
118747          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
118748          "name": "has-unicode",
118749          "version": "2.0.1",
118750          "description": "Try to guess if your terminal supports unicode",
118751          "licenses": [
118752            {
118753              "license": {
118754                "id": "ISC"
118755              }
118756            }
118757          ],
118758          "cpe": "cpe:2.3:a:has-unicode:has-unicode:2.0.1:*:*:*:*:*:*:*",
118759          "purl": "pkg:npm/has-unicode@2.0.1",
118760          "swid": {
118761            "attachment": {}
118762          },
118763          "pedigree": {},
118764          "externalReferences": [
118765            {
118766              "url": "https://github.com/iarna/has-unicode",
118767              "type": "distribution"
118768            },
118769            {
118770              "url": "https://github.com/iarna/has-unicode",
118771              "type": "website"
118772            }
118773          ],
118774          "evidence": {},
118775          "signature": {
118776            "signature": {
118777              "publicKey": {}
118778            }
118779          },
118780          "modelCard": {
118781            "modelParameters": {
118782              "approach": {}
118783            },
118784            "quantitativeAnalysis": {
118785              "graphics": {}
118786            },
118787            "considerations": {}
118788          }
118789        },
118790        {
118791          "type": "library",
118792          "bom-ref": "pkg:npm/hosted-git-info@5.2.1?package-id=daac03af08cd11f6",
118793          "supplier": {},
118794          "author": "GitHub Inc.",
118795          "name": "hosted-git-info",
118796          "version": "5.2.1",
118797          "description": "Provides metadata and conversions from repository urls for GitHub, Bitbucket and GitLab",
118798          "licenses": [
118799            {
118800              "license": {
118801                "id": "ISC"
118802              }
118803            }
118804          ],
118805          "cpe": "cpe:2.3:a:hosted-git-info:hosted-git-info:5.2.1:*:*:*:*:*:*:*",
118806          "purl": "pkg:npm/hosted-git-info@5.2.1",
118807          "swid": {
118808            "attachment": {}
118809          },
118810          "pedigree": {},
118811          "externalReferences": [
118812            {
118813              "url": "https://github.com/npm/hosted-git-info.git",
118814              "type": "distribution"
118815            },
118816            {
118817              "url": "https://github.com/npm/hosted-git-info",
118818              "type": "website"
118819            }
118820          ],
118821          "evidence": {},
118822          "signature": {
118823            "signature": {
118824              "publicKey": {}
118825            }
118826          },
118827          "modelCard": {
118828            "modelParameters": {
118829              "approach": {}
118830            },
118831            "quantitativeAnalysis": {
118832              "graphics": {}
118833            },
118834            "considerations": {}
118835          }
118836        },
118837        {
118838          "type": "library",
118839          "bom-ref": "pkg:npm/http-cache-semantics@4.1.1?package-id=916aa3ebe914a835",
118840          "supplier": {},
118841          "author": "Kornel Lesiński \u003ckornel@geekhood.net\u003e (https://kornel.ski/)",
118842          "name": "http-cache-semantics",
118843          "version": "4.1.1",
118844          "description": "Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies",
118845          "licenses": [
118846            {
118847              "license": {
118848                "id": "BSD-2-Clause"
118849              }
118850            }
118851          ],
118852          "cpe": "cpe:2.3:a:http-cache-semantics:http-cache-semantics:4.1.1:*:*:*:*:*:*:*",
118853          "purl": "pkg:npm/http-cache-semantics@4.1.1",
118854          "swid": {
118855            "attachment": {}
118856          },
118857          "pedigree": {},
118858          "externalReferences": [
118859            {
118860              "url": "https://github.com/kornelski/http-cache-semantics.git",
118861              "type": "distribution"
118862            }
118863          ],
118864          "evidence": {},
118865          "signature": {
118866            "signature": {
118867              "publicKey": {}
118868            }
118869          },
118870          "modelCard": {
118871            "modelParameters": {
118872              "approach": {}
118873            },
118874            "quantitativeAnalysis": {
118875              "graphics": {}
118876            },
118877            "considerations": {}
118878          }
118879        },
118880        {
118881          "type": "library",
118882          "bom-ref": "pkg:npm/http-proxy-agent@5.0.0?package-id=af3d467415b1e643",
118883          "supplier": {},
118884          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
118885          "name": "http-proxy-agent",
118886          "version": "5.0.0",
118887          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTP",
118888          "licenses": [
118889            {
118890              "license": {
118891                "id": "MIT"
118892              }
118893            }
118894          ],
118895          "cpe": "cpe:2.3:a:http-proxy-agent:http-proxy-agent:5.0.0:*:*:*:*:*:*:*",
118896          "purl": "pkg:npm/http-proxy-agent@5.0.0",
118897          "swid": {
118898            "attachment": {}
118899          },
118900          "pedigree": {},
118901          "externalReferences": [
118902            {
118903              "url": "git://github.com/TooTallNate/node-http-proxy-agent.git",
118904              "type": "distribution"
118905            }
118906          ],
118907          "evidence": {},
118908          "signature": {
118909            "signature": {
118910              "publicKey": {}
118911            }
118912          },
118913          "modelCard": {
118914            "modelParameters": {
118915              "approach": {}
118916            },
118917            "quantitativeAnalysis": {
118918              "graphics": {}
118919            },
118920            "considerations": {}
118921          }
118922        },
118923        {
118924          "type": "library",
118925          "bom-ref": "pkg:npm/https-proxy-agent@5.0.1?package-id=b2694aac4dc305de",
118926          "supplier": {},
118927          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
118928          "name": "https-proxy-agent",
118929          "version": "5.0.1",
118930          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
118931          "licenses": [
118932            {
118933              "license": {
118934                "id": "MIT"
118935              }
118936            }
118937          ],
118938          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:5.0.1:*:*:*:*:*:*:*",
118939          "purl": "pkg:npm/https-proxy-agent@5.0.1",
118940          "swid": {
118941            "attachment": {}
118942          },
118943          "pedigree": {},
118944          "externalReferences": [
118945            {
118946              "url": "git://github.com/TooTallNate/node-https-proxy-agent.git",
118947              "type": "distribution"
118948            }
118949          ],
118950          "evidence": {},
118951          "signature": {
118952            "signature": {
118953              "publicKey": {}
118954            }
118955          },
118956          "modelCard": {
118957            "modelParameters": {
118958              "approach": {}
118959            },
118960            "quantitativeAnalysis": {
118961              "graphics": {}
118962            },
118963            "considerations": {}
118964          }
118965        },
118966        {
118967          "type": "library",
118968          "bom-ref": "pkg:npm/humanize-ms@1.2.1?package-id=d773c44dd2f9a86d",
118969          "supplier": {},
118970          "author": "dead-horse \u003cdead_horse@qq.com\u003e (http://deadhorse.me)",
118971          "name": "humanize-ms",
118972          "version": "1.2.1",
118973          "description": "transform humanize time to ms",
118974          "licenses": [
118975            {
118976              "license": {
118977                "id": "MIT"
118978              }
118979            }
118980          ],
118981          "cpe": "cpe:2.3:a:node-modules:humanize-ms:1.2.1:*:*:*:*:*:*:*",
118982          "purl": "pkg:npm/humanize-ms@1.2.1",
118983          "swid": {
118984            "attachment": {}
118985          },
118986          "pedigree": {},
118987          "externalReferences": [
118988            {
118989              "url": "https://github.com/node-modules/humanize-ms",
118990              "type": "distribution"
118991            }
118992          ],
118993          "evidence": {},
118994          "signature": {
118995            "signature": {
118996              "publicKey": {}
118997            }
118998          },
118999          "modelCard": {
119000            "modelParameters": {
119001              "approach": {}
119002            },
119003            "quantitativeAnalysis": {
119004              "graphics": {}
119005            },
119006            "considerations": {}
119007          }
119008        },
119009        {
119010          "type": "library",
119011          "bom-ref": "pkg:npm/iconv-lite@0.6.3?package-id=fc4965fa5a86a9c9",
119012          "supplier": {},
119013          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
119014          "name": "iconv-lite",
119015          "version": "0.6.3",
119016          "description": "Convert character encodings in pure javascript.",
119017          "licenses": [
119018            {
119019              "license": {
119020                "id": "MIT"
119021              }
119022            }
119023          ],
119024          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.6.3:*:*:*:*:*:*:*",
119025          "purl": "pkg:npm/iconv-lite@0.6.3",
119026          "swid": {
119027            "attachment": {}
119028          },
119029          "pedigree": {},
119030          "externalReferences": [
119031            {
119032              "url": "git://github.com/ashtuchkin/iconv-lite.git",
119033              "type": "distribution"
119034            },
119035            {
119036              "url": "https://github.com/ashtuchkin/iconv-lite",
119037              "type": "website"
119038            }
119039          ],
119040          "evidence": {},
119041          "signature": {
119042            "signature": {
119043              "publicKey": {}
119044            }
119045          },
119046          "modelCard": {
119047            "modelParameters": {
119048              "approach": {}
119049            },
119050            "quantitativeAnalysis": {
119051              "graphics": {}
119052            },
119053            "considerations": {}
119054          }
119055        },
119056        {
119057          "type": "library",
119058          "bom-ref": "pkg:npm/ignore-walk@5.0.1?package-id=39d6166153eb8a8",
119059          "supplier": {},
119060          "author": "GitHub Inc.",
119061          "name": "ignore-walk",
119062          "version": "5.0.1",
119063          "description": "Nested/recursive `.gitignore`/`.npmignore` parsing and filtering.",
119064          "licenses": [
119065            {
119066              "license": {
119067                "id": "ISC"
119068              }
119069            }
119070          ],
119071          "cpe": "cpe:2.3:a:ignore-walk:ignore-walk:5.0.1:*:*:*:*:*:*:*",
119072          "purl": "pkg:npm/ignore-walk@5.0.1",
119073          "swid": {
119074            "attachment": {}
119075          },
119076          "pedigree": {},
119077          "externalReferences": [
119078            {
119079              "url": "https://github.com/npm/ignore-walk.git",
119080              "type": "distribution"
119081            }
119082          ],
119083          "evidence": {},
119084          "signature": {
119085            "signature": {
119086              "publicKey": {}
119087            }
119088          },
119089          "modelCard": {
119090            "modelParameters": {
119091              "approach": {}
119092            },
119093            "quantitativeAnalysis": {
119094              "graphics": {}
119095            },
119096            "considerations": {}
119097          }
119098        },
119099        {
119100          "type": "library",
119101          "bom-ref": "pkg:npm/imurmurhash@0.1.4?package-id=6444b4b295dc6bb1",
119102          "supplier": {},
119103          "author": "Jens Taylor \u003cjensyt@gmail.com\u003e (https://github.com/homebrewing)",
119104          "name": "imurmurhash",
119105          "version": "0.1.4",
119106          "description": "An incremental implementation of MurmurHash3",
119107          "licenses": [
119108            {
119109              "license": {
119110                "id": "MIT"
119111              }
119112            }
119113          ],
119114          "cpe": "cpe:2.3:a:imurmurhash:imurmurhash:0.1.4:*:*:*:*:*:*:*",
119115          "purl": "pkg:npm/imurmurhash@0.1.4",
119116          "swid": {
119117            "attachment": {}
119118          },
119119          "pedigree": {},
119120          "externalReferences": [
119121            {
119122              "url": "https://github.com/jensyt/imurmurhash-js",
119123              "type": "distribution"
119124            },
119125            {
119126              "url": "https://github.com/jensyt/imurmurhash-js",
119127              "type": "website"
119128            }
119129          ],
119130          "evidence": {},
119131          "signature": {
119132            "signature": {
119133              "publicKey": {}
119134            }
119135          },
119136          "modelCard": {
119137            "modelParameters": {
119138              "approach": {}
119139            },
119140            "quantitativeAnalysis": {
119141              "graphics": {}
119142            },
119143            "considerations": {}
119144          }
119145        },
119146        {
119147          "type": "library",
119148          "bom-ref": "pkg:npm/indent-string@4.0.0?package-id=9c9aada4281114e7",
119149          "supplier": {},
119150          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
119151          "name": "indent-string",
119152          "version": "4.0.0",
119153          "description": "Indent each line in a string",
119154          "licenses": [
119155            {
119156              "license": {
119157                "id": "MIT"
119158              }
119159            }
119160          ],
119161          "cpe": "cpe:2.3:a:indent-string:indent-string:4.0.0:*:*:*:*:*:*:*",
119162          "purl": "pkg:npm/indent-string@4.0.0",
119163          "swid": {
119164            "attachment": {}
119165          },
119166          "pedigree": {},
119167          "externalReferences": [
119168            {
119169              "url": "sindresorhus/indent-string",
119170              "type": "distribution"
119171            }
119172          ],
119173          "evidence": {},
119174          "signature": {
119175            "signature": {
119176              "publicKey": {}
119177            }
119178          },
119179          "modelCard": {
119180            "modelParameters": {
119181              "approach": {}
119182            },
119183            "quantitativeAnalysis": {
119184              "graphics": {}
119185            },
119186            "considerations": {}
119187          }
119188        },
119189        {
119190          "type": "library",
119191          "bom-ref": "pkg:npm/infer-owner@1.0.4?package-id=70041214f8f231ae",
119192          "supplier": {},
119193          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
119194          "name": "infer-owner",
119195          "version": "1.0.4",
119196          "description": "Infer the owner of a path based on the owner of its nearest existing parent",
119197          "licenses": [
119198            {
119199              "license": {
119200                "id": "ISC"
119201              }
119202            }
119203          ],
119204          "cpe": "cpe:2.3:a:infer-owner:infer-owner:1.0.4:*:*:*:*:*:*:*",
119205          "purl": "pkg:npm/infer-owner@1.0.4",
119206          "swid": {
119207            "attachment": {}
119208          },
119209          "pedigree": {},
119210          "externalReferences": [
119211            {
119212              "url": "https://github.com/npm/infer-owner",
119213              "type": "distribution"
119214            }
119215          ],
119216          "evidence": {},
119217          "signature": {
119218            "signature": {
119219              "publicKey": {}
119220            }
119221          },
119222          "modelCard": {
119223            "modelParameters": {
119224              "approach": {}
119225            },
119226            "quantitativeAnalysis": {
119227              "graphics": {}
119228            },
119229            "considerations": {}
119230          }
119231        },
119232        {
119233          "type": "library",
119234          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=59c3c8a2d2437082",
119235          "supplier": {},
119236          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
119237          "name": "inflight",
119238          "version": "1.0.6",
119239          "description": "Add callbacks to requests in flight to avoid async duplication",
119240          "licenses": [
119241            {
119242              "license": {
119243                "id": "ISC"
119244              }
119245            }
119246          ],
119247          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
119248          "purl": "pkg:npm/inflight@1.0.6",
119249          "swid": {
119250            "attachment": {}
119251          },
119252          "pedigree": {},
119253          "externalReferences": [
119254            {
119255              "url": "https://github.com/npm/inflight.git",
119256              "type": "distribution"
119257            },
119258            {
119259              "url": "https://github.com/isaacs/inflight",
119260              "type": "website"
119261            }
119262          ],
119263          "evidence": {},
119264          "signature": {
119265            "signature": {
119266              "publicKey": {}
119267            }
119268          },
119269          "modelCard": {
119270            "modelParameters": {
119271              "approach": {}
119272            },
119273            "quantitativeAnalysis": {
119274              "graphics": {}
119275            },
119276            "considerations": {}
119277          }
119278        },
119279        {
119280          "type": "library",
119281          "bom-ref": "pkg:npm/inherits@2.0.3?package-id=8f61c802178ab66a",
119282          "supplier": {},
119283          "name": "inherits",
119284          "version": "2.0.3",
119285          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
119286          "licenses": [
119287            {
119288              "license": {
119289                "id": "ISC"
119290              }
119291            }
119292          ],
119293          "cpe": "cpe:2.3:a:inherits:inherits:2.0.3:*:*:*:*:*:*:*",
119294          "purl": "pkg:npm/inherits@2.0.3",
119295          "swid": {
119296            "attachment": {}
119297          },
119298          "pedigree": {},
119299          "externalReferences": [
119300            {
119301              "url": "git://github.com/isaacs/inherits",
119302              "type": "distribution"
119303            }
119304          ],
119305          "evidence": {},
119306          "signature": {
119307            "signature": {
119308              "publicKey": {}
119309            }
119310          },
119311          "modelCard": {
119312            "modelParameters": {
119313              "approach": {}
119314            },
119315            "quantitativeAnalysis": {
119316              "graphics": {}
119317            },
119318            "considerations": {}
119319          }
119320        },
119321        {
119322          "type": "library",
119323          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=2aa76eeeb4a32e94",
119324          "supplier": {},
119325          "name": "inherits",
119326          "version": "2.0.4",
119327          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
119328          "licenses": [
119329            {
119330              "license": {
119331                "id": "ISC"
119332              }
119333            }
119334          ],
119335          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
119336          "purl": "pkg:npm/inherits@2.0.4",
119337          "swid": {
119338            "attachment": {}
119339          },
119340          "pedigree": {},
119341          "externalReferences": [
119342            {
119343              "url": "git://github.com/isaacs/inherits",
119344              "type": "distribution"
119345            }
119346          ],
119347          "evidence": {},
119348          "signature": {
119349            "signature": {
119350              "publicKey": {}
119351            }
119352          },
119353          "modelCard": {
119354            "modelParameters": {
119355              "approach": {}
119356            },
119357            "quantitativeAnalysis": {
119358              "graphics": {}
119359            },
119360            "considerations": {}
119361          }
119362        },
119363        {
119364          "type": "library",
119365          "bom-ref": "pkg:npm/ini@3.0.1?package-id=143d409d5161792",
119366          "supplier": {},
119367          "author": "GitHub Inc.",
119368          "name": "ini",
119369          "version": "3.0.1",
119370          "description": "An ini encoder/decoder for node",
119371          "licenses": [
119372            {
119373              "license": {
119374                "id": "ISC"
119375              }
119376            }
119377          ],
119378          "cpe": "cpe:2.3:a:ini:ini:3.0.1:*:*:*:*:*:*:*",
119379          "purl": "pkg:npm/ini@3.0.1",
119380          "swid": {
119381            "attachment": {}
119382          },
119383          "pedigree": {},
119384          "externalReferences": [
119385            {
119386              "url": "https://github.com/npm/ini.git",
119387              "type": "distribution"
119388            }
119389          ],
119390          "evidence": {},
119391          "signature": {
119392            "signature": {
119393              "publicKey": {}
119394            }
119395          },
119396          "modelCard": {
119397            "modelParameters": {
119398              "approach": {}
119399            },
119400            "quantitativeAnalysis": {
119401              "graphics": {}
119402            },
119403            "considerations": {}
119404          }
119405        },
119406        {
119407          "type": "library",
119408          "bom-ref": "pkg:npm/init-package-json@3.0.2?package-id=6836db1e46d935b6",
119409          "supplier": {},
119410          "author": "GitHub Inc.",
119411          "name": "init-package-json",
119412          "version": "3.0.2",
119413          "description": "A node module to get your node module started",
119414          "licenses": [
119415            {
119416              "license": {
119417                "id": "ISC"
119418              }
119419            }
119420          ],
119421          "cpe": "cpe:2.3:a:init-package-json:init-package-json:3.0.2:*:*:*:*:*:*:*",
119422          "purl": "pkg:npm/init-package-json@3.0.2",
119423          "swid": {
119424            "attachment": {}
119425          },
119426          "pedigree": {},
119427          "externalReferences": [
119428            {
119429              "url": "https://github.com/npm/init-package-json.git",
119430              "type": "distribution"
119431            }
119432          ],
119433          "evidence": {},
119434          "signature": {
119435            "signature": {
119436              "publicKey": {}
119437            }
119438          },
119439          "modelCard": {
119440            "modelParameters": {
119441              "approach": {}
119442            },
119443            "quantitativeAnalysis": {
119444              "graphics": {}
119445            },
119446            "considerations": {}
119447          }
119448        },
119449        {
119450          "type": "library",
119451          "bom-ref": "pkg:npm/ip@2.0.0?package-id=218d1c05ea387b3c",
119452          "supplier": {},
119453          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
119454          "name": "ip",
119455          "version": "2.0.0",
119456          "licenses": [
119457            {
119458              "license": {
119459                "id": "MIT"
119460              }
119461            }
119462          ],
119463          "cpe": "cpe:2.3:a:indutny:ip:2.0.0:*:*:*:*:*:*:*",
119464          "purl": "pkg:npm/ip@2.0.0",
119465          "swid": {
119466            "attachment": {}
119467          },
119468          "pedigree": {},
119469          "externalReferences": [
119470            {
119471              "url": "http://github.com/indutny/node-ip.git",
119472              "type": "distribution"
119473            },
119474            {
119475              "url": "https://github.com/indutny/node-ip",
119476              "type": "website"
119477            }
119478          ],
119479          "evidence": {},
119480          "signature": {
119481            "signature": {
119482              "publicKey": {}
119483            }
119484          },
119485          "modelCard": {
119486            "modelParameters": {
119487              "approach": {}
119488            },
119489            "quantitativeAnalysis": {
119490              "graphics": {}
119491            },
119492            "considerations": {}
119493          }
119494        },
119495        {
119496          "type": "library",
119497          "bom-ref": "pkg:npm/ip-regex@4.3.0?package-id=ce63365b733beafc",
119498          "supplier": {},
119499          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
119500          "name": "ip-regex",
119501          "version": "4.3.0",
119502          "description": "Regular expression for matching IP addresses (IPv4 \u0026 IPv6)",
119503          "licenses": [
119504            {
119505              "license": {
119506                "id": "MIT"
119507              }
119508            }
119509          ],
119510          "cpe": "cpe:2.3:a:ip-regex:ip-regex:4.3.0:*:*:*:*:*:*:*",
119511          "purl": "pkg:npm/ip-regex@4.3.0",
119512          "swid": {
119513            "attachment": {}
119514          },
119515          "pedigree": {},
119516          "externalReferences": [
119517            {
119518              "url": "sindresorhus/ip-regex",
119519              "type": "distribution"
119520            }
119521          ],
119522          "evidence": {},
119523          "signature": {
119524            "signature": {
119525              "publicKey": {}
119526            }
119527          },
119528          "modelCard": {
119529            "modelParameters": {
119530              "approach": {}
119531            },
119532            "quantitativeAnalysis": {
119533              "graphics": {}
119534            },
119535            "considerations": {}
119536          }
119537        },
119538        {
119539          "type": "library",
119540          "bom-ref": "pkg:npm/is-cidr@4.0.2?package-id=b7267695f8ce1238",
119541          "supplier": {},
119542          "author": "silverwind \u003cme@silverwind.io\u003e",
119543          "name": "is-cidr",
119544          "version": "4.0.2",
119545          "description": "Check if a string is an IP address in CIDR notation",
119546          "licenses": [
119547            {
119548              "license": {
119549                "id": "BSD-2-Clause"
119550              }
119551            }
119552          ],
119553          "cpe": "cpe:2.3:a:is-cidr:is-cidr:4.0.2:*:*:*:*:*:*:*",
119554          "purl": "pkg:npm/is-cidr@4.0.2",
119555          "swid": {
119556            "attachment": {}
119557          },
119558          "pedigree": {},
119559          "externalReferences": [
119560            {
119561              "url": "silverwind/is-cidr",
119562              "type": "distribution"
119563            }
119564          ],
119565          "evidence": {},
119566          "signature": {
119567            "signature": {
119568              "publicKey": {}
119569            }
119570          },
119571          "modelCard": {
119572            "modelParameters": {
119573              "approach": {}
119574            },
119575            "quantitativeAnalysis": {
119576              "graphics": {}
119577            },
119578            "considerations": {}
119579          }
119580        },
119581        {
119582          "type": "library",
119583          "bom-ref": "pkg:npm/is-core-module@2.10.0?package-id=22642820ec847015",
119584          "supplier": {},
119585          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
119586          "name": "is-core-module",
119587          "version": "2.10.0",
119588          "description": "Is this specifier a node.js core module?",
119589          "licenses": [
119590            {
119591              "license": {
119592                "id": "MIT"
119593              }
119594            }
119595          ],
119596          "cpe": "cpe:2.3:a:is-core-module:is-core-module:2.10.0:*:*:*:*:*:*:*",
119597          "purl": "pkg:npm/is-core-module@2.10.0",
119598          "swid": {
119599            "attachment": {}
119600          },
119601          "pedigree": {},
119602          "externalReferences": [
119603            {
119604              "url": "git+https://github.com/inspect-js/is-core-module.git",
119605              "type": "distribution"
119606            },
119607            {
119608              "url": "https://github.com/inspect-js/is-core-module",
119609              "type": "website"
119610            }
119611          ],
119612          "evidence": {},
119613          "signature": {
119614            "signature": {
119615              "publicKey": {}
119616            }
119617          },
119618          "modelCard": {
119619            "modelParameters": {
119620              "approach": {}
119621            },
119622            "quantitativeAnalysis": {
119623              "graphics": {}
119624            },
119625            "considerations": {}
119626          }
119627        },
119628        {
119629          "type": "library",
119630          "bom-ref": "pkg:npm/is-fullwidth-code-point@3.0.0?package-id=f89f6ce8e80b50d",
119631          "supplier": {},
119632          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
119633          "name": "is-fullwidth-code-point",
119634          "version": "3.0.0",
119635          "description": "Check if the character represented by a given Unicode code point is fullwidth",
119636          "licenses": [
119637            {
119638              "license": {
119639                "id": "MIT"
119640              }
119641            }
119642          ],
119643          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:3.0.0:*:*:*:*:*:*:*",
119644          "purl": "pkg:npm/is-fullwidth-code-point@3.0.0",
119645          "swid": {
119646            "attachment": {}
119647          },
119648          "pedigree": {},
119649          "externalReferences": [
119650            {
119651              "url": "sindresorhus/is-fullwidth-code-point",
119652              "type": "distribution"
119653            }
119654          ],
119655          "evidence": {},
119656          "signature": {
119657            "signature": {
119658              "publicKey": {}
119659            }
119660          },
119661          "modelCard": {
119662            "modelParameters": {
119663              "approach": {}
119664            },
119665            "quantitativeAnalysis": {
119666              "graphics": {}
119667            },
119668            "considerations": {}
119669          }
119670        },
119671        {
119672          "type": "library",
119673          "bom-ref": "pkg:npm/is-lambda@1.0.1?package-id=841af64487227951",
119674          "supplier": {},
119675          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
119676          "name": "is-lambda",
119677          "version": "1.0.1",
119678          "description": "Detect if your code is running on an AWS Lambda server",
119679          "licenses": [
119680            {
119681              "license": {
119682                "id": "MIT"
119683              }
119684            }
119685          ],
119686          "cpe": "cpe:2.3:a:is-lambda:is-lambda:1.0.1:*:*:*:*:*:*:*",
119687          "purl": "pkg:npm/is-lambda@1.0.1",
119688          "swid": {
119689            "attachment": {}
119690          },
119691          "pedigree": {},
119692          "externalReferences": [
119693            {
119694              "url": "https://github.com/watson/is-lambda.git",
119695              "type": "distribution"
119696            },
119697            {
119698              "url": "https://github.com/watson/is-lambda",
119699              "type": "website"
119700            }
119701          ],
119702          "evidence": {},
119703          "signature": {
119704            "signature": {
119705              "publicKey": {}
119706            }
119707          },
119708          "modelCard": {
119709            "modelParameters": {
119710              "approach": {}
119711            },
119712            "quantitativeAnalysis": {
119713              "graphics": {}
119714            },
119715            "considerations": {}
119716          }
119717        },
119718        {
119719          "type": "library",
119720          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=8c6bff07fe7d51b4",
119721          "supplier": {},
119722          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
119723          "name": "isarray",
119724          "version": "1.0.0",
119725          "description": "Array#isArray for older browsers",
119726          "licenses": [
119727            {
119728              "license": {
119729                "id": "MIT"
119730              }
119731            }
119732          ],
119733          "cpe": "cpe:2.3:a:juliangruber:isarray:1.0.0:*:*:*:*:*:*:*",
119734          "purl": "pkg:npm/isarray@1.0.0",
119735          "swid": {
119736            "attachment": {}
119737          },
119738          "pedigree": {},
119739          "externalReferences": [
119740            {
119741              "url": "git://github.com/juliangruber/isarray.git",
119742              "type": "distribution"
119743            },
119744            {
119745              "url": "https://github.com/juliangruber/isarray",
119746              "type": "website"
119747            }
119748          ],
119749          "evidence": {},
119750          "signature": {
119751            "signature": {
119752              "publicKey": {}
119753            }
119754          },
119755          "modelCard": {
119756            "modelParameters": {
119757              "approach": {}
119758            },
119759            "quantitativeAnalysis": {
119760              "graphics": {}
119761            },
119762            "considerations": {}
119763          }
119764        },
119765        {
119766          "type": "library",
119767          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=b58983cda03515a",
119768          "supplier": {},
119769          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
119770          "name": "isarray",
119771          "version": "1.0.0",
119772          "description": "Array#isArray for older browsers",
119773          "licenses": [
119774            {
119775              "license": {
119776                "id": "MIT"
119777              }
119778            }
119779          ],
119780          "cpe": "cpe:2.3:a:juliangruber:isarray:1.0.0:*:*:*:*:*:*:*",
119781          "purl": "pkg:npm/isarray@1.0.0",
119782          "swid": {
119783            "attachment": {}
119784          },
119785          "pedigree": {},
119786          "externalReferences": [
119787            {
119788              "url": "git://github.com/juliangruber/isarray.git",
119789              "type": "distribution"
119790            },
119791            {
119792              "url": "https://github.com/juliangruber/isarray",
119793              "type": "website"
119794            }
119795          ],
119796          "evidence": {},
119797          "signature": {
119798            "signature": {
119799              "publicKey": {}
119800            }
119801          },
119802          "modelCard": {
119803            "modelParameters": {
119804              "approach": {}
119805            },
119806            "quantitativeAnalysis": {
119807              "graphics": {}
119808            },
119809            "considerations": {}
119810          }
119811        },
119812        {
119813          "type": "library",
119814          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=cac2857ecac9cad9",
119815          "supplier": {},
119816          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
119817          "name": "isexe",
119818          "version": "2.0.0",
119819          "description": "Minimal module to check if a file is executable.",
119820          "licenses": [
119821            {
119822              "license": {
119823                "id": "ISC"
119824              }
119825            }
119826          ],
119827          "cpe": "cpe:2.3:a:isaacs:isexe:2.0.0:*:*:*:*:*:*:*",
119828          "purl": "pkg:npm/isexe@2.0.0",
119829          "swid": {
119830            "attachment": {}
119831          },
119832          "pedigree": {},
119833          "externalReferences": [
119834            {
119835              "url": "git+https://github.com/isaacs/isexe.git",
119836              "type": "distribution"
119837            },
119838            {
119839              "url": "https://github.com/isaacs/isexe#readme",
119840              "type": "website"
119841            }
119842          ],
119843          "evidence": {},
119844          "signature": {
119845            "signature": {
119846              "publicKey": {}
119847            }
119848          },
119849          "modelCard": {
119850            "modelParameters": {
119851              "approach": {}
119852            },
119853            "quantitativeAnalysis": {
119854              "graphics": {}
119855            },
119856            "considerations": {}
119857          }
119858        },
119859        {
119860          "type": "library",
119861          "bom-ref": "pkg:npm/json-parse-even-better-errors@2.3.1?package-id=abf07f33abe9247b",
119862          "supplier": {},
119863          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
119864          "name": "json-parse-even-better-errors",
119865          "version": "2.3.1",
119866          "description": "JSON.parse with context information on error",
119867          "licenses": [
119868            {
119869              "license": {
119870                "id": "MIT"
119871              }
119872            }
119873          ],
119874          "cpe": "cpe:2.3:a:json-parse-even-better-errors:json-parse-even-better-errors:2.3.1:*:*:*:*:*:*:*",
119875          "purl": "pkg:npm/json-parse-even-better-errors@2.3.1",
119876          "swid": {
119877            "attachment": {}
119878          },
119879          "pedigree": {},
119880          "externalReferences": [
119881            {
119882              "url": "https://github.com/npm/json-parse-even-better-errors",
119883              "type": "distribution"
119884            }
119885          ],
119886          "evidence": {},
119887          "signature": {
119888            "signature": {
119889              "publicKey": {}
119890            }
119891          },
119892          "modelCard": {
119893            "modelParameters": {
119894              "approach": {}
119895            },
119896            "quantitativeAnalysis": {
119897              "graphics": {}
119898            },
119899            "considerations": {}
119900          }
119901        },
119902        {
119903          "type": "library",
119904          "bom-ref": "pkg:npm/json-stringify-nice@1.1.4?package-id=e53e3b4efad53e7c",
119905          "supplier": {},
119906          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
119907          "name": "json-stringify-nice",
119908          "version": "1.1.4",
119909          "description": "Stringify an object sorting scalars before objects, and defaulting to 2-space indent",
119910          "licenses": [
119911            {
119912              "license": {
119913                "id": "ISC"
119914              }
119915            }
119916          ],
119917          "cpe": "cpe:2.3:a:json-stringify-nice:json-stringify-nice:1.1.4:*:*:*:*:*:*:*",
119918          "purl": "pkg:npm/json-stringify-nice@1.1.4",
119919          "swid": {
119920            "attachment": {}
119921          },
119922          "pedigree": {},
119923          "externalReferences": [
119924            {
119925              "url": "https://github.com/isaacs/json-stringify-nice",
119926              "type": "distribution"
119927            }
119928          ],
119929          "evidence": {},
119930          "signature": {
119931            "signature": {
119932              "publicKey": {}
119933            }
119934          },
119935          "modelCard": {
119936            "modelParameters": {
119937              "approach": {}
119938            },
119939            "quantitativeAnalysis": {
119940              "graphics": {}
119941            },
119942            "considerations": {}
119943          }
119944        },
119945        {
119946          "type": "library",
119947          "bom-ref": "pkg:npm/jsonparse@1.3.1?package-id=4ac9c9dc14c89718",
119948          "supplier": {},
119949          "author": "Tim Caswell \u003ctim@creationix.com\u003e",
119950          "name": "jsonparse",
119951          "version": "1.3.1",
119952          "description": "This is a pure-js JSON streaming parser for node.js",
119953          "licenses": [
119954            {
119955              "license": {
119956                "id": "MIT"
119957              }
119958            }
119959          ],
119960          "cpe": "cpe:2.3:a:creationix:jsonparse:1.3.1:*:*:*:*:*:*:*",
119961          "purl": "pkg:npm/jsonparse@1.3.1",
119962          "swid": {
119963            "attachment": {}
119964          },
119965          "pedigree": {},
119966          "externalReferences": [
119967            {
119968              "url": "http://github.com/creationix/jsonparse.git",
119969              "type": "distribution"
119970            }
119971          ],
119972          "evidence": {},
119973          "signature": {
119974            "signature": {
119975              "publicKey": {}
119976            }
119977          },
119978          "modelCard": {
119979            "modelParameters": {
119980              "approach": {}
119981            },
119982            "quantitativeAnalysis": {
119983              "graphics": {}
119984            },
119985            "considerations": {}
119986          }
119987        },
119988        {
119989          "type": "library",
119990          "bom-ref": "pkg:npm/jsonwebtoken@8.5.1?package-id=92b793e78f1f6688",
119991          "supplier": {},
119992          "author": "auth0",
119993          "name": "jsonwebtoken",
119994          "version": "8.5.1",
119995          "description": "JSON Web Token implementation (symmetric and asymmetric)",
119996          "licenses": [
119997            {
119998              "license": {
119999                "id": "MIT"
120000              }
120001            }
120002          ],
120003          "cpe": "cpe:2.3:a:jsonwebtoken:jsonwebtoken:8.5.1:*:*:*:*:*:*:*",
120004          "purl": "pkg:npm/jsonwebtoken@8.5.1",
120005          "swid": {
120006            "attachment": {}
120007          },
120008          "pedigree": {},
120009          "externalReferences": [
120010            {
120011              "url": "https://github.com/auth0/node-jsonwebtoken",
120012              "type": "distribution"
120013            }
120014          ],
120015          "evidence": {},
120016          "signature": {
120017            "signature": {
120018              "publicKey": {}
120019            }
120020          },
120021          "modelCard": {
120022            "modelParameters": {
120023              "approach": {}
120024            },
120025            "quantitativeAnalysis": {
120026              "graphics": {}
120027            },
120028            "considerations": {}
120029          }
120030        },
120031        {
120032          "type": "library",
120033          "bom-ref": "pkg:npm/just-diff@5.1.1?package-id=ce66f628f594c549",
120034          "supplier": {},
120035          "author": "Angus Croll",
120036          "name": "just-diff",
120037          "version": "5.1.1",
120038          "description": "Return an object representing the diffs between two objects. Supports jsonPatch protocol",
120039          "licenses": [
120040            {
120041              "license": {
120042                "id": "MIT"
120043              }
120044            }
120045          ],
120046          "cpe": "cpe:2.3:a:just-diff:just-diff:5.1.1:*:*:*:*:*:*:*",
120047          "purl": "pkg:npm/just-diff@5.1.1",
120048          "swid": {
120049            "attachment": {}
120050          },
120051          "pedigree": {},
120052          "externalReferences": [
120053            {
120054              "url": "https://github.com/angus-c/just",
120055              "type": "distribution"
120056            }
120057          ],
120058          "evidence": {},
120059          "signature": {
120060            "signature": {
120061              "publicKey": {}
120062            }
120063          },
120064          "modelCard": {
120065            "modelParameters": {
120066              "approach": {}
120067            },
120068            "quantitativeAnalysis": {
120069              "graphics": {}
120070            },
120071            "considerations": {}
120072          }
120073        },
120074        {
120075          "type": "library",
120076          "bom-ref": "pkg:npm/just-diff-apply@5.4.1?package-id=11dfc45c877cf5ba",
120077          "supplier": {},
120078          "author": "Angus Croll",
120079          "name": "just-diff-apply",
120080          "version": "5.4.1",
120081          "description": "Apply a diff to an object. Optionally supports jsonPatch protocol",
120082          "licenses": [
120083            {
120084              "license": {
120085                "id": "MIT"
120086              }
120087            }
120088          ],
120089          "cpe": "cpe:2.3:a:just-diff-apply:just-diff-apply:5.4.1:*:*:*:*:*:*:*",
120090          "purl": "pkg:npm/just-diff-apply@5.4.1",
120091          "swid": {
120092            "attachment": {}
120093          },
120094          "pedigree": {},
120095          "externalReferences": [
120096            {
120097              "url": "https://github.com/angus-c/just",
120098              "type": "distribution"
120099            }
120100          ],
120101          "evidence": {},
120102          "signature": {
120103            "signature": {
120104              "publicKey": {}
120105            }
120106          },
120107          "modelCard": {
120108            "modelParameters": {
120109              "approach": {}
120110            },
120111            "quantitativeAnalysis": {
120112              "graphics": {}
120113            },
120114            "considerations": {}
120115          }
120116        },
120117        {
120118          "type": "library",
120119          "bom-ref": "pkg:npm/jwa@1.4.1?package-id=d5fbc3744196211c",
120120          "supplier": {},
120121          "author": "Brian J. Brennan \u003cbrianloveswords@gmail.com\u003e",
120122          "name": "jwa",
120123          "version": "1.4.1",
120124          "description": "JWA implementation (supports all JWS algorithms)",
120125          "licenses": [
120126            {
120127              "license": {
120128                "id": "MIT"
120129              }
120130            }
120131          ],
120132          "cpe": "cpe:2.3:a:brianloveswords:jwa:1.4.1:*:*:*:*:*:*:*",
120133          "purl": "pkg:npm/jwa@1.4.1",
120134          "swid": {
120135            "attachment": {}
120136          },
120137          "pedigree": {},
120138          "externalReferences": [
120139            {
120140              "url": "git://github.com/brianloveswords/node-jwa.git",
120141              "type": "distribution"
120142            }
120143          ],
120144          "evidence": {},
120145          "signature": {
120146            "signature": {
120147              "publicKey": {}
120148            }
120149          },
120150          "modelCard": {
120151            "modelParameters": {
120152              "approach": {}
120153            },
120154            "quantitativeAnalysis": {
120155              "graphics": {}
120156            },
120157            "considerations": {}
120158          }
120159        },
120160        {
120161          "type": "library",
120162          "bom-ref": "pkg:npm/jws@3.2.2?package-id=21bd84daa035d836",
120163          "supplier": {},
120164          "author": "Brian J Brennan",
120165          "name": "jws",
120166          "version": "3.2.2",
120167          "description": "Implementation of JSON Web Signatures",
120168          "licenses": [
120169            {
120170              "license": {
120171                "id": "MIT"
120172              }
120173            }
120174          ],
120175          "cpe": "cpe:2.3:a:brianloveswords:jws:3.2.2:*:*:*:*:*:*:*",
120176          "purl": "pkg:npm/jws@3.2.2",
120177          "swid": {
120178            "attachment": {}
120179          },
120180          "pedigree": {},
120181          "externalReferences": [
120182            {
120183              "url": "git://github.com/brianloveswords/node-jws.git",
120184              "type": "distribution"
120185            }
120186          ],
120187          "evidence": {},
120188          "signature": {
120189            "signature": {
120190              "publicKey": {}
120191            }
120192          },
120193          "modelCard": {
120194            "modelParameters": {
120195              "approach": {}
120196            },
120197            "quantitativeAnalysis": {
120198              "graphics": {}
120199            },
120200            "considerations": {}
120201          }
120202        },
120203        {
120204          "type": "library",
120205          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5\u0026package-id=2abd3b45f6fa4702",
120206          "supplier": {},
120207          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
120208          "name": "libc-utils",
120209          "version": "0.7.2-r3",
120210          "description": "Meta package to pull in correct libc",
120211          "licenses": [
120212            {
120213              "license": {
120214                "id": "BSD-2-Clause"
120215              }
120216            },
120217            {
120218              "license": {
120219                "name": "AND"
120220              }
120221            },
120222            {
120223              "license": {
120224                "id": "BSD-3-Clause"
120225              }
120226            }
120227          ],
120228          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
120229          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5",
120230          "swid": {
120231            "attachment": {}
120232          },
120233          "pedigree": {},
120234          "externalReferences": [
120235            {
120236              "url": "https://alpinelinux.org",
120237              "type": "distribution"
120238            }
120239          ],
120240          "evidence": {},
120241          "signature": {
120242            "signature": {
120243              "publicKey": {}
120244            }
120245          },
120246          "modelCard": {
120247            "modelParameters": {
120248              "approach": {}
120249            },
120250            "quantitativeAnalysis": {
120251              "graphics": {}
120252            },
120253            "considerations": {}
120254          }
120255        },
120256        {
120257          "type": "library",
120258          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=13bc051822a24e8d",
120259          "supplier": {},
120260          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
120261          "name": "libcrypto1.1",
120262          "version": "1.1.1t-r2",
120263          "description": "Crypto library from openssl",
120264          "licenses": [
120265            {
120266              "license": {
120267                "id": "OpenSSL"
120268              }
120269            }
120270          ],
120271          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1t-r2:*:*:*:*:*:*:*",
120272          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
120273          "swid": {
120274            "attachment": {}
120275          },
120276          "pedigree": {},
120277          "externalReferences": [
120278            {
120279              "url": "https://www.openssl.org/",
120280              "type": "distribution"
120281            }
120282          ],
120283          "evidence": {},
120284          "signature": {
120285            "signature": {
120286              "publicKey": {}
120287            }
120288          },
120289          "modelCard": {
120290            "modelParameters": {
120291              "approach": {}
120292            },
120293            "quantitativeAnalysis": {
120294              "graphics": {}
120295            },
120296            "considerations": {}
120297          }
120298        },
120299        {
120300          "type": "library",
120301          "bom-ref": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=d2886381f1e7cdb2",
120302          "supplier": {},
120303          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
120304          "name": "libgcc",
120305          "version": "11.2.1_git20220219-r2",
120306          "description": "GNU C compiler runtime libraries",
120307          "licenses": [
120308            {
120309              "license": {
120310                "id": "GPL-2.0-or-later"
120311              }
120312            },
120313            {
120314              "license": {
120315                "id": "LGPL-2.1-or-later"
120316              }
120317            }
120318          ],
120319          "cpe": "cpe:2.3:a:libgcc:libgcc:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
120320          "purl": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
120321          "swid": {
120322            "attachment": {}
120323          },
120324          "pedigree": {},
120325          "externalReferences": [
120326            {
120327              "url": "https://gcc.gnu.org",
120328              "type": "distribution"
120329            }
120330          ],
120331          "evidence": {},
120332          "signature": {
120333            "signature": {
120334              "publicKey": {}
120335            }
120336          },
120337          "modelCard": {
120338            "modelParameters": {
120339              "approach": {}
120340            },
120341            "quantitativeAnalysis": {
120342              "graphics": {}
120343            },
120344            "considerations": {}
120345          }
120346        },
120347        {
120348          "type": "library",
120349          "bom-ref": "pkg:npm/libnpmaccess@6.0.4?package-id=f3410b3d946e1c4d",
120350          "supplier": {},
120351          "author": "GitHub Inc.",
120352          "name": "libnpmaccess",
120353          "version": "6.0.4",
120354          "description": "programmatic library for `npm access` commands",
120355          "licenses": [
120356            {
120357              "license": {
120358                "id": "ISC"
120359              }
120360            }
120361          ],
120362          "cpe": "cpe:2.3:a:libnpmaccess:libnpmaccess:6.0.4:*:*:*:*:*:*:*",
120363          "purl": "pkg:npm/libnpmaccess@6.0.4",
120364          "swid": {
120365            "attachment": {}
120366          },
120367          "pedigree": {},
120368          "externalReferences": [
120369            {
120370              "url": "https://github.com/npm/cli.git",
120371              "type": "distribution"
120372            },
120373            {
120374              "url": "https://npmjs.com/package/libnpmaccess",
120375              "type": "website"
120376            }
120377          ],
120378          "evidence": {},
120379          "signature": {
120380            "signature": {
120381              "publicKey": {}
120382            }
120383          },
120384          "modelCard": {
120385            "modelParameters": {
120386              "approach": {}
120387            },
120388            "quantitativeAnalysis": {
120389              "graphics": {}
120390            },
120391            "considerations": {}
120392          }
120393        },
120394        {
120395          "type": "library",
120396          "bom-ref": "pkg:npm/libnpmdiff@4.0.5?package-id=ce3262e2c08529ea",
120397          "supplier": {},
120398          "author": "GitHub Inc.",
120399          "name": "libnpmdiff",
120400          "version": "4.0.5",
120401          "description": "The registry diff",
120402          "licenses": [
120403            {
120404              "license": {
120405                "id": "ISC"
120406              }
120407            }
120408          ],
120409          "cpe": "cpe:2.3:a:libnpmdiff:libnpmdiff:4.0.5:*:*:*:*:*:*:*",
120410          "purl": "pkg:npm/libnpmdiff@4.0.5",
120411          "swid": {
120412            "attachment": {}
120413          },
120414          "pedigree": {},
120415          "externalReferences": [
120416            {
120417              "url": "https://github.com/npm/cli.git",
120418              "type": "distribution"
120419            }
120420          ],
120421          "evidence": {},
120422          "signature": {
120423            "signature": {
120424              "publicKey": {}
120425            }
120426          },
120427          "modelCard": {
120428            "modelParameters": {
120429              "approach": {}
120430            },
120431            "quantitativeAnalysis": {
120432              "graphics": {}
120433            },
120434            "considerations": {}
120435          }
120436        },
120437        {
120438          "type": "library",
120439          "bom-ref": "pkg:npm/libnpmexec@4.0.14?package-id=902cc2f16bb11ffc",
120440          "supplier": {},
120441          "author": "GitHub Inc.",
120442          "name": "libnpmexec",
120443          "version": "4.0.14",
120444          "description": "npm exec (npx) programmatic API",
120445          "licenses": [
120446            {
120447              "license": {
120448                "id": "ISC"
120449              }
120450            }
120451          ],
120452          "cpe": "cpe:2.3:a:libnpmexec:libnpmexec:4.0.14:*:*:*:*:*:*:*",
120453          "purl": "pkg:npm/libnpmexec@4.0.14",
120454          "swid": {
120455            "attachment": {}
120456          },
120457          "pedigree": {},
120458          "externalReferences": [
120459            {
120460              "url": "https://github.com/npm/cli.git",
120461              "type": "distribution"
120462            }
120463          ],
120464          "evidence": {},
120465          "signature": {
120466            "signature": {
120467              "publicKey": {}
120468            }
120469          },
120470          "modelCard": {
120471            "modelParameters": {
120472              "approach": {}
120473            },
120474            "quantitativeAnalysis": {
120475              "graphics": {}
120476            },
120477            "considerations": {}
120478          }
120479        },
120480        {
120481          "type": "library",
120482          "bom-ref": "pkg:npm/libnpmfund@3.0.5?package-id=201ebcb5d992fa75",
120483          "supplier": {},
120484          "author": "GitHub Inc.",
120485          "name": "libnpmfund",
120486          "version": "3.0.5",
120487          "description": "Programmatic API for npm fund",
120488          "licenses": [
120489            {
120490              "license": {
120491                "id": "ISC"
120492              }
120493            }
120494          ],
120495          "cpe": "cpe:2.3:a:libnpmfund:libnpmfund:3.0.5:*:*:*:*:*:*:*",
120496          "purl": "pkg:npm/libnpmfund@3.0.5",
120497          "swid": {
120498            "attachment": {}
120499          },
120500          "pedigree": {},
120501          "externalReferences": [
120502            {
120503              "url": "https://github.com/npm/cli.git",
120504              "type": "distribution"
120505            }
120506          ],
120507          "evidence": {},
120508          "signature": {
120509            "signature": {
120510              "publicKey": {}
120511            }
120512          },
120513          "modelCard": {
120514            "modelParameters": {
120515              "approach": {}
120516            },
120517            "quantitativeAnalysis": {
120518              "graphics": {}
120519            },
120520            "considerations": {}
120521          }
120522        },
120523        {
120524          "type": "library",
120525          "bom-ref": "pkg:npm/libnpmhook@8.0.4?package-id=5679bee9e2f7003c",
120526          "supplier": {},
120527          "author": "GitHub Inc.",
120528          "name": "libnpmhook",
120529          "version": "8.0.4",
120530          "description": "programmatic API for managing npm registry hooks",
120531          "licenses": [
120532            {
120533              "license": {
120534                "id": "ISC"
120535              }
120536            }
120537          ],
120538          "cpe": "cpe:2.3:a:libnpmhook:libnpmhook:8.0.4:*:*:*:*:*:*:*",
120539          "purl": "pkg:npm/libnpmhook@8.0.4",
120540          "swid": {
120541            "attachment": {}
120542          },
120543          "pedigree": {},
120544          "externalReferences": [
120545            {
120546              "url": "https://github.com/npm/cli.git",
120547              "type": "distribution"
120548            }
120549          ],
120550          "evidence": {},
120551          "signature": {
120552            "signature": {
120553              "publicKey": {}
120554            }
120555          },
120556          "modelCard": {
120557            "modelParameters": {
120558              "approach": {}
120559            },
120560            "quantitativeAnalysis": {
120561              "graphics": {}
120562            },
120563            "considerations": {}
120564          }
120565        },
120566        {
120567          "type": "library",
120568          "bom-ref": "pkg:npm/libnpmorg@4.0.4?package-id=80c945656f22ba9d",
120569          "supplier": {},
120570          "author": "GitHub Inc.",
120571          "name": "libnpmorg",
120572          "version": "4.0.4",
120573          "description": "Programmatic api for `npm org` commands",
120574          "licenses": [
120575            {
120576              "license": {
120577                "id": "ISC"
120578              }
120579            }
120580          ],
120581          "cpe": "cpe:2.3:a:libnpmorg:libnpmorg:4.0.4:*:*:*:*:*:*:*",
120582          "purl": "pkg:npm/libnpmorg@4.0.4",
120583          "swid": {
120584            "attachment": {}
120585          },
120586          "pedigree": {},
120587          "externalReferences": [
120588            {
120589              "url": "https://github.com/npm/cli.git",
120590              "type": "distribution"
120591            },
120592            {
120593              "url": "https://npmjs.com/package/libnpmorg",
120594              "type": "website"
120595            }
120596          ],
120597          "evidence": {},
120598          "signature": {
120599            "signature": {
120600              "publicKey": {}
120601            }
120602          },
120603          "modelCard": {
120604            "modelParameters": {
120605              "approach": {}
120606            },
120607            "quantitativeAnalysis": {
120608              "graphics": {}
120609            },
120610            "considerations": {}
120611          }
120612        },
120613        {
120614          "type": "library",
120615          "bom-ref": "pkg:npm/libnpmpack@4.1.3?package-id=62f6985b14d7de3e",
120616          "supplier": {},
120617          "author": "GitHub Inc.",
120618          "name": "libnpmpack",
120619          "version": "4.1.3",
120620          "description": "Programmatic API for the bits behind npm pack",
120621          "licenses": [
120622            {
120623              "license": {
120624                "id": "ISC"
120625              }
120626            }
120627          ],
120628          "cpe": "cpe:2.3:a:libnpmpack:libnpmpack:4.1.3:*:*:*:*:*:*:*",
120629          "purl": "pkg:npm/libnpmpack@4.1.3",
120630          "swid": {
120631            "attachment": {}
120632          },
120633          "pedigree": {},
120634          "externalReferences": [
120635            {
120636              "url": "https://github.com/npm/cli.git",
120637              "type": "distribution"
120638            },
120639            {
120640              "url": "https://npmjs.com/package/libnpmpack",
120641              "type": "website"
120642            }
120643          ],
120644          "evidence": {},
120645          "signature": {
120646            "signature": {
120647              "publicKey": {}
120648            }
120649          },
120650          "modelCard": {
120651            "modelParameters": {
120652              "approach": {}
120653            },
120654            "quantitativeAnalysis": {
120655              "graphics": {}
120656            },
120657            "considerations": {}
120658          }
120659        },
120660        {
120661          "type": "library",
120662          "bom-ref": "pkg:npm/libnpmpublish@6.0.5?package-id=a970d9d2bf422a57",
120663          "supplier": {},
120664          "author": "GitHub Inc.",
120665          "name": "libnpmpublish",
120666          "version": "6.0.5",
120667          "description": "Programmatic API for the bits behind npm publish and unpublish",
120668          "licenses": [
120669            {
120670              "license": {
120671                "id": "ISC"
120672              }
120673            }
120674          ],
120675          "cpe": "cpe:2.3:a:libnpmpublish:libnpmpublish:6.0.5:*:*:*:*:*:*:*",
120676          "purl": "pkg:npm/libnpmpublish@6.0.5",
120677          "swid": {
120678            "attachment": {}
120679          },
120680          "pedigree": {},
120681          "externalReferences": [
120682            {
120683              "url": "https://github.com/npm/cli.git",
120684              "type": "distribution"
120685            },
120686            {
120687              "url": "https://npmjs.com/package/libnpmpublish",
120688              "type": "website"
120689            }
120690          ],
120691          "evidence": {},
120692          "signature": {
120693            "signature": {
120694              "publicKey": {}
120695            }
120696          },
120697          "modelCard": {
120698            "modelParameters": {
120699              "approach": {}
120700            },
120701            "quantitativeAnalysis": {
120702              "graphics": {}
120703            },
120704            "considerations": {}
120705          }
120706        },
120707        {
120708          "type": "library",
120709          "bom-ref": "pkg:npm/libnpmsearch@5.0.4?package-id=e3666452dd7e585d",
120710          "supplier": {},
120711          "author": "GitHub Inc.",
120712          "name": "libnpmsearch",
120713          "version": "5.0.4",
120714          "description": "Programmatic API for searching in npm and compatible registries.",
120715          "licenses": [
120716            {
120717              "license": {
120718                "id": "ISC"
120719              }
120720            }
120721          ],
120722          "cpe": "cpe:2.3:a:libnpmsearch:libnpmsearch:5.0.4:*:*:*:*:*:*:*",
120723          "purl": "pkg:npm/libnpmsearch@5.0.4",
120724          "swid": {
120725            "attachment": {}
120726          },
120727          "pedigree": {},
120728          "externalReferences": [
120729            {
120730              "url": "https://github.com/npm/cli.git",
120731              "type": "distribution"
120732            },
120733            {
120734              "url": "https://npmjs.com/package/libnpmsearch",
120735              "type": "website"
120736            }
120737          ],
120738          "evidence": {},
120739          "signature": {
120740            "signature": {
120741              "publicKey": {}
120742            }
120743          },
120744          "modelCard": {
120745            "modelParameters": {
120746              "approach": {}
120747            },
120748            "quantitativeAnalysis": {
120749              "graphics": {}
120750            },
120751            "considerations": {}
120752          }
120753        },
120754        {
120755          "type": "library",
120756          "bom-ref": "pkg:npm/libnpmteam@4.0.4?package-id=95c3c29c4dcd60d1",
120757          "supplier": {},
120758          "author": "GitHub Inc.",
120759          "name": "libnpmteam",
120760          "version": "4.0.4",
120761          "description": "npm Team management APIs",
120762          "licenses": [
120763            {
120764              "license": {
120765                "id": "ISC"
120766              }
120767            }
120768          ],
120769          "cpe": "cpe:2.3:a:libnpmteam:libnpmteam:4.0.4:*:*:*:*:*:*:*",
120770          "purl": "pkg:npm/libnpmteam@4.0.4",
120771          "swid": {
120772            "attachment": {}
120773          },
120774          "pedigree": {},
120775          "externalReferences": [
120776            {
120777              "url": "https://github.com/npm/cli.git",
120778              "type": "distribution"
120779            },
120780            {
120781              "url": "https://npmjs.com/package/libnpmteam",
120782              "type": "website"
120783            }
120784          ],
120785          "evidence": {},
120786          "signature": {
120787            "signature": {
120788              "publicKey": {}
120789            }
120790          },
120791          "modelCard": {
120792            "modelParameters": {
120793              "approach": {}
120794            },
120795            "quantitativeAnalysis": {
120796              "graphics": {}
120797            },
120798            "considerations": {}
120799          }
120800        },
120801        {
120802          "type": "library",
120803          "bom-ref": "pkg:npm/libnpmversion@3.0.7?package-id=9ace162e3f4ca294",
120804          "supplier": {},
120805          "author": "GitHub Inc.",
120806          "name": "libnpmversion",
120807          "version": "3.0.7",
120808          "description": "library to do the things that 'npm version' does",
120809          "licenses": [
120810            {
120811              "license": {
120812                "id": "ISC"
120813              }
120814            }
120815          ],
120816          "cpe": "cpe:2.3:a:libnpmversion:libnpmversion:3.0.7:*:*:*:*:*:*:*",
120817          "purl": "pkg:npm/libnpmversion@3.0.7",
120818          "swid": {
120819            "attachment": {}
120820          },
120821          "pedigree": {},
120822          "externalReferences": [
120823            {
120824              "url": "https://github.com/npm/cli.git",
120825              "type": "distribution"
120826            }
120827          ],
120828          "evidence": {},
120829          "signature": {
120830            "signature": {
120831              "publicKey": {}
120832            }
120833          },
120834          "modelCard": {
120835            "modelParameters": {
120836              "approach": {}
120837            },
120838            "quantitativeAnalysis": {
120839              "graphics": {}
120840            },
120841            "considerations": {}
120842          }
120843        },
120844        {
120845          "type": "library",
120846          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=609cb94e63dc06dd",
120847          "supplier": {},
120848          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
120849          "name": "libssl1.1",
120850          "version": "1.1.1t-r2",
120851          "description": "SSL shared libraries",
120852          "licenses": [
120853            {
120854              "license": {
120855                "id": "OpenSSL"
120856              }
120857            }
120858          ],
120859          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1t-r2:*:*:*:*:*:*:*",
120860          "purl": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
120861          "swid": {
120862            "attachment": {}
120863          },
120864          "pedigree": {},
120865          "externalReferences": [
120866            {
120867              "url": "https://www.openssl.org/",
120868              "type": "distribution"
120869            }
120870          ],
120871          "evidence": {},
120872          "signature": {
120873            "signature": {
120874              "publicKey": {}
120875            }
120876          },
120877          "modelCard": {
120878            "modelParameters": {
120879              "approach": {}
120880            },
120881            "quantitativeAnalysis": {
120882              "graphics": {}
120883            },
120884            "considerations": {}
120885          }
120886        },
120887        {
120888          "type": "library",
120889          "bom-ref": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=9913678ca8fd323d",
120890          "supplier": {},
120891          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
120892          "name": "libstdc++",
120893          "version": "11.2.1_git20220219-r2",
120894          "description": "GNU C++ standard runtime library",
120895          "licenses": [
120896            {
120897              "license": {
120898                "id": "GPL-2.0-or-later"
120899              }
120900            },
120901            {
120902              "license": {
120903                "id": "LGPL-2.1-or-later"
120904              }
120905            }
120906          ],
120907          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
120908          "purl": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
120909          "swid": {
120910            "attachment": {}
120911          },
120912          "pedigree": {},
120913          "externalReferences": [
120914            {
120915              "url": "https://gcc.gnu.org",
120916              "type": "distribution"
120917            }
120918          ],
120919          "evidence": {},
120920          "signature": {
120921            "signature": {
120922              "publicKey": {}
120923            }
120924          },
120925          "modelCard": {
120926            "modelParameters": {
120927              "approach": {}
120928            },
120929            "quantitativeAnalysis": {
120930              "graphics": {}
120931            },
120932            "considerations": {}
120933          }
120934        },
120935        {
120936          "type": "library",
120937          "bom-ref": "pkg:npm/lodash.includes@4.3.0?package-id=e642ed7dc69687c",
120938          "supplier": {},
120939          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
120940          "name": "lodash.includes",
120941          "version": "4.3.0",
120942          "description": "The lodash method `_.includes` exported as a module.",
120943          "licenses": [
120944            {
120945              "license": {
120946                "id": "MIT"
120947              }
120948            }
120949          ],
120950          "cpe": "cpe:2.3:a:lodash.includes:lodash.includes:4.3.0:*:*:*:*:*:*:*",
120951          "purl": "pkg:npm/lodash.includes@4.3.0",
120952          "swid": {
120953            "attachment": {}
120954          },
120955          "pedigree": {},
120956          "externalReferences": [
120957            {
120958              "url": "lodash/lodash",
120959              "type": "distribution"
120960            },
120961            {
120962              "url": "https://lodash.com/",
120963              "type": "website"
120964            }
120965          ],
120966          "evidence": {},
120967          "signature": {
120968            "signature": {
120969              "publicKey": {}
120970            }
120971          },
120972          "modelCard": {
120973            "modelParameters": {
120974              "approach": {}
120975            },
120976            "quantitativeAnalysis": {
120977              "graphics": {}
120978            },
120979            "considerations": {}
120980          }
120981        },
120982        {
120983          "type": "library",
120984          "bom-ref": "pkg:npm/lodash.isboolean@3.0.3?package-id=9c5c8366ab928120",
120985          "supplier": {},
120986          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
120987          "name": "lodash.isboolean",
120988          "version": "3.0.3",
120989          "description": "The lodash method `_.isBoolean` exported as a module.",
120990          "licenses": [
120991            {
120992              "license": {
120993                "id": "MIT"
120994              }
120995            }
120996          ],
120997          "cpe": "cpe:2.3:a:lodash.isboolean:lodash.isboolean:3.0.3:*:*:*:*:*:*:*",
120998          "purl": "pkg:npm/lodash.isboolean@3.0.3",
120999          "swid": {
121000            "attachment": {}
121001          },
121002          "pedigree": {},
121003          "externalReferences": [
121004            {
121005              "url": "lodash/lodash",
121006              "type": "distribution"
121007            },
121008            {
121009              "url": "https://lodash.com/",
121010              "type": "website"
121011            }
121012          ],
121013          "evidence": {},
121014          "signature": {
121015            "signature": {
121016              "publicKey": {}
121017            }
121018          },
121019          "modelCard": {
121020            "modelParameters": {
121021              "approach": {}
121022            },
121023            "quantitativeAnalysis": {
121024              "graphics": {}
121025            },
121026            "considerations": {}
121027          }
121028        },
121029        {
121030          "type": "library",
121031          "bom-ref": "pkg:npm/lodash.isinteger@4.0.4?package-id=aa92f56128804239",
121032          "supplier": {},
121033          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
121034          "name": "lodash.isinteger",
121035          "version": "4.0.4",
121036          "description": "The lodash method `_.isInteger` exported as a module.",
121037          "licenses": [
121038            {
121039              "license": {
121040                "id": "MIT"
121041              }
121042            }
121043          ],
121044          "cpe": "cpe:2.3:a:lodash.isinteger:lodash.isinteger:4.0.4:*:*:*:*:*:*:*",
121045          "purl": "pkg:npm/lodash.isinteger@4.0.4",
121046          "swid": {
121047            "attachment": {}
121048          },
121049          "pedigree": {},
121050          "externalReferences": [
121051            {
121052              "url": "lodash/lodash",
121053              "type": "distribution"
121054            },
121055            {
121056              "url": "https://lodash.com/",
121057              "type": "website"
121058            }
121059          ],
121060          "evidence": {},
121061          "signature": {
121062            "signature": {
121063              "publicKey": {}
121064            }
121065          },
121066          "modelCard": {
121067            "modelParameters": {
121068              "approach": {}
121069            },
121070            "quantitativeAnalysis": {
121071              "graphics": {}
121072            },
121073            "considerations": {}
121074          }
121075        },
121076        {
121077          "type": "library",
121078          "bom-ref": "pkg:npm/lodash.isnumber@3.0.3?package-id=963f9beea645577e",
121079          "supplier": {},
121080          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
121081          "name": "lodash.isnumber",
121082          "version": "3.0.3",
121083          "description": "The lodash method `_.isNumber` exported as a module.",
121084          "licenses": [
121085            {
121086              "license": {
121087                "id": "MIT"
121088              }
121089            }
121090          ],
121091          "cpe": "cpe:2.3:a:lodash.isnumber:lodash.isnumber:3.0.3:*:*:*:*:*:*:*",
121092          "purl": "pkg:npm/lodash.isnumber@3.0.3",
121093          "swid": {
121094            "attachment": {}
121095          },
121096          "pedigree": {},
121097          "externalReferences": [
121098            {
121099              "url": "lodash/lodash",
121100              "type": "distribution"
121101            },
121102            {
121103              "url": "https://lodash.com/",
121104              "type": "website"
121105            }
121106          ],
121107          "evidence": {},
121108          "signature": {
121109            "signature": {
121110              "publicKey": {}
121111            }
121112          },
121113          "modelCard": {
121114            "modelParameters": {
121115              "approach": {}
121116            },
121117            "quantitativeAnalysis": {
121118              "graphics": {}
121119            },
121120            "considerations": {}
121121          }
121122        },
121123        {
121124          "type": "library",
121125          "bom-ref": "pkg:npm/lodash.isplainobject@4.0.6?package-id=523afc7470c06d90",
121126          "supplier": {},
121127          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
121128          "name": "lodash.isplainobject",
121129          "version": "4.0.6",
121130          "description": "The lodash method `_.isPlainObject` exported as a module.",
121131          "licenses": [
121132            {
121133              "license": {
121134                "id": "MIT"
121135              }
121136            }
121137          ],
121138          "cpe": "cpe:2.3:a:lodash.isplainobject:lodash.isplainobject:4.0.6:*:*:*:*:*:*:*",
121139          "purl": "pkg:npm/lodash.isplainobject@4.0.6",
121140          "swid": {
121141            "attachment": {}
121142          },
121143          "pedigree": {},
121144          "externalReferences": [
121145            {
121146              "url": "lodash/lodash",
121147              "type": "distribution"
121148            },
121149            {
121150              "url": "https://lodash.com/",
121151              "type": "website"
121152            }
121153          ],
121154          "evidence": {},
121155          "signature": {
121156            "signature": {
121157              "publicKey": {}
121158            }
121159          },
121160          "modelCard": {
121161            "modelParameters": {
121162              "approach": {}
121163            },
121164            "quantitativeAnalysis": {
121165              "graphics": {}
121166            },
121167            "considerations": {}
121168          }
121169        },
121170        {
121171          "type": "library",
121172          "bom-ref": "pkg:npm/lodash.isstring@4.0.1?package-id=8d274551fef91ebf",
121173          "supplier": {},
121174          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
121175          "name": "lodash.isstring",
121176          "version": "4.0.1",
121177          "description": "The lodash method `_.isString` exported as a module.",
121178          "licenses": [
121179            {
121180              "license": {
121181                "id": "MIT"
121182              }
121183            }
121184          ],
121185          "cpe": "cpe:2.3:a:lodash.isstring:lodash.isstring:4.0.1:*:*:*:*:*:*:*",
121186          "purl": "pkg:npm/lodash.isstring@4.0.1",
121187          "swid": {
121188            "attachment": {}
121189          },
121190          "pedigree": {},
121191          "externalReferences": [
121192            {
121193              "url": "lodash/lodash",
121194              "type": "distribution"
121195            },
121196            {
121197              "url": "https://lodash.com/",
121198              "type": "website"
121199            }
121200          ],
121201          "evidence": {},
121202          "signature": {
121203            "signature": {
121204              "publicKey": {}
121205            }
121206          },
121207          "modelCard": {
121208            "modelParameters": {
121209              "approach": {}
121210            },
121211            "quantitativeAnalysis": {
121212              "graphics": {}
121213            },
121214            "considerations": {}
121215          }
121216        },
121217        {
121218          "type": "library",
121219          "bom-ref": "pkg:npm/lodash.once@4.1.1?package-id=69698aaf59fc8049",
121220          "supplier": {},
121221          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
121222          "name": "lodash.once",
121223          "version": "4.1.1",
121224          "description": "The lodash method `_.once` exported as a module.",
121225          "licenses": [
121226            {
121227              "license": {
121228                "id": "MIT"
121229              }
121230            }
121231          ],
121232          "cpe": "cpe:2.3:a:lodash.once:lodash.once:4.1.1:*:*:*:*:*:*:*",
121233          "purl": "pkg:npm/lodash.once@4.1.1",
121234          "swid": {
121235            "attachment": {}
121236          },
121237          "pedigree": {},
121238          "externalReferences": [
121239            {
121240              "url": "lodash/lodash",
121241              "type": "distribution"
121242            },
121243            {
121244              "url": "https://lodash.com/",
121245              "type": "website"
121246            }
121247          ],
121248          "evidence": {},
121249          "signature": {
121250            "signature": {
121251              "publicKey": {}
121252            }
121253          },
121254          "modelCard": {
121255            "modelParameters": {
121256              "approach": {}
121257            },
121258            "quantitativeAnalysis": {
121259              "graphics": {}
121260            },
121261            "considerations": {}
121262          }
121263        },
121264        {
121265          "type": "library",
121266          "bom-ref": "pkg:npm/lru-cache@6.0.0?package-id=a9db11b8d6d48a85",
121267          "supplier": {},
121268          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
121269          "name": "lru-cache",
121270          "version": "6.0.0",
121271          "description": "A cache object that deletes the least-recently-used items.",
121272          "licenses": [
121273            {
121274              "license": {
121275                "id": "ISC"
121276              }
121277            }
121278          ],
121279          "cpe": "cpe:2.3:a:lru-cache:lru-cache:6.0.0:*:*:*:*:*:*:*",
121280          "purl": "pkg:npm/lru-cache@6.0.0",
121281          "swid": {
121282            "attachment": {}
121283          },
121284          "pedigree": {},
121285          "externalReferences": [
121286            {
121287              "url": "git://github.com/isaacs/node-lru-cache.git",
121288              "type": "distribution"
121289            }
121290          ],
121291          "evidence": {},
121292          "signature": {
121293            "signature": {
121294              "publicKey": {}
121295            }
121296          },
121297          "modelCard": {
121298            "modelParameters": {
121299              "approach": {}
121300            },
121301            "quantitativeAnalysis": {
121302              "graphics": {}
121303            },
121304            "considerations": {}
121305          }
121306        },
121307        {
121308          "type": "library",
121309          "bom-ref": "pkg:npm/lru-cache@7.13.2?package-id=be5c7dc6ddace7cd",
121310          "supplier": {},
121311          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
121312          "name": "lru-cache",
121313          "version": "7.13.2",
121314          "description": "A cache object that deletes the least-recently-used items.",
121315          "licenses": [
121316            {
121317              "license": {
121318                "id": "ISC"
121319              }
121320            }
121321          ],
121322          "cpe": "cpe:2.3:a:lru-cache:lru-cache:7.13.2:*:*:*:*:*:*:*",
121323          "purl": "pkg:npm/lru-cache@7.13.2",
121324          "swid": {
121325            "attachment": {}
121326          },
121327          "pedigree": {},
121328          "externalReferences": [
121329            {
121330              "url": "git://github.com/isaacs/node-lru-cache.git",
121331              "type": "distribution"
121332            }
121333          ],
121334          "evidence": {},
121335          "signature": {
121336            "signature": {
121337              "publicKey": {}
121338            }
121339          },
121340          "modelCard": {
121341            "modelParameters": {
121342              "approach": {}
121343            },
121344            "quantitativeAnalysis": {
121345              "graphics": {}
121346            },
121347            "considerations": {}
121348          }
121349        },
121350        {
121351          "type": "library",
121352          "bom-ref": "pkg:npm/make-fetch-happen@10.2.1?package-id=d230079dee920278",
121353          "supplier": {},
121354          "author": "GitHub Inc.",
121355          "name": "make-fetch-happen",
121356          "version": "10.2.1",
121357          "description": "Opinionated, caching, retrying fetch client",
121358          "licenses": [
121359            {
121360              "license": {
121361                "id": "ISC"
121362              }
121363            }
121364          ],
121365          "cpe": "cpe:2.3:a:make-fetch-happen:make-fetch-happen:10.2.1:*:*:*:*:*:*:*",
121366          "purl": "pkg:npm/make-fetch-happen@10.2.1",
121367          "swid": {
121368            "attachment": {}
121369          },
121370          "pedigree": {},
121371          "externalReferences": [
121372            {
121373              "url": "https://github.com/npm/make-fetch-happen.git",
121374              "type": "distribution"
121375            }
121376          ],
121377          "evidence": {},
121378          "signature": {
121379            "signature": {
121380              "publicKey": {}
121381            }
121382          },
121383          "modelCard": {
121384            "modelParameters": {
121385              "approach": {}
121386            },
121387            "quantitativeAnalysis": {
121388              "graphics": {}
121389            },
121390            "considerations": {}
121391          }
121392        },
121393        {
121394          "type": "library",
121395          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=32b47b032f3721ab",
121396          "supplier": {},
121397          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
121398          "name": "minimatch",
121399          "version": "3.1.2",
121400          "description": "a glob matcher in javascript",
121401          "licenses": [
121402            {
121403              "license": {
121404                "id": "ISC"
121405              }
121406            }
121407          ],
121408          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
121409          "purl": "pkg:npm/minimatch@3.1.2",
121410          "swid": {
121411            "attachment": {}
121412          },
121413          "pedigree": {},
121414          "externalReferences": [
121415            {
121416              "url": "git://github.com/isaacs/minimatch.git",
121417              "type": "distribution"
121418            }
121419          ],
121420          "evidence": {},
121421          "signature": {
121422            "signature": {
121423              "publicKey": {}
121424            }
121425          },
121426          "modelCard": {
121427            "modelParameters": {
121428              "approach": {}
121429            },
121430            "quantitativeAnalysis": {
121431              "graphics": {}
121432            },
121433            "considerations": {}
121434          }
121435        },
121436        {
121437          "type": "library",
121438          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=7392185ecbfd5435",
121439          "supplier": {},
121440          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
121441          "name": "minimatch",
121442          "version": "3.1.2",
121443          "description": "a glob matcher in javascript",
121444          "licenses": [
121445            {
121446              "license": {
121447                "id": "ISC"
121448              }
121449            }
121450          ],
121451          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
121452          "purl": "pkg:npm/minimatch@3.1.2",
121453          "swid": {
121454            "attachment": {}
121455          },
121456          "pedigree": {},
121457          "externalReferences": [
121458            {
121459              "url": "git://github.com/isaacs/minimatch.git",
121460              "type": "distribution"
121461            }
121462          ],
121463          "evidence": {},
121464          "signature": {
121465            "signature": {
121466              "publicKey": {}
121467            }
121468          },
121469          "modelCard": {
121470            "modelParameters": {
121471              "approach": {}
121472            },
121473            "quantitativeAnalysis": {
121474              "graphics": {}
121475            },
121476            "considerations": {}
121477          }
121478        },
121479        {
121480          "type": "library",
121481          "bom-ref": "pkg:npm/minimatch@5.1.0?package-id=7bf8dbc1a2543e83",
121482          "supplier": {},
121483          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
121484          "name": "minimatch",
121485          "version": "5.1.0",
121486          "description": "a glob matcher in javascript",
121487          "licenses": [
121488            {
121489              "license": {
121490                "id": "ISC"
121491              }
121492            }
121493          ],
121494          "cpe": "cpe:2.3:a:minimatch:minimatch:5.1.0:*:*:*:*:*:*:*",
121495          "purl": "pkg:npm/minimatch@5.1.0",
121496          "swid": {
121497            "attachment": {}
121498          },
121499          "pedigree": {},
121500          "externalReferences": [
121501            {
121502              "url": "git://github.com/isaacs/minimatch.git",
121503              "type": "distribution"
121504            }
121505          ],
121506          "evidence": {},
121507          "signature": {
121508            "signature": {
121509              "publicKey": {}
121510            }
121511          },
121512          "modelCard": {
121513            "modelParameters": {
121514              "approach": {}
121515            },
121516            "quantitativeAnalysis": {
121517              "graphics": {}
121518            },
121519            "considerations": {}
121520          }
121521        },
121522        {
121523          "type": "library",
121524          "bom-ref": "pkg:npm/minipass@3.3.4?package-id=b613ca6e3e5e1fdb",
121525          "supplier": {},
121526          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
121527          "name": "minipass",
121528          "version": "3.3.4",
121529          "description": "minimal implementation of a PassThrough stream",
121530          "licenses": [
121531            {
121532              "license": {
121533                "id": "ISC"
121534              }
121535            }
121536          ],
121537          "cpe": "cpe:2.3:a:minipass:minipass:3.3.4:*:*:*:*:*:*:*",
121538          "purl": "pkg:npm/minipass@3.3.4",
121539          "swid": {
121540            "attachment": {}
121541          },
121542          "pedigree": {},
121543          "externalReferences": [
121544            {
121545              "url": "git+https://github.com/isaacs/minipass.git",
121546              "type": "distribution"
121547            }
121548          ],
121549          "evidence": {},
121550          "signature": {
121551            "signature": {
121552              "publicKey": {}
121553            }
121554          },
121555          "modelCard": {
121556            "modelParameters": {
121557              "approach": {}
121558            },
121559            "quantitativeAnalysis": {
121560              "graphics": {}
121561            },
121562            "considerations": {}
121563          }
121564        },
121565        {
121566          "type": "library",
121567          "bom-ref": "pkg:npm/minipass-collect@1.0.2?package-id=48596b1d4dbb4f19",
121568          "supplier": {},
121569          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
121570          "name": "minipass-collect",
121571          "version": "1.0.2",
121572          "description": "A Minipass stream that collects all the data into a single chunk",
121573          "licenses": [
121574            {
121575              "license": {
121576                "id": "ISC"
121577              }
121578            }
121579          ],
121580          "cpe": "cpe:2.3:a:minipass-collect:minipass-collect:1.0.2:*:*:*:*:*:*:*",
121581          "purl": "pkg:npm/minipass-collect@1.0.2",
121582          "swid": {
121583            "attachment": {}
121584          },
121585          "pedigree": {},
121586          "evidence": {},
121587          "signature": {
121588            "signature": {
121589              "publicKey": {}
121590            }
121591          },
121592          "modelCard": {
121593            "modelParameters": {
121594              "approach": {}
121595            },
121596            "quantitativeAnalysis": {
121597              "graphics": {}
121598            },
121599            "considerations": {}
121600          }
121601        },
121602        {
121603          "type": "library",
121604          "bom-ref": "pkg:npm/minipass-fetch@2.1.1?package-id=1efc5437ba452e1d",
121605          "supplier": {},
121606          "author": "GitHub Inc.",
121607          "name": "minipass-fetch",
121608          "version": "2.1.1",
121609          "description": "An implementation of window.fetch in Node.js using Minipass streams",
121610          "licenses": [
121611            {
121612              "license": {
121613                "id": "MIT"
121614              }
121615            }
121616          ],
121617          "cpe": "cpe:2.3:a:minipass-fetch:minipass-fetch:2.1.1:*:*:*:*:*:*:*",
121618          "purl": "pkg:npm/minipass-fetch@2.1.1",
121619          "swid": {
121620            "attachment": {}
121621          },
121622          "pedigree": {},
121623          "externalReferences": [
121624            {
121625              "url": "https://github.com/npm/minipass-fetch.git",
121626              "type": "distribution"
121627            }
121628          ],
121629          "evidence": {},
121630          "signature": {
121631            "signature": {
121632              "publicKey": {}
121633            }
121634          },
121635          "modelCard": {
121636            "modelParameters": {
121637              "approach": {}
121638            },
121639            "quantitativeAnalysis": {
121640              "graphics": {}
121641            },
121642            "considerations": {}
121643          }
121644        },
121645        {
121646          "type": "library",
121647          "bom-ref": "pkg:npm/minipass-flush@1.0.5?package-id=f00a260926226ede",
121648          "supplier": {},
121649          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
121650          "name": "minipass-flush",
121651          "version": "1.0.5",
121652          "description": "A Minipass stream that calls a flush function before emitting 'end'",
121653          "licenses": [
121654            {
121655              "license": {
121656                "id": "ISC"
121657              }
121658            }
121659          ],
121660          "cpe": "cpe:2.3:a:minipass-flush:minipass-flush:1.0.5:*:*:*:*:*:*:*",
121661          "purl": "pkg:npm/minipass-flush@1.0.5",
121662          "swid": {
121663            "attachment": {}
121664          },
121665          "pedigree": {},
121666          "externalReferences": [
121667            {
121668              "url": "git+https://github.com/isaacs/minipass-flush.git",
121669              "type": "distribution"
121670            }
121671          ],
121672          "evidence": {},
121673          "signature": {
121674            "signature": {
121675              "publicKey": {}
121676            }
121677          },
121678          "modelCard": {
121679            "modelParameters": {
121680              "approach": {}
121681            },
121682            "quantitativeAnalysis": {
121683              "graphics": {}
121684            },
121685            "considerations": {}
121686          }
121687        },
121688        {
121689          "type": "library",
121690          "bom-ref": "pkg:npm/minipass-json-stream@1.0.1?package-id=43ed818882788b6b",
121691          "supplier": {},
121692          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
121693          "name": "minipass-json-stream",
121694          "version": "1.0.1",
121695          "description": "Like JSONStream, but using Minipass streams",
121696          "licenses": [
121697            {
121698              "license": {
121699                "id": "MIT"
121700              }
121701            }
121702          ],
121703          "cpe": "cpe:2.3:a:minipass-json-stream:minipass-json-stream:1.0.1:*:*:*:*:*:*:*",
121704          "purl": "pkg:npm/minipass-json-stream@1.0.1",
121705          "swid": {
121706            "attachment": {}
121707          },
121708          "pedigree": {},
121709          "externalReferences": [
121710            {
121711              "url": "git+https://github.com/npm/minipass-json-stream.git",
121712              "type": "distribution"
121713            }
121714          ],
121715          "evidence": {},
121716          "signature": {
121717            "signature": {
121718              "publicKey": {}
121719            }
121720          },
121721          "modelCard": {
121722            "modelParameters": {
121723              "approach": {}
121724            },
121725            "quantitativeAnalysis": {
121726              "graphics": {}
121727            },
121728            "considerations": {}
121729          }
121730        },
121731        {
121732          "type": "library",
121733          "bom-ref": "pkg:npm/minipass-pipeline@1.2.4?package-id=891713a52fe6cc27",
121734          "supplier": {},
121735          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
121736          "name": "minipass-pipeline",
121737          "version": "1.2.4",
121738          "description": "create a pipeline of streams using Minipass",
121739          "licenses": [
121740            {
121741              "license": {
121742                "id": "ISC"
121743              }
121744            }
121745          ],
121746          "cpe": "cpe:2.3:a:minipass-pipeline:minipass-pipeline:1.2.4:*:*:*:*:*:*:*",
121747          "purl": "pkg:npm/minipass-pipeline@1.2.4",
121748          "swid": {
121749            "attachment": {}
121750          },
121751          "pedigree": {},
121752          "evidence": {},
121753          "signature": {
121754            "signature": {
121755              "publicKey": {}
121756            }
121757          },
121758          "modelCard": {
121759            "modelParameters": {
121760              "approach": {}
121761            },
121762            "quantitativeAnalysis": {
121763              "graphics": {}
121764            },
121765            "considerations": {}
121766          }
121767        },
121768        {
121769          "type": "library",
121770          "bom-ref": "pkg:npm/minipass-sized@1.0.3?package-id=cd4842c35733398b",
121771          "supplier": {},
121772          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
121773          "name": "minipass-sized",
121774          "version": "1.0.3",
121775          "description": "A Minipass stream that raises an error if you get a different number of bytes than expected",
121776          "licenses": [
121777            {
121778              "license": {
121779                "id": "ISC"
121780              }
121781            }
121782          ],
121783          "cpe": "cpe:2.3:a:minipass-sized:minipass-sized:1.0.3:*:*:*:*:*:*:*",
121784          "purl": "pkg:npm/minipass-sized@1.0.3",
121785          "swid": {
121786            "attachment": {}
121787          },
121788          "pedigree": {},
121789          "externalReferences": [
121790            {
121791              "url": "git+https://github.com/isaacs/minipass-sized.git",
121792              "type": "distribution"
121793            }
121794          ],
121795          "evidence": {},
121796          "signature": {
121797            "signature": {
121798              "publicKey": {}
121799            }
121800          },
121801          "modelCard": {
121802            "modelParameters": {
121803              "approach": {}
121804            },
121805            "quantitativeAnalysis": {
121806              "graphics": {}
121807            },
121808            "considerations": {}
121809          }
121810        },
121811        {
121812          "type": "library",
121813          "bom-ref": "pkg:npm/minizlib@2.1.2?package-id=a651644b4f6a3e3",
121814          "supplier": {},
121815          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
121816          "name": "minizlib",
121817          "version": "2.1.2",
121818          "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
121819          "licenses": [
121820            {
121821              "license": {
121822                "id": "MIT"
121823              }
121824            }
121825          ],
121826          "cpe": "cpe:2.3:a:minizlib:minizlib:2.1.2:*:*:*:*:*:*:*",
121827          "purl": "pkg:npm/minizlib@2.1.2",
121828          "swid": {
121829            "attachment": {}
121830          },
121831          "pedigree": {},
121832          "externalReferences": [
121833            {
121834              "url": "git+https://github.com/isaacs/minizlib.git",
121835              "type": "distribution"
121836            }
121837          ],
121838          "evidence": {},
121839          "signature": {
121840            "signature": {
121841              "publicKey": {}
121842            }
121843          },
121844          "modelCard": {
121845            "modelParameters": {
121846              "approach": {}
121847            },
121848            "quantitativeAnalysis": {
121849              "graphics": {}
121850            },
121851            "considerations": {}
121852          }
121853        },
121854        {
121855          "type": "library",
121856          "bom-ref": "pkg:npm/mkdirp@1.0.4?package-id=9695628e211e131d",
121857          "supplier": {},
121858          "name": "mkdirp",
121859          "version": "1.0.4",
121860          "description": "Recursively mkdir, like `mkdir -p`",
121861          "licenses": [
121862            {
121863              "license": {
121864                "id": "MIT"
121865              }
121866            }
121867          ],
121868          "cpe": "cpe:2.3:a:isaacs:mkdirp:1.0.4:*:*:*:*:*:*:*",
121869          "purl": "pkg:npm/mkdirp@1.0.4",
121870          "swid": {
121871            "attachment": {}
121872          },
121873          "pedigree": {},
121874          "externalReferences": [
121875            {
121876              "url": "https://github.com/isaacs/node-mkdirp.git",
121877              "type": "distribution"
121878            }
121879          ],
121880          "evidence": {},
121881          "signature": {
121882            "signature": {
121883              "publicKey": {}
121884            }
121885          },
121886          "modelCard": {
121887            "modelParameters": {
121888              "approach": {}
121889            },
121890            "quantitativeAnalysis": {
121891              "graphics": {}
121892            },
121893            "considerations": {}
121894          }
121895        },
121896        {
121897          "type": "library",
121898          "bom-ref": "pkg:npm/mkdirp-infer-owner@2.0.0?package-id=cd2840516db98e09",
121899          "supplier": {},
121900          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
121901          "name": "mkdirp-infer-owner",
121902          "version": "2.0.0",
121903          "description": "mkdirp, but chown to the owner of the containing folder if possible and necessary",
121904          "licenses": [
121905            {
121906              "license": {
121907                "id": "ISC"
121908              }
121909            }
121910          ],
121911          "cpe": "cpe:2.3:a:mkdirp-infer-owner:mkdirp-infer-owner:2.0.0:*:*:*:*:*:*:*",
121912          "purl": "pkg:npm/mkdirp-infer-owner@2.0.0",
121913          "swid": {
121914            "attachment": {}
121915          },
121916          "pedigree": {},
121917          "externalReferences": [
121918            {
121919              "url": "git+https://github.com/isaacs/mkdirp-infer-owner",
121920              "type": "distribution"
121921            }
121922          ],
121923          "evidence": {},
121924          "signature": {
121925            "signature": {
121926              "publicKey": {}
121927            }
121928          },
121929          "modelCard": {
121930            "modelParameters": {
121931              "approach": {}
121932            },
121933            "quantitativeAnalysis": {
121934              "graphics": {}
121935            },
121936            "considerations": {}
121937          }
121938        },
121939        {
121940          "type": "library",
121941          "bom-ref": "pkg:npm/ms@2.1.2?package-id=baab6160abc8414d",
121942          "supplier": {},
121943          "name": "ms",
121944          "version": "2.1.2",
121945          "description": "Tiny millisecond conversion utility",
121946          "licenses": [
121947            {
121948              "license": {
121949                "id": "MIT"
121950              }
121951            }
121952          ],
121953          "cpe": "cpe:2.3:a:ms:ms:2.1.2:*:*:*:*:*:*:*",
121954          "purl": "pkg:npm/ms@2.1.2",
121955          "swid": {
121956            "attachment": {}
121957          },
121958          "pedigree": {},
121959          "externalReferences": [
121960            {
121961              "url": "zeit/ms",
121962              "type": "distribution"
121963            }
121964          ],
121965          "evidence": {},
121966          "signature": {
121967            "signature": {
121968              "publicKey": {}
121969            }
121970          },
121971          "modelCard": {
121972            "modelParameters": {
121973              "approach": {}
121974            },
121975            "quantitativeAnalysis": {
121976              "graphics": {}
121977            },
121978            "considerations": {}
121979          }
121980        },
121981        {
121982          "type": "library",
121983          "bom-ref": "pkg:npm/ms@2.1.3?package-id=b589e0f87d3cac5b",
121984          "supplier": {},
121985          "name": "ms",
121986          "version": "2.1.3",
121987          "description": "Tiny millisecond conversion utility",
121988          "licenses": [
121989            {
121990              "license": {
121991                "id": "MIT"
121992              }
121993            }
121994          ],
121995          "cpe": "cpe:2.3:a:ms:ms:2.1.3:*:*:*:*:*:*:*",
121996          "purl": "pkg:npm/ms@2.1.3",
121997          "swid": {
121998            "attachment": {}
121999          },
122000          "pedigree": {},
122001          "externalReferences": [
122002            {
122003              "url": "vercel/ms",
122004              "type": "distribution"
122005            }
122006          ],
122007          "evidence": {},
122008          "signature": {
122009            "signature": {
122010              "publicKey": {}
122011            }
122012          },
122013          "modelCard": {
122014            "modelParameters": {
122015              "approach": {}
122016            },
122017            "quantitativeAnalysis": {
122018              "graphics": {}
122019            },
122020            "considerations": {}
122021          }
122022        },
122023        {
122024          "type": "library",
122025          "bom-ref": "pkg:npm/ms@2.1.3?package-id=56db25c219fa0f4e",
122026          "supplier": {},
122027          "name": "ms",
122028          "version": "2.1.3",
122029          "description": "Tiny millisecond conversion utility",
122030          "licenses": [
122031            {
122032              "license": {
122033                "id": "MIT"
122034              }
122035            }
122036          ],
122037          "cpe": "cpe:2.3:a:ms:ms:2.1.3:*:*:*:*:*:*:*",
122038          "purl": "pkg:npm/ms@2.1.3",
122039          "swid": {
122040            "attachment": {}
122041          },
122042          "pedigree": {},
122043          "externalReferences": [
122044            {
122045              "url": "vercel/ms",
122046              "type": "distribution"
122047            }
122048          ],
122049          "evidence": {},
122050          "signature": {
122051            "signature": {
122052              "publicKey": {}
122053            }
122054          },
122055          "modelCard": {
122056            "modelParameters": {
122057              "approach": {}
122058            },
122059            "quantitativeAnalysis": {
122060              "graphics": {}
122061            },
122062            "considerations": {}
122063          }
122064        },
122065        {
122066          "type": "library",
122067          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=24c6089b81ca7d19",
122068          "supplier": {},
122069          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
122070          "name": "musl",
122071          "version": "1.2.3-r2",
122072          "description": "the musl c library (libc) implementation",
122073          "licenses": [
122074            {
122075              "license": {
122076                "id": "MIT"
122077              }
122078            }
122079          ],
122080          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r2:*:*:*:*:*:*:*",
122081          "purl": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5",
122082          "swid": {
122083            "attachment": {}
122084          },
122085          "pedigree": {},
122086          "externalReferences": [
122087            {
122088              "url": "https://musl.libc.org/",
122089              "type": "distribution"
122090            }
122091          ],
122092          "evidence": {},
122093          "signature": {
122094            "signature": {
122095              "publicKey": {}
122096            }
122097          },
122098          "modelCard": {
122099            "modelParameters": {
122100              "approach": {}
122101            },
122102            "quantitativeAnalysis": {
122103              "graphics": {}
122104            },
122105            "considerations": {}
122106          }
122107        },
122108        {
122109          "type": "library",
122110          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5\u0026package-id=d33c14d727ae74d1",
122111          "supplier": {},
122112          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
122113          "name": "musl-utils",
122114          "version": "1.2.3-r2",
122115          "description": "the musl c library (libc) implementation",
122116          "licenses": [
122117            {
122118              "license": {
122119                "id": "MIT"
122120              }
122121            },
122122            {
122123              "license": {
122124                "name": "BSD"
122125              }
122126            },
122127            {
122128              "license": {
122129                "id": "GPL-2.0-or-later"
122130              }
122131            }
122132          ],
122133          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r2:*:*:*:*:*:*:*",
122134          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5",
122135          "swid": {
122136            "attachment": {}
122137          },
122138          "pedigree": {},
122139          "externalReferences": [
122140            {
122141              "url": "https://musl.libc.org/",
122142              "type": "distribution"
122143            }
122144          ],
122145          "evidence": {},
122146          "signature": {
122147            "signature": {
122148              "publicKey": {}
122149            }
122150          },
122151          "modelCard": {
122152            "modelParameters": {
122153              "approach": {}
122154            },
122155            "quantitativeAnalysis": {
122156              "graphics": {}
122157            },
122158            "considerations": {}
122159          }
122160        },
122161        {
122162          "type": "library",
122163          "bom-ref": "pkg:npm/mute-stream@0.0.8?package-id=b093eec725f75ac9",
122164          "supplier": {},
122165          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
122166          "name": "mute-stream",
122167          "version": "0.0.8",
122168          "description": "Bytes go in, but they don't come out (when muted).",
122169          "licenses": [
122170            {
122171              "license": {
122172                "id": "ISC"
122173              }
122174            }
122175          ],
122176          "cpe": "cpe:2.3:a:mute-stream:mute-stream:0.0.8:*:*:*:*:*:*:*",
122177          "purl": "pkg:npm/mute-stream@0.0.8",
122178          "swid": {
122179            "attachment": {}
122180          },
122181          "pedigree": {},
122182          "externalReferences": [
122183            {
122184              "url": "git://github.com/isaacs/mute-stream",
122185              "type": "distribution"
122186            }
122187          ],
122188          "evidence": {},
122189          "signature": {
122190            "signature": {
122191              "publicKey": {}
122192            }
122193          },
122194          "modelCard": {
122195            "modelParameters": {
122196              "approach": {}
122197            },
122198            "quantitativeAnalysis": {
122199              "graphics": {}
122200            },
122201            "considerations": {}
122202          }
122203        },
122204        {
122205          "type": "library",
122206          "bom-ref": "pkg:npm/negotiator@0.6.3?package-id=87cc6cb502ab228a",
122207          "supplier": {},
122208          "name": "negotiator",
122209          "version": "0.6.3",
122210          "description": "HTTP content negotiation",
122211          "licenses": [
122212            {
122213              "license": {
122214                "id": "MIT"
122215              }
122216            }
122217          ],
122218          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.3:*:*:*:*:*:*:*",
122219          "purl": "pkg:npm/negotiator@0.6.3",
122220          "swid": {
122221            "attachment": {}
122222          },
122223          "pedigree": {},
122224          "externalReferences": [
122225            {
122226              "url": "jshttp/negotiator",
122227              "type": "distribution"
122228            }
122229          ],
122230          "evidence": {},
122231          "signature": {
122232            "signature": {
122233              "publicKey": {}
122234            }
122235          },
122236          "modelCard": {
122237            "modelParameters": {
122238              "approach": {}
122239            },
122240            "quantitativeAnalysis": {
122241              "graphics": {}
122242            },
122243            "considerations": {}
122244          }
122245        },
122246        {
122247          "type": "application",
122248          "bom-ref": "pkg:generic/node@16.20.0?package-id=c3df0c8aa56599a1",
122249          "supplier": {},
122250          "name": "node",
122251          "version": "16.20.0",
122252          "cpe": "cpe:2.3:a:nodejs:node.js:16.20.0:*:*:*:*:*:*:*",
122253          "purl": "pkg:generic/node@16.20.0",
122254          "swid": {
122255            "attachment": {}
122256          },
122257          "pedigree": {},
122258          "evidence": {},
122259          "signature": {
122260            "signature": {
122261              "publicKey": {}
122262            }
122263          },
122264          "modelCard": {
122265            "modelParameters": {
122266              "approach": {}
122267            },
122268            "quantitativeAnalysis": {
122269              "graphics": {}
122270            },
122271            "considerations": {}
122272          }
122273        },
122274        {
122275          "type": "library",
122276          "bom-ref": "pkg:npm/node-gyp@9.1.0?package-id=594531fb28fce181",
122277          "supplier": {},
122278          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://tootallnate.net)",
122279          "name": "node-gyp",
122280          "version": "9.1.0",
122281          "description": "Node.js native addon build tool",
122282          "licenses": [
122283            {
122284              "license": {
122285                "id": "MIT"
122286              }
122287            }
122288          ],
122289          "cpe": "cpe:2.3:a:node-gyp:node-gyp:9.1.0:*:*:*:*:*:*:*",
122290          "purl": "pkg:npm/node-gyp@9.1.0",
122291          "swid": {
122292            "attachment": {}
122293          },
122294          "pedigree": {},
122295          "externalReferences": [
122296            {
122297              "url": "git://github.com/nodejs/node-gyp.git",
122298              "type": "distribution"
122299            }
122300          ],
122301          "evidence": {},
122302          "signature": {
122303            "signature": {
122304              "publicKey": {}
122305            }
122306          },
122307          "modelCard": {
122308            "modelParameters": {
122309              "approach": {}
122310            },
122311            "quantitativeAnalysis": {
122312              "graphics": {}
122313            },
122314            "considerations": {}
122315          }
122316        },
122317        {
122318          "type": "library",
122319          "bom-ref": "pkg:npm/nopt@5.0.0?package-id=16f8d211f06e4fc1",
122320          "supplier": {},
122321          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
122322          "name": "nopt",
122323          "version": "5.0.0",
122324          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
122325          "licenses": [
122326            {
122327              "license": {
122328                "id": "ISC"
122329              }
122330            }
122331          ],
122332          "cpe": "cpe:2.3:a:nopt:nopt:5.0.0:*:*:*:*:*:*:*",
122333          "purl": "pkg:npm/nopt@5.0.0",
122334          "swid": {
122335            "attachment": {}
122336          },
122337          "pedigree": {},
122338          "externalReferences": [
122339            {
122340              "url": "https://github.com/npm/nopt.git",
122341              "type": "distribution"
122342            }
122343          ],
122344          "evidence": {},
122345          "signature": {
122346            "signature": {
122347              "publicKey": {}
122348            }
122349          },
122350          "modelCard": {
122351            "modelParameters": {
122352              "approach": {}
122353            },
122354            "quantitativeAnalysis": {
122355              "graphics": {}
122356            },
122357            "considerations": {}
122358          }
122359        },
122360        {
122361          "type": "library",
122362          "bom-ref": "pkg:npm/nopt@6.0.0?package-id=2da699f46c59247",
122363          "supplier": {},
122364          "author": "GitHub Inc.",
122365          "name": "nopt",
122366          "version": "6.0.0",
122367          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
122368          "licenses": [
122369            {
122370              "license": {
122371                "id": "ISC"
122372              }
122373            }
122374          ],
122375          "cpe": "cpe:2.3:a:nopt:nopt:6.0.0:*:*:*:*:*:*:*",
122376          "purl": "pkg:npm/nopt@6.0.0",
122377          "swid": {
122378            "attachment": {}
122379          },
122380          "pedigree": {},
122381          "externalReferences": [
122382            {
122383              "url": "https://github.com/npm/nopt.git",
122384              "type": "distribution"
122385            }
122386          ],
122387          "evidence": {},
122388          "signature": {
122389            "signature": {
122390              "publicKey": {}
122391            }
122392          },
122393          "modelCard": {
122394            "modelParameters": {
122395              "approach": {}
122396            },
122397            "quantitativeAnalysis": {
122398              "graphics": {}
122399            },
122400            "considerations": {}
122401          }
122402        },
122403        {
122404          "type": "library",
122405          "bom-ref": "pkg:npm/normalize-package-data@4.0.1?package-id=f65ac6113e729b71",
122406          "supplier": {},
122407          "author": "GitHub Inc.",
122408          "name": "normalize-package-data",
122409          "version": "4.0.1",
122410          "description": "Normalizes data that can be found in package.json files.",
122411          "licenses": [
122412            {
122413              "license": {
122414                "id": "BSD-2-Clause"
122415              }
122416            }
122417          ],
122418          "cpe": "cpe:2.3:a:normalize-package-data:normalize-package-data:4.0.1:*:*:*:*:*:*:*",
122419          "purl": "pkg:npm/normalize-package-data@4.0.1",
122420          "swid": {
122421            "attachment": {}
122422          },
122423          "pedigree": {},
122424          "externalReferences": [
122425            {
122426              "url": "https://github.com/npm/normalize-package-data.git",
122427              "type": "distribution"
122428            }
122429          ],
122430          "evidence": {},
122431          "signature": {
122432            "signature": {
122433              "publicKey": {}
122434            }
122435          },
122436          "modelCard": {
122437            "modelParameters": {
122438              "approach": {}
122439            },
122440            "quantitativeAnalysis": {
122441              "graphics": {}
122442            },
122443            "considerations": {}
122444          }
122445        },
122446        {
122447          "type": "library",
122448          "bom-ref": "pkg:npm/npm@8.19.4?package-id=3a7215c0f0fd939a",
122449          "supplier": {},
122450          "author": "GitHub Inc.",
122451          "name": "npm",
122452          "version": "8.19.4",
122453          "description": "a package manager for JavaScript",
122454          "licenses": [
122455            {
122456              "license": {
122457                "id": "Artistic-2.0"
122458              }
122459            }
122460          ],
122461          "cpe": "cpe:2.3:a:npm:npm:8.19.4:*:*:*:*:*:*:*",
122462          "purl": "pkg:npm/npm@8.19.4",
122463          "swid": {
122464            "attachment": {}
122465          },
122466          "pedigree": {},
122467          "externalReferences": [
122468            {
122469              "url": "https://github.com/npm/cli.git",
122470              "type": "distribution"
122471            },
122472            {
122473              "url": "https://docs.npmjs.com/",
122474              "type": "website"
122475            }
122476          ],
122477          "evidence": {},
122478          "signature": {
122479            "signature": {
122480              "publicKey": {}
122481            }
122482          },
122483          "modelCard": {
122484            "modelParameters": {
122485              "approach": {}
122486            },
122487            "quantitativeAnalysis": {
122488              "graphics": {}
122489            },
122490            "considerations": {}
122491          }
122492        },
122493        {
122494          "type": "library",
122495          "bom-ref": "pkg:npm/npm-audit-report@3.0.0?package-id=838d59a41103d415",
122496          "supplier": {},
122497          "author": "GitHub Inc.",
122498          "name": "npm-audit-report",
122499          "version": "3.0.0",
122500          "description": "Given a response from the npm security api, render it into a variety of security reports",
122501          "licenses": [
122502            {
122503              "license": {
122504                "id": "ISC"
122505              }
122506            }
122507          ],
122508          "cpe": "cpe:2.3:a:npm-audit-report:npm-audit-report:3.0.0:*:*:*:*:*:*:*",
122509          "purl": "pkg:npm/npm-audit-report@3.0.0",
122510          "swid": {
122511            "attachment": {}
122512          },
122513          "pedigree": {},
122514          "externalReferences": [
122515            {
122516              "url": "https://github.com/npm/npm-audit-report.git",
122517              "type": "distribution"
122518            },
122519            {
122520              "url": "https://github.com/npm/npm-audit-report#readme",
122521              "type": "website"
122522            }
122523          ],
122524          "evidence": {},
122525          "signature": {
122526            "signature": {
122527              "publicKey": {}
122528            }
122529          },
122530          "modelCard": {
122531            "modelParameters": {
122532              "approach": {}
122533            },
122534            "quantitativeAnalysis": {
122535              "graphics": {}
122536            },
122537            "considerations": {}
122538          }
122539        },
122540        {
122541          "type": "library",
122542          "bom-ref": "pkg:npm/npm-bundled@1.1.2?package-id=d3fc92546524f1a0",
122543          "supplier": {},
122544          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
122545          "name": "npm-bundled",
122546          "version": "1.1.2",
122547          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
122548          "licenses": [
122549            {
122550              "license": {
122551                "id": "ISC"
122552              }
122553            }
122554          ],
122555          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:1.1.2:*:*:*:*:*:*:*",
122556          "purl": "pkg:npm/npm-bundled@1.1.2",
122557          "swid": {
122558            "attachment": {}
122559          },
122560          "pedigree": {},
122561          "externalReferences": [
122562            {
122563              "url": "git+https://github.com/npm/npm-bundled.git",
122564              "type": "distribution"
122565            }
122566          ],
122567          "evidence": {},
122568          "signature": {
122569            "signature": {
122570              "publicKey": {}
122571            }
122572          },
122573          "modelCard": {
122574            "modelParameters": {
122575              "approach": {}
122576            },
122577            "quantitativeAnalysis": {
122578              "graphics": {}
122579            },
122580            "considerations": {}
122581          }
122582        },
122583        {
122584          "type": "library",
122585          "bom-ref": "pkg:npm/npm-bundled@2.0.1?package-id=4342e4ccfcb927ca",
122586          "supplier": {},
122587          "author": "GitHub Inc.",
122588          "name": "npm-bundled",
122589          "version": "2.0.1",
122590          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
122591          "licenses": [
122592            {
122593              "license": {
122594                "id": "ISC"
122595              }
122596            }
122597          ],
122598          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:2.0.1:*:*:*:*:*:*:*",
122599          "purl": "pkg:npm/npm-bundled@2.0.1",
122600          "swid": {
122601            "attachment": {}
122602          },
122603          "pedigree": {},
122604          "externalReferences": [
122605            {
122606              "url": "https://github.com/npm/npm-bundled.git",
122607              "type": "distribution"
122608            }
122609          ],
122610          "evidence": {},
122611          "signature": {
122612            "signature": {
122613              "publicKey": {}
122614            }
122615          },
122616          "modelCard": {
122617            "modelParameters": {
122618              "approach": {}
122619            },
122620            "quantitativeAnalysis": {
122621              "graphics": {}
122622            },
122623            "considerations": {}
122624          }
122625        },
122626        {
122627          "type": "library",
122628          "bom-ref": "pkg:npm/npm-init@0.0.0?package-id=e58118b5aaeeedd7",
122629          "supplier": {},
122630          "name": "npm-init",
122631          "version": "0.0.0",
122632          "description": "an initter you init wit, innit?",
122633          "licenses": [
122634            {
122635              "license": {
122636                "name": "BSD"
122637              }
122638            }
122639          ],
122640          "cpe": "cpe:2.3:a:npm-init:npm-init:0.0.0:*:*:*:*:*:*:*",
122641          "purl": "pkg:npm/npm-init@0.0.0",
122642          "swid": {
122643            "attachment": {}
122644          },
122645          "pedigree": {},
122646          "evidence": {},
122647          "signature": {
122648            "signature": {
122649              "publicKey": {}
122650            }
122651          },
122652          "modelCard": {
122653            "modelParameters": {
122654              "approach": {}
122655            },
122656            "quantitativeAnalysis": {
122657              "graphics": {}
122658            },
122659            "considerations": {}
122660          }
122661        },
122662        {
122663          "type": "library",
122664          "bom-ref": "pkg:npm/npm-install-checks@5.0.0?package-id=ea3011565b04383b",
122665          "supplier": {},
122666          "author": "GitHub Inc.",
122667          "name": "npm-install-checks",
122668          "version": "5.0.0",
122669          "description": "Check the engines and platform fields in package.json",
122670          "licenses": [
122671            {
122672              "license": {
122673                "id": "BSD-2-Clause"
122674              }
122675            }
122676          ],
122677          "cpe": "cpe:2.3:a:npm-install-checks:npm-install-checks:5.0.0:*:*:*:*:*:*:*",
122678          "purl": "pkg:npm/npm-install-checks@5.0.0",
122679          "swid": {
122680            "attachment": {}
122681          },
122682          "pedigree": {},
122683          "externalReferences": [
122684            {
122685              "url": "https://github.com/npm/npm-install-checks.git",
122686              "type": "distribution"
122687            }
122688          ],
122689          "evidence": {},
122690          "signature": {
122691            "signature": {
122692              "publicKey": {}
122693            }
122694          },
122695          "modelCard": {
122696            "modelParameters": {
122697              "approach": {}
122698            },
122699            "quantitativeAnalysis": {
122700              "graphics": {}
122701            },
122702            "considerations": {}
122703          }
122704        },
122705        {
122706          "type": "library",
122707          "bom-ref": "pkg:npm/npm-normalize-package-bin@1.0.1?package-id=7cccc2d8907ef9bb",
122708          "supplier": {},
122709          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
122710          "name": "npm-normalize-package-bin",
122711          "version": "1.0.1",
122712          "description": "Turn any flavor of allowable package.json bin into a normalized object",
122713          "licenses": [
122714            {
122715              "license": {
122716                "id": "ISC"
122717              }
122718            }
122719          ],
122720          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:1.0.1:*:*:*:*:*:*:*",
122721          "purl": "pkg:npm/npm-normalize-package-bin@1.0.1",
122722          "swid": {
122723            "attachment": {}
122724          },
122725          "pedigree": {},
122726          "externalReferences": [
122727            {
122728              "url": "git+https://github.com/npm/npm-normalize-package-bin",
122729              "type": "distribution"
122730            }
122731          ],
122732          "evidence": {},
122733          "signature": {
122734            "signature": {
122735              "publicKey": {}
122736            }
122737          },
122738          "modelCard": {
122739            "modelParameters": {
122740              "approach": {}
122741            },
122742            "quantitativeAnalysis": {
122743              "graphics": {}
122744            },
122745            "considerations": {}
122746          }
122747        },
122748        {
122749          "type": "library",
122750          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=3b502df6a54faf04",
122751          "supplier": {},
122752          "author": "GitHub Inc.",
122753          "name": "npm-normalize-package-bin",
122754          "version": "2.0.0",
122755          "description": "Turn any flavor of allowable package.json bin into a normalized object",
122756          "licenses": [
122757            {
122758              "license": {
122759                "id": "ISC"
122760              }
122761            }
122762          ],
122763          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
122764          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
122765          "swid": {
122766            "attachment": {}
122767          },
122768          "pedigree": {},
122769          "externalReferences": [
122770            {
122771              "url": "https://github.com/npm/npm-normalize-package-bin.git",
122772              "type": "distribution"
122773            }
122774          ],
122775          "evidence": {},
122776          "signature": {
122777            "signature": {
122778              "publicKey": {}
122779            }
122780          },
122781          "modelCard": {
122782            "modelParameters": {
122783              "approach": {}
122784            },
122785            "quantitativeAnalysis": {
122786              "graphics": {}
122787            },
122788            "considerations": {}
122789          }
122790        },
122791        {
122792          "type": "library",
122793          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=cb496c88bc54cdd7",
122794          "supplier": {},
122795          "author": "GitHub Inc.",
122796          "name": "npm-normalize-package-bin",
122797          "version": "2.0.0",
122798          "description": "Turn any flavor of allowable package.json bin into a normalized object",
122799          "licenses": [
122800            {
122801              "license": {
122802                "id": "ISC"
122803              }
122804            }
122805          ],
122806          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
122807          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
122808          "swid": {
122809            "attachment": {}
122810          },
122811          "pedigree": {},
122812          "externalReferences": [
122813            {
122814              "url": "https://github.com/npm/npm-normalize-package-bin.git",
122815              "type": "distribution"
122816            }
122817          ],
122818          "evidence": {},
122819          "signature": {
122820            "signature": {
122821              "publicKey": {}
122822            }
122823          },
122824          "modelCard": {
122825            "modelParameters": {
122826              "approach": {}
122827            },
122828            "quantitativeAnalysis": {
122829              "graphics": {}
122830            },
122831            "considerations": {}
122832          }
122833        },
122834        {
122835          "type": "library",
122836          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=3675dcedd841f8b6",
122837          "supplier": {},
122838          "author": "GitHub Inc.",
122839          "name": "npm-normalize-package-bin",
122840          "version": "2.0.0",
122841          "description": "Turn any flavor of allowable package.json bin into a normalized object",
122842          "licenses": [
122843            {
122844              "license": {
122845                "id": "ISC"
122846              }
122847            }
122848          ],
122849          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
122850          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
122851          "swid": {
122852            "attachment": {}
122853          },
122854          "pedigree": {},
122855          "externalReferences": [
122856            {
122857              "url": "https://github.com/npm/npm-normalize-package-bin.git",
122858              "type": "distribution"
122859            }
122860          ],
122861          "evidence": {},
122862          "signature": {
122863            "signature": {
122864              "publicKey": {}
122865            }
122866          },
122867          "modelCard": {
122868            "modelParameters": {
122869              "approach": {}
122870            },
122871            "quantitativeAnalysis": {
122872              "graphics": {}
122873            },
122874            "considerations": {}
122875          }
122876        },
122877        {
122878          "type": "library",
122879          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=a6c4eec149dbad2b",
122880          "supplier": {},
122881          "author": "GitHub Inc.",
122882          "name": "npm-normalize-package-bin",
122883          "version": "2.0.0",
122884          "description": "Turn any flavor of allowable package.json bin into a normalized object",
122885          "licenses": [
122886            {
122887              "license": {
122888                "id": "ISC"
122889              }
122890            }
122891          ],
122892          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
122893          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
122894          "swid": {
122895            "attachment": {}
122896          },
122897          "pedigree": {},
122898          "externalReferences": [
122899            {
122900              "url": "https://github.com/npm/npm-normalize-package-bin.git",
122901              "type": "distribution"
122902            }
122903          ],
122904          "evidence": {},
122905          "signature": {
122906            "signature": {
122907              "publicKey": {}
122908            }
122909          },
122910          "modelCard": {
122911            "modelParameters": {
122912              "approach": {}
122913            },
122914            "quantitativeAnalysis": {
122915              "graphics": {}
122916            },
122917            "considerations": {}
122918          }
122919        },
122920        {
122921          "type": "library",
122922          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=b373bbb7c439b789",
122923          "supplier": {},
122924          "author": "GitHub Inc.",
122925          "name": "npm-normalize-package-bin",
122926          "version": "2.0.0",
122927          "description": "Turn any flavor of allowable package.json bin into a normalized object",
122928          "licenses": [
122929            {
122930              "license": {
122931                "id": "ISC"
122932              }
122933            }
122934          ],
122935          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
122936          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
122937          "swid": {
122938            "attachment": {}
122939          },
122940          "pedigree": {},
122941          "externalReferences": [
122942            {
122943              "url": "https://github.com/npm/npm-normalize-package-bin.git",
122944              "type": "distribution"
122945            }
122946          ],
122947          "evidence": {},
122948          "signature": {
122949            "signature": {
122950              "publicKey": {}
122951            }
122952          },
122953          "modelCard": {
122954            "modelParameters": {
122955              "approach": {}
122956            },
122957            "quantitativeAnalysis": {
122958              "graphics": {}
122959            },
122960            "considerations": {}
122961          }
122962        },
122963        {
122964          "type": "library",
122965          "bom-ref": "pkg:npm/npm-package-arg@9.1.0?package-id=30ebe98710a08c64",
122966          "supplier": {},
122967          "author": "GitHub Inc.",
122968          "name": "npm-package-arg",
122969          "version": "9.1.0",
122970          "description": "Parse the things that can be arguments to `npm install`",
122971          "licenses": [
122972            {
122973              "license": {
122974                "id": "ISC"
122975              }
122976            }
122977          ],
122978          "cpe": "cpe:2.3:a:npm-package-arg:npm-package-arg:9.1.0:*:*:*:*:*:*:*",
122979          "purl": "pkg:npm/npm-package-arg@9.1.0",
122980          "swid": {
122981            "attachment": {}
122982          },
122983          "pedigree": {},
122984          "externalReferences": [
122985            {
122986              "url": "https://github.com/npm/npm-package-arg.git",
122987              "type": "distribution"
122988            },
122989            {
122990              "url": "https://github.com/npm/npm-package-arg",
122991              "type": "website"
122992            }
122993          ],
122994          "evidence": {},
122995          "signature": {
122996            "signature": {
122997              "publicKey": {}
122998            }
122999          },
123000          "modelCard": {
123001            "modelParameters": {
123002              "approach": {}
123003            },
123004            "quantitativeAnalysis": {
123005              "graphics": {}
123006            },
123007            "considerations": {}
123008          }
123009        },
123010        {
123011          "type": "library",
123012          "bom-ref": "pkg:npm/npm-packlist@5.1.3?package-id=e87ec46a213d7a87",
123013          "supplier": {},
123014          "author": "GitHub Inc.",
123015          "name": "npm-packlist",
123016          "version": "5.1.3",
123017          "description": "Get a list of the files to add from a folder into an npm package",
123018          "licenses": [
123019            {
123020              "license": {
123021                "id": "ISC"
123022              }
123023            }
123024          ],
123025          "cpe": "cpe:2.3:a:npm-packlist:npm-packlist:5.1.3:*:*:*:*:*:*:*",
123026          "purl": "pkg:npm/npm-packlist@5.1.3",
123027          "swid": {
123028            "attachment": {}
123029          },
123030          "pedigree": {},
123031          "externalReferences": [
123032            {
123033              "url": "https://github.com/npm/npm-packlist.git",
123034              "type": "distribution"
123035            }
123036          ],
123037          "evidence": {},
123038          "signature": {
123039            "signature": {
123040              "publicKey": {}
123041            }
123042          },
123043          "modelCard": {
123044            "modelParameters": {
123045              "approach": {}
123046            },
123047            "quantitativeAnalysis": {
123048              "graphics": {}
123049            },
123050            "considerations": {}
123051          }
123052        },
123053        {
123054          "type": "library",
123055          "bom-ref": "pkg:npm/npm-pick-manifest@7.0.2?package-id=a9dc194030f7ba31",
123056          "supplier": {},
123057          "author": "GitHub Inc.",
123058          "name": "npm-pick-manifest",
123059          "version": "7.0.2",
123060          "description": "Resolves a matching manifest from a package metadata document according to standard npm semver resolution rules.",
123061          "licenses": [
123062            {
123063              "license": {
123064                "id": "ISC"
123065              }
123066            }
123067          ],
123068          "cpe": "cpe:2.3:a:npm-pick-manifest:npm-pick-manifest:7.0.2:*:*:*:*:*:*:*",
123069          "purl": "pkg:npm/npm-pick-manifest@7.0.2",
123070          "swid": {
123071            "attachment": {}
123072          },
123073          "pedigree": {},
123074          "externalReferences": [
123075            {
123076              "url": "https://github.com/npm/npm-pick-manifest.git",
123077              "type": "distribution"
123078            }
123079          ],
123080          "evidence": {},
123081          "signature": {
123082            "signature": {
123083              "publicKey": {}
123084            }
123085          },
123086          "modelCard": {
123087            "modelParameters": {
123088              "approach": {}
123089            },
123090            "quantitativeAnalysis": {
123091              "graphics": {}
123092            },
123093            "considerations": {}
123094          }
123095        },
123096        {
123097          "type": "library",
123098          "bom-ref": "pkg:npm/npm-profile@6.2.1?package-id=4b7db9f7ec8bd8ec",
123099          "supplier": {},
123100          "author": "GitHub Inc.",
123101          "name": "npm-profile",
123102          "version": "6.2.1",
123103          "description": "Library for updating an npmjs.com profile",
123104          "licenses": [
123105            {
123106              "license": {
123107                "id": "ISC"
123108              }
123109            }
123110          ],
123111          "cpe": "cpe:2.3:a:npm-profile:npm-profile:6.2.1:*:*:*:*:*:*:*",
123112          "purl": "pkg:npm/npm-profile@6.2.1",
123113          "swid": {
123114            "attachment": {}
123115          },
123116          "pedigree": {},
123117          "externalReferences": [
123118            {
123119              "url": "https://github.com/npm/npm-profile.git",
123120              "type": "distribution"
123121            }
123122          ],
123123          "evidence": {},
123124          "signature": {
123125            "signature": {
123126              "publicKey": {}
123127            }
123128          },
123129          "modelCard": {
123130            "modelParameters": {
123131              "approach": {}
123132            },
123133            "quantitativeAnalysis": {
123134              "graphics": {}
123135            },
123136            "considerations": {}
123137          }
123138        },
123139        {
123140          "type": "library",
123141          "bom-ref": "pkg:npm/npm-registry-fetch@13.3.1?package-id=4a24a52ce2bed90",
123142          "supplier": {},
123143          "author": "GitHub Inc.",
123144          "name": "npm-registry-fetch",
123145          "version": "13.3.1",
123146          "description": "Fetch-based http client for use with npm registry APIs",
123147          "licenses": [
123148            {
123149              "license": {
123150                "id": "ISC"
123151              }
123152            }
123153          ],
123154          "cpe": "cpe:2.3:a:npm-registry-fetch:npm-registry-fetch:13.3.1:*:*:*:*:*:*:*",
123155          "purl": "pkg:npm/npm-registry-fetch@13.3.1",
123156          "swid": {
123157            "attachment": {}
123158          },
123159          "pedigree": {},
123160          "externalReferences": [
123161            {
123162              "url": "https://github.com/npm/npm-registry-fetch.git",
123163              "type": "distribution"
123164            }
123165          ],
123166          "evidence": {},
123167          "signature": {
123168            "signature": {
123169              "publicKey": {}
123170            }
123171          },
123172          "modelCard": {
123173            "modelParameters": {
123174              "approach": {}
123175            },
123176            "quantitativeAnalysis": {
123177              "graphics": {}
123178            },
123179            "considerations": {}
123180          }
123181        },
123182        {
123183          "type": "library",
123184          "bom-ref": "pkg:npm/npm-user-validate@1.0.1?package-id=6154858fa52c8fec",
123185          "supplier": {},
123186          "author": "Robert Kowalski \u003crok@kowalski.gd\u003e",
123187          "name": "npm-user-validate",
123188          "version": "1.0.1",
123189          "description": "User validations for npm",
123190          "licenses": [
123191            {
123192              "license": {
123193                "id": "BSD-2-Clause"
123194              }
123195            }
123196          ],
123197          "cpe": "cpe:2.3:a:npm-user-validate:npm-user-validate:1.0.1:*:*:*:*:*:*:*",
123198          "purl": "pkg:npm/npm-user-validate@1.0.1",
123199          "swid": {
123200            "attachment": {}
123201          },
123202          "pedigree": {},
123203          "externalReferences": [
123204            {
123205              "url": "git://github.com/npm/npm-user-validate.git",
123206              "type": "distribution"
123207            }
123208          ],
123209          "evidence": {},
123210          "signature": {
123211            "signature": {
123212              "publicKey": {}
123213            }
123214          },
123215          "modelCard": {
123216            "modelParameters": {
123217              "approach": {}
123218            },
123219            "quantitativeAnalysis": {
123220              "graphics": {}
123221            },
123222            "considerations": {}
123223          }
123224        },
123225        {
123226          "type": "library",
123227          "bom-ref": "pkg:npm/npmlog@6.0.2?package-id=e1d7f39551f111f",
123228          "supplier": {},
123229          "author": "GitHub Inc.",
123230          "name": "npmlog",
123231          "version": "6.0.2",
123232          "description": "logger for npm",
123233          "licenses": [
123234            {
123235              "license": {
123236                "id": "ISC"
123237              }
123238            }
123239          ],
123240          "cpe": "cpe:2.3:a:npmlog:npmlog:6.0.2:*:*:*:*:*:*:*",
123241          "purl": "pkg:npm/npmlog@6.0.2",
123242          "swid": {
123243            "attachment": {}
123244          },
123245          "pedigree": {},
123246          "externalReferences": [
123247            {
123248              "url": "https://github.com/npm/npmlog.git",
123249              "type": "distribution"
123250            }
123251          ],
123252          "evidence": {},
123253          "signature": {
123254            "signature": {
123255              "publicKey": {}
123256            }
123257          },
123258          "modelCard": {
123259            "modelParameters": {
123260              "approach": {}
123261            },
123262            "quantitativeAnalysis": {
123263              "graphics": {}
123264            },
123265            "considerations": {}
123266          }
123267        },
123268        {
123269          "type": "library",
123270          "bom-ref": "pkg:npm/once@1.4.0?package-id=6a66d209255e8adb",
123271          "supplier": {},
123272          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
123273          "name": "once",
123274          "version": "1.4.0",
123275          "description": "Run a function exactly one time",
123276          "licenses": [
123277            {
123278              "license": {
123279                "id": "ISC"
123280              }
123281            }
123282          ],
123283          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
123284          "purl": "pkg:npm/once@1.4.0",
123285          "swid": {
123286            "attachment": {}
123287          },
123288          "pedigree": {},
123289          "externalReferences": [
123290            {
123291              "url": "git://github.com/isaacs/once",
123292              "type": "distribution"
123293            }
123294          ],
123295          "evidence": {},
123296          "signature": {
123297            "signature": {
123298              "publicKey": {}
123299            }
123300          },
123301          "modelCard": {
123302            "modelParameters": {
123303              "approach": {}
123304            },
123305            "quantitativeAnalysis": {
123306              "graphics": {}
123307            },
123308            "considerations": {}
123309          }
123310        },
123311        {
123312          "type": "library",
123313          "bom-ref": "pkg:npm/once@1.4.0?package-id=2bfb1efabaee8e52",
123314          "supplier": {},
123315          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
123316          "name": "once",
123317          "version": "1.4.0",
123318          "description": "Run a function exactly one time",
123319          "licenses": [
123320            {
123321              "license": {
123322                "id": "ISC"
123323              }
123324            }
123325          ],
123326          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
123327          "purl": "pkg:npm/once@1.4.0",
123328          "swid": {
123329            "attachment": {}
123330          },
123331          "pedigree": {},
123332          "externalReferences": [
123333            {
123334              "url": "git://github.com/isaacs/once",
123335              "type": "distribution"
123336            }
123337          ],
123338          "evidence": {},
123339          "signature": {
123340            "signature": {
123341              "publicKey": {}
123342            }
123343          },
123344          "modelCard": {
123345            "modelParameters": {
123346              "approach": {}
123347            },
123348            "quantitativeAnalysis": {
123349              "graphics": {}
123350            },
123351            "considerations": {}
123352          }
123353        },
123354        {
123355          "type": "library",
123356          "bom-ref": "pkg:npm/opener@1.5.2?package-id=44a3614f9f359ab5",
123357          "supplier": {},
123358          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me/)",
123359          "name": "opener",
123360          "version": "1.5.2",
123361          "description": "Opens stuff, like webpages and files and executables, cross-platform",
123362          "licenses": [
123363            {
123364              "license": {
123365                "name": "(WTFPL OR MIT)"
123366              }
123367            }
123368          ],
123369          "cpe": "cpe:2.3:a:opener:opener:1.5.2:*:*:*:*:*:*:*",
123370          "purl": "pkg:npm/opener@1.5.2",
123371          "swid": {
123372            "attachment": {}
123373          },
123374          "pedigree": {},
123375          "externalReferences": [
123376            {
123377              "url": "domenic/opener",
123378              "type": "distribution"
123379            }
123380          ],
123381          "evidence": {},
123382          "signature": {
123383            "signature": {
123384              "publicKey": {}
123385            }
123386          },
123387          "modelCard": {
123388            "modelParameters": {
123389              "approach": {}
123390            },
123391            "quantitativeAnalysis": {
123392              "graphics": {}
123393            },
123394            "considerations": {}
123395          }
123396        },
123397        {
123398          "type": "library",
123399          "bom-ref": "pkg:npm/p-map@4.0.0?package-id=1c07a8cbe4bd91d5",
123400          "supplier": {},
123401          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
123402          "name": "p-map",
123403          "version": "4.0.0",
123404          "description": "Map over promises concurrently",
123405          "licenses": [
123406            {
123407              "license": {
123408                "id": "MIT"
123409              }
123410            }
123411          ],
123412          "cpe": "cpe:2.3:a:p-map:p-map:4.0.0:*:*:*:*:*:*:*",
123413          "purl": "pkg:npm/p-map@4.0.0",
123414          "swid": {
123415            "attachment": {}
123416          },
123417          "pedigree": {},
123418          "externalReferences": [
123419            {
123420              "url": "sindresorhus/p-map",
123421              "type": "distribution"
123422            }
123423          ],
123424          "evidence": {},
123425          "signature": {
123426            "signature": {
123427              "publicKey": {}
123428            }
123429          },
123430          "modelCard": {
123431            "modelParameters": {
123432              "approach": {}
123433            },
123434            "quantitativeAnalysis": {
123435              "graphics": {}
123436            },
123437            "considerations": {}
123438          }
123439        },
123440        {
123441          "type": "library",
123442          "bom-ref": "pkg:npm/pacote@13.6.2?package-id=481670a57d8719a5",
123443          "supplier": {},
123444          "author": "GitHub Inc.",
123445          "name": "pacote",
123446          "version": "13.6.2",
123447          "description": "JavaScript package downloader",
123448          "licenses": [
123449            {
123450              "license": {
123451                "id": "ISC"
123452              }
123453            }
123454          ],
123455          "cpe": "cpe:2.3:a:pacote:pacote:13.6.2:*:*:*:*:*:*:*",
123456          "purl": "pkg:npm/pacote@13.6.2",
123457          "swid": {
123458            "attachment": {}
123459          },
123460          "pedigree": {},
123461          "externalReferences": [
123462            {
123463              "url": "https://github.com/npm/pacote.git",
123464              "type": "distribution"
123465            }
123466          ],
123467          "evidence": {},
123468          "signature": {
123469            "signature": {
123470              "publicKey": {}
123471            }
123472          },
123473          "modelCard": {
123474            "modelParameters": {
123475              "approach": {}
123476            },
123477            "quantitativeAnalysis": {
123478              "graphics": {}
123479            },
123480            "considerations": {}
123481          }
123482        },
123483        {
123484          "type": "library",
123485          "bom-ref": "pkg:npm/parse-conflict-json@2.0.2?package-id=94638d4f43f17ad7",
123486          "supplier": {},
123487          "author": "GitHub Inc.",
123488          "name": "parse-conflict-json",
123489          "version": "2.0.2",
123490          "description": "Parse a JSON string that has git merge conflicts, resolving if possible",
123491          "licenses": [
123492            {
123493              "license": {
123494                "id": "ISC"
123495              }
123496            }
123497          ],
123498          "cpe": "cpe:2.3:a:parse-conflict-json:parse-conflict-json:2.0.2:*:*:*:*:*:*:*",
123499          "purl": "pkg:npm/parse-conflict-json@2.0.2",
123500          "swid": {
123501            "attachment": {}
123502          },
123503          "pedigree": {},
123504          "externalReferences": [
123505            {
123506              "url": "https://github.com/npm/parse-conflict-json.git",
123507              "type": "distribution"
123508            }
123509          ],
123510          "evidence": {},
123511          "signature": {
123512            "signature": {
123513              "publicKey": {}
123514            }
123515          },
123516          "modelCard": {
123517            "modelParameters": {
123518              "approach": {}
123519            },
123520            "quantitativeAnalysis": {
123521              "graphics": {}
123522            },
123523            "considerations": {}
123524          }
123525        },
123526        {
123527          "type": "library",
123528          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=ed58648f2f773bd9",
123529          "supplier": {},
123530          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
123531          "name": "path-is-absolute",
123532          "version": "1.0.1",
123533          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
123534          "licenses": [
123535            {
123536              "license": {
123537                "id": "MIT"
123538              }
123539            }
123540          ],
123541          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
123542          "purl": "pkg:npm/path-is-absolute@1.0.1",
123543          "swid": {
123544            "attachment": {}
123545          },
123546          "pedigree": {},
123547          "externalReferences": [
123548            {
123549              "url": "sindresorhus/path-is-absolute",
123550              "type": "distribution"
123551            }
123552          ],
123553          "evidence": {},
123554          "signature": {
123555            "signature": {
123556              "publicKey": {}
123557            }
123558          },
123559          "modelCard": {
123560            "modelParameters": {
123561              "approach": {}
123562            },
123563            "quantitativeAnalysis": {
123564              "graphics": {}
123565            },
123566            "considerations": {}
123567          }
123568        },
123569        {
123570          "type": "library",
123571          "bom-ref": "pkg:npm/postcss-selector-parser@6.0.10?package-id=29dd6871004e9325",
123572          "supplier": {},
123573          "name": "postcss-selector-parser",
123574          "version": "6.0.10",
123575          "licenses": [
123576            {
123577              "license": {
123578                "id": "MIT"
123579              }
123580            }
123581          ],
123582          "cpe": "cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:6.0.10:*:*:*:*:*:*:*",
123583          "purl": "pkg:npm/postcss-selector-parser@6.0.10",
123584          "swid": {
123585            "attachment": {}
123586          },
123587          "pedigree": {},
123588          "externalReferences": [
123589            {
123590              "url": "postcss/postcss-selector-parser",
123591              "type": "distribution"
123592            },
123593            {
123594              "url": "https://github.com/postcss/postcss-selector-parser",
123595              "type": "website"
123596            }
123597          ],
123598          "evidence": {},
123599          "signature": {
123600            "signature": {
123601              "publicKey": {}
123602            }
123603          },
123604          "modelCard": {
123605            "modelParameters": {
123606              "approach": {}
123607            },
123608            "quantitativeAnalysis": {
123609              "graphics": {}
123610            },
123611            "considerations": {}
123612          }
123613        },
123614        {
123615          "type": "library",
123616          "bom-ref": "pkg:npm/proc-log@2.0.1?package-id=a4591425ab5edc60",
123617          "supplier": {},
123618          "author": "GitHub Inc.",
123619          "name": "proc-log",
123620          "version": "2.0.1",
123621          "description": "just emit 'log' events on the process object",
123622          "licenses": [
123623            {
123624              "license": {
123625                "id": "ISC"
123626              }
123627            }
123628          ],
123629          "cpe": "cpe:2.3:a:proc-log:proc-log:2.0.1:*:*:*:*:*:*:*",
123630          "purl": "pkg:npm/proc-log@2.0.1",
123631          "swid": {
123632            "attachment": {}
123633          },
123634          "pedigree": {},
123635          "externalReferences": [
123636            {
123637              "url": "https://github.com/npm/proc-log.git",
123638              "type": "distribution"
123639            }
123640          ],
123641          "evidence": {},
123642          "signature": {
123643            "signature": {
123644              "publicKey": {}
123645            }
123646          },
123647          "modelCard": {
123648            "modelParameters": {
123649              "approach": {}
123650            },
123651            "quantitativeAnalysis": {
123652              "graphics": {}
123653            },
123654            "considerations": {}
123655          }
123656        },
123657        {
123658          "type": "library",
123659          "bom-ref": "pkg:npm/process-nextick-args@2.0.1?package-id=e40e9e1f49dce12f",
123660          "supplier": {},
123661          "name": "process-nextick-args",
123662          "version": "2.0.1",
123663          "description": "process.nextTick but always with args",
123664          "licenses": [
123665            {
123666              "license": {
123667                "id": "MIT"
123668              }
123669            }
123670          ],
123671          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.1:*:*:*:*:*:*:*",
123672          "purl": "pkg:npm/process-nextick-args@2.0.1",
123673          "swid": {
123674            "attachment": {}
123675          },
123676          "pedigree": {},
123677          "externalReferences": [
123678            {
123679              "url": "https://github.com/calvinmetcalf/process-nextick-args.git",
123680              "type": "distribution"
123681            },
123682            {
123683              "url": "https://github.com/calvinmetcalf/process-nextick-args",
123684              "type": "website"
123685            }
123686          ],
123687          "evidence": {},
123688          "signature": {
123689            "signature": {
123690              "publicKey": {}
123691            }
123692          },
123693          "modelCard": {
123694            "modelParameters": {
123695              "approach": {}
123696            },
123697            "quantitativeAnalysis": {
123698              "graphics": {}
123699            },
123700            "considerations": {}
123701          }
123702        },
123703        {
123704          "type": "library",
123705          "bom-ref": "pkg:npm/promise-all-reject-late@1.0.1?package-id=7b92ff8460614d4f",
123706          "supplier": {},
123707          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
123708          "name": "promise-all-reject-late",
123709          "version": "1.0.1",
123710          "description": "Like Promise.all, but save rejections until all promises are resolved",
123711          "licenses": [
123712            {
123713              "license": {
123714                "id": "ISC"
123715              }
123716            }
123717          ],
123718          "cpe": "cpe:2.3:a:promise-all-reject-late:promise-all-reject-late:1.0.1:*:*:*:*:*:*:*",
123719          "purl": "pkg:npm/promise-all-reject-late@1.0.1",
123720          "swid": {
123721            "attachment": {}
123722          },
123723          "pedigree": {},
123724          "evidence": {},
123725          "signature": {
123726            "signature": {
123727              "publicKey": {}
123728            }
123729          },
123730          "modelCard": {
123731            "modelParameters": {
123732              "approach": {}
123733            },
123734            "quantitativeAnalysis": {
123735              "graphics": {}
123736            },
123737            "considerations": {}
123738          }
123739        },
123740        {
123741          "type": "library",
123742          "bom-ref": "pkg:npm/promise-call-limit@1.0.1?package-id=2b0b41bd7b0aa502",
123743          "supplier": {},
123744          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
123745          "name": "promise-call-limit",
123746          "version": "1.0.1",
123747          "description": "Call an array of promise-returning functions, restricting concurrency to a specified limit.",
123748          "licenses": [
123749            {
123750              "license": {
123751                "id": "ISC"
123752              }
123753            }
123754          ],
123755          "cpe": "cpe:2.3:a:promise-call-limit:promise-call-limit:1.0.1:*:*:*:*:*:*:*",
123756          "purl": "pkg:npm/promise-call-limit@1.0.1",
123757          "swid": {
123758            "attachment": {}
123759          },
123760          "pedigree": {},
123761          "externalReferences": [
123762            {
123763              "url": "git+https://github.com/isaacs/promise-call-limit",
123764              "type": "distribution"
123765            }
123766          ],
123767          "evidence": {},
123768          "signature": {
123769            "signature": {
123770              "publicKey": {}
123771            }
123772          },
123773          "modelCard": {
123774            "modelParameters": {
123775              "approach": {}
123776            },
123777            "quantitativeAnalysis": {
123778              "graphics": {}
123779            },
123780            "considerations": {}
123781          }
123782        },
123783        {
123784          "type": "library",
123785          "bom-ref": "pkg:npm/promise-inflight@1.0.1?package-id=8ae6caef1e6290fe",
123786          "supplier": {},
123787          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
123788          "name": "promise-inflight",
123789          "version": "1.0.1",
123790          "description": "One promise for multiple requests in flight to avoid async duplication",
123791          "licenses": [
123792            {
123793              "license": {
123794                "id": "ISC"
123795              }
123796            }
123797          ],
123798          "cpe": "cpe:2.3:a:promise-inflight:promise-inflight:1.0.1:*:*:*:*:*:*:*",
123799          "purl": "pkg:npm/promise-inflight@1.0.1",
123800          "swid": {
123801            "attachment": {}
123802          },
123803          "pedigree": {},
123804          "externalReferences": [
123805            {
123806              "url": "git+https://github.com/iarna/promise-inflight.git",
123807              "type": "distribution"
123808            },
123809            {
123810              "url": "https://github.com/iarna/promise-inflight#readme",
123811              "type": "website"
123812            }
123813          ],
123814          "evidence": {},
123815          "signature": {
123816            "signature": {
123817              "publicKey": {}
123818            }
123819          },
123820          "modelCard": {
123821            "modelParameters": {
123822              "approach": {}
123823            },
123824            "quantitativeAnalysis": {
123825              "graphics": {}
123826            },
123827            "considerations": {}
123828          }
123829        },
123830        {
123831          "type": "library",
123832          "bom-ref": "pkg:npm/promise-retry@2.0.1?package-id=7d483cd4a8ed637e",
123833          "supplier": {},
123834          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
123835          "name": "promise-retry",
123836          "version": "2.0.1",
123837          "description": "Retries a function that returns a promise, leveraging the power of the retry module.",
123838          "licenses": [
123839            {
123840              "license": {
123841                "id": "MIT"
123842              }
123843            }
123844          ],
123845          "cpe": "cpe:2.3:a:promise-retry:promise-retry:2.0.1:*:*:*:*:*:*:*",
123846          "purl": "pkg:npm/promise-retry@2.0.1",
123847          "swid": {
123848            "attachment": {}
123849          },
123850          "pedigree": {},
123851          "externalReferences": [
123852            {
123853              "url": "git://github.com/IndigoUnited/node-promise-retry.git",
123854              "type": "distribution"
123855            }
123856          ],
123857          "evidence": {},
123858          "signature": {
123859            "signature": {
123860              "publicKey": {}
123861            }
123862          },
123863          "modelCard": {
123864            "modelParameters": {
123865              "approach": {}
123866            },
123867            "quantitativeAnalysis": {
123868              "graphics": {}
123869            },
123870            "considerations": {}
123871          }
123872        },
123873        {
123874          "type": "library",
123875          "bom-ref": "pkg:npm/promzard@0.3.0?package-id=33cefe299422041",
123876          "supplier": {},
123877          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
123878          "name": "promzard",
123879          "version": "0.3.0",
123880          "description": "prompting wizardly",
123881          "licenses": [
123882            {
123883              "license": {
123884                "id": "ISC"
123885              }
123886            }
123887          ],
123888          "cpe": "cpe:2.3:a:promzard:promzard:0.3.0:*:*:*:*:*:*:*",
123889          "purl": "pkg:npm/promzard@0.3.0",
123890          "swid": {
123891            "attachment": {}
123892          },
123893          "pedigree": {},
123894          "externalReferences": [
123895            {
123896              "url": "git://github.com/isaacs/promzard",
123897              "type": "distribution"
123898            }
123899          ],
123900          "evidence": {},
123901          "signature": {
123902            "signature": {
123903              "publicKey": {}
123904            }
123905          },
123906          "modelCard": {
123907            "modelParameters": {
123908              "approach": {}
123909            },
123910            "quantitativeAnalysis": {
123911              "graphics": {}
123912            },
123913            "considerations": {}
123914          }
123915        },
123916        {
123917          "type": "library",
123918          "bom-ref": "pkg:npm/pump@3.0.0?package-id=42f972f5e9e52299",
123919          "supplier": {},
123920          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
123921          "name": "pump",
123922          "version": "3.0.0",
123923          "description": "pipe streams together and close all of them if one of them closes",
123924          "licenses": [
123925            {
123926              "license": {
123927                "id": "MIT"
123928              }
123929            }
123930          ],
123931          "cpe": "cpe:2.3:a:mafintosh:pump:3.0.0:*:*:*:*:*:*:*",
123932          "purl": "pkg:npm/pump@3.0.0",
123933          "swid": {
123934            "attachment": {}
123935          },
123936          "pedigree": {},
123937          "externalReferences": [
123938            {
123939              "url": "git://github.com/mafintosh/pump.git",
123940              "type": "distribution"
123941            }
123942          ],
123943          "evidence": {},
123944          "signature": {
123945            "signature": {
123946              "publicKey": {}
123947            }
123948          },
123949          "modelCard": {
123950            "modelParameters": {
123951              "approach": {}
123952            },
123953            "quantitativeAnalysis": {
123954              "graphics": {}
123955            },
123956            "considerations": {}
123957          }
123958        },
123959        {
123960          "type": "library",
123961          "bom-ref": "pkg:npm/qrcode-terminal@0.12.0?package-id=83c91f496595f73",
123962          "supplier": {},
123963          "name": "qrcode-terminal",
123964          "version": "0.12.0",
123965          "description": "QRCodes, in the terminal",
123966          "licenses": [
123967            {
123968              "license": {
123969                "name": "Apache 2.0"
123970              }
123971            }
123972          ],
123973          "cpe": "cpe:2.3:a:qrcode-terminal:qrcode-terminal:0.12.0:*:*:*:*:*:*:*",
123974          "purl": "pkg:npm/qrcode-terminal@0.12.0",
123975          "swid": {
123976            "attachment": {}
123977          },
123978          "pedigree": {},
123979          "externalReferences": [
123980            {
123981              "url": "https://github.com/gtanner/qrcode-terminal",
123982              "type": "distribution"
123983            },
123984            {
123985              "url": "https://github.com/gtanner/qrcode-terminal",
123986              "type": "website"
123987            }
123988          ],
123989          "evidence": {},
123990          "signature": {
123991            "signature": {
123992              "publicKey": {}
123993            }
123994          },
123995          "modelCard": {
123996            "modelParameters": {
123997              "approach": {}
123998            },
123999            "quantitativeAnalysis": {
124000              "graphics": {}
124001            },
124002            "considerations": {}
124003          }
124004        },
124005        {
124006          "type": "library",
124007          "bom-ref": "pkg:npm/read@1.0.7?package-id=cf65e05575a1a15",
124008          "supplier": {},
124009          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
124010          "name": "read",
124011          "version": "1.0.7",
124012          "description": "read(1) for node programs",
124013          "licenses": [
124014            {
124015              "license": {
124016                "id": "ISC"
124017              }
124018            }
124019          ],
124020          "cpe": "cpe:2.3:a:isaacs:read:1.0.7:*:*:*:*:*:*:*",
124021          "purl": "pkg:npm/read@1.0.7",
124022          "swid": {
124023            "attachment": {}
124024          },
124025          "pedigree": {},
124026          "externalReferences": [
124027            {
124028              "url": "git://github.com/isaacs/read.git",
124029              "type": "distribution"
124030            }
124031          ],
124032          "evidence": {},
124033          "signature": {
124034            "signature": {
124035              "publicKey": {}
124036            }
124037          },
124038          "modelCard": {
124039            "modelParameters": {
124040              "approach": {}
124041            },
124042            "quantitativeAnalysis": {
124043              "graphics": {}
124044            },
124045            "considerations": {}
124046          }
124047        },
124048        {
124049          "type": "library",
124050          "bom-ref": "pkg:npm/read-cmd-shim@3.0.0?package-id=4b927be3f703982b",
124051          "supplier": {},
124052          "author": "GitHub Inc.",
124053          "name": "read-cmd-shim",
124054          "version": "3.0.0",
124055          "description": "Figure out what a cmd-shim is pointing at. This acts as the equivalent of fs.readlink.",
124056          "licenses": [
124057            {
124058              "license": {
124059                "id": "ISC"
124060              }
124061            }
124062          ],
124063          "cpe": "cpe:2.3:a:read-cmd-shim:read-cmd-shim:3.0.0:*:*:*:*:*:*:*",
124064          "purl": "pkg:npm/read-cmd-shim@3.0.0",
124065          "swid": {
124066            "attachment": {}
124067          },
124068          "pedigree": {},
124069          "externalReferences": [
124070            {
124071              "url": "https://github.com/npm/read-cmd-shim.git",
124072              "type": "distribution"
124073            },
124074            {
124075              "url": "https://github.com/npm/read-cmd-shim#readme",
124076              "type": "website"
124077            }
124078          ],
124079          "evidence": {},
124080          "signature": {
124081            "signature": {
124082              "publicKey": {}
124083            }
124084          },
124085          "modelCard": {
124086            "modelParameters": {
124087              "approach": {}
124088            },
124089            "quantitativeAnalysis": {
124090              "graphics": {}
124091            },
124092            "considerations": {}
124093          }
124094        },
124095        {
124096          "type": "library",
124097          "bom-ref": "pkg:npm/read-package-json@5.0.2?package-id=d15e27cd5cddf2b4",
124098          "supplier": {},
124099          "author": "GitHub Inc.",
124100          "name": "read-package-json",
124101          "version": "5.0.2",
124102          "description": "The thing npm uses to read package.json files with semantics and defaults and validation",
124103          "licenses": [
124104            {
124105              "license": {
124106                "id": "ISC"
124107              }
124108            }
124109          ],
124110          "cpe": "cpe:2.3:a:read-package-json:read-package-json:5.0.2:*:*:*:*:*:*:*",
124111          "purl": "pkg:npm/read-package-json@5.0.2",
124112          "swid": {
124113            "attachment": {}
124114          },
124115          "pedigree": {},
124116          "externalReferences": [
124117            {
124118              "url": "https://github.com/npm/read-package-json.git",
124119              "type": "distribution"
124120            }
124121          ],
124122          "evidence": {},
124123          "signature": {
124124            "signature": {
124125              "publicKey": {}
124126            }
124127          },
124128          "modelCard": {
124129            "modelParameters": {
124130              "approach": {}
124131            },
124132            "quantitativeAnalysis": {
124133              "graphics": {}
124134            },
124135            "considerations": {}
124136          }
124137        },
124138        {
124139          "type": "library",
124140          "bom-ref": "pkg:npm/read-package-json-fast@2.0.3?package-id=bb9e08c93f4b4c89",
124141          "supplier": {},
124142          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
124143          "name": "read-package-json-fast",
124144          "version": "2.0.3",
124145          "description": "Like read-package-json, but faster",
124146          "licenses": [
124147            {
124148              "license": {
124149                "id": "ISC"
124150              }
124151            }
124152          ],
124153          "cpe": "cpe:2.3:a:read-package-json-fast:read-package-json-fast:2.0.3:*:*:*:*:*:*:*",
124154          "purl": "pkg:npm/read-package-json-fast@2.0.3",
124155          "swid": {
124156            "attachment": {}
124157          },
124158          "pedigree": {},
124159          "externalReferences": [
124160            {
124161              "url": "git+https://github.com/npm/read-package-json-fast.git",
124162              "type": "distribution"
124163            }
124164          ],
124165          "evidence": {},
124166          "signature": {
124167            "signature": {
124168              "publicKey": {}
124169            }
124170          },
124171          "modelCard": {
124172            "modelParameters": {
124173              "approach": {}
124174            },
124175            "quantitativeAnalysis": {
124176              "graphics": {}
124177            },
124178            "considerations": {}
124179          }
124180        },
124181        {
124182          "type": "library",
124183          "bom-ref": "pkg:npm/readable-stream@2.3.7?package-id=515a8af3a698c35",
124184          "supplier": {},
124185          "name": "readable-stream",
124186          "version": "2.3.7",
124187          "description": "Streams3, a user-land copy of the stream library from Node.js",
124188          "licenses": [
124189            {
124190              "license": {
124191                "id": "MIT"
124192              }
124193            }
124194          ],
124195          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.7:*:*:*:*:*:*:*",
124196          "purl": "pkg:npm/readable-stream@2.3.7",
124197          "swid": {
124198            "attachment": {}
124199          },
124200          "pedigree": {},
124201          "externalReferences": [
124202            {
124203              "url": "git://github.com/nodejs/readable-stream",
124204              "type": "distribution"
124205            }
124206          ],
124207          "evidence": {},
124208          "signature": {
124209            "signature": {
124210              "publicKey": {}
124211            }
124212          },
124213          "modelCard": {
124214            "modelParameters": {
124215              "approach": {}
124216            },
124217            "quantitativeAnalysis": {
124218              "graphics": {}
124219            },
124220            "considerations": {}
124221          }
124222        },
124223        {
124224          "type": "library",
124225          "bom-ref": "pkg:npm/readable-stream@2.3.7?package-id=2379aec81d6162c3",
124226          "supplier": {},
124227          "name": "readable-stream",
124228          "version": "2.3.7",
124229          "description": "Streams3, a user-land copy of the stream library from Node.js",
124230          "licenses": [
124231            {
124232              "license": {
124233                "id": "MIT"
124234              }
124235            }
124236          ],
124237          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.7:*:*:*:*:*:*:*",
124238          "purl": "pkg:npm/readable-stream@2.3.7",
124239          "swid": {
124240            "attachment": {}
124241          },
124242          "pedigree": {},
124243          "externalReferences": [
124244            {
124245              "url": "git://github.com/nodejs/readable-stream",
124246              "type": "distribution"
124247            }
124248          ],
124249          "evidence": {},
124250          "signature": {
124251            "signature": {
124252              "publicKey": {}
124253            }
124254          },
124255          "modelCard": {
124256            "modelParameters": {
124257              "approach": {}
124258            },
124259            "quantitativeAnalysis": {
124260              "graphics": {}
124261            },
124262            "considerations": {}
124263          }
124264        },
124265        {
124266          "type": "library",
124267          "bom-ref": "pkg:npm/readable-stream@3.6.0?package-id=32d9c32dd3126020",
124268          "supplier": {},
124269          "name": "readable-stream",
124270          "version": "3.6.0",
124271          "description": "Streams3, a user-land copy of the stream library from Node.js",
124272          "licenses": [
124273            {
124274              "license": {
124275                "id": "MIT"
124276              }
124277            }
124278          ],
124279          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.0:*:*:*:*:*:*:*",
124280          "purl": "pkg:npm/readable-stream@3.6.0",
124281          "swid": {
124282            "attachment": {}
124283          },
124284          "pedigree": {},
124285          "externalReferences": [
124286            {
124287              "url": "git://github.com/nodejs/readable-stream",
124288              "type": "distribution"
124289            }
124290          ],
124291          "evidence": {},
124292          "signature": {
124293            "signature": {
124294              "publicKey": {}
124295            }
124296          },
124297          "modelCard": {
124298            "modelParameters": {
124299              "approach": {}
124300            },
124301            "quantitativeAnalysis": {
124302              "graphics": {}
124303            },
124304            "considerations": {}
124305          }
124306        },
124307        {
124308          "type": "library",
124309          "bom-ref": "pkg:npm/readdir-scoped-modules@1.1.0?package-id=33ac24742869be8b",
124310          "supplier": {},
124311          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
124312          "name": "readdir-scoped-modules",
124313          "version": "1.1.0",
124314          "description": "Like `fs.readdir` but handling `@org/module` dirs as if they were a single entry.",
124315          "licenses": [
124316            {
124317              "license": {
124318                "id": "ISC"
124319              }
124320            }
124321          ],
124322          "cpe": "cpe:2.3:a:readdir-scoped-modules:readdir-scoped-modules:1.1.0:*:*:*:*:*:*:*",
124323          "purl": "pkg:npm/readdir-scoped-modules@1.1.0",
124324          "swid": {
124325            "attachment": {}
124326          },
124327          "pedigree": {},
124328          "externalReferences": [
124329            {
124330              "url": "https://github.com/npm/readdir-scoped-modules",
124331              "type": "distribution"
124332            },
124333            {
124334              "url": "https://github.com/npm/readdir-scoped-modules",
124335              "type": "website"
124336            }
124337          ],
124338          "evidence": {},
124339          "signature": {
124340            "signature": {
124341              "publicKey": {}
124342            }
124343          },
124344          "modelCard": {
124345            "modelParameters": {
124346              "approach": {}
124347            },
124348            "quantitativeAnalysis": {
124349              "graphics": {}
124350            },
124351            "considerations": {}
124352          }
124353        },
124354        {
124355          "type": "library",
124356          "bom-ref": "pkg:npm/retry@0.12.0?package-id=c3f319915fd297ec",
124357          "supplier": {},
124358          "author": "Tim Koschützki \u003ctim@debuggable.com\u003e (http://debuggable.com/)",
124359          "name": "retry",
124360          "version": "0.12.0",
124361          "description": "Abstraction for exponential and custom retry strategies for failed operations.",
124362          "licenses": [
124363            {
124364              "license": {
124365                "id": "MIT"
124366              }
124367            }
124368          ],
124369          "cpe": "cpe:2.3:a:tim-kos:retry:0.12.0:*:*:*:*:*:*:*",
124370          "purl": "pkg:npm/retry@0.12.0",
124371          "swid": {
124372            "attachment": {}
124373          },
124374          "pedigree": {},
124375          "externalReferences": [
124376            {
124377              "url": "git://github.com/tim-kos/node-retry.git",
124378              "type": "distribution"
124379            },
124380            {
124381              "url": "https://github.com/tim-kos/node-retry",
124382              "type": "website"
124383            }
124384          ],
124385          "evidence": {},
124386          "signature": {
124387            "signature": {
124388              "publicKey": {}
124389            }
124390          },
124391          "modelCard": {
124392            "modelParameters": {
124393              "approach": {}
124394            },
124395            "quantitativeAnalysis": {
124396              "graphics": {}
124397            },
124398            "considerations": {}
124399          }
124400        },
124401        {
124402          "type": "library",
124403          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=92690f32c123c49b",
124404          "supplier": {},
124405          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
124406          "name": "rimraf",
124407          "version": "3.0.2",
124408          "description": "A deep deletion module for node (like `rm -rf`)",
124409          "licenses": [
124410            {
124411              "license": {
124412                "id": "ISC"
124413              }
124414            }
124415          ],
124416          "cpe": "cpe:2.3:a:isaacs:rimraf:3.0.2:*:*:*:*:*:*:*",
124417          "purl": "pkg:npm/rimraf@3.0.2",
124418          "swid": {
124419            "attachment": {}
124420          },
124421          "pedigree": {},
124422          "externalReferences": [
124423            {
124424              "url": "git://github.com/isaacs/rimraf.git",
124425              "type": "distribution"
124426            }
124427          ],
124428          "evidence": {},
124429          "signature": {
124430            "signature": {
124431              "publicKey": {}
124432            }
124433          },
124434          "modelCard": {
124435            "modelParameters": {
124436              "approach": {}
124437            },
124438            "quantitativeAnalysis": {
124439              "graphics": {}
124440            },
124441            "considerations": {}
124442          }
124443        },
124444        {
124445          "type": "library",
124446          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=ad8e4b783ec0cc69",
124447          "supplier": {},
124448          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
124449          "name": "safe-buffer",
124450          "version": "5.1.2",
124451          "description": "Safer Node.js Buffer API",
124452          "licenses": [
124453            {
124454              "license": {
124455                "id": "MIT"
124456              }
124457            }
124458          ],
124459          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
124460          "purl": "pkg:npm/safe-buffer@5.1.2",
124461          "swid": {
124462            "attachment": {}
124463          },
124464          "pedigree": {},
124465          "externalReferences": [
124466            {
124467              "url": "git://github.com/feross/safe-buffer.git",
124468              "type": "distribution"
124469            },
124470            {
124471              "url": "https://github.com/feross/safe-buffer",
124472              "type": "website"
124473            }
124474          ],
124475          "evidence": {},
124476          "signature": {
124477            "signature": {
124478              "publicKey": {}
124479            }
124480          },
124481          "modelCard": {
124482            "modelParameters": {
124483              "approach": {}
124484            },
124485            "quantitativeAnalysis": {
124486              "graphics": {}
124487            },
124488            "considerations": {}
124489          }
124490        },
124491        {
124492          "type": "library",
124493          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=17b89784efaad79e",
124494          "supplier": {},
124495          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
124496          "name": "safe-buffer",
124497          "version": "5.1.2",
124498          "description": "Safer Node.js Buffer API",
124499          "licenses": [
124500            {
124501              "license": {
124502                "id": "MIT"
124503              }
124504            }
124505          ],
124506          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
124507          "purl": "pkg:npm/safe-buffer@5.1.2",
124508          "swid": {
124509            "attachment": {}
124510          },
124511          "pedigree": {},
124512          "externalReferences": [
124513            {
124514              "url": "git://github.com/feross/safe-buffer.git",
124515              "type": "distribution"
124516            },
124517            {
124518              "url": "https://github.com/feross/safe-buffer",
124519              "type": "website"
124520            }
124521          ],
124522          "evidence": {},
124523          "signature": {
124524            "signature": {
124525              "publicKey": {}
124526            }
124527          },
124528          "modelCard": {
124529            "modelParameters": {
124530              "approach": {}
124531            },
124532            "quantitativeAnalysis": {
124533              "graphics": {}
124534            },
124535            "considerations": {}
124536          }
124537        },
124538        {
124539          "type": "library",
124540          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=37bd52a7cabd5921",
124541          "supplier": {},
124542          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
124543          "name": "safe-buffer",
124544          "version": "5.1.2",
124545          "description": "Safer Node.js Buffer API",
124546          "licenses": [
124547            {
124548              "license": {
124549                "id": "MIT"
124550              }
124551            }
124552          ],
124553          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
124554          "purl": "pkg:npm/safe-buffer@5.1.2",
124555          "swid": {
124556            "attachment": {}
124557          },
124558          "pedigree": {},
124559          "externalReferences": [
124560            {
124561              "url": "git://github.com/feross/safe-buffer.git",
124562              "type": "distribution"
124563            },
124564            {
124565              "url": "https://github.com/feross/safe-buffer",
124566              "type": "website"
124567            }
124568          ],
124569          "evidence": {},
124570          "signature": {
124571            "signature": {
124572              "publicKey": {}
124573            }
124574          },
124575          "modelCard": {
124576            "modelParameters": {
124577              "approach": {}
124578            },
124579            "quantitativeAnalysis": {
124580              "graphics": {}
124581            },
124582            "considerations": {}
124583          }
124584        },
124585        {
124586          "type": "library",
124587          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=84f64b73f6fc2a9b",
124588          "supplier": {},
124589          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
124590          "name": "safe-buffer",
124591          "version": "5.2.1",
124592          "description": "Safer Node.js Buffer API",
124593          "licenses": [
124594            {
124595              "license": {
124596                "id": "MIT"
124597              }
124598            }
124599          ],
124600          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
124601          "purl": "pkg:npm/safe-buffer@5.2.1",
124602          "swid": {
124603            "attachment": {}
124604          },
124605          "pedigree": {},
124606          "externalReferences": [
124607            {
124608              "url": "git://github.com/feross/safe-buffer.git",
124609              "type": "distribution"
124610            },
124611            {
124612              "url": "https://github.com/feross/safe-buffer",
124613              "type": "website"
124614            }
124615          ],
124616          "evidence": {},
124617          "signature": {
124618            "signature": {
124619              "publicKey": {}
124620            }
124621          },
124622          "modelCard": {
124623            "modelParameters": {
124624              "approach": {}
124625            },
124626            "quantitativeAnalysis": {
124627              "graphics": {}
124628            },
124629            "considerations": {}
124630          }
124631        },
124632        {
124633          "type": "library",
124634          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=edf513d3ab46bee",
124635          "supplier": {},
124636          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
124637          "name": "safe-buffer",
124638          "version": "5.2.1",
124639          "description": "Safer Node.js Buffer API",
124640          "licenses": [
124641            {
124642              "license": {
124643                "id": "MIT"
124644              }
124645            }
124646          ],
124647          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
124648          "purl": "pkg:npm/safe-buffer@5.2.1",
124649          "swid": {
124650            "attachment": {}
124651          },
124652          "pedigree": {},
124653          "externalReferences": [
124654            {
124655              "url": "git://github.com/feross/safe-buffer.git",
124656              "type": "distribution"
124657            },
124658            {
124659              "url": "https://github.com/feross/safe-buffer",
124660              "type": "website"
124661            }
124662          ],
124663          "evidence": {},
124664          "signature": {
124665            "signature": {
124666              "publicKey": {}
124667            }
124668          },
124669          "modelCard": {
124670            "modelParameters": {
124671              "approach": {}
124672            },
124673            "quantitativeAnalysis": {
124674              "graphics": {}
124675            },
124676            "considerations": {}
124677          }
124678        },
124679        {
124680          "type": "library",
124681          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=4ab2220d3f3f4961",
124682          "supplier": {},
124683          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
124684          "name": "safer-buffer",
124685          "version": "2.1.2",
124686          "description": "Modern Buffer API polyfill without footguns",
124687          "licenses": [
124688            {
124689              "license": {
124690                "id": "MIT"
124691              }
124692            }
124693          ],
124694          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
124695          "purl": "pkg:npm/safer-buffer@2.1.2",
124696          "swid": {
124697            "attachment": {}
124698          },
124699          "pedigree": {},
124700          "externalReferences": [
124701            {
124702              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
124703              "type": "distribution"
124704            }
124705          ],
124706          "evidence": {},
124707          "signature": {
124708            "signature": {
124709              "publicKey": {}
124710            }
124711          },
124712          "modelCard": {
124713            "modelParameters": {
124714              "approach": {}
124715            },
124716            "quantitativeAnalysis": {
124717              "graphics": {}
124718            },
124719            "considerations": {}
124720          }
124721        },
124722        {
124723          "type": "library",
124724          "bom-ref": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5\u0026package-id=206fdb47b3e980eb",
124725          "supplier": {},
124726          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
124727          "name": "scanelf",
124728          "version": "1.3.4-r0",
124729          "description": "Scan ELF binaries for stuff",
124730          "licenses": [
124731            {
124732              "license": {
124733                "id": "GPL-2.0-only"
124734              }
124735            }
124736          ],
124737          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.4-r0:*:*:*:*:*:*:*",
124738          "purl": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5",
124739          "swid": {
124740            "attachment": {}
124741          },
124742          "pedigree": {},
124743          "externalReferences": [
124744            {
124745              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
124746              "type": "distribution"
124747            }
124748          ],
124749          "evidence": {},
124750          "signature": {
124751            "signature": {
124752              "publicKey": {}
124753            }
124754          },
124755          "modelCard": {
124756            "modelParameters": {
124757              "approach": {}
124758            },
124759            "quantitativeAnalysis": {
124760              "graphics": {}
124761            },
124762            "considerations": {}
124763          }
124764        },
124765        {
124766          "type": "library",
124767          "bom-ref": "pkg:npm/semver@5.7.1?package-id=ea0de706714a055e",
124768          "supplier": {},
124769          "name": "semver",
124770          "version": "5.7.1",
124771          "description": "The semantic version parser used by npm.",
124772          "licenses": [
124773            {
124774              "license": {
124775                "id": "ISC"
124776              }
124777            }
124778          ],
124779          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
124780          "purl": "pkg:npm/semver@5.7.1",
124781          "swid": {
124782            "attachment": {}
124783          },
124784          "pedigree": {},
124785          "externalReferences": [
124786            {
124787              "url": "https://github.com/npm/node-semver",
124788              "type": "distribution"
124789            }
124790          ],
124791          "evidence": {},
124792          "signature": {
124793            "signature": {
124794              "publicKey": {}
124795            }
124796          },
124797          "modelCard": {
124798            "modelParameters": {
124799              "approach": {}
124800            },
124801            "quantitativeAnalysis": {
124802              "graphics": {}
124803            },
124804            "considerations": {}
124805          }
124806        },
124807        {
124808          "type": "library",
124809          "bom-ref": "pkg:npm/semver@7.3.7?package-id=73e16bb8e099774",
124810          "supplier": {},
124811          "author": "GitHub Inc.",
124812          "name": "semver",
124813          "version": "7.3.7",
124814          "description": "The semantic version parser used by npm.",
124815          "licenses": [
124816            {
124817              "license": {
124818                "id": "ISC"
124819              }
124820            }
124821          ],
124822          "cpe": "cpe:2.3:a:semver:semver:7.3.7:*:*:*:*:*:*:*",
124823          "purl": "pkg:npm/semver@7.3.7",
124824          "swid": {
124825            "attachment": {}
124826          },
124827          "pedigree": {},
124828          "externalReferences": [
124829            {
124830              "url": "https://github.com/npm/node-semver.git",
124831              "type": "distribution"
124832            }
124833          ],
124834          "evidence": {},
124835          "signature": {
124836            "signature": {
124837              "publicKey": {}
124838            }
124839          },
124840          "modelCard": {
124841            "modelParameters": {
124842              "approach": {}
124843            },
124844            "quantitativeAnalysis": {
124845              "graphics": {}
124846            },
124847            "considerations": {}
124848          }
124849        },
124850        {
124851          "type": "library",
124852          "bom-ref": "pkg:npm/set-blocking@2.0.0?package-id=bac85cbb844de9c9",
124853          "supplier": {},
124854          "author": "Ben Coe \u003cben@npmjs.com\u003e",
124855          "name": "set-blocking",
124856          "version": "2.0.0",
124857          "description": "set blocking stdio and stderr ensuring that terminal output does not truncate",
124858          "licenses": [
124859            {
124860              "license": {
124861                "id": "ISC"
124862              }
124863            }
124864          ],
124865          "cpe": "cpe:2.3:a:set-blocking:set-blocking:2.0.0:*:*:*:*:*:*:*",
124866          "purl": "pkg:npm/set-blocking@2.0.0",
124867          "swid": {
124868            "attachment": {}
124869          },
124870          "pedigree": {},
124871          "externalReferences": [
124872            {
124873              "url": "git+https://github.com/yargs/set-blocking.git",
124874              "type": "distribution"
124875            },
124876            {
124877              "url": "https://github.com/yargs/set-blocking#readme",
124878              "type": "website"
124879            }
124880          ],
124881          "evidence": {},
124882          "signature": {
124883            "signature": {
124884              "publicKey": {}
124885            }
124886          },
124887          "modelCard": {
124888            "modelParameters": {
124889              "approach": {}
124890            },
124891            "quantitativeAnalysis": {
124892              "graphics": {}
124893            },
124894            "considerations": {}
124895          }
124896        },
124897        {
124898          "type": "library",
124899          "bom-ref": "pkg:npm/signal-exit@3.0.7?package-id=998659694cba1dfd",
124900          "supplier": {},
124901          "author": "Ben Coe \u003cben@npmjs.com\u003e",
124902          "name": "signal-exit",
124903          "version": "3.0.7",
124904          "description": "when you want to fire an event no matter how a process exits.",
124905          "licenses": [
124906            {
124907              "license": {
124908                "id": "ISC"
124909              }
124910            }
124911          ],
124912          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.7:*:*:*:*:*:*:*",
124913          "purl": "pkg:npm/signal-exit@3.0.7",
124914          "swid": {
124915            "attachment": {}
124916          },
124917          "pedigree": {},
124918          "externalReferences": [
124919            {
124920              "url": "https://github.com/tapjs/signal-exit.git",
124921              "type": "distribution"
124922            },
124923            {
124924              "url": "https://github.com/tapjs/signal-exit",
124925              "type": "website"
124926            }
124927          ],
124928          "evidence": {},
124929          "signature": {
124930            "signature": {
124931              "publicKey": {}
124932            }
124933          },
124934          "modelCard": {
124935            "modelParameters": {
124936              "approach": {}
124937            },
124938            "quantitativeAnalysis": {
124939              "graphics": {}
124940            },
124941            "considerations": {}
124942          }
124943        },
124944        {
124945          "type": "library",
124946          "bom-ref": "pkg:npm/smart-buffer@4.2.0?package-id=ad322c124ae3043c",
124947          "supplier": {},
124948          "author": "Josh Glazebrook",
124949          "name": "smart-buffer",
124950          "version": "4.2.0",
124951          "description": "smart-buffer is a Buffer wrapper that adds automatic read \u0026 write offset tracking, string operations, data insertions, and more.",
124952          "licenses": [
124953            {
124954              "license": {
124955                "id": "MIT"
124956              }
124957            }
124958          ],
124959          "cpe": "cpe:2.3:a:JoshGlazebrook:smart-buffer:4.2.0:*:*:*:*:*:*:*",
124960          "purl": "pkg:npm/smart-buffer@4.2.0",
124961          "swid": {
124962            "attachment": {}
124963          },
124964          "pedigree": {},
124965          "externalReferences": [
124966            {
124967              "url": "https://github.com/JoshGlazebrook/smart-buffer.git",
124968              "type": "distribution"
124969            },
124970            {
124971              "url": "https://github.com/JoshGlazebrook/smart-buffer/",
124972              "type": "website"
124973            }
124974          ],
124975          "evidence": {},
124976          "signature": {
124977            "signature": {
124978              "publicKey": {}
124979            }
124980          },
124981          "modelCard": {
124982            "modelParameters": {
124983              "approach": {}
124984            },
124985            "quantitativeAnalysis": {
124986              "graphics": {}
124987            },
124988            "considerations": {}
124989          }
124990        },
124991        {
124992          "type": "library",
124993          "bom-ref": "pkg:npm/socks@2.7.0?package-id=267f6eb3d489a8eb",
124994          "supplier": {},
124995          "author": "Josh Glazebrook",
124996          "name": "socks",
124997          "version": "2.7.0",
124998          "description": "Fully featured SOCKS proxy client supporting SOCKSv4, SOCKSv4a, and SOCKSv5. Includes Bind and Associate functionality.",
124999          "licenses": [
125000            {
125001              "license": {
125002                "id": "MIT"
125003              }
125004            }
125005          ],
125006          "cpe": "cpe:2.3:a:JoshGlazebrook:socks:2.7.0:*:*:*:*:*:*:*",
125007          "purl": "pkg:npm/socks@2.7.0",
125008          "swid": {
125009            "attachment": {}
125010          },
125011          "pedigree": {},
125012          "externalReferences": [
125013            {
125014              "url": "https://github.com/JoshGlazebrook/socks.git",
125015              "type": "distribution"
125016            },
125017            {
125018              "url": "https://github.com/JoshGlazebrook/socks/",
125019              "type": "website"
125020            }
125021          ],
125022          "evidence": {},
125023          "signature": {
125024            "signature": {
125025              "publicKey": {}
125026            }
125027          },
125028          "modelCard": {
125029            "modelParameters": {
125030              "approach": {}
125031            },
125032            "quantitativeAnalysis": {
125033              "graphics": {}
125034            },
125035            "considerations": {}
125036          }
125037        },
125038        {
125039          "type": "library",
125040          "bom-ref": "pkg:npm/socks-proxy-agent@7.0.0?package-id=8dc0e605920052a1",
125041          "supplier": {},
125042          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
125043          "name": "socks-proxy-agent",
125044          "version": "7.0.0",
125045          "description": "A SOCKS proxy `http.Agent` implementation for HTTP and HTTPS",
125046          "licenses": [
125047            {
125048              "license": {
125049                "id": "MIT"
125050              }
125051            }
125052          ],
125053          "cpe": "cpe:2.3:a:socks-proxy-agent:socks-proxy-agent:7.0.0:*:*:*:*:*:*:*",
125054          "purl": "pkg:npm/socks-proxy-agent@7.0.0",
125055          "swid": {
125056            "attachment": {}
125057          },
125058          "pedigree": {},
125059          "externalReferences": [
125060            {
125061              "url": "git://github.com/TooTallNate/node-socks-proxy-agent.git",
125062              "type": "distribution"
125063            },
125064            {
125065              "url": "https://github.com/TooTallNate/node-socks-proxy-agent#readme",
125066              "type": "website"
125067            }
125068          ],
125069          "evidence": {},
125070          "signature": {
125071            "signature": {
125072              "publicKey": {}
125073            }
125074          },
125075          "modelCard": {
125076            "modelParameters": {
125077              "approach": {}
125078            },
125079            "quantitativeAnalysis": {
125080              "graphics": {}
125081            },
125082            "considerations": {}
125083          }
125084        },
125085        {
125086          "type": "library",
125087          "bom-ref": "pkg:npm/spdx-correct@3.1.1?package-id=d6b0214947e454eb",
125088          "supplier": {},
125089          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
125090          "name": "spdx-correct",
125091          "version": "3.1.1",
125092          "description": "correct invalid SPDX expressions",
125093          "licenses": [
125094            {
125095              "license": {
125096                "id": "Apache-2.0"
125097              }
125098            }
125099          ],
125100          "cpe": "cpe:2.3:a:spdx-correct:spdx-correct:3.1.1:*:*:*:*:*:*:*",
125101          "purl": "pkg:npm/spdx-correct@3.1.1",
125102          "swid": {
125103            "attachment": {}
125104          },
125105          "pedigree": {},
125106          "externalReferences": [
125107            {
125108              "url": "jslicense/spdx-correct.js",
125109              "type": "distribution"
125110            }
125111          ],
125112          "evidence": {},
125113          "signature": {
125114            "signature": {
125115              "publicKey": {}
125116            }
125117          },
125118          "modelCard": {
125119            "modelParameters": {
125120              "approach": {}
125121            },
125122            "quantitativeAnalysis": {
125123              "graphics": {}
125124            },
125125            "considerations": {}
125126          }
125127        },
125128        {
125129          "type": "library",
125130          "bom-ref": "pkg:npm/spdx-exceptions@2.3.0?package-id=22aa1fb7c596c6c7",
125131          "supplier": {},
125132          "author": "The Linux Foundation",
125133          "name": "spdx-exceptions",
125134          "version": "2.3.0",
125135          "description": "list of SPDX standard license exceptions",
125136          "licenses": [
125137            {
125138              "license": {
125139                "id": "CC-BY-3.0"
125140              }
125141            }
125142          ],
125143          "cpe": "cpe:2.3:a:spdx-exceptions:spdx-exceptions:2.3.0:*:*:*:*:*:*:*",
125144          "purl": "pkg:npm/spdx-exceptions@2.3.0",
125145          "swid": {
125146            "attachment": {}
125147          },
125148          "pedigree": {},
125149          "externalReferences": [
125150            {
125151              "url": "kemitchell/spdx-exceptions.json",
125152              "type": "distribution"
125153            }
125154          ],
125155          "evidence": {},
125156          "signature": {
125157            "signature": {
125158              "publicKey": {}
125159            }
125160          },
125161          "modelCard": {
125162            "modelParameters": {
125163              "approach": {}
125164            },
125165            "quantitativeAnalysis": {
125166              "graphics": {}
125167            },
125168            "considerations": {}
125169          }
125170        },
125171        {
125172          "type": "library",
125173          "bom-ref": "pkg:npm/spdx-expression-parse@3.0.1?package-id=78c73c9b189e2783",
125174          "supplier": {},
125175          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
125176          "name": "spdx-expression-parse",
125177          "version": "3.0.1",
125178          "description": "parse SPDX license expressions",
125179          "licenses": [
125180            {
125181              "license": {
125182                "id": "MIT"
125183              }
125184            }
125185          ],
125186          "cpe": "cpe:2.3:a:spdx-expression-parse:spdx-expression-parse:3.0.1:*:*:*:*:*:*:*",
125187          "purl": "pkg:npm/spdx-expression-parse@3.0.1",
125188          "swid": {
125189            "attachment": {}
125190          },
125191          "pedigree": {},
125192          "externalReferences": [
125193            {
125194              "url": "jslicense/spdx-expression-parse.js",
125195              "type": "distribution"
125196            }
125197          ],
125198          "evidence": {},
125199          "signature": {
125200            "signature": {
125201              "publicKey": {}
125202            }
125203          },
125204          "modelCard": {
125205            "modelParameters": {
125206              "approach": {}
125207            },
125208            "quantitativeAnalysis": {
125209              "graphics": {}
125210            },
125211            "considerations": {}
125212          }
125213        },
125214        {
125215          "type": "library",
125216          "bom-ref": "pkg:npm/spdx-license-ids@3.0.11?package-id=6530ac28616ec508",
125217          "supplier": {},
125218          "author": "Shinnosuke Watanabe (https://github.com/shinnn)",
125219          "name": "spdx-license-ids",
125220          "version": "3.0.11",
125221          "description": "A list of SPDX license identifiers",
125222          "licenses": [
125223            {
125224              "license": {
125225                "id": "CC0-1.0"
125226              }
125227            }
125228          ],
125229          "cpe": "cpe:2.3:a:spdx-license-ids:spdx-license-ids:3.0.11:*:*:*:*:*:*:*",
125230          "purl": "pkg:npm/spdx-license-ids@3.0.11",
125231          "swid": {
125232            "attachment": {}
125233          },
125234          "pedigree": {},
125235          "externalReferences": [
125236            {
125237              "url": "jslicense/spdx-license-ids",
125238              "type": "distribution"
125239            }
125240          ],
125241          "evidence": {},
125242          "signature": {
125243            "signature": {
125244              "publicKey": {}
125245            }
125246          },
125247          "modelCard": {
125248            "modelParameters": {
125249              "approach": {}
125250            },
125251            "quantitativeAnalysis": {
125252              "graphics": {}
125253            },
125254            "considerations": {}
125255          }
125256        },
125257        {
125258          "type": "library",
125259          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5\u0026package-id=674d1e2fba4d633a",
125260          "supplier": {},
125261          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
125262          "name": "ssl_client",
125263          "version": "1.35.0-r17",
125264          "description": "EXternal ssl_client for busybox wget",
125265          "licenses": [
125266            {
125267              "license": {
125268                "id": "GPL-2.0-only"
125269              }
125270            }
125271          ],
125272          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r17:*:*:*:*:*:*:*",
125273          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5",
125274          "swid": {
125275            "attachment": {}
125276          },
125277          "pedigree": {},
125278          "externalReferences": [
125279            {
125280              "url": "https://busybox.net/",
125281              "type": "distribution"
125282            }
125283          ],
125284          "evidence": {},
125285          "signature": {
125286            "signature": {
125287              "publicKey": {}
125288            }
125289          },
125290          "modelCard": {
125291            "modelParameters": {
125292              "approach": {}
125293            },
125294            "quantitativeAnalysis": {
125295              "graphics": {}
125296            },
125297            "considerations": {}
125298          }
125299        },
125300        {
125301          "type": "library",
125302          "bom-ref": "pkg:npm/ssri@9.0.1?package-id=49986701356bf646",
125303          "supplier": {},
125304          "author": "GitHub Inc.",
125305          "name": "ssri",
125306          "version": "9.0.1",
125307          "description": "Standard Subresource Integrity library -- parses, serializes, generates, and verifies integrity metadata according to the SRI spec.",
125308          "licenses": [
125309            {
125310              "license": {
125311                "id": "ISC"
125312              }
125313            }
125314          ],
125315          "cpe": "cpe:2.3:a:ssri:ssri:9.0.1:*:*:*:*:*:*:*",
125316          "purl": "pkg:npm/ssri@9.0.1",
125317          "swid": {
125318            "attachment": {}
125319          },
125320          "pedigree": {},
125321          "externalReferences": [
125322            {
125323              "url": "https://github.com/npm/ssri.git",
125324              "type": "distribution"
125325            }
125326          ],
125327          "evidence": {},
125328          "signature": {
125329            "signature": {
125330              "publicKey": {}
125331            }
125332          },
125333          "modelCard": {
125334            "modelParameters": {
125335              "approach": {}
125336            },
125337            "quantitativeAnalysis": {
125338              "graphics": {}
125339            },
125340            "considerations": {}
125341          }
125342        },
125343        {
125344          "type": "library",
125345          "bom-ref": "pkg:npm/stream-shift@1.0.1?package-id=b27a016b7ab367a8",
125346          "supplier": {},
125347          "author": "Mathias Buus (@mafintosh)",
125348          "name": "stream-shift",
125349          "version": "1.0.1",
125350          "description": "Returns the next buffer/object in a stream's readable queue",
125351          "licenses": [
125352            {
125353              "license": {
125354                "id": "MIT"
125355              }
125356            }
125357          ],
125358          "cpe": "cpe:2.3:a:stream-shift:stream-shift:1.0.1:*:*:*:*:*:*:*",
125359          "purl": "pkg:npm/stream-shift@1.0.1",
125360          "swid": {
125361            "attachment": {}
125362          },
125363          "pedigree": {},
125364          "externalReferences": [
125365            {
125366              "url": "https://github.com/mafintosh/stream-shift.git",
125367              "type": "distribution"
125368            },
125369            {
125370              "url": "https://github.com/mafintosh/stream-shift",
125371              "type": "website"
125372            }
125373          ],
125374          "evidence": {},
125375          "signature": {
125376            "signature": {
125377              "publicKey": {}
125378            }
125379          },
125380          "modelCard": {
125381            "modelParameters": {
125382              "approach": {}
125383            },
125384            "quantitativeAnalysis": {
125385              "graphics": {}
125386            },
125387            "considerations": {}
125388          }
125389        },
125390        {
125391          "type": "library",
125392          "bom-ref": "pkg:npm/string-width@4.2.3?package-id=c50e61a77e3ea809",
125393          "supplier": {},
125394          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
125395          "name": "string-width",
125396          "version": "4.2.3",
125397          "description": "Get the visual width of a string - the number of columns required to display it",
125398          "licenses": [
125399            {
125400              "license": {
125401                "id": "MIT"
125402              }
125403            }
125404          ],
125405          "cpe": "cpe:2.3:a:string-width:string-width:4.2.3:*:*:*:*:*:*:*",
125406          "purl": "pkg:npm/string-width@4.2.3",
125407          "swid": {
125408            "attachment": {}
125409          },
125410          "pedigree": {},
125411          "externalReferences": [
125412            {
125413              "url": "sindresorhus/string-width",
125414              "type": "distribution"
125415            }
125416          ],
125417          "evidence": {},
125418          "signature": {
125419            "signature": {
125420              "publicKey": {}
125421            }
125422          },
125423          "modelCard": {
125424            "modelParameters": {
125425              "approach": {}
125426            },
125427            "quantitativeAnalysis": {
125428              "graphics": {}
125429            },
125430            "considerations": {}
125431          }
125432        },
125433        {
125434          "type": "library",
125435          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=b92fbc6f9b574fb4",
125436          "supplier": {},
125437          "name": "string_decoder",
125438          "version": "1.1.1",
125439          "description": "The string_decoder module from Node core",
125440          "licenses": [
125441            {
125442              "license": {
125443                "id": "MIT"
125444              }
125445            }
125446          ],
125447          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
125448          "purl": "pkg:npm/string_decoder@1.1.1",
125449          "swid": {
125450            "attachment": {}
125451          },
125452          "pedigree": {},
125453          "externalReferences": [
125454            {
125455              "url": "git://github.com/nodejs/string_decoder.git",
125456              "type": "distribution"
125457            },
125458            {
125459              "url": "https://github.com/nodejs/string_decoder",
125460              "type": "website"
125461            }
125462          ],
125463          "evidence": {},
125464          "signature": {
125465            "signature": {
125466              "publicKey": {}
125467            }
125468          },
125469          "modelCard": {
125470            "modelParameters": {
125471              "approach": {}
125472            },
125473            "quantitativeAnalysis": {
125474              "graphics": {}
125475            },
125476            "considerations": {}
125477          }
125478        },
125479        {
125480          "type": "library",
125481          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=6f9f2f60fec7ea8b",
125482          "supplier": {},
125483          "name": "string_decoder",
125484          "version": "1.1.1",
125485          "description": "The string_decoder module from Node core",
125486          "licenses": [
125487            {
125488              "license": {
125489                "id": "MIT"
125490              }
125491            }
125492          ],
125493          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
125494          "purl": "pkg:npm/string_decoder@1.1.1",
125495          "swid": {
125496            "attachment": {}
125497          },
125498          "pedigree": {},
125499          "externalReferences": [
125500            {
125501              "url": "git://github.com/nodejs/string_decoder.git",
125502              "type": "distribution"
125503            },
125504            {
125505              "url": "https://github.com/nodejs/string_decoder",
125506              "type": "website"
125507            }
125508          ],
125509          "evidence": {},
125510          "signature": {
125511            "signature": {
125512              "publicKey": {}
125513            }
125514          },
125515          "modelCard": {
125516            "modelParameters": {
125517              "approach": {}
125518            },
125519            "quantitativeAnalysis": {
125520              "graphics": {}
125521            },
125522            "considerations": {}
125523          }
125524        },
125525        {
125526          "type": "library",
125527          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=ca8af4aa6b41ca75",
125528          "supplier": {},
125529          "name": "string_decoder",
125530          "version": "1.3.0",
125531          "description": "The string_decoder module from Node core",
125532          "licenses": [
125533            {
125534              "license": {
125535                "id": "MIT"
125536              }
125537            }
125538          ],
125539          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
125540          "purl": "pkg:npm/string_decoder@1.3.0",
125541          "swid": {
125542            "attachment": {}
125543          },
125544          "pedigree": {},
125545          "externalReferences": [
125546            {
125547              "url": "git://github.com/nodejs/string_decoder.git",
125548              "type": "distribution"
125549            },
125550            {
125551              "url": "https://github.com/nodejs/string_decoder",
125552              "type": "website"
125553            }
125554          ],
125555          "evidence": {},
125556          "signature": {
125557            "signature": {
125558              "publicKey": {}
125559            }
125560          },
125561          "modelCard": {
125562            "modelParameters": {
125563              "approach": {}
125564            },
125565            "quantitativeAnalysis": {
125566              "graphics": {}
125567            },
125568            "considerations": {}
125569          }
125570        },
125571        {
125572          "type": "library",
125573          "bom-ref": "pkg:npm/strip-ansi@6.0.1?package-id=5ec73c7d72940ceb",
125574          "supplier": {},
125575          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
125576          "name": "strip-ansi",
125577          "version": "6.0.1",
125578          "description": "Strip ANSI escape codes from a string",
125579          "licenses": [
125580            {
125581              "license": {
125582                "id": "MIT"
125583              }
125584            }
125585          ],
125586          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:6.0.1:*:*:*:*:*:*:*",
125587          "purl": "pkg:npm/strip-ansi@6.0.1",
125588          "swid": {
125589            "attachment": {}
125590          },
125591          "pedigree": {},
125592          "externalReferences": [
125593            {
125594              "url": "chalk/strip-ansi",
125595              "type": "distribution"
125596            }
125597          ],
125598          "evidence": {},
125599          "signature": {
125600            "signature": {
125601              "publicKey": {}
125602            }
125603          },
125604          "modelCard": {
125605            "modelParameters": {
125606              "approach": {}
125607            },
125608            "quantitativeAnalysis": {
125609              "graphics": {}
125610            },
125611            "considerations": {}
125612          }
125613        },
125614        {
125615          "type": "library",
125616          "bom-ref": "pkg:npm/supports-color@7.2.0?package-id=4c97deb16c788c95",
125617          "supplier": {},
125618          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
125619          "name": "supports-color",
125620          "version": "7.2.0",
125621          "description": "Detect whether a terminal supports color",
125622          "licenses": [
125623            {
125624              "license": {
125625                "id": "MIT"
125626              }
125627            }
125628          ],
125629          "cpe": "cpe:2.3:a:supports-color:supports-color:7.2.0:*:*:*:*:*:*:*",
125630          "purl": "pkg:npm/supports-color@7.2.0",
125631          "swid": {
125632            "attachment": {}
125633          },
125634          "pedigree": {},
125635          "externalReferences": [
125636            {
125637              "url": "chalk/supports-color",
125638              "type": "distribution"
125639            }
125640          ],
125641          "evidence": {},
125642          "signature": {
125643            "signature": {
125644              "publicKey": {}
125645            }
125646          },
125647          "modelCard": {
125648            "modelParameters": {
125649              "approach": {}
125650            },
125651            "quantitativeAnalysis": {
125652              "graphics": {}
125653            },
125654            "considerations": {}
125655          }
125656        },
125657        {
125658          "type": "library",
125659          "bom-ref": "pkg:npm/tar@6.1.11?package-id=97823590d9da9c9f",
125660          "supplier": {},
125661          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
125662          "name": "tar",
125663          "version": "6.1.11",
125664          "description": "tar for node",
125665          "licenses": [
125666            {
125667              "license": {
125668                "id": "ISC"
125669              }
125670            }
125671          ],
125672          "cpe": "cpe:2.3:a:npm:tar:6.1.11:*:*:*:*:*:*:*",
125673          "purl": "pkg:npm/tar@6.1.11",
125674          "swid": {
125675            "attachment": {}
125676          },
125677          "pedigree": {},
125678          "externalReferences": [
125679            {
125680              "url": "https://github.com/npm/node-tar.git",
125681              "type": "distribution"
125682            }
125683          ],
125684          "evidence": {},
125685          "signature": {
125686            "signature": {
125687              "publicKey": {}
125688            }
125689          },
125690          "modelCard": {
125691            "modelParameters": {
125692              "approach": {}
125693            },
125694            "quantitativeAnalysis": {
125695              "graphics": {}
125696            },
125697            "considerations": {}
125698          }
125699        },
125700        {
125701          "type": "library",
125702          "bom-ref": "pkg:npm/text-table@0.2.0?package-id=a124be9ad599668f",
125703          "supplier": {},
125704          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
125705          "name": "text-table",
125706          "version": "0.2.0",
125707          "description": "borderless text tables with alignment",
125708          "licenses": [
125709            {
125710              "license": {
125711                "id": "MIT"
125712              }
125713            }
125714          ],
125715          "cpe": "cpe:2.3:a:text-table:text-table:0.2.0:*:*:*:*:*:*:*",
125716          "purl": "pkg:npm/text-table@0.2.0",
125717          "swid": {
125718            "attachment": {}
125719          },
125720          "pedigree": {},
125721          "externalReferences": [
125722            {
125723              "url": "git://github.com/substack/text-table.git",
125724              "type": "distribution"
125725            },
125726            {
125727              "url": "https://github.com/substack/text-table",
125728              "type": "website"
125729            }
125730          ],
125731          "evidence": {},
125732          "signature": {
125733            "signature": {
125734              "publicKey": {}
125735            }
125736          },
125737          "modelCard": {
125738            "modelParameters": {
125739              "approach": {}
125740            },
125741            "quantitativeAnalysis": {
125742              "graphics": {}
125743            },
125744            "considerations": {}
125745          }
125746        },
125747        {
125748          "type": "library",
125749          "bom-ref": "pkg:npm/tiny-relative-date@1.3.0?package-id=bc2a707c455ba496",
125750          "supplier": {},
125751          "author": "Joseph Wynn \u003cjoseph@wildlyinaccurate.com\u003e (https://wildlyinaccurate.com/)",
125752          "name": "tiny-relative-date",
125753          "version": "1.3.0",
125754          "description": "Tiny function that provides relative, human-readable dates.",
125755          "licenses": [
125756            {
125757              "license": {
125758                "id": "MIT"
125759              }
125760            }
125761          ],
125762          "cpe": "cpe:2.3:a:tiny-relative-date:tiny-relative-date:1.3.0:*:*:*:*:*:*:*",
125763          "purl": "pkg:npm/tiny-relative-date@1.3.0",
125764          "swid": {
125765            "attachment": {}
125766          },
125767          "pedigree": {},
125768          "externalReferences": [
125769            {
125770              "url": "https://github.com/wildlyinaccurate/relative-date.git",
125771              "type": "distribution"
125772            }
125773          ],
125774          "evidence": {},
125775          "signature": {
125776            "signature": {
125777              "publicKey": {}
125778            }
125779          },
125780          "modelCard": {
125781            "modelParameters": {
125782              "approach": {}
125783            },
125784            "quantitativeAnalysis": {
125785              "graphics": {}
125786            },
125787            "considerations": {}
125788          }
125789        },
125790        {
125791          "type": "library",
125792          "bom-ref": "pkg:npm/treeverse@2.0.0?package-id=283d5c0745aa3ce7",
125793          "supplier": {},
125794          "author": "GitHub Inc.",
125795          "name": "treeverse",
125796          "version": "2.0.0",
125797          "description": "Walk any kind of tree structure depth- or breadth-first. Supports promises and advanced map-reduce operations with a very small API.",
125798          "licenses": [
125799            {
125800              "license": {
125801                "id": "ISC"
125802              }
125803            }
125804          ],
125805          "cpe": "cpe:2.3:a:treeverse:treeverse:2.0.0:*:*:*:*:*:*:*",
125806          "purl": "pkg:npm/treeverse@2.0.0",
125807          "swid": {
125808            "attachment": {}
125809          },
125810          "pedigree": {},
125811          "externalReferences": [
125812            {
125813              "url": "https://github.com/npm/treeverse.git",
125814              "type": "distribution"
125815            }
125816          ],
125817          "evidence": {},
125818          "signature": {
125819            "signature": {
125820              "publicKey": {}
125821            }
125822          },
125823          "modelCard": {
125824            "modelParameters": {
125825              "approach": {}
125826            },
125827            "quantitativeAnalysis": {
125828              "graphics": {}
125829            },
125830            "considerations": {}
125831          }
125832        },
125833        {
125834          "type": "library",
125835          "bom-ref": "pkg:npm/ultron@1.1.1?package-id=ae7d41536eb1a830",
125836          "supplier": {},
125837          "author": "Arnout Kazemier",
125838          "name": "ultron",
125839          "version": "1.1.1",
125840          "description": "Ultron is high-intelligence robot. It gathers intel so it can start improving upon his rudimentary design",
125841          "licenses": [
125842            {
125843              "license": {
125844                "id": "MIT"
125845              }
125846            }
125847          ],
125848          "cpe": "cpe:2.3:a:unshiftio:ultron:1.1.1:*:*:*:*:*:*:*",
125849          "purl": "pkg:npm/ultron@1.1.1",
125850          "swid": {
125851            "attachment": {}
125852          },
125853          "pedigree": {},
125854          "externalReferences": [
125855            {
125856              "url": "https://github.com/unshiftio/ultron",
125857              "type": "distribution"
125858            },
125859            {
125860              "url": "https://github.com/unshiftio/ultron",
125861              "type": "website"
125862            }
125863          ],
125864          "evidence": {},
125865          "signature": {
125866            "signature": {
125867              "publicKey": {}
125868            }
125869          },
125870          "modelCard": {
125871            "modelParameters": {
125872              "approach": {}
125873            },
125874            "quantitativeAnalysis": {
125875              "graphics": {}
125876            },
125877            "considerations": {}
125878          }
125879        },
125880        {
125881          "type": "library",
125882          "bom-ref": "pkg:npm/unique-filename@2.0.1?package-id=ddbea63cf5bc0343",
125883          "supplier": {},
125884          "author": "GitHub Inc.",
125885          "name": "unique-filename",
125886          "version": "2.0.1",
125887          "description": "Generate a unique filename for use in temporary directories or caches.",
125888          "licenses": [
125889            {
125890              "license": {
125891                "id": "ISC"
125892              }
125893            }
125894          ],
125895          "cpe": "cpe:2.3:a:unique-filename:unique-filename:2.0.1:*:*:*:*:*:*:*",
125896          "purl": "pkg:npm/unique-filename@2.0.1",
125897          "swid": {
125898            "attachment": {}
125899          },
125900          "pedigree": {},
125901          "externalReferences": [
125902            {
125903              "url": "https://github.com/npm/unique-filename.git",
125904              "type": "distribution"
125905            },
125906            {
125907              "url": "https://github.com/iarna/unique-filename",
125908              "type": "website"
125909            }
125910          ],
125911          "evidence": {},
125912          "signature": {
125913            "signature": {
125914              "publicKey": {}
125915            }
125916          },
125917          "modelCard": {
125918            "modelParameters": {
125919              "approach": {}
125920            },
125921            "quantitativeAnalysis": {
125922              "graphics": {}
125923            },
125924            "considerations": {}
125925          }
125926        },
125927        {
125928          "type": "library",
125929          "bom-ref": "pkg:npm/unique-slug@3.0.0?package-id=a61e6b90d7850f42",
125930          "supplier": {},
125931          "author": "GitHub Inc.",
125932          "name": "unique-slug",
125933          "version": "3.0.0",
125934          "description": "Generate a unique character string suitible for use in files and URLs.",
125935          "licenses": [
125936            {
125937              "license": {
125938                "id": "ISC"
125939              }
125940            }
125941          ],
125942          "cpe": "cpe:2.3:a:unique-slug:unique-slug:3.0.0:*:*:*:*:*:*:*",
125943          "purl": "pkg:npm/unique-slug@3.0.0",
125944          "swid": {
125945            "attachment": {}
125946          },
125947          "pedigree": {},
125948          "externalReferences": [
125949            {
125950              "url": "https://github.com/npm/unique-slug.git",
125951              "type": "distribution"
125952            }
125953          ],
125954          "evidence": {},
125955          "signature": {
125956            "signature": {
125957              "publicKey": {}
125958            }
125959          },
125960          "modelCard": {
125961            "modelParameters": {
125962              "approach": {}
125963            },
125964            "quantitativeAnalysis": {
125965              "graphics": {}
125966            },
125967            "considerations": {}
125968          }
125969        },
125970        {
125971          "type": "library",
125972          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=adcfe60f42b3bf40",
125973          "supplier": {},
125974          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
125975          "name": "util-deprecate",
125976          "version": "1.0.2",
125977          "description": "The Node.js `util.deprecate()` function with browser support",
125978          "licenses": [
125979            {
125980              "license": {
125981                "id": "MIT"
125982              }
125983            }
125984          ],
125985          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
125986          "purl": "pkg:npm/util-deprecate@1.0.2",
125987          "swid": {
125988            "attachment": {}
125989          },
125990          "pedigree": {},
125991          "externalReferences": [
125992            {
125993              "url": "git://github.com/TooTallNate/util-deprecate.git",
125994              "type": "distribution"
125995            },
125996            {
125997              "url": "https://github.com/TooTallNate/util-deprecate",
125998              "type": "website"
125999            }
126000          ],
126001          "evidence": {},
126002          "signature": {
126003            "signature": {
126004              "publicKey": {}
126005            }
126006          },
126007          "modelCard": {
126008            "modelParameters": {
126009              "approach": {}
126010            },
126011            "quantitativeAnalysis": {
126012              "graphics": {}
126013            },
126014            "considerations": {}
126015          }
126016        },
126017        {
126018          "type": "library",
126019          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=ecf076cf26fe73d0",
126020          "supplier": {},
126021          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
126022          "name": "util-deprecate",
126023          "version": "1.0.2",
126024          "description": "The Node.js `util.deprecate()` function with browser support",
126025          "licenses": [
126026            {
126027              "license": {
126028                "id": "MIT"
126029              }
126030            }
126031          ],
126032          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
126033          "purl": "pkg:npm/util-deprecate@1.0.2",
126034          "swid": {
126035            "attachment": {}
126036          },
126037          "pedigree": {},
126038          "externalReferences": [
126039            {
126040              "url": "git://github.com/TooTallNate/util-deprecate.git",
126041              "type": "distribution"
126042            },
126043            {
126044              "url": "https://github.com/TooTallNate/util-deprecate",
126045              "type": "website"
126046            }
126047          ],
126048          "evidence": {},
126049          "signature": {
126050            "signature": {
126051              "publicKey": {}
126052            }
126053          },
126054          "modelCard": {
126055            "modelParameters": {
126056              "approach": {}
126057            },
126058            "quantitativeAnalysis": {
126059              "graphics": {}
126060            },
126061            "considerations": {}
126062          }
126063        },
126064        {
126065          "type": "library",
126066          "bom-ref": "pkg:npm/validate-npm-package-license@3.0.4?package-id=fa90b625ec15ead",
126067          "supplier": {},
126068          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
126069          "name": "validate-npm-package-license",
126070          "version": "3.0.4",
126071          "description": "Give me a string and I'll tell you if it's a valid npm package license string",
126072          "licenses": [
126073            {
126074              "license": {
126075                "id": "Apache-2.0"
126076              }
126077            }
126078          ],
126079          "cpe": "cpe:2.3:a:validate-npm-package-license:validate-npm-package-license:3.0.4:*:*:*:*:*:*:*",
126080          "purl": "pkg:npm/validate-npm-package-license@3.0.4",
126081          "swid": {
126082            "attachment": {}
126083          },
126084          "pedigree": {},
126085          "externalReferences": [
126086            {
126087              "url": "kemitchell/validate-npm-package-license.js",
126088              "type": "distribution"
126089            }
126090          ],
126091          "evidence": {},
126092          "signature": {
126093            "signature": {
126094              "publicKey": {}
126095            }
126096          },
126097          "modelCard": {
126098            "modelParameters": {
126099              "approach": {}
126100            },
126101            "quantitativeAnalysis": {
126102              "graphics": {}
126103            },
126104            "considerations": {}
126105          }
126106        },
126107        {
126108          "type": "library",
126109          "bom-ref": "pkg:npm/validate-npm-package-name@4.0.0?package-id=dc3a9f2b7a700330",
126110          "supplier": {},
126111          "author": "GitHub Inc.",
126112          "name": "validate-npm-package-name",
126113          "version": "4.0.0",
126114          "description": "Give me a string and I'll tell you if it's a valid npm package name",
126115          "licenses": [
126116            {
126117              "license": {
126118                "id": "ISC"
126119              }
126120            }
126121          ],
126122          "cpe": "cpe:2.3:a:validate-npm-package-name:validate-npm-package-name:4.0.0:*:*:*:*:*:*:*",
126123          "purl": "pkg:npm/validate-npm-package-name@4.0.0",
126124          "swid": {
126125            "attachment": {}
126126          },
126127          "pedigree": {},
126128          "externalReferences": [
126129            {
126130              "url": "https://github.com/npm/validate-npm-package-name.git",
126131              "type": "distribution"
126132            },
126133            {
126134              "url": "https://github.com/npm/validate-npm-package-name",
126135              "type": "website"
126136            }
126137          ],
126138          "evidence": {},
126139          "signature": {
126140            "signature": {
126141              "publicKey": {}
126142            }
126143          },
126144          "modelCard": {
126145            "modelParameters": {
126146              "approach": {}
126147            },
126148            "quantitativeAnalysis": {
126149              "graphics": {}
126150            },
126151            "considerations": {}
126152          }
126153        },
126154        {
126155          "type": "library",
126156          "bom-ref": "pkg:npm/walk-up-path@1.0.0?package-id=9a8dd6f20b12184f",
126157          "supplier": {},
126158          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
126159          "name": "walk-up-path",
126160          "version": "1.0.0",
126161          "description": "Given a path string, return a generator that walks up the path, emitting each dirname.",
126162          "licenses": [
126163            {
126164              "license": {
126165                "id": "ISC"
126166              }
126167            }
126168          ],
126169          "cpe": "cpe:2.3:a:walk-up-path:walk-up-path:1.0.0:*:*:*:*:*:*:*",
126170          "purl": "pkg:npm/walk-up-path@1.0.0",
126171          "swid": {
126172            "attachment": {}
126173          },
126174          "pedigree": {},
126175          "externalReferences": [
126176            {
126177              "url": "git+https://github.com/isaacs/walk-up-path",
126178              "type": "distribution"
126179            }
126180          ],
126181          "evidence": {},
126182          "signature": {
126183            "signature": {
126184              "publicKey": {}
126185            }
126186          },
126187          "modelCard": {
126188            "modelParameters": {
126189              "approach": {}
126190            },
126191            "quantitativeAnalysis": {
126192              "graphics": {}
126193            },
126194            "considerations": {}
126195          }
126196        },
126197        {
126198          "type": "library",
126199          "bom-ref": "pkg:npm/wcwidth@1.0.1?package-id=ee54c63162090e16",
126200          "supplier": {},
126201          "author": "Tim Oxley",
126202          "name": "wcwidth",
126203          "version": "1.0.1",
126204          "description": "Port of C's wcwidth() and wcswidth()",
126205          "licenses": [
126206            {
126207              "license": {
126208                "id": "MIT"
126209              }
126210            }
126211          ],
126212          "cpe": "cpe:2.3:a:timoxley:wcwidth:1.0.1:*:*:*:*:*:*:*",
126213          "purl": "pkg:npm/wcwidth@1.0.1",
126214          "swid": {
126215            "attachment": {}
126216          },
126217          "pedigree": {},
126218          "externalReferences": [
126219            {
126220              "url": "git+https://github.com/timoxley/wcwidth.git",
126221              "type": "distribution"
126222            },
126223            {
126224              "url": "https://github.com/timoxley/wcwidth#readme",
126225              "type": "website"
126226            }
126227          ],
126228          "evidence": {},
126229          "signature": {
126230            "signature": {
126231              "publicKey": {}
126232            }
126233          },
126234          "modelCard": {
126235            "modelParameters": {
126236              "approach": {}
126237            },
126238            "quantitativeAnalysis": {
126239              "graphics": {}
126240            },
126241            "considerations": {}
126242          }
126243        },
126244        {
126245          "type": "library",
126246          "bom-ref": "pkg:npm/websocket-stream@5.5.2?package-id=7fdacabad23a7eaa",
126247          "supplier": {},
126248          "name": "websocket-stream",
126249          "version": "5.5.2",
126250          "description": "Use websockets with the node streams API. Works in browser and node",
126251          "licenses": [
126252            {
126253              "license": {
126254                "id": "BSD-2-Clause"
126255              }
126256            }
126257          ],
126258          "cpe": "cpe:2.3:a:websocket-stream:websocket-stream:5.5.2:*:*:*:*:*:*:*",
126259          "purl": "pkg:npm/websocket-stream@5.5.2",
126260          "swid": {
126261            "attachment": {}
126262          },
126263          "pedigree": {},
126264          "externalReferences": [
126265            {
126266              "url": "git+ssh://git@github.com/maxogden/websocket-stream.git",
126267              "type": "distribution"
126268            },
126269            {
126270              "url": "https://github.com/maxogden/websocket-stream#readme",
126271              "type": "website"
126272            }
126273          ],
126274          "evidence": {},
126275          "signature": {
126276            "signature": {
126277              "publicKey": {}
126278            }
126279          },
126280          "modelCard": {
126281            "modelParameters": {
126282              "approach": {}
126283            },
126284            "quantitativeAnalysis": {
126285              "graphics": {}
126286            },
126287            "considerations": {}
126288          }
126289        },
126290        {
126291          "type": "library",
126292          "bom-ref": "pkg:npm/which@2.0.2?package-id=1d2beaa974655b97",
126293          "supplier": {},
126294          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
126295          "name": "which",
126296          "version": "2.0.2",
126297          "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
126298          "licenses": [
126299            {
126300              "license": {
126301                "id": "ISC"
126302              }
126303            }
126304          ],
126305          "cpe": "cpe:2.3:a:isaacs:which:2.0.2:*:*:*:*:*:*:*",
126306          "purl": "pkg:npm/which@2.0.2",
126307          "swid": {
126308            "attachment": {}
126309          },
126310          "pedigree": {},
126311          "externalReferences": [
126312            {
126313              "url": "git://github.com/isaacs/node-which.git",
126314              "type": "distribution"
126315            }
126316          ],
126317          "evidence": {},
126318          "signature": {
126319            "signature": {
126320              "publicKey": {}
126321            }
126322          },
126323          "modelCard": {
126324            "modelParameters": {
126325              "approach": {}
126326            },
126327            "quantitativeAnalysis": {
126328              "graphics": {}
126329            },
126330            "considerations": {}
126331          }
126332        },
126333        {
126334          "type": "library",
126335          "bom-ref": "pkg:npm/wide-align@1.1.5?package-id=f0bd5200e29a21be",
126336          "supplier": {},
126337          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
126338          "name": "wide-align",
126339          "version": "1.1.5",
126340          "description": "A wide-character aware text alignment function for use on the console or with fixed width fonts.",
126341          "licenses": [
126342            {
126343              "license": {
126344                "id": "ISC"
126345              }
126346            }
126347          ],
126348          "cpe": "cpe:2.3:a:wide-align:wide-align:1.1.5:*:*:*:*:*:*:*",
126349          "purl": "pkg:npm/wide-align@1.1.5",
126350          "swid": {
126351            "attachment": {}
126352          },
126353          "pedigree": {},
126354          "externalReferences": [
126355            {
126356              "url": "https://github.com/iarna/wide-align",
126357              "type": "distribution"
126358            }
126359          ],
126360          "evidence": {},
126361          "signature": {
126362            "signature": {
126363              "publicKey": {}
126364            }
126365          },
126366          "modelCard": {
126367            "modelParameters": {
126368              "approach": {}
126369            },
126370            "quantitativeAnalysis": {
126371              "graphics": {}
126372            },
126373            "considerations": {}
126374          }
126375        },
126376        {
126377          "type": "library",
126378          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=ce6ead4039a1b1e8",
126379          "supplier": {},
126380          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
126381          "name": "wrappy",
126382          "version": "1.0.2",
126383          "description": "Callback wrapping utility",
126384          "licenses": [
126385            {
126386              "license": {
126387                "id": "ISC"
126388              }
126389            }
126390          ],
126391          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
126392          "purl": "pkg:npm/wrappy@1.0.2",
126393          "swid": {
126394            "attachment": {}
126395          },
126396          "pedigree": {},
126397          "externalReferences": [
126398            {
126399              "url": "https://github.com/npm/wrappy",
126400              "type": "distribution"
126401            },
126402            {
126403              "url": "https://github.com/npm/wrappy",
126404              "type": "website"
126405            }
126406          ],
126407          "evidence": {},
126408          "signature": {
126409            "signature": {
126410              "publicKey": {}
126411            }
126412          },
126413          "modelCard": {
126414            "modelParameters": {
126415              "approach": {}
126416            },
126417            "quantitativeAnalysis": {
126418              "graphics": {}
126419            },
126420            "considerations": {}
126421          }
126422        },
126423        {
126424          "type": "library",
126425          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=88b7c304022dd8b8",
126426          "supplier": {},
126427          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
126428          "name": "wrappy",
126429          "version": "1.0.2",
126430          "description": "Callback wrapping utility",
126431          "licenses": [
126432            {
126433              "license": {
126434                "id": "ISC"
126435              }
126436            }
126437          ],
126438          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
126439          "purl": "pkg:npm/wrappy@1.0.2",
126440          "swid": {
126441            "attachment": {}
126442          },
126443          "pedigree": {},
126444          "externalReferences": [
126445            {
126446              "url": "https://github.com/npm/wrappy",
126447              "type": "distribution"
126448            },
126449            {
126450              "url": "https://github.com/npm/wrappy",
126451              "type": "website"
126452            }
126453          ],
126454          "evidence": {},
126455          "signature": {
126456            "signature": {
126457              "publicKey": {}
126458            }
126459          },
126460          "modelCard": {
126461            "modelParameters": {
126462              "approach": {}
126463            },
126464            "quantitativeAnalysis": {
126465              "graphics": {}
126466            },
126467            "considerations": {}
126468          }
126469        },
126470        {
126471          "type": "library",
126472          "bom-ref": "pkg:npm/write-file-atomic@4.0.2?package-id=401a0baef0d4f8db",
126473          "supplier": {},
126474          "author": "GitHub Inc.",
126475          "name": "write-file-atomic",
126476          "version": "4.0.2",
126477          "description": "Write files in an atomic fashion w/configurable ownership",
126478          "licenses": [
126479            {
126480              "license": {
126481                "id": "ISC"
126482              }
126483            }
126484          ],
126485          "cpe": "cpe:2.3:a:write-file-atomic:write-file-atomic:4.0.2:*:*:*:*:*:*:*",
126486          "purl": "pkg:npm/write-file-atomic@4.0.2",
126487          "swid": {
126488            "attachment": {}
126489          },
126490          "pedigree": {},
126491          "externalReferences": [
126492            {
126493              "url": "https://github.com/npm/write-file-atomic.git",
126494              "type": "distribution"
126495            },
126496            {
126497              "url": "https://github.com/npm/write-file-atomic",
126498              "type": "website"
126499            }
126500          ],
126501          "evidence": {},
126502          "signature": {
126503            "signature": {
126504              "publicKey": {}
126505            }
126506          },
126507          "modelCard": {
126508            "modelParameters": {
126509              "approach": {}
126510            },
126511            "quantitativeAnalysis": {
126512              "graphics": {}
126513            },
126514            "considerations": {}
126515          }
126516        },
126517        {
126518          "type": "library",
126519          "bom-ref": "pkg:npm/ws@3.3.3?package-id=efcc73cb0f0d4333",
126520          "supplier": {},
126521          "author": "Einar Otto Stangvik \u003ceinaros@gmail.com\u003e (http://2x.io)",
126522          "name": "ws",
126523          "version": "3.3.3",
126524          "description": "Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js",
126525          "licenses": [
126526            {
126527              "license": {
126528                "id": "MIT"
126529              }
126530            }
126531          ],
126532          "cpe": "cpe:2.3:a:websockets:ws:3.3.3:*:*:*:*:*:*:*",
126533          "purl": "pkg:npm/ws@3.3.3",
126534          "swid": {
126535            "attachment": {}
126536          },
126537          "pedigree": {},
126538          "externalReferences": [
126539            {
126540              "url": "websockets/ws",
126541              "type": "distribution"
126542            },
126543            {
126544              "url": "https://github.com/websockets/ws",
126545              "type": "website"
126546            }
126547          ],
126548          "evidence": {},
126549          "signature": {
126550            "signature": {
126551              "publicKey": {}
126552            }
126553          },
126554          "modelCard": {
126555            "modelParameters": {
126556              "approach": {}
126557            },
126558            "quantitativeAnalysis": {
126559              "graphics": {}
126560            },
126561            "considerations": {}
126562          }
126563        },
126564        {
126565          "type": "library",
126566          "bom-ref": "pkg:npm/xtend@4.0.2?package-id=806268954298f9d0",
126567          "supplier": {},
126568          "author": "Raynos \u003craynos2@gmail.com\u003e",
126569          "name": "xtend",
126570          "version": "4.0.2",
126571          "description": "extend like a boss",
126572          "licenses": [
126573            {
126574              "license": {
126575                "id": "MIT"
126576              }
126577            }
126578          ],
126579          "cpe": "cpe:2.3:a:Raynos:xtend:4.0.2:*:*:*:*:*:*:*",
126580          "purl": "pkg:npm/xtend@4.0.2",
126581          "swid": {
126582            "attachment": {}
126583          },
126584          "pedigree": {},
126585          "externalReferences": [
126586            {
126587              "url": "git://github.com/Raynos/xtend.git",
126588              "type": "distribution"
126589            },
126590            {
126591              "url": "https://github.com/Raynos/xtend",
126592              "type": "website"
126593            }
126594          ],
126595          "evidence": {},
126596          "signature": {
126597            "signature": {
126598              "publicKey": {}
126599            }
126600          },
126601          "modelCard": {
126602            "modelParameters": {
126603              "approach": {}
126604            },
126605            "quantitativeAnalysis": {
126606              "graphics": {}
126607            },
126608            "considerations": {}
126609          }
126610        },
126611        {
126612          "type": "library",
126613          "bom-ref": "pkg:npm/yallist@4.0.0?package-id=c5b3d2829d8d6201",
126614          "supplier": {},
126615          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
126616          "name": "yallist",
126617          "version": "4.0.0",
126618          "description": "Yet Another Linked List",
126619          "licenses": [
126620            {
126621              "license": {
126622                "id": "ISC"
126623              }
126624            }
126625          ],
126626          "cpe": "cpe:2.3:a:yallist:yallist:4.0.0:*:*:*:*:*:*:*",
126627          "purl": "pkg:npm/yallist@4.0.0",
126628          "swid": {
126629            "attachment": {}
126630          },
126631          "pedigree": {},
126632          "externalReferences": [
126633            {
126634              "url": "git+https://github.com/isaacs/yallist.git",
126635              "type": "distribution"
126636            }
126637          ],
126638          "evidence": {},
126639          "signature": {
126640            "signature": {
126641              "publicKey": {}
126642            }
126643          },
126644          "modelCard": {
126645            "modelParameters": {
126646              "approach": {}
126647            },
126648            "quantitativeAnalysis": {
126649              "graphics": {}
126650            },
126651            "considerations": {}
126652          }
126653        },
126654        {
126655          "type": "library",
126656          "bom-ref": "pkg:npm/yarn@1.22.19?package-id=f2b974a78000b26b",
126657          "supplier": {},
126658          "name": "yarn",
126659          "version": "1.22.19",
126660          "description": "📦🐈 Fast, reliable, and secure dependency management.",
126661          "licenses": [
126662            {
126663              "license": {
126664                "id": "BSD-2-Clause"
126665              }
126666            }
126667          ],
126668          "cpe": "cpe:2.3:a:yarn:yarn:1.22.19:*:*:*:*:*:*:*",
126669          "purl": "pkg:npm/yarn@1.22.19",
126670          "swid": {
126671            "attachment": {}
126672          },
126673          "pedigree": {},
126674          "externalReferences": [
126675            {
126676              "url": "yarnpkg/yarn",
126677              "type": "distribution"
126678            }
126679          ],
126680          "evidence": {},
126681          "signature": {
126682            "signature": {
126683              "publicKey": {}
126684            }
126685          },
126686          "modelCard": {
126687            "modelParameters": {
126688              "approach": {}
126689            },
126690            "quantitativeAnalysis": {
126691              "graphics": {}
126692            },
126693            "considerations": {}
126694          }
126695        },
126696        {
126697          "type": "library",
126698          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=75f0d92f695b4303",
126699          "supplier": {},
126700          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
126701          "name": "zlib",
126702          "version": "1.2.12-r3",
126703          "description": "A compression/decompression Library",
126704          "licenses": [
126705            {
126706              "license": {
126707                "id": "Zlib"
126708              }
126709            }
126710          ],
126711          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
126712          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5",
126713          "swid": {
126714            "attachment": {}
126715          },
126716          "pedigree": {},
126717          "externalReferences": [
126718            {
126719              "url": "https://zlib.net/",
126720              "type": "distribution"
126721            }
126722          ],
126723          "evidence": {},
126724          "signature": {
126725            "signature": {
126726              "publicKey": {}
126727            }
126728          },
126729          "modelCard": {
126730            "modelParameters": {
126731              "approach": {}
126732            },
126733            "quantitativeAnalysis": {
126734              "graphics": {}
126735            },
126736            "considerations": {}
126737          }
126738        },
126739        {
126740          "type": "operating-system",
126741          "supplier": {},
126742          "name": "alpine",
126743          "version": "3.16.5",
126744          "description": "Alpine Linux v3.16",
126745          "swid": {
126746            "tagId": "alpine",
126747            "name": "alpine",
126748            "version": "3.16.5",
126749            "attachment": {}
126750          },
126751          "pedigree": {},
126752          "externalReferences": [
126753            {
126754              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
126755              "type": "issue-tracker"
126756            },
126757            {
126758              "url": "https://alpinelinux.org/",
126759              "type": "website"
126760            }
126761          ],
126762          "evidence": {},
126763          "signature": {
126764            "signature": {
126765              "publicKey": {}
126766            }
126767          },
126768          "modelCard": {
126769            "modelParameters": {
126770              "approach": {}
126771            },
126772            "quantitativeAnalysis": {
126773              "graphics": {}
126774            },
126775            "considerations": {}
126776          }
126777        },
126778        {
126779          "type": "library",
126780          "bom-ref": "pkg:maven/US_export_policy/US_export_policy?package-id=6b95b2812763991f",
126781          "supplier": {},
126782          "name": "US_export_policy",
126783          "cpe": "cpe:2.3:a:US-export-policy:US-export-policy:*:*:*:*:*:*:*:*",
126784          "purl": "pkg:maven/US_export_policy/US_export_policy",
126785          "swid": {
126786            "attachment": {}
126787          },
126788          "pedigree": {},
126789          "externalReferences": [
126790            {
126791              "type": "build-meta",
126792              "hashes": [
126793                {
126794                  "alg": "SHA-1",
126795                  "content": "8e0a479b10f5d9ff8cb1c42e597b1f2be67e529e"
126796                }
126797              ]
126798            }
126799          ],
126800          "evidence": {},
126801          "signature": {
126802            "signature": {
126803              "publicKey": {}
126804            }
126805          },
126806          "modelCard": {
126807            "modelParameters": {
126808              "approach": {}
126809            },
126810            "quantitativeAnalysis": {
126811              "graphics": {}
126812            },
126813            "considerations": {}
126814          }
126815        },
126816        {
126817          "type": "library",
126818          "bom-ref": "pkg:maven/US_export_policy/US_export_policy?package-id=870c14eda8614328",
126819          "supplier": {},
126820          "name": "US_export_policy",
126821          "cpe": "cpe:2.3:a:US-export-policy:US-export-policy:*:*:*:*:*:*:*:*",
126822          "purl": "pkg:maven/US_export_policy/US_export_policy",
126823          "swid": {
126824            "attachment": {}
126825          },
126826          "pedigree": {},
126827          "externalReferences": [
126828            {
126829              "type": "build-meta",
126830              "hashes": [
126831                {
126832                  "alg": "SHA-1",
126833                  "content": "8e0a479b10f5d9ff8cb1c42e597b1f2be67e529e"
126834                }
126835              ]
126836            }
126837          ],
126838          "evidence": {},
126839          "signature": {
126840            "signature": {
126841              "publicKey": {}
126842            }
126843          },
126844          "modelCard": {
126845            "modelParameters": {
126846              "approach": {}
126847            },
126848            "quantitativeAnalysis": {
126849              "graphics": {}
126850            },
126851            "considerations": {}
126852          }
126853        },
126854        {
126855          "type": "library",
126856          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.1.0-r3?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=c1681612500d2a5f",
126857          "supplier": {},
126858          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
126859          "name": "alpine-baselayout",
126860          "version": "3.1.0-r3",
126861          "description": "Alpine base dir structure and init scripts",
126862          "licenses": [
126863            {
126864              "license": {
126865                "id": "GPL-2.0-only"
126866              }
126867            }
126868          ],
126869          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.1.0-r3:*:*:*:*:*:*:*",
126870          "purl": "pkg:apk/alpine/alpine-baselayout@3.1.0-r3?arch=x86_64\u0026distro=alpine-3.9.4",
126871          "swid": {
126872            "attachment": {}
126873          },
126874          "pedigree": {},
126875          "externalReferences": [
126876            {
126877              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
126878              "type": "distribution"
126879            }
126880          ],
126881          "evidence": {},
126882          "signature": {
126883            "signature": {
126884              "publicKey": {}
126885            }
126886          },
126887          "modelCard": {
126888            "modelParameters": {
126889              "approach": {}
126890            },
126891            "quantitativeAnalysis": {
126892              "graphics": {}
126893            },
126894            "considerations": {}
126895          }
126896        },
126897        {
126898          "type": "library",
126899          "bom-ref": "pkg:apk/alpine/alpine-keys@2.1-r1?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=97e2cc5f95031f4f",
126900          "supplier": {},
126901          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
126902          "name": "alpine-keys",
126903          "version": "2.1-r1",
126904          "description": "Public keys for Alpine Linux packages",
126905          "licenses": [
126906            {
126907              "license": {
126908                "id": "MIT"
126909              }
126910            }
126911          ],
126912          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.1-r1:*:*:*:*:*:*:*",
126913          "purl": "pkg:apk/alpine/alpine-keys@2.1-r1?arch=x86_64\u0026distro=alpine-3.9.4",
126914          "swid": {
126915            "attachment": {}
126916          },
126917          "pedigree": {},
126918          "externalReferences": [
126919            {
126920              "url": "http://alpinelinux.org",
126921              "type": "distribution"
126922            }
126923          ],
126924          "evidence": {},
126925          "signature": {
126926            "signature": {
126927              "publicKey": {}
126928            }
126929          },
126930          "modelCard": {
126931            "modelParameters": {
126932              "approach": {}
126933            },
126934            "quantitativeAnalysis": {
126935              "graphics": {}
126936            },
126937            "considerations": {}
126938          }
126939        },
126940        {
126941          "type": "library",
126942          "bom-ref": "pkg:apk/alpine/alsa-lib@1.1.8-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=3d9fdb578832e1cb",
126943          "supplier": {},
126944          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
126945          "name": "alsa-lib",
126946          "version": "1.1.8-r0",
126947          "description": "Advanced Linux Sound Architecture (ALSA) library",
126948          "licenses": [
126949            {
126950              "license": {
126951                "id": "LGPL-2.1-or-later"
126952              }
126953            }
126954          ],
126955          "cpe": "cpe:2.3:a:alsa-project:alsa-lib:1.1.8-r0:*:*:*:*:*:*:*",
126956          "purl": "pkg:apk/alpine/alsa-lib@1.1.8-r0?arch=x86_64\u0026distro=alpine-3.9.4",
126957          "swid": {
126958            "attachment": {}
126959          },
126960          "pedigree": {},
126961          "externalReferences": [
126962            {
126963              "url": "http://www.alsa-project.org",
126964              "type": "distribution"
126965            }
126966          ],
126967          "evidence": {},
126968          "signature": {
126969            "signature": {
126970              "publicKey": {}
126971            }
126972          },
126973          "modelCard": {
126974            "modelParameters": {
126975              "approach": {}
126976            },
126977            "quantitativeAnalysis": {
126978              "graphics": {}
126979            },
126980            "considerations": {}
126981          }
126982        },
126983        {
126984          "type": "library",
126985          "bom-ref": "pkg:apk/alpine/apk-tools@2.10.3-r1?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=4304c9827dad66db",
126986          "supplier": {},
126987          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
126988          "name": "apk-tools",
126989          "version": "2.10.3-r1",
126990          "description": "Alpine Package Keeper - package manager for alpine",
126991          "licenses": [
126992            {
126993              "license": {
126994                "id": "GPL-2.0-only"
126995              }
126996            }
126997          ],
126998          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.10.3-r1:*:*:*:*:*:*:*",
126999          "purl": "pkg:apk/alpine/apk-tools@2.10.3-r1?arch=x86_64\u0026distro=alpine-3.9.4",
127000          "swid": {
127001            "attachment": {}
127002          },
127003          "pedigree": {},
127004          "externalReferences": [
127005            {
127006              "url": "https://git.alpinelinux.org/cgit/apk-tools/",
127007              "type": "distribution"
127008            }
127009          ],
127010          "evidence": {},
127011          "signature": {
127012            "signature": {
127013              "publicKey": {}
127014            }
127015          },
127016          "modelCard": {
127017            "modelParameters": {
127018              "approach": {}
127019            },
127020            "quantitativeAnalysis": {
127021              "graphics": {}
127022            },
127023            "considerations": {}
127024          }
127025        },
127026        {
127027          "type": "application",
127028          "bom-ref": "a8f085f759193e56",
127029          "supplier": {},
127030          "name": "busybox",
127031          "version": "1.29.3",
127032          "cpe": "cpe:2.3:a:busybox:busybox:1.29.3:*:*:*:*:*:*:*",
127033          "swid": {
127034            "attachment": {}
127035          },
127036          "pedigree": {},
127037          "evidence": {},
127038          "signature": {
127039            "signature": {
127040              "publicKey": {}
127041            }
127042          },
127043          "modelCard": {
127044            "modelParameters": {
127045              "approach": {}
127046            },
127047            "quantitativeAnalysis": {
127048              "graphics": {}
127049            },
127050            "considerations": {}
127051          }
127052        },
127053        {
127054          "type": "library",
127055          "bom-ref": "pkg:apk/alpine/busybox@1.29.3-r10?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=731a07abb126ae58",
127056          "supplier": {},
127057          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127058          "name": "busybox",
127059          "version": "1.29.3-r10",
127060          "description": "Size optimized toolbox of many common UNIX utilities",
127061          "licenses": [
127062            {
127063              "license": {
127064                "id": "GPL-2.0-only"
127065              }
127066            }
127067          ],
127068          "cpe": "cpe:2.3:a:busybox:busybox:1.29.3-r10:*:*:*:*:*:*:*",
127069          "purl": "pkg:apk/alpine/busybox@1.29.3-r10?arch=x86_64\u0026distro=alpine-3.9.4",
127070          "swid": {
127071            "attachment": {}
127072          },
127073          "pedigree": {},
127074          "externalReferences": [
127075            {
127076              "url": "http://busybox.net",
127077              "type": "distribution"
127078            }
127079          ],
127080          "evidence": {},
127081          "signature": {
127082            "signature": {
127083              "publicKey": {}
127084            }
127085          },
127086          "modelCard": {
127087            "modelParameters": {
127088              "approach": {}
127089            },
127090            "quantitativeAnalysis": {
127091              "graphics": {}
127092            },
127093            "considerations": {}
127094          }
127095        },
127096        {
127097          "type": "library",
127098          "bom-ref": "pkg:apk/alpine/ca-certificates@20190108-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=8968181f62df7bf4",
127099          "supplier": {},
127100          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127101          "name": "ca-certificates",
127102          "version": "20190108-r0",
127103          "description": "Common CA certificates PEM files",
127104          "licenses": [
127105            {
127106              "license": {
127107                "id": "MPL-2.0"
127108              }
127109            },
127110            {
127111              "license": {
127112                "id": "GPL-2.0-or-later"
127113              }
127114            }
127115          ],
127116          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20190108-r0:*:*:*:*:*:*:*",
127117          "purl": "pkg:apk/alpine/ca-certificates@20190108-r0?arch=x86_64\u0026distro=alpine-3.9.4",
127118          "swid": {
127119            "attachment": {}
127120          },
127121          "pedigree": {},
127122          "externalReferences": [
127123            {
127124              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
127125              "type": "distribution"
127126            }
127127          ],
127128          "evidence": {},
127129          "signature": {
127130            "signature": {
127131              "publicKey": {}
127132            }
127133          },
127134          "modelCard": {
127135            "modelParameters": {
127136              "approach": {}
127137            },
127138            "quantitativeAnalysis": {
127139              "graphics": {}
127140            },
127141            "considerations": {}
127142          }
127143        },
127144        {
127145          "type": "library",
127146          "bom-ref": "pkg:apk/alpine/ca-certificates-cacert@20190108-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.9.4\u0026package-id=ae8340d6e803e072",
127147          "supplier": {},
127148          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127149          "name": "ca-certificates-cacert",
127150          "version": "20190108-r0",
127151          "description": "Mozilla bundled certificates",
127152          "licenses": [
127153            {
127154              "license": {
127155                "id": "MPL-2.0"
127156              }
127157            },
127158            {
127159              "license": {
127160                "id": "GPL-2.0-or-later"
127161              }
127162            }
127163          ],
127164          "cpe": "cpe:2.3:a:ca-certificates-cacert:ca-certificates-cacert:20190108-r0:*:*:*:*:*:*:*",
127165          "purl": "pkg:apk/alpine/ca-certificates-cacert@20190108-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.9.4",
127166          "swid": {
127167            "attachment": {}
127168          },
127169          "pedigree": {},
127170          "externalReferences": [
127171            {
127172              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
127173              "type": "distribution"
127174            }
127175          ],
127176          "evidence": {},
127177          "signature": {
127178            "signature": {
127179              "publicKey": {}
127180            }
127181          },
127182          "modelCard": {
127183            "modelParameters": {
127184              "approach": {}
127185            },
127186            "quantitativeAnalysis": {
127187              "graphics": {}
127188            },
127189            "considerations": {}
127190          }
127191        },
127192        {
127193          "type": "library",
127194          "bom-ref": "pkg:maven/charsets/charsets?package-id=cb237d1b56b1b665",
127195          "supplier": {},
127196          "name": "charsets",
127197          "cpe": "cpe:2.3:a:charsets:charsets:*:*:*:*:*:*:*:*",
127198          "purl": "pkg:maven/charsets/charsets",
127199          "swid": {
127200            "attachment": {}
127201          },
127202          "pedigree": {},
127203          "externalReferences": [
127204            {
127205              "type": "build-meta",
127206              "hashes": [
127207                {
127208                  "alg": "SHA-1",
127209                  "content": "01bd4339bc27a8b7adaee968edfc646b925b2e0a"
127210                }
127211              ]
127212            }
127213          ],
127214          "evidence": {},
127215          "signature": {
127216            "signature": {
127217              "publicKey": {}
127218            }
127219          },
127220          "modelCard": {
127221            "modelParameters": {
127222              "approach": {}
127223            },
127224            "quantitativeAnalysis": {
127225              "graphics": {}
127226            },
127227            "considerations": {}
127228          }
127229        },
127230        {
127231          "type": "library",
127232          "bom-ref": "pkg:maven/cldrdata/cldrdata?package-id=2d74d1551f63c0cf",
127233          "supplier": {},
127234          "name": "cldrdata",
127235          "cpe": "cpe:2.3:a:cldrdata:cldrdata:*:*:*:*:*:*:*:*",
127236          "purl": "pkg:maven/cldrdata/cldrdata",
127237          "swid": {
127238            "attachment": {}
127239          },
127240          "pedigree": {},
127241          "externalReferences": [
127242            {
127243              "type": "build-meta",
127244              "hashes": [
127245                {
127246                  "alg": "SHA-1",
127247                  "content": "65ef04845378cbb6bbd9eaa931292740726be866"
127248                }
127249              ]
127250            }
127251          ],
127252          "evidence": {},
127253          "signature": {
127254            "signature": {
127255              "publicKey": {}
127256            }
127257          },
127258          "modelCard": {
127259            "modelParameters": {
127260              "approach": {}
127261            },
127262            "quantitativeAnalysis": {
127263              "graphics": {}
127264            },
127265            "considerations": {}
127266          }
127267        },
127268        {
127269          "type": "library",
127270          "bom-ref": "pkg:maven/dnsns/dnsns?package-id=ff95cfa383074613",
127271          "supplier": {},
127272          "name": "dnsns",
127273          "cpe": "cpe:2.3:a:dnsns:dnsns:*:*:*:*:*:*:*:*",
127274          "purl": "pkg:maven/dnsns/dnsns",
127275          "swid": {
127276            "attachment": {}
127277          },
127278          "pedigree": {},
127279          "externalReferences": [
127280            {
127281              "type": "build-meta",
127282              "hashes": [
127283                {
127284                  "alg": "SHA-1",
127285                  "content": "f892124957b83136a583b95b20dd453a0cce8bd2"
127286                }
127287              ]
127288            }
127289          ],
127290          "evidence": {},
127291          "signature": {
127292            "signature": {
127293              "publicKey": {}
127294            }
127295          },
127296          "modelCard": {
127297            "modelParameters": {
127298              "approach": {}
127299            },
127300            "quantitativeAnalysis": {
127301              "graphics": {}
127302            },
127303            "considerations": {}
127304          }
127305        },
127306        {
127307          "type": "library",
127308          "bom-ref": "pkg:apk/alpine/freetype@2.9.1-r2?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=7ddcfcaf98877e24",
127309          "supplier": {},
127310          "publisher": "Carlo Landmeter \u003cclandmeter@gmail.com\u003e",
127311          "name": "freetype",
127312          "version": "2.9.1-r2",
127313          "description": "TrueType font rendering library",
127314          "licenses": [
127315            {
127316              "license": {
127317                "id": "FTL"
127318              }
127319            },
127320            {
127321              "license": {
127322                "id": "GPL-2.0-or-later"
127323              }
127324            }
127325          ],
127326          "cpe": "cpe:2.3:a:freetype:freetype:2.9.1-r2:*:*:*:*:*:*:*",
127327          "purl": "pkg:apk/alpine/freetype@2.9.1-r2?arch=x86_64\u0026distro=alpine-3.9.4",
127328          "swid": {
127329            "attachment": {}
127330          },
127331          "pedigree": {},
127332          "externalReferences": [
127333            {
127334              "url": "https://www.freetype.org/",
127335              "type": "distribution"
127336            }
127337          ],
127338          "evidence": {},
127339          "signature": {
127340            "signature": {
127341              "publicKey": {}
127342            }
127343          },
127344          "modelCard": {
127345            "modelParameters": {
127346              "approach": {}
127347            },
127348            "quantitativeAnalysis": {
127349              "graphics": {}
127350            },
127351            "considerations": {}
127352          }
127353        },
127354        {
127355          "type": "library",
127356          "bom-ref": "pkg:apk/alpine/giflib@5.1.4-r2?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=2983f9fe6daa7f20",
127357          "supplier": {},
127358          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127359          "name": "giflib",
127360          "version": "5.1.4-r2",
127361          "description": "A library for reading and writing GIF images",
127362          "licenses": [
127363            {
127364              "license": {
127365                "id": "MIT"
127366              }
127367            }
127368          ],
127369          "cpe": "cpe:2.3:a:giflib:giflib:5.1.4-r2:*:*:*:*:*:*:*",
127370          "purl": "pkg:apk/alpine/giflib@5.1.4-r2?arch=x86_64\u0026distro=alpine-3.9.4",
127371          "swid": {
127372            "attachment": {}
127373          },
127374          "pedigree": {},
127375          "externalReferences": [
127376            {
127377              "url": "https://sourceforge.net/projects/giflib/",
127378              "type": "distribution"
127379            }
127380          ],
127381          "evidence": {},
127382          "signature": {
127383            "signature": {
127384              "publicKey": {}
127385            }
127386          },
127387          "modelCard": {
127388            "modelParameters": {
127389              "approach": {}
127390            },
127391            "quantitativeAnalysis": {
127392              "graphics": {}
127393            },
127394            "considerations": {}
127395          }
127396        },
127397        {
127398          "type": "library",
127399          "bom-ref": "pkg:maven/jaccess/jaccess?package-id=20bd4d803cf4322c",
127400          "supplier": {},
127401          "name": "jaccess",
127402          "cpe": "cpe:2.3:a:jaccess:jaccess:*:*:*:*:*:*:*:*",
127403          "purl": "pkg:maven/jaccess/jaccess",
127404          "swid": {
127405            "attachment": {}
127406          },
127407          "pedigree": {},
127408          "externalReferences": [
127409            {
127410              "type": "build-meta",
127411              "hashes": [
127412                {
127413                  "alg": "SHA-1",
127414                  "content": "a3947729ad5538131e3b75810c455584e327c5d3"
127415                }
127416              ]
127417            }
127418          ],
127419          "evidence": {},
127420          "signature": {
127421            "signature": {
127422              "publicKey": {}
127423            }
127424          },
127425          "modelCard": {
127426            "modelParameters": {
127427              "approach": {}
127428            },
127429            "quantitativeAnalysis": {
127430              "graphics": {}
127431            },
127432            "considerations": {}
127433          }
127434        },
127435        {
127436          "type": "application",
127437          "bom-ref": "pkg:generic/java@1.8.0_212-b04?package-id=e71647f6945b3d8e",
127438          "supplier": {},
127439          "name": "java",
127440          "version": "1.8.0_212-b04",
127441          "cpe": "cpe:2.3:a:oracle:openjdk:1.8.0_212-b04:*:*:*:*:*:*:*",
127442          "purl": "pkg:generic/java@1.8.0_212-b04",
127443          "swid": {
127444            "attachment": {}
127445          },
127446          "pedigree": {},
127447          "evidence": {},
127448          "signature": {
127449            "signature": {
127450              "publicKey": {}
127451            }
127452          },
127453          "modelCard": {
127454            "modelParameters": {
127455              "approach": {}
127456            },
127457            "quantitativeAnalysis": {
127458              "graphics": {}
127459            },
127460            "considerations": {}
127461          }
127462        },
127463        {
127464          "type": "library",
127465          "bom-ref": "pkg:apk/alpine/java-cacerts@1.0-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=602ec058807ecf4f",
127466          "supplier": {},
127467          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127468          "name": "java-cacerts",
127469          "version": "1.0-r0",
127470          "description": "Script to update java cacerts store",
127471          "licenses": [
127472            {
127473              "license": {
127474                "id": "MIT"
127475              }
127476            }
127477          ],
127478          "cpe": "cpe:2.3:a:java-cacerts:java-cacerts:1.0-r0:*:*:*:*:*:*:*",
127479          "purl": "pkg:apk/alpine/java-cacerts@1.0-r0?arch=x86_64\u0026distro=alpine-3.9.4",
127480          "swid": {
127481            "attachment": {}
127482          },
127483          "pedigree": {},
127484          "externalReferences": [
127485            {
127486              "url": "https://git.alpinelinux.org/cgit/aports/community/java-cacerts",
127487              "type": "distribution"
127488            }
127489          ],
127490          "evidence": {},
127491          "signature": {
127492            "signature": {
127493              "publicKey": {}
127494            }
127495          },
127496          "modelCard": {
127497            "modelParameters": {
127498              "approach": {}
127499            },
127500            "quantitativeAnalysis": {
127501              "graphics": {}
127502            },
127503            "considerations": {}
127504          }
127505        },
127506        {
127507          "type": "library",
127508          "bom-ref": "pkg:apk/alpine/java-common@0.1-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=1f640b6e5c188d45",
127509          "supplier": {},
127510          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
127511          "name": "java-common",
127512          "version": "0.1-r0",
127513          "description": "Java common (updates java links)",
127514          "licenses": [
127515            {
127516              "license": {
127517                "id": "GPL-2.0-only"
127518              }
127519            }
127520          ],
127521          "cpe": "cpe:2.3:a:java-common:java-common:0.1-r0:*:*:*:*:*:*:*",
127522          "purl": "pkg:apk/alpine/java-common@0.1-r0?arch=x86_64\u0026distro=alpine-3.9.4",
127523          "swid": {
127524            "attachment": {}
127525          },
127526          "pedigree": {},
127527          "externalReferences": [
127528            {
127529              "url": "https://git.alpinelinux.org/aports.git",
127530              "type": "distribution"
127531            }
127532          ],
127533          "evidence": {},
127534          "signature": {
127535            "signature": {
127536              "publicKey": {}
127537            }
127538          },
127539          "modelCard": {
127540            "modelParameters": {
127541              "approach": {}
127542            },
127543            "quantitativeAnalysis": {
127544              "graphics": {}
127545            },
127546            "considerations": {}
127547          }
127548        },
127549        {
127550          "type": "library",
127551          "bom-ref": "pkg:maven/com.sun/jce@1.8.0_212?package-id=bca18fa6ca29dd47",
127552          "supplier": {},
127553          "name": "jce",
127554          "version": "1.8.0_212",
127555          "cpe": "cpe:2.3:a:oracle-corporation:jce:1.8.0_212:*:*:*:*:*:*:*",
127556          "purl": "pkg:maven/com.sun/jce@1.8.0_212",
127557          "swid": {
127558            "attachment": {}
127559          },
127560          "pedigree": {},
127561          "externalReferences": [
127562            {
127563              "type": "build-meta",
127564              "hashes": [
127565                {
127566                  "alg": "SHA-1",
127567                  "content": "fd8cc24a0f2ccf1359dbb80d48f3a2a5cc603fbb"
127568                }
127569              ]
127570            }
127571          ],
127572          "evidence": {},
127573          "signature": {
127574            "signature": {
127575              "publicKey": {}
127576            }
127577          },
127578          "modelCard": {
127579            "modelParameters": {
127580              "approach": {}
127581            },
127582            "quantitativeAnalysis": {
127583              "graphics": {}
127584            },
127585            "considerations": {}
127586          }
127587        },
127588        {
127589          "type": "library",
127590          "bom-ref": "pkg:maven/jsse/jsse@1.8.0_212?package-id=5a5b44bff4a943d3",
127591          "supplier": {},
127592          "name": "jsse",
127593          "version": "1.8.0_212",
127594          "cpe": "cpe:2.3:a:oracle-corporation:jsse:1.8.0_212:*:*:*:*:*:*:*",
127595          "purl": "pkg:maven/jsse/jsse@1.8.0_212",
127596          "swid": {
127597            "attachment": {}
127598          },
127599          "pedigree": {},
127600          "externalReferences": [
127601            {
127602              "type": "build-meta",
127603              "hashes": [
127604                {
127605                  "alg": "SHA-1",
127606                  "content": "95fe87433761cca9087bbbb35f3ab201ec7dc73a"
127607                }
127608              ]
127609            }
127610          ],
127611          "evidence": {},
127612          "signature": {
127613            "signature": {
127614              "publicKey": {}
127615            }
127616          },
127617          "modelCard": {
127618            "modelParameters": {
127619              "approach": {}
127620            },
127621            "quantitativeAnalysis": {
127622              "graphics": {}
127623            },
127624            "considerations": {}
127625          }
127626        },
127627        {
127628          "type": "library",
127629          "bom-ref": "pkg:apk/alpine/keyutils-libs@1.6-r0?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.9.4\u0026package-id=82adc21a98dd93f8",
127630          "supplier": {},
127631          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127632          "name": "keyutils-libs",
127633          "version": "1.6-r0",
127634          "description": "Key utilities library",
127635          "licenses": [
127636            {
127637              "license": {
127638                "id": "GPL-2.0-or-later"
127639              }
127640            },
127641            {
127642              "license": {
127643                "id": "LGPL-2.0-or-later"
127644              }
127645            }
127646          ],
127647          "cpe": "cpe:2.3:a:keyutils-libs:keyutils-libs:1.6-r0:*:*:*:*:*:*:*",
127648          "purl": "pkg:apk/alpine/keyutils-libs@1.6-r0?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.9.4",
127649          "swid": {
127650            "attachment": {}
127651          },
127652          "pedigree": {},
127653          "externalReferences": [
127654            {
127655              "url": "http://people.redhat.com/~dhowells/keyutils/",
127656              "type": "distribution"
127657            }
127658          ],
127659          "evidence": {},
127660          "signature": {
127661            "signature": {
127662              "publicKey": {}
127663            }
127664          },
127665          "modelCard": {
127666            "modelParameters": {
127667              "approach": {}
127668            },
127669            "quantitativeAnalysis": {
127670              "graphics": {}
127671            },
127672            "considerations": {}
127673          }
127674        },
127675        {
127676          "type": "library",
127677          "bom-ref": "pkg:apk/alpine/krb5-conf@1.0-r1?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=d9a373b63e1d7760",
127678          "supplier": {},
127679          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127680          "name": "krb5-conf",
127681          "version": "1.0-r1",
127682          "description": "Shared krb5.conf for both MIT krb5 and heimdal",
127683          "licenses": [
127684            {
127685              "license": {
127686                "id": "MIT"
127687              }
127688            }
127689          ],
127690          "cpe": "cpe:2.3:a:krb5-conf:krb5-conf:1.0-r1:*:*:*:*:*:*:*",
127691          "purl": "pkg:apk/alpine/krb5-conf@1.0-r1?arch=x86_64\u0026distro=alpine-3.9.4",
127692          "swid": {
127693            "attachment": {}
127694          },
127695          "pedigree": {},
127696          "externalReferences": [
127697            {
127698              "url": "http://web.mit.edu/kerberos/www/ http://h5l.org",
127699              "type": "distribution"
127700            }
127701          ],
127702          "evidence": {},
127703          "signature": {
127704            "signature": {
127705              "publicKey": {}
127706            }
127707          },
127708          "modelCard": {
127709            "modelParameters": {
127710              "approach": {}
127711            },
127712            "quantitativeAnalysis": {
127713              "graphics": {}
127714            },
127715            "considerations": {}
127716          }
127717        },
127718        {
127719          "type": "library",
127720          "bom-ref": "pkg:apk/alpine/krb5-libs@1.15.5-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.9.4\u0026package-id=1b490c6a76e8de9e",
127721          "supplier": {},
127722          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127723          "name": "krb5-libs",
127724          "version": "1.15.5-r0",
127725          "description": "The shared libraries used by Kerberos 5",
127726          "licenses": [
127727            {
127728              "license": {
127729                "id": "MIT"
127730              }
127731            }
127732          ],
127733          "cpe": "cpe:2.3:a:krb5-libs:krb5-libs:1.15.5-r0:*:*:*:*:*:*:*",
127734          "purl": "pkg:apk/alpine/krb5-libs@1.15.5-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.9.4",
127735          "swid": {
127736            "attachment": {}
127737          },
127738          "pedigree": {},
127739          "externalReferences": [
127740            {
127741              "url": "https://web.mit.edu/kerberos/www/",
127742              "type": "distribution"
127743            }
127744          ],
127745          "evidence": {},
127746          "signature": {
127747            "signature": {
127748              "publicKey": {}
127749            }
127750          },
127751          "modelCard": {
127752            "modelParameters": {
127753              "approach": {}
127754            },
127755            "quantitativeAnalysis": {
127756              "graphics": {}
127757            },
127758            "considerations": {}
127759          }
127760        },
127761        {
127762          "type": "library",
127763          "bom-ref": "pkg:apk/alpine/lcms2@2.9-r1?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=715865191ba47afc",
127764          "supplier": {},
127765          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127766          "name": "lcms2",
127767          "version": "2.9-r1",
127768          "description": "Color Management Engine",
127769          "licenses": [
127770            {
127771              "license": {
127772                "id": "MIT"
127773              }
127774            }
127775          ],
127776          "cpe": "cpe:2.3:a:lcms2:lcms2:2.9-r1:*:*:*:*:*:*:*",
127777          "purl": "pkg:apk/alpine/lcms2@2.9-r1?arch=x86_64\u0026distro=alpine-3.9.4",
127778          "swid": {
127779            "attachment": {}
127780          },
127781          "pedigree": {},
127782          "externalReferences": [
127783            {
127784              "url": "http://www.littlecms.com",
127785              "type": "distribution"
127786            }
127787          ],
127788          "evidence": {},
127789          "signature": {
127790            "signature": {
127791              "publicKey": {}
127792            }
127793          },
127794          "modelCard": {
127795            "modelParameters": {
127796              "approach": {}
127797            },
127798            "quantitativeAnalysis": {
127799              "graphics": {}
127800            },
127801            "considerations": {}
127802          }
127803        },
127804        {
127805          "type": "library",
127806          "bom-ref": "pkg:apk/alpine/libbsd@0.8.6-r2?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=fba3949810bbcaa6",
127807          "supplier": {},
127808          "publisher": "William Pitcock \u003cnenolod@dereferenced.org\u003e",
127809          "name": "libbsd",
127810          "version": "0.8.6-r2",
127811          "description": "commonly-used BSD functions not implemented by all libcs",
127812          "licenses": [
127813            {
127814              "license": {
127815                "name": "BSD"
127816              }
127817            }
127818          ],
127819          "cpe": "cpe:2.3:a:libbsd:libbsd:0.8.6-r2:*:*:*:*:*:*:*",
127820          "purl": "pkg:apk/alpine/libbsd@0.8.6-r2?arch=x86_64\u0026distro=alpine-3.9.4",
127821          "swid": {
127822            "attachment": {}
127823          },
127824          "pedigree": {},
127825          "externalReferences": [
127826            {
127827              "url": "https://libbsd.freedesktop.org/",
127828              "type": "distribution"
127829            }
127830          ],
127831          "evidence": {},
127832          "signature": {
127833            "signature": {
127834              "publicKey": {}
127835            }
127836          },
127837          "modelCard": {
127838            "modelParameters": {
127839              "approach": {}
127840            },
127841            "quantitativeAnalysis": {
127842              "graphics": {}
127843            },
127844            "considerations": {}
127845          }
127846        },
127847        {
127848          "type": "library",
127849          "bom-ref": "pkg:apk/alpine/libbz2@1.0.6-r6?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.9.4\u0026package-id=7abefaac69512737",
127850          "supplier": {},
127851          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127852          "name": "libbz2",
127853          "version": "1.0.6-r6",
127854          "description": "Shared library for bz2",
127855          "licenses": [
127856            {
127857              "license": {
127858                "name": "BSD"
127859              }
127860            }
127861          ],
127862          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.6-r6:*:*:*:*:*:*:*",
127863          "purl": "pkg:apk/alpine/libbz2@1.0.6-r6?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.9.4",
127864          "swid": {
127865            "attachment": {}
127866          },
127867          "pedigree": {},
127868          "externalReferences": [
127869            {
127870              "url": "http://sources.redhat.com/bzip2",
127871              "type": "distribution"
127872            }
127873          ],
127874          "evidence": {},
127875          "signature": {
127876            "signature": {
127877              "publicKey": {}
127878            }
127879          },
127880          "modelCard": {
127881            "modelParameters": {
127882              "approach": {}
127883            },
127884            "quantitativeAnalysis": {
127885              "graphics": {}
127886            },
127887            "considerations": {}
127888          }
127889        },
127890        {
127891          "type": "library",
127892          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.1-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.9.4\u0026package-id=f1efc120e7d9e31b",
127893          "supplier": {},
127894          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127895          "name": "libc-utils",
127896          "version": "0.7.1-r0",
127897          "description": "Meta package to pull in correct libc",
127898          "licenses": [
127899            {
127900              "license": {
127901                "name": "BSD"
127902              }
127903            }
127904          ],
127905          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.1-r0:*:*:*:*:*:*:*",
127906          "purl": "pkg:apk/alpine/libc-utils@0.7.1-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.9.4",
127907          "swid": {
127908            "attachment": {}
127909          },
127910          "pedigree": {},
127911          "externalReferences": [
127912            {
127913              "url": "http://alpinelinux.org",
127914              "type": "distribution"
127915            }
127916          ],
127917          "evidence": {},
127918          "signature": {
127919            "signature": {
127920              "publicKey": {}
127921            }
127922          },
127923          "modelCard": {
127924            "modelParameters": {
127925              "approach": {}
127926            },
127927            "quantitativeAnalysis": {
127928              "graphics": {}
127929            },
127930            "considerations": {}
127931          }
127932        },
127933        {
127934          "type": "library",
127935          "bom-ref": "pkg:apk/alpine/libcom_err@1.44.5-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.9.4\u0026package-id=57a9cac52abf811f",
127936          "supplier": {},
127937          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
127938          "name": "libcom_err",
127939          "version": "1.44.5-r0",
127940          "description": "Common error description library",
127941          "licenses": [
127942            {
127943              "license": {
127944                "id": "GPL-2.0-or-later"
127945              }
127946            },
127947            {
127948              "license": {
127949                "id": "LGPL-2.0-only"
127950              }
127951            },
127952            {
127953              "license": {
127954                "id": "BSD-3-Clause"
127955              }
127956            },
127957            {
127958              "license": {
127959                "id": "MIT"
127960              }
127961            }
127962          ],
127963          "cpe": "cpe:2.3:a:libcom-err:libcom-err:1.44.5-r0:*:*:*:*:*:*:*",
127964          "purl": "pkg:apk/alpine/libcom_err@1.44.5-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.9.4",
127965          "swid": {
127966            "attachment": {}
127967          },
127968          "pedigree": {},
127969          "externalReferences": [
127970            {
127971              "url": "http://e2fsprogs.sourceforge.net",
127972              "type": "distribution"
127973            }
127974          ],
127975          "evidence": {},
127976          "signature": {
127977            "signature": {
127978              "publicKey": {}
127979            }
127980          },
127981          "modelCard": {
127982            "modelParameters": {
127983              "approach": {}
127984            },
127985            "quantitativeAnalysis": {
127986              "graphics": {}
127987            },
127988            "considerations": {}
127989          }
127990        },
127991        {
127992          "type": "library",
127993          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1b-r1?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.9.4\u0026package-id=40f51ac175781d2d",
127994          "supplier": {},
127995          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
127996          "name": "libcrypto1.1",
127997          "version": "1.1.1b-r1",
127998          "description": "Crypto library from openssl",
127999          "licenses": [
128000            {
128001              "license": {
128002                "id": "OpenSSL"
128003              }
128004            }
128005          ],
128006          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1b-r1:*:*:*:*:*:*:*",
128007          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1b-r1?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.9.4",
128008          "swid": {
128009            "attachment": {}
128010          },
128011          "pedigree": {},
128012          "externalReferences": [
128013            {
128014              "url": "https://www.openssl.org",
128015              "type": "distribution"
128016            }
128017          ],
128018          "evidence": {},
128019          "signature": {
128020            "signature": {
128021              "publicKey": {}
128022            }
128023          },
128024          "modelCard": {
128025            "modelParameters": {
128026              "approach": {}
128027            },
128028            "quantitativeAnalysis": {
128029              "graphics": {}
128030            },
128031            "considerations": {}
128032          }
128033        },
128034        {
128035          "type": "library",
128036          "bom-ref": "pkg:apk/alpine/libffi@3.2.1-r6?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=8075dee98777280",
128037          "supplier": {},
128038          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128039          "name": "libffi",
128040          "version": "3.2.1-r6",
128041          "description": "A portable, high level programming interface to various calling conventions.",
128042          "licenses": [
128043            {
128044              "license": {
128045                "id": "MIT"
128046              }
128047            }
128048          ],
128049          "cpe": "cpe:2.3:a:libffi:libffi:3.2.1-r6:*:*:*:*:*:*:*",
128050          "purl": "pkg:apk/alpine/libffi@3.2.1-r6?arch=x86_64\u0026distro=alpine-3.9.4",
128051          "swid": {
128052            "attachment": {}
128053          },
128054          "pedigree": {},
128055          "externalReferences": [
128056            {
128057              "url": "http://sourceware.org/libffi",
128058              "type": "distribution"
128059            }
128060          ],
128061          "evidence": {},
128062          "signature": {
128063            "signature": {
128064              "publicKey": {}
128065            }
128066          },
128067          "modelCard": {
128068            "modelParameters": {
128069              "approach": {}
128070            },
128071            "quantitativeAnalysis": {
128072              "graphics": {}
128073            },
128074            "considerations": {}
128075          }
128076        },
128077        {
128078          "type": "library",
128079          "bom-ref": "pkg:apk/alpine/libgcc@8.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.9.4\u0026package-id=8a3b62229918f6f4",
128080          "supplier": {},
128081          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128082          "name": "libgcc",
128083          "version": "8.3.0-r0",
128084          "description": "GNU C compiler runtime libraries",
128085          "licenses": [
128086            {
128087              "license": {
128088                "name": "GPL"
128089              }
128090            },
128091            {
128092              "license": {
128093                "name": "LGPL"
128094              }
128095            }
128096          ],
128097          "cpe": "cpe:2.3:a:libgcc:libgcc:8.3.0-r0:*:*:*:*:*:*:*",
128098          "purl": "pkg:apk/alpine/libgcc@8.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.9.4",
128099          "swid": {
128100            "attachment": {}
128101          },
128102          "pedigree": {},
128103          "externalReferences": [
128104            {
128105              "url": "http://gcc.gnu.org",
128106              "type": "distribution"
128107            }
128108          ],
128109          "evidence": {},
128110          "signature": {
128111            "signature": {
128112              "publicKey": {}
128113            }
128114          },
128115          "modelCard": {
128116            "modelParameters": {
128117              "approach": {}
128118            },
128119            "quantitativeAnalysis": {
128120              "graphics": {}
128121            },
128122            "considerations": {}
128123          }
128124        },
128125        {
128126          "type": "library",
128127          "bom-ref": "pkg:apk/alpine/libjpeg-turbo@1.5.3-r4?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=be7d740544f70578",
128128          "supplier": {},
128129          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128130          "name": "libjpeg-turbo",
128131          "version": "1.5.3-r4",
128132          "description": "accelerated baseline JPEG compression and decompression library",
128133          "licenses": [
128134            {
128135              "license": {
128136                "id": "IJG"
128137              }
128138            }
128139          ],
128140          "cpe": "cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:1.5.3-r4:*:*:*:*:*:*:*",
128141          "purl": "pkg:apk/alpine/libjpeg-turbo@1.5.3-r4?arch=x86_64\u0026distro=alpine-3.9.4",
128142          "swid": {
128143            "attachment": {}
128144          },
128145          "pedigree": {},
128146          "externalReferences": [
128147            {
128148              "url": "https://libjpeg-turbo.org/",
128149              "type": "distribution"
128150            }
128151          ],
128152          "evidence": {},
128153          "signature": {
128154            "signature": {
128155              "publicKey": {}
128156            }
128157          },
128158          "modelCard": {
128159            "modelParameters": {
128160              "approach": {}
128161            },
128162            "quantitativeAnalysis": {
128163              "graphics": {}
128164            },
128165            "considerations": {}
128166          }
128167        },
128168        {
128169          "type": "library",
128170          "bom-ref": "pkg:apk/alpine/libpng@1.6.37-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=80d3f1682193c07b",
128171          "supplier": {},
128172          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128173          "name": "libpng",
128174          "version": "1.6.37-r0",
128175          "description": "Portable Network Graphics library",
128176          "licenses": [
128177            {
128178              "license": {
128179                "id": "Libpng"
128180              }
128181            }
128182          ],
128183          "cpe": "cpe:2.3:a:libpng:libpng:1.6.37-r0:*:*:*:*:*:*:*",
128184          "purl": "pkg:apk/alpine/libpng@1.6.37-r0?arch=x86_64\u0026distro=alpine-3.9.4",
128185          "swid": {
128186            "attachment": {}
128187          },
128188          "pedigree": {},
128189          "externalReferences": [
128190            {
128191              "url": "http://www.libpng.org",
128192              "type": "distribution"
128193            }
128194          ],
128195          "evidence": {},
128196          "signature": {
128197            "signature": {
128198              "publicKey": {}
128199            }
128200          },
128201          "modelCard": {
128202            "modelParameters": {
128203              "approach": {}
128204            },
128205            "quantitativeAnalysis": {
128206              "graphics": {}
128207            },
128208            "considerations": {}
128209          }
128210        },
128211        {
128212          "type": "library",
128213          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1b-r1?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.9.4\u0026package-id=5476af5bb147929d",
128214          "supplier": {},
128215          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
128216          "name": "libssl1.1",
128217          "version": "1.1.1b-r1",
128218          "description": "SSL shared libraries",
128219          "licenses": [
128220            {
128221              "license": {
128222                "id": "OpenSSL"
128223              }
128224            }
128225          ],
128226          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1b-r1:*:*:*:*:*:*:*",
128227          "purl": "pkg:apk/alpine/libssl1.1@1.1.1b-r1?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.9.4",
128228          "swid": {
128229            "attachment": {}
128230          },
128231          "pedigree": {},
128232          "externalReferences": [
128233            {
128234              "url": "https://www.openssl.org",
128235              "type": "distribution"
128236            }
128237          ],
128238          "evidence": {},
128239          "signature": {
128240            "signature": {
128241              "publicKey": {}
128242            }
128243          },
128244          "modelCard": {
128245            "modelParameters": {
128246              "approach": {}
128247            },
128248            "quantitativeAnalysis": {
128249              "graphics": {}
128250            },
128251            "considerations": {}
128252          }
128253        },
128254        {
128255          "type": "library",
128256          "bom-ref": "pkg:apk/alpine/libstdc++@8.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.9.4\u0026package-id=3f67f6b0d2dd7b69",
128257          "supplier": {},
128258          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128259          "name": "libstdc++",
128260          "version": "8.3.0-r0",
128261          "description": "GNU C++ standard runtime library",
128262          "licenses": [
128263            {
128264              "license": {
128265                "name": "GPL"
128266              }
128267            },
128268            {
128269              "license": {
128270                "name": "LGPL"
128271              }
128272            }
128273          ],
128274          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:8.3.0-r0:*:*:*:*:*:*:*",
128275          "purl": "pkg:apk/alpine/libstdc++@8.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.9.4",
128276          "swid": {
128277            "attachment": {}
128278          },
128279          "pedigree": {},
128280          "externalReferences": [
128281            {
128282              "url": "http://gcc.gnu.org",
128283              "type": "distribution"
128284            }
128285          ],
128286          "evidence": {},
128287          "signature": {
128288            "signature": {
128289              "publicKey": {}
128290            }
128291          },
128292          "modelCard": {
128293            "modelParameters": {
128294              "approach": {}
128295            },
128296            "quantitativeAnalysis": {
128297              "graphics": {}
128298            },
128299            "considerations": {}
128300          }
128301        },
128302        {
128303          "type": "library",
128304          "bom-ref": "pkg:apk/alpine/libtasn1@4.13-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=9c38e06d5284c2dd",
128305          "supplier": {},
128306          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128307          "name": "libtasn1",
128308          "version": "4.13-r0",
128309          "description": "The ASN.1 library used in GNUTLS",
128310          "licenses": [
128311            {
128312              "license": {
128313                "id": "GPL-3.0-only"
128314              }
128315            },
128316            {
128317              "license": {
128318                "name": "LGPL"
128319              }
128320            }
128321          ],
128322          "cpe": "cpe:2.3:a:libtasn1:libtasn1:4.13-r0:*:*:*:*:*:*:*",
128323          "purl": "pkg:apk/alpine/libtasn1@4.13-r0?arch=x86_64\u0026distro=alpine-3.9.4",
128324          "swid": {
128325            "attachment": {}
128326          },
128327          "pedigree": {},
128328          "externalReferences": [
128329            {
128330              "url": "https://www.gnu.org/software/gnutls/",
128331              "type": "distribution"
128332            }
128333          ],
128334          "evidence": {},
128335          "signature": {
128336            "signature": {
128337              "publicKey": {}
128338            }
128339          },
128340          "modelCard": {
128341            "modelParameters": {
128342              "approach": {}
128343            },
128344            "quantitativeAnalysis": {
128345              "graphics": {}
128346            },
128347            "considerations": {}
128348          }
128349        },
128350        {
128351          "type": "library",
128352          "bom-ref": "pkg:apk/alpine/libtls-standalone@2.7.4-r6?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=ae20bd0a3178821a",
128353          "supplier": {},
128354          "publisher": "William Pitcock \u003cnenolod@dereferenced.org\u003e",
128355          "name": "libtls-standalone",
128356          "version": "2.7.4-r6",
128357          "description": "libtls extricated from libressl sources",
128358          "licenses": [
128359            {
128360              "license": {
128361                "id": "ISC"
128362              }
128363            }
128364          ],
128365          "cpe": "cpe:2.3:a:libtls-standalone:libtls-standalone:2.7.4-r6:*:*:*:*:*:*:*",
128366          "purl": "pkg:apk/alpine/libtls-standalone@2.7.4-r6?arch=x86_64\u0026distro=alpine-3.9.4",
128367          "swid": {
128368            "attachment": {}
128369          },
128370          "pedigree": {},
128371          "externalReferences": [
128372            {
128373              "url": "http://www.libressl.org/",
128374              "type": "distribution"
128375            }
128376          ],
128377          "evidence": {},
128378          "signature": {
128379            "signature": {
128380              "publicKey": {}
128381            }
128382          },
128383          "modelCard": {
128384            "modelParameters": {
128385              "approach": {}
128386            },
128387            "quantitativeAnalysis": {
128388              "graphics": {}
128389            },
128390            "considerations": {}
128391          }
128392        },
128393        {
128394          "type": "library",
128395          "bom-ref": "pkg:apk/alpine/libverto@0.3.0-r1?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=7edf9b3d753fa296",
128396          "supplier": {},
128397          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
128398          "name": "libverto",
128399          "version": "0.3.0-r1",
128400          "description": "Main loop abstraction library",
128401          "licenses": [
128402            {
128403              "license": {
128404                "id": "MIT"
128405              }
128406            }
128407          ],
128408          "cpe": "cpe:2.3:a:npmccallum:libverto:0.3.0-r1:*:*:*:*:*:*:*",
128409          "purl": "pkg:apk/alpine/libverto@0.3.0-r1?arch=x86_64\u0026distro=alpine-3.9.4",
128410          "swid": {
128411            "attachment": {}
128412          },
128413          "pedigree": {},
128414          "externalReferences": [
128415            {
128416              "url": "https://github.com/npmccallum/libverto",
128417              "type": "distribution"
128418            }
128419          ],
128420          "evidence": {},
128421          "signature": {
128422            "signature": {
128423              "publicKey": {}
128424            }
128425          },
128426          "modelCard": {
128427            "modelParameters": {
128428              "approach": {}
128429            },
128430            "quantitativeAnalysis": {
128431              "graphics": {}
128432            },
128433            "considerations": {}
128434          }
128435        },
128436        {
128437          "type": "library",
128438          "bom-ref": "pkg:apk/alpine/libx11@1.6.7-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=baabf61763795057",
128439          "supplier": {},
128440          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128441          "name": "libx11",
128442          "version": "1.6.7-r0",
128443          "description": "X11 client-side library",
128444          "licenses": [
128445            {
128446              "license": {
128447                "name": "custom:XFREE86"
128448              }
128449            }
128450          ],
128451          "cpe": "cpe:2.3:a:libx11:libx11:1.6.7-r0:*:*:*:*:*:*:*",
128452          "purl": "pkg:apk/alpine/libx11@1.6.7-r0?arch=x86_64\u0026distro=alpine-3.9.4",
128453          "swid": {
128454            "attachment": {}
128455          },
128456          "pedigree": {},
128457          "externalReferences": [
128458            {
128459              "url": "http://xorg.freedesktop.org/",
128460              "type": "distribution"
128461            }
128462          ],
128463          "evidence": {},
128464          "signature": {
128465            "signature": {
128466              "publicKey": {}
128467            }
128468          },
128469          "modelCard": {
128470            "modelParameters": {
128471              "approach": {}
128472            },
128473            "quantitativeAnalysis": {
128474              "graphics": {}
128475            },
128476            "considerations": {}
128477          }
128478        },
128479        {
128480          "type": "library",
128481          "bom-ref": "pkg:apk/alpine/libxau@1.0.8-r3?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=9ca8d6221fa823da",
128482          "supplier": {},
128483          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128484          "name": "libxau",
128485          "version": "1.0.8-r3",
128486          "description": "X11 authorisation library",
128487          "licenses": [
128488            {
128489              "license": {
128490                "name": "custom"
128491              }
128492            }
128493          ],
128494          "cpe": "cpe:2.3:a:libxau:libxau:1.0.8-r3:*:*:*:*:*:*:*",
128495          "purl": "pkg:apk/alpine/libxau@1.0.8-r3?arch=x86_64\u0026distro=alpine-3.9.4",
128496          "swid": {
128497            "attachment": {}
128498          },
128499          "pedigree": {},
128500          "externalReferences": [
128501            {
128502              "url": "http://xorg.freedesktop.org/",
128503              "type": "distribution"
128504            }
128505          ],
128506          "evidence": {},
128507          "signature": {
128508            "signature": {
128509              "publicKey": {}
128510            }
128511          },
128512          "modelCard": {
128513            "modelParameters": {
128514              "approach": {}
128515            },
128516            "quantitativeAnalysis": {
128517              "graphics": {}
128518            },
128519            "considerations": {}
128520          }
128521        },
128522        {
128523          "type": "library",
128524          "bom-ref": "pkg:apk/alpine/libxcb@1.13-r2?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=83d685c2793c57b4",
128525          "supplier": {},
128526          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128527          "name": "libxcb",
128528          "version": "1.13-r2",
128529          "description": "X11 client-side library",
128530          "licenses": [
128531            {
128532              "license": {
128533                "id": "MIT"
128534              }
128535            }
128536          ],
128537          "cpe": "cpe:2.3:a:libxcb:libxcb:1.13-r2:*:*:*:*:*:*:*",
128538          "purl": "pkg:apk/alpine/libxcb@1.13-r2?arch=x86_64\u0026distro=alpine-3.9.4",
128539          "swid": {
128540            "attachment": {}
128541          },
128542          "pedigree": {},
128543          "externalReferences": [
128544            {
128545              "url": "https://xcb.freedesktop.org",
128546              "type": "distribution"
128547            }
128548          ],
128549          "evidence": {},
128550          "signature": {
128551            "signature": {
128552              "publicKey": {}
128553            }
128554          },
128555          "modelCard": {
128556            "modelParameters": {
128557              "approach": {}
128558            },
128559            "quantitativeAnalysis": {
128560              "graphics": {}
128561            },
128562            "considerations": {}
128563          }
128564        },
128565        {
128566          "type": "library",
128567          "bom-ref": "pkg:apk/alpine/libxcomposite@0.4.4-r2?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=7cab3834fb38c41d",
128568          "supplier": {},
128569          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128570          "name": "libxcomposite",
128571          "version": "0.4.4-r2",
128572          "description": "X11 Composite extension library",
128573          "licenses": [
128574            {
128575              "license": {
128576                "name": "custom"
128577              }
128578            }
128579          ],
128580          "cpe": "cpe:2.3:a:libxcomposite:libxcomposite:0.4.4-r2:*:*:*:*:*:*:*",
128581          "purl": "pkg:apk/alpine/libxcomposite@0.4.4-r2?arch=x86_64\u0026distro=alpine-3.9.4",
128582          "swid": {
128583            "attachment": {}
128584          },
128585          "pedigree": {},
128586          "externalReferences": [
128587            {
128588              "url": "http://xorg.freedesktop.org/",
128589              "type": "distribution"
128590            }
128591          ],
128592          "evidence": {},
128593          "signature": {
128594            "signature": {
128595              "publicKey": {}
128596            }
128597          },
128598          "modelCard": {
128599            "modelParameters": {
128600              "approach": {}
128601            },
128602            "quantitativeAnalysis": {
128603              "graphics": {}
128604            },
128605            "considerations": {}
128606          }
128607        },
128608        {
128609          "type": "library",
128610          "bom-ref": "pkg:apk/alpine/libxdmcp@1.1.2-r5?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=111ec23c46f34c19",
128611          "supplier": {},
128612          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128613          "name": "libxdmcp",
128614          "version": "1.1.2-r5",
128615          "description": "X11 Display Manager Control Protocol library",
128616          "licenses": [
128617            {
128618              "license": {
128619                "id": "MIT"
128620              }
128621            }
128622          ],
128623          "cpe": "cpe:2.3:a:libxdmcp:libxdmcp:1.1.2-r5:*:*:*:*:*:*:*",
128624          "purl": "pkg:apk/alpine/libxdmcp@1.1.2-r5?arch=x86_64\u0026distro=alpine-3.9.4",
128625          "swid": {
128626            "attachment": {}
128627          },
128628          "pedigree": {},
128629          "externalReferences": [
128630            {
128631              "url": "http://xorg.freedesktop.org/",
128632              "type": "distribution"
128633            }
128634          ],
128635          "evidence": {},
128636          "signature": {
128637            "signature": {
128638              "publicKey": {}
128639            }
128640          },
128641          "modelCard": {
128642            "modelParameters": {
128643              "approach": {}
128644            },
128645            "quantitativeAnalysis": {
128646              "graphics": {}
128647            },
128648            "considerations": {}
128649          }
128650        },
128651        {
128652          "type": "library",
128653          "bom-ref": "pkg:apk/alpine/libxext@1.3.3-r3?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=fb98d23c55553290",
128654          "supplier": {},
128655          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128656          "name": "libxext",
128657          "version": "1.3.3-r3",
128658          "description": "X11 miscellaneous extensions library",
128659          "licenses": [
128660            {
128661              "license": {
128662                "name": "custom"
128663              }
128664            }
128665          ],
128666          "cpe": "cpe:2.3:a:libxext:libxext:1.3.3-r3:*:*:*:*:*:*:*",
128667          "purl": "pkg:apk/alpine/libxext@1.3.3-r3?arch=x86_64\u0026distro=alpine-3.9.4",
128668          "swid": {
128669            "attachment": {}
128670          },
128671          "pedigree": {},
128672          "externalReferences": [
128673            {
128674              "url": "http://xorg.freedesktop.org/",
128675              "type": "distribution"
128676            }
128677          ],
128678          "evidence": {},
128679          "signature": {
128680            "signature": {
128681              "publicKey": {}
128682            }
128683          },
128684          "modelCard": {
128685            "modelParameters": {
128686              "approach": {}
128687            },
128688            "quantitativeAnalysis": {
128689              "graphics": {}
128690            },
128691            "considerations": {}
128692          }
128693        },
128694        {
128695          "type": "library",
128696          "bom-ref": "pkg:apk/alpine/libxi@1.7.9-r2?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=f71fe5e8b4d26aa0",
128697          "supplier": {},
128698          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128699          "name": "libxi",
128700          "version": "1.7.9-r2",
128701          "description": "X11 Input extension library",
128702          "licenses": [
128703            {
128704              "license": {
128705                "name": "custom"
128706              }
128707            }
128708          ],
128709          "cpe": "cpe:2.3:a:libxi:libxi:1.7.9-r2:*:*:*:*:*:*:*",
128710          "purl": "pkg:apk/alpine/libxi@1.7.9-r2?arch=x86_64\u0026distro=alpine-3.9.4",
128711          "swid": {
128712            "attachment": {}
128713          },
128714          "pedigree": {},
128715          "externalReferences": [
128716            {
128717              "url": "http://xorg.freedesktop.org",
128718              "type": "distribution"
128719            }
128720          ],
128721          "evidence": {},
128722          "signature": {
128723            "signature": {
128724              "publicKey": {}
128725            }
128726          },
128727          "modelCard": {
128728            "modelParameters": {
128729              "approach": {}
128730            },
128731            "quantitativeAnalysis": {
128732              "graphics": {}
128733            },
128734            "considerations": {}
128735          }
128736        },
128737        {
128738          "type": "library",
128739          "bom-ref": "pkg:apk/alpine/libxrender@0.9.10-r3?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=fdca5d3c6e7fd6f9",
128740          "supplier": {},
128741          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128742          "name": "libxrender",
128743          "version": "0.9.10-r3",
128744          "description": "X Rendering Extension client library",
128745          "licenses": [
128746            {
128747              "license": {
128748                "name": "custom"
128749              }
128750            }
128751          ],
128752          "cpe": "cpe:2.3:a:libxrender:libxrender:0.9.10-r3:*:*:*:*:*:*:*",
128753          "purl": "pkg:apk/alpine/libxrender@0.9.10-r3?arch=x86_64\u0026distro=alpine-3.9.4",
128754          "swid": {
128755            "attachment": {}
128756          },
128757          "pedigree": {},
128758          "externalReferences": [
128759            {
128760              "url": "http://xorg.freedesktop.org/",
128761              "type": "distribution"
128762            }
128763          ],
128764          "evidence": {},
128765          "signature": {
128766            "signature": {
128767              "publicKey": {}
128768            }
128769          },
128770          "modelCard": {
128771            "modelParameters": {
128772              "approach": {}
128773            },
128774            "quantitativeAnalysis": {
128775              "graphics": {}
128776            },
128777            "considerations": {}
128778          }
128779        },
128780        {
128781          "type": "library",
128782          "bom-ref": "pkg:apk/alpine/libxtst@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=e3be10bbfccda5b4",
128783          "supplier": {},
128784          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128785          "name": "libxtst",
128786          "version": "1.2.3-r2",
128787          "description": "X11 Testing -- Resource extension library",
128788          "licenses": [
128789            {
128790              "license": {
128791                "name": "custom"
128792              }
128793            }
128794          ],
128795          "cpe": "cpe:2.3:a:libxtst:libxtst:1.2.3-r2:*:*:*:*:*:*:*",
128796          "purl": "pkg:apk/alpine/libxtst@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.9.4",
128797          "swid": {
128798            "attachment": {}
128799          },
128800          "pedigree": {},
128801          "externalReferences": [
128802            {
128803              "url": "http://xorg.freedesktop.org/",
128804              "type": "distribution"
128805            }
128806          ],
128807          "evidence": {},
128808          "signature": {
128809            "signature": {
128810              "publicKey": {}
128811            }
128812          },
128813          "modelCard": {
128814            "modelParameters": {
128815              "approach": {}
128816            },
128817            "quantitativeAnalysis": {
128818              "graphics": {}
128819            },
128820            "considerations": {}
128821          }
128822        },
128823        {
128824          "type": "library",
128825          "bom-ref": "pkg:apk/alpine/lksctp-tools@1.0.17-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=4354c714b3b998af",
128826          "supplier": {},
128827          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
128828          "name": "lksctp-tools",
128829          "version": "1.0.17-r0",
128830          "description": "User-space access to Linux Kernel SCTP",
128831          "licenses": [
128832            {
128833              "license": {
128834                "id": "GPL-2.0-only"
128835              }
128836            },
128837            {
128838              "license": {
128839                "name": "and"
128840              }
128841            },
128842            {
128843              "license": {
128844                "id": "GPL-2.0-or-later"
128845              }
128846            },
128847            {
128848              "license": {
128849                "name": "and"
128850              }
128851            },
128852            {
128853              "license": {
128854                "id": "LGPL-2.0-only"
128855              }
128856            },
128857            {
128858              "license": {
128859                "name": "and"
128860              }
128861            },
128862            {
128863              "license": {
128864                "id": "MIT"
128865              }
128866            }
128867          ],
128868          "cpe": "cpe:2.3:a:lksctp-tools:lksctp-tools:1.0.17-r0:*:*:*:*:*:*:*",
128869          "purl": "pkg:apk/alpine/lksctp-tools@1.0.17-r0?arch=x86_64\u0026distro=alpine-3.9.4",
128870          "swid": {
128871            "attachment": {}
128872          },
128873          "pedigree": {},
128874          "externalReferences": [
128875            {
128876              "url": "http://lksctp.sourceforge.net",
128877              "type": "distribution"
128878            }
128879          ],
128880          "evidence": {},
128881          "signature": {
128882            "signature": {
128883              "publicKey": {}
128884            }
128885          },
128886          "modelCard": {
128887            "modelParameters": {
128888              "approach": {}
128889            },
128890            "quantitativeAnalysis": {
128891              "graphics": {}
128892            },
128893            "considerations": {}
128894          }
128895        },
128896        {
128897          "type": "library",
128898          "bom-ref": "pkg:maven/local_policy/local_policy?package-id=ce32d805bb8dfe2d",
128899          "supplier": {},
128900          "name": "local_policy",
128901          "cpe": "cpe:2.3:a:local-policy:local-policy:*:*:*:*:*:*:*:*",
128902          "purl": "pkg:maven/local_policy/local_policy",
128903          "swid": {
128904            "attachment": {}
128905          },
128906          "pedigree": {},
128907          "externalReferences": [
128908            {
128909              "type": "build-meta",
128910              "hashes": [
128911                {
128912                  "alg": "SHA-1",
128913                  "content": "ab8c2f861765669b32140efd655941d4e7c07686"
128914                }
128915              ]
128916            }
128917          ],
128918          "evidence": {},
128919          "signature": {
128920            "signature": {
128921              "publicKey": {}
128922            }
128923          },
128924          "modelCard": {
128925            "modelParameters": {
128926              "approach": {}
128927            },
128928            "quantitativeAnalysis": {
128929              "graphics": {}
128930            },
128931            "considerations": {}
128932          }
128933        },
128934        {
128935          "type": "library",
128936          "bom-ref": "pkg:maven/local_policy/local_policy?package-id=93c833e485d52707",
128937          "supplier": {},
128938          "name": "local_policy",
128939          "cpe": "cpe:2.3:a:local-policy:local-policy:*:*:*:*:*:*:*:*",
128940          "purl": "pkg:maven/local_policy/local_policy",
128941          "swid": {
128942            "attachment": {}
128943          },
128944          "pedigree": {},
128945          "externalReferences": [
128946            {
128947              "type": "build-meta",
128948              "hashes": [
128949                {
128950                  "alg": "SHA-1",
128951                  "content": "b58059aa9d47f1e2d6825e1ca692a3e3927b85cc"
128952                }
128953              ]
128954            }
128955          ],
128956          "evidence": {},
128957          "signature": {
128958            "signature": {
128959              "publicKey": {}
128960            }
128961          },
128962          "modelCard": {
128963            "modelParameters": {
128964              "approach": {}
128965            },
128966            "quantitativeAnalysis": {
128967              "graphics": {}
128968            },
128969            "considerations": {}
128970          }
128971        },
128972        {
128973          "type": "library",
128974          "bom-ref": "pkg:maven/localedata/localedata?package-id=e1c81a9e51e17f2a",
128975          "supplier": {},
128976          "name": "localedata",
128977          "cpe": "cpe:2.3:a:localedata:localedata:*:*:*:*:*:*:*:*",
128978          "purl": "pkg:maven/localedata/localedata",
128979          "swid": {
128980            "attachment": {}
128981          },
128982          "pedigree": {},
128983          "externalReferences": [
128984            {
128985              "type": "build-meta",
128986              "hashes": [
128987                {
128988                  "alg": "SHA-1",
128989                  "content": "2ddb20ac95c78b9b99b7ed1f3761bfb740c37d8f"
128990                }
128991              ]
128992            }
128993          ],
128994          "evidence": {},
128995          "signature": {
128996            "signature": {
128997              "publicKey": {}
128998            }
128999          },
129000          "modelCard": {
129001            "modelParameters": {
129002              "approach": {}
129003            },
129004            "quantitativeAnalysis": {
129005              "graphics": {}
129006            },
129007            "considerations": {}
129008          }
129009        },
129010        {
129011          "type": "library",
129012          "bom-ref": "pkg:maven/management-agent/management-agent?package-id=ee2660a251230db6",
129013          "supplier": {},
129014          "name": "management-agent",
129015          "cpe": "cpe:2.3:a:management-agent:management-agent:*:*:*:*:*:*:*:*",
129016          "purl": "pkg:maven/management-agent/management-agent",
129017          "swid": {
129018            "attachment": {}
129019          },
129020          "pedigree": {},
129021          "externalReferences": [
129022            {
129023              "type": "build-meta",
129024              "hashes": [
129025                {
129026                  "alg": "SHA-1",
129027                  "content": "5ad935729a468d94baf71680381a6771ec32ed4b"
129028                }
129029              ]
129030            }
129031          ],
129032          "evidence": {},
129033          "signature": {
129034            "signature": {
129035              "publicKey": {}
129036            }
129037          },
129038          "modelCard": {
129039            "modelParameters": {
129040              "approach": {}
129041            },
129042            "quantitativeAnalysis": {
129043              "graphics": {}
129044            },
129045            "considerations": {}
129046          }
129047        },
129048        {
129049          "type": "library",
129050          "bom-ref": "pkg:apk/alpine/musl@1.1.20-r4?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=da77d7b818dcca83",
129051          "supplier": {},
129052          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
129053          "name": "musl",
129054          "version": "1.1.20-r4",
129055          "description": "the musl c library (libc) implementation",
129056          "licenses": [
129057            {
129058              "license": {
129059                "id": "MIT"
129060              }
129061            }
129062          ],
129063          "cpe": "cpe:2.3:a:musl-libc:musl:1.1.20-r4:*:*:*:*:*:*:*",
129064          "purl": "pkg:apk/alpine/musl@1.1.20-r4?arch=x86_64\u0026distro=alpine-3.9.4",
129065          "swid": {
129066            "attachment": {}
129067          },
129068          "pedigree": {},
129069          "externalReferences": [
129070            {
129071              "url": "http://www.musl-libc.org/",
129072              "type": "distribution"
129073            }
129074          ],
129075          "evidence": {},
129076          "signature": {
129077            "signature": {
129078              "publicKey": {}
129079            }
129080          },
129081          "modelCard": {
129082            "modelParameters": {
129083              "approach": {}
129084            },
129085            "quantitativeAnalysis": {
129086              "graphics": {}
129087            },
129088            "considerations": {}
129089          }
129090        },
129091        {
129092          "type": "library",
129093          "bom-ref": "pkg:apk/alpine/musl-utils@1.1.20-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.9.4\u0026package-id=f4c28b86d9856cfc",
129094          "supplier": {},
129095          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
129096          "name": "musl-utils",
129097          "version": "1.1.20-r4",
129098          "description": "the musl c library (libc) implementation",
129099          "licenses": [
129100            {
129101              "license": {
129102                "id": "MIT"
129103              }
129104            },
129105            {
129106              "license": {
129107                "name": "BSD"
129108              }
129109            },
129110            {
129111              "license": {
129112                "id": "GPL-2.0-or-later"
129113              }
129114            }
129115          ],
129116          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.1.20-r4:*:*:*:*:*:*:*",
129117          "purl": "pkg:apk/alpine/musl-utils@1.1.20-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.9.4",
129118          "swid": {
129119            "attachment": {}
129120          },
129121          "pedigree": {},
129122          "externalReferences": [
129123            {
129124              "url": "http://www.musl-libc.org/",
129125              "type": "distribution"
129126            }
129127          ],
129128          "evidence": {},
129129          "signature": {
129130            "signature": {
129131              "publicKey": {}
129132            }
129133          },
129134          "modelCard": {
129135            "modelParameters": {
129136              "approach": {}
129137            },
129138            "quantitativeAnalysis": {
129139              "graphics": {}
129140            },
129141            "considerations": {}
129142          }
129143        },
129144        {
129145          "type": "library",
129146          "bom-ref": "pkg:maven/nashorn/nashorn@1.8.0_212-b04?package-id=606955922ee09a52",
129147          "supplier": {},
129148          "name": "nashorn",
129149          "version": "1.8.0_212-b04",
129150          "cpe": "cpe:2.3:a:oracle-corporation:nashorn:1.8.0_212-b04:*:*:*:*:*:*:*",
129151          "purl": "pkg:maven/nashorn/nashorn@1.8.0_212-b04",
129152          "swid": {
129153            "attachment": {}
129154          },
129155          "pedigree": {},
129156          "externalReferences": [
129157            {
129158              "type": "build-meta",
129159              "hashes": [
129160                {
129161                  "alg": "SHA-1",
129162                  "content": "fbe08ca5288808c2d51b7b21dfa83033d530e49b"
129163                }
129164              ]
129165            }
129166          ],
129167          "evidence": {},
129168          "signature": {
129169            "signature": {
129170              "publicKey": {}
129171            }
129172          },
129173          "modelCard": {
129174            "modelParameters": {
129175              "approach": {}
129176            },
129177            "quantitativeAnalysis": {
129178              "graphics": {}
129179            },
129180            "considerations": {}
129181          }
129182        },
129183        {
129184          "type": "library",
129185          "bom-ref": "pkg:apk/alpine/nspr@4.20-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=722c83ce60fccd1a",
129186          "supplier": {},
129187          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
129188          "name": "nspr",
129189          "version": "4.20-r0",
129190          "description": "Netscape Portable Runtime",
129191          "licenses": [
129192            {
129193              "license": {
129194                "id": "MPL-1.1"
129195              }
129196            },
129197            {
129198              "license": {
129199                "id": "GPL-2.0-only"
129200              }
129201            },
129202            {
129203              "license": {
129204                "id": "LGPL-2.1-only"
129205              }
129206            }
129207          ],
129208          "cpe": "cpe:2.3:a:nspr:nspr:4.20-r0:*:*:*:*:*:*:*",
129209          "purl": "pkg:apk/alpine/nspr@4.20-r0?arch=x86_64\u0026distro=alpine-3.9.4",
129210          "swid": {
129211            "attachment": {}
129212          },
129213          "pedigree": {},
129214          "externalReferences": [
129215            {
129216              "url": "http://www.mozilla.org/projects/nspr/",
129217              "type": "distribution"
129218            }
129219          ],
129220          "evidence": {},
129221          "signature": {
129222            "signature": {
129223              "publicKey": {}
129224            }
129225          },
129226          "modelCard": {
129227            "modelParameters": {
129228              "approach": {}
129229            },
129230            "quantitativeAnalysis": {
129231              "graphics": {}
129232            },
129233            "considerations": {}
129234          }
129235        },
129236        {
129237          "type": "library",
129238          "bom-ref": "pkg:apk/alpine/nss@3.41-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=eccfe151a68528f2",
129239          "supplier": {},
129240          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
129241          "name": "nss",
129242          "version": "3.41-r0",
129243          "description": "Mozilla Network Security Services",
129244          "licenses": [
129245            {
129246              "license": {
129247                "name": "MPL"
129248              }
129249            },
129250            {
129251              "license": {
129252                "name": "GPL"
129253              }
129254            }
129255          ],
129256          "cpe": "cpe:2.3:a:nss:nss:3.41-r0:*:*:*:*:*:*:*",
129257          "purl": "pkg:apk/alpine/nss@3.41-r0?arch=x86_64\u0026distro=alpine-3.9.4",
129258          "swid": {
129259            "attachment": {}
129260          },
129261          "pedigree": {},
129262          "externalReferences": [
129263            {
129264              "url": "http://www.mozilla.org/projects/security/pki/nss/",
129265              "type": "distribution"
129266            }
129267          ],
129268          "evidence": {},
129269          "signature": {
129270            "signature": {
129271              "publicKey": {}
129272            }
129273          },
129274          "modelCard": {
129275            "modelParameters": {
129276              "approach": {}
129277            },
129278            "quantitativeAnalysis": {
129279              "graphics": {}
129280            },
129281            "considerations": {}
129282          }
129283        },
129284        {
129285          "type": "library",
129286          "bom-ref": "pkg:apk/alpine/openjdk8-jre@8.212.04-r0?arch=x86_64\u0026upstream=openjdk8\u0026distro=alpine-3.9.4\u0026package-id=8d1763f1e329f423",
129287          "supplier": {},
129288          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
129289          "name": "openjdk8-jre",
129290          "version": "8.212.04-r0",
129291          "description": "OpenJDK 8 Java Runtime",
129292          "licenses": [
129293            {
129294              "license": {
129295                "name": "custom"
129296              }
129297            }
129298          ],
129299          "cpe": "cpe:2.3:a:openjdk8-jre:openjdk8-jre:8.212.04-r0:*:*:*:*:*:*:*",
129300          "purl": "pkg:apk/alpine/openjdk8-jre@8.212.04-r0?arch=x86_64\u0026upstream=openjdk8\u0026distro=alpine-3.9.4",
129301          "swid": {
129302            "attachment": {}
129303          },
129304          "pedigree": {},
129305          "externalReferences": [
129306            {
129307              "url": "https://icedtea.classpath.org/",
129308              "type": "distribution"
129309            }
129310          ],
129311          "evidence": {},
129312          "signature": {
129313            "signature": {
129314              "publicKey": {}
129315            }
129316          },
129317          "modelCard": {
129318            "modelParameters": {
129319              "approach": {}
129320            },
129321            "quantitativeAnalysis": {
129322              "graphics": {}
129323            },
129324            "considerations": {}
129325          }
129326        },
129327        {
129328          "type": "library",
129329          "bom-ref": "pkg:apk/alpine/openjdk8-jre-base@8.212.04-r0?arch=x86_64\u0026upstream=openjdk8\u0026distro=alpine-3.9.4\u0026package-id=7f93e18ec5e9327e",
129330          "supplier": {},
129331          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
129332          "name": "openjdk8-jre-base",
129333          "version": "8.212.04-r0",
129334          "description": "OpenJDK 8 Java Runtime (no GUI support)",
129335          "licenses": [
129336            {
129337              "license": {
129338                "name": "custom"
129339              }
129340            }
129341          ],
129342          "cpe": "cpe:2.3:a:openjdk8-jre-base:openjdk8-jre-base:8.212.04-r0:*:*:*:*:*:*:*",
129343          "purl": "pkg:apk/alpine/openjdk8-jre-base@8.212.04-r0?arch=x86_64\u0026upstream=openjdk8\u0026distro=alpine-3.9.4",
129344          "swid": {
129345            "attachment": {}
129346          },
129347          "pedigree": {},
129348          "externalReferences": [
129349            {
129350              "url": "https://icedtea.classpath.org/",
129351              "type": "distribution"
129352            }
129353          ],
129354          "evidence": {},
129355          "signature": {
129356            "signature": {
129357              "publicKey": {}
129358            }
129359          },
129360          "modelCard": {
129361            "modelParameters": {
129362              "approach": {}
129363            },
129364            "quantitativeAnalysis": {
129365              "graphics": {}
129366            },
129367            "considerations": {}
129368          }
129369        },
129370        {
129371          "type": "library",
129372          "bom-ref": "pkg:apk/alpine/openjdk8-jre-lib@8.212.04-r0?arch=x86_64\u0026upstream=openjdk8\u0026distro=alpine-3.9.4\u0026package-id=e3fa1d68ed731a25",
129373          "supplier": {},
129374          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
129375          "name": "openjdk8-jre-lib",
129376          "version": "8.212.04-r0",
129377          "description": "OpenJDK 8 Java Runtime (class libraries)",
129378          "licenses": [
129379            {
129380              "license": {
129381                "name": "custom"
129382              }
129383            }
129384          ],
129385          "cpe": "cpe:2.3:a:openjdk8-jre-lib:openjdk8-jre-lib:8.212.04-r0:*:*:*:*:*:*:*",
129386          "purl": "pkg:apk/alpine/openjdk8-jre-lib@8.212.04-r0?arch=x86_64\u0026upstream=openjdk8\u0026distro=alpine-3.9.4",
129387          "swid": {
129388            "attachment": {}
129389          },
129390          "pedigree": {},
129391          "externalReferences": [
129392            {
129393              "url": "https://icedtea.classpath.org/",
129394              "type": "distribution"
129395            }
129396          ],
129397          "evidence": {},
129398          "signature": {
129399            "signature": {
129400              "publicKey": {}
129401            }
129402          },
129403          "modelCard": {
129404            "modelParameters": {
129405              "approach": {}
129406            },
129407            "quantitativeAnalysis": {
129408              "graphics": {}
129409            },
129410            "considerations": {}
129411          }
129412        },
129413        {
129414          "type": "library",
129415          "bom-ref": "pkg:apk/alpine/p11-kit@0.23.14-r0?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=407a5ed3debd16f7",
129416          "supplier": {},
129417          "publisher": "Fabian Affolter \u003cfabian@affolter-engineering.ch\u003e",
129418          "name": "p11-kit",
129419          "version": "0.23.14-r0",
129420          "description": "Library for loading and sharing PKCS#11 modules",
129421          "licenses": [
129422            {
129423              "license": {
129424                "name": "BSD"
129425              }
129426            }
129427          ],
129428          "cpe": "cpe:2.3:a:p11-kit:p11-kit:0.23.14-r0:*:*:*:*:*:*:*",
129429          "purl": "pkg:apk/alpine/p11-kit@0.23.14-r0?arch=x86_64\u0026distro=alpine-3.9.4",
129430          "swid": {
129431            "attachment": {}
129432          },
129433          "pedigree": {},
129434          "externalReferences": [
129435            {
129436              "url": "https://p11-glue.freedesktop.org/",
129437              "type": "distribution"
129438            }
129439          ],
129440          "evidence": {},
129441          "signature": {
129442            "signature": {
129443              "publicKey": {}
129444            }
129445          },
129446          "modelCard": {
129447            "modelParameters": {
129448              "approach": {}
129449            },
129450            "quantitativeAnalysis": {
129451              "graphics": {}
129452            },
129453            "considerations": {}
129454          }
129455        },
129456        {
129457          "type": "library",
129458          "bom-ref": "pkg:apk/alpine/p11-kit-trust@0.23.14-r0?arch=x86_64\u0026upstream=p11-kit\u0026distro=alpine-3.9.4\u0026package-id=c33bbbefa20e1e9b",
129459          "supplier": {},
129460          "publisher": "Fabian Affolter \u003cfabian@affolter-engineering.ch\u003e",
129461          "name": "p11-kit-trust",
129462          "version": "0.23.14-r0",
129463          "description": "System trust module from p11-kit",
129464          "licenses": [
129465            {
129466              "license": {
129467                "name": "BSD"
129468              }
129469            }
129470          ],
129471          "cpe": "cpe:2.3:a:p11-kit-trust:p11-kit-trust:0.23.14-r0:*:*:*:*:*:*:*",
129472          "purl": "pkg:apk/alpine/p11-kit-trust@0.23.14-r0?arch=x86_64\u0026upstream=p11-kit\u0026distro=alpine-3.9.4",
129473          "swid": {
129474            "attachment": {}
129475          },
129476          "pedigree": {},
129477          "externalReferences": [
129478            {
129479              "url": "https://p11-glue.freedesktop.org/",
129480              "type": "distribution"
129481            }
129482          ],
129483          "evidence": {},
129484          "signature": {
129485            "signature": {
129486              "publicKey": {}
129487            }
129488          },
129489          "modelCard": {
129490            "modelParameters": {
129491              "approach": {}
129492            },
129493            "quantitativeAnalysis": {
129494              "graphics": {}
129495            },
129496            "considerations": {}
129497          }
129498        },
129499        {
129500          "type": "library",
129501          "bom-ref": "pkg:apk/alpine/pcsc-lite-libs@1.8.24-r1?arch=x86_64\u0026upstream=pcsc-lite\u0026distro=alpine-3.9.4\u0026package-id=d0a4cb0758393878",
129502          "supplier": {},
129503          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
129504          "name": "pcsc-lite-libs",
129505          "version": "1.8.24-r1",
129506          "description": "Middleware to access a smart card using SCard API (PC/SC) (libraries)",
129507          "licenses": [
129508            {
129509              "license": {
129510                "name": "Custom"
129511              }
129512            }
129513          ],
129514          "cpe": "cpe:2.3:a:pcsc-lite-libs:pcsc-lite-libs:1.8.24-r1:*:*:*:*:*:*:*",
129515          "purl": "pkg:apk/alpine/pcsc-lite-libs@1.8.24-r1?arch=x86_64\u0026upstream=pcsc-lite\u0026distro=alpine-3.9.4",
129516          "swid": {
129517            "attachment": {}
129518          },
129519          "pedigree": {},
129520          "externalReferences": [
129521            {
129522              "url": "https://pcsclite.apdu.fr/",
129523              "type": "distribution"
129524            }
129525          ],
129526          "evidence": {},
129527          "signature": {
129528            "signature": {
129529              "publicKey": {}
129530            }
129531          },
129532          "modelCard": {
129533            "modelParameters": {
129534              "approach": {}
129535            },
129536            "quantitativeAnalysis": {
129537              "graphics": {}
129538            },
129539            "considerations": {}
129540          }
129541        },
129542        {
129543          "type": "library",
129544          "bom-ref": "pkg:maven/resources/resources@1.8.0_212?package-id=6892c0c1953b226d",
129545          "supplier": {},
129546          "name": "resources",
129547          "version": "1.8.0_212",
129548          "cpe": "cpe:2.3:a:oracle-corporation:resources:1.8.0_212:*:*:*:*:*:*:*",
129549          "purl": "pkg:maven/resources/resources@1.8.0_212",
129550          "swid": {
129551            "attachment": {}
129552          },
129553          "pedigree": {},
129554          "externalReferences": [
129555            {
129556              "type": "build-meta",
129557              "hashes": [
129558                {
129559                  "alg": "SHA-1",
129560                  "content": "058b0b5d2fa4d1c6e861077f9b505d18784c54dd"
129561                }
129562              ]
129563            }
129564          ],
129565          "evidence": {},
129566          "signature": {
129567            "signature": {
129568              "publicKey": {}
129569            }
129570          },
129571          "modelCard": {
129572            "modelParameters": {
129573              "approach": {}
129574            },
129575            "quantitativeAnalysis": {
129576              "graphics": {}
129577            },
129578            "considerations": {}
129579          }
129580        },
129581        {
129582          "type": "library",
129583          "bom-ref": "pkg:maven/rt/rt@1.8.0_212?package-id=504c24e42b62eb5f",
129584          "supplier": {},
129585          "name": "rt",
129586          "version": "1.8.0_212",
129587          "cpe": "cpe:2.3:a:oracle-corporation:rt:1.8.0_212:*:*:*:*:*:*:*",
129588          "purl": "pkg:maven/rt/rt@1.8.0_212",
129589          "swid": {
129590            "attachment": {}
129591          },
129592          "pedigree": {},
129593          "externalReferences": [
129594            {
129595              "type": "build-meta",
129596              "hashes": [
129597                {
129598                  "alg": "SHA-1",
129599                  "content": "8bfb18575ade5c7352c449326354426a97e99eff"
129600                }
129601              ]
129602            }
129603          ],
129604          "evidence": {},
129605          "signature": {
129606            "signature": {
129607              "publicKey": {}
129608            }
129609          },
129610          "modelCard": {
129611            "modelParameters": {
129612              "approach": {}
129613            },
129614            "quantitativeAnalysis": {
129615              "graphics": {}
129616            },
129617            "considerations": {}
129618          }
129619        },
129620        {
129621          "type": "library",
129622          "bom-ref": "pkg:apk/alpine/scanelf@1.2.3-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.9.4\u0026package-id=a04b4c0278a4015c",
129623          "supplier": {},
129624          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
129625          "name": "scanelf",
129626          "version": "1.2.3-r0",
129627          "description": "Scan ELF binaries for stuff",
129628          "licenses": [
129629            {
129630              "license": {
129631                "id": "GPL-2.0-only"
129632              }
129633            }
129634          ],
129635          "cpe": "cpe:2.3:a:scanelf:scanelf:1.2.3-r0:*:*:*:*:*:*:*",
129636          "purl": "pkg:apk/alpine/scanelf@1.2.3-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.9.4",
129637          "swid": {
129638            "attachment": {}
129639          },
129640          "pedigree": {},
129641          "externalReferences": [
129642            {
129643              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
129644              "type": "distribution"
129645            }
129646          ],
129647          "evidence": {},
129648          "signature": {
129649            "signature": {
129650              "publicKey": {}
129651            }
129652          },
129653          "modelCard": {
129654            "modelParameters": {
129655              "approach": {}
129656            },
129657            "quantitativeAnalysis": {
129658              "graphics": {}
129659            },
129660            "considerations": {}
129661          }
129662        },
129663        {
129664          "type": "library",
129665          "bom-ref": "pkg:apk/alpine/sqlite-libs@3.26.0-r3?arch=x86_64\u0026upstream=sqlite\u0026distro=alpine-3.9.4\u0026package-id=25c740fcd85e3d6c",
129666          "supplier": {},
129667          "publisher": "Carlo Landmeter \u003cclandmeter@gmail.com\u003e",
129668          "name": "sqlite-libs",
129669          "version": "3.26.0-r3",
129670          "description": "Sqlite3 library",
129671          "licenses": [
129672            {
129673              "license": {
129674                "name": "Public-Domain"
129675              }
129676            }
129677          ],
129678          "cpe": "cpe:2.3:a:sqlite-libs:sqlite-libs:3.26.0-r3:*:*:*:*:*:*:*",
129679          "purl": "pkg:apk/alpine/sqlite-libs@3.26.0-r3?arch=x86_64\u0026upstream=sqlite\u0026distro=alpine-3.9.4",
129680          "swid": {
129681            "attachment": {}
129682          },
129683          "pedigree": {},
129684          "externalReferences": [
129685            {
129686              "url": "http://www.sqlite.org",
129687              "type": "distribution"
129688            }
129689          ],
129690          "evidence": {},
129691          "signature": {
129692            "signature": {
129693              "publicKey": {}
129694            }
129695          },
129696          "modelCard": {
129697            "modelParameters": {
129698              "approach": {}
129699            },
129700            "quantitativeAnalysis": {
129701              "graphics": {}
129702            },
129703            "considerations": {}
129704          }
129705        },
129706        {
129707          "type": "library",
129708          "bom-ref": "pkg:apk/alpine/ssl_client@1.29.3-r10?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.9.4\u0026package-id=d77875e77b763cf9",
129709          "supplier": {},
129710          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
129711          "name": "ssl_client",
129712          "version": "1.29.3-r10",
129713          "description": "EXternal ssl_client for busybox wget",
129714          "licenses": [
129715            {
129716              "license": {
129717                "id": "GPL-2.0-only"
129718              }
129719            }
129720          ],
129721          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.29.3-r10:*:*:*:*:*:*:*",
129722          "purl": "pkg:apk/alpine/ssl_client@1.29.3-r10?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.9.4",
129723          "swid": {
129724            "attachment": {}
129725          },
129726          "pedigree": {},
129727          "externalReferences": [
129728            {
129729              "url": "http://busybox.net",
129730              "type": "distribution"
129731            }
129732          ],
129733          "evidence": {},
129734          "signature": {
129735            "signature": {
129736              "publicKey": {}
129737            }
129738          },
129739          "modelCard": {
129740            "modelParameters": {
129741              "approach": {}
129742            },
129743            "quantitativeAnalysis": {
129744              "graphics": {}
129745            },
129746            "considerations": {}
129747          }
129748        },
129749        {
129750          "type": "library",
129751          "bom-ref": "pkg:maven/com.sun/sunec@1.8.0_212?package-id=3a6bfbe372f66229",
129752          "supplier": {},
129753          "name": "sunec",
129754          "version": "1.8.0_212",
129755          "cpe": "cpe:2.3:a:oracle-corporation:sunec:1.8.0_212:*:*:*:*:*:*:*",
129756          "purl": "pkg:maven/com.sun/sunec@1.8.0_212",
129757          "swid": {
129758            "attachment": {}
129759          },
129760          "pedigree": {},
129761          "externalReferences": [
129762            {
129763              "type": "build-meta",
129764              "hashes": [
129765                {
129766                  "alg": "SHA-1",
129767                  "content": "28b0b4b73a2e3ad2d1ba948859d61614be535496"
129768                }
129769              ]
129770            }
129771          ],
129772          "evidence": {},
129773          "signature": {
129774            "signature": {
129775              "publicKey": {}
129776            }
129777          },
129778          "modelCard": {
129779            "modelParameters": {
129780              "approach": {}
129781            },
129782            "quantitativeAnalysis": {
129783              "graphics": {}
129784            },
129785            "considerations": {}
129786          }
129787        },
129788        {
129789          "type": "library",
129790          "bom-ref": "pkg:maven/com.sun/sunjce_provider@1.8.0_212?package-id=671357c13741117b",
129791          "supplier": {},
129792          "name": "sunjce_provider",
129793          "version": "1.8.0_212",
129794          "cpe": "cpe:2.3:a:oracle-corporation:sunjce-provider:1.8.0_212:*:*:*:*:*:*:*",
129795          "purl": "pkg:maven/com.sun/sunjce_provider@1.8.0_212",
129796          "swid": {
129797            "attachment": {}
129798          },
129799          "pedigree": {},
129800          "externalReferences": [
129801            {
129802              "type": "build-meta",
129803              "hashes": [
129804                {
129805                  "alg": "SHA-1",
129806                  "content": "9ee8b3a1deadc99d937a99436e28d2165526dc52"
129807                }
129808              ]
129809            }
129810          ],
129811          "evidence": {},
129812          "signature": {
129813            "signature": {
129814              "publicKey": {}
129815            }
129816          },
129817          "modelCard": {
129818            "modelParameters": {
129819              "approach": {}
129820            },
129821            "quantitativeAnalysis": {
129822              "graphics": {}
129823            },
129824            "considerations": {}
129825          }
129826        },
129827        {
129828          "type": "library",
129829          "bom-ref": "pkg:maven/com.sun/sunpkcs11@1.8.0_212?package-id=3daf763897494509",
129830          "supplier": {},
129831          "name": "sunpkcs11",
129832          "version": "1.8.0_212",
129833          "cpe": "cpe:2.3:a:oracle-corporation:sunpkcs11:1.8.0_212:*:*:*:*:*:*:*",
129834          "purl": "pkg:maven/com.sun/sunpkcs11@1.8.0_212",
129835          "swid": {
129836            "attachment": {}
129837          },
129838          "pedigree": {},
129839          "externalReferences": [
129840            {
129841              "type": "build-meta",
129842              "hashes": [
129843                {
129844                  "alg": "SHA-1",
129845                  "content": "3336e4ed99c6af1494984ea8459a600efe43231e"
129846                }
129847              ]
129848            }
129849          ],
129850          "evidence": {},
129851          "signature": {
129852            "signature": {
129853              "publicKey": {}
129854            }
129855          },
129856          "modelCard": {
129857            "modelParameters": {
129858              "approach": {}
129859            },
129860            "quantitativeAnalysis": {
129861              "graphics": {}
129862            },
129863            "considerations": {}
129864          }
129865        },
129866        {
129867          "type": "library",
129868          "bom-ref": "pkg:maven/zipfs/zipfs@1.8.0_212?package-id=d289699e0ed8cb87",
129869          "supplier": {},
129870          "name": "zipfs",
129871          "version": "1.8.0_212",
129872          "cpe": "cpe:2.3:a:oracle-corporation:zipfs:1.8.0_212:*:*:*:*:*:*:*",
129873          "purl": "pkg:maven/zipfs/zipfs@1.8.0_212",
129874          "swid": {
129875            "attachment": {}
129876          },
129877          "pedigree": {},
129878          "externalReferences": [
129879            {
129880              "type": "build-meta",
129881              "hashes": [
129882                {
129883                  "alg": "SHA-1",
129884                  "content": "ef8360bb3117276313d0588d71767d44b021d498"
129885                }
129886              ]
129887            }
129888          ],
129889          "evidence": {},
129890          "signature": {
129891            "signature": {
129892              "publicKey": {}
129893            }
129894          },
129895          "modelCard": {
129896            "modelParameters": {
129897              "approach": {}
129898            },
129899            "quantitativeAnalysis": {
129900              "graphics": {}
129901            },
129902            "considerations": {}
129903          }
129904        },
129905        {
129906          "type": "library",
129907          "bom-ref": "pkg:apk/alpine/zlib@1.2.11-r1?arch=x86_64\u0026distro=alpine-3.9.4\u0026package-id=ef697b2585f09f7f",
129908          "supplier": {},
129909          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
129910          "name": "zlib",
129911          "version": "1.2.11-r1",
129912          "description": "A compression/decompression Library",
129913          "licenses": [
129914            {
129915              "license": {
129916                "id": "Zlib"
129917              }
129918            }
129919          ],
129920          "cpe": "cpe:2.3:a:zlib:zlib:1.2.11-r1:*:*:*:*:*:*:*",
129921          "purl": "pkg:apk/alpine/zlib@1.2.11-r1?arch=x86_64\u0026distro=alpine-3.9.4",
129922          "swid": {
129923            "attachment": {}
129924          },
129925          "pedigree": {},
129926          "externalReferences": [
129927            {
129928              "url": "http://zlib.net",
129929              "type": "distribution"
129930            }
129931          ],
129932          "evidence": {},
129933          "signature": {
129934            "signature": {
129935              "publicKey": {}
129936            }
129937          },
129938          "modelCard": {
129939            "modelParameters": {
129940              "approach": {}
129941            },
129942            "quantitativeAnalysis": {
129943              "graphics": {}
129944            },
129945            "considerations": {}
129946          }
129947        },
129948        {
129949          "type": "operating-system",
129950          "supplier": {},
129951          "name": "alpine",
129952          "version": "3.9.4",
129953          "description": "Alpine Linux v3.9",
129954          "swid": {
129955            "tagId": "alpine",
129956            "name": "alpine",
129957            "version": "3.9.4",
129958            "attachment": {}
129959          },
129960          "pedigree": {},
129961          "externalReferences": [
129962            {
129963              "url": "https://bugs.alpinelinux.org/",
129964              "type": "issue-tracker"
129965            },
129966            {
129967              "url": "https://alpinelinux.org/",
129968              "type": "website"
129969            }
129970          ],
129971          "evidence": {},
129972          "signature": {
129973            "signature": {
129974              "publicKey": {}
129975            }
129976          },
129977          "modelCard": {
129978            "modelParameters": {
129979              "approach": {}
129980            },
129981            "quantitativeAnalysis": {
129982              "graphics": {}
129983            },
129984            "considerations": {}
129985          }
129986        },
129987        {
129988          "type": "library",
129989          "bom-ref": "pkg:rpm/rhel/audit-libs@3.0.7-2.el8.2?arch=x86_64\u0026upstream=audit-3.0.7-2.el8.2.src.rpm\u0026distro=rhel-8.6\u0026package-id=66e683a1875601a6",
129990          "supplier": {},
129991          "publisher": "Red Hat, Inc.",
129992          "name": "audit-libs",
129993          "version": "3.0.7-2.el8.2",
129994          "licenses": [
129995            {
129996              "license": {
129997                "name": "LGPLv2+"
129998              }
129999            }
130000          ],
130001          "cpe": "cpe:2.3:a:audit-libs:audit-libs:3.0.7-2.el8.2:*:*:*:*:*:*:*",
130002          "purl": "pkg:rpm/rhel/audit-libs@3.0.7-2.el8.2?arch=x86_64\u0026upstream=audit-3.0.7-2.el8.2.src.rpm\u0026distro=rhel-8.6",
130003          "swid": {
130004            "attachment": {}
130005          },
130006          "pedigree": {},
130007          "evidence": {},
130008          "signature": {
130009            "signature": {
130010              "publicKey": {}
130011            }
130012          },
130013          "modelCard": {
130014            "modelParameters": {
130015              "approach": {}
130016            },
130017            "quantitativeAnalysis": {
130018              "graphics": {}
130019            },
130020            "considerations": {}
130021          }
130022        },
130023        {
130024          "type": "library",
130025          "bom-ref": "pkg:rpm/rhel/basesystem@11-5.el8?arch=noarch\u0026upstream=basesystem-11-5.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=32ab6ec64951c2f9",
130026          "supplier": {},
130027          "publisher": "Red Hat, Inc.",
130028          "name": "basesystem",
130029          "version": "11-5.el8",
130030          "licenses": [
130031            {
130032              "license": {
130033                "name": "Public Domain"
130034              }
130035            }
130036          ],
130037          "cpe": "cpe:2.3:a:basesystem:basesystem:11-5.el8:*:*:*:*:*:*:*",
130038          "purl": "pkg:rpm/rhel/basesystem@11-5.el8?arch=noarch\u0026upstream=basesystem-11-5.el8.src.rpm\u0026distro=rhel-8.6",
130039          "swid": {
130040            "attachment": {}
130041          },
130042          "pedigree": {},
130043          "evidence": {},
130044          "signature": {
130045            "signature": {
130046              "publicKey": {}
130047            }
130048          },
130049          "modelCard": {
130050            "modelParameters": {
130051              "approach": {}
130052            },
130053            "quantitativeAnalysis": {
130054              "graphics": {}
130055            },
130056            "considerations": {}
130057          }
130058        },
130059        {
130060          "type": "library",
130061          "bom-ref": "pkg:rpm/rhel/bash@4.4.20-4.el8_6?arch=x86_64\u0026upstream=bash-4.4.20-4.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=3a3e27ed335150ba",
130062          "supplier": {},
130063          "publisher": "Red Hat, Inc.",
130064          "name": "bash",
130065          "version": "4.4.20-4.el8_6",
130066          "licenses": [
130067            {
130068              "license": {
130069                "name": "GPLv3+"
130070              }
130071            }
130072          ],
130073          "cpe": "cpe:2.3:a:redhat:bash:4.4.20-4.el8_6:*:*:*:*:*:*:*",
130074          "purl": "pkg:rpm/rhel/bash@4.4.20-4.el8_6?arch=x86_64\u0026upstream=bash-4.4.20-4.el8_6.src.rpm\u0026distro=rhel-8.6",
130075          "swid": {
130076            "attachment": {}
130077          },
130078          "pedigree": {},
130079          "evidence": {},
130080          "signature": {
130081            "signature": {
130082              "publicKey": {}
130083            }
130084          },
130085          "modelCard": {
130086            "modelParameters": {
130087              "approach": {}
130088            },
130089            "quantitativeAnalysis": {
130090              "graphics": {}
130091            },
130092            "considerations": {}
130093          }
130094        },
130095        {
130096          "type": "library",
130097          "bom-ref": "pkg:rpm/rhel/brotli@1.0.6-3.el8?arch=x86_64\u0026upstream=brotli-1.0.6-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=f870f5a4c3c9509e",
130098          "supplier": {},
130099          "publisher": "Red Hat, Inc.",
130100          "name": "brotli",
130101          "version": "1.0.6-3.el8",
130102          "licenses": [
130103            {
130104              "license": {
130105                "id": "MIT"
130106              }
130107            }
130108          ],
130109          "cpe": "cpe:2.3:a:brotli:brotli:1.0.6-3.el8:*:*:*:*:*:*:*",
130110          "purl": "pkg:rpm/rhel/brotli@1.0.6-3.el8?arch=x86_64\u0026upstream=brotli-1.0.6-3.el8.src.rpm\u0026distro=rhel-8.6",
130111          "swid": {
130112            "attachment": {}
130113          },
130114          "pedigree": {},
130115          "evidence": {},
130116          "signature": {
130117            "signature": {
130118              "publicKey": {}
130119            }
130120          },
130121          "modelCard": {
130122            "modelParameters": {
130123              "approach": {}
130124            },
130125            "quantitativeAnalysis": {
130126              "graphics": {}
130127            },
130128            "considerations": {}
130129          }
130130        },
130131        {
130132          "type": "library",
130133          "bom-ref": "pkg:rpm/rhel/bzip2-libs@1.0.6-26.el8?arch=x86_64\u0026upstream=bzip2-1.0.6-26.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=bac3b5b8910ea8",
130134          "supplier": {},
130135          "publisher": "Red Hat, Inc.",
130136          "name": "bzip2-libs",
130137          "version": "1.0.6-26.el8",
130138          "licenses": [
130139            {
130140              "license": {
130141                "name": "BSD"
130142              }
130143            }
130144          ],
130145          "cpe": "cpe:2.3:a:bzip2-libs:bzip2-libs:1.0.6-26.el8:*:*:*:*:*:*:*",
130146          "purl": "pkg:rpm/rhel/bzip2-libs@1.0.6-26.el8?arch=x86_64\u0026upstream=bzip2-1.0.6-26.el8.src.rpm\u0026distro=rhel-8.6",
130147          "swid": {
130148            "attachment": {}
130149          },
130150          "pedigree": {},
130151          "evidence": {},
130152          "signature": {
130153            "signature": {
130154              "publicKey": {}
130155            }
130156          },
130157          "modelCard": {
130158            "modelParameters": {
130159              "approach": {}
130160            },
130161            "quantitativeAnalysis": {
130162              "graphics": {}
130163            },
130164            "considerations": {}
130165          }
130166        },
130167        {
130168          "type": "library",
130169          "bom-ref": "pkg:rpm/rhel/ca-certificates@2022.2.54-80.2.el8_6?arch=noarch\u0026upstream=ca-certificates-2022.2.54-80.2.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=a9ae7ff2ca0aefda",
130170          "supplier": {},
130171          "publisher": "Red Hat, Inc.",
130172          "name": "ca-certificates",
130173          "version": "2022.2.54-80.2.el8_6",
130174          "licenses": [
130175            {
130176              "license": {
130177                "name": "Public Domain"
130178              }
130179            }
130180          ],
130181          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:2022.2.54-80.2.el8_6:*:*:*:*:*:*:*",
130182          "purl": "pkg:rpm/rhel/ca-certificates@2022.2.54-80.2.el8_6?arch=noarch\u0026upstream=ca-certificates-2022.2.54-80.2.el8_6.src.rpm\u0026distro=rhel-8.6",
130183          "swid": {
130184            "attachment": {}
130185          },
130186          "pedigree": {},
130187          "evidence": {},
130188          "signature": {
130189            "signature": {
130190              "publicKey": {}
130191            }
130192          },
130193          "modelCard": {
130194            "modelParameters": {
130195              "approach": {}
130196            },
130197            "quantitativeAnalysis": {
130198              "graphics": {}
130199            },
130200            "considerations": {}
130201          }
130202        },
130203        {
130204          "type": "library",
130205          "bom-ref": "pkg:rpm/rhel/chkconfig@1.19.1-1.el8?arch=x86_64\u0026upstream=chkconfig-1.19.1-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=43d15da7260fb61b",
130206          "supplier": {},
130207          "publisher": "Red Hat, Inc.",
130208          "name": "chkconfig",
130209          "version": "1.19.1-1.el8",
130210          "licenses": [
130211            {
130212              "license": {
130213                "name": "GPLv2"
130214              }
130215            }
130216          ],
130217          "cpe": "cpe:2.3:a:chkconfig:chkconfig:1.19.1-1.el8:*:*:*:*:*:*:*",
130218          "purl": "pkg:rpm/rhel/chkconfig@1.19.1-1.el8?arch=x86_64\u0026upstream=chkconfig-1.19.1-1.el8.src.rpm\u0026distro=rhel-8.6",
130219          "swid": {
130220            "attachment": {}
130221          },
130222          "pedigree": {},
130223          "evidence": {},
130224          "signature": {
130225            "signature": {
130226              "publicKey": {}
130227            }
130228          },
130229          "modelCard": {
130230            "modelParameters": {
130231              "approach": {}
130232            },
130233            "quantitativeAnalysis": {
130234              "graphics": {}
130235            },
130236            "considerations": {}
130237          }
130238        },
130239        {
130240          "type": "library",
130241          "bom-ref": "pkg:golang/cloud.google.com/go@v0.104.0?package-id=e5fa38b4cb58bd44",
130242          "supplier": {},
130243          "name": "cloud.google.com/go",
130244          "version": "v0.104.0",
130245          "purl": "pkg:golang/cloud.google.com/go@v0.104.0",
130246          "swid": {
130247            "attachment": {}
130248          },
130249          "pedigree": {},
130250          "evidence": {},
130251          "signature": {
130252            "signature": {
130253              "publicKey": {}
130254            }
130255          },
130256          "modelCard": {
130257            "modelParameters": {
130258              "approach": {}
130259            },
130260            "quantitativeAnalysis": {
130261              "graphics": {}
130262            },
130263            "considerations": {}
130264          }
130265        },
130266        {
130267          "type": "library",
130268          "bom-ref": "pkg:golang/cloud.google.com/go/compute@v1.10.0?package-id=76b0548566928b7a",
130269          "supplier": {},
130270          "name": "cloud.google.com/go/compute",
130271          "version": "v1.10.0",
130272          "cpe": "cpe:2.3:a:go:compute:v1.10.0:*:*:*:*:*:*:*",
130273          "purl": "pkg:golang/cloud.google.com/go/compute@v1.10.0",
130274          "swid": {
130275            "attachment": {}
130276          },
130277          "pedigree": {},
130278          "evidence": {},
130279          "signature": {
130280            "signature": {
130281              "publicKey": {}
130282            }
130283          },
130284          "modelCard": {
130285            "modelParameters": {
130286              "approach": {}
130287            },
130288            "quantitativeAnalysis": {
130289              "graphics": {}
130290            },
130291            "considerations": {}
130292          }
130293        },
130294        {
130295          "type": "library",
130296          "bom-ref": "pkg:golang/cloud.google.com/go/iam@v0.4.0?package-id=7548bc9844825eb8",
130297          "supplier": {},
130298          "name": "cloud.google.com/go/iam",
130299          "version": "v0.4.0",
130300          "cpe": "cpe:2.3:a:go:iam:v0.4.0:*:*:*:*:*:*:*",
130301          "purl": "pkg:golang/cloud.google.com/go/iam@v0.4.0",
130302          "swid": {
130303            "attachment": {}
130304          },
130305          "pedigree": {},
130306          "evidence": {},
130307          "signature": {
130308            "signature": {
130309              "publicKey": {}
130310            }
130311          },
130312          "modelCard": {
130313            "modelParameters": {
130314              "approach": {}
130315            },
130316            "quantitativeAnalysis": {
130317              "graphics": {}
130318            },
130319            "considerations": {}
130320          }
130321        },
130322        {
130323          "type": "library",
130324          "bom-ref": "pkg:golang/cloud.google.com/go/storage@v1.26.0?package-id=a022debfe49630be",
130325          "supplier": {},
130326          "name": "cloud.google.com/go/storage",
130327          "version": "v1.26.0",
130328          "cpe": "cpe:2.3:a:go:storage:v1.26.0:*:*:*:*:*:*:*",
130329          "purl": "pkg:golang/cloud.google.com/go/storage@v1.26.0",
130330          "swid": {
130331            "attachment": {}
130332          },
130333          "pedigree": {},
130334          "evidence": {},
130335          "signature": {
130336            "signature": {
130337              "publicKey": {}
130338            }
130339          },
130340          "modelCard": {
130341            "modelParameters": {
130342              "approach": {}
130343            },
130344            "quantitativeAnalysis": {
130345              "graphics": {}
130346            },
130347            "considerations": {}
130348          }
130349        },
130350        {
130351          "type": "library",
130352          "bom-ref": "pkg:rpm/rhel/coreutils-single@8.30-12.el8?arch=x86_64\u0026upstream=coreutils-8.30-12.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=7540137126f39d71",
130353          "supplier": {},
130354          "publisher": "Red Hat, Inc.",
130355          "name": "coreutils-single",
130356          "version": "8.30-12.el8",
130357          "licenses": [
130358            {
130359              "license": {
130360                "name": "GPLv3+"
130361              }
130362            }
130363          ],
130364          "cpe": "cpe:2.3:a:coreutils-single:coreutils-single:8.30-12.el8:*:*:*:*:*:*:*",
130365          "purl": "pkg:rpm/rhel/coreutils-single@8.30-12.el8?arch=x86_64\u0026upstream=coreutils-8.30-12.el8.src.rpm\u0026distro=rhel-8.6",
130366          "swid": {
130367            "attachment": {}
130368          },
130369          "pedigree": {},
130370          "evidence": {},
130371          "signature": {
130372            "signature": {
130373              "publicKey": {}
130374            }
130375          },
130376          "modelCard": {
130377            "modelParameters": {
130378              "approach": {}
130379            },
130380            "quantitativeAnalysis": {
130381              "graphics": {}
130382            },
130383            "considerations": {}
130384          }
130385        },
130386        {
130387          "type": "library",
130388          "bom-ref": "pkg:rpm/rhel/cracklib@2.9.6-15.el8?arch=x86_64\u0026upstream=cracklib-2.9.6-15.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=fbcbd1b8e9d6c609",
130389          "supplier": {},
130390          "publisher": "Red Hat, Inc.",
130391          "name": "cracklib",
130392          "version": "2.9.6-15.el8",
130393          "licenses": [
130394            {
130395              "license": {
130396                "name": "LGPLv2+"
130397              }
130398            }
130399          ],
130400          "cpe": "cpe:2.3:a:cracklib:cracklib:2.9.6-15.el8:*:*:*:*:*:*:*",
130401          "purl": "pkg:rpm/rhel/cracklib@2.9.6-15.el8?arch=x86_64\u0026upstream=cracklib-2.9.6-15.el8.src.rpm\u0026distro=rhel-8.6",
130402          "swid": {
130403            "attachment": {}
130404          },
130405          "pedigree": {},
130406          "evidence": {},
130407          "signature": {
130408            "signature": {
130409              "publicKey": {}
130410            }
130411          },
130412          "modelCard": {
130413            "modelParameters": {
130414              "approach": {}
130415            },
130416            "quantitativeAnalysis": {
130417              "graphics": {}
130418            },
130419            "considerations": {}
130420          }
130421        },
130422        {
130423          "type": "library",
130424          "bom-ref": "pkg:rpm/rhel/cracklib-dicts@2.9.6-15.el8?arch=x86_64\u0026upstream=cracklib-2.9.6-15.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=5583133586aef509",
130425          "supplier": {},
130426          "publisher": "Red Hat, Inc.",
130427          "name": "cracklib-dicts",
130428          "version": "2.9.6-15.el8",
130429          "licenses": [
130430            {
130431              "license": {
130432                "name": "LGPLv2+"
130433              }
130434            }
130435          ],
130436          "cpe": "cpe:2.3:a:cracklib-dicts:cracklib-dicts:2.9.6-15.el8:*:*:*:*:*:*:*",
130437          "purl": "pkg:rpm/rhel/cracklib-dicts@2.9.6-15.el8?arch=x86_64\u0026upstream=cracklib-2.9.6-15.el8.src.rpm\u0026distro=rhel-8.6",
130438          "swid": {
130439            "attachment": {}
130440          },
130441          "pedigree": {},
130442          "evidence": {},
130443          "signature": {
130444            "signature": {
130445              "publicKey": {}
130446            }
130447          },
130448          "modelCard": {
130449            "modelParameters": {
130450              "approach": {}
130451            },
130452            "quantitativeAnalysis": {
130453              "graphics": {}
130454            },
130455            "considerations": {}
130456          }
130457        },
130458        {
130459          "type": "library",
130460          "bom-ref": "pkg:rpm/rhel/crypto-policies@20211116-1.gitae470d6.el8?arch=noarch\u0026upstream=crypto-policies-20211116-1.gitae470d6.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=d0c79ee3e4914c6a",
130461          "supplier": {},
130462          "publisher": "Red Hat, Inc.",
130463          "name": "crypto-policies",
130464          "version": "20211116-1.gitae470d6.el8",
130465          "licenses": [
130466            {
130467              "license": {
130468                "name": "LGPLv2+"
130469              }
130470            }
130471          ],
130472          "cpe": "cpe:2.3:a:crypto-policies:crypto-policies:20211116-1.gitae470d6.el8:*:*:*:*:*:*:*",
130473          "purl": "pkg:rpm/rhel/crypto-policies@20211116-1.gitae470d6.el8?arch=noarch\u0026upstream=crypto-policies-20211116-1.gitae470d6.el8.src.rpm\u0026distro=rhel-8.6",
130474          "swid": {
130475            "attachment": {}
130476          },
130477          "pedigree": {},
130478          "evidence": {},
130479          "signature": {
130480            "signature": {
130481              "publicKey": {}
130482            }
130483          },
130484          "modelCard": {
130485            "modelParameters": {
130486              "approach": {}
130487            },
130488            "quantitativeAnalysis": {
130489              "graphics": {}
130490            },
130491            "considerations": {}
130492          }
130493        },
130494        {
130495          "type": "library",
130496          "bom-ref": "pkg:rpm/rhel/curl@7.61.1-22.el8_6.4?arch=x86_64\u0026upstream=curl-7.61.1-22.el8_6.4.src.rpm\u0026distro=rhel-8.6\u0026package-id=a2890d13e930db6a",
130497          "supplier": {},
130498          "publisher": "Red Hat, Inc.",
130499          "name": "curl",
130500          "version": "7.61.1-22.el8_6.4",
130501          "licenses": [
130502            {
130503              "license": {
130504                "id": "MIT"
130505              }
130506            }
130507          ],
130508          "cpe": "cpe:2.3:a:redhat:curl:7.61.1-22.el8_6.4:*:*:*:*:*:*:*",
130509          "purl": "pkg:rpm/rhel/curl@7.61.1-22.el8_6.4?arch=x86_64\u0026upstream=curl-7.61.1-22.el8_6.4.src.rpm\u0026distro=rhel-8.6",
130510          "swid": {
130511            "attachment": {}
130512          },
130513          "pedigree": {},
130514          "evidence": {},
130515          "signature": {
130516            "signature": {
130517              "publicKey": {}
130518            }
130519          },
130520          "modelCard": {
130521            "modelParameters": {
130522              "approach": {}
130523            },
130524            "quantitativeAnalysis": {
130525              "graphics": {}
130526            },
130527            "considerations": {}
130528          }
130529        },
130530        {
130531          "type": "library",
130532          "bom-ref": "pkg:rpm/rhel/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64\u0026upstream=cyrus-sasl-2.1.27-6.el8_5.src.rpm\u0026distro=rhel-8.6\u0026package-id=b8eb1522e7ef9f09",
130533          "supplier": {},
130534          "publisher": "Red Hat, Inc.",
130535          "name": "cyrus-sasl-lib",
130536          "version": "2.1.27-6.el8_5",
130537          "licenses": [
130538            {
130539              "license": {
130540                "name": "BSD with advertising"
130541              }
130542            }
130543          ],
130544          "cpe": "cpe:2.3:a:cyrus-sasl-lib:cyrus-sasl-lib:2.1.27-6.el8_5:*:*:*:*:*:*:*",
130545          "purl": "pkg:rpm/rhel/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64\u0026upstream=cyrus-sasl-2.1.27-6.el8_5.src.rpm\u0026distro=rhel-8.6",
130546          "swid": {
130547            "attachment": {}
130548          },
130549          "pedigree": {},
130550          "evidence": {},
130551          "signature": {
130552            "signature": {
130553              "publicKey": {}
130554            }
130555          },
130556          "modelCard": {
130557            "modelParameters": {
130558              "approach": {}
130559            },
130560            "quantitativeAnalysis": {
130561              "graphics": {}
130562            },
130563            "considerations": {}
130564          }
130565        },
130566        {
130567          "type": "library",
130568          "bom-ref": "pkg:rpm/rhel/elfutils-libelf@0.186-1.el8?arch=x86_64\u0026upstream=elfutils-0.186-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=185c0ed992424df9",
130569          "supplier": {},
130570          "publisher": "Red Hat, Inc.",
130571          "name": "elfutils-libelf",
130572          "version": "0.186-1.el8",
130573          "licenses": [
130574            {
130575              "license": {
130576                "name": "GPLv2+ or LGPLv3+"
130577              }
130578            }
130579          ],
130580          "cpe": "cpe:2.3:a:elfutils-libelf:elfutils-libelf:0.186-1.el8:*:*:*:*:*:*:*",
130581          "purl": "pkg:rpm/rhel/elfutils-libelf@0.186-1.el8?arch=x86_64\u0026upstream=elfutils-0.186-1.el8.src.rpm\u0026distro=rhel-8.6",
130582          "swid": {
130583            "attachment": {}
130584          },
130585          "pedigree": {},
130586          "evidence": {},
130587          "signature": {
130588            "signature": {
130589              "publicKey": {}
130590            }
130591          },
130592          "modelCard": {
130593            "modelParameters": {
130594              "approach": {}
130595            },
130596            "quantitativeAnalysis": {
130597              "graphics": {}
130598            },
130599            "considerations": {}
130600          }
130601        },
130602        {
130603          "type": "library",
130604          "bom-ref": "pkg:rpm/rhel/epel-release@8-17.el8?arch=noarch\u0026upstream=epel-release-8-17.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=3b935f3cb36bec5c",
130605          "supplier": {},
130606          "publisher": "Fedora Project",
130607          "name": "epel-release",
130608          "version": "8-17.el8",
130609          "licenses": [
130610            {
130611              "license": {
130612                "name": "GPLv2"
130613              }
130614            }
130615          ],
130616          "cpe": "cpe:2.3:a:fedoraproject:epel-release:8-17.el8:*:*:*:*:*:*:*",
130617          "purl": "pkg:rpm/rhel/epel-release@8-17.el8?arch=noarch\u0026upstream=epel-release-8-17.el8.src.rpm\u0026distro=rhel-8.6",
130618          "swid": {
130619            "attachment": {}
130620          },
130621          "pedigree": {},
130622          "evidence": {},
130623          "signature": {
130624            "signature": {
130625              "publicKey": {}
130626            }
130627          },
130628          "modelCard": {
130629            "modelParameters": {
130630              "approach": {}
130631            },
130632            "quantitativeAnalysis": {
130633              "graphics": {}
130634            },
130635            "considerations": {}
130636          }
130637        },
130638        {
130639          "type": "library",
130640          "bom-ref": "pkg:rpm/rhel/file-libs@5.33-20.el8?arch=x86_64\u0026upstream=file-5.33-20.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=e27c01b0a8977c13",
130641          "supplier": {},
130642          "publisher": "Red Hat, Inc.",
130643          "name": "file-libs",
130644          "version": "5.33-20.el8",
130645          "licenses": [
130646            {
130647              "license": {
130648                "name": "BSD"
130649              }
130650            }
130651          ],
130652          "cpe": "cpe:2.3:a:file-libs:file-libs:5.33-20.el8:*:*:*:*:*:*:*",
130653          "purl": "pkg:rpm/rhel/file-libs@5.33-20.el8?arch=x86_64\u0026upstream=file-5.33-20.el8.src.rpm\u0026distro=rhel-8.6",
130654          "swid": {
130655            "attachment": {}
130656          },
130657          "pedigree": {},
130658          "evidence": {},
130659          "signature": {
130660            "signature": {
130661              "publicKey": {}
130662            }
130663          },
130664          "modelCard": {
130665            "modelParameters": {
130666              "approach": {}
130667            },
130668            "quantitativeAnalysis": {
130669              "graphics": {}
130670            },
130671            "considerations": {}
130672          }
130673        },
130674        {
130675          "type": "library",
130676          "bom-ref": "pkg:rpm/rhel/filesystem@3.8-6.el8?arch=x86_64\u0026upstream=filesystem-3.8-6.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=240b338f77f520be",
130677          "supplier": {},
130678          "publisher": "Red Hat, Inc.",
130679          "name": "filesystem",
130680          "version": "3.8-6.el8",
130681          "licenses": [
130682            {
130683              "license": {
130684                "name": "Public Domain"
130685              }
130686            }
130687          ],
130688          "cpe": "cpe:2.3:a:filesystem:filesystem:3.8-6.el8:*:*:*:*:*:*:*",
130689          "purl": "pkg:rpm/rhel/filesystem@3.8-6.el8?arch=x86_64\u0026upstream=filesystem-3.8-6.el8.src.rpm\u0026distro=rhel-8.6",
130690          "swid": {
130691            "attachment": {}
130692          },
130693          "pedigree": {},
130694          "evidence": {},
130695          "signature": {
130696            "signature": {
130697              "publicKey": {}
130698            }
130699          },
130700          "modelCard": {
130701            "modelParameters": {
130702              "approach": {}
130703            },
130704            "quantitativeAnalysis": {
130705              "graphics": {}
130706            },
130707            "considerations": {}
130708          }
130709        },
130710        {
130711          "type": "library",
130712          "bom-ref": "pkg:rpm/rhel/gawk@4.2.1-4.el8?arch=x86_64\u0026upstream=gawk-4.2.1-4.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=ff58f12bc5f8f7ba",
130713          "supplier": {},
130714          "publisher": "Red Hat, Inc.",
130715          "name": "gawk",
130716          "version": "4.2.1-4.el8",
130717          "licenses": [
130718            {
130719              "license": {
130720                "name": "GPLv3+ and GPLv2+ and LGPLv2+ and BSD"
130721              }
130722            }
130723          ],
130724          "cpe": "cpe:2.3:a:redhat:gawk:4.2.1-4.el8:*:*:*:*:*:*:*",
130725          "purl": "pkg:rpm/rhel/gawk@4.2.1-4.el8?arch=x86_64\u0026upstream=gawk-4.2.1-4.el8.src.rpm\u0026distro=rhel-8.6",
130726          "swid": {
130727            "attachment": {}
130728          },
130729          "pedigree": {},
130730          "evidence": {},
130731          "signature": {
130732            "signature": {
130733              "publicKey": {}
130734            }
130735          },
130736          "modelCard": {
130737            "modelParameters": {
130738              "approach": {}
130739            },
130740            "quantitativeAnalysis": {
130741              "graphics": {}
130742            },
130743            "considerations": {}
130744          }
130745        },
130746        {
130747          "type": "library",
130748          "bom-ref": "pkg:golang/github.com/azure/azure-pipeline-go@v0.2.3?package-id=d7dc018b2e73b988",
130749          "supplier": {},
130750          "name": "github.com/Azure/azure-pipeline-go",
130751          "version": "v0.2.3",
130752          "cpe": "cpe:2.3:a:Azure:azure-pipeline-go:v0.2.3:*:*:*:*:*:*:*",
130753          "purl": "pkg:golang/github.com/Azure/azure-pipeline-go@v0.2.3",
130754          "swid": {
130755            "attachment": {}
130756          },
130757          "pedigree": {},
130758          "evidence": {},
130759          "signature": {
130760            "signature": {
130761              "publicKey": {}
130762            }
130763          },
130764          "modelCard": {
130765            "modelParameters": {
130766              "approach": {}
130767            },
130768            "quantitativeAnalysis": {
130769              "graphics": {}
130770            },
130771            "considerations": {}
130772          }
130773        },
130774        {
130775          "type": "library",
130776          "bom-ref": "pkg:golang/github.com/azure/azure-storage-blob-go@v0.15.0?package-id=61566e3901526712",
130777          "supplier": {},
130778          "name": "github.com/Azure/azure-storage-blob-go",
130779          "version": "v0.15.0",
130780          "cpe": "cpe:2.3:a:Azure:azure-storage-blob-go:v0.15.0:*:*:*:*:*:*:*",
130781          "purl": "pkg:golang/github.com/Azure/azure-storage-blob-go@v0.15.0",
130782          "swid": {
130783            "attachment": {}
130784          },
130785          "pedigree": {},
130786          "evidence": {},
130787          "signature": {
130788            "signature": {
130789              "publicKey": {}
130790            }
130791          },
130792          "modelCard": {
130793            "modelParameters": {
130794              "approach": {}
130795            },
130796            "quantitativeAnalysis": {
130797              "graphics": {}
130798            },
130799            "considerations": {}
130800          }
130801        },
130802        {
130803          "type": "library",
130804          "bom-ref": "pkg:golang/github.com/azure/go-ntlmssp@v0.0.0-20220621081337-cb9428e4ac1e?package-id=de6fcfb91e74d692",
130805          "supplier": {},
130806          "name": "github.com/Azure/go-ntlmssp",
130807          "version": "v0.0.0-20220621081337-cb9428e4ac1e",
130808          "cpe": "cpe:2.3:a:Azure:go-ntlmssp:v0.0.0-20220621081337-cb9428e4ac1e:*:*:*:*:*:*:*",
130809          "purl": "pkg:golang/github.com/Azure/go-ntlmssp@v0.0.0-20220621081337-cb9428e4ac1e",
130810          "swid": {
130811            "attachment": {}
130812          },
130813          "pedigree": {},
130814          "evidence": {},
130815          "signature": {
130816            "signature": {
130817              "publicKey": {}
130818            }
130819          },
130820          "modelCard": {
130821            "modelParameters": {
130822              "approach": {}
130823            },
130824            "quantitativeAnalysis": {
130825              "graphics": {}
130826            },
130827            "considerations": {}
130828          }
130829        },
130830        {
130831          "type": "library",
130832          "bom-ref": "pkg:golang/github.com/shopify/sarama@v1.36.0?package-id=5432bbbb95e3bc6",
130833          "supplier": {},
130834          "name": "github.com/Shopify/sarama",
130835          "version": "v1.36.0",
130836          "cpe": "cpe:2.3:a:Shopify:sarama:v1.36.0:*:*:*:*:*:*:*",
130837          "purl": "pkg:golang/github.com/Shopify/sarama@v1.36.0",
130838          "swid": {
130839            "attachment": {}
130840          },
130841          "pedigree": {},
130842          "evidence": {},
130843          "signature": {
130844            "signature": {
130845              "publicKey": {}
130846            }
130847          },
130848          "modelCard": {
130849            "modelParameters": {
130850              "approach": {}
130851            },
130852            "quantitativeAnalysis": {
130853              "graphics": {}
130854            },
130855            "considerations": {}
130856          }
130857        },
130858        {
130859          "type": "library",
130860          "bom-ref": "pkg:golang/github.com/alecthomas/participle@v0.7.1?package-id=8eaa9ff66ac98731",
130861          "supplier": {},
130862          "name": "github.com/alecthomas/participle",
130863          "version": "v0.7.1",
130864          "cpe": "cpe:2.3:a:alecthomas:participle:v0.7.1:*:*:*:*:*:*:*",
130865          "purl": "pkg:golang/github.com/alecthomas/participle@v0.7.1",
130866          "swid": {
130867            "attachment": {}
130868          },
130869          "pedigree": {},
130870          "evidence": {},
130871          "signature": {
130872            "signature": {
130873              "publicKey": {}
130874            }
130875          },
130876          "modelCard": {
130877            "modelParameters": {
130878              "approach": {}
130879            },
130880            "quantitativeAnalysis": {
130881              "graphics": {}
130882            },
130883            "considerations": {}
130884          }
130885        },
130886        {
130887          "type": "library",
130888          "bom-ref": "pkg:golang/github.com/apache/thrift@v0.16.0?package-id=10a5a82e0846fbb5",
130889          "supplier": {},
130890          "name": "github.com/apache/thrift",
130891          "version": "v0.16.0",
130892          "cpe": "cpe:2.3:a:apache:thrift:v0.16.0:*:*:*:*:*:*:*",
130893          "purl": "pkg:golang/github.com/apache/thrift@v0.16.0",
130894          "swid": {
130895            "attachment": {}
130896          },
130897          "pedigree": {},
130898          "evidence": {},
130899          "signature": {
130900            "signature": {
130901              "publicKey": {}
130902            }
130903          },
130904          "modelCard": {
130905            "modelParameters": {
130906              "approach": {}
130907            },
130908            "quantitativeAnalysis": {
130909              "graphics": {}
130910            },
130911            "considerations": {}
130912          }
130913        },
130914        {
130915          "type": "library",
130916          "bom-ref": "pkg:golang/github.com/asaskevich/govalidator@v0.0.0-20210307081110-f21760c49a8d?package-id=c2a6f429564cfc33",
130917          "supplier": {},
130918          "name": "github.com/asaskevich/govalidator",
130919          "version": "v0.0.0-20210307081110-f21760c49a8d",
130920          "cpe": "cpe:2.3:a:asaskevich:govalidator:v0.0.0-20210307081110-f21760c49a8d:*:*:*:*:*:*:*",
130921          "purl": "pkg:golang/github.com/asaskevich/govalidator@v0.0.0-20210307081110-f21760c49a8d",
130922          "swid": {
130923            "attachment": {}
130924          },
130925          "pedigree": {},
130926          "evidence": {},
130927          "signature": {
130928            "signature": {
130929              "publicKey": {}
130930            }
130931          },
130932          "modelCard": {
130933            "modelParameters": {
130934              "approach": {}
130935            },
130936            "quantitativeAnalysis": {
130937              "graphics": {}
130938            },
130939            "considerations": {}
130940          }
130941        },
130942        {
130943          "type": "library",
130944          "bom-ref": "pkg:golang/github.com/aymanbagabas/go-osc52@v1.2.1?package-id=b65191faeeac88b",
130945          "supplier": {},
130946          "name": "github.com/aymanbagabas/go-osc52",
130947          "version": "v1.2.1",
130948          "cpe": "cpe:2.3:a:aymanbagabas:go-osc52:v1.2.1:*:*:*:*:*:*:*",
130949          "purl": "pkg:golang/github.com/aymanbagabas/go-osc52@v1.2.1",
130950          "swid": {
130951            "attachment": {}
130952          },
130953          "pedigree": {},
130954          "evidence": {},
130955          "signature": {
130956            "signature": {
130957              "publicKey": {}
130958            }
130959          },
130960          "modelCard": {
130961            "modelParameters": {
130962              "approach": {}
130963            },
130964            "quantitativeAnalysis": {
130965              "graphics": {}
130966            },
130967            "considerations": {}
130968          }
130969        },
130970        {
130971          "type": "library",
130972          "bom-ref": "pkg:golang/github.com/bcicen/jstream@v1.0.1?package-id=f967db1d4fc27678",
130973          "supplier": {},
130974          "name": "github.com/bcicen/jstream",
130975          "version": "v1.0.1",
130976          "cpe": "cpe:2.3:a:bcicen:jstream:v1.0.1:*:*:*:*:*:*:*",
130977          "purl": "pkg:golang/github.com/bcicen/jstream@v1.0.1",
130978          "swid": {
130979            "attachment": {}
130980          },
130981          "pedigree": {},
130982          "evidence": {},
130983          "signature": {
130984            "signature": {
130985              "publicKey": {}
130986            }
130987          },
130988          "modelCard": {
130989            "modelParameters": {
130990              "approach": {}
130991            },
130992            "quantitativeAnalysis": {
130993              "graphics": {}
130994            },
130995            "considerations": {}
130996          }
130997        },
130998        {
130999          "type": "library",
131000          "bom-ref": "pkg:golang/github.com/beevik/ntp@v0.3.0?package-id=d5bb5fceb82dd575",
131001          "supplier": {},
131002          "name": "github.com/beevik/ntp",
131003          "version": "v0.3.0",
131004          "cpe": "cpe:2.3:a:beevik:ntp:v0.3.0:*:*:*:*:*:*:*",
131005          "purl": "pkg:golang/github.com/beevik/ntp@v0.3.0",
131006          "swid": {
131007            "attachment": {}
131008          },
131009          "pedigree": {},
131010          "evidence": {},
131011          "signature": {
131012            "signature": {
131013              "publicKey": {}
131014            }
131015          },
131016          "modelCard": {
131017            "modelParameters": {
131018              "approach": {}
131019            },
131020            "quantitativeAnalysis": {
131021              "graphics": {}
131022            },
131023            "considerations": {}
131024          }
131025        },
131026        {
131027          "type": "library",
131028          "bom-ref": "pkg:golang/github.com/beorn7/perks@v1.0.1?package-id=1c6269c6bdce2a46",
131029          "supplier": {},
131030          "name": "github.com/beorn7/perks",
131031          "version": "v1.0.1",
131032          "cpe": "cpe:2.3:a:beorn7:perks:v1.0.1:*:*:*:*:*:*:*",
131033          "purl": "pkg:golang/github.com/beorn7/perks@v1.0.1",
131034          "swid": {
131035            "attachment": {}
131036          },
131037          "pedigree": {},
131038          "evidence": {},
131039          "signature": {
131040            "signature": {
131041              "publicKey": {}
131042            }
131043          },
131044          "modelCard": {
131045            "modelParameters": {
131046              "approach": {}
131047            },
131048            "quantitativeAnalysis": {
131049              "graphics": {}
131050            },
131051            "considerations": {}
131052          }
131053        },
131054        {
131055          "type": "library",
131056          "bom-ref": "pkg:golang/github.com/bits-and-blooms/bitset@v1.3.3?package-id=6a3d99472e8049fb",
131057          "supplier": {},
131058          "name": "github.com/bits-and-blooms/bitset",
131059          "version": "v1.3.3",
131060          "cpe": "cpe:2.3:a:bits-and-blooms:bitset:v1.3.3:*:*:*:*:*:*:*",
131061          "purl": "pkg:golang/github.com/bits-and-blooms/bitset@v1.3.3",
131062          "swid": {
131063            "attachment": {}
131064          },
131065          "pedigree": {},
131066          "evidence": {},
131067          "signature": {
131068            "signature": {
131069              "publicKey": {}
131070            }
131071          },
131072          "modelCard": {
131073            "modelParameters": {
131074              "approach": {}
131075            },
131076            "quantitativeAnalysis": {
131077              "graphics": {}
131078            },
131079            "considerations": {}
131080          }
131081        },
131082        {
131083          "type": "library",
131084          "bom-ref": "pkg:golang/github.com/bits-and-blooms/bloom/v3@v3.3.1?package-id=ee8382cd38aa897d",
131085          "supplier": {},
131086          "name": "github.com/bits-and-blooms/bloom/v3",
131087          "version": "v3.3.1",
131088          "cpe": "cpe:2.3:a:bits-and-blooms:bloom\\/v3:v3.3.1:*:*:*:*:*:*:*",
131089          "purl": "pkg:golang/github.com/bits-and-blooms/bloom/v3@v3.3.1",
131090          "swid": {
131091            "attachment": {}
131092          },
131093          "pedigree": {},
131094          "evidence": {},
131095          "signature": {
131096            "signature": {
131097              "publicKey": {}
131098            }
131099          },
131100          "modelCard": {
131101            "modelParameters": {
131102              "approach": {}
131103            },
131104            "quantitativeAnalysis": {
131105              "graphics": {}
131106            },
131107            "considerations": {}
131108          }
131109        },
131110        {
131111          "type": "library",
131112          "bom-ref": "pkg:golang/github.com/buger/jsonparser@v1.1.1?package-id=d82df197fc7f7aea",
131113          "supplier": {},
131114          "name": "github.com/buger/jsonparser",
131115          "version": "v1.1.1",
131116          "cpe": "cpe:2.3:a:buger:jsonparser:v1.1.1:*:*:*:*:*:*:*",
131117          "purl": "pkg:golang/github.com/buger/jsonparser@v1.1.1",
131118          "swid": {
131119            "attachment": {}
131120          },
131121          "pedigree": {},
131122          "evidence": {},
131123          "signature": {
131124            "signature": {
131125              "publicKey": {}
131126            }
131127          },
131128          "modelCard": {
131129            "modelParameters": {
131130              "approach": {}
131131            },
131132            "quantitativeAnalysis": {
131133              "graphics": {}
131134            },
131135            "considerations": {}
131136          }
131137        },
131138        {
131139          "type": "library",
131140          "bom-ref": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.2?package-id=7bfd1b1b69a3c200",
131141          "supplier": {},
131142          "name": "github.com/cespare/xxhash/v2",
131143          "version": "v2.1.2",
131144          "cpe": "cpe:2.3:a:cespare:xxhash\\/v2:v2.1.2:*:*:*:*:*:*:*",
131145          "purl": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.2",
131146          "swid": {
131147            "attachment": {}
131148          },
131149          "pedigree": {},
131150          "evidence": {},
131151          "signature": {
131152            "signature": {
131153              "publicKey": {}
131154            }
131155          },
131156          "modelCard": {
131157            "modelParameters": {
131158              "approach": {}
131159            },
131160            "quantitativeAnalysis": {
131161              "graphics": {}
131162            },
131163            "considerations": {}
131164          }
131165        },
131166        {
131167          "type": "library",
131168          "bom-ref": "pkg:golang/github.com/charmbracelet/bubbles@v0.14.0?package-id=a8010010fa34eb",
131169          "supplier": {},
131170          "name": "github.com/charmbracelet/bubbles",
131171          "version": "v0.14.0",
131172          "cpe": "cpe:2.3:a:charmbracelet:bubbles:v0.14.0:*:*:*:*:*:*:*",
131173          "purl": "pkg:golang/github.com/charmbracelet/bubbles@v0.14.0",
131174          "swid": {
131175            "attachment": {}
131176          },
131177          "pedigree": {},
131178          "evidence": {},
131179          "signature": {
131180            "signature": {
131181              "publicKey": {}
131182            }
131183          },
131184          "modelCard": {
131185            "modelParameters": {
131186              "approach": {}
131187            },
131188            "quantitativeAnalysis": {
131189              "graphics": {}
131190            },
131191            "considerations": {}
131192          }
131193        },
131194        {
131195          "type": "library",
131196          "bom-ref": "pkg:golang/github.com/charmbracelet/bubbletea@v0.22.1?package-id=59cc4784dc7fffc5",
131197          "supplier": {},
131198          "name": "github.com/charmbracelet/bubbletea",
131199          "version": "v0.22.1",
131200          "cpe": "cpe:2.3:a:charmbracelet:bubbletea:v0.22.1:*:*:*:*:*:*:*",
131201          "purl": "pkg:golang/github.com/charmbracelet/bubbletea@v0.22.1",
131202          "swid": {
131203            "attachment": {}
131204          },
131205          "pedigree": {},
131206          "evidence": {},
131207          "signature": {
131208            "signature": {
131209              "publicKey": {}
131210            }
131211          },
131212          "modelCard": {
131213            "modelParameters": {
131214              "approach": {}
131215            },
131216            "quantitativeAnalysis": {
131217              "graphics": {}
131218            },
131219            "considerations": {}
131220          }
131221        },
131222        {
131223          "type": "library",
131224          "bom-ref": "pkg:golang/github.com/charmbracelet/lipgloss@v0.6.0?package-id=c44f9620fcfbc0b0",
131225          "supplier": {},
131226          "name": "github.com/charmbracelet/lipgloss",
131227          "version": "v0.6.0",
131228          "cpe": "cpe:2.3:a:charmbracelet:lipgloss:v0.6.0:*:*:*:*:*:*:*",
131229          "purl": "pkg:golang/github.com/charmbracelet/lipgloss@v0.6.0",
131230          "swid": {
131231            "attachment": {}
131232          },
131233          "pedigree": {},
131234          "evidence": {},
131235          "signature": {
131236            "signature": {
131237              "publicKey": {}
131238            }
131239          },
131240          "modelCard": {
131241            "modelParameters": {
131242              "approach": {}
131243            },
131244            "quantitativeAnalysis": {
131245              "graphics": {}
131246            },
131247            "considerations": {}
131248          }
131249        },
131250        {
131251          "type": "library",
131252          "bom-ref": "pkg:golang/github.com/cheggaaa/pb@v1.0.29?package-id=361c9996c84d511e",
131253          "supplier": {},
131254          "name": "github.com/cheggaaa/pb",
131255          "version": "v1.0.29",
131256          "cpe": "cpe:2.3:a:cheggaaa:pb:v1.0.29:*:*:*:*:*:*:*",
131257          "purl": "pkg:golang/github.com/cheggaaa/pb@v1.0.29",
131258          "swid": {
131259            "attachment": {}
131260          },
131261          "pedigree": {},
131262          "evidence": {},
131263          "signature": {
131264            "signature": {
131265              "publicKey": {}
131266            }
131267          },
131268          "modelCard": {
131269            "modelParameters": {
131270              "approach": {}
131271            },
131272            "quantitativeAnalysis": {
131273              "graphics": {}
131274            },
131275            "considerations": {}
131276          }
131277        },
131278        {
131279          "type": "library",
131280          "bom-ref": "pkg:golang/github.com/containerd/console@v1.0.3?package-id=263e1f82d13ec9d5",
131281          "supplier": {},
131282          "name": "github.com/containerd/console",
131283          "version": "v1.0.3",
131284          "cpe": "cpe:2.3:a:containerd:console:v1.0.3:*:*:*:*:*:*:*",
131285          "purl": "pkg:golang/github.com/containerd/console@v1.0.3",
131286          "swid": {
131287            "attachment": {}
131288          },
131289          "pedigree": {},
131290          "evidence": {},
131291          "signature": {
131292            "signature": {
131293              "publicKey": {}
131294            }
131295          },
131296          "modelCard": {
131297            "modelParameters": {
131298              "approach": {}
131299            },
131300            "quantitativeAnalysis": {
131301              "graphics": {}
131302            },
131303            "considerations": {}
131304          }
131305        },
131306        {
131307          "type": "library",
131308          "bom-ref": "pkg:golang/github.com/coredns/coredns@v1.9.4?package-id=5585ad513e0f260f",
131309          "supplier": {},
131310          "name": "github.com/coredns/coredns",
131311          "version": "v1.9.4",
131312          "cpe": "cpe:2.3:a:coredns:coredns:v1.9.4:*:*:*:*:*:*:*",
131313          "purl": "pkg:golang/github.com/coredns/coredns@v1.9.4",
131314          "swid": {
131315            "attachment": {}
131316          },
131317          "pedigree": {},
131318          "evidence": {},
131319          "signature": {
131320            "signature": {
131321              "publicKey": {}
131322            }
131323          },
131324          "modelCard": {
131325            "modelParameters": {
131326              "approach": {}
131327            },
131328            "quantitativeAnalysis": {
131329              "graphics": {}
131330            },
131331            "considerations": {}
131332          }
131333        },
131334        {
131335          "type": "library",
131336          "bom-ref": "pkg:golang/github.com/coreos/go-oidc@v2.2.1+incompatible?package-id=dfbd96e12b86f3d2",
131337          "supplier": {},
131338          "name": "github.com/coreos/go-oidc",
131339          "version": "v2.2.1+incompatible",
131340          "cpe": "cpe:2.3:a:coreos:go-oidc:v2.2.1\\+incompatible:*:*:*:*:*:*:*",
131341          "purl": "pkg:golang/github.com/coreos/go-oidc@v2.2.1+incompatible",
131342          "swid": {
131343            "attachment": {}
131344          },
131345          "pedigree": {},
131346          "evidence": {},
131347          "signature": {
131348            "signature": {
131349              "publicKey": {}
131350            }
131351          },
131352          "modelCard": {
131353            "modelParameters": {
131354              "approach": {}
131355            },
131356            "quantitativeAnalysis": {
131357              "graphics": {}
131358            },
131359            "considerations": {}
131360          }
131361        },
131362        {
131363          "type": "library",
131364          "bom-ref": "pkg:golang/github.com/coreos/go-semver@v0.3.0?package-id=be57b11a62f6251c",
131365          "supplier": {},
131366          "name": "github.com/coreos/go-semver",
131367          "version": "v0.3.0",
131368          "cpe": "cpe:2.3:a:coreos:go-semver:v0.3.0:*:*:*:*:*:*:*",
131369          "purl": "pkg:golang/github.com/coreos/go-semver@v0.3.0",
131370          "swid": {
131371            "attachment": {}
131372          },
131373          "pedigree": {},
131374          "evidence": {},
131375          "signature": {
131376            "signature": {
131377              "publicKey": {}
131378            }
131379          },
131380          "modelCard": {
131381            "modelParameters": {
131382              "approach": {}
131383            },
131384            "quantitativeAnalysis": {
131385              "graphics": {}
131386            },
131387            "considerations": {}
131388          }
131389        },
131390        {
131391          "type": "library",
131392          "bom-ref": "pkg:golang/github.com/coreos/go-systemd/v22@v22.4.0?package-id=552c1614a0f0fd5d",
131393          "supplier": {},
131394          "name": "github.com/coreos/go-systemd/v22",
131395          "version": "v22.4.0",
131396          "cpe": "cpe:2.3:a:coreos:go-systemd\\/v22:v22.4.0:*:*:*:*:*:*:*",
131397          "purl": "pkg:golang/github.com/coreos/go-systemd/v22@v22.4.0",
131398          "swid": {
131399            "attachment": {}
131400          },
131401          "pedigree": {},
131402          "evidence": {},
131403          "signature": {
131404            "signature": {
131405              "publicKey": {}
131406            }
131407          },
131408          "modelCard": {
131409            "modelParameters": {
131410              "approach": {}
131411            },
131412            "quantitativeAnalysis": {
131413              "graphics": {}
131414            },
131415            "considerations": {}
131416          }
131417        },
131418        {
131419          "type": "library",
131420          "bom-ref": "pkg:golang/github.com/cosnicolaou/pbzip2@v1.0.1?package-id=c0bfa7e7cdcda5bf",
131421          "supplier": {},
131422          "name": "github.com/cosnicolaou/pbzip2",
131423          "version": "v1.0.1",
131424          "cpe": "cpe:2.3:a:cosnicolaou:pbzip2:v1.0.1:*:*:*:*:*:*:*",
131425          "purl": "pkg:golang/github.com/cosnicolaou/pbzip2@v1.0.1",
131426          "swid": {
131427            "attachment": {}
131428          },
131429          "pedigree": {},
131430          "evidence": {},
131431          "signature": {
131432            "signature": {
131433              "publicKey": {}
131434            }
131435          },
131436          "modelCard": {
131437            "modelParameters": {
131438              "approach": {}
131439            },
131440            "quantitativeAnalysis": {
131441              "graphics": {}
131442            },
131443            "considerations": {}
131444          }
131445        },
131446        {
131447          "type": "library",
131448          "bom-ref": "pkg:golang/github.com/davecgh/go-spew@v1.1.1?package-id=927396c4895d00f1",
131449          "supplier": {},
131450          "name": "github.com/davecgh/go-spew",
131451          "version": "v1.1.1",
131452          "cpe": "cpe:2.3:a:davecgh:go-spew:v1.1.1:*:*:*:*:*:*:*",
131453          "purl": "pkg:golang/github.com/davecgh/go-spew@v1.1.1",
131454          "swid": {
131455            "attachment": {}
131456          },
131457          "pedigree": {},
131458          "evidence": {},
131459          "signature": {
131460            "signature": {
131461              "publicKey": {}
131462            }
131463          },
131464          "modelCard": {
131465            "modelParameters": {
131466              "approach": {}
131467            },
131468            "quantitativeAnalysis": {
131469              "graphics": {}
131470            },
131471            "considerations": {}
131472          }
131473        },
131474        {
131475          "type": "library",
131476          "bom-ref": "pkg:golang/github.com/dchest/siphash@v1.2.3?package-id=837e1d7944105e4f",
131477          "supplier": {},
131478          "name": "github.com/dchest/siphash",
131479          "version": "v1.2.3",
131480          "cpe": "cpe:2.3:a:dchest:siphash:v1.2.3:*:*:*:*:*:*:*",
131481          "purl": "pkg:golang/github.com/dchest/siphash@v1.2.3",
131482          "swid": {
131483            "attachment": {}
131484          },
131485          "pedigree": {},
131486          "evidence": {},
131487          "signature": {
131488            "signature": {
131489              "publicKey": {}
131490            }
131491          },
131492          "modelCard": {
131493            "modelParameters": {
131494              "approach": {}
131495            },
131496            "quantitativeAnalysis": {
131497              "graphics": {}
131498            },
131499            "considerations": {}
131500          }
131501        },
131502        {
131503          "type": "library",
131504          "bom-ref": "pkg:golang/github.com/djherbis/atime@v1.1.0?package-id=7b2948b994d1eef0",
131505          "supplier": {},
131506          "name": "github.com/djherbis/atime",
131507          "version": "v1.1.0",
131508          "cpe": "cpe:2.3:a:djherbis:atime:v1.1.0:*:*:*:*:*:*:*",
131509          "purl": "pkg:golang/github.com/djherbis/atime@v1.1.0",
131510          "swid": {
131511            "attachment": {}
131512          },
131513          "pedigree": {},
131514          "evidence": {},
131515          "signature": {
131516            "signature": {
131517              "publicKey": {}
131518            }
131519          },
131520          "modelCard": {
131521            "modelParameters": {
131522              "approach": {}
131523            },
131524            "quantitativeAnalysis": {
131525              "graphics": {}
131526            },
131527            "considerations": {}
131528          }
131529        },
131530        {
131531          "type": "library",
131532          "bom-ref": "pkg:golang/github.com/docker/go-units@v0.5.0?package-id=3aa2eb4bd49f7460",
131533          "supplier": {},
131534          "name": "github.com/docker/go-units",
131535          "version": "v0.5.0",
131536          "cpe": "cpe:2.3:a:docker:go-units:v0.5.0:*:*:*:*:*:*:*",
131537          "purl": "pkg:golang/github.com/docker/go-units@v0.5.0",
131538          "swid": {
131539            "attachment": {}
131540          },
131541          "pedigree": {},
131542          "evidence": {},
131543          "signature": {
131544            "signature": {
131545              "publicKey": {}
131546            }
131547          },
131548          "modelCard": {
131549            "modelParameters": {
131550              "approach": {}
131551            },
131552            "quantitativeAnalysis": {
131553              "graphics": {}
131554            },
131555            "considerations": {}
131556          }
131557        },
131558        {
131559          "type": "library",
131560          "bom-ref": "pkg:golang/github.com/dustin/go-humanize@v1.0.0?package-id=3632ad8766e42b06",
131561          "supplier": {},
131562          "name": "github.com/dustin/go-humanize",
131563          "version": "v1.0.0",
131564          "cpe": "cpe:2.3:a:dustin:go-humanize:v1.0.0:*:*:*:*:*:*:*",
131565          "purl": "pkg:golang/github.com/dustin/go-humanize@v1.0.0",
131566          "swid": {
131567            "attachment": {}
131568          },
131569          "pedigree": {},
131570          "evidence": {},
131571          "signature": {
131572            "signature": {
131573              "publicKey": {}
131574            }
131575          },
131576          "modelCard": {
131577            "modelParameters": {
131578              "approach": {}
131579            },
131580            "quantitativeAnalysis": {
131581              "graphics": {}
131582            },
131583            "considerations": {}
131584          }
131585        },
131586        {
131587          "type": "library",
131588          "bom-ref": "pkg:golang/github.com/eapache/go-resiliency@v1.3.0?package-id=8fca6519a6726253",
131589          "supplier": {},
131590          "name": "github.com/eapache/go-resiliency",
131591          "version": "v1.3.0",
131592          "cpe": "cpe:2.3:a:eapache:go-resiliency:v1.3.0:*:*:*:*:*:*:*",
131593          "purl": "pkg:golang/github.com/eapache/go-resiliency@v1.3.0",
131594          "swid": {
131595            "attachment": {}
131596          },
131597          "pedigree": {},
131598          "evidence": {},
131599          "signature": {
131600            "signature": {
131601              "publicKey": {}
131602            }
131603          },
131604          "modelCard": {
131605            "modelParameters": {
131606              "approach": {}
131607            },
131608            "quantitativeAnalysis": {
131609              "graphics": {}
131610            },
131611            "considerations": {}
131612          }
131613        },
131614        {
131615          "type": "library",
131616          "bom-ref": "pkg:golang/github.com/eapache/go-xerial-snappy@v0.0.0-20180814174437-776d5712da21?package-id=5acef2cce95e2ef",
131617          "supplier": {},
131618          "name": "github.com/eapache/go-xerial-snappy",
131619          "version": "v0.0.0-20180814174437-776d5712da21",
131620          "cpe": "cpe:2.3:a:eapache:go-xerial-snappy:v0.0.0-20180814174437-776d5712da21:*:*:*:*:*:*:*",
131621          "purl": "pkg:golang/github.com/eapache/go-xerial-snappy@v0.0.0-20180814174437-776d5712da21",
131622          "swid": {
131623            "attachment": {}
131624          },
131625          "pedigree": {},
131626          "evidence": {},
131627          "signature": {
131628            "signature": {
131629              "publicKey": {}
131630            }
131631          },
131632          "modelCard": {
131633            "modelParameters": {
131634              "approach": {}
131635            },
131636            "quantitativeAnalysis": {
131637              "graphics": {}
131638            },
131639            "considerations": {}
131640          }
131641        },
131642        {
131643          "type": "library",
131644          "bom-ref": "pkg:golang/github.com/eapache/queue@v1.1.0?package-id=4484a80d58f0da4d",
131645          "supplier": {},
131646          "name": "github.com/eapache/queue",
131647          "version": "v1.1.0",
131648          "cpe": "cpe:2.3:a:eapache:queue:v1.1.0:*:*:*:*:*:*:*",
131649          "purl": "pkg:golang/github.com/eapache/queue@v1.1.0",
131650          "swid": {
131651            "attachment": {}
131652          },
131653          "pedigree": {},
131654          "evidence": {},
131655          "signature": {
131656            "signature": {
131657              "publicKey": {}
131658            }
131659          },
131660          "modelCard": {
131661            "modelParameters": {
131662              "approach": {}
131663            },
131664            "quantitativeAnalysis": {
131665              "graphics": {}
131666            },
131667            "considerations": {}
131668          }
131669        },
131670        {
131671          "type": "library",
131672          "bom-ref": "pkg:golang/github.com/eclipse/paho.mqtt.golang@v1.4.1?package-id=81f319389b923572",
131673          "supplier": {},
131674          "name": "github.com/eclipse/paho.mqtt.golang",
131675          "version": "v1.4.1",
131676          "cpe": "cpe:2.3:a:eclipse:paho.mqtt.golang:v1.4.1:*:*:*:*:*:*:*",
131677          "purl": "pkg:golang/github.com/eclipse/paho.mqtt.golang@v1.4.1",
131678          "swid": {
131679            "attachment": {}
131680          },
131681          "pedigree": {},
131682          "evidence": {},
131683          "signature": {
131684            "signature": {
131685              "publicKey": {}
131686            }
131687          },
131688          "modelCard": {
131689            "modelParameters": {
131690              "approach": {}
131691            },
131692            "quantitativeAnalysis": {
131693              "graphics": {}
131694            },
131695            "considerations": {}
131696          }
131697        },
131698        {
131699          "type": "library",
131700          "bom-ref": "pkg:golang/github.com/elastic/go-elasticsearch/v7@v7.17.1?package-id=caadefbcfcdd6f77",
131701          "supplier": {},
131702          "name": "github.com/elastic/go-elasticsearch/v7",
131703          "version": "v7.17.1",
131704          "cpe": "cpe:2.3:a:elastic:go-elasticsearch\\/v7:v7.17.1:*:*:*:*:*:*:*",
131705          "purl": "pkg:golang/github.com/elastic/go-elasticsearch/v7@v7.17.1",
131706          "swid": {
131707            "attachment": {}
131708          },
131709          "pedigree": {},
131710          "evidence": {},
131711          "signature": {
131712            "signature": {
131713              "publicKey": {}
131714            }
131715          },
131716          "modelCard": {
131717            "modelParameters": {
131718              "approach": {}
131719            },
131720            "quantitativeAnalysis": {
131721              "graphics": {}
131722            },
131723            "considerations": {}
131724          }
131725        },
131726        {
131727          "type": "library",
131728          "bom-ref": "pkg:golang/github.com/fatih/color@v1.13.0?package-id=d41416611fb3fee2",
131729          "supplier": {},
131730          "name": "github.com/fatih/color",
131731          "version": "v1.13.0",
131732          "cpe": "cpe:2.3:a:fatih:color:v1.13.0:*:*:*:*:*:*:*",
131733          "purl": "pkg:golang/github.com/fatih/color@v1.13.0",
131734          "swid": {
131735            "attachment": {}
131736          },
131737          "pedigree": {},
131738          "evidence": {},
131739          "signature": {
131740            "signature": {
131741              "publicKey": {}
131742            }
131743          },
131744          "modelCard": {
131745            "modelParameters": {
131746              "approach": {}
131747            },
131748            "quantitativeAnalysis": {
131749              "graphics": {}
131750            },
131751            "considerations": {}
131752          }
131753        },
131754        {
131755          "type": "library",
131756          "bom-ref": "pkg:golang/github.com/fatih/structs@v1.1.0?package-id=f99c0c57a96ba34d",
131757          "supplier": {},
131758          "name": "github.com/fatih/structs",
131759          "version": "v1.1.0",
131760          "cpe": "cpe:2.3:a:fatih:structs:v1.1.0:*:*:*:*:*:*:*",
131761          "purl": "pkg:golang/github.com/fatih/structs@v1.1.0",
131762          "swid": {
131763            "attachment": {}
131764          },
131765          "pedigree": {},
131766          "evidence": {},
131767          "signature": {
131768            "signature": {
131769              "publicKey": {}
131770            }
131771          },
131772          "modelCard": {
131773            "modelParameters": {
131774              "approach": {}
131775            },
131776            "quantitativeAnalysis": {
131777              "graphics": {}
131778            },
131779            "considerations": {}
131780          }
131781        },
131782        {
131783          "type": "library",
131784          "bom-ref": "pkg:golang/github.com/felixge/fgprof@v0.9.3?package-id=c55534641e7d5703",
131785          "supplier": {},
131786          "name": "github.com/felixge/fgprof",
131787          "version": "v0.9.3",
131788          "cpe": "cpe:2.3:a:felixge:fgprof:v0.9.3:*:*:*:*:*:*:*",
131789          "purl": "pkg:golang/github.com/felixge/fgprof@v0.9.3",
131790          "swid": {
131791            "attachment": {}
131792          },
131793          "pedigree": {},
131794          "evidence": {},
131795          "signature": {
131796            "signature": {
131797              "publicKey": {}
131798            }
131799          },
131800          "modelCard": {
131801            "modelParameters": {
131802              "approach": {}
131803            },
131804            "quantitativeAnalysis": {
131805              "graphics": {}
131806            },
131807            "considerations": {}
131808          }
131809        },
131810        {
131811          "type": "library",
131812          "bom-ref": "pkg:golang/github.com/fraugster/parquet-go@v0.12.0?package-id=8e1fc2b4ffa20c6a",
131813          "supplier": {},
131814          "name": "github.com/fraugster/parquet-go",
131815          "version": "v0.12.0",
131816          "cpe": "cpe:2.3:a:fraugster:parquet-go:v0.12.0:*:*:*:*:*:*:*",
131817          "purl": "pkg:golang/github.com/fraugster/parquet-go@v0.12.0",
131818          "swid": {
131819            "attachment": {}
131820          },
131821          "pedigree": {},
131822          "evidence": {},
131823          "signature": {
131824            "signature": {
131825              "publicKey": {}
131826            }
131827          },
131828          "modelCard": {
131829            "modelParameters": {
131830              "approach": {}
131831            },
131832            "quantitativeAnalysis": {
131833              "graphics": {}
131834            },
131835            "considerations": {}
131836          }
131837        },
131838        {
131839          "type": "library",
131840          "bom-ref": "pkg:golang/github.com/gdamore/encoding@v1.0.0?package-id=fa7dcd88f81282a9",
131841          "supplier": {},
131842          "name": "github.com/gdamore/encoding",
131843          "version": "v1.0.0",
131844          "cpe": "cpe:2.3:a:gdamore:encoding:v1.0.0:*:*:*:*:*:*:*",
131845          "purl": "pkg:golang/github.com/gdamore/encoding@v1.0.0",
131846          "swid": {
131847            "attachment": {}
131848          },
131849          "pedigree": {},
131850          "evidence": {},
131851          "signature": {
131852            "signature": {
131853              "publicKey": {}
131854            }
131855          },
131856          "modelCard": {
131857            "modelParameters": {
131858              "approach": {}
131859            },
131860            "quantitativeAnalysis": {
131861              "graphics": {}
131862            },
131863            "considerations": {}
131864          }
131865        },
131866        {
131867          "type": "library",
131868          "bom-ref": "pkg:golang/github.com/gdamore/tcell/v2@v2.5.3?package-id=8f5daabd8eb8c830",
131869          "supplier": {},
131870          "name": "github.com/gdamore/tcell/v2",
131871          "version": "v2.5.3",
131872          "cpe": "cpe:2.3:a:gdamore:tcell\\/v2:v2.5.3:*:*:*:*:*:*:*",
131873          "purl": "pkg:golang/github.com/gdamore/tcell/v2@v2.5.3",
131874          "swid": {
131875            "attachment": {}
131876          },
131877          "pedigree": {},
131878          "evidence": {},
131879          "signature": {
131880            "signature": {
131881              "publicKey": {}
131882            }
131883          },
131884          "modelCard": {
131885            "modelParameters": {
131886              "approach": {}
131887            },
131888            "quantitativeAnalysis": {
131889              "graphics": {}
131890            },
131891            "considerations": {}
131892          }
131893        },
131894        {
131895          "type": "library",
131896          "bom-ref": "pkg:golang/github.com/go-asn1-ber/asn1-ber@v1.5.4?package-id=5885a2bf68b15db5",
131897          "supplier": {},
131898          "name": "github.com/go-asn1-ber/asn1-ber",
131899          "version": "v1.5.4",
131900          "cpe": "cpe:2.3:a:go-asn1-ber:asn1-ber:v1.5.4:*:*:*:*:*:*:*",
131901          "purl": "pkg:golang/github.com/go-asn1-ber/asn1-ber@v1.5.4",
131902          "swid": {
131903            "attachment": {}
131904          },
131905          "pedigree": {},
131906          "evidence": {},
131907          "signature": {
131908            "signature": {
131909              "publicKey": {}
131910            }
131911          },
131912          "modelCard": {
131913            "modelParameters": {
131914              "approach": {}
131915            },
131916            "quantitativeAnalysis": {
131917              "graphics": {}
131918            },
131919            "considerations": {}
131920          }
131921        },
131922        {
131923          "type": "library",
131924          "bom-ref": "pkg:golang/github.com/go-ldap/ldap/v3@v3.4.4?package-id=3896b73efd8264c1",
131925          "supplier": {},
131926          "name": "github.com/go-ldap/ldap/v3",
131927          "version": "v3.4.4",
131928          "cpe": "cpe:2.3:a:go-ldap:ldap\\/v3:v3.4.4:*:*:*:*:*:*:*",
131929          "purl": "pkg:golang/github.com/go-ldap/ldap/v3@v3.4.4",
131930          "swid": {
131931            "attachment": {}
131932          },
131933          "pedigree": {},
131934          "evidence": {},
131935          "signature": {
131936            "signature": {
131937              "publicKey": {}
131938            }
131939          },
131940          "modelCard": {
131941            "modelParameters": {
131942              "approach": {}
131943            },
131944            "quantitativeAnalysis": {
131945              "graphics": {}
131946            },
131947            "considerations": {}
131948          }
131949        },
131950        {
131951          "type": "library",
131952          "bom-ref": "pkg:golang/github.com/go-openapi/analysis@v0.21.4?package-id=e7804cdc7771653a",
131953          "supplier": {},
131954          "name": "github.com/go-openapi/analysis",
131955          "version": "v0.21.4",
131956          "cpe": "cpe:2.3:a:go-openapi:analysis:v0.21.4:*:*:*:*:*:*:*",
131957          "purl": "pkg:golang/github.com/go-openapi/analysis@v0.21.4",
131958          "swid": {
131959            "attachment": {}
131960          },
131961          "pedigree": {},
131962          "evidence": {},
131963          "signature": {
131964            "signature": {
131965              "publicKey": {}
131966            }
131967          },
131968          "modelCard": {
131969            "modelParameters": {
131970              "approach": {}
131971            },
131972            "quantitativeAnalysis": {
131973              "graphics": {}
131974            },
131975            "considerations": {}
131976          }
131977        },
131978        {
131979          "type": "library",
131980          "bom-ref": "pkg:golang/github.com/go-openapi/errors@v0.20.3?package-id=a3e76da594f47b48",
131981          "supplier": {},
131982          "name": "github.com/go-openapi/errors",
131983          "version": "v0.20.3",
131984          "cpe": "cpe:2.3:a:go-openapi:errors:v0.20.3:*:*:*:*:*:*:*",
131985          "purl": "pkg:golang/github.com/go-openapi/errors@v0.20.3",
131986          "swid": {
131987            "attachment": {}
131988          },
131989          "pedigree": {},
131990          "evidence": {},
131991          "signature": {
131992            "signature": {
131993              "publicKey": {}
131994            }
131995          },
131996          "modelCard": {
131997            "modelParameters": {
131998              "approach": {}
131999            },
132000            "quantitativeAnalysis": {
132001              "graphics": {}
132002            },
132003            "considerations": {}
132004          }
132005        },
132006        {
132007          "type": "library",
132008          "bom-ref": "pkg:golang/github.com/go-openapi/jsonpointer@v0.19.5?package-id=183770eb28bbc47a",
132009          "supplier": {},
132010          "name": "github.com/go-openapi/jsonpointer",
132011          "version": "v0.19.5",
132012          "cpe": "cpe:2.3:a:go-openapi:jsonpointer:v0.19.5:*:*:*:*:*:*:*",
132013          "purl": "pkg:golang/github.com/go-openapi/jsonpointer@v0.19.5",
132014          "swid": {
132015            "attachment": {}
132016          },
132017          "pedigree": {},
132018          "evidence": {},
132019          "signature": {
132020            "signature": {
132021              "publicKey": {}
132022            }
132023          },
132024          "modelCard": {
132025            "modelParameters": {
132026              "approach": {}
132027            },
132028            "quantitativeAnalysis": {
132029              "graphics": {}
132030            },
132031            "considerations": {}
132032          }
132033        },
132034        {
132035          "type": "library",
132036          "bom-ref": "pkg:golang/github.com/go-openapi/jsonreference@v0.20.0?package-id=f855372317a5acd0",
132037          "supplier": {},
132038          "name": "github.com/go-openapi/jsonreference",
132039          "version": "v0.20.0",
132040          "cpe": "cpe:2.3:a:go-openapi:jsonreference:v0.20.0:*:*:*:*:*:*:*",
132041          "purl": "pkg:golang/github.com/go-openapi/jsonreference@v0.20.0",
132042          "swid": {
132043            "attachment": {}
132044          },
132045          "pedigree": {},
132046          "evidence": {},
132047          "signature": {
132048            "signature": {
132049              "publicKey": {}
132050            }
132051          },
132052          "modelCard": {
132053            "modelParameters": {
132054              "approach": {}
132055            },
132056            "quantitativeAnalysis": {
132057              "graphics": {}
132058            },
132059            "considerations": {}
132060          }
132061        },
132062        {
132063          "type": "library",
132064          "bom-ref": "pkg:golang/github.com/go-openapi/loads@v0.21.2?package-id=374b00618c794b75",
132065          "supplier": {},
132066          "name": "github.com/go-openapi/loads",
132067          "version": "v0.21.2",
132068          "cpe": "cpe:2.3:a:go-openapi:loads:v0.21.2:*:*:*:*:*:*:*",
132069          "purl": "pkg:golang/github.com/go-openapi/loads@v0.21.2",
132070          "swid": {
132071            "attachment": {}
132072          },
132073          "pedigree": {},
132074          "evidence": {},
132075          "signature": {
132076            "signature": {
132077              "publicKey": {}
132078            }
132079          },
132080          "modelCard": {
132081            "modelParameters": {
132082              "approach": {}
132083            },
132084            "quantitativeAnalysis": {
132085              "graphics": {}
132086            },
132087            "considerations": {}
132088          }
132089        },
132090        {
132091          "type": "library",
132092          "bom-ref": "pkg:golang/github.com/go-openapi/runtime@v0.24.2?package-id=936321d3ce31e7cf",
132093          "supplier": {},
132094          "name": "github.com/go-openapi/runtime",
132095          "version": "v0.24.2",
132096          "cpe": "cpe:2.3:a:go-openapi:runtime:v0.24.2:*:*:*:*:*:*:*",
132097          "purl": "pkg:golang/github.com/go-openapi/runtime@v0.24.2",
132098          "swid": {
132099            "attachment": {}
132100          },
132101          "pedigree": {},
132102          "evidence": {},
132103          "signature": {
132104            "signature": {
132105              "publicKey": {}
132106            }
132107          },
132108          "modelCard": {
132109            "modelParameters": {
132110              "approach": {}
132111            },
132112            "quantitativeAnalysis": {
132113              "graphics": {}
132114            },
132115            "considerations": {}
132116          }
132117        },
132118        {
132119          "type": "library",
132120          "bom-ref": "pkg:golang/github.com/go-openapi/spec@v0.20.7?package-id=b828acf7acc0dd33",
132121          "supplier": {},
132122          "name": "github.com/go-openapi/spec",
132123          "version": "v0.20.7",
132124          "cpe": "cpe:2.3:a:go-openapi:spec:v0.20.7:*:*:*:*:*:*:*",
132125          "purl": "pkg:golang/github.com/go-openapi/spec@v0.20.7",
132126          "swid": {
132127            "attachment": {}
132128          },
132129          "pedigree": {},
132130          "evidence": {},
132131          "signature": {
132132            "signature": {
132133              "publicKey": {}
132134            }
132135          },
132136          "modelCard": {
132137            "modelParameters": {
132138              "approach": {}
132139            },
132140            "quantitativeAnalysis": {
132141              "graphics": {}
132142            },
132143            "considerations": {}
132144          }
132145        },
132146        {
132147          "type": "library",
132148          "bom-ref": "pkg:golang/github.com/go-openapi/strfmt@v0.21.3?package-id=b675f875831b17f7",
132149          "supplier": {},
132150          "name": "github.com/go-openapi/strfmt",
132151          "version": "v0.21.3",
132152          "cpe": "cpe:2.3:a:go-openapi:strfmt:v0.21.3:*:*:*:*:*:*:*",
132153          "purl": "pkg:golang/github.com/go-openapi/strfmt@v0.21.3",
132154          "swid": {
132155            "attachment": {}
132156          },
132157          "pedigree": {},
132158          "evidence": {},
132159          "signature": {
132160            "signature": {
132161              "publicKey": {}
132162            }
132163          },
132164          "modelCard": {
132165            "modelParameters": {
132166              "approach": {}
132167            },
132168            "quantitativeAnalysis": {
132169              "graphics": {}
132170            },
132171            "considerations": {}
132172          }
132173        },
132174        {
132175          "type": "library",
132176          "bom-ref": "pkg:golang/github.com/go-openapi/swag@v0.22.3?package-id=710fc982226514d3",
132177          "supplier": {},
132178          "name": "github.com/go-openapi/swag",
132179          "version": "v0.22.3",
132180          "cpe": "cpe:2.3:a:go-openapi:swag:v0.22.3:*:*:*:*:*:*:*",
132181          "purl": "pkg:golang/github.com/go-openapi/swag@v0.22.3",
132182          "swid": {
132183            "attachment": {}
132184          },
132185          "pedigree": {},
132186          "evidence": {},
132187          "signature": {
132188            "signature": {
132189              "publicKey": {}
132190            }
132191          },
132192          "modelCard": {
132193            "modelParameters": {
132194              "approach": {}
132195            },
132196            "quantitativeAnalysis": {
132197              "graphics": {}
132198            },
132199            "considerations": {}
132200          }
132201        },
132202        {
132203          "type": "library",
132204          "bom-ref": "pkg:golang/github.com/go-openapi/validate@v0.22.0?package-id=a02d45f4e7b2caf8",
132205          "supplier": {},
132206          "name": "github.com/go-openapi/validate",
132207          "version": "v0.22.0",
132208          "cpe": "cpe:2.3:a:go-openapi:validate:v0.22.0:*:*:*:*:*:*:*",
132209          "purl": "pkg:golang/github.com/go-openapi/validate@v0.22.0",
132210          "swid": {
132211            "attachment": {}
132212          },
132213          "pedigree": {},
132214          "evidence": {},
132215          "signature": {
132216            "signature": {
132217              "publicKey": {}
132218            }
132219          },
132220          "modelCard": {
132221            "modelParameters": {
132222              "approach": {}
132223            },
132224            "quantitativeAnalysis": {
132225              "graphics": {}
132226            },
132227            "considerations": {}
132228          }
132229        },
132230        {
132231          "type": "library",
132232          "bom-ref": "pkg:golang/github.com/go-sql-driver/mysql@v1.6.0?package-id=d12dbb7a797ac8d3",
132233          "supplier": {},
132234          "name": "github.com/go-sql-driver/mysql",
132235          "version": "v1.6.0",
132236          "cpe": "cpe:2.3:a:go-sql-driver:mysql:v1.6.0:*:*:*:*:*:*:*",
132237          "purl": "pkg:golang/github.com/go-sql-driver/mysql@v1.6.0",
132238          "swid": {
132239            "attachment": {}
132240          },
132241          "pedigree": {},
132242          "evidence": {},
132243          "signature": {
132244            "signature": {
132245              "publicKey": {}
132246            }
132247          },
132248          "modelCard": {
132249            "modelParameters": {
132250              "approach": {}
132251            },
132252            "quantitativeAnalysis": {
132253              "graphics": {}
132254            },
132255            "considerations": {}
132256          }
132257        },
132258        {
132259          "type": "library",
132260          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.2?package-id=bfb1e9d6a52bce66",
132261          "supplier": {},
132262          "name": "github.com/gogo/protobuf",
132263          "version": "v1.3.2",
132264          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.2:*:*:*:*:*:*:*",
132265          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.2",
132266          "swid": {
132267            "attachment": {}
132268          },
132269          "pedigree": {},
132270          "evidence": {},
132271          "signature": {
132272            "signature": {
132273              "publicKey": {}
132274            }
132275          },
132276          "modelCard": {
132277            "modelParameters": {
132278              "approach": {}
132279            },
132280            "quantitativeAnalysis": {
132281              "graphics": {}
132282            },
132283            "considerations": {}
132284          }
132285        },
132286        {
132287          "type": "library",
132288          "bom-ref": "pkg:golang/github.com/golang-jwt/jwt/v4@v4.4.2?package-id=ae2d80fc87f4a800",
132289          "supplier": {},
132290          "name": "github.com/golang-jwt/jwt/v4",
132291          "version": "v4.4.2",
132292          "cpe": "cpe:2.3:a:golang-jwt:jwt\\/v4:v4.4.2:*:*:*:*:*:*:*",
132293          "purl": "pkg:golang/github.com/golang-jwt/jwt/v4@v4.4.2",
132294          "swid": {
132295            "attachment": {}
132296          },
132297          "pedigree": {},
132298          "evidence": {},
132299          "signature": {
132300            "signature": {
132301              "publicKey": {}
132302            }
132303          },
132304          "modelCard": {
132305            "modelParameters": {
132306              "approach": {}
132307            },
132308            "quantitativeAnalysis": {
132309              "graphics": {}
132310            },
132311            "considerations": {}
132312          }
132313        },
132314        {
132315          "type": "library",
132316          "bom-ref": "pkg:golang/github.com/golang/groupcache@v0.0.0-20210331224755-41bb18bfe9da?package-id=49956f71b0a7d4e2",
132317          "supplier": {},
132318          "name": "github.com/golang/groupcache",
132319          "version": "v0.0.0-20210331224755-41bb18bfe9da",
132320          "cpe": "cpe:2.3:a:golang:groupcache:v0.0.0-20210331224755-41bb18bfe9da:*:*:*:*:*:*:*",
132321          "purl": "pkg:golang/github.com/golang/groupcache@v0.0.0-20210331224755-41bb18bfe9da",
132322          "swid": {
132323            "attachment": {}
132324          },
132325          "pedigree": {},
132326          "evidence": {},
132327          "signature": {
132328            "signature": {
132329              "publicKey": {}
132330            }
132331          },
132332          "modelCard": {
132333            "modelParameters": {
132334              "approach": {}
132335            },
132336            "quantitativeAnalysis": {
132337              "graphics": {}
132338            },
132339            "considerations": {}
132340          }
132341        },
132342        {
132343          "type": "library",
132344          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.5.2?package-id=9bdee3375a3a07ee",
132345          "supplier": {},
132346          "name": "github.com/golang/protobuf",
132347          "version": "v1.5.2",
132348          "cpe": "cpe:2.3:a:golang:protobuf:v1.5.2:*:*:*:*:*:*:*",
132349          "purl": "pkg:golang/github.com/golang/protobuf@v1.5.2",
132350          "swid": {
132351            "attachment": {}
132352          },
132353          "pedigree": {},
132354          "evidence": {},
132355          "signature": {
132356            "signature": {
132357              "publicKey": {}
132358            }
132359          },
132360          "modelCard": {
132361            "modelParameters": {
132362              "approach": {}
132363            },
132364            "quantitativeAnalysis": {
132365              "graphics": {}
132366            },
132367            "considerations": {}
132368          }
132369        },
132370        {
132371          "type": "library",
132372          "bom-ref": "pkg:golang/github.com/golang/snappy@v0.0.4?package-id=36673a1e8ea61fc5",
132373          "supplier": {},
132374          "name": "github.com/golang/snappy",
132375          "version": "v0.0.4",
132376          "cpe": "cpe:2.3:a:golang:snappy:v0.0.4:*:*:*:*:*:*:*",
132377          "purl": "pkg:golang/github.com/golang/snappy@v0.0.4",
132378          "swid": {
132379            "attachment": {}
132380          },
132381          "pedigree": {},
132382          "evidence": {},
132383          "signature": {
132384            "signature": {
132385              "publicKey": {}
132386            }
132387          },
132388          "modelCard": {
132389            "modelParameters": {
132390              "approach": {}
132391            },
132392            "quantitativeAnalysis": {
132393              "graphics": {}
132394            },
132395            "considerations": {}
132396          }
132397        },
132398        {
132399          "type": "library",
132400          "bom-ref": "pkg:golang/github.com/gomodule/redigo@v1.8.9?package-id=95c01f3ff42fcf50",
132401          "supplier": {},
132402          "name": "github.com/gomodule/redigo",
132403          "version": "v1.8.9",
132404          "cpe": "cpe:2.3:a:gomodule:redigo:v1.8.9:*:*:*:*:*:*:*",
132405          "purl": "pkg:golang/github.com/gomodule/redigo@v1.8.9",
132406          "swid": {
132407            "attachment": {}
132408          },
132409          "pedigree": {},
132410          "evidence": {},
132411          "signature": {
132412            "signature": {
132413              "publicKey": {}
132414            }
132415          },
132416          "modelCard": {
132417            "modelParameters": {
132418              "approach": {}
132419            },
132420            "quantitativeAnalysis": {
132421              "graphics": {}
132422            },
132423            "considerations": {}
132424          }
132425        },
132426        {
132427          "type": "library",
132428          "bom-ref": "pkg:golang/github.com/google/go-cmp@v0.5.9?package-id=a46ac69220db825c",
132429          "supplier": {},
132430          "name": "github.com/google/go-cmp",
132431          "version": "v0.5.9",
132432          "cpe": "cpe:2.3:a:google:go-cmp:v0.5.9:*:*:*:*:*:*:*",
132433          "purl": "pkg:golang/github.com/google/go-cmp@v0.5.9",
132434          "swid": {
132435            "attachment": {}
132436          },
132437          "pedigree": {},
132438          "evidence": {},
132439          "signature": {
132440            "signature": {
132441              "publicKey": {}
132442            }
132443          },
132444          "modelCard": {
132445            "modelParameters": {
132446              "approach": {}
132447            },
132448            "quantitativeAnalysis": {
132449              "graphics": {}
132450            },
132451            "considerations": {}
132452          }
132453        },
132454        {
132455          "type": "library",
132456          "bom-ref": "pkg:golang/github.com/google/pprof@v0.0.0-20220829040838-70bd9ae97f40?package-id=a12b79b9460022c1",
132457          "supplier": {},
132458          "name": "github.com/google/pprof",
132459          "version": "v0.0.0-20220829040838-70bd9ae97f40",
132460          "cpe": "cpe:2.3:a:google:pprof:v0.0.0-20220829040838-70bd9ae97f40:*:*:*:*:*:*:*",
132461          "purl": "pkg:golang/github.com/google/pprof@v0.0.0-20220829040838-70bd9ae97f40",
132462          "swid": {
132463            "attachment": {}
132464          },
132465          "pedigree": {},
132466          "evidence": {},
132467          "signature": {
132468            "signature": {
132469              "publicKey": {}
132470            }
132471          },
132472          "modelCard": {
132473            "modelParameters": {
132474              "approach": {}
132475            },
132476            "quantitativeAnalysis": {
132477              "graphics": {}
132478            },
132479            "considerations": {}
132480          }
132481        },
132482        {
132483          "type": "library",
132484          "bom-ref": "pkg:golang/github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510?package-id=c26557299240c0e1",
132485          "supplier": {},
132486          "name": "github.com/google/shlex",
132487          "version": "v0.0.0-20191202100458-e7afc7fbc510",
132488          "cpe": "cpe:2.3:a:google:shlex:v0.0.0-20191202100458-e7afc7fbc510:*:*:*:*:*:*:*",
132489          "purl": "pkg:golang/github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510",
132490          "swid": {
132491            "attachment": {}
132492          },
132493          "pedigree": {},
132494          "evidence": {},
132495          "signature": {
132496            "signature": {
132497              "publicKey": {}
132498            }
132499          },
132500          "modelCard": {
132501            "modelParameters": {
132502              "approach": {}
132503            },
132504            "quantitativeAnalysis": {
132505              "graphics": {}
132506            },
132507            "considerations": {}
132508          }
132509        },
132510        {
132511          "type": "library",
132512          "bom-ref": "pkg:golang/github.com/google/uuid@v1.3.0?package-id=66470a00f501f2f4",
132513          "supplier": {},
132514          "name": "github.com/google/uuid",
132515          "version": "v1.3.0",
132516          "cpe": "cpe:2.3:a:google:uuid:v1.3.0:*:*:*:*:*:*:*",
132517          "purl": "pkg:golang/github.com/google/uuid@v1.3.0",
132518          "swid": {
132519            "attachment": {}
132520          },
132521          "pedigree": {},
132522          "evidence": {},
132523          "signature": {
132524            "signature": {
132525              "publicKey": {}
132526            }
132527          },
132528          "modelCard": {
132529            "modelParameters": {
132530              "approach": {}
132531            },
132532            "quantitativeAnalysis": {
132533              "graphics": {}
132534            },
132535            "considerations": {}
132536          }
132537        },
132538        {
132539          "type": "library",
132540          "bom-ref": "pkg:golang/github.com/googleapis/enterprise-certificate-proxy@v0.1.0?package-id=a19c6930e8486951",
132541          "supplier": {},
132542          "name": "github.com/googleapis/enterprise-certificate-proxy",
132543          "version": "v0.1.0",
132544          "cpe": "cpe:2.3:a:googleapis:enterprise-certificate-proxy:v0.1.0:*:*:*:*:*:*:*",
132545          "purl": "pkg:golang/github.com/googleapis/enterprise-certificate-proxy@v0.1.0",
132546          "swid": {
132547            "attachment": {}
132548          },
132549          "pedigree": {},
132550          "evidence": {},
132551          "signature": {
132552            "signature": {
132553              "publicKey": {}
132554            }
132555          },
132556          "modelCard": {
132557            "modelParameters": {
132558              "approach": {}
132559            },
132560            "quantitativeAnalysis": {
132561              "graphics": {}
132562            },
132563            "considerations": {}
132564          }
132565        },
132566        {
132567          "type": "library",
132568          "bom-ref": "pkg:golang/github.com/googleapis/gax-go/v2@v2.5.1?package-id=1c7a5c362f90456d",
132569          "supplier": {},
132570          "name": "github.com/googleapis/gax-go/v2",
132571          "version": "v2.5.1",
132572          "cpe": "cpe:2.3:a:googleapis:gax-go\\/v2:v2.5.1:*:*:*:*:*:*:*",
132573          "purl": "pkg:golang/github.com/googleapis/gax-go/v2@v2.5.1",
132574          "swid": {
132575            "attachment": {}
132576          },
132577          "pedigree": {},
132578          "evidence": {},
132579          "signature": {
132580            "signature": {
132581              "publicKey": {}
132582            }
132583          },
132584          "modelCard": {
132585            "modelParameters": {
132586              "approach": {}
132587            },
132588            "quantitativeAnalysis": {
132589              "graphics": {}
132590            },
132591            "considerations": {}
132592          }
132593        },
132594        {
132595          "type": "library",
132596          "bom-ref": "pkg:golang/github.com/gorilla/mux@v1.8.0?package-id=b14cdef6a123051a",
132597          "supplier": {},
132598          "name": "github.com/gorilla/mux",
132599          "version": "v1.8.0",
132600          "cpe": "cpe:2.3:a:gorilla:mux:v1.8.0:*:*:*:*:*:*:*",
132601          "purl": "pkg:golang/github.com/gorilla/mux@v1.8.0",
132602          "swid": {
132603            "attachment": {}
132604          },
132605          "pedigree": {},
132606          "evidence": {},
132607          "signature": {
132608            "signature": {
132609              "publicKey": {}
132610            }
132611          },
132612          "modelCard": {
132613            "modelParameters": {
132614              "approach": {}
132615            },
132616            "quantitativeAnalysis": {
132617              "graphics": {}
132618            },
132619            "considerations": {}
132620          }
132621        },
132622        {
132623          "type": "library",
132624          "bom-ref": "pkg:golang/github.com/gorilla/websocket@v1.5.0?package-id=e1c7c2b28ad15415",
132625          "supplier": {},
132626          "name": "github.com/gorilla/websocket",
132627          "version": "v1.5.0",
132628          "cpe": "cpe:2.3:a:gorilla:websocket:v1.5.0:*:*:*:*:*:*:*",
132629          "purl": "pkg:golang/github.com/gorilla/websocket@v1.5.0",
132630          "swid": {
132631            "attachment": {}
132632          },
132633          "pedigree": {},
132634          "evidence": {},
132635          "signature": {
132636            "signature": {
132637              "publicKey": {}
132638            }
132639          },
132640          "modelCard": {
132641            "modelParameters": {
132642              "approach": {}
132643            },
132644            "quantitativeAnalysis": {
132645              "graphics": {}
132646            },
132647            "considerations": {}
132648          }
132649        },
132650        {
132651          "type": "library",
132652          "bom-ref": "pkg:golang/github.com/hashicorp/errwrap@v1.1.0?package-id=a721303979a608fe",
132653          "supplier": {},
132654          "name": "github.com/hashicorp/errwrap",
132655          "version": "v1.1.0",
132656          "cpe": "cpe:2.3:a:hashicorp:errwrap:v1.1.0:*:*:*:*:*:*:*",
132657          "purl": "pkg:golang/github.com/hashicorp/errwrap@v1.1.0",
132658          "swid": {
132659            "attachment": {}
132660          },
132661          "pedigree": {},
132662          "evidence": {},
132663          "signature": {
132664            "signature": {
132665              "publicKey": {}
132666            }
132667          },
132668          "modelCard": {
132669            "modelParameters": {
132670              "approach": {}
132671            },
132672            "quantitativeAnalysis": {
132673              "graphics": {}
132674            },
132675            "considerations": {}
132676          }
132677        },
132678        {
132679          "type": "library",
132680          "bom-ref": "pkg:golang/github.com/hashicorp/go-multierror@v1.1.1?package-id=2cacda4d32b2243b",
132681          "supplier": {},
132682          "name": "github.com/hashicorp/go-multierror",
132683          "version": "v1.1.1",
132684          "cpe": "cpe:2.3:a:hashicorp:go-multierror:v1.1.1:*:*:*:*:*:*:*",
132685          "purl": "pkg:golang/github.com/hashicorp/go-multierror@v1.1.1",
132686          "swid": {
132687            "attachment": {}
132688          },
132689          "pedigree": {},
132690          "evidence": {},
132691          "signature": {
132692            "signature": {
132693              "publicKey": {}
132694            }
132695          },
132696          "modelCard": {
132697            "modelParameters": {
132698              "approach": {}
132699            },
132700            "quantitativeAnalysis": {
132701              "graphics": {}
132702            },
132703            "considerations": {}
132704          }
132705        },
132706        {
132707          "type": "library",
132708          "bom-ref": "pkg:golang/github.com/hashicorp/go-uuid@v1.0.3?package-id=ac4c833aadbfbdda",
132709          "supplier": {},
132710          "name": "github.com/hashicorp/go-uuid",
132711          "version": "v1.0.3",
132712          "cpe": "cpe:2.3:a:hashicorp:go-uuid:v1.0.3:*:*:*:*:*:*:*",
132713          "purl": "pkg:golang/github.com/hashicorp/go-uuid@v1.0.3",
132714          "swid": {
132715            "attachment": {}
132716          },
132717          "pedigree": {},
132718          "evidence": {},
132719          "signature": {
132720            "signature": {
132721              "publicKey": {}
132722            }
132723          },
132724          "modelCard": {
132725            "modelParameters": {
132726              "approach": {}
132727            },
132728            "quantitativeAnalysis": {
132729              "graphics": {}
132730            },
132731            "considerations": {}
132732          }
132733        },
132734        {
132735          "type": "library",
132736          "bom-ref": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.4?package-id=d3995209406f708e",
132737          "supplier": {},
132738          "name": "github.com/hashicorp/golang-lru",
132739          "version": "v0.5.4",
132740          "cpe": "cpe:2.3:a:hashicorp:golang-lru:v0.5.4:*:*:*:*:*:*:*",
132741          "purl": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.4",
132742          "swid": {
132743            "attachment": {}
132744          },
132745          "pedigree": {},
132746          "evidence": {},
132747          "signature": {
132748            "signature": {
132749              "publicKey": {}
132750            }
132751          },
132752          "modelCard": {
132753            "modelParameters": {
132754              "approach": {}
132755            },
132756            "quantitativeAnalysis": {
132757              "graphics": {}
132758            },
132759            "considerations": {}
132760          }
132761        },
132762        {
132763          "type": "library",
132764          "bom-ref": "pkg:golang/github.com/inconshreveable/mousetrap@v1.0.1?package-id=928c94fac157d9fc",
132765          "supplier": {},
132766          "name": "github.com/inconshreveable/mousetrap",
132767          "version": "v1.0.1",
132768          "cpe": "cpe:2.3:a:inconshreveable:mousetrap:v1.0.1:*:*:*:*:*:*:*",
132769          "purl": "pkg:golang/github.com/inconshreveable/mousetrap@v1.0.1",
132770          "swid": {
132771            "attachment": {}
132772          },
132773          "pedigree": {},
132774          "evidence": {},
132775          "signature": {
132776            "signature": {
132777              "publicKey": {}
132778            }
132779          },
132780          "modelCard": {
132781            "modelParameters": {
132782              "approach": {}
132783            },
132784            "quantitativeAnalysis": {
132785              "graphics": {}
132786            },
132787            "considerations": {}
132788          }
132789        },
132790        {
132791          "type": "library",
132792          "bom-ref": "pkg:golang/github.com/jcmturner/aescts/v2@v2.0.0?package-id=2c8046e49b91841c",
132793          "supplier": {},
132794          "name": "github.com/jcmturner/aescts/v2",
132795          "version": "v2.0.0",
132796          "cpe": "cpe:2.3:a:jcmturner:aescts\\/v2:v2.0.0:*:*:*:*:*:*:*",
132797          "purl": "pkg:golang/github.com/jcmturner/aescts/v2@v2.0.0",
132798          "swid": {
132799            "attachment": {}
132800          },
132801          "pedigree": {},
132802          "evidence": {},
132803          "signature": {
132804            "signature": {
132805              "publicKey": {}
132806            }
132807          },
132808          "modelCard": {
132809            "modelParameters": {
132810              "approach": {}
132811            },
132812            "quantitativeAnalysis": {
132813              "graphics": {}
132814            },
132815            "considerations": {}
132816          }
132817        },
132818        {
132819          "type": "library",
132820          "bom-ref": "pkg:golang/github.com/jcmturner/dnsutils/v2@v2.0.0?package-id=734004c5260db35a",
132821          "supplier": {},
132822          "name": "github.com/jcmturner/dnsutils/v2",
132823          "version": "v2.0.0",
132824          "cpe": "cpe:2.3:a:jcmturner:dnsutils\\/v2:v2.0.0:*:*:*:*:*:*:*",
132825          "purl": "pkg:golang/github.com/jcmturner/dnsutils/v2@v2.0.0",
132826          "swid": {
132827            "attachment": {}
132828          },
132829          "pedigree": {},
132830          "evidence": {},
132831          "signature": {
132832            "signature": {
132833              "publicKey": {}
132834            }
132835          },
132836          "modelCard": {
132837            "modelParameters": {
132838              "approach": {}
132839            },
132840            "quantitativeAnalysis": {
132841              "graphics": {}
132842            },
132843            "considerations": {}
132844          }
132845        },
132846        {
132847          "type": "library",
132848          "bom-ref": "pkg:golang/github.com/jcmturner/gofork@v1.7.6?package-id=af39cbdcc7d69bb6",
132849          "supplier": {},
132850          "name": "github.com/jcmturner/gofork",
132851          "version": "v1.7.6",
132852          "cpe": "cpe:2.3:a:jcmturner:gofork:v1.7.6:*:*:*:*:*:*:*",
132853          "purl": "pkg:golang/github.com/jcmturner/gofork@v1.7.6",
132854          "swid": {
132855            "attachment": {}
132856          },
132857          "pedigree": {},
132858          "evidence": {},
132859          "signature": {
132860            "signature": {
132861              "publicKey": {}
132862            }
132863          },
132864          "modelCard": {
132865            "modelParameters": {
132866              "approach": {}
132867            },
132868            "quantitativeAnalysis": {
132869              "graphics": {}
132870            },
132871            "considerations": {}
132872          }
132873        },
132874        {
132875          "type": "library",
132876          "bom-ref": "pkg:golang/github.com/jcmturner/gokrb5/v8@v8.4.3?package-id=56957a6f89c2f7ac",
132877          "supplier": {},
132878          "name": "github.com/jcmturner/gokrb5/v8",
132879          "version": "v8.4.3",
132880          "cpe": "cpe:2.3:a:jcmturner:gokrb5\\/v8:v8.4.3:*:*:*:*:*:*:*",
132881          "purl": "pkg:golang/github.com/jcmturner/gokrb5/v8@v8.4.3",
132882          "swid": {
132883            "attachment": {}
132884          },
132885          "pedigree": {},
132886          "evidence": {},
132887          "signature": {
132888            "signature": {
132889              "publicKey": {}
132890            }
132891          },
132892          "modelCard": {
132893            "modelParameters": {
132894              "approach": {}
132895            },
132896            "quantitativeAnalysis": {
132897              "graphics": {}
132898            },
132899            "considerations": {}
132900          }
132901        },
132902        {
132903          "type": "library",
132904          "bom-ref": "pkg:golang/github.com/jcmturner/rpc/v2@v2.0.3?package-id=1b5c6b3b1920dd65",
132905          "supplier": {},
132906          "name": "github.com/jcmturner/rpc/v2",
132907          "version": "v2.0.3",
132908          "cpe": "cpe:2.3:a:jcmturner:rpc\\/v2:v2.0.3:*:*:*:*:*:*:*",
132909          "purl": "pkg:golang/github.com/jcmturner/rpc/v2@v2.0.3",
132910          "swid": {
132911            "attachment": {}
132912          },
132913          "pedigree": {},
132914          "evidence": {},
132915          "signature": {
132916            "signature": {
132917              "publicKey": {}
132918            }
132919          },
132920          "modelCard": {
132921            "modelParameters": {
132922              "approach": {}
132923            },
132924            "quantitativeAnalysis": {
132925              "graphics": {}
132926            },
132927            "considerations": {}
132928          }
132929        },
132930        {
132931          "type": "library",
132932          "bom-ref": "pkg:golang/github.com/jessevdk/go-flags@v1.5.0?package-id=51fc2b2b88da61f7",
132933          "supplier": {},
132934          "name": "github.com/jessevdk/go-flags",
132935          "version": "v1.5.0",
132936          "cpe": "cpe:2.3:a:jessevdk:go-flags:v1.5.0:*:*:*:*:*:*:*",
132937          "purl": "pkg:golang/github.com/jessevdk/go-flags@v1.5.0",
132938          "swid": {
132939            "attachment": {}
132940          },
132941          "pedigree": {},
132942          "evidence": {},
132943          "signature": {
132944            "signature": {
132945              "publicKey": {}
132946            }
132947          },
132948          "modelCard": {
132949            "modelParameters": {
132950              "approach": {}
132951            },
132952            "quantitativeAnalysis": {
132953              "graphics": {}
132954            },
132955            "considerations": {}
132956          }
132957        },
132958        {
132959          "type": "library",
132960          "bom-ref": "pkg:golang/github.com/josharian/intern@v1.0.0?package-id=ea9e7c2553383be9",
132961          "supplier": {},
132962          "name": "github.com/josharian/intern",
132963          "version": "v1.0.0",
132964          "cpe": "cpe:2.3:a:josharian:intern:v1.0.0:*:*:*:*:*:*:*",
132965          "purl": "pkg:golang/github.com/josharian/intern@v1.0.0",
132966          "swid": {
132967            "attachment": {}
132968          },
132969          "pedigree": {},
132970          "evidence": {},
132971          "signature": {
132972            "signature": {
132973              "publicKey": {}
132974            }
132975          },
132976          "modelCard": {
132977            "modelParameters": {
132978              "approach": {}
132979            },
132980            "quantitativeAnalysis": {
132981              "graphics": {}
132982            },
132983            "considerations": {}
132984          }
132985        },
132986        {
132987          "type": "library",
132988          "bom-ref": "pkg:golang/github.com/json-iterator/go@v1.1.12?package-id=7fd28c3aac80d450",
132989          "supplier": {},
132990          "name": "github.com/json-iterator/go",
132991          "version": "v1.1.12",
132992          "cpe": "cpe:2.3:a:json-iterator:go:v1.1.12:*:*:*:*:*:*:*",
132993          "purl": "pkg:golang/github.com/json-iterator/go@v1.1.12",
132994          "swid": {
132995            "attachment": {}
132996          },
132997          "pedigree": {},
132998          "evidence": {},
132999          "signature": {
133000            "signature": {
133001              "publicKey": {}
133002            }
133003          },
133004          "modelCard": {
133005            "modelParameters": {
133006              "approach": {}
133007            },
133008            "quantitativeAnalysis": {
133009              "graphics": {}
133010            },
133011            "considerations": {}
133012          }
133013        },
133014        {
133015          "type": "library",
133016          "bom-ref": "pkg:golang/github.com/klauspost/compress@v1.15.11?package-id=ee175857ca80438a",
133017          "supplier": {},
133018          "name": "github.com/klauspost/compress",
133019          "version": "v1.15.11",
133020          "cpe": "cpe:2.3:a:klauspost:compress:v1.15.11:*:*:*:*:*:*:*",
133021          "purl": "pkg:golang/github.com/klauspost/compress@v1.15.11",
133022          "swid": {
133023            "attachment": {}
133024          },
133025          "pedigree": {},
133026          "evidence": {},
133027          "signature": {
133028            "signature": {
133029              "publicKey": {}
133030            }
133031          },
133032          "modelCard": {
133033            "modelParameters": {
133034              "approach": {}
133035            },
133036            "quantitativeAnalysis": {
133037              "graphics": {}
133038            },
133039            "considerations": {}
133040          }
133041        },
133042        {
133043          "type": "library",
133044          "bom-ref": "pkg:golang/github.com/klauspost/cpuid/v2@v2.1.2?package-id=f20447fffce06b3a",
133045          "supplier": {},
133046          "name": "github.com/klauspost/cpuid/v2",
133047          "version": "v2.1.2",
133048          "cpe": "cpe:2.3:a:klauspost:cpuid\\/v2:v2.1.2:*:*:*:*:*:*:*",
133049          "purl": "pkg:golang/github.com/klauspost/cpuid/v2@v2.1.2",
133050          "swid": {
133051            "attachment": {}
133052          },
133053          "pedigree": {},
133054          "evidence": {},
133055          "signature": {
133056            "signature": {
133057              "publicKey": {}
133058            }
133059          },
133060          "modelCard": {
133061            "modelParameters": {
133062              "approach": {}
133063            },
133064            "quantitativeAnalysis": {
133065              "graphics": {}
133066            },
133067            "considerations": {}
133068          }
133069        },
133070        {
133071          "type": "library",
133072          "bom-ref": "pkg:golang/github.com/klauspost/pgzip@v1.2.5?package-id=da4a68ace11f251d",
133073          "supplier": {},
133074          "name": "github.com/klauspost/pgzip",
133075          "version": "v1.2.5",
133076          "cpe": "cpe:2.3:a:klauspost:pgzip:v1.2.5:*:*:*:*:*:*:*",
133077          "purl": "pkg:golang/github.com/klauspost/pgzip@v1.2.5",
133078          "swid": {
133079            "attachment": {}
133080          },
133081          "pedigree": {},
133082          "evidence": {},
133083          "signature": {
133084            "signature": {
133085              "publicKey": {}
133086            }
133087          },
133088          "modelCard": {
133089            "modelParameters": {
133090              "approach": {}
133091            },
133092            "quantitativeAnalysis": {
133093              "graphics": {}
133094            },
133095            "considerations": {}
133096          }
133097        },
133098        {
133099          "type": "library",
133100          "bom-ref": "pkg:golang/github.com/klauspost/readahead@v1.4.0?package-id=ed0cfe00830d9e98",
133101          "supplier": {},
133102          "name": "github.com/klauspost/readahead",
133103          "version": "v1.4.0",
133104          "cpe": "cpe:2.3:a:klauspost:readahead:v1.4.0:*:*:*:*:*:*:*",
133105          "purl": "pkg:golang/github.com/klauspost/readahead@v1.4.0",
133106          "swid": {
133107            "attachment": {}
133108          },
133109          "pedigree": {},
133110          "evidence": {},
133111          "signature": {
133112            "signature": {
133113              "publicKey": {}
133114            }
133115          },
133116          "modelCard": {
133117            "modelParameters": {
133118              "approach": {}
133119            },
133120            "quantitativeAnalysis": {
133121              "graphics": {}
133122            },
133123            "considerations": {}
133124          }
133125        },
133126        {
133127          "type": "library",
133128          "bom-ref": "pkg:golang/github.com/klauspost/reedsolomon@v1.11.0?package-id=d95bad06d6fa589e",
133129          "supplier": {},
133130          "name": "github.com/klauspost/reedsolomon",
133131          "version": "v1.11.0",
133132          "cpe": "cpe:2.3:a:klauspost:reedsolomon:v1.11.0:*:*:*:*:*:*:*",
133133          "purl": "pkg:golang/github.com/klauspost/reedsolomon@v1.11.0",
133134          "swid": {
133135            "attachment": {}
133136          },
133137          "pedigree": {},
133138          "evidence": {},
133139          "signature": {
133140            "signature": {
133141              "publicKey": {}
133142            }
133143          },
133144          "modelCard": {
133145            "modelParameters": {
133146              "approach": {}
133147            },
133148            "quantitativeAnalysis": {
133149              "graphics": {}
133150            },
133151            "considerations": {}
133152          }
133153        },
133154        {
133155          "type": "library",
133156          "bom-ref": "pkg:golang/github.com/lestrrat-go/backoff/v2@v2.0.8?package-id=acc22d1453a4e115",
133157          "supplier": {},
133158          "name": "github.com/lestrrat-go/backoff/v2",
133159          "version": "v2.0.8",
133160          "cpe": "cpe:2.3:a:lestrrat-go:backoff\\/v2:v2.0.8:*:*:*:*:*:*:*",
133161          "purl": "pkg:golang/github.com/lestrrat-go/backoff/v2@v2.0.8",
133162          "swid": {
133163            "attachment": {}
133164          },
133165          "pedigree": {},
133166          "evidence": {},
133167          "signature": {
133168            "signature": {
133169              "publicKey": {}
133170            }
133171          },
133172          "modelCard": {
133173            "modelParameters": {
133174              "approach": {}
133175            },
133176            "quantitativeAnalysis": {
133177              "graphics": {}
133178            },
133179            "considerations": {}
133180          }
133181        },
133182        {
133183          "type": "library",
133184          "bom-ref": "pkg:golang/github.com/lestrrat-go/blackmagic@v1.0.1?package-id=ae1faff25cace8b1",
133185          "supplier": {},
133186          "name": "github.com/lestrrat-go/blackmagic",
133187          "version": "v1.0.1",
133188          "cpe": "cpe:2.3:a:lestrrat-go:blackmagic:v1.0.1:*:*:*:*:*:*:*",
133189          "purl": "pkg:golang/github.com/lestrrat-go/blackmagic@v1.0.1",
133190          "swid": {
133191            "attachment": {}
133192          },
133193          "pedigree": {},
133194          "evidence": {},
133195          "signature": {
133196            "signature": {
133197              "publicKey": {}
133198            }
133199          },
133200          "modelCard": {
133201            "modelParameters": {
133202              "approach": {}
133203            },
133204            "quantitativeAnalysis": {
133205              "graphics": {}
133206            },
133207            "considerations": {}
133208          }
133209        },
133210        {
133211          "type": "library",
133212          "bom-ref": "pkg:golang/github.com/lestrrat-go/httpcc@v1.0.1?package-id=19e74708e1d85cb6",
133213          "supplier": {},
133214          "name": "github.com/lestrrat-go/httpcc",
133215          "version": "v1.0.1",
133216          "cpe": "cpe:2.3:a:lestrrat-go:httpcc:v1.0.1:*:*:*:*:*:*:*",
133217          "purl": "pkg:golang/github.com/lestrrat-go/httpcc@v1.0.1",
133218          "swid": {
133219            "attachment": {}
133220          },
133221          "pedigree": {},
133222          "evidence": {},
133223          "signature": {
133224            "signature": {
133225              "publicKey": {}
133226            }
133227          },
133228          "modelCard": {
133229            "modelParameters": {
133230              "approach": {}
133231            },
133232            "quantitativeAnalysis": {
133233              "graphics": {}
133234            },
133235            "considerations": {}
133236          }
133237        },
133238        {
133239          "type": "library",
133240          "bom-ref": "pkg:golang/github.com/lestrrat-go/iter@v1.0.2?package-id=f6de4c4e6c08c682",
133241          "supplier": {},
133242          "name": "github.com/lestrrat-go/iter",
133243          "version": "v1.0.2",
133244          "cpe": "cpe:2.3:a:lestrrat-go:iter:v1.0.2:*:*:*:*:*:*:*",
133245          "purl": "pkg:golang/github.com/lestrrat-go/iter@v1.0.2",
133246          "swid": {
133247            "attachment": {}
133248          },
133249          "pedigree": {},
133250          "evidence": {},
133251          "signature": {
133252            "signature": {
133253              "publicKey": {}
133254            }
133255          },
133256          "modelCard": {
133257            "modelParameters": {
133258              "approach": {}
133259            },
133260            "quantitativeAnalysis": {
133261              "graphics": {}
133262            },
133263            "considerations": {}
133264          }
133265        },
133266        {
133267          "type": "library",
133268          "bom-ref": "pkg:golang/github.com/lestrrat-go/jwx@v1.2.25?package-id=d146273868f9dacd",
133269          "supplier": {},
133270          "name": "github.com/lestrrat-go/jwx",
133271          "version": "v1.2.25",
133272          "cpe": "cpe:2.3:a:lestrrat-go:jwx:v1.2.25:*:*:*:*:*:*:*",
133273          "purl": "pkg:golang/github.com/lestrrat-go/jwx@v1.2.25",
133274          "swid": {
133275            "attachment": {}
133276          },
133277          "pedigree": {},
133278          "evidence": {},
133279          "signature": {
133280            "signature": {
133281              "publicKey": {}
133282            }
133283          },
133284          "modelCard": {
133285            "modelParameters": {
133286              "approach": {}
133287            },
133288            "quantitativeAnalysis": {
133289              "graphics": {}
133290            },
133291            "considerations": {}
133292          }
133293        },
133294        {
133295          "type": "library",
133296          "bom-ref": "pkg:golang/github.com/lestrrat-go/option@v1.0.0?package-id=3ba2542df482596",
133297          "supplier": {},
133298          "name": "github.com/lestrrat-go/option",
133299          "version": "v1.0.0",
133300          "cpe": "cpe:2.3:a:lestrrat-go:option:v1.0.0:*:*:*:*:*:*:*",
133301          "purl": "pkg:golang/github.com/lestrrat-go/option@v1.0.0",
133302          "swid": {
133303            "attachment": {}
133304          },
133305          "pedigree": {},
133306          "evidence": {},
133307          "signature": {
133308            "signature": {
133309              "publicKey": {}
133310            }
133311          },
133312          "modelCard": {
133313            "modelParameters": {
133314              "approach": {}
133315            },
133316            "quantitativeAnalysis": {
133317              "graphics": {}
133318            },
133319            "considerations": {}
133320          }
133321        },
133322        {
133323          "type": "library",
133324          "bom-ref": "pkg:golang/github.com/lib/pq@v1.10.7?package-id=ff24f498769a3566",
133325          "supplier": {},
133326          "name": "github.com/lib/pq",
133327          "version": "v1.10.7",
133328          "cpe": "cpe:2.3:a:lib:pq:v1.10.7:*:*:*:*:*:*:*",
133329          "purl": "pkg:golang/github.com/lib/pq@v1.10.7",
133330          "swid": {
133331            "attachment": {}
133332          },
133333          "pedigree": {},
133334          "evidence": {},
133335          "signature": {
133336            "signature": {
133337              "publicKey": {}
133338            }
133339          },
133340          "modelCard": {
133341            "modelParameters": {
133342              "approach": {}
133343            },
133344            "quantitativeAnalysis": {
133345              "graphics": {}
133346            },
133347            "considerations": {}
133348          }
133349        },
133350        {
133351          "type": "library",
133352          "bom-ref": "pkg:golang/github.com/lithammer/shortuuid/v4@v4.0.0?package-id=7d618ea87be6d52",
133353          "supplier": {},
133354          "name": "github.com/lithammer/shortuuid/v4",
133355          "version": "v4.0.0",
133356          "cpe": "cpe:2.3:a:lithammer:shortuuid\\/v4:v4.0.0:*:*:*:*:*:*:*",
133357          "purl": "pkg:golang/github.com/lithammer/shortuuid/v4@v4.0.0",
133358          "swid": {
133359            "attachment": {}
133360          },
133361          "pedigree": {},
133362          "evidence": {},
133363          "signature": {
133364            "signature": {
133365              "publicKey": {}
133366            }
133367          },
133368          "modelCard": {
133369            "modelParameters": {
133370              "approach": {}
133371            },
133372            "quantitativeAnalysis": {
133373              "graphics": {}
133374            },
133375            "considerations": {}
133376          }
133377        },
133378        {
133379          "type": "library",
133380          "bom-ref": "pkg:golang/github.com/lucasb-eyer/go-colorful@v1.2.0?package-id=3c79bb2f645bc5d7",
133381          "supplier": {},
133382          "name": "github.com/lucasb-eyer/go-colorful",
133383          "version": "v1.2.0",
133384          "cpe": "cpe:2.3:a:lucasb-eyer:go-colorful:v1.2.0:*:*:*:*:*:*:*",
133385          "purl": "pkg:golang/github.com/lucasb-eyer/go-colorful@v1.2.0",
133386          "swid": {
133387            "attachment": {}
133388          },
133389          "pedigree": {},
133390          "evidence": {},
133391          "signature": {
133392            "signature": {
133393              "publicKey": {}
133394            }
133395          },
133396          "modelCard": {
133397            "modelParameters": {
133398              "approach": {}
133399            },
133400            "quantitativeAnalysis": {
133401              "graphics": {}
133402            },
133403            "considerations": {}
133404          }
133405        },
133406        {
133407          "type": "library",
133408          "bom-ref": "pkg:golang/github.com/mailru/easyjson@v0.7.7?package-id=bb1ae4bbcf553795",
133409          "supplier": {},
133410          "name": "github.com/mailru/easyjson",
133411          "version": "v0.7.7",
133412          "cpe": "cpe:2.3:a:mailru:easyjson:v0.7.7:*:*:*:*:*:*:*",
133413          "purl": "pkg:golang/github.com/mailru/easyjson@v0.7.7",
133414          "swid": {
133415            "attachment": {}
133416          },
133417          "pedigree": {},
133418          "evidence": {},
133419          "signature": {
133420            "signature": {
133421              "publicKey": {}
133422            }
133423          },
133424          "modelCard": {
133425            "modelParameters": {
133426              "approach": {}
133427            },
133428            "quantitativeAnalysis": {
133429              "graphics": {}
133430            },
133431            "considerations": {}
133432          }
133433        },
133434        {
133435          "type": "library",
133436          "bom-ref": "pkg:golang/github.com/mattn/go-colorable@v0.1.13?package-id=3231c19b1f5749f8",
133437          "supplier": {},
133438          "name": "github.com/mattn/go-colorable",
133439          "version": "v0.1.13",
133440          "cpe": "cpe:2.3:a:mattn:go-colorable:v0.1.13:*:*:*:*:*:*:*",
133441          "purl": "pkg:golang/github.com/mattn/go-colorable@v0.1.13",
133442          "swid": {
133443            "attachment": {}
133444          },
133445          "pedigree": {},
133446          "evidence": {},
133447          "signature": {
133448            "signature": {
133449              "publicKey": {}
133450            }
133451          },
133452          "modelCard": {
133453            "modelParameters": {
133454              "approach": {}
133455            },
133456            "quantitativeAnalysis": {
133457              "graphics": {}
133458            },
133459            "considerations": {}
133460          }
133461        },
133462        {
133463          "type": "library",
133464          "bom-ref": "pkg:golang/github.com/mattn/go-ieproxy@v0.0.1?package-id=6baacc2223e137eb",
133465          "supplier": {},
133466          "name": "github.com/mattn/go-ieproxy",
133467          "version": "v0.0.1",
133468          "cpe": "cpe:2.3:a:mattn:go-ieproxy:v0.0.1:*:*:*:*:*:*:*",
133469          "purl": "pkg:golang/github.com/mattn/go-ieproxy@v0.0.1",
133470          "swid": {
133471            "attachment": {}
133472          },
133473          "pedigree": {},
133474          "evidence": {},
133475          "signature": {
133476            "signature": {
133477              "publicKey": {}
133478            }
133479          },
133480          "modelCard": {
133481            "modelParameters": {
133482              "approach": {}
133483            },
133484            "quantitativeAnalysis": {
133485              "graphics": {}
133486            },
133487            "considerations": {}
133488          }
133489        },
133490        {
133491          "type": "library",
133492          "bom-ref": "pkg:golang/github.com/mattn/go-isatty@v0.0.16?package-id=6c096753e739c733",
133493          "supplier": {},
133494          "name": "github.com/mattn/go-isatty",
133495          "version": "v0.0.16",
133496          "cpe": "cpe:2.3:a:mattn:go-isatty:v0.0.16:*:*:*:*:*:*:*",
133497          "purl": "pkg:golang/github.com/mattn/go-isatty@v0.0.16",
133498          "swid": {
133499            "attachment": {}
133500          },
133501          "pedigree": {},
133502          "evidence": {},
133503          "signature": {
133504            "signature": {
133505              "publicKey": {}
133506            }
133507          },
133508          "modelCard": {
133509            "modelParameters": {
133510              "approach": {}
133511            },
133512            "quantitativeAnalysis": {
133513              "graphics": {}
133514            },
133515            "considerations": {}
133516          }
133517        },
133518        {
133519          "type": "library",
133520          "bom-ref": "pkg:golang/github.com/mattn/go-localereader@v0.0.1?package-id=a2af36c63dd1ff23",
133521          "supplier": {},
133522          "name": "github.com/mattn/go-localereader",
133523          "version": "v0.0.1",
133524          "cpe": "cpe:2.3:a:mattn:go-localereader:v0.0.1:*:*:*:*:*:*:*",
133525          "purl": "pkg:golang/github.com/mattn/go-localereader@v0.0.1",
133526          "swid": {
133527            "attachment": {}
133528          },
133529          "pedigree": {},
133530          "evidence": {},
133531          "signature": {
133532            "signature": {
133533              "publicKey": {}
133534            }
133535          },
133536          "modelCard": {
133537            "modelParameters": {
133538              "approach": {}
133539            },
133540            "quantitativeAnalysis": {
133541              "graphics": {}
133542            },
133543            "considerations": {}
133544          }
133545        },
133546        {
133547          "type": "library",
133548          "bom-ref": "pkg:golang/github.com/mattn/go-runewidth@v0.0.14?package-id=da5f9e2c3233ab0f",
133549          "supplier": {},
133550          "name": "github.com/mattn/go-runewidth",
133551          "version": "v0.0.14",
133552          "cpe": "cpe:2.3:a:mattn:go-runewidth:v0.0.14:*:*:*:*:*:*:*",
133553          "purl": "pkg:golang/github.com/mattn/go-runewidth@v0.0.14",
133554          "swid": {
133555            "attachment": {}
133556          },
133557          "pedigree": {},
133558          "evidence": {},
133559          "signature": {
133560            "signature": {
133561              "publicKey": {}
133562            }
133563          },
133564          "modelCard": {
133565            "modelParameters": {
133566              "approach": {}
133567            },
133568            "quantitativeAnalysis": {
133569              "graphics": {}
133570            },
133571            "considerations": {}
133572          }
133573        },
133574        {
133575          "type": "library",
133576          "bom-ref": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2?package-id=2742bd840d0205d",
133577          "supplier": {},
133578          "name": "github.com/matttproud/golang_protobuf_extensions",
133579          "version": "v1.0.2",
133580          "cpe": "cpe:2.3:a:matttproud:golang-protobuf-extensions:v1.0.2:*:*:*:*:*:*:*",
133581          "purl": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2",
133582          "swid": {
133583            "attachment": {}
133584          },
133585          "pedigree": {},
133586          "evidence": {},
133587          "signature": {
133588            "signature": {
133589              "publicKey": {}
133590            }
133591          },
133592          "modelCard": {
133593            "modelParameters": {
133594              "approach": {}
133595            },
133596            "quantitativeAnalysis": {
133597              "graphics": {}
133598            },
133599            "considerations": {}
133600          }
133601        },
133602        {
133603          "type": "library",
133604          "bom-ref": "pkg:golang/github.com/miekg/dns@v1.1.50?package-id=40ea89188ba0bf77",
133605          "supplier": {},
133606          "name": "github.com/miekg/dns",
133607          "version": "v1.1.50",
133608          "cpe": "cpe:2.3:a:miekg:dns:v1.1.50:*:*:*:*:*:*:*",
133609          "purl": "pkg:golang/github.com/miekg/dns@v1.1.50",
133610          "swid": {
133611            "attachment": {}
133612          },
133613          "pedigree": {},
133614          "evidence": {},
133615          "signature": {
133616            "signature": {
133617              "publicKey": {}
133618            }
133619          },
133620          "modelCard": {
133621            "modelParameters": {
133622              "approach": {}
133623            },
133624            "quantitativeAnalysis": {
133625              "graphics": {}
133626            },
133627            "considerations": {}
133628          }
133629        },
133630        {
133631          "type": "library",
133632          "bom-ref": "pkg:golang/github.com/minio/cli@v1.24.0?package-id=61898b5a5c23c5aa",
133633          "supplier": {},
133634          "name": "github.com/minio/cli",
133635          "version": "v1.24.0",
133636          "cpe": "cpe:2.3:a:minio:cli:v1.24.0:*:*:*:*:*:*:*",
133637          "purl": "pkg:golang/github.com/minio/cli@v1.24.0",
133638          "swid": {
133639            "attachment": {}
133640          },
133641          "pedigree": {},
133642          "evidence": {},
133643          "signature": {
133644            "signature": {
133645              "publicKey": {}
133646            }
133647          },
133648          "modelCard": {
133649            "modelParameters": {
133650              "approach": {}
133651            },
133652            "quantitativeAnalysis": {
133653              "graphics": {}
133654            },
133655            "considerations": {}
133656          }
133657        },
133658        {
133659          "type": "library",
133660          "bom-ref": "pkg:golang/github.com/minio/colorjson@v1.0.4?package-id=857d9524ef615546",
133661          "supplier": {},
133662          "name": "github.com/minio/colorjson",
133663          "version": "v1.0.4",
133664          "cpe": "cpe:2.3:a:minio:colorjson:v1.0.4:*:*:*:*:*:*:*",
133665          "purl": "pkg:golang/github.com/minio/colorjson@v1.0.4",
133666          "swid": {
133667            "attachment": {}
133668          },
133669          "pedigree": {},
133670          "evidence": {},
133671          "signature": {
133672            "signature": {
133673              "publicKey": {}
133674            }
133675          },
133676          "modelCard": {
133677            "modelParameters": {
133678              "approach": {}
133679            },
133680            "quantitativeAnalysis": {
133681              "graphics": {}
133682            },
133683            "considerations": {}
133684          }
133685        },
133686        {
133687          "type": "library",
133688          "bom-ref": "pkg:golang/github.com/minio/console@v0.21.1?package-id=ab9d7b98ac0ab45b",
133689          "supplier": {},
133690          "name": "github.com/minio/console",
133691          "version": "v0.21.1",
133692          "cpe": "cpe:2.3:a:minio:console:v0.21.1:*:*:*:*:*:*:*",
133693          "purl": "pkg:golang/github.com/minio/console@v0.21.1",
133694          "swid": {
133695            "attachment": {}
133696          },
133697          "pedigree": {},
133698          "evidence": {},
133699          "signature": {
133700            "signature": {
133701              "publicKey": {}
133702            }
133703          },
133704          "modelCard": {
133705            "modelParameters": {
133706              "approach": {}
133707            },
133708            "quantitativeAnalysis": {
133709              "graphics": {}
133710            },
133711            "considerations": {}
133712          }
133713        },
133714        {
133715          "type": "library",
133716          "bom-ref": "pkg:golang/github.com/minio/csvparser@v1.0.0?package-id=c322b8358047c4b0",
133717          "supplier": {},
133718          "name": "github.com/minio/csvparser",
133719          "version": "v1.0.0",
133720          "cpe": "cpe:2.3:a:minio:csvparser:v1.0.0:*:*:*:*:*:*:*",
133721          "purl": "pkg:golang/github.com/minio/csvparser@v1.0.0",
133722          "swid": {
133723            "attachment": {}
133724          },
133725          "pedigree": {},
133726          "evidence": {},
133727          "signature": {
133728            "signature": {
133729              "publicKey": {}
133730            }
133731          },
133732          "modelCard": {
133733            "modelParameters": {
133734              "approach": {}
133735            },
133736            "quantitativeAnalysis": {
133737              "graphics": {}
133738            },
133739            "considerations": {}
133740          }
133741        },
133742        {
133743          "type": "library",
133744          "bom-ref": "pkg:golang/github.com/minio/dperf@v0.4.2?package-id=9d238d243d88f0e6",
133745          "supplier": {},
133746          "name": "github.com/minio/dperf",
133747          "version": "v0.4.2",
133748          "cpe": "cpe:2.3:a:minio:dperf:v0.4.2:*:*:*:*:*:*:*",
133749          "purl": "pkg:golang/github.com/minio/dperf@v0.4.2",
133750          "swid": {
133751            "attachment": {}
133752          },
133753          "pedigree": {},
133754          "evidence": {},
133755          "signature": {
133756            "signature": {
133757              "publicKey": {}
133758            }
133759          },
133760          "modelCard": {
133761            "modelParameters": {
133762              "approach": {}
133763            },
133764            "quantitativeAnalysis": {
133765              "graphics": {}
133766            },
133767            "considerations": {}
133768          }
133769        },
133770        {
133771          "type": "library",
133772          "bom-ref": "pkg:golang/github.com/minio/filepath@v1.0.0?package-id=f9233a61bf6864b4",
133773          "supplier": {},
133774          "name": "github.com/minio/filepath",
133775          "version": "v1.0.0",
133776          "cpe": "cpe:2.3:a:minio:filepath:v1.0.0:*:*:*:*:*:*:*",
133777          "purl": "pkg:golang/github.com/minio/filepath@v1.0.0",
133778          "swid": {
133779            "attachment": {}
133780          },
133781          "pedigree": {},
133782          "evidence": {},
133783          "signature": {
133784            "signature": {
133785              "publicKey": {}
133786            }
133787          },
133788          "modelCard": {
133789            "modelParameters": {
133790              "approach": {}
133791            },
133792            "quantitativeAnalysis": {
133793              "graphics": {}
133794            },
133795            "considerations": {}
133796          }
133797        },
133798        {
133799          "type": "library",
133800          "bom-ref": "pkg:golang/github.com/minio/highwayhash@v1.0.2?package-id=7b479c5567f2c9a6",
133801          "supplier": {},
133802          "name": "github.com/minio/highwayhash",
133803          "version": "v1.0.2",
133804          "cpe": "cpe:2.3:a:minio:highwayhash:v1.0.2:*:*:*:*:*:*:*",
133805          "purl": "pkg:golang/github.com/minio/highwayhash@v1.0.2",
133806          "swid": {
133807            "attachment": {}
133808          },
133809          "pedigree": {},
133810          "evidence": {},
133811          "signature": {
133812            "signature": {
133813              "publicKey": {}
133814            }
133815          },
133816          "modelCard": {
133817            "modelParameters": {
133818              "approach": {}
133819            },
133820            "quantitativeAnalysis": {
133821              "graphics": {}
133822            },
133823            "considerations": {}
133824          }
133825        },
133826        {
133827          "type": "library",
133828          "bom-ref": "pkg:golang/github.com/minio/kes@v0.21.1?package-id=99339414511e9143",
133829          "supplier": {},
133830          "name": "github.com/minio/kes",
133831          "version": "v0.21.1",
133832          "cpe": "cpe:2.3:a:minio:kes:v0.21.1:*:*:*:*:*:*:*",
133833          "purl": "pkg:golang/github.com/minio/kes@v0.21.1",
133834          "swid": {
133835            "attachment": {}
133836          },
133837          "pedigree": {},
133838          "evidence": {},
133839          "signature": {
133840            "signature": {
133841              "publicKey": {}
133842            }
133843          },
133844          "modelCard": {
133845            "modelParameters": {
133846              "approach": {}
133847            },
133848            "quantitativeAnalysis": {
133849              "graphics": {}
133850            },
133851            "considerations": {}
133852          }
133853        },
133854        {
133855          "type": "library",
133856          "bom-ref": "pkg:golang/github.com/minio/madmin-go@v1.6.6?package-id=ef0be9560a1efd71",
133857          "supplier": {},
133858          "name": "github.com/minio/madmin-go",
133859          "version": "v1.6.6",
133860          "cpe": "cpe:2.3:a:minio:madmin-go:v1.6.6:*:*:*:*:*:*:*",
133861          "purl": "pkg:golang/github.com/minio/madmin-go@v1.6.6",
133862          "swid": {
133863            "attachment": {}
133864          },
133865          "pedigree": {},
133866          "evidence": {},
133867          "signature": {
133868            "signature": {
133869              "publicKey": {}
133870            }
133871          },
133872          "modelCard": {
133873            "modelParameters": {
133874              "approach": {}
133875            },
133876            "quantitativeAnalysis": {
133877              "graphics": {}
133878            },
133879            "considerations": {}
133880          }
133881        },
133882        {
133883          "type": "library",
133884          "bom-ref": "pkg:golang/github.com/minio/mc@v0.0.0-20221019004256-8493f97e042f?package-id=85755c26f844b790",
133885          "supplier": {},
133886          "name": "github.com/minio/mc",
133887          "version": "v0.0.0-20221019004256-8493f97e042f",
133888          "cpe": "cpe:2.3:a:minio:mc:v0.0.0-20221019004256-8493f97e042f:*:*:*:*:*:*:*",
133889          "purl": "pkg:golang/github.com/minio/mc@v0.0.0-20221019004256-8493f97e042f",
133890          "swid": {
133891            "attachment": {}
133892          },
133893          "pedigree": {},
133894          "evidence": {},
133895          "signature": {
133896            "signature": {
133897              "publicKey": {}
133898            }
133899          },
133900          "modelCard": {
133901            "modelParameters": {
133902              "approach": {}
133903            },
133904            "quantitativeAnalysis": {
133905              "graphics": {}
133906            },
133907            "considerations": {}
133908          }
133909        },
133910        {
133911          "type": "library",
133912          "bom-ref": "pkg:golang/github.com/minio/md5-simd@v1.1.2?package-id=ac74320a0421a79a",
133913          "supplier": {},
133914          "name": "github.com/minio/md5-simd",
133915          "version": "v1.1.2",
133916          "cpe": "cpe:2.3:a:minio:md5-simd:v1.1.2:*:*:*:*:*:*:*",
133917          "purl": "pkg:golang/github.com/minio/md5-simd@v1.1.2",
133918          "swid": {
133919            "attachment": {}
133920          },
133921          "pedigree": {},
133922          "evidence": {},
133923          "signature": {
133924            "signature": {
133925              "publicKey": {}
133926            }
133927          },
133928          "modelCard": {
133929            "modelParameters": {
133930              "approach": {}
133931            },
133932            "quantitativeAnalysis": {
133933              "graphics": {}
133934            },
133935            "considerations": {}
133936          }
133937        },
133938        {
133939          "type": "library",
133940          "bom-ref": "pkg:golang/github.com/minio/minio@v0.0.0-20221024183507-fc6c7949727e?package-id=4b70dfc865a348e1",
133941          "supplier": {},
133942          "name": "github.com/minio/minio",
133943          "version": "v0.0.0-20221024183507-fc6c7949727e",
133944          "cpe": "cpe:2.3:a:minio:minio:v0.0.0-20221024183507-fc6c7949727e:*:*:*:*:*:*:*",
133945          "purl": "pkg:golang/github.com/minio/minio@v0.0.0-20221024183507-fc6c7949727e",
133946          "swid": {
133947            "attachment": {}
133948          },
133949          "pedigree": {},
133950          "evidence": {},
133951          "signature": {
133952            "signature": {
133953              "publicKey": {}
133954            }
133955          },
133956          "modelCard": {
133957            "modelParameters": {
133958              "approach": {}
133959            },
133960            "quantitativeAnalysis": {
133961              "graphics": {}
133962            },
133963            "considerations": {}
133964          }
133965        },
133966        {
133967          "type": "library",
133968          "bom-ref": "pkg:golang/github.com/minio/minio-go/v7@v7.0.43-0.20221021202758-c6319beb6b27?package-id=c04a11a63a1cc4f",
133969          "supplier": {},
133970          "name": "github.com/minio/minio-go/v7",
133971          "version": "v7.0.43-0.20221021202758-c6319beb6b27",
133972          "cpe": "cpe:2.3:a:minio:minio-go\\/v7:v7.0.43-0.20221021202758-c6319beb6b27:*:*:*:*:*:*:*",
133973          "purl": "pkg:golang/github.com/minio/minio-go/v7@v7.0.43-0.20221021202758-c6319beb6b27",
133974          "swid": {
133975            "attachment": {}
133976          },
133977          "pedigree": {},
133978          "evidence": {},
133979          "signature": {
133980            "signature": {
133981              "publicKey": {}
133982            }
133983          },
133984          "modelCard": {
133985            "modelParameters": {
133986              "approach": {}
133987            },
133988            "quantitativeAnalysis": {
133989              "graphics": {}
133990            },
133991            "considerations": {}
133992          }
133993        },
133994        {
133995          "type": "library",
133996          "bom-ref": "pkg:golang/github.com/minio/pkg@v1.5.4?package-id=7f5d702778d8d160",
133997          "supplier": {},
133998          "name": "github.com/minio/pkg",
133999          "version": "v1.5.4",
134000          "cpe": "cpe:2.3:a:minio:pkg:v1.5.4:*:*:*:*:*:*:*",
134001          "purl": "pkg:golang/github.com/minio/pkg@v1.5.4",
134002          "swid": {
134003            "attachment": {}
134004          },
134005          "pedigree": {},
134006          "evidence": {},
134007          "signature": {
134008            "signature": {
134009              "publicKey": {}
134010            }
134011          },
134012          "modelCard": {
134013            "modelParameters": {
134014              "approach": {}
134015            },
134016            "quantitativeAnalysis": {
134017              "graphics": {}
134018            },
134019            "considerations": {}
134020          }
134021        },
134022        {
134023          "type": "library",
134024          "bom-ref": "pkg:golang/github.com/minio/selfupdate@v0.5.0?package-id=f191b37fdccb879a",
134025          "supplier": {},
134026          "name": "github.com/minio/selfupdate",
134027          "version": "v0.5.0",
134028          "cpe": "cpe:2.3:a:minio:selfupdate:v0.5.0:*:*:*:*:*:*:*",
134029          "purl": "pkg:golang/github.com/minio/selfupdate@v0.5.0",
134030          "swid": {
134031            "attachment": {}
134032          },
134033          "pedigree": {},
134034          "evidence": {},
134035          "signature": {
134036            "signature": {
134037              "publicKey": {}
134038            }
134039          },
134040          "modelCard": {
134041            "modelParameters": {
134042              "approach": {}
134043            },
134044            "quantitativeAnalysis": {
134045              "graphics": {}
134046            },
134047            "considerations": {}
134048          }
134049        },
134050        {
134051          "type": "library",
134052          "bom-ref": "pkg:golang/github.com/minio/sha256-simd@v1.0.0?package-id=185bae10bca96c50",
134053          "supplier": {},
134054          "name": "github.com/minio/sha256-simd",
134055          "version": "v1.0.0",
134056          "cpe": "cpe:2.3:a:minio:sha256-simd:v1.0.0:*:*:*:*:*:*:*",
134057          "purl": "pkg:golang/github.com/minio/sha256-simd@v1.0.0",
134058          "swid": {
134059            "attachment": {}
134060          },
134061          "pedigree": {},
134062          "evidence": {},
134063          "signature": {
134064            "signature": {
134065              "publicKey": {}
134066            }
134067          },
134068          "modelCard": {
134069            "modelParameters": {
134070              "approach": {}
134071            },
134072            "quantitativeAnalysis": {
134073              "graphics": {}
134074            },
134075            "considerations": {}
134076          }
134077        },
134078        {
134079          "type": "library",
134080          "bom-ref": "pkg:golang/github.com/minio/simdjson-go@v0.4.2?package-id=9c63029d0a3e1aa3",
134081          "supplier": {},
134082          "name": "github.com/minio/simdjson-go",
134083          "version": "v0.4.2",
134084          "cpe": "cpe:2.3:a:minio:simdjson-go:v0.4.2:*:*:*:*:*:*:*",
134085          "purl": "pkg:golang/github.com/minio/simdjson-go@v0.4.2",
134086          "swid": {
134087            "attachment": {}
134088          },
134089          "pedigree": {},
134090          "evidence": {},
134091          "signature": {
134092            "signature": {
134093              "publicKey": {}
134094            }
134095          },
134096          "modelCard": {
134097            "modelParameters": {
134098              "approach": {}
134099            },
134100            "quantitativeAnalysis": {
134101              "graphics": {}
134102            },
134103            "considerations": {}
134104          }
134105        },
134106        {
134107          "type": "library",
134108          "bom-ref": "pkg:golang/github.com/minio/sio@v0.3.0?package-id=9196bd9eb9b0df5d",
134109          "supplier": {},
134110          "name": "github.com/minio/sio",
134111          "version": "v0.3.0",
134112          "cpe": "cpe:2.3:a:minio:sio:v0.3.0:*:*:*:*:*:*:*",
134113          "purl": "pkg:golang/github.com/minio/sio@v0.3.0",
134114          "swid": {
134115            "attachment": {}
134116          },
134117          "pedigree": {},
134118          "evidence": {},
134119          "signature": {
134120            "signature": {
134121              "publicKey": {}
134122            }
134123          },
134124          "modelCard": {
134125            "modelParameters": {
134126              "approach": {}
134127            },
134128            "quantitativeAnalysis": {
134129              "graphics": {}
134130            },
134131            "considerations": {}
134132          }
134133        },
134134        {
134135          "type": "library",
134136          "bom-ref": "pkg:golang/github.com/minio/xxml@v0.0.3?package-id=c4864b4e5cbcccfa",
134137          "supplier": {},
134138          "name": "github.com/minio/xxml",
134139          "version": "v0.0.3",
134140          "cpe": "cpe:2.3:a:minio:xxml:v0.0.3:*:*:*:*:*:*:*",
134141          "purl": "pkg:golang/github.com/minio/xxml@v0.0.3",
134142          "swid": {
134143            "attachment": {}
134144          },
134145          "pedigree": {},
134146          "evidence": {},
134147          "signature": {
134148            "signature": {
134149              "publicKey": {}
134150            }
134151          },
134152          "modelCard": {
134153            "modelParameters": {
134154              "approach": {}
134155            },
134156            "quantitativeAnalysis": {
134157              "graphics": {}
134158            },
134159            "considerations": {}
134160          }
134161        },
134162        {
134163          "type": "library",
134164          "bom-ref": "pkg:golang/github.com/minio/zipindex@v0.3.0?package-id=754f35738a4d6920",
134165          "supplier": {},
134166          "name": "github.com/minio/zipindex",
134167          "version": "v0.3.0",
134168          "cpe": "cpe:2.3:a:minio:zipindex:v0.3.0:*:*:*:*:*:*:*",
134169          "purl": "pkg:golang/github.com/minio/zipindex@v0.3.0",
134170          "swid": {
134171            "attachment": {}
134172          },
134173          "pedigree": {},
134174          "evidence": {},
134175          "signature": {
134176            "signature": {
134177              "publicKey": {}
134178            }
134179          },
134180          "modelCard": {
134181            "modelParameters": {
134182              "approach": {}
134183            },
134184            "quantitativeAnalysis": {
134185              "graphics": {}
134186            },
134187            "considerations": {}
134188          }
134189        },
134190        {
134191          "type": "library",
134192          "bom-ref": "pkg:golang/github.com/mitchellh/go-homedir@v1.1.0?package-id=62a5b9346e6da275",
134193          "supplier": {},
134194          "name": "github.com/mitchellh/go-homedir",
134195          "version": "v1.1.0",
134196          "cpe": "cpe:2.3:a:mitchellh:go-homedir:v1.1.0:*:*:*:*:*:*:*",
134197          "purl": "pkg:golang/github.com/mitchellh/go-homedir@v1.1.0",
134198          "swid": {
134199            "attachment": {}
134200          },
134201          "pedigree": {},
134202          "evidence": {},
134203          "signature": {
134204            "signature": {
134205              "publicKey": {}
134206            }
134207          },
134208          "modelCard": {
134209            "modelParameters": {
134210              "approach": {}
134211            },
134212            "quantitativeAnalysis": {
134213              "graphics": {}
134214            },
134215            "considerations": {}
134216          }
134217        },
134218        {
134219          "type": "library",
134220          "bom-ref": "pkg:golang/github.com/mitchellh/mapstructure@v1.5.0?package-id=253d5a619ee9ba3c",
134221          "supplier": {},
134222          "name": "github.com/mitchellh/mapstructure",
134223          "version": "v1.5.0",
134224          "cpe": "cpe:2.3:a:mitchellh:mapstructure:v1.5.0:*:*:*:*:*:*:*",
134225          "purl": "pkg:golang/github.com/mitchellh/mapstructure@v1.5.0",
134226          "swid": {
134227            "attachment": {}
134228          },
134229          "pedigree": {},
134230          "evidence": {},
134231          "signature": {
134232            "signature": {
134233              "publicKey": {}
134234            }
134235          },
134236          "modelCard": {
134237            "modelParameters": {
134238              "approach": {}
134239            },
134240            "quantitativeAnalysis": {
134241              "graphics": {}
134242            },
134243            "considerations": {}
134244          }
134245        },
134246        {
134247          "type": "library",
134248          "bom-ref": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd?package-id=8ce7aeebb9be5b3",
134249          "supplier": {},
134250          "name": "github.com/modern-go/concurrent",
134251          "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
134252          "cpe": "cpe:2.3:a:modern-go:concurrent:v0.0.0-20180306012644-bacd9c7ef1dd:*:*:*:*:*:*:*",
134253          "purl": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd",
134254          "swid": {
134255            "attachment": {}
134256          },
134257          "pedigree": {},
134258          "evidence": {},
134259          "signature": {
134260            "signature": {
134261              "publicKey": {}
134262            }
134263          },
134264          "modelCard": {
134265            "modelParameters": {
134266              "approach": {}
134267            },
134268            "quantitativeAnalysis": {
134269              "graphics": {}
134270            },
134271            "considerations": {}
134272          }
134273        },
134274        {
134275          "type": "library",
134276          "bom-ref": "pkg:golang/github.com/modern-go/reflect2@v1.0.2?package-id=8e4cb0f6c3e77e1e",
134277          "supplier": {},
134278          "name": "github.com/modern-go/reflect2",
134279          "version": "v1.0.2",
134280          "cpe": "cpe:2.3:a:modern-go:reflect2:v1.0.2:*:*:*:*:*:*:*",
134281          "purl": "pkg:golang/github.com/modern-go/reflect2@v1.0.2",
134282          "swid": {
134283            "attachment": {}
134284          },
134285          "pedigree": {},
134286          "evidence": {},
134287          "signature": {
134288            "signature": {
134289              "publicKey": {}
134290            }
134291          },
134292          "modelCard": {
134293            "modelParameters": {
134294              "approach": {}
134295            },
134296            "quantitativeAnalysis": {
134297              "graphics": {}
134298            },
134299            "considerations": {}
134300          }
134301        },
134302        {
134303          "type": "library",
134304          "bom-ref": "pkg:golang/github.com/montanaflynn/stats@v0.6.6?package-id=12e98f72a5063e8",
134305          "supplier": {},
134306          "name": "github.com/montanaflynn/stats",
134307          "version": "v0.6.6",
134308          "cpe": "cpe:2.3:a:montanaflynn:stats:v0.6.6:*:*:*:*:*:*:*",
134309          "purl": "pkg:golang/github.com/montanaflynn/stats@v0.6.6",
134310          "swid": {
134311            "attachment": {}
134312          },
134313          "pedigree": {},
134314          "evidence": {},
134315          "signature": {
134316            "signature": {
134317              "publicKey": {}
134318            }
134319          },
134320          "modelCard": {
134321            "modelParameters": {
134322              "approach": {}
134323            },
134324            "quantitativeAnalysis": {
134325              "graphics": {}
134326            },
134327            "considerations": {}
134328          }
134329        },
134330        {
134331          "type": "library",
134332          "bom-ref": "pkg:golang/github.com/muesli/ansi@v0.0.0-20211031195517-c9f0611b6c70?package-id=a363003beaf807cd",
134333          "supplier": {},
134334          "name": "github.com/muesli/ansi",
134335          "version": "v0.0.0-20211031195517-c9f0611b6c70",
134336          "cpe": "cpe:2.3:a:muesli:ansi:v0.0.0-20211031195517-c9f0611b6c70:*:*:*:*:*:*:*",
134337          "purl": "pkg:golang/github.com/muesli/ansi@v0.0.0-20211031195517-c9f0611b6c70",
134338          "swid": {
134339            "attachment": {}
134340          },
134341          "pedigree": {},
134342          "evidence": {},
134343          "signature": {
134344            "signature": {
134345              "publicKey": {}
134346            }
134347          },
134348          "modelCard": {
134349            "modelParameters": {
134350              "approach": {}
134351            },
134352            "quantitativeAnalysis": {
134353              "graphics": {}
134354            },
134355            "considerations": {}
134356          }
134357        },
134358        {
134359          "type": "library",
134360          "bom-ref": "pkg:golang/github.com/muesli/cancelreader@v0.2.2?package-id=748bc09943934c8b",
134361          "supplier": {},
134362          "name": "github.com/muesli/cancelreader",
134363          "version": "v0.2.2",
134364          "cpe": "cpe:2.3:a:muesli:cancelreader:v0.2.2:*:*:*:*:*:*:*",
134365          "purl": "pkg:golang/github.com/muesli/cancelreader@v0.2.2",
134366          "swid": {
134367            "attachment": {}
134368          },
134369          "pedigree": {},
134370          "evidence": {},
134371          "signature": {
134372            "signature": {
134373              "publicKey": {}
134374            }
134375          },
134376          "modelCard": {
134377            "modelParameters": {
134378              "approach": {}
134379            },
134380            "quantitativeAnalysis": {
134381              "graphics": {}
134382            },
134383            "considerations": {}
134384          }
134385        },
134386        {
134387          "type": "library",
134388          "bom-ref": "pkg:golang/github.com/muesli/reflow@v0.3.0?package-id=7087648dd3c4e0d5",
134389          "supplier": {},
134390          "name": "github.com/muesli/reflow",
134391          "version": "v0.3.0",
134392          "cpe": "cpe:2.3:a:muesli:reflow:v0.3.0:*:*:*:*:*:*:*",
134393          "purl": "pkg:golang/github.com/muesli/reflow@v0.3.0",
134394          "swid": {
134395            "attachment": {}
134396          },
134397          "pedigree": {},
134398          "evidence": {},
134399          "signature": {
134400            "signature": {
134401              "publicKey": {}
134402            }
134403          },
134404          "modelCard": {
134405            "modelParameters": {
134406              "approach": {}
134407            },
134408            "quantitativeAnalysis": {
134409              "graphics": {}
134410            },
134411            "considerations": {}
134412          }
134413        },
134414        {
134415          "type": "library",
134416          "bom-ref": "pkg:golang/github.com/muesli/termenv@v0.13.0?package-id=25129a1d82c81f6f",
134417          "supplier": {},
134418          "name": "github.com/muesli/termenv",
134419          "version": "v0.13.0",
134420          "cpe": "cpe:2.3:a:muesli:termenv:v0.13.0:*:*:*:*:*:*:*",
134421          "purl": "pkg:golang/github.com/muesli/termenv@v0.13.0",
134422          "swid": {
134423            "attachment": {}
134424          },
134425          "pedigree": {},
134426          "evidence": {},
134427          "signature": {
134428            "signature": {
134429              "publicKey": {}
134430            }
134431          },
134432          "modelCard": {
134433            "modelParameters": {
134434              "approach": {}
134435            },
134436            "quantitativeAnalysis": {
134437              "graphics": {}
134438            },
134439            "considerations": {}
134440          }
134441        },
134442        {
134443          "type": "library",
134444          "bom-ref": "pkg:golang/github.com/nats-io/nats.go@v1.17.0?package-id=640d5430ff164098",
134445          "supplier": {},
134446          "name": "github.com/nats-io/nats.go",
134447          "version": "v1.17.0",
134448          "cpe": "cpe:2.3:a:nats-io:nats.go:v1.17.0:*:*:*:*:*:*:*",
134449          "purl": "pkg:golang/github.com/nats-io/nats.go@v1.17.0",
134450          "swid": {
134451            "attachment": {}
134452          },
134453          "pedigree": {},
134454          "evidence": {},
134455          "signature": {
134456            "signature": {
134457              "publicKey": {}
134458            }
134459          },
134460          "modelCard": {
134461            "modelParameters": {
134462              "approach": {}
134463            },
134464            "quantitativeAnalysis": {
134465              "graphics": {}
134466            },
134467            "considerations": {}
134468          }
134469        },
134470        {
134471          "type": "library",
134472          "bom-ref": "pkg:golang/github.com/nats-io/nkeys@v0.3.0?package-id=893eac853a9c985c",
134473          "supplier": {},
134474          "name": "github.com/nats-io/nkeys",
134475          "version": "v0.3.0",
134476          "cpe": "cpe:2.3:a:nats-io:nkeys:v0.3.0:*:*:*:*:*:*:*",
134477          "purl": "pkg:golang/github.com/nats-io/nkeys@v0.3.0",
134478          "swid": {
134479            "attachment": {}
134480          },
134481          "pedigree": {},
134482          "evidence": {},
134483          "signature": {
134484            "signature": {
134485              "publicKey": {}
134486            }
134487          },
134488          "modelCard": {
134489            "modelParameters": {
134490              "approach": {}
134491            },
134492            "quantitativeAnalysis": {
134493              "graphics": {}
134494            },
134495            "considerations": {}
134496          }
134497        },
134498        {
134499          "type": "library",
134500          "bom-ref": "pkg:golang/github.com/nats-io/nuid@v1.0.1?package-id=eb7f4076b95a07f1",
134501          "supplier": {},
134502          "name": "github.com/nats-io/nuid",
134503          "version": "v1.0.1",
134504          "cpe": "cpe:2.3:a:nats-io:nuid:v1.0.1:*:*:*:*:*:*:*",
134505          "purl": "pkg:golang/github.com/nats-io/nuid@v1.0.1",
134506          "swid": {
134507            "attachment": {}
134508          },
134509          "pedigree": {},
134510          "evidence": {},
134511          "signature": {
134512            "signature": {
134513              "publicKey": {}
134514            }
134515          },
134516          "modelCard": {
134517            "modelParameters": {
134518              "approach": {}
134519            },
134520            "quantitativeAnalysis": {
134521              "graphics": {}
134522            },
134523            "considerations": {}
134524          }
134525        },
134526        {
134527          "type": "library",
134528          "bom-ref": "pkg:golang/github.com/nats-io/stan.go@v0.10.3?package-id=f17c8472825c9114",
134529          "supplier": {},
134530          "name": "github.com/nats-io/stan.go",
134531          "version": "v0.10.3",
134532          "cpe": "cpe:2.3:a:nats-io:stan.go:v0.10.3:*:*:*:*:*:*:*",
134533          "purl": "pkg:golang/github.com/nats-io/stan.go@v0.10.3",
134534          "swid": {
134535            "attachment": {}
134536          },
134537          "pedigree": {},
134538          "evidence": {},
134539          "signature": {
134540            "signature": {
134541              "publicKey": {}
134542            }
134543          },
134544          "modelCard": {
134545            "modelParameters": {
134546              "approach": {}
134547            },
134548            "quantitativeAnalysis": {
134549              "graphics": {}
134550            },
134551            "considerations": {}
134552          }
134553        },
134554        {
134555          "type": "library",
134556          "bom-ref": "pkg:golang/github.com/navidys/tvxwidgets@v0.1.1?package-id=5126c2602f9159eb",
134557          "supplier": {},
134558          "name": "github.com/navidys/tvxwidgets",
134559          "version": "v0.1.1",
134560          "cpe": "cpe:2.3:a:navidys:tvxwidgets:v0.1.1:*:*:*:*:*:*:*",
134561          "purl": "pkg:golang/github.com/navidys/tvxwidgets@v0.1.1",
134562          "swid": {
134563            "attachment": {}
134564          },
134565          "pedigree": {},
134566          "evidence": {},
134567          "signature": {
134568            "signature": {
134569              "publicKey": {}
134570            }
134571          },
134572          "modelCard": {
134573            "modelParameters": {
134574              "approach": {}
134575            },
134576            "quantitativeAnalysis": {
134577              "graphics": {}
134578            },
134579            "considerations": {}
134580          }
134581        },
134582        {
134583          "type": "library",
134584          "bom-ref": "pkg:golang/github.com/ncw/directio@v1.0.5?package-id=dede4e750f761443",
134585          "supplier": {},
134586          "name": "github.com/ncw/directio",
134587          "version": "v1.0.5",
134588          "cpe": "cpe:2.3:a:ncw:directio:v1.0.5:*:*:*:*:*:*:*",
134589          "purl": "pkg:golang/github.com/ncw/directio@v1.0.5",
134590          "swid": {
134591            "attachment": {}
134592          },
134593          "pedigree": {},
134594          "evidence": {},
134595          "signature": {
134596            "signature": {
134597              "publicKey": {}
134598            }
134599          },
134600          "modelCard": {
134601            "modelParameters": {
134602              "approach": {}
134603            },
134604            "quantitativeAnalysis": {
134605              "graphics": {}
134606            },
134607            "considerations": {}
134608          }
134609        },
134610        {
134611          "type": "library",
134612          "bom-ref": "pkg:golang/github.com/nsqio/go-nsq@v1.1.0?package-id=5ba1c642f575a1c6",
134613          "supplier": {},
134614          "name": "github.com/nsqio/go-nsq",
134615          "version": "v1.1.0",
134616          "cpe": "cpe:2.3:a:nsqio:go-nsq:v1.1.0:*:*:*:*:*:*:*",
134617          "purl": "pkg:golang/github.com/nsqio/go-nsq@v1.1.0",
134618          "swid": {
134619            "attachment": {}
134620          },
134621          "pedigree": {},
134622          "evidence": {},
134623          "signature": {
134624            "signature": {
134625              "publicKey": {}
134626            }
134627          },
134628          "modelCard": {
134629            "modelParameters": {
134630              "approach": {}
134631            },
134632            "quantitativeAnalysis": {
134633              "graphics": {}
134634            },
134635            "considerations": {}
134636          }
134637        },
134638        {
134639          "type": "library",
134640          "bom-ref": "pkg:golang/github.com/oklog/ulid@v1.3.1?package-id=384d1eb89472b23b",
134641          "supplier": {},
134642          "name": "github.com/oklog/ulid",
134643          "version": "v1.3.1",
134644          "cpe": "cpe:2.3:a:oklog:ulid:v1.3.1:*:*:*:*:*:*:*",
134645          "purl": "pkg:golang/github.com/oklog/ulid@v1.3.1",
134646          "swid": {
134647            "attachment": {}
134648          },
134649          "pedigree": {},
134650          "evidence": {},
134651          "signature": {
134652            "signature": {
134653              "publicKey": {}
134654            }
134655          },
134656          "modelCard": {
134657            "modelParameters": {
134658              "approach": {}
134659            },
134660            "quantitativeAnalysis": {
134661              "graphics": {}
134662            },
134663            "considerations": {}
134664          }
134665        },
134666        {
134667          "type": "library",
134668          "bom-ref": "pkg:golang/github.com/olekukonko/tablewriter@v0.0.5?package-id=67f04e6754207444",
134669          "supplier": {},
134670          "name": "github.com/olekukonko/tablewriter",
134671          "version": "v0.0.5",
134672          "cpe": "cpe:2.3:a:olekukonko:tablewriter:v0.0.5:*:*:*:*:*:*:*",
134673          "purl": "pkg:golang/github.com/olekukonko/tablewriter@v0.0.5",
134674          "swid": {
134675            "attachment": {}
134676          },
134677          "pedigree": {},
134678          "evidence": {},
134679          "signature": {
134680            "signature": {
134681              "publicKey": {}
134682            }
134683          },
134684          "modelCard": {
134685            "modelParameters": {
134686              "approach": {}
134687            },
134688            "quantitativeAnalysis": {
134689              "graphics": {}
134690            },
134691            "considerations": {}
134692          }
134693        },
134694        {
134695          "type": "library",
134696          "bom-ref": "pkg:golang/github.com/philhofer/fwd@v1.1.2-0.20210722190033-5c56ac6d0bb9?package-id=83e3b2226b39ae9e",
134697          "supplier": {},
134698          "name": "github.com/philhofer/fwd",
134699          "version": "v1.1.2-0.20210722190033-5c56ac6d0bb9",
134700          "cpe": "cpe:2.3:a:philhofer:fwd:v1.1.2-0.20210722190033-5c56ac6d0bb9:*:*:*:*:*:*:*",
134701          "purl": "pkg:golang/github.com/philhofer/fwd@v1.1.2-0.20210722190033-5c56ac6d0bb9",
134702          "swid": {
134703            "attachment": {}
134704          },
134705          "pedigree": {},
134706          "evidence": {},
134707          "signature": {
134708            "signature": {
134709              "publicKey": {}
134710            }
134711          },
134712          "modelCard": {
134713            "modelParameters": {
134714              "approach": {}
134715            },
134716            "quantitativeAnalysis": {
134717              "graphics": {}
134718            },
134719            "considerations": {}
134720          }
134721        },
134722        {
134723          "type": "library",
134724          "bom-ref": "pkg:golang/github.com/pierrec/lz4@v2.6.1+incompatible?package-id=65e3f6f155289db2",
134725          "supplier": {},
134726          "name": "github.com/pierrec/lz4",
134727          "version": "v2.6.1+incompatible",
134728          "cpe": "cpe:2.3:a:pierrec:lz4:v2.6.1\\+incompatible:*:*:*:*:*:*:*",
134729          "purl": "pkg:golang/github.com/pierrec/lz4@v2.6.1+incompatible",
134730          "swid": {
134731            "attachment": {}
134732          },
134733          "pedigree": {},
134734          "evidence": {},
134735          "signature": {
134736            "signature": {
134737              "publicKey": {}
134738            }
134739          },
134740          "modelCard": {
134741            "modelParameters": {
134742              "approach": {}
134743            },
134744            "quantitativeAnalysis": {
134745              "graphics": {}
134746            },
134747            "considerations": {}
134748          }
134749        },
134750        {
134751          "type": "library",
134752          "bom-ref": "pkg:golang/github.com/pierrec/lz4/v4@v4.1.16?package-id=7681fc3e98abb772",
134753          "supplier": {},
134754          "name": "github.com/pierrec/lz4/v4",
134755          "version": "v4.1.16",
134756          "cpe": "cpe:2.3:a:pierrec:lz4\\/v4:v4.1.16:*:*:*:*:*:*:*",
134757          "purl": "pkg:golang/github.com/pierrec/lz4/v4@v4.1.16",
134758          "swid": {
134759            "attachment": {}
134760          },
134761          "pedigree": {},
134762          "evidence": {},
134763          "signature": {
134764            "signature": {
134765              "publicKey": {}
134766            }
134767          },
134768          "modelCard": {
134769            "modelParameters": {
134770              "approach": {}
134771            },
134772            "quantitativeAnalysis": {
134773              "graphics": {}
134774            },
134775            "considerations": {}
134776          }
134777        },
134778        {
134779          "type": "library",
134780          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.9.1?package-id=b59b087b0bcec3cd",
134781          "supplier": {},
134782          "name": "github.com/pkg/errors",
134783          "version": "v0.9.1",
134784          "cpe": "cpe:2.3:a:pkg:errors:v0.9.1:*:*:*:*:*:*:*",
134785          "purl": "pkg:golang/github.com/pkg/errors@v0.9.1",
134786          "swid": {
134787            "attachment": {}
134788          },
134789          "pedigree": {},
134790          "evidence": {},
134791          "signature": {
134792            "signature": {
134793              "publicKey": {}
134794            }
134795          },
134796          "modelCard": {
134797            "modelParameters": {
134798              "approach": {}
134799            },
134800            "quantitativeAnalysis": {
134801              "graphics": {}
134802            },
134803            "considerations": {}
134804          }
134805        },
134806        {
134807          "type": "library",
134808          "bom-ref": "pkg:golang/github.com/pkg/xattr@v0.4.9?package-id=e0156666041288e4",
134809          "supplier": {},
134810          "name": "github.com/pkg/xattr",
134811          "version": "v0.4.9",
134812          "cpe": "cpe:2.3:a:pkg:xattr:v0.4.9:*:*:*:*:*:*:*",
134813          "purl": "pkg:golang/github.com/pkg/xattr@v0.4.9",
134814          "swid": {
134815            "attachment": {}
134816          },
134817          "pedigree": {},
134818          "evidence": {},
134819          "signature": {
134820            "signature": {
134821              "publicKey": {}
134822            }
134823          },
134824          "modelCard": {
134825            "modelParameters": {
134826              "approach": {}
134827            },
134828            "quantitativeAnalysis": {
134829              "graphics": {}
134830            },
134831            "considerations": {}
134832          }
134833        },
134834        {
134835          "type": "library",
134836          "bom-ref": "pkg:golang/github.com/posener/complete@v1.2.3?package-id=a7929153b1b58436",
134837          "supplier": {},
134838          "name": "github.com/posener/complete",
134839          "version": "v1.2.3",
134840          "cpe": "cpe:2.3:a:posener:complete:v1.2.3:*:*:*:*:*:*:*",
134841          "purl": "pkg:golang/github.com/posener/complete@v1.2.3",
134842          "swid": {
134843            "attachment": {}
134844          },
134845          "pedigree": {},
134846          "evidence": {},
134847          "signature": {
134848            "signature": {
134849              "publicKey": {}
134850            }
134851          },
134852          "modelCard": {
134853            "modelParameters": {
134854              "approach": {}
134855            },
134856            "quantitativeAnalysis": {
134857              "graphics": {}
134858            },
134859            "considerations": {}
134860          }
134861        },
134862        {
134863          "type": "library",
134864          "bom-ref": "pkg:golang/github.com/pquerna/cachecontrol@v0.1.0?package-id=66f9fd0136788fad",
134865          "supplier": {},
134866          "name": "github.com/pquerna/cachecontrol",
134867          "version": "v0.1.0",
134868          "cpe": "cpe:2.3:a:pquerna:cachecontrol:v0.1.0:*:*:*:*:*:*:*",
134869          "purl": "pkg:golang/github.com/pquerna/cachecontrol@v0.1.0",
134870          "swid": {
134871            "attachment": {}
134872          },
134873          "pedigree": {},
134874          "evidence": {},
134875          "signature": {
134876            "signature": {
134877              "publicKey": {}
134878            }
134879          },
134880          "modelCard": {
134881            "modelParameters": {
134882              "approach": {}
134883            },
134884            "quantitativeAnalysis": {
134885              "graphics": {}
134886            },
134887            "considerations": {}
134888          }
134889        },
134890        {
134891          "type": "library",
134892          "bom-ref": "pkg:golang/github.com/prometheus/client_golang@v1.13.0?package-id=79fe73fdebf06609",
134893          "supplier": {},
134894          "name": "github.com/prometheus/client_golang",
134895          "version": "v1.13.0",
134896          "cpe": "cpe:2.3:a:prometheus:client-golang:v1.13.0:*:*:*:*:*:*:*",
134897          "purl": "pkg:golang/github.com/prometheus/client_golang@v1.13.0",
134898          "swid": {
134899            "attachment": {}
134900          },
134901          "pedigree": {},
134902          "evidence": {},
134903          "signature": {
134904            "signature": {
134905              "publicKey": {}
134906            }
134907          },
134908          "modelCard": {
134909            "modelParameters": {
134910              "approach": {}
134911            },
134912            "quantitativeAnalysis": {
134913              "graphics": {}
134914            },
134915            "considerations": {}
134916          }
134917        },
134918        {
134919          "type": "library",
134920          "bom-ref": "pkg:golang/github.com/prometheus/client_model@v0.3.0?package-id=f610d8cc39a3c3f7",
134921          "supplier": {},
134922          "name": "github.com/prometheus/client_model",
134923          "version": "v0.3.0",
134924          "cpe": "cpe:2.3:a:prometheus:client-model:v0.3.0:*:*:*:*:*:*:*",
134925          "purl": "pkg:golang/github.com/prometheus/client_model@v0.3.0",
134926          "swid": {
134927            "attachment": {}
134928          },
134929          "pedigree": {},
134930          "evidence": {},
134931          "signature": {
134932            "signature": {
134933              "publicKey": {}
134934            }
134935          },
134936          "modelCard": {
134937            "modelParameters": {
134938              "approach": {}
134939            },
134940            "quantitativeAnalysis": {
134941              "graphics": {}
134942            },
134943            "considerations": {}
134944          }
134945        },
134946        {
134947          "type": "library",
134948          "bom-ref": "pkg:golang/github.com/prometheus/common@v0.37.0?package-id=6952570f7536ecfd",
134949          "supplier": {},
134950          "name": "github.com/prometheus/common",
134951          "version": "v0.37.0",
134952          "cpe": "cpe:2.3:a:prometheus:common:v0.37.0:*:*:*:*:*:*:*",
134953          "purl": "pkg:golang/github.com/prometheus/common@v0.37.0",
134954          "swid": {
134955            "attachment": {}
134956          },
134957          "pedigree": {},
134958          "evidence": {},
134959          "signature": {
134960            "signature": {
134961              "publicKey": {}
134962            }
134963          },
134964          "modelCard": {
134965            "modelParameters": {
134966              "approach": {}
134967            },
134968            "quantitativeAnalysis": {
134969              "graphics": {}
134970            },
134971            "considerations": {}
134972          }
134973        },
134974        {
134975          "type": "library",
134976          "bom-ref": "pkg:golang/github.com/prometheus/procfs@v0.8.0?package-id=f09878d83a91b212",
134977          "supplier": {},
134978          "name": "github.com/prometheus/procfs",
134979          "version": "v0.8.0",
134980          "cpe": "cpe:2.3:a:prometheus:procfs:v0.8.0:*:*:*:*:*:*:*",
134981          "purl": "pkg:golang/github.com/prometheus/procfs@v0.8.0",
134982          "swid": {
134983            "attachment": {}
134984          },
134985          "pedigree": {},
134986          "evidence": {},
134987          "signature": {
134988            "signature": {
134989              "publicKey": {}
134990            }
134991          },
134992          "modelCard": {
134993            "modelParameters": {
134994              "approach": {}
134995            },
134996            "quantitativeAnalysis": {
134997              "graphics": {}
134998            },
134999            "considerations": {}
135000          }
135001        },
135002        {
135003          "type": "library",
135004          "bom-ref": "pkg:golang/github.com/prometheus/prom2json@v1.3.2?package-id=67d1cce2adfb2bd5",
135005          "supplier": {},
135006          "name": "github.com/prometheus/prom2json",
135007          "version": "v1.3.2",
135008          "cpe": "cpe:2.3:a:prometheus:prom2json:v1.3.2:*:*:*:*:*:*:*",
135009          "purl": "pkg:golang/github.com/prometheus/prom2json@v1.3.2",
135010          "swid": {
135011            "attachment": {}
135012          },
135013          "pedigree": {},
135014          "evidence": {},
135015          "signature": {
135016            "signature": {
135017              "publicKey": {}
135018            }
135019          },
135020          "modelCard": {
135021            "modelParameters": {
135022              "approach": {}
135023            },
135024            "quantitativeAnalysis": {
135025              "graphics": {}
135026            },
135027            "considerations": {}
135028          }
135029        },
135030        {
135031          "type": "library",
135032          "bom-ref": "pkg:golang/github.com/rcrowley/go-metrics@v0.0.0-20201227073835-cf1acfcdf475?package-id=1dae6fa258b736cd",
135033          "supplier": {},
135034          "name": "github.com/rcrowley/go-metrics",
135035          "version": "v0.0.0-20201227073835-cf1acfcdf475",
135036          "cpe": "cpe:2.3:a:rcrowley:go-metrics:v0.0.0-20201227073835-cf1acfcdf475:*:*:*:*:*:*:*",
135037          "purl": "pkg:golang/github.com/rcrowley/go-metrics@v0.0.0-20201227073835-cf1acfcdf475",
135038          "swid": {
135039            "attachment": {}
135040          },
135041          "pedigree": {},
135042          "evidence": {},
135043          "signature": {
135044            "signature": {
135045              "publicKey": {}
135046            }
135047          },
135048          "modelCard": {
135049            "modelParameters": {
135050              "approach": {}
135051            },
135052            "quantitativeAnalysis": {
135053              "graphics": {}
135054            },
135055            "considerations": {}
135056          }
135057        },
135058        {
135059          "type": "library",
135060          "bom-ref": "pkg:golang/github.com/rivo/tview@v0.0.0-20220916081518-2e69b7385a37?package-id=c696487ebea8f484",
135061          "supplier": {},
135062          "name": "github.com/rivo/tview",
135063          "version": "v0.0.0-20220916081518-2e69b7385a37",
135064          "cpe": "cpe:2.3:a:rivo:tview:v0.0.0-20220916081518-2e69b7385a37:*:*:*:*:*:*:*",
135065          "purl": "pkg:golang/github.com/rivo/tview@v0.0.0-20220916081518-2e69b7385a37",
135066          "swid": {
135067            "attachment": {}
135068          },
135069          "pedigree": {},
135070          "evidence": {},
135071          "signature": {
135072            "signature": {
135073              "publicKey": {}
135074            }
135075          },
135076          "modelCard": {
135077            "modelParameters": {
135078              "approach": {}
135079            },
135080            "quantitativeAnalysis": {
135081              "graphics": {}
135082            },
135083            "considerations": {}
135084          }
135085        },
135086        {
135087          "type": "library",
135088          "bom-ref": "pkg:golang/github.com/rivo/uniseg@v0.4.2?package-id=43bb8239eb813ed6",
135089          "supplier": {},
135090          "name": "github.com/rivo/uniseg",
135091          "version": "v0.4.2",
135092          "cpe": "cpe:2.3:a:rivo:uniseg:v0.4.2:*:*:*:*:*:*:*",
135093          "purl": "pkg:golang/github.com/rivo/uniseg@v0.4.2",
135094          "swid": {
135095            "attachment": {}
135096          },
135097          "pedigree": {},
135098          "evidence": {},
135099          "signature": {
135100            "signature": {
135101              "publicKey": {}
135102            }
135103          },
135104          "modelCard": {
135105            "modelParameters": {
135106              "approach": {}
135107            },
135108            "quantitativeAnalysis": {
135109              "graphics": {}
135110            },
135111            "considerations": {}
135112          }
135113        },
135114        {
135115          "type": "library",
135116          "bom-ref": "pkg:golang/github.com/rjeczalik/notify@v0.9.2?package-id=da0718f2516e3fd6",
135117          "supplier": {},
135118          "name": "github.com/rjeczalik/notify",
135119          "version": "v0.9.2",
135120          "cpe": "cpe:2.3:a:rjeczalik:notify:v0.9.2:*:*:*:*:*:*:*",
135121          "purl": "pkg:golang/github.com/rjeczalik/notify@v0.9.2",
135122          "swid": {
135123            "attachment": {}
135124          },
135125          "pedigree": {},
135126          "evidence": {},
135127          "signature": {
135128            "signature": {
135129              "publicKey": {}
135130            }
135131          },
135132          "modelCard": {
135133            "modelParameters": {
135134              "approach": {}
135135            },
135136            "quantitativeAnalysis": {
135137              "graphics": {}
135138            },
135139            "considerations": {}
135140          }
135141        },
135142        {
135143          "type": "library",
135144          "bom-ref": "pkg:golang/github.com/rs/cors@v1.8.2?package-id=bd20ccd8c9475b31",
135145          "supplier": {},
135146          "name": "github.com/rs/cors",
135147          "version": "v1.8.2",
135148          "cpe": "cpe:2.3:a:rs:cors:v1.8.2:*:*:*:*:*:*:*",
135149          "purl": "pkg:golang/github.com/rs/cors@v1.8.2",
135150          "swid": {
135151            "attachment": {}
135152          },
135153          "pedigree": {},
135154          "evidence": {},
135155          "signature": {
135156            "signature": {
135157              "publicKey": {}
135158            }
135159          },
135160          "modelCard": {
135161            "modelParameters": {
135162              "approach": {}
135163            },
135164            "quantitativeAnalysis": {
135165              "graphics": {}
135166            },
135167            "considerations": {}
135168          }
135169        },
135170        {
135171          "type": "library",
135172          "bom-ref": "pkg:golang/github.com/rs/dnscache@v0.0.0-20211102005908-e0241e321417?package-id=e6111a9b0a034650",
135173          "supplier": {},
135174          "name": "github.com/rs/dnscache",
135175          "version": "v0.0.0-20211102005908-e0241e321417",
135176          "cpe": "cpe:2.3:a:rs:dnscache:v0.0.0-20211102005908-e0241e321417:*:*:*:*:*:*:*",
135177          "purl": "pkg:golang/github.com/rs/dnscache@v0.0.0-20211102005908-e0241e321417",
135178          "swid": {
135179            "attachment": {}
135180          },
135181          "pedigree": {},
135182          "evidence": {},
135183          "signature": {
135184            "signature": {
135185              "publicKey": {}
135186            }
135187          },
135188          "modelCard": {
135189            "modelParameters": {
135190              "approach": {}
135191            },
135192            "quantitativeAnalysis": {
135193              "graphics": {}
135194            },
135195            "considerations": {}
135196          }
135197        },
135198        {
135199          "type": "library",
135200          "bom-ref": "pkg:golang/github.com/rs/xid@v1.4.0?package-id=81dde1457c97301f",
135201          "supplier": {},
135202          "name": "github.com/rs/xid",
135203          "version": "v1.4.0",
135204          "cpe": "cpe:2.3:a:rs:xid:v1.4.0:*:*:*:*:*:*:*",
135205          "purl": "pkg:golang/github.com/rs/xid@v1.4.0",
135206          "swid": {
135207            "attachment": {}
135208          },
135209          "pedigree": {},
135210          "evidence": {},
135211          "signature": {
135212            "signature": {
135213              "publicKey": {}
135214            }
135215          },
135216          "modelCard": {
135217            "modelParameters": {
135218              "approach": {}
135219            },
135220            "quantitativeAnalysis": {
135221              "graphics": {}
135222            },
135223            "considerations": {}
135224          }
135225        },
135226        {
135227          "type": "library",
135228          "bom-ref": "pkg:golang/github.com/secure-io/sio-go@v0.3.1?package-id=4cb7db61685ad864",
135229          "supplier": {},
135230          "name": "github.com/secure-io/sio-go",
135231          "version": "v0.3.1",
135232          "cpe": "cpe:2.3:a:secure-io:sio-go:v0.3.1:*:*:*:*:*:*:*",
135233          "purl": "pkg:golang/github.com/secure-io/sio-go@v0.3.1",
135234          "swid": {
135235            "attachment": {}
135236          },
135237          "pedigree": {},
135238          "evidence": {},
135239          "signature": {
135240            "signature": {
135241              "publicKey": {}
135242            }
135243          },
135244          "modelCard": {
135245            "modelParameters": {
135246              "approach": {}
135247            },
135248            "quantitativeAnalysis": {
135249              "graphics": {}
135250            },
135251            "considerations": {}
135252          }
135253        },
135254        {
135255          "type": "library",
135256          "bom-ref": "pkg:golang/github.com/shirou/gopsutil/v3@v3.22.9?package-id=1457e1667c521674",
135257          "supplier": {},
135258          "name": "github.com/shirou/gopsutil/v3",
135259          "version": "v3.22.9",
135260          "cpe": "cpe:2.3:a:shirou:gopsutil\\/v3:v3.22.9:*:*:*:*:*:*:*",
135261          "purl": "pkg:golang/github.com/shirou/gopsutil/v3@v3.22.9",
135262          "swid": {
135263            "attachment": {}
135264          },
135265          "pedigree": {},
135266          "evidence": {},
135267          "signature": {
135268            "signature": {
135269              "publicKey": {}
135270            }
135271          },
135272          "modelCard": {
135273            "modelParameters": {
135274              "approach": {}
135275            },
135276            "quantitativeAnalysis": {
135277              "graphics": {}
135278            },
135279            "considerations": {}
135280          }
135281        },
135282        {
135283          "type": "library",
135284          "bom-ref": "pkg:golang/github.com/streadway/amqp@v1.0.0?package-id=4e1db82c5daa44db",
135285          "supplier": {},
135286          "name": "github.com/streadway/amqp",
135287          "version": "v1.0.0",
135288          "cpe": "cpe:2.3:a:streadway:amqp:v1.0.0:*:*:*:*:*:*:*",
135289          "purl": "pkg:golang/github.com/streadway/amqp@v1.0.0",
135290          "swid": {
135291            "attachment": {}
135292          },
135293          "pedigree": {},
135294          "evidence": {},
135295          "signature": {
135296            "signature": {
135297              "publicKey": {}
135298            }
135299          },
135300          "modelCard": {
135301            "modelParameters": {
135302              "approach": {}
135303            },
135304            "quantitativeAnalysis": {
135305              "graphics": {}
135306            },
135307            "considerations": {}
135308          }
135309        },
135310        {
135311          "type": "library",
135312          "bom-ref": "pkg:golang/github.com/tidwall/gjson@v1.14.3?package-id=a1c2ecd7b6817e0",
135313          "supplier": {},
135314          "name": "github.com/tidwall/gjson",
135315          "version": "v1.14.3",
135316          "cpe": "cpe:2.3:a:tidwall:gjson:v1.14.3:*:*:*:*:*:*:*",
135317          "purl": "pkg:golang/github.com/tidwall/gjson@v1.14.3",
135318          "swid": {
135319            "attachment": {}
135320          },
135321          "pedigree": {},
135322          "evidence": {},
135323          "signature": {
135324            "signature": {
135325              "publicKey": {}
135326            }
135327          },
135328          "modelCard": {
135329            "modelParameters": {
135330              "approach": {}
135331            },
135332            "quantitativeAnalysis": {
135333              "graphics": {}
135334            },
135335            "considerations": {}
135336          }
135337        },
135338        {
135339          "type": "library",
135340          "bom-ref": "pkg:golang/github.com/tidwall/match@v1.1.1?package-id=6ea60cd9db5c58cb",
135341          "supplier": {},
135342          "name": "github.com/tidwall/match",
135343          "version": "v1.1.1",
135344          "cpe": "cpe:2.3:a:tidwall:match:v1.1.1:*:*:*:*:*:*:*",
135345          "purl": "pkg:golang/github.com/tidwall/match@v1.1.1",
135346          "swid": {
135347            "attachment": {}
135348          },
135349          "pedigree": {},
135350          "evidence": {},
135351          "signature": {
135352            "signature": {
135353              "publicKey": {}
135354            }
135355          },
135356          "modelCard": {
135357            "modelParameters": {
135358              "approach": {}
135359            },
135360            "quantitativeAnalysis": {
135361              "graphics": {}
135362            },
135363            "considerations": {}
135364          }
135365        },
135366        {
135367          "type": "library",
135368          "bom-ref": "pkg:golang/github.com/tidwall/pretty@v1.2.1?package-id=a204091cd5a4e6f9",
135369          "supplier": {},
135370          "name": "github.com/tidwall/pretty",
135371          "version": "v1.2.1",
135372          "cpe": "cpe:2.3:a:tidwall:pretty:v1.2.1:*:*:*:*:*:*:*",
135373          "purl": "pkg:golang/github.com/tidwall/pretty@v1.2.1",
135374          "swid": {
135375            "attachment": {}
135376          },
135377          "pedigree": {},
135378          "evidence": {},
135379          "signature": {
135380            "signature": {
135381              "publicKey": {}
135382            }
135383          },
135384          "modelCard": {
135385            "modelParameters": {
135386              "approach": {}
135387            },
135388            "quantitativeAnalysis": {
135389              "graphics": {}
135390            },
135391            "considerations": {}
135392          }
135393        },
135394        {
135395          "type": "library",
135396          "bom-ref": "pkg:golang/github.com/tinylib/msgp@v1.1.7-0.20220719154719-f3635b96e483?package-id=5c000c0cab1afbd1",
135397          "supplier": {},
135398          "name": "github.com/tinylib/msgp",
135399          "version": "v1.1.7-0.20220719154719-f3635b96e483",
135400          "cpe": "cpe:2.3:a:tinylib:msgp:v1.1.7-0.20220719154719-f3635b96e483:*:*:*:*:*:*:*",
135401          "purl": "pkg:golang/github.com/tinylib/msgp@v1.1.7-0.20220719154719-f3635b96e483",
135402          "swid": {
135403            "attachment": {}
135404          },
135405          "pedigree": {},
135406          "evidence": {},
135407          "signature": {
135408            "signature": {
135409              "publicKey": {}
135410            }
135411          },
135412          "modelCard": {
135413            "modelParameters": {
135414              "approach": {}
135415            },
135416            "quantitativeAnalysis": {
135417              "graphics": {}
135418            },
135419            "considerations": {}
135420          }
135421        },
135422        {
135423          "type": "library",
135424          "bom-ref": "pkg:golang/github.com/tklauser/go-sysconf@v0.3.10?package-id=a15c15c0099921b0",
135425          "supplier": {},
135426          "name": "github.com/tklauser/go-sysconf",
135427          "version": "v0.3.10",
135428          "cpe": "cpe:2.3:a:tklauser:go-sysconf:v0.3.10:*:*:*:*:*:*:*",
135429          "purl": "pkg:golang/github.com/tklauser/go-sysconf@v0.3.10",
135430          "swid": {
135431            "attachment": {}
135432          },
135433          "pedigree": {},
135434          "evidence": {},
135435          "signature": {
135436            "signature": {
135437              "publicKey": {}
135438            }
135439          },
135440          "modelCard": {
135441            "modelParameters": {
135442              "approach": {}
135443            },
135444            "quantitativeAnalysis": {
135445              "graphics": {}
135446            },
135447            "considerations": {}
135448          }
135449        },
135450        {
135451          "type": "library",
135452          "bom-ref": "pkg:golang/github.com/tklauser/numcpus@v0.5.0?package-id=8a36de772e52c0ce",
135453          "supplier": {},
135454          "name": "github.com/tklauser/numcpus",
135455          "version": "v0.5.0",
135456          "cpe": "cpe:2.3:a:tklauser:numcpus:v0.5.0:*:*:*:*:*:*:*",
135457          "purl": "pkg:golang/github.com/tklauser/numcpus@v0.5.0",
135458          "swid": {
135459            "attachment": {}
135460          },
135461          "pedigree": {},
135462          "evidence": {},
135463          "signature": {
135464            "signature": {
135465              "publicKey": {}
135466            }
135467          },
135468          "modelCard": {
135469            "modelParameters": {
135470              "approach": {}
135471            },
135472            "quantitativeAnalysis": {
135473              "graphics": {}
135474            },
135475            "considerations": {}
135476          }
135477        },
135478        {
135479          "type": "library",
135480          "bom-ref": "pkg:golang/github.com/unrolled/secure@v1.13.0?package-id=f350d5676a6b3004",
135481          "supplier": {},
135482          "name": "github.com/unrolled/secure",
135483          "version": "v1.13.0",
135484          "cpe": "cpe:2.3:a:unrolled:secure:v1.13.0:*:*:*:*:*:*:*",
135485          "purl": "pkg:golang/github.com/unrolled/secure@v1.13.0",
135486          "swid": {
135487            "attachment": {}
135488          },
135489          "pedigree": {},
135490          "evidence": {},
135491          "signature": {
135492            "signature": {
135493              "publicKey": {}
135494            }
135495          },
135496          "modelCard": {
135497            "modelParameters": {
135498              "approach": {}
135499            },
135500            "quantitativeAnalysis": {
135501              "graphics": {}
135502            },
135503            "considerations": {}
135504          }
135505        },
135506        {
135507          "type": "library",
135508          "bom-ref": "pkg:golang/github.com/valyala/bytebufferpool@v1.0.0?package-id=c9d6a4f69f00560",
135509          "supplier": {},
135510          "name": "github.com/valyala/bytebufferpool",
135511          "version": "v1.0.0",
135512          "cpe": "cpe:2.3:a:valyala:bytebufferpool:v1.0.0:*:*:*:*:*:*:*",
135513          "purl": "pkg:golang/github.com/valyala/bytebufferpool@v1.0.0",
135514          "swid": {
135515            "attachment": {}
135516          },
135517          "pedigree": {},
135518          "evidence": {},
135519          "signature": {
135520            "signature": {
135521              "publicKey": {}
135522            }
135523          },
135524          "modelCard": {
135525            "modelParameters": {
135526              "approach": {}
135527            },
135528            "quantitativeAnalysis": {
135529              "graphics": {}
135530            },
135531            "considerations": {}
135532          }
135533        },
135534        {
135535          "type": "library",
135536          "bom-ref": "pkg:golang/github.com/xdg/scram@v1.0.5?package-id=a5e952780a4be5dc",
135537          "supplier": {},
135538          "name": "github.com/xdg/scram",
135539          "version": "v1.0.5",
135540          "cpe": "cpe:2.3:a:xdg:scram:v1.0.5:*:*:*:*:*:*:*",
135541          "purl": "pkg:golang/github.com/xdg/scram@v1.0.5",
135542          "swid": {
135543            "attachment": {}
135544          },
135545          "pedigree": {},
135546          "evidence": {},
135547          "signature": {
135548            "signature": {
135549              "publicKey": {}
135550            }
135551          },
135552          "modelCard": {
135553            "modelParameters": {
135554              "approach": {}
135555            },
135556            "quantitativeAnalysis": {
135557              "graphics": {}
135558            },
135559            "considerations": {}
135560          }
135561        },
135562        {
135563          "type": "library",
135564          "bom-ref": "pkg:golang/github.com/xdg/stringprep@v1.0.3?package-id=6d37402a60f0fd30",
135565          "supplier": {},
135566          "name": "github.com/xdg/stringprep",
135567          "version": "v1.0.3",
135568          "cpe": "cpe:2.3:a:xdg:stringprep:v1.0.3:*:*:*:*:*:*:*",
135569          "purl": "pkg:golang/github.com/xdg/stringprep@v1.0.3",
135570          "swid": {
135571            "attachment": {}
135572          },
135573          "pedigree": {},
135574          "evidence": {},
135575          "signature": {
135576            "signature": {
135577              "publicKey": {}
135578            }
135579          },
135580          "modelCard": {
135581            "modelParameters": {
135582              "approach": {}
135583            },
135584            "quantitativeAnalysis": {
135585              "graphics": {}
135586            },
135587            "considerations": {}
135588          }
135589        },
135590        {
135591          "type": "library",
135592          "bom-ref": "pkg:golang/github.com/yargevad/filepathx@v1.0.0?package-id=ecf7c443a8746115",
135593          "supplier": {},
135594          "name": "github.com/yargevad/filepathx",
135595          "version": "v1.0.0",
135596          "cpe": "cpe:2.3:a:yargevad:filepathx:v1.0.0:*:*:*:*:*:*:*",
135597          "purl": "pkg:golang/github.com/yargevad/filepathx@v1.0.0",
135598          "swid": {
135599            "attachment": {}
135600          },
135601          "pedigree": {},
135602          "evidence": {},
135603          "signature": {
135604            "signature": {
135605              "publicKey": {}
135606            }
135607          },
135608          "modelCard": {
135609            "modelParameters": {
135610              "approach": {}
135611            },
135612            "quantitativeAnalysis": {
135613              "graphics": {}
135614            },
135615            "considerations": {}
135616          }
135617        },
135618        {
135619          "type": "library",
135620          "bom-ref": "pkg:golang/github.com/zeebo/xxh3@v1.0.2?package-id=44b34c835ed779fc",
135621          "supplier": {},
135622          "name": "github.com/zeebo/xxh3",
135623          "version": "v1.0.2",
135624          "cpe": "cpe:2.3:a:zeebo:xxh3:v1.0.2:*:*:*:*:*:*:*",
135625          "purl": "pkg:golang/github.com/zeebo/xxh3@v1.0.2",
135626          "swid": {
135627            "attachment": {}
135628          },
135629          "pedigree": {},
135630          "evidence": {},
135631          "signature": {
135632            "signature": {
135633              "publicKey": {}
135634            }
135635          },
135636          "modelCard": {
135637            "modelParameters": {
135638              "approach": {}
135639            },
135640            "quantitativeAnalysis": {
135641              "graphics": {}
135642            },
135643            "considerations": {}
135644          }
135645        },
135646        {
135647          "type": "library",
135648          "bom-ref": "pkg:rpm/rhel/glib2@2.56.4-158.el8?arch=x86_64\u0026upstream=glib2-2.56.4-158.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=af7039b378a7b223",
135649          "supplier": {},
135650          "publisher": "Red Hat, Inc.",
135651          "name": "glib2",
135652          "version": "2.56.4-158.el8",
135653          "licenses": [
135654            {
135655              "license": {
135656                "name": "LGPLv2+"
135657              }
135658            }
135659          ],
135660          "cpe": "cpe:2.3:a:redhat:glib2:2.56.4-158.el8:*:*:*:*:*:*:*",
135661          "purl": "pkg:rpm/rhel/glib2@2.56.4-158.el8?arch=x86_64\u0026upstream=glib2-2.56.4-158.el8.src.rpm\u0026distro=rhel-8.6",
135662          "swid": {
135663            "attachment": {}
135664          },
135665          "pedigree": {},
135666          "evidence": {},
135667          "signature": {
135668            "signature": {
135669              "publicKey": {}
135670            }
135671          },
135672          "modelCard": {
135673            "modelParameters": {
135674              "approach": {}
135675            },
135676            "quantitativeAnalysis": {
135677              "graphics": {}
135678            },
135679            "considerations": {}
135680          }
135681        },
135682        {
135683          "type": "library",
135684          "bom-ref": "pkg:rpm/rhel/glibc@2.28-189.5.el8_6?arch=x86_64\u0026upstream=glibc-2.28-189.5.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=d7889d606899a182",
135685          "supplier": {},
135686          "publisher": "Red Hat, Inc.",
135687          "name": "glibc",
135688          "version": "2.28-189.5.el8_6",
135689          "licenses": [
135690            {
135691              "license": {
135692                "name": "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
135693              }
135694            }
135695          ],
135696          "cpe": "cpe:2.3:a:redhat:glibc:2.28-189.5.el8_6:*:*:*:*:*:*:*",
135697          "purl": "pkg:rpm/rhel/glibc@2.28-189.5.el8_6?arch=x86_64\u0026upstream=glibc-2.28-189.5.el8_6.src.rpm\u0026distro=rhel-8.6",
135698          "swid": {
135699            "attachment": {}
135700          },
135701          "pedigree": {},
135702          "evidence": {},
135703          "signature": {
135704            "signature": {
135705              "publicKey": {}
135706            }
135707          },
135708          "modelCard": {
135709            "modelParameters": {
135710              "approach": {}
135711            },
135712            "quantitativeAnalysis": {
135713              "graphics": {}
135714            },
135715            "considerations": {}
135716          }
135717        },
135718        {
135719          "type": "library",
135720          "bom-ref": "pkg:rpm/rhel/glibc-common@2.28-189.5.el8_6?arch=x86_64\u0026upstream=glibc-2.28-189.5.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=60ee28007692aead",
135721          "supplier": {},
135722          "publisher": "Red Hat, Inc.",
135723          "name": "glibc-common",
135724          "version": "2.28-189.5.el8_6",
135725          "licenses": [
135726            {
135727              "license": {
135728                "name": "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
135729              }
135730            }
135731          ],
135732          "cpe": "cpe:2.3:a:glibc-common:glibc-common:2.28-189.5.el8_6:*:*:*:*:*:*:*",
135733          "purl": "pkg:rpm/rhel/glibc-common@2.28-189.5.el8_6?arch=x86_64\u0026upstream=glibc-2.28-189.5.el8_6.src.rpm\u0026distro=rhel-8.6",
135734          "swid": {
135735            "attachment": {}
135736          },
135737          "pedigree": {},
135738          "evidence": {},
135739          "signature": {
135740            "signature": {
135741              "publicKey": {}
135742            }
135743          },
135744          "modelCard": {
135745            "modelParameters": {
135746              "approach": {}
135747            },
135748            "quantitativeAnalysis": {
135749              "graphics": {}
135750            },
135751            "considerations": {}
135752          }
135753        },
135754        {
135755          "type": "library",
135756          "bom-ref": "pkg:rpm/rhel/glibc-minimal-langpack@2.28-189.5.el8_6?arch=x86_64\u0026upstream=glibc-2.28-189.5.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=1bb320d243991db5",
135757          "supplier": {},
135758          "publisher": "Red Hat, Inc.",
135759          "name": "glibc-minimal-langpack",
135760          "version": "2.28-189.5.el8_6",
135761          "licenses": [
135762            {
135763              "license": {
135764                "name": "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
135765              }
135766            }
135767          ],
135768          "cpe": "cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-189.5.el8_6:*:*:*:*:*:*:*",
135769          "purl": "pkg:rpm/rhel/glibc-minimal-langpack@2.28-189.5.el8_6?arch=x86_64\u0026upstream=glibc-2.28-189.5.el8_6.src.rpm\u0026distro=rhel-8.6",
135770          "swid": {
135771            "attachment": {}
135772          },
135773          "pedigree": {},
135774          "evidence": {},
135775          "signature": {
135776            "signature": {
135777              "publicKey": {}
135778            }
135779          },
135780          "modelCard": {
135781            "modelParameters": {
135782              "approach": {}
135783            },
135784            "quantitativeAnalysis": {
135785              "graphics": {}
135786            },
135787            "considerations": {}
135788          }
135789        },
135790        {
135791          "type": "library",
135792          "bom-ref": "pkg:rpm/rhel/gmp@6.1.2-10.el8?arch=x86_64\u0026epoch=1\u0026upstream=gmp-6.1.2-10.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=6a36a5dc44564b2d",
135793          "supplier": {},
135794          "publisher": "Red Hat, Inc.",
135795          "name": "gmp",
135796          "version": "1:6.1.2-10.el8",
135797          "licenses": [
135798            {
135799              "license": {
135800                "name": "LGPLv3+ or GPLv2+"
135801              }
135802            }
135803          ],
135804          "cpe": "cpe:2.3:a:redhat:gmp:1\\:6.1.2-10.el8:*:*:*:*:*:*:*",
135805          "purl": "pkg:rpm/rhel/gmp@6.1.2-10.el8?arch=x86_64\u0026epoch=1\u0026upstream=gmp-6.1.2-10.el8.src.rpm\u0026distro=rhel-8.6",
135806          "swid": {
135807            "attachment": {}
135808          },
135809          "pedigree": {},
135810          "evidence": {},
135811          "signature": {
135812            "signature": {
135813              "publicKey": {}
135814            }
135815          },
135816          "modelCard": {
135817            "modelParameters": {
135818              "approach": {}
135819            },
135820            "quantitativeAnalysis": {
135821              "graphics": {}
135822            },
135823            "considerations": {}
135824          }
135825        },
135826        {
135827          "type": "library",
135828          "bom-ref": "pkg:rpm/rhel/gnupg2@2.2.20-3.el8_6?arch=x86_64\u0026upstream=gnupg2-2.2.20-3.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=1b3663d04bda2281",
135829          "supplier": {},
135830          "publisher": "Red Hat, Inc.",
135831          "name": "gnupg2",
135832          "version": "2.2.20-3.el8_6",
135833          "licenses": [
135834            {
135835              "license": {
135836                "name": "GPLv3+"
135837              }
135838            }
135839          ],
135840          "cpe": "cpe:2.3:a:gnupg2:gnupg2:2.2.20-3.el8_6:*:*:*:*:*:*:*",
135841          "purl": "pkg:rpm/rhel/gnupg2@2.2.20-3.el8_6?arch=x86_64\u0026upstream=gnupg2-2.2.20-3.el8_6.src.rpm\u0026distro=rhel-8.6",
135842          "swid": {
135843            "attachment": {}
135844          },
135845          "pedigree": {},
135846          "evidence": {},
135847          "signature": {
135848            "signature": {
135849              "publicKey": {}
135850            }
135851          },
135852          "modelCard": {
135853            "modelParameters": {
135854              "approach": {}
135855            },
135856            "quantitativeAnalysis": {
135857              "graphics": {}
135858            },
135859            "considerations": {}
135860          }
135861        },
135862        {
135863          "type": "library",
135864          "bom-ref": "pkg:rpm/rhel/gnutls@3.6.16-4.el8?arch=x86_64\u0026upstream=gnutls-3.6.16-4.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=778adf1817cd21ea",
135865          "supplier": {},
135866          "publisher": "Red Hat, Inc.",
135867          "name": "gnutls",
135868          "version": "3.6.16-4.el8",
135869          "licenses": [
135870            {
135871              "license": {
135872                "name": "GPLv3+ and LGPLv2+"
135873              }
135874            }
135875          ],
135876          "cpe": "cpe:2.3:a:gnutls:gnutls:3.6.16-4.el8:*:*:*:*:*:*:*",
135877          "purl": "pkg:rpm/rhel/gnutls@3.6.16-4.el8?arch=x86_64\u0026upstream=gnutls-3.6.16-4.el8.src.rpm\u0026distro=rhel-8.6",
135878          "swid": {
135879            "attachment": {}
135880          },
135881          "pedigree": {},
135882          "evidence": {},
135883          "signature": {
135884            "signature": {
135885              "publicKey": {}
135886            }
135887          },
135888          "modelCard": {
135889            "modelParameters": {
135890              "approach": {}
135891            },
135892            "quantitativeAnalysis": {
135893              "graphics": {}
135894            },
135895            "considerations": {}
135896          }
135897        },
135898        {
135899          "type": "library",
135900          "bom-ref": "pkg:golang/go.etcd.io/etcd/api/v3@v3.5.5?package-id=8b1ec1b19b79db56",
135901          "supplier": {},
135902          "name": "go.etcd.io/etcd/api/v3",
135903          "version": "v3.5.5",
135904          "cpe": "cpe:2.3:a:etcd:api\\/v3:v3.5.5:*:*:*:*:*:*:*",
135905          "purl": "pkg:golang/go.etcd.io/etcd/api/v3@v3.5.5",
135906          "swid": {
135907            "attachment": {}
135908          },
135909          "pedigree": {},
135910          "evidence": {},
135911          "signature": {
135912            "signature": {
135913              "publicKey": {}
135914            }
135915          },
135916          "modelCard": {
135917            "modelParameters": {
135918              "approach": {}
135919            },
135920            "quantitativeAnalysis": {
135921              "graphics": {}
135922            },
135923            "considerations": {}
135924          }
135925        },
135926        {
135927          "type": "library",
135928          "bom-ref": "pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.5.5?package-id=3034d9f13120487b",
135929          "supplier": {},
135930          "name": "go.etcd.io/etcd/client/pkg/v3",
135931          "version": "v3.5.5",
135932          "cpe": "cpe:2.3:a:etcd:client\\/pkg\\/v3:v3.5.5:*:*:*:*:*:*:*",
135933          "purl": "pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.5.5",
135934          "swid": {
135935            "attachment": {}
135936          },
135937          "pedigree": {},
135938          "evidence": {},
135939          "signature": {
135940            "signature": {
135941              "publicKey": {}
135942            }
135943          },
135944          "modelCard": {
135945            "modelParameters": {
135946              "approach": {}
135947            },
135948            "quantitativeAnalysis": {
135949              "graphics": {}
135950            },
135951            "considerations": {}
135952          }
135953        },
135954        {
135955          "type": "library",
135956          "bom-ref": "pkg:golang/go.etcd.io/etcd/client/v3@v3.5.5?package-id=c82467860259549e",
135957          "supplier": {},
135958          "name": "go.etcd.io/etcd/client/v3",
135959          "version": "v3.5.5",
135960          "cpe": "cpe:2.3:a:etcd:client\\/v3:v3.5.5:*:*:*:*:*:*:*",
135961          "purl": "pkg:golang/go.etcd.io/etcd/client/v3@v3.5.5",
135962          "swid": {
135963            "attachment": {}
135964          },
135965          "pedigree": {},
135966          "evidence": {},
135967          "signature": {
135968            "signature": {
135969              "publicKey": {}
135970            }
135971          },
135972          "modelCard": {
135973            "modelParameters": {
135974              "approach": {}
135975            },
135976            "quantitativeAnalysis": {
135977              "graphics": {}
135978            },
135979            "considerations": {}
135980          }
135981        },
135982        {
135983          "type": "library",
135984          "bom-ref": "pkg:golang/go.mongodb.org/mongo-driver@v1.10.2?package-id=450c0b8e6bc43189",
135985          "supplier": {},
135986          "name": "go.mongodb.org/mongo-driver",
135987          "version": "v1.10.2",
135988          "purl": "pkg:golang/go.mongodb.org/mongo-driver@v1.10.2",
135989          "swid": {
135990            "attachment": {}
135991          },
135992          "pedigree": {},
135993          "evidence": {},
135994          "signature": {
135995            "signature": {
135996              "publicKey": {}
135997            }
135998          },
135999          "modelCard": {
136000            "modelParameters": {
136001              "approach": {}
136002            },
136003            "quantitativeAnalysis": {
136004              "graphics": {}
136005            },
136006            "considerations": {}
136007          }
136008        },
136009        {
136010          "type": "library",
136011          "bom-ref": "pkg:golang/go.opencensus.io@v0.23.0?package-id=e809c5a72ea2b4f7",
136012          "supplier": {},
136013          "name": "go.opencensus.io",
136014          "version": "v0.23.0",
136015          "purl": "pkg:golang/go.opencensus.io@v0.23.0",
136016          "swid": {
136017            "attachment": {}
136018          },
136019          "pedigree": {},
136020          "evidence": {},
136021          "signature": {
136022            "signature": {
136023              "publicKey": {}
136024            }
136025          },
136026          "modelCard": {
136027            "modelParameters": {
136028              "approach": {}
136029            },
136030            "quantitativeAnalysis": {
136031              "graphics": {}
136032            },
136033            "considerations": {}
136034          }
136035        },
136036        {
136037          "type": "library",
136038          "bom-ref": "pkg:golang/go.uber.org/atomic@v1.10.0?package-id=1da106344404fcb2",
136039          "supplier": {},
136040          "name": "go.uber.org/atomic",
136041          "version": "v1.10.0",
136042          "purl": "pkg:golang/go.uber.org/atomic@v1.10.0",
136043          "swid": {
136044            "attachment": {}
136045          },
136046          "pedigree": {},
136047          "evidence": {},
136048          "signature": {
136049            "signature": {
136050              "publicKey": {}
136051            }
136052          },
136053          "modelCard": {
136054            "modelParameters": {
136055              "approach": {}
136056            },
136057            "quantitativeAnalysis": {
136058              "graphics": {}
136059            },
136060            "considerations": {}
136061          }
136062        },
136063        {
136064          "type": "library",
136065          "bom-ref": "pkg:golang/go.uber.org/multierr@v1.8.0?package-id=57bfaf9c3b5fccba",
136066          "supplier": {},
136067          "name": "go.uber.org/multierr",
136068          "version": "v1.8.0",
136069          "purl": "pkg:golang/go.uber.org/multierr@v1.8.0",
136070          "swid": {
136071            "attachment": {}
136072          },
136073          "pedigree": {},
136074          "evidence": {},
136075          "signature": {
136076            "signature": {
136077              "publicKey": {}
136078            }
136079          },
136080          "modelCard": {
136081            "modelParameters": {
136082              "approach": {}
136083            },
136084            "quantitativeAnalysis": {
136085              "graphics": {}
136086            },
136087            "considerations": {}
136088          }
136089        },
136090        {
136091          "type": "library",
136092          "bom-ref": "pkg:golang/go.uber.org/zap@v1.23.0?package-id=288b89a19c0f6e0f",
136093          "supplier": {},
136094          "name": "go.uber.org/zap",
136095          "version": "v1.23.0",
136096          "purl": "pkg:golang/go.uber.org/zap@v1.23.0",
136097          "swid": {
136098            "attachment": {}
136099          },
136100          "pedigree": {},
136101          "evidence": {},
136102          "signature": {
136103            "signature": {
136104              "publicKey": {}
136105            }
136106          },
136107          "modelCard": {
136108            "modelParameters": {
136109              "approach": {}
136110            },
136111            "quantitativeAnalysis": {
136112              "graphics": {}
136113            },
136114            "considerations": {}
136115          }
136116        },
136117        {
136118          "type": "library",
136119          "bom-ref": "pkg:rpm/rhel/gobject-introspection@1.56.1-1.el8?arch=x86_64\u0026upstream=gobject-introspection-1.56.1-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=a22daf0266301db4",
136120          "supplier": {},
136121          "publisher": "Red Hat, Inc.",
136122          "name": "gobject-introspection",
136123          "version": "1.56.1-1.el8",
136124          "licenses": [
136125            {
136126              "license": {
136127                "name": "GPLv2+, LGPLv2+, MIT"
136128              }
136129            }
136130          ],
136131          "cpe": "cpe:2.3:a:gobject-introspection:gobject-introspection:1.56.1-1.el8:*:*:*:*:*:*:*",
136132          "purl": "pkg:rpm/rhel/gobject-introspection@1.56.1-1.el8?arch=x86_64\u0026upstream=gobject-introspection-1.56.1-1.el8.src.rpm\u0026distro=rhel-8.6",
136133          "swid": {
136134            "attachment": {}
136135          },
136136          "pedigree": {},
136137          "evidence": {},
136138          "signature": {
136139            "signature": {
136140              "publicKey": {}
136141            }
136142          },
136143          "modelCard": {
136144            "modelParameters": {
136145              "approach": {}
136146            },
136147            "quantitativeAnalysis": {
136148              "graphics": {}
136149            },
136150            "considerations": {}
136151          }
136152        },
136153        {
136154          "type": "library",
136155          "bom-ref": "pkg:golang/golang.org/x/crypto@v0.1.0?package-id=d97ddf3cd5ce556c",
136156          "supplier": {},
136157          "name": "golang.org/x/crypto",
136158          "version": "v0.1.0",
136159          "cpe": "cpe:2.3:a:golang:x\\/crypto:v0.1.0:*:*:*:*:*:*:*",
136160          "purl": "pkg:golang/golang.org/x/crypto@v0.1.0",
136161          "swid": {
136162            "attachment": {}
136163          },
136164          "pedigree": {},
136165          "evidence": {},
136166          "signature": {
136167            "signature": {
136168              "publicKey": {}
136169            }
136170          },
136171          "modelCard": {
136172            "modelParameters": {
136173              "approach": {}
136174            },
136175            "quantitativeAnalysis": {
136176              "graphics": {}
136177            },
136178            "considerations": {}
136179          }
136180        },
136181        {
136182          "type": "library",
136183          "bom-ref": "pkg:golang/golang.org/x/net@v0.1.0?package-id=c50871a434248607",
136184          "supplier": {},
136185          "name": "golang.org/x/net",
136186          "version": "v0.1.0",
136187          "cpe": "cpe:2.3:a:golang:x\\/net:v0.1.0:*:*:*:*:*:*:*",
136188          "purl": "pkg:golang/golang.org/x/net@v0.1.0",
136189          "swid": {
136190            "attachment": {}
136191          },
136192          "pedigree": {},
136193          "evidence": {},
136194          "signature": {
136195            "signature": {
136196              "publicKey": {}
136197            }
136198          },
136199          "modelCard": {
136200            "modelParameters": {
136201              "approach": {}
136202            },
136203            "quantitativeAnalysis": {
136204              "graphics": {}
136205            },
136206            "considerations": {}
136207          }
136208        },
136209        {
136210          "type": "library",
136211          "bom-ref": "pkg:golang/golang.org/x/oauth2@v0.1.0?package-id=a3ed243ba2d9392a",
136212          "supplier": {},
136213          "name": "golang.org/x/oauth2",
136214          "version": "v0.1.0",
136215          "cpe": "cpe:2.3:a:golang:x\\/oauth2:v0.1.0:*:*:*:*:*:*:*",
136216          "purl": "pkg:golang/golang.org/x/oauth2@v0.1.0",
136217          "swid": {
136218            "attachment": {}
136219          },
136220          "pedigree": {},
136221          "evidence": {},
136222          "signature": {
136223            "signature": {
136224              "publicKey": {}
136225            }
136226          },
136227          "modelCard": {
136228            "modelParameters": {
136229              "approach": {}
136230            },
136231            "quantitativeAnalysis": {
136232              "graphics": {}
136233            },
136234            "considerations": {}
136235          }
136236        },
136237        {
136238          "type": "library",
136239          "bom-ref": "pkg:golang/golang.org/x/sync@v0.1.0?package-id=3bbdb99ee7f81f15",
136240          "supplier": {},
136241          "name": "golang.org/x/sync",
136242          "version": "v0.1.0",
136243          "cpe": "cpe:2.3:a:golang:x\\/sync:v0.1.0:*:*:*:*:*:*:*",
136244          "purl": "pkg:golang/golang.org/x/sync@v0.1.0",
136245          "swid": {
136246            "attachment": {}
136247          },
136248          "pedigree": {},
136249          "evidence": {},
136250          "signature": {
136251            "signature": {
136252              "publicKey": {}
136253            }
136254          },
136255          "modelCard": {
136256            "modelParameters": {
136257              "approach": {}
136258            },
136259            "quantitativeAnalysis": {
136260              "graphics": {}
136261            },
136262            "considerations": {}
136263          }
136264        },
136265        {
136266          "type": "library",
136267          "bom-ref": "pkg:golang/golang.org/x/sys@v0.1.0?package-id=cbc9c44c3f61b89c",
136268          "supplier": {},
136269          "name": "golang.org/x/sys",
136270          "version": "v0.1.0",
136271          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.1.0:*:*:*:*:*:*:*",
136272          "purl": "pkg:golang/golang.org/x/sys@v0.1.0",
136273          "swid": {
136274            "attachment": {}
136275          },
136276          "pedigree": {},
136277          "evidence": {},
136278          "signature": {
136279            "signature": {
136280              "publicKey": {}
136281            }
136282          },
136283          "modelCard": {
136284            "modelParameters": {
136285              "approach": {}
136286            },
136287            "quantitativeAnalysis": {
136288              "graphics": {}
136289            },
136290            "considerations": {}
136291          }
136292        },
136293        {
136294          "type": "library",
136295          "bom-ref": "pkg:golang/golang.org/x/term@v0.1.0?package-id=5fbeaecfd75d284e",
136296          "supplier": {},
136297          "name": "golang.org/x/term",
136298          "version": "v0.1.0",
136299          "cpe": "cpe:2.3:a:golang:x\\/term:v0.1.0:*:*:*:*:*:*:*",
136300          "purl": "pkg:golang/golang.org/x/term@v0.1.0",
136301          "swid": {
136302            "attachment": {}
136303          },
136304          "pedigree": {},
136305          "evidence": {},
136306          "signature": {
136307            "signature": {
136308              "publicKey": {}
136309            }
136310          },
136311          "modelCard": {
136312            "modelParameters": {
136313              "approach": {}
136314            },
136315            "quantitativeAnalysis": {
136316              "graphics": {}
136317            },
136318            "considerations": {}
136319          }
136320        },
136321        {
136322          "type": "library",
136323          "bom-ref": "pkg:golang/golang.org/x/text@v0.4.0?package-id=acb731cb7bde553",
136324          "supplier": {},
136325          "name": "golang.org/x/text",
136326          "version": "v0.4.0",
136327          "cpe": "cpe:2.3:a:golang:x\\/text:v0.4.0:*:*:*:*:*:*:*",
136328          "purl": "pkg:golang/golang.org/x/text@v0.4.0",
136329          "swid": {
136330            "attachment": {}
136331          },
136332          "pedigree": {},
136333          "evidence": {},
136334          "signature": {
136335            "signature": {
136336              "publicKey": {}
136337            }
136338          },
136339          "modelCard": {
136340            "modelParameters": {
136341              "approach": {}
136342            },
136343            "quantitativeAnalysis": {
136344              "graphics": {}
136345            },
136346            "considerations": {}
136347          }
136348        },
136349        {
136350          "type": "library",
136351          "bom-ref": "pkg:golang/golang.org/x/time@v0.0.0-20220722155302-e5dcc9cfc0b9?package-id=6b973a2a5edb54c",
136352          "supplier": {},
136353          "name": "golang.org/x/time",
136354          "version": "v0.0.0-20220722155302-e5dcc9cfc0b9",
136355          "cpe": "cpe:2.3:a:golang:x\\/time:v0.0.0-20220722155302-e5dcc9cfc0b9:*:*:*:*:*:*:*",
136356          "purl": "pkg:golang/golang.org/x/time@v0.0.0-20220722155302-e5dcc9cfc0b9",
136357          "swid": {
136358            "attachment": {}
136359          },
136360          "pedigree": {},
136361          "evidence": {},
136362          "signature": {
136363            "signature": {
136364              "publicKey": {}
136365            }
136366          },
136367          "modelCard": {
136368            "modelParameters": {
136369              "approach": {}
136370            },
136371            "quantitativeAnalysis": {
136372              "graphics": {}
136373            },
136374            "considerations": {}
136375          }
136376        },
136377        {
136378          "type": "library",
136379          "bom-ref": "pkg:golang/golang.org/x/xerrors@v0.0.0-20220907171357-04be3eba64a2?package-id=d34e8dfdbca73674",
136380          "supplier": {},
136381          "name": "golang.org/x/xerrors",
136382          "version": "v0.0.0-20220907171357-04be3eba64a2",
136383          "cpe": "cpe:2.3:a:golang:x\\/xerrors:v0.0.0-20220907171357-04be3eba64a2:*:*:*:*:*:*:*",
136384          "purl": "pkg:golang/golang.org/x/xerrors@v0.0.0-20220907171357-04be3eba64a2",
136385          "swid": {
136386            "attachment": {}
136387          },
136388          "pedigree": {},
136389          "evidence": {},
136390          "signature": {
136391            "signature": {
136392              "publicKey": {}
136393            }
136394          },
136395          "modelCard": {
136396            "modelParameters": {
136397              "approach": {}
136398            },
136399            "quantitativeAnalysis": {
136400              "graphics": {}
136401            },
136402            "considerations": {}
136403          }
136404        },
136405        {
136406          "type": "library",
136407          "bom-ref": "pkg:golang/google.golang.org/api@v0.98.0?package-id=c5b02ec985ca4546",
136408          "supplier": {},
136409          "name": "google.golang.org/api",
136410          "version": "v0.98.0",
136411          "cpe": "cpe:2.3:a:google:api:v0.98.0:*:*:*:*:*:*:*",
136412          "purl": "pkg:golang/google.golang.org/api@v0.98.0",
136413          "swid": {
136414            "attachment": {}
136415          },
136416          "pedigree": {},
136417          "evidence": {},
136418          "signature": {
136419            "signature": {
136420              "publicKey": {}
136421            }
136422          },
136423          "modelCard": {
136424            "modelParameters": {
136425              "approach": {}
136426            },
136427            "quantitativeAnalysis": {
136428              "graphics": {}
136429            },
136430            "considerations": {}
136431          }
136432        },
136433        {
136434          "type": "library",
136435          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20221018160656-63c7b68cfc55?package-id=668c3c10f4c75f32",
136436          "supplier": {},
136437          "name": "google.golang.org/genproto",
136438          "version": "v0.0.0-20221018160656-63c7b68cfc55",
136439          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20221018160656-63c7b68cfc55:*:*:*:*:*:*:*",
136440          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20221018160656-63c7b68cfc55",
136441          "swid": {
136442            "attachment": {}
136443          },
136444          "pedigree": {},
136445          "evidence": {},
136446          "signature": {
136447            "signature": {
136448              "publicKey": {}
136449            }
136450          },
136451          "modelCard": {
136452            "modelParameters": {
136453              "approach": {}
136454            },
136455            "quantitativeAnalysis": {
136456              "graphics": {}
136457            },
136458            "considerations": {}
136459          }
136460        },
136461        {
136462          "type": "library",
136463          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.50.1?package-id=8de5c594d0677530",
136464          "supplier": {},
136465          "name": "google.golang.org/grpc",
136466          "version": "v1.50.1",
136467          "cpe": "cpe:2.3:a:google:grpc:v1.50.1:*:*:*:*:*:*:*",
136468          "purl": "pkg:golang/google.golang.org/grpc@v1.50.1",
136469          "swid": {
136470            "attachment": {}
136471          },
136472          "pedigree": {},
136473          "evidence": {},
136474          "signature": {
136475            "signature": {
136476              "publicKey": {}
136477            }
136478          },
136479          "modelCard": {
136480            "modelParameters": {
136481              "approach": {}
136482            },
136483            "quantitativeAnalysis": {
136484              "graphics": {}
136485            },
136486            "considerations": {}
136487          }
136488        },
136489        {
136490          "type": "library",
136491          "bom-ref": "pkg:golang/google.golang.org/protobuf@v1.28.1?package-id=3ef0f448dab9fea4",
136492          "supplier": {},
136493          "name": "google.golang.org/protobuf",
136494          "version": "v1.28.1",
136495          "cpe": "cpe:2.3:a:google:protobuf:v1.28.1:*:*:*:*:*:*:*",
136496          "purl": "pkg:golang/google.golang.org/protobuf@v1.28.1",
136497          "swid": {
136498            "attachment": {}
136499          },
136500          "pedigree": {},
136501          "evidence": {},
136502          "signature": {
136503            "signature": {
136504              "publicKey": {}
136505            }
136506          },
136507          "modelCard": {
136508            "modelParameters": {
136509              "approach": {}
136510            },
136511            "quantitativeAnalysis": {
136512              "graphics": {}
136513            },
136514            "considerations": {}
136515          }
136516        },
136517        {
136518          "type": "library",
136519          "bom-ref": "pkg:golang/gopkg.in/h2non/filetype.v1@v1.0.5?package-id=93ca5f56d3b49e84",
136520          "supplier": {},
136521          "name": "gopkg.in/h2non/filetype.v1",
136522          "version": "v1.0.5",
136523          "purl": "pkg:golang/gopkg.in/h2non/filetype.v1@v1.0.5",
136524          "swid": {
136525            "attachment": {}
136526          },
136527          "pedigree": {},
136528          "evidence": {},
136529          "signature": {
136530            "signature": {
136531              "publicKey": {}
136532            }
136533          },
136534          "modelCard": {
136535            "modelParameters": {
136536              "approach": {}
136537            },
136538            "quantitativeAnalysis": {
136539              "graphics": {}
136540            },
136541            "considerations": {}
136542          }
136543        },
136544        {
136545          "type": "library",
136546          "bom-ref": "pkg:golang/gopkg.in/ini.v1@v1.67.0?package-id=a37eee3a430e8215",
136547          "supplier": {},
136548          "name": "gopkg.in/ini.v1",
136549          "version": "v1.67.0",
136550          "purl": "pkg:golang/gopkg.in/ini.v1@v1.67.0",
136551          "swid": {
136552            "attachment": {}
136553          },
136554          "pedigree": {},
136555          "evidence": {},
136556          "signature": {
136557            "signature": {
136558              "publicKey": {}
136559            }
136560          },
136561          "modelCard": {
136562            "modelParameters": {
136563              "approach": {}
136564            },
136565            "quantitativeAnalysis": {
136566              "graphics": {}
136567            },
136568            "considerations": {}
136569          }
136570        },
136571        {
136572          "type": "library",
136573          "bom-ref": "pkg:golang/gopkg.in/square/go-jose.v2@v2.6.0?package-id=f8e4414955179475",
136574          "supplier": {},
136575          "name": "gopkg.in/square/go-jose.v2",
136576          "version": "v2.6.0",
136577          "purl": "pkg:golang/gopkg.in/square/go-jose.v2@v2.6.0",
136578          "swid": {
136579            "attachment": {}
136580          },
136581          "pedigree": {},
136582          "evidence": {},
136583          "signature": {
136584            "signature": {
136585              "publicKey": {}
136586            }
136587          },
136588          "modelCard": {
136589            "modelParameters": {
136590              "approach": {}
136591            },
136592            "quantitativeAnalysis": {
136593              "graphics": {}
136594            },
136595            "considerations": {}
136596          }
136597        },
136598        {
136599          "type": "library",
136600          "bom-ref": "pkg:golang/gopkg.in/yaml.v2@v2.4.0?package-id=c718293b9b0a65e3",
136601          "supplier": {},
136602          "name": "gopkg.in/yaml.v2",
136603          "version": "v2.4.0",
136604          "purl": "pkg:golang/gopkg.in/yaml.v2@v2.4.0",
136605          "swid": {
136606            "attachment": {}
136607          },
136608          "pedigree": {},
136609          "evidence": {},
136610          "signature": {
136611            "signature": {
136612              "publicKey": {}
136613            }
136614          },
136615          "modelCard": {
136616            "modelParameters": {
136617              "approach": {}
136618            },
136619            "quantitativeAnalysis": {
136620              "graphics": {}
136621            },
136622            "considerations": {}
136623          }
136624        },
136625        {
136626          "type": "library",
136627          "bom-ref": "pkg:golang/gopkg.in/yaml.v3@v3.0.1?package-id=dddab0270cebb717",
136628          "supplier": {},
136629          "name": "gopkg.in/yaml.v3",
136630          "version": "v3.0.1",
136631          "purl": "pkg:golang/gopkg.in/yaml.v3@v3.0.1",
136632          "swid": {
136633            "attachment": {}
136634          },
136635          "pedigree": {},
136636          "evidence": {},
136637          "signature": {
136638            "signature": {
136639              "publicKey": {}
136640            }
136641          },
136642          "modelCard": {
136643            "modelParameters": {
136644              "approach": {}
136645            },
136646            "quantitativeAnalysis": {
136647              "graphics": {}
136648            },
136649            "considerations": {}
136650          }
136651        },
136652        {
136653          "type": "library",
136654          "bom-ref": "pkg:rpm/rhel/gpg-pubkey@d4082792-5b32db75?distro=rhel-8.6\u0026package-id=79b894b4caa3ac63",
136655          "supplier": {},
136656          "name": "gpg-pubkey",
136657          "version": "d4082792-5b32db75",
136658          "licenses": [
136659            {
136660              "license": {
136661                "name": "pubkey"
136662              }
136663            }
136664          ],
136665          "cpe": "cpe:2.3:a:gpg-pubkey:gpg-pubkey:d4082792-5b32db75:*:*:*:*:*:*:*",
136666          "purl": "pkg:rpm/rhel/gpg-pubkey@d4082792-5b32db75?distro=rhel-8.6",
136667          "swid": {
136668            "attachment": {}
136669          },
136670          "pedigree": {},
136671          "evidence": {},
136672          "signature": {
136673            "signature": {
136674              "publicKey": {}
136675            }
136676          },
136677          "modelCard": {
136678            "modelParameters": {
136679              "approach": {}
136680            },
136681            "quantitativeAnalysis": {
136682              "graphics": {}
136683            },
136684            "considerations": {}
136685          }
136686        },
136687        {
136688          "type": "library",
136689          "bom-ref": "pkg:rpm/rhel/gpg-pubkey@fd431d51-4ae0493b?distro=rhel-8.6\u0026package-id=421b2878b8d9bbd7",
136690          "supplier": {},
136691          "name": "gpg-pubkey",
136692          "version": "fd431d51-4ae0493b",
136693          "licenses": [
136694            {
136695              "license": {
136696                "name": "pubkey"
136697              }
136698            }
136699          ],
136700          "cpe": "cpe:2.3:a:gpg-pubkey:gpg-pubkey:fd431d51-4ae0493b:*:*:*:*:*:*:*",
136701          "purl": "pkg:rpm/rhel/gpg-pubkey@fd431d51-4ae0493b?distro=rhel-8.6",
136702          "swid": {
136703            "attachment": {}
136704          },
136705          "pedigree": {},
136706          "evidence": {},
136707          "signature": {
136708            "signature": {
136709              "publicKey": {}
136710            }
136711          },
136712          "modelCard": {
136713            "modelParameters": {
136714              "approach": {}
136715            },
136716            "quantitativeAnalysis": {
136717              "graphics": {}
136718            },
136719            "considerations": {}
136720          }
136721        },
136722        {
136723          "type": "library",
136724          "bom-ref": "pkg:rpm/rhel/gpgme@1.13.1-11.el8?arch=x86_64\u0026upstream=gpgme-1.13.1-11.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=e31d80eb6a0c5fd6",
136725          "supplier": {},
136726          "publisher": "Red Hat, Inc.",
136727          "name": "gpgme",
136728          "version": "1.13.1-11.el8",
136729          "licenses": [
136730            {
136731              "license": {
136732                "name": "LGPLv2+ and GPLv3+"
136733              }
136734            }
136735          ],
136736          "cpe": "cpe:2.3:a:redhat:gpgme:1.13.1-11.el8:*:*:*:*:*:*:*",
136737          "purl": "pkg:rpm/rhel/gpgme@1.13.1-11.el8?arch=x86_64\u0026upstream=gpgme-1.13.1-11.el8.src.rpm\u0026distro=rhel-8.6",
136738          "swid": {
136739            "attachment": {}
136740          },
136741          "pedigree": {},
136742          "evidence": {},
136743          "signature": {
136744            "signature": {
136745              "publicKey": {}
136746            }
136747          },
136748          "modelCard": {
136749            "modelParameters": {
136750              "approach": {}
136751            },
136752            "quantitativeAnalysis": {
136753              "graphics": {}
136754            },
136755            "considerations": {}
136756          }
136757        },
136758        {
136759          "type": "library",
136760          "bom-ref": "pkg:rpm/rhel/grep@3.1-6.el8?arch=x86_64\u0026upstream=grep-3.1-6.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=dcf380266f505a97",
136761          "supplier": {},
136762          "publisher": "Red Hat, Inc.",
136763          "name": "grep",
136764          "version": "3.1-6.el8",
136765          "licenses": [
136766            {
136767              "license": {
136768                "name": "GPLv3+"
136769              }
136770            }
136771          ],
136772          "cpe": "cpe:2.3:a:redhat:grep:3.1-6.el8:*:*:*:*:*:*:*",
136773          "purl": "pkg:rpm/rhel/grep@3.1-6.el8?arch=x86_64\u0026upstream=grep-3.1-6.el8.src.rpm\u0026distro=rhel-8.6",
136774          "swid": {
136775            "attachment": {}
136776          },
136777          "pedigree": {},
136778          "evidence": {},
136779          "signature": {
136780            "signature": {
136781              "publicKey": {}
136782            }
136783          },
136784          "modelCard": {
136785            "modelParameters": {
136786              "approach": {}
136787            },
136788            "quantitativeAnalysis": {
136789              "graphics": {}
136790            },
136791            "considerations": {}
136792          }
136793        },
136794        {
136795          "type": "library",
136796          "bom-ref": "pkg:rpm/rhel/gzip@1.9-13.el8_5?arch=x86_64\u0026upstream=gzip-1.9-13.el8_5.src.rpm\u0026distro=rhel-8.6\u0026package-id=402935efe4fc330d",
136797          "supplier": {},
136798          "publisher": "Red Hat, Inc.",
136799          "name": "gzip",
136800          "version": "1.9-13.el8_5",
136801          "licenses": [
136802            {
136803              "license": {
136804                "name": "GPLv3+ and GFDL"
136805              }
136806            }
136807          ],
136808          "cpe": "cpe:2.3:a:redhat:gzip:1.9-13.el8_5:*:*:*:*:*:*:*",
136809          "purl": "pkg:rpm/rhel/gzip@1.9-13.el8_5?arch=x86_64\u0026upstream=gzip-1.9-13.el8_5.src.rpm\u0026distro=rhel-8.6",
136810          "swid": {
136811            "attachment": {}
136812          },
136813          "pedigree": {},
136814          "evidence": {},
136815          "signature": {
136816            "signature": {
136817              "publicKey": {}
136818            }
136819          },
136820          "modelCard": {
136821            "modelParameters": {
136822              "approach": {}
136823            },
136824            "quantitativeAnalysis": {
136825              "graphics": {}
136826            },
136827            "considerations": {}
136828          }
136829        },
136830        {
136831          "type": "library",
136832          "bom-ref": "pkg:rpm/rhel/info@6.5-7.el8?arch=x86_64\u0026upstream=texinfo-6.5-7.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=8be22186d57c1627",
136833          "supplier": {},
136834          "publisher": "Red Hat, Inc.",
136835          "name": "info",
136836          "version": "6.5-7.el8",
136837          "licenses": [
136838            {
136839              "license": {
136840                "name": "GPLv3+"
136841              }
136842            }
136843          ],
136844          "cpe": "cpe:2.3:a:redhat:info:6.5-7.el8:*:*:*:*:*:*:*",
136845          "purl": "pkg:rpm/rhel/info@6.5-7.el8?arch=x86_64\u0026upstream=texinfo-6.5-7.el8.src.rpm\u0026distro=rhel-8.6",
136846          "swid": {
136847            "attachment": {}
136848          },
136849          "pedigree": {},
136850          "evidence": {},
136851          "signature": {
136852            "signature": {
136853              "publicKey": {}
136854            }
136855          },
136856          "modelCard": {
136857            "modelParameters": {
136858              "approach": {}
136859            },
136860            "quantitativeAnalysis": {
136861              "graphics": {}
136862            },
136863            "considerations": {}
136864          }
136865        },
136866        {
136867          "type": "library",
136868          "bom-ref": "pkg:rpm/rhel/json-c@0.13.1-3.el8?arch=x86_64\u0026upstream=json-c-0.13.1-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=e2321487b60479b5",
136869          "supplier": {},
136870          "publisher": "Red Hat, Inc.",
136871          "name": "json-c",
136872          "version": "0.13.1-3.el8",
136873          "licenses": [
136874            {
136875              "license": {
136876                "id": "MIT"
136877              }
136878            }
136879          ],
136880          "cpe": "cpe:2.3:a:json-c:json-c:0.13.1-3.el8:*:*:*:*:*:*:*",
136881          "purl": "pkg:rpm/rhel/json-c@0.13.1-3.el8?arch=x86_64\u0026upstream=json-c-0.13.1-3.el8.src.rpm\u0026distro=rhel-8.6",
136882          "swid": {
136883            "attachment": {}
136884          },
136885          "pedigree": {},
136886          "evidence": {},
136887          "signature": {
136888            "signature": {
136889              "publicKey": {}
136890            }
136891          },
136892          "modelCard": {
136893            "modelParameters": {
136894              "approach": {}
136895            },
136896            "quantitativeAnalysis": {
136897              "graphics": {}
136898            },
136899            "considerations": {}
136900          }
136901        },
136902        {
136903          "type": "library",
136904          "bom-ref": "pkg:rpm/rhel/json-glib@1.4.4-1.el8?arch=x86_64\u0026upstream=json-glib-1.4.4-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=f58fc0d9670b7376",
136905          "supplier": {},
136906          "publisher": "Red Hat, Inc.",
136907          "name": "json-glib",
136908          "version": "1.4.4-1.el8",
136909          "licenses": [
136910            {
136911              "license": {
136912                "name": "LGPLv2+"
136913              }
136914            }
136915          ],
136916          "cpe": "cpe:2.3:a:json-glib:json-glib:1.4.4-1.el8:*:*:*:*:*:*:*",
136917          "purl": "pkg:rpm/rhel/json-glib@1.4.4-1.el8?arch=x86_64\u0026upstream=json-glib-1.4.4-1.el8.src.rpm\u0026distro=rhel-8.6",
136918          "swid": {
136919            "attachment": {}
136920          },
136921          "pedigree": {},
136922          "evidence": {},
136923          "signature": {
136924            "signature": {
136925              "publicKey": {}
136926            }
136927          },
136928          "modelCard": {
136929            "modelParameters": {
136930              "approach": {}
136931            },
136932            "quantitativeAnalysis": {
136933              "graphics": {}
136934            },
136935            "considerations": {}
136936          }
136937        },
136938        {
136939          "type": "library",
136940          "bom-ref": "pkg:rpm/rhel/keyutils-libs@1.5.10-9.el8?arch=x86_64\u0026upstream=keyutils-1.5.10-9.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=4843e44e4d426358",
136941          "supplier": {},
136942          "publisher": "Red Hat, Inc.",
136943          "name": "keyutils-libs",
136944          "version": "1.5.10-9.el8",
136945          "licenses": [
136946            {
136947              "license": {
136948                "name": "GPLv2+ and LGPLv2+"
136949              }
136950            }
136951          ],
136952          "cpe": "cpe:2.3:a:keyutils-libs:keyutils-libs:1.5.10-9.el8:*:*:*:*:*:*:*",
136953          "purl": "pkg:rpm/rhel/keyutils-libs@1.5.10-9.el8?arch=x86_64\u0026upstream=keyutils-1.5.10-9.el8.src.rpm\u0026distro=rhel-8.6",
136954          "swid": {
136955            "attachment": {}
136956          },
136957          "pedigree": {},
136958          "evidence": {},
136959          "signature": {
136960            "signature": {
136961              "publicKey": {}
136962            }
136963          },
136964          "modelCard": {
136965            "modelParameters": {
136966              "approach": {}
136967            },
136968            "quantitativeAnalysis": {
136969              "graphics": {}
136970            },
136971            "considerations": {}
136972          }
136973        },
136974        {
136975          "type": "library",
136976          "bom-ref": "pkg:rpm/rhel/krb5-libs@1.18.2-14.el8?arch=x86_64\u0026upstream=krb5-1.18.2-14.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=35fc2060ec0378b3",
136977          "supplier": {},
136978          "publisher": "Red Hat, Inc.",
136979          "name": "krb5-libs",
136980          "version": "1.18.2-14.el8",
136981          "licenses": [
136982            {
136983              "license": {
136984                "id": "MIT"
136985              }
136986            }
136987          ],
136988          "cpe": "cpe:2.3:a:krb5-libs:krb5-libs:1.18.2-14.el8:*:*:*:*:*:*:*",
136989          "purl": "pkg:rpm/rhel/krb5-libs@1.18.2-14.el8?arch=x86_64\u0026upstream=krb5-1.18.2-14.el8.src.rpm\u0026distro=rhel-8.6",
136990          "swid": {
136991            "attachment": {}
136992          },
136993          "pedigree": {},
136994          "evidence": {},
136995          "signature": {
136996            "signature": {
136997              "publicKey": {}
136998            }
136999          },
137000          "modelCard": {
137001            "modelParameters": {
137002              "approach": {}
137003            },
137004            "quantitativeAnalysis": {
137005              "graphics": {}
137006            },
137007            "considerations": {}
137008          }
137009        },
137010        {
137011          "type": "library",
137012          "bom-ref": "pkg:rpm/rhel/langpacks-en@1.0-12.el8?arch=noarch\u0026upstream=langpacks-1.0-12.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=6a756e34249d314a",
137013          "supplier": {},
137014          "publisher": "Red Hat, Inc.",
137015          "name": "langpacks-en",
137016          "version": "1.0-12.el8",
137017          "licenses": [
137018            {
137019              "license": {
137020                "name": "GPLv2+"
137021              }
137022            }
137023          ],
137024          "cpe": "cpe:2.3:a:langpacks-en:langpacks-en:1.0-12.el8:*:*:*:*:*:*:*",
137025          "purl": "pkg:rpm/rhel/langpacks-en@1.0-12.el8?arch=noarch\u0026upstream=langpacks-1.0-12.el8.src.rpm\u0026distro=rhel-8.6",
137026          "swid": {
137027            "attachment": {}
137028          },
137029          "pedigree": {},
137030          "evidence": {},
137031          "signature": {
137032            "signature": {
137033              "publicKey": {}
137034            }
137035          },
137036          "modelCard": {
137037            "modelParameters": {
137038              "approach": {}
137039            },
137040            "quantitativeAnalysis": {
137041              "graphics": {}
137042            },
137043            "considerations": {}
137044          }
137045        },
137046        {
137047          "type": "library",
137048          "bom-ref": "pkg:rpm/rhel/libacl@2.2.53-1.el8?arch=x86_64\u0026upstream=acl-2.2.53-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=8d0e2ddb3a76c2e3",
137049          "supplier": {},
137050          "publisher": "Red Hat, Inc.",
137051          "name": "libacl",
137052          "version": "2.2.53-1.el8",
137053          "licenses": [
137054            {
137055              "license": {
137056                "name": "LGPLv2+"
137057              }
137058            }
137059          ],
137060          "cpe": "cpe:2.3:a:libacl:libacl:2.2.53-1.el8:*:*:*:*:*:*:*",
137061          "purl": "pkg:rpm/rhel/libacl@2.2.53-1.el8?arch=x86_64\u0026upstream=acl-2.2.53-1.el8.src.rpm\u0026distro=rhel-8.6",
137062          "swid": {
137063            "attachment": {}
137064          },
137065          "pedigree": {},
137066          "evidence": {},
137067          "signature": {
137068            "signature": {
137069              "publicKey": {}
137070            }
137071          },
137072          "modelCard": {
137073            "modelParameters": {
137074              "approach": {}
137075            },
137076            "quantitativeAnalysis": {
137077              "graphics": {}
137078            },
137079            "considerations": {}
137080          }
137081        },
137082        {
137083          "type": "library",
137084          "bom-ref": "pkg:rpm/rhel/libarchive@3.3.3-3.el8_5?arch=x86_64\u0026upstream=libarchive-3.3.3-3.el8_5.src.rpm\u0026distro=rhel-8.6\u0026package-id=884bcc48382677ea",
137085          "supplier": {},
137086          "publisher": "Red Hat, Inc.",
137087          "name": "libarchive",
137088          "version": "3.3.3-3.el8_5",
137089          "licenses": [
137090            {
137091              "license": {
137092                "name": "BSD"
137093              }
137094            }
137095          ],
137096          "cpe": "cpe:2.3:a:libarchive:libarchive:3.3.3-3.el8_5:*:*:*:*:*:*:*",
137097          "purl": "pkg:rpm/rhel/libarchive@3.3.3-3.el8_5?arch=x86_64\u0026upstream=libarchive-3.3.3-3.el8_5.src.rpm\u0026distro=rhel-8.6",
137098          "swid": {
137099            "attachment": {}
137100          },
137101          "pedigree": {},
137102          "evidence": {},
137103          "signature": {
137104            "signature": {
137105              "publicKey": {}
137106            }
137107          },
137108          "modelCard": {
137109            "modelParameters": {
137110              "approach": {}
137111            },
137112            "quantitativeAnalysis": {
137113              "graphics": {}
137114            },
137115            "considerations": {}
137116          }
137117        },
137118        {
137119          "type": "library",
137120          "bom-ref": "pkg:rpm/rhel/libassuan@2.5.1-3.el8?arch=x86_64\u0026upstream=libassuan-2.5.1-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=f49e816e114b317",
137121          "supplier": {},
137122          "publisher": "Red Hat, Inc.",
137123          "name": "libassuan",
137124          "version": "2.5.1-3.el8",
137125          "licenses": [
137126            {
137127              "license": {
137128                "name": "LGPLv2+ and GPLv3+"
137129              }
137130            }
137131          ],
137132          "cpe": "cpe:2.3:a:libassuan:libassuan:2.5.1-3.el8:*:*:*:*:*:*:*",
137133          "purl": "pkg:rpm/rhel/libassuan@2.5.1-3.el8?arch=x86_64\u0026upstream=libassuan-2.5.1-3.el8.src.rpm\u0026distro=rhel-8.6",
137134          "swid": {
137135            "attachment": {}
137136          },
137137          "pedigree": {},
137138          "evidence": {},
137139          "signature": {
137140            "signature": {
137141              "publicKey": {}
137142            }
137143          },
137144          "modelCard": {
137145            "modelParameters": {
137146              "approach": {}
137147            },
137148            "quantitativeAnalysis": {
137149              "graphics": {}
137150            },
137151            "considerations": {}
137152          }
137153        },
137154        {
137155          "type": "library",
137156          "bom-ref": "pkg:rpm/rhel/libattr@2.4.48-3.el8?arch=x86_64\u0026upstream=attr-2.4.48-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=1dfb79cdce2c79df",
137157          "supplier": {},
137158          "publisher": "Red Hat, Inc.",
137159          "name": "libattr",
137160          "version": "2.4.48-3.el8",
137161          "licenses": [
137162            {
137163              "license": {
137164                "name": "LGPLv2+"
137165              }
137166            }
137167          ],
137168          "cpe": "cpe:2.3:a:libattr:libattr:2.4.48-3.el8:*:*:*:*:*:*:*",
137169          "purl": "pkg:rpm/rhel/libattr@2.4.48-3.el8?arch=x86_64\u0026upstream=attr-2.4.48-3.el8.src.rpm\u0026distro=rhel-8.6",
137170          "swid": {
137171            "attachment": {}
137172          },
137173          "pedigree": {},
137174          "evidence": {},
137175          "signature": {
137176            "signature": {
137177              "publicKey": {}
137178            }
137179          },
137180          "modelCard": {
137181            "modelParameters": {
137182              "approach": {}
137183            },
137184            "quantitativeAnalysis": {
137185              "graphics": {}
137186            },
137187            "considerations": {}
137188          }
137189        },
137190        {
137191          "type": "library",
137192          "bom-ref": "pkg:rpm/rhel/libblkid@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=b42771a3f27629d0",
137193          "supplier": {},
137194          "publisher": "Red Hat, Inc.",
137195          "name": "libblkid",
137196          "version": "2.32.1-35.el8",
137197          "licenses": [
137198            {
137199              "license": {
137200                "name": "LGPLv2+"
137201              }
137202            }
137203          ],
137204          "cpe": "cpe:2.3:a:libblkid:libblkid:2.32.1-35.el8:*:*:*:*:*:*:*",
137205          "purl": "pkg:rpm/rhel/libblkid@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6",
137206          "swid": {
137207            "attachment": {}
137208          },
137209          "pedigree": {},
137210          "evidence": {},
137211          "signature": {
137212            "signature": {
137213              "publicKey": {}
137214            }
137215          },
137216          "modelCard": {
137217            "modelParameters": {
137218              "approach": {}
137219            },
137220            "quantitativeAnalysis": {
137221              "graphics": {}
137222            },
137223            "considerations": {}
137224          }
137225        },
137226        {
137227          "type": "library",
137228          "bom-ref": "pkg:rpm/rhel/libcap@2.48-2.el8?arch=x86_64\u0026upstream=libcap-2.48-2.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=50b24d19d2895760",
137229          "supplier": {},
137230          "publisher": "Red Hat, Inc.",
137231          "name": "libcap",
137232          "version": "2.48-2.el8",
137233          "licenses": [
137234            {
137235              "license": {
137236                "name": "BSD or GPLv2"
137237              }
137238            }
137239          ],
137240          "cpe": "cpe:2.3:a:libcap:libcap:2.48-2.el8:*:*:*:*:*:*:*",
137241          "purl": "pkg:rpm/rhel/libcap@2.48-2.el8?arch=x86_64\u0026upstream=libcap-2.48-2.el8.src.rpm\u0026distro=rhel-8.6",
137242          "swid": {
137243            "attachment": {}
137244          },
137245          "pedigree": {},
137246          "evidence": {},
137247          "signature": {
137248            "signature": {
137249              "publicKey": {}
137250            }
137251          },
137252          "modelCard": {
137253            "modelParameters": {
137254              "approach": {}
137255            },
137256            "quantitativeAnalysis": {
137257              "graphics": {}
137258            },
137259            "considerations": {}
137260          }
137261        },
137262        {
137263          "type": "library",
137264          "bom-ref": "pkg:rpm/rhel/libcap-ng@0.7.11-1.el8?arch=x86_64\u0026upstream=libcap-ng-0.7.11-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=38a5e4ba1e6410f5",
137265          "supplier": {},
137266          "publisher": "Red Hat, Inc.",
137267          "name": "libcap-ng",
137268          "version": "0.7.11-1.el8",
137269          "licenses": [
137270            {
137271              "license": {
137272                "name": "LGPLv2+"
137273              }
137274            }
137275          ],
137276          "cpe": "cpe:2.3:a:libcap-ng:libcap-ng:0.7.11-1.el8:*:*:*:*:*:*:*",
137277          "purl": "pkg:rpm/rhel/libcap-ng@0.7.11-1.el8?arch=x86_64\u0026upstream=libcap-ng-0.7.11-1.el8.src.rpm\u0026distro=rhel-8.6",
137278          "swid": {
137279            "attachment": {}
137280          },
137281          "pedigree": {},
137282          "evidence": {},
137283          "signature": {
137284            "signature": {
137285              "publicKey": {}
137286            }
137287          },
137288          "modelCard": {
137289            "modelParameters": {
137290              "approach": {}
137291            },
137292            "quantitativeAnalysis": {
137293              "graphics": {}
137294            },
137295            "considerations": {}
137296          }
137297        },
137298        {
137299          "type": "library",
137300          "bom-ref": "pkg:rpm/rhel/libcom_err@1.45.6-4.el8?arch=x86_64\u0026upstream=e2fsprogs-1.45.6-4.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=f169b3a1502aae2e",
137301          "supplier": {},
137302          "publisher": "Red Hat, Inc.",
137303          "name": "libcom_err",
137304          "version": "1.45.6-4.el8",
137305          "licenses": [
137306            {
137307              "license": {
137308                "id": "MIT"
137309              }
137310            }
137311          ],
137312          "cpe": "cpe:2.3:a:libcom-err:libcom-err:1.45.6-4.el8:*:*:*:*:*:*:*",
137313          "purl": "pkg:rpm/rhel/libcom_err@1.45.6-4.el8?arch=x86_64\u0026upstream=e2fsprogs-1.45.6-4.el8.src.rpm\u0026distro=rhel-8.6",
137314          "swid": {
137315            "attachment": {}
137316          },
137317          "pedigree": {},
137318          "evidence": {},
137319          "signature": {
137320            "signature": {
137321              "publicKey": {}
137322            }
137323          },
137324          "modelCard": {
137325            "modelParameters": {
137326              "approach": {}
137327            },
137328            "quantitativeAnalysis": {
137329              "graphics": {}
137330            },
137331            "considerations": {}
137332          }
137333        },
137334        {
137335          "type": "library",
137336          "bom-ref": "pkg:rpm/rhel/libcurl@7.61.1-22.el8_6.4?arch=x86_64\u0026upstream=curl-7.61.1-22.el8_6.4.src.rpm\u0026distro=rhel-8.6\u0026package-id=8d84eb64bd8655f3",
137337          "supplier": {},
137338          "publisher": "Red Hat, Inc.",
137339          "name": "libcurl",
137340          "version": "7.61.1-22.el8_6.4",
137341          "licenses": [
137342            {
137343              "license": {
137344                "id": "MIT"
137345              }
137346            }
137347          ],
137348          "cpe": "cpe:2.3:a:libcurl:libcurl:7.61.1-22.el8_6.4:*:*:*:*:*:*:*",
137349          "purl": "pkg:rpm/rhel/libcurl@7.61.1-22.el8_6.4?arch=x86_64\u0026upstream=curl-7.61.1-22.el8_6.4.src.rpm\u0026distro=rhel-8.6",
137350          "swid": {
137351            "attachment": {}
137352          },
137353          "pedigree": {},
137354          "evidence": {},
137355          "signature": {
137356            "signature": {
137357              "publicKey": {}
137358            }
137359          },
137360          "modelCard": {
137361            "modelParameters": {
137362              "approach": {}
137363            },
137364            "quantitativeAnalysis": {
137365              "graphics": {}
137366            },
137367            "considerations": {}
137368          }
137369        },
137370        {
137371          "type": "library",
137372          "bom-ref": "pkg:rpm/rhel/libdb@5.3.28-42.el8_4?arch=x86_64\u0026upstream=libdb-5.3.28-42.el8_4.src.rpm\u0026distro=rhel-8.6\u0026package-id=aa9ac1b53ca22450",
137373          "supplier": {},
137374          "publisher": "Red Hat, Inc.",
137375          "name": "libdb",
137376          "version": "5.3.28-42.el8_4",
137377          "licenses": [
137378            {
137379              "license": {
137380                "name": "BSD and LGPLv2 and Sleepycat"
137381              }
137382            }
137383          ],
137384          "cpe": "cpe:2.3:a:redhat:libdb:5.3.28-42.el8_4:*:*:*:*:*:*:*",
137385          "purl": "pkg:rpm/rhel/libdb@5.3.28-42.el8_4?arch=x86_64\u0026upstream=libdb-5.3.28-42.el8_4.src.rpm\u0026distro=rhel-8.6",
137386          "swid": {
137387            "attachment": {}
137388          },
137389          "pedigree": {},
137390          "evidence": {},
137391          "signature": {
137392            "signature": {
137393              "publicKey": {}
137394            }
137395          },
137396          "modelCard": {
137397            "modelParameters": {
137398              "approach": {}
137399            },
137400            "quantitativeAnalysis": {
137401              "graphics": {}
137402            },
137403            "considerations": {}
137404          }
137405        },
137406        {
137407          "type": "library",
137408          "bom-ref": "pkg:rpm/rhel/libdb-utils@5.3.28-42.el8_4?arch=x86_64\u0026upstream=libdb-5.3.28-42.el8_4.src.rpm\u0026distro=rhel-8.6\u0026package-id=c05e0e0d0c33b43f",
137409          "supplier": {},
137410          "publisher": "Red Hat, Inc.",
137411          "name": "libdb-utils",
137412          "version": "5.3.28-42.el8_4",
137413          "licenses": [
137414            {
137415              "license": {
137416                "name": "BSD and LGPLv2 and Sleepycat"
137417              }
137418            }
137419          ],
137420          "cpe": "cpe:2.3:a:libdb-utils:libdb-utils:5.3.28-42.el8_4:*:*:*:*:*:*:*",
137421          "purl": "pkg:rpm/rhel/libdb-utils@5.3.28-42.el8_4?arch=x86_64\u0026upstream=libdb-5.3.28-42.el8_4.src.rpm\u0026distro=rhel-8.6",
137422          "swid": {
137423            "attachment": {}
137424          },
137425          "pedigree": {},
137426          "evidence": {},
137427          "signature": {
137428            "signature": {
137429              "publicKey": {}
137430            }
137431          },
137432          "modelCard": {
137433            "modelParameters": {
137434              "approach": {}
137435            },
137436            "quantitativeAnalysis": {
137437              "graphics": {}
137438            },
137439            "considerations": {}
137440          }
137441        },
137442        {
137443          "type": "library",
137444          "bom-ref": "pkg:rpm/rhel/libdnf@0.63.0-8.2.el8_6?arch=x86_64\u0026upstream=libdnf-0.63.0-8.2.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=e910aae5404bf2ce",
137445          "supplier": {},
137446          "publisher": "Red Hat, Inc.",
137447          "name": "libdnf",
137448          "version": "0.63.0-8.2.el8_6",
137449          "licenses": [
137450            {
137451              "license": {
137452                "name": "LGPLv2+"
137453              }
137454            }
137455          ],
137456          "cpe": "cpe:2.3:a:libdnf:libdnf:0.63.0-8.2.el8_6:*:*:*:*:*:*:*",
137457          "purl": "pkg:rpm/rhel/libdnf@0.63.0-8.2.el8_6?arch=x86_64\u0026upstream=libdnf-0.63.0-8.2.el8_6.src.rpm\u0026distro=rhel-8.6",
137458          "swid": {
137459            "attachment": {}
137460          },
137461          "pedigree": {},
137462          "evidence": {},
137463          "signature": {
137464            "signature": {
137465              "publicKey": {}
137466            }
137467          },
137468          "modelCard": {
137469            "modelParameters": {
137470              "approach": {}
137471            },
137472            "quantitativeAnalysis": {
137473              "graphics": {}
137474            },
137475            "considerations": {}
137476          }
137477        },
137478        {
137479          "type": "library",
137480          "bom-ref": "pkg:rpm/rhel/libfdisk@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=57375ea754a066f5",
137481          "supplier": {},
137482          "publisher": "Red Hat, Inc.",
137483          "name": "libfdisk",
137484          "version": "2.32.1-35.el8",
137485          "licenses": [
137486            {
137487              "license": {
137488                "name": "LGPLv2+"
137489              }
137490            }
137491          ],
137492          "cpe": "cpe:2.3:a:libfdisk:libfdisk:2.32.1-35.el8:*:*:*:*:*:*:*",
137493          "purl": "pkg:rpm/rhel/libfdisk@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6",
137494          "swid": {
137495            "attachment": {}
137496          },
137497          "pedigree": {},
137498          "evidence": {},
137499          "signature": {
137500            "signature": {
137501              "publicKey": {}
137502            }
137503          },
137504          "modelCard": {
137505            "modelParameters": {
137506              "approach": {}
137507            },
137508            "quantitativeAnalysis": {
137509              "graphics": {}
137510            },
137511            "considerations": {}
137512          }
137513        },
137514        {
137515          "type": "library",
137516          "bom-ref": "pkg:rpm/rhel/libffi@3.1-23.el8?arch=x86_64\u0026upstream=libffi-3.1-23.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=c5672d2a9bd45225",
137517          "supplier": {},
137518          "publisher": "Red Hat, Inc.",
137519          "name": "libffi",
137520          "version": "3.1-23.el8",
137521          "licenses": [
137522            {
137523              "license": {
137524                "id": "MIT"
137525              }
137526            }
137527          ],
137528          "cpe": "cpe:2.3:a:libffi:libffi:3.1-23.el8:*:*:*:*:*:*:*",
137529          "purl": "pkg:rpm/rhel/libffi@3.1-23.el8?arch=x86_64\u0026upstream=libffi-3.1-23.el8.src.rpm\u0026distro=rhel-8.6",
137530          "swid": {
137531            "attachment": {}
137532          },
137533          "pedigree": {},
137534          "evidence": {},
137535          "signature": {
137536            "signature": {
137537              "publicKey": {}
137538            }
137539          },
137540          "modelCard": {
137541            "modelParameters": {
137542              "approach": {}
137543            },
137544            "quantitativeAnalysis": {
137545              "graphics": {}
137546            },
137547            "considerations": {}
137548          }
137549        },
137550        {
137551          "type": "library",
137552          "bom-ref": "pkg:rpm/rhel/libgcc@8.5.0-10.1.el8_6?arch=x86_64\u0026upstream=gcc-8.5.0-10.1.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=8a0c4419338c2e5e",
137553          "supplier": {},
137554          "publisher": "Red Hat, Inc.",
137555          "name": "libgcc",
137556          "version": "8.5.0-10.1.el8_6",
137557          "licenses": [
137558            {
137559              "license": {
137560                "name": "GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"
137561              }
137562            }
137563          ],
137564          "cpe": "cpe:2.3:a:libgcc:libgcc:8.5.0-10.1.el8_6:*:*:*:*:*:*:*",
137565          "purl": "pkg:rpm/rhel/libgcc@8.5.0-10.1.el8_6?arch=x86_64\u0026upstream=gcc-8.5.0-10.1.el8_6.src.rpm\u0026distro=rhel-8.6",
137566          "swid": {
137567            "attachment": {}
137568          },
137569          "pedigree": {},
137570          "evidence": {},
137571          "signature": {
137572            "signature": {
137573              "publicKey": {}
137574            }
137575          },
137576          "modelCard": {
137577            "modelParameters": {
137578              "approach": {}
137579            },
137580            "quantitativeAnalysis": {
137581              "graphics": {}
137582            },
137583            "considerations": {}
137584          }
137585        },
137586        {
137587          "type": "library",
137588          "bom-ref": "pkg:rpm/rhel/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=b029a2bca644cc7a",
137589          "supplier": {},
137590          "publisher": "Red Hat, Inc.",
137591          "name": "libgcrypt",
137592          "version": "1.8.5-7.el8_6",
137593          "licenses": [
137594            {
137595              "license": {
137596                "name": "LGPLv2+"
137597              }
137598            }
137599          ],
137600          "cpe": "cpe:2.3:a:libgcrypt:libgcrypt:1.8.5-7.el8_6:*:*:*:*:*:*:*",
137601          "purl": "pkg:rpm/rhel/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm\u0026distro=rhel-8.6",
137602          "swid": {
137603            "attachment": {}
137604          },
137605          "pedigree": {},
137606          "evidence": {},
137607          "signature": {
137608            "signature": {
137609              "publicKey": {}
137610            }
137611          },
137612          "modelCard": {
137613            "modelParameters": {
137614              "approach": {}
137615            },
137616            "quantitativeAnalysis": {
137617              "graphics": {}
137618            },
137619            "considerations": {}
137620          }
137621        },
137622        {
137623          "type": "library",
137624          "bom-ref": "pkg:rpm/rhel/libgpg-error@1.31-1.el8?arch=x86_64\u0026upstream=libgpg-error-1.31-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=b00b5e1ee55ac62",
137625          "supplier": {},
137626          "publisher": "Red Hat, Inc.",
137627          "name": "libgpg-error",
137628          "version": "1.31-1.el8",
137629          "licenses": [
137630            {
137631              "license": {
137632                "name": "LGPLv2+"
137633              }
137634            }
137635          ],
137636          "cpe": "cpe:2.3:a:libgpg-error:libgpg-error:1.31-1.el8:*:*:*:*:*:*:*",
137637          "purl": "pkg:rpm/rhel/libgpg-error@1.31-1.el8?arch=x86_64\u0026upstream=libgpg-error-1.31-1.el8.src.rpm\u0026distro=rhel-8.6",
137638          "swid": {
137639            "attachment": {}
137640          },
137641          "pedigree": {},
137642          "evidence": {},
137643          "signature": {
137644            "signature": {
137645              "publicKey": {}
137646            }
137647          },
137648          "modelCard": {
137649            "modelParameters": {
137650              "approach": {}
137651            },
137652            "quantitativeAnalysis": {
137653              "graphics": {}
137654            },
137655            "considerations": {}
137656          }
137657        },
137658        {
137659          "type": "library",
137660          "bom-ref": "pkg:rpm/rhel/libidn2@2.2.0-1.el8?arch=x86_64\u0026upstream=libidn2-2.2.0-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=7f4404b324b19931",
137661          "supplier": {},
137662          "publisher": "Red Hat, Inc.",
137663          "name": "libidn2",
137664          "version": "2.2.0-1.el8",
137665          "licenses": [
137666            {
137667              "license": {
137668                "name": "(GPLv2+ or LGPLv3+) and GPLv3+"
137669              }
137670            }
137671          ],
137672          "cpe": "cpe:2.3:a:libidn2:libidn2:2.2.0-1.el8:*:*:*:*:*:*:*",
137673          "purl": "pkg:rpm/rhel/libidn2@2.2.0-1.el8?arch=x86_64\u0026upstream=libidn2-2.2.0-1.el8.src.rpm\u0026distro=rhel-8.6",
137674          "swid": {
137675            "attachment": {}
137676          },
137677          "pedigree": {},
137678          "evidence": {},
137679          "signature": {
137680            "signature": {
137681              "publicKey": {}
137682            }
137683          },
137684          "modelCard": {
137685            "modelParameters": {
137686              "approach": {}
137687            },
137688            "quantitativeAnalysis": {
137689              "graphics": {}
137690            },
137691            "considerations": {}
137692          }
137693        },
137694        {
137695          "type": "library",
137696          "bom-ref": "pkg:rpm/rhel/libksba@1.3.5-7.el8?arch=x86_64\u0026upstream=libksba-1.3.5-7.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=e80c3032e7b93321",
137697          "supplier": {},
137698          "publisher": "Red Hat, Inc.",
137699          "name": "libksba",
137700          "version": "1.3.5-7.el8",
137701          "licenses": [
137702            {
137703              "license": {
137704                "name": "(LGPLv3+ or GPLv2+) and GPLv3+"
137705              }
137706            }
137707          ],
137708          "cpe": "cpe:2.3:a:libksba:libksba:1.3.5-7.el8:*:*:*:*:*:*:*",
137709          "purl": "pkg:rpm/rhel/libksba@1.3.5-7.el8?arch=x86_64\u0026upstream=libksba-1.3.5-7.el8.src.rpm\u0026distro=rhel-8.6",
137710          "swid": {
137711            "attachment": {}
137712          },
137713          "pedigree": {},
137714          "evidence": {},
137715          "signature": {
137716            "signature": {
137717              "publicKey": {}
137718            }
137719          },
137720          "modelCard": {
137721            "modelParameters": {
137722              "approach": {}
137723            },
137724            "quantitativeAnalysis": {
137725              "graphics": {}
137726            },
137727            "considerations": {}
137728          }
137729        },
137730        {
137731          "type": "library",
137732          "bom-ref": "pkg:rpm/rhel/libksba@1.3.5-8.el8_6?arch=x86_64\u0026upstream=libksba-1.3.5-8.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=a48aeeecdff2040a",
137733          "supplier": {},
137734          "publisher": "Red Hat, Inc.",
137735          "name": "libksba",
137736          "version": "1.3.5-8.el8_6",
137737          "licenses": [
137738            {
137739              "license": {
137740                "name": "(LGPLv3+ or GPLv2+) and GPLv3+"
137741              }
137742            }
137743          ],
137744          "cpe": "cpe:2.3:a:libksba:libksba:1.3.5-8.el8_6:*:*:*:*:*:*:*",
137745          "purl": "pkg:rpm/rhel/libksba@1.3.5-8.el8_6?arch=x86_64\u0026upstream=libksba-1.3.5-8.el8_6.src.rpm\u0026distro=rhel-8.6",
137746          "swid": {
137747            "attachment": {}
137748          },
137749          "pedigree": {},
137750          "evidence": {},
137751          "signature": {
137752            "signature": {
137753              "publicKey": {}
137754            }
137755          },
137756          "modelCard": {
137757            "modelParameters": {
137758              "approach": {}
137759            },
137760            "quantitativeAnalysis": {
137761              "graphics": {}
137762            },
137763            "considerations": {}
137764          }
137765        },
137766        {
137767          "type": "library",
137768          "bom-ref": "pkg:rpm/rhel/libmodulemd@2.13.0-1.el8?arch=x86_64\u0026upstream=libmodulemd-2.13.0-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=eff3a2ff49c573e9",
137769          "supplier": {},
137770          "publisher": "Red Hat, Inc.",
137771          "name": "libmodulemd",
137772          "version": "2.13.0-1.el8",
137773          "licenses": [
137774            {
137775              "license": {
137776                "id": "MIT"
137777              }
137778            }
137779          ],
137780          "cpe": "cpe:2.3:a:libmodulemd:libmodulemd:2.13.0-1.el8:*:*:*:*:*:*:*",
137781          "purl": "pkg:rpm/rhel/libmodulemd@2.13.0-1.el8?arch=x86_64\u0026upstream=libmodulemd-2.13.0-1.el8.src.rpm\u0026distro=rhel-8.6",
137782          "swid": {
137783            "attachment": {}
137784          },
137785          "pedigree": {},
137786          "evidence": {},
137787          "signature": {
137788            "signature": {
137789              "publicKey": {}
137790            }
137791          },
137792          "modelCard": {
137793            "modelParameters": {
137794              "approach": {}
137795            },
137796            "quantitativeAnalysis": {
137797              "graphics": {}
137798            },
137799            "considerations": {}
137800          }
137801        },
137802        {
137803          "type": "library",
137804          "bom-ref": "pkg:rpm/rhel/libmount@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=ed7e2c140ba9603d",
137805          "supplier": {},
137806          "publisher": "Red Hat, Inc.",
137807          "name": "libmount",
137808          "version": "2.32.1-35.el8",
137809          "licenses": [
137810            {
137811              "license": {
137812                "name": "LGPLv2+"
137813              }
137814            }
137815          ],
137816          "cpe": "cpe:2.3:a:libmount:libmount:2.32.1-35.el8:*:*:*:*:*:*:*",
137817          "purl": "pkg:rpm/rhel/libmount@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6",
137818          "swid": {
137819            "attachment": {}
137820          },
137821          "pedigree": {},
137822          "evidence": {},
137823          "signature": {
137824            "signature": {
137825              "publicKey": {}
137826            }
137827          },
137828          "modelCard": {
137829            "modelParameters": {
137830              "approach": {}
137831            },
137832            "quantitativeAnalysis": {
137833              "graphics": {}
137834            },
137835            "considerations": {}
137836          }
137837        },
137838        {
137839          "type": "library",
137840          "bom-ref": "pkg:rpm/rhel/libnghttp2@1.33.0-3.el8_2.1?arch=x86_64\u0026upstream=nghttp2-1.33.0-3.el8_2.1.src.rpm\u0026distro=rhel-8.6\u0026package-id=e18e17e678c6285a",
137841          "supplier": {},
137842          "publisher": "Red Hat, Inc.",
137843          "name": "libnghttp2",
137844          "version": "1.33.0-3.el8_2.1",
137845          "licenses": [
137846            {
137847              "license": {
137848                "id": "MIT"
137849              }
137850            }
137851          ],
137852          "cpe": "cpe:2.3:a:libnghttp2:libnghttp2:1.33.0-3.el8_2.1:*:*:*:*:*:*:*",
137853          "purl": "pkg:rpm/rhel/libnghttp2@1.33.0-3.el8_2.1?arch=x86_64\u0026upstream=nghttp2-1.33.0-3.el8_2.1.src.rpm\u0026distro=rhel-8.6",
137854          "swid": {
137855            "attachment": {}
137856          },
137857          "pedigree": {},
137858          "evidence": {},
137859          "signature": {
137860            "signature": {
137861              "publicKey": {}
137862            }
137863          },
137864          "modelCard": {
137865            "modelParameters": {
137866              "approach": {}
137867            },
137868            "quantitativeAnalysis": {
137869              "graphics": {}
137870            },
137871            "considerations": {}
137872          }
137873        },
137874        {
137875          "type": "library",
137876          "bom-ref": "pkg:rpm/rhel/libnsl2@1.2.0-2.20180605git4a062cf.el8?arch=x86_64\u0026upstream=libnsl2-1.2.0-2.20180605git4a062cf.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=d41b62920a081480",
137877          "supplier": {},
137878          "publisher": "Red Hat, Inc.",
137879          "name": "libnsl2",
137880          "version": "1.2.0-2.20180605git4a062cf.el8",
137881          "licenses": [
137882            {
137883              "license": {
137884                "name": "BSD and LGPLv2+"
137885              }
137886            }
137887          ],
137888          "cpe": "cpe:2.3:a:libnsl2:libnsl2:1.2.0-2.20180605git4a062cf.el8:*:*:*:*:*:*:*",
137889          "purl": "pkg:rpm/rhel/libnsl2@1.2.0-2.20180605git4a062cf.el8?arch=x86_64\u0026upstream=libnsl2-1.2.0-2.20180605git4a062cf.el8.src.rpm\u0026distro=rhel-8.6",
137890          "swid": {
137891            "attachment": {}
137892          },
137893          "pedigree": {},
137894          "evidence": {},
137895          "signature": {
137896            "signature": {
137897              "publicKey": {}
137898            }
137899          },
137900          "modelCard": {
137901            "modelParameters": {
137902              "approach": {}
137903            },
137904            "quantitativeAnalysis": {
137905              "graphics": {}
137906            },
137907            "considerations": {}
137908          }
137909        },
137910        {
137911          "type": "library",
137912          "bom-ref": "pkg:rpm/rhel/libpeas@1.22.0-6.el8?arch=x86_64\u0026upstream=libpeas-1.22.0-6.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=67d4a12e0310f9b7",
137913          "supplier": {},
137914          "publisher": "Red Hat, Inc.",
137915          "name": "libpeas",
137916          "version": "1.22.0-6.el8",
137917          "licenses": [
137918            {
137919              "license": {
137920                "name": "LGPLv2+"
137921              }
137922            }
137923          ],
137924          "cpe": "cpe:2.3:a:libpeas:libpeas:1.22.0-6.el8:*:*:*:*:*:*:*",
137925          "purl": "pkg:rpm/rhel/libpeas@1.22.0-6.el8?arch=x86_64\u0026upstream=libpeas-1.22.0-6.el8.src.rpm\u0026distro=rhel-8.6",
137926          "swid": {
137927            "attachment": {}
137928          },
137929          "pedigree": {},
137930          "evidence": {},
137931          "signature": {
137932            "signature": {
137933              "publicKey": {}
137934            }
137935          },
137936          "modelCard": {
137937            "modelParameters": {
137938              "approach": {}
137939            },
137940            "quantitativeAnalysis": {
137941              "graphics": {}
137942            },
137943            "considerations": {}
137944          }
137945        },
137946        {
137947          "type": "library",
137948          "bom-ref": "pkg:rpm/rhel/libpsl@0.20.2-6.el8?arch=x86_64\u0026upstream=libpsl-0.20.2-6.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=2371ea567af586ed",
137949          "supplier": {},
137950          "publisher": "Red Hat, Inc.",
137951          "name": "libpsl",
137952          "version": "0.20.2-6.el8",
137953          "licenses": [
137954            {
137955              "license": {
137956                "id": "MIT"
137957              }
137958            }
137959          ],
137960          "cpe": "cpe:2.3:a:libpsl:libpsl:0.20.2-6.el8:*:*:*:*:*:*:*",
137961          "purl": "pkg:rpm/rhel/libpsl@0.20.2-6.el8?arch=x86_64\u0026upstream=libpsl-0.20.2-6.el8.src.rpm\u0026distro=rhel-8.6",
137962          "swid": {
137963            "attachment": {}
137964          },
137965          "pedigree": {},
137966          "evidence": {},
137967          "signature": {
137968            "signature": {
137969              "publicKey": {}
137970            }
137971          },
137972          "modelCard": {
137973            "modelParameters": {
137974              "approach": {}
137975            },
137976            "quantitativeAnalysis": {
137977              "graphics": {}
137978            },
137979            "considerations": {}
137980          }
137981        },
137982        {
137983          "type": "library",
137984          "bom-ref": "pkg:rpm/rhel/libpwquality@1.4.4-3.el8?arch=x86_64\u0026upstream=libpwquality-1.4.4-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=ece84021fc5f51fe",
137985          "supplier": {},
137986          "publisher": "Red Hat, Inc.",
137987          "name": "libpwquality",
137988          "version": "1.4.4-3.el8",
137989          "licenses": [
137990            {
137991              "license": {
137992                "name": "BSD or GPLv2+"
137993              }
137994            }
137995          ],
137996          "cpe": "cpe:2.3:a:libpwquality:libpwquality:1.4.4-3.el8:*:*:*:*:*:*:*",
137997          "purl": "pkg:rpm/rhel/libpwquality@1.4.4-3.el8?arch=x86_64\u0026upstream=libpwquality-1.4.4-3.el8.src.rpm\u0026distro=rhel-8.6",
137998          "swid": {
137999            "attachment": {}
138000          },
138001          "pedigree": {},
138002          "evidence": {},
138003          "signature": {
138004            "signature": {
138005              "publicKey": {}
138006            }
138007          },
138008          "modelCard": {
138009            "modelParameters": {
138010              "approach": {}
138011            },
138012            "quantitativeAnalysis": {
138013              "graphics": {}
138014            },
138015            "considerations": {}
138016          }
138017        },
138018        {
138019          "type": "library",
138020          "bom-ref": "pkg:rpm/rhel/librepo@1.14.2-1.el8?arch=x86_64\u0026upstream=librepo-1.14.2-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=f75a7bac253d6105",
138021          "supplier": {},
138022          "publisher": "Red Hat, Inc.",
138023          "name": "librepo",
138024          "version": "1.14.2-1.el8",
138025          "licenses": [
138026            {
138027              "license": {
138028                "name": "LGPLv2+"
138029              }
138030            }
138031          ],
138032          "cpe": "cpe:2.3:a:librepo:librepo:1.14.2-1.el8:*:*:*:*:*:*:*",
138033          "purl": "pkg:rpm/rhel/librepo@1.14.2-1.el8?arch=x86_64\u0026upstream=librepo-1.14.2-1.el8.src.rpm\u0026distro=rhel-8.6",
138034          "swid": {
138035            "attachment": {}
138036          },
138037          "pedigree": {},
138038          "evidence": {},
138039          "signature": {
138040            "signature": {
138041              "publicKey": {}
138042            }
138043          },
138044          "modelCard": {
138045            "modelParameters": {
138046              "approach": {}
138047            },
138048            "quantitativeAnalysis": {
138049              "graphics": {}
138050            },
138051            "considerations": {}
138052          }
138053        },
138054        {
138055          "type": "library",
138056          "bom-ref": "pkg:rpm/rhel/librhsm@0.0.3-4.el8?arch=x86_64\u0026upstream=librhsm-0.0.3-4.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=c46786473351d412",
138057          "supplier": {},
138058          "publisher": "Red Hat, Inc.",
138059          "name": "librhsm",
138060          "version": "0.0.3-4.el8",
138061          "licenses": [
138062            {
138063              "license": {
138064                "name": "LGPLv2+"
138065              }
138066            }
138067          ],
138068          "cpe": "cpe:2.3:a:librhsm:librhsm:0.0.3-4.el8:*:*:*:*:*:*:*",
138069          "purl": "pkg:rpm/rhel/librhsm@0.0.3-4.el8?arch=x86_64\u0026upstream=librhsm-0.0.3-4.el8.src.rpm\u0026distro=rhel-8.6",
138070          "swid": {
138071            "attachment": {}
138072          },
138073          "pedigree": {},
138074          "evidence": {},
138075          "signature": {
138076            "signature": {
138077              "publicKey": {}
138078            }
138079          },
138080          "modelCard": {
138081            "modelParameters": {
138082              "approach": {}
138083            },
138084            "quantitativeAnalysis": {
138085              "graphics": {}
138086            },
138087            "considerations": {}
138088          }
138089        },
138090        {
138091          "type": "library",
138092          "bom-ref": "pkg:rpm/rhel/libselinux@2.9-5.el8?arch=x86_64\u0026upstream=libselinux-2.9-5.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=a09f64b9b7008311",
138093          "supplier": {},
138094          "publisher": "Red Hat, Inc.",
138095          "name": "libselinux",
138096          "version": "2.9-5.el8",
138097          "licenses": [
138098            {
138099              "license": {
138100                "name": "Public Domain"
138101              }
138102            }
138103          ],
138104          "cpe": "cpe:2.3:a:libselinux:libselinux:2.9-5.el8:*:*:*:*:*:*:*",
138105          "purl": "pkg:rpm/rhel/libselinux@2.9-5.el8?arch=x86_64\u0026upstream=libselinux-2.9-5.el8.src.rpm\u0026distro=rhel-8.6",
138106          "swid": {
138107            "attachment": {}
138108          },
138109          "pedigree": {},
138110          "evidence": {},
138111          "signature": {
138112            "signature": {
138113              "publicKey": {}
138114            }
138115          },
138116          "modelCard": {
138117            "modelParameters": {
138118              "approach": {}
138119            },
138120            "quantitativeAnalysis": {
138121              "graphics": {}
138122            },
138123            "considerations": {}
138124          }
138125        },
138126        {
138127          "type": "library",
138128          "bom-ref": "pkg:rpm/rhel/libsemanage@2.9-8.el8?arch=x86_64\u0026upstream=libsemanage-2.9-8.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=bdaa918f9e014ce3",
138129          "supplier": {},
138130          "publisher": "Red Hat, Inc.",
138131          "name": "libsemanage",
138132          "version": "2.9-8.el8",
138133          "licenses": [
138134            {
138135              "license": {
138136                "name": "LGPLv2+"
138137              }
138138            }
138139          ],
138140          "cpe": "cpe:2.3:a:libsemanage:libsemanage:2.9-8.el8:*:*:*:*:*:*:*",
138141          "purl": "pkg:rpm/rhel/libsemanage@2.9-8.el8?arch=x86_64\u0026upstream=libsemanage-2.9-8.el8.src.rpm\u0026distro=rhel-8.6",
138142          "swid": {
138143            "attachment": {}
138144          },
138145          "pedigree": {},
138146          "evidence": {},
138147          "signature": {
138148            "signature": {
138149              "publicKey": {}
138150            }
138151          },
138152          "modelCard": {
138153            "modelParameters": {
138154              "approach": {}
138155            },
138156            "quantitativeAnalysis": {
138157              "graphics": {}
138158            },
138159            "considerations": {}
138160          }
138161        },
138162        {
138163          "type": "library",
138164          "bom-ref": "pkg:rpm/rhel/libsepol@2.9-3.el8?arch=x86_64\u0026upstream=libsepol-2.9-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=7998489dcc1a2869",
138165          "supplier": {},
138166          "publisher": "Red Hat, Inc.",
138167          "name": "libsepol",
138168          "version": "2.9-3.el8",
138169          "licenses": [
138170            {
138171              "license": {
138172                "name": "LGPLv2+"
138173              }
138174            }
138175          ],
138176          "cpe": "cpe:2.3:a:libsepol:libsepol:2.9-3.el8:*:*:*:*:*:*:*",
138177          "purl": "pkg:rpm/rhel/libsepol@2.9-3.el8?arch=x86_64\u0026upstream=libsepol-2.9-3.el8.src.rpm\u0026distro=rhel-8.6",
138178          "swid": {
138179            "attachment": {}
138180          },
138181          "pedigree": {},
138182          "evidence": {},
138183          "signature": {
138184            "signature": {
138185              "publicKey": {}
138186            }
138187          },
138188          "modelCard": {
138189            "modelParameters": {
138190              "approach": {}
138191            },
138192            "quantitativeAnalysis": {
138193              "graphics": {}
138194            },
138195            "considerations": {}
138196          }
138197        },
138198        {
138199          "type": "library",
138200          "bom-ref": "pkg:rpm/rhel/libsigsegv@2.11-5.el8?arch=x86_64\u0026upstream=libsigsegv-2.11-5.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=bb2a5d4309598888",
138201          "supplier": {},
138202          "publisher": "Red Hat, Inc.",
138203          "name": "libsigsegv",
138204          "version": "2.11-5.el8",
138205          "licenses": [
138206            {
138207              "license": {
138208                "name": "GPLv2+"
138209              }
138210            }
138211          ],
138212          "cpe": "cpe:2.3:a:libsigsegv:libsigsegv:2.11-5.el8:*:*:*:*:*:*:*",
138213          "purl": "pkg:rpm/rhel/libsigsegv@2.11-5.el8?arch=x86_64\u0026upstream=libsigsegv-2.11-5.el8.src.rpm\u0026distro=rhel-8.6",
138214          "swid": {
138215            "attachment": {}
138216          },
138217          "pedigree": {},
138218          "evidence": {},
138219          "signature": {
138220            "signature": {
138221              "publicKey": {}
138222            }
138223          },
138224          "modelCard": {
138225            "modelParameters": {
138226              "approach": {}
138227            },
138228            "quantitativeAnalysis": {
138229              "graphics": {}
138230            },
138231            "considerations": {}
138232          }
138233        },
138234        {
138235          "type": "library",
138236          "bom-ref": "pkg:rpm/rhel/libsmartcols@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=181567a951582f08",
138237          "supplier": {},
138238          "publisher": "Red Hat, Inc.",
138239          "name": "libsmartcols",
138240          "version": "2.32.1-35.el8",
138241          "licenses": [
138242            {
138243              "license": {
138244                "name": "LGPLv2+"
138245              }
138246            }
138247          ],
138248          "cpe": "cpe:2.3:a:libsmartcols:libsmartcols:2.32.1-35.el8:*:*:*:*:*:*:*",
138249          "purl": "pkg:rpm/rhel/libsmartcols@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6",
138250          "swid": {
138251            "attachment": {}
138252          },
138253          "pedigree": {},
138254          "evidence": {},
138255          "signature": {
138256            "signature": {
138257              "publicKey": {}
138258            }
138259          },
138260          "modelCard": {
138261            "modelParameters": {
138262              "approach": {}
138263            },
138264            "quantitativeAnalysis": {
138265              "graphics": {}
138266            },
138267            "considerations": {}
138268          }
138269        },
138270        {
138271          "type": "library",
138272          "bom-ref": "pkg:rpm/rhel/libsodium@1.0.18-2.el8?arch=x86_64\u0026upstream=libsodium-1.0.18-2.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=79fb2ddd16d88d74",
138273          "supplier": {},
138274          "publisher": "Fedora Project",
138275          "name": "libsodium",
138276          "version": "1.0.18-2.el8",
138277          "licenses": [
138278            {
138279              "license": {
138280                "id": "ISC"
138281              }
138282            }
138283          ],
138284          "cpe": "cpe:2.3:a:fedoraproject:libsodium:1.0.18-2.el8:*:*:*:*:*:*:*",
138285          "purl": "pkg:rpm/rhel/libsodium@1.0.18-2.el8?arch=x86_64\u0026upstream=libsodium-1.0.18-2.el8.src.rpm\u0026distro=rhel-8.6",
138286          "swid": {
138287            "attachment": {}
138288          },
138289          "pedigree": {},
138290          "evidence": {},
138291          "signature": {
138292            "signature": {
138293              "publicKey": {}
138294            }
138295          },
138296          "modelCard": {
138297            "modelParameters": {
138298              "approach": {}
138299            },
138300            "quantitativeAnalysis": {
138301              "graphics": {}
138302            },
138303            "considerations": {}
138304          }
138305        },
138306        {
138307          "type": "library",
138308          "bom-ref": "pkg:rpm/rhel/libsolv@0.7.20-1.el8?arch=x86_64\u0026upstream=libsolv-0.7.20-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=22941cca64818882",
138309          "supplier": {},
138310          "publisher": "Red Hat, Inc.",
138311          "name": "libsolv",
138312          "version": "0.7.20-1.el8",
138313          "licenses": [
138314            {
138315              "license": {
138316                "name": "BSD"
138317              }
138318            }
138319          ],
138320          "cpe": "cpe:2.3:a:libsolv:libsolv:0.7.20-1.el8:*:*:*:*:*:*:*",
138321          "purl": "pkg:rpm/rhel/libsolv@0.7.20-1.el8?arch=x86_64\u0026upstream=libsolv-0.7.20-1.el8.src.rpm\u0026distro=rhel-8.6",
138322          "swid": {
138323            "attachment": {}
138324          },
138325          "pedigree": {},
138326          "evidence": {},
138327          "signature": {
138328            "signature": {
138329              "publicKey": {}
138330            }
138331          },
138332          "modelCard": {
138333            "modelParameters": {
138334              "approach": {}
138335            },
138336            "quantitativeAnalysis": {
138337              "graphics": {}
138338            },
138339            "considerations": {}
138340          }
138341        },
138342        {
138343          "type": "library",
138344          "bom-ref": "pkg:rpm/rhel/libssh@0.9.6-3.el8?arch=x86_64\u0026upstream=libssh-0.9.6-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=14db8c66be68bde7",
138345          "supplier": {},
138346          "publisher": "Red Hat, Inc.",
138347          "name": "libssh",
138348          "version": "0.9.6-3.el8",
138349          "licenses": [
138350            {
138351              "license": {
138352                "name": "LGPLv2+"
138353              }
138354            }
138355          ],
138356          "cpe": "cpe:2.3:a:libssh:libssh:0.9.6-3.el8:*:*:*:*:*:*:*",
138357          "purl": "pkg:rpm/rhel/libssh@0.9.6-3.el8?arch=x86_64\u0026upstream=libssh-0.9.6-3.el8.src.rpm\u0026distro=rhel-8.6",
138358          "swid": {
138359            "attachment": {}
138360          },
138361          "pedigree": {},
138362          "evidence": {},
138363          "signature": {
138364            "signature": {
138365              "publicKey": {}
138366            }
138367          },
138368          "modelCard": {
138369            "modelParameters": {
138370              "approach": {}
138371            },
138372            "quantitativeAnalysis": {
138373              "graphics": {}
138374            },
138375            "considerations": {}
138376          }
138377        },
138378        {
138379          "type": "library",
138380          "bom-ref": "pkg:rpm/rhel/libssh-config@0.9.6-3.el8?arch=noarch\u0026upstream=libssh-0.9.6-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=e21003e880ba05ec",
138381          "supplier": {},
138382          "publisher": "Red Hat, Inc.",
138383          "name": "libssh-config",
138384          "version": "0.9.6-3.el8",
138385          "licenses": [
138386            {
138387              "license": {
138388                "name": "LGPLv2+"
138389              }
138390            }
138391          ],
138392          "cpe": "cpe:2.3:a:libssh-config:libssh-config:0.9.6-3.el8:*:*:*:*:*:*:*",
138393          "purl": "pkg:rpm/rhel/libssh-config@0.9.6-3.el8?arch=noarch\u0026upstream=libssh-0.9.6-3.el8.src.rpm\u0026distro=rhel-8.6",
138394          "swid": {
138395            "attachment": {}
138396          },
138397          "pedigree": {},
138398          "evidence": {},
138399          "signature": {
138400            "signature": {
138401              "publicKey": {}
138402            }
138403          },
138404          "modelCard": {
138405            "modelParameters": {
138406              "approach": {}
138407            },
138408            "quantitativeAnalysis": {
138409              "graphics": {}
138410            },
138411            "considerations": {}
138412          }
138413        },
138414        {
138415          "type": "library",
138416          "bom-ref": "pkg:rpm/rhel/libstdc++@8.5.0-10.1.el8_6?arch=x86_64\u0026upstream=gcc-8.5.0-10.1.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=e7b45ccd55c431a4",
138417          "supplier": {},
138418          "publisher": "Red Hat, Inc.",
138419          "name": "libstdc++",
138420          "version": "8.5.0-10.1.el8_6",
138421          "licenses": [
138422            {
138423              "license": {
138424                "name": "GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"
138425              }
138426            }
138427          ],
138428          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:8.5.0-10.1.el8_6:*:*:*:*:*:*:*",
138429          "purl": "pkg:rpm/rhel/libstdc++@8.5.0-10.1.el8_6?arch=x86_64\u0026upstream=gcc-8.5.0-10.1.el8_6.src.rpm\u0026distro=rhel-8.6",
138430          "swid": {
138431            "attachment": {}
138432          },
138433          "pedigree": {},
138434          "evidence": {},
138435          "signature": {
138436            "signature": {
138437              "publicKey": {}
138438            }
138439          },
138440          "modelCard": {
138441            "modelParameters": {
138442              "approach": {}
138443            },
138444            "quantitativeAnalysis": {
138445              "graphics": {}
138446            },
138447            "considerations": {}
138448          }
138449        },
138450        {
138451          "type": "library",
138452          "bom-ref": "pkg:rpm/rhel/libtasn1@4.13-3.el8?arch=x86_64\u0026upstream=libtasn1-4.13-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=159c2b10da56c5c7",
138453          "supplier": {},
138454          "publisher": "Red Hat, Inc.",
138455          "name": "libtasn1",
138456          "version": "4.13-3.el8",
138457          "licenses": [
138458            {
138459              "license": {
138460                "name": "GPLv3+ and LGPLv2+"
138461              }
138462            }
138463          ],
138464          "cpe": "cpe:2.3:a:libtasn1:libtasn1:4.13-3.el8:*:*:*:*:*:*:*",
138465          "purl": "pkg:rpm/rhel/libtasn1@4.13-3.el8?arch=x86_64\u0026upstream=libtasn1-4.13-3.el8.src.rpm\u0026distro=rhel-8.6",
138466          "swid": {
138467            "attachment": {}
138468          },
138469          "pedigree": {},
138470          "evidence": {},
138471          "signature": {
138472            "signature": {
138473              "publicKey": {}
138474            }
138475          },
138476          "modelCard": {
138477            "modelParameters": {
138478              "approach": {}
138479            },
138480            "quantitativeAnalysis": {
138481              "graphics": {}
138482            },
138483            "considerations": {}
138484          }
138485        },
138486        {
138487          "type": "library",
138488          "bom-ref": "pkg:rpm/rhel/libtirpc@1.1.4-6.el8?arch=x86_64\u0026upstream=libtirpc-1.1.4-6.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=62a22749dc595cd2",
138489          "supplier": {},
138490          "publisher": "Red Hat, Inc.",
138491          "name": "libtirpc",
138492          "version": "1.1.4-6.el8",
138493          "licenses": [
138494            {
138495              "license": {
138496                "name": "SISSL and BSD"
138497              }
138498            }
138499          ],
138500          "cpe": "cpe:2.3:a:libtirpc:libtirpc:1.1.4-6.el8:*:*:*:*:*:*:*",
138501          "purl": "pkg:rpm/rhel/libtirpc@1.1.4-6.el8?arch=x86_64\u0026upstream=libtirpc-1.1.4-6.el8.src.rpm\u0026distro=rhel-8.6",
138502          "swid": {
138503            "attachment": {}
138504          },
138505          "pedigree": {},
138506          "evidence": {},
138507          "signature": {
138508            "signature": {
138509              "publicKey": {}
138510            }
138511          },
138512          "modelCard": {
138513            "modelParameters": {
138514              "approach": {}
138515            },
138516            "quantitativeAnalysis": {
138517              "graphics": {}
138518            },
138519            "considerations": {}
138520          }
138521        },
138522        {
138523          "type": "library",
138524          "bom-ref": "pkg:rpm/rhel/libunistring@0.9.9-3.el8?arch=x86_64\u0026upstream=libunistring-0.9.9-3.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=42de6e635746f2bb",
138525          "supplier": {},
138526          "publisher": "Red Hat, Inc.",
138527          "name": "libunistring",
138528          "version": "0.9.9-3.el8",
138529          "licenses": [
138530            {
138531              "license": {
138532                "name": "GPLv2+ or LGPLv3+"
138533              }
138534            }
138535          ],
138536          "cpe": "cpe:2.3:a:libunistring:libunistring:0.9.9-3.el8:*:*:*:*:*:*:*",
138537          "purl": "pkg:rpm/rhel/libunistring@0.9.9-3.el8?arch=x86_64\u0026upstream=libunistring-0.9.9-3.el8.src.rpm\u0026distro=rhel-8.6",
138538          "swid": {
138539            "attachment": {}
138540          },
138541          "pedigree": {},
138542          "evidence": {},
138543          "signature": {
138544            "signature": {
138545              "publicKey": {}
138546            }
138547          },
138548          "modelCard": {
138549            "modelParameters": {
138550              "approach": {}
138551            },
138552            "quantitativeAnalysis": {
138553              "graphics": {}
138554            },
138555            "considerations": {}
138556          }
138557        },
138558        {
138559          "type": "library",
138560          "bom-ref": "pkg:rpm/rhel/libusbx@1.0.23-4.el8?arch=x86_64\u0026upstream=libusbx-1.0.23-4.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=6d44b14cda1496c6",
138561          "supplier": {},
138562          "publisher": "Red Hat, Inc.",
138563          "name": "libusbx",
138564          "version": "1.0.23-4.el8",
138565          "licenses": [
138566            {
138567              "license": {
138568                "name": "LGPLv2+"
138569              }
138570            }
138571          ],
138572          "cpe": "cpe:2.3:a:libusbx:libusbx:1.0.23-4.el8:*:*:*:*:*:*:*",
138573          "purl": "pkg:rpm/rhel/libusbx@1.0.23-4.el8?arch=x86_64\u0026upstream=libusbx-1.0.23-4.el8.src.rpm\u0026distro=rhel-8.6",
138574          "swid": {
138575            "attachment": {}
138576          },
138577          "pedigree": {},
138578          "evidence": {},
138579          "signature": {
138580            "signature": {
138581              "publicKey": {}
138582            }
138583          },
138584          "modelCard": {
138585            "modelParameters": {
138586              "approach": {}
138587            },
138588            "quantitativeAnalysis": {
138589              "graphics": {}
138590            },
138591            "considerations": {}
138592          }
138593        },
138594        {
138595          "type": "library",
138596          "bom-ref": "pkg:rpm/rhel/libutempter@1.1.6-14.el8?arch=x86_64\u0026upstream=libutempter-1.1.6-14.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=ce0c3a72536371a6",
138597          "supplier": {},
138598          "publisher": "Red Hat, Inc.",
138599          "name": "libutempter",
138600          "version": "1.1.6-14.el8",
138601          "licenses": [
138602            {
138603              "license": {
138604                "name": "LGPLv2+"
138605              }
138606            }
138607          ],
138608          "cpe": "cpe:2.3:a:libutempter:libutempter:1.1.6-14.el8:*:*:*:*:*:*:*",
138609          "purl": "pkg:rpm/rhel/libutempter@1.1.6-14.el8?arch=x86_64\u0026upstream=libutempter-1.1.6-14.el8.src.rpm\u0026distro=rhel-8.6",
138610          "swid": {
138611            "attachment": {}
138612          },
138613          "pedigree": {},
138614          "evidence": {},
138615          "signature": {
138616            "signature": {
138617              "publicKey": {}
138618            }
138619          },
138620          "modelCard": {
138621            "modelParameters": {
138622              "approach": {}
138623            },
138624            "quantitativeAnalysis": {
138625              "graphics": {}
138626            },
138627            "considerations": {}
138628          }
138629        },
138630        {
138631          "type": "library",
138632          "bom-ref": "pkg:rpm/rhel/libuuid@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=7f5abf7a05bbadc6",
138633          "supplier": {},
138634          "publisher": "Red Hat, Inc.",
138635          "name": "libuuid",
138636          "version": "2.32.1-35.el8",
138637          "licenses": [
138638            {
138639              "license": {
138640                "name": "BSD"
138641              }
138642            }
138643          ],
138644          "cpe": "cpe:2.3:a:libuuid:libuuid:2.32.1-35.el8:*:*:*:*:*:*:*",
138645          "purl": "pkg:rpm/rhel/libuuid@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6",
138646          "swid": {
138647            "attachment": {}
138648          },
138649          "pedigree": {},
138650          "evidence": {},
138651          "signature": {
138652            "signature": {
138653              "publicKey": {}
138654            }
138655          },
138656          "modelCard": {
138657            "modelParameters": {
138658              "approach": {}
138659            },
138660            "quantitativeAnalysis": {
138661              "graphics": {}
138662            },
138663            "considerations": {}
138664          }
138665        },
138666        {
138667          "type": "library",
138668          "bom-ref": "pkg:rpm/rhel/libverto@0.3.0-5.el8?arch=x86_64\u0026upstream=libverto-0.3.0-5.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=afbcf425a13df06e",
138669          "supplier": {},
138670          "publisher": "Red Hat, Inc.",
138671          "name": "libverto",
138672          "version": "0.3.0-5.el8",
138673          "licenses": [
138674            {
138675              "license": {
138676                "id": "MIT"
138677              }
138678            }
138679          ],
138680          "cpe": "cpe:2.3:a:libverto:libverto:0.3.0-5.el8:*:*:*:*:*:*:*",
138681          "purl": "pkg:rpm/rhel/libverto@0.3.0-5.el8?arch=x86_64\u0026upstream=libverto-0.3.0-5.el8.src.rpm\u0026distro=rhel-8.6",
138682          "swid": {
138683            "attachment": {}
138684          },
138685          "pedigree": {},
138686          "evidence": {},
138687          "signature": {
138688            "signature": {
138689              "publicKey": {}
138690            }
138691          },
138692          "modelCard": {
138693            "modelParameters": {
138694              "approach": {}
138695            },
138696            "quantitativeAnalysis": {
138697              "graphics": {}
138698            },
138699            "considerations": {}
138700          }
138701        },
138702        {
138703          "type": "library",
138704          "bom-ref": "pkg:rpm/rhel/libxcrypt@4.1.1-6.el8?arch=x86_64\u0026upstream=libxcrypt-4.1.1-6.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=c9f4cb90f1d9fdb7",
138705          "supplier": {},
138706          "publisher": "Red Hat, Inc.",
138707          "name": "libxcrypt",
138708          "version": "4.1.1-6.el8",
138709          "licenses": [
138710            {
138711              "license": {
138712                "name": "LGPLv2+ and BSD and Public Domain"
138713              }
138714            }
138715          ],
138716          "cpe": "cpe:2.3:a:libxcrypt:libxcrypt:4.1.1-6.el8:*:*:*:*:*:*:*",
138717          "purl": "pkg:rpm/rhel/libxcrypt@4.1.1-6.el8?arch=x86_64\u0026upstream=libxcrypt-4.1.1-6.el8.src.rpm\u0026distro=rhel-8.6",
138718          "swid": {
138719            "attachment": {}
138720          },
138721          "pedigree": {},
138722          "evidence": {},
138723          "signature": {
138724            "signature": {
138725              "publicKey": {}
138726            }
138727          },
138728          "modelCard": {
138729            "modelParameters": {
138730              "approach": {}
138731            },
138732            "quantitativeAnalysis": {
138733              "graphics": {}
138734            },
138735            "considerations": {}
138736          }
138737        },
138738        {
138739          "type": "library",
138740          "bom-ref": "pkg:rpm/rhel/libxml2@2.9.7-13.el8_6.1?arch=x86_64\u0026upstream=libxml2-2.9.7-13.el8_6.1.src.rpm\u0026distro=rhel-8.6\u0026package-id=d50d7a1e9d9caa9",
138741          "supplier": {},
138742          "publisher": "Red Hat, Inc.",
138743          "name": "libxml2",
138744          "version": "2.9.7-13.el8_6.1",
138745          "licenses": [
138746            {
138747              "license": {
138748                "id": "MIT"
138749              }
138750            }
138751          ],
138752          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.7-13.el8_6.1:*:*:*:*:*:*:*",
138753          "purl": "pkg:rpm/rhel/libxml2@2.9.7-13.el8_6.1?arch=x86_64\u0026upstream=libxml2-2.9.7-13.el8_6.1.src.rpm\u0026distro=rhel-8.6",
138754          "swid": {
138755            "attachment": {}
138756          },
138757          "pedigree": {},
138758          "evidence": {},
138759          "signature": {
138760            "signature": {
138761              "publicKey": {}
138762            }
138763          },
138764          "modelCard": {
138765            "modelParameters": {
138766              "approach": {}
138767            },
138768            "quantitativeAnalysis": {
138769              "graphics": {}
138770            },
138771            "considerations": {}
138772          }
138773        },
138774        {
138775          "type": "library",
138776          "bom-ref": "pkg:rpm/rhel/libyaml@0.1.7-5.el8?arch=x86_64\u0026upstream=libyaml-0.1.7-5.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=95655bb43e12fc9b",
138777          "supplier": {},
138778          "publisher": "Red Hat, Inc.",
138779          "name": "libyaml",
138780          "version": "0.1.7-5.el8",
138781          "licenses": [
138782            {
138783              "license": {
138784                "id": "MIT"
138785              }
138786            }
138787          ],
138788          "cpe": "cpe:2.3:a:libyaml:libyaml:0.1.7-5.el8:*:*:*:*:*:*:*",
138789          "purl": "pkg:rpm/rhel/libyaml@0.1.7-5.el8?arch=x86_64\u0026upstream=libyaml-0.1.7-5.el8.src.rpm\u0026distro=rhel-8.6",
138790          "swid": {
138791            "attachment": {}
138792          },
138793          "pedigree": {},
138794          "evidence": {},
138795          "signature": {
138796            "signature": {
138797              "publicKey": {}
138798            }
138799          },
138800          "modelCard": {
138801            "modelParameters": {
138802              "approach": {}
138803            },
138804            "quantitativeAnalysis": {
138805              "graphics": {}
138806            },
138807            "considerations": {}
138808          }
138809        },
138810        {
138811          "type": "library",
138812          "bom-ref": "pkg:rpm/rhel/libzstd@1.4.4-1.el8?arch=x86_64\u0026upstream=zstd-1.4.4-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=715b9b1896e70710",
138813          "supplier": {},
138814          "publisher": "Red Hat, Inc.",
138815          "name": "libzstd",
138816          "version": "1.4.4-1.el8",
138817          "licenses": [
138818            {
138819              "license": {
138820                "name": "BSD and GPLv2"
138821              }
138822            }
138823          ],
138824          "cpe": "cpe:2.3:a:libzstd:libzstd:1.4.4-1.el8:*:*:*:*:*:*:*",
138825          "purl": "pkg:rpm/rhel/libzstd@1.4.4-1.el8?arch=x86_64\u0026upstream=zstd-1.4.4-1.el8.src.rpm\u0026distro=rhel-8.6",
138826          "swid": {
138827            "attachment": {}
138828          },
138829          "pedigree": {},
138830          "evidence": {},
138831          "signature": {
138832            "signature": {
138833              "publicKey": {}
138834            }
138835          },
138836          "modelCard": {
138837            "modelParameters": {
138838              "approach": {}
138839            },
138840            "quantitativeAnalysis": {
138841              "graphics": {}
138842            },
138843            "considerations": {}
138844          }
138845        },
138846        {
138847          "type": "library",
138848          "bom-ref": "pkg:rpm/rhel/lua-libs@5.3.4-12.el8?arch=x86_64\u0026upstream=lua-5.3.4-12.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=7197ebf16b3fe587",
138849          "supplier": {},
138850          "publisher": "Red Hat, Inc.",
138851          "name": "lua-libs",
138852          "version": "5.3.4-12.el8",
138853          "licenses": [
138854            {
138855              "license": {
138856                "id": "MIT"
138857              }
138858            }
138859          ],
138860          "cpe": "cpe:2.3:a:lua-libs:lua-libs:5.3.4-12.el8:*:*:*:*:*:*:*",
138861          "purl": "pkg:rpm/rhel/lua-libs@5.3.4-12.el8?arch=x86_64\u0026upstream=lua-5.3.4-12.el8.src.rpm\u0026distro=rhel-8.6",
138862          "swid": {
138863            "attachment": {}
138864          },
138865          "pedigree": {},
138866          "evidence": {},
138867          "signature": {
138868            "signature": {
138869              "publicKey": {}
138870            }
138871          },
138872          "modelCard": {
138873            "modelParameters": {
138874              "approach": {}
138875            },
138876            "quantitativeAnalysis": {
138877              "graphics": {}
138878            },
138879            "considerations": {}
138880          }
138881        },
138882        {
138883          "type": "library",
138884          "bom-ref": "pkg:rpm/rhel/lz4-libs@1.8.3-3.el8_4?arch=x86_64\u0026upstream=lz4-1.8.3-3.el8_4.src.rpm\u0026distro=rhel-8.6\u0026package-id=ca403e7013eee117",
138885          "supplier": {},
138886          "publisher": "Red Hat, Inc.",
138887          "name": "lz4-libs",
138888          "version": "1.8.3-3.el8_4",
138889          "licenses": [
138890            {
138891              "license": {
138892                "name": "GPLv2+ and BSD"
138893              }
138894            }
138895          ],
138896          "cpe": "cpe:2.3:a:lz4-libs:lz4-libs:1.8.3-3.el8_4:*:*:*:*:*:*:*",
138897          "purl": "pkg:rpm/rhel/lz4-libs@1.8.3-3.el8_4?arch=x86_64\u0026upstream=lz4-1.8.3-3.el8_4.src.rpm\u0026distro=rhel-8.6",
138898          "swid": {
138899            "attachment": {}
138900          },
138901          "pedigree": {},
138902          "evidence": {},
138903          "signature": {
138904            "signature": {
138905              "publicKey": {}
138906            }
138907          },
138908          "modelCard": {
138909            "modelParameters": {
138910              "approach": {}
138911            },
138912            "quantitativeAnalysis": {
138913              "graphics": {}
138914            },
138915            "considerations": {}
138916          }
138917        },
138918        {
138919          "type": "library",
138920          "bom-ref": "pkg:rpm/rhel/microdnf@3.8.0-2.el8?arch=x86_64\u0026upstream=microdnf-3.8.0-2.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=b1d1c82094fb041e",
138921          "supplier": {},
138922          "publisher": "Red Hat, Inc.",
138923          "name": "microdnf",
138924          "version": "3.8.0-2.el8",
138925          "licenses": [
138926            {
138927              "license": {
138928                "name": "GPLv2+"
138929              }
138930            }
138931          ],
138932          "cpe": "cpe:2.3:a:microdnf:microdnf:3.8.0-2.el8:*:*:*:*:*:*:*",
138933          "purl": "pkg:rpm/rhel/microdnf@3.8.0-2.el8?arch=x86_64\u0026upstream=microdnf-3.8.0-2.el8.src.rpm\u0026distro=rhel-8.6",
138934          "swid": {
138935            "attachment": {}
138936          },
138937          "pedigree": {},
138938          "evidence": {},
138939          "signature": {
138940            "signature": {
138941              "publicKey": {}
138942            }
138943          },
138944          "modelCard": {
138945            "modelParameters": {
138946              "approach": {}
138947            },
138948            "quantitativeAnalysis": {
138949              "graphics": {}
138950            },
138951            "considerations": {}
138952          }
138953        },
138954        {
138955          "type": "library",
138956          "bom-ref": "pkg:rpm/rhel/minisign@0.9-1.el8?arch=x86_64\u0026upstream=minisign-0.9-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=aceef44d7a0b7eb7",
138957          "supplier": {},
138958          "publisher": "Fedora Project",
138959          "name": "minisign",
138960          "version": "0.9-1.el8",
138961          "licenses": [
138962            {
138963              "license": {
138964                "id": "ISC"
138965              }
138966            }
138967          ],
138968          "cpe": "cpe:2.3:a:fedoraproject:minisign:0.9-1.el8:*:*:*:*:*:*:*",
138969          "purl": "pkg:rpm/rhel/minisign@0.9-1.el8?arch=x86_64\u0026upstream=minisign-0.9-1.el8.src.rpm\u0026distro=rhel-8.6",
138970          "swid": {
138971            "attachment": {}
138972          },
138973          "pedigree": {},
138974          "evidence": {},
138975          "signature": {
138976            "signature": {
138977              "publicKey": {}
138978            }
138979          },
138980          "modelCard": {
138981            "modelParameters": {
138982              "approach": {}
138983            },
138984            "quantitativeAnalysis": {
138985              "graphics": {}
138986            },
138987            "considerations": {}
138988          }
138989        },
138990        {
138991          "type": "library",
138992          "bom-ref": "pkg:rpm/rhel/mpfr@3.1.6-1.el8?arch=x86_64\u0026upstream=mpfr-3.1.6-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=c515ebd09bbbee10",
138993          "supplier": {},
138994          "publisher": "Red Hat, Inc.",
138995          "name": "mpfr",
138996          "version": "3.1.6-1.el8",
138997          "licenses": [
138998            {
138999              "license": {
139000                "name": "LGPLv3+ and GPLv3+ and GFDL"
139001              }
139002            }
139003          ],
139004          "cpe": "cpe:2.3:a:redhat:mpfr:3.1.6-1.el8:*:*:*:*:*:*:*",
139005          "purl": "pkg:rpm/rhel/mpfr@3.1.6-1.el8?arch=x86_64\u0026upstream=mpfr-3.1.6-1.el8.src.rpm\u0026distro=rhel-8.6",
139006          "swid": {
139007            "attachment": {}
139008          },
139009          "pedigree": {},
139010          "evidence": {},
139011          "signature": {
139012            "signature": {
139013              "publicKey": {}
139014            }
139015          },
139016          "modelCard": {
139017            "modelParameters": {
139018              "approach": {}
139019            },
139020            "quantitativeAnalysis": {
139021              "graphics": {}
139022            },
139023            "considerations": {}
139024          }
139025        },
139026        {
139027          "type": "library",
139028          "bom-ref": "pkg:rpm/rhel/ncurses-base@6.1-9.20180224.el8?arch=noarch\u0026upstream=ncurses-6.1-9.20180224.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=e5ad8a54f0da4576",
139029          "supplier": {},
139030          "publisher": "Red Hat, Inc.",
139031          "name": "ncurses-base",
139032          "version": "6.1-9.20180224.el8",
139033          "licenses": [
139034            {
139035              "license": {
139036                "id": "MIT"
139037              }
139038            }
139039          ],
139040          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.1-9.20180224.el8:*:*:*:*:*:*:*",
139041          "purl": "pkg:rpm/rhel/ncurses-base@6.1-9.20180224.el8?arch=noarch\u0026upstream=ncurses-6.1-9.20180224.el8.src.rpm\u0026distro=rhel-8.6",
139042          "swid": {
139043            "attachment": {}
139044          },
139045          "pedigree": {},
139046          "evidence": {},
139047          "signature": {
139048            "signature": {
139049              "publicKey": {}
139050            }
139051          },
139052          "modelCard": {
139053            "modelParameters": {
139054              "approach": {}
139055            },
139056            "quantitativeAnalysis": {
139057              "graphics": {}
139058            },
139059            "considerations": {}
139060          }
139061        },
139062        {
139063          "type": "library",
139064          "bom-ref": "pkg:rpm/rhel/ncurses-libs@6.1-9.20180224.el8?arch=x86_64\u0026upstream=ncurses-6.1-9.20180224.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=92f6d17e993a156c",
139065          "supplier": {},
139066          "publisher": "Red Hat, Inc.",
139067          "name": "ncurses-libs",
139068          "version": "6.1-9.20180224.el8",
139069          "licenses": [
139070            {
139071              "license": {
139072                "id": "MIT"
139073              }
139074            }
139075          ],
139076          "cpe": "cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-9.20180224.el8:*:*:*:*:*:*:*",
139077          "purl": "pkg:rpm/rhel/ncurses-libs@6.1-9.20180224.el8?arch=x86_64\u0026upstream=ncurses-6.1-9.20180224.el8.src.rpm\u0026distro=rhel-8.6",
139078          "swid": {
139079            "attachment": {}
139080          },
139081          "pedigree": {},
139082          "evidence": {},
139083          "signature": {
139084            "signature": {
139085              "publicKey": {}
139086            }
139087          },
139088          "modelCard": {
139089            "modelParameters": {
139090              "approach": {}
139091            },
139092            "quantitativeAnalysis": {
139093              "graphics": {}
139094            },
139095            "considerations": {}
139096          }
139097        },
139098        {
139099          "type": "library",
139100          "bom-ref": "pkg:rpm/rhel/nettle@3.4.1-7.el8?arch=x86_64\u0026upstream=nettle-3.4.1-7.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=addc7521b8c9e5f",
139101          "supplier": {},
139102          "publisher": "Red Hat, Inc.",
139103          "name": "nettle",
139104          "version": "3.4.1-7.el8",
139105          "licenses": [
139106            {
139107              "license": {
139108                "name": "LGPLv3+ or GPLv2+"
139109              }
139110            }
139111          ],
139112          "cpe": "cpe:2.3:a:nettle:nettle:3.4.1-7.el8:*:*:*:*:*:*:*",
139113          "purl": "pkg:rpm/rhel/nettle@3.4.1-7.el8?arch=x86_64\u0026upstream=nettle-3.4.1-7.el8.src.rpm\u0026distro=rhel-8.6",
139114          "swid": {
139115            "attachment": {}
139116          },
139117          "pedigree": {},
139118          "evidence": {},
139119          "signature": {
139120            "signature": {
139121              "publicKey": {}
139122            }
139123          },
139124          "modelCard": {
139125            "modelParameters": {
139126              "approach": {}
139127            },
139128            "quantitativeAnalysis": {
139129              "graphics": {}
139130            },
139131            "considerations": {}
139132          }
139133        },
139134        {
139135          "type": "library",
139136          "bom-ref": "pkg:rpm/rhel/npth@1.5-4.el8?arch=x86_64\u0026upstream=npth-1.5-4.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=10169dc5c8cd1ebc",
139137          "supplier": {},
139138          "publisher": "Red Hat, Inc.",
139139          "name": "npth",
139140          "version": "1.5-4.el8",
139141          "licenses": [
139142            {
139143              "license": {
139144                "name": "LGPLv2+"
139145              }
139146            }
139147          ],
139148          "cpe": "cpe:2.3:a:redhat:npth:1.5-4.el8:*:*:*:*:*:*:*",
139149          "purl": "pkg:rpm/rhel/npth@1.5-4.el8?arch=x86_64\u0026upstream=npth-1.5-4.el8.src.rpm\u0026distro=rhel-8.6",
139150          "swid": {
139151            "attachment": {}
139152          },
139153          "pedigree": {},
139154          "evidence": {},
139155          "signature": {
139156            "signature": {
139157              "publicKey": {}
139158            }
139159          },
139160          "modelCard": {
139161            "modelParameters": {
139162              "approach": {}
139163            },
139164            "quantitativeAnalysis": {
139165              "graphics": {}
139166            },
139167            "considerations": {}
139168          }
139169        },
139170        {
139171          "type": "library",
139172          "bom-ref": "pkg:rpm/rhel/openldap@2.4.46-18.el8?arch=x86_64\u0026upstream=openldap-2.4.46-18.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=25e75ae945384d69",
139173          "supplier": {},
139174          "publisher": "Red Hat, Inc.",
139175          "name": "openldap",
139176          "version": "2.4.46-18.el8",
139177          "licenses": [
139178            {
139179              "license": {
139180                "name": "OpenLDAP"
139181              }
139182            }
139183          ],
139184          "cpe": "cpe:2.3:a:openldap:openldap:2.4.46-18.el8:*:*:*:*:*:*:*",
139185          "purl": "pkg:rpm/rhel/openldap@2.4.46-18.el8?arch=x86_64\u0026upstream=openldap-2.4.46-18.el8.src.rpm\u0026distro=rhel-8.6",
139186          "swid": {
139187            "attachment": {}
139188          },
139189          "pedigree": {},
139190          "evidence": {},
139191          "signature": {
139192            "signature": {
139193              "publicKey": {}
139194            }
139195          },
139196          "modelCard": {
139197            "modelParameters": {
139198              "approach": {}
139199            },
139200            "quantitativeAnalysis": {
139201              "graphics": {}
139202            },
139203            "considerations": {}
139204          }
139205        },
139206        {
139207          "type": "library",
139208          "bom-ref": "pkg:rpm/rhel/openssl-libs@1.1.1k-7.el8_6?arch=x86_64\u0026epoch=1\u0026upstream=openssl-1.1.1k-7.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=9040df89ae0d557c",
139209          "supplier": {},
139210          "publisher": "Red Hat, Inc.",
139211          "name": "openssl-libs",
139212          "version": "1:1.1.1k-7.el8_6",
139213          "licenses": [
139214            {
139215              "license": {
139216                "name": "OpenSSL and ASL 2.0"
139217              }
139218            }
139219          ],
139220          "cpe": "cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-7.el8_6:*:*:*:*:*:*:*",
139221          "purl": "pkg:rpm/rhel/openssl-libs@1.1.1k-7.el8_6?arch=x86_64\u0026epoch=1\u0026upstream=openssl-1.1.1k-7.el8_6.src.rpm\u0026distro=rhel-8.6",
139222          "swid": {
139223            "attachment": {}
139224          },
139225          "pedigree": {},
139226          "evidence": {},
139227          "signature": {
139228            "signature": {
139229              "publicKey": {}
139230            }
139231          },
139232          "modelCard": {
139233            "modelParameters": {
139234              "approach": {}
139235            },
139236            "quantitativeAnalysis": {
139237              "graphics": {}
139238            },
139239            "considerations": {}
139240          }
139241        },
139242        {
139243          "type": "library",
139244          "bom-ref": "pkg:rpm/rhel/p11-kit@0.23.22-1.el8?arch=x86_64\u0026upstream=p11-kit-0.23.22-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=b254c77cacc73abc",
139245          "supplier": {},
139246          "publisher": "Red Hat, Inc.",
139247          "name": "p11-kit",
139248          "version": "0.23.22-1.el8",
139249          "licenses": [
139250            {
139251              "license": {
139252                "name": "BSD"
139253              }
139254            }
139255          ],
139256          "cpe": "cpe:2.3:a:p11-kit:p11-kit:0.23.22-1.el8:*:*:*:*:*:*:*",
139257          "purl": "pkg:rpm/rhel/p11-kit@0.23.22-1.el8?arch=x86_64\u0026upstream=p11-kit-0.23.22-1.el8.src.rpm\u0026distro=rhel-8.6",
139258          "swid": {
139259            "attachment": {}
139260          },
139261          "pedigree": {},
139262          "evidence": {},
139263          "signature": {
139264            "signature": {
139265              "publicKey": {}
139266            }
139267          },
139268          "modelCard": {
139269            "modelParameters": {
139270              "approach": {}
139271            },
139272            "quantitativeAnalysis": {
139273              "graphics": {}
139274            },
139275            "considerations": {}
139276          }
139277        },
139278        {
139279          "type": "library",
139280          "bom-ref": "pkg:rpm/rhel/p11-kit-trust@0.23.22-1.el8?arch=x86_64\u0026upstream=p11-kit-0.23.22-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=9bbc280cfc6925b2",
139281          "supplier": {},
139282          "publisher": "Red Hat, Inc.",
139283          "name": "p11-kit-trust",
139284          "version": "0.23.22-1.el8",
139285          "licenses": [
139286            {
139287              "license": {
139288                "name": "BSD"
139289              }
139290            }
139291          ],
139292          "cpe": "cpe:2.3:a:p11-kit-trust:p11-kit-trust:0.23.22-1.el8:*:*:*:*:*:*:*",
139293          "purl": "pkg:rpm/rhel/p11-kit-trust@0.23.22-1.el8?arch=x86_64\u0026upstream=p11-kit-0.23.22-1.el8.src.rpm\u0026distro=rhel-8.6",
139294          "swid": {
139295            "attachment": {}
139296          },
139297          "pedigree": {},
139298          "evidence": {},
139299          "signature": {
139300            "signature": {
139301              "publicKey": {}
139302            }
139303          },
139304          "modelCard": {
139305            "modelParameters": {
139306              "approach": {}
139307            },
139308            "quantitativeAnalysis": {
139309              "graphics": {}
139310            },
139311            "considerations": {}
139312          }
139313        },
139314        {
139315          "type": "library",
139316          "bom-ref": "pkg:rpm/rhel/pam@1.3.1-16.el8_6.1?arch=x86_64\u0026upstream=pam-1.3.1-16.el8_6.1.src.rpm\u0026distro=rhel-8.6\u0026package-id=3fb1665d41bc6d49",
139317          "supplier": {},
139318          "publisher": "Red Hat, Inc.",
139319          "name": "pam",
139320          "version": "1.3.1-16.el8_6.1",
139321          "licenses": [
139322            {
139323              "license": {
139324                "name": "BSD and GPLv2+"
139325              }
139326            }
139327          ],
139328          "cpe": "cpe:2.3:a:redhat:pam:1.3.1-16.el8_6.1:*:*:*:*:*:*:*",
139329          "purl": "pkg:rpm/rhel/pam@1.3.1-16.el8_6.1?arch=x86_64\u0026upstream=pam-1.3.1-16.el8_6.1.src.rpm\u0026distro=rhel-8.6",
139330          "swid": {
139331            "attachment": {}
139332          },
139333          "pedigree": {},
139334          "evidence": {},
139335          "signature": {
139336            "signature": {
139337              "publicKey": {}
139338            }
139339          },
139340          "modelCard": {
139341            "modelParameters": {
139342              "approach": {}
139343            },
139344            "quantitativeAnalysis": {
139345              "graphics": {}
139346            },
139347            "considerations": {}
139348          }
139349        },
139350        {
139351          "type": "library",
139352          "bom-ref": "pkg:rpm/rhel/pcre@8.42-6.el8?arch=x86_64\u0026upstream=pcre-8.42-6.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=3d22a919de1209fc",
139353          "supplier": {},
139354          "publisher": "Red Hat, Inc.",
139355          "name": "pcre",
139356          "version": "8.42-6.el8",
139357          "licenses": [
139358            {
139359              "license": {
139360                "name": "BSD"
139361              }
139362            }
139363          ],
139364          "cpe": "cpe:2.3:a:redhat:pcre:8.42-6.el8:*:*:*:*:*:*:*",
139365          "purl": "pkg:rpm/rhel/pcre@8.42-6.el8?arch=x86_64\u0026upstream=pcre-8.42-6.el8.src.rpm\u0026distro=rhel-8.6",
139366          "swid": {
139367            "attachment": {}
139368          },
139369          "pedigree": {},
139370          "evidence": {},
139371          "signature": {
139372            "signature": {
139373              "publicKey": {}
139374            }
139375          },
139376          "modelCard": {
139377            "modelParameters": {
139378              "approach": {}
139379            },
139380            "quantitativeAnalysis": {
139381              "graphics": {}
139382            },
139383            "considerations": {}
139384          }
139385        },
139386        {
139387          "type": "library",
139388          "bom-ref": "pkg:rpm/rhel/pcre2@10.32-3.el8_6?arch=x86_64\u0026upstream=pcre2-10.32-3.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=239777e88c48f2ef",
139389          "supplier": {},
139390          "publisher": "Red Hat, Inc.",
139391          "name": "pcre2",
139392          "version": "10.32-3.el8_6",
139393          "licenses": [
139394            {
139395              "license": {
139396                "name": "BSD"
139397              }
139398            }
139399          ],
139400          "cpe": "cpe:2.3:a:redhat:pcre2:10.32-3.el8_6:*:*:*:*:*:*:*",
139401          "purl": "pkg:rpm/rhel/pcre2@10.32-3.el8_6?arch=x86_64\u0026upstream=pcre2-10.32-3.el8_6.src.rpm\u0026distro=rhel-8.6",
139402          "swid": {
139403            "attachment": {}
139404          },
139405          "pedigree": {},
139406          "evidence": {},
139407          "signature": {
139408            "signature": {
139409              "publicKey": {}
139410            }
139411          },
139412          "modelCard": {
139413            "modelParameters": {
139414              "approach": {}
139415            },
139416            "quantitativeAnalysis": {
139417              "graphics": {}
139418            },
139419            "considerations": {}
139420          }
139421        },
139422        {
139423          "type": "library",
139424          "bom-ref": "pkg:rpm/rhel/popt@1.18-1.el8?arch=x86_64\u0026upstream=popt-1.18-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=5e4c6fe5d94c33be",
139425          "supplier": {},
139426          "publisher": "Red Hat, Inc.",
139427          "name": "popt",
139428          "version": "1.18-1.el8",
139429          "licenses": [
139430            {
139431              "license": {
139432                "id": "MIT"
139433              }
139434            }
139435          ],
139436          "cpe": "cpe:2.3:a:redhat:popt:1.18-1.el8:*:*:*:*:*:*:*",
139437          "purl": "pkg:rpm/rhel/popt@1.18-1.el8?arch=x86_64\u0026upstream=popt-1.18-1.el8.src.rpm\u0026distro=rhel-8.6",
139438          "swid": {
139439            "attachment": {}
139440          },
139441          "pedigree": {},
139442          "evidence": {},
139443          "signature": {
139444            "signature": {
139445              "publicKey": {}
139446            }
139447          },
139448          "modelCard": {
139449            "modelParameters": {
139450              "approach": {}
139451            },
139452            "quantitativeAnalysis": {
139453              "graphics": {}
139454            },
139455            "considerations": {}
139456          }
139457        },
139458        {
139459          "type": "library",
139460          "bom-ref": "pkg:rpm/rhel/publicsuffix-list-dafsa@20180723-1.el8?arch=noarch\u0026upstream=publicsuffix-list-20180723-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=82573d5ccba23d8b",
139461          "supplier": {},
139462          "publisher": "Red Hat, Inc.",
139463          "name": "publicsuffix-list-dafsa",
139464          "version": "20180723-1.el8",
139465          "licenses": [
139466            {
139467              "license": {
139468                "name": "MPLv2.0"
139469              }
139470            }
139471          ],
139472          "cpe": "cpe:2.3:a:publicsuffix-list-dafsa:publicsuffix-list-dafsa:20180723-1.el8:*:*:*:*:*:*:*",
139473          "purl": "pkg:rpm/rhel/publicsuffix-list-dafsa@20180723-1.el8?arch=noarch\u0026upstream=publicsuffix-list-20180723-1.el8.src.rpm\u0026distro=rhel-8.6",
139474          "swid": {
139475            "attachment": {}
139476          },
139477          "pedigree": {},
139478          "evidence": {},
139479          "signature": {
139480            "signature": {
139481              "publicKey": {}
139482            }
139483          },
139484          "modelCard": {
139485            "modelParameters": {
139486              "approach": {}
139487            },
139488            "quantitativeAnalysis": {
139489              "graphics": {}
139490            },
139491            "considerations": {}
139492          }
139493        },
139494        {
139495          "type": "library",
139496          "bom-ref": "pkg:rpm/rhel/readline@7.0-10.el8?arch=x86_64\u0026upstream=readline-7.0-10.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=cebe4f3f58f38e93",
139497          "supplier": {},
139498          "publisher": "Red Hat, Inc.",
139499          "name": "readline",
139500          "version": "7.0-10.el8",
139501          "licenses": [
139502            {
139503              "license": {
139504                "name": "GPLv3+"
139505              }
139506            }
139507          ],
139508          "cpe": "cpe:2.3:a:readline:readline:7.0-10.el8:*:*:*:*:*:*:*",
139509          "purl": "pkg:rpm/rhel/readline@7.0-10.el8?arch=x86_64\u0026upstream=readline-7.0-10.el8.src.rpm\u0026distro=rhel-8.6",
139510          "swid": {
139511            "attachment": {}
139512          },
139513          "pedigree": {},
139514          "evidence": {},
139515          "signature": {
139516            "signature": {
139517              "publicKey": {}
139518            }
139519          },
139520          "modelCard": {
139521            "modelParameters": {
139522              "approach": {}
139523            },
139524            "quantitativeAnalysis": {
139525              "graphics": {}
139526            },
139527            "considerations": {}
139528          }
139529        },
139530        {
139531          "type": "library",
139532          "bom-ref": "pkg:rpm/rhel/redhat-release@8.6-0.1.el8?arch=x86_64\u0026upstream=redhat-release-8.6-0.1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=7b4f1acb3768e4b0",
139533          "supplier": {},
139534          "publisher": "Red Hat, Inc.",
139535          "name": "redhat-release",
139536          "version": "8.6-0.1.el8",
139537          "licenses": [
139538            {
139539              "license": {
139540                "name": "GPLv2"
139541              }
139542            }
139543          ],
139544          "cpe": "cpe:2.3:a:redhat-release:redhat-release:8.6-0.1.el8:*:*:*:*:*:*:*",
139545          "purl": "pkg:rpm/rhel/redhat-release@8.6-0.1.el8?arch=x86_64\u0026upstream=redhat-release-8.6-0.1.el8.src.rpm\u0026distro=rhel-8.6",
139546          "swid": {
139547            "attachment": {}
139548          },
139549          "pedigree": {},
139550          "evidence": {},
139551          "signature": {
139552            "signature": {
139553              "publicKey": {}
139554            }
139555          },
139556          "modelCard": {
139557            "modelParameters": {
139558              "approach": {}
139559            },
139560            "quantitativeAnalysis": {
139561              "graphics": {}
139562            },
139563            "considerations": {}
139564          }
139565        },
139566        {
139567          "type": "library",
139568          "bom-ref": "pkg:rpm/rhel/rootfiles@8.1-22.el8?arch=noarch\u0026upstream=rootfiles-8.1-22.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=e258779ba67e6208",
139569          "supplier": {},
139570          "publisher": "Red Hat, Inc.",
139571          "name": "rootfiles",
139572          "version": "8.1-22.el8",
139573          "licenses": [
139574            {
139575              "license": {
139576                "name": "Public Domain"
139577              }
139578            }
139579          ],
139580          "cpe": "cpe:2.3:a:rootfiles:rootfiles:8.1-22.el8:*:*:*:*:*:*:*",
139581          "purl": "pkg:rpm/rhel/rootfiles@8.1-22.el8?arch=noarch\u0026upstream=rootfiles-8.1-22.el8.src.rpm\u0026distro=rhel-8.6",
139582          "swid": {
139583            "attachment": {}
139584          },
139585          "pedigree": {},
139586          "evidence": {},
139587          "signature": {
139588            "signature": {
139589              "publicKey": {}
139590            }
139591          },
139592          "modelCard": {
139593            "modelParameters": {
139594              "approach": {}
139595            },
139596            "quantitativeAnalysis": {
139597              "graphics": {}
139598            },
139599            "considerations": {}
139600          }
139601        },
139602        {
139603          "type": "library",
139604          "bom-ref": "pkg:rpm/rhel/rpm@4.14.3-23.el8?arch=x86_64\u0026upstream=rpm-4.14.3-23.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=43018d83462bf75",
139605          "supplier": {},
139606          "publisher": "Red Hat, Inc.",
139607          "name": "rpm",
139608          "version": "4.14.3-23.el8",
139609          "licenses": [
139610            {
139611              "license": {
139612                "name": "GPLv2+"
139613              }
139614            }
139615          ],
139616          "cpe": "cpe:2.3:a:redhat:rpm:4.14.3-23.el8:*:*:*:*:*:*:*",
139617          "purl": "pkg:rpm/rhel/rpm@4.14.3-23.el8?arch=x86_64\u0026upstream=rpm-4.14.3-23.el8.src.rpm\u0026distro=rhel-8.6",
139618          "swid": {
139619            "attachment": {}
139620          },
139621          "pedigree": {},
139622          "evidence": {},
139623          "signature": {
139624            "signature": {
139625              "publicKey": {}
139626            }
139627          },
139628          "modelCard": {
139629            "modelParameters": {
139630              "approach": {}
139631            },
139632            "quantitativeAnalysis": {
139633              "graphics": {}
139634            },
139635            "considerations": {}
139636          }
139637        },
139638        {
139639          "type": "library",
139640          "bom-ref": "pkg:rpm/rhel/rpm-libs@4.14.3-23.el8?arch=x86_64\u0026upstream=rpm-4.14.3-23.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=f5c738c4cf69b92f",
139641          "supplier": {},
139642          "publisher": "Red Hat, Inc.",
139643          "name": "rpm-libs",
139644          "version": "4.14.3-23.el8",
139645          "licenses": [
139646            {
139647              "license": {
139648                "name": "GPLv2+ and LGPLv2+ with exceptions"
139649              }
139650            }
139651          ],
139652          "cpe": "cpe:2.3:a:rpm-libs:rpm-libs:4.14.3-23.el8:*:*:*:*:*:*:*",
139653          "purl": "pkg:rpm/rhel/rpm-libs@4.14.3-23.el8?arch=x86_64\u0026upstream=rpm-4.14.3-23.el8.src.rpm\u0026distro=rhel-8.6",
139654          "swid": {
139655            "attachment": {}
139656          },
139657          "pedigree": {},
139658          "evidence": {},
139659          "signature": {
139660            "signature": {
139661              "publicKey": {}
139662            }
139663          },
139664          "modelCard": {
139665            "modelParameters": {
139666              "approach": {}
139667            },
139668            "quantitativeAnalysis": {
139669              "graphics": {}
139670            },
139671            "considerations": {}
139672          }
139673        },
139674        {
139675          "type": "library",
139676          "bom-ref": "pkg:rpm/rhel/sed@4.5-5.el8?arch=x86_64\u0026upstream=sed-4.5-5.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=159d798b8ff085f2",
139677          "supplier": {},
139678          "publisher": "Red Hat, Inc.",
139679          "name": "sed",
139680          "version": "4.5-5.el8",
139681          "licenses": [
139682            {
139683              "license": {
139684                "name": "GPLv3+"
139685              }
139686            }
139687          ],
139688          "cpe": "cpe:2.3:a:redhat:sed:4.5-5.el8:*:*:*:*:*:*:*",
139689          "purl": "pkg:rpm/rhel/sed@4.5-5.el8?arch=x86_64\u0026upstream=sed-4.5-5.el8.src.rpm\u0026distro=rhel-8.6",
139690          "swid": {
139691            "attachment": {}
139692          },
139693          "pedigree": {},
139694          "evidence": {},
139695          "signature": {
139696            "signature": {
139697              "publicKey": {}
139698            }
139699          },
139700          "modelCard": {
139701            "modelParameters": {
139702              "approach": {}
139703            },
139704            "quantitativeAnalysis": {
139705              "graphics": {}
139706            },
139707            "considerations": {}
139708          }
139709        },
139710        {
139711          "type": "library",
139712          "bom-ref": "pkg:rpm/rhel/setup@2.12.2-6.el8?arch=noarch\u0026upstream=setup-2.12.2-6.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=a70f2321beee4ac8",
139713          "supplier": {},
139714          "publisher": "Red Hat, Inc.",
139715          "name": "setup",
139716          "version": "2.12.2-6.el8",
139717          "licenses": [
139718            {
139719              "license": {
139720                "name": "Public Domain"
139721              }
139722            }
139723          ],
139724          "cpe": "cpe:2.3:a:redhat:setup:2.12.2-6.el8:*:*:*:*:*:*:*",
139725          "purl": "pkg:rpm/rhel/setup@2.12.2-6.el8?arch=noarch\u0026upstream=setup-2.12.2-6.el8.src.rpm\u0026distro=rhel-8.6",
139726          "swid": {
139727            "attachment": {}
139728          },
139729          "pedigree": {},
139730          "evidence": {},
139731          "signature": {
139732            "signature": {
139733              "publicKey": {}
139734            }
139735          },
139736          "modelCard": {
139737            "modelParameters": {
139738              "approach": {}
139739            },
139740            "quantitativeAnalysis": {
139741              "graphics": {}
139742            },
139743            "considerations": {}
139744          }
139745        },
139746        {
139747          "type": "library",
139748          "bom-ref": "pkg:rpm/rhel/shadow-utils@4.6-16.el8?arch=x86_64\u0026epoch=2\u0026upstream=shadow-utils-4.6-16.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=fa18e2d0e4dcbee0",
139749          "supplier": {},
139750          "publisher": "Red Hat, Inc.",
139751          "name": "shadow-utils",
139752          "version": "2:4.6-16.el8",
139753          "licenses": [
139754            {
139755              "license": {
139756                "name": "BSD and GPLv2+"
139757              }
139758            }
139759          ],
139760          "cpe": "cpe:2.3:a:shadow-utils:shadow-utils:2\\:4.6-16.el8:*:*:*:*:*:*:*",
139761          "purl": "pkg:rpm/rhel/shadow-utils@4.6-16.el8?arch=x86_64\u0026epoch=2\u0026upstream=shadow-utils-4.6-16.el8.src.rpm\u0026distro=rhel-8.6",
139762          "swid": {
139763            "attachment": {}
139764          },
139765          "pedigree": {},
139766          "evidence": {},
139767          "signature": {
139768            "signature": {
139769              "publicKey": {}
139770            }
139771          },
139772          "modelCard": {
139773            "modelParameters": {
139774              "approach": {}
139775            },
139776            "quantitativeAnalysis": {
139777              "graphics": {}
139778            },
139779            "considerations": {}
139780          }
139781        },
139782        {
139783          "type": "library",
139784          "bom-ref": "pkg:rpm/rhel/sqlite-libs@3.26.0-15.el8?arch=x86_64\u0026upstream=sqlite-3.26.0-15.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=e29e20bbd4cc3162",
139785          "supplier": {},
139786          "publisher": "Red Hat, Inc.",
139787          "name": "sqlite-libs",
139788          "version": "3.26.0-15.el8",
139789          "licenses": [
139790            {
139791              "license": {
139792                "name": "Public Domain"
139793              }
139794            }
139795          ],
139796          "cpe": "cpe:2.3:a:sqlite-libs:sqlite-libs:3.26.0-15.el8:*:*:*:*:*:*:*",
139797          "purl": "pkg:rpm/rhel/sqlite-libs@3.26.0-15.el8?arch=x86_64\u0026upstream=sqlite-3.26.0-15.el8.src.rpm\u0026distro=rhel-8.6",
139798          "swid": {
139799            "attachment": {}
139800          },
139801          "pedigree": {},
139802          "evidence": {},
139803          "signature": {
139804            "signature": {
139805              "publicKey": {}
139806            }
139807          },
139808          "modelCard": {
139809            "modelParameters": {
139810              "approach": {}
139811            },
139812            "quantitativeAnalysis": {
139813              "graphics": {}
139814            },
139815            "considerations": {}
139816          }
139817        },
139818        {
139819          "type": "library",
139820          "bom-ref": "pkg:rpm/rhel/systemd-libs@239-58.el8_6.7?arch=x86_64\u0026upstream=systemd-239-58.el8_6.7.src.rpm\u0026distro=rhel-8.6\u0026package-id=aaa1e024dff8197b",
139821          "supplier": {},
139822          "publisher": "Red Hat, Inc.",
139823          "name": "systemd-libs",
139824          "version": "239-58.el8_6.7",
139825          "licenses": [
139826            {
139827              "license": {
139828                "name": "LGPLv2+ and MIT"
139829              }
139830            }
139831          ],
139832          "cpe": "cpe:2.3:a:systemd-libs:systemd-libs:239-58.el8_6.7:*:*:*:*:*:*:*",
139833          "purl": "pkg:rpm/rhel/systemd-libs@239-58.el8_6.7?arch=x86_64\u0026upstream=systemd-239-58.el8_6.7.src.rpm\u0026distro=rhel-8.6",
139834          "swid": {
139835            "attachment": {}
139836          },
139837          "pedigree": {},
139838          "evidence": {},
139839          "signature": {
139840            "signature": {
139841              "publicKey": {}
139842            }
139843          },
139844          "modelCard": {
139845            "modelParameters": {
139846              "approach": {}
139847            },
139848            "quantitativeAnalysis": {
139849              "graphics": {}
139850            },
139851            "considerations": {}
139852          }
139853        },
139854        {
139855          "type": "library",
139856          "bom-ref": "pkg:rpm/rhel/tzdata@2022c-1.el8?arch=noarch\u0026upstream=tzdata-2022c-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=40501185c21edb6d",
139857          "supplier": {},
139858          "publisher": "Red Hat, Inc.",
139859          "name": "tzdata",
139860          "version": "2022c-1.el8",
139861          "licenses": [
139862            {
139863              "license": {
139864                "name": "Public Domain"
139865              }
139866            }
139867          ],
139868          "cpe": "cpe:2.3:a:redhat:tzdata:2022c-1.el8:*:*:*:*:*:*:*",
139869          "purl": "pkg:rpm/rhel/tzdata@2022c-1.el8?arch=noarch\u0026upstream=tzdata-2022c-1.el8.src.rpm\u0026distro=rhel-8.6",
139870          "swid": {
139871            "attachment": {}
139872          },
139873          "pedigree": {},
139874          "evidence": {},
139875          "signature": {
139876            "signature": {
139877              "publicKey": {}
139878            }
139879          },
139880          "modelCard": {
139881            "modelParameters": {
139882              "approach": {}
139883            },
139884            "quantitativeAnalysis": {
139885              "graphics": {}
139886            },
139887            "considerations": {}
139888          }
139889        },
139890        {
139891          "type": "library",
139892          "bom-ref": "pkg:rpm/rhel/tzdata@2022e-1.el8?arch=noarch\u0026upstream=tzdata-2022e-1.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=a4b858d525f17613",
139893          "supplier": {},
139894          "publisher": "Red Hat, Inc.",
139895          "name": "tzdata",
139896          "version": "2022e-1.el8",
139897          "licenses": [
139898            {
139899              "license": {
139900                "name": "Public Domain"
139901              }
139902            }
139903          ],
139904          "cpe": "cpe:2.3:a:redhat:tzdata:2022e-1.el8:*:*:*:*:*:*:*",
139905          "purl": "pkg:rpm/rhel/tzdata@2022e-1.el8?arch=noarch\u0026upstream=tzdata-2022e-1.el8.src.rpm\u0026distro=rhel-8.6",
139906          "swid": {
139907            "attachment": {}
139908          },
139909          "pedigree": {},
139910          "evidence": {},
139911          "signature": {
139912            "signature": {
139913              "publicKey": {}
139914            }
139915          },
139916          "modelCard": {
139917            "modelParameters": {
139918              "approach": {}
139919            },
139920            "quantitativeAnalysis": {
139921              "graphics": {}
139922            },
139923            "considerations": {}
139924          }
139925        },
139926        {
139927          "type": "library",
139928          "bom-ref": "pkg:rpm/rhel/util-linux@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6\u0026package-id=71479b278960efce",
139929          "supplier": {},
139930          "publisher": "Red Hat, Inc.",
139931          "name": "util-linux",
139932          "version": "2.32.1-35.el8",
139933          "licenses": [
139934            {
139935              "license": {
139936                "name": "GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"
139937              }
139938            }
139939          ],
139940          "cpe": "cpe:2.3:a:util-linux:util-linux:2.32.1-35.el8:*:*:*:*:*:*:*",
139941          "purl": "pkg:rpm/rhel/util-linux@2.32.1-35.el8?arch=x86_64\u0026upstream=util-linux-2.32.1-35.el8.src.rpm\u0026distro=rhel-8.6",
139942          "swid": {
139943            "attachment": {}
139944          },
139945          "pedigree": {},
139946          "evidence": {},
139947          "signature": {
139948            "signature": {
139949              "publicKey": {}
139950            }
139951          },
139952          "modelCard": {
139953            "modelParameters": {
139954              "approach": {}
139955            },
139956            "quantitativeAnalysis": {
139957              "graphics": {}
139958            },
139959            "considerations": {}
139960          }
139961        },
139962        {
139963          "type": "library",
139964          "bom-ref": "pkg:rpm/rhel/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026upstream=xz-5.2.4-4.el8_6.src.rpm\u0026distro=rhel-8.6\u0026package-id=486833b51e8afb80",
139965          "supplier": {},
139966          "publisher": "Red Hat, Inc.",
139967          "name": "xz-libs",
139968          "version": "5.2.4-4.el8_6",
139969          "licenses": [
139970            {
139971              "license": {
139972                "name": "Public Domain"
139973              }
139974            }
139975          ],
139976          "cpe": "cpe:2.3:a:xz-libs:xz-libs:5.2.4-4.el8_6:*:*:*:*:*:*:*",
139977          "purl": "pkg:rpm/rhel/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026upstream=xz-5.2.4-4.el8_6.src.rpm\u0026distro=rhel-8.6",
139978          "swid": {
139979            "attachment": {}
139980          },
139981          "pedigree": {},
139982          "evidence": {},
139983          "signature": {
139984            "signature": {
139985              "publicKey": {}
139986            }
139987          },
139988          "modelCard": {
139989            "modelParameters": {
139990              "approach": {}
139991            },
139992            "quantitativeAnalysis": {
139993              "graphics": {}
139994            },
139995            "considerations": {}
139996          }
139997        },
139998        {
139999          "type": "library",
140000          "bom-ref": "pkg:rpm/rhel/zlib@1.2.11-18.el8_5?arch=x86_64\u0026upstream=zlib-1.2.11-18.el8_5.src.rpm\u0026distro=rhel-8.6\u0026package-id=fa33927f0375bac0",
140001          "supplier": {},
140002          "publisher": "Red Hat, Inc.",
140003          "name": "zlib",
140004          "version": "1.2.11-18.el8_5",
140005          "licenses": [
140006            {
140007              "license": {
140008                "name": "zlib and Boost"
140009              }
140010            }
140011          ],
140012          "cpe": "cpe:2.3:a:redhat:zlib:1.2.11-18.el8_5:*:*:*:*:*:*:*",
140013          "purl": "pkg:rpm/rhel/zlib@1.2.11-18.el8_5?arch=x86_64\u0026upstream=zlib-1.2.11-18.el8_5.src.rpm\u0026distro=rhel-8.6",
140014          "swid": {
140015            "attachment": {}
140016          },
140017          "pedigree": {},
140018          "evidence": {},
140019          "signature": {
140020            "signature": {
140021              "publicKey": {}
140022            }
140023          },
140024          "modelCard": {
140025            "modelParameters": {
140026              "approach": {}
140027            },
140028            "quantitativeAnalysis": {
140029              "graphics": {}
140030            },
140031            "considerations": {}
140032          }
140033        },
140034        {
140035          "type": "operating-system",
140036          "supplier": {},
140037          "name": "rhel",
140038          "version": "8.6",
140039          "description": "Red Hat Enterprise Linux 8.6 (Ootpa)",
140040          "cpe": "cpe:2.3:o:redhat:enterprise_linux:8:*:baseos:*:*:*:*:*",
140041          "swid": {
140042            "tagId": "rhel",
140043            "name": "rhel",
140044            "version": "8.6",
140045            "attachment": {}
140046          },
140047          "pedigree": {},
140048          "externalReferences": [
140049            {
140050              "url": "https://bugzilla.redhat.com/",
140051              "type": "issue-tracker"
140052            },
140053            {
140054              "url": "https://www.redhat.com/",
140055              "type": "website"
140056            }
140057          ],
140058          "evidence": {},
140059          "signature": {
140060            "signature": {
140061              "publicKey": {}
140062            }
140063          },
140064          "modelCard": {
140065            "modelParameters": {
140066              "approach": {}
140067            },
140068            "quantitativeAnalysis": {
140069              "graphics": {}
140070            },
140071            "considerations": {}
140072          }
140073        },
140074        {
140075          "type": "library",
140076          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r6?arch=x86_64\u0026distro=alpine-3.12.0\u0026package-id=cb9c936830cdd1b4",
140077          "supplier": {},
140078          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
140079          "name": "alpine-baselayout",
140080          "version": "3.2.0-r6",
140081          "description": "Alpine base dir structure and init scripts",
140082          "licenses": [
140083            {
140084              "license": {
140085                "id": "GPL-2.0-only"
140086              }
140087            }
140088          ],
140089          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r6:*:*:*:*:*:*:*",
140090          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r6?arch=x86_64\u0026distro=alpine-3.12.0",
140091          "swid": {
140092            "attachment": {}
140093          },
140094          "pedigree": {},
140095          "externalReferences": [
140096            {
140097              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
140098              "type": "distribution"
140099            }
140100          ],
140101          "evidence": {},
140102          "signature": {
140103            "signature": {
140104              "publicKey": {}
140105            }
140106          },
140107          "modelCard": {
140108            "modelParameters": {
140109              "approach": {}
140110            },
140111            "quantitativeAnalysis": {
140112              "graphics": {}
140113            },
140114            "considerations": {}
140115          }
140116        },
140117        {
140118          "type": "library",
140119          "bom-ref": "pkg:apk/alpine/alpine-keys@2.2-r0?arch=x86_64\u0026distro=alpine-3.12.0\u0026package-id=6e76b2cc6bf8236",
140120          "supplier": {},
140121          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
140122          "name": "alpine-keys",
140123          "version": "2.2-r0",
140124          "description": "Public keys for Alpine Linux packages",
140125          "licenses": [
140126            {
140127              "license": {
140128                "id": "MIT"
140129              }
140130            }
140131          ],
140132          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.2-r0:*:*:*:*:*:*:*",
140133          "purl": "pkg:apk/alpine/alpine-keys@2.2-r0?arch=x86_64\u0026distro=alpine-3.12.0",
140134          "swid": {
140135            "attachment": {}
140136          },
140137          "pedigree": {},
140138          "externalReferences": [
140139            {
140140              "url": "https://alpinelinux.org",
140141              "type": "distribution"
140142            }
140143          ],
140144          "evidence": {},
140145          "signature": {
140146            "signature": {
140147              "publicKey": {}
140148            }
140149          },
140150          "modelCard": {
140151            "modelParameters": {
140152              "approach": {}
140153            },
140154            "quantitativeAnalysis": {
140155              "graphics": {}
140156            },
140157            "considerations": {}
140158          }
140159        },
140160        {
140161          "type": "library",
140162          "bom-ref": "pkg:apk/alpine/apk-tools@2.10.5-r1?arch=x86_64\u0026distro=alpine-3.12.0\u0026package-id=4c5552e9bb4204e",
140163          "supplier": {},
140164          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
140165          "name": "apk-tools",
140166          "version": "2.10.5-r1",
140167          "description": "Alpine Package Keeper - package manager for alpine",
140168          "licenses": [
140169            {
140170              "license": {
140171                "id": "GPL-2.0-only"
140172              }
140173            }
140174          ],
140175          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.10.5-r1:*:*:*:*:*:*:*",
140176          "purl": "pkg:apk/alpine/apk-tools@2.10.5-r1?arch=x86_64\u0026distro=alpine-3.12.0",
140177          "swid": {
140178            "attachment": {}
140179          },
140180          "pedigree": {},
140181          "externalReferences": [
140182            {
140183              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
140184              "type": "distribution"
140185            }
140186          ],
140187          "evidence": {},
140188          "signature": {
140189            "signature": {
140190              "publicKey": {}
140191            }
140192          },
140193          "modelCard": {
140194            "modelParameters": {
140195              "approach": {}
140196            },
140197            "quantitativeAnalysis": {
140198              "graphics": {}
140199            },
140200            "considerations": {}
140201          }
140202        },
140203        {
140204          "type": "application",
140205          "bom-ref": "c7f7fc7e2b76ab25",
140206          "supplier": {},
140207          "name": "busybox",
140208          "version": "1.31.1",
140209          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1:*:*:*:*:*:*:*",
140210          "swid": {
140211            "attachment": {}
140212          },
140213          "pedigree": {},
140214          "evidence": {},
140215          "signature": {
140216            "signature": {
140217              "publicKey": {}
140218            }
140219          },
140220          "modelCard": {
140221            "modelParameters": {
140222              "approach": {}
140223            },
140224            "quantitativeAnalysis": {
140225              "graphics": {}
140226            },
140227            "considerations": {}
140228          }
140229        },
140230        {
140231          "type": "library",
140232          "bom-ref": "pkg:apk/alpine/busybox@1.31.1-r16?arch=x86_64\u0026distro=alpine-3.12.0\u0026package-id=5933148412b0c042",
140233          "supplier": {},
140234          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
140235          "name": "busybox",
140236          "version": "1.31.1-r16",
140237          "description": "Size optimized toolbox of many common UNIX utilities",
140238          "licenses": [
140239            {
140240              "license": {
140241                "id": "GPL-2.0-only"
140242              }
140243            }
140244          ],
140245          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1-r16:*:*:*:*:*:*:*",
140246          "purl": "pkg:apk/alpine/busybox@1.31.1-r16?arch=x86_64\u0026distro=alpine-3.12.0",
140247          "swid": {
140248            "attachment": {}
140249          },
140250          "pedigree": {},
140251          "externalReferences": [
140252            {
140253              "url": "https://busybox.net/",
140254              "type": "distribution"
140255            }
140256          ],
140257          "evidence": {},
140258          "signature": {
140259            "signature": {
140260              "publicKey": {}
140261            }
140262          },
140263          "modelCard": {
140264            "modelParameters": {
140265              "approach": {}
140266            },
140267            "quantitativeAnalysis": {
140268              "graphics": {}
140269            },
140270            "considerations": {}
140271          }
140272        },
140273        {
140274          "type": "library",
140275          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20191127-r2?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.12.0\u0026package-id=c5af572d6bab8dd9",
140276          "supplier": {},
140277          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
140278          "name": "ca-certificates-bundle",
140279          "version": "20191127-r2",
140280          "description": "Pre generated bundle of Mozilla certificates",
140281          "licenses": [
140282            {
140283              "license": {
140284                "id": "MPL-2.0"
140285              }
140286            },
140287            {
140288              "license": {
140289                "id": "GPL-2.0-or-later"
140290              }
140291            }
140292          ],
140293          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20191127-r2:*:*:*:*:*:*:*",
140294          "purl": "pkg:apk/alpine/ca-certificates-bundle@20191127-r2?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.12.0",
140295          "swid": {
140296            "attachment": {}
140297          },
140298          "pedigree": {},
140299          "externalReferences": [
140300            {
140301              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
140302              "type": "distribution"
140303            }
140304          ],
140305          "evidence": {},
140306          "signature": {
140307            "signature": {
140308              "publicKey": {}
140309            }
140310          },
140311          "modelCard": {
140312            "modelParameters": {
140313              "approach": {}
140314            },
140315            "quantitativeAnalysis": {
140316              "graphics": {}
140317            },
140318            "considerations": {}
140319          }
140320        },
140321        {
140322          "type": "library",
140323          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.12.0\u0026package-id=cf75e8a6d9cf09fc",
140324          "supplier": {},
140325          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
140326          "name": "libc-utils",
140327          "version": "0.7.2-r3",
140328          "description": "Meta package to pull in correct libc",
140329          "licenses": [
140330            {
140331              "license": {
140332                "id": "BSD-2-Clause"
140333              }
140334            },
140335            {
140336              "license": {
140337                "name": "AND"
140338              }
140339            },
140340            {
140341              "license": {
140342                "id": "BSD-3-Clause"
140343              }
140344            }
140345          ],
140346          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
140347          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.12.0",
140348          "swid": {
140349            "attachment": {}
140350          },
140351          "pedigree": {},
140352          "externalReferences": [
140353            {
140354              "url": "https://alpinelinux.org",
140355              "type": "distribution"
140356            }
140357          ],
140358          "evidence": {},
140359          "signature": {
140360            "signature": {
140361              "publicKey": {}
140362            }
140363          },
140364          "modelCard": {
140365            "modelParameters": {
140366              "approach": {}
140367            },
140368            "quantitativeAnalysis": {
140369              "graphics": {}
140370            },
140371            "considerations": {}
140372          }
140373        },
140374        {
140375          "type": "library",
140376          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1g-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.12.0\u0026package-id=2efad31e3aae0b7",
140377          "supplier": {},
140378          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
140379          "name": "libcrypto1.1",
140380          "version": "1.1.1g-r0",
140381          "description": "Crypto library from openssl",
140382          "licenses": [
140383            {
140384              "license": {
140385                "id": "OpenSSL"
140386              }
140387            }
140388          ],
140389          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1g-r0:*:*:*:*:*:*:*",
140390          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1g-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.12.0",
140391          "swid": {
140392            "attachment": {}
140393          },
140394          "pedigree": {},
140395          "externalReferences": [
140396            {
140397              "url": "https://www.openssl.org/",
140398              "type": "distribution"
140399            }
140400          ],
140401          "evidence": {},
140402          "signature": {
140403            "signature": {
140404              "publicKey": {}
140405            }
140406          },
140407          "modelCard": {
140408            "modelParameters": {
140409              "approach": {}
140410            },
140411            "quantitativeAnalysis": {
140412              "graphics": {}
140413            },
140414            "considerations": {}
140415          }
140416        },
140417        {
140418          "type": "library",
140419          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1g-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.12.0\u0026package-id=ff9ffd0be98bf531",
140420          "supplier": {},
140421          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
140422          "name": "libssl1.1",
140423          "version": "1.1.1g-r0",
140424          "description": "SSL shared libraries",
140425          "licenses": [
140426            {
140427              "license": {
140428                "id": "OpenSSL"
140429              }
140430            }
140431          ],
140432          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1g-r0:*:*:*:*:*:*:*",
140433          "purl": "pkg:apk/alpine/libssl1.1@1.1.1g-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.12.0",
140434          "swid": {
140435            "attachment": {}
140436          },
140437          "pedigree": {},
140438          "externalReferences": [
140439            {
140440              "url": "https://www.openssl.org/",
140441              "type": "distribution"
140442            }
140443          ],
140444          "evidence": {},
140445          "signature": {
140446            "signature": {
140447              "publicKey": {}
140448            }
140449          },
140450          "modelCard": {
140451            "modelParameters": {
140452              "approach": {}
140453            },
140454            "quantitativeAnalysis": {
140455              "graphics": {}
140456            },
140457            "considerations": {}
140458          }
140459        },
140460        {
140461          "type": "library",
140462          "bom-ref": "pkg:apk/alpine/libtls-standalone@2.9.1-r1?arch=x86_64\u0026distro=alpine-3.12.0\u0026package-id=9af7ecda8019fe5b",
140463          "supplier": {},
140464          "name": "libtls-standalone",
140465          "version": "2.9.1-r1",
140466          "description": "libtls extricated from libressl sources",
140467          "licenses": [
140468            {
140469              "license": {
140470                "id": "ISC"
140471              }
140472            }
140473          ],
140474          "cpe": "cpe:2.3:a:libtls-standalone:libtls-standalone:2.9.1-r1:*:*:*:*:*:*:*",
140475          "purl": "pkg:apk/alpine/libtls-standalone@2.9.1-r1?arch=x86_64\u0026distro=alpine-3.12.0",
140476          "swid": {
140477            "attachment": {}
140478          },
140479          "pedigree": {},
140480          "externalReferences": [
140481            {
140482              "url": "https://www.libressl.org/",
140483              "type": "distribution"
140484            }
140485          ],
140486          "evidence": {},
140487          "signature": {
140488            "signature": {
140489              "publicKey": {}
140490            }
140491          },
140492          "modelCard": {
140493            "modelParameters": {
140494              "approach": {}
140495            },
140496            "quantitativeAnalysis": {
140497              "graphics": {}
140498            },
140499            "considerations": {}
140500          }
140501        },
140502        {
140503          "type": "library",
140504          "bom-ref": "pkg:apk/alpine/musl@1.1.24-r8?arch=x86_64\u0026distro=alpine-3.12.0\u0026package-id=8c619fe0fec71f88",
140505          "supplier": {},
140506          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
140507          "name": "musl",
140508          "version": "1.1.24-r8",
140509          "description": "the musl c library (libc) implementation",
140510          "licenses": [
140511            {
140512              "license": {
140513                "id": "MIT"
140514              }
140515            }
140516          ],
140517          "cpe": "cpe:2.3:a:musl-libc:musl:1.1.24-r8:*:*:*:*:*:*:*",
140518          "purl": "pkg:apk/alpine/musl@1.1.24-r8?arch=x86_64\u0026distro=alpine-3.12.0",
140519          "swid": {
140520            "attachment": {}
140521          },
140522          "pedigree": {},
140523          "externalReferences": [
140524            {
140525              "url": "https://musl.libc.org/",
140526              "type": "distribution"
140527            }
140528          ],
140529          "evidence": {},
140530          "signature": {
140531            "signature": {
140532              "publicKey": {}
140533            }
140534          },
140535          "modelCard": {
140536            "modelParameters": {
140537              "approach": {}
140538            },
140539            "quantitativeAnalysis": {
140540              "graphics": {}
140541            },
140542            "considerations": {}
140543          }
140544        },
140545        {
140546          "type": "library",
140547          "bom-ref": "pkg:apk/alpine/musl-utils@1.1.24-r8?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.12.0\u0026package-id=30c8a6c885b5baa1",
140548          "supplier": {},
140549          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
140550          "name": "musl-utils",
140551          "version": "1.1.24-r8",
140552          "description": "the musl c library (libc) implementation",
140553          "licenses": [
140554            {
140555              "license": {
140556                "id": "MIT"
140557              }
140558            },
140559            {
140560              "license": {
140561                "name": "BSD"
140562              }
140563            },
140564            {
140565              "license": {
140566                "id": "GPL-2.0-or-later"
140567              }
140568            }
140569          ],
140570          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.1.24-r8:*:*:*:*:*:*:*",
140571          "purl": "pkg:apk/alpine/musl-utils@1.1.24-r8?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.12.0",
140572          "swid": {
140573            "attachment": {}
140574          },
140575          "pedigree": {},
140576          "externalReferences": [
140577            {
140578              "url": "https://musl.libc.org/",
140579              "type": "distribution"
140580            }
140581          ],
140582          "evidence": {},
140583          "signature": {
140584            "signature": {
140585              "publicKey": {}
140586            }
140587          },
140588          "modelCard": {
140589            "modelParameters": {
140590              "approach": {}
140591            },
140592            "quantitativeAnalysis": {
140593              "graphics": {}
140594            },
140595            "considerations": {}
140596          }
140597        },
140598        {
140599          "type": "library",
140600          "bom-ref": "pkg:apk/alpine/scanelf@1.2.6-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.12.0\u0026package-id=6bb4b607de5648aa",
140601          "supplier": {},
140602          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
140603          "name": "scanelf",
140604          "version": "1.2.6-r0",
140605          "description": "Scan ELF binaries for stuff",
140606          "licenses": [
140607            {
140608              "license": {
140609                "id": "GPL-2.0-only"
140610              }
140611            }
140612          ],
140613          "cpe": "cpe:2.3:a:scanelf:scanelf:1.2.6-r0:*:*:*:*:*:*:*",
140614          "purl": "pkg:apk/alpine/scanelf@1.2.6-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.12.0",
140615          "swid": {
140616            "attachment": {}
140617          },
140618          "pedigree": {},
140619          "externalReferences": [
140620            {
140621              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
140622              "type": "distribution"
140623            }
140624          ],
140625          "evidence": {},
140626          "signature": {
140627            "signature": {
140628              "publicKey": {}
140629            }
140630          },
140631          "modelCard": {
140632            "modelParameters": {
140633              "approach": {}
140634            },
140635            "quantitativeAnalysis": {
140636              "graphics": {}
140637            },
140638            "considerations": {}
140639          }
140640        },
140641        {
140642          "type": "library",
140643          "bom-ref": "pkg:apk/alpine/ssl_client@1.31.1-r16?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.12.0\u0026package-id=e7b773e0ca06b456",
140644          "supplier": {},
140645          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
140646          "name": "ssl_client",
140647          "version": "1.31.1-r16",
140648          "description": "EXternal ssl_client for busybox wget",
140649          "licenses": [
140650            {
140651              "license": {
140652                "id": "GPL-2.0-only"
140653              }
140654            }
140655          ],
140656          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.31.1-r16:*:*:*:*:*:*:*",
140657          "purl": "pkg:apk/alpine/ssl_client@1.31.1-r16?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.12.0",
140658          "swid": {
140659            "attachment": {}
140660          },
140661          "pedigree": {},
140662          "externalReferences": [
140663            {
140664              "url": "https://busybox.net/",
140665              "type": "distribution"
140666            }
140667          ],
140668          "evidence": {},
140669          "signature": {
140670            "signature": {
140671              "publicKey": {}
140672            }
140673          },
140674          "modelCard": {
140675            "modelParameters": {
140676              "approach": {}
140677            },
140678            "quantitativeAnalysis": {
140679              "graphics": {}
140680            },
140681            "considerations": {}
140682          }
140683        },
140684        {
140685          "type": "library",
140686          "bom-ref": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.12.0\u0026package-id=e5b843eacba99f13",
140687          "supplier": {},
140688          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
140689          "name": "zlib",
140690          "version": "1.2.11-r3",
140691          "description": "A compression/decompression Library",
140692          "licenses": [
140693            {
140694              "license": {
140695                "id": "Zlib"
140696              }
140697            }
140698          ],
140699          "cpe": "cpe:2.3:a:zlib:zlib:1.2.11-r3:*:*:*:*:*:*:*",
140700          "purl": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.12.0",
140701          "swid": {
140702            "attachment": {}
140703          },
140704          "pedigree": {},
140705          "externalReferences": [
140706            {
140707              "url": "https://zlib.net/",
140708              "type": "distribution"
140709            }
140710          ],
140711          "evidence": {},
140712          "signature": {
140713            "signature": {
140714              "publicKey": {}
140715            }
140716          },
140717          "modelCard": {
140718            "modelParameters": {
140719              "approach": {}
140720            },
140721            "quantitativeAnalysis": {
140722              "graphics": {}
140723            },
140724            "considerations": {}
140725          }
140726        },
140727        {
140728          "type": "operating-system",
140729          "supplier": {},
140730          "name": "alpine",
140731          "version": "3.12.0",
140732          "description": "Alpine Linux v3.12",
140733          "swid": {
140734            "tagId": "alpine",
140735            "name": "alpine",
140736            "version": "3.12.0",
140737            "attachment": {}
140738          },
140739          "pedigree": {},
140740          "externalReferences": [
140741            {
140742              "url": "https://bugs.alpinelinux.org/",
140743              "type": "issue-tracker"
140744            },
140745            {
140746              "url": "https://alpinelinux.org/",
140747              "type": "website"
140748            }
140749          ],
140750          "evidence": {},
140751          "signature": {
140752            "signature": {
140753              "publicKey": {}
140754            }
140755          },
140756          "modelCard": {
140757            "modelParameters": {
140758              "approach": {}
140759            },
140760            "quantitativeAnalysis": {
140761              "graphics": {}
140762            },
140763            "considerations": {}
140764          }
140765        },
140766        {
140767          "type": "library",
140768          "bom-ref": "pkg:deb/debian/base-files@10.3+deb10u9?arch=amd64\u0026distro=debian-10\u0026package-id=5aa6e4929bf16696",
140769          "supplier": {},
140770          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
140771          "name": "base-files",
140772          "version": "10.3+deb10u9",
140773          "licenses": [
140774            {
140775              "license": {
140776                "name": "GPL"
140777              }
140778            }
140779          ],
140780          "cpe": "cpe:2.3:a:base-files:base-files:10.3\\+deb10u9:*:*:*:*:*:*:*",
140781          "purl": "pkg:deb/debian/base-files@10.3+deb10u9?arch=amd64\u0026distro=debian-10",
140782          "swid": {
140783            "attachment": {}
140784          },
140785          "pedigree": {},
140786          "evidence": {},
140787          "signature": {
140788            "signature": {
140789              "publicKey": {}
140790            }
140791          },
140792          "modelCard": {
140793            "modelParameters": {
140794              "approach": {}
140795            },
140796            "quantitativeAnalysis": {
140797              "graphics": {}
140798            },
140799            "considerations": {}
140800          }
140801        },
140802        {
140803          "type": "library",
140804          "bom-ref": "pkg:golang/github.com/beorn7/perks@v1.0.1?package-id=2053cbd7487ca8ea",
140805          "supplier": {},
140806          "name": "github.com/beorn7/perks",
140807          "version": "v1.0.1",
140808          "cpe": "cpe:2.3:a:beorn7:perks:v1.0.1:*:*:*:*:*:*:*",
140809          "purl": "pkg:golang/github.com/beorn7/perks@v1.0.1",
140810          "swid": {
140811            "attachment": {}
140812          },
140813          "pedigree": {},
140814          "evidence": {},
140815          "signature": {
140816            "signature": {
140817              "publicKey": {}
140818            }
140819          },
140820          "modelCard": {
140821            "modelParameters": {
140822              "approach": {}
140823            },
140824            "quantitativeAnalysis": {
140825              "graphics": {}
140826            },
140827            "considerations": {}
140828          }
140829        },
140830        {
140831          "type": "library",
140832          "bom-ref": "pkg:golang/github.com/blang/semver@v3.5.1+incompatible?package-id=feed8c8267911e82",
140833          "supplier": {},
140834          "name": "github.com/blang/semver",
140835          "version": "v3.5.1+incompatible",
140836          "cpe": "cpe:2.3:a:blang:semver:v3.5.1\\+incompatible:*:*:*:*:*:*:*",
140837          "purl": "pkg:golang/github.com/blang/semver@v3.5.1+incompatible",
140838          "swid": {
140839            "attachment": {}
140840          },
140841          "pedigree": {},
140842          "evidence": {},
140843          "signature": {
140844            "signature": {
140845              "publicKey": {}
140846            }
140847          },
140848          "modelCard": {
140849            "modelParameters": {
140850              "approach": {}
140851            },
140852            "quantitativeAnalysis": {
140853              "graphics": {}
140854            },
140855            "considerations": {}
140856          }
140857        },
140858        {
140859          "type": "library",
140860          "bom-ref": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1?package-id=5f868d1576fdcd11",
140861          "supplier": {},
140862          "name": "github.com/cespare/xxhash/v2",
140863          "version": "v2.1.1",
140864          "cpe": "cpe:2.3:a:cespare:xxhash\\/v2:v2.1.1:*:*:*:*:*:*:*",
140865          "purl": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1",
140866          "swid": {
140867            "attachment": {}
140868          },
140869          "pedigree": {},
140870          "evidence": {},
140871          "signature": {
140872            "signature": {
140873              "publicKey": {}
140874            }
140875          },
140876          "modelCard": {
140877            "modelParameters": {
140878              "approach": {}
140879            },
140880            "quantitativeAnalysis": {
140881              "graphics": {}
140882            },
140883            "considerations": {}
140884          }
140885        },
140886        {
140887          "type": "library",
140888          "bom-ref": "pkg:golang/github.com/container-storage-interface/spec@v1.4.0?package-id=df466f544a58829f",
140889          "supplier": {},
140890          "name": "github.com/container-storage-interface/spec",
140891          "version": "v1.4.0",
140892          "cpe": "cpe:2.3:a:container-storage-interface:spec:v1.4.0:*:*:*:*:*:*:*",
140893          "purl": "pkg:golang/github.com/container-storage-interface/spec@v1.4.0",
140894          "swid": {
140895            "attachment": {}
140896          },
140897          "pedigree": {},
140898          "evidence": {},
140899          "signature": {
140900            "signature": {
140901              "publicKey": {}
140902            }
140903          },
140904          "modelCard": {
140905            "modelParameters": {
140906              "approach": {}
140907            },
140908            "quantitativeAnalysis": {
140909              "graphics": {}
140910            },
140911            "considerations": {}
140912          }
140913        },
140914        {
140915          "type": "library",
140916          "bom-ref": "pkg:golang/github.com/davecgh/go-spew@v1.1.1?package-id=a66d99cb9a4c2b73",
140917          "supplier": {},
140918          "name": "github.com/davecgh/go-spew",
140919          "version": "v1.1.1",
140920          "cpe": "cpe:2.3:a:davecgh:go-spew:v1.1.1:*:*:*:*:*:*:*",
140921          "purl": "pkg:golang/github.com/davecgh/go-spew@v1.1.1",
140922          "swid": {
140923            "attachment": {}
140924          },
140925          "pedigree": {},
140926          "evidence": {},
140927          "signature": {
140928            "signature": {
140929              "publicKey": {}
140930            }
140931          },
140932          "modelCard": {
140933            "modelParameters": {
140934              "approach": {}
140935            },
140936            "quantitativeAnalysis": {
140937              "graphics": {}
140938            },
140939            "considerations": {}
140940          }
140941        },
140942        {
140943          "type": "library",
140944          "bom-ref": "pkg:golang/github.com/evanphx/json-patch@v4.9.0+incompatible?package-id=c3f3d8d12c2f7337",
140945          "supplier": {},
140946          "name": "github.com/evanphx/json-patch",
140947          "version": "v4.9.0+incompatible",
140948          "cpe": "cpe:2.3:a:evanphx:json-patch:v4.9.0\\+incompatible:*:*:*:*:*:*:*",
140949          "purl": "pkg:golang/github.com/evanphx/json-patch@v4.9.0+incompatible",
140950          "swid": {
140951            "attachment": {}
140952          },
140953          "pedigree": {},
140954          "evidence": {},
140955          "signature": {
140956            "signature": {
140957              "publicKey": {}
140958            }
140959          },
140960          "modelCard": {
140961            "modelParameters": {
140962              "approach": {}
140963            },
140964            "quantitativeAnalysis": {
140965              "graphics": {}
140966            },
140967            "considerations": {}
140968          }
140969        },
140970        {
140971          "type": "library",
140972          "bom-ref": "pkg:golang/github.com/go-logr/logr@v0.4.0?package-id=1de7ef165be7c1a9",
140973          "supplier": {},
140974          "name": "github.com/go-logr/logr",
140975          "version": "v0.4.0",
140976          "cpe": "cpe:2.3:a:go-logr:logr:v0.4.0:*:*:*:*:*:*:*",
140977          "purl": "pkg:golang/github.com/go-logr/logr@v0.4.0",
140978          "swid": {
140979            "attachment": {}
140980          },
140981          "pedigree": {},
140982          "evidence": {},
140983          "signature": {
140984            "signature": {
140985              "publicKey": {}
140986            }
140987          },
140988          "modelCard": {
140989            "modelParameters": {
140990              "approach": {}
140991            },
140992            "quantitativeAnalysis": {
140993              "graphics": {}
140994            },
140995            "considerations": {}
140996          }
140997        },
140998        {
140999          "type": "library",
141000          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.2?package-id=1f7006f4c2049e6c",
141001          "supplier": {},
141002          "name": "github.com/gogo/protobuf",
141003          "version": "v1.3.2",
141004          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.2:*:*:*:*:*:*:*",
141005          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.2",
141006          "swid": {
141007            "attachment": {}
141008          },
141009          "pedigree": {},
141010          "evidence": {},
141011          "signature": {
141012            "signature": {
141013              "publicKey": {}
141014            }
141015          },
141016          "modelCard": {
141017            "modelParameters": {
141018              "approach": {}
141019            },
141020            "quantitativeAnalysis": {
141021              "graphics": {}
141022            },
141023            "considerations": {}
141024          }
141025        },
141026        {
141027          "type": "library",
141028          "bom-ref": "pkg:golang/github.com/golang/groupcache@v0.0.0-20200121045136-8c9f03a8e57e?package-id=ade818ebe0450085",
141029          "supplier": {},
141030          "name": "github.com/golang/groupcache",
141031          "version": "v0.0.0-20200121045136-8c9f03a8e57e",
141032          "cpe": "cpe:2.3:a:golang:groupcache:v0.0.0-20200121045136-8c9f03a8e57e:*:*:*:*:*:*:*",
141033          "purl": "pkg:golang/github.com/golang/groupcache@v0.0.0-20200121045136-8c9f03a8e57e",
141034          "swid": {
141035            "attachment": {}
141036          },
141037          "pedigree": {},
141038          "evidence": {},
141039          "signature": {
141040            "signature": {
141041              "publicKey": {}
141042            }
141043          },
141044          "modelCard": {
141045            "modelParameters": {
141046              "approach": {}
141047            },
141048            "quantitativeAnalysis": {
141049              "graphics": {}
141050            },
141051            "considerations": {}
141052          }
141053        },
141054        {
141055          "type": "library",
141056          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.5.1?package-id=60da2529107650f9",
141057          "supplier": {},
141058          "name": "github.com/golang/protobuf",
141059          "version": "v1.5.1",
141060          "cpe": "cpe:2.3:a:golang:protobuf:v1.5.1:*:*:*:*:*:*:*",
141061          "purl": "pkg:golang/github.com/golang/protobuf@v1.5.1",
141062          "swid": {
141063            "attachment": {}
141064          },
141065          "pedigree": {},
141066          "evidence": {},
141067          "signature": {
141068            "signature": {
141069              "publicKey": {}
141070            }
141071          },
141072          "modelCard": {
141073            "modelParameters": {
141074              "approach": {}
141075            },
141076            "quantitativeAnalysis": {
141077              "graphics": {}
141078            },
141079            "considerations": {}
141080          }
141081        },
141082        {
141083          "type": "library",
141084          "bom-ref": "pkg:golang/github.com/google/go-cmp@v0.5.5?package-id=a0f1cbad3e9f5659",
141085          "supplier": {},
141086          "name": "github.com/google/go-cmp",
141087          "version": "v0.5.5",
141088          "cpe": "cpe:2.3:a:google:go-cmp:v0.5.5:*:*:*:*:*:*:*",
141089          "purl": "pkg:golang/github.com/google/go-cmp@v0.5.5",
141090          "swid": {
141091            "attachment": {}
141092          },
141093          "pedigree": {},
141094          "evidence": {},
141095          "signature": {
141096            "signature": {
141097              "publicKey": {}
141098            }
141099          },
141100          "modelCard": {
141101            "modelParameters": {
141102              "approach": {}
141103            },
141104            "quantitativeAnalysis": {
141105              "graphics": {}
141106            },
141107            "considerations": {}
141108          }
141109        },
141110        {
141111          "type": "library",
141112          "bom-ref": "pkg:golang/github.com/google/gofuzz@v1.2.0?package-id=a85884e76c725b34",
141113          "supplier": {},
141114          "name": "github.com/google/gofuzz",
141115          "version": "v1.2.0",
141116          "cpe": "cpe:2.3:a:google:gofuzz:v1.2.0:*:*:*:*:*:*:*",
141117          "purl": "pkg:golang/github.com/google/gofuzz@v1.2.0",
141118          "swid": {
141119            "attachment": {}
141120          },
141121          "pedigree": {},
141122          "evidence": {},
141123          "signature": {
141124            "signature": {
141125              "publicKey": {}
141126            }
141127          },
141128          "modelCard": {
141129            "modelParameters": {
141130              "approach": {}
141131            },
141132            "quantitativeAnalysis": {
141133              "graphics": {}
141134            },
141135            "considerations": {}
141136          }
141137        },
141138        {
141139          "type": "library",
141140          "bom-ref": "pkg:golang/github.com/googleapis/gnostic@v0.5.4?package-id=ad65d61e9224f044",
141141          "supplier": {},
141142          "name": "github.com/googleapis/gnostic",
141143          "version": "v0.5.4",
141144          "cpe": "cpe:2.3:a:googleapis:gnostic:v0.5.4:*:*:*:*:*:*:*",
141145          "purl": "pkg:golang/github.com/googleapis/gnostic@v0.5.4",
141146          "swid": {
141147            "attachment": {}
141148          },
141149          "pedigree": {},
141150          "evidence": {},
141151          "signature": {
141152            "signature": {
141153              "publicKey": {}
141154            }
141155          },
141156          "modelCard": {
141157            "modelParameters": {
141158              "approach": {}
141159            },
141160            "quantitativeAnalysis": {
141161              "graphics": {}
141162            },
141163            "considerations": {}
141164          }
141165        },
141166        {
141167          "type": "library",
141168          "bom-ref": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.4?package-id=847799a13c8441ca",
141169          "supplier": {},
141170          "name": "github.com/hashicorp/golang-lru",
141171          "version": "v0.5.4",
141172          "cpe": "cpe:2.3:a:hashicorp:golang-lru:v0.5.4:*:*:*:*:*:*:*",
141173          "purl": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.4",
141174          "swid": {
141175            "attachment": {}
141176          },
141177          "pedigree": {},
141178          "evidence": {},
141179          "signature": {
141180            "signature": {
141181              "publicKey": {}
141182            }
141183          },
141184          "modelCard": {
141185            "modelParameters": {
141186              "approach": {}
141187            },
141188            "quantitativeAnalysis": {
141189              "graphics": {}
141190            },
141191            "considerations": {}
141192          }
141193        },
141194        {
141195          "type": "library",
141196          "bom-ref": "pkg:golang/github.com/imdario/mergo@v0.3.12?package-id=8121c4bb67073130",
141197          "supplier": {},
141198          "name": "github.com/imdario/mergo",
141199          "version": "v0.3.12",
141200          "cpe": "cpe:2.3:a:imdario:mergo:v0.3.12:*:*:*:*:*:*:*",
141201          "purl": "pkg:golang/github.com/imdario/mergo@v0.3.12",
141202          "swid": {
141203            "attachment": {}
141204          },
141205          "pedigree": {},
141206          "evidence": {},
141207          "signature": {
141208            "signature": {
141209              "publicKey": {}
141210            }
141211          },
141212          "modelCard": {
141213            "modelParameters": {
141214              "approach": {}
141215            },
141216            "quantitativeAnalysis": {
141217              "graphics": {}
141218            },
141219            "considerations": {}
141220          }
141221        },
141222        {
141223          "type": "library",
141224          "bom-ref": "pkg:golang/github.com/json-iterator/go@v1.1.10?package-id=f78e766297e3c595",
141225          "supplier": {},
141226          "name": "github.com/json-iterator/go",
141227          "version": "v1.1.10",
141228          "cpe": "cpe:2.3:a:json-iterator:go:v1.1.10:*:*:*:*:*:*:*",
141229          "purl": "pkg:golang/github.com/json-iterator/go@v1.1.10",
141230          "swid": {
141231            "attachment": {}
141232          },
141233          "pedigree": {},
141234          "evidence": {},
141235          "signature": {
141236            "signature": {
141237              "publicKey": {}
141238            }
141239          },
141240          "modelCard": {
141241            "modelParameters": {
141242              "approach": {}
141243            },
141244            "quantitativeAnalysis": {
141245              "graphics": {}
141246            },
141247            "considerations": {}
141248          }
141249        },
141250        {
141251          "type": "library",
141252          "bom-ref": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.9.1?package-id=9abad8b34dcbfbd4",
141253          "supplier": {},
141254          "name": "github.com/kubernetes-csi/csi-lib-utils",
141255          "version": "v0.9.1",
141256          "cpe": "cpe:2.3:a:kubernetes-csi:csi-lib-utils:v0.9.1:*:*:*:*:*:*:*",
141257          "purl": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.9.1",
141258          "swid": {
141259            "attachment": {}
141260          },
141261          "pedigree": {},
141262          "evidence": {},
141263          "signature": {
141264            "signature": {
141265              "publicKey": {}
141266            }
141267          },
141268          "modelCard": {
141269            "modelParameters": {
141270              "approach": {}
141271            },
141272            "quantitativeAnalysis": {
141273              "graphics": {}
141274            },
141275            "considerations": {}
141276          }
141277        },
141278        {
141279          "type": "library",
141280          "bom-ref": "pkg:golang/github.com/kubernetes-csi/external-attacher@(devel)?package-id=c6e7a0e4fd1233bc",
141281          "supplier": {},
141282          "name": "github.com/kubernetes-csi/external-attacher",
141283          "version": "(devel)",
141284          "cpe": "cpe:2.3:a:kubernetes-csi:external-attacher:\\(devel\\):*:*:*:*:*:*:*",
141285          "purl": "pkg:golang/github.com/kubernetes-csi/external-attacher@(devel)",
141286          "swid": {
141287            "attachment": {}
141288          },
141289          "pedigree": {},
141290          "evidence": {},
141291          "signature": {
141292            "signature": {
141293              "publicKey": {}
141294            }
141295          },
141296          "modelCard": {
141297            "modelParameters": {
141298              "approach": {}
141299            },
141300            "quantitativeAnalysis": {
141301              "graphics": {}
141302            },
141303            "considerations": {}
141304          }
141305        },
141306        {
141307          "type": "library",
141308          "bom-ref": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369?package-id=9199bffe49d1f2e5",
141309          "supplier": {},
141310          "name": "github.com/matttproud/golang_protobuf_extensions",
141311          "version": "v1.0.2-0.20181231171920-c182affec369",
141312          "cpe": "cpe:2.3:a:matttproud:golang-protobuf-extensions:v1.0.2-0.20181231171920-c182affec369:*:*:*:*:*:*:*",
141313          "purl": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369",
141314          "swid": {
141315            "attachment": {}
141316          },
141317          "pedigree": {},
141318          "evidence": {},
141319          "signature": {
141320            "signature": {
141321              "publicKey": {}
141322            }
141323          },
141324          "modelCard": {
141325            "modelParameters": {
141326              "approach": {}
141327            },
141328            "quantitativeAnalysis": {
141329              "graphics": {}
141330            },
141331            "considerations": {}
141332          }
141333        },
141334        {
141335          "type": "library",
141336          "bom-ref": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd?package-id=4b9acff0c68448ee",
141337          "supplier": {},
141338          "name": "github.com/modern-go/concurrent",
141339          "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
141340          "cpe": "cpe:2.3:a:modern-go:concurrent:v0.0.0-20180306012644-bacd9c7ef1dd:*:*:*:*:*:*:*",
141341          "purl": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd",
141342          "swid": {
141343            "attachment": {}
141344          },
141345          "pedigree": {},
141346          "evidence": {},
141347          "signature": {
141348            "signature": {
141349              "publicKey": {}
141350            }
141351          },
141352          "modelCard": {
141353            "modelParameters": {
141354              "approach": {}
141355            },
141356            "quantitativeAnalysis": {
141357              "graphics": {}
141358            },
141359            "considerations": {}
141360          }
141361        },
141362        {
141363          "type": "library",
141364          "bom-ref": "pkg:golang/github.com/modern-go/reflect2@v1.0.1?package-id=e81e1f8ca994c1f0",
141365          "supplier": {},
141366          "name": "github.com/modern-go/reflect2",
141367          "version": "v1.0.1",
141368          "cpe": "cpe:2.3:a:modern-go:reflect2:v1.0.1:*:*:*:*:*:*:*",
141369          "purl": "pkg:golang/github.com/modern-go/reflect2@v1.0.1",
141370          "swid": {
141371            "attachment": {}
141372          },
141373          "pedigree": {},
141374          "evidence": {},
141375          "signature": {
141376            "signature": {
141377              "publicKey": {}
141378            }
141379          },
141380          "modelCard": {
141381            "modelParameters": {
141382              "approach": {}
141383            },
141384            "quantitativeAnalysis": {
141385              "graphics": {}
141386            },
141387            "considerations": {}
141388          }
141389        },
141390        {
141391          "type": "library",
141392          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.9.1?package-id=ba043f5f90a9e4e",
141393          "supplier": {},
141394          "name": "github.com/pkg/errors",
141395          "version": "v0.9.1",
141396          "cpe": "cpe:2.3:a:pkg:errors:v0.9.1:*:*:*:*:*:*:*",
141397          "purl": "pkg:golang/github.com/pkg/errors@v0.9.1",
141398          "swid": {
141399            "attachment": {}
141400          },
141401          "pedigree": {},
141402          "evidence": {},
141403          "signature": {
141404            "signature": {
141405              "publicKey": {}
141406            }
141407          },
141408          "modelCard": {
141409            "modelParameters": {
141410              "approach": {}
141411            },
141412            "quantitativeAnalysis": {
141413              "graphics": {}
141414            },
141415            "considerations": {}
141416          }
141417        },
141418        {
141419          "type": "library",
141420          "bom-ref": "pkg:golang/github.com/prometheus/client_golang@v1.9.0?package-id=93c70d21e2c848ac",
141421          "supplier": {},
141422          "name": "github.com/prometheus/client_golang",
141423          "version": "v1.9.0",
141424          "cpe": "cpe:2.3:a:prometheus:client-golang:v1.9.0:*:*:*:*:*:*:*",
141425          "purl": "pkg:golang/github.com/prometheus/client_golang@v1.9.0",
141426          "swid": {
141427            "attachment": {}
141428          },
141429          "pedigree": {},
141430          "evidence": {},
141431          "signature": {
141432            "signature": {
141433              "publicKey": {}
141434            }
141435          },
141436          "modelCard": {
141437            "modelParameters": {
141438              "approach": {}
141439            },
141440            "quantitativeAnalysis": {
141441              "graphics": {}
141442            },
141443            "considerations": {}
141444          }
141445        },
141446        {
141447          "type": "library",
141448          "bom-ref": "pkg:golang/github.com/prometheus/client_model@v0.2.0?package-id=5ab3ebc090b83583",
141449          "supplier": {},
141450          "name": "github.com/prometheus/client_model",
141451          "version": "v0.2.0",
141452          "cpe": "cpe:2.3:a:prometheus:client-model:v0.2.0:*:*:*:*:*:*:*",
141453          "purl": "pkg:golang/github.com/prometheus/client_model@v0.2.0",
141454          "swid": {
141455            "attachment": {}
141456          },
141457          "pedigree": {},
141458          "evidence": {},
141459          "signature": {
141460            "signature": {
141461              "publicKey": {}
141462            }
141463          },
141464          "modelCard": {
141465            "modelParameters": {
141466              "approach": {}
141467            },
141468            "quantitativeAnalysis": {
141469              "graphics": {}
141470            },
141471            "considerations": {}
141472          }
141473        },
141474        {
141475          "type": "library",
141476          "bom-ref": "pkg:golang/github.com/prometheus/common@v0.19.0?package-id=c4302444a88710ca",
141477          "supplier": {},
141478          "name": "github.com/prometheus/common",
141479          "version": "v0.19.0",
141480          "cpe": "cpe:2.3:a:prometheus:common:v0.19.0:*:*:*:*:*:*:*",
141481          "purl": "pkg:golang/github.com/prometheus/common@v0.19.0",
141482          "swid": {
141483            "attachment": {}
141484          },
141485          "pedigree": {},
141486          "evidence": {},
141487          "signature": {
141488            "signature": {
141489              "publicKey": {}
141490            }
141491          },
141492          "modelCard": {
141493            "modelParameters": {
141494              "approach": {}
141495            },
141496            "quantitativeAnalysis": {
141497              "graphics": {}
141498            },
141499            "considerations": {}
141500          }
141501        },
141502        {
141503          "type": "library",
141504          "bom-ref": "pkg:golang/github.com/prometheus/procfs@v0.6.0?package-id=e9619d77aeba0ea1",
141505          "supplier": {},
141506          "name": "github.com/prometheus/procfs",
141507          "version": "v0.6.0",
141508          "cpe": "cpe:2.3:a:prometheus:procfs:v0.6.0:*:*:*:*:*:*:*",
141509          "purl": "pkg:golang/github.com/prometheus/procfs@v0.6.0",
141510          "swid": {
141511            "attachment": {}
141512          },
141513          "pedigree": {},
141514          "evidence": {},
141515          "signature": {
141516            "signature": {
141517              "publicKey": {}
141518            }
141519          },
141520          "modelCard": {
141521            "modelParameters": {
141522              "approach": {}
141523            },
141524            "quantitativeAnalysis": {
141525              "graphics": {}
141526            },
141527            "considerations": {}
141528          }
141529        },
141530        {
141531          "type": "library",
141532          "bom-ref": "pkg:golang/github.com/spf13/pflag@v1.0.5?package-id=a246a1efaed3fb16",
141533          "supplier": {},
141534          "name": "github.com/spf13/pflag",
141535          "version": "v1.0.5",
141536          "cpe": "cpe:2.3:a:spf13:pflag:v1.0.5:*:*:*:*:*:*:*",
141537          "purl": "pkg:golang/github.com/spf13/pflag@v1.0.5",
141538          "swid": {
141539            "attachment": {}
141540          },
141541          "pedigree": {},
141542          "evidence": {},
141543          "signature": {
141544            "signature": {
141545              "publicKey": {}
141546            }
141547          },
141548          "modelCard": {
141549            "modelParameters": {
141550              "approach": {}
141551            },
141552            "quantitativeAnalysis": {
141553              "graphics": {}
141554            },
141555            "considerations": {}
141556          }
141557        },
141558        {
141559          "type": "library",
141560          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1?package-id=b22630daeaccdf65",
141561          "supplier": {},
141562          "name": "golang.org/x/net",
141563          "version": "v0.0.0-20210410081132-afb366fc7cd1",
141564          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20210410081132-afb366fc7cd1:*:*:*:*:*:*:*",
141565          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1",
141566          "swid": {
141567            "attachment": {}
141568          },
141569          "pedigree": {},
141570          "evidence": {},
141571          "signature": {
141572            "signature": {
141573              "publicKey": {}
141574            }
141575          },
141576          "modelCard": {
141577            "modelParameters": {
141578              "approach": {}
141579            },
141580            "quantitativeAnalysis": {
141581              "graphics": {}
141582            },
141583            "considerations": {}
141584          }
141585        },
141586        {
141587          "type": "library",
141588          "bom-ref": "pkg:golang/golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84?package-id=29dac68ea756a565",
141589          "supplier": {},
141590          "name": "golang.org/x/oauth2",
141591          "version": "v0.0.0-20210313182246-cd4f82c27b84",
141592          "cpe": "cpe:2.3:a:golang:x\\/oauth2:v0.0.0-20210313182246-cd4f82c27b84:*:*:*:*:*:*:*",
141593          "purl": "pkg:golang/golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84",
141594          "swid": {
141595            "attachment": {}
141596          },
141597          "pedigree": {},
141598          "evidence": {},
141599          "signature": {
141600            "signature": {
141601              "publicKey": {}
141602            }
141603          },
141604          "modelCard": {
141605            "modelParameters": {
141606              "approach": {}
141607            },
141608            "quantitativeAnalysis": {
141609              "graphics": {}
141610            },
141611            "considerations": {}
141612          }
141613        },
141614        {
141615          "type": "library",
141616          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20210330210617-4fbd30eecc44?package-id=ce5e5f7a85470ecd",
141617          "supplier": {},
141618          "name": "golang.org/x/sys",
141619          "version": "v0.0.0-20210330210617-4fbd30eecc44",
141620          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20210330210617-4fbd30eecc44:*:*:*:*:*:*:*",
141621          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20210330210617-4fbd30eecc44",
141622          "swid": {
141623            "attachment": {}
141624          },
141625          "pedigree": {},
141626          "evidence": {},
141627          "signature": {
141628            "signature": {
141629              "publicKey": {}
141630            }
141631          },
141632          "modelCard": {
141633            "modelParameters": {
141634              "approach": {}
141635            },
141636            "quantitativeAnalysis": {
141637              "graphics": {}
141638            },
141639            "considerations": {}
141640          }
141641        },
141642        {
141643          "type": "library",
141644          "bom-ref": "pkg:golang/golang.org/x/term@v0.0.0-20210317153231-de623e64d2a6?package-id=e4c400b96c792f4b",
141645          "supplier": {},
141646          "name": "golang.org/x/term",
141647          "version": "v0.0.0-20210317153231-de623e64d2a6",
141648          "cpe": "cpe:2.3:a:golang:x\\/term:v0.0.0-20210317153231-de623e64d2a6:*:*:*:*:*:*:*",
141649          "purl": "pkg:golang/golang.org/x/term@v0.0.0-20210317153231-de623e64d2a6",
141650          "swid": {
141651            "attachment": {}
141652          },
141653          "pedigree": {},
141654          "evidence": {},
141655          "signature": {
141656            "signature": {
141657              "publicKey": {}
141658            }
141659          },
141660          "modelCard": {
141661            "modelParameters": {
141662              "approach": {}
141663            },
141664            "quantitativeAnalysis": {
141665              "graphics": {}
141666            },
141667            "considerations": {}
141668          }
141669        },
141670        {
141671          "type": "library",
141672          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.6?package-id=645547806213a3b0",
141673          "supplier": {},
141674          "name": "golang.org/x/text",
141675          "version": "v0.3.6",
141676          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.6:*:*:*:*:*:*:*",
141677          "purl": "pkg:golang/golang.org/x/text@v0.3.6",
141678          "swid": {
141679            "attachment": {}
141680          },
141681          "pedigree": {},
141682          "evidence": {},
141683          "signature": {
141684            "signature": {
141685              "publicKey": {}
141686            }
141687          },
141688          "modelCard": {
141689            "modelParameters": {
141690              "approach": {}
141691            },
141692            "quantitativeAnalysis": {
141693              "graphics": {}
141694            },
141695            "considerations": {}
141696          }
141697        },
141698        {
141699          "type": "library",
141700          "bom-ref": "pkg:golang/golang.org/x/time@v0.0.0-20210220033141-f8bda1e9f3ba?package-id=573f5a02a903fdcc",
141701          "supplier": {},
141702          "name": "golang.org/x/time",
141703          "version": "v0.0.0-20210220033141-f8bda1e9f3ba",
141704          "cpe": "cpe:2.3:a:golang:x\\/time:v0.0.0-20210220033141-f8bda1e9f3ba:*:*:*:*:*:*:*",
141705          "purl": "pkg:golang/golang.org/x/time@v0.0.0-20210220033141-f8bda1e9f3ba",
141706          "swid": {
141707            "attachment": {}
141708          },
141709          "pedigree": {},
141710          "evidence": {},
141711          "signature": {
141712            "signature": {
141713              "publicKey": {}
141714            }
141715          },
141716          "modelCard": {
141717            "modelParameters": {
141718              "approach": {}
141719            },
141720            "quantitativeAnalysis": {
141721              "graphics": {}
141722            },
141723            "considerations": {}
141724          }
141725        },
141726        {
141727          "type": "library",
141728          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20210317182105-75c7a8546eb9?package-id=b510145cb00447d4",
141729          "supplier": {},
141730          "name": "google.golang.org/genproto",
141731          "version": "v0.0.0-20210317182105-75c7a8546eb9",
141732          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20210317182105-75c7a8546eb9:*:*:*:*:*:*:*",
141733          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20210317182105-75c7a8546eb9",
141734          "swid": {
141735            "attachment": {}
141736          },
141737          "pedigree": {},
141738          "evidence": {},
141739          "signature": {
141740            "signature": {
141741              "publicKey": {}
141742            }
141743          },
141744          "modelCard": {
141745            "modelParameters": {
141746              "approach": {}
141747            },
141748            "quantitativeAnalysis": {
141749              "graphics": {}
141750            },
141751            "considerations": {}
141752          }
141753        },
141754        {
141755          "type": "library",
141756          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.36.0?package-id=e21223220bd05443",
141757          "supplier": {},
141758          "name": "google.golang.org/grpc",
141759          "version": "v1.36.0",
141760          "cpe": "cpe:2.3:a:google:grpc:v1.36.0:*:*:*:*:*:*:*",
141761          "purl": "pkg:golang/google.golang.org/grpc@v1.36.0",
141762          "swid": {
141763            "attachment": {}
141764          },
141765          "pedigree": {},
141766          "evidence": {},
141767          "signature": {
141768            "signature": {
141769              "publicKey": {}
141770            }
141771          },
141772          "modelCard": {
141773            "modelParameters": {
141774              "approach": {}
141775            },
141776            "quantitativeAnalysis": {
141777              "graphics": {}
141778            },
141779            "considerations": {}
141780          }
141781        },
141782        {
141783          "type": "library",
141784          "bom-ref": "pkg:golang/google.golang.org/protobuf@v1.26.0?package-id=9600efcd83b31efb",
141785          "supplier": {},
141786          "name": "google.golang.org/protobuf",
141787          "version": "v1.26.0",
141788          "cpe": "cpe:2.3:a:google:protobuf:v1.26.0:*:*:*:*:*:*:*",
141789          "purl": "pkg:golang/google.golang.org/protobuf@v1.26.0",
141790          "swid": {
141791            "attachment": {}
141792          },
141793          "pedigree": {},
141794          "evidence": {},
141795          "signature": {
141796            "signature": {
141797              "publicKey": {}
141798            }
141799          },
141800          "modelCard": {
141801            "modelParameters": {
141802              "approach": {}
141803            },
141804            "quantitativeAnalysis": {
141805              "graphics": {}
141806            },
141807            "considerations": {}
141808          }
141809        },
141810        {
141811          "type": "library",
141812          "bom-ref": "pkg:golang/gopkg.in/inf.v0@v0.9.1?package-id=cc381cd853993d48",
141813          "supplier": {},
141814          "name": "gopkg.in/inf.v0",
141815          "version": "v0.9.1",
141816          "purl": "pkg:golang/gopkg.in/inf.v0@v0.9.1",
141817          "swid": {
141818            "attachment": {}
141819          },
141820          "pedigree": {},
141821          "evidence": {},
141822          "signature": {
141823            "signature": {
141824              "publicKey": {}
141825            }
141826          },
141827          "modelCard": {
141828            "modelParameters": {
141829              "approach": {}
141830            },
141831            "quantitativeAnalysis": {
141832              "graphics": {}
141833            },
141834            "considerations": {}
141835          }
141836        },
141837        {
141838          "type": "library",
141839          "bom-ref": "pkg:golang/gopkg.in/yaml.v2@v2.4.0?package-id=34b11fe7b078766a",
141840          "supplier": {},
141841          "name": "gopkg.in/yaml.v2",
141842          "version": "v2.4.0",
141843          "purl": "pkg:golang/gopkg.in/yaml.v2@v2.4.0",
141844          "swid": {
141845            "attachment": {}
141846          },
141847          "pedigree": {},
141848          "evidence": {},
141849          "signature": {
141850            "signature": {
141851              "publicKey": {}
141852            }
141853          },
141854          "modelCard": {
141855            "modelParameters": {
141856              "approach": {}
141857            },
141858            "quantitativeAnalysis": {
141859              "graphics": {}
141860            },
141861            "considerations": {}
141862          }
141863        },
141864        {
141865          "type": "library",
141866          "bom-ref": "pkg:golang/gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b?package-id=372de8538add7377",
141867          "supplier": {},
141868          "name": "gopkg.in/yaml.v3",
141869          "version": "v3.0.0-20210107192922-496545a6307b",
141870          "purl": "pkg:golang/gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b",
141871          "swid": {
141872            "attachment": {}
141873          },
141874          "pedigree": {},
141875          "evidence": {},
141876          "signature": {
141877            "signature": {
141878              "publicKey": {}
141879            }
141880          },
141881          "modelCard": {
141882            "modelParameters": {
141883              "approach": {}
141884            },
141885            "quantitativeAnalysis": {
141886              "graphics": {}
141887            },
141888            "considerations": {}
141889          }
141890        },
141891        {
141892          "type": "library",
141893          "bom-ref": "pkg:golang/k8s.io/api@v0.21.0?package-id=6eeceb6836126161",
141894          "supplier": {},
141895          "name": "k8s.io/api",
141896          "version": "v0.21.0",
141897          "purl": "pkg:golang/k8s.io/api@v0.21.0",
141898          "swid": {
141899            "attachment": {}
141900          },
141901          "pedigree": {},
141902          "evidence": {},
141903          "signature": {
141904            "signature": {
141905              "publicKey": {}
141906            }
141907          },
141908          "modelCard": {
141909            "modelParameters": {
141910              "approach": {}
141911            },
141912            "quantitativeAnalysis": {
141913              "graphics": {}
141914            },
141915            "considerations": {}
141916          }
141917        },
141918        {
141919          "type": "library",
141920          "bom-ref": "pkg:golang/k8s.io/apimachinery@v0.21.0?package-id=ee2d2302e4078e15",
141921          "supplier": {},
141922          "name": "k8s.io/apimachinery",
141923          "version": "v0.21.0",
141924          "purl": "pkg:golang/k8s.io/apimachinery@v0.21.0",
141925          "swid": {
141926            "attachment": {}
141927          },
141928          "pedigree": {},
141929          "evidence": {},
141930          "signature": {
141931            "signature": {
141932              "publicKey": {}
141933            }
141934          },
141935          "modelCard": {
141936            "modelParameters": {
141937              "approach": {}
141938            },
141939            "quantitativeAnalysis": {
141940              "graphics": {}
141941            },
141942            "considerations": {}
141943          }
141944        },
141945        {
141946          "type": "library",
141947          "bom-ref": "pkg:golang/k8s.io/client-go@v0.21.0?package-id=3eb5845f9ab3b2ef",
141948          "supplier": {},
141949          "name": "k8s.io/client-go",
141950          "version": "v0.21.0",
141951          "purl": "pkg:golang/k8s.io/client-go@v0.21.0",
141952          "swid": {
141953            "attachment": {}
141954          },
141955          "pedigree": {},
141956          "evidence": {},
141957          "signature": {
141958            "signature": {
141959              "publicKey": {}
141960            }
141961          },
141962          "modelCard": {
141963            "modelParameters": {
141964              "approach": {}
141965            },
141966            "quantitativeAnalysis": {
141967              "graphics": {}
141968            },
141969            "considerations": {}
141970          }
141971        },
141972        {
141973          "type": "library",
141974          "bom-ref": "pkg:golang/k8s.io/component-base@v0.21.0?package-id=52e5855b80da64d0",
141975          "supplier": {},
141976          "name": "k8s.io/component-base",
141977          "version": "v0.21.0",
141978          "purl": "pkg:golang/k8s.io/component-base@v0.21.0",
141979          "swid": {
141980            "attachment": {}
141981          },
141982          "pedigree": {},
141983          "evidence": {},
141984          "signature": {
141985            "signature": {
141986              "publicKey": {}
141987            }
141988          },
141989          "modelCard": {
141990            "modelParameters": {
141991              "approach": {}
141992            },
141993            "quantitativeAnalysis": {
141994              "graphics": {}
141995            },
141996            "considerations": {}
141997          }
141998        },
141999        {
142000          "type": "library",
142001          "bom-ref": "pkg:golang/k8s.io/csi-translation-lib@v0.21.0?package-id=426e4661e3be93d9",
142002          "supplier": {},
142003          "name": "k8s.io/csi-translation-lib",
142004          "version": "v0.21.0",
142005          "purl": "pkg:golang/k8s.io/csi-translation-lib@v0.21.0",
142006          "swid": {
142007            "attachment": {}
142008          },
142009          "pedigree": {},
142010          "evidence": {},
142011          "signature": {
142012            "signature": {
142013              "publicKey": {}
142014            }
142015          },
142016          "modelCard": {
142017            "modelParameters": {
142018              "approach": {}
142019            },
142020            "quantitativeAnalysis": {
142021              "graphics": {}
142022            },
142023            "considerations": {}
142024          }
142025        },
142026        {
142027          "type": "library",
142028          "bom-ref": "pkg:golang/k8s.io/klog/v2@v2.8.0?package-id=7d3d7215ce8142ba",
142029          "supplier": {},
142030          "name": "k8s.io/klog/v2",
142031          "version": "v2.8.0",
142032          "cpe": "cpe:2.3:a:klog:v2:v2.8.0:*:*:*:*:*:*:*",
142033          "purl": "pkg:golang/k8s.io/klog/v2@v2.8.0",
142034          "swid": {
142035            "attachment": {}
142036          },
142037          "pedigree": {},
142038          "evidence": {},
142039          "signature": {
142040            "signature": {
142041              "publicKey": {}
142042            }
142043          },
142044          "modelCard": {
142045            "modelParameters": {
142046              "approach": {}
142047            },
142048            "quantitativeAnalysis": {
142049              "graphics": {}
142050            },
142051            "considerations": {}
142052          }
142053        },
142054        {
142055          "type": "library",
142056          "bom-ref": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20210305164622-f622666832c1?package-id=f60858d6c30d2a5d",
142057          "supplier": {},
142058          "name": "k8s.io/kube-openapi",
142059          "version": "v0.0.0-20210305164622-f622666832c1",
142060          "purl": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20210305164622-f622666832c1",
142061          "swid": {
142062            "attachment": {}
142063          },
142064          "pedigree": {},
142065          "evidence": {},
142066          "signature": {
142067            "signature": {
142068              "publicKey": {}
142069            }
142070          },
142071          "modelCard": {
142072            "modelParameters": {
142073              "approach": {}
142074            },
142075            "quantitativeAnalysis": {
142076              "graphics": {}
142077            },
142078            "considerations": {}
142079          }
142080        },
142081        {
142082          "type": "library",
142083          "bom-ref": "pkg:golang/k8s.io/utils@v0.0.0-20210305010621-2afb4311ab10?package-id=8da12d2b98587a53",
142084          "supplier": {},
142085          "name": "k8s.io/utils",
142086          "version": "v0.0.0-20210305010621-2afb4311ab10",
142087          "purl": "pkg:golang/k8s.io/utils@v0.0.0-20210305010621-2afb4311ab10",
142088          "swid": {
142089            "attachment": {}
142090          },
142091          "pedigree": {},
142092          "evidence": {},
142093          "signature": {
142094            "signature": {
142095              "publicKey": {}
142096            }
142097          },
142098          "modelCard": {
142099            "modelParameters": {
142100              "approach": {}
142101            },
142102            "quantitativeAnalysis": {
142103              "graphics": {}
142104            },
142105            "considerations": {}
142106          }
142107        },
142108        {
142109          "type": "library",
142110          "bom-ref": "pkg:deb/debian/netbase@5.6?arch=all\u0026distro=debian-10\u0026package-id=b55e51dca4eba9a6",
142111          "supplier": {},
142112          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
142113          "name": "netbase",
142114          "version": "5.6",
142115          "licenses": [
142116            {
142117              "license": {
142118                "id": "GPL-2.0-only"
142119              }
142120            }
142121          ],
142122          "cpe": "cpe:2.3:a:netbase:netbase:5.6:*:*:*:*:*:*:*",
142123          "purl": "pkg:deb/debian/netbase@5.6?arch=all\u0026distro=debian-10",
142124          "swid": {
142125            "attachment": {}
142126          },
142127          "pedigree": {},
142128          "evidence": {},
142129          "signature": {
142130            "signature": {
142131              "publicKey": {}
142132            }
142133          },
142134          "modelCard": {
142135            "modelParameters": {
142136              "approach": {}
142137            },
142138            "quantitativeAnalysis": {
142139              "graphics": {}
142140            },
142141            "considerations": {}
142142          }
142143        },
142144        {
142145          "type": "library",
142146          "bom-ref": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.1.1?package-id=19aec1903e488487",
142147          "supplier": {},
142148          "name": "sigs.k8s.io/structured-merge-diff/v4",
142149          "version": "v4.1.1",
142150          "cpe": "cpe:2.3:a:structured-merge-diff:v4:v4.1.1:*:*:*:*:*:*:*",
142151          "purl": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.1.1",
142152          "swid": {
142153            "attachment": {}
142154          },
142155          "pedigree": {},
142156          "evidence": {},
142157          "signature": {
142158            "signature": {
142159              "publicKey": {}
142160            }
142161          },
142162          "modelCard": {
142163            "modelParameters": {
142164              "approach": {}
142165            },
142166            "quantitativeAnalysis": {
142167              "graphics": {}
142168            },
142169            "considerations": {}
142170          }
142171        },
142172        {
142173          "type": "library",
142174          "bom-ref": "pkg:golang/sigs.k8s.io/yaml@v1.2.0?package-id=e364b7d517979806",
142175          "supplier": {},
142176          "name": "sigs.k8s.io/yaml",
142177          "version": "v1.2.0",
142178          "purl": "pkg:golang/sigs.k8s.io/yaml@v1.2.0",
142179          "swid": {
142180            "attachment": {}
142181          },
142182          "pedigree": {},
142183          "evidence": {},
142184          "signature": {
142185            "signature": {
142186              "publicKey": {}
142187            }
142188          },
142189          "modelCard": {
142190            "modelParameters": {
142191              "approach": {}
142192            },
142193            "quantitativeAnalysis": {
142194              "graphics": {}
142195            },
142196            "considerations": {}
142197          }
142198        },
142199        {
142200          "type": "library",
142201          "bom-ref": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10\u0026package-id=9e5b2198bbbd7fb0",
142202          "supplier": {},
142203          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
142204          "name": "tzdata",
142205          "version": "2021a-0+deb10u1",
142206          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0\\+deb10u1:*:*:*:*:*:*:*",
142207          "purl": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10",
142208          "swid": {
142209            "attachment": {}
142210          },
142211          "pedigree": {},
142212          "evidence": {},
142213          "signature": {
142214            "signature": {
142215              "publicKey": {}
142216            }
142217          },
142218          "modelCard": {
142219            "modelParameters": {
142220              "approach": {}
142221            },
142222            "quantitativeAnalysis": {
142223              "graphics": {}
142224            },
142225            "considerations": {}
142226          }
142227        },
142228        {
142229          "type": "operating-system",
142230          "supplier": {},
142231          "name": "debian",
142232          "version": "10",
142233          "description": "Distroless",
142234          "swid": {
142235            "tagId": "debian",
142236            "name": "debian",
142237            "version": "10",
142238            "attachment": {}
142239          },
142240          "pedigree": {},
142241          "externalReferences": [
142242            {
142243              "url": "https://github.com/GoogleContainerTools/distroless/issues/new",
142244              "type": "issue-tracker"
142245            },
142246            {
142247              "url": "https://github.com/GoogleContainerTools/distroless",
142248              "type": "website"
142249            },
142250            {
142251              "url": "https://github.com/GoogleContainerTools/distroless/blob/master/README.md",
142252              "comment": "support",
142253              "type": "other"
142254            }
142255          ],
142256          "evidence": {},
142257          "signature": {
142258            "signature": {
142259              "publicKey": {}
142260            }
142261          },
142262          "modelCard": {
142263            "modelParameters": {
142264              "approach": {}
142265            },
142266            "quantitativeAnalysis": {
142267              "graphics": {}
142268            },
142269            "considerations": {}
142270          }
142271        },
142272        {
142273          "type": "library",
142274          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r22?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=f6648e0bfefbfa72",
142275          "supplier": {},
142276          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142277          "name": "alpine-baselayout",
142278          "version": "3.2.0-r22",
142279          "description": "Alpine base dir structure and init scripts",
142280          "licenses": [
142281            {
142282              "license": {
142283                "id": "GPL-2.0-only"
142284              }
142285            }
142286          ],
142287          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r22:*:*:*:*:*:*:*",
142288          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r22?arch=x86_64\u0026distro=alpine-3.16.2",
142289          "swid": {
142290            "attachment": {}
142291          },
142292          "pedigree": {},
142293          "externalReferences": [
142294            {
142295              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
142296              "type": "distribution"
142297            }
142298          ],
142299          "evidence": {},
142300          "signature": {
142301            "signature": {
142302              "publicKey": {}
142303            }
142304          },
142305          "modelCard": {
142306            "modelParameters": {
142307              "approach": {}
142308            },
142309            "quantitativeAnalysis": {
142310              "graphics": {}
142311            },
142312            "considerations": {}
142313          }
142314        },
142315        {
142316          "type": "library",
142317          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r22?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.2\u0026package-id=f61a63f68bd86d61",
142318          "supplier": {},
142319          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142320          "name": "alpine-baselayout-data",
142321          "version": "3.2.0-r22",
142322          "description": "Alpine base dir structure and init scripts",
142323          "licenses": [
142324            {
142325              "license": {
142326                "id": "GPL-2.0-only"
142327              }
142328            }
142329          ],
142330          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.2.0-r22:*:*:*:*:*:*:*",
142331          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r22?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.2",
142332          "swid": {
142333            "attachment": {}
142334          },
142335          "pedigree": {},
142336          "externalReferences": [
142337            {
142338              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
142339              "type": "distribution"
142340            }
142341          ],
142342          "evidence": {},
142343          "signature": {
142344            "signature": {
142345              "publicKey": {}
142346            }
142347          },
142348          "modelCard": {
142349            "modelParameters": {
142350              "approach": {}
142351            },
142352            "quantitativeAnalysis": {
142353              "graphics": {}
142354            },
142355            "considerations": {}
142356          }
142357        },
142358        {
142359          "type": "library",
142360          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=82d183eb300978cc",
142361          "supplier": {},
142362          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142363          "name": "alpine-keys",
142364          "version": "2.4-r1",
142365          "description": "Public keys for Alpine Linux packages",
142366          "licenses": [
142367            {
142368              "license": {
142369                "id": "MIT"
142370              }
142371            }
142372          ],
142373          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
142374          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.2",
142375          "swid": {
142376            "attachment": {}
142377          },
142378          "pedigree": {},
142379          "externalReferences": [
142380            {
142381              "url": "https://alpinelinux.org",
142382              "type": "distribution"
142383            }
142384          ],
142385          "evidence": {},
142386          "signature": {
142387            "signature": {
142388              "publicKey": {}
142389            }
142390          },
142391          "modelCard": {
142392            "modelParameters": {
142393              "approach": {}
142394            },
142395            "quantitativeAnalysis": {
142396              "graphics": {}
142397            },
142398            "considerations": {}
142399          }
142400        },
142401        {
142402          "type": "library",
142403          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=42d502b764a37310",
142404          "supplier": {},
142405          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142406          "name": "apk-tools",
142407          "version": "2.12.9-r3",
142408          "description": "Alpine Package Keeper - package manager for alpine",
142409          "licenses": [
142410            {
142411              "license": {
142412                "id": "GPL-2.0-only"
142413              }
142414            }
142415          ],
142416          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.9-r3:*:*:*:*:*:*:*",
142417          "purl": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.2",
142418          "swid": {
142419            "attachment": {}
142420          },
142421          "pedigree": {},
142422          "externalReferences": [
142423            {
142424              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
142425              "type": "distribution"
142426            }
142427          ],
142428          "evidence": {},
142429          "signature": {
142430            "signature": {
142431              "publicKey": {}
142432            }
142433          },
142434          "modelCard": {
142435            "modelParameters": {
142436              "approach": {}
142437            },
142438            "quantitativeAnalysis": {
142439              "graphics": {}
142440            },
142441            "considerations": {}
142442          }
142443        },
142444        {
142445          "type": "library",
142446          "bom-ref": "pkg:apk/alpine/brotli-libs@1.0.9-r6?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.16.2\u0026package-id=ce770907e6d64ccd",
142447          "supplier": {},
142448          "publisher": "prspkt \u003cprspkt@protonmail.com\u003e",
142449          "name": "brotli-libs",
142450          "version": "1.0.9-r6",
142451          "description": "Generic lossless compressor (libraries)",
142452          "licenses": [
142453            {
142454              "license": {
142455                "id": "MIT"
142456              }
142457            }
142458          ],
142459          "cpe": "cpe:2.3:a:brotli-libs:brotli-libs:1.0.9-r6:*:*:*:*:*:*:*",
142460          "purl": "pkg:apk/alpine/brotli-libs@1.0.9-r6?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.16.2",
142461          "swid": {
142462            "attachment": {}
142463          },
142464          "pedigree": {},
142465          "externalReferences": [
142466            {
142467              "url": "https://github.com/google/brotli",
142468              "type": "distribution"
142469            }
142470          ],
142471          "evidence": {},
142472          "signature": {
142473            "signature": {
142474              "publicKey": {}
142475            }
142476          },
142477          "modelCard": {
142478            "modelParameters": {
142479              "approach": {}
142480            },
142481            "quantitativeAnalysis": {
142482              "graphics": {}
142483            },
142484            "considerations": {}
142485          }
142486        },
142487        {
142488          "type": "application",
142489          "bom-ref": "d80026167ff6b969",
142490          "supplier": {},
142491          "name": "busybox",
142492          "version": "1.35.0",
142493          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
142494          "swid": {
142495            "attachment": {}
142496          },
142497          "pedigree": {},
142498          "evidence": {},
142499          "signature": {
142500            "signature": {
142501              "publicKey": {}
142502            }
142503          },
142504          "modelCard": {
142505            "modelParameters": {
142506              "approach": {}
142507            },
142508            "quantitativeAnalysis": {
142509              "graphics": {}
142510            },
142511            "considerations": {}
142512          }
142513        },
142514        {
142515          "type": "library",
142516          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=4b48ef6f6b983526",
142517          "supplier": {},
142518          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
142519          "name": "busybox",
142520          "version": "1.35.0-r17",
142521          "description": "Size optimized toolbox of many common UNIX utilities",
142522          "licenses": [
142523            {
142524              "license": {
142525                "id": "GPL-2.0-only"
142526              }
142527            }
142528          ],
142529          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r17:*:*:*:*:*:*:*",
142530          "purl": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.2",
142531          "swid": {
142532            "attachment": {}
142533          },
142534          "pedigree": {},
142535          "externalReferences": [
142536            {
142537              "url": "https://busybox.net/",
142538              "type": "distribution"
142539            }
142540          ],
142541          "evidence": {},
142542          "signature": {
142543            "signature": {
142544              "publicKey": {}
142545            }
142546          },
142547          "modelCard": {
142548            "modelParameters": {
142549              "approach": {}
142550            },
142551            "quantitativeAnalysis": {
142552              "graphics": {}
142553            },
142554            "considerations": {}
142555          }
142556        },
142557        {
142558          "type": "library",
142559          "bom-ref": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=fbb1924ff870cc71",
142560          "supplier": {},
142561          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142562          "name": "ca-certificates",
142563          "version": "20220614-r0",
142564          "description": "Common CA certificates PEM files from Mozilla",
142565          "licenses": [
142566            {
142567              "license": {
142568                "id": "MPL-2.0"
142569              }
142570            },
142571            {
142572              "license": {
142573                "name": "AND"
142574              }
142575            },
142576            {
142577              "license": {
142578                "id": "MIT"
142579              }
142580            }
142581          ],
142582          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20220614-r0:*:*:*:*:*:*:*",
142583          "purl": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.2",
142584          "swid": {
142585            "attachment": {}
142586          },
142587          "pedigree": {},
142588          "externalReferences": [
142589            {
142590              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
142591              "type": "distribution"
142592            }
142593          ],
142594          "evidence": {},
142595          "signature": {
142596            "signature": {
142597              "publicKey": {}
142598            }
142599          },
142600          "modelCard": {
142601            "modelParameters": {
142602              "approach": {}
142603            },
142604            "quantitativeAnalysis": {
142605              "graphics": {}
142606            },
142607            "considerations": {}
142608          }
142609        },
142610        {
142611          "type": "library",
142612          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.2\u0026package-id=30622a1848b22bca",
142613          "supplier": {},
142614          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142615          "name": "ca-certificates-bundle",
142616          "version": "20220614-r0",
142617          "description": "Pre generated bundle of Mozilla certificates",
142618          "licenses": [
142619            {
142620              "license": {
142621                "id": "MPL-2.0"
142622              }
142623            },
142624            {
142625              "license": {
142626                "name": "AND"
142627              }
142628            },
142629            {
142630              "license": {
142631                "id": "MIT"
142632              }
142633            }
142634          ],
142635          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
142636          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.2",
142637          "swid": {
142638            "attachment": {}
142639          },
142640          "pedigree": {},
142641          "externalReferences": [
142642            {
142643              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
142644              "type": "distribution"
142645            }
142646          ],
142647          "evidence": {},
142648          "signature": {
142649            "signature": {
142650              "publicKey": {}
142651            }
142652          },
142653          "modelCard": {
142654            "modelParameters": {
142655              "approach": {}
142656            },
142657            "quantitativeAnalysis": {
142658              "graphics": {}
142659            },
142660            "considerations": {}
142661          }
142662        },
142663        {
142664          "type": "library",
142665          "bom-ref": "pkg:apk/alpine/curl@7.83.1-r3?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=80d2f6c52cf9efcc",
142666          "supplier": {},
142667          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142668          "name": "curl",
142669          "version": "7.83.1-r3",
142670          "description": "URL retrival utility and library",
142671          "licenses": [
142672            {
142673              "license": {
142674                "id": "curl"
142675              }
142676            }
142677          ],
142678          "cpe": "cpe:2.3:a:curl:curl:7.83.1-r3:*:*:*:*:*:*:*",
142679          "purl": "pkg:apk/alpine/curl@7.83.1-r3?arch=x86_64\u0026distro=alpine-3.16.2",
142680          "swid": {
142681            "attachment": {}
142682          },
142683          "pedigree": {},
142684          "externalReferences": [
142685            {
142686              "url": "https://curl.se/",
142687              "type": "distribution"
142688            }
142689          ],
142690          "evidence": {},
142691          "signature": {
142692            "signature": {
142693              "publicKey": {}
142694            }
142695          },
142696          "modelCard": {
142697            "modelParameters": {
142698              "approach": {}
142699            },
142700            "quantitativeAnalysis": {
142701              "graphics": {}
142702            },
142703            "considerations": {}
142704          }
142705        },
142706        {
142707          "type": "library",
142708          "bom-ref": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=bdcd538a4a36b9b8",
142709          "supplier": {},
142710          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
142711          "name": "freetype",
142712          "version": "2.12.1-r0",
142713          "description": "TrueType font rendering library",
142714          "licenses": [
142715            {
142716              "license": {
142717                "id": "FTL"
142718              }
142719            },
142720            {
142721              "license": {
142722                "id": "GPL-2.0-or-later"
142723              }
142724            }
142725          ],
142726          "cpe": "cpe:2.3:a:freetype:freetype:2.12.1-r0:*:*:*:*:*:*:*",
142727          "purl": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.16.2",
142728          "swid": {
142729            "attachment": {}
142730          },
142731          "pedigree": {},
142732          "externalReferences": [
142733            {
142734              "url": "https://www.freetype.org/",
142735              "type": "distribution"
142736            }
142737          ],
142738          "evidence": {},
142739          "signature": {
142740            "signature": {
142741              "publicKey": {}
142742            }
142743          },
142744          "modelCard": {
142745            "modelParameters": {
142746              "approach": {}
142747            },
142748            "quantitativeAnalysis": {
142749              "graphics": {}
142750            },
142751            "considerations": {}
142752          }
142753        },
142754        {
142755          "type": "library",
142756          "bom-ref": "pkg:apk/alpine/geoip@1.6.12-r2?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=41dd13b32a3e021e",
142757          "supplier": {},
142758          "publisher": "Leonardo Arena \u003crnalrd@alpinelinux.org\u003e",
142759          "name": "geoip",
142760          "version": "1.6.12-r2",
142761          "description": "Lookup countries by IP addresses",
142762          "licenses": [
142763            {
142764              "license": {
142765                "name": "GPL"
142766              }
142767            }
142768          ],
142769          "cpe": "cpe:2.3:a:geoip:geoip:1.6.12-r2:*:*:*:*:*:*:*",
142770          "purl": "pkg:apk/alpine/geoip@1.6.12-r2?arch=x86_64\u0026distro=alpine-3.16.2",
142771          "swid": {
142772            "attachment": {}
142773          },
142774          "pedigree": {},
142775          "externalReferences": [
142776            {
142777              "url": "http://www.maxmind.com/app/ip-location",
142778              "type": "distribution"
142779            }
142780          ],
142781          "evidence": {},
142782          "signature": {
142783            "signature": {
142784              "publicKey": {}
142785            }
142786          },
142787          "modelCard": {
142788            "modelParameters": {
142789              "approach": {}
142790            },
142791            "quantitativeAnalysis": {
142792              "graphics": {}
142793            },
142794            "considerations": {}
142795          }
142796        },
142797        {
142798          "type": "library",
142799          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.16.2\u0026package-id=b681aee18ae0aa50",
142800          "supplier": {},
142801          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142802          "name": "libbz2",
142803          "version": "1.0.8-r1",
142804          "description": "Shared library for bz2",
142805          "licenses": [
142806            {
142807              "license": {
142808                "id": "bzip2-1.0.6"
142809              }
142810            }
142811          ],
142812          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r1:*:*:*:*:*:*:*",
142813          "purl": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.16.2",
142814          "swid": {
142815            "attachment": {}
142816          },
142817          "pedigree": {},
142818          "externalReferences": [
142819            {
142820              "url": "http://sources.redhat.com/bzip2",
142821              "type": "distribution"
142822            }
142823          ],
142824          "evidence": {},
142825          "signature": {
142826            "signature": {
142827              "publicKey": {}
142828            }
142829          },
142830          "modelCard": {
142831            "modelParameters": {
142832              "approach": {}
142833            },
142834            "quantitativeAnalysis": {
142835              "graphics": {}
142836            },
142837            "considerations": {}
142838          }
142839        },
142840        {
142841          "type": "library",
142842          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.2\u0026package-id=2abd3b45f6fa4702",
142843          "supplier": {},
142844          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142845          "name": "libc-utils",
142846          "version": "0.7.2-r3",
142847          "description": "Meta package to pull in correct libc",
142848          "licenses": [
142849            {
142850              "license": {
142851                "id": "BSD-2-Clause"
142852              }
142853            },
142854            {
142855              "license": {
142856                "name": "AND"
142857              }
142858            },
142859            {
142860              "license": {
142861                "id": "BSD-3-Clause"
142862              }
142863            }
142864          ],
142865          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
142866          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.2",
142867          "swid": {
142868            "attachment": {}
142869          },
142870          "pedigree": {},
142871          "externalReferences": [
142872            {
142873              "url": "https://alpinelinux.org",
142874              "type": "distribution"
142875            }
142876          ],
142877          "evidence": {},
142878          "signature": {
142879            "signature": {
142880              "publicKey": {}
142881            }
142882          },
142883          "modelCard": {
142884            "modelParameters": {
142885              "approach": {}
142886            },
142887            "quantitativeAnalysis": {
142888              "graphics": {}
142889            },
142890            "considerations": {}
142891          }
142892        },
142893        {
142894          "type": "library",
142895          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1q-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.2\u0026package-id=eade7968dddaae93",
142896          "supplier": {},
142897          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
142898          "name": "libcrypto1.1",
142899          "version": "1.1.1q-r0",
142900          "description": "Crypto library from openssl",
142901          "licenses": [
142902            {
142903              "license": {
142904                "id": "OpenSSL"
142905              }
142906            }
142907          ],
142908          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1q-r0:*:*:*:*:*:*:*",
142909          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1q-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.2",
142910          "swid": {
142911            "attachment": {}
142912          },
142913          "pedigree": {},
142914          "externalReferences": [
142915            {
142916              "url": "https://www.openssl.org/",
142917              "type": "distribution"
142918            }
142919          ],
142920          "evidence": {},
142921          "signature": {
142922            "signature": {
142923              "publicKey": {}
142924            }
142925          },
142926          "modelCard": {
142927            "modelParameters": {
142928              "approach": {}
142929            },
142930            "quantitativeAnalysis": {
142931              "graphics": {}
142932            },
142933            "considerations": {}
142934          }
142935        },
142936        {
142937          "type": "library",
142938          "bom-ref": "pkg:apk/alpine/libcurl@7.83.1-r3?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.16.2\u0026package-id=7c6fae9adae2be46",
142939          "supplier": {},
142940          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
142941          "name": "libcurl",
142942          "version": "7.83.1-r3",
142943          "description": "The multiprotocol file transfer library",
142944          "licenses": [
142945            {
142946              "license": {
142947                "id": "curl"
142948              }
142949            }
142950          ],
142951          "cpe": "cpe:2.3:a:libcurl:libcurl:7.83.1-r3:*:*:*:*:*:*:*",
142952          "purl": "pkg:apk/alpine/libcurl@7.83.1-r3?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.16.2",
142953          "swid": {
142954            "attachment": {}
142955          },
142956          "pedigree": {},
142957          "externalReferences": [
142958            {
142959              "url": "https://curl.se/",
142960              "type": "distribution"
142961            }
142962          ],
142963          "evidence": {},
142964          "signature": {
142965            "signature": {
142966              "publicKey": {}
142967            }
142968          },
142969          "modelCard": {
142970            "modelParameters": {
142971              "approach": {}
142972            },
142973            "quantitativeAnalysis": {
142974              "graphics": {}
142975            },
142976            "considerations": {}
142977          }
142978        },
142979        {
142980          "type": "library",
142981          "bom-ref": "pkg:apk/alpine/libedit@20210910.3.1-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=306ebeb39081e8f5",
142982          "supplier": {},
142983          "publisher": "Drew DeVault \u003csir@cmpwn.com\u003e",
142984          "name": "libedit",
142985          "version": "20210910.3.1-r0",
142986          "description": "BSD line editing library",
142987          "licenses": [
142988            {
142989              "license": {
142990                "id": "BSD-3-Clause"
142991              }
142992            }
142993          ],
142994          "cpe": "cpe:2.3:a:libedit:libedit:20210910.3.1-r0:*:*:*:*:*:*:*",
142995          "purl": "pkg:apk/alpine/libedit@20210910.3.1-r0?arch=x86_64\u0026distro=alpine-3.16.2",
142996          "swid": {
142997            "attachment": {}
142998          },
142999          "pedigree": {},
143000          "externalReferences": [
143001            {
143002              "url": "https://www.thrysoee.dk/editline",
143003              "type": "distribution"
143004            }
143005          ],
143006          "evidence": {},
143007          "signature": {
143008            "signature": {
143009              "publicKey": {}
143010            }
143011          },
143012          "modelCard": {
143013            "modelParameters": {
143014              "approach": {}
143015            },
143016            "quantitativeAnalysis": {
143017              "graphics": {}
143018            },
143019            "considerations": {}
143020          }
143021        },
143022        {
143023          "type": "library",
143024          "bom-ref": "pkg:apk/alpine/libgcrypt@1.10.1-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=8d8621f41a52d13e",
143025          "supplier": {},
143026          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
143027          "name": "libgcrypt",
143028          "version": "1.10.1-r0",
143029          "description": "General purpose crypto library based on the code used in GnuPG",
143030          "licenses": [
143031            {
143032              "license": {
143033                "id": "LGPL-2.1-or-later"
143034              }
143035            }
143036          ],
143037          "cpe": "cpe:2.3:a:libgcrypt:libgcrypt:1.10.1-r0:*:*:*:*:*:*:*",
143038          "purl": "pkg:apk/alpine/libgcrypt@1.10.1-r0?arch=x86_64\u0026distro=alpine-3.16.2",
143039          "swid": {
143040            "attachment": {}
143041          },
143042          "pedigree": {},
143043          "externalReferences": [
143044            {
143045              "url": "https://www.gnupg.org/",
143046              "type": "distribution"
143047            }
143048          ],
143049          "evidence": {},
143050          "signature": {
143051            "signature": {
143052              "publicKey": {}
143053            }
143054          },
143055          "modelCard": {
143056            "modelParameters": {
143057              "approach": {}
143058            },
143059            "quantitativeAnalysis": {
143060              "graphics": {}
143061            },
143062            "considerations": {}
143063          }
143064        },
143065        {
143066          "type": "library",
143067          "bom-ref": "pkg:apk/alpine/libgd@2.3.3-r0?arch=x86_64\u0026upstream=gd\u0026distro=alpine-3.16.2\u0026package-id=daf831a88d77055d",
143068          "supplier": {},
143069          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
143070          "name": "libgd",
143071          "version": "2.3.3-r0",
143072          "description": "Library for the dynamic creation of images by programmers (libraries)",
143073          "licenses": [
143074            {
143075              "license": {
143076                "name": "custom"
143077              }
143078            }
143079          ],
143080          "cpe": "cpe:2.3:a:libgd:libgd:2.3.3-r0:*:*:*:*:*:*:*",
143081          "purl": "pkg:apk/alpine/libgd@2.3.3-r0?arch=x86_64\u0026upstream=gd\u0026distro=alpine-3.16.2",
143082          "swid": {
143083            "attachment": {}
143084          },
143085          "pedigree": {},
143086          "externalReferences": [
143087            {
143088              "url": "https://libgd.github.io/",
143089              "type": "distribution"
143090            }
143091          ],
143092          "evidence": {},
143093          "signature": {
143094            "signature": {
143095              "publicKey": {}
143096            }
143097          },
143098          "modelCard": {
143099            "modelParameters": {
143100              "approach": {}
143101            },
143102            "quantitativeAnalysis": {
143103              "graphics": {}
143104            },
143105            "considerations": {}
143106          }
143107        },
143108        {
143109          "type": "library",
143110          "bom-ref": "pkg:apk/alpine/libgpg-error@1.45-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=62e461ecf8077e13",
143111          "supplier": {},
143112          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
143113          "name": "libgpg-error",
143114          "version": "1.45-r0",
143115          "description": "Support library for libgcrypt",
143116          "licenses": [
143117            {
143118              "license": {
143119                "id": "GPL-2.0-or-later"
143120              }
143121            },
143122            {
143123              "license": {
143124                "id": "LGPL-2.1-or-later"
143125              }
143126            }
143127          ],
143128          "cpe": "cpe:2.3:a:libgpg-error:libgpg-error:1.45-r0:*:*:*:*:*:*:*",
143129          "purl": "pkg:apk/alpine/libgpg-error@1.45-r0?arch=x86_64\u0026distro=alpine-3.16.2",
143130          "swid": {
143131            "attachment": {}
143132          },
143133          "pedigree": {},
143134          "externalReferences": [
143135            {
143136              "url": "https://www.gnupg.org/",
143137              "type": "distribution"
143138            }
143139          ],
143140          "evidence": {},
143141          "signature": {
143142            "signature": {
143143              "publicKey": {}
143144            }
143145          },
143146          "modelCard": {
143147            "modelParameters": {
143148              "approach": {}
143149            },
143150            "quantitativeAnalysis": {
143151              "graphics": {}
143152            },
143153            "considerations": {}
143154          }
143155        },
143156        {
143157          "type": "library",
143158          "bom-ref": "pkg:apk/alpine/libintl@0.21-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.16.2\u0026package-id=8a4b8fffbba0af61",
143159          "supplier": {},
143160          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
143161          "name": "libintl",
143162          "version": "0.21-r2",
143163          "description": "GNU gettext runtime library",
143164          "licenses": [
143165            {
143166              "license": {
143167                "id": "LGPL-2.1-or-later"
143168              }
143169            }
143170          ],
143171          "cpe": "cpe:2.3:a:libintl:libintl:0.21-r2:*:*:*:*:*:*:*",
143172          "purl": "pkg:apk/alpine/libintl@0.21-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.16.2",
143173          "swid": {
143174            "attachment": {}
143175          },
143176          "pedigree": {},
143177          "externalReferences": [
143178            {
143179              "url": "https://www.gnu.org/software/gettext/gettext.html",
143180              "type": "distribution"
143181            }
143182          ],
143183          "evidence": {},
143184          "signature": {
143185            "signature": {
143186              "publicKey": {}
143187            }
143188          },
143189          "modelCard": {
143190            "modelParameters": {
143191              "approach": {}
143192            },
143193            "quantitativeAnalysis": {
143194              "graphics": {}
143195            },
143196            "considerations": {}
143197          }
143198        },
143199        {
143200          "type": "library",
143201          "bom-ref": "pkg:apk/alpine/libjpeg-turbo@2.1.3-r1?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=429c360bc26d4e41",
143202          "supplier": {},
143203          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
143204          "name": "libjpeg-turbo",
143205          "version": "2.1.3-r1",
143206          "description": "Accelerated baseline JPEG compression and decompression library",
143207          "licenses": [
143208            {
143209              "license": {
143210                "id": "BSD-3-Clause"
143211              }
143212            },
143213            {
143214              "license": {
143215                "id": "IJG"
143216              }
143217            },
143218            {
143219              "license": {
143220                "id": "Zlib"
143221              }
143222            }
143223          ],
143224          "cpe": "cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:2.1.3-r1:*:*:*:*:*:*:*",
143225          "purl": "pkg:apk/alpine/libjpeg-turbo@2.1.3-r1?arch=x86_64\u0026distro=alpine-3.16.2",
143226          "swid": {
143227            "attachment": {}
143228          },
143229          "pedigree": {},
143230          "externalReferences": [
143231            {
143232              "url": "https://libjpeg-turbo.org/",
143233              "type": "distribution"
143234            }
143235          ],
143236          "evidence": {},
143237          "signature": {
143238            "signature": {
143239              "publicKey": {}
143240            }
143241          },
143242          "modelCard": {
143243            "modelParameters": {
143244              "approach": {}
143245            },
143246            "quantitativeAnalysis": {
143247              "graphics": {}
143248            },
143249            "considerations": {}
143250          }
143251        },
143252        {
143253          "type": "library",
143254          "bom-ref": "pkg:apk/alpine/libpng@1.6.37-r1?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=2934e8314b6cdcc2",
143255          "supplier": {},
143256          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
143257          "name": "libpng",
143258          "version": "1.6.37-r1",
143259          "description": "Portable Network Graphics library",
143260          "licenses": [
143261            {
143262              "license": {
143263                "id": "Libpng"
143264              }
143265            }
143266          ],
143267          "cpe": "cpe:2.3:a:libpng:libpng:1.6.37-r1:*:*:*:*:*:*:*",
143268          "purl": "pkg:apk/alpine/libpng@1.6.37-r1?arch=x86_64\u0026distro=alpine-3.16.2",
143269          "swid": {
143270            "attachment": {}
143271          },
143272          "pedigree": {},
143273          "externalReferences": [
143274            {
143275              "url": "http://www.libpng.org",
143276              "type": "distribution"
143277            }
143278          ],
143279          "evidence": {},
143280          "signature": {
143281            "signature": {
143282              "publicKey": {}
143283            }
143284          },
143285          "modelCard": {
143286            "modelParameters": {
143287              "approach": {}
143288            },
143289            "quantitativeAnalysis": {
143290              "graphics": {}
143291            },
143292            "considerations": {}
143293          }
143294        },
143295        {
143296          "type": "library",
143297          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1q-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.2\u0026package-id=472a3672a587f543",
143298          "supplier": {},
143299          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
143300          "name": "libssl1.1",
143301          "version": "1.1.1q-r0",
143302          "description": "SSL shared libraries",
143303          "licenses": [
143304            {
143305              "license": {
143306                "id": "OpenSSL"
143307              }
143308            }
143309          ],
143310          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1q-r0:*:*:*:*:*:*:*",
143311          "purl": "pkg:apk/alpine/libssl1.1@1.1.1q-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.2",
143312          "swid": {
143313            "attachment": {}
143314          },
143315          "pedigree": {},
143316          "externalReferences": [
143317            {
143318              "url": "https://www.openssl.org/",
143319              "type": "distribution"
143320            }
143321          ],
143322          "evidence": {},
143323          "signature": {
143324            "signature": {
143325              "publicKey": {}
143326            }
143327          },
143328          "modelCard": {
143329            "modelParameters": {
143330              "approach": {}
143331            },
143332            "quantitativeAnalysis": {
143333              "graphics": {}
143334            },
143335            "considerations": {}
143336          }
143337        },
143338        {
143339          "type": "library",
143340          "bom-ref": "pkg:apk/alpine/libwebp@1.2.3-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=422b5f9230b7cf0e",
143341          "supplier": {},
143342          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
143343          "name": "libwebp",
143344          "version": "1.2.3-r0",
143345          "description": "Libraries for working with WebP images",
143346          "licenses": [
143347            {
143348              "license": {
143349                "id": "BSD-3-Clause"
143350              }
143351            }
143352          ],
143353          "cpe": "cpe:2.3:a:libwebp:libwebp:1.2.3-r0:*:*:*:*:*:*:*",
143354          "purl": "pkg:apk/alpine/libwebp@1.2.3-r0?arch=x86_64\u0026distro=alpine-3.16.2",
143355          "swid": {
143356            "attachment": {}
143357          },
143358          "pedigree": {},
143359          "externalReferences": [
143360            {
143361              "url": "https://developers.google.com/speed/webp",
143362              "type": "distribution"
143363            }
143364          ],
143365          "evidence": {},
143366          "signature": {
143367            "signature": {
143368              "publicKey": {}
143369            }
143370          },
143371          "modelCard": {
143372            "modelParameters": {
143373              "approach": {}
143374            },
143375            "quantitativeAnalysis": {
143376              "graphics": {}
143377            },
143378            "considerations": {}
143379          }
143380        },
143381        {
143382          "type": "library",
143383          "bom-ref": "pkg:apk/alpine/libxml2@2.9.14-r2?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=66abf048c3e1ee7a",
143384          "supplier": {},
143385          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
143386          "name": "libxml2",
143387          "version": "2.9.14-r2",
143388          "description": "XML parsing library, version 2",
143389          "licenses": [
143390            {
143391              "license": {
143392                "id": "MIT"
143393              }
143394            }
143395          ],
143396          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.14-r2:*:*:*:*:*:*:*",
143397          "purl": "pkg:apk/alpine/libxml2@2.9.14-r2?arch=x86_64\u0026distro=alpine-3.16.2",
143398          "swid": {
143399            "attachment": {}
143400          },
143401          "pedigree": {},
143402          "externalReferences": [
143403            {
143404              "url": "http://www.xmlsoft.org/",
143405              "type": "distribution"
143406            }
143407          ],
143408          "evidence": {},
143409          "signature": {
143410            "signature": {
143411              "publicKey": {}
143412            }
143413          },
143414          "modelCard": {
143415            "modelParameters": {
143416              "approach": {}
143417            },
143418            "quantitativeAnalysis": {
143419              "graphics": {}
143420            },
143421            "considerations": {}
143422          }
143423        },
143424        {
143425          "type": "library",
143426          "bom-ref": "pkg:apk/alpine/libxslt@1.1.35-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=7861179abda69224",
143427          "supplier": {},
143428          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
143429          "name": "libxslt",
143430          "version": "1.1.35-r0",
143431          "description": "XML stylesheet transformation library",
143432          "licenses": [
143433            {
143434              "license": {
143435                "name": "custom"
143436              }
143437            }
143438          ],
143439          "cpe": "cpe:2.3:a:libxslt:libxslt:1.1.35-r0:*:*:*:*:*:*:*",
143440          "purl": "pkg:apk/alpine/libxslt@1.1.35-r0?arch=x86_64\u0026distro=alpine-3.16.2",
143441          "swid": {
143442            "attachment": {}
143443          },
143444          "pedigree": {},
143445          "externalReferences": [
143446            {
143447              "url": "http://xmlsoft.org/XSLT/",
143448              "type": "distribution"
143449            }
143450          ],
143451          "evidence": {},
143452          "signature": {
143453            "signature": {
143454              "publicKey": {}
143455            }
143456          },
143457          "modelCard": {
143458            "modelParameters": {
143459              "approach": {}
143460            },
143461            "quantitativeAnalysis": {
143462              "graphics": {}
143463            },
143464            "considerations": {}
143465          }
143466        },
143467        {
143468          "type": "library",
143469          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=ce80c45bcc942859",
143470          "supplier": {},
143471          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
143472          "name": "musl",
143473          "version": "1.2.3-r0",
143474          "description": "the musl c library (libc) implementation",
143475          "licenses": [
143476            {
143477              "license": {
143478                "id": "MIT"
143479              }
143480            }
143481          ],
143482          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r0:*:*:*:*:*:*:*",
143483          "purl": "pkg:apk/alpine/musl@1.2.3-r0?arch=x86_64\u0026distro=alpine-3.16.2",
143484          "swid": {
143485            "attachment": {}
143486          },
143487          "pedigree": {},
143488          "externalReferences": [
143489            {
143490              "url": "https://musl.libc.org/",
143491              "type": "distribution"
143492            }
143493          ],
143494          "evidence": {},
143495          "signature": {
143496            "signature": {
143497              "publicKey": {}
143498            }
143499          },
143500          "modelCard": {
143501            "modelParameters": {
143502              "approach": {}
143503            },
143504            "quantitativeAnalysis": {
143505              "graphics": {}
143506            },
143507            "considerations": {}
143508          }
143509        },
143510        {
143511          "type": "library",
143512          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r0?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.2\u0026package-id=a4e585b09fc4d514",
143513          "supplier": {},
143514          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
143515          "name": "musl-utils",
143516          "version": "1.2.3-r0",
143517          "description": "the musl c library (libc) implementation",
143518          "licenses": [
143519            {
143520              "license": {
143521                "id": "MIT"
143522              }
143523            },
143524            {
143525              "license": {
143526                "name": "BSD"
143527              }
143528            },
143529            {
143530              "license": {
143531                "id": "GPL-2.0-or-later"
143532              }
143533            }
143534          ],
143535          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r0:*:*:*:*:*:*:*",
143536          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r0?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.2",
143537          "swid": {
143538            "attachment": {}
143539          },
143540          "pedigree": {},
143541          "externalReferences": [
143542            {
143543              "url": "https://musl.libc.org/",
143544              "type": "distribution"
143545            }
143546          ],
143547          "evidence": {},
143548          "signature": {
143549            "signature": {
143550              "publicKey": {}
143551            }
143552          },
143553          "modelCard": {
143554            "modelParameters": {
143555              "approach": {}
143556            },
143557            "quantitativeAnalysis": {
143558              "graphics": {}
143559            },
143560            "considerations": {}
143561          }
143562        },
143563        {
143564          "type": "library",
143565          "bom-ref": "pkg:apk/alpine/ncurses-libs@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.2\u0026package-id=c2bd1192d3d60d2c",
143566          "supplier": {},
143567          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
143568          "name": "ncurses-libs",
143569          "version": "6.3_p20220521-r0",
143570          "description": "Ncurses libraries",
143571          "licenses": [
143572            {
143573              "license": {
143574                "id": "MIT"
143575              }
143576            }
143577          ],
143578          "cpe": "cpe:2.3:a:ncurses-libs:ncurses-libs:6.3_p20220521-r0:*:*:*:*:*:*:*",
143579          "purl": "pkg:apk/alpine/ncurses-libs@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.2",
143580          "swid": {
143581            "attachment": {}
143582          },
143583          "pedigree": {},
143584          "externalReferences": [
143585            {
143586              "url": "https://invisible-island.net/ncurses/",
143587              "type": "distribution"
143588            }
143589          ],
143590          "evidence": {},
143591          "signature": {
143592            "signature": {
143593              "publicKey": {}
143594            }
143595          },
143596          "modelCard": {
143597            "modelParameters": {
143598              "approach": {}
143599            },
143600            "quantitativeAnalysis": {
143601              "graphics": {}
143602            },
143603            "considerations": {}
143604          }
143605        },
143606        {
143607          "type": "library",
143608          "bom-ref": "pkg:apk/alpine/ncurses-terminfo-base@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.2\u0026package-id=28679685d0eccfdc",
143609          "supplier": {},
143610          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
143611          "name": "ncurses-terminfo-base",
143612          "version": "6.3_p20220521-r0",
143613          "description": "Descriptions of common terminals",
143614          "licenses": [
143615            {
143616              "license": {
143617                "id": "MIT"
143618              }
143619            }
143620          ],
143621          "cpe": "cpe:2.3:a:ncurses-terminfo-base:ncurses-terminfo-base:6.3_p20220521-r0:*:*:*:*:*:*:*",
143622          "purl": "pkg:apk/alpine/ncurses-terminfo-base@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.2",
143623          "swid": {
143624            "attachment": {}
143625          },
143626          "pedigree": {},
143627          "externalReferences": [
143628            {
143629              "url": "https://invisible-island.net/ncurses/",
143630              "type": "distribution"
143631            }
143632          ],
143633          "evidence": {},
143634          "signature": {
143635            "signature": {
143636              "publicKey": {}
143637            }
143638          },
143639          "modelCard": {
143640            "modelParameters": {
143641              "approach": {}
143642            },
143643            "quantitativeAnalysis": {
143644              "graphics": {}
143645            },
143646            "considerations": {}
143647          }
143648        },
143649        {
143650          "type": "library",
143651          "bom-ref": "pkg:apk/alpine/nghttp2-libs@1.47.0-r0?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.16.2\u0026package-id=3f26eb4be5f62dce",
143652          "supplier": {},
143653          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
143654          "name": "nghttp2-libs",
143655          "version": "1.47.0-r0",
143656          "description": "Experimental HTTP/2 client, server and proxy (libraries)",
143657          "licenses": [
143658            {
143659              "license": {
143660                "id": "MIT"
143661              }
143662            }
143663          ],
143664          "cpe": "cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.47.0-r0:*:*:*:*:*:*:*",
143665          "purl": "pkg:apk/alpine/nghttp2-libs@1.47.0-r0?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.16.2",
143666          "swid": {
143667            "attachment": {}
143668          },
143669          "pedigree": {},
143670          "externalReferences": [
143671            {
143672              "url": "https://nghttp2.org",
143673              "type": "distribution"
143674            }
143675          ],
143676          "evidence": {},
143677          "signature": {
143678            "signature": {
143679              "publicKey": {}
143680            }
143681          },
143682          "modelCard": {
143683            "modelParameters": {
143684              "approach": {}
143685            },
143686            "quantitativeAnalysis": {
143687              "graphics": {}
143688            },
143689            "considerations": {}
143690          }
143691        },
143692        {
143693          "type": "library",
143694          "bom-ref": "pkg:apk/alpine/nginx@1.22.1-r1?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=cc5f00be0a99d8df",
143695          "supplier": {},
143696          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
143697          "name": "nginx",
143698          "version": "1.22.1-r1",
143699          "description": "High performance web server",
143700          "licenses": [
143701            {
143702              "license": {
143703                "name": "2-clause"
143704              }
143705            },
143706            {
143707              "license": {
143708                "name": "BSD-like"
143709              }
143710            },
143711            {
143712              "license": {
143713                "name": "license"
143714              }
143715            }
143716          ],
143717          "cpe": "cpe:2.3:a:nginx:nginx:1.22.1-r1:*:*:*:*:*:*:*",
143718          "purl": "pkg:apk/alpine/nginx@1.22.1-r1?arch=x86_64\u0026distro=alpine-3.16.2",
143719          "swid": {
143720            "attachment": {}
143721          },
143722          "pedigree": {},
143723          "externalReferences": [
143724            {
143725              "url": "https://nginx.org/",
143726              "type": "distribution"
143727            }
143728          ],
143729          "evidence": {},
143730          "signature": {
143731            "signature": {
143732              "publicKey": {}
143733            }
143734          },
143735          "modelCard": {
143736            "modelParameters": {
143737              "approach": {}
143738            },
143739            "quantitativeAnalysis": {
143740              "graphics": {}
143741            },
143742            "considerations": {}
143743          }
143744        },
143745        {
143746          "type": "library",
143747          "bom-ref": "pkg:apk/alpine/nginx-module-geoip@1.22.1-r1?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=886ff332093effd3",
143748          "supplier": {},
143749          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
143750          "name": "nginx-module-geoip",
143751          "version": "1.22.1-r1",
143752          "description": "nginx GeoIP dynamic modules",
143753          "licenses": [
143754            {
143755              "license": {
143756                "name": "2-clause"
143757              }
143758            },
143759            {
143760              "license": {
143761                "name": "BSD-like"
143762              }
143763            },
143764            {
143765              "license": {
143766                "name": "license"
143767              }
143768            }
143769          ],
143770          "cpe": "cpe:2.3:a:nginx-module-geoip:nginx-module-geoip:1.22.1-r1:*:*:*:*:*:*:*",
143771          "purl": "pkg:apk/alpine/nginx-module-geoip@1.22.1-r1?arch=x86_64\u0026distro=alpine-3.16.2",
143772          "swid": {
143773            "attachment": {}
143774          },
143775          "pedigree": {},
143776          "externalReferences": [
143777            {
143778              "url": "https://nginx.org/",
143779              "type": "distribution"
143780            }
143781          ],
143782          "evidence": {},
143783          "signature": {
143784            "signature": {
143785              "publicKey": {}
143786            }
143787          },
143788          "modelCard": {
143789            "modelParameters": {
143790              "approach": {}
143791            },
143792            "quantitativeAnalysis": {
143793              "graphics": {}
143794            },
143795            "considerations": {}
143796          }
143797        },
143798        {
143799          "type": "library",
143800          "bom-ref": "pkg:apk/alpine/nginx-module-image-filter@1.22.1-r1?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=e1d7de48606524ac",
143801          "supplier": {},
143802          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
143803          "name": "nginx-module-image-filter",
143804          "version": "1.22.1-r1",
143805          "description": "nginx image filter dynamic module",
143806          "licenses": [
143807            {
143808              "license": {
143809                "name": "2-clause"
143810              }
143811            },
143812            {
143813              "license": {
143814                "name": "BSD-like"
143815              }
143816            },
143817            {
143818              "license": {
143819                "name": "license"
143820              }
143821            }
143822          ],
143823          "cpe": "cpe:2.3:a:nginx-module-image-filter:nginx-module-image-filter:1.22.1-r1:*:*:*:*:*:*:*",
143824          "purl": "pkg:apk/alpine/nginx-module-image-filter@1.22.1-r1?arch=x86_64\u0026distro=alpine-3.16.2",
143825          "swid": {
143826            "attachment": {}
143827          },
143828          "pedigree": {},
143829          "externalReferences": [
143830            {
143831              "url": "https://nginx.org/",
143832              "type": "distribution"
143833            }
143834          ],
143835          "evidence": {},
143836          "signature": {
143837            "signature": {
143838              "publicKey": {}
143839            }
143840          },
143841          "modelCard": {
143842            "modelParameters": {
143843              "approach": {}
143844            },
143845            "quantitativeAnalysis": {
143846              "graphics": {}
143847            },
143848            "considerations": {}
143849          }
143850        },
143851        {
143852          "type": "library",
143853          "bom-ref": "pkg:apk/alpine/nginx-module-njs@1.22.1.0.7.7-r1?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=a24b9aba93d58482",
143854          "supplier": {},
143855          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
143856          "name": "nginx-module-njs",
143857          "version": "1.22.1.0.7.7-r1",
143858          "description": "nginx njs dynamic modules",
143859          "licenses": [
143860            {
143861              "license": {
143862                "name": "2-clause"
143863              }
143864            },
143865            {
143866              "license": {
143867                "name": "BSD-like"
143868              }
143869            },
143870            {
143871              "license": {
143872                "name": "license"
143873              }
143874            }
143875          ],
143876          "cpe": "cpe:2.3:a:nginx-module-njs:nginx-module-njs:1.22.1.0.7.7-r1:*:*:*:*:*:*:*",
143877          "purl": "pkg:apk/alpine/nginx-module-njs@1.22.1.0.7.7-r1?arch=x86_64\u0026distro=alpine-3.16.2",
143878          "swid": {
143879            "attachment": {}
143880          },
143881          "pedigree": {},
143882          "externalReferences": [
143883            {
143884              "url": "https://nginx.org/",
143885              "type": "distribution"
143886            }
143887          ],
143888          "evidence": {},
143889          "signature": {
143890            "signature": {
143891              "publicKey": {}
143892            }
143893          },
143894          "modelCard": {
143895            "modelParameters": {
143896              "approach": {}
143897            },
143898            "quantitativeAnalysis": {
143899              "graphics": {}
143900            },
143901            "considerations": {}
143902          }
143903        },
143904        {
143905          "type": "library",
143906          "bom-ref": "pkg:apk/alpine/nginx-module-xslt@1.22.1-r1?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=488cf350ed1d23eb",
143907          "supplier": {},
143908          "publisher": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e",
143909          "name": "nginx-module-xslt",
143910          "version": "1.22.1-r1",
143911          "description": "nginx xslt dynamic module",
143912          "licenses": [
143913            {
143914              "license": {
143915                "name": "2-clause"
143916              }
143917            },
143918            {
143919              "license": {
143920                "name": "BSD-like"
143921              }
143922            },
143923            {
143924              "license": {
143925                "name": "license"
143926              }
143927            }
143928          ],
143929          "cpe": "cpe:2.3:a:nginx-module-xslt:nginx-module-xslt:1.22.1-r1:*:*:*:*:*:*:*",
143930          "purl": "pkg:apk/alpine/nginx-module-xslt@1.22.1-r1?arch=x86_64\u0026distro=alpine-3.16.2",
143931          "swid": {
143932            "attachment": {}
143933          },
143934          "pedigree": {},
143935          "externalReferences": [
143936            {
143937              "url": "https://nginx.org/",
143938              "type": "distribution"
143939            }
143940          ],
143941          "evidence": {},
143942          "signature": {
143943            "signature": {
143944              "publicKey": {}
143945            }
143946          },
143947          "modelCard": {
143948            "modelParameters": {
143949              "approach": {}
143950            },
143951            "quantitativeAnalysis": {
143952              "graphics": {}
143953            },
143954            "considerations": {}
143955          }
143956        },
143957        {
143958          "type": "library",
143959          "bom-ref": "pkg:apk/alpine/openssl@1.1.1q-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=7e082b51fee5a0ed",
143960          "supplier": {},
143961          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
143962          "name": "openssl",
143963          "version": "1.1.1q-r0",
143964          "description": "toolkit for transport layer security (TLS) - version 1.1",
143965          "licenses": [
143966            {
143967              "license": {
143968                "id": "OpenSSL"
143969              }
143970            }
143971          ],
143972          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1q-r0:*:*:*:*:*:*:*",
143973          "purl": "pkg:apk/alpine/openssl@1.1.1q-r0?arch=x86_64\u0026distro=alpine-3.16.2",
143974          "swid": {
143975            "attachment": {}
143976          },
143977          "pedigree": {},
143978          "externalReferences": [
143979            {
143980              "url": "https://www.openssl.org/",
143981              "type": "distribution"
143982            }
143983          ],
143984          "evidence": {},
143985          "signature": {
143986            "signature": {
143987              "publicKey": {}
143988            }
143989          },
143990          "modelCard": {
143991            "modelParameters": {
143992              "approach": {}
143993            },
143994            "quantitativeAnalysis": {
143995              "graphics": {}
143996            },
143997            "considerations": {}
143998          }
143999        },
144000        {
144001          "type": "library",
144002          "bom-ref": "pkg:apk/alpine/pcre2@10.40-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=2256c35482ac26ef",
144003          "supplier": {},
144004          "publisher": "Jakub Jirutka \u003cjakub@jirutka.cz\u003e",
144005          "name": "pcre2",
144006          "version": "10.40-r0",
144007          "description": "Perl-compatible regular expression library",
144008          "licenses": [
144009            {
144010              "license": {
144011                "id": "BSD-3-Clause"
144012              }
144013            }
144014          ],
144015          "cpe": "cpe:2.3:a:pcre2:pcre2:10.40-r0:*:*:*:*:*:*:*",
144016          "purl": "pkg:apk/alpine/pcre2@10.40-r0?arch=x86_64\u0026distro=alpine-3.16.2",
144017          "swid": {
144018            "attachment": {}
144019          },
144020          "pedigree": {},
144021          "externalReferences": [
144022            {
144023              "url": "https://pcre.org/",
144024              "type": "distribution"
144025            }
144026          ],
144027          "evidence": {},
144028          "signature": {
144029            "signature": {
144030              "publicKey": {}
144031            }
144032          },
144033          "modelCard": {
144034            "modelParameters": {
144035              "approach": {}
144036            },
144037            "quantitativeAnalysis": {
144038              "graphics": {}
144039            },
144040            "considerations": {}
144041          }
144042        },
144043        {
144044          "type": "library",
144045          "bom-ref": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.2\u0026package-id=206fdb47b3e980eb",
144046          "supplier": {},
144047          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
144048          "name": "scanelf",
144049          "version": "1.3.4-r0",
144050          "description": "Scan ELF binaries for stuff",
144051          "licenses": [
144052            {
144053              "license": {
144054                "id": "GPL-2.0-only"
144055              }
144056            }
144057          ],
144058          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.4-r0:*:*:*:*:*:*:*",
144059          "purl": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.2",
144060          "swid": {
144061            "attachment": {}
144062          },
144063          "pedigree": {},
144064          "externalReferences": [
144065            {
144066              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
144067              "type": "distribution"
144068            }
144069          ],
144070          "evidence": {},
144071          "signature": {
144072            "signature": {
144073              "publicKey": {}
144074            }
144075          },
144076          "modelCard": {
144077            "modelParameters": {
144078              "approach": {}
144079            },
144080            "quantitativeAnalysis": {
144081              "graphics": {}
144082            },
144083            "considerations": {}
144084          }
144085        },
144086        {
144087          "type": "library",
144088          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.2\u0026package-id=674d1e2fba4d633a",
144089          "supplier": {},
144090          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
144091          "name": "ssl_client",
144092          "version": "1.35.0-r17",
144093          "description": "EXternal ssl_client for busybox wget",
144094          "licenses": [
144095            {
144096              "license": {
144097                "id": "GPL-2.0-only"
144098              }
144099            }
144100          ],
144101          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r17:*:*:*:*:*:*:*",
144102          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.2",
144103          "swid": {
144104            "attachment": {}
144105          },
144106          "pedigree": {},
144107          "externalReferences": [
144108            {
144109              "url": "https://busybox.net/",
144110              "type": "distribution"
144111            }
144112          ],
144113          "evidence": {},
144114          "signature": {
144115            "signature": {
144116              "publicKey": {}
144117            }
144118          },
144119          "modelCard": {
144120            "modelParameters": {
144121              "approach": {}
144122            },
144123            "quantitativeAnalysis": {
144124              "graphics": {}
144125            },
144126            "considerations": {}
144127          }
144128        },
144129        {
144130          "type": "library",
144131          "bom-ref": "pkg:apk/alpine/tzdata@2022c-r0?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=634fcfeb6c22bab6",
144132          "supplier": {},
144133          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
144134          "name": "tzdata",
144135          "version": "2022c-r0",
144136          "description": "Timezone data",
144137          "licenses": [
144138            {
144139              "license": {
144140                "name": "Public-Domain"
144141              }
144142            }
144143          ],
144144          "cpe": "cpe:2.3:a:tzdata:tzdata:2022c-r0:*:*:*:*:*:*:*",
144145          "purl": "pkg:apk/alpine/tzdata@2022c-r0?arch=x86_64\u0026distro=alpine-3.16.2",
144146          "swid": {
144147            "attachment": {}
144148          },
144149          "pedigree": {},
144150          "externalReferences": [
144151            {
144152              "url": "https://www.iana.org/time-zones",
144153              "type": "distribution"
144154            }
144155          ],
144156          "evidence": {},
144157          "signature": {
144158            "signature": {
144159              "publicKey": {}
144160            }
144161          },
144162          "modelCard": {
144163            "modelParameters": {
144164              "approach": {}
144165            },
144166            "quantitativeAnalysis": {
144167              "graphics": {}
144168            },
144169            "considerations": {}
144170          }
144171        },
144172        {
144173          "type": "library",
144174          "bom-ref": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.2\u0026package-id=168e14fa822d49a0",
144175          "supplier": {},
144176          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
144177          "name": "xz-libs",
144178          "version": "5.2.5-r1",
144179          "description": "Library and CLI tools for XZ and LZMA compressed files (libraries)",
144180          "licenses": [
144181            {
144182              "license": {
144183                "id": "GPL-2.0-or-later"
144184              }
144185            },
144186            {
144187              "license": {
144188                "name": "AND"
144189              }
144190            },
144191            {
144192              "license": {
144193                "name": "Public-Domain"
144194              }
144195            },
144196            {
144197              "license": {
144198                "name": "AND"
144199              }
144200            },
144201            {
144202              "license": {
144203                "id": "LGPL-2.1-or-later"
144204              }
144205            }
144206          ],
144207          "cpe": "cpe:2.3:a:xz-libs:xz-libs:5.2.5-r1:*:*:*:*:*:*:*",
144208          "purl": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.2",
144209          "swid": {
144210            "attachment": {}
144211          },
144212          "pedigree": {},
144213          "externalReferences": [
144214            {
144215              "url": "https://tukaani.org/xz",
144216              "type": "distribution"
144217            }
144218          ],
144219          "evidence": {},
144220          "signature": {
144221            "signature": {
144222              "publicKey": {}
144223            }
144224          },
144225          "modelCard": {
144226            "modelParameters": {
144227              "approach": {}
144228            },
144229            "quantitativeAnalysis": {
144230              "graphics": {}
144231            },
144232            "considerations": {}
144233          }
144234        },
144235        {
144236          "type": "library",
144237          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.2\u0026package-id=75f0d92f695b4303",
144238          "supplier": {},
144239          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
144240          "name": "zlib",
144241          "version": "1.2.12-r3",
144242          "description": "A compression/decompression Library",
144243          "licenses": [
144244            {
144245              "license": {
144246                "id": "Zlib"
144247              }
144248            }
144249          ],
144250          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
144251          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.2",
144252          "swid": {
144253            "attachment": {}
144254          },
144255          "pedigree": {},
144256          "externalReferences": [
144257            {
144258              "url": "https://zlib.net/",
144259              "type": "distribution"
144260            }
144261          ],
144262          "evidence": {},
144263          "signature": {
144264            "signature": {
144265              "publicKey": {}
144266            }
144267          },
144268          "modelCard": {
144269            "modelParameters": {
144270              "approach": {}
144271            },
144272            "quantitativeAnalysis": {
144273              "graphics": {}
144274            },
144275            "considerations": {}
144276          }
144277        },
144278        {
144279          "type": "operating-system",
144280          "supplier": {},
144281          "name": "alpine",
144282          "version": "3.16.2",
144283          "description": "Alpine Linux v3.16",
144284          "swid": {
144285            "tagId": "alpine",
144286            "name": "alpine",
144287            "version": "3.16.2",
144288            "attachment": {}
144289          },
144290          "pedigree": {},
144291          "externalReferences": [
144292            {
144293              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
144294              "type": "issue-tracker"
144295            },
144296            {
144297              "url": "https://alpinelinux.org/",
144298              "type": "website"
144299            }
144300          ],
144301          "evidence": {},
144302          "signature": {
144303            "signature": {
144304              "publicKey": {}
144305            }
144306          },
144307          "modelCard": {
144308            "modelParameters": {
144309              "approach": {}
144310            },
144311            "quantitativeAnalysis": {
144312              "graphics": {}
144313            },
144314            "considerations": {}
144315          }
144316        },
144317        {
144318          "type": "library",
144319          "bom-ref": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04\u0026package-id=69d1980477020fa3",
144320          "supplier": {},
144321          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144322          "name": "adduser",
144323          "version": "3.118ubuntu2",
144324          "licenses": [
144325            {
144326              "license": {
144327                "id": "GPL-2.0-only"
144328              }
144329            }
144330          ],
144331          "cpe": "cpe:2.3:a:adduser:adduser:3.118ubuntu2:*:*:*:*:*:*:*",
144332          "purl": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04",
144333          "swid": {
144334            "attachment": {}
144335          },
144336          "pedigree": {},
144337          "evidence": {},
144338          "signature": {
144339            "signature": {
144340              "publicKey": {}
144341            }
144342          },
144343          "modelCard": {
144344            "modelParameters": {
144345              "approach": {}
144346            },
144347            "quantitativeAnalysis": {
144348              "graphics": {}
144349            },
144350            "considerations": {}
144351          }
144352        },
144353        {
144354          "type": "library",
144355          "bom-ref": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=55988ea1c6f336e3",
144356          "supplier": {},
144357          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144358          "name": "apt",
144359          "version": "2.0.6",
144360          "licenses": [
144361            {
144362              "license": {
144363                "id": "GPL-2.0-only"
144364              }
144365            },
144366            {
144367              "license": {
144368                "name": "GPLv2+"
144369              }
144370            }
144371          ],
144372          "cpe": "cpe:2.3:a:apt:apt:2.0.6:*:*:*:*:*:*:*",
144373          "purl": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04",
144374          "swid": {
144375            "attachment": {}
144376          },
144377          "pedigree": {},
144378          "evidence": {},
144379          "signature": {
144380            "signature": {
144381              "publicKey": {}
144382            }
144383          },
144384          "modelCard": {
144385            "modelParameters": {
144386              "approach": {}
144387            },
144388            "quantitativeAnalysis": {
144389              "graphics": {}
144390            },
144391            "considerations": {}
144392          }
144393        },
144394        {
144395          "type": "library",
144396          "bom-ref": "pkg:deb/ubuntu/base-files@11ubuntu5.3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=1c2af4464cd392e1",
144397          "supplier": {},
144398          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144399          "name": "base-files",
144400          "version": "11ubuntu5.3",
144401          "licenses": [
144402            {
144403              "license": {
144404                "name": "GPL"
144405              }
144406            }
144407          ],
144408          "cpe": "cpe:2.3:a:base-files:base-files:11ubuntu5.3:*:*:*:*:*:*:*",
144409          "purl": "pkg:deb/ubuntu/base-files@11ubuntu5.3?arch=amd64\u0026distro=ubuntu-20.04",
144410          "swid": {
144411            "attachment": {}
144412          },
144413          "pedigree": {},
144414          "evidence": {},
144415          "signature": {
144416            "signature": {
144417              "publicKey": {}
144418            }
144419          },
144420          "modelCard": {
144421            "modelParameters": {
144422              "approach": {}
144423            },
144424            "quantitativeAnalysis": {
144425              "graphics": {}
144426            },
144427            "considerations": {}
144428          }
144429        },
144430        {
144431          "type": "library",
144432          "bom-ref": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=63c89c28c512e1db",
144433          "supplier": {},
144434          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144435          "name": "base-files",
144436          "version": "11ubuntu5.4",
144437          "licenses": [
144438            {
144439              "license": {
144440                "name": "GPL"
144441              }
144442            }
144443          ],
144444          "cpe": "cpe:2.3:a:base-files:base-files:11ubuntu5.4:*:*:*:*:*:*:*",
144445          "purl": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04",
144446          "swid": {
144447            "attachment": {}
144448          },
144449          "pedigree": {},
144450          "evidence": {},
144451          "signature": {
144452            "signature": {
144453              "publicKey": {}
144454            }
144455          },
144456          "modelCard": {
144457            "modelParameters": {
144458              "approach": {}
144459            },
144460            "quantitativeAnalysis": {
144461              "graphics": {}
144462            },
144463            "considerations": {}
144464          }
144465        },
144466        {
144467          "type": "library",
144468          "bom-ref": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=8b6e494dac6dab09",
144469          "supplier": {},
144470          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
144471          "name": "base-passwd",
144472          "version": "3.5.47",
144473          "licenses": [
144474            {
144475              "license": {
144476                "id": "GPL-2.0-only"
144477              }
144478            },
144479            {
144480              "license": {
144481                "name": "PD"
144482              }
144483            }
144484          ],
144485          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.47:*:*:*:*:*:*:*",
144486          "purl": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04",
144487          "swid": {
144488            "attachment": {}
144489          },
144490          "pedigree": {},
144491          "evidence": {},
144492          "signature": {
144493            "signature": {
144494              "publicKey": {}
144495            }
144496          },
144497          "modelCard": {
144498            "modelParameters": {
144499              "approach": {}
144500            },
144501            "quantitativeAnalysis": {
144502              "graphics": {}
144503            },
144504            "considerations": {}
144505          }
144506        },
144507        {
144508          "type": "library",
144509          "bom-ref": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e774a3e87113196b",
144510          "supplier": {},
144511          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144512          "name": "bash",
144513          "version": "5.0-6ubuntu1.1",
144514          "licenses": [
144515            {
144516              "license": {
144517                "id": "GPL-3.0-only"
144518              }
144519            }
144520          ],
144521          "cpe": "cpe:2.3:a:bash:bash:5.0-6ubuntu1.1:*:*:*:*:*:*:*",
144522          "purl": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04",
144523          "swid": {
144524            "attachment": {}
144525          },
144526          "pedigree": {},
144527          "evidence": {},
144528          "signature": {
144529            "signature": {
144530              "publicKey": {}
144531            }
144532          },
144533          "modelCard": {
144534            "modelParameters": {
144535              "approach": {}
144536            },
144537            "quantitativeAnalysis": {
144538              "graphics": {}
144539            },
144540            "considerations": {}
144541          }
144542        },
144543        {
144544          "type": "library",
144545          "bom-ref": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04\u0026package-id=20018d8de777eda9",
144546          "supplier": {},
144547          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144548          "name": "bsdutils",
144549          "version": "1:2.34-0.1ubuntu9.1",
144550          "licenses": [
144551            {
144552              "license": {
144553                "id": "BSD-2-Clause"
144554              }
144555            },
144556            {
144557              "license": {
144558                "id": "BSD-3-Clause"
144559              }
144560            },
144561            {
144562              "license": {
144563                "id": "BSD-4-Clause"
144564              }
144565            },
144566            {
144567              "license": {
144568                "id": "GPL-2.0-only"
144569              }
144570            },
144571            {
144572              "license": {
144573                "id": "GPL-2.0-or-later"
144574              }
144575            },
144576            {
144577              "license": {
144578                "id": "GPL-3.0-only"
144579              }
144580            },
144581            {
144582              "license": {
144583                "id": "GPL-3.0-or-later"
144584              }
144585            },
144586            {
144587              "license": {
144588                "name": "LGPL"
144589              }
144590            },
144591            {
144592              "license": {
144593                "id": "LGPL-2.0-only"
144594              }
144595            },
144596            {
144597              "license": {
144598                "id": "LGPL-2.0-or-later"
144599              }
144600            },
144601            {
144602              "license": {
144603                "id": "LGPL-2.1-only"
144604              }
144605            },
144606            {
144607              "license": {
144608                "id": "LGPL-2.1-or-later"
144609              }
144610            },
144611            {
144612              "license": {
144613                "id": "LGPL-3.0-only"
144614              }
144615            },
144616            {
144617              "license": {
144618                "id": "LGPL-3.0-or-later"
144619              }
144620            },
144621            {
144622              "license": {
144623                "id": "MIT"
144624              }
144625            },
144626            {
144627              "license": {
144628                "name": "public-domain"
144629              }
144630            }
144631          ],
144632          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
144633          "purl": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04",
144634          "swid": {
144635            "attachment": {}
144636          },
144637          "pedigree": {},
144638          "evidence": {},
144639          "signature": {
144640            "signature": {
144641              "publicKey": {}
144642            }
144643          },
144644          "modelCard": {
144645            "modelParameters": {
144646              "approach": {}
144647            },
144648            "quantitativeAnalysis": {
144649              "graphics": {}
144650            },
144651            "considerations": {}
144652          }
144653        },
144654        {
144655          "type": "library",
144656          "bom-ref": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=97dab883cac4c956",
144657          "supplier": {},
144658          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144659          "name": "bzip2",
144660          "version": "1.0.8-2",
144661          "licenses": [
144662            {
144663              "license": {
144664                "name": "BSD-variant"
144665              }
144666            },
144667            {
144668              "license": {
144669                "id": "GPL-2.0-only"
144670              }
144671            }
144672          ],
144673          "cpe": "cpe:2.3:a:bzip2:bzip2:1.0.8-2:*:*:*:*:*:*:*",
144674          "purl": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04",
144675          "swid": {
144676            "attachment": {}
144677          },
144678          "pedigree": {},
144679          "evidence": {},
144680          "signature": {
144681            "signature": {
144682              "publicKey": {}
144683            }
144684          },
144685          "modelCard": {
144686            "modelParameters": {
144687              "approach": {}
144688            },
144689            "quantitativeAnalysis": {
144690              "graphics": {}
144691            },
144692            "considerations": {}
144693          }
144694        },
144695        {
144696          "type": "library",
144697          "bom-ref": "pkg:deb/ubuntu/ca-certificates@20210119~20.04.1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=b34020e11d6f8983",
144698          "supplier": {},
144699          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144700          "name": "ca-certificates",
144701          "version": "20210119~20.04.1",
144702          "licenses": [
144703            {
144704              "license": {
144705                "id": "GPL-2.0-only"
144706              }
144707            },
144708            {
144709              "license": {
144710                "id": "GPL-2.0-or-later"
144711              }
144712            },
144713            {
144714              "license": {
144715                "id": "MPL-2.0"
144716              }
144717            }
144718          ],
144719          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20210119\\~20.04.1:*:*:*:*:*:*:*",
144720          "purl": "pkg:deb/ubuntu/ca-certificates@20210119~20.04.1?arch=all\u0026distro=ubuntu-20.04",
144721          "swid": {
144722            "attachment": {}
144723          },
144724          "pedigree": {},
144725          "evidence": {},
144726          "signature": {
144727            "signature": {
144728              "publicKey": {}
144729            }
144730          },
144731          "modelCard": {
144732            "modelParameters": {
144733              "approach": {}
144734            },
144735            "quantitativeAnalysis": {
144736              "graphics": {}
144737            },
144738            "considerations": {}
144739          }
144740        },
144741        {
144742          "type": "library",
144743          "bom-ref": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f77283ee51e117fa",
144744          "supplier": {},
144745          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144746          "name": "coreutils",
144747          "version": "8.30-3ubuntu2",
144748          "licenses": [
144749            {
144750              "license": {
144751                "id": "GPL-3.0-only"
144752              }
144753            }
144754          ],
144755          "cpe": "cpe:2.3:a:coreutils:coreutils:8.30-3ubuntu2:*:*:*:*:*:*:*",
144756          "purl": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
144757          "swid": {
144758            "attachment": {}
144759          },
144760          "pedigree": {},
144761          "evidence": {},
144762          "signature": {
144763            "signature": {
144764              "publicKey": {}
144765            }
144766          },
144767          "modelCard": {
144768            "modelParameters": {
144769              "approach": {}
144770            },
144771            "quantitativeAnalysis": {
144772              "graphics": {}
144773            },
144774            "considerations": {}
144775          }
144776        },
144777        {
144778          "type": "library",
144779          "bom-ref": "pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=123513dd4ae6c6b7",
144780          "supplier": {},
144781          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144782          "name": "curl",
144783          "version": "7.68.0-1ubuntu2.6",
144784          "licenses": [
144785            {
144786              "license": {
144787                "id": "BSD-3-Clause"
144788              }
144789            },
144790            {
144791              "license": {
144792                "id": "BSD-4-Clause"
144793              }
144794            },
144795            {
144796              "license": {
144797                "id": "ISC"
144798              }
144799            },
144800            {
144801              "license": {
144802                "id": "curl"
144803              }
144804            },
144805            {
144806              "license": {
144807                "name": "other"
144808              }
144809            },
144810            {
144811              "license": {
144812                "name": "public-domain"
144813              }
144814            }
144815          ],
144816          "cpe": "cpe:2.3:a:curl:curl:7.68.0-1ubuntu2.6:*:*:*:*:*:*:*",
144817          "purl": "pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.6?arch=amd64\u0026distro=ubuntu-20.04",
144818          "swid": {
144819            "attachment": {}
144820          },
144821          "pedigree": {},
144822          "evidence": {},
144823          "signature": {
144824            "signature": {
144825              "publicKey": {}
144826            }
144827          },
144828          "modelCard": {
144829            "modelParameters": {
144830              "approach": {}
144831            },
144832            "quantitativeAnalysis": {
144833              "graphics": {}
144834            },
144835            "considerations": {}
144836          }
144837        },
144838        {
144839          "type": "library",
144840          "bom-ref": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=fa0f613df8411b7",
144841          "supplier": {},
144842          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144843          "name": "dash",
144844          "version": "0.5.10.2-6",
144845          "licenses": [
144846            {
144847              "license": {
144848                "name": "GPL"
144849              }
144850            }
144851          ],
144852          "cpe": "cpe:2.3:a:dash:dash:0.5.10.2-6:*:*:*:*:*:*:*",
144853          "purl": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04",
144854          "swid": {
144855            "attachment": {}
144856          },
144857          "pedigree": {},
144858          "evidence": {},
144859          "signature": {
144860            "signature": {
144861              "publicKey": {}
144862            }
144863          },
144864          "modelCard": {
144865            "modelParameters": {
144866              "approach": {}
144867            },
144868            "quantitativeAnalysis": {
144869              "graphics": {}
144870            },
144871            "considerations": {}
144872          }
144873        },
144874        {
144875          "type": "library",
144876          "bom-ref": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04\u0026package-id=128eb6066f5ec19c",
144877          "supplier": {},
144878          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144879          "name": "debconf",
144880          "version": "1.5.73",
144881          "licenses": [
144882            {
144883              "license": {
144884                "id": "BSD-2-Clause"
144885              }
144886            }
144887          ],
144888          "cpe": "cpe:2.3:a:debconf:debconf:1.5.73:*:*:*:*:*:*:*",
144889          "purl": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04",
144890          "swid": {
144891            "attachment": {}
144892          },
144893          "pedigree": {},
144894          "evidence": {},
144895          "signature": {
144896            "signature": {
144897              "publicKey": {}
144898            }
144899          },
144900          "modelCard": {
144901            "modelParameters": {
144902              "approach": {}
144903            },
144904            "quantitativeAnalysis": {
144905              "graphics": {}
144906            },
144907            "considerations": {}
144908          }
144909        },
144910        {
144911          "type": "library",
144912          "bom-ref": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=328b1094024bda26",
144913          "supplier": {},
144914          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144915          "name": "debianutils",
144916          "version": "4.9.1",
144917          "licenses": [
144918            {
144919              "license": {
144920                "name": "GPL"
144921              }
144922            }
144923          ],
144924          "cpe": "cpe:2.3:a:debianutils:debianutils:4.9.1:*:*:*:*:*:*:*",
144925          "purl": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04",
144926          "swid": {
144927            "attachment": {}
144928          },
144929          "pedigree": {},
144930          "evidence": {},
144931          "signature": {
144932            "signature": {
144933              "publicKey": {}
144934            }
144935          },
144936          "modelCard": {
144937            "modelParameters": {
144938              "approach": {}
144939            },
144940            "quantitativeAnalysis": {
144941              "graphics": {}
144942            },
144943            "considerations": {}
144944          }
144945        },
144946        {
144947          "type": "library",
144948          "bom-ref": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=d21aefcaf9c9c9b6",
144949          "supplier": {},
144950          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144951          "name": "diffutils",
144952          "version": "1:3.7-3",
144953          "licenses": [
144954            {
144955              "license": {
144956                "name": "GFDL"
144957              }
144958            },
144959            {
144960              "license": {
144961                "name": "GPL"
144962              }
144963            }
144964          ],
144965          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-3:*:*:*:*:*:*:*",
144966          "purl": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04",
144967          "swid": {
144968            "attachment": {}
144969          },
144970          "pedigree": {},
144971          "evidence": {},
144972          "signature": {
144973            "signature": {
144974              "publicKey": {}
144975            }
144976          },
144977          "modelCard": {
144978            "modelParameters": {
144979              "approach": {}
144980            },
144981            "quantitativeAnalysis": {
144982              "graphics": {}
144983            },
144984            "considerations": {}
144985          }
144986        },
144987        {
144988          "type": "library",
144989          "bom-ref": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=c0d6316be2747294",
144990          "supplier": {},
144991          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
144992          "name": "dmsetup",
144993          "version": "2:1.02.167-1ubuntu1",
144994          "licenses": [
144995            {
144996              "license": {
144997                "id": "BSD-2-Clause"
144998              }
144999            },
145000            {
145001              "license": {
145002                "id": "GPL-2.0-only"
145003              }
145004            },
145005            {
145006              "license": {
145007                "id": "GPL-2.0-only"
145008              }
145009            },
145010            {
145011              "license": {
145012                "id": "GPL-2.0-or-later"
145013              }
145014            },
145015            {
145016              "license": {
145017                "id": "LGPL-2.0-only"
145018              }
145019            },
145020            {
145021              "license": {
145022                "id": "LGPL-2.1-only"
145023              }
145024            }
145025          ],
145026          "cpe": "cpe:2.3:a:dmsetup:dmsetup:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
145027          "purl": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
145028          "swid": {
145029            "attachment": {}
145030          },
145031          "pedigree": {},
145032          "evidence": {},
145033          "signature": {
145034            "signature": {
145035              "publicKey": {}
145036            }
145037          },
145038          "modelCard": {
145039            "modelParameters": {
145040              "approach": {}
145041            },
145042            "quantitativeAnalysis": {
145043              "graphics": {}
145044            },
145045            "considerations": {}
145046          }
145047        },
145048        {
145049          "type": "library",
145050          "bom-ref": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e28aea5c134a7f8",
145051          "supplier": {},
145052          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
145053          "name": "dpkg",
145054          "version": "1.19.7ubuntu3",
145055          "licenses": [
145056            {
145057              "license": {
145058                "id": "BSD-2-Clause"
145059              }
145060            },
145061            {
145062              "license": {
145063                "id": "GPL-2.0-only"
145064              }
145065            },
145066            {
145067              "license": {
145068                "id": "GPL-2.0-or-later"
145069              }
145070            },
145071            {
145072              "license": {
145073                "name": "public-domain-md5"
145074              }
145075            },
145076            {
145077              "license": {
145078                "name": "public-domain-s-s-d"
145079              }
145080            }
145081          ],
145082          "cpe": "cpe:2.3:a:dpkg:dpkg:1.19.7ubuntu3:*:*:*:*:*:*:*",
145083          "purl": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04",
145084          "swid": {
145085            "attachment": {}
145086          },
145087          "pedigree": {},
145088          "evidence": {},
145089          "signature": {
145090            "signature": {
145091              "publicKey": {}
145092            }
145093          },
145094          "modelCard": {
145095            "modelParameters": {
145096              "approach": {}
145097            },
145098            "quantitativeAnalysis": {
145099              "graphics": {}
145100            },
145101            "considerations": {}
145102          }
145103        },
145104        {
145105          "type": "library",
145106          "bom-ref": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=6a037357f3ebf47a",
145107          "supplier": {},
145108          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
145109          "name": "e2fsprogs",
145110          "version": "1.45.5-2ubuntu1",
145111          "licenses": [
145112            {
145113              "license": {
145114                "id": "GPL-2.0-only"
145115              }
145116            },
145117            {
145118              "license": {
145119                "id": "LGPL-2.0-only"
145120              }
145121            }
145122          ],
145123          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
145124          "purl": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
145125          "swid": {
145126            "attachment": {}
145127          },
145128          "pedigree": {},
145129          "evidence": {},
145130          "signature": {
145131            "signature": {
145132              "publicKey": {}
145133            }
145134          },
145135          "modelCard": {
145136            "modelParameters": {
145137              "approach": {}
145138            },
145139            "quantitativeAnalysis": {
145140              "graphics": {}
145141            },
145142            "considerations": {}
145143          }
145144        },
145145        {
145146          "type": "library",
145147          "bom-ref": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=a57a5f37c7970fe9",
145148          "supplier": {},
145149          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
145150          "name": "fdisk",
145151          "version": "2.34-0.1ubuntu9.1",
145152          "licenses": [
145153            {
145154              "license": {
145155                "id": "BSD-2-Clause"
145156              }
145157            },
145158            {
145159              "license": {
145160                "id": "BSD-3-Clause"
145161              }
145162            },
145163            {
145164              "license": {
145165                "id": "BSD-4-Clause"
145166              }
145167            },
145168            {
145169              "license": {
145170                "id": "GPL-2.0-only"
145171              }
145172            },
145173            {
145174              "license": {
145175                "id": "GPL-2.0-or-later"
145176              }
145177            },
145178            {
145179              "license": {
145180                "id": "GPL-3.0-only"
145181              }
145182            },
145183            {
145184              "license": {
145185                "id": "GPL-3.0-or-later"
145186              }
145187            },
145188            {
145189              "license": {
145190                "name": "LGPL"
145191              }
145192            },
145193            {
145194              "license": {
145195                "id": "LGPL-2.0-only"
145196              }
145197            },
145198            {
145199              "license": {
145200                "id": "LGPL-2.0-or-later"
145201              }
145202            },
145203            {
145204              "license": {
145205                "id": "LGPL-2.1-only"
145206              }
145207            },
145208            {
145209              "license": {
145210                "id": "LGPL-2.1-or-later"
145211              }
145212            },
145213            {
145214              "license": {
145215                "id": "LGPL-3.0-only"
145216              }
145217            },
145218            {
145219              "license": {
145220                "id": "LGPL-3.0-or-later"
145221              }
145222            },
145223            {
145224              "license": {
145225                "id": "MIT"
145226              }
145227            },
145228            {
145229              "license": {
145230                "name": "public-domain"
145231              }
145232            }
145233          ],
145234          "cpe": "cpe:2.3:a:fdisk:fdisk:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
145235          "purl": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
145236          "swid": {
145237            "attachment": {}
145238          },
145239          "pedigree": {},
145240          "evidence": {},
145241          "signature": {
145242            "signature": {
145243              "publicKey": {}
145244            }
145245          },
145246          "modelCard": {
145247            "modelParameters": {
145248              "approach": {}
145249            },
145250            "quantitativeAnalysis": {
145251              "graphics": {}
145252            },
145253            "considerations": {}
145254          }
145255        },
145256        {
145257          "type": "library",
145258          "bom-ref": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7f183ce6dc05cfb",
145259          "supplier": {},
145260          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
145261          "name": "file",
145262          "version": "1:5.38-4",
145263          "licenses": [
145264            {
145265              "license": {
145266                "name": "BSD-2-Clause-alike"
145267              }
145268            },
145269            {
145270              "license": {
145271                "id": "BSD-2-Clause"
145272              }
145273            },
145274            {
145275              "license": {
145276                "name": "BSD-2-Clause-regents"
145277              }
145278            },
145279            {
145280              "license": {
145281                "name": "MIT-Old-Style-with-legal-disclaimer-2"
145282              }
145283            },
145284            {
145285              "license": {
145286                "name": "public-domain"
145287              }
145288            }
145289          ],
145290          "cpe": "cpe:2.3:a:file:file:1\\:5.38-4:*:*:*:*:*:*:*",
145291          "purl": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04",
145292          "swid": {
145293            "attachment": {}
145294          },
145295          "pedigree": {},
145296          "evidence": {},
145297          "signature": {
145298            "signature": {
145299              "publicKey": {}
145300            }
145301          },
145302          "modelCard": {
145303            "modelParameters": {
145304              "approach": {}
145305            },
145306            "quantitativeAnalysis": {
145307              "graphics": {}
145308            },
145309            "considerations": {}
145310          }
145311        },
145312        {
145313          "type": "library",
145314          "bom-ref": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=103a5999463b7e08",
145315          "supplier": {},
145316          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
145317          "name": "findutils",
145318          "version": "4.7.0-1ubuntu1",
145319          "licenses": [
145320            {
145321              "license": {
145322                "id": "GFDL-1.3-only"
145323              }
145324            },
145325            {
145326              "license": {
145327                "id": "GPL-3.0-only"
145328              }
145329            }
145330          ],
145331          "cpe": "cpe:2.3:a:findutils:findutils:4.7.0-1ubuntu1:*:*:*:*:*:*:*",
145332          "purl": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
145333          "swid": {
145334            "attachment": {}
145335          },
145336          "pedigree": {},
145337          "evidence": {},
145338          "signature": {
145339            "signature": {
145340              "publicKey": {}
145341            }
145342          },
145343          "modelCard": {
145344            "modelParameters": {
145345              "approach": {}
145346            },
145347            "quantitativeAnalysis": {
145348              "graphics": {}
145349            },
145350            "considerations": {}
145351          }
145352        },
145353        {
145354          "type": "library",
145355          "bom-ref": "pkg:deb/ubuntu/fuse@2.9.9-3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=3862cd07205c94e",
145356          "supplier": {},
145357          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
145358          "name": "fuse",
145359          "version": "2.9.9-3",
145360          "licenses": [
145361            {
145362              "license": {
145363                "id": "GPL-2.0-only"
145364              }
145365            },
145366            {
145367              "license": {
145368                "id": "GPL-2.0-or-later"
145369              }
145370            },
145371            {
145372              "license": {
145373                "id": "LGPL-2.0-only"
145374              }
145375            }
145376          ],
145377          "cpe": "cpe:2.3:a:fuse:fuse:2.9.9-3:*:*:*:*:*:*:*",
145378          "purl": "pkg:deb/ubuntu/fuse@2.9.9-3?arch=amd64\u0026distro=ubuntu-20.04",
145379          "swid": {
145380            "attachment": {}
145381          },
145382          "pedigree": {},
145383          "evidence": {},
145384          "signature": {
145385            "signature": {
145386              "publicKey": {}
145387            }
145388          },
145389          "modelCard": {
145390            "modelParameters": {
145391              "approach": {}
145392            },
145393            "quantitativeAnalysis": {
145394              "graphics": {}
145395            },
145396            "considerations": {}
145397          }
145398        },
145399        {
145400          "type": "library",
145401          "bom-ref": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=a268d6ad2986f239",
145402          "supplier": {},
145403          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
145404          "name": "gcc-10-base",
145405          "version": "10.3.0-1ubuntu1~20.04",
145406          "licenses": [
145407            {
145408              "license": {
145409                "name": "Artistic"
145410              }
145411            },
145412            {
145413              "license": {
145414                "id": "GFDL-1.2-only"
145415              }
145416            },
145417            {
145418              "license": {
145419                "name": "GPL"
145420              }
145421            },
145422            {
145423              "license": {
145424                "id": "GPL-2.0-only"
145425              }
145426            },
145427            {
145428              "license": {
145429                "id": "GPL-3.0-only"
145430              }
145431            },
145432            {
145433              "license": {
145434                "name": "LGPL"
145435              }
145436            }
145437          ],
145438          "cpe": "cpe:2.3:a:gcc-10-base:gcc-10-base:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
145439          "purl": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
145440          "swid": {
145441            "attachment": {}
145442          },
145443          "pedigree": {},
145444          "evidence": {},
145445          "signature": {
145446            "signature": {
145447              "publicKey": {}
145448            }
145449          },
145450          "modelCard": {
145451            "modelParameters": {
145452              "approach": {}
145453            },
145454            "quantitativeAnalysis": {
145455              "graphics": {}
145456            },
145457            "considerations": {}
145458          }
145459        },
145460        {
145461          "type": "library",
145462          "bom-ref": "pkg:golang/github.com/roaringbitmap/roaring@v0.4.18?package-id=2ab78f8b00c7fb23",
145463          "supplier": {},
145464          "name": "github.com/RoaringBitmap/roaring",
145465          "version": "v0.4.18",
145466          "cpe": "cpe:2.3:a:RoaringBitmap:roaring:v0.4.18:*:*:*:*:*:*:*",
145467          "purl": "pkg:golang/github.com/RoaringBitmap/roaring@v0.4.18",
145468          "swid": {
145469            "attachment": {}
145470          },
145471          "pedigree": {},
145472          "evidence": {},
145473          "signature": {
145474            "signature": {
145475              "publicKey": {}
145476            }
145477          },
145478          "modelCard": {
145479            "modelParameters": {
145480              "approach": {}
145481            },
145482            "quantitativeAnalysis": {
145483              "graphics": {}
145484            },
145485            "considerations": {}
145486          }
145487        },
145488        {
145489          "type": "library",
145490          "bom-ref": "pkg:golang/github.com/c9s/goprocinfo@v0.0.0-20190309065803-0b2ad9ac246b?package-id=dfa5dd136a97849f",
145491          "supplier": {},
145492          "name": "github.com/c9s/goprocinfo",
145493          "version": "v0.0.0-20190309065803-0b2ad9ac246b",
145494          "cpe": "cpe:2.3:a:c9s:goprocinfo:v0.0.0-20190309065803-0b2ad9ac246b:*:*:*:*:*:*:*",
145495          "purl": "pkg:golang/github.com/c9s/goprocinfo@v0.0.0-20190309065803-0b2ad9ac246b",
145496          "swid": {
145497            "attachment": {}
145498          },
145499          "pedigree": {},
145500          "evidence": {},
145501          "signature": {
145502            "signature": {
145503              "publicKey": {}
145504            }
145505          },
145506          "modelCard": {
145507            "modelParameters": {
145508              "approach": {}
145509            },
145510            "quantitativeAnalysis": {
145511              "graphics": {}
145512            },
145513            "considerations": {}
145514          }
145515        },
145516        {
145517          "type": "library",
145518          "bom-ref": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d?package-id=f82b726640827af0",
145519          "supplier": {},
145520          "name": "github.com/cpuguy83/go-md2man/v2",
145521          "version": "v2.0.0-20190314233015-f79a8a8ca69d",
145522          "cpe": "cpe:2.3:a:cpuguy83:go-md2man\\/v2:v2.0.0-20190314233015-f79a8a8ca69d:*:*:*:*:*:*:*",
145523          "purl": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d",
145524          "swid": {
145525            "attachment": {}
145526          },
145527          "pedigree": {},
145528          "evidence": {},
145529          "signature": {
145530            "signature": {
145531              "publicKey": {}
145532            }
145533          },
145534          "modelCard": {
145535            "modelParameters": {
145536              "approach": {}
145537            },
145538            "quantitativeAnalysis": {
145539              "graphics": {}
145540            },
145541            "considerations": {}
145542          }
145543        },
145544        {
145545          "type": "library",
145546          "bom-ref": "pkg:golang/github.com/glycerine/go-unsnap-stream@v0.0.0-20181221182339-f9677308dec2?package-id=2220c4d4560c7156",
145547          "supplier": {},
145548          "name": "github.com/glycerine/go-unsnap-stream",
145549          "version": "v0.0.0-20181221182339-f9677308dec2",
145550          "cpe": "cpe:2.3:a:glycerine:go-unsnap-stream:v0.0.0-20181221182339-f9677308dec2:*:*:*:*:*:*:*",
145551          "purl": "pkg:golang/github.com/glycerine/go-unsnap-stream@v0.0.0-20181221182339-f9677308dec2",
145552          "swid": {
145553            "attachment": {}
145554          },
145555          "pedigree": {},
145556          "evidence": {},
145557          "signature": {
145558            "signature": {
145559              "publicKey": {}
145560            }
145561          },
145562          "modelCard": {
145563            "modelParameters": {
145564              "approach": {}
145565            },
145566            "quantitativeAnalysis": {
145567              "graphics": {}
145568            },
145569            "considerations": {}
145570          }
145571        },
145572        {
145573          "type": "library",
145574          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf?package-id=72803f491048bce8",
145575          "supplier": {},
145576          "name": "github.com/golang/protobuf",
145577          "version": "v1.3.3-0.20190920234318-1680a479a2cf",
145578          "cpe": "cpe:2.3:a:golang:protobuf:v1.3.3-0.20190920234318-1680a479a2cf:*:*:*:*:*:*:*",
145579          "purl": "pkg:golang/github.com/golang/protobuf@v1.3.3-0.20190920234318-1680a479a2cf",
145580          "swid": {
145581            "attachment": {}
145582          },
145583          "pedigree": {},
145584          "evidence": {},
145585          "signature": {
145586            "signature": {
145587              "publicKey": {}
145588            }
145589          },
145590          "modelCard": {
145591            "modelParameters": {
145592              "approach": {}
145593            },
145594            "quantitativeAnalysis": {
145595              "graphics": {}
145596            },
145597            "considerations": {}
145598          }
145599        },
145600        {
145601          "type": "library",
145602          "bom-ref": "pkg:golang/github.com/golang/snappy@v0.0.1?package-id=4faa11db80b31934",
145603          "supplier": {},
145604          "name": "github.com/golang/snappy",
145605          "version": "v0.0.1",
145606          "cpe": "cpe:2.3:a:golang:snappy:v0.0.1:*:*:*:*:*:*:*",
145607          "purl": "pkg:golang/github.com/golang/snappy@v0.0.1",
145608          "swid": {
145609            "attachment": {}
145610          },
145611          "pedigree": {},
145612          "evidence": {},
145613          "signature": {
145614            "signature": {
145615              "publicKey": {}
145616            }
145617          },
145618          "modelCard": {
145619            "modelParameters": {
145620              "approach": {}
145621            },
145622            "quantitativeAnalysis": {
145623              "graphics": {}
145624            },
145625            "considerations": {}
145626          }
145627        },
145628        {
145629          "type": "library",
145630          "bom-ref": "pkg:golang/github.com/gorilla/handlers@v1.4.2?package-id=a7bae7113c5e41dd",
145631          "supplier": {},
145632          "name": "github.com/gorilla/handlers",
145633          "version": "v1.4.2",
145634          "cpe": "cpe:2.3:a:gorilla:handlers:v1.4.2:*:*:*:*:*:*:*",
145635          "purl": "pkg:golang/github.com/gorilla/handlers@v1.4.2",
145636          "swid": {
145637            "attachment": {}
145638          },
145639          "pedigree": {},
145640          "evidence": {},
145641          "signature": {
145642            "signature": {
145643              "publicKey": {}
145644            }
145645          },
145646          "modelCard": {
145647            "modelParameters": {
145648              "approach": {}
145649            },
145650            "quantitativeAnalysis": {
145651              "graphics": {}
145652            },
145653            "considerations": {}
145654          }
145655        },
145656        {
145657          "type": "library",
145658          "bom-ref": "pkg:golang/github.com/gorilla/mux@v1.7.3?package-id=9c8b1c982000a208",
145659          "supplier": {},
145660          "name": "github.com/gorilla/mux",
145661          "version": "v1.7.3",
145662          "cpe": "cpe:2.3:a:gorilla:mux:v1.7.3:*:*:*:*:*:*:*",
145663          "purl": "pkg:golang/github.com/gorilla/mux@v1.7.3",
145664          "swid": {
145665            "attachment": {}
145666          },
145667          "pedigree": {},
145668          "evidence": {},
145669          "signature": {
145670            "signature": {
145671              "publicKey": {}
145672            }
145673          },
145674          "modelCard": {
145675            "modelParameters": {
145676              "approach": {}
145677            },
145678            "quantitativeAnalysis": {
145679              "graphics": {}
145680            },
145681            "considerations": {}
145682          }
145683        },
145684        {
145685          "type": "library",
145686          "bom-ref": "pkg:golang/github.com/longhorn/backing-image-manager@(devel)?package-id=ffc43a69dd95e264",
145687          "supplier": {},
145688          "name": "github.com/longhorn/backing-image-manager",
145689          "version": "(devel)",
145690          "cpe": "cpe:2.3:a:longhorn:backing-image-manager:\\(devel\\):*:*:*:*:*:*:*",
145691          "purl": "pkg:golang/github.com/longhorn/backing-image-manager@(devel)",
145692          "swid": {
145693            "attachment": {}
145694          },
145695          "pedigree": {},
145696          "evidence": {},
145697          "signature": {
145698            "signature": {
145699              "publicKey": {}
145700            }
145701          },
145702          "modelCard": {
145703            "modelParameters": {
145704              "approach": {}
145705            },
145706            "quantitativeAnalysis": {
145707              "graphics": {}
145708            },
145709            "considerations": {}
145710          }
145711        },
145712        {
145713          "type": "library",
145714          "bom-ref": "pkg:golang/github.com/longhorn/go-iscsi-helper@v0.0.0-20210330030558-49a327fb024e?package-id=1f3ecf015745a713",
145715          "supplier": {},
145716          "name": "github.com/longhorn/go-iscsi-helper",
145717          "version": "v0.0.0-20210330030558-49a327fb024e",
145718          "cpe": "cpe:2.3:a:longhorn:go-iscsi-helper:v0.0.0-20210330030558-49a327fb024e:*:*:*:*:*:*:*",
145719          "purl": "pkg:golang/github.com/longhorn/go-iscsi-helper@v0.0.0-20210330030558-49a327fb024e",
145720          "swid": {
145721            "attachment": {}
145722          },
145723          "pedigree": {},
145724          "evidence": {},
145725          "signature": {
145726            "signature": {
145727              "publicKey": {}
145728            }
145729          },
145730          "modelCard": {
145731            "modelParameters": {
145732              "approach": {}
145733            },
145734            "quantitativeAnalysis": {
145735              "graphics": {}
145736            },
145737            "considerations": {}
145738          }
145739        },
145740        {
145741          "type": "library",
145742          "bom-ref": "pkg:golang/github.com/longhorn/longhorn-engine@v1.2.0-preview1.0.20210818142058-32cb7dfd0630?package-id=780fb22e1986ca99",
145743          "supplier": {},
145744          "name": "github.com/longhorn/longhorn-engine",
145745          "version": "v1.2.0-preview1.0.20210818142058-32cb7dfd0630",
145746          "cpe": "cpe:2.3:a:longhorn:longhorn-engine:v1.2.0-preview1.0.20210818142058-32cb7dfd0630:*:*:*:*:*:*:*",
145747          "purl": "pkg:golang/github.com/longhorn/longhorn-engine@v1.2.0-preview1.0.20210818142058-32cb7dfd0630",
145748          "swid": {
145749            "attachment": {}
145750          },
145751          "pedigree": {},
145752          "evidence": {},
145753          "signature": {
145754            "signature": {
145755              "publicKey": {}
145756            }
145757          },
145758          "modelCard": {
145759            "modelParameters": {
145760              "approach": {}
145761            },
145762            "quantitativeAnalysis": {
145763              "graphics": {}
145764            },
145765            "considerations": {}
145766          }
145767        },
145768        {
145769          "type": "library",
145770          "bom-ref": "pkg:golang/github.com/longhorn/sparse-tools@v0.0.0-20210729195155-a0fb4226a960?package-id=2e50c4b7e30c80f",
145771          "supplier": {},
145772          "name": "github.com/longhorn/sparse-tools",
145773          "version": "v0.0.0-20210729195155-a0fb4226a960",
145774          "cpe": "cpe:2.3:a:longhorn:sparse-tools:v0.0.0-20210729195155-a0fb4226a960:*:*:*:*:*:*:*",
145775          "purl": "pkg:golang/github.com/longhorn/sparse-tools@v0.0.0-20210729195155-a0fb4226a960",
145776          "swid": {
145777            "attachment": {}
145778          },
145779          "pedigree": {},
145780          "evidence": {},
145781          "signature": {
145782            "signature": {
145783              "publicKey": {}
145784            }
145785          },
145786          "modelCard": {
145787            "modelParameters": {
145788              "approach": {}
145789            },
145790            "quantitativeAnalysis": {
145791              "graphics": {}
145792            },
145793            "considerations": {}
145794          }
145795        },
145796        {
145797          "type": "library",
145798          "bom-ref": "pkg:golang/github.com/philhofer/fwd@v1.0.0?package-id=acf87332c4c922e3",
145799          "supplier": {},
145800          "name": "github.com/philhofer/fwd",
145801          "version": "v1.0.0",
145802          "cpe": "cpe:2.3:a:philhofer:fwd:v1.0.0:*:*:*:*:*:*:*",
145803          "purl": "pkg:golang/github.com/philhofer/fwd@v1.0.0",
145804          "swid": {
145805            "attachment": {}
145806          },
145807          "pedigree": {},
145808          "evidence": {},
145809          "signature": {
145810            "signature": {
145811              "publicKey": {}
145812            }
145813          },
145814          "modelCard": {
145815            "modelParameters": {
145816              "approach": {}
145817            },
145818            "quantitativeAnalysis": {
145819              "graphics": {}
145820            },
145821            "considerations": {}
145822          }
145823        },
145824        {
145825          "type": "library",
145826          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.9.1?package-id=548db79e9f4bc26f",
145827          "supplier": {},
145828          "name": "github.com/pkg/errors",
145829          "version": "v0.9.1",
145830          "cpe": "cpe:2.3:a:pkg:errors:v0.9.1:*:*:*:*:*:*:*",
145831          "purl": "pkg:golang/github.com/pkg/errors@v0.9.1",
145832          "swid": {
145833            "attachment": {}
145834          },
145835          "pedigree": {},
145836          "evidence": {},
145837          "signature": {
145838            "signature": {
145839              "publicKey": {}
145840            }
145841          },
145842          "modelCard": {
145843            "modelParameters": {
145844              "approach": {}
145845            },
145846            "quantitativeAnalysis": {
145847              "graphics": {}
145848            },
145849            "considerations": {}
145850          }
145851        },
145852        {
145853          "type": "library",
145854          "bom-ref": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1?package-id=9d56f5a3a013a5ed",
145855          "supplier": {},
145856          "name": "github.com/russross/blackfriday/v2",
145857          "version": "v2.0.1",
145858          "cpe": "cpe:2.3:a:russross:blackfriday\\/v2:v2.0.1:*:*:*:*:*:*:*",
145859          "purl": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1",
145860          "swid": {
145861            "attachment": {}
145862          },
145863          "pedigree": {},
145864          "evidence": {},
145865          "signature": {
145866            "signature": {
145867              "publicKey": {}
145868            }
145869          },
145870          "modelCard": {
145871            "modelParameters": {
145872              "approach": {}
145873            },
145874            "quantitativeAnalysis": {
145875              "graphics": {}
145876            },
145877            "considerations": {}
145878          }
145879        },
145880        {
145881          "type": "library",
145882          "bom-ref": "pkg:golang/github.com/satori/go.uuid@v1.2.0?package-id=e9b4eb22cca6b2f2",
145883          "supplier": {},
145884          "name": "github.com/satori/go.uuid",
145885          "version": "v1.2.0",
145886          "cpe": "cpe:2.3:a:satori:go.uuid:v1.2.0:*:*:*:*:*:*:*",
145887          "purl": "pkg:golang/github.com/satori/go.uuid@v1.2.0",
145888          "swid": {
145889            "attachment": {}
145890          },
145891          "pedigree": {},
145892          "evidence": {},
145893          "signature": {
145894            "signature": {
145895              "publicKey": {}
145896            }
145897          },
145898          "modelCard": {
145899            "modelParameters": {
145900              "approach": {}
145901            },
145902            "quantitativeAnalysis": {
145903              "graphics": {}
145904            },
145905            "considerations": {}
145906          }
145907        },
145908        {
145909          "type": "library",
145910          "bom-ref": "pkg:golang/github.com/shurcool/sanitized_anchor_name@v1.0.0?package-id=3c7b58b884111da5",
145911          "supplier": {},
145912          "name": "github.com/shurcooL/sanitized_anchor_name",
145913          "version": "v1.0.0",
145914          "cpe": "cpe:2.3:a:shurcooL:sanitized-anchor-name:v1.0.0:*:*:*:*:*:*:*",
145915          "purl": "pkg:golang/github.com/shurcooL/sanitized_anchor_name@v1.0.0",
145916          "swid": {
145917            "attachment": {}
145918          },
145919          "pedigree": {},
145920          "evidence": {},
145921          "signature": {
145922            "signature": {
145923              "publicKey": {}
145924            }
145925          },
145926          "modelCard": {
145927            "modelParameters": {
145928              "approach": {}
145929            },
145930            "quantitativeAnalysis": {
145931              "graphics": {}
145932            },
145933            "considerations": {}
145934          }
145935        },
145936        {
145937          "type": "library",
145938          "bom-ref": "pkg:golang/github.com/sirupsen/logrus@v1.8.1?package-id=9ba83838968aa4e9",
145939          "supplier": {},
145940          "name": "github.com/sirupsen/logrus",
145941          "version": "v1.8.1",
145942          "cpe": "cpe:2.3:a:sirupsen:logrus:v1.8.1:*:*:*:*:*:*:*",
145943          "purl": "pkg:golang/github.com/sirupsen/logrus@v1.8.1",
145944          "swid": {
145945            "attachment": {}
145946          },
145947          "pedigree": {},
145948          "evidence": {},
145949          "signature": {
145950            "signature": {
145951              "publicKey": {}
145952            }
145953          },
145954          "modelCard": {
145955            "modelParameters": {
145956              "approach": {}
145957            },
145958            "quantitativeAnalysis": {
145959              "graphics": {}
145960            },
145961            "considerations": {}
145962          }
145963        },
145964        {
145965          "type": "library",
145966          "bom-ref": "pkg:golang/github.com/tinylib/msgp@v1.1.1-0.20190612170807-0573788bc2a8?package-id=dbe836d5220404ac",
145967          "supplier": {},
145968          "name": "github.com/tinylib/msgp",
145969          "version": "v1.1.1-0.20190612170807-0573788bc2a8",
145970          "cpe": "cpe:2.3:a:tinylib:msgp:v1.1.1-0.20190612170807-0573788bc2a8:*:*:*:*:*:*:*",
145971          "purl": "pkg:golang/github.com/tinylib/msgp@v1.1.1-0.20190612170807-0573788bc2a8",
145972          "swid": {
145973            "attachment": {}
145974          },
145975          "pedigree": {},
145976          "evidence": {},
145977          "signature": {
145978            "signature": {
145979              "publicKey": {}
145980            }
145981          },
145982          "modelCard": {
145983            "modelParameters": {
145984              "approach": {}
145985            },
145986            "quantitativeAnalysis": {
145987              "graphics": {}
145988            },
145989            "considerations": {}
145990          }
145991        },
145992        {
145993          "type": "library",
145994          "bom-ref": "pkg:golang/github.com/urfave/cli@v1.22.1?package-id=85cb338d96b8cce5",
145995          "supplier": {},
145996          "name": "github.com/urfave/cli",
145997          "version": "v1.22.1",
145998          "cpe": "cpe:2.3:a:urfave:cli:v1.22.1:*:*:*:*:*:*:*",
145999          "purl": "pkg:golang/github.com/urfave/cli@v1.22.1",
146000          "swid": {
146001            "attachment": {}
146002          },
146003          "pedigree": {},
146004          "evidence": {},
146005          "signature": {
146006            "signature": {
146007              "publicKey": {}
146008            }
146009          },
146010          "modelCard": {
146011            "modelParameters": {
146012              "approach": {}
146013            },
146014            "quantitativeAnalysis": {
146015              "graphics": {}
146016            },
146017            "considerations": {}
146018          }
146019        },
146020        {
146021          "type": "library",
146022          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20190522155817-f3200d17e092?package-id=3593943397abc098",
146023          "supplier": {},
146024          "name": "golang.org/x/net",
146025          "version": "v0.0.0-20190522155817-f3200d17e092",
146026          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20190522155817-f3200d17e092:*:*:*:*:*:*:*",
146027          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20190522155817-f3200d17e092",
146028          "swid": {
146029            "attachment": {}
146030          },
146031          "pedigree": {},
146032          "evidence": {},
146033          "signature": {
146034            "signature": {
146035              "publicKey": {}
146036            }
146037          },
146038          "modelCard": {
146039            "modelParameters": {
146040              "approach": {}
146041            },
146042            "quantitativeAnalysis": {
146043              "graphics": {}
146044            },
146045            "considerations": {}
146046          }
146047        },
146048        {
146049          "type": "library",
146050          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c?package-id=80a6303ad99c8ab1",
146051          "supplier": {},
146052          "name": "golang.org/x/sys",
146053          "version": "v0.0.0-20210630005230-0f9fa26af87c",
146054          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20210630005230-0f9fa26af87c:*:*:*:*:*:*:*",
146055          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20210630005230-0f9fa26af87c",
146056          "swid": {
146057            "attachment": {}
146058          },
146059          "pedigree": {},
146060          "evidence": {},
146061          "signature": {
146062            "signature": {
146063              "publicKey": {}
146064            }
146065          },
146066          "modelCard": {
146067            "modelParameters": {
146068              "approach": {}
146069            },
146070            "quantitativeAnalysis": {
146071              "graphics": {}
146072            },
146073            "considerations": {}
146074          }
146075        },
146076        {
146077          "type": "library",
146078          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.3?package-id=cc890121940b4a2c",
146079          "supplier": {},
146080          "name": "golang.org/x/text",
146081          "version": "v0.3.3",
146082          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.3:*:*:*:*:*:*:*",
146083          "purl": "pkg:golang/golang.org/x/text@v0.3.3",
146084          "swid": {
146085            "attachment": {}
146086          },
146087          "pedigree": {},
146088          "evidence": {},
146089          "signature": {
146090            "signature": {
146091              "publicKey": {}
146092            }
146093          },
146094          "modelCard": {
146095            "modelParameters": {
146096              "approach": {}
146097            },
146098            "quantitativeAnalysis": {
146099              "graphics": {}
146100            },
146101            "considerations": {}
146102          }
146103        },
146104        {
146105          "type": "library",
146106          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20180817151627-c66870c02cf8?package-id=b71d9d82980960b2",
146107          "supplier": {},
146108          "name": "google.golang.org/genproto",
146109          "version": "v0.0.0-20180817151627-c66870c02cf8",
146110          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20180817151627-c66870c02cf8:*:*:*:*:*:*:*",
146111          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20180817151627-c66870c02cf8",
146112          "swid": {
146113            "attachment": {}
146114          },
146115          "pedigree": {},
146116          "evidence": {},
146117          "signature": {
146118            "signature": {
146119              "publicKey": {}
146120            }
146121          },
146122          "modelCard": {
146123            "modelParameters": {
146124              "approach": {}
146125            },
146126            "quantitativeAnalysis": {
146127              "graphics": {}
146128            },
146129            "considerations": {}
146130          }
146131        },
146132        {
146133          "type": "library",
146134          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.21.0?package-id=7723f5dcb8390645",
146135          "supplier": {},
146136          "name": "google.golang.org/grpc",
146137          "version": "v1.21.0",
146138          "cpe": "cpe:2.3:a:google:grpc:v1.21.0:*:*:*:*:*:*:*",
146139          "purl": "pkg:golang/google.golang.org/grpc@v1.21.0",
146140          "swid": {
146141            "attachment": {}
146142          },
146143          "pedigree": {},
146144          "evidence": {},
146145          "signature": {
146146            "signature": {
146147              "publicKey": {}
146148            }
146149          },
146150          "modelCard": {
146151            "modelParameters": {
146152              "approach": {}
146153            },
146154            "quantitativeAnalysis": {
146155              "graphics": {}
146156            },
146157            "considerations": {}
146158          }
146159        },
146160        {
146161          "type": "library",
146162          "bom-ref": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04\u0026package-id=b3a56223224b45d2",
146163          "supplier": {},
146164          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146165          "name": "gpgv",
146166          "version": "2.2.19-3ubuntu2.1",
146167          "licenses": [
146168            {
146169              "license": {
146170                "id": "BSD-3-Clause"
146171              }
146172            },
146173            {
146174              "license": {
146175                "id": "CC0-1.0"
146176              }
146177            },
146178            {
146179              "license": {
146180                "name": "Expat"
146181              }
146182            },
146183            {
146184              "license": {
146185                "id": "GPL-3.0-only"
146186              }
146187            },
146188            {
146189              "license": {
146190                "id": "GPL-3.0-or-later"
146191              }
146192            },
146193            {
146194              "license": {
146195                "id": "LGPL-2.1-only"
146196              }
146197            },
146198            {
146199              "license": {
146200                "id": "LGPL-2.1-or-later"
146201              }
146202            },
146203            {
146204              "license": {
146205                "id": "LGPL-3.0-only"
146206              }
146207            },
146208            {
146209              "license": {
146210                "id": "LGPL-3.0-or-later"
146211              }
146212            },
146213            {
146214              "license": {
146215                "name": "RFC-Reference"
146216              }
146217            },
146218            {
146219              "license": {
146220                "name": "TinySCHEME"
146221              }
146222            },
146223            {
146224              "license": {
146225                "name": "permissive"
146226              }
146227            }
146228          ],
146229          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.19-3ubuntu2.1:*:*:*:*:*:*:*",
146230          "purl": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04",
146231          "swid": {
146232            "attachment": {}
146233          },
146234          "pedigree": {},
146235          "evidence": {},
146236          "signature": {
146237            "signature": {
146238              "publicKey": {}
146239            }
146240          },
146241          "modelCard": {
146242            "modelParameters": {
146243              "approach": {}
146244            },
146245            "quantitativeAnalysis": {
146246              "graphics": {}
146247            },
146248            "considerations": {}
146249          }
146250        },
146251        {
146252          "type": "library",
146253          "bom-ref": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7af9af4b90473f",
146254          "supplier": {},
146255          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146256          "name": "grep",
146257          "version": "3.4-1",
146258          "licenses": [
146259            {
146260              "license": {
146261                "id": "GPL-3.0-only"
146262              }
146263            },
146264            {
146265              "license": {
146266                "id": "GPL-3.0-or-later"
146267              }
146268            }
146269          ],
146270          "cpe": "cpe:2.3:a:grep:grep:3.4-1:*:*:*:*:*:*:*",
146271          "purl": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04",
146272          "swid": {
146273            "attachment": {}
146274          },
146275          "pedigree": {},
146276          "evidence": {},
146277          "signature": {
146278            "signature": {
146279              "publicKey": {}
146280            }
146281          },
146282          "modelCard": {
146283            "modelParameters": {
146284              "approach": {}
146285            },
146286            "quantitativeAnalysis": {
146287              "graphics": {}
146288            },
146289            "considerations": {}
146290          }
146291        },
146292        {
146293          "type": "library",
146294          "bom-ref": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a9696917d3b9f9fc",
146295          "supplier": {},
146296          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146297          "name": "gzip",
146298          "version": "1.10-0ubuntu4",
146299          "licenses": [
146300            {
146301              "license": {
146302                "name": "GPL"
146303              }
146304            }
146305          ],
146306          "cpe": "cpe:2.3:a:gzip:gzip:1.10-0ubuntu4:*:*:*:*:*:*:*",
146307          "purl": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04",
146308          "swid": {
146309            "attachment": {}
146310          },
146311          "pedigree": {},
146312          "evidence": {},
146313          "signature": {
146314            "signature": {
146315              "publicKey": {}
146316            }
146317          },
146318          "modelCard": {
146319            "modelParameters": {
146320              "approach": {}
146321            },
146322            "quantitativeAnalysis": {
146323              "graphics": {}
146324            },
146325            "considerations": {}
146326          }
146327        },
146328        {
146329          "type": "library",
146330          "bom-ref": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=263dae70cc8e6a4f",
146331          "supplier": {},
146332          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146333          "name": "hostname",
146334          "version": "3.23",
146335          "licenses": [
146336            {
146337              "license": {
146338                "id": "GPL-2.0-only"
146339              }
146340            }
146341          ],
146342          "cpe": "cpe:2.3:a:hostname:hostname:3.23:*:*:*:*:*:*:*",
146343          "purl": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04",
146344          "swid": {
146345            "attachment": {}
146346          },
146347          "pedigree": {},
146348          "evidence": {},
146349          "signature": {
146350            "signature": {
146351              "publicKey": {}
146352            }
146353          },
146354          "modelCard": {
146355            "modelParameters": {
146356              "approach": {}
146357            },
146358            "quantitativeAnalysis": {
146359              "graphics": {}
146360            },
146361            "considerations": {}
146362          }
146363        },
146364        {
146365          "type": "library",
146366          "bom-ref": "pkg:deb/ubuntu/ibverbs-providers@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04\u0026package-id=8e9d2de3c937ce3c",
146367          "supplier": {},
146368          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146369          "name": "ibverbs-providers",
146370          "version": "28.0-1ubuntu1",
146371          "licenses": [
146372            {
146373              "license": {
146374                "id": "BSD-2-Clause"
146375              }
146376            },
146377            {
146378              "license": {
146379                "id": "BSD-3-Clause"
146380              }
146381            },
146382            {
146383              "license": {
146384                "name": "BSD-MIT"
146385              }
146386            },
146387            {
146388              "license": {
146389                "name": "CC0"
146390              }
146391            },
146392            {
146393              "license": {
146394                "id": "CPL-1.0"
146395              }
146396            },
146397            {
146398              "license": {
146399                "id": "GPL-2.0-only"
146400              }
146401            },
146402            {
146403              "license": {
146404                "id": "GPL-2.0-or-later"
146405              }
146406            },
146407            {
146408              "license": {
146409                "id": "MIT"
146410              }
146411            }
146412          ],
146413          "cpe": "cpe:2.3:a:ibverbs-providers:ibverbs-providers:28.0-1ubuntu1:*:*:*:*:*:*:*",
146414          "purl": "pkg:deb/ubuntu/ibverbs-providers@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04",
146415          "swid": {
146416            "attachment": {}
146417          },
146418          "pedigree": {},
146419          "evidence": {},
146420          "signature": {
146421            "signature": {
146422              "publicKey": {}
146423            }
146424          },
146425          "modelCard": {
146426            "modelParameters": {
146427              "approach": {}
146428            },
146429            "quantitativeAnalysis": {
146430              "graphics": {}
146431            },
146432            "considerations": {}
146433          }
146434        },
146435        {
146436          "type": "library",
146437          "bom-ref": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04\u0026package-id=b0e335d96f12154d",
146438          "supplier": {},
146439          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146440          "name": "init-system-helpers",
146441          "version": "1.57",
146442          "licenses": [
146443            {
146444              "license": {
146445                "id": "BSD-3-Clause"
146446              }
146447            },
146448            {
146449              "license": {
146450                "id": "GPL-2.0-only"
146451              }
146452            },
146453            {
146454              "license": {
146455                "id": "GPL-2.0-or-later"
146456              }
146457            }
146458          ],
146459          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.57:*:*:*:*:*:*:*",
146460          "purl": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04",
146461          "swid": {
146462            "attachment": {}
146463          },
146464          "pedigree": {},
146465          "evidence": {},
146466          "signature": {
146467            "signature": {
146468              "publicKey": {}
146469            }
146470          },
146471          "modelCard": {
146472            "modelParameters": {
146473              "approach": {}
146474            },
146475            "quantitativeAnalysis": {
146476              "graphics": {}
146477            },
146478            "considerations": {}
146479          }
146480        },
146481        {
146482          "type": "library",
146483          "bom-ref": "pkg:deb/ubuntu/iperf@2.0.13+dfsg1-1build1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=52f5841ee19da566",
146484          "supplier": {},
146485          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146486          "name": "iperf",
146487          "version": "2.0.13+dfsg1-1build1",
146488          "licenses": [
146489            {
146490              "license": {
146491                "id": "BSD-3-Clause"
146492              }
146493            },
146494            {
146495              "license": {
146496                "name": "FSF-something"
146497              }
146498            },
146499            {
146500              "license": {
146501                "id": "GPL-2.0-only"
146502              }
146503            },
146504            {
146505              "license": {
146506                "id": "GPL-2.0-or-later"
146507              }
146508            },
146509            {
146510              "license": {
146511                "name": "GPL-2-WithACException"
146512              }
146513            },
146514            {
146515              "license": {
146516                "id": "GPL-3.0-only"
146517              }
146518            },
146519            {
146520              "license": {
146521                "name": "GPL-3-WithACException"
146522              }
146523            },
146524            {
146525              "license": {
146526                "id": "ISC"
146527              }
146528            },
146529            {
146530              "license": {
146531                "id": "LGPL-2.0-only"
146532              }
146533            },
146534            {
146535              "license": {
146536                "id": "LGPL-2.0-or-later"
146537              }
146538            },
146539            {
146540              "license": {
146541                "id": "MIT"
146542              }
146543            }
146544          ],
146545          "cpe": "cpe:2.3:a:iperf:iperf:2.0.13\\+dfsg1-1build1:*:*:*:*:*:*:*",
146546          "purl": "pkg:deb/ubuntu/iperf@2.0.13+dfsg1-1build1?arch=amd64\u0026distro=ubuntu-20.04",
146547          "swid": {
146548            "attachment": {}
146549          },
146550          "pedigree": {},
146551          "evidence": {},
146552          "signature": {
146553            "signature": {
146554              "publicKey": {}
146555            }
146556          },
146557          "modelCard": {
146558            "modelParameters": {
146559              "approach": {}
146560            },
146561            "quantitativeAnalysis": {
146562              "graphics": {}
146563            },
146564            "considerations": {}
146565          }
146566        },
146567        {
146568          "type": "library",
146569          "bom-ref": "pkg:deb/ubuntu/iproute2@5.5.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f4afda4dc550367c",
146570          "supplier": {},
146571          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146572          "name": "iproute2",
146573          "version": "5.5.0-1ubuntu1",
146574          "licenses": [
146575            {
146576              "license": {
146577                "id": "GPL-2.0-only"
146578              }
146579            }
146580          ],
146581          "cpe": "cpe:2.3:a:iproute2:iproute2:5.5.0-1ubuntu1:*:*:*:*:*:*:*",
146582          "purl": "pkg:deb/ubuntu/iproute2@5.5.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
146583          "swid": {
146584            "attachment": {}
146585          },
146586          "pedigree": {},
146587          "evidence": {},
146588          "signature": {
146589            "signature": {
146590              "publicKey": {}
146591            }
146592          },
146593          "modelCard": {
146594            "modelParameters": {
146595              "approach": {}
146596            },
146597            "quantitativeAnalysis": {
146598              "graphics": {}
146599            },
146600            "considerations": {}
146601          }
146602        },
146603        {
146604          "type": "library",
146605          "bom-ref": "pkg:deb/ubuntu/iputils-ping@3:20190709-3?arch=amd64\u0026upstream=iputils\u0026distro=ubuntu-20.04\u0026package-id=83f284daebd0969f",
146606          "supplier": {},
146607          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146608          "name": "iputils-ping",
146609          "version": "3:20190709-3",
146610          "licenses": [
146611            {
146612              "license": {
146613                "name": "GPL"
146614              }
146615            }
146616          ],
146617          "cpe": "cpe:2.3:a:iputils-ping:iputils-ping:3\\:20190709-3:*:*:*:*:*:*:*",
146618          "purl": "pkg:deb/ubuntu/iputils-ping@3:20190709-3?arch=amd64\u0026upstream=iputils\u0026distro=ubuntu-20.04",
146619          "swid": {
146620            "attachment": {}
146621          },
146622          "pedigree": {},
146623          "evidence": {},
146624          "signature": {
146625            "signature": {
146626              "publicKey": {}
146627            }
146628          },
146629          "modelCard": {
146630            "modelParameters": {
146631              "approach": {}
146632            },
146633            "quantitativeAnalysis": {
146634              "graphics": {}
146635            },
146636            "considerations": {}
146637          }
146638        },
146639        {
146640          "type": "library",
146641          "bom-ref": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a61b8b47cf58815b",
146642          "supplier": {},
146643          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146644          "name": "keyutils",
146645          "version": "1.6-6ubuntu1",
146646          "licenses": [
146647            {
146648              "license": {
146649                "id": "GPL-2.0-only"
146650              }
146651            },
146652            {
146653              "license": {
146654                "id": "GPL-2.0-or-later"
146655              }
146656            },
146657            {
146658              "license": {
146659                "id": "LGPL-2.0-only"
146660              }
146661            },
146662            {
146663              "license": {
146664                "id": "LGPL-2.0-or-later"
146665              }
146666            }
146667          ],
146668          "cpe": "cpe:2.3:a:keyutils:keyutils:1.6-6ubuntu1:*:*:*:*:*:*:*",
146669          "purl": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
146670          "swid": {
146671            "attachment": {}
146672          },
146673          "pedigree": {},
146674          "evidence": {},
146675          "signature": {
146676            "signature": {
146677              "publicKey": {}
146678            }
146679          },
146680          "modelCard": {
146681            "modelParameters": {
146682              "approach": {}
146683            },
146684            "quantitativeAnalysis": {
146685              "graphics": {}
146686            },
146687            "considerations": {}
146688          }
146689        },
146690        {
146691          "type": "library",
146692          "bom-ref": "pkg:deb/ubuntu/kmod@27-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e1280bc47493e972",
146693          "supplier": {},
146694          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146695          "name": "kmod",
146696          "version": "27-1ubuntu2",
146697          "licenses": [
146698            {
146699              "license": {
146700                "id": "GPL-2.0-only"
146701              }
146702            }
146703          ],
146704          "cpe": "cpe:2.3:a:kmod:kmod:27-1ubuntu2:*:*:*:*:*:*:*",
146705          "purl": "pkg:deb/ubuntu/kmod@27-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
146706          "swid": {
146707            "attachment": {}
146708          },
146709          "pedigree": {},
146710          "evidence": {},
146711          "signature": {
146712            "signature": {
146713              "publicKey": {}
146714            }
146715          },
146716          "modelCard": {
146717            "modelParameters": {
146718              "approach": {}
146719            },
146720            "quantitativeAnalysis": {
146721              "graphics": {}
146722            },
146723            "considerations": {}
146724          }
146725        },
146726        {
146727          "type": "library",
146728          "bom-ref": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=87ea48972fb4adab",
146729          "supplier": {},
146730          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146731          "name": "krb5-locales",
146732          "version": "1.17-6ubuntu4.1",
146733          "licenses": [
146734            {
146735              "license": {
146736                "id": "GPL-2.0-only"
146737              }
146738            }
146739          ],
146740          "cpe": "cpe:2.3:a:krb5-locales:krb5-locales:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
146741          "purl": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04",
146742          "swid": {
146743            "attachment": {}
146744          },
146745          "pedigree": {},
146746          "evidence": {},
146747          "signature": {
146748            "signature": {
146749              "publicKey": {}
146750            }
146751          },
146752          "modelCard": {
146753            "modelParameters": {
146754              "approach": {}
146755            },
146756            "quantitativeAnalysis": {
146757              "graphics": {}
146758            },
146759            "considerations": {}
146760          }
146761        },
146762        {
146763          "type": "library",
146764          "bom-ref": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04\u0026package-id=5cec2c2009596050",
146765          "supplier": {},
146766          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146767          "name": "libacl1",
146768          "version": "2.2.53-6",
146769          "licenses": [
146770            {
146771              "license": {
146772                "id": "GPL-2.0-only"
146773              }
146774            },
146775            {
146776              "license": {
146777                "id": "GPL-2.0-or-later"
146778              }
146779            },
146780            {
146781              "license": {
146782                "id": "LGPL-2.0-or-later"
146783              }
146784            },
146785            {
146786              "license": {
146787                "id": "LGPL-2.1-only"
146788              }
146789            }
146790          ],
146791          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-6:*:*:*:*:*:*:*",
146792          "purl": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04",
146793          "swid": {
146794            "attachment": {}
146795          },
146796          "pedigree": {},
146797          "evidence": {},
146798          "signature": {
146799            "signature": {
146800              "publicKey": {}
146801            }
146802          },
146803          "modelCard": {
146804            "modelParameters": {
146805              "approach": {}
146806            },
146807            "quantitativeAnalysis": {
146808              "graphics": {}
146809            },
146810            "considerations": {}
146811          }
146812        },
146813        {
146814          "type": "library",
146815          "bom-ref": "pkg:deb/ubuntu/libaio1@0.3.112-5?arch=amd64\u0026upstream=libaio\u0026distro=ubuntu-20.04\u0026package-id=f850a0a77c824c95",
146816          "supplier": {},
146817          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146818          "name": "libaio1",
146819          "version": "0.3.112-5",
146820          "licenses": [
146821            {
146822              "license": {
146823                "id": "LGPL-2.1-only"
146824              }
146825            },
146826            {
146827              "license": {
146828                "id": "LGPL-2.1-or-later"
146829              }
146830            }
146831          ],
146832          "cpe": "cpe:2.3:a:libaio1:libaio1:0.3.112-5:*:*:*:*:*:*:*",
146833          "purl": "pkg:deb/ubuntu/libaio1@0.3.112-5?arch=amd64\u0026upstream=libaio\u0026distro=ubuntu-20.04",
146834          "swid": {
146835            "attachment": {}
146836          },
146837          "pedigree": {},
146838          "evidence": {},
146839          "signature": {
146840            "signature": {
146841              "publicKey": {}
146842            }
146843          },
146844          "modelCard": {
146845            "modelParameters": {
146846              "approach": {}
146847            },
146848            "quantitativeAnalysis": {
146849              "graphics": {}
146850            },
146851            "considerations": {}
146852          }
146853        },
146854        {
146855          "type": "library",
146856          "bom-ref": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04\u0026package-id=864e143f4c606a6c",
146857          "supplier": {},
146858          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146859          "name": "libapt-pkg6.0",
146860          "version": "2.0.6",
146861          "licenses": [
146862            {
146863              "license": {
146864                "id": "GPL-2.0-only"
146865              }
146866            },
146867            {
146868              "license": {
146869                "name": "GPLv2+"
146870              }
146871            }
146872          ],
146873          "cpe": "cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.0.6:*:*:*:*:*:*:*",
146874          "purl": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04",
146875          "swid": {
146876            "attachment": {}
146877          },
146878          "pedigree": {},
146879          "evidence": {},
146880          "signature": {
146881            "signature": {
146882              "publicKey": {}
146883            }
146884          },
146885          "modelCard": {
146886            "modelParameters": {
146887              "approach": {}
146888            },
146889            "quantitativeAnalysis": {
146890              "graphics": {}
146891            },
146892            "considerations": {}
146893          }
146894        },
146895        {
146896          "type": "library",
146897          "bom-ref": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=915f8cf154d1b7ce",
146898          "supplier": {},
146899          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146900          "name": "libasn1-8-heimdal",
146901          "version": "7.7.0+dfsg-1ubuntu1",
146902          "licenses": [
146903            {
146904              "license": {
146905                "id": "BSD-3-Clause"
146906              }
146907            },
146908            {
146909              "license": {
146910                "id": "GPL-2.0-only"
146911              }
146912            },
146913            {
146914              "license": {
146915                "id": "GPL-2.0-or-later"
146916              }
146917            },
146918            {
146919              "license": {
146920                "name": "custom"
146921              }
146922            }
146923          ],
146924          "cpe": "cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
146925          "purl": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
146926          "swid": {
146927            "attachment": {}
146928          },
146929          "pedigree": {},
146930          "evidence": {},
146931          "signature": {
146932            "signature": {
146933              "publicKey": {}
146934            }
146935          },
146936          "modelCard": {
146937            "modelParameters": {
146938              "approach": {}
146939            },
146940            "quantitativeAnalysis": {
146941              "graphics": {}
146942            },
146943            "considerations": {}
146944          }
146945        },
146946        {
146947          "type": "library",
146948          "bom-ref": "pkg:deb/ubuntu/libatm1@1:2.5.1-4?arch=amd64\u0026upstream=linux-atm\u0026distro=ubuntu-20.04\u0026package-id=38fbc3dda7412f50",
146949          "supplier": {},
146950          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146951          "name": "libatm1",
146952          "version": "1:2.5.1-4",
146953          "licenses": [
146954            {
146955              "license": {
146956                "id": "GPL-2.0-only"
146957              }
146958            }
146959          ],
146960          "cpe": "cpe:2.3:a:libatm1:libatm1:1\\:2.5.1-4:*:*:*:*:*:*:*",
146961          "purl": "pkg:deb/ubuntu/libatm1@1:2.5.1-4?arch=amd64\u0026upstream=linux-atm\u0026distro=ubuntu-20.04",
146962          "swid": {
146963            "attachment": {}
146964          },
146965          "pedigree": {},
146966          "evidence": {},
146967          "signature": {
146968            "signature": {
146969              "publicKey": {}
146970            }
146971          },
146972          "modelCard": {
146973            "modelParameters": {
146974              "approach": {}
146975            },
146976            "quantitativeAnalysis": {
146977              "graphics": {}
146978            },
146979            "considerations": {}
146980          }
146981        },
146982        {
146983          "type": "library",
146984          "bom-ref": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04\u0026package-id=edf8dd62bd537bd5",
146985          "supplier": {},
146986          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
146987          "name": "libattr1",
146988          "version": "1:2.4.48-5",
146989          "licenses": [
146990            {
146991              "license": {
146992                "id": "GPL-2.0-only"
146993              }
146994            },
146995            {
146996              "license": {
146997                "id": "GPL-2.0-or-later"
146998              }
146999            },
147000            {
147001              "license": {
147002                "id": "LGPL-2.0-or-later"
147003              }
147004            },
147005            {
147006              "license": {
147007                "id": "LGPL-2.1-only"
147008              }
147009            }
147010          ],
147011          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-5:*:*:*:*:*:*:*",
147012          "purl": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04",
147013          "swid": {
147014            "attachment": {}
147015          },
147016          "pedigree": {},
147017          "evidence": {},
147018          "signature": {
147019            "signature": {
147020              "publicKey": {}
147021            }
147022          },
147023          "modelCard": {
147024            "modelParameters": {
147025              "approach": {}
147026            },
147027            "quantitativeAnalysis": {
147028              "graphics": {}
147029            },
147030            "considerations": {}
147031          }
147032        },
147033        {
147034          "type": "library",
147035          "bom-ref": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=4a463ab850d7c68c",
147036          "supplier": {},
147037          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147038          "name": "libaudit-common",
147039          "version": "1:2.8.5-2ubuntu6",
147040          "licenses": [
147041            {
147042              "license": {
147043                "id": "GPL-1.0-only"
147044              }
147045            },
147046            {
147047              "license": {
147048                "id": "GPL-2.0-only"
147049              }
147050            },
147051            {
147052              "license": {
147053                "id": "LGPL-2.1-only"
147054              }
147055            }
147056          ],
147057          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
147058          "purl": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04",
147059          "swid": {
147060            "attachment": {}
147061          },
147062          "pedigree": {},
147063          "evidence": {},
147064          "signature": {
147065            "signature": {
147066              "publicKey": {}
147067            }
147068          },
147069          "modelCard": {
147070            "modelParameters": {
147071              "approach": {}
147072            },
147073            "quantitativeAnalysis": {
147074              "graphics": {}
147075            },
147076            "considerations": {}
147077          }
147078        },
147079        {
147080          "type": "library",
147081          "bom-ref": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=be9537deb8db616e",
147082          "supplier": {},
147083          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147084          "name": "libaudit1",
147085          "version": "1:2.8.5-2ubuntu6",
147086          "licenses": [
147087            {
147088              "license": {
147089                "id": "GPL-1.0-only"
147090              }
147091            },
147092            {
147093              "license": {
147094                "id": "GPL-2.0-only"
147095              }
147096            },
147097            {
147098              "license": {
147099                "id": "LGPL-2.1-only"
147100              }
147101            }
147102          ],
147103          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
147104          "purl": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04",
147105          "swid": {
147106            "attachment": {}
147107          },
147108          "pedigree": {},
147109          "evidence": {},
147110          "signature": {
147111            "signature": {
147112              "publicKey": {}
147113            }
147114          },
147115          "modelCard": {
147116            "modelParameters": {
147117              "approach": {}
147118            },
147119            "quantitativeAnalysis": {
147120              "graphics": {}
147121            },
147122            "considerations": {}
147123          }
147124        },
147125        {
147126          "type": "library",
147127          "bom-ref": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=e1d6f2e998332d7d",
147128          "supplier": {},
147129          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147130          "name": "libblkid1",
147131          "version": "2.34-0.1ubuntu9.1",
147132          "licenses": [
147133            {
147134              "license": {
147135                "id": "BSD-2-Clause"
147136              }
147137            },
147138            {
147139              "license": {
147140                "id": "BSD-3-Clause"
147141              }
147142            },
147143            {
147144              "license": {
147145                "id": "BSD-4-Clause"
147146              }
147147            },
147148            {
147149              "license": {
147150                "id": "GPL-2.0-only"
147151              }
147152            },
147153            {
147154              "license": {
147155                "id": "GPL-2.0-or-later"
147156              }
147157            },
147158            {
147159              "license": {
147160                "id": "GPL-3.0-only"
147161              }
147162            },
147163            {
147164              "license": {
147165                "id": "GPL-3.0-or-later"
147166              }
147167            },
147168            {
147169              "license": {
147170                "name": "LGPL"
147171              }
147172            },
147173            {
147174              "license": {
147175                "id": "LGPL-2.0-only"
147176              }
147177            },
147178            {
147179              "license": {
147180                "id": "LGPL-2.0-or-later"
147181              }
147182            },
147183            {
147184              "license": {
147185                "id": "LGPL-2.1-only"
147186              }
147187            },
147188            {
147189              "license": {
147190                "id": "LGPL-2.1-or-later"
147191              }
147192            },
147193            {
147194              "license": {
147195                "id": "LGPL-3.0-only"
147196              }
147197            },
147198            {
147199              "license": {
147200                "id": "LGPL-3.0-or-later"
147201              }
147202            },
147203            {
147204              "license": {
147205                "id": "MIT"
147206              }
147207            },
147208            {
147209              "license": {
147210                "name": "public-domain"
147211              }
147212            }
147213          ],
147214          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
147215          "purl": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
147216          "swid": {
147217            "attachment": {}
147218          },
147219          "pedigree": {},
147220          "evidence": {},
147221          "signature": {
147222            "signature": {
147223              "publicKey": {}
147224            }
147225          },
147226          "modelCard": {
147227            "modelParameters": {
147228              "approach": {}
147229            },
147230            "quantitativeAnalysis": {
147231              "graphics": {}
147232            },
147233            "considerations": {}
147234          }
147235        },
147236        {
147237          "type": "library",
147238          "bom-ref": "pkg:deb/ubuntu/libboost-iostreams1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04\u0026package-id=c10288fd207d7ab9",
147239          "supplier": {},
147240          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147241          "name": "libboost-iostreams1.71.0",
147242          "version": "1.71.0-6ubuntu6",
147243          "licenses": [
147244            {
147245              "license": {
147246                "id": "Apache-2.0"
147247              }
147248            },
147249            {
147250              "license": {
147251                "name": "BSD2"
147252              }
147253            },
147254            {
147255              "license": {
147256                "name": "BSD3_DEShaw"
147257              }
147258            },
147259            {
147260              "license": {
147261                "name": "BSD3_Google"
147262              }
147263            },
147264            {
147265              "license": {
147266                "id": "BSL-1.0"
147267              }
147268            },
147269            {
147270              "license": {
147271                "name": "Caramel"
147272              }
147273            },
147274            {
147275              "license": {
147276                "name": "CrystalClear"
147277              }
147278            },
147279            {
147280              "license": {
147281                "name": "HP"
147282              }
147283            },
147284            {
147285              "license": {
147286                "id": "Jam"
147287              }
147288            },
147289            {
147290              "license": {
147291                "name": "Kempf"
147292              }
147293            },
147294            {
147295              "license": {
147296                "id": "MIT"
147297              }
147298            },
147299            {
147300              "license": {
147301                "name": "NIST"
147302              }
147303            },
147304            {
147305              "license": {
147306                "name": "OldBoost1"
147307              }
147308            },
147309            {
147310              "license": {
147311                "name": "OldBoost2"
147312              }
147313            },
147314            {
147315              "license": {
147316                "name": "OldBoost3"
147317              }
147318            },
147319            {
147320              "license": {
147321                "name": "Python"
147322              }
147323            },
147324            {
147325              "license": {
147326                "name": "SGI"
147327              }
147328            },
147329            {
147330              "license": {
147331                "name": "Spencer"
147332              }
147333            },
147334            {
147335              "license": {
147336                "id": "Zlib"
147337              }
147338            }
147339          ],
147340          "cpe": "cpe:2.3:a:libboost-iostreams1.71.0:libboost-iostreams1.71.0:1.71.0-6ubuntu6:*:*:*:*:*:*:*",
147341          "purl": "pkg:deb/ubuntu/libboost-iostreams1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04",
147342          "swid": {
147343            "attachment": {}
147344          },
147345          "pedigree": {},
147346          "evidence": {},
147347          "signature": {
147348            "signature": {
147349              "publicKey": {}
147350            }
147351          },
147352          "modelCard": {
147353            "modelParameters": {
147354              "approach": {}
147355            },
147356            "quantitativeAnalysis": {
147357              "graphics": {}
147358            },
147359            "considerations": {}
147360          }
147361        },
147362        {
147363          "type": "library",
147364          "bom-ref": "pkg:deb/ubuntu/libboost-thread1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04\u0026package-id=7bdbd4008b339d07",
147365          "supplier": {},
147366          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147367          "name": "libboost-thread1.71.0",
147368          "version": "1.71.0-6ubuntu6",
147369          "licenses": [
147370            {
147371              "license": {
147372                "id": "Apache-2.0"
147373              }
147374            },
147375            {
147376              "license": {
147377                "name": "BSD2"
147378              }
147379            },
147380            {
147381              "license": {
147382                "name": "BSD3_DEShaw"
147383              }
147384            },
147385            {
147386              "license": {
147387                "name": "BSD3_Google"
147388              }
147389            },
147390            {
147391              "license": {
147392                "id": "BSL-1.0"
147393              }
147394            },
147395            {
147396              "license": {
147397                "name": "Caramel"
147398              }
147399            },
147400            {
147401              "license": {
147402                "name": "CrystalClear"
147403              }
147404            },
147405            {
147406              "license": {
147407                "name": "HP"
147408              }
147409            },
147410            {
147411              "license": {
147412                "id": "Jam"
147413              }
147414            },
147415            {
147416              "license": {
147417                "name": "Kempf"
147418              }
147419            },
147420            {
147421              "license": {
147422                "id": "MIT"
147423              }
147424            },
147425            {
147426              "license": {
147427                "name": "NIST"
147428              }
147429            },
147430            {
147431              "license": {
147432                "name": "OldBoost1"
147433              }
147434            },
147435            {
147436              "license": {
147437                "name": "OldBoost2"
147438              }
147439            },
147440            {
147441              "license": {
147442                "name": "OldBoost3"
147443              }
147444            },
147445            {
147446              "license": {
147447                "name": "Python"
147448              }
147449            },
147450            {
147451              "license": {
147452                "name": "SGI"
147453              }
147454            },
147455            {
147456              "license": {
147457                "name": "Spencer"
147458              }
147459            },
147460            {
147461              "license": {
147462                "id": "Zlib"
147463              }
147464            }
147465          ],
147466          "cpe": "cpe:2.3:a:libboost-thread1.71.0:libboost-thread1.71.0:1.71.0-6ubuntu6:*:*:*:*:*:*:*",
147467          "purl": "pkg:deb/ubuntu/libboost-thread1.71.0@1.71.0-6ubuntu6?arch=amd64\u0026upstream=boost1.71\u0026distro=ubuntu-20.04",
147468          "swid": {
147469            "attachment": {}
147470          },
147471          "pedigree": {},
147472          "evidence": {},
147473          "signature": {
147474            "signature": {
147475              "publicKey": {}
147476            }
147477          },
147478          "modelCard": {
147479            "modelParameters": {
147480              "approach": {}
147481            },
147482            "quantitativeAnalysis": {
147483              "graphics": {}
147484            },
147485            "considerations": {}
147486          }
147487        },
147488        {
147489          "type": "library",
147490          "bom-ref": "pkg:deb/ubuntu/libbrotli1@1.0.7-6ubuntu0.1?arch=amd64\u0026upstream=brotli\u0026distro=ubuntu-20.04\u0026package-id=3cfc22417c2e74ac",
147491          "supplier": {},
147492          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147493          "name": "libbrotli1",
147494          "version": "1.0.7-6ubuntu0.1",
147495          "licenses": [
147496            {
147497              "license": {
147498                "id": "MIT"
147499              }
147500            }
147501          ],
147502          "cpe": "cpe:2.3:a:libbrotli1:libbrotli1:1.0.7-6ubuntu0.1:*:*:*:*:*:*:*",
147503          "purl": "pkg:deb/ubuntu/libbrotli1@1.0.7-6ubuntu0.1?arch=amd64\u0026upstream=brotli\u0026distro=ubuntu-20.04",
147504          "swid": {
147505            "attachment": {}
147506          },
147507          "pedigree": {},
147508          "evidence": {},
147509          "signature": {
147510            "signature": {
147511              "publicKey": {}
147512            }
147513          },
147514          "modelCard": {
147515            "modelParameters": {
147516              "approach": {}
147517            },
147518            "quantitativeAnalysis": {
147519              "graphics": {}
147520            },
147521            "considerations": {}
147522          }
147523        },
147524        {
147525          "type": "library",
147526          "bom-ref": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04\u0026package-id=88ee716d66a17869",
147527          "supplier": {},
147528          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147529          "name": "libbsd0",
147530          "version": "0.10.0-1",
147531          "licenses": [
147532            {
147533              "license": {
147534                "id": "BSD-2-Clause"
147535              }
147536            },
147537            {
147538              "license": {
147539                "id": "BSD-2-Clause"
147540              }
147541            },
147542            {
147543              "license": {
147544                "name": "BSD-2-clause-author"
147545              }
147546            },
147547            {
147548              "license": {
147549                "name": "BSD-2-clause-verbatim"
147550              }
147551            },
147552            {
147553              "license": {
147554                "id": "BSD-3-Clause"
147555              }
147556            },
147557            {
147558              "license": {
147559                "name": "BSD-3-clause-John-Birrell"
147560              }
147561            },
147562            {
147563              "license": {
147564                "name": "BSD-3-clause-Regents"
147565              }
147566            },
147567            {
147568              "license": {
147569                "name": "BSD-3-clause-author"
147570              }
147571            },
147572            {
147573              "license": {
147574                "name": "BSD-4-clause-Christopher-G-Demetriou"
147575              }
147576            },
147577            {
147578              "license": {
147579                "name": "BSD-4-clause-Niels-Provos"
147580              }
147581            },
147582            {
147583              "license": {
147584                "name": "BSD-5-clause-Peter-Wemm"
147585              }
147586            },
147587            {
147588              "license": {
147589                "id": "Beerware"
147590              }
147591            },
147592            {
147593              "license": {
147594                "name": "Expat"
147595              }
147596            },
147597            {
147598              "license": {
147599                "id": "ISC"
147600              }
147601            },
147602            {
147603              "license": {
147604                "name": "ISC-Original"
147605              }
147606            },
147607            {
147608              "license": {
147609                "name": "public-domain"
147610              }
147611            },
147612            {
147613              "license": {
147614                "name": "public-domain-Colin-Plumb"
147615              }
147616            }
147617          ],
147618          "cpe": "cpe:2.3:a:libbsd0:libbsd0:0.10.0-1:*:*:*:*:*:*:*",
147619          "purl": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04",
147620          "swid": {
147621            "attachment": {}
147622          },
147623          "pedigree": {},
147624          "evidence": {},
147625          "signature": {
147626            "signature": {
147627              "publicKey": {}
147628            }
147629          },
147630          "modelCard": {
147631            "modelParameters": {
147632              "approach": {}
147633            },
147634            "quantitativeAnalysis": {
147635              "graphics": {}
147636            },
147637            "considerations": {}
147638          }
147639        },
147640        {
147641          "type": "library",
147642          "bom-ref": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04\u0026package-id=fd8b0edf257b69b7",
147643          "supplier": {},
147644          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147645          "name": "libbz2-1.0",
147646          "version": "1.0.8-2",
147647          "licenses": [
147648            {
147649              "license": {
147650                "name": "BSD-variant"
147651              }
147652            },
147653            {
147654              "license": {
147655                "id": "GPL-2.0-only"
147656              }
147657            }
147658          ],
147659          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-2:*:*:*:*:*:*:*",
147660          "purl": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04",
147661          "swid": {
147662            "attachment": {}
147663          },
147664          "pedigree": {},
147665          "evidence": {},
147666          "signature": {
147667            "signature": {
147668              "publicKey": {}
147669            }
147670          },
147671          "modelCard": {
147672            "modelParameters": {
147673              "approach": {}
147674            },
147675            "quantitativeAnalysis": {
147676              "graphics": {}
147677            },
147678            "considerations": {}
147679          }
147680        },
147681        {
147682          "type": "library",
147683          "bom-ref": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=256facf7cbb95a65",
147684          "supplier": {},
147685          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147686          "name": "libc-bin",
147687          "version": "2.31-0ubuntu9.2",
147688          "licenses": [
147689            {
147690              "license": {
147691                "id": "GPL-2.0-only"
147692              }
147693            },
147694            {
147695              "license": {
147696                "id": "LGPL-2.1-only"
147697              }
147698            }
147699          ],
147700          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
147701          "purl": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
147702          "swid": {
147703            "attachment": {}
147704          },
147705          "pedigree": {},
147706          "evidence": {},
147707          "signature": {
147708            "signature": {
147709              "publicKey": {}
147710            }
147711          },
147712          "modelCard": {
147713            "modelParameters": {
147714              "approach": {}
147715            },
147716            "quantitativeAnalysis": {
147717              "graphics": {}
147718            },
147719            "considerations": {}
147720          }
147721        },
147722        {
147723          "type": "library",
147724          "bom-ref": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=2a96b94fa4db214",
147725          "supplier": {},
147726          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147727          "name": "libc6",
147728          "version": "2.31-0ubuntu9.2",
147729          "licenses": [
147730            {
147731              "license": {
147732                "id": "GPL-2.0-only"
147733              }
147734            },
147735            {
147736              "license": {
147737                "id": "LGPL-2.1-only"
147738              }
147739            }
147740          ],
147741          "cpe": "cpe:2.3:a:libc6:libc6:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
147742          "purl": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
147743          "swid": {
147744            "attachment": {}
147745          },
147746          "pedigree": {},
147747          "evidence": {},
147748          "signature": {
147749            "signature": {
147750              "publicKey": {}
147751            }
147752          },
147753          "modelCard": {
147754            "modelParameters": {
147755              "approach": {}
147756            },
147757            "quantitativeAnalysis": {
147758              "graphics": {}
147759            },
147760            "considerations": {}
147761          }
147762        },
147763        {
147764          "type": "library",
147765          "bom-ref": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04\u0026package-id=57ceb68462a99cb4",
147766          "supplier": {},
147767          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147768          "name": "libcap-ng0",
147769          "version": "0.7.9-2.1build1",
147770          "licenses": [
147771            {
147772              "license": {
147773                "id": "GPL-2.0-only"
147774              }
147775            },
147776            {
147777              "license": {
147778                "id": "GPL-3.0-only"
147779              }
147780            },
147781            {
147782              "license": {
147783                "id": "LGPL-2.1-only"
147784              }
147785            }
147786          ],
147787          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2.1build1:*:*:*:*:*:*:*",
147788          "purl": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04",
147789          "swid": {
147790            "attachment": {}
147791          },
147792          "pedigree": {},
147793          "evidence": {},
147794          "signature": {
147795            "signature": {
147796              "publicKey": {}
147797            }
147798          },
147799          "modelCard": {
147800            "modelParameters": {
147801              "approach": {}
147802            },
147803            "quantitativeAnalysis": {
147804              "graphics": {}
147805            },
147806            "considerations": {}
147807          }
147808        },
147809        {
147810          "type": "library",
147811          "bom-ref": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=682f3e304c127762",
147812          "supplier": {},
147813          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147814          "name": "libcap2",
147815          "version": "1:2.32-1",
147816          "licenses": [
147817            {
147818              "license": {
147819                "id": "BSD-3-Clause"
147820              }
147821            },
147822            {
147823              "license": {
147824                "id": "GPL-2.0-only"
147825              }
147826            },
147827            {
147828              "license": {
147829                "id": "GPL-2.0-or-later"
147830              }
147831            }
147832          ],
147833          "cpe": "cpe:2.3:a:libcap2:libcap2:1\\:2.32-1:*:*:*:*:*:*:*",
147834          "purl": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04",
147835          "swid": {
147836            "attachment": {}
147837          },
147838          "pedigree": {},
147839          "evidence": {},
147840          "signature": {
147841            "signature": {
147842              "publicKey": {}
147843            }
147844          },
147845          "modelCard": {
147846            "modelParameters": {
147847              "approach": {}
147848            },
147849            "quantitativeAnalysis": {
147850              "graphics": {}
147851            },
147852            "considerations": {}
147853          }
147854        },
147855        {
147856          "type": "library",
147857          "bom-ref": "pkg:deb/ubuntu/libcap2-bin@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04\u0026package-id=8f0ae2256856772c",
147858          "supplier": {},
147859          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147860          "name": "libcap2-bin",
147861          "version": "1:2.32-1",
147862          "licenses": [
147863            {
147864              "license": {
147865                "id": "BSD-3-Clause"
147866              }
147867            },
147868            {
147869              "license": {
147870                "id": "GPL-2.0-only"
147871              }
147872            },
147873            {
147874              "license": {
147875                "id": "GPL-2.0-or-later"
147876              }
147877            }
147878          ],
147879          "cpe": "cpe:2.3:a:libcap2-bin:libcap2-bin:1\\:2.32-1:*:*:*:*:*:*:*",
147880          "purl": "pkg:deb/ubuntu/libcap2-bin@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04",
147881          "swid": {
147882            "attachment": {}
147883          },
147884          "pedigree": {},
147885          "evidence": {},
147886          "signature": {
147887            "signature": {
147888              "publicKey": {}
147889            }
147890          },
147891          "modelCard": {
147892            "modelParameters": {
147893              "approach": {}
147894            },
147895            "quantitativeAnalysis": {
147896              "graphics": {}
147897            },
147898            "considerations": {}
147899          }
147900        },
147901        {
147902          "type": "library",
147903          "bom-ref": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=fbaeb4c3d5d0f976",
147904          "supplier": {},
147905          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147906          "name": "libcom-err2",
147907          "version": "1.45.5-2ubuntu1",
147908          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
147909          "purl": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
147910          "swid": {
147911            "attachment": {}
147912          },
147913          "pedigree": {},
147914          "evidence": {},
147915          "signature": {
147916            "signature": {
147917              "publicKey": {}
147918            }
147919          },
147920          "modelCard": {
147921            "modelParameters": {
147922              "approach": {}
147923            },
147924            "quantitativeAnalysis": {
147925              "graphics": {}
147926            },
147927            "considerations": {}
147928          }
147929        },
147930        {
147931          "type": "library",
147932          "bom-ref": "pkg:deb/ubuntu/libconfig-general-perl@2.63-1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=da9c7895b5630089",
147933          "supplier": {},
147934          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147935          "name": "libconfig-general-perl",
147936          "version": "2.63-1",
147937          "licenses": [
147938            {
147939              "license": {
147940                "name": "Artistic"
147941              }
147942            },
147943            {
147944              "license": {
147945                "id": "GPL-1.0-only"
147946              }
147947            },
147948            {
147949              "license": {
147950                "id": "GPL-1.0-or-later"
147951              }
147952            }
147953          ],
147954          "cpe": "cpe:2.3:a:libconfig-general-perl:libconfig-general-perl:2.63-1:*:*:*:*:*:*:*",
147955          "purl": "pkg:deb/ubuntu/libconfig-general-perl@2.63-1?arch=all\u0026distro=ubuntu-20.04",
147956          "swid": {
147957            "attachment": {}
147958          },
147959          "pedigree": {},
147960          "evidence": {},
147961          "signature": {
147962            "signature": {
147963              "publicKey": {}
147964            }
147965          },
147966          "modelCard": {
147967            "modelParameters": {
147968              "approach": {}
147969            },
147970            "quantitativeAnalysis": {
147971              "graphics": {}
147972            },
147973            "considerations": {}
147974          }
147975        },
147976        {
147977          "type": "library",
147978          "bom-ref": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04\u0026package-id=8a4302e2e7027353",
147979          "supplier": {},
147980          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
147981          "name": "libcrypt1",
147982          "version": "1:4.4.10-10ubuntu4",
147983          "cpe": "cpe:2.3:a:libcrypt1:libcrypt1:1\\:4.4.10-10ubuntu4:*:*:*:*:*:*:*",
147984          "purl": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04",
147985          "swid": {
147986            "attachment": {}
147987          },
147988          "pedigree": {},
147989          "evidence": {},
147990          "signature": {
147991            "signature": {
147992              "publicKey": {}
147993            }
147994          },
147995          "modelCard": {
147996            "modelParameters": {
147997              "approach": {}
147998            },
147999            "quantitativeAnalysis": {
148000              "graphics": {}
148001            },
148002            "considerations": {}
148003          }
148004        },
148005        {
148006          "type": "library",
148007          "bom-ref": "pkg:deb/ubuntu/libcurl3-gnutls@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04\u0026package-id=823f387cfa54f312",
148008          "supplier": {},
148009          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148010          "name": "libcurl3-gnutls",
148011          "version": "7.68.0-1ubuntu2.6",
148012          "licenses": [
148013            {
148014              "license": {
148015                "id": "BSD-3-Clause"
148016              }
148017            },
148018            {
148019              "license": {
148020                "id": "BSD-4-Clause"
148021              }
148022            },
148023            {
148024              "license": {
148025                "id": "ISC"
148026              }
148027            },
148028            {
148029              "license": {
148030                "id": "curl"
148031              }
148032            },
148033            {
148034              "license": {
148035                "name": "other"
148036              }
148037            },
148038            {
148039              "license": {
148040                "name": "public-domain"
148041              }
148042            }
148043          ],
148044          "cpe": "cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.68.0-1ubuntu2.6:*:*:*:*:*:*:*",
148045          "purl": "pkg:deb/ubuntu/libcurl3-gnutls@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04",
148046          "swid": {
148047            "attachment": {}
148048          },
148049          "pedigree": {},
148050          "evidence": {},
148051          "signature": {
148052            "signature": {
148053              "publicKey": {}
148054            }
148055          },
148056          "modelCard": {
148057            "modelParameters": {
148058              "approach": {}
148059            },
148060            "quantitativeAnalysis": {
148061              "graphics": {}
148062            },
148063            "considerations": {}
148064          }
148065        },
148066        {
148067          "type": "library",
148068          "bom-ref": "pkg:deb/ubuntu/libcurl4@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04\u0026package-id=c9dd9bae4f158cd3",
148069          "supplier": {},
148070          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148071          "name": "libcurl4",
148072          "version": "7.68.0-1ubuntu2.6",
148073          "licenses": [
148074            {
148075              "license": {
148076                "id": "BSD-3-Clause"
148077              }
148078            },
148079            {
148080              "license": {
148081                "id": "BSD-4-Clause"
148082              }
148083            },
148084            {
148085              "license": {
148086                "id": "ISC"
148087              }
148088            },
148089            {
148090              "license": {
148091                "id": "curl"
148092              }
148093            },
148094            {
148095              "license": {
148096                "name": "other"
148097              }
148098            },
148099            {
148100              "license": {
148101                "name": "public-domain"
148102              }
148103            }
148104          ],
148105          "cpe": "cpe:2.3:a:libcurl4:libcurl4:7.68.0-1ubuntu2.6:*:*:*:*:*:*:*",
148106          "purl": "pkg:deb/ubuntu/libcurl4@7.68.0-1ubuntu2.6?arch=amd64\u0026upstream=curl\u0026distro=ubuntu-20.04",
148107          "swid": {
148108            "attachment": {}
148109          },
148110          "pedigree": {},
148111          "evidence": {},
148112          "signature": {
148113            "signature": {
148114              "publicKey": {}
148115            }
148116          },
148117          "modelCard": {
148118            "modelParameters": {
148119              "approach": {}
148120            },
148121            "quantitativeAnalysis": {
148122              "graphics": {}
148123            },
148124            "considerations": {}
148125          }
148126        },
148127        {
148128          "type": "library",
148129          "bom-ref": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04\u0026package-id=bc84b4da0031640d",
148130          "supplier": {},
148131          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148132          "name": "libdb5.3",
148133          "version": "5.3.28+dfsg1-0.6ubuntu2",
148134          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.6ubuntu2:*:*:*:*:*:*:*",
148135          "purl": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04",
148136          "swid": {
148137            "attachment": {}
148138          },
148139          "pedigree": {},
148140          "evidence": {},
148141          "signature": {
148142            "signature": {
148143              "publicKey": {}
148144            }
148145          },
148146          "modelCard": {
148147            "modelParameters": {
148148              "approach": {}
148149            },
148150            "quantitativeAnalysis": {
148151              "graphics": {}
148152            },
148153            "considerations": {}
148154          }
148155        },
148156        {
148157          "type": "library",
148158          "bom-ref": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04\u0026package-id=78bbe40d9c2ef9b5",
148159          "supplier": {},
148160          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148161          "name": "libdebconfclient0",
148162          "version": "0.251ubuntu1",
148163          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.251ubuntu1:*:*:*:*:*:*:*",
148164          "purl": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04",
148165          "swid": {
148166            "attachment": {}
148167          },
148168          "pedigree": {},
148169          "evidence": {},
148170          "signature": {
148171            "signature": {
148172              "publicKey": {}
148173            }
148174          },
148175          "modelCard": {
148176            "modelParameters": {
148177              "approach": {}
148178            },
148179            "quantitativeAnalysis": {
148180              "graphics": {}
148181            },
148182            "considerations": {}
148183          }
148184        },
148185        {
148186          "type": "library",
148187          "bom-ref": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=30b70188951a65f0",
148188          "supplier": {},
148189          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148190          "name": "libdevmapper1.02.1",
148191          "version": "2:1.02.167-1ubuntu1",
148192          "licenses": [
148193            {
148194              "license": {
148195                "id": "BSD-2-Clause"
148196              }
148197            },
148198            {
148199              "license": {
148200                "id": "GPL-2.0-only"
148201              }
148202            },
148203            {
148204              "license": {
148205                "id": "GPL-2.0-only"
148206              }
148207            },
148208            {
148209              "license": {
148210                "id": "GPL-2.0-or-later"
148211              }
148212            },
148213            {
148214              "license": {
148215                "id": "LGPL-2.0-only"
148216              }
148217            },
148218            {
148219              "license": {
148220                "id": "LGPL-2.1-only"
148221              }
148222            }
148223          ],
148224          "cpe": "cpe:2.3:a:libdevmapper1.02.1:libdevmapper1.02.1:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
148225          "purl": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
148226          "swid": {
148227            "attachment": {}
148228          },
148229          "pedigree": {},
148230          "evidence": {},
148231          "signature": {
148232            "signature": {
148233              "publicKey": {}
148234            }
148235          },
148236          "modelCard": {
148237            "modelParameters": {
148238              "approach": {}
148239            },
148240            "quantitativeAnalysis": {
148241              "graphics": {}
148242            },
148243            "considerations": {}
148244          }
148245        },
148246        {
148247          "type": "library",
148248          "bom-ref": "pkg:deb/ubuntu/libelf1@0.176-1.1build1?arch=amd64\u0026upstream=elfutils\u0026distro=ubuntu-20.04\u0026package-id=316daaa294f5e8d8",
148249          "supplier": {},
148250          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148251          "name": "libelf1",
148252          "version": "0.176-1.1build1",
148253          "licenses": [
148254            {
148255              "license": {
148256                "id": "GPL-2.0-only"
148257              }
148258            },
148259            {
148260              "license": {
148261                "id": "GPL-3.0-only"
148262              }
148263            },
148264            {
148265              "license": {
148266                "name": "LGPL-"
148267              }
148268            }
148269          ],
148270          "cpe": "cpe:2.3:a:libelf1:libelf1:0.176-1.1build1:*:*:*:*:*:*:*",
148271          "purl": "pkg:deb/ubuntu/libelf1@0.176-1.1build1?arch=amd64\u0026upstream=elfutils\u0026distro=ubuntu-20.04",
148272          "swid": {
148273            "attachment": {}
148274          },
148275          "pedigree": {},
148276          "evidence": {},
148277          "signature": {
148278            "signature": {
148279              "publicKey": {}
148280            }
148281          },
148282          "modelCard": {
148283            "modelParameters": {
148284              "approach": {}
148285            },
148286            "quantitativeAnalysis": {
148287              "graphics": {}
148288            },
148289            "considerations": {}
148290          }
148291        },
148292        {
148293          "type": "library",
148294          "bom-ref": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04\u0026package-id=6b93a7dccfeb49e0",
148295          "supplier": {},
148296          "publisher": "Balint Reczey \u003crbalint@ubuntu.com\u003e",
148297          "name": "libevent-2.1-7",
148298          "version": "2.1.11-stable-1",
148299          "licenses": [
148300            {
148301              "license": {
148302                "id": "BSD-2-Clause"
148303              }
148304            },
148305            {
148306              "license": {
148307                "name": "BSD-3-Clause~Kitware"
148308              }
148309            },
148310            {
148311              "license": {
148312                "id": "BSD-3-Clause"
148313              }
148314            },
148315            {
148316              "license": {
148317                "name": "BSL"
148318              }
148319            },
148320            {
148321              "license": {
148322                "name": "Expat"
148323              }
148324            },
148325            {
148326              "license": {
148327                "id": "FSFUL"
148328              }
148329            },
148330            {
148331              "license": {
148332                "id": "FSFULLR"
148333              }
148334            },
148335            {
148336              "license": {
148337                "name": "FSFULLR-No-Warranty"
148338              }
148339            },
148340            {
148341              "license": {
148342                "id": "GPL-2.0-only"
148343              }
148344            },
148345            {
148346              "license": {
148347                "id": "GPL-2.0-or-later"
148348              }
148349            },
148350            {
148351              "license": {
148352                "id": "GPL-3.0-only"
148353              }
148354            },
148355            {
148356              "license": {
148357                "id": "GPL-3.0-or-later"
148358              }
148359            },
148360            {
148361              "license": {
148362                "id": "ISC"
148363              }
148364            },
148365            {
148366              "license": {
148367                "id": "curl"
148368              }
148369            }
148370          ],
148371          "cpe": "cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.11-stable-1:*:*:*:*:*:*:*",
148372          "purl": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04",
148373          "swid": {
148374            "attachment": {}
148375          },
148376          "pedigree": {},
148377          "evidence": {},
148378          "signature": {
148379            "signature": {
148380              "publicKey": {}
148381            }
148382          },
148383          "modelCard": {
148384            "modelParameters": {
148385              "approach": {}
148386            },
148387            "quantitativeAnalysis": {
148388              "graphics": {}
148389            },
148390            "considerations": {}
148391          }
148392        },
148393        {
148394          "type": "library",
148395          "bom-ref": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04\u0026package-id=f3ac75cd161f13c6",
148396          "supplier": {},
148397          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148398          "name": "libexpat1",
148399          "version": "2.2.9-1build1",
148400          "licenses": [
148401            {
148402              "license": {
148403                "id": "MIT"
148404              }
148405            }
148406          ],
148407          "cpe": "cpe:2.3:a:libexpat1:libexpat1:2.2.9-1build1:*:*:*:*:*:*:*",
148408          "purl": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04",
148409          "swid": {
148410            "attachment": {}
148411          },
148412          "pedigree": {},
148413          "evidence": {},
148414          "signature": {
148415            "signature": {
148416              "publicKey": {}
148417            }
148418          },
148419          "modelCard": {
148420            "modelParameters": {
148421              "approach": {}
148422            },
148423            "quantitativeAnalysis": {
148424              "graphics": {}
148425            },
148426            "considerations": {}
148427          }
148428        },
148429        {
148430          "type": "library",
148431          "bom-ref": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=ec6113f55e73d1fd",
148432          "supplier": {},
148433          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148434          "name": "libext2fs2",
148435          "version": "1.45.5-2ubuntu1",
148436          "licenses": [
148437            {
148438              "license": {
148439                "id": "GPL-2.0-only"
148440              }
148441            },
148442            {
148443              "license": {
148444                "id": "LGPL-2.0-only"
148445              }
148446            }
148447          ],
148448          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
148449          "purl": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
148450          "swid": {
148451            "attachment": {}
148452          },
148453          "pedigree": {},
148454          "evidence": {},
148455          "signature": {
148456            "signature": {
148457              "publicKey": {}
148458            }
148459          },
148460          "modelCard": {
148461            "modelParameters": {
148462              "approach": {}
148463            },
148464            "quantitativeAnalysis": {
148465              "graphics": {}
148466            },
148467            "considerations": {}
148468          }
148469        },
148470        {
148471          "type": "library",
148472          "bom-ref": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=486ce61647644619",
148473          "supplier": {},
148474          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148475          "name": "libfdisk1",
148476          "version": "2.34-0.1ubuntu9.1",
148477          "licenses": [
148478            {
148479              "license": {
148480                "id": "BSD-2-Clause"
148481              }
148482            },
148483            {
148484              "license": {
148485                "id": "BSD-3-Clause"
148486              }
148487            },
148488            {
148489              "license": {
148490                "id": "BSD-4-Clause"
148491              }
148492            },
148493            {
148494              "license": {
148495                "id": "GPL-2.0-only"
148496              }
148497            },
148498            {
148499              "license": {
148500                "id": "GPL-2.0-or-later"
148501              }
148502            },
148503            {
148504              "license": {
148505                "id": "GPL-3.0-only"
148506              }
148507            },
148508            {
148509              "license": {
148510                "id": "GPL-3.0-or-later"
148511              }
148512            },
148513            {
148514              "license": {
148515                "name": "LGPL"
148516              }
148517            },
148518            {
148519              "license": {
148520                "id": "LGPL-2.0-only"
148521              }
148522            },
148523            {
148524              "license": {
148525                "id": "LGPL-2.0-or-later"
148526              }
148527            },
148528            {
148529              "license": {
148530                "id": "LGPL-2.1-only"
148531              }
148532            },
148533            {
148534              "license": {
148535                "id": "LGPL-2.1-or-later"
148536              }
148537            },
148538            {
148539              "license": {
148540                "id": "LGPL-3.0-only"
148541              }
148542            },
148543            {
148544              "license": {
148545                "id": "LGPL-3.0-or-later"
148546              }
148547            },
148548            {
148549              "license": {
148550                "id": "MIT"
148551              }
148552            },
148553            {
148554              "license": {
148555                "name": "public-domain"
148556              }
148557            }
148558          ],
148559          "cpe": "cpe:2.3:a:libfdisk1:libfdisk1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
148560          "purl": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
148561          "swid": {
148562            "attachment": {}
148563          },
148564          "pedigree": {},
148565          "evidence": {},
148566          "signature": {
148567            "signature": {
148568              "publicKey": {}
148569            }
148570          },
148571          "modelCard": {
148572            "modelParameters": {
148573              "approach": {}
148574            },
148575            "quantitativeAnalysis": {
148576              "graphics": {}
148577            },
148578            "considerations": {}
148579          }
148580        },
148581        {
148582          "type": "library",
148583          "bom-ref": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04\u0026package-id=b43b799d45da9d97",
148584          "supplier": {},
148585          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148586          "name": "libffi7",
148587          "version": "3.3-4",
148588          "licenses": [
148589            {
148590              "license": {
148591                "name": "GPL"
148592              }
148593            }
148594          ],
148595          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-4:*:*:*:*:*:*:*",
148596          "purl": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04",
148597          "swid": {
148598            "attachment": {}
148599          },
148600          "pedigree": {},
148601          "evidence": {},
148602          "signature": {
148603            "signature": {
148604              "publicKey": {}
148605            }
148606          },
148607          "modelCard": {
148608            "modelParameters": {
148609              "approach": {}
148610            },
148611            "quantitativeAnalysis": {
148612              "graphics": {}
148613            },
148614            "considerations": {}
148615          }
148616        },
148617        {
148618          "type": "library",
148619          "bom-ref": "pkg:deb/ubuntu/libfuse2@2.9.9-3?arch=amd64\u0026upstream=fuse\u0026distro=ubuntu-20.04\u0026package-id=cb74b48e2705f805",
148620          "supplier": {},
148621          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148622          "name": "libfuse2",
148623          "version": "2.9.9-3",
148624          "licenses": [
148625            {
148626              "license": {
148627                "id": "GPL-2.0-only"
148628              }
148629            },
148630            {
148631              "license": {
148632                "id": "GPL-2.0-or-later"
148633              }
148634            },
148635            {
148636              "license": {
148637                "id": "LGPL-2.0-only"
148638              }
148639            }
148640          ],
148641          "cpe": "cpe:2.3:a:libfuse2:libfuse2:2.9.9-3:*:*:*:*:*:*:*",
148642          "purl": "pkg:deb/ubuntu/libfuse2@2.9.9-3?arch=amd64\u0026upstream=fuse\u0026distro=ubuntu-20.04",
148643          "swid": {
148644            "attachment": {}
148645          },
148646          "pedigree": {},
148647          "evidence": {},
148648          "signature": {
148649            "signature": {
148650              "publicKey": {}
148651            }
148652          },
148653          "modelCard": {
148654            "modelParameters": {
148655              "approach": {}
148656            },
148657            "quantitativeAnalysis": {
148658              "graphics": {}
148659            },
148660            "considerations": {}
148661          }
148662        },
148663        {
148664          "type": "library",
148665          "bom-ref": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=f98ce69fd9e55bb8",
148666          "supplier": {},
148667          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148668          "name": "libgcc-s1",
148669          "version": "10.3.0-1ubuntu1~20.04",
148670          "licenses": [
148671            {
148672              "license": {
148673                "name": "Artistic"
148674              }
148675            },
148676            {
148677              "license": {
148678                "id": "GFDL-1.2-only"
148679              }
148680            },
148681            {
148682              "license": {
148683                "name": "GPL"
148684              }
148685            },
148686            {
148687              "license": {
148688                "id": "GPL-2.0-only"
148689              }
148690            },
148691            {
148692              "license": {
148693                "id": "GPL-3.0-only"
148694              }
148695            },
148696            {
148697              "license": {
148698                "name": "LGPL"
148699              }
148700            }
148701          ],
148702          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
148703          "purl": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
148704          "swid": {
148705            "attachment": {}
148706          },
148707          "pedigree": {},
148708          "evidence": {},
148709          "signature": {
148710            "signature": {
148711              "publicKey": {}
148712            }
148713          },
148714          "modelCard": {
148715            "modelParameters": {
148716              "approach": {}
148717            },
148718            "quantitativeAnalysis": {
148719              "graphics": {}
148720            },
148721            "considerations": {}
148722          }
148723        },
148724        {
148725          "type": "library",
148726          "bom-ref": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=c8a43aa5b28727a1",
148727          "supplier": {},
148728          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148729          "name": "libgcrypt20",
148730          "version": "1.8.5-5ubuntu1",
148731          "licenses": [
148732            {
148733              "license": {
148734                "id": "GPL-2.0-only"
148735              }
148736            },
148737            {
148738              "license": {
148739                "name": "LGPL"
148740              }
148741            }
148742          ],
148743          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.5-5ubuntu1:*:*:*:*:*:*:*",
148744          "purl": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
148745          "swid": {
148746            "attachment": {}
148747          },
148748          "pedigree": {},
148749          "evidence": {},
148750          "signature": {
148751            "signature": {
148752              "publicKey": {}
148753            }
148754          },
148755          "modelCard": {
148756            "modelParameters": {
148757              "approach": {}
148758            },
148759            "quantitativeAnalysis": {
148760              "graphics": {}
148761            },
148762            "considerations": {}
148763          }
148764        },
148765        {
148766          "type": "library",
148767          "bom-ref": "pkg:deb/ubuntu/libgdbm-compat4@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04\u0026package-id=216492c4d03e5a3b",
148768          "supplier": {},
148769          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148770          "name": "libgdbm-compat4",
148771          "version": "1.18.1-5",
148772          "licenses": [
148773            {
148774              "license": {
148775                "name": "GFDL-NIV-1.3+"
148776              }
148777            },
148778            {
148779              "license": {
148780                "id": "GPL-2.0-only"
148781              }
148782            },
148783            {
148784              "license": {
148785                "id": "GPL-2.0-or-later"
148786              }
148787            },
148788            {
148789              "license": {
148790                "id": "GPL-3.0-only"
148791              }
148792            },
148793            {
148794              "license": {
148795                "id": "GPL-3.0-or-later"
148796              }
148797            }
148798          ],
148799          "cpe": "cpe:2.3:a:libgdbm-compat4:libgdbm-compat4:1.18.1-5:*:*:*:*:*:*:*",
148800          "purl": "pkg:deb/ubuntu/libgdbm-compat4@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04",
148801          "swid": {
148802            "attachment": {}
148803          },
148804          "pedigree": {},
148805          "evidence": {},
148806          "signature": {
148807            "signature": {
148808              "publicKey": {}
148809            }
148810          },
148811          "modelCard": {
148812            "modelParameters": {
148813              "approach": {}
148814            },
148815            "quantitativeAnalysis": {
148816              "graphics": {}
148817            },
148818            "considerations": {}
148819          }
148820        },
148821        {
148822          "type": "library",
148823          "bom-ref": "pkg:deb/ubuntu/libgdbm6@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04\u0026package-id=e7baa5d6d4faa647",
148824          "supplier": {},
148825          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148826          "name": "libgdbm6",
148827          "version": "1.18.1-5",
148828          "licenses": [
148829            {
148830              "license": {
148831                "name": "GFDL-NIV-1.3+"
148832              }
148833            },
148834            {
148835              "license": {
148836                "id": "GPL-2.0-only"
148837              }
148838            },
148839            {
148840              "license": {
148841                "id": "GPL-2.0-or-later"
148842              }
148843            },
148844            {
148845              "license": {
148846                "id": "GPL-3.0-only"
148847              }
148848            },
148849            {
148850              "license": {
148851                "id": "GPL-3.0-or-later"
148852              }
148853            }
148854          ],
148855          "cpe": "cpe:2.3:a:libgdbm6:libgdbm6:1.18.1-5:*:*:*:*:*:*:*",
148856          "purl": "pkg:deb/ubuntu/libgdbm6@1.18.1-5?arch=amd64\u0026upstream=gdbm\u0026distro=ubuntu-20.04",
148857          "swid": {
148858            "attachment": {}
148859          },
148860          "pedigree": {},
148861          "evidence": {},
148862          "signature": {
148863            "signature": {
148864              "publicKey": {}
148865            }
148866          },
148867          "modelCard": {
148868            "modelParameters": {
148869              "approach": {}
148870            },
148871            "quantitativeAnalysis": {
148872              "graphics": {}
148873            },
148874            "considerations": {}
148875          }
148876        },
148877        {
148878          "type": "library",
148879          "bom-ref": "pkg:deb/ubuntu/libglib2.0-0@2.64.6-1~ubuntu20.04.4?arch=amd64\u0026upstream=glib2.0\u0026distro=ubuntu-20.04\u0026package-id=173f54b9a4ea5bbf",
148880          "supplier": {},
148881          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148882          "name": "libglib2.0-0",
148883          "version": "2.64.6-1~ubuntu20.04.4",
148884          "licenses": [
148885            {
148886              "license": {
148887                "name": "Expat"
148888              }
148889            },
148890            {
148891              "license": {
148892                "id": "GPL-2.0-or-later"
148893              }
148894            },
148895            {
148896              "license": {
148897                "name": "LGPL"
148898              }
148899            }
148900          ],
148901          "cpe": "cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.64.6-1\\~ubuntu20.04.4:*:*:*:*:*:*:*",
148902          "purl": "pkg:deb/ubuntu/libglib2.0-0@2.64.6-1~ubuntu20.04.4?arch=amd64\u0026upstream=glib2.0\u0026distro=ubuntu-20.04",
148903          "swid": {
148904            "attachment": {}
148905          },
148906          "pedigree": {},
148907          "evidence": {},
148908          "signature": {
148909            "signature": {
148910              "publicKey": {}
148911            }
148912          },
148913          "modelCard": {
148914            "modelParameters": {
148915              "approach": {}
148916            },
148917            "quantitativeAnalysis": {
148918              "graphics": {}
148919            },
148920            "considerations": {}
148921          }
148922        },
148923        {
148924          "type": "library",
148925          "bom-ref": "pkg:deb/ubuntu/libglib2.0-data@2.64.6-1~ubuntu20.04.4?arch=all\u0026upstream=glib2.0\u0026distro=ubuntu-20.04\u0026package-id=84c7d5b71baf104a",
148926          "supplier": {},
148927          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148928          "name": "libglib2.0-data",
148929          "version": "2.64.6-1~ubuntu20.04.4",
148930          "licenses": [
148931            {
148932              "license": {
148933                "name": "Expat"
148934              }
148935            },
148936            {
148937              "license": {
148938                "id": "GPL-2.0-or-later"
148939              }
148940            },
148941            {
148942              "license": {
148943                "name": "LGPL"
148944              }
148945            }
148946          ],
148947          "cpe": "cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.64.6-1\\~ubuntu20.04.4:*:*:*:*:*:*:*",
148948          "purl": "pkg:deb/ubuntu/libglib2.0-data@2.64.6-1~ubuntu20.04.4?arch=all\u0026upstream=glib2.0\u0026distro=ubuntu-20.04",
148949          "swid": {
148950            "attachment": {}
148951          },
148952          "pedigree": {},
148953          "evidence": {},
148954          "signature": {
148955            "signature": {
148956              "publicKey": {}
148957            }
148958          },
148959          "modelCard": {
148960            "modelParameters": {
148961              "approach": {}
148962            },
148963            "quantitativeAnalysis": {
148964              "graphics": {}
148965            },
148966            "considerations": {}
148967          }
148968        },
148969        {
148970          "type": "library",
148971          "bom-ref": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04\u0026package-id=40fc269dcb8b3369",
148972          "supplier": {},
148973          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
148974          "name": "libgmp10",
148975          "version": "2:6.2.0+dfsg-4",
148976          "licenses": [
148977            {
148978              "license": {
148979                "name": "GPL"
148980              }
148981            },
148982            {
148983              "license": {
148984                "id": "GPL-2.0-only"
148985              }
148986            },
148987            {
148988              "license": {
148989                "id": "GPL-3.0-only"
148990              }
148991            },
148992            {
148993              "license": {
148994                "id": "LGPL-3.0-only"
148995              }
148996            }
148997          ],
148998          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.0\\+dfsg-4:*:*:*:*:*:*:*",
148999          "purl": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04",
149000          "swid": {
149001            "attachment": {}
149002          },
149003          "pedigree": {},
149004          "evidence": {},
149005          "signature": {
149006            "signature": {
149007              "publicKey": {}
149008            }
149009          },
149010          "modelCard": {
149011            "modelParameters": {
149012              "approach": {}
149013            },
149014            "quantitativeAnalysis": {
149015              "graphics": {}
149016            },
149017            "considerations": {}
149018          }
149019        },
149020        {
149021          "type": "library",
149022          "bom-ref": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.3?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04\u0026package-id=209bb478086322a1",
149023          "supplier": {},
149024          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149025          "name": "libgnutls30",
149026          "version": "3.6.13-2ubuntu1.3",
149027          "licenses": [
149028            {
149029              "license": {
149030                "id": "Apache-2.0"
149031              }
149032            },
149033            {
149034              "license": {
149035                "id": "BSD-3-Clause"
149036              }
149037            },
149038            {
149039              "license": {
149040                "name": "CC0"
149041              }
149042            },
149043            {
149044              "license": {
149045                "name": "Expat"
149046              }
149047            },
149048            {
149049              "license": {
149050                "id": "GFDL-1.3-only"
149051              }
149052            },
149053            {
149054              "license": {
149055                "name": "GPL"
149056              }
149057            },
149058            {
149059              "license": {
149060                "id": "GPL-3.0-only"
149061              }
149062            },
149063            {
149064              "license": {
149065                "name": "GPLv3+"
149066              }
149067            },
149068            {
149069              "license": {
149070                "name": "LGPL"
149071              }
149072            },
149073            {
149074              "license": {
149075                "id": "LGPL-3.0-only"
149076              }
149077            },
149078            {
149079              "license": {
149080                "name": "LGPLv2.1+"
149081              }
149082            },
149083            {
149084              "license": {
149085                "name": "LGPLv3+_or_GPLv2+"
149086              }
149087            },
149088            {
149089              "license": {
149090                "name": "The"
149091              }
149092            }
149093          ],
149094          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.13-2ubuntu1.3:*:*:*:*:*:*:*",
149095          "purl": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.3?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04",
149096          "swid": {
149097            "attachment": {}
149098          },
149099          "pedigree": {},
149100          "evidence": {},
149101          "signature": {
149102            "signature": {
149103              "publicKey": {}
149104            }
149105          },
149106          "modelCard": {
149107            "modelParameters": {
149108              "approach": {}
149109            },
149110            "quantitativeAnalysis": {
149111              "graphics": {}
149112            },
149113            "considerations": {}
149114          }
149115        },
149116        {
149117          "type": "library",
149118          "bom-ref": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04\u0026package-id=7490f76da775c6e",
149119          "supplier": {},
149120          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149121          "name": "libgnutls30",
149122          "version": "3.6.13-2ubuntu1.6",
149123          "licenses": [
149124            {
149125              "license": {
149126                "id": "Apache-2.0"
149127              }
149128            },
149129            {
149130              "license": {
149131                "id": "BSD-3-Clause"
149132              }
149133            },
149134            {
149135              "license": {
149136                "name": "CC0"
149137              }
149138            },
149139            {
149140              "license": {
149141                "name": "Expat"
149142              }
149143            },
149144            {
149145              "license": {
149146                "id": "GFDL-1.3-only"
149147              }
149148            },
149149            {
149150              "license": {
149151                "name": "GPL"
149152              }
149153            },
149154            {
149155              "license": {
149156                "id": "GPL-3.0-only"
149157              }
149158            },
149159            {
149160              "license": {
149161                "name": "GPLv3+"
149162              }
149163            },
149164            {
149165              "license": {
149166                "name": "LGPL"
149167              }
149168            },
149169            {
149170              "license": {
149171                "id": "LGPL-3.0-only"
149172              }
149173            },
149174            {
149175              "license": {
149176                "name": "LGPLv2.1+"
149177              }
149178            },
149179            {
149180              "license": {
149181                "name": "LGPLv3+_or_GPLv2+"
149182              }
149183            },
149184            {
149185              "license": {
149186                "name": "The"
149187              }
149188            }
149189          ],
149190          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.13-2ubuntu1.6:*:*:*:*:*:*:*",
149191          "purl": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04",
149192          "swid": {
149193            "attachment": {}
149194          },
149195          "pedigree": {},
149196          "evidence": {},
149197          "signature": {
149198            "signature": {
149199              "publicKey": {}
149200            }
149201          },
149202          "modelCard": {
149203            "modelParameters": {
149204              "approach": {}
149205            },
149206            "quantitativeAnalysis": {
149207              "graphics": {}
149208            },
149209            "considerations": {}
149210          }
149211        },
149212        {
149213          "type": "library",
149214          "bom-ref": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04\u0026package-id=37ef62d87edfe03",
149215          "supplier": {},
149216          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149217          "name": "libgpg-error0",
149218          "version": "1.37-1",
149219          "licenses": [
149220            {
149221              "license": {
149222                "id": "BSD-3-Clause"
149223              }
149224            },
149225            {
149226              "license": {
149227                "id": "GPL-3.0-only"
149228              }
149229            },
149230            {
149231              "license": {
149232                "id": "GPL-3.0-or-later"
149233              }
149234            },
149235            {
149236              "license": {
149237                "id": "LGPL-2.1-only"
149238              }
149239            },
149240            {
149241              "license": {
149242                "id": "LGPL-2.1-or-later"
149243              }
149244            },
149245            {
149246              "license": {
149247                "name": "g10-permissive"
149248              }
149249            }
149250          ],
149251          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.37-1:*:*:*:*:*:*:*",
149252          "purl": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04",
149253          "swid": {
149254            "attachment": {}
149255          },
149256          "pedigree": {},
149257          "evidence": {},
149258          "signature": {
149259            "signature": {
149260              "publicKey": {}
149261            }
149262          },
149263          "modelCard": {
149264            "modelParameters": {
149265              "approach": {}
149266            },
149267            "quantitativeAnalysis": {
149268              "graphics": {}
149269            },
149270            "considerations": {}
149271          }
149272        },
149273        {
149274          "type": "library",
149275          "bom-ref": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=443eafe2785f5a4c",
149276          "supplier": {},
149277          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149278          "name": "libgssapi-krb5-2",
149279          "version": "1.17-6ubuntu4.1",
149280          "licenses": [
149281            {
149282              "license": {
149283                "id": "GPL-2.0-only"
149284              }
149285            }
149286          ],
149287          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
149288          "purl": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
149289          "swid": {
149290            "attachment": {}
149291          },
149292          "pedigree": {},
149293          "evidence": {},
149294          "signature": {
149295            "signature": {
149296              "publicKey": {}
149297            }
149298          },
149299          "modelCard": {
149300            "modelParameters": {
149301              "approach": {}
149302            },
149303            "quantitativeAnalysis": {
149304              "graphics": {}
149305            },
149306            "considerations": {}
149307          }
149308        },
149309        {
149310          "type": "library",
149311          "bom-ref": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=17a37cca2446b615",
149312          "supplier": {},
149313          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149314          "name": "libgssapi3-heimdal",
149315          "version": "7.7.0+dfsg-1ubuntu1",
149316          "licenses": [
149317            {
149318              "license": {
149319                "id": "BSD-3-Clause"
149320              }
149321            },
149322            {
149323              "license": {
149324                "id": "GPL-2.0-only"
149325              }
149326            },
149327            {
149328              "license": {
149329                "id": "GPL-2.0-or-later"
149330              }
149331            },
149332            {
149333              "license": {
149334                "name": "custom"
149335              }
149336            }
149337          ],
149338          "cpe": "cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
149339          "purl": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
149340          "swid": {
149341            "attachment": {}
149342          },
149343          "pedigree": {},
149344          "evidence": {},
149345          "signature": {
149346            "signature": {
149347              "publicKey": {}
149348            }
149349          },
149350          "modelCard": {
149351            "modelParameters": {
149352              "approach": {}
149353            },
149354            "quantitativeAnalysis": {
149355              "graphics": {}
149356            },
149357            "considerations": {}
149358          }
149359        },
149360        {
149361          "type": "library",
149362          "bom-ref": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=98098d582df76b44",
149363          "supplier": {},
149364          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149365          "name": "libhcrypto4-heimdal",
149366          "version": "7.7.0+dfsg-1ubuntu1",
149367          "licenses": [
149368            {
149369              "license": {
149370                "id": "BSD-3-Clause"
149371              }
149372            },
149373            {
149374              "license": {
149375                "id": "GPL-2.0-only"
149376              }
149377            },
149378            {
149379              "license": {
149380                "id": "GPL-2.0-or-later"
149381              }
149382            },
149383            {
149384              "license": {
149385                "name": "custom"
149386              }
149387            }
149388          ],
149389          "cpe": "cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
149390          "purl": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
149391          "swid": {
149392            "attachment": {}
149393          },
149394          "pedigree": {},
149395          "evidence": {},
149396          "signature": {
149397            "signature": {
149398              "publicKey": {}
149399            }
149400          },
149401          "modelCard": {
149402            "modelParameters": {
149403              "approach": {}
149404            },
149405            "quantitativeAnalysis": {
149406              "graphics": {}
149407            },
149408            "considerations": {}
149409          }
149410        },
149411        {
149412          "type": "library",
149413          "bom-ref": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=f8dfc9a84c337835",
149414          "supplier": {},
149415          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149416          "name": "libheimbase1-heimdal",
149417          "version": "7.7.0+dfsg-1ubuntu1",
149418          "licenses": [
149419            {
149420              "license": {
149421                "id": "BSD-3-Clause"
149422              }
149423            },
149424            {
149425              "license": {
149426                "id": "GPL-2.0-only"
149427              }
149428            },
149429            {
149430              "license": {
149431                "id": "GPL-2.0-or-later"
149432              }
149433            },
149434            {
149435              "license": {
149436                "name": "custom"
149437              }
149438            }
149439          ],
149440          "cpe": "cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
149441          "purl": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
149442          "swid": {
149443            "attachment": {}
149444          },
149445          "pedigree": {},
149446          "evidence": {},
149447          "signature": {
149448            "signature": {
149449              "publicKey": {}
149450            }
149451          },
149452          "modelCard": {
149453            "modelParameters": {
149454              "approach": {}
149455            },
149456            "quantitativeAnalysis": {
149457              "graphics": {}
149458            },
149459            "considerations": {}
149460          }
149461        },
149462        {
149463          "type": "library",
149464          "bom-ref": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=9992d88ac7d6e8e3",
149465          "supplier": {},
149466          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149467          "name": "libheimntlm0-heimdal",
149468          "version": "7.7.0+dfsg-1ubuntu1",
149469          "licenses": [
149470            {
149471              "license": {
149472                "id": "BSD-3-Clause"
149473              }
149474            },
149475            {
149476              "license": {
149477                "id": "GPL-2.0-only"
149478              }
149479            },
149480            {
149481              "license": {
149482                "id": "GPL-2.0-or-later"
149483              }
149484            },
149485            {
149486              "license": {
149487                "name": "custom"
149488              }
149489            }
149490          ],
149491          "cpe": "cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
149492          "purl": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
149493          "swid": {
149494            "attachment": {}
149495          },
149496          "pedigree": {},
149497          "evidence": {},
149498          "signature": {
149499            "signature": {
149500              "publicKey": {}
149501            }
149502          },
149503          "modelCard": {
149504            "modelParameters": {
149505              "approach": {}
149506            },
149507            "quantitativeAnalysis": {
149508              "graphics": {}
149509            },
149510            "considerations": {}
149511          }
149512        },
149513        {
149514          "type": "library",
149515          "bom-ref": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3caecccf070e6760",
149516          "supplier": {},
149517          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149518          "name": "libhogweed5",
149519          "version": "3.5.1+really3.5.1-2ubuntu0.2",
149520          "licenses": [
149521            {
149522              "license": {
149523                "name": "GAP"
149524              }
149525            },
149526            {
149527              "license": {
149528                "name": "GPL"
149529              }
149530            },
149531            {
149532              "license": {
149533                "id": "GPL-2.0-only"
149534              }
149535            },
149536            {
149537              "license": {
149538                "id": "GPL-2.0-or-later"
149539              }
149540            },
149541            {
149542              "license": {
149543                "name": "LGPL"
149544              }
149545            },
149546            {
149547              "license": {
149548                "id": "LGPL-2.0-only"
149549              }
149550            },
149551            {
149552              "license": {
149553                "id": "LGPL-2.0-or-later"
149554              }
149555            },
149556            {
149557              "license": {
149558                "id": "LGPL-2.1-or-later"
149559              }
149560            },
149561            {
149562              "license": {
149563                "name": "other"
149564              }
149565            },
149566            {
149567              "license": {
149568                "name": "public-domain"
149569              }
149570            }
149571          ],
149572          "cpe": "cpe:2.3:a:libhogweed5:libhogweed5:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
149573          "purl": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
149574          "swid": {
149575            "attachment": {}
149576          },
149577          "pedigree": {},
149578          "evidence": {},
149579          "signature": {
149580            "signature": {
149581              "publicKey": {}
149582            }
149583          },
149584          "modelCard": {
149585            "modelParameters": {
149586              "approach": {}
149587            },
149588            "quantitativeAnalysis": {
149589              "graphics": {}
149590            },
149591            "considerations": {}
149592          }
149593        },
149594        {
149595          "type": "library",
149596          "bom-ref": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=3b0bac5e4e8f23c5",
149597          "supplier": {},
149598          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149599          "name": "libhx509-5-heimdal",
149600          "version": "7.7.0+dfsg-1ubuntu1",
149601          "licenses": [
149602            {
149603              "license": {
149604                "id": "BSD-3-Clause"
149605              }
149606            },
149607            {
149608              "license": {
149609                "id": "GPL-2.0-only"
149610              }
149611            },
149612            {
149613              "license": {
149614                "id": "GPL-2.0-or-later"
149615              }
149616            },
149617            {
149618              "license": {
149619                "name": "custom"
149620              }
149621            }
149622          ],
149623          "cpe": "cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
149624          "purl": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
149625          "swid": {
149626            "attachment": {}
149627          },
149628          "pedigree": {},
149629          "evidence": {},
149630          "signature": {
149631            "signature": {
149632              "publicKey": {}
149633            }
149634          },
149635          "modelCard": {
149636            "modelParameters": {
149637              "approach": {}
149638            },
149639            "quantitativeAnalysis": {
149640              "graphics": {}
149641            },
149642            "considerations": {}
149643          }
149644        },
149645        {
149646          "type": "library",
149647          "bom-ref": "pkg:deb/ubuntu/libibverbs1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04\u0026package-id=8a574b9c0296728e",
149648          "supplier": {},
149649          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149650          "name": "libibverbs1",
149651          "version": "28.0-1ubuntu1",
149652          "licenses": [
149653            {
149654              "license": {
149655                "id": "BSD-2-Clause"
149656              }
149657            },
149658            {
149659              "license": {
149660                "id": "BSD-3-Clause"
149661              }
149662            },
149663            {
149664              "license": {
149665                "name": "BSD-MIT"
149666              }
149667            },
149668            {
149669              "license": {
149670                "name": "CC0"
149671              }
149672            },
149673            {
149674              "license": {
149675                "id": "CPL-1.0"
149676              }
149677            },
149678            {
149679              "license": {
149680                "id": "GPL-2.0-only"
149681              }
149682            },
149683            {
149684              "license": {
149685                "id": "GPL-2.0-or-later"
149686              }
149687            },
149688            {
149689              "license": {
149690                "id": "MIT"
149691              }
149692            }
149693          ],
149694          "cpe": "cpe:2.3:a:libibverbs1:libibverbs1:28.0-1ubuntu1:*:*:*:*:*:*:*",
149695          "purl": "pkg:deb/ubuntu/libibverbs1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04",
149696          "swid": {
149697            "attachment": {}
149698          },
149699          "pedigree": {},
149700          "evidence": {},
149701          "signature": {
149702            "signature": {
149703              "publicKey": {}
149704            }
149705          },
149706          "modelCard": {
149707            "modelParameters": {
149708              "approach": {}
149709            },
149710            "quantitativeAnalysis": {
149711              "graphics": {}
149712            },
149713            "considerations": {}
149714          }
149715        },
149716        {
149717          "type": "library",
149718          "bom-ref": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04\u0026package-id=bcf598a9dea4cd38",
149719          "supplier": {},
149720          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149721          "name": "libicu66",
149722          "version": "66.1-2ubuntu2",
149723          "cpe": "cpe:2.3:a:libicu66:libicu66:66.1-2ubuntu2:*:*:*:*:*:*:*",
149724          "purl": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04",
149725          "swid": {
149726            "attachment": {}
149727          },
149728          "pedigree": {},
149729          "evidence": {},
149730          "signature": {
149731            "signature": {
149732              "publicKey": {}
149733            }
149734          },
149735          "modelCard": {
149736            "modelParameters": {
149737              "approach": {}
149738            },
149739            "quantitativeAnalysis": {
149740              "graphics": {}
149741            },
149742            "considerations": {}
149743          }
149744        },
149745        {
149746          "type": "library",
149747          "bom-ref": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04\u0026package-id=d2a82c3e28413bc1",
149748          "supplier": {},
149749          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149750          "name": "libidn2-0",
149751          "version": "2.2.0-2",
149752          "licenses": [
149753            {
149754              "license": {
149755                "id": "GPL-2.0-only"
149756              }
149757            },
149758            {
149759              "license": {
149760                "id": "GPL-2.0-or-later"
149761              }
149762            },
149763            {
149764              "license": {
149765                "id": "GPL-3.0-only"
149766              }
149767            },
149768            {
149769              "license": {
149770                "id": "GPL-3.0-or-later"
149771              }
149772            },
149773            {
149774              "license": {
149775                "id": "LGPL-3.0-only"
149776              }
149777            },
149778            {
149779              "license": {
149780                "id": "LGPL-3.0-or-later"
149781              }
149782            },
149783            {
149784              "license": {
149785                "name": "Unicode"
149786              }
149787            }
149788          ],
149789          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.2.0-2:*:*:*:*:*:*:*",
149790          "purl": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04",
149791          "swid": {
149792            "attachment": {}
149793          },
149794          "pedigree": {},
149795          "evidence": {},
149796          "signature": {
149797            "signature": {
149798              "publicKey": {}
149799            }
149800          },
149801          "modelCard": {
149802            "modelParameters": {
149803              "approach": {}
149804            },
149805            "quantitativeAnalysis": {
149806              "graphics": {}
149807            },
149808            "considerations": {}
149809          }
149810        },
149811        {
149812          "type": "library",
149813          "bom-ref": "pkg:deb/ubuntu/libiscsi7@1.18.0-2?arch=amd64\u0026upstream=libiscsi\u0026distro=ubuntu-20.04\u0026package-id=d3404aeee287695b",
149814          "supplier": {},
149815          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149816          "name": "libiscsi7",
149817          "version": "1.18.0-2",
149818          "licenses": [
149819            {
149820              "license": {
149821                "id": "GPL-2.0-only"
149822              }
149823            },
149824            {
149825              "license": {
149826                "id": "GPL-2.0-or-later"
149827              }
149828            },
149829            {
149830              "license": {
149831                "id": "GPL-3.0-only"
149832              }
149833            },
149834            {
149835              "license": {
149836                "id": "GPL-3.0-or-later"
149837              }
149838            },
149839            {
149840              "license": {
149841                "id": "LGPL-2.1-only"
149842              }
149843            },
149844            {
149845              "license": {
149846                "id": "LGPL-2.1-or-later"
149847              }
149848            },
149849            {
149850              "license": {
149851                "name": "MIT/X11"
149852              }
149853            },
149854            {
149855              "license": {
149856                "name": "Public_domain"
149857              }
149858            }
149859          ],
149860          "cpe": "cpe:2.3:a:libiscsi7:libiscsi7:1.18.0-2:*:*:*:*:*:*:*",
149861          "purl": "pkg:deb/ubuntu/libiscsi7@1.18.0-2?arch=amd64\u0026upstream=libiscsi\u0026distro=ubuntu-20.04",
149862          "swid": {
149863            "attachment": {}
149864          },
149865          "pedigree": {},
149866          "evidence": {},
149867          "signature": {
149868            "signature": {
149869              "publicKey": {}
149870            }
149871          },
149872          "modelCard": {
149873            "modelParameters": {
149874              "approach": {}
149875            },
149876            "quantitativeAnalysis": {
149877              "graphics": {}
149878            },
149879            "considerations": {}
149880          }
149881        },
149882        {
149883          "type": "library",
149884          "bom-ref": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=f9479050b59432b4",
149885          "supplier": {},
149886          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149887          "name": "libk5crypto3",
149888          "version": "1.17-6ubuntu4.1",
149889          "licenses": [
149890            {
149891              "license": {
149892                "id": "GPL-2.0-only"
149893              }
149894            }
149895          ],
149896          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
149897          "purl": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
149898          "swid": {
149899            "attachment": {}
149900          },
149901          "pedigree": {},
149902          "evidence": {},
149903          "signature": {
149904            "signature": {
149905              "publicKey": {}
149906            }
149907          },
149908          "modelCard": {
149909            "modelParameters": {
149910              "approach": {}
149911            },
149912            "quantitativeAnalysis": {
149913              "graphics": {}
149914            },
149915            "considerations": {}
149916          }
149917        },
149918        {
149919          "type": "library",
149920          "bom-ref": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04\u0026package-id=e8692427b123ea73",
149921          "supplier": {},
149922          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149923          "name": "libkeyutils1",
149924          "version": "1.6-6ubuntu1",
149925          "licenses": [
149926            {
149927              "license": {
149928                "id": "GPL-2.0-only"
149929              }
149930            },
149931            {
149932              "license": {
149933                "id": "GPL-2.0-or-later"
149934              }
149935            },
149936            {
149937              "license": {
149938                "id": "LGPL-2.0-only"
149939              }
149940            },
149941            {
149942              "license": {
149943                "id": "LGPL-2.0-or-later"
149944              }
149945            }
149946          ],
149947          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6-6ubuntu1:*:*:*:*:*:*:*",
149948          "purl": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04",
149949          "swid": {
149950            "attachment": {}
149951          },
149952          "pedigree": {},
149953          "evidence": {},
149954          "signature": {
149955            "signature": {
149956              "publicKey": {}
149957            }
149958          },
149959          "modelCard": {
149960            "modelParameters": {
149961              "approach": {}
149962            },
149963            "quantitativeAnalysis": {
149964              "graphics": {}
149965            },
149966            "considerations": {}
149967          }
149968        },
149969        {
149970          "type": "library",
149971          "bom-ref": "pkg:deb/ubuntu/libkmod2@27-1ubuntu2?arch=amd64\u0026upstream=kmod\u0026distro=ubuntu-20.04\u0026package-id=9de5f0614e60f8ee",
149972          "supplier": {},
149973          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
149974          "name": "libkmod2",
149975          "version": "27-1ubuntu2",
149976          "licenses": [
149977            {
149978              "license": {
149979                "id": "GPL-2.0-only"
149980              }
149981            }
149982          ],
149983          "cpe": "cpe:2.3:a:libkmod2:libkmod2:27-1ubuntu2:*:*:*:*:*:*:*",
149984          "purl": "pkg:deb/ubuntu/libkmod2@27-1ubuntu2?arch=amd64\u0026upstream=kmod\u0026distro=ubuntu-20.04",
149985          "swid": {
149986            "attachment": {}
149987          },
149988          "pedigree": {},
149989          "evidence": {},
149990          "signature": {
149991            "signature": {
149992              "publicKey": {}
149993            }
149994          },
149995          "modelCard": {
149996            "modelParameters": {
149997              "approach": {}
149998            },
149999            "quantitativeAnalysis": {
150000              "graphics": {}
150001            },
150002            "considerations": {}
150003          }
150004        },
150005        {
150006          "type": "library",
150007          "bom-ref": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=2beb670b9378498e",
150008          "supplier": {},
150009          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150010          "name": "libkrb5-26-heimdal",
150011          "version": "7.7.0+dfsg-1ubuntu1",
150012          "licenses": [
150013            {
150014              "license": {
150015                "id": "BSD-3-Clause"
150016              }
150017            },
150018            {
150019              "license": {
150020                "id": "GPL-2.0-only"
150021              }
150022            },
150023            {
150024              "license": {
150025                "id": "GPL-2.0-or-later"
150026              }
150027            },
150028            {
150029              "license": {
150030                "name": "custom"
150031              }
150032            }
150033          ],
150034          "cpe": "cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
150035          "purl": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
150036          "swid": {
150037            "attachment": {}
150038          },
150039          "pedigree": {},
150040          "evidence": {},
150041          "signature": {
150042            "signature": {
150043              "publicKey": {}
150044            }
150045          },
150046          "modelCard": {
150047            "modelParameters": {
150048              "approach": {}
150049            },
150050            "quantitativeAnalysis": {
150051              "graphics": {}
150052            },
150053            "considerations": {}
150054          }
150055        },
150056        {
150057          "type": "library",
150058          "bom-ref": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=fdb5970d8394a182",
150059          "supplier": {},
150060          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150061          "name": "libkrb5-3",
150062          "version": "1.17-6ubuntu4.1",
150063          "licenses": [
150064            {
150065              "license": {
150066                "id": "GPL-2.0-only"
150067              }
150068            }
150069          ],
150070          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
150071          "purl": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
150072          "swid": {
150073            "attachment": {}
150074          },
150075          "pedigree": {},
150076          "evidence": {},
150077          "signature": {
150078            "signature": {
150079              "publicKey": {}
150080            }
150081          },
150082          "modelCard": {
150083            "modelParameters": {
150084              "approach": {}
150085            },
150086            "quantitativeAnalysis": {
150087              "graphics": {}
150088            },
150089            "considerations": {}
150090          }
150091        },
150092        {
150093          "type": "library",
150094          "bom-ref": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=a8d21a32e178b211",
150095          "supplier": {},
150096          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150097          "name": "libkrb5support0",
150098          "version": "1.17-6ubuntu4.1",
150099          "licenses": [
150100            {
150101              "license": {
150102                "id": "GPL-2.0-only"
150103              }
150104            }
150105          ],
150106          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
150107          "purl": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
150108          "swid": {
150109            "attachment": {}
150110          },
150111          "pedigree": {},
150112          "evidence": {},
150113          "signature": {
150114            "signature": {
150115              "publicKey": {}
150116            }
150117          },
150118          "modelCard": {
150119            "modelParameters": {
150120              "approach": {}
150121            },
150122            "quantitativeAnalysis": {
150123              "graphics": {}
150124            },
150125            "considerations": {}
150126          }
150127        },
150128        {
150129          "type": "library",
150130          "bom-ref": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=efdc80a7ae6eae19",
150131          "supplier": {},
150132          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150133          "name": "libldap-2.4-2",
150134          "version": "2.4.49+dfsg-2ubuntu1.8",
150135          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
150136          "purl": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04",
150137          "swid": {
150138            "attachment": {}
150139          },
150140          "pedigree": {},
150141          "evidence": {},
150142          "signature": {
150143            "signature": {
150144              "publicKey": {}
150145            }
150146          },
150147          "modelCard": {
150148            "modelParameters": {
150149              "approach": {}
150150            },
150151            "quantitativeAnalysis": {
150152              "graphics": {}
150153            },
150154            "considerations": {}
150155          }
150156        },
150157        {
150158          "type": "library",
150159          "bom-ref": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=4d0b88f98b40786b",
150160          "supplier": {},
150161          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150162          "name": "libldap-common",
150163          "version": "2.4.49+dfsg-2ubuntu1.8",
150164          "cpe": "cpe:2.3:a:libldap-common:libldap-common:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
150165          "purl": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04",
150166          "swid": {
150167            "attachment": {}
150168          },
150169          "pedigree": {},
150170          "evidence": {},
150171          "signature": {
150172            "signature": {
150173              "publicKey": {}
150174            }
150175          },
150176          "modelCard": {
150177            "modelParameters": {
150178              "approach": {}
150179            },
150180            "quantitativeAnalysis": {
150181              "graphics": {}
150182            },
150183            "considerations": {}
150184          }
150185        },
150186        {
150187          "type": "library",
150188          "bom-ref": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04\u0026package-id=6f2c431caeb4980a",
150189          "supplier": {},
150190          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150191          "name": "liblz4-1",
150192          "version": "1.9.2-2ubuntu0.20.04.1",
150193          "licenses": [
150194            {
150195              "license": {
150196                "id": "BSD-2-Clause"
150197              }
150198            },
150199            {
150200              "license": {
150201                "id": "GPL-2.0-only"
150202              }
150203            },
150204            {
150205              "license": {
150206                "id": "GPL-2.0-or-later"
150207              }
150208            }
150209          ],
150210          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.2-2ubuntu0.20.04.1:*:*:*:*:*:*:*",
150211          "purl": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04",
150212          "swid": {
150213            "attachment": {}
150214          },
150215          "pedigree": {},
150216          "evidence": {},
150217          "signature": {
150218            "signature": {
150219              "publicKey": {}
150220            }
150221          },
150222          "modelCard": {
150223            "modelParameters": {
150224              "approach": {}
150225            },
150226            "quantitativeAnalysis": {
150227              "graphics": {}
150228            },
150229            "considerations": {}
150230          }
150231        },
150232        {
150233          "type": "library",
150234          "bom-ref": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04\u0026package-id=f1e9f3b6205a664a",
150235          "supplier": {},
150236          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150237          "name": "liblzma5",
150238          "version": "5.2.4-1ubuntu1",
150239          "licenses": [
150240            {
150241              "license": {
150242                "name": "Autoconf"
150243              }
150244            },
150245            {
150246              "license": {
150247                "id": "GPL-2.0-only"
150248              }
150249            },
150250            {
150251              "license": {
150252                "id": "GPL-2.0-or-later"
150253              }
150254            },
150255            {
150256              "license": {
150257                "id": "GPL-3.0-only"
150258              }
150259            },
150260            {
150261              "license": {
150262                "id": "LGPL-2.0-only"
150263              }
150264            },
150265            {
150266              "license": {
150267                "id": "LGPL-2.1-only"
150268              }
150269            },
150270            {
150271              "license": {
150272                "id": "LGPL-2.1-or-later"
150273              }
150274            },
150275            {
150276              "license": {
150277                "name": "PD"
150278              }
150279            },
150280            {
150281              "license": {
150282                "name": "PD-debian"
150283              }
150284            },
150285            {
150286              "license": {
150287                "name": "config-h"
150288              }
150289            },
150290            {
150291              "license": {
150292                "name": "noderivs"
150293              }
150294            },
150295            {
150296              "license": {
150297                "name": "permissive-fsf"
150298              }
150299            },
150300            {
150301              "license": {
150302                "name": "permissive-nowarranty"
150303              }
150304            },
150305            {
150306              "license": {
150307                "name": "probably-PD"
150308              }
150309            }
150310          ],
150311          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
150312          "purl": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04",
150313          "swid": {
150314            "attachment": {}
150315          },
150316          "pedigree": {},
150317          "evidence": {},
150318          "signature": {
150319            "signature": {
150320              "publicKey": {}
150321            }
150322          },
150323          "modelCard": {
150324            "modelParameters": {
150325              "approach": {}
150326            },
150327            "quantitativeAnalysis": {
150328              "graphics": {}
150329            },
150330            "considerations": {}
150331          }
150332        },
150333        {
150334          "type": "library",
150335          "bom-ref": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=3b4f02792ccf99bb",
150336          "supplier": {},
150337          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150338          "name": "libmagic-mgc",
150339          "version": "1:5.38-4",
150340          "licenses": [
150341            {
150342              "license": {
150343                "name": "BSD-2-Clause-alike"
150344              }
150345            },
150346            {
150347              "license": {
150348                "id": "BSD-2-Clause"
150349              }
150350            },
150351            {
150352              "license": {
150353                "name": "BSD-2-Clause-regents"
150354              }
150355            },
150356            {
150357              "license": {
150358                "name": "MIT-Old-Style-with-legal-disclaimer-2"
150359              }
150360            },
150361            {
150362              "license": {
150363                "name": "public-domain"
150364              }
150365            }
150366          ],
150367          "cpe": "cpe:2.3:a:libmagic-mgc:libmagic-mgc:1\\:5.38-4:*:*:*:*:*:*:*",
150368          "purl": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
150369          "swid": {
150370            "attachment": {}
150371          },
150372          "pedigree": {},
150373          "evidence": {},
150374          "signature": {
150375            "signature": {
150376              "publicKey": {}
150377            }
150378          },
150379          "modelCard": {
150380            "modelParameters": {
150381              "approach": {}
150382            },
150383            "quantitativeAnalysis": {
150384              "graphics": {}
150385            },
150386            "considerations": {}
150387          }
150388        },
150389        {
150390          "type": "library",
150391          "bom-ref": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=302b8497a938556",
150392          "supplier": {},
150393          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150394          "name": "libmagic1",
150395          "version": "1:5.38-4",
150396          "licenses": [
150397            {
150398              "license": {
150399                "name": "BSD-2-Clause-alike"
150400              }
150401            },
150402            {
150403              "license": {
150404                "id": "BSD-2-Clause"
150405              }
150406            },
150407            {
150408              "license": {
150409                "name": "BSD-2-Clause-regents"
150410              }
150411            },
150412            {
150413              "license": {
150414                "name": "MIT-Old-Style-with-legal-disclaimer-2"
150415              }
150416            },
150417            {
150418              "license": {
150419                "name": "public-domain"
150420              }
150421            }
150422          ],
150423          "cpe": "cpe:2.3:a:libmagic1:libmagic1:1\\:5.38-4:*:*:*:*:*:*:*",
150424          "purl": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
150425          "swid": {
150426            "attachment": {}
150427          },
150428          "pedigree": {},
150429          "evidence": {},
150430          "signature": {
150431            "signature": {
150432              "publicKey": {}
150433            }
150434          },
150435          "modelCard": {
150436            "modelParameters": {
150437              "approach": {}
150438            },
150439            "quantitativeAnalysis": {
150440              "graphics": {}
150441            },
150442            "considerations": {}
150443          }
150444        },
150445        {
150446          "type": "library",
150447          "bom-ref": "pkg:deb/ubuntu/libmnl0@1.0.4-2?arch=amd64\u0026upstream=libmnl\u0026distro=ubuntu-20.04\u0026package-id=162cfe25074edf0d",
150448          "supplier": {},
150449          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150450          "name": "libmnl0",
150451          "version": "1.0.4-2",
150452          "licenses": [
150453            {
150454              "license": {
150455                "id": "GPL-2.0-only"
150456              }
150457            },
150458            {
150459              "license": {
150460                "id": "GPL-2.0-or-later"
150461              }
150462            },
150463            {
150464              "license": {
150465                "id": "LGPL-2.1-only"
150466              }
150467            }
150468          ],
150469          "cpe": "cpe:2.3:a:libmnl0:libmnl0:1.0.4-2:*:*:*:*:*:*:*",
150470          "purl": "pkg:deb/ubuntu/libmnl0@1.0.4-2?arch=amd64\u0026upstream=libmnl\u0026distro=ubuntu-20.04",
150471          "swid": {
150472            "attachment": {}
150473          },
150474          "pedigree": {},
150475          "evidence": {},
150476          "signature": {
150477            "signature": {
150478              "publicKey": {}
150479            }
150480          },
150481          "modelCard": {
150482            "modelParameters": {
150483              "approach": {}
150484            },
150485            "quantitativeAnalysis": {
150486              "graphics": {}
150487            },
150488            "considerations": {}
150489          }
150490        },
150491        {
150492          "type": "library",
150493          "bom-ref": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=39446194385ebce5",
150494          "supplier": {},
150495          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150496          "name": "libmount1",
150497          "version": "2.34-0.1ubuntu9.1",
150498          "licenses": [
150499            {
150500              "license": {
150501                "id": "BSD-2-Clause"
150502              }
150503            },
150504            {
150505              "license": {
150506                "id": "BSD-3-Clause"
150507              }
150508            },
150509            {
150510              "license": {
150511                "id": "BSD-4-Clause"
150512              }
150513            },
150514            {
150515              "license": {
150516                "id": "GPL-2.0-only"
150517              }
150518            },
150519            {
150520              "license": {
150521                "id": "GPL-2.0-or-later"
150522              }
150523            },
150524            {
150525              "license": {
150526                "id": "GPL-3.0-only"
150527              }
150528            },
150529            {
150530              "license": {
150531                "id": "GPL-3.0-or-later"
150532              }
150533            },
150534            {
150535              "license": {
150536                "name": "LGPL"
150537              }
150538            },
150539            {
150540              "license": {
150541                "id": "LGPL-2.0-only"
150542              }
150543            },
150544            {
150545              "license": {
150546                "id": "LGPL-2.0-or-later"
150547              }
150548            },
150549            {
150550              "license": {
150551                "id": "LGPL-2.1-only"
150552              }
150553            },
150554            {
150555              "license": {
150556                "id": "LGPL-2.1-or-later"
150557              }
150558            },
150559            {
150560              "license": {
150561                "id": "LGPL-3.0-only"
150562              }
150563            },
150564            {
150565              "license": {
150566                "id": "LGPL-3.0-or-later"
150567              }
150568            },
150569            {
150570              "license": {
150571                "id": "MIT"
150572              }
150573            },
150574            {
150575              "license": {
150576                "name": "public-domain"
150577              }
150578            }
150579          ],
150580          "cpe": "cpe:2.3:a:libmount1:libmount1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
150581          "purl": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
150582          "swid": {
150583            "attachment": {}
150584          },
150585          "pedigree": {},
150586          "evidence": {},
150587          "signature": {
150588            "signature": {
150589              "publicKey": {}
150590            }
150591          },
150592          "modelCard": {
150593            "modelParameters": {
150594              "approach": {}
150595            },
150596            "quantitativeAnalysis": {
150597              "graphics": {}
150598            },
150599            "considerations": {}
150600          }
150601        },
150602        {
150603          "type": "library",
150604          "bom-ref": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04\u0026package-id=b45a0d57576ce262",
150605          "supplier": {},
150606          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150607          "name": "libmpdec2",
150608          "version": "2.4.2-3",
150609          "licenses": [
150610            {
150611              "license": {
150612                "name": "BSD"
150613              }
150614            },
150615            {
150616              "license": {
150617                "id": "GPL-2.0-only"
150618              }
150619            },
150620            {
150621              "license": {
150622                "id": "GPL-2.0-or-later"
150623              }
150624            }
150625          ],
150626          "cpe": "cpe:2.3:a:libmpdec2:libmpdec2:2.4.2-3:*:*:*:*:*:*:*",
150627          "purl": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04",
150628          "swid": {
150629            "attachment": {}
150630          },
150631          "pedigree": {},
150632          "evidence": {},
150633          "signature": {
150634            "signature": {
150635              "publicKey": {}
150636            }
150637          },
150638          "modelCard": {
150639            "modelParameters": {
150640              "approach": {}
150641            },
150642            "quantitativeAnalysis": {
150643              "graphics": {}
150644            },
150645            "considerations": {}
150646          }
150647        },
150648        {
150649          "type": "library",
150650          "bom-ref": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=ed8fb166163a75b8",
150651          "supplier": {},
150652          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150653          "name": "libncurses6",
150654          "version": "6.2-0ubuntu2",
150655          "cpe": "cpe:2.3:a:libncurses6:libncurses6:6.2-0ubuntu2:*:*:*:*:*:*:*",
150656          "purl": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
150657          "swid": {
150658            "attachment": {}
150659          },
150660          "pedigree": {},
150661          "evidence": {},
150662          "signature": {
150663            "signature": {
150664              "publicKey": {}
150665            }
150666          },
150667          "modelCard": {
150668            "modelParameters": {
150669              "approach": {}
150670            },
150671            "quantitativeAnalysis": {
150672              "graphics": {}
150673            },
150674            "considerations": {}
150675          }
150676        },
150677        {
150678          "type": "library",
150679          "bom-ref": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=58525ddc073a008a",
150680          "supplier": {},
150681          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150682          "name": "libncursesw6",
150683          "version": "6.2-0ubuntu2",
150684          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.2-0ubuntu2:*:*:*:*:*:*:*",
150685          "purl": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
150686          "swid": {
150687            "attachment": {}
150688          },
150689          "pedigree": {},
150690          "evidence": {},
150691          "signature": {
150692            "signature": {
150693              "publicKey": {}
150694            }
150695          },
150696          "modelCard": {
150697            "modelParameters": {
150698              "approach": {}
150699            },
150700            "quantitativeAnalysis": {
150701              "graphics": {}
150702            },
150703            "considerations": {}
150704          }
150705        },
150706        {
150707          "type": "library",
150708          "bom-ref": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3d185fbd6a7e56f",
150709          "supplier": {},
150710          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150711          "name": "libnettle7",
150712          "version": "3.5.1+really3.5.1-2ubuntu0.2",
150713          "licenses": [
150714            {
150715              "license": {
150716                "name": "GAP"
150717              }
150718            },
150719            {
150720              "license": {
150721                "name": "GPL"
150722              }
150723            },
150724            {
150725              "license": {
150726                "id": "GPL-2.0-only"
150727              }
150728            },
150729            {
150730              "license": {
150731                "id": "GPL-2.0-or-later"
150732              }
150733            },
150734            {
150735              "license": {
150736                "name": "LGPL"
150737              }
150738            },
150739            {
150740              "license": {
150741                "id": "LGPL-2.0-only"
150742              }
150743            },
150744            {
150745              "license": {
150746                "id": "LGPL-2.0-or-later"
150747              }
150748            },
150749            {
150750              "license": {
150751                "id": "LGPL-2.1-or-later"
150752              }
150753            },
150754            {
150755              "license": {
150756                "name": "other"
150757              }
150758            },
150759            {
150760              "license": {
150761                "name": "public-domain"
150762              }
150763            }
150764          ],
150765          "cpe": "cpe:2.3:a:libnettle7:libnettle7:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
150766          "purl": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
150767          "swid": {
150768            "attachment": {}
150769          },
150770          "pedigree": {},
150771          "evidence": {},
150772          "signature": {
150773            "signature": {
150774              "publicKey": {}
150775            }
150776          },
150777          "modelCard": {
150778            "modelParameters": {
150779              "approach": {}
150780            },
150781            "quantitativeAnalysis": {
150782              "graphics": {}
150783            },
150784            "considerations": {}
150785          }
150786        },
150787        {
150788          "type": "library",
150789          "bom-ref": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04\u0026package-id=71bd574c47c02b75",
150790          "supplier": {},
150791          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150792          "name": "libnfsidmap2",
150793          "version": "0.25-5.1ubuntu1",
150794          "cpe": "cpe:2.3:a:libnfsidmap2:libnfsidmap2:0.25-5.1ubuntu1:*:*:*:*:*:*:*",
150795          "purl": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04",
150796          "swid": {
150797            "attachment": {}
150798          },
150799          "pedigree": {},
150800          "evidence": {},
150801          "signature": {
150802            "signature": {
150803              "publicKey": {}
150804            }
150805          },
150806          "modelCard": {
150807            "modelParameters": {
150808              "approach": {}
150809            },
150810            "quantitativeAnalysis": {
150811              "graphics": {}
150812            },
150813            "considerations": {}
150814          }
150815        },
150816        {
150817          "type": "library",
150818          "bom-ref": "pkg:deb/ubuntu/libnghttp2-14@1.40.0-1build1?arch=amd64\u0026upstream=nghttp2\u0026distro=ubuntu-20.04\u0026package-id=c86604c1fa72dd96",
150819          "supplier": {},
150820          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150821          "name": "libnghttp2-14",
150822          "version": "1.40.0-1build1",
150823          "licenses": [
150824            {
150825              "license": {
150826                "id": "BSD-2-Clause"
150827              }
150828            },
150829            {
150830              "license": {
150831                "name": "Expat"
150832              }
150833            },
150834            {
150835              "license": {
150836                "id": "GPL-3.0-only"
150837              }
150838            },
150839            {
150840              "license": {
150841                "id": "GPL-3.0-or-later"
150842              }
150843            },
150844            {
150845              "license": {
150846                "id": "MIT"
150847              }
150848            },
150849            {
150850              "license": {
150851                "name": "SIL-OFL-1.1"
150852              }
150853            },
150854            {
150855              "license": {
150856                "name": "all-permissive"
150857              }
150858            }
150859          ],
150860          "cpe": "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.40.0-1build1:*:*:*:*:*:*:*",
150861          "purl": "pkg:deb/ubuntu/libnghttp2-14@1.40.0-1build1?arch=amd64\u0026upstream=nghttp2\u0026distro=ubuntu-20.04",
150862          "swid": {
150863            "attachment": {}
150864          },
150865          "pedigree": {},
150866          "evidence": {},
150867          "signature": {
150868            "signature": {
150869              "publicKey": {}
150870            }
150871          },
150872          "modelCard": {
150873            "modelParameters": {
150874              "approach": {}
150875            },
150876            "quantitativeAnalysis": {
150877              "graphics": {}
150878            },
150879            "considerations": {}
150880          }
150881        },
150882        {
150883          "type": "library",
150884          "bom-ref": "pkg:deb/ubuntu/libnl-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04\u0026package-id=520a765636f2f20f",
150885          "supplier": {},
150886          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150887          "name": "libnl-3-200",
150888          "version": "3.4.0-1",
150889          "licenses": [
150890            {
150891              "license": {
150892                "id": "GPL-2.0-only"
150893              }
150894            },
150895            {
150896              "license": {
150897                "id": "LGPL-2.1-only"
150898              }
150899            }
150900          ],
150901          "cpe": "cpe:2.3:a:libnl-3-200:libnl-3-200:3.4.0-1:*:*:*:*:*:*:*",
150902          "purl": "pkg:deb/ubuntu/libnl-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04",
150903          "swid": {
150904            "attachment": {}
150905          },
150906          "pedigree": {},
150907          "evidence": {},
150908          "signature": {
150909            "signature": {
150910              "publicKey": {}
150911            }
150912          },
150913          "modelCard": {
150914            "modelParameters": {
150915              "approach": {}
150916            },
150917            "quantitativeAnalysis": {
150918              "graphics": {}
150919            },
150920            "considerations": {}
150921          }
150922        },
150923        {
150924          "type": "library",
150925          "bom-ref": "pkg:deb/ubuntu/libnl-route-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04\u0026package-id=1a1d9f0f1f34e88b",
150926          "supplier": {},
150927          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150928          "name": "libnl-route-3-200",
150929          "version": "3.4.0-1",
150930          "licenses": [
150931            {
150932              "license": {
150933                "id": "GPL-2.0-only"
150934              }
150935            },
150936            {
150937              "license": {
150938                "id": "LGPL-2.1-only"
150939              }
150940            }
150941          ],
150942          "cpe": "cpe:2.3:a:libnl-route-3-200:libnl-route-3-200:3.4.0-1:*:*:*:*:*:*:*",
150943          "purl": "pkg:deb/ubuntu/libnl-route-3-200@3.4.0-1?arch=amd64\u0026upstream=libnl3\u0026distro=ubuntu-20.04",
150944          "swid": {
150945            "attachment": {}
150946          },
150947          "pedigree": {},
150948          "evidence": {},
150949          "signature": {
150950            "signature": {
150951              "publicKey": {}
150952            }
150953          },
150954          "modelCard": {
150955            "modelParameters": {
150956              "approach": {}
150957            },
150958            "quantitativeAnalysis": {
150959              "graphics": {}
150960            },
150961            "considerations": {}
150962          }
150963        },
150964        {
150965          "type": "library",
150966          "bom-ref": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04\u0026package-id=9fc0ca46e6d21557",
150967          "supplier": {},
150968          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
150969          "name": "libp11-kit0",
150970          "version": "0.23.20-1ubuntu0.1",
150971          "licenses": [
150972            {
150973              "license": {
150974                "id": "BSD-3-Clause"
150975              }
150976            },
150977            {
150978              "license": {
150979                "id": "ISC"
150980              }
150981            },
150982            {
150983              "license": {
150984                "name": "ISC+IBM"
150985              }
150986            },
150987            {
150988              "license": {
150989                "name": "permissive-like-automake-output"
150990              }
150991            },
150992            {
150993              "license": {
150994                "name": "same-as-rest-of-p11kit"
150995              }
150996            }
150997          ],
150998          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.20-1ubuntu0.1:*:*:*:*:*:*:*",
150999          "purl": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04",
151000          "swid": {
151001            "attachment": {}
151002          },
151003          "pedigree": {},
151004          "evidence": {},
151005          "signature": {
151006            "signature": {
151007              "publicKey": {}
151008            }
151009          },
151010          "modelCard": {
151011            "modelParameters": {
151012              "approach": {}
151013            },
151014            "quantitativeAnalysis": {
151015              "graphics": {}
151016            },
151017            "considerations": {}
151018          }
151019        },
151020        {
151021          "type": "library",
151022          "bom-ref": "pkg:deb/ubuntu/libpam-cap@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04\u0026package-id=20db44acb7f94535",
151023          "supplier": {},
151024          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151025          "name": "libpam-cap",
151026          "version": "1:2.32-1",
151027          "licenses": [
151028            {
151029              "license": {
151030                "id": "BSD-3-Clause"
151031              }
151032            },
151033            {
151034              "license": {
151035                "id": "GPL-2.0-only"
151036              }
151037            },
151038            {
151039              "license": {
151040                "id": "GPL-2.0-or-later"
151041              }
151042            }
151043          ],
151044          "cpe": "cpe:2.3:a:libpam-cap:libpam-cap:1\\:2.32-1:*:*:*:*:*:*:*",
151045          "purl": "pkg:deb/ubuntu/libpam-cap@1:2.32-1?arch=amd64\u0026upstream=libcap2\u0026distro=ubuntu-20.04",
151046          "swid": {
151047            "attachment": {}
151048          },
151049          "pedigree": {},
151050          "evidence": {},
151051          "signature": {
151052            "signature": {
151053              "publicKey": {}
151054            }
151055          },
151056          "modelCard": {
151057            "modelParameters": {
151058              "approach": {}
151059            },
151060            "quantitativeAnalysis": {
151061              "graphics": {}
151062            },
151063            "considerations": {}
151064          }
151065        },
151066        {
151067          "type": "library",
151068          "bom-ref": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=e7be6c0ad703fc9a",
151069          "supplier": {},
151070          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151071          "name": "libpam-modules",
151072          "version": "1.3.1-5ubuntu4.2",
151073          "licenses": [
151074            {
151075              "license": {
151076                "name": "GPL"
151077              }
151078            }
151079          ],
151080          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
151081          "purl": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
151082          "swid": {
151083            "attachment": {}
151084          },
151085          "pedigree": {},
151086          "evidence": {},
151087          "signature": {
151088            "signature": {
151089              "publicKey": {}
151090            }
151091          },
151092          "modelCard": {
151093            "modelParameters": {
151094              "approach": {}
151095            },
151096            "quantitativeAnalysis": {
151097              "graphics": {}
151098            },
151099            "considerations": {}
151100          }
151101        },
151102        {
151103          "type": "library",
151104          "bom-ref": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=7ff667273975da27",
151105          "supplier": {},
151106          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151107          "name": "libpam-modules-bin",
151108          "version": "1.3.1-5ubuntu4.2",
151109          "licenses": [
151110            {
151111              "license": {
151112                "name": "GPL"
151113              }
151114            }
151115          ],
151116          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
151117          "purl": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
151118          "swid": {
151119            "attachment": {}
151120          },
151121          "pedigree": {},
151122          "evidence": {},
151123          "signature": {
151124            "signature": {
151125              "publicKey": {}
151126            }
151127          },
151128          "modelCard": {
151129            "modelParameters": {
151130              "approach": {}
151131            },
151132            "quantitativeAnalysis": {
151133              "graphics": {}
151134            },
151135            "considerations": {}
151136          }
151137        },
151138        {
151139          "type": "library",
151140          "bom-ref": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.2?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=47a743e8128a9af6",
151141          "supplier": {},
151142          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151143          "name": "libpam-runtime",
151144          "version": "1.3.1-5ubuntu4.2",
151145          "licenses": [
151146            {
151147              "license": {
151148                "name": "GPL"
151149              }
151150            }
151151          ],
151152          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
151153          "purl": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.2?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04",
151154          "swid": {
151155            "attachment": {}
151156          },
151157          "pedigree": {},
151158          "evidence": {},
151159          "signature": {
151160            "signature": {
151161              "publicKey": {}
151162            }
151163          },
151164          "modelCard": {
151165            "modelParameters": {
151166              "approach": {}
151167            },
151168            "quantitativeAnalysis": {
151169              "graphics": {}
151170            },
151171            "considerations": {}
151172          }
151173        },
151174        {
151175          "type": "library",
151176          "bom-ref": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=e57fbdd1e7d57983",
151177          "supplier": {},
151178          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151179          "name": "libpam0g",
151180          "version": "1.3.1-5ubuntu4.2",
151181          "licenses": [
151182            {
151183              "license": {
151184                "name": "GPL"
151185              }
151186            }
151187          ],
151188          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
151189          "purl": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
151190          "swid": {
151191            "attachment": {}
151192          },
151193          "pedigree": {},
151194          "evidence": {},
151195          "signature": {
151196            "signature": {
151197              "publicKey": {}
151198            }
151199          },
151200          "modelCard": {
151201            "modelParameters": {
151202              "approach": {}
151203            },
151204            "quantitativeAnalysis": {
151205              "graphics": {}
151206            },
151207            "considerations": {}
151208          }
151209        },
151210        {
151211          "type": "library",
151212          "bom-ref": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04\u0026package-id=ec9eb70008ed8b14",
151213          "supplier": {},
151214          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151215          "name": "libpcre2-8-0",
151216          "version": "10.34-7",
151217          "cpe": "cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.34-7:*:*:*:*:*:*:*",
151218          "purl": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04",
151219          "swid": {
151220            "attachment": {}
151221          },
151222          "pedigree": {},
151223          "evidence": {},
151224          "signature": {
151225            "signature": {
151226              "publicKey": {}
151227            }
151228          },
151229          "modelCard": {
151230            "modelParameters": {
151231              "approach": {}
151232            },
151233            "quantitativeAnalysis": {
151234              "graphics": {}
151235            },
151236            "considerations": {}
151237          }
151238        },
151239        {
151240          "type": "library",
151241          "bom-ref": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04\u0026package-id=f2af8e66c60a624",
151242          "supplier": {},
151243          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151244          "name": "libpcre3",
151245          "version": "2:8.39-12build1",
151246          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-12build1:*:*:*:*:*:*:*",
151247          "purl": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04",
151248          "swid": {
151249            "attachment": {}
151250          },
151251          "pedigree": {},
151252          "evidence": {},
151253          "signature": {
151254            "signature": {
151255              "publicKey": {}
151256            }
151257          },
151258          "modelCard": {
151259            "modelParameters": {
151260              "approach": {}
151261            },
151262            "quantitativeAnalysis": {
151263              "graphics": {}
151264            },
151265            "considerations": {}
151266          }
151267        },
151268        {
151269          "type": "library",
151270          "bom-ref": "pkg:deb/ubuntu/libperl5.30@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=8748dda005dfdd96",
151271          "supplier": {},
151272          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151273          "name": "libperl5.30",
151274          "version": "5.30.0-9ubuntu0.2",
151275          "licenses": [
151276            {
151277              "license": {
151278                "name": "Artistic"
151279              }
151280            },
151281            {
151282              "license": {
151283                "id": "Artistic-2.0"
151284              }
151285            },
151286            {
151287              "license": {
151288                "name": "Artistic-dist"
151289              }
151290            },
151291            {
151292              "license": {
151293                "id": "BSD-3-Clause"
151294              }
151295            },
151296            {
151297              "license": {
151298                "name": "BSD-3-clause-GENERIC"
151299              }
151300            },
151301            {
151302              "license": {
151303                "name": "BSD-3-clause-with-weird-numbering"
151304              }
151305            },
151306            {
151307              "license": {
151308                "name": "BSD-4-clause-POWERDOG"
151309              }
151310            },
151311            {
151312              "license": {
151313                "name": "BZIP"
151314              }
151315            },
151316            {
151317              "license": {
151318                "name": "DONT-CHANGE-THE-GPL"
151319              }
151320            },
151321            {
151322              "license": {
151323                "name": "Expat"
151324              }
151325            },
151326            {
151327              "license": {
151328                "id": "GPL-1.0-only"
151329              }
151330            },
151331            {
151332              "license": {
151333                "id": "GPL-1.0-or-later"
151334              }
151335            },
151336            {
151337              "license": {
151338                "id": "GPL-2.0-only"
151339              }
151340            },
151341            {
151342              "license": {
151343                "id": "GPL-2.0-or-later"
151344              }
151345            },
151346            {
151347              "license": {
151348                "name": "GPL-3+-WITH-BISON-EXCEPTION"
151349              }
151350            },
151351            {
151352              "license": {
151353                "name": "HSIEH-BSD"
151354              }
151355            },
151356            {
151357              "license": {
151358                "name": "HSIEH-DERIVATIVE"
151359              }
151360            },
151361            {
151362              "license": {
151363                "id": "LGPL-2.1-only"
151364              }
151365            },
151366            {
151367              "license": {
151368                "name": "REGCOMP"
151369              }
151370            },
151371            {
151372              "license": {
151373                "name": "REGCOMP,"
151374              }
151375            },
151376            {
151377              "license": {
151378                "name": "RRA-KEEP-THIS-NOTICE"
151379              }
151380            },
151381            {
151382              "license": {
151383                "name": "SDBM-PUBLIC-DOMAIN"
151384              }
151385            },
151386            {
151387              "license": {
151388                "name": "TEXT-TABS"
151389              }
151390            },
151391            {
151392              "license": {
151393                "name": "Unicode"
151394              }
151395            },
151396            {
151397              "license": {
151398                "id": "Zlib"
151399              }
151400            }
151401          ],
151402          "cpe": "cpe:2.3:a:libperl5.30:libperl5.30:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
151403          "purl": "pkg:deb/ubuntu/libperl5.30@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04",
151404          "swid": {
151405            "attachment": {}
151406          },
151407          "pedigree": {},
151408          "evidence": {},
151409          "signature": {
151410            "signature": {
151411              "publicKey": {}
151412            }
151413          },
151414          "modelCard": {
151415            "modelParameters": {
151416              "approach": {}
151417            },
151418            "quantitativeAnalysis": {
151419              "graphics": {}
151420            },
151421            "considerations": {}
151422          }
151423        },
151424        {
151425          "type": "library",
151426          "bom-ref": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.2?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04\u0026package-id=1444db6c35de79c6",
151427          "supplier": {},
151428          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151429          "name": "libprocps8",
151430          "version": "2:3.3.16-1ubuntu2.2",
151431          "licenses": [
151432            {
151433              "license": {
151434                "id": "GPL-2.0-only"
151435              }
151436            },
151437            {
151438              "license": {
151439                "id": "GPL-2.0-or-later"
151440              }
151441            },
151442            {
151443              "license": {
151444                "id": "LGPL-2.0-only"
151445              }
151446            },
151447            {
151448              "license": {
151449                "id": "LGPL-2.0-or-later"
151450              }
151451            },
151452            {
151453              "license": {
151454                "id": "LGPL-2.1-only"
151455              }
151456            },
151457            {
151458              "license": {
151459                "id": "LGPL-2.1-or-later"
151460              }
151461            }
151462          ],
151463          "cpe": "cpe:2.3:a:libprocps8:libprocps8:2\\:3.3.16-1ubuntu2.2:*:*:*:*:*:*:*",
151464          "purl": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.2?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04",
151465          "swid": {
151466            "attachment": {}
151467          },
151468          "pedigree": {},
151469          "evidence": {},
151470          "signature": {
151471            "signature": {
151472              "publicKey": {}
151473            }
151474          },
151475          "modelCard": {
151476            "modelParameters": {
151477              "approach": {}
151478            },
151479            "quantitativeAnalysis": {
151480              "graphics": {}
151481            },
151482            "considerations": {}
151483          }
151484        },
151485        {
151486          "type": "library",
151487          "bom-ref": "pkg:deb/ubuntu/libpsl5@0.21.0-1ubuntu1?arch=amd64\u0026upstream=libpsl\u0026distro=ubuntu-20.04\u0026package-id=e77e76f35a3ad192",
151488          "supplier": {},
151489          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151490          "name": "libpsl5",
151491          "version": "0.21.0-1ubuntu1",
151492          "licenses": [
151493            {
151494              "license": {
151495                "name": "Chromium"
151496              }
151497            },
151498            {
151499              "license": {
151500                "id": "MIT"
151501              }
151502            }
151503          ],
151504          "cpe": "cpe:2.3:a:libpsl5:libpsl5:0.21.0-1ubuntu1:*:*:*:*:*:*:*",
151505          "purl": "pkg:deb/ubuntu/libpsl5@0.21.0-1ubuntu1?arch=amd64\u0026upstream=libpsl\u0026distro=ubuntu-20.04",
151506          "swid": {
151507            "attachment": {}
151508          },
151509          "pedigree": {},
151510          "evidence": {},
151511          "signature": {
151512            "signature": {
151513              "publicKey": {}
151514            }
151515          },
151516          "modelCard": {
151517            "modelParameters": {
151518              "approach": {}
151519            },
151520            "quantitativeAnalysis": {
151521              "graphics": {}
151522            },
151523            "considerations": {}
151524          }
151525        },
151526        {
151527          "type": "library",
151528          "bom-ref": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=b40e3316416bbdaf",
151529          "supplier": {},
151530          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151531          "name": "libpython3-stdlib",
151532          "version": "3.8.2-0ubuntu2",
151533          "cpe": "cpe:2.3:a:libpython3-stdlib:libpython3-stdlib:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
151534          "purl": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
151535          "swid": {
151536            "attachment": {}
151537          },
151538          "pedigree": {},
151539          "evidence": {},
151540          "signature": {
151541            "signature": {
151542              "publicKey": {}
151543            }
151544          },
151545          "modelCard": {
151546            "modelParameters": {
151547              "approach": {}
151548            },
151549            "quantitativeAnalysis": {
151550              "graphics": {}
151551            },
151552            "considerations": {}
151553          }
151554        },
151555        {
151556          "type": "library",
151557          "bom-ref": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=fb58dad98da64e3b",
151558          "supplier": {},
151559          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151560          "name": "libpython3.8-minimal",
151561          "version": "3.8.10-0ubuntu1~20.04",
151562          "licenses": [
151563            {
151564              "license": {
151565                "name": "By"
151566              }
151567            },
151568            {
151569              "license": {
151570                "id": "GPL-2.0-only"
151571              }
151572            },
151573            {
151574              "license": {
151575                "name": "Permission"
151576              }
151577            },
151578            {
151579              "license": {
151580                "name": "Redistribution"
151581              }
151582            },
151583            {
151584              "license": {
151585                "name": "This"
151586              }
151587            }
151588          ],
151589          "cpe": "cpe:2.3:a:libpython3.8-minimal:libpython3.8-minimal:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
151590          "purl": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
151591          "swid": {
151592            "attachment": {}
151593          },
151594          "pedigree": {},
151595          "evidence": {},
151596          "signature": {
151597            "signature": {
151598              "publicKey": {}
151599            }
151600          },
151601          "modelCard": {
151602            "modelParameters": {
151603              "approach": {}
151604            },
151605            "quantitativeAnalysis": {
151606              "graphics": {}
151607            },
151608            "considerations": {}
151609          }
151610        },
151611        {
151612          "type": "library",
151613          "bom-ref": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=54e48e611df3b41d",
151614          "supplier": {},
151615          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151616          "name": "libpython3.8-stdlib",
151617          "version": "3.8.10-0ubuntu1~20.04",
151618          "licenses": [
151619            {
151620              "license": {
151621                "name": "By"
151622              }
151623            },
151624            {
151625              "license": {
151626                "id": "GPL-2.0-only"
151627              }
151628            },
151629            {
151630              "license": {
151631                "name": "Permission"
151632              }
151633            },
151634            {
151635              "license": {
151636                "name": "Redistribution"
151637              }
151638            },
151639            {
151640              "license": {
151641                "name": "This"
151642              }
151643            }
151644          ],
151645          "cpe": "cpe:2.3:a:libpython3.8-stdlib:libpython3.8-stdlib:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
151646          "purl": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
151647          "swid": {
151648            "attachment": {}
151649          },
151650          "pedigree": {},
151651          "evidence": {},
151652          "signature": {
151653            "signature": {
151654              "publicKey": {}
151655            }
151656          },
151657          "modelCard": {
151658            "modelParameters": {
151659              "approach": {}
151660            },
151661            "quantitativeAnalysis": {
151662              "graphics": {}
151663            },
151664            "considerations": {}
151665          }
151666        },
151667        {
151668          "type": "library",
151669          "bom-ref": "pkg:deb/ubuntu/librados2@15.2.13-0ubuntu0.20.04.1?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04\u0026package-id=298550ee0e4c8b6b",
151670          "supplier": {},
151671          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151672          "name": "librados2",
151673          "version": "15.2.13-0ubuntu0.20.04.1",
151674          "licenses": [
151675            {
151676              "license": {
151677                "id": "APSL-2.0"
151678              }
151679            },
151680            {
151681              "license": {
151682                "id": "Apache-2.0"
151683              }
151684            },
151685            {
151686              "license": {
151687                "name": "BSD"
151688              }
151689            },
151690            {
151691              "license": {
151692                "id": "BSD-2-Clause"
151693              }
151694            },
151695            {
151696              "license": {
151697                "id": "BSD-3-Clause"
151698              }
151699            },
151700            {
151701              "license": {
151702                "name": "Boost"
151703              }
151704            },
151705            {
151706              "license": {
151707                "name": "Boost-Software-License-1.0"
151708              }
151709            },
151710            {
151711              "license": {
151712                "id": "CC-BY-SA-3.0"
151713              }
151714            },
151715            {
151716              "license": {
151717                "name": "Creative"
151718              }
151719            },
151720            {
151721              "license": {
151722                "name": "Expat"
151723              }
151724            },
151725            {
151726              "license": {
151727                "id": "GPL-2.0-only"
151728              }
151729            },
151730            {
151731              "license": {
151732                "id": "GPL-2.0-or-later"
151733              }
151734            },
151735            {
151736              "license": {
151737                "id": "GPL-3.0-only"
151738              }
151739            },
151740            {
151741              "license": {
151742                "name": "GPL-3/OpenSSL"
151743              }
151744            },
151745            {
151746              "license": {
151747                "id": "GPL-2.0-only"
151748              }
151749            },
151750            {
151751              "license": {
151752                "id": "GPL-3.0-only"
151753              }
151754            },
151755            {
151756              "license": {
151757                "id": "LGPL-2.0-only"
151758              }
151759            },
151760            {
151761              "license": {
151762                "id": "LGPL-2.0-or-later"
151763              }
151764            },
151765            {
151766              "license": {
151767                "id": "LGPL-2.1-only"
151768              }
151769            },
151770            {
151771              "license": {
151772                "id": "LGPL-2.1-or-later"
151773              }
151774            },
151775            {
151776              "license": {
151777                "id": "LGPL-2.0-only"
151778              }
151779            },
151780            {
151781              "license": {
151782                "id": "LGPL-2.1-only"
151783              }
151784            },
151785            {
151786              "license": {
151787                "id": "MIT"
151788              }
151789            },
151790            {
151791              "license": {
151792                "name": "Public"
151793              }
151794            },
151795            {
151796              "license": {
151797                "name": "public-domain"
151798              }
151799            }
151800          ],
151801          "cpe": "cpe:2.3:a:librados2:librados2:15.2.13-0ubuntu0.20.04.1:*:*:*:*:*:*:*",
151802          "purl": "pkg:deb/ubuntu/librados2@15.2.13-0ubuntu0.20.04.1?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04",
151803          "swid": {
151804            "attachment": {}
151805          },
151806          "pedigree": {},
151807          "evidence": {},
151808          "signature": {
151809            "signature": {
151810              "publicKey": {}
151811            }
151812          },
151813          "modelCard": {
151814            "modelParameters": {
151815              "approach": {}
151816            },
151817            "quantitativeAnalysis": {
151818              "graphics": {}
151819            },
151820            "considerations": {}
151821          }
151822        },
151823        {
151824          "type": "library",
151825          "bom-ref": "pkg:deb/ubuntu/librbd1@15.2.13-0ubuntu0.20.04.1?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04\u0026package-id=853b50c61a31c72e",
151826          "supplier": {},
151827          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151828          "name": "librbd1",
151829          "version": "15.2.13-0ubuntu0.20.04.1",
151830          "licenses": [
151831            {
151832              "license": {
151833                "id": "APSL-2.0"
151834              }
151835            },
151836            {
151837              "license": {
151838                "id": "Apache-2.0"
151839              }
151840            },
151841            {
151842              "license": {
151843                "name": "BSD"
151844              }
151845            },
151846            {
151847              "license": {
151848                "id": "BSD-2-Clause"
151849              }
151850            },
151851            {
151852              "license": {
151853                "id": "BSD-3-Clause"
151854              }
151855            },
151856            {
151857              "license": {
151858                "name": "Boost"
151859              }
151860            },
151861            {
151862              "license": {
151863                "name": "Boost-Software-License-1.0"
151864              }
151865            },
151866            {
151867              "license": {
151868                "id": "CC-BY-SA-3.0"
151869              }
151870            },
151871            {
151872              "license": {
151873                "name": "Creative"
151874              }
151875            },
151876            {
151877              "license": {
151878                "name": "Expat"
151879              }
151880            },
151881            {
151882              "license": {
151883                "id": "GPL-2.0-only"
151884              }
151885            },
151886            {
151887              "license": {
151888                "id": "GPL-2.0-or-later"
151889              }
151890            },
151891            {
151892              "license": {
151893                "id": "GPL-3.0-only"
151894              }
151895            },
151896            {
151897              "license": {
151898                "name": "GPL-3/OpenSSL"
151899              }
151900            },
151901            {
151902              "license": {
151903                "id": "GPL-2.0-only"
151904              }
151905            },
151906            {
151907              "license": {
151908                "id": "GPL-3.0-only"
151909              }
151910            },
151911            {
151912              "license": {
151913                "id": "LGPL-2.0-only"
151914              }
151915            },
151916            {
151917              "license": {
151918                "id": "LGPL-2.0-or-later"
151919              }
151920            },
151921            {
151922              "license": {
151923                "id": "LGPL-2.1-only"
151924              }
151925            },
151926            {
151927              "license": {
151928                "id": "LGPL-2.1-or-later"
151929              }
151930            },
151931            {
151932              "license": {
151933                "id": "LGPL-2.0-only"
151934              }
151935            },
151936            {
151937              "license": {
151938                "id": "LGPL-2.1-only"
151939              }
151940            },
151941            {
151942              "license": {
151943                "id": "MIT"
151944              }
151945            },
151946            {
151947              "license": {
151948                "name": "Public"
151949              }
151950            },
151951            {
151952              "license": {
151953                "name": "public-domain"
151954              }
151955            }
151956          ],
151957          "cpe": "cpe:2.3:a:librbd1:librbd1:15.2.13-0ubuntu0.20.04.1:*:*:*:*:*:*:*",
151958          "purl": "pkg:deb/ubuntu/librbd1@15.2.13-0ubuntu0.20.04.1?arch=amd64\u0026upstream=ceph\u0026distro=ubuntu-20.04",
151959          "swid": {
151960            "attachment": {}
151961          },
151962          "pedigree": {},
151963          "evidence": {},
151964          "signature": {
151965            "signature": {
151966              "publicKey": {}
151967            }
151968          },
151969          "modelCard": {
151970            "modelParameters": {
151971              "approach": {}
151972            },
151973            "quantitativeAnalysis": {
151974              "graphics": {}
151975            },
151976            "considerations": {}
151977          }
151978        },
151979        {
151980          "type": "library",
151981          "bom-ref": "pkg:deb/ubuntu/librdmacm1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04\u0026package-id=ba8ceed5ec4f0c95",
151982          "supplier": {},
151983          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
151984          "name": "librdmacm1",
151985          "version": "28.0-1ubuntu1",
151986          "licenses": [
151987            {
151988              "license": {
151989                "id": "BSD-2-Clause"
151990              }
151991            },
151992            {
151993              "license": {
151994                "id": "BSD-3-Clause"
151995              }
151996            },
151997            {
151998              "license": {
151999                "name": "BSD-MIT"
152000              }
152001            },
152002            {
152003              "license": {
152004                "name": "CC0"
152005              }
152006            },
152007            {
152008              "license": {
152009                "id": "CPL-1.0"
152010              }
152011            },
152012            {
152013              "license": {
152014                "id": "GPL-2.0-only"
152015              }
152016            },
152017            {
152018              "license": {
152019                "id": "GPL-2.0-or-later"
152020              }
152021            },
152022            {
152023              "license": {
152024                "id": "MIT"
152025              }
152026            }
152027          ],
152028          "cpe": "cpe:2.3:a:librdmacm1:librdmacm1:28.0-1ubuntu1:*:*:*:*:*:*:*",
152029          "purl": "pkg:deb/ubuntu/librdmacm1@28.0-1ubuntu1?arch=amd64\u0026upstream=rdma-core\u0026distro=ubuntu-20.04",
152030          "swid": {
152031            "attachment": {}
152032          },
152033          "pedigree": {},
152034          "evidence": {},
152035          "signature": {
152036            "signature": {
152037              "publicKey": {}
152038            }
152039          },
152040          "modelCard": {
152041            "modelParameters": {
152042              "approach": {}
152043            },
152044            "quantitativeAnalysis": {
152045              "graphics": {}
152046            },
152047            "considerations": {}
152048          }
152049        },
152050        {
152051          "type": "library",
152052          "bom-ref": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=67b876656fcd9e68",
152053          "supplier": {},
152054          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152055          "name": "libreadline8",
152056          "version": "8.0-4",
152057          "licenses": [
152058            {
152059              "license": {
152060                "name": "GFDL"
152061              }
152062            },
152063            {
152064              "license": {
152065                "id": "GPL-3.0-only"
152066              }
152067            }
152068          ],
152069          "cpe": "cpe:2.3:a:libreadline8:libreadline8:8.0-4:*:*:*:*:*:*:*",
152070          "purl": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04",
152071          "swid": {
152072            "attachment": {}
152073          },
152074          "pedigree": {},
152075          "evidence": {},
152076          "signature": {
152077            "signature": {
152078              "publicKey": {}
152079            }
152080          },
152081          "modelCard": {
152082            "modelParameters": {
152083              "approach": {}
152084            },
152085            "quantitativeAnalysis": {
152086              "graphics": {}
152087            },
152088            "considerations": {}
152089          }
152090        },
152091        {
152092          "type": "library",
152093          "bom-ref": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=68e35bc456818613",
152094          "supplier": {},
152095          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152096          "name": "libroken18-heimdal",
152097          "version": "7.7.0+dfsg-1ubuntu1",
152098          "licenses": [
152099            {
152100              "license": {
152101                "id": "BSD-3-Clause"
152102              }
152103            },
152104            {
152105              "license": {
152106                "id": "GPL-2.0-only"
152107              }
152108            },
152109            {
152110              "license": {
152111                "id": "GPL-2.0-or-later"
152112              }
152113            },
152114            {
152115              "license": {
152116                "name": "custom"
152117              }
152118            }
152119          ],
152120          "cpe": "cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
152121          "purl": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
152122          "swid": {
152123            "attachment": {}
152124          },
152125          "pedigree": {},
152126          "evidence": {},
152127          "signature": {
152128            "signature": {
152129              "publicKey": {}
152130            }
152131          },
152132          "modelCard": {
152133            "modelParameters": {
152134              "approach": {}
152135            },
152136            "quantitativeAnalysis": {
152137              "graphics": {}
152138            },
152139            "considerations": {}
152140          }
152141        },
152142        {
152143          "type": "library",
152144          "bom-ref": "pkg:deb/ubuntu/librtmp1@2.4+20151223.gitfa8646d.1-2build1?arch=amd64\u0026upstream=rtmpdump\u0026distro=ubuntu-20.04\u0026package-id=ede637f87a4bfd7b",
152145          "supplier": {},
152146          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152147          "name": "librtmp1",
152148          "version": "2.4+20151223.gitfa8646d.1-2build1",
152149          "licenses": [
152150            {
152151              "license": {
152152                "id": "GPL-2.0-only"
152153              }
152154            },
152155            {
152156              "license": {
152157                "id": "LGPL-2.1-only"
152158              }
152159            }
152160          ],
152161          "cpe": "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20151223.gitfa8646d.1-2build1:*:*:*:*:*:*:*",
152162          "purl": "pkg:deb/ubuntu/librtmp1@2.4+20151223.gitfa8646d.1-2build1?arch=amd64\u0026upstream=rtmpdump\u0026distro=ubuntu-20.04",
152163          "swid": {
152164            "attachment": {}
152165          },
152166          "pedigree": {},
152167          "evidence": {},
152168          "signature": {
152169            "signature": {
152170              "publicKey": {}
152171            }
152172          },
152173          "modelCard": {
152174            "modelParameters": {
152175              "approach": {}
152176            },
152177            "quantitativeAnalysis": {
152178              "graphics": {}
152179            },
152180            "considerations": {}
152181          }
152182        },
152183        {
152184          "type": "library",
152185          "bom-ref": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=374396d82667544d",
152186          "supplier": {},
152187          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152188          "name": "libsasl2-2",
152189          "version": "2.1.27+dfsg-2",
152190          "licenses": [
152191            {
152192              "license": {
152193                "id": "BSD-4-Clause"
152194              }
152195            },
152196            {
152197              "license": {
152198                "id": "GPL-3.0-only"
152199              }
152200            },
152201            {
152202              "license": {
152203                "id": "GPL-3.0-or-later"
152204              }
152205            }
152206          ],
152207          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
152208          "purl": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
152209          "swid": {
152210            "attachment": {}
152211          },
152212          "pedigree": {},
152213          "evidence": {},
152214          "signature": {
152215            "signature": {
152216              "publicKey": {}
152217            }
152218          },
152219          "modelCard": {
152220            "modelParameters": {
152221              "approach": {}
152222            },
152223            "quantitativeAnalysis": {
152224              "graphics": {}
152225            },
152226            "considerations": {}
152227          }
152228        },
152229        {
152230          "type": "library",
152231          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=fb8d278d10c4a3cf",
152232          "supplier": {},
152233          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152234          "name": "libsasl2-modules",
152235          "version": "2.1.27+dfsg-2",
152236          "licenses": [
152237            {
152238              "license": {
152239                "id": "BSD-4-Clause"
152240              }
152241            },
152242            {
152243              "license": {
152244                "id": "GPL-3.0-only"
152245              }
152246            },
152247            {
152248              "license": {
152249                "id": "GPL-3.0-or-later"
152250              }
152251            }
152252          ],
152253          "cpe": "cpe:2.3:a:libsasl2-modules:libsasl2-modules:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
152254          "purl": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
152255          "swid": {
152256            "attachment": {}
152257          },
152258          "pedigree": {},
152259          "evidence": {},
152260          "signature": {
152261            "signature": {
152262              "publicKey": {}
152263            }
152264          },
152265          "modelCard": {
152266            "modelParameters": {
152267              "approach": {}
152268            },
152269            "quantitativeAnalysis": {
152270              "graphics": {}
152271            },
152272            "considerations": {}
152273          }
152274        },
152275        {
152276          "type": "library",
152277          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=63c3c50d36ec1d13",
152278          "supplier": {},
152279          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152280          "name": "libsasl2-modules-db",
152281          "version": "2.1.27+dfsg-2",
152282          "licenses": [
152283            {
152284              "license": {
152285                "id": "BSD-4-Clause"
152286              }
152287            },
152288            {
152289              "license": {
152290                "id": "GPL-3.0-only"
152291              }
152292            },
152293            {
152294              "license": {
152295                "id": "GPL-3.0-or-later"
152296              }
152297            }
152298          ],
152299          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
152300          "purl": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
152301          "swid": {
152302            "attachment": {}
152303          },
152304          "pedigree": {},
152305          "evidence": {},
152306          "signature": {
152307            "signature": {
152308              "publicKey": {}
152309            }
152310          },
152311          "modelCard": {
152312            "modelParameters": {
152313              "approach": {}
152314            },
152315            "quantitativeAnalysis": {
152316              "graphics": {}
152317            },
152318            "considerations": {}
152319          }
152320        },
152321        {
152322          "type": "library",
152323          "bom-ref": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04\u0026package-id=b2fd79b9c242e8e8",
152324          "supplier": {},
152325          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152326          "name": "libseccomp2",
152327          "version": "2.5.1-1ubuntu1~20.04.1",
152328          "licenses": [
152329            {
152330              "license": {
152331                "id": "LGPL-2.1-only"
152332              }
152333            }
152334          ],
152335          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.5.1-1ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
152336          "purl": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04",
152337          "swid": {
152338            "attachment": {}
152339          },
152340          "pedigree": {},
152341          "evidence": {},
152342          "signature": {
152343            "signature": {
152344              "publicKey": {}
152345            }
152346          },
152347          "modelCard": {
152348            "modelParameters": {
152349              "approach": {}
152350            },
152351            "quantitativeAnalysis": {
152352              "graphics": {}
152353            },
152354            "considerations": {}
152355          }
152356        },
152357        {
152358          "type": "library",
152359          "bom-ref": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04\u0026package-id=e5d4ae16ac79b901",
152360          "supplier": {},
152361          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152362          "name": "libselinux1",
152363          "version": "3.0-1build2",
152364          "licenses": [
152365            {
152366              "license": {
152367                "id": "GPL-2.0-only"
152368              }
152369            },
152370            {
152371              "license": {
152372                "id": "LGPL-2.1-only"
152373              }
152374            }
152375          ],
152376          "cpe": "cpe:2.3:a:libselinux1:libselinux1:3.0-1build2:*:*:*:*:*:*:*",
152377          "purl": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04",
152378          "swid": {
152379            "attachment": {}
152380          },
152381          "pedigree": {},
152382          "evidence": {},
152383          "signature": {
152384            "signature": {
152385              "publicKey": {}
152386            }
152387          },
152388          "modelCard": {
152389            "modelParameters": {
152390              "approach": {}
152391            },
152392            "quantitativeAnalysis": {
152393              "graphics": {}
152394            },
152395            "considerations": {}
152396          }
152397        },
152398        {
152399          "type": "library",
152400          "bom-ref": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=4c6cd9f68ce53262",
152401          "supplier": {},
152402          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152403          "name": "libsemanage-common",
152404          "version": "3.0-1build2",
152405          "licenses": [
152406            {
152407              "license": {
152408                "name": "GPL"
152409              }
152410            },
152411            {
152412              "license": {
152413                "name": "LGPL"
152414              }
152415            }
152416          ],
152417          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:3.0-1build2:*:*:*:*:*:*:*",
152418          "purl": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
152419          "swid": {
152420            "attachment": {}
152421          },
152422          "pedigree": {},
152423          "evidence": {},
152424          "signature": {
152425            "signature": {
152426              "publicKey": {}
152427            }
152428          },
152429          "modelCard": {
152430            "modelParameters": {
152431              "approach": {}
152432            },
152433            "quantitativeAnalysis": {
152434              "graphics": {}
152435            },
152436            "considerations": {}
152437          }
152438        },
152439        {
152440          "type": "library",
152441          "bom-ref": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=963297f19b339026",
152442          "supplier": {},
152443          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152444          "name": "libsemanage1",
152445          "version": "3.0-1build2",
152446          "licenses": [
152447            {
152448              "license": {
152449                "name": "GPL"
152450              }
152451            },
152452            {
152453              "license": {
152454                "name": "LGPL"
152455              }
152456            }
152457          ],
152458          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:3.0-1build2:*:*:*:*:*:*:*",
152459          "purl": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
152460          "swid": {
152461            "attachment": {}
152462          },
152463          "pedigree": {},
152464          "evidence": {},
152465          "signature": {
152466            "signature": {
152467              "publicKey": {}
152468            }
152469          },
152470          "modelCard": {
152471            "modelParameters": {
152472              "approach": {}
152473            },
152474            "quantitativeAnalysis": {
152475              "graphics": {}
152476            },
152477            "considerations": {}
152478          }
152479        },
152480        {
152481          "type": "library",
152482          "bom-ref": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04\u0026package-id=991afdd7bf17200c",
152483          "supplier": {},
152484          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152485          "name": "libsepol1",
152486          "version": "3.0-1",
152487          "licenses": [
152488            {
152489              "license": {
152490                "name": "GPL"
152491              }
152492            },
152493            {
152494              "license": {
152495                "name": "LGPL"
152496              }
152497            }
152498          ],
152499          "cpe": "cpe:2.3:a:libsepol1:libsepol1:3.0-1:*:*:*:*:*:*:*",
152500          "purl": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04",
152501          "swid": {
152502            "attachment": {}
152503          },
152504          "pedigree": {},
152505          "evidence": {},
152506          "signature": {
152507            "signature": {
152508              "publicKey": {}
152509            }
152510          },
152511          "modelCard": {
152512            "modelParameters": {
152513              "approach": {}
152514            },
152515            "quantitativeAnalysis": {
152516              "graphics": {}
152517            },
152518            "considerations": {}
152519          }
152520        },
152521        {
152522          "type": "library",
152523          "bom-ref": "pkg:deb/ubuntu/libsgutils2-2@1.44-1ubuntu2?arch=amd64\u0026upstream=sg3-utils\u0026distro=ubuntu-20.04\u0026package-id=5eee3420d656cf76",
152524          "supplier": {},
152525          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152526          "name": "libsgutils2-2",
152527          "version": "1.44-1ubuntu2",
152528          "licenses": [
152529            {
152530              "license": {
152531                "name": "GPL"
152532              }
152533            }
152534          ],
152535          "cpe": "cpe:2.3:a:libsgutils2-2:libsgutils2-2:1.44-1ubuntu2:*:*:*:*:*:*:*",
152536          "purl": "pkg:deb/ubuntu/libsgutils2-2@1.44-1ubuntu2?arch=amd64\u0026upstream=sg3-utils\u0026distro=ubuntu-20.04",
152537          "swid": {
152538            "attachment": {}
152539          },
152540          "pedigree": {},
152541          "evidence": {},
152542          "signature": {
152543            "signature": {
152544              "publicKey": {}
152545            }
152546          },
152547          "modelCard": {
152548            "modelParameters": {
152549              "approach": {}
152550            },
152551            "quantitativeAnalysis": {
152552              "graphics": {}
152553            },
152554            "considerations": {}
152555          }
152556        },
152557        {
152558          "type": "library",
152559          "bom-ref": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=b47d3a935260c518",
152560          "supplier": {},
152561          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152562          "name": "libsmartcols1",
152563          "version": "2.34-0.1ubuntu9.1",
152564          "licenses": [
152565            {
152566              "license": {
152567                "id": "BSD-2-Clause"
152568              }
152569            },
152570            {
152571              "license": {
152572                "id": "BSD-3-Clause"
152573              }
152574            },
152575            {
152576              "license": {
152577                "id": "BSD-4-Clause"
152578              }
152579            },
152580            {
152581              "license": {
152582                "id": "GPL-2.0-only"
152583              }
152584            },
152585            {
152586              "license": {
152587                "id": "GPL-2.0-or-later"
152588              }
152589            },
152590            {
152591              "license": {
152592                "id": "GPL-3.0-only"
152593              }
152594            },
152595            {
152596              "license": {
152597                "id": "GPL-3.0-or-later"
152598              }
152599            },
152600            {
152601              "license": {
152602                "name": "LGPL"
152603              }
152604            },
152605            {
152606              "license": {
152607                "id": "LGPL-2.0-only"
152608              }
152609            },
152610            {
152611              "license": {
152612                "id": "LGPL-2.0-or-later"
152613              }
152614            },
152615            {
152616              "license": {
152617                "id": "LGPL-2.1-only"
152618              }
152619            },
152620            {
152621              "license": {
152622                "id": "LGPL-2.1-or-later"
152623              }
152624            },
152625            {
152626              "license": {
152627                "id": "LGPL-3.0-only"
152628              }
152629            },
152630            {
152631              "license": {
152632                "id": "LGPL-3.0-or-later"
152633              }
152634            },
152635            {
152636              "license": {
152637                "id": "MIT"
152638              }
152639            },
152640            {
152641              "license": {
152642                "name": "public-domain"
152643              }
152644            }
152645          ],
152646          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
152647          "purl": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
152648          "swid": {
152649            "attachment": {}
152650          },
152651          "pedigree": {},
152652          "evidence": {},
152653          "signature": {
152654            "signature": {
152655              "publicKey": {}
152656            }
152657          },
152658          "modelCard": {
152659            "modelParameters": {
152660              "approach": {}
152661            },
152662            "quantitativeAnalysis": {
152663              "graphics": {}
152664            },
152665            "considerations": {}
152666          }
152667        },
152668        {
152669          "type": "library",
152670          "bom-ref": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04\u0026package-id=a7c7ccf11d3583d1",
152671          "supplier": {},
152672          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152673          "name": "libsqlite3-0",
152674          "version": "3.31.1-4ubuntu0.2",
152675          "licenses": [
152676            {
152677              "license": {
152678                "id": "GPL-2.0-only"
152679              }
152680            },
152681            {
152682              "license": {
152683                "id": "GPL-2.0-or-later"
152684              }
152685            },
152686            {
152687              "license": {
152688                "name": "public-domain"
152689              }
152690            }
152691          ],
152692          "cpe": "cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.31.1-4ubuntu0.2:*:*:*:*:*:*:*",
152693          "purl": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04",
152694          "swid": {
152695            "attachment": {}
152696          },
152697          "pedigree": {},
152698          "evidence": {},
152699          "signature": {
152700            "signature": {
152701              "publicKey": {}
152702            }
152703          },
152704          "modelCard": {
152705            "modelParameters": {
152706              "approach": {}
152707            },
152708            "quantitativeAnalysis": {
152709              "graphics": {}
152710            },
152711            "considerations": {}
152712          }
152713        },
152714        {
152715          "type": "library",
152716          "bom-ref": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4715894cb8165c",
152717          "supplier": {},
152718          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152719          "name": "libss2",
152720          "version": "1.45.5-2ubuntu1",
152721          "cpe": "cpe:2.3:a:libss2:libss2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
152722          "purl": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
152723          "swid": {
152724            "attachment": {}
152725          },
152726          "pedigree": {},
152727          "evidence": {},
152728          "signature": {
152729            "signature": {
152730              "publicKey": {}
152731            }
152732          },
152733          "modelCard": {
152734            "modelParameters": {
152735              "approach": {}
152736            },
152737            "quantitativeAnalysis": {
152738              "graphics": {}
152739            },
152740            "considerations": {}
152741          }
152742        },
152743        {
152744          "type": "library",
152745          "bom-ref": "pkg:deb/ubuntu/libssh-4@0.9.3-2ubuntu2.1?arch=amd64\u0026upstream=libssh\u0026distro=ubuntu-20.04\u0026package-id=7d95b303fdc1fe32",
152746          "supplier": {},
152747          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152748          "name": "libssh-4",
152749          "version": "0.9.3-2ubuntu2.1",
152750          "licenses": [
152751            {
152752              "license": {
152753                "id": "BSD-2-Clause"
152754              }
152755            },
152756            {
152757              "license": {
152758                "id": "BSD-3-Clause"
152759              }
152760            },
152761            {
152762              "license": {
152763                "id": "LGPL-2.1-only"
152764              }
152765            },
152766            {
152767              "license": {
152768                "name": "LGPL-2.1+~OpenSSL"
152769              }
152770            },
152771            {
152772              "license": {
152773                "name": "public-domain"
152774              }
152775            }
152776          ],
152777          "cpe": "cpe:2.3:a:libssh-4:libssh-4:0.9.3-2ubuntu2.1:*:*:*:*:*:*:*",
152778          "purl": "pkg:deb/ubuntu/libssh-4@0.9.3-2ubuntu2.1?arch=amd64\u0026upstream=libssh\u0026distro=ubuntu-20.04",
152779          "swid": {
152780            "attachment": {}
152781          },
152782          "pedigree": {},
152783          "evidence": {},
152784          "signature": {
152785            "signature": {
152786              "publicKey": {}
152787            }
152788          },
152789          "modelCard": {
152790            "modelParameters": {
152791              "approach": {}
152792            },
152793            "quantitativeAnalysis": {
152794              "graphics": {}
152795            },
152796            "considerations": {}
152797          }
152798        },
152799        {
152800          "type": "library",
152801          "bom-ref": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.8?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04\u0026package-id=9228d1481eea75e3",
152802          "supplier": {},
152803          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152804          "name": "libssl1.1",
152805          "version": "1.1.1f-1ubuntu2.8",
152806          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1f-1ubuntu2.8:*:*:*:*:*:*:*",
152807          "purl": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.8?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04",
152808          "swid": {
152809            "attachment": {}
152810          },
152811          "pedigree": {},
152812          "evidence": {},
152813          "signature": {
152814            "signature": {
152815              "publicKey": {}
152816            }
152817          },
152818          "modelCard": {
152819            "modelParameters": {
152820              "approach": {}
152821            },
152822            "quantitativeAnalysis": {
152823              "graphics": {}
152824            },
152825            "considerations": {}
152826          }
152827        },
152828        {
152829          "type": "library",
152830          "bom-ref": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=241fcb3d9b65153a",
152831          "supplier": {},
152832          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152833          "name": "libstdc++6",
152834          "version": "10.3.0-1ubuntu1~20.04",
152835          "licenses": [
152836            {
152837              "license": {
152838                "name": "Artistic"
152839              }
152840            },
152841            {
152842              "license": {
152843                "id": "GFDL-1.2-only"
152844              }
152845            },
152846            {
152847              "license": {
152848                "name": "GPL"
152849              }
152850            },
152851            {
152852              "license": {
152853                "id": "GPL-2.0-only"
152854              }
152855            },
152856            {
152857              "license": {
152858                "id": "GPL-3.0-only"
152859              }
152860            },
152861            {
152862              "license": {
152863                "name": "LGPL"
152864              }
152865            }
152866          ],
152867          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
152868          "purl": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
152869          "swid": {
152870            "attachment": {}
152871          },
152872          "pedigree": {},
152873          "evidence": {},
152874          "signature": {
152875            "signature": {
152876              "publicKey": {}
152877            }
152878          },
152879          "modelCard": {
152880            "modelParameters": {
152881              "approach": {}
152882            },
152883            "quantitativeAnalysis": {
152884              "graphics": {}
152885            },
152886            "considerations": {}
152887          }
152888        },
152889        {
152890          "type": "library",
152891          "bom-ref": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=72d1f4b2fda6e155",
152892          "supplier": {},
152893          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152894          "name": "libsystemd0",
152895          "version": "245.4-4ubuntu3.11",
152896          "licenses": [
152897            {
152898              "license": {
152899                "id": "CC0-1.0"
152900              }
152901            },
152902            {
152903              "license": {
152904                "name": "Expat"
152905              }
152906            },
152907            {
152908              "license": {
152909                "id": "GPL-2.0-only"
152910              }
152911            },
152912            {
152913              "license": {
152914                "id": "GPL-2.0-or-later"
152915              }
152916            },
152917            {
152918              "license": {
152919                "id": "LGPL-2.1-only"
152920              }
152921            },
152922            {
152923              "license": {
152924                "id": "LGPL-2.1-or-later"
152925              }
152926            },
152927            {
152928              "license": {
152929                "name": "public-domain"
152930              }
152931            }
152932          ],
152933          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:245.4-4ubuntu3.11:*:*:*:*:*:*:*",
152934          "purl": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
152935          "swid": {
152936            "attachment": {}
152937          },
152938          "pedigree": {},
152939          "evidence": {},
152940          "signature": {
152941            "signature": {
152942              "publicKey": {}
152943            }
152944          },
152945          "modelCard": {
152946            "modelParameters": {
152947              "approach": {}
152948            },
152949            "quantitativeAnalysis": {
152950              "graphics": {}
152951            },
152952            "considerations": {}
152953          }
152954        },
152955        {
152956          "type": "library",
152957          "bom-ref": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a290c35fc0220ba0",
152958          "supplier": {},
152959          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
152960          "name": "libtasn1-6",
152961          "version": "4.16.0-2",
152962          "licenses": [
152963            {
152964              "license": {
152965                "id": "GFDL-1.3-only"
152966              }
152967            },
152968            {
152969              "license": {
152970                "id": "GPL-3.0-only"
152971              }
152972            },
152973            {
152974              "license": {
152975                "name": "LGPL"
152976              }
152977            },
152978            {
152979              "license": {
152980                "id": "LGPL-2.1-only"
152981              }
152982            }
152983          ],
152984          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2:*:*:*:*:*:*:*",
152985          "purl": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04",
152986          "swid": {
152987            "attachment": {}
152988          },
152989          "pedigree": {},
152990          "evidence": {},
152991          "signature": {
152992            "signature": {
152993              "publicKey": {}
152994            }
152995          },
152996          "modelCard": {
152997            "modelParameters": {
152998              "approach": {}
152999            },
153000            "quantitativeAnalysis": {
153001              "graphics": {}
153002            },
153003            "considerations": {}
153004          }
153005        },
153006        {
153007          "type": "library",
153008          "bom-ref": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=72ad56d118fefea3",
153009          "supplier": {},
153010          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153011          "name": "libtinfo6",
153012          "version": "6.2-0ubuntu2",
153013          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.2-0ubuntu2:*:*:*:*:*:*:*",
153014          "purl": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
153015          "swid": {
153016            "attachment": {}
153017          },
153018          "pedigree": {},
153019          "evidence": {},
153020          "signature": {
153021            "signature": {
153022              "publicKey": {}
153023            }
153024          },
153025          "modelCard": {
153026            "modelParameters": {
153027              "approach": {}
153028            },
153029            "quantitativeAnalysis": {
153030              "graphics": {}
153031            },
153032            "considerations": {}
153033          }
153034        },
153035        {
153036          "type": "library",
153037          "bom-ref": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=ba22fe8af5722b24",
153038          "supplier": {},
153039          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153040          "name": "libtirpc-common",
153041          "version": "1.2.5-1",
153042          "licenses": [
153043            {
153044              "license": {
153045                "id": "BSD-3-Clause"
153046              }
153047            },
153048            {
153049              "license": {
153050                "id": "GPL-2.0-only"
153051              }
153052            },
153053            {
153054              "license": {
153055                "id": "LGPL-2.1-only"
153056              }
153057            }
153058          ],
153059          "cpe": "cpe:2.3:a:libtirpc-common:libtirpc-common:1.2.5-1:*:*:*:*:*:*:*",
153060          "purl": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
153061          "swid": {
153062            "attachment": {}
153063          },
153064          "pedigree": {},
153065          "evidence": {},
153066          "signature": {
153067            "signature": {
153068              "publicKey": {}
153069            }
153070          },
153071          "modelCard": {
153072            "modelParameters": {
153073              "approach": {}
153074            },
153075            "quantitativeAnalysis": {
153076              "graphics": {}
153077            },
153078            "considerations": {}
153079          }
153080        },
153081        {
153082          "type": "library",
153083          "bom-ref": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=57b2bfa0a8467ab7",
153084          "supplier": {},
153085          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153086          "name": "libtirpc3",
153087          "version": "1.2.5-1",
153088          "licenses": [
153089            {
153090              "license": {
153091                "id": "BSD-3-Clause"
153092              }
153093            },
153094            {
153095              "license": {
153096                "id": "GPL-2.0-only"
153097              }
153098            },
153099            {
153100              "license": {
153101                "id": "LGPL-2.1-only"
153102              }
153103            }
153104          ],
153105          "cpe": "cpe:2.3:a:libtirpc3:libtirpc3:1.2.5-1:*:*:*:*:*:*:*",
153106          "purl": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
153107          "swid": {
153108            "attachment": {}
153109          },
153110          "pedigree": {},
153111          "evidence": {},
153112          "signature": {
153113            "signature": {
153114              "publicKey": {}
153115            }
153116          },
153117          "modelCard": {
153118            "modelParameters": {
153119              "approach": {}
153120            },
153121            "quantitativeAnalysis": {
153122              "graphics": {}
153123            },
153124            "considerations": {}
153125          }
153126        },
153127        {
153128          "type": "library",
153129          "bom-ref": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=28d962536291b482",
153130          "supplier": {},
153131          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153132          "name": "libudev1",
153133          "version": "245.4-4ubuntu3.11",
153134          "licenses": [
153135            {
153136              "license": {
153137                "id": "CC0-1.0"
153138              }
153139            },
153140            {
153141              "license": {
153142                "name": "Expat"
153143              }
153144            },
153145            {
153146              "license": {
153147                "id": "GPL-2.0-only"
153148              }
153149            },
153150            {
153151              "license": {
153152                "id": "GPL-2.0-or-later"
153153              }
153154            },
153155            {
153156              "license": {
153157                "id": "LGPL-2.1-only"
153158              }
153159            },
153160            {
153161              "license": {
153162                "id": "LGPL-2.1-or-later"
153163              }
153164            },
153165            {
153166              "license": {
153167                "name": "public-domain"
153168              }
153169            }
153170          ],
153171          "cpe": "cpe:2.3:a:libudev1:libudev1:245.4-4ubuntu3.11:*:*:*:*:*:*:*",
153172          "purl": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
153173          "swid": {
153174            "attachment": {}
153175          },
153176          "pedigree": {},
153177          "evidence": {},
153178          "signature": {
153179            "signature": {
153180              "publicKey": {}
153181            }
153182          },
153183          "modelCard": {
153184            "modelParameters": {
153185              "approach": {}
153186            },
153187            "quantitativeAnalysis": {
153188              "graphics": {}
153189            },
153190            "considerations": {}
153191          }
153192        },
153193        {
153194          "type": "library",
153195          "bom-ref": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04\u0026package-id=3140ffa70dcd9831",
153196          "supplier": {},
153197          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153198          "name": "libunistring2",
153199          "version": "0.9.10-2",
153200          "licenses": [
153201            {
153202              "license": {
153203                "name": "FreeSoftware"
153204              }
153205            },
153206            {
153207              "license": {
153208                "id": "GFDL-1.2-only"
153209              }
153210            },
153211            {
153212              "license": {
153213                "name": "GFDL-1.2+"
153214              }
153215            },
153216            {
153217              "license": {
153218                "id": "GPL-2.0-only"
153219              }
153220            },
153221            {
153222              "license": {
153223                "id": "GPL-2.0-or-later"
153224              }
153225            },
153226            {
153227              "license": {
153228                "id": "GPL-3.0-only"
153229              }
153230            },
153231            {
153232              "license": {
153233                "id": "GPL-3.0-or-later"
153234              }
153235            },
153236            {
153237              "license": {
153238                "id": "LGPL-3.0-only"
153239              }
153240            },
153241            {
153242              "license": {
153243                "id": "LGPL-3.0-or-later"
153244              }
153245            },
153246            {
153247              "license": {
153248                "id": "MIT"
153249              }
153250            }
153251          ],
153252          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-2:*:*:*:*:*:*:*",
153253          "purl": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04",
153254          "swid": {
153255            "attachment": {}
153256          },
153257          "pedigree": {},
153258          "evidence": {},
153259          "signature": {
153260            "signature": {
153261              "publicKey": {}
153262            }
153263          },
153264          "modelCard": {
153265            "modelParameters": {
153266              "approach": {}
153267            },
153268            "quantitativeAnalysis": {
153269              "graphics": {}
153270            },
153271            "considerations": {}
153272          }
153273        },
153274        {
153275          "type": "library",
153276          "bom-ref": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=5395a07c00002ea6",
153277          "supplier": {},
153278          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153279          "name": "libuuid1",
153280          "version": "2.34-0.1ubuntu9.1",
153281          "licenses": [
153282            {
153283              "license": {
153284                "id": "BSD-2-Clause"
153285              }
153286            },
153287            {
153288              "license": {
153289                "id": "BSD-3-Clause"
153290              }
153291            },
153292            {
153293              "license": {
153294                "id": "BSD-4-Clause"
153295              }
153296            },
153297            {
153298              "license": {
153299                "id": "GPL-2.0-only"
153300              }
153301            },
153302            {
153303              "license": {
153304                "id": "GPL-2.0-or-later"
153305              }
153306            },
153307            {
153308              "license": {
153309                "id": "GPL-3.0-only"
153310              }
153311            },
153312            {
153313              "license": {
153314                "id": "GPL-3.0-or-later"
153315              }
153316            },
153317            {
153318              "license": {
153319                "name": "LGPL"
153320              }
153321            },
153322            {
153323              "license": {
153324                "id": "LGPL-2.0-only"
153325              }
153326            },
153327            {
153328              "license": {
153329                "id": "LGPL-2.0-or-later"
153330              }
153331            },
153332            {
153333              "license": {
153334                "id": "LGPL-2.1-only"
153335              }
153336            },
153337            {
153338              "license": {
153339                "id": "LGPL-2.1-or-later"
153340              }
153341            },
153342            {
153343              "license": {
153344                "id": "LGPL-3.0-only"
153345              }
153346            },
153347            {
153348              "license": {
153349                "id": "LGPL-3.0-or-later"
153350              }
153351            },
153352            {
153353              "license": {
153354                "id": "MIT"
153355              }
153356            },
153357            {
153358              "license": {
153359                "name": "public-domain"
153360              }
153361            }
153362          ],
153363          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
153364          "purl": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
153365          "swid": {
153366            "attachment": {}
153367          },
153368          "pedigree": {},
153369          "evidence": {},
153370          "signature": {
153371            "signature": {
153372              "publicKey": {}
153373            }
153374          },
153375          "modelCard": {
153376            "modelParameters": {
153377              "approach": {}
153378            },
153379            "quantitativeAnalysis": {
153380              "graphics": {}
153381            },
153382            "considerations": {}
153383          }
153384        },
153385        {
153386          "type": "library",
153387          "bom-ref": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=7b0e172efdb36a99",
153388          "supplier": {},
153389          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153390          "name": "libwind0-heimdal",
153391          "version": "7.7.0+dfsg-1ubuntu1",
153392          "licenses": [
153393            {
153394              "license": {
153395                "id": "BSD-3-Clause"
153396              }
153397            },
153398            {
153399              "license": {
153400                "id": "GPL-2.0-only"
153401              }
153402            },
153403            {
153404              "license": {
153405                "id": "GPL-2.0-or-later"
153406              }
153407            },
153408            {
153409              "license": {
153410                "name": "custom"
153411              }
153412            }
153413          ],
153414          "cpe": "cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
153415          "purl": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
153416          "swid": {
153417            "attachment": {}
153418          },
153419          "pedigree": {},
153420          "evidence": {},
153421          "signature": {
153422            "signature": {
153423              "publicKey": {}
153424            }
153425          },
153426          "modelCard": {
153427            "modelParameters": {
153428              "approach": {}
153429            },
153430            "quantitativeAnalysis": {
153431              "graphics": {}
153432            },
153433            "considerations": {}
153434          }
153435        },
153436        {
153437          "type": "library",
153438          "bom-ref": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04\u0026package-id=5b14391c61bb94f1",
153439          "supplier": {},
153440          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153441          "name": "libwrap0",
153442          "version": "7.6.q-30",
153443          "cpe": "cpe:2.3:a:libwrap0:libwrap0:7.6.q-30:*:*:*:*:*:*:*",
153444          "purl": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04",
153445          "swid": {
153446            "attachment": {}
153447          },
153448          "pedigree": {},
153449          "evidence": {},
153450          "signature": {
153451            "signature": {
153452              "publicKey": {}
153453            }
153454          },
153455          "modelCard": {
153456            "modelParameters": {
153457              "approach": {}
153458            },
153459            "quantitativeAnalysis": {
153460              "graphics": {}
153461            },
153462            "considerations": {}
153463          }
153464        },
153465        {
153466          "type": "library",
153467          "bom-ref": "pkg:deb/ubuntu/libxml2@2.9.10+dfsg-5ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=5227ee2e55b78734",
153468          "supplier": {},
153469          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153470          "name": "libxml2",
153471          "version": "2.9.10+dfsg-5ubuntu0.20.04.1",
153472          "licenses": [
153473            {
153474              "license": {
153475                "id": "ISC"
153476              }
153477            },
153478            {
153479              "license": {
153480                "name": "MIT-1"
153481              }
153482            }
153483          ],
153484          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.10\\+dfsg-5ubuntu0.20.04.1:*:*:*:*:*:*:*",
153485          "purl": "pkg:deb/ubuntu/libxml2@2.9.10+dfsg-5ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
153486          "swid": {
153487            "attachment": {}
153488          },
153489          "pedigree": {},
153490          "evidence": {},
153491          "signature": {
153492            "signature": {
153493              "publicKey": {}
153494            }
153495          },
153496          "modelCard": {
153497            "modelParameters": {
153498              "approach": {}
153499            },
153500            "quantitativeAnalysis": {
153501              "graphics": {}
153502            },
153503            "considerations": {}
153504          }
153505        },
153506        {
153507          "type": "library",
153508          "bom-ref": "pkg:deb/ubuntu/libxtables12@1.8.4-3ubuntu2?arch=amd64\u0026upstream=iptables\u0026distro=ubuntu-20.04\u0026package-id=440c57e95fc3a35c",
153509          "supplier": {},
153510          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153511          "name": "libxtables12",
153512          "version": "1.8.4-3ubuntu2",
153513          "licenses": [
153514            {
153515              "license": {
153516                "name": "Artistic"
153517              }
153518            },
153519            {
153520              "license": {
153521                "id": "GPL-2.0-only"
153522              }
153523            },
153524            {
153525              "license": {
153526                "id": "GPL-2.0-or-later"
153527              }
153528            },
153529            {
153530              "license": {
153531                "name": "custom"
153532              }
153533            }
153534          ],
153535          "cpe": "cpe:2.3:a:libxtables12:libxtables12:1.8.4-3ubuntu2:*:*:*:*:*:*:*",
153536          "purl": "pkg:deb/ubuntu/libxtables12@1.8.4-3ubuntu2?arch=amd64\u0026upstream=iptables\u0026distro=ubuntu-20.04",
153537          "swid": {
153538            "attachment": {}
153539          },
153540          "pedigree": {},
153541          "evidence": {},
153542          "signature": {
153543            "signature": {
153544              "publicKey": {}
153545            }
153546          },
153547          "modelCard": {
153548            "modelParameters": {
153549              "approach": {}
153550            },
153551            "quantitativeAnalysis": {
153552              "graphics": {}
153553            },
153554            "considerations": {}
153555          }
153556        },
153557        {
153558          "type": "library",
153559          "bom-ref": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04\u0026package-id=47cff0564e160066",
153560          "supplier": {},
153561          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153562          "name": "libzstd1",
153563          "version": "1.4.4+dfsg-3ubuntu0.1",
153564          "licenses": [
153565            {
153566              "license": {
153567                "id": "BSD-3-Clause"
153568              }
153569            },
153570            {
153571              "license": {
153572                "name": "Expat"
153573              }
153574            },
153575            {
153576              "license": {
153577                "id": "GPL-2.0-only"
153578              }
153579            },
153580            {
153581              "license": {
153582                "id": "GPL-2.0-or-later"
153583              }
153584            },
153585            {
153586              "license": {
153587                "id": "Zlib"
153588              }
153589            }
153590          ],
153591          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.4\\+dfsg-3ubuntu0.1:*:*:*:*:*:*:*",
153592          "purl": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04",
153593          "swid": {
153594            "attachment": {}
153595          },
153596          "pedigree": {},
153597          "evidence": {},
153598          "signature": {
153599            "signature": {
153600              "publicKey": {}
153601            }
153602          },
153603          "modelCard": {
153604            "modelParameters": {
153605              "approach": {}
153606            },
153607            "quantitativeAnalysis": {
153608              "graphics": {}
153609            },
153610            "considerations": {}
153611          }
153612        },
153613        {
153614          "type": "library",
153615          "bom-ref": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=bb92db08e65352ae",
153616          "supplier": {},
153617          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153618          "name": "login",
153619          "version": "1:4.8.1-1ubuntu5.20.04",
153620          "licenses": [
153621            {
153622              "license": {
153623                "id": "GPL-2.0-only"
153624              }
153625            }
153626          ],
153627          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1ubuntu5.20.04:*:*:*:*:*:*:*",
153628          "purl": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
153629          "swid": {
153630            "attachment": {}
153631          },
153632          "pedigree": {},
153633          "evidence": {},
153634          "signature": {
153635            "signature": {
153636              "publicKey": {}
153637            }
153638          },
153639          "modelCard": {
153640            "modelParameters": {
153641              "approach": {}
153642            },
153643            "quantitativeAnalysis": {
153644              "graphics": {}
153645            },
153646            "considerations": {}
153647          }
153648        },
153649        {
153650          "type": "library",
153651          "bom-ref": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=cb23947502a7c38d",
153652          "supplier": {},
153653          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153654          "name": "login",
153655          "version": "1:4.8.1-1ubuntu5.20.04.1",
153656          "licenses": [
153657            {
153658              "license": {
153659                "id": "GPL-2.0-only"
153660              }
153661            }
153662          ],
153663          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
153664          "purl": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
153665          "swid": {
153666            "attachment": {}
153667          },
153668          "pedigree": {},
153669          "evidence": {},
153670          "signature": {
153671            "signature": {
153672              "publicKey": {}
153673            }
153674          },
153675          "modelCard": {
153676            "modelParameters": {
153677              "approach": {}
153678            },
153679            "quantitativeAnalysis": {
153680              "graphics": {}
153681            },
153682            "considerations": {}
153683          }
153684        },
153685        {
153686          "type": "library",
153687          "bom-ref": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4a92556bee4b4f91",
153688          "supplier": {},
153689          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153690          "name": "logsave",
153691          "version": "1.45.5-2ubuntu1",
153692          "licenses": [
153693            {
153694              "license": {
153695                "id": "GPL-2.0-only"
153696              }
153697            },
153698            {
153699              "license": {
153700                "id": "LGPL-2.0-only"
153701              }
153702            }
153703          ],
153704          "cpe": "cpe:2.3:a:logsave:logsave:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
153705          "purl": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
153706          "swid": {
153707            "attachment": {}
153708          },
153709          "pedigree": {},
153710          "evidence": {},
153711          "signature": {
153712            "signature": {
153713              "publicKey": {}
153714            }
153715          },
153716          "modelCard": {
153717            "modelParameters": {
153718              "approach": {}
153719            },
153720            "quantitativeAnalysis": {
153721              "graphics": {}
153722            },
153723            "considerations": {}
153724          }
153725        },
153726        {
153727          "type": "library",
153728          "bom-ref": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04\u0026package-id=b76348b7f1282c61",
153729          "supplier": {},
153730          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153731          "name": "lsb-base",
153732          "version": "11.1.0ubuntu2",
153733          "licenses": [
153734            {
153735              "license": {
153736                "id": "BSD-3-Clause"
153737              }
153738            },
153739            {
153740              "license": {
153741                "id": "GPL-2.0-only"
153742              }
153743            }
153744          ],
153745          "cpe": "cpe:2.3:a:lsb-base:lsb-base:11.1.0ubuntu2:*:*:*:*:*:*:*",
153746          "purl": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04",
153747          "swid": {
153748            "attachment": {}
153749          },
153750          "pedigree": {},
153751          "evidence": {},
153752          "signature": {
153753            "signature": {
153754              "publicKey": {}
153755            }
153756          },
153757          "modelCard": {
153758            "modelParameters": {
153759              "approach": {}
153760            },
153761            "quantitativeAnalysis": {
153762              "graphics": {}
153763            },
153764            "considerations": {}
153765          }
153766        },
153767        {
153768          "type": "library",
153769          "bom-ref": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=435885c82afbf721",
153770          "supplier": {},
153771          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153772          "name": "mawk",
153773          "version": "1.3.4.20200120-2",
153774          "licenses": [
153775            {
153776              "license": {
153777                "id": "GPL-2.0-only"
153778              }
153779            }
153780          ],
153781          "cpe": "cpe:2.3:a:mawk:mawk:1.3.4.20200120-2:*:*:*:*:*:*:*",
153782          "purl": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04",
153783          "swid": {
153784            "attachment": {}
153785          },
153786          "pedigree": {},
153787          "evidence": {},
153788          "signature": {
153789            "signature": {
153790              "publicKey": {}
153791            }
153792          },
153793          "modelCard": {
153794            "modelParameters": {
153795              "approach": {}
153796            },
153797            "quantitativeAnalysis": {
153798              "graphics": {}
153799            },
153800            "considerations": {}
153801          }
153802        },
153803        {
153804          "type": "library",
153805          "bom-ref": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=405891a224258a92",
153806          "supplier": {},
153807          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153808          "name": "mime-support",
153809          "version": "3.64ubuntu1",
153810          "licenses": [
153811            {
153812              "license": {
153813                "name": "Bellcore"
153814              }
153815            },
153816            {
153817              "license": {
153818                "name": "ad-hoc"
153819              }
153820            }
153821          ],
153822          "cpe": "cpe:2.3:a:mime-support:mime-support:3.64ubuntu1:*:*:*:*:*:*:*",
153823          "purl": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04",
153824          "swid": {
153825            "attachment": {}
153826          },
153827          "pedigree": {},
153828          "evidence": {},
153829          "signature": {
153830            "signature": {
153831              "publicKey": {}
153832            }
153833          },
153834          "modelCard": {
153835            "modelParameters": {
153836              "approach": {}
153837            },
153838            "quantitativeAnalysis": {
153839              "graphics": {}
153840            },
153841            "considerations": {}
153842          }
153843        },
153844        {
153845          "type": "library",
153846          "bom-ref": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=fa4ef6b12af7900c",
153847          "supplier": {},
153848          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153849          "name": "mount",
153850          "version": "2.34-0.1ubuntu9.1",
153851          "licenses": [
153852            {
153853              "license": {
153854                "id": "BSD-2-Clause"
153855              }
153856            },
153857            {
153858              "license": {
153859                "id": "BSD-3-Clause"
153860              }
153861            },
153862            {
153863              "license": {
153864                "id": "BSD-4-Clause"
153865              }
153866            },
153867            {
153868              "license": {
153869                "id": "GPL-2.0-only"
153870              }
153871            },
153872            {
153873              "license": {
153874                "id": "GPL-2.0-or-later"
153875              }
153876            },
153877            {
153878              "license": {
153879                "id": "GPL-3.0-only"
153880              }
153881            },
153882            {
153883              "license": {
153884                "id": "GPL-3.0-or-later"
153885              }
153886            },
153887            {
153888              "license": {
153889                "name": "LGPL"
153890              }
153891            },
153892            {
153893              "license": {
153894                "id": "LGPL-2.0-only"
153895              }
153896            },
153897            {
153898              "license": {
153899                "id": "LGPL-2.0-or-later"
153900              }
153901            },
153902            {
153903              "license": {
153904                "id": "LGPL-2.1-only"
153905              }
153906            },
153907            {
153908              "license": {
153909                "id": "LGPL-2.1-or-later"
153910              }
153911            },
153912            {
153913              "license": {
153914                "id": "LGPL-3.0-only"
153915              }
153916            },
153917            {
153918              "license": {
153919                "id": "LGPL-3.0-or-later"
153920              }
153921            },
153922            {
153923              "license": {
153924                "id": "MIT"
153925              }
153926            },
153927            {
153928              "license": {
153929                "name": "public-domain"
153930              }
153931            }
153932          ],
153933          "cpe": "cpe:2.3:a:mount:mount:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
153934          "purl": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
153935          "swid": {
153936            "attachment": {}
153937          },
153938          "pedigree": {},
153939          "evidence": {},
153940          "signature": {
153941            "signature": {
153942              "publicKey": {}
153943            }
153944          },
153945          "modelCard": {
153946            "modelParameters": {
153947              "approach": {}
153948            },
153949            "quantitativeAnalysis": {
153950              "graphics": {}
153951            },
153952            "considerations": {}
153953          }
153954        },
153955        {
153956          "type": "library",
153957          "bom-ref": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d7393defd95e4554",
153958          "supplier": {},
153959          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153960          "name": "ncurses-base",
153961          "version": "6.2-0ubuntu2",
153962          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.2-0ubuntu2:*:*:*:*:*:*:*",
153963          "purl": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
153964          "swid": {
153965            "attachment": {}
153966          },
153967          "pedigree": {},
153968          "evidence": {},
153969          "signature": {
153970            "signature": {
153971              "publicKey": {}
153972            }
153973          },
153974          "modelCard": {
153975            "modelParameters": {
153976              "approach": {}
153977            },
153978            "quantitativeAnalysis": {
153979              "graphics": {}
153980            },
153981            "considerations": {}
153982          }
153983        },
153984        {
153985          "type": "library",
153986          "bom-ref": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d6bdd43961b680f6",
153987          "supplier": {},
153988          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
153989          "name": "ncurses-bin",
153990          "version": "6.2-0ubuntu2",
153991          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.2-0ubuntu2:*:*:*:*:*:*:*",
153992          "purl": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
153993          "swid": {
153994            "attachment": {}
153995          },
153996          "pedigree": {},
153997          "evidence": {},
153998          "signature": {
153999            "signature": {
154000              "publicKey": {}
154001            }
154002          },
154003          "modelCard": {
154004            "modelParameters": {
154005              "approach": {}
154006            },
154007            "quantitativeAnalysis": {
154008              "graphics": {}
154009            },
154010            "considerations": {}
154011          }
154012        },
154013        {
154014          "type": "library",
154015          "bom-ref": "pkg:deb/ubuntu/netbase@6.1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=c6847a50307ac1ba",
154016          "supplier": {},
154017          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154018          "name": "netbase",
154019          "version": "6.1",
154020          "licenses": [
154021            {
154022              "license": {
154023                "id": "GPL-2.0-only"
154024              }
154025            }
154026          ],
154027          "cpe": "cpe:2.3:a:netbase:netbase:6.1:*:*:*:*:*:*:*",
154028          "purl": "pkg:deb/ubuntu/netbase@6.1?arch=all\u0026distro=ubuntu-20.04",
154029          "swid": {
154030            "attachment": {}
154031          },
154032          "pedigree": {},
154033          "evidence": {},
154034          "signature": {
154035            "signature": {
154036              "publicKey": {}
154037            }
154038          },
154039          "modelCard": {
154040            "modelParameters": {
154041              "approach": {}
154042            },
154043            "quantitativeAnalysis": {
154044              "graphics": {}
154045            },
154046            "considerations": {}
154047          }
154048        },
154049        {
154050          "type": "library",
154051          "bom-ref": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04\u0026package-id=6a00c331080f32b7",
154052          "supplier": {},
154053          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154054          "name": "nfs-common",
154055          "version": "1:1.3.4-2.5ubuntu3.4",
154056          "licenses": [
154057            {
154058              "license": {
154059                "id": "GPL-2.0-only"
154060              }
154061            }
154062          ],
154063          "cpe": "cpe:2.3:a:nfs-common:nfs-common:1\\:1.3.4-2.5ubuntu3.4:*:*:*:*:*:*:*",
154064          "purl": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04",
154065          "swid": {
154066            "attachment": {}
154067          },
154068          "pedigree": {},
154069          "evidence": {},
154070          "signature": {
154071            "signature": {
154072              "publicKey": {}
154073            }
154074          },
154075          "modelCard": {
154076            "modelParameters": {
154077              "approach": {}
154078            },
154079            "quantitativeAnalysis": {
154080              "graphics": {}
154081            },
154082            "considerations": {}
154083          }
154084        },
154085        {
154086          "type": "library",
154087          "bom-ref": "pkg:deb/ubuntu/openssl@1.1.1f-1ubuntu2.8?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=5727f60759ec90aa",
154088          "supplier": {},
154089          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154090          "name": "openssl",
154091          "version": "1.1.1f-1ubuntu2.8",
154092          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1f-1ubuntu2.8:*:*:*:*:*:*:*",
154093          "purl": "pkg:deb/ubuntu/openssl@1.1.1f-1ubuntu2.8?arch=amd64\u0026distro=ubuntu-20.04",
154094          "swid": {
154095            "attachment": {}
154096          },
154097          "pedigree": {},
154098          "evidence": {},
154099          "signature": {
154100            "signature": {
154101              "publicKey": {}
154102            }
154103          },
154104          "modelCard": {
154105            "modelParameters": {
154106              "approach": {}
154107            },
154108            "quantitativeAnalysis": {
154109              "graphics": {}
154110            },
154111            "considerations": {}
154112          }
154113        },
154114        {
154115          "type": "library",
154116          "bom-ref": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=d99390960eea7b3e",
154117          "supplier": {},
154118          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154119          "name": "passwd",
154120          "version": "1:4.8.1-1ubuntu5.20.04",
154121          "licenses": [
154122            {
154123              "license": {
154124                "id": "GPL-2.0-only"
154125              }
154126            }
154127          ],
154128          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1ubuntu5.20.04:*:*:*:*:*:*:*",
154129          "purl": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
154130          "swid": {
154131            "attachment": {}
154132          },
154133          "pedigree": {},
154134          "evidence": {},
154135          "signature": {
154136            "signature": {
154137              "publicKey": {}
154138            }
154139          },
154140          "modelCard": {
154141            "modelParameters": {
154142              "approach": {}
154143            },
154144            "quantitativeAnalysis": {
154145              "graphics": {}
154146            },
154147            "considerations": {}
154148          }
154149        },
154150        {
154151          "type": "library",
154152          "bom-ref": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=c4a1ed5267891532",
154153          "supplier": {},
154154          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154155          "name": "passwd",
154156          "version": "1:4.8.1-1ubuntu5.20.04.1",
154157          "licenses": [
154158            {
154159              "license": {
154160                "id": "GPL-2.0-only"
154161              }
154162            }
154163          ],
154164          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
154165          "purl": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
154166          "swid": {
154167            "attachment": {}
154168          },
154169          "pedigree": {},
154170          "evidence": {},
154171          "signature": {
154172            "signature": {
154173              "publicKey": {}
154174            }
154175          },
154176          "modelCard": {
154177            "modelParameters": {
154178              "approach": {}
154179            },
154180            "quantitativeAnalysis": {
154181              "graphics": {}
154182            },
154183            "considerations": {}
154184          }
154185        },
154186        {
154187          "type": "library",
154188          "bom-ref": "pkg:deb/ubuntu/perl@5.30.0-9ubuntu0.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=80890d41e31d4ad9",
154189          "supplier": {},
154190          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154191          "name": "perl",
154192          "version": "5.30.0-9ubuntu0.2",
154193          "licenses": [
154194            {
154195              "license": {
154196                "name": "Artistic"
154197              }
154198            },
154199            {
154200              "license": {
154201                "id": "Artistic-2.0"
154202              }
154203            },
154204            {
154205              "license": {
154206                "name": "Artistic-dist"
154207              }
154208            },
154209            {
154210              "license": {
154211                "id": "BSD-3-Clause"
154212              }
154213            },
154214            {
154215              "license": {
154216                "name": "BSD-3-clause-GENERIC"
154217              }
154218            },
154219            {
154220              "license": {
154221                "name": "BSD-3-clause-with-weird-numbering"
154222              }
154223            },
154224            {
154225              "license": {
154226                "name": "BSD-4-clause-POWERDOG"
154227              }
154228            },
154229            {
154230              "license": {
154231                "name": "BZIP"
154232              }
154233            },
154234            {
154235              "license": {
154236                "name": "DONT-CHANGE-THE-GPL"
154237              }
154238            },
154239            {
154240              "license": {
154241                "name": "Expat"
154242              }
154243            },
154244            {
154245              "license": {
154246                "id": "GPL-1.0-only"
154247              }
154248            },
154249            {
154250              "license": {
154251                "id": "GPL-1.0-or-later"
154252              }
154253            },
154254            {
154255              "license": {
154256                "id": "GPL-2.0-only"
154257              }
154258            },
154259            {
154260              "license": {
154261                "id": "GPL-2.0-or-later"
154262              }
154263            },
154264            {
154265              "license": {
154266                "name": "GPL-3+-WITH-BISON-EXCEPTION"
154267              }
154268            },
154269            {
154270              "license": {
154271                "name": "HSIEH-BSD"
154272              }
154273            },
154274            {
154275              "license": {
154276                "name": "HSIEH-DERIVATIVE"
154277              }
154278            },
154279            {
154280              "license": {
154281                "id": "LGPL-2.1-only"
154282              }
154283            },
154284            {
154285              "license": {
154286                "name": "REGCOMP"
154287              }
154288            },
154289            {
154290              "license": {
154291                "name": "REGCOMP,"
154292              }
154293            },
154294            {
154295              "license": {
154296                "name": "RRA-KEEP-THIS-NOTICE"
154297              }
154298            },
154299            {
154300              "license": {
154301                "name": "SDBM-PUBLIC-DOMAIN"
154302              }
154303            },
154304            {
154305              "license": {
154306                "name": "TEXT-TABS"
154307              }
154308            },
154309            {
154310              "license": {
154311                "name": "Unicode"
154312              }
154313            },
154314            {
154315              "license": {
154316                "id": "Zlib"
154317              }
154318            }
154319          ],
154320          "cpe": "cpe:2.3:a:perl:perl:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
154321          "purl": "pkg:deb/ubuntu/perl@5.30.0-9ubuntu0.2?arch=amd64\u0026distro=ubuntu-20.04",
154322          "swid": {
154323            "attachment": {}
154324          },
154325          "pedigree": {},
154326          "evidence": {},
154327          "signature": {
154328            "signature": {
154329              "publicKey": {}
154330            }
154331          },
154332          "modelCard": {
154333            "modelParameters": {
154334              "approach": {}
154335            },
154336            "quantitativeAnalysis": {
154337              "graphics": {}
154338            },
154339            "considerations": {}
154340          }
154341        },
154342        {
154343          "type": "library",
154344          "bom-ref": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=eab1752e76cf29f",
154345          "supplier": {},
154346          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154347          "name": "perl-base",
154348          "version": "5.30.0-9ubuntu0.2",
154349          "licenses": [
154350            {
154351              "license": {
154352                "name": "Artistic"
154353              }
154354            },
154355            {
154356              "license": {
154357                "id": "Artistic-2.0"
154358              }
154359            },
154360            {
154361              "license": {
154362                "name": "Artistic-dist"
154363              }
154364            },
154365            {
154366              "license": {
154367                "id": "BSD-3-Clause"
154368              }
154369            },
154370            {
154371              "license": {
154372                "name": "BSD-3-clause-GENERIC"
154373              }
154374            },
154375            {
154376              "license": {
154377                "name": "BSD-3-clause-with-weird-numbering"
154378              }
154379            },
154380            {
154381              "license": {
154382                "name": "BSD-4-clause-POWERDOG"
154383              }
154384            },
154385            {
154386              "license": {
154387                "name": "BZIP"
154388              }
154389            },
154390            {
154391              "license": {
154392                "name": "DONT-CHANGE-THE-GPL"
154393              }
154394            },
154395            {
154396              "license": {
154397                "name": "Expat"
154398              }
154399            },
154400            {
154401              "license": {
154402                "id": "GPL-1.0-only"
154403              }
154404            },
154405            {
154406              "license": {
154407                "id": "GPL-1.0-or-later"
154408              }
154409            },
154410            {
154411              "license": {
154412                "id": "GPL-2.0-only"
154413              }
154414            },
154415            {
154416              "license": {
154417                "id": "GPL-2.0-or-later"
154418              }
154419            },
154420            {
154421              "license": {
154422                "name": "GPL-3+-WITH-BISON-EXCEPTION"
154423              }
154424            },
154425            {
154426              "license": {
154427                "name": "HSIEH-BSD"
154428              }
154429            },
154430            {
154431              "license": {
154432                "name": "HSIEH-DERIVATIVE"
154433              }
154434            },
154435            {
154436              "license": {
154437                "id": "LGPL-2.1-only"
154438              }
154439            },
154440            {
154441              "license": {
154442                "name": "REGCOMP"
154443              }
154444            },
154445            {
154446              "license": {
154447                "name": "REGCOMP,"
154448              }
154449            },
154450            {
154451              "license": {
154452                "name": "RRA-KEEP-THIS-NOTICE"
154453              }
154454            },
154455            {
154456              "license": {
154457                "name": "SDBM-PUBLIC-DOMAIN"
154458              }
154459            },
154460            {
154461              "license": {
154462                "name": "TEXT-TABS"
154463              }
154464            },
154465            {
154466              "license": {
154467                "name": "Unicode"
154468              }
154469            },
154470            {
154471              "license": {
154472                "id": "Zlib"
154473              }
154474            }
154475          ],
154476          "cpe": "cpe:2.3:a:perl-base:perl-base:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
154477          "purl": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04",
154478          "swid": {
154479            "attachment": {}
154480          },
154481          "pedigree": {},
154482          "evidence": {},
154483          "signature": {
154484            "signature": {
154485              "publicKey": {}
154486            }
154487          },
154488          "modelCard": {
154489            "modelParameters": {
154490              "approach": {}
154491            },
154492            "quantitativeAnalysis": {
154493              "graphics": {}
154494            },
154495            "considerations": {}
154496          }
154497        },
154498        {
154499          "type": "library",
154500          "bom-ref": "pkg:deb/ubuntu/perl-modules-5.30@5.30.0-9ubuntu0.2?arch=all\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=fb3bcb2d22f50638",
154501          "supplier": {},
154502          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154503          "name": "perl-modules-5.30",
154504          "version": "5.30.0-9ubuntu0.2",
154505          "licenses": [
154506            {
154507              "license": {
154508                "name": "Artistic"
154509              }
154510            },
154511            {
154512              "license": {
154513                "id": "Artistic-2.0"
154514              }
154515            },
154516            {
154517              "license": {
154518                "name": "Artistic-dist"
154519              }
154520            },
154521            {
154522              "license": {
154523                "id": "BSD-3-Clause"
154524              }
154525            },
154526            {
154527              "license": {
154528                "name": "BSD-3-clause-GENERIC"
154529              }
154530            },
154531            {
154532              "license": {
154533                "name": "BSD-3-clause-with-weird-numbering"
154534              }
154535            },
154536            {
154537              "license": {
154538                "name": "BSD-4-clause-POWERDOG"
154539              }
154540            },
154541            {
154542              "license": {
154543                "name": "BZIP"
154544              }
154545            },
154546            {
154547              "license": {
154548                "name": "DONT-CHANGE-THE-GPL"
154549              }
154550            },
154551            {
154552              "license": {
154553                "name": "Expat"
154554              }
154555            },
154556            {
154557              "license": {
154558                "id": "GPL-1.0-only"
154559              }
154560            },
154561            {
154562              "license": {
154563                "id": "GPL-1.0-or-later"
154564              }
154565            },
154566            {
154567              "license": {
154568                "id": "GPL-2.0-only"
154569              }
154570            },
154571            {
154572              "license": {
154573                "id": "GPL-2.0-or-later"
154574              }
154575            },
154576            {
154577              "license": {
154578                "name": "GPL-3+-WITH-BISON-EXCEPTION"
154579              }
154580            },
154581            {
154582              "license": {
154583                "name": "HSIEH-BSD"
154584              }
154585            },
154586            {
154587              "license": {
154588                "name": "HSIEH-DERIVATIVE"
154589              }
154590            },
154591            {
154592              "license": {
154593                "id": "LGPL-2.1-only"
154594              }
154595            },
154596            {
154597              "license": {
154598                "name": "REGCOMP"
154599              }
154600            },
154601            {
154602              "license": {
154603                "name": "REGCOMP,"
154604              }
154605            },
154606            {
154607              "license": {
154608                "name": "RRA-KEEP-THIS-NOTICE"
154609              }
154610            },
154611            {
154612              "license": {
154613                "name": "SDBM-PUBLIC-DOMAIN"
154614              }
154615            },
154616            {
154617              "license": {
154618                "name": "TEXT-TABS"
154619              }
154620            },
154621            {
154622              "license": {
154623                "name": "Unicode"
154624              }
154625            },
154626            {
154627              "license": {
154628                "id": "Zlib"
154629              }
154630            }
154631          ],
154632          "cpe": "cpe:2.3:a:perl-modules-5.30:perl-modules-5.30:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
154633          "purl": "pkg:deb/ubuntu/perl-modules-5.30@5.30.0-9ubuntu0.2?arch=all\u0026upstream=perl\u0026distro=ubuntu-20.04",
154634          "swid": {
154635            "attachment": {}
154636          },
154637          "pedigree": {},
154638          "evidence": {},
154639          "signature": {
154640            "signature": {
154641              "publicKey": {}
154642            }
154643          },
154644          "modelCard": {
154645            "modelParameters": {
154646              "approach": {}
154647            },
154648            "quantitativeAnalysis": {
154649              "graphics": {}
154650            },
154651            "considerations": {}
154652          }
154653        },
154654        {
154655          "type": "library",
154656          "bom-ref": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f177d21a50776ea7",
154657          "supplier": {},
154658          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154659          "name": "procps",
154660          "version": "2:3.3.16-1ubuntu2.2",
154661          "licenses": [
154662            {
154663              "license": {
154664                "id": "GPL-2.0-only"
154665              }
154666            },
154667            {
154668              "license": {
154669                "id": "GPL-2.0-or-later"
154670              }
154671            },
154672            {
154673              "license": {
154674                "id": "LGPL-2.0-only"
154675              }
154676            },
154677            {
154678              "license": {
154679                "id": "LGPL-2.0-or-later"
154680              }
154681            },
154682            {
154683              "license": {
154684                "id": "LGPL-2.1-only"
154685              }
154686            },
154687            {
154688              "license": {
154689                "id": "LGPL-2.1-or-later"
154690              }
154691            }
154692          ],
154693          "cpe": "cpe:2.3:a:procps:procps:2\\:3.3.16-1ubuntu2.2:*:*:*:*:*:*:*",
154694          "purl": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.2?arch=amd64\u0026distro=ubuntu-20.04",
154695          "swid": {
154696            "attachment": {}
154697          },
154698          "pedigree": {},
154699          "evidence": {},
154700          "signature": {
154701            "signature": {
154702              "publicKey": {}
154703            }
154704          },
154705          "modelCard": {
154706            "modelParameters": {
154707              "approach": {}
154708            },
154709            "quantitativeAnalysis": {
154710              "graphics": {}
154711            },
154712            "considerations": {}
154713          }
154714        },
154715        {
154716          "type": "library",
154717          "bom-ref": "pkg:deb/ubuntu/publicsuffix@20200303.0012-1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=fe371293cddb3ef3",
154718          "supplier": {},
154719          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154720          "name": "publicsuffix",
154721          "version": "20200303.0012-1",
154722          "licenses": [
154723            {
154724              "license": {
154725                "name": "CC0"
154726              }
154727            },
154728            {
154729              "license": {
154730                "id": "MPL-2.0"
154731              }
154732            }
154733          ],
154734          "cpe": "cpe:2.3:a:publicsuffix:publicsuffix:20200303.0012-1:*:*:*:*:*:*:*",
154735          "purl": "pkg:deb/ubuntu/publicsuffix@20200303.0012-1?arch=all\u0026distro=ubuntu-20.04",
154736          "swid": {
154737            "attachment": {}
154738          },
154739          "pedigree": {},
154740          "evidence": {},
154741          "signature": {
154742            "signature": {
154743              "publicKey": {}
154744            }
154745          },
154746          "modelCard": {
154747            "modelParameters": {
154748              "approach": {}
154749            },
154750            "quantitativeAnalysis": {
154751              "graphics": {}
154752            },
154753            "considerations": {}
154754          }
154755        },
154756        {
154757          "type": "application",
154758          "bom-ref": "pkg:generic/python@3.8.10?package-id=9f595431cf5573c7",
154759          "supplier": {},
154760          "name": "python",
154761          "version": "3.8.10",
154762          "cpe": "cpe:2.3:a:python_software_foundation:python:3.8.10:*:*:*:*:*:*:*",
154763          "purl": "pkg:generic/python@3.8.10",
154764          "swid": {
154765            "attachment": {}
154766          },
154767          "pedigree": {},
154768          "evidence": {},
154769          "signature": {
154770            "signature": {
154771              "publicKey": {}
154772            }
154773          },
154774          "modelCard": {
154775            "modelParameters": {
154776              "approach": {}
154777            },
154778            "quantitativeAnalysis": {
154779              "graphics": {}
154780            },
154781            "considerations": {}
154782          }
154783        },
154784        {
154785          "type": "library",
154786          "bom-ref": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=ca939acbf264771",
154787          "supplier": {},
154788          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154789          "name": "python3",
154790          "version": "3.8.2-0ubuntu2",
154791          "cpe": "cpe:2.3:a:python3:python3:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
154792          "purl": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
154793          "swid": {
154794            "attachment": {}
154795          },
154796          "pedigree": {},
154797          "evidence": {},
154798          "signature": {
154799            "signature": {
154800              "publicKey": {}
154801            }
154802          },
154803          "modelCard": {
154804            "modelParameters": {
154805              "approach": {}
154806            },
154807            "quantitativeAnalysis": {
154808              "graphics": {}
154809            },
154810            "considerations": {}
154811          }
154812        },
154813        {
154814          "type": "library",
154815          "bom-ref": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=26eebf392e0b02cf",
154816          "supplier": {},
154817          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154818          "name": "python3-minimal",
154819          "version": "3.8.2-0ubuntu2",
154820          "cpe": "cpe:2.3:a:python3-minimal:python3-minimal:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
154821          "purl": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
154822          "swid": {
154823            "attachment": {}
154824          },
154825          "pedigree": {},
154826          "evidence": {},
154827          "signature": {
154828            "signature": {
154829              "publicKey": {}
154830            }
154831          },
154832          "modelCard": {
154833            "modelParameters": {
154834              "approach": {}
154835            },
154836            "quantitativeAnalysis": {
154837              "graphics": {}
154838            },
154839            "considerations": {}
154840          }
154841        },
154842        {
154843          "type": "library",
154844          "bom-ref": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=b1de928401abc554",
154845          "supplier": {},
154846          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154847          "name": "python3.8",
154848          "version": "3.8.10-0ubuntu1~20.04",
154849          "licenses": [
154850            {
154851              "license": {
154852                "name": "By"
154853              }
154854            },
154855            {
154856              "license": {
154857                "id": "GPL-2.0-only"
154858              }
154859            },
154860            {
154861              "license": {
154862                "name": "Permission"
154863              }
154864            },
154865            {
154866              "license": {
154867                "name": "Redistribution"
154868              }
154869            },
154870            {
154871              "license": {
154872                "name": "This"
154873              }
154874            }
154875          ],
154876          "cpe": "cpe:2.3:a:python3.8:python3.8:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
154877          "purl": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026distro=ubuntu-20.04",
154878          "swid": {
154879            "attachment": {}
154880          },
154881          "pedigree": {},
154882          "evidence": {},
154883          "signature": {
154884            "signature": {
154885              "publicKey": {}
154886            }
154887          },
154888          "modelCard": {
154889            "modelParameters": {
154890              "approach": {}
154891            },
154892            "quantitativeAnalysis": {
154893              "graphics": {}
154894            },
154895            "considerations": {}
154896          }
154897        },
154898        {
154899          "type": "library",
154900          "bom-ref": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=91fa2bead1762d08",
154901          "supplier": {},
154902          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154903          "name": "python3.8-minimal",
154904          "version": "3.8.10-0ubuntu1~20.04",
154905          "licenses": [
154906            {
154907              "license": {
154908                "name": "By"
154909              }
154910            },
154911            {
154912              "license": {
154913                "id": "GPL-2.0-only"
154914              }
154915            },
154916            {
154917              "license": {
154918                "name": "Permission"
154919              }
154920            },
154921            {
154922              "license": {
154923                "name": "Redistribution"
154924              }
154925            },
154926            {
154927              "license": {
154928                "name": "This"
154929              }
154930            }
154931          ],
154932          "cpe": "cpe:2.3:a:python3.8-minimal:python3.8-minimal:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
154933          "purl": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
154934          "swid": {
154935            "attachment": {}
154936          },
154937          "pedigree": {},
154938          "evidence": {},
154939          "signature": {
154940            "signature": {
154941              "publicKey": {}
154942            }
154943          },
154944          "modelCard": {
154945            "modelParameters": {
154946              "approach": {}
154947            },
154948            "quantitativeAnalysis": {
154949              "graphics": {}
154950            },
154951            "considerations": {}
154952          }
154953        },
154954        {
154955          "type": "library",
154956          "bom-ref": "pkg:deb/ubuntu/qemu-block-extra@1:4.2-3ubuntu6.17?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04\u0026package-id=f2ce7313d353bf0d",
154957          "supplier": {},
154958          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
154959          "name": "qemu-block-extra",
154960          "version": "1:4.2-3ubuntu6.17",
154961          "licenses": [
154962            {
154963              "license": {
154964                "id": "GPL-2.0-only"
154965              }
154966            },
154967            {
154968              "license": {
154969                "id": "LGPL-2.0-only"
154970              }
154971            }
154972          ],
154973          "cpe": "cpe:2.3:a:qemu-block-extra:qemu-block-extra:1\\:4.2-3ubuntu6.17:*:*:*:*:*:*:*",
154974          "purl": "pkg:deb/ubuntu/qemu-block-extra@1:4.2-3ubuntu6.17?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04",
154975          "swid": {
154976            "attachment": {}
154977          },
154978          "pedigree": {},
154979          "evidence": {},
154980          "signature": {
154981            "signature": {
154982              "publicKey": {}
154983            }
154984          },
154985          "modelCard": {
154986            "modelParameters": {
154987              "approach": {}
154988            },
154989            "quantitativeAnalysis": {
154990              "graphics": {}
154991            },
154992            "considerations": {}
154993          }
154994        },
154995        {
154996          "type": "library",
154997          "bom-ref": "pkg:deb/ubuntu/qemu-utils@1:4.2-3ubuntu6.17?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04\u0026package-id=fd8d39c65bc83889",
154998          "supplier": {},
154999          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155000          "name": "qemu-utils",
155001          "version": "1:4.2-3ubuntu6.17",
155002          "licenses": [
155003            {
155004              "license": {
155005                "id": "GPL-2.0-only"
155006              }
155007            },
155008            {
155009              "license": {
155010                "id": "LGPL-2.0-only"
155011              }
155012            }
155013          ],
155014          "cpe": "cpe:2.3:a:qemu-utils:qemu-utils:1\\:4.2-3ubuntu6.17:*:*:*:*:*:*:*",
155015          "purl": "pkg:deb/ubuntu/qemu-utils@1:4.2-3ubuntu6.17?arch=amd64\u0026upstream=qemu\u0026distro=ubuntu-20.04",
155016          "swid": {
155017            "attachment": {}
155018          },
155019          "pedigree": {},
155020          "evidence": {},
155021          "signature": {
155022            "signature": {
155023              "publicKey": {}
155024            }
155025          },
155026          "modelCard": {
155027            "modelParameters": {
155028              "approach": {}
155029            },
155030            "quantitativeAnalysis": {
155031              "graphics": {}
155032            },
155033            "considerations": {}
155034          }
155035        },
155036        {
155037          "type": "library",
155038          "bom-ref": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=34a85b4423ecbe7",
155039          "supplier": {},
155040          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155041          "name": "readline-common",
155042          "version": "8.0-4",
155043          "licenses": [
155044            {
155045              "license": {
155046                "name": "GFDL"
155047              }
155048            },
155049            {
155050              "license": {
155051                "id": "GPL-3.0-only"
155052              }
155053            }
155054          ],
155055          "cpe": "cpe:2.3:a:readline-common:readline-common:8.0-4:*:*:*:*:*:*:*",
155056          "purl": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04",
155057          "swid": {
155058            "attachment": {}
155059          },
155060          "pedigree": {},
155061          "evidence": {},
155062          "signature": {
155063            "signature": {
155064              "publicKey": {}
155065            }
155066          },
155067          "modelCard": {
155068            "modelParameters": {
155069              "approach": {}
155070            },
155071            "quantitativeAnalysis": {
155072              "graphics": {}
155073            },
155074            "considerations": {}
155075          }
155076        },
155077        {
155078          "type": "library",
155079          "bom-ref": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e98d3334085e4495",
155080          "supplier": {},
155081          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155082          "name": "rpcbind",
155083          "version": "1.2.5-8",
155084          "licenses": [
155085            {
155086              "license": {
155087                "id": "BSD-3-Clause"
155088              }
155089            },
155090            {
155091              "license": {
155092                "id": "BSD-4-Clause"
155093              }
155094            },
155095            {
155096              "license": {
155097                "id": "BSD-4-Clause"
155098              }
155099            },
155100            {
155101              "license": {
155102                "id": "GPL-2.0-only"
155103              }
155104            },
155105            {
155106              "license": {
155107                "id": "GPL-2.0-or-later"
155108              }
155109            },
155110            {
155111              "license": {
155112                "id": "GPL-3.0-only"
155113              }
155114            },
155115            {
155116              "license": {
155117                "id": "MIT"
155118              }
155119            },
155120            {
155121              "license": {
155122                "name": "PERMISSIVE"
155123              }
155124            }
155125          ],
155126          "cpe": "cpe:2.3:a:rpcbind:rpcbind:1.2.5-8:*:*:*:*:*:*:*",
155127          "purl": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04",
155128          "swid": {
155129            "attachment": {}
155130          },
155131          "pedigree": {},
155132          "evidence": {},
155133          "signature": {
155134            "signature": {
155135              "publicKey": {}
155136            }
155137          },
155138          "modelCard": {
155139            "modelParameters": {
155140              "approach": {}
155141            },
155142            "quantitativeAnalysis": {
155143              "graphics": {}
155144            },
155145            "considerations": {}
155146          }
155147        },
155148        {
155149          "type": "library",
155150          "bom-ref": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=24bbb8989a1870c7",
155151          "supplier": {},
155152          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155153          "name": "sed",
155154          "version": "4.7-1",
155155          "licenses": [
155156            {
155157              "license": {
155158                "id": "GPL-3.0-only"
155159              }
155160            }
155161          ],
155162          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
155163          "purl": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04",
155164          "swid": {
155165            "attachment": {}
155166          },
155167          "pedigree": {},
155168          "evidence": {},
155169          "signature": {
155170            "signature": {
155171              "publicKey": {}
155172            }
155173          },
155174          "modelCard": {
155175            "modelParameters": {
155176              "approach": {}
155177            },
155178            "quantitativeAnalysis": {
155179              "graphics": {}
155180            },
155181            "considerations": {}
155182          }
155183        },
155184        {
155185          "type": "library",
155186          "bom-ref": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=7e50cf6ac335106e",
155187          "supplier": {},
155188          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155189          "name": "sensible-utils",
155190          "version": "0.0.12+nmu1",
155191          "licenses": [
155192            {
155193              "license": {
155194                "name": "All-permissive"
155195              }
155196            },
155197            {
155198              "license": {
155199                "id": "GPL-2.0-only"
155200              }
155201            },
155202            {
155203              "license": {
155204                "id": "GPL-2.0-or-later"
155205              }
155206            },
155207            {
155208              "license": {
155209                "name": "configure"
155210              }
155211            },
155212            {
155213              "license": {
155214                "name": "installsh"
155215              }
155216            }
155217          ],
155218          "cpe": "cpe:2.3:a:sensible-utils:sensible-utils:0.0.12\\+nmu1:*:*:*:*:*:*:*",
155219          "purl": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04",
155220          "swid": {
155221            "attachment": {}
155222          },
155223          "pedigree": {},
155224          "evidence": {},
155225          "signature": {
155226            "signature": {
155227              "publicKey": {}
155228            }
155229          },
155230          "modelCard": {
155231            "modelParameters": {
155232              "approach": {}
155233            },
155234            "quantitativeAnalysis": {
155235              "graphics": {}
155236            },
155237            "considerations": {}
155238          }
155239        },
155240        {
155241          "type": "library",
155242          "bom-ref": "pkg:deb/ubuntu/sg3-utils@1.44-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=794bb1692a1cfa88",
155243          "supplier": {},
155244          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155245          "name": "sg3-utils",
155246          "version": "1.44-1ubuntu2",
155247          "licenses": [
155248            {
155249              "license": {
155250                "name": "GPL"
155251              }
155252            }
155253          ],
155254          "cpe": "cpe:2.3:a:sg3-utils:sg3-utils:1.44-1ubuntu2:*:*:*:*:*:*:*",
155255          "purl": "pkg:deb/ubuntu/sg3-utils@1.44-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
155256          "swid": {
155257            "attachment": {}
155258          },
155259          "pedigree": {},
155260          "evidence": {},
155261          "signature": {
155262            "signature": {
155263              "publicKey": {}
155264            }
155265          },
155266          "modelCard": {
155267            "modelParameters": {
155268              "approach": {}
155269            },
155270            "quantitativeAnalysis": {
155271              "graphics": {}
155272            },
155273            "considerations": {}
155274          }
155275        },
155276        {
155277          "type": "library",
155278          "bom-ref": "pkg:deb/ubuntu/shared-mime-info@1.15-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=c15ede029a3e38cd",
155279          "supplier": {},
155280          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155281          "name": "shared-mime-info",
155282          "version": "1.15-1",
155283          "licenses": [
155284            {
155285              "license": {
155286                "name": "GPL"
155287              }
155288            }
155289          ],
155290          "cpe": "cpe:2.3:a:shared-mime-info:shared-mime-info:1.15-1:*:*:*:*:*:*:*",
155291          "purl": "pkg:deb/ubuntu/shared-mime-info@1.15-1?arch=amd64\u0026distro=ubuntu-20.04",
155292          "swid": {
155293            "attachment": {}
155294          },
155295          "pedigree": {},
155296          "evidence": {},
155297          "signature": {
155298            "signature": {
155299              "publicKey": {}
155300            }
155301          },
155302          "modelCard": {
155303            "modelParameters": {
155304              "approach": {}
155305            },
155306            "quantitativeAnalysis": {
155307              "graphics": {}
155308            },
155309            "considerations": {}
155310          }
155311        },
155312        {
155313          "type": "library",
155314          "bom-ref": "pkg:deb/ubuntu/sharutils@1:4.15.2-4build1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e920784bf62009c0",
155315          "supplier": {},
155316          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155317          "name": "sharutils",
155318          "version": "1:4.15.2-4build1",
155319          "licenses": [
155320            {
155321              "license": {
155322                "name": "GFDL"
155323              }
155324            },
155325            {
155326              "license": {
155327                "name": "GPL"
155328              }
155329            }
155330          ],
155331          "cpe": "cpe:2.3:a:sharutils:sharutils:1\\:4.15.2-4build1:*:*:*:*:*:*:*",
155332          "purl": "pkg:deb/ubuntu/sharutils@1:4.15.2-4build1?arch=amd64\u0026distro=ubuntu-20.04",
155333          "swid": {
155334            "attachment": {}
155335          },
155336          "pedigree": {},
155337          "evidence": {},
155338          "signature": {
155339            "signature": {
155340              "publicKey": {}
155341            }
155342          },
155343          "modelCard": {
155344            "modelParameters": {
155345              "approach": {}
155346            },
155347            "quantitativeAnalysis": {
155348              "graphics": {}
155349            },
155350            "considerations": {}
155351          }
155352        },
155353        {
155354          "type": "library",
155355          "bom-ref": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04\u0026package-id=abc451774789c392",
155356          "supplier": {},
155357          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155358          "name": "sysvinit-utils",
155359          "version": "2.96-2.1ubuntu1",
155360          "licenses": [
155361            {
155362              "license": {
155363                "id": "GPL-2.0-only"
155364              }
155365            },
155366            {
155367              "license": {
155368                "id": "GPL-2.0-or-later"
155369              }
155370            }
155371          ],
155372          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.96-2.1ubuntu1:*:*:*:*:*:*:*",
155373          "purl": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04",
155374          "swid": {
155375            "attachment": {}
155376          },
155377          "pedigree": {},
155378          "evidence": {},
155379          "signature": {
155380            "signature": {
155381              "publicKey": {}
155382            }
155383          },
155384          "modelCard": {
155385            "modelParameters": {
155386              "approach": {}
155387            },
155388            "quantitativeAnalysis": {
155389              "graphics": {}
155390            },
155391            "considerations": {}
155392          }
155393        },
155394        {
155395          "type": "library",
155396          "bom-ref": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=4c6cd0d17cc842e",
155397          "supplier": {},
155398          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155399          "name": "tar",
155400          "version": "1.30+dfsg-7ubuntu0.20.04.1",
155401          "licenses": [
155402            {
155403              "license": {
155404                "id": "GPL-2.0-only"
155405              }
155406            },
155407            {
155408              "license": {
155409                "id": "GPL-3.0-only"
155410              }
155411            }
155412          ],
155413          "cpe": "cpe:2.3:a:tar:tar:1.30\\+dfsg-7ubuntu0.20.04.1:*:*:*:*:*:*:*",
155414          "purl": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
155415          "swid": {
155416            "attachment": {}
155417          },
155418          "pedigree": {},
155419          "evidence": {},
155420          "signature": {
155421            "signature": {
155422              "publicKey": {}
155423            }
155424          },
155425          "modelCard": {
155426            "modelParameters": {
155427              "approach": {}
155428            },
155429            "quantitativeAnalysis": {
155430              "graphics": {}
155431            },
155432            "considerations": {}
155433          }
155434        },
155435        {
155436          "type": "library",
155437          "bom-ref": "pkg:deb/ubuntu/telnet@0.17-41.2build1?arch=amd64\u0026upstream=netkit-telnet\u0026distro=ubuntu-20.04\u0026package-id=440d9ef0dcd8675e",
155438          "supplier": {},
155439          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155440          "name": "telnet",
155441          "version": "0.17-41.2build1",
155442          "cpe": "cpe:2.3:a:telnet:telnet:0.17-41.2build1:*:*:*:*:*:*:*",
155443          "purl": "pkg:deb/ubuntu/telnet@0.17-41.2build1?arch=amd64\u0026upstream=netkit-telnet\u0026distro=ubuntu-20.04",
155444          "swid": {
155445            "attachment": {}
155446          },
155447          "pedigree": {},
155448          "evidence": {},
155449          "signature": {
155450            "signature": {
155451              "publicKey": {}
155452            }
155453          },
155454          "modelCard": {
155455            "modelParameters": {
155456              "approach": {}
155457            },
155458            "quantitativeAnalysis": {
155459              "graphics": {}
155460            },
155461            "considerations": {}
155462          }
155463        },
155464        {
155465          "type": "library",
155466          "bom-ref": "pkg:deb/ubuntu/tzdata@2021a-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04\u0026package-id=aaae4a94d26494c0",
155467          "supplier": {},
155468          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155469          "name": "tzdata",
155470          "version": "2021a-0ubuntu0.20.04",
155471          "licenses": [
155472            {
155473              "license": {
155474                "id": "ICU"
155475              }
155476            }
155477          ],
155478          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0ubuntu0.20.04:*:*:*:*:*:*:*",
155479          "purl": "pkg:deb/ubuntu/tzdata@2021a-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04",
155480          "swid": {
155481            "attachment": {}
155482          },
155483          "pedigree": {},
155484          "evidence": {},
155485          "signature": {
155486            "signature": {
155487              "publicKey": {}
155488            }
155489          },
155490          "modelCard": {
155491            "modelParameters": {
155492              "approach": {}
155493            },
155494            "quantitativeAnalysis": {
155495              "graphics": {}
155496            },
155497            "considerations": {}
155498          }
155499        },
155500        {
155501          "type": "library",
155502          "bom-ref": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04\u0026package-id=6d2b18ebcbe1dab7",
155503          "supplier": {},
155504          "publisher": "Dimitri John Ledkov \u003cdimitri.ledkov@canonical.com\u003e",
155505          "name": "ubuntu-keyring",
155506          "version": "2020.02.11.4",
155507          "licenses": [
155508            {
155509              "license": {
155510                "name": "GPL"
155511              }
155512            }
155513          ],
155514          "cpe": "cpe:2.3:a:ubuntu-keyring:ubuntu-keyring:2020.02.11.4:*:*:*:*:*:*:*",
155515          "purl": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04",
155516          "swid": {
155517            "attachment": {}
155518          },
155519          "pedigree": {},
155520          "evidence": {},
155521          "signature": {
155522            "signature": {
155523              "publicKey": {}
155524            }
155525          },
155526          "modelCard": {
155527            "modelParameters": {
155528              "approach": {}
155529            },
155530            "quantitativeAnalysis": {
155531              "graphics": {}
155532            },
155533            "considerations": {}
155534          }
155535        },
155536        {
155537          "type": "library",
155538          "bom-ref": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=ab3b8cc8be7b5655",
155539          "supplier": {},
155540          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155541          "name": "ucf",
155542          "version": "3.0038+nmu1",
155543          "licenses": [
155544            {
155545              "license": {
155546                "id": "GPL-2.0-only"
155547              }
155548            }
155549          ],
155550          "cpe": "cpe:2.3:a:ucf:ucf:3.0038\\+nmu1:*:*:*:*:*:*:*",
155551          "purl": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04",
155552          "swid": {
155553            "attachment": {}
155554          },
155555          "pedigree": {},
155556          "evidence": {},
155557          "signature": {
155558            "signature": {
155559              "publicKey": {}
155560            }
155561          },
155562          "modelCard": {
155563            "modelParameters": {
155564              "approach": {}
155565            },
155566            "quantitativeAnalysis": {
155567              "graphics": {}
155568            },
155569            "considerations": {}
155570          }
155571        },
155572        {
155573          "type": "library",
155574          "bom-ref": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=33e86bd94ef763b6",
155575          "supplier": {},
155576          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155577          "name": "util-linux",
155578          "version": "2.34-0.1ubuntu9.1",
155579          "licenses": [
155580            {
155581              "license": {
155582                "id": "BSD-2-Clause"
155583              }
155584            },
155585            {
155586              "license": {
155587                "id": "BSD-3-Clause"
155588              }
155589            },
155590            {
155591              "license": {
155592                "id": "BSD-4-Clause"
155593              }
155594            },
155595            {
155596              "license": {
155597                "id": "GPL-2.0-only"
155598              }
155599            },
155600            {
155601              "license": {
155602                "id": "GPL-2.0-or-later"
155603              }
155604            },
155605            {
155606              "license": {
155607                "id": "GPL-3.0-only"
155608              }
155609            },
155610            {
155611              "license": {
155612                "id": "GPL-3.0-or-later"
155613              }
155614            },
155615            {
155616              "license": {
155617                "name": "LGPL"
155618              }
155619            },
155620            {
155621              "license": {
155622                "id": "LGPL-2.0-only"
155623              }
155624            },
155625            {
155626              "license": {
155627                "id": "LGPL-2.0-or-later"
155628              }
155629            },
155630            {
155631              "license": {
155632                "id": "LGPL-2.1-only"
155633              }
155634            },
155635            {
155636              "license": {
155637                "id": "LGPL-2.1-or-later"
155638              }
155639            },
155640            {
155641              "license": {
155642                "id": "LGPL-3.0-only"
155643              }
155644            },
155645            {
155646              "license": {
155647                "id": "LGPL-3.0-or-later"
155648              }
155649            },
155650            {
155651              "license": {
155652                "id": "MIT"
155653              }
155654            },
155655            {
155656              "license": {
155657                "name": "public-domain"
155658              }
155659            }
155660          ],
155661          "cpe": "cpe:2.3:a:util-linux:util-linux:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
155662          "purl": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04",
155663          "swid": {
155664            "attachment": {}
155665          },
155666          "pedigree": {},
155667          "evidence": {},
155668          "signature": {
155669            "signature": {
155670              "publicKey": {}
155671            }
155672          },
155673          "modelCard": {
155674            "modelParameters": {
155675              "approach": {}
155676            },
155677            "quantitativeAnalysis": {
155678              "graphics": {}
155679            },
155680            "considerations": {}
155681          }
155682        },
155683        {
155684          "type": "library",
155685          "bom-ref": "pkg:deb/ubuntu/wget@1.20.3-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=2fee01aeba885b76",
155686          "supplier": {},
155687          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155688          "name": "wget",
155689          "version": "1.20.3-1ubuntu1",
155690          "licenses": [
155691            {
155692              "license": {
155693                "id": "GFDL-1.2-only"
155694              }
155695            },
155696            {
155697              "license": {
155698                "id": "GPL-3.0-only"
155699              }
155700            }
155701          ],
155702          "cpe": "cpe:2.3:a:wget:wget:1.20.3-1ubuntu1:*:*:*:*:*:*:*",
155703          "purl": "pkg:deb/ubuntu/wget@1.20.3-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
155704          "swid": {
155705            "attachment": {}
155706          },
155707          "pedigree": {},
155708          "evidence": {},
155709          "signature": {
155710            "signature": {
155711              "publicKey": {}
155712            }
155713          },
155714          "modelCard": {
155715            "modelParameters": {
155716              "approach": {}
155717            },
155718            "quantitativeAnalysis": {
155719              "graphics": {}
155720            },
155721            "considerations": {}
155722          }
155723        },
155724        {
155725          "type": "library",
155726          "bom-ref": "pkg:deb/ubuntu/xdg-user-dirs@0.17-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=6c580aaac3aa6068",
155727          "supplier": {},
155728          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155729          "name": "xdg-user-dirs",
155730          "version": "0.17-2ubuntu1",
155731          "licenses": [
155732            {
155733              "license": {
155734                "id": "GPL-2.0-only"
155735              }
155736            }
155737          ],
155738          "cpe": "cpe:2.3:a:xdg-user-dirs:xdg-user-dirs:0.17-2ubuntu1:*:*:*:*:*:*:*",
155739          "purl": "pkg:deb/ubuntu/xdg-user-dirs@0.17-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
155740          "swid": {
155741            "attachment": {}
155742          },
155743          "pedigree": {},
155744          "evidence": {},
155745          "signature": {
155746            "signature": {
155747              "publicKey": {}
155748            }
155749          },
155750          "modelCard": {
155751            "modelParameters": {
155752              "approach": {}
155753            },
155754            "quantitativeAnalysis": {
155755              "graphics": {}
155756            },
155757            "considerations": {}
155758          }
155759        },
155760        {
155761          "type": "library",
155762          "bom-ref": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=46271b3ba3de19b6",
155763          "supplier": {},
155764          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155765          "name": "xz-utils",
155766          "version": "5.2.4-1ubuntu1",
155767          "licenses": [
155768            {
155769              "license": {
155770                "name": "Autoconf"
155771              }
155772            },
155773            {
155774              "license": {
155775                "id": "GPL-2.0-only"
155776              }
155777            },
155778            {
155779              "license": {
155780                "id": "GPL-2.0-or-later"
155781              }
155782            },
155783            {
155784              "license": {
155785                "id": "GPL-3.0-only"
155786              }
155787            },
155788            {
155789              "license": {
155790                "id": "LGPL-2.0-only"
155791              }
155792            },
155793            {
155794              "license": {
155795                "id": "LGPL-2.1-only"
155796              }
155797            },
155798            {
155799              "license": {
155800                "id": "LGPL-2.1-or-later"
155801              }
155802            },
155803            {
155804              "license": {
155805                "name": "PD"
155806              }
155807            },
155808            {
155809              "license": {
155810                "name": "PD-debian"
155811              }
155812            },
155813            {
155814              "license": {
155815                "name": "config-h"
155816              }
155817            },
155818            {
155819              "license": {
155820                "name": "noderivs"
155821              }
155822            },
155823            {
155824              "license": {
155825                "name": "permissive-fsf"
155826              }
155827            },
155828            {
155829              "license": {
155830                "name": "permissive-nowarranty"
155831              }
155832            },
155833            {
155834              "license": {
155835                "name": "probably-PD"
155836              }
155837            }
155838          ],
155839          "cpe": "cpe:2.3:a:xz-utils:xz-utils:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
155840          "purl": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
155841          "swid": {
155842            "attachment": {}
155843          },
155844          "pedigree": {},
155845          "evidence": {},
155846          "signature": {
155847            "signature": {
155848              "publicKey": {}
155849            }
155850          },
155851          "modelCard": {
155852            "modelParameters": {
155853              "approach": {}
155854            },
155855            "quantitativeAnalysis": {
155856              "graphics": {}
155857            },
155858            "considerations": {}
155859          }
155860        },
155861        {
155862          "type": "library",
155863          "bom-ref": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04\u0026package-id=65361fdd213cfcf7",
155864          "supplier": {},
155865          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
155866          "name": "zlib1g",
155867          "version": "1:1.2.11.dfsg-2ubuntu1.2",
155868          "licenses": [
155869            {
155870              "license": {
155871                "id": "Zlib"
155872              }
155873            }
155874          ],
155875          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2ubuntu1.2:*:*:*:*:*:*:*",
155876          "purl": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04",
155877          "swid": {
155878            "attachment": {}
155879          },
155880          "pedigree": {},
155881          "evidence": {},
155882          "signature": {
155883            "signature": {
155884              "publicKey": {}
155885            }
155886          },
155887          "modelCard": {
155888            "modelParameters": {
155889              "approach": {}
155890            },
155891            "quantitativeAnalysis": {
155892              "graphics": {}
155893            },
155894            "considerations": {}
155895          }
155896        },
155897        {
155898          "type": "operating-system",
155899          "supplier": {},
155900          "name": "ubuntu",
155901          "version": "20.04",
155902          "description": "Ubuntu 20.04.2 LTS",
155903          "swid": {
155904            "tagId": "ubuntu",
155905            "name": "ubuntu",
155906            "version": "20.04",
155907            "attachment": {}
155908          },
155909          "pedigree": {},
155910          "externalReferences": [
155911            {
155912              "url": "https://bugs.launchpad.net/ubuntu/",
155913              "type": "issue-tracker"
155914            },
155915            {
155916              "url": "https://www.ubuntu.com/",
155917              "type": "website"
155918            },
155919            {
155920              "url": "https://help.ubuntu.com/",
155921              "comment": "support",
155922              "type": "other"
155923            },
155924            {
155925              "url": "https://www.ubuntu.com/legal/terms-and-policies/privacy-policy",
155926              "comment": "privacyPolicy",
155927              "type": "other"
155928            }
155929          ],
155930          "evidence": {},
155931          "signature": {
155932            "signature": {
155933              "publicKey": {}
155934            }
155935          },
155936          "modelCard": {
155937            "modelParameters": {
155938              "approach": {}
155939            },
155940            "quantitativeAnalysis": {
155941              "graphics": {}
155942            },
155943            "considerations": {}
155944          }
155945        },
155946        {
155947          "type": "library",
155948          "bom-ref": "pkg:deb/debian/base-files@10.3+deb10u9?arch=amd64\u0026distro=debian-10\u0026package-id=5aa6e4929bf16696",
155949          "supplier": {},
155950          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
155951          "name": "base-files",
155952          "version": "10.3+deb10u9",
155953          "licenses": [
155954            {
155955              "license": {
155956                "name": "GPL"
155957              }
155958            }
155959          ],
155960          "cpe": "cpe:2.3:a:base-files:base-files:10.3\\+deb10u9:*:*:*:*:*:*:*",
155961          "purl": "pkg:deb/debian/base-files@10.3+deb10u9?arch=amd64\u0026distro=debian-10",
155962          "swid": {
155963            "attachment": {}
155964          },
155965          "pedigree": {},
155966          "evidence": {},
155967          "signature": {
155968            "signature": {
155969              "publicKey": {}
155970            }
155971          },
155972          "modelCard": {
155973            "modelParameters": {
155974              "approach": {}
155975            },
155976            "quantitativeAnalysis": {
155977              "graphics": {}
155978            },
155979            "considerations": {}
155980          }
155981        },
155982        {
155983          "type": "library",
155984          "bom-ref": "pkg:golang/github.com/beorn7/perks@v1.0.1?package-id=fe208845850e761b",
155985          "supplier": {},
155986          "name": "github.com/beorn7/perks",
155987          "version": "v1.0.1",
155988          "cpe": "cpe:2.3:a:beorn7:perks:v1.0.1:*:*:*:*:*:*:*",
155989          "purl": "pkg:golang/github.com/beorn7/perks@v1.0.1",
155990          "swid": {
155991            "attachment": {}
155992          },
155993          "pedigree": {},
155994          "evidence": {},
155995          "signature": {
155996            "signature": {
155997              "publicKey": {}
155998            }
155999          },
156000          "modelCard": {
156001            "modelParameters": {
156002              "approach": {}
156003            },
156004            "quantitativeAnalysis": {
156005              "graphics": {}
156006            },
156007            "considerations": {}
156008          }
156009        },
156010        {
156011          "type": "library",
156012          "bom-ref": "pkg:golang/github.com/blang/semver@v3.5.1+incompatible?package-id=a0fcce25c1c87943",
156013          "supplier": {},
156014          "name": "github.com/blang/semver",
156015          "version": "v3.5.1+incompatible",
156016          "cpe": "cpe:2.3:a:blang:semver:v3.5.1\\+incompatible:*:*:*:*:*:*:*",
156017          "purl": "pkg:golang/github.com/blang/semver@v3.5.1+incompatible",
156018          "swid": {
156019            "attachment": {}
156020          },
156021          "pedigree": {},
156022          "evidence": {},
156023          "signature": {
156024            "signature": {
156025              "publicKey": {}
156026            }
156027          },
156028          "modelCard": {
156029            "modelParameters": {
156030              "approach": {}
156031            },
156032            "quantitativeAnalysis": {
156033              "graphics": {}
156034            },
156035            "considerations": {}
156036          }
156037        },
156038        {
156039          "type": "library",
156040          "bom-ref": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1?package-id=a3cf89dad3a1cb14",
156041          "supplier": {},
156042          "name": "github.com/cespare/xxhash/v2",
156043          "version": "v2.1.1",
156044          "cpe": "cpe:2.3:a:cespare:xxhash\\/v2:v2.1.1:*:*:*:*:*:*:*",
156045          "purl": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1",
156046          "swid": {
156047            "attachment": {}
156048          },
156049          "pedigree": {},
156050          "evidence": {},
156051          "signature": {
156052            "signature": {
156053              "publicKey": {}
156054            }
156055          },
156056          "modelCard": {
156057            "modelParameters": {
156058              "approach": {}
156059            },
156060            "quantitativeAnalysis": {
156061              "graphics": {}
156062            },
156063            "considerations": {}
156064          }
156065        },
156066        {
156067          "type": "library",
156068          "bom-ref": "pkg:golang/github.com/container-storage-interface/spec@v1.4.0?package-id=d167582a01352137",
156069          "supplier": {},
156070          "name": "github.com/container-storage-interface/spec",
156071          "version": "v1.4.0",
156072          "cpe": "cpe:2.3:a:container-storage-interface:spec:v1.4.0:*:*:*:*:*:*:*",
156073          "purl": "pkg:golang/github.com/container-storage-interface/spec@v1.4.0",
156074          "swid": {
156075            "attachment": {}
156076          },
156077          "pedigree": {},
156078          "evidence": {},
156079          "signature": {
156080            "signature": {
156081              "publicKey": {}
156082            }
156083          },
156084          "modelCard": {
156085            "modelParameters": {
156086              "approach": {}
156087            },
156088            "quantitativeAnalysis": {
156089              "graphics": {}
156090            },
156091            "considerations": {}
156092          }
156093        },
156094        {
156095          "type": "library",
156096          "bom-ref": "pkg:golang/github.com/davecgh/go-spew@v1.1.1?package-id=1552c23ced3a50ec",
156097          "supplier": {},
156098          "name": "github.com/davecgh/go-spew",
156099          "version": "v1.1.1",
156100          "cpe": "cpe:2.3:a:davecgh:go-spew:v1.1.1:*:*:*:*:*:*:*",
156101          "purl": "pkg:golang/github.com/davecgh/go-spew@v1.1.1",
156102          "swid": {
156103            "attachment": {}
156104          },
156105          "pedigree": {},
156106          "evidence": {},
156107          "signature": {
156108            "signature": {
156109              "publicKey": {}
156110            }
156111          },
156112          "modelCard": {
156113            "modelParameters": {
156114              "approach": {}
156115            },
156116            "quantitativeAnalysis": {
156117              "graphics": {}
156118            },
156119            "considerations": {}
156120          }
156121        },
156122        {
156123          "type": "library",
156124          "bom-ref": "pkg:golang/github.com/go-logr/logr@v0.4.0?package-id=81dacddb5e57d473",
156125          "supplier": {},
156126          "name": "github.com/go-logr/logr",
156127          "version": "v0.4.0",
156128          "cpe": "cpe:2.3:a:go-logr:logr:v0.4.0:*:*:*:*:*:*:*",
156129          "purl": "pkg:golang/github.com/go-logr/logr@v0.4.0",
156130          "swid": {
156131            "attachment": {}
156132          },
156133          "pedigree": {},
156134          "evidence": {},
156135          "signature": {
156136            "signature": {
156137              "publicKey": {}
156138            }
156139          },
156140          "modelCard": {
156141            "modelParameters": {
156142              "approach": {}
156143            },
156144            "quantitativeAnalysis": {
156145              "graphics": {}
156146            },
156147            "considerations": {}
156148          }
156149        },
156150        {
156151          "type": "library",
156152          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.2?package-id=5d77f4e6dec464a0",
156153          "supplier": {},
156154          "name": "github.com/gogo/protobuf",
156155          "version": "v1.3.2",
156156          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.2:*:*:*:*:*:*:*",
156157          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.2",
156158          "swid": {
156159            "attachment": {}
156160          },
156161          "pedigree": {},
156162          "evidence": {},
156163          "signature": {
156164            "signature": {
156165              "publicKey": {}
156166            }
156167          },
156168          "modelCard": {
156169            "modelParameters": {
156170              "approach": {}
156171            },
156172            "quantitativeAnalysis": {
156173              "graphics": {}
156174            },
156175            "considerations": {}
156176          }
156177        },
156178        {
156179          "type": "library",
156180          "bom-ref": "pkg:golang/github.com/golang/groupcache@v0.0.0-20200121045136-8c9f03a8e57e?package-id=49655a5a6aa0ab40",
156181          "supplier": {},
156182          "name": "github.com/golang/groupcache",
156183          "version": "v0.0.0-20200121045136-8c9f03a8e57e",
156184          "cpe": "cpe:2.3:a:golang:groupcache:v0.0.0-20200121045136-8c9f03a8e57e:*:*:*:*:*:*:*",
156185          "purl": "pkg:golang/github.com/golang/groupcache@v0.0.0-20200121045136-8c9f03a8e57e",
156186          "swid": {
156187            "attachment": {}
156188          },
156189          "pedigree": {},
156190          "evidence": {},
156191          "signature": {
156192            "signature": {
156193              "publicKey": {}
156194            }
156195          },
156196          "modelCard": {
156197            "modelParameters": {
156198              "approach": {}
156199            },
156200            "quantitativeAnalysis": {
156201              "graphics": {}
156202            },
156203            "considerations": {}
156204          }
156205        },
156206        {
156207          "type": "library",
156208          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.5.1?package-id=df7a31ccba759cc6",
156209          "supplier": {},
156210          "name": "github.com/golang/protobuf",
156211          "version": "v1.5.1",
156212          "cpe": "cpe:2.3:a:golang:protobuf:v1.5.1:*:*:*:*:*:*:*",
156213          "purl": "pkg:golang/github.com/golang/protobuf@v1.5.1",
156214          "swid": {
156215            "attachment": {}
156216          },
156217          "pedigree": {},
156218          "evidence": {},
156219          "signature": {
156220            "signature": {
156221              "publicKey": {}
156222            }
156223          },
156224          "modelCard": {
156225            "modelParameters": {
156226              "approach": {}
156227            },
156228            "quantitativeAnalysis": {
156229              "graphics": {}
156230            },
156231            "considerations": {}
156232          }
156233        },
156234        {
156235          "type": "library",
156236          "bom-ref": "pkg:golang/github.com/google/go-cmp@v0.5.5?package-id=ae445c0d544c5a2f",
156237          "supplier": {},
156238          "name": "github.com/google/go-cmp",
156239          "version": "v0.5.5",
156240          "cpe": "cpe:2.3:a:google:go-cmp:v0.5.5:*:*:*:*:*:*:*",
156241          "purl": "pkg:golang/github.com/google/go-cmp@v0.5.5",
156242          "swid": {
156243            "attachment": {}
156244          },
156245          "pedigree": {},
156246          "evidence": {},
156247          "signature": {
156248            "signature": {
156249              "publicKey": {}
156250            }
156251          },
156252          "modelCard": {
156253            "modelParameters": {
156254              "approach": {}
156255            },
156256            "quantitativeAnalysis": {
156257              "graphics": {}
156258            },
156259            "considerations": {}
156260          }
156261        },
156262        {
156263          "type": "library",
156264          "bom-ref": "pkg:golang/github.com/google/gofuzz@v1.2.0?package-id=728996eb813a5896",
156265          "supplier": {},
156266          "name": "github.com/google/gofuzz",
156267          "version": "v1.2.0",
156268          "cpe": "cpe:2.3:a:google:gofuzz:v1.2.0:*:*:*:*:*:*:*",
156269          "purl": "pkg:golang/github.com/google/gofuzz@v1.2.0",
156270          "swid": {
156271            "attachment": {}
156272          },
156273          "pedigree": {},
156274          "evidence": {},
156275          "signature": {
156276            "signature": {
156277              "publicKey": {}
156278            }
156279          },
156280          "modelCard": {
156281            "modelParameters": {
156282              "approach": {}
156283            },
156284            "quantitativeAnalysis": {
156285              "graphics": {}
156286            },
156287            "considerations": {}
156288          }
156289        },
156290        {
156291          "type": "library",
156292          "bom-ref": "pkg:golang/github.com/googleapis/gnostic@v0.5.4?package-id=58b1aa0f2d634b33",
156293          "supplier": {},
156294          "name": "github.com/googleapis/gnostic",
156295          "version": "v0.5.4",
156296          "cpe": "cpe:2.3:a:googleapis:gnostic:v0.5.4:*:*:*:*:*:*:*",
156297          "purl": "pkg:golang/github.com/googleapis/gnostic@v0.5.4",
156298          "swid": {
156299            "attachment": {}
156300          },
156301          "pedigree": {},
156302          "evidence": {},
156303          "signature": {
156304            "signature": {
156305              "publicKey": {}
156306            }
156307          },
156308          "modelCard": {
156309            "modelParameters": {
156310              "approach": {}
156311            },
156312            "quantitativeAnalysis": {
156313              "graphics": {}
156314            },
156315            "considerations": {}
156316          }
156317        },
156318        {
156319          "type": "library",
156320          "bom-ref": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.4?package-id=eb19310b49d31c33",
156321          "supplier": {},
156322          "name": "github.com/hashicorp/golang-lru",
156323          "version": "v0.5.4",
156324          "cpe": "cpe:2.3:a:hashicorp:golang-lru:v0.5.4:*:*:*:*:*:*:*",
156325          "purl": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.4",
156326          "swid": {
156327            "attachment": {}
156328          },
156329          "pedigree": {},
156330          "evidence": {},
156331          "signature": {
156332            "signature": {
156333              "publicKey": {}
156334            }
156335          },
156336          "modelCard": {
156337            "modelParameters": {
156338              "approach": {}
156339            },
156340            "quantitativeAnalysis": {
156341              "graphics": {}
156342            },
156343            "considerations": {}
156344          }
156345        },
156346        {
156347          "type": "library",
156348          "bom-ref": "pkg:golang/github.com/imdario/mergo@v0.3.12?package-id=615bf0276f4720c1",
156349          "supplier": {},
156350          "name": "github.com/imdario/mergo",
156351          "version": "v0.3.12",
156352          "cpe": "cpe:2.3:a:imdario:mergo:v0.3.12:*:*:*:*:*:*:*",
156353          "purl": "pkg:golang/github.com/imdario/mergo@v0.3.12",
156354          "swid": {
156355            "attachment": {}
156356          },
156357          "pedigree": {},
156358          "evidence": {},
156359          "signature": {
156360            "signature": {
156361              "publicKey": {}
156362            }
156363          },
156364          "modelCard": {
156365            "modelParameters": {
156366              "approach": {}
156367            },
156368            "quantitativeAnalysis": {
156369              "graphics": {}
156370            },
156371            "considerations": {}
156372          }
156373        },
156374        {
156375          "type": "library",
156376          "bom-ref": "pkg:golang/github.com/json-iterator/go@v1.1.10?package-id=604391da90d0269b",
156377          "supplier": {},
156378          "name": "github.com/json-iterator/go",
156379          "version": "v1.1.10",
156380          "cpe": "cpe:2.3:a:json-iterator:go:v1.1.10:*:*:*:*:*:*:*",
156381          "purl": "pkg:golang/github.com/json-iterator/go@v1.1.10",
156382          "swid": {
156383            "attachment": {}
156384          },
156385          "pedigree": {},
156386          "evidence": {},
156387          "signature": {
156388            "signature": {
156389              "publicKey": {}
156390            }
156391          },
156392          "modelCard": {
156393            "modelParameters": {
156394              "approach": {}
156395            },
156396            "quantitativeAnalysis": {
156397              "graphics": {}
156398            },
156399            "considerations": {}
156400          }
156401        },
156402        {
156403          "type": "library",
156404          "bom-ref": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.9.1?package-id=f15d5f2721545be7",
156405          "supplier": {},
156406          "name": "github.com/kubernetes-csi/csi-lib-utils",
156407          "version": "v0.9.1",
156408          "cpe": "cpe:2.3:a:kubernetes-csi:csi-lib-utils:v0.9.1:*:*:*:*:*:*:*",
156409          "purl": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.9.1",
156410          "swid": {
156411            "attachment": {}
156412          },
156413          "pedigree": {},
156414          "evidence": {},
156415          "signature": {
156416            "signature": {
156417              "publicKey": {}
156418            }
156419          },
156420          "modelCard": {
156421            "modelParameters": {
156422              "approach": {}
156423            },
156424            "quantitativeAnalysis": {
156425              "graphics": {}
156426            },
156427            "considerations": {}
156428          }
156429        },
156430        {
156431          "type": "library",
156432          "bom-ref": "pkg:golang/github.com/kubernetes-csi/external-resizer@(devel)?package-id=67e7cf3d6129d38",
156433          "supplier": {},
156434          "name": "github.com/kubernetes-csi/external-resizer",
156435          "version": "(devel)",
156436          "cpe": "cpe:2.3:a:kubernetes-csi:external-resizer:\\(devel\\):*:*:*:*:*:*:*",
156437          "purl": "pkg:golang/github.com/kubernetes-csi/external-resizer@(devel)",
156438          "swid": {
156439            "attachment": {}
156440          },
156441          "pedigree": {},
156442          "evidence": {},
156443          "signature": {
156444            "signature": {
156445              "publicKey": {}
156446            }
156447          },
156448          "modelCard": {
156449            "modelParameters": {
156450              "approach": {}
156451            },
156452            "quantitativeAnalysis": {
156453              "graphics": {}
156454            },
156455            "considerations": {}
156456          }
156457        },
156458        {
156459          "type": "library",
156460          "bom-ref": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369?package-id=af6d9140b50303b6",
156461          "supplier": {},
156462          "name": "github.com/matttproud/golang_protobuf_extensions",
156463          "version": "v1.0.2-0.20181231171920-c182affec369",
156464          "cpe": "cpe:2.3:a:matttproud:golang-protobuf-extensions:v1.0.2-0.20181231171920-c182affec369:*:*:*:*:*:*:*",
156465          "purl": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369",
156466          "swid": {
156467            "attachment": {}
156468          },
156469          "pedigree": {},
156470          "evidence": {},
156471          "signature": {
156472            "signature": {
156473              "publicKey": {}
156474            }
156475          },
156476          "modelCard": {
156477            "modelParameters": {
156478              "approach": {}
156479            },
156480            "quantitativeAnalysis": {
156481              "graphics": {}
156482            },
156483            "considerations": {}
156484          }
156485        },
156486        {
156487          "type": "library",
156488          "bom-ref": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd?package-id=2c638b682effc6ac",
156489          "supplier": {},
156490          "name": "github.com/modern-go/concurrent",
156491          "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
156492          "cpe": "cpe:2.3:a:modern-go:concurrent:v0.0.0-20180306012644-bacd9c7ef1dd:*:*:*:*:*:*:*",
156493          "purl": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd",
156494          "swid": {
156495            "attachment": {}
156496          },
156497          "pedigree": {},
156498          "evidence": {},
156499          "signature": {
156500            "signature": {
156501              "publicKey": {}
156502            }
156503          },
156504          "modelCard": {
156505            "modelParameters": {
156506              "approach": {}
156507            },
156508            "quantitativeAnalysis": {
156509              "graphics": {}
156510            },
156511            "considerations": {}
156512          }
156513        },
156514        {
156515          "type": "library",
156516          "bom-ref": "pkg:golang/github.com/modern-go/reflect2@v1.0.1?package-id=c55e380a734816f9",
156517          "supplier": {},
156518          "name": "github.com/modern-go/reflect2",
156519          "version": "v1.0.1",
156520          "cpe": "cpe:2.3:a:modern-go:reflect2:v1.0.1:*:*:*:*:*:*:*",
156521          "purl": "pkg:golang/github.com/modern-go/reflect2@v1.0.1",
156522          "swid": {
156523            "attachment": {}
156524          },
156525          "pedigree": {},
156526          "evidence": {},
156527          "signature": {
156528            "signature": {
156529              "publicKey": {}
156530            }
156531          },
156532          "modelCard": {
156533            "modelParameters": {
156534              "approach": {}
156535            },
156536            "quantitativeAnalysis": {
156537              "graphics": {}
156538            },
156539            "considerations": {}
156540          }
156541        },
156542        {
156543          "type": "library",
156544          "bom-ref": "pkg:golang/github.com/prometheus/client_golang@v1.9.0?package-id=ba1d9eb559485a13",
156545          "supplier": {},
156546          "name": "github.com/prometheus/client_golang",
156547          "version": "v1.9.0",
156548          "cpe": "cpe:2.3:a:prometheus:client-golang:v1.9.0:*:*:*:*:*:*:*",
156549          "purl": "pkg:golang/github.com/prometheus/client_golang@v1.9.0",
156550          "swid": {
156551            "attachment": {}
156552          },
156553          "pedigree": {},
156554          "evidence": {},
156555          "signature": {
156556            "signature": {
156557              "publicKey": {}
156558            }
156559          },
156560          "modelCard": {
156561            "modelParameters": {
156562              "approach": {}
156563            },
156564            "quantitativeAnalysis": {
156565              "graphics": {}
156566            },
156567            "considerations": {}
156568          }
156569        },
156570        {
156571          "type": "library",
156572          "bom-ref": "pkg:golang/github.com/prometheus/client_model@v0.2.0?package-id=51dd0152d6e0fdbd",
156573          "supplier": {},
156574          "name": "github.com/prometheus/client_model",
156575          "version": "v0.2.0",
156576          "cpe": "cpe:2.3:a:prometheus:client-model:v0.2.0:*:*:*:*:*:*:*",
156577          "purl": "pkg:golang/github.com/prometheus/client_model@v0.2.0",
156578          "swid": {
156579            "attachment": {}
156580          },
156581          "pedigree": {},
156582          "evidence": {},
156583          "signature": {
156584            "signature": {
156585              "publicKey": {}
156586            }
156587          },
156588          "modelCard": {
156589            "modelParameters": {
156590              "approach": {}
156591            },
156592            "quantitativeAnalysis": {
156593              "graphics": {}
156594            },
156595            "considerations": {}
156596          }
156597        },
156598        {
156599          "type": "library",
156600          "bom-ref": "pkg:golang/github.com/prometheus/common@v0.19.0?package-id=fba5945728425a37",
156601          "supplier": {},
156602          "name": "github.com/prometheus/common",
156603          "version": "v0.19.0",
156604          "cpe": "cpe:2.3:a:prometheus:common:v0.19.0:*:*:*:*:*:*:*",
156605          "purl": "pkg:golang/github.com/prometheus/common@v0.19.0",
156606          "swid": {
156607            "attachment": {}
156608          },
156609          "pedigree": {},
156610          "evidence": {},
156611          "signature": {
156612            "signature": {
156613              "publicKey": {}
156614            }
156615          },
156616          "modelCard": {
156617            "modelParameters": {
156618              "approach": {}
156619            },
156620            "quantitativeAnalysis": {
156621              "graphics": {}
156622            },
156623            "considerations": {}
156624          }
156625        },
156626        {
156627          "type": "library",
156628          "bom-ref": "pkg:golang/github.com/prometheus/procfs@v0.6.0?package-id=535a47f4217466cb",
156629          "supplier": {},
156630          "name": "github.com/prometheus/procfs",
156631          "version": "v0.6.0",
156632          "cpe": "cpe:2.3:a:prometheus:procfs:v0.6.0:*:*:*:*:*:*:*",
156633          "purl": "pkg:golang/github.com/prometheus/procfs@v0.6.0",
156634          "swid": {
156635            "attachment": {}
156636          },
156637          "pedigree": {},
156638          "evidence": {},
156639          "signature": {
156640            "signature": {
156641              "publicKey": {}
156642            }
156643          },
156644          "modelCard": {
156645            "modelParameters": {
156646              "approach": {}
156647            },
156648            "quantitativeAnalysis": {
156649              "graphics": {}
156650            },
156651            "considerations": {}
156652          }
156653        },
156654        {
156655          "type": "library",
156656          "bom-ref": "pkg:golang/github.com/spf13/pflag@v1.0.5?package-id=4d38286b12cd6450",
156657          "supplier": {},
156658          "name": "github.com/spf13/pflag",
156659          "version": "v1.0.5",
156660          "cpe": "cpe:2.3:a:spf13:pflag:v1.0.5:*:*:*:*:*:*:*",
156661          "purl": "pkg:golang/github.com/spf13/pflag@v1.0.5",
156662          "swid": {
156663            "attachment": {}
156664          },
156665          "pedigree": {},
156666          "evidence": {},
156667          "signature": {
156668            "signature": {
156669              "publicKey": {}
156670            }
156671          },
156672          "modelCard": {
156673            "modelParameters": {
156674              "approach": {}
156675            },
156676            "quantitativeAnalysis": {
156677              "graphics": {}
156678            },
156679            "considerations": {}
156680          }
156681        },
156682        {
156683          "type": "library",
156684          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4?package-id=e44cb9cc3c602db6",
156685          "supplier": {},
156686          "name": "golang.org/x/net",
156687          "version": "v0.0.0-20210316092652-d523dce5a7f4",
156688          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20210316092652-d523dce5a7f4:*:*:*:*:*:*:*",
156689          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4",
156690          "swid": {
156691            "attachment": {}
156692          },
156693          "pedigree": {},
156694          "evidence": {},
156695          "signature": {
156696            "signature": {
156697              "publicKey": {}
156698            }
156699          },
156700          "modelCard": {
156701            "modelParameters": {
156702              "approach": {}
156703            },
156704            "quantitativeAnalysis": {
156705              "graphics": {}
156706            },
156707            "considerations": {}
156708          }
156709        },
156710        {
156711          "type": "library",
156712          "bom-ref": "pkg:golang/golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84?package-id=f31028471e0b4388",
156713          "supplier": {},
156714          "name": "golang.org/x/oauth2",
156715          "version": "v0.0.0-20210313182246-cd4f82c27b84",
156716          "cpe": "cpe:2.3:a:golang:x\\/oauth2:v0.0.0-20210313182246-cd4f82c27b84:*:*:*:*:*:*:*",
156717          "purl": "pkg:golang/golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84",
156718          "swid": {
156719            "attachment": {}
156720          },
156721          "pedigree": {},
156722          "evidence": {},
156723          "signature": {
156724            "signature": {
156725              "publicKey": {}
156726            }
156727          },
156728          "modelCard": {
156729            "modelParameters": {
156730              "approach": {}
156731            },
156732            "quantitativeAnalysis": {
156733              "graphics": {}
156734            },
156735            "considerations": {}
156736          }
156737        },
156738        {
156739          "type": "library",
156740          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e?package-id=950dcd4bb9c9f694",
156741          "supplier": {},
156742          "name": "golang.org/x/sys",
156743          "version": "v0.0.0-20210317225723-c4fcb01b228e",
156744          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20210317225723-c4fcb01b228e:*:*:*:*:*:*:*",
156745          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20210317225723-c4fcb01b228e",
156746          "swid": {
156747            "attachment": {}
156748          },
156749          "pedigree": {},
156750          "evidence": {},
156751          "signature": {
156752            "signature": {
156753              "publicKey": {}
156754            }
156755          },
156756          "modelCard": {
156757            "modelParameters": {
156758              "approach": {}
156759            },
156760            "quantitativeAnalysis": {
156761              "graphics": {}
156762            },
156763            "considerations": {}
156764          }
156765        },
156766        {
156767          "type": "library",
156768          "bom-ref": "pkg:golang/golang.org/x/term@v0.0.0-20210317153231-de623e64d2a6?package-id=d248cfab3d519302",
156769          "supplier": {},
156770          "name": "golang.org/x/term",
156771          "version": "v0.0.0-20210317153231-de623e64d2a6",
156772          "cpe": "cpe:2.3:a:golang:x\\/term:v0.0.0-20210317153231-de623e64d2a6:*:*:*:*:*:*:*",
156773          "purl": "pkg:golang/golang.org/x/term@v0.0.0-20210317153231-de623e64d2a6",
156774          "swid": {
156775            "attachment": {}
156776          },
156777          "pedigree": {},
156778          "evidence": {},
156779          "signature": {
156780            "signature": {
156781              "publicKey": {}
156782            }
156783          },
156784          "modelCard": {
156785            "modelParameters": {
156786              "approach": {}
156787            },
156788            "quantitativeAnalysis": {
156789              "graphics": {}
156790            },
156791            "considerations": {}
156792          }
156793        },
156794        {
156795          "type": "library",
156796          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.5?package-id=7492515188a94adc",
156797          "supplier": {},
156798          "name": "golang.org/x/text",
156799          "version": "v0.3.5",
156800          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.5:*:*:*:*:*:*:*",
156801          "purl": "pkg:golang/golang.org/x/text@v0.3.5",
156802          "swid": {
156803            "attachment": {}
156804          },
156805          "pedigree": {},
156806          "evidence": {},
156807          "signature": {
156808            "signature": {
156809              "publicKey": {}
156810            }
156811          },
156812          "modelCard": {
156813            "modelParameters": {
156814              "approach": {}
156815            },
156816            "quantitativeAnalysis": {
156817              "graphics": {}
156818            },
156819            "considerations": {}
156820          }
156821        },
156822        {
156823          "type": "library",
156824          "bom-ref": "pkg:golang/golang.org/x/time@v0.0.0-20210220033141-f8bda1e9f3ba?package-id=9f7b470f10543aaa",
156825          "supplier": {},
156826          "name": "golang.org/x/time",
156827          "version": "v0.0.0-20210220033141-f8bda1e9f3ba",
156828          "cpe": "cpe:2.3:a:golang:x\\/time:v0.0.0-20210220033141-f8bda1e9f3ba:*:*:*:*:*:*:*",
156829          "purl": "pkg:golang/golang.org/x/time@v0.0.0-20210220033141-f8bda1e9f3ba",
156830          "swid": {
156831            "attachment": {}
156832          },
156833          "pedigree": {},
156834          "evidence": {},
156835          "signature": {
156836            "signature": {
156837              "publicKey": {}
156838            }
156839          },
156840          "modelCard": {
156841            "modelParameters": {
156842              "approach": {}
156843            },
156844            "quantitativeAnalysis": {
156845              "graphics": {}
156846            },
156847            "considerations": {}
156848          }
156849        },
156850        {
156851          "type": "library",
156852          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20210317182105-75c7a8546eb9?package-id=eada3d755ec385e8",
156853          "supplier": {},
156854          "name": "google.golang.org/genproto",
156855          "version": "v0.0.0-20210317182105-75c7a8546eb9",
156856          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20210317182105-75c7a8546eb9:*:*:*:*:*:*:*",
156857          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20210317182105-75c7a8546eb9",
156858          "swid": {
156859            "attachment": {}
156860          },
156861          "pedigree": {},
156862          "evidence": {},
156863          "signature": {
156864            "signature": {
156865              "publicKey": {}
156866            }
156867          },
156868          "modelCard": {
156869            "modelParameters": {
156870              "approach": {}
156871            },
156872            "quantitativeAnalysis": {
156873              "graphics": {}
156874            },
156875            "considerations": {}
156876          }
156877        },
156878        {
156879          "type": "library",
156880          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.36.0?package-id=8255b782ac9494a1",
156881          "supplier": {},
156882          "name": "google.golang.org/grpc",
156883          "version": "v1.36.0",
156884          "cpe": "cpe:2.3:a:google:grpc:v1.36.0:*:*:*:*:*:*:*",
156885          "purl": "pkg:golang/google.golang.org/grpc@v1.36.0",
156886          "swid": {
156887            "attachment": {}
156888          },
156889          "pedigree": {},
156890          "evidence": {},
156891          "signature": {
156892            "signature": {
156893              "publicKey": {}
156894            }
156895          },
156896          "modelCard": {
156897            "modelParameters": {
156898              "approach": {}
156899            },
156900            "quantitativeAnalysis": {
156901              "graphics": {}
156902            },
156903            "considerations": {}
156904          }
156905        },
156906        {
156907          "type": "library",
156908          "bom-ref": "pkg:golang/google.golang.org/protobuf@v1.26.0?package-id=5ba9e2d27f0b9a52",
156909          "supplier": {},
156910          "name": "google.golang.org/protobuf",
156911          "version": "v1.26.0",
156912          "cpe": "cpe:2.3:a:google:protobuf:v1.26.0:*:*:*:*:*:*:*",
156913          "purl": "pkg:golang/google.golang.org/protobuf@v1.26.0",
156914          "swid": {
156915            "attachment": {}
156916          },
156917          "pedigree": {},
156918          "evidence": {},
156919          "signature": {
156920            "signature": {
156921              "publicKey": {}
156922            }
156923          },
156924          "modelCard": {
156925            "modelParameters": {
156926              "approach": {}
156927            },
156928            "quantitativeAnalysis": {
156929              "graphics": {}
156930            },
156931            "considerations": {}
156932          }
156933        },
156934        {
156935          "type": "library",
156936          "bom-ref": "pkg:golang/gopkg.in/inf.v0@v0.9.1?package-id=55bacc9ffde81982",
156937          "supplier": {},
156938          "name": "gopkg.in/inf.v0",
156939          "version": "v0.9.1",
156940          "purl": "pkg:golang/gopkg.in/inf.v0@v0.9.1",
156941          "swid": {
156942            "attachment": {}
156943          },
156944          "pedigree": {},
156945          "evidence": {},
156946          "signature": {
156947            "signature": {
156948              "publicKey": {}
156949            }
156950          },
156951          "modelCard": {
156952            "modelParameters": {
156953              "approach": {}
156954            },
156955            "quantitativeAnalysis": {
156956              "graphics": {}
156957            },
156958            "considerations": {}
156959          }
156960        },
156961        {
156962          "type": "library",
156963          "bom-ref": "pkg:golang/gopkg.in/yaml.v2@v2.4.0?package-id=55326b5ee7f9bfa4",
156964          "supplier": {},
156965          "name": "gopkg.in/yaml.v2",
156966          "version": "v2.4.0",
156967          "purl": "pkg:golang/gopkg.in/yaml.v2@v2.4.0",
156968          "swid": {
156969            "attachment": {}
156970          },
156971          "pedigree": {},
156972          "evidence": {},
156973          "signature": {
156974            "signature": {
156975              "publicKey": {}
156976            }
156977          },
156978          "modelCard": {
156979            "modelParameters": {
156980              "approach": {}
156981            },
156982            "quantitativeAnalysis": {
156983              "graphics": {}
156984            },
156985            "considerations": {}
156986          }
156987        },
156988        {
156989          "type": "library",
156990          "bom-ref": "pkg:golang/gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b?package-id=5feeb0f0bddedf6a",
156991          "supplier": {},
156992          "name": "gopkg.in/yaml.v3",
156993          "version": "v3.0.0-20210107192922-496545a6307b",
156994          "purl": "pkg:golang/gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b",
156995          "swid": {
156996            "attachment": {}
156997          },
156998          "pedigree": {},
156999          "evidence": {},
157000          "signature": {
157001            "signature": {
157002              "publicKey": {}
157003            }
157004          },
157005          "modelCard": {
157006            "modelParameters": {
157007              "approach": {}
157008            },
157009            "quantitativeAnalysis": {
157010              "graphics": {}
157011            },
157012            "considerations": {}
157013          }
157014        },
157015        {
157016          "type": "library",
157017          "bom-ref": "pkg:golang/k8s.io/api@v0.21.0?package-id=ff3c9d603f5b46c4",
157018          "supplier": {},
157019          "name": "k8s.io/api",
157020          "version": "v0.21.0",
157021          "purl": "pkg:golang/k8s.io/api@v0.21.0",
157022          "swid": {
157023            "attachment": {}
157024          },
157025          "pedigree": {},
157026          "evidence": {},
157027          "signature": {
157028            "signature": {
157029              "publicKey": {}
157030            }
157031          },
157032          "modelCard": {
157033            "modelParameters": {
157034              "approach": {}
157035            },
157036            "quantitativeAnalysis": {
157037              "graphics": {}
157038            },
157039            "considerations": {}
157040          }
157041        },
157042        {
157043          "type": "library",
157044          "bom-ref": "pkg:golang/k8s.io/apimachinery@v0.21.0?package-id=6581a390e38569d3",
157045          "supplier": {},
157046          "name": "k8s.io/apimachinery",
157047          "version": "v0.21.0",
157048          "purl": "pkg:golang/k8s.io/apimachinery@v0.21.0",
157049          "swid": {
157050            "attachment": {}
157051          },
157052          "pedigree": {},
157053          "evidence": {},
157054          "signature": {
157055            "signature": {
157056              "publicKey": {}
157057            }
157058          },
157059          "modelCard": {
157060            "modelParameters": {
157061              "approach": {}
157062            },
157063            "quantitativeAnalysis": {
157064              "graphics": {}
157065            },
157066            "considerations": {}
157067          }
157068        },
157069        {
157070          "type": "library",
157071          "bom-ref": "pkg:golang/k8s.io/apiserver@v0.20.0?package-id=4db3b35cb1bf574a",
157072          "supplier": {},
157073          "name": "k8s.io/apiserver",
157074          "version": "v0.20.0",
157075          "purl": "pkg:golang/k8s.io/apiserver@v0.20.0",
157076          "swid": {
157077            "attachment": {}
157078          },
157079          "pedigree": {},
157080          "evidence": {},
157081          "signature": {
157082            "signature": {
157083              "publicKey": {}
157084            }
157085          },
157086          "modelCard": {
157087            "modelParameters": {
157088              "approach": {}
157089            },
157090            "quantitativeAnalysis": {
157091              "graphics": {}
157092            },
157093            "considerations": {}
157094          }
157095        },
157096        {
157097          "type": "library",
157098          "bom-ref": "pkg:golang/k8s.io/client-go@v0.21.0?package-id=36d03aada45c2efe",
157099          "supplier": {},
157100          "name": "k8s.io/client-go",
157101          "version": "v0.21.0",
157102          "purl": "pkg:golang/k8s.io/client-go@v0.21.0",
157103          "swid": {
157104            "attachment": {}
157105          },
157106          "pedigree": {},
157107          "evidence": {},
157108          "signature": {
157109            "signature": {
157110              "publicKey": {}
157111            }
157112          },
157113          "modelCard": {
157114            "modelParameters": {
157115              "approach": {}
157116            },
157117            "quantitativeAnalysis": {
157118              "graphics": {}
157119            },
157120            "considerations": {}
157121          }
157122        },
157123        {
157124          "type": "library",
157125          "bom-ref": "pkg:golang/k8s.io/component-base@v0.21.0?package-id=88d86de91cbd8dd6",
157126          "supplier": {},
157127          "name": "k8s.io/component-base",
157128          "version": "v0.21.0",
157129          "purl": "pkg:golang/k8s.io/component-base@v0.21.0",
157130          "swid": {
157131            "attachment": {}
157132          },
157133          "pedigree": {},
157134          "evidence": {},
157135          "signature": {
157136            "signature": {
157137              "publicKey": {}
157138            }
157139          },
157140          "modelCard": {
157141            "modelParameters": {
157142              "approach": {}
157143            },
157144            "quantitativeAnalysis": {
157145              "graphics": {}
157146            },
157147            "considerations": {}
157148          }
157149        },
157150        {
157151          "type": "library",
157152          "bom-ref": "pkg:golang/k8s.io/csi-translation-lib@v0.21.0?package-id=b06287d56fb3bfc3",
157153          "supplier": {},
157154          "name": "k8s.io/csi-translation-lib",
157155          "version": "v0.21.0",
157156          "purl": "pkg:golang/k8s.io/csi-translation-lib@v0.21.0",
157157          "swid": {
157158            "attachment": {}
157159          },
157160          "pedigree": {},
157161          "evidence": {},
157162          "signature": {
157163            "signature": {
157164              "publicKey": {}
157165            }
157166          },
157167          "modelCard": {
157168            "modelParameters": {
157169              "approach": {}
157170            },
157171            "quantitativeAnalysis": {
157172              "graphics": {}
157173            },
157174            "considerations": {}
157175          }
157176        },
157177        {
157178          "type": "library",
157179          "bom-ref": "pkg:golang/k8s.io/klog/v2@v2.8.0?package-id=39073ab938b1c44d",
157180          "supplier": {},
157181          "name": "k8s.io/klog/v2",
157182          "version": "v2.8.0",
157183          "cpe": "cpe:2.3:a:klog:v2:v2.8.0:*:*:*:*:*:*:*",
157184          "purl": "pkg:golang/k8s.io/klog/v2@v2.8.0",
157185          "swid": {
157186            "attachment": {}
157187          },
157188          "pedigree": {},
157189          "evidence": {},
157190          "signature": {
157191            "signature": {
157192              "publicKey": {}
157193            }
157194          },
157195          "modelCard": {
157196            "modelParameters": {
157197              "approach": {}
157198            },
157199            "quantitativeAnalysis": {
157200              "graphics": {}
157201            },
157202            "considerations": {}
157203          }
157204        },
157205        {
157206          "type": "library",
157207          "bom-ref": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20210305164622-f622666832c1?package-id=b4a1f6ece5f5f037",
157208          "supplier": {},
157209          "name": "k8s.io/kube-openapi",
157210          "version": "v0.0.0-20210305164622-f622666832c1",
157211          "purl": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20210305164622-f622666832c1",
157212          "swid": {
157213            "attachment": {}
157214          },
157215          "pedigree": {},
157216          "evidence": {},
157217          "signature": {
157218            "signature": {
157219              "publicKey": {}
157220            }
157221          },
157222          "modelCard": {
157223            "modelParameters": {
157224              "approach": {}
157225            },
157226            "quantitativeAnalysis": {
157227              "graphics": {}
157228            },
157229            "considerations": {}
157230          }
157231        },
157232        {
157233          "type": "library",
157234          "bom-ref": "pkg:golang/k8s.io/utils@v0.0.0-20210305010621-2afb4311ab10?package-id=28103bb78327fc1b",
157235          "supplier": {},
157236          "name": "k8s.io/utils",
157237          "version": "v0.0.0-20210305010621-2afb4311ab10",
157238          "purl": "pkg:golang/k8s.io/utils@v0.0.0-20210305010621-2afb4311ab10",
157239          "swid": {
157240            "attachment": {}
157241          },
157242          "pedigree": {},
157243          "evidence": {},
157244          "signature": {
157245            "signature": {
157246              "publicKey": {}
157247            }
157248          },
157249          "modelCard": {
157250            "modelParameters": {
157251              "approach": {}
157252            },
157253            "quantitativeAnalysis": {
157254              "graphics": {}
157255            },
157256            "considerations": {}
157257          }
157258        },
157259        {
157260          "type": "library",
157261          "bom-ref": "pkg:deb/debian/netbase@5.6?arch=all\u0026distro=debian-10\u0026package-id=b55e51dca4eba9a6",
157262          "supplier": {},
157263          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
157264          "name": "netbase",
157265          "version": "5.6",
157266          "licenses": [
157267            {
157268              "license": {
157269                "id": "GPL-2.0-only"
157270              }
157271            }
157272          ],
157273          "cpe": "cpe:2.3:a:netbase:netbase:5.6:*:*:*:*:*:*:*",
157274          "purl": "pkg:deb/debian/netbase@5.6?arch=all\u0026distro=debian-10",
157275          "swid": {
157276            "attachment": {}
157277          },
157278          "pedigree": {},
157279          "evidence": {},
157280          "signature": {
157281            "signature": {
157282              "publicKey": {}
157283            }
157284          },
157285          "modelCard": {
157286            "modelParameters": {
157287              "approach": {}
157288            },
157289            "quantitativeAnalysis": {
157290              "graphics": {}
157291            },
157292            "considerations": {}
157293          }
157294        },
157295        {
157296          "type": "library",
157297          "bom-ref": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.1.0?package-id=f721ecf66abff125",
157298          "supplier": {},
157299          "name": "sigs.k8s.io/structured-merge-diff/v4",
157300          "version": "v4.1.0",
157301          "cpe": "cpe:2.3:a:structured-merge-diff:v4:v4.1.0:*:*:*:*:*:*:*",
157302          "purl": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.1.0",
157303          "swid": {
157304            "attachment": {}
157305          },
157306          "pedigree": {},
157307          "evidence": {},
157308          "signature": {
157309            "signature": {
157310              "publicKey": {}
157311            }
157312          },
157313          "modelCard": {
157314            "modelParameters": {
157315              "approach": {}
157316            },
157317            "quantitativeAnalysis": {
157318              "graphics": {}
157319            },
157320            "considerations": {}
157321          }
157322        },
157323        {
157324          "type": "library",
157325          "bom-ref": "pkg:golang/sigs.k8s.io/yaml@v1.2.0?package-id=7a71f62ed60b4490",
157326          "supplier": {},
157327          "name": "sigs.k8s.io/yaml",
157328          "version": "v1.2.0",
157329          "purl": "pkg:golang/sigs.k8s.io/yaml@v1.2.0",
157330          "swid": {
157331            "attachment": {}
157332          },
157333          "pedigree": {},
157334          "evidence": {},
157335          "signature": {
157336            "signature": {
157337              "publicKey": {}
157338            }
157339          },
157340          "modelCard": {
157341            "modelParameters": {
157342              "approach": {}
157343            },
157344            "quantitativeAnalysis": {
157345              "graphics": {}
157346            },
157347            "considerations": {}
157348          }
157349        },
157350        {
157351          "type": "library",
157352          "bom-ref": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10\u0026package-id=9e5b2198bbbd7fb0",
157353          "supplier": {},
157354          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
157355          "name": "tzdata",
157356          "version": "2021a-0+deb10u1",
157357          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0\\+deb10u1:*:*:*:*:*:*:*",
157358          "purl": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10",
157359          "swid": {
157360            "attachment": {}
157361          },
157362          "pedigree": {},
157363          "evidence": {},
157364          "signature": {
157365            "signature": {
157366              "publicKey": {}
157367            }
157368          },
157369          "modelCard": {
157370            "modelParameters": {
157371              "approach": {}
157372            },
157373            "quantitativeAnalysis": {
157374              "graphics": {}
157375            },
157376            "considerations": {}
157377          }
157378        },
157379        {
157380          "type": "operating-system",
157381          "supplier": {},
157382          "name": "debian",
157383          "version": "10",
157384          "description": "Distroless",
157385          "swid": {
157386            "tagId": "debian",
157387            "name": "debian",
157388            "version": "10",
157389            "attachment": {}
157390          },
157391          "pedigree": {},
157392          "externalReferences": [
157393            {
157394              "url": "https://github.com/GoogleContainerTools/distroless/issues/new",
157395              "type": "issue-tracker"
157396            },
157397            {
157398              "url": "https://github.com/GoogleContainerTools/distroless",
157399              "type": "website"
157400            },
157401            {
157402              "url": "https://github.com/GoogleContainerTools/distroless/blob/master/README.md",
157403              "comment": "support",
157404              "type": "other"
157405            }
157406          ],
157407          "evidence": {},
157408          "signature": {
157409            "signature": {
157410              "publicKey": {}
157411            }
157412          },
157413          "modelCard": {
157414            "modelParameters": {
157415              "approach": {}
157416            },
157417            "quantitativeAnalysis": {
157418              "graphics": {}
157419            },
157420            "considerations": {}
157421          }
157422        },
157423        {
157424          "type": "library",
157425          "bom-ref": "pkg:npm/1to2@1.0.0?package-id=b0ed3b5fe4e5cbb3",
157426          "supplier": {},
157427          "name": "1to2",
157428          "version": "1.0.0",
157429          "description": "NAN 1 -\u003e 2 Migration Script",
157430          "licenses": [
157431            {
157432              "license": {
157433                "id": "MIT"
157434              }
157435            }
157436          ],
157437          "cpe": "cpe:2.3:a:nodejs:1to2:1.0.0:*:*:*:*:*:*:*",
157438          "purl": "pkg:npm/1to2@1.0.0",
157439          "swid": {
157440            "attachment": {}
157441          },
157442          "pedigree": {},
157443          "externalReferences": [
157444            {
157445              "url": "git://github.com/nodejs/nan.git",
157446              "type": "distribution"
157447            }
157448          ],
157449          "evidence": {},
157450          "signature": {
157451            "signature": {
157452              "publicKey": {}
157453            }
157454          },
157455          "modelCard": {
157456            "modelParameters": {
157457              "approach": {}
157458            },
157459            "quantitativeAnalysis": {
157460              "graphics": {}
157461            },
157462            "considerations": {}
157463          }
157464        },
157465        {
157466          "type": "library",
157467          "bom-ref": "pkg:npm/%40angular/material@8.0.0?package-id=1d00b998d1390487",
157468          "supplier": {},
157469          "name": "@angular/material",
157470          "version": "8.0.0",
157471          "description": "Angular Material",
157472          "licenses": [
157473            {
157474              "license": {
157475                "id": "MIT"
157476              }
157477            }
157478          ],
157479          "cpe": "cpe:2.3:a:\\@angular\\/material:\\@angular\\/material:8.0.0:*:*:*:*:*:*:*",
157480          "purl": "pkg:npm/%40angular/material@8.0.0",
157481          "swid": {
157482            "attachment": {}
157483          },
157484          "pedigree": {},
157485          "externalReferences": [
157486            {
157487              "url": "https://github.com/angular/components.git",
157488              "type": "distribution"
157489            },
157490            {
157491              "url": "https://github.com/angular/components#readme",
157492              "type": "website"
157493            }
157494          ],
157495          "evidence": {},
157496          "signature": {
157497            "signature": {
157498              "publicKey": {}
157499            }
157500          },
157501          "modelCard": {
157502            "modelParameters": {
157503              "approach": {}
157504            },
157505            "quantitativeAnalysis": {
157506              "graphics": {}
157507            },
157508            "considerations": {}
157509          }
157510        },
157511        {
157512          "type": "library",
157513          "bom-ref": "pkg:npm/%40aytek/material-color-picker@1.0.4?package-id=446759678641ab0d",
157514          "supplier": {},
157515          "author": "Aytek Meral \u0026 S. Ferit Arslan",
157516          "name": "@aytek/material-color-picker",
157517          "version": "1.0.4",
157518          "description": "material color picker ",
157519          "licenses": [
157520            {
157521              "license": {
157522                "id": "MIT"
157523              }
157524            }
157525          ],
157526          "cpe": "cpe:2.3:a:\\@aytek\\/material-color-picker:\\@aytek\\/material-color-picker:1.0.4:*:*:*:*:*:*:*",
157527          "purl": "pkg:npm/%40aytek/material-color-picker@1.0.4",
157528          "swid": {
157529            "attachment": {}
157530          },
157531          "pedigree": {},
157532          "evidence": {},
157533          "signature": {
157534            "signature": {
157535              "publicKey": {}
157536            }
157537          },
157538          "modelCard": {
157539            "modelParameters": {
157540              "approach": {}
157541            },
157542            "quantitativeAnalysis": {
157543              "graphics": {}
157544            },
157545            "considerations": {}
157546          }
157547        },
157548        {
157549          "type": "library",
157550          "bom-ref": "pkg:npm/%40babel/code-frame@7.21.4?package-id=20a467bc170e49cb",
157551          "supplier": {},
157552          "author": "The Babel Team (https://babel.dev/team)",
157553          "name": "@babel/code-frame",
157554          "version": "7.21.4",
157555          "description": "Generate errors that contain a code frame that point to source locations.",
157556          "licenses": [
157557            {
157558              "license": {
157559                "id": "MIT"
157560              }
157561            }
157562          ],
157563          "cpe": "cpe:2.3:a:\\@babel\\/code-frame:\\@babel\\/code-frame:7.21.4:*:*:*:*:*:*:*",
157564          "purl": "pkg:npm/%40babel/code-frame@7.21.4",
157565          "swid": {
157566            "attachment": {}
157567          },
157568          "pedigree": {},
157569          "externalReferences": [
157570            {
157571              "url": "https://github.com/babel/babel.git",
157572              "type": "distribution"
157573            },
157574            {
157575              "url": "https://babel.dev/docs/en/next/babel-code-frame",
157576              "type": "website"
157577            }
157578          ],
157579          "evidence": {},
157580          "signature": {
157581            "signature": {
157582              "publicKey": {}
157583            }
157584          },
157585          "modelCard": {
157586            "modelParameters": {
157587              "approach": {}
157588            },
157589            "quantitativeAnalysis": {
157590              "graphics": {}
157591            },
157592            "considerations": {}
157593          }
157594        },
157595        {
157596          "type": "library",
157597          "bom-ref": "pkg:npm/%40babel/helper-validator-identifier@7.19.1?package-id=9118211910506819",
157598          "supplier": {},
157599          "author": "The Babel Team (https://babel.dev/team)",
157600          "name": "@babel/helper-validator-identifier",
157601          "version": "7.19.1",
157602          "description": "Validate identifier/keywords name",
157603          "licenses": [
157604            {
157605              "license": {
157606                "id": "MIT"
157607              }
157608            }
157609          ],
157610          "cpe": "cpe:2.3:a:\\@babel\\/helper-validator-identifier:\\@babel\\/helper-validator-identifier:7.19.1:*:*:*:*:*:*:*",
157611          "purl": "pkg:npm/%40babel/helper-validator-identifier@7.19.1",
157612          "swid": {
157613            "attachment": {}
157614          },
157615          "pedigree": {},
157616          "externalReferences": [
157617            {
157618              "url": "https://github.com/babel/babel.git",
157619              "type": "distribution"
157620            }
157621          ],
157622          "evidence": {},
157623          "signature": {
157624            "signature": {
157625              "publicKey": {}
157626            }
157627          },
157628          "modelCard": {
157629            "modelParameters": {
157630              "approach": {}
157631            },
157632            "quantitativeAnalysis": {
157633              "graphics": {}
157634            },
157635            "considerations": {}
157636          }
157637        },
157638        {
157639          "type": "library",
157640          "bom-ref": "pkg:npm/%40babel/highlight@7.18.6?package-id=67f84cf681f3c74c",
157641          "supplier": {},
157642          "author": "The Babel Team (https://babel.dev/team)",
157643          "name": "@babel/highlight",
157644          "version": "7.18.6",
157645          "description": "Syntax highlight JavaScript strings for output in terminals.",
157646          "licenses": [
157647            {
157648              "license": {
157649                "id": "MIT"
157650              }
157651            }
157652          ],
157653          "cpe": "cpe:2.3:a:\\@babel\\/highlight:\\@babel\\/highlight:7.18.6:*:*:*:*:*:*:*",
157654          "purl": "pkg:npm/%40babel/highlight@7.18.6",
157655          "swid": {
157656            "attachment": {}
157657          },
157658          "pedigree": {},
157659          "externalReferences": [
157660            {
157661              "url": "https://github.com/babel/babel.git",
157662              "type": "distribution"
157663            },
157664            {
157665              "url": "https://babel.dev/docs/en/next/babel-highlight",
157666              "type": "website"
157667            }
157668          ],
157669          "evidence": {},
157670          "signature": {
157671            "signature": {
157672              "publicKey": {}
157673            }
157674          },
157675          "modelCard": {
157676            "modelParameters": {
157677              "approach": {}
157678            },
157679            "quantitativeAnalysis": {
157680              "graphics": {}
157681            },
157682            "considerations": {}
157683          }
157684        },
157685        {
157686          "type": "library",
157687          "bom-ref": "pkg:npm/%40colors/colors@1.5.0?package-id=1e63eea14f4d61ef",
157688          "supplier": {},
157689          "author": "DABH",
157690          "name": "@colors/colors",
157691          "version": "1.5.0",
157692          "description": "get colors in your node.js console",
157693          "licenses": [
157694            {
157695              "license": {
157696                "id": "MIT"
157697              }
157698            }
157699          ],
157700          "cpe": "cpe:2.3:a:\\@colors\\/colors:\\@colors\\/colors:1.5.0:*:*:*:*:*:*:*",
157701          "purl": "pkg:npm/%40colors/colors@1.5.0",
157702          "swid": {
157703            "attachment": {}
157704          },
157705          "pedigree": {},
157706          "externalReferences": [
157707            {
157708              "url": "http://github.com/DABH/colors.js.git",
157709              "type": "distribution"
157710            },
157711            {
157712              "url": "https://github.com/DABH/colors.js",
157713              "type": "website"
157714            }
157715          ],
157716          "evidence": {},
157717          "signature": {
157718            "signature": {
157719              "publicKey": {}
157720            }
157721          },
157722          "modelCard": {
157723            "modelParameters": {
157724              "approach": {}
157725            },
157726            "quantitativeAnalysis": {
157727              "graphics": {}
157728            },
157729            "considerations": {}
157730          }
157731        },
157732        {
157733          "type": "library",
157734          "bom-ref": "pkg:npm/%40danielmoncada/angular-datetime-picker@9.2.0?package-id=9c4e82e05b812a03",
157735          "supplier": {},
157736          "author": "Maintained and updated by Daniel Moncada, original implementatiom by Daniel Pan",
157737          "name": "@danielmoncada/angular-datetime-picker",
157738          "version": "9.2.0",
157739          "description": "Angular Date Time Picker",
157740          "licenses": [
157741            {
157742              "license": {
157743                "id": "MIT"
157744              }
157745            }
157746          ],
157747          "cpe": "cpe:2.3:a:\\@danielmoncada\\/angular-datetime-picker:\\@danielmoncada\\/angular-datetime-picker:9.2.0:*:*:*:*:*:*:*",
157748          "purl": "pkg:npm/%40danielmoncada/angular-datetime-picker@9.2.0",
157749          "swid": {
157750            "attachment": {}
157751          },
157752          "pedigree": {},
157753          "externalReferences": [
157754            {
157755              "url": "https://github.com/danielmoncada/date-time-picker.git",
157756              "type": "distribution"
157757            },
157758            {
157759              "url": "https://github.com/danielmoncada/date-time-picker",
157760              "type": "website"
157761            }
157762          ],
157763          "evidence": {},
157764          "signature": {
157765            "signature": {
157766              "publicKey": {}
157767            }
157768          },
157769          "modelCard": {
157770            "modelParameters": {
157771              "approach": {}
157772            },
157773            "quantitativeAnalysis": {
157774              "graphics": {}
157775            },
157776            "considerations": {}
157777          }
157778        },
157779        {
157780          "type": "library",
157781          "bom-ref": "pkg:npm/%40gar/promisify@1.1.3?package-id=6fab079a7c06c1de",
157782          "supplier": {},
157783          "author": "Gar \u003cgar+npm@danger.computer\u003e",
157784          "name": "@gar/promisify",
157785          "version": "1.1.3",
157786          "description": "Promisify an entire class or object",
157787          "licenses": [
157788            {
157789              "license": {
157790                "id": "MIT"
157791              }
157792            }
157793          ],
157794          "cpe": "cpe:2.3:a:\\@gar\\/promisify:\\@gar\\/promisify:1.1.3:*:*:*:*:*:*:*",
157795          "purl": "pkg:npm/%40gar/promisify@1.1.3",
157796          "swid": {
157797            "attachment": {}
157798          },
157799          "pedigree": {},
157800          "externalReferences": [
157801            {
157802              "url": "https://github.com/wraithgar/gar-promisify.git",
157803              "type": "distribution"
157804            }
157805          ],
157806          "evidence": {},
157807          "signature": {
157808            "signature": {
157809              "publicKey": {}
157810            }
157811          },
157812          "modelCard": {
157813            "modelParameters": {
157814              "approach": {}
157815            },
157816            "quantitativeAnalysis": {
157817              "graphics": {}
157818            },
157819            "considerations": {}
157820          }
157821        },
157822        {
157823          "type": "library",
157824          "bom-ref": "pkg:npm/%40isaacs/string-locale-compare@1.1.0?package-id=fbe0dcb344723a67",
157825          "supplier": {},
157826          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
157827          "name": "@isaacs/string-locale-compare",
157828          "version": "1.1.0",
157829          "description": "Compare strings with Intl.Collator if available, falling back to String.localeCompare otherwise",
157830          "licenses": [
157831            {
157832              "license": {
157833                "id": "ISC"
157834              }
157835            }
157836          ],
157837          "cpe": "cpe:2.3:a:\\@isaacs\\/string-locale-compare:\\@isaacs\\/string-locale-compare:1.1.0:*:*:*:*:*:*:*",
157838          "purl": "pkg:npm/%40isaacs/string-locale-compare@1.1.0",
157839          "swid": {
157840            "attachment": {}
157841          },
157842          "pedigree": {},
157843          "externalReferences": [
157844            {
157845              "url": "git+https://github.com/isaacs/string-locale-compare",
157846              "type": "distribution"
157847            }
157848          ],
157849          "evidence": {},
157850          "signature": {
157851            "signature": {
157852              "publicKey": {}
157853            }
157854          },
157855          "modelCard": {
157856            "modelParameters": {
157857              "approach": {}
157858            },
157859            "quantitativeAnalysis": {
157860              "graphics": {}
157861            },
157862            "considerations": {}
157863          }
157864        },
157865        {
157866          "type": "library",
157867          "bom-ref": "pkg:npm/%40my-scope/package-a@0.0.0?package-id=9e7e5553c3ebce03",
157868          "supplier": {},
157869          "name": "@my-scope/package-a",
157870          "version": "0.0.0",
157871          "licenses": [
157872            {
157873              "license": {
157874                "id": "MIT"
157875              }
157876            }
157877          ],
157878          "cpe": "cpe:2.3:a:\\@my-scope\\/package-a:\\@my-scope\\/package-a:0.0.0:*:*:*:*:*:*:*",
157879          "purl": "pkg:npm/%40my-scope/package-a@0.0.0",
157880          "swid": {
157881            "attachment": {}
157882          },
157883          "pedigree": {},
157884          "evidence": {},
157885          "signature": {
157886            "signature": {
157887              "publicKey": {}
157888            }
157889          },
157890          "modelCard": {
157891            "modelParameters": {
157892              "approach": {}
157893            },
157894            "quantitativeAnalysis": {
157895              "graphics": {}
157896            },
157897            "considerations": {}
157898          }
157899        },
157900        {
157901          "type": "library",
157902          "bom-ref": "pkg:npm/%40my-scope/package-b@0.0.0?package-id=9abfa6541a414f95",
157903          "supplier": {},
157904          "name": "@my-scope/package-b",
157905          "version": "0.0.0",
157906          "licenses": [
157907            {
157908              "license": {
157909                "id": "MIT"
157910              }
157911            }
157912          ],
157913          "cpe": "cpe:2.3:a:\\@my-scope\\/package-b:\\@my-scope\\/package-b:0.0.0:*:*:*:*:*:*:*",
157914          "purl": "pkg:npm/%40my-scope/package-b@0.0.0",
157915          "swid": {
157916            "attachment": {}
157917          },
157918          "pedigree": {},
157919          "evidence": {},
157920          "signature": {
157921            "signature": {
157922              "publicKey": {}
157923            }
157924          },
157925          "modelCard": {
157926            "modelParameters": {
157927              "approach": {}
157928            },
157929            "quantitativeAnalysis": {
157930              "graphics": {}
157931            },
157932            "considerations": {}
157933          }
157934        },
157935        {
157936          "type": "library",
157937          "bom-ref": "pkg:npm/%40npmcli/arborist@5.6.3?package-id=60e008e2ceb94218",
157938          "supplier": {},
157939          "author": "GitHub Inc.",
157940          "name": "@npmcli/arborist",
157941          "version": "5.6.3",
157942          "description": "Manage node_modules trees",
157943          "licenses": [
157944            {
157945              "license": {
157946                "id": "ISC"
157947              }
157948            }
157949          ],
157950          "cpe": "cpe:2.3:a:\\@npmcli\\/arborist:\\@npmcli\\/arborist:5.6.3:*:*:*:*:*:*:*",
157951          "purl": "pkg:npm/%40npmcli/arborist@5.6.3",
157952          "swid": {
157953            "attachment": {}
157954          },
157955          "pedigree": {},
157956          "externalReferences": [
157957            {
157958              "url": "https://github.com/npm/cli.git",
157959              "type": "distribution"
157960            }
157961          ],
157962          "evidence": {},
157963          "signature": {
157964            "signature": {
157965              "publicKey": {}
157966            }
157967          },
157968          "modelCard": {
157969            "modelParameters": {
157970              "approach": {}
157971            },
157972            "quantitativeAnalysis": {
157973              "graphics": {}
157974            },
157975            "considerations": {}
157976          }
157977        },
157978        {
157979          "type": "library",
157980          "bom-ref": "pkg:npm/%40npmcli/ci-detect@2.0.0?package-id=8a40a38b900bcf1d",
157981          "supplier": {},
157982          "author": "GitHub Inc.",
157983          "name": "@npmcli/ci-detect",
157984          "version": "2.0.0",
157985          "description": "Detect what kind of CI environment the program is in",
157986          "licenses": [
157987            {
157988              "license": {
157989                "id": "ISC"
157990              }
157991            }
157992          ],
157993          "cpe": "cpe:2.3:a:\\@npmcli\\/ci-detect:\\@npmcli\\/ci-detect:2.0.0:*:*:*:*:*:*:*",
157994          "purl": "pkg:npm/%40npmcli/ci-detect@2.0.0",
157995          "swid": {
157996            "attachment": {}
157997          },
157998          "pedigree": {},
157999          "externalReferences": [
158000            {
158001              "url": "git+https://github.com/npm/ci-detect.git",
158002              "type": "distribution"
158003            }
158004          ],
158005          "evidence": {},
158006          "signature": {
158007            "signature": {
158008              "publicKey": {}
158009            }
158010          },
158011          "modelCard": {
158012            "modelParameters": {
158013              "approach": {}
158014            },
158015            "quantitativeAnalysis": {
158016              "graphics": {}
158017            },
158018            "considerations": {}
158019          }
158020        },
158021        {
158022          "type": "library",
158023          "bom-ref": "pkg:npm/%40npmcli/config@4.2.2?package-id=a02559bafd837882",
158024          "supplier": {},
158025          "author": "GitHub Inc.",
158026          "name": "@npmcli/config",
158027          "version": "4.2.2",
158028          "description": "Configuration management for the npm cli",
158029          "licenses": [
158030            {
158031              "license": {
158032                "id": "ISC"
158033              }
158034            }
158035          ],
158036          "cpe": "cpe:2.3:a:\\@npmcli\\/config:\\@npmcli\\/config:4.2.2:*:*:*:*:*:*:*",
158037          "purl": "pkg:npm/%40npmcli/config@4.2.2",
158038          "swid": {
158039            "attachment": {}
158040          },
158041          "pedigree": {},
158042          "externalReferences": [
158043            {
158044              "url": "https://github.com/npm/config.git",
158045              "type": "distribution"
158046            }
158047          ],
158048          "evidence": {},
158049          "signature": {
158050            "signature": {
158051              "publicKey": {}
158052            }
158053          },
158054          "modelCard": {
158055            "modelParameters": {
158056              "approach": {}
158057            },
158058            "quantitativeAnalysis": {
158059              "graphics": {}
158060            },
158061            "considerations": {}
158062          }
158063        },
158064        {
158065          "type": "library",
158066          "bom-ref": "pkg:npm/%40npmcli/disparity-colors@2.0.0?package-id=3e63715f5300a753",
158067          "supplier": {},
158068          "author": "GitHub Inc.",
158069          "name": "@npmcli/disparity-colors",
158070          "version": "2.0.0",
158071          "description": "Colorizes unified diff output",
158072          "licenses": [
158073            {
158074              "license": {
158075                "id": "ISC"
158076              }
158077            }
158078          ],
158079          "cpe": "cpe:2.3:a:\\@npmcli\\/disparity-colors:\\@npmcli\\/disparity-colors:2.0.0:*:*:*:*:*:*:*",
158080          "purl": "pkg:npm/%40npmcli/disparity-colors@2.0.0",
158081          "swid": {
158082            "attachment": {}
158083          },
158084          "pedigree": {},
158085          "externalReferences": [
158086            {
158087              "url": "https://github.com/npm/disparity-colors.git",
158088              "type": "distribution"
158089            }
158090          ],
158091          "evidence": {},
158092          "signature": {
158093            "signature": {
158094              "publicKey": {}
158095            }
158096          },
158097          "modelCard": {
158098            "modelParameters": {
158099              "approach": {}
158100            },
158101            "quantitativeAnalysis": {
158102              "graphics": {}
158103            },
158104            "considerations": {}
158105          }
158106        },
158107        {
158108          "type": "library",
158109          "bom-ref": "pkg:npm/%40npmcli/fs@2.1.2?package-id=cd19a20b4774187f",
158110          "supplier": {},
158111          "author": "GitHub Inc.",
158112          "name": "@npmcli/fs",
158113          "version": "2.1.2",
158114          "description": "filesystem utilities for the npm cli",
158115          "licenses": [
158116            {
158117              "license": {
158118                "id": "ISC"
158119              }
158120            }
158121          ],
158122          "cpe": "cpe:2.3:a:\\@npmcli\\/fs:\\@npmcli\\/fs:2.1.2:*:*:*:*:*:*:*",
158123          "purl": "pkg:npm/%40npmcli/fs@2.1.2",
158124          "swid": {
158125            "attachment": {}
158126          },
158127          "pedigree": {},
158128          "externalReferences": [
158129            {
158130              "url": "https://github.com/npm/fs.git",
158131              "type": "distribution"
158132            }
158133          ],
158134          "evidence": {},
158135          "signature": {
158136            "signature": {
158137              "publicKey": {}
158138            }
158139          },
158140          "modelCard": {
158141            "modelParameters": {
158142              "approach": {}
158143            },
158144            "quantitativeAnalysis": {
158145              "graphics": {}
158146            },
158147            "considerations": {}
158148          }
158149        },
158150        {
158151          "type": "library",
158152          "bom-ref": "pkg:npm/%40npmcli/git@3.0.2?package-id=34b16cf601f612a9",
158153          "supplier": {},
158154          "author": "GitHub Inc.",
158155          "name": "@npmcli/git",
158156          "version": "3.0.2",
158157          "description": "a util for spawning git from npm CLI contexts",
158158          "licenses": [
158159            {
158160              "license": {
158161                "id": "ISC"
158162              }
158163            }
158164          ],
158165          "cpe": "cpe:2.3:a:\\@npmcli\\/git:\\@npmcli\\/git:3.0.2:*:*:*:*:*:*:*",
158166          "purl": "pkg:npm/%40npmcli/git@3.0.2",
158167          "swid": {
158168            "attachment": {}
158169          },
158170          "pedigree": {},
158171          "externalReferences": [
158172            {
158173              "url": "https://github.com/npm/git.git",
158174              "type": "distribution"
158175            }
158176          ],
158177          "evidence": {},
158178          "signature": {
158179            "signature": {
158180              "publicKey": {}
158181            }
158182          },
158183          "modelCard": {
158184            "modelParameters": {
158185              "approach": {}
158186            },
158187            "quantitativeAnalysis": {
158188              "graphics": {}
158189            },
158190            "considerations": {}
158191          }
158192        },
158193        {
158194          "type": "library",
158195          "bom-ref": "pkg:npm/%40npmcli/installed-package-contents@1.0.7?package-id=8562f58f85ba40df",
158196          "supplier": {},
158197          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
158198          "name": "@npmcli/installed-package-contents",
158199          "version": "1.0.7",
158200          "description": "Get the list of files installed in a package in node_modules, including bundled dependencies",
158201          "licenses": [
158202            {
158203              "license": {
158204                "id": "ISC"
158205              }
158206            }
158207          ],
158208          "cpe": "cpe:2.3:a:\\@npmcli\\/installed-package-contents:\\@npmcli\\/installed-package-contents:1.0.7:*:*:*:*:*:*:*",
158209          "purl": "pkg:npm/%40npmcli/installed-package-contents@1.0.7",
158210          "swid": {
158211            "attachment": {}
158212          },
158213          "pedigree": {},
158214          "externalReferences": [
158215            {
158216              "url": "git+https://github.com/npm/installed-package-contents",
158217              "type": "distribution"
158218            }
158219          ],
158220          "evidence": {},
158221          "signature": {
158222            "signature": {
158223              "publicKey": {}
158224            }
158225          },
158226          "modelCard": {
158227            "modelParameters": {
158228              "approach": {}
158229            },
158230            "quantitativeAnalysis": {
158231              "graphics": {}
158232            },
158233            "considerations": {}
158234          }
158235        },
158236        {
158237          "type": "library",
158238          "bom-ref": "pkg:npm/%40npmcli/map-workspaces@2.0.4?package-id=471052449bb417cb",
158239          "supplier": {},
158240          "author": "GitHub Inc.",
158241          "name": "@npmcli/map-workspaces",
158242          "version": "2.0.4",
158243          "description": "Retrieves a name:pathname Map for a given workspaces config",
158244          "licenses": [
158245            {
158246              "license": {
158247                "id": "ISC"
158248              }
158249            }
158250          ],
158251          "cpe": "cpe:2.3:a:\\@npmcli\\/map-workspaces:\\@npmcli\\/map-workspaces:2.0.4:*:*:*:*:*:*:*",
158252          "purl": "pkg:npm/%40npmcli/map-workspaces@2.0.4",
158253          "swid": {
158254            "attachment": {}
158255          },
158256          "pedigree": {},
158257          "externalReferences": [
158258            {
158259              "url": "https://github.com/npm/map-workspaces.git",
158260              "type": "distribution"
158261            }
158262          ],
158263          "evidence": {},
158264          "signature": {
158265            "signature": {
158266              "publicKey": {}
158267            }
158268          },
158269          "modelCard": {
158270            "modelParameters": {
158271              "approach": {}
158272            },
158273            "quantitativeAnalysis": {
158274              "graphics": {}
158275            },
158276            "considerations": {}
158277          }
158278        },
158279        {
158280          "type": "library",
158281          "bom-ref": "pkg:npm/%40npmcli/metavuln-calculator@3.1.1?package-id=5a94ed44a78625cd",
158282          "supplier": {},
158283          "author": "GitHub Inc.",
158284          "name": "@npmcli/metavuln-calculator",
158285          "version": "3.1.1",
158286          "description": "Calculate meta-vulnerabilities from package security advisories",
158287          "licenses": [
158288            {
158289              "license": {
158290                "id": "ISC"
158291              }
158292            }
158293          ],
158294          "cpe": "cpe:2.3:a:\\@npmcli\\/metavuln-calculator:\\@npmcli\\/metavuln-calculator:3.1.1:*:*:*:*:*:*:*",
158295          "purl": "pkg:npm/%40npmcli/metavuln-calculator@3.1.1",
158296          "swid": {
158297            "attachment": {}
158298          },
158299          "pedigree": {},
158300          "externalReferences": [
158301            {
158302              "url": "https://github.com/npm/metavuln-calculator.git",
158303              "type": "distribution"
158304            }
158305          ],
158306          "evidence": {},
158307          "signature": {
158308            "signature": {
158309              "publicKey": {}
158310            }
158311          },
158312          "modelCard": {
158313            "modelParameters": {
158314              "approach": {}
158315            },
158316            "quantitativeAnalysis": {
158317              "graphics": {}
158318            },
158319            "considerations": {}
158320          }
158321        },
158322        {
158323          "type": "library",
158324          "bom-ref": "pkg:npm/%40npmcli/move-file@2.0.1?package-id=76e6ffad7033dea3",
158325          "supplier": {},
158326          "author": "GitHub Inc.",
158327          "name": "@npmcli/move-file",
158328          "version": "2.0.1",
158329          "description": "move a file (fork of move-file)",
158330          "licenses": [
158331            {
158332              "license": {
158333                "id": "MIT"
158334              }
158335            }
158336          ],
158337          "cpe": "cpe:2.3:a:\\@npmcli\\/move-file:\\@npmcli\\/move-file:2.0.1:*:*:*:*:*:*:*",
158338          "purl": "pkg:npm/%40npmcli/move-file@2.0.1",
158339          "swid": {
158340            "attachment": {}
158341          },
158342          "pedigree": {},
158343          "externalReferences": [
158344            {
158345              "url": "https://github.com/npm/move-file.git",
158346              "type": "distribution"
158347            }
158348          ],
158349          "evidence": {},
158350          "signature": {
158351            "signature": {
158352              "publicKey": {}
158353            }
158354          },
158355          "modelCard": {
158356            "modelParameters": {
158357              "approach": {}
158358            },
158359            "quantitativeAnalysis": {
158360              "graphics": {}
158361            },
158362            "considerations": {}
158363          }
158364        },
158365        {
158366          "type": "library",
158367          "bom-ref": "pkg:npm/%40npmcli/name-from-folder@1.0.1?package-id=bda8c8030d6b515f",
158368          "supplier": {},
158369          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
158370          "name": "@npmcli/name-from-folder",
158371          "version": "1.0.1",
158372          "description": "Get the package name from a folder path",
158373          "licenses": [
158374            {
158375              "license": {
158376                "id": "ISC"
158377              }
158378            }
158379          ],
158380          "cpe": "cpe:2.3:a:\\@npmcli\\/name-from-folder:\\@npmcli\\/name-from-folder:1.0.1:*:*:*:*:*:*:*",
158381          "purl": "pkg:npm/%40npmcli/name-from-folder@1.0.1",
158382          "swid": {
158383            "attachment": {}
158384          },
158385          "pedigree": {},
158386          "externalReferences": [
158387            {
158388              "url": "git+https://github.com/npm/name-from-folder",
158389              "type": "distribution"
158390            }
158391          ],
158392          "evidence": {},
158393          "signature": {
158394            "signature": {
158395              "publicKey": {}
158396            }
158397          },
158398          "modelCard": {
158399            "modelParameters": {
158400              "approach": {}
158401            },
158402            "quantitativeAnalysis": {
158403              "graphics": {}
158404            },
158405            "considerations": {}
158406          }
158407        },
158408        {
158409          "type": "library",
158410          "bom-ref": "pkg:npm/%40npmcli/node-gyp@2.0.0?package-id=c9fb094d61d2ac04",
158411          "supplier": {},
158412          "author": "GitHub Inc.",
158413          "name": "@npmcli/node-gyp",
158414          "version": "2.0.0",
158415          "description": "Tools for dealing with node-gyp packages",
158416          "licenses": [
158417            {
158418              "license": {
158419                "id": "ISC"
158420              }
158421            }
158422          ],
158423          "cpe": "cpe:2.3:a:\\@npmcli\\/node-gyp:\\@npmcli\\/node-gyp:2.0.0:*:*:*:*:*:*:*",
158424          "purl": "pkg:npm/%40npmcli/node-gyp@2.0.0",
158425          "swid": {
158426            "attachment": {}
158427          },
158428          "pedigree": {},
158429          "externalReferences": [
158430            {
158431              "url": "https://github.com/npm/node-gyp.git",
158432              "type": "distribution"
158433            }
158434          ],
158435          "evidence": {},
158436          "signature": {
158437            "signature": {
158438              "publicKey": {}
158439            }
158440          },
158441          "modelCard": {
158442            "modelParameters": {
158443              "approach": {}
158444            },
158445            "quantitativeAnalysis": {
158446              "graphics": {}
158447            },
158448            "considerations": {}
158449          }
158450        },
158451        {
158452          "type": "library",
158453          "bom-ref": "pkg:npm/%40npmcli/package-json@2.0.0?package-id=63189c571859bb1a",
158454          "supplier": {},
158455          "author": "GitHub Inc.",
158456          "name": "@npmcli/package-json",
158457          "version": "2.0.0",
158458          "description": "Programmatic API to update package.json",
158459          "licenses": [
158460            {
158461              "license": {
158462                "id": "ISC"
158463              }
158464            }
158465          ],
158466          "cpe": "cpe:2.3:a:\\@npmcli\\/package-json:\\@npmcli\\/package-json:2.0.0:*:*:*:*:*:*:*",
158467          "purl": "pkg:npm/%40npmcli/package-json@2.0.0",
158468          "swid": {
158469            "attachment": {}
158470          },
158471          "pedigree": {},
158472          "externalReferences": [
158473            {
158474              "url": "https://github.com/npm/package-json.git",
158475              "type": "distribution"
158476            }
158477          ],
158478          "evidence": {},
158479          "signature": {
158480            "signature": {
158481              "publicKey": {}
158482            }
158483          },
158484          "modelCard": {
158485            "modelParameters": {
158486              "approach": {}
158487            },
158488            "quantitativeAnalysis": {
158489              "graphics": {}
158490            },
158491            "considerations": {}
158492          }
158493        },
158494        {
158495          "type": "library",
158496          "bom-ref": "pkg:npm/%40npmcli/promise-spawn@3.0.0?package-id=426c6e033be010cb",
158497          "supplier": {},
158498          "author": "GitHub Inc.",
158499          "name": "@npmcli/promise-spawn",
158500          "version": "3.0.0",
158501          "description": "spawn processes the way the npm cli likes to do",
158502          "licenses": [
158503            {
158504              "license": {
158505                "id": "ISC"
158506              }
158507            }
158508          ],
158509          "cpe": "cpe:2.3:a:\\@npmcli\\/promise-spawn:\\@npmcli\\/promise-spawn:3.0.0:*:*:*:*:*:*:*",
158510          "purl": "pkg:npm/%40npmcli/promise-spawn@3.0.0",
158511          "swid": {
158512            "attachment": {}
158513          },
158514          "pedigree": {},
158515          "externalReferences": [
158516            {
158517              "url": "https://github.com/npm/promise-spawn.git",
158518              "type": "distribution"
158519            }
158520          ],
158521          "evidence": {},
158522          "signature": {
158523            "signature": {
158524              "publicKey": {}
158525            }
158526          },
158527          "modelCard": {
158528            "modelParameters": {
158529              "approach": {}
158530            },
158531            "quantitativeAnalysis": {
158532              "graphics": {}
158533            },
158534            "considerations": {}
158535          }
158536        },
158537        {
158538          "type": "library",
158539          "bom-ref": "pkg:npm/%40npmcli/query@1.2.0?package-id=e71e78476048755c",
158540          "supplier": {},
158541          "author": "GitHub Inc.",
158542          "name": "@npmcli/query",
158543          "version": "1.2.0",
158544          "description": "npm query parser and tools",
158545          "licenses": [
158546            {
158547              "license": {
158548                "id": "ISC"
158549              }
158550            }
158551          ],
158552          "cpe": "cpe:2.3:a:\\@npmcli\\/query:\\@npmcli\\/query:1.2.0:*:*:*:*:*:*:*",
158553          "purl": "pkg:npm/%40npmcli/query@1.2.0",
158554          "swid": {
158555            "attachment": {}
158556          },
158557          "pedigree": {},
158558          "externalReferences": [
158559            {
158560              "url": "https://github.com/npm/query.git",
158561              "type": "distribution"
158562            }
158563          ],
158564          "evidence": {},
158565          "signature": {
158566            "signature": {
158567              "publicKey": {}
158568            }
158569          },
158570          "modelCard": {
158571            "modelParameters": {
158572              "approach": {}
158573            },
158574            "quantitativeAnalysis": {
158575              "graphics": {}
158576            },
158577            "considerations": {}
158578          }
158579        },
158580        {
158581          "type": "library",
158582          "bom-ref": "pkg:npm/%40npmcli/run-script@4.2.1?package-id=a13d191f5a0789d1",
158583          "supplier": {},
158584          "author": "GitHub Inc.",
158585          "name": "@npmcli/run-script",
158586          "version": "4.2.1",
158587          "description": "Run a lifecycle script for a package (descendant of npm-lifecycle)",
158588          "licenses": [
158589            {
158590              "license": {
158591                "id": "ISC"
158592              }
158593            }
158594          ],
158595          "cpe": "cpe:2.3:a:\\@npmcli\\/run-script:\\@npmcli\\/run-script:4.2.1:*:*:*:*:*:*:*",
158596          "purl": "pkg:npm/%40npmcli/run-script@4.2.1",
158597          "swid": {
158598            "attachment": {}
158599          },
158600          "pedigree": {},
158601          "externalReferences": [
158602            {
158603              "url": "https://github.com/npm/run-script.git",
158604              "type": "distribution"
158605            }
158606          ],
158607          "evidence": {},
158608          "signature": {
158609            "signature": {
158610              "publicKey": {}
158611            }
158612          },
158613          "modelCard": {
158614            "modelParameters": {
158615              "approach": {}
158616            },
158617            "quantitativeAnalysis": {
158618              "graphics": {}
158619            },
158620            "considerations": {}
158621          }
158622        },
158623        {
158624          "type": "library",
158625          "bom-ref": "pkg:npm/%40tootallnate/once@2.0.0?package-id=5edbc75b01ae9167",
158626          "supplier": {},
158627          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
158628          "name": "@tootallnate/once",
158629          "version": "2.0.0",
158630          "description": "Creates a Promise that waits for a single event",
158631          "licenses": [
158632            {
158633              "license": {
158634                "id": "MIT"
158635              }
158636            }
158637          ],
158638          "cpe": "cpe:2.3:a:\\@tootallnate\\/once:\\@tootallnate\\/once:2.0.0:*:*:*:*:*:*:*",
158639          "purl": "pkg:npm/%40tootallnate/once@2.0.0",
158640          "swid": {
158641            "attachment": {}
158642          },
158643          "pedigree": {},
158644          "externalReferences": [
158645            {
158646              "url": "git://github.com/TooTallNate/once.git",
158647              "type": "distribution"
158648            }
158649          ],
158650          "evidence": {},
158651          "signature": {
158652            "signature": {
158653              "publicKey": {}
158654            }
158655          },
158656          "modelCard": {
158657            "modelParameters": {
158658              "approach": {}
158659            },
158660            "quantitativeAnalysis": {
158661              "graphics": {}
158662            },
158663            "considerations": {}
158664          }
158665        },
158666        {
158667          "type": "library",
158668          "bom-ref": "pkg:npm/%40types/hammerjs@2.0.36?package-id=497759fd8d1e5621",
158669          "supplier": {},
158670          "name": "@types/hammerjs",
158671          "version": "2.0.36",
158672          "description": "TypeScript definitions for Hammer.js",
158673          "licenses": [
158674            {
158675              "license": {
158676                "id": "MIT"
158677              }
158678            }
158679          ],
158680          "cpe": "cpe:2.3:a:\\@types\\/hammerjs:\\@types\\/hammerjs:2.0.36:*:*:*:*:*:*:*",
158681          "purl": "pkg:npm/%40types/hammerjs@2.0.36",
158682          "swid": {
158683            "attachment": {}
158684          },
158685          "pedigree": {},
158686          "externalReferences": [
158687            {
158688              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
158689              "type": "distribution"
158690            }
158691          ],
158692          "evidence": {},
158693          "signature": {
158694            "signature": {
158695              "publicKey": {}
158696            }
158697          },
158698          "modelCard": {
158699            "modelParameters": {
158700              "approach": {}
158701            },
158702            "quantitativeAnalysis": {
158703              "graphics": {}
158704            },
158705            "considerations": {}
158706          }
158707        },
158708        {
158709          "type": "library",
158710          "bom-ref": "pkg:npm/%40types/minimist@1.2.2?package-id=98deb2ed490d5744",
158711          "supplier": {},
158712          "name": "@types/minimist",
158713          "version": "1.2.2",
158714          "description": "TypeScript definitions for minimist",
158715          "licenses": [
158716            {
158717              "license": {
158718                "id": "MIT"
158719              }
158720            }
158721          ],
158722          "cpe": "cpe:2.3:a:\\@types\\/minimist:\\@types\\/minimist:1.2.2:*:*:*:*:*:*:*",
158723          "purl": "pkg:npm/%40types/minimist@1.2.2",
158724          "swid": {
158725            "attachment": {}
158726          },
158727          "pedigree": {},
158728          "externalReferences": [
158729            {
158730              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
158731              "type": "distribution"
158732            },
158733            {
158734              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/minimist",
158735              "type": "website"
158736            }
158737          ],
158738          "evidence": {},
158739          "signature": {
158740            "signature": {
158741              "publicKey": {}
158742            }
158743          },
158744          "modelCard": {
158745            "modelParameters": {
158746              "approach": {}
158747            },
158748            "quantitativeAnalysis": {
158749              "graphics": {}
158750            },
158751            "considerations": {}
158752          }
158753        },
158754        {
158755          "type": "library",
158756          "bom-ref": "pkg:npm/%40types/normalize-package-data@2.4.1?package-id=9300a27ff31dc618",
158757          "supplier": {},
158758          "name": "@types/normalize-package-data",
158759          "version": "2.4.1",
158760          "description": "TypeScript definitions for normalize-package-data",
158761          "licenses": [
158762            {
158763              "license": {
158764                "id": "MIT"
158765              }
158766            }
158767          ],
158768          "cpe": "cpe:2.3:a:\\@types\\/normalize-package-data:\\@types\\/normalize-package-data:2.4.1:*:*:*:*:*:*:*",
158769          "purl": "pkg:npm/%40types/normalize-package-data@2.4.1",
158770          "swid": {
158771            "attachment": {}
158772          },
158773          "pedigree": {},
158774          "externalReferences": [
158775            {
158776              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
158777              "type": "distribution"
158778            },
158779            {
158780              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/normalize-package-data",
158781              "type": "website"
158782            }
158783          ],
158784          "evidence": {},
158785          "signature": {
158786            "signature": {
158787              "publicKey": {}
158788            }
158789          },
158790          "modelCard": {
158791            "modelParameters": {
158792              "approach": {}
158793            },
158794            "quantitativeAnalysis": {
158795              "graphics": {}
158796            },
158797            "considerations": {}
158798          }
158799        },
158800        {
158801          "type": "library",
158802          "bom-ref": "pkg:npm/abbrev@1.1.1?package-id=98be1cad3f4d1d11",
158803          "supplier": {},
158804          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
158805          "name": "abbrev",
158806          "version": "1.1.1",
158807          "description": "Like ruby's abbrev module, but in js",
158808          "licenses": [
158809            {
158810              "license": {
158811                "id": "ISC"
158812              }
158813            }
158814          ],
158815          "cpe": "cpe:2.3:a:abbrev:abbrev:1.1.1:*:*:*:*:*:*:*",
158816          "purl": "pkg:npm/abbrev@1.1.1",
158817          "swid": {
158818            "attachment": {}
158819          },
158820          "pedigree": {},
158821          "externalReferences": [
158822            {
158823              "url": "http://github.com/isaacs/abbrev-js",
158824              "type": "distribution"
158825            }
158826          ],
158827          "evidence": {},
158828          "signature": {
158829            "signature": {
158830              "publicKey": {}
158831            }
158832          },
158833          "modelCard": {
158834            "modelParameters": {
158835              "approach": {}
158836            },
158837            "quantitativeAnalysis": {
158838              "graphics": {}
158839            },
158840            "considerations": {}
158841          }
158842        },
158843        {
158844          "type": "library",
158845          "bom-ref": "pkg:npm/abbrev@1.1.1?package-id=7e084c60dbbfc7b6",
158846          "supplier": {},
158847          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
158848          "name": "abbrev",
158849          "version": "1.1.1",
158850          "description": "Like ruby's abbrev module, but in js",
158851          "licenses": [
158852            {
158853              "license": {
158854                "id": "ISC"
158855              }
158856            }
158857          ],
158858          "cpe": "cpe:2.3:a:abbrev:abbrev:1.1.1:*:*:*:*:*:*:*",
158859          "purl": "pkg:npm/abbrev@1.1.1",
158860          "swid": {
158861            "attachment": {}
158862          },
158863          "pedigree": {},
158864          "externalReferences": [
158865            {
158866              "url": "http://github.com/isaacs/abbrev-js",
158867              "type": "distribution"
158868            }
158869          ],
158870          "evidence": {},
158871          "signature": {
158872            "signature": {
158873              "publicKey": {}
158874            }
158875          },
158876          "modelCard": {
158877            "modelParameters": {
158878              "approach": {}
158879            },
158880            "quantitativeAnalysis": {
158881              "graphics": {}
158882            },
158883            "considerations": {}
158884          }
158885        },
158886        {
158887          "type": "library",
158888          "bom-ref": "pkg:npm/accepts@1.3.7?package-id=e240b614957beb3f",
158889          "supplier": {},
158890          "name": "accepts",
158891          "version": "1.3.7",
158892          "description": "Higher-level content negotiation",
158893          "licenses": [
158894            {
158895              "license": {
158896                "id": "MIT"
158897              }
158898            }
158899          ],
158900          "cpe": "cpe:2.3:a:accepts:accepts:1.3.7:*:*:*:*:*:*:*",
158901          "purl": "pkg:npm/accepts@1.3.7",
158902          "swid": {
158903            "attachment": {}
158904          },
158905          "pedigree": {},
158906          "externalReferences": [
158907            {
158908              "url": "jshttp/accepts",
158909              "type": "distribution"
158910            }
158911          ],
158912          "evidence": {},
158913          "signature": {
158914            "signature": {
158915              "publicKey": {}
158916            }
158917          },
158918          "modelCard": {
158919            "modelParameters": {
158920              "approach": {}
158921            },
158922            "quantitativeAnalysis": {
158923              "graphics": {}
158924            },
158925            "considerations": {}
158926          }
158927        },
158928        {
158929          "type": "library",
158930          "bom-ref": "pkg:npm/agent-base@6.0.2?package-id=4b0b5c9ee7d8fc08",
158931          "supplier": {},
158932          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
158933          "name": "agent-base",
158934          "version": "6.0.2",
158935          "description": "Turn a function into an `http.Agent` instance",
158936          "licenses": [
158937            {
158938              "license": {
158939                "id": "MIT"
158940              }
158941            }
158942          ],
158943          "cpe": "cpe:2.3:a:TooTallNate:agent-base:6.0.2:*:*:*:*:*:*:*",
158944          "purl": "pkg:npm/agent-base@6.0.2",
158945          "swid": {
158946            "attachment": {}
158947          },
158948          "pedigree": {},
158949          "externalReferences": [
158950            {
158951              "url": "git://github.com/TooTallNate/node-agent-base.git",
158952              "type": "distribution"
158953            }
158954          ],
158955          "evidence": {},
158956          "signature": {
158957            "signature": {
158958              "publicKey": {}
158959            }
158960          },
158961          "modelCard": {
158962            "modelParameters": {
158963              "approach": {}
158964            },
158965            "quantitativeAnalysis": {
158966              "graphics": {}
158967            },
158968            "considerations": {}
158969          }
158970        },
158971        {
158972          "type": "library",
158973          "bom-ref": "pkg:npm/agentkeepalive@4.2.1?package-id=37fa9bcd67324d6e",
158974          "supplier": {},
158975          "author": "fengmk2 \u003cfengmk2@gmail.com\u003e (https://fengmk2.com)",
158976          "name": "agentkeepalive",
158977          "version": "4.2.1",
158978          "description": "Missing keepalive http.Agent",
158979          "licenses": [
158980            {
158981              "license": {
158982                "id": "MIT"
158983              }
158984            }
158985          ],
158986          "cpe": "cpe:2.3:a:agentkeepalive:agentkeepalive:4.2.1:*:*:*:*:*:*:*",
158987          "purl": "pkg:npm/agentkeepalive@4.2.1",
158988          "swid": {
158989            "attachment": {}
158990          },
158991          "pedigree": {},
158992          "externalReferences": [
158993            {
158994              "url": "git://github.com/node-modules/agentkeepalive.git",
158995              "type": "distribution"
158996            }
158997          ],
158998          "evidence": {},
158999          "signature": {
159000            "signature": {
159001              "publicKey": {}
159002            }
159003          },
159004          "modelCard": {
159005            "modelParameters": {
159006              "approach": {}
159007            },
159008            "quantitativeAnalysis": {
159009              "graphics": {}
159010            },
159011            "considerations": {}
159012          }
159013        },
159014        {
159015          "type": "library",
159016          "bom-ref": "pkg:npm/aggregate-error@3.1.0?package-id=b1b74a520919b83f",
159017          "supplier": {},
159018          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159019          "name": "aggregate-error",
159020          "version": "3.1.0",
159021          "description": "Create an error from multiple errors",
159022          "licenses": [
159023            {
159024              "license": {
159025                "id": "MIT"
159026              }
159027            }
159028          ],
159029          "cpe": "cpe:2.3:a:aggregate-error:aggregate-error:3.1.0:*:*:*:*:*:*:*",
159030          "purl": "pkg:npm/aggregate-error@3.1.0",
159031          "swid": {
159032            "attachment": {}
159033          },
159034          "pedigree": {},
159035          "externalReferences": [
159036            {
159037              "url": "sindresorhus/aggregate-error",
159038              "type": "distribution"
159039            }
159040          ],
159041          "evidence": {},
159042          "signature": {
159043            "signature": {
159044              "publicKey": {}
159045            }
159046          },
159047          "modelCard": {
159048            "modelParameters": {
159049              "approach": {}
159050            },
159051            "quantitativeAnalysis": {
159052              "graphics": {}
159053            },
159054            "considerations": {}
159055          }
159056        },
159057        {
159058          "type": "library",
159059          "bom-ref": "pkg:npm/ajv@6.12.6?package-id=499abcf86654fa15",
159060          "supplier": {},
159061          "author": "Evgeny Poberezkin",
159062          "name": "ajv",
159063          "version": "6.12.6",
159064          "description": "Another JSON Schema Validator",
159065          "licenses": [
159066            {
159067              "license": {
159068                "id": "MIT"
159069              }
159070            }
159071          ],
159072          "cpe": "cpe:2.3:a:ajv-validator:ajv:6.12.6:*:*:*:*:*:*:*",
159073          "purl": "pkg:npm/ajv@6.12.6",
159074          "swid": {
159075            "attachment": {}
159076          },
159077          "pedigree": {},
159078          "externalReferences": [
159079            {
159080              "url": "https://github.com/ajv-validator/ajv.git",
159081              "type": "distribution"
159082            },
159083            {
159084              "url": "https://github.com/ajv-validator/ajv",
159085              "type": "website"
159086            }
159087          ],
159088          "evidence": {},
159089          "signature": {
159090            "signature": {
159091              "publicKey": {}
159092            }
159093          },
159094          "modelCard": {
159095            "modelParameters": {
159096              "approach": {}
159097            },
159098            "quantitativeAnalysis": {
159099              "graphics": {}
159100            },
159101            "considerations": {}
159102          }
159103        },
159104        {
159105          "type": "library",
159106          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=61eac5ce8105d394",
159107          "supplier": {},
159108          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
159109          "name": "alpine-baselayout",
159110          "version": "3.2.0-r23",
159111          "description": "Alpine base dir structure and init scripts",
159112          "licenses": [
159113            {
159114              "license": {
159115                "id": "GPL-2.0-only"
159116              }
159117            }
159118          ],
159119          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r23:*:*:*:*:*:*:*",
159120          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5",
159121          "swid": {
159122            "attachment": {}
159123          },
159124          "pedigree": {},
159125          "externalReferences": [
159126            {
159127              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
159128              "type": "distribution"
159129            }
159130          ],
159131          "evidence": {},
159132          "signature": {
159133            "signature": {
159134              "publicKey": {}
159135            }
159136          },
159137          "modelCard": {
159138            "modelParameters": {
159139              "approach": {}
159140            },
159141            "quantitativeAnalysis": {
159142              "graphics": {}
159143            },
159144            "considerations": {}
159145          }
159146        },
159147        {
159148          "type": "library",
159149          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5\u0026package-id=e8c6fcc3a282ed4f",
159150          "supplier": {},
159151          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
159152          "name": "alpine-baselayout-data",
159153          "version": "3.2.0-r23",
159154          "description": "Alpine base dir structure and init scripts",
159155          "licenses": [
159156            {
159157              "license": {
159158                "id": "GPL-2.0-only"
159159              }
159160            }
159161          ],
159162          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.2.0-r23:*:*:*:*:*:*:*",
159163          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5",
159164          "swid": {
159165            "attachment": {}
159166          },
159167          "pedigree": {},
159168          "externalReferences": [
159169            {
159170              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
159171              "type": "distribution"
159172            }
159173          ],
159174          "evidence": {},
159175          "signature": {
159176            "signature": {
159177              "publicKey": {}
159178            }
159179          },
159180          "modelCard": {
159181            "modelParameters": {
159182              "approach": {}
159183            },
159184            "quantitativeAnalysis": {
159185              "graphics": {}
159186            },
159187            "considerations": {}
159188          }
159189        },
159190        {
159191          "type": "library",
159192          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=82d183eb300978cc",
159193          "supplier": {},
159194          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
159195          "name": "alpine-keys",
159196          "version": "2.4-r1",
159197          "description": "Public keys for Alpine Linux packages",
159198          "licenses": [
159199            {
159200              "license": {
159201                "id": "MIT"
159202              }
159203            }
159204          ],
159205          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
159206          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5",
159207          "swid": {
159208            "attachment": {}
159209          },
159210          "pedigree": {},
159211          "externalReferences": [
159212            {
159213              "url": "https://alpinelinux.org",
159214              "type": "distribution"
159215            }
159216          ],
159217          "evidence": {},
159218          "signature": {
159219            "signature": {
159220              "publicKey": {}
159221            }
159222          },
159223          "modelCard": {
159224            "modelParameters": {
159225              "approach": {}
159226            },
159227            "quantitativeAnalysis": {
159228              "graphics": {}
159229            },
159230            "considerations": {}
159231          }
159232        },
159233        {
159234          "type": "library",
159235          "bom-ref": "pkg:npm/amdefine@1.0.1?package-id=424003c885d9f1d5",
159236          "supplier": {},
159237          "author": "James Burke \u003cjrburke@gmail.com\u003e (http://github.com/jrburke)",
159238          "name": "amdefine",
159239          "version": "1.0.1",
159240          "description": "Provide AMD's define() API for declaring modules in the AMD format",
159241          "licenses": [
159242            {
159243              "license": {
159244                "name": "BSD-3-Clause OR MIT"
159245              }
159246            }
159247          ],
159248          "cpe": "cpe:2.3:a:amdefine:amdefine:1.0.1:*:*:*:*:*:*:*",
159249          "purl": "pkg:npm/amdefine@1.0.1",
159250          "swid": {
159251            "attachment": {}
159252          },
159253          "pedigree": {},
159254          "externalReferences": [
159255            {
159256              "url": "https://github.com/jrburke/amdefine.git",
159257              "type": "distribution"
159258            },
159259            {
159260              "url": "http://github.com/jrburke/amdefine",
159261              "type": "website"
159262            }
159263          ],
159264          "evidence": {},
159265          "signature": {
159266            "signature": {
159267              "publicKey": {}
159268            }
159269          },
159270          "modelCard": {
159271            "modelParameters": {
159272              "approach": {}
159273            },
159274            "quantitativeAnalysis": {
159275              "graphics": {}
159276            },
159277            "considerations": {}
159278          }
159279        },
159280        {
159281          "type": "library",
159282          "bom-ref": "pkg:npm/ansi-regex@2.1.1?package-id=f171d96c5c85c648",
159283          "supplier": {},
159284          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159285          "name": "ansi-regex",
159286          "version": "2.1.1",
159287          "description": "Regular expression for matching ANSI escape codes",
159288          "licenses": [
159289            {
159290              "license": {
159291                "id": "MIT"
159292              }
159293            }
159294          ],
159295          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:2.1.1:*:*:*:*:*:*:*",
159296          "purl": "pkg:npm/ansi-regex@2.1.1",
159297          "swid": {
159298            "attachment": {}
159299          },
159300          "pedigree": {},
159301          "externalReferences": [
159302            {
159303              "url": "chalk/ansi-regex",
159304              "type": "distribution"
159305            }
159306          ],
159307          "evidence": {},
159308          "signature": {
159309            "signature": {
159310              "publicKey": {}
159311            }
159312          },
159313          "modelCard": {
159314            "modelParameters": {
159315              "approach": {}
159316            },
159317            "quantitativeAnalysis": {
159318              "graphics": {}
159319            },
159320            "considerations": {}
159321          }
159322        },
159323        {
159324          "type": "library",
159325          "bom-ref": "pkg:npm/ansi-regex@4.1.1?package-id=2b2c69332642e60d",
159326          "supplier": {},
159327          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159328          "name": "ansi-regex",
159329          "version": "4.1.1",
159330          "description": "Regular expression for matching ANSI escape codes",
159331          "licenses": [
159332            {
159333              "license": {
159334                "id": "MIT"
159335              }
159336            }
159337          ],
159338          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.1:*:*:*:*:*:*:*",
159339          "purl": "pkg:npm/ansi-regex@4.1.1",
159340          "swid": {
159341            "attachment": {}
159342          },
159343          "pedigree": {},
159344          "externalReferences": [
159345            {
159346              "url": "chalk/ansi-regex",
159347              "type": "distribution"
159348            }
159349          ],
159350          "evidence": {},
159351          "signature": {
159352            "signature": {
159353              "publicKey": {}
159354            }
159355          },
159356          "modelCard": {
159357            "modelParameters": {
159358              "approach": {}
159359            },
159360            "quantitativeAnalysis": {
159361              "graphics": {}
159362            },
159363            "considerations": {}
159364          }
159365        },
159366        {
159367          "type": "library",
159368          "bom-ref": "pkg:npm/ansi-regex@4.1.1?package-id=57570b242bca44bc",
159369          "supplier": {},
159370          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159371          "name": "ansi-regex",
159372          "version": "4.1.1",
159373          "description": "Regular expression for matching ANSI escape codes",
159374          "licenses": [
159375            {
159376              "license": {
159377                "id": "MIT"
159378              }
159379            }
159380          ],
159381          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.1:*:*:*:*:*:*:*",
159382          "purl": "pkg:npm/ansi-regex@4.1.1",
159383          "swid": {
159384            "attachment": {}
159385          },
159386          "pedigree": {},
159387          "externalReferences": [
159388            {
159389              "url": "chalk/ansi-regex",
159390              "type": "distribution"
159391            }
159392          ],
159393          "evidence": {},
159394          "signature": {
159395            "signature": {
159396              "publicKey": {}
159397            }
159398          },
159399          "modelCard": {
159400            "modelParameters": {
159401              "approach": {}
159402            },
159403            "quantitativeAnalysis": {
159404              "graphics": {}
159405            },
159406            "considerations": {}
159407          }
159408        },
159409        {
159410          "type": "library",
159411          "bom-ref": "pkg:npm/ansi-regex@4.1.1?package-id=89ccb90286cd81cf",
159412          "supplier": {},
159413          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159414          "name": "ansi-regex",
159415          "version": "4.1.1",
159416          "description": "Regular expression for matching ANSI escape codes",
159417          "licenses": [
159418            {
159419              "license": {
159420                "id": "MIT"
159421              }
159422            }
159423          ],
159424          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.1:*:*:*:*:*:*:*",
159425          "purl": "pkg:npm/ansi-regex@4.1.1",
159426          "swid": {
159427            "attachment": {}
159428          },
159429          "pedigree": {},
159430          "externalReferences": [
159431            {
159432              "url": "chalk/ansi-regex",
159433              "type": "distribution"
159434            }
159435          ],
159436          "evidence": {},
159437          "signature": {
159438            "signature": {
159439              "publicKey": {}
159440            }
159441          },
159442          "modelCard": {
159443            "modelParameters": {
159444              "approach": {}
159445            },
159446            "quantitativeAnalysis": {
159447              "graphics": {}
159448            },
159449            "considerations": {}
159450          }
159451        },
159452        {
159453          "type": "library",
159454          "bom-ref": "pkg:npm/ansi-regex@5.0.1?package-id=fe78ee8372cda3ef",
159455          "supplier": {},
159456          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159457          "name": "ansi-regex",
159458          "version": "5.0.1",
159459          "description": "Regular expression for matching ANSI escape codes",
159460          "licenses": [
159461            {
159462              "license": {
159463                "id": "MIT"
159464              }
159465            }
159466          ],
159467          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:5.0.1:*:*:*:*:*:*:*",
159468          "purl": "pkg:npm/ansi-regex@5.0.1",
159469          "swid": {
159470            "attachment": {}
159471          },
159472          "pedigree": {},
159473          "externalReferences": [
159474            {
159475              "url": "chalk/ansi-regex",
159476              "type": "distribution"
159477            }
159478          ],
159479          "evidence": {},
159480          "signature": {
159481            "signature": {
159482              "publicKey": {}
159483            }
159484          },
159485          "modelCard": {
159486            "modelParameters": {
159487              "approach": {}
159488            },
159489            "quantitativeAnalysis": {
159490              "graphics": {}
159491            },
159492            "considerations": {}
159493          }
159494        },
159495        {
159496          "type": "library",
159497          "bom-ref": "pkg:npm/ansi-styles@2.2.1?package-id=d4b2e8c78b45f2de",
159498          "supplier": {},
159499          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159500          "name": "ansi-styles",
159501          "version": "2.2.1",
159502          "description": "ANSI escape codes for styling strings in the terminal",
159503          "licenses": [
159504            {
159505              "license": {
159506                "id": "MIT"
159507              }
159508            }
159509          ],
159510          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:2.2.1:*:*:*:*:*:*:*",
159511          "purl": "pkg:npm/ansi-styles@2.2.1",
159512          "swid": {
159513            "attachment": {}
159514          },
159515          "pedigree": {},
159516          "externalReferences": [
159517            {
159518              "url": "chalk/ansi-styles",
159519              "type": "distribution"
159520            }
159521          ],
159522          "evidence": {},
159523          "signature": {
159524            "signature": {
159525              "publicKey": {}
159526            }
159527          },
159528          "modelCard": {
159529            "modelParameters": {
159530              "approach": {}
159531            },
159532            "quantitativeAnalysis": {
159533              "graphics": {}
159534            },
159535            "considerations": {}
159536          }
159537        },
159538        {
159539          "type": "library",
159540          "bom-ref": "pkg:npm/ansi-styles@3.2.1?package-id=44d19522b5daaa82",
159541          "supplier": {},
159542          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159543          "name": "ansi-styles",
159544          "version": "3.2.1",
159545          "description": "ANSI escape codes for styling strings in the terminal",
159546          "licenses": [
159547            {
159548              "license": {
159549                "id": "MIT"
159550              }
159551            }
159552          ],
159553          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:3.2.1:*:*:*:*:*:*:*",
159554          "purl": "pkg:npm/ansi-styles@3.2.1",
159555          "swid": {
159556            "attachment": {}
159557          },
159558          "pedigree": {},
159559          "externalReferences": [
159560            {
159561              "url": "chalk/ansi-styles",
159562              "type": "distribution"
159563            }
159564          ],
159565          "evidence": {},
159566          "signature": {
159567            "signature": {
159568              "publicKey": {}
159569            }
159570          },
159571          "modelCard": {
159572            "modelParameters": {
159573              "approach": {}
159574            },
159575            "quantitativeAnalysis": {
159576              "graphics": {}
159577            },
159578            "considerations": {}
159579          }
159580        },
159581        {
159582          "type": "library",
159583          "bom-ref": "pkg:npm/ansi-styles@3.2.1?package-id=2df8c46d58763f23",
159584          "supplier": {},
159585          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159586          "name": "ansi-styles",
159587          "version": "3.2.1",
159588          "description": "ANSI escape codes for styling strings in the terminal",
159589          "licenses": [
159590            {
159591              "license": {
159592                "id": "MIT"
159593              }
159594            }
159595          ],
159596          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:3.2.1:*:*:*:*:*:*:*",
159597          "purl": "pkg:npm/ansi-styles@3.2.1",
159598          "swid": {
159599            "attachment": {}
159600          },
159601          "pedigree": {},
159602          "externalReferences": [
159603            {
159604              "url": "chalk/ansi-styles",
159605              "type": "distribution"
159606            }
159607          ],
159608          "evidence": {},
159609          "signature": {
159610            "signature": {
159611              "publicKey": {}
159612            }
159613          },
159614          "modelCard": {
159615            "modelParameters": {
159616              "approach": {}
159617            },
159618            "quantitativeAnalysis": {
159619              "graphics": {}
159620            },
159621            "considerations": {}
159622          }
159623        },
159624        {
159625          "type": "library",
159626          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=e3f310fd74532509",
159627          "supplier": {},
159628          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159629          "name": "ansi-styles",
159630          "version": "4.3.0",
159631          "description": "ANSI escape codes for styling strings in the terminal",
159632          "licenses": [
159633            {
159634              "license": {
159635                "id": "MIT"
159636              }
159637            }
159638          ],
159639          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
159640          "purl": "pkg:npm/ansi-styles@4.3.0",
159641          "swid": {
159642            "attachment": {}
159643          },
159644          "pedigree": {},
159645          "externalReferences": [
159646            {
159647              "url": "chalk/ansi-styles",
159648              "type": "distribution"
159649            }
159650          ],
159651          "evidence": {},
159652          "signature": {
159653            "signature": {
159654              "publicKey": {}
159655            }
159656          },
159657          "modelCard": {
159658            "modelParameters": {
159659              "approach": {}
159660            },
159661            "quantitativeAnalysis": {
159662              "graphics": {}
159663            },
159664            "considerations": {}
159665          }
159666        },
159667        {
159668          "type": "library",
159669          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=42d502b764a37310",
159670          "supplier": {},
159671          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
159672          "name": "apk-tools",
159673          "version": "2.12.9-r3",
159674          "description": "Alpine Package Keeper - package manager for alpine",
159675          "licenses": [
159676            {
159677              "license": {
159678                "id": "GPL-2.0-only"
159679              }
159680            }
159681          ],
159682          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.9-r3:*:*:*:*:*:*:*",
159683          "purl": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5",
159684          "swid": {
159685            "attachment": {}
159686          },
159687          "pedigree": {},
159688          "externalReferences": [
159689            {
159690              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
159691              "type": "distribution"
159692            }
159693          ],
159694          "evidence": {},
159695          "signature": {
159696            "signature": {
159697              "publicKey": {}
159698            }
159699          },
159700          "modelCard": {
159701            "modelParameters": {
159702              "approach": {}
159703            },
159704            "quantitativeAnalysis": {
159705              "graphics": {}
159706            },
159707            "considerations": {}
159708          }
159709        },
159710        {
159711          "type": "library",
159712          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=f8753d6fa099a7d0",
159713          "supplier": {},
159714          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
159715          "name": "aproba",
159716          "version": "1.2.0",
159717          "description": "A ridiculously light-weight argument validator (now browser friendly)",
159718          "licenses": [
159719            {
159720              "license": {
159721                "id": "ISC"
159722              }
159723            }
159724          ],
159725          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
159726          "purl": "pkg:npm/aproba@1.2.0",
159727          "swid": {
159728            "attachment": {}
159729          },
159730          "pedigree": {},
159731          "externalReferences": [
159732            {
159733              "url": "https://github.com/iarna/aproba",
159734              "type": "distribution"
159735            },
159736            {
159737              "url": "https://github.com/iarna/aproba",
159738              "type": "website"
159739            }
159740          ],
159741          "evidence": {},
159742          "signature": {
159743            "signature": {
159744              "publicKey": {}
159745            }
159746          },
159747          "modelCard": {
159748            "modelParameters": {
159749              "approach": {}
159750            },
159751            "quantitativeAnalysis": {
159752              "graphics": {}
159753            },
159754            "considerations": {}
159755          }
159756        },
159757        {
159758          "type": "library",
159759          "bom-ref": "pkg:npm/aproba@2.0.0?package-id=d11111a04d810227",
159760          "supplier": {},
159761          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
159762          "name": "aproba",
159763          "version": "2.0.0",
159764          "description": "A ridiculously light-weight argument validator (now browser friendly)",
159765          "licenses": [
159766            {
159767              "license": {
159768                "id": "ISC"
159769              }
159770            }
159771          ],
159772          "cpe": "cpe:2.3:a:aproba:aproba:2.0.0:*:*:*:*:*:*:*",
159773          "purl": "pkg:npm/aproba@2.0.0",
159774          "swid": {
159775            "attachment": {}
159776          },
159777          "pedigree": {},
159778          "externalReferences": [
159779            {
159780              "url": "https://github.com/iarna/aproba",
159781              "type": "distribution"
159782            },
159783            {
159784              "url": "https://github.com/iarna/aproba",
159785              "type": "website"
159786            }
159787          ],
159788          "evidence": {},
159789          "signature": {
159790            "signature": {
159791              "publicKey": {}
159792            }
159793          },
159794          "modelCard": {
159795            "modelParameters": {
159796              "approach": {}
159797            },
159798            "quantitativeAnalysis": {
159799              "graphics": {}
159800            },
159801            "considerations": {}
159802          }
159803        },
159804        {
159805          "type": "library",
159806          "bom-ref": "pkg:npm/archy@1.0.0?package-id=a1e7fd77fec54095",
159807          "supplier": {},
159808          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
159809          "name": "archy",
159810          "version": "1.0.0",
159811          "description": "render nested hierarchies `npm ls` style with unicode pipes",
159812          "licenses": [
159813            {
159814              "license": {
159815                "id": "MIT"
159816              }
159817            }
159818          ],
159819          "cpe": "cpe:2.3:a:substack:archy:1.0.0:*:*:*:*:*:*:*",
159820          "purl": "pkg:npm/archy@1.0.0",
159821          "swid": {
159822            "attachment": {}
159823          },
159824          "pedigree": {},
159825          "externalReferences": [
159826            {
159827              "url": "http://github.com/substack/node-archy.git",
159828              "type": "distribution"
159829            }
159830          ],
159831          "evidence": {},
159832          "signature": {
159833            "signature": {
159834              "publicKey": {}
159835            }
159836          },
159837          "modelCard": {
159838            "modelParameters": {
159839              "approach": {}
159840            },
159841            "quantitativeAnalysis": {
159842              "graphics": {}
159843            },
159844            "considerations": {}
159845          }
159846        },
159847        {
159848          "type": "library",
159849          "bom-ref": "pkg:npm/are-we-there-yet@1.1.7?package-id=bf4c3e64194953d8",
159850          "supplier": {},
159851          "author": "Rebecca Turner (http://re-becca.org)",
159852          "name": "are-we-there-yet",
159853          "version": "1.1.7",
159854          "description": "Keep track of the overall completion of many disparate processes",
159855          "licenses": [
159856            {
159857              "license": {
159858                "id": "ISC"
159859              }
159860            }
159861          ],
159862          "cpe": "cpe:2.3:a:are-we-there-yet:are-we-there-yet:1.1.7:*:*:*:*:*:*:*",
159863          "purl": "pkg:npm/are-we-there-yet@1.1.7",
159864          "swid": {
159865            "attachment": {}
159866          },
159867          "pedigree": {},
159868          "externalReferences": [
159869            {
159870              "url": "https://github.com/iarna/are-we-there-yet.git",
159871              "type": "distribution"
159872            },
159873            {
159874              "url": "https://github.com/iarna/are-we-there-yet",
159875              "type": "website"
159876            }
159877          ],
159878          "evidence": {},
159879          "signature": {
159880            "signature": {
159881              "publicKey": {}
159882            }
159883          },
159884          "modelCard": {
159885            "modelParameters": {
159886              "approach": {}
159887            },
159888            "quantitativeAnalysis": {
159889              "graphics": {}
159890            },
159891            "considerations": {}
159892          }
159893        },
159894        {
159895          "type": "library",
159896          "bom-ref": "pkg:npm/are-we-there-yet@3.0.1?package-id=d7ea73c2e385c95d",
159897          "supplier": {},
159898          "author": "GitHub Inc.",
159899          "name": "are-we-there-yet",
159900          "version": "3.0.1",
159901          "description": "Keep track of the overall completion of many disparate processes",
159902          "licenses": [
159903            {
159904              "license": {
159905                "id": "ISC"
159906              }
159907            }
159908          ],
159909          "cpe": "cpe:2.3:a:are-we-there-yet:are-we-there-yet:3.0.1:*:*:*:*:*:*:*",
159910          "purl": "pkg:npm/are-we-there-yet@3.0.1",
159911          "swid": {
159912            "attachment": {}
159913          },
159914          "pedigree": {},
159915          "externalReferences": [
159916            {
159917              "url": "https://github.com/npm/are-we-there-yet.git",
159918              "type": "distribution"
159919            },
159920            {
159921              "url": "https://github.com/npm/are-we-there-yet",
159922              "type": "website"
159923            }
159924          ],
159925          "evidence": {},
159926          "signature": {
159927            "signature": {
159928              "publicKey": {}
159929            }
159930          },
159931          "modelCard": {
159932            "modelParameters": {
159933              "approach": {}
159934            },
159935            "quantitativeAnalysis": {
159936              "graphics": {}
159937            },
159938            "considerations": {}
159939          }
159940        },
159941        {
159942          "type": "library",
159943          "bom-ref": "pkg:npm/array-flatten@1.1.1?package-id=169fa984c33ff9f6",
159944          "supplier": {},
159945          "author": "Blake Embrey \u003chello@blakeembrey.com\u003e (http://blakeembrey.me)",
159946          "name": "array-flatten",
159947          "version": "1.1.1",
159948          "description": "Flatten an array of nested arrays into a single flat array",
159949          "licenses": [
159950            {
159951              "license": {
159952                "id": "MIT"
159953              }
159954            }
159955          ],
159956          "cpe": "cpe:2.3:a:array-flatten:array-flatten:1.1.1:*:*:*:*:*:*:*",
159957          "purl": "pkg:npm/array-flatten@1.1.1",
159958          "swid": {
159959            "attachment": {}
159960          },
159961          "pedigree": {},
159962          "externalReferences": [
159963            {
159964              "url": "git://github.com/blakeembrey/array-flatten.git",
159965              "type": "distribution"
159966            },
159967            {
159968              "url": "https://github.com/blakeembrey/array-flatten",
159969              "type": "website"
159970            }
159971          ],
159972          "evidence": {},
159973          "signature": {
159974            "signature": {
159975              "publicKey": {}
159976            }
159977          },
159978          "modelCard": {
159979            "modelParameters": {
159980              "approach": {}
159981            },
159982            "quantitativeAnalysis": {
159983              "graphics": {}
159984            },
159985            "considerations": {}
159986          }
159987        },
159988        {
159989          "type": "library",
159990          "bom-ref": "pkg:npm/arrify@1.0.1?package-id=a9e847f06d506623",
159991          "supplier": {},
159992          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
159993          "name": "arrify",
159994          "version": "1.0.1",
159995          "description": "Convert a value to an array",
159996          "licenses": [
159997            {
159998              "license": {
159999                "id": "MIT"
160000              }
160001            }
160002          ],
160003          "cpe": "cpe:2.3:a:arrify:arrify:1.0.1:*:*:*:*:*:*:*",
160004          "purl": "pkg:npm/arrify@1.0.1",
160005          "swid": {
160006            "attachment": {}
160007          },
160008          "pedigree": {},
160009          "externalReferences": [
160010            {
160011              "url": "sindresorhus/arrify",
160012              "type": "distribution"
160013            }
160014          ],
160015          "evidence": {},
160016          "signature": {
160017            "signature": {
160018              "publicKey": {}
160019            }
160020          },
160021          "modelCard": {
160022            "modelParameters": {
160023              "approach": {}
160024            },
160025            "quantitativeAnalysis": {
160026              "graphics": {}
160027            },
160028            "considerations": {}
160029          }
160030        },
160031        {
160032          "type": "library",
160033          "bom-ref": "pkg:npm/asap@2.0.6?package-id=4069b89e24646503",
160034          "supplier": {},
160035          "name": "asap",
160036          "version": "2.0.6",
160037          "description": "High-priority task queue for Node.js and browsers",
160038          "licenses": [
160039            {
160040              "license": {
160041                "id": "MIT"
160042              }
160043            }
160044          ],
160045          "cpe": "cpe:2.3:a:kriskowal:asap:2.0.6:*:*:*:*:*:*:*",
160046          "purl": "pkg:npm/asap@2.0.6",
160047          "swid": {
160048            "attachment": {}
160049          },
160050          "pedigree": {},
160051          "externalReferences": [
160052            {
160053              "url": "https://github.com/kriskowal/asap.git",
160054              "type": "distribution"
160055            }
160056          ],
160057          "evidence": {},
160058          "signature": {
160059            "signature": {
160060              "publicKey": {}
160061            }
160062          },
160063          "modelCard": {
160064            "modelParameters": {
160065              "approach": {}
160066            },
160067            "quantitativeAnalysis": {
160068              "graphics": {}
160069            },
160070            "considerations": {}
160071          }
160072        },
160073        {
160074          "type": "library",
160075          "bom-ref": "pkg:npm/asn1@0.2.6?package-id=fa945e5e8e9c4123",
160076          "supplier": {},
160077          "author": "Joyent (joyent.com)",
160078          "name": "asn1",
160079          "version": "0.2.6",
160080          "description": "Contains parsers and serializers for ASN.1 (currently BER only)",
160081          "licenses": [
160082            {
160083              "license": {
160084                "id": "MIT"
160085              }
160086            }
160087          ],
160088          "cpe": "cpe:2.3:a:joyent:asn1:0.2.6:*:*:*:*:*:*:*",
160089          "purl": "pkg:npm/asn1@0.2.6",
160090          "swid": {
160091            "attachment": {}
160092          },
160093          "pedigree": {},
160094          "externalReferences": [
160095            {
160096              "url": "https://github.com/joyent/node-asn1.git",
160097              "type": "distribution"
160098            }
160099          ],
160100          "evidence": {},
160101          "signature": {
160102            "signature": {
160103              "publicKey": {}
160104            }
160105          },
160106          "modelCard": {
160107            "modelParameters": {
160108              "approach": {}
160109            },
160110            "quantitativeAnalysis": {
160111              "graphics": {}
160112            },
160113            "considerations": {}
160114          }
160115        },
160116        {
160117          "type": "library",
160118          "bom-ref": "pkg:npm/assert-plus@1.0.0?package-id=fefb0d3370d896dc",
160119          "supplier": {},
160120          "author": "Mark Cavage \u003cmcavage@gmail.com\u003e",
160121          "name": "assert-plus",
160122          "version": "1.0.0",
160123          "description": "Extra assertions on top of node's assert module",
160124          "licenses": [
160125            {
160126              "license": {
160127                "id": "MIT"
160128              }
160129            }
160130          ],
160131          "cpe": "cpe:2.3:a:assert-plus:assert-plus:1.0.0:*:*:*:*:*:*:*",
160132          "purl": "pkg:npm/assert-plus@1.0.0",
160133          "swid": {
160134            "attachment": {}
160135          },
160136          "pedigree": {},
160137          "externalReferences": [
160138            {
160139              "url": "https://github.com/mcavage/node-assert-plus.git",
160140              "type": "distribution"
160141            }
160142          ],
160143          "evidence": {},
160144          "signature": {
160145            "signature": {
160146              "publicKey": {}
160147            }
160148          },
160149          "modelCard": {
160150            "modelParameters": {
160151              "approach": {}
160152            },
160153            "quantitativeAnalysis": {
160154              "graphics": {}
160155            },
160156            "considerations": {}
160157          }
160158        },
160159        {
160160          "type": "library",
160161          "bom-ref": "pkg:npm/async-foreach@0.1.3?package-id=36caf08e8333209",
160162          "supplier": {},
160163          "author": "\"Cowboy\" Ben Alman (http://benalman.com/)",
160164          "name": "async-foreach",
160165          "version": "0.1.3",
160166          "description": "An optionally-asynchronous forEach with an interesting interface.",
160167          "cpe": "cpe:2.3:a:async-foreach:async-foreach:0.1.3:*:*:*:*:*:*:*",
160168          "purl": "pkg:npm/async-foreach@0.1.3",
160169          "swid": {
160170            "attachment": {}
160171          },
160172          "pedigree": {},
160173          "externalReferences": [
160174            {
160175              "url": "git://github.com/cowboy/javascript-sync-async-foreach.git",
160176              "type": "distribution"
160177            },
160178            {
160179              "url": "http://github.com/cowboy/javascript-sync-async-foreach",
160180              "type": "website"
160181            }
160182          ],
160183          "evidence": {},
160184          "signature": {
160185            "signature": {
160186              "publicKey": {}
160187            }
160188          },
160189          "modelCard": {
160190            "modelParameters": {
160191              "approach": {}
160192            },
160193            "quantitativeAnalysis": {
160194              "graphics": {}
160195            },
160196            "considerations": {}
160197          }
160198        },
160199        {
160200          "type": "library",
160201          "bom-ref": "pkg:npm/asynckit@0.4.0?package-id=ae8f87968d557dba",
160202          "supplier": {},
160203          "author": "Alex Indigo \u003ciam@alexindigo.com\u003e",
160204          "name": "asynckit",
160205          "version": "0.4.0",
160206          "description": "Minimal async jobs utility library, with streams support",
160207          "licenses": [
160208            {
160209              "license": {
160210                "id": "MIT"
160211              }
160212            }
160213          ],
160214          "cpe": "cpe:2.3:a:alexindigo:asynckit:0.4.0:*:*:*:*:*:*:*",
160215          "purl": "pkg:npm/asynckit@0.4.0",
160216          "swid": {
160217            "attachment": {}
160218          },
160219          "pedigree": {},
160220          "externalReferences": [
160221            {
160222              "url": "git+https://github.com/alexindigo/asynckit.git",
160223              "type": "distribution"
160224            },
160225            {
160226              "url": "https://github.com/alexindigo/asynckit#readme",
160227              "type": "website"
160228            }
160229          ],
160230          "evidence": {},
160231          "signature": {
160232            "signature": {
160233              "publicKey": {}
160234            }
160235          },
160236          "modelCard": {
160237            "modelParameters": {
160238              "approach": {}
160239            },
160240            "quantitativeAnalysis": {
160241              "graphics": {}
160242            },
160243            "considerations": {}
160244          }
160245        },
160246        {
160247          "type": "library",
160248          "bom-ref": "pkg:npm/aws-sign2@0.7.0?package-id=2ea4d2f6e82a7f7d",
160249          "supplier": {},
160250          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
160251          "name": "aws-sign2",
160252          "version": "0.7.0",
160253          "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
160254          "licenses": [
160255            {
160256              "license": {
160257                "id": "Apache-2.0"
160258              }
160259            }
160260          ],
160261          "cpe": "cpe:2.3:a:aws-sign2:aws-sign2:0.7.0:*:*:*:*:*:*:*",
160262          "purl": "pkg:npm/aws-sign2@0.7.0",
160263          "swid": {
160264            "attachment": {}
160265          },
160266          "pedigree": {},
160267          "externalReferences": [
160268            {
160269              "url": "https://github.com/mikeal/aws-sign",
160270              "type": "distribution"
160271            }
160272          ],
160273          "evidence": {},
160274          "signature": {
160275            "signature": {
160276              "publicKey": {}
160277            }
160278          },
160279          "modelCard": {
160280            "modelParameters": {
160281              "approach": {}
160282            },
160283            "quantitativeAnalysis": {
160284              "graphics": {}
160285            },
160286            "considerations": {}
160287          }
160288        },
160289        {
160290          "type": "library",
160291          "bom-ref": "pkg:npm/aws4@1.11.0?package-id=5f7693878d6531bc",
160292          "supplier": {},
160293          "author": "Michael Hart \u003cmichael.hart.au@gmail.com\u003e (https://github.com/mhart)",
160294          "name": "aws4",
160295          "version": "1.11.0",
160296          "description": "Signs and prepares requests using AWS Signature Version 4",
160297          "licenses": [
160298            {
160299              "license": {
160300                "id": "MIT"
160301              }
160302            }
160303          ],
160304          "cpe": "cpe:2.3:a:aws4:aws4:1.11.0:*:*:*:*:*:*:*",
160305          "purl": "pkg:npm/aws4@1.11.0",
160306          "swid": {
160307            "attachment": {}
160308          },
160309          "pedigree": {},
160310          "externalReferences": [
160311            {
160312              "url": "github:mhart/aws4",
160313              "type": "distribution"
160314            }
160315          ],
160316          "evidence": {},
160317          "signature": {
160318            "signature": {
160319              "publicKey": {}
160320            }
160321          },
160322          "modelCard": {
160323            "modelParameters": {
160324              "approach": {}
160325            },
160326            "quantitativeAnalysis": {
160327              "graphics": {}
160328            },
160329            "considerations": {}
160330          }
160331        },
160332        {
160333          "type": "library",
160334          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=c15b2106d0ae19d4",
160335          "supplier": {},
160336          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
160337          "name": "balanced-match",
160338          "version": "1.0.2",
160339          "description": "Match balanced character pairs, like \"{\" and \"}\"",
160340          "licenses": [
160341            {
160342              "license": {
160343                "id": "MIT"
160344              }
160345            }
160346          ],
160347          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
160348          "purl": "pkg:npm/balanced-match@1.0.2",
160349          "swid": {
160350            "attachment": {}
160351          },
160352          "pedigree": {},
160353          "externalReferences": [
160354            {
160355              "url": "git://github.com/juliangruber/balanced-match.git",
160356              "type": "distribution"
160357            },
160358            {
160359              "url": "https://github.com/juliangruber/balanced-match",
160360              "type": "website"
160361            }
160362          ],
160363          "evidence": {},
160364          "signature": {
160365            "signature": {
160366              "publicKey": {}
160367            }
160368          },
160369          "modelCard": {
160370            "modelParameters": {
160371              "approach": {}
160372            },
160373            "quantitativeAnalysis": {
160374              "graphics": {}
160375            },
160376            "considerations": {}
160377          }
160378        },
160379        {
160380          "type": "library",
160381          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=8db1f18b661f67ae",
160382          "supplier": {},
160383          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
160384          "name": "balanced-match",
160385          "version": "1.0.2",
160386          "description": "Match balanced character pairs, like \"{\" and \"}\"",
160387          "licenses": [
160388            {
160389              "license": {
160390                "id": "MIT"
160391              }
160392            }
160393          ],
160394          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
160395          "purl": "pkg:npm/balanced-match@1.0.2",
160396          "swid": {
160397            "attachment": {}
160398          },
160399          "pedigree": {},
160400          "externalReferences": [
160401            {
160402              "url": "git://github.com/juliangruber/balanced-match.git",
160403              "type": "distribution"
160404            },
160405            {
160406              "url": "https://github.com/juliangruber/balanced-match",
160407              "type": "website"
160408            }
160409          ],
160410          "evidence": {},
160411          "signature": {
160412            "signature": {
160413              "publicKey": {}
160414            }
160415          },
160416          "modelCard": {
160417            "modelParameters": {
160418              "approach": {}
160419            },
160420            "quantitativeAnalysis": {
160421              "graphics": {}
160422            },
160423            "considerations": {}
160424          }
160425        },
160426        {
160427          "type": "library",
160428          "bom-ref": "pkg:npm/bcrypt-pbkdf@1.0.2?package-id=e522f8051f2c594b",
160429          "supplier": {},
160430          "name": "bcrypt-pbkdf",
160431          "version": "1.0.2",
160432          "description": "Port of the OpenBSD bcrypt_pbkdf function to pure JS",
160433          "licenses": [
160434            {
160435              "license": {
160436                "id": "BSD-3-Clause"
160437              }
160438            }
160439          ],
160440          "cpe": "cpe:2.3:a:bcrypt-pbkdf:bcrypt-pbkdf:1.0.2:*:*:*:*:*:*:*",
160441          "purl": "pkg:npm/bcrypt-pbkdf@1.0.2",
160442          "swid": {
160443            "attachment": {}
160444          },
160445          "pedigree": {},
160446          "externalReferences": [
160447            {
160448              "url": "git://github.com/joyent/node-bcrypt-pbkdf.git",
160449              "type": "distribution"
160450            }
160451          ],
160452          "evidence": {},
160453          "signature": {
160454            "signature": {
160455              "publicKey": {}
160456            }
160457          },
160458          "modelCard": {
160459            "modelParameters": {
160460              "approach": {}
160461            },
160462            "quantitativeAnalysis": {
160463              "graphics": {}
160464            },
160465            "considerations": {}
160466          }
160467        },
160468        {
160469          "type": "library",
160470          "bom-ref": "pkg:npm/bin-links@3.0.3?package-id=605ade84572e7fb",
160471          "supplier": {},
160472          "author": "GitHub Inc.",
160473          "name": "bin-links",
160474          "version": "3.0.3",
160475          "description": "JavaScript package binary linker",
160476          "licenses": [
160477            {
160478              "license": {
160479                "id": "ISC"
160480              }
160481            }
160482          ],
160483          "cpe": "cpe:2.3:a:bin-links:bin-links:3.0.3:*:*:*:*:*:*:*",
160484          "purl": "pkg:npm/bin-links@3.0.3",
160485          "swid": {
160486            "attachment": {}
160487          },
160488          "pedigree": {},
160489          "externalReferences": [
160490            {
160491              "url": "https://github.com/npm/bin-links.git",
160492              "type": "distribution"
160493            }
160494          ],
160495          "evidence": {},
160496          "signature": {
160497            "signature": {
160498              "publicKey": {}
160499            }
160500          },
160501          "modelCard": {
160502            "modelParameters": {
160503              "approach": {}
160504            },
160505            "quantitativeAnalysis": {
160506              "graphics": {}
160507            },
160508            "considerations": {}
160509          }
160510        },
160511        {
160512          "type": "library",
160513          "bom-ref": "pkg:npm/binary-extensions@2.2.0?package-id=2ddda84d3ad7f3e1",
160514          "supplier": {},
160515          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
160516          "name": "binary-extensions",
160517          "version": "2.2.0",
160518          "description": "List of binary file extensions",
160519          "licenses": [
160520            {
160521              "license": {
160522                "id": "MIT"
160523              }
160524            }
160525          ],
160526          "cpe": "cpe:2.3:a:binary-extensions:binary-extensions:2.2.0:*:*:*:*:*:*:*",
160527          "purl": "pkg:npm/binary-extensions@2.2.0",
160528          "swid": {
160529            "attachment": {}
160530          },
160531          "pedigree": {},
160532          "externalReferences": [
160533            {
160534              "url": "sindresorhus/binary-extensions",
160535              "type": "distribution"
160536            }
160537          ],
160538          "evidence": {},
160539          "signature": {
160540            "signature": {
160541              "publicKey": {}
160542            }
160543          },
160544          "modelCard": {
160545            "modelParameters": {
160546              "approach": {}
160547            },
160548            "quantitativeAnalysis": {
160549              "graphics": {}
160550            },
160551            "considerations": {}
160552          }
160553        },
160554        {
160555          "type": "library",
160556          "bom-ref": "pkg:npm/body-parser@1.19.0?package-id=462cc944e01953ba",
160557          "supplier": {},
160558          "name": "body-parser",
160559          "version": "1.19.0",
160560          "description": "Node.js body parsing middleware",
160561          "licenses": [
160562            {
160563              "license": {
160564                "id": "MIT"
160565              }
160566            }
160567          ],
160568          "cpe": "cpe:2.3:a:body-parser:body-parser:1.19.0:*:*:*:*:*:*:*",
160569          "purl": "pkg:npm/body-parser@1.19.0",
160570          "swid": {
160571            "attachment": {}
160572          },
160573          "pedigree": {},
160574          "externalReferences": [
160575            {
160576              "url": "expressjs/body-parser",
160577              "type": "distribution"
160578            }
160579          ],
160580          "evidence": {},
160581          "signature": {
160582            "signature": {
160583              "publicKey": {}
160584            }
160585          },
160586          "modelCard": {
160587            "modelParameters": {
160588              "approach": {}
160589            },
160590            "quantitativeAnalysis": {
160591              "graphics": {}
160592            },
160593            "considerations": {}
160594          }
160595        },
160596        {
160597          "type": "library",
160598          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=a36ca63616a6d457",
160599          "supplier": {},
160600          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
160601          "name": "brace-expansion",
160602          "version": "1.1.11",
160603          "description": "Brace expansion as known from sh/bash",
160604          "licenses": [
160605            {
160606              "license": {
160607                "id": "MIT"
160608              }
160609            }
160610          ],
160611          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
160612          "purl": "pkg:npm/brace-expansion@1.1.11",
160613          "swid": {
160614            "attachment": {}
160615          },
160616          "pedigree": {},
160617          "externalReferences": [
160618            {
160619              "url": "git://github.com/juliangruber/brace-expansion.git",
160620              "type": "distribution"
160621            },
160622            {
160623              "url": "https://github.com/juliangruber/brace-expansion",
160624              "type": "website"
160625            }
160626          ],
160627          "evidence": {},
160628          "signature": {
160629            "signature": {
160630              "publicKey": {}
160631            }
160632          },
160633          "modelCard": {
160634            "modelParameters": {
160635              "approach": {}
160636            },
160637            "quantitativeAnalysis": {
160638              "graphics": {}
160639            },
160640            "considerations": {}
160641          }
160642        },
160643        {
160644          "type": "library",
160645          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=8aefa0d5bf7ea5ce",
160646          "supplier": {},
160647          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
160648          "name": "brace-expansion",
160649          "version": "1.1.11",
160650          "description": "Brace expansion as known from sh/bash",
160651          "licenses": [
160652            {
160653              "license": {
160654                "id": "MIT"
160655              }
160656            }
160657          ],
160658          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
160659          "purl": "pkg:npm/brace-expansion@1.1.11",
160660          "swid": {
160661            "attachment": {}
160662          },
160663          "pedigree": {},
160664          "externalReferences": [
160665            {
160666              "url": "git://github.com/juliangruber/brace-expansion.git",
160667              "type": "distribution"
160668            },
160669            {
160670              "url": "https://github.com/juliangruber/brace-expansion",
160671              "type": "website"
160672            }
160673          ],
160674          "evidence": {},
160675          "signature": {
160676            "signature": {
160677              "publicKey": {}
160678            }
160679          },
160680          "modelCard": {
160681            "modelParameters": {
160682              "approach": {}
160683            },
160684            "quantitativeAnalysis": {
160685              "graphics": {}
160686            },
160687            "considerations": {}
160688          }
160689        },
160690        {
160691          "type": "library",
160692          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=1bc35b4fad6ec801",
160693          "supplier": {},
160694          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
160695          "name": "brace-expansion",
160696          "version": "1.1.11",
160697          "description": "Brace expansion as known from sh/bash",
160698          "licenses": [
160699            {
160700              "license": {
160701                "id": "MIT"
160702              }
160703            }
160704          ],
160705          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
160706          "purl": "pkg:npm/brace-expansion@1.1.11",
160707          "swid": {
160708            "attachment": {}
160709          },
160710          "pedigree": {},
160711          "externalReferences": [
160712            {
160713              "url": "git://github.com/juliangruber/brace-expansion.git",
160714              "type": "distribution"
160715            },
160716            {
160717              "url": "https://github.com/juliangruber/brace-expansion",
160718              "type": "website"
160719            }
160720          ],
160721          "evidence": {},
160722          "signature": {
160723            "signature": {
160724              "publicKey": {}
160725            }
160726          },
160727          "modelCard": {
160728            "modelParameters": {
160729              "approach": {}
160730            },
160731            "quantitativeAnalysis": {
160732              "graphics": {}
160733            },
160734            "considerations": {}
160735          }
160736        },
160737        {
160738          "type": "library",
160739          "bom-ref": "pkg:npm/brace-expansion@2.0.1?package-id=70d44e2ab0a06da3",
160740          "supplier": {},
160741          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
160742          "name": "brace-expansion",
160743          "version": "2.0.1",
160744          "description": "Brace expansion as known from sh/bash",
160745          "licenses": [
160746            {
160747              "license": {
160748                "id": "MIT"
160749              }
160750            }
160751          ],
160752          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:2.0.1:*:*:*:*:*:*:*",
160753          "purl": "pkg:npm/brace-expansion@2.0.1",
160754          "swid": {
160755            "attachment": {}
160756          },
160757          "pedigree": {},
160758          "externalReferences": [
160759            {
160760              "url": "git://github.com/juliangruber/brace-expansion.git",
160761              "type": "distribution"
160762            },
160763            {
160764              "url": "https://github.com/juliangruber/brace-expansion",
160765              "type": "website"
160766            }
160767          ],
160768          "evidence": {},
160769          "signature": {
160770            "signature": {
160771              "publicKey": {}
160772            }
160773          },
160774          "modelCard": {
160775            "modelParameters": {
160776              "approach": {}
160777            },
160778            "quantitativeAnalysis": {
160779              "graphics": {}
160780            },
160781            "considerations": {}
160782          }
160783        },
160784        {
160785          "type": "library",
160786          "bom-ref": "pkg:npm/builtins@5.0.1?package-id=af6ac207a0c6926d",
160787          "supplier": {},
160788          "name": "builtins",
160789          "version": "5.0.1",
160790          "description": "List of node.js builtin modules",
160791          "licenses": [
160792            {
160793              "license": {
160794                "id": "MIT"
160795              }
160796            }
160797          ],
160798          "cpe": "cpe:2.3:a:builtins:builtins:5.0.1:*:*:*:*:*:*:*",
160799          "purl": "pkg:npm/builtins@5.0.1",
160800          "swid": {
160801            "attachment": {}
160802          },
160803          "pedigree": {},
160804          "externalReferences": [
160805            {
160806              "url": "juliangruber/builtins",
160807              "type": "distribution"
160808            }
160809          ],
160810          "evidence": {},
160811          "signature": {
160812            "signature": {
160813              "publicKey": {}
160814            }
160815          },
160816          "modelCard": {
160817            "modelParameters": {
160818              "approach": {}
160819            },
160820            "quantitativeAnalysis": {
160821              "graphics": {}
160822            },
160823            "considerations": {}
160824          }
160825        },
160826        {
160827          "type": "application",
160828          "bom-ref": "e14718c64f5147f4",
160829          "supplier": {},
160830          "name": "busybox",
160831          "version": "1.35.0",
160832          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
160833          "swid": {
160834            "attachment": {}
160835          },
160836          "pedigree": {},
160837          "evidence": {},
160838          "signature": {
160839            "signature": {
160840              "publicKey": {}
160841            }
160842          },
160843          "modelCard": {
160844            "modelParameters": {
160845              "approach": {}
160846            },
160847            "quantitativeAnalysis": {
160848              "graphics": {}
160849            },
160850            "considerations": {}
160851          }
160852        },
160853        {
160854          "type": "library",
160855          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=4b48ef6f6b983526",
160856          "supplier": {},
160857          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
160858          "name": "busybox",
160859          "version": "1.35.0-r17",
160860          "description": "Size optimized toolbox of many common UNIX utilities",
160861          "licenses": [
160862            {
160863              "license": {
160864                "id": "GPL-2.0-only"
160865              }
160866            }
160867          ],
160868          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r17:*:*:*:*:*:*:*",
160869          "purl": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5",
160870          "swid": {
160871            "attachment": {}
160872          },
160873          "pedigree": {},
160874          "externalReferences": [
160875            {
160876              "url": "https://busybox.net/",
160877              "type": "distribution"
160878            }
160879          ],
160880          "evidence": {},
160881          "signature": {
160882            "signature": {
160883              "publicKey": {}
160884            }
160885          },
160886          "modelCard": {
160887            "modelParameters": {
160888              "approach": {}
160889            },
160890            "quantitativeAnalysis": {
160891              "graphics": {}
160892            },
160893            "considerations": {}
160894          }
160895        },
160896        {
160897          "type": "library",
160898          "bom-ref": "pkg:npm/bytes@3.1.0?package-id=2d0d8d4dfef7b17c",
160899          "supplier": {},
160900          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
160901          "name": "bytes",
160902          "version": "3.1.0",
160903          "description": "Utility to parse a string bytes to bytes and vice-versa",
160904          "licenses": [
160905            {
160906              "license": {
160907                "id": "MIT"
160908              }
160909            }
160910          ],
160911          "cpe": "cpe:2.3:a:bytes:bytes:3.1.0:*:*:*:*:*:*:*",
160912          "purl": "pkg:npm/bytes@3.1.0",
160913          "swid": {
160914            "attachment": {}
160915          },
160916          "pedigree": {},
160917          "externalReferences": [
160918            {
160919              "url": "visionmedia/bytes.js",
160920              "type": "distribution"
160921            }
160922          ],
160923          "evidence": {},
160924          "signature": {
160925            "signature": {
160926              "publicKey": {}
160927            }
160928          },
160929          "modelCard": {
160930            "modelParameters": {
160931              "approach": {}
160932            },
160933            "quantitativeAnalysis": {
160934              "graphics": {}
160935            },
160936            "considerations": {}
160937          }
160938        },
160939        {
160940          "type": "library",
160941          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5\u0026package-id=30622a1848b22bca",
160942          "supplier": {},
160943          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
160944          "name": "ca-certificates-bundle",
160945          "version": "20220614-r0",
160946          "description": "Pre generated bundle of Mozilla certificates",
160947          "licenses": [
160948            {
160949              "license": {
160950                "id": "MPL-2.0"
160951              }
160952            },
160953            {
160954              "license": {
160955                "name": "AND"
160956              }
160957            },
160958            {
160959              "license": {
160960                "id": "MIT"
160961              }
160962            }
160963          ],
160964          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
160965          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5",
160966          "swid": {
160967            "attachment": {}
160968          },
160969          "pedigree": {},
160970          "externalReferences": [
160971            {
160972              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
160973              "type": "distribution"
160974            }
160975          ],
160976          "evidence": {},
160977          "signature": {
160978            "signature": {
160979              "publicKey": {}
160980            }
160981          },
160982          "modelCard": {
160983            "modelParameters": {
160984              "approach": {}
160985            },
160986            "quantitativeAnalysis": {
160987              "graphics": {}
160988            },
160989            "considerations": {}
160990          }
160991        },
160992        {
160993          "type": "library",
160994          "bom-ref": "pkg:npm/cacache@16.1.3?package-id=4e055fb1e595c11",
160995          "supplier": {},
160996          "author": "GitHub Inc.",
160997          "name": "cacache",
160998          "version": "16.1.3",
160999          "description": "Fast, fault-tolerant, cross-platform, disk-based, data-agnostic, content-addressable cache.",
161000          "licenses": [
161001            {
161002              "license": {
161003                "id": "ISC"
161004              }
161005            }
161006          ],
161007          "cpe": "cpe:2.3:a:cacache:cacache:16.1.3:*:*:*:*:*:*:*",
161008          "purl": "pkg:npm/cacache@16.1.3",
161009          "swid": {
161010            "attachment": {}
161011          },
161012          "pedigree": {},
161013          "externalReferences": [
161014            {
161015              "url": "https://github.com/npm/cacache.git",
161016              "type": "distribution"
161017            }
161018          ],
161019          "evidence": {},
161020          "signature": {
161021            "signature": {
161022              "publicKey": {}
161023            }
161024          },
161025          "modelCard": {
161026            "modelParameters": {
161027              "approach": {}
161028            },
161029            "quantitativeAnalysis": {
161030              "graphics": {}
161031            },
161032            "considerations": {}
161033          }
161034        },
161035        {
161036          "type": "library",
161037          "bom-ref": "pkg:npm/camelcase@5.3.1?package-id=17dbb50316aee704",
161038          "supplier": {},
161039          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
161040          "name": "camelcase",
161041          "version": "5.3.1",
161042          "description": "Convert a dash/dot/underscore/space separated string to camelCase or PascalCase: `foo-bar` → `fooBar`",
161043          "licenses": [
161044            {
161045              "license": {
161046                "id": "MIT"
161047              }
161048            }
161049          ],
161050          "cpe": "cpe:2.3:a:camelcase:camelcase:5.3.1:*:*:*:*:*:*:*",
161051          "purl": "pkg:npm/camelcase@5.3.1",
161052          "swid": {
161053            "attachment": {}
161054          },
161055          "pedigree": {},
161056          "externalReferences": [
161057            {
161058              "url": "sindresorhus/camelcase",
161059              "type": "distribution"
161060            }
161061          ],
161062          "evidence": {},
161063          "signature": {
161064            "signature": {
161065              "publicKey": {}
161066            }
161067          },
161068          "modelCard": {
161069            "modelParameters": {
161070              "approach": {}
161071            },
161072            "quantitativeAnalysis": {
161073              "graphics": {}
161074            },
161075            "considerations": {}
161076          }
161077        },
161078        {
161079          "type": "library",
161080          "bom-ref": "pkg:npm/camelcase-keys@6.2.2?package-id=5a5b5ae4e4a9a274",
161081          "supplier": {},
161082          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
161083          "name": "camelcase-keys",
161084          "version": "6.2.2",
161085          "description": "Convert object keys to camel case",
161086          "licenses": [
161087            {
161088              "license": {
161089                "id": "MIT"
161090              }
161091            }
161092          ],
161093          "cpe": "cpe:2.3:a:camelcase-keys:camelcase-keys:6.2.2:*:*:*:*:*:*:*",
161094          "purl": "pkg:npm/camelcase-keys@6.2.2",
161095          "swid": {
161096            "attachment": {}
161097          },
161098          "pedigree": {},
161099          "externalReferences": [
161100            {
161101              "url": "sindresorhus/camelcase-keys",
161102              "type": "distribution"
161103            }
161104          ],
161105          "evidence": {},
161106          "signature": {
161107            "signature": {
161108              "publicKey": {}
161109            }
161110          },
161111          "modelCard": {
161112            "modelParameters": {
161113              "approach": {}
161114            },
161115            "quantitativeAnalysis": {
161116              "graphics": {}
161117            },
161118            "considerations": {}
161119          }
161120        },
161121        {
161122          "type": "library",
161123          "bom-ref": "pkg:npm/caseless@0.12.0?package-id=227a1a61cfc117ad",
161124          "supplier": {},
161125          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
161126          "name": "caseless",
161127          "version": "0.12.0",
161128          "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
161129          "licenses": [
161130            {
161131              "license": {
161132                "id": "Apache-2.0"
161133              }
161134            }
161135          ],
161136          "cpe": "cpe:2.3:a:caseless:caseless:0.12.0:*:*:*:*:*:*:*",
161137          "purl": "pkg:npm/caseless@0.12.0",
161138          "swid": {
161139            "attachment": {}
161140          },
161141          "pedigree": {},
161142          "externalReferences": [
161143            {
161144              "url": "https://github.com/mikeal/caseless",
161145              "type": "distribution"
161146            }
161147          ],
161148          "evidence": {},
161149          "signature": {
161150            "signature": {
161151              "publicKey": {}
161152            }
161153          },
161154          "modelCard": {
161155            "modelParameters": {
161156              "approach": {}
161157            },
161158            "quantitativeAnalysis": {
161159              "graphics": {}
161160            },
161161            "considerations": {}
161162          }
161163        },
161164        {
161165          "type": "library",
161166          "bom-ref": "pkg:npm/chalk@1.1.3?package-id=76f13078d58865d",
161167          "supplier": {},
161168          "name": "chalk",
161169          "version": "1.1.3",
161170          "description": "Terminal string styling done right. Much color.",
161171          "licenses": [
161172            {
161173              "license": {
161174                "id": "MIT"
161175              }
161176            }
161177          ],
161178          "cpe": "cpe:2.3:a:chalk:chalk:1.1.3:*:*:*:*:*:*:*",
161179          "purl": "pkg:npm/chalk@1.1.3",
161180          "swid": {
161181            "attachment": {}
161182          },
161183          "pedigree": {},
161184          "externalReferences": [
161185            {
161186              "url": "chalk/chalk",
161187              "type": "distribution"
161188            }
161189          ],
161190          "evidence": {},
161191          "signature": {
161192            "signature": {
161193              "publicKey": {}
161194            }
161195          },
161196          "modelCard": {
161197            "modelParameters": {
161198              "approach": {}
161199            },
161200            "quantitativeAnalysis": {
161201              "graphics": {}
161202            },
161203            "considerations": {}
161204          }
161205        },
161206        {
161207          "type": "library",
161208          "bom-ref": "pkg:npm/chalk@2.4.2?package-id=2dda8dd3bedbb7a9",
161209          "supplier": {},
161210          "name": "chalk",
161211          "version": "2.4.2",
161212          "description": "Terminal string styling done right",
161213          "licenses": [
161214            {
161215              "license": {
161216                "id": "MIT"
161217              }
161218            }
161219          ],
161220          "cpe": "cpe:2.3:a:chalk:chalk:2.4.2:*:*:*:*:*:*:*",
161221          "purl": "pkg:npm/chalk@2.4.2",
161222          "swid": {
161223            "attachment": {}
161224          },
161225          "pedigree": {},
161226          "externalReferences": [
161227            {
161228              "url": "chalk/chalk",
161229              "type": "distribution"
161230            }
161231          ],
161232          "evidence": {},
161233          "signature": {
161234            "signature": {
161235              "publicKey": {}
161236            }
161237          },
161238          "modelCard": {
161239            "modelParameters": {
161240              "approach": {}
161241            },
161242            "quantitativeAnalysis": {
161243              "graphics": {}
161244            },
161245            "considerations": {}
161246          }
161247        },
161248        {
161249          "type": "library",
161250          "bom-ref": "pkg:npm/chalk@4.1.2?package-id=b12178723b56594f",
161251          "supplier": {},
161252          "name": "chalk",
161253          "version": "4.1.2",
161254          "description": "Terminal string styling done right",
161255          "licenses": [
161256            {
161257              "license": {
161258                "id": "MIT"
161259              }
161260            }
161261          ],
161262          "cpe": "cpe:2.3:a:chalk:chalk:4.1.2:*:*:*:*:*:*:*",
161263          "purl": "pkg:npm/chalk@4.1.2",
161264          "swid": {
161265            "attachment": {}
161266          },
161267          "pedigree": {},
161268          "externalReferences": [
161269            {
161270              "url": "chalk/chalk",
161271              "type": "distribution"
161272            }
161273          ],
161274          "evidence": {},
161275          "signature": {
161276            "signature": {
161277              "publicKey": {}
161278            }
161279          },
161280          "modelCard": {
161281            "modelParameters": {
161282              "approach": {}
161283            },
161284            "quantitativeAnalysis": {
161285              "graphics": {}
161286            },
161287            "considerations": {}
161288          }
161289        },
161290        {
161291          "type": "library",
161292          "bom-ref": "pkg:npm/chownr@2.0.0?package-id=b5088c57ceda122f",
161293          "supplier": {},
161294          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
161295          "name": "chownr",
161296          "version": "2.0.0",
161297          "description": "like `chown -R`",
161298          "licenses": [
161299            {
161300              "license": {
161301                "id": "ISC"
161302              }
161303            }
161304          ],
161305          "cpe": "cpe:2.3:a:chownr:chownr:2.0.0:*:*:*:*:*:*:*",
161306          "purl": "pkg:npm/chownr@2.0.0",
161307          "swid": {
161308            "attachment": {}
161309          },
161310          "pedigree": {},
161311          "externalReferences": [
161312            {
161313              "url": "git://github.com/isaacs/chownr.git",
161314              "type": "distribution"
161315            }
161316          ],
161317          "evidence": {},
161318          "signature": {
161319            "signature": {
161320              "publicKey": {}
161321            }
161322          },
161323          "modelCard": {
161324            "modelParameters": {
161325              "approach": {}
161326            },
161327            "quantitativeAnalysis": {
161328              "graphics": {}
161329            },
161330            "considerations": {}
161331          }
161332        },
161333        {
161334          "type": "library",
161335          "bom-ref": "pkg:npm/chownr@2.0.0?package-id=b6eb8c484ba68dba",
161336          "supplier": {},
161337          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
161338          "name": "chownr",
161339          "version": "2.0.0",
161340          "description": "like `chown -R`",
161341          "licenses": [
161342            {
161343              "license": {
161344                "id": "ISC"
161345              }
161346            }
161347          ],
161348          "cpe": "cpe:2.3:a:chownr:chownr:2.0.0:*:*:*:*:*:*:*",
161349          "purl": "pkg:npm/chownr@2.0.0",
161350          "swid": {
161351            "attachment": {}
161352          },
161353          "pedigree": {},
161354          "externalReferences": [
161355            {
161356              "url": "git://github.com/isaacs/chownr.git",
161357              "type": "distribution"
161358            }
161359          ],
161360          "evidence": {},
161361          "signature": {
161362            "signature": {
161363              "publicKey": {}
161364            }
161365          },
161366          "modelCard": {
161367            "modelParameters": {
161368              "approach": {}
161369            },
161370            "quantitativeAnalysis": {
161371              "graphics": {}
161372            },
161373            "considerations": {}
161374          }
161375        },
161376        {
161377          "type": "library",
161378          "bom-ref": "pkg:npm/cidr-regex@3.1.1?package-id=be2d165b38649e26",
161379          "supplier": {},
161380          "author": "silverwind \u003cme@silverwind.io\u003e",
161381          "name": "cidr-regex",
161382          "version": "3.1.1",
161383          "description": "Regular expression for matching IP addresses in CIDR notation",
161384          "licenses": [
161385            {
161386              "license": {
161387                "id": "BSD-2-Clause"
161388              }
161389            }
161390          ],
161391          "cpe": "cpe:2.3:a:cidr-regex:cidr-regex:3.1.1:*:*:*:*:*:*:*",
161392          "purl": "pkg:npm/cidr-regex@3.1.1",
161393          "swid": {
161394            "attachment": {}
161395          },
161396          "pedigree": {},
161397          "externalReferences": [
161398            {
161399              "url": "silverwind/cidr-regex",
161400              "type": "distribution"
161401            }
161402          ],
161403          "evidence": {},
161404          "signature": {
161405            "signature": {
161406              "publicKey": {}
161407            }
161408          },
161409          "modelCard": {
161410            "modelParameters": {
161411              "approach": {}
161412            },
161413            "quantitativeAnalysis": {
161414              "graphics": {}
161415            },
161416            "considerations": {}
161417          }
161418        },
161419        {
161420          "type": "library",
161421          "bom-ref": "pkg:npm/clean-stack@2.2.0?package-id=9a5c51e7acb4b115",
161422          "supplier": {},
161423          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
161424          "name": "clean-stack",
161425          "version": "2.2.0",
161426          "description": "Clean up error stack traces",
161427          "licenses": [
161428            {
161429              "license": {
161430                "id": "MIT"
161431              }
161432            }
161433          ],
161434          "cpe": "cpe:2.3:a:clean-stack:clean-stack:2.2.0:*:*:*:*:*:*:*",
161435          "purl": "pkg:npm/clean-stack@2.2.0",
161436          "swid": {
161437            "attachment": {}
161438          },
161439          "pedigree": {},
161440          "externalReferences": [
161441            {
161442              "url": "sindresorhus/clean-stack",
161443              "type": "distribution"
161444            }
161445          ],
161446          "evidence": {},
161447          "signature": {
161448            "signature": {
161449              "publicKey": {}
161450            }
161451          },
161452          "modelCard": {
161453            "modelParameters": {
161454              "approach": {}
161455            },
161456            "quantitativeAnalysis": {
161457              "graphics": {}
161458            },
161459            "considerations": {}
161460          }
161461        },
161462        {
161463          "type": "library",
161464          "bom-ref": "pkg:npm/cli-columns@4.0.0?package-id=61a1dfb277c2e6f7",
161465          "supplier": {},
161466          "author": "Shannon Moeller \u003cme@shannonmoeller\u003e (http://shannonmoeller.com)",
161467          "name": "cli-columns",
161468          "version": "4.0.0",
161469          "description": "Columnated lists for the CLI.",
161470          "licenses": [
161471            {
161472              "license": {
161473                "id": "MIT"
161474              }
161475            }
161476          ],
161477          "cpe": "cpe:2.3:a:shannonmoeller:cli-columns:4.0.0:*:*:*:*:*:*:*",
161478          "purl": "pkg:npm/cli-columns@4.0.0",
161479          "swid": {
161480            "attachment": {}
161481          },
161482          "pedigree": {},
161483          "externalReferences": [
161484            {
161485              "url": "shannonmoeller/cli-columns",
161486              "type": "distribution"
161487            },
161488            {
161489              "url": "https://github.com/shannonmoeller/cli-columns#readme",
161490              "type": "website"
161491            }
161492          ],
161493          "evidence": {},
161494          "signature": {
161495            "signature": {
161496              "publicKey": {}
161497            }
161498          },
161499          "modelCard": {
161500            "modelParameters": {
161501              "approach": {}
161502            },
161503            "quantitativeAnalysis": {
161504              "graphics": {}
161505            },
161506            "considerations": {}
161507          }
161508        },
161509        {
161510          "type": "library",
161511          "bom-ref": "pkg:npm/cli-table3@0.6.2?package-id=c77ee2194bd52f3d",
161512          "supplier": {},
161513          "author": "James Talmage",
161514          "name": "cli-table3",
161515          "version": "0.6.2",
161516          "description": "Pretty unicode tables for the command line. Based on the original cli-table.",
161517          "licenses": [
161518            {
161519              "license": {
161520                "id": "MIT"
161521              }
161522            }
161523          ],
161524          "cpe": "cpe:2.3:a:cli-table3:cli-table3:0.6.2:*:*:*:*:*:*:*",
161525          "purl": "pkg:npm/cli-table3@0.6.2",
161526          "swid": {
161527            "attachment": {}
161528          },
161529          "pedigree": {},
161530          "externalReferences": [
161531            {
161532              "url": "https://github.com/cli-table/cli-table3.git",
161533              "type": "distribution"
161534            },
161535            {
161536              "url": "https://github.com/cli-table/cli-table3",
161537              "type": "website"
161538            }
161539          ],
161540          "evidence": {},
161541          "signature": {
161542            "signature": {
161543              "publicKey": {}
161544            }
161545          },
161546          "modelCard": {
161547            "modelParameters": {
161548              "approach": {}
161549            },
161550            "quantitativeAnalysis": {
161551              "graphics": {}
161552            },
161553            "considerations": {}
161554          }
161555        },
161556        {
161557          "type": "library",
161558          "bom-ref": "pkg:npm/cliui@5.0.0?package-id=fc23b83417a19917",
161559          "supplier": {},
161560          "author": "Ben Coe \u003cben@npmjs.com\u003e",
161561          "name": "cliui",
161562          "version": "5.0.0",
161563          "description": "easily create complex multi-column command-line-interfaces",
161564          "licenses": [
161565            {
161566              "license": {
161567                "id": "ISC"
161568              }
161569            }
161570          ],
161571          "cpe": "cpe:2.3:a:cliui:cliui:5.0.0:*:*:*:*:*:*:*",
161572          "purl": "pkg:npm/cliui@5.0.0",
161573          "swid": {
161574            "attachment": {}
161575          },
161576          "pedigree": {},
161577          "externalReferences": [
161578            {
161579              "url": "http://github.com/yargs/cliui.git",
161580              "type": "distribution"
161581            }
161582          ],
161583          "evidence": {},
161584          "signature": {
161585            "signature": {
161586              "publicKey": {}
161587            }
161588          },
161589          "modelCard": {
161590            "modelParameters": {
161591              "approach": {}
161592            },
161593            "quantitativeAnalysis": {
161594              "graphics": {}
161595            },
161596            "considerations": {}
161597          }
161598        },
161599        {
161600          "type": "library",
161601          "bom-ref": "pkg:npm/clone@1.0.4?package-id=44b571b36478d30c",
161602          "supplier": {},
161603          "author": "Paul Vorbach \u003cpaul@vorba.ch\u003e (http://paul.vorba.ch/)",
161604          "name": "clone",
161605          "version": "1.0.4",
161606          "description": "deep cloning of objects and arrays",
161607          "licenses": [
161608            {
161609              "license": {
161610                "id": "MIT"
161611              }
161612            }
161613          ],
161614          "cpe": "cpe:2.3:a:clone:clone:1.0.4:*:*:*:*:*:*:*",
161615          "purl": "pkg:npm/clone@1.0.4",
161616          "swid": {
161617            "attachment": {}
161618          },
161619          "pedigree": {},
161620          "externalReferences": [
161621            {
161622              "url": "git://github.com/pvorb/node-clone.git",
161623              "type": "distribution"
161624            }
161625          ],
161626          "evidence": {},
161627          "signature": {
161628            "signature": {
161629              "publicKey": {}
161630            }
161631          },
161632          "modelCard": {
161633            "modelParameters": {
161634              "approach": {}
161635            },
161636            "quantitativeAnalysis": {
161637              "graphics": {}
161638            },
161639            "considerations": {}
161640          }
161641        },
161642        {
161643          "type": "library",
161644          "bom-ref": "pkg:npm/cmd-shim@5.0.0?package-id=6701e31fdf422502",
161645          "supplier": {},
161646          "author": "GitHub Inc.",
161647          "name": "cmd-shim",
161648          "version": "5.0.0",
161649          "description": "Used in npm for command line application support",
161650          "licenses": [
161651            {
161652              "license": {
161653                "id": "ISC"
161654              }
161655            }
161656          ],
161657          "cpe": "cpe:2.3:a:cmd-shim:cmd-shim:5.0.0:*:*:*:*:*:*:*",
161658          "purl": "pkg:npm/cmd-shim@5.0.0",
161659          "swid": {
161660            "attachment": {}
161661          },
161662          "pedigree": {},
161663          "externalReferences": [
161664            {
161665              "url": "https://github.com/npm/cmd-shim.git",
161666              "type": "distribution"
161667            }
161668          ],
161669          "evidence": {},
161670          "signature": {
161671            "signature": {
161672              "publicKey": {}
161673            }
161674          },
161675          "modelCard": {
161676            "modelParameters": {
161677              "approach": {}
161678            },
161679            "quantitativeAnalysis": {
161680              "graphics": {}
161681            },
161682            "considerations": {}
161683          }
161684        },
161685        {
161686          "type": "library",
161687          "bom-ref": "pkg:npm/code-point-at@1.1.0?package-id=3512fa99162e2014",
161688          "supplier": {},
161689          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
161690          "name": "code-point-at",
161691          "version": "1.1.0",
161692          "description": "ES2015 `String#codePointAt()` ponyfill",
161693          "licenses": [
161694            {
161695              "license": {
161696                "id": "MIT"
161697              }
161698            }
161699          ],
161700          "cpe": "cpe:2.3:a:code-point-at:code-point-at:1.1.0:*:*:*:*:*:*:*",
161701          "purl": "pkg:npm/code-point-at@1.1.0",
161702          "swid": {
161703            "attachment": {}
161704          },
161705          "pedigree": {},
161706          "externalReferences": [
161707            {
161708              "url": "sindresorhus/code-point-at",
161709              "type": "distribution"
161710            }
161711          ],
161712          "evidence": {},
161713          "signature": {
161714            "signature": {
161715              "publicKey": {}
161716            }
161717          },
161718          "modelCard": {
161719            "modelParameters": {
161720              "approach": {}
161721            },
161722            "quantitativeAnalysis": {
161723              "graphics": {}
161724            },
161725            "considerations": {}
161726          }
161727        },
161728        {
161729          "type": "library",
161730          "bom-ref": "pkg:npm/color-convert@1.9.3?package-id=b59d318e978e5d66",
161731          "supplier": {},
161732          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
161733          "name": "color-convert",
161734          "version": "1.9.3",
161735          "description": "Plain color conversion functions",
161736          "licenses": [
161737            {
161738              "license": {
161739                "id": "MIT"
161740              }
161741            }
161742          ],
161743          "cpe": "cpe:2.3:a:color-convert:color-convert:1.9.3:*:*:*:*:*:*:*",
161744          "purl": "pkg:npm/color-convert@1.9.3",
161745          "swid": {
161746            "attachment": {}
161747          },
161748          "pedigree": {},
161749          "externalReferences": [
161750            {
161751              "url": "Qix-/color-convert",
161752              "type": "distribution"
161753            }
161754          ],
161755          "evidence": {},
161756          "signature": {
161757            "signature": {
161758              "publicKey": {}
161759            }
161760          },
161761          "modelCard": {
161762            "modelParameters": {
161763              "approach": {}
161764            },
161765            "quantitativeAnalysis": {
161766              "graphics": {}
161767            },
161768            "considerations": {}
161769          }
161770        },
161771        {
161772          "type": "library",
161773          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=2be936aafe32cf82",
161774          "supplier": {},
161775          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
161776          "name": "color-convert",
161777          "version": "2.0.1",
161778          "description": "Plain color conversion functions",
161779          "licenses": [
161780            {
161781              "license": {
161782                "id": "MIT"
161783              }
161784            }
161785          ],
161786          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
161787          "purl": "pkg:npm/color-convert@2.0.1",
161788          "swid": {
161789            "attachment": {}
161790          },
161791          "pedigree": {},
161792          "externalReferences": [
161793            {
161794              "url": "Qix-/color-convert",
161795              "type": "distribution"
161796            }
161797          ],
161798          "evidence": {},
161799          "signature": {
161800            "signature": {
161801              "publicKey": {}
161802            }
161803          },
161804          "modelCard": {
161805            "modelParameters": {
161806              "approach": {}
161807            },
161808            "quantitativeAnalysis": {
161809              "graphics": {}
161810            },
161811            "considerations": {}
161812          }
161813        },
161814        {
161815          "type": "library",
161816          "bom-ref": "pkg:npm/color-name@1.1.3?package-id=21b65fb759f90e9b",
161817          "supplier": {},
161818          "author": "DY \u003cdfcreative@gmail.com\u003e",
161819          "name": "color-name",
161820          "version": "1.1.3",
161821          "description": "A list of color names and its values",
161822          "licenses": [
161823            {
161824              "license": {
161825                "id": "MIT"
161826              }
161827            }
161828          ],
161829          "cpe": "cpe:2.3:a:color-name:color-name:1.1.3:*:*:*:*:*:*:*",
161830          "purl": "pkg:npm/color-name@1.1.3",
161831          "swid": {
161832            "attachment": {}
161833          },
161834          "pedigree": {},
161835          "externalReferences": [
161836            {
161837              "url": "git@github.com:dfcreative/color-name.git",
161838              "type": "distribution"
161839            },
161840            {
161841              "url": "https://github.com/dfcreative/color-name",
161842              "type": "website"
161843            }
161844          ],
161845          "evidence": {},
161846          "signature": {
161847            "signature": {
161848              "publicKey": {}
161849            }
161850          },
161851          "modelCard": {
161852            "modelParameters": {
161853              "approach": {}
161854            },
161855            "quantitativeAnalysis": {
161856              "graphics": {}
161857            },
161858            "considerations": {}
161859          }
161860        },
161861        {
161862          "type": "library",
161863          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=b14fd2e37cdab40f",
161864          "supplier": {},
161865          "author": "DY \u003cdfcreative@gmail.com\u003e",
161866          "name": "color-name",
161867          "version": "1.1.4",
161868          "description": "A list of color names and its values",
161869          "licenses": [
161870            {
161871              "license": {
161872                "id": "MIT"
161873              }
161874            }
161875          ],
161876          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
161877          "purl": "pkg:npm/color-name@1.1.4",
161878          "swid": {
161879            "attachment": {}
161880          },
161881          "pedigree": {},
161882          "externalReferences": [
161883            {
161884              "url": "git@github.com:colorjs/color-name.git",
161885              "type": "distribution"
161886            },
161887            {
161888              "url": "https://github.com/colorjs/color-name",
161889              "type": "website"
161890            }
161891          ],
161892          "evidence": {},
161893          "signature": {
161894            "signature": {
161895              "publicKey": {}
161896            }
161897          },
161898          "modelCard": {
161899            "modelParameters": {
161900              "approach": {}
161901            },
161902            "quantitativeAnalysis": {
161903              "graphics": {}
161904            },
161905            "considerations": {}
161906          }
161907        },
161908        {
161909          "type": "library",
161910          "bom-ref": "pkg:npm/color-support@1.1.3?package-id=33c3f3c0dd43aff8",
161911          "supplier": {},
161912          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
161913          "name": "color-support",
161914          "version": "1.1.3",
161915          "description": "A module which will endeavor to guess your terminal's level of color support.",
161916          "licenses": [
161917            {
161918              "license": {
161919                "id": "ISC"
161920              }
161921            }
161922          ],
161923          "cpe": "cpe:2.3:a:color-support:color-support:1.1.3:*:*:*:*:*:*:*",
161924          "purl": "pkg:npm/color-support@1.1.3",
161925          "swid": {
161926            "attachment": {}
161927          },
161928          "pedigree": {},
161929          "externalReferences": [
161930            {
161931              "url": "git+https://github.com/isaacs/color-support.git",
161932              "type": "distribution"
161933            }
161934          ],
161935          "evidence": {},
161936          "signature": {
161937            "signature": {
161938              "publicKey": {}
161939            }
161940          },
161941          "modelCard": {
161942            "modelParameters": {
161943              "approach": {}
161944            },
161945            "quantitativeAnalysis": {
161946              "graphics": {}
161947            },
161948            "considerations": {}
161949          }
161950        },
161951        {
161952          "type": "library",
161953          "bom-ref": "pkg:npm/columnify@1.6.0?package-id=fc90187aad4a6027",
161954          "supplier": {},
161955          "author": "Tim Oxley",
161956          "name": "columnify",
161957          "version": "1.6.0",
161958          "description": "Render data in text columns. Supports in-column text-wrap.",
161959          "licenses": [
161960            {
161961              "license": {
161962                "id": "MIT"
161963              }
161964            }
161965          ],
161966          "cpe": "cpe:2.3:a:columnify:columnify:1.6.0:*:*:*:*:*:*:*",
161967          "purl": "pkg:npm/columnify@1.6.0",
161968          "swid": {
161969            "attachment": {}
161970          },
161971          "pedigree": {},
161972          "externalReferences": [
161973            {
161974              "url": "git://github.com/timoxley/columnify.git",
161975              "type": "distribution"
161976            },
161977            {
161978              "url": "https://github.com/timoxley/columnify",
161979              "type": "website"
161980            }
161981          ],
161982          "evidence": {},
161983          "signature": {
161984            "signature": {
161985              "publicKey": {}
161986            }
161987          },
161988          "modelCard": {
161989            "modelParameters": {
161990              "approach": {}
161991            },
161992            "quantitativeAnalysis": {
161993              "graphics": {}
161994            },
161995            "considerations": {}
161996          }
161997        },
161998        {
161999          "type": "library",
162000          "bom-ref": "pkg:npm/combined-stream@1.0.8?package-id=868606bb12d293db",
162001          "supplier": {},
162002          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
162003          "name": "combined-stream",
162004          "version": "1.0.8",
162005          "description": "A stream that emits multiple other streams one after another.",
162006          "licenses": [
162007            {
162008              "license": {
162009                "id": "MIT"
162010              }
162011            }
162012          ],
162013          "cpe": "cpe:2.3:a:combined-stream:combined-stream:1.0.8:*:*:*:*:*:*:*",
162014          "purl": "pkg:npm/combined-stream@1.0.8",
162015          "swid": {
162016            "attachment": {}
162017          },
162018          "pedigree": {},
162019          "externalReferences": [
162020            {
162021              "url": "git://github.com/felixge/node-combined-stream.git",
162022              "type": "distribution"
162023            },
162024            {
162025              "url": "https://github.com/felixge/node-combined-stream",
162026              "type": "website"
162027            }
162028          ],
162029          "evidence": {},
162030          "signature": {
162031            "signature": {
162032              "publicKey": {}
162033            }
162034          },
162035          "modelCard": {
162036            "modelParameters": {
162037              "approach": {}
162038            },
162039            "quantitativeAnalysis": {
162040              "graphics": {}
162041            },
162042            "considerations": {}
162043          }
162044        },
162045        {
162046          "type": "library",
162047          "bom-ref": "pkg:npm/common-ancestor-path@1.0.1?package-id=4296edf5ae5437c0",
162048          "supplier": {},
162049          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
162050          "name": "common-ancestor-path",
162051          "version": "1.0.1",
162052          "description": "Find the common ancestor of 2 or more paths on Windows or Unix",
162053          "licenses": [
162054            {
162055              "license": {
162056                "id": "ISC"
162057              }
162058            }
162059          ],
162060          "cpe": "cpe:2.3:a:common-ancestor-path:common-ancestor-path:1.0.1:*:*:*:*:*:*:*",
162061          "purl": "pkg:npm/common-ancestor-path@1.0.1",
162062          "swid": {
162063            "attachment": {}
162064          },
162065          "pedigree": {},
162066          "externalReferences": [
162067            {
162068              "url": "git+https://github.com/isaacs/common-ancestor-path",
162069              "type": "distribution"
162070            }
162071          ],
162072          "evidence": {},
162073          "signature": {
162074            "signature": {
162075              "publicKey": {}
162076            }
162077          },
162078          "modelCard": {
162079            "modelParameters": {
162080              "approach": {}
162081            },
162082            "quantitativeAnalysis": {
162083              "graphics": {}
162084            },
162085            "considerations": {}
162086          }
162087        },
162088        {
162089          "type": "library",
162090          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=bdf14b65a5715b98",
162091          "supplier": {},
162092          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
162093          "name": "concat-map",
162094          "version": "0.0.1",
162095          "description": "concatenative mapdashery",
162096          "licenses": [
162097            {
162098              "license": {
162099                "id": "MIT"
162100              }
162101            }
162102          ],
162103          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
162104          "purl": "pkg:npm/concat-map@0.0.1",
162105          "swid": {
162106            "attachment": {}
162107          },
162108          "pedigree": {},
162109          "externalReferences": [
162110            {
162111              "url": "git://github.com/substack/node-concat-map.git",
162112              "type": "distribution"
162113            }
162114          ],
162115          "evidence": {},
162116          "signature": {
162117            "signature": {
162118              "publicKey": {}
162119            }
162120          },
162121          "modelCard": {
162122            "modelParameters": {
162123              "approach": {}
162124            },
162125            "quantitativeAnalysis": {
162126              "graphics": {}
162127            },
162128            "considerations": {}
162129          }
162130        },
162131        {
162132          "type": "library",
162133          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=c45208cf5ec4e0c1",
162134          "supplier": {},
162135          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
162136          "name": "concat-map",
162137          "version": "0.0.1",
162138          "description": "concatenative mapdashery",
162139          "licenses": [
162140            {
162141              "license": {
162142                "id": "MIT"
162143              }
162144            }
162145          ],
162146          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
162147          "purl": "pkg:npm/concat-map@0.0.1",
162148          "swid": {
162149            "attachment": {}
162150          },
162151          "pedigree": {},
162152          "externalReferences": [
162153            {
162154              "url": "git://github.com/substack/node-concat-map.git",
162155              "type": "distribution"
162156            }
162157          ],
162158          "evidence": {},
162159          "signature": {
162160            "signature": {
162161              "publicKey": {}
162162            }
162163          },
162164          "modelCard": {
162165            "modelParameters": {
162166              "approach": {}
162167            },
162168            "quantitativeAnalysis": {
162169              "graphics": {}
162170            },
162171            "considerations": {}
162172          }
162173        },
162174        {
162175          "type": "library",
162176          "bom-ref": "pkg:npm/console-control-strings@1.1.0?package-id=f5b1c468fcf0a37a",
162177          "supplier": {},
162178          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
162179          "name": "console-control-strings",
162180          "version": "1.1.0",
162181          "description": "A library of cross-platform tested terminal/console command strings for doing things like color and cursor positioning.  This is a subset of both ansi and vt100.  All control codes included work on both Windows \u0026 Unix-like OSes, except where noted.",
162182          "licenses": [
162183            {
162184              "license": {
162185                "id": "ISC"
162186              }
162187            }
162188          ],
162189          "cpe": "cpe:2.3:a:console-control-strings:console-control-strings:1.1.0:*:*:*:*:*:*:*",
162190          "purl": "pkg:npm/console-control-strings@1.1.0",
162191          "swid": {
162192            "attachment": {}
162193          },
162194          "pedigree": {},
162195          "externalReferences": [
162196            {
162197              "url": "https://github.com/iarna/console-control-strings",
162198              "type": "distribution"
162199            }
162200          ],
162201          "evidence": {},
162202          "signature": {
162203            "signature": {
162204              "publicKey": {}
162205            }
162206          },
162207          "modelCard": {
162208            "modelParameters": {
162209              "approach": {}
162210            },
162211            "quantitativeAnalysis": {
162212              "graphics": {}
162213            },
162214            "considerations": {}
162215          }
162216        },
162217        {
162218          "type": "library",
162219          "bom-ref": "pkg:npm/console-control-strings@1.1.0?package-id=f1988658aefff76d",
162220          "supplier": {},
162221          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
162222          "name": "console-control-strings",
162223          "version": "1.1.0",
162224          "description": "A library of cross-platform tested terminal/console command strings for doing things like color and cursor positioning.  This is a subset of both ansi and vt100.  All control codes included work on both Windows \u0026 Unix-like OSes, except where noted.",
162225          "licenses": [
162226            {
162227              "license": {
162228                "id": "ISC"
162229              }
162230            }
162231          ],
162232          "cpe": "cpe:2.3:a:console-control-strings:console-control-strings:1.1.0:*:*:*:*:*:*:*",
162233          "purl": "pkg:npm/console-control-strings@1.1.0",
162234          "swid": {
162235            "attachment": {}
162236          },
162237          "pedigree": {},
162238          "externalReferences": [
162239            {
162240              "url": "https://github.com/iarna/console-control-strings",
162241              "type": "distribution"
162242            }
162243          ],
162244          "evidence": {},
162245          "signature": {
162246            "signature": {
162247              "publicKey": {}
162248            }
162249          },
162250          "modelCard": {
162251            "modelParameters": {
162252              "approach": {}
162253            },
162254            "quantitativeAnalysis": {
162255              "graphics": {}
162256            },
162257            "considerations": {}
162258          }
162259        },
162260        {
162261          "type": "library",
162262          "bom-ref": "pkg:npm/content-disposition@0.5.3?package-id=1e905051ff96d81d",
162263          "supplier": {},
162264          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
162265          "name": "content-disposition",
162266          "version": "0.5.3",
162267          "description": "Create and parse Content-Disposition header",
162268          "licenses": [
162269            {
162270              "license": {
162271                "id": "MIT"
162272              }
162273            }
162274          ],
162275          "cpe": "cpe:2.3:a:content-disposition:content-disposition:0.5.3:*:*:*:*:*:*:*",
162276          "purl": "pkg:npm/content-disposition@0.5.3",
162277          "swid": {
162278            "attachment": {}
162279          },
162280          "pedigree": {},
162281          "externalReferences": [
162282            {
162283              "url": "jshttp/content-disposition",
162284              "type": "distribution"
162285            }
162286          ],
162287          "evidence": {},
162288          "signature": {
162289            "signature": {
162290              "publicKey": {}
162291            }
162292          },
162293          "modelCard": {
162294            "modelParameters": {
162295              "approach": {}
162296            },
162297            "quantitativeAnalysis": {
162298              "graphics": {}
162299            },
162300            "considerations": {}
162301          }
162302        },
162303        {
162304          "type": "library",
162305          "bom-ref": "pkg:npm/content-type@1.0.4?package-id=d344220e964f6e33",
162306          "supplier": {},
162307          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
162308          "name": "content-type",
162309          "version": "1.0.4",
162310          "description": "Create and parse HTTP Content-Type header",
162311          "licenses": [
162312            {
162313              "license": {
162314                "id": "MIT"
162315              }
162316            }
162317          ],
162318          "cpe": "cpe:2.3:a:content-type:content-type:1.0.4:*:*:*:*:*:*:*",
162319          "purl": "pkg:npm/content-type@1.0.4",
162320          "swid": {
162321            "attachment": {}
162322          },
162323          "pedigree": {},
162324          "externalReferences": [
162325            {
162326              "url": "jshttp/content-type",
162327              "type": "distribution"
162328            }
162329          ],
162330          "evidence": {},
162331          "signature": {
162332            "signature": {
162333              "publicKey": {}
162334            }
162335          },
162336          "modelCard": {
162337            "modelParameters": {
162338              "approach": {}
162339            },
162340            "quantitativeAnalysis": {
162341              "graphics": {}
162342            },
162343            "considerations": {}
162344          }
162345        },
162346        {
162347          "type": "library",
162348          "bom-ref": "pkg:npm/cookie@0.4.0?package-id=73a66864dec2ee22",
162349          "supplier": {},
162350          "author": "Roman Shtylman \u003cshtylman@gmail.com\u003e",
162351          "name": "cookie",
162352          "version": "0.4.0",
162353          "description": "HTTP server cookie parsing and serialization",
162354          "licenses": [
162355            {
162356              "license": {
162357                "id": "MIT"
162358              }
162359            }
162360          ],
162361          "cpe": "cpe:2.3:a:cookie:cookie:0.4.0:*:*:*:*:*:*:*",
162362          "purl": "pkg:npm/cookie@0.4.0",
162363          "swid": {
162364            "attachment": {}
162365          },
162366          "pedigree": {},
162367          "externalReferences": [
162368            {
162369              "url": "jshttp/cookie",
162370              "type": "distribution"
162371            }
162372          ],
162373          "evidence": {},
162374          "signature": {
162375            "signature": {
162376              "publicKey": {}
162377            }
162378          },
162379          "modelCard": {
162380            "modelParameters": {
162381              "approach": {}
162382            },
162383            "quantitativeAnalysis": {
162384              "graphics": {}
162385            },
162386            "considerations": {}
162387          }
162388        },
162389        {
162390          "type": "library",
162391          "bom-ref": "pkg:npm/cookie-signature@1.0.6?package-id=679e26b17ad72290",
162392          "supplier": {},
162393          "author": "TJ Holowaychuk \u003ctj@learnboost.com\u003e",
162394          "name": "cookie-signature",
162395          "version": "1.0.6",
162396          "description": "Sign and unsign cookies",
162397          "licenses": [
162398            {
162399              "license": {
162400                "id": "MIT"
162401              }
162402            }
162403          ],
162404          "cpe": "cpe:2.3:a:cookie-signature:cookie-signature:1.0.6:*:*:*:*:*:*:*",
162405          "purl": "pkg:npm/cookie-signature@1.0.6",
162406          "swid": {
162407            "attachment": {}
162408          },
162409          "pedigree": {},
162410          "externalReferences": [
162411            {
162412              "url": "https://github.com/visionmedia/node-cookie-signature.git",
162413              "type": "distribution"
162414            }
162415          ],
162416          "evidence": {},
162417          "signature": {
162418            "signature": {
162419              "publicKey": {}
162420            }
162421          },
162422          "modelCard": {
162423            "modelParameters": {
162424              "approach": {}
162425            },
162426            "quantitativeAnalysis": {
162427              "graphics": {}
162428            },
162429            "considerations": {}
162430          }
162431        },
162432        {
162433          "type": "library",
162434          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=619d47a4e1417653",
162435          "supplier": {},
162436          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
162437          "name": "core-util-is",
162438          "version": "1.0.2",
162439          "description": "The `util.is*` functions introduced in Node v0.12.",
162440          "licenses": [
162441            {
162442              "license": {
162443                "id": "MIT"
162444              }
162445            }
162446          ],
162447          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
162448          "purl": "pkg:npm/core-util-is@1.0.2",
162449          "swid": {
162450            "attachment": {}
162451          },
162452          "pedigree": {},
162453          "externalReferences": [
162454            {
162455              "url": "git://github.com/isaacs/core-util-is",
162456              "type": "distribution"
162457            }
162458          ],
162459          "evidence": {},
162460          "signature": {
162461            "signature": {
162462              "publicKey": {}
162463            }
162464          },
162465          "modelCard": {
162466            "modelParameters": {
162467              "approach": {}
162468            },
162469            "quantitativeAnalysis": {
162470              "graphics": {}
162471            },
162472            "considerations": {}
162473          }
162474        },
162475        {
162476          "type": "library",
162477          "bom-ref": "pkg:npm/corepack@0.17.0?package-id=9d78c3bef9c05db3",
162478          "supplier": {},
162479          "name": "corepack",
162480          "version": "0.17.0",
162481          "licenses": [
162482            {
162483              "license": {
162484                "id": "MIT"
162485              }
162486            }
162487          ],
162488          "cpe": "cpe:2.3:a:corepack:corepack:0.17.0:*:*:*:*:*:*:*",
162489          "purl": "pkg:npm/corepack@0.17.0",
162490          "swid": {
162491            "attachment": {}
162492          },
162493          "pedigree": {},
162494          "externalReferences": [
162495            {
162496              "url": "https://github.com/nodejs/corepack.git",
162497              "type": "distribution"
162498            },
162499            {
162500              "url": "https://github.com/nodejs/corepack#readme",
162501              "type": "website"
162502            }
162503          ],
162504          "evidence": {},
162505          "signature": {
162506            "signature": {
162507              "publicKey": {}
162508            }
162509          },
162510          "modelCard": {
162511            "modelParameters": {
162512              "approach": {}
162513            },
162514            "quantitativeAnalysis": {
162515              "graphics": {}
162516            },
162517            "considerations": {}
162518          }
162519        },
162520        {
162521          "type": "library",
162522          "bom-ref": "pkg:npm/cross-spawn@7.0.3?package-id=68f286a9fc565c0b",
162523          "supplier": {},
162524          "author": "André Cruz \u003candre@moxy.studio\u003e",
162525          "name": "cross-spawn",
162526          "version": "7.0.3",
162527          "description": "Cross platform child_process#spawn and child_process#spawnSync",
162528          "licenses": [
162529            {
162530              "license": {
162531                "id": "MIT"
162532              }
162533            }
162534          ],
162535          "cpe": "cpe:2.3:a:cross-spawn:cross-spawn:7.0.3:*:*:*:*:*:*:*",
162536          "purl": "pkg:npm/cross-spawn@7.0.3",
162537          "swid": {
162538            "attachment": {}
162539          },
162540          "pedigree": {},
162541          "externalReferences": [
162542            {
162543              "url": "git@github.com:moxystudio/node-cross-spawn.git",
162544              "type": "distribution"
162545            },
162546            {
162547              "url": "https://github.com/moxystudio/node-cross-spawn",
162548              "type": "website"
162549            }
162550          ],
162551          "evidence": {},
162552          "signature": {
162553            "signature": {
162554              "publicKey": {}
162555            }
162556          },
162557          "modelCard": {
162558            "modelParameters": {
162559              "approach": {}
162560            },
162561            "quantitativeAnalysis": {
162562              "graphics": {}
162563            },
162564            "considerations": {}
162565          }
162566        },
162567        {
162568          "type": "library",
162569          "bom-ref": "pkg:npm/cssesc@3.0.0?package-id=91a6a74efc4b88ba",
162570          "supplier": {},
162571          "author": "Mathias Bynens (https://mathiasbynens.be/)",
162572          "name": "cssesc",
162573          "version": "3.0.0",
162574          "description": "A JavaScript library for escaping CSS strings and identifiers while generating the shortest possible ASCII-only output.",
162575          "licenses": [
162576            {
162577              "license": {
162578                "id": "MIT"
162579              }
162580            }
162581          ],
162582          "cpe": "cpe:2.3:a:mathiasbynens:cssesc:3.0.0:*:*:*:*:*:*:*",
162583          "purl": "pkg:npm/cssesc@3.0.0",
162584          "swid": {
162585            "attachment": {}
162586          },
162587          "pedigree": {},
162588          "externalReferences": [
162589            {
162590              "url": "https://github.com/mathiasbynens/cssesc.git",
162591              "type": "distribution"
162592            },
162593            {
162594              "url": "https://mths.be/cssesc",
162595              "type": "website"
162596            }
162597          ],
162598          "evidence": {},
162599          "signature": {
162600            "signature": {
162601              "publicKey": {}
162602            }
162603          },
162604          "modelCard": {
162605            "modelParameters": {
162606              "approach": {}
162607            },
162608            "quantitativeAnalysis": {
162609              "graphics": {}
162610            },
162611            "considerations": {}
162612          }
162613        },
162614        {
162615          "type": "library",
162616          "bom-ref": "pkg:npm/dashdash@1.14.1?package-id=a7ca4af6d828a5a2",
162617          "supplier": {},
162618          "author": "Trent Mick \u003ctrentm@gmail.com\u003e (http://trentm.com)",
162619          "name": "dashdash",
162620          "version": "1.14.1",
162621          "description": "A light, featureful and explicit option parsing library.",
162622          "licenses": [
162623            {
162624              "license": {
162625                "id": "MIT"
162626              }
162627            }
162628          ],
162629          "cpe": "cpe:2.3:a:dashdash:dashdash:1.14.1:*:*:*:*:*:*:*",
162630          "purl": "pkg:npm/dashdash@1.14.1",
162631          "swid": {
162632            "attachment": {}
162633          },
162634          "pedigree": {},
162635          "externalReferences": [
162636            {
162637              "url": "git://github.com/trentm/node-dashdash.git",
162638              "type": "distribution"
162639            }
162640          ],
162641          "evidence": {},
162642          "signature": {
162643            "signature": {
162644              "publicKey": {}
162645            }
162646          },
162647          "modelCard": {
162648            "modelParameters": {
162649              "approach": {}
162650            },
162651            "quantitativeAnalysis": {
162652              "graphics": {}
162653            },
162654            "considerations": {}
162655          }
162656        },
162657        {
162658          "type": "library",
162659          "bom-ref": "pkg:npm/debug@2.6.9?package-id=189dbf0c8c397194",
162660          "supplier": {},
162661          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
162662          "name": "debug",
162663          "version": "2.6.9",
162664          "description": "small debugging utility",
162665          "licenses": [
162666            {
162667              "license": {
162668                "id": "MIT"
162669              }
162670            }
162671          ],
162672          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
162673          "purl": "pkg:npm/debug@2.6.9",
162674          "swid": {
162675            "attachment": {}
162676          },
162677          "pedigree": {},
162678          "externalReferences": [
162679            {
162680              "url": "git://github.com/visionmedia/debug.git",
162681              "type": "distribution"
162682            }
162683          ],
162684          "evidence": {},
162685          "signature": {
162686            "signature": {
162687              "publicKey": {}
162688            }
162689          },
162690          "modelCard": {
162691            "modelParameters": {
162692              "approach": {}
162693            },
162694            "quantitativeAnalysis": {
162695              "graphics": {}
162696            },
162697            "considerations": {}
162698          }
162699        },
162700        {
162701          "type": "library",
162702          "bom-ref": "pkg:npm/debug@4.3.4?package-id=744fe4d31961f128",
162703          "supplier": {},
162704          "author": "Josh Junon \u003cjosh.junon@protonmail.com\u003e",
162705          "name": "debug",
162706          "version": "4.3.4",
162707          "description": "Lightweight debugging utility for Node.js and the browser",
162708          "licenses": [
162709            {
162710              "license": {
162711                "id": "MIT"
162712              }
162713            }
162714          ],
162715          "cpe": "cpe:2.3:a:debug-js:debug:4.3.4:*:*:*:*:*:*:*",
162716          "purl": "pkg:npm/debug@4.3.4",
162717          "swid": {
162718            "attachment": {}
162719          },
162720          "pedigree": {},
162721          "externalReferences": [
162722            {
162723              "url": "git://github.com/debug-js/debug.git",
162724              "type": "distribution"
162725            }
162726          ],
162727          "evidence": {},
162728          "signature": {
162729            "signature": {
162730              "publicKey": {}
162731            }
162732          },
162733          "modelCard": {
162734            "modelParameters": {
162735              "approach": {}
162736            },
162737            "quantitativeAnalysis": {
162738              "graphics": {}
162739            },
162740            "considerations": {}
162741          }
162742        },
162743        {
162744          "type": "library",
162745          "bom-ref": "pkg:npm/debuglog@1.0.1?package-id=de8cab91bb3727ee",
162746          "supplier": {},
162747          "author": "Sam Roberts \u003csam@strongloop.com\u003e",
162748          "name": "debuglog",
162749          "version": "1.0.1",
162750          "description": "backport of util.debuglog from node v0.11",
162751          "licenses": [
162752            {
162753              "license": {
162754                "id": "MIT"
162755              }
162756            }
162757          ],
162758          "cpe": "cpe:2.3:a:sam-github:debuglog:1.0.1:*:*:*:*:*:*:*",
162759          "purl": "pkg:npm/debuglog@1.0.1",
162760          "swid": {
162761            "attachment": {}
162762          },
162763          "pedigree": {},
162764          "externalReferences": [
162765            {
162766              "url": "https://github.com/sam-github/node-debuglog.git",
162767              "type": "distribution"
162768            }
162769          ],
162770          "evidence": {},
162771          "signature": {
162772            "signature": {
162773              "publicKey": {}
162774            }
162775          },
162776          "modelCard": {
162777            "modelParameters": {
162778              "approach": {}
162779            },
162780            "quantitativeAnalysis": {
162781              "graphics": {}
162782            },
162783            "considerations": {}
162784          }
162785        },
162786        {
162787          "type": "library",
162788          "bom-ref": "pkg:npm/decamelize@1.2.0?package-id=ea04b30bc07ca72e",
162789          "supplier": {},
162790          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
162791          "name": "decamelize",
162792          "version": "1.2.0",
162793          "description": "Convert a camelized string into a lowercased one with a custom separator: unicornRainbow → unicorn_rainbow",
162794          "licenses": [
162795            {
162796              "license": {
162797                "id": "MIT"
162798              }
162799            }
162800          ],
162801          "cpe": "cpe:2.3:a:decamelize:decamelize:1.2.0:*:*:*:*:*:*:*",
162802          "purl": "pkg:npm/decamelize@1.2.0",
162803          "swid": {
162804            "attachment": {}
162805          },
162806          "pedigree": {},
162807          "externalReferences": [
162808            {
162809              "url": "sindresorhus/decamelize",
162810              "type": "distribution"
162811            }
162812          ],
162813          "evidence": {},
162814          "signature": {
162815            "signature": {
162816              "publicKey": {}
162817            }
162818          },
162819          "modelCard": {
162820            "modelParameters": {
162821              "approach": {}
162822            },
162823            "quantitativeAnalysis": {
162824              "graphics": {}
162825            },
162826            "considerations": {}
162827          }
162828        },
162829        {
162830          "type": "library",
162831          "bom-ref": "pkg:npm/decamelize-keys@1.1.1?package-id=4ef8653ed0679bb4",
162832          "supplier": {},
162833          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (http://sindresorhus.com)",
162834          "name": "decamelize-keys",
162835          "version": "1.1.1",
162836          "description": "Convert object keys from camelCase to lowercase with a custom separator",
162837          "licenses": [
162838            {
162839              "license": {
162840                "id": "MIT"
162841              }
162842            }
162843          ],
162844          "cpe": "cpe:2.3:a:decamelize-keys:decamelize-keys:1.1.1:*:*:*:*:*:*:*",
162845          "purl": "pkg:npm/decamelize-keys@1.1.1",
162846          "swid": {
162847            "attachment": {}
162848          },
162849          "pedigree": {},
162850          "externalReferences": [
162851            {
162852              "url": "sindresorhus/decamelize-keys",
162853              "type": "distribution"
162854            }
162855          ],
162856          "evidence": {},
162857          "signature": {
162858            "signature": {
162859              "publicKey": {}
162860            }
162861          },
162862          "modelCard": {
162863            "modelParameters": {
162864              "approach": {}
162865            },
162866            "quantitativeAnalysis": {
162867              "graphics": {}
162868            },
162869            "considerations": {}
162870          }
162871        },
162872        {
162873          "type": "library",
162874          "bom-ref": "pkg:npm/defaults@1.0.3?package-id=539a687773af61fe",
162875          "supplier": {},
162876          "author": "Elijah Insua \u003ctmpvar@gmail.com\u003e",
162877          "name": "defaults",
162878          "version": "1.0.3",
162879          "description": "merge single level defaults over a config object",
162880          "licenses": [
162881            {
162882              "license": {
162883                "id": "MIT"
162884              }
162885            }
162886          ],
162887          "cpe": "cpe:2.3:a:defaults:defaults:1.0.3:*:*:*:*:*:*:*",
162888          "purl": "pkg:npm/defaults@1.0.3",
162889          "swid": {
162890            "attachment": {}
162891          },
162892          "pedigree": {},
162893          "externalReferences": [
162894            {
162895              "url": "git://github.com/tmpvar/defaults.git",
162896              "type": "distribution"
162897            }
162898          ],
162899          "evidence": {},
162900          "signature": {
162901            "signature": {
162902              "publicKey": {}
162903            }
162904          },
162905          "modelCard": {
162906            "modelParameters": {
162907              "approach": {}
162908            },
162909            "quantitativeAnalysis": {
162910              "graphics": {}
162911            },
162912            "considerations": {}
162913          }
162914        },
162915        {
162916          "type": "library",
162917          "bom-ref": "pkg:npm/delayed-stream@1.0.0?package-id=2e87a018d352ff35",
162918          "supplier": {},
162919          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
162920          "name": "delayed-stream",
162921          "version": "1.0.0",
162922          "description": "Buffers events from a stream until you are ready to handle them.",
162923          "licenses": [
162924            {
162925              "license": {
162926                "id": "MIT"
162927              }
162928            }
162929          ],
162930          "cpe": "cpe:2.3:a:delayed-stream:delayed-stream:1.0.0:*:*:*:*:*:*:*",
162931          "purl": "pkg:npm/delayed-stream@1.0.0",
162932          "swid": {
162933            "attachment": {}
162934          },
162935          "pedigree": {},
162936          "externalReferences": [
162937            {
162938              "url": "git://github.com/felixge/node-delayed-stream.git",
162939              "type": "distribution"
162940            },
162941            {
162942              "url": "https://github.com/felixge/node-delayed-stream",
162943              "type": "website"
162944            }
162945          ],
162946          "evidence": {},
162947          "signature": {
162948            "signature": {
162949              "publicKey": {}
162950            }
162951          },
162952          "modelCard": {
162953            "modelParameters": {
162954              "approach": {}
162955            },
162956            "quantitativeAnalysis": {
162957              "graphics": {}
162958            },
162959            "considerations": {}
162960          }
162961        },
162962        {
162963          "type": "library",
162964          "bom-ref": "pkg:npm/delegates@1.0.0?package-id=ed0c22d60c260f5c",
162965          "supplier": {},
162966          "name": "delegates",
162967          "version": "1.0.0",
162968          "description": "delegate methods and accessors to another property",
162969          "licenses": [
162970            {
162971              "license": {
162972                "id": "MIT"
162973              }
162974            }
162975          ],
162976          "cpe": "cpe:2.3:a:delegates:delegates:1.0.0:*:*:*:*:*:*:*",
162977          "purl": "pkg:npm/delegates@1.0.0",
162978          "swid": {
162979            "attachment": {}
162980          },
162981          "pedigree": {},
162982          "externalReferences": [
162983            {
162984              "url": "visionmedia/node-delegates",
162985              "type": "distribution"
162986            }
162987          ],
162988          "evidence": {},
162989          "signature": {
162990            "signature": {
162991              "publicKey": {}
162992            }
162993          },
162994          "modelCard": {
162995            "modelParameters": {
162996              "approach": {}
162997            },
162998            "quantitativeAnalysis": {
162999              "graphics": {}
163000            },
163001            "considerations": {}
163002          }
163003        },
163004        {
163005          "type": "library",
163006          "bom-ref": "pkg:npm/delegates@1.0.0?package-id=82e18a186444f540",
163007          "supplier": {},
163008          "name": "delegates",
163009          "version": "1.0.0",
163010          "description": "delegate methods and accessors to another property",
163011          "licenses": [
163012            {
163013              "license": {
163014                "id": "MIT"
163015              }
163016            }
163017          ],
163018          "cpe": "cpe:2.3:a:delegates:delegates:1.0.0:*:*:*:*:*:*:*",
163019          "purl": "pkg:npm/delegates@1.0.0",
163020          "swid": {
163021            "attachment": {}
163022          },
163023          "pedigree": {},
163024          "externalReferences": [
163025            {
163026              "url": "visionmedia/node-delegates",
163027              "type": "distribution"
163028            }
163029          ],
163030          "evidence": {},
163031          "signature": {
163032            "signature": {
163033              "publicKey": {}
163034            }
163035          },
163036          "modelCard": {
163037            "modelParameters": {
163038              "approach": {}
163039            },
163040            "quantitativeAnalysis": {
163041              "graphics": {}
163042            },
163043            "considerations": {}
163044          }
163045        },
163046        {
163047          "type": "library",
163048          "bom-ref": "pkg:npm/depd@1.1.2?package-id=8f51ca0c72f74b81",
163049          "supplier": {},
163050          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
163051          "name": "depd",
163052          "version": "1.1.2",
163053          "description": "Deprecate all the things",
163054          "licenses": [
163055            {
163056              "license": {
163057                "id": "MIT"
163058              }
163059            }
163060          ],
163061          "cpe": "cpe:2.3:a:depd:depd:1.1.2:*:*:*:*:*:*:*",
163062          "purl": "pkg:npm/depd@1.1.2",
163063          "swid": {
163064            "attachment": {}
163065          },
163066          "pedigree": {},
163067          "externalReferences": [
163068            {
163069              "url": "dougwilson/nodejs-depd",
163070              "type": "distribution"
163071            }
163072          ],
163073          "evidence": {},
163074          "signature": {
163075            "signature": {
163076              "publicKey": {}
163077            }
163078          },
163079          "modelCard": {
163080            "modelParameters": {
163081              "approach": {}
163082            },
163083            "quantitativeAnalysis": {
163084              "graphics": {}
163085            },
163086            "considerations": {}
163087          }
163088        },
163089        {
163090          "type": "library",
163091          "bom-ref": "pkg:npm/depd@1.1.2?package-id=88f59320de2b0d4a",
163092          "supplier": {},
163093          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
163094          "name": "depd",
163095          "version": "1.1.2",
163096          "description": "Deprecate all the things",
163097          "licenses": [
163098            {
163099              "license": {
163100                "id": "MIT"
163101              }
163102            }
163103          ],
163104          "cpe": "cpe:2.3:a:depd:depd:1.1.2:*:*:*:*:*:*:*",
163105          "purl": "pkg:npm/depd@1.1.2",
163106          "swid": {
163107            "attachment": {}
163108          },
163109          "pedigree": {},
163110          "externalReferences": [
163111            {
163112              "url": "dougwilson/nodejs-depd",
163113              "type": "distribution"
163114            }
163115          ],
163116          "evidence": {},
163117          "signature": {
163118            "signature": {
163119              "publicKey": {}
163120            }
163121          },
163122          "modelCard": {
163123            "modelParameters": {
163124              "approach": {}
163125            },
163126            "quantitativeAnalysis": {
163127              "graphics": {}
163128            },
163129            "considerations": {}
163130          }
163131        },
163132        {
163133          "type": "library",
163134          "bom-ref": "pkg:npm/destroy@1.0.4?package-id=7a46d2c188b90042",
163135          "supplier": {},
163136          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
163137          "name": "destroy",
163138          "version": "1.0.4",
163139          "description": "destroy a stream if possible",
163140          "licenses": [
163141            {
163142              "license": {
163143                "id": "MIT"
163144              }
163145            }
163146          ],
163147          "cpe": "cpe:2.3:a:destroy:destroy:1.0.4:*:*:*:*:*:*:*",
163148          "purl": "pkg:npm/destroy@1.0.4",
163149          "swid": {
163150            "attachment": {}
163151          },
163152          "pedigree": {},
163153          "externalReferences": [
163154            {
163155              "url": "stream-utils/destroy",
163156              "type": "distribution"
163157            }
163158          ],
163159          "evidence": {},
163160          "signature": {
163161            "signature": {
163162              "publicKey": {}
163163            }
163164          },
163165          "modelCard": {
163166            "modelParameters": {
163167              "approach": {}
163168            },
163169            "quantitativeAnalysis": {
163170              "graphics": {}
163171            },
163172            "considerations": {}
163173          }
163174        },
163175        {
163176          "type": "library",
163177          "bom-ref": "pkg:npm/dezalgo@1.0.4?package-id=d8ccca0e738815bf",
163178          "supplier": {},
163179          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
163180          "name": "dezalgo",
163181          "version": "1.0.4",
163182          "description": "Contain async insanity so that the dark pony lord doesn't eat souls",
163183          "licenses": [
163184            {
163185              "license": {
163186                "id": "ISC"
163187              }
163188            }
163189          ],
163190          "cpe": "cpe:2.3:a:dezalgo:dezalgo:1.0.4:*:*:*:*:*:*:*",
163191          "purl": "pkg:npm/dezalgo@1.0.4",
163192          "swid": {
163193            "attachment": {}
163194          },
163195          "pedigree": {},
163196          "externalReferences": [
163197            {
163198              "url": "https://github.com/npm/dezalgo",
163199              "type": "distribution"
163200            },
163201            {
163202              "url": "https://github.com/npm/dezalgo",
163203              "type": "website"
163204            }
163205          ],
163206          "evidence": {},
163207          "signature": {
163208            "signature": {
163209              "publicKey": {}
163210            }
163211          },
163212          "modelCard": {
163213            "modelParameters": {
163214              "approach": {}
163215            },
163216            "quantitativeAnalysis": {
163217              "graphics": {}
163218            },
163219            "considerations": {}
163220          }
163221        },
163222        {
163223          "type": "library",
163224          "bom-ref": "pkg:npm/diff@5.1.0?package-id=d6e2c2128602c71d",
163225          "supplier": {},
163226          "name": "diff",
163227          "version": "5.1.0",
163228          "description": "A javascript text diff implementation.",
163229          "licenses": [
163230            {
163231              "license": {
163232                "id": "BSD-3-Clause"
163233              }
163234            }
163235          ],
163236          "cpe": "cpe:2.3:a:kpdecker:diff:5.1.0:*:*:*:*:*:*:*",
163237          "purl": "pkg:npm/diff@5.1.0",
163238          "swid": {
163239            "attachment": {}
163240          },
163241          "pedigree": {},
163242          "externalReferences": [
163243            {
163244              "url": "git://github.com/kpdecker/jsdiff.git",
163245              "type": "distribution"
163246            }
163247          ],
163248          "evidence": {},
163249          "signature": {
163250            "signature": {
163251              "publicKey": {}
163252            }
163253          },
163254          "modelCard": {
163255            "modelParameters": {
163256              "approach": {}
163257            },
163258            "quantitativeAnalysis": {
163259              "graphics": {}
163260            },
163261            "considerations": {}
163262          }
163263        },
163264        {
163265          "type": "library",
163266          "bom-ref": "pkg:npm/ecc-jsbn@0.1.2?package-id=281a10dc51f85ca9",
163267          "supplier": {},
163268          "author": "Jeremie Miller \u003cjeremie@jabber.org\u003e (http://jeremie.com/)",
163269          "name": "ecc-jsbn",
163270          "version": "0.1.2",
163271          "description": "ECC JS code based on JSBN",
163272          "licenses": [
163273            {
163274              "license": {
163275                "id": "MIT"
163276              }
163277            }
163278          ],
163279          "cpe": "cpe:2.3:a:quartzjer:ecc-jsbn:0.1.2:*:*:*:*:*:*:*",
163280          "purl": "pkg:npm/ecc-jsbn@0.1.2",
163281          "swid": {
163282            "attachment": {}
163283          },
163284          "pedigree": {},
163285          "externalReferences": [
163286            {
163287              "url": "https://github.com/quartzjer/ecc-jsbn.git",
163288              "type": "distribution"
163289            },
163290            {
163291              "url": "https://github.com/quartzjer/ecc-jsbn",
163292              "type": "website"
163293            }
163294          ],
163295          "evidence": {},
163296          "signature": {
163297            "signature": {
163298              "publicKey": {}
163299            }
163300          },
163301          "modelCard": {
163302            "modelParameters": {
163303              "approach": {}
163304            },
163305            "quantitativeAnalysis": {
163306              "graphics": {}
163307            },
163308            "considerations": {}
163309          }
163310        },
163311        {
163312          "type": "library",
163313          "bom-ref": "pkg:npm/ee-first@1.1.1?package-id=e237c873e14ffd47",
163314          "supplier": {},
163315          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
163316          "name": "ee-first",
163317          "version": "1.1.1",
163318          "description": "return the first event in a set of ee/event pairs",
163319          "licenses": [
163320            {
163321              "license": {
163322                "id": "MIT"
163323              }
163324            }
163325          ],
163326          "cpe": "cpe:2.3:a:ee-first:ee-first:1.1.1:*:*:*:*:*:*:*",
163327          "purl": "pkg:npm/ee-first@1.1.1",
163328          "swid": {
163329            "attachment": {}
163330          },
163331          "pedigree": {},
163332          "externalReferences": [
163333            {
163334              "url": "jonathanong/ee-first",
163335              "type": "distribution"
163336            }
163337          ],
163338          "evidence": {},
163339          "signature": {
163340            "signature": {
163341              "publicKey": {}
163342            }
163343          },
163344          "modelCard": {
163345            "modelParameters": {
163346              "approach": {}
163347            },
163348            "quantitativeAnalysis": {
163349              "graphics": {}
163350            },
163351            "considerations": {}
163352          }
163353        },
163354        {
163355          "type": "library",
163356          "bom-ref": "pkg:npm/emoji-regex@7.0.3?package-id=4161e2e73378d2aa",
163357          "supplier": {},
163358          "author": "Mathias Bynens (https://mathiasbynens.be/)",
163359          "name": "emoji-regex",
163360          "version": "7.0.3",
163361          "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
163362          "licenses": [
163363            {
163364              "license": {
163365                "id": "MIT"
163366              }
163367            }
163368          ],
163369          "cpe": "cpe:2.3:a:mathiasbynens:emoji-regex:7.0.3:*:*:*:*:*:*:*",
163370          "purl": "pkg:npm/emoji-regex@7.0.3",
163371          "swid": {
163372            "attachment": {}
163373          },
163374          "pedigree": {},
163375          "externalReferences": [
163376            {
163377              "url": "https://github.com/mathiasbynens/emoji-regex.git",
163378              "type": "distribution"
163379            },
163380            {
163381              "url": "https://mths.be/emoji-regex",
163382              "type": "website"
163383            }
163384          ],
163385          "evidence": {},
163386          "signature": {
163387            "signature": {
163388              "publicKey": {}
163389            }
163390          },
163391          "modelCard": {
163392            "modelParameters": {
163393              "approach": {}
163394            },
163395            "quantitativeAnalysis": {
163396              "graphics": {}
163397            },
163398            "considerations": {}
163399          }
163400        },
163401        {
163402          "type": "library",
163403          "bom-ref": "pkg:npm/emoji-regex@8.0.0?package-id=6bb38678688ed46f",
163404          "supplier": {},
163405          "author": "Mathias Bynens (https://mathiasbynens.be/)",
163406          "name": "emoji-regex",
163407          "version": "8.0.0",
163408          "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
163409          "licenses": [
163410            {
163411              "license": {
163412                "id": "MIT"
163413              }
163414            }
163415          ],
163416          "cpe": "cpe:2.3:a:mathiasbynens:emoji-regex:8.0.0:*:*:*:*:*:*:*",
163417          "purl": "pkg:npm/emoji-regex@8.0.0",
163418          "swid": {
163419            "attachment": {}
163420          },
163421          "pedigree": {},
163422          "externalReferences": [
163423            {
163424              "url": "https://github.com/mathiasbynens/emoji-regex.git",
163425              "type": "distribution"
163426            },
163427            {
163428              "url": "https://mths.be/emoji-regex",
163429              "type": "website"
163430            }
163431          ],
163432          "evidence": {},
163433          "signature": {
163434            "signature": {
163435              "publicKey": {}
163436            }
163437          },
163438          "modelCard": {
163439            "modelParameters": {
163440              "approach": {}
163441            },
163442            "quantitativeAnalysis": {
163443              "graphics": {}
163444            },
163445            "considerations": {}
163446          }
163447        },
163448        {
163449          "type": "library",
163450          "bom-ref": "pkg:npm/encodeurl@1.0.2?package-id=ca5122f9d292a60f",
163451          "supplier": {},
163452          "name": "encodeurl",
163453          "version": "1.0.2",
163454          "description": "Encode a URL to a percent-encoded form, excluding already-encoded sequences",
163455          "licenses": [
163456            {
163457              "license": {
163458                "id": "MIT"
163459              }
163460            }
163461          ],
163462          "cpe": "cpe:2.3:a:encodeurl:encodeurl:1.0.2:*:*:*:*:*:*:*",
163463          "purl": "pkg:npm/encodeurl@1.0.2",
163464          "swid": {
163465            "attachment": {}
163466          },
163467          "pedigree": {},
163468          "externalReferences": [
163469            {
163470              "url": "pillarjs/encodeurl",
163471              "type": "distribution"
163472            }
163473          ],
163474          "evidence": {},
163475          "signature": {
163476            "signature": {
163477              "publicKey": {}
163478            }
163479          },
163480          "modelCard": {
163481            "modelParameters": {
163482              "approach": {}
163483            },
163484            "quantitativeAnalysis": {
163485              "graphics": {}
163486            },
163487            "considerations": {}
163488          }
163489        },
163490        {
163491          "type": "library",
163492          "bom-ref": "pkg:npm/encoding@0.1.13?package-id=e65b6a429cd40212",
163493          "supplier": {},
163494          "author": "Andris Reinman",
163495          "name": "encoding",
163496          "version": "0.1.13",
163497          "description": "Convert encodings, uses iconv-lite",
163498          "licenses": [
163499            {
163500              "license": {
163501                "id": "MIT"
163502              }
163503            }
163504          ],
163505          "cpe": "cpe:2.3:a:encoding:encoding:0.1.13:*:*:*:*:*:*:*",
163506          "purl": "pkg:npm/encoding@0.1.13",
163507          "swid": {
163508            "attachment": {}
163509          },
163510          "pedigree": {},
163511          "externalReferences": [
163512            {
163513              "url": "https://github.com/andris9/encoding.git",
163514              "type": "distribution"
163515            }
163516          ],
163517          "evidence": {},
163518          "signature": {
163519            "signature": {
163520              "publicKey": {}
163521            }
163522          },
163523          "modelCard": {
163524            "modelParameters": {
163525              "approach": {}
163526            },
163527            "quantitativeAnalysis": {
163528              "graphics": {}
163529            },
163530            "considerations": {}
163531          }
163532        },
163533        {
163534          "type": "library",
163535          "bom-ref": "pkg:npm/env-paths@2.2.1?package-id=d14634fe75802cac",
163536          "supplier": {},
163537          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
163538          "name": "env-paths",
163539          "version": "2.2.1",
163540          "description": "Get paths for storing things like data, config, cache, etc",
163541          "licenses": [
163542            {
163543              "license": {
163544                "id": "MIT"
163545              }
163546            }
163547          ],
163548          "cpe": "cpe:2.3:a:env-paths:env-paths:2.2.1:*:*:*:*:*:*:*",
163549          "purl": "pkg:npm/env-paths@2.2.1",
163550          "swid": {
163551            "attachment": {}
163552          },
163553          "pedigree": {},
163554          "externalReferences": [
163555            {
163556              "url": "sindresorhus/env-paths",
163557              "type": "distribution"
163558            }
163559          ],
163560          "evidence": {},
163561          "signature": {
163562            "signature": {
163563              "publicKey": {}
163564            }
163565          },
163566          "modelCard": {
163567            "modelParameters": {
163568              "approach": {}
163569            },
163570            "quantitativeAnalysis": {
163571              "graphics": {}
163572            },
163573            "considerations": {}
163574          }
163575        },
163576        {
163577          "type": "library",
163578          "bom-ref": "pkg:npm/env-paths@2.2.1?package-id=a40344c1c9f3ec9",
163579          "supplier": {},
163580          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
163581          "name": "env-paths",
163582          "version": "2.2.1",
163583          "description": "Get paths for storing things like data, config, cache, etc",
163584          "licenses": [
163585            {
163586              "license": {
163587                "id": "MIT"
163588              }
163589            }
163590          ],
163591          "cpe": "cpe:2.3:a:env-paths:env-paths:2.2.1:*:*:*:*:*:*:*",
163592          "purl": "pkg:npm/env-paths@2.2.1",
163593          "swid": {
163594            "attachment": {}
163595          },
163596          "pedigree": {},
163597          "externalReferences": [
163598            {
163599              "url": "sindresorhus/env-paths",
163600              "type": "distribution"
163601            }
163602          ],
163603          "evidence": {},
163604          "signature": {
163605            "signature": {
163606              "publicKey": {}
163607            }
163608          },
163609          "modelCard": {
163610            "modelParameters": {
163611              "approach": {}
163612            },
163613            "quantitativeAnalysis": {
163614              "graphics": {}
163615            },
163616            "considerations": {}
163617          }
163618        },
163619        {
163620          "type": "library",
163621          "bom-ref": "pkg:npm/err-code@2.0.3?package-id=60b62094686938a4",
163622          "supplier": {},
163623          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
163624          "name": "err-code",
163625          "version": "2.0.3",
163626          "description": "Create an error with a code",
163627          "licenses": [
163628            {
163629              "license": {
163630                "id": "MIT"
163631              }
163632            }
163633          ],
163634          "cpe": "cpe:2.3:a:IndigoUnited:err-code:2.0.3:*:*:*:*:*:*:*",
163635          "purl": "pkg:npm/err-code@2.0.3",
163636          "swid": {
163637            "attachment": {}
163638          },
163639          "pedigree": {},
163640          "externalReferences": [
163641            {
163642              "url": "git://github.com/IndigoUnited/js-err-code.git",
163643              "type": "distribution"
163644            }
163645          ],
163646          "evidence": {},
163647          "signature": {
163648            "signature": {
163649              "publicKey": {}
163650            }
163651          },
163652          "modelCard": {
163653            "modelParameters": {
163654              "approach": {}
163655            },
163656            "quantitativeAnalysis": {
163657              "graphics": {}
163658            },
163659            "considerations": {}
163660          }
163661        },
163662        {
163663          "type": "library",
163664          "bom-ref": "pkg:npm/error-ex@1.3.2?package-id=165ddbb0fda57ed3",
163665          "supplier": {},
163666          "name": "error-ex",
163667          "version": "1.3.2",
163668          "description": "Easy error subclassing and stack customization",
163669          "licenses": [
163670            {
163671              "license": {
163672                "id": "MIT"
163673              }
163674            }
163675          ],
163676          "cpe": "cpe:2.3:a:error-ex:error-ex:1.3.2:*:*:*:*:*:*:*",
163677          "purl": "pkg:npm/error-ex@1.3.2",
163678          "swid": {
163679            "attachment": {}
163680          },
163681          "pedigree": {},
163682          "externalReferences": [
163683            {
163684              "url": "qix-/node-error-ex",
163685              "type": "distribution"
163686            }
163687          ],
163688          "evidence": {},
163689          "signature": {
163690            "signature": {
163691              "publicKey": {}
163692            }
163693          },
163694          "modelCard": {
163695            "modelParameters": {
163696              "approach": {}
163697            },
163698            "quantitativeAnalysis": {
163699              "graphics": {}
163700            },
163701            "considerations": {}
163702          }
163703        },
163704        {
163705          "type": "library",
163706          "bom-ref": "pkg:npm/escape-html@1.0.3?package-id=29b06dd1d0ba635a",
163707          "supplier": {},
163708          "name": "escape-html",
163709          "version": "1.0.3",
163710          "description": "Escape string for use in HTML",
163711          "licenses": [
163712            {
163713              "license": {
163714                "id": "MIT"
163715              }
163716            }
163717          ],
163718          "cpe": "cpe:2.3:a:escape-html:escape-html:1.0.3:*:*:*:*:*:*:*",
163719          "purl": "pkg:npm/escape-html@1.0.3",
163720          "swid": {
163721            "attachment": {}
163722          },
163723          "pedigree": {},
163724          "externalReferences": [
163725            {
163726              "url": "component/escape-html",
163727              "type": "distribution"
163728            }
163729          ],
163730          "evidence": {},
163731          "signature": {
163732            "signature": {
163733              "publicKey": {}
163734            }
163735          },
163736          "modelCard": {
163737            "modelParameters": {
163738              "approach": {}
163739            },
163740            "quantitativeAnalysis": {
163741              "graphics": {}
163742            },
163743            "considerations": {}
163744          }
163745        },
163746        {
163747          "type": "library",
163748          "bom-ref": "pkg:npm/escape-string-regexp@1.0.5?package-id=25bd30cd97ed1bdf",
163749          "supplier": {},
163750          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
163751          "name": "escape-string-regexp",
163752          "version": "1.0.5",
163753          "description": "Escape RegExp special characters",
163754          "licenses": [
163755            {
163756              "license": {
163757                "id": "MIT"
163758              }
163759            }
163760          ],
163761          "cpe": "cpe:2.3:a:escape-string-regexp:escape-string-regexp:1.0.5:*:*:*:*:*:*:*",
163762          "purl": "pkg:npm/escape-string-regexp@1.0.5",
163763          "swid": {
163764            "attachment": {}
163765          },
163766          "pedigree": {},
163767          "externalReferences": [
163768            {
163769              "url": "sindresorhus/escape-string-regexp",
163770              "type": "distribution"
163771            }
163772          ],
163773          "evidence": {},
163774          "signature": {
163775            "signature": {
163776              "publicKey": {}
163777            }
163778          },
163779          "modelCard": {
163780            "modelParameters": {
163781              "approach": {}
163782            },
163783            "quantitativeAnalysis": {
163784              "graphics": {}
163785            },
163786            "considerations": {}
163787          }
163788        },
163789        {
163790          "type": "library",
163791          "bom-ref": "pkg:npm/etag@1.8.1?package-id=9151d174424b86ef",
163792          "supplier": {},
163793          "name": "etag",
163794          "version": "1.8.1",
163795          "description": "Create simple HTTP ETags",
163796          "licenses": [
163797            {
163798              "license": {
163799                "id": "MIT"
163800              }
163801            }
163802          ],
163803          "cpe": "cpe:2.3:a:etag:etag:1.8.1:*:*:*:*:*:*:*",
163804          "purl": "pkg:npm/etag@1.8.1",
163805          "swid": {
163806            "attachment": {}
163807          },
163808          "pedigree": {},
163809          "externalReferences": [
163810            {
163811              "url": "jshttp/etag",
163812              "type": "distribution"
163813            }
163814          ],
163815          "evidence": {},
163816          "signature": {
163817            "signature": {
163818              "publicKey": {}
163819            }
163820          },
163821          "modelCard": {
163822            "modelParameters": {
163823              "approach": {}
163824            },
163825            "quantitativeAnalysis": {
163826              "graphics": {}
163827            },
163828            "considerations": {}
163829          }
163830        },
163831        {
163832          "type": "library",
163833          "bom-ref": "pkg:npm/express@4.17.1?package-id=8df8a39c19cb2192",
163834          "supplier": {},
163835          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
163836          "name": "express",
163837          "version": "4.17.1",
163838          "description": "Fast, unopinionated, minimalist web framework",
163839          "licenses": [
163840            {
163841              "license": {
163842                "id": "MIT"
163843              }
163844            }
163845          ],
163846          "cpe": "cpe:2.3:a:express:express:4.17.1:*:*:*:*:*:*:*",
163847          "purl": "pkg:npm/express@4.17.1",
163848          "swid": {
163849            "attachment": {}
163850          },
163851          "pedigree": {},
163852          "externalReferences": [
163853            {
163854              "url": "expressjs/express",
163855              "type": "distribution"
163856            },
163857            {
163858              "url": "http://expressjs.com/",
163859              "type": "website"
163860            }
163861          ],
163862          "evidence": {},
163863          "signature": {
163864            "signature": {
163865              "publicKey": {}
163866            }
163867          },
163868          "modelCard": {
163869            "modelParameters": {
163870              "approach": {}
163871            },
163872            "quantitativeAnalysis": {
163873              "graphics": {}
163874            },
163875            "considerations": {}
163876          }
163877        },
163878        {
163879          "type": "library",
163880          "bom-ref": "pkg:npm/extend@3.0.2?package-id=ac3f1ce155e9acb0",
163881          "supplier": {},
163882          "author": "Stefan Thomas \u003cjustmoon@members.fsf.org\u003e (http://www.justmoon.net)",
163883          "name": "extend",
163884          "version": "3.0.2",
163885          "description": "Port of jQuery.extend for node.js and the browser",
163886          "licenses": [
163887            {
163888              "license": {
163889                "id": "MIT"
163890              }
163891            }
163892          ],
163893          "cpe": "cpe:2.3:a:justmoon:extend:3.0.2:*:*:*:*:*:*:*",
163894          "purl": "pkg:npm/extend@3.0.2",
163895          "swid": {
163896            "attachment": {}
163897          },
163898          "pedigree": {},
163899          "externalReferences": [
163900            {
163901              "url": "https://github.com/justmoon/node-extend.git",
163902              "type": "distribution"
163903            }
163904          ],
163905          "evidence": {},
163906          "signature": {
163907            "signature": {
163908              "publicKey": {}
163909            }
163910          },
163911          "modelCard": {
163912            "modelParameters": {
163913              "approach": {}
163914            },
163915            "quantitativeAnalysis": {
163916              "graphics": {}
163917            },
163918            "considerations": {}
163919          }
163920        },
163921        {
163922          "type": "library",
163923          "bom-ref": "pkg:npm/extsprintf@1.3.0?package-id=e1ddb770c979f4c3",
163924          "supplier": {},
163925          "name": "extsprintf",
163926          "version": "1.3.0",
163927          "description": "extended POSIX-style sprintf",
163928          "licenses": [
163929            {
163930              "license": {
163931                "id": "MIT"
163932              }
163933            }
163934          ],
163935          "cpe": "cpe:2.3:a:davepacheco:extsprintf:1.3.0:*:*:*:*:*:*:*",
163936          "purl": "pkg:npm/extsprintf@1.3.0",
163937          "swid": {
163938            "attachment": {}
163939          },
163940          "pedigree": {},
163941          "externalReferences": [
163942            {
163943              "url": "git://github.com/davepacheco/node-extsprintf.git",
163944              "type": "distribution"
163945            }
163946          ],
163947          "evidence": {},
163948          "signature": {
163949            "signature": {
163950              "publicKey": {}
163951            }
163952          },
163953          "modelCard": {
163954            "modelParameters": {
163955              "approach": {}
163956            },
163957            "quantitativeAnalysis": {
163958              "graphics": {}
163959            },
163960            "considerations": {}
163961          }
163962        },
163963        {
163964          "type": "library",
163965          "bom-ref": "pkg:npm/fast-deep-equal@3.1.3?package-id=8b9d45ccd3ca33c0",
163966          "supplier": {},
163967          "author": "Evgeny Poberezkin",
163968          "name": "fast-deep-equal",
163969          "version": "3.1.3",
163970          "description": "Fast deep equal",
163971          "licenses": [
163972            {
163973              "license": {
163974                "id": "MIT"
163975              }
163976            }
163977          ],
163978          "cpe": "cpe:2.3:a:fast-deep-equal:fast-deep-equal:3.1.3:*:*:*:*:*:*:*",
163979          "purl": "pkg:npm/fast-deep-equal@3.1.3",
163980          "swid": {
163981            "attachment": {}
163982          },
163983          "pedigree": {},
163984          "externalReferences": [
163985            {
163986              "url": "git+https://github.com/epoberezkin/fast-deep-equal.git",
163987              "type": "distribution"
163988            },
163989            {
163990              "url": "https://github.com/epoberezkin/fast-deep-equal#readme",
163991              "type": "website"
163992            }
163993          ],
163994          "evidence": {},
163995          "signature": {
163996            "signature": {
163997              "publicKey": {}
163998            }
163999          },
164000          "modelCard": {
164001            "modelParameters": {
164002              "approach": {}
164003            },
164004            "quantitativeAnalysis": {
164005              "graphics": {}
164006            },
164007            "considerations": {}
164008          }
164009        },
164010        {
164011          "type": "library",
164012          "bom-ref": "pkg:npm/fast-json-stable-stringify@2.1.0?package-id=9e19806bed3935c1",
164013          "supplier": {},
164014          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
164015          "name": "fast-json-stable-stringify",
164016          "version": "2.1.0",
164017          "description": "deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify",
164018          "licenses": [
164019            {
164020              "license": {
164021                "id": "MIT"
164022              }
164023            }
164024          ],
164025          "cpe": "cpe:2.3:a:fast-json-stable-stringify:fast-json-stable-stringify:2.1.0:*:*:*:*:*:*:*",
164026          "purl": "pkg:npm/fast-json-stable-stringify@2.1.0",
164027          "swid": {
164028            "attachment": {}
164029          },
164030          "pedigree": {},
164031          "externalReferences": [
164032            {
164033              "url": "git://github.com/epoberezkin/fast-json-stable-stringify.git",
164034              "type": "distribution"
164035            },
164036            {
164037              "url": "https://github.com/epoberezkin/fast-json-stable-stringify",
164038              "type": "website"
164039            }
164040          ],
164041          "evidence": {},
164042          "signature": {
164043            "signature": {
164044              "publicKey": {}
164045            }
164046          },
164047          "modelCard": {
164048            "modelParameters": {
164049              "approach": {}
164050            },
164051            "quantitativeAnalysis": {
164052              "graphics": {}
164053            },
164054            "considerations": {}
164055          }
164056        },
164057        {
164058          "type": "library",
164059          "bom-ref": "pkg:npm/fastest-levenshtein@1.0.12?package-id=f703cf6832613e31",
164060          "supplier": {},
164061          "author": "Kasper U. Weihe",
164062          "name": "fastest-levenshtein",
164063          "version": "1.0.12",
164064          "description": "Fastest Levenshtein distance implementation in JS.",
164065          "licenses": [
164066            {
164067              "license": {
164068                "id": "MIT"
164069              }
164070            }
164071          ],
164072          "cpe": "cpe:2.3:a:fastest-levenshtein:fastest-levenshtein:1.0.12:*:*:*:*:*:*:*",
164073          "purl": "pkg:npm/fastest-levenshtein@1.0.12",
164074          "swid": {
164075            "attachment": {}
164076          },
164077          "pedigree": {},
164078          "externalReferences": [
164079            {
164080              "url": "git+https://github.com/ka-weihe/fastest-levenshtein.git",
164081              "type": "distribution"
164082            },
164083            {
164084              "url": "https://github.com/ka-weihe/fastest-levenshtein#README",
164085              "type": "website"
164086            }
164087          ],
164088          "evidence": {},
164089          "signature": {
164090            "signature": {
164091              "publicKey": {}
164092            }
164093          },
164094          "modelCard": {
164095            "modelParameters": {
164096              "approach": {}
164097            },
164098            "quantitativeAnalysis": {
164099              "graphics": {}
164100            },
164101            "considerations": {}
164102          }
164103        },
164104        {
164105          "type": "library",
164106          "bom-ref": "pkg:npm/finalhandler@1.1.2?package-id=7ddac0b926b41ecd",
164107          "supplier": {},
164108          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
164109          "name": "finalhandler",
164110          "version": "1.1.2",
164111          "description": "Node.js final http responder",
164112          "licenses": [
164113            {
164114              "license": {
164115                "id": "MIT"
164116              }
164117            }
164118          ],
164119          "cpe": "cpe:2.3:a:finalhandler:finalhandler:1.1.2:*:*:*:*:*:*:*",
164120          "purl": "pkg:npm/finalhandler@1.1.2",
164121          "swid": {
164122            "attachment": {}
164123          },
164124          "pedigree": {},
164125          "externalReferences": [
164126            {
164127              "url": "pillarjs/finalhandler",
164128              "type": "distribution"
164129            }
164130          ],
164131          "evidence": {},
164132          "signature": {
164133            "signature": {
164134              "publicKey": {}
164135            }
164136          },
164137          "modelCard": {
164138            "modelParameters": {
164139              "approach": {}
164140            },
164141            "quantitativeAnalysis": {
164142              "graphics": {}
164143            },
164144            "considerations": {}
164145          }
164146        },
164147        {
164148          "type": "library",
164149          "bom-ref": "pkg:npm/find-parent-dir@0.3.0?package-id=5530a908a83772cf",
164150          "supplier": {},
164151          "author": "Thorsten Lorenz \u003cthlorenz@gmx.de\u003e (http://thlorenz.com)",
164152          "name": "find-parent-dir",
164153          "version": "0.3.0",
164154          "description": "Finds the first parent directory that contains a given file or directory.",
164155          "licenses": [
164156            {
164157              "license": {
164158                "id": "MIT"
164159              }
164160            }
164161          ],
164162          "cpe": "cpe:2.3:a:find-parent-dir:find-parent-dir:0.3.0:*:*:*:*:*:*:*",
164163          "purl": "pkg:npm/find-parent-dir@0.3.0",
164164          "swid": {
164165            "attachment": {}
164166          },
164167          "pedigree": {},
164168          "externalReferences": [
164169            {
164170              "url": "git://github.com/thlorenz/find-parent-dir.git",
164171              "type": "distribution"
164172            },
164173            {
164174              "url": "https://github.com/thlorenz/find-parent-dir",
164175              "type": "website"
164176            }
164177          ],
164178          "evidence": {},
164179          "signature": {
164180            "signature": {
164181              "publicKey": {}
164182            }
164183          },
164184          "modelCard": {
164185            "modelParameters": {
164186              "approach": {}
164187            },
164188            "quantitativeAnalysis": {
164189              "graphics": {}
164190            },
164191            "considerations": {}
164192          }
164193        },
164194        {
164195          "type": "library",
164196          "bom-ref": "pkg:npm/find-up@3.0.0?package-id=b2c52ba40870e6f8",
164197          "supplier": {},
164198          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
164199          "name": "find-up",
164200          "version": "3.0.0",
164201          "description": "Find a file or directory by walking up parent directories",
164202          "licenses": [
164203            {
164204              "license": {
164205                "id": "MIT"
164206              }
164207            }
164208          ],
164209          "cpe": "cpe:2.3:a:find-up:find-up:3.0.0:*:*:*:*:*:*:*",
164210          "purl": "pkg:npm/find-up@3.0.0",
164211          "swid": {
164212            "attachment": {}
164213          },
164214          "pedigree": {},
164215          "externalReferences": [
164216            {
164217              "url": "sindresorhus/find-up",
164218              "type": "distribution"
164219            }
164220          ],
164221          "evidence": {},
164222          "signature": {
164223            "signature": {
164224              "publicKey": {}
164225            }
164226          },
164227          "modelCard": {
164228            "modelParameters": {
164229              "approach": {}
164230            },
164231            "quantitativeAnalysis": {
164232              "graphics": {}
164233            },
164234            "considerations": {}
164235          }
164236        },
164237        {
164238          "type": "library",
164239          "bom-ref": "pkg:npm/find-up@4.1.0?package-id=5375fdd0e5ee58cb",
164240          "supplier": {},
164241          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
164242          "name": "find-up",
164243          "version": "4.1.0",
164244          "description": "Find a file or directory by walking up parent directories",
164245          "licenses": [
164246            {
164247              "license": {
164248                "id": "MIT"
164249              }
164250            }
164251          ],
164252          "cpe": "cpe:2.3:a:find-up:find-up:4.1.0:*:*:*:*:*:*:*",
164253          "purl": "pkg:npm/find-up@4.1.0",
164254          "swid": {
164255            "attachment": {}
164256          },
164257          "pedigree": {},
164258          "externalReferences": [
164259            {
164260              "url": "sindresorhus/find-up",
164261              "type": "distribution"
164262            }
164263          ],
164264          "evidence": {},
164265          "signature": {
164266            "signature": {
164267              "publicKey": {}
164268            }
164269          },
164270          "modelCard": {
164271            "modelParameters": {
164272              "approach": {}
164273            },
164274            "quantitativeAnalysis": {
164275              "graphics": {}
164276            },
164277            "considerations": {}
164278          }
164279        },
164280        {
164281          "type": "library",
164282          "bom-ref": "pkg:npm/forever-agent@0.6.1?package-id=987c799490a62745",
164283          "supplier": {},
164284          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
164285          "name": "forever-agent",
164286          "version": "0.6.1",
164287          "description": "HTTP Agent that keeps socket connections alive between keep-alive requests. Formerly part of mikeal/request, now a standalone module.",
164288          "licenses": [
164289            {
164290              "license": {
164291                "id": "Apache-2.0"
164292              }
164293            }
164294          ],
164295          "cpe": "cpe:2.3:a:forever-agent:forever-agent:0.6.1:*:*:*:*:*:*:*",
164296          "purl": "pkg:npm/forever-agent@0.6.1",
164297          "swid": {
164298            "attachment": {}
164299          },
164300          "pedigree": {},
164301          "externalReferences": [
164302            {
164303              "url": "https://github.com/mikeal/forever-agent",
164304              "type": "distribution"
164305            }
164306          ],
164307          "evidence": {},
164308          "signature": {
164309            "signature": {
164310              "publicKey": {}
164311            }
164312          },
164313          "modelCard": {
164314            "modelParameters": {
164315              "approach": {}
164316            },
164317            "quantitativeAnalysis": {
164318              "graphics": {}
164319            },
164320            "considerations": {}
164321          }
164322        },
164323        {
164324          "type": "library",
164325          "bom-ref": "pkg:npm/form-data@2.3.3?package-id=901e4c8507a70298",
164326          "supplier": {},
164327          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
164328          "name": "form-data",
164329          "version": "2.3.3",
164330          "description": "A library to create readable \"multipart/form-data\" streams. Can be used to submit forms and file uploads to other web applications.",
164331          "licenses": [
164332            {
164333              "license": {
164334                "id": "MIT"
164335              }
164336            }
164337          ],
164338          "cpe": "cpe:2.3:a:form-data:form-data:2.3.3:*:*:*:*:*:*:*",
164339          "purl": "pkg:npm/form-data@2.3.3",
164340          "swid": {
164341            "attachment": {}
164342          },
164343          "pedigree": {},
164344          "externalReferences": [
164345            {
164346              "url": "git://github.com/form-data/form-data.git",
164347              "type": "distribution"
164348            }
164349          ],
164350          "evidence": {},
164351          "signature": {
164352            "signature": {
164353              "publicKey": {}
164354            }
164355          },
164356          "modelCard": {
164357            "modelParameters": {
164358              "approach": {}
164359            },
164360            "quantitativeAnalysis": {
164361              "graphics": {}
164362            },
164363            "considerations": {}
164364          }
164365        },
164366        {
164367          "type": "library",
164368          "bom-ref": "pkg:npm/forwarded@0.1.2?package-id=d96391915b25acbf",
164369          "supplier": {},
164370          "name": "forwarded",
164371          "version": "0.1.2",
164372          "description": "Parse HTTP X-Forwarded-For header",
164373          "licenses": [
164374            {
164375              "license": {
164376                "id": "MIT"
164377              }
164378            }
164379          ],
164380          "cpe": "cpe:2.3:a:forwarded:forwarded:0.1.2:*:*:*:*:*:*:*",
164381          "purl": "pkg:npm/forwarded@0.1.2",
164382          "swid": {
164383            "attachment": {}
164384          },
164385          "pedigree": {},
164386          "externalReferences": [
164387            {
164388              "url": "jshttp/forwarded",
164389              "type": "distribution"
164390            }
164391          ],
164392          "evidence": {},
164393          "signature": {
164394            "signature": {
164395              "publicKey": {}
164396            }
164397          },
164398          "modelCard": {
164399            "modelParameters": {
164400              "approach": {}
164401            },
164402            "quantitativeAnalysis": {
164403              "graphics": {}
164404            },
164405            "considerations": {}
164406          }
164407        },
164408        {
164409          "type": "library",
164410          "bom-ref": "pkg:npm/fresh@0.5.2?package-id=7080d1485688188f",
164411          "supplier": {},
164412          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
164413          "name": "fresh",
164414          "version": "0.5.2",
164415          "description": "HTTP response freshness testing",
164416          "licenses": [
164417            {
164418              "license": {
164419                "id": "MIT"
164420              }
164421            }
164422          ],
164423          "cpe": "cpe:2.3:a:fresh:fresh:0.5.2:*:*:*:*:*:*:*",
164424          "purl": "pkg:npm/fresh@0.5.2",
164425          "swid": {
164426            "attachment": {}
164427          },
164428          "pedigree": {},
164429          "externalReferences": [
164430            {
164431              "url": "jshttp/fresh",
164432              "type": "distribution"
164433            }
164434          ],
164435          "evidence": {},
164436          "signature": {
164437            "signature": {
164438              "publicKey": {}
164439            }
164440          },
164441          "modelCard": {
164442            "modelParameters": {
164443              "approach": {}
164444            },
164445            "quantitativeAnalysis": {
164446              "graphics": {}
164447            },
164448            "considerations": {}
164449          }
164450        },
164451        {
164452          "type": "library",
164453          "bom-ref": "pkg:npm/fs-extra@8.0.1?package-id=867e78ed80c61e36",
164454          "supplier": {},
164455          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
164456          "name": "fs-extra",
164457          "version": "8.0.1",
164458          "description": "fs-extra contains methods that aren't included in the vanilla Node.js fs package. Such as mkdir -p, cp -r, and rm -rf.",
164459          "licenses": [
164460            {
164461              "license": {
164462                "id": "MIT"
164463              }
164464            }
164465          ],
164466          "cpe": "cpe:2.3:a:jprichardson:fs-extra:8.0.1:*:*:*:*:*:*:*",
164467          "purl": "pkg:npm/fs-extra@8.0.1",
164468          "swid": {
164469            "attachment": {}
164470          },
164471          "pedigree": {},
164472          "externalReferences": [
164473            {
164474              "url": "https://github.com/jprichardson/node-fs-extra",
164475              "type": "distribution"
164476            },
164477            {
164478              "url": "https://github.com/jprichardson/node-fs-extra",
164479              "type": "website"
164480            }
164481          ],
164482          "evidence": {},
164483          "signature": {
164484            "signature": {
164485              "publicKey": {}
164486            }
164487          },
164488          "modelCard": {
164489            "modelParameters": {
164490              "approach": {}
164491            },
164492            "quantitativeAnalysis": {
164493              "graphics": {}
164494            },
164495            "considerations": {}
164496          }
164497        },
164498        {
164499          "type": "library",
164500          "bom-ref": "pkg:npm/fs-minipass@2.1.0?package-id=398fbbb28fb7e1f4",
164501          "supplier": {},
164502          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
164503          "name": "fs-minipass",
164504          "version": "2.1.0",
164505          "description": "fs read and write streams based on minipass",
164506          "licenses": [
164507            {
164508              "license": {
164509                "id": "ISC"
164510              }
164511            }
164512          ],
164513          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:2.1.0:*:*:*:*:*:*:*",
164514          "purl": "pkg:npm/fs-minipass@2.1.0",
164515          "swid": {
164516            "attachment": {}
164517          },
164518          "pedigree": {},
164519          "externalReferences": [
164520            {
164521              "url": "git+https://github.com/npm/fs-minipass.git",
164522              "type": "distribution"
164523            },
164524            {
164525              "url": "https://github.com/npm/fs-minipass#readme",
164526              "type": "website"
164527            }
164528          ],
164529          "evidence": {},
164530          "signature": {
164531            "signature": {
164532              "publicKey": {}
164533            }
164534          },
164535          "modelCard": {
164536            "modelParameters": {
164537              "approach": {}
164538            },
164539            "quantitativeAnalysis": {
164540              "graphics": {}
164541            },
164542            "considerations": {}
164543          }
164544        },
164545        {
164546          "type": "library",
164547          "bom-ref": "pkg:npm/fs-minipass@2.1.0?package-id=f1b7ae0257cf54f0",
164548          "supplier": {},
164549          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
164550          "name": "fs-minipass",
164551          "version": "2.1.0",
164552          "description": "fs read and write streams based on minipass",
164553          "licenses": [
164554            {
164555              "license": {
164556                "id": "ISC"
164557              }
164558            }
164559          ],
164560          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:2.1.0:*:*:*:*:*:*:*",
164561          "purl": "pkg:npm/fs-minipass@2.1.0",
164562          "swid": {
164563            "attachment": {}
164564          },
164565          "pedigree": {},
164566          "externalReferences": [
164567            {
164568              "url": "git+https://github.com/npm/fs-minipass.git",
164569              "type": "distribution"
164570            },
164571            {
164572              "url": "https://github.com/npm/fs-minipass#readme",
164573              "type": "website"
164574            }
164575          ],
164576          "evidence": {},
164577          "signature": {
164578            "signature": {
164579              "publicKey": {}
164580            }
164581          },
164582          "modelCard": {
164583            "modelParameters": {
164584              "approach": {}
164585            },
164586            "quantitativeAnalysis": {
164587              "graphics": {}
164588            },
164589            "considerations": {}
164590          }
164591        },
164592        {
164593          "type": "library",
164594          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=21800424481533b1",
164595          "supplier": {},
164596          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
164597          "name": "fs.realpath",
164598          "version": "1.0.0",
164599          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
164600          "licenses": [
164601            {
164602              "license": {
164603                "id": "ISC"
164604              }
164605            }
164606          ],
164607          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
164608          "purl": "pkg:npm/fs.realpath@1.0.0",
164609          "swid": {
164610            "attachment": {}
164611          },
164612          "pedigree": {},
164613          "externalReferences": [
164614            {
164615              "url": "git+https://github.com/isaacs/fs.realpath.git",
164616              "type": "distribution"
164617            }
164618          ],
164619          "evidence": {},
164620          "signature": {
164621            "signature": {
164622              "publicKey": {}
164623            }
164624          },
164625          "modelCard": {
164626            "modelParameters": {
164627              "approach": {}
164628            },
164629            "quantitativeAnalysis": {
164630              "graphics": {}
164631            },
164632            "considerations": {}
164633          }
164634        },
164635        {
164636          "type": "library",
164637          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=65729748c227165e",
164638          "supplier": {},
164639          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
164640          "name": "fs.realpath",
164641          "version": "1.0.0",
164642          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
164643          "licenses": [
164644            {
164645              "license": {
164646                "id": "ISC"
164647              }
164648            }
164649          ],
164650          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
164651          "purl": "pkg:npm/fs.realpath@1.0.0",
164652          "swid": {
164653            "attachment": {}
164654          },
164655          "pedigree": {},
164656          "externalReferences": [
164657            {
164658              "url": "git+https://github.com/isaacs/fs.realpath.git",
164659              "type": "distribution"
164660            }
164661          ],
164662          "evidence": {},
164663          "signature": {
164664            "signature": {
164665              "publicKey": {}
164666            }
164667          },
164668          "modelCard": {
164669            "modelParameters": {
164670              "approach": {}
164671            },
164672            "quantitativeAnalysis": {
164673              "graphics": {}
164674            },
164675            "considerations": {}
164676          }
164677        },
164678        {
164679          "type": "library",
164680          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=44648bf09db15f6c",
164681          "supplier": {},
164682          "author": "Raynos \u003craynos2@gmail.com\u003e",
164683          "name": "function-bind",
164684          "version": "1.1.1",
164685          "description": "Implementation of Function.prototype.bind",
164686          "licenses": [
164687            {
164688              "license": {
164689                "id": "MIT"
164690              }
164691            }
164692          ],
164693          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
164694          "purl": "pkg:npm/function-bind@1.1.1",
164695          "swid": {
164696            "attachment": {}
164697          },
164698          "pedigree": {},
164699          "externalReferences": [
164700            {
164701              "url": "git://github.com/Raynos/function-bind.git",
164702              "type": "distribution"
164703            },
164704            {
164705              "url": "https://github.com/Raynos/function-bind",
164706              "type": "website"
164707            }
164708          ],
164709          "evidence": {},
164710          "signature": {
164711            "signature": {
164712              "publicKey": {}
164713            }
164714          },
164715          "modelCard": {
164716            "modelParameters": {
164717              "approach": {}
164718            },
164719            "quantitativeAnalysis": {
164720              "graphics": {}
164721            },
164722            "considerations": {}
164723          }
164724        },
164725        {
164726          "type": "library",
164727          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=7bd79c8f88820292",
164728          "supplier": {},
164729          "author": "Raynos \u003craynos2@gmail.com\u003e",
164730          "name": "function-bind",
164731          "version": "1.1.1",
164732          "description": "Implementation of Function.prototype.bind",
164733          "licenses": [
164734            {
164735              "license": {
164736                "id": "MIT"
164737              }
164738            }
164739          ],
164740          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
164741          "purl": "pkg:npm/function-bind@1.1.1",
164742          "swid": {
164743            "attachment": {}
164744          },
164745          "pedigree": {},
164746          "externalReferences": [
164747            {
164748              "url": "git://github.com/Raynos/function-bind.git",
164749              "type": "distribution"
164750            },
164751            {
164752              "url": "https://github.com/Raynos/function-bind",
164753              "type": "website"
164754            }
164755          ],
164756          "evidence": {},
164757          "signature": {
164758            "signature": {
164759              "publicKey": {}
164760            }
164761          },
164762          "modelCard": {
164763            "modelParameters": {
164764              "approach": {}
164765            },
164766            "quantitativeAnalysis": {
164767              "graphics": {}
164768            },
164769            "considerations": {}
164770          }
164771        },
164772        {
164773          "type": "library",
164774          "bom-ref": "pkg:npm/gauge@2.7.4?package-id=e3560fb3e9d7712d",
164775          "supplier": {},
164776          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
164777          "name": "gauge",
164778          "version": "2.7.4",
164779          "description": "A terminal based horizontal guage",
164780          "licenses": [
164781            {
164782              "license": {
164783                "id": "ISC"
164784              }
164785            }
164786          ],
164787          "cpe": "cpe:2.3:a:gauge:gauge:2.7.4:*:*:*:*:*:*:*",
164788          "purl": "pkg:npm/gauge@2.7.4",
164789          "swid": {
164790            "attachment": {}
164791          },
164792          "pedigree": {},
164793          "externalReferences": [
164794            {
164795              "url": "https://github.com/iarna/gauge",
164796              "type": "distribution"
164797            },
164798            {
164799              "url": "https://github.com/iarna/gauge",
164800              "type": "website"
164801            }
164802          ],
164803          "evidence": {},
164804          "signature": {
164805            "signature": {
164806              "publicKey": {}
164807            }
164808          },
164809          "modelCard": {
164810            "modelParameters": {
164811              "approach": {}
164812            },
164813            "quantitativeAnalysis": {
164814              "graphics": {}
164815            },
164816            "considerations": {}
164817          }
164818        },
164819        {
164820          "type": "library",
164821          "bom-ref": "pkg:npm/gauge@4.0.4?package-id=fc4632a6e143d550",
164822          "supplier": {},
164823          "author": "GitHub Inc.",
164824          "name": "gauge",
164825          "version": "4.0.4",
164826          "description": "A terminal based horizontal gauge",
164827          "licenses": [
164828            {
164829              "license": {
164830                "id": "ISC"
164831              }
164832            }
164833          ],
164834          "cpe": "cpe:2.3:a:gauge:gauge:4.0.4:*:*:*:*:*:*:*",
164835          "purl": "pkg:npm/gauge@4.0.4",
164836          "swid": {
164837            "attachment": {}
164838          },
164839          "pedigree": {},
164840          "externalReferences": [
164841            {
164842              "url": "https://github.com/npm/gauge.git",
164843              "type": "distribution"
164844            },
164845            {
164846              "url": "https://github.com/npm/gauge",
164847              "type": "website"
164848            }
164849          ],
164850          "evidence": {},
164851          "signature": {
164852            "signature": {
164853              "publicKey": {}
164854            }
164855          },
164856          "modelCard": {
164857            "modelParameters": {
164858              "approach": {}
164859            },
164860            "quantitativeAnalysis": {
164861              "graphics": {}
164862            },
164863            "considerations": {}
164864          }
164865        },
164866        {
164867          "type": "library",
164868          "bom-ref": "pkg:npm/gaze@1.1.3?package-id=37239de1e454afe5",
164869          "supplier": {},
164870          "author": "Kyle Robinson Young \u003ckyle@dontkry.com\u003e",
164871          "name": "gaze",
164872          "version": "1.1.3",
164873          "description": "A globbing fs.watch wrapper built from the best parts of other fine watch libs.",
164874          "licenses": [
164875            {
164876              "license": {
164877                "id": "MIT"
164878              }
164879            }
164880          ],
164881          "cpe": "cpe:2.3:a:shama:gaze:1.1.3:*:*:*:*:*:*:*",
164882          "purl": "pkg:npm/gaze@1.1.3",
164883          "swid": {
164884            "attachment": {}
164885          },
164886          "pedigree": {},
164887          "externalReferences": [
164888            {
164889              "url": "https://github.com/shama/gaze.git",
164890              "type": "distribution"
164891            },
164892            {
164893              "url": "https://github.com/shama/gaze",
164894              "type": "website"
164895            }
164896          ],
164897          "evidence": {},
164898          "signature": {
164899            "signature": {
164900              "publicKey": {}
164901            }
164902          },
164903          "modelCard": {
164904            "modelParameters": {
164905              "approach": {}
164906            },
164907            "quantitativeAnalysis": {
164908              "graphics": {}
164909            },
164910            "considerations": {}
164911          }
164912        },
164913        {
164914          "type": "library",
164915          "bom-ref": "pkg:npm/get-caller-file@2.0.5?package-id=4b23483947ffc7ae",
164916          "supplier": {},
164917          "author": "Stefan Penner",
164918          "name": "get-caller-file",
164919          "version": "2.0.5",
164920          "licenses": [
164921            {
164922              "license": {
164923                "id": "ISC"
164924              }
164925            }
164926          ],
164927          "cpe": "cpe:2.3:a:get-caller-file:get-caller-file:2.0.5:*:*:*:*:*:*:*",
164928          "purl": "pkg:npm/get-caller-file@2.0.5",
164929          "swid": {
164930            "attachment": {}
164931          },
164932          "pedigree": {},
164933          "externalReferences": [
164934            {
164935              "url": "git+https://github.com/stefanpenner/get-caller-file.git",
164936              "type": "distribution"
164937            },
164938            {
164939              "url": "https://github.com/stefanpenner/get-caller-file#readme",
164940              "type": "website"
164941            }
164942          ],
164943          "evidence": {},
164944          "signature": {
164945            "signature": {
164946              "publicKey": {}
164947            }
164948          },
164949          "modelCard": {
164950            "modelParameters": {
164951              "approach": {}
164952            },
164953            "quantitativeAnalysis": {
164954              "graphics": {}
164955            },
164956            "considerations": {}
164957          }
164958        },
164959        {
164960          "type": "library",
164961          "bom-ref": "pkg:npm/get-stdin@4.0.1?package-id=9fd981ecaeefe3b7",
164962          "supplier": {},
164963          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (http://sindresorhus.com)",
164964          "name": "get-stdin",
164965          "version": "4.0.1",
164966          "description": "Easier stdin",
164967          "licenses": [
164968            {
164969              "license": {
164970                "id": "MIT"
164971              }
164972            }
164973          ],
164974          "cpe": "cpe:2.3:a:get-stdin:get-stdin:4.0.1:*:*:*:*:*:*:*",
164975          "purl": "pkg:npm/get-stdin@4.0.1",
164976          "swid": {
164977            "attachment": {}
164978          },
164979          "pedigree": {},
164980          "externalReferences": [
164981            {
164982              "url": "sindresorhus/get-stdin",
164983              "type": "distribution"
164984            }
164985          ],
164986          "evidence": {},
164987          "signature": {
164988            "signature": {
164989              "publicKey": {}
164990            }
164991          },
164992          "modelCard": {
164993            "modelParameters": {
164994              "approach": {}
164995            },
164996            "quantitativeAnalysis": {
164997              "graphics": {}
164998            },
164999            "considerations": {}
165000          }
165001        },
165002        {
165003          "type": "library",
165004          "bom-ref": "pkg:npm/getpass@0.1.7?package-id=75c291a71588a422",
165005          "supplier": {},
165006          "author": "Alex Wilson \u003calex.wilson@joyent.com\u003e",
165007          "name": "getpass",
165008          "version": "0.1.7",
165009          "description": "getpass for node.js",
165010          "licenses": [
165011            {
165012              "license": {
165013                "id": "MIT"
165014              }
165015            }
165016          ],
165017          "cpe": "cpe:2.3:a:arekinath:getpass:0.1.7:*:*:*:*:*:*:*",
165018          "purl": "pkg:npm/getpass@0.1.7",
165019          "swid": {
165020            "attachment": {}
165021          },
165022          "pedigree": {},
165023          "externalReferences": [
165024            {
165025              "url": "https://github.com/arekinath/node-getpass.git",
165026              "type": "distribution"
165027            }
165028          ],
165029          "evidence": {},
165030          "signature": {
165031            "signature": {
165032              "publicKey": {}
165033            }
165034          },
165035          "modelCard": {
165036            "modelParameters": {
165037              "approach": {}
165038            },
165039            "quantitativeAnalysis": {
165040              "graphics": {}
165041            },
165042            "considerations": {}
165043          }
165044        },
165045        {
165046          "type": "library",
165047          "bom-ref": "pkg:npm/glob@7.1.7?package-id=2469a5ca066ad1d7",
165048          "supplier": {},
165049          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
165050          "name": "glob",
165051          "version": "7.1.7",
165052          "description": "a little globber",
165053          "licenses": [
165054            {
165055              "license": {
165056                "id": "ISC"
165057              }
165058            }
165059          ],
165060          "cpe": "cpe:2.3:a:isaacs:glob:7.1.7:*:*:*:*:*:*:*",
165061          "purl": "pkg:npm/glob@7.1.7",
165062          "swid": {
165063            "attachment": {}
165064          },
165065          "pedigree": {},
165066          "externalReferences": [
165067            {
165068              "url": "git://github.com/isaacs/node-glob.git",
165069              "type": "distribution"
165070            }
165071          ],
165072          "evidence": {},
165073          "signature": {
165074            "signature": {
165075              "publicKey": {}
165076            }
165077          },
165078          "modelCard": {
165079            "modelParameters": {
165080              "approach": {}
165081            },
165082            "quantitativeAnalysis": {
165083              "graphics": {}
165084            },
165085            "considerations": {}
165086          }
165087        },
165088        {
165089          "type": "library",
165090          "bom-ref": "pkg:npm/glob@7.2.3?package-id=b961e222f6e54786",
165091          "supplier": {},
165092          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
165093          "name": "glob",
165094          "version": "7.2.3",
165095          "description": "a little globber",
165096          "licenses": [
165097            {
165098              "license": {
165099                "id": "ISC"
165100              }
165101            }
165102          ],
165103          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
165104          "purl": "pkg:npm/glob@7.2.3",
165105          "swid": {
165106            "attachment": {}
165107          },
165108          "pedigree": {},
165109          "externalReferences": [
165110            {
165111              "url": "git://github.com/isaacs/node-glob.git",
165112              "type": "distribution"
165113            }
165114          ],
165115          "evidence": {},
165116          "signature": {
165117            "signature": {
165118              "publicKey": {}
165119            }
165120          },
165121          "modelCard": {
165122            "modelParameters": {
165123              "approach": {}
165124            },
165125            "quantitativeAnalysis": {
165126              "graphics": {}
165127            },
165128            "considerations": {}
165129          }
165130        },
165131        {
165132          "type": "library",
165133          "bom-ref": "pkg:npm/glob@7.2.3?package-id=37af2473a85a6fa0",
165134          "supplier": {},
165135          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
165136          "name": "glob",
165137          "version": "7.2.3",
165138          "description": "a little globber",
165139          "licenses": [
165140            {
165141              "license": {
165142                "id": "ISC"
165143              }
165144            }
165145          ],
165146          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
165147          "purl": "pkg:npm/glob@7.2.3",
165148          "swid": {
165149            "attachment": {}
165150          },
165151          "pedigree": {},
165152          "externalReferences": [
165153            {
165154              "url": "git://github.com/isaacs/node-glob.git",
165155              "type": "distribution"
165156            }
165157          ],
165158          "evidence": {},
165159          "signature": {
165160            "signature": {
165161              "publicKey": {}
165162            }
165163          },
165164          "modelCard": {
165165            "modelParameters": {
165166              "approach": {}
165167            },
165168            "quantitativeAnalysis": {
165169              "graphics": {}
165170            },
165171            "considerations": {}
165172          }
165173        },
165174        {
165175          "type": "library",
165176          "bom-ref": "pkg:npm/glob@7.2.3?package-id=27f74d4e19b8aa02",
165177          "supplier": {},
165178          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
165179          "name": "glob",
165180          "version": "7.2.3",
165181          "description": "a little globber",
165182          "licenses": [
165183            {
165184              "license": {
165185                "id": "ISC"
165186              }
165187            }
165188          ],
165189          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
165190          "purl": "pkg:npm/glob@7.2.3",
165191          "swid": {
165192            "attachment": {}
165193          },
165194          "pedigree": {},
165195          "externalReferences": [
165196            {
165197              "url": "git://github.com/isaacs/node-glob.git",
165198              "type": "distribution"
165199            }
165200          ],
165201          "evidence": {},
165202          "signature": {
165203            "signature": {
165204              "publicKey": {}
165205            }
165206          },
165207          "modelCard": {
165208            "modelParameters": {
165209              "approach": {}
165210            },
165211            "quantitativeAnalysis": {
165212              "graphics": {}
165213            },
165214            "considerations": {}
165215          }
165216        },
165217        {
165218          "type": "library",
165219          "bom-ref": "pkg:npm/glob@8.0.3?package-id=f9282babaa70cabf",
165220          "supplier": {},
165221          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
165222          "name": "glob",
165223          "version": "8.0.3",
165224          "description": "a little globber",
165225          "licenses": [
165226            {
165227              "license": {
165228                "id": "ISC"
165229              }
165230            }
165231          ],
165232          "cpe": "cpe:2.3:a:isaacs:glob:8.0.3:*:*:*:*:*:*:*",
165233          "purl": "pkg:npm/glob@8.0.3",
165234          "swid": {
165235            "attachment": {}
165236          },
165237          "pedigree": {},
165238          "externalReferences": [
165239            {
165240              "url": "git://github.com/isaacs/node-glob.git",
165241              "type": "distribution"
165242            }
165243          ],
165244          "evidence": {},
165245          "signature": {
165246            "signature": {
165247              "publicKey": {}
165248            }
165249          },
165250          "modelCard": {
165251            "modelParameters": {
165252              "approach": {}
165253            },
165254            "quantitativeAnalysis": {
165255              "graphics": {}
165256            },
165257            "considerations": {}
165258          }
165259        },
165260        {
165261          "type": "library",
165262          "bom-ref": "pkg:npm/globule@1.3.4?package-id=ea81e98ac969d65d",
165263          "supplier": {},
165264          "author": "\"Cowboy\" Ben Alman (http://benalman.com/)",
165265          "name": "globule",
165266          "version": "1.3.4",
165267          "description": "An easy-to-use wildcard globbing library.",
165268          "licenses": [
165269            {
165270              "license": {
165271                "id": "MIT"
165272              }
165273            }
165274          ],
165275          "cpe": "cpe:2.3:a:globule:globule:1.3.4:*:*:*:*:*:*:*",
165276          "purl": "pkg:npm/globule@1.3.4",
165277          "swid": {
165278            "attachment": {}
165279          },
165280          "pedigree": {},
165281          "externalReferences": [
165282            {
165283              "url": "git://github.com/cowboy/node-globule.git",
165284              "type": "distribution"
165285            },
165286            {
165287              "url": "https://github.com/cowboy/node-globule",
165288              "type": "website"
165289            }
165290          ],
165291          "evidence": {},
165292          "signature": {
165293            "signature": {
165294              "publicKey": {}
165295            }
165296          },
165297          "modelCard": {
165298            "modelParameters": {
165299              "approach": {}
165300            },
165301            "quantitativeAnalysis": {
165302              "graphics": {}
165303            },
165304            "considerations": {}
165305          }
165306        },
165307        {
165308          "type": "library",
165309          "bom-ref": "pkg:npm/graceful-fs@4.2.10?package-id=9591c6b5bd9602cc",
165310          "supplier": {},
165311          "name": "graceful-fs",
165312          "version": "4.2.10",
165313          "description": "A drop-in replacement for fs, making various improvements.",
165314          "licenses": [
165315            {
165316              "license": {
165317                "id": "ISC"
165318              }
165319            }
165320          ],
165321          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.10:*:*:*:*:*:*:*",
165322          "purl": "pkg:npm/graceful-fs@4.2.10",
165323          "swid": {
165324            "attachment": {}
165325          },
165326          "pedigree": {},
165327          "externalReferences": [
165328            {
165329              "url": "https://github.com/isaacs/node-graceful-fs",
165330              "type": "distribution"
165331            }
165332          ],
165333          "evidence": {},
165334          "signature": {
165335            "signature": {
165336              "publicKey": {}
165337            }
165338          },
165339          "modelCard": {
165340            "modelParameters": {
165341              "approach": {}
165342            },
165343            "quantitativeAnalysis": {
165344              "graphics": {}
165345            },
165346            "considerations": {}
165347          }
165348        },
165349        {
165350          "type": "library",
165351          "bom-ref": "pkg:npm/graceful-fs@4.2.11?package-id=bef9b71aa253a928",
165352          "supplier": {},
165353          "name": "graceful-fs",
165354          "version": "4.2.11",
165355          "description": "A drop-in replacement for fs, making various improvements.",
165356          "licenses": [
165357            {
165358              "license": {
165359                "id": "ISC"
165360              }
165361            }
165362          ],
165363          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.11:*:*:*:*:*:*:*",
165364          "purl": "pkg:npm/graceful-fs@4.2.11",
165365          "swid": {
165366            "attachment": {}
165367          },
165368          "pedigree": {},
165369          "externalReferences": [
165370            {
165371              "url": "https://github.com/isaacs/node-graceful-fs",
165372              "type": "distribution"
165373            }
165374          ],
165375          "evidence": {},
165376          "signature": {
165377            "signature": {
165378              "publicKey": {}
165379            }
165380          },
165381          "modelCard": {
165382            "modelParameters": {
165383              "approach": {}
165384            },
165385            "quantitativeAnalysis": {
165386              "graphics": {}
165387            },
165388            "considerations": {}
165389          }
165390        },
165391        {
165392          "type": "library",
165393          "bom-ref": "pkg:npm/hammerjs@2.0.8?package-id=4beb41d0a101c05a",
165394          "supplier": {},
165395          "author": "Jorik Tangelder \u003cj.tangelder@gmail.com\u003e",
165396          "name": "hammerjs",
165397          "version": "2.0.8",
165398          "description": "A javascript library for multi-touch gestures",
165399          "licenses": [
165400            {
165401              "license": {
165402                "id": "MIT"
165403              }
165404            }
165405          ],
165406          "cpe": "cpe:2.3:a:hammerjs:hammerjs:2.0.8:*:*:*:*:*:*:*",
165407          "purl": "pkg:npm/hammerjs@2.0.8",
165408          "swid": {
165409            "attachment": {}
165410          },
165411          "pedigree": {},
165412          "externalReferences": [
165413            {
165414              "url": "git://github.com/hammerjs/hammer.js.git",
165415              "type": "distribution"
165416            },
165417            {
165418              "url": "http://hammerjs.github.io/",
165419              "type": "website"
165420            }
165421          ],
165422          "evidence": {},
165423          "signature": {
165424            "signature": {
165425              "publicKey": {}
165426            }
165427          },
165428          "modelCard": {
165429            "modelParameters": {
165430              "approach": {}
165431            },
165432            "quantitativeAnalysis": {
165433              "graphics": {}
165434            },
165435            "considerations": {}
165436          }
165437        },
165438        {
165439          "type": "library",
165440          "bom-ref": "pkg:npm/har-schema@2.0.0?package-id=4dcd539e47ce1819",
165441          "supplier": {},
165442          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
165443          "name": "har-schema",
165444          "version": "2.0.0",
165445          "description": "JSON Schema for HTTP Archive (HAR)",
165446          "licenses": [
165447            {
165448              "license": {
165449                "id": "ISC"
165450              }
165451            }
165452          ],
165453          "cpe": "cpe:2.3:a:ahmadnassri:har-schema:2.0.0:*:*:*:*:*:*:*",
165454          "purl": "pkg:npm/har-schema@2.0.0",
165455          "swid": {
165456            "attachment": {}
165457          },
165458          "pedigree": {},
165459          "externalReferences": [
165460            {
165461              "url": "https://github.com/ahmadnassri/har-schema.git",
165462              "type": "distribution"
165463            },
165464            {
165465              "url": "https://github.com/ahmadnassri/har-schema",
165466              "type": "website"
165467            }
165468          ],
165469          "evidence": {},
165470          "signature": {
165471            "signature": {
165472              "publicKey": {}
165473            }
165474          },
165475          "modelCard": {
165476            "modelParameters": {
165477              "approach": {}
165478            },
165479            "quantitativeAnalysis": {
165480              "graphics": {}
165481            },
165482            "considerations": {}
165483          }
165484        },
165485        {
165486          "type": "library",
165487          "bom-ref": "pkg:npm/har-validator@5.1.5?package-id=d992c94a0553947c",
165488          "supplier": {},
165489          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
165490          "name": "har-validator",
165491          "version": "5.1.5",
165492          "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
165493          "licenses": [
165494            {
165495              "license": {
165496                "id": "MIT"
165497              }
165498            }
165499          ],
165500          "cpe": "cpe:2.3:a:har-validator:har-validator:5.1.5:*:*:*:*:*:*:*",
165501          "purl": "pkg:npm/har-validator@5.1.5",
165502          "swid": {
165503            "attachment": {}
165504          },
165505          "pedigree": {},
165506          "externalReferences": [
165507            {
165508              "url": "https://github.com/ahmadnassri/node-har-validator.git",
165509              "type": "distribution"
165510            },
165511            {
165512              "url": "https://github.com/ahmadnassri/node-har-validator",
165513              "type": "website"
165514            }
165515          ],
165516          "evidence": {},
165517          "signature": {
165518            "signature": {
165519              "publicKey": {}
165520            }
165521          },
165522          "modelCard": {
165523            "modelParameters": {
165524              "approach": {}
165525            },
165526            "quantitativeAnalysis": {
165527              "graphics": {}
165528            },
165529            "considerations": {}
165530          }
165531        },
165532        {
165533          "type": "library",
165534          "bom-ref": "pkg:npm/hard-rejection@2.1.0?package-id=7dd0883a3751ad07",
165535          "supplier": {},
165536          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
165537          "name": "hard-rejection",
165538          "version": "2.1.0",
165539          "description": "Make unhandled promise rejections fail hard right away instead of the default silent fail",
165540          "licenses": [
165541            {
165542              "license": {
165543                "id": "MIT"
165544              }
165545            }
165546          ],
165547          "cpe": "cpe:2.3:a:hard-rejection:hard-rejection:2.1.0:*:*:*:*:*:*:*",
165548          "purl": "pkg:npm/hard-rejection@2.1.0",
165549          "swid": {
165550            "attachment": {}
165551          },
165552          "pedigree": {},
165553          "externalReferences": [
165554            {
165555              "url": "sindresorhus/hard-rejection",
165556              "type": "distribution"
165557            }
165558          ],
165559          "evidence": {},
165560          "signature": {
165561            "signature": {
165562              "publicKey": {}
165563            }
165564          },
165565          "modelCard": {
165566            "modelParameters": {
165567              "approach": {}
165568            },
165569            "quantitativeAnalysis": {
165570              "graphics": {}
165571            },
165572            "considerations": {}
165573          }
165574        },
165575        {
165576          "type": "library",
165577          "bom-ref": "pkg:npm/has@1.0.3?package-id=57072cf8ae347274",
165578          "supplier": {},
165579          "author": "Thiago de Arruda \u003ctpadilha84@gmail.com\u003e",
165580          "name": "has",
165581          "version": "1.0.3",
165582          "description": "Object.prototype.hasOwnProperty.call shortcut",
165583          "licenses": [
165584            {
165585              "license": {
165586                "id": "MIT"
165587              }
165588            }
165589          ],
165590          "cpe": "cpe:2.3:a:tarruda:has:1.0.3:*:*:*:*:*:*:*",
165591          "purl": "pkg:npm/has@1.0.3",
165592          "swid": {
165593            "attachment": {}
165594          },
165595          "pedigree": {},
165596          "externalReferences": [
165597            {
165598              "url": "git://github.com/tarruda/has.git",
165599              "type": "distribution"
165600            },
165601            {
165602              "url": "https://github.com/tarruda/has",
165603              "type": "website"
165604            }
165605          ],
165606          "evidence": {},
165607          "signature": {
165608            "signature": {
165609              "publicKey": {}
165610            }
165611          },
165612          "modelCard": {
165613            "modelParameters": {
165614              "approach": {}
165615            },
165616            "quantitativeAnalysis": {
165617              "graphics": {}
165618            },
165619            "considerations": {}
165620          }
165621        },
165622        {
165623          "type": "library",
165624          "bom-ref": "pkg:npm/has@1.0.3?package-id=63cdb16663093af0",
165625          "supplier": {},
165626          "author": "Thiago de Arruda \u003ctpadilha84@gmail.com\u003e",
165627          "name": "has",
165628          "version": "1.0.3",
165629          "description": "Object.prototype.hasOwnProperty.call shortcut",
165630          "licenses": [
165631            {
165632              "license": {
165633                "id": "MIT"
165634              }
165635            }
165636          ],
165637          "cpe": "cpe:2.3:a:tarruda:has:1.0.3:*:*:*:*:*:*:*",
165638          "purl": "pkg:npm/has@1.0.3",
165639          "swid": {
165640            "attachment": {}
165641          },
165642          "pedigree": {},
165643          "externalReferences": [
165644            {
165645              "url": "git://github.com/tarruda/has.git",
165646              "type": "distribution"
165647            },
165648            {
165649              "url": "https://github.com/tarruda/has",
165650              "type": "website"
165651            }
165652          ],
165653          "evidence": {},
165654          "signature": {
165655            "signature": {
165656              "publicKey": {}
165657            }
165658          },
165659          "modelCard": {
165660            "modelParameters": {
165661              "approach": {}
165662            },
165663            "quantitativeAnalysis": {
165664              "graphics": {}
165665            },
165666            "considerations": {}
165667          }
165668        },
165669        {
165670          "type": "library",
165671          "bom-ref": "pkg:npm/has-ansi@2.0.0?package-id=3a6add928c31a3bb",
165672          "supplier": {},
165673          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
165674          "name": "has-ansi",
165675          "version": "2.0.0",
165676          "description": "Check if a string has ANSI escape codes",
165677          "licenses": [
165678            {
165679              "license": {
165680                "id": "MIT"
165681              }
165682            }
165683          ],
165684          "cpe": "cpe:2.3:a:has-ansi:has-ansi:2.0.0:*:*:*:*:*:*:*",
165685          "purl": "pkg:npm/has-ansi@2.0.0",
165686          "swid": {
165687            "attachment": {}
165688          },
165689          "pedigree": {},
165690          "externalReferences": [
165691            {
165692              "url": "sindresorhus/has-ansi",
165693              "type": "distribution"
165694            }
165695          ],
165696          "evidence": {},
165697          "signature": {
165698            "signature": {
165699              "publicKey": {}
165700            }
165701          },
165702          "modelCard": {
165703            "modelParameters": {
165704              "approach": {}
165705            },
165706            "quantitativeAnalysis": {
165707              "graphics": {}
165708            },
165709            "considerations": {}
165710          }
165711        },
165712        {
165713          "type": "library",
165714          "bom-ref": "pkg:npm/has-flag@3.0.0?package-id=827f03d0a0fb3972",
165715          "supplier": {},
165716          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
165717          "name": "has-flag",
165718          "version": "3.0.0",
165719          "description": "Check if argv has a specific flag",
165720          "licenses": [
165721            {
165722              "license": {
165723                "id": "MIT"
165724              }
165725            }
165726          ],
165727          "cpe": "cpe:2.3:a:has-flag:has-flag:3.0.0:*:*:*:*:*:*:*",
165728          "purl": "pkg:npm/has-flag@3.0.0",
165729          "swid": {
165730            "attachment": {}
165731          },
165732          "pedigree": {},
165733          "externalReferences": [
165734            {
165735              "url": "sindresorhus/has-flag",
165736              "type": "distribution"
165737            }
165738          ],
165739          "evidence": {},
165740          "signature": {
165741            "signature": {
165742              "publicKey": {}
165743            }
165744          },
165745          "modelCard": {
165746            "modelParameters": {
165747              "approach": {}
165748            },
165749            "quantitativeAnalysis": {
165750              "graphics": {}
165751            },
165752            "considerations": {}
165753          }
165754        },
165755        {
165756          "type": "library",
165757          "bom-ref": "pkg:npm/has-flag@4.0.0?package-id=1ac717b55f99f4f2",
165758          "supplier": {},
165759          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
165760          "name": "has-flag",
165761          "version": "4.0.0",
165762          "description": "Check if argv has a specific flag",
165763          "licenses": [
165764            {
165765              "license": {
165766                "id": "MIT"
165767              }
165768            }
165769          ],
165770          "cpe": "cpe:2.3:a:has-flag:has-flag:4.0.0:*:*:*:*:*:*:*",
165771          "purl": "pkg:npm/has-flag@4.0.0",
165772          "swid": {
165773            "attachment": {}
165774          },
165775          "pedigree": {},
165776          "externalReferences": [
165777            {
165778              "url": "sindresorhus/has-flag",
165779              "type": "distribution"
165780            }
165781          ],
165782          "evidence": {},
165783          "signature": {
165784            "signature": {
165785              "publicKey": {}
165786            }
165787          },
165788          "modelCard": {
165789            "modelParameters": {
165790              "approach": {}
165791            },
165792            "quantitativeAnalysis": {
165793              "graphics": {}
165794            },
165795            "considerations": {}
165796          }
165797        },
165798        {
165799          "type": "library",
165800          "bom-ref": "pkg:npm/has-unicode@2.0.1?package-id=28dbbd6e7951181f",
165801          "supplier": {},
165802          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
165803          "name": "has-unicode",
165804          "version": "2.0.1",
165805          "description": "Try to guess if your terminal supports unicode",
165806          "licenses": [
165807            {
165808              "license": {
165809                "id": "ISC"
165810              }
165811            }
165812          ],
165813          "cpe": "cpe:2.3:a:has-unicode:has-unicode:2.0.1:*:*:*:*:*:*:*",
165814          "purl": "pkg:npm/has-unicode@2.0.1",
165815          "swid": {
165816            "attachment": {}
165817          },
165818          "pedigree": {},
165819          "externalReferences": [
165820            {
165821              "url": "https://github.com/iarna/has-unicode",
165822              "type": "distribution"
165823            },
165824            {
165825              "url": "https://github.com/iarna/has-unicode",
165826              "type": "website"
165827            }
165828          ],
165829          "evidence": {},
165830          "signature": {
165831            "signature": {
165832              "publicKey": {}
165833            }
165834          },
165835          "modelCard": {
165836            "modelParameters": {
165837              "approach": {}
165838            },
165839            "quantitativeAnalysis": {
165840              "graphics": {}
165841            },
165842            "considerations": {}
165843          }
165844        },
165845        {
165846          "type": "library",
165847          "bom-ref": "pkg:npm/has-unicode@2.0.1?package-id=5faeeaf9daab02cc",
165848          "supplier": {},
165849          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
165850          "name": "has-unicode",
165851          "version": "2.0.1",
165852          "description": "Try to guess if your terminal supports unicode",
165853          "licenses": [
165854            {
165855              "license": {
165856                "id": "ISC"
165857              }
165858            }
165859          ],
165860          "cpe": "cpe:2.3:a:has-unicode:has-unicode:2.0.1:*:*:*:*:*:*:*",
165861          "purl": "pkg:npm/has-unicode@2.0.1",
165862          "swid": {
165863            "attachment": {}
165864          },
165865          "pedigree": {},
165866          "externalReferences": [
165867            {
165868              "url": "https://github.com/iarna/has-unicode",
165869              "type": "distribution"
165870            },
165871            {
165872              "url": "https://github.com/iarna/has-unicode",
165873              "type": "website"
165874            }
165875          ],
165876          "evidence": {},
165877          "signature": {
165878            "signature": {
165879              "publicKey": {}
165880            }
165881          },
165882          "modelCard": {
165883            "modelParameters": {
165884              "approach": {}
165885            },
165886            "quantitativeAnalysis": {
165887              "graphics": {}
165888            },
165889            "considerations": {}
165890          }
165891        },
165892        {
165893          "type": "library",
165894          "bom-ref": "pkg:npm/hosted-git-info@2.8.9?package-id=56651d3dbc838027",
165895          "supplier": {},
165896          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org)",
165897          "name": "hosted-git-info",
165898          "version": "2.8.9",
165899          "description": "Provides metadata and conversions from repository urls for Github, Bitbucket and Gitlab",
165900          "licenses": [
165901            {
165902              "license": {
165903                "id": "ISC"
165904              }
165905            }
165906          ],
165907          "cpe": "cpe:2.3:a:hosted-git-info:hosted-git-info:2.8.9:*:*:*:*:*:*:*",
165908          "purl": "pkg:npm/hosted-git-info@2.8.9",
165909          "swid": {
165910            "attachment": {}
165911          },
165912          "pedigree": {},
165913          "externalReferences": [
165914            {
165915              "url": "git+https://github.com/npm/hosted-git-info.git",
165916              "type": "distribution"
165917            },
165918            {
165919              "url": "https://github.com/npm/hosted-git-info",
165920              "type": "website"
165921            }
165922          ],
165923          "evidence": {},
165924          "signature": {
165925            "signature": {
165926              "publicKey": {}
165927            }
165928          },
165929          "modelCard": {
165930            "modelParameters": {
165931              "approach": {}
165932            },
165933            "quantitativeAnalysis": {
165934              "graphics": {}
165935            },
165936            "considerations": {}
165937          }
165938        },
165939        {
165940          "type": "library",
165941          "bom-ref": "pkg:npm/hosted-git-info@4.1.0?package-id=89797d3e01db5f5f",
165942          "supplier": {},
165943          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org)",
165944          "name": "hosted-git-info",
165945          "version": "4.1.0",
165946          "description": "Provides metadata and conversions from repository urls for GitHub, Bitbucket and GitLab",
165947          "licenses": [
165948            {
165949              "license": {
165950                "id": "ISC"
165951              }
165952            }
165953          ],
165954          "cpe": "cpe:2.3:a:hosted-git-info:hosted-git-info:4.1.0:*:*:*:*:*:*:*",
165955          "purl": "pkg:npm/hosted-git-info@4.1.0",
165956          "swid": {
165957            "attachment": {}
165958          },
165959          "pedigree": {},
165960          "externalReferences": [
165961            {
165962              "url": "git+https://github.com/npm/hosted-git-info.git",
165963              "type": "distribution"
165964            },
165965            {
165966              "url": "https://github.com/npm/hosted-git-info",
165967              "type": "website"
165968            }
165969          ],
165970          "evidence": {},
165971          "signature": {
165972            "signature": {
165973              "publicKey": {}
165974            }
165975          },
165976          "modelCard": {
165977            "modelParameters": {
165978              "approach": {}
165979            },
165980            "quantitativeAnalysis": {
165981              "graphics": {}
165982            },
165983            "considerations": {}
165984          }
165985        },
165986        {
165987          "type": "library",
165988          "bom-ref": "pkg:npm/hosted-git-info@5.2.1?package-id=daac03af08cd11f6",
165989          "supplier": {},
165990          "author": "GitHub Inc.",
165991          "name": "hosted-git-info",
165992          "version": "5.2.1",
165993          "description": "Provides metadata and conversions from repository urls for GitHub, Bitbucket and GitLab",
165994          "licenses": [
165995            {
165996              "license": {
165997                "id": "ISC"
165998              }
165999            }
166000          ],
166001          "cpe": "cpe:2.3:a:hosted-git-info:hosted-git-info:5.2.1:*:*:*:*:*:*:*",
166002          "purl": "pkg:npm/hosted-git-info@5.2.1",
166003          "swid": {
166004            "attachment": {}
166005          },
166006          "pedigree": {},
166007          "externalReferences": [
166008            {
166009              "url": "https://github.com/npm/hosted-git-info.git",
166010              "type": "distribution"
166011            },
166012            {
166013              "url": "https://github.com/npm/hosted-git-info",
166014              "type": "website"
166015            }
166016          ],
166017          "evidence": {},
166018          "signature": {
166019            "signature": {
166020              "publicKey": {}
166021            }
166022          },
166023          "modelCard": {
166024            "modelParameters": {
166025              "approach": {}
166026            },
166027            "quantitativeAnalysis": {
166028              "graphics": {}
166029            },
166030            "considerations": {}
166031          }
166032        },
166033        {
166034          "type": "library",
166035          "bom-ref": "pkg:npm/http-cache-semantics@4.1.1?package-id=916aa3ebe914a835",
166036          "supplier": {},
166037          "author": "Kornel Lesiński \u003ckornel@geekhood.net\u003e (https://kornel.ski/)",
166038          "name": "http-cache-semantics",
166039          "version": "4.1.1",
166040          "description": "Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies",
166041          "licenses": [
166042            {
166043              "license": {
166044                "id": "BSD-2-Clause"
166045              }
166046            }
166047          ],
166048          "cpe": "cpe:2.3:a:http-cache-semantics:http-cache-semantics:4.1.1:*:*:*:*:*:*:*",
166049          "purl": "pkg:npm/http-cache-semantics@4.1.1",
166050          "swid": {
166051            "attachment": {}
166052          },
166053          "pedigree": {},
166054          "externalReferences": [
166055            {
166056              "url": "https://github.com/kornelski/http-cache-semantics.git",
166057              "type": "distribution"
166058            }
166059          ],
166060          "evidence": {},
166061          "signature": {
166062            "signature": {
166063              "publicKey": {}
166064            }
166065          },
166066          "modelCard": {
166067            "modelParameters": {
166068              "approach": {}
166069            },
166070            "quantitativeAnalysis": {
166071              "graphics": {}
166072            },
166073            "considerations": {}
166074          }
166075        },
166076        {
166077          "type": "library",
166078          "bom-ref": "pkg:npm/http-errors@1.7.2?package-id=d5bb7c99a838d2db",
166079          "supplier": {},
166080          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
166081          "name": "http-errors",
166082          "version": "1.7.2",
166083          "description": "Create HTTP error objects",
166084          "licenses": [
166085            {
166086              "license": {
166087                "id": "MIT"
166088              }
166089            }
166090          ],
166091          "cpe": "cpe:2.3:a:http-errors:http-errors:1.7.2:*:*:*:*:*:*:*",
166092          "purl": "pkg:npm/http-errors@1.7.2",
166093          "swid": {
166094            "attachment": {}
166095          },
166096          "pedigree": {},
166097          "externalReferences": [
166098            {
166099              "url": "jshttp/http-errors",
166100              "type": "distribution"
166101            }
166102          ],
166103          "evidence": {},
166104          "signature": {
166105            "signature": {
166106              "publicKey": {}
166107            }
166108          },
166109          "modelCard": {
166110            "modelParameters": {
166111              "approach": {}
166112            },
166113            "quantitativeAnalysis": {
166114              "graphics": {}
166115            },
166116            "considerations": {}
166117          }
166118        },
166119        {
166120          "type": "library",
166121          "bom-ref": "pkg:npm/http-proxy-agent@5.0.0?package-id=af3d467415b1e643",
166122          "supplier": {},
166123          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
166124          "name": "http-proxy-agent",
166125          "version": "5.0.0",
166126          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTP",
166127          "licenses": [
166128            {
166129              "license": {
166130                "id": "MIT"
166131              }
166132            }
166133          ],
166134          "cpe": "cpe:2.3:a:http-proxy-agent:http-proxy-agent:5.0.0:*:*:*:*:*:*:*",
166135          "purl": "pkg:npm/http-proxy-agent@5.0.0",
166136          "swid": {
166137            "attachment": {}
166138          },
166139          "pedigree": {},
166140          "externalReferences": [
166141            {
166142              "url": "git://github.com/TooTallNate/node-http-proxy-agent.git",
166143              "type": "distribution"
166144            }
166145          ],
166146          "evidence": {},
166147          "signature": {
166148            "signature": {
166149              "publicKey": {}
166150            }
166151          },
166152          "modelCard": {
166153            "modelParameters": {
166154              "approach": {}
166155            },
166156            "quantitativeAnalysis": {
166157              "graphics": {}
166158            },
166159            "considerations": {}
166160          }
166161        },
166162        {
166163          "type": "library",
166164          "bom-ref": "pkg:npm/http-signature@1.2.0?package-id=b566cae888becf5d",
166165          "supplier": {},
166166          "author": "Joyent, Inc",
166167          "name": "http-signature",
166168          "version": "1.2.0",
166169          "description": "Reference implementation of Joyent's HTTP Signature scheme.",
166170          "licenses": [
166171            {
166172              "license": {
166173                "id": "MIT"
166174              }
166175            }
166176          ],
166177          "cpe": "cpe:2.3:a:http-signature:http-signature:1.2.0:*:*:*:*:*:*:*",
166178          "purl": "pkg:npm/http-signature@1.2.0",
166179          "swid": {
166180            "attachment": {}
166181          },
166182          "pedigree": {},
166183          "externalReferences": [
166184            {
166185              "url": "git://github.com/joyent/node-http-signature.git",
166186              "type": "distribution"
166187            },
166188            {
166189              "url": "https://github.com/joyent/node-http-signature/",
166190              "type": "website"
166191            }
166192          ],
166193          "evidence": {},
166194          "signature": {
166195            "signature": {
166196              "publicKey": {}
166197            }
166198          },
166199          "modelCard": {
166200            "modelParameters": {
166201              "approach": {}
166202            },
166203            "quantitativeAnalysis": {
166204              "graphics": {}
166205            },
166206            "considerations": {}
166207          }
166208        },
166209        {
166210          "type": "library",
166211          "bom-ref": "pkg:npm/https-proxy-agent@5.0.1?package-id=b2694aac4dc305de",
166212          "supplier": {},
166213          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
166214          "name": "https-proxy-agent",
166215          "version": "5.0.1",
166216          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
166217          "licenses": [
166218            {
166219              "license": {
166220                "id": "MIT"
166221              }
166222            }
166223          ],
166224          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:5.0.1:*:*:*:*:*:*:*",
166225          "purl": "pkg:npm/https-proxy-agent@5.0.1",
166226          "swid": {
166227            "attachment": {}
166228          },
166229          "pedigree": {},
166230          "externalReferences": [
166231            {
166232              "url": "git://github.com/TooTallNate/node-https-proxy-agent.git",
166233              "type": "distribution"
166234            }
166235          ],
166236          "evidence": {},
166237          "signature": {
166238            "signature": {
166239              "publicKey": {}
166240            }
166241          },
166242          "modelCard": {
166243            "modelParameters": {
166244              "approach": {}
166245            },
166246            "quantitativeAnalysis": {
166247              "graphics": {}
166248            },
166249            "considerations": {}
166250          }
166251        },
166252        {
166253          "type": "library",
166254          "bom-ref": "pkg:npm/humanize-ms@1.2.1?package-id=d773c44dd2f9a86d",
166255          "supplier": {},
166256          "author": "dead-horse \u003cdead_horse@qq.com\u003e (http://deadhorse.me)",
166257          "name": "humanize-ms",
166258          "version": "1.2.1",
166259          "description": "transform humanize time to ms",
166260          "licenses": [
166261            {
166262              "license": {
166263                "id": "MIT"
166264              }
166265            }
166266          ],
166267          "cpe": "cpe:2.3:a:node-modules:humanize-ms:1.2.1:*:*:*:*:*:*:*",
166268          "purl": "pkg:npm/humanize-ms@1.2.1",
166269          "swid": {
166270            "attachment": {}
166271          },
166272          "pedigree": {},
166273          "externalReferences": [
166274            {
166275              "url": "https://github.com/node-modules/humanize-ms",
166276              "type": "distribution"
166277            }
166278          ],
166279          "evidence": {},
166280          "signature": {
166281            "signature": {
166282              "publicKey": {}
166283            }
166284          },
166285          "modelCard": {
166286            "modelParameters": {
166287              "approach": {}
166288            },
166289            "quantitativeAnalysis": {
166290              "graphics": {}
166291            },
166292            "considerations": {}
166293          }
166294        },
166295        {
166296          "type": "library",
166297          "bom-ref": "pkg:npm/iconv-lite@0.4.24?package-id=a2f86b03a2bcafd9",
166298          "supplier": {},
166299          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
166300          "name": "iconv-lite",
166301          "version": "0.4.24",
166302          "description": "Convert character encodings in pure javascript.",
166303          "licenses": [
166304            {
166305              "license": {
166306                "id": "MIT"
166307              }
166308            }
166309          ],
166310          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.4.24:*:*:*:*:*:*:*",
166311          "purl": "pkg:npm/iconv-lite@0.4.24",
166312          "swid": {
166313            "attachment": {}
166314          },
166315          "pedigree": {},
166316          "externalReferences": [
166317            {
166318              "url": "git://github.com/ashtuchkin/iconv-lite.git",
166319              "type": "distribution"
166320            },
166321            {
166322              "url": "https://github.com/ashtuchkin/iconv-lite",
166323              "type": "website"
166324            }
166325          ],
166326          "evidence": {},
166327          "signature": {
166328            "signature": {
166329              "publicKey": {}
166330            }
166331          },
166332          "modelCard": {
166333            "modelParameters": {
166334              "approach": {}
166335            },
166336            "quantitativeAnalysis": {
166337              "graphics": {}
166338            },
166339            "considerations": {}
166340          }
166341        },
166342        {
166343          "type": "library",
166344          "bom-ref": "pkg:npm/iconv-lite@0.6.3?package-id=fc4965fa5a86a9c9",
166345          "supplier": {},
166346          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
166347          "name": "iconv-lite",
166348          "version": "0.6.3",
166349          "description": "Convert character encodings in pure javascript.",
166350          "licenses": [
166351            {
166352              "license": {
166353                "id": "MIT"
166354              }
166355            }
166356          ],
166357          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.6.3:*:*:*:*:*:*:*",
166358          "purl": "pkg:npm/iconv-lite@0.6.3",
166359          "swid": {
166360            "attachment": {}
166361          },
166362          "pedigree": {},
166363          "externalReferences": [
166364            {
166365              "url": "git://github.com/ashtuchkin/iconv-lite.git",
166366              "type": "distribution"
166367            },
166368            {
166369              "url": "https://github.com/ashtuchkin/iconv-lite",
166370              "type": "website"
166371            }
166372          ],
166373          "evidence": {},
166374          "signature": {
166375            "signature": {
166376              "publicKey": {}
166377            }
166378          },
166379          "modelCard": {
166380            "modelParameters": {
166381              "approach": {}
166382            },
166383            "quantitativeAnalysis": {
166384              "graphics": {}
166385            },
166386            "considerations": {}
166387          }
166388        },
166389        {
166390          "type": "library",
166391          "bom-ref": "pkg:npm/igniteui-angular@9.0.3?package-id=cb97323e55cf687a",
166392          "supplier": {},
166393          "author": "Infragistics",
166394          "name": "igniteui-angular",
166395          "version": "9.0.3",
166396          "description": "Ignite UI for Angular is a dependency-free Angular toolkit for building modern web apps",
166397          "licenses": [
166398            {
166399              "license": {
166400                "id": "Apache-2.0"
166401              }
166402            }
166403          ],
166404          "cpe": "cpe:2.3:a:igniteui-angular:igniteui-angular:9.0.3:*:*:*:*:*:*:*",
166405          "purl": "pkg:npm/igniteui-angular@9.0.3",
166406          "swid": {
166407            "attachment": {}
166408          },
166409          "pedigree": {},
166410          "externalReferences": [
166411            {
166412              "url": "https://github.com/IgniteUI/igniteui-angular",
166413              "type": "distribution"
166414            }
166415          ],
166416          "evidence": {},
166417          "signature": {
166418            "signature": {
166419              "publicKey": {}
166420            }
166421          },
166422          "modelCard": {
166423            "modelParameters": {
166424              "approach": {}
166425            },
166426            "quantitativeAnalysis": {
166427              "graphics": {}
166428            },
166429            "considerations": {}
166430          }
166431        },
166432        {
166433          "type": "library",
166434          "bom-ref": "pkg:npm/ignore-walk@5.0.1?package-id=39d6166153eb8a8",
166435          "supplier": {},
166436          "author": "GitHub Inc.",
166437          "name": "ignore-walk",
166438          "version": "5.0.1",
166439          "description": "Nested/recursive `.gitignore`/`.npmignore` parsing and filtering.",
166440          "licenses": [
166441            {
166442              "license": {
166443                "id": "ISC"
166444              }
166445            }
166446          ],
166447          "cpe": "cpe:2.3:a:ignore-walk:ignore-walk:5.0.1:*:*:*:*:*:*:*",
166448          "purl": "pkg:npm/ignore-walk@5.0.1",
166449          "swid": {
166450            "attachment": {}
166451          },
166452          "pedigree": {},
166453          "externalReferences": [
166454            {
166455              "url": "https://github.com/npm/ignore-walk.git",
166456              "type": "distribution"
166457            }
166458          ],
166459          "evidence": {},
166460          "signature": {
166461            "signature": {
166462              "publicKey": {}
166463            }
166464          },
166465          "modelCard": {
166466            "modelParameters": {
166467              "approach": {}
166468            },
166469            "quantitativeAnalysis": {
166470              "graphics": {}
166471            },
166472            "considerations": {}
166473          }
166474        },
166475        {
166476          "type": "library",
166477          "bom-ref": "pkg:npm/immediate@3.0.6?package-id=d2e401a8568285e0",
166478          "supplier": {},
166479          "name": "immediate",
166480          "version": "3.0.6",
166481          "description": "A cross browser microtask library",
166482          "licenses": [
166483            {
166484              "license": {
166485                "id": "MIT"
166486              }
166487            }
166488          ],
166489          "cpe": "cpe:2.3:a:calvinmetcalf:immediate:3.0.6:*:*:*:*:*:*:*",
166490          "purl": "pkg:npm/immediate@3.0.6",
166491          "swid": {
166492            "attachment": {}
166493          },
166494          "pedigree": {},
166495          "externalReferences": [
166496            {
166497              "url": "git://github.com/calvinmetcalf/immediate.git",
166498              "type": "distribution"
166499            }
166500          ],
166501          "evidence": {},
166502          "signature": {
166503            "signature": {
166504              "publicKey": {}
166505            }
166506          },
166507          "modelCard": {
166508            "modelParameters": {
166509              "approach": {}
166510            },
166511            "quantitativeAnalysis": {
166512              "graphics": {}
166513            },
166514            "considerations": {}
166515          }
166516        },
166517        {
166518          "type": "library",
166519          "bom-ref": "pkg:npm/imurmurhash@0.1.4?package-id=6444b4b295dc6bb1",
166520          "supplier": {},
166521          "author": "Jens Taylor \u003cjensyt@gmail.com\u003e (https://github.com/homebrewing)",
166522          "name": "imurmurhash",
166523          "version": "0.1.4",
166524          "description": "An incremental implementation of MurmurHash3",
166525          "licenses": [
166526            {
166527              "license": {
166528                "id": "MIT"
166529              }
166530            }
166531          ],
166532          "cpe": "cpe:2.3:a:imurmurhash:imurmurhash:0.1.4:*:*:*:*:*:*:*",
166533          "purl": "pkg:npm/imurmurhash@0.1.4",
166534          "swid": {
166535            "attachment": {}
166536          },
166537          "pedigree": {},
166538          "externalReferences": [
166539            {
166540              "url": "https://github.com/jensyt/imurmurhash-js",
166541              "type": "distribution"
166542            },
166543            {
166544              "url": "https://github.com/jensyt/imurmurhash-js",
166545              "type": "website"
166546            }
166547          ],
166548          "evidence": {},
166549          "signature": {
166550            "signature": {
166551              "publicKey": {}
166552            }
166553          },
166554          "modelCard": {
166555            "modelParameters": {
166556              "approach": {}
166557            },
166558            "quantitativeAnalysis": {
166559              "graphics": {}
166560            },
166561            "considerations": {}
166562          }
166563        },
166564        {
166565          "type": "library",
166566          "bom-ref": "pkg:npm/indent-string@4.0.0?package-id=9c9aada4281114e7",
166567          "supplier": {},
166568          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
166569          "name": "indent-string",
166570          "version": "4.0.0",
166571          "description": "Indent each line in a string",
166572          "licenses": [
166573            {
166574              "license": {
166575                "id": "MIT"
166576              }
166577            }
166578          ],
166579          "cpe": "cpe:2.3:a:indent-string:indent-string:4.0.0:*:*:*:*:*:*:*",
166580          "purl": "pkg:npm/indent-string@4.0.0",
166581          "swid": {
166582            "attachment": {}
166583          },
166584          "pedigree": {},
166585          "externalReferences": [
166586            {
166587              "url": "sindresorhus/indent-string",
166588              "type": "distribution"
166589            }
166590          ],
166591          "evidence": {},
166592          "signature": {
166593            "signature": {
166594              "publicKey": {}
166595            }
166596          },
166597          "modelCard": {
166598            "modelParameters": {
166599              "approach": {}
166600            },
166601            "quantitativeAnalysis": {
166602              "graphics": {}
166603            },
166604            "considerations": {}
166605          }
166606        },
166607        {
166608          "type": "library",
166609          "bom-ref": "pkg:npm/indent-string@4.0.0?package-id=221cbf992506c9b0",
166610          "supplier": {},
166611          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
166612          "name": "indent-string",
166613          "version": "4.0.0",
166614          "description": "Indent each line in a string",
166615          "licenses": [
166616            {
166617              "license": {
166618                "id": "MIT"
166619              }
166620            }
166621          ],
166622          "cpe": "cpe:2.3:a:indent-string:indent-string:4.0.0:*:*:*:*:*:*:*",
166623          "purl": "pkg:npm/indent-string@4.0.0",
166624          "swid": {
166625            "attachment": {}
166626          },
166627          "pedigree": {},
166628          "externalReferences": [
166629            {
166630              "url": "sindresorhus/indent-string",
166631              "type": "distribution"
166632            }
166633          ],
166634          "evidence": {},
166635          "signature": {
166636            "signature": {
166637              "publicKey": {}
166638            }
166639          },
166640          "modelCard": {
166641            "modelParameters": {
166642              "approach": {}
166643            },
166644            "quantitativeAnalysis": {
166645              "graphics": {}
166646            },
166647            "considerations": {}
166648          }
166649        },
166650        {
166651          "type": "library",
166652          "bom-ref": "pkg:npm/infer-owner@1.0.4?package-id=70041214f8f231ae",
166653          "supplier": {},
166654          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
166655          "name": "infer-owner",
166656          "version": "1.0.4",
166657          "description": "Infer the owner of a path based on the owner of its nearest existing parent",
166658          "licenses": [
166659            {
166660              "license": {
166661                "id": "ISC"
166662              }
166663            }
166664          ],
166665          "cpe": "cpe:2.3:a:infer-owner:infer-owner:1.0.4:*:*:*:*:*:*:*",
166666          "purl": "pkg:npm/infer-owner@1.0.4",
166667          "swid": {
166668            "attachment": {}
166669          },
166670          "pedigree": {},
166671          "externalReferences": [
166672            {
166673              "url": "https://github.com/npm/infer-owner",
166674              "type": "distribution"
166675            }
166676          ],
166677          "evidence": {},
166678          "signature": {
166679            "signature": {
166680              "publicKey": {}
166681            }
166682          },
166683          "modelCard": {
166684            "modelParameters": {
166685              "approach": {}
166686            },
166687            "quantitativeAnalysis": {
166688              "graphics": {}
166689            },
166690            "considerations": {}
166691          }
166692        },
166693        {
166694          "type": "library",
166695          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=59c3c8a2d2437082",
166696          "supplier": {},
166697          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
166698          "name": "inflight",
166699          "version": "1.0.6",
166700          "description": "Add callbacks to requests in flight to avoid async duplication",
166701          "licenses": [
166702            {
166703              "license": {
166704                "id": "ISC"
166705              }
166706            }
166707          ],
166708          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
166709          "purl": "pkg:npm/inflight@1.0.6",
166710          "swid": {
166711            "attachment": {}
166712          },
166713          "pedigree": {},
166714          "externalReferences": [
166715            {
166716              "url": "https://github.com/npm/inflight.git",
166717              "type": "distribution"
166718            },
166719            {
166720              "url": "https://github.com/isaacs/inflight",
166721              "type": "website"
166722            }
166723          ],
166724          "evidence": {},
166725          "signature": {
166726            "signature": {
166727              "publicKey": {}
166728            }
166729          },
166730          "modelCard": {
166731            "modelParameters": {
166732              "approach": {}
166733            },
166734            "quantitativeAnalysis": {
166735              "graphics": {}
166736            },
166737            "considerations": {}
166738          }
166739        },
166740        {
166741          "type": "library",
166742          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=f9bd5cf95258dad4",
166743          "supplier": {},
166744          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
166745          "name": "inflight",
166746          "version": "1.0.6",
166747          "description": "Add callbacks to requests in flight to avoid async duplication",
166748          "licenses": [
166749            {
166750              "license": {
166751                "id": "ISC"
166752              }
166753            }
166754          ],
166755          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
166756          "purl": "pkg:npm/inflight@1.0.6",
166757          "swid": {
166758            "attachment": {}
166759          },
166760          "pedigree": {},
166761          "externalReferences": [
166762            {
166763              "url": "https://github.com/npm/inflight.git",
166764              "type": "distribution"
166765            },
166766            {
166767              "url": "https://github.com/isaacs/inflight",
166768              "type": "website"
166769            }
166770          ],
166771          "evidence": {},
166772          "signature": {
166773            "signature": {
166774              "publicKey": {}
166775            }
166776          },
166777          "modelCard": {
166778            "modelParameters": {
166779              "approach": {}
166780            },
166781            "quantitativeAnalysis": {
166782              "graphics": {}
166783            },
166784            "considerations": {}
166785          }
166786        },
166787        {
166788          "type": "library",
166789          "bom-ref": "pkg:npm/inherits@2.0.3?package-id=1bb44148e405c144",
166790          "supplier": {},
166791          "name": "inherits",
166792          "version": "2.0.3",
166793          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
166794          "licenses": [
166795            {
166796              "license": {
166797                "id": "ISC"
166798              }
166799            }
166800          ],
166801          "cpe": "cpe:2.3:a:inherits:inherits:2.0.3:*:*:*:*:*:*:*",
166802          "purl": "pkg:npm/inherits@2.0.3",
166803          "swid": {
166804            "attachment": {}
166805          },
166806          "pedigree": {},
166807          "externalReferences": [
166808            {
166809              "url": "git://github.com/isaacs/inherits",
166810              "type": "distribution"
166811            }
166812          ],
166813          "evidence": {},
166814          "signature": {
166815            "signature": {
166816              "publicKey": {}
166817            }
166818          },
166819          "modelCard": {
166820            "modelParameters": {
166821              "approach": {}
166822            },
166823            "quantitativeAnalysis": {
166824              "graphics": {}
166825            },
166826            "considerations": {}
166827          }
166828        },
166829        {
166830          "type": "library",
166831          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=2aa76eeeb4a32e94",
166832          "supplier": {},
166833          "name": "inherits",
166834          "version": "2.0.4",
166835          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
166836          "licenses": [
166837            {
166838              "license": {
166839                "id": "ISC"
166840              }
166841            }
166842          ],
166843          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
166844          "purl": "pkg:npm/inherits@2.0.4",
166845          "swid": {
166846            "attachment": {}
166847          },
166848          "pedigree": {},
166849          "externalReferences": [
166850            {
166851              "url": "git://github.com/isaacs/inherits",
166852              "type": "distribution"
166853            }
166854          ],
166855          "evidence": {},
166856          "signature": {
166857            "signature": {
166858              "publicKey": {}
166859            }
166860          },
166861          "modelCard": {
166862            "modelParameters": {
166863              "approach": {}
166864            },
166865            "quantitativeAnalysis": {
166866              "graphics": {}
166867            },
166868            "considerations": {}
166869          }
166870        },
166871        {
166872          "type": "library",
166873          "bom-ref": "pkg:npm/ini@3.0.1?package-id=143d409d5161792",
166874          "supplier": {},
166875          "author": "GitHub Inc.",
166876          "name": "ini",
166877          "version": "3.0.1",
166878          "description": "An ini encoder/decoder for node",
166879          "licenses": [
166880            {
166881              "license": {
166882                "id": "ISC"
166883              }
166884            }
166885          ],
166886          "cpe": "cpe:2.3:a:ini:ini:3.0.1:*:*:*:*:*:*:*",
166887          "purl": "pkg:npm/ini@3.0.1",
166888          "swid": {
166889            "attachment": {}
166890          },
166891          "pedigree": {},
166892          "externalReferences": [
166893            {
166894              "url": "https://github.com/npm/ini.git",
166895              "type": "distribution"
166896            }
166897          ],
166898          "evidence": {},
166899          "signature": {
166900            "signature": {
166901              "publicKey": {}
166902            }
166903          },
166904          "modelCard": {
166905            "modelParameters": {
166906              "approach": {}
166907            },
166908            "quantitativeAnalysis": {
166909              "graphics": {}
166910            },
166911            "considerations": {}
166912          }
166913        },
166914        {
166915          "type": "library",
166916          "bom-ref": "pkg:npm/init-package-json@3.0.2?package-id=6836db1e46d935b6",
166917          "supplier": {},
166918          "author": "GitHub Inc.",
166919          "name": "init-package-json",
166920          "version": "3.0.2",
166921          "description": "A node module to get your node module started",
166922          "licenses": [
166923            {
166924              "license": {
166925                "id": "ISC"
166926              }
166927            }
166928          ],
166929          "cpe": "cpe:2.3:a:init-package-json:init-package-json:3.0.2:*:*:*:*:*:*:*",
166930          "purl": "pkg:npm/init-package-json@3.0.2",
166931          "swid": {
166932            "attachment": {}
166933          },
166934          "pedigree": {},
166935          "externalReferences": [
166936            {
166937              "url": "https://github.com/npm/init-package-json.git",
166938              "type": "distribution"
166939            }
166940          ],
166941          "evidence": {},
166942          "signature": {
166943            "signature": {
166944              "publicKey": {}
166945            }
166946          },
166947          "modelCard": {
166948            "modelParameters": {
166949              "approach": {}
166950            },
166951            "quantitativeAnalysis": {
166952              "graphics": {}
166953            },
166954            "considerations": {}
166955          }
166956        },
166957        {
166958          "type": "library",
166959          "bom-ref": "pkg:npm/ip@2.0.0?package-id=218d1c05ea387b3c",
166960          "supplier": {},
166961          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
166962          "name": "ip",
166963          "version": "2.0.0",
166964          "licenses": [
166965            {
166966              "license": {
166967                "id": "MIT"
166968              }
166969            }
166970          ],
166971          "cpe": "cpe:2.3:a:indutny:ip:2.0.0:*:*:*:*:*:*:*",
166972          "purl": "pkg:npm/ip@2.0.0",
166973          "swid": {
166974            "attachment": {}
166975          },
166976          "pedigree": {},
166977          "externalReferences": [
166978            {
166979              "url": "http://github.com/indutny/node-ip.git",
166980              "type": "distribution"
166981            },
166982            {
166983              "url": "https://github.com/indutny/node-ip",
166984              "type": "website"
166985            }
166986          ],
166987          "evidence": {},
166988          "signature": {
166989            "signature": {
166990              "publicKey": {}
166991            }
166992          },
166993          "modelCard": {
166994            "modelParameters": {
166995              "approach": {}
166996            },
166997            "quantitativeAnalysis": {
166998              "graphics": {}
166999            },
167000            "considerations": {}
167001          }
167002        },
167003        {
167004          "type": "library",
167005          "bom-ref": "pkg:npm/ip-regex@4.3.0?package-id=ce63365b733beafc",
167006          "supplier": {},
167007          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
167008          "name": "ip-regex",
167009          "version": "4.3.0",
167010          "description": "Regular expression for matching IP addresses (IPv4 \u0026 IPv6)",
167011          "licenses": [
167012            {
167013              "license": {
167014                "id": "MIT"
167015              }
167016            }
167017          ],
167018          "cpe": "cpe:2.3:a:ip-regex:ip-regex:4.3.0:*:*:*:*:*:*:*",
167019          "purl": "pkg:npm/ip-regex@4.3.0",
167020          "swid": {
167021            "attachment": {}
167022          },
167023          "pedigree": {},
167024          "externalReferences": [
167025            {
167026              "url": "sindresorhus/ip-regex",
167027              "type": "distribution"
167028            }
167029          ],
167030          "evidence": {},
167031          "signature": {
167032            "signature": {
167033              "publicKey": {}
167034            }
167035          },
167036          "modelCard": {
167037            "modelParameters": {
167038              "approach": {}
167039            },
167040            "quantitativeAnalysis": {
167041              "graphics": {}
167042            },
167043            "considerations": {}
167044          }
167045        },
167046        {
167047          "type": "library",
167048          "bom-ref": "pkg:npm/ipaddr.js@1.9.0?package-id=edfe0b7d113597f2",
167049          "supplier": {},
167050          "author": "whitequark \u003cwhitequark@whitequark.org\u003e",
167051          "name": "ipaddr.js",
167052          "version": "1.9.0",
167053          "description": "A library for manipulating IPv4 and IPv6 addresses in JavaScript.",
167054          "licenses": [
167055            {
167056              "license": {
167057                "id": "MIT"
167058              }
167059            }
167060          ],
167061          "cpe": "cpe:2.3:a:whitequark:ipaddr.js:1.9.0:*:*:*:*:*:*:*",
167062          "purl": "pkg:npm/ipaddr.js@1.9.0",
167063          "swid": {
167064            "attachment": {}
167065          },
167066          "pedigree": {},
167067          "externalReferences": [
167068            {
167069              "url": "git://github.com/whitequark/ipaddr.js",
167070              "type": "distribution"
167071            }
167072          ],
167073          "evidence": {},
167074          "signature": {
167075            "signature": {
167076              "publicKey": {}
167077            }
167078          },
167079          "modelCard": {
167080            "modelParameters": {
167081              "approach": {}
167082            },
167083            "quantitativeAnalysis": {
167084              "graphics": {}
167085            },
167086            "considerations": {}
167087          }
167088        },
167089        {
167090          "type": "library",
167091          "bom-ref": "pkg:npm/is-arrayish@0.2.1?package-id=5651b9aea93d51b0",
167092          "supplier": {},
167093          "author": "Qix (http://github.com/qix-)",
167094          "name": "is-arrayish",
167095          "version": "0.2.1",
167096          "description": "Determines if an object can be used as an array",
167097          "licenses": [
167098            {
167099              "license": {
167100                "id": "MIT"
167101              }
167102            }
167103          ],
167104          "cpe": "cpe:2.3:a:is-arrayish:is-arrayish:0.2.1:*:*:*:*:*:*:*",
167105          "purl": "pkg:npm/is-arrayish@0.2.1",
167106          "swid": {
167107            "attachment": {}
167108          },
167109          "pedigree": {},
167110          "externalReferences": [
167111            {
167112              "url": "https://github.com/qix-/node-is-arrayish.git",
167113              "type": "distribution"
167114            }
167115          ],
167116          "evidence": {},
167117          "signature": {
167118            "signature": {
167119              "publicKey": {}
167120            }
167121          },
167122          "modelCard": {
167123            "modelParameters": {
167124              "approach": {}
167125            },
167126            "quantitativeAnalysis": {
167127              "graphics": {}
167128            },
167129            "considerations": {}
167130          }
167131        },
167132        {
167133          "type": "library",
167134          "bom-ref": "pkg:npm/is-cidr@4.0.2?package-id=b7267695f8ce1238",
167135          "supplier": {},
167136          "author": "silverwind \u003cme@silverwind.io\u003e",
167137          "name": "is-cidr",
167138          "version": "4.0.2",
167139          "description": "Check if a string is an IP address in CIDR notation",
167140          "licenses": [
167141            {
167142              "license": {
167143                "id": "BSD-2-Clause"
167144              }
167145            }
167146          ],
167147          "cpe": "cpe:2.3:a:is-cidr:is-cidr:4.0.2:*:*:*:*:*:*:*",
167148          "purl": "pkg:npm/is-cidr@4.0.2",
167149          "swid": {
167150            "attachment": {}
167151          },
167152          "pedigree": {},
167153          "externalReferences": [
167154            {
167155              "url": "silverwind/is-cidr",
167156              "type": "distribution"
167157            }
167158          ],
167159          "evidence": {},
167160          "signature": {
167161            "signature": {
167162              "publicKey": {}
167163            }
167164          },
167165          "modelCard": {
167166            "modelParameters": {
167167              "approach": {}
167168            },
167169            "quantitativeAnalysis": {
167170              "graphics": {}
167171            },
167172            "considerations": {}
167173          }
167174        },
167175        {
167176          "type": "library",
167177          "bom-ref": "pkg:npm/is-core-module@2.10.0?package-id=22642820ec847015",
167178          "supplier": {},
167179          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
167180          "name": "is-core-module",
167181          "version": "2.10.0",
167182          "description": "Is this specifier a node.js core module?",
167183          "licenses": [
167184            {
167185              "license": {
167186                "id": "MIT"
167187              }
167188            }
167189          ],
167190          "cpe": "cpe:2.3:a:is-core-module:is-core-module:2.10.0:*:*:*:*:*:*:*",
167191          "purl": "pkg:npm/is-core-module@2.10.0",
167192          "swid": {
167193            "attachment": {}
167194          },
167195          "pedigree": {},
167196          "externalReferences": [
167197            {
167198              "url": "git+https://github.com/inspect-js/is-core-module.git",
167199              "type": "distribution"
167200            },
167201            {
167202              "url": "https://github.com/inspect-js/is-core-module",
167203              "type": "website"
167204            }
167205          ],
167206          "evidence": {},
167207          "signature": {
167208            "signature": {
167209              "publicKey": {}
167210            }
167211          },
167212          "modelCard": {
167213            "modelParameters": {
167214              "approach": {}
167215            },
167216            "quantitativeAnalysis": {
167217              "graphics": {}
167218            },
167219            "considerations": {}
167220          }
167221        },
167222        {
167223          "type": "library",
167224          "bom-ref": "pkg:npm/is-core-module@2.11.0?package-id=8daa8eea83313492",
167225          "supplier": {},
167226          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
167227          "name": "is-core-module",
167228          "version": "2.11.0",
167229          "description": "Is this specifier a node.js core module?",
167230          "licenses": [
167231            {
167232              "license": {
167233                "id": "MIT"
167234              }
167235            }
167236          ],
167237          "cpe": "cpe:2.3:a:is-core-module:is-core-module:2.11.0:*:*:*:*:*:*:*",
167238          "purl": "pkg:npm/is-core-module@2.11.0",
167239          "swid": {
167240            "attachment": {}
167241          },
167242          "pedigree": {},
167243          "externalReferences": [
167244            {
167245              "url": "git+https://github.com/inspect-js/is-core-module.git",
167246              "type": "distribution"
167247            },
167248            {
167249              "url": "https://github.com/inspect-js/is-core-module",
167250              "type": "website"
167251            }
167252          ],
167253          "evidence": {},
167254          "signature": {
167255            "signature": {
167256              "publicKey": {}
167257            }
167258          },
167259          "modelCard": {
167260            "modelParameters": {
167261              "approach": {}
167262            },
167263            "quantitativeAnalysis": {
167264              "graphics": {}
167265            },
167266            "considerations": {}
167267          }
167268        },
167269        {
167270          "type": "library",
167271          "bom-ref": "pkg:npm/is-fullwidth-code-point@1.0.0?package-id=539aa617ed9058c3",
167272          "supplier": {},
167273          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
167274          "name": "is-fullwidth-code-point",
167275          "version": "1.0.0",
167276          "description": "Check if the character represented by a given Unicode code point is fullwidth",
167277          "licenses": [
167278            {
167279              "license": {
167280                "id": "MIT"
167281              }
167282            }
167283          ],
167284          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:1.0.0:*:*:*:*:*:*:*",
167285          "purl": "pkg:npm/is-fullwidth-code-point@1.0.0",
167286          "swid": {
167287            "attachment": {}
167288          },
167289          "pedigree": {},
167290          "externalReferences": [
167291            {
167292              "url": "sindresorhus/is-fullwidth-code-point",
167293              "type": "distribution"
167294            }
167295          ],
167296          "evidence": {},
167297          "signature": {
167298            "signature": {
167299              "publicKey": {}
167300            }
167301          },
167302          "modelCard": {
167303            "modelParameters": {
167304              "approach": {}
167305            },
167306            "quantitativeAnalysis": {
167307              "graphics": {}
167308            },
167309            "considerations": {}
167310          }
167311        },
167312        {
167313          "type": "library",
167314          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=420b1651620a4233",
167315          "supplier": {},
167316          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
167317          "name": "is-fullwidth-code-point",
167318          "version": "2.0.0",
167319          "description": "Check if the character represented by a given Unicode code point is fullwidth",
167320          "licenses": [
167321            {
167322              "license": {
167323                "id": "MIT"
167324              }
167325            }
167326          ],
167327          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
167328          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
167329          "swid": {
167330            "attachment": {}
167331          },
167332          "pedigree": {},
167333          "externalReferences": [
167334            {
167335              "url": "sindresorhus/is-fullwidth-code-point",
167336              "type": "distribution"
167337            }
167338          ],
167339          "evidence": {},
167340          "signature": {
167341            "signature": {
167342              "publicKey": {}
167343            }
167344          },
167345          "modelCard": {
167346            "modelParameters": {
167347              "approach": {}
167348            },
167349            "quantitativeAnalysis": {
167350              "graphics": {}
167351            },
167352            "considerations": {}
167353          }
167354        },
167355        {
167356          "type": "library",
167357          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=66b7dca169e5b9bc",
167358          "supplier": {},
167359          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
167360          "name": "is-fullwidth-code-point",
167361          "version": "2.0.0",
167362          "description": "Check if the character represented by a given Unicode code point is fullwidth",
167363          "licenses": [
167364            {
167365              "license": {
167366                "id": "MIT"
167367              }
167368            }
167369          ],
167370          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
167371          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
167372          "swid": {
167373            "attachment": {}
167374          },
167375          "pedigree": {},
167376          "externalReferences": [
167377            {
167378              "url": "sindresorhus/is-fullwidth-code-point",
167379              "type": "distribution"
167380            }
167381          ],
167382          "evidence": {},
167383          "signature": {
167384            "signature": {
167385              "publicKey": {}
167386            }
167387          },
167388          "modelCard": {
167389            "modelParameters": {
167390              "approach": {}
167391            },
167392            "quantitativeAnalysis": {
167393              "graphics": {}
167394            },
167395            "considerations": {}
167396          }
167397        },
167398        {
167399          "type": "library",
167400          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=47feb179d49d95da",
167401          "supplier": {},
167402          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
167403          "name": "is-fullwidth-code-point",
167404          "version": "2.0.0",
167405          "description": "Check if the character represented by a given Unicode code point is fullwidth",
167406          "licenses": [
167407            {
167408              "license": {
167409                "id": "MIT"
167410              }
167411            }
167412          ],
167413          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
167414          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
167415          "swid": {
167416            "attachment": {}
167417          },
167418          "pedigree": {},
167419          "externalReferences": [
167420            {
167421              "url": "sindresorhus/is-fullwidth-code-point",
167422              "type": "distribution"
167423            }
167424          ],
167425          "evidence": {},
167426          "signature": {
167427            "signature": {
167428              "publicKey": {}
167429            }
167430          },
167431          "modelCard": {
167432            "modelParameters": {
167433              "approach": {}
167434            },
167435            "quantitativeAnalysis": {
167436              "graphics": {}
167437            },
167438            "considerations": {}
167439          }
167440        },
167441        {
167442          "type": "library",
167443          "bom-ref": "pkg:npm/is-fullwidth-code-point@3.0.0?package-id=f89f6ce8e80b50d",
167444          "supplier": {},
167445          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
167446          "name": "is-fullwidth-code-point",
167447          "version": "3.0.0",
167448          "description": "Check if the character represented by a given Unicode code point is fullwidth",
167449          "licenses": [
167450            {
167451              "license": {
167452                "id": "MIT"
167453              }
167454            }
167455          ],
167456          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:3.0.0:*:*:*:*:*:*:*",
167457          "purl": "pkg:npm/is-fullwidth-code-point@3.0.0",
167458          "swid": {
167459            "attachment": {}
167460          },
167461          "pedigree": {},
167462          "externalReferences": [
167463            {
167464              "url": "sindresorhus/is-fullwidth-code-point",
167465              "type": "distribution"
167466            }
167467          ],
167468          "evidence": {},
167469          "signature": {
167470            "signature": {
167471              "publicKey": {}
167472            }
167473          },
167474          "modelCard": {
167475            "modelParameters": {
167476              "approach": {}
167477            },
167478            "quantitativeAnalysis": {
167479              "graphics": {}
167480            },
167481            "considerations": {}
167482          }
167483        },
167484        {
167485          "type": "library",
167486          "bom-ref": "pkg:npm/is-lambda@1.0.1?package-id=841af64487227951",
167487          "supplier": {},
167488          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
167489          "name": "is-lambda",
167490          "version": "1.0.1",
167491          "description": "Detect if your code is running on an AWS Lambda server",
167492          "licenses": [
167493            {
167494              "license": {
167495                "id": "MIT"
167496              }
167497            }
167498          ],
167499          "cpe": "cpe:2.3:a:is-lambda:is-lambda:1.0.1:*:*:*:*:*:*:*",
167500          "purl": "pkg:npm/is-lambda@1.0.1",
167501          "swid": {
167502            "attachment": {}
167503          },
167504          "pedigree": {},
167505          "externalReferences": [
167506            {
167507              "url": "https://github.com/watson/is-lambda.git",
167508              "type": "distribution"
167509            },
167510            {
167511              "url": "https://github.com/watson/is-lambda",
167512              "type": "website"
167513            }
167514          ],
167515          "evidence": {},
167516          "signature": {
167517            "signature": {
167518              "publicKey": {}
167519            }
167520          },
167521          "modelCard": {
167522            "modelParameters": {
167523              "approach": {}
167524            },
167525            "quantitativeAnalysis": {
167526              "graphics": {}
167527            },
167528            "considerations": {}
167529          }
167530        },
167531        {
167532          "type": "library",
167533          "bom-ref": "pkg:npm/is-plain-obj@1.1.0?package-id=2b5099a344c93333",
167534          "supplier": {},
167535          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
167536          "name": "is-plain-obj",
167537          "version": "1.1.0",
167538          "description": "Check if a value is a plain object",
167539          "licenses": [
167540            {
167541              "license": {
167542                "id": "MIT"
167543              }
167544            }
167545          ],
167546          "cpe": "cpe:2.3:a:is-plain-obj:is-plain-obj:1.1.0:*:*:*:*:*:*:*",
167547          "purl": "pkg:npm/is-plain-obj@1.1.0",
167548          "swid": {
167549            "attachment": {}
167550          },
167551          "pedigree": {},
167552          "externalReferences": [
167553            {
167554              "url": "sindresorhus/is-plain-obj",
167555              "type": "distribution"
167556            }
167557          ],
167558          "evidence": {},
167559          "signature": {
167560            "signature": {
167561              "publicKey": {}
167562            }
167563          },
167564          "modelCard": {
167565            "modelParameters": {
167566              "approach": {}
167567            },
167568            "quantitativeAnalysis": {
167569              "graphics": {}
167570            },
167571            "considerations": {}
167572          }
167573        },
167574        {
167575          "type": "library",
167576          "bom-ref": "pkg:npm/is-typedarray@1.0.0?package-id=7c7a7687a151a58f",
167577          "supplier": {},
167578          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
167579          "name": "is-typedarray",
167580          "version": "1.0.0",
167581          "description": "Detect whether or not an object is a Typed Array",
167582          "licenses": [
167583            {
167584              "license": {
167585                "id": "MIT"
167586              }
167587            }
167588          ],
167589          "cpe": "cpe:2.3:a:is-typedarray:is-typedarray:1.0.0:*:*:*:*:*:*:*",
167590          "purl": "pkg:npm/is-typedarray@1.0.0",
167591          "swid": {
167592            "attachment": {}
167593          },
167594          "pedigree": {},
167595          "externalReferences": [
167596            {
167597              "url": "git://github.com/hughsk/is-typedarray.git",
167598              "type": "distribution"
167599            },
167600            {
167601              "url": "https://github.com/hughsk/is-typedarray",
167602              "type": "website"
167603            }
167604          ],
167605          "evidence": {},
167606          "signature": {
167607            "signature": {
167608              "publicKey": {}
167609            }
167610          },
167611          "modelCard": {
167612            "modelParameters": {
167613              "approach": {}
167614            },
167615            "quantitativeAnalysis": {
167616              "graphics": {}
167617            },
167618            "considerations": {}
167619          }
167620        },
167621        {
167622          "type": "library",
167623          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=91eedced5ea0d9f4",
167624          "supplier": {},
167625          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
167626          "name": "isarray",
167627          "version": "1.0.0",
167628          "description": "Array#isArray for older browsers",
167629          "licenses": [
167630            {
167631              "license": {
167632                "id": "MIT"
167633              }
167634            }
167635          ],
167636          "cpe": "cpe:2.3:a:juliangruber:isarray:1.0.0:*:*:*:*:*:*:*",
167637          "purl": "pkg:npm/isarray@1.0.0",
167638          "swid": {
167639            "attachment": {}
167640          },
167641          "pedigree": {},
167642          "externalReferences": [
167643            {
167644              "url": "git://github.com/juliangruber/isarray.git",
167645              "type": "distribution"
167646            },
167647            {
167648              "url": "https://github.com/juliangruber/isarray",
167649              "type": "website"
167650            }
167651          ],
167652          "evidence": {},
167653          "signature": {
167654            "signature": {
167655              "publicKey": {}
167656            }
167657          },
167658          "modelCard": {
167659            "modelParameters": {
167660              "approach": {}
167661            },
167662            "quantitativeAnalysis": {
167663              "graphics": {}
167664            },
167665            "considerations": {}
167666          }
167667        },
167668        {
167669          "type": "library",
167670          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=cac2857ecac9cad9",
167671          "supplier": {},
167672          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
167673          "name": "isexe",
167674          "version": "2.0.0",
167675          "description": "Minimal module to check if a file is executable.",
167676          "licenses": [
167677            {
167678              "license": {
167679                "id": "ISC"
167680              }
167681            }
167682          ],
167683          "cpe": "cpe:2.3:a:isaacs:isexe:2.0.0:*:*:*:*:*:*:*",
167684          "purl": "pkg:npm/isexe@2.0.0",
167685          "swid": {
167686            "attachment": {}
167687          },
167688          "pedigree": {},
167689          "externalReferences": [
167690            {
167691              "url": "git+https://github.com/isaacs/isexe.git",
167692              "type": "distribution"
167693            },
167694            {
167695              "url": "https://github.com/isaacs/isexe#readme",
167696              "type": "website"
167697            }
167698          ],
167699          "evidence": {},
167700          "signature": {
167701            "signature": {
167702              "publicKey": {}
167703            }
167704          },
167705          "modelCard": {
167706            "modelParameters": {
167707              "approach": {}
167708            },
167709            "quantitativeAnalysis": {
167710              "graphics": {}
167711            },
167712            "considerations": {}
167713          }
167714        },
167715        {
167716          "type": "library",
167717          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=2f3fac93ebc9c581",
167718          "supplier": {},
167719          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
167720          "name": "isexe",
167721          "version": "2.0.0",
167722          "description": "Minimal module to check if a file is executable.",
167723          "licenses": [
167724            {
167725              "license": {
167726                "id": "ISC"
167727              }
167728            }
167729          ],
167730          "cpe": "cpe:2.3:a:isaacs:isexe:2.0.0:*:*:*:*:*:*:*",
167731          "purl": "pkg:npm/isexe@2.0.0",
167732          "swid": {
167733            "attachment": {}
167734          },
167735          "pedigree": {},
167736          "externalReferences": [
167737            {
167738              "url": "git+https://github.com/isaacs/isexe.git",
167739              "type": "distribution"
167740            },
167741            {
167742              "url": "https://github.com/isaacs/isexe#readme",
167743              "type": "website"
167744            }
167745          ],
167746          "evidence": {},
167747          "signature": {
167748            "signature": {
167749              "publicKey": {}
167750            }
167751          },
167752          "modelCard": {
167753            "modelParameters": {
167754              "approach": {}
167755            },
167756            "quantitativeAnalysis": {
167757              "graphics": {}
167758            },
167759            "considerations": {}
167760          }
167761        },
167762        {
167763          "type": "library",
167764          "bom-ref": "pkg:npm/isstream@0.1.2?package-id=60627e35aae479e",
167765          "supplier": {},
167766          "author": "Rod Vagg \u003crod@vagg.org\u003e",
167767          "name": "isstream",
167768          "version": "0.1.2",
167769          "description": "Determine if an object is a Stream",
167770          "licenses": [
167771            {
167772              "license": {
167773                "id": "MIT"
167774              }
167775            }
167776          ],
167777          "cpe": "cpe:2.3:a:isstream:isstream:0.1.2:*:*:*:*:*:*:*",
167778          "purl": "pkg:npm/isstream@0.1.2",
167779          "swid": {
167780            "attachment": {}
167781          },
167782          "pedigree": {},
167783          "externalReferences": [
167784            {
167785              "url": "https://github.com/rvagg/isstream.git",
167786              "type": "distribution"
167787            },
167788            {
167789              "url": "https://github.com/rvagg/isstream",
167790              "type": "website"
167791            }
167792          ],
167793          "evidence": {},
167794          "signature": {
167795            "signature": {
167796              "publicKey": {}
167797            }
167798          },
167799          "modelCard": {
167800            "modelParameters": {
167801              "approach": {}
167802            },
167803            "quantitativeAnalysis": {
167804              "graphics": {}
167805            },
167806            "considerations": {}
167807          }
167808        },
167809        {
167810          "type": "library",
167811          "bom-ref": "pkg:npm/js-base64@2.6.4?package-id=12a669467e5301e",
167812          "supplier": {},
167813          "author": "Dan Kogai",
167814          "name": "js-base64",
167815          "version": "2.6.4",
167816          "description": "Yet another Base64 transcoder in pure-JS",
167817          "licenses": [
167818            {
167819              "license": {
167820                "id": "BSD-3-Clause"
167821              }
167822            }
167823          ],
167824          "cpe": "cpe:2.3:a:js-base64:js-base64:2.6.4:*:*:*:*:*:*:*",
167825          "purl": "pkg:npm/js-base64@2.6.4",
167826          "swid": {
167827            "attachment": {}
167828          },
167829          "pedigree": {},
167830          "externalReferences": [
167831            {
167832              "url": "git://github.com/dankogai/js-base64.git",
167833              "type": "distribution"
167834            }
167835          ],
167836          "evidence": {},
167837          "signature": {
167838            "signature": {
167839              "publicKey": {}
167840            }
167841          },
167842          "modelCard": {
167843            "modelParameters": {
167844              "approach": {}
167845            },
167846            "quantitativeAnalysis": {
167847              "graphics": {}
167848            },
167849            "considerations": {}
167850          }
167851        },
167852        {
167853          "type": "library",
167854          "bom-ref": "pkg:npm/js-tokens@4.0.0?package-id=7ba661b8c7568cc4",
167855          "supplier": {},
167856          "author": "Simon Lydell",
167857          "name": "js-tokens",
167858          "version": "4.0.0",
167859          "description": "A regex that tokenizes JavaScript.",
167860          "licenses": [
167861            {
167862              "license": {
167863                "id": "MIT"
167864              }
167865            }
167866          ],
167867          "cpe": "cpe:2.3:a:js-tokens:js-tokens:4.0.0:*:*:*:*:*:*:*",
167868          "purl": "pkg:npm/js-tokens@4.0.0",
167869          "swid": {
167870            "attachment": {}
167871          },
167872          "pedigree": {},
167873          "externalReferences": [
167874            {
167875              "url": "lydell/js-tokens",
167876              "type": "distribution"
167877            }
167878          ],
167879          "evidence": {},
167880          "signature": {
167881            "signature": {
167882              "publicKey": {}
167883            }
167884          },
167885          "modelCard": {
167886            "modelParameters": {
167887              "approach": {}
167888            },
167889            "quantitativeAnalysis": {
167890              "graphics": {}
167891            },
167892            "considerations": {}
167893          }
167894        },
167895        {
167896          "type": "library",
167897          "bom-ref": "pkg:npm/jsbn@0.1.1?package-id=f3ac3ad288be4178",
167898          "supplier": {},
167899          "author": "Tom Wu",
167900          "name": "jsbn",
167901          "version": "0.1.1",
167902          "description": "The jsbn library is a fast, portable implementation of large-number math in pure JavaScript, enabling public-key crypto and other applications on desktop and mobile browsers.",
167903          "licenses": [
167904            {
167905              "license": {
167906                "id": "MIT"
167907              }
167908            }
167909          ],
167910          "cpe": "cpe:2.3:a:andyperlitch:jsbn:0.1.1:*:*:*:*:*:*:*",
167911          "purl": "pkg:npm/jsbn@0.1.1",
167912          "swid": {
167913            "attachment": {}
167914          },
167915          "pedigree": {},
167916          "externalReferences": [
167917            {
167918              "url": "https://github.com/andyperlitch/jsbn.git",
167919              "type": "distribution"
167920            }
167921          ],
167922          "evidence": {},
167923          "signature": {
167924            "signature": {
167925              "publicKey": {}
167926            }
167927          },
167928          "modelCard": {
167929            "modelParameters": {
167930              "approach": {}
167931            },
167932            "quantitativeAnalysis": {
167933              "graphics": {}
167934            },
167935            "considerations": {}
167936          }
167937        },
167938        {
167939          "type": "library",
167940          "bom-ref": "pkg:npm/json-parse-even-better-errors@2.3.1?package-id=abf07f33abe9247b",
167941          "supplier": {},
167942          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
167943          "name": "json-parse-even-better-errors",
167944          "version": "2.3.1",
167945          "description": "JSON.parse with context information on error",
167946          "licenses": [
167947            {
167948              "license": {
167949                "id": "MIT"
167950              }
167951            }
167952          ],
167953          "cpe": "cpe:2.3:a:json-parse-even-better-errors:json-parse-even-better-errors:2.3.1:*:*:*:*:*:*:*",
167954          "purl": "pkg:npm/json-parse-even-better-errors@2.3.1",
167955          "swid": {
167956            "attachment": {}
167957          },
167958          "pedigree": {},
167959          "externalReferences": [
167960            {
167961              "url": "https://github.com/npm/json-parse-even-better-errors",
167962              "type": "distribution"
167963            }
167964          ],
167965          "evidence": {},
167966          "signature": {
167967            "signature": {
167968              "publicKey": {}
167969            }
167970          },
167971          "modelCard": {
167972            "modelParameters": {
167973              "approach": {}
167974            },
167975            "quantitativeAnalysis": {
167976              "graphics": {}
167977            },
167978            "considerations": {}
167979          }
167980        },
167981        {
167982          "type": "library",
167983          "bom-ref": "pkg:npm/json-parse-even-better-errors@2.3.1?package-id=f2d336434bd86052",
167984          "supplier": {},
167985          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
167986          "name": "json-parse-even-better-errors",
167987          "version": "2.3.1",
167988          "description": "JSON.parse with context information on error",
167989          "licenses": [
167990            {
167991              "license": {
167992                "id": "MIT"
167993              }
167994            }
167995          ],
167996          "cpe": "cpe:2.3:a:json-parse-even-better-errors:json-parse-even-better-errors:2.3.1:*:*:*:*:*:*:*",
167997          "purl": "pkg:npm/json-parse-even-better-errors@2.3.1",
167998          "swid": {
167999            "attachment": {}
168000          },
168001          "pedigree": {},
168002          "externalReferences": [
168003            {
168004              "url": "https://github.com/npm/json-parse-even-better-errors",
168005              "type": "distribution"
168006            }
168007          ],
168008          "evidence": {},
168009          "signature": {
168010            "signature": {
168011              "publicKey": {}
168012            }
168013          },
168014          "modelCard": {
168015            "modelParameters": {
168016              "approach": {}
168017            },
168018            "quantitativeAnalysis": {
168019              "graphics": {}
168020            },
168021            "considerations": {}
168022          }
168023        },
168024        {
168025          "type": "library",
168026          "bom-ref": "pkg:npm/json-schema@0.4.0?package-id=f6da4a26d6afa2e4",
168027          "supplier": {},
168028          "author": "Kris Zyp",
168029          "name": "json-schema",
168030          "version": "0.4.0",
168031          "description": "JSON Schema validation and specifications",
168032          "licenses": [
168033            {
168034              "license": {
168035                "name": "(AFL-2.1 OR BSD-3-Clause)"
168036              }
168037            }
168038          ],
168039          "cpe": "cpe:2.3:a:json-schema:json-schema:0.4.0:*:*:*:*:*:*:*",
168040          "purl": "pkg:npm/json-schema@0.4.0",
168041          "swid": {
168042            "attachment": {}
168043          },
168044          "pedigree": {},
168045          "externalReferences": [
168046            {
168047              "url": "http://github.com/kriszyp/json-schema",
168048              "type": "distribution"
168049            }
168050          ],
168051          "evidence": {},
168052          "signature": {
168053            "signature": {
168054              "publicKey": {}
168055            }
168056          },
168057          "modelCard": {
168058            "modelParameters": {
168059              "approach": {}
168060            },
168061            "quantitativeAnalysis": {
168062              "graphics": {}
168063            },
168064            "considerations": {}
168065          }
168066        },
168067        {
168068          "type": "library",
168069          "bom-ref": "pkg:npm/json-schema-traverse@0.4.1?package-id=3b5dfc07da3fba89",
168070          "supplier": {},
168071          "author": "Evgeny Poberezkin",
168072          "name": "json-schema-traverse",
168073          "version": "0.4.1",
168074          "description": "Traverse JSON Schema passing each schema object to callback",
168075          "licenses": [
168076            {
168077              "license": {
168078                "id": "MIT"
168079              }
168080            }
168081          ],
168082          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:0.4.1:*:*:*:*:*:*:*",
168083          "purl": "pkg:npm/json-schema-traverse@0.4.1",
168084          "swid": {
168085            "attachment": {}
168086          },
168087          "pedigree": {},
168088          "externalReferences": [
168089            {
168090              "url": "git+https://github.com/epoberezkin/json-schema-traverse.git",
168091              "type": "distribution"
168092            },
168093            {
168094              "url": "https://github.com/epoberezkin/json-schema-traverse#readme",
168095              "type": "website"
168096            }
168097          ],
168098          "evidence": {},
168099          "signature": {
168100            "signature": {
168101              "publicKey": {}
168102            }
168103          },
168104          "modelCard": {
168105            "modelParameters": {
168106              "approach": {}
168107            },
168108            "quantitativeAnalysis": {
168109              "graphics": {}
168110            },
168111            "considerations": {}
168112          }
168113        },
168114        {
168115          "type": "library",
168116          "bom-ref": "pkg:npm/json-stringify-nice@1.1.4?package-id=e53e3b4efad53e7c",
168117          "supplier": {},
168118          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
168119          "name": "json-stringify-nice",
168120          "version": "1.1.4",
168121          "description": "Stringify an object sorting scalars before objects, and defaulting to 2-space indent",
168122          "licenses": [
168123            {
168124              "license": {
168125                "id": "ISC"
168126              }
168127            }
168128          ],
168129          "cpe": "cpe:2.3:a:json-stringify-nice:json-stringify-nice:1.1.4:*:*:*:*:*:*:*",
168130          "purl": "pkg:npm/json-stringify-nice@1.1.4",
168131          "swid": {
168132            "attachment": {}
168133          },
168134          "pedigree": {},
168135          "externalReferences": [
168136            {
168137              "url": "https://github.com/isaacs/json-stringify-nice",
168138              "type": "distribution"
168139            }
168140          ],
168141          "evidence": {},
168142          "signature": {
168143            "signature": {
168144              "publicKey": {}
168145            }
168146          },
168147          "modelCard": {
168148            "modelParameters": {
168149              "approach": {}
168150            },
168151            "quantitativeAnalysis": {
168152              "graphics": {}
168153            },
168154            "considerations": {}
168155          }
168156        },
168157        {
168158          "type": "library",
168159          "bom-ref": "pkg:npm/json-stringify-safe@5.0.1?package-id=f6bc9b393e0af00f",
168160          "supplier": {},
168161          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
168162          "name": "json-stringify-safe",
168163          "version": "5.0.1",
168164          "description": "Like JSON.stringify, but doesn't blow up on circular refs.",
168165          "licenses": [
168166            {
168167              "license": {
168168                "id": "ISC"
168169              }
168170            }
168171          ],
168172          "cpe": "cpe:2.3:a:json-stringify-safe:json-stringify-safe:5.0.1:*:*:*:*:*:*:*",
168173          "purl": "pkg:npm/json-stringify-safe@5.0.1",
168174          "swid": {
168175            "attachment": {}
168176          },
168177          "pedigree": {},
168178          "externalReferences": [
168179            {
168180              "url": "git://github.com/isaacs/json-stringify-safe",
168181              "type": "distribution"
168182            },
168183            {
168184              "url": "https://github.com/isaacs/json-stringify-safe",
168185              "type": "website"
168186            }
168187          ],
168188          "evidence": {},
168189          "signature": {
168190            "signature": {
168191              "publicKey": {}
168192            }
168193          },
168194          "modelCard": {
168195            "modelParameters": {
168196              "approach": {}
168197            },
168198            "quantitativeAnalysis": {
168199              "graphics": {}
168200            },
168201            "considerations": {}
168202          }
168203        },
168204        {
168205          "type": "library",
168206          "bom-ref": "pkg:npm/jsonfile@4.0.0?package-id=4cfeca6860892aa8",
168207          "supplier": {},
168208          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
168209          "name": "jsonfile",
168210          "version": "4.0.0",
168211          "description": "Easily read/write JSON files.",
168212          "licenses": [
168213            {
168214              "license": {
168215                "id": "MIT"
168216              }
168217            }
168218          ],
168219          "cpe": "cpe:2.3:a:jsonfile:jsonfile:4.0.0:*:*:*:*:*:*:*",
168220          "purl": "pkg:npm/jsonfile@4.0.0",
168221          "swid": {
168222            "attachment": {}
168223          },
168224          "pedigree": {},
168225          "externalReferences": [
168226            {
168227              "url": "git@github.com:jprichardson/node-jsonfile.git",
168228              "type": "distribution"
168229            }
168230          ],
168231          "evidence": {},
168232          "signature": {
168233            "signature": {
168234              "publicKey": {}
168235            }
168236          },
168237          "modelCard": {
168238            "modelParameters": {
168239              "approach": {}
168240            },
168241            "quantitativeAnalysis": {
168242              "graphics": {}
168243            },
168244            "considerations": {}
168245          }
168246        },
168247        {
168248          "type": "library",
168249          "bom-ref": "pkg:npm/jsonparse@1.3.1?package-id=4ac9c9dc14c89718",
168250          "supplier": {},
168251          "author": "Tim Caswell \u003ctim@creationix.com\u003e",
168252          "name": "jsonparse",
168253          "version": "1.3.1",
168254          "description": "This is a pure-js JSON streaming parser for node.js",
168255          "licenses": [
168256            {
168257              "license": {
168258                "id": "MIT"
168259              }
168260            }
168261          ],
168262          "cpe": "cpe:2.3:a:creationix:jsonparse:1.3.1:*:*:*:*:*:*:*",
168263          "purl": "pkg:npm/jsonparse@1.3.1",
168264          "swid": {
168265            "attachment": {}
168266          },
168267          "pedigree": {},
168268          "externalReferences": [
168269            {
168270              "url": "http://github.com/creationix/jsonparse.git",
168271              "type": "distribution"
168272            }
168273          ],
168274          "evidence": {},
168275          "signature": {
168276            "signature": {
168277              "publicKey": {}
168278            }
168279          },
168280          "modelCard": {
168281            "modelParameters": {
168282              "approach": {}
168283            },
168284            "quantitativeAnalysis": {
168285              "graphics": {}
168286            },
168287            "considerations": {}
168288          }
168289        },
168290        {
168291          "type": "library",
168292          "bom-ref": "pkg:npm/jsprim@1.4.2?package-id=5cc587fdf3d16342",
168293          "supplier": {},
168294          "name": "jsprim",
168295          "version": "1.4.2",
168296          "description": "utilities for primitive JavaScript types",
168297          "licenses": [
168298            {
168299              "license": {
168300                "id": "MIT"
168301              }
168302            }
168303          ],
168304          "cpe": "cpe:2.3:a:joyent:jsprim:1.4.2:*:*:*:*:*:*:*",
168305          "purl": "pkg:npm/jsprim@1.4.2",
168306          "swid": {
168307            "attachment": {}
168308          },
168309          "pedigree": {},
168310          "externalReferences": [
168311            {
168312              "url": "git://github.com/joyent/node-jsprim.git",
168313              "type": "distribution"
168314            }
168315          ],
168316          "evidence": {},
168317          "signature": {
168318            "signature": {
168319              "publicKey": {}
168320            }
168321          },
168322          "modelCard": {
168323            "modelParameters": {
168324              "approach": {}
168325            },
168326            "quantitativeAnalysis": {
168327              "graphics": {}
168328            },
168329            "considerations": {}
168330          }
168331        },
168332        {
168333          "type": "library",
168334          "bom-ref": "pkg:npm/jszip@3.2.2?package-id=c57d0869ae4da13f",
168335          "supplier": {},
168336          "author": "Stuart Knightley \u003cstuart@stuartk.com\u003e",
168337          "name": "jszip",
168338          "version": "3.2.2",
168339          "description": "Create, read and edit .zip files with JavaScript http://stuartk.com/jszip",
168340          "licenses": [
168341            {
168342              "license": {
168343                "name": "(MIT OR GPL-3.0)"
168344              }
168345            }
168346          ],
168347          "cpe": "cpe:2.3:a:jszip:jszip:3.2.2:*:*:*:*:*:*:*",
168348          "purl": "pkg:npm/jszip@3.2.2",
168349          "swid": {
168350            "attachment": {}
168351          },
168352          "pedigree": {},
168353          "externalReferences": [
168354            {
168355              "url": "https://github.com/Stuk/jszip.git",
168356              "type": "distribution"
168357            }
168358          ],
168359          "evidence": {},
168360          "signature": {
168361            "signature": {
168362              "publicKey": {}
168363            }
168364          },
168365          "modelCard": {
168366            "modelParameters": {
168367              "approach": {}
168368            },
168369            "quantitativeAnalysis": {
168370              "graphics": {}
168371            },
168372            "considerations": {}
168373          }
168374        },
168375        {
168376          "type": "library",
168377          "bom-ref": "pkg:npm/just-diff@5.1.1?package-id=ce66f628f594c549",
168378          "supplier": {},
168379          "author": "Angus Croll",
168380          "name": "just-diff",
168381          "version": "5.1.1",
168382          "description": "Return an object representing the diffs between two objects. Supports jsonPatch protocol",
168383          "licenses": [
168384            {
168385              "license": {
168386                "id": "MIT"
168387              }
168388            }
168389          ],
168390          "cpe": "cpe:2.3:a:just-diff:just-diff:5.1.1:*:*:*:*:*:*:*",
168391          "purl": "pkg:npm/just-diff@5.1.1",
168392          "swid": {
168393            "attachment": {}
168394          },
168395          "pedigree": {},
168396          "externalReferences": [
168397            {
168398              "url": "https://github.com/angus-c/just",
168399              "type": "distribution"
168400            }
168401          ],
168402          "evidence": {},
168403          "signature": {
168404            "signature": {
168405              "publicKey": {}
168406            }
168407          },
168408          "modelCard": {
168409            "modelParameters": {
168410              "approach": {}
168411            },
168412            "quantitativeAnalysis": {
168413              "graphics": {}
168414            },
168415            "considerations": {}
168416          }
168417        },
168418        {
168419          "type": "library",
168420          "bom-ref": "pkg:npm/just-diff-apply@5.4.1?package-id=11dfc45c877cf5ba",
168421          "supplier": {},
168422          "author": "Angus Croll",
168423          "name": "just-diff-apply",
168424          "version": "5.4.1",
168425          "description": "Apply a diff to an object. Optionally supports jsonPatch protocol",
168426          "licenses": [
168427            {
168428              "license": {
168429                "id": "MIT"
168430              }
168431            }
168432          ],
168433          "cpe": "cpe:2.3:a:just-diff-apply:just-diff-apply:5.4.1:*:*:*:*:*:*:*",
168434          "purl": "pkg:npm/just-diff-apply@5.4.1",
168435          "swid": {
168436            "attachment": {}
168437          },
168438          "pedigree": {},
168439          "externalReferences": [
168440            {
168441              "url": "https://github.com/angus-c/just",
168442              "type": "distribution"
168443            }
168444          ],
168445          "evidence": {},
168446          "signature": {
168447            "signature": {
168448              "publicKey": {}
168449            }
168450          },
168451          "modelCard": {
168452            "modelParameters": {
168453              "approach": {}
168454            },
168455            "quantitativeAnalysis": {
168456              "graphics": {}
168457            },
168458            "considerations": {}
168459          }
168460        },
168461        {
168462          "type": "library",
168463          "bom-ref": "pkg:npm/kind-of@6.0.3?package-id=a7344207303f4cfd",
168464          "supplier": {},
168465          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
168466          "name": "kind-of",
168467          "version": "6.0.3",
168468          "description": "Get the native type of a value.",
168469          "licenses": [
168470            {
168471              "license": {
168472                "id": "MIT"
168473              }
168474            }
168475          ],
168476          "cpe": "cpe:2.3:a:jonschlinkert:kind-of:6.0.3:*:*:*:*:*:*:*",
168477          "purl": "pkg:npm/kind-of@6.0.3",
168478          "swid": {
168479            "attachment": {}
168480          },
168481          "pedigree": {},
168482          "externalReferences": [
168483            {
168484              "url": "jonschlinkert/kind-of",
168485              "type": "distribution"
168486            },
168487            {
168488              "url": "https://github.com/jonschlinkert/kind-of",
168489              "type": "website"
168490            }
168491          ],
168492          "evidence": {},
168493          "signature": {
168494            "signature": {
168495              "publicKey": {}
168496            }
168497          },
168498          "modelCard": {
168499            "modelParameters": {
168500              "approach": {}
168501            },
168502            "quantitativeAnalysis": {
168503              "graphics": {}
168504            },
168505            "considerations": {}
168506          }
168507        },
168508        {
168509          "type": "library",
168510          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5\u0026package-id=2abd3b45f6fa4702",
168511          "supplier": {},
168512          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
168513          "name": "libc-utils",
168514          "version": "0.7.2-r3",
168515          "description": "Meta package to pull in correct libc",
168516          "licenses": [
168517            {
168518              "license": {
168519                "id": "BSD-2-Clause"
168520              }
168521            },
168522            {
168523              "license": {
168524                "name": "AND"
168525              }
168526            },
168527            {
168528              "license": {
168529                "id": "BSD-3-Clause"
168530              }
168531            }
168532          ],
168533          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
168534          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5",
168535          "swid": {
168536            "attachment": {}
168537          },
168538          "pedigree": {},
168539          "externalReferences": [
168540            {
168541              "url": "https://alpinelinux.org",
168542              "type": "distribution"
168543            }
168544          ],
168545          "evidence": {},
168546          "signature": {
168547            "signature": {
168548              "publicKey": {}
168549            }
168550          },
168551          "modelCard": {
168552            "modelParameters": {
168553              "approach": {}
168554            },
168555            "quantitativeAnalysis": {
168556              "graphics": {}
168557            },
168558            "considerations": {}
168559          }
168560        },
168561        {
168562          "type": "library",
168563          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=13bc051822a24e8d",
168564          "supplier": {},
168565          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
168566          "name": "libcrypto1.1",
168567          "version": "1.1.1t-r2",
168568          "description": "Crypto library from openssl",
168569          "licenses": [
168570            {
168571              "license": {
168572                "id": "OpenSSL"
168573              }
168574            }
168575          ],
168576          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1t-r2:*:*:*:*:*:*:*",
168577          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
168578          "swid": {
168579            "attachment": {}
168580          },
168581          "pedigree": {},
168582          "externalReferences": [
168583            {
168584              "url": "https://www.openssl.org/",
168585              "type": "distribution"
168586            }
168587          ],
168588          "evidence": {},
168589          "signature": {
168590            "signature": {
168591              "publicKey": {}
168592            }
168593          },
168594          "modelCard": {
168595            "modelParameters": {
168596              "approach": {}
168597            },
168598            "quantitativeAnalysis": {
168599              "graphics": {}
168600            },
168601            "considerations": {}
168602          }
168603        },
168604        {
168605          "type": "library",
168606          "bom-ref": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=d2886381f1e7cdb2",
168607          "supplier": {},
168608          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
168609          "name": "libgcc",
168610          "version": "11.2.1_git20220219-r2",
168611          "description": "GNU C compiler runtime libraries",
168612          "licenses": [
168613            {
168614              "license": {
168615                "id": "GPL-2.0-or-later"
168616              }
168617            },
168618            {
168619              "license": {
168620                "id": "LGPL-2.1-or-later"
168621              }
168622            }
168623          ],
168624          "cpe": "cpe:2.3:a:libgcc:libgcc:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
168625          "purl": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
168626          "swid": {
168627            "attachment": {}
168628          },
168629          "pedigree": {},
168630          "externalReferences": [
168631            {
168632              "url": "https://gcc.gnu.org",
168633              "type": "distribution"
168634            }
168635          ],
168636          "evidence": {},
168637          "signature": {
168638            "signature": {
168639              "publicKey": {}
168640            }
168641          },
168642          "modelCard": {
168643            "modelParameters": {
168644              "approach": {}
168645            },
168646            "quantitativeAnalysis": {
168647              "graphics": {}
168648            },
168649            "considerations": {}
168650          }
168651        },
168652        {
168653          "type": "library",
168654          "bom-ref": "pkg:npm/libnpmaccess@6.0.4?package-id=f3410b3d946e1c4d",
168655          "supplier": {},
168656          "author": "GitHub Inc.",
168657          "name": "libnpmaccess",
168658          "version": "6.0.4",
168659          "description": "programmatic library for `npm access` commands",
168660          "licenses": [
168661            {
168662              "license": {
168663                "id": "ISC"
168664              }
168665            }
168666          ],
168667          "cpe": "cpe:2.3:a:libnpmaccess:libnpmaccess:6.0.4:*:*:*:*:*:*:*",
168668          "purl": "pkg:npm/libnpmaccess@6.0.4",
168669          "swid": {
168670            "attachment": {}
168671          },
168672          "pedigree": {},
168673          "externalReferences": [
168674            {
168675              "url": "https://github.com/npm/cli.git",
168676              "type": "distribution"
168677            },
168678            {
168679              "url": "https://npmjs.com/package/libnpmaccess",
168680              "type": "website"
168681            }
168682          ],
168683          "evidence": {},
168684          "signature": {
168685            "signature": {
168686              "publicKey": {}
168687            }
168688          },
168689          "modelCard": {
168690            "modelParameters": {
168691              "approach": {}
168692            },
168693            "quantitativeAnalysis": {
168694              "graphics": {}
168695            },
168696            "considerations": {}
168697          }
168698        },
168699        {
168700          "type": "library",
168701          "bom-ref": "pkg:npm/libnpmdiff@4.0.5?package-id=ce3262e2c08529ea",
168702          "supplier": {},
168703          "author": "GitHub Inc.",
168704          "name": "libnpmdiff",
168705          "version": "4.0.5",
168706          "description": "The registry diff",
168707          "licenses": [
168708            {
168709              "license": {
168710                "id": "ISC"
168711              }
168712            }
168713          ],
168714          "cpe": "cpe:2.3:a:libnpmdiff:libnpmdiff:4.0.5:*:*:*:*:*:*:*",
168715          "purl": "pkg:npm/libnpmdiff@4.0.5",
168716          "swid": {
168717            "attachment": {}
168718          },
168719          "pedigree": {},
168720          "externalReferences": [
168721            {
168722              "url": "https://github.com/npm/cli.git",
168723              "type": "distribution"
168724            }
168725          ],
168726          "evidence": {},
168727          "signature": {
168728            "signature": {
168729              "publicKey": {}
168730            }
168731          },
168732          "modelCard": {
168733            "modelParameters": {
168734              "approach": {}
168735            },
168736            "quantitativeAnalysis": {
168737              "graphics": {}
168738            },
168739            "considerations": {}
168740          }
168741        },
168742        {
168743          "type": "library",
168744          "bom-ref": "pkg:npm/libnpmexec@4.0.14?package-id=902cc2f16bb11ffc",
168745          "supplier": {},
168746          "author": "GitHub Inc.",
168747          "name": "libnpmexec",
168748          "version": "4.0.14",
168749          "description": "npm exec (npx) programmatic API",
168750          "licenses": [
168751            {
168752              "license": {
168753                "id": "ISC"
168754              }
168755            }
168756          ],
168757          "cpe": "cpe:2.3:a:libnpmexec:libnpmexec:4.0.14:*:*:*:*:*:*:*",
168758          "purl": "pkg:npm/libnpmexec@4.0.14",
168759          "swid": {
168760            "attachment": {}
168761          },
168762          "pedigree": {},
168763          "externalReferences": [
168764            {
168765              "url": "https://github.com/npm/cli.git",
168766              "type": "distribution"
168767            }
168768          ],
168769          "evidence": {},
168770          "signature": {
168771            "signature": {
168772              "publicKey": {}
168773            }
168774          },
168775          "modelCard": {
168776            "modelParameters": {
168777              "approach": {}
168778            },
168779            "quantitativeAnalysis": {
168780              "graphics": {}
168781            },
168782            "considerations": {}
168783          }
168784        },
168785        {
168786          "type": "library",
168787          "bom-ref": "pkg:npm/libnpmfund@3.0.5?package-id=201ebcb5d992fa75",
168788          "supplier": {},
168789          "author": "GitHub Inc.",
168790          "name": "libnpmfund",
168791          "version": "3.0.5",
168792          "description": "Programmatic API for npm fund",
168793          "licenses": [
168794            {
168795              "license": {
168796                "id": "ISC"
168797              }
168798            }
168799          ],
168800          "cpe": "cpe:2.3:a:libnpmfund:libnpmfund:3.0.5:*:*:*:*:*:*:*",
168801          "purl": "pkg:npm/libnpmfund@3.0.5",
168802          "swid": {
168803            "attachment": {}
168804          },
168805          "pedigree": {},
168806          "externalReferences": [
168807            {
168808              "url": "https://github.com/npm/cli.git",
168809              "type": "distribution"
168810            }
168811          ],
168812          "evidence": {},
168813          "signature": {
168814            "signature": {
168815              "publicKey": {}
168816            }
168817          },
168818          "modelCard": {
168819            "modelParameters": {
168820              "approach": {}
168821            },
168822            "quantitativeAnalysis": {
168823              "graphics": {}
168824            },
168825            "considerations": {}
168826          }
168827        },
168828        {
168829          "type": "library",
168830          "bom-ref": "pkg:npm/libnpmhook@8.0.4?package-id=5679bee9e2f7003c",
168831          "supplier": {},
168832          "author": "GitHub Inc.",
168833          "name": "libnpmhook",
168834          "version": "8.0.4",
168835          "description": "programmatic API for managing npm registry hooks",
168836          "licenses": [
168837            {
168838              "license": {
168839                "id": "ISC"
168840              }
168841            }
168842          ],
168843          "cpe": "cpe:2.3:a:libnpmhook:libnpmhook:8.0.4:*:*:*:*:*:*:*",
168844          "purl": "pkg:npm/libnpmhook@8.0.4",
168845          "swid": {
168846            "attachment": {}
168847          },
168848          "pedigree": {},
168849          "externalReferences": [
168850            {
168851              "url": "https://github.com/npm/cli.git",
168852              "type": "distribution"
168853            }
168854          ],
168855          "evidence": {},
168856          "signature": {
168857            "signature": {
168858              "publicKey": {}
168859            }
168860          },
168861          "modelCard": {
168862            "modelParameters": {
168863              "approach": {}
168864            },
168865            "quantitativeAnalysis": {
168866              "graphics": {}
168867            },
168868            "considerations": {}
168869          }
168870        },
168871        {
168872          "type": "library",
168873          "bom-ref": "pkg:npm/libnpmorg@4.0.4?package-id=80c945656f22ba9d",
168874          "supplier": {},
168875          "author": "GitHub Inc.",
168876          "name": "libnpmorg",
168877          "version": "4.0.4",
168878          "description": "Programmatic api for `npm org` commands",
168879          "licenses": [
168880            {
168881              "license": {
168882                "id": "ISC"
168883              }
168884            }
168885          ],
168886          "cpe": "cpe:2.3:a:libnpmorg:libnpmorg:4.0.4:*:*:*:*:*:*:*",
168887          "purl": "pkg:npm/libnpmorg@4.0.4",
168888          "swid": {
168889            "attachment": {}
168890          },
168891          "pedigree": {},
168892          "externalReferences": [
168893            {
168894              "url": "https://github.com/npm/cli.git",
168895              "type": "distribution"
168896            },
168897            {
168898              "url": "https://npmjs.com/package/libnpmorg",
168899              "type": "website"
168900            }
168901          ],
168902          "evidence": {},
168903          "signature": {
168904            "signature": {
168905              "publicKey": {}
168906            }
168907          },
168908          "modelCard": {
168909            "modelParameters": {
168910              "approach": {}
168911            },
168912            "quantitativeAnalysis": {
168913              "graphics": {}
168914            },
168915            "considerations": {}
168916          }
168917        },
168918        {
168919          "type": "library",
168920          "bom-ref": "pkg:npm/libnpmpack@4.1.3?package-id=62f6985b14d7de3e",
168921          "supplier": {},
168922          "author": "GitHub Inc.",
168923          "name": "libnpmpack",
168924          "version": "4.1.3",
168925          "description": "Programmatic API for the bits behind npm pack",
168926          "licenses": [
168927            {
168928              "license": {
168929                "id": "ISC"
168930              }
168931            }
168932          ],
168933          "cpe": "cpe:2.3:a:libnpmpack:libnpmpack:4.1.3:*:*:*:*:*:*:*",
168934          "purl": "pkg:npm/libnpmpack@4.1.3",
168935          "swid": {
168936            "attachment": {}
168937          },
168938          "pedigree": {},
168939          "externalReferences": [
168940            {
168941              "url": "https://github.com/npm/cli.git",
168942              "type": "distribution"
168943            },
168944            {
168945              "url": "https://npmjs.com/package/libnpmpack",
168946              "type": "website"
168947            }
168948          ],
168949          "evidence": {},
168950          "signature": {
168951            "signature": {
168952              "publicKey": {}
168953            }
168954          },
168955          "modelCard": {
168956            "modelParameters": {
168957              "approach": {}
168958            },
168959            "quantitativeAnalysis": {
168960              "graphics": {}
168961            },
168962            "considerations": {}
168963          }
168964        },
168965        {
168966          "type": "library",
168967          "bom-ref": "pkg:npm/libnpmpublish@6.0.5?package-id=a970d9d2bf422a57",
168968          "supplier": {},
168969          "author": "GitHub Inc.",
168970          "name": "libnpmpublish",
168971          "version": "6.0.5",
168972          "description": "Programmatic API for the bits behind npm publish and unpublish",
168973          "licenses": [
168974            {
168975              "license": {
168976                "id": "ISC"
168977              }
168978            }
168979          ],
168980          "cpe": "cpe:2.3:a:libnpmpublish:libnpmpublish:6.0.5:*:*:*:*:*:*:*",
168981          "purl": "pkg:npm/libnpmpublish@6.0.5",
168982          "swid": {
168983            "attachment": {}
168984          },
168985          "pedigree": {},
168986          "externalReferences": [
168987            {
168988              "url": "https://github.com/npm/cli.git",
168989              "type": "distribution"
168990            },
168991            {
168992              "url": "https://npmjs.com/package/libnpmpublish",
168993              "type": "website"
168994            }
168995          ],
168996          "evidence": {},
168997          "signature": {
168998            "signature": {
168999              "publicKey": {}
169000            }
169001          },
169002          "modelCard": {
169003            "modelParameters": {
169004              "approach": {}
169005            },
169006            "quantitativeAnalysis": {
169007              "graphics": {}
169008            },
169009            "considerations": {}
169010          }
169011        },
169012        {
169013          "type": "library",
169014          "bom-ref": "pkg:npm/libnpmsearch@5.0.4?package-id=e3666452dd7e585d",
169015          "supplier": {},
169016          "author": "GitHub Inc.",
169017          "name": "libnpmsearch",
169018          "version": "5.0.4",
169019          "description": "Programmatic API for searching in npm and compatible registries.",
169020          "licenses": [
169021            {
169022              "license": {
169023                "id": "ISC"
169024              }
169025            }
169026          ],
169027          "cpe": "cpe:2.3:a:libnpmsearch:libnpmsearch:5.0.4:*:*:*:*:*:*:*",
169028          "purl": "pkg:npm/libnpmsearch@5.0.4",
169029          "swid": {
169030            "attachment": {}
169031          },
169032          "pedigree": {},
169033          "externalReferences": [
169034            {
169035              "url": "https://github.com/npm/cli.git",
169036              "type": "distribution"
169037            },
169038            {
169039              "url": "https://npmjs.com/package/libnpmsearch",
169040              "type": "website"
169041            }
169042          ],
169043          "evidence": {},
169044          "signature": {
169045            "signature": {
169046              "publicKey": {}
169047            }
169048          },
169049          "modelCard": {
169050            "modelParameters": {
169051              "approach": {}
169052            },
169053            "quantitativeAnalysis": {
169054              "graphics": {}
169055            },
169056            "considerations": {}
169057          }
169058        },
169059        {
169060          "type": "library",
169061          "bom-ref": "pkg:npm/libnpmteam@4.0.4?package-id=95c3c29c4dcd60d1",
169062          "supplier": {},
169063          "author": "GitHub Inc.",
169064          "name": "libnpmteam",
169065          "version": "4.0.4",
169066          "description": "npm Team management APIs",
169067          "licenses": [
169068            {
169069              "license": {
169070                "id": "ISC"
169071              }
169072            }
169073          ],
169074          "cpe": "cpe:2.3:a:libnpmteam:libnpmteam:4.0.4:*:*:*:*:*:*:*",
169075          "purl": "pkg:npm/libnpmteam@4.0.4",
169076          "swid": {
169077            "attachment": {}
169078          },
169079          "pedigree": {},
169080          "externalReferences": [
169081            {
169082              "url": "https://github.com/npm/cli.git",
169083              "type": "distribution"
169084            },
169085            {
169086              "url": "https://npmjs.com/package/libnpmteam",
169087              "type": "website"
169088            }
169089          ],
169090          "evidence": {},
169091          "signature": {
169092            "signature": {
169093              "publicKey": {}
169094            }
169095          },
169096          "modelCard": {
169097            "modelParameters": {
169098              "approach": {}
169099            },
169100            "quantitativeAnalysis": {
169101              "graphics": {}
169102            },
169103            "considerations": {}
169104          }
169105        },
169106        {
169107          "type": "library",
169108          "bom-ref": "pkg:npm/libnpmversion@3.0.7?package-id=9ace162e3f4ca294",
169109          "supplier": {},
169110          "author": "GitHub Inc.",
169111          "name": "libnpmversion",
169112          "version": "3.0.7",
169113          "description": "library to do the things that 'npm version' does",
169114          "licenses": [
169115            {
169116              "license": {
169117                "id": "ISC"
169118              }
169119            }
169120          ],
169121          "cpe": "cpe:2.3:a:libnpmversion:libnpmversion:3.0.7:*:*:*:*:*:*:*",
169122          "purl": "pkg:npm/libnpmversion@3.0.7",
169123          "swid": {
169124            "attachment": {}
169125          },
169126          "pedigree": {},
169127          "externalReferences": [
169128            {
169129              "url": "https://github.com/npm/cli.git",
169130              "type": "distribution"
169131            }
169132          ],
169133          "evidence": {},
169134          "signature": {
169135            "signature": {
169136              "publicKey": {}
169137            }
169138          },
169139          "modelCard": {
169140            "modelParameters": {
169141              "approach": {}
169142            },
169143            "quantitativeAnalysis": {
169144              "graphics": {}
169145            },
169146            "considerations": {}
169147          }
169148        },
169149        {
169150          "type": "library",
169151          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=609cb94e63dc06dd",
169152          "supplier": {},
169153          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
169154          "name": "libssl1.1",
169155          "version": "1.1.1t-r2",
169156          "description": "SSL shared libraries",
169157          "licenses": [
169158            {
169159              "license": {
169160                "id": "OpenSSL"
169161              }
169162            }
169163          ],
169164          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1t-r2:*:*:*:*:*:*:*",
169165          "purl": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
169166          "swid": {
169167            "attachment": {}
169168          },
169169          "pedigree": {},
169170          "externalReferences": [
169171            {
169172              "url": "https://www.openssl.org/",
169173              "type": "distribution"
169174            }
169175          ],
169176          "evidence": {},
169177          "signature": {
169178            "signature": {
169179              "publicKey": {}
169180            }
169181          },
169182          "modelCard": {
169183            "modelParameters": {
169184              "approach": {}
169185            },
169186            "quantitativeAnalysis": {
169187              "graphics": {}
169188            },
169189            "considerations": {}
169190          }
169191        },
169192        {
169193          "type": "library",
169194          "bom-ref": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=9913678ca8fd323d",
169195          "supplier": {},
169196          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
169197          "name": "libstdc++",
169198          "version": "11.2.1_git20220219-r2",
169199          "description": "GNU C++ standard runtime library",
169200          "licenses": [
169201            {
169202              "license": {
169203                "id": "GPL-2.0-or-later"
169204              }
169205            },
169206            {
169207              "license": {
169208                "id": "LGPL-2.1-or-later"
169209              }
169210            }
169211          ],
169212          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
169213          "purl": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
169214          "swid": {
169215            "attachment": {}
169216          },
169217          "pedigree": {},
169218          "externalReferences": [
169219            {
169220              "url": "https://gcc.gnu.org",
169221              "type": "distribution"
169222            }
169223          ],
169224          "evidence": {},
169225          "signature": {
169226            "signature": {
169227              "publicKey": {}
169228            }
169229          },
169230          "modelCard": {
169231            "modelParameters": {
169232              "approach": {}
169233            },
169234            "quantitativeAnalysis": {
169235              "graphics": {}
169236            },
169237            "considerations": {}
169238          }
169239        },
169240        {
169241          "type": "library",
169242          "bom-ref": "pkg:npm/lie@3.3.0?package-id=db03f266d31d486e",
169243          "supplier": {},
169244          "name": "lie",
169245          "version": "3.3.0",
169246          "description": "A basic but performant promise implementation",
169247          "licenses": [
169248            {
169249              "license": {
169250                "id": "MIT"
169251              }
169252            }
169253          ],
169254          "cpe": "cpe:2.3:a:calvinmetcalf:lie:3.3.0:*:*:*:*:*:*:*",
169255          "purl": "pkg:npm/lie@3.3.0",
169256          "swid": {
169257            "attachment": {}
169258          },
169259          "pedigree": {},
169260          "externalReferences": [
169261            {
169262              "url": "https://github.com/calvinmetcalf/lie.git",
169263              "type": "distribution"
169264            }
169265          ],
169266          "evidence": {},
169267          "signature": {
169268            "signature": {
169269              "publicKey": {}
169270            }
169271          },
169272          "modelCard": {
169273            "modelParameters": {
169274              "approach": {}
169275            },
169276            "quantitativeAnalysis": {
169277              "graphics": {}
169278            },
169279            "considerations": {}
169280          }
169281        },
169282        {
169283          "type": "library",
169284          "bom-ref": "pkg:npm/lines-and-columns@1.2.4?package-id=e16b7bf0fe2bdb56",
169285          "supplier": {},
169286          "author": "Brian Donovan \u003cbrian@donovans.cc\u003e",
169287          "name": "lines-and-columns",
169288          "version": "1.2.4",
169289          "description": "Maps lines and columns to character offsets and back.",
169290          "licenses": [
169291            {
169292              "license": {
169293                "id": "MIT"
169294              }
169295            }
169296          ],
169297          "cpe": "cpe:2.3:a:lines-and-columns:lines-and-columns:1.2.4:*:*:*:*:*:*:*",
169298          "purl": "pkg:npm/lines-and-columns@1.2.4",
169299          "swid": {
169300            "attachment": {}
169301          },
169302          "pedigree": {},
169303          "externalReferences": [
169304            {
169305              "url": "https://github.com/eventualbuddha/lines-and-columns.git",
169306              "type": "distribution"
169307            },
169308            {
169309              "url": "https://github.com/eventualbuddha/lines-and-columns#readme",
169310              "type": "website"
169311            }
169312          ],
169313          "evidence": {},
169314          "signature": {
169315            "signature": {
169316              "publicKey": {}
169317            }
169318          },
169319          "modelCard": {
169320            "modelParameters": {
169321              "approach": {}
169322            },
169323            "quantitativeAnalysis": {
169324              "graphics": {}
169325            },
169326            "considerations": {}
169327          }
169328        },
169329        {
169330          "type": "library",
169331          "bom-ref": "pkg:npm/locate-path@3.0.0?package-id=a657b1478ede4b77",
169332          "supplier": {},
169333          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
169334          "name": "locate-path",
169335          "version": "3.0.0",
169336          "description": "Get the first path that exists on disk of multiple paths",
169337          "licenses": [
169338            {
169339              "license": {
169340                "id": "MIT"
169341              }
169342            }
169343          ],
169344          "cpe": "cpe:2.3:a:locate-path:locate-path:3.0.0:*:*:*:*:*:*:*",
169345          "purl": "pkg:npm/locate-path@3.0.0",
169346          "swid": {
169347            "attachment": {}
169348          },
169349          "pedigree": {},
169350          "externalReferences": [
169351            {
169352              "url": "sindresorhus/locate-path",
169353              "type": "distribution"
169354            }
169355          ],
169356          "evidence": {},
169357          "signature": {
169358            "signature": {
169359              "publicKey": {}
169360            }
169361          },
169362          "modelCard": {
169363            "modelParameters": {
169364              "approach": {}
169365            },
169366            "quantitativeAnalysis": {
169367              "graphics": {}
169368            },
169369            "considerations": {}
169370          }
169371        },
169372        {
169373          "type": "library",
169374          "bom-ref": "pkg:npm/locate-path@5.0.0?package-id=622f665a0bf0d8bd",
169375          "supplier": {},
169376          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
169377          "name": "locate-path",
169378          "version": "5.0.0",
169379          "description": "Get the first path that exists on disk of multiple paths",
169380          "licenses": [
169381            {
169382              "license": {
169383                "id": "MIT"
169384              }
169385            }
169386          ],
169387          "cpe": "cpe:2.3:a:locate-path:locate-path:5.0.0:*:*:*:*:*:*:*",
169388          "purl": "pkg:npm/locate-path@5.0.0",
169389          "swid": {
169390            "attachment": {}
169391          },
169392          "pedigree": {},
169393          "externalReferences": [
169394            {
169395              "url": "sindresorhus/locate-path",
169396              "type": "distribution"
169397            }
169398          ],
169399          "evidence": {},
169400          "signature": {
169401            "signature": {
169402              "publicKey": {}
169403            }
169404          },
169405          "modelCard": {
169406            "modelParameters": {
169407              "approach": {}
169408            },
169409            "quantitativeAnalysis": {
169410              "graphics": {}
169411            },
169412            "considerations": {}
169413          }
169414        },
169415        {
169416          "type": "library",
169417          "bom-ref": "pkg:npm/lodash@4.17.21?package-id=75dfb844472e21c2",
169418          "supplier": {},
169419          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e",
169420          "name": "lodash",
169421          "version": "4.17.21",
169422          "description": "Lodash modular utilities.",
169423          "licenses": [
169424            {
169425              "license": {
169426                "id": "MIT"
169427              }
169428            }
169429          ],
169430          "cpe": "cpe:2.3:a:lodash:lodash:4.17.21:*:*:*:*:*:*:*",
169431          "purl": "pkg:npm/lodash@4.17.21",
169432          "swid": {
169433            "attachment": {}
169434          },
169435          "pedigree": {},
169436          "externalReferences": [
169437            {
169438              "url": "lodash/lodash",
169439              "type": "distribution"
169440            },
169441            {
169442              "url": "https://lodash.com/",
169443              "type": "website"
169444            }
169445          ],
169446          "evidence": {},
169447          "signature": {
169448            "signature": {
169449              "publicKey": {}
169450            }
169451          },
169452          "modelCard": {
169453            "modelParameters": {
169454              "approach": {}
169455            },
169456            "quantitativeAnalysis": {
169457              "graphics": {}
169458            },
169459            "considerations": {}
169460          }
169461        },
169462        {
169463          "type": "library",
169464          "bom-ref": "pkg:npm/lru-cache@6.0.0?package-id=a9db11b8d6d48a85",
169465          "supplier": {},
169466          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
169467          "name": "lru-cache",
169468          "version": "6.0.0",
169469          "description": "A cache object that deletes the least-recently-used items.",
169470          "licenses": [
169471            {
169472              "license": {
169473                "id": "ISC"
169474              }
169475            }
169476          ],
169477          "cpe": "cpe:2.3:a:lru-cache:lru-cache:6.0.0:*:*:*:*:*:*:*",
169478          "purl": "pkg:npm/lru-cache@6.0.0",
169479          "swid": {
169480            "attachment": {}
169481          },
169482          "pedigree": {},
169483          "externalReferences": [
169484            {
169485              "url": "git://github.com/isaacs/node-lru-cache.git",
169486              "type": "distribution"
169487            }
169488          ],
169489          "evidence": {},
169490          "signature": {
169491            "signature": {
169492              "publicKey": {}
169493            }
169494          },
169495          "modelCard": {
169496            "modelParameters": {
169497              "approach": {}
169498            },
169499            "quantitativeAnalysis": {
169500              "graphics": {}
169501            },
169502            "considerations": {}
169503          }
169504        },
169505        {
169506          "type": "library",
169507          "bom-ref": "pkg:npm/lru-cache@6.0.0?package-id=c938bdb42f7a80e2",
169508          "supplier": {},
169509          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
169510          "name": "lru-cache",
169511          "version": "6.0.0",
169512          "description": "A cache object that deletes the least-recently-used items.",
169513          "licenses": [
169514            {
169515              "license": {
169516                "id": "ISC"
169517              }
169518            }
169519          ],
169520          "cpe": "cpe:2.3:a:lru-cache:lru-cache:6.0.0:*:*:*:*:*:*:*",
169521          "purl": "pkg:npm/lru-cache@6.0.0",
169522          "swid": {
169523            "attachment": {}
169524          },
169525          "pedigree": {},
169526          "externalReferences": [
169527            {
169528              "url": "git://github.com/isaacs/node-lru-cache.git",
169529              "type": "distribution"
169530            }
169531          ],
169532          "evidence": {},
169533          "signature": {
169534            "signature": {
169535              "publicKey": {}
169536            }
169537          },
169538          "modelCard": {
169539            "modelParameters": {
169540              "approach": {}
169541            },
169542            "quantitativeAnalysis": {
169543              "graphics": {}
169544            },
169545            "considerations": {}
169546          }
169547        },
169548        {
169549          "type": "library",
169550          "bom-ref": "pkg:npm/lru-cache@7.13.2?package-id=be5c7dc6ddace7cd",
169551          "supplier": {},
169552          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
169553          "name": "lru-cache",
169554          "version": "7.13.2",
169555          "description": "A cache object that deletes the least-recently-used items.",
169556          "licenses": [
169557            {
169558              "license": {
169559                "id": "ISC"
169560              }
169561            }
169562          ],
169563          "cpe": "cpe:2.3:a:lru-cache:lru-cache:7.13.2:*:*:*:*:*:*:*",
169564          "purl": "pkg:npm/lru-cache@7.13.2",
169565          "swid": {
169566            "attachment": {}
169567          },
169568          "pedigree": {},
169569          "externalReferences": [
169570            {
169571              "url": "git://github.com/isaacs/node-lru-cache.git",
169572              "type": "distribution"
169573            }
169574          ],
169575          "evidence": {},
169576          "signature": {
169577            "signature": {
169578              "publicKey": {}
169579            }
169580          },
169581          "modelCard": {
169582            "modelParameters": {
169583              "approach": {}
169584            },
169585            "quantitativeAnalysis": {
169586              "graphics": {}
169587            },
169588            "considerations": {}
169589          }
169590        },
169591        {
169592          "type": "library",
169593          "bom-ref": "pkg:npm/make-fetch-happen@10.2.1?package-id=d230079dee920278",
169594          "supplier": {},
169595          "author": "GitHub Inc.",
169596          "name": "make-fetch-happen",
169597          "version": "10.2.1",
169598          "description": "Opinionated, caching, retrying fetch client",
169599          "licenses": [
169600            {
169601              "license": {
169602                "id": "ISC"
169603              }
169604            }
169605          ],
169606          "cpe": "cpe:2.3:a:make-fetch-happen:make-fetch-happen:10.2.1:*:*:*:*:*:*:*",
169607          "purl": "pkg:npm/make-fetch-happen@10.2.1",
169608          "swid": {
169609            "attachment": {}
169610          },
169611          "pedigree": {},
169612          "externalReferences": [
169613            {
169614              "url": "https://github.com/npm/make-fetch-happen.git",
169615              "type": "distribution"
169616            }
169617          ],
169618          "evidence": {},
169619          "signature": {
169620            "signature": {
169621              "publicKey": {}
169622            }
169623          },
169624          "modelCard": {
169625            "modelParameters": {
169626              "approach": {}
169627            },
169628            "quantitativeAnalysis": {
169629              "graphics": {}
169630            },
169631            "considerations": {}
169632          }
169633        },
169634        {
169635          "type": "library",
169636          "bom-ref": "pkg:npm/map-obj@1.0.1?package-id=d9b58c3f7e7ee73",
169637          "supplier": {},
169638          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
169639          "name": "map-obj",
169640          "version": "1.0.1",
169641          "description": "Map object keys and values into a new object",
169642          "licenses": [
169643            {
169644              "license": {
169645                "id": "MIT"
169646              }
169647            }
169648          ],
169649          "cpe": "cpe:2.3:a:map-obj:map-obj:1.0.1:*:*:*:*:*:*:*",
169650          "purl": "pkg:npm/map-obj@1.0.1",
169651          "swid": {
169652            "attachment": {}
169653          },
169654          "pedigree": {},
169655          "externalReferences": [
169656            {
169657              "url": "sindresorhus/map-obj",
169658              "type": "distribution"
169659            }
169660          ],
169661          "evidence": {},
169662          "signature": {
169663            "signature": {
169664              "publicKey": {}
169665            }
169666          },
169667          "modelCard": {
169668            "modelParameters": {
169669              "approach": {}
169670            },
169671            "quantitativeAnalysis": {
169672              "graphics": {}
169673            },
169674            "considerations": {}
169675          }
169676        },
169677        {
169678          "type": "library",
169679          "bom-ref": "pkg:npm/map-obj@4.3.0?package-id=e650deaf663debbb",
169680          "supplier": {},
169681          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
169682          "name": "map-obj",
169683          "version": "4.3.0",
169684          "description": "Map object keys and values into a new object",
169685          "licenses": [
169686            {
169687              "license": {
169688                "id": "MIT"
169689              }
169690            }
169691          ],
169692          "cpe": "cpe:2.3:a:map-obj:map-obj:4.3.0:*:*:*:*:*:*:*",
169693          "purl": "pkg:npm/map-obj@4.3.0",
169694          "swid": {
169695            "attachment": {}
169696          },
169697          "pedigree": {},
169698          "externalReferences": [
169699            {
169700              "url": "sindresorhus/map-obj",
169701              "type": "distribution"
169702            }
169703          ],
169704          "evidence": {},
169705          "signature": {
169706            "signature": {
169707              "publicKey": {}
169708            }
169709          },
169710          "modelCard": {
169711            "modelParameters": {
169712              "approach": {}
169713            },
169714            "quantitativeAnalysis": {
169715              "graphics": {}
169716            },
169717            "considerations": {}
169718          }
169719        },
169720        {
169721          "type": "library",
169722          "bom-ref": "pkg:npm/media-typer@0.3.0?package-id=edc1220ee5504fb4",
169723          "supplier": {},
169724          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
169725          "name": "media-typer",
169726          "version": "0.3.0",
169727          "description": "Simple RFC 6838 media type parser and formatter",
169728          "licenses": [
169729            {
169730              "license": {
169731                "id": "MIT"
169732              }
169733            }
169734          ],
169735          "cpe": "cpe:2.3:a:media-typer:media-typer:0.3.0:*:*:*:*:*:*:*",
169736          "purl": "pkg:npm/media-typer@0.3.0",
169737          "swid": {
169738            "attachment": {}
169739          },
169740          "pedigree": {},
169741          "externalReferences": [
169742            {
169743              "url": "jshttp/media-typer",
169744              "type": "distribution"
169745            }
169746          ],
169747          "evidence": {},
169748          "signature": {
169749            "signature": {
169750              "publicKey": {}
169751            }
169752          },
169753          "modelCard": {
169754            "modelParameters": {
169755              "approach": {}
169756            },
169757            "quantitativeAnalysis": {
169758              "graphics": {}
169759            },
169760            "considerations": {}
169761          }
169762        },
169763        {
169764          "type": "library",
169765          "bom-ref": "pkg:npm/meow@9.0.0?package-id=35513e503f8dd60b",
169766          "supplier": {},
169767          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
169768          "name": "meow",
169769          "version": "9.0.0",
169770          "description": "CLI app helper",
169771          "licenses": [
169772            {
169773              "license": {
169774                "id": "MIT"
169775              }
169776            }
169777          ],
169778          "cpe": "cpe:2.3:a:meow:meow:9.0.0:*:*:*:*:*:*:*",
169779          "purl": "pkg:npm/meow@9.0.0",
169780          "swid": {
169781            "attachment": {}
169782          },
169783          "pedigree": {},
169784          "externalReferences": [
169785            {
169786              "url": "sindresorhus/meow",
169787              "type": "distribution"
169788            }
169789          ],
169790          "evidence": {},
169791          "signature": {
169792            "signature": {
169793              "publicKey": {}
169794            }
169795          },
169796          "modelCard": {
169797            "modelParameters": {
169798              "approach": {}
169799            },
169800            "quantitativeAnalysis": {
169801              "graphics": {}
169802            },
169803            "considerations": {}
169804          }
169805        },
169806        {
169807          "type": "library",
169808          "bom-ref": "pkg:npm/merge-descriptors@1.0.1?package-id=24f38b1ffa4b7603",
169809          "supplier": {},
169810          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
169811          "name": "merge-descriptors",
169812          "version": "1.0.1",
169813          "description": "Merge objects using descriptors",
169814          "licenses": [
169815            {
169816              "license": {
169817                "id": "MIT"
169818              }
169819            }
169820          ],
169821          "cpe": "cpe:2.3:a:merge-descriptors:merge-descriptors:1.0.1:*:*:*:*:*:*:*",
169822          "purl": "pkg:npm/merge-descriptors@1.0.1",
169823          "swid": {
169824            "attachment": {}
169825          },
169826          "pedigree": {},
169827          "externalReferences": [
169828            {
169829              "url": "component/merge-descriptors",
169830              "type": "distribution"
169831            }
169832          ],
169833          "evidence": {},
169834          "signature": {
169835            "signature": {
169836              "publicKey": {}
169837            }
169838          },
169839          "modelCard": {
169840            "modelParameters": {
169841              "approach": {}
169842            },
169843            "quantitativeAnalysis": {
169844              "graphics": {}
169845            },
169846            "considerations": {}
169847          }
169848        },
169849        {
169850          "type": "library",
169851          "bom-ref": "pkg:npm/methods@1.1.2?package-id=9b85a46f19a1f1aa",
169852          "supplier": {},
169853          "name": "methods",
169854          "version": "1.1.2",
169855          "description": "HTTP methods that node supports",
169856          "licenses": [
169857            {
169858              "license": {
169859                "id": "MIT"
169860              }
169861            }
169862          ],
169863          "cpe": "cpe:2.3:a:methods:methods:1.1.2:*:*:*:*:*:*:*",
169864          "purl": "pkg:npm/methods@1.1.2",
169865          "swid": {
169866            "attachment": {}
169867          },
169868          "pedigree": {},
169869          "externalReferences": [
169870            {
169871              "url": "jshttp/methods",
169872              "type": "distribution"
169873            }
169874          ],
169875          "evidence": {},
169876          "signature": {
169877            "signature": {
169878              "publicKey": {}
169879            }
169880          },
169881          "modelCard": {
169882            "modelParameters": {
169883              "approach": {}
169884            },
169885            "quantitativeAnalysis": {
169886              "graphics": {}
169887            },
169888            "considerations": {}
169889          }
169890        },
169891        {
169892          "type": "library",
169893          "bom-ref": "pkg:npm/mime@1.6.0?package-id=f48c5ee033535ed4",
169894          "supplier": {},
169895          "author": "Robert Kieffer \u003crobert@broofa.com\u003e (http://github.com/broofa)",
169896          "name": "mime",
169897          "version": "1.6.0",
169898          "description": "A comprehensive library for mime-type mapping",
169899          "licenses": [
169900            {
169901              "license": {
169902                "id": "MIT"
169903              }
169904            }
169905          ],
169906          "cpe": "cpe:2.3:a:broofa:mime:1.6.0:*:*:*:*:*:*:*",
169907          "purl": "pkg:npm/mime@1.6.0",
169908          "swid": {
169909            "attachment": {}
169910          },
169911          "pedigree": {},
169912          "externalReferences": [
169913            {
169914              "url": "https://github.com/broofa/node-mime",
169915              "type": "distribution"
169916            }
169917          ],
169918          "evidence": {},
169919          "signature": {
169920            "signature": {
169921              "publicKey": {}
169922            }
169923          },
169924          "modelCard": {
169925            "modelParameters": {
169926              "approach": {}
169927            },
169928            "quantitativeAnalysis": {
169929              "graphics": {}
169930            },
169931            "considerations": {}
169932          }
169933        },
169934        {
169935          "type": "library",
169936          "bom-ref": "pkg:npm/mime-db@1.40.0?package-id=bee1749d3adba611",
169937          "supplier": {},
169938          "name": "mime-db",
169939          "version": "1.40.0",
169940          "description": "Media Type Database",
169941          "licenses": [
169942            {
169943              "license": {
169944                "id": "MIT"
169945              }
169946            }
169947          ],
169948          "cpe": "cpe:2.3:a:mime-db:mime-db:1.40.0:*:*:*:*:*:*:*",
169949          "purl": "pkg:npm/mime-db@1.40.0",
169950          "swid": {
169951            "attachment": {}
169952          },
169953          "pedigree": {},
169954          "externalReferences": [
169955            {
169956              "url": "jshttp/mime-db",
169957              "type": "distribution"
169958            }
169959          ],
169960          "evidence": {},
169961          "signature": {
169962            "signature": {
169963              "publicKey": {}
169964            }
169965          },
169966          "modelCard": {
169967            "modelParameters": {
169968              "approach": {}
169969            },
169970            "quantitativeAnalysis": {
169971              "graphics": {}
169972            },
169973            "considerations": {}
169974          }
169975        },
169976        {
169977          "type": "library",
169978          "bom-ref": "pkg:npm/mime-types@2.1.24?package-id=ba2ec9e915a8563f",
169979          "supplier": {},
169980          "name": "mime-types",
169981          "version": "2.1.24",
169982          "description": "The ultimate javascript content-type utility.",
169983          "licenses": [
169984            {
169985              "license": {
169986                "id": "MIT"
169987              }
169988            }
169989          ],
169990          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.24:*:*:*:*:*:*:*",
169991          "purl": "pkg:npm/mime-types@2.1.24",
169992          "swid": {
169993            "attachment": {}
169994          },
169995          "pedigree": {},
169996          "externalReferences": [
169997            {
169998              "url": "jshttp/mime-types",
169999              "type": "distribution"
170000            }
170001          ],
170002          "evidence": {},
170003          "signature": {
170004            "signature": {
170005              "publicKey": {}
170006            }
170007          },
170008          "modelCard": {
170009            "modelParameters": {
170010              "approach": {}
170011            },
170012            "quantitativeAnalysis": {
170013              "graphics": {}
170014            },
170015            "considerations": {}
170016          }
170017        },
170018        {
170019          "type": "library",
170020          "bom-ref": "pkg:npm/min-indent@1.0.1?package-id=b027336927e7884d",
170021          "supplier": {},
170022          "author": "James Kyle \u003cme@thejameskyle.com\u003e (thejameskyle.com)",
170023          "name": "min-indent",
170024          "version": "1.0.1",
170025          "description": "Get the shortest leading whitespace from lines in a string",
170026          "licenses": [
170027            {
170028              "license": {
170029                "id": "MIT"
170030              }
170031            }
170032          ],
170033          "cpe": "cpe:2.3:a:thejameskyle:min-indent:1.0.1:*:*:*:*:*:*:*",
170034          "purl": "pkg:npm/min-indent@1.0.1",
170035          "swid": {
170036            "attachment": {}
170037          },
170038          "pedigree": {},
170039          "externalReferences": [
170040            {
170041              "url": "https://github.com/thejameskyle/min-indent",
170042              "type": "distribution"
170043            }
170044          ],
170045          "evidence": {},
170046          "signature": {
170047            "signature": {
170048              "publicKey": {}
170049            }
170050          },
170051          "modelCard": {
170052            "modelParameters": {
170053              "approach": {}
170054            },
170055            "quantitativeAnalysis": {
170056              "graphics": {}
170057            },
170058            "considerations": {}
170059          }
170060        },
170061        {
170062          "type": "library",
170063          "bom-ref": "pkg:npm/minimatch@3.0.8?package-id=6eafef7f6398a3e6",
170064          "supplier": {},
170065          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
170066          "name": "minimatch",
170067          "version": "3.0.8",
170068          "description": "a glob matcher in javascript",
170069          "licenses": [
170070            {
170071              "license": {
170072                "id": "ISC"
170073              }
170074            }
170075          ],
170076          "cpe": "cpe:2.3:a:minimatch:minimatch:3.0.8:*:*:*:*:*:*:*",
170077          "purl": "pkg:npm/minimatch@3.0.8",
170078          "swid": {
170079            "attachment": {}
170080          },
170081          "pedigree": {},
170082          "externalReferences": [
170083            {
170084              "url": "git://github.com/isaacs/minimatch.git",
170085              "type": "distribution"
170086            }
170087          ],
170088          "evidence": {},
170089          "signature": {
170090            "signature": {
170091              "publicKey": {}
170092            }
170093          },
170094          "modelCard": {
170095            "modelParameters": {
170096              "approach": {}
170097            },
170098            "quantitativeAnalysis": {
170099              "graphics": {}
170100            },
170101            "considerations": {}
170102          }
170103        },
170104        {
170105          "type": "library",
170106          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=32b47b032f3721ab",
170107          "supplier": {},
170108          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
170109          "name": "minimatch",
170110          "version": "3.1.2",
170111          "description": "a glob matcher in javascript",
170112          "licenses": [
170113            {
170114              "license": {
170115                "id": "ISC"
170116              }
170117            }
170118          ],
170119          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
170120          "purl": "pkg:npm/minimatch@3.1.2",
170121          "swid": {
170122            "attachment": {}
170123          },
170124          "pedigree": {},
170125          "externalReferences": [
170126            {
170127              "url": "git://github.com/isaacs/minimatch.git",
170128              "type": "distribution"
170129            }
170130          ],
170131          "evidence": {},
170132          "signature": {
170133            "signature": {
170134              "publicKey": {}
170135            }
170136          },
170137          "modelCard": {
170138            "modelParameters": {
170139              "approach": {}
170140            },
170141            "quantitativeAnalysis": {
170142              "graphics": {}
170143            },
170144            "considerations": {}
170145          }
170146        },
170147        {
170148          "type": "library",
170149          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=7392185ecbfd5435",
170150          "supplier": {},
170151          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
170152          "name": "minimatch",
170153          "version": "3.1.2",
170154          "description": "a glob matcher in javascript",
170155          "licenses": [
170156            {
170157              "license": {
170158                "id": "ISC"
170159              }
170160            }
170161          ],
170162          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
170163          "purl": "pkg:npm/minimatch@3.1.2",
170164          "swid": {
170165            "attachment": {}
170166          },
170167          "pedigree": {},
170168          "externalReferences": [
170169            {
170170              "url": "git://github.com/isaacs/minimatch.git",
170171              "type": "distribution"
170172            }
170173          ],
170174          "evidence": {},
170175          "signature": {
170176            "signature": {
170177              "publicKey": {}
170178            }
170179          },
170180          "modelCard": {
170181            "modelParameters": {
170182              "approach": {}
170183            },
170184            "quantitativeAnalysis": {
170185              "graphics": {}
170186            },
170187            "considerations": {}
170188          }
170189        },
170190        {
170191          "type": "library",
170192          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=6b4731ea6f19e173",
170193          "supplier": {},
170194          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
170195          "name": "minimatch",
170196          "version": "3.1.2",
170197          "description": "a glob matcher in javascript",
170198          "licenses": [
170199            {
170200              "license": {
170201                "id": "ISC"
170202              }
170203            }
170204          ],
170205          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
170206          "purl": "pkg:npm/minimatch@3.1.2",
170207          "swid": {
170208            "attachment": {}
170209          },
170210          "pedigree": {},
170211          "externalReferences": [
170212            {
170213              "url": "git://github.com/isaacs/minimatch.git",
170214              "type": "distribution"
170215            }
170216          ],
170217          "evidence": {},
170218          "signature": {
170219            "signature": {
170220              "publicKey": {}
170221            }
170222          },
170223          "modelCard": {
170224            "modelParameters": {
170225              "approach": {}
170226            },
170227            "quantitativeAnalysis": {
170228              "graphics": {}
170229            },
170230            "considerations": {}
170231          }
170232        },
170233        {
170234          "type": "library",
170235          "bom-ref": "pkg:npm/minimatch@5.1.0?package-id=7bf8dbc1a2543e83",
170236          "supplier": {},
170237          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
170238          "name": "minimatch",
170239          "version": "5.1.0",
170240          "description": "a glob matcher in javascript",
170241          "licenses": [
170242            {
170243              "license": {
170244                "id": "ISC"
170245              }
170246            }
170247          ],
170248          "cpe": "cpe:2.3:a:minimatch:minimatch:5.1.0:*:*:*:*:*:*:*",
170249          "purl": "pkg:npm/minimatch@5.1.0",
170250          "swid": {
170251            "attachment": {}
170252          },
170253          "pedigree": {},
170254          "externalReferences": [
170255            {
170256              "url": "git://github.com/isaacs/minimatch.git",
170257              "type": "distribution"
170258            }
170259          ],
170260          "evidence": {},
170261          "signature": {
170262            "signature": {
170263              "publicKey": {}
170264            }
170265          },
170266          "modelCard": {
170267            "modelParameters": {
170268              "approach": {}
170269            },
170270            "quantitativeAnalysis": {
170271              "graphics": {}
170272            },
170273            "considerations": {}
170274          }
170275        },
170276        {
170277          "type": "library",
170278          "bom-ref": "pkg:npm/minimist-options@4.1.0?package-id=d615d77b50850421",
170279          "supplier": {},
170280          "author": "Vadim Demedes \u003cvdemedes@gmail.com\u003e",
170281          "name": "minimist-options",
170282          "version": "4.1.0",
170283          "description": "Pretty options for minimist",
170284          "licenses": [
170285            {
170286              "license": {
170287                "id": "MIT"
170288              }
170289            }
170290          ],
170291          "cpe": "cpe:2.3:a:minimist-options:minimist-options:4.1.0:*:*:*:*:*:*:*",
170292          "purl": "pkg:npm/minimist-options@4.1.0",
170293          "swid": {
170294            "attachment": {}
170295          },
170296          "pedigree": {},
170297          "externalReferences": [
170298            {
170299              "url": "vadimdemedes/minimist-options",
170300              "type": "distribution"
170301            }
170302          ],
170303          "evidence": {},
170304          "signature": {
170305            "signature": {
170306              "publicKey": {}
170307            }
170308          },
170309          "modelCard": {
170310            "modelParameters": {
170311              "approach": {}
170312            },
170313            "quantitativeAnalysis": {
170314              "graphics": {}
170315            },
170316            "considerations": {}
170317          }
170318        },
170319        {
170320          "type": "library",
170321          "bom-ref": "pkg:npm/minipass@3.3.4?package-id=b613ca6e3e5e1fdb",
170322          "supplier": {},
170323          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
170324          "name": "minipass",
170325          "version": "3.3.4",
170326          "description": "minimal implementation of a PassThrough stream",
170327          "licenses": [
170328            {
170329              "license": {
170330                "id": "ISC"
170331              }
170332            }
170333          ],
170334          "cpe": "cpe:2.3:a:minipass:minipass:3.3.4:*:*:*:*:*:*:*",
170335          "purl": "pkg:npm/minipass@3.3.4",
170336          "swid": {
170337            "attachment": {}
170338          },
170339          "pedigree": {},
170340          "externalReferences": [
170341            {
170342              "url": "git+https://github.com/isaacs/minipass.git",
170343              "type": "distribution"
170344            }
170345          ],
170346          "evidence": {},
170347          "signature": {
170348            "signature": {
170349              "publicKey": {}
170350            }
170351          },
170352          "modelCard": {
170353            "modelParameters": {
170354              "approach": {}
170355            },
170356            "quantitativeAnalysis": {
170357              "graphics": {}
170358            },
170359            "considerations": {}
170360          }
170361        },
170362        {
170363          "type": "library",
170364          "bom-ref": "pkg:npm/minipass@3.3.6?package-id=cf3bc2db7652613b",
170365          "supplier": {},
170366          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
170367          "name": "minipass",
170368          "version": "3.3.6",
170369          "description": "minimal implementation of a PassThrough stream",
170370          "licenses": [
170371            {
170372              "license": {
170373                "id": "ISC"
170374              }
170375            }
170376          ],
170377          "cpe": "cpe:2.3:a:minipass:minipass:3.3.6:*:*:*:*:*:*:*",
170378          "purl": "pkg:npm/minipass@3.3.6",
170379          "swid": {
170380            "attachment": {}
170381          },
170382          "pedigree": {},
170383          "externalReferences": [
170384            {
170385              "url": "git+https://github.com/isaacs/minipass.git",
170386              "type": "distribution"
170387            }
170388          ],
170389          "evidence": {},
170390          "signature": {
170391            "signature": {
170392              "publicKey": {}
170393            }
170394          },
170395          "modelCard": {
170396            "modelParameters": {
170397              "approach": {}
170398            },
170399            "quantitativeAnalysis": {
170400              "graphics": {}
170401            },
170402            "considerations": {}
170403          }
170404        },
170405        {
170406          "type": "library",
170407          "bom-ref": "pkg:npm/minipass@3.3.6?package-id=f0863d9180e7f0b3",
170408          "supplier": {},
170409          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
170410          "name": "minipass",
170411          "version": "3.3.6",
170412          "description": "minimal implementation of a PassThrough stream",
170413          "licenses": [
170414            {
170415              "license": {
170416                "id": "ISC"
170417              }
170418            }
170419          ],
170420          "cpe": "cpe:2.3:a:minipass:minipass:3.3.6:*:*:*:*:*:*:*",
170421          "purl": "pkg:npm/minipass@3.3.6",
170422          "swid": {
170423            "attachment": {}
170424          },
170425          "pedigree": {},
170426          "externalReferences": [
170427            {
170428              "url": "git+https://github.com/isaacs/minipass.git",
170429              "type": "distribution"
170430            }
170431          ],
170432          "evidence": {},
170433          "signature": {
170434            "signature": {
170435              "publicKey": {}
170436            }
170437          },
170438          "modelCard": {
170439            "modelParameters": {
170440              "approach": {}
170441            },
170442            "quantitativeAnalysis": {
170443              "graphics": {}
170444            },
170445            "considerations": {}
170446          }
170447        },
170448        {
170449          "type": "library",
170450          "bom-ref": "pkg:npm/minipass@4.2.5?package-id=55b840b1c3a672da",
170451          "supplier": {},
170452          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
170453          "name": "minipass",
170454          "version": "4.2.5",
170455          "description": "minimal implementation of a PassThrough stream",
170456          "licenses": [
170457            {
170458              "license": {
170459                "id": "ISC"
170460              }
170461            }
170462          ],
170463          "cpe": "cpe:2.3:a:minipass:minipass:4.2.5:*:*:*:*:*:*:*",
170464          "purl": "pkg:npm/minipass@4.2.5",
170465          "swid": {
170466            "attachment": {}
170467          },
170468          "pedigree": {},
170469          "externalReferences": [
170470            {
170471              "url": "git+https://github.com/isaacs/minipass.git",
170472              "type": "distribution"
170473            }
170474          ],
170475          "evidence": {},
170476          "signature": {
170477            "signature": {
170478              "publicKey": {}
170479            }
170480          },
170481          "modelCard": {
170482            "modelParameters": {
170483              "approach": {}
170484            },
170485            "quantitativeAnalysis": {
170486              "graphics": {}
170487            },
170488            "considerations": {}
170489          }
170490        },
170491        {
170492          "type": "library",
170493          "bom-ref": "pkg:npm/minipass-collect@1.0.2?package-id=48596b1d4dbb4f19",
170494          "supplier": {},
170495          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
170496          "name": "minipass-collect",
170497          "version": "1.0.2",
170498          "description": "A Minipass stream that collects all the data into a single chunk",
170499          "licenses": [
170500            {
170501              "license": {
170502                "id": "ISC"
170503              }
170504            }
170505          ],
170506          "cpe": "cpe:2.3:a:minipass-collect:minipass-collect:1.0.2:*:*:*:*:*:*:*",
170507          "purl": "pkg:npm/minipass-collect@1.0.2",
170508          "swid": {
170509            "attachment": {}
170510          },
170511          "pedigree": {},
170512          "evidence": {},
170513          "signature": {
170514            "signature": {
170515              "publicKey": {}
170516            }
170517          },
170518          "modelCard": {
170519            "modelParameters": {
170520              "approach": {}
170521            },
170522            "quantitativeAnalysis": {
170523              "graphics": {}
170524            },
170525            "considerations": {}
170526          }
170527        },
170528        {
170529          "type": "library",
170530          "bom-ref": "pkg:npm/minipass-fetch@2.1.1?package-id=1efc5437ba452e1d",
170531          "supplier": {},
170532          "author": "GitHub Inc.",
170533          "name": "minipass-fetch",
170534          "version": "2.1.1",
170535          "description": "An implementation of window.fetch in Node.js using Minipass streams",
170536          "licenses": [
170537            {
170538              "license": {
170539                "id": "MIT"
170540              }
170541            }
170542          ],
170543          "cpe": "cpe:2.3:a:minipass-fetch:minipass-fetch:2.1.1:*:*:*:*:*:*:*",
170544          "purl": "pkg:npm/minipass-fetch@2.1.1",
170545          "swid": {
170546            "attachment": {}
170547          },
170548          "pedigree": {},
170549          "externalReferences": [
170550            {
170551              "url": "https://github.com/npm/minipass-fetch.git",
170552              "type": "distribution"
170553            }
170554          ],
170555          "evidence": {},
170556          "signature": {
170557            "signature": {
170558              "publicKey": {}
170559            }
170560          },
170561          "modelCard": {
170562            "modelParameters": {
170563              "approach": {}
170564            },
170565            "quantitativeAnalysis": {
170566              "graphics": {}
170567            },
170568            "considerations": {}
170569          }
170570        },
170571        {
170572          "type": "library",
170573          "bom-ref": "pkg:npm/minipass-flush@1.0.5?package-id=f00a260926226ede",
170574          "supplier": {},
170575          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
170576          "name": "minipass-flush",
170577          "version": "1.0.5",
170578          "description": "A Minipass stream that calls a flush function before emitting 'end'",
170579          "licenses": [
170580            {
170581              "license": {
170582                "id": "ISC"
170583              }
170584            }
170585          ],
170586          "cpe": "cpe:2.3:a:minipass-flush:minipass-flush:1.0.5:*:*:*:*:*:*:*",
170587          "purl": "pkg:npm/minipass-flush@1.0.5",
170588          "swid": {
170589            "attachment": {}
170590          },
170591          "pedigree": {},
170592          "externalReferences": [
170593            {
170594              "url": "git+https://github.com/isaacs/minipass-flush.git",
170595              "type": "distribution"
170596            }
170597          ],
170598          "evidence": {},
170599          "signature": {
170600            "signature": {
170601              "publicKey": {}
170602            }
170603          },
170604          "modelCard": {
170605            "modelParameters": {
170606              "approach": {}
170607            },
170608            "quantitativeAnalysis": {
170609              "graphics": {}
170610            },
170611            "considerations": {}
170612          }
170613        },
170614        {
170615          "type": "library",
170616          "bom-ref": "pkg:npm/minipass-json-stream@1.0.1?package-id=43ed818882788b6b",
170617          "supplier": {},
170618          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
170619          "name": "minipass-json-stream",
170620          "version": "1.0.1",
170621          "description": "Like JSONStream, but using Minipass streams",
170622          "licenses": [
170623            {
170624              "license": {
170625                "id": "MIT"
170626              }
170627            }
170628          ],
170629          "cpe": "cpe:2.3:a:minipass-json-stream:minipass-json-stream:1.0.1:*:*:*:*:*:*:*",
170630          "purl": "pkg:npm/minipass-json-stream@1.0.1",
170631          "swid": {
170632            "attachment": {}
170633          },
170634          "pedigree": {},
170635          "externalReferences": [
170636            {
170637              "url": "git+https://github.com/npm/minipass-json-stream.git",
170638              "type": "distribution"
170639            }
170640          ],
170641          "evidence": {},
170642          "signature": {
170643            "signature": {
170644              "publicKey": {}
170645            }
170646          },
170647          "modelCard": {
170648            "modelParameters": {
170649              "approach": {}
170650            },
170651            "quantitativeAnalysis": {
170652              "graphics": {}
170653            },
170654            "considerations": {}
170655          }
170656        },
170657        {
170658          "type": "library",
170659          "bom-ref": "pkg:npm/minipass-pipeline@1.2.4?package-id=891713a52fe6cc27",
170660          "supplier": {},
170661          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
170662          "name": "minipass-pipeline",
170663          "version": "1.2.4",
170664          "description": "create a pipeline of streams using Minipass",
170665          "licenses": [
170666            {
170667              "license": {
170668                "id": "ISC"
170669              }
170670            }
170671          ],
170672          "cpe": "cpe:2.3:a:minipass-pipeline:minipass-pipeline:1.2.4:*:*:*:*:*:*:*",
170673          "purl": "pkg:npm/minipass-pipeline@1.2.4",
170674          "swid": {
170675            "attachment": {}
170676          },
170677          "pedigree": {},
170678          "evidence": {},
170679          "signature": {
170680            "signature": {
170681              "publicKey": {}
170682            }
170683          },
170684          "modelCard": {
170685            "modelParameters": {
170686              "approach": {}
170687            },
170688            "quantitativeAnalysis": {
170689              "graphics": {}
170690            },
170691            "considerations": {}
170692          }
170693        },
170694        {
170695          "type": "library",
170696          "bom-ref": "pkg:npm/minipass-sized@1.0.3?package-id=cd4842c35733398b",
170697          "supplier": {},
170698          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
170699          "name": "minipass-sized",
170700          "version": "1.0.3",
170701          "description": "A Minipass stream that raises an error if you get a different number of bytes than expected",
170702          "licenses": [
170703            {
170704              "license": {
170705                "id": "ISC"
170706              }
170707            }
170708          ],
170709          "cpe": "cpe:2.3:a:minipass-sized:minipass-sized:1.0.3:*:*:*:*:*:*:*",
170710          "purl": "pkg:npm/minipass-sized@1.0.3",
170711          "swid": {
170712            "attachment": {}
170713          },
170714          "pedigree": {},
170715          "externalReferences": [
170716            {
170717              "url": "git+https://github.com/isaacs/minipass-sized.git",
170718              "type": "distribution"
170719            }
170720          ],
170721          "evidence": {},
170722          "signature": {
170723            "signature": {
170724              "publicKey": {}
170725            }
170726          },
170727          "modelCard": {
170728            "modelParameters": {
170729              "approach": {}
170730            },
170731            "quantitativeAnalysis": {
170732              "graphics": {}
170733            },
170734            "considerations": {}
170735          }
170736        },
170737        {
170738          "type": "library",
170739          "bom-ref": "pkg:npm/minizlib@2.1.2?package-id=a651644b4f6a3e3",
170740          "supplier": {},
170741          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
170742          "name": "minizlib",
170743          "version": "2.1.2",
170744          "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
170745          "licenses": [
170746            {
170747              "license": {
170748                "id": "MIT"
170749              }
170750            }
170751          ],
170752          "cpe": "cpe:2.3:a:minizlib:minizlib:2.1.2:*:*:*:*:*:*:*",
170753          "purl": "pkg:npm/minizlib@2.1.2",
170754          "swid": {
170755            "attachment": {}
170756          },
170757          "pedigree": {},
170758          "externalReferences": [
170759            {
170760              "url": "git+https://github.com/isaacs/minizlib.git",
170761              "type": "distribution"
170762            }
170763          ],
170764          "evidence": {},
170765          "signature": {
170766            "signature": {
170767              "publicKey": {}
170768            }
170769          },
170770          "modelCard": {
170771            "modelParameters": {
170772              "approach": {}
170773            },
170774            "quantitativeAnalysis": {
170775              "graphics": {}
170776            },
170777            "considerations": {}
170778          }
170779        },
170780        {
170781          "type": "library",
170782          "bom-ref": "pkg:npm/minizlib@2.1.2?package-id=7bb75b451bb46790",
170783          "supplier": {},
170784          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
170785          "name": "minizlib",
170786          "version": "2.1.2",
170787          "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
170788          "licenses": [
170789            {
170790              "license": {
170791                "id": "MIT"
170792              }
170793            }
170794          ],
170795          "cpe": "cpe:2.3:a:minizlib:minizlib:2.1.2:*:*:*:*:*:*:*",
170796          "purl": "pkg:npm/minizlib@2.1.2",
170797          "swid": {
170798            "attachment": {}
170799          },
170800          "pedigree": {},
170801          "externalReferences": [
170802            {
170803              "url": "git+https://github.com/isaacs/minizlib.git",
170804              "type": "distribution"
170805            }
170806          ],
170807          "evidence": {},
170808          "signature": {
170809            "signature": {
170810              "publicKey": {}
170811            }
170812          },
170813          "modelCard": {
170814            "modelParameters": {
170815              "approach": {}
170816            },
170817            "quantitativeAnalysis": {
170818              "graphics": {}
170819            },
170820            "considerations": {}
170821          }
170822        },
170823        {
170824          "type": "library",
170825          "bom-ref": "pkg:npm/mkdirp@1.0.4?package-id=9695628e211e131d",
170826          "supplier": {},
170827          "name": "mkdirp",
170828          "version": "1.0.4",
170829          "description": "Recursively mkdir, like `mkdir -p`",
170830          "licenses": [
170831            {
170832              "license": {
170833                "id": "MIT"
170834              }
170835            }
170836          ],
170837          "cpe": "cpe:2.3:a:isaacs:mkdirp:1.0.4:*:*:*:*:*:*:*",
170838          "purl": "pkg:npm/mkdirp@1.0.4",
170839          "swid": {
170840            "attachment": {}
170841          },
170842          "pedigree": {},
170843          "externalReferences": [
170844            {
170845              "url": "https://github.com/isaacs/node-mkdirp.git",
170846              "type": "distribution"
170847            }
170848          ],
170849          "evidence": {},
170850          "signature": {
170851            "signature": {
170852              "publicKey": {}
170853            }
170854          },
170855          "modelCard": {
170856            "modelParameters": {
170857              "approach": {}
170858            },
170859            "quantitativeAnalysis": {
170860              "graphics": {}
170861            },
170862            "considerations": {}
170863          }
170864        },
170865        {
170866          "type": "library",
170867          "bom-ref": "pkg:npm/mkdirp@1.0.4?package-id=9258d24e97ef9bc8",
170868          "supplier": {},
170869          "name": "mkdirp",
170870          "version": "1.0.4",
170871          "description": "Recursively mkdir, like `mkdir -p`",
170872          "licenses": [
170873            {
170874              "license": {
170875                "id": "MIT"
170876              }
170877            }
170878          ],
170879          "cpe": "cpe:2.3:a:isaacs:mkdirp:1.0.4:*:*:*:*:*:*:*",
170880          "purl": "pkg:npm/mkdirp@1.0.4",
170881          "swid": {
170882            "attachment": {}
170883          },
170884          "pedigree": {},
170885          "externalReferences": [
170886            {
170887              "url": "https://github.com/isaacs/node-mkdirp.git",
170888              "type": "distribution"
170889            }
170890          ],
170891          "evidence": {},
170892          "signature": {
170893            "signature": {
170894              "publicKey": {}
170895            }
170896          },
170897          "modelCard": {
170898            "modelParameters": {
170899              "approach": {}
170900            },
170901            "quantitativeAnalysis": {
170902              "graphics": {}
170903            },
170904            "considerations": {}
170905          }
170906        },
170907        {
170908          "type": "library",
170909          "bom-ref": "pkg:npm/mkdirp-infer-owner@2.0.0?package-id=cd2840516db98e09",
170910          "supplier": {},
170911          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
170912          "name": "mkdirp-infer-owner",
170913          "version": "2.0.0",
170914          "description": "mkdirp, but chown to the owner of the containing folder if possible and necessary",
170915          "licenses": [
170916            {
170917              "license": {
170918                "id": "ISC"
170919              }
170920            }
170921          ],
170922          "cpe": "cpe:2.3:a:mkdirp-infer-owner:mkdirp-infer-owner:2.0.0:*:*:*:*:*:*:*",
170923          "purl": "pkg:npm/mkdirp-infer-owner@2.0.0",
170924          "swid": {
170925            "attachment": {}
170926          },
170927          "pedigree": {},
170928          "externalReferences": [
170929            {
170930              "url": "git+https://github.com/isaacs/mkdirp-infer-owner",
170931              "type": "distribution"
170932            }
170933          ],
170934          "evidence": {},
170935          "signature": {
170936            "signature": {
170937              "publicKey": {}
170938            }
170939          },
170940          "modelCard": {
170941            "modelParameters": {
170942              "approach": {}
170943            },
170944            "quantitativeAnalysis": {
170945              "graphics": {}
170946            },
170947            "considerations": {}
170948          }
170949        },
170950        {
170951          "type": "library",
170952          "bom-ref": "pkg:npm/monorepo-symlink-test@0.0.0?package-id=fb8f3eb0b123561e",
170953          "supplier": {},
170954          "name": "monorepo-symlink-test",
170955          "version": "0.0.0",
170956          "licenses": [
170957            {
170958              "license": {
170959                "id": "MIT"
170960              }
170961            }
170962          ],
170963          "cpe": "cpe:2.3:a:monorepo-symlink-test:monorepo-symlink-test:0.0.0:*:*:*:*:*:*:*",
170964          "purl": "pkg:npm/monorepo-symlink-test@0.0.0",
170965          "swid": {
170966            "attachment": {}
170967          },
170968          "pedigree": {},
170969          "evidence": {},
170970          "signature": {
170971            "signature": {
170972              "publicKey": {}
170973            }
170974          },
170975          "modelCard": {
170976            "modelParameters": {
170977              "approach": {}
170978            },
170979            "quantitativeAnalysis": {
170980              "graphics": {}
170981            },
170982            "considerations": {}
170983          }
170984        },
170985        {
170986          "type": "library",
170987          "bom-ref": "pkg:npm/ms@2.0.0?package-id=5a1105814fc945d6",
170988          "supplier": {},
170989          "name": "ms",
170990          "version": "2.0.0",
170991          "description": "Tiny milisecond conversion utility",
170992          "licenses": [
170993            {
170994              "license": {
170995                "id": "MIT"
170996              }
170997            }
170998          ],
170999          "cpe": "cpe:2.3:a:ms:ms:2.0.0:*:*:*:*:*:*:*",
171000          "purl": "pkg:npm/ms@2.0.0",
171001          "swid": {
171002            "attachment": {}
171003          },
171004          "pedigree": {},
171005          "externalReferences": [
171006            {
171007              "url": "zeit/ms",
171008              "type": "distribution"
171009            }
171010          ],
171011          "evidence": {},
171012          "signature": {
171013            "signature": {
171014              "publicKey": {}
171015            }
171016          },
171017          "modelCard": {
171018            "modelParameters": {
171019              "approach": {}
171020            },
171021            "quantitativeAnalysis": {
171022              "graphics": {}
171023            },
171024            "considerations": {}
171025          }
171026        },
171027        {
171028          "type": "library",
171029          "bom-ref": "pkg:npm/ms@2.1.1?package-id=b637ed80fef8c29b",
171030          "supplier": {},
171031          "name": "ms",
171032          "version": "2.1.1",
171033          "description": "Tiny millisecond conversion utility",
171034          "licenses": [
171035            {
171036              "license": {
171037                "id": "MIT"
171038              }
171039            }
171040          ],
171041          "cpe": "cpe:2.3:a:ms:ms:2.1.1:*:*:*:*:*:*:*",
171042          "purl": "pkg:npm/ms@2.1.1",
171043          "swid": {
171044            "attachment": {}
171045          },
171046          "pedigree": {},
171047          "externalReferences": [
171048            {
171049              "url": "zeit/ms",
171050              "type": "distribution"
171051            }
171052          ],
171053          "evidence": {},
171054          "signature": {
171055            "signature": {
171056              "publicKey": {}
171057            }
171058          },
171059          "modelCard": {
171060            "modelParameters": {
171061              "approach": {}
171062            },
171063            "quantitativeAnalysis": {
171064              "graphics": {}
171065            },
171066            "considerations": {}
171067          }
171068        },
171069        {
171070          "type": "library",
171071          "bom-ref": "pkg:npm/ms@2.1.2?package-id=baab6160abc8414d",
171072          "supplier": {},
171073          "name": "ms",
171074          "version": "2.1.2",
171075          "description": "Tiny millisecond conversion utility",
171076          "licenses": [
171077            {
171078              "license": {
171079                "id": "MIT"
171080              }
171081            }
171082          ],
171083          "cpe": "cpe:2.3:a:ms:ms:2.1.2:*:*:*:*:*:*:*",
171084          "purl": "pkg:npm/ms@2.1.2",
171085          "swid": {
171086            "attachment": {}
171087          },
171088          "pedigree": {},
171089          "externalReferences": [
171090            {
171091              "url": "zeit/ms",
171092              "type": "distribution"
171093            }
171094          ],
171095          "evidence": {},
171096          "signature": {
171097            "signature": {
171098              "publicKey": {}
171099            }
171100          },
171101          "modelCard": {
171102            "modelParameters": {
171103              "approach": {}
171104            },
171105            "quantitativeAnalysis": {
171106              "graphics": {}
171107            },
171108            "considerations": {}
171109          }
171110        },
171111        {
171112          "type": "library",
171113          "bom-ref": "pkg:npm/ms@2.1.3?package-id=56db25c219fa0f4e",
171114          "supplier": {},
171115          "name": "ms",
171116          "version": "2.1.3",
171117          "description": "Tiny millisecond conversion utility",
171118          "licenses": [
171119            {
171120              "license": {
171121                "id": "MIT"
171122              }
171123            }
171124          ],
171125          "cpe": "cpe:2.3:a:ms:ms:2.1.3:*:*:*:*:*:*:*",
171126          "purl": "pkg:npm/ms@2.1.3",
171127          "swid": {
171128            "attachment": {}
171129          },
171130          "pedigree": {},
171131          "externalReferences": [
171132            {
171133              "url": "vercel/ms",
171134              "type": "distribution"
171135            }
171136          ],
171137          "evidence": {},
171138          "signature": {
171139            "signature": {
171140              "publicKey": {}
171141            }
171142          },
171143          "modelCard": {
171144            "modelParameters": {
171145              "approach": {}
171146            },
171147            "quantitativeAnalysis": {
171148              "graphics": {}
171149            },
171150            "considerations": {}
171151          }
171152        },
171153        {
171154          "type": "library",
171155          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=24c6089b81ca7d19",
171156          "supplier": {},
171157          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
171158          "name": "musl",
171159          "version": "1.2.3-r2",
171160          "description": "the musl c library (libc) implementation",
171161          "licenses": [
171162            {
171163              "license": {
171164                "id": "MIT"
171165              }
171166            }
171167          ],
171168          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r2:*:*:*:*:*:*:*",
171169          "purl": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5",
171170          "swid": {
171171            "attachment": {}
171172          },
171173          "pedigree": {},
171174          "externalReferences": [
171175            {
171176              "url": "https://musl.libc.org/",
171177              "type": "distribution"
171178            }
171179          ],
171180          "evidence": {},
171181          "signature": {
171182            "signature": {
171183              "publicKey": {}
171184            }
171185          },
171186          "modelCard": {
171187            "modelParameters": {
171188              "approach": {}
171189            },
171190            "quantitativeAnalysis": {
171191              "graphics": {}
171192            },
171193            "considerations": {}
171194          }
171195        },
171196        {
171197          "type": "library",
171198          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5\u0026package-id=d33c14d727ae74d1",
171199          "supplier": {},
171200          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
171201          "name": "musl-utils",
171202          "version": "1.2.3-r2",
171203          "description": "the musl c library (libc) implementation",
171204          "licenses": [
171205            {
171206              "license": {
171207                "id": "MIT"
171208              }
171209            },
171210            {
171211              "license": {
171212                "name": "BSD"
171213              }
171214            },
171215            {
171216              "license": {
171217                "id": "GPL-2.0-or-later"
171218              }
171219            }
171220          ],
171221          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r2:*:*:*:*:*:*:*",
171222          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5",
171223          "swid": {
171224            "attachment": {}
171225          },
171226          "pedigree": {},
171227          "externalReferences": [
171228            {
171229              "url": "https://musl.libc.org/",
171230              "type": "distribution"
171231            }
171232          ],
171233          "evidence": {},
171234          "signature": {
171235            "signature": {
171236              "publicKey": {}
171237            }
171238          },
171239          "modelCard": {
171240            "modelParameters": {
171241              "approach": {}
171242            },
171243            "quantitativeAnalysis": {
171244              "graphics": {}
171245            },
171246            "considerations": {}
171247          }
171248        },
171249        {
171250          "type": "library",
171251          "bom-ref": "pkg:npm/mute-stream@0.0.8?package-id=b093eec725f75ac9",
171252          "supplier": {},
171253          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
171254          "name": "mute-stream",
171255          "version": "0.0.8",
171256          "description": "Bytes go in, but they don't come out (when muted).",
171257          "licenses": [
171258            {
171259              "license": {
171260                "id": "ISC"
171261              }
171262            }
171263          ],
171264          "cpe": "cpe:2.3:a:mute-stream:mute-stream:0.0.8:*:*:*:*:*:*:*",
171265          "purl": "pkg:npm/mute-stream@0.0.8",
171266          "swid": {
171267            "attachment": {}
171268          },
171269          "pedigree": {},
171270          "externalReferences": [
171271            {
171272              "url": "git://github.com/isaacs/mute-stream",
171273              "type": "distribution"
171274            }
171275          ],
171276          "evidence": {},
171277          "signature": {
171278            "signature": {
171279              "publicKey": {}
171280            }
171281          },
171282          "modelCard": {
171283            "modelParameters": {
171284              "approach": {}
171285            },
171286            "quantitativeAnalysis": {
171287              "graphics": {}
171288            },
171289            "considerations": {}
171290          }
171291        },
171292        {
171293          "type": "library",
171294          "bom-ref": "pkg:npm/mylib@0.0.0?package-id=9b8da0f44b3dbc2",
171295          "supplier": {},
171296          "name": "mylib",
171297          "version": "0.0.0",
171298          "licenses": [
171299            {
171300              "license": {
171301                "id": "ISC"
171302              }
171303            }
171304          ],
171305          "cpe": "cpe:2.3:a:mylib:mylib:0.0.0:*:*:*:*:*:*:*",
171306          "purl": "pkg:npm/mylib@0.0.0",
171307          "swid": {
171308            "attachment": {}
171309          },
171310          "pedigree": {},
171311          "evidence": {},
171312          "signature": {
171313            "signature": {
171314              "publicKey": {}
171315            }
171316          },
171317          "modelCard": {
171318            "modelParameters": {
171319              "approach": {}
171320            },
171321            "quantitativeAnalysis": {
171322              "graphics": {}
171323            },
171324            "considerations": {}
171325          }
171326        },
171327        {
171328          "type": "library",
171329          "bom-ref": "pkg:npm/nan@2.16.0?package-id=430e00056ba7a1b6",
171330          "supplier": {},
171331          "name": "nan",
171332          "version": "2.16.0",
171333          "description": "Native Abstractions for Node.js: C++ header for Node 0.8 -\u003e 14 compatibility",
171334          "licenses": [
171335            {
171336              "license": {
171337                "id": "MIT"
171338              }
171339            }
171340          ],
171341          "cpe": "cpe:2.3:a:nodejs:nan:2.16.0:*:*:*:*:*:*:*",
171342          "purl": "pkg:npm/nan@2.16.0",
171343          "swid": {
171344            "attachment": {}
171345          },
171346          "pedigree": {},
171347          "externalReferences": [
171348            {
171349              "url": "git://github.com/nodejs/nan.git",
171350              "type": "distribution"
171351            }
171352          ],
171353          "evidence": {},
171354          "signature": {
171355            "signature": {
171356              "publicKey": {}
171357            }
171358          },
171359          "modelCard": {
171360            "modelParameters": {
171361              "approach": {}
171362            },
171363            "quantitativeAnalysis": {
171364              "graphics": {}
171365            },
171366            "considerations": {}
171367          }
171368        },
171369        {
171370          "type": "library",
171371          "bom-ref": "pkg:npm/negotiator@0.6.2?package-id=fda5fb209d9198e7",
171372          "supplier": {},
171373          "name": "negotiator",
171374          "version": "0.6.2",
171375          "description": "HTTP content negotiation",
171376          "licenses": [
171377            {
171378              "license": {
171379                "id": "MIT"
171380              }
171381            }
171382          ],
171383          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.2:*:*:*:*:*:*:*",
171384          "purl": "pkg:npm/negotiator@0.6.2",
171385          "swid": {
171386            "attachment": {}
171387          },
171388          "pedigree": {},
171389          "externalReferences": [
171390            {
171391              "url": "jshttp/negotiator",
171392              "type": "distribution"
171393            }
171394          ],
171395          "evidence": {},
171396          "signature": {
171397            "signature": {
171398              "publicKey": {}
171399            }
171400          },
171401          "modelCard": {
171402            "modelParameters": {
171403              "approach": {}
171404            },
171405            "quantitativeAnalysis": {
171406              "graphics": {}
171407            },
171408            "considerations": {}
171409          }
171410        },
171411        {
171412          "type": "library",
171413          "bom-ref": "pkg:npm/negotiator@0.6.3?package-id=87cc6cb502ab228a",
171414          "supplier": {},
171415          "name": "negotiator",
171416          "version": "0.6.3",
171417          "description": "HTTP content negotiation",
171418          "licenses": [
171419            {
171420              "license": {
171421                "id": "MIT"
171422              }
171423            }
171424          ],
171425          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.3:*:*:*:*:*:*:*",
171426          "purl": "pkg:npm/negotiator@0.6.3",
171427          "swid": {
171428            "attachment": {}
171429          },
171430          "pedigree": {},
171431          "externalReferences": [
171432            {
171433              "url": "jshttp/negotiator",
171434              "type": "distribution"
171435            }
171436          ],
171437          "evidence": {},
171438          "signature": {
171439            "signature": {
171440              "publicKey": {}
171441            }
171442          },
171443          "modelCard": {
171444            "modelParameters": {
171445              "approach": {}
171446            },
171447            "quantitativeAnalysis": {
171448              "graphics": {}
171449            },
171450            "considerations": {}
171451          }
171452        },
171453        {
171454          "type": "application",
171455          "bom-ref": "pkg:generic/node@16.20.0?package-id=c3df0c8aa56599a1",
171456          "supplier": {},
171457          "name": "node",
171458          "version": "16.20.0",
171459          "cpe": "cpe:2.3:a:nodejs:node.js:16.20.0:*:*:*:*:*:*:*",
171460          "purl": "pkg:generic/node@16.20.0",
171461          "swid": {
171462            "attachment": {}
171463          },
171464          "pedigree": {},
171465          "evidence": {},
171466          "signature": {
171467            "signature": {
171468              "publicKey": {}
171469            }
171470          },
171471          "modelCard": {
171472            "modelParameters": {
171473              "approach": {}
171474            },
171475            "quantitativeAnalysis": {
171476              "graphics": {}
171477            },
171478            "considerations": {}
171479          }
171480        },
171481        {
171482          "type": "library",
171483          "bom-ref": "pkg:npm/node-gyp@7.1.2?package-id=d6358be7e6610e78",
171484          "supplier": {},
171485          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://tootallnate.net)",
171486          "name": "node-gyp",
171487          "version": "7.1.2",
171488          "description": "Node.js native addon build tool",
171489          "licenses": [
171490            {
171491              "license": {
171492                "id": "MIT"
171493              }
171494            }
171495          ],
171496          "cpe": "cpe:2.3:a:node-gyp:node-gyp:7.1.2:*:*:*:*:*:*:*",
171497          "purl": "pkg:npm/node-gyp@7.1.2",
171498          "swid": {
171499            "attachment": {}
171500          },
171501          "pedigree": {},
171502          "externalReferences": [
171503            {
171504              "url": "git://github.com/nodejs/node-gyp.git",
171505              "type": "distribution"
171506            }
171507          ],
171508          "evidence": {},
171509          "signature": {
171510            "signature": {
171511              "publicKey": {}
171512            }
171513          },
171514          "modelCard": {
171515            "modelParameters": {
171516              "approach": {}
171517            },
171518            "quantitativeAnalysis": {
171519              "graphics": {}
171520            },
171521            "considerations": {}
171522          }
171523        },
171524        {
171525          "type": "library",
171526          "bom-ref": "pkg:npm/node-gyp@9.1.0?package-id=594531fb28fce181",
171527          "supplier": {},
171528          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://tootallnate.net)",
171529          "name": "node-gyp",
171530          "version": "9.1.0",
171531          "description": "Node.js native addon build tool",
171532          "licenses": [
171533            {
171534              "license": {
171535                "id": "MIT"
171536              }
171537            }
171538          ],
171539          "cpe": "cpe:2.3:a:node-gyp:node-gyp:9.1.0:*:*:*:*:*:*:*",
171540          "purl": "pkg:npm/node-gyp@9.1.0",
171541          "swid": {
171542            "attachment": {}
171543          },
171544          "pedigree": {},
171545          "externalReferences": [
171546            {
171547              "url": "git://github.com/nodejs/node-gyp.git",
171548              "type": "distribution"
171549            }
171550          ],
171551          "evidence": {},
171552          "signature": {
171553            "signature": {
171554              "publicKey": {}
171555            }
171556          },
171557          "modelCard": {
171558            "modelParameters": {
171559              "approach": {}
171560            },
171561            "quantitativeAnalysis": {
171562              "graphics": {}
171563            },
171564            "considerations": {}
171565          }
171566        },
171567        {
171568          "type": "library",
171569          "bom-ref": "pkg:npm/node-sass@6.0.1?package-id=8ed8bfb84f23be1c",
171570          "supplier": {},
171571          "author": "Andrew Nesbitt \u003candrewnez@gmail.com\u003e (http://andrew.github.com)",
171572          "name": "node-sass",
171573          "version": "6.0.1",
171574          "description": "Wrapper around libsass",
171575          "licenses": [
171576            {
171577              "license": {
171578                "id": "MIT"
171579              }
171580            }
171581          ],
171582          "cpe": "cpe:2.3:a:node-sass:node-sass:6.0.1:*:*:*:*:*:*:*",
171583          "purl": "pkg:npm/node-sass@6.0.1",
171584          "swid": {
171585            "attachment": {}
171586          },
171587          "pedigree": {},
171588          "externalReferences": [
171589            {
171590              "url": "https://github.com/sass/node-sass",
171591              "type": "distribution"
171592            },
171593            {
171594              "url": "https://github.com/sass/node-sass",
171595              "type": "website"
171596            }
171597          ],
171598          "evidence": {},
171599          "signature": {
171600            "signature": {
171601              "publicKey": {}
171602            }
171603          },
171604          "modelCard": {
171605            "modelParameters": {
171606              "approach": {}
171607            },
171608            "quantitativeAnalysis": {
171609              "graphics": {}
171610            },
171611            "considerations": {}
171612          }
171613        },
171614        {
171615          "type": "library",
171616          "bom-ref": "pkg:npm/node-sass-tilde-importer@1.0.2?package-id=7ddb032aafbef65",
171617          "supplier": {},
171618          "author": "Matthew Davidson \u003cmatthew.davidson@skyscanner.net\u003e",
171619          "name": "node-sass-tilde-importer",
171620          "version": "1.0.2",
171621          "description": "A node-sass custom importer which turns ~ into absolute paths to the nearest parent node_modules directory.",
171622          "licenses": [
171623            {
171624              "license": {
171625                "id": "Apache-2.0"
171626              }
171627            }
171628          ],
171629          "cpe": "cpe:2.3:a:node-sass-tilde-importer:node-sass-tilde-importer:1.0.2:*:*:*:*:*:*:*",
171630          "purl": "pkg:npm/node-sass-tilde-importer@1.0.2",
171631          "swid": {
171632            "attachment": {}
171633          },
171634          "pedigree": {},
171635          "externalReferences": [
171636            {
171637              "url": "matthewdavidson/node-sass-tilde-importer",
171638              "type": "distribution"
171639            }
171640          ],
171641          "evidence": {},
171642          "signature": {
171643            "signature": {
171644              "publicKey": {}
171645            }
171646          },
171647          "modelCard": {
171648            "modelParameters": {
171649              "approach": {}
171650            },
171651            "quantitativeAnalysis": {
171652              "graphics": {}
171653            },
171654            "considerations": {}
171655          }
171656        },
171657        {
171658          "type": "library",
171659          "bom-ref": "pkg:npm/nopt@5.0.0?package-id=16f8d211f06e4fc1",
171660          "supplier": {},
171661          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
171662          "name": "nopt",
171663          "version": "5.0.0",
171664          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
171665          "licenses": [
171666            {
171667              "license": {
171668                "id": "ISC"
171669              }
171670            }
171671          ],
171672          "cpe": "cpe:2.3:a:nopt:nopt:5.0.0:*:*:*:*:*:*:*",
171673          "purl": "pkg:npm/nopt@5.0.0",
171674          "swid": {
171675            "attachment": {}
171676          },
171677          "pedigree": {},
171678          "externalReferences": [
171679            {
171680              "url": "https://github.com/npm/nopt.git",
171681              "type": "distribution"
171682            }
171683          ],
171684          "evidence": {},
171685          "signature": {
171686            "signature": {
171687              "publicKey": {}
171688            }
171689          },
171690          "modelCard": {
171691            "modelParameters": {
171692              "approach": {}
171693            },
171694            "quantitativeAnalysis": {
171695              "graphics": {}
171696            },
171697            "considerations": {}
171698          }
171699        },
171700        {
171701          "type": "library",
171702          "bom-ref": "pkg:npm/nopt@5.0.0?package-id=4a65eb288b716fd8",
171703          "supplier": {},
171704          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
171705          "name": "nopt",
171706          "version": "5.0.0",
171707          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
171708          "licenses": [
171709            {
171710              "license": {
171711                "id": "ISC"
171712              }
171713            }
171714          ],
171715          "cpe": "cpe:2.3:a:nopt:nopt:5.0.0:*:*:*:*:*:*:*",
171716          "purl": "pkg:npm/nopt@5.0.0",
171717          "swid": {
171718            "attachment": {}
171719          },
171720          "pedigree": {},
171721          "externalReferences": [
171722            {
171723              "url": "https://github.com/npm/nopt.git",
171724              "type": "distribution"
171725            }
171726          ],
171727          "evidence": {},
171728          "signature": {
171729            "signature": {
171730              "publicKey": {}
171731            }
171732          },
171733          "modelCard": {
171734            "modelParameters": {
171735              "approach": {}
171736            },
171737            "quantitativeAnalysis": {
171738              "graphics": {}
171739            },
171740            "considerations": {}
171741          }
171742        },
171743        {
171744          "type": "library",
171745          "bom-ref": "pkg:npm/nopt@6.0.0?package-id=2da699f46c59247",
171746          "supplier": {},
171747          "author": "GitHub Inc.",
171748          "name": "nopt",
171749          "version": "6.0.0",
171750          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
171751          "licenses": [
171752            {
171753              "license": {
171754                "id": "ISC"
171755              }
171756            }
171757          ],
171758          "cpe": "cpe:2.3:a:nopt:nopt:6.0.0:*:*:*:*:*:*:*",
171759          "purl": "pkg:npm/nopt@6.0.0",
171760          "swid": {
171761            "attachment": {}
171762          },
171763          "pedigree": {},
171764          "externalReferences": [
171765            {
171766              "url": "https://github.com/npm/nopt.git",
171767              "type": "distribution"
171768            }
171769          ],
171770          "evidence": {},
171771          "signature": {
171772            "signature": {
171773              "publicKey": {}
171774            }
171775          },
171776          "modelCard": {
171777            "modelParameters": {
171778              "approach": {}
171779            },
171780            "quantitativeAnalysis": {
171781              "graphics": {}
171782            },
171783            "considerations": {}
171784          }
171785        },
171786        {
171787          "type": "library",
171788          "bom-ref": "pkg:npm/normalize-package-data@2.5.0?package-id=2acaa02f4b693695",
171789          "supplier": {},
171790          "author": "Meryn Stol \u003cmerynstol@gmail.com\u003e",
171791          "name": "normalize-package-data",
171792          "version": "2.5.0",
171793          "description": "Normalizes data that can be found in package.json files.",
171794          "licenses": [
171795            {
171796              "license": {
171797                "id": "BSD-2-Clause"
171798              }
171799            }
171800          ],
171801          "cpe": "cpe:2.3:a:normalize-package-data:normalize-package-data:2.5.0:*:*:*:*:*:*:*",
171802          "purl": "pkg:npm/normalize-package-data@2.5.0",
171803          "swid": {
171804            "attachment": {}
171805          },
171806          "pedigree": {},
171807          "externalReferences": [
171808            {
171809              "url": "git://github.com/npm/normalize-package-data.git",
171810              "type": "distribution"
171811            }
171812          ],
171813          "evidence": {},
171814          "signature": {
171815            "signature": {
171816              "publicKey": {}
171817            }
171818          },
171819          "modelCard": {
171820            "modelParameters": {
171821              "approach": {}
171822            },
171823            "quantitativeAnalysis": {
171824              "graphics": {}
171825            },
171826            "considerations": {}
171827          }
171828        },
171829        {
171830          "type": "library",
171831          "bom-ref": "pkg:npm/normalize-package-data@3.0.3?package-id=eba03005d68df6bd",
171832          "supplier": {},
171833          "author": "Meryn Stol \u003cmerynstol@gmail.com\u003e",
171834          "name": "normalize-package-data",
171835          "version": "3.0.3",
171836          "description": "Normalizes data that can be found in package.json files.",
171837          "licenses": [
171838            {
171839              "license": {
171840                "id": "BSD-2-Clause"
171841              }
171842            }
171843          ],
171844          "cpe": "cpe:2.3:a:normalize-package-data:normalize-package-data:3.0.3:*:*:*:*:*:*:*",
171845          "purl": "pkg:npm/normalize-package-data@3.0.3",
171846          "swid": {
171847            "attachment": {}
171848          },
171849          "pedigree": {},
171850          "externalReferences": [
171851            {
171852              "url": "git://github.com/npm/normalize-package-data.git",
171853              "type": "distribution"
171854            }
171855          ],
171856          "evidence": {},
171857          "signature": {
171858            "signature": {
171859              "publicKey": {}
171860            }
171861          },
171862          "modelCard": {
171863            "modelParameters": {
171864              "approach": {}
171865            },
171866            "quantitativeAnalysis": {
171867              "graphics": {}
171868            },
171869            "considerations": {}
171870          }
171871        },
171872        {
171873          "type": "library",
171874          "bom-ref": "pkg:npm/normalize-package-data@4.0.1?package-id=f65ac6113e729b71",
171875          "supplier": {},
171876          "author": "GitHub Inc.",
171877          "name": "normalize-package-data",
171878          "version": "4.0.1",
171879          "description": "Normalizes data that can be found in package.json files.",
171880          "licenses": [
171881            {
171882              "license": {
171883                "id": "BSD-2-Clause"
171884              }
171885            }
171886          ],
171887          "cpe": "cpe:2.3:a:normalize-package-data:normalize-package-data:4.0.1:*:*:*:*:*:*:*",
171888          "purl": "pkg:npm/normalize-package-data@4.0.1",
171889          "swid": {
171890            "attachment": {}
171891          },
171892          "pedigree": {},
171893          "externalReferences": [
171894            {
171895              "url": "https://github.com/npm/normalize-package-data.git",
171896              "type": "distribution"
171897            }
171898          ],
171899          "evidence": {},
171900          "signature": {
171901            "signature": {
171902              "publicKey": {}
171903            }
171904          },
171905          "modelCard": {
171906            "modelParameters": {
171907              "approach": {}
171908            },
171909            "quantitativeAnalysis": {
171910              "graphics": {}
171911            },
171912            "considerations": {}
171913          }
171914        },
171915        {
171916          "type": "library",
171917          "bom-ref": "pkg:npm/npm@8.19.4?package-id=3a7215c0f0fd939a",
171918          "supplier": {},
171919          "author": "GitHub Inc.",
171920          "name": "npm",
171921          "version": "8.19.4",
171922          "description": "a package manager for JavaScript",
171923          "licenses": [
171924            {
171925              "license": {
171926                "id": "Artistic-2.0"
171927              }
171928            }
171929          ],
171930          "cpe": "cpe:2.3:a:npm:npm:8.19.4:*:*:*:*:*:*:*",
171931          "purl": "pkg:npm/npm@8.19.4",
171932          "swid": {
171933            "attachment": {}
171934          },
171935          "pedigree": {},
171936          "externalReferences": [
171937            {
171938              "url": "https://github.com/npm/cli.git",
171939              "type": "distribution"
171940            },
171941            {
171942              "url": "https://docs.npmjs.com/",
171943              "type": "website"
171944            }
171945          ],
171946          "evidence": {},
171947          "signature": {
171948            "signature": {
171949              "publicKey": {}
171950            }
171951          },
171952          "modelCard": {
171953            "modelParameters": {
171954              "approach": {}
171955            },
171956            "quantitativeAnalysis": {
171957              "graphics": {}
171958            },
171959            "considerations": {}
171960          }
171961        },
171962        {
171963          "type": "library",
171964          "bom-ref": "pkg:npm/npm-audit-report@3.0.0?package-id=838d59a41103d415",
171965          "supplier": {},
171966          "author": "GitHub Inc.",
171967          "name": "npm-audit-report",
171968          "version": "3.0.0",
171969          "description": "Given a response from the npm security api, render it into a variety of security reports",
171970          "licenses": [
171971            {
171972              "license": {
171973                "id": "ISC"
171974              }
171975            }
171976          ],
171977          "cpe": "cpe:2.3:a:npm-audit-report:npm-audit-report:3.0.0:*:*:*:*:*:*:*",
171978          "purl": "pkg:npm/npm-audit-report@3.0.0",
171979          "swid": {
171980            "attachment": {}
171981          },
171982          "pedigree": {},
171983          "externalReferences": [
171984            {
171985              "url": "https://github.com/npm/npm-audit-report.git",
171986              "type": "distribution"
171987            },
171988            {
171989              "url": "https://github.com/npm/npm-audit-report#readme",
171990              "type": "website"
171991            }
171992          ],
171993          "evidence": {},
171994          "signature": {
171995            "signature": {
171996              "publicKey": {}
171997            }
171998          },
171999          "modelCard": {
172000            "modelParameters": {
172001              "approach": {}
172002            },
172003            "quantitativeAnalysis": {
172004              "graphics": {}
172005            },
172006            "considerations": {}
172007          }
172008        },
172009        {
172010          "type": "library",
172011          "bom-ref": "pkg:npm/npm-bundled@1.1.2?package-id=d3fc92546524f1a0",
172012          "supplier": {},
172013          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
172014          "name": "npm-bundled",
172015          "version": "1.1.2",
172016          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
172017          "licenses": [
172018            {
172019              "license": {
172020                "id": "ISC"
172021              }
172022            }
172023          ],
172024          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:1.1.2:*:*:*:*:*:*:*",
172025          "purl": "pkg:npm/npm-bundled@1.1.2",
172026          "swid": {
172027            "attachment": {}
172028          },
172029          "pedigree": {},
172030          "externalReferences": [
172031            {
172032              "url": "git+https://github.com/npm/npm-bundled.git",
172033              "type": "distribution"
172034            }
172035          ],
172036          "evidence": {},
172037          "signature": {
172038            "signature": {
172039              "publicKey": {}
172040            }
172041          },
172042          "modelCard": {
172043            "modelParameters": {
172044              "approach": {}
172045            },
172046            "quantitativeAnalysis": {
172047              "graphics": {}
172048            },
172049            "considerations": {}
172050          }
172051        },
172052        {
172053          "type": "library",
172054          "bom-ref": "pkg:npm/npm-bundled@2.0.1?package-id=4342e4ccfcb927ca",
172055          "supplier": {},
172056          "author": "GitHub Inc.",
172057          "name": "npm-bundled",
172058          "version": "2.0.1",
172059          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
172060          "licenses": [
172061            {
172062              "license": {
172063                "id": "ISC"
172064              }
172065            }
172066          ],
172067          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:2.0.1:*:*:*:*:*:*:*",
172068          "purl": "pkg:npm/npm-bundled@2.0.1",
172069          "swid": {
172070            "attachment": {}
172071          },
172072          "pedigree": {},
172073          "externalReferences": [
172074            {
172075              "url": "https://github.com/npm/npm-bundled.git",
172076              "type": "distribution"
172077            }
172078          ],
172079          "evidence": {},
172080          "signature": {
172081            "signature": {
172082              "publicKey": {}
172083            }
172084          },
172085          "modelCard": {
172086            "modelParameters": {
172087              "approach": {}
172088            },
172089            "quantitativeAnalysis": {
172090              "graphics": {}
172091            },
172092            "considerations": {}
172093          }
172094        },
172095        {
172096          "type": "library",
172097          "bom-ref": "pkg:npm/npm-init@0.0.0?package-id=e58118b5aaeeedd7",
172098          "supplier": {},
172099          "name": "npm-init",
172100          "version": "0.0.0",
172101          "description": "an initter you init wit, innit?",
172102          "licenses": [
172103            {
172104              "license": {
172105                "name": "BSD"
172106              }
172107            }
172108          ],
172109          "cpe": "cpe:2.3:a:npm-init:npm-init:0.0.0:*:*:*:*:*:*:*",
172110          "purl": "pkg:npm/npm-init@0.0.0",
172111          "swid": {
172112            "attachment": {}
172113          },
172114          "pedigree": {},
172115          "evidence": {},
172116          "signature": {
172117            "signature": {
172118              "publicKey": {}
172119            }
172120          },
172121          "modelCard": {
172122            "modelParameters": {
172123              "approach": {}
172124            },
172125            "quantitativeAnalysis": {
172126              "graphics": {}
172127            },
172128            "considerations": {}
172129          }
172130        },
172131        {
172132          "type": "library",
172133          "bom-ref": "pkg:npm/npm-install-checks@5.0.0?package-id=ea3011565b04383b",
172134          "supplier": {},
172135          "author": "GitHub Inc.",
172136          "name": "npm-install-checks",
172137          "version": "5.0.0",
172138          "description": "Check the engines and platform fields in package.json",
172139          "licenses": [
172140            {
172141              "license": {
172142                "id": "BSD-2-Clause"
172143              }
172144            }
172145          ],
172146          "cpe": "cpe:2.3:a:npm-install-checks:npm-install-checks:5.0.0:*:*:*:*:*:*:*",
172147          "purl": "pkg:npm/npm-install-checks@5.0.0",
172148          "swid": {
172149            "attachment": {}
172150          },
172151          "pedigree": {},
172152          "externalReferences": [
172153            {
172154              "url": "https://github.com/npm/npm-install-checks.git",
172155              "type": "distribution"
172156            }
172157          ],
172158          "evidence": {},
172159          "signature": {
172160            "signature": {
172161              "publicKey": {}
172162            }
172163          },
172164          "modelCard": {
172165            "modelParameters": {
172166              "approach": {}
172167            },
172168            "quantitativeAnalysis": {
172169              "graphics": {}
172170            },
172171            "considerations": {}
172172          }
172173        },
172174        {
172175          "type": "library",
172176          "bom-ref": "pkg:npm/npm-normalize-package-bin@1.0.1?package-id=7cccc2d8907ef9bb",
172177          "supplier": {},
172178          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
172179          "name": "npm-normalize-package-bin",
172180          "version": "1.0.1",
172181          "description": "Turn any flavor of allowable package.json bin into a normalized object",
172182          "licenses": [
172183            {
172184              "license": {
172185                "id": "ISC"
172186              }
172187            }
172188          ],
172189          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:1.0.1:*:*:*:*:*:*:*",
172190          "purl": "pkg:npm/npm-normalize-package-bin@1.0.1",
172191          "swid": {
172192            "attachment": {}
172193          },
172194          "pedigree": {},
172195          "externalReferences": [
172196            {
172197              "url": "git+https://github.com/npm/npm-normalize-package-bin",
172198              "type": "distribution"
172199            }
172200          ],
172201          "evidence": {},
172202          "signature": {
172203            "signature": {
172204              "publicKey": {}
172205            }
172206          },
172207          "modelCard": {
172208            "modelParameters": {
172209              "approach": {}
172210            },
172211            "quantitativeAnalysis": {
172212              "graphics": {}
172213            },
172214            "considerations": {}
172215          }
172216        },
172217        {
172218          "type": "library",
172219          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=3b502df6a54faf04",
172220          "supplier": {},
172221          "author": "GitHub Inc.",
172222          "name": "npm-normalize-package-bin",
172223          "version": "2.0.0",
172224          "description": "Turn any flavor of allowable package.json bin into a normalized object",
172225          "licenses": [
172226            {
172227              "license": {
172228                "id": "ISC"
172229              }
172230            }
172231          ],
172232          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
172233          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
172234          "swid": {
172235            "attachment": {}
172236          },
172237          "pedigree": {},
172238          "externalReferences": [
172239            {
172240              "url": "https://github.com/npm/npm-normalize-package-bin.git",
172241              "type": "distribution"
172242            }
172243          ],
172244          "evidence": {},
172245          "signature": {
172246            "signature": {
172247              "publicKey": {}
172248            }
172249          },
172250          "modelCard": {
172251            "modelParameters": {
172252              "approach": {}
172253            },
172254            "quantitativeAnalysis": {
172255              "graphics": {}
172256            },
172257            "considerations": {}
172258          }
172259        },
172260        {
172261          "type": "library",
172262          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=cb496c88bc54cdd7",
172263          "supplier": {},
172264          "author": "GitHub Inc.",
172265          "name": "npm-normalize-package-bin",
172266          "version": "2.0.0",
172267          "description": "Turn any flavor of allowable package.json bin into a normalized object",
172268          "licenses": [
172269            {
172270              "license": {
172271                "id": "ISC"
172272              }
172273            }
172274          ],
172275          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
172276          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
172277          "swid": {
172278            "attachment": {}
172279          },
172280          "pedigree": {},
172281          "externalReferences": [
172282            {
172283              "url": "https://github.com/npm/npm-normalize-package-bin.git",
172284              "type": "distribution"
172285            }
172286          ],
172287          "evidence": {},
172288          "signature": {
172289            "signature": {
172290              "publicKey": {}
172291            }
172292          },
172293          "modelCard": {
172294            "modelParameters": {
172295              "approach": {}
172296            },
172297            "quantitativeAnalysis": {
172298              "graphics": {}
172299            },
172300            "considerations": {}
172301          }
172302        },
172303        {
172304          "type": "library",
172305          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=3675dcedd841f8b6",
172306          "supplier": {},
172307          "author": "GitHub Inc.",
172308          "name": "npm-normalize-package-bin",
172309          "version": "2.0.0",
172310          "description": "Turn any flavor of allowable package.json bin into a normalized object",
172311          "licenses": [
172312            {
172313              "license": {
172314                "id": "ISC"
172315              }
172316            }
172317          ],
172318          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
172319          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
172320          "swid": {
172321            "attachment": {}
172322          },
172323          "pedigree": {},
172324          "externalReferences": [
172325            {
172326              "url": "https://github.com/npm/npm-normalize-package-bin.git",
172327              "type": "distribution"
172328            }
172329          ],
172330          "evidence": {},
172331          "signature": {
172332            "signature": {
172333              "publicKey": {}
172334            }
172335          },
172336          "modelCard": {
172337            "modelParameters": {
172338              "approach": {}
172339            },
172340            "quantitativeAnalysis": {
172341              "graphics": {}
172342            },
172343            "considerations": {}
172344          }
172345        },
172346        {
172347          "type": "library",
172348          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=a6c4eec149dbad2b",
172349          "supplier": {},
172350          "author": "GitHub Inc.",
172351          "name": "npm-normalize-package-bin",
172352          "version": "2.0.0",
172353          "description": "Turn any flavor of allowable package.json bin into a normalized object",
172354          "licenses": [
172355            {
172356              "license": {
172357                "id": "ISC"
172358              }
172359            }
172360          ],
172361          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
172362          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
172363          "swid": {
172364            "attachment": {}
172365          },
172366          "pedigree": {},
172367          "externalReferences": [
172368            {
172369              "url": "https://github.com/npm/npm-normalize-package-bin.git",
172370              "type": "distribution"
172371            }
172372          ],
172373          "evidence": {},
172374          "signature": {
172375            "signature": {
172376              "publicKey": {}
172377            }
172378          },
172379          "modelCard": {
172380            "modelParameters": {
172381              "approach": {}
172382            },
172383            "quantitativeAnalysis": {
172384              "graphics": {}
172385            },
172386            "considerations": {}
172387          }
172388        },
172389        {
172390          "type": "library",
172391          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=b373bbb7c439b789",
172392          "supplier": {},
172393          "author": "GitHub Inc.",
172394          "name": "npm-normalize-package-bin",
172395          "version": "2.0.0",
172396          "description": "Turn any flavor of allowable package.json bin into a normalized object",
172397          "licenses": [
172398            {
172399              "license": {
172400                "id": "ISC"
172401              }
172402            }
172403          ],
172404          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
172405          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
172406          "swid": {
172407            "attachment": {}
172408          },
172409          "pedigree": {},
172410          "externalReferences": [
172411            {
172412              "url": "https://github.com/npm/npm-normalize-package-bin.git",
172413              "type": "distribution"
172414            }
172415          ],
172416          "evidence": {},
172417          "signature": {
172418            "signature": {
172419              "publicKey": {}
172420            }
172421          },
172422          "modelCard": {
172423            "modelParameters": {
172424              "approach": {}
172425            },
172426            "quantitativeAnalysis": {
172427              "graphics": {}
172428            },
172429            "considerations": {}
172430          }
172431        },
172432        {
172433          "type": "library",
172434          "bom-ref": "pkg:npm/npm-package-arg@9.1.0?package-id=30ebe98710a08c64",
172435          "supplier": {},
172436          "author": "GitHub Inc.",
172437          "name": "npm-package-arg",
172438          "version": "9.1.0",
172439          "description": "Parse the things that can be arguments to `npm install`",
172440          "licenses": [
172441            {
172442              "license": {
172443                "id": "ISC"
172444              }
172445            }
172446          ],
172447          "cpe": "cpe:2.3:a:npm-package-arg:npm-package-arg:9.1.0:*:*:*:*:*:*:*",
172448          "purl": "pkg:npm/npm-package-arg@9.1.0",
172449          "swid": {
172450            "attachment": {}
172451          },
172452          "pedigree": {},
172453          "externalReferences": [
172454            {
172455              "url": "https://github.com/npm/npm-package-arg.git",
172456              "type": "distribution"
172457            },
172458            {
172459              "url": "https://github.com/npm/npm-package-arg",
172460              "type": "website"
172461            }
172462          ],
172463          "evidence": {},
172464          "signature": {
172465            "signature": {
172466              "publicKey": {}
172467            }
172468          },
172469          "modelCard": {
172470            "modelParameters": {
172471              "approach": {}
172472            },
172473            "quantitativeAnalysis": {
172474              "graphics": {}
172475            },
172476            "considerations": {}
172477          }
172478        },
172479        {
172480          "type": "library",
172481          "bom-ref": "pkg:npm/npm-packlist@5.1.3?package-id=e87ec46a213d7a87",
172482          "supplier": {},
172483          "author": "GitHub Inc.",
172484          "name": "npm-packlist",
172485          "version": "5.1.3",
172486          "description": "Get a list of the files to add from a folder into an npm package",
172487          "licenses": [
172488            {
172489              "license": {
172490                "id": "ISC"
172491              }
172492            }
172493          ],
172494          "cpe": "cpe:2.3:a:npm-packlist:npm-packlist:5.1.3:*:*:*:*:*:*:*",
172495          "purl": "pkg:npm/npm-packlist@5.1.3",
172496          "swid": {
172497            "attachment": {}
172498          },
172499          "pedigree": {},
172500          "externalReferences": [
172501            {
172502              "url": "https://github.com/npm/npm-packlist.git",
172503              "type": "distribution"
172504            }
172505          ],
172506          "evidence": {},
172507          "signature": {
172508            "signature": {
172509              "publicKey": {}
172510            }
172511          },
172512          "modelCard": {
172513            "modelParameters": {
172514              "approach": {}
172515            },
172516            "quantitativeAnalysis": {
172517              "graphics": {}
172518            },
172519            "considerations": {}
172520          }
172521        },
172522        {
172523          "type": "library",
172524          "bom-ref": "pkg:npm/npm-pick-manifest@7.0.2?package-id=a9dc194030f7ba31",
172525          "supplier": {},
172526          "author": "GitHub Inc.",
172527          "name": "npm-pick-manifest",
172528          "version": "7.0.2",
172529          "description": "Resolves a matching manifest from a package metadata document according to standard npm semver resolution rules.",
172530          "licenses": [
172531            {
172532              "license": {
172533                "id": "ISC"
172534              }
172535            }
172536          ],
172537          "cpe": "cpe:2.3:a:npm-pick-manifest:npm-pick-manifest:7.0.2:*:*:*:*:*:*:*",
172538          "purl": "pkg:npm/npm-pick-manifest@7.0.2",
172539          "swid": {
172540            "attachment": {}
172541          },
172542          "pedigree": {},
172543          "externalReferences": [
172544            {
172545              "url": "https://github.com/npm/npm-pick-manifest.git",
172546              "type": "distribution"
172547            }
172548          ],
172549          "evidence": {},
172550          "signature": {
172551            "signature": {
172552              "publicKey": {}
172553            }
172554          },
172555          "modelCard": {
172556            "modelParameters": {
172557              "approach": {}
172558            },
172559            "quantitativeAnalysis": {
172560              "graphics": {}
172561            },
172562            "considerations": {}
172563          }
172564        },
172565        {
172566          "type": "library",
172567          "bom-ref": "pkg:npm/npm-profile@6.2.1?package-id=4b7db9f7ec8bd8ec",
172568          "supplier": {},
172569          "author": "GitHub Inc.",
172570          "name": "npm-profile",
172571          "version": "6.2.1",
172572          "description": "Library for updating an npmjs.com profile",
172573          "licenses": [
172574            {
172575              "license": {
172576                "id": "ISC"
172577              }
172578            }
172579          ],
172580          "cpe": "cpe:2.3:a:npm-profile:npm-profile:6.2.1:*:*:*:*:*:*:*",
172581          "purl": "pkg:npm/npm-profile@6.2.1",
172582          "swid": {
172583            "attachment": {}
172584          },
172585          "pedigree": {},
172586          "externalReferences": [
172587            {
172588              "url": "https://github.com/npm/npm-profile.git",
172589              "type": "distribution"
172590            }
172591          ],
172592          "evidence": {},
172593          "signature": {
172594            "signature": {
172595              "publicKey": {}
172596            }
172597          },
172598          "modelCard": {
172599            "modelParameters": {
172600              "approach": {}
172601            },
172602            "quantitativeAnalysis": {
172603              "graphics": {}
172604            },
172605            "considerations": {}
172606          }
172607        },
172608        {
172609          "type": "library",
172610          "bom-ref": "pkg:npm/npm-registry-fetch@13.3.1?package-id=4a24a52ce2bed90",
172611          "supplier": {},
172612          "author": "GitHub Inc.",
172613          "name": "npm-registry-fetch",
172614          "version": "13.3.1",
172615          "description": "Fetch-based http client for use with npm registry APIs",
172616          "licenses": [
172617            {
172618              "license": {
172619                "id": "ISC"
172620              }
172621            }
172622          ],
172623          "cpe": "cpe:2.3:a:npm-registry-fetch:npm-registry-fetch:13.3.1:*:*:*:*:*:*:*",
172624          "purl": "pkg:npm/npm-registry-fetch@13.3.1",
172625          "swid": {
172626            "attachment": {}
172627          },
172628          "pedigree": {},
172629          "externalReferences": [
172630            {
172631              "url": "https://github.com/npm/npm-registry-fetch.git",
172632              "type": "distribution"
172633            }
172634          ],
172635          "evidence": {},
172636          "signature": {
172637            "signature": {
172638              "publicKey": {}
172639            }
172640          },
172641          "modelCard": {
172642            "modelParameters": {
172643              "approach": {}
172644            },
172645            "quantitativeAnalysis": {
172646              "graphics": {}
172647            },
172648            "considerations": {}
172649          }
172650        },
172651        {
172652          "type": "library",
172653          "bom-ref": "pkg:npm/npm-user-validate@1.0.1?package-id=6154858fa52c8fec",
172654          "supplier": {},
172655          "author": "Robert Kowalski \u003crok@kowalski.gd\u003e",
172656          "name": "npm-user-validate",
172657          "version": "1.0.1",
172658          "description": "User validations for npm",
172659          "licenses": [
172660            {
172661              "license": {
172662                "id": "BSD-2-Clause"
172663              }
172664            }
172665          ],
172666          "cpe": "cpe:2.3:a:npm-user-validate:npm-user-validate:1.0.1:*:*:*:*:*:*:*",
172667          "purl": "pkg:npm/npm-user-validate@1.0.1",
172668          "swid": {
172669            "attachment": {}
172670          },
172671          "pedigree": {},
172672          "externalReferences": [
172673            {
172674              "url": "git://github.com/npm/npm-user-validate.git",
172675              "type": "distribution"
172676            }
172677          ],
172678          "evidence": {},
172679          "signature": {
172680            "signature": {
172681              "publicKey": {}
172682            }
172683          },
172684          "modelCard": {
172685            "modelParameters": {
172686              "approach": {}
172687            },
172688            "quantitativeAnalysis": {
172689              "graphics": {}
172690            },
172691            "considerations": {}
172692          }
172693        },
172694        {
172695          "type": "library",
172696          "bom-ref": "pkg:npm/npmlog@4.1.2?package-id=3e6a9b76fcf5c0b5",
172697          "supplier": {},
172698          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
172699          "name": "npmlog",
172700          "version": "4.1.2",
172701          "description": "logger for npm",
172702          "licenses": [
172703            {
172704              "license": {
172705                "id": "ISC"
172706              }
172707            }
172708          ],
172709          "cpe": "cpe:2.3:a:npmlog:npmlog:4.1.2:*:*:*:*:*:*:*",
172710          "purl": "pkg:npm/npmlog@4.1.2",
172711          "swid": {
172712            "attachment": {}
172713          },
172714          "pedigree": {},
172715          "externalReferences": [
172716            {
172717              "url": "https://github.com/npm/npmlog.git",
172718              "type": "distribution"
172719            }
172720          ],
172721          "evidence": {},
172722          "signature": {
172723            "signature": {
172724              "publicKey": {}
172725            }
172726          },
172727          "modelCard": {
172728            "modelParameters": {
172729              "approach": {}
172730            },
172731            "quantitativeAnalysis": {
172732              "graphics": {}
172733            },
172734            "considerations": {}
172735          }
172736        },
172737        {
172738          "type": "library",
172739          "bom-ref": "pkg:npm/npmlog@6.0.2?package-id=e1d7f39551f111f",
172740          "supplier": {},
172741          "author": "GitHub Inc.",
172742          "name": "npmlog",
172743          "version": "6.0.2",
172744          "description": "logger for npm",
172745          "licenses": [
172746            {
172747              "license": {
172748                "id": "ISC"
172749              }
172750            }
172751          ],
172752          "cpe": "cpe:2.3:a:npmlog:npmlog:6.0.2:*:*:*:*:*:*:*",
172753          "purl": "pkg:npm/npmlog@6.0.2",
172754          "swid": {
172755            "attachment": {}
172756          },
172757          "pedigree": {},
172758          "externalReferences": [
172759            {
172760              "url": "https://github.com/npm/npmlog.git",
172761              "type": "distribution"
172762            }
172763          ],
172764          "evidence": {},
172765          "signature": {
172766            "signature": {
172767              "publicKey": {}
172768            }
172769          },
172770          "modelCard": {
172771            "modelParameters": {
172772              "approach": {}
172773            },
172774            "quantitativeAnalysis": {
172775              "graphics": {}
172776            },
172777            "considerations": {}
172778          }
172779        },
172780        {
172781          "type": "library",
172782          "bom-ref": "pkg:npm/number-is-nan@1.0.1?package-id=dfd433e1796a6a88",
172783          "supplier": {},
172784          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
172785          "name": "number-is-nan",
172786          "version": "1.0.1",
172787          "description": "ES2015 Number.isNaN() ponyfill",
172788          "licenses": [
172789            {
172790              "license": {
172791                "id": "MIT"
172792              }
172793            }
172794          ],
172795          "cpe": "cpe:2.3:a:number-is-nan:number-is-nan:1.0.1:*:*:*:*:*:*:*",
172796          "purl": "pkg:npm/number-is-nan@1.0.1",
172797          "swid": {
172798            "attachment": {}
172799          },
172800          "pedigree": {},
172801          "externalReferences": [
172802            {
172803              "url": "sindresorhus/number-is-nan",
172804              "type": "distribution"
172805            }
172806          ],
172807          "evidence": {},
172808          "signature": {
172809            "signature": {
172810              "publicKey": {}
172811            }
172812          },
172813          "modelCard": {
172814            "modelParameters": {
172815              "approach": {}
172816            },
172817            "quantitativeAnalysis": {
172818              "graphics": {}
172819            },
172820            "considerations": {}
172821          }
172822        },
172823        {
172824          "type": "library",
172825          "bom-ref": "pkg:npm/oauth-sign@0.9.0?package-id=db172ac1d3949e1b",
172826          "supplier": {},
172827          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
172828          "name": "oauth-sign",
172829          "version": "0.9.0",
172830          "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
172831          "licenses": [
172832            {
172833              "license": {
172834                "id": "Apache-2.0"
172835              }
172836            }
172837          ],
172838          "cpe": "cpe:2.3:a:oauth-sign:oauth-sign:0.9.0:*:*:*:*:*:*:*",
172839          "purl": "pkg:npm/oauth-sign@0.9.0",
172840          "swid": {
172841            "attachment": {}
172842          },
172843          "pedigree": {},
172844          "externalReferences": [
172845            {
172846              "url": "https://github.com/mikeal/oauth-sign",
172847              "type": "distribution"
172848            }
172849          ],
172850          "evidence": {},
172851          "signature": {
172852            "signature": {
172853              "publicKey": {}
172854            }
172855          },
172856          "modelCard": {
172857            "modelParameters": {
172858              "approach": {}
172859            },
172860            "quantitativeAnalysis": {
172861              "graphics": {}
172862            },
172863            "considerations": {}
172864          }
172865        },
172866        {
172867          "type": "library",
172868          "bom-ref": "pkg:npm/object-assign@4.1.1?package-id=9f37d7ea88ae7c48",
172869          "supplier": {},
172870          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
172871          "name": "object-assign",
172872          "version": "4.1.1",
172873          "description": "ES2015 `Object.assign()` ponyfill",
172874          "licenses": [
172875            {
172876              "license": {
172877                "id": "MIT"
172878              }
172879            }
172880          ],
172881          "cpe": "cpe:2.3:a:object-assign:object-assign:4.1.1:*:*:*:*:*:*:*",
172882          "purl": "pkg:npm/object-assign@4.1.1",
172883          "swid": {
172884            "attachment": {}
172885          },
172886          "pedigree": {},
172887          "externalReferences": [
172888            {
172889              "url": "sindresorhus/object-assign",
172890              "type": "distribution"
172891            }
172892          ],
172893          "evidence": {},
172894          "signature": {
172895            "signature": {
172896              "publicKey": {}
172897            }
172898          },
172899          "modelCard": {
172900            "modelParameters": {
172901              "approach": {}
172902            },
172903            "quantitativeAnalysis": {
172904              "graphics": {}
172905            },
172906            "considerations": {}
172907          }
172908        },
172909        {
172910          "type": "library",
172911          "bom-ref": "pkg:npm/on-finished@2.3.0?package-id=10e3e142a47fe504",
172912          "supplier": {},
172913          "name": "on-finished",
172914          "version": "2.3.0",
172915          "description": "Execute a callback when a request closes, finishes, or errors",
172916          "licenses": [
172917            {
172918              "license": {
172919                "id": "MIT"
172920              }
172921            }
172922          ],
172923          "cpe": "cpe:2.3:a:on-finished:on-finished:2.3.0:*:*:*:*:*:*:*",
172924          "purl": "pkg:npm/on-finished@2.3.0",
172925          "swid": {
172926            "attachment": {}
172927          },
172928          "pedigree": {},
172929          "externalReferences": [
172930            {
172931              "url": "jshttp/on-finished",
172932              "type": "distribution"
172933            }
172934          ],
172935          "evidence": {},
172936          "signature": {
172937            "signature": {
172938              "publicKey": {}
172939            }
172940          },
172941          "modelCard": {
172942            "modelParameters": {
172943              "approach": {}
172944            },
172945            "quantitativeAnalysis": {
172946              "graphics": {}
172947            },
172948            "considerations": {}
172949          }
172950        },
172951        {
172952          "type": "library",
172953          "bom-ref": "pkg:npm/once@1.4.0?package-id=2bfb1efabaee8e52",
172954          "supplier": {},
172955          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
172956          "name": "once",
172957          "version": "1.4.0",
172958          "description": "Run a function exactly one time",
172959          "licenses": [
172960            {
172961              "license": {
172962                "id": "ISC"
172963              }
172964            }
172965          ],
172966          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
172967          "purl": "pkg:npm/once@1.4.0",
172968          "swid": {
172969            "attachment": {}
172970          },
172971          "pedigree": {},
172972          "externalReferences": [
172973            {
172974              "url": "git://github.com/isaacs/once",
172975              "type": "distribution"
172976            }
172977          ],
172978          "evidence": {},
172979          "signature": {
172980            "signature": {
172981              "publicKey": {}
172982            }
172983          },
172984          "modelCard": {
172985            "modelParameters": {
172986              "approach": {}
172987            },
172988            "quantitativeAnalysis": {
172989              "graphics": {}
172990            },
172991            "considerations": {}
172992          }
172993        },
172994        {
172995          "type": "library",
172996          "bom-ref": "pkg:npm/once@1.4.0?package-id=931b0bd981a31418",
172997          "supplier": {},
172998          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
172999          "name": "once",
173000          "version": "1.4.0",
173001          "description": "Run a function exactly one time",
173002          "licenses": [
173003            {
173004              "license": {
173005                "id": "ISC"
173006              }
173007            }
173008          ],
173009          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
173010          "purl": "pkg:npm/once@1.4.0",
173011          "swid": {
173012            "attachment": {}
173013          },
173014          "pedigree": {},
173015          "externalReferences": [
173016            {
173017              "url": "git://github.com/isaacs/once",
173018              "type": "distribution"
173019            }
173020          ],
173021          "evidence": {},
173022          "signature": {
173023            "signature": {
173024              "publicKey": {}
173025            }
173026          },
173027          "modelCard": {
173028            "modelParameters": {
173029              "approach": {}
173030            },
173031            "quantitativeAnalysis": {
173032              "graphics": {}
173033            },
173034            "considerations": {}
173035          }
173036        },
173037        {
173038          "type": "library",
173039          "bom-ref": "pkg:npm/opener@1.5.2?package-id=44a3614f9f359ab5",
173040          "supplier": {},
173041          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me/)",
173042          "name": "opener",
173043          "version": "1.5.2",
173044          "description": "Opens stuff, like webpages and files and executables, cross-platform",
173045          "licenses": [
173046            {
173047              "license": {
173048                "name": "(WTFPL OR MIT)"
173049              }
173050            }
173051          ],
173052          "cpe": "cpe:2.3:a:opener:opener:1.5.2:*:*:*:*:*:*:*",
173053          "purl": "pkg:npm/opener@1.5.2",
173054          "swid": {
173055            "attachment": {}
173056          },
173057          "pedigree": {},
173058          "externalReferences": [
173059            {
173060              "url": "domenic/opener",
173061              "type": "distribution"
173062            }
173063          ],
173064          "evidence": {},
173065          "signature": {
173066            "signature": {
173067              "publicKey": {}
173068            }
173069          },
173070          "modelCard": {
173071            "modelParameters": {
173072              "approach": {}
173073            },
173074            "quantitativeAnalysis": {
173075              "graphics": {}
173076            },
173077            "considerations": {}
173078          }
173079        },
173080        {
173081          "type": "library",
173082          "bom-ref": "pkg:npm/p-limit@2.3.0?package-id=740d957b6a14c8f8",
173083          "supplier": {},
173084          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
173085          "name": "p-limit",
173086          "version": "2.3.0",
173087          "description": "Run multiple promise-returning \u0026 async functions with limited concurrency",
173088          "licenses": [
173089            {
173090              "license": {
173091                "id": "MIT"
173092              }
173093            }
173094          ],
173095          "cpe": "cpe:2.3:a:p-limit:p-limit:2.3.0:*:*:*:*:*:*:*",
173096          "purl": "pkg:npm/p-limit@2.3.0",
173097          "swid": {
173098            "attachment": {}
173099          },
173100          "pedigree": {},
173101          "externalReferences": [
173102            {
173103              "url": "sindresorhus/p-limit",
173104              "type": "distribution"
173105            }
173106          ],
173107          "evidence": {},
173108          "signature": {
173109            "signature": {
173110              "publicKey": {}
173111            }
173112          },
173113          "modelCard": {
173114            "modelParameters": {
173115              "approach": {}
173116            },
173117            "quantitativeAnalysis": {
173118              "graphics": {}
173119            },
173120            "considerations": {}
173121          }
173122        },
173123        {
173124          "type": "library",
173125          "bom-ref": "pkg:npm/p-locate@3.0.0?package-id=da32ac4f0c6227d6",
173126          "supplier": {},
173127          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
173128          "name": "p-locate",
173129          "version": "3.0.0",
173130          "description": "Get the first fulfilled promise that satisfies the provided testing function",
173131          "licenses": [
173132            {
173133              "license": {
173134                "id": "MIT"
173135              }
173136            }
173137          ],
173138          "cpe": "cpe:2.3:a:p-locate:p-locate:3.0.0:*:*:*:*:*:*:*",
173139          "purl": "pkg:npm/p-locate@3.0.0",
173140          "swid": {
173141            "attachment": {}
173142          },
173143          "pedigree": {},
173144          "externalReferences": [
173145            {
173146              "url": "sindresorhus/p-locate",
173147              "type": "distribution"
173148            }
173149          ],
173150          "evidence": {},
173151          "signature": {
173152            "signature": {
173153              "publicKey": {}
173154            }
173155          },
173156          "modelCard": {
173157            "modelParameters": {
173158              "approach": {}
173159            },
173160            "quantitativeAnalysis": {
173161              "graphics": {}
173162            },
173163            "considerations": {}
173164          }
173165        },
173166        {
173167          "type": "library",
173168          "bom-ref": "pkg:npm/p-locate@4.1.0?package-id=9405b01a2e4f963e",
173169          "supplier": {},
173170          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
173171          "name": "p-locate",
173172          "version": "4.1.0",
173173          "description": "Get the first fulfilled promise that satisfies the provided testing function",
173174          "licenses": [
173175            {
173176              "license": {
173177                "id": "MIT"
173178              }
173179            }
173180          ],
173181          "cpe": "cpe:2.3:a:p-locate:p-locate:4.1.0:*:*:*:*:*:*:*",
173182          "purl": "pkg:npm/p-locate@4.1.0",
173183          "swid": {
173184            "attachment": {}
173185          },
173186          "pedigree": {},
173187          "externalReferences": [
173188            {
173189              "url": "sindresorhus/p-locate",
173190              "type": "distribution"
173191            }
173192          ],
173193          "evidence": {},
173194          "signature": {
173195            "signature": {
173196              "publicKey": {}
173197            }
173198          },
173199          "modelCard": {
173200            "modelParameters": {
173201              "approach": {}
173202            },
173203            "quantitativeAnalysis": {
173204              "graphics": {}
173205            },
173206            "considerations": {}
173207          }
173208        },
173209        {
173210          "type": "library",
173211          "bom-ref": "pkg:npm/p-map@4.0.0?package-id=1c07a8cbe4bd91d5",
173212          "supplier": {},
173213          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
173214          "name": "p-map",
173215          "version": "4.0.0",
173216          "description": "Map over promises concurrently",
173217          "licenses": [
173218            {
173219              "license": {
173220                "id": "MIT"
173221              }
173222            }
173223          ],
173224          "cpe": "cpe:2.3:a:p-map:p-map:4.0.0:*:*:*:*:*:*:*",
173225          "purl": "pkg:npm/p-map@4.0.0",
173226          "swid": {
173227            "attachment": {}
173228          },
173229          "pedigree": {},
173230          "externalReferences": [
173231            {
173232              "url": "sindresorhus/p-map",
173233              "type": "distribution"
173234            }
173235          ],
173236          "evidence": {},
173237          "signature": {
173238            "signature": {
173239              "publicKey": {}
173240            }
173241          },
173242          "modelCard": {
173243            "modelParameters": {
173244              "approach": {}
173245            },
173246            "quantitativeAnalysis": {
173247              "graphics": {}
173248            },
173249            "considerations": {}
173250          }
173251        },
173252        {
173253          "type": "library",
173254          "bom-ref": "pkg:npm/p-try@2.2.0?package-id=520c2a547947b938",
173255          "supplier": {},
173256          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
173257          "name": "p-try",
173258          "version": "2.2.0",
173259          "description": "`Start a promise chain",
173260          "licenses": [
173261            {
173262              "license": {
173263                "id": "MIT"
173264              }
173265            }
173266          ],
173267          "cpe": "cpe:2.3:a:p-try:p-try:2.2.0:*:*:*:*:*:*:*",
173268          "purl": "pkg:npm/p-try@2.2.0",
173269          "swid": {
173270            "attachment": {}
173271          },
173272          "pedigree": {},
173273          "externalReferences": [
173274            {
173275              "url": "sindresorhus/p-try",
173276              "type": "distribution"
173277            }
173278          ],
173279          "evidence": {},
173280          "signature": {
173281            "signature": {
173282              "publicKey": {}
173283            }
173284          },
173285          "modelCard": {
173286            "modelParameters": {
173287              "approach": {}
173288            },
173289            "quantitativeAnalysis": {
173290              "graphics": {}
173291            },
173292            "considerations": {}
173293          }
173294        },
173295        {
173296          "type": "library",
173297          "bom-ref": "pkg:npm/pacote@13.6.2?package-id=481670a57d8719a5",
173298          "supplier": {},
173299          "author": "GitHub Inc.",
173300          "name": "pacote",
173301          "version": "13.6.2",
173302          "description": "JavaScript package downloader",
173303          "licenses": [
173304            {
173305              "license": {
173306                "id": "ISC"
173307              }
173308            }
173309          ],
173310          "cpe": "cpe:2.3:a:pacote:pacote:13.6.2:*:*:*:*:*:*:*",
173311          "purl": "pkg:npm/pacote@13.6.2",
173312          "swid": {
173313            "attachment": {}
173314          },
173315          "pedigree": {},
173316          "externalReferences": [
173317            {
173318              "url": "https://github.com/npm/pacote.git",
173319              "type": "distribution"
173320            }
173321          ],
173322          "evidence": {},
173323          "signature": {
173324            "signature": {
173325              "publicKey": {}
173326            }
173327          },
173328          "modelCard": {
173329            "modelParameters": {
173330              "approach": {}
173331            },
173332            "quantitativeAnalysis": {
173333              "graphics": {}
173334            },
173335            "considerations": {}
173336          }
173337        },
173338        {
173339          "type": "library",
173340          "bom-ref": "pkg:npm/pako@1.0.11?package-id=f661ff2562ab67d",
173341          "supplier": {},
173342          "name": "pako",
173343          "version": "1.0.11",
173344          "description": "zlib port to javascript - fast, modularized, with browser support",
173345          "licenses": [
173346            {
173347              "license": {
173348                "name": "(MIT AND Zlib)"
173349              }
173350            }
173351          ],
173352          "cpe": "cpe:2.3:a:nodeca:pako:1.0.11:*:*:*:*:*:*:*",
173353          "purl": "pkg:npm/pako@1.0.11",
173354          "swid": {
173355            "attachment": {}
173356          },
173357          "pedigree": {},
173358          "externalReferences": [
173359            {
173360              "url": "nodeca/pako",
173361              "type": "distribution"
173362            },
173363            {
173364              "url": "https://github.com/nodeca/pako",
173365              "type": "website"
173366            }
173367          ],
173368          "evidence": {},
173369          "signature": {
173370            "signature": {
173371              "publicKey": {}
173372            }
173373          },
173374          "modelCard": {
173375            "modelParameters": {
173376              "approach": {}
173377            },
173378            "quantitativeAnalysis": {
173379              "graphics": {}
173380            },
173381            "considerations": {}
173382          }
173383        },
173384        {
173385          "type": "library",
173386          "bom-ref": "pkg:npm/parse-conflict-json@2.0.2?package-id=94638d4f43f17ad7",
173387          "supplier": {},
173388          "author": "GitHub Inc.",
173389          "name": "parse-conflict-json",
173390          "version": "2.0.2",
173391          "description": "Parse a JSON string that has git merge conflicts, resolving if possible",
173392          "licenses": [
173393            {
173394              "license": {
173395                "id": "ISC"
173396              }
173397            }
173398          ],
173399          "cpe": "cpe:2.3:a:parse-conflict-json:parse-conflict-json:2.0.2:*:*:*:*:*:*:*",
173400          "purl": "pkg:npm/parse-conflict-json@2.0.2",
173401          "swid": {
173402            "attachment": {}
173403          },
173404          "pedigree": {},
173405          "externalReferences": [
173406            {
173407              "url": "https://github.com/npm/parse-conflict-json.git",
173408              "type": "distribution"
173409            }
173410          ],
173411          "evidence": {},
173412          "signature": {
173413            "signature": {
173414              "publicKey": {}
173415            }
173416          },
173417          "modelCard": {
173418            "modelParameters": {
173419              "approach": {}
173420            },
173421            "quantitativeAnalysis": {
173422              "graphics": {}
173423            },
173424            "considerations": {}
173425          }
173426        },
173427        {
173428          "type": "library",
173429          "bom-ref": "pkg:npm/parse-json@5.2.0?package-id=69aedb15a89a2fd8",
173430          "supplier": {},
173431          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
173432          "name": "parse-json",
173433          "version": "5.2.0",
173434          "description": "Parse JSON with more helpful errors",
173435          "licenses": [
173436            {
173437              "license": {
173438                "id": "MIT"
173439              }
173440            }
173441          ],
173442          "cpe": "cpe:2.3:a:parse-json:parse-json:5.2.0:*:*:*:*:*:*:*",
173443          "purl": "pkg:npm/parse-json@5.2.0",
173444          "swid": {
173445            "attachment": {}
173446          },
173447          "pedigree": {},
173448          "externalReferences": [
173449            {
173450              "url": "sindresorhus/parse-json",
173451              "type": "distribution"
173452            }
173453          ],
173454          "evidence": {},
173455          "signature": {
173456            "signature": {
173457              "publicKey": {}
173458            }
173459          },
173460          "modelCard": {
173461            "modelParameters": {
173462              "approach": {}
173463            },
173464            "quantitativeAnalysis": {
173465              "graphics": {}
173466            },
173467            "considerations": {}
173468          }
173469        },
173470        {
173471          "type": "library",
173472          "bom-ref": "pkg:npm/parseurl@1.3.3?package-id=5a8f19386b323f4b",
173473          "supplier": {},
173474          "name": "parseurl",
173475          "version": "1.3.3",
173476          "description": "parse a url with memoization",
173477          "licenses": [
173478            {
173479              "license": {
173480                "id": "MIT"
173481              }
173482            }
173483          ],
173484          "cpe": "cpe:2.3:a:parseurl:parseurl:1.3.3:*:*:*:*:*:*:*",
173485          "purl": "pkg:npm/parseurl@1.3.3",
173486          "swid": {
173487            "attachment": {}
173488          },
173489          "pedigree": {},
173490          "externalReferences": [
173491            {
173492              "url": "pillarjs/parseurl",
173493              "type": "distribution"
173494            }
173495          ],
173496          "evidence": {},
173497          "signature": {
173498            "signature": {
173499              "publicKey": {}
173500            }
173501          },
173502          "modelCard": {
173503            "modelParameters": {
173504              "approach": {}
173505            },
173506            "quantitativeAnalysis": {
173507              "graphics": {}
173508            },
173509            "considerations": {}
173510          }
173511        },
173512        {
173513          "type": "library",
173514          "bom-ref": "pkg:npm/path-exists@3.0.0?package-id=dc628303d89cd038",
173515          "supplier": {},
173516          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
173517          "name": "path-exists",
173518          "version": "3.0.0",
173519          "description": "Check if a path exists",
173520          "licenses": [
173521            {
173522              "license": {
173523                "id": "MIT"
173524              }
173525            }
173526          ],
173527          "cpe": "cpe:2.3:a:path-exists:path-exists:3.0.0:*:*:*:*:*:*:*",
173528          "purl": "pkg:npm/path-exists@3.0.0",
173529          "swid": {
173530            "attachment": {}
173531          },
173532          "pedigree": {},
173533          "externalReferences": [
173534            {
173535              "url": "sindresorhus/path-exists",
173536              "type": "distribution"
173537            }
173538          ],
173539          "evidence": {},
173540          "signature": {
173541            "signature": {
173542              "publicKey": {}
173543            }
173544          },
173545          "modelCard": {
173546            "modelParameters": {
173547              "approach": {}
173548            },
173549            "quantitativeAnalysis": {
173550              "graphics": {}
173551            },
173552            "considerations": {}
173553          }
173554        },
173555        {
173556          "type": "library",
173557          "bom-ref": "pkg:npm/path-exists@4.0.0?package-id=32f6c6f926c1330a",
173558          "supplier": {},
173559          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
173560          "name": "path-exists",
173561          "version": "4.0.0",
173562          "description": "Check if a path exists",
173563          "licenses": [
173564            {
173565              "license": {
173566                "id": "MIT"
173567              }
173568            }
173569          ],
173570          "cpe": "cpe:2.3:a:path-exists:path-exists:4.0.0:*:*:*:*:*:*:*",
173571          "purl": "pkg:npm/path-exists@4.0.0",
173572          "swid": {
173573            "attachment": {}
173574          },
173575          "pedigree": {},
173576          "externalReferences": [
173577            {
173578              "url": "sindresorhus/path-exists",
173579              "type": "distribution"
173580            }
173581          ],
173582          "evidence": {},
173583          "signature": {
173584            "signature": {
173585              "publicKey": {}
173586            }
173587          },
173588          "modelCard": {
173589            "modelParameters": {
173590              "approach": {}
173591            },
173592            "quantitativeAnalysis": {
173593              "graphics": {}
173594            },
173595            "considerations": {}
173596          }
173597        },
173598        {
173599          "type": "library",
173600          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=ed58648f2f773bd9",
173601          "supplier": {},
173602          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
173603          "name": "path-is-absolute",
173604          "version": "1.0.1",
173605          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
173606          "licenses": [
173607            {
173608              "license": {
173609                "id": "MIT"
173610              }
173611            }
173612          ],
173613          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
173614          "purl": "pkg:npm/path-is-absolute@1.0.1",
173615          "swid": {
173616            "attachment": {}
173617          },
173618          "pedigree": {},
173619          "externalReferences": [
173620            {
173621              "url": "sindresorhus/path-is-absolute",
173622              "type": "distribution"
173623            }
173624          ],
173625          "evidence": {},
173626          "signature": {
173627            "signature": {
173628              "publicKey": {}
173629            }
173630          },
173631          "modelCard": {
173632            "modelParameters": {
173633              "approach": {}
173634            },
173635            "quantitativeAnalysis": {
173636              "graphics": {}
173637            },
173638            "considerations": {}
173639          }
173640        },
173641        {
173642          "type": "library",
173643          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=70cf293874d995a2",
173644          "supplier": {},
173645          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
173646          "name": "path-is-absolute",
173647          "version": "1.0.1",
173648          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
173649          "licenses": [
173650            {
173651              "license": {
173652                "id": "MIT"
173653              }
173654            }
173655          ],
173656          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
173657          "purl": "pkg:npm/path-is-absolute@1.0.1",
173658          "swid": {
173659            "attachment": {}
173660          },
173661          "pedigree": {},
173662          "externalReferences": [
173663            {
173664              "url": "sindresorhus/path-is-absolute",
173665              "type": "distribution"
173666            }
173667          ],
173668          "evidence": {},
173669          "signature": {
173670            "signature": {
173671              "publicKey": {}
173672            }
173673          },
173674          "modelCard": {
173675            "modelParameters": {
173676              "approach": {}
173677            },
173678            "quantitativeAnalysis": {
173679              "graphics": {}
173680            },
173681            "considerations": {}
173682          }
173683        },
173684        {
173685          "type": "library",
173686          "bom-ref": "pkg:npm/path-key@3.1.1?package-id=738f6ea51d24b15a",
173687          "supplier": {},
173688          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
173689          "name": "path-key",
173690          "version": "3.1.1",
173691          "description": "Get the PATH environment variable key cross-platform",
173692          "licenses": [
173693            {
173694              "license": {
173695                "id": "MIT"
173696              }
173697            }
173698          ],
173699          "cpe": "cpe:2.3:a:path-key:path-key:3.1.1:*:*:*:*:*:*:*",
173700          "purl": "pkg:npm/path-key@3.1.1",
173701          "swid": {
173702            "attachment": {}
173703          },
173704          "pedigree": {},
173705          "externalReferences": [
173706            {
173707              "url": "sindresorhus/path-key",
173708              "type": "distribution"
173709            }
173710          ],
173711          "evidence": {},
173712          "signature": {
173713            "signature": {
173714              "publicKey": {}
173715            }
173716          },
173717          "modelCard": {
173718            "modelParameters": {
173719              "approach": {}
173720            },
173721            "quantitativeAnalysis": {
173722              "graphics": {}
173723            },
173724            "considerations": {}
173725          }
173726        },
173727        {
173728          "type": "library",
173729          "bom-ref": "pkg:npm/path-parse@1.0.7?package-id=a9f85aa88ec56175",
173730          "supplier": {},
173731          "author": "Javier Blanco \u003chttp://jbgutierrez.info\u003e",
173732          "name": "path-parse",
173733          "version": "1.0.7",
173734          "description": "Node.js path.parse() ponyfill",
173735          "licenses": [
173736            {
173737              "license": {
173738                "id": "MIT"
173739              }
173740            }
173741          ],
173742          "cpe": "cpe:2.3:a:jbgutierrez:path-parse:1.0.7:*:*:*:*:*:*:*",
173743          "purl": "pkg:npm/path-parse@1.0.7",
173744          "swid": {
173745            "attachment": {}
173746          },
173747          "pedigree": {},
173748          "externalReferences": [
173749            {
173750              "url": "https://github.com/jbgutierrez/path-parse.git",
173751              "type": "distribution"
173752            },
173753            {
173754              "url": "https://github.com/jbgutierrez/path-parse#readme",
173755              "type": "website"
173756            }
173757          ],
173758          "evidence": {},
173759          "signature": {
173760            "signature": {
173761              "publicKey": {}
173762            }
173763          },
173764          "modelCard": {
173765            "modelParameters": {
173766              "approach": {}
173767            },
173768            "quantitativeAnalysis": {
173769              "graphics": {}
173770            },
173771            "considerations": {}
173772          }
173773        },
173774        {
173775          "type": "library",
173776          "bom-ref": "pkg:npm/path-to-regexp@0.1.7?package-id=ccbe7b36b309edc1",
173777          "supplier": {},
173778          "name": "path-to-regexp",
173779          "version": "0.1.7",
173780          "description": "Express style path to RegExp utility",
173781          "licenses": [
173782            {
173783              "license": {
173784                "id": "MIT"
173785              }
173786            }
173787          ],
173788          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:0.1.7:*:*:*:*:*:*:*",
173789          "purl": "pkg:npm/path-to-regexp@0.1.7",
173790          "swid": {
173791            "attachment": {}
173792          },
173793          "pedigree": {},
173794          "externalReferences": [
173795            {
173796              "url": "https://github.com/component/path-to-regexp.git",
173797              "type": "distribution"
173798            }
173799          ],
173800          "evidence": {},
173801          "signature": {
173802            "signature": {
173803              "publicKey": {}
173804            }
173805          },
173806          "modelCard": {
173807            "modelParameters": {
173808              "approach": {}
173809            },
173810            "quantitativeAnalysis": {
173811              "graphics": {}
173812            },
173813            "considerations": {}
173814          }
173815        },
173816        {
173817          "type": "library",
173818          "bom-ref": "pkg:npm/performance-now@2.1.0?package-id=571cf474f11938e4",
173819          "supplier": {},
173820          "author": "Braveg1rl \u003cbraveg1rl@outlook.com\u003e",
173821          "name": "performance-now",
173822          "version": "2.1.0",
173823          "description": "Implements performance.now (based on process.hrtime).",
173824          "licenses": [
173825            {
173826              "license": {
173827                "id": "MIT"
173828              }
173829            }
173830          ],
173831          "cpe": "cpe:2.3:a:performance-now:performance-now:2.1.0:*:*:*:*:*:*:*",
173832          "purl": "pkg:npm/performance-now@2.1.0",
173833          "swid": {
173834            "attachment": {}
173835          },
173836          "pedigree": {},
173837          "externalReferences": [
173838            {
173839              "url": "git://github.com/braveg1rl/performance-now.git",
173840              "type": "distribution"
173841            },
173842            {
173843              "url": "https://github.com/braveg1rl/performance-now",
173844              "type": "website"
173845            }
173846          ],
173847          "evidence": {},
173848          "signature": {
173849            "signature": {
173850              "publicKey": {}
173851            }
173852          },
173853          "modelCard": {
173854            "modelParameters": {
173855              "approach": {}
173856            },
173857            "quantitativeAnalysis": {
173858              "graphics": {}
173859            },
173860            "considerations": {}
173861          }
173862        },
173863        {
173864          "type": "library",
173865          "bom-ref": "pkg:npm/pliant-addon-themes@1.0.0?package-id=70bccb6336959cc0",
173866          "supplier": {},
173867          "name": "pliant-addon-themes",
173868          "version": "1.0.0",
173869          "description": "pliant-addon-themes",
173870          "licenses": [
173871            {
173872              "license": {
173873                "name": "UNLICENSED"
173874              }
173875            }
173876          ],
173877          "cpe": "cpe:2.3:a:pliant-addon-themes:pliant-addon-themes:1.0.0:*:*:*:*:*:*:*",
173878          "purl": "pkg:npm/pliant-addon-themes@1.0.0",
173879          "swid": {
173880            "attachment": {}
173881          },
173882          "pedigree": {},
173883          "evidence": {},
173884          "signature": {
173885            "signature": {
173886              "publicKey": {}
173887            }
173888          },
173889          "modelCard": {
173890            "modelParameters": {
173891              "approach": {}
173892            },
173893            "quantitativeAnalysis": {
173894              "graphics": {}
173895            },
173896            "considerations": {}
173897          }
173898        },
173899        {
173900          "type": "library",
173901          "bom-ref": "pkg:npm/postcss-selector-parser@6.0.10?package-id=29dd6871004e9325",
173902          "supplier": {},
173903          "name": "postcss-selector-parser",
173904          "version": "6.0.10",
173905          "licenses": [
173906            {
173907              "license": {
173908                "id": "MIT"
173909              }
173910            }
173911          ],
173912          "cpe": "cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:6.0.10:*:*:*:*:*:*:*",
173913          "purl": "pkg:npm/postcss-selector-parser@6.0.10",
173914          "swid": {
173915            "attachment": {}
173916          },
173917          "pedigree": {},
173918          "externalReferences": [
173919            {
173920              "url": "postcss/postcss-selector-parser",
173921              "type": "distribution"
173922            },
173923            {
173924              "url": "https://github.com/postcss/postcss-selector-parser",
173925              "type": "website"
173926            }
173927          ],
173928          "evidence": {},
173929          "signature": {
173930            "signature": {
173931              "publicKey": {}
173932            }
173933          },
173934          "modelCard": {
173935            "modelParameters": {
173936              "approach": {}
173937            },
173938            "quantitativeAnalysis": {
173939              "graphics": {}
173940            },
173941            "considerations": {}
173942          }
173943        },
173944        {
173945          "type": "library",
173946          "bom-ref": "pkg:npm/proc-log@2.0.1?package-id=a4591425ab5edc60",
173947          "supplier": {},
173948          "author": "GitHub Inc.",
173949          "name": "proc-log",
173950          "version": "2.0.1",
173951          "description": "just emit 'log' events on the process object",
173952          "licenses": [
173953            {
173954              "license": {
173955                "id": "ISC"
173956              }
173957            }
173958          ],
173959          "cpe": "cpe:2.3:a:proc-log:proc-log:2.0.1:*:*:*:*:*:*:*",
173960          "purl": "pkg:npm/proc-log@2.0.1",
173961          "swid": {
173962            "attachment": {}
173963          },
173964          "pedigree": {},
173965          "externalReferences": [
173966            {
173967              "url": "https://github.com/npm/proc-log.git",
173968              "type": "distribution"
173969            }
173970          ],
173971          "evidence": {},
173972          "signature": {
173973            "signature": {
173974              "publicKey": {}
173975            }
173976          },
173977          "modelCard": {
173978            "modelParameters": {
173979              "approach": {}
173980            },
173981            "quantitativeAnalysis": {
173982              "graphics": {}
173983            },
173984            "considerations": {}
173985          }
173986        },
173987        {
173988          "type": "library",
173989          "bom-ref": "pkg:npm/process-nextick-args@2.0.0?package-id=1f54bdeae1fcde6d",
173990          "supplier": {},
173991          "name": "process-nextick-args",
173992          "version": "2.0.0",
173993          "description": "process.nextTick but always with args",
173994          "licenses": [
173995            {
173996              "license": {
173997                "id": "MIT"
173998              }
173999            }
174000          ],
174001          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.0:*:*:*:*:*:*:*",
174002          "purl": "pkg:npm/process-nextick-args@2.0.0",
174003          "swid": {
174004            "attachment": {}
174005          },
174006          "pedigree": {},
174007          "externalReferences": [
174008            {
174009              "url": "https://github.com/calvinmetcalf/process-nextick-args.git",
174010              "type": "distribution"
174011            },
174012            {
174013              "url": "https://github.com/calvinmetcalf/process-nextick-args",
174014              "type": "website"
174015            }
174016          ],
174017          "evidence": {},
174018          "signature": {
174019            "signature": {
174020              "publicKey": {}
174021            }
174022          },
174023          "modelCard": {
174024            "modelParameters": {
174025              "approach": {}
174026            },
174027            "quantitativeAnalysis": {
174028              "graphics": {}
174029            },
174030            "considerations": {}
174031          }
174032        },
174033        {
174034          "type": "library",
174035          "bom-ref": "pkg:npm/promise-all-reject-late@1.0.1?package-id=7b92ff8460614d4f",
174036          "supplier": {},
174037          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
174038          "name": "promise-all-reject-late",
174039          "version": "1.0.1",
174040          "description": "Like Promise.all, but save rejections until all promises are resolved",
174041          "licenses": [
174042            {
174043              "license": {
174044                "id": "ISC"
174045              }
174046            }
174047          ],
174048          "cpe": "cpe:2.3:a:promise-all-reject-late:promise-all-reject-late:1.0.1:*:*:*:*:*:*:*",
174049          "purl": "pkg:npm/promise-all-reject-late@1.0.1",
174050          "swid": {
174051            "attachment": {}
174052          },
174053          "pedigree": {},
174054          "evidence": {},
174055          "signature": {
174056            "signature": {
174057              "publicKey": {}
174058            }
174059          },
174060          "modelCard": {
174061            "modelParameters": {
174062              "approach": {}
174063            },
174064            "quantitativeAnalysis": {
174065              "graphics": {}
174066            },
174067            "considerations": {}
174068          }
174069        },
174070        {
174071          "type": "library",
174072          "bom-ref": "pkg:npm/promise-call-limit@1.0.1?package-id=2b0b41bd7b0aa502",
174073          "supplier": {},
174074          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
174075          "name": "promise-call-limit",
174076          "version": "1.0.1",
174077          "description": "Call an array of promise-returning functions, restricting concurrency to a specified limit.",
174078          "licenses": [
174079            {
174080              "license": {
174081                "id": "ISC"
174082              }
174083            }
174084          ],
174085          "cpe": "cpe:2.3:a:promise-call-limit:promise-call-limit:1.0.1:*:*:*:*:*:*:*",
174086          "purl": "pkg:npm/promise-call-limit@1.0.1",
174087          "swid": {
174088            "attachment": {}
174089          },
174090          "pedigree": {},
174091          "externalReferences": [
174092            {
174093              "url": "git+https://github.com/isaacs/promise-call-limit",
174094              "type": "distribution"
174095            }
174096          ],
174097          "evidence": {},
174098          "signature": {
174099            "signature": {
174100              "publicKey": {}
174101            }
174102          },
174103          "modelCard": {
174104            "modelParameters": {
174105              "approach": {}
174106            },
174107            "quantitativeAnalysis": {
174108              "graphics": {}
174109            },
174110            "considerations": {}
174111          }
174112        },
174113        {
174114          "type": "library",
174115          "bom-ref": "pkg:npm/promise-inflight@1.0.1?package-id=8ae6caef1e6290fe",
174116          "supplier": {},
174117          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
174118          "name": "promise-inflight",
174119          "version": "1.0.1",
174120          "description": "One promise for multiple requests in flight to avoid async duplication",
174121          "licenses": [
174122            {
174123              "license": {
174124                "id": "ISC"
174125              }
174126            }
174127          ],
174128          "cpe": "cpe:2.3:a:promise-inflight:promise-inflight:1.0.1:*:*:*:*:*:*:*",
174129          "purl": "pkg:npm/promise-inflight@1.0.1",
174130          "swid": {
174131            "attachment": {}
174132          },
174133          "pedigree": {},
174134          "externalReferences": [
174135            {
174136              "url": "git+https://github.com/iarna/promise-inflight.git",
174137              "type": "distribution"
174138            },
174139            {
174140              "url": "https://github.com/iarna/promise-inflight#readme",
174141              "type": "website"
174142            }
174143          ],
174144          "evidence": {},
174145          "signature": {
174146            "signature": {
174147              "publicKey": {}
174148            }
174149          },
174150          "modelCard": {
174151            "modelParameters": {
174152              "approach": {}
174153            },
174154            "quantitativeAnalysis": {
174155              "graphics": {}
174156            },
174157            "considerations": {}
174158          }
174159        },
174160        {
174161          "type": "library",
174162          "bom-ref": "pkg:npm/promise-retry@2.0.1?package-id=7d483cd4a8ed637e",
174163          "supplier": {},
174164          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
174165          "name": "promise-retry",
174166          "version": "2.0.1",
174167          "description": "Retries a function that returns a promise, leveraging the power of the retry module.",
174168          "licenses": [
174169            {
174170              "license": {
174171                "id": "MIT"
174172              }
174173            }
174174          ],
174175          "cpe": "cpe:2.3:a:promise-retry:promise-retry:2.0.1:*:*:*:*:*:*:*",
174176          "purl": "pkg:npm/promise-retry@2.0.1",
174177          "swid": {
174178            "attachment": {}
174179          },
174180          "pedigree": {},
174181          "externalReferences": [
174182            {
174183              "url": "git://github.com/IndigoUnited/node-promise-retry.git",
174184              "type": "distribution"
174185            }
174186          ],
174187          "evidence": {},
174188          "signature": {
174189            "signature": {
174190              "publicKey": {}
174191            }
174192          },
174193          "modelCard": {
174194            "modelParameters": {
174195              "approach": {}
174196            },
174197            "quantitativeAnalysis": {
174198              "graphics": {}
174199            },
174200            "considerations": {}
174201          }
174202        },
174203        {
174204          "type": "library",
174205          "bom-ref": "pkg:npm/promzard@0.3.0?package-id=33cefe299422041",
174206          "supplier": {},
174207          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
174208          "name": "promzard",
174209          "version": "0.3.0",
174210          "description": "prompting wizardly",
174211          "licenses": [
174212            {
174213              "license": {
174214                "id": "ISC"
174215              }
174216            }
174217          ],
174218          "cpe": "cpe:2.3:a:promzard:promzard:0.3.0:*:*:*:*:*:*:*",
174219          "purl": "pkg:npm/promzard@0.3.0",
174220          "swid": {
174221            "attachment": {}
174222          },
174223          "pedigree": {},
174224          "externalReferences": [
174225            {
174226              "url": "git://github.com/isaacs/promzard",
174227              "type": "distribution"
174228            }
174229          ],
174230          "evidence": {},
174231          "signature": {
174232            "signature": {
174233              "publicKey": {}
174234            }
174235          },
174236          "modelCard": {
174237            "modelParameters": {
174238              "approach": {}
174239            },
174240            "quantitativeAnalysis": {
174241              "graphics": {}
174242            },
174243            "considerations": {}
174244          }
174245        },
174246        {
174247          "type": "library",
174248          "bom-ref": "pkg:npm/proxy-addr@2.0.5?package-id=8658125c1260006d",
174249          "supplier": {},
174250          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
174251          "name": "proxy-addr",
174252          "version": "2.0.5",
174253          "description": "Determine address of proxied request",
174254          "licenses": [
174255            {
174256              "license": {
174257                "id": "MIT"
174258              }
174259            }
174260          ],
174261          "cpe": "cpe:2.3:a:proxy-addr:proxy-addr:2.0.5:*:*:*:*:*:*:*",
174262          "purl": "pkg:npm/proxy-addr@2.0.5",
174263          "swid": {
174264            "attachment": {}
174265          },
174266          "pedigree": {},
174267          "externalReferences": [
174268            {
174269              "url": "jshttp/proxy-addr",
174270              "type": "distribution"
174271            }
174272          ],
174273          "evidence": {},
174274          "signature": {
174275            "signature": {
174276              "publicKey": {}
174277            }
174278          },
174279          "modelCard": {
174280            "modelParameters": {
174281              "approach": {}
174282            },
174283            "quantitativeAnalysis": {
174284              "graphics": {}
174285            },
174286            "considerations": {}
174287          }
174288        },
174289        {
174290          "type": "library",
174291          "bom-ref": "pkg:npm/psl@1.9.0?package-id=53b253f7b10f23e5",
174292          "supplier": {},
174293          "author": "Lupo Montero \u003clupomontero@gmail.com\u003e (https://lupomontero.com/)",
174294          "name": "psl",
174295          "version": "1.9.0",
174296          "description": "Domain name parser based on the Public Suffix List",
174297          "licenses": [
174298            {
174299              "license": {
174300                "id": "MIT"
174301              }
174302            }
174303          ],
174304          "cpe": "cpe:2.3:a:psl:psl:1.9.0:*:*:*:*:*:*:*",
174305          "purl": "pkg:npm/psl@1.9.0",
174306          "swid": {
174307            "attachment": {}
174308          },
174309          "pedigree": {},
174310          "externalReferences": [
174311            {
174312              "url": "git@github.com:lupomontero/psl.git",
174313              "type": "distribution"
174314            }
174315          ],
174316          "evidence": {},
174317          "signature": {
174318            "signature": {
174319              "publicKey": {}
174320            }
174321          },
174322          "modelCard": {
174323            "modelParameters": {
174324              "approach": {}
174325            },
174326            "quantitativeAnalysis": {
174327              "graphics": {}
174328            },
174329            "considerations": {}
174330          }
174331        },
174332        {
174333          "type": "library",
174334          "bom-ref": "pkg:npm/punycode@2.1.1?package-id=fa3e1b378dd1760a",
174335          "supplier": {},
174336          "author": "Mathias Bynens (https://mathiasbynens.be/)",
174337          "name": "punycode",
174338          "version": "2.1.1",
174339          "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
174340          "licenses": [
174341            {
174342              "license": {
174343                "id": "MIT"
174344              }
174345            }
174346          ],
174347          "cpe": "cpe:2.3:a:bestiejs:punycode:2.1.1:*:*:*:*:*:*:*",
174348          "purl": "pkg:npm/punycode@2.1.1",
174349          "swid": {
174350            "attachment": {}
174351          },
174352          "pedigree": {},
174353          "externalReferences": [
174354            {
174355              "url": "https://github.com/bestiejs/punycode.js.git",
174356              "type": "distribution"
174357            },
174358            {
174359              "url": "https://mths.be/punycode",
174360              "type": "website"
174361            }
174362          ],
174363          "evidence": {},
174364          "signature": {
174365            "signature": {
174366              "publicKey": {}
174367            }
174368          },
174369          "modelCard": {
174370            "modelParameters": {
174371              "approach": {}
174372            },
174373            "quantitativeAnalysis": {
174374              "graphics": {}
174375            },
174376            "considerations": {}
174377          }
174378        },
174379        {
174380          "type": "library",
174381          "bom-ref": "pkg:npm/qrcode-terminal@0.12.0?package-id=83c91f496595f73",
174382          "supplier": {},
174383          "name": "qrcode-terminal",
174384          "version": "0.12.0",
174385          "description": "QRCodes, in the terminal",
174386          "licenses": [
174387            {
174388              "license": {
174389                "name": "Apache 2.0"
174390              }
174391            }
174392          ],
174393          "cpe": "cpe:2.3:a:qrcode-terminal:qrcode-terminal:0.12.0:*:*:*:*:*:*:*",
174394          "purl": "pkg:npm/qrcode-terminal@0.12.0",
174395          "swid": {
174396            "attachment": {}
174397          },
174398          "pedigree": {},
174399          "externalReferences": [
174400            {
174401              "url": "https://github.com/gtanner/qrcode-terminal",
174402              "type": "distribution"
174403            },
174404            {
174405              "url": "https://github.com/gtanner/qrcode-terminal",
174406              "type": "website"
174407            }
174408          ],
174409          "evidence": {},
174410          "signature": {
174411            "signature": {
174412              "publicKey": {}
174413            }
174414          },
174415          "modelCard": {
174416            "modelParameters": {
174417              "approach": {}
174418            },
174419            "quantitativeAnalysis": {
174420              "graphics": {}
174421            },
174422            "considerations": {}
174423          }
174424        },
174425        {
174426          "type": "library",
174427          "bom-ref": "pkg:npm/qs@6.5.3?package-id=323c4310a1a5da48",
174428          "supplier": {},
174429          "name": "qs",
174430          "version": "6.5.3",
174431          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
174432          "licenses": [
174433            {
174434              "license": {
174435                "id": "BSD-3-Clause"
174436              }
174437            }
174438          ],
174439          "cpe": "cpe:2.3:a:ljharb:qs:6.5.3:*:*:*:*:*:*:*",
174440          "purl": "pkg:npm/qs@6.5.3",
174441          "swid": {
174442            "attachment": {}
174443          },
174444          "pedigree": {},
174445          "externalReferences": [
174446            {
174447              "url": "https://github.com/ljharb/qs.git",
174448              "type": "distribution"
174449            },
174450            {
174451              "url": "https://github.com/ljharb/qs",
174452              "type": "website"
174453            }
174454          ],
174455          "evidence": {},
174456          "signature": {
174457            "signature": {
174458              "publicKey": {}
174459            }
174460          },
174461          "modelCard": {
174462            "modelParameters": {
174463              "approach": {}
174464            },
174465            "quantitativeAnalysis": {
174466              "graphics": {}
174467            },
174468            "considerations": {}
174469          }
174470        },
174471        {
174472          "type": "library",
174473          "bom-ref": "pkg:npm/qs@6.7.0?package-id=4fccd8666f262a4b",
174474          "supplier": {},
174475          "name": "qs",
174476          "version": "6.7.0",
174477          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
174478          "licenses": [
174479            {
174480              "license": {
174481                "id": "BSD-3-Clause"
174482              }
174483            }
174484          ],
174485          "cpe": "cpe:2.3:a:ljharb:qs:6.7.0:*:*:*:*:*:*:*",
174486          "purl": "pkg:npm/qs@6.7.0",
174487          "swid": {
174488            "attachment": {}
174489          },
174490          "pedigree": {},
174491          "externalReferences": [
174492            {
174493              "url": "https://github.com/ljharb/qs.git",
174494              "type": "distribution"
174495            },
174496            {
174497              "url": "https://github.com/ljharb/qs",
174498              "type": "website"
174499            }
174500          ],
174501          "evidence": {},
174502          "signature": {
174503            "signature": {
174504              "publicKey": {}
174505            }
174506          },
174507          "modelCard": {
174508            "modelParameters": {
174509              "approach": {}
174510            },
174511            "quantitativeAnalysis": {
174512              "graphics": {}
174513            },
174514            "considerations": {}
174515          }
174516        },
174517        {
174518          "type": "library",
174519          "bom-ref": "pkg:npm/quick-lru@4.0.1?package-id=bd6e460313c1679d",
174520          "supplier": {},
174521          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
174522          "name": "quick-lru",
174523          "version": "4.0.1",
174524          "description": "Simple \"Least Recently Used\" (LRU) cache",
174525          "licenses": [
174526            {
174527              "license": {
174528                "id": "MIT"
174529              }
174530            }
174531          ],
174532          "cpe": "cpe:2.3:a:quick-lru:quick-lru:4.0.1:*:*:*:*:*:*:*",
174533          "purl": "pkg:npm/quick-lru@4.0.1",
174534          "swid": {
174535            "attachment": {}
174536          },
174537          "pedigree": {},
174538          "externalReferences": [
174539            {
174540              "url": "sindresorhus/quick-lru",
174541              "type": "distribution"
174542            }
174543          ],
174544          "evidence": {},
174545          "signature": {
174546            "signature": {
174547              "publicKey": {}
174548            }
174549          },
174550          "modelCard": {
174551            "modelParameters": {
174552              "approach": {}
174553            },
174554            "quantitativeAnalysis": {
174555              "graphics": {}
174556            },
174557            "considerations": {}
174558          }
174559        },
174560        {
174561          "type": "library",
174562          "bom-ref": "pkg:npm/range-parser@1.2.1?package-id=4426c7b6b8b9fe0c",
174563          "supplier": {},
174564          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
174565          "name": "range-parser",
174566          "version": "1.2.1",
174567          "description": "Range header field string parser",
174568          "licenses": [
174569            {
174570              "license": {
174571                "id": "MIT"
174572              }
174573            }
174574          ],
174575          "cpe": "cpe:2.3:a:range-parser:range-parser:1.2.1:*:*:*:*:*:*:*",
174576          "purl": "pkg:npm/range-parser@1.2.1",
174577          "swid": {
174578            "attachment": {}
174579          },
174580          "pedigree": {},
174581          "externalReferences": [
174582            {
174583              "url": "jshttp/range-parser",
174584              "type": "distribution"
174585            }
174586          ],
174587          "evidence": {},
174588          "signature": {
174589            "signature": {
174590              "publicKey": {}
174591            }
174592          },
174593          "modelCard": {
174594            "modelParameters": {
174595              "approach": {}
174596            },
174597            "quantitativeAnalysis": {
174598              "graphics": {}
174599            },
174600            "considerations": {}
174601          }
174602        },
174603        {
174604          "type": "library",
174605          "bom-ref": "pkg:npm/raw-body@2.4.0?package-id=86045e8e28d17aa5",
174606          "supplier": {},
174607          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
174608          "name": "raw-body",
174609          "version": "2.4.0",
174610          "description": "Get and validate the raw body of a readable stream.",
174611          "licenses": [
174612            {
174613              "license": {
174614                "id": "MIT"
174615              }
174616            }
174617          ],
174618          "cpe": "cpe:2.3:a:raw-body:raw-body:2.4.0:*:*:*:*:*:*:*",
174619          "purl": "pkg:npm/raw-body@2.4.0",
174620          "swid": {
174621            "attachment": {}
174622          },
174623          "pedigree": {},
174624          "externalReferences": [
174625            {
174626              "url": "stream-utils/raw-body",
174627              "type": "distribution"
174628            }
174629          ],
174630          "evidence": {},
174631          "signature": {
174632            "signature": {
174633              "publicKey": {}
174634            }
174635          },
174636          "modelCard": {
174637            "modelParameters": {
174638              "approach": {}
174639            },
174640            "quantitativeAnalysis": {
174641              "graphics": {}
174642            },
174643            "considerations": {}
174644          }
174645        },
174646        {
174647          "type": "library",
174648          "bom-ref": "pkg:npm/read@1.0.7?package-id=cf65e05575a1a15",
174649          "supplier": {},
174650          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
174651          "name": "read",
174652          "version": "1.0.7",
174653          "description": "read(1) for node programs",
174654          "licenses": [
174655            {
174656              "license": {
174657                "id": "ISC"
174658              }
174659            }
174660          ],
174661          "cpe": "cpe:2.3:a:isaacs:read:1.0.7:*:*:*:*:*:*:*",
174662          "purl": "pkg:npm/read@1.0.7",
174663          "swid": {
174664            "attachment": {}
174665          },
174666          "pedigree": {},
174667          "externalReferences": [
174668            {
174669              "url": "git://github.com/isaacs/read.git",
174670              "type": "distribution"
174671            }
174672          ],
174673          "evidence": {},
174674          "signature": {
174675            "signature": {
174676              "publicKey": {}
174677            }
174678          },
174679          "modelCard": {
174680            "modelParameters": {
174681              "approach": {}
174682            },
174683            "quantitativeAnalysis": {
174684              "graphics": {}
174685            },
174686            "considerations": {}
174687          }
174688        },
174689        {
174690          "type": "library",
174691          "bom-ref": "pkg:npm/read-cmd-shim@3.0.0?package-id=4b927be3f703982b",
174692          "supplier": {},
174693          "author": "GitHub Inc.",
174694          "name": "read-cmd-shim",
174695          "version": "3.0.0",
174696          "description": "Figure out what a cmd-shim is pointing at. This acts as the equivalent of fs.readlink.",
174697          "licenses": [
174698            {
174699              "license": {
174700                "id": "ISC"
174701              }
174702            }
174703          ],
174704          "cpe": "cpe:2.3:a:read-cmd-shim:read-cmd-shim:3.0.0:*:*:*:*:*:*:*",
174705          "purl": "pkg:npm/read-cmd-shim@3.0.0",
174706          "swid": {
174707            "attachment": {}
174708          },
174709          "pedigree": {},
174710          "externalReferences": [
174711            {
174712              "url": "https://github.com/npm/read-cmd-shim.git",
174713              "type": "distribution"
174714            },
174715            {
174716              "url": "https://github.com/npm/read-cmd-shim#readme",
174717              "type": "website"
174718            }
174719          ],
174720          "evidence": {},
174721          "signature": {
174722            "signature": {
174723              "publicKey": {}
174724            }
174725          },
174726          "modelCard": {
174727            "modelParameters": {
174728              "approach": {}
174729            },
174730            "quantitativeAnalysis": {
174731              "graphics": {}
174732            },
174733            "considerations": {}
174734          }
174735        },
174736        {
174737          "type": "library",
174738          "bom-ref": "pkg:npm/read-package-json@5.0.2?package-id=d15e27cd5cddf2b4",
174739          "supplier": {},
174740          "author": "GitHub Inc.",
174741          "name": "read-package-json",
174742          "version": "5.0.2",
174743          "description": "The thing npm uses to read package.json files with semantics and defaults and validation",
174744          "licenses": [
174745            {
174746              "license": {
174747                "id": "ISC"
174748              }
174749            }
174750          ],
174751          "cpe": "cpe:2.3:a:read-package-json:read-package-json:5.0.2:*:*:*:*:*:*:*",
174752          "purl": "pkg:npm/read-package-json@5.0.2",
174753          "swid": {
174754            "attachment": {}
174755          },
174756          "pedigree": {},
174757          "externalReferences": [
174758            {
174759              "url": "https://github.com/npm/read-package-json.git",
174760              "type": "distribution"
174761            }
174762          ],
174763          "evidence": {},
174764          "signature": {
174765            "signature": {
174766              "publicKey": {}
174767            }
174768          },
174769          "modelCard": {
174770            "modelParameters": {
174771              "approach": {}
174772            },
174773            "quantitativeAnalysis": {
174774              "graphics": {}
174775            },
174776            "considerations": {}
174777          }
174778        },
174779        {
174780          "type": "library",
174781          "bom-ref": "pkg:npm/read-package-json-fast@2.0.3?package-id=bb9e08c93f4b4c89",
174782          "supplier": {},
174783          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
174784          "name": "read-package-json-fast",
174785          "version": "2.0.3",
174786          "description": "Like read-package-json, but faster",
174787          "licenses": [
174788            {
174789              "license": {
174790                "id": "ISC"
174791              }
174792            }
174793          ],
174794          "cpe": "cpe:2.3:a:read-package-json-fast:read-package-json-fast:2.0.3:*:*:*:*:*:*:*",
174795          "purl": "pkg:npm/read-package-json-fast@2.0.3",
174796          "swid": {
174797            "attachment": {}
174798          },
174799          "pedigree": {},
174800          "externalReferences": [
174801            {
174802              "url": "git+https://github.com/npm/read-package-json-fast.git",
174803              "type": "distribution"
174804            }
174805          ],
174806          "evidence": {},
174807          "signature": {
174808            "signature": {
174809              "publicKey": {}
174810            }
174811          },
174812          "modelCard": {
174813            "modelParameters": {
174814              "approach": {}
174815            },
174816            "quantitativeAnalysis": {
174817              "graphics": {}
174818            },
174819            "considerations": {}
174820          }
174821        },
174822        {
174823          "type": "library",
174824          "bom-ref": "pkg:npm/read-pkg@5.2.0?package-id=ea2f8cf876469822",
174825          "supplier": {},
174826          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
174827          "name": "read-pkg",
174828          "version": "5.2.0",
174829          "description": "Read a package.json file",
174830          "licenses": [
174831            {
174832              "license": {
174833                "id": "MIT"
174834              }
174835            }
174836          ],
174837          "cpe": "cpe:2.3:a:read-pkg:read-pkg:5.2.0:*:*:*:*:*:*:*",
174838          "purl": "pkg:npm/read-pkg@5.2.0",
174839          "swid": {
174840            "attachment": {}
174841          },
174842          "pedigree": {},
174843          "externalReferences": [
174844            {
174845              "url": "sindresorhus/read-pkg",
174846              "type": "distribution"
174847            }
174848          ],
174849          "evidence": {},
174850          "signature": {
174851            "signature": {
174852              "publicKey": {}
174853            }
174854          },
174855          "modelCard": {
174856            "modelParameters": {
174857              "approach": {}
174858            },
174859            "quantitativeAnalysis": {
174860              "graphics": {}
174861            },
174862            "considerations": {}
174863          }
174864        },
174865        {
174866          "type": "library",
174867          "bom-ref": "pkg:npm/read-pkg-up@7.0.1?package-id=ce76c9dbb59a1a5c",
174868          "supplier": {},
174869          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
174870          "name": "read-pkg-up",
174871          "version": "7.0.1",
174872          "description": "Read the closest package.json file",
174873          "licenses": [
174874            {
174875              "license": {
174876                "id": "MIT"
174877              }
174878            }
174879          ],
174880          "cpe": "cpe:2.3:a:read-pkg-up:read-pkg-up:7.0.1:*:*:*:*:*:*:*",
174881          "purl": "pkg:npm/read-pkg-up@7.0.1",
174882          "swid": {
174883            "attachment": {}
174884          },
174885          "pedigree": {},
174886          "externalReferences": [
174887            {
174888              "url": "sindresorhus/read-pkg-up",
174889              "type": "distribution"
174890            }
174891          ],
174892          "evidence": {},
174893          "signature": {
174894            "signature": {
174895              "publicKey": {}
174896            }
174897          },
174898          "modelCard": {
174899            "modelParameters": {
174900              "approach": {}
174901            },
174902            "quantitativeAnalysis": {
174903              "graphics": {}
174904            },
174905            "considerations": {}
174906          }
174907        },
174908        {
174909          "type": "library",
174910          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=5e01f3e591a23990",
174911          "supplier": {},
174912          "name": "readable-stream",
174913          "version": "2.3.6",
174914          "description": "Streams3, a user-land copy of the stream library from Node.js",
174915          "licenses": [
174916            {
174917              "license": {
174918                "id": "MIT"
174919              }
174920            }
174921          ],
174922          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
174923          "purl": "pkg:npm/readable-stream@2.3.6",
174924          "swid": {
174925            "attachment": {}
174926          },
174927          "pedigree": {},
174928          "externalReferences": [
174929            {
174930              "url": "git://github.com/nodejs/readable-stream",
174931              "type": "distribution"
174932            }
174933          ],
174934          "evidence": {},
174935          "signature": {
174936            "signature": {
174937              "publicKey": {}
174938            }
174939          },
174940          "modelCard": {
174941            "modelParameters": {
174942              "approach": {}
174943            },
174944            "quantitativeAnalysis": {
174945              "graphics": {}
174946            },
174947            "considerations": {}
174948          }
174949        },
174950        {
174951          "type": "library",
174952          "bom-ref": "pkg:npm/readable-stream@3.6.0?package-id=32d9c32dd3126020",
174953          "supplier": {},
174954          "name": "readable-stream",
174955          "version": "3.6.0",
174956          "description": "Streams3, a user-land copy of the stream library from Node.js",
174957          "licenses": [
174958            {
174959              "license": {
174960                "id": "MIT"
174961              }
174962            }
174963          ],
174964          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.0:*:*:*:*:*:*:*",
174965          "purl": "pkg:npm/readable-stream@3.6.0",
174966          "swid": {
174967            "attachment": {}
174968          },
174969          "pedigree": {},
174970          "externalReferences": [
174971            {
174972              "url": "git://github.com/nodejs/readable-stream",
174973              "type": "distribution"
174974            }
174975          ],
174976          "evidence": {},
174977          "signature": {
174978            "signature": {
174979              "publicKey": {}
174980            }
174981          },
174982          "modelCard": {
174983            "modelParameters": {
174984              "approach": {}
174985            },
174986            "quantitativeAnalysis": {
174987              "graphics": {}
174988            },
174989            "considerations": {}
174990          }
174991        },
174992        {
174993          "type": "library",
174994          "bom-ref": "pkg:npm/readdir-scoped-modules@1.1.0?package-id=33ac24742869be8b",
174995          "supplier": {},
174996          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
174997          "name": "readdir-scoped-modules",
174998          "version": "1.1.0",
174999          "description": "Like `fs.readdir` but handling `@org/module` dirs as if they were a single entry.",
175000          "licenses": [
175001            {
175002              "license": {
175003                "id": "ISC"
175004              }
175005            }
175006          ],
175007          "cpe": "cpe:2.3:a:readdir-scoped-modules:readdir-scoped-modules:1.1.0:*:*:*:*:*:*:*",
175008          "purl": "pkg:npm/readdir-scoped-modules@1.1.0",
175009          "swid": {
175010            "attachment": {}
175011          },
175012          "pedigree": {},
175013          "externalReferences": [
175014            {
175015              "url": "https://github.com/npm/readdir-scoped-modules",
175016              "type": "distribution"
175017            },
175018            {
175019              "url": "https://github.com/npm/readdir-scoped-modules",
175020              "type": "website"
175021            }
175022          ],
175023          "evidence": {},
175024          "signature": {
175025            "signature": {
175026              "publicKey": {}
175027            }
175028          },
175029          "modelCard": {
175030            "modelParameters": {
175031              "approach": {}
175032            },
175033            "quantitativeAnalysis": {
175034              "graphics": {}
175035            },
175036            "considerations": {}
175037          }
175038        },
175039        {
175040          "type": "library",
175041          "bom-ref": "pkg:npm/redent@3.0.0?package-id=e20a794a0b358697",
175042          "supplier": {},
175043          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
175044          "name": "redent",
175045          "version": "3.0.0",
175046          "description": "Strip redundant indentation and indent the string",
175047          "licenses": [
175048            {
175049              "license": {
175050                "id": "MIT"
175051              }
175052            }
175053          ],
175054          "cpe": "cpe:2.3:a:redent:redent:3.0.0:*:*:*:*:*:*:*",
175055          "purl": "pkg:npm/redent@3.0.0",
175056          "swid": {
175057            "attachment": {}
175058          },
175059          "pedigree": {},
175060          "externalReferences": [
175061            {
175062              "url": "sindresorhus/redent",
175063              "type": "distribution"
175064            }
175065          ],
175066          "evidence": {},
175067          "signature": {
175068            "signature": {
175069              "publicKey": {}
175070            }
175071          },
175072          "modelCard": {
175073            "modelParameters": {
175074              "approach": {}
175075            },
175076            "quantitativeAnalysis": {
175077              "graphics": {}
175078            },
175079            "considerations": {}
175080          }
175081        },
175082        {
175083          "type": "library",
175084          "bom-ref": "pkg:npm/request@2.88.2?package-id=9d4ba60210bc5002",
175085          "supplier": {},
175086          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
175087          "name": "request",
175088          "version": "2.88.2",
175089          "description": "Simplified HTTP request client.",
175090          "licenses": [
175091            {
175092              "license": {
175093                "id": "Apache-2.0"
175094              }
175095            }
175096          ],
175097          "cpe": "cpe:2.3:a:request:request:2.88.2:*:*:*:*:*:*:*",
175098          "purl": "pkg:npm/request@2.88.2",
175099          "swid": {
175100            "attachment": {}
175101          },
175102          "pedigree": {},
175103          "externalReferences": [
175104            {
175105              "url": "https://github.com/request/request.git",
175106              "type": "distribution"
175107            }
175108          ],
175109          "evidence": {},
175110          "signature": {
175111            "signature": {
175112              "publicKey": {}
175113            }
175114          },
175115          "modelCard": {
175116            "modelParameters": {
175117              "approach": {}
175118            },
175119            "quantitativeAnalysis": {
175120              "graphics": {}
175121            },
175122            "considerations": {}
175123          }
175124        },
175125        {
175126          "type": "library",
175127          "bom-ref": "pkg:npm/require-directory@2.1.1?package-id=411dd6ad0d64a0bc",
175128          "supplier": {},
175129          "author": "Troy Goode \u003ctroygoode@gmail.com\u003e (http://github.com/troygoode/)",
175130          "name": "require-directory",
175131          "version": "2.1.1",
175132          "description": "Recursively iterates over specified directory, require()'ing each file, and returning a nested hash structure containing those modules.",
175133          "licenses": [
175134            {
175135              "license": {
175136                "id": "MIT"
175137              }
175138            }
175139          ],
175140          "cpe": "cpe:2.3:a:require-directory:require-directory:2.1.1:*:*:*:*:*:*:*",
175141          "purl": "pkg:npm/require-directory@2.1.1",
175142          "swid": {
175143            "attachment": {}
175144          },
175145          "pedigree": {},
175146          "externalReferences": [
175147            {
175148              "url": "git://github.com/troygoode/node-require-directory.git",
175149              "type": "distribution"
175150            },
175151            {
175152              "url": "https://github.com/troygoode/node-require-directory/",
175153              "type": "website"
175154            }
175155          ],
175156          "evidence": {},
175157          "signature": {
175158            "signature": {
175159              "publicKey": {}
175160            }
175161          },
175162          "modelCard": {
175163            "modelParameters": {
175164              "approach": {}
175165            },
175166            "quantitativeAnalysis": {
175167              "graphics": {}
175168            },
175169            "considerations": {}
175170          }
175171        },
175172        {
175173          "type": "library",
175174          "bom-ref": "pkg:npm/require-main-filename@2.0.0?package-id=9d7de391d2d9366d",
175175          "supplier": {},
175176          "author": "Ben Coe \u003cben@npmjs.com\u003e",
175177          "name": "require-main-filename",
175178          "version": "2.0.0",
175179          "description": "shim for require.main.filename() that works in as many environments as possible",
175180          "licenses": [
175181            {
175182              "license": {
175183                "id": "ISC"
175184              }
175185            }
175186          ],
175187          "cpe": "cpe:2.3:a:require-main-filename:require-main-filename:2.0.0:*:*:*:*:*:*:*",
175188          "purl": "pkg:npm/require-main-filename@2.0.0",
175189          "swid": {
175190            "attachment": {}
175191          },
175192          "pedigree": {},
175193          "externalReferences": [
175194            {
175195              "url": "git+ssh://git@github.com/yargs/require-main-filename.git",
175196              "type": "distribution"
175197            },
175198            {
175199              "url": "https://github.com/yargs/require-main-filename#readme",
175200              "type": "website"
175201            }
175202          ],
175203          "evidence": {},
175204          "signature": {
175205            "signature": {
175206              "publicKey": {}
175207            }
175208          },
175209          "modelCard": {
175210            "modelParameters": {
175211              "approach": {}
175212            },
175213            "quantitativeAnalysis": {
175214              "graphics": {}
175215            },
175216            "considerations": {}
175217          }
175218        },
175219        {
175220          "type": "library",
175221          "bom-ref": "pkg:npm/resize-observer-polyfill@1.5.1?package-id=cf15a93cb62d629c",
175222          "supplier": {},
175223          "author": "Denis Rul \u003cque.etc@gmail.com\u003e",
175224          "name": "resize-observer-polyfill",
175225          "version": "1.5.1",
175226          "description": "A polyfill for the Resize Observer API",
175227          "licenses": [
175228            {
175229              "license": {
175230                "id": "MIT"
175231              }
175232            }
175233          ],
175234          "cpe": "cpe:2.3:a:resize-observer-polyfill:resize-observer-polyfill:1.5.1:*:*:*:*:*:*:*",
175235          "purl": "pkg:npm/resize-observer-polyfill@1.5.1",
175236          "swid": {
175237            "attachment": {}
175238          },
175239          "pedigree": {},
175240          "externalReferences": [
175241            {
175242              "url": "https://github.com/que-etc/resize-observer-polyfill.git",
175243              "type": "distribution"
175244            },
175245            {
175246              "url": "https://github.com/que-etc/resize-observer-polyfill",
175247              "type": "website"
175248            }
175249          ],
175250          "evidence": {},
175251          "signature": {
175252            "signature": {
175253              "publicKey": {}
175254            }
175255          },
175256          "modelCard": {
175257            "modelParameters": {
175258              "approach": {}
175259            },
175260            "quantitativeAnalysis": {
175261              "graphics": {}
175262            },
175263            "considerations": {}
175264          }
175265        },
175266        {
175267          "type": "library",
175268          "bom-ref": "pkg:npm/resolve@1.22.1?package-id=83d934ebb6d52bde",
175269          "supplier": {},
175270          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
175271          "name": "resolve",
175272          "version": "1.22.1",
175273          "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
175274          "licenses": [
175275            {
175276              "license": {
175277                "id": "MIT"
175278              }
175279            }
175280          ],
175281          "cpe": "cpe:2.3:a:browserify:resolve:1.22.1:*:*:*:*:*:*:*",
175282          "purl": "pkg:npm/resolve@1.22.1",
175283          "swid": {
175284            "attachment": {}
175285          },
175286          "pedigree": {},
175287          "externalReferences": [
175288            {
175289              "url": "git://github.com/browserify/resolve.git",
175290              "type": "distribution"
175291            }
175292          ],
175293          "evidence": {},
175294          "signature": {
175295            "signature": {
175296              "publicKey": {}
175297            }
175298          },
175299          "modelCard": {
175300            "modelParameters": {
175301              "approach": {}
175302            },
175303            "quantitativeAnalysis": {
175304              "graphics": {}
175305            },
175306            "considerations": {}
175307          }
175308        },
175309        {
175310          "type": "library",
175311          "bom-ref": "pkg:npm/retry@0.12.0?package-id=c3f319915fd297ec",
175312          "supplier": {},
175313          "author": "Tim Koschützki \u003ctim@debuggable.com\u003e (http://debuggable.com/)",
175314          "name": "retry",
175315          "version": "0.12.0",
175316          "description": "Abstraction for exponential and custom retry strategies for failed operations.",
175317          "licenses": [
175318            {
175319              "license": {
175320                "id": "MIT"
175321              }
175322            }
175323          ],
175324          "cpe": "cpe:2.3:a:tim-kos:retry:0.12.0:*:*:*:*:*:*:*",
175325          "purl": "pkg:npm/retry@0.12.0",
175326          "swid": {
175327            "attachment": {}
175328          },
175329          "pedigree": {},
175330          "externalReferences": [
175331            {
175332              "url": "git://github.com/tim-kos/node-retry.git",
175333              "type": "distribution"
175334            },
175335            {
175336              "url": "https://github.com/tim-kos/node-retry",
175337              "type": "website"
175338            }
175339          ],
175340          "evidence": {},
175341          "signature": {
175342            "signature": {
175343              "publicKey": {}
175344            }
175345          },
175346          "modelCard": {
175347            "modelParameters": {
175348              "approach": {}
175349            },
175350            "quantitativeAnalysis": {
175351              "graphics": {}
175352            },
175353            "considerations": {}
175354          }
175355        },
175356        {
175357          "type": "library",
175358          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=92690f32c123c49b",
175359          "supplier": {},
175360          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
175361          "name": "rimraf",
175362          "version": "3.0.2",
175363          "description": "A deep deletion module for node (like `rm -rf`)",
175364          "licenses": [
175365            {
175366              "license": {
175367                "id": "ISC"
175368              }
175369            }
175370          ],
175371          "cpe": "cpe:2.3:a:isaacs:rimraf:3.0.2:*:*:*:*:*:*:*",
175372          "purl": "pkg:npm/rimraf@3.0.2",
175373          "swid": {
175374            "attachment": {}
175375          },
175376          "pedigree": {},
175377          "externalReferences": [
175378            {
175379              "url": "git://github.com/isaacs/rimraf.git",
175380              "type": "distribution"
175381            }
175382          ],
175383          "evidence": {},
175384          "signature": {
175385            "signature": {
175386              "publicKey": {}
175387            }
175388          },
175389          "modelCard": {
175390            "modelParameters": {
175391              "approach": {}
175392            },
175393            "quantitativeAnalysis": {
175394              "graphics": {}
175395            },
175396            "considerations": {}
175397          }
175398        },
175399        {
175400          "type": "library",
175401          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=691571e29c90ccb4",
175402          "supplier": {},
175403          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
175404          "name": "rimraf",
175405          "version": "3.0.2",
175406          "description": "A deep deletion module for node (like `rm -rf`)",
175407          "licenses": [
175408            {
175409              "license": {
175410                "id": "ISC"
175411              }
175412            }
175413          ],
175414          "cpe": "cpe:2.3:a:isaacs:rimraf:3.0.2:*:*:*:*:*:*:*",
175415          "purl": "pkg:npm/rimraf@3.0.2",
175416          "swid": {
175417            "attachment": {}
175418          },
175419          "pedigree": {},
175420          "externalReferences": [
175421            {
175422              "url": "git://github.com/isaacs/rimraf.git",
175423              "type": "distribution"
175424            }
175425          ],
175426          "evidence": {},
175427          "signature": {
175428            "signature": {
175429              "publicKey": {}
175430            }
175431          },
175432          "modelCard": {
175433            "modelParameters": {
175434              "approach": {}
175435            },
175436            "quantitativeAnalysis": {
175437              "graphics": {}
175438            },
175439            "considerations": {}
175440          }
175441        },
175442        {
175443          "type": "library",
175444          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=2726b88c81e31063",
175445          "supplier": {},
175446          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
175447          "name": "safe-buffer",
175448          "version": "5.1.2",
175449          "description": "Safer Node.js Buffer API",
175450          "licenses": [
175451            {
175452              "license": {
175453                "id": "MIT"
175454              }
175455            }
175456          ],
175457          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
175458          "purl": "pkg:npm/safe-buffer@5.1.2",
175459          "swid": {
175460            "attachment": {}
175461          },
175462          "pedigree": {},
175463          "externalReferences": [
175464            {
175465              "url": "git://github.com/feross/safe-buffer.git",
175466              "type": "distribution"
175467            },
175468            {
175469              "url": "https://github.com/feross/safe-buffer",
175470              "type": "website"
175471            }
175472          ],
175473          "evidence": {},
175474          "signature": {
175475            "signature": {
175476              "publicKey": {}
175477            }
175478          },
175479          "modelCard": {
175480            "modelParameters": {
175481              "approach": {}
175482            },
175483            "quantitativeAnalysis": {
175484              "graphics": {}
175485            },
175486            "considerations": {}
175487          }
175488        },
175489        {
175490          "type": "library",
175491          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=edf513d3ab46bee",
175492          "supplier": {},
175493          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
175494          "name": "safe-buffer",
175495          "version": "5.2.1",
175496          "description": "Safer Node.js Buffer API",
175497          "licenses": [
175498            {
175499              "license": {
175500                "id": "MIT"
175501              }
175502            }
175503          ],
175504          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
175505          "purl": "pkg:npm/safe-buffer@5.2.1",
175506          "swid": {
175507            "attachment": {}
175508          },
175509          "pedigree": {},
175510          "externalReferences": [
175511            {
175512              "url": "git://github.com/feross/safe-buffer.git",
175513              "type": "distribution"
175514            },
175515            {
175516              "url": "https://github.com/feross/safe-buffer",
175517              "type": "website"
175518            }
175519          ],
175520          "evidence": {},
175521          "signature": {
175522            "signature": {
175523              "publicKey": {}
175524            }
175525          },
175526          "modelCard": {
175527            "modelParameters": {
175528              "approach": {}
175529            },
175530            "quantitativeAnalysis": {
175531              "graphics": {}
175532            },
175533            "considerations": {}
175534          }
175535        },
175536        {
175537          "type": "library",
175538          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=4ab2220d3f3f4961",
175539          "supplier": {},
175540          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
175541          "name": "safer-buffer",
175542          "version": "2.1.2",
175543          "description": "Modern Buffer API polyfill without footguns",
175544          "licenses": [
175545            {
175546              "license": {
175547                "id": "MIT"
175548              }
175549            }
175550          ],
175551          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
175552          "purl": "pkg:npm/safer-buffer@2.1.2",
175553          "swid": {
175554            "attachment": {}
175555          },
175556          "pedigree": {},
175557          "externalReferences": [
175558            {
175559              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
175560              "type": "distribution"
175561            }
175562          ],
175563          "evidence": {},
175564          "signature": {
175565            "signature": {
175566              "publicKey": {}
175567            }
175568          },
175569          "modelCard": {
175570            "modelParameters": {
175571              "approach": {}
175572            },
175573            "quantitativeAnalysis": {
175574              "graphics": {}
175575            },
175576            "considerations": {}
175577          }
175578        },
175579        {
175580          "type": "library",
175581          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=cc287d73489b4567",
175582          "supplier": {},
175583          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
175584          "name": "safer-buffer",
175585          "version": "2.1.2",
175586          "description": "Modern Buffer API polyfill without footguns",
175587          "licenses": [
175588            {
175589              "license": {
175590                "id": "MIT"
175591              }
175592            }
175593          ],
175594          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
175595          "purl": "pkg:npm/safer-buffer@2.1.2",
175596          "swid": {
175597            "attachment": {}
175598          },
175599          "pedigree": {},
175600          "externalReferences": [
175601            {
175602              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
175603              "type": "distribution"
175604            }
175605          ],
175606          "evidence": {},
175607          "signature": {
175608            "signature": {
175609              "publicKey": {}
175610            }
175611          },
175612          "modelCard": {
175613            "modelParameters": {
175614              "approach": {}
175615            },
175616            "quantitativeAnalysis": {
175617              "graphics": {}
175618            },
175619            "considerations": {}
175620          }
175621        },
175622        {
175623          "type": "library",
175624          "bom-ref": "pkg:npm/sass-graph@2.2.5?package-id=7d18350a4afdf27f",
175625          "supplier": {},
175626          "author": "xzyfer",
175627          "name": "sass-graph",
175628          "version": "2.2.5",
175629          "description": "Parse sass files and extract a graph of imports",
175630          "licenses": [
175631            {
175632              "license": {
175633                "id": "MIT"
175634              }
175635            }
175636          ],
175637          "cpe": "cpe:2.3:a:sass-graph:sass-graph:2.2.5:*:*:*:*:*:*:*",
175638          "purl": "pkg:npm/sass-graph@2.2.5",
175639          "swid": {
175640            "attachment": {}
175641          },
175642          "pedigree": {},
175643          "externalReferences": [
175644            {
175645              "url": "xzyfer/sass-graph",
175646              "type": "distribution"
175647            }
175648          ],
175649          "evidence": {},
175650          "signature": {
175651            "signature": {
175652              "publicKey": {}
175653            }
175654          },
175655          "modelCard": {
175656            "modelParameters": {
175657              "approach": {}
175658            },
175659            "quantitativeAnalysis": {
175660              "graphics": {}
175661            },
175662            "considerations": {}
175663          }
175664        },
175665        {
175666          "type": "library",
175667          "bom-ref": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5\u0026package-id=206fdb47b3e980eb",
175668          "supplier": {},
175669          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
175670          "name": "scanelf",
175671          "version": "1.3.4-r0",
175672          "description": "Scan ELF binaries for stuff",
175673          "licenses": [
175674            {
175675              "license": {
175676                "id": "GPL-2.0-only"
175677              }
175678            }
175679          ],
175680          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.4-r0:*:*:*:*:*:*:*",
175681          "purl": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5",
175682          "swid": {
175683            "attachment": {}
175684          },
175685          "pedigree": {},
175686          "externalReferences": [
175687            {
175688              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
175689              "type": "distribution"
175690            }
175691          ],
175692          "evidence": {},
175693          "signature": {
175694            "signature": {
175695              "publicKey": {}
175696            }
175697          },
175698          "modelCard": {
175699            "modelParameters": {
175700              "approach": {}
175701            },
175702            "quantitativeAnalysis": {
175703              "graphics": {}
175704            },
175705            "considerations": {}
175706          }
175707        },
175708        {
175709          "type": "library",
175710          "bom-ref": "pkg:npm/scss-tokenizer@0.2.3?package-id=66abb25b2e8aae0",
175711          "supplier": {},
175712          "author": "xzyfer",
175713          "name": "scss-tokenizer",
175714          "version": "0.2.3",
175715          "description": "A tokenzier for Sass' SCSS syntax",
175716          "licenses": [
175717            {
175718              "license": {
175719                "id": "MIT"
175720              }
175721            }
175722          ],
175723          "cpe": "cpe:2.3:a:scss-tokenizer:scss-tokenizer:0.2.3:*:*:*:*:*:*:*",
175724          "purl": "pkg:npm/scss-tokenizer@0.2.3",
175725          "swid": {
175726            "attachment": {}
175727          },
175728          "pedigree": {},
175729          "externalReferences": [
175730            {
175731              "url": "https://github.com/sasstools/scss-tokenizer.git",
175732              "type": "distribution"
175733            },
175734            {
175735              "url": "https://github.com/sasstools/scss-tokenizer",
175736              "type": "website"
175737            }
175738          ],
175739          "evidence": {},
175740          "signature": {
175741            "signature": {
175742              "publicKey": {}
175743            }
175744          },
175745          "modelCard": {
175746            "modelParameters": {
175747              "approach": {}
175748            },
175749            "quantitativeAnalysis": {
175750              "graphics": {}
175751            },
175752            "considerations": {}
175753          }
175754        },
175755        {
175756          "type": "library",
175757          "bom-ref": "pkg:npm/semver@5.7.1?package-id=c944ab3d54a3a640",
175758          "supplier": {},
175759          "name": "semver",
175760          "version": "5.7.1",
175761          "description": "The semantic version parser used by npm.",
175762          "licenses": [
175763            {
175764              "license": {
175765                "id": "ISC"
175766              }
175767            }
175768          ],
175769          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
175770          "purl": "pkg:npm/semver@5.7.1",
175771          "swid": {
175772            "attachment": {}
175773          },
175774          "pedigree": {},
175775          "externalReferences": [
175776            {
175777              "url": "https://github.com/npm/node-semver",
175778              "type": "distribution"
175779            }
175780          ],
175781          "evidence": {},
175782          "signature": {
175783            "signature": {
175784              "publicKey": {}
175785            }
175786          },
175787          "modelCard": {
175788            "modelParameters": {
175789              "approach": {}
175790            },
175791            "quantitativeAnalysis": {
175792              "graphics": {}
175793            },
175794            "considerations": {}
175795          }
175796        },
175797        {
175798          "type": "library",
175799          "bom-ref": "pkg:npm/semver@7.3.7?package-id=73e16bb8e099774",
175800          "supplier": {},
175801          "author": "GitHub Inc.",
175802          "name": "semver",
175803          "version": "7.3.7",
175804          "description": "The semantic version parser used by npm.",
175805          "licenses": [
175806            {
175807              "license": {
175808                "id": "ISC"
175809              }
175810            }
175811          ],
175812          "cpe": "cpe:2.3:a:semver:semver:7.3.7:*:*:*:*:*:*:*",
175813          "purl": "pkg:npm/semver@7.3.7",
175814          "swid": {
175815            "attachment": {}
175816          },
175817          "pedigree": {},
175818          "externalReferences": [
175819            {
175820              "url": "https://github.com/npm/node-semver.git",
175821              "type": "distribution"
175822            }
175823          ],
175824          "evidence": {},
175825          "signature": {
175826            "signature": {
175827              "publicKey": {}
175828            }
175829          },
175830          "modelCard": {
175831            "modelParameters": {
175832              "approach": {}
175833            },
175834            "quantitativeAnalysis": {
175835              "graphics": {}
175836            },
175837            "considerations": {}
175838          }
175839        },
175840        {
175841          "type": "library",
175842          "bom-ref": "pkg:npm/semver@7.3.8?package-id=665caad5b223ed6f",
175843          "supplier": {},
175844          "author": "GitHub Inc.",
175845          "name": "semver",
175846          "version": "7.3.8",
175847          "description": "The semantic version parser used by npm.",
175848          "licenses": [
175849            {
175850              "license": {
175851                "id": "ISC"
175852              }
175853            }
175854          ],
175855          "cpe": "cpe:2.3:a:semver:semver:7.3.8:*:*:*:*:*:*:*",
175856          "purl": "pkg:npm/semver@7.3.8",
175857          "swid": {
175858            "attachment": {}
175859          },
175860          "pedigree": {},
175861          "externalReferences": [
175862            {
175863              "url": "https://github.com/npm/node-semver.git",
175864              "type": "distribution"
175865            }
175866          ],
175867          "evidence": {},
175868          "signature": {
175869            "signature": {
175870              "publicKey": {}
175871            }
175872          },
175873          "modelCard": {
175874            "modelParameters": {
175875              "approach": {}
175876            },
175877            "quantitativeAnalysis": {
175878              "graphics": {}
175879            },
175880            "considerations": {}
175881          }
175882        },
175883        {
175884          "type": "library",
175885          "bom-ref": "pkg:npm/send@0.17.1?package-id=5cf87af6e2815632",
175886          "supplier": {},
175887          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
175888          "name": "send",
175889          "version": "0.17.1",
175890          "description": "Better streaming static file server with Range and conditional-GET support",
175891          "licenses": [
175892            {
175893              "license": {
175894                "id": "MIT"
175895              }
175896            }
175897          ],
175898          "cpe": "cpe:2.3:a:send:send:0.17.1:*:*:*:*:*:*:*",
175899          "purl": "pkg:npm/send@0.17.1",
175900          "swid": {
175901            "attachment": {}
175902          },
175903          "pedigree": {},
175904          "externalReferences": [
175905            {
175906              "url": "pillarjs/send",
175907              "type": "distribution"
175908            }
175909          ],
175910          "evidence": {},
175911          "signature": {
175912            "signature": {
175913              "publicKey": {}
175914            }
175915          },
175916          "modelCard": {
175917            "modelParameters": {
175918              "approach": {}
175919            },
175920            "quantitativeAnalysis": {
175921              "graphics": {}
175922            },
175923            "considerations": {}
175924          }
175925        },
175926        {
175927          "type": "library",
175928          "bom-ref": "pkg:npm/serve-static@1.14.1?package-id=5a9e309a893cc7fa",
175929          "supplier": {},
175930          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
175931          "name": "serve-static",
175932          "version": "1.14.1",
175933          "description": "Serve static files",
175934          "licenses": [
175935            {
175936              "license": {
175937                "id": "MIT"
175938              }
175939            }
175940          ],
175941          "cpe": "cpe:2.3:a:serve-static:serve-static:1.14.1:*:*:*:*:*:*:*",
175942          "purl": "pkg:npm/serve-static@1.14.1",
175943          "swid": {
175944            "attachment": {}
175945          },
175946          "pedigree": {},
175947          "externalReferences": [
175948            {
175949              "url": "expressjs/serve-static",
175950              "type": "distribution"
175951            }
175952          ],
175953          "evidence": {},
175954          "signature": {
175955            "signature": {
175956              "publicKey": {}
175957            }
175958          },
175959          "modelCard": {
175960            "modelParameters": {
175961              "approach": {}
175962            },
175963            "quantitativeAnalysis": {
175964              "graphics": {}
175965            },
175966            "considerations": {}
175967          }
175968        },
175969        {
175970          "type": "library",
175971          "bom-ref": "pkg:npm/set-blocking@2.0.0?package-id=bac85cbb844de9c9",
175972          "supplier": {},
175973          "author": "Ben Coe \u003cben@npmjs.com\u003e",
175974          "name": "set-blocking",
175975          "version": "2.0.0",
175976          "description": "set blocking stdio and stderr ensuring that terminal output does not truncate",
175977          "licenses": [
175978            {
175979              "license": {
175980                "id": "ISC"
175981              }
175982            }
175983          ],
175984          "cpe": "cpe:2.3:a:set-blocking:set-blocking:2.0.0:*:*:*:*:*:*:*",
175985          "purl": "pkg:npm/set-blocking@2.0.0",
175986          "swid": {
175987            "attachment": {}
175988          },
175989          "pedigree": {},
175990          "externalReferences": [
175991            {
175992              "url": "git+https://github.com/yargs/set-blocking.git",
175993              "type": "distribution"
175994            },
175995            {
175996              "url": "https://github.com/yargs/set-blocking#readme",
175997              "type": "website"
175998            }
175999          ],
176000          "evidence": {},
176001          "signature": {
176002            "signature": {
176003              "publicKey": {}
176004            }
176005          },
176006          "modelCard": {
176007            "modelParameters": {
176008              "approach": {}
176009            },
176010            "quantitativeAnalysis": {
176011              "graphics": {}
176012            },
176013            "considerations": {}
176014          }
176015        },
176016        {
176017          "type": "library",
176018          "bom-ref": "pkg:npm/set-blocking@2.0.0?package-id=eedd514f5da11e23",
176019          "supplier": {},
176020          "author": "Ben Coe \u003cben@npmjs.com\u003e",
176021          "name": "set-blocking",
176022          "version": "2.0.0",
176023          "description": "set blocking stdio and stderr ensuring that terminal output does not truncate",
176024          "licenses": [
176025            {
176026              "license": {
176027                "id": "ISC"
176028              }
176029            }
176030          ],
176031          "cpe": "cpe:2.3:a:set-blocking:set-blocking:2.0.0:*:*:*:*:*:*:*",
176032          "purl": "pkg:npm/set-blocking@2.0.0",
176033          "swid": {
176034            "attachment": {}
176035          },
176036          "pedigree": {},
176037          "externalReferences": [
176038            {
176039              "url": "git+https://github.com/yargs/set-blocking.git",
176040              "type": "distribution"
176041            },
176042            {
176043              "url": "https://github.com/yargs/set-blocking#readme",
176044              "type": "website"
176045            }
176046          ],
176047          "evidence": {},
176048          "signature": {
176049            "signature": {
176050              "publicKey": {}
176051            }
176052          },
176053          "modelCard": {
176054            "modelParameters": {
176055              "approach": {}
176056            },
176057            "quantitativeAnalysis": {
176058              "graphics": {}
176059            },
176060            "considerations": {}
176061          }
176062        },
176063        {
176064          "type": "library",
176065          "bom-ref": "pkg:npm/set-immediate-shim@1.0.1?package-id=fdec1f5d3db6562c",
176066          "supplier": {},
176067          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
176068          "name": "set-immediate-shim",
176069          "version": "1.0.1",
176070          "description": "Simple setImmediate shim",
176071          "licenses": [
176072            {
176073              "license": {
176074                "id": "MIT"
176075              }
176076            }
176077          ],
176078          "cpe": "cpe:2.3:a:set-immediate-shim:set-immediate-shim:1.0.1:*:*:*:*:*:*:*",
176079          "purl": "pkg:npm/set-immediate-shim@1.0.1",
176080          "swid": {
176081            "attachment": {}
176082          },
176083          "pedigree": {},
176084          "externalReferences": [
176085            {
176086              "url": "sindresorhus/set-immediate-shim",
176087              "type": "distribution"
176088            }
176089          ],
176090          "evidence": {},
176091          "signature": {
176092            "signature": {
176093              "publicKey": {}
176094            }
176095          },
176096          "modelCard": {
176097            "modelParameters": {
176098              "approach": {}
176099            },
176100            "quantitativeAnalysis": {
176101              "graphics": {}
176102            },
176103            "considerations": {}
176104          }
176105        },
176106        {
176107          "type": "library",
176108          "bom-ref": "pkg:npm/setprototypeof@1.1.1?package-id=221ad70c81d999c5",
176109          "supplier": {},
176110          "author": "Wes Todd",
176111          "name": "setprototypeof",
176112          "version": "1.1.1",
176113          "description": "A small polyfill for Object.setprototypeof",
176114          "licenses": [
176115            {
176116              "license": {
176117                "id": "ISC"
176118              }
176119            }
176120          ],
176121          "cpe": "cpe:2.3:a:setprototypeof:setprototypeof:1.1.1:*:*:*:*:*:*:*",
176122          "purl": "pkg:npm/setprototypeof@1.1.1",
176123          "swid": {
176124            "attachment": {}
176125          },
176126          "pedigree": {},
176127          "externalReferences": [
176128            {
176129              "url": "https://github.com/wesleytodd/setprototypeof.git",
176130              "type": "distribution"
176131            },
176132            {
176133              "url": "https://github.com/wesleytodd/setprototypeof",
176134              "type": "website"
176135            }
176136          ],
176137          "evidence": {},
176138          "signature": {
176139            "signature": {
176140              "publicKey": {}
176141            }
176142          },
176143          "modelCard": {
176144            "modelParameters": {
176145              "approach": {}
176146            },
176147            "quantitativeAnalysis": {
176148              "graphics": {}
176149            },
176150            "considerations": {}
176151          }
176152        },
176153        {
176154          "type": "library",
176155          "bom-ref": "pkg:npm/shebang-command@2.0.0?package-id=a89760612079cb7d",
176156          "supplier": {},
176157          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
176158          "name": "shebang-command",
176159          "version": "2.0.0",
176160          "description": "Get the command from a shebang",
176161          "licenses": [
176162            {
176163              "license": {
176164                "id": "MIT"
176165              }
176166            }
176167          ],
176168          "cpe": "cpe:2.3:a:shebang-command:shebang-command:2.0.0:*:*:*:*:*:*:*",
176169          "purl": "pkg:npm/shebang-command@2.0.0",
176170          "swid": {
176171            "attachment": {}
176172          },
176173          "pedigree": {},
176174          "externalReferences": [
176175            {
176176              "url": "kevva/shebang-command",
176177              "type": "distribution"
176178            }
176179          ],
176180          "evidence": {},
176181          "signature": {
176182            "signature": {
176183              "publicKey": {}
176184            }
176185          },
176186          "modelCard": {
176187            "modelParameters": {
176188              "approach": {}
176189            },
176190            "quantitativeAnalysis": {
176191              "graphics": {}
176192            },
176193            "considerations": {}
176194          }
176195        },
176196        {
176197          "type": "library",
176198          "bom-ref": "pkg:npm/shebang-regex@3.0.0?package-id=f5411c29bb38615e",
176199          "supplier": {},
176200          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
176201          "name": "shebang-regex",
176202          "version": "3.0.0",
176203          "description": "Regular expression for matching a shebang line",
176204          "licenses": [
176205            {
176206              "license": {
176207                "id": "MIT"
176208              }
176209            }
176210          ],
176211          "cpe": "cpe:2.3:a:shebang-regex:shebang-regex:3.0.0:*:*:*:*:*:*:*",
176212          "purl": "pkg:npm/shebang-regex@3.0.0",
176213          "swid": {
176214            "attachment": {}
176215          },
176216          "pedigree": {},
176217          "externalReferences": [
176218            {
176219              "url": "sindresorhus/shebang-regex",
176220              "type": "distribution"
176221            }
176222          ],
176223          "evidence": {},
176224          "signature": {
176225            "signature": {
176226              "publicKey": {}
176227            }
176228          },
176229          "modelCard": {
176230            "modelParameters": {
176231              "approach": {}
176232            },
176233            "quantitativeAnalysis": {
176234              "graphics": {}
176235            },
176236            "considerations": {}
176237          }
176238        },
176239        {
176240          "type": "library",
176241          "bom-ref": "pkg:npm/signal-exit@3.0.7?package-id=998659694cba1dfd",
176242          "supplier": {},
176243          "author": "Ben Coe \u003cben@npmjs.com\u003e",
176244          "name": "signal-exit",
176245          "version": "3.0.7",
176246          "description": "when you want to fire an event no matter how a process exits.",
176247          "licenses": [
176248            {
176249              "license": {
176250                "id": "ISC"
176251              }
176252            }
176253          ],
176254          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.7:*:*:*:*:*:*:*",
176255          "purl": "pkg:npm/signal-exit@3.0.7",
176256          "swid": {
176257            "attachment": {}
176258          },
176259          "pedigree": {},
176260          "externalReferences": [
176261            {
176262              "url": "https://github.com/tapjs/signal-exit.git",
176263              "type": "distribution"
176264            },
176265            {
176266              "url": "https://github.com/tapjs/signal-exit",
176267              "type": "website"
176268            }
176269          ],
176270          "evidence": {},
176271          "signature": {
176272            "signature": {
176273              "publicKey": {}
176274            }
176275          },
176276          "modelCard": {
176277            "modelParameters": {
176278              "approach": {}
176279            },
176280            "quantitativeAnalysis": {
176281              "graphics": {}
176282            },
176283            "considerations": {}
176284          }
176285        },
176286        {
176287          "type": "library",
176288          "bom-ref": "pkg:npm/signal-exit@3.0.7?package-id=133483a000431c75",
176289          "supplier": {},
176290          "author": "Ben Coe \u003cben@npmjs.com\u003e",
176291          "name": "signal-exit",
176292          "version": "3.0.7",
176293          "description": "when you want to fire an event no matter how a process exits.",
176294          "licenses": [
176295            {
176296              "license": {
176297                "id": "ISC"
176298              }
176299            }
176300          ],
176301          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.7:*:*:*:*:*:*:*",
176302          "purl": "pkg:npm/signal-exit@3.0.7",
176303          "swid": {
176304            "attachment": {}
176305          },
176306          "pedigree": {},
176307          "externalReferences": [
176308            {
176309              "url": "https://github.com/tapjs/signal-exit.git",
176310              "type": "distribution"
176311            },
176312            {
176313              "url": "https://github.com/tapjs/signal-exit",
176314              "type": "website"
176315            }
176316          ],
176317          "evidence": {},
176318          "signature": {
176319            "signature": {
176320              "publicKey": {}
176321            }
176322          },
176323          "modelCard": {
176324            "modelParameters": {
176325              "approach": {}
176326            },
176327            "quantitativeAnalysis": {
176328              "graphics": {}
176329            },
176330            "considerations": {}
176331          }
176332        },
176333        {
176334          "type": "library",
176335          "bom-ref": "pkg:npm/smart-buffer@4.2.0?package-id=ad322c124ae3043c",
176336          "supplier": {},
176337          "author": "Josh Glazebrook",
176338          "name": "smart-buffer",
176339          "version": "4.2.0",
176340          "description": "smart-buffer is a Buffer wrapper that adds automatic read \u0026 write offset tracking, string operations, data insertions, and more.",
176341          "licenses": [
176342            {
176343              "license": {
176344                "id": "MIT"
176345              }
176346            }
176347          ],
176348          "cpe": "cpe:2.3:a:JoshGlazebrook:smart-buffer:4.2.0:*:*:*:*:*:*:*",
176349          "purl": "pkg:npm/smart-buffer@4.2.0",
176350          "swid": {
176351            "attachment": {}
176352          },
176353          "pedigree": {},
176354          "externalReferences": [
176355            {
176356              "url": "https://github.com/JoshGlazebrook/smart-buffer.git",
176357              "type": "distribution"
176358            },
176359            {
176360              "url": "https://github.com/JoshGlazebrook/smart-buffer/",
176361              "type": "website"
176362            }
176363          ],
176364          "evidence": {},
176365          "signature": {
176366            "signature": {
176367              "publicKey": {}
176368            }
176369          },
176370          "modelCard": {
176371            "modelParameters": {
176372              "approach": {}
176373            },
176374            "quantitativeAnalysis": {
176375              "graphics": {}
176376            },
176377            "considerations": {}
176378          }
176379        },
176380        {
176381          "type": "library",
176382          "bom-ref": "pkg:npm/socks@2.7.0?package-id=267f6eb3d489a8eb",
176383          "supplier": {},
176384          "author": "Josh Glazebrook",
176385          "name": "socks",
176386          "version": "2.7.0",
176387          "description": "Fully featured SOCKS proxy client supporting SOCKSv4, SOCKSv4a, and SOCKSv5. Includes Bind and Associate functionality.",
176388          "licenses": [
176389            {
176390              "license": {
176391                "id": "MIT"
176392              }
176393            }
176394          ],
176395          "cpe": "cpe:2.3:a:JoshGlazebrook:socks:2.7.0:*:*:*:*:*:*:*",
176396          "purl": "pkg:npm/socks@2.7.0",
176397          "swid": {
176398            "attachment": {}
176399          },
176400          "pedigree": {},
176401          "externalReferences": [
176402            {
176403              "url": "https://github.com/JoshGlazebrook/socks.git",
176404              "type": "distribution"
176405            },
176406            {
176407              "url": "https://github.com/JoshGlazebrook/socks/",
176408              "type": "website"
176409            }
176410          ],
176411          "evidence": {},
176412          "signature": {
176413            "signature": {
176414              "publicKey": {}
176415            }
176416          },
176417          "modelCard": {
176418            "modelParameters": {
176419              "approach": {}
176420            },
176421            "quantitativeAnalysis": {
176422              "graphics": {}
176423            },
176424            "considerations": {}
176425          }
176426        },
176427        {
176428          "type": "library",
176429          "bom-ref": "pkg:npm/socks-proxy-agent@7.0.0?package-id=8dc0e605920052a1",
176430          "supplier": {},
176431          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
176432          "name": "socks-proxy-agent",
176433          "version": "7.0.0",
176434          "description": "A SOCKS proxy `http.Agent` implementation for HTTP and HTTPS",
176435          "licenses": [
176436            {
176437              "license": {
176438                "id": "MIT"
176439              }
176440            }
176441          ],
176442          "cpe": "cpe:2.3:a:socks-proxy-agent:socks-proxy-agent:7.0.0:*:*:*:*:*:*:*",
176443          "purl": "pkg:npm/socks-proxy-agent@7.0.0",
176444          "swid": {
176445            "attachment": {}
176446          },
176447          "pedigree": {},
176448          "externalReferences": [
176449            {
176450              "url": "git://github.com/TooTallNate/node-socks-proxy-agent.git",
176451              "type": "distribution"
176452            },
176453            {
176454              "url": "https://github.com/TooTallNate/node-socks-proxy-agent#readme",
176455              "type": "website"
176456            }
176457          ],
176458          "evidence": {},
176459          "signature": {
176460            "signature": {
176461              "publicKey": {}
176462            }
176463          },
176464          "modelCard": {
176465            "modelParameters": {
176466              "approach": {}
176467            },
176468            "quantitativeAnalysis": {
176469              "graphics": {}
176470            },
176471            "considerations": {}
176472          }
176473        },
176474        {
176475          "type": "library",
176476          "bom-ref": "pkg:npm/source-map@0.4.4?package-id=cadf33a697da7f07",
176477          "supplier": {},
176478          "author": "Nick Fitzgerald \u003cnfitzgerald@mozilla.com\u003e",
176479          "name": "source-map",
176480          "version": "0.4.4",
176481          "description": "Generates and consumes source maps",
176482          "licenses": [
176483            {
176484              "license": {
176485                "id": "BSD-3-Clause"
176486              }
176487            }
176488          ],
176489          "cpe": "cpe:2.3:a:source-map:source-map:0.4.4:*:*:*:*:*:*:*",
176490          "purl": "pkg:npm/source-map@0.4.4",
176491          "swid": {
176492            "attachment": {}
176493          },
176494          "pedigree": {},
176495          "externalReferences": [
176496            {
176497              "url": "http://github.com/mozilla/source-map.git",
176498              "type": "distribution"
176499            },
176500            {
176501              "url": "https://github.com/mozilla/source-map",
176502              "type": "website"
176503            }
176504          ],
176505          "evidence": {},
176506          "signature": {
176507            "signature": {
176508              "publicKey": {}
176509            }
176510          },
176511          "modelCard": {
176512            "modelParameters": {
176513              "approach": {}
176514            },
176515            "quantitativeAnalysis": {
176516              "graphics": {}
176517            },
176518            "considerations": {}
176519          }
176520        },
176521        {
176522          "type": "library",
176523          "bom-ref": "pkg:npm/spdx-correct@3.1.1?package-id=d6b0214947e454eb",
176524          "supplier": {},
176525          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
176526          "name": "spdx-correct",
176527          "version": "3.1.1",
176528          "description": "correct invalid SPDX expressions",
176529          "licenses": [
176530            {
176531              "license": {
176532                "id": "Apache-2.0"
176533              }
176534            }
176535          ],
176536          "cpe": "cpe:2.3:a:spdx-correct:spdx-correct:3.1.1:*:*:*:*:*:*:*",
176537          "purl": "pkg:npm/spdx-correct@3.1.1",
176538          "swid": {
176539            "attachment": {}
176540          },
176541          "pedigree": {},
176542          "externalReferences": [
176543            {
176544              "url": "jslicense/spdx-correct.js",
176545              "type": "distribution"
176546            }
176547          ],
176548          "evidence": {},
176549          "signature": {
176550            "signature": {
176551              "publicKey": {}
176552            }
176553          },
176554          "modelCard": {
176555            "modelParameters": {
176556              "approach": {}
176557            },
176558            "quantitativeAnalysis": {
176559              "graphics": {}
176560            },
176561            "considerations": {}
176562          }
176563        },
176564        {
176565          "type": "library",
176566          "bom-ref": "pkg:npm/spdx-correct@3.2.0?package-id=354ef0f5eebdb222",
176567          "supplier": {},
176568          "name": "spdx-correct",
176569          "version": "3.2.0",
176570          "description": "correct invalid SPDX expressions",
176571          "licenses": [
176572            {
176573              "license": {
176574                "id": "Apache-2.0"
176575              }
176576            }
176577          ],
176578          "cpe": "cpe:2.3:a:spdx-correct:spdx-correct:3.2.0:*:*:*:*:*:*:*",
176579          "purl": "pkg:npm/spdx-correct@3.2.0",
176580          "swid": {
176581            "attachment": {}
176582          },
176583          "pedigree": {},
176584          "externalReferences": [
176585            {
176586              "url": "jslicense/spdx-correct.js",
176587              "type": "distribution"
176588            }
176589          ],
176590          "evidence": {},
176591          "signature": {
176592            "signature": {
176593              "publicKey": {}
176594            }
176595          },
176596          "modelCard": {
176597            "modelParameters": {
176598              "approach": {}
176599            },
176600            "quantitativeAnalysis": {
176601              "graphics": {}
176602            },
176603            "considerations": {}
176604          }
176605        },
176606        {
176607          "type": "library",
176608          "bom-ref": "pkg:npm/spdx-exceptions@2.3.0?package-id=22aa1fb7c596c6c7",
176609          "supplier": {},
176610          "author": "The Linux Foundation",
176611          "name": "spdx-exceptions",
176612          "version": "2.3.0",
176613          "description": "list of SPDX standard license exceptions",
176614          "licenses": [
176615            {
176616              "license": {
176617                "id": "CC-BY-3.0"
176618              }
176619            }
176620          ],
176621          "cpe": "cpe:2.3:a:spdx-exceptions:spdx-exceptions:2.3.0:*:*:*:*:*:*:*",
176622          "purl": "pkg:npm/spdx-exceptions@2.3.0",
176623          "swid": {
176624            "attachment": {}
176625          },
176626          "pedigree": {},
176627          "externalReferences": [
176628            {
176629              "url": "kemitchell/spdx-exceptions.json",
176630              "type": "distribution"
176631            }
176632          ],
176633          "evidence": {},
176634          "signature": {
176635            "signature": {
176636              "publicKey": {}
176637            }
176638          },
176639          "modelCard": {
176640            "modelParameters": {
176641              "approach": {}
176642            },
176643            "quantitativeAnalysis": {
176644              "graphics": {}
176645            },
176646            "considerations": {}
176647          }
176648        },
176649        {
176650          "type": "library",
176651          "bom-ref": "pkg:npm/spdx-exceptions@2.3.0?package-id=a66d428fbb321cc7",
176652          "supplier": {},
176653          "author": "The Linux Foundation",
176654          "name": "spdx-exceptions",
176655          "version": "2.3.0",
176656          "description": "list of SPDX standard license exceptions",
176657          "licenses": [
176658            {
176659              "license": {
176660                "id": "CC-BY-3.0"
176661              }
176662            }
176663          ],
176664          "cpe": "cpe:2.3:a:spdx-exceptions:spdx-exceptions:2.3.0:*:*:*:*:*:*:*",
176665          "purl": "pkg:npm/spdx-exceptions@2.3.0",
176666          "swid": {
176667            "attachment": {}
176668          },
176669          "pedigree": {},
176670          "externalReferences": [
176671            {
176672              "url": "kemitchell/spdx-exceptions.json",
176673              "type": "distribution"
176674            }
176675          ],
176676          "evidence": {},
176677          "signature": {
176678            "signature": {
176679              "publicKey": {}
176680            }
176681          },
176682          "modelCard": {
176683            "modelParameters": {
176684              "approach": {}
176685            },
176686            "quantitativeAnalysis": {
176687              "graphics": {}
176688            },
176689            "considerations": {}
176690          }
176691        },
176692        {
176693          "type": "library",
176694          "bom-ref": "pkg:npm/spdx-expression-parse@3.0.1?package-id=78c73c9b189e2783",
176695          "supplier": {},
176696          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
176697          "name": "spdx-expression-parse",
176698          "version": "3.0.1",
176699          "description": "parse SPDX license expressions",
176700          "licenses": [
176701            {
176702              "license": {
176703                "id": "MIT"
176704              }
176705            }
176706          ],
176707          "cpe": "cpe:2.3:a:spdx-expression-parse:spdx-expression-parse:3.0.1:*:*:*:*:*:*:*",
176708          "purl": "pkg:npm/spdx-expression-parse@3.0.1",
176709          "swid": {
176710            "attachment": {}
176711          },
176712          "pedigree": {},
176713          "externalReferences": [
176714            {
176715              "url": "jslicense/spdx-expression-parse.js",
176716              "type": "distribution"
176717            }
176718          ],
176719          "evidence": {},
176720          "signature": {
176721            "signature": {
176722              "publicKey": {}
176723            }
176724          },
176725          "modelCard": {
176726            "modelParameters": {
176727              "approach": {}
176728            },
176729            "quantitativeAnalysis": {
176730              "graphics": {}
176731            },
176732            "considerations": {}
176733          }
176734        },
176735        {
176736          "type": "library",
176737          "bom-ref": "pkg:npm/spdx-expression-parse@3.0.1?package-id=f20cbacf4a471831",
176738          "supplier": {},
176739          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
176740          "name": "spdx-expression-parse",
176741          "version": "3.0.1",
176742          "description": "parse SPDX license expressions",
176743          "licenses": [
176744            {
176745              "license": {
176746                "id": "MIT"
176747              }
176748            }
176749          ],
176750          "cpe": "cpe:2.3:a:spdx-expression-parse:spdx-expression-parse:3.0.1:*:*:*:*:*:*:*",
176751          "purl": "pkg:npm/spdx-expression-parse@3.0.1",
176752          "swid": {
176753            "attachment": {}
176754          },
176755          "pedigree": {},
176756          "externalReferences": [
176757            {
176758              "url": "jslicense/spdx-expression-parse.js",
176759              "type": "distribution"
176760            }
176761          ],
176762          "evidence": {},
176763          "signature": {
176764            "signature": {
176765              "publicKey": {}
176766            }
176767          },
176768          "modelCard": {
176769            "modelParameters": {
176770              "approach": {}
176771            },
176772            "quantitativeAnalysis": {
176773              "graphics": {}
176774            },
176775            "considerations": {}
176776          }
176777        },
176778        {
176779          "type": "library",
176780          "bom-ref": "pkg:npm/spdx-license-ids@3.0.11?package-id=6530ac28616ec508",
176781          "supplier": {},
176782          "author": "Shinnosuke Watanabe (https://github.com/shinnn)",
176783          "name": "spdx-license-ids",
176784          "version": "3.0.11",
176785          "description": "A list of SPDX license identifiers",
176786          "licenses": [
176787            {
176788              "license": {
176789                "id": "CC0-1.0"
176790              }
176791            }
176792          ],
176793          "cpe": "cpe:2.3:a:spdx-license-ids:spdx-license-ids:3.0.11:*:*:*:*:*:*:*",
176794          "purl": "pkg:npm/spdx-license-ids@3.0.11",
176795          "swid": {
176796            "attachment": {}
176797          },
176798          "pedigree": {},
176799          "externalReferences": [
176800            {
176801              "url": "jslicense/spdx-license-ids",
176802              "type": "distribution"
176803            }
176804          ],
176805          "evidence": {},
176806          "signature": {
176807            "signature": {
176808              "publicKey": {}
176809            }
176810          },
176811          "modelCard": {
176812            "modelParameters": {
176813              "approach": {}
176814            },
176815            "quantitativeAnalysis": {
176816              "graphics": {}
176817            },
176818            "considerations": {}
176819          }
176820        },
176821        {
176822          "type": "library",
176823          "bom-ref": "pkg:npm/spdx-license-ids@3.0.13?package-id=b973922dc641c6a7",
176824          "supplier": {},
176825          "author": "Shinnosuke Watanabe (https://github.com/shinnn)",
176826          "name": "spdx-license-ids",
176827          "version": "3.0.13",
176828          "description": "A list of SPDX license identifiers",
176829          "licenses": [
176830            {
176831              "license": {
176832                "id": "CC0-1.0"
176833              }
176834            }
176835          ],
176836          "cpe": "cpe:2.3:a:spdx-license-ids:spdx-license-ids:3.0.13:*:*:*:*:*:*:*",
176837          "purl": "pkg:npm/spdx-license-ids@3.0.13",
176838          "swid": {
176839            "attachment": {}
176840          },
176841          "pedigree": {},
176842          "externalReferences": [
176843            {
176844              "url": "jslicense/spdx-license-ids",
176845              "type": "distribution"
176846            }
176847          ],
176848          "evidence": {},
176849          "signature": {
176850            "signature": {
176851              "publicKey": {}
176852            }
176853          },
176854          "modelCard": {
176855            "modelParameters": {
176856              "approach": {}
176857            },
176858            "quantitativeAnalysis": {
176859              "graphics": {}
176860            },
176861            "considerations": {}
176862          }
176863        },
176864        {
176865          "type": "library",
176866          "bom-ref": "pkg:npm/sshpk@1.17.0?package-id=343f480d60c250d6",
176867          "supplier": {},
176868          "author": "Joyent, Inc",
176869          "name": "sshpk",
176870          "version": "1.17.0",
176871          "description": "A library for finding and using SSH public keys",
176872          "licenses": [
176873            {
176874              "license": {
176875                "id": "MIT"
176876              }
176877            }
176878          ],
176879          "cpe": "cpe:2.3:a:arekinath:sshpk:1.17.0:*:*:*:*:*:*:*",
176880          "purl": "pkg:npm/sshpk@1.17.0",
176881          "swid": {
176882            "attachment": {}
176883          },
176884          "pedigree": {},
176885          "externalReferences": [
176886            {
176887              "url": "git+https://github.com/joyent/node-sshpk.git",
176888              "type": "distribution"
176889            },
176890            {
176891              "url": "https://github.com/arekinath/node-sshpk#readme",
176892              "type": "website"
176893            }
176894          ],
176895          "evidence": {},
176896          "signature": {
176897            "signature": {
176898              "publicKey": {}
176899            }
176900          },
176901          "modelCard": {
176902            "modelParameters": {
176903              "approach": {}
176904            },
176905            "quantitativeAnalysis": {
176906              "graphics": {}
176907            },
176908            "considerations": {}
176909          }
176910        },
176911        {
176912          "type": "library",
176913          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5\u0026package-id=674d1e2fba4d633a",
176914          "supplier": {},
176915          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
176916          "name": "ssl_client",
176917          "version": "1.35.0-r17",
176918          "description": "EXternal ssl_client for busybox wget",
176919          "licenses": [
176920            {
176921              "license": {
176922                "id": "GPL-2.0-only"
176923              }
176924            }
176925          ],
176926          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r17:*:*:*:*:*:*:*",
176927          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5",
176928          "swid": {
176929            "attachment": {}
176930          },
176931          "pedigree": {},
176932          "externalReferences": [
176933            {
176934              "url": "https://busybox.net/",
176935              "type": "distribution"
176936            }
176937          ],
176938          "evidence": {},
176939          "signature": {
176940            "signature": {
176941              "publicKey": {}
176942            }
176943          },
176944          "modelCard": {
176945            "modelParameters": {
176946              "approach": {}
176947            },
176948            "quantitativeAnalysis": {
176949              "graphics": {}
176950            },
176951            "considerations": {}
176952          }
176953        },
176954        {
176955          "type": "library",
176956          "bom-ref": "pkg:npm/ssri@9.0.1?package-id=49986701356bf646",
176957          "supplier": {},
176958          "author": "GitHub Inc.",
176959          "name": "ssri",
176960          "version": "9.0.1",
176961          "description": "Standard Subresource Integrity library -- parses, serializes, generates, and verifies integrity metadata according to the SRI spec.",
176962          "licenses": [
176963            {
176964              "license": {
176965                "id": "ISC"
176966              }
176967            }
176968          ],
176969          "cpe": "cpe:2.3:a:ssri:ssri:9.0.1:*:*:*:*:*:*:*",
176970          "purl": "pkg:npm/ssri@9.0.1",
176971          "swid": {
176972            "attachment": {}
176973          },
176974          "pedigree": {},
176975          "externalReferences": [
176976            {
176977              "url": "https://github.com/npm/ssri.git",
176978              "type": "distribution"
176979            }
176980          ],
176981          "evidence": {},
176982          "signature": {
176983            "signature": {
176984              "publicKey": {}
176985            }
176986          },
176987          "modelCard": {
176988            "modelParameters": {
176989              "approach": {}
176990            },
176991            "quantitativeAnalysis": {
176992              "graphics": {}
176993            },
176994            "considerations": {}
176995          }
176996        },
176997        {
176998          "type": "library",
176999          "bom-ref": "pkg:npm/statuses@1.5.0?package-id=96ff1cfb5add4c46",
177000          "supplier": {},
177001          "name": "statuses",
177002          "version": "1.5.0",
177003          "description": "HTTP status utility",
177004          "licenses": [
177005            {
177006              "license": {
177007                "id": "MIT"
177008              }
177009            }
177010          ],
177011          "cpe": "cpe:2.3:a:statuses:statuses:1.5.0:*:*:*:*:*:*:*",
177012          "purl": "pkg:npm/statuses@1.5.0",
177013          "swid": {
177014            "attachment": {}
177015          },
177016          "pedigree": {},
177017          "externalReferences": [
177018            {
177019              "url": "jshttp/statuses",
177020              "type": "distribution"
177021            }
177022          ],
177023          "evidence": {},
177024          "signature": {
177025            "signature": {
177026              "publicKey": {}
177027            }
177028          },
177029          "modelCard": {
177030            "modelParameters": {
177031              "approach": {}
177032            },
177033            "quantitativeAnalysis": {
177034              "graphics": {}
177035            },
177036            "considerations": {}
177037          }
177038        },
177039        {
177040          "type": "library",
177041          "bom-ref": "pkg:npm/stdout-stream@1.4.1?package-id=f3980bf34929f31f",
177042          "supplier": {},
177043          "name": "stdout-stream",
177044          "version": "1.4.1",
177045          "description": "Non-blocking stdout stream",
177046          "licenses": [
177047            {
177048              "license": {
177049                "id": "MIT"
177050              }
177051            }
177052          ],
177053          "cpe": "cpe:2.3:a:stdout-stream:stdout-stream:1.4.1:*:*:*:*:*:*:*",
177054          "purl": "pkg:npm/stdout-stream@1.4.1",
177055          "swid": {
177056            "attachment": {}
177057          },
177058          "pedigree": {},
177059          "externalReferences": [
177060            {
177061              "url": "mafintosh/stdout-stream",
177062              "type": "distribution"
177063            }
177064          ],
177065          "evidence": {},
177066          "signature": {
177067            "signature": {
177068              "publicKey": {}
177069            }
177070          },
177071          "modelCard": {
177072            "modelParameters": {
177073              "approach": {}
177074            },
177075            "quantitativeAnalysis": {
177076              "graphics": {}
177077            },
177078            "considerations": {}
177079          }
177080        },
177081        {
177082          "type": "library",
177083          "bom-ref": "pkg:npm/string-width@1.0.2?package-id=99c2eff90c5879e8",
177084          "supplier": {},
177085          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177086          "name": "string-width",
177087          "version": "1.0.2",
177088          "description": "Get the visual width of a string - the number of columns required to display it",
177089          "licenses": [
177090            {
177091              "license": {
177092                "id": "MIT"
177093              }
177094            }
177095          ],
177096          "cpe": "cpe:2.3:a:string-width:string-width:1.0.2:*:*:*:*:*:*:*",
177097          "purl": "pkg:npm/string-width@1.0.2",
177098          "swid": {
177099            "attachment": {}
177100          },
177101          "pedigree": {},
177102          "externalReferences": [
177103            {
177104              "url": "sindresorhus/string-width",
177105              "type": "distribution"
177106            }
177107          ],
177108          "evidence": {},
177109          "signature": {
177110            "signature": {
177111              "publicKey": {}
177112            }
177113          },
177114          "modelCard": {
177115            "modelParameters": {
177116              "approach": {}
177117            },
177118            "quantitativeAnalysis": {
177119              "graphics": {}
177120            },
177121            "considerations": {}
177122          }
177123        },
177124        {
177125          "type": "library",
177126          "bom-ref": "pkg:npm/string-width@3.1.0?package-id=13d0998431f8e6ca",
177127          "supplier": {},
177128          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177129          "name": "string-width",
177130          "version": "3.1.0",
177131          "description": "Get the visual width of a string - the number of columns required to display it",
177132          "licenses": [
177133            {
177134              "license": {
177135                "id": "MIT"
177136              }
177137            }
177138          ],
177139          "cpe": "cpe:2.3:a:string-width:string-width:3.1.0:*:*:*:*:*:*:*",
177140          "purl": "pkg:npm/string-width@3.1.0",
177141          "swid": {
177142            "attachment": {}
177143          },
177144          "pedigree": {},
177145          "externalReferences": [
177146            {
177147              "url": "sindresorhus/string-width",
177148              "type": "distribution"
177149            }
177150          ],
177151          "evidence": {},
177152          "signature": {
177153            "signature": {
177154              "publicKey": {}
177155            }
177156          },
177157          "modelCard": {
177158            "modelParameters": {
177159              "approach": {}
177160            },
177161            "quantitativeAnalysis": {
177162              "graphics": {}
177163            },
177164            "considerations": {}
177165          }
177166        },
177167        {
177168          "type": "library",
177169          "bom-ref": "pkg:npm/string-width@3.1.0?package-id=c616574e33942189",
177170          "supplier": {},
177171          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177172          "name": "string-width",
177173          "version": "3.1.0",
177174          "description": "Get the visual width of a string - the number of columns required to display it",
177175          "licenses": [
177176            {
177177              "license": {
177178                "id": "MIT"
177179              }
177180            }
177181          ],
177182          "cpe": "cpe:2.3:a:string-width:string-width:3.1.0:*:*:*:*:*:*:*",
177183          "purl": "pkg:npm/string-width@3.1.0",
177184          "swid": {
177185            "attachment": {}
177186          },
177187          "pedigree": {},
177188          "externalReferences": [
177189            {
177190              "url": "sindresorhus/string-width",
177191              "type": "distribution"
177192            }
177193          ],
177194          "evidence": {},
177195          "signature": {
177196            "signature": {
177197              "publicKey": {}
177198            }
177199          },
177200          "modelCard": {
177201            "modelParameters": {
177202              "approach": {}
177203            },
177204            "quantitativeAnalysis": {
177205              "graphics": {}
177206            },
177207            "considerations": {}
177208          }
177209        },
177210        {
177211          "type": "library",
177212          "bom-ref": "pkg:npm/string-width@3.1.0?package-id=da15c8966a32e6fc",
177213          "supplier": {},
177214          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177215          "name": "string-width",
177216          "version": "3.1.0",
177217          "description": "Get the visual width of a string - the number of columns required to display it",
177218          "licenses": [
177219            {
177220              "license": {
177221                "id": "MIT"
177222              }
177223            }
177224          ],
177225          "cpe": "cpe:2.3:a:string-width:string-width:3.1.0:*:*:*:*:*:*:*",
177226          "purl": "pkg:npm/string-width@3.1.0",
177227          "swid": {
177228            "attachment": {}
177229          },
177230          "pedigree": {},
177231          "externalReferences": [
177232            {
177233              "url": "sindresorhus/string-width",
177234              "type": "distribution"
177235            }
177236          ],
177237          "evidence": {},
177238          "signature": {
177239            "signature": {
177240              "publicKey": {}
177241            }
177242          },
177243          "modelCard": {
177244            "modelParameters": {
177245              "approach": {}
177246            },
177247            "quantitativeAnalysis": {
177248              "graphics": {}
177249            },
177250            "considerations": {}
177251          }
177252        },
177253        {
177254          "type": "library",
177255          "bom-ref": "pkg:npm/string-width@4.2.3?package-id=c50e61a77e3ea809",
177256          "supplier": {},
177257          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177258          "name": "string-width",
177259          "version": "4.2.3",
177260          "description": "Get the visual width of a string - the number of columns required to display it",
177261          "licenses": [
177262            {
177263              "license": {
177264                "id": "MIT"
177265              }
177266            }
177267          ],
177268          "cpe": "cpe:2.3:a:string-width:string-width:4.2.3:*:*:*:*:*:*:*",
177269          "purl": "pkg:npm/string-width@4.2.3",
177270          "swid": {
177271            "attachment": {}
177272          },
177273          "pedigree": {},
177274          "externalReferences": [
177275            {
177276              "url": "sindresorhus/string-width",
177277              "type": "distribution"
177278            }
177279          ],
177280          "evidence": {},
177281          "signature": {
177282            "signature": {
177283              "publicKey": {}
177284            }
177285          },
177286          "modelCard": {
177287            "modelParameters": {
177288              "approach": {}
177289            },
177290            "quantitativeAnalysis": {
177291              "graphics": {}
177292            },
177293            "considerations": {}
177294          }
177295        },
177296        {
177297          "type": "library",
177298          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=5a4daef36b769162",
177299          "supplier": {},
177300          "name": "string_decoder",
177301          "version": "1.1.1",
177302          "description": "The string_decoder module from Node core",
177303          "licenses": [
177304            {
177305              "license": {
177306                "id": "MIT"
177307              }
177308            }
177309          ],
177310          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
177311          "purl": "pkg:npm/string_decoder@1.1.1",
177312          "swid": {
177313            "attachment": {}
177314          },
177315          "pedigree": {},
177316          "externalReferences": [
177317            {
177318              "url": "git://github.com/nodejs/string_decoder.git",
177319              "type": "distribution"
177320            },
177321            {
177322              "url": "https://github.com/nodejs/string_decoder",
177323              "type": "website"
177324            }
177325          ],
177326          "evidence": {},
177327          "signature": {
177328            "signature": {
177329              "publicKey": {}
177330            }
177331          },
177332          "modelCard": {
177333            "modelParameters": {
177334              "approach": {}
177335            },
177336            "quantitativeAnalysis": {
177337              "graphics": {}
177338            },
177339            "considerations": {}
177340          }
177341        },
177342        {
177343          "type": "library",
177344          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=ca8af4aa6b41ca75",
177345          "supplier": {},
177346          "name": "string_decoder",
177347          "version": "1.3.0",
177348          "description": "The string_decoder module from Node core",
177349          "licenses": [
177350            {
177351              "license": {
177352                "id": "MIT"
177353              }
177354            }
177355          ],
177356          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
177357          "purl": "pkg:npm/string_decoder@1.3.0",
177358          "swid": {
177359            "attachment": {}
177360          },
177361          "pedigree": {},
177362          "externalReferences": [
177363            {
177364              "url": "git://github.com/nodejs/string_decoder.git",
177365              "type": "distribution"
177366            },
177367            {
177368              "url": "https://github.com/nodejs/string_decoder",
177369              "type": "website"
177370            }
177371          ],
177372          "evidence": {},
177373          "signature": {
177374            "signature": {
177375              "publicKey": {}
177376            }
177377          },
177378          "modelCard": {
177379            "modelParameters": {
177380              "approach": {}
177381            },
177382            "quantitativeAnalysis": {
177383              "graphics": {}
177384            },
177385            "considerations": {}
177386          }
177387        },
177388        {
177389          "type": "library",
177390          "bom-ref": "pkg:npm/strip-ansi@3.0.1?package-id=5660dbb18dd8d236",
177391          "supplier": {},
177392          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177393          "name": "strip-ansi",
177394          "version": "3.0.1",
177395          "description": "Strip ANSI escape codes",
177396          "licenses": [
177397            {
177398              "license": {
177399                "id": "MIT"
177400              }
177401            }
177402          ],
177403          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:3.0.1:*:*:*:*:*:*:*",
177404          "purl": "pkg:npm/strip-ansi@3.0.1",
177405          "swid": {
177406            "attachment": {}
177407          },
177408          "pedigree": {},
177409          "externalReferences": [
177410            {
177411              "url": "chalk/strip-ansi",
177412              "type": "distribution"
177413            }
177414          ],
177415          "evidence": {},
177416          "signature": {
177417            "signature": {
177418              "publicKey": {}
177419            }
177420          },
177421          "modelCard": {
177422            "modelParameters": {
177423              "approach": {}
177424            },
177425            "quantitativeAnalysis": {
177426              "graphics": {}
177427            },
177428            "considerations": {}
177429          }
177430        },
177431        {
177432          "type": "library",
177433          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=b4723b70c5bdeabc",
177434          "supplier": {},
177435          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177436          "name": "strip-ansi",
177437          "version": "5.2.0",
177438          "description": "Strip ANSI escape codes from a string",
177439          "licenses": [
177440            {
177441              "license": {
177442                "id": "MIT"
177443              }
177444            }
177445          ],
177446          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
177447          "purl": "pkg:npm/strip-ansi@5.2.0",
177448          "swid": {
177449            "attachment": {}
177450          },
177451          "pedigree": {},
177452          "externalReferences": [
177453            {
177454              "url": "chalk/strip-ansi",
177455              "type": "distribution"
177456            }
177457          ],
177458          "evidence": {},
177459          "signature": {
177460            "signature": {
177461              "publicKey": {}
177462            }
177463          },
177464          "modelCard": {
177465            "modelParameters": {
177466              "approach": {}
177467            },
177468            "quantitativeAnalysis": {
177469              "graphics": {}
177470            },
177471            "considerations": {}
177472          }
177473        },
177474        {
177475          "type": "library",
177476          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=fae2bda52317bc81",
177477          "supplier": {},
177478          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177479          "name": "strip-ansi",
177480          "version": "5.2.0",
177481          "description": "Strip ANSI escape codes from a string",
177482          "licenses": [
177483            {
177484              "license": {
177485                "id": "MIT"
177486              }
177487            }
177488          ],
177489          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
177490          "purl": "pkg:npm/strip-ansi@5.2.0",
177491          "swid": {
177492            "attachment": {}
177493          },
177494          "pedigree": {},
177495          "externalReferences": [
177496            {
177497              "url": "chalk/strip-ansi",
177498              "type": "distribution"
177499            }
177500          ],
177501          "evidence": {},
177502          "signature": {
177503            "signature": {
177504              "publicKey": {}
177505            }
177506          },
177507          "modelCard": {
177508            "modelParameters": {
177509              "approach": {}
177510            },
177511            "quantitativeAnalysis": {
177512              "graphics": {}
177513            },
177514            "considerations": {}
177515          }
177516        },
177517        {
177518          "type": "library",
177519          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=9fdc9686bba43de6",
177520          "supplier": {},
177521          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177522          "name": "strip-ansi",
177523          "version": "5.2.0",
177524          "description": "Strip ANSI escape codes from a string",
177525          "licenses": [
177526            {
177527              "license": {
177528                "id": "MIT"
177529              }
177530            }
177531          ],
177532          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
177533          "purl": "pkg:npm/strip-ansi@5.2.0",
177534          "swid": {
177535            "attachment": {}
177536          },
177537          "pedigree": {},
177538          "externalReferences": [
177539            {
177540              "url": "chalk/strip-ansi",
177541              "type": "distribution"
177542            }
177543          ],
177544          "evidence": {},
177545          "signature": {
177546            "signature": {
177547              "publicKey": {}
177548            }
177549          },
177550          "modelCard": {
177551            "modelParameters": {
177552              "approach": {}
177553            },
177554            "quantitativeAnalysis": {
177555              "graphics": {}
177556            },
177557            "considerations": {}
177558          }
177559        },
177560        {
177561          "type": "library",
177562          "bom-ref": "pkg:npm/strip-ansi@6.0.1?package-id=5ec73c7d72940ceb",
177563          "supplier": {},
177564          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177565          "name": "strip-ansi",
177566          "version": "6.0.1",
177567          "description": "Strip ANSI escape codes from a string",
177568          "licenses": [
177569            {
177570              "license": {
177571                "id": "MIT"
177572              }
177573            }
177574          ],
177575          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:6.0.1:*:*:*:*:*:*:*",
177576          "purl": "pkg:npm/strip-ansi@6.0.1",
177577          "swid": {
177578            "attachment": {}
177579          },
177580          "pedigree": {},
177581          "externalReferences": [
177582            {
177583              "url": "chalk/strip-ansi",
177584              "type": "distribution"
177585            }
177586          ],
177587          "evidence": {},
177588          "signature": {
177589            "signature": {
177590              "publicKey": {}
177591            }
177592          },
177593          "modelCard": {
177594            "modelParameters": {
177595              "approach": {}
177596            },
177597            "quantitativeAnalysis": {
177598              "graphics": {}
177599            },
177600            "considerations": {}
177601          }
177602        },
177603        {
177604          "type": "library",
177605          "bom-ref": "pkg:npm/strip-indent@3.0.0?package-id=1bc30b600b420b1a",
177606          "supplier": {},
177607          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177608          "name": "strip-indent",
177609          "version": "3.0.0",
177610          "description": "Strip leading whitespace from each line in a string",
177611          "licenses": [
177612            {
177613              "license": {
177614                "id": "MIT"
177615              }
177616            }
177617          ],
177618          "cpe": "cpe:2.3:a:strip-indent:strip-indent:3.0.0:*:*:*:*:*:*:*",
177619          "purl": "pkg:npm/strip-indent@3.0.0",
177620          "swid": {
177621            "attachment": {}
177622          },
177623          "pedigree": {},
177624          "externalReferences": [
177625            {
177626              "url": "sindresorhus/strip-indent",
177627              "type": "distribution"
177628            }
177629          ],
177630          "evidence": {},
177631          "signature": {
177632            "signature": {
177633              "publicKey": {}
177634            }
177635          },
177636          "modelCard": {
177637            "modelParameters": {
177638              "approach": {}
177639            },
177640            "quantitativeAnalysis": {
177641              "graphics": {}
177642            },
177643            "considerations": {}
177644          }
177645        },
177646        {
177647          "type": "library",
177648          "bom-ref": "pkg:npm/supports-color@2.0.0?package-id=31606d8b3a6a4bcb",
177649          "supplier": {},
177650          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177651          "name": "supports-color",
177652          "version": "2.0.0",
177653          "description": "Detect whether a terminal supports color",
177654          "licenses": [
177655            {
177656              "license": {
177657                "id": "MIT"
177658              }
177659            }
177660          ],
177661          "cpe": "cpe:2.3:a:supports-color:supports-color:2.0.0:*:*:*:*:*:*:*",
177662          "purl": "pkg:npm/supports-color@2.0.0",
177663          "swid": {
177664            "attachment": {}
177665          },
177666          "pedigree": {},
177667          "externalReferences": [
177668            {
177669              "url": "chalk/supports-color",
177670              "type": "distribution"
177671            }
177672          ],
177673          "evidence": {},
177674          "signature": {
177675            "signature": {
177676              "publicKey": {}
177677            }
177678          },
177679          "modelCard": {
177680            "modelParameters": {
177681              "approach": {}
177682            },
177683            "quantitativeAnalysis": {
177684              "graphics": {}
177685            },
177686            "considerations": {}
177687          }
177688        },
177689        {
177690          "type": "library",
177691          "bom-ref": "pkg:npm/supports-color@5.5.0?package-id=a92bebf96aece909",
177692          "supplier": {},
177693          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177694          "name": "supports-color",
177695          "version": "5.5.0",
177696          "description": "Detect whether a terminal supports color",
177697          "licenses": [
177698            {
177699              "license": {
177700                "id": "MIT"
177701              }
177702            }
177703          ],
177704          "cpe": "cpe:2.3:a:supports-color:supports-color:5.5.0:*:*:*:*:*:*:*",
177705          "purl": "pkg:npm/supports-color@5.5.0",
177706          "swid": {
177707            "attachment": {}
177708          },
177709          "pedigree": {},
177710          "externalReferences": [
177711            {
177712              "url": "chalk/supports-color",
177713              "type": "distribution"
177714            }
177715          ],
177716          "evidence": {},
177717          "signature": {
177718            "signature": {
177719              "publicKey": {}
177720            }
177721          },
177722          "modelCard": {
177723            "modelParameters": {
177724              "approach": {}
177725            },
177726            "quantitativeAnalysis": {
177727              "graphics": {}
177728            },
177729            "considerations": {}
177730          }
177731        },
177732        {
177733          "type": "library",
177734          "bom-ref": "pkg:npm/supports-color@7.2.0?package-id=4c97deb16c788c95",
177735          "supplier": {},
177736          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
177737          "name": "supports-color",
177738          "version": "7.2.0",
177739          "description": "Detect whether a terminal supports color",
177740          "licenses": [
177741            {
177742              "license": {
177743                "id": "MIT"
177744              }
177745            }
177746          ],
177747          "cpe": "cpe:2.3:a:supports-color:supports-color:7.2.0:*:*:*:*:*:*:*",
177748          "purl": "pkg:npm/supports-color@7.2.0",
177749          "swid": {
177750            "attachment": {}
177751          },
177752          "pedigree": {},
177753          "externalReferences": [
177754            {
177755              "url": "chalk/supports-color",
177756              "type": "distribution"
177757            }
177758          ],
177759          "evidence": {},
177760          "signature": {
177761            "signature": {
177762              "publicKey": {}
177763            }
177764          },
177765          "modelCard": {
177766            "modelParameters": {
177767              "approach": {}
177768            },
177769            "quantitativeAnalysis": {
177770              "graphics": {}
177771            },
177772            "considerations": {}
177773          }
177774        },
177775        {
177776          "type": "library",
177777          "bom-ref": "pkg:npm/supports-preserve-symlinks-flag@1.0.0?package-id=63de1d09c9944553",
177778          "supplier": {},
177779          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
177780          "name": "supports-preserve-symlinks-flag",
177781          "version": "1.0.0",
177782          "description": "Determine if the current node version supports the `--preserve-symlinks` flag.",
177783          "licenses": [
177784            {
177785              "license": {
177786                "id": "MIT"
177787              }
177788            }
177789          ],
177790          "cpe": "cpe:2.3:a:supports-preserve-symlinks-flag:supports-preserve-symlinks-flag:1.0.0:*:*:*:*:*:*:*",
177791          "purl": "pkg:npm/supports-preserve-symlinks-flag@1.0.0",
177792          "swid": {
177793            "attachment": {}
177794          },
177795          "pedigree": {},
177796          "externalReferences": [
177797            {
177798              "url": "git+https://github.com/inspect-js/node-supports-preserve-symlinks-flag.git",
177799              "type": "distribution"
177800            },
177801            {
177802              "url": "https://github.com/inspect-js/node-supports-preserve-symlinks-flag#readme",
177803              "type": "website"
177804            }
177805          ],
177806          "evidence": {},
177807          "signature": {
177808            "signature": {
177809              "publicKey": {}
177810            }
177811          },
177812          "modelCard": {
177813            "modelParameters": {
177814              "approach": {}
177815            },
177816            "quantitativeAnalysis": {
177817              "graphics": {}
177818            },
177819            "considerations": {}
177820          }
177821        },
177822        {
177823          "type": "library",
177824          "bom-ref": "pkg:npm/tar@6.1.11?package-id=97823590d9da9c9f",
177825          "supplier": {},
177826          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
177827          "name": "tar",
177828          "version": "6.1.11",
177829          "description": "tar for node",
177830          "licenses": [
177831            {
177832              "license": {
177833                "id": "ISC"
177834              }
177835            }
177836          ],
177837          "cpe": "cpe:2.3:a:npm:tar:6.1.11:*:*:*:*:*:*:*",
177838          "purl": "pkg:npm/tar@6.1.11",
177839          "swid": {
177840            "attachment": {}
177841          },
177842          "pedigree": {},
177843          "externalReferences": [
177844            {
177845              "url": "https://github.com/npm/node-tar.git",
177846              "type": "distribution"
177847            }
177848          ],
177849          "evidence": {},
177850          "signature": {
177851            "signature": {
177852              "publicKey": {}
177853            }
177854          },
177855          "modelCard": {
177856            "modelParameters": {
177857              "approach": {}
177858            },
177859            "quantitativeAnalysis": {
177860              "graphics": {}
177861            },
177862            "considerations": {}
177863          }
177864        },
177865        {
177866          "type": "library",
177867          "bom-ref": "pkg:npm/tar@6.1.13?package-id=28c160aaaff6b1e5",
177868          "supplier": {},
177869          "author": "GitHub Inc.",
177870          "name": "tar",
177871          "version": "6.1.13",
177872          "description": "tar for node",
177873          "licenses": [
177874            {
177875              "license": {
177876                "id": "ISC"
177877              }
177878            }
177879          ],
177880          "cpe": "cpe:2.3:a:npm:tar:6.1.13:*:*:*:*:*:*:*",
177881          "purl": "pkg:npm/tar@6.1.13",
177882          "swid": {
177883            "attachment": {}
177884          },
177885          "pedigree": {},
177886          "externalReferences": [
177887            {
177888              "url": "https://github.com/npm/node-tar.git",
177889              "type": "distribution"
177890            }
177891          ],
177892          "evidence": {},
177893          "signature": {
177894            "signature": {
177895              "publicKey": {}
177896            }
177897          },
177898          "modelCard": {
177899            "modelParameters": {
177900              "approach": {}
177901            },
177902            "quantitativeAnalysis": {
177903              "graphics": {}
177904            },
177905            "considerations": {}
177906          }
177907        },
177908        {
177909          "type": "library",
177910          "bom-ref": "pkg:npm/text-table@0.2.0?package-id=a124be9ad599668f",
177911          "supplier": {},
177912          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
177913          "name": "text-table",
177914          "version": "0.2.0",
177915          "description": "borderless text tables with alignment",
177916          "licenses": [
177917            {
177918              "license": {
177919                "id": "MIT"
177920              }
177921            }
177922          ],
177923          "cpe": "cpe:2.3:a:text-table:text-table:0.2.0:*:*:*:*:*:*:*",
177924          "purl": "pkg:npm/text-table@0.2.0",
177925          "swid": {
177926            "attachment": {}
177927          },
177928          "pedigree": {},
177929          "externalReferences": [
177930            {
177931              "url": "git://github.com/substack/text-table.git",
177932              "type": "distribution"
177933            },
177934            {
177935              "url": "https://github.com/substack/text-table",
177936              "type": "website"
177937            }
177938          ],
177939          "evidence": {},
177940          "signature": {
177941            "signature": {
177942              "publicKey": {}
177943            }
177944          },
177945          "modelCard": {
177946            "modelParameters": {
177947              "approach": {}
177948            },
177949            "quantitativeAnalysis": {
177950              "graphics": {}
177951            },
177952            "considerations": {}
177953          }
177954        },
177955        {
177956          "type": "library",
177957          "bom-ref": "pkg:npm/tiny-relative-date@1.3.0?package-id=bc2a707c455ba496",
177958          "supplier": {},
177959          "author": "Joseph Wynn \u003cjoseph@wildlyinaccurate.com\u003e (https://wildlyinaccurate.com/)",
177960          "name": "tiny-relative-date",
177961          "version": "1.3.0",
177962          "description": "Tiny function that provides relative, human-readable dates.",
177963          "licenses": [
177964            {
177965              "license": {
177966                "id": "MIT"
177967              }
177968            }
177969          ],
177970          "cpe": "cpe:2.3:a:tiny-relative-date:tiny-relative-date:1.3.0:*:*:*:*:*:*:*",
177971          "purl": "pkg:npm/tiny-relative-date@1.3.0",
177972          "swid": {
177973            "attachment": {}
177974          },
177975          "pedigree": {},
177976          "externalReferences": [
177977            {
177978              "url": "https://github.com/wildlyinaccurate/relative-date.git",
177979              "type": "distribution"
177980            }
177981          ],
177982          "evidence": {},
177983          "signature": {
177984            "signature": {
177985              "publicKey": {}
177986            }
177987          },
177988          "modelCard": {
177989            "modelParameters": {
177990              "approach": {}
177991            },
177992            "quantitativeAnalysis": {
177993              "graphics": {}
177994            },
177995            "considerations": {}
177996          }
177997        },
177998        {
177999          "type": "library",
178000          "bom-ref": "pkg:npm/toidentifier@1.0.0?package-id=9530da023df4a67f",
178001          "supplier": {},
178002          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
178003          "name": "toidentifier",
178004          "version": "1.0.0",
178005          "description": "Convert a string of words to a JavaScript identifier",
178006          "licenses": [
178007            {
178008              "license": {
178009                "id": "MIT"
178010              }
178011            }
178012          ],
178013          "cpe": "cpe:2.3:a:toidentifier:toidentifier:1.0.0:*:*:*:*:*:*:*",
178014          "purl": "pkg:npm/toidentifier@1.0.0",
178015          "swid": {
178016            "attachment": {}
178017          },
178018          "pedigree": {},
178019          "externalReferences": [
178020            {
178021              "url": "component/toidentifier",
178022              "type": "distribution"
178023            }
178024          ],
178025          "evidence": {},
178026          "signature": {
178027            "signature": {
178028              "publicKey": {}
178029            }
178030          },
178031          "modelCard": {
178032            "modelParameters": {
178033              "approach": {}
178034            },
178035            "quantitativeAnalysis": {
178036              "graphics": {}
178037            },
178038            "considerations": {}
178039          }
178040        },
178041        {
178042          "type": "library",
178043          "bom-ref": "pkg:npm/tough-cookie@2.5.0?package-id=a301940673b885ce",
178044          "supplier": {},
178045          "author": "Jeremy Stashewsky \u003cjstash@gmail.com\u003e",
178046          "name": "tough-cookie",
178047          "version": "2.5.0",
178048          "description": "RFC6265 Cookies and Cookie Jar for node.js",
178049          "licenses": [
178050            {
178051              "license": {
178052                "id": "BSD-3-Clause"
178053              }
178054            }
178055          ],
178056          "cpe": "cpe:2.3:a:tough-cookie:tough-cookie:2.5.0:*:*:*:*:*:*:*",
178057          "purl": "pkg:npm/tough-cookie@2.5.0",
178058          "swid": {
178059            "attachment": {}
178060          },
178061          "pedigree": {},
178062          "externalReferences": [
178063            {
178064              "url": "git://github.com/salesforce/tough-cookie.git",
178065              "type": "distribution"
178066            },
178067            {
178068              "url": "https://github.com/salesforce/tough-cookie",
178069              "type": "website"
178070            }
178071          ],
178072          "evidence": {},
178073          "signature": {
178074            "signature": {
178075              "publicKey": {}
178076            }
178077          },
178078          "modelCard": {
178079            "modelParameters": {
178080              "approach": {}
178081            },
178082            "quantitativeAnalysis": {
178083              "graphics": {}
178084            },
178085            "considerations": {}
178086          }
178087        },
178088        {
178089          "type": "library",
178090          "bom-ref": "pkg:npm/treeverse@2.0.0?package-id=283d5c0745aa3ce7",
178091          "supplier": {},
178092          "author": "GitHub Inc.",
178093          "name": "treeverse",
178094          "version": "2.0.0",
178095          "description": "Walk any kind of tree structure depth- or breadth-first. Supports promises and advanced map-reduce operations with a very small API.",
178096          "licenses": [
178097            {
178098              "license": {
178099                "id": "ISC"
178100              }
178101            }
178102          ],
178103          "cpe": "cpe:2.3:a:treeverse:treeverse:2.0.0:*:*:*:*:*:*:*",
178104          "purl": "pkg:npm/treeverse@2.0.0",
178105          "swid": {
178106            "attachment": {}
178107          },
178108          "pedigree": {},
178109          "externalReferences": [
178110            {
178111              "url": "https://github.com/npm/treeverse.git",
178112              "type": "distribution"
178113            }
178114          ],
178115          "evidence": {},
178116          "signature": {
178117            "signature": {
178118              "publicKey": {}
178119            }
178120          },
178121          "modelCard": {
178122            "modelParameters": {
178123              "approach": {}
178124            },
178125            "quantitativeAnalysis": {
178126              "graphics": {}
178127            },
178128            "considerations": {}
178129          }
178130        },
178131        {
178132          "type": "library",
178133          "bom-ref": "pkg:npm/trim-newlines@3.0.1?package-id=c96d10cad34298f2",
178134          "supplier": {},
178135          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
178136          "name": "trim-newlines",
178137          "version": "3.0.1",
178138          "description": "Trim newlines from the start and/or end of a string",
178139          "licenses": [
178140            {
178141              "license": {
178142                "id": "MIT"
178143              }
178144            }
178145          ],
178146          "cpe": "cpe:2.3:a:trim-newlines:trim-newlines:3.0.1:*:*:*:*:*:*:*",
178147          "purl": "pkg:npm/trim-newlines@3.0.1",
178148          "swid": {
178149            "attachment": {}
178150          },
178151          "pedigree": {},
178152          "externalReferences": [
178153            {
178154              "url": "sindresorhus/trim-newlines",
178155              "type": "distribution"
178156            }
178157          ],
178158          "evidence": {},
178159          "signature": {
178160            "signature": {
178161              "publicKey": {}
178162            }
178163          },
178164          "modelCard": {
178165            "modelParameters": {
178166              "approach": {}
178167            },
178168            "quantitativeAnalysis": {
178169              "graphics": {}
178170            },
178171            "considerations": {}
178172          }
178173        },
178174        {
178175          "type": "library",
178176          "bom-ref": "pkg:npm/true-case-path@1.0.3?package-id=21c9dae6ead27ec1",
178177          "supplier": {},
178178          "author": "barsh",
178179          "name": "true-case-path",
178180          "version": "1.0.3",
178181          "description": "Given a possibly case-variant version of an existing filesystem path, returns the case-exact, normalized version as stored in the filesystem.",
178182          "licenses": [
178183            {
178184              "license": {
178185                "id": "Apache-2.0"
178186              }
178187            }
178188          ],
178189          "cpe": "cpe:2.3:a:true-case-path:true-case-path:1.0.3:*:*:*:*:*:*:*",
178190          "purl": "pkg:npm/true-case-path@1.0.3",
178191          "swid": {
178192            "attachment": {}
178193          },
178194          "pedigree": {},
178195          "externalReferences": [
178196            {
178197              "url": "git+https://github.com/barsh/true-case-path.git",
178198              "type": "distribution"
178199            },
178200            {
178201              "url": "https://github.com/barsh/true-case-path#readme",
178202              "type": "website"
178203            }
178204          ],
178205          "evidence": {},
178206          "signature": {
178207            "signature": {
178208              "publicKey": {}
178209            }
178210          },
178211          "modelCard": {
178212            "modelParameters": {
178213              "approach": {}
178214            },
178215            "quantitativeAnalysis": {
178216              "graphics": {}
178217            },
178218            "considerations": {}
178219          }
178220        },
178221        {
178222          "type": "library",
178223          "bom-ref": "pkg:npm/tslib@1.9.3?package-id=a9ed9d8d6ca01dd2",
178224          "supplier": {},
178225          "author": "Microsoft Corp.",
178226          "name": "tslib",
178227          "version": "1.9.3",
178228          "description": "Runtime library for TypeScript helper functions",
178229          "licenses": [
178230            {
178231              "license": {
178232                "id": "Apache-2.0"
178233              }
178234            }
178235          ],
178236          "cpe": "cpe:2.3:a:Microsoft:tslib:1.9.3:*:*:*:*:*:*:*",
178237          "purl": "pkg:npm/tslib@1.9.3",
178238          "swid": {
178239            "attachment": {}
178240          },
178241          "pedigree": {},
178242          "externalReferences": [
178243            {
178244              "url": "https://github.com/Microsoft/tslib.git",
178245              "type": "distribution"
178246            },
178247            {
178248              "url": "http://typescriptlang.org/",
178249              "type": "website"
178250            }
178251          ],
178252          "evidence": {},
178253          "signature": {
178254            "signature": {
178255              "publicKey": {}
178256            }
178257          },
178258          "modelCard": {
178259            "modelParameters": {
178260              "approach": {}
178261            },
178262            "quantitativeAnalysis": {
178263              "graphics": {}
178264            },
178265            "considerations": {}
178266          }
178267        },
178268        {
178269          "type": "library",
178270          "bom-ref": "pkg:npm/tunnel-agent@0.6.0?package-id=2bdf83051339ef2c",
178271          "supplier": {},
178272          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
178273          "name": "tunnel-agent",
178274          "version": "0.6.0",
178275          "description": "HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.",
178276          "licenses": [
178277            {
178278              "license": {
178279                "id": "Apache-2.0"
178280              }
178281            }
178282          ],
178283          "cpe": "cpe:2.3:a:tunnel-agent:tunnel-agent:0.6.0:*:*:*:*:*:*:*",
178284          "purl": "pkg:npm/tunnel-agent@0.6.0",
178285          "swid": {
178286            "attachment": {}
178287          },
178288          "pedigree": {},
178289          "externalReferences": [
178290            {
178291              "url": "https://github.com/mikeal/tunnel-agent",
178292              "type": "distribution"
178293            }
178294          ],
178295          "evidence": {},
178296          "signature": {
178297            "signature": {
178298              "publicKey": {}
178299            }
178300          },
178301          "modelCard": {
178302            "modelParameters": {
178303              "approach": {}
178304            },
178305            "quantitativeAnalysis": {
178306              "graphics": {}
178307            },
178308            "considerations": {}
178309          }
178310        },
178311        {
178312          "type": "library",
178313          "bom-ref": "pkg:npm/tweetnacl@0.14.5?package-id=70ac65ccc05f56fb",
178314          "supplier": {},
178315          "author": "TweetNaCl-js contributors",
178316          "name": "tweetnacl",
178317          "version": "0.14.5",
178318          "description": "Port of TweetNaCl cryptographic library to JavaScript",
178319          "licenses": [
178320            {
178321              "license": {
178322                "id": "Unlicense"
178323              }
178324            }
178325          ],
178326          "cpe": "cpe:2.3:a:tweetnacl:tweetnacl:0.14.5:*:*:*:*:*:*:*",
178327          "purl": "pkg:npm/tweetnacl@0.14.5",
178328          "swid": {
178329            "attachment": {}
178330          },
178331          "pedigree": {},
178332          "externalReferences": [
178333            {
178334              "url": "https://github.com/dchest/tweetnacl-js.git",
178335              "type": "distribution"
178336            },
178337            {
178338              "url": "https://tweetnacl.js.org",
178339              "type": "website"
178340            }
178341          ],
178342          "evidence": {},
178343          "signature": {
178344            "signature": {
178345              "publicKey": {}
178346            }
178347          },
178348          "modelCard": {
178349            "modelParameters": {
178350              "approach": {}
178351            },
178352            "quantitativeAnalysis": {
178353              "graphics": {}
178354            },
178355            "considerations": {}
178356          }
178357        },
178358        {
178359          "type": "library",
178360          "bom-ref": "pkg:npm/type-fest@0.18.1?package-id=8671d02251d4f42",
178361          "supplier": {},
178362          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
178363          "name": "type-fest",
178364          "version": "0.18.1",
178365          "description": "A collection of essential TypeScript types",
178366          "licenses": [
178367            {
178368              "license": {
178369                "name": "(MIT OR CC0-1.0)"
178370              }
178371            }
178372          ],
178373          "cpe": "cpe:2.3:a:type-fest:type-fest:0.18.1:*:*:*:*:*:*:*",
178374          "purl": "pkg:npm/type-fest@0.18.1",
178375          "swid": {
178376            "attachment": {}
178377          },
178378          "pedigree": {},
178379          "externalReferences": [
178380            {
178381              "url": "sindresorhus/type-fest",
178382              "type": "distribution"
178383            }
178384          ],
178385          "evidence": {},
178386          "signature": {
178387            "signature": {
178388              "publicKey": {}
178389            }
178390          },
178391          "modelCard": {
178392            "modelParameters": {
178393              "approach": {}
178394            },
178395            "quantitativeAnalysis": {
178396              "graphics": {}
178397            },
178398            "considerations": {}
178399          }
178400        },
178401        {
178402          "type": "library",
178403          "bom-ref": "pkg:npm/type-fest@0.6.0?package-id=5d825eebad9b4a4d",
178404          "supplier": {},
178405          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
178406          "name": "type-fest",
178407          "version": "0.6.0",
178408          "description": "A collection of essential TypeScript types",
178409          "licenses": [
178410            {
178411              "license": {
178412                "name": "(MIT OR CC0-1.0)"
178413              }
178414            }
178415          ],
178416          "cpe": "cpe:2.3:a:type-fest:type-fest:0.6.0:*:*:*:*:*:*:*",
178417          "purl": "pkg:npm/type-fest@0.6.0",
178418          "swid": {
178419            "attachment": {}
178420          },
178421          "pedigree": {},
178422          "externalReferences": [
178423            {
178424              "url": "sindresorhus/type-fest",
178425              "type": "distribution"
178426            }
178427          ],
178428          "evidence": {},
178429          "signature": {
178430            "signature": {
178431              "publicKey": {}
178432            }
178433          },
178434          "modelCard": {
178435            "modelParameters": {
178436              "approach": {}
178437            },
178438            "quantitativeAnalysis": {
178439              "graphics": {}
178440            },
178441            "considerations": {}
178442          }
178443        },
178444        {
178445          "type": "library",
178446          "bom-ref": "pkg:npm/type-fest@0.8.1?package-id=974173f6f239e858",
178447          "supplier": {},
178448          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
178449          "name": "type-fest",
178450          "version": "0.8.1",
178451          "description": "A collection of essential TypeScript types",
178452          "licenses": [
178453            {
178454              "license": {
178455                "name": "(MIT OR CC0-1.0)"
178456              }
178457            }
178458          ],
178459          "cpe": "cpe:2.3:a:type-fest:type-fest:0.8.1:*:*:*:*:*:*:*",
178460          "purl": "pkg:npm/type-fest@0.8.1",
178461          "swid": {
178462            "attachment": {}
178463          },
178464          "pedigree": {},
178465          "externalReferences": [
178466            {
178467              "url": "sindresorhus/type-fest",
178468              "type": "distribution"
178469            }
178470          ],
178471          "evidence": {},
178472          "signature": {
178473            "signature": {
178474              "publicKey": {}
178475            }
178476          },
178477          "modelCard": {
178478            "modelParameters": {
178479              "approach": {}
178480            },
178481            "quantitativeAnalysis": {
178482              "graphics": {}
178483            },
178484            "considerations": {}
178485          }
178486        },
178487        {
178488          "type": "library",
178489          "bom-ref": "pkg:npm/type-is@1.6.18?package-id=5bdf50fc9a89514f",
178490          "supplier": {},
178491          "name": "type-is",
178492          "version": "1.6.18",
178493          "description": "Infer the content-type of a request.",
178494          "licenses": [
178495            {
178496              "license": {
178497                "id": "MIT"
178498              }
178499            }
178500          ],
178501          "cpe": "cpe:2.3:a:type-is:type-is:1.6.18:*:*:*:*:*:*:*",
178502          "purl": "pkg:npm/type-is@1.6.18",
178503          "swid": {
178504            "attachment": {}
178505          },
178506          "pedigree": {},
178507          "externalReferences": [
178508            {
178509              "url": "jshttp/type-is",
178510              "type": "distribution"
178511            }
178512          ],
178513          "evidence": {},
178514          "signature": {
178515            "signature": {
178516              "publicKey": {}
178517            }
178518          },
178519          "modelCard": {
178520            "modelParameters": {
178521              "approach": {}
178522            },
178523            "quantitativeAnalysis": {
178524              "graphics": {}
178525            },
178526            "considerations": {}
178527          }
178528        },
178529        {
178530          "type": "library",
178531          "bom-ref": "pkg:npm/unique-filename@2.0.1?package-id=ddbea63cf5bc0343",
178532          "supplier": {},
178533          "author": "GitHub Inc.",
178534          "name": "unique-filename",
178535          "version": "2.0.1",
178536          "description": "Generate a unique filename for use in temporary directories or caches.",
178537          "licenses": [
178538            {
178539              "license": {
178540                "id": "ISC"
178541              }
178542            }
178543          ],
178544          "cpe": "cpe:2.3:a:unique-filename:unique-filename:2.0.1:*:*:*:*:*:*:*",
178545          "purl": "pkg:npm/unique-filename@2.0.1",
178546          "swid": {
178547            "attachment": {}
178548          },
178549          "pedigree": {},
178550          "externalReferences": [
178551            {
178552              "url": "https://github.com/npm/unique-filename.git",
178553              "type": "distribution"
178554            },
178555            {
178556              "url": "https://github.com/iarna/unique-filename",
178557              "type": "website"
178558            }
178559          ],
178560          "evidence": {},
178561          "signature": {
178562            "signature": {
178563              "publicKey": {}
178564            }
178565          },
178566          "modelCard": {
178567            "modelParameters": {
178568              "approach": {}
178569            },
178570            "quantitativeAnalysis": {
178571              "graphics": {}
178572            },
178573            "considerations": {}
178574          }
178575        },
178576        {
178577          "type": "library",
178578          "bom-ref": "pkg:npm/unique-slug@3.0.0?package-id=a61e6b90d7850f42",
178579          "supplier": {},
178580          "author": "GitHub Inc.",
178581          "name": "unique-slug",
178582          "version": "3.0.0",
178583          "description": "Generate a unique character string suitible for use in files and URLs.",
178584          "licenses": [
178585            {
178586              "license": {
178587                "id": "ISC"
178588              }
178589            }
178590          ],
178591          "cpe": "cpe:2.3:a:unique-slug:unique-slug:3.0.0:*:*:*:*:*:*:*",
178592          "purl": "pkg:npm/unique-slug@3.0.0",
178593          "swid": {
178594            "attachment": {}
178595          },
178596          "pedigree": {},
178597          "externalReferences": [
178598            {
178599              "url": "https://github.com/npm/unique-slug.git",
178600              "type": "distribution"
178601            }
178602          ],
178603          "evidence": {},
178604          "signature": {
178605            "signature": {
178606              "publicKey": {}
178607            }
178608          },
178609          "modelCard": {
178610            "modelParameters": {
178611              "approach": {}
178612            },
178613            "quantitativeAnalysis": {
178614              "graphics": {}
178615            },
178616            "considerations": {}
178617          }
178618        },
178619        {
178620          "type": "library",
178621          "bom-ref": "pkg:npm/universalify@0.1.2?package-id=69eed8a5747afb4f",
178622          "supplier": {},
178623          "author": "Ryan Zimmerman \u003copensrc@ryanzim.com\u003e",
178624          "name": "universalify",
178625          "version": "0.1.2",
178626          "description": "Make a callback- or promise-based function support both promises and callbacks.",
178627          "licenses": [
178628            {
178629              "license": {
178630                "id": "MIT"
178631              }
178632            }
178633          ],
178634          "cpe": "cpe:2.3:a:universalify:universalify:0.1.2:*:*:*:*:*:*:*",
178635          "purl": "pkg:npm/universalify@0.1.2",
178636          "swid": {
178637            "attachment": {}
178638          },
178639          "pedigree": {},
178640          "externalReferences": [
178641            {
178642              "url": "git+https://github.com/RyanZim/universalify.git",
178643              "type": "distribution"
178644            },
178645            {
178646              "url": "https://github.com/RyanZim/universalify#readme",
178647              "type": "website"
178648            }
178649          ],
178650          "evidence": {},
178651          "signature": {
178652            "signature": {
178653              "publicKey": {}
178654            }
178655          },
178656          "modelCard": {
178657            "modelParameters": {
178658              "approach": {}
178659            },
178660            "quantitativeAnalysis": {
178661              "graphics": {}
178662            },
178663            "considerations": {}
178664          }
178665        },
178666        {
178667          "type": "library",
178668          "bom-ref": "pkg:npm/unpipe@1.0.0?package-id=c584cebc0a9824f4",
178669          "supplier": {},
178670          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
178671          "name": "unpipe",
178672          "version": "1.0.0",
178673          "description": "Unpipe a stream from all destinations",
178674          "licenses": [
178675            {
178676              "license": {
178677                "id": "MIT"
178678              }
178679            }
178680          ],
178681          "cpe": "cpe:2.3:a:unpipe:unpipe:1.0.0:*:*:*:*:*:*:*",
178682          "purl": "pkg:npm/unpipe@1.0.0",
178683          "swid": {
178684            "attachment": {}
178685          },
178686          "pedigree": {},
178687          "externalReferences": [
178688            {
178689              "url": "stream-utils/unpipe",
178690              "type": "distribution"
178691            }
178692          ],
178693          "evidence": {},
178694          "signature": {
178695            "signature": {
178696              "publicKey": {}
178697            }
178698          },
178699          "modelCard": {
178700            "modelParameters": {
178701              "approach": {}
178702            },
178703            "quantitativeAnalysis": {
178704              "graphics": {}
178705            },
178706            "considerations": {}
178707          }
178708        },
178709        {
178710          "type": "library",
178711          "bom-ref": "pkg:npm/uri-js@4.4.1?package-id=fe61e3e32f3aaf87",
178712          "supplier": {},
178713          "author": "Gary Court \u003cgary.court@gmail.com\u003e",
178714          "name": "uri-js",
178715          "version": "4.4.1",
178716          "description": "An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.",
178717          "licenses": [
178718            {
178719              "license": {
178720                "id": "BSD-2-Clause"
178721              }
178722            }
178723          ],
178724          "cpe": "cpe:2.3:a:garycourt:uri-js:4.4.1:*:*:*:*:*:*:*",
178725          "purl": "pkg:npm/uri-js@4.4.1",
178726          "swid": {
178727            "attachment": {}
178728          },
178729          "pedigree": {},
178730          "externalReferences": [
178731            {
178732              "url": "http://github.com/garycourt/uri-js",
178733              "type": "distribution"
178734            },
178735            {
178736              "url": "https://github.com/garycourt/uri-js",
178737              "type": "website"
178738            }
178739          ],
178740          "evidence": {},
178741          "signature": {
178742            "signature": {
178743              "publicKey": {}
178744            }
178745          },
178746          "modelCard": {
178747            "modelParameters": {
178748              "approach": {}
178749            },
178750            "quantitativeAnalysis": {
178751              "graphics": {}
178752            },
178753            "considerations": {}
178754          }
178755        },
178756        {
178757          "type": "library",
178758          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=ecf076cf26fe73d0",
178759          "supplier": {},
178760          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
178761          "name": "util-deprecate",
178762          "version": "1.0.2",
178763          "description": "The Node.js `util.deprecate()` function with browser support",
178764          "licenses": [
178765            {
178766              "license": {
178767                "id": "MIT"
178768              }
178769            }
178770          ],
178771          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
178772          "purl": "pkg:npm/util-deprecate@1.0.2",
178773          "swid": {
178774            "attachment": {}
178775          },
178776          "pedigree": {},
178777          "externalReferences": [
178778            {
178779              "url": "git://github.com/TooTallNate/util-deprecate.git",
178780              "type": "distribution"
178781            },
178782            {
178783              "url": "https://github.com/TooTallNate/util-deprecate",
178784              "type": "website"
178785            }
178786          ],
178787          "evidence": {},
178788          "signature": {
178789            "signature": {
178790              "publicKey": {}
178791            }
178792          },
178793          "modelCard": {
178794            "modelParameters": {
178795              "approach": {}
178796            },
178797            "quantitativeAnalysis": {
178798              "graphics": {}
178799            },
178800            "considerations": {}
178801          }
178802        },
178803        {
178804          "type": "library",
178805          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=78a196ea3de81330",
178806          "supplier": {},
178807          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
178808          "name": "util-deprecate",
178809          "version": "1.0.2",
178810          "description": "The Node.js `util.deprecate()` function with browser support",
178811          "licenses": [
178812            {
178813              "license": {
178814                "id": "MIT"
178815              }
178816            }
178817          ],
178818          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
178819          "purl": "pkg:npm/util-deprecate@1.0.2",
178820          "swid": {
178821            "attachment": {}
178822          },
178823          "pedigree": {},
178824          "externalReferences": [
178825            {
178826              "url": "git://github.com/TooTallNate/util-deprecate.git",
178827              "type": "distribution"
178828            },
178829            {
178830              "url": "https://github.com/TooTallNate/util-deprecate",
178831              "type": "website"
178832            }
178833          ],
178834          "evidence": {},
178835          "signature": {
178836            "signature": {
178837              "publicKey": {}
178838            }
178839          },
178840          "modelCard": {
178841            "modelParameters": {
178842              "approach": {}
178843            },
178844            "quantitativeAnalysis": {
178845              "graphics": {}
178846            },
178847            "considerations": {}
178848          }
178849        },
178850        {
178851          "type": "library",
178852          "bom-ref": "pkg:npm/utils-merge@1.0.1?package-id=62471f9f4fe7cedd",
178853          "supplier": {},
178854          "author": "Jared Hanson \u003cjaredhanson@gmail.com\u003e (http://www.jaredhanson.net/)",
178855          "name": "utils-merge",
178856          "version": "1.0.1",
178857          "description": "merge() utility function",
178858          "licenses": [
178859            {
178860              "license": {
178861                "id": "MIT"
178862              }
178863            }
178864          ],
178865          "cpe": "cpe:2.3:a:jaredhanson:utils-merge:1.0.1:*:*:*:*:*:*:*",
178866          "purl": "pkg:npm/utils-merge@1.0.1",
178867          "swid": {
178868            "attachment": {}
178869          },
178870          "pedigree": {},
178871          "externalReferences": [
178872            {
178873              "url": "git://github.com/jaredhanson/utils-merge.git",
178874              "type": "distribution"
178875            }
178876          ],
178877          "evidence": {},
178878          "signature": {
178879            "signature": {
178880              "publicKey": {}
178881            }
178882          },
178883          "modelCard": {
178884            "modelParameters": {
178885              "approach": {}
178886            },
178887            "quantitativeAnalysis": {
178888              "graphics": {}
178889            },
178890            "considerations": {}
178891          }
178892        },
178893        {
178894          "type": "library",
178895          "bom-ref": "pkg:npm/uuid@3.3.2?package-id=f2344b1d346d5fe5",
178896          "supplier": {},
178897          "name": "uuid",
178898          "version": "3.3.2",
178899          "description": "RFC4122 (v1, v4, and v5) UUIDs",
178900          "licenses": [
178901            {
178902              "license": {
178903                "id": "MIT"
178904              }
178905            }
178906          ],
178907          "cpe": "cpe:2.3:a:kelektiv:uuid:3.3.2:*:*:*:*:*:*:*",
178908          "purl": "pkg:npm/uuid@3.3.2",
178909          "swid": {
178910            "attachment": {}
178911          },
178912          "pedigree": {},
178913          "externalReferences": [
178914            {
178915              "url": "https://github.com/kelektiv/node-uuid.git",
178916              "type": "distribution"
178917            }
178918          ],
178919          "evidence": {},
178920          "signature": {
178921            "signature": {
178922              "publicKey": {}
178923            }
178924          },
178925          "modelCard": {
178926            "modelParameters": {
178927              "approach": {}
178928            },
178929            "quantitativeAnalysis": {
178930              "graphics": {}
178931            },
178932            "considerations": {}
178933          }
178934        },
178935        {
178936          "type": "library",
178937          "bom-ref": "pkg:npm/validate-npm-package-license@3.0.4?package-id=fa90b625ec15ead",
178938          "supplier": {},
178939          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
178940          "name": "validate-npm-package-license",
178941          "version": "3.0.4",
178942          "description": "Give me a string and I'll tell you if it's a valid npm package license string",
178943          "licenses": [
178944            {
178945              "license": {
178946                "id": "Apache-2.0"
178947              }
178948            }
178949          ],
178950          "cpe": "cpe:2.3:a:validate-npm-package-license:validate-npm-package-license:3.0.4:*:*:*:*:*:*:*",
178951          "purl": "pkg:npm/validate-npm-package-license@3.0.4",
178952          "swid": {
178953            "attachment": {}
178954          },
178955          "pedigree": {},
178956          "externalReferences": [
178957            {
178958              "url": "kemitchell/validate-npm-package-license.js",
178959              "type": "distribution"
178960            }
178961          ],
178962          "evidence": {},
178963          "signature": {
178964            "signature": {
178965              "publicKey": {}
178966            }
178967          },
178968          "modelCard": {
178969            "modelParameters": {
178970              "approach": {}
178971            },
178972            "quantitativeAnalysis": {
178973              "graphics": {}
178974            },
178975            "considerations": {}
178976          }
178977        },
178978        {
178979          "type": "library",
178980          "bom-ref": "pkg:npm/validate-npm-package-license@3.0.4?package-id=4aec2633663a7186",
178981          "supplier": {},
178982          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
178983          "name": "validate-npm-package-license",
178984          "version": "3.0.4",
178985          "description": "Give me a string and I'll tell you if it's a valid npm package license string",
178986          "licenses": [
178987            {
178988              "license": {
178989                "id": "Apache-2.0"
178990              }
178991            }
178992          ],
178993          "cpe": "cpe:2.3:a:validate-npm-package-license:validate-npm-package-license:3.0.4:*:*:*:*:*:*:*",
178994          "purl": "pkg:npm/validate-npm-package-license@3.0.4",
178995          "swid": {
178996            "attachment": {}
178997          },
178998          "pedigree": {},
178999          "externalReferences": [
179000            {
179001              "url": "kemitchell/validate-npm-package-license.js",
179002              "type": "distribution"
179003            }
179004          ],
179005          "evidence": {},
179006          "signature": {
179007            "signature": {
179008              "publicKey": {}
179009            }
179010          },
179011          "modelCard": {
179012            "modelParameters": {
179013              "approach": {}
179014            },
179015            "quantitativeAnalysis": {
179016              "graphics": {}
179017            },
179018            "considerations": {}
179019          }
179020        },
179021        {
179022          "type": "library",
179023          "bom-ref": "pkg:npm/validate-npm-package-name@4.0.0?package-id=dc3a9f2b7a700330",
179024          "supplier": {},
179025          "author": "GitHub Inc.",
179026          "name": "validate-npm-package-name",
179027          "version": "4.0.0",
179028          "description": "Give me a string and I'll tell you if it's a valid npm package name",
179029          "licenses": [
179030            {
179031              "license": {
179032                "id": "ISC"
179033              }
179034            }
179035          ],
179036          "cpe": "cpe:2.3:a:validate-npm-package-name:validate-npm-package-name:4.0.0:*:*:*:*:*:*:*",
179037          "purl": "pkg:npm/validate-npm-package-name@4.0.0",
179038          "swid": {
179039            "attachment": {}
179040          },
179041          "pedigree": {},
179042          "externalReferences": [
179043            {
179044              "url": "https://github.com/npm/validate-npm-package-name.git",
179045              "type": "distribution"
179046            },
179047            {
179048              "url": "https://github.com/npm/validate-npm-package-name",
179049              "type": "website"
179050            }
179051          ],
179052          "evidence": {},
179053          "signature": {
179054            "signature": {
179055              "publicKey": {}
179056            }
179057          },
179058          "modelCard": {
179059            "modelParameters": {
179060              "approach": {}
179061            },
179062            "quantitativeAnalysis": {
179063              "graphics": {}
179064            },
179065            "considerations": {}
179066          }
179067        },
179068        {
179069          "type": "library",
179070          "bom-ref": "pkg:npm/vary@1.1.2?package-id=7021c84ca0665099",
179071          "supplier": {},
179072          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
179073          "name": "vary",
179074          "version": "1.1.2",
179075          "description": "Manipulate the HTTP Vary header",
179076          "licenses": [
179077            {
179078              "license": {
179079                "id": "MIT"
179080              }
179081            }
179082          ],
179083          "cpe": "cpe:2.3:a:vary:vary:1.1.2:*:*:*:*:*:*:*",
179084          "purl": "pkg:npm/vary@1.1.2",
179085          "swid": {
179086            "attachment": {}
179087          },
179088          "pedigree": {},
179089          "externalReferences": [
179090            {
179091              "url": "jshttp/vary",
179092              "type": "distribution"
179093            }
179094          ],
179095          "evidence": {},
179096          "signature": {
179097            "signature": {
179098              "publicKey": {}
179099            }
179100          },
179101          "modelCard": {
179102            "modelParameters": {
179103              "approach": {}
179104            },
179105            "quantitativeAnalysis": {
179106              "graphics": {}
179107            },
179108            "considerations": {}
179109          }
179110        },
179111        {
179112          "type": "library",
179113          "bom-ref": "pkg:npm/verror@1.10.0?package-id=f23f33c383aecb1a",
179114          "supplier": {},
179115          "name": "verror",
179116          "version": "1.10.0",
179117          "description": "richer JavaScript errors",
179118          "licenses": [
179119            {
179120              "license": {
179121                "id": "MIT"
179122              }
179123            }
179124          ],
179125          "cpe": "cpe:2.3:a:davepacheco:verror:1.10.0:*:*:*:*:*:*:*",
179126          "purl": "pkg:npm/verror@1.10.0",
179127          "swid": {
179128            "attachment": {}
179129          },
179130          "pedigree": {},
179131          "externalReferences": [
179132            {
179133              "url": "git://github.com/davepacheco/node-verror.git",
179134              "type": "distribution"
179135            }
179136          ],
179137          "evidence": {},
179138          "signature": {
179139            "signature": {
179140              "publicKey": {}
179141            }
179142          },
179143          "modelCard": {
179144            "modelParameters": {
179145              "approach": {}
179146            },
179147            "quantitativeAnalysis": {
179148              "graphics": {}
179149            },
179150            "considerations": {}
179151          }
179152        },
179153        {
179154          "type": "library",
179155          "bom-ref": "pkg:npm/walk-up-path@1.0.0?package-id=9a8dd6f20b12184f",
179156          "supplier": {},
179157          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
179158          "name": "walk-up-path",
179159          "version": "1.0.0",
179160          "description": "Given a path string, return a generator that walks up the path, emitting each dirname.",
179161          "licenses": [
179162            {
179163              "license": {
179164                "id": "ISC"
179165              }
179166            }
179167          ],
179168          "cpe": "cpe:2.3:a:walk-up-path:walk-up-path:1.0.0:*:*:*:*:*:*:*",
179169          "purl": "pkg:npm/walk-up-path@1.0.0",
179170          "swid": {
179171            "attachment": {}
179172          },
179173          "pedigree": {},
179174          "externalReferences": [
179175            {
179176              "url": "git+https://github.com/isaacs/walk-up-path",
179177              "type": "distribution"
179178            }
179179          ],
179180          "evidence": {},
179181          "signature": {
179182            "signature": {
179183              "publicKey": {}
179184            }
179185          },
179186          "modelCard": {
179187            "modelParameters": {
179188              "approach": {}
179189            },
179190            "quantitativeAnalysis": {
179191              "graphics": {}
179192            },
179193            "considerations": {}
179194          }
179195        },
179196        {
179197          "type": "library",
179198          "bom-ref": "pkg:npm/wcwidth@1.0.1?package-id=ee54c63162090e16",
179199          "supplier": {},
179200          "author": "Tim Oxley",
179201          "name": "wcwidth",
179202          "version": "1.0.1",
179203          "description": "Port of C's wcwidth() and wcswidth()",
179204          "licenses": [
179205            {
179206              "license": {
179207                "id": "MIT"
179208              }
179209            }
179210          ],
179211          "cpe": "cpe:2.3:a:timoxley:wcwidth:1.0.1:*:*:*:*:*:*:*",
179212          "purl": "pkg:npm/wcwidth@1.0.1",
179213          "swid": {
179214            "attachment": {}
179215          },
179216          "pedigree": {},
179217          "externalReferences": [
179218            {
179219              "url": "git+https://github.com/timoxley/wcwidth.git",
179220              "type": "distribution"
179221            },
179222            {
179223              "url": "https://github.com/timoxley/wcwidth#readme",
179224              "type": "website"
179225            }
179226          ],
179227          "evidence": {},
179228          "signature": {
179229            "signature": {
179230              "publicKey": {}
179231            }
179232          },
179233          "modelCard": {
179234            "modelParameters": {
179235              "approach": {}
179236            },
179237            "quantitativeAnalysis": {
179238              "graphics": {}
179239            },
179240            "considerations": {}
179241          }
179242        },
179243        {
179244          "type": "library",
179245          "bom-ref": "pkg:npm/which@2.0.2?package-id=1d2beaa974655b97",
179246          "supplier": {},
179247          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
179248          "name": "which",
179249          "version": "2.0.2",
179250          "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
179251          "licenses": [
179252            {
179253              "license": {
179254                "id": "ISC"
179255              }
179256            }
179257          ],
179258          "cpe": "cpe:2.3:a:isaacs:which:2.0.2:*:*:*:*:*:*:*",
179259          "purl": "pkg:npm/which@2.0.2",
179260          "swid": {
179261            "attachment": {}
179262          },
179263          "pedigree": {},
179264          "externalReferences": [
179265            {
179266              "url": "git://github.com/isaacs/node-which.git",
179267              "type": "distribution"
179268            }
179269          ],
179270          "evidence": {},
179271          "signature": {
179272            "signature": {
179273              "publicKey": {}
179274            }
179275          },
179276          "modelCard": {
179277            "modelParameters": {
179278              "approach": {}
179279            },
179280            "quantitativeAnalysis": {
179281              "graphics": {}
179282            },
179283            "considerations": {}
179284          }
179285        },
179286        {
179287          "type": "library",
179288          "bom-ref": "pkg:npm/which@2.0.2?package-id=e5a03b0ce6856cfb",
179289          "supplier": {},
179290          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
179291          "name": "which",
179292          "version": "2.0.2",
179293          "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
179294          "licenses": [
179295            {
179296              "license": {
179297                "id": "ISC"
179298              }
179299            }
179300          ],
179301          "cpe": "cpe:2.3:a:isaacs:which:2.0.2:*:*:*:*:*:*:*",
179302          "purl": "pkg:npm/which@2.0.2",
179303          "swid": {
179304            "attachment": {}
179305          },
179306          "pedigree": {},
179307          "externalReferences": [
179308            {
179309              "url": "git://github.com/isaacs/node-which.git",
179310              "type": "distribution"
179311            }
179312          ],
179313          "evidence": {},
179314          "signature": {
179315            "signature": {
179316              "publicKey": {}
179317            }
179318          },
179319          "modelCard": {
179320            "modelParameters": {
179321              "approach": {}
179322            },
179323            "quantitativeAnalysis": {
179324              "graphics": {}
179325            },
179326            "considerations": {}
179327          }
179328        },
179329        {
179330          "type": "library",
179331          "bom-ref": "pkg:npm/which-module@2.0.0?package-id=aa72ca00ee9f5c47",
179332          "supplier": {},
179333          "author": "nexdrew",
179334          "name": "which-module",
179335          "version": "2.0.0",
179336          "description": "Find the module object for something that was require()d",
179337          "licenses": [
179338            {
179339              "license": {
179340                "id": "ISC"
179341              }
179342            }
179343          ],
179344          "cpe": "cpe:2.3:a:which-module:which-module:2.0.0:*:*:*:*:*:*:*",
179345          "purl": "pkg:npm/which-module@2.0.0",
179346          "swid": {
179347            "attachment": {}
179348          },
179349          "pedigree": {},
179350          "externalReferences": [
179351            {
179352              "url": "git+https://github.com/nexdrew/which-module.git",
179353              "type": "distribution"
179354            },
179355            {
179356              "url": "https://github.com/nexdrew/which-module#readme",
179357              "type": "website"
179358            }
179359          ],
179360          "evidence": {},
179361          "signature": {
179362            "signature": {
179363              "publicKey": {}
179364            }
179365          },
179366          "modelCard": {
179367            "modelParameters": {
179368              "approach": {}
179369            },
179370            "quantitativeAnalysis": {
179371              "graphics": {}
179372            },
179373            "considerations": {}
179374          }
179375        },
179376        {
179377          "type": "library",
179378          "bom-ref": "pkg:npm/wide-align@1.1.5?package-id=f0bd5200e29a21be",
179379          "supplier": {},
179380          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
179381          "name": "wide-align",
179382          "version": "1.1.5",
179383          "description": "A wide-character aware text alignment function for use on the console or with fixed width fonts.",
179384          "licenses": [
179385            {
179386              "license": {
179387                "id": "ISC"
179388              }
179389            }
179390          ],
179391          "cpe": "cpe:2.3:a:wide-align:wide-align:1.1.5:*:*:*:*:*:*:*",
179392          "purl": "pkg:npm/wide-align@1.1.5",
179393          "swid": {
179394            "attachment": {}
179395          },
179396          "pedigree": {},
179397          "externalReferences": [
179398            {
179399              "url": "https://github.com/iarna/wide-align",
179400              "type": "distribution"
179401            }
179402          ],
179403          "evidence": {},
179404          "signature": {
179405            "signature": {
179406              "publicKey": {}
179407            }
179408          },
179409          "modelCard": {
179410            "modelParameters": {
179411              "approach": {}
179412            },
179413            "quantitativeAnalysis": {
179414              "graphics": {}
179415            },
179416            "considerations": {}
179417          }
179418        },
179419        {
179420          "type": "library",
179421          "bom-ref": "pkg:npm/wide-align@1.1.5?package-id=f289ab46627a3f1a",
179422          "supplier": {},
179423          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
179424          "name": "wide-align",
179425          "version": "1.1.5",
179426          "description": "A wide-character aware text alignment function for use on the console or with fixed width fonts.",
179427          "licenses": [
179428            {
179429              "license": {
179430                "id": "ISC"
179431              }
179432            }
179433          ],
179434          "cpe": "cpe:2.3:a:wide-align:wide-align:1.1.5:*:*:*:*:*:*:*",
179435          "purl": "pkg:npm/wide-align@1.1.5",
179436          "swid": {
179437            "attachment": {}
179438          },
179439          "pedigree": {},
179440          "externalReferences": [
179441            {
179442              "url": "https://github.com/iarna/wide-align",
179443              "type": "distribution"
179444            }
179445          ],
179446          "evidence": {},
179447          "signature": {
179448            "signature": {
179449              "publicKey": {}
179450            }
179451          },
179452          "modelCard": {
179453            "modelParameters": {
179454              "approach": {}
179455            },
179456            "quantitativeAnalysis": {
179457              "graphics": {}
179458            },
179459            "considerations": {}
179460          }
179461        },
179462        {
179463          "type": "library",
179464          "bom-ref": "pkg:npm/wrap-ansi@5.1.0?package-id=99d759e29fd00fc",
179465          "supplier": {},
179466          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
179467          "name": "wrap-ansi",
179468          "version": "5.1.0",
179469          "description": "Wordwrap a string with ANSI escape codes",
179470          "licenses": [
179471            {
179472              "license": {
179473                "id": "MIT"
179474              }
179475            }
179476          ],
179477          "cpe": "cpe:2.3:a:wrap-ansi:wrap-ansi:5.1.0:*:*:*:*:*:*:*",
179478          "purl": "pkg:npm/wrap-ansi@5.1.0",
179479          "swid": {
179480            "attachment": {}
179481          },
179482          "pedigree": {},
179483          "externalReferences": [
179484            {
179485              "url": "chalk/wrap-ansi",
179486              "type": "distribution"
179487            }
179488          ],
179489          "evidence": {},
179490          "signature": {
179491            "signature": {
179492              "publicKey": {}
179493            }
179494          },
179495          "modelCard": {
179496            "modelParameters": {
179497              "approach": {}
179498            },
179499            "quantitativeAnalysis": {
179500              "graphics": {}
179501            },
179502            "considerations": {}
179503          }
179504        },
179505        {
179506          "type": "library",
179507          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=88b7c304022dd8b8",
179508          "supplier": {},
179509          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
179510          "name": "wrappy",
179511          "version": "1.0.2",
179512          "description": "Callback wrapping utility",
179513          "licenses": [
179514            {
179515              "license": {
179516                "id": "ISC"
179517              }
179518            }
179519          ],
179520          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
179521          "purl": "pkg:npm/wrappy@1.0.2",
179522          "swid": {
179523            "attachment": {}
179524          },
179525          "pedigree": {},
179526          "externalReferences": [
179527            {
179528              "url": "https://github.com/npm/wrappy",
179529              "type": "distribution"
179530            },
179531            {
179532              "url": "https://github.com/npm/wrappy",
179533              "type": "website"
179534            }
179535          ],
179536          "evidence": {},
179537          "signature": {
179538            "signature": {
179539              "publicKey": {}
179540            }
179541          },
179542          "modelCard": {
179543            "modelParameters": {
179544              "approach": {}
179545            },
179546            "quantitativeAnalysis": {
179547              "graphics": {}
179548            },
179549            "considerations": {}
179550          }
179551        },
179552        {
179553          "type": "library",
179554          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=ed5926f6f76e646b",
179555          "supplier": {},
179556          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
179557          "name": "wrappy",
179558          "version": "1.0.2",
179559          "description": "Callback wrapping utility",
179560          "licenses": [
179561            {
179562              "license": {
179563                "id": "ISC"
179564              }
179565            }
179566          ],
179567          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
179568          "purl": "pkg:npm/wrappy@1.0.2",
179569          "swid": {
179570            "attachment": {}
179571          },
179572          "pedigree": {},
179573          "externalReferences": [
179574            {
179575              "url": "https://github.com/npm/wrappy",
179576              "type": "distribution"
179577            },
179578            {
179579              "url": "https://github.com/npm/wrappy",
179580              "type": "website"
179581            }
179582          ],
179583          "evidence": {},
179584          "signature": {
179585            "signature": {
179586              "publicKey": {}
179587            }
179588          },
179589          "modelCard": {
179590            "modelParameters": {
179591              "approach": {}
179592            },
179593            "quantitativeAnalysis": {
179594              "graphics": {}
179595            },
179596            "considerations": {}
179597          }
179598        },
179599        {
179600          "type": "library",
179601          "bom-ref": "pkg:npm/write-file-atomic@4.0.2?package-id=401a0baef0d4f8db",
179602          "supplier": {},
179603          "author": "GitHub Inc.",
179604          "name": "write-file-atomic",
179605          "version": "4.0.2",
179606          "description": "Write files in an atomic fashion w/configurable ownership",
179607          "licenses": [
179608            {
179609              "license": {
179610                "id": "ISC"
179611              }
179612            }
179613          ],
179614          "cpe": "cpe:2.3:a:write-file-atomic:write-file-atomic:4.0.2:*:*:*:*:*:*:*",
179615          "purl": "pkg:npm/write-file-atomic@4.0.2",
179616          "swid": {
179617            "attachment": {}
179618          },
179619          "pedigree": {},
179620          "externalReferences": [
179621            {
179622              "url": "https://github.com/npm/write-file-atomic.git",
179623              "type": "distribution"
179624            },
179625            {
179626              "url": "https://github.com/npm/write-file-atomic",
179627              "type": "website"
179628            }
179629          ],
179630          "evidence": {},
179631          "signature": {
179632            "signature": {
179633              "publicKey": {}
179634            }
179635          },
179636          "modelCard": {
179637            "modelParameters": {
179638              "approach": {}
179639            },
179640            "quantitativeAnalysis": {
179641              "graphics": {}
179642            },
179643            "considerations": {}
179644          }
179645        },
179646        {
179647          "type": "library",
179648          "bom-ref": "pkg:npm/y18n@4.0.3?package-id=c92ff00a51eefe99",
179649          "supplier": {},
179650          "author": "Ben Coe \u003cben@npmjs.com\u003e",
179651          "name": "y18n",
179652          "version": "4.0.3",
179653          "description": "the bare-bones internationalization library used by yargs",
179654          "licenses": [
179655            {
179656              "license": {
179657                "id": "ISC"
179658              }
179659            }
179660          ],
179661          "cpe": "cpe:2.3:a:yargs:y18n:4.0.3:*:*:*:*:*:*:*",
179662          "purl": "pkg:npm/y18n@4.0.3",
179663          "swid": {
179664            "attachment": {}
179665          },
179666          "pedigree": {},
179667          "externalReferences": [
179668            {
179669              "url": "git@github.com:yargs/y18n.git",
179670              "type": "distribution"
179671            },
179672            {
179673              "url": "https://github.com/yargs/y18n",
179674              "type": "website"
179675            }
179676          ],
179677          "evidence": {},
179678          "signature": {
179679            "signature": {
179680              "publicKey": {}
179681            }
179682          },
179683          "modelCard": {
179684            "modelParameters": {
179685              "approach": {}
179686            },
179687            "quantitativeAnalysis": {
179688              "graphics": {}
179689            },
179690            "considerations": {}
179691          }
179692        },
179693        {
179694          "type": "library",
179695          "bom-ref": "pkg:npm/yallist@4.0.0?package-id=c5b3d2829d8d6201",
179696          "supplier": {},
179697          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
179698          "name": "yallist",
179699          "version": "4.0.0",
179700          "description": "Yet Another Linked List",
179701          "licenses": [
179702            {
179703              "license": {
179704                "id": "ISC"
179705              }
179706            }
179707          ],
179708          "cpe": "cpe:2.3:a:yallist:yallist:4.0.0:*:*:*:*:*:*:*",
179709          "purl": "pkg:npm/yallist@4.0.0",
179710          "swid": {
179711            "attachment": {}
179712          },
179713          "pedigree": {},
179714          "externalReferences": [
179715            {
179716              "url": "git+https://github.com/isaacs/yallist.git",
179717              "type": "distribution"
179718            }
179719          ],
179720          "evidence": {},
179721          "signature": {
179722            "signature": {
179723              "publicKey": {}
179724            }
179725          },
179726          "modelCard": {
179727            "modelParameters": {
179728              "approach": {}
179729            },
179730            "quantitativeAnalysis": {
179731              "graphics": {}
179732            },
179733            "considerations": {}
179734          }
179735        },
179736        {
179737          "type": "library",
179738          "bom-ref": "pkg:npm/yallist@4.0.0?package-id=962f7b1d680d2d52",
179739          "supplier": {},
179740          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
179741          "name": "yallist",
179742          "version": "4.0.0",
179743          "description": "Yet Another Linked List",
179744          "licenses": [
179745            {
179746              "license": {
179747                "id": "ISC"
179748              }
179749            }
179750          ],
179751          "cpe": "cpe:2.3:a:yallist:yallist:4.0.0:*:*:*:*:*:*:*",
179752          "purl": "pkg:npm/yallist@4.0.0",
179753          "swid": {
179754            "attachment": {}
179755          },
179756          "pedigree": {},
179757          "externalReferences": [
179758            {
179759              "url": "git+https://github.com/isaacs/yallist.git",
179760              "type": "distribution"
179761            }
179762          ],
179763          "evidence": {},
179764          "signature": {
179765            "signature": {
179766              "publicKey": {}
179767            }
179768          },
179769          "modelCard": {
179770            "modelParameters": {
179771              "approach": {}
179772            },
179773            "quantitativeAnalysis": {
179774              "graphics": {}
179775            },
179776            "considerations": {}
179777          }
179778        },
179779        {
179780          "type": "library",
179781          "bom-ref": "pkg:npm/yargs@13.3.2?package-id=2ef5bb5df9eb81e7",
179782          "supplier": {},
179783          "name": "yargs",
179784          "version": "13.3.2",
179785          "description": "yargs the modern, pirate-themed, successor to optimist.",
179786          "licenses": [
179787            {
179788              "license": {
179789                "id": "MIT"
179790              }
179791            }
179792          ],
179793          "cpe": "cpe:2.3:a:yargs:yargs:13.3.2:*:*:*:*:*:*:*",
179794          "purl": "pkg:npm/yargs@13.3.2",
179795          "swid": {
179796            "attachment": {}
179797          },
179798          "pedigree": {},
179799          "externalReferences": [
179800            {
179801              "url": "https://github.com/yargs/yargs.git",
179802              "type": "distribution"
179803            },
179804            {
179805              "url": "https://yargs.js.org/",
179806              "type": "website"
179807            }
179808          ],
179809          "evidence": {},
179810          "signature": {
179811            "signature": {
179812              "publicKey": {}
179813            }
179814          },
179815          "modelCard": {
179816            "modelParameters": {
179817              "approach": {}
179818            },
179819            "quantitativeAnalysis": {
179820              "graphics": {}
179821            },
179822            "considerations": {}
179823          }
179824        },
179825        {
179826          "type": "library",
179827          "bom-ref": "pkg:npm/yargs-parser@13.1.2?package-id=fd557779eae2a359",
179828          "supplier": {},
179829          "author": "Ben Coe \u003cben@npmjs.com\u003e",
179830          "name": "yargs-parser",
179831          "version": "13.1.2",
179832          "description": "the mighty option parser used by yargs",
179833          "licenses": [
179834            {
179835              "license": {
179836                "id": "ISC"
179837              }
179838            }
179839          ],
179840          "cpe": "cpe:2.3:a:yargs-parser:yargs-parser:13.1.2:*:*:*:*:*:*:*",
179841          "purl": "pkg:npm/yargs-parser@13.1.2",
179842          "swid": {
179843            "attachment": {}
179844          },
179845          "pedigree": {},
179846          "externalReferences": [
179847            {
179848              "url": "git@github.com:yargs/yargs-parser.git",
179849              "type": "distribution"
179850            }
179851          ],
179852          "evidence": {},
179853          "signature": {
179854            "signature": {
179855              "publicKey": {}
179856            }
179857          },
179858          "modelCard": {
179859            "modelParameters": {
179860              "approach": {}
179861            },
179862            "quantitativeAnalysis": {
179863              "graphics": {}
179864            },
179865            "considerations": {}
179866          }
179867        },
179868        {
179869          "type": "library",
179870          "bom-ref": "pkg:npm/yargs-parser@20.2.9?package-id=5e93c3480eb20787",
179871          "supplier": {},
179872          "author": "Ben Coe \u003cben@npmjs.com\u003e",
179873          "name": "yargs-parser",
179874          "version": "20.2.9",
179875          "description": "the mighty option parser used by yargs",
179876          "licenses": [
179877            {
179878              "license": {
179879                "id": "ISC"
179880              }
179881            }
179882          ],
179883          "cpe": "cpe:2.3:a:yargs-parser:yargs-parser:20.2.9:*:*:*:*:*:*:*",
179884          "purl": "pkg:npm/yargs-parser@20.2.9",
179885          "swid": {
179886            "attachment": {}
179887          },
179888          "pedigree": {},
179889          "externalReferences": [
179890            {
179891              "url": "https://github.com/yargs/yargs-parser.git",
179892              "type": "distribution"
179893            }
179894          ],
179895          "evidence": {},
179896          "signature": {
179897            "signature": {
179898              "publicKey": {}
179899            }
179900          },
179901          "modelCard": {
179902            "modelParameters": {
179903              "approach": {}
179904            },
179905            "quantitativeAnalysis": {
179906              "graphics": {}
179907            },
179908            "considerations": {}
179909          }
179910        },
179911        {
179912          "type": "library",
179913          "bom-ref": "pkg:npm/yarn@1.22.19?package-id=f2b974a78000b26b",
179914          "supplier": {},
179915          "name": "yarn",
179916          "version": "1.22.19",
179917          "description": "📦🐈 Fast, reliable, and secure dependency management.",
179918          "licenses": [
179919            {
179920              "license": {
179921                "id": "BSD-2-Clause"
179922              }
179923            }
179924          ],
179925          "cpe": "cpe:2.3:a:yarn:yarn:1.22.19:*:*:*:*:*:*:*",
179926          "purl": "pkg:npm/yarn@1.22.19",
179927          "swid": {
179928            "attachment": {}
179929          },
179930          "pedigree": {},
179931          "externalReferences": [
179932            {
179933              "url": "yarnpkg/yarn",
179934              "type": "distribution"
179935            }
179936          ],
179937          "evidence": {},
179938          "signature": {
179939            "signature": {
179940              "publicKey": {}
179941            }
179942          },
179943          "modelCard": {
179944            "modelParameters": {
179945              "approach": {}
179946            },
179947            "quantitativeAnalysis": {
179948              "graphics": {}
179949            },
179950            "considerations": {}
179951          }
179952        },
179953        {
179954          "type": "library",
179955          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=75f0d92f695b4303",
179956          "supplier": {},
179957          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
179958          "name": "zlib",
179959          "version": "1.2.12-r3",
179960          "description": "A compression/decompression Library",
179961          "licenses": [
179962            {
179963              "license": {
179964                "id": "Zlib"
179965              }
179966            }
179967          ],
179968          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
179969          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5",
179970          "swid": {
179971            "attachment": {}
179972          },
179973          "pedigree": {},
179974          "externalReferences": [
179975            {
179976              "url": "https://zlib.net/",
179977              "type": "distribution"
179978            }
179979          ],
179980          "evidence": {},
179981          "signature": {
179982            "signature": {
179983              "publicKey": {}
179984            }
179985          },
179986          "modelCard": {
179987            "modelParameters": {
179988              "approach": {}
179989            },
179990            "quantitativeAnalysis": {
179991              "graphics": {}
179992            },
179993            "considerations": {}
179994          }
179995        },
179996        {
179997          "type": "operating-system",
179998          "supplier": {},
179999          "name": "alpine",
180000          "version": "3.16.5",
180001          "description": "Alpine Linux v3.16",
180002          "swid": {
180003            "tagId": "alpine",
180004            "name": "alpine",
180005            "version": "3.16.5",
180006            "attachment": {}
180007          },
180008          "pedigree": {},
180009          "externalReferences": [
180010            {
180011              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
180012              "type": "issue-tracker"
180013            },
180014            {
180015              "url": "https://alpinelinux.org/",
180016              "type": "website"
180017            }
180018          ],
180019          "evidence": {},
180020          "signature": {
180021            "signature": {
180022              "publicKey": {}
180023            }
180024          },
180025          "modelCard": {
180026            "modelParameters": {
180027              "approach": {}
180028            },
180029            "quantitativeAnalysis": {
180030              "graphics": {}
180031            },
180032            "considerations": {}
180033          }
180034        },
180035        {
180036          "type": "library",
180037          "bom-ref": "pkg:npm/%40fastify/deepmerge@1.3.0?package-id=e2d8e13424224470",
180038          "supplier": {},
180039          "name": "@fastify/deepmerge",
180040          "version": "1.3.0",
180041          "description": "Merges the enumerable properties of two or more objects deeply.",
180042          "licenses": [
180043            {
180044              "license": {
180045                "id": "MIT"
180046              }
180047            }
180048          ],
180049          "cpe": "cpe:2.3:a:\\@fastify\\/deepmerge:\\@fastify\\/deepmerge:1.3.0:*:*:*:*:*:*:*",
180050          "purl": "pkg:npm/%40fastify/deepmerge@1.3.0",
180051          "swid": {
180052            "attachment": {}
180053          },
180054          "pedigree": {},
180055          "externalReferences": [
180056            {
180057              "url": "git+https://github.com/fastify/deepmerge.git",
180058              "type": "distribution"
180059            },
180060            {
180061              "url": "https://github.com/fastify/deepmerge#readme",
180062              "type": "website"
180063            }
180064          ],
180065          "evidence": {},
180066          "signature": {
180067            "signature": {
180068              "publicKey": {}
180069            }
180070          },
180071          "modelCard": {
180072            "modelParameters": {
180073              "approach": {}
180074            },
180075            "quantitativeAnalysis": {
180076              "graphics": {}
180077            },
180078            "considerations": {}
180079          }
180080        },
180081        {
180082          "type": "library",
180083          "bom-ref": "pkg:npm/%40nestjs/common@7.6.12?package-id=d54be2ae3d12494b",
180084          "supplier": {},
180085          "author": "Kamil Mysliwiec",
180086          "name": "@nestjs/common",
180087          "version": "7.6.12",
180088          "description": "Nest - modern, fast, powerful node.js web framework (@common)",
180089          "licenses": [
180090            {
180091              "license": {
180092                "id": "MIT"
180093              }
180094            }
180095          ],
180096          "cpe": "cpe:2.3:a:\\@nestjs\\/common:\\@nestjs\\/common:7.6.12:*:*:*:*:*:*:*",
180097          "purl": "pkg:npm/%40nestjs/common@7.6.12",
180098          "swid": {
180099            "attachment": {}
180100          },
180101          "pedigree": {},
180102          "externalReferences": [
180103            {
180104              "url": "git+https://github.com/nestjs/nest.git",
180105              "type": "distribution"
180106            },
180107            {
180108              "url": "https://nestjs.com",
180109              "type": "website"
180110            }
180111          ],
180112          "evidence": {},
180113          "signature": {
180114            "signature": {
180115              "publicKey": {}
180116            }
180117          },
180118          "modelCard": {
180119            "modelParameters": {
180120              "approach": {}
180121            },
180122            "quantitativeAnalysis": {
180123              "graphics": {}
180124            },
180125            "considerations": {}
180126          }
180127        },
180128        {
180129          "type": "library",
180130          "bom-ref": "pkg:npm/%40nestjs/core@7.6.12?package-id=4f81c182fc0c1725",
180131          "supplier": {},
180132          "author": "Kamil Mysliwiec",
180133          "name": "@nestjs/core",
180134          "version": "7.6.12",
180135          "description": "Nest - modern, fast, powerful node.js web framework (@core)",
180136          "licenses": [
180137            {
180138              "license": {
180139                "id": "MIT"
180140              }
180141            }
180142          ],
180143          "cpe": "cpe:2.3:a:\\@nestjs\\/core:\\@nestjs\\/core:7.6.12:*:*:*:*:*:*:*",
180144          "purl": "pkg:npm/%40nestjs/core@7.6.12",
180145          "swid": {
180146            "attachment": {}
180147          },
180148          "pedigree": {},
180149          "externalReferences": [
180150            {
180151              "url": "git+https://github.com/nestjs/nest.git",
180152              "type": "distribution"
180153            },
180154            {
180155              "url": "https://nestjs.com",
180156              "type": "website"
180157            }
180158          ],
180159          "evidence": {},
180160          "signature": {
180161            "signature": {
180162              "publicKey": {}
180163            }
180164          },
180165          "modelCard": {
180166            "modelParameters": {
180167              "approach": {}
180168            },
180169            "quantitativeAnalysis": {
180170              "graphics": {}
180171            },
180172            "considerations": {}
180173          }
180174        },
180175        {
180176          "type": "library",
180177          "bom-ref": "pkg:npm/%40nestjs/mapped-types@0.3.0?package-id=33f368ce65b8a92c",
180178          "supplier": {},
180179          "author": "Kamil Mysliwiec",
180180          "name": "@nestjs/mapped-types",
180181          "version": "0.3.0",
180182          "description": "Nest - modern, fast, powerful node.js web framework (@mapped-types)",
180183          "licenses": [
180184            {
180185              "license": {
180186                "id": "MIT"
180187              }
180188            }
180189          ],
180190          "cpe": "cpe:2.3:a:\\@nestjs\\/mapped-types:\\@nestjs\\/mapped-types:0.3.0:*:*:*:*:*:*:*",
180191          "purl": "pkg:npm/%40nestjs/mapped-types@0.3.0",
180192          "swid": {
180193            "attachment": {}
180194          },
180195          "pedigree": {},
180196          "externalReferences": [
180197            {
180198              "url": "git+https://github.com/nestjs/mapped-types.git",
180199              "type": "distribution"
180200            },
180201            {
180202              "url": "https://github.com/nestjs/mapped-types#readme",
180203              "type": "website"
180204            }
180205          ],
180206          "evidence": {},
180207          "signature": {
180208            "signature": {
180209              "publicKey": {}
180210            }
180211          },
180212          "modelCard": {
180213            "modelParameters": {
180214              "approach": {}
180215            },
180216            "quantitativeAnalysis": {
180217              "graphics": {}
180218            },
180219            "considerations": {}
180220          }
180221        },
180222        {
180223          "type": "library",
180224          "bom-ref": "pkg:npm/%40nestjs/platform-express@7.6.12?package-id=bce3b466e5e7f496",
180225          "supplier": {},
180226          "author": "Kamil Mysliwiec",
180227          "name": "@nestjs/platform-express",
180228          "version": "7.6.12",
180229          "description": "Nest - modern, fast, powerful node.js web framework (@platform-express)",
180230          "licenses": [
180231            {
180232              "license": {
180233                "id": "MIT"
180234              }
180235            }
180236          ],
180237          "cpe": "cpe:2.3:a:\\@nestjs\\/platform-express:\\@nestjs\\/platform-express:7.6.12:*:*:*:*:*:*:*",
180238          "purl": "pkg:npm/%40nestjs/platform-express@7.6.12",
180239          "swid": {
180240            "attachment": {}
180241          },
180242          "pedigree": {},
180243          "externalReferences": [
180244            {
180245              "url": "git+https://github.com/nestjs/nest.git",
180246              "type": "distribution"
180247            },
180248            {
180249              "url": "https://nestjs.com",
180250              "type": "website"
180251            }
180252          ],
180253          "evidence": {},
180254          "signature": {
180255            "signature": {
180256              "publicKey": {}
180257            }
180258          },
180259          "modelCard": {
180260            "modelParameters": {
180261              "approach": {}
180262            },
180263            "quantitativeAnalysis": {
180264              "graphics": {}
180265            },
180266            "considerations": {}
180267          }
180268        },
180269        {
180270          "type": "library",
180271          "bom-ref": "pkg:npm/%40nestjs/swagger@4.7.13?package-id=c910b4ab7eafab3d",
180272          "supplier": {},
180273          "author": "Kamil Mysliwiec",
180274          "name": "@nestjs/swagger",
180275          "version": "4.7.13",
180276          "description": "Nest - modern, fast, powerful node.js web framework (@swagger)",
180277          "licenses": [
180278            {
180279              "license": {
180280                "id": "MIT"
180281              }
180282            }
180283          ],
180284          "cpe": "cpe:2.3:a:\\@nestjs\\/swagger:\\@nestjs\\/swagger:4.7.13:*:*:*:*:*:*:*",
180285          "purl": "pkg:npm/%40nestjs/swagger@4.7.13",
180286          "swid": {
180287            "attachment": {}
180288          },
180289          "pedigree": {},
180290          "externalReferences": [
180291            {
180292              "url": "git+https://github.com/nestjs/swagger.git",
180293              "type": "distribution"
180294            },
180295            {
180296              "url": "https://github.com/nestjs/swagger#readme",
180297              "type": "website"
180298            }
180299          ],
180300          "evidence": {},
180301          "signature": {
180302            "signature": {
180303              "publicKey": {}
180304            }
180305          },
180306          "modelCard": {
180307            "modelParameters": {
180308              "approach": {}
180309            },
180310            "quantitativeAnalysis": {
180311              "graphics": {}
180312            },
180313            "considerations": {}
180314          }
180315        },
180316        {
180317          "type": "library",
180318          "bom-ref": "pkg:npm/%40nuxtjs/opencollective@0.3.2?package-id=4e66d3ddcbf4b722",
180319          "supplier": {},
180320          "name": "@nuxtjs/opencollective",
180321          "version": "0.3.2",
180322          "description": "[![npm version][npm-v-src]][npm-v-href] [![npm downloads][npm-d-src]][npm-d-href] [![status][github-actions-src]][github-actions-href]",
180323          "licenses": [
180324            {
180325              "license": {
180326                "id": "MIT"
180327              }
180328            }
180329          ],
180330          "cpe": "cpe:2.3:a:\\@nuxtjs\\/opencollective:\\@nuxtjs\\/opencollective:0.3.2:*:*:*:*:*:*:*",
180331          "purl": "pkg:npm/%40nuxtjs/opencollective@0.3.2",
180332          "swid": {
180333            "attachment": {}
180334          },
180335          "pedigree": {},
180336          "externalReferences": [
180337            {
180338              "url": "git+https://github.com/nuxt-contrib/opencollective.git",
180339              "type": "distribution"
180340            },
180341            {
180342              "url": "https://github.com/nuxt-contrib/opencollective#readme",
180343              "type": "website"
180344            }
180345          ],
180346          "evidence": {},
180347          "signature": {
180348            "signature": {
180349              "publicKey": {}
180350            }
180351          },
180352          "modelCard": {
180353            "modelParameters": {
180354              "approach": {}
180355            },
180356            "quantitativeAnalysis": {
180357              "graphics": {}
180358            },
180359            "considerations": {}
180360          }
180361        },
180362        {
180363          "type": "library",
180364          "bom-ref": "pkg:npm/%40sentry/core@6.19.7?package-id=cd0c1f5b8fc79b8d",
180365          "supplier": {},
180366          "author": "Sentry",
180367          "name": "@sentry/core",
180368          "version": "6.19.7",
180369          "description": "Base implementation for all Sentry JavaScript SDKs",
180370          "licenses": [
180371            {
180372              "license": {
180373                "id": "BSD-3-Clause"
180374              }
180375            }
180376          ],
180377          "cpe": "cpe:2.3:a:\\@sentry\\/core:\\@sentry\\/core:6.19.7:*:*:*:*:*:*:*",
180378          "purl": "pkg:npm/%40sentry/core@6.19.7",
180379          "swid": {
180380            "attachment": {}
180381          },
180382          "pedigree": {},
180383          "externalReferences": [
180384            {
180385              "url": "git://github.com/getsentry/sentry-javascript.git",
180386              "type": "distribution"
180387            },
180388            {
180389              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/core",
180390              "type": "website"
180391            }
180392          ],
180393          "evidence": {},
180394          "signature": {
180395            "signature": {
180396              "publicKey": {}
180397            }
180398          },
180399          "modelCard": {
180400            "modelParameters": {
180401              "approach": {}
180402            },
180403            "quantitativeAnalysis": {
180404              "graphics": {}
180405            },
180406            "considerations": {}
180407          }
180408        },
180409        {
180410          "type": "library",
180411          "bom-ref": "pkg:npm/%40sentry/hub@6.19.7?package-id=9d14c99265a8607f",
180412          "supplier": {},
180413          "author": "Sentry",
180414          "name": "@sentry/hub",
180415          "version": "6.19.7",
180416          "description": "Sentry hub which handles global state managment.",
180417          "licenses": [
180418            {
180419              "license": {
180420                "id": "BSD-3-Clause"
180421              }
180422            }
180423          ],
180424          "cpe": "cpe:2.3:a:\\@sentry\\/hub:\\@sentry\\/hub:6.19.7:*:*:*:*:*:*:*",
180425          "purl": "pkg:npm/%40sentry/hub@6.19.7",
180426          "swid": {
180427            "attachment": {}
180428          },
180429          "pedigree": {},
180430          "externalReferences": [
180431            {
180432              "url": "git://github.com/getsentry/sentry-javascript.git",
180433              "type": "distribution"
180434            },
180435            {
180436              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/hub",
180437              "type": "website"
180438            }
180439          ],
180440          "evidence": {},
180441          "signature": {
180442            "signature": {
180443              "publicKey": {}
180444            }
180445          },
180446          "modelCard": {
180447            "modelParameters": {
180448              "approach": {}
180449            },
180450            "quantitativeAnalysis": {
180451              "graphics": {}
180452            },
180453            "considerations": {}
180454          }
180455        },
180456        {
180457          "type": "library",
180458          "bom-ref": "pkg:npm/%40sentry/minimal@6.19.7?package-id=777bce7c6aa8896f",
180459          "supplier": {},
180460          "author": "Sentry",
180461          "name": "@sentry/minimal",
180462          "version": "6.19.7",
180463          "description": "Sentry minimal library that can be used in other packages",
180464          "licenses": [
180465            {
180466              "license": {
180467                "id": "BSD-3-Clause"
180468              }
180469            }
180470          ],
180471          "cpe": "cpe:2.3:a:\\@sentry\\/minimal:\\@sentry\\/minimal:6.19.7:*:*:*:*:*:*:*",
180472          "purl": "pkg:npm/%40sentry/minimal@6.19.7",
180473          "swid": {
180474            "attachment": {}
180475          },
180476          "pedigree": {},
180477          "externalReferences": [
180478            {
180479              "url": "git://github.com/getsentry/sentry-javascript.git",
180480              "type": "distribution"
180481            },
180482            {
180483              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/minimal",
180484              "type": "website"
180485            }
180486          ],
180487          "evidence": {},
180488          "signature": {
180489            "signature": {
180490              "publicKey": {}
180491            }
180492          },
180493          "modelCard": {
180494            "modelParameters": {
180495              "approach": {}
180496            },
180497            "quantitativeAnalysis": {
180498              "graphics": {}
180499            },
180500            "considerations": {}
180501          }
180502        },
180503        {
180504          "type": "library",
180505          "bom-ref": "pkg:npm/%40sentry/node@6.19.7?package-id=a0e2d79b4943eadd",
180506          "supplier": {},
180507          "author": "Sentry",
180508          "name": "@sentry/node",
180509          "version": "6.19.7",
180510          "description": "Official Sentry SDK for Node.js",
180511          "licenses": [
180512            {
180513              "license": {
180514                "id": "BSD-3-Clause"
180515              }
180516            }
180517          ],
180518          "cpe": "cpe:2.3:a:\\@sentry\\/node:\\@sentry\\/node:6.19.7:*:*:*:*:*:*:*",
180519          "purl": "pkg:npm/%40sentry/node@6.19.7",
180520          "swid": {
180521            "attachment": {}
180522          },
180523          "pedigree": {},
180524          "externalReferences": [
180525            {
180526              "url": "git://github.com/getsentry/sentry-javascript.git",
180527              "type": "distribution"
180528            },
180529            {
180530              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/node",
180531              "type": "website"
180532            }
180533          ],
180534          "evidence": {},
180535          "signature": {
180536            "signature": {
180537              "publicKey": {}
180538            }
180539          },
180540          "modelCard": {
180541            "modelParameters": {
180542              "approach": {}
180543            },
180544            "quantitativeAnalysis": {
180545              "graphics": {}
180546            },
180547            "considerations": {}
180548          }
180549        },
180550        {
180551          "type": "library",
180552          "bom-ref": "pkg:npm/%40sentry/types@6.19.7?package-id=11f2f61157a029d8",
180553          "supplier": {},
180554          "author": "Sentry",
180555          "name": "@sentry/types",
180556          "version": "6.19.7",
180557          "description": "Types for all Sentry JavaScript SDKs",
180558          "licenses": [
180559            {
180560              "license": {
180561                "id": "BSD-3-Clause"
180562              }
180563            }
180564          ],
180565          "cpe": "cpe:2.3:a:\\@sentry\\/types:\\@sentry\\/types:6.19.7:*:*:*:*:*:*:*",
180566          "purl": "pkg:npm/%40sentry/types@6.19.7",
180567          "swid": {
180568            "attachment": {}
180569          },
180570          "pedigree": {},
180571          "externalReferences": [
180572            {
180573              "url": "git://github.com/getsentry/sentry-javascript.git",
180574              "type": "distribution"
180575            },
180576            {
180577              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/types",
180578              "type": "website"
180579            }
180580          ],
180581          "evidence": {},
180582          "signature": {
180583            "signature": {
180584              "publicKey": {}
180585            }
180586          },
180587          "modelCard": {
180588            "modelParameters": {
180589              "approach": {}
180590            },
180591            "quantitativeAnalysis": {
180592              "graphics": {}
180593            },
180594            "considerations": {}
180595          }
180596        },
180597        {
180598          "type": "library",
180599          "bom-ref": "pkg:npm/%40sentry/utils@6.19.7?package-id=a2a54a310d970b26",
180600          "supplier": {},
180601          "author": "Sentry",
180602          "name": "@sentry/utils",
180603          "version": "6.19.7",
180604          "description": "Utilities for all Sentry JavaScript SDKs",
180605          "licenses": [
180606            {
180607              "license": {
180608                "id": "BSD-3-Clause"
180609              }
180610            }
180611          ],
180612          "cpe": "cpe:2.3:a:\\@sentry\\/utils:\\@sentry\\/utils:6.19.7:*:*:*:*:*:*:*",
180613          "purl": "pkg:npm/%40sentry/utils@6.19.7",
180614          "swid": {
180615            "attachment": {}
180616          },
180617          "pedigree": {},
180618          "externalReferences": [
180619            {
180620              "url": "git://github.com/getsentry/sentry-javascript.git",
180621              "type": "distribution"
180622            },
180623            {
180624              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/utils",
180625              "type": "website"
180626            }
180627          ],
180628          "evidence": {},
180629          "signature": {
180630            "signature": {
180631              "publicKey": {}
180632            }
180633          },
180634          "modelCard": {
180635            "modelParameters": {
180636              "approach": {}
180637            },
180638            "quantitativeAnalysis": {
180639              "graphics": {}
180640            },
180641            "considerations": {}
180642          }
180643        },
180644        {
180645          "type": "library",
180646          "bom-ref": "pkg:npm/%40types/swagger-schema-official@2.0.21?package-id=fb625df5e37ecc8e",
180647          "supplier": {},
180648          "name": "@types/swagger-schema-official",
180649          "version": "2.0.21",
180650          "description": "TypeScript definitions for swagger-schema-official",
180651          "licenses": [
180652            {
180653              "license": {
180654                "id": "MIT"
180655              }
180656            }
180657          ],
180658          "cpe": "cpe:2.3:a:\\@types\\/swagger-schema-official:\\@types\\/swagger-schema-official:2.0.21:*:*:*:*:*:*:*",
180659          "purl": "pkg:npm/%40types/swagger-schema-official@2.0.21",
180660          "swid": {
180661            "attachment": {}
180662          },
180663          "pedigree": {},
180664          "externalReferences": [
180665            {
180666              "url": "git+https://github.com/DefinitelyTyped/DefinitelyTyped.git",
180667              "type": "distribution"
180668            },
180669            {
180670              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped#readme",
180671              "type": "website"
180672            }
180673          ],
180674          "evidence": {},
180675          "signature": {
180676            "signature": {
180677              "publicKey": {}
180678            }
180679          },
180680          "modelCard": {
180681            "modelParameters": {
180682              "approach": {}
180683            },
180684            "quantitativeAnalysis": {
180685              "graphics": {}
180686            },
180687            "considerations": {}
180688          }
180689        },
180690        {
180691          "type": "library",
180692          "bom-ref": "pkg:npm/%40types/validator@13.0.0?package-id=df4b0f14d888b090",
180693          "supplier": {},
180694          "name": "@types/validator",
180695          "version": "13.0.0",
180696          "description": "TypeScript definitions for validator.js",
180697          "licenses": [
180698            {
180699              "license": {
180700                "id": "MIT"
180701              }
180702            }
180703          ],
180704          "cpe": "cpe:2.3:a:\\@types\\/validator:\\@types\\/validator:13.0.0:*:*:*:*:*:*:*",
180705          "purl": "pkg:npm/%40types/validator@13.0.0",
180706          "swid": {
180707            "attachment": {}
180708          },
180709          "pedigree": {},
180710          "externalReferences": [
180711            {
180712              "url": "git+https://github.com/DefinitelyTyped/DefinitelyTyped.git",
180713              "type": "distribution"
180714            },
180715            {
180716              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped#readme",
180717              "type": "website"
180718            }
180719          ],
180720          "evidence": {},
180721          "signature": {
180722            "signature": {
180723              "publicKey": {}
180724            }
180725          },
180726          "modelCard": {
180727            "modelParameters": {
180728              "approach": {}
180729            },
180730            "quantitativeAnalysis": {
180731              "graphics": {}
180732            },
180733            "considerations": {}
180734          }
180735        },
180736        {
180737          "type": "library",
180738          "bom-ref": "pkg:npm/JSONStream@1.3.5?package-id=362f19a26f622e0",
180739          "supplier": {},
180740          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (http://bit.ly/dominictarr)",
180741          "name": "JSONStream",
180742          "version": "1.3.5",
180743          "description": "rawStream.pipe(JSONStream.parse()).pipe(streamOfObjects)",
180744          "licenses": [
180745            {
180746              "license": {
180747                "name": "(MIT OR Apache-2.0)"
180748              }
180749            }
180750          ],
180751          "cpe": "cpe:2.3:a:dominictarr:JSONStream:1.3.5:*:*:*:*:*:*:*",
180752          "purl": "pkg:npm/JSONStream@1.3.5",
180753          "swid": {
180754            "attachment": {}
180755          },
180756          "pedigree": {},
180757          "externalReferences": [
180758            {
180759              "url": "git://github.com/dominictarr/JSONStream.git",
180760              "type": "distribution"
180761            },
180762            {
180763              "url": "http://github.com/dominictarr/JSONStream",
180764              "type": "website"
180765            }
180766          ],
180767          "evidence": {},
180768          "signature": {
180769            "signature": {
180770              "publicKey": {}
180771            }
180772          },
180773          "modelCard": {
180774            "modelParameters": {
180775              "approach": {}
180776            },
180777            "quantitativeAnalysis": {
180778              "graphics": {}
180779            },
180780            "considerations": {}
180781          }
180782        },
180783        {
180784          "type": "library",
180785          "bom-ref": "pkg:npm/abbrev@1.1.1?package-id=79936430981a8702",
180786          "supplier": {},
180787          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
180788          "name": "abbrev",
180789          "version": "1.1.1",
180790          "description": "Like ruby's abbrev module, but in js",
180791          "licenses": [
180792            {
180793              "license": {
180794                "id": "ISC"
180795              }
180796            }
180797          ],
180798          "cpe": "cpe:2.3:a:abbrev:abbrev:1.1.1:*:*:*:*:*:*:*",
180799          "purl": "pkg:npm/abbrev@1.1.1",
180800          "swid": {
180801            "attachment": {}
180802          },
180803          "pedigree": {},
180804          "externalReferences": [
180805            {
180806              "url": "git+ssh://git@github.com/isaacs/abbrev-js.git",
180807              "type": "distribution"
180808            },
180809            {
180810              "url": "https://github.com/isaacs/abbrev-js#readme",
180811              "type": "website"
180812            }
180813          ],
180814          "evidence": {},
180815          "signature": {
180816            "signature": {
180817              "publicKey": {}
180818            }
180819          },
180820          "modelCard": {
180821            "modelParameters": {
180822              "approach": {}
180823            },
180824            "quantitativeAnalysis": {
180825              "graphics": {}
180826            },
180827            "considerations": {}
180828          }
180829        },
180830        {
180831          "type": "library",
180832          "bom-ref": "pkg:npm/accepts@1.3.7?package-id=bbbf816fe622ef49",
180833          "supplier": {},
180834          "name": "accepts",
180835          "version": "1.3.7",
180836          "description": "Higher-level content negotiation",
180837          "licenses": [
180838            {
180839              "license": {
180840                "id": "MIT"
180841              }
180842            }
180843          ],
180844          "cpe": "cpe:2.3:a:accepts:accepts:1.3.7:*:*:*:*:*:*:*",
180845          "purl": "pkg:npm/accepts@1.3.7",
180846          "swid": {
180847            "attachment": {}
180848          },
180849          "pedigree": {},
180850          "externalReferences": [
180851            {
180852              "url": "git+https://github.com/jshttp/accepts.git",
180853              "type": "distribution"
180854            },
180855            {
180856              "url": "https://github.com/jshttp/accepts#readme",
180857              "type": "website"
180858            }
180859          ],
180860          "evidence": {},
180861          "signature": {
180862            "signature": {
180863              "publicKey": {}
180864            }
180865          },
180866          "modelCard": {
180867            "modelParameters": {
180868              "approach": {}
180869            },
180870            "quantitativeAnalysis": {
180871              "graphics": {}
180872            },
180873            "considerations": {}
180874          }
180875        },
180876        {
180877          "type": "library",
180878          "bom-ref": "pkg:npm/acorn@8.0.5?package-id=3d1e17617f009f24",
180879          "supplier": {},
180880          "name": "acorn",
180881          "version": "8.0.5",
180882          "description": "ECMAScript parser",
180883          "licenses": [
180884            {
180885              "license": {
180886                "id": "MIT"
180887              }
180888            }
180889          ],
180890          "cpe": "cpe:2.3:a:acornjs:acorn:8.0.5:*:*:*:*:*:*:*",
180891          "purl": "pkg:npm/acorn@8.0.5",
180892          "swid": {
180893            "attachment": {}
180894          },
180895          "pedigree": {},
180896          "externalReferences": [
180897            {
180898              "url": "git+https://github.com/acornjs/acorn.git",
180899              "type": "distribution"
180900            },
180901            {
180902              "url": "https://github.com/acornjs/acorn",
180903              "type": "website"
180904            }
180905          ],
180906          "evidence": {},
180907          "signature": {
180908            "signature": {
180909              "publicKey": {}
180910            }
180911          },
180912          "modelCard": {
180913            "modelParameters": {
180914              "approach": {}
180915            },
180916            "quantitativeAnalysis": {
180917              "graphics": {}
180918            },
180919            "considerations": {}
180920          }
180921        },
180922        {
180923          "type": "library",
180924          "bom-ref": "pkg:npm/acorn-walk@8.0.2?package-id=1b1982bbf272f1dd",
180925          "supplier": {},
180926          "name": "acorn-walk",
180927          "version": "8.0.2",
180928          "description": "ECMAScript (ESTree) AST walker",
180929          "licenses": [
180930            {
180931              "license": {
180932                "id": "MIT"
180933              }
180934            }
180935          ],
180936          "cpe": "cpe:2.3:a:acorn-walk:acorn-walk:8.0.2:*:*:*:*:*:*:*",
180937          "purl": "pkg:npm/acorn-walk@8.0.2",
180938          "swid": {
180939            "attachment": {}
180940          },
180941          "pedigree": {},
180942          "externalReferences": [
180943            {
180944              "url": "git+https://github.com/acornjs/acorn.git",
180945              "type": "distribution"
180946            },
180947            {
180948              "url": "https://github.com/acornjs/acorn",
180949              "type": "website"
180950            }
180951          ],
180952          "evidence": {},
180953          "signature": {
180954            "signature": {
180955              "publicKey": {}
180956            }
180957          },
180958          "modelCard": {
180959            "modelParameters": {
180960              "approach": {}
180961            },
180962            "quantitativeAnalysis": {
180963              "graphics": {}
180964            },
180965            "considerations": {}
180966          }
180967        },
180968        {
180969          "type": "library",
180970          "bom-ref": "pkg:npm/agent-base@4.2.1?package-id=5fc4c61198f37ad3",
180971          "supplier": {},
180972          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
180973          "name": "agent-base",
180974          "version": "4.2.1",
180975          "description": "Turn a function into an `http.Agent` instance",
180976          "licenses": [
180977            {
180978              "license": {
180979                "id": "MIT"
180980              }
180981            }
180982          ],
180983          "cpe": "cpe:2.3:a:TooTallNate:agent-base:4.2.1:*:*:*:*:*:*:*",
180984          "purl": "pkg:npm/agent-base@4.2.1",
180985          "swid": {
180986            "attachment": {}
180987          },
180988          "pedigree": {},
180989          "externalReferences": [
180990            {
180991              "url": "git://github.com/TooTallNate/node-agent-base.git",
180992              "type": "distribution"
180993            },
180994            {
180995              "url": "https://github.com/TooTallNate/node-agent-base#readme",
180996              "type": "website"
180997            }
180998          ],
180999          "evidence": {},
181000          "signature": {
181001            "signature": {
181002              "publicKey": {}
181003            }
181004          },
181005          "modelCard": {
181006            "modelParameters": {
181007              "approach": {}
181008            },
181009            "quantitativeAnalysis": {
181010              "graphics": {}
181011            },
181012            "considerations": {}
181013          }
181014        },
181015        {
181016          "type": "library",
181017          "bom-ref": "pkg:npm/agent-base@4.3.0?package-id=5ba0b4e2347e7c24",
181018          "supplier": {},
181019          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
181020          "name": "agent-base",
181021          "version": "4.3.0",
181022          "description": "Turn a function into an `http.Agent` instance",
181023          "licenses": [
181024            {
181025              "license": {
181026                "id": "MIT"
181027              }
181028            }
181029          ],
181030          "cpe": "cpe:2.3:a:TooTallNate:agent-base:4.3.0:*:*:*:*:*:*:*",
181031          "purl": "pkg:npm/agent-base@4.3.0",
181032          "swid": {
181033            "attachment": {}
181034          },
181035          "pedigree": {},
181036          "externalReferences": [
181037            {
181038              "url": "git://github.com/TooTallNate/node-agent-base.git",
181039              "type": "distribution"
181040            },
181041            {
181042              "url": "https://github.com/TooTallNate/node-agent-base#readme",
181043              "type": "website"
181044            }
181045          ],
181046          "evidence": {},
181047          "signature": {
181048            "signature": {
181049              "publicKey": {}
181050            }
181051          },
181052          "modelCard": {
181053            "modelParameters": {
181054              "approach": {}
181055            },
181056            "quantitativeAnalysis": {
181057              "graphics": {}
181058            },
181059            "considerations": {}
181060          }
181061        },
181062        {
181063          "type": "library",
181064          "bom-ref": "pkg:npm/agent-base@6.0.2?package-id=b1bf7cf127c6dcdf",
181065          "supplier": {},
181066          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
181067          "name": "agent-base",
181068          "version": "6.0.2",
181069          "description": "Turn a function into an `http.Agent` instance",
181070          "licenses": [
181071            {
181072              "license": {
181073                "id": "MIT"
181074              }
181075            }
181076          ],
181077          "cpe": "cpe:2.3:a:TooTallNate:agent-base:6.0.2:*:*:*:*:*:*:*",
181078          "purl": "pkg:npm/agent-base@6.0.2",
181079          "swid": {
181080            "attachment": {}
181081          },
181082          "pedigree": {},
181083          "externalReferences": [
181084            {
181085              "url": "git://github.com/TooTallNate/node-agent-base.git",
181086              "type": "distribution"
181087            },
181088            {
181089              "url": "https://github.com/TooTallNate/node-agent-base#readme",
181090              "type": "website"
181091            }
181092          ],
181093          "evidence": {},
181094          "signature": {
181095            "signature": {
181096              "publicKey": {}
181097            }
181098          },
181099          "modelCard": {
181100            "modelParameters": {
181101              "approach": {}
181102            },
181103            "quantitativeAnalysis": {
181104              "graphics": {}
181105            },
181106            "considerations": {}
181107          }
181108        },
181109        {
181110          "type": "library",
181111          "bom-ref": "pkg:npm/agentkeepalive@3.5.2?package-id=1b7d5bc0186ab4c",
181112          "supplier": {},
181113          "author": "fengmk2 \u003cfengmk2@gmail.com\u003e (https://fengmk2.com)",
181114          "name": "agentkeepalive",
181115          "version": "3.5.2",
181116          "description": "Missing keepalive http.Agent",
181117          "licenses": [
181118            {
181119              "license": {
181120                "id": "MIT"
181121              }
181122            }
181123          ],
181124          "cpe": "cpe:2.3:a:agentkeepalive:agentkeepalive:3.5.2:*:*:*:*:*:*:*",
181125          "purl": "pkg:npm/agentkeepalive@3.5.2",
181126          "swid": {
181127            "attachment": {}
181128          },
181129          "pedigree": {},
181130          "externalReferences": [
181131            {
181132              "url": "git://github.com/node-modules/agentkeepalive.git",
181133              "type": "distribution"
181134            },
181135            {
181136              "url": "https://github.com/node-modules/agentkeepalive#readme",
181137              "type": "website"
181138            }
181139          ],
181140          "evidence": {},
181141          "signature": {
181142            "signature": {
181143              "publicKey": {}
181144            }
181145          },
181146          "modelCard": {
181147            "modelParameters": {
181148              "approach": {}
181149            },
181150            "quantitativeAnalysis": {
181151              "graphics": {}
181152            },
181153            "considerations": {}
181154          }
181155        },
181156        {
181157          "type": "library",
181158          "bom-ref": "pkg:npm/ajv@6.12.6?package-id=d362ede6e3c68fc2",
181159          "supplier": {},
181160          "author": "Evgeny Poberezkin",
181161          "name": "ajv",
181162          "version": "6.12.6",
181163          "description": "Another JSON Schema Validator",
181164          "licenses": [
181165            {
181166              "license": {
181167                "id": "MIT"
181168              }
181169            }
181170          ],
181171          "cpe": "cpe:2.3:a:ajv-validator:ajv:6.12.6:*:*:*:*:*:*:*",
181172          "purl": "pkg:npm/ajv@6.12.6",
181173          "swid": {
181174            "attachment": {}
181175          },
181176          "pedigree": {},
181177          "externalReferences": [
181178            {
181179              "url": "git+https://github.com/ajv-validator/ajv.git",
181180              "type": "distribution"
181181            },
181182            {
181183              "url": "https://github.com/ajv-validator/ajv",
181184              "type": "website"
181185            }
181186          ],
181187          "evidence": {},
181188          "signature": {
181189            "signature": {
181190              "publicKey": {}
181191            }
181192          },
181193          "modelCard": {
181194            "modelParameters": {
181195              "approach": {}
181196            },
181197            "quantitativeAnalysis": {
181198              "graphics": {}
181199            },
181200            "considerations": {}
181201          }
181202        },
181203        {
181204          "type": "library",
181205          "bom-ref": "pkg:npm/ajv@8.11.2?package-id=1209ce04f62066",
181206          "supplier": {},
181207          "author": "Evgeny Poberezkin",
181208          "name": "ajv",
181209          "version": "8.11.2",
181210          "description": "Another JSON Schema Validator",
181211          "licenses": [
181212            {
181213              "license": {
181214                "id": "MIT"
181215              }
181216            }
181217          ],
181218          "cpe": "cpe:2.3:a:ajv:ajv:8.11.2:*:*:*:*:*:*:*",
181219          "purl": "pkg:npm/ajv@8.11.2",
181220          "swid": {
181221            "attachment": {}
181222          },
181223          "pedigree": {},
181224          "externalReferences": [
181225            {
181226              "url": "git+https://github.com/ajv-validator/ajv.git",
181227              "type": "distribution"
181228            },
181229            {
181230              "url": "https://ajv.js.org",
181231              "type": "website"
181232            }
181233          ],
181234          "evidence": {},
181235          "signature": {
181236            "signature": {
181237              "publicKey": {}
181238            }
181239          },
181240          "modelCard": {
181241            "modelParameters": {
181242              "approach": {}
181243            },
181244            "quantitativeAnalysis": {
181245              "graphics": {}
181246            },
181247            "considerations": {}
181248          }
181249        },
181250        {
181251          "type": "library",
181252          "bom-ref": "pkg:npm/ajv@8.11.2?package-id=21ec2c8474075145",
181253          "supplier": {},
181254          "author": "Evgeny Poberezkin",
181255          "name": "ajv",
181256          "version": "8.11.2",
181257          "description": "Another JSON Schema Validator",
181258          "licenses": [
181259            {
181260              "license": {
181261                "id": "MIT"
181262              }
181263            }
181264          ],
181265          "cpe": "cpe:2.3:a:ajv:ajv:8.11.2:*:*:*:*:*:*:*",
181266          "purl": "pkg:npm/ajv@8.11.2",
181267          "swid": {
181268            "attachment": {}
181269          },
181270          "pedigree": {},
181271          "externalReferences": [
181272            {
181273              "url": "git+https://github.com/ajv-validator/ajv.git",
181274              "type": "distribution"
181275            },
181276            {
181277              "url": "https://ajv.js.org",
181278              "type": "website"
181279            }
181280          ],
181281          "evidence": {},
181282          "signature": {
181283            "signature": {
181284              "publicKey": {}
181285            }
181286          },
181287          "modelCard": {
181288            "modelParameters": {
181289              "approach": {}
181290            },
181291            "quantitativeAnalysis": {
181292              "graphics": {}
181293            },
181294            "considerations": {}
181295          }
181296        },
181297        {
181298          "type": "library",
181299          "bom-ref": "pkg:npm/ajv-formats@2.1.1?package-id=e2512f1bfeb8344c",
181300          "supplier": {},
181301          "author": "Evgeny Poberezkin",
181302          "name": "ajv-formats",
181303          "version": "2.1.1",
181304          "description": "Format validation for Ajv v7+",
181305          "licenses": [
181306            {
181307              "license": {
181308                "id": "MIT"
181309              }
181310            }
181311          ],
181312          "cpe": "cpe:2.3:a:ajv-validator:ajv-formats:2.1.1:*:*:*:*:*:*:*",
181313          "purl": "pkg:npm/ajv-formats@2.1.1",
181314          "swid": {
181315            "attachment": {}
181316          },
181317          "pedigree": {},
181318          "externalReferences": [
181319            {
181320              "url": "git+https://github.com/ajv-validator/ajv-formats.git",
181321              "type": "distribution"
181322            },
181323            {
181324              "url": "https://github.com/ajv-validator/ajv-formats#readme",
181325              "type": "website"
181326            }
181327          ],
181328          "evidence": {},
181329          "signature": {
181330            "signature": {
181331              "publicKey": {}
181332            }
181333          },
181334          "modelCard": {
181335            "modelParameters": {
181336              "approach": {}
181337            },
181338            "quantitativeAnalysis": {
181339              "graphics": {}
181340            },
181341            "considerations": {}
181342          }
181343        },
181344        {
181345          "type": "library",
181346          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.1\u0026package-id=92b19c7750fb559d",
181347          "supplier": {},
181348          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
181349          "name": "alpine-baselayout",
181350          "version": "3.4.0-r0",
181351          "description": "Alpine base dir structure and init scripts",
181352          "licenses": [
181353            {
181354              "license": {
181355                "id": "GPL-2.0-only"
181356              }
181357            }
181358          ],
181359          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.4.0-r0:*:*:*:*:*:*:*",
181360          "purl": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.1",
181361          "swid": {
181362            "attachment": {}
181363          },
181364          "pedigree": {},
181365          "externalReferences": [
181366            {
181367              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
181368              "type": "distribution"
181369            }
181370          ],
181371          "evidence": {},
181372          "signature": {
181373            "signature": {
181374              "publicKey": {}
181375            }
181376          },
181377          "modelCard": {
181378            "modelParameters": {
181379              "approach": {}
181380            },
181381            "quantitativeAnalysis": {
181382              "graphics": {}
181383            },
181384            "considerations": {}
181385          }
181386        },
181387        {
181388          "type": "library",
181389          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.1\u0026package-id=291d1267b40d636f",
181390          "supplier": {},
181391          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
181392          "name": "alpine-baselayout-data",
181393          "version": "3.4.0-r0",
181394          "description": "Alpine base dir structure and init scripts",
181395          "licenses": [
181396            {
181397              "license": {
181398                "id": "GPL-2.0-only"
181399              }
181400            }
181401          ],
181402          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.4.0-r0:*:*:*:*:*:*:*",
181403          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.1",
181404          "swid": {
181405            "attachment": {}
181406          },
181407          "pedigree": {},
181408          "externalReferences": [
181409            {
181410              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
181411              "type": "distribution"
181412            }
181413          ],
181414          "evidence": {},
181415          "signature": {
181416            "signature": {
181417              "publicKey": {}
181418            }
181419          },
181420          "modelCard": {
181421            "modelParameters": {
181422              "approach": {}
181423            },
181424            "quantitativeAnalysis": {
181425              "graphics": {}
181426            },
181427            "considerations": {}
181428          }
181429        },
181430        {
181431          "type": "library",
181432          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.1\u0026package-id=2b5e23d349b556cf",
181433          "supplier": {},
181434          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
181435          "name": "alpine-keys",
181436          "version": "2.4-r1",
181437          "description": "Public keys for Alpine Linux packages",
181438          "licenses": [
181439            {
181440              "license": {
181441                "id": "MIT"
181442              }
181443            }
181444          ],
181445          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
181446          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.1",
181447          "swid": {
181448            "attachment": {}
181449          },
181450          "pedigree": {},
181451          "externalReferences": [
181452            {
181453              "url": "https://alpinelinux.org",
181454              "type": "distribution"
181455            }
181456          ],
181457          "evidence": {},
181458          "signature": {
181459            "signature": {
181460              "publicKey": {}
181461            }
181462          },
181463          "modelCard": {
181464            "modelParameters": {
181465              "approach": {}
181466            },
181467            "quantitativeAnalysis": {
181468              "graphics": {}
181469            },
181470            "considerations": {}
181471          }
181472        },
181473        {
181474          "type": "library",
181475          "bom-ref": "pkg:npm/ansi-align@2.0.0?package-id=d1d8dd5f88203c8",
181476          "supplier": {},
181477          "author": "nexdrew",
181478          "name": "ansi-align",
181479          "version": "2.0.0",
181480          "description": "align-text with ANSI support for CLIs",
181481          "licenses": [
181482            {
181483              "license": {
181484                "id": "ISC"
181485              }
181486            }
181487          ],
181488          "cpe": "cpe:2.3:a:ansi-align:ansi-align:2.0.0:*:*:*:*:*:*:*",
181489          "purl": "pkg:npm/ansi-align@2.0.0",
181490          "swid": {
181491            "attachment": {}
181492          },
181493          "pedigree": {},
181494          "externalReferences": [
181495            {
181496              "url": "git+https://github.com/nexdrew/ansi-align.git",
181497              "type": "distribution"
181498            },
181499            {
181500              "url": "https://github.com/nexdrew/ansi-align#readme",
181501              "type": "website"
181502            }
181503          ],
181504          "evidence": {},
181505          "signature": {
181506            "signature": {
181507              "publicKey": {}
181508            }
181509          },
181510          "modelCard": {
181511            "modelParameters": {
181512              "approach": {}
181513            },
181514            "quantitativeAnalysis": {
181515              "graphics": {}
181516            },
181517            "considerations": {}
181518          }
181519        },
181520        {
181521          "type": "library",
181522          "bom-ref": "pkg:npm/ansi-regex@2.1.1?package-id=b7526b5cc6e97d15",
181523          "supplier": {},
181524          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
181525          "name": "ansi-regex",
181526          "version": "2.1.1",
181527          "description": "Regular expression for matching ANSI escape codes",
181528          "licenses": [
181529            {
181530              "license": {
181531                "id": "MIT"
181532              }
181533            }
181534          ],
181535          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:2.1.1:*:*:*:*:*:*:*",
181536          "purl": "pkg:npm/ansi-regex@2.1.1",
181537          "swid": {
181538            "attachment": {}
181539          },
181540          "pedigree": {},
181541          "externalReferences": [
181542            {
181543              "url": "git+https://github.com/chalk/ansi-regex.git",
181544              "type": "distribution"
181545            },
181546            {
181547              "url": "https://github.com/chalk/ansi-regex#readme",
181548              "type": "website"
181549            }
181550          ],
181551          "evidence": {},
181552          "signature": {
181553            "signature": {
181554              "publicKey": {}
181555            }
181556          },
181557          "modelCard": {
181558            "modelParameters": {
181559              "approach": {}
181560            },
181561            "quantitativeAnalysis": {
181562              "graphics": {}
181563            },
181564            "considerations": {}
181565          }
181566        },
181567        {
181568          "type": "library",
181569          "bom-ref": "pkg:npm/ansi-regex@3.0.0?package-id=f6bd6cc6b4b0fe11",
181570          "supplier": {},
181571          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
181572          "name": "ansi-regex",
181573          "version": "3.0.0",
181574          "description": "Regular expression for matching ANSI escape codes",
181575          "licenses": [
181576            {
181577              "license": {
181578                "id": "MIT"
181579              }
181580            }
181581          ],
181582          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:3.0.0:*:*:*:*:*:*:*",
181583          "purl": "pkg:npm/ansi-regex@3.0.0",
181584          "swid": {
181585            "attachment": {}
181586          },
181587          "pedigree": {},
181588          "externalReferences": [
181589            {
181590              "url": "git+https://github.com/chalk/ansi-regex.git",
181591              "type": "distribution"
181592            },
181593            {
181594              "url": "https://github.com/chalk/ansi-regex#readme",
181595              "type": "website"
181596            }
181597          ],
181598          "evidence": {},
181599          "signature": {
181600            "signature": {
181601              "publicKey": {}
181602            }
181603          },
181604          "modelCard": {
181605            "modelParameters": {
181606              "approach": {}
181607            },
181608            "quantitativeAnalysis": {
181609              "graphics": {}
181610            },
181611            "considerations": {}
181612          }
181613        },
181614        {
181615          "type": "library",
181616          "bom-ref": "pkg:npm/ansi-regex@4.1.0?package-id=1898e7de5ccb0b04",
181617          "supplier": {},
181618          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
181619          "name": "ansi-regex",
181620          "version": "4.1.0",
181621          "description": "Regular expression for matching ANSI escape codes",
181622          "licenses": [
181623            {
181624              "license": {
181625                "id": "MIT"
181626              }
181627            }
181628          ],
181629          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.0:*:*:*:*:*:*:*",
181630          "purl": "pkg:npm/ansi-regex@4.1.0",
181631          "swid": {
181632            "attachment": {}
181633          },
181634          "pedigree": {},
181635          "externalReferences": [
181636            {
181637              "url": "git+https://github.com/chalk/ansi-regex.git",
181638              "type": "distribution"
181639            },
181640            {
181641              "url": "https://github.com/chalk/ansi-regex#readme",
181642              "type": "website"
181643            }
181644          ],
181645          "evidence": {},
181646          "signature": {
181647            "signature": {
181648              "publicKey": {}
181649            }
181650          },
181651          "modelCard": {
181652            "modelParameters": {
181653              "approach": {}
181654            },
181655            "quantitativeAnalysis": {
181656              "graphics": {}
181657            },
181658            "considerations": {}
181659          }
181660        },
181661        {
181662          "type": "library",
181663          "bom-ref": "pkg:npm/ansi-regex@4.1.1?package-id=5d5c8bf716d3dada",
181664          "supplier": {},
181665          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
181666          "name": "ansi-regex",
181667          "version": "4.1.1",
181668          "description": "Regular expression for matching ANSI escape codes",
181669          "licenses": [
181670            {
181671              "license": {
181672                "id": "MIT"
181673              }
181674            }
181675          ],
181676          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.1:*:*:*:*:*:*:*",
181677          "purl": "pkg:npm/ansi-regex@4.1.1",
181678          "swid": {
181679            "attachment": {}
181680          },
181681          "pedigree": {},
181682          "externalReferences": [
181683            {
181684              "url": "git+https://github.com/chalk/ansi-regex.git",
181685              "type": "distribution"
181686            },
181687            {
181688              "url": "https://github.com/chalk/ansi-regex#readme",
181689              "type": "website"
181690            }
181691          ],
181692          "evidence": {},
181693          "signature": {
181694            "signature": {
181695              "publicKey": {}
181696            }
181697          },
181698          "modelCard": {
181699            "modelParameters": {
181700              "approach": {}
181701            },
181702            "quantitativeAnalysis": {
181703              "graphics": {}
181704            },
181705            "considerations": {}
181706          }
181707        },
181708        {
181709          "type": "library",
181710          "bom-ref": "pkg:npm/ansi-regex@4.1.1?package-id=4c2cae6839d80ac9",
181711          "supplier": {},
181712          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
181713          "name": "ansi-regex",
181714          "version": "4.1.1",
181715          "description": "Regular expression for matching ANSI escape codes",
181716          "licenses": [
181717            {
181718              "license": {
181719                "id": "MIT"
181720              }
181721            }
181722          ],
181723          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.1:*:*:*:*:*:*:*",
181724          "purl": "pkg:npm/ansi-regex@4.1.1",
181725          "swid": {
181726            "attachment": {}
181727          },
181728          "pedigree": {},
181729          "externalReferences": [
181730            {
181731              "url": "git+https://github.com/chalk/ansi-regex.git",
181732              "type": "distribution"
181733            },
181734            {
181735              "url": "https://github.com/chalk/ansi-regex#readme",
181736              "type": "website"
181737            }
181738          ],
181739          "evidence": {},
181740          "signature": {
181741            "signature": {
181742              "publicKey": {}
181743            }
181744          },
181745          "modelCard": {
181746            "modelParameters": {
181747              "approach": {}
181748            },
181749            "quantitativeAnalysis": {
181750              "graphics": {}
181751            },
181752            "considerations": {}
181753          }
181754        },
181755        {
181756          "type": "library",
181757          "bom-ref": "pkg:npm/ansi-styles@3.2.1?package-id=822983e67603ef84",
181758          "supplier": {},
181759          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
181760          "name": "ansi-styles",
181761          "version": "3.2.1",
181762          "description": "ANSI escape codes for styling strings in the terminal",
181763          "licenses": [
181764            {
181765              "license": {
181766                "id": "MIT"
181767              }
181768            }
181769          ],
181770          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:3.2.1:*:*:*:*:*:*:*",
181771          "purl": "pkg:npm/ansi-styles@3.2.1",
181772          "swid": {
181773            "attachment": {}
181774          },
181775          "pedigree": {},
181776          "externalReferences": [
181777            {
181778              "url": "git+https://github.com/chalk/ansi-styles.git",
181779              "type": "distribution"
181780            },
181781            {
181782              "url": "https://github.com/chalk/ansi-styles#readme",
181783              "type": "website"
181784            }
181785          ],
181786          "evidence": {},
181787          "signature": {
181788            "signature": {
181789              "publicKey": {}
181790            }
181791          },
181792          "modelCard": {
181793            "modelParameters": {
181794              "approach": {}
181795            },
181796            "quantitativeAnalysis": {
181797              "graphics": {}
181798            },
181799            "considerations": {}
181800          }
181801        },
181802        {
181803          "type": "library",
181804          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=45c620984a9fcd36",
181805          "supplier": {},
181806          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
181807          "name": "ansi-styles",
181808          "version": "4.3.0",
181809          "description": "ANSI escape codes for styling strings in the terminal",
181810          "licenses": [
181811            {
181812              "license": {
181813                "id": "MIT"
181814              }
181815            }
181816          ],
181817          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
181818          "purl": "pkg:npm/ansi-styles@4.3.0",
181819          "swid": {
181820            "attachment": {}
181821          },
181822          "pedigree": {},
181823          "externalReferences": [
181824            {
181825              "url": "git+https://github.com/chalk/ansi-styles.git",
181826              "type": "distribution"
181827            },
181828            {
181829              "url": "https://github.com/chalk/ansi-styles#readme",
181830              "type": "website"
181831            }
181832          ],
181833          "evidence": {},
181834          "signature": {
181835            "signature": {
181836              "publicKey": {}
181837            }
181838          },
181839          "modelCard": {
181840            "modelParameters": {
181841              "approach": {}
181842            },
181843            "quantitativeAnalysis": {
181844              "graphics": {}
181845            },
181846            "considerations": {}
181847          }
181848        },
181849        {
181850          "type": "library",
181851          "bom-ref": "pkg:npm/ansicolors@0.3.2?package-id=b232b7afe5d99ae2",
181852          "supplier": {},
181853          "author": "Thorsten Lorenz \u003cthlorenz@gmx.de\u003e (thlorenz.com)",
181854          "name": "ansicolors",
181855          "version": "0.3.2",
181856          "description": "Functions that surround a string with ansicolor codes so it prints in color.",
181857          "licenses": [
181858            {
181859              "license": {
181860                "id": "MIT"
181861              }
181862            }
181863          ],
181864          "cpe": "cpe:2.3:a:ansicolors:ansicolors:0.3.2:*:*:*:*:*:*:*",
181865          "purl": "pkg:npm/ansicolors@0.3.2",
181866          "swid": {
181867            "attachment": {}
181868          },
181869          "pedigree": {},
181870          "externalReferences": [
181871            {
181872              "url": "git://github.com/thlorenz/ansicolors.git",
181873              "type": "distribution"
181874            },
181875            {
181876              "url": "https://github.com/thlorenz/ansicolors#readme",
181877              "type": "website"
181878            }
181879          ],
181880          "evidence": {},
181881          "signature": {
181882            "signature": {
181883              "publicKey": {}
181884            }
181885          },
181886          "modelCard": {
181887            "modelParameters": {
181888              "approach": {}
181889            },
181890            "quantitativeAnalysis": {
181891              "graphics": {}
181892            },
181893            "considerations": {}
181894          }
181895        },
181896        {
181897          "type": "library",
181898          "bom-ref": "pkg:npm/ansistyles@0.1.3?package-id=3ab660f779efda37",
181899          "supplier": {},
181900          "author": "Thorsten Lorenz \u003cthlorenz@gmx.de\u003e (thlorenz.com)",
181901          "name": "ansistyles",
181902          "version": "0.1.3",
181903          "description": "Functions that surround a string with ansistyle codes so it prints in style.",
181904          "licenses": [
181905            {
181906              "license": {
181907                "id": "MIT"
181908              }
181909            }
181910          ],
181911          "cpe": "cpe:2.3:a:ansistyles:ansistyles:0.1.3:*:*:*:*:*:*:*",
181912          "purl": "pkg:npm/ansistyles@0.1.3",
181913          "swid": {
181914            "attachment": {}
181915          },
181916          "pedigree": {},
181917          "externalReferences": [
181918            {
181919              "url": "git://github.com/thlorenz/ansistyles.git",
181920              "type": "distribution"
181921            },
181922            {
181923              "url": "https://github.com/thlorenz/ansistyles#readme",
181924              "type": "website"
181925            }
181926          ],
181927          "evidence": {},
181928          "signature": {
181929            "signature": {
181930              "publicKey": {}
181931            }
181932          },
181933          "modelCard": {
181934            "modelParameters": {
181935              "approach": {}
181936            },
181937            "quantitativeAnalysis": {
181938              "graphics": {}
181939            },
181940            "considerations": {}
181941          }
181942        },
181943        {
181944          "type": "library",
181945          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.1\u0026package-id=e5f757b0df1f62bc",
181946          "supplier": {},
181947          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
181948          "name": "apk-tools",
181949          "version": "2.12.10-r1",
181950          "description": "Alpine Package Keeper - package manager for alpine",
181951          "licenses": [
181952            {
181953              "license": {
181954                "id": "GPL-2.0-only"
181955              }
181956            }
181957          ],
181958          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.10-r1:*:*:*:*:*:*:*",
181959          "purl": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.1",
181960          "swid": {
181961            "attachment": {}
181962          },
181963          "pedigree": {},
181964          "externalReferences": [
181965            {
181966              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
181967              "type": "distribution"
181968            }
181969          ],
181970          "evidence": {},
181971          "signature": {
181972            "signature": {
181973              "publicKey": {}
181974            }
181975          },
181976          "modelCard": {
181977            "modelParameters": {
181978              "approach": {}
181979            },
181980            "quantitativeAnalysis": {
181981              "graphics": {}
181982            },
181983            "considerations": {}
181984          }
181985        },
181986        {
181987          "type": "library",
181988          "bom-ref": "pkg:npm/append-field@1.0.0?package-id=b4d8c83b22bdf90a",
181989          "supplier": {},
181990          "author": "Linus Unnebäck \u003clinus@folkdatorn.se\u003e",
181991          "name": "append-field",
181992          "version": "1.0.0",
181993          "description": "A [W3C HTML JSON forms spec](http://www.w3.org/TR/html-json-forms/) compliant field appender (for lack of a better name). Useful for people implementing `application/x-www-form-urlencoded` and `multipart/form-data` parsers.",
181994          "licenses": [
181995            {
181996              "license": {
181997                "id": "MIT"
181998              }
181999            }
182000          ],
182001          "cpe": "cpe:2.3:a:append-field:append-field:1.0.0:*:*:*:*:*:*:*",
182002          "purl": "pkg:npm/append-field@1.0.0",
182003          "swid": {
182004            "attachment": {}
182005          },
182006          "pedigree": {},
182007          "externalReferences": [
182008            {
182009              "url": "git+ssh://git@github.com/LinusU/node-append-field.git",
182010              "type": "distribution"
182011            },
182012            {
182013              "url": "https://github.com/LinusU/node-append-field#readme",
182014              "type": "website"
182015            }
182016          ],
182017          "evidence": {},
182018          "signature": {
182019            "signature": {
182020              "publicKey": {}
182021            }
182022          },
182023          "modelCard": {
182024            "modelParameters": {
182025              "approach": {}
182026            },
182027            "quantitativeAnalysis": {
182028              "graphics": {}
182029            },
182030            "considerations": {}
182031          }
182032        },
182033        {
182034          "type": "library",
182035          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=46ad585877d1bee7",
182036          "supplier": {},
182037          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
182038          "name": "aproba",
182039          "version": "1.2.0",
182040          "description": "A ridiculously light-weight argument validator (now browser friendly)",
182041          "licenses": [
182042            {
182043              "license": {
182044                "id": "ISC"
182045              }
182046            }
182047          ],
182048          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
182049          "purl": "pkg:npm/aproba@1.2.0",
182050          "swid": {
182051            "attachment": {}
182052          },
182053          "pedigree": {},
182054          "externalReferences": [
182055            {
182056              "url": "git+https://github.com/iarna/aproba.git",
182057              "type": "distribution"
182058            },
182059            {
182060              "url": "https://github.com/iarna/aproba",
182061              "type": "website"
182062            }
182063          ],
182064          "evidence": {},
182065          "signature": {
182066            "signature": {
182067              "publicKey": {}
182068            }
182069          },
182070          "modelCard": {
182071            "modelParameters": {
182072              "approach": {}
182073            },
182074            "quantitativeAnalysis": {
182075              "graphics": {}
182076            },
182077            "considerations": {}
182078          }
182079        },
182080        {
182081          "type": "library",
182082          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=9379102f72715cd",
182083          "supplier": {},
182084          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
182085          "name": "aproba",
182086          "version": "1.2.0",
182087          "description": "A ridiculously light-weight argument validator (now browser friendly)",
182088          "licenses": [
182089            {
182090              "license": {
182091                "id": "ISC"
182092              }
182093            }
182094          ],
182095          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
182096          "purl": "pkg:npm/aproba@1.2.0",
182097          "swid": {
182098            "attachment": {}
182099          },
182100          "pedigree": {},
182101          "externalReferences": [
182102            {
182103              "url": "git+https://github.com/iarna/aproba.git",
182104              "type": "distribution"
182105            },
182106            {
182107              "url": "https://github.com/iarna/aproba",
182108              "type": "website"
182109            }
182110          ],
182111          "evidence": {},
182112          "signature": {
182113            "signature": {
182114              "publicKey": {}
182115            }
182116          },
182117          "modelCard": {
182118            "modelParameters": {
182119              "approach": {}
182120            },
182121            "quantitativeAnalysis": {
182122              "graphics": {}
182123            },
182124            "considerations": {}
182125          }
182126        },
182127        {
182128          "type": "library",
182129          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=b0b533a70d15e523",
182130          "supplier": {},
182131          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
182132          "name": "aproba",
182133          "version": "1.2.0",
182134          "description": "A ridiculously light-weight argument validator (now browser friendly)",
182135          "licenses": [
182136            {
182137              "license": {
182138                "id": "ISC"
182139              }
182140            }
182141          ],
182142          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
182143          "purl": "pkg:npm/aproba@1.2.0",
182144          "swid": {
182145            "attachment": {}
182146          },
182147          "pedigree": {},
182148          "externalReferences": [
182149            {
182150              "url": "git+https://github.com/iarna/aproba.git",
182151              "type": "distribution"
182152            },
182153            {
182154              "url": "https://github.com/iarna/aproba",
182155              "type": "website"
182156            }
182157          ],
182158          "evidence": {},
182159          "signature": {
182160            "signature": {
182161              "publicKey": {}
182162            }
182163          },
182164          "modelCard": {
182165            "modelParameters": {
182166              "approach": {}
182167            },
182168            "quantitativeAnalysis": {
182169              "graphics": {}
182170            },
182171            "considerations": {}
182172          }
182173        },
182174        {
182175          "type": "library",
182176          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=79645860424278c4",
182177          "supplier": {},
182178          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
182179          "name": "aproba",
182180          "version": "1.2.0",
182181          "description": "A ridiculously light-weight argument validator (now browser friendly)",
182182          "licenses": [
182183            {
182184              "license": {
182185                "id": "ISC"
182186              }
182187            }
182188          ],
182189          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
182190          "purl": "pkg:npm/aproba@1.2.0",
182191          "swid": {
182192            "attachment": {}
182193          },
182194          "pedigree": {},
182195          "externalReferences": [
182196            {
182197              "url": "git+https://github.com/iarna/aproba.git",
182198              "type": "distribution"
182199            },
182200            {
182201              "url": "https://github.com/iarna/aproba",
182202              "type": "website"
182203            }
182204          ],
182205          "evidence": {},
182206          "signature": {
182207            "signature": {
182208              "publicKey": {}
182209            }
182210          },
182211          "modelCard": {
182212            "modelParameters": {
182213              "approach": {}
182214            },
182215            "quantitativeAnalysis": {
182216              "graphics": {}
182217            },
182218            "considerations": {}
182219          }
182220        },
182221        {
182222          "type": "library",
182223          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=811071cd19319711",
182224          "supplier": {},
182225          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
182226          "name": "aproba",
182227          "version": "1.2.0",
182228          "description": "A ridiculously light-weight argument validator (now browser friendly)",
182229          "licenses": [
182230            {
182231              "license": {
182232                "id": "ISC"
182233              }
182234            }
182235          ],
182236          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
182237          "purl": "pkg:npm/aproba@1.2.0",
182238          "swid": {
182239            "attachment": {}
182240          },
182241          "pedigree": {},
182242          "externalReferences": [
182243            {
182244              "url": "git+https://github.com/iarna/aproba.git",
182245              "type": "distribution"
182246            },
182247            {
182248              "url": "https://github.com/iarna/aproba",
182249              "type": "website"
182250            }
182251          ],
182252          "evidence": {},
182253          "signature": {
182254            "signature": {
182255              "publicKey": {}
182256            }
182257          },
182258          "modelCard": {
182259            "modelParameters": {
182260              "approach": {}
182261            },
182262            "quantitativeAnalysis": {
182263              "graphics": {}
182264            },
182265            "considerations": {}
182266          }
182267        },
182268        {
182269          "type": "library",
182270          "bom-ref": "pkg:npm/aproba@2.0.0?package-id=1375db1ef28ee546",
182271          "supplier": {},
182272          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
182273          "name": "aproba",
182274          "version": "2.0.0",
182275          "description": "A ridiculously light-weight argument validator (now browser friendly)",
182276          "licenses": [
182277            {
182278              "license": {
182279                "id": "ISC"
182280              }
182281            }
182282          ],
182283          "cpe": "cpe:2.3:a:aproba:aproba:2.0.0:*:*:*:*:*:*:*",
182284          "purl": "pkg:npm/aproba@2.0.0",
182285          "swid": {
182286            "attachment": {}
182287          },
182288          "pedigree": {},
182289          "externalReferences": [
182290            {
182291              "url": "git+https://github.com/iarna/aproba.git",
182292              "type": "distribution"
182293            },
182294            {
182295              "url": "https://github.com/iarna/aproba",
182296              "type": "website"
182297            }
182298          ],
182299          "evidence": {},
182300          "signature": {
182301            "signature": {
182302              "publicKey": {}
182303            }
182304          },
182305          "modelCard": {
182306            "modelParameters": {
182307              "approach": {}
182308            },
182309            "quantitativeAnalysis": {
182310              "graphics": {}
182311            },
182312            "considerations": {}
182313          }
182314        },
182315        {
182316          "type": "library",
182317          "bom-ref": "pkg:npm/archy@1.0.0?package-id=b81fc5a638c3732d",
182318          "supplier": {},
182319          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
182320          "name": "archy",
182321          "version": "1.0.0",
182322          "description": "render nested hierarchies `npm ls` style with unicode pipes",
182323          "licenses": [
182324            {
182325              "license": {
182326                "id": "MIT"
182327              }
182328            }
182329          ],
182330          "cpe": "cpe:2.3:a:substack:archy:1.0.0:*:*:*:*:*:*:*",
182331          "purl": "pkg:npm/archy@1.0.0",
182332          "swid": {
182333            "attachment": {}
182334          },
182335          "pedigree": {},
182336          "externalReferences": [
182337            {
182338              "url": "git+ssh://git@github.com/substack/node-archy.git",
182339              "type": "distribution"
182340            },
182341            {
182342              "url": "https://github.com/substack/node-archy#readme",
182343              "type": "website"
182344            }
182345          ],
182346          "evidence": {},
182347          "signature": {
182348            "signature": {
182349              "publicKey": {}
182350            }
182351          },
182352          "modelCard": {
182353            "modelParameters": {
182354              "approach": {}
182355            },
182356            "quantitativeAnalysis": {
182357              "graphics": {}
182358            },
182359            "considerations": {}
182360          }
182361        },
182362        {
182363          "type": "library",
182364          "bom-ref": "pkg:npm/are-we-there-yet@1.1.4?package-id=13183467f0c1f82b",
182365          "supplier": {},
182366          "author": "Rebecca Turner (http://re-becca.org)",
182367          "name": "are-we-there-yet",
182368          "version": "1.1.4",
182369          "description": "Keep track of the overall completion of many disparate processes",
182370          "licenses": [
182371            {
182372              "license": {
182373                "id": "ISC"
182374              }
182375            }
182376          ],
182377          "cpe": "cpe:2.3:a:are-we-there-yet:are-we-there-yet:1.1.4:*:*:*:*:*:*:*",
182378          "purl": "pkg:npm/are-we-there-yet@1.1.4",
182379          "swid": {
182380            "attachment": {}
182381          },
182382          "pedigree": {},
182383          "externalReferences": [
182384            {
182385              "url": "git+https://github.com/iarna/are-we-there-yet.git",
182386              "type": "distribution"
182387            },
182388            {
182389              "url": "https://github.com/iarna/are-we-there-yet",
182390              "type": "website"
182391            }
182392          ],
182393          "evidence": {},
182394          "signature": {
182395            "signature": {
182396              "publicKey": {}
182397            }
182398          },
182399          "modelCard": {
182400            "modelParameters": {
182401              "approach": {}
182402            },
182403            "quantitativeAnalysis": {
182404              "graphics": {}
182405            },
182406            "considerations": {}
182407          }
182408        },
182409        {
182410          "type": "library",
182411          "bom-ref": "pkg:npm/argparse@1.0.10?package-id=100e667c428dea85",
182412          "supplier": {},
182413          "name": "argparse",
182414          "version": "1.0.10",
182415          "description": "Very powerful CLI arguments parser. Native port of argparse - python's options parsing library",
182416          "licenses": [
182417            {
182418              "license": {
182419                "id": "MIT"
182420              }
182421            }
182422          ],
182423          "cpe": "cpe:2.3:a:argparse:argparse:1.0.10:*:*:*:*:*:*:*",
182424          "purl": "pkg:npm/argparse@1.0.10",
182425          "swid": {
182426            "attachment": {}
182427          },
182428          "pedigree": {},
182429          "externalReferences": [
182430            {
182431              "url": "git+https://github.com/nodeca/argparse.git",
182432              "type": "distribution"
182433            },
182434            {
182435              "url": "https://github.com/nodeca/argparse#readme",
182436              "type": "website"
182437            }
182438          ],
182439          "evidence": {},
182440          "signature": {
182441            "signature": {
182442              "publicKey": {}
182443            }
182444          },
182445          "modelCard": {
182446            "modelParameters": {
182447              "approach": {}
182448            },
182449            "quantitativeAnalysis": {
182450              "graphics": {}
182451            },
182452            "considerations": {}
182453          }
182454        },
182455        {
182456          "type": "library",
182457          "bom-ref": "pkg:npm/array-flatten@1.1.1?package-id=a0792ccdcca020ca",
182458          "supplier": {},
182459          "author": "Blake Embrey \u003chello@blakeembrey.com\u003e (http://blakeembrey.me)",
182460          "name": "array-flatten",
182461          "version": "1.1.1",
182462          "description": "Flatten an array of nested arrays into a single flat array",
182463          "licenses": [
182464            {
182465              "license": {
182466                "id": "MIT"
182467              }
182468            }
182469          ],
182470          "cpe": "cpe:2.3:a:array-flatten:array-flatten:1.1.1:*:*:*:*:*:*:*",
182471          "purl": "pkg:npm/array-flatten@1.1.1",
182472          "swid": {
182473            "attachment": {}
182474          },
182475          "pedigree": {},
182476          "externalReferences": [
182477            {
182478              "url": "git://github.com/blakeembrey/array-flatten.git",
182479              "type": "distribution"
182480            },
182481            {
182482              "url": "https://github.com/blakeembrey/array-flatten",
182483              "type": "website"
182484            }
182485          ],
182486          "evidence": {},
182487          "signature": {
182488            "signature": {
182489              "publicKey": {}
182490            }
182491          },
182492          "modelCard": {
182493            "modelParameters": {
182494              "approach": {}
182495            },
182496            "quantitativeAnalysis": {
182497              "graphics": {}
182498            },
182499            "considerations": {}
182500          }
182501        },
182502        {
182503          "type": "library",
182504          "bom-ref": "pkg:npm/asap@2.0.6?package-id=56ea014550752625",
182505          "supplier": {},
182506          "name": "asap",
182507          "version": "2.0.6",
182508          "description": "High-priority task queue for Node.js and browsers",
182509          "licenses": [
182510            {
182511              "license": {
182512                "id": "MIT"
182513              }
182514            }
182515          ],
182516          "cpe": "cpe:2.3:a:kriskowal:asap:2.0.6:*:*:*:*:*:*:*",
182517          "purl": "pkg:npm/asap@2.0.6",
182518          "swid": {
182519            "attachment": {}
182520          },
182521          "pedigree": {},
182522          "externalReferences": [
182523            {
182524              "url": "git+https://github.com/kriskowal/asap.git",
182525              "type": "distribution"
182526            },
182527            {
182528              "url": "https://github.com/kriskowal/asap#readme",
182529              "type": "website"
182530            }
182531          ],
182532          "evidence": {},
182533          "signature": {
182534            "signature": {
182535              "publicKey": {}
182536            }
182537          },
182538          "modelCard": {
182539            "modelParameters": {
182540              "approach": {}
182541            },
182542            "quantitativeAnalysis": {
182543              "graphics": {}
182544            },
182545            "considerations": {}
182546          }
182547        },
182548        {
182549          "type": "library",
182550          "bom-ref": "pkg:npm/asn1@0.2.4?package-id=12c39bfa53d7d26f",
182551          "supplier": {},
182552          "author": "Joyent (joyent.com)",
182553          "name": "asn1",
182554          "version": "0.2.4",
182555          "description": "Contains parsers and serializers for ASN.1 (currently BER only)",
182556          "licenses": [
182557            {
182558              "license": {
182559                "id": "MIT"
182560              }
182561            }
182562          ],
182563          "cpe": "cpe:2.3:a:joyent:asn1:0.2.4:*:*:*:*:*:*:*",
182564          "purl": "pkg:npm/asn1@0.2.4",
182565          "swid": {
182566            "attachment": {}
182567          },
182568          "pedigree": {},
182569          "externalReferences": [
182570            {
182571              "url": "git://github.com/joyent/node-asn1.git",
182572              "type": "distribution"
182573            },
182574            {
182575              "url": "https://github.com/joyent/node-asn1#readme",
182576              "type": "website"
182577            }
182578          ],
182579          "evidence": {},
182580          "signature": {
182581            "signature": {
182582              "publicKey": {}
182583            }
182584          },
182585          "modelCard": {
182586            "modelParameters": {
182587              "approach": {}
182588            },
182589            "quantitativeAnalysis": {
182590              "graphics": {}
182591            },
182592            "considerations": {}
182593          }
182594        },
182595        {
182596          "type": "library",
182597          "bom-ref": "pkg:npm/assert-plus@1.0.0?package-id=7b7c9640aad220f0",
182598          "supplier": {},
182599          "author": "Mark Cavage \u003cmcavage@gmail.com\u003e",
182600          "name": "assert-plus",
182601          "version": "1.0.0",
182602          "description": "Extra assertions on top of node's assert module",
182603          "licenses": [
182604            {
182605              "license": {
182606                "id": "MIT"
182607              }
182608            }
182609          ],
182610          "cpe": "cpe:2.3:a:assert-plus:assert-plus:1.0.0:*:*:*:*:*:*:*",
182611          "purl": "pkg:npm/assert-plus@1.0.0",
182612          "swid": {
182613            "attachment": {}
182614          },
182615          "pedigree": {},
182616          "externalReferences": [
182617            {
182618              "url": "git+https://github.com/mcavage/node-assert-plus.git",
182619              "type": "distribution"
182620            },
182621            {
182622              "url": "https://github.com/mcavage/node-assert-plus#readme",
182623              "type": "website"
182624            }
182625          ],
182626          "evidence": {},
182627          "signature": {
182628            "signature": {
182629              "publicKey": {}
182630            }
182631          },
182632          "modelCard": {
182633            "modelParameters": {
182634              "approach": {}
182635            },
182636            "quantitativeAnalysis": {
182637              "graphics": {}
182638            },
182639            "considerations": {}
182640          }
182641        },
182642        {
182643          "type": "library",
182644          "bom-ref": "pkg:npm/asynckit@0.4.0?package-id=7f18bf9a25c0da72",
182645          "supplier": {},
182646          "author": "Alex Indigo \u003ciam@alexindigo.com\u003e",
182647          "name": "asynckit",
182648          "version": "0.4.0",
182649          "description": "Minimal async jobs utility library, with streams support",
182650          "licenses": [
182651            {
182652              "license": {
182653                "id": "MIT"
182654              }
182655            }
182656          ],
182657          "cpe": "cpe:2.3:a:alexindigo:asynckit:0.4.0:*:*:*:*:*:*:*",
182658          "purl": "pkg:npm/asynckit@0.4.0",
182659          "swid": {
182660            "attachment": {}
182661          },
182662          "pedigree": {},
182663          "externalReferences": [
182664            {
182665              "url": "git+https://github.com/alexindigo/asynckit.git",
182666              "type": "distribution"
182667            },
182668            {
182669              "url": "https://github.com/alexindigo/asynckit#readme",
182670              "type": "website"
182671            }
182672          ],
182673          "evidence": {},
182674          "signature": {
182675            "signature": {
182676              "publicKey": {}
182677            }
182678          },
182679          "modelCard": {
182680            "modelParameters": {
182681              "approach": {}
182682            },
182683            "quantitativeAnalysis": {
182684              "graphics": {}
182685            },
182686            "considerations": {}
182687          }
182688        },
182689        {
182690          "type": "library",
182691          "bom-ref": "pkg:npm/aws-sign2@0.7.0?package-id=f8fe112c8da3e39f",
182692          "supplier": {},
182693          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
182694          "name": "aws-sign2",
182695          "version": "0.7.0",
182696          "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
182697          "licenses": [
182698            {
182699              "license": {
182700                "id": "Apache-2.0"
182701              }
182702            }
182703          ],
182704          "cpe": "cpe:2.3:a:aws-sign2:aws-sign2:0.7.0:*:*:*:*:*:*:*",
182705          "purl": "pkg:npm/aws-sign2@0.7.0",
182706          "swid": {
182707            "attachment": {}
182708          },
182709          "pedigree": {},
182710          "externalReferences": [
182711            {
182712              "url": "git+https://github.com/mikeal/aws-sign.git",
182713              "type": "distribution"
182714            },
182715            {
182716              "url": "https://github.com/mikeal/aws-sign#readme",
182717              "type": "website"
182718            }
182719          ],
182720          "evidence": {},
182721          "signature": {
182722            "signature": {
182723              "publicKey": {}
182724            }
182725          },
182726          "modelCard": {
182727            "modelParameters": {
182728              "approach": {}
182729            },
182730            "quantitativeAnalysis": {
182731              "graphics": {}
182732            },
182733            "considerations": {}
182734          }
182735        },
182736        {
182737          "type": "library",
182738          "bom-ref": "pkg:npm/aws4@1.8.0?package-id=eb9b4fd5d957d188",
182739          "supplier": {},
182740          "author": "Michael Hart \u003cmichael.hart.au@gmail.com\u003e (http://github.com/mhart)",
182741          "name": "aws4",
182742          "version": "1.8.0",
182743          "description": "Signs and prepares requests using AWS Signature Version 4",
182744          "licenses": [
182745            {
182746              "license": {
182747                "id": "MIT"
182748              }
182749            }
182750          ],
182751          "cpe": "cpe:2.3:a:mhart:aws4:1.8.0:*:*:*:*:*:*:*",
182752          "purl": "pkg:npm/aws4@1.8.0",
182753          "swid": {
182754            "attachment": {}
182755          },
182756          "pedigree": {},
182757          "externalReferences": [
182758            {
182759              "url": "git+https://github.com/mhart/aws4.git",
182760              "type": "distribution"
182761            },
182762            {
182763              "url": "https://github.com/mhart/aws4#readme",
182764              "type": "website"
182765            }
182766          ],
182767          "evidence": {},
182768          "signature": {
182769            "signature": {
182770              "publicKey": {}
182771            }
182772          },
182773          "modelCard": {
182774            "modelParameters": {
182775              "approach": {}
182776            },
182777            "quantitativeAnalysis": {
182778              "graphics": {}
182779            },
182780            "considerations": {}
182781          }
182782        },
182783        {
182784          "type": "library",
182785          "bom-ref": "pkg:npm/axios@0.21.1?package-id=5a7030bf3c0c089c",
182786          "supplier": {},
182787          "author": "Matt Zabriskie",
182788          "name": "axios",
182789          "version": "0.21.1",
182790          "description": "Promise based HTTP client for the browser and node.js",
182791          "licenses": [
182792            {
182793              "license": {
182794                "id": "MIT"
182795              }
182796            }
182797          ],
182798          "cpe": "cpe:2.3:a:axios:axios:0.21.1:*:*:*:*:*:*:*",
182799          "purl": "pkg:npm/axios@0.21.1",
182800          "swid": {
182801            "attachment": {}
182802          },
182803          "pedigree": {},
182804          "externalReferences": [
182805            {
182806              "url": "git+https://github.com/axios/axios.git",
182807              "type": "distribution"
182808            },
182809            {
182810              "url": "https://github.com/axios/axios",
182811              "type": "website"
182812            }
182813          ],
182814          "evidence": {},
182815          "signature": {
182816            "signature": {
182817              "publicKey": {}
182818            }
182819          },
182820          "modelCard": {
182821            "modelParameters": {
182822              "approach": {}
182823            },
182824            "quantitativeAnalysis": {
182825              "graphics": {}
182826            },
182827            "considerations": {}
182828          }
182829        },
182830        {
182831          "type": "library",
182832          "bom-ref": "pkg:npm/balanced-match@1.0.0?package-id=f2485d1f88b2b3bf",
182833          "supplier": {},
182834          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
182835          "name": "balanced-match",
182836          "version": "1.0.0",
182837          "description": "Match balanced character pairs, like \"{\" and \"}\"",
182838          "licenses": [
182839            {
182840              "license": {
182841                "id": "MIT"
182842              }
182843            }
182844          ],
182845          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.0:*:*:*:*:*:*:*",
182846          "purl": "pkg:npm/balanced-match@1.0.0",
182847          "swid": {
182848            "attachment": {}
182849          },
182850          "pedigree": {},
182851          "externalReferences": [
182852            {
182853              "url": "git://github.com/juliangruber/balanced-match.git",
182854              "type": "distribution"
182855            },
182856            {
182857              "url": "https://github.com/juliangruber/balanced-match",
182858              "type": "website"
182859            }
182860          ],
182861          "evidence": {},
182862          "signature": {
182863            "signature": {
182864              "publicKey": {}
182865            }
182866          },
182867          "modelCard": {
182868            "modelParameters": {
182869              "approach": {}
182870            },
182871            "quantitativeAnalysis": {
182872              "graphics": {}
182873            },
182874            "considerations": {}
182875          }
182876        },
182877        {
182878          "type": "library",
182879          "bom-ref": "pkg:npm/balanced-match@1.0.0?package-id=604bcb0d94c55468",
182880          "supplier": {},
182881          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
182882          "name": "balanced-match",
182883          "version": "1.0.0",
182884          "description": "Match balanced character pairs, like \"{\" and \"}\"",
182885          "licenses": [
182886            {
182887              "license": {
182888                "id": "MIT"
182889              }
182890            }
182891          ],
182892          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.0:*:*:*:*:*:*:*",
182893          "purl": "pkg:npm/balanced-match@1.0.0",
182894          "swid": {
182895            "attachment": {}
182896          },
182897          "pedigree": {},
182898          "externalReferences": [
182899            {
182900              "url": "git://github.com/juliangruber/balanced-match.git",
182901              "type": "distribution"
182902            },
182903            {
182904              "url": "https://github.com/juliangruber/balanced-match",
182905              "type": "website"
182906            }
182907          ],
182908          "evidence": {},
182909          "signature": {
182910            "signature": {
182911              "publicKey": {}
182912            }
182913          },
182914          "modelCard": {
182915            "modelParameters": {
182916              "approach": {}
182917            },
182918            "quantitativeAnalysis": {
182919              "graphics": {}
182920            },
182921            "considerations": {}
182922          }
182923        },
182924        {
182925          "type": "library",
182926          "bom-ref": "pkg:npm/bcrypt-pbkdf@1.0.2?package-id=b345fa0f3bee37c",
182927          "supplier": {},
182928          "name": "bcrypt-pbkdf",
182929          "version": "1.0.2",
182930          "description": "Port of the OpenBSD bcrypt_pbkdf function to pure JS",
182931          "licenses": [
182932            {
182933              "license": {
182934                "id": "BSD-3-Clause"
182935              }
182936            }
182937          ],
182938          "cpe": "cpe:2.3:a:bcrypt-pbkdf:bcrypt-pbkdf:1.0.2:*:*:*:*:*:*:*",
182939          "purl": "pkg:npm/bcrypt-pbkdf@1.0.2",
182940          "swid": {
182941            "attachment": {}
182942          },
182943          "pedigree": {},
182944          "externalReferences": [
182945            {
182946              "url": "git://github.com/joyent/node-bcrypt-pbkdf.git",
182947              "type": "distribution"
182948            },
182949            {
182950              "url": "https://github.com/joyent/node-bcrypt-pbkdf#readme",
182951              "type": "website"
182952            }
182953          ],
182954          "evidence": {},
182955          "signature": {
182956            "signature": {
182957              "publicKey": {}
182958            }
182959          },
182960          "modelCard": {
182961            "modelParameters": {
182962              "approach": {}
182963            },
182964            "quantitativeAnalysis": {
182965              "graphics": {}
182966            },
182967            "considerations": {}
182968          }
182969        },
182970        {
182971          "type": "library",
182972          "bom-ref": "pkg:npm/bin-links@1.1.8?package-id=d51f215e6a9beb3e",
182973          "supplier": {},
182974          "author": "Mike Sherov",
182975          "name": "bin-links",
182976          "version": "1.1.8",
182977          "description": "JavaScript package binary linker",
182978          "licenses": [
182979            {
182980              "license": {
182981                "id": "Artistic-2.0"
182982              }
182983            }
182984          ],
182985          "cpe": "cpe:2.3:a:bin-links:bin-links:1.1.8:*:*:*:*:*:*:*",
182986          "purl": "pkg:npm/bin-links@1.1.8",
182987          "swid": {
182988            "attachment": {}
182989          },
182990          "pedigree": {},
182991          "externalReferences": [
182992            {
182993              "url": "git://github.com/npm/bin-links.git",
182994              "type": "distribution"
182995            },
182996            {
182997              "url": "https://github.com/npm/bin-links#readme",
182998              "type": "website"
182999            }
183000          ],
183001          "evidence": {},
183002          "signature": {
183003            "signature": {
183004              "publicKey": {}
183005            }
183006          },
183007          "modelCard": {
183008            "modelParameters": {
183009              "approach": {}
183010            },
183011            "quantitativeAnalysis": {
183012              "graphics": {}
183013            },
183014            "considerations": {}
183015          }
183016        },
183017        {
183018          "type": "library",
183019          "bom-ref": "pkg:npm/bluebird@3.5.5?package-id=23a13a465eeec006",
183020          "supplier": {},
183021          "author": "Petka Antonov \u003cpetka_antonov@hotmail.com\u003e (http://github.com/petkaantonov/)",
183022          "name": "bluebird",
183023          "version": "3.5.5",
183024          "description": "Full featured Promises/A+ implementation with exceptionally good performance",
183025          "licenses": [
183026            {
183027              "license": {
183028                "id": "MIT"
183029              }
183030            }
183031          ],
183032          "cpe": "cpe:2.3:a:petkaantonov:bluebird:3.5.5:*:*:*:*:*:*:*",
183033          "purl": "pkg:npm/bluebird@3.5.5",
183034          "swid": {
183035            "attachment": {}
183036          },
183037          "pedigree": {},
183038          "externalReferences": [
183039            {
183040              "url": "git://github.com/petkaantonov/bluebird.git",
183041              "type": "distribution"
183042            },
183043            {
183044              "url": "https://github.com/petkaantonov/bluebird",
183045              "type": "website"
183046            }
183047          ],
183048          "evidence": {},
183049          "signature": {
183050            "signature": {
183051              "publicKey": {}
183052            }
183053          },
183054          "modelCard": {
183055            "modelParameters": {
183056              "approach": {}
183057            },
183058            "quantitativeAnalysis": {
183059              "graphics": {}
183060            },
183061            "considerations": {}
183062          }
183063        },
183064        {
183065          "type": "library",
183066          "bom-ref": "pkg:npm/body-parser@1.19.0?package-id=be42f3aef28246c",
183067          "supplier": {},
183068          "name": "body-parser",
183069          "version": "1.19.0",
183070          "description": "Node.js body parsing middleware",
183071          "licenses": [
183072            {
183073              "license": {
183074                "id": "MIT"
183075              }
183076            }
183077          ],
183078          "cpe": "cpe:2.3:a:body-parser:body-parser:1.19.0:*:*:*:*:*:*:*",
183079          "purl": "pkg:npm/body-parser@1.19.0",
183080          "swid": {
183081            "attachment": {}
183082          },
183083          "pedigree": {},
183084          "externalReferences": [
183085            {
183086              "url": "git+https://github.com/expressjs/body-parser.git",
183087              "type": "distribution"
183088            },
183089            {
183090              "url": "https://github.com/expressjs/body-parser#readme",
183091              "type": "website"
183092            }
183093          ],
183094          "evidence": {},
183095          "signature": {
183096            "signature": {
183097              "publicKey": {}
183098            }
183099          },
183100          "modelCard": {
183101            "modelParameters": {
183102              "approach": {}
183103            },
183104            "quantitativeAnalysis": {
183105              "graphics": {}
183106            },
183107            "considerations": {}
183108          }
183109        },
183110        {
183111          "type": "library",
183112          "bom-ref": "pkg:npm/boolean@3.2.0?package-id=a5139e59aa9a5908",
183113          "supplier": {},
183114          "name": "boolean",
183115          "version": "3.2.0",
183116          "description": "boolean converts lots of things to boolean.",
183117          "licenses": [
183118            {
183119              "license": {
183120                "id": "MIT"
183121              }
183122            }
183123          ],
183124          "cpe": "cpe:2.3:a:thenativeweb:boolean:3.2.0:*:*:*:*:*:*:*",
183125          "purl": "pkg:npm/boolean@3.2.0",
183126          "swid": {
183127            "attachment": {}
183128          },
183129          "pedigree": {},
183130          "externalReferences": [
183131            {
183132              "url": "git://github.com/thenativeweb/boolean.git",
183133              "type": "distribution"
183134            },
183135            {
183136              "url": "https://github.com/thenativeweb/boolean#readme",
183137              "type": "website"
183138            }
183139          ],
183140          "evidence": {},
183141          "signature": {
183142            "signature": {
183143              "publicKey": {}
183144            }
183145          },
183146          "modelCard": {
183147            "modelParameters": {
183148              "approach": {}
183149            },
183150            "quantitativeAnalysis": {
183151              "graphics": {}
183152            },
183153            "considerations": {}
183154          }
183155        },
183156        {
183157          "type": "library",
183158          "bom-ref": "pkg:npm/boxen@1.3.0?package-id=9733e2ac66f5ce9b",
183159          "supplier": {},
183160          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
183161          "name": "boxen",
183162          "version": "1.3.0",
183163          "description": "Create boxes in the terminal",
183164          "licenses": [
183165            {
183166              "license": {
183167                "id": "MIT"
183168              }
183169            }
183170          ],
183171          "cpe": "cpe:2.3:a:sindresorhus:boxen:1.3.0:*:*:*:*:*:*:*",
183172          "purl": "pkg:npm/boxen@1.3.0",
183173          "swid": {
183174            "attachment": {}
183175          },
183176          "pedigree": {},
183177          "externalReferences": [
183178            {
183179              "url": "git+https://github.com/sindresorhus/boxen.git",
183180              "type": "distribution"
183181            },
183182            {
183183              "url": "https://github.com/sindresorhus/boxen#readme",
183184              "type": "website"
183185            }
183186          ],
183187          "evidence": {},
183188          "signature": {
183189            "signature": {
183190              "publicKey": {}
183191            }
183192          },
183193          "modelCard": {
183194            "modelParameters": {
183195              "approach": {}
183196            },
183197            "quantitativeAnalysis": {
183198              "graphics": {}
183199            },
183200            "considerations": {}
183201          }
183202        },
183203        {
183204          "type": "library",
183205          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=b2f1259ad317cd31",
183206          "supplier": {},
183207          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
183208          "name": "brace-expansion",
183209          "version": "1.1.11",
183210          "description": "Brace expansion as known from sh/bash",
183211          "licenses": [
183212            {
183213              "license": {
183214                "id": "MIT"
183215              }
183216            }
183217          ],
183218          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
183219          "purl": "pkg:npm/brace-expansion@1.1.11",
183220          "swid": {
183221            "attachment": {}
183222          },
183223          "pedigree": {},
183224          "externalReferences": [
183225            {
183226              "url": "git://github.com/juliangruber/brace-expansion.git",
183227              "type": "distribution"
183228            },
183229            {
183230              "url": "https://github.com/juliangruber/brace-expansion",
183231              "type": "website"
183232            }
183233          ],
183234          "evidence": {},
183235          "signature": {
183236            "signature": {
183237              "publicKey": {}
183238            }
183239          },
183240          "modelCard": {
183241            "modelParameters": {
183242              "approach": {}
183243            },
183244            "quantitativeAnalysis": {
183245              "graphics": {}
183246            },
183247            "considerations": {}
183248          }
183249        },
183250        {
183251          "type": "library",
183252          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=a3ea8e119b765a4b",
183253          "supplier": {},
183254          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
183255          "name": "brace-expansion",
183256          "version": "1.1.11",
183257          "description": "Brace expansion as known from sh/bash",
183258          "licenses": [
183259            {
183260              "license": {
183261                "id": "MIT"
183262              }
183263            }
183264          ],
183265          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
183266          "purl": "pkg:npm/brace-expansion@1.1.11",
183267          "swid": {
183268            "attachment": {}
183269          },
183270          "pedigree": {},
183271          "externalReferences": [
183272            {
183273              "url": "git://github.com/juliangruber/brace-expansion.git",
183274              "type": "distribution"
183275            },
183276            {
183277              "url": "https://github.com/juliangruber/brace-expansion",
183278              "type": "website"
183279            }
183280          ],
183281          "evidence": {},
183282          "signature": {
183283            "signature": {
183284              "publicKey": {}
183285            }
183286          },
183287          "modelCard": {
183288            "modelParameters": {
183289              "approach": {}
183290            },
183291            "quantitativeAnalysis": {
183292              "graphics": {}
183293            },
183294            "considerations": {}
183295          }
183296        },
183297        {
183298          "type": "library",
183299          "bom-ref": "pkg:npm/buffer-from@1.0.0?package-id=679ef1b5d74ace0f",
183300          "supplier": {},
183301          "name": "buffer-from",
183302          "version": "1.0.0",
183303          "description": "A [ponyfill](https://ponyfill.com) for `Buffer.from`, uses native implementation if available.",
183304          "licenses": [
183305            {
183306              "license": {
183307                "id": "MIT"
183308              }
183309            }
183310          ],
183311          "cpe": "cpe:2.3:a:buffer-from:buffer-from:1.0.0:*:*:*:*:*:*:*",
183312          "purl": "pkg:npm/buffer-from@1.0.0",
183313          "swid": {
183314            "attachment": {}
183315          },
183316          "pedigree": {},
183317          "externalReferences": [
183318            {
183319              "url": "git+https://github.com/LinusU/buffer-from.git",
183320              "type": "distribution"
183321            },
183322            {
183323              "url": "https://github.com/LinusU/buffer-from#readme",
183324              "type": "website"
183325            }
183326          ],
183327          "evidence": {},
183328          "signature": {
183329            "signature": {
183330              "publicKey": {}
183331            }
183332          },
183333          "modelCard": {
183334            "modelParameters": {
183335              "approach": {}
183336            },
183337            "quantitativeAnalysis": {
183338              "graphics": {}
183339            },
183340            "considerations": {}
183341          }
183342        },
183343        {
183344          "type": "library",
183345          "bom-ref": "pkg:npm/buffer-from@1.1.1?package-id=f79feba1e77ff417",
183346          "supplier": {},
183347          "name": "buffer-from",
183348          "version": "1.1.1",
183349          "description": "A [ponyfill](https://ponyfill.com) for `Buffer.from`, uses native implementation if available.",
183350          "licenses": [
183351            {
183352              "license": {
183353                "id": "MIT"
183354              }
183355            }
183356          ],
183357          "cpe": "cpe:2.3:a:buffer-from:buffer-from:1.1.1:*:*:*:*:*:*:*",
183358          "purl": "pkg:npm/buffer-from@1.1.1",
183359          "swid": {
183360            "attachment": {}
183361          },
183362          "pedigree": {},
183363          "externalReferences": [
183364            {
183365              "url": "git+https://github.com/LinusU/buffer-from.git",
183366              "type": "distribution"
183367            },
183368            {
183369              "url": "https://github.com/LinusU/buffer-from#readme",
183370              "type": "website"
183371            }
183372          ],
183373          "evidence": {},
183374          "signature": {
183375            "signature": {
183376              "publicKey": {}
183377            }
183378          },
183379          "modelCard": {
183380            "modelParameters": {
183381              "approach": {}
183382            },
183383            "quantitativeAnalysis": {
183384              "graphics": {}
183385            },
183386            "considerations": {}
183387          }
183388        },
183389        {
183390          "type": "library",
183391          "bom-ref": "pkg:npm/builtins@1.0.3?package-id=38ca391b8ca0276a",
183392          "supplier": {},
183393          "name": "builtins",
183394          "version": "1.0.3",
183395          "description": "List of node.js builtin modules",
183396          "licenses": [
183397            {
183398              "license": {
183399                "id": "MIT"
183400              }
183401            }
183402          ],
183403          "cpe": "cpe:2.3:a:juliangruber:builtins:1.0.3:*:*:*:*:*:*:*",
183404          "purl": "pkg:npm/builtins@1.0.3",
183405          "swid": {
183406            "attachment": {}
183407          },
183408          "pedigree": {},
183409          "externalReferences": [
183410            {
183411              "url": "git+https://github.com/juliangruber/builtins.git",
183412              "type": "distribution"
183413            },
183414            {
183415              "url": "https://github.com/juliangruber/builtins#readme",
183416              "type": "website"
183417            }
183418          ],
183419          "evidence": {},
183420          "signature": {
183421            "signature": {
183422              "publicKey": {}
183423            }
183424          },
183425          "modelCard": {
183426            "modelParameters": {
183427              "approach": {}
183428            },
183429            "quantitativeAnalysis": {
183430              "graphics": {}
183431            },
183432            "considerations": {}
183433          }
183434        },
183435        {
183436          "type": "library",
183437          "bom-ref": "pkg:npm/busboy@0.2.14?package-id=b320ea57e5b5ba6a",
183438          "supplier": {},
183439          "author": "Brian White \u003cmscdex@mscdex.net\u003e",
183440          "name": "busboy",
183441          "version": "0.2.14",
183442          "description": "A streaming parser for HTML form data for node.js",
183443          "licenses": [
183444            {
183445              "license": {
183446                "id": "MIT"
183447              }
183448            }
183449          ],
183450          "cpe": "cpe:2.3:a:busboy:busboy:0.2.14:*:*:*:*:*:*:*",
183451          "purl": "pkg:npm/busboy@0.2.14",
183452          "swid": {
183453            "attachment": {}
183454          },
183455          "pedigree": {},
183456          "externalReferences": [
183457            {
183458              "url": "git+ssh://git@github.com/mscdex/busboy.git",
183459              "type": "distribution"
183460            },
183461            {
183462              "url": "https://github.com/mscdex/busboy#readme",
183463              "type": "website"
183464            }
183465          ],
183466          "evidence": {},
183467          "signature": {
183468            "signature": {
183469              "publicKey": {}
183470            }
183471          },
183472          "modelCard": {
183473            "modelParameters": {
183474              "approach": {}
183475            },
183476            "quantitativeAnalysis": {
183477              "graphics": {}
183478            },
183479            "considerations": {}
183480          }
183481        },
183482        {
183483          "type": "application",
183484          "bom-ref": "5c25680736f90c12",
183485          "supplier": {},
183486          "name": "busybox",
183487          "version": "1.35.0",
183488          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
183489          "swid": {
183490            "attachment": {}
183491          },
183492          "pedigree": {},
183493          "evidence": {},
183494          "signature": {
183495            "signature": {
183496              "publicKey": {}
183497            }
183498          },
183499          "modelCard": {
183500            "modelParameters": {
183501              "approach": {}
183502            },
183503            "quantitativeAnalysis": {
183504              "graphics": {}
183505            },
183506            "considerations": {}
183507          }
183508        },
183509        {
183510          "type": "library",
183511          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.1\u0026package-id=623d53216342d45e",
183512          "supplier": {},
183513          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
183514          "name": "busybox",
183515          "version": "1.35.0-r29",
183516          "description": "Size optimized toolbox of many common UNIX utilities",
183517          "licenses": [
183518            {
183519              "license": {
183520                "id": "GPL-2.0-only"
183521              }
183522            }
183523          ],
183524          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r29:*:*:*:*:*:*:*",
183525          "purl": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.1",
183526          "swid": {
183527            "attachment": {}
183528          },
183529          "pedigree": {},
183530          "externalReferences": [
183531            {
183532              "url": "https://busybox.net/",
183533              "type": "distribution"
183534            }
183535          ],
183536          "evidence": {},
183537          "signature": {
183538            "signature": {
183539              "publicKey": {}
183540            }
183541          },
183542          "modelCard": {
183543            "modelParameters": {
183544              "approach": {}
183545            },
183546            "quantitativeAnalysis": {
183547              "graphics": {}
183548            },
183549            "considerations": {}
183550          }
183551        },
183552        {
183553          "type": "library",
183554          "bom-ref": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.1\u0026package-id=256fc96b4a8c4da8",
183555          "supplier": {},
183556          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
183557          "name": "busybox-binsh",
183558          "version": "1.35.0-r29",
183559          "description": "busybox ash /bin/sh",
183560          "licenses": [
183561            {
183562              "license": {
183563                "id": "GPL-2.0-only"
183564              }
183565            }
183566          ],
183567          "cpe": "cpe:2.3:a:busybox-binsh:busybox-binsh:1.35.0-r29:*:*:*:*:*:*:*",
183568          "purl": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.1",
183569          "swid": {
183570            "attachment": {}
183571          },
183572          "pedigree": {},
183573          "externalReferences": [
183574            {
183575              "url": "https://busybox.net/",
183576              "type": "distribution"
183577            }
183578          ],
183579          "evidence": {},
183580          "signature": {
183581            "signature": {
183582              "publicKey": {}
183583            }
183584          },
183585          "modelCard": {
183586            "modelParameters": {
183587              "approach": {}
183588            },
183589            "quantitativeAnalysis": {
183590              "graphics": {}
183591            },
183592            "considerations": {}
183593          }
183594        },
183595        {
183596          "type": "library",
183597          "bom-ref": "pkg:npm/byline@5.0.0?package-id=bc8643b43cbc314e",
183598          "supplier": {},
183599          "author": "John Hewson",
183600          "name": "byline",
183601          "version": "5.0.0",
183602          "description": "simple line-by-line stream reader",
183603          "licenses": [
183604            {
183605              "license": {
183606                "id": "MIT"
183607              }
183608            }
183609          ],
183610          "cpe": "cpe:2.3:a:jahewson:byline:5.0.0:*:*:*:*:*:*:*",
183611          "purl": "pkg:npm/byline@5.0.0",
183612          "swid": {
183613            "attachment": {}
183614          },
183615          "pedigree": {},
183616          "externalReferences": [
183617            {
183618              "url": "git+https://github.com/jahewson/node-byline.git",
183619              "type": "distribution"
183620            },
183621            {
183622              "url": "https://github.com/jahewson/node-byline",
183623              "type": "website"
183624            }
183625          ],
183626          "evidence": {},
183627          "signature": {
183628            "signature": {
183629              "publicKey": {}
183630            }
183631          },
183632          "modelCard": {
183633            "modelParameters": {
183634              "approach": {}
183635            },
183636            "quantitativeAnalysis": {
183637              "graphics": {}
183638            },
183639            "considerations": {}
183640          }
183641        },
183642        {
183643          "type": "library",
183644          "bom-ref": "pkg:npm/byte-size@5.0.1?package-id=ca5e03ebe208c5ec",
183645          "supplier": {},
183646          "author": "Lloyd Brookes \u003c75pound@gmail.com\u003e",
183647          "name": "byte-size",
183648          "version": "5.0.1",
183649          "description": "Convert a bytes (and octets) value to a more human-readable format. Choose between metric or IEC units.",
183650          "licenses": [
183651            {
183652              "license": {
183653                "id": "MIT"
183654              }
183655            }
183656          ],
183657          "cpe": "cpe:2.3:a:byte-size:byte-size:5.0.1:*:*:*:*:*:*:*",
183658          "purl": "pkg:npm/byte-size@5.0.1",
183659          "swid": {
183660            "attachment": {}
183661          },
183662          "pedigree": {},
183663          "externalReferences": [
183664            {
183665              "url": "git+https://github.com/75lb/byte-size.git",
183666              "type": "distribution"
183667            },
183668            {
183669              "url": "https://github.com/75lb/byte-size#readme",
183670              "type": "website"
183671            }
183672          ],
183673          "evidence": {},
183674          "signature": {
183675            "signature": {
183676              "publicKey": {}
183677            }
183678          },
183679          "modelCard": {
183680            "modelParameters": {
183681              "approach": {}
183682            },
183683            "quantitativeAnalysis": {
183684              "graphics": {}
183685            },
183686            "considerations": {}
183687          }
183688        },
183689        {
183690          "type": "library",
183691          "bom-ref": "pkg:npm/bytes@3.1.0?package-id=b4af9154bbf6604c",
183692          "supplier": {},
183693          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
183694          "name": "bytes",
183695          "version": "3.1.0",
183696          "description": "Utility to parse a string bytes to bytes and vice-versa",
183697          "licenses": [
183698            {
183699              "license": {
183700                "id": "MIT"
183701              }
183702            }
183703          ],
183704          "cpe": "cpe:2.3:a:visionmedia:bytes:3.1.0:*:*:*:*:*:*:*",
183705          "purl": "pkg:npm/bytes@3.1.0",
183706          "swid": {
183707            "attachment": {}
183708          },
183709          "pedigree": {},
183710          "externalReferences": [
183711            {
183712              "url": "git+https://github.com/visionmedia/bytes.js.git",
183713              "type": "distribution"
183714            },
183715            {
183716              "url": "https://github.com/visionmedia/bytes.js#readme",
183717              "type": "website"
183718            }
183719          ],
183720          "evidence": {},
183721          "signature": {
183722            "signature": {
183723              "publicKey": {}
183724            }
183725          },
183726          "modelCard": {
183727            "modelParameters": {
183728              "approach": {}
183729            },
183730            "quantitativeAnalysis": {
183731              "graphics": {}
183732            },
183733            "considerations": {}
183734          }
183735        },
183736        {
183737          "type": "library",
183738          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.1\u0026package-id=b805d823ae624f04",
183739          "supplier": {},
183740          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
183741          "name": "ca-certificates-bundle",
183742          "version": "20220614-r4",
183743          "description": "Pre generated bundle of Mozilla certificates",
183744          "licenses": [
183745            {
183746              "license": {
183747                "id": "MPL-2.0"
183748              }
183749            },
183750            {
183751              "license": {
183752                "name": "AND"
183753              }
183754            },
183755            {
183756              "license": {
183757                "id": "MIT"
183758              }
183759            }
183760          ],
183761          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r4:*:*:*:*:*:*:*",
183762          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.1",
183763          "swid": {
183764            "attachment": {}
183765          },
183766          "pedigree": {},
183767          "externalReferences": [
183768            {
183769              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
183770              "type": "distribution"
183771            }
183772          ],
183773          "evidence": {},
183774          "signature": {
183775            "signature": {
183776              "publicKey": {}
183777            }
183778          },
183779          "modelCard": {
183780            "modelParameters": {
183781              "approach": {}
183782            },
183783            "quantitativeAnalysis": {
183784              "graphics": {}
183785            },
183786            "considerations": {}
183787          }
183788        },
183789        {
183790          "type": "library",
183791          "bom-ref": "pkg:npm/cacache@12.0.3?package-id=4dc4cde2d8aef433",
183792          "supplier": {},
183793          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
183794          "name": "cacache",
183795          "version": "12.0.3",
183796          "description": "Fast, fault-tolerant, cross-platform, disk-based, data-agnostic, content-addressable cache.",
183797          "licenses": [
183798            {
183799              "license": {
183800                "id": "ISC"
183801              }
183802            }
183803          ],
183804          "cpe": "cpe:2.3:a:cacache:cacache:12.0.3:*:*:*:*:*:*:*",
183805          "purl": "pkg:npm/cacache@12.0.3",
183806          "swid": {
183807            "attachment": {}
183808          },
183809          "pedigree": {},
183810          "externalReferences": [
183811            {
183812              "url": "git+https://github.com/npm/cacache.git",
183813              "type": "distribution"
183814            },
183815            {
183816              "url": "https://github.com/npm/cacache#readme",
183817              "type": "website"
183818            }
183819          ],
183820          "evidence": {},
183821          "signature": {
183822            "signature": {
183823              "publicKey": {}
183824            }
183825          },
183826          "modelCard": {
183827            "modelParameters": {
183828              "approach": {}
183829            },
183830            "quantitativeAnalysis": {
183831              "graphics": {}
183832            },
183833            "considerations": {}
183834          }
183835        },
183836        {
183837          "type": "library",
183838          "bom-ref": "pkg:npm/call-limit@1.1.1?package-id=94eefbf82cd78b25",
183839          "supplier": {},
183840          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
183841          "name": "call-limit",
183842          "version": "1.1.1",
183843          "description": "Limit the number of simultaneous calls to an async function",
183844          "licenses": [
183845            {
183846              "license": {
183847                "id": "ISC"
183848              }
183849            }
183850          ],
183851          "cpe": "cpe:2.3:a:call-limit:call-limit:1.1.1:*:*:*:*:*:*:*",
183852          "purl": "pkg:npm/call-limit@1.1.1",
183853          "swid": {
183854            "attachment": {}
183855          },
183856          "pedigree": {},
183857          "externalReferences": [
183858            {
183859              "url": "git+https://github.com/iarna/call-limit.git",
183860              "type": "distribution"
183861            },
183862            {
183863              "url": "https://npmjs.com/packages/call-limit",
183864              "type": "website"
183865            }
183866          ],
183867          "evidence": {},
183868          "signature": {
183869            "signature": {
183870              "publicKey": {}
183871            }
183872          },
183873          "modelCard": {
183874            "modelParameters": {
183875              "approach": {}
183876            },
183877            "quantitativeAnalysis": {
183878              "graphics": {}
183879            },
183880            "considerations": {}
183881          }
183882        },
183883        {
183884          "type": "library",
183885          "bom-ref": "pkg:npm/camelcase@4.1.0?package-id=be57efd9d82defbf",
183886          "supplier": {},
183887          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
183888          "name": "camelcase",
183889          "version": "4.1.0",
183890          "description": "Convert a dash/dot/underscore/space separated string to camelCase: foo-bar → fooBar",
183891          "licenses": [
183892            {
183893              "license": {
183894                "id": "MIT"
183895              }
183896            }
183897          ],
183898          "cpe": "cpe:2.3:a:sindresorhus:camelcase:4.1.0:*:*:*:*:*:*:*",
183899          "purl": "pkg:npm/camelcase@4.1.0",
183900          "swid": {
183901            "attachment": {}
183902          },
183903          "pedigree": {},
183904          "externalReferences": [
183905            {
183906              "url": "git+https://github.com/sindresorhus/camelcase.git",
183907              "type": "distribution"
183908            },
183909            {
183910              "url": "https://github.com/sindresorhus/camelcase#readme",
183911              "type": "website"
183912            }
183913          ],
183914          "evidence": {},
183915          "signature": {
183916            "signature": {
183917              "publicKey": {}
183918            }
183919          },
183920          "modelCard": {
183921            "modelParameters": {
183922              "approach": {}
183923            },
183924            "quantitativeAnalysis": {
183925              "graphics": {}
183926            },
183927            "considerations": {}
183928          }
183929        },
183930        {
183931          "type": "library",
183932          "bom-ref": "pkg:npm/camelcase@5.3.1?package-id=4d249508c958ea3b",
183933          "supplier": {},
183934          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
183935          "name": "camelcase",
183936          "version": "5.3.1",
183937          "description": "Convert a dash/dot/underscore/space separated string to camelCase or PascalCase: `foo-bar` → `fooBar`",
183938          "licenses": [
183939            {
183940              "license": {
183941                "id": "MIT"
183942              }
183943            }
183944          ],
183945          "cpe": "cpe:2.3:a:sindresorhus:camelcase:5.3.1:*:*:*:*:*:*:*",
183946          "purl": "pkg:npm/camelcase@5.3.1",
183947          "swid": {
183948            "attachment": {}
183949          },
183950          "pedigree": {},
183951          "externalReferences": [
183952            {
183953              "url": "git+https://github.com/sindresorhus/camelcase.git",
183954              "type": "distribution"
183955            },
183956            {
183957              "url": "https://github.com/sindresorhus/camelcase#readme",
183958              "type": "website"
183959            }
183960          ],
183961          "evidence": {},
183962          "signature": {
183963            "signature": {
183964              "publicKey": {}
183965            }
183966          },
183967          "modelCard": {
183968            "modelParameters": {
183969              "approach": {}
183970            },
183971            "quantitativeAnalysis": {
183972              "graphics": {}
183973            },
183974            "considerations": {}
183975          }
183976        },
183977        {
183978          "type": "library",
183979          "bom-ref": "pkg:npm/capture-stack-trace@1.0.0?package-id=12efd23d12d8a98f",
183980          "supplier": {},
183981          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
183982          "name": "capture-stack-trace",
183983          "version": "1.0.0",
183984          "description": "Error.captureStackTrace ponyfill",
183985          "licenses": [
183986            {
183987              "license": {
183988                "id": "MIT"
183989              }
183990            }
183991          ],
183992          "cpe": "cpe:2.3:a:capture-stack-trace:capture-stack-trace:1.0.0:*:*:*:*:*:*:*",
183993          "purl": "pkg:npm/capture-stack-trace@1.0.0",
183994          "swid": {
183995            "attachment": {}
183996          },
183997          "pedigree": {},
183998          "externalReferences": [
183999            {
184000              "url": "git+https://github.com/floatdrop/capture-stack-trace.git",
184001              "type": "distribution"
184002            },
184003            {
184004              "url": "https://github.com/floatdrop/capture-stack-trace#readme",
184005              "type": "website"
184006            }
184007          ],
184008          "evidence": {},
184009          "signature": {
184010            "signature": {
184011              "publicKey": {}
184012            }
184013          },
184014          "modelCard": {
184015            "modelParameters": {
184016              "approach": {}
184017            },
184018            "quantitativeAnalysis": {
184019              "graphics": {}
184020            },
184021            "considerations": {}
184022          }
184023        },
184024        {
184025          "type": "library",
184026          "bom-ref": "pkg:npm/caseless@0.12.0?package-id=748962a916b10431",
184027          "supplier": {},
184028          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
184029          "name": "caseless",
184030          "version": "0.12.0",
184031          "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
184032          "licenses": [
184033            {
184034              "license": {
184035                "id": "Apache-2.0"
184036              }
184037            }
184038          ],
184039          "cpe": "cpe:2.3:a:caseless:caseless:0.12.0:*:*:*:*:*:*:*",
184040          "purl": "pkg:npm/caseless@0.12.0",
184041          "swid": {
184042            "attachment": {}
184043          },
184044          "pedigree": {},
184045          "externalReferences": [
184046            {
184047              "url": "git+https://github.com/mikeal/caseless.git",
184048              "type": "distribution"
184049            },
184050            {
184051              "url": "https://github.com/mikeal/caseless#readme",
184052              "type": "website"
184053            }
184054          ],
184055          "evidence": {},
184056          "signature": {
184057            "signature": {
184058              "publicKey": {}
184059            }
184060          },
184061          "modelCard": {
184062            "modelParameters": {
184063              "approach": {}
184064            },
184065            "quantitativeAnalysis": {
184066              "graphics": {}
184067            },
184068            "considerations": {}
184069          }
184070        },
184071        {
184072          "type": "library",
184073          "bom-ref": "pkg:npm/chalk@2.4.1?package-id=772c80d6136b5c7c",
184074          "supplier": {},
184075          "name": "chalk",
184076          "version": "2.4.1",
184077          "description": "Terminal string styling done right",
184078          "licenses": [
184079            {
184080              "license": {
184081                "id": "MIT"
184082              }
184083            }
184084          ],
184085          "cpe": "cpe:2.3:a:chalk:chalk:2.4.1:*:*:*:*:*:*:*",
184086          "purl": "pkg:npm/chalk@2.4.1",
184087          "swid": {
184088            "attachment": {}
184089          },
184090          "pedigree": {},
184091          "externalReferences": [
184092            {
184093              "url": "git+https://github.com/chalk/chalk.git",
184094              "type": "distribution"
184095            },
184096            {
184097              "url": "https://github.com/chalk/chalk#readme",
184098              "type": "website"
184099            }
184100          ],
184101          "evidence": {},
184102          "signature": {
184103            "signature": {
184104              "publicKey": {}
184105            }
184106          },
184107          "modelCard": {
184108            "modelParameters": {
184109              "approach": {}
184110            },
184111            "quantitativeAnalysis": {
184112              "graphics": {}
184113            },
184114            "considerations": {}
184115          }
184116        },
184117        {
184118          "type": "library",
184119          "bom-ref": "pkg:npm/chalk@4.1.0?package-id=836e37cb96ea7d5f",
184120          "supplier": {},
184121          "name": "chalk",
184122          "version": "4.1.0",
184123          "description": "Terminal string styling done right",
184124          "licenses": [
184125            {
184126              "license": {
184127                "id": "MIT"
184128              }
184129            }
184130          ],
184131          "cpe": "cpe:2.3:a:chalk:chalk:4.1.0:*:*:*:*:*:*:*",
184132          "purl": "pkg:npm/chalk@4.1.0",
184133          "swid": {
184134            "attachment": {}
184135          },
184136          "pedigree": {},
184137          "externalReferences": [
184138            {
184139              "url": "git+https://github.com/chalk/chalk.git",
184140              "type": "distribution"
184141            },
184142            {
184143              "url": "https://github.com/chalk/chalk#readme",
184144              "type": "website"
184145            }
184146          ],
184147          "evidence": {},
184148          "signature": {
184149            "signature": {
184150              "publicKey": {}
184151            }
184152          },
184153          "modelCard": {
184154            "modelParameters": {
184155              "approach": {}
184156            },
184157            "quantitativeAnalysis": {
184158              "graphics": {}
184159            },
184160            "considerations": {}
184161          }
184162        },
184163        {
184164          "type": "library",
184165          "bom-ref": "pkg:npm/chownr@1.1.4?package-id=8e7f2809309b2b87",
184166          "supplier": {},
184167          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
184168          "name": "chownr",
184169          "version": "1.1.4",
184170          "description": "like `chown -R`",
184171          "licenses": [
184172            {
184173              "license": {
184174                "id": "ISC"
184175              }
184176            }
184177          ],
184178          "cpe": "cpe:2.3:a:chownr:chownr:1.1.4:*:*:*:*:*:*:*",
184179          "purl": "pkg:npm/chownr@1.1.4",
184180          "swid": {
184181            "attachment": {}
184182          },
184183          "pedigree": {},
184184          "externalReferences": [
184185            {
184186              "url": "git://github.com/isaacs/chownr.git",
184187              "type": "distribution"
184188            },
184189            {
184190              "url": "https://github.com/isaacs/chownr#readme",
184191              "type": "website"
184192            }
184193          ],
184194          "evidence": {},
184195          "signature": {
184196            "signature": {
184197              "publicKey": {}
184198            }
184199          },
184200          "modelCard": {
184201            "modelParameters": {
184202              "approach": {}
184203            },
184204            "quantitativeAnalysis": {
184205              "graphics": {}
184206            },
184207            "considerations": {}
184208          }
184209        },
184210        {
184211          "type": "library",
184212          "bom-ref": "pkg:npm/ci-info@1.6.0?package-id=55ea54d1f904bd5e",
184213          "supplier": {},
184214          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
184215          "name": "ci-info",
184216          "version": "1.6.0",
184217          "description": "Get details about the current Continuous Integration environment",
184218          "licenses": [
184219            {
184220              "license": {
184221                "id": "MIT"
184222              }
184223            }
184224          ],
184225          "cpe": "cpe:2.3:a:ci-info:ci-info:1.6.0:*:*:*:*:*:*:*",
184226          "purl": "pkg:npm/ci-info@1.6.0",
184227          "swid": {
184228            "attachment": {}
184229          },
184230          "pedigree": {},
184231          "externalReferences": [
184232            {
184233              "url": "git+https://github.com/watson/ci-info.git",
184234              "type": "distribution"
184235            },
184236            {
184237              "url": "https://github.com/watson/ci-info",
184238              "type": "website"
184239            }
184240          ],
184241          "evidence": {},
184242          "signature": {
184243            "signature": {
184244              "publicKey": {}
184245            }
184246          },
184247          "modelCard": {
184248            "modelParameters": {
184249              "approach": {}
184250            },
184251            "quantitativeAnalysis": {
184252              "graphics": {}
184253            },
184254            "considerations": {}
184255          }
184256        },
184257        {
184258          "type": "library",
184259          "bom-ref": "pkg:npm/ci-info@2.0.0?package-id=16574bf0190b83e7",
184260          "supplier": {},
184261          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
184262          "name": "ci-info",
184263          "version": "2.0.0",
184264          "description": "Get details about the current Continuous Integration environment",
184265          "licenses": [
184266            {
184267              "license": {
184268                "id": "MIT"
184269              }
184270            }
184271          ],
184272          "cpe": "cpe:2.3:a:ci-info:ci-info:2.0.0:*:*:*:*:*:*:*",
184273          "purl": "pkg:npm/ci-info@2.0.0",
184274          "swid": {
184275            "attachment": {}
184276          },
184277          "pedigree": {},
184278          "externalReferences": [
184279            {
184280              "url": "git+https://github.com/watson/ci-info.git",
184281              "type": "distribution"
184282            },
184283            {
184284              "url": "https://github.com/watson/ci-info",
184285              "type": "website"
184286            }
184287          ],
184288          "evidence": {},
184289          "signature": {
184290            "signature": {
184291              "publicKey": {}
184292            }
184293          },
184294          "modelCard": {
184295            "modelParameters": {
184296              "approach": {}
184297            },
184298            "quantitativeAnalysis": {
184299              "graphics": {}
184300            },
184301            "considerations": {}
184302          }
184303        },
184304        {
184305          "type": "library",
184306          "bom-ref": "pkg:npm/cidr-regex@2.0.10?package-id=444a2d33b9bb6cf8",
184307          "supplier": {},
184308          "author": "silverwind \u003cme@silverwind.io\u003e",
184309          "name": "cidr-regex",
184310          "version": "2.0.10",
184311          "description": "Regular expression for matching IP addresses in CIDR notation",
184312          "licenses": [
184313            {
184314              "license": {
184315                "id": "BSD-2-Clause"
184316              }
184317            }
184318          ],
184319          "cpe": "cpe:2.3:a:cidr-regex:cidr-regex:2.0.10:*:*:*:*:*:*:*",
184320          "purl": "pkg:npm/cidr-regex@2.0.10",
184321          "swid": {
184322            "attachment": {}
184323          },
184324          "pedigree": {},
184325          "externalReferences": [
184326            {
184327              "url": "git+https://github.com/silverwind/cidr-regex.git",
184328              "type": "distribution"
184329            },
184330            {
184331              "url": "https://github.com/silverwind/cidr-regex#readme",
184332              "type": "website"
184333            }
184334          ],
184335          "evidence": {},
184336          "signature": {
184337            "signature": {
184338              "publicKey": {}
184339            }
184340          },
184341          "modelCard": {
184342            "modelParameters": {
184343              "approach": {}
184344            },
184345            "quantitativeAnalysis": {
184346              "graphics": {}
184347            },
184348            "considerations": {}
184349          }
184350        },
184351        {
184352          "type": "library",
184353          "bom-ref": "pkg:npm/class-transformer@0.3.1?package-id=e7a380cceb8414d2",
184354          "supplier": {},
184355          "author": "Umed Khudoiberdiev \u003cpleerock.me@gmail.com\u003e",
184356          "name": "class-transformer",
184357          "version": "0.3.1",
184358          "description": "Proper decorator-based transformation / serialization / deserialization of plain javascript objects to class constructors",
184359          "licenses": [
184360            {
184361              "license": {
184362                "id": "MIT"
184363              }
184364            }
184365          ],
184366          "cpe": "cpe:2.3:a:class-transformer:class-transformer:0.3.1:*:*:*:*:*:*:*",
184367          "purl": "pkg:npm/class-transformer@0.3.1",
184368          "swid": {
184369            "attachment": {}
184370          },
184371          "pedigree": {},
184372          "externalReferences": [
184373            {
184374              "url": "git+https://github.com/typestack/class-transformer.git",
184375              "type": "distribution"
184376            },
184377            {
184378              "url": "https://github.com/typestack/class-transformer#readme",
184379              "type": "website"
184380            }
184381          ],
184382          "evidence": {},
184383          "signature": {
184384            "signature": {
184385              "publicKey": {}
184386            }
184387          },
184388          "modelCard": {
184389            "modelParameters": {
184390              "approach": {}
184391            },
184392            "quantitativeAnalysis": {
184393              "graphics": {}
184394            },
184395            "considerations": {}
184396          }
184397        },
184398        {
184399          "type": "library",
184400          "bom-ref": "pkg:npm/class-validator@0.12.2?package-id=c94eed0c9e7dc64a",
184401          "supplier": {},
184402          "author": "Umed Khudoiberdiev \u003cpleerock.me@gmail.com\u003e",
184403          "name": "class-validator",
184404          "version": "0.12.2",
184405          "description": "Class-based validation with Typescript / ES6 / ES5 using decorators or validation schemas. Supports both node.js and browser",
184406          "licenses": [
184407            {
184408              "license": {
184409                "id": "MIT"
184410              }
184411            }
184412          ],
184413          "cpe": "cpe:2.3:a:class-validator:class-validator:0.12.2:*:*:*:*:*:*:*",
184414          "purl": "pkg:npm/class-validator@0.12.2",
184415          "swid": {
184416            "attachment": {}
184417          },
184418          "pedigree": {},
184419          "externalReferences": [
184420            {
184421              "url": "git+https://github.com/typestack/class-validator.git",
184422              "type": "distribution"
184423            },
184424            {
184425              "url": "https://github.com/typestack/class-validator#readme",
184426              "type": "website"
184427            }
184428          ],
184429          "evidence": {},
184430          "signature": {
184431            "signature": {
184432              "publicKey": {}
184433            }
184434          },
184435          "modelCard": {
184436            "modelParameters": {
184437              "approach": {}
184438            },
184439            "quantitativeAnalysis": {
184440              "graphics": {}
184441            },
184442            "considerations": {}
184443          }
184444        },
184445        {
184446          "type": "library",
184447          "bom-ref": "pkg:npm/cli-boxes@1.0.0?package-id=9c02e7f0cdd715b7",
184448          "supplier": {},
184449          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
184450          "name": "cli-boxes",
184451          "version": "1.0.0",
184452          "description": "Boxes for use in the terminal",
184453          "licenses": [
184454            {
184455              "license": {
184456                "id": "MIT"
184457              }
184458            }
184459          ],
184460          "cpe": "cpe:2.3:a:sindresorhus:cli-boxes:1.0.0:*:*:*:*:*:*:*",
184461          "purl": "pkg:npm/cli-boxes@1.0.0",
184462          "swid": {
184463            "attachment": {}
184464          },
184465          "pedigree": {},
184466          "externalReferences": [
184467            {
184468              "url": "git+https://github.com/sindresorhus/cli-boxes.git",
184469              "type": "distribution"
184470            },
184471            {
184472              "url": "https://github.com/sindresorhus/cli-boxes#readme",
184473              "type": "website"
184474            }
184475          ],
184476          "evidence": {},
184477          "signature": {
184478            "signature": {
184479              "publicKey": {}
184480            }
184481          },
184482          "modelCard": {
184483            "modelParameters": {
184484              "approach": {}
184485            },
184486            "quantitativeAnalysis": {
184487              "graphics": {}
184488            },
184489            "considerations": {}
184490          }
184491        },
184492        {
184493          "type": "library",
184494          "bom-ref": "pkg:npm/cli-columns@3.1.2?package-id=e9543de12daa768f",
184495          "supplier": {},
184496          "author": "Shannon Moeller \u003cme@shannonmoeller\u003e (http://shannonmoeller.com)",
184497          "name": "cli-columns",
184498          "version": "3.1.2",
184499          "description": "Columnated lists for the CLI.",
184500          "licenses": [
184501            {
184502              "license": {
184503                "id": "MIT"
184504              }
184505            }
184506          ],
184507          "cpe": "cpe:2.3:a:shannonmoeller:cli-columns:3.1.2:*:*:*:*:*:*:*",
184508          "purl": "pkg:npm/cli-columns@3.1.2",
184509          "swid": {
184510            "attachment": {}
184511          },
184512          "pedigree": {},
184513          "externalReferences": [
184514            {
184515              "url": "git+https://github.com/shannonmoeller/cli-columns.git",
184516              "type": "distribution"
184517            },
184518            {
184519              "url": "https://github.com/shannonmoeller/cli-columns#readme",
184520              "type": "website"
184521            }
184522          ],
184523          "evidence": {},
184524          "signature": {
184525            "signature": {
184526              "publicKey": {}
184527            }
184528          },
184529          "modelCard": {
184530            "modelParameters": {
184531              "approach": {}
184532            },
184533            "quantitativeAnalysis": {
184534              "graphics": {}
184535            },
184536            "considerations": {}
184537          }
184538        },
184539        {
184540          "type": "library",
184541          "bom-ref": "pkg:npm/cli-table3@0.5.1?package-id=65433b3fd2fe95a6",
184542          "supplier": {},
184543          "author": "James Talmage",
184544          "name": "cli-table3",
184545          "version": "0.5.1",
184546          "description": "Pretty unicode tables for the command line. Based on the original cli-table.",
184547          "licenses": [
184548            {
184549              "license": {
184550                "id": "MIT"
184551              }
184552            }
184553          ],
184554          "cpe": "cpe:2.3:a:cli-table3:cli-table3:0.5.1:*:*:*:*:*:*:*",
184555          "purl": "pkg:npm/cli-table3@0.5.1",
184556          "swid": {
184557            "attachment": {}
184558          },
184559          "pedigree": {},
184560          "externalReferences": [
184561            {
184562              "url": "git+https://github.com/cli-table/cli-table3.git",
184563              "type": "distribution"
184564            },
184565            {
184566              "url": "https://github.com/cli-table/cli-table3",
184567              "type": "website"
184568            }
184569          ],
184570          "evidence": {},
184571          "signature": {
184572            "signature": {
184573              "publicKey": {}
184574            }
184575          },
184576          "modelCard": {
184577            "modelParameters": {
184578              "approach": {}
184579            },
184580            "quantitativeAnalysis": {
184581              "graphics": {}
184582            },
184583            "considerations": {}
184584          }
184585        },
184586        {
184587          "type": "library",
184588          "bom-ref": "pkg:npm/cliui@5.0.0?package-id=9c059219de8ff0b6",
184589          "supplier": {},
184590          "author": "Ben Coe \u003cben@npmjs.com\u003e",
184591          "name": "cliui",
184592          "version": "5.0.0",
184593          "description": "easily create complex multi-column command-line-interfaces",
184594          "licenses": [
184595            {
184596              "license": {
184597                "id": "ISC"
184598              }
184599            }
184600          ],
184601          "cpe": "cpe:2.3:a:cliui:cliui:5.0.0:*:*:*:*:*:*:*",
184602          "purl": "pkg:npm/cliui@5.0.0",
184603          "swid": {
184604            "attachment": {}
184605          },
184606          "pedigree": {},
184607          "externalReferences": [
184608            {
184609              "url": "git+ssh://git@github.com/yargs/cliui.git",
184610              "type": "distribution"
184611            },
184612            {
184613              "url": "https://github.com/yargs/cliui#readme",
184614              "type": "website"
184615            }
184616          ],
184617          "evidence": {},
184618          "signature": {
184619            "signature": {
184620              "publicKey": {}
184621            }
184622          },
184623          "modelCard": {
184624            "modelParameters": {
184625              "approach": {}
184626            },
184627            "quantitativeAnalysis": {
184628              "graphics": {}
184629            },
184630            "considerations": {}
184631          }
184632        },
184633        {
184634          "type": "library",
184635          "bom-ref": "pkg:npm/clone@1.0.4?package-id=13cad0458880c288",
184636          "supplier": {},
184637          "author": "Paul Vorbach \u003cpaul@vorba.ch\u003e (http://paul.vorba.ch/)",
184638          "name": "clone",
184639          "version": "1.0.4",
184640          "description": "deep cloning of objects and arrays",
184641          "licenses": [
184642            {
184643              "license": {
184644                "id": "MIT"
184645              }
184646            }
184647          ],
184648          "cpe": "cpe:2.3:a:clone:clone:1.0.4:*:*:*:*:*:*:*",
184649          "purl": "pkg:npm/clone@1.0.4",
184650          "swid": {
184651            "attachment": {}
184652          },
184653          "pedigree": {},
184654          "externalReferences": [
184655            {
184656              "url": "git://github.com/pvorb/node-clone.git",
184657              "type": "distribution"
184658            },
184659            {
184660              "url": "https://github.com/pvorb/node-clone#readme",
184661              "type": "website"
184662            }
184663          ],
184664          "evidence": {},
184665          "signature": {
184666            "signature": {
184667              "publicKey": {}
184668            }
184669          },
184670          "modelCard": {
184671            "modelParameters": {
184672              "approach": {}
184673            },
184674            "quantitativeAnalysis": {
184675              "graphics": {}
184676            },
184677            "considerations": {}
184678          }
184679        },
184680        {
184681          "type": "library",
184682          "bom-ref": "pkg:npm/cmd-shim@3.0.3?package-id=6d36801ba84205fb",
184683          "supplier": {},
184684          "name": "cmd-shim",
184685          "version": "3.0.3",
184686          "description": "Used in npm for command line application support",
184687          "licenses": [
184688            {
184689              "license": {
184690                "id": "ISC"
184691              }
184692            }
184693          ],
184694          "cpe": "cpe:2.3:a:cmd-shim:cmd-shim:3.0.3:*:*:*:*:*:*:*",
184695          "purl": "pkg:npm/cmd-shim@3.0.3",
184696          "swid": {
184697            "attachment": {}
184698          },
184699          "pedigree": {},
184700          "externalReferences": [
184701            {
184702              "url": "git+https://github.com/npm/cmd-shim.git",
184703              "type": "distribution"
184704            },
184705            {
184706              "url": "https://github.com/npm/cmd-shim#readme",
184707              "type": "website"
184708            }
184709          ],
184710          "evidence": {},
184711          "signature": {
184712            "signature": {
184713              "publicKey": {}
184714            }
184715          },
184716          "modelCard": {
184717            "modelParameters": {
184718              "approach": {}
184719            },
184720            "quantitativeAnalysis": {
184721              "graphics": {}
184722            },
184723            "considerations": {}
184724          }
184725        },
184726        {
184727          "type": "library",
184728          "bom-ref": "pkg:npm/code-point-at@1.1.0?package-id=cdc2db70d5aa7113",
184729          "supplier": {},
184730          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
184731          "name": "code-point-at",
184732          "version": "1.1.0",
184733          "description": "ES2015 `String#codePointAt()` ponyfill",
184734          "licenses": [
184735            {
184736              "license": {
184737                "id": "MIT"
184738              }
184739            }
184740          ],
184741          "cpe": "cpe:2.3:a:code-point-at:code-point-at:1.1.0:*:*:*:*:*:*:*",
184742          "purl": "pkg:npm/code-point-at@1.1.0",
184743          "swid": {
184744            "attachment": {}
184745          },
184746          "pedigree": {},
184747          "externalReferences": [
184748            {
184749              "url": "git+https://github.com/sindresorhus/code-point-at.git",
184750              "type": "distribution"
184751            },
184752            {
184753              "url": "https://github.com/sindresorhus/code-point-at#readme",
184754              "type": "website"
184755            }
184756          ],
184757          "evidence": {},
184758          "signature": {
184759            "signature": {
184760              "publicKey": {}
184761            }
184762          },
184763          "modelCard": {
184764            "modelParameters": {
184765              "approach": {}
184766            },
184767            "quantitativeAnalysis": {
184768              "graphics": {}
184769            },
184770            "considerations": {}
184771          }
184772        },
184773        {
184774          "type": "library",
184775          "bom-ref": "pkg:npm/color-convert@1.9.1?package-id=6a9f0408fc41f63d",
184776          "supplier": {},
184777          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
184778          "name": "color-convert",
184779          "version": "1.9.1",
184780          "description": "Plain color conversion functions",
184781          "licenses": [
184782            {
184783              "license": {
184784                "id": "MIT"
184785              }
184786            }
184787          ],
184788          "cpe": "cpe:2.3:a:color-convert:color-convert:1.9.1:*:*:*:*:*:*:*",
184789          "purl": "pkg:npm/color-convert@1.9.1",
184790          "swid": {
184791            "attachment": {}
184792          },
184793          "pedigree": {},
184794          "externalReferences": [
184795            {
184796              "url": "git+https://github.com/Qix-/color-convert.git",
184797              "type": "distribution"
184798            },
184799            {
184800              "url": "https://github.com/Qix-/color-convert#readme",
184801              "type": "website"
184802            }
184803          ],
184804          "evidence": {},
184805          "signature": {
184806            "signature": {
184807              "publicKey": {}
184808            }
184809          },
184810          "modelCard": {
184811            "modelParameters": {
184812              "approach": {}
184813            },
184814            "quantitativeAnalysis": {
184815              "graphics": {}
184816            },
184817            "considerations": {}
184818          }
184819        },
184820        {
184821          "type": "library",
184822          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=417528da04af2cd8",
184823          "supplier": {},
184824          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
184825          "name": "color-convert",
184826          "version": "2.0.1",
184827          "description": "Plain color conversion functions",
184828          "licenses": [
184829            {
184830              "license": {
184831                "id": "MIT"
184832              }
184833            }
184834          ],
184835          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
184836          "purl": "pkg:npm/color-convert@2.0.1",
184837          "swid": {
184838            "attachment": {}
184839          },
184840          "pedigree": {},
184841          "externalReferences": [
184842            {
184843              "url": "git+https://github.com/Qix-/color-convert.git",
184844              "type": "distribution"
184845            },
184846            {
184847              "url": "https://github.com/Qix-/color-convert#readme",
184848              "type": "website"
184849            }
184850          ],
184851          "evidence": {},
184852          "signature": {
184853            "signature": {
184854              "publicKey": {}
184855            }
184856          },
184857          "modelCard": {
184858            "modelParameters": {
184859              "approach": {}
184860            },
184861            "quantitativeAnalysis": {
184862              "graphics": {}
184863            },
184864            "considerations": {}
184865          }
184866        },
184867        {
184868          "type": "library",
184869          "bom-ref": "pkg:npm/color-name@1.1.3?package-id=55fdc340e318670",
184870          "supplier": {},
184871          "author": "DY \u003cdfcreative@gmail.com\u003e",
184872          "name": "color-name",
184873          "version": "1.1.3",
184874          "description": "A list of color names and its values",
184875          "licenses": [
184876            {
184877              "license": {
184878                "id": "MIT"
184879              }
184880            }
184881          ],
184882          "cpe": "cpe:2.3:a:color-name:color-name:1.1.3:*:*:*:*:*:*:*",
184883          "purl": "pkg:npm/color-name@1.1.3",
184884          "swid": {
184885            "attachment": {}
184886          },
184887          "pedigree": {},
184888          "externalReferences": [
184889            {
184890              "url": "git+ssh://git@github.com/dfcreative/color-name.git",
184891              "type": "distribution"
184892            },
184893            {
184894              "url": "https://github.com/dfcreative/color-name",
184895              "type": "website"
184896            }
184897          ],
184898          "evidence": {},
184899          "signature": {
184900            "signature": {
184901              "publicKey": {}
184902            }
184903          },
184904          "modelCard": {
184905            "modelParameters": {
184906              "approach": {}
184907            },
184908            "quantitativeAnalysis": {
184909              "graphics": {}
184910            },
184911            "considerations": {}
184912          }
184913        },
184914        {
184915          "type": "library",
184916          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=f1798456080e41f3",
184917          "supplier": {},
184918          "author": "DY \u003cdfcreative@gmail.com\u003e",
184919          "name": "color-name",
184920          "version": "1.1.4",
184921          "description": "A list of color names and its values",
184922          "licenses": [
184923            {
184924              "license": {
184925                "id": "MIT"
184926              }
184927            }
184928          ],
184929          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
184930          "purl": "pkg:npm/color-name@1.1.4",
184931          "swid": {
184932            "attachment": {}
184933          },
184934          "pedigree": {},
184935          "externalReferences": [
184936            {
184937              "url": "git+ssh://git@github.com/colorjs/color-name.git",
184938              "type": "distribution"
184939            },
184940            {
184941              "url": "https://github.com/colorjs/color-name",
184942              "type": "website"
184943            }
184944          ],
184945          "evidence": {},
184946          "signature": {
184947            "signature": {
184948              "publicKey": {}
184949            }
184950          },
184951          "modelCard": {
184952            "modelParameters": {
184953              "approach": {}
184954            },
184955            "quantitativeAnalysis": {
184956              "graphics": {}
184957            },
184958            "considerations": {}
184959          }
184960        },
184961        {
184962          "type": "library",
184963          "bom-ref": "pkg:npm/colors@1.3.3?package-id=c0b370b3fbefe8a8",
184964          "supplier": {},
184965          "author": "Marak Squires",
184966          "name": "colors",
184967          "version": "1.3.3",
184968          "description": "get colors in your node.js console",
184969          "licenses": [
184970            {
184971              "license": {
184972                "id": "MIT"
184973              }
184974            }
184975          ],
184976          "cpe": "cpe:2.3:a:colors:colors:1.3.3:*:*:*:*:*:*:*",
184977          "purl": "pkg:npm/colors@1.3.3",
184978          "swid": {
184979            "attachment": {}
184980          },
184981          "pedigree": {},
184982          "externalReferences": [
184983            {
184984              "url": "git+ssh://git@github.com/Marak/colors.js.git",
184985              "type": "distribution"
184986            },
184987            {
184988              "url": "https://github.com/Marak/colors.js",
184989              "type": "website"
184990            }
184991          ],
184992          "evidence": {},
184993          "signature": {
184994            "signature": {
184995              "publicKey": {}
184996            }
184997          },
184998          "modelCard": {
184999            "modelParameters": {
185000              "approach": {}
185001            },
185002            "quantitativeAnalysis": {
185003              "graphics": {}
185004            },
185005            "considerations": {}
185006          }
185007        },
185008        {
185009          "type": "library",
185010          "bom-ref": "pkg:npm/columnify@1.5.4?package-id=c10dc5491c1ec9ba",
185011          "supplier": {},
185012          "author": "Tim Oxley",
185013          "name": "columnify",
185014          "version": "1.5.4",
185015          "description": "Render data in text columns. Supports in-column text-wrap.",
185016          "licenses": [
185017            {
185018              "license": {
185019                "id": "MIT"
185020              }
185021            }
185022          ],
185023          "cpe": "cpe:2.3:a:columnify:columnify:1.5.4:*:*:*:*:*:*:*",
185024          "purl": "pkg:npm/columnify@1.5.4",
185025          "swid": {
185026            "attachment": {}
185027          },
185028          "pedigree": {},
185029          "externalReferences": [
185030            {
185031              "url": "git://github.com/timoxley/columnify.git",
185032              "type": "distribution"
185033            },
185034            {
185035              "url": "https://github.com/timoxley/columnify",
185036              "type": "website"
185037            }
185038          ],
185039          "evidence": {},
185040          "signature": {
185041            "signature": {
185042              "publicKey": {}
185043            }
185044          },
185045          "modelCard": {
185046            "modelParameters": {
185047              "approach": {}
185048            },
185049            "quantitativeAnalysis": {
185050              "graphics": {}
185051            },
185052            "considerations": {}
185053          }
185054        },
185055        {
185056          "type": "library",
185057          "bom-ref": "pkg:npm/combined-stream@1.0.6?package-id=40ad2220c38228d3",
185058          "supplier": {},
185059          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
185060          "name": "combined-stream",
185061          "version": "1.0.6",
185062          "description": "A stream that emits multiple other streams one after another.",
185063          "licenses": [
185064            {
185065              "license": {
185066                "id": "MIT"
185067              }
185068            }
185069          ],
185070          "cpe": "cpe:2.3:a:combined-stream:combined-stream:1.0.6:*:*:*:*:*:*:*",
185071          "purl": "pkg:npm/combined-stream@1.0.6",
185072          "swid": {
185073            "attachment": {}
185074          },
185075          "pedigree": {},
185076          "externalReferences": [
185077            {
185078              "url": "git://github.com/felixge/node-combined-stream.git",
185079              "type": "distribution"
185080            },
185081            {
185082              "url": "https://github.com/felixge/node-combined-stream",
185083              "type": "website"
185084            }
185085          ],
185086          "evidence": {},
185087          "signature": {
185088            "signature": {
185089              "publicKey": {}
185090            }
185091          },
185092          "modelCard": {
185093            "modelParameters": {
185094              "approach": {}
185095            },
185096            "quantitativeAnalysis": {
185097              "graphics": {}
185098            },
185099            "considerations": {}
185100          }
185101        },
185102        {
185103          "type": "library",
185104          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=cae0cd90b1194aad",
185105          "supplier": {},
185106          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
185107          "name": "concat-map",
185108          "version": "0.0.1",
185109          "description": "concatenative mapdashery",
185110          "licenses": [
185111            {
185112              "license": {
185113                "id": "MIT"
185114              }
185115            }
185116          ],
185117          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
185118          "purl": "pkg:npm/concat-map@0.0.1",
185119          "swid": {
185120            "attachment": {}
185121          },
185122          "pedigree": {},
185123          "externalReferences": [
185124            {
185125              "url": "git://github.com/substack/node-concat-map.git",
185126              "type": "distribution"
185127            },
185128            {
185129              "url": "https://github.com/substack/node-concat-map#readme",
185130              "type": "website"
185131            }
185132          ],
185133          "evidence": {},
185134          "signature": {
185135            "signature": {
185136              "publicKey": {}
185137            }
185138          },
185139          "modelCard": {
185140            "modelParameters": {
185141              "approach": {}
185142            },
185143            "quantitativeAnalysis": {
185144              "graphics": {}
185145            },
185146            "considerations": {}
185147          }
185148        },
185149        {
185150          "type": "library",
185151          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=329fc63deaa5be87",
185152          "supplier": {},
185153          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
185154          "name": "concat-map",
185155          "version": "0.0.1",
185156          "description": "concatenative mapdashery",
185157          "licenses": [
185158            {
185159              "license": {
185160                "id": "MIT"
185161              }
185162            }
185163          ],
185164          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
185165          "purl": "pkg:npm/concat-map@0.0.1",
185166          "swid": {
185167            "attachment": {}
185168          },
185169          "pedigree": {},
185170          "externalReferences": [
185171            {
185172              "url": "git://github.com/substack/node-concat-map.git",
185173              "type": "distribution"
185174            },
185175            {
185176              "url": "https://github.com/substack/node-concat-map#readme",
185177              "type": "website"
185178            }
185179          ],
185180          "evidence": {},
185181          "signature": {
185182            "signature": {
185183              "publicKey": {}
185184            }
185185          },
185186          "modelCard": {
185187            "modelParameters": {
185188              "approach": {}
185189            },
185190            "quantitativeAnalysis": {
185191              "graphics": {}
185192            },
185193            "considerations": {}
185194          }
185195        },
185196        {
185197          "type": "library",
185198          "bom-ref": "pkg:npm/concat-stream@1.6.2?package-id=bc1b41c56853527e",
185199          "supplier": {},
185200          "author": "Max Ogden \u003cmax@maxogden.com\u003e",
185201          "name": "concat-stream",
185202          "version": "1.6.2",
185203          "description": "writable stream that concatenates strings or binary data and calls a callback with the result",
185204          "licenses": [
185205            {
185206              "license": {
185207                "id": "MIT"
185208              }
185209            }
185210          ],
185211          "cpe": "cpe:2.3:a:concat-stream:concat-stream:1.6.2:*:*:*:*:*:*:*",
185212          "purl": "pkg:npm/concat-stream@1.6.2",
185213          "swid": {
185214            "attachment": {}
185215          },
185216          "pedigree": {},
185217          "externalReferences": [
185218            {
185219              "url": "git+ssh://git@github.com/maxogden/concat-stream.git",
185220              "type": "distribution"
185221            },
185222            {
185223              "url": "https://github.com/maxogden/concat-stream#readme",
185224              "type": "website"
185225            }
185226          ],
185227          "evidence": {},
185228          "signature": {
185229            "signature": {
185230              "publicKey": {}
185231            }
185232          },
185233          "modelCard": {
185234            "modelParameters": {
185235              "approach": {}
185236            },
185237            "quantitativeAnalysis": {
185238              "graphics": {}
185239            },
185240            "considerations": {}
185241          }
185242        },
185243        {
185244          "type": "library",
185245          "bom-ref": "pkg:npm/concat-stream@1.6.2?package-id=a6eeed3b9d53d4b7",
185246          "supplier": {},
185247          "author": "Max Ogden \u003cmax@maxogden.com\u003e",
185248          "name": "concat-stream",
185249          "version": "1.6.2",
185250          "description": "writable stream that concatenates strings or binary data and calls a callback with the result",
185251          "licenses": [
185252            {
185253              "license": {
185254                "id": "MIT"
185255              }
185256            }
185257          ],
185258          "cpe": "cpe:2.3:a:concat-stream:concat-stream:1.6.2:*:*:*:*:*:*:*",
185259          "purl": "pkg:npm/concat-stream@1.6.2",
185260          "swid": {
185261            "attachment": {}
185262          },
185263          "pedigree": {},
185264          "externalReferences": [
185265            {
185266              "url": "git+ssh://git@github.com/maxogden/concat-stream.git",
185267              "type": "distribution"
185268            },
185269            {
185270              "url": "https://github.com/maxogden/concat-stream#readme",
185271              "type": "website"
185272            }
185273          ],
185274          "evidence": {},
185275          "signature": {
185276            "signature": {
185277              "publicKey": {}
185278            }
185279          },
185280          "modelCard": {
185281            "modelParameters": {
185282              "approach": {}
185283            },
185284            "quantitativeAnalysis": {
185285              "graphics": {}
185286            },
185287            "considerations": {}
185288          }
185289        },
185290        {
185291          "type": "library",
185292          "bom-ref": "pkg:npm/config-chain@1.1.12?package-id=ab957e8b65997c1d",
185293          "supplier": {},
185294          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (http://dominictarr.com)",
185295          "name": "config-chain",
185296          "version": "1.1.12",
185297          "description": "HANDLE CONFIGURATION ONCE AND FOR ALL",
185298          "licenses": [
185299            {
185300              "license": {
185301                "id": "MIT"
185302              }
185303            }
185304          ],
185305          "cpe": "cpe:2.3:a:config-chain:config-chain:1.1.12:*:*:*:*:*:*:*",
185306          "purl": "pkg:npm/config-chain@1.1.12",
185307          "swid": {
185308            "attachment": {}
185309          },
185310          "pedigree": {},
185311          "externalReferences": [
185312            {
185313              "url": "git+https://github.com/dominictarr/config-chain.git",
185314              "type": "distribution"
185315            },
185316            {
185317              "url": "http://github.com/dominictarr/config-chain",
185318              "type": "website"
185319            }
185320          ],
185321          "evidence": {},
185322          "signature": {
185323            "signature": {
185324              "publicKey": {}
185325            }
185326          },
185327          "modelCard": {
185328            "modelParameters": {
185329              "approach": {}
185330            },
185331            "quantitativeAnalysis": {
185332              "graphics": {}
185333            },
185334            "considerations": {}
185335          }
185336        },
185337        {
185338          "type": "library",
185339          "bom-ref": "pkg:npm/configstore@3.1.5?package-id=cbe4550eb45f019",
185340          "supplier": {},
185341          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
185342          "name": "configstore",
185343          "version": "3.1.5",
185344          "description": "Easily load and save config without having to think about where and how",
185345          "licenses": [
185346            {
185347              "license": {
185348                "id": "BSD-2-Clause"
185349              }
185350            }
185351          ],
185352          "cpe": "cpe:2.3:a:configstore:configstore:3.1.5:*:*:*:*:*:*:*",
185353          "purl": "pkg:npm/configstore@3.1.5",
185354          "swid": {
185355            "attachment": {}
185356          },
185357          "pedigree": {},
185358          "externalReferences": [
185359            {
185360              "url": "git+https://github.com/yeoman/configstore.git",
185361              "type": "distribution"
185362            },
185363            {
185364              "url": "https://github.com/yeoman/configstore#readme",
185365              "type": "website"
185366            }
185367          ],
185368          "evidence": {},
185369          "signature": {
185370            "signature": {
185371              "publicKey": {}
185372            }
185373          },
185374          "modelCard": {
185375            "modelParameters": {
185376              "approach": {}
185377            },
185378            "quantitativeAnalysis": {
185379              "graphics": {}
185380            },
185381            "considerations": {}
185382          }
185383        },
185384        {
185385          "type": "library",
185386          "bom-ref": "pkg:npm/consola@2.15.3?package-id=9b03a0585128a93a",
185387          "supplier": {},
185388          "name": "consola",
185389          "version": "2.15.3",
185390          "description": "Elegant Console Logger for Node.js and Browser",
185391          "licenses": [
185392            {
185393              "license": {
185394                "id": "MIT"
185395              }
185396            }
185397          ],
185398          "cpe": "cpe:2.3:a:consola:consola:2.15.3:*:*:*:*:*:*:*",
185399          "purl": "pkg:npm/consola@2.15.3",
185400          "swid": {
185401            "attachment": {}
185402          },
185403          "pedigree": {},
185404          "externalReferences": [
185405            {
185406              "url": "git+https://github.com/nuxt/consola.git",
185407              "type": "distribution"
185408            },
185409            {
185410              "url": "https://github.com/nuxt/consola#readme",
185411              "type": "website"
185412            }
185413          ],
185414          "evidence": {},
185415          "signature": {
185416            "signature": {
185417              "publicKey": {}
185418            }
185419          },
185420          "modelCard": {
185421            "modelParameters": {
185422              "approach": {}
185423            },
185424            "quantitativeAnalysis": {
185425              "graphics": {}
185426            },
185427            "considerations": {}
185428          }
185429        },
185430        {
185431          "type": "library",
185432          "bom-ref": "pkg:npm/console-control-strings@1.1.0?package-id=40a4233e59daf424",
185433          "supplier": {},
185434          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
185435          "name": "console-control-strings",
185436          "version": "1.1.0",
185437          "description": "A library of cross-platform tested terminal/console command strings for doing things like color and cursor positioning.  This is a subset of both ansi and vt100.  All control codes included work on both Windows \u0026 Unix-like OSes, except where noted.",
185438          "licenses": [
185439            {
185440              "license": {
185441                "id": "ISC"
185442              }
185443            }
185444          ],
185445          "cpe": "cpe:2.3:a:console-control-strings:console-control-strings:1.1.0:*:*:*:*:*:*:*",
185446          "purl": "pkg:npm/console-control-strings@1.1.0",
185447          "swid": {
185448            "attachment": {}
185449          },
185450          "pedigree": {},
185451          "externalReferences": [
185452            {
185453              "url": "git+https://github.com/iarna/console-control-strings.git",
185454              "type": "distribution"
185455            },
185456            {
185457              "url": "https://github.com/iarna/console-control-strings#readme",
185458              "type": "website"
185459            }
185460          ],
185461          "evidence": {},
185462          "signature": {
185463            "signature": {
185464              "publicKey": {}
185465            }
185466          },
185467          "modelCard": {
185468            "modelParameters": {
185469              "approach": {}
185470            },
185471            "quantitativeAnalysis": {
185472              "graphics": {}
185473            },
185474            "considerations": {}
185475          }
185476        },
185477        {
185478          "type": "library",
185479          "bom-ref": "pkg:npm/content-disposition@0.5.3?package-id=9818af4848590460",
185480          "supplier": {},
185481          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
185482          "name": "content-disposition",
185483          "version": "0.5.3",
185484          "description": "Create and parse Content-Disposition header",
185485          "licenses": [
185486            {
185487              "license": {
185488                "id": "MIT"
185489              }
185490            }
185491          ],
185492          "cpe": "cpe:2.3:a:content-disposition:content-disposition:0.5.3:*:*:*:*:*:*:*",
185493          "purl": "pkg:npm/content-disposition@0.5.3",
185494          "swid": {
185495            "attachment": {}
185496          },
185497          "pedigree": {},
185498          "externalReferences": [
185499            {
185500              "url": "git+https://github.com/jshttp/content-disposition.git",
185501              "type": "distribution"
185502            },
185503            {
185504              "url": "https://github.com/jshttp/content-disposition#readme",
185505              "type": "website"
185506            }
185507          ],
185508          "evidence": {},
185509          "signature": {
185510            "signature": {
185511              "publicKey": {}
185512            }
185513          },
185514          "modelCard": {
185515            "modelParameters": {
185516              "approach": {}
185517            },
185518            "quantitativeAnalysis": {
185519              "graphics": {}
185520            },
185521            "considerations": {}
185522          }
185523        },
185524        {
185525          "type": "library",
185526          "bom-ref": "pkg:npm/content-type@1.0.4?package-id=e516a2b57e9346c6",
185527          "supplier": {},
185528          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
185529          "name": "content-type",
185530          "version": "1.0.4",
185531          "description": "Create and parse HTTP Content-Type header",
185532          "licenses": [
185533            {
185534              "license": {
185535                "id": "MIT"
185536              }
185537            }
185538          ],
185539          "cpe": "cpe:2.3:a:content-type:content-type:1.0.4:*:*:*:*:*:*:*",
185540          "purl": "pkg:npm/content-type@1.0.4",
185541          "swid": {
185542            "attachment": {}
185543          },
185544          "pedigree": {},
185545          "externalReferences": [
185546            {
185547              "url": "git+https://github.com/jshttp/content-type.git",
185548              "type": "distribution"
185549            },
185550            {
185551              "url": "https://github.com/jshttp/content-type#readme",
185552              "type": "website"
185553            }
185554          ],
185555          "evidence": {},
185556          "signature": {
185557            "signature": {
185558              "publicKey": {}
185559            }
185560          },
185561          "modelCard": {
185562            "modelParameters": {
185563              "approach": {}
185564            },
185565            "quantitativeAnalysis": {
185566              "graphics": {}
185567            },
185568            "considerations": {}
185569          }
185570        },
185571        {
185572          "type": "library",
185573          "bom-ref": "pkg:npm/cookie@0.4.0?package-id=5fac5f18e7a1cc19",
185574          "supplier": {},
185575          "author": "Roman Shtylman \u003cshtylman@gmail.com\u003e",
185576          "name": "cookie",
185577          "version": "0.4.0",
185578          "description": "HTTP server cookie parsing and serialization",
185579          "licenses": [
185580            {
185581              "license": {
185582                "id": "MIT"
185583              }
185584            }
185585          ],
185586          "cpe": "cpe:2.3:a:cookie:cookie:0.4.0:*:*:*:*:*:*:*",
185587          "purl": "pkg:npm/cookie@0.4.0",
185588          "swid": {
185589            "attachment": {}
185590          },
185591          "pedigree": {},
185592          "externalReferences": [
185593            {
185594              "url": "git+https://github.com/jshttp/cookie.git",
185595              "type": "distribution"
185596            },
185597            {
185598              "url": "https://github.com/jshttp/cookie#readme",
185599              "type": "website"
185600            }
185601          ],
185602          "evidence": {},
185603          "signature": {
185604            "signature": {
185605              "publicKey": {}
185606            }
185607          },
185608          "modelCard": {
185609            "modelParameters": {
185610              "approach": {}
185611            },
185612            "quantitativeAnalysis": {
185613              "graphics": {}
185614            },
185615            "considerations": {}
185616          }
185617        },
185618        {
185619          "type": "library",
185620          "bom-ref": "pkg:npm/cookie@0.4.2?package-id=e48014f93b9ab851",
185621          "supplier": {},
185622          "author": "Roman Shtylman \u003cshtylman@gmail.com\u003e",
185623          "name": "cookie",
185624          "version": "0.4.2",
185625          "description": "HTTP server cookie parsing and serialization",
185626          "licenses": [
185627            {
185628              "license": {
185629                "id": "MIT"
185630              }
185631            }
185632          ],
185633          "cpe": "cpe:2.3:a:cookie:cookie:0.4.2:*:*:*:*:*:*:*",
185634          "purl": "pkg:npm/cookie@0.4.2",
185635          "swid": {
185636            "attachment": {}
185637          },
185638          "pedigree": {},
185639          "externalReferences": [
185640            {
185641              "url": "git+https://github.com/jshttp/cookie.git",
185642              "type": "distribution"
185643            },
185644            {
185645              "url": "https://github.com/jshttp/cookie#readme",
185646              "type": "website"
185647            }
185648          ],
185649          "evidence": {},
185650          "signature": {
185651            "signature": {
185652              "publicKey": {}
185653            }
185654          },
185655          "modelCard": {
185656            "modelParameters": {
185657              "approach": {}
185658            },
185659            "quantitativeAnalysis": {
185660              "graphics": {}
185661            },
185662            "considerations": {}
185663          }
185664        },
185665        {
185666          "type": "library",
185667          "bom-ref": "pkg:npm/cookie-signature@1.0.6?package-id=a948a26643209509",
185668          "supplier": {},
185669          "author": "TJ Holowaychuk \u003ctj@learnboost.com\u003e",
185670          "name": "cookie-signature",
185671          "version": "1.0.6",
185672          "description": "Sign and unsign cookies",
185673          "licenses": [
185674            {
185675              "license": {
185676                "id": "MIT"
185677              }
185678            }
185679          ],
185680          "cpe": "cpe:2.3:a:cookie-signature:cookie-signature:1.0.6:*:*:*:*:*:*:*",
185681          "purl": "pkg:npm/cookie-signature@1.0.6",
185682          "swid": {
185683            "attachment": {}
185684          },
185685          "pedigree": {},
185686          "externalReferences": [
185687            {
185688              "url": "git+https://github.com/visionmedia/node-cookie-signature.git",
185689              "type": "distribution"
185690            },
185691            {
185692              "url": "https://github.com/visionmedia/node-cookie-signature#readme",
185693              "type": "website"
185694            }
185695          ],
185696          "evidence": {},
185697          "signature": {
185698            "signature": {
185699              "publicKey": {}
185700            }
185701          },
185702          "modelCard": {
185703            "modelParameters": {
185704              "approach": {}
185705            },
185706            "quantitativeAnalysis": {
185707              "graphics": {}
185708            },
185709            "considerations": {}
185710          }
185711        },
185712        {
185713          "type": "library",
185714          "bom-ref": "pkg:npm/copy-concurrently@1.0.5?package-id=edf05ca839b08cd4",
185715          "supplier": {},
185716          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
185717          "name": "copy-concurrently",
185718          "version": "1.0.5",
185719          "description": "Promises of copies of files, directories and symlinks, with concurrency controls and win32 junction fallback.",
185720          "licenses": [
185721            {
185722              "license": {
185723                "id": "ISC"
185724              }
185725            }
185726          ],
185727          "cpe": "cpe:2.3:a:copy-concurrently:copy-concurrently:1.0.5:*:*:*:*:*:*:*",
185728          "purl": "pkg:npm/copy-concurrently@1.0.5",
185729          "swid": {
185730            "attachment": {}
185731          },
185732          "pedigree": {},
185733          "externalReferences": [
185734            {
185735              "url": "git+https://github.com/npm/copy-concurrently.git",
185736              "type": "distribution"
185737            },
185738            {
185739              "url": "https://www.npmjs.com/package/copy-concurrently",
185740              "type": "website"
185741            }
185742          ],
185743          "evidence": {},
185744          "signature": {
185745            "signature": {
185746              "publicKey": {}
185747            }
185748          },
185749          "modelCard": {
185750            "modelParameters": {
185751              "approach": {}
185752            },
185753            "quantitativeAnalysis": {
185754              "graphics": {}
185755            },
185756            "considerations": {}
185757          }
185758        },
185759        {
185760          "type": "library",
185761          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=88273ea59dd04956",
185762          "supplier": {},
185763          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
185764          "name": "core-util-is",
185765          "version": "1.0.2",
185766          "description": "The `util.is*` functions introduced in Node v0.12.",
185767          "licenses": [
185768            {
185769              "license": {
185770                "id": "MIT"
185771              }
185772            }
185773          ],
185774          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
185775          "purl": "pkg:npm/core-util-is@1.0.2",
185776          "swid": {
185777            "attachment": {}
185778          },
185779          "pedigree": {},
185780          "externalReferences": [
185781            {
185782              "url": "git://github.com/isaacs/core-util-is.git",
185783              "type": "distribution"
185784            },
185785            {
185786              "url": "https://github.com/isaacs/core-util-is#readme",
185787              "type": "website"
185788            }
185789          ],
185790          "evidence": {},
185791          "signature": {
185792            "signature": {
185793              "publicKey": {}
185794            }
185795          },
185796          "modelCard": {
185797            "modelParameters": {
185798              "approach": {}
185799            },
185800            "quantitativeAnalysis": {
185801              "graphics": {}
185802            },
185803            "considerations": {}
185804          }
185805        },
185806        {
185807          "type": "library",
185808          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=c0eb72d0948fdcd7",
185809          "supplier": {},
185810          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
185811          "name": "core-util-is",
185812          "version": "1.0.2",
185813          "description": "The `util.is*` functions introduced in Node v0.12.",
185814          "licenses": [
185815            {
185816              "license": {
185817                "id": "MIT"
185818              }
185819            }
185820          ],
185821          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
185822          "purl": "pkg:npm/core-util-is@1.0.2",
185823          "swid": {
185824            "attachment": {}
185825          },
185826          "pedigree": {},
185827          "externalReferences": [
185828            {
185829              "url": "git://github.com/isaacs/core-util-is.git",
185830              "type": "distribution"
185831            },
185832            {
185833              "url": "https://github.com/isaacs/core-util-is#readme",
185834              "type": "website"
185835            }
185836          ],
185837          "evidence": {},
185838          "signature": {
185839            "signature": {
185840              "publicKey": {}
185841            }
185842          },
185843          "modelCard": {
185844            "modelParameters": {
185845              "approach": {}
185846            },
185847            "quantitativeAnalysis": {
185848              "graphics": {}
185849            },
185850            "considerations": {}
185851          }
185852        },
185853        {
185854          "type": "library",
185855          "bom-ref": "pkg:npm/corepack@0.15.1?package-id=ceed1cd3d200ed93",
185856          "supplier": {},
185857          "name": "corepack",
185858          "version": "0.15.1",
185859          "licenses": [
185860            {
185861              "license": {
185862                "id": "MIT"
185863              }
185864            }
185865          ],
185866          "cpe": "cpe:2.3:a:corepack:corepack:0.15.1:*:*:*:*:*:*:*",
185867          "purl": "pkg:npm/corepack@0.15.1",
185868          "swid": {
185869            "attachment": {}
185870          },
185871          "pedigree": {},
185872          "externalReferences": [
185873            {
185874              "url": "https://github.com/nodejs/corepack.git",
185875              "type": "distribution"
185876            },
185877            {
185878              "url": "https://github.com/nodejs/corepack#readme",
185879              "type": "website"
185880            }
185881          ],
185882          "evidence": {},
185883          "signature": {
185884            "signature": {
185885              "publicKey": {}
185886            }
185887          },
185888          "modelCard": {
185889            "modelParameters": {
185890              "approach": {}
185891            },
185892            "quantitativeAnalysis": {
185893              "graphics": {}
185894            },
185895            "considerations": {}
185896          }
185897        },
185898        {
185899          "type": "library",
185900          "bom-ref": "pkg:npm/cors@2.8.5?package-id=9e15e0015d5f6152",
185901          "supplier": {},
185902          "author": "Troy Goode \u003ctroygoode@gmail.com\u003e (https://github.com/troygoode/)",
185903          "name": "cors",
185904          "version": "2.8.5",
185905          "description": "Node.js CORS middleware",
185906          "licenses": [
185907            {
185908              "license": {
185909                "id": "MIT"
185910              }
185911            }
185912          ],
185913          "cpe": "cpe:2.3:a:expressjs:cors:2.8.5:*:*:*:*:*:*:*",
185914          "purl": "pkg:npm/cors@2.8.5",
185915          "swid": {
185916            "attachment": {}
185917          },
185918          "pedigree": {},
185919          "externalReferences": [
185920            {
185921              "url": "git+https://github.com/expressjs/cors.git",
185922              "type": "distribution"
185923            },
185924            {
185925              "url": "https://github.com/expressjs/cors#readme",
185926              "type": "website"
185927            }
185928          ],
185929          "evidence": {},
185930          "signature": {
185931            "signature": {
185932              "publicKey": {}
185933            }
185934          },
185935          "modelCard": {
185936            "modelParameters": {
185937              "approach": {}
185938            },
185939            "quantitativeAnalysis": {
185940              "graphics": {}
185941            },
185942            "considerations": {}
185943          }
185944        },
185945        {
185946          "type": "library",
185947          "bom-ref": "pkg:npm/create-error-class@3.0.2?package-id=bf8293b4fe00649d",
185948          "supplier": {},
185949          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
185950          "name": "create-error-class",
185951          "version": "3.0.2",
185952          "description": "Create Error classes",
185953          "licenses": [
185954            {
185955              "license": {
185956                "id": "MIT"
185957              }
185958            }
185959          ],
185960          "cpe": "cpe:2.3:a:create-error-class:create-error-class:3.0.2:*:*:*:*:*:*:*",
185961          "purl": "pkg:npm/create-error-class@3.0.2",
185962          "swid": {
185963            "attachment": {}
185964          },
185965          "pedigree": {},
185966          "externalReferences": [
185967            {
185968              "url": "git+https://github.com/floatdrop/create-error-class.git",
185969              "type": "distribution"
185970            },
185971            {
185972              "url": "https://github.com/floatdrop/create-error-class#readme",
185973              "type": "website"
185974            }
185975          ],
185976          "evidence": {},
185977          "signature": {
185978            "signature": {
185979              "publicKey": {}
185980            }
185981          },
185982          "modelCard": {
185983            "modelParameters": {
185984              "approach": {}
185985            },
185986            "quantitativeAnalysis": {
185987              "graphics": {}
185988            },
185989            "considerations": {}
185990          }
185991        },
185992        {
185993          "type": "library",
185994          "bom-ref": "pkg:npm/cross-spawn@5.1.0?package-id=61672b0d32e13073",
185995          "supplier": {},
185996          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
185997          "name": "cross-spawn",
185998          "version": "5.1.0",
185999          "description": "Cross platform child_process#spawn and child_process#spawnSync",
186000          "licenses": [
186001            {
186002              "license": {
186003                "id": "MIT"
186004              }
186005            }
186006          ],
186007          "cpe": "cpe:2.3:a:IndigoUnited:cross-spawn:5.1.0:*:*:*:*:*:*:*",
186008          "purl": "pkg:npm/cross-spawn@5.1.0",
186009          "swid": {
186010            "attachment": {}
186011          },
186012          "pedigree": {},
186013          "externalReferences": [
186014            {
186015              "url": "git://github.com/IndigoUnited/node-cross-spawn.git",
186016              "type": "distribution"
186017            },
186018            {
186019              "url": "https://github.com/IndigoUnited/node-cross-spawn#readme",
186020              "type": "website"
186021            }
186022          ],
186023          "evidence": {},
186024          "signature": {
186025            "signature": {
186026              "publicKey": {}
186027            }
186028          },
186029          "modelCard": {
186030            "modelParameters": {
186031              "approach": {}
186032            },
186033            "quantitativeAnalysis": {
186034              "graphics": {}
186035            },
186036            "considerations": {}
186037          }
186038        },
186039        {
186040          "type": "library",
186041          "bom-ref": "pkg:npm/crypto-random-string@1.0.0?package-id=e95397a312b450f1",
186042          "supplier": {},
186043          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
186044          "name": "crypto-random-string",
186045          "version": "1.0.0",
186046          "description": "Generate a cryptographically strong random string",
186047          "licenses": [
186048            {
186049              "license": {
186050                "id": "MIT"
186051              }
186052            }
186053          ],
186054          "cpe": "cpe:2.3:a:crypto-random-string:crypto-random-string:1.0.0:*:*:*:*:*:*:*",
186055          "purl": "pkg:npm/crypto-random-string@1.0.0",
186056          "swid": {
186057            "attachment": {}
186058          },
186059          "pedigree": {},
186060          "externalReferences": [
186061            {
186062              "url": "git+https://github.com/sindresorhus/crypto-random-string.git",
186063              "type": "distribution"
186064            },
186065            {
186066              "url": "https://github.com/sindresorhus/crypto-random-string#readme",
186067              "type": "website"
186068            }
186069          ],
186070          "evidence": {},
186071          "signature": {
186072            "signature": {
186073              "publicKey": {}
186074            }
186075          },
186076          "modelCard": {
186077            "modelParameters": {
186078              "approach": {}
186079            },
186080            "quantitativeAnalysis": {
186081              "graphics": {}
186082            },
186083            "considerations": {}
186084          }
186085        },
186086        {
186087          "type": "library",
186088          "bom-ref": "pkg:npm/cyclist@0.2.2?package-id=f1897ed52fc1db0d",
186089          "supplier": {},
186090          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
186091          "name": "cyclist",
186092          "version": "0.2.2",
186093          "description": "Cyclist is an efficient cyclic list implemention.",
186094          "cpe": "cpe:2.3:a:mafintosh:cyclist:0.2.2:*:*:*:*:*:*:*",
186095          "purl": "pkg:npm/cyclist@0.2.2",
186096          "swid": {
186097            "attachment": {}
186098          },
186099          "pedigree": {},
186100          "externalReferences": [
186101            {
186102              "url": "git://github.com/mafintosh/cyclist.git",
186103              "type": "distribution"
186104            },
186105            {
186106              "url": "https://github.com/mafintosh/cyclist#readme",
186107              "type": "website"
186108            }
186109          ],
186110          "evidence": {},
186111          "signature": {
186112            "signature": {
186113              "publicKey": {}
186114            }
186115          },
186116          "modelCard": {
186117            "modelParameters": {
186118              "approach": {}
186119            },
186120            "quantitativeAnalysis": {
186121              "graphics": {}
186122            },
186123            "considerations": {}
186124          }
186125        },
186126        {
186127          "type": "library",
186128          "bom-ref": "pkg:npm/dashdash@1.14.1?package-id=d46834cee3b39d41",
186129          "supplier": {},
186130          "author": "Trent Mick \u003ctrentm@gmail.com\u003e (http://trentm.com)",
186131          "name": "dashdash",
186132          "version": "1.14.1",
186133          "description": "A light, featureful and explicit option parsing library.",
186134          "licenses": [
186135            {
186136              "license": {
186137                "id": "MIT"
186138              }
186139            }
186140          ],
186141          "cpe": "cpe:2.3:a:dashdash:dashdash:1.14.1:*:*:*:*:*:*:*",
186142          "purl": "pkg:npm/dashdash@1.14.1",
186143          "swid": {
186144            "attachment": {}
186145          },
186146          "pedigree": {},
186147          "externalReferences": [
186148            {
186149              "url": "git://github.com/trentm/node-dashdash.git",
186150              "type": "distribution"
186151            },
186152            {
186153              "url": "https://github.com/trentm/node-dashdash#readme",
186154              "type": "website"
186155            }
186156          ],
186157          "evidence": {},
186158          "signature": {
186159            "signature": {
186160              "publicKey": {}
186161            }
186162          },
186163          "modelCard": {
186164            "modelParameters": {
186165              "approach": {}
186166            },
186167            "quantitativeAnalysis": {
186168              "graphics": {}
186169            },
186170            "considerations": {}
186171          }
186172        },
186173        {
186174          "type": "library",
186175          "bom-ref": "pkg:npm/debug@2.6.9?package-id=eaa4bb0dd0b61ab6",
186176          "supplier": {},
186177          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
186178          "name": "debug",
186179          "version": "2.6.9",
186180          "description": "small debugging utility",
186181          "licenses": [
186182            {
186183              "license": {
186184                "id": "MIT"
186185              }
186186            }
186187          ],
186188          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
186189          "purl": "pkg:npm/debug@2.6.9",
186190          "swid": {
186191            "attachment": {}
186192          },
186193          "pedigree": {},
186194          "externalReferences": [
186195            {
186196              "url": "git://github.com/visionmedia/debug.git",
186197              "type": "distribution"
186198            },
186199            {
186200              "url": "https://github.com/visionmedia/debug#readme",
186201              "type": "website"
186202            }
186203          ],
186204          "evidence": {},
186205          "signature": {
186206            "signature": {
186207              "publicKey": {}
186208            }
186209          },
186210          "modelCard": {
186211            "modelParameters": {
186212              "approach": {}
186213            },
186214            "quantitativeAnalysis": {
186215              "graphics": {}
186216            },
186217            "considerations": {}
186218          }
186219        },
186220        {
186221          "type": "library",
186222          "bom-ref": "pkg:npm/debug@3.1.0?package-id=6cd8fab77e7f9acc",
186223          "supplier": {},
186224          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
186225          "name": "debug",
186226          "version": "3.1.0",
186227          "description": "small debugging utility",
186228          "licenses": [
186229            {
186230              "license": {
186231                "id": "MIT"
186232              }
186233            }
186234          ],
186235          "cpe": "cpe:2.3:a:visionmedia:debug:3.1.0:*:*:*:*:*:*:*",
186236          "purl": "pkg:npm/debug@3.1.0",
186237          "swid": {
186238            "attachment": {}
186239          },
186240          "pedigree": {},
186241          "externalReferences": [
186242            {
186243              "url": "git://github.com/visionmedia/debug.git",
186244              "type": "distribution"
186245            },
186246            {
186247              "url": "https://github.com/visionmedia/debug#readme",
186248              "type": "website"
186249            }
186250          ],
186251          "evidence": {},
186252          "signature": {
186253            "signature": {
186254              "publicKey": {}
186255            }
186256          },
186257          "modelCard": {
186258            "modelParameters": {
186259              "approach": {}
186260            },
186261            "quantitativeAnalysis": {
186262              "graphics": {}
186263            },
186264            "considerations": {}
186265          }
186266        },
186267        {
186268          "type": "library",
186269          "bom-ref": "pkg:npm/debug@4.3.1?package-id=c8e552beb88cc156",
186270          "supplier": {},
186271          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
186272          "name": "debug",
186273          "version": "4.3.1",
186274          "description": "small debugging utility",
186275          "licenses": [
186276            {
186277              "license": {
186278                "id": "MIT"
186279              }
186280            }
186281          ],
186282          "cpe": "cpe:2.3:a:visionmedia:debug:4.3.1:*:*:*:*:*:*:*",
186283          "purl": "pkg:npm/debug@4.3.1",
186284          "swid": {
186285            "attachment": {}
186286          },
186287          "pedigree": {},
186288          "externalReferences": [
186289            {
186290              "url": "git://github.com/visionmedia/debug.git",
186291              "type": "distribution"
186292            },
186293            {
186294              "url": "https://github.com/visionmedia/debug#readme",
186295              "type": "website"
186296            }
186297          ],
186298          "evidence": {},
186299          "signature": {
186300            "signature": {
186301              "publicKey": {}
186302            }
186303          },
186304          "modelCard": {
186305            "modelParameters": {
186306              "approach": {}
186307            },
186308            "quantitativeAnalysis": {
186309              "graphics": {}
186310            },
186311            "considerations": {}
186312          }
186313        },
186314        {
186315          "type": "library",
186316          "bom-ref": "pkg:npm/debug@4.3.4?package-id=d53d67056f050b4c",
186317          "supplier": {},
186318          "author": "Josh Junon \u003cjosh.junon@protonmail.com\u003e",
186319          "name": "debug",
186320          "version": "4.3.4",
186321          "description": "Lightweight debugging utility for Node.js and the browser",
186322          "licenses": [
186323            {
186324              "license": {
186325                "id": "MIT"
186326              }
186327            }
186328          ],
186329          "cpe": "cpe:2.3:a:debug-js:debug:4.3.4:*:*:*:*:*:*:*",
186330          "purl": "pkg:npm/debug@4.3.4",
186331          "swid": {
186332            "attachment": {}
186333          },
186334          "pedigree": {},
186335          "externalReferences": [
186336            {
186337              "url": "git://github.com/debug-js/debug.git",
186338              "type": "distribution"
186339            },
186340            {
186341              "url": "https://github.com/debug-js/debug#readme",
186342              "type": "website"
186343            }
186344          ],
186345          "evidence": {},
186346          "signature": {
186347            "signature": {
186348              "publicKey": {}
186349            }
186350          },
186351          "modelCard": {
186352            "modelParameters": {
186353              "approach": {}
186354            },
186355            "quantitativeAnalysis": {
186356              "graphics": {}
186357            },
186358            "considerations": {}
186359          }
186360        },
186361        {
186362          "type": "library",
186363          "bom-ref": "pkg:npm/debug@4.3.4?package-id=5842283db096bc55",
186364          "supplier": {},
186365          "author": "Josh Junon \u003cjosh.junon@protonmail.com\u003e",
186366          "name": "debug",
186367          "version": "4.3.4",
186368          "description": "Lightweight debugging utility for Node.js and the browser",
186369          "licenses": [
186370            {
186371              "license": {
186372                "id": "MIT"
186373              }
186374            }
186375          ],
186376          "cpe": "cpe:2.3:a:debug-js:debug:4.3.4:*:*:*:*:*:*:*",
186377          "purl": "pkg:npm/debug@4.3.4",
186378          "swid": {
186379            "attachment": {}
186380          },
186381          "pedigree": {},
186382          "externalReferences": [
186383            {
186384              "url": "git://github.com/debug-js/debug.git",
186385              "type": "distribution"
186386            },
186387            {
186388              "url": "https://github.com/debug-js/debug#readme",
186389              "type": "website"
186390            }
186391          ],
186392          "evidence": {},
186393          "signature": {
186394            "signature": {
186395              "publicKey": {}
186396            }
186397          },
186398          "modelCard": {
186399            "modelParameters": {
186400              "approach": {}
186401            },
186402            "quantitativeAnalysis": {
186403              "graphics": {}
186404            },
186405            "considerations": {}
186406          }
186407        },
186408        {
186409          "type": "library",
186410          "bom-ref": "pkg:npm/debuglog@1.0.1?package-id=abf6b1b40c49bc95",
186411          "supplier": {},
186412          "author": "Sam Roberts \u003csam@strongloop.com\u003e",
186413          "name": "debuglog",
186414          "version": "1.0.1",
186415          "description": "backport of util.debuglog from node v0.11",
186416          "licenses": [
186417            {
186418              "license": {
186419                "id": "MIT"
186420              }
186421            }
186422          ],
186423          "cpe": "cpe:2.3:a:sam-github:debuglog:1.0.1:*:*:*:*:*:*:*",
186424          "purl": "pkg:npm/debuglog@1.0.1",
186425          "swid": {
186426            "attachment": {}
186427          },
186428          "pedigree": {},
186429          "externalReferences": [
186430            {
186431              "url": "git+https://github.com/sam-github/node-debuglog.git",
186432              "type": "distribution"
186433            },
186434            {
186435              "url": "https://github.com/sam-github/node-debuglog#readme",
186436              "type": "website"
186437            }
186438          ],
186439          "evidence": {},
186440          "signature": {
186441            "signature": {
186442              "publicKey": {}
186443            }
186444          },
186445          "modelCard": {
186446            "modelParameters": {
186447              "approach": {}
186448            },
186449            "quantitativeAnalysis": {
186450              "graphics": {}
186451            },
186452            "considerations": {}
186453          }
186454        },
186455        {
186456          "type": "library",
186457          "bom-ref": "pkg:npm/decamelize@1.2.0?package-id=ad1f772c12d9a9f",
186458          "supplier": {},
186459          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
186460          "name": "decamelize",
186461          "version": "1.2.0",
186462          "description": "Convert a camelized string into a lowercased one with a custom separator: unicornRainbow → unicorn_rainbow",
186463          "licenses": [
186464            {
186465              "license": {
186466                "id": "MIT"
186467              }
186468            }
186469          ],
186470          "cpe": "cpe:2.3:a:sindresorhus:decamelize:1.2.0:*:*:*:*:*:*:*",
186471          "purl": "pkg:npm/decamelize@1.2.0",
186472          "swid": {
186473            "attachment": {}
186474          },
186475          "pedigree": {},
186476          "externalReferences": [
186477            {
186478              "url": "git+https://github.com/sindresorhus/decamelize.git",
186479              "type": "distribution"
186480            },
186481            {
186482              "url": "https://github.com/sindresorhus/decamelize#readme",
186483              "type": "website"
186484            }
186485          ],
186486          "evidence": {},
186487          "signature": {
186488            "signature": {
186489              "publicKey": {}
186490            }
186491          },
186492          "modelCard": {
186493            "modelParameters": {
186494              "approach": {}
186495            },
186496            "quantitativeAnalysis": {
186497              "graphics": {}
186498            },
186499            "considerations": {}
186500          }
186501        },
186502        {
186503          "type": "library",
186504          "bom-ref": "pkg:npm/decode-uri-component@0.2.0?package-id=b9c7ee4cc85ee60c",
186505          "supplier": {},
186506          "author": "Sam Verschueren \u003csam.verschueren@gmail.com\u003e (github.com/SamVerschueren)",
186507          "name": "decode-uri-component",
186508          "version": "0.2.0",
186509          "description": "A better decodeURIComponent",
186510          "licenses": [
186511            {
186512              "license": {
186513                "id": "MIT"
186514              }
186515            }
186516          ],
186517          "cpe": "cpe:2.3:a:decode-uri-component:decode-uri-component:0.2.0:*:*:*:*:*:*:*",
186518          "purl": "pkg:npm/decode-uri-component@0.2.0",
186519          "swid": {
186520            "attachment": {}
186521          },
186522          "pedigree": {},
186523          "externalReferences": [
186524            {
186525              "url": "git+https://github.com/SamVerschueren/decode-uri-component.git",
186526              "type": "distribution"
186527            },
186528            {
186529              "url": "https://github.com/SamVerschueren/decode-uri-component#readme",
186530              "type": "website"
186531            }
186532          ],
186533          "evidence": {},
186534          "signature": {
186535            "signature": {
186536              "publicKey": {}
186537            }
186538          },
186539          "modelCard": {
186540            "modelParameters": {
186541              "approach": {}
186542            },
186543            "quantitativeAnalysis": {
186544              "graphics": {}
186545            },
186546            "considerations": {}
186547          }
186548        },
186549        {
186550          "type": "library",
186551          "bom-ref": "pkg:npm/deep-extend@0.6.0?package-id=249a5a2e595cbcf5",
186552          "supplier": {},
186553          "author": "Viacheslav Lotsmanov \u003clotsmanov89@gmail.com\u003e",
186554          "name": "deep-extend",
186555          "version": "0.6.0",
186556          "description": "Recursive object extending",
186557          "licenses": [
186558            {
186559              "license": {
186560                "id": "MIT"
186561              }
186562            }
186563          ],
186564          "cpe": "cpe:2.3:a:deep-extend:deep-extend:0.6.0:*:*:*:*:*:*:*",
186565          "purl": "pkg:npm/deep-extend@0.6.0",
186566          "swid": {
186567            "attachment": {}
186568          },
186569          "pedigree": {},
186570          "externalReferences": [
186571            {
186572              "url": "git://github.com/unclechu/node-deep-extend.git",
186573              "type": "distribution"
186574            },
186575            {
186576              "url": "https://github.com/unclechu/node-deep-extend",
186577              "type": "website"
186578            }
186579          ],
186580          "evidence": {},
186581          "signature": {
186582            "signature": {
186583              "publicKey": {}
186584            }
186585          },
186586          "modelCard": {
186587            "modelParameters": {
186588              "approach": {}
186589            },
186590            "quantitativeAnalysis": {
186591              "graphics": {}
186592            },
186593            "considerations": {}
186594          }
186595        },
186596        {
186597          "type": "library",
186598          "bom-ref": "pkg:npm/defaults@1.0.3?package-id=b87ef5ac001f1810",
186599          "supplier": {},
186600          "author": "Elijah Insua \u003ctmpvar@gmail.com\u003e",
186601          "name": "defaults",
186602          "version": "1.0.3",
186603          "description": "merge single level defaults over a config object",
186604          "licenses": [
186605            {
186606              "license": {
186607                "id": "MIT"
186608              }
186609            }
186610          ],
186611          "cpe": "cpe:2.3:a:defaults:defaults:1.0.3:*:*:*:*:*:*:*",
186612          "purl": "pkg:npm/defaults@1.0.3",
186613          "swid": {
186614            "attachment": {}
186615          },
186616          "pedigree": {},
186617          "externalReferences": [
186618            {
186619              "url": "git://github.com/tmpvar/defaults.git",
186620              "type": "distribution"
186621            },
186622            {
186623              "url": "https://github.com/tmpvar/defaults#readme",
186624              "type": "website"
186625            }
186626          ],
186627          "evidence": {},
186628          "signature": {
186629            "signature": {
186630              "publicKey": {}
186631            }
186632          },
186633          "modelCard": {
186634            "modelParameters": {
186635              "approach": {}
186636            },
186637            "quantitativeAnalysis": {
186638              "graphics": {}
186639            },
186640            "considerations": {}
186641          }
186642        },
186643        {
186644          "type": "library",
186645          "bom-ref": "pkg:npm/define-properties@1.1.3?package-id=6f151d17ca4e763e",
186646          "supplier": {},
186647          "author": "Jordan Harband",
186648          "name": "define-properties",
186649          "version": "1.1.3",
186650          "description": "Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.",
186651          "licenses": [
186652            {
186653              "license": {
186654                "id": "MIT"
186655              }
186656            }
186657          ],
186658          "cpe": "cpe:2.3:a:define-properties:define-properties:1.1.3:*:*:*:*:*:*:*",
186659          "purl": "pkg:npm/define-properties@1.1.3",
186660          "swid": {
186661            "attachment": {}
186662          },
186663          "pedigree": {},
186664          "externalReferences": [
186665            {
186666              "url": "git://github.com/ljharb/define-properties.git",
186667              "type": "distribution"
186668            },
186669            {
186670              "url": "https://github.com/ljharb/define-properties#readme",
186671              "type": "website"
186672            }
186673          ],
186674          "evidence": {},
186675          "signature": {
186676            "signature": {
186677              "publicKey": {}
186678            }
186679          },
186680          "modelCard": {
186681            "modelParameters": {
186682              "approach": {}
186683            },
186684            "quantitativeAnalysis": {
186685              "graphics": {}
186686            },
186687            "considerations": {}
186688          }
186689        },
186690        {
186691          "type": "library",
186692          "bom-ref": "pkg:npm/define-properties@1.1.3?package-id=b4b6e57cfdee31b8",
186693          "supplier": {},
186694          "author": "Jordan Harband",
186695          "name": "define-properties",
186696          "version": "1.1.3",
186697          "description": "Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.",
186698          "licenses": [
186699            {
186700              "license": {
186701                "id": "MIT"
186702              }
186703            }
186704          ],
186705          "cpe": "cpe:2.3:a:define-properties:define-properties:1.1.3:*:*:*:*:*:*:*",
186706          "purl": "pkg:npm/define-properties@1.1.3",
186707          "swid": {
186708            "attachment": {}
186709          },
186710          "pedigree": {},
186711          "externalReferences": [
186712            {
186713              "url": "git://github.com/ljharb/define-properties.git",
186714              "type": "distribution"
186715            }
186716          ],
186717          "evidence": {},
186718          "signature": {
186719            "signature": {
186720              "publicKey": {}
186721            }
186722          },
186723          "modelCard": {
186724            "modelParameters": {
186725              "approach": {}
186726            },
186727            "quantitativeAnalysis": {
186728              "graphics": {}
186729            },
186730            "considerations": {}
186731          }
186732        },
186733        {
186734          "type": "library",
186735          "bom-ref": "pkg:npm/delay@5.0.0?package-id=1fdfc0742e38417a",
186736          "supplier": {},
186737          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
186738          "name": "delay",
186739          "version": "5.0.0",
186740          "description": "Delay a promise a specified amount of time",
186741          "licenses": [
186742            {
186743              "license": {
186744                "id": "MIT"
186745              }
186746            }
186747          ],
186748          "cpe": "cpe:2.3:a:sindresorhus:delay:5.0.0:*:*:*:*:*:*:*",
186749          "purl": "pkg:npm/delay@5.0.0",
186750          "swid": {
186751            "attachment": {}
186752          },
186753          "pedigree": {},
186754          "externalReferences": [
186755            {
186756              "url": "git+https://github.com/sindresorhus/delay.git",
186757              "type": "distribution"
186758            },
186759            {
186760              "url": "https://github.com/sindresorhus/delay#readme",
186761              "type": "website"
186762            }
186763          ],
186764          "evidence": {},
186765          "signature": {
186766            "signature": {
186767              "publicKey": {}
186768            }
186769          },
186770          "modelCard": {
186771            "modelParameters": {
186772              "approach": {}
186773            },
186774            "quantitativeAnalysis": {
186775              "graphics": {}
186776            },
186777            "considerations": {}
186778          }
186779        },
186780        {
186781          "type": "library",
186782          "bom-ref": "pkg:npm/delayed-stream@1.0.0?package-id=a195d79ef31bc579",
186783          "supplier": {},
186784          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
186785          "name": "delayed-stream",
186786          "version": "1.0.0",
186787          "description": "Buffers events from a stream until you are ready to handle them.",
186788          "licenses": [
186789            {
186790              "license": {
186791                "id": "MIT"
186792              }
186793            }
186794          ],
186795          "cpe": "cpe:2.3:a:delayed-stream:delayed-stream:1.0.0:*:*:*:*:*:*:*",
186796          "purl": "pkg:npm/delayed-stream@1.0.0",
186797          "swid": {
186798            "attachment": {}
186799          },
186800          "pedigree": {},
186801          "externalReferences": [
186802            {
186803              "url": "git://github.com/felixge/node-delayed-stream.git",
186804              "type": "distribution"
186805            },
186806            {
186807              "url": "https://github.com/felixge/node-delayed-stream",
186808              "type": "website"
186809            }
186810          ],
186811          "evidence": {},
186812          "signature": {
186813            "signature": {
186814              "publicKey": {}
186815            }
186816          },
186817          "modelCard": {
186818            "modelParameters": {
186819              "approach": {}
186820            },
186821            "quantitativeAnalysis": {
186822              "graphics": {}
186823            },
186824            "considerations": {}
186825          }
186826        },
186827        {
186828          "type": "library",
186829          "bom-ref": "pkg:npm/delegates@1.0.0?package-id=611fe8c99f30481e",
186830          "supplier": {},
186831          "name": "delegates",
186832          "version": "1.0.0",
186833          "description": "delegate methods and accessors to another property",
186834          "licenses": [
186835            {
186836              "license": {
186837                "id": "MIT"
186838              }
186839            }
186840          ],
186841          "cpe": "cpe:2.3:a:visionmedia:delegates:1.0.0:*:*:*:*:*:*:*",
186842          "purl": "pkg:npm/delegates@1.0.0",
186843          "swid": {
186844            "attachment": {}
186845          },
186846          "pedigree": {},
186847          "externalReferences": [
186848            {
186849              "url": "git+https://github.com/visionmedia/node-delegates.git",
186850              "type": "distribution"
186851            },
186852            {
186853              "url": "https://github.com/visionmedia/node-delegates#readme",
186854              "type": "website"
186855            }
186856          ],
186857          "evidence": {},
186858          "signature": {
186859            "signature": {
186860              "publicKey": {}
186861            }
186862          },
186863          "modelCard": {
186864            "modelParameters": {
186865              "approach": {}
186866            },
186867            "quantitativeAnalysis": {
186868              "graphics": {}
186869            },
186870            "considerations": {}
186871          }
186872        },
186873        {
186874          "type": "library",
186875          "bom-ref": "pkg:npm/depd@1.1.2?package-id=b4e3a373f4fec0b8",
186876          "supplier": {},
186877          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
186878          "name": "depd",
186879          "version": "1.1.2",
186880          "description": "Deprecate all the things",
186881          "licenses": [
186882            {
186883              "license": {
186884                "id": "MIT"
186885              }
186886            }
186887          ],
186888          "cpe": "cpe:2.3:a:dougwilson:depd:1.1.2:*:*:*:*:*:*:*",
186889          "purl": "pkg:npm/depd@1.1.2",
186890          "swid": {
186891            "attachment": {}
186892          },
186893          "pedigree": {},
186894          "externalReferences": [
186895            {
186896              "url": "git+https://github.com/dougwilson/nodejs-depd.git",
186897              "type": "distribution"
186898            },
186899            {
186900              "url": "https://github.com/dougwilson/nodejs-depd#readme",
186901              "type": "website"
186902            }
186903          ],
186904          "evidence": {},
186905          "signature": {
186906            "signature": {
186907              "publicKey": {}
186908            }
186909          },
186910          "modelCard": {
186911            "modelParameters": {
186912              "approach": {}
186913            },
186914            "quantitativeAnalysis": {
186915              "graphics": {}
186916            },
186917            "considerations": {}
186918          }
186919        },
186920        {
186921          "type": "library",
186922          "bom-ref": "pkg:npm/destroy@1.0.4?package-id=d0ece580645e4cd1",
186923          "supplier": {},
186924          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
186925          "name": "destroy",
186926          "version": "1.0.4",
186927          "description": "destroy a stream if possible",
186928          "licenses": [
186929            {
186930              "license": {
186931                "id": "MIT"
186932              }
186933            }
186934          ],
186935          "cpe": "cpe:2.3:a:stream-utils:destroy:1.0.4:*:*:*:*:*:*:*",
186936          "purl": "pkg:npm/destroy@1.0.4",
186937          "swid": {
186938            "attachment": {}
186939          },
186940          "pedigree": {},
186941          "externalReferences": [
186942            {
186943              "url": "git+https://github.com/stream-utils/destroy.git",
186944              "type": "distribution"
186945            },
186946            {
186947              "url": "https://github.com/stream-utils/destroy#readme",
186948              "type": "website"
186949            }
186950          ],
186951          "evidence": {},
186952          "signature": {
186953            "signature": {
186954              "publicKey": {}
186955            }
186956          },
186957          "modelCard": {
186958            "modelParameters": {
186959              "approach": {}
186960            },
186961            "quantitativeAnalysis": {
186962              "graphics": {}
186963            },
186964            "considerations": {}
186965          }
186966        },
186967        {
186968          "type": "library",
186969          "bom-ref": "pkg:npm/detect-indent@5.0.0?package-id=cbccbb5dd754391",
186970          "supplier": {},
186971          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
186972          "name": "detect-indent",
186973          "version": "5.0.0",
186974          "description": "Detect the indentation of code",
186975          "licenses": [
186976            {
186977              "license": {
186978                "id": "MIT"
186979              }
186980            }
186981          ],
186982          "cpe": "cpe:2.3:a:detect-indent:detect-indent:5.0.0:*:*:*:*:*:*:*",
186983          "purl": "pkg:npm/detect-indent@5.0.0",
186984          "swid": {
186985            "attachment": {}
186986          },
186987          "pedigree": {},
186988          "externalReferences": [
186989            {
186990              "url": "git+https://github.com/sindresorhus/detect-indent.git",
186991              "type": "distribution"
186992            },
186993            {
186994              "url": "https://github.com/sindresorhus/detect-indent#readme",
186995              "type": "website"
186996            }
186997          ],
186998          "evidence": {},
186999          "signature": {
187000            "signature": {
187001              "publicKey": {}
187002            }
187003          },
187004          "modelCard": {
187005            "modelParameters": {
187006              "approach": {}
187007            },
187008            "quantitativeAnalysis": {
187009              "graphics": {}
187010            },
187011            "considerations": {}
187012          }
187013        },
187014        {
187015          "type": "library",
187016          "bom-ref": "pkg:npm/detect-newline@2.1.0?package-id=9759ace33b9872ed",
187017          "supplier": {},
187018          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
187019          "name": "detect-newline",
187020          "version": "2.1.0",
187021          "description": "Detect the dominant newline character of a string",
187022          "licenses": [
187023            {
187024              "license": {
187025                "id": "MIT"
187026              }
187027            }
187028          ],
187029          "cpe": "cpe:2.3:a:detect-newline:detect-newline:2.1.0:*:*:*:*:*:*:*",
187030          "purl": "pkg:npm/detect-newline@2.1.0",
187031          "swid": {
187032            "attachment": {}
187033          },
187034          "pedigree": {},
187035          "externalReferences": [
187036            {
187037              "url": "git+https://github.com/sindresorhus/detect-newline.git",
187038              "type": "distribution"
187039            },
187040            {
187041              "url": "https://github.com/sindresorhus/detect-newline#readme",
187042              "type": "website"
187043            }
187044          ],
187045          "evidence": {},
187046          "signature": {
187047            "signature": {
187048              "publicKey": {}
187049            }
187050          },
187051          "modelCard": {
187052            "modelParameters": {
187053              "approach": {}
187054            },
187055            "quantitativeAnalysis": {
187056              "graphics": {}
187057            },
187058            "considerations": {}
187059          }
187060        },
187061        {
187062          "type": "library",
187063          "bom-ref": "pkg:npm/dezalgo@1.0.3?package-id=a0ca0da76ce71f2f",
187064          "supplier": {},
187065          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
187066          "name": "dezalgo",
187067          "version": "1.0.3",
187068          "description": "Contain async insanity so that the dark pony lord doesn't eat souls",
187069          "licenses": [
187070            {
187071              "license": {
187072                "id": "ISC"
187073              }
187074            }
187075          ],
187076          "cpe": "cpe:2.3:a:dezalgo:dezalgo:1.0.3:*:*:*:*:*:*:*",
187077          "purl": "pkg:npm/dezalgo@1.0.3",
187078          "swid": {
187079            "attachment": {}
187080          },
187081          "pedigree": {},
187082          "externalReferences": [
187083            {
187084              "url": "git+https://github.com/npm/dezalgo.git",
187085              "type": "distribution"
187086            },
187087            {
187088              "url": "https://github.com/npm/dezalgo",
187089              "type": "website"
187090            }
187091          ],
187092          "evidence": {},
187093          "signature": {
187094            "signature": {
187095              "publicKey": {}
187096            }
187097          },
187098          "modelCard": {
187099            "modelParameters": {
187100              "approach": {}
187101            },
187102            "quantitativeAnalysis": {
187103              "graphics": {}
187104            },
187105            "considerations": {}
187106          }
187107        },
187108        {
187109          "type": "library",
187110          "bom-ref": "pkg:npm/dicer@0.2.5?package-id=a8a869ccc4536dc8",
187111          "supplier": {},
187112          "author": "Brian White \u003cmscdex@mscdex.net\u003e",
187113          "name": "dicer",
187114          "version": "0.2.5",
187115          "description": "A very fast streaming multipart parser for node.js",
187116          "licenses": [
187117            {
187118              "license": {
187119                "id": "MIT"
187120              }
187121            }
187122          ],
187123          "cpe": "cpe:2.3:a:mscdex:dicer:0.2.5:*:*:*:*:*:*:*",
187124          "purl": "pkg:npm/dicer@0.2.5",
187125          "swid": {
187126            "attachment": {}
187127          },
187128          "pedigree": {},
187129          "externalReferences": [
187130            {
187131              "url": "git+ssh://git@github.com/mscdex/dicer.git",
187132              "type": "distribution"
187133            },
187134            {
187135              "url": "https://github.com/mscdex/dicer#readme",
187136              "type": "website"
187137            }
187138          ],
187139          "evidence": {},
187140          "signature": {
187141            "signature": {
187142              "publicKey": {}
187143            }
187144          },
187145          "modelCard": {
187146            "modelParameters": {
187147              "approach": {}
187148            },
187149            "quantitativeAnalysis": {
187150              "graphics": {}
187151            },
187152            "considerations": {}
187153          }
187154        },
187155        {
187156          "type": "library",
187157          "bom-ref": "pkg:npm/dot-prop@4.2.1?package-id=d49bd91a9d2691c0",
187158          "supplier": {},
187159          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
187160          "name": "dot-prop",
187161          "version": "4.2.1",
187162          "description": "Get, set, or delete a property from a nested object using a dot path",
187163          "licenses": [
187164            {
187165              "license": {
187166                "id": "MIT"
187167              }
187168            }
187169          ],
187170          "cpe": "cpe:2.3:a:sindresorhus:dot-prop:4.2.1:*:*:*:*:*:*:*",
187171          "purl": "pkg:npm/dot-prop@4.2.1",
187172          "swid": {
187173            "attachment": {}
187174          },
187175          "pedigree": {},
187176          "externalReferences": [
187177            {
187178              "url": "git+https://github.com/sindresorhus/dot-prop.git",
187179              "type": "distribution"
187180            },
187181            {
187182              "url": "https://github.com/sindresorhus/dot-prop#readme",
187183              "type": "website"
187184            }
187185          ],
187186          "evidence": {},
187187          "signature": {
187188            "signature": {
187189              "publicKey": {}
187190            }
187191          },
187192          "modelCard": {
187193            "modelParameters": {
187194              "approach": {}
187195            },
187196            "quantitativeAnalysis": {
187197              "graphics": {}
187198            },
187199            "considerations": {}
187200          }
187201        },
187202        {
187203          "type": "library",
187204          "bom-ref": "pkg:npm/dotenv@5.0.1?package-id=52ed2ee809f10570",
187205          "supplier": {},
187206          "author": "scottmotte",
187207          "name": "dotenv",
187208          "version": "5.0.1",
187209          "description": "Loads environment variables from .env file",
187210          "licenses": [
187211            {
187212              "license": {
187213                "id": "BSD-2-Clause"
187214              }
187215            }
187216          ],
187217          "cpe": "cpe:2.3:a:motdotla:dotenv:5.0.1:*:*:*:*:*:*:*",
187218          "purl": "pkg:npm/dotenv@5.0.1",
187219          "swid": {
187220            "attachment": {}
187221          },
187222          "pedigree": {},
187223          "externalReferences": [
187224            {
187225              "url": "git://github.com/motdotla/dotenv.git",
187226              "type": "distribution"
187227            },
187228            {
187229              "url": "https://github.com/motdotla/dotenv#readme",
187230              "type": "website"
187231            }
187232          ],
187233          "evidence": {},
187234          "signature": {
187235            "signature": {
187236              "publicKey": {}
187237            }
187238          },
187239          "modelCard": {
187240            "modelParameters": {
187241              "approach": {}
187242            },
187243            "quantitativeAnalysis": {
187244              "graphics": {}
187245            },
187246            "considerations": {}
187247          }
187248        },
187249        {
187250          "type": "library",
187251          "bom-ref": "pkg:npm/duplexer3@0.1.4?package-id=98204faeb1e0cfb8",
187252          "supplier": {},
187253          "author": "Conrad Pankoff \u003cdeoxxa@fknsrs.biz\u003e (http://www.fknsrs.biz/)",
187254          "name": "duplexer3",
187255          "version": "0.1.4",
187256          "description": "Like duplexer but using streams3",
187257          "licenses": [
187258            {
187259              "license": {
187260                "id": "BSD-3-Clause"
187261              }
187262            }
187263          ],
187264          "cpe": "cpe:2.3:a:duplexer3:duplexer3:0.1.4:*:*:*:*:*:*:*",
187265          "purl": "pkg:npm/duplexer3@0.1.4",
187266          "swid": {
187267            "attachment": {}
187268          },
187269          "pedigree": {},
187270          "externalReferences": [
187271            {
187272              "url": "git+https://github.com/floatdrop/duplexer3.git",
187273              "type": "distribution"
187274            },
187275            {
187276              "url": "https://github.com/floatdrop/duplexer3#readme",
187277              "type": "website"
187278            }
187279          ],
187280          "evidence": {},
187281          "signature": {
187282            "signature": {
187283              "publicKey": {}
187284            }
187285          },
187286          "modelCard": {
187287            "modelParameters": {
187288              "approach": {}
187289            },
187290            "quantitativeAnalysis": {
187291              "graphics": {}
187292            },
187293            "considerations": {}
187294          }
187295        },
187296        {
187297          "type": "library",
187298          "bom-ref": "pkg:npm/duplexify@3.6.0?package-id=80b25920959c0055",
187299          "supplier": {},
187300          "author": "Mathias Buus",
187301          "name": "duplexify",
187302          "version": "3.6.0",
187303          "description": "Turn a writable and readable stream into a streams2 duplex stream with support for async initialization and streams1/streams2 input",
187304          "licenses": [
187305            {
187306              "license": {
187307                "id": "MIT"
187308              }
187309            }
187310          ],
187311          "cpe": "cpe:2.3:a:duplexify:duplexify:3.6.0:*:*:*:*:*:*:*",
187312          "purl": "pkg:npm/duplexify@3.6.0",
187313          "swid": {
187314            "attachment": {}
187315          },
187316          "pedigree": {},
187317          "externalReferences": [
187318            {
187319              "url": "git://github.com/mafintosh/duplexify.git",
187320              "type": "distribution"
187321            },
187322            {
187323              "url": "https://github.com/mafintosh/duplexify",
187324              "type": "website"
187325            }
187326          ],
187327          "evidence": {},
187328          "signature": {
187329            "signature": {
187330              "publicKey": {}
187331            }
187332          },
187333          "modelCard": {
187334            "modelParameters": {
187335              "approach": {}
187336            },
187337            "quantitativeAnalysis": {
187338              "graphics": {}
187339            },
187340            "considerations": {}
187341          }
187342        },
187343        {
187344          "type": "library",
187345          "bom-ref": "pkg:npm/ecc-jsbn@0.1.2?package-id=13a413a168a6381f",
187346          "supplier": {},
187347          "author": "Jeremie Miller \u003cjeremie@jabber.org\u003e (http://jeremie.com/)",
187348          "name": "ecc-jsbn",
187349          "version": "0.1.2",
187350          "description": "ECC JS code based on JSBN",
187351          "licenses": [
187352            {
187353              "license": {
187354                "id": "MIT"
187355              }
187356            }
187357          ],
187358          "cpe": "cpe:2.3:a:quartzjer:ecc-jsbn:0.1.2:*:*:*:*:*:*:*",
187359          "purl": "pkg:npm/ecc-jsbn@0.1.2",
187360          "swid": {
187361            "attachment": {}
187362          },
187363          "pedigree": {},
187364          "externalReferences": [
187365            {
187366              "url": "git+https://github.com/quartzjer/ecc-jsbn.git",
187367              "type": "distribution"
187368            },
187369            {
187370              "url": "https://github.com/quartzjer/ecc-jsbn",
187371              "type": "website"
187372            }
187373          ],
187374          "evidence": {},
187375          "signature": {
187376            "signature": {
187377              "publicKey": {}
187378            }
187379          },
187380          "modelCard": {
187381            "modelParameters": {
187382              "approach": {}
187383            },
187384            "quantitativeAnalysis": {
187385              "graphics": {}
187386            },
187387            "considerations": {}
187388          }
187389        },
187390        {
187391          "type": "library",
187392          "bom-ref": "pkg:npm/editor@1.0.0?package-id=57824e36461985c2",
187393          "supplier": {},
187394          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
187395          "name": "editor",
187396          "version": "1.0.0",
187397          "description": "launch $EDITOR in your program",
187398          "licenses": [
187399            {
187400              "license": {
187401                "id": "MIT"
187402              }
187403            }
187404          ],
187405          "cpe": "cpe:2.3:a:substack:editor:1.0.0:*:*:*:*:*:*:*",
187406          "purl": "pkg:npm/editor@1.0.0",
187407          "swid": {
187408            "attachment": {}
187409          },
187410          "pedigree": {},
187411          "externalReferences": [
187412            {
187413              "url": "git://github.com/substack/node-editor.git",
187414              "type": "distribution"
187415            },
187416            {
187417              "url": "https://github.com/substack/node-editor",
187418              "type": "website"
187419            }
187420          ],
187421          "evidence": {},
187422          "signature": {
187423            "signature": {
187424              "publicKey": {}
187425            }
187426          },
187427          "modelCard": {
187428            "modelParameters": {
187429              "approach": {}
187430            },
187431            "quantitativeAnalysis": {
187432              "graphics": {}
187433            },
187434            "considerations": {}
187435          }
187436        },
187437        {
187438          "type": "library",
187439          "bom-ref": "pkg:npm/ee-first@1.1.1?package-id=64407a6fdf5ac08b",
187440          "supplier": {},
187441          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
187442          "name": "ee-first",
187443          "version": "1.1.1",
187444          "description": "return the first event in a set of ee/event pairs",
187445          "licenses": [
187446            {
187447              "license": {
187448                "id": "MIT"
187449              }
187450            }
187451          ],
187452          "cpe": "cpe:2.3:a:jonathanong:ee-first:1.1.1:*:*:*:*:*:*:*",
187453          "purl": "pkg:npm/ee-first@1.1.1",
187454          "swid": {
187455            "attachment": {}
187456          },
187457          "pedigree": {},
187458          "externalReferences": [
187459            {
187460              "url": "git+https://github.com/jonathanong/ee-first.git",
187461              "type": "distribution"
187462            },
187463            {
187464              "url": "https://github.com/jonathanong/ee-first#readme",
187465              "type": "website"
187466            }
187467          ],
187468          "evidence": {},
187469          "signature": {
187470            "signature": {
187471              "publicKey": {}
187472            }
187473          },
187474          "modelCard": {
187475            "modelParameters": {
187476              "approach": {}
187477            },
187478            "quantitativeAnalysis": {
187479              "graphics": {}
187480            },
187481            "considerations": {}
187482          }
187483        },
187484        {
187485          "type": "library",
187486          "bom-ref": "pkg:npm/emoji-regex@7.0.3?package-id=67c6a2d66166ba44",
187487          "supplier": {},
187488          "author": "Mathias Bynens (https://mathiasbynens.be/)",
187489          "name": "emoji-regex",
187490          "version": "7.0.3",
187491          "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
187492          "licenses": [
187493            {
187494              "license": {
187495                "id": "MIT"
187496              }
187497            }
187498          ],
187499          "cpe": "cpe:2.3:a:emoji-regex:emoji-regex:7.0.3:*:*:*:*:*:*:*",
187500          "purl": "pkg:npm/emoji-regex@7.0.3",
187501          "swid": {
187502            "attachment": {}
187503          },
187504          "pedigree": {},
187505          "externalReferences": [
187506            {
187507              "url": "git+https://github.com/mathiasbynens/emoji-regex.git",
187508              "type": "distribution"
187509            },
187510            {
187511              "url": "https://mths.be/emoji-regex",
187512              "type": "website"
187513            }
187514          ],
187515          "evidence": {},
187516          "signature": {
187517            "signature": {
187518              "publicKey": {}
187519            }
187520          },
187521          "modelCard": {
187522            "modelParameters": {
187523              "approach": {}
187524            },
187525            "quantitativeAnalysis": {
187526              "graphics": {}
187527            },
187528            "considerations": {}
187529          }
187530        },
187531        {
187532          "type": "library",
187533          "bom-ref": "pkg:npm/encodeurl@1.0.2?package-id=6de19f90b58f26e3",
187534          "supplier": {},
187535          "name": "encodeurl",
187536          "version": "1.0.2",
187537          "description": "Encode a URL to a percent-encoded form, excluding already-encoded sequences",
187538          "licenses": [
187539            {
187540              "license": {
187541                "id": "MIT"
187542              }
187543            }
187544          ],
187545          "cpe": "cpe:2.3:a:encodeurl:encodeurl:1.0.2:*:*:*:*:*:*:*",
187546          "purl": "pkg:npm/encodeurl@1.0.2",
187547          "swid": {
187548            "attachment": {}
187549          },
187550          "pedigree": {},
187551          "externalReferences": [
187552            {
187553              "url": "git+https://github.com/pillarjs/encodeurl.git",
187554              "type": "distribution"
187555            },
187556            {
187557              "url": "https://github.com/pillarjs/encodeurl#readme",
187558              "type": "website"
187559            }
187560          ],
187561          "evidence": {},
187562          "signature": {
187563            "signature": {
187564              "publicKey": {}
187565            }
187566          },
187567          "modelCard": {
187568            "modelParameters": {
187569              "approach": {}
187570            },
187571            "quantitativeAnalysis": {
187572              "graphics": {}
187573            },
187574            "considerations": {}
187575          }
187576        },
187577        {
187578          "type": "library",
187579          "bom-ref": "pkg:npm/encoding@0.1.12?package-id=871fd80324ab2784",
187580          "supplier": {},
187581          "author": "Andris Reinman",
187582          "name": "encoding",
187583          "version": "0.1.12",
187584          "description": "Convert encodings, uses iconv by default and fallbacks to iconv-lite if needed",
187585          "licenses": [
187586            {
187587              "license": {
187588                "id": "MIT"
187589              }
187590            }
187591          ],
187592          "cpe": "cpe:2.3:a:encoding:encoding:0.1.12:*:*:*:*:*:*:*",
187593          "purl": "pkg:npm/encoding@0.1.12",
187594          "swid": {
187595            "attachment": {}
187596          },
187597          "pedigree": {},
187598          "externalReferences": [
187599            {
187600              "url": "git+https://github.com/andris9/encoding.git",
187601              "type": "distribution"
187602            },
187603            {
187604              "url": "https://github.com/andris9/encoding#readme",
187605              "type": "website"
187606            }
187607          ],
187608          "evidence": {},
187609          "signature": {
187610            "signature": {
187611              "publicKey": {}
187612            }
187613          },
187614          "modelCard": {
187615            "modelParameters": {
187616              "approach": {}
187617            },
187618            "quantitativeAnalysis": {
187619              "graphics": {}
187620            },
187621            "considerations": {}
187622          }
187623        },
187624        {
187625          "type": "library",
187626          "bom-ref": "pkg:npm/end-of-stream@1.4.1?package-id=6a3ff5d2005a6a76",
187627          "supplier": {},
187628          "author": "Mathias Buus \u003cmathiasbuus@gmail.com\u003e",
187629          "name": "end-of-stream",
187630          "version": "1.4.1",
187631          "description": "Call a callback when a readable/writable/duplex stream has completed or failed.",
187632          "licenses": [
187633            {
187634              "license": {
187635                "id": "MIT"
187636              }
187637            }
187638          ],
187639          "cpe": "cpe:2.3:a:end-of-stream:end-of-stream:1.4.1:*:*:*:*:*:*:*",
187640          "purl": "pkg:npm/end-of-stream@1.4.1",
187641          "swid": {
187642            "attachment": {}
187643          },
187644          "pedigree": {},
187645          "externalReferences": [
187646            {
187647              "url": "git://github.com/mafintosh/end-of-stream.git",
187648              "type": "distribution"
187649            },
187650            {
187651              "url": "https://github.com/mafintosh/end-of-stream",
187652              "type": "website"
187653            }
187654          ],
187655          "evidence": {},
187656          "signature": {
187657            "signature": {
187658              "publicKey": {}
187659            }
187660          },
187661          "modelCard": {
187662            "modelParameters": {
187663              "approach": {}
187664            },
187665            "quantitativeAnalysis": {
187666              "graphics": {}
187667            },
187668            "considerations": {}
187669          }
187670        },
187671        {
187672          "type": "library",
187673          "bom-ref": "pkg:npm/env-paths@2.2.0?package-id=cc33898e5e6c4f25",
187674          "supplier": {},
187675          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
187676          "name": "env-paths",
187677          "version": "2.2.0",
187678          "description": "Get paths for storing things like data, config, cache, etc",
187679          "licenses": [
187680            {
187681              "license": {
187682                "id": "MIT"
187683              }
187684            }
187685          ],
187686          "cpe": "cpe:2.3:a:sindresorhus:env-paths:2.2.0:*:*:*:*:*:*:*",
187687          "purl": "pkg:npm/env-paths@2.2.0",
187688          "swid": {
187689            "attachment": {}
187690          },
187691          "pedigree": {},
187692          "externalReferences": [
187693            {
187694              "url": "git+https://github.com/sindresorhus/env-paths.git",
187695              "type": "distribution"
187696            },
187697            {
187698              "url": "https://github.com/sindresorhus/env-paths#readme",
187699              "type": "website"
187700            }
187701          ],
187702          "evidence": {},
187703          "signature": {
187704            "signature": {
187705              "publicKey": {}
187706            }
187707          },
187708          "modelCard": {
187709            "modelParameters": {
187710              "approach": {}
187711            },
187712            "quantitativeAnalysis": {
187713              "graphics": {}
187714            },
187715            "considerations": {}
187716          }
187717        },
187718        {
187719          "type": "library",
187720          "bom-ref": "pkg:npm/err-code@1.1.2?package-id=47b4e2b3e9659ed4",
187721          "supplier": {},
187722          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
187723          "name": "err-code",
187724          "version": "1.1.2",
187725          "description": "Create an error with a code",
187726          "licenses": [
187727            {
187728              "license": {
187729                "id": "MIT"
187730              }
187731            }
187732          ],
187733          "cpe": "cpe:2.3:a:IndigoUnited:err-code:1.1.2:*:*:*:*:*:*:*",
187734          "purl": "pkg:npm/err-code@1.1.2",
187735          "swid": {
187736            "attachment": {}
187737          },
187738          "pedigree": {},
187739          "externalReferences": [
187740            {
187741              "url": "git://github.com/IndigoUnited/js-err-code.git",
187742              "type": "distribution"
187743            },
187744            {
187745              "url": "https://github.com/IndigoUnited/js-err-code#readme",
187746              "type": "website"
187747            }
187748          ],
187749          "evidence": {},
187750          "signature": {
187751            "signature": {
187752              "publicKey": {}
187753            }
187754          },
187755          "modelCard": {
187756            "modelParameters": {
187757              "approach": {}
187758            },
187759            "quantitativeAnalysis": {
187760              "graphics": {}
187761            },
187762            "considerations": {}
187763          }
187764        },
187765        {
187766          "type": "library",
187767          "bom-ref": "pkg:npm/errno@0.1.7?package-id=1f6d7a00a99768b0",
187768          "supplier": {},
187769          "name": "errno",
187770          "version": "0.1.7",
187771          "description": "libuv errno details exposed",
187772          "licenses": [
187773            {
187774              "license": {
187775                "id": "MIT"
187776              }
187777            }
187778          ],
187779          "cpe": "cpe:2.3:a:errno:errno:0.1.7:*:*:*:*:*:*:*",
187780          "purl": "pkg:npm/errno@0.1.7",
187781          "swid": {
187782            "attachment": {}
187783          },
187784          "pedigree": {},
187785          "externalReferences": [
187786            {
187787              "url": "git+https://github.com/rvagg/node-errno.git",
187788              "type": "distribution"
187789            },
187790            {
187791              "url": "https://github.com/rvagg/node-errno#readme",
187792              "type": "website"
187793            }
187794          ],
187795          "evidence": {},
187796          "signature": {
187797            "signature": {
187798              "publicKey": {}
187799            }
187800          },
187801          "modelCard": {
187802            "modelParameters": {
187803              "approach": {}
187804            },
187805            "quantitativeAnalysis": {
187806              "graphics": {}
187807            },
187808            "considerations": {}
187809          }
187810        },
187811        {
187812          "type": "library",
187813          "bom-ref": "pkg:npm/es-abstract@1.12.0?package-id=a2b6224dc1972289",
187814          "supplier": {},
187815          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
187816          "name": "es-abstract",
187817          "version": "1.12.0",
187818          "description": "ECMAScript spec abstract operations.",
187819          "licenses": [
187820            {
187821              "license": {
187822                "id": "MIT"
187823              }
187824            }
187825          ],
187826          "cpe": "cpe:2.3:a:es-abstract:es-abstract:1.12.0:*:*:*:*:*:*:*",
187827          "purl": "pkg:npm/es-abstract@1.12.0",
187828          "swid": {
187829            "attachment": {}
187830          },
187831          "pedigree": {},
187832          "externalReferences": [
187833            {
187834              "url": "git://github.com/ljharb/es-abstract.git",
187835              "type": "distribution"
187836            }
187837          ],
187838          "evidence": {},
187839          "signature": {
187840            "signature": {
187841              "publicKey": {}
187842            }
187843          },
187844          "modelCard": {
187845            "modelParameters": {
187846              "approach": {}
187847            },
187848            "quantitativeAnalysis": {
187849              "graphics": {}
187850            },
187851            "considerations": {}
187852          }
187853        },
187854        {
187855          "type": "library",
187856          "bom-ref": "pkg:npm/es-to-primitive@1.2.0?package-id=ff185285dcd118b3",
187857          "supplier": {},
187858          "author": "Jordan Harband",
187859          "name": "es-to-primitive",
187860          "version": "1.2.0",
187861          "description": "ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES2015 versions.",
187862          "licenses": [
187863            {
187864              "license": {
187865                "id": "MIT"
187866              }
187867            }
187868          ],
187869          "cpe": "cpe:2.3:a:es-to-primitive:es-to-primitive:1.2.0:*:*:*:*:*:*:*",
187870          "purl": "pkg:npm/es-to-primitive@1.2.0",
187871          "swid": {
187872            "attachment": {}
187873          },
187874          "pedigree": {},
187875          "externalReferences": [
187876            {
187877              "url": "git://github.com/ljharb/es-to-primitive.git",
187878              "type": "distribution"
187879            }
187880          ],
187881          "evidence": {},
187882          "signature": {
187883            "signature": {
187884              "publicKey": {}
187885            }
187886          },
187887          "modelCard": {
187888            "modelParameters": {
187889              "approach": {}
187890            },
187891            "quantitativeAnalysis": {
187892              "graphics": {}
187893            },
187894            "considerations": {}
187895          }
187896        },
187897        {
187898          "type": "library",
187899          "bom-ref": "pkg:npm/es6-promise@4.2.8?package-id=7acd7eff273aea0f",
187900          "supplier": {},
187901          "author": "Yehuda Katz, Tom Dale, Stefan Penner and contributors (Conversion to ES6 API by Jake Archibald)",
187902          "name": "es6-promise",
187903          "version": "4.2.8",
187904          "description": "A lightweight library that provides tools for organizing asynchronous code",
187905          "licenses": [
187906            {
187907              "license": {
187908                "id": "MIT"
187909              }
187910            }
187911          ],
187912          "cpe": "cpe:2.3:a:stefanpenner:es6-promise:4.2.8:*:*:*:*:*:*:*",
187913          "purl": "pkg:npm/es6-promise@4.2.8",
187914          "swid": {
187915            "attachment": {}
187916          },
187917          "pedigree": {},
187918          "externalReferences": [
187919            {
187920              "url": "git://github.com/stefanpenner/es6-promise.git",
187921              "type": "distribution"
187922            },
187923            {
187924              "url": "https://github.com/stefanpenner/es6-promise",
187925              "type": "website"
187926            }
187927          ],
187928          "evidence": {},
187929          "signature": {
187930            "signature": {
187931              "publicKey": {}
187932            }
187933          },
187934          "modelCard": {
187935            "modelParameters": {
187936              "approach": {}
187937            },
187938            "quantitativeAnalysis": {
187939              "graphics": {}
187940            },
187941            "considerations": {}
187942          }
187943        },
187944        {
187945          "type": "library",
187946          "bom-ref": "pkg:npm/es6-promisify@5.0.0?package-id=922e6b6cb34c0449",
187947          "supplier": {},
187948          "author": "Mike Hall \u003cmikehall314@gmail.com\u003e",
187949          "name": "es6-promisify",
187950          "version": "5.0.0",
187951          "description": "Converts callback-based functions to ES6 Promises",
187952          "licenses": [
187953            {
187954              "license": {
187955                "id": "MIT"
187956              }
187957            }
187958          ],
187959          "cpe": "cpe:2.3:a:digitaldesignlabs:es6-promisify:5.0.0:*:*:*:*:*:*:*",
187960          "purl": "pkg:npm/es6-promisify@5.0.0",
187961          "swid": {
187962            "attachment": {}
187963          },
187964          "pedigree": {},
187965          "externalReferences": [
187966            {
187967              "url": "git+https://github.com/digitaldesignlabs/es6-promisify.git",
187968              "type": "distribution"
187969            },
187970            {
187971              "url": "https://github.com/digitaldesignlabs/es6-promisify#readme",
187972              "type": "website"
187973            }
187974          ],
187975          "evidence": {},
187976          "signature": {
187977            "signature": {
187978              "publicKey": {}
187979            }
187980          },
187981          "modelCard": {
187982            "modelParameters": {
187983              "approach": {}
187984            },
187985            "quantitativeAnalysis": {
187986              "graphics": {}
187987            },
187988            "considerations": {}
187989          }
187990        },
187991        {
187992          "type": "library",
187993          "bom-ref": "pkg:npm/escape-html@1.0.3?package-id=fc052a8fdf6a88f1",
187994          "supplier": {},
187995          "name": "escape-html",
187996          "version": "1.0.3",
187997          "description": "Escape string for use in HTML",
187998          "licenses": [
187999            {
188000              "license": {
188001                "id": "MIT"
188002              }
188003            }
188004          ],
188005          "cpe": "cpe:2.3:a:escape-html:escape-html:1.0.3:*:*:*:*:*:*:*",
188006          "purl": "pkg:npm/escape-html@1.0.3",
188007          "swid": {
188008            "attachment": {}
188009          },
188010          "pedigree": {},
188011          "externalReferences": [
188012            {
188013              "url": "git+https://github.com/component/escape-html.git",
188014              "type": "distribution"
188015            },
188016            {
188017              "url": "https://github.com/component/escape-html#readme",
188018              "type": "website"
188019            }
188020          ],
188021          "evidence": {},
188022          "signature": {
188023            "signature": {
188024              "publicKey": {}
188025            }
188026          },
188027          "modelCard": {
188028            "modelParameters": {
188029              "approach": {}
188030            },
188031            "quantitativeAnalysis": {
188032              "graphics": {}
188033            },
188034            "considerations": {}
188035          }
188036        },
188037        {
188038          "type": "library",
188039          "bom-ref": "pkg:npm/escape-string-regexp@1.0.5?package-id=4ab0b66784f88a18",
188040          "supplier": {},
188041          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
188042          "name": "escape-string-regexp",
188043          "version": "1.0.5",
188044          "description": "Escape RegExp special characters",
188045          "licenses": [
188046            {
188047              "license": {
188048                "id": "MIT"
188049              }
188050            }
188051          ],
188052          "cpe": "cpe:2.3:a:escape-string-regexp:escape-string-regexp:1.0.5:*:*:*:*:*:*:*",
188053          "purl": "pkg:npm/escape-string-regexp@1.0.5",
188054          "swid": {
188055            "attachment": {}
188056          },
188057          "pedigree": {},
188058          "externalReferences": [
188059            {
188060              "url": "git+https://github.com/sindresorhus/escape-string-regexp.git",
188061              "type": "distribution"
188062            },
188063            {
188064              "url": "https://github.com/sindresorhus/escape-string-regexp#readme",
188065              "type": "website"
188066            }
188067          ],
188068          "evidence": {},
188069          "signature": {
188070            "signature": {
188071              "publicKey": {}
188072            }
188073          },
188074          "modelCard": {
188075            "modelParameters": {
188076              "approach": {}
188077            },
188078            "quantitativeAnalysis": {
188079              "graphics": {}
188080            },
188081            "considerations": {}
188082          }
188083        },
188084        {
188085          "type": "library",
188086          "bom-ref": "pkg:npm/esprima@4.0.1?package-id=17f4ea46648742e6",
188087          "supplier": {},
188088          "author": "Ariya Hidayat \u003cariya.hidayat@gmail.com\u003e",
188089          "name": "esprima",
188090          "version": "4.0.1",
188091          "description": "ECMAScript parsing infrastructure for multipurpose analysis",
188092          "licenses": [
188093            {
188094              "license": {
188095                "id": "BSD-2-Clause"
188096              }
188097            }
188098          ],
188099          "cpe": "cpe:2.3:a:esprima:esprima:4.0.1:*:*:*:*:*:*:*",
188100          "purl": "pkg:npm/esprima@4.0.1",
188101          "swid": {
188102            "attachment": {}
188103          },
188104          "pedigree": {},
188105          "externalReferences": [
188106            {
188107              "url": "git+https://github.com/jquery/esprima.git",
188108              "type": "distribution"
188109            },
188110            {
188111              "url": "http://esprima.org",
188112              "type": "website"
188113            }
188114          ],
188115          "evidence": {},
188116          "signature": {
188117            "signature": {
188118              "publicKey": {}
188119            }
188120          },
188121          "modelCard": {
188122            "modelParameters": {
188123              "approach": {}
188124            },
188125            "quantitativeAnalysis": {
188126              "graphics": {}
188127            },
188128            "considerations": {}
188129          }
188130        },
188131        {
188132          "type": "library",
188133          "bom-ref": "pkg:npm/etag@1.8.1?package-id=3601ed58fabb680",
188134          "supplier": {},
188135          "name": "etag",
188136          "version": "1.8.1",
188137          "description": "Create simple HTTP ETags",
188138          "licenses": [
188139            {
188140              "license": {
188141                "id": "MIT"
188142              }
188143            }
188144          ],
188145          "cpe": "cpe:2.3:a:jshttp:etag:1.8.1:*:*:*:*:*:*:*",
188146          "purl": "pkg:npm/etag@1.8.1",
188147          "swid": {
188148            "attachment": {}
188149          },
188150          "pedigree": {},
188151          "externalReferences": [
188152            {
188153              "url": "git+https://github.com/jshttp/etag.git",
188154              "type": "distribution"
188155            },
188156            {
188157              "url": "https://github.com/jshttp/etag#readme",
188158              "type": "website"
188159            }
188160          ],
188161          "evidence": {},
188162          "signature": {
188163            "signature": {
188164              "publicKey": {}
188165            }
188166          },
188167          "modelCard": {
188168            "modelParameters": {
188169              "approach": {}
188170            },
188171            "quantitativeAnalysis": {
188172              "graphics": {}
188173            },
188174            "considerations": {}
188175          }
188176        },
188177        {
188178          "type": "library",
188179          "bom-ref": "pkg:npm/execa@0.7.0?package-id=cb39ab257461721b",
188180          "supplier": {},
188181          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
188182          "name": "execa",
188183          "version": "0.7.0",
188184          "description": "A better `child_process`",
188185          "licenses": [
188186            {
188187              "license": {
188188                "id": "MIT"
188189              }
188190            }
188191          ],
188192          "cpe": "cpe:2.3:a:sindresorhus:execa:0.7.0:*:*:*:*:*:*:*",
188193          "purl": "pkg:npm/execa@0.7.0",
188194          "swid": {
188195            "attachment": {}
188196          },
188197          "pedigree": {},
188198          "externalReferences": [
188199            {
188200              "url": "git+https://github.com/sindresorhus/execa.git",
188201              "type": "distribution"
188202            },
188203            {
188204              "url": "https://github.com/sindresorhus/execa#readme",
188205              "type": "website"
188206            }
188207          ],
188208          "evidence": {},
188209          "signature": {
188210            "signature": {
188211              "publicKey": {}
188212            }
188213          },
188214          "modelCard": {
188215            "modelParameters": {
188216              "approach": {}
188217            },
188218            "quantitativeAnalysis": {
188219              "graphics": {}
188220            },
188221            "considerations": {}
188222          }
188223        },
188224        {
188225          "type": "library",
188226          "bom-ref": "pkg:npm/express@4.17.1?package-id=b158c53a8f877dac",
188227          "supplier": {},
188228          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
188229          "name": "express",
188230          "version": "4.17.1",
188231          "description": "Fast, unopinionated, minimalist web framework",
188232          "licenses": [
188233            {
188234              "license": {
188235                "id": "MIT"
188236              }
188237            }
188238          ],
188239          "cpe": "cpe:2.3:a:express:express:4.17.1:*:*:*:*:*:*:*",
188240          "purl": "pkg:npm/express@4.17.1",
188241          "swid": {
188242            "attachment": {}
188243          },
188244          "pedigree": {},
188245          "externalReferences": [
188246            {
188247              "url": "git+https://github.com/expressjs/express.git",
188248              "type": "distribution"
188249            },
188250            {
188251              "url": "http://expressjs.com/",
188252              "type": "website"
188253            }
188254          ],
188255          "evidence": {},
188256          "signature": {
188257            "signature": {
188258              "publicKey": {}
188259            }
188260          },
188261          "modelCard": {
188262            "modelParameters": {
188263              "approach": {}
188264            },
188265            "quantitativeAnalysis": {
188266              "graphics": {}
188267            },
188268            "considerations": {}
188269          }
188270        },
188271        {
188272          "type": "library",
188273          "bom-ref": "pkg:npm/extend@3.0.2?package-id=6a93821e99ea76cf",
188274          "supplier": {},
188275          "author": "Stefan Thomas \u003cjustmoon@members.fsf.org\u003e (http://www.justmoon.net)",
188276          "name": "extend",
188277          "version": "3.0.2",
188278          "description": "Port of jQuery.extend for node.js and the browser",
188279          "licenses": [
188280            {
188281              "license": {
188282                "id": "MIT"
188283              }
188284            }
188285          ],
188286          "cpe": "cpe:2.3:a:justmoon:extend:3.0.2:*:*:*:*:*:*:*",
188287          "purl": "pkg:npm/extend@3.0.2",
188288          "swid": {
188289            "attachment": {}
188290          },
188291          "pedigree": {},
188292          "externalReferences": [
188293            {
188294              "url": "git+https://github.com/justmoon/node-extend.git",
188295              "type": "distribution"
188296            },
188297            {
188298              "url": "https://github.com/justmoon/node-extend#readme",
188299              "type": "website"
188300            }
188301          ],
188302          "evidence": {},
188303          "signature": {
188304            "signature": {
188305              "publicKey": {}
188306            }
188307          },
188308          "modelCard": {
188309            "modelParameters": {
188310              "approach": {}
188311            },
188312            "quantitativeAnalysis": {
188313              "graphics": {}
188314            },
188315            "considerations": {}
188316          }
188317        },
188318        {
188319          "type": "library",
188320          "bom-ref": "pkg:npm/extsprintf@1.3.0?package-id=c9c71fa4864f843a",
188321          "supplier": {},
188322          "name": "extsprintf",
188323          "version": "1.3.0",
188324          "description": "extended POSIX-style sprintf",
188325          "licenses": [
188326            {
188327              "license": {
188328                "id": "MIT"
188329              }
188330            }
188331          ],
188332          "cpe": "cpe:2.3:a:davepacheco:extsprintf:1.3.0:*:*:*:*:*:*:*",
188333          "purl": "pkg:npm/extsprintf@1.3.0",
188334          "swid": {
188335            "attachment": {}
188336          },
188337          "pedigree": {},
188338          "externalReferences": [
188339            {
188340              "url": "git://github.com/davepacheco/node-extsprintf.git",
188341              "type": "distribution"
188342            },
188343            {
188344              "url": "https://github.com/davepacheco/node-extsprintf#readme",
188345              "type": "website"
188346            }
188347          ],
188348          "evidence": {},
188349          "signature": {
188350            "signature": {
188351              "publicKey": {}
188352            }
188353          },
188354          "modelCard": {
188355            "modelParameters": {
188356              "approach": {}
188357            },
188358            "quantitativeAnalysis": {
188359              "graphics": {}
188360            },
188361            "considerations": {}
188362          }
188363        },
188364        {
188365          "type": "library",
188366          "bom-ref": "pkg:npm/fast-deep-equal@3.1.3?package-id=50fc8df9c652bfea",
188367          "supplier": {},
188368          "author": "Evgeny Poberezkin",
188369          "name": "fast-deep-equal",
188370          "version": "3.1.3",
188371          "description": "Fast deep equal",
188372          "licenses": [
188373            {
188374              "license": {
188375                "id": "MIT"
188376              }
188377            }
188378          ],
188379          "cpe": "cpe:2.3:a:fast-deep-equal:fast-deep-equal:3.1.3:*:*:*:*:*:*:*",
188380          "purl": "pkg:npm/fast-deep-equal@3.1.3",
188381          "swid": {
188382            "attachment": {}
188383          },
188384          "pedigree": {},
188385          "externalReferences": [
188386            {
188387              "url": "git+https://github.com/epoberezkin/fast-deep-equal.git",
188388              "type": "distribution"
188389            },
188390            {
188391              "url": "https://github.com/epoberezkin/fast-deep-equal#readme",
188392              "type": "website"
188393            }
188394          ],
188395          "evidence": {},
188396          "signature": {
188397            "signature": {
188398              "publicKey": {}
188399            }
188400          },
188401          "modelCard": {
188402            "modelParameters": {
188403              "approach": {}
188404            },
188405            "quantitativeAnalysis": {
188406              "graphics": {}
188407            },
188408            "considerations": {}
188409          }
188410        },
188411        {
188412          "type": "library",
188413          "bom-ref": "pkg:npm/fast-deep-equal@3.1.3?package-id=6bf670068a1ba042",
188414          "supplier": {},
188415          "author": "Evgeny Poberezkin",
188416          "name": "fast-deep-equal",
188417          "version": "3.1.3",
188418          "description": "Fast deep equal",
188419          "licenses": [
188420            {
188421              "license": {
188422                "id": "MIT"
188423              }
188424            }
188425          ],
188426          "cpe": "cpe:2.3:a:fast-deep-equal:fast-deep-equal:3.1.3:*:*:*:*:*:*:*",
188427          "purl": "pkg:npm/fast-deep-equal@3.1.3",
188428          "swid": {
188429            "attachment": {}
188430          },
188431          "pedigree": {},
188432          "externalReferences": [
188433            {
188434              "url": "git+https://github.com/epoberezkin/fast-deep-equal.git",
188435              "type": "distribution"
188436            },
188437            {
188438              "url": "https://github.com/epoberezkin/fast-deep-equal#readme",
188439              "type": "website"
188440            }
188441          ],
188442          "evidence": {},
188443          "signature": {
188444            "signature": {
188445              "publicKey": {}
188446            }
188447          },
188448          "modelCard": {
188449            "modelParameters": {
188450              "approach": {}
188451            },
188452            "quantitativeAnalysis": {
188453              "graphics": {}
188454            },
188455            "considerations": {}
188456          }
188457        },
188458        {
188459          "type": "library",
188460          "bom-ref": "pkg:npm/fast-json-stable-stringify@2.0.0?package-id=2012b0c94dfc94ce",
188461          "supplier": {},
188462          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
188463          "name": "fast-json-stable-stringify",
188464          "version": "2.0.0",
188465          "description": "deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify",
188466          "licenses": [
188467            {
188468              "license": {
188469                "id": "MIT"
188470              }
188471            }
188472          ],
188473          "cpe": "cpe:2.3:a:fast-json-stable-stringify:fast-json-stable-stringify:2.0.0:*:*:*:*:*:*:*",
188474          "purl": "pkg:npm/fast-json-stable-stringify@2.0.0",
188475          "swid": {
188476            "attachment": {}
188477          },
188478          "pedigree": {},
188479          "externalReferences": [
188480            {
188481              "url": "git://github.com/epoberezkin/fast-json-stable-stringify.git",
188482              "type": "distribution"
188483            },
188484            {
188485              "url": "https://github.com/epoberezkin/fast-json-stable-stringify",
188486              "type": "website"
188487            }
188488          ],
188489          "evidence": {},
188490          "signature": {
188491            "signature": {
188492              "publicKey": {}
188493            }
188494          },
188495          "modelCard": {
188496            "modelParameters": {
188497              "approach": {}
188498            },
188499            "quantitativeAnalysis": {
188500              "graphics": {}
188501            },
188502            "considerations": {}
188503          }
188504        },
188505        {
188506          "type": "library",
188507          "bom-ref": "pkg:npm/fast-json-stringify@5.5.0?package-id=6654047de7e0dd0f",
188508          "supplier": {},
188509          "author": "Matteo Collina \u003chello@matteocollina.com\u003e",
188510          "name": "fast-json-stringify",
188511          "version": "5.5.0",
188512          "description": "Stringify your JSON at max speed",
188513          "licenses": [
188514            {
188515              "license": {
188516                "id": "MIT"
188517              }
188518            }
188519          ],
188520          "cpe": "cpe:2.3:a:fast-json-stringify:fast-json-stringify:5.5.0:*:*:*:*:*:*:*",
188521          "purl": "pkg:npm/fast-json-stringify@5.5.0",
188522          "swid": {
188523            "attachment": {}
188524          },
188525          "pedigree": {},
188526          "externalReferences": [
188527            {
188528              "url": "git+https://github.com/fastify/fast-json-stringify.git",
188529              "type": "distribution"
188530            },
188531            {
188532              "url": "https://github.com/fastify/fast-json-stringify#readme",
188533              "type": "website"
188534            }
188535          ],
188536          "evidence": {},
188537          "signature": {
188538            "signature": {
188539              "publicKey": {}
188540            }
188541          },
188542          "modelCard": {
188543            "modelParameters": {
188544              "approach": {}
188545            },
188546            "quantitativeAnalysis": {
188547              "graphics": {}
188548            },
188549            "considerations": {}
188550          }
188551        },
188552        {
188553          "type": "library",
188554          "bom-ref": "pkg:npm/fast-printf@1.6.9?package-id=fd1faec12b09e98e",
188555          "supplier": {},
188556          "author": "Gajus Kuizinas \u003cgajus@gajus.com\u003e (http://gajus.com)",
188557          "name": "fast-printf",
188558          "version": "1.6.9",
188559          "description": "Fast and spec-compliant printf implementation for Node.js and browser.",
188560          "licenses": [
188561            {
188562              "license": {
188563                "id": "BSD-3-Clause"
188564              }
188565            }
188566          ],
188567          "cpe": "cpe:2.3:a:fast-printf:fast-printf:1.6.9:*:*:*:*:*:*:*",
188568          "purl": "pkg:npm/fast-printf@1.6.9",
188569          "swid": {
188570            "attachment": {}
188571          },
188572          "pedigree": {},
188573          "externalReferences": [
188574            {
188575              "url": "git+ssh://git@github.com/gajus/fast-printf.git",
188576              "type": "distribution"
188577            },
188578            {
188579              "url": "https://github.com/gajus/fast-printf#readme",
188580              "type": "website"
188581            }
188582          ],
188583          "evidence": {},
188584          "signature": {
188585            "signature": {
188586              "publicKey": {}
188587            }
188588          },
188589          "modelCard": {
188590            "modelParameters": {
188591              "approach": {}
188592            },
188593            "quantitativeAnalysis": {
188594              "graphics": {}
188595            },
188596            "considerations": {}
188597          }
188598        },
188599        {
188600          "type": "library",
188601          "bom-ref": "pkg:npm/fast-safe-stringify@2.0.7?package-id=c12cba20e0a81013",
188602          "supplier": {},
188603          "author": "David Mark Clements",
188604          "name": "fast-safe-stringify",
188605          "version": "2.0.7",
188606          "description": "Safely and quickly serialize JavaScript objects",
188607          "licenses": [
188608            {
188609              "license": {
188610                "id": "MIT"
188611              }
188612            }
188613          ],
188614          "cpe": "cpe:2.3:a:fast-safe-stringify:fast-safe-stringify:2.0.7:*:*:*:*:*:*:*",
188615          "purl": "pkg:npm/fast-safe-stringify@2.0.7",
188616          "swid": {
188617            "attachment": {}
188618          },
188619          "pedigree": {},
188620          "externalReferences": [
188621            {
188622              "url": "git+https://github.com/davidmarkclements/fast-safe-stringify.git",
188623              "type": "distribution"
188624            },
188625            {
188626              "url": "https://github.com/davidmarkclements/fast-safe-stringify#readme",
188627              "type": "website"
188628            }
188629          ],
188630          "evidence": {},
188631          "signature": {
188632            "signature": {
188633              "publicKey": {}
188634            }
188635          },
188636          "modelCard": {
188637            "modelParameters": {
188638              "approach": {}
188639            },
188640            "quantitativeAnalysis": {
188641              "graphics": {}
188642            },
188643            "considerations": {}
188644          }
188645        },
188646        {
188647          "type": "library",
188648          "bom-ref": "pkg:npm/fast-uri@2.2.0?package-id=348ed330e4d49c5",
188649          "supplier": {},
188650          "author": "Vincent Le Goff \u003cvince.legoff@gmail.com\u003e (https://github.com/zekth)",
188651          "name": "fast-uri",
188652          "version": "2.2.0",
188653          "description": "Dependency free RFC 3986 URI toolbox",
188654          "licenses": [
188655            {
188656              "license": {
188657                "id": "MIT"
188658              }
188659            }
188660          ],
188661          "cpe": "cpe:2.3:a:fast-uri:fast-uri:2.2.0:*:*:*:*:*:*:*",
188662          "purl": "pkg:npm/fast-uri@2.2.0",
188663          "swid": {
188664            "attachment": {}
188665          },
188666          "pedigree": {},
188667          "externalReferences": [
188668            {
188669              "url": "git+https://github.com/fastify/fast-uri.git",
188670              "type": "distribution"
188671            },
188672            {
188673              "url": "https://github.com/fastify/fast-uri",
188674              "type": "website"
188675            }
188676          ],
188677          "evidence": {},
188678          "signature": {
188679            "signature": {
188680              "publicKey": {}
188681            }
188682          },
188683          "modelCard": {
188684            "modelParameters": {
188685              "approach": {}
188686            },
188687            "quantitativeAnalysis": {
188688              "graphics": {}
188689            },
188690            "considerations": {}
188691          }
188692        },
188693        {
188694          "type": "library",
188695          "bom-ref": "pkg:npm/fastify-plugin@3.0.0?package-id=7d44b0537dbe0461",
188696          "supplier": {},
188697          "author": "Tomas Della Vedova - @delvedor (http://delved.org)",
188698          "name": "fastify-plugin",
188699          "version": "3.0.0",
188700          "description": "Plugin helper for Fastify",
188701          "licenses": [
188702            {
188703              "license": {
188704                "id": "MIT"
188705              }
188706            }
188707          ],
188708          "cpe": "cpe:2.3:a:fastify-plugin:fastify-plugin:3.0.0:*:*:*:*:*:*:*",
188709          "purl": "pkg:npm/fastify-plugin@3.0.0",
188710          "swid": {
188711            "attachment": {}
188712          },
188713          "pedigree": {},
188714          "externalReferences": [
188715            {
188716              "url": "git+https://github.com/fastify/fastify-plugin.git",
188717              "type": "distribution"
188718            },
188719            {
188720              "url": "https://github.com/fastify/fastify-plugin#readme",
188721              "type": "website"
188722            }
188723          ],
188724          "evidence": {},
188725          "signature": {
188726            "signature": {
188727              "publicKey": {}
188728            }
188729          },
188730          "modelCard": {
188731            "modelParameters": {
188732              "approach": {}
188733            },
188734            "quantitativeAnalysis": {
188735              "graphics": {}
188736            },
188737            "considerations": {}
188738          }
188739        },
188740        {
188741          "type": "library",
188742          "bom-ref": "pkg:npm/fastify-static@3.4.0?package-id=17170748528d3481",
188743          "supplier": {},
188744          "author": "Tommaso Allevi - @allevo",
188745          "name": "fastify-static",
188746          "version": "3.4.0",
188747          "description": "Plugin for serving static files as fast as possible.",
188748          "licenses": [
188749            {
188750              "license": {
188751                "id": "MIT"
188752              }
188753            }
188754          ],
188755          "cpe": "cpe:2.3:a:fastify-static:fastify-static:3.4.0:*:*:*:*:*:*:*",
188756          "purl": "pkg:npm/fastify-static@3.4.0",
188757          "swid": {
188758            "attachment": {}
188759          },
188760          "pedigree": {},
188761          "externalReferences": [
188762            {
188763              "url": "git+https://github.com/fastify/fastify-static.git",
188764              "type": "distribution"
188765            },
188766            {
188767              "url": "https://github.com/fastify/fastify-static",
188768              "type": "website"
188769            }
188770          ],
188771          "evidence": {},
188772          "signature": {
188773            "signature": {
188774              "publicKey": {}
188775            }
188776          },
188777          "modelCard": {
188778            "modelParameters": {
188779              "approach": {}
188780            },
188781            "quantitativeAnalysis": {
188782              "graphics": {}
188783            },
188784            "considerations": {}
188785          }
188786        },
188787        {
188788          "type": "library",
188789          "bom-ref": "pkg:npm/fastify-swagger@3.5.0?package-id=36ac3481c48adce7",
188790          "supplier": {},
188791          "author": "Tomas Della Vedova - @delvedor (http://delved.org)",
188792          "name": "fastify-swagger",
188793          "version": "3.5.0",
188794          "description": "Generate Swagger files automatically for Fastify.",
188795          "licenses": [
188796            {
188797              "license": {
188798                "id": "MIT"
188799              }
188800            }
188801          ],
188802          "cpe": "cpe:2.3:a:fastify-swagger:fastify-swagger:3.5.0:*:*:*:*:*:*:*",
188803          "purl": "pkg:npm/fastify-swagger@3.5.0",
188804          "swid": {
188805            "attachment": {}
188806          },
188807          "pedigree": {},
188808          "externalReferences": [
188809            {
188810              "url": "git+https://github.com/fastify/fastify-swagger.git",
188811              "type": "distribution"
188812            },
188813            {
188814              "url": "https://github.com/fastify/fastify-swagger#readme",
188815              "type": "website"
188816            }
188817          ],
188818          "evidence": {},
188819          "signature": {
188820            "signature": {
188821              "publicKey": {}
188822            }
188823          },
188824          "modelCard": {
188825            "modelParameters": {
188826              "approach": {}
188827            },
188828            "quantitativeAnalysis": {
188829              "graphics": {}
188830            },
188831            "considerations": {}
188832          }
188833        },
188834        {
188835          "type": "library",
188836          "bom-ref": "pkg:npm/figgy-pudding@3.5.1?package-id=c23a6d314b4a4c22",
188837          "supplier": {},
188838          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
188839          "name": "figgy-pudding",
188840          "version": "3.5.1",
188841          "description": "Delicious, festive, cascading config/opts definitions",
188842          "licenses": [
188843            {
188844              "license": {
188845                "id": "ISC"
188846              }
188847            }
188848          ],
188849          "cpe": "cpe:2.3:a:figgy-pudding:figgy-pudding:3.5.1:*:*:*:*:*:*:*",
188850          "purl": "pkg:npm/figgy-pudding@3.5.1",
188851          "swid": {
188852            "attachment": {}
188853          },
188854          "pedigree": {},
188855          "externalReferences": [
188856            {
188857              "url": "git+https://github.com/zkat/figgy-pudding.git",
188858              "type": "distribution"
188859            },
188860            {
188861              "url": "https://github.com/zkat/figgy-pudding#readme",
188862              "type": "website"
188863            }
188864          ],
188865          "evidence": {},
188866          "signature": {
188867            "signature": {
188868              "publicKey": {}
188869            }
188870          },
188871          "modelCard": {
188872            "modelParameters": {
188873              "approach": {}
188874            },
188875            "quantitativeAnalysis": {
188876              "graphics": {}
188877            },
188878            "considerations": {}
188879          }
188880        },
188881        {
188882          "type": "library",
188883          "bom-ref": "pkg:npm/finalhandler@1.1.2?package-id=6259b7a0001a9b91",
188884          "supplier": {},
188885          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
188886          "name": "finalhandler",
188887          "version": "1.1.2",
188888          "description": "Node.js final http responder",
188889          "licenses": [
188890            {
188891              "license": {
188892                "id": "MIT"
188893              }
188894            }
188895          ],
188896          "cpe": "cpe:2.3:a:finalhandler:finalhandler:1.1.2:*:*:*:*:*:*:*",
188897          "purl": "pkg:npm/finalhandler@1.1.2",
188898          "swid": {
188899            "attachment": {}
188900          },
188901          "pedigree": {},
188902          "externalReferences": [
188903            {
188904              "url": "git+https://github.com/pillarjs/finalhandler.git",
188905              "type": "distribution"
188906            },
188907            {
188908              "url": "https://github.com/pillarjs/finalhandler#readme",
188909              "type": "website"
188910            }
188911          ],
188912          "evidence": {},
188913          "signature": {
188914            "signature": {
188915              "publicKey": {}
188916            }
188917          },
188918          "modelCard": {
188919            "modelParameters": {
188920              "approach": {}
188921            },
188922            "quantitativeAnalysis": {
188923              "graphics": {}
188924            },
188925            "considerations": {}
188926          }
188927        },
188928        {
188929          "type": "library",
188930          "bom-ref": "pkg:npm/find-npm-prefix@1.0.2?package-id=52a36cf455f307ab",
188931          "supplier": {},
188932          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
188933          "name": "find-npm-prefix",
188934          "version": "1.0.2",
188935          "description": "Find the npm project directory associated with for a given directory",
188936          "licenses": [
188937            {
188938              "license": {
188939                "id": "ISC"
188940              }
188941            }
188942          ],
188943          "cpe": "cpe:2.3:a:find-npm-prefix:find-npm-prefix:1.0.2:*:*:*:*:*:*:*",
188944          "purl": "pkg:npm/find-npm-prefix@1.0.2",
188945          "swid": {
188946            "attachment": {}
188947          },
188948          "pedigree": {},
188949          "externalReferences": [
188950            {
188951              "url": "git+https://github.com/npm/find-npm-prefix.git",
188952              "type": "distribution"
188953            },
188954            {
188955              "url": "https://github.com/npm/find-npm-prefix#readme",
188956              "type": "website"
188957            }
188958          ],
188959          "evidence": {},
188960          "signature": {
188961            "signature": {
188962              "publicKey": {}
188963            }
188964          },
188965          "modelCard": {
188966            "modelParameters": {
188967              "approach": {}
188968            },
188969            "quantitativeAnalysis": {
188970              "graphics": {}
188971            },
188972            "considerations": {}
188973          }
188974        },
188975        {
188976          "type": "library",
188977          "bom-ref": "pkg:npm/find-up@3.0.0?package-id=74983d480f9ee68a",
188978          "supplier": {},
188979          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
188980          "name": "find-up",
188981          "version": "3.0.0",
188982          "description": "Find a file or directory by walking up parent directories",
188983          "licenses": [
188984            {
188985              "license": {
188986                "id": "MIT"
188987              }
188988            }
188989          ],
188990          "cpe": "cpe:2.3:a:sindresorhus:find-up:3.0.0:*:*:*:*:*:*:*",
188991          "purl": "pkg:npm/find-up@3.0.0",
188992          "swid": {
188993            "attachment": {}
188994          },
188995          "pedigree": {},
188996          "externalReferences": [
188997            {
188998              "url": "git+https://github.com/sindresorhus/find-up.git",
188999              "type": "distribution"
189000            },
189001            {
189002              "url": "https://github.com/sindresorhus/find-up#readme",
189003              "type": "website"
189004            }
189005          ],
189006          "evidence": {},
189007          "signature": {
189008            "signature": {
189009              "publicKey": {}
189010            }
189011          },
189012          "modelCard": {
189013            "modelParameters": {
189014              "approach": {}
189015            },
189016            "quantitativeAnalysis": {
189017              "graphics": {}
189018            },
189019            "considerations": {}
189020          }
189021        },
189022        {
189023          "type": "library",
189024          "bom-ref": "pkg:npm/find-up@3.0.0?package-id=9716c27e89885f20",
189025          "supplier": {},
189026          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
189027          "name": "find-up",
189028          "version": "3.0.0",
189029          "description": "Find a file or directory by walking up parent directories",
189030          "licenses": [
189031            {
189032              "license": {
189033                "id": "MIT"
189034              }
189035            }
189036          ],
189037          "cpe": "cpe:2.3:a:sindresorhus:find-up:3.0.0:*:*:*:*:*:*:*",
189038          "purl": "pkg:npm/find-up@3.0.0",
189039          "swid": {
189040            "attachment": {}
189041          },
189042          "pedigree": {},
189043          "externalReferences": [
189044            {
189045              "url": "git+https://github.com/sindresorhus/find-up.git",
189046              "type": "distribution"
189047            },
189048            {
189049              "url": "https://github.com/sindresorhus/find-up#readme",
189050              "type": "website"
189051            }
189052          ],
189053          "evidence": {},
189054          "signature": {
189055            "signature": {
189056              "publicKey": {}
189057            }
189058          },
189059          "modelCard": {
189060            "modelParameters": {
189061              "approach": {}
189062            },
189063            "quantitativeAnalysis": {
189064              "graphics": {}
189065            },
189066            "considerations": {}
189067          }
189068        },
189069        {
189070          "type": "library",
189071          "bom-ref": "pkg:npm/flush-write-stream@1.0.3?package-id=e1274c36a6d8d9af",
189072          "supplier": {},
189073          "author": "Mathias Buus (@mafintosh)",
189074          "name": "flush-write-stream",
189075          "version": "1.0.3",
189076          "description": "A write stream constructor that supports a flush function that is called before finish is emitted",
189077          "licenses": [
189078            {
189079              "license": {
189080                "id": "MIT"
189081              }
189082            }
189083          ],
189084          "cpe": "cpe:2.3:a:flush-write-stream:flush-write-stream:1.0.3:*:*:*:*:*:*:*",
189085          "purl": "pkg:npm/flush-write-stream@1.0.3",
189086          "swid": {
189087            "attachment": {}
189088          },
189089          "pedigree": {},
189090          "externalReferences": [
189091            {
189092              "url": "git+https://github.com/mafintosh/flush-write-stream.git",
189093              "type": "distribution"
189094            },
189095            {
189096              "url": "https://github.com/mafintosh/flush-write-stream",
189097              "type": "website"
189098            }
189099          ],
189100          "evidence": {},
189101          "signature": {
189102            "signature": {
189103              "publicKey": {}
189104            }
189105          },
189106          "modelCard": {
189107            "modelParameters": {
189108              "approach": {}
189109            },
189110            "quantitativeAnalysis": {
189111              "graphics": {}
189112            },
189113            "considerations": {}
189114          }
189115        },
189116        {
189117          "type": "library",
189118          "bom-ref": "pkg:npm/follow-redirects@1.13.2?package-id=11d925047a942922",
189119          "supplier": {},
189120          "author": "Ruben Verborgh \u003cruben@verborgh.org\u003e (https://ruben.verborgh.org/)",
189121          "name": "follow-redirects",
189122          "version": "1.13.2",
189123          "description": "HTTP and HTTPS modules that follow redirects.",
189124          "licenses": [
189125            {
189126              "license": {
189127                "id": "MIT"
189128              }
189129            }
189130          ],
189131          "cpe": "cpe:2.3:a:follow-redirects:follow-redirects:1.13.2:*:*:*:*:*:*:*",
189132          "purl": "pkg:npm/follow-redirects@1.13.2",
189133          "swid": {
189134            "attachment": {}
189135          },
189136          "pedigree": {},
189137          "externalReferences": [
189138            {
189139              "url": "git+ssh://git@github.com/follow-redirects/follow-redirects.git",
189140              "type": "distribution"
189141            },
189142            {
189143              "url": "https://github.com/follow-redirects/follow-redirects",
189144              "type": "website"
189145            }
189146          ],
189147          "evidence": {},
189148          "signature": {
189149            "signature": {
189150              "publicKey": {}
189151            }
189152          },
189153          "modelCard": {
189154            "modelParameters": {
189155              "approach": {}
189156            },
189157            "quantitativeAnalysis": {
189158              "graphics": {}
189159            },
189160            "considerations": {}
189161          }
189162        },
189163        {
189164          "type": "library",
189165          "bom-ref": "pkg:npm/forever-agent@0.6.1?package-id=f246b38c6ee5f71b",
189166          "supplier": {},
189167          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
189168          "name": "forever-agent",
189169          "version": "0.6.1",
189170          "description": "HTTP Agent that keeps socket connections alive between keep-alive requests. Formerly part of mikeal/request, now a standalone module.",
189171          "licenses": [
189172            {
189173              "license": {
189174                "id": "Apache-2.0"
189175              }
189176            }
189177          ],
189178          "cpe": "cpe:2.3:a:forever-agent:forever-agent:0.6.1:*:*:*:*:*:*:*",
189179          "purl": "pkg:npm/forever-agent@0.6.1",
189180          "swid": {
189181            "attachment": {}
189182          },
189183          "pedigree": {},
189184          "externalReferences": [
189185            {
189186              "url": "git+https://github.com/mikeal/forever-agent.git",
189187              "type": "distribution"
189188            },
189189            {
189190              "url": "https://github.com/mikeal/forever-agent#readme",
189191              "type": "website"
189192            }
189193          ],
189194          "evidence": {},
189195          "signature": {
189196            "signature": {
189197              "publicKey": {}
189198            }
189199          },
189200          "modelCard": {
189201            "modelParameters": {
189202              "approach": {}
189203            },
189204            "quantitativeAnalysis": {
189205              "graphics": {}
189206            },
189207            "considerations": {}
189208          }
189209        },
189210        {
189211          "type": "library",
189212          "bom-ref": "pkg:npm/form-data@2.3.2?package-id=a65eba2cf670811b",
189213          "supplier": {},
189214          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
189215          "name": "form-data",
189216          "version": "2.3.2",
189217          "description": "A library to create readable \"multipart/form-data\" streams. Can be used to submit forms and file uploads to other web applications.",
189218          "licenses": [
189219            {
189220              "license": {
189221                "id": "MIT"
189222              }
189223            }
189224          ],
189225          "cpe": "cpe:2.3:a:form-data:form-data:2.3.2:*:*:*:*:*:*:*",
189226          "purl": "pkg:npm/form-data@2.3.2",
189227          "swid": {
189228            "attachment": {}
189229          },
189230          "pedigree": {},
189231          "externalReferences": [
189232            {
189233              "url": "git://github.com/form-data/form-data.git",
189234              "type": "distribution"
189235            },
189236            {
189237              "url": "https://github.com/form-data/form-data#readme",
189238              "type": "website"
189239            }
189240          ],
189241          "evidence": {},
189242          "signature": {
189243            "signature": {
189244              "publicKey": {}
189245            }
189246          },
189247          "modelCard": {
189248            "modelParameters": {
189249              "approach": {}
189250            },
189251            "quantitativeAnalysis": {
189252              "graphics": {}
189253            },
189254            "considerations": {}
189255          }
189256        },
189257        {
189258          "type": "library",
189259          "bom-ref": "pkg:npm/forwarded@0.1.2?package-id=5628d515e146bf2f",
189260          "supplier": {},
189261          "name": "forwarded",
189262          "version": "0.1.2",
189263          "description": "Parse HTTP X-Forwarded-For header",
189264          "licenses": [
189265            {
189266              "license": {
189267                "id": "MIT"
189268              }
189269            }
189270          ],
189271          "cpe": "cpe:2.3:a:forwarded:forwarded:0.1.2:*:*:*:*:*:*:*",
189272          "purl": "pkg:npm/forwarded@0.1.2",
189273          "swid": {
189274            "attachment": {}
189275          },
189276          "pedigree": {},
189277          "externalReferences": [
189278            {
189279              "url": "git+https://github.com/jshttp/forwarded.git",
189280              "type": "distribution"
189281            },
189282            {
189283              "url": "https://github.com/jshttp/forwarded#readme",
189284              "type": "website"
189285            }
189286          ],
189287          "evidence": {},
189288          "signature": {
189289            "signature": {
189290              "publicKey": {}
189291            }
189292          },
189293          "modelCard": {
189294            "modelParameters": {
189295              "approach": {}
189296            },
189297            "quantitativeAnalysis": {
189298              "graphics": {}
189299            },
189300            "considerations": {}
189301          }
189302        },
189303        {
189304          "type": "library",
189305          "bom-ref": "pkg:npm/fresh@0.5.2?package-id=1aacf9842bb86f3e",
189306          "supplier": {},
189307          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
189308          "name": "fresh",
189309          "version": "0.5.2",
189310          "description": "HTTP response freshness testing",
189311          "licenses": [
189312            {
189313              "license": {
189314                "id": "MIT"
189315              }
189316            }
189317          ],
189318          "cpe": "cpe:2.3:a:jshttp:fresh:0.5.2:*:*:*:*:*:*:*",
189319          "purl": "pkg:npm/fresh@0.5.2",
189320          "swid": {
189321            "attachment": {}
189322          },
189323          "pedigree": {},
189324          "externalReferences": [
189325            {
189326              "url": "git+https://github.com/jshttp/fresh.git",
189327              "type": "distribution"
189328            },
189329            {
189330              "url": "https://github.com/jshttp/fresh#readme",
189331              "type": "website"
189332            }
189333          ],
189334          "evidence": {},
189335          "signature": {
189336            "signature": {
189337              "publicKey": {}
189338            }
189339          },
189340          "modelCard": {
189341            "modelParameters": {
189342              "approach": {}
189343            },
189344            "quantitativeAnalysis": {
189345              "graphics": {}
189346            },
189347            "considerations": {}
189348          }
189349        },
189350        {
189351          "type": "library",
189352          "bom-ref": "pkg:npm/from2@1.3.0?package-id=c7f3a7e49c7e8f25",
189353          "supplier": {},
189354          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
189355          "name": "from2",
189356          "version": "1.3.0",
189357          "description": "Convenience wrapper for ReadableStream, with an API lifted from \"from\" and \"through2\"",
189358          "licenses": [
189359            {
189360              "license": {
189361                "id": "MIT"
189362              }
189363            }
189364          ],
189365          "cpe": "cpe:2.3:a:hughsk:from2:1.3.0:*:*:*:*:*:*:*",
189366          "purl": "pkg:npm/from2@1.3.0",
189367          "swid": {
189368            "attachment": {}
189369          },
189370          "pedigree": {},
189371          "externalReferences": [
189372            {
189373              "url": "git://github.com/hughsk/from2.git",
189374              "type": "distribution"
189375            },
189376            {
189377              "url": "https://github.com/hughsk/from2",
189378              "type": "website"
189379            }
189380          ],
189381          "evidence": {},
189382          "signature": {
189383            "signature": {
189384              "publicKey": {}
189385            }
189386          },
189387          "modelCard": {
189388            "modelParameters": {
189389              "approach": {}
189390            },
189391            "quantitativeAnalysis": {
189392              "graphics": {}
189393            },
189394            "considerations": {}
189395          }
189396        },
189397        {
189398          "type": "library",
189399          "bom-ref": "pkg:npm/from2@2.3.0?package-id=ee2d6b417c35bfd2",
189400          "supplier": {},
189401          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
189402          "name": "from2",
189403          "version": "2.3.0",
189404          "description": "Convenience wrapper for ReadableStream, with an API lifted from \"from\" and \"through2\"",
189405          "licenses": [
189406            {
189407              "license": {
189408                "id": "MIT"
189409              }
189410            }
189411          ],
189412          "cpe": "cpe:2.3:a:hughsk:from2:2.3.0:*:*:*:*:*:*:*",
189413          "purl": "pkg:npm/from2@2.3.0",
189414          "swid": {
189415            "attachment": {}
189416          },
189417          "pedigree": {},
189418          "externalReferences": [
189419            {
189420              "url": "git://github.com/hughsk/from2.git",
189421              "type": "distribution"
189422            },
189423            {
189424              "url": "https://github.com/hughsk/from2",
189425              "type": "website"
189426            }
189427          ],
189428          "evidence": {},
189429          "signature": {
189430            "signature": {
189431              "publicKey": {}
189432            }
189433          },
189434          "modelCard": {
189435            "modelParameters": {
189436              "approach": {}
189437            },
189438            "quantitativeAnalysis": {
189439              "graphics": {}
189440            },
189441            "considerations": {}
189442          }
189443        },
189444        {
189445          "type": "library",
189446          "bom-ref": "pkg:npm/fs-minipass@1.2.7?package-id=2e904f22ead50ae2",
189447          "supplier": {},
189448          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
189449          "name": "fs-minipass",
189450          "version": "1.2.7",
189451          "description": "fs read and write streams based on minipass",
189452          "licenses": [
189453            {
189454              "license": {
189455                "id": "ISC"
189456              }
189457            }
189458          ],
189459          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:1.2.7:*:*:*:*:*:*:*",
189460          "purl": "pkg:npm/fs-minipass@1.2.7",
189461          "swid": {
189462            "attachment": {}
189463          },
189464          "pedigree": {},
189465          "externalReferences": [
189466            {
189467              "url": "git+https://github.com/npm/fs-minipass.git",
189468              "type": "distribution"
189469            },
189470            {
189471              "url": "https://github.com/npm/fs-minipass#readme",
189472              "type": "website"
189473            }
189474          ],
189475          "evidence": {},
189476          "signature": {
189477            "signature": {
189478              "publicKey": {}
189479            }
189480          },
189481          "modelCard": {
189482            "modelParameters": {
189483              "approach": {}
189484            },
189485            "quantitativeAnalysis": {
189486              "graphics": {}
189487            },
189488            "considerations": {}
189489          }
189490        },
189491        {
189492          "type": "library",
189493          "bom-ref": "pkg:npm/fs-vacuum@1.2.10?package-id=b9aa5d16af1961b0",
189494          "supplier": {},
189495          "author": "Forrest L Norvell \u003cogd@aoaioxxysz.net\u003e",
189496          "name": "fs-vacuum",
189497          "version": "1.2.10",
189498          "description": "recursively remove empty directories -- to a point",
189499          "licenses": [
189500            {
189501              "license": {
189502                "id": "ISC"
189503              }
189504            }
189505          ],
189506          "cpe": "cpe:2.3:a:fs-vacuum:fs-vacuum:1.2.10:*:*:*:*:*:*:*",
189507          "purl": "pkg:npm/fs-vacuum@1.2.10",
189508          "swid": {
189509            "attachment": {}
189510          },
189511          "pedigree": {},
189512          "externalReferences": [
189513            {
189514              "url": "git+https://github.com/npm/fs-vacuum.git",
189515              "type": "distribution"
189516            },
189517            {
189518              "url": "https://github.com/npm/fs-vacuum",
189519              "type": "website"
189520            }
189521          ],
189522          "evidence": {},
189523          "signature": {
189524            "signature": {
189525              "publicKey": {}
189526            }
189527          },
189528          "modelCard": {
189529            "modelParameters": {
189530              "approach": {}
189531            },
189532            "quantitativeAnalysis": {
189533              "graphics": {}
189534            },
189535            "considerations": {}
189536          }
189537        },
189538        {
189539          "type": "library",
189540          "bom-ref": "pkg:npm/fs-write-stream-atomic@1.0.10?package-id=7b08016bb08061fe",
189541          "supplier": {},
189542          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
189543          "name": "fs-write-stream-atomic",
189544          "version": "1.0.10",
189545          "description": "Like `fs.createWriteStream(...)`, but atomic.",
189546          "licenses": [
189547            {
189548              "license": {
189549                "id": "ISC"
189550              }
189551            }
189552          ],
189553          "cpe": "cpe:2.3:a:fs-write-stream-atomic:fs-write-stream-atomic:1.0.10:*:*:*:*:*:*:*",
189554          "purl": "pkg:npm/fs-write-stream-atomic@1.0.10",
189555          "swid": {
189556            "attachment": {}
189557          },
189558          "pedigree": {},
189559          "externalReferences": [
189560            {
189561              "url": "git+https://github.com/npm/fs-write-stream-atomic.git",
189562              "type": "distribution"
189563            },
189564            {
189565              "url": "https://github.com/npm/fs-write-stream-atomic",
189566              "type": "website"
189567            }
189568          ],
189569          "evidence": {},
189570          "signature": {
189571            "signature": {
189572              "publicKey": {}
189573            }
189574          },
189575          "modelCard": {
189576            "modelParameters": {
189577              "approach": {}
189578            },
189579            "quantitativeAnalysis": {
189580              "graphics": {}
189581            },
189582            "considerations": {}
189583          }
189584        },
189585        {
189586          "type": "library",
189587          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=9584ea0c034d1c3c",
189588          "supplier": {},
189589          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
189590          "name": "fs.realpath",
189591          "version": "1.0.0",
189592          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
189593          "licenses": [
189594            {
189595              "license": {
189596                "id": "ISC"
189597              }
189598            }
189599          ],
189600          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
189601          "purl": "pkg:npm/fs.realpath@1.0.0",
189602          "swid": {
189603            "attachment": {}
189604          },
189605          "pedigree": {},
189606          "externalReferences": [
189607            {
189608              "url": "git+https://github.com/isaacs/fs.realpath.git",
189609              "type": "distribution"
189610            },
189611            {
189612              "url": "https://github.com/isaacs/fs.realpath#readme",
189613              "type": "website"
189614            }
189615          ],
189616          "evidence": {},
189617          "signature": {
189618            "signature": {
189619              "publicKey": {}
189620            }
189621          },
189622          "modelCard": {
189623            "modelParameters": {
189624              "approach": {}
189625            },
189626            "quantitativeAnalysis": {
189627              "graphics": {}
189628            },
189629            "considerations": {}
189630          }
189631        },
189632        {
189633          "type": "library",
189634          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=ac3c818d9ca6548d",
189635          "supplier": {},
189636          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
189637          "name": "fs.realpath",
189638          "version": "1.0.0",
189639          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
189640          "licenses": [
189641            {
189642              "license": {
189643                "id": "ISC"
189644              }
189645            }
189646          ],
189647          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
189648          "purl": "pkg:npm/fs.realpath@1.0.0",
189649          "swid": {
189650            "attachment": {}
189651          },
189652          "pedigree": {},
189653          "externalReferences": [
189654            {
189655              "url": "git+https://github.com/isaacs/fs.realpath.git",
189656              "type": "distribution"
189657            },
189658            {
189659              "url": "https://github.com/isaacs/fs.realpath#readme",
189660              "type": "website"
189661            }
189662          ],
189663          "evidence": {},
189664          "signature": {
189665            "signature": {
189666              "publicKey": {}
189667            }
189668          },
189669          "modelCard": {
189670            "modelParameters": {
189671              "approach": {}
189672            },
189673            "quantitativeAnalysis": {
189674              "graphics": {}
189675            },
189676            "considerations": {}
189677          }
189678        },
189679        {
189680          "type": "library",
189681          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=44648bf09db15f6c",
189682          "supplier": {},
189683          "author": "Raynos \u003craynos2@gmail.com\u003e",
189684          "name": "function-bind",
189685          "version": "1.1.1",
189686          "description": "Implementation of Function.prototype.bind",
189687          "licenses": [
189688            {
189689              "license": {
189690                "id": "MIT"
189691              }
189692            }
189693          ],
189694          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
189695          "purl": "pkg:npm/function-bind@1.1.1",
189696          "swid": {
189697            "attachment": {}
189698          },
189699          "pedigree": {},
189700          "externalReferences": [
189701            {
189702              "url": "git://github.com/Raynos/function-bind.git",
189703              "type": "distribution"
189704            },
189705            {
189706              "url": "https://github.com/Raynos/function-bind",
189707              "type": "website"
189708            }
189709          ],
189710          "evidence": {},
189711          "signature": {
189712            "signature": {
189713              "publicKey": {}
189714            }
189715          },
189716          "modelCard": {
189717            "modelParameters": {
189718              "approach": {}
189719            },
189720            "quantitativeAnalysis": {
189721              "graphics": {}
189722            },
189723            "considerations": {}
189724          }
189725        },
189726        {
189727          "type": "library",
189728          "bom-ref": "pkg:npm/gauge@2.7.4?package-id=ea01ccd89b49fe1f",
189729          "supplier": {},
189730          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
189731          "name": "gauge",
189732          "version": "2.7.4",
189733          "description": "A terminal based horizontal guage",
189734          "licenses": [
189735            {
189736              "license": {
189737                "id": "ISC"
189738              }
189739            }
189740          ],
189741          "cpe": "cpe:2.3:a:gauge:gauge:2.7.4:*:*:*:*:*:*:*",
189742          "purl": "pkg:npm/gauge@2.7.4",
189743          "swid": {
189744            "attachment": {}
189745          },
189746          "pedigree": {},
189747          "externalReferences": [
189748            {
189749              "url": "git+https://github.com/iarna/gauge.git",
189750              "type": "distribution"
189751            },
189752            {
189753              "url": "https://github.com/iarna/gauge",
189754              "type": "website"
189755            }
189756          ],
189757          "evidence": {},
189758          "signature": {
189759            "signature": {
189760              "publicKey": {}
189761            }
189762          },
189763          "modelCard": {
189764            "modelParameters": {
189765              "approach": {}
189766            },
189767            "quantitativeAnalysis": {
189768              "graphics": {}
189769            },
189770            "considerations": {}
189771          }
189772        },
189773        {
189774          "type": "library",
189775          "bom-ref": "pkg:npm/genfun@5.0.0?package-id=6ca73a56321ec465",
189776          "supplier": {},
189777          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
189778          "name": "genfun",
189779          "version": "5.0.0",
189780          "description": "Fast, prototype-friendly multimethods.",
189781          "licenses": [
189782            {
189783              "license": {
189784                "id": "MIT"
189785              }
189786            }
189787          ],
189788          "cpe": "cpe:2.3:a:genfun:genfun:5.0.0:*:*:*:*:*:*:*",
189789          "purl": "pkg:npm/genfun@5.0.0",
189790          "swid": {
189791            "attachment": {}
189792          },
189793          "pedigree": {},
189794          "externalReferences": [
189795            {
189796              "url": "git://github.com/zkat/genfun.git",
189797              "type": "distribution"
189798            },
189799            {
189800              "url": "http://github.com/zkat/genfun",
189801              "type": "website"
189802            }
189803          ],
189804          "evidence": {},
189805          "signature": {
189806            "signature": {
189807              "publicKey": {}
189808            }
189809          },
189810          "modelCard": {
189811            "modelParameters": {
189812              "approach": {}
189813            },
189814            "quantitativeAnalysis": {
189815              "graphics": {}
189816            },
189817            "considerations": {}
189818          }
189819        },
189820        {
189821          "type": "library",
189822          "bom-ref": "pkg:npm/gentle-fs@2.3.1?package-id=9e57430eae250bbf",
189823          "supplier": {},
189824          "author": "Mike Sherov",
189825          "name": "gentle-fs",
189826          "version": "2.3.1",
189827          "description": "Gentle Filesystem operations",
189828          "licenses": [
189829            {
189830              "license": {
189831                "id": "Artistic-2.0"
189832              }
189833            }
189834          ],
189835          "cpe": "cpe:2.3:a:gentle-fs:gentle-fs:2.3.1:*:*:*:*:*:*:*",
189836          "purl": "pkg:npm/gentle-fs@2.3.1",
189837          "swid": {
189838            "attachment": {}
189839          },
189840          "pedigree": {},
189841          "externalReferences": [
189842            {
189843              "url": "git://github.com/npm/gentle-fs.git",
189844              "type": "distribution"
189845            },
189846            {
189847              "url": "https://github.com/npm/gentle-fs#readme",
189848              "type": "website"
189849            }
189850          ],
189851          "evidence": {},
189852          "signature": {
189853            "signature": {
189854              "publicKey": {}
189855            }
189856          },
189857          "modelCard": {
189858            "modelParameters": {
189859              "approach": {}
189860            },
189861            "quantitativeAnalysis": {
189862              "graphics": {}
189863            },
189864            "considerations": {}
189865          }
189866        },
189867        {
189868          "type": "library",
189869          "bom-ref": "pkg:npm/get-caller-file@2.0.5?package-id=c3a7c0e90ec1bd2a",
189870          "supplier": {},
189871          "author": "Stefan Penner",
189872          "name": "get-caller-file",
189873          "version": "2.0.5",
189874          "description": "[![Build Status](https://travis-ci.org/stefanpenner/get-caller-file.svg?branch=master)](https://travis-ci.org/stefanpenner/get-caller-file) [![Build status](https://ci.appveyor.com/api/projects/status/ol2q94g1932cy14a/branch/master?svg=true)](https://ci.appveyor.com/project/embercli/get-caller-file/branch/master)",
189875          "licenses": [
189876            {
189877              "license": {
189878                "id": "ISC"
189879              }
189880            }
189881          ],
189882          "cpe": "cpe:2.3:a:get-caller-file:get-caller-file:2.0.5:*:*:*:*:*:*:*",
189883          "purl": "pkg:npm/get-caller-file@2.0.5",
189884          "swid": {
189885            "attachment": {}
189886          },
189887          "pedigree": {},
189888          "externalReferences": [
189889            {
189890              "url": "git+https://github.com/stefanpenner/get-caller-file.git",
189891              "type": "distribution"
189892            },
189893            {
189894              "url": "https://github.com/stefanpenner/get-caller-file#readme",
189895              "type": "website"
189896            }
189897          ],
189898          "evidence": {},
189899          "signature": {
189900            "signature": {
189901              "publicKey": {}
189902            }
189903          },
189904          "modelCard": {
189905            "modelParameters": {
189906              "approach": {}
189907            },
189908            "quantitativeAnalysis": {
189909              "graphics": {}
189910            },
189911            "considerations": {}
189912          }
189913        },
189914        {
189915          "type": "library",
189916          "bom-ref": "pkg:npm/get-stream@3.0.0?package-id=1101f5258c5b4846",
189917          "supplier": {},
189918          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
189919          "name": "get-stream",
189920          "version": "3.0.0",
189921          "description": "Get a stream as a string, buffer, or array",
189922          "licenses": [
189923            {
189924              "license": {
189925                "id": "MIT"
189926              }
189927            }
189928          ],
189929          "cpe": "cpe:2.3:a:sindresorhus:get-stream:3.0.0:*:*:*:*:*:*:*",
189930          "purl": "pkg:npm/get-stream@3.0.0",
189931          "swid": {
189932            "attachment": {}
189933          },
189934          "pedigree": {},
189935          "externalReferences": [
189936            {
189937              "url": "git+https://github.com/sindresorhus/get-stream.git",
189938              "type": "distribution"
189939            },
189940            {
189941              "url": "https://github.com/sindresorhus/get-stream#readme",
189942              "type": "website"
189943            }
189944          ],
189945          "evidence": {},
189946          "signature": {
189947            "signature": {
189948              "publicKey": {}
189949            }
189950          },
189951          "modelCard": {
189952            "modelParameters": {
189953              "approach": {}
189954            },
189955            "quantitativeAnalysis": {
189956              "graphics": {}
189957            },
189958            "considerations": {}
189959          }
189960        },
189961        {
189962          "type": "library",
189963          "bom-ref": "pkg:npm/get-stream@3.0.0?package-id=d5ca602593287b20",
189964          "supplier": {},
189965          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
189966          "name": "get-stream",
189967          "version": "3.0.0",
189968          "description": "Get a stream as a string, buffer, or array",
189969          "licenses": [
189970            {
189971              "license": {
189972                "id": "MIT"
189973              }
189974            }
189975          ],
189976          "cpe": "cpe:2.3:a:sindresorhus:get-stream:3.0.0:*:*:*:*:*:*:*",
189977          "purl": "pkg:npm/get-stream@3.0.0",
189978          "swid": {
189979            "attachment": {}
189980          },
189981          "pedigree": {},
189982          "externalReferences": [
189983            {
189984              "url": "git+https://github.com/sindresorhus/get-stream.git",
189985              "type": "distribution"
189986            },
189987            {
189988              "url": "https://github.com/sindresorhus/get-stream#readme",
189989              "type": "website"
189990            }
189991          ],
189992          "evidence": {},
189993          "signature": {
189994            "signature": {
189995              "publicKey": {}
189996            }
189997          },
189998          "modelCard": {
189999            "modelParameters": {
190000              "approach": {}
190001            },
190002            "quantitativeAnalysis": {
190003              "graphics": {}
190004            },
190005            "considerations": {}
190006          }
190007        },
190008        {
190009          "type": "library",
190010          "bom-ref": "pkg:npm/get-stream@4.1.0?package-id=d90dfcea848a9fbf",
190011          "supplier": {},
190012          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
190013          "name": "get-stream",
190014          "version": "4.1.0",
190015          "description": "Get a stream as a string, buffer, or array",
190016          "licenses": [
190017            {
190018              "license": {
190019                "id": "MIT"
190020              }
190021            }
190022          ],
190023          "cpe": "cpe:2.3:a:sindresorhus:get-stream:4.1.0:*:*:*:*:*:*:*",
190024          "purl": "pkg:npm/get-stream@4.1.0",
190025          "swid": {
190026            "attachment": {}
190027          },
190028          "pedigree": {},
190029          "externalReferences": [
190030            {
190031              "url": "git+https://github.com/sindresorhus/get-stream.git",
190032              "type": "distribution"
190033            },
190034            {
190035              "url": "https://github.com/sindresorhus/get-stream#readme",
190036              "type": "website"
190037            }
190038          ],
190039          "evidence": {},
190040          "signature": {
190041            "signature": {
190042              "publicKey": {}
190043            }
190044          },
190045          "modelCard": {
190046            "modelParameters": {
190047              "approach": {}
190048            },
190049            "quantitativeAnalysis": {
190050              "graphics": {}
190051            },
190052            "considerations": {}
190053          }
190054        },
190055        {
190056          "type": "library",
190057          "bom-ref": "pkg:npm/getpass@0.1.7?package-id=25b6b9755ea147b4",
190058          "supplier": {},
190059          "author": "Alex Wilson \u003calex.wilson@joyent.com\u003e",
190060          "name": "getpass",
190061          "version": "0.1.7",
190062          "description": "getpass for node.js",
190063          "licenses": [
190064            {
190065              "license": {
190066                "id": "MIT"
190067              }
190068            }
190069          ],
190070          "cpe": "cpe:2.3:a:arekinath:getpass:0.1.7:*:*:*:*:*:*:*",
190071          "purl": "pkg:npm/getpass@0.1.7",
190072          "swid": {
190073            "attachment": {}
190074          },
190075          "pedigree": {},
190076          "externalReferences": [
190077            {
190078              "url": "git+https://github.com/arekinath/node-getpass.git",
190079              "type": "distribution"
190080            },
190081            {
190082              "url": "https://github.com/arekinath/node-getpass#readme",
190083              "type": "website"
190084            }
190085          ],
190086          "evidence": {},
190087          "signature": {
190088            "signature": {
190089              "publicKey": {}
190090            }
190091          },
190092          "modelCard": {
190093            "modelParameters": {
190094              "approach": {}
190095            },
190096            "quantitativeAnalysis": {
190097              "graphics": {}
190098            },
190099            "considerations": {}
190100          }
190101        },
190102        {
190103          "type": "library",
190104          "bom-ref": "pkg:npm/glob@7.1.6?package-id=be41ab1822148062",
190105          "supplier": {},
190106          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
190107          "name": "glob",
190108          "version": "7.1.6",
190109          "description": "a little globber",
190110          "licenses": [
190111            {
190112              "license": {
190113                "id": "ISC"
190114              }
190115            }
190116          ],
190117          "cpe": "cpe:2.3:a:isaacs:glob:7.1.6:*:*:*:*:*:*:*",
190118          "purl": "pkg:npm/glob@7.1.6",
190119          "swid": {
190120            "attachment": {}
190121          },
190122          "pedigree": {},
190123          "externalReferences": [
190124            {
190125              "url": "git://github.com/isaacs/node-glob.git",
190126              "type": "distribution"
190127            },
190128            {
190129              "url": "https://github.com/isaacs/node-glob#readme",
190130              "type": "website"
190131            }
190132          ],
190133          "evidence": {},
190134          "signature": {
190135            "signature": {
190136              "publicKey": {}
190137            }
190138          },
190139          "modelCard": {
190140            "modelParameters": {
190141              "approach": {}
190142            },
190143            "quantitativeAnalysis": {
190144              "graphics": {}
190145            },
190146            "considerations": {}
190147          }
190148        },
190149        {
190150          "type": "library",
190151          "bom-ref": "pkg:npm/glob@7.1.6?package-id=460f2e393a17861d",
190152          "supplier": {},
190153          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
190154          "name": "glob",
190155          "version": "7.1.6",
190156          "description": "a little globber",
190157          "licenses": [
190158            {
190159              "license": {
190160                "id": "ISC"
190161              }
190162            }
190163          ],
190164          "cpe": "cpe:2.3:a:isaacs:glob:7.1.6:*:*:*:*:*:*:*",
190165          "purl": "pkg:npm/glob@7.1.6",
190166          "swid": {
190167            "attachment": {}
190168          },
190169          "pedigree": {},
190170          "externalReferences": [
190171            {
190172              "url": "git://github.com/isaacs/node-glob.git",
190173              "type": "distribution"
190174            },
190175            {
190176              "url": "https://github.com/isaacs/node-glob#readme",
190177              "type": "website"
190178            }
190179          ],
190180          "evidence": {},
190181          "signature": {
190182            "signature": {
190183              "publicKey": {}
190184            }
190185          },
190186          "modelCard": {
190187            "modelParameters": {
190188              "approach": {}
190189            },
190190            "quantitativeAnalysis": {
190191              "graphics": {}
190192            },
190193            "considerations": {}
190194          }
190195        },
190196        {
190197          "type": "library",
190198          "bom-ref": "pkg:npm/global-dirs@0.1.1?package-id=a81eae1ffee86ac6",
190199          "supplier": {},
190200          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
190201          "name": "global-dirs",
190202          "version": "0.1.1",
190203          "description": "Get the directory of globally installed packages and binaries",
190204          "licenses": [
190205            {
190206              "license": {
190207                "id": "MIT"
190208              }
190209            }
190210          ],
190211          "cpe": "cpe:2.3:a:sindresorhus:global-dirs:0.1.1:*:*:*:*:*:*:*",
190212          "purl": "pkg:npm/global-dirs@0.1.1",
190213          "swid": {
190214            "attachment": {}
190215          },
190216          "pedigree": {},
190217          "externalReferences": [
190218            {
190219              "url": "git+https://github.com/sindresorhus/global-dirs.git",
190220              "type": "distribution"
190221            },
190222            {
190223              "url": "https://github.com/sindresorhus/global-dirs#readme",
190224              "type": "website"
190225            }
190226          ],
190227          "evidence": {},
190228          "signature": {
190229            "signature": {
190230              "publicKey": {}
190231            }
190232          },
190233          "modelCard": {
190234            "modelParameters": {
190235              "approach": {}
190236            },
190237            "quantitativeAnalysis": {
190238              "graphics": {}
190239            },
190240            "considerations": {}
190241          }
190242        },
190243        {
190244          "type": "library",
190245          "bom-ref": "pkg:npm/globalthis@1.0.3?package-id=140b7f899d64d402",
190246          "supplier": {},
190247          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
190248          "name": "globalthis",
190249          "version": "1.0.3",
190250          "description": "ECMAScript spec-compliant polyfill/shim for `globalThis`",
190251          "licenses": [
190252            {
190253              "license": {
190254                "id": "MIT"
190255              }
190256            }
190257          ],
190258          "cpe": "cpe:2.3:a:globalthis:globalthis:1.0.3:*:*:*:*:*:*:*",
190259          "purl": "pkg:npm/globalthis@1.0.3",
190260          "swid": {
190261            "attachment": {}
190262          },
190263          "pedigree": {},
190264          "externalReferences": [
190265            {
190266              "url": "git://github.com/ljharb/System.global.git",
190267              "type": "distribution"
190268            },
190269            {
190270              "url": "https://github.com/ljharb/System.global#readme",
190271              "type": "website"
190272            }
190273          ],
190274          "evidence": {},
190275          "signature": {
190276            "signature": {
190277              "publicKey": {}
190278            }
190279          },
190280          "modelCard": {
190281            "modelParameters": {
190282              "approach": {}
190283            },
190284            "quantitativeAnalysis": {
190285              "graphics": {}
190286            },
190287            "considerations": {}
190288          }
190289        },
190290        {
190291          "type": "library",
190292          "bom-ref": "pkg:npm/google-libphonenumber@3.2.17?package-id=e6ed838b7eadf96c",
190293          "supplier": {},
190294          "author": "Rui Marinho \u003cruipmarinho@gmail.com\u003e",
190295          "name": "google-libphonenumber",
190296          "version": "3.2.17",
190297          "description": "The up-to-date and reliable Google's libphonenumber package for node.js.",
190298          "licenses": [
190299            {
190300              "license": {
190301                "name": "(MIT AND Apache-2.0)"
190302              }
190303            }
190304          ],
190305          "cpe": "cpe:2.3:a:google-libphonenumber:google-libphonenumber:3.2.17:*:*:*:*:*:*:*",
190306          "purl": "pkg:npm/google-libphonenumber@3.2.17",
190307          "swid": {
190308            "attachment": {}
190309          },
190310          "pedigree": {},
190311          "externalReferences": [
190312            {
190313              "url": "git+https://github.com/ruimarinho/google-libphonenumber.git",
190314              "type": "distribution"
190315            },
190316            {
190317              "url": "https://ruimarinho.github.io/google-libphonenumber/",
190318              "type": "website"
190319            }
190320          ],
190321          "evidence": {},
190322          "signature": {
190323            "signature": {
190324              "publicKey": {}
190325            }
190326          },
190327          "modelCard": {
190328            "modelParameters": {
190329              "approach": {}
190330            },
190331            "quantitativeAnalysis": {
190332              "graphics": {}
190333            },
190334            "considerations": {}
190335          }
190336        },
190337        {
190338          "type": "library",
190339          "bom-ref": "pkg:npm/got@6.7.1?package-id=ab6c4d5a78007334",
190340          "supplier": {},
190341          "name": "got",
190342          "version": "6.7.1",
190343          "description": "Simplified HTTP requests",
190344          "licenses": [
190345            {
190346              "license": {
190347                "id": "MIT"
190348              }
190349            }
190350          ],
190351          "cpe": "cpe:2.3:a:sindresorhus:got:6.7.1:*:*:*:*:*:*:*",
190352          "purl": "pkg:npm/got@6.7.1",
190353          "swid": {
190354            "attachment": {}
190355          },
190356          "pedigree": {},
190357          "externalReferences": [
190358            {
190359              "url": "git+https://github.com/sindresorhus/got.git",
190360              "type": "distribution"
190361            },
190362            {
190363              "url": "https://github.com/sindresorhus/got#readme",
190364              "type": "website"
190365            }
190366          ],
190367          "evidence": {},
190368          "signature": {
190369            "signature": {
190370              "publicKey": {}
190371            }
190372          },
190373          "modelCard": {
190374            "modelParameters": {
190375              "approach": {}
190376            },
190377            "quantitativeAnalysis": {
190378              "graphics": {}
190379            },
190380            "considerations": {}
190381          }
190382        },
190383        {
190384          "type": "library",
190385          "bom-ref": "pkg:npm/graceful-fs@4.2.4?package-id=ae13bb0be4da9294",
190386          "supplier": {},
190387          "name": "graceful-fs",
190388          "version": "4.2.4",
190389          "description": "A drop-in replacement for fs, making various improvements.",
190390          "licenses": [
190391            {
190392              "license": {
190393                "id": "ISC"
190394              }
190395            }
190396          ],
190397          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.4:*:*:*:*:*:*:*",
190398          "purl": "pkg:npm/graceful-fs@4.2.4",
190399          "swid": {
190400            "attachment": {}
190401          },
190402          "pedigree": {},
190403          "externalReferences": [
190404            {
190405              "url": "git+https://github.com/isaacs/node-graceful-fs.git",
190406              "type": "distribution"
190407            },
190408            {
190409              "url": "https://github.com/isaacs/node-graceful-fs#readme",
190410              "type": "website"
190411            }
190412          ],
190413          "evidence": {},
190414          "signature": {
190415            "signature": {
190416              "publicKey": {}
190417            }
190418          },
190419          "modelCard": {
190420            "modelParameters": {
190421              "approach": {}
190422            },
190423            "quantitativeAnalysis": {
190424              "graphics": {}
190425            },
190426            "considerations": {}
190427          }
190428        },
190429        {
190430          "type": "library",
190431          "bom-ref": "pkg:npm/har-schema@2.0.0?package-id=df1ab60f5188f58f",
190432          "supplier": {},
190433          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
190434          "name": "har-schema",
190435          "version": "2.0.0",
190436          "description": "JSON Schema for HTTP Archive (HAR)",
190437          "licenses": [
190438            {
190439              "license": {
190440                "id": "ISC"
190441              }
190442            }
190443          ],
190444          "cpe": "cpe:2.3:a:ahmadnassri:har-schema:2.0.0:*:*:*:*:*:*:*",
190445          "purl": "pkg:npm/har-schema@2.0.0",
190446          "swid": {
190447            "attachment": {}
190448          },
190449          "pedigree": {},
190450          "externalReferences": [
190451            {
190452              "url": "git+https://github.com/ahmadnassri/har-schema.git",
190453              "type": "distribution"
190454            },
190455            {
190456              "url": "https://github.com/ahmadnassri/har-schema",
190457              "type": "website"
190458            }
190459          ],
190460          "evidence": {},
190461          "signature": {
190462            "signature": {
190463              "publicKey": {}
190464            }
190465          },
190466          "modelCard": {
190467            "modelParameters": {
190468              "approach": {}
190469            },
190470            "quantitativeAnalysis": {
190471              "graphics": {}
190472            },
190473            "considerations": {}
190474          }
190475        },
190476        {
190477          "type": "library",
190478          "bom-ref": "pkg:npm/har-validator@5.1.5?package-id=9cf5dbba4ee808aa",
190479          "supplier": {},
190480          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
190481          "name": "har-validator",
190482          "version": "5.1.5",
190483          "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
190484          "licenses": [
190485            {
190486              "license": {
190487                "id": "MIT"
190488              }
190489            }
190490          ],
190491          "cpe": "cpe:2.3:a:har-validator:har-validator:5.1.5:*:*:*:*:*:*:*",
190492          "purl": "pkg:npm/har-validator@5.1.5",
190493          "swid": {
190494            "attachment": {}
190495          },
190496          "pedigree": {},
190497          "externalReferences": [
190498            {
190499              "url": "git+https://github.com/ahmadnassri/node-har-validator.git",
190500              "type": "distribution"
190501            },
190502            {
190503              "url": "https://github.com/ahmadnassri/node-har-validator",
190504              "type": "website"
190505            }
190506          ],
190507          "evidence": {},
190508          "signature": {
190509            "signature": {
190510              "publicKey": {}
190511            }
190512          },
190513          "modelCard": {
190514            "modelParameters": {
190515              "approach": {}
190516            },
190517            "quantitativeAnalysis": {
190518              "graphics": {}
190519            },
190520            "considerations": {}
190521          }
190522        },
190523        {
190524          "type": "library",
190525          "bom-ref": "pkg:npm/has@1.0.3?package-id=57072cf8ae347274",
190526          "supplier": {},
190527          "author": "Thiago de Arruda \u003ctpadilha84@gmail.com\u003e",
190528          "name": "has",
190529          "version": "1.0.3",
190530          "description": "Object.prototype.hasOwnProperty.call shortcut",
190531          "licenses": [
190532            {
190533              "license": {
190534                "id": "MIT"
190535              }
190536            }
190537          ],
190538          "cpe": "cpe:2.3:a:tarruda:has:1.0.3:*:*:*:*:*:*:*",
190539          "purl": "pkg:npm/has@1.0.3",
190540          "swid": {
190541            "attachment": {}
190542          },
190543          "pedigree": {},
190544          "externalReferences": [
190545            {
190546              "url": "git://github.com/tarruda/has.git",
190547              "type": "distribution"
190548            },
190549            {
190550              "url": "https://github.com/tarruda/has",
190551              "type": "website"
190552            }
190553          ],
190554          "evidence": {},
190555          "signature": {
190556            "signature": {
190557              "publicKey": {}
190558            }
190559          },
190560          "modelCard": {
190561            "modelParameters": {
190562              "approach": {}
190563            },
190564            "quantitativeAnalysis": {
190565              "graphics": {}
190566            },
190567            "considerations": {}
190568          }
190569        },
190570        {
190571          "type": "library",
190572          "bom-ref": "pkg:npm/has-flag@3.0.0?package-id=d1a82ebb7b8ff26c",
190573          "supplier": {},
190574          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
190575          "name": "has-flag",
190576          "version": "3.0.0",
190577          "description": "Check if argv has a specific flag",
190578          "licenses": [
190579            {
190580              "license": {
190581                "id": "MIT"
190582              }
190583            }
190584          ],
190585          "cpe": "cpe:2.3:a:sindresorhus:has-flag:3.0.0:*:*:*:*:*:*:*",
190586          "purl": "pkg:npm/has-flag@3.0.0",
190587          "swid": {
190588            "attachment": {}
190589          },
190590          "pedigree": {},
190591          "externalReferences": [
190592            {
190593              "url": "git+https://github.com/sindresorhus/has-flag.git",
190594              "type": "distribution"
190595            },
190596            {
190597              "url": "https://github.com/sindresorhus/has-flag#readme",
190598              "type": "website"
190599            }
190600          ],
190601          "evidence": {},
190602          "signature": {
190603            "signature": {
190604              "publicKey": {}
190605            }
190606          },
190607          "modelCard": {
190608            "modelParameters": {
190609              "approach": {}
190610            },
190611            "quantitativeAnalysis": {
190612              "graphics": {}
190613            },
190614            "considerations": {}
190615          }
190616        },
190617        {
190618          "type": "library",
190619          "bom-ref": "pkg:npm/has-flag@4.0.0?package-id=de3b59daaf6d7165",
190620          "supplier": {},
190621          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
190622          "name": "has-flag",
190623          "version": "4.0.0",
190624          "description": "Check if argv has a specific flag",
190625          "licenses": [
190626            {
190627              "license": {
190628                "id": "MIT"
190629              }
190630            }
190631          ],
190632          "cpe": "cpe:2.3:a:sindresorhus:has-flag:4.0.0:*:*:*:*:*:*:*",
190633          "purl": "pkg:npm/has-flag@4.0.0",
190634          "swid": {
190635            "attachment": {}
190636          },
190637          "pedigree": {},
190638          "externalReferences": [
190639            {
190640              "url": "git+https://github.com/sindresorhus/has-flag.git",
190641              "type": "distribution"
190642            },
190643            {
190644              "url": "https://github.com/sindresorhus/has-flag#readme",
190645              "type": "website"
190646            }
190647          ],
190648          "evidence": {},
190649          "signature": {
190650            "signature": {
190651              "publicKey": {}
190652            }
190653          },
190654          "modelCard": {
190655            "modelParameters": {
190656              "approach": {}
190657            },
190658            "quantitativeAnalysis": {
190659              "graphics": {}
190660            },
190661            "considerations": {}
190662          }
190663        },
190664        {
190665          "type": "library",
190666          "bom-ref": "pkg:npm/has-symbols@1.0.0?package-id=9bd065ba951794af",
190667          "supplier": {},
190668          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
190669          "name": "has-symbols",
190670          "version": "1.0.0",
190671          "description": "Determine if the JS environment has Symbol support. Supports spec, or shams.",
190672          "licenses": [
190673            {
190674              "license": {
190675                "id": "MIT"
190676              }
190677            }
190678          ],
190679          "cpe": "cpe:2.3:a:has-symbols:has-symbols:1.0.0:*:*:*:*:*:*:*",
190680          "purl": "pkg:npm/has-symbols@1.0.0",
190681          "swid": {
190682            "attachment": {}
190683          },
190684          "pedigree": {},
190685          "externalReferences": [
190686            {
190687              "url": "git://github.com/ljharb/has-symbols.git",
190688              "type": "distribution"
190689            }
190690          ],
190691          "evidence": {},
190692          "signature": {
190693            "signature": {
190694              "publicKey": {}
190695            }
190696          },
190697          "modelCard": {
190698            "modelParameters": {
190699              "approach": {}
190700            },
190701            "quantitativeAnalysis": {
190702              "graphics": {}
190703            },
190704            "considerations": {}
190705          }
190706        },
190707        {
190708          "type": "library",
190709          "bom-ref": "pkg:npm/has-unicode@2.0.1?package-id=c2a2690b355e1e80",
190710          "supplier": {},
190711          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
190712          "name": "has-unicode",
190713          "version": "2.0.1",
190714          "description": "Try to guess if your terminal supports unicode",
190715          "licenses": [
190716            {
190717              "license": {
190718                "id": "ISC"
190719              }
190720            }
190721          ],
190722          "cpe": "cpe:2.3:a:has-unicode:has-unicode:2.0.1:*:*:*:*:*:*:*",
190723          "purl": "pkg:npm/has-unicode@2.0.1",
190724          "swid": {
190725            "attachment": {}
190726          },
190727          "pedigree": {},
190728          "externalReferences": [
190729            {
190730              "url": "git+https://github.com/iarna/has-unicode.git",
190731              "type": "distribution"
190732            },
190733            {
190734              "url": "https://github.com/iarna/has-unicode",
190735              "type": "website"
190736            }
190737          ],
190738          "evidence": {},
190739          "signature": {
190740            "signature": {
190741              "publicKey": {}
190742            }
190743          },
190744          "modelCard": {
190745            "modelParameters": {
190746              "approach": {}
190747            },
190748            "quantitativeAnalysis": {
190749              "graphics": {}
190750            },
190751            "considerations": {}
190752          }
190753        },
190754        {
190755          "type": "library",
190756          "bom-ref": "pkg:npm/hosted-git-info@2.8.9?package-id=d8c63249d170a0bb",
190757          "supplier": {},
190758          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org)",
190759          "name": "hosted-git-info",
190760          "version": "2.8.9",
190761          "description": "Provides metadata and conversions from repository urls for Github, Bitbucket and Gitlab",
190762          "licenses": [
190763            {
190764              "license": {
190765                "id": "ISC"
190766              }
190767            }
190768          ],
190769          "cpe": "cpe:2.3:a:hosted-git-info:hosted-git-info:2.8.9:*:*:*:*:*:*:*",
190770          "purl": "pkg:npm/hosted-git-info@2.8.9",
190771          "swid": {
190772            "attachment": {}
190773          },
190774          "pedigree": {},
190775          "externalReferences": [
190776            {
190777              "url": "git+https://github.com/npm/hosted-git-info.git",
190778              "type": "distribution"
190779            },
190780            {
190781              "url": "https://github.com/npm/hosted-git-info",
190782              "type": "website"
190783            }
190784          ],
190785          "evidence": {},
190786          "signature": {
190787            "signature": {
190788              "publicKey": {}
190789            }
190790          },
190791          "modelCard": {
190792            "modelParameters": {
190793              "approach": {}
190794            },
190795            "quantitativeAnalysis": {
190796              "graphics": {}
190797            },
190798            "considerations": {}
190799          }
190800        },
190801        {
190802          "type": "library",
190803          "bom-ref": "pkg:npm/http-cache-semantics@3.8.1?package-id=be50af68f0bf4318",
190804          "supplier": {},
190805          "author": "Kornel Lesiński \u003ckornel@geekhood.net\u003e (https://kornel.ski/)",
190806          "name": "http-cache-semantics",
190807          "version": "3.8.1",
190808          "description": "Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies",
190809          "licenses": [
190810            {
190811              "license": {
190812                "id": "BSD-2-Clause"
190813              }
190814            }
190815          ],
190816          "cpe": "cpe:2.3:a:http-cache-semantics:http-cache-semantics:3.8.1:*:*:*:*:*:*:*",
190817          "purl": "pkg:npm/http-cache-semantics@3.8.1",
190818          "swid": {
190819            "attachment": {}
190820          },
190821          "pedigree": {},
190822          "externalReferences": [
190823            {
190824              "url": "git+https://github.com/pornel/http-cache-semantics.git",
190825              "type": "distribution"
190826            },
190827            {
190828              "url": "https://github.com/pornel/http-cache-semantics#readme",
190829              "type": "website"
190830            }
190831          ],
190832          "evidence": {},
190833          "signature": {
190834            "signature": {
190835              "publicKey": {}
190836            }
190837          },
190838          "modelCard": {
190839            "modelParameters": {
190840              "approach": {}
190841            },
190842            "quantitativeAnalysis": {
190843              "graphics": {}
190844            },
190845            "considerations": {}
190846          }
190847        },
190848        {
190849          "type": "library",
190850          "bom-ref": "pkg:npm/http-errors@1.7.2?package-id=caf9fdc642308a1c",
190851          "supplier": {},
190852          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
190853          "name": "http-errors",
190854          "version": "1.7.2",
190855          "description": "Create HTTP error objects",
190856          "licenses": [
190857            {
190858              "license": {
190859                "id": "MIT"
190860              }
190861            }
190862          ],
190863          "cpe": "cpe:2.3:a:http-errors:http-errors:1.7.2:*:*:*:*:*:*:*",
190864          "purl": "pkg:npm/http-errors@1.7.2",
190865          "swid": {
190866            "attachment": {}
190867          },
190868          "pedigree": {},
190869          "externalReferences": [
190870            {
190871              "url": "git+https://github.com/jshttp/http-errors.git",
190872              "type": "distribution"
190873            },
190874            {
190875              "url": "https://github.com/jshttp/http-errors#readme",
190876              "type": "website"
190877            }
190878          ],
190879          "evidence": {},
190880          "signature": {
190881            "signature": {
190882              "publicKey": {}
190883            }
190884          },
190885          "modelCard": {
190886            "modelParameters": {
190887              "approach": {}
190888            },
190889            "quantitativeAnalysis": {
190890              "graphics": {}
190891            },
190892            "considerations": {}
190893          }
190894        },
190895        {
190896          "type": "library",
190897          "bom-ref": "pkg:npm/http-proxy-agent@2.1.0?package-id=f58ccb0049d952d2",
190898          "supplier": {},
190899          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
190900          "name": "http-proxy-agent",
190901          "version": "2.1.0",
190902          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTP",
190903          "licenses": [
190904            {
190905              "license": {
190906                "id": "MIT"
190907              }
190908            }
190909          ],
190910          "cpe": "cpe:2.3:a:http-proxy-agent:http-proxy-agent:2.1.0:*:*:*:*:*:*:*",
190911          "purl": "pkg:npm/http-proxy-agent@2.1.0",
190912          "swid": {
190913            "attachment": {}
190914          },
190915          "pedigree": {},
190916          "externalReferences": [
190917            {
190918              "url": "git://github.com/TooTallNate/node-http-proxy-agent.git",
190919              "type": "distribution"
190920            },
190921            {
190922              "url": "https://github.com/TooTallNate/node-http-proxy-agent#readme",
190923              "type": "website"
190924            }
190925          ],
190926          "evidence": {},
190927          "signature": {
190928            "signature": {
190929              "publicKey": {}
190930            }
190931          },
190932          "modelCard": {
190933            "modelParameters": {
190934              "approach": {}
190935            },
190936            "quantitativeAnalysis": {
190937              "graphics": {}
190938            },
190939            "considerations": {}
190940          }
190941        },
190942        {
190943          "type": "library",
190944          "bom-ref": "pkg:npm/http-signature@1.2.0?package-id=ec4c21581261e6af",
190945          "supplier": {},
190946          "author": "Joyent, Inc",
190947          "name": "http-signature",
190948          "version": "1.2.0",
190949          "description": "Reference implementation of Joyent's HTTP Signature scheme.",
190950          "licenses": [
190951            {
190952              "license": {
190953                "id": "MIT"
190954              }
190955            }
190956          ],
190957          "cpe": "cpe:2.3:a:http-signature:http-signature:1.2.0:*:*:*:*:*:*:*",
190958          "purl": "pkg:npm/http-signature@1.2.0",
190959          "swid": {
190960            "attachment": {}
190961          },
190962          "pedigree": {},
190963          "externalReferences": [
190964            {
190965              "url": "git://github.com/joyent/node-http-signature.git",
190966              "type": "distribution"
190967            },
190968            {
190969              "url": "https://github.com/joyent/node-http-signature/",
190970              "type": "website"
190971            }
190972          ],
190973          "evidence": {},
190974          "signature": {
190975            "signature": {
190976              "publicKey": {}
190977            }
190978          },
190979          "modelCard": {
190980            "modelParameters": {
190981              "approach": {}
190982            },
190983            "quantitativeAnalysis": {
190984              "graphics": {}
190985            },
190986            "considerations": {}
190987          }
190988        },
190989        {
190990          "type": "library",
190991          "bom-ref": "pkg:npm/http-terminator@3.2.0?package-id=74c7a1b1f1eee594",
190992          "supplier": {},
190993          "author": "Gajus Kuizinas \u003cgajus@gajus.com\u003e (http://gajus.com)",
190994          "name": "http-terminator",
190995          "version": "3.2.0",
190996          "description": "Gracefully terminates HTTP(S) server.",
190997          "licenses": [
190998            {
190999              "license": {
191000                "id": "BSD-3-Clause"
191001              }
191002            }
191003          ],
191004          "cpe": "cpe:2.3:a:http-terminator:http-terminator:3.2.0:*:*:*:*:*:*:*",
191005          "purl": "pkg:npm/http-terminator@3.2.0",
191006          "swid": {
191007            "attachment": {}
191008          },
191009          "pedigree": {},
191010          "externalReferences": [
191011            {
191012              "url": "git+https://github.com/gajus/http-terminator.git",
191013              "type": "distribution"
191014            },
191015            {
191016              "url": "https://github.com/gajus/http-terminator#readme",
191017              "type": "website"
191018            }
191019          ],
191020          "evidence": {},
191021          "signature": {
191022            "signature": {
191023              "publicKey": {}
191024            }
191025          },
191026          "modelCard": {
191027            "modelParameters": {
191028              "approach": {}
191029            },
191030            "quantitativeAnalysis": {
191031              "graphics": {}
191032            },
191033            "considerations": {}
191034          }
191035        },
191036        {
191037          "type": "library",
191038          "bom-ref": "pkg:npm/https-proxy-agent@2.2.4?package-id=3865d5b676fac485",
191039          "supplier": {},
191040          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
191041          "name": "https-proxy-agent",
191042          "version": "2.2.4",
191043          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
191044          "licenses": [
191045            {
191046              "license": {
191047                "id": "MIT"
191048              }
191049            }
191050          ],
191051          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:2.2.4:*:*:*:*:*:*:*",
191052          "purl": "pkg:npm/https-proxy-agent@2.2.4",
191053          "swid": {
191054            "attachment": {}
191055          },
191056          "pedigree": {},
191057          "externalReferences": [
191058            {
191059              "url": "git://github.com/TooTallNate/node-https-proxy-agent.git",
191060              "type": "distribution"
191061            },
191062            {
191063              "url": "https://github.com/TooTallNate/node-https-proxy-agent#readme",
191064              "type": "website"
191065            }
191066          ],
191067          "evidence": {},
191068          "signature": {
191069            "signature": {
191070              "publicKey": {}
191071            }
191072          },
191073          "modelCard": {
191074            "modelParameters": {
191075              "approach": {}
191076            },
191077            "quantitativeAnalysis": {
191078              "graphics": {}
191079            },
191080            "considerations": {}
191081          }
191082        },
191083        {
191084          "type": "library",
191085          "bom-ref": "pkg:npm/https-proxy-agent@5.0.1?package-id=27162acbce375aff",
191086          "supplier": {},
191087          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
191088          "name": "https-proxy-agent",
191089          "version": "5.0.1",
191090          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
191091          "licenses": [
191092            {
191093              "license": {
191094                "id": "MIT"
191095              }
191096            }
191097          ],
191098          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:5.0.1:*:*:*:*:*:*:*",
191099          "purl": "pkg:npm/https-proxy-agent@5.0.1",
191100          "swid": {
191101            "attachment": {}
191102          },
191103          "pedigree": {},
191104          "externalReferences": [
191105            {
191106              "url": "git://github.com/TooTallNate/node-https-proxy-agent.git",
191107              "type": "distribution"
191108            },
191109            {
191110              "url": "https://github.com/TooTallNate/node-https-proxy-agent#readme",
191111              "type": "website"
191112            }
191113          ],
191114          "evidence": {},
191115          "signature": {
191116            "signature": {
191117              "publicKey": {}
191118            }
191119          },
191120          "modelCard": {
191121            "modelParameters": {
191122              "approach": {}
191123            },
191124            "quantitativeAnalysis": {
191125              "graphics": {}
191126            },
191127            "considerations": {}
191128          }
191129        },
191130        {
191131          "type": "library",
191132          "bom-ref": "pkg:npm/humanize-ms@1.2.1?package-id=6269f846c887d763",
191133          "supplier": {},
191134          "author": "dead-horse \u003cdead_horse@qq.com\u003e (http://deadhorse.me)",
191135          "name": "humanize-ms",
191136          "version": "1.2.1",
191137          "description": "transform humanize time to ms",
191138          "licenses": [
191139            {
191140              "license": {
191141                "id": "MIT"
191142              }
191143            }
191144          ],
191145          "cpe": "cpe:2.3:a:node-modules:humanize-ms:1.2.1:*:*:*:*:*:*:*",
191146          "purl": "pkg:npm/humanize-ms@1.2.1",
191147          "swid": {
191148            "attachment": {}
191149          },
191150          "pedigree": {},
191151          "externalReferences": [
191152            {
191153              "url": "git+https://github.com/node-modules/humanize-ms.git",
191154              "type": "distribution"
191155            },
191156            {
191157              "url": "https://github.com/node-modules/humanize-ms#readme",
191158              "type": "website"
191159            }
191160          ],
191161          "evidence": {},
191162          "signature": {
191163            "signature": {
191164              "publicKey": {}
191165            }
191166          },
191167          "modelCard": {
191168            "modelParameters": {
191169              "approach": {}
191170            },
191171            "quantitativeAnalysis": {
191172              "graphics": {}
191173            },
191174            "considerations": {}
191175          }
191176        },
191177        {
191178          "type": "library",
191179          "bom-ref": "pkg:npm/iconv-lite@0.4.23?package-id=72aa978f928b8369",
191180          "supplier": {},
191181          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
191182          "name": "iconv-lite",
191183          "version": "0.4.23",
191184          "description": "Convert character encodings in pure javascript.",
191185          "licenses": [
191186            {
191187              "license": {
191188                "id": "MIT"
191189              }
191190            }
191191          ],
191192          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.4.23:*:*:*:*:*:*:*",
191193          "purl": "pkg:npm/iconv-lite@0.4.23",
191194          "swid": {
191195            "attachment": {}
191196          },
191197          "pedigree": {},
191198          "externalReferences": [
191199            {
191200              "url": "git://github.com/ashtuchkin/iconv-lite.git",
191201              "type": "distribution"
191202            },
191203            {
191204              "url": "https://github.com/ashtuchkin/iconv-lite",
191205              "type": "website"
191206            }
191207          ],
191208          "evidence": {},
191209          "signature": {
191210            "signature": {
191211              "publicKey": {}
191212            }
191213          },
191214          "modelCard": {
191215            "modelParameters": {
191216              "approach": {}
191217            },
191218            "quantitativeAnalysis": {
191219              "graphics": {}
191220            },
191221            "considerations": {}
191222          }
191223        },
191224        {
191225          "type": "library",
191226          "bom-ref": "pkg:npm/iconv-lite@0.4.24?package-id=5b9a586d4ff6589f",
191227          "supplier": {},
191228          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
191229          "name": "iconv-lite",
191230          "version": "0.4.24",
191231          "description": "Convert character encodings in pure javascript.",
191232          "licenses": [
191233            {
191234              "license": {
191235                "id": "MIT"
191236              }
191237            }
191238          ],
191239          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.4.24:*:*:*:*:*:*:*",
191240          "purl": "pkg:npm/iconv-lite@0.4.24",
191241          "swid": {
191242            "attachment": {}
191243          },
191244          "pedigree": {},
191245          "externalReferences": [
191246            {
191247              "url": "git://github.com/ashtuchkin/iconv-lite.git",
191248              "type": "distribution"
191249            },
191250            {
191251              "url": "https://github.com/ashtuchkin/iconv-lite",
191252              "type": "website"
191253            }
191254          ],
191255          "evidence": {},
191256          "signature": {
191257            "signature": {
191258              "publicKey": {}
191259            }
191260          },
191261          "modelCard": {
191262            "modelParameters": {
191263              "approach": {}
191264            },
191265            "quantitativeAnalysis": {
191266              "graphics": {}
191267            },
191268            "considerations": {}
191269          }
191270        },
191271        {
191272          "type": "library",
191273          "bom-ref": "pkg:npm/iferr@0.1.5?package-id=240c8b7b718f7cca",
191274          "supplier": {},
191275          "author": "Nadav Ivgi",
191276          "name": "iferr",
191277          "version": "0.1.5",
191278          "description": "Higher-order functions for easier error handling",
191279          "licenses": [
191280            {
191281              "license": {
191282                "id": "MIT"
191283              }
191284            }
191285          ],
191286          "cpe": "cpe:2.3:a:shesek:iferr:0.1.5:*:*:*:*:*:*:*",
191287          "purl": "pkg:npm/iferr@0.1.5",
191288          "swid": {
191289            "attachment": {}
191290          },
191291          "pedigree": {},
191292          "externalReferences": [
191293            {
191294              "url": "git+https://github.com/shesek/iferr.git",
191295              "type": "distribution"
191296            },
191297            {
191298              "url": "https://github.com/shesek/iferr",
191299              "type": "website"
191300            }
191301          ],
191302          "evidence": {},
191303          "signature": {
191304            "signature": {
191305              "publicKey": {}
191306            }
191307          },
191308          "modelCard": {
191309            "modelParameters": {
191310              "approach": {}
191311            },
191312            "quantitativeAnalysis": {
191313              "graphics": {}
191314            },
191315            "considerations": {}
191316          }
191317        },
191318        {
191319          "type": "library",
191320          "bom-ref": "pkg:npm/iferr@0.1.5?package-id=78ea6eb1d1172c78",
191321          "supplier": {},
191322          "author": "Nadav Ivgi",
191323          "name": "iferr",
191324          "version": "0.1.5",
191325          "description": "Higher-order functions for easier error handling",
191326          "licenses": [
191327            {
191328              "license": {
191329                "id": "MIT"
191330              }
191331            }
191332          ],
191333          "cpe": "cpe:2.3:a:shesek:iferr:0.1.5:*:*:*:*:*:*:*",
191334          "purl": "pkg:npm/iferr@0.1.5",
191335          "swid": {
191336            "attachment": {}
191337          },
191338          "pedigree": {},
191339          "externalReferences": [
191340            {
191341              "url": "git+https://github.com/shesek/iferr.git",
191342              "type": "distribution"
191343            },
191344            {
191345              "url": "https://github.com/shesek/iferr",
191346              "type": "website"
191347            }
191348          ],
191349          "evidence": {},
191350          "signature": {
191351            "signature": {
191352              "publicKey": {}
191353            }
191354          },
191355          "modelCard": {
191356            "modelParameters": {
191357              "approach": {}
191358            },
191359            "quantitativeAnalysis": {
191360              "graphics": {}
191361            },
191362            "considerations": {}
191363          }
191364        },
191365        {
191366          "type": "library",
191367          "bom-ref": "pkg:npm/iferr@0.1.5?package-id=394fba8c06946b1c",
191368          "supplier": {},
191369          "author": "Nadav Ivgi",
191370          "name": "iferr",
191371          "version": "0.1.5",
191372          "description": "Higher-order functions for easier error handling",
191373          "licenses": [
191374            {
191375              "license": {
191376                "id": "MIT"
191377              }
191378            }
191379          ],
191380          "cpe": "cpe:2.3:a:shesek:iferr:0.1.5:*:*:*:*:*:*:*",
191381          "purl": "pkg:npm/iferr@0.1.5",
191382          "swid": {
191383            "attachment": {}
191384          },
191385          "pedigree": {},
191386          "externalReferences": [
191387            {
191388              "url": "git+https://github.com/shesek/iferr.git",
191389              "type": "distribution"
191390            },
191391            {
191392              "url": "https://github.com/shesek/iferr",
191393              "type": "website"
191394            }
191395          ],
191396          "evidence": {},
191397          "signature": {
191398            "signature": {
191399              "publicKey": {}
191400            }
191401          },
191402          "modelCard": {
191403            "modelParameters": {
191404              "approach": {}
191405            },
191406            "quantitativeAnalysis": {
191407              "graphics": {}
191408            },
191409            "considerations": {}
191410          }
191411        },
191412        {
191413          "type": "library",
191414          "bom-ref": "pkg:npm/iferr@1.0.2?package-id=23983836ee47095c",
191415          "supplier": {},
191416          "author": "Nadav Ivgi",
191417          "name": "iferr",
191418          "version": "1.0.2",
191419          "description": "Higher-order functions for easier error handling",
191420          "licenses": [
191421            {
191422              "license": {
191423                "id": "MIT"
191424              }
191425            }
191426          ],
191427          "cpe": "cpe:2.3:a:shesek:iferr:1.0.2:*:*:*:*:*:*:*",
191428          "purl": "pkg:npm/iferr@1.0.2",
191429          "swid": {
191430            "attachment": {}
191431          },
191432          "pedigree": {},
191433          "externalReferences": [
191434            {
191435              "url": "git+https://github.com/shesek/iferr.git",
191436              "type": "distribution"
191437            },
191438            {
191439              "url": "https://github.com/shesek/iferr",
191440              "type": "website"
191441            }
191442          ],
191443          "evidence": {},
191444          "signature": {
191445            "signature": {
191446              "publicKey": {}
191447            }
191448          },
191449          "modelCard": {
191450            "modelParameters": {
191451              "approach": {}
191452            },
191453            "quantitativeAnalysis": {
191454              "graphics": {}
191455            },
191456            "considerations": {}
191457          }
191458        },
191459        {
191460          "type": "library",
191461          "bom-ref": "pkg:npm/ignore-walk@3.0.3?package-id=4b3b7cbce830d44b",
191462          "supplier": {},
191463          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
191464          "name": "ignore-walk",
191465          "version": "3.0.3",
191466          "description": "Nested/recursive `.gitignore`/`.npmignore` parsing and filtering.",
191467          "licenses": [
191468            {
191469              "license": {
191470                "id": "ISC"
191471              }
191472            }
191473          ],
191474          "cpe": "cpe:2.3:a:ignore-walk:ignore-walk:3.0.3:*:*:*:*:*:*:*",
191475          "purl": "pkg:npm/ignore-walk@3.0.3",
191476          "swid": {
191477            "attachment": {}
191478          },
191479          "pedigree": {},
191480          "externalReferences": [
191481            {
191482              "url": "git+https://github.com/isaacs/ignore-walk.git",
191483              "type": "distribution"
191484            },
191485            {
191486              "url": "https://github.com/isaacs/ignore-walk#readme",
191487              "type": "website"
191488            }
191489          ],
191490          "evidence": {},
191491          "signature": {
191492            "signature": {
191493              "publicKey": {}
191494            }
191495          },
191496          "modelCard": {
191497            "modelParameters": {
191498              "approach": {}
191499            },
191500            "quantitativeAnalysis": {
191501              "graphics": {}
191502            },
191503            "considerations": {}
191504          }
191505        },
191506        {
191507          "type": "library",
191508          "bom-ref": "pkg:npm/import-lazy@2.1.0?package-id=af14ea31551b29b",
191509          "supplier": {},
191510          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
191511          "name": "import-lazy",
191512          "version": "2.1.0",
191513          "description": "Import modules lazily",
191514          "licenses": [
191515            {
191516              "license": {
191517                "id": "MIT"
191518              }
191519            }
191520          ],
191521          "cpe": "cpe:2.3:a:sindresorhus:import-lazy:2.1.0:*:*:*:*:*:*:*",
191522          "purl": "pkg:npm/import-lazy@2.1.0",
191523          "swid": {
191524            "attachment": {}
191525          },
191526          "pedigree": {},
191527          "externalReferences": [
191528            {
191529              "url": "git+https://github.com/sindresorhus/import-lazy.git",
191530              "type": "distribution"
191531            },
191532            {
191533              "url": "https://github.com/sindresorhus/import-lazy#readme",
191534              "type": "website"
191535            }
191536          ],
191537          "evidence": {},
191538          "signature": {
191539            "signature": {
191540              "publicKey": {}
191541            }
191542          },
191543          "modelCard": {
191544            "modelParameters": {
191545              "approach": {}
191546            },
191547            "quantitativeAnalysis": {
191548              "graphics": {}
191549            },
191550            "considerations": {}
191551          }
191552        },
191553        {
191554          "type": "library",
191555          "bom-ref": "pkg:npm/imurmurhash@0.1.4?package-id=209f0ed2459f2a66",
191556          "supplier": {},
191557          "author": "Jens Taylor \u003cjensyt@gmail.com\u003e (https://github.com/homebrewing)",
191558          "name": "imurmurhash",
191559          "version": "0.1.4",
191560          "description": "An incremental implementation of MurmurHash3",
191561          "licenses": [
191562            {
191563              "license": {
191564                "id": "MIT"
191565              }
191566            }
191567          ],
191568          "cpe": "cpe:2.3:a:imurmurhash:imurmurhash:0.1.4:*:*:*:*:*:*:*",
191569          "purl": "pkg:npm/imurmurhash@0.1.4",
191570          "swid": {
191571            "attachment": {}
191572          },
191573          "pedigree": {},
191574          "externalReferences": [
191575            {
191576              "url": "git+https://github.com/jensyt/imurmurhash-js.git",
191577              "type": "distribution"
191578            },
191579            {
191580              "url": "https://github.com/jensyt/imurmurhash-js",
191581              "type": "website"
191582            }
191583          ],
191584          "evidence": {},
191585          "signature": {
191586            "signature": {
191587              "publicKey": {}
191588            }
191589          },
191590          "modelCard": {
191591            "modelParameters": {
191592              "approach": {}
191593            },
191594            "quantitativeAnalysis": {
191595              "graphics": {}
191596            },
191597            "considerations": {}
191598          }
191599        },
191600        {
191601          "type": "library",
191602          "bom-ref": "pkg:npm/infer-owner@1.0.4?package-id=ff8bebe3c92e29be",
191603          "supplier": {},
191604          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
191605          "name": "infer-owner",
191606          "version": "1.0.4",
191607          "description": "Infer the owner of a path based on the owner of its nearest existing parent",
191608          "licenses": [
191609            {
191610              "license": {
191611                "id": "ISC"
191612              }
191613            }
191614          ],
191615          "cpe": "cpe:2.3:a:infer-owner:infer-owner:1.0.4:*:*:*:*:*:*:*",
191616          "purl": "pkg:npm/infer-owner@1.0.4",
191617          "swid": {
191618            "attachment": {}
191619          },
191620          "pedigree": {},
191621          "externalReferences": [
191622            {
191623              "url": "git+https://github.com/npm/infer-owner.git",
191624              "type": "distribution"
191625            },
191626            {
191627              "url": "https://github.com/npm/infer-owner#readme",
191628              "type": "website"
191629            }
191630          ],
191631          "evidence": {},
191632          "signature": {
191633            "signature": {
191634              "publicKey": {}
191635            }
191636          },
191637          "modelCard": {
191638            "modelParameters": {
191639              "approach": {}
191640            },
191641            "quantitativeAnalysis": {
191642              "graphics": {}
191643            },
191644            "considerations": {}
191645          }
191646        },
191647        {
191648          "type": "library",
191649          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=7f4a1389d99344e1",
191650          "supplier": {},
191651          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
191652          "name": "inflight",
191653          "version": "1.0.6",
191654          "description": "Add callbacks to requests in flight to avoid async duplication",
191655          "licenses": [
191656            {
191657              "license": {
191658                "id": "ISC"
191659              }
191660            }
191661          ],
191662          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
191663          "purl": "pkg:npm/inflight@1.0.6",
191664          "swid": {
191665            "attachment": {}
191666          },
191667          "pedigree": {},
191668          "externalReferences": [
191669            {
191670              "url": "git+https://github.com/npm/inflight.git",
191671              "type": "distribution"
191672            },
191673            {
191674              "url": "https://github.com/isaacs/inflight",
191675              "type": "website"
191676            }
191677          ],
191678          "evidence": {},
191679          "signature": {
191680            "signature": {
191681              "publicKey": {}
191682            }
191683          },
191684          "modelCard": {
191685            "modelParameters": {
191686              "approach": {}
191687            },
191688            "quantitativeAnalysis": {
191689              "graphics": {}
191690            },
191691            "considerations": {}
191692          }
191693        },
191694        {
191695          "type": "library",
191696          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=699ceddffcda4478",
191697          "supplier": {},
191698          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
191699          "name": "inflight",
191700          "version": "1.0.6",
191701          "description": "Add callbacks to requests in flight to avoid async duplication",
191702          "licenses": [
191703            {
191704              "license": {
191705                "id": "ISC"
191706              }
191707            }
191708          ],
191709          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
191710          "purl": "pkg:npm/inflight@1.0.6",
191711          "swid": {
191712            "attachment": {}
191713          },
191714          "pedigree": {},
191715          "externalReferences": [
191716            {
191717              "url": "git+https://github.com/npm/inflight.git",
191718              "type": "distribution"
191719            },
191720            {
191721              "url": "https://github.com/isaacs/inflight",
191722              "type": "website"
191723            }
191724          ],
191725          "evidence": {},
191726          "signature": {
191727            "signature": {
191728              "publicKey": {}
191729            }
191730          },
191731          "modelCard": {
191732            "modelParameters": {
191733              "approach": {}
191734            },
191735            "quantitativeAnalysis": {
191736              "graphics": {}
191737            },
191738            "considerations": {}
191739          }
191740        },
191741        {
191742          "type": "library",
191743          "bom-ref": "pkg:npm/inherits@2.0.3?package-id=9e94bf16095bed86",
191744          "supplier": {},
191745          "name": "inherits",
191746          "version": "2.0.3",
191747          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
191748          "licenses": [
191749            {
191750              "license": {
191751                "id": "ISC"
191752              }
191753            }
191754          ],
191755          "cpe": "cpe:2.3:a:inherits:inherits:2.0.3:*:*:*:*:*:*:*",
191756          "purl": "pkg:npm/inherits@2.0.3",
191757          "swid": {
191758            "attachment": {}
191759          },
191760          "pedigree": {},
191761          "externalReferences": [
191762            {
191763              "url": "git://github.com/isaacs/inherits.git",
191764              "type": "distribution"
191765            },
191766            {
191767              "url": "https://github.com/isaacs/inherits#readme",
191768              "type": "website"
191769            }
191770          ],
191771          "evidence": {},
191772          "signature": {
191773            "signature": {
191774              "publicKey": {}
191775            }
191776          },
191777          "modelCard": {
191778            "modelParameters": {
191779              "approach": {}
191780            },
191781            "quantitativeAnalysis": {
191782              "graphics": {}
191783            },
191784            "considerations": {}
191785          }
191786        },
191787        {
191788          "type": "library",
191789          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=c75e2d1e61a335c0",
191790          "supplier": {},
191791          "name": "inherits",
191792          "version": "2.0.4",
191793          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
191794          "licenses": [
191795            {
191796              "license": {
191797                "id": "ISC"
191798              }
191799            }
191800          ],
191801          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
191802          "purl": "pkg:npm/inherits@2.0.4",
191803          "swid": {
191804            "attachment": {}
191805          },
191806          "pedigree": {},
191807          "externalReferences": [
191808            {
191809              "url": "git://github.com/isaacs/inherits.git",
191810              "type": "distribution"
191811            },
191812            {
191813              "url": "https://github.com/isaacs/inherits#readme",
191814              "type": "website"
191815            }
191816          ],
191817          "evidence": {},
191818          "signature": {
191819            "signature": {
191820              "publicKey": {}
191821            }
191822          },
191823          "modelCard": {
191824            "modelParameters": {
191825              "approach": {}
191826            },
191827            "quantitativeAnalysis": {
191828              "graphics": {}
191829            },
191830            "considerations": {}
191831          }
191832        },
191833        {
191834          "type": "library",
191835          "bom-ref": "pkg:npm/ini@1.3.8?package-id=1144947c22b83407",
191836          "supplier": {},
191837          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
191838          "name": "ini",
191839          "version": "1.3.8",
191840          "description": "An ini encoder/decoder for node",
191841          "licenses": [
191842            {
191843              "license": {
191844                "id": "ISC"
191845              }
191846            }
191847          ],
191848          "cpe": "cpe:2.3:a:isaacs:ini:1.3.8:*:*:*:*:*:*:*",
191849          "purl": "pkg:npm/ini@1.3.8",
191850          "swid": {
191851            "attachment": {}
191852          },
191853          "pedigree": {},
191854          "externalReferences": [
191855            {
191856              "url": "git://github.com/isaacs/ini.git",
191857              "type": "distribution"
191858            },
191859            {
191860              "url": "https://github.com/isaacs/ini#readme",
191861              "type": "website"
191862            }
191863          ],
191864          "evidence": {},
191865          "signature": {
191866            "signature": {
191867              "publicKey": {}
191868            }
191869          },
191870          "modelCard": {
191871            "modelParameters": {
191872              "approach": {}
191873            },
191874            "quantitativeAnalysis": {
191875              "graphics": {}
191876            },
191877            "considerations": {}
191878          }
191879        },
191880        {
191881          "type": "library",
191882          "bom-ref": "pkg:npm/init-package-json@1.10.3?package-id=612217504bf238b9",
191883          "supplier": {},
191884          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
191885          "name": "init-package-json",
191886          "version": "1.10.3",
191887          "description": "A node module to get your node module started",
191888          "licenses": [
191889            {
191890              "license": {
191891                "id": "ISC"
191892              }
191893            }
191894          ],
191895          "cpe": "cpe:2.3:a:init-package-json:init-package-json:1.10.3:*:*:*:*:*:*:*",
191896          "purl": "pkg:npm/init-package-json@1.10.3",
191897          "swid": {
191898            "attachment": {}
191899          },
191900          "pedigree": {},
191901          "externalReferences": [
191902            {
191903              "url": "git+https://github.com/npm/init-package-json.git",
191904              "type": "distribution"
191905            },
191906            {
191907              "url": "https://github.com/npm/init-package-json#readme",
191908              "type": "website"
191909            }
191910          ],
191911          "evidence": {},
191912          "signature": {
191913            "signature": {
191914              "publicKey": {}
191915            }
191916          },
191917          "modelCard": {
191918            "modelParameters": {
191919              "approach": {}
191920            },
191921            "quantitativeAnalysis": {
191922              "graphics": {}
191923            },
191924            "considerations": {}
191925          }
191926        },
191927        {
191928          "type": "library",
191929          "bom-ref": "pkg:npm/ip@1.1.5?package-id=40b78732d677da70",
191930          "supplier": {},
191931          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
191932          "name": "ip",
191933          "version": "1.1.5",
191934          "description": "[![](https://badge.fury.io/js/ip.svg)](https://www.npmjs.com/package/ip)",
191935          "licenses": [
191936            {
191937              "license": {
191938                "id": "MIT"
191939              }
191940            }
191941          ],
191942          "cpe": "cpe:2.3:a:indutny:ip:1.1.5:*:*:*:*:*:*:*",
191943          "purl": "pkg:npm/ip@1.1.5",
191944          "swid": {
191945            "attachment": {}
191946          },
191947          "pedigree": {},
191948          "externalReferences": [
191949            {
191950              "url": "git+ssh://git@github.com/indutny/node-ip.git",
191951              "type": "distribution"
191952            },
191953            {
191954              "url": "https://github.com/indutny/node-ip",
191955              "type": "website"
191956            }
191957          ],
191958          "evidence": {},
191959          "signature": {
191960            "signature": {
191961              "publicKey": {}
191962            }
191963          },
191964          "modelCard": {
191965            "modelParameters": {
191966              "approach": {}
191967            },
191968            "quantitativeAnalysis": {
191969              "graphics": {}
191970            },
191971            "considerations": {}
191972          }
191973        },
191974        {
191975          "type": "library",
191976          "bom-ref": "pkg:npm/ip-regex@2.1.0?package-id=7de70bcecf1718ee",
191977          "supplier": {},
191978          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
191979          "name": "ip-regex",
191980          "version": "2.1.0",
191981          "description": "Regular expression for matching IP addresses (IPv4 \u0026 IPv6)",
191982          "licenses": [
191983            {
191984              "license": {
191985                "id": "MIT"
191986              }
191987            }
191988          ],
191989          "cpe": "cpe:2.3:a:sindresorhus:ip-regex:2.1.0:*:*:*:*:*:*:*",
191990          "purl": "pkg:npm/ip-regex@2.1.0",
191991          "swid": {
191992            "attachment": {}
191993          },
191994          "pedigree": {},
191995          "externalReferences": [
191996            {
191997              "url": "git+https://github.com/sindresorhus/ip-regex.git",
191998              "type": "distribution"
191999            },
192000            {
192001              "url": "https://github.com/sindresorhus/ip-regex#readme",
192002              "type": "website"
192003            }
192004          ],
192005          "evidence": {},
192006          "signature": {
192007            "signature": {
192008              "publicKey": {}
192009            }
192010          },
192011          "modelCard": {
192012            "modelParameters": {
192013              "approach": {}
192014            },
192015            "quantitativeAnalysis": {
192016              "graphics": {}
192017            },
192018            "considerations": {}
192019          }
192020        },
192021        {
192022          "type": "library",
192023          "bom-ref": "pkg:npm/ipaddr.js@1.9.1?package-id=79e3881762ad8396",
192024          "supplier": {},
192025          "author": "whitequark \u003cwhitequark@whitequark.org\u003e",
192026          "name": "ipaddr.js",
192027          "version": "1.9.1",
192028          "description": "A library for manipulating IPv4 and IPv6 addresses in JavaScript.",
192029          "licenses": [
192030            {
192031              "license": {
192032                "id": "MIT"
192033              }
192034            }
192035          ],
192036          "cpe": "cpe:2.3:a:whitequark:ipaddr.js:1.9.1:*:*:*:*:*:*:*",
192037          "purl": "pkg:npm/ipaddr.js@1.9.1",
192038          "swid": {
192039            "attachment": {}
192040          },
192041          "pedigree": {},
192042          "externalReferences": [
192043            {
192044              "url": "git://github.com/whitequark/ipaddr.js.git",
192045              "type": "distribution"
192046            },
192047            {
192048              "url": "https://github.com/whitequark/ipaddr.js#readme",
192049              "type": "website"
192050            }
192051          ],
192052          "evidence": {},
192053          "signature": {
192054            "signature": {
192055              "publicKey": {}
192056            }
192057          },
192058          "modelCard": {
192059            "modelParameters": {
192060              "approach": {}
192061            },
192062            "quantitativeAnalysis": {
192063              "graphics": {}
192064            },
192065            "considerations": {}
192066          }
192067        },
192068        {
192069          "type": "library",
192070          "bom-ref": "pkg:npm/is-callable@1.1.4?package-id=1dc6d2322f00d7bb",
192071          "supplier": {},
192072          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
192073          "name": "is-callable",
192074          "version": "1.1.4",
192075          "description": "Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.",
192076          "licenses": [
192077            {
192078              "license": {
192079                "id": "MIT"
192080              }
192081            }
192082          ],
192083          "cpe": "cpe:2.3:a:is-callable:is-callable:1.1.4:*:*:*:*:*:*:*",
192084          "purl": "pkg:npm/is-callable@1.1.4",
192085          "swid": {
192086            "attachment": {}
192087          },
192088          "pedigree": {},
192089          "externalReferences": [
192090            {
192091              "url": "git://github.com/ljharb/is-callable.git",
192092              "type": "distribution"
192093            }
192094          ],
192095          "evidence": {},
192096          "signature": {
192097            "signature": {
192098              "publicKey": {}
192099            }
192100          },
192101          "modelCard": {
192102            "modelParameters": {
192103              "approach": {}
192104            },
192105            "quantitativeAnalysis": {
192106              "graphics": {}
192107            },
192108            "considerations": {}
192109          }
192110        },
192111        {
192112          "type": "library",
192113          "bom-ref": "pkg:npm/is-ci@1.2.1?package-id=33144f04a12b9be2",
192114          "supplier": {},
192115          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
192116          "name": "is-ci",
192117          "version": "1.2.1",
192118          "description": "Detect if the current environment is a CI server",
192119          "licenses": [
192120            {
192121              "license": {
192122                "id": "MIT"
192123              }
192124            }
192125          ],
192126          "cpe": "cpe:2.3:a:watson:is-ci:1.2.1:*:*:*:*:*:*:*",
192127          "purl": "pkg:npm/is-ci@1.2.1",
192128          "swid": {
192129            "attachment": {}
192130          },
192131          "pedigree": {},
192132          "externalReferences": [
192133            {
192134              "url": "git+https://github.com/watson/is-ci.git",
192135              "type": "distribution"
192136            },
192137            {
192138              "url": "https://github.com/watson/is-ci",
192139              "type": "website"
192140            }
192141          ],
192142          "evidence": {},
192143          "signature": {
192144            "signature": {
192145              "publicKey": {}
192146            }
192147          },
192148          "modelCard": {
192149            "modelParameters": {
192150              "approach": {}
192151            },
192152            "quantitativeAnalysis": {
192153              "graphics": {}
192154            },
192155            "considerations": {}
192156          }
192157        },
192158        {
192159          "type": "library",
192160          "bom-ref": "pkg:npm/is-cidr@3.0.0?package-id=e9a3ecf72f7e23a2",
192161          "supplier": {},
192162          "author": "silverwind \u003cme@silverwind.io\u003e",
192163          "name": "is-cidr",
192164          "version": "3.0.0",
192165          "description": "Check if a string is an IP address in CIDR notation",
192166          "licenses": [
192167            {
192168              "license": {
192169                "id": "BSD-2-Clause"
192170              }
192171            }
192172          ],
192173          "cpe": "cpe:2.3:a:silverwind:is-cidr:3.0.0:*:*:*:*:*:*:*",
192174          "purl": "pkg:npm/is-cidr@3.0.0",
192175          "swid": {
192176            "attachment": {}
192177          },
192178          "pedigree": {},
192179          "externalReferences": [
192180            {
192181              "url": "git+https://github.com/silverwind/is-cidr.git",
192182              "type": "distribution"
192183            },
192184            {
192185              "url": "https://github.com/silverwind/is-cidr#readme",
192186              "type": "website"
192187            }
192188          ],
192189          "evidence": {},
192190          "signature": {
192191            "signature": {
192192              "publicKey": {}
192193            }
192194          },
192195          "modelCard": {
192196            "modelParameters": {
192197              "approach": {}
192198            },
192199            "quantitativeAnalysis": {
192200              "graphics": {}
192201            },
192202            "considerations": {}
192203          }
192204        },
192205        {
192206          "type": "library",
192207          "bom-ref": "pkg:npm/is-date-object@1.0.1?package-id=92b971217126a920",
192208          "supplier": {},
192209          "author": "Jordan Harband",
192210          "name": "is-date-object",
192211          "version": "1.0.1",
192212          "description": "Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.",
192213          "licenses": [
192214            {
192215              "license": {
192216                "id": "MIT"
192217              }
192218            }
192219          ],
192220          "cpe": "cpe:2.3:a:is-date-object:is-date-object:1.0.1:*:*:*:*:*:*:*",
192221          "purl": "pkg:npm/is-date-object@1.0.1",
192222          "swid": {
192223            "attachment": {}
192224          },
192225          "pedigree": {},
192226          "externalReferences": [
192227            {
192228              "url": "git://github.com/ljharb/is-date-object.git",
192229              "type": "distribution"
192230            }
192231          ],
192232          "evidence": {},
192233          "signature": {
192234            "signature": {
192235              "publicKey": {}
192236            }
192237          },
192238          "modelCard": {
192239            "modelParameters": {
192240              "approach": {}
192241            },
192242            "quantitativeAnalysis": {
192243              "graphics": {}
192244            },
192245            "considerations": {}
192246          }
192247        },
192248        {
192249          "type": "library",
192250          "bom-ref": "pkg:npm/is-fullwidth-code-point@1.0.0?package-id=5e069f3bee1f8e8c",
192251          "supplier": {},
192252          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192253          "name": "is-fullwidth-code-point",
192254          "version": "1.0.0",
192255          "description": "Check if the character represented by a given Unicode code point is fullwidth",
192256          "licenses": [
192257            {
192258              "license": {
192259                "id": "MIT"
192260              }
192261            }
192262          ],
192263          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:1.0.0:*:*:*:*:*:*:*",
192264          "purl": "pkg:npm/is-fullwidth-code-point@1.0.0",
192265          "swid": {
192266            "attachment": {}
192267          },
192268          "pedigree": {},
192269          "externalReferences": [
192270            {
192271              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
192272              "type": "distribution"
192273            },
192274            {
192275              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
192276              "type": "website"
192277            }
192278          ],
192279          "evidence": {},
192280          "signature": {
192281            "signature": {
192282              "publicKey": {}
192283            }
192284          },
192285          "modelCard": {
192286            "modelParameters": {
192287              "approach": {}
192288            },
192289            "quantitativeAnalysis": {
192290              "graphics": {}
192291            },
192292            "considerations": {}
192293          }
192294        },
192295        {
192296          "type": "library",
192297          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=c9e52c69ac61a15d",
192298          "supplier": {},
192299          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192300          "name": "is-fullwidth-code-point",
192301          "version": "2.0.0",
192302          "description": "Check if the character represented by a given Unicode code point is fullwidth",
192303          "licenses": [
192304            {
192305              "license": {
192306                "id": "MIT"
192307              }
192308            }
192309          ],
192310          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
192311          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
192312          "swid": {
192313            "attachment": {}
192314          },
192315          "pedigree": {},
192316          "externalReferences": [
192317            {
192318              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
192319              "type": "distribution"
192320            },
192321            {
192322              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
192323              "type": "website"
192324            }
192325          ],
192326          "evidence": {},
192327          "signature": {
192328            "signature": {
192329              "publicKey": {}
192330            }
192331          },
192332          "modelCard": {
192333            "modelParameters": {
192334              "approach": {}
192335            },
192336            "quantitativeAnalysis": {
192337              "graphics": {}
192338            },
192339            "considerations": {}
192340          }
192341        },
192342        {
192343          "type": "library",
192344          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=18d3c43bb481b40e",
192345          "supplier": {},
192346          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192347          "name": "is-fullwidth-code-point",
192348          "version": "2.0.0",
192349          "description": "Check if the character represented by a given Unicode code point is fullwidth",
192350          "licenses": [
192351            {
192352              "license": {
192353                "id": "MIT"
192354              }
192355            }
192356          ],
192357          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
192358          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
192359          "swid": {
192360            "attachment": {}
192361          },
192362          "pedigree": {},
192363          "externalReferences": [
192364            {
192365              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
192366              "type": "distribution"
192367            },
192368            {
192369              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
192370              "type": "website"
192371            }
192372          ],
192373          "evidence": {},
192374          "signature": {
192375            "signature": {
192376              "publicKey": {}
192377            }
192378          },
192379          "modelCard": {
192380            "modelParameters": {
192381              "approach": {}
192382            },
192383            "quantitativeAnalysis": {
192384              "graphics": {}
192385            },
192386            "considerations": {}
192387          }
192388        },
192389        {
192390          "type": "library",
192391          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=bc292caf09c7f0a6",
192392          "supplier": {},
192393          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192394          "name": "is-fullwidth-code-point",
192395          "version": "2.0.0",
192396          "description": "Check if the character represented by a given Unicode code point is fullwidth",
192397          "licenses": [
192398            {
192399              "license": {
192400                "id": "MIT"
192401              }
192402            }
192403          ],
192404          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
192405          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
192406          "swid": {
192407            "attachment": {}
192408          },
192409          "pedigree": {},
192410          "externalReferences": [
192411            {
192412              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
192413              "type": "distribution"
192414            },
192415            {
192416              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
192417              "type": "website"
192418            }
192419          ],
192420          "evidence": {},
192421          "signature": {
192422            "signature": {
192423              "publicKey": {}
192424            }
192425          },
192426          "modelCard": {
192427            "modelParameters": {
192428              "approach": {}
192429            },
192430            "quantitativeAnalysis": {
192431              "graphics": {}
192432            },
192433            "considerations": {}
192434          }
192435        },
192436        {
192437          "type": "library",
192438          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=b4b1a80d5cc6ed9f",
192439          "supplier": {},
192440          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192441          "name": "is-fullwidth-code-point",
192442          "version": "2.0.0",
192443          "description": "Check if the character represented by a given Unicode code point is fullwidth",
192444          "licenses": [
192445            {
192446              "license": {
192447                "id": "MIT"
192448              }
192449            }
192450          ],
192451          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
192452          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
192453          "swid": {
192454            "attachment": {}
192455          },
192456          "pedigree": {},
192457          "externalReferences": [
192458            {
192459              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
192460              "type": "distribution"
192461            },
192462            {
192463              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
192464              "type": "website"
192465            }
192466          ],
192467          "evidence": {},
192468          "signature": {
192469            "signature": {
192470              "publicKey": {}
192471            }
192472          },
192473          "modelCard": {
192474            "modelParameters": {
192475              "approach": {}
192476            },
192477            "quantitativeAnalysis": {
192478              "graphics": {}
192479            },
192480            "considerations": {}
192481          }
192482        },
192483        {
192484          "type": "library",
192485          "bom-ref": "pkg:npm/is-installed-globally@0.1.0?package-id=52068e84c707b28e",
192486          "supplier": {},
192487          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192488          "name": "is-installed-globally",
192489          "version": "0.1.0",
192490          "description": "Check if your package was installed globally",
192491          "licenses": [
192492            {
192493              "license": {
192494                "id": "MIT"
192495              }
192496            }
192497          ],
192498          "cpe": "cpe:2.3:a:is-installed-globally:is-installed-globally:0.1.0:*:*:*:*:*:*:*",
192499          "purl": "pkg:npm/is-installed-globally@0.1.0",
192500          "swid": {
192501            "attachment": {}
192502          },
192503          "pedigree": {},
192504          "externalReferences": [
192505            {
192506              "url": "git+https://github.com/sindresorhus/is-installed-globally.git",
192507              "type": "distribution"
192508            },
192509            {
192510              "url": "https://github.com/sindresorhus/is-installed-globally#readme",
192511              "type": "website"
192512            }
192513          ],
192514          "evidence": {},
192515          "signature": {
192516            "signature": {
192517              "publicKey": {}
192518            }
192519          },
192520          "modelCard": {
192521            "modelParameters": {
192522              "approach": {}
192523            },
192524            "quantitativeAnalysis": {
192525              "graphics": {}
192526            },
192527            "considerations": {}
192528          }
192529        },
192530        {
192531          "type": "library",
192532          "bom-ref": "pkg:npm/is-npm@1.0.0?package-id=a091bf82a35edad5",
192533          "supplier": {},
192534          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (http://sindresorhus.com)",
192535          "name": "is-npm",
192536          "version": "1.0.0",
192537          "description": "Check if your code is running as an npm script",
192538          "licenses": [
192539            {
192540              "license": {
192541                "id": "MIT"
192542              }
192543            }
192544          ],
192545          "cpe": "cpe:2.3:a:sindresorhus:is-npm:1.0.0:*:*:*:*:*:*:*",
192546          "purl": "pkg:npm/is-npm@1.0.0",
192547          "swid": {
192548            "attachment": {}
192549          },
192550          "pedigree": {},
192551          "externalReferences": [
192552            {
192553              "url": "git+https://github.com/sindresorhus/is-npm.git",
192554              "type": "distribution"
192555            },
192556            {
192557              "url": "https://github.com/sindresorhus/is-npm#readme",
192558              "type": "website"
192559            }
192560          ],
192561          "evidence": {},
192562          "signature": {
192563            "signature": {
192564              "publicKey": {}
192565            }
192566          },
192567          "modelCard": {
192568            "modelParameters": {
192569              "approach": {}
192570            },
192571            "quantitativeAnalysis": {
192572              "graphics": {}
192573            },
192574            "considerations": {}
192575          }
192576        },
192577        {
192578          "type": "library",
192579          "bom-ref": "pkg:npm/is-obj@1.0.1?package-id=7979f769260859e3",
192580          "supplier": {},
192581          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192582          "name": "is-obj",
192583          "version": "1.0.1",
192584          "description": "Check if a value is an object",
192585          "licenses": [
192586            {
192587              "license": {
192588                "id": "MIT"
192589              }
192590            }
192591          ],
192592          "cpe": "cpe:2.3:a:sindresorhus:is-obj:1.0.1:*:*:*:*:*:*:*",
192593          "purl": "pkg:npm/is-obj@1.0.1",
192594          "swid": {
192595            "attachment": {}
192596          },
192597          "pedigree": {},
192598          "externalReferences": [
192599            {
192600              "url": "git+https://github.com/sindresorhus/is-obj.git",
192601              "type": "distribution"
192602            },
192603            {
192604              "url": "https://github.com/sindresorhus/is-obj#readme",
192605              "type": "website"
192606            }
192607          ],
192608          "evidence": {},
192609          "signature": {
192610            "signature": {
192611              "publicKey": {}
192612            }
192613          },
192614          "modelCard": {
192615            "modelParameters": {
192616              "approach": {}
192617            },
192618            "quantitativeAnalysis": {
192619              "graphics": {}
192620            },
192621            "considerations": {}
192622          }
192623        },
192624        {
192625          "type": "library",
192626          "bom-ref": "pkg:npm/is-path-inside@1.0.1?package-id=62bf5e53df19f8af",
192627          "supplier": {},
192628          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192629          "name": "is-path-inside",
192630          "version": "1.0.1",
192631          "description": "Check if a path is inside another path",
192632          "licenses": [
192633            {
192634              "license": {
192635                "id": "MIT"
192636              }
192637            }
192638          ],
192639          "cpe": "cpe:2.3:a:is-path-inside:is-path-inside:1.0.1:*:*:*:*:*:*:*",
192640          "purl": "pkg:npm/is-path-inside@1.0.1",
192641          "swid": {
192642            "attachment": {}
192643          },
192644          "pedigree": {},
192645          "externalReferences": [
192646            {
192647              "url": "git+https://github.com/sindresorhus/is-path-inside.git",
192648              "type": "distribution"
192649            },
192650            {
192651              "url": "https://github.com/sindresorhus/is-path-inside#readme",
192652              "type": "website"
192653            }
192654          ],
192655          "evidence": {},
192656          "signature": {
192657            "signature": {
192658              "publicKey": {}
192659            }
192660          },
192661          "modelCard": {
192662            "modelParameters": {
192663              "approach": {}
192664            },
192665            "quantitativeAnalysis": {
192666              "graphics": {}
192667            },
192668            "considerations": {}
192669          }
192670        },
192671        {
192672          "type": "library",
192673          "bom-ref": "pkg:npm/is-redirect@1.0.0?package-id=a4990c9b97577de8",
192674          "supplier": {},
192675          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192676          "name": "is-redirect",
192677          "version": "1.0.0",
192678          "description": "Check if a number is a redirect HTTP status code",
192679          "licenses": [
192680            {
192681              "license": {
192682                "id": "MIT"
192683              }
192684            }
192685          ],
192686          "cpe": "cpe:2.3:a:sindresorhus:is-redirect:1.0.0:*:*:*:*:*:*:*",
192687          "purl": "pkg:npm/is-redirect@1.0.0",
192688          "swid": {
192689            "attachment": {}
192690          },
192691          "pedigree": {},
192692          "externalReferences": [
192693            {
192694              "url": "git+https://github.com/sindresorhus/is-redirect.git",
192695              "type": "distribution"
192696            },
192697            {
192698              "url": "https://github.com/sindresorhus/is-redirect#readme",
192699              "type": "website"
192700            }
192701          ],
192702          "evidence": {},
192703          "signature": {
192704            "signature": {
192705              "publicKey": {}
192706            }
192707          },
192708          "modelCard": {
192709            "modelParameters": {
192710              "approach": {}
192711            },
192712            "quantitativeAnalysis": {
192713              "graphics": {}
192714            },
192715            "considerations": {}
192716          }
192717        },
192718        {
192719          "type": "library",
192720          "bom-ref": "pkg:npm/is-regex@1.0.4?package-id=f0395380adf7d3e7",
192721          "supplier": {},
192722          "author": "Jordan Harband",
192723          "name": "is-regex",
192724          "version": "1.0.4",
192725          "description": "Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag",
192726          "licenses": [
192727            {
192728              "license": {
192729                "id": "MIT"
192730              }
192731            }
192732          ],
192733          "cpe": "cpe:2.3:a:is-regex:is-regex:1.0.4:*:*:*:*:*:*:*",
192734          "purl": "pkg:npm/is-regex@1.0.4",
192735          "swid": {
192736            "attachment": {}
192737          },
192738          "pedigree": {},
192739          "externalReferences": [
192740            {
192741              "url": "git://github.com/ljharb/is-regex.git",
192742              "type": "distribution"
192743            },
192744            {
192745              "url": "https://github.com/ljharb/is-regex",
192746              "type": "website"
192747            }
192748          ],
192749          "evidence": {},
192750          "signature": {
192751            "signature": {
192752              "publicKey": {}
192753            }
192754          },
192755          "modelCard": {
192756            "modelParameters": {
192757              "approach": {}
192758            },
192759            "quantitativeAnalysis": {
192760              "graphics": {}
192761            },
192762            "considerations": {}
192763          }
192764        },
192765        {
192766          "type": "library",
192767          "bom-ref": "pkg:npm/is-retry-allowed@1.2.0?package-id=b30668148b87771",
192768          "supplier": {},
192769          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
192770          "name": "is-retry-allowed",
192771          "version": "1.2.0",
192772          "description": "Is retry allowed for Error?",
192773          "licenses": [
192774            {
192775              "license": {
192776                "id": "MIT"
192777              }
192778            }
192779          ],
192780          "cpe": "cpe:2.3:a:is-retry-allowed:is-retry-allowed:1.2.0:*:*:*:*:*:*:*",
192781          "purl": "pkg:npm/is-retry-allowed@1.2.0",
192782          "swid": {
192783            "attachment": {}
192784          },
192785          "pedigree": {},
192786          "externalReferences": [
192787            {
192788              "url": "git+https://github.com/floatdrop/is-retry-allowed.git",
192789              "type": "distribution"
192790            },
192791            {
192792              "url": "https://github.com/floatdrop/is-retry-allowed#readme",
192793              "type": "website"
192794            }
192795          ],
192796          "evidence": {},
192797          "signature": {
192798            "signature": {
192799              "publicKey": {}
192800            }
192801          },
192802          "modelCard": {
192803            "modelParameters": {
192804              "approach": {}
192805            },
192806            "quantitativeAnalysis": {
192807              "graphics": {}
192808            },
192809            "considerations": {}
192810          }
192811        },
192812        {
192813          "type": "library",
192814          "bom-ref": "pkg:npm/is-stream@1.1.0?package-id=e2a191b14586fcc2",
192815          "supplier": {},
192816          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
192817          "name": "is-stream",
192818          "version": "1.1.0",
192819          "description": "Check if something is a Node.js stream",
192820          "licenses": [
192821            {
192822              "license": {
192823                "id": "MIT"
192824              }
192825            }
192826          ],
192827          "cpe": "cpe:2.3:a:sindresorhus:is-stream:1.1.0:*:*:*:*:*:*:*",
192828          "purl": "pkg:npm/is-stream@1.1.0",
192829          "swid": {
192830            "attachment": {}
192831          },
192832          "pedigree": {},
192833          "externalReferences": [
192834            {
192835              "url": "git+https://github.com/sindresorhus/is-stream.git",
192836              "type": "distribution"
192837            },
192838            {
192839              "url": "https://github.com/sindresorhus/is-stream#readme",
192840              "type": "website"
192841            }
192842          ],
192843          "evidence": {},
192844          "signature": {
192845            "signature": {
192846              "publicKey": {}
192847            }
192848          },
192849          "modelCard": {
192850            "modelParameters": {
192851              "approach": {}
192852            },
192853            "quantitativeAnalysis": {
192854              "graphics": {}
192855            },
192856            "considerations": {}
192857          }
192858        },
192859        {
192860          "type": "library",
192861          "bom-ref": "pkg:npm/is-symbol@1.0.2?package-id=6f84bf274f444b99",
192862          "supplier": {},
192863          "author": "Jordan Harband",
192864          "name": "is-symbol",
192865          "version": "1.0.2",
192866          "description": "Determine if a value is an ES6 Symbol or not.",
192867          "licenses": [
192868            {
192869              "license": {
192870                "id": "MIT"
192871              }
192872            }
192873          ],
192874          "cpe": "cpe:2.3:a:is-symbol:is-symbol:1.0.2:*:*:*:*:*:*:*",
192875          "purl": "pkg:npm/is-symbol@1.0.2",
192876          "swid": {
192877            "attachment": {}
192878          },
192879          "pedigree": {},
192880          "externalReferences": [
192881            {
192882              "url": "git://github.com/ljharb/is-symbol.git",
192883              "type": "distribution"
192884            }
192885          ],
192886          "evidence": {},
192887          "signature": {
192888            "signature": {
192889              "publicKey": {}
192890            }
192891          },
192892          "modelCard": {
192893            "modelParameters": {
192894              "approach": {}
192895            },
192896            "quantitativeAnalysis": {
192897              "graphics": {}
192898            },
192899            "considerations": {}
192900          }
192901        },
192902        {
192903          "type": "library",
192904          "bom-ref": "pkg:npm/is-typedarray@1.0.0?package-id=4614424f10a58ef7",
192905          "supplier": {},
192906          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
192907          "name": "is-typedarray",
192908          "version": "1.0.0",
192909          "description": "Detect whether or not an object is a Typed Array",
192910          "licenses": [
192911            {
192912              "license": {
192913                "id": "MIT"
192914              }
192915            }
192916          ],
192917          "cpe": "cpe:2.3:a:is-typedarray:is-typedarray:1.0.0:*:*:*:*:*:*:*",
192918          "purl": "pkg:npm/is-typedarray@1.0.0",
192919          "swid": {
192920            "attachment": {}
192921          },
192922          "pedigree": {},
192923          "externalReferences": [
192924            {
192925              "url": "git://github.com/hughsk/is-typedarray.git",
192926              "type": "distribution"
192927            },
192928            {
192929              "url": "https://github.com/hughsk/is-typedarray",
192930              "type": "website"
192931            }
192932          ],
192933          "evidence": {},
192934          "signature": {
192935            "signature": {
192936              "publicKey": {}
192937            }
192938          },
192939          "modelCard": {
192940            "modelParameters": {
192941              "approach": {}
192942            },
192943            "quantitativeAnalysis": {
192944              "graphics": {}
192945            },
192946            "considerations": {}
192947          }
192948        },
192949        {
192950          "type": "library",
192951          "bom-ref": "pkg:npm/isarray@0.0.1?package-id=4eab13fd6138583f",
192952          "supplier": {},
192953          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
192954          "name": "isarray",
192955          "version": "0.0.1",
192956          "description": "Array#isArray for older browsers",
192957          "licenses": [
192958            {
192959              "license": {
192960                "id": "MIT"
192961              }
192962            }
192963          ],
192964          "cpe": "cpe:2.3:a:juliangruber:isarray:0.0.1:*:*:*:*:*:*:*",
192965          "purl": "pkg:npm/isarray@0.0.1",
192966          "swid": {
192967            "attachment": {}
192968          },
192969          "pedigree": {},
192970          "externalReferences": [
192971            {
192972              "url": "git://github.com/juliangruber/isarray.git",
192973              "type": "distribution"
192974            },
192975            {
192976              "url": "https://github.com/juliangruber/isarray",
192977              "type": "website"
192978            }
192979          ],
192980          "evidence": {},
192981          "signature": {
192982            "signature": {
192983              "publicKey": {}
192984            }
192985          },
192986          "modelCard": {
192987            "modelParameters": {
192988              "approach": {}
192989            },
192990            "quantitativeAnalysis": {
192991              "graphics": {}
192992            },
192993            "considerations": {}
192994          }
192995        },
192996        {
192997          "type": "library",
192998          "bom-ref": "pkg:npm/isarray@0.0.1?package-id=9165d82d33f922a9",
192999          "supplier": {},
193000          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
193001          "name": "isarray",
193002          "version": "0.0.1",
193003          "description": "Array#isArray for older browsers",
193004          "licenses": [
193005            {
193006              "license": {
193007                "id": "MIT"
193008              }
193009            }
193010          ],
193011          "cpe": "cpe:2.3:a:juliangruber:isarray:0.0.1:*:*:*:*:*:*:*",
193012          "purl": "pkg:npm/isarray@0.0.1",
193013          "swid": {
193014            "attachment": {}
193015          },
193016          "pedigree": {},
193017          "externalReferences": [
193018            {
193019              "url": "git://github.com/juliangruber/isarray.git",
193020              "type": "distribution"
193021            },
193022            {
193023              "url": "https://github.com/juliangruber/isarray",
193024              "type": "website"
193025            }
193026          ],
193027          "evidence": {},
193028          "signature": {
193029            "signature": {
193030              "publicKey": {}
193031            }
193032          },
193033          "modelCard": {
193034            "modelParameters": {
193035              "approach": {}
193036            },
193037            "quantitativeAnalysis": {
193038              "graphics": {}
193039            },
193040            "considerations": {}
193041          }
193042        },
193043        {
193044          "type": "library",
193045          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=67e7a38d852b614a",
193046          "supplier": {},
193047          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
193048          "name": "isarray",
193049          "version": "1.0.0",
193050          "description": "Array#isArray for older browsers",
193051          "licenses": [
193052            {
193053              "license": {
193054                "id": "MIT"
193055              }
193056            }
193057          ],
193058          "cpe": "cpe:2.3:a:juliangruber:isarray:1.0.0:*:*:*:*:*:*:*",
193059          "purl": "pkg:npm/isarray@1.0.0",
193060          "swid": {
193061            "attachment": {}
193062          },
193063          "pedigree": {},
193064          "externalReferences": [
193065            {
193066              "url": "git://github.com/juliangruber/isarray.git",
193067              "type": "distribution"
193068            },
193069            {
193070              "url": "https://github.com/juliangruber/isarray",
193071              "type": "website"
193072            }
193073          ],
193074          "evidence": {},
193075          "signature": {
193076            "signature": {
193077              "publicKey": {}
193078            }
193079          },
193080          "modelCard": {
193081            "modelParameters": {
193082              "approach": {}
193083            },
193084            "quantitativeAnalysis": {
193085              "graphics": {}
193086            },
193087            "considerations": {}
193088          }
193089        },
193090        {
193091          "type": "library",
193092          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=2d92be2d9c6d102e",
193093          "supplier": {},
193094          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
193095          "name": "isarray",
193096          "version": "1.0.0",
193097          "description": "Array#isArray for older browsers",
193098          "licenses": [
193099            {
193100              "license": {
193101                "id": "MIT"
193102              }
193103            }
193104          ],
193105          "cpe": "cpe:2.3:a:juliangruber:isarray:1.0.0:*:*:*:*:*:*:*",
193106          "purl": "pkg:npm/isarray@1.0.0",
193107          "swid": {
193108            "attachment": {}
193109          },
193110          "pedigree": {},
193111          "externalReferences": [
193112            {
193113              "url": "git://github.com/juliangruber/isarray.git",
193114              "type": "distribution"
193115            },
193116            {
193117              "url": "https://github.com/juliangruber/isarray",
193118              "type": "website"
193119            }
193120          ],
193121          "evidence": {},
193122          "signature": {
193123            "signature": {
193124              "publicKey": {}
193125            }
193126          },
193127          "modelCard": {
193128            "modelParameters": {
193129              "approach": {}
193130            },
193131            "quantitativeAnalysis": {
193132              "graphics": {}
193133            },
193134            "considerations": {}
193135          }
193136        },
193137        {
193138          "type": "library",
193139          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=cac2857ecac9cad9",
193140          "supplier": {},
193141          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
193142          "name": "isexe",
193143          "version": "2.0.0",
193144          "description": "Minimal module to check if a file is executable.",
193145          "licenses": [
193146            {
193147              "license": {
193148                "id": "ISC"
193149              }
193150            }
193151          ],
193152          "cpe": "cpe:2.3:a:isaacs:isexe:2.0.0:*:*:*:*:*:*:*",
193153          "purl": "pkg:npm/isexe@2.0.0",
193154          "swid": {
193155            "attachment": {}
193156          },
193157          "pedigree": {},
193158          "externalReferences": [
193159            {
193160              "url": "git+https://github.com/isaacs/isexe.git",
193161              "type": "distribution"
193162            },
193163            {
193164              "url": "https://github.com/isaacs/isexe#readme",
193165              "type": "website"
193166            }
193167          ],
193168          "evidence": {},
193169          "signature": {
193170            "signature": {
193171              "publicKey": {}
193172            }
193173          },
193174          "modelCard": {
193175            "modelParameters": {
193176              "approach": {}
193177            },
193178            "quantitativeAnalysis": {
193179              "graphics": {}
193180            },
193181            "considerations": {}
193182          }
193183        },
193184        {
193185          "type": "library",
193186          "bom-ref": "pkg:npm/isstream@0.1.2?package-id=fd7d0a75eb876e94",
193187          "supplier": {},
193188          "author": "Rod Vagg \u003crod@vagg.org\u003e",
193189          "name": "isstream",
193190          "version": "0.1.2",
193191          "description": "Determine if an object is a Stream",
193192          "licenses": [
193193            {
193194              "license": {
193195                "id": "MIT"
193196              }
193197            }
193198          ],
193199          "cpe": "cpe:2.3:a:isstream:isstream:0.1.2:*:*:*:*:*:*:*",
193200          "purl": "pkg:npm/isstream@0.1.2",
193201          "swid": {
193202            "attachment": {}
193203          },
193204          "pedigree": {},
193205          "externalReferences": [
193206            {
193207              "url": "git+https://github.com/rvagg/isstream.git",
193208              "type": "distribution"
193209            },
193210            {
193211              "url": "https://github.com/rvagg/isstream",
193212              "type": "website"
193213            }
193214          ],
193215          "evidence": {},
193216          "signature": {
193217            "signature": {
193218              "publicKey": {}
193219            }
193220          },
193221          "modelCard": {
193222            "modelParameters": {
193223              "approach": {}
193224            },
193225            "quantitativeAnalysis": {
193226              "graphics": {}
193227            },
193228            "considerations": {}
193229          }
193230        },
193231        {
193232          "type": "library",
193233          "bom-ref": "pkg:npm/iterare@1.2.1?package-id=f6ab001f5555d5ae",
193234          "supplier": {},
193235          "author": "Felix Becker \u003cfelix.b@outlook.com\u003e",
193236          "name": "iterare",
193237          "version": "1.2.1",
193238          "description": "Array methods for ES6 Iterators",
193239          "licenses": [
193240            {
193241              "license": {
193242                "id": "ISC"
193243              }
193244            }
193245          ],
193246          "cpe": "cpe:2.3:a:felixfbecker:iterare:1.2.1:*:*:*:*:*:*:*",
193247          "purl": "pkg:npm/iterare@1.2.1",
193248          "swid": {
193249            "attachment": {}
193250          },
193251          "pedigree": {},
193252          "externalReferences": [
193253            {
193254              "url": "git+https://github.com/felixfbecker/iterare.git",
193255              "type": "distribution"
193256            },
193257            {
193258              "url": "https://github.com/felixfbecker/iterare#readme",
193259              "type": "website"
193260            }
193261          ],
193262          "evidence": {},
193263          "signature": {
193264            "signature": {
193265              "publicKey": {}
193266            }
193267          },
193268          "modelCard": {
193269            "modelParameters": {
193270              "approach": {}
193271            },
193272            "quantitativeAnalysis": {
193273              "graphics": {}
193274            },
193275            "considerations": {}
193276          }
193277        },
193278        {
193279          "type": "library",
193280          "bom-ref": "pkg:npm/js-yaml@3.14.1?package-id=ac3e3bf70973edb6",
193281          "supplier": {},
193282          "author": "Vladimir Zapparov \u003cdervus.grim@gmail.com\u003e",
193283          "name": "js-yaml",
193284          "version": "3.14.1",
193285          "description": "YAML 1.2 parser and serializer",
193286          "licenses": [
193287            {
193288              "license": {
193289                "id": "MIT"
193290              }
193291            }
193292          ],
193293          "cpe": "cpe:2.3:a:js-yaml:js-yaml:3.14.1:*:*:*:*:*:*:*",
193294          "purl": "pkg:npm/js-yaml@3.14.1",
193295          "swid": {
193296            "attachment": {}
193297          },
193298          "pedigree": {},
193299          "externalReferences": [
193300            {
193301              "url": "git+https://github.com/nodeca/js-yaml.git",
193302              "type": "distribution"
193303            },
193304            {
193305              "url": "https://github.com/nodeca/js-yaml",
193306              "type": "website"
193307            }
193308          ],
193309          "evidence": {},
193310          "signature": {
193311            "signature": {
193312              "publicKey": {}
193313            }
193314          },
193315          "modelCard": {
193316            "modelParameters": {
193317              "approach": {}
193318            },
193319            "quantitativeAnalysis": {
193320              "graphics": {}
193321            },
193322            "considerations": {}
193323          }
193324        },
193325        {
193326          "type": "library",
193327          "bom-ref": "pkg:npm/jsbn@0.1.1?package-id=5423bb90883d31d3",
193328          "supplier": {},
193329          "author": "Tom Wu",
193330          "name": "jsbn",
193331          "version": "0.1.1",
193332          "description": "The jsbn library is a fast, portable implementation of large-number math in pure JavaScript, enabling public-key crypto and other applications on desktop and mobile browsers.",
193333          "licenses": [
193334            {
193335              "license": {
193336                "id": "MIT"
193337              }
193338            }
193339          ],
193340          "cpe": "cpe:2.3:a:andyperlitch:jsbn:0.1.1:*:*:*:*:*:*:*",
193341          "purl": "pkg:npm/jsbn@0.1.1",
193342          "swid": {
193343            "attachment": {}
193344          },
193345          "pedigree": {},
193346          "externalReferences": [
193347            {
193348              "url": "git+https://github.com/andyperlitch/jsbn.git",
193349              "type": "distribution"
193350            },
193351            {
193352              "url": "https://github.com/andyperlitch/jsbn#readme",
193353              "type": "website"
193354            }
193355          ],
193356          "evidence": {},
193357          "signature": {
193358            "signature": {
193359              "publicKey": {}
193360            }
193361          },
193362          "modelCard": {
193363            "modelParameters": {
193364              "approach": {}
193365            },
193366            "quantitativeAnalysis": {
193367              "graphics": {}
193368            },
193369            "considerations": {}
193370          }
193371        },
193372        {
193373          "type": "library",
193374          "bom-ref": "pkg:npm/json-parse-better-errors@1.0.2?package-id=988410d00081283c",
193375          "supplier": {},
193376          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
193377          "name": "json-parse-better-errors",
193378          "version": "1.0.2",
193379          "description": "JSON.parse with context information on error",
193380          "licenses": [
193381            {
193382              "license": {
193383                "id": "MIT"
193384              }
193385            }
193386          ],
193387          "cpe": "cpe:2.3:a:json-parse-better-errors:json-parse-better-errors:1.0.2:*:*:*:*:*:*:*",
193388          "purl": "pkg:npm/json-parse-better-errors@1.0.2",
193389          "swid": {
193390            "attachment": {}
193391          },
193392          "pedigree": {},
193393          "externalReferences": [
193394            {
193395              "url": "git+https://github.com/zkat/json-parse-better-errors.git",
193396              "type": "distribution"
193397            },
193398            {
193399              "url": "https://github.com/zkat/json-parse-better-errors#readme",
193400              "type": "website"
193401            }
193402          ],
193403          "evidence": {},
193404          "signature": {
193405            "signature": {
193406              "publicKey": {}
193407            }
193408          },
193409          "modelCard": {
193410            "modelParameters": {
193411              "approach": {}
193412            },
193413            "quantitativeAnalysis": {
193414              "graphics": {}
193415            },
193416            "considerations": {}
193417          }
193418        },
193419        {
193420          "type": "library",
193421          "bom-ref": "pkg:npm/json-schema@0.4.0?package-id=45c9a86c44dd53da",
193422          "supplier": {},
193423          "author": "Kris Zyp",
193424          "name": "json-schema",
193425          "version": "0.4.0",
193426          "description": "JSON Schema validation and specifications",
193427          "licenses": [
193428            {
193429              "license": {
193430                "name": "(AFL-2.1 OR BSD-3-Clause)"
193431              }
193432            }
193433          ],
193434          "cpe": "cpe:2.3:a:json-schema:json-schema:0.4.0:*:*:*:*:*:*:*",
193435          "purl": "pkg:npm/json-schema@0.4.0",
193436          "swid": {
193437            "attachment": {}
193438          },
193439          "pedigree": {},
193440          "externalReferences": [
193441            {
193442              "url": "git+ssh://git@github.com/kriszyp/json-schema.git",
193443              "type": "distribution"
193444            },
193445            {
193446              "url": "https://github.com/kriszyp/json-schema#readme",
193447              "type": "website"
193448            }
193449          ],
193450          "evidence": {},
193451          "signature": {
193452            "signature": {
193453              "publicKey": {}
193454            }
193455          },
193456          "modelCard": {
193457            "modelParameters": {
193458              "approach": {}
193459            },
193460            "quantitativeAnalysis": {
193461              "graphics": {}
193462            },
193463            "considerations": {}
193464          }
193465        },
193466        {
193467          "type": "library",
193468          "bom-ref": "pkg:npm/json-schema-resolver@1.2.2?package-id=42078307ae74905d",
193469          "supplier": {},
193470          "author": "Manuel Spigolon \u003cbehemoth89@gmail.com\u003e (https://github.com/Eomm)",
193471          "name": "json-schema-resolver",
193472          "version": "1.2.2",
193473          "description": "Resolve all your $refs",
193474          "licenses": [
193475            {
193476              "license": {
193477                "id": "MIT"
193478              }
193479            }
193480          ],
193481          "cpe": "cpe:2.3:a:json-schema-resolver:json-schema-resolver:1.2.2:*:*:*:*:*:*:*",
193482          "purl": "pkg:npm/json-schema-resolver@1.2.2",
193483          "swid": {
193484            "attachment": {}
193485          },
193486          "pedigree": {},
193487          "externalReferences": [
193488            {
193489              "url": "git+https://github.com/Eomm/json-schema-resolver.git",
193490              "type": "distribution"
193491            },
193492            {
193493              "url": "https://github.com/Eomm/json-schema-resolver#readme",
193494              "type": "website"
193495            }
193496          ],
193497          "evidence": {},
193498          "signature": {
193499            "signature": {
193500              "publicKey": {}
193501            }
193502          },
193503          "modelCard": {
193504            "modelParameters": {
193505              "approach": {}
193506            },
193507            "quantitativeAnalysis": {
193508              "graphics": {}
193509            },
193510            "considerations": {}
193511          }
193512        },
193513        {
193514          "type": "library",
193515          "bom-ref": "pkg:npm/json-schema-traverse@0.4.1?package-id=93d700e76c4d5de0",
193516          "supplier": {},
193517          "author": "Evgeny Poberezkin",
193518          "name": "json-schema-traverse",
193519          "version": "0.4.1",
193520          "description": "Traverse JSON Schema passing each schema object to callback",
193521          "licenses": [
193522            {
193523              "license": {
193524                "id": "MIT"
193525              }
193526            }
193527          ],
193528          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:0.4.1:*:*:*:*:*:*:*",
193529          "purl": "pkg:npm/json-schema-traverse@0.4.1",
193530          "swid": {
193531            "attachment": {}
193532          },
193533          "pedigree": {},
193534          "externalReferences": [
193535            {
193536              "url": "git+https://github.com/epoberezkin/json-schema-traverse.git",
193537              "type": "distribution"
193538            },
193539            {
193540              "url": "https://github.com/epoberezkin/json-schema-traverse#readme",
193541              "type": "website"
193542            }
193543          ],
193544          "evidence": {},
193545          "signature": {
193546            "signature": {
193547              "publicKey": {}
193548            }
193549          },
193550          "modelCard": {
193551            "modelParameters": {
193552              "approach": {}
193553            },
193554            "quantitativeAnalysis": {
193555              "graphics": {}
193556            },
193557            "considerations": {}
193558          }
193559        },
193560        {
193561          "type": "library",
193562          "bom-ref": "pkg:npm/json-schema-traverse@1.0.0?package-id=3ff544f972f069f",
193563          "supplier": {},
193564          "author": "Evgeny Poberezkin",
193565          "name": "json-schema-traverse",
193566          "version": "1.0.0",
193567          "description": "Traverse JSON Schema passing each schema object to callback",
193568          "licenses": [
193569            {
193570              "license": {
193571                "id": "MIT"
193572              }
193573            }
193574          ],
193575          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:1.0.0:*:*:*:*:*:*:*",
193576          "purl": "pkg:npm/json-schema-traverse@1.0.0",
193577          "swid": {
193578            "attachment": {}
193579          },
193580          "pedigree": {},
193581          "externalReferences": [
193582            {
193583              "url": "git+https://github.com/epoberezkin/json-schema-traverse.git",
193584              "type": "distribution"
193585            },
193586            {
193587              "url": "https://github.com/epoberezkin/json-schema-traverse#readme",
193588              "type": "website"
193589            }
193590          ],
193591          "evidence": {},
193592          "signature": {
193593            "signature": {
193594              "publicKey": {}
193595            }
193596          },
193597          "modelCard": {
193598            "modelParameters": {
193599              "approach": {}
193600            },
193601            "quantitativeAnalysis": {
193602              "graphics": {}
193603            },
193604            "considerations": {}
193605          }
193606        },
193607        {
193608          "type": "library",
193609          "bom-ref": "pkg:npm/json-schema-traverse@1.0.0?package-id=af6940def8a1a1b8",
193610          "supplier": {},
193611          "author": "Evgeny Poberezkin",
193612          "name": "json-schema-traverse",
193613          "version": "1.0.0",
193614          "description": "Traverse JSON Schema passing each schema object to callback",
193615          "licenses": [
193616            {
193617              "license": {
193618                "id": "MIT"
193619              }
193620            }
193621          ],
193622          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:1.0.0:*:*:*:*:*:*:*",
193623          "purl": "pkg:npm/json-schema-traverse@1.0.0",
193624          "swid": {
193625            "attachment": {}
193626          },
193627          "pedigree": {},
193628          "externalReferences": [
193629            {
193630              "url": "git+https://github.com/epoberezkin/json-schema-traverse.git",
193631              "type": "distribution"
193632            },
193633            {
193634              "url": "https://github.com/epoberezkin/json-schema-traverse#readme",
193635              "type": "website"
193636            }
193637          ],
193638          "evidence": {},
193639          "signature": {
193640            "signature": {
193641              "publicKey": {}
193642            }
193643          },
193644          "modelCard": {
193645            "modelParameters": {
193646              "approach": {}
193647            },
193648            "quantitativeAnalysis": {
193649              "graphics": {}
193650            },
193651            "considerations": {}
193652          }
193653        },
193654        {
193655          "type": "library",
193656          "bom-ref": "pkg:npm/json-stringify-safe@5.0.1?package-id=1e6af39edc851fec",
193657          "supplier": {},
193658          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
193659          "name": "json-stringify-safe",
193660          "version": "5.0.1",
193661          "description": "Like JSON.stringify, but doesn't blow up on circular refs.",
193662          "licenses": [
193663            {
193664              "license": {
193665                "id": "ISC"
193666              }
193667            }
193668          ],
193669          "cpe": "cpe:2.3:a:json-stringify-safe:json-stringify-safe:5.0.1:*:*:*:*:*:*:*",
193670          "purl": "pkg:npm/json-stringify-safe@5.0.1",
193671          "swid": {
193672            "attachment": {}
193673          },
193674          "pedigree": {},
193675          "externalReferences": [
193676            {
193677              "url": "git://github.com/isaacs/json-stringify-safe.git",
193678              "type": "distribution"
193679            },
193680            {
193681              "url": "https://github.com/isaacs/json-stringify-safe",
193682              "type": "website"
193683            }
193684          ],
193685          "evidence": {},
193686          "signature": {
193687            "signature": {
193688              "publicKey": {}
193689            }
193690          },
193691          "modelCard": {
193692            "modelParameters": {
193693              "approach": {}
193694            },
193695            "quantitativeAnalysis": {
193696              "graphics": {}
193697            },
193698            "considerations": {}
193699          }
193700        },
193701        {
193702          "type": "library",
193703          "bom-ref": "pkg:npm/jsonparse@1.3.1?package-id=b1e13c9869e6a60e",
193704          "supplier": {},
193705          "author": "Tim Caswell \u003ctim@creationix.com\u003e",
193706          "name": "jsonparse",
193707          "version": "1.3.1",
193708          "description": "This is a pure-js JSON streaming parser for node.js",
193709          "licenses": [
193710            {
193711              "license": {
193712                "id": "MIT"
193713              }
193714            }
193715          ],
193716          "cpe": "cpe:2.3:a:creationix:jsonparse:1.3.1:*:*:*:*:*:*:*",
193717          "purl": "pkg:npm/jsonparse@1.3.1",
193718          "swid": {
193719            "attachment": {}
193720          },
193721          "pedigree": {},
193722          "externalReferences": [
193723            {
193724              "url": "git+ssh://git@github.com/creationix/jsonparse.git",
193725              "type": "distribution"
193726            },
193727            {
193728              "url": "https://github.com/creationix/jsonparse#readme",
193729              "type": "website"
193730            }
193731          ],
193732          "evidence": {},
193733          "signature": {
193734            "signature": {
193735              "publicKey": {}
193736            }
193737          },
193738          "modelCard": {
193739            "modelParameters": {
193740              "approach": {}
193741            },
193742            "quantitativeAnalysis": {
193743              "graphics": {}
193744            },
193745            "considerations": {}
193746          }
193747        },
193748        {
193749          "type": "library",
193750          "bom-ref": "pkg:npm/jsprim@1.4.2?package-id=1555634d1f1bf190",
193751          "supplier": {},
193752          "name": "jsprim",
193753          "version": "1.4.2",
193754          "description": "utilities for primitive JavaScript types",
193755          "licenses": [
193756            {
193757              "license": {
193758                "id": "MIT"
193759              }
193760            }
193761          ],
193762          "cpe": "cpe:2.3:a:joyent:jsprim:1.4.2:*:*:*:*:*:*:*",
193763          "purl": "pkg:npm/jsprim@1.4.2",
193764          "swid": {
193765            "attachment": {}
193766          },
193767          "pedigree": {},
193768          "externalReferences": [
193769            {
193770              "url": "git://github.com/joyent/node-jsprim.git",
193771              "type": "distribution"
193772            },
193773            {
193774              "url": "https://github.com/joyent/node-jsprim#readme",
193775              "type": "website"
193776            }
193777          ],
193778          "evidence": {},
193779          "signature": {
193780            "signature": {
193781              "publicKey": {}
193782            }
193783          },
193784          "modelCard": {
193785            "modelParameters": {
193786              "approach": {}
193787            },
193788            "quantitativeAnalysis": {
193789              "graphics": {}
193790            },
193791            "considerations": {}
193792          }
193793        },
193794        {
193795          "type": "library",
193796          "bom-ref": "pkg:npm/latest-version@3.1.0?package-id=112a46fc0e19bff6",
193797          "supplier": {},
193798          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
193799          "name": "latest-version",
193800          "version": "3.1.0",
193801          "description": "Get the latest version of an npm package",
193802          "licenses": [
193803            {
193804              "license": {
193805                "id": "MIT"
193806              }
193807            }
193808          ],
193809          "cpe": "cpe:2.3:a:latest-version:latest-version:3.1.0:*:*:*:*:*:*:*",
193810          "purl": "pkg:npm/latest-version@3.1.0",
193811          "swid": {
193812            "attachment": {}
193813          },
193814          "pedigree": {},
193815          "externalReferences": [
193816            {
193817              "url": "git+https://github.com/sindresorhus/latest-version.git",
193818              "type": "distribution"
193819            },
193820            {
193821              "url": "https://github.com/sindresorhus/latest-version#readme",
193822              "type": "website"
193823            }
193824          ],
193825          "evidence": {},
193826          "signature": {
193827            "signature": {
193828              "publicKey": {}
193829            }
193830          },
193831          "modelCard": {
193832            "modelParameters": {
193833              "approach": {}
193834            },
193835            "quantitativeAnalysis": {
193836              "graphics": {}
193837            },
193838            "considerations": {}
193839          }
193840        },
193841        {
193842          "type": "library",
193843          "bom-ref": "pkg:npm/lazy-property@1.0.0?package-id=3cdbabf15e025def",
193844          "supplier": {},
193845          "author": "Mikola Lysenko",
193846          "name": "lazy-property",
193847          "version": "1.0.0",
193848          "description": "Lazily initialized properties for objects",
193849          "licenses": [
193850            {
193851              "license": {
193852                "id": "MIT"
193853              }
193854            }
193855          ],
193856          "cpe": "cpe:2.3:a:lazy-property:lazy-property:1.0.0:*:*:*:*:*:*:*",
193857          "purl": "pkg:npm/lazy-property@1.0.0",
193858          "swid": {
193859            "attachment": {}
193860          },
193861          "pedigree": {},
193862          "externalReferences": [
193863            {
193864              "url": "git://github.com/mikolalysenko/lazy-property.git",
193865              "type": "distribution"
193866            },
193867            {
193868              "url": "https://github.com/mikolalysenko/lazy-property#readme",
193869              "type": "website"
193870            }
193871          ],
193872          "evidence": {},
193873          "signature": {
193874            "signature": {
193875              "publicKey": {}
193876            }
193877          },
193878          "modelCard": {
193879            "modelParameters": {
193880              "approach": {}
193881            },
193882            "quantitativeAnalysis": {
193883              "graphics": {}
193884            },
193885            "considerations": {}
193886          }
193887        },
193888        {
193889          "type": "library",
193890          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.1\u0026package-id=8126b232e2d3c608",
193891          "supplier": {},
193892          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
193893          "name": "libc-utils",
193894          "version": "0.7.2-r3",
193895          "description": "Meta package to pull in correct libc",
193896          "licenses": [
193897            {
193898              "license": {
193899                "id": "BSD-2-Clause"
193900              }
193901            },
193902            {
193903              "license": {
193904                "name": "AND"
193905              }
193906            },
193907            {
193908              "license": {
193909                "id": "BSD-3-Clause"
193910              }
193911            }
193912          ],
193913          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
193914          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.1",
193915          "swid": {
193916            "attachment": {}
193917          },
193918          "pedigree": {},
193919          "externalReferences": [
193920            {
193921              "url": "https://alpinelinux.org",
193922              "type": "distribution"
193923            }
193924          ],
193925          "evidence": {},
193926          "signature": {
193927            "signature": {
193928              "publicKey": {}
193929            }
193930          },
193931          "modelCard": {
193932            "modelParameters": {
193933              "approach": {}
193934            },
193935            "quantitativeAnalysis": {
193936              "graphics": {}
193937            },
193938            "considerations": {}
193939          }
193940        },
193941        {
193942          "type": "library",
193943          "bom-ref": "pkg:npm/libcipm@4.0.8?package-id=939bd2c33a65cf65",
193944          "supplier": {},
193945          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
193946          "name": "libcipm",
193947          "version": "4.0.8",
193948          "description": "programmatic API for cipm: a ci-oriented package installer for npm",
193949          "licenses": [
193950            {
193951              "license": {
193952                "id": "MIT"
193953              }
193954            }
193955          ],
193956          "cpe": "cpe:2.3:a:libcipm:libcipm:4.0.8:*:*:*:*:*:*:*",
193957          "purl": "pkg:npm/libcipm@4.0.8",
193958          "swid": {
193959            "attachment": {}
193960          },
193961          "pedigree": {},
193962          "externalReferences": [
193963            {
193964              "url": "git+https://github.com/npm/libcipm.git",
193965              "type": "distribution"
193966            },
193967            {
193968              "url": "https://github.com/npm/libcipm#readme",
193969              "type": "website"
193970            }
193971          ],
193972          "evidence": {},
193973          "signature": {
193974            "signature": {
193975              "publicKey": {}
193976            }
193977          },
193978          "modelCard": {
193979            "modelParameters": {
193980              "approach": {}
193981            },
193982            "quantitativeAnalysis": {
193983              "graphics": {}
193984            },
193985            "considerations": {}
193986          }
193987        },
193988        {
193989          "type": "library",
193990          "bom-ref": "pkg:apk/alpine/libcrypto3@3.0.7-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.1\u0026package-id=598e6b7529ed70b1",
193991          "supplier": {},
193992          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
193993          "name": "libcrypto3",
193994          "version": "3.0.7-r2",
193995          "description": "Crypto library from openssl",
193996          "licenses": [
193997            {
193998              "license": {
193999                "id": "Apache-2.0"
194000              }
194001            }
194002          ],
194003          "cpe": "cpe:2.3:a:libcrypto3:libcrypto3:3.0.7-r2:*:*:*:*:*:*:*",
194004          "purl": "pkg:apk/alpine/libcrypto3@3.0.7-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.1",
194005          "swid": {
194006            "attachment": {}
194007          },
194008          "pedigree": {},
194009          "externalReferences": [
194010            {
194011              "url": "https://www.openssl.org/",
194012              "type": "distribution"
194013            }
194014          ],
194015          "evidence": {},
194016          "signature": {
194017            "signature": {
194018              "publicKey": {}
194019            }
194020          },
194021          "modelCard": {
194022            "modelParameters": {
194023              "approach": {}
194024            },
194025            "quantitativeAnalysis": {
194026              "graphics": {}
194027            },
194028            "considerations": {}
194029          }
194030        },
194031        {
194032          "type": "library",
194033          "bom-ref": "pkg:apk/alpine/libgcc@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.1\u0026package-id=4dbb63d06d9618e9",
194034          "supplier": {},
194035          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
194036          "name": "libgcc",
194037          "version": "12.2.1_git20220924-r4",
194038          "description": "GNU C compiler runtime libraries",
194039          "licenses": [
194040            {
194041              "license": {
194042                "id": "GPL-2.0-or-later"
194043              }
194044            },
194045            {
194046              "license": {
194047                "id": "LGPL-2.1-or-later"
194048              }
194049            }
194050          ],
194051          "cpe": "cpe:2.3:a:libgcc:libgcc:12.2.1_git20220924-r4:*:*:*:*:*:*:*",
194052          "purl": "pkg:apk/alpine/libgcc@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.1",
194053          "swid": {
194054            "attachment": {}
194055          },
194056          "pedigree": {},
194057          "externalReferences": [
194058            {
194059              "url": "https://gcc.gnu.org",
194060              "type": "distribution"
194061            }
194062          ],
194063          "evidence": {},
194064          "signature": {
194065            "signature": {
194066              "publicKey": {}
194067            }
194068          },
194069          "modelCard": {
194070            "modelParameters": {
194071              "approach": {}
194072            },
194073            "quantitativeAnalysis": {
194074              "graphics": {}
194075            },
194076            "considerations": {}
194077          }
194078        },
194079        {
194080          "type": "library",
194081          "bom-ref": "pkg:npm/libnpm@3.0.1?package-id=8765b2a6f6c0fa16",
194082          "supplier": {},
194083          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
194084          "name": "libnpm",
194085          "version": "3.0.1",
194086          "description": "Collection of programmatic APIs for the npm CLI",
194087          "licenses": [
194088            {
194089              "license": {
194090                "id": "ISC"
194091              }
194092            }
194093          ],
194094          "cpe": "cpe:2.3:a:libnpm:libnpm:3.0.1:*:*:*:*:*:*:*",
194095          "purl": "pkg:npm/libnpm@3.0.1",
194096          "swid": {
194097            "attachment": {}
194098          },
194099          "pedigree": {},
194100          "externalReferences": [
194101            {
194102              "url": "git+https://github.com/npm/libnpm.git",
194103              "type": "distribution"
194104            },
194105            {
194106              "url": "https://github.com/npm/libnpm#readme",
194107              "type": "website"
194108            }
194109          ],
194110          "evidence": {},
194111          "signature": {
194112            "signature": {
194113              "publicKey": {}
194114            }
194115          },
194116          "modelCard": {
194117            "modelParameters": {
194118              "approach": {}
194119            },
194120            "quantitativeAnalysis": {
194121              "graphics": {}
194122            },
194123            "considerations": {}
194124          }
194125        },
194126        {
194127          "type": "library",
194128          "bom-ref": "pkg:npm/libnpmaccess@3.0.2?package-id=5341f660eccfba6b",
194129          "supplier": {},
194130          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
194131          "name": "libnpmaccess",
194132          "version": "3.0.2",
194133          "description": "programmatic library for `npm access` commands",
194134          "licenses": [
194135            {
194136              "license": {
194137                "id": "ISC"
194138              }
194139            }
194140          ],
194141          "cpe": "cpe:2.3:a:libnpmaccess:libnpmaccess:3.0.2:*:*:*:*:*:*:*",
194142          "purl": "pkg:npm/libnpmaccess@3.0.2",
194143          "swid": {
194144            "attachment": {}
194145          },
194146          "pedigree": {},
194147          "externalReferences": [
194148            {
194149              "url": "git+https://github.com/npm/libnpmaccess.git",
194150              "type": "distribution"
194151            },
194152            {
194153              "url": "https://npmjs.com/package/libnpmaccess",
194154              "type": "website"
194155            }
194156          ],
194157          "evidence": {},
194158          "signature": {
194159            "signature": {
194160              "publicKey": {}
194161            }
194162          },
194163          "modelCard": {
194164            "modelParameters": {
194165              "approach": {}
194166            },
194167            "quantitativeAnalysis": {
194168              "graphics": {}
194169            },
194170            "considerations": {}
194171          }
194172        },
194173        {
194174          "type": "library",
194175          "bom-ref": "pkg:npm/libnpmconfig@1.2.1?package-id=db2a17ecbb5c09ba",
194176          "supplier": {},
194177          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
194178          "name": "libnpmconfig",
194179          "version": "1.2.1",
194180          "description": "Standalone library for reading/writing/managing npm configurations",
194181          "licenses": [
194182            {
194183              "license": {
194184                "id": "ISC"
194185              }
194186            }
194187          ],
194188          "cpe": "cpe:2.3:a:libnpmconfig:libnpmconfig:1.2.1:*:*:*:*:*:*:*",
194189          "purl": "pkg:npm/libnpmconfig@1.2.1",
194190          "swid": {
194191            "attachment": {}
194192          },
194193          "pedigree": {},
194194          "externalReferences": [
194195            {
194196              "url": "git+https://github.com/npm/libnpmconfig.git",
194197              "type": "distribution"
194198            },
194199            {
194200              "url": "https://npmjs.com/package/libnpmconfig",
194201              "type": "website"
194202            }
194203          ],
194204          "evidence": {},
194205          "signature": {
194206            "signature": {
194207              "publicKey": {}
194208            }
194209          },
194210          "modelCard": {
194211            "modelParameters": {
194212              "approach": {}
194213            },
194214            "quantitativeAnalysis": {
194215              "graphics": {}
194216            },
194217            "considerations": {}
194218          }
194219        },
194220        {
194221          "type": "library",
194222          "bom-ref": "pkg:npm/libnpmhook@5.0.3?package-id=15a009beffa78fc4",
194223          "supplier": {},
194224          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
194225          "name": "libnpmhook",
194226          "version": "5.0.3",
194227          "description": "programmatic API for managing npm registry hooks",
194228          "licenses": [
194229            {
194230              "license": {
194231                "id": "ISC"
194232              }
194233            }
194234          ],
194235          "cpe": "cpe:2.3:a:libnpmhook:libnpmhook:5.0.3:*:*:*:*:*:*:*",
194236          "purl": "pkg:npm/libnpmhook@5.0.3",
194237          "swid": {
194238            "attachment": {}
194239          },
194240          "pedigree": {},
194241          "externalReferences": [
194242            {
194243              "url": "git+https://github.com/npm/libnpmhook.git",
194244              "type": "distribution"
194245            },
194246            {
194247              "url": "https://github.com/npm/libnpmhook#readme",
194248              "type": "website"
194249            }
194250          ],
194251          "evidence": {},
194252          "signature": {
194253            "signature": {
194254              "publicKey": {}
194255            }
194256          },
194257          "modelCard": {
194258            "modelParameters": {
194259              "approach": {}
194260            },
194261            "quantitativeAnalysis": {
194262              "graphics": {}
194263            },
194264            "considerations": {}
194265          }
194266        },
194267        {
194268          "type": "library",
194269          "bom-ref": "pkg:npm/libnpmorg@1.0.1?package-id=8b6fdd9d34b188a7",
194270          "supplier": {},
194271          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
194272          "name": "libnpmorg",
194273          "version": "1.0.1",
194274          "description": "Programmatic api for `npm org` commands",
194275          "licenses": [
194276            {
194277              "license": {
194278                "id": "ISC"
194279              }
194280            }
194281          ],
194282          "cpe": "cpe:2.3:a:libnpmorg:libnpmorg:1.0.1:*:*:*:*:*:*:*",
194283          "purl": "pkg:npm/libnpmorg@1.0.1",
194284          "swid": {
194285            "attachment": {}
194286          },
194287          "pedigree": {},
194288          "externalReferences": [
194289            {
194290              "url": "git+https://github.com/npm/libnpmorg.git",
194291              "type": "distribution"
194292            },
194293            {
194294              "url": "https://npmjs.com/package/libnpmorg",
194295              "type": "website"
194296            }
194297          ],
194298          "evidence": {},
194299          "signature": {
194300            "signature": {
194301              "publicKey": {}
194302            }
194303          },
194304          "modelCard": {
194305            "modelParameters": {
194306              "approach": {}
194307            },
194308            "quantitativeAnalysis": {
194309              "graphics": {}
194310            },
194311            "considerations": {}
194312          }
194313        },
194314        {
194315          "type": "library",
194316          "bom-ref": "pkg:npm/libnpmpublish@1.1.2?package-id=4940e26c16b646a2",
194317          "supplier": {},
194318          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
194319          "name": "libnpmpublish",
194320          "version": "1.1.2",
194321          "description": "Programmatic API for the bits behind npm publish and unpublish",
194322          "licenses": [
194323            {
194324              "license": {
194325                "id": "ISC"
194326              }
194327            }
194328          ],
194329          "cpe": "cpe:2.3:a:libnpmpublish:libnpmpublish:1.1.2:*:*:*:*:*:*:*",
194330          "purl": "pkg:npm/libnpmpublish@1.1.2",
194331          "swid": {
194332            "attachment": {}
194333          },
194334          "pedigree": {},
194335          "externalReferences": [
194336            {
194337              "url": "git+https://github.com/npm/libnpmpublish.git",
194338              "type": "distribution"
194339            },
194340            {
194341              "url": "https://npmjs.com/package/libnpmpublish",
194342              "type": "website"
194343            }
194344          ],
194345          "evidence": {},
194346          "signature": {
194347            "signature": {
194348              "publicKey": {}
194349            }
194350          },
194351          "modelCard": {
194352            "modelParameters": {
194353              "approach": {}
194354            },
194355            "quantitativeAnalysis": {
194356              "graphics": {}
194357            },
194358            "considerations": {}
194359          }
194360        },
194361        {
194362          "type": "library",
194363          "bom-ref": "pkg:npm/libnpmsearch@2.0.2?package-id=4152eb0fada08f68",
194364          "supplier": {},
194365          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
194366          "name": "libnpmsearch",
194367          "version": "2.0.2",
194368          "description": "Programmatic API for searching in npm and compatible registries.",
194369          "licenses": [
194370            {
194371              "license": {
194372                "id": "ISC"
194373              }
194374            }
194375          ],
194376          "cpe": "cpe:2.3:a:libnpmsearch:libnpmsearch:2.0.2:*:*:*:*:*:*:*",
194377          "purl": "pkg:npm/libnpmsearch@2.0.2",
194378          "swid": {
194379            "attachment": {}
194380          },
194381          "pedigree": {},
194382          "externalReferences": [
194383            {
194384              "url": "git+https://github.com/npm/libnpmsearch.git",
194385              "type": "distribution"
194386            },
194387            {
194388              "url": "https://npmjs.com/package/libnpmsearch",
194389              "type": "website"
194390            }
194391          ],
194392          "evidence": {},
194393          "signature": {
194394            "signature": {
194395              "publicKey": {}
194396            }
194397          },
194398          "modelCard": {
194399            "modelParameters": {
194400              "approach": {}
194401            },
194402            "quantitativeAnalysis": {
194403              "graphics": {}
194404            },
194405            "considerations": {}
194406          }
194407        },
194408        {
194409          "type": "library",
194410          "bom-ref": "pkg:npm/libnpmteam@1.0.2?package-id=ab825ae6bda4b852",
194411          "supplier": {},
194412          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
194413          "name": "libnpmteam",
194414          "version": "1.0.2",
194415          "description": "npm Team management APIs",
194416          "licenses": [
194417            {
194418              "license": {
194419                "id": "ISC"
194420              }
194421            }
194422          ],
194423          "cpe": "cpe:2.3:a:libnpmteam:libnpmteam:1.0.2:*:*:*:*:*:*:*",
194424          "purl": "pkg:npm/libnpmteam@1.0.2",
194425          "swid": {
194426            "attachment": {}
194427          },
194428          "pedigree": {},
194429          "externalReferences": [
194430            {
194431              "url": "git+https://github.com/npm/libnpmteam.git",
194432              "type": "distribution"
194433            },
194434            {
194435              "url": "https://npmjs.com/package/libnpmteam",
194436              "type": "website"
194437            }
194438          ],
194439          "evidence": {},
194440          "signature": {
194441            "signature": {
194442              "publicKey": {}
194443            }
194444          },
194445          "modelCard": {
194446            "modelParameters": {
194447              "approach": {}
194448            },
194449            "quantitativeAnalysis": {
194450              "graphics": {}
194451            },
194452            "considerations": {}
194453          }
194454        },
194455        {
194456          "type": "library",
194457          "bom-ref": "pkg:npm/libnpx@10.2.4?package-id=670932cf0842993",
194458          "supplier": {},
194459          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
194460          "name": "libnpx",
194461          "version": "10.2.4",
194462          "description": "support library for npx -- an tool for executing npm-based packages.",
194463          "licenses": [
194464            {
194465              "license": {
194466                "id": "ISC"
194467              }
194468            }
194469          ],
194470          "cpe": "cpe:2.3:a:libnpx:libnpx:10.2.4:*:*:*:*:*:*:*",
194471          "purl": "pkg:npm/libnpx@10.2.4",
194472          "swid": {
194473            "attachment": {}
194474          },
194475          "pedigree": {},
194476          "externalReferences": [
194477            {
194478              "url": "git+https://github.com/npm/npx.git",
194479              "type": "distribution"
194480            },
194481            {
194482              "url": "https://github.com/npm/npx#readme",
194483              "type": "website"
194484            }
194485          ],
194486          "evidence": {},
194487          "signature": {
194488            "signature": {
194489              "publicKey": {}
194490            }
194491          },
194492          "modelCard": {
194493            "modelParameters": {
194494              "approach": {}
194495            },
194496            "quantitativeAnalysis": {
194497              "graphics": {}
194498            },
194499            "considerations": {}
194500          }
194501        },
194502        {
194503          "type": "library",
194504          "bom-ref": "pkg:apk/alpine/libssl3@3.0.7-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.1\u0026package-id=62fe4f2c0262ca5c",
194505          "supplier": {},
194506          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
194507          "name": "libssl3",
194508          "version": "3.0.7-r2",
194509          "description": "SSL shared libraries",
194510          "licenses": [
194511            {
194512              "license": {
194513                "id": "Apache-2.0"
194514              }
194515            }
194516          ],
194517          "cpe": "cpe:2.3:a:libssl3:libssl3:3.0.7-r2:*:*:*:*:*:*:*",
194518          "purl": "pkg:apk/alpine/libssl3@3.0.7-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.1",
194519          "swid": {
194520            "attachment": {}
194521          },
194522          "pedigree": {},
194523          "externalReferences": [
194524            {
194525              "url": "https://www.openssl.org/",
194526              "type": "distribution"
194527            }
194528          ],
194529          "evidence": {},
194530          "signature": {
194531            "signature": {
194532              "publicKey": {}
194533            }
194534          },
194535          "modelCard": {
194536            "modelParameters": {
194537              "approach": {}
194538            },
194539            "quantitativeAnalysis": {
194540              "graphics": {}
194541            },
194542            "considerations": {}
194543          }
194544        },
194545        {
194546          "type": "library",
194547          "bom-ref": "pkg:apk/alpine/libstdc++@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.1\u0026package-id=3c33807c48d3ddd2",
194548          "supplier": {},
194549          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
194550          "name": "libstdc++",
194551          "version": "12.2.1_git20220924-r4",
194552          "description": "GNU C++ standard runtime library",
194553          "licenses": [
194554            {
194555              "license": {
194556                "id": "GPL-2.0-or-later"
194557              }
194558            },
194559            {
194560              "license": {
194561                "id": "LGPL-2.1-or-later"
194562              }
194563            }
194564          ],
194565          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:12.2.1_git20220924-r4:*:*:*:*:*:*:*",
194566          "purl": "pkg:apk/alpine/libstdc++@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.1",
194567          "swid": {
194568            "attachment": {}
194569          },
194570          "pedigree": {},
194571          "externalReferences": [
194572            {
194573              "url": "https://gcc.gnu.org",
194574              "type": "distribution"
194575            }
194576          ],
194577          "evidence": {},
194578          "signature": {
194579            "signature": {
194580              "publicKey": {}
194581            }
194582          },
194583          "modelCard": {
194584            "modelParameters": {
194585              "approach": {}
194586            },
194587            "quantitativeAnalysis": {
194588              "graphics": {}
194589            },
194590            "considerations": {}
194591          }
194592        },
194593        {
194594          "type": "library",
194595          "bom-ref": "pkg:npm/lightship@6.8.0?package-id=83f0bd939f5ec53b",
194596          "supplier": {},
194597          "author": "Gajus Kuizinas \u003cgajus@gajus.com\u003e (http://gajus.com)",
194598          "name": "lightship",
194599          "version": "6.8.0",
194600          "description": "Abstracts readiness, liveness and startup checks and graceful shutdown of Node.js services running in Kubernetes.",
194601          "licenses": [
194602            {
194603              "license": {
194604                "id": "BSD-3-Clause"
194605              }
194606            }
194607          ],
194608          "cpe": "cpe:2.3:a:lightship:lightship:6.8.0:*:*:*:*:*:*:*",
194609          "purl": "pkg:npm/lightship@6.8.0",
194610          "swid": {
194611            "attachment": {}
194612          },
194613          "pedigree": {},
194614          "externalReferences": [
194615            {
194616              "url": "git+https://github.com/gajus/lightship.git",
194617              "type": "distribution"
194618            },
194619            {
194620              "url": "https://github.com/gajus/lightship#readme",
194621              "type": "website"
194622            }
194623          ],
194624          "evidence": {},
194625          "signature": {
194626            "signature": {
194627              "publicKey": {}
194628            }
194629          },
194630          "modelCard": {
194631            "modelParameters": {
194632              "approach": {}
194633            },
194634            "quantitativeAnalysis": {
194635              "graphics": {}
194636            },
194637            "considerations": {}
194638          }
194639        },
194640        {
194641          "type": "library",
194642          "bom-ref": "pkg:npm/locate-path@3.0.0?package-id=6a3c95978434a1d0",
194643          "supplier": {},
194644          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
194645          "name": "locate-path",
194646          "version": "3.0.0",
194647          "description": "Get the first path that exists on disk of multiple paths",
194648          "licenses": [
194649            {
194650              "license": {
194651                "id": "MIT"
194652              }
194653            }
194654          ],
194655          "cpe": "cpe:2.3:a:sindresorhus:locate-path:3.0.0:*:*:*:*:*:*:*",
194656          "purl": "pkg:npm/locate-path@3.0.0",
194657          "swid": {
194658            "attachment": {}
194659          },
194660          "pedigree": {},
194661          "externalReferences": [
194662            {
194663              "url": "git+https://github.com/sindresorhus/locate-path.git",
194664              "type": "distribution"
194665            },
194666            {
194667              "url": "https://github.com/sindresorhus/locate-path#readme",
194668              "type": "website"
194669            }
194670          ],
194671          "evidence": {},
194672          "signature": {
194673            "signature": {
194674              "publicKey": {}
194675            }
194676          },
194677          "modelCard": {
194678            "modelParameters": {
194679              "approach": {}
194680            },
194681            "quantitativeAnalysis": {
194682              "graphics": {}
194683            },
194684            "considerations": {}
194685          }
194686        },
194687        {
194688          "type": "library",
194689          "bom-ref": "pkg:npm/locate-path@3.0.0?package-id=e9f822cde2a9982c",
194690          "supplier": {},
194691          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
194692          "name": "locate-path",
194693          "version": "3.0.0",
194694          "description": "Get the first path that exists on disk of multiple paths",
194695          "licenses": [
194696            {
194697              "license": {
194698                "id": "MIT"
194699              }
194700            }
194701          ],
194702          "cpe": "cpe:2.3:a:sindresorhus:locate-path:3.0.0:*:*:*:*:*:*:*",
194703          "purl": "pkg:npm/locate-path@3.0.0",
194704          "swid": {
194705            "attachment": {}
194706          },
194707          "pedigree": {},
194708          "externalReferences": [
194709            {
194710              "url": "git+https://github.com/sindresorhus/locate-path.git",
194711              "type": "distribution"
194712            },
194713            {
194714              "url": "https://github.com/sindresorhus/locate-path#readme",
194715              "type": "website"
194716            }
194717          ],
194718          "evidence": {},
194719          "signature": {
194720            "signature": {
194721              "publicKey": {}
194722            }
194723          },
194724          "modelCard": {
194725            "modelParameters": {
194726              "approach": {}
194727            },
194728            "quantitativeAnalysis": {
194729              "graphics": {}
194730            },
194731            "considerations": {}
194732          }
194733        },
194734        {
194735          "type": "library",
194736          "bom-ref": "pkg:npm/lock-verify@2.1.0?package-id=f4dd576a958e3bb6",
194737          "supplier": {},
194738          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
194739          "name": "lock-verify",
194740          "version": "2.1.0",
194741          "description": "Report if your package.json is out of sync with your package-lock.json.",
194742          "licenses": [
194743            {
194744              "license": {
194745                "id": "ISC"
194746              }
194747            }
194748          ],
194749          "cpe": "cpe:2.3:a:lock-verify:lock-verify:2.1.0:*:*:*:*:*:*:*",
194750          "purl": "pkg:npm/lock-verify@2.1.0",
194751          "swid": {
194752            "attachment": {}
194753          },
194754          "pedigree": {},
194755          "externalReferences": [
194756            {
194757              "url": "git+https://github.com/iarna/lock-verify.git",
194758              "type": "distribution"
194759            },
194760            {
194761              "url": "https://github.com/iarna/lock-verify#readme",
194762              "type": "website"
194763            }
194764          ],
194765          "evidence": {},
194766          "signature": {
194767            "signature": {
194768              "publicKey": {}
194769            }
194770          },
194771          "modelCard": {
194772            "modelParameters": {
194773              "approach": {}
194774            },
194775            "quantitativeAnalysis": {
194776              "graphics": {}
194777            },
194778            "considerations": {}
194779          }
194780        },
194781        {
194782          "type": "library",
194783          "bom-ref": "pkg:npm/lockfile@1.0.4?package-id=ebdf70a73ac68f2d",
194784          "supplier": {},
194785          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
194786          "name": "lockfile",
194787          "version": "1.0.4",
194788          "description": "A very polite lock file utility, which endeavors to not litter, and to wait patiently for others.",
194789          "licenses": [
194790            {
194791              "license": {
194792                "id": "ISC"
194793              }
194794            }
194795          ],
194796          "cpe": "cpe:2.3:a:lockfile:lockfile:1.0.4:*:*:*:*:*:*:*",
194797          "purl": "pkg:npm/lockfile@1.0.4",
194798          "swid": {
194799            "attachment": {}
194800          },
194801          "pedigree": {},
194802          "externalReferences": [
194803            {
194804              "url": "git+https://github.com/npm/lockfile.git",
194805              "type": "distribution"
194806            },
194807            {
194808              "url": "https://github.com/npm/lockfile#readme",
194809              "type": "website"
194810            }
194811          ],
194812          "evidence": {},
194813          "signature": {
194814            "signature": {
194815              "publicKey": {}
194816            }
194817          },
194818          "modelCard": {
194819            "modelParameters": {
194820              "approach": {}
194821            },
194822            "quantitativeAnalysis": {
194823              "graphics": {}
194824            },
194825            "considerations": {}
194826          }
194827        },
194828        {
194829          "type": "library",
194830          "bom-ref": "pkg:npm/lodash@4.17.20?package-id=f72fa7bfea8130bb",
194831          "supplier": {},
194832          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e",
194833          "name": "lodash",
194834          "version": "4.17.20",
194835          "description": "Lodash modular utilities.",
194836          "licenses": [
194837            {
194838              "license": {
194839                "id": "MIT"
194840              }
194841            }
194842          ],
194843          "cpe": "cpe:2.3:a:lodash:lodash:4.17.20:*:*:*:*:*:*:*",
194844          "purl": "pkg:npm/lodash@4.17.20",
194845          "swid": {
194846            "attachment": {}
194847          },
194848          "pedigree": {},
194849          "externalReferences": [
194850            {
194851              "url": "git+https://github.com/lodash/lodash.git",
194852              "type": "distribution"
194853            },
194854            {
194855              "url": "https://lodash.com/",
194856              "type": "website"
194857            }
194858          ],
194859          "evidence": {},
194860          "signature": {
194861            "signature": {
194862              "publicKey": {}
194863            }
194864          },
194865          "modelCard": {
194866            "modelParameters": {
194867              "approach": {}
194868            },
194869            "quantitativeAnalysis": {
194870              "graphics": {}
194871            },
194872            "considerations": {}
194873          }
194874        },
194875        {
194876          "type": "library",
194877          "bom-ref": "pkg:npm/lodash._baseindexof@3.1.0?package-id=38efd060e3a4d336",
194878          "supplier": {},
194879          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
194880          "name": "lodash._baseindexof",
194881          "version": "3.1.0",
194882          "description": "The modern build of lodash’s internal `baseIndexOf` as a module.",
194883          "licenses": [
194884            {
194885              "license": {
194886                "id": "MIT"
194887              }
194888            }
194889          ],
194890          "cpe": "cpe:2.3:a:lodash.-baseindexof:lodash.-baseindexof:3.1.0:*:*:*:*:*:*:*",
194891          "purl": "pkg:npm/lodash._baseindexof@3.1.0",
194892          "swid": {
194893            "attachment": {}
194894          },
194895          "pedigree": {},
194896          "externalReferences": [
194897            {
194898              "url": "git+https://github.com/lodash/lodash.git",
194899              "type": "distribution"
194900            },
194901            {
194902              "url": "https://lodash.com/",
194903              "type": "website"
194904            }
194905          ],
194906          "evidence": {},
194907          "signature": {
194908            "signature": {
194909              "publicKey": {}
194910            }
194911          },
194912          "modelCard": {
194913            "modelParameters": {
194914              "approach": {}
194915            },
194916            "quantitativeAnalysis": {
194917              "graphics": {}
194918            },
194919            "considerations": {}
194920          }
194921        },
194922        {
194923          "type": "library",
194924          "bom-ref": "pkg:npm/lodash._baseuniq@4.6.0?package-id=f3cad3a8a8778d94",
194925          "supplier": {},
194926          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
194927          "name": "lodash._baseuniq",
194928          "version": "4.6.0",
194929          "description": "The internal lodash function `baseUniq` exported as a module.",
194930          "licenses": [
194931            {
194932              "license": {
194933                "id": "MIT"
194934              }
194935            }
194936          ],
194937          "cpe": "cpe:2.3:a:lodash.-baseuniq:lodash.-baseuniq:4.6.0:*:*:*:*:*:*:*",
194938          "purl": "pkg:npm/lodash._baseuniq@4.6.0",
194939          "swid": {
194940            "attachment": {}
194941          },
194942          "pedigree": {},
194943          "externalReferences": [
194944            {
194945              "url": "git+https://github.com/lodash/lodash.git",
194946              "type": "distribution"
194947            },
194948            {
194949              "url": "https://lodash.com/",
194950              "type": "website"
194951            }
194952          ],
194953          "evidence": {},
194954          "signature": {
194955            "signature": {
194956              "publicKey": {}
194957            }
194958          },
194959          "modelCard": {
194960            "modelParameters": {
194961              "approach": {}
194962            },
194963            "quantitativeAnalysis": {
194964              "graphics": {}
194965            },
194966            "considerations": {}
194967          }
194968        },
194969        {
194970          "type": "library",
194971          "bom-ref": "pkg:npm/lodash._bindcallback@3.0.1?package-id=aceccd904d52fec7",
194972          "supplier": {},
194973          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
194974          "name": "lodash._bindcallback",
194975          "version": "3.0.1",
194976          "description": "The modern build of lodash’s internal `bindCallback` as a module.",
194977          "licenses": [
194978            {
194979              "license": {
194980                "id": "MIT"
194981              }
194982            }
194983          ],
194984          "cpe": "cpe:2.3:a:lodash.-bindcallback:lodash.-bindcallback:3.0.1:*:*:*:*:*:*:*",
194985          "purl": "pkg:npm/lodash._bindcallback@3.0.1",
194986          "swid": {
194987            "attachment": {}
194988          },
194989          "pedigree": {},
194990          "externalReferences": [
194991            {
194992              "url": "git+https://github.com/lodash/lodash.git",
194993              "type": "distribution"
194994            },
194995            {
194996              "url": "https://lodash.com/",
194997              "type": "website"
194998            }
194999          ],
195000          "evidence": {},
195001          "signature": {
195002            "signature": {
195003              "publicKey": {}
195004            }
195005          },
195006          "modelCard": {
195007            "modelParameters": {
195008              "approach": {}
195009            },
195010            "quantitativeAnalysis": {
195011              "graphics": {}
195012            },
195013            "considerations": {}
195014          }
195015        },
195016        {
195017          "type": "library",
195018          "bom-ref": "pkg:npm/lodash._cacheindexof@3.0.2?package-id=9366742db20085f0",
195019          "supplier": {},
195020          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195021          "name": "lodash._cacheindexof",
195022          "version": "3.0.2",
195023          "description": "The modern build of lodash’s internal `cacheIndexOf` as a module.",
195024          "licenses": [
195025            {
195026              "license": {
195027                "id": "MIT"
195028              }
195029            }
195030          ],
195031          "cpe": "cpe:2.3:a:lodash.-cacheindexof:lodash.-cacheindexof:3.0.2:*:*:*:*:*:*:*",
195032          "purl": "pkg:npm/lodash._cacheindexof@3.0.2",
195033          "swid": {
195034            "attachment": {}
195035          },
195036          "pedigree": {},
195037          "externalReferences": [
195038            {
195039              "url": "git+https://github.com/lodash/lodash.git",
195040              "type": "distribution"
195041            },
195042            {
195043              "url": "https://lodash.com/",
195044              "type": "website"
195045            }
195046          ],
195047          "evidence": {},
195048          "signature": {
195049            "signature": {
195050              "publicKey": {}
195051            }
195052          },
195053          "modelCard": {
195054            "modelParameters": {
195055              "approach": {}
195056            },
195057            "quantitativeAnalysis": {
195058              "graphics": {}
195059            },
195060            "considerations": {}
195061          }
195062        },
195063        {
195064          "type": "library",
195065          "bom-ref": "pkg:npm/lodash._createcache@3.1.2?package-id=edbe9d8077eb16ba",
195066          "supplier": {},
195067          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195068          "name": "lodash._createcache",
195069          "version": "3.1.2",
195070          "description": "The modern build of lodash’s internal `createCache` as a module.",
195071          "licenses": [
195072            {
195073              "license": {
195074                "id": "MIT"
195075              }
195076            }
195077          ],
195078          "cpe": "cpe:2.3:a:lodash.-createcache:lodash.-createcache:3.1.2:*:*:*:*:*:*:*",
195079          "purl": "pkg:npm/lodash._createcache@3.1.2",
195080          "swid": {
195081            "attachment": {}
195082          },
195083          "pedigree": {},
195084          "externalReferences": [
195085            {
195086              "url": "git+https://github.com/lodash/lodash.git",
195087              "type": "distribution"
195088            },
195089            {
195090              "url": "https://lodash.com/",
195091              "type": "website"
195092            }
195093          ],
195094          "evidence": {},
195095          "signature": {
195096            "signature": {
195097              "publicKey": {}
195098            }
195099          },
195100          "modelCard": {
195101            "modelParameters": {
195102              "approach": {}
195103            },
195104            "quantitativeAnalysis": {
195105              "graphics": {}
195106            },
195107            "considerations": {}
195108          }
195109        },
195110        {
195111          "type": "library",
195112          "bom-ref": "pkg:npm/lodash._createset@4.0.3?package-id=27ed42f7fc9601ba",
195113          "supplier": {},
195114          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195115          "name": "lodash._createset",
195116          "version": "4.0.3",
195117          "description": "The internal lodash function `createSet` exported as a module.",
195118          "licenses": [
195119            {
195120              "license": {
195121                "id": "MIT"
195122              }
195123            }
195124          ],
195125          "cpe": "cpe:2.3:a:lodash.-createset:lodash.-createset:4.0.3:*:*:*:*:*:*:*",
195126          "purl": "pkg:npm/lodash._createset@4.0.3",
195127          "swid": {
195128            "attachment": {}
195129          },
195130          "pedigree": {},
195131          "externalReferences": [
195132            {
195133              "url": "git+https://github.com/lodash/lodash.git",
195134              "type": "distribution"
195135            },
195136            {
195137              "url": "https://lodash.com/",
195138              "type": "website"
195139            }
195140          ],
195141          "evidence": {},
195142          "signature": {
195143            "signature": {
195144              "publicKey": {}
195145            }
195146          },
195147          "modelCard": {
195148            "modelParameters": {
195149              "approach": {}
195150            },
195151            "quantitativeAnalysis": {
195152              "graphics": {}
195153            },
195154            "considerations": {}
195155          }
195156        },
195157        {
195158          "type": "library",
195159          "bom-ref": "pkg:npm/lodash._getnative@3.9.1?package-id=b817ace9e00c6dc1",
195160          "supplier": {},
195161          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195162          "name": "lodash._getnative",
195163          "version": "3.9.1",
195164          "description": "The modern build of lodash’s internal `getNative` as a module.",
195165          "licenses": [
195166            {
195167              "license": {
195168                "id": "MIT"
195169              }
195170            }
195171          ],
195172          "cpe": "cpe:2.3:a:lodash.-getnative:lodash.-getnative:3.9.1:*:*:*:*:*:*:*",
195173          "purl": "pkg:npm/lodash._getnative@3.9.1",
195174          "swid": {
195175            "attachment": {}
195176          },
195177          "pedigree": {},
195178          "externalReferences": [
195179            {
195180              "url": "git+https://github.com/lodash/lodash.git",
195181              "type": "distribution"
195182            },
195183            {
195184              "url": "https://lodash.com/",
195185              "type": "website"
195186            }
195187          ],
195188          "evidence": {},
195189          "signature": {
195190            "signature": {
195191              "publicKey": {}
195192            }
195193          },
195194          "modelCard": {
195195            "modelParameters": {
195196              "approach": {}
195197            },
195198            "quantitativeAnalysis": {
195199              "graphics": {}
195200            },
195201            "considerations": {}
195202          }
195203        },
195204        {
195205          "type": "library",
195206          "bom-ref": "pkg:npm/lodash._root@3.0.1?package-id=3975d2ad53d321e8",
195207          "supplier": {},
195208          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195209          "name": "lodash._root",
195210          "version": "3.0.1",
195211          "description": "The internal lodash function `root` exported as a module.",
195212          "licenses": [
195213            {
195214              "license": {
195215                "id": "MIT"
195216              }
195217            }
195218          ],
195219          "cpe": "cpe:2.3:a:lodash.-root:lodash.-root:3.0.1:*:*:*:*:*:*:*",
195220          "purl": "pkg:npm/lodash._root@3.0.1",
195221          "swid": {
195222            "attachment": {}
195223          },
195224          "pedigree": {},
195225          "externalReferences": [
195226            {
195227              "url": "git+https://github.com/lodash/lodash.git",
195228              "type": "distribution"
195229            },
195230            {
195231              "url": "https://lodash.com/",
195232              "type": "website"
195233            }
195234          ],
195235          "evidence": {},
195236          "signature": {
195237            "signature": {
195238              "publicKey": {}
195239            }
195240          },
195241          "modelCard": {
195242            "modelParameters": {
195243              "approach": {}
195244            },
195245            "quantitativeAnalysis": {
195246              "graphics": {}
195247            },
195248            "considerations": {}
195249          }
195250        },
195251        {
195252          "type": "library",
195253          "bom-ref": "pkg:npm/lodash.clonedeep@4.5.0?package-id=60a70c19659c0615",
195254          "supplier": {},
195255          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195256          "name": "lodash.clonedeep",
195257          "version": "4.5.0",
195258          "description": "The lodash method `_.cloneDeep` exported as a module.",
195259          "licenses": [
195260            {
195261              "license": {
195262                "id": "MIT"
195263              }
195264            }
195265          ],
195266          "cpe": "cpe:2.3:a:lodash.clonedeep:lodash.clonedeep:4.5.0:*:*:*:*:*:*:*",
195267          "purl": "pkg:npm/lodash.clonedeep@4.5.0",
195268          "swid": {
195269            "attachment": {}
195270          },
195271          "pedigree": {},
195272          "externalReferences": [
195273            {
195274              "url": "git+https://github.com/lodash/lodash.git",
195275              "type": "distribution"
195276            },
195277            {
195278              "url": "https://lodash.com/",
195279              "type": "website"
195280            }
195281          ],
195282          "evidence": {},
195283          "signature": {
195284            "signature": {
195285              "publicKey": {}
195286            }
195287          },
195288          "modelCard": {
195289            "modelParameters": {
195290              "approach": {}
195291            },
195292            "quantitativeAnalysis": {
195293              "graphics": {}
195294            },
195295            "considerations": {}
195296          }
195297        },
195298        {
195299          "type": "library",
195300          "bom-ref": "pkg:npm/lodash.restparam@3.6.1?package-id=cd218c729d0105b1",
195301          "supplier": {},
195302          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195303          "name": "lodash.restparam",
195304          "version": "3.6.1",
195305          "description": "The modern build of lodash’s `_.restParam` as a module.",
195306          "licenses": [
195307            {
195308              "license": {
195309                "id": "MIT"
195310              }
195311            }
195312          ],
195313          "cpe": "cpe:2.3:a:lodash.restparam:lodash.restparam:3.6.1:*:*:*:*:*:*:*",
195314          "purl": "pkg:npm/lodash.restparam@3.6.1",
195315          "swid": {
195316            "attachment": {}
195317          },
195318          "pedigree": {},
195319          "externalReferences": [
195320            {
195321              "url": "git+https://github.com/lodash/lodash.git",
195322              "type": "distribution"
195323            },
195324            {
195325              "url": "https://lodash.com/",
195326              "type": "website"
195327            }
195328          ],
195329          "evidence": {},
195330          "signature": {
195331            "signature": {
195332              "publicKey": {}
195333            }
195334          },
195335          "modelCard": {
195336            "modelParameters": {
195337              "approach": {}
195338            },
195339            "quantitativeAnalysis": {
195340              "graphics": {}
195341            },
195342            "considerations": {}
195343          }
195344        },
195345        {
195346          "type": "library",
195347          "bom-ref": "pkg:npm/lodash.union@4.6.0?package-id=fd1f76b549051dc5",
195348          "supplier": {},
195349          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195350          "name": "lodash.union",
195351          "version": "4.6.0",
195352          "description": "The lodash method `_.union` exported as a module.",
195353          "licenses": [
195354            {
195355              "license": {
195356                "id": "MIT"
195357              }
195358            }
195359          ],
195360          "cpe": "cpe:2.3:a:lodash.union:lodash.union:4.6.0:*:*:*:*:*:*:*",
195361          "purl": "pkg:npm/lodash.union@4.6.0",
195362          "swid": {
195363            "attachment": {}
195364          },
195365          "pedigree": {},
195366          "externalReferences": [
195367            {
195368              "url": "git+https://github.com/lodash/lodash.git",
195369              "type": "distribution"
195370            },
195371            {
195372              "url": "https://lodash.com/",
195373              "type": "website"
195374            }
195375          ],
195376          "evidence": {},
195377          "signature": {
195378            "signature": {
195379              "publicKey": {}
195380            }
195381          },
195382          "modelCard": {
195383            "modelParameters": {
195384              "approach": {}
195385            },
195386            "quantitativeAnalysis": {
195387              "graphics": {}
195388            },
195389            "considerations": {}
195390          }
195391        },
195392        {
195393          "type": "library",
195394          "bom-ref": "pkg:npm/lodash.uniq@4.5.0?package-id=ff80c2262d287958",
195395          "supplier": {},
195396          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195397          "name": "lodash.uniq",
195398          "version": "4.5.0",
195399          "description": "The lodash method `_.uniq` exported as a module.",
195400          "licenses": [
195401            {
195402              "license": {
195403                "id": "MIT"
195404              }
195405            }
195406          ],
195407          "cpe": "cpe:2.3:a:lodash.uniq:lodash.uniq:4.5.0:*:*:*:*:*:*:*",
195408          "purl": "pkg:npm/lodash.uniq@4.5.0",
195409          "swid": {
195410            "attachment": {}
195411          },
195412          "pedigree": {},
195413          "externalReferences": [
195414            {
195415              "url": "git+https://github.com/lodash/lodash.git",
195416              "type": "distribution"
195417            },
195418            {
195419              "url": "https://lodash.com/",
195420              "type": "website"
195421            }
195422          ],
195423          "evidence": {},
195424          "signature": {
195425            "signature": {
195426              "publicKey": {}
195427            }
195428          },
195429          "modelCard": {
195430            "modelParameters": {
195431              "approach": {}
195432            },
195433            "quantitativeAnalysis": {
195434              "graphics": {}
195435            },
195436            "considerations": {}
195437          }
195438        },
195439        {
195440          "type": "library",
195441          "bom-ref": "pkg:npm/lodash.without@4.4.0?package-id=284f38c0ca8041d8",
195442          "supplier": {},
195443          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
195444          "name": "lodash.without",
195445          "version": "4.4.0",
195446          "description": "The lodash method `_.without` exported as a module.",
195447          "licenses": [
195448            {
195449              "license": {
195450                "id": "MIT"
195451              }
195452            }
195453          ],
195454          "cpe": "cpe:2.3:a:lodash.without:lodash.without:4.4.0:*:*:*:*:*:*:*",
195455          "purl": "pkg:npm/lodash.without@4.4.0",
195456          "swid": {
195457            "attachment": {}
195458          },
195459          "pedigree": {},
195460          "externalReferences": [
195461            {
195462              "url": "git+https://github.com/lodash/lodash.git",
195463              "type": "distribution"
195464            },
195465            {
195466              "url": "https://lodash.com/",
195467              "type": "website"
195468            }
195469          ],
195470          "evidence": {},
195471          "signature": {
195472            "signature": {
195473              "publicKey": {}
195474            }
195475          },
195476          "modelCard": {
195477            "modelParameters": {
195478              "approach": {}
195479            },
195480            "quantitativeAnalysis": {
195481              "graphics": {}
195482            },
195483            "considerations": {}
195484          }
195485        },
195486        {
195487          "type": "library",
195488          "bom-ref": "pkg:npm/lowercase-keys@1.0.1?package-id=409c8833cd49dbdb",
195489          "supplier": {},
195490          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
195491          "name": "lowercase-keys",
195492          "version": "1.0.1",
195493          "description": "Lowercase the keys of an object",
195494          "licenses": [
195495            {
195496              "license": {
195497                "id": "MIT"
195498              }
195499            }
195500          ],
195501          "cpe": "cpe:2.3:a:lowercase-keys:lowercase-keys:1.0.1:*:*:*:*:*:*:*",
195502          "purl": "pkg:npm/lowercase-keys@1.0.1",
195503          "swid": {
195504            "attachment": {}
195505          },
195506          "pedigree": {},
195507          "externalReferences": [
195508            {
195509              "url": "git+https://github.com/sindresorhus/lowercase-keys.git",
195510              "type": "distribution"
195511            },
195512            {
195513              "url": "https://github.com/sindresorhus/lowercase-keys#readme",
195514              "type": "website"
195515            }
195516          ],
195517          "evidence": {},
195518          "signature": {
195519            "signature": {
195520              "publicKey": {}
195521            }
195522          },
195523          "modelCard": {
195524            "modelParameters": {
195525              "approach": {}
195526            },
195527            "quantitativeAnalysis": {
195528              "graphics": {}
195529            },
195530            "considerations": {}
195531          }
195532        },
195533        {
195534          "type": "library",
195535          "bom-ref": "pkg:npm/lru-cache@4.1.5?package-id=eef94188c4c5e168",
195536          "supplier": {},
195537          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
195538          "name": "lru-cache",
195539          "version": "4.1.5",
195540          "description": "A cache object that deletes the least-recently-used items.",
195541          "licenses": [
195542            {
195543              "license": {
195544                "id": "ISC"
195545              }
195546            }
195547          ],
195548          "cpe": "cpe:2.3:a:lru-cache:lru-cache:4.1.5:*:*:*:*:*:*:*",
195549          "purl": "pkg:npm/lru-cache@4.1.5",
195550          "swid": {
195551            "attachment": {}
195552          },
195553          "pedigree": {},
195554          "externalReferences": [
195555            {
195556              "url": "git://github.com/isaacs/node-lru-cache.git",
195557              "type": "distribution"
195558            },
195559            {
195560              "url": "https://github.com/isaacs/node-lru-cache#readme",
195561              "type": "website"
195562            }
195563          ],
195564          "evidence": {},
195565          "signature": {
195566            "signature": {
195567              "publicKey": {}
195568            }
195569          },
195570          "modelCard": {
195571            "modelParameters": {
195572              "approach": {}
195573            },
195574            "quantitativeAnalysis": {
195575              "graphics": {}
195576            },
195577            "considerations": {}
195578          }
195579        },
195580        {
195581          "type": "library",
195582          "bom-ref": "pkg:npm/lru-cache@5.1.1?package-id=6e978256c4691a8c",
195583          "supplier": {},
195584          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
195585          "name": "lru-cache",
195586          "version": "5.1.1",
195587          "description": "A cache object that deletes the least-recently-used items.",
195588          "licenses": [
195589            {
195590              "license": {
195591                "id": "ISC"
195592              }
195593            }
195594          ],
195595          "cpe": "cpe:2.3:a:lru-cache:lru-cache:5.1.1:*:*:*:*:*:*:*",
195596          "purl": "pkg:npm/lru-cache@5.1.1",
195597          "swid": {
195598            "attachment": {}
195599          },
195600          "pedigree": {},
195601          "externalReferences": [
195602            {
195603              "url": "git://github.com/isaacs/node-lru-cache.git",
195604              "type": "distribution"
195605            },
195606            {
195607              "url": "https://github.com/isaacs/node-lru-cache#readme",
195608              "type": "website"
195609            }
195610          ],
195611          "evidence": {},
195612          "signature": {
195613            "signature": {
195614              "publicKey": {}
195615            }
195616          },
195617          "modelCard": {
195618            "modelParameters": {
195619              "approach": {}
195620            },
195621            "quantitativeAnalysis": {
195622              "graphics": {}
195623            },
195624            "considerations": {}
195625          }
195626        },
195627        {
195628          "type": "library",
195629          "bom-ref": "pkg:npm/lru_map@0.3.3?package-id=8593166d4c692511",
195630          "supplier": {},
195631          "author": "Rasmus Andersson \u003cme@rsms.me\u003e",
195632          "name": "lru_map",
195633          "version": "0.3.3",
195634          "description": "Finite key-value map using the Least Recently Used (LRU) algorithm where the most recently used objects are keept in the map while less recently used items are evicted to make room for new ones.",
195635          "licenses": [
195636            {
195637              "license": {
195638                "id": "MIT"
195639              }
195640            }
195641          ],
195642          "cpe": "cpe:2.3:a:lru-map:lru-map:0.3.3:*:*:*:*:*:*:*",
195643          "purl": "pkg:npm/lru_map@0.3.3",
195644          "swid": {
195645            "attachment": {}
195646          },
195647          "pedigree": {},
195648          "externalReferences": [
195649            {
195650              "url": "git+https://github.com/rsms/js-lru.git",
195651              "type": "distribution"
195652            },
195653            {
195654              "url": "https://github.com/rsms/js-lru#readme",
195655              "type": "website"
195656            }
195657          ],
195658          "evidence": {},
195659          "signature": {
195660            "signature": {
195661              "publicKey": {}
195662            }
195663          },
195664          "modelCard": {
195665            "modelParameters": {
195666              "approach": {}
195667            },
195668            "quantitativeAnalysis": {
195669              "graphics": {}
195670            },
195671            "considerations": {}
195672          }
195673        },
195674        {
195675          "type": "library",
195676          "bom-ref": "pkg:npm/make-dir@1.3.0?package-id=8c1dc4a13ddd1f8b",
195677          "supplier": {},
195678          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
195679          "name": "make-dir",
195680          "version": "1.3.0",
195681          "description": "Make a directory and its parents if needed - Think `mkdir -p`",
195682          "licenses": [
195683            {
195684              "license": {
195685                "id": "MIT"
195686              }
195687            }
195688          ],
195689          "cpe": "cpe:2.3:a:sindresorhus:make-dir:1.3.0:*:*:*:*:*:*:*",
195690          "purl": "pkg:npm/make-dir@1.3.0",
195691          "swid": {
195692            "attachment": {}
195693          },
195694          "pedigree": {},
195695          "externalReferences": [
195696            {
195697              "url": "git+https://github.com/sindresorhus/make-dir.git",
195698              "type": "distribution"
195699            },
195700            {
195701              "url": "https://github.com/sindresorhus/make-dir#readme",
195702              "type": "website"
195703            }
195704          ],
195705          "evidence": {},
195706          "signature": {
195707            "signature": {
195708              "publicKey": {}
195709            }
195710          },
195711          "modelCard": {
195712            "modelParameters": {
195713              "approach": {}
195714            },
195715            "quantitativeAnalysis": {
195716              "graphics": {}
195717            },
195718            "considerations": {}
195719          }
195720        },
195721        {
195722          "type": "library",
195723          "bom-ref": "pkg:npm/make-fetch-happen@5.0.2?package-id=b812e5c3d8342059",
195724          "supplier": {},
195725          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
195726          "name": "make-fetch-happen",
195727          "version": "5.0.2",
195728          "description": "Opinionated, caching, retrying fetch client",
195729          "licenses": [
195730            {
195731              "license": {
195732                "id": "ISC"
195733              }
195734            }
195735          ],
195736          "cpe": "cpe:2.3:a:make-fetch-happen:make-fetch-happen:5.0.2:*:*:*:*:*:*:*",
195737          "purl": "pkg:npm/make-fetch-happen@5.0.2",
195738          "swid": {
195739            "attachment": {}
195740          },
195741          "pedigree": {},
195742          "externalReferences": [
195743            {
195744              "url": "git+https://github.com/zkat/make-fetch-happen.git",
195745              "type": "distribution"
195746            },
195747            {
195748              "url": "https://github.com/zkat/make-fetch-happen#readme",
195749              "type": "website"
195750            }
195751          ],
195752          "evidence": {},
195753          "signature": {
195754            "signature": {
195755              "publicKey": {}
195756            }
195757          },
195758          "modelCard": {
195759            "modelParameters": {
195760              "approach": {}
195761            },
195762            "quantitativeAnalysis": {
195763              "graphics": {}
195764            },
195765            "considerations": {}
195766          }
195767        },
195768        {
195769          "type": "library",
195770          "bom-ref": "pkg:npm/meant@1.0.2?package-id=9f846d616f5464f2",
195771          "supplier": {},
195772          "author": "Daijiro Wachi",
195773          "name": "meant",
195774          "version": "1.0.2",
195775          "description": "Like the `Did you mean?` in git for npm",
195776          "licenses": [
195777            {
195778              "license": {
195779                "id": "MIT"
195780              }
195781            }
195782          ],
195783          "cpe": "cpe:2.3:a:watilde:meant:1.0.2:*:*:*:*:*:*:*",
195784          "purl": "pkg:npm/meant@1.0.2",
195785          "swid": {
195786            "attachment": {}
195787          },
195788          "pedigree": {},
195789          "externalReferences": [
195790            {
195791              "url": "git+https://github.com/watilde/meant.git",
195792              "type": "distribution"
195793            },
195794            {
195795              "url": "https://github.com/watilde/meant#readme",
195796              "type": "website"
195797            }
195798          ],
195799          "evidence": {},
195800          "signature": {
195801            "signature": {
195802              "publicKey": {}
195803            }
195804          },
195805          "modelCard": {
195806            "modelParameters": {
195807              "approach": {}
195808            },
195809            "quantitativeAnalysis": {
195810              "graphics": {}
195811            },
195812            "considerations": {}
195813          }
195814        },
195815        {
195816          "type": "library",
195817          "bom-ref": "pkg:npm/media-typer@0.3.0?package-id=33c04253526b5d6b",
195818          "supplier": {},
195819          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
195820          "name": "media-typer",
195821          "version": "0.3.0",
195822          "description": "Simple RFC 6838 media type parser and formatter",
195823          "licenses": [
195824            {
195825              "license": {
195826                "id": "MIT"
195827              }
195828            }
195829          ],
195830          "cpe": "cpe:2.3:a:media-typer:media-typer:0.3.0:*:*:*:*:*:*:*",
195831          "purl": "pkg:npm/media-typer@0.3.0",
195832          "swid": {
195833            "attachment": {}
195834          },
195835          "pedigree": {},
195836          "externalReferences": [
195837            {
195838              "url": "git+https://github.com/jshttp/media-typer.git",
195839              "type": "distribution"
195840            },
195841            {
195842              "url": "https://github.com/jshttp/media-typer#readme",
195843              "type": "website"
195844            }
195845          ],
195846          "evidence": {},
195847          "signature": {
195848            "signature": {
195849              "publicKey": {}
195850            }
195851          },
195852          "modelCard": {
195853            "modelParameters": {
195854              "approach": {}
195855            },
195856            "quantitativeAnalysis": {
195857              "graphics": {}
195858            },
195859            "considerations": {}
195860          }
195861        },
195862        {
195863          "type": "library",
195864          "bom-ref": "pkg:npm/merge-descriptors@1.0.1?package-id=c7a60e972125bba3",
195865          "supplier": {},
195866          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
195867          "name": "merge-descriptors",
195868          "version": "1.0.1",
195869          "description": "Merge objects using descriptors",
195870          "licenses": [
195871            {
195872              "license": {
195873                "id": "MIT"
195874              }
195875            }
195876          ],
195877          "cpe": "cpe:2.3:a:merge-descriptors:merge-descriptors:1.0.1:*:*:*:*:*:*:*",
195878          "purl": "pkg:npm/merge-descriptors@1.0.1",
195879          "swid": {
195880            "attachment": {}
195881          },
195882          "pedigree": {},
195883          "externalReferences": [
195884            {
195885              "url": "git+https://github.com/component/merge-descriptors.git",
195886              "type": "distribution"
195887            },
195888            {
195889              "url": "https://github.com/component/merge-descriptors#readme",
195890              "type": "website"
195891            }
195892          ],
195893          "evidence": {},
195894          "signature": {
195895            "signature": {
195896              "publicKey": {}
195897            }
195898          },
195899          "modelCard": {
195900            "modelParameters": {
195901              "approach": {}
195902            },
195903            "quantitativeAnalysis": {
195904              "graphics": {}
195905            },
195906            "considerations": {}
195907          }
195908        },
195909        {
195910          "type": "library",
195911          "bom-ref": "pkg:npm/methods@1.1.2?package-id=96ba5c582a21e3ad",
195912          "supplier": {},
195913          "name": "methods",
195914          "version": "1.1.2",
195915          "description": "HTTP methods that node supports",
195916          "licenses": [
195917            {
195918              "license": {
195919                "id": "MIT"
195920              }
195921            }
195922          ],
195923          "cpe": "cpe:2.3:a:methods:methods:1.1.2:*:*:*:*:*:*:*",
195924          "purl": "pkg:npm/methods@1.1.2",
195925          "swid": {
195926            "attachment": {}
195927          },
195928          "pedigree": {},
195929          "externalReferences": [
195930            {
195931              "url": "git+https://github.com/jshttp/methods.git",
195932              "type": "distribution"
195933            },
195934            {
195935              "url": "https://github.com/jshttp/methods#readme",
195936              "type": "website"
195937            }
195938          ],
195939          "evidence": {},
195940          "signature": {
195941            "signature": {
195942              "publicKey": {}
195943            }
195944          },
195945          "modelCard": {
195946            "modelParameters": {
195947              "approach": {}
195948            },
195949            "quantitativeAnalysis": {
195950              "graphics": {}
195951            },
195952            "considerations": {}
195953          }
195954        },
195955        {
195956          "type": "library",
195957          "bom-ref": "pkg:npm/mime@1.6.0?package-id=e5feb4f33fab3438",
195958          "supplier": {},
195959          "author": "Robert Kieffer \u003crobert@broofa.com\u003e (http://github.com/broofa)",
195960          "name": "mime",
195961          "version": "1.6.0",
195962          "description": "A comprehensive library for mime-type mapping",
195963          "licenses": [
195964            {
195965              "license": {
195966                "id": "MIT"
195967              }
195968            }
195969          ],
195970          "cpe": "cpe:2.3:a:broofa:mime:1.6.0:*:*:*:*:*:*:*",
195971          "purl": "pkg:npm/mime@1.6.0",
195972          "swid": {
195973            "attachment": {}
195974          },
195975          "pedigree": {},
195976          "externalReferences": [
195977            {
195978              "url": "git+https://github.com/broofa/node-mime.git",
195979              "type": "distribution"
195980            },
195981            {
195982              "url": "https://github.com/broofa/node-mime#readme",
195983              "type": "website"
195984            }
195985          ],
195986          "evidence": {},
195987          "signature": {
195988            "signature": {
195989              "publicKey": {}
195990            }
195991          },
195992          "modelCard": {
195993            "modelParameters": {
195994              "approach": {}
195995            },
195996            "quantitativeAnalysis": {
195997              "graphics": {}
195998            },
195999            "considerations": {}
196000          }
196001        },
196002        {
196003          "type": "library",
196004          "bom-ref": "pkg:npm/mime-db@1.35.0?package-id=c25238efc221af78",
196005          "supplier": {},
196006          "name": "mime-db",
196007          "version": "1.35.0",
196008          "description": "Media Type Database",
196009          "licenses": [
196010            {
196011              "license": {
196012                "id": "MIT"
196013              }
196014            }
196015          ],
196016          "cpe": "cpe:2.3:a:mime-db:mime-db:1.35.0:*:*:*:*:*:*:*",
196017          "purl": "pkg:npm/mime-db@1.35.0",
196018          "swid": {
196019            "attachment": {}
196020          },
196021          "pedigree": {},
196022          "externalReferences": [
196023            {
196024              "url": "git+https://github.com/jshttp/mime-db.git",
196025              "type": "distribution"
196026            },
196027            {
196028              "url": "https://github.com/jshttp/mime-db#readme",
196029              "type": "website"
196030            }
196031          ],
196032          "evidence": {},
196033          "signature": {
196034            "signature": {
196035              "publicKey": {}
196036            }
196037          },
196038          "modelCard": {
196039            "modelParameters": {
196040              "approach": {}
196041            },
196042            "quantitativeAnalysis": {
196043              "graphics": {}
196044            },
196045            "considerations": {}
196046          }
196047        },
196048        {
196049          "type": "library",
196050          "bom-ref": "pkg:npm/mime-db@1.46.0?package-id=e7158f9d9f9f8c50",
196051          "supplier": {},
196052          "name": "mime-db",
196053          "version": "1.46.0",
196054          "description": "Media Type Database",
196055          "licenses": [
196056            {
196057              "license": {
196058                "id": "MIT"
196059              }
196060            }
196061          ],
196062          "cpe": "cpe:2.3:a:mime-db:mime-db:1.46.0:*:*:*:*:*:*:*",
196063          "purl": "pkg:npm/mime-db@1.46.0",
196064          "swid": {
196065            "attachment": {}
196066          },
196067          "pedigree": {},
196068          "externalReferences": [
196069            {
196070              "url": "git+https://github.com/jshttp/mime-db.git",
196071              "type": "distribution"
196072            },
196073            {
196074              "url": "https://github.com/jshttp/mime-db#readme",
196075              "type": "website"
196076            }
196077          ],
196078          "evidence": {},
196079          "signature": {
196080            "signature": {
196081              "publicKey": {}
196082            }
196083          },
196084          "modelCard": {
196085            "modelParameters": {
196086              "approach": {}
196087            },
196088            "quantitativeAnalysis": {
196089              "graphics": {}
196090            },
196091            "considerations": {}
196092          }
196093        },
196094        {
196095          "type": "library",
196096          "bom-ref": "pkg:npm/mime-types@2.1.19?package-id=62a25db5618d2057",
196097          "supplier": {},
196098          "name": "mime-types",
196099          "version": "2.1.19",
196100          "description": "The ultimate javascript content-type utility.",
196101          "licenses": [
196102            {
196103              "license": {
196104                "id": "MIT"
196105              }
196106            }
196107          ],
196108          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.19:*:*:*:*:*:*:*",
196109          "purl": "pkg:npm/mime-types@2.1.19",
196110          "swid": {
196111            "attachment": {}
196112          },
196113          "pedigree": {},
196114          "externalReferences": [
196115            {
196116              "url": "git+https://github.com/jshttp/mime-types.git",
196117              "type": "distribution"
196118            },
196119            {
196120              "url": "https://github.com/jshttp/mime-types#readme",
196121              "type": "website"
196122            }
196123          ],
196124          "evidence": {},
196125          "signature": {
196126            "signature": {
196127              "publicKey": {}
196128            }
196129          },
196130          "modelCard": {
196131            "modelParameters": {
196132              "approach": {}
196133            },
196134            "quantitativeAnalysis": {
196135              "graphics": {}
196136            },
196137            "considerations": {}
196138          }
196139        },
196140        {
196141          "type": "library",
196142          "bom-ref": "pkg:npm/mime-types@2.1.29?package-id=b14edb66509f19f5",
196143          "supplier": {},
196144          "name": "mime-types",
196145          "version": "2.1.29",
196146          "description": "The ultimate javascript content-type utility.",
196147          "licenses": [
196148            {
196149              "license": {
196150                "id": "MIT"
196151              }
196152            }
196153          ],
196154          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.29:*:*:*:*:*:*:*",
196155          "purl": "pkg:npm/mime-types@2.1.29",
196156          "swid": {
196157            "attachment": {}
196158          },
196159          "pedigree": {},
196160          "externalReferences": [
196161            {
196162              "url": "git+https://github.com/jshttp/mime-types.git",
196163              "type": "distribution"
196164            },
196165            {
196166              "url": "https://github.com/jshttp/mime-types#readme",
196167              "type": "website"
196168            }
196169          ],
196170          "evidence": {},
196171          "signature": {
196172            "signature": {
196173              "publicKey": {}
196174            }
196175          },
196176          "modelCard": {
196177            "modelParameters": {
196178              "approach": {}
196179            },
196180            "quantitativeAnalysis": {
196181              "graphics": {}
196182            },
196183            "considerations": {}
196184          }
196185        },
196186        {
196187          "type": "library",
196188          "bom-ref": "pkg:npm/minimatch@3.0.4?package-id=7fcd6e247b4522bb",
196189          "supplier": {},
196190          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
196191          "name": "minimatch",
196192          "version": "3.0.4",
196193          "description": "a glob matcher in javascript",
196194          "licenses": [
196195            {
196196              "license": {
196197                "id": "ISC"
196198              }
196199            }
196200          ],
196201          "cpe": "cpe:2.3:a:minimatch:minimatch:3.0.4:*:*:*:*:*:*:*",
196202          "purl": "pkg:npm/minimatch@3.0.4",
196203          "swid": {
196204            "attachment": {}
196205          },
196206          "pedigree": {},
196207          "externalReferences": [
196208            {
196209              "url": "git://github.com/isaacs/minimatch.git",
196210              "type": "distribution"
196211            },
196212            {
196213              "url": "https://github.com/isaacs/minimatch#readme",
196214              "type": "website"
196215            }
196216          ],
196217          "evidence": {},
196218          "signature": {
196219            "signature": {
196220              "publicKey": {}
196221            }
196222          },
196223          "modelCard": {
196224            "modelParameters": {
196225              "approach": {}
196226            },
196227            "quantitativeAnalysis": {
196228              "graphics": {}
196229            },
196230            "considerations": {}
196231          }
196232        },
196233        {
196234          "type": "library",
196235          "bom-ref": "pkg:npm/minimatch@3.0.4?package-id=b74a272da922258",
196236          "supplier": {},
196237          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
196238          "name": "minimatch",
196239          "version": "3.0.4",
196240          "description": "a glob matcher in javascript",
196241          "licenses": [
196242            {
196243              "license": {
196244                "id": "ISC"
196245              }
196246            }
196247          ],
196248          "cpe": "cpe:2.3:a:minimatch:minimatch:3.0.4:*:*:*:*:*:*:*",
196249          "purl": "pkg:npm/minimatch@3.0.4",
196250          "swid": {
196251            "attachment": {}
196252          },
196253          "pedigree": {},
196254          "externalReferences": [
196255            {
196256              "url": "git://github.com/isaacs/minimatch.git",
196257              "type": "distribution"
196258            },
196259            {
196260              "url": "https://github.com/isaacs/minimatch#readme",
196261              "type": "website"
196262            }
196263          ],
196264          "evidence": {},
196265          "signature": {
196266            "signature": {
196267              "publicKey": {}
196268            }
196269          },
196270          "modelCard": {
196271            "modelParameters": {
196272              "approach": {}
196273            },
196274            "quantitativeAnalysis": {
196275              "graphics": {}
196276            },
196277            "considerations": {}
196278          }
196279        },
196280        {
196281          "type": "library",
196282          "bom-ref": "pkg:npm/minimist@1.2.5?package-id=7e33f89f406fa4cd",
196283          "supplier": {},
196284          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
196285          "name": "minimist",
196286          "version": "1.2.5",
196287          "description": "parse argument options",
196288          "licenses": [
196289            {
196290              "license": {
196291                "id": "MIT"
196292              }
196293            }
196294          ],
196295          "cpe": "cpe:2.3:a:minimist:minimist:1.2.5:*:*:*:*:*:*:*",
196296          "purl": "pkg:npm/minimist@1.2.5",
196297          "swid": {
196298            "attachment": {}
196299          },
196300          "pedigree": {},
196301          "externalReferences": [
196302            {
196303              "url": "git://github.com/substack/minimist.git",
196304              "type": "distribution"
196305            },
196306            {
196307              "url": "https://github.com/substack/minimist",
196308              "type": "website"
196309            }
196310          ],
196311          "evidence": {},
196312          "signature": {
196313            "signature": {
196314              "publicKey": {}
196315            }
196316          },
196317          "modelCard": {
196318            "modelParameters": {
196319              "approach": {}
196320            },
196321            "quantitativeAnalysis": {
196322              "graphics": {}
196323            },
196324            "considerations": {}
196325          }
196326        },
196327        {
196328          "type": "library",
196329          "bom-ref": "pkg:npm/minimist@1.2.6?package-id=65c18082a40e8fdd",
196330          "supplier": {},
196331          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
196332          "name": "minimist",
196333          "version": "1.2.6",
196334          "description": "parse argument options",
196335          "licenses": [
196336            {
196337              "license": {
196338                "id": "MIT"
196339              }
196340            }
196341          ],
196342          "cpe": "cpe:2.3:a:minimist:minimist:1.2.6:*:*:*:*:*:*:*",
196343          "purl": "pkg:npm/minimist@1.2.6",
196344          "swid": {
196345            "attachment": {}
196346          },
196347          "pedigree": {},
196348          "externalReferences": [
196349            {
196350              "url": "git://github.com/substack/minimist.git",
196351              "type": "distribution"
196352            },
196353            {
196354              "url": "https://github.com/substack/minimist",
196355              "type": "website"
196356            }
196357          ],
196358          "evidence": {},
196359          "signature": {
196360            "signature": {
196361              "publicKey": {}
196362            }
196363          },
196364          "modelCard": {
196365            "modelParameters": {
196366              "approach": {}
196367            },
196368            "quantitativeAnalysis": {
196369              "graphics": {}
196370            },
196371            "considerations": {}
196372          }
196373        },
196374        {
196375          "type": "library",
196376          "bom-ref": "pkg:npm/minimist@1.2.6?package-id=402e6e7e70713122",
196377          "supplier": {},
196378          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
196379          "name": "minimist",
196380          "version": "1.2.6",
196381          "description": "parse argument options",
196382          "licenses": [
196383            {
196384              "license": {
196385                "id": "MIT"
196386              }
196387            }
196388          ],
196389          "cpe": "cpe:2.3:a:minimist:minimist:1.2.6:*:*:*:*:*:*:*",
196390          "purl": "pkg:npm/minimist@1.2.6",
196391          "swid": {
196392            "attachment": {}
196393          },
196394          "pedigree": {},
196395          "externalReferences": [
196396            {
196397              "url": "git://github.com/substack/minimist.git",
196398              "type": "distribution"
196399            },
196400            {
196401              "url": "https://github.com/substack/minimist",
196402              "type": "website"
196403            }
196404          ],
196405          "evidence": {},
196406          "signature": {
196407            "signature": {
196408              "publicKey": {}
196409            }
196410          },
196411          "modelCard": {
196412            "modelParameters": {
196413              "approach": {}
196414            },
196415            "quantitativeAnalysis": {
196416              "graphics": {}
196417            },
196418            "considerations": {}
196419          }
196420        },
196421        {
196422          "type": "library",
196423          "bom-ref": "pkg:npm/minipass@2.9.0?package-id=f2f474de24692541",
196424          "supplier": {},
196425          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
196426          "name": "minipass",
196427          "version": "2.9.0",
196428          "description": "minimal implementation of a PassThrough stream",
196429          "licenses": [
196430            {
196431              "license": {
196432                "id": "ISC"
196433              }
196434            }
196435          ],
196436          "cpe": "cpe:2.3:a:minipass:minipass:2.9.0:*:*:*:*:*:*:*",
196437          "purl": "pkg:npm/minipass@2.9.0",
196438          "swid": {
196439            "attachment": {}
196440          },
196441          "pedigree": {},
196442          "externalReferences": [
196443            {
196444              "url": "git+https://github.com/isaacs/minipass.git",
196445              "type": "distribution"
196446            },
196447            {
196448              "url": "https://github.com/isaacs/minipass#readme",
196449              "type": "website"
196450            }
196451          ],
196452          "evidence": {},
196453          "signature": {
196454            "signature": {
196455              "publicKey": {}
196456            }
196457          },
196458          "modelCard": {
196459            "modelParameters": {
196460              "approach": {}
196461            },
196462            "quantitativeAnalysis": {
196463              "graphics": {}
196464            },
196465            "considerations": {}
196466          }
196467        },
196468        {
196469          "type": "library",
196470          "bom-ref": "pkg:npm/minipass@2.9.0?package-id=5d775be3798a9729",
196471          "supplier": {},
196472          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
196473          "name": "minipass",
196474          "version": "2.9.0",
196475          "description": "minimal implementation of a PassThrough stream",
196476          "licenses": [
196477            {
196478              "license": {
196479                "id": "ISC"
196480              }
196481            }
196482          ],
196483          "cpe": "cpe:2.3:a:minipass:minipass:2.9.0:*:*:*:*:*:*:*",
196484          "purl": "pkg:npm/minipass@2.9.0",
196485          "swid": {
196486            "attachment": {}
196487          },
196488          "pedigree": {},
196489          "externalReferences": [
196490            {
196491              "url": "git+https://github.com/isaacs/minipass.git",
196492              "type": "distribution"
196493            },
196494            {
196495              "url": "https://github.com/isaacs/minipass#readme",
196496              "type": "website"
196497            }
196498          ],
196499          "evidence": {},
196500          "signature": {
196501            "signature": {
196502              "publicKey": {}
196503            }
196504          },
196505          "modelCard": {
196506            "modelParameters": {
196507              "approach": {}
196508            },
196509            "quantitativeAnalysis": {
196510              "graphics": {}
196511            },
196512            "considerations": {}
196513          }
196514        },
196515        {
196516          "type": "library",
196517          "bom-ref": "pkg:npm/minipass@2.9.0?package-id=e33a08c31794e287",
196518          "supplier": {},
196519          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
196520          "name": "minipass",
196521          "version": "2.9.0",
196522          "description": "minimal implementation of a PassThrough stream",
196523          "licenses": [
196524            {
196525              "license": {
196526                "id": "ISC"
196527              }
196528            }
196529          ],
196530          "cpe": "cpe:2.3:a:minipass:minipass:2.9.0:*:*:*:*:*:*:*",
196531          "purl": "pkg:npm/minipass@2.9.0",
196532          "swid": {
196533            "attachment": {}
196534          },
196535          "pedigree": {},
196536          "externalReferences": [
196537            {
196538              "url": "git+https://github.com/isaacs/minipass.git",
196539              "type": "distribution"
196540            },
196541            {
196542              "url": "https://github.com/isaacs/minipass#readme",
196543              "type": "website"
196544            }
196545          ],
196546          "evidence": {},
196547          "signature": {
196548            "signature": {
196549              "publicKey": {}
196550            }
196551          },
196552          "modelCard": {
196553            "modelParameters": {
196554              "approach": {}
196555            },
196556            "quantitativeAnalysis": {
196557              "graphics": {}
196558            },
196559            "considerations": {}
196560          }
196561        },
196562        {
196563          "type": "library",
196564          "bom-ref": "pkg:npm/minipass@2.9.0?package-id=535794a8ced5f304",
196565          "supplier": {},
196566          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
196567          "name": "minipass",
196568          "version": "2.9.0",
196569          "description": "minimal implementation of a PassThrough stream",
196570          "licenses": [
196571            {
196572              "license": {
196573                "id": "ISC"
196574              }
196575            }
196576          ],
196577          "cpe": "cpe:2.3:a:minipass:minipass:2.9.0:*:*:*:*:*:*:*",
196578          "purl": "pkg:npm/minipass@2.9.0",
196579          "swid": {
196580            "attachment": {}
196581          },
196582          "pedigree": {},
196583          "externalReferences": [
196584            {
196585              "url": "git+https://github.com/isaacs/minipass.git",
196586              "type": "distribution"
196587            },
196588            {
196589              "url": "https://github.com/isaacs/minipass#readme",
196590              "type": "website"
196591            }
196592          ],
196593          "evidence": {},
196594          "signature": {
196595            "signature": {
196596              "publicKey": {}
196597            }
196598          },
196599          "modelCard": {
196600            "modelParameters": {
196601              "approach": {}
196602            },
196603            "quantitativeAnalysis": {
196604              "graphics": {}
196605            },
196606            "considerations": {}
196607          }
196608        },
196609        {
196610          "type": "library",
196611          "bom-ref": "pkg:npm/minizlib@1.3.3?package-id=140f93595fa83c95",
196612          "supplier": {},
196613          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
196614          "name": "minizlib",
196615          "version": "1.3.3",
196616          "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
196617          "licenses": [
196618            {
196619              "license": {
196620                "id": "MIT"
196621              }
196622            }
196623          ],
196624          "cpe": "cpe:2.3:a:minizlib:minizlib:1.3.3:*:*:*:*:*:*:*",
196625          "purl": "pkg:npm/minizlib@1.3.3",
196626          "swid": {
196627            "attachment": {}
196628          },
196629          "pedigree": {},
196630          "externalReferences": [
196631            {
196632              "url": "git+https://github.com/isaacs/minizlib.git",
196633              "type": "distribution"
196634            },
196635            {
196636              "url": "https://github.com/isaacs/minizlib#readme",
196637              "type": "website"
196638            }
196639          ],
196640          "evidence": {},
196641          "signature": {
196642            "signature": {
196643              "publicKey": {}
196644            }
196645          },
196646          "modelCard": {
196647            "modelParameters": {
196648              "approach": {}
196649            },
196650            "quantitativeAnalysis": {
196651              "graphics": {}
196652            },
196653            "considerations": {}
196654          }
196655        },
196656        {
196657          "type": "library",
196658          "bom-ref": "pkg:npm/mississippi@3.0.0?package-id=9436d1be28573634",
196659          "supplier": {},
196660          "author": "max ogden",
196661          "name": "mississippi",
196662          "version": "3.0.0",
196663          "description": "a collection of useful streams",
196664          "licenses": [
196665            {
196666              "license": {
196667                "id": "BSD-2-Clause"
196668              }
196669            }
196670          ],
196671          "cpe": "cpe:2.3:a:mississippi:mississippi:3.0.0:*:*:*:*:*:*:*",
196672          "purl": "pkg:npm/mississippi@3.0.0",
196673          "swid": {
196674            "attachment": {}
196675          },
196676          "pedigree": {},
196677          "externalReferences": [
196678            {
196679              "url": "git+https://github.com/maxogden/mississippi.git",
196680              "type": "distribution"
196681            },
196682            {
196683              "url": "https://github.com/maxogden/mississippi#readme",
196684              "type": "website"
196685            }
196686          ],
196687          "evidence": {},
196688          "signature": {
196689            "signature": {
196690              "publicKey": {}
196691            }
196692          },
196693          "modelCard": {
196694            "modelParameters": {
196695              "approach": {}
196696            },
196697            "quantitativeAnalysis": {
196698              "graphics": {}
196699            },
196700            "considerations": {}
196701          }
196702        },
196703        {
196704          "type": "library",
196705          "bom-ref": "pkg:npm/mkdirp@0.5.5?package-id=56a07975b148c1e",
196706          "supplier": {},
196707          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
196708          "name": "mkdirp",
196709          "version": "0.5.5",
196710          "description": "Recursively mkdir, like `mkdir -p`",
196711          "licenses": [
196712            {
196713              "license": {
196714                "id": "MIT"
196715              }
196716            }
196717          ],
196718          "cpe": "cpe:2.3:a:substack:mkdirp:0.5.5:*:*:*:*:*:*:*",
196719          "purl": "pkg:npm/mkdirp@0.5.5",
196720          "swid": {
196721            "attachment": {}
196722          },
196723          "pedigree": {},
196724          "externalReferences": [
196725            {
196726              "url": "git+https://github.com/substack/node-mkdirp.git",
196727              "type": "distribution"
196728            },
196729            {
196730              "url": "https://github.com/substack/node-mkdirp#readme",
196731              "type": "website"
196732            }
196733          ],
196734          "evidence": {},
196735          "signature": {
196736            "signature": {
196737              "publicKey": {}
196738            }
196739          },
196740          "modelCard": {
196741            "modelParameters": {
196742              "approach": {}
196743            },
196744            "quantitativeAnalysis": {
196745              "graphics": {}
196746            },
196747            "considerations": {}
196748          }
196749        },
196750        {
196751          "type": "library",
196752          "bom-ref": "pkg:npm/mkdirp@0.5.5?package-id=505d896e9aff08a3",
196753          "supplier": {},
196754          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
196755          "name": "mkdirp",
196756          "version": "0.5.5",
196757          "description": "Recursively mkdir, like `mkdir -p`",
196758          "licenses": [
196759            {
196760              "license": {
196761                "id": "MIT"
196762              }
196763            }
196764          ],
196765          "cpe": "cpe:2.3:a:substack:mkdirp:0.5.5:*:*:*:*:*:*:*",
196766          "purl": "pkg:npm/mkdirp@0.5.5",
196767          "swid": {
196768            "attachment": {}
196769          },
196770          "pedigree": {},
196771          "externalReferences": [
196772            {
196773              "url": "git+https://github.com/substack/node-mkdirp.git",
196774              "type": "distribution"
196775            },
196776            {
196777              "url": "https://github.com/substack/node-mkdirp#readme",
196778              "type": "website"
196779            }
196780          ],
196781          "evidence": {},
196782          "signature": {
196783            "signature": {
196784              "publicKey": {}
196785            }
196786          },
196787          "modelCard": {
196788            "modelParameters": {
196789              "approach": {}
196790            },
196791            "quantitativeAnalysis": {
196792              "graphics": {}
196793            },
196794            "considerations": {}
196795          }
196796        },
196797        {
196798          "type": "library",
196799          "bom-ref": "pkg:npm/move-concurrently@1.0.1?package-id=bd433a898366d4cd",
196800          "supplier": {},
196801          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
196802          "name": "move-concurrently",
196803          "version": "1.0.1",
196804          "description": "Promises of moves of files or directories with rename, falling back to recursive rename/copy on EXDEV errors, with configurable concurrency and win32 junction support.",
196805          "licenses": [
196806            {
196807              "license": {
196808                "id": "ISC"
196809              }
196810            }
196811          ],
196812          "cpe": "cpe:2.3:a:move-concurrently:move-concurrently:1.0.1:*:*:*:*:*:*:*",
196813          "purl": "pkg:npm/move-concurrently@1.0.1",
196814          "swid": {
196815            "attachment": {}
196816          },
196817          "pedigree": {},
196818          "externalReferences": [
196819            {
196820              "url": "git+https://github.com/npm/move-concurrently.git",
196821              "type": "distribution"
196822            },
196823            {
196824              "url": "https://www.npmjs.com/package/move-concurrently",
196825              "type": "website"
196826            }
196827          ],
196828          "evidence": {},
196829          "signature": {
196830            "signature": {
196831              "publicKey": {}
196832            }
196833          },
196834          "modelCard": {
196835            "modelParameters": {
196836              "approach": {}
196837            },
196838            "quantitativeAnalysis": {
196839              "graphics": {}
196840            },
196841            "considerations": {}
196842          }
196843        },
196844        {
196845          "type": "library",
196846          "bom-ref": "pkg:npm/ms@2.0.0?package-id=8a90bac75ece8442",
196847          "supplier": {},
196848          "name": "ms",
196849          "version": "2.0.0",
196850          "description": "Tiny milisecond conversion utility",
196851          "licenses": [
196852            {
196853              "license": {
196854                "id": "MIT"
196855              }
196856            }
196857          ],
196858          "cpe": "cpe:2.3:a:zeit:ms:2.0.0:*:*:*:*:*:*:*",
196859          "purl": "pkg:npm/ms@2.0.0",
196860          "swid": {
196861            "attachment": {}
196862          },
196863          "pedigree": {},
196864          "externalReferences": [
196865            {
196866              "url": "git+https://github.com/zeit/ms.git",
196867              "type": "distribution"
196868            },
196869            {
196870              "url": "https://github.com/zeit/ms#readme",
196871              "type": "website"
196872            }
196873          ],
196874          "evidence": {},
196875          "signature": {
196876            "signature": {
196877              "publicKey": {}
196878            }
196879          },
196880          "modelCard": {
196881            "modelParameters": {
196882              "approach": {}
196883            },
196884            "quantitativeAnalysis": {
196885              "graphics": {}
196886            },
196887            "considerations": {}
196888          }
196889        },
196890        {
196891          "type": "library",
196892          "bom-ref": "pkg:npm/ms@2.0.0?package-id=489a012f564610ef",
196893          "supplier": {},
196894          "name": "ms",
196895          "version": "2.0.0",
196896          "description": "Tiny milisecond conversion utility",
196897          "licenses": [
196898            {
196899              "license": {
196900                "id": "MIT"
196901              }
196902            }
196903          ],
196904          "cpe": "cpe:2.3:a:zeit:ms:2.0.0:*:*:*:*:*:*:*",
196905          "purl": "pkg:npm/ms@2.0.0",
196906          "swid": {
196907            "attachment": {}
196908          },
196909          "pedigree": {},
196910          "externalReferences": [
196911            {
196912              "url": "git+https://github.com/zeit/ms.git",
196913              "type": "distribution"
196914            },
196915            {
196916              "url": "https://github.com/zeit/ms#readme",
196917              "type": "website"
196918            }
196919          ],
196920          "evidence": {},
196921          "signature": {
196922            "signature": {
196923              "publicKey": {}
196924            }
196925          },
196926          "modelCard": {
196927            "modelParameters": {
196928              "approach": {}
196929            },
196930            "quantitativeAnalysis": {
196931              "graphics": {}
196932            },
196933            "considerations": {}
196934          }
196935        },
196936        {
196937          "type": "library",
196938          "bom-ref": "pkg:npm/ms@2.1.1?package-id=8d2514ddd40cc73b",
196939          "supplier": {},
196940          "name": "ms",
196941          "version": "2.1.1",
196942          "description": "Tiny millisecond conversion utility",
196943          "licenses": [
196944            {
196945              "license": {
196946                "id": "MIT"
196947              }
196948            }
196949          ],
196950          "cpe": "cpe:2.3:a:zeit:ms:2.1.1:*:*:*:*:*:*:*",
196951          "purl": "pkg:npm/ms@2.1.1",
196952          "swid": {
196953            "attachment": {}
196954          },
196955          "pedigree": {},
196956          "externalReferences": [
196957            {
196958              "url": "git+https://github.com/zeit/ms.git",
196959              "type": "distribution"
196960            },
196961            {
196962              "url": "https://github.com/zeit/ms#readme",
196963              "type": "website"
196964            }
196965          ],
196966          "evidence": {},
196967          "signature": {
196968            "signature": {
196969              "publicKey": {}
196970            }
196971          },
196972          "modelCard": {
196973            "modelParameters": {
196974              "approach": {}
196975            },
196976            "quantitativeAnalysis": {
196977              "graphics": {}
196978            },
196979            "considerations": {}
196980          }
196981        },
196982        {
196983          "type": "library",
196984          "bom-ref": "pkg:npm/ms@2.1.1?package-id=c3b6931e886fa739",
196985          "supplier": {},
196986          "name": "ms",
196987          "version": "2.1.1",
196988          "description": "Tiny millisecond conversion utility",
196989          "licenses": [
196990            {
196991              "license": {
196992                "id": "MIT"
196993              }
196994            }
196995          ],
196996          "cpe": "cpe:2.3:a:zeit:ms:2.1.1:*:*:*:*:*:*:*",
196997          "purl": "pkg:npm/ms@2.1.1",
196998          "swid": {
196999            "attachment": {}
197000          },
197001          "pedigree": {},
197002          "externalReferences": [
197003            {
197004              "url": "git+https://github.com/zeit/ms.git",
197005              "type": "distribution"
197006            },
197007            {
197008              "url": "https://github.com/zeit/ms#readme",
197009              "type": "website"
197010            }
197011          ],
197012          "evidence": {},
197013          "signature": {
197014            "signature": {
197015              "publicKey": {}
197016            }
197017          },
197018          "modelCard": {
197019            "modelParameters": {
197020              "approach": {}
197021            },
197022            "quantitativeAnalysis": {
197023              "graphics": {}
197024            },
197025            "considerations": {}
197026          }
197027        },
197028        {
197029          "type": "library",
197030          "bom-ref": "pkg:npm/ms@2.1.2?package-id=4125489c3f9d17dc",
197031          "supplier": {},
197032          "name": "ms",
197033          "version": "2.1.2",
197034          "description": "Tiny millisecond conversion utility",
197035          "licenses": [
197036            {
197037              "license": {
197038                "id": "MIT"
197039              }
197040            }
197041          ],
197042          "cpe": "cpe:2.3:a:zeit:ms:2.1.2:*:*:*:*:*:*:*",
197043          "purl": "pkg:npm/ms@2.1.2",
197044          "swid": {
197045            "attachment": {}
197046          },
197047          "pedigree": {},
197048          "externalReferences": [
197049            {
197050              "url": "git+https://github.com/zeit/ms.git",
197051              "type": "distribution"
197052            },
197053            {
197054              "url": "https://github.com/zeit/ms#readme",
197055              "type": "website"
197056            }
197057          ],
197058          "evidence": {},
197059          "signature": {
197060            "signature": {
197061              "publicKey": {}
197062            }
197063          },
197064          "modelCard": {
197065            "modelParameters": {
197066              "approach": {}
197067            },
197068            "quantitativeAnalysis": {
197069              "graphics": {}
197070            },
197071            "considerations": {}
197072          }
197073        },
197074        {
197075          "type": "library",
197076          "bom-ref": "pkg:npm/ms@2.1.2?package-id=b8f30c8413c3d272",
197077          "supplier": {},
197078          "name": "ms",
197079          "version": "2.1.2",
197080          "description": "Tiny millisecond conversion utility",
197081          "licenses": [
197082            {
197083              "license": {
197084                "id": "MIT"
197085              }
197086            }
197087          ],
197088          "cpe": "cpe:2.3:a:zeit:ms:2.1.2:*:*:*:*:*:*:*",
197089          "purl": "pkg:npm/ms@2.1.2",
197090          "swid": {
197091            "attachment": {}
197092          },
197093          "pedigree": {},
197094          "externalReferences": [
197095            {
197096              "url": "git+https://github.com/zeit/ms.git",
197097              "type": "distribution"
197098            },
197099            {
197100              "url": "https://github.com/zeit/ms#readme",
197101              "type": "website"
197102            }
197103          ],
197104          "evidence": {},
197105          "signature": {
197106            "signature": {
197107              "publicKey": {}
197108            }
197109          },
197110          "modelCard": {
197111            "modelParameters": {
197112              "approach": {}
197113            },
197114            "quantitativeAnalysis": {
197115              "graphics": {}
197116            },
197117            "considerations": {}
197118          }
197119        },
197120        {
197121          "type": "library",
197122          "bom-ref": "pkg:npm/ms@2.1.2?package-id=4a5d80c8c2a7c2a7",
197123          "supplier": {},
197124          "name": "ms",
197125          "version": "2.1.2",
197126          "description": "Tiny millisecond conversion utility",
197127          "licenses": [
197128            {
197129              "license": {
197130                "id": "MIT"
197131              }
197132            }
197133          ],
197134          "cpe": "cpe:2.3:a:zeit:ms:2.1.2:*:*:*:*:*:*:*",
197135          "purl": "pkg:npm/ms@2.1.2",
197136          "swid": {
197137            "attachment": {}
197138          },
197139          "pedigree": {},
197140          "externalReferences": [
197141            {
197142              "url": "git+https://github.com/zeit/ms.git",
197143              "type": "distribution"
197144            },
197145            {
197146              "url": "https://github.com/zeit/ms#readme",
197147              "type": "website"
197148            }
197149          ],
197150          "evidence": {},
197151          "signature": {
197152            "signature": {
197153              "publicKey": {}
197154            }
197155          },
197156          "modelCard": {
197157            "modelParameters": {
197158              "approach": {}
197159            },
197160            "quantitativeAnalysis": {
197161              "graphics": {}
197162            },
197163            "considerations": {}
197164          }
197165        },
197166        {
197167          "type": "library",
197168          "bom-ref": "pkg:npm/multer@1.4.2?package-id=cd7acf9d44738a70",
197169          "supplier": {},
197170          "name": "multer",
197171          "version": "1.4.2",
197172          "description": "Middleware for handling `multipart/form-data`.",
197173          "licenses": [
197174            {
197175              "license": {
197176                "id": "MIT"
197177              }
197178            }
197179          ],
197180          "cpe": "cpe:2.3:a:expressjs:multer:1.4.2:*:*:*:*:*:*:*",
197181          "purl": "pkg:npm/multer@1.4.2",
197182          "swid": {
197183            "attachment": {}
197184          },
197185          "pedigree": {},
197186          "externalReferences": [
197187            {
197188              "url": "git+https://github.com/expressjs/multer.git",
197189              "type": "distribution"
197190            },
197191            {
197192              "url": "https://github.com/expressjs/multer#readme",
197193              "type": "website"
197194            }
197195          ],
197196          "evidence": {},
197197          "signature": {
197198            "signature": {
197199              "publicKey": {}
197200            }
197201          },
197202          "modelCard": {
197203            "modelParameters": {
197204              "approach": {}
197205            },
197206            "quantitativeAnalysis": {
197207              "graphics": {}
197208            },
197209            "considerations": {}
197210          }
197211        },
197212        {
197213          "type": "library",
197214          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.1\u0026package-id=d9700f02cf26e8b8",
197215          "supplier": {},
197216          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
197217          "name": "musl",
197218          "version": "1.2.3-r4",
197219          "description": "the musl c library (libc) implementation",
197220          "licenses": [
197221            {
197222              "license": {
197223                "id": "MIT"
197224              }
197225            }
197226          ],
197227          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r4:*:*:*:*:*:*:*",
197228          "purl": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.1",
197229          "swid": {
197230            "attachment": {}
197231          },
197232          "pedigree": {},
197233          "externalReferences": [
197234            {
197235              "url": "https://musl.libc.org/",
197236              "type": "distribution"
197237            }
197238          ],
197239          "evidence": {},
197240          "signature": {
197241            "signature": {
197242              "publicKey": {}
197243            }
197244          },
197245          "modelCard": {
197246            "modelParameters": {
197247              "approach": {}
197248            },
197249            "quantitativeAnalysis": {
197250              "graphics": {}
197251            },
197252            "considerations": {}
197253          }
197254        },
197255        {
197256          "type": "library",
197257          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.1\u0026package-id=f71ecf5267e6c37b",
197258          "supplier": {},
197259          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
197260          "name": "musl-utils",
197261          "version": "1.2.3-r4",
197262          "description": "the musl c library (libc) implementation",
197263          "licenses": [
197264            {
197265              "license": {
197266                "id": "MIT"
197267              }
197268            },
197269            {
197270              "license": {
197271                "name": "AND"
197272              }
197273            },
197274            {
197275              "license": {
197276                "id": "BSD-2-Clause"
197277              }
197278            },
197279            {
197280              "license": {
197281                "name": "AND"
197282              }
197283            },
197284            {
197285              "license": {
197286                "id": "GPL-2.0-or-later"
197287              }
197288            }
197289          ],
197290          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r4:*:*:*:*:*:*:*",
197291          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.1",
197292          "swid": {
197293            "attachment": {}
197294          },
197295          "pedigree": {},
197296          "externalReferences": [
197297            {
197298              "url": "https://musl.libc.org/",
197299              "type": "distribution"
197300            }
197301          ],
197302          "evidence": {},
197303          "signature": {
197304            "signature": {
197305              "publicKey": {}
197306            }
197307          },
197308          "modelCard": {
197309            "modelParameters": {
197310              "approach": {}
197311            },
197312            "quantitativeAnalysis": {
197313              "graphics": {}
197314            },
197315            "considerations": {}
197316          }
197317        },
197318        {
197319          "type": "library",
197320          "bom-ref": "pkg:npm/mute-stream@0.0.7?package-id=ab0b4d84af6e6552",
197321          "supplier": {},
197322          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
197323          "name": "mute-stream",
197324          "version": "0.0.7",
197325          "description": "Bytes go in, but they don't come out (when muted).",
197326          "licenses": [
197327            {
197328              "license": {
197329                "id": "ISC"
197330              }
197331            }
197332          ],
197333          "cpe": "cpe:2.3:a:mute-stream:mute-stream:0.0.7:*:*:*:*:*:*:*",
197334          "purl": "pkg:npm/mute-stream@0.0.7",
197335          "swid": {
197336            "attachment": {}
197337          },
197338          "pedigree": {},
197339          "externalReferences": [
197340            {
197341              "url": "git://github.com/isaacs/mute-stream.git",
197342              "type": "distribution"
197343            },
197344            {
197345              "url": "https://github.com/isaacs/mute-stream#readme",
197346              "type": "website"
197347            }
197348          ],
197349          "evidence": {},
197350          "signature": {
197351            "signature": {
197352              "publicKey": {}
197353            }
197354          },
197355          "modelCard": {
197356            "modelParameters": {
197357              "approach": {}
197358            },
197359            "quantitativeAnalysis": {
197360              "graphics": {}
197361            },
197362            "considerations": {}
197363          }
197364        },
197365        {
197366          "type": "library",
197367          "bom-ref": "pkg:npm/negotiator@0.6.2?package-id=ad18b750d9f88ada",
197368          "supplier": {},
197369          "name": "negotiator",
197370          "version": "0.6.2",
197371          "description": "HTTP content negotiation",
197372          "licenses": [
197373            {
197374              "license": {
197375                "id": "MIT"
197376              }
197377            }
197378          ],
197379          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.2:*:*:*:*:*:*:*",
197380          "purl": "pkg:npm/negotiator@0.6.2",
197381          "swid": {
197382            "attachment": {}
197383          },
197384          "pedigree": {},
197385          "externalReferences": [
197386            {
197387              "url": "git+https://github.com/jshttp/negotiator.git",
197388              "type": "distribution"
197389            },
197390            {
197391              "url": "https://github.com/jshttp/negotiator#readme",
197392              "type": "website"
197393            }
197394          ],
197395          "evidence": {},
197396          "signature": {
197397            "signature": {
197398              "publicKey": {}
197399            }
197400          },
197401          "modelCard": {
197402            "modelParameters": {
197403              "approach": {}
197404            },
197405            "quantitativeAnalysis": {
197406              "graphics": {}
197407            },
197408            "considerations": {}
197409          }
197410        },
197411        {
197412          "type": "application",
197413          "bom-ref": "pkg:generic/node@14.21.2?package-id=c10925941d01dbd1",
197414          "supplier": {},
197415          "name": "node",
197416          "version": "14.21.2",
197417          "cpe": "cpe:2.3:a:nodejs:node.js:14.21.2:*:*:*:*:*:*:*",
197418          "purl": "pkg:generic/node@14.21.2",
197419          "swid": {
197420            "attachment": {}
197421          },
197422          "pedigree": {},
197423          "evidence": {},
197424          "signature": {
197425            "signature": {
197426              "publicKey": {}
197427            }
197428          },
197429          "modelCard": {
197430            "modelParameters": {
197431              "approach": {}
197432            },
197433            "quantitativeAnalysis": {
197434              "graphics": {}
197435            },
197436            "considerations": {}
197437          }
197438        },
197439        {
197440          "type": "library",
197441          "bom-ref": "pkg:npm/node-fetch@2.6.1?package-id=ff97b9d822553e25",
197442          "supplier": {},
197443          "author": "David Frank",
197444          "name": "node-fetch",
197445          "version": "2.6.1",
197446          "description": "A light-weight module that brings window.fetch to node.js",
197447          "licenses": [
197448            {
197449              "license": {
197450                "id": "MIT"
197451              }
197452            }
197453          ],
197454          "cpe": "cpe:2.3:a:node-fetch:node-fetch:2.6.1:*:*:*:*:*:*:*",
197455          "purl": "pkg:npm/node-fetch@2.6.1",
197456          "swid": {
197457            "attachment": {}
197458          },
197459          "pedigree": {},
197460          "externalReferences": [
197461            {
197462              "url": "git+https://github.com/bitinn/node-fetch.git",
197463              "type": "distribution"
197464            },
197465            {
197466              "url": "https://github.com/bitinn/node-fetch",
197467              "type": "website"
197468            }
197469          ],
197470          "evidence": {},
197471          "signature": {
197472            "signature": {
197473              "publicKey": {}
197474            }
197475          },
197476          "modelCard": {
197477            "modelParameters": {
197478              "approach": {}
197479            },
197480            "quantitativeAnalysis": {
197481              "graphics": {}
197482            },
197483            "considerations": {}
197484          }
197485        },
197486        {
197487          "type": "library",
197488          "bom-ref": "pkg:npm/node-fetch-npm@2.0.2?package-id=adeeb0d4a244c44",
197489          "supplier": {},
197490          "author": "David Frank",
197491          "name": "node-fetch-npm",
197492          "version": "2.0.2",
197493          "description": "An npm cli-oriented fork of the excellent node-fetch",
197494          "licenses": [
197495            {
197496              "license": {
197497                "id": "MIT"
197498              }
197499            }
197500          ],
197501          "cpe": "cpe:2.3:a:node-fetch-npm:node-fetch-npm:2.0.2:*:*:*:*:*:*:*",
197502          "purl": "pkg:npm/node-fetch-npm@2.0.2",
197503          "swid": {
197504            "attachment": {}
197505          },
197506          "pedigree": {},
197507          "externalReferences": [
197508            {
197509              "url": "git+https://github.com/npm/node-fetch-npm.git",
197510              "type": "distribution"
197511            },
197512            {
197513              "url": "https://github.com/npm/node-fetch-npm",
197514              "type": "website"
197515            }
197516          ],
197517          "evidence": {},
197518          "signature": {
197519            "signature": {
197520              "publicKey": {}
197521            }
197522          },
197523          "modelCard": {
197524            "modelParameters": {
197525              "approach": {}
197526            },
197527            "quantitativeAnalysis": {
197528              "graphics": {}
197529            },
197530            "considerations": {}
197531          }
197532        },
197533        {
197534          "type": "library",
197535          "bom-ref": "pkg:npm/node-gyp@5.1.0?package-id=b9b00a18ece22cef",
197536          "supplier": {},
197537          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://tootallnate.net)",
197538          "name": "node-gyp",
197539          "version": "5.1.0",
197540          "description": "Node.js native addon build tool",
197541          "licenses": [
197542            {
197543              "license": {
197544                "id": "MIT"
197545              }
197546            }
197547          ],
197548          "cpe": "cpe:2.3:a:node-gyp:node-gyp:5.1.0:*:*:*:*:*:*:*",
197549          "purl": "pkg:npm/node-gyp@5.1.0",
197550          "swid": {
197551            "attachment": {}
197552          },
197553          "pedigree": {},
197554          "externalReferences": [
197555            {
197556              "url": "git://github.com/nodejs/node-gyp.git",
197557              "type": "distribution"
197558            },
197559            {
197560              "url": "https://github.com/nodejs/node-gyp#readme",
197561              "type": "website"
197562            }
197563          ],
197564          "evidence": {},
197565          "signature": {
197566            "signature": {
197567              "publicKey": {}
197568            }
197569          },
197570          "modelCard": {
197571            "modelParameters": {
197572              "approach": {}
197573            },
197574            "quantitativeAnalysis": {
197575              "graphics": {}
197576            },
197577            "considerations": {}
197578          }
197579        },
197580        {
197581          "type": "library",
197582          "bom-ref": "pkg:npm/nopt@4.0.3?package-id=2f83f388c5e5a214",
197583          "supplier": {},
197584          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
197585          "name": "nopt",
197586          "version": "4.0.3",
197587          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
197588          "licenses": [
197589            {
197590              "license": {
197591                "id": "ISC"
197592              }
197593            }
197594          ],
197595          "cpe": "cpe:2.3:a:nopt:nopt:4.0.3:*:*:*:*:*:*:*",
197596          "purl": "pkg:npm/nopt@4.0.3",
197597          "swid": {
197598            "attachment": {}
197599          },
197600          "pedigree": {},
197601          "externalReferences": [
197602            {
197603              "url": "git+https://github.com/npm/nopt.git",
197604              "type": "distribution"
197605            },
197606            {
197607              "url": "https://github.com/npm/nopt#readme",
197608              "type": "website"
197609            }
197610          ],
197611          "evidence": {},
197612          "signature": {
197613            "signature": {
197614              "publicKey": {}
197615            }
197616          },
197617          "modelCard": {
197618            "modelParameters": {
197619              "approach": {}
197620            },
197621            "quantitativeAnalysis": {
197622              "graphics": {}
197623            },
197624            "considerations": {}
197625          }
197626        },
197627        {
197628          "type": "library",
197629          "bom-ref": "pkg:npm/normalize-package-data@2.5.0?package-id=8439f54251b29848",
197630          "supplier": {},
197631          "author": "Meryn Stol \u003cmerynstol@gmail.com\u003e",
197632          "name": "normalize-package-data",
197633          "version": "2.5.0",
197634          "description": "Normalizes data that can be found in package.json files.",
197635          "licenses": [
197636            {
197637              "license": {
197638                "id": "BSD-2-Clause"
197639              }
197640            }
197641          ],
197642          "cpe": "cpe:2.3:a:normalize-package-data:normalize-package-data:2.5.0:*:*:*:*:*:*:*",
197643          "purl": "pkg:npm/normalize-package-data@2.5.0",
197644          "swid": {
197645            "attachment": {}
197646          },
197647          "pedigree": {},
197648          "externalReferences": [
197649            {
197650              "url": "git://github.com/npm/normalize-package-data.git",
197651              "type": "distribution"
197652            },
197653            {
197654              "url": "https://github.com/npm/normalize-package-data#readme",
197655              "type": "website"
197656            }
197657          ],
197658          "evidence": {},
197659          "signature": {
197660            "signature": {
197661              "publicKey": {}
197662            }
197663          },
197664          "modelCard": {
197665            "modelParameters": {
197666              "approach": {}
197667            },
197668            "quantitativeAnalysis": {
197669              "graphics": {}
197670            },
197671            "considerations": {}
197672          }
197673        },
197674        {
197675          "type": "library",
197676          "bom-ref": "pkg:npm/npm@6.14.17?package-id=b37c7f858fd429d1",
197677          "supplier": {},
197678          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
197679          "name": "npm",
197680          "version": "6.14.17",
197681          "description": "a package manager for JavaScript",
197682          "licenses": [
197683            {
197684              "license": {
197685                "id": "Artistic-2.0"
197686              }
197687            }
197688          ],
197689          "cpe": "cpe:2.3:a:npm:npm:6.14.17:*:*:*:*:*:*:*",
197690          "purl": "pkg:npm/npm@6.14.17",
197691          "swid": {
197692            "attachment": {}
197693          },
197694          "pedigree": {},
197695          "externalReferences": [
197696            {
197697              "url": "https://github.com/npm/cli",
197698              "type": "distribution"
197699            },
197700            {
197701              "url": "https://docs.npmjs.com/",
197702              "type": "website"
197703            }
197704          ],
197705          "evidence": {},
197706          "signature": {
197707            "signature": {
197708              "publicKey": {}
197709            }
197710          },
197711          "modelCard": {
197712            "modelParameters": {
197713              "approach": {}
197714            },
197715            "quantitativeAnalysis": {
197716              "graphics": {}
197717            },
197718            "considerations": {}
197719          }
197720        },
197721        {
197722          "type": "library",
197723          "bom-ref": "pkg:npm/npm-audit-report@1.3.3?package-id=cfbfbebf3fce8431",
197724          "supplier": {},
197725          "author": "Adam Baldwin",
197726          "name": "npm-audit-report",
197727          "version": "1.3.3",
197728          "description": "Given a response from the npm security api, render it into a variety of security reports",
197729          "licenses": [
197730            {
197731              "license": {
197732                "id": "ISC"
197733              }
197734            }
197735          ],
197736          "cpe": "cpe:2.3:a:npm-audit-report:npm-audit-report:1.3.3:*:*:*:*:*:*:*",
197737          "purl": "pkg:npm/npm-audit-report@1.3.3",
197738          "swid": {
197739            "attachment": {}
197740          },
197741          "pedigree": {},
197742          "externalReferences": [
197743            {
197744              "url": "git+https://github.com/npm/npm-audit-report.git",
197745              "type": "distribution"
197746            },
197747            {
197748              "url": "https://github.com/npm/npm-audit-report#readme",
197749              "type": "website"
197750            }
197751          ],
197752          "evidence": {},
197753          "signature": {
197754            "signature": {
197755              "publicKey": {}
197756            }
197757          },
197758          "modelCard": {
197759            "modelParameters": {
197760              "approach": {}
197761            },
197762            "quantitativeAnalysis": {
197763              "graphics": {}
197764            },
197765            "considerations": {}
197766          }
197767        },
197768        {
197769          "type": "library",
197770          "bom-ref": "pkg:npm/npm-bundled@1.1.1?package-id=9e77c8c8f13f445a",
197771          "supplier": {},
197772          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
197773          "name": "npm-bundled",
197774          "version": "1.1.1",
197775          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
197776          "licenses": [
197777            {
197778              "license": {
197779                "id": "ISC"
197780              }
197781            }
197782          ],
197783          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:1.1.1:*:*:*:*:*:*:*",
197784          "purl": "pkg:npm/npm-bundled@1.1.1",
197785          "swid": {
197786            "attachment": {}
197787          },
197788          "pedigree": {},
197789          "externalReferences": [
197790            {
197791              "url": "git+https://github.com/npm/npm-bundled.git",
197792              "type": "distribution"
197793            },
197794            {
197795              "url": "https://github.com/npm/npm-bundled#readme",
197796              "type": "website"
197797            }
197798          ],
197799          "evidence": {},
197800          "signature": {
197801            "signature": {
197802              "publicKey": {}
197803            }
197804          },
197805          "modelCard": {
197806            "modelParameters": {
197807              "approach": {}
197808            },
197809            "quantitativeAnalysis": {
197810              "graphics": {}
197811            },
197812            "considerations": {}
197813          }
197814        },
197815        {
197816          "type": "library",
197817          "bom-ref": "pkg:npm/npm-cache-filename@1.0.2?package-id=cb5b8efb67903585",
197818          "supplier": {},
197819          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
197820          "name": "npm-cache-filename",
197821          "version": "1.0.2",
197822          "description": "Given a cache folder and url, return the appropriate cache folder.",
197823          "licenses": [
197824            {
197825              "license": {
197826                "id": "ISC"
197827              }
197828            }
197829          ],
197830          "cpe": "cpe:2.3:a:npm-cache-filename:npm-cache-filename:1.0.2:*:*:*:*:*:*:*",
197831          "purl": "pkg:npm/npm-cache-filename@1.0.2",
197832          "swid": {
197833            "attachment": {}
197834          },
197835          "pedigree": {},
197836          "externalReferences": [
197837            {
197838              "url": "git://github.com/npm/npm-cache-filename.git",
197839              "type": "distribution"
197840            },
197841            {
197842              "url": "https://github.com/npm/npm-cache-filename",
197843              "type": "website"
197844            }
197845          ],
197846          "evidence": {},
197847          "signature": {
197848            "signature": {
197849              "publicKey": {}
197850            }
197851          },
197852          "modelCard": {
197853            "modelParameters": {
197854              "approach": {}
197855            },
197856            "quantitativeAnalysis": {
197857              "graphics": {}
197858            },
197859            "considerations": {}
197860          }
197861        },
197862        {
197863          "type": "library",
197864          "bom-ref": "pkg:npm/npm-cli-docs@0.1.0?package-id=8f1a0cc1a30d42f6",
197865          "supplier": {},
197866          "author": "Tanya Brassie \u003ctanyabrassie@tanyascmachine2.home\u003e",
197867          "name": "npm-cli-docs",
197868          "version": "0.1.0",
197869          "description": "npm cli docs",
197870          "licenses": [
197871            {
197872              "license": {
197873                "id": "Artistic-2.0"
197874              }
197875            }
197876          ],
197877          "cpe": "cpe:2.3:a:npm-cli-docs:npm-cli-docs:0.1.0:*:*:*:*:*:*:*",
197878          "purl": "pkg:npm/npm-cli-docs@0.1.0",
197879          "swid": {
197880            "attachment": {}
197881          },
197882          "pedigree": {},
197883          "externalReferences": [
197884            {
197885              "url": "https://github.com/npm/cli",
197886              "type": "distribution"
197887            }
197888          ],
197889          "evidence": {},
197890          "signature": {
197891            "signature": {
197892              "publicKey": {}
197893            }
197894          },
197895          "modelCard": {
197896            "modelParameters": {
197897              "approach": {}
197898            },
197899            "quantitativeAnalysis": {
197900              "graphics": {}
197901            },
197902            "considerations": {}
197903          }
197904        },
197905        {
197906          "type": "library",
197907          "bom-ref": "pkg:npm/npm-init@0.0.0?package-id=e58118b5aaeeedd7",
197908          "supplier": {},
197909          "name": "npm-init",
197910          "version": "0.0.0",
197911          "description": "an initter you init wit, innit?",
197912          "licenses": [
197913            {
197914              "license": {
197915                "name": "BSD"
197916              }
197917            }
197918          ],
197919          "cpe": "cpe:2.3:a:npm-init:npm-init:0.0.0:*:*:*:*:*:*:*",
197920          "purl": "pkg:npm/npm-init@0.0.0",
197921          "swid": {
197922            "attachment": {}
197923          },
197924          "pedigree": {},
197925          "evidence": {},
197926          "signature": {
197927            "signature": {
197928              "publicKey": {}
197929            }
197930          },
197931          "modelCard": {
197932            "modelParameters": {
197933              "approach": {}
197934            },
197935            "quantitativeAnalysis": {
197936              "graphics": {}
197937            },
197938            "considerations": {}
197939          }
197940        },
197941        {
197942          "type": "library",
197943          "bom-ref": "pkg:npm/npm-install-checks@3.0.2?package-id=cbed4ef3ca50d013",
197944          "supplier": {},
197945          "author": "Robert Kowalski \u003crok@kowalski.gd\u003e",
197946          "name": "npm-install-checks",
197947          "version": "3.0.2",
197948          "description": "checks that npm runs during the installation of a module",
197949          "licenses": [
197950            {
197951              "license": {
197952                "id": "BSD-2-Clause"
197953              }
197954            }
197955          ],
197956          "cpe": "cpe:2.3:a:npm-install-checks:npm-install-checks:3.0.2:*:*:*:*:*:*:*",
197957          "purl": "pkg:npm/npm-install-checks@3.0.2",
197958          "swid": {
197959            "attachment": {}
197960          },
197961          "pedigree": {},
197962          "externalReferences": [
197963            {
197964              "url": "git://github.com/npm/npm-install-checks.git",
197965              "type": "distribution"
197966            },
197967            {
197968              "url": "https://github.com/npm/npm-install-checks",
197969              "type": "website"
197970            }
197971          ],
197972          "evidence": {},
197973          "signature": {
197974            "signature": {
197975              "publicKey": {}
197976            }
197977          },
197978          "modelCard": {
197979            "modelParameters": {
197980              "approach": {}
197981            },
197982            "quantitativeAnalysis": {
197983              "graphics": {}
197984            },
197985            "considerations": {}
197986          }
197987        },
197988        {
197989          "type": "library",
197990          "bom-ref": "pkg:npm/npm-lifecycle@3.1.5?package-id=b6ff96c0c3bbf7d2",
197991          "supplier": {},
197992          "author": "Mike Sherov",
197993          "name": "npm-lifecycle",
197994          "version": "3.1.5",
197995          "description": "JavaScript package lifecycle hook runner",
197996          "licenses": [
197997            {
197998              "license": {
197999                "id": "Artistic-2.0"
198000              }
198001            }
198002          ],
198003          "cpe": "cpe:2.3:a:npm-lifecycle:npm-lifecycle:3.1.5:*:*:*:*:*:*:*",
198004          "purl": "pkg:npm/npm-lifecycle@3.1.5",
198005          "swid": {
198006            "attachment": {}
198007          },
198008          "pedigree": {},
198009          "externalReferences": [
198010            {
198011              "url": "git://github.com/npm/lifecycle.git",
198012              "type": "distribution"
198013            },
198014            {
198015              "url": "https://github.com/npm/lifecycle#readme",
198016              "type": "website"
198017            }
198018          ],
198019          "evidence": {},
198020          "signature": {
198021            "signature": {
198022              "publicKey": {}
198023            }
198024          },
198025          "modelCard": {
198026            "modelParameters": {
198027              "approach": {}
198028            },
198029            "quantitativeAnalysis": {
198030              "graphics": {}
198031            },
198032            "considerations": {}
198033          }
198034        },
198035        {
198036          "type": "library",
198037          "bom-ref": "pkg:npm/npm-logical-tree@1.2.1?package-id=441198ebc020e01d",
198038          "supplier": {},
198039          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
198040          "name": "npm-logical-tree",
198041          "version": "1.2.1",
198042          "description": "Calculate 'logical' trees from a package.json + package-lock",
198043          "licenses": [
198044            {
198045              "license": {
198046                "id": "ISC"
198047              }
198048            }
198049          ],
198050          "cpe": "cpe:2.3:a:npm-logical-tree:npm-logical-tree:1.2.1:*:*:*:*:*:*:*",
198051          "purl": "pkg:npm/npm-logical-tree@1.2.1",
198052          "swid": {
198053            "attachment": {}
198054          },
198055          "pedigree": {},
198056          "externalReferences": [
198057            {
198058              "url": "git+https://github.com/npm/logical-tree.git",
198059              "type": "distribution"
198060            },
198061            {
198062              "url": "https://github.com/npm/logical-tree#readme",
198063              "type": "website"
198064            }
198065          ],
198066          "evidence": {},
198067          "signature": {
198068            "signature": {
198069              "publicKey": {}
198070            }
198071          },
198072          "modelCard": {
198073            "modelParameters": {
198074              "approach": {}
198075            },
198076            "quantitativeAnalysis": {
198077              "graphics": {}
198078            },
198079            "considerations": {}
198080          }
198081        },
198082        {
198083          "type": "library",
198084          "bom-ref": "pkg:npm/npm-normalize-package-bin@1.0.1?package-id=faf8a116dafcc8d",
198085          "supplier": {},
198086          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
198087          "name": "npm-normalize-package-bin",
198088          "version": "1.0.1",
198089          "description": "Turn any flavor of allowable package.json bin into a normalized object",
198090          "licenses": [
198091            {
198092              "license": {
198093                "id": "ISC"
198094              }
198095            }
198096          ],
198097          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:1.0.1:*:*:*:*:*:*:*",
198098          "purl": "pkg:npm/npm-normalize-package-bin@1.0.1",
198099          "swid": {
198100            "attachment": {}
198101          },
198102          "pedigree": {},
198103          "externalReferences": [
198104            {
198105              "url": "git+https://github.com/npm/npm-normalize-package-bin.git",
198106              "type": "distribution"
198107            },
198108            {
198109              "url": "https://github.com/npm/npm-normalize-package-bin#readme",
198110              "type": "website"
198111            }
198112          ],
198113          "evidence": {},
198114          "signature": {
198115            "signature": {
198116              "publicKey": {}
198117            }
198118          },
198119          "modelCard": {
198120            "modelParameters": {
198121              "approach": {}
198122            },
198123            "quantitativeAnalysis": {
198124              "graphics": {}
198125            },
198126            "considerations": {}
198127          }
198128        },
198129        {
198130          "type": "library",
198131          "bom-ref": "pkg:npm/npm-package-arg@6.1.1?package-id=361cb151e33b38b8",
198132          "supplier": {},
198133          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
198134          "name": "npm-package-arg",
198135          "version": "6.1.1",
198136          "description": "Parse the things that can be arguments to `npm install`",
198137          "licenses": [
198138            {
198139              "license": {
198140                "id": "ISC"
198141              }
198142            }
198143          ],
198144          "cpe": "cpe:2.3:a:npm-package-arg:npm-package-arg:6.1.1:*:*:*:*:*:*:*",
198145          "purl": "pkg:npm/npm-package-arg@6.1.1",
198146          "swid": {
198147            "attachment": {}
198148          },
198149          "pedigree": {},
198150          "externalReferences": [
198151            {
198152              "url": "git+https://github.com/npm/npm-package-arg.git",
198153              "type": "distribution"
198154            },
198155            {
198156              "url": "https://github.com/npm/npm-package-arg",
198157              "type": "website"
198158            }
198159          ],
198160          "evidence": {},
198161          "signature": {
198162            "signature": {
198163              "publicKey": {}
198164            }
198165          },
198166          "modelCard": {
198167            "modelParameters": {
198168              "approach": {}
198169            },
198170            "quantitativeAnalysis": {
198171              "graphics": {}
198172            },
198173            "considerations": {}
198174          }
198175        },
198176        {
198177          "type": "library",
198178          "bom-ref": "pkg:npm/npm-packlist@1.4.8?package-id=45dd5db953381614",
198179          "supplier": {},
198180          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
198181          "name": "npm-packlist",
198182          "version": "1.4.8",
198183          "description": "Get a list of the files to add from a folder into an npm package",
198184          "licenses": [
198185            {
198186              "license": {
198187                "id": "ISC"
198188              }
198189            }
198190          ],
198191          "cpe": "cpe:2.3:a:npm-packlist:npm-packlist:1.4.8:*:*:*:*:*:*:*",
198192          "purl": "pkg:npm/npm-packlist@1.4.8",
198193          "swid": {
198194            "attachment": {}
198195          },
198196          "pedigree": {},
198197          "externalReferences": [
198198            {
198199              "url": "git+https://github.com/npm/npm-packlist.git",
198200              "type": "distribution"
198201            },
198202            {
198203              "url": "https://www.npmjs.com/package/npm-packlist",
198204              "type": "website"
198205            }
198206          ],
198207          "evidence": {},
198208          "signature": {
198209            "signature": {
198210              "publicKey": {}
198211            }
198212          },
198213          "modelCard": {
198214            "modelParameters": {
198215              "approach": {}
198216            },
198217            "quantitativeAnalysis": {
198218              "graphics": {}
198219            },
198220            "considerations": {}
198221          }
198222        },
198223        {
198224          "type": "library",
198225          "bom-ref": "pkg:npm/npm-pick-manifest@3.0.2?package-id=eaeea9720b4d5360",
198226          "supplier": {},
198227          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
198228          "name": "npm-pick-manifest",
198229          "version": "3.0.2",
198230          "description": "Resolves a matching manifest from a package metadata document according to standard npm semver resolution rules.",
198231          "licenses": [
198232            {
198233              "license": {
198234                "id": "ISC"
198235              }
198236            }
198237          ],
198238          "cpe": "cpe:2.3:a:npm-pick-manifest:npm-pick-manifest:3.0.2:*:*:*:*:*:*:*",
198239          "purl": "pkg:npm/npm-pick-manifest@3.0.2",
198240          "swid": {
198241            "attachment": {}
198242          },
198243          "pedigree": {},
198244          "externalReferences": [
198245            {
198246              "url": "git+https://github.com/npm/npm-pick-manifest.git",
198247              "type": "distribution"
198248            },
198249            {
198250              "url": "https://github.com/npm/npm-pick-manifest#readme",
198251              "type": "website"
198252            }
198253          ],
198254          "evidence": {},
198255          "signature": {
198256            "signature": {
198257              "publicKey": {}
198258            }
198259          },
198260          "modelCard": {
198261            "modelParameters": {
198262              "approach": {}
198263            },
198264            "quantitativeAnalysis": {
198265              "graphics": {}
198266            },
198267            "considerations": {}
198268          }
198269        },
198270        {
198271          "type": "library",
198272          "bom-ref": "pkg:npm/npm-profile@4.0.4?package-id=4d9e591b42474ecb",
198273          "supplier": {},
198274          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
198275          "name": "npm-profile",
198276          "version": "4.0.4",
198277          "description": "Library for updating an npmjs.com profile",
198278          "licenses": [
198279            {
198280              "license": {
198281                "id": "ISC"
198282              }
198283            }
198284          ],
198285          "cpe": "cpe:2.3:a:npm-profile:npm-profile:4.0.4:*:*:*:*:*:*:*",
198286          "purl": "pkg:npm/npm-profile@4.0.4",
198287          "swid": {
198288            "attachment": {}
198289          },
198290          "pedigree": {},
198291          "externalReferences": [
198292            {
198293              "url": "git+https://github.com/npm/npm-profile.git",
198294              "type": "distribution"
198295            },
198296            {
198297              "url": "https://github.com/npm/npm-profile/tree/latest/lib#readme",
198298              "type": "website"
198299            }
198300          ],
198301          "evidence": {},
198302          "signature": {
198303            "signature": {
198304              "publicKey": {}
198305            }
198306          },
198307          "modelCard": {
198308            "modelParameters": {
198309              "approach": {}
198310            },
198311            "quantitativeAnalysis": {
198312              "graphics": {}
198313            },
198314            "considerations": {}
198315          }
198316        },
198317        {
198318          "type": "library",
198319          "bom-ref": "pkg:npm/npm-registry-fetch@4.0.7?package-id=ff298f561e427135",
198320          "supplier": {},
198321          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
198322          "name": "npm-registry-fetch",
198323          "version": "4.0.7",
198324          "description": "Fetch-based http client for use with npm registry APIs",
198325          "licenses": [
198326            {
198327              "license": {
198328                "id": "ISC"
198329              }
198330            }
198331          ],
198332          "cpe": "cpe:2.3:a:npm-registry-fetch:npm-registry-fetch:4.0.7:*:*:*:*:*:*:*",
198333          "purl": "pkg:npm/npm-registry-fetch@4.0.7",
198334          "swid": {
198335            "attachment": {}
198336          },
198337          "pedigree": {},
198338          "externalReferences": [
198339            {
198340              "url": "git+https://github.com/npm/registry-fetch.git",
198341              "type": "distribution"
198342            },
198343            {
198344              "url": "https://github.com/npm/registry-fetch#readme",
198345              "type": "website"
198346            }
198347          ],
198348          "evidence": {},
198349          "signature": {
198350            "signature": {
198351              "publicKey": {}
198352            }
198353          },
198354          "modelCard": {
198355            "modelParameters": {
198356              "approach": {}
198357            },
198358            "quantitativeAnalysis": {
198359              "graphics": {}
198360            },
198361            "considerations": {}
198362          }
198363        },
198364        {
198365          "type": "library",
198366          "bom-ref": "pkg:npm/npm-run-path@2.0.2?package-id=affacdccaca7f37f",
198367          "supplier": {},
198368          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
198369          "name": "npm-run-path",
198370          "version": "2.0.2",
198371          "description": "Get your PATH prepended with locally installed binaries",
198372          "licenses": [
198373            {
198374              "license": {
198375                "id": "MIT"
198376              }
198377            }
198378          ],
198379          "cpe": "cpe:2.3:a:npm-run-path:npm-run-path:2.0.2:*:*:*:*:*:*:*",
198380          "purl": "pkg:npm/npm-run-path@2.0.2",
198381          "swid": {
198382            "attachment": {}
198383          },
198384          "pedigree": {},
198385          "externalReferences": [
198386            {
198387              "url": "git+https://github.com/sindresorhus/npm-run-path.git",
198388              "type": "distribution"
198389            },
198390            {
198391              "url": "https://github.com/sindresorhus/npm-run-path#readme",
198392              "type": "website"
198393            }
198394          ],
198395          "evidence": {},
198396          "signature": {
198397            "signature": {
198398              "publicKey": {}
198399            }
198400          },
198401          "modelCard": {
198402            "modelParameters": {
198403              "approach": {}
198404            },
198405            "quantitativeAnalysis": {
198406              "graphics": {}
198407            },
198408            "considerations": {}
198409          }
198410        },
198411        {
198412          "type": "library",
198413          "bom-ref": "pkg:npm/npm-user-validate@1.0.1?package-id=9cb265c5d2df8131",
198414          "supplier": {},
198415          "author": "Robert Kowalski \u003crok@kowalski.gd\u003e",
198416          "name": "npm-user-validate",
198417          "version": "1.0.1",
198418          "description": "User validations for npm",
198419          "licenses": [
198420            {
198421              "license": {
198422                "id": "BSD-2-Clause"
198423              }
198424            }
198425          ],
198426          "cpe": "cpe:2.3:a:npm-user-validate:npm-user-validate:1.0.1:*:*:*:*:*:*:*",
198427          "purl": "pkg:npm/npm-user-validate@1.0.1",
198428          "swid": {
198429            "attachment": {}
198430          },
198431          "pedigree": {},
198432          "externalReferences": [
198433            {
198434              "url": "git://github.com/npm/npm-user-validate.git",
198435              "type": "distribution"
198436            },
198437            {
198438              "url": "https://github.com/npm/npm-user-validate#readme",
198439              "type": "website"
198440            }
198441          ],
198442          "evidence": {},
198443          "signature": {
198444            "signature": {
198445              "publicKey": {}
198446            }
198447          },
198448          "modelCard": {
198449            "modelParameters": {
198450              "approach": {}
198451            },
198452            "quantitativeAnalysis": {
198453              "graphics": {}
198454            },
198455            "considerations": {}
198456          }
198457        },
198458        {
198459          "type": "library",
198460          "bom-ref": "pkg:npm/npmlog@4.1.2?package-id=25b4bcebeb6b5003",
198461          "supplier": {},
198462          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
198463          "name": "npmlog",
198464          "version": "4.1.2",
198465          "description": "logger for npm",
198466          "licenses": [
198467            {
198468              "license": {
198469                "id": "ISC"
198470              }
198471            }
198472          ],
198473          "cpe": "cpe:2.3:a:npmlog:npmlog:4.1.2:*:*:*:*:*:*:*",
198474          "purl": "pkg:npm/npmlog@4.1.2",
198475          "swid": {
198476            "attachment": {}
198477          },
198478          "pedigree": {},
198479          "externalReferences": [
198480            {
198481              "url": "git+https://github.com/npm/npmlog.git",
198482              "type": "distribution"
198483            },
198484            {
198485              "url": "https://github.com/npm/npmlog#readme",
198486              "type": "website"
198487            }
198488          ],
198489          "evidence": {},
198490          "signature": {
198491            "signature": {
198492              "publicKey": {}
198493            }
198494          },
198495          "modelCard": {
198496            "modelParameters": {
198497              "approach": {}
198498            },
198499            "quantitativeAnalysis": {
198500              "graphics": {}
198501            },
198502            "considerations": {}
198503          }
198504        },
198505        {
198506          "type": "library",
198507          "bom-ref": "pkg:npm/number-is-nan@1.0.1?package-id=52229f13f55aa483",
198508          "supplier": {},
198509          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
198510          "name": "number-is-nan",
198511          "version": "1.0.1",
198512          "description": "ES2015 Number.isNaN() ponyfill",
198513          "licenses": [
198514            {
198515              "license": {
198516                "id": "MIT"
198517              }
198518            }
198519          ],
198520          "cpe": "cpe:2.3:a:number-is-nan:number-is-nan:1.0.1:*:*:*:*:*:*:*",
198521          "purl": "pkg:npm/number-is-nan@1.0.1",
198522          "swid": {
198523            "attachment": {}
198524          },
198525          "pedigree": {},
198526          "externalReferences": [
198527            {
198528              "url": "git+https://github.com/sindresorhus/number-is-nan.git",
198529              "type": "distribution"
198530            },
198531            {
198532              "url": "https://github.com/sindresorhus/number-is-nan#readme",
198533              "type": "website"
198534            }
198535          ],
198536          "evidence": {},
198537          "signature": {
198538            "signature": {
198539              "publicKey": {}
198540            }
198541          },
198542          "modelCard": {
198543            "modelParameters": {
198544              "approach": {}
198545            },
198546            "quantitativeAnalysis": {
198547              "graphics": {}
198548            },
198549            "considerations": {}
198550          }
198551        },
198552        {
198553          "type": "library",
198554          "bom-ref": "pkg:npm/oauth-sign@0.9.0?package-id=ca46b51b0266a848",
198555          "supplier": {},
198556          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
198557          "name": "oauth-sign",
198558          "version": "0.9.0",
198559          "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
198560          "licenses": [
198561            {
198562              "license": {
198563                "id": "Apache-2.0"
198564              }
198565            }
198566          ],
198567          "cpe": "cpe:2.3:a:oauth-sign:oauth-sign:0.9.0:*:*:*:*:*:*:*",
198568          "purl": "pkg:npm/oauth-sign@0.9.0",
198569          "swid": {
198570            "attachment": {}
198571          },
198572          "pedigree": {},
198573          "externalReferences": [
198574            {
198575              "url": "git+https://github.com/mikeal/oauth-sign.git",
198576              "type": "distribution"
198577            },
198578            {
198579              "url": "https://github.com/mikeal/oauth-sign#readme",
198580              "type": "website"
198581            }
198582          ],
198583          "evidence": {},
198584          "signature": {
198585            "signature": {
198586              "publicKey": {}
198587            }
198588          },
198589          "modelCard": {
198590            "modelParameters": {
198591              "approach": {}
198592            },
198593            "quantitativeAnalysis": {
198594              "graphics": {}
198595            },
198596            "considerations": {}
198597          }
198598        },
198599        {
198600          "type": "library",
198601          "bom-ref": "pkg:npm/object-assign@4.1.1?package-id=ae257450c890715a",
198602          "supplier": {},
198603          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
198604          "name": "object-assign",
198605          "version": "4.1.1",
198606          "description": "ES2015 `Object.assign()` ponyfill",
198607          "licenses": [
198608            {
198609              "license": {
198610                "id": "MIT"
198611              }
198612            }
198613          ],
198614          "cpe": "cpe:2.3:a:object-assign:object-assign:4.1.1:*:*:*:*:*:*:*",
198615          "purl": "pkg:npm/object-assign@4.1.1",
198616          "swid": {
198617            "attachment": {}
198618          },
198619          "pedigree": {},
198620          "externalReferences": [
198621            {
198622              "url": "git+https://github.com/sindresorhus/object-assign.git",
198623              "type": "distribution"
198624            },
198625            {
198626              "url": "https://github.com/sindresorhus/object-assign#readme",
198627              "type": "website"
198628            }
198629          ],
198630          "evidence": {},
198631          "signature": {
198632            "signature": {
198633              "publicKey": {}
198634            }
198635          },
198636          "modelCard": {
198637            "modelParameters": {
198638              "approach": {}
198639            },
198640            "quantitativeAnalysis": {
198641              "graphics": {}
198642            },
198643            "considerations": {}
198644          }
198645        },
198646        {
198647          "type": "library",
198648          "bom-ref": "pkg:npm/object-assign@4.1.1?package-id=4352ef57ca64ac71",
198649          "supplier": {},
198650          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
198651          "name": "object-assign",
198652          "version": "4.1.1",
198653          "description": "ES2015 `Object.assign()` ponyfill",
198654          "licenses": [
198655            {
198656              "license": {
198657                "id": "MIT"
198658              }
198659            }
198660          ],
198661          "cpe": "cpe:2.3:a:object-assign:object-assign:4.1.1:*:*:*:*:*:*:*",
198662          "purl": "pkg:npm/object-assign@4.1.1",
198663          "swid": {
198664            "attachment": {}
198665          },
198666          "pedigree": {},
198667          "externalReferences": [
198668            {
198669              "url": "git+https://github.com/sindresorhus/object-assign.git",
198670              "type": "distribution"
198671            },
198672            {
198673              "url": "https://github.com/sindresorhus/object-assign#readme",
198674              "type": "website"
198675            }
198676          ],
198677          "evidence": {},
198678          "signature": {
198679            "signature": {
198680              "publicKey": {}
198681            }
198682          },
198683          "modelCard": {
198684            "modelParameters": {
198685              "approach": {}
198686            },
198687            "quantitativeAnalysis": {
198688              "graphics": {}
198689            },
198690            "considerations": {}
198691          }
198692        },
198693        {
198694          "type": "library",
198695          "bom-ref": "pkg:npm/object-hash@2.1.1?package-id=1a268c519d95fecd",
198696          "supplier": {},
198697          "author": "Scott Puleo \u003cpuleos@gmail.com\u003e",
198698          "name": "object-hash",
198699          "version": "2.1.1",
198700          "description": "Generate hashes from javascript objects in node and the browser.",
198701          "licenses": [
198702            {
198703              "license": {
198704                "id": "MIT"
198705              }
198706            }
198707          ],
198708          "cpe": "cpe:2.3:a:object-hash:object-hash:2.1.1:*:*:*:*:*:*:*",
198709          "purl": "pkg:npm/object-hash@2.1.1",
198710          "swid": {
198711            "attachment": {}
198712          },
198713          "pedigree": {},
198714          "externalReferences": [
198715            {
198716              "url": "git+https://github.com/puleos/object-hash.git",
198717              "type": "distribution"
198718            },
198719            {
198720              "url": "https://github.com/puleos/object-hash",
198721              "type": "website"
198722            }
198723          ],
198724          "evidence": {},
198725          "signature": {
198726            "signature": {
198727              "publicKey": {}
198728            }
198729          },
198730          "modelCard": {
198731            "modelParameters": {
198732              "approach": {}
198733            },
198734            "quantitativeAnalysis": {
198735              "graphics": {}
198736            },
198737            "considerations": {}
198738          }
198739        },
198740        {
198741          "type": "library",
198742          "bom-ref": "pkg:npm/object-keys@1.0.12?package-id=553c1830da4c0f15",
198743          "supplier": {},
198744          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
198745          "name": "object-keys",
198746          "version": "1.0.12",
198747          "description": "An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim",
198748          "licenses": [
198749            {
198750              "license": {
198751                "id": "MIT"
198752              }
198753            }
198754          ],
198755          "cpe": "cpe:2.3:a:object-keys:object-keys:1.0.12:*:*:*:*:*:*:*",
198756          "purl": "pkg:npm/object-keys@1.0.12",
198757          "swid": {
198758            "attachment": {}
198759          },
198760          "pedigree": {},
198761          "externalReferences": [
198762            {
198763              "url": "git://github.com/ljharb/object-keys.git",
198764              "type": "distribution"
198765            }
198766          ],
198767          "evidence": {},
198768          "signature": {
198769            "signature": {
198770              "publicKey": {}
198771            }
198772          },
198773          "modelCard": {
198774            "modelParameters": {
198775              "approach": {}
198776            },
198777            "quantitativeAnalysis": {
198778              "graphics": {}
198779            },
198780            "considerations": {}
198781          }
198782        },
198783        {
198784          "type": "library",
198785          "bom-ref": "pkg:npm/object-keys@1.1.1?package-id=319eacbf6a0ef5d",
198786          "supplier": {},
198787          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
198788          "name": "object-keys",
198789          "version": "1.1.1",
198790          "description": "An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim",
198791          "licenses": [
198792            {
198793              "license": {
198794                "id": "MIT"
198795              }
198796            }
198797          ],
198798          "cpe": "cpe:2.3:a:object-keys:object-keys:1.1.1:*:*:*:*:*:*:*",
198799          "purl": "pkg:npm/object-keys@1.1.1",
198800          "swid": {
198801            "attachment": {}
198802          },
198803          "pedigree": {},
198804          "externalReferences": [
198805            {
198806              "url": "git://github.com/ljharb/object-keys.git",
198807              "type": "distribution"
198808            },
198809            {
198810              "url": "https://github.com/ljharb/object-keys#readme",
198811              "type": "website"
198812            }
198813          ],
198814          "evidence": {},
198815          "signature": {
198816            "signature": {
198817              "publicKey": {}
198818            }
198819          },
198820          "modelCard": {
198821            "modelParameters": {
198822              "approach": {}
198823            },
198824            "quantitativeAnalysis": {
198825              "graphics": {}
198826            },
198827            "considerations": {}
198828          }
198829        },
198830        {
198831          "type": "library",
198832          "bom-ref": "pkg:npm/object.getownpropertydescriptors@2.0.3?package-id=5a48ed26122d77f7",
198833          "supplier": {},
198834          "author": "Jordan Harband",
198835          "name": "object.getownpropertydescriptors",
198836          "version": "2.0.3",
198837          "description": "ES2017 spec-compliant shim for `Object.getOwnPropertyDescriptors` that works in ES5.",
198838          "licenses": [
198839            {
198840              "license": {
198841                "id": "MIT"
198842              }
198843            }
198844          ],
198845          "cpe": "cpe:2.3:a:object.getownpropertydescriptors:object.getownpropertydescriptors:2.0.3:*:*:*:*:*:*:*",
198846          "purl": "pkg:npm/object.getownpropertydescriptors@2.0.3",
198847          "swid": {
198848            "attachment": {}
198849          },
198850          "pedigree": {},
198851          "externalReferences": [
198852            {
198853              "url": "git://github.com/ljharb/object.getownpropertydescriptors.git",
198854              "type": "distribution"
198855            },
198856            {
198857              "url": "https://github.com/ljharb/object.getownpropertydescriptors#readme",
198858              "type": "website"
198859            }
198860          ],
198861          "evidence": {},
198862          "signature": {
198863            "signature": {
198864              "publicKey": {}
198865            }
198866          },
198867          "modelCard": {
198868            "modelParameters": {
198869              "approach": {}
198870            },
198871            "quantitativeAnalysis": {
198872              "graphics": {}
198873            },
198874            "considerations": {}
198875          }
198876        },
198877        {
198878          "type": "library",
198879          "bom-ref": "pkg:npm/on-finished@2.3.0?package-id=ce866b6fa0101af5",
198880          "supplier": {},
198881          "name": "on-finished",
198882          "version": "2.3.0",
198883          "description": "Execute a callback when a request closes, finishes, or errors",
198884          "licenses": [
198885            {
198886              "license": {
198887                "id": "MIT"
198888              }
198889            }
198890          ],
198891          "cpe": "cpe:2.3:a:on-finished:on-finished:2.3.0:*:*:*:*:*:*:*",
198892          "purl": "pkg:npm/on-finished@2.3.0",
198893          "swid": {
198894            "attachment": {}
198895          },
198896          "pedigree": {},
198897          "externalReferences": [
198898            {
198899              "url": "git+https://github.com/jshttp/on-finished.git",
198900              "type": "distribution"
198901            },
198902            {
198903              "url": "https://github.com/jshttp/on-finished#readme",
198904              "type": "website"
198905            }
198906          ],
198907          "evidence": {},
198908          "signature": {
198909            "signature": {
198910              "publicKey": {}
198911            }
198912          },
198913          "modelCard": {
198914            "modelParameters": {
198915              "approach": {}
198916            },
198917            "quantitativeAnalysis": {
198918              "graphics": {}
198919            },
198920            "considerations": {}
198921          }
198922        },
198923        {
198924          "type": "library",
198925          "bom-ref": "pkg:npm/once@1.4.0?package-id=acd9aa54ac049a0e",
198926          "supplier": {},
198927          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
198928          "name": "once",
198929          "version": "1.4.0",
198930          "description": "Run a function exactly one time",
198931          "licenses": [
198932            {
198933              "license": {
198934                "id": "ISC"
198935              }
198936            }
198937          ],
198938          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
198939          "purl": "pkg:npm/once@1.4.0",
198940          "swid": {
198941            "attachment": {}
198942          },
198943          "pedigree": {},
198944          "externalReferences": [
198945            {
198946              "url": "git://github.com/isaacs/once.git",
198947              "type": "distribution"
198948            },
198949            {
198950              "url": "https://github.com/isaacs/once#readme",
198951              "type": "website"
198952            }
198953          ],
198954          "evidence": {},
198955          "signature": {
198956            "signature": {
198957              "publicKey": {}
198958            }
198959          },
198960          "modelCard": {
198961            "modelParameters": {
198962              "approach": {}
198963            },
198964            "quantitativeAnalysis": {
198965              "graphics": {}
198966            },
198967            "considerations": {}
198968          }
198969        },
198970        {
198971          "type": "library",
198972          "bom-ref": "pkg:npm/once@1.4.0?package-id=56789787f3e05aa7",
198973          "supplier": {},
198974          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
198975          "name": "once",
198976          "version": "1.4.0",
198977          "description": "Run a function exactly one time",
198978          "licenses": [
198979            {
198980              "license": {
198981                "id": "ISC"
198982              }
198983            }
198984          ],
198985          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
198986          "purl": "pkg:npm/once@1.4.0",
198987          "swid": {
198988            "attachment": {}
198989          },
198990          "pedigree": {},
198991          "externalReferences": [
198992            {
198993              "url": "git://github.com/isaacs/once.git",
198994              "type": "distribution"
198995            },
198996            {
198997              "url": "https://github.com/isaacs/once#readme",
198998              "type": "website"
198999            }
199000          ],
199001          "evidence": {},
199002          "signature": {
199003            "signature": {
199004              "publicKey": {}
199005            }
199006          },
199007          "modelCard": {
199008            "modelParameters": {
199009              "approach": {}
199010            },
199011            "quantitativeAnalysis": {
199012              "graphics": {}
199013            },
199014            "considerations": {}
199015          }
199016        },
199017        {
199018          "type": "library",
199019          "bom-ref": "pkg:npm/opener@1.5.2?package-id=7e147c5eae081fba",
199020          "supplier": {},
199021          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me/)",
199022          "name": "opener",
199023          "version": "1.5.2",
199024          "description": "Opens stuff, like webpages and files and executables, cross-platform",
199025          "licenses": [
199026            {
199027              "license": {
199028                "name": "(WTFPL OR MIT)"
199029              }
199030            }
199031          ],
199032          "cpe": "cpe:2.3:a:domenic:opener:1.5.2:*:*:*:*:*:*:*",
199033          "purl": "pkg:npm/opener@1.5.2",
199034          "swid": {
199035            "attachment": {}
199036          },
199037          "pedigree": {},
199038          "externalReferences": [
199039            {
199040              "url": "git+https://github.com/domenic/opener.git",
199041              "type": "distribution"
199042            },
199043            {
199044              "url": "https://github.com/domenic/opener#readme",
199045              "type": "website"
199046            }
199047          ],
199048          "evidence": {},
199049          "signature": {
199050            "signature": {
199051              "publicKey": {}
199052            }
199053          },
199054          "modelCard": {
199055            "modelParameters": {
199056              "approach": {}
199057            },
199058            "quantitativeAnalysis": {
199059              "graphics": {}
199060            },
199061            "considerations": {}
199062          }
199063        },
199064        {
199065          "type": "library",
199066          "bom-ref": "pkg:npm/os-homedir@1.0.2?package-id=8f5251251e0a2862",
199067          "supplier": {},
199068          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199069          "name": "os-homedir",
199070          "version": "1.0.2",
199071          "description": "Node.js 4 `os.homedir()` ponyfill",
199072          "licenses": [
199073            {
199074              "license": {
199075                "id": "MIT"
199076              }
199077            }
199078          ],
199079          "cpe": "cpe:2.3:a:sindresorhus:os-homedir:1.0.2:*:*:*:*:*:*:*",
199080          "purl": "pkg:npm/os-homedir@1.0.2",
199081          "swid": {
199082            "attachment": {}
199083          },
199084          "pedigree": {},
199085          "externalReferences": [
199086            {
199087              "url": "git+https://github.com/sindresorhus/os-homedir.git",
199088              "type": "distribution"
199089            },
199090            {
199091              "url": "https://github.com/sindresorhus/os-homedir#readme",
199092              "type": "website"
199093            }
199094          ],
199095          "evidence": {},
199096          "signature": {
199097            "signature": {
199098              "publicKey": {}
199099            }
199100          },
199101          "modelCard": {
199102            "modelParameters": {
199103              "approach": {}
199104            },
199105            "quantitativeAnalysis": {
199106              "graphics": {}
199107            },
199108            "considerations": {}
199109          }
199110        },
199111        {
199112          "type": "library",
199113          "bom-ref": "pkg:npm/os-tmpdir@1.0.2?package-id=319f8a779adc8672",
199114          "supplier": {},
199115          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199116          "name": "os-tmpdir",
199117          "version": "1.0.2",
199118          "description": "Node.js os.tmpdir() ponyfill",
199119          "licenses": [
199120            {
199121              "license": {
199122                "id": "MIT"
199123              }
199124            }
199125          ],
199126          "cpe": "cpe:2.3:a:sindresorhus:os-tmpdir:1.0.2:*:*:*:*:*:*:*",
199127          "purl": "pkg:npm/os-tmpdir@1.0.2",
199128          "swid": {
199129            "attachment": {}
199130          },
199131          "pedigree": {},
199132          "externalReferences": [
199133            {
199134              "url": "git+https://github.com/sindresorhus/os-tmpdir.git",
199135              "type": "distribution"
199136            },
199137            {
199138              "url": "https://github.com/sindresorhus/os-tmpdir#readme",
199139              "type": "website"
199140            }
199141          ],
199142          "evidence": {},
199143          "signature": {
199144            "signature": {
199145              "publicKey": {}
199146            }
199147          },
199148          "modelCard": {
199149            "modelParameters": {
199150              "approach": {}
199151            },
199152            "quantitativeAnalysis": {
199153              "graphics": {}
199154            },
199155            "considerations": {}
199156          }
199157        },
199158        {
199159          "type": "library",
199160          "bom-ref": "pkg:npm/osenv@0.1.5?package-id=299bd30a410ad76d",
199161          "supplier": {},
199162          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
199163          "name": "osenv",
199164          "version": "0.1.5",
199165          "description": "Look up environment settings specific to different operating systems",
199166          "licenses": [
199167            {
199168              "license": {
199169                "id": "ISC"
199170              }
199171            }
199172          ],
199173          "cpe": "cpe:2.3:a:osenv:osenv:0.1.5:*:*:*:*:*:*:*",
199174          "purl": "pkg:npm/osenv@0.1.5",
199175          "swid": {
199176            "attachment": {}
199177          },
199178          "pedigree": {},
199179          "externalReferences": [
199180            {
199181              "url": "git+https://github.com/npm/osenv.git",
199182              "type": "distribution"
199183            },
199184            {
199185              "url": "https://github.com/npm/osenv#readme",
199186              "type": "website"
199187            }
199188          ],
199189          "evidence": {},
199190          "signature": {
199191            "signature": {
199192              "publicKey": {}
199193            }
199194          },
199195          "modelCard": {
199196            "modelParameters": {
199197              "approach": {}
199198            },
199199            "quantitativeAnalysis": {
199200              "graphics": {}
199201            },
199202            "considerations": {}
199203          }
199204        },
199205        {
199206          "type": "library",
199207          "bom-ref": "pkg:npm/p-finally@1.0.0?package-id=da0efa231a6d3078",
199208          "supplier": {},
199209          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199210          "name": "p-finally",
199211          "version": "1.0.0",
199212          "description": "`Promise#finally()` ponyfill - Invoked when the promise is settled regardless of outcome",
199213          "licenses": [
199214            {
199215              "license": {
199216                "id": "MIT"
199217              }
199218            }
199219          ],
199220          "cpe": "cpe:2.3:a:sindresorhus:p-finally:1.0.0:*:*:*:*:*:*:*",
199221          "purl": "pkg:npm/p-finally@1.0.0",
199222          "swid": {
199223            "attachment": {}
199224          },
199225          "pedigree": {},
199226          "externalReferences": [
199227            {
199228              "url": "git+https://github.com/sindresorhus/p-finally.git",
199229              "type": "distribution"
199230            },
199231            {
199232              "url": "https://github.com/sindresorhus/p-finally#readme",
199233              "type": "website"
199234            }
199235          ],
199236          "evidence": {},
199237          "signature": {
199238            "signature": {
199239              "publicKey": {}
199240            }
199241          },
199242          "modelCard": {
199243            "modelParameters": {
199244              "approach": {}
199245            },
199246            "quantitativeAnalysis": {
199247              "graphics": {}
199248            },
199249            "considerations": {}
199250          }
199251        },
199252        {
199253          "type": "library",
199254          "bom-ref": "pkg:npm/p-finally@1.0.0?package-id=ee6201c5c1a7fb4d",
199255          "supplier": {},
199256          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199257          "name": "p-finally",
199258          "version": "1.0.0",
199259          "description": "`Promise#finally()` ponyfill - Invoked when the promise is settled regardless of outcome",
199260          "licenses": [
199261            {
199262              "license": {
199263                "id": "MIT"
199264              }
199265            }
199266          ],
199267          "cpe": "cpe:2.3:a:sindresorhus:p-finally:1.0.0:*:*:*:*:*:*:*",
199268          "purl": "pkg:npm/p-finally@1.0.0",
199269          "swid": {
199270            "attachment": {}
199271          },
199272          "pedigree": {},
199273          "externalReferences": [
199274            {
199275              "url": "git+https://github.com/sindresorhus/p-finally.git",
199276              "type": "distribution"
199277            },
199278            {
199279              "url": "https://github.com/sindresorhus/p-finally#readme",
199280              "type": "website"
199281            }
199282          ],
199283          "evidence": {},
199284          "signature": {
199285            "signature": {
199286              "publicKey": {}
199287            }
199288          },
199289          "modelCard": {
199290            "modelParameters": {
199291              "approach": {}
199292            },
199293            "quantitativeAnalysis": {
199294              "graphics": {}
199295            },
199296            "considerations": {}
199297          }
199298        },
199299        {
199300          "type": "library",
199301          "bom-ref": "pkg:npm/p-limit@2.2.0?package-id=8e8636a82737dbe8",
199302          "supplier": {},
199303          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199304          "name": "p-limit",
199305          "version": "2.2.0",
199306          "description": "Run multiple promise-returning \u0026 async functions with limited concurrency",
199307          "licenses": [
199308            {
199309              "license": {
199310                "id": "MIT"
199311              }
199312            }
199313          ],
199314          "cpe": "cpe:2.3:a:sindresorhus:p-limit:2.2.0:*:*:*:*:*:*:*",
199315          "purl": "pkg:npm/p-limit@2.2.0",
199316          "swid": {
199317            "attachment": {}
199318          },
199319          "pedigree": {},
199320          "externalReferences": [
199321            {
199322              "url": "git+https://github.com/sindresorhus/p-limit.git",
199323              "type": "distribution"
199324            },
199325            {
199326              "url": "https://github.com/sindresorhus/p-limit#readme",
199327              "type": "website"
199328            }
199329          ],
199330          "evidence": {},
199331          "signature": {
199332            "signature": {
199333              "publicKey": {}
199334            }
199335          },
199336          "modelCard": {
199337            "modelParameters": {
199338              "approach": {}
199339            },
199340            "quantitativeAnalysis": {
199341              "graphics": {}
199342            },
199343            "considerations": {}
199344          }
199345        },
199346        {
199347          "type": "library",
199348          "bom-ref": "pkg:npm/p-limit@2.3.0?package-id=55e0eb9e24d434b9",
199349          "supplier": {},
199350          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199351          "name": "p-limit",
199352          "version": "2.3.0",
199353          "description": "Run multiple promise-returning \u0026 async functions with limited concurrency",
199354          "licenses": [
199355            {
199356              "license": {
199357                "id": "MIT"
199358              }
199359            }
199360          ],
199361          "cpe": "cpe:2.3:a:sindresorhus:p-limit:2.3.0:*:*:*:*:*:*:*",
199362          "purl": "pkg:npm/p-limit@2.3.0",
199363          "swid": {
199364            "attachment": {}
199365          },
199366          "pedigree": {},
199367          "externalReferences": [
199368            {
199369              "url": "git+https://github.com/sindresorhus/p-limit.git",
199370              "type": "distribution"
199371            },
199372            {
199373              "url": "https://github.com/sindresorhus/p-limit#readme",
199374              "type": "website"
199375            }
199376          ],
199377          "evidence": {},
199378          "signature": {
199379            "signature": {
199380              "publicKey": {}
199381            }
199382          },
199383          "modelCard": {
199384            "modelParameters": {
199385              "approach": {}
199386            },
199387            "quantitativeAnalysis": {
199388              "graphics": {}
199389            },
199390            "considerations": {}
199391          }
199392        },
199393        {
199394          "type": "library",
199395          "bom-ref": "pkg:npm/p-locate@3.0.0?package-id=caacbeef8553cb8b",
199396          "supplier": {},
199397          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199398          "name": "p-locate",
199399          "version": "3.0.0",
199400          "description": "Get the first fulfilled promise that satisfies the provided testing function",
199401          "licenses": [
199402            {
199403              "license": {
199404                "id": "MIT"
199405              }
199406            }
199407          ],
199408          "cpe": "cpe:2.3:a:sindresorhus:p-locate:3.0.0:*:*:*:*:*:*:*",
199409          "purl": "pkg:npm/p-locate@3.0.0",
199410          "swid": {
199411            "attachment": {}
199412          },
199413          "pedigree": {},
199414          "externalReferences": [
199415            {
199416              "url": "git+https://github.com/sindresorhus/p-locate.git",
199417              "type": "distribution"
199418            },
199419            {
199420              "url": "https://github.com/sindresorhus/p-locate#readme",
199421              "type": "website"
199422            }
199423          ],
199424          "evidence": {},
199425          "signature": {
199426            "signature": {
199427              "publicKey": {}
199428            }
199429          },
199430          "modelCard": {
199431            "modelParameters": {
199432              "approach": {}
199433            },
199434            "quantitativeAnalysis": {
199435              "graphics": {}
199436            },
199437            "considerations": {}
199438          }
199439        },
199440        {
199441          "type": "library",
199442          "bom-ref": "pkg:npm/p-locate@3.0.0?package-id=f95bdff20b3ee519",
199443          "supplier": {},
199444          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199445          "name": "p-locate",
199446          "version": "3.0.0",
199447          "description": "Get the first fulfilled promise that satisfies the provided testing function",
199448          "licenses": [
199449            {
199450              "license": {
199451                "id": "MIT"
199452              }
199453            }
199454          ],
199455          "cpe": "cpe:2.3:a:sindresorhus:p-locate:3.0.0:*:*:*:*:*:*:*",
199456          "purl": "pkg:npm/p-locate@3.0.0",
199457          "swid": {
199458            "attachment": {}
199459          },
199460          "pedigree": {},
199461          "externalReferences": [
199462            {
199463              "url": "git+https://github.com/sindresorhus/p-locate.git",
199464              "type": "distribution"
199465            },
199466            {
199467              "url": "https://github.com/sindresorhus/p-locate#readme",
199468              "type": "website"
199469            }
199470          ],
199471          "evidence": {},
199472          "signature": {
199473            "signature": {
199474              "publicKey": {}
199475            }
199476          },
199477          "modelCard": {
199478            "modelParameters": {
199479              "approach": {}
199480            },
199481            "quantitativeAnalysis": {
199482              "graphics": {}
199483            },
199484            "considerations": {}
199485          }
199486        },
199487        {
199488          "type": "library",
199489          "bom-ref": "pkg:npm/p-timeout@3.2.0?package-id=1109246b0f2dc3d3",
199490          "supplier": {},
199491          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199492          "name": "p-timeout",
199493          "version": "3.2.0",
199494          "description": "Timeout a promise after a specified amount of time",
199495          "licenses": [
199496            {
199497              "license": {
199498                "id": "MIT"
199499              }
199500            }
199501          ],
199502          "cpe": "cpe:2.3:a:sindresorhus:p-timeout:3.2.0:*:*:*:*:*:*:*",
199503          "purl": "pkg:npm/p-timeout@3.2.0",
199504          "swid": {
199505            "attachment": {}
199506          },
199507          "pedigree": {},
199508          "externalReferences": [
199509            {
199510              "url": "git+https://github.com/sindresorhus/p-timeout.git",
199511              "type": "distribution"
199512            },
199513            {
199514              "url": "https://github.com/sindresorhus/p-timeout#readme",
199515              "type": "website"
199516            }
199517          ],
199518          "evidence": {},
199519          "signature": {
199520            "signature": {
199521              "publicKey": {}
199522            }
199523          },
199524          "modelCard": {
199525            "modelParameters": {
199526              "approach": {}
199527            },
199528            "quantitativeAnalysis": {
199529              "graphics": {}
199530            },
199531            "considerations": {}
199532          }
199533        },
199534        {
199535          "type": "library",
199536          "bom-ref": "pkg:npm/p-try@2.2.0?package-id=c42ca8af78a02fe7",
199537          "supplier": {},
199538          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199539          "name": "p-try",
199540          "version": "2.2.0",
199541          "description": "`Start a promise chain",
199542          "licenses": [
199543            {
199544              "license": {
199545                "id": "MIT"
199546              }
199547            }
199548          ],
199549          "cpe": "cpe:2.3:a:sindresorhus:p-try:2.2.0:*:*:*:*:*:*:*",
199550          "purl": "pkg:npm/p-try@2.2.0",
199551          "swid": {
199552            "attachment": {}
199553          },
199554          "pedigree": {},
199555          "externalReferences": [
199556            {
199557              "url": "git+https://github.com/sindresorhus/p-try.git",
199558              "type": "distribution"
199559            },
199560            {
199561              "url": "https://github.com/sindresorhus/p-try#readme",
199562              "type": "website"
199563            }
199564          ],
199565          "evidence": {},
199566          "signature": {
199567            "signature": {
199568              "publicKey": {}
199569            }
199570          },
199571          "modelCard": {
199572            "modelParameters": {
199573              "approach": {}
199574            },
199575            "quantitativeAnalysis": {
199576              "graphics": {}
199577            },
199578            "considerations": {}
199579          }
199580        },
199581        {
199582          "type": "library",
199583          "bom-ref": "pkg:npm/p-try@2.2.0?package-id=c6cc8bcd8e8c6777",
199584          "supplier": {},
199585          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199586          "name": "p-try",
199587          "version": "2.2.0",
199588          "description": "`Start a promise chain",
199589          "licenses": [
199590            {
199591              "license": {
199592                "id": "MIT"
199593              }
199594            }
199595          ],
199596          "cpe": "cpe:2.3:a:sindresorhus:p-try:2.2.0:*:*:*:*:*:*:*",
199597          "purl": "pkg:npm/p-try@2.2.0",
199598          "swid": {
199599            "attachment": {}
199600          },
199601          "pedigree": {},
199602          "externalReferences": [
199603            {
199604              "url": "git+https://github.com/sindresorhus/p-try.git",
199605              "type": "distribution"
199606            },
199607            {
199608              "url": "https://github.com/sindresorhus/p-try#readme",
199609              "type": "website"
199610            }
199611          ],
199612          "evidence": {},
199613          "signature": {
199614            "signature": {
199615              "publicKey": {}
199616            }
199617          },
199618          "modelCard": {
199619            "modelParameters": {
199620              "approach": {}
199621            },
199622            "quantitativeAnalysis": {
199623              "graphics": {}
199624            },
199625            "considerations": {}
199626          }
199627        },
199628        {
199629          "type": "library",
199630          "bom-ref": "pkg:npm/p-wait-for@3.2.0?package-id=46408edc8e37cf24",
199631          "supplier": {},
199632          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
199633          "name": "p-wait-for",
199634          "version": "3.2.0",
199635          "description": "Wait for a condition to be true",
199636          "licenses": [
199637            {
199638              "license": {
199639                "id": "MIT"
199640              }
199641            }
199642          ],
199643          "cpe": "cpe:2.3:a:sindresorhus:p-wait-for:3.2.0:*:*:*:*:*:*:*",
199644          "purl": "pkg:npm/p-wait-for@3.2.0",
199645          "swid": {
199646            "attachment": {}
199647          },
199648          "pedigree": {},
199649          "externalReferences": [
199650            {
199651              "url": "git+https://github.com/sindresorhus/p-wait-for.git",
199652              "type": "distribution"
199653            },
199654            {
199655              "url": "https://github.com/sindresorhus/p-wait-for#readme",
199656              "type": "website"
199657            }
199658          ],
199659          "evidence": {},
199660          "signature": {
199661            "signature": {
199662              "publicKey": {}
199663            }
199664          },
199665          "modelCard": {
199666            "modelParameters": {
199667              "approach": {}
199668            },
199669            "quantitativeAnalysis": {
199670              "graphics": {}
199671            },
199672            "considerations": {}
199673          }
199674        },
199675        {
199676          "type": "library",
199677          "bom-ref": "pkg:npm/package-json@4.0.1?package-id=4e92e688a7ce2a15",
199678          "supplier": {},
199679          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199680          "name": "package-json",
199681          "version": "4.0.1",
199682          "description": "Get metadata of a package from the npm registry",
199683          "licenses": [
199684            {
199685              "license": {
199686                "id": "MIT"
199687              }
199688            }
199689          ],
199690          "cpe": "cpe:2.3:a:package-json:package-json:4.0.1:*:*:*:*:*:*:*",
199691          "purl": "pkg:npm/package-json@4.0.1",
199692          "swid": {
199693            "attachment": {}
199694          },
199695          "pedigree": {},
199696          "externalReferences": [
199697            {
199698              "url": "git+https://github.com/sindresorhus/package-json.git",
199699              "type": "distribution"
199700            },
199701            {
199702              "url": "https://github.com/sindresorhus/package-json#readme",
199703              "type": "website"
199704            }
199705          ],
199706          "evidence": {},
199707          "signature": {
199708            "signature": {
199709              "publicKey": {}
199710            }
199711          },
199712          "modelCard": {
199713            "modelParameters": {
199714              "approach": {}
199715            },
199716            "quantitativeAnalysis": {
199717              "graphics": {}
199718            },
199719            "considerations": {}
199720          }
199721        },
199722        {
199723          "type": "library",
199724          "bom-ref": "pkg:npm/pacote@9.5.12?package-id=140141515a255620",
199725          "supplier": {},
199726          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
199727          "name": "pacote",
199728          "version": "9.5.12",
199729          "description": "JavaScript package downloader",
199730          "licenses": [
199731            {
199732              "license": {
199733                "id": "MIT"
199734              }
199735            }
199736          ],
199737          "cpe": "cpe:2.3:a:pacote:pacote:9.5.12:*:*:*:*:*:*:*",
199738          "purl": "pkg:npm/pacote@9.5.12",
199739          "swid": {
199740            "attachment": {}
199741          },
199742          "pedigree": {},
199743          "externalReferences": [
199744            {
199745              "url": "git+https://github.com/npm/pacote.git",
199746              "type": "distribution"
199747            },
199748            {
199749              "url": "https://github.com/npm/pacote#readme",
199750              "type": "website"
199751            }
199752          ],
199753          "evidence": {},
199754          "signature": {
199755            "signature": {
199756              "publicKey": {}
199757            }
199758          },
199759          "modelCard": {
199760            "modelParameters": {
199761              "approach": {}
199762            },
199763            "quantitativeAnalysis": {
199764              "graphics": {}
199765            },
199766            "considerations": {}
199767          }
199768        },
199769        {
199770          "type": "library",
199771          "bom-ref": "pkg:npm/parallel-transform@1.1.0?package-id=62f72bf19fb9ed91",
199772          "supplier": {},
199773          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
199774          "name": "parallel-transform",
199775          "version": "1.1.0",
199776          "description": "Transform stream that allows you to run your transforms in parallel without changing the order",
199777          "licenses": [
199778            {
199779              "license": {
199780                "id": "MIT"
199781              }
199782            }
199783          ],
199784          "cpe": "cpe:2.3:a:parallel-transform:parallel-transform:1.1.0:*:*:*:*:*:*:*",
199785          "purl": "pkg:npm/parallel-transform@1.1.0",
199786          "swid": {
199787            "attachment": {}
199788          },
199789          "pedigree": {},
199790          "externalReferences": [
199791            {
199792              "url": "git://github.com/mafintosh/parallel-transform.git",
199793              "type": "distribution"
199794            },
199795            {
199796              "url": "https://github.com/mafintosh/parallel-transform#readme",
199797              "type": "website"
199798            }
199799          ],
199800          "evidence": {},
199801          "signature": {
199802            "signature": {
199803              "publicKey": {}
199804            }
199805          },
199806          "modelCard": {
199807            "modelParameters": {
199808              "approach": {}
199809            },
199810            "quantitativeAnalysis": {
199811              "graphics": {}
199812            },
199813            "considerations": {}
199814          }
199815        },
199816        {
199817          "type": "library",
199818          "bom-ref": "pkg:npm/parseurl@1.3.3?package-id=a522a78fd0867f72",
199819          "supplier": {},
199820          "name": "parseurl",
199821          "version": "1.3.3",
199822          "description": "parse a url with memoization",
199823          "licenses": [
199824            {
199825              "license": {
199826                "id": "MIT"
199827              }
199828            }
199829          ],
199830          "cpe": "cpe:2.3:a:parseurl:parseurl:1.3.3:*:*:*:*:*:*:*",
199831          "purl": "pkg:npm/parseurl@1.3.3",
199832          "swid": {
199833            "attachment": {}
199834          },
199835          "pedigree": {},
199836          "externalReferences": [
199837            {
199838              "url": "git+https://github.com/pillarjs/parseurl.git",
199839              "type": "distribution"
199840            },
199841            {
199842              "url": "https://github.com/pillarjs/parseurl#readme",
199843              "type": "website"
199844            }
199845          ],
199846          "evidence": {},
199847          "signature": {
199848            "signature": {
199849              "publicKey": {}
199850            }
199851          },
199852          "modelCard": {
199853            "modelParameters": {
199854              "approach": {}
199855            },
199856            "quantitativeAnalysis": {
199857              "graphics": {}
199858            },
199859            "considerations": {}
199860          }
199861        },
199862        {
199863          "type": "library",
199864          "bom-ref": "pkg:npm/path-exists@3.0.0?package-id=e62b33d309c41526",
199865          "supplier": {},
199866          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199867          "name": "path-exists",
199868          "version": "3.0.0",
199869          "description": "Check if a path exists",
199870          "licenses": [
199871            {
199872              "license": {
199873                "id": "MIT"
199874              }
199875            }
199876          ],
199877          "cpe": "cpe:2.3:a:sindresorhus:path-exists:3.0.0:*:*:*:*:*:*:*",
199878          "purl": "pkg:npm/path-exists@3.0.0",
199879          "swid": {
199880            "attachment": {}
199881          },
199882          "pedigree": {},
199883          "externalReferences": [
199884            {
199885              "url": "git+https://github.com/sindresorhus/path-exists.git",
199886              "type": "distribution"
199887            },
199888            {
199889              "url": "https://github.com/sindresorhus/path-exists#readme",
199890              "type": "website"
199891            }
199892          ],
199893          "evidence": {},
199894          "signature": {
199895            "signature": {
199896              "publicKey": {}
199897            }
199898          },
199899          "modelCard": {
199900            "modelParameters": {
199901              "approach": {}
199902            },
199903            "quantitativeAnalysis": {
199904              "graphics": {}
199905            },
199906            "considerations": {}
199907          }
199908        },
199909        {
199910          "type": "library",
199911          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=b30d6bddac8e825a",
199912          "supplier": {},
199913          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199914          "name": "path-is-absolute",
199915          "version": "1.0.1",
199916          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
199917          "licenses": [
199918            {
199919              "license": {
199920                "id": "MIT"
199921              }
199922            }
199923          ],
199924          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
199925          "purl": "pkg:npm/path-is-absolute@1.0.1",
199926          "swid": {
199927            "attachment": {}
199928          },
199929          "pedigree": {},
199930          "externalReferences": [
199931            {
199932              "url": "git+https://github.com/sindresorhus/path-is-absolute.git",
199933              "type": "distribution"
199934            },
199935            {
199936              "url": "https://github.com/sindresorhus/path-is-absolute#readme",
199937              "type": "website"
199938            }
199939          ],
199940          "evidence": {},
199941          "signature": {
199942            "signature": {
199943              "publicKey": {}
199944            }
199945          },
199946          "modelCard": {
199947            "modelParameters": {
199948              "approach": {}
199949            },
199950            "quantitativeAnalysis": {
199951              "graphics": {}
199952            },
199953            "considerations": {}
199954          }
199955        },
199956        {
199957          "type": "library",
199958          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=89d0f4a70e07b9bf",
199959          "supplier": {},
199960          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
199961          "name": "path-is-absolute",
199962          "version": "1.0.1",
199963          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
199964          "licenses": [
199965            {
199966              "license": {
199967                "id": "MIT"
199968              }
199969            }
199970          ],
199971          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
199972          "purl": "pkg:npm/path-is-absolute@1.0.1",
199973          "swid": {
199974            "attachment": {}
199975          },
199976          "pedigree": {},
199977          "externalReferences": [
199978            {
199979              "url": "git+https://github.com/sindresorhus/path-is-absolute.git",
199980              "type": "distribution"
199981            },
199982            {
199983              "url": "https://github.com/sindresorhus/path-is-absolute#readme",
199984              "type": "website"
199985            }
199986          ],
199987          "evidence": {},
199988          "signature": {
199989            "signature": {
199990              "publicKey": {}
199991            }
199992          },
199993          "modelCard": {
199994            "modelParameters": {
199995              "approach": {}
199996            },
199997            "quantitativeAnalysis": {
199998              "graphics": {}
199999            },
200000            "considerations": {}
200001          }
200002        },
200003        {
200004          "type": "library",
200005          "bom-ref": "pkg:npm/path-is-inside@1.0.2?package-id=9b511c0f5818d466",
200006          "supplier": {},
200007          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me)",
200008          "name": "path-is-inside",
200009          "version": "1.0.2",
200010          "description": "Tests whether one path is inside another path",
200011          "licenses": [
200012            {
200013              "license": {
200014                "name": "(WTFPL OR MIT)"
200015              }
200016            }
200017          ],
200018          "cpe": "cpe:2.3:a:path-is-inside:path-is-inside:1.0.2:*:*:*:*:*:*:*",
200019          "purl": "pkg:npm/path-is-inside@1.0.2",
200020          "swid": {
200021            "attachment": {}
200022          },
200023          "pedigree": {},
200024          "externalReferences": [
200025            {
200026              "url": "git+https://github.com/domenic/path-is-inside.git",
200027              "type": "distribution"
200028            },
200029            {
200030              "url": "https://github.com/domenic/path-is-inside#readme",
200031              "type": "website"
200032            }
200033          ],
200034          "evidence": {},
200035          "signature": {
200036            "signature": {
200037              "publicKey": {}
200038            }
200039          },
200040          "modelCard": {
200041            "modelParameters": {
200042              "approach": {}
200043            },
200044            "quantitativeAnalysis": {
200045              "graphics": {}
200046            },
200047            "considerations": {}
200048          }
200049        },
200050        {
200051          "type": "library",
200052          "bom-ref": "pkg:npm/path-key@2.0.1?package-id=2de86124def740fb",
200053          "supplier": {},
200054          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
200055          "name": "path-key",
200056          "version": "2.0.1",
200057          "description": "Get the PATH environment variable key cross-platform",
200058          "licenses": [
200059            {
200060              "license": {
200061                "id": "MIT"
200062              }
200063            }
200064          ],
200065          "cpe": "cpe:2.3:a:sindresorhus:path-key:2.0.1:*:*:*:*:*:*:*",
200066          "purl": "pkg:npm/path-key@2.0.1",
200067          "swid": {
200068            "attachment": {}
200069          },
200070          "pedigree": {},
200071          "externalReferences": [
200072            {
200073              "url": "git+https://github.com/sindresorhus/path-key.git",
200074              "type": "distribution"
200075            },
200076            {
200077              "url": "https://github.com/sindresorhus/path-key#readme",
200078              "type": "website"
200079            }
200080          ],
200081          "evidence": {},
200082          "signature": {
200083            "signature": {
200084              "publicKey": {}
200085            }
200086          },
200087          "modelCard": {
200088            "modelParameters": {
200089              "approach": {}
200090            },
200091            "quantitativeAnalysis": {
200092              "graphics": {}
200093            },
200094            "considerations": {}
200095          }
200096        },
200097        {
200098          "type": "library",
200099          "bom-ref": "pkg:npm/path-parse@1.0.7?package-id=8726bfd9ba83e33b",
200100          "supplier": {},
200101          "author": "Javier Blanco \u003chttp://jbgutierrez.info\u003e",
200102          "name": "path-parse",
200103          "version": "1.0.7",
200104          "description": "Node.js path.parse() ponyfill",
200105          "licenses": [
200106            {
200107              "license": {
200108                "id": "MIT"
200109              }
200110            }
200111          ],
200112          "cpe": "cpe:2.3:a:jbgutierrez:path-parse:1.0.7:*:*:*:*:*:*:*",
200113          "purl": "pkg:npm/path-parse@1.0.7",
200114          "swid": {
200115            "attachment": {}
200116          },
200117          "pedigree": {},
200118          "externalReferences": [
200119            {
200120              "url": "git+https://github.com/jbgutierrez/path-parse.git",
200121              "type": "distribution"
200122            },
200123            {
200124              "url": "https://github.com/jbgutierrez/path-parse#readme",
200125              "type": "website"
200126            }
200127          ],
200128          "evidence": {},
200129          "signature": {
200130            "signature": {
200131              "publicKey": {}
200132            }
200133          },
200134          "modelCard": {
200135            "modelParameters": {
200136              "approach": {}
200137            },
200138            "quantitativeAnalysis": {
200139              "graphics": {}
200140            },
200141            "considerations": {}
200142          }
200143        },
200144        {
200145          "type": "library",
200146          "bom-ref": "pkg:npm/path-to-regexp@0.1.7?package-id=c5bea2fa2a46ed82",
200147          "supplier": {},
200148          "name": "path-to-regexp",
200149          "version": "0.1.7",
200150          "description": "Express style path to RegExp utility",
200151          "licenses": [
200152            {
200153              "license": {
200154                "id": "MIT"
200155              }
200156            }
200157          ],
200158          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:0.1.7:*:*:*:*:*:*:*",
200159          "purl": "pkg:npm/path-to-regexp@0.1.7",
200160          "swid": {
200161            "attachment": {}
200162          },
200163          "pedigree": {},
200164          "externalReferences": [
200165            {
200166              "url": "git+https://github.com/component/path-to-regexp.git",
200167              "type": "distribution"
200168            },
200169            {
200170              "url": "https://github.com/component/path-to-regexp#readme",
200171              "type": "website"
200172            }
200173          ],
200174          "evidence": {},
200175          "signature": {
200176            "signature": {
200177              "publicKey": {}
200178            }
200179          },
200180          "modelCard": {
200181            "modelParameters": {
200182              "approach": {}
200183            },
200184            "quantitativeAnalysis": {
200185              "graphics": {}
200186            },
200187            "considerations": {}
200188          }
200189        },
200190        {
200191          "type": "library",
200192          "bom-ref": "pkg:npm/path-to-regexp@3.2.0?package-id=89f78191777fd1c7",
200193          "supplier": {},
200194          "name": "path-to-regexp",
200195          "version": "3.2.0",
200196          "description": "Express style path to RegExp utility",
200197          "licenses": [
200198            {
200199              "license": {
200200                "id": "MIT"
200201              }
200202            }
200203          ],
200204          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:3.2.0:*:*:*:*:*:*:*",
200205          "purl": "pkg:npm/path-to-regexp@3.2.0",
200206          "swid": {
200207            "attachment": {}
200208          },
200209          "pedigree": {},
200210          "externalReferences": [
200211            {
200212              "url": "git+https://github.com/pillarjs/path-to-regexp.git",
200213              "type": "distribution"
200214            },
200215            {
200216              "url": "https://github.com/pillarjs/path-to-regexp#readme",
200217              "type": "website"
200218            }
200219          ],
200220          "evidence": {},
200221          "signature": {
200222            "signature": {
200223              "publicKey": {}
200224            }
200225          },
200226          "modelCard": {
200227            "modelParameters": {
200228              "approach": {}
200229            },
200230            "quantitativeAnalysis": {
200231              "graphics": {}
200232            },
200233            "considerations": {}
200234          }
200235        },
200236        {
200237          "type": "library",
200238          "bom-ref": "pkg:npm/performance-now@2.1.0?package-id=111ced796010edab",
200239          "supplier": {},
200240          "author": "Braveg1rl \u003cbraveg1rl@outlook.com\u003e",
200241          "name": "performance-now",
200242          "version": "2.1.0",
200243          "description": "Implements performance.now (based on process.hrtime).",
200244          "licenses": [
200245            {
200246              "license": {
200247                "id": "MIT"
200248              }
200249            }
200250          ],
200251          "cpe": "cpe:2.3:a:performance-now:performance-now:2.1.0:*:*:*:*:*:*:*",
200252          "purl": "pkg:npm/performance-now@2.1.0",
200253          "swid": {
200254            "attachment": {}
200255          },
200256          "pedigree": {},
200257          "externalReferences": [
200258            {
200259              "url": "git://github.com/braveg1rl/performance-now.git",
200260              "type": "distribution"
200261            },
200262            {
200263              "url": "https://github.com/braveg1rl/performance-now",
200264              "type": "website"
200265            }
200266          ],
200267          "evidence": {},
200268          "signature": {
200269            "signature": {
200270              "publicKey": {}
200271            }
200272          },
200273          "modelCard": {
200274            "modelParameters": {
200275              "approach": {}
200276            },
200277            "quantitativeAnalysis": {
200278              "graphics": {}
200279            },
200280            "considerations": {}
200281          }
200282        },
200283        {
200284          "type": "library",
200285          "bom-ref": "pkg:npm/pify@3.0.0?package-id=fbdbb56dc0a20970",
200286          "supplier": {},
200287          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
200288          "name": "pify",
200289          "version": "3.0.0",
200290          "description": "Promisify a callback-style function",
200291          "licenses": [
200292            {
200293              "license": {
200294                "id": "MIT"
200295              }
200296            }
200297          ],
200298          "cpe": "cpe:2.3:a:sindresorhus:pify:3.0.0:*:*:*:*:*:*:*",
200299          "purl": "pkg:npm/pify@3.0.0",
200300          "swid": {
200301            "attachment": {}
200302          },
200303          "pedigree": {},
200304          "externalReferences": [
200305            {
200306              "url": "git+https://github.com/sindresorhus/pify.git",
200307              "type": "distribution"
200308            },
200309            {
200310              "url": "https://github.com/sindresorhus/pify#readme",
200311              "type": "website"
200312            }
200313          ],
200314          "evidence": {},
200315          "signature": {
200316            "signature": {
200317              "publicKey": {}
200318            }
200319          },
200320          "modelCard": {
200321            "modelParameters": {
200322              "approach": {}
200323            },
200324            "quantitativeAnalysis": {
200325              "graphics": {}
200326            },
200327            "considerations": {}
200328          }
200329        },
200330        {
200331          "type": "library",
200332          "bom-ref": "pkg:npm/pliant-compiler@0.0.1?package-id=4b3f7cb0cf33f6d",
200333          "supplier": {},
200334          "name": "pliant-compiler",
200335          "version": "0.0.1",
200336          "licenses": [
200337            {
200338              "license": {
200339                "name": "UNLICENSED"
200340              }
200341            }
200342          ],
200343          "cpe": "cpe:2.3:a:pliant-compiler:pliant-compiler:0.0.1:*:*:*:*:*:*:*",
200344          "purl": "pkg:npm/pliant-compiler@0.0.1",
200345          "swid": {
200346            "attachment": {}
200347          },
200348          "pedigree": {},
200349          "evidence": {},
200350          "signature": {
200351            "signature": {
200352              "publicKey": {}
200353            }
200354          },
200355          "modelCard": {
200356            "modelParameters": {
200357              "approach": {}
200358            },
200359            "quantitativeAnalysis": {
200360              "graphics": {}
200361            },
200362            "considerations": {}
200363          }
200364        },
200365        {
200366          "type": "library",
200367          "bom-ref": "pkg:npm/prepend-http@1.0.4?package-id=5a1dd47457f85ce5",
200368          "supplier": {},
200369          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
200370          "name": "prepend-http",
200371          "version": "1.0.4",
200372          "description": "Prepend `http://` to humanized URLs like todomvc.com and localhost",
200373          "licenses": [
200374            {
200375              "license": {
200376                "id": "MIT"
200377              }
200378            }
200379          ],
200380          "cpe": "cpe:2.3:a:prepend-http:prepend-http:1.0.4:*:*:*:*:*:*:*",
200381          "purl": "pkg:npm/prepend-http@1.0.4",
200382          "swid": {
200383            "attachment": {}
200384          },
200385          "pedigree": {},
200386          "externalReferences": [
200387            {
200388              "url": "git+https://github.com/sindresorhus/prepend-http.git",
200389              "type": "distribution"
200390            },
200391            {
200392              "url": "https://github.com/sindresorhus/prepend-http#readme",
200393              "type": "website"
200394            }
200395          ],
200396          "evidence": {},
200397          "signature": {
200398            "signature": {
200399              "publicKey": {}
200400            }
200401          },
200402          "modelCard": {
200403            "modelParameters": {
200404              "approach": {}
200405            },
200406            "quantitativeAnalysis": {
200407              "graphics": {}
200408            },
200409            "considerations": {}
200410          }
200411        },
200412        {
200413          "type": "library",
200414          "bom-ref": "pkg:npm/process-nextick-args@2.0.0?package-id=8bbb7c6bdbbf3e62",
200415          "supplier": {},
200416          "name": "process-nextick-args",
200417          "version": "2.0.0",
200418          "description": "process.nextTick but always with args",
200419          "licenses": [
200420            {
200421              "license": {
200422                "id": "MIT"
200423              }
200424            }
200425          ],
200426          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.0:*:*:*:*:*:*:*",
200427          "purl": "pkg:npm/process-nextick-args@2.0.0",
200428          "swid": {
200429            "attachment": {}
200430          },
200431          "pedigree": {},
200432          "externalReferences": [
200433            {
200434              "url": "git+https://github.com/calvinmetcalf/process-nextick-args.git",
200435              "type": "distribution"
200436            },
200437            {
200438              "url": "https://github.com/calvinmetcalf/process-nextick-args",
200439              "type": "website"
200440            }
200441          ],
200442          "evidence": {},
200443          "signature": {
200444            "signature": {
200445              "publicKey": {}
200446            }
200447          },
200448          "modelCard": {
200449            "modelParameters": {
200450              "approach": {}
200451            },
200452            "quantitativeAnalysis": {
200453              "graphics": {}
200454            },
200455            "considerations": {}
200456          }
200457        },
200458        {
200459          "type": "library",
200460          "bom-ref": "pkg:npm/process-nextick-args@2.0.1?package-id=19dd49024e39231",
200461          "supplier": {},
200462          "name": "process-nextick-args",
200463          "version": "2.0.1",
200464          "description": "process.nextTick but always with args",
200465          "licenses": [
200466            {
200467              "license": {
200468                "id": "MIT"
200469              }
200470            }
200471          ],
200472          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.1:*:*:*:*:*:*:*",
200473          "purl": "pkg:npm/process-nextick-args@2.0.1",
200474          "swid": {
200475            "attachment": {}
200476          },
200477          "pedigree": {},
200478          "externalReferences": [
200479            {
200480              "url": "git+https://github.com/calvinmetcalf/process-nextick-args.git",
200481              "type": "distribution"
200482            },
200483            {
200484              "url": "https://github.com/calvinmetcalf/process-nextick-args",
200485              "type": "website"
200486            }
200487          ],
200488          "evidence": {},
200489          "signature": {
200490            "signature": {
200491              "publicKey": {}
200492            }
200493          },
200494          "modelCard": {
200495            "modelParameters": {
200496              "approach": {}
200497            },
200498            "quantitativeAnalysis": {
200499              "graphics": {}
200500            },
200501            "considerations": {}
200502          }
200503        },
200504        {
200505          "type": "library",
200506          "bom-ref": "pkg:npm/promise-inflight@1.0.1?package-id=8ae6caef1e6290fe",
200507          "supplier": {},
200508          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
200509          "name": "promise-inflight",
200510          "version": "1.0.1",
200511          "description": "One promise for multiple requests in flight to avoid async duplication",
200512          "licenses": [
200513            {
200514              "license": {
200515                "id": "ISC"
200516              }
200517            }
200518          ],
200519          "cpe": "cpe:2.3:a:promise-inflight:promise-inflight:1.0.1:*:*:*:*:*:*:*",
200520          "purl": "pkg:npm/promise-inflight@1.0.1",
200521          "swid": {
200522            "attachment": {}
200523          },
200524          "pedigree": {},
200525          "externalReferences": [
200526            {
200527              "url": "git+https://github.com/iarna/promise-inflight.git",
200528              "type": "distribution"
200529            },
200530            {
200531              "url": "https://github.com/iarna/promise-inflight#readme",
200532              "type": "website"
200533            }
200534          ],
200535          "evidence": {},
200536          "signature": {
200537            "signature": {
200538              "publicKey": {}
200539            }
200540          },
200541          "modelCard": {
200542            "modelParameters": {
200543              "approach": {}
200544            },
200545            "quantitativeAnalysis": {
200546              "graphics": {}
200547            },
200548            "considerations": {}
200549          }
200550        },
200551        {
200552          "type": "library",
200553          "bom-ref": "pkg:npm/promise-retry@1.1.1?package-id=4d71993cfae70c18",
200554          "supplier": {},
200555          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
200556          "name": "promise-retry",
200557          "version": "1.1.1",
200558          "description": "Retries a function that returns a promise, leveraging the power of the retry module.",
200559          "licenses": [
200560            {
200561              "license": {
200562                "id": "MIT"
200563              }
200564            }
200565          ],
200566          "cpe": "cpe:2.3:a:promise-retry:promise-retry:1.1.1:*:*:*:*:*:*:*",
200567          "purl": "pkg:npm/promise-retry@1.1.1",
200568          "swid": {
200569            "attachment": {}
200570          },
200571          "pedigree": {},
200572          "externalReferences": [
200573            {
200574              "url": "git://github.com/IndigoUnited/node-promise-retry.git",
200575              "type": "distribution"
200576            },
200577            {
200578              "url": "https://github.com/IndigoUnited/node-promise-retry#readme",
200579              "type": "website"
200580            }
200581          ],
200582          "evidence": {},
200583          "signature": {
200584            "signature": {
200585              "publicKey": {}
200586            }
200587          },
200588          "modelCard": {
200589            "modelParameters": {
200590              "approach": {}
200591            },
200592            "quantitativeAnalysis": {
200593              "graphics": {}
200594            },
200595            "considerations": {}
200596          }
200597        },
200598        {
200599          "type": "library",
200600          "bom-ref": "pkg:npm/promzard@0.3.0?package-id=c6cc33c4ce6e7c43",
200601          "supplier": {},
200602          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
200603          "name": "promzard",
200604          "version": "0.3.0",
200605          "description": "prompting wizardly",
200606          "licenses": [
200607            {
200608              "license": {
200609                "id": "ISC"
200610              }
200611            }
200612          ],
200613          "cpe": "cpe:2.3:a:promzard:promzard:0.3.0:*:*:*:*:*:*:*",
200614          "purl": "pkg:npm/promzard@0.3.0",
200615          "swid": {
200616            "attachment": {}
200617          },
200618          "pedigree": {},
200619          "externalReferences": [
200620            {
200621              "url": "git://github.com/isaacs/promzard.git",
200622              "type": "distribution"
200623            },
200624            {
200625              "url": "https://github.com/isaacs/promzard#readme",
200626              "type": "website"
200627            }
200628          ],
200629          "evidence": {},
200630          "signature": {
200631            "signature": {
200632              "publicKey": {}
200633            }
200634          },
200635          "modelCard": {
200636            "modelParameters": {
200637              "approach": {}
200638            },
200639            "quantitativeAnalysis": {
200640              "graphics": {}
200641            },
200642            "considerations": {}
200643          }
200644        },
200645        {
200646          "type": "library",
200647          "bom-ref": "pkg:npm/proto-list@1.2.4?package-id=c43196d550bdd95d",
200648          "supplier": {},
200649          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
200650          "name": "proto-list",
200651          "version": "1.2.4",
200652          "description": "A utility for managing a prototype chain",
200653          "licenses": [
200654            {
200655              "license": {
200656                "id": "ISC"
200657              }
200658            }
200659          ],
200660          "cpe": "cpe:2.3:a:proto-list:proto-list:1.2.4:*:*:*:*:*:*:*",
200661          "purl": "pkg:npm/proto-list@1.2.4",
200662          "swid": {
200663            "attachment": {}
200664          },
200665          "pedigree": {},
200666          "externalReferences": [
200667            {
200668              "url": "git+https://github.com/isaacs/proto-list.git",
200669              "type": "distribution"
200670            },
200671            {
200672              "url": "https://github.com/isaacs/proto-list#readme",
200673              "type": "website"
200674            }
200675          ],
200676          "evidence": {},
200677          "signature": {
200678            "signature": {
200679              "publicKey": {}
200680            }
200681          },
200682          "modelCard": {
200683            "modelParameters": {
200684              "approach": {}
200685            },
200686            "quantitativeAnalysis": {
200687              "graphics": {}
200688            },
200689            "considerations": {}
200690          }
200691        },
200692        {
200693          "type": "library",
200694          "bom-ref": "pkg:npm/protoduck@5.0.1?package-id=b68f59ea3292e512",
200695          "supplier": {},
200696          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
200697          "name": "protoduck",
200698          "version": "5.0.1",
200699          "description": "Fancy duck typing for the most serious of ducks.",
200700          "licenses": [
200701            {
200702              "license": {
200703                "id": "MIT"
200704              }
200705            }
200706          ],
200707          "cpe": "cpe:2.3:a:protoduck:protoduck:5.0.1:*:*:*:*:*:*:*",
200708          "purl": "pkg:npm/protoduck@5.0.1",
200709          "swid": {
200710            "attachment": {}
200711          },
200712          "pedigree": {},
200713          "externalReferences": [
200714            {
200715              "url": "git+https://github.com/zkat/protoduck.git",
200716              "type": "distribution"
200717            },
200718            {
200719              "url": "https://github.com/zkat/protoduck#readme",
200720              "type": "website"
200721            }
200722          ],
200723          "evidence": {},
200724          "signature": {
200725            "signature": {
200726              "publicKey": {}
200727            }
200728          },
200729          "modelCard": {
200730            "modelParameters": {
200731              "approach": {}
200732            },
200733            "quantitativeAnalysis": {
200734              "graphics": {}
200735            },
200736            "considerations": {}
200737          }
200738        },
200739        {
200740          "type": "library",
200741          "bom-ref": "pkg:npm/proxy-addr@2.0.6?package-id=123f0887df70f1b6",
200742          "supplier": {},
200743          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
200744          "name": "proxy-addr",
200745          "version": "2.0.6",
200746          "description": "Determine address of proxied request",
200747          "licenses": [
200748            {
200749              "license": {
200750                "id": "MIT"
200751              }
200752            }
200753          ],
200754          "cpe": "cpe:2.3:a:proxy-addr:proxy-addr:2.0.6:*:*:*:*:*:*:*",
200755          "purl": "pkg:npm/proxy-addr@2.0.6",
200756          "swid": {
200757            "attachment": {}
200758          },
200759          "pedigree": {},
200760          "externalReferences": [
200761            {
200762              "url": "git+https://github.com/jshttp/proxy-addr.git",
200763              "type": "distribution"
200764            },
200765            {
200766              "url": "https://github.com/jshttp/proxy-addr#readme",
200767              "type": "website"
200768            }
200769          ],
200770          "evidence": {},
200771          "signature": {
200772            "signature": {
200773              "publicKey": {}
200774            }
200775          },
200776          "modelCard": {
200777            "modelParameters": {
200778              "approach": {}
200779            },
200780            "quantitativeAnalysis": {
200781              "graphics": {}
200782            },
200783            "considerations": {}
200784          }
200785        },
200786        {
200787          "type": "library",
200788          "bom-ref": "pkg:npm/prr@1.0.1?package-id=63f1d318228c3928",
200789          "supplier": {},
200790          "author": "Rod Vagg \u003crod@vagg.org\u003e (https://github.com/rvagg)",
200791          "name": "prr",
200792          "version": "1.0.1",
200793          "description": "A better Object.defineProperty()",
200794          "licenses": [
200795            {
200796              "license": {
200797                "id": "MIT"
200798              }
200799            }
200800          ],
200801          "cpe": "cpe:2.3:a:rvagg:prr:1.0.1:*:*:*:*:*:*:*",
200802          "purl": "pkg:npm/prr@1.0.1",
200803          "swid": {
200804            "attachment": {}
200805          },
200806          "pedigree": {},
200807          "externalReferences": [
200808            {
200809              "url": "git+https://github.com/rvagg/prr.git",
200810              "type": "distribution"
200811            },
200812            {
200813              "url": "https://github.com/rvagg/prr",
200814              "type": "website"
200815            }
200816          ],
200817          "evidence": {},
200818          "signature": {
200819            "signature": {
200820              "publicKey": {}
200821            }
200822          },
200823          "modelCard": {
200824            "modelParameters": {
200825              "approach": {}
200826            },
200827            "quantitativeAnalysis": {
200828              "graphics": {}
200829            },
200830            "considerations": {}
200831          }
200832        },
200833        {
200834          "type": "library",
200835          "bom-ref": "pkg:npm/pseudomap@1.0.2?package-id=ad27150a47cebf68",
200836          "supplier": {},
200837          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
200838          "name": "pseudomap",
200839          "version": "1.0.2",
200840          "description": "A thing that is a lot like ES6 `Map`, but without iterators, for use in environments where `for..of` syntax and `Map` are not available.",
200841          "licenses": [
200842            {
200843              "license": {
200844                "id": "ISC"
200845              }
200846            }
200847          ],
200848          "cpe": "cpe:2.3:a:pseudomap:pseudomap:1.0.2:*:*:*:*:*:*:*",
200849          "purl": "pkg:npm/pseudomap@1.0.2",
200850          "swid": {
200851            "attachment": {}
200852          },
200853          "pedigree": {},
200854          "externalReferences": [
200855            {
200856              "url": "git+https://github.com/isaacs/pseudomap.git",
200857              "type": "distribution"
200858            },
200859            {
200860              "url": "https://github.com/isaacs/pseudomap#readme",
200861              "type": "website"
200862            }
200863          ],
200864          "evidence": {},
200865          "signature": {
200866            "signature": {
200867              "publicKey": {}
200868            }
200869          },
200870          "modelCard": {
200871            "modelParameters": {
200872              "approach": {}
200873            },
200874            "quantitativeAnalysis": {
200875              "graphics": {}
200876            },
200877            "considerations": {}
200878          }
200879        },
200880        {
200881          "type": "library",
200882          "bom-ref": "pkg:npm/psl@1.1.29?package-id=4ac2f379b7d8203e",
200883          "supplier": {},
200884          "author": "Lupo Montero",
200885          "name": "psl",
200886          "version": "1.1.29",
200887          "description": "Domain name parser based on the Public Suffix List",
200888          "licenses": [
200889            {
200890              "license": {
200891                "id": "MIT"
200892              }
200893            }
200894          ],
200895          "cpe": "cpe:2.3:a:wrangr:psl:1.1.29:*:*:*:*:*:*:*",
200896          "purl": "pkg:npm/psl@1.1.29",
200897          "swid": {
200898            "attachment": {}
200899          },
200900          "pedigree": {},
200901          "externalReferences": [
200902            {
200903              "url": "git+ssh://git@github.com/wrangr/psl.git",
200904              "type": "distribution"
200905            },
200906            {
200907              "url": "https://github.com/wrangr/psl#readme",
200908              "type": "website"
200909            }
200910          ],
200911          "evidence": {},
200912          "signature": {
200913            "signature": {
200914              "publicKey": {}
200915            }
200916          },
200917          "modelCard": {
200918            "modelParameters": {
200919              "approach": {}
200920            },
200921            "quantitativeAnalysis": {
200922              "graphics": {}
200923            },
200924            "considerations": {}
200925          }
200926        },
200927        {
200928          "type": "library",
200929          "bom-ref": "pkg:npm/pump@2.0.1?package-id=a8def469cb4dfeae",
200930          "supplier": {},
200931          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
200932          "name": "pump",
200933          "version": "2.0.1",
200934          "description": "pipe streams together and close all of them if one of them closes",
200935          "licenses": [
200936            {
200937              "license": {
200938                "id": "MIT"
200939              }
200940            }
200941          ],
200942          "cpe": "cpe:2.3:a:mafintosh:pump:2.0.1:*:*:*:*:*:*:*",
200943          "purl": "pkg:npm/pump@2.0.1",
200944          "swid": {
200945            "attachment": {}
200946          },
200947          "pedigree": {},
200948          "externalReferences": [
200949            {
200950              "url": "git://github.com/mafintosh/pump.git",
200951              "type": "distribution"
200952            },
200953            {
200954              "url": "https://github.com/mafintosh/pump#readme",
200955              "type": "website"
200956            }
200957          ],
200958          "evidence": {},
200959          "signature": {
200960            "signature": {
200961              "publicKey": {}
200962            }
200963          },
200964          "modelCard": {
200965            "modelParameters": {
200966              "approach": {}
200967            },
200968            "quantitativeAnalysis": {
200969              "graphics": {}
200970            },
200971            "considerations": {}
200972          }
200973        },
200974        {
200975          "type": "library",
200976          "bom-ref": "pkg:npm/pump@3.0.0?package-id=3312119136f0c5b9",
200977          "supplier": {},
200978          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
200979          "name": "pump",
200980          "version": "3.0.0",
200981          "description": "pipe streams together and close all of them if one of them closes",
200982          "licenses": [
200983            {
200984              "license": {
200985                "id": "MIT"
200986              }
200987            }
200988          ],
200989          "cpe": "cpe:2.3:a:mafintosh:pump:3.0.0:*:*:*:*:*:*:*",
200990          "purl": "pkg:npm/pump@3.0.0",
200991          "swid": {
200992            "attachment": {}
200993          },
200994          "pedigree": {},
200995          "externalReferences": [
200996            {
200997              "url": "git://github.com/mafintosh/pump.git",
200998              "type": "distribution"
200999            },
201000            {
201001              "url": "https://github.com/mafintosh/pump#readme",
201002              "type": "website"
201003            }
201004          ],
201005          "evidence": {},
201006          "signature": {
201007            "signature": {
201008              "publicKey": {}
201009            }
201010          },
201011          "modelCard": {
201012            "modelParameters": {
201013              "approach": {}
201014            },
201015            "quantitativeAnalysis": {
201016              "graphics": {}
201017            },
201018            "considerations": {}
201019          }
201020        },
201021        {
201022          "type": "library",
201023          "bom-ref": "pkg:npm/pumpify@1.5.1?package-id=dfd38f508d390c3c",
201024          "supplier": {},
201025          "author": "Mathias Buus",
201026          "name": "pumpify",
201027          "version": "1.5.1",
201028          "description": "Combine an array of streams into a single duplex stream using pump and duplexify",
201029          "licenses": [
201030            {
201031              "license": {
201032                "id": "MIT"
201033              }
201034            }
201035          ],
201036          "cpe": "cpe:2.3:a:mafintosh:pumpify:1.5.1:*:*:*:*:*:*:*",
201037          "purl": "pkg:npm/pumpify@1.5.1",
201038          "swid": {
201039            "attachment": {}
201040          },
201041          "pedigree": {},
201042          "externalReferences": [
201043            {
201044              "url": "git://github.com/mafintosh/pumpify.git",
201045              "type": "distribution"
201046            },
201047            {
201048              "url": "https://github.com/mafintosh/pumpify",
201049              "type": "website"
201050            }
201051          ],
201052          "evidence": {},
201053          "signature": {
201054            "signature": {
201055              "publicKey": {}
201056            }
201057          },
201058          "modelCard": {
201059            "modelParameters": {
201060              "approach": {}
201061            },
201062            "quantitativeAnalysis": {
201063              "graphics": {}
201064            },
201065            "considerations": {}
201066          }
201067        },
201068        {
201069          "type": "library",
201070          "bom-ref": "pkg:npm/punycode@1.4.1?package-id=f447605e37be624d",
201071          "supplier": {},
201072          "author": "Mathias Bynens (https://mathiasbynens.be/)",
201073          "name": "punycode",
201074          "version": "1.4.1",
201075          "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
201076          "licenses": [
201077            {
201078              "license": {
201079                "id": "MIT"
201080              }
201081            }
201082          ],
201083          "cpe": "cpe:2.3:a:punycode:punycode:1.4.1:*:*:*:*:*:*:*",
201084          "purl": "pkg:npm/punycode@1.4.1",
201085          "swid": {
201086            "attachment": {}
201087          },
201088          "pedigree": {},
201089          "externalReferences": [
201090            {
201091              "url": "git+https://github.com/bestiejs/punycode.js.git",
201092              "type": "distribution"
201093            },
201094            {
201095              "url": "https://mths.be/punycode",
201096              "type": "website"
201097            }
201098          ],
201099          "evidence": {},
201100          "signature": {
201101            "signature": {
201102              "publicKey": {}
201103            }
201104          },
201105          "modelCard": {
201106            "modelParameters": {
201107              "approach": {}
201108            },
201109            "quantitativeAnalysis": {
201110              "graphics": {}
201111            },
201112            "considerations": {}
201113          }
201114        },
201115        {
201116          "type": "library",
201117          "bom-ref": "pkg:npm/punycode@2.1.1?package-id=a14c3d9d17c7ad6a",
201118          "supplier": {},
201119          "author": "Mathias Bynens (https://mathiasbynens.be/)",
201120          "name": "punycode",
201121          "version": "2.1.1",
201122          "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
201123          "licenses": [
201124            {
201125              "license": {
201126                "id": "MIT"
201127              }
201128            }
201129          ],
201130          "cpe": "cpe:2.3:a:punycode:punycode:2.1.1:*:*:*:*:*:*:*",
201131          "purl": "pkg:npm/punycode@2.1.1",
201132          "swid": {
201133            "attachment": {}
201134          },
201135          "pedigree": {},
201136          "externalReferences": [
201137            {
201138              "url": "git+https://github.com/bestiejs/punycode.js.git",
201139              "type": "distribution"
201140            },
201141            {
201142              "url": "https://mths.be/punycode",
201143              "type": "website"
201144            }
201145          ],
201146          "evidence": {},
201147          "signature": {
201148            "signature": {
201149              "publicKey": {}
201150            }
201151          },
201152          "modelCard": {
201153            "modelParameters": {
201154              "approach": {}
201155            },
201156            "quantitativeAnalysis": {
201157              "graphics": {}
201158            },
201159            "considerations": {}
201160          }
201161        },
201162        {
201163          "type": "library",
201164          "bom-ref": "pkg:npm/punycode@2.1.1?package-id=c670851ee62b8607",
201165          "supplier": {},
201166          "author": "Mathias Bynens (https://mathiasbynens.be/)",
201167          "name": "punycode",
201168          "version": "2.1.1",
201169          "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
201170          "licenses": [
201171            {
201172              "license": {
201173                "id": "MIT"
201174              }
201175            }
201176          ],
201177          "cpe": "cpe:2.3:a:punycode:punycode:2.1.1:*:*:*:*:*:*:*",
201178          "purl": "pkg:npm/punycode@2.1.1",
201179          "swid": {
201180            "attachment": {}
201181          },
201182          "pedigree": {},
201183          "externalReferences": [
201184            {
201185              "url": "git+https://github.com/bestiejs/punycode.js.git",
201186              "type": "distribution"
201187            },
201188            {
201189              "url": "https://mths.be/punycode",
201190              "type": "website"
201191            }
201192          ],
201193          "evidence": {},
201194          "signature": {
201195            "signature": {
201196              "publicKey": {}
201197            }
201198          },
201199          "modelCard": {
201200            "modelParameters": {
201201              "approach": {}
201202            },
201203            "quantitativeAnalysis": {
201204              "graphics": {}
201205            },
201206            "considerations": {}
201207          }
201208        },
201209        {
201210          "type": "library",
201211          "bom-ref": "pkg:npm/qrcode-terminal@0.12.0?package-id=12a4e61b4c7723ca",
201212          "supplier": {},
201213          "name": "qrcode-terminal",
201214          "version": "0.12.0",
201215          "description": "QRCodes, in the terminal",
201216          "licenses": [
201217            {
201218              "license": {
201219                "name": "Apache 2.0"
201220              }
201221            }
201222          ],
201223          "cpe": "cpe:2.3:a:qrcode-terminal:qrcode-terminal:0.12.0:*:*:*:*:*:*:*",
201224          "purl": "pkg:npm/qrcode-terminal@0.12.0",
201225          "swid": {
201226            "attachment": {}
201227          },
201228          "pedigree": {},
201229          "externalReferences": [
201230            {
201231              "url": "git+https://github.com/gtanner/qrcode-terminal.git",
201232              "type": "distribution"
201233            },
201234            {
201235              "url": "https://github.com/gtanner/qrcode-terminal",
201236              "type": "website"
201237            }
201238          ],
201239          "evidence": {},
201240          "signature": {
201241            "signature": {
201242              "publicKey": {}
201243            }
201244          },
201245          "modelCard": {
201246            "modelParameters": {
201247              "approach": {}
201248            },
201249            "quantitativeAnalysis": {
201250              "graphics": {}
201251            },
201252            "considerations": {}
201253          }
201254        },
201255        {
201256          "type": "library",
201257          "bom-ref": "pkg:npm/qs@6.5.2?package-id=3ce787a6bf6df684",
201258          "supplier": {},
201259          "name": "qs",
201260          "version": "6.5.2",
201261          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
201262          "licenses": [
201263            {
201264              "license": {
201265                "id": "BSD-3-Clause"
201266              }
201267            }
201268          ],
201269          "cpe": "cpe:2.3:a:ljharb:qs:6.5.2:*:*:*:*:*:*:*",
201270          "purl": "pkg:npm/qs@6.5.2",
201271          "swid": {
201272            "attachment": {}
201273          },
201274          "pedigree": {},
201275          "externalReferences": [
201276            {
201277              "url": "git+https://github.com/ljharb/qs.git",
201278              "type": "distribution"
201279            },
201280            {
201281              "url": "https://github.com/ljharb/qs",
201282              "type": "website"
201283            }
201284          ],
201285          "evidence": {},
201286          "signature": {
201287            "signature": {
201288              "publicKey": {}
201289            }
201290          },
201291          "modelCard": {
201292            "modelParameters": {
201293              "approach": {}
201294            },
201295            "quantitativeAnalysis": {
201296              "graphics": {}
201297            },
201298            "considerations": {}
201299          }
201300        },
201301        {
201302          "type": "library",
201303          "bom-ref": "pkg:npm/qs@6.7.0?package-id=1e95eebb398f373b",
201304          "supplier": {},
201305          "name": "qs",
201306          "version": "6.7.0",
201307          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
201308          "licenses": [
201309            {
201310              "license": {
201311                "id": "BSD-3-Clause"
201312              }
201313            }
201314          ],
201315          "cpe": "cpe:2.3:a:ljharb:qs:6.7.0:*:*:*:*:*:*:*",
201316          "purl": "pkg:npm/qs@6.7.0",
201317          "swid": {
201318            "attachment": {}
201319          },
201320          "pedigree": {},
201321          "externalReferences": [
201322            {
201323              "url": "git+https://github.com/ljharb/qs.git",
201324              "type": "distribution"
201325            },
201326            {
201327              "url": "https://github.com/ljharb/qs",
201328              "type": "website"
201329            }
201330          ],
201331          "evidence": {},
201332          "signature": {
201333            "signature": {
201334              "publicKey": {}
201335            }
201336          },
201337          "modelCard": {
201338            "modelParameters": {
201339              "approach": {}
201340            },
201341            "quantitativeAnalysis": {
201342              "graphics": {}
201343            },
201344            "considerations": {}
201345          }
201346        },
201347        {
201348          "type": "library",
201349          "bom-ref": "pkg:npm/query-string@6.8.2?package-id=17a1cdcb1043d65",
201350          "supplier": {},
201351          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
201352          "name": "query-string",
201353          "version": "6.8.2",
201354          "description": "Parse and stringify URL query strings",
201355          "licenses": [
201356            {
201357              "license": {
201358                "id": "MIT"
201359              }
201360            }
201361          ],
201362          "cpe": "cpe:2.3:a:query-string:query-string:6.8.2:*:*:*:*:*:*:*",
201363          "purl": "pkg:npm/query-string@6.8.2",
201364          "swid": {
201365            "attachment": {}
201366          },
201367          "pedigree": {},
201368          "externalReferences": [
201369            {
201370              "url": "git+https://github.com/sindresorhus/query-string.git",
201371              "type": "distribution"
201372            },
201373            {
201374              "url": "https://github.com/sindresorhus/query-string#readme",
201375              "type": "website"
201376            }
201377          ],
201378          "evidence": {},
201379          "signature": {
201380            "signature": {
201381              "publicKey": {}
201382            }
201383          },
201384          "modelCard": {
201385            "modelParameters": {
201386              "approach": {}
201387            },
201388            "quantitativeAnalysis": {
201389              "graphics": {}
201390            },
201391            "considerations": {}
201392          }
201393        },
201394        {
201395          "type": "library",
201396          "bom-ref": "pkg:npm/qw@1.0.1?package-id=ddfd5a6a50550a8a",
201397          "supplier": {},
201398          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
201399          "name": "qw",
201400          "version": "1.0.1",
201401          "description": "Quoted word literals!",
201402          "licenses": [
201403            {
201404              "license": {
201405                "id": "ISC"
201406              }
201407            }
201408          ],
201409          "cpe": "cpe:2.3:a:iarna:qw:1.0.1:*:*:*:*:*:*:*",
201410          "purl": "pkg:npm/qw@1.0.1",
201411          "swid": {
201412            "attachment": {}
201413          },
201414          "pedigree": {},
201415          "externalReferences": [
201416            {
201417              "url": "git+https://github.com/iarna/node-qw.git",
201418              "type": "distribution"
201419            },
201420            {
201421              "url": "https://github.com/iarna/node-qw#readme",
201422              "type": "website"
201423            }
201424          ],
201425          "evidence": {},
201426          "signature": {
201427            "signature": {
201428              "publicKey": {}
201429            }
201430          },
201431          "modelCard": {
201432            "modelParameters": {
201433              "approach": {}
201434            },
201435            "quantitativeAnalysis": {
201436              "graphics": {}
201437            },
201438            "considerations": {}
201439          }
201440        },
201441        {
201442          "type": "library",
201443          "bom-ref": "pkg:npm/range-parser@1.2.1?package-id=5f29bd6f8c12ae73",
201444          "supplier": {},
201445          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
201446          "name": "range-parser",
201447          "version": "1.2.1",
201448          "description": "Range header field string parser",
201449          "licenses": [
201450            {
201451              "license": {
201452                "id": "MIT"
201453              }
201454            }
201455          ],
201456          "cpe": "cpe:2.3:a:range-parser:range-parser:1.2.1:*:*:*:*:*:*:*",
201457          "purl": "pkg:npm/range-parser@1.2.1",
201458          "swid": {
201459            "attachment": {}
201460          },
201461          "pedigree": {},
201462          "externalReferences": [
201463            {
201464              "url": "git+https://github.com/jshttp/range-parser.git",
201465              "type": "distribution"
201466            },
201467            {
201468              "url": "https://github.com/jshttp/range-parser#readme",
201469              "type": "website"
201470            }
201471          ],
201472          "evidence": {},
201473          "signature": {
201474            "signature": {
201475              "publicKey": {}
201476            }
201477          },
201478          "modelCard": {
201479            "modelParameters": {
201480              "approach": {}
201481            },
201482            "quantitativeAnalysis": {
201483              "graphics": {}
201484            },
201485            "considerations": {}
201486          }
201487        },
201488        {
201489          "type": "library",
201490          "bom-ref": "pkg:npm/raw-body@2.4.0?package-id=94f992c82048f5e8",
201491          "supplier": {},
201492          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
201493          "name": "raw-body",
201494          "version": "2.4.0",
201495          "description": "Get and validate the raw body of a readable stream.",
201496          "licenses": [
201497            {
201498              "license": {
201499                "id": "MIT"
201500              }
201501            }
201502          ],
201503          "cpe": "cpe:2.3:a:stream-utils:raw-body:2.4.0:*:*:*:*:*:*:*",
201504          "purl": "pkg:npm/raw-body@2.4.0",
201505          "swid": {
201506            "attachment": {}
201507          },
201508          "pedigree": {},
201509          "externalReferences": [
201510            {
201511              "url": "git+https://github.com/stream-utils/raw-body.git",
201512              "type": "distribution"
201513            },
201514            {
201515              "url": "https://github.com/stream-utils/raw-body#readme",
201516              "type": "website"
201517            }
201518          ],
201519          "evidence": {},
201520          "signature": {
201521            "signature": {
201522              "publicKey": {}
201523            }
201524          },
201525          "modelCard": {
201526            "modelParameters": {
201527              "approach": {}
201528            },
201529            "quantitativeAnalysis": {
201530              "graphics": {}
201531            },
201532            "considerations": {}
201533          }
201534        },
201535        {
201536          "type": "library",
201537          "bom-ref": "pkg:npm/rc@1.2.8?package-id=4eb7e0d572bcca8b",
201538          "supplier": {},
201539          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (dominictarr.com)",
201540          "name": "rc",
201541          "version": "1.2.8",
201542          "description": "hardwired configuration loader",
201543          "licenses": [
201544            {
201545              "license": {
201546                "name": "(BSD-2-Clause OR MIT OR Apache-2.0)"
201547              }
201548            }
201549          ],
201550          "cpe": "cpe:2.3:a:dominictarr:rc:1.2.8:*:*:*:*:*:*:*",
201551          "purl": "pkg:npm/rc@1.2.8",
201552          "swid": {
201553            "attachment": {}
201554          },
201555          "pedigree": {},
201556          "externalReferences": [
201557            {
201558              "url": "git+https://github.com/dominictarr/rc.git",
201559              "type": "distribution"
201560            },
201561            {
201562              "url": "https://github.com/dominictarr/rc#readme",
201563              "type": "website"
201564            }
201565          ],
201566          "evidence": {},
201567          "signature": {
201568            "signature": {
201569              "publicKey": {}
201570            }
201571          },
201572          "modelCard": {
201573            "modelParameters": {
201574              "approach": {}
201575            },
201576            "quantitativeAnalysis": {
201577              "graphics": {}
201578            },
201579            "considerations": {}
201580          }
201581        },
201582        {
201583          "type": "library",
201584          "bom-ref": "pkg:npm/read@1.0.7?package-id=c9bc8b81b738d1cf",
201585          "supplier": {},
201586          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
201587          "name": "read",
201588          "version": "1.0.7",
201589          "description": "read(1) for node programs",
201590          "licenses": [
201591            {
201592              "license": {
201593                "id": "ISC"
201594              }
201595            }
201596          ],
201597          "cpe": "cpe:2.3:a:isaacs:read:1.0.7:*:*:*:*:*:*:*",
201598          "purl": "pkg:npm/read@1.0.7",
201599          "swid": {
201600            "attachment": {}
201601          },
201602          "pedigree": {},
201603          "externalReferences": [
201604            {
201605              "url": "git://github.com/isaacs/read.git",
201606              "type": "distribution"
201607            },
201608            {
201609              "url": "https://github.com/isaacs/read#readme",
201610              "type": "website"
201611            }
201612          ],
201613          "evidence": {},
201614          "signature": {
201615            "signature": {
201616              "publicKey": {}
201617            }
201618          },
201619          "modelCard": {
201620            "modelParameters": {
201621              "approach": {}
201622            },
201623            "quantitativeAnalysis": {
201624              "graphics": {}
201625            },
201626            "considerations": {}
201627          }
201628        },
201629        {
201630          "type": "library",
201631          "bom-ref": "pkg:npm/read-cmd-shim@1.0.5?package-id=f4070b859bc3daec",
201632          "supplier": {},
201633          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
201634          "name": "read-cmd-shim",
201635          "version": "1.0.5",
201636          "description": "Figure out what a cmd-shim is pointing at. This acts as the equivalent of fs.readlink.",
201637          "licenses": [
201638            {
201639              "license": {
201640                "id": "ISC"
201641              }
201642            }
201643          ],
201644          "cpe": "cpe:2.3:a:read-cmd-shim:read-cmd-shim:1.0.5:*:*:*:*:*:*:*",
201645          "purl": "pkg:npm/read-cmd-shim@1.0.5",
201646          "swid": {
201647            "attachment": {}
201648          },
201649          "pedigree": {},
201650          "externalReferences": [
201651            {
201652              "url": "git+https://github.com/npm/read-cmd-shim.git",
201653              "type": "distribution"
201654            },
201655            {
201656              "url": "https://github.com/npm/read-cmd-shim#readme",
201657              "type": "website"
201658            }
201659          ],
201660          "evidence": {},
201661          "signature": {
201662            "signature": {
201663              "publicKey": {}
201664            }
201665          },
201666          "modelCard": {
201667            "modelParameters": {
201668              "approach": {}
201669            },
201670            "quantitativeAnalysis": {
201671              "graphics": {}
201672            },
201673            "considerations": {}
201674          }
201675        },
201676        {
201677          "type": "library",
201678          "bom-ref": "pkg:npm/read-installed@4.0.3?package-id=9b81d092221c4f30",
201679          "supplier": {},
201680          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
201681          "name": "read-installed",
201682          "version": "4.0.3",
201683          "description": "Read all the installed packages in a folder, and return a tree structure with all the data.",
201684          "licenses": [
201685            {
201686              "license": {
201687                "id": "ISC"
201688              }
201689            }
201690          ],
201691          "cpe": "cpe:2.3:a:read-installed:read-installed:4.0.3:*:*:*:*:*:*:*",
201692          "purl": "pkg:npm/read-installed@4.0.3",
201693          "swid": {
201694            "attachment": {}
201695          },
201696          "pedigree": {},
201697          "externalReferences": [
201698            {
201699              "url": "git://github.com/isaacs/read-installed.git",
201700              "type": "distribution"
201701            },
201702            {
201703              "url": "https://github.com/isaacs/read-installed#readme",
201704              "type": "website"
201705            }
201706          ],
201707          "evidence": {},
201708          "signature": {
201709            "signature": {
201710              "publicKey": {}
201711            }
201712          },
201713          "modelCard": {
201714            "modelParameters": {
201715              "approach": {}
201716            },
201717            "quantitativeAnalysis": {
201718              "graphics": {}
201719            },
201720            "considerations": {}
201721          }
201722        },
201723        {
201724          "type": "library",
201725          "bom-ref": "pkg:npm/read-package-json@2.1.1?package-id=4f64a93322ae44fc",
201726          "supplier": {},
201727          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
201728          "name": "read-package-json",
201729          "version": "2.1.1",
201730          "description": "The thing npm uses to read package.json files with semantics and defaults and validation",
201731          "licenses": [
201732            {
201733              "license": {
201734                "id": "ISC"
201735              }
201736            }
201737          ],
201738          "cpe": "cpe:2.3:a:read-package-json:read-package-json:2.1.1:*:*:*:*:*:*:*",
201739          "purl": "pkg:npm/read-package-json@2.1.1",
201740          "swid": {
201741            "attachment": {}
201742          },
201743          "pedigree": {},
201744          "externalReferences": [
201745            {
201746              "url": "git+https://github.com/npm/read-package-json.git",
201747              "type": "distribution"
201748            },
201749            {
201750              "url": "https://github.com/npm/read-package-json#readme",
201751              "type": "website"
201752            }
201753          ],
201754          "evidence": {},
201755          "signature": {
201756            "signature": {
201757              "publicKey": {}
201758            }
201759          },
201760          "modelCard": {
201761            "modelParameters": {
201762              "approach": {}
201763            },
201764            "quantitativeAnalysis": {
201765              "graphics": {}
201766            },
201767            "considerations": {}
201768          }
201769        },
201770        {
201771          "type": "library",
201772          "bom-ref": "pkg:npm/read-package-tree@5.3.1?package-id=ae8f6f2464715ed7",
201773          "supplier": {},
201774          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
201775          "name": "read-package-tree",
201776          "version": "5.3.1",
201777          "description": "Read the contents of node_modules.",
201778          "licenses": [
201779            {
201780              "license": {
201781                "id": "ISC"
201782              }
201783            }
201784          ],
201785          "cpe": "cpe:2.3:a:read-package-tree:read-package-tree:5.3.1:*:*:*:*:*:*:*",
201786          "purl": "pkg:npm/read-package-tree@5.3.1",
201787          "swid": {
201788            "attachment": {}
201789          },
201790          "pedigree": {},
201791          "externalReferences": [
201792            {
201793              "url": "git+https://github.com/npm/read-package-tree.git",
201794              "type": "distribution"
201795            },
201796            {
201797              "url": "https://github.com/npm/read-package-tree",
201798              "type": "website"
201799            }
201800          ],
201801          "evidence": {},
201802          "signature": {
201803            "signature": {
201804              "publicKey": {}
201805            }
201806          },
201807          "modelCard": {
201808            "modelParameters": {
201809              "approach": {}
201810            },
201811            "quantitativeAnalysis": {
201812              "graphics": {}
201813            },
201814            "considerations": {}
201815          }
201816        },
201817        {
201818          "type": "library",
201819          "bom-ref": "pkg:npm/readable-stream@1.1.14?package-id=8757df08ac8f65d0",
201820          "supplier": {},
201821          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
201822          "name": "readable-stream",
201823          "version": "1.1.14",
201824          "description": "Streams3, a user-land copy of the stream library from Node.js v0.11.x",
201825          "licenses": [
201826            {
201827              "license": {
201828                "id": "MIT"
201829              }
201830            }
201831          ],
201832          "cpe": "cpe:2.3:a:readable-stream:readable-stream:1.1.14:*:*:*:*:*:*:*",
201833          "purl": "pkg:npm/readable-stream@1.1.14",
201834          "swid": {
201835            "attachment": {}
201836          },
201837          "pedigree": {},
201838          "externalReferences": [
201839            {
201840              "url": "git://github.com/isaacs/readable-stream.git",
201841              "type": "distribution"
201842            },
201843            {
201844              "url": "https://github.com/isaacs/readable-stream#readme",
201845              "type": "website"
201846            }
201847          ],
201848          "evidence": {},
201849          "signature": {
201850            "signature": {
201851              "publicKey": {}
201852            }
201853          },
201854          "modelCard": {
201855            "modelParameters": {
201856              "approach": {}
201857            },
201858            "quantitativeAnalysis": {
201859              "graphics": {}
201860            },
201861            "considerations": {}
201862          }
201863        },
201864        {
201865          "type": "library",
201866          "bom-ref": "pkg:npm/readable-stream@1.1.14?package-id=48b97f0045dc6076",
201867          "supplier": {},
201868          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
201869          "name": "readable-stream",
201870          "version": "1.1.14",
201871          "description": "Streams3, a user-land copy of the stream library from Node.js v0.11.x",
201872          "licenses": [
201873            {
201874              "license": {
201875                "id": "MIT"
201876              }
201877            }
201878          ],
201879          "cpe": "cpe:2.3:a:readable-stream:readable-stream:1.1.14:*:*:*:*:*:*:*",
201880          "purl": "pkg:npm/readable-stream@1.1.14",
201881          "swid": {
201882            "attachment": {}
201883          },
201884          "pedigree": {},
201885          "externalReferences": [
201886            {
201887              "url": "git://github.com/isaacs/readable-stream.git",
201888              "type": "distribution"
201889            },
201890            {
201891              "url": "https://github.com/isaacs/readable-stream#readme",
201892              "type": "website"
201893            }
201894          ],
201895          "evidence": {},
201896          "signature": {
201897            "signature": {
201898              "publicKey": {}
201899            }
201900          },
201901          "modelCard": {
201902            "modelParameters": {
201903              "approach": {}
201904            },
201905            "quantitativeAnalysis": {
201906              "graphics": {}
201907            },
201908            "considerations": {}
201909          }
201910        },
201911        {
201912          "type": "library",
201913          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=7353d87f1c25d400",
201914          "supplier": {},
201915          "name": "readable-stream",
201916          "version": "2.3.6",
201917          "description": "Streams3, a user-land copy of the stream library from Node.js",
201918          "licenses": [
201919            {
201920              "license": {
201921                "id": "MIT"
201922              }
201923            }
201924          ],
201925          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
201926          "purl": "pkg:npm/readable-stream@2.3.6",
201927          "swid": {
201928            "attachment": {}
201929          },
201930          "pedigree": {},
201931          "externalReferences": [
201932            {
201933              "url": "git://github.com/nodejs/readable-stream.git",
201934              "type": "distribution"
201935            },
201936            {
201937              "url": "https://github.com/nodejs/readable-stream#readme",
201938              "type": "website"
201939            }
201940          ],
201941          "evidence": {},
201942          "signature": {
201943            "signature": {
201944              "publicKey": {}
201945            }
201946          },
201947          "modelCard": {
201948            "modelParameters": {
201949              "approach": {}
201950            },
201951            "quantitativeAnalysis": {
201952              "graphics": {}
201953            },
201954            "considerations": {}
201955          }
201956        },
201957        {
201958          "type": "library",
201959          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=fe3065896055c182",
201960          "supplier": {},
201961          "name": "readable-stream",
201962          "version": "2.3.6",
201963          "description": "Streams3, a user-land copy of the stream library from Node.js",
201964          "licenses": [
201965            {
201966              "license": {
201967                "id": "MIT"
201968              }
201969            }
201970          ],
201971          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
201972          "purl": "pkg:npm/readable-stream@2.3.6",
201973          "swid": {
201974            "attachment": {}
201975          },
201976          "pedigree": {},
201977          "externalReferences": [
201978            {
201979              "url": "git://github.com/nodejs/readable-stream.git",
201980              "type": "distribution"
201981            },
201982            {
201983              "url": "https://github.com/nodejs/readable-stream#readme",
201984              "type": "website"
201985            }
201986          ],
201987          "evidence": {},
201988          "signature": {
201989            "signature": {
201990              "publicKey": {}
201991            }
201992          },
201993          "modelCard": {
201994            "modelParameters": {
201995              "approach": {}
201996            },
201997            "quantitativeAnalysis": {
201998              "graphics": {}
201999            },
202000            "considerations": {}
202001          }
202002        },
202003        {
202004          "type": "library",
202005          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=ee88dc9eaec41878",
202006          "supplier": {},
202007          "name": "readable-stream",
202008          "version": "2.3.6",
202009          "description": "Streams3, a user-land copy of the stream library from Node.js",
202010          "licenses": [
202011            {
202012              "license": {
202013                "id": "MIT"
202014              }
202015            }
202016          ],
202017          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
202018          "purl": "pkg:npm/readable-stream@2.3.6",
202019          "swid": {
202020            "attachment": {}
202021          },
202022          "pedigree": {},
202023          "externalReferences": [
202024            {
202025              "url": "git://github.com/nodejs/readable-stream.git",
202026              "type": "distribution"
202027            },
202028            {
202029              "url": "https://github.com/nodejs/readable-stream#readme",
202030              "type": "website"
202031            }
202032          ],
202033          "evidence": {},
202034          "signature": {
202035            "signature": {
202036              "publicKey": {}
202037            }
202038          },
202039          "modelCard": {
202040            "modelParameters": {
202041              "approach": {}
202042            },
202043            "quantitativeAnalysis": {
202044              "graphics": {}
202045            },
202046            "considerations": {}
202047          }
202048        },
202049        {
202050          "type": "library",
202051          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=de77726bf8112b61",
202052          "supplier": {},
202053          "name": "readable-stream",
202054          "version": "2.3.6",
202055          "description": "Streams3, a user-land copy of the stream library from Node.js",
202056          "licenses": [
202057            {
202058              "license": {
202059                "id": "MIT"
202060              }
202061            }
202062          ],
202063          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
202064          "purl": "pkg:npm/readable-stream@2.3.6",
202065          "swid": {
202066            "attachment": {}
202067          },
202068          "pedigree": {},
202069          "externalReferences": [
202070            {
202071              "url": "git://github.com/nodejs/readable-stream.git",
202072              "type": "distribution"
202073            },
202074            {
202075              "url": "https://github.com/nodejs/readable-stream#readme",
202076              "type": "website"
202077            }
202078          ],
202079          "evidence": {},
202080          "signature": {
202081            "signature": {
202082              "publicKey": {}
202083            }
202084          },
202085          "modelCard": {
202086            "modelParameters": {
202087              "approach": {}
202088            },
202089            "quantitativeAnalysis": {
202090              "graphics": {}
202091            },
202092            "considerations": {}
202093          }
202094        },
202095        {
202096          "type": "library",
202097          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=a2ed95a02f789ed0",
202098          "supplier": {},
202099          "name": "readable-stream",
202100          "version": "2.3.6",
202101          "description": "Streams3, a user-land copy of the stream library from Node.js",
202102          "licenses": [
202103            {
202104              "license": {
202105                "id": "MIT"
202106              }
202107            }
202108          ],
202109          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
202110          "purl": "pkg:npm/readable-stream@2.3.6",
202111          "swid": {
202112            "attachment": {}
202113          },
202114          "pedigree": {},
202115          "externalReferences": [
202116            {
202117              "url": "git://github.com/nodejs/readable-stream.git",
202118              "type": "distribution"
202119            },
202120            {
202121              "url": "https://github.com/nodejs/readable-stream#readme",
202122              "type": "website"
202123            }
202124          ],
202125          "evidence": {},
202126          "signature": {
202127            "signature": {
202128              "publicKey": {}
202129            }
202130          },
202131          "modelCard": {
202132            "modelParameters": {
202133              "approach": {}
202134            },
202135            "quantitativeAnalysis": {
202136              "graphics": {}
202137            },
202138            "considerations": {}
202139          }
202140        },
202141        {
202142          "type": "library",
202143          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=4bf24eaec254b2f5",
202144          "supplier": {},
202145          "name": "readable-stream",
202146          "version": "2.3.6",
202147          "description": "Streams3, a user-land copy of the stream library from Node.js",
202148          "licenses": [
202149            {
202150              "license": {
202151                "id": "MIT"
202152              }
202153            }
202154          ],
202155          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
202156          "purl": "pkg:npm/readable-stream@2.3.6",
202157          "swid": {
202158            "attachment": {}
202159          },
202160          "pedigree": {},
202161          "externalReferences": [
202162            {
202163              "url": "git://github.com/nodejs/readable-stream.git",
202164              "type": "distribution"
202165            },
202166            {
202167              "url": "https://github.com/nodejs/readable-stream#readme",
202168              "type": "website"
202169            }
202170          ],
202171          "evidence": {},
202172          "signature": {
202173            "signature": {
202174              "publicKey": {}
202175            }
202176          },
202177          "modelCard": {
202178            "modelParameters": {
202179              "approach": {}
202180            },
202181            "quantitativeAnalysis": {
202182              "graphics": {}
202183            },
202184            "considerations": {}
202185          }
202186        },
202187        {
202188          "type": "library",
202189          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=fbc5f578bd8a0000",
202190          "supplier": {},
202191          "name": "readable-stream",
202192          "version": "2.3.6",
202193          "description": "Streams3, a user-land copy of the stream library from Node.js",
202194          "licenses": [
202195            {
202196              "license": {
202197                "id": "MIT"
202198              }
202199            }
202200          ],
202201          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
202202          "purl": "pkg:npm/readable-stream@2.3.6",
202203          "swid": {
202204            "attachment": {}
202205          },
202206          "pedigree": {},
202207          "externalReferences": [
202208            {
202209              "url": "git://github.com/nodejs/readable-stream.git",
202210              "type": "distribution"
202211            },
202212            {
202213              "url": "https://github.com/nodejs/readable-stream#readme",
202214              "type": "website"
202215            }
202216          ],
202217          "evidence": {},
202218          "signature": {
202219            "signature": {
202220              "publicKey": {}
202221            }
202222          },
202223          "modelCard": {
202224            "modelParameters": {
202225              "approach": {}
202226            },
202227            "quantitativeAnalysis": {
202228              "graphics": {}
202229            },
202230            "considerations": {}
202231          }
202232        },
202233        {
202234          "type": "library",
202235          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=7cd5df9449d0f2a5",
202236          "supplier": {},
202237          "name": "readable-stream",
202238          "version": "2.3.6",
202239          "description": "Streams3, a user-land copy of the stream library from Node.js",
202240          "licenses": [
202241            {
202242              "license": {
202243                "id": "MIT"
202244              }
202245            }
202246          ],
202247          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
202248          "purl": "pkg:npm/readable-stream@2.3.6",
202249          "swid": {
202250            "attachment": {}
202251          },
202252          "pedigree": {},
202253          "externalReferences": [
202254            {
202255              "url": "git://github.com/nodejs/readable-stream.git",
202256              "type": "distribution"
202257            },
202258            {
202259              "url": "https://github.com/nodejs/readable-stream#readme",
202260              "type": "website"
202261            }
202262          ],
202263          "evidence": {},
202264          "signature": {
202265            "signature": {
202266              "publicKey": {}
202267            }
202268          },
202269          "modelCard": {
202270            "modelParameters": {
202271              "approach": {}
202272            },
202273            "quantitativeAnalysis": {
202274              "graphics": {}
202275            },
202276            "considerations": {}
202277          }
202278        },
202279        {
202280          "type": "library",
202281          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=e6f05a441c42f027",
202282          "supplier": {},
202283          "name": "readable-stream",
202284          "version": "2.3.6",
202285          "description": "Streams3, a user-land copy of the stream library from Node.js",
202286          "licenses": [
202287            {
202288              "license": {
202289                "id": "MIT"
202290              }
202291            }
202292          ],
202293          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
202294          "purl": "pkg:npm/readable-stream@2.3.6",
202295          "swid": {
202296            "attachment": {}
202297          },
202298          "pedigree": {},
202299          "externalReferences": [
202300            {
202301              "url": "git://github.com/nodejs/readable-stream.git",
202302              "type": "distribution"
202303            },
202304            {
202305              "url": "https://github.com/nodejs/readable-stream#readme",
202306              "type": "website"
202307            }
202308          ],
202309          "evidence": {},
202310          "signature": {
202311            "signature": {
202312              "publicKey": {}
202313            }
202314          },
202315          "modelCard": {
202316            "modelParameters": {
202317              "approach": {}
202318            },
202319            "quantitativeAnalysis": {
202320              "graphics": {}
202321            },
202322            "considerations": {}
202323          }
202324        },
202325        {
202326          "type": "library",
202327          "bom-ref": "pkg:npm/readable-stream@2.3.7?package-id=b99a917b60ecef17",
202328          "supplier": {},
202329          "name": "readable-stream",
202330          "version": "2.3.7",
202331          "description": "Streams3, a user-land copy of the stream library from Node.js",
202332          "licenses": [
202333            {
202334              "license": {
202335                "id": "MIT"
202336              }
202337            }
202338          ],
202339          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.7:*:*:*:*:*:*:*",
202340          "purl": "pkg:npm/readable-stream@2.3.7",
202341          "swid": {
202342            "attachment": {}
202343          },
202344          "pedigree": {},
202345          "externalReferences": [
202346            {
202347              "url": "git://github.com/nodejs/readable-stream.git",
202348              "type": "distribution"
202349            },
202350            {
202351              "url": "https://github.com/nodejs/readable-stream#readme",
202352              "type": "website"
202353            }
202354          ],
202355          "evidence": {},
202356          "signature": {
202357            "signature": {
202358              "publicKey": {}
202359            }
202360          },
202361          "modelCard": {
202362            "modelParameters": {
202363              "approach": {}
202364            },
202365            "quantitativeAnalysis": {
202366              "graphics": {}
202367            },
202368            "considerations": {}
202369          }
202370        },
202371        {
202372          "type": "library",
202373          "bom-ref": "pkg:npm/readable-stream@3.6.0?package-id=534bbd008356bd1a",
202374          "supplier": {},
202375          "name": "readable-stream",
202376          "version": "3.6.0",
202377          "description": "Streams3, a user-land copy of the stream library from Node.js",
202378          "licenses": [
202379            {
202380              "license": {
202381                "id": "MIT"
202382              }
202383            }
202384          ],
202385          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.0:*:*:*:*:*:*:*",
202386          "purl": "pkg:npm/readable-stream@3.6.0",
202387          "swid": {
202388            "attachment": {}
202389          },
202390          "pedigree": {},
202391          "externalReferences": [
202392            {
202393              "url": "git://github.com/nodejs/readable-stream.git",
202394              "type": "distribution"
202395            },
202396            {
202397              "url": "https://github.com/nodejs/readable-stream#readme",
202398              "type": "website"
202399            }
202400          ],
202401          "evidence": {},
202402          "signature": {
202403            "signature": {
202404              "publicKey": {}
202405            }
202406          },
202407          "modelCard": {
202408            "modelParameters": {
202409              "approach": {}
202410            },
202411            "quantitativeAnalysis": {
202412              "graphics": {}
202413            },
202414            "considerations": {}
202415          }
202416        },
202417        {
202418          "type": "library",
202419          "bom-ref": "pkg:npm/readable-stream@3.6.0?package-id=e68425c0a847320d",
202420          "supplier": {},
202421          "name": "readable-stream",
202422          "version": "3.6.0",
202423          "description": "Streams3, a user-land copy of the stream library from Node.js",
202424          "licenses": [
202425            {
202426              "license": {
202427                "id": "MIT"
202428              }
202429            }
202430          ],
202431          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.0:*:*:*:*:*:*:*",
202432          "purl": "pkg:npm/readable-stream@3.6.0",
202433          "swid": {
202434            "attachment": {}
202435          },
202436          "pedigree": {},
202437          "externalReferences": [
202438            {
202439              "url": "git://github.com/nodejs/readable-stream.git",
202440              "type": "distribution"
202441            },
202442            {
202443              "url": "https://github.com/nodejs/readable-stream#readme",
202444              "type": "website"
202445            }
202446          ],
202447          "evidence": {},
202448          "signature": {
202449            "signature": {
202450              "publicKey": {}
202451            }
202452          },
202453          "modelCard": {
202454            "modelParameters": {
202455              "approach": {}
202456            },
202457            "quantitativeAnalysis": {
202458              "graphics": {}
202459            },
202460            "considerations": {}
202461          }
202462        },
202463        {
202464          "type": "library",
202465          "bom-ref": "pkg:npm/readdir-scoped-modules@1.1.0?package-id=faa5c279a92af9df",
202466          "supplier": {},
202467          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
202468          "name": "readdir-scoped-modules",
202469          "version": "1.1.0",
202470          "description": "Like `fs.readdir` but handling `@org/module` dirs as if they were a single entry.",
202471          "licenses": [
202472            {
202473              "license": {
202474                "id": "ISC"
202475              }
202476            }
202477          ],
202478          "cpe": "cpe:2.3:a:readdir-scoped-modules:readdir-scoped-modules:1.1.0:*:*:*:*:*:*:*",
202479          "purl": "pkg:npm/readdir-scoped-modules@1.1.0",
202480          "swid": {
202481            "attachment": {}
202482          },
202483          "pedigree": {},
202484          "externalReferences": [
202485            {
202486              "url": "git+https://github.com/npm/readdir-scoped-modules.git",
202487              "type": "distribution"
202488            },
202489            {
202490              "url": "https://github.com/npm/readdir-scoped-modules",
202491              "type": "website"
202492            }
202493          ],
202494          "evidence": {},
202495          "signature": {
202496            "signature": {
202497              "publicKey": {}
202498            }
202499          },
202500          "modelCard": {
202501            "modelParameters": {
202502              "approach": {}
202503            },
202504            "quantitativeAnalysis": {
202505              "graphics": {}
202506            },
202507            "considerations": {}
202508          }
202509        },
202510        {
202511          "type": "library",
202512          "bom-ref": "pkg:npm/reflect-metadata@0.1.13?package-id=c10a8a0418712a9f",
202513          "supplier": {},
202514          "author": "Ron Buckton \u003cron.buckton@microsoft.com\u003e (http://github.com/rbuckton)",
202515          "name": "reflect-metadata",
202516          "version": "0.1.13",
202517          "description": "Polyfill for Metadata Reflection API",
202518          "licenses": [
202519            {
202520              "license": {
202521                "id": "Apache-2.0"
202522              }
202523            }
202524          ],
202525          "cpe": "cpe:2.3:a:reflect-metadata:reflect-metadata:0.1.13:*:*:*:*:*:*:*",
202526          "purl": "pkg:npm/reflect-metadata@0.1.13",
202527          "swid": {
202528            "attachment": {}
202529          },
202530          "pedigree": {},
202531          "externalReferences": [
202532            {
202533              "url": "git+https://github.com/rbuckton/reflect-metadata.git",
202534              "type": "distribution"
202535            },
202536            {
202537              "url": "http://rbuckton.github.io/reflect-metadata",
202538              "type": "website"
202539            }
202540          ],
202541          "evidence": {},
202542          "signature": {
202543            "signature": {
202544              "publicKey": {}
202545            }
202546          },
202547          "modelCard": {
202548            "modelParameters": {
202549              "approach": {}
202550            },
202551            "quantitativeAnalysis": {
202552              "graphics": {}
202553            },
202554            "considerations": {}
202555          }
202556        },
202557        {
202558          "type": "library",
202559          "bom-ref": "pkg:npm/registry-auth-token@3.4.0?package-id=7b8cdd936c12baa6",
202560          "supplier": {},
202561          "author": "Espen Hovlandsdal \u003cespen@hovlandsdal.com\u003e",
202562          "name": "registry-auth-token",
202563          "version": "3.4.0",
202564          "description": "Get the auth token set for an npm registry (if any)",
202565          "licenses": [
202566            {
202567              "license": {
202568                "id": "MIT"
202569              }
202570            }
202571          ],
202572          "cpe": "cpe:2.3:a:registry-auth-token:registry-auth-token:3.4.0:*:*:*:*:*:*:*",
202573          "purl": "pkg:npm/registry-auth-token@3.4.0",
202574          "swid": {
202575            "attachment": {}
202576          },
202577          "pedigree": {},
202578          "externalReferences": [
202579            {
202580              "url": "git+ssh://git@github.com/rexxars/registry-auth-token.git",
202581              "type": "distribution"
202582            },
202583            {
202584              "url": "https://github.com/rexxars/registry-auth-token#readme",
202585              "type": "website"
202586            }
202587          ],
202588          "evidence": {},
202589          "signature": {
202590            "signature": {
202591              "publicKey": {}
202592            }
202593          },
202594          "modelCard": {
202595            "modelParameters": {
202596              "approach": {}
202597            },
202598            "quantitativeAnalysis": {
202599              "graphics": {}
202600            },
202601            "considerations": {}
202602          }
202603        },
202604        {
202605          "type": "library",
202606          "bom-ref": "pkg:npm/registry-url@3.1.0?package-id=fcf8f05cbd852c57",
202607          "supplier": {},
202608          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
202609          "name": "registry-url",
202610          "version": "3.1.0",
202611          "description": "Get the set npm registry URL",
202612          "licenses": [
202613            {
202614              "license": {
202615                "id": "MIT"
202616              }
202617            }
202618          ],
202619          "cpe": "cpe:2.3:a:registry-url:registry-url:3.1.0:*:*:*:*:*:*:*",
202620          "purl": "pkg:npm/registry-url@3.1.0",
202621          "swid": {
202622            "attachment": {}
202623          },
202624          "pedigree": {},
202625          "externalReferences": [
202626            {
202627              "url": "git+https://github.com/sindresorhus/registry-url.git",
202628              "type": "distribution"
202629            },
202630            {
202631              "url": "https://github.com/sindresorhus/registry-url#readme",
202632              "type": "website"
202633            }
202634          ],
202635          "evidence": {},
202636          "signature": {
202637            "signature": {
202638              "publicKey": {}
202639            }
202640          },
202641          "modelCard": {
202642            "modelParameters": {
202643              "approach": {}
202644            },
202645            "quantitativeAnalysis": {
202646              "graphics": {}
202647            },
202648            "considerations": {}
202649          }
202650        },
202651        {
202652          "type": "library",
202653          "bom-ref": "pkg:npm/request@2.88.0?package-id=d960fbbc3970c57d",
202654          "supplier": {},
202655          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
202656          "name": "request",
202657          "version": "2.88.0",
202658          "description": "Simplified HTTP request client.",
202659          "licenses": [
202660            {
202661              "license": {
202662                "id": "Apache-2.0"
202663              }
202664            }
202665          ],
202666          "cpe": "cpe:2.3:a:request:request:2.88.0:*:*:*:*:*:*:*",
202667          "purl": "pkg:npm/request@2.88.0",
202668          "swid": {
202669            "attachment": {}
202670          },
202671          "pedigree": {},
202672          "externalReferences": [
202673            {
202674              "url": "git+https://github.com/request/request.git",
202675              "type": "distribution"
202676            },
202677            {
202678              "url": "https://github.com/request/request#readme",
202679              "type": "website"
202680            }
202681          ],
202682          "evidence": {},
202683          "signature": {
202684            "signature": {
202685              "publicKey": {}
202686            }
202687          },
202688          "modelCard": {
202689            "modelParameters": {
202690              "approach": {}
202691            },
202692            "quantitativeAnalysis": {
202693              "graphics": {}
202694            },
202695            "considerations": {}
202696          }
202697        },
202698        {
202699          "type": "library",
202700          "bom-ref": "pkg:npm/require-directory@2.1.1?package-id=bec44f06abee329",
202701          "supplier": {},
202702          "author": "Troy Goode \u003ctroygoode@gmail.com\u003e (http://github.com/troygoode/)",
202703          "name": "require-directory",
202704          "version": "2.1.1",
202705          "description": "Recursively iterates over specified directory, require()'ing each file, and returning a nested hash structure containing those modules.",
202706          "licenses": [
202707            {
202708              "license": {
202709                "id": "MIT"
202710              }
202711            }
202712          ],
202713          "cpe": "cpe:2.3:a:require-directory:require-directory:2.1.1:*:*:*:*:*:*:*",
202714          "purl": "pkg:npm/require-directory@2.1.1",
202715          "swid": {
202716            "attachment": {}
202717          },
202718          "pedigree": {},
202719          "externalReferences": [
202720            {
202721              "url": "git://github.com/troygoode/node-require-directory.git",
202722              "type": "distribution"
202723            },
202724            {
202725              "url": "https://github.com/troygoode/node-require-directory/",
202726              "type": "website"
202727            }
202728          ],
202729          "evidence": {},
202730          "signature": {
202731            "signature": {
202732              "publicKey": {}
202733            }
202734          },
202735          "modelCard": {
202736            "modelParameters": {
202737              "approach": {}
202738            },
202739            "quantitativeAnalysis": {
202740              "graphics": {}
202741            },
202742            "considerations": {}
202743          }
202744        },
202745        {
202746          "type": "library",
202747          "bom-ref": "pkg:npm/require-from-string@2.0.2?package-id=11e90a26bc88f3bb",
202748          "supplier": {},
202749          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
202750          "name": "require-from-string",
202751          "version": "2.0.2",
202752          "description": "Require module from string",
202753          "licenses": [
202754            {
202755              "license": {
202756                "id": "MIT"
202757              }
202758            }
202759          ],
202760          "cpe": "cpe:2.3:a:require-from-string:require-from-string:2.0.2:*:*:*:*:*:*:*",
202761          "purl": "pkg:npm/require-from-string@2.0.2",
202762          "swid": {
202763            "attachment": {}
202764          },
202765          "pedigree": {},
202766          "externalReferences": [
202767            {
202768              "url": "git+https://github.com/floatdrop/require-from-string.git",
202769              "type": "distribution"
202770            },
202771            {
202772              "url": "https://github.com/floatdrop/require-from-string#readme",
202773              "type": "website"
202774            }
202775          ],
202776          "evidence": {},
202777          "signature": {
202778            "signature": {
202779              "publicKey": {}
202780            }
202781          },
202782          "modelCard": {
202783            "modelParameters": {
202784              "approach": {}
202785            },
202786            "quantitativeAnalysis": {
202787              "graphics": {}
202788            },
202789            "considerations": {}
202790          }
202791        },
202792        {
202793          "type": "library",
202794          "bom-ref": "pkg:npm/require-main-filename@2.0.0?package-id=90371ac30591c486",
202795          "supplier": {},
202796          "author": "Ben Coe \u003cben@npmjs.com\u003e",
202797          "name": "require-main-filename",
202798          "version": "2.0.0",
202799          "description": "shim for require.main.filename() that works in as many environments as possible",
202800          "licenses": [
202801            {
202802              "license": {
202803                "id": "ISC"
202804              }
202805            }
202806          ],
202807          "cpe": "cpe:2.3:a:require-main-filename:require-main-filename:2.0.0:*:*:*:*:*:*:*",
202808          "purl": "pkg:npm/require-main-filename@2.0.0",
202809          "swid": {
202810            "attachment": {}
202811          },
202812          "pedigree": {},
202813          "externalReferences": [
202814            {
202815              "url": "git+ssh://git@github.com/yargs/require-main-filename.git",
202816              "type": "distribution"
202817            },
202818            {
202819              "url": "https://github.com/yargs/require-main-filename#readme",
202820              "type": "website"
202821            }
202822          ],
202823          "evidence": {},
202824          "signature": {
202825            "signature": {
202826              "publicKey": {}
202827            }
202828          },
202829          "modelCard": {
202830            "modelParameters": {
202831              "approach": {}
202832            },
202833            "quantitativeAnalysis": {
202834              "graphics": {}
202835            },
202836            "considerations": {}
202837          }
202838        },
202839        {
202840          "type": "library",
202841          "bom-ref": "pkg:npm/resolve@1.10.0?package-id=dd5261f69051c0d3",
202842          "supplier": {},
202843          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
202844          "name": "resolve",
202845          "version": "1.10.0",
202846          "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
202847          "licenses": [
202848            {
202849              "license": {
202850                "id": "MIT"
202851              }
202852            }
202853          ],
202854          "cpe": "cpe:2.3:a:browserify:resolve:1.10.0:*:*:*:*:*:*:*",
202855          "purl": "pkg:npm/resolve@1.10.0",
202856          "swid": {
202857            "attachment": {}
202858          },
202859          "pedigree": {},
202860          "externalReferences": [
202861            {
202862              "url": "git://github.com/browserify/resolve.git",
202863              "type": "distribution"
202864            },
202865            {
202866              "url": "https://github.com/browserify/resolve#readme",
202867              "type": "website"
202868            }
202869          ],
202870          "evidence": {},
202871          "signature": {
202872            "signature": {
202873              "publicKey": {}
202874            }
202875          },
202876          "modelCard": {
202877            "modelParameters": {
202878              "approach": {}
202879            },
202880            "quantitativeAnalysis": {
202881              "graphics": {}
202882            },
202883            "considerations": {}
202884          }
202885        },
202886        {
202887          "type": "library",
202888          "bom-ref": "pkg:npm/resolve-from@4.0.0?package-id=8184b04db20ef759",
202889          "supplier": {},
202890          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
202891          "name": "resolve-from",
202892          "version": "4.0.0",
202893          "description": "Resolve the path of a module like `require.resolve()` but from a given path",
202894          "licenses": [
202895            {
202896              "license": {
202897                "id": "MIT"
202898              }
202899            }
202900          ],
202901          "cpe": "cpe:2.3:a:resolve-from:resolve-from:4.0.0:*:*:*:*:*:*:*",
202902          "purl": "pkg:npm/resolve-from@4.0.0",
202903          "swid": {
202904            "attachment": {}
202905          },
202906          "pedigree": {},
202907          "externalReferences": [
202908            {
202909              "url": "git+https://github.com/sindresorhus/resolve-from.git",
202910              "type": "distribution"
202911            },
202912            {
202913              "url": "https://github.com/sindresorhus/resolve-from#readme",
202914              "type": "website"
202915            }
202916          ],
202917          "evidence": {},
202918          "signature": {
202919            "signature": {
202920              "publicKey": {}
202921            }
202922          },
202923          "modelCard": {
202924            "modelParameters": {
202925              "approach": {}
202926            },
202927            "quantitativeAnalysis": {
202928              "graphics": {}
202929            },
202930            "considerations": {}
202931          }
202932        },
202933        {
202934          "type": "library",
202935          "bom-ref": "pkg:npm/retry@0.10.1?package-id=baef3799d7cf16e1",
202936          "supplier": {},
202937          "author": "Tim Koschützki \u003ctim@debuggable.com\u003e (http://debuggable.com/)",
202938          "name": "retry",
202939          "version": "0.10.1",
202940          "description": "Abstraction for exponential and custom retry strategies for failed operations.",
202941          "licenses": [
202942            {
202943              "license": {
202944                "id": "MIT"
202945              }
202946            }
202947          ],
202948          "cpe": "cpe:2.3:a:tim-kos:retry:0.10.1:*:*:*:*:*:*:*",
202949          "purl": "pkg:npm/retry@0.10.1",
202950          "swid": {
202951            "attachment": {}
202952          },
202953          "pedigree": {},
202954          "externalReferences": [
202955            {
202956              "url": "git://github.com/tim-kos/node-retry.git",
202957              "type": "distribution"
202958            },
202959            {
202960              "url": "https://github.com/tim-kos/node-retry",
202961              "type": "website"
202962            }
202963          ],
202964          "evidence": {},
202965          "signature": {
202966            "signature": {
202967              "publicKey": {}
202968            }
202969          },
202970          "modelCard": {
202971            "modelParameters": {
202972              "approach": {}
202973            },
202974            "quantitativeAnalysis": {
202975              "graphics": {}
202976            },
202977            "considerations": {}
202978          }
202979        },
202980        {
202981          "type": "library",
202982          "bom-ref": "pkg:npm/retry@0.12.0?package-id=c3f319915fd297ec",
202983          "supplier": {},
202984          "author": "Tim Koschützki \u003ctim@debuggable.com\u003e (http://debuggable.com/)",
202985          "name": "retry",
202986          "version": "0.12.0",
202987          "description": "Abstraction for exponential and custom retry strategies for failed operations.",
202988          "licenses": [
202989            {
202990              "license": {
202991                "id": "MIT"
202992              }
202993            }
202994          ],
202995          "cpe": "cpe:2.3:a:tim-kos:retry:0.12.0:*:*:*:*:*:*:*",
202996          "purl": "pkg:npm/retry@0.12.0",
202997          "swid": {
202998            "attachment": {}
202999          },
203000          "pedigree": {},
203001          "externalReferences": [
203002            {
203003              "url": "git://github.com/tim-kos/node-retry.git",
203004              "type": "distribution"
203005            },
203006            {
203007              "url": "https://github.com/tim-kos/node-retry",
203008              "type": "website"
203009            }
203010          ],
203011          "evidence": {},
203012          "signature": {
203013            "signature": {
203014              "publicKey": {}
203015            }
203016          },
203017          "modelCard": {
203018            "modelParameters": {
203019              "approach": {}
203020            },
203021            "quantitativeAnalysis": {
203022              "graphics": {}
203023            },
203024            "considerations": {}
203025          }
203026        },
203027        {
203028          "type": "library",
203029          "bom-ref": "pkg:npm/rfdc@1.2.0?package-id=bda32043b343edc5",
203030          "supplier": {},
203031          "author": "David Mark Clements \u003cdavid.clements@nearform.com\u003e",
203032          "name": "rfdc",
203033          "version": "1.2.0",
203034          "description": "Really Fast Deep Clone",
203035          "licenses": [
203036            {
203037              "license": {
203038                "id": "MIT"
203039              }
203040            }
203041          ],
203042          "cpe": "cpe:2.3:a:davidmarkclements:rfdc:1.2.0:*:*:*:*:*:*:*",
203043          "purl": "pkg:npm/rfdc@1.2.0",
203044          "swid": {
203045            "attachment": {}
203046          },
203047          "pedigree": {},
203048          "externalReferences": [
203049            {
203050              "url": "git+https://github.com/davidmarkclements/rfdc.git",
203051              "type": "distribution"
203052            },
203053            {
203054              "url": "https://github.com/davidmarkclements/rfdc#readme",
203055              "type": "website"
203056            }
203057          ],
203058          "evidence": {},
203059          "signature": {
203060            "signature": {
203061              "publicKey": {}
203062            }
203063          },
203064          "modelCard": {
203065            "modelParameters": {
203066              "approach": {}
203067            },
203068            "quantitativeAnalysis": {
203069              "graphics": {}
203070            },
203071            "considerations": {}
203072          }
203073        },
203074        {
203075          "type": "library",
203076          "bom-ref": "pkg:npm/rimraf@2.7.1?package-id=be161be7f66aefcd",
203077          "supplier": {},
203078          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
203079          "name": "rimraf",
203080          "version": "2.7.1",
203081          "description": "A deep deletion module for node (like `rm -rf`)",
203082          "licenses": [
203083            {
203084              "license": {
203085                "id": "ISC"
203086              }
203087            }
203088          ],
203089          "cpe": "cpe:2.3:a:isaacs:rimraf:2.7.1:*:*:*:*:*:*:*",
203090          "purl": "pkg:npm/rimraf@2.7.1",
203091          "swid": {
203092            "attachment": {}
203093          },
203094          "pedigree": {},
203095          "externalReferences": [
203096            {
203097              "url": "git://github.com/isaacs/rimraf.git",
203098              "type": "distribution"
203099            },
203100            {
203101              "url": "https://github.com/isaacs/rimraf#readme",
203102              "type": "website"
203103            }
203104          ],
203105          "evidence": {},
203106          "signature": {
203107            "signature": {
203108              "publicKey": {}
203109            }
203110          },
203111          "modelCard": {
203112            "modelParameters": {
203113              "approach": {}
203114            },
203115            "quantitativeAnalysis": {
203116              "graphics": {}
203117            },
203118            "considerations": {}
203119          }
203120        },
203121        {
203122          "type": "library",
203123          "bom-ref": "pkg:npm/roarr@7.14.1?package-id=5025f686ab418801",
203124          "supplier": {},
203125          "author": "Gajus Kuizinas \u003cgajus@gajus.com\u003e (http://gajus.com)",
203126          "name": "roarr",
203127          "version": "7.14.1",
203128          "description": "JSON logger for Node.js and browser.",
203129          "licenses": [
203130            {
203131              "license": {
203132                "id": "BSD-3-Clause"
203133              }
203134            }
203135          ],
203136          "cpe": "cpe:2.3:a:gajus:roarr:7.14.1:*:*:*:*:*:*:*",
203137          "purl": "pkg:npm/roarr@7.14.1",
203138          "swid": {
203139            "attachment": {}
203140          },
203141          "pedigree": {},
203142          "externalReferences": [
203143            {
203144              "url": "git+ssh://git@github.com/gajus/roarr.git",
203145              "type": "distribution"
203146            },
203147            {
203148              "url": "https://github.com/gajus/roarr#readme",
203149              "type": "website"
203150            }
203151          ],
203152          "evidence": {},
203153          "signature": {
203154            "signature": {
203155              "publicKey": {}
203156            }
203157          },
203158          "modelCard": {
203159            "modelParameters": {
203160              "approach": {}
203161            },
203162            "quantitativeAnalysis": {
203163              "graphics": {}
203164            },
203165            "considerations": {}
203166          }
203167        },
203168        {
203169          "type": "library",
203170          "bom-ref": "pkg:npm/run-queue@1.0.3?package-id=442b305f6fbe55fa",
203171          "supplier": {},
203172          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
203173          "name": "run-queue",
203174          "version": "1.0.3",
203175          "description": "A promise based, dynamic priority queue runner, with concurrency limiting.",
203176          "licenses": [
203177            {
203178              "license": {
203179                "id": "ISC"
203180              }
203181            }
203182          ],
203183          "cpe": "cpe:2.3:a:run-queue:run-queue:1.0.3:*:*:*:*:*:*:*",
203184          "purl": "pkg:npm/run-queue@1.0.3",
203185          "swid": {
203186            "attachment": {}
203187          },
203188          "pedigree": {},
203189          "externalReferences": [
203190            {
203191              "url": "git+https://github.com/iarna/run-queue.git",
203192              "type": "distribution"
203193            },
203194            {
203195              "url": "https://npmjs.com/package/run-queue",
203196              "type": "website"
203197            }
203198          ],
203199          "evidence": {},
203200          "signature": {
203201            "signature": {
203202              "publicKey": {}
203203            }
203204          },
203205          "modelCard": {
203206            "modelParameters": {
203207              "approach": {}
203208            },
203209            "quantitativeAnalysis": {
203210              "graphics": {}
203211            },
203212            "considerations": {}
203213          }
203214        },
203215        {
203216          "type": "library",
203217          "bom-ref": "pkg:npm/rxjs@6.6.3?package-id=ff52683ef05bf27c",
203218          "supplier": {},
203219          "author": "Ben Lesh \u003cben@benlesh.com\u003e",
203220          "name": "rxjs",
203221          "version": "6.6.3",
203222          "description": "Reactive Extensions for modern JavaScript",
203223          "licenses": [
203224            {
203225              "license": {
203226                "id": "Apache-2.0"
203227              }
203228            }
203229          ],
203230          "cpe": "cpe:2.3:a:ReactiveX:rxjs:6.6.3:*:*:*:*:*:*:*",
203231          "purl": "pkg:npm/rxjs@6.6.3",
203232          "swid": {
203233            "attachment": {}
203234          },
203235          "pedigree": {},
203236          "externalReferences": [
203237            {
203238              "url": "git+https://github.com/reactivex/rxjs.git",
203239              "type": "distribution"
203240            },
203241            {
203242              "url": "https://github.com/ReactiveX/RxJS",
203243              "type": "website"
203244            }
203245          ],
203246          "evidence": {},
203247          "signature": {
203248            "signature": {
203249              "publicKey": {}
203250            }
203251          },
203252          "modelCard": {
203253            "modelParameters": {
203254              "approach": {}
203255            },
203256            "quantitativeAnalysis": {
203257              "graphics": {}
203258            },
203259            "considerations": {}
203260          }
203261        },
203262        {
203263          "type": "library",
203264          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=ad8e4b783ec0cc69",
203265          "supplier": {},
203266          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
203267          "name": "safe-buffer",
203268          "version": "5.1.2",
203269          "description": "Safer Node.js Buffer API",
203270          "licenses": [
203271            {
203272              "license": {
203273                "id": "MIT"
203274              }
203275            }
203276          ],
203277          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
203278          "purl": "pkg:npm/safe-buffer@5.1.2",
203279          "swid": {
203280            "attachment": {}
203281          },
203282          "pedigree": {},
203283          "externalReferences": [
203284            {
203285              "url": "git://github.com/feross/safe-buffer.git",
203286              "type": "distribution"
203287            },
203288            {
203289              "url": "https://github.com/feross/safe-buffer",
203290              "type": "website"
203291            }
203292          ],
203293          "evidence": {},
203294          "signature": {
203295            "signature": {
203296              "publicKey": {}
203297            }
203298          },
203299          "modelCard": {
203300            "modelParameters": {
203301              "approach": {}
203302            },
203303            "quantitativeAnalysis": {
203304              "graphics": {}
203305            },
203306            "considerations": {}
203307          }
203308        },
203309        {
203310          "type": "library",
203311          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=e80d2a70105aad97",
203312          "supplier": {},
203313          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
203314          "name": "safe-buffer",
203315          "version": "5.1.2",
203316          "description": "Safer Node.js Buffer API",
203317          "licenses": [
203318            {
203319              "license": {
203320                "id": "MIT"
203321              }
203322            }
203323          ],
203324          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
203325          "purl": "pkg:npm/safe-buffer@5.1.2",
203326          "swid": {
203327            "attachment": {}
203328          },
203329          "pedigree": {},
203330          "externalReferences": [
203331            {
203332              "url": "git://github.com/feross/safe-buffer.git",
203333              "type": "distribution"
203334            },
203335            {
203336              "url": "https://github.com/feross/safe-buffer",
203337              "type": "website"
203338            }
203339          ],
203340          "evidence": {},
203341          "signature": {
203342            "signature": {
203343              "publicKey": {}
203344            }
203345          },
203346          "modelCard": {
203347            "modelParameters": {
203348              "approach": {}
203349            },
203350            "quantitativeAnalysis": {
203351              "graphics": {}
203352            },
203353            "considerations": {}
203354          }
203355        },
203356        {
203357          "type": "library",
203358          "bom-ref": "pkg:npm/safe-buffer@5.2.0?package-id=516952fe04a9e096",
203359          "supplier": {},
203360          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
203361          "name": "safe-buffer",
203362          "version": "5.2.0",
203363          "description": "Safer Node.js Buffer API",
203364          "licenses": [
203365            {
203366              "license": {
203367                "id": "MIT"
203368              }
203369            }
203370          ],
203371          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.0:*:*:*:*:*:*:*",
203372          "purl": "pkg:npm/safe-buffer@5.2.0",
203373          "swid": {
203374            "attachment": {}
203375          },
203376          "pedigree": {},
203377          "externalReferences": [
203378            {
203379              "url": "git://github.com/feross/safe-buffer.git",
203380              "type": "distribution"
203381            },
203382            {
203383              "url": "https://github.com/feross/safe-buffer",
203384              "type": "website"
203385            }
203386          ],
203387          "evidence": {},
203388          "signature": {
203389            "signature": {
203390              "publicKey": {}
203391            }
203392          },
203393          "modelCard": {
203394            "modelParameters": {
203395              "approach": {}
203396            },
203397            "quantitativeAnalysis": {
203398              "graphics": {}
203399            },
203400            "considerations": {}
203401          }
203402        },
203403        {
203404          "type": "library",
203405          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=dea359a9da63b3e8",
203406          "supplier": {},
203407          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
203408          "name": "safe-buffer",
203409          "version": "5.2.1",
203410          "description": "Safer Node.js Buffer API",
203411          "licenses": [
203412            {
203413              "license": {
203414                "id": "MIT"
203415              }
203416            }
203417          ],
203418          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
203419          "purl": "pkg:npm/safe-buffer@5.2.1",
203420          "swid": {
203421            "attachment": {}
203422          },
203423          "pedigree": {},
203424          "externalReferences": [
203425            {
203426              "url": "git://github.com/feross/safe-buffer.git",
203427              "type": "distribution"
203428            },
203429            {
203430              "url": "https://github.com/feross/safe-buffer",
203431              "type": "website"
203432            }
203433          ],
203434          "evidence": {},
203435          "signature": {
203436            "signature": {
203437              "publicKey": {}
203438            }
203439          },
203440          "modelCard": {
203441            "modelParameters": {
203442              "approach": {}
203443            },
203444            "quantitativeAnalysis": {
203445              "graphics": {}
203446            },
203447            "considerations": {}
203448          }
203449        },
203450        {
203451          "type": "library",
203452          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=5521c324233fe89",
203453          "supplier": {},
203454          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
203455          "name": "safe-buffer",
203456          "version": "5.2.1",
203457          "description": "Safer Node.js Buffer API",
203458          "licenses": [
203459            {
203460              "license": {
203461                "id": "MIT"
203462              }
203463            }
203464          ],
203465          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
203466          "purl": "pkg:npm/safe-buffer@5.2.1",
203467          "swid": {
203468            "attachment": {}
203469          },
203470          "pedigree": {},
203471          "externalReferences": [
203472            {
203473              "url": "git://github.com/feross/safe-buffer.git",
203474              "type": "distribution"
203475            },
203476            {
203477              "url": "https://github.com/feross/safe-buffer",
203478              "type": "website"
203479            }
203480          ],
203481          "evidence": {},
203482          "signature": {
203483            "signature": {
203484              "publicKey": {}
203485            }
203486          },
203487          "modelCard": {
203488            "modelParameters": {
203489              "approach": {}
203490            },
203491            "quantitativeAnalysis": {
203492              "graphics": {}
203493            },
203494            "considerations": {}
203495          }
203496        },
203497        {
203498          "type": "library",
203499          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=94bc01ba89de1a5",
203500          "supplier": {},
203501          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
203502          "name": "safe-buffer",
203503          "version": "5.2.1",
203504          "description": "Safer Node.js Buffer API",
203505          "licenses": [
203506            {
203507              "license": {
203508                "id": "MIT"
203509              }
203510            }
203511          ],
203512          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
203513          "purl": "pkg:npm/safe-buffer@5.2.1",
203514          "swid": {
203515            "attachment": {}
203516          },
203517          "pedigree": {},
203518          "externalReferences": [
203519            {
203520              "url": "git://github.com/feross/safe-buffer.git",
203521              "type": "distribution"
203522            },
203523            {
203524              "url": "https://github.com/feross/safe-buffer",
203525              "type": "website"
203526            }
203527          ],
203528          "evidence": {},
203529          "signature": {
203530            "signature": {
203531              "publicKey": {}
203532            }
203533          },
203534          "modelCard": {
203535            "modelParameters": {
203536              "approach": {}
203537            },
203538            "quantitativeAnalysis": {
203539              "graphics": {}
203540            },
203541            "considerations": {}
203542          }
203543        },
203544        {
203545          "type": "library",
203546          "bom-ref": "pkg:npm/safe-stable-stringify@2.4.1?package-id=6c481e7270221230",
203547          "supplier": {},
203548          "author": "Ruben Bridgewater",
203549          "name": "safe-stable-stringify",
203550          "version": "2.4.1",
203551          "description": "Deterministic and safely JSON.stringify to quickly serialize JavaScript objects",
203552          "licenses": [
203553            {
203554              "license": {
203555                "id": "MIT"
203556              }
203557            }
203558          ],
203559          "cpe": "cpe:2.3:a:safe-stable-stringify:safe-stable-stringify:2.4.1:*:*:*:*:*:*:*",
203560          "purl": "pkg:npm/safe-stable-stringify@2.4.1",
203561          "swid": {
203562            "attachment": {}
203563          },
203564          "pedigree": {},
203565          "externalReferences": [
203566            {
203567              "url": "git+https://github.com/BridgeAR/safe-stable-stringify.git",
203568              "type": "distribution"
203569            },
203570            {
203571              "url": "https://github.com/BridgeAR/safe-stable-stringify#readme",
203572              "type": "website"
203573            }
203574          ],
203575          "evidence": {},
203576          "signature": {
203577            "signature": {
203578              "publicKey": {}
203579            }
203580          },
203581          "modelCard": {
203582            "modelParameters": {
203583              "approach": {}
203584            },
203585            "quantitativeAnalysis": {
203586              "graphics": {}
203587            },
203588            "considerations": {}
203589          }
203590        },
203591        {
203592          "type": "library",
203593          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=7c597e987a69726c",
203594          "supplier": {},
203595          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
203596          "name": "safer-buffer",
203597          "version": "2.1.2",
203598          "description": "Modern Buffer API polyfill without footguns",
203599          "licenses": [
203600            {
203601              "license": {
203602                "id": "MIT"
203603              }
203604            }
203605          ],
203606          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
203607          "purl": "pkg:npm/safer-buffer@2.1.2",
203608          "swid": {
203609            "attachment": {}
203610          },
203611          "pedigree": {},
203612          "externalReferences": [
203613            {
203614              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
203615              "type": "distribution"
203616            },
203617            {
203618              "url": "https://github.com/ChALkeR/safer-buffer#readme",
203619              "type": "website"
203620            }
203621          ],
203622          "evidence": {},
203623          "signature": {
203624            "signature": {
203625              "publicKey": {}
203626            }
203627          },
203628          "modelCard": {
203629            "modelParameters": {
203630              "approach": {}
203631            },
203632            "quantitativeAnalysis": {
203633              "graphics": {}
203634            },
203635            "considerations": {}
203636          }
203637        },
203638        {
203639          "type": "library",
203640          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=1bec84d27ea929ed",
203641          "supplier": {},
203642          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
203643          "name": "safer-buffer",
203644          "version": "2.1.2",
203645          "description": "Modern Buffer API polyfill without footguns",
203646          "licenses": [
203647            {
203648              "license": {
203649                "id": "MIT"
203650              }
203651            }
203652          ],
203653          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
203654          "purl": "pkg:npm/safer-buffer@2.1.2",
203655          "swid": {
203656            "attachment": {}
203657          },
203658          "pedigree": {},
203659          "externalReferences": [
203660            {
203661              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
203662              "type": "distribution"
203663            },
203664            {
203665              "url": "https://github.com/ChALkeR/safer-buffer#readme",
203666              "type": "website"
203667            }
203668          ],
203669          "evidence": {},
203670          "signature": {
203671            "signature": {
203672              "publicKey": {}
203673            }
203674          },
203675          "modelCard": {
203676            "modelParameters": {
203677              "approach": {}
203678            },
203679            "quantitativeAnalysis": {
203680              "graphics": {}
203681            },
203682            "considerations": {}
203683          }
203684        },
203685        {
203686          "type": "library",
203687          "bom-ref": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.1\u0026package-id=e903138d19e85b80",
203688          "supplier": {},
203689          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
203690          "name": "scanelf",
203691          "version": "1.3.5-r1",
203692          "description": "Scan ELF binaries for stuff",
203693          "licenses": [
203694            {
203695              "license": {
203696                "id": "GPL-2.0-only"
203697              }
203698            }
203699          ],
203700          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.5-r1:*:*:*:*:*:*:*",
203701          "purl": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.1",
203702          "swid": {
203703            "attachment": {}
203704          },
203705          "pedigree": {},
203706          "externalReferences": [
203707            {
203708              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
203709              "type": "distribution"
203710            }
203711          ],
203712          "evidence": {},
203713          "signature": {
203714            "signature": {
203715              "publicKey": {}
203716            }
203717          },
203718          "modelCard": {
203719            "modelParameters": {
203720              "approach": {}
203721            },
203722            "quantitativeAnalysis": {
203723              "graphics": {}
203724            },
203725            "considerations": {}
203726          }
203727        },
203728        {
203729          "type": "library",
203730          "bom-ref": "pkg:npm/semver@5.7.1?package-id=3d4365fad3b89b36",
203731          "supplier": {},
203732          "name": "semver",
203733          "version": "5.7.1",
203734          "description": "The semantic version parser used by npm.",
203735          "licenses": [
203736            {
203737              "license": {
203738                "id": "ISC"
203739              }
203740            }
203741          ],
203742          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
203743          "purl": "pkg:npm/semver@5.7.1",
203744          "swid": {
203745            "attachment": {}
203746          },
203747          "pedigree": {},
203748          "externalReferences": [
203749            {
203750              "url": "git+https://github.com/npm/node-semver.git",
203751              "type": "distribution"
203752            },
203753            {
203754              "url": "https://github.com/npm/node-semver#readme",
203755              "type": "website"
203756            }
203757          ],
203758          "evidence": {},
203759          "signature": {
203760            "signature": {
203761              "publicKey": {}
203762            }
203763          },
203764          "modelCard": {
203765            "modelParameters": {
203766              "approach": {}
203767            },
203768            "quantitativeAnalysis": {
203769              "graphics": {}
203770            },
203771            "considerations": {}
203772          }
203773        },
203774        {
203775          "type": "library",
203776          "bom-ref": "pkg:npm/semver-compare@1.0.0?package-id=e18fbcae955a3a19",
203777          "supplier": {},
203778          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
203779          "name": "semver-compare",
203780          "version": "1.0.0",
203781          "description": "compare two semver version strings, returning -1, 0, or 1",
203782          "licenses": [
203783            {
203784              "license": {
203785                "id": "MIT"
203786              }
203787            }
203788          ],
203789          "cpe": "cpe:2.3:a:semver-compare:semver-compare:1.0.0:*:*:*:*:*:*:*",
203790          "purl": "pkg:npm/semver-compare@1.0.0",
203791          "swid": {
203792            "attachment": {}
203793          },
203794          "pedigree": {},
203795          "externalReferences": [
203796            {
203797              "url": "git://github.com/substack/semver-compare.git",
203798              "type": "distribution"
203799            },
203800            {
203801              "url": "https://github.com/substack/semver-compare",
203802              "type": "website"
203803            }
203804          ],
203805          "evidence": {},
203806          "signature": {
203807            "signature": {
203808              "publicKey": {}
203809            }
203810          },
203811          "modelCard": {
203812            "modelParameters": {
203813              "approach": {}
203814            },
203815            "quantitativeAnalysis": {
203816              "graphics": {}
203817            },
203818            "considerations": {}
203819          }
203820        },
203821        {
203822          "type": "library",
203823          "bom-ref": "pkg:npm/semver-diff@2.1.0?package-id=8addb1f46fbb0950",
203824          "supplier": {},
203825          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (http://sindresorhus.com)",
203826          "name": "semver-diff",
203827          "version": "2.1.0",
203828          "description": "Get the diff type of two semver versions: 0.0.1 0.0.2 → patch",
203829          "licenses": [
203830            {
203831              "license": {
203832                "id": "MIT"
203833              }
203834            }
203835          ],
203836          "cpe": "cpe:2.3:a:sindresorhus:semver-diff:2.1.0:*:*:*:*:*:*:*",
203837          "purl": "pkg:npm/semver-diff@2.1.0",
203838          "swid": {
203839            "attachment": {}
203840          },
203841          "pedigree": {},
203842          "externalReferences": [
203843            {
203844              "url": "git+https://github.com/sindresorhus/semver-diff.git",
203845              "type": "distribution"
203846            },
203847            {
203848              "url": "https://github.com/sindresorhus/semver-diff#readme",
203849              "type": "website"
203850            }
203851          ],
203852          "evidence": {},
203853          "signature": {
203854            "signature": {
203855              "publicKey": {}
203856            }
203857          },
203858          "modelCard": {
203859            "modelParameters": {
203860              "approach": {}
203861            },
203862            "quantitativeAnalysis": {
203863              "graphics": {}
203864            },
203865            "considerations": {}
203866          }
203867        },
203868        {
203869          "type": "library",
203870          "bom-ref": "pkg:npm/send@0.17.1?package-id=39fd424f16226051",
203871          "supplier": {},
203872          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
203873          "name": "send",
203874          "version": "0.17.1",
203875          "description": "Better streaming static file server with Range and conditional-GET support",
203876          "licenses": [
203877            {
203878              "license": {
203879                "id": "MIT"
203880              }
203881            }
203882          ],
203883          "cpe": "cpe:2.3:a:pillarjs:send:0.17.1:*:*:*:*:*:*:*",
203884          "purl": "pkg:npm/send@0.17.1",
203885          "swid": {
203886            "attachment": {}
203887          },
203888          "pedigree": {},
203889          "externalReferences": [
203890            {
203891              "url": "git+https://github.com/pillarjs/send.git",
203892              "type": "distribution"
203893            },
203894            {
203895              "url": "https://github.com/pillarjs/send#readme",
203896              "type": "website"
203897            }
203898          ],
203899          "evidence": {},
203900          "signature": {
203901            "signature": {
203902              "publicKey": {}
203903            }
203904          },
203905          "modelCard": {
203906            "modelParameters": {
203907              "approach": {}
203908            },
203909            "quantitativeAnalysis": {
203910              "graphics": {}
203911            },
203912            "considerations": {}
203913          }
203914        },
203915        {
203916          "type": "library",
203917          "bom-ref": "pkg:npm/serialize-error@8.1.0?package-id=e5fdc9cccc69c57b",
203918          "supplier": {},
203919          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
203920          "name": "serialize-error",
203921          "version": "8.1.0",
203922          "description": "Serialize/deserialize an error into a plain object",
203923          "licenses": [
203924            {
203925              "license": {
203926                "id": "MIT"
203927              }
203928            }
203929          ],
203930          "cpe": "cpe:2.3:a:serialize-error:serialize-error:8.1.0:*:*:*:*:*:*:*",
203931          "purl": "pkg:npm/serialize-error@8.1.0",
203932          "swid": {
203933            "attachment": {}
203934          },
203935          "pedigree": {},
203936          "externalReferences": [
203937            {
203938              "url": "git+https://github.com/sindresorhus/serialize-error.git",
203939              "type": "distribution"
203940            },
203941            {
203942              "url": "https://github.com/sindresorhus/serialize-error#readme",
203943              "type": "website"
203944            }
203945          ],
203946          "evidence": {},
203947          "signature": {
203948            "signature": {
203949              "publicKey": {}
203950            }
203951          },
203952          "modelCard": {
203953            "modelParameters": {
203954              "approach": {}
203955            },
203956            "quantitativeAnalysis": {
203957              "graphics": {}
203958            },
203959            "considerations": {}
203960          }
203961        },
203962        {
203963          "type": "library",
203964          "bom-ref": "pkg:npm/serve-static@1.14.1?package-id=8a14231746896ad1",
203965          "supplier": {},
203966          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
203967          "name": "serve-static",
203968          "version": "1.14.1",
203969          "description": "Serve static files",
203970          "licenses": [
203971            {
203972              "license": {
203973                "id": "MIT"
203974              }
203975            }
203976          ],
203977          "cpe": "cpe:2.3:a:serve-static:serve-static:1.14.1:*:*:*:*:*:*:*",
203978          "purl": "pkg:npm/serve-static@1.14.1",
203979          "swid": {
203980            "attachment": {}
203981          },
203982          "pedigree": {},
203983          "externalReferences": [
203984            {
203985              "url": "git+https://github.com/expressjs/serve-static.git",
203986              "type": "distribution"
203987            },
203988            {
203989              "url": "https://github.com/expressjs/serve-static#readme",
203990              "type": "website"
203991            }
203992          ],
203993          "evidence": {},
203994          "signature": {
203995            "signature": {
203996              "publicKey": {}
203997            }
203998          },
203999          "modelCard": {
204000            "modelParameters": {
204001              "approach": {}
204002            },
204003            "quantitativeAnalysis": {
204004              "graphics": {}
204005            },
204006            "considerations": {}
204007          }
204008        },
204009        {
204010          "type": "library",
204011          "bom-ref": "pkg:npm/set-blocking@2.0.0?package-id=bac85cbb844de9c9",
204012          "supplier": {},
204013          "author": "Ben Coe \u003cben@npmjs.com\u003e",
204014          "name": "set-blocking",
204015          "version": "2.0.0",
204016          "description": "set blocking stdio and stderr ensuring that terminal output does not truncate",
204017          "licenses": [
204018            {
204019              "license": {
204020                "id": "ISC"
204021              }
204022            }
204023          ],
204024          "cpe": "cpe:2.3:a:set-blocking:set-blocking:2.0.0:*:*:*:*:*:*:*",
204025          "purl": "pkg:npm/set-blocking@2.0.0",
204026          "swid": {
204027            "attachment": {}
204028          },
204029          "pedigree": {},
204030          "externalReferences": [
204031            {
204032              "url": "git+https://github.com/yargs/set-blocking.git",
204033              "type": "distribution"
204034            },
204035            {
204036              "url": "https://github.com/yargs/set-blocking#readme",
204037              "type": "website"
204038            }
204039          ],
204040          "evidence": {},
204041          "signature": {
204042            "signature": {
204043              "publicKey": {}
204044            }
204045          },
204046          "modelCard": {
204047            "modelParameters": {
204048              "approach": {}
204049            },
204050            "quantitativeAnalysis": {
204051              "graphics": {}
204052            },
204053            "considerations": {}
204054          }
204055        },
204056        {
204057          "type": "library",
204058          "bom-ref": "pkg:npm/setprototypeof@1.1.1?package-id=48c9427615459103",
204059          "supplier": {},
204060          "author": "Wes Todd",
204061          "name": "setprototypeof",
204062          "version": "1.1.1",
204063          "description": "A small polyfill for Object.setprototypeof",
204064          "licenses": [
204065            {
204066              "license": {
204067                "id": "ISC"
204068              }
204069            }
204070          ],
204071          "cpe": "cpe:2.3:a:setprototypeof:setprototypeof:1.1.1:*:*:*:*:*:*:*",
204072          "purl": "pkg:npm/setprototypeof@1.1.1",
204073          "swid": {
204074            "attachment": {}
204075          },
204076          "pedigree": {},
204077          "externalReferences": [
204078            {
204079              "url": "git+https://github.com/wesleytodd/setprototypeof.git",
204080              "type": "distribution"
204081            },
204082            {
204083              "url": "https://github.com/wesleytodd/setprototypeof",
204084              "type": "website"
204085            }
204086          ],
204087          "evidence": {},
204088          "signature": {
204089            "signature": {
204090              "publicKey": {}
204091            }
204092          },
204093          "modelCard": {
204094            "modelParameters": {
204095              "approach": {}
204096            },
204097            "quantitativeAnalysis": {
204098              "graphics": {}
204099            },
204100            "considerations": {}
204101          }
204102        },
204103        {
204104          "type": "library",
204105          "bom-ref": "pkg:npm/sha@3.0.0?package-id=64341d7e8de754f6",
204106          "supplier": {},
204107          "name": "sha",
204108          "version": "3.0.0",
204109          "description": "Check and get file hashes",
204110          "licenses": [
204111            {
204112              "license": {
204113                "name": "(BSD-2-Clause OR MIT)"
204114              }
204115            }
204116          ],
204117          "cpe": "cpe:2.3:a:ForbesLindesay:sha:3.0.0:*:*:*:*:*:*:*",
204118          "purl": "pkg:npm/sha@3.0.0",
204119          "swid": {
204120            "attachment": {}
204121          },
204122          "pedigree": {},
204123          "externalReferences": [
204124            {
204125              "url": "git+https://github.com/ForbesLindesay/sha.git",
204126              "type": "distribution"
204127            },
204128            {
204129              "url": "https://github.com/ForbesLindesay/sha#readme",
204130              "type": "website"
204131            }
204132          ],
204133          "evidence": {},
204134          "signature": {
204135            "signature": {
204136              "publicKey": {}
204137            }
204138          },
204139          "modelCard": {
204140            "modelParameters": {
204141              "approach": {}
204142            },
204143            "quantitativeAnalysis": {
204144              "graphics": {}
204145            },
204146            "considerations": {}
204147          }
204148        },
204149        {
204150          "type": "library",
204151          "bom-ref": "pkg:npm/shebang-command@1.2.0?package-id=31728ea7868ca29",
204152          "supplier": {},
204153          "author": "Kevin Martensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
204154          "name": "shebang-command",
204155          "version": "1.2.0",
204156          "description": "Get the command from a shebang",
204157          "licenses": [
204158            {
204159              "license": {
204160                "id": "MIT"
204161              }
204162            }
204163          ],
204164          "cpe": "cpe:2.3:a:shebang-command:shebang-command:1.2.0:*:*:*:*:*:*:*",
204165          "purl": "pkg:npm/shebang-command@1.2.0",
204166          "swid": {
204167            "attachment": {}
204168          },
204169          "pedigree": {},
204170          "externalReferences": [
204171            {
204172              "url": "git+https://github.com/kevva/shebang-command.git",
204173              "type": "distribution"
204174            },
204175            {
204176              "url": "https://github.com/kevva/shebang-command#readme",
204177              "type": "website"
204178            }
204179          ],
204180          "evidence": {},
204181          "signature": {
204182            "signature": {
204183              "publicKey": {}
204184            }
204185          },
204186          "modelCard": {
204187            "modelParameters": {
204188              "approach": {}
204189            },
204190            "quantitativeAnalysis": {
204191              "graphics": {}
204192            },
204193            "considerations": {}
204194          }
204195        },
204196        {
204197          "type": "library",
204198          "bom-ref": "pkg:npm/shebang-regex@1.0.0?package-id=3ee6cea199436243",
204199          "supplier": {},
204200          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
204201          "name": "shebang-regex",
204202          "version": "1.0.0",
204203          "description": "Regular expression for matching a shebang",
204204          "licenses": [
204205            {
204206              "license": {
204207                "id": "MIT"
204208              }
204209            }
204210          ],
204211          "cpe": "cpe:2.3:a:shebang-regex:shebang-regex:1.0.0:*:*:*:*:*:*:*",
204212          "purl": "pkg:npm/shebang-regex@1.0.0",
204213          "swid": {
204214            "attachment": {}
204215          },
204216          "pedigree": {},
204217          "externalReferences": [
204218            {
204219              "url": "git+https://github.com/sindresorhus/shebang-regex.git",
204220              "type": "distribution"
204221            },
204222            {
204223              "url": "https://github.com/sindresorhus/shebang-regex#readme",
204224              "type": "website"
204225            }
204226          ],
204227          "evidence": {},
204228          "signature": {
204229            "signature": {
204230              "publicKey": {}
204231            }
204232          },
204233          "modelCard": {
204234            "modelParameters": {
204235              "approach": {}
204236            },
204237            "quantitativeAnalysis": {
204238              "graphics": {}
204239            },
204240            "considerations": {}
204241          }
204242        },
204243        {
204244          "type": "library",
204245          "bom-ref": "pkg:npm/signal-exit@3.0.2?package-id=5f81e92f345b2dca",
204246          "supplier": {},
204247          "author": "Ben Coe \u003cben@npmjs.com\u003e",
204248          "name": "signal-exit",
204249          "version": "3.0.2",
204250          "description": "when you want to fire an event no matter how a process exits.",
204251          "licenses": [
204252            {
204253              "license": {
204254                "id": "ISC"
204255              }
204256            }
204257          ],
204258          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.2:*:*:*:*:*:*:*",
204259          "purl": "pkg:npm/signal-exit@3.0.2",
204260          "swid": {
204261            "attachment": {}
204262          },
204263          "pedigree": {},
204264          "externalReferences": [
204265            {
204266              "url": "git+https://github.com/tapjs/signal-exit.git",
204267              "type": "distribution"
204268            },
204269            {
204270              "url": "https://github.com/tapjs/signal-exit",
204271              "type": "website"
204272            }
204273          ],
204274          "evidence": {},
204275          "signature": {
204276            "signature": {
204277              "publicKey": {}
204278            }
204279          },
204280          "modelCard": {
204281            "modelParameters": {
204282              "approach": {}
204283            },
204284            "quantitativeAnalysis": {
204285              "graphics": {}
204286            },
204287            "considerations": {}
204288          }
204289        },
204290        {
204291          "type": "library",
204292          "bom-ref": "pkg:npm/slide@1.1.6?package-id=67c80effc5f2e06c",
204293          "supplier": {},
204294          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
204295          "name": "slide",
204296          "version": "1.1.6",
204297          "description": "A flow control lib small enough to fit on in a slide presentation. Derived live at Oak.JS",
204298          "licenses": [
204299            {
204300              "license": {
204301                "id": "ISC"
204302              }
204303            }
204304          ],
204305          "cpe": "cpe:2.3:a:isaacs:slide:1.1.6:*:*:*:*:*:*:*",
204306          "purl": "pkg:npm/slide@1.1.6",
204307          "swid": {
204308            "attachment": {}
204309          },
204310          "pedigree": {},
204311          "externalReferences": [
204312            {
204313              "url": "git://github.com/isaacs/slide-flow-control.git",
204314              "type": "distribution"
204315            },
204316            {
204317              "url": "https://github.com/isaacs/slide-flow-control#readme",
204318              "type": "website"
204319            }
204320          ],
204321          "evidence": {},
204322          "signature": {
204323            "signature": {
204324              "publicKey": {}
204325            }
204326          },
204327          "modelCard": {
204328            "modelParameters": {
204329              "approach": {}
204330            },
204331            "quantitativeAnalysis": {
204332              "graphics": {}
204333            },
204334            "considerations": {}
204335          }
204336        },
204337        {
204338          "type": "library",
204339          "bom-ref": "pkg:npm/smart-buffer@4.1.0?package-id=8a098cd7b95880b2",
204340          "supplier": {},
204341          "author": "Josh Glazebrook",
204342          "name": "smart-buffer",
204343          "version": "4.1.0",
204344          "description": "smart-buffer is a Buffer wrapper that adds automatic read \u0026 write offset tracking, string operations, data insertions, and more.",
204345          "licenses": [
204346            {
204347              "license": {
204348                "id": "MIT"
204349              }
204350            }
204351          ],
204352          "cpe": "cpe:2.3:a:JoshGlazebrook:smart-buffer:4.1.0:*:*:*:*:*:*:*",
204353          "purl": "pkg:npm/smart-buffer@4.1.0",
204354          "swid": {
204355            "attachment": {}
204356          },
204357          "pedigree": {},
204358          "externalReferences": [
204359            {
204360              "url": "git+https://github.com/JoshGlazebrook/smart-buffer.git",
204361              "type": "distribution"
204362            },
204363            {
204364              "url": "https://github.com/JoshGlazebrook/smart-buffer/",
204365              "type": "website"
204366            }
204367          ],
204368          "evidence": {},
204369          "signature": {
204370            "signature": {
204371              "publicKey": {}
204372            }
204373          },
204374          "modelCard": {
204375            "modelParameters": {
204376              "approach": {}
204377            },
204378            "quantitativeAnalysis": {
204379              "graphics": {}
204380            },
204381            "considerations": {}
204382          }
204383        },
204384        {
204385          "type": "library",
204386          "bom-ref": "pkg:npm/socks@2.3.3?package-id=df90bddac1fc2e9b",
204387          "supplier": {},
204388          "author": "Josh Glazebrook",
204389          "name": "socks",
204390          "version": "2.3.3",
204391          "description": "Fully featured SOCKS proxy client supporting SOCKSv4, SOCKSv4a, and SOCKSv5. Includes Bind and Associate functionality.",
204392          "licenses": [
204393            {
204394              "license": {
204395                "id": "MIT"
204396              }
204397            }
204398          ],
204399          "cpe": "cpe:2.3:a:JoshGlazebrook:socks:2.3.3:*:*:*:*:*:*:*",
204400          "purl": "pkg:npm/socks@2.3.3",
204401          "swid": {
204402            "attachment": {}
204403          },
204404          "pedigree": {},
204405          "externalReferences": [
204406            {
204407              "url": "git+https://github.com/JoshGlazebrook/socks.git",
204408              "type": "distribution"
204409            },
204410            {
204411              "url": "https://github.com/JoshGlazebrook/socks/",
204412              "type": "website"
204413            }
204414          ],
204415          "evidence": {},
204416          "signature": {
204417            "signature": {
204418              "publicKey": {}
204419            }
204420          },
204421          "modelCard": {
204422            "modelParameters": {
204423              "approach": {}
204424            },
204425            "quantitativeAnalysis": {
204426              "graphics": {}
204427            },
204428            "considerations": {}
204429          }
204430        },
204431        {
204432          "type": "library",
204433          "bom-ref": "pkg:npm/socks-proxy-agent@4.0.2?package-id=467552ce30535bfb",
204434          "supplier": {},
204435          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
204436          "name": "socks-proxy-agent",
204437          "version": "4.0.2",
204438          "description": "A SOCKS proxy `http.Agent` implementation for HTTP and HTTPS",
204439          "licenses": [
204440            {
204441              "license": {
204442                "id": "MIT"
204443              }
204444            }
204445          ],
204446          "cpe": "cpe:2.3:a:socks-proxy-agent:socks-proxy-agent:4.0.2:*:*:*:*:*:*:*",
204447          "purl": "pkg:npm/socks-proxy-agent@4.0.2",
204448          "swid": {
204449            "attachment": {}
204450          },
204451          "pedigree": {},
204452          "externalReferences": [
204453            {
204454              "url": "git://github.com/TooTallNate/node-socks-proxy-agent.git",
204455              "type": "distribution"
204456            },
204457            {
204458              "url": "https://github.com/TooTallNate/node-socks-proxy-agent#readme",
204459              "type": "website"
204460            }
204461          ],
204462          "evidence": {},
204463          "signature": {
204464            "signature": {
204465              "publicKey": {}
204466            }
204467          },
204468          "modelCard": {
204469            "modelParameters": {
204470              "approach": {}
204471            },
204472            "quantitativeAnalysis": {
204473              "graphics": {}
204474            },
204475            "considerations": {}
204476          }
204477        },
204478        {
204479          "type": "library",
204480          "bom-ref": "pkg:npm/sorted-object@2.0.1?package-id=b1d8024e52e50f32",
204481          "supplier": {},
204482          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me/)",
204483          "name": "sorted-object",
204484          "version": "2.0.1",
204485          "description": "Returns a copy of an object with its keys sorted",
204486          "licenses": [
204487            {
204488              "license": {
204489                "name": "(WTFPL OR MIT)"
204490              }
204491            }
204492          ],
204493          "cpe": "cpe:2.3:a:sorted-object:sorted-object:2.0.1:*:*:*:*:*:*:*",
204494          "purl": "pkg:npm/sorted-object@2.0.1",
204495          "swid": {
204496            "attachment": {}
204497          },
204498          "pedigree": {},
204499          "externalReferences": [
204500            {
204501              "url": "git+https://github.com/domenic/sorted-object.git",
204502              "type": "distribution"
204503            },
204504            {
204505              "url": "https://github.com/domenic/sorted-object#readme",
204506              "type": "website"
204507            }
204508          ],
204509          "evidence": {},
204510          "signature": {
204511            "signature": {
204512              "publicKey": {}
204513            }
204514          },
204515          "modelCard": {
204516            "modelParameters": {
204517              "approach": {}
204518            },
204519            "quantitativeAnalysis": {
204520              "graphics": {}
204521            },
204522            "considerations": {}
204523          }
204524        },
204525        {
204526          "type": "library",
204527          "bom-ref": "pkg:npm/sorted-union-stream@2.1.3?package-id=6fde9400f65d4713",
204528          "supplier": {},
204529          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
204530          "name": "sorted-union-stream",
204531          "version": "2.1.3",
204532          "description": "Get the union of two sorted streams",
204533          "licenses": [
204534            {
204535              "license": {
204536                "id": "MIT"
204537              }
204538            }
204539          ],
204540          "cpe": "cpe:2.3:a:sorted-union-stream:sorted-union-stream:2.1.3:*:*:*:*:*:*:*",
204541          "purl": "pkg:npm/sorted-union-stream@2.1.3",
204542          "swid": {
204543            "attachment": {}
204544          },
204545          "pedigree": {},
204546          "externalReferences": [
204547            {
204548              "url": "git://github.com/mafintosh/sorted-union-stream.git",
204549              "type": "distribution"
204550            },
204551            {
204552              "url": "https://github.com/mafintosh/sorted-union-stream",
204553              "type": "website"
204554            }
204555          ],
204556          "evidence": {},
204557          "signature": {
204558            "signature": {
204559              "publicKey": {}
204560            }
204561          },
204562          "modelCard": {
204563            "modelParameters": {
204564              "approach": {}
204565            },
204566            "quantitativeAnalysis": {
204567              "graphics": {}
204568            },
204569            "considerations": {}
204570          }
204571        },
204572        {
204573          "type": "library",
204574          "bom-ref": "pkg:npm/spdx-correct@3.0.0?package-id=73531364f1007a1",
204575          "supplier": {},
204576          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
204577          "name": "spdx-correct",
204578          "version": "3.0.0",
204579          "description": "correct invalid SPDX expressions",
204580          "licenses": [
204581            {
204582              "license": {
204583                "id": "Apache-2.0"
204584              }
204585            }
204586          ],
204587          "cpe": "cpe:2.3:a:spdx-correct:spdx-correct:3.0.0:*:*:*:*:*:*:*",
204588          "purl": "pkg:npm/spdx-correct@3.0.0",
204589          "swid": {
204590            "attachment": {}
204591          },
204592          "pedigree": {},
204593          "externalReferences": [
204594            {
204595              "url": "git+https://github.com/jslicense/spdx-correct.js.git",
204596              "type": "distribution"
204597            },
204598            {
204599              "url": "https://github.com/jslicense/spdx-correct.js#readme",
204600              "type": "website"
204601            }
204602          ],
204603          "evidence": {},
204604          "signature": {
204605            "signature": {
204606              "publicKey": {}
204607            }
204608          },
204609          "modelCard": {
204610            "modelParameters": {
204611              "approach": {}
204612            },
204613            "quantitativeAnalysis": {
204614              "graphics": {}
204615            },
204616            "considerations": {}
204617          }
204618        },
204619        {
204620          "type": "library",
204621          "bom-ref": "pkg:npm/spdx-exceptions@2.1.0?package-id=1e5a7f3e71a3aea6",
204622          "supplier": {},
204623          "author": "The Linux Foundation",
204624          "name": "spdx-exceptions",
204625          "version": "2.1.0",
204626          "description": "list of SPDX standard license exceptions",
204627          "licenses": [
204628            {
204629              "license": {
204630                "id": "CC-BY-3.0"
204631              }
204632            }
204633          ],
204634          "cpe": "cpe:2.3:a:spdx-exceptions:spdx-exceptions:2.1.0:*:*:*:*:*:*:*",
204635          "purl": "pkg:npm/spdx-exceptions@2.1.0",
204636          "swid": {
204637            "attachment": {}
204638          },
204639          "pedigree": {},
204640          "externalReferences": [
204641            {
204642              "url": "git+https://github.com/kemitchell/spdx-exceptions.json.git",
204643              "type": "distribution"
204644            },
204645            {
204646              "url": "https://github.com/kemitchell/spdx-exceptions.json#readme",
204647              "type": "website"
204648            }
204649          ],
204650          "evidence": {},
204651          "signature": {
204652            "signature": {
204653              "publicKey": {}
204654            }
204655          },
204656          "modelCard": {
204657            "modelParameters": {
204658              "approach": {}
204659            },
204660            "quantitativeAnalysis": {
204661              "graphics": {}
204662            },
204663            "considerations": {}
204664          }
204665        },
204666        {
204667          "type": "library",
204668          "bom-ref": "pkg:npm/spdx-expression-parse@3.0.0?package-id=71a0de12075b58c5",
204669          "supplier": {},
204670          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (http://kemitchell.com)",
204671          "name": "spdx-expression-parse",
204672          "version": "3.0.0",
204673          "description": "parse SPDX license expressions",
204674          "licenses": [
204675            {
204676              "license": {
204677                "id": "MIT"
204678              }
204679            }
204680          ],
204681          "cpe": "cpe:2.3:a:spdx-expression-parse:spdx-expression-parse:3.0.0:*:*:*:*:*:*:*",
204682          "purl": "pkg:npm/spdx-expression-parse@3.0.0",
204683          "swid": {
204684            "attachment": {}
204685          },
204686          "pedigree": {},
204687          "externalReferences": [
204688            {
204689              "url": "git+https://github.com/jslicense/spdx-expression-parse.js.git",
204690              "type": "distribution"
204691            },
204692            {
204693              "url": "https://github.com/jslicense/spdx-expression-parse.js#readme",
204694              "type": "website"
204695            }
204696          ],
204697          "evidence": {},
204698          "signature": {
204699            "signature": {
204700              "publicKey": {}
204701            }
204702          },
204703          "modelCard": {
204704            "modelParameters": {
204705              "approach": {}
204706            },
204707            "quantitativeAnalysis": {
204708              "graphics": {}
204709            },
204710            "considerations": {}
204711          }
204712        },
204713        {
204714          "type": "library",
204715          "bom-ref": "pkg:npm/spdx-license-ids@3.0.5?package-id=1138941acd86a408",
204716          "supplier": {},
204717          "author": "Shinnosuke Watanabe (https://github.com/shinnn)",
204718          "name": "spdx-license-ids",
204719          "version": "3.0.5",
204720          "description": "A list of SPDX license identifiers",
204721          "licenses": [
204722            {
204723              "license": {
204724                "id": "CC0-1.0"
204725              }
204726            }
204727          ],
204728          "cpe": "cpe:2.3:a:spdx-license-ids:spdx-license-ids:3.0.5:*:*:*:*:*:*:*",
204729          "purl": "pkg:npm/spdx-license-ids@3.0.5",
204730          "swid": {
204731            "attachment": {}
204732          },
204733          "pedigree": {},
204734          "externalReferences": [
204735            {
204736              "url": "git+https://github.com/shinnn/spdx-license-ids.git",
204737              "type": "distribution"
204738            },
204739            {
204740              "url": "https://github.com/shinnn/spdx-license-ids#readme",
204741              "type": "website"
204742            }
204743          ],
204744          "evidence": {},
204745          "signature": {
204746            "signature": {
204747              "publicKey": {}
204748            }
204749          },
204750          "modelCard": {
204751            "modelParameters": {
204752              "approach": {}
204753            },
204754            "quantitativeAnalysis": {
204755              "graphics": {}
204756            },
204757            "considerations": {}
204758          }
204759        },
204760        {
204761          "type": "library",
204762          "bom-ref": "pkg:npm/split-on-first@1.1.0?package-id=a53cafaea7f6944b",
204763          "supplier": {},
204764          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
204765          "name": "split-on-first",
204766          "version": "1.1.0",
204767          "description": "Split a string on the first occurance of a given separator",
204768          "licenses": [
204769            {
204770              "license": {
204771                "id": "MIT"
204772              }
204773            }
204774          ],
204775          "cpe": "cpe:2.3:a:split-on-first:split-on-first:1.1.0:*:*:*:*:*:*:*",
204776          "purl": "pkg:npm/split-on-first@1.1.0",
204777          "swid": {
204778            "attachment": {}
204779          },
204780          "pedigree": {},
204781          "externalReferences": [
204782            {
204783              "url": "git+https://github.com/sindresorhus/split-on-first.git",
204784              "type": "distribution"
204785            },
204786            {
204787              "url": "https://github.com/sindresorhus/split-on-first#readme",
204788              "type": "website"
204789            }
204790          ],
204791          "evidence": {},
204792          "signature": {
204793            "signature": {
204794              "publicKey": {}
204795            }
204796          },
204797          "modelCard": {
204798            "modelParameters": {
204799              "approach": {}
204800            },
204801            "quantitativeAnalysis": {
204802              "graphics": {}
204803            },
204804            "considerations": {}
204805          }
204806        },
204807        {
204808          "type": "library",
204809          "bom-ref": "pkg:npm/sprintf-js@1.0.3?package-id=c0e64437ada9115b",
204810          "supplier": {},
204811          "author": "Alexandru Marasteanu \u003chello@alexei.ro\u003e (http://alexei.ro/)",
204812          "name": "sprintf-js",
204813          "version": "1.0.3",
204814          "description": "JavaScript sprintf implementation",
204815          "licenses": [
204816            {
204817              "license": {
204818                "id": "BSD-3-Clause"
204819              }
204820            }
204821          ],
204822          "cpe": "cpe:2.3:a:sprintf-js:sprintf-js:1.0.3:*:*:*:*:*:*:*",
204823          "purl": "pkg:npm/sprintf-js@1.0.3",
204824          "swid": {
204825            "attachment": {}
204826          },
204827          "pedigree": {},
204828          "externalReferences": [
204829            {
204830              "url": "git+https://github.com/alexei/sprintf.js.git",
204831              "type": "distribution"
204832            },
204833            {
204834              "url": "https://github.com/alexei/sprintf.js#readme",
204835              "type": "website"
204836            }
204837          ],
204838          "evidence": {},
204839          "signature": {
204840            "signature": {
204841              "publicKey": {}
204842            }
204843          },
204844          "modelCard": {
204845            "modelParameters": {
204846              "approach": {}
204847            },
204848            "quantitativeAnalysis": {
204849              "graphics": {}
204850            },
204851            "considerations": {}
204852          }
204853        },
204854        {
204855          "type": "library",
204856          "bom-ref": "pkg:npm/sshpk@1.14.2?package-id=41b4eebd6b06963f",
204857          "supplier": {},
204858          "author": "Joyent, Inc",
204859          "name": "sshpk",
204860          "version": "1.14.2",
204861          "description": "A library for finding and using SSH public keys",
204862          "licenses": [
204863            {
204864              "license": {
204865                "id": "MIT"
204866              }
204867            }
204868          ],
204869          "cpe": "cpe:2.3:a:arekinath:sshpk:1.14.2:*:*:*:*:*:*:*",
204870          "purl": "pkg:npm/sshpk@1.14.2",
204871          "swid": {
204872            "attachment": {}
204873          },
204874          "pedigree": {},
204875          "externalReferences": [
204876            {
204877              "url": "git+https://github.com/arekinath/node-sshpk.git",
204878              "type": "distribution"
204879            },
204880            {
204881              "url": "https://github.com/arekinath/node-sshpk#readme",
204882              "type": "website"
204883            }
204884          ],
204885          "evidence": {},
204886          "signature": {
204887            "signature": {
204888              "publicKey": {}
204889            }
204890          },
204891          "modelCard": {
204892            "modelParameters": {
204893              "approach": {}
204894            },
204895            "quantitativeAnalysis": {
204896              "graphics": {}
204897            },
204898            "considerations": {}
204899          }
204900        },
204901        {
204902          "type": "library",
204903          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.1\u0026package-id=b15247aafcd4a647",
204904          "supplier": {},
204905          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
204906          "name": "ssl_client",
204907          "version": "1.35.0-r29",
204908          "description": "EXternal ssl_client for busybox wget",
204909          "licenses": [
204910            {
204911              "license": {
204912                "id": "GPL-2.0-only"
204913              }
204914            }
204915          ],
204916          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r29:*:*:*:*:*:*:*",
204917          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.1",
204918          "swid": {
204919            "attachment": {}
204920          },
204921          "pedigree": {},
204922          "externalReferences": [
204923            {
204924              "url": "https://busybox.net/",
204925              "type": "distribution"
204926            }
204927          ],
204928          "evidence": {},
204929          "signature": {
204930            "signature": {
204931              "publicKey": {}
204932            }
204933          },
204934          "modelCard": {
204935            "modelParameters": {
204936              "approach": {}
204937            },
204938            "quantitativeAnalysis": {
204939              "graphics": {}
204940            },
204941            "considerations": {}
204942          }
204943        },
204944        {
204945          "type": "library",
204946          "bom-ref": "pkg:npm/ssri@6.0.2?package-id=739aca50718ed16c",
204947          "supplier": {},
204948          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
204949          "name": "ssri",
204950          "version": "6.0.2",
204951          "description": "Standard Subresource Integrity library --  parses, serializes, generates, and verifies integrity metadata according to the SRI spec.",
204952          "licenses": [
204953            {
204954              "license": {
204955                "id": "ISC"
204956              }
204957            }
204958          ],
204959          "cpe": "cpe:2.3:a:ssri:ssri:6.0.2:*:*:*:*:*:*:*",
204960          "purl": "pkg:npm/ssri@6.0.2",
204961          "swid": {
204962            "attachment": {}
204963          },
204964          "pedigree": {},
204965          "externalReferences": [
204966            {
204967              "url": "git+https://github.com/zkat/ssri.git",
204968              "type": "distribution"
204969            },
204970            {
204971              "url": "https://github.com/zkat/ssri#readme",
204972              "type": "website"
204973            }
204974          ],
204975          "evidence": {},
204976          "signature": {
204977            "signature": {
204978              "publicKey": {}
204979            }
204980          },
204981          "modelCard": {
204982            "modelParameters": {
204983              "approach": {}
204984            },
204985            "quantitativeAnalysis": {
204986              "graphics": {}
204987            },
204988            "considerations": {}
204989          }
204990        },
204991        {
204992          "type": "library",
204993          "bom-ref": "pkg:npm/statuses@1.5.0?package-id=7880c86343c91f02",
204994          "supplier": {},
204995          "name": "statuses",
204996          "version": "1.5.0",
204997          "description": "HTTP status utility",
204998          "licenses": [
204999            {
205000              "license": {
205001                "id": "MIT"
205002              }
205003            }
205004          ],
205005          "cpe": "cpe:2.3:a:statuses:statuses:1.5.0:*:*:*:*:*:*:*",
205006          "purl": "pkg:npm/statuses@1.5.0",
205007          "swid": {
205008            "attachment": {}
205009          },
205010          "pedigree": {},
205011          "externalReferences": [
205012            {
205013              "url": "git+https://github.com/jshttp/statuses.git",
205014              "type": "distribution"
205015            },
205016            {
205017              "url": "https://github.com/jshttp/statuses#readme",
205018              "type": "website"
205019            }
205020          ],
205021          "evidence": {},
205022          "signature": {
205023            "signature": {
205024              "publicKey": {}
205025            }
205026          },
205027          "modelCard": {
205028            "modelParameters": {
205029              "approach": {}
205030            },
205031            "quantitativeAnalysis": {
205032              "graphics": {}
205033            },
205034            "considerations": {}
205035          }
205036        },
205037        {
205038          "type": "library",
205039          "bom-ref": "pkg:npm/stream-each@1.2.2?package-id=ff21dffb4b08347c",
205040          "supplier": {},
205041          "author": "Mathias Buus (@mafintosh)",
205042          "name": "stream-each",
205043          "version": "1.2.2",
205044          "description": "Iterate all the data in a stream",
205045          "licenses": [
205046            {
205047              "license": {
205048                "id": "MIT"
205049              }
205050            }
205051          ],
205052          "cpe": "cpe:2.3:a:stream-each:stream-each:1.2.2:*:*:*:*:*:*:*",
205053          "purl": "pkg:npm/stream-each@1.2.2",
205054          "swid": {
205055            "attachment": {}
205056          },
205057          "pedigree": {},
205058          "externalReferences": [
205059            {
205060              "url": "git+https://github.com/mafintosh/stream-each.git",
205061              "type": "distribution"
205062            },
205063            {
205064              "url": "https://github.com/mafintosh/stream-each",
205065              "type": "website"
205066            }
205067          ],
205068          "evidence": {},
205069          "signature": {
205070            "signature": {
205071              "publicKey": {}
205072            }
205073          },
205074          "modelCard": {
205075            "modelParameters": {
205076              "approach": {}
205077            },
205078            "quantitativeAnalysis": {
205079              "graphics": {}
205080            },
205081            "considerations": {}
205082          }
205083        },
205084        {
205085          "type": "library",
205086          "bom-ref": "pkg:npm/stream-iterate@1.2.0?package-id=45645dfa25e969e7",
205087          "supplier": {},
205088          "author": "Mathias Buus (@mafintosh)",
205089          "name": "stream-iterate",
205090          "version": "1.2.0",
205091          "description": "Iterate through the values of a stream",
205092          "licenses": [
205093            {
205094              "license": {
205095                "id": "MIT"
205096              }
205097            }
205098          ],
205099          "cpe": "cpe:2.3:a:stream-iterate:stream-iterate:1.2.0:*:*:*:*:*:*:*",
205100          "purl": "pkg:npm/stream-iterate@1.2.0",
205101          "swid": {
205102            "attachment": {}
205103          },
205104          "pedigree": {},
205105          "externalReferences": [
205106            {
205107              "url": "git+https://github.com/mafintosh/stream-iterate.git",
205108              "type": "distribution"
205109            },
205110            {
205111              "url": "https://github.com/mafintosh/stream-iterate",
205112              "type": "website"
205113            }
205114          ],
205115          "evidence": {},
205116          "signature": {
205117            "signature": {
205118              "publicKey": {}
205119            }
205120          },
205121          "modelCard": {
205122            "modelParameters": {
205123              "approach": {}
205124            },
205125            "quantitativeAnalysis": {
205126              "graphics": {}
205127            },
205128            "considerations": {}
205129          }
205130        },
205131        {
205132          "type": "library",
205133          "bom-ref": "pkg:npm/stream-shift@1.0.0?package-id=e058037128eb4cc1",
205134          "supplier": {},
205135          "author": "Mathias Buus (@mafintosh)",
205136          "name": "stream-shift",
205137          "version": "1.0.0",
205138          "description": "Returns the next buffer/object in a stream's readable queue",
205139          "licenses": [
205140            {
205141              "license": {
205142                "id": "MIT"
205143              }
205144            }
205145          ],
205146          "cpe": "cpe:2.3:a:stream-shift:stream-shift:1.0.0:*:*:*:*:*:*:*",
205147          "purl": "pkg:npm/stream-shift@1.0.0",
205148          "swid": {
205149            "attachment": {}
205150          },
205151          "pedigree": {},
205152          "externalReferences": [
205153            {
205154              "url": "git+https://github.com/mafintosh/stream-shift.git",
205155              "type": "distribution"
205156            },
205157            {
205158              "url": "https://github.com/mafintosh/stream-shift",
205159              "type": "website"
205160            }
205161          ],
205162          "evidence": {},
205163          "signature": {
205164            "signature": {
205165              "publicKey": {}
205166            }
205167          },
205168          "modelCard": {
205169            "modelParameters": {
205170              "approach": {}
205171            },
205172            "quantitativeAnalysis": {
205173              "graphics": {}
205174            },
205175            "considerations": {}
205176          }
205177        },
205178        {
205179          "type": "library",
205180          "bom-ref": "pkg:npm/streamsearch@0.1.2?package-id=900089132d0d8437",
205181          "supplier": {},
205182          "author": "Brian White \u003cmscdex@mscdex.net\u003e",
205183          "name": "streamsearch",
205184          "version": "0.1.2",
205185          "description": "Streaming Boyer-Moore-Horspool searching for node.js",
205186          "licenses": [
205187            {
205188              "license": {
205189                "id": "MIT"
205190              }
205191            }
205192          ],
205193          "cpe": "cpe:2.3:a:streamsearch:streamsearch:0.1.2:*:*:*:*:*:*:*",
205194          "purl": "pkg:npm/streamsearch@0.1.2",
205195          "swid": {
205196            "attachment": {}
205197          },
205198          "pedigree": {},
205199          "externalReferences": [
205200            {
205201              "url": "git+ssh://git@github.com/mscdex/streamsearch.git",
205202              "type": "distribution"
205203            },
205204            {
205205              "url": "https://github.com/mscdex/streamsearch#readme",
205206              "type": "website"
205207            }
205208          ],
205209          "evidence": {},
205210          "signature": {
205211            "signature": {
205212              "publicKey": {}
205213            }
205214          },
205215          "modelCard": {
205216            "modelParameters": {
205217              "approach": {}
205218            },
205219            "quantitativeAnalysis": {
205220              "graphics": {}
205221            },
205222            "considerations": {}
205223          }
205224        },
205225        {
205226          "type": "library",
205227          "bom-ref": "pkg:npm/strict-uri-encode@2.0.0?package-id=8d1313eb6c7e50c6",
205228          "supplier": {},
205229          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
205230          "name": "strict-uri-encode",
205231          "version": "2.0.0",
205232          "description": "A stricter URI encode adhering to RFC 3986",
205233          "licenses": [
205234            {
205235              "license": {
205236                "id": "MIT"
205237              }
205238            }
205239          ],
205240          "cpe": "cpe:2.3:a:strict-uri-encode:strict-uri-encode:2.0.0:*:*:*:*:*:*:*",
205241          "purl": "pkg:npm/strict-uri-encode@2.0.0",
205242          "swid": {
205243            "attachment": {}
205244          },
205245          "pedigree": {},
205246          "externalReferences": [
205247            {
205248              "url": "git+https://github.com/kevva/strict-uri-encode.git",
205249              "type": "distribution"
205250            },
205251            {
205252              "url": "https://github.com/kevva/strict-uri-encode#readme",
205253              "type": "website"
205254            }
205255          ],
205256          "evidence": {},
205257          "signature": {
205258            "signature": {
205259              "publicKey": {}
205260            }
205261          },
205262          "modelCard": {
205263            "modelParameters": {
205264              "approach": {}
205265            },
205266            "quantitativeAnalysis": {
205267              "graphics": {}
205268            },
205269            "considerations": {}
205270          }
205271        },
205272        {
205273          "type": "library",
205274          "bom-ref": "pkg:npm/string-width@1.0.2?package-id=f3fde1d1bb9d11bb",
205275          "supplier": {},
205276          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
205277          "name": "string-width",
205278          "version": "1.0.2",
205279          "description": "Get the visual width of a string - the number of columns required to display it",
205280          "licenses": [
205281            {
205282              "license": {
205283                "id": "MIT"
205284              }
205285            }
205286          ],
205287          "cpe": "cpe:2.3:a:sindresorhus:string-width:1.0.2:*:*:*:*:*:*:*",
205288          "purl": "pkg:npm/string-width@1.0.2",
205289          "swid": {
205290            "attachment": {}
205291          },
205292          "pedigree": {},
205293          "externalReferences": [
205294            {
205295              "url": "git+https://github.com/sindresorhus/string-width.git",
205296              "type": "distribution"
205297            },
205298            {
205299              "url": "https://github.com/sindresorhus/string-width#readme",
205300              "type": "website"
205301            }
205302          ],
205303          "evidence": {},
205304          "signature": {
205305            "signature": {
205306              "publicKey": {}
205307            }
205308          },
205309          "modelCard": {
205310            "modelParameters": {
205311              "approach": {}
205312            },
205313            "quantitativeAnalysis": {
205314              "graphics": {}
205315            },
205316            "considerations": {}
205317          }
205318        },
205319        {
205320          "type": "library",
205321          "bom-ref": "pkg:npm/string-width@1.0.2?package-id=aad7726ab13feca",
205322          "supplier": {},
205323          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
205324          "name": "string-width",
205325          "version": "1.0.2",
205326          "description": "Get the visual width of a string - the number of columns required to display it",
205327          "licenses": [
205328            {
205329              "license": {
205330                "id": "MIT"
205331              }
205332            }
205333          ],
205334          "cpe": "cpe:2.3:a:sindresorhus:string-width:1.0.2:*:*:*:*:*:*:*",
205335          "purl": "pkg:npm/string-width@1.0.2",
205336          "swid": {
205337            "attachment": {}
205338          },
205339          "pedigree": {},
205340          "externalReferences": [
205341            {
205342              "url": "git+https://github.com/sindresorhus/string-width.git",
205343              "type": "distribution"
205344            },
205345            {
205346              "url": "https://github.com/sindresorhus/string-width#readme",
205347              "type": "website"
205348            }
205349          ],
205350          "evidence": {},
205351          "signature": {
205352            "signature": {
205353              "publicKey": {}
205354            }
205355          },
205356          "modelCard": {
205357            "modelParameters": {
205358              "approach": {}
205359            },
205360            "quantitativeAnalysis": {
205361              "graphics": {}
205362            },
205363            "considerations": {}
205364          }
205365        },
205366        {
205367          "type": "library",
205368          "bom-ref": "pkg:npm/string-width@2.1.1?package-id=aa7b698cf21b3eed",
205369          "supplier": {},
205370          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
205371          "name": "string-width",
205372          "version": "2.1.1",
205373          "description": "Get the visual width of a string - the number of columns required to display it",
205374          "licenses": [
205375            {
205376              "license": {
205377                "id": "MIT"
205378              }
205379            }
205380          ],
205381          "cpe": "cpe:2.3:a:sindresorhus:string-width:2.1.1:*:*:*:*:*:*:*",
205382          "purl": "pkg:npm/string-width@2.1.1",
205383          "swid": {
205384            "attachment": {}
205385          },
205386          "pedigree": {},
205387          "externalReferences": [
205388            {
205389              "url": "git+https://github.com/sindresorhus/string-width.git",
205390              "type": "distribution"
205391            },
205392            {
205393              "url": "https://github.com/sindresorhus/string-width#readme",
205394              "type": "website"
205395            }
205396          ],
205397          "evidence": {},
205398          "signature": {
205399            "signature": {
205400              "publicKey": {}
205401            }
205402          },
205403          "modelCard": {
205404            "modelParameters": {
205405              "approach": {}
205406            },
205407            "quantitativeAnalysis": {
205408              "graphics": {}
205409            },
205410            "considerations": {}
205411          }
205412        },
205413        {
205414          "type": "library",
205415          "bom-ref": "pkg:npm/string-width@3.1.0?package-id=87790d6cb608b04c",
205416          "supplier": {},
205417          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
205418          "name": "string-width",
205419          "version": "3.1.0",
205420          "description": "Get the visual width of a string - the number of columns required to display it",
205421          "licenses": [
205422            {
205423              "license": {
205424                "id": "MIT"
205425              }
205426            }
205427          ],
205428          "cpe": "cpe:2.3:a:sindresorhus:string-width:3.1.0:*:*:*:*:*:*:*",
205429          "purl": "pkg:npm/string-width@3.1.0",
205430          "swid": {
205431            "attachment": {}
205432          },
205433          "pedigree": {},
205434          "externalReferences": [
205435            {
205436              "url": "git+https://github.com/sindresorhus/string-width.git",
205437              "type": "distribution"
205438            },
205439            {
205440              "url": "https://github.com/sindresorhus/string-width#readme",
205441              "type": "website"
205442            }
205443          ],
205444          "evidence": {},
205445          "signature": {
205446            "signature": {
205447              "publicKey": {}
205448            }
205449          },
205450          "modelCard": {
205451            "modelParameters": {
205452              "approach": {}
205453            },
205454            "quantitativeAnalysis": {
205455              "graphics": {}
205456            },
205457            "considerations": {}
205458          }
205459        },
205460        {
205461          "type": "library",
205462          "bom-ref": "pkg:npm/string-width@3.1.0?package-id=12bb72b3585d56cb",
205463          "supplier": {},
205464          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
205465          "name": "string-width",
205466          "version": "3.1.0",
205467          "description": "Get the visual width of a string - the number of columns required to display it",
205468          "licenses": [
205469            {
205470              "license": {
205471                "id": "MIT"
205472              }
205473            }
205474          ],
205475          "cpe": "cpe:2.3:a:sindresorhus:string-width:3.1.0:*:*:*:*:*:*:*",
205476          "purl": "pkg:npm/string-width@3.1.0",
205477          "swid": {
205478            "attachment": {}
205479          },
205480          "pedigree": {},
205481          "externalReferences": [
205482            {
205483              "url": "git+https://github.com/sindresorhus/string-width.git",
205484              "type": "distribution"
205485            },
205486            {
205487              "url": "https://github.com/sindresorhus/string-width#readme",
205488              "type": "website"
205489            }
205490          ],
205491          "evidence": {},
205492          "signature": {
205493            "signature": {
205494              "publicKey": {}
205495            }
205496          },
205497          "modelCard": {
205498            "modelParameters": {
205499              "approach": {}
205500            },
205501            "quantitativeAnalysis": {
205502              "graphics": {}
205503            },
205504            "considerations": {}
205505          }
205506        },
205507        {
205508          "type": "library",
205509          "bom-ref": "pkg:npm/string-width@3.1.0?package-id=55af5077fbd273b",
205510          "supplier": {},
205511          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
205512          "name": "string-width",
205513          "version": "3.1.0",
205514          "description": "Get the visual width of a string - the number of columns required to display it",
205515          "licenses": [
205516            {
205517              "license": {
205518                "id": "MIT"
205519              }
205520            }
205521          ],
205522          "cpe": "cpe:2.3:a:sindresorhus:string-width:3.1.0:*:*:*:*:*:*:*",
205523          "purl": "pkg:npm/string-width@3.1.0",
205524          "swid": {
205525            "attachment": {}
205526          },
205527          "pedigree": {},
205528          "externalReferences": [
205529            {
205530              "url": "git+https://github.com/sindresorhus/string-width.git",
205531              "type": "distribution"
205532            },
205533            {
205534              "url": "https://github.com/sindresorhus/string-width#readme",
205535              "type": "website"
205536            }
205537          ],
205538          "evidence": {},
205539          "signature": {
205540            "signature": {
205541              "publicKey": {}
205542            }
205543          },
205544          "modelCard": {
205545            "modelParameters": {
205546              "approach": {}
205547            },
205548            "quantitativeAnalysis": {
205549              "graphics": {}
205550            },
205551            "considerations": {}
205552          }
205553        },
205554        {
205555          "type": "library",
205556          "bom-ref": "pkg:npm/string_decoder@0.10.31?package-id=842458f1d210431a",
205557          "supplier": {},
205558          "name": "string_decoder",
205559          "version": "0.10.31",
205560          "description": "The string_decoder module from Node core",
205561          "licenses": [
205562            {
205563              "license": {
205564                "id": "MIT"
205565              }
205566            }
205567          ],
205568          "cpe": "cpe:2.3:a:string-decoder:string-decoder:0.10.31:*:*:*:*:*:*:*",
205569          "purl": "pkg:npm/string_decoder@0.10.31",
205570          "swid": {
205571            "attachment": {}
205572          },
205573          "pedigree": {},
205574          "externalReferences": [
205575            {
205576              "url": "git://github.com/rvagg/string_decoder.git",
205577              "type": "distribution"
205578            },
205579            {
205580              "url": "https://github.com/rvagg/string_decoder",
205581              "type": "website"
205582            }
205583          ],
205584          "evidence": {},
205585          "signature": {
205586            "signature": {
205587              "publicKey": {}
205588            }
205589          },
205590          "modelCard": {
205591            "modelParameters": {
205592              "approach": {}
205593            },
205594            "quantitativeAnalysis": {
205595              "graphics": {}
205596            },
205597            "considerations": {}
205598          }
205599        },
205600        {
205601          "type": "library",
205602          "bom-ref": "pkg:npm/string_decoder@0.10.31?package-id=b225c432d9e6b500",
205603          "supplier": {},
205604          "name": "string_decoder",
205605          "version": "0.10.31",
205606          "description": "The string_decoder module from Node core",
205607          "licenses": [
205608            {
205609              "license": {
205610                "id": "MIT"
205611              }
205612            }
205613          ],
205614          "cpe": "cpe:2.3:a:string-decoder:string-decoder:0.10.31:*:*:*:*:*:*:*",
205615          "purl": "pkg:npm/string_decoder@0.10.31",
205616          "swid": {
205617            "attachment": {}
205618          },
205619          "pedigree": {},
205620          "externalReferences": [
205621            {
205622              "url": "git://github.com/rvagg/string_decoder.git",
205623              "type": "distribution"
205624            },
205625            {
205626              "url": "https://github.com/rvagg/string_decoder",
205627              "type": "website"
205628            }
205629          ],
205630          "evidence": {},
205631          "signature": {
205632            "signature": {
205633              "publicKey": {}
205634            }
205635          },
205636          "modelCard": {
205637            "modelParameters": {
205638              "approach": {}
205639            },
205640            "quantitativeAnalysis": {
205641              "graphics": {}
205642            },
205643            "considerations": {}
205644          }
205645        },
205646        {
205647          "type": "library",
205648          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=a6eeeaeb8b6353ea",
205649          "supplier": {},
205650          "name": "string_decoder",
205651          "version": "1.1.1",
205652          "description": "The string_decoder module from Node core",
205653          "licenses": [
205654            {
205655              "license": {
205656                "id": "MIT"
205657              }
205658            }
205659          ],
205660          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
205661          "purl": "pkg:npm/string_decoder@1.1.1",
205662          "swid": {
205663            "attachment": {}
205664          },
205665          "pedigree": {},
205666          "externalReferences": [
205667            {
205668              "url": "git://github.com/nodejs/string_decoder.git",
205669              "type": "distribution"
205670            },
205671            {
205672              "url": "https://github.com/nodejs/string_decoder",
205673              "type": "website"
205674            }
205675          ],
205676          "evidence": {},
205677          "signature": {
205678            "signature": {
205679              "publicKey": {}
205680            }
205681          },
205682          "modelCard": {
205683            "modelParameters": {
205684              "approach": {}
205685            },
205686            "quantitativeAnalysis": {
205687              "graphics": {}
205688            },
205689            "considerations": {}
205690          }
205691        },
205692        {
205693          "type": "library",
205694          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=361d8a5e7e28d65b",
205695          "supplier": {},
205696          "name": "string_decoder",
205697          "version": "1.1.1",
205698          "description": "The string_decoder module from Node core",
205699          "licenses": [
205700            {
205701              "license": {
205702                "id": "MIT"
205703              }
205704            }
205705          ],
205706          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
205707          "purl": "pkg:npm/string_decoder@1.1.1",
205708          "swid": {
205709            "attachment": {}
205710          },
205711          "pedigree": {},
205712          "externalReferences": [
205713            {
205714              "url": "git://github.com/nodejs/string_decoder.git",
205715              "type": "distribution"
205716            },
205717            {
205718              "url": "https://github.com/nodejs/string_decoder",
205719              "type": "website"
205720            }
205721          ],
205722          "evidence": {},
205723          "signature": {
205724            "signature": {
205725              "publicKey": {}
205726            }
205727          },
205728          "modelCard": {
205729            "modelParameters": {
205730              "approach": {}
205731            },
205732            "quantitativeAnalysis": {
205733              "graphics": {}
205734            },
205735            "considerations": {}
205736          }
205737        },
205738        {
205739          "type": "library",
205740          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=6de5785db73e974c",
205741          "supplier": {},
205742          "name": "string_decoder",
205743          "version": "1.1.1",
205744          "description": "The string_decoder module from Node core",
205745          "licenses": [
205746            {
205747              "license": {
205748                "id": "MIT"
205749              }
205750            }
205751          ],
205752          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
205753          "purl": "pkg:npm/string_decoder@1.1.1",
205754          "swid": {
205755            "attachment": {}
205756          },
205757          "pedigree": {},
205758          "externalReferences": [
205759            {
205760              "url": "git://github.com/nodejs/string_decoder.git",
205761              "type": "distribution"
205762            },
205763            {
205764              "url": "https://github.com/nodejs/string_decoder",
205765              "type": "website"
205766            }
205767          ],
205768          "evidence": {},
205769          "signature": {
205770            "signature": {
205771              "publicKey": {}
205772            }
205773          },
205774          "modelCard": {
205775            "modelParameters": {
205776              "approach": {}
205777            },
205778            "quantitativeAnalysis": {
205779              "graphics": {}
205780            },
205781            "considerations": {}
205782          }
205783        },
205784        {
205785          "type": "library",
205786          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=64921df3b8583429",
205787          "supplier": {},
205788          "name": "string_decoder",
205789          "version": "1.1.1",
205790          "description": "The string_decoder module from Node core",
205791          "licenses": [
205792            {
205793              "license": {
205794                "id": "MIT"
205795              }
205796            }
205797          ],
205798          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
205799          "purl": "pkg:npm/string_decoder@1.1.1",
205800          "swid": {
205801            "attachment": {}
205802          },
205803          "pedigree": {},
205804          "externalReferences": [
205805            {
205806              "url": "git://github.com/nodejs/string_decoder.git",
205807              "type": "distribution"
205808            },
205809            {
205810              "url": "https://github.com/nodejs/string_decoder",
205811              "type": "website"
205812            }
205813          ],
205814          "evidence": {},
205815          "signature": {
205816            "signature": {
205817              "publicKey": {}
205818            }
205819          },
205820          "modelCard": {
205821            "modelParameters": {
205822              "approach": {}
205823            },
205824            "quantitativeAnalysis": {
205825              "graphics": {}
205826            },
205827            "considerations": {}
205828          }
205829        },
205830        {
205831          "type": "library",
205832          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=f7db62bc91e69852",
205833          "supplier": {},
205834          "name": "string_decoder",
205835          "version": "1.1.1",
205836          "description": "The string_decoder module from Node core",
205837          "licenses": [
205838            {
205839              "license": {
205840                "id": "MIT"
205841              }
205842            }
205843          ],
205844          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
205845          "purl": "pkg:npm/string_decoder@1.1.1",
205846          "swid": {
205847            "attachment": {}
205848          },
205849          "pedigree": {},
205850          "externalReferences": [
205851            {
205852              "url": "git://github.com/nodejs/string_decoder.git",
205853              "type": "distribution"
205854            },
205855            {
205856              "url": "https://github.com/nodejs/string_decoder",
205857              "type": "website"
205858            }
205859          ],
205860          "evidence": {},
205861          "signature": {
205862            "signature": {
205863              "publicKey": {}
205864            }
205865          },
205866          "modelCard": {
205867            "modelParameters": {
205868              "approach": {}
205869            },
205870            "quantitativeAnalysis": {
205871              "graphics": {}
205872            },
205873            "considerations": {}
205874          }
205875        },
205876        {
205877          "type": "library",
205878          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=44a4766f5469b746",
205879          "supplier": {},
205880          "name": "string_decoder",
205881          "version": "1.1.1",
205882          "description": "The string_decoder module from Node core",
205883          "licenses": [
205884            {
205885              "license": {
205886                "id": "MIT"
205887              }
205888            }
205889          ],
205890          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
205891          "purl": "pkg:npm/string_decoder@1.1.1",
205892          "swid": {
205893            "attachment": {}
205894          },
205895          "pedigree": {},
205896          "externalReferences": [
205897            {
205898              "url": "git://github.com/nodejs/string_decoder.git",
205899              "type": "distribution"
205900            },
205901            {
205902              "url": "https://github.com/nodejs/string_decoder",
205903              "type": "website"
205904            }
205905          ],
205906          "evidence": {},
205907          "signature": {
205908            "signature": {
205909              "publicKey": {}
205910            }
205911          },
205912          "modelCard": {
205913            "modelParameters": {
205914              "approach": {}
205915            },
205916            "quantitativeAnalysis": {
205917              "graphics": {}
205918            },
205919            "considerations": {}
205920          }
205921        },
205922        {
205923          "type": "library",
205924          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=2892cc6855d3777f",
205925          "supplier": {},
205926          "name": "string_decoder",
205927          "version": "1.1.1",
205928          "description": "The string_decoder module from Node core",
205929          "licenses": [
205930            {
205931              "license": {
205932                "id": "MIT"
205933              }
205934            }
205935          ],
205936          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
205937          "purl": "pkg:npm/string_decoder@1.1.1",
205938          "swid": {
205939            "attachment": {}
205940          },
205941          "pedigree": {},
205942          "externalReferences": [
205943            {
205944              "url": "git://github.com/nodejs/string_decoder.git",
205945              "type": "distribution"
205946            },
205947            {
205948              "url": "https://github.com/nodejs/string_decoder",
205949              "type": "website"
205950            }
205951          ],
205952          "evidence": {},
205953          "signature": {
205954            "signature": {
205955              "publicKey": {}
205956            }
205957          },
205958          "modelCard": {
205959            "modelParameters": {
205960              "approach": {}
205961            },
205962            "quantitativeAnalysis": {
205963              "graphics": {}
205964            },
205965            "considerations": {}
205966          }
205967        },
205968        {
205969          "type": "library",
205970          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=b44575a021be68ba",
205971          "supplier": {},
205972          "name": "string_decoder",
205973          "version": "1.1.1",
205974          "description": "The string_decoder module from Node core",
205975          "licenses": [
205976            {
205977              "license": {
205978                "id": "MIT"
205979              }
205980            }
205981          ],
205982          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
205983          "purl": "pkg:npm/string_decoder@1.1.1",
205984          "swid": {
205985            "attachment": {}
205986          },
205987          "pedigree": {},
205988          "externalReferences": [
205989            {
205990              "url": "git://github.com/nodejs/string_decoder.git",
205991              "type": "distribution"
205992            },
205993            {
205994              "url": "https://github.com/nodejs/string_decoder",
205995              "type": "website"
205996            }
205997          ],
205998          "evidence": {},
205999          "signature": {
206000            "signature": {
206001              "publicKey": {}
206002            }
206003          },
206004          "modelCard": {
206005            "modelParameters": {
206006              "approach": {}
206007            },
206008            "quantitativeAnalysis": {
206009              "graphics": {}
206010            },
206011            "considerations": {}
206012          }
206013        },
206014        {
206015          "type": "library",
206016          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=b19b3b00778e1d8",
206017          "supplier": {},
206018          "name": "string_decoder",
206019          "version": "1.1.1",
206020          "description": "The string_decoder module from Node core",
206021          "licenses": [
206022            {
206023              "license": {
206024                "id": "MIT"
206025              }
206026            }
206027          ],
206028          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
206029          "purl": "pkg:npm/string_decoder@1.1.1",
206030          "swid": {
206031            "attachment": {}
206032          },
206033          "pedigree": {},
206034          "externalReferences": [
206035            {
206036              "url": "git://github.com/nodejs/string_decoder.git",
206037              "type": "distribution"
206038            },
206039            {
206040              "url": "https://github.com/nodejs/string_decoder",
206041              "type": "website"
206042            }
206043          ],
206044          "evidence": {},
206045          "signature": {
206046            "signature": {
206047              "publicKey": {}
206048            }
206049          },
206050          "modelCard": {
206051            "modelParameters": {
206052              "approach": {}
206053            },
206054            "quantitativeAnalysis": {
206055              "graphics": {}
206056            },
206057            "considerations": {}
206058          }
206059        },
206060        {
206061          "type": "library",
206062          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=5c7fd10ffa2e6849",
206063          "supplier": {},
206064          "name": "string_decoder",
206065          "version": "1.1.1",
206066          "description": "The string_decoder module from Node core",
206067          "licenses": [
206068            {
206069              "license": {
206070                "id": "MIT"
206071              }
206072            }
206073          ],
206074          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
206075          "purl": "pkg:npm/string_decoder@1.1.1",
206076          "swid": {
206077            "attachment": {}
206078          },
206079          "pedigree": {},
206080          "externalReferences": [
206081            {
206082              "url": "git://github.com/nodejs/string_decoder.git",
206083              "type": "distribution"
206084            },
206085            {
206086              "url": "https://github.com/nodejs/string_decoder",
206087              "type": "website"
206088            }
206089          ],
206090          "evidence": {},
206091          "signature": {
206092            "signature": {
206093              "publicKey": {}
206094            }
206095          },
206096          "modelCard": {
206097            "modelParameters": {
206098              "approach": {}
206099            },
206100            "quantitativeAnalysis": {
206101              "graphics": {}
206102            },
206103            "considerations": {}
206104          }
206105        },
206106        {
206107          "type": "library",
206108          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=804f0a28a30f2774",
206109          "supplier": {},
206110          "name": "string_decoder",
206111          "version": "1.3.0",
206112          "description": "The string_decoder module from Node core",
206113          "licenses": [
206114            {
206115              "license": {
206116                "id": "MIT"
206117              }
206118            }
206119          ],
206120          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
206121          "purl": "pkg:npm/string_decoder@1.3.0",
206122          "swid": {
206123            "attachment": {}
206124          },
206125          "pedigree": {},
206126          "externalReferences": [
206127            {
206128              "url": "git://github.com/nodejs/string_decoder.git",
206129              "type": "distribution"
206130            },
206131            {
206132              "url": "https://github.com/nodejs/string_decoder",
206133              "type": "website"
206134            }
206135          ],
206136          "evidence": {},
206137          "signature": {
206138            "signature": {
206139              "publicKey": {}
206140            }
206141          },
206142          "modelCard": {
206143            "modelParameters": {
206144              "approach": {}
206145            },
206146            "quantitativeAnalysis": {
206147              "graphics": {}
206148            },
206149            "considerations": {}
206150          }
206151        },
206152        {
206153          "type": "library",
206154          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=ca8af4aa6b41ca75",
206155          "supplier": {},
206156          "name": "string_decoder",
206157          "version": "1.3.0",
206158          "description": "The string_decoder module from Node core",
206159          "licenses": [
206160            {
206161              "license": {
206162                "id": "MIT"
206163              }
206164            }
206165          ],
206166          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
206167          "purl": "pkg:npm/string_decoder@1.3.0",
206168          "swid": {
206169            "attachment": {}
206170          },
206171          "pedigree": {},
206172          "externalReferences": [
206173            {
206174              "url": "git://github.com/nodejs/string_decoder.git",
206175              "type": "distribution"
206176            },
206177            {
206178              "url": "https://github.com/nodejs/string_decoder",
206179              "type": "website"
206180            }
206181          ],
206182          "evidence": {},
206183          "signature": {
206184            "signature": {
206185              "publicKey": {}
206186            }
206187          },
206188          "modelCard": {
206189            "modelParameters": {
206190              "approach": {}
206191            },
206192            "quantitativeAnalysis": {
206193              "graphics": {}
206194            },
206195            "considerations": {}
206196          }
206197        },
206198        {
206199          "type": "library",
206200          "bom-ref": "pkg:npm/stringify-package@1.0.1?package-id=c67453153e496783",
206201          "supplier": {},
206202          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
206203          "name": "stringify-package",
206204          "version": "1.0.1",
206205          "description": "stringifies npm-written json files",
206206          "licenses": [
206207            {
206208              "license": {
206209                "id": "ISC"
206210              }
206211            }
206212          ],
206213          "cpe": "cpe:2.3:a:stringify-package:stringify-package:1.0.1:*:*:*:*:*:*:*",
206214          "purl": "pkg:npm/stringify-package@1.0.1",
206215          "swid": {
206216            "attachment": {}
206217          },
206218          "pedigree": {},
206219          "externalReferences": [
206220            {
206221              "url": "git+https://github.com/npm/stringify-package.git",
206222              "type": "distribution"
206223            },
206224            {
206225              "url": "https://github.com/npm/stringify-package",
206226              "type": "website"
206227            }
206228          ],
206229          "evidence": {},
206230          "signature": {
206231            "signature": {
206232              "publicKey": {}
206233            }
206234          },
206235          "modelCard": {
206236            "modelParameters": {
206237              "approach": {}
206238            },
206239            "quantitativeAnalysis": {
206240              "graphics": {}
206241            },
206242            "considerations": {}
206243          }
206244        },
206245        {
206246          "type": "library",
206247          "bom-ref": "pkg:npm/strip-ansi@3.0.1?package-id=51b22d897b0450b8",
206248          "supplier": {},
206249          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206250          "name": "strip-ansi",
206251          "version": "3.0.1",
206252          "description": "Strip ANSI escape codes",
206253          "licenses": [
206254            {
206255              "license": {
206256                "id": "MIT"
206257              }
206258            }
206259          ],
206260          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:3.0.1:*:*:*:*:*:*:*",
206261          "purl": "pkg:npm/strip-ansi@3.0.1",
206262          "swid": {
206263            "attachment": {}
206264          },
206265          "pedigree": {},
206266          "externalReferences": [
206267            {
206268              "url": "git+https://github.com/chalk/strip-ansi.git",
206269              "type": "distribution"
206270            },
206271            {
206272              "url": "https://github.com/chalk/strip-ansi#readme",
206273              "type": "website"
206274            }
206275          ],
206276          "evidence": {},
206277          "signature": {
206278            "signature": {
206279              "publicKey": {}
206280            }
206281          },
206282          "modelCard": {
206283            "modelParameters": {
206284              "approach": {}
206285            },
206286            "quantitativeAnalysis": {
206287              "graphics": {}
206288            },
206289            "considerations": {}
206290          }
206291        },
206292        {
206293          "type": "library",
206294          "bom-ref": "pkg:npm/strip-ansi@4.0.0?package-id=13ba95b5b65e8a37",
206295          "supplier": {},
206296          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206297          "name": "strip-ansi",
206298          "version": "4.0.0",
206299          "description": "Strip ANSI escape codes",
206300          "licenses": [
206301            {
206302              "license": {
206303                "id": "MIT"
206304              }
206305            }
206306          ],
206307          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:4.0.0:*:*:*:*:*:*:*",
206308          "purl": "pkg:npm/strip-ansi@4.0.0",
206309          "swid": {
206310            "attachment": {}
206311          },
206312          "pedigree": {},
206313          "externalReferences": [
206314            {
206315              "url": "git+https://github.com/chalk/strip-ansi.git",
206316              "type": "distribution"
206317            },
206318            {
206319              "url": "https://github.com/chalk/strip-ansi#readme",
206320              "type": "website"
206321            }
206322          ],
206323          "evidence": {},
206324          "signature": {
206325            "signature": {
206326              "publicKey": {}
206327            }
206328          },
206329          "modelCard": {
206330            "modelParameters": {
206331              "approach": {}
206332            },
206333            "quantitativeAnalysis": {
206334              "graphics": {}
206335            },
206336            "considerations": {}
206337          }
206338        },
206339        {
206340          "type": "library",
206341          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=465f19aa1b6b9497",
206342          "supplier": {},
206343          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206344          "name": "strip-ansi",
206345          "version": "5.2.0",
206346          "description": "Strip ANSI escape codes from a string",
206347          "licenses": [
206348            {
206349              "license": {
206350                "id": "MIT"
206351              }
206352            }
206353          ],
206354          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
206355          "purl": "pkg:npm/strip-ansi@5.2.0",
206356          "swid": {
206357            "attachment": {}
206358          },
206359          "pedigree": {},
206360          "externalReferences": [
206361            {
206362              "url": "git+https://github.com/chalk/strip-ansi.git",
206363              "type": "distribution"
206364            },
206365            {
206366              "url": "https://github.com/chalk/strip-ansi#readme",
206367              "type": "website"
206368            }
206369          ],
206370          "evidence": {},
206371          "signature": {
206372            "signature": {
206373              "publicKey": {}
206374            }
206375          },
206376          "modelCard": {
206377            "modelParameters": {
206378              "approach": {}
206379            },
206380            "quantitativeAnalysis": {
206381              "graphics": {}
206382            },
206383            "considerations": {}
206384          }
206385        },
206386        {
206387          "type": "library",
206388          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=f78d385de6e5730d",
206389          "supplier": {},
206390          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206391          "name": "strip-ansi",
206392          "version": "5.2.0",
206393          "description": "Strip ANSI escape codes from a string",
206394          "licenses": [
206395            {
206396              "license": {
206397                "id": "MIT"
206398              }
206399            }
206400          ],
206401          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
206402          "purl": "pkg:npm/strip-ansi@5.2.0",
206403          "swid": {
206404            "attachment": {}
206405          },
206406          "pedigree": {},
206407          "externalReferences": [
206408            {
206409              "url": "git+https://github.com/chalk/strip-ansi.git",
206410              "type": "distribution"
206411            },
206412            {
206413              "url": "https://github.com/chalk/strip-ansi#readme",
206414              "type": "website"
206415            }
206416          ],
206417          "evidence": {},
206418          "signature": {
206419            "signature": {
206420              "publicKey": {}
206421            }
206422          },
206423          "modelCard": {
206424            "modelParameters": {
206425              "approach": {}
206426            },
206427            "quantitativeAnalysis": {
206428              "graphics": {}
206429            },
206430            "considerations": {}
206431          }
206432        },
206433        {
206434          "type": "library",
206435          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=6eaeb57df2549822",
206436          "supplier": {},
206437          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206438          "name": "strip-ansi",
206439          "version": "5.2.0",
206440          "description": "Strip ANSI escape codes from a string",
206441          "licenses": [
206442            {
206443              "license": {
206444                "id": "MIT"
206445              }
206446            }
206447          ],
206448          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
206449          "purl": "pkg:npm/strip-ansi@5.2.0",
206450          "swid": {
206451            "attachment": {}
206452          },
206453          "pedigree": {},
206454          "externalReferences": [
206455            {
206456              "url": "git+https://github.com/chalk/strip-ansi.git",
206457              "type": "distribution"
206458            },
206459            {
206460              "url": "https://github.com/chalk/strip-ansi#readme",
206461              "type": "website"
206462            }
206463          ],
206464          "evidence": {},
206465          "signature": {
206466            "signature": {
206467              "publicKey": {}
206468            }
206469          },
206470          "modelCard": {
206471            "modelParameters": {
206472              "approach": {}
206473            },
206474            "quantitativeAnalysis": {
206475              "graphics": {}
206476            },
206477            "considerations": {}
206478          }
206479        },
206480        {
206481          "type": "library",
206482          "bom-ref": "pkg:npm/strip-eof@1.0.0?package-id=16191ba994ef2bb8",
206483          "supplier": {},
206484          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206485          "name": "strip-eof",
206486          "version": "1.0.0",
206487          "description": "Strip the End-Of-File (EOF) character from a string/buffer",
206488          "licenses": [
206489            {
206490              "license": {
206491                "id": "MIT"
206492              }
206493            }
206494          ],
206495          "cpe": "cpe:2.3:a:sindresorhus:strip-eof:1.0.0:*:*:*:*:*:*:*",
206496          "purl": "pkg:npm/strip-eof@1.0.0",
206497          "swid": {
206498            "attachment": {}
206499          },
206500          "pedigree": {},
206501          "externalReferences": [
206502            {
206503              "url": "git+https://github.com/sindresorhus/strip-eof.git",
206504              "type": "distribution"
206505            },
206506            {
206507              "url": "https://github.com/sindresorhus/strip-eof#readme",
206508              "type": "website"
206509            }
206510          ],
206511          "evidence": {},
206512          "signature": {
206513            "signature": {
206514              "publicKey": {}
206515            }
206516          },
206517          "modelCard": {
206518            "modelParameters": {
206519              "approach": {}
206520            },
206521            "quantitativeAnalysis": {
206522              "graphics": {}
206523            },
206524            "considerations": {}
206525          }
206526        },
206527        {
206528          "type": "library",
206529          "bom-ref": "pkg:npm/strip-json-comments@2.0.1?package-id=ccf04b5e0cce811a",
206530          "supplier": {},
206531          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206532          "name": "strip-json-comments",
206533          "version": "2.0.1",
206534          "description": "Strip comments from JSON. Lets you use comments in your JSON files!",
206535          "licenses": [
206536            {
206537              "license": {
206538                "id": "MIT"
206539              }
206540            }
206541          ],
206542          "cpe": "cpe:2.3:a:strip-json-comments:strip-json-comments:2.0.1:*:*:*:*:*:*:*",
206543          "purl": "pkg:npm/strip-json-comments@2.0.1",
206544          "swid": {
206545            "attachment": {}
206546          },
206547          "pedigree": {},
206548          "externalReferences": [
206549            {
206550              "url": "git+https://github.com/sindresorhus/strip-json-comments.git",
206551              "type": "distribution"
206552            },
206553            {
206554              "url": "https://github.com/sindresorhus/strip-json-comments#readme",
206555              "type": "website"
206556            }
206557          ],
206558          "evidence": {},
206559          "signature": {
206560            "signature": {
206561              "publicKey": {}
206562            }
206563          },
206564          "modelCard": {
206565            "modelParameters": {
206566              "approach": {}
206567            },
206568            "quantitativeAnalysis": {
206569              "graphics": {}
206570            },
206571            "considerations": {}
206572          }
206573        },
206574        {
206575          "type": "library",
206576          "bom-ref": "pkg:npm/supports-color@5.4.0?package-id=4145d752dc87470d",
206577          "supplier": {},
206578          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206579          "name": "supports-color",
206580          "version": "5.4.0",
206581          "description": "Detect whether a terminal supports color",
206582          "licenses": [
206583            {
206584              "license": {
206585                "id": "MIT"
206586              }
206587            }
206588          ],
206589          "cpe": "cpe:2.3:a:supports-color:supports-color:5.4.0:*:*:*:*:*:*:*",
206590          "purl": "pkg:npm/supports-color@5.4.0",
206591          "swid": {
206592            "attachment": {}
206593          },
206594          "pedigree": {},
206595          "externalReferences": [
206596            {
206597              "url": "git+https://github.com/chalk/supports-color.git",
206598              "type": "distribution"
206599            },
206600            {
206601              "url": "https://github.com/chalk/supports-color#readme",
206602              "type": "website"
206603            }
206604          ],
206605          "evidence": {},
206606          "signature": {
206607            "signature": {
206608              "publicKey": {}
206609            }
206610          },
206611          "modelCard": {
206612            "modelParameters": {
206613              "approach": {}
206614            },
206615            "quantitativeAnalysis": {
206616              "graphics": {}
206617            },
206618            "considerations": {}
206619          }
206620        },
206621        {
206622          "type": "library",
206623          "bom-ref": "pkg:npm/supports-color@7.2.0?package-id=33ae3b7b72211ee6",
206624          "supplier": {},
206625          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206626          "name": "supports-color",
206627          "version": "7.2.0",
206628          "description": "Detect whether a terminal supports color",
206629          "licenses": [
206630            {
206631              "license": {
206632                "id": "MIT"
206633              }
206634            }
206635          ],
206636          "cpe": "cpe:2.3:a:supports-color:supports-color:7.2.0:*:*:*:*:*:*:*",
206637          "purl": "pkg:npm/supports-color@7.2.0",
206638          "swid": {
206639            "attachment": {}
206640          },
206641          "pedigree": {},
206642          "externalReferences": [
206643            {
206644              "url": "git+https://github.com/chalk/supports-color.git",
206645              "type": "distribution"
206646            },
206647            {
206648              "url": "https://github.com/chalk/supports-color#readme",
206649              "type": "website"
206650            }
206651          ],
206652          "evidence": {},
206653          "signature": {
206654            "signature": {
206655              "publicKey": {}
206656            }
206657          },
206658          "modelCard": {
206659            "modelParameters": {
206660              "approach": {}
206661            },
206662            "quantitativeAnalysis": {
206663              "graphics": {}
206664            },
206665            "considerations": {}
206666          }
206667        },
206668        {
206669          "type": "library",
206670          "bom-ref": "pkg:npm/swagger-ui-dist@3.43.0?package-id=9e46999407d696d1",
206671          "supplier": {},
206672          "name": "swagger-ui-dist",
206673          "version": "3.43.0",
206674          "description": "[![NPM version](https://badge.fury.io/js/swagger-ui-dist.svg)](http://badge.fury.io/js/swagger-ui-dist)",
206675          "licenses": [
206676            {
206677              "license": {
206678                "id": "Apache-2.0"
206679              }
206680            }
206681          ],
206682          "cpe": "cpe:2.3:a:swagger-ui-dist:swagger-ui-dist:3.43.0:*:*:*:*:*:*:*",
206683          "purl": "pkg:npm/swagger-ui-dist@3.43.0",
206684          "swid": {
206685            "attachment": {}
206686          },
206687          "pedigree": {},
206688          "externalReferences": [
206689            {
206690              "url": "git+ssh://git@github.com/swagger-api/swagger-ui.git",
206691              "type": "distribution"
206692            },
206693            {
206694              "url": "https://github.com/swagger-api/swagger-ui#readme",
206695              "type": "website"
206696            }
206697          ],
206698          "evidence": {},
206699          "signature": {
206700            "signature": {
206701              "publicKey": {}
206702            }
206703          },
206704          "modelCard": {
206705            "modelParameters": {
206706              "approach": {}
206707            },
206708            "quantitativeAnalysis": {
206709              "graphics": {}
206710            },
206711            "considerations": {}
206712          }
206713        },
206714        {
206715          "type": "library",
206716          "bom-ref": "pkg:npm/swagger-ui-express@4.1.6?package-id=7b829ce58415e1f2",
206717          "supplier": {},
206718          "author": "Stephen Scott \u003cscottie1984@gmail.com\u003e",
206719          "name": "swagger-ui-express",
206720          "version": "4.1.6",
206721          "description": "Swagger UI Express",
206722          "licenses": [
206723            {
206724              "license": {
206725                "id": "MIT"
206726              }
206727            }
206728          ],
206729          "cpe": "cpe:2.3:a:swagger-ui-express:swagger-ui-express:4.1.6:*:*:*:*:*:*:*",
206730          "purl": "pkg:npm/swagger-ui-express@4.1.6",
206731          "swid": {
206732            "attachment": {}
206733          },
206734          "pedigree": {},
206735          "externalReferences": [
206736            {
206737              "url": "git+ssh://git@github.com/scottie1984/swagger-ui-express.git",
206738              "type": "distribution"
206739            },
206740            {
206741              "url": "https://github.com/scottie1984/swagger-ui-express",
206742              "type": "website"
206743            }
206744          ],
206745          "evidence": {},
206746          "signature": {
206747            "signature": {
206748              "publicKey": {}
206749            }
206750          },
206751          "modelCard": {
206752            "modelParameters": {
206753              "approach": {}
206754            },
206755            "quantitativeAnalysis": {
206756              "graphics": {}
206757            },
206758            "considerations": {}
206759          }
206760        },
206761        {
206762          "type": "library",
206763          "bom-ref": "pkg:npm/tar@4.4.19?package-id=9c9c5053c0d2bf4e",
206764          "supplier": {},
206765          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
206766          "name": "tar",
206767          "version": "4.4.19",
206768          "description": "tar for node",
206769          "licenses": [
206770            {
206771              "license": {
206772                "id": "ISC"
206773              }
206774            }
206775          ],
206776          "cpe": "cpe:2.3:a:npm:tar:4.4.19:*:*:*:*:*:*:*",
206777          "purl": "pkg:npm/tar@4.4.19",
206778          "swid": {
206779            "attachment": {}
206780          },
206781          "pedigree": {},
206782          "externalReferences": [
206783            {
206784              "url": "git+https://github.com/npm/node-tar.git",
206785              "type": "distribution"
206786            },
206787            {
206788              "url": "https://github.com/npm/node-tar#readme",
206789              "type": "website"
206790            }
206791          ],
206792          "evidence": {},
206793          "signature": {
206794            "signature": {
206795              "publicKey": {}
206796            }
206797          },
206798          "modelCard": {
206799            "modelParameters": {
206800              "approach": {}
206801            },
206802            "quantitativeAnalysis": {
206803              "graphics": {}
206804            },
206805            "considerations": {}
206806          }
206807        },
206808        {
206809          "type": "library",
206810          "bom-ref": "pkg:npm/term-size@1.2.0?package-id=b1193806642eaebf",
206811          "supplier": {},
206812          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
206813          "name": "term-size",
206814          "version": "1.2.0",
206815          "description": "Reliably get the terminal window size (columns \u0026 rows)",
206816          "licenses": [
206817            {
206818              "license": {
206819                "id": "MIT"
206820              }
206821            }
206822          ],
206823          "cpe": "cpe:2.3:a:sindresorhus:term-size:1.2.0:*:*:*:*:*:*:*",
206824          "purl": "pkg:npm/term-size@1.2.0",
206825          "swid": {
206826            "attachment": {}
206827          },
206828          "pedigree": {},
206829          "externalReferences": [
206830            {
206831              "url": "git+https://github.com/sindresorhus/term-size.git",
206832              "type": "distribution"
206833            },
206834            {
206835              "url": "https://github.com/sindresorhus/term-size#readme",
206836              "type": "website"
206837            }
206838          ],
206839          "evidence": {},
206840          "signature": {
206841            "signature": {
206842              "publicKey": {}
206843            }
206844          },
206845          "modelCard": {
206846            "modelParameters": {
206847              "approach": {}
206848            },
206849            "quantitativeAnalysis": {
206850              "graphics": {}
206851            },
206852            "considerations": {}
206853          }
206854        },
206855        {
206856          "type": "library",
206857          "bom-ref": "pkg:npm/text-table@0.2.0?package-id=a124be9ad599668f",
206858          "supplier": {},
206859          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
206860          "name": "text-table",
206861          "version": "0.2.0",
206862          "description": "borderless text tables with alignment",
206863          "licenses": [
206864            {
206865              "license": {
206866                "id": "MIT"
206867              }
206868            }
206869          ],
206870          "cpe": "cpe:2.3:a:text-table:text-table:0.2.0:*:*:*:*:*:*:*",
206871          "purl": "pkg:npm/text-table@0.2.0",
206872          "swid": {
206873            "attachment": {}
206874          },
206875          "pedigree": {},
206876          "externalReferences": [
206877            {
206878              "url": "git://github.com/substack/text-table.git",
206879              "type": "distribution"
206880            },
206881            {
206882              "url": "https://github.com/substack/text-table",
206883              "type": "website"
206884            }
206885          ],
206886          "evidence": {},
206887          "signature": {
206888            "signature": {
206889              "publicKey": {}
206890            }
206891          },
206892          "modelCard": {
206893            "modelParameters": {
206894              "approach": {}
206895            },
206896            "quantitativeAnalysis": {
206897              "graphics": {}
206898            },
206899            "considerations": {}
206900          }
206901        },
206902        {
206903          "type": "library",
206904          "bom-ref": "pkg:npm/through@2.3.8?package-id=4d5d009c68a6687c",
206905          "supplier": {},
206906          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (dominictarr.com)",
206907          "name": "through",
206908          "version": "2.3.8",
206909          "description": "simplified stream construction",
206910          "licenses": [
206911            {
206912              "license": {
206913                "id": "MIT"
206914              }
206915            }
206916          ],
206917          "cpe": "cpe:2.3:a:dominictarr:through:2.3.8:*:*:*:*:*:*:*",
206918          "purl": "pkg:npm/through@2.3.8",
206919          "swid": {
206920            "attachment": {}
206921          },
206922          "pedigree": {},
206923          "externalReferences": [
206924            {
206925              "url": "git+https://github.com/dominictarr/through.git",
206926              "type": "distribution"
206927            },
206928            {
206929              "url": "https://github.com/dominictarr/through",
206930              "type": "website"
206931            }
206932          ],
206933          "evidence": {},
206934          "signature": {
206935            "signature": {
206936              "publicKey": {}
206937            }
206938          },
206939          "modelCard": {
206940            "modelParameters": {
206941              "approach": {}
206942            },
206943            "quantitativeAnalysis": {
206944              "graphics": {}
206945            },
206946            "considerations": {}
206947          }
206948        },
206949        {
206950          "type": "library",
206951          "bom-ref": "pkg:npm/through2@2.0.3?package-id=8dbf9f3bfb369784",
206952          "supplier": {},
206953          "author": "Rod Vagg \u003cr@va.gg\u003e (https://github.com/rvagg)",
206954          "name": "through2",
206955          "version": "2.0.3",
206956          "description": "A tiny wrapper around Node streams2 Transform to avoid explicit subclassing noise",
206957          "licenses": [
206958            {
206959              "license": {
206960                "id": "MIT"
206961              }
206962            }
206963          ],
206964          "cpe": "cpe:2.3:a:through2:through2:2.0.3:*:*:*:*:*:*:*",
206965          "purl": "pkg:npm/through2@2.0.3",
206966          "swid": {
206967            "attachment": {}
206968          },
206969          "pedigree": {},
206970          "externalReferences": [
206971            {
206972              "url": "git+https://github.com/rvagg/through2.git",
206973              "type": "distribution"
206974            },
206975            {
206976              "url": "https://github.com/rvagg/through2#readme",
206977              "type": "website"
206978            }
206979          ],
206980          "evidence": {},
206981          "signature": {
206982            "signature": {
206983              "publicKey": {}
206984            }
206985          },
206986          "modelCard": {
206987            "modelParameters": {
206988              "approach": {}
206989            },
206990            "quantitativeAnalysis": {
206991              "graphics": {}
206992            },
206993            "considerations": {}
206994          }
206995        },
206996        {
206997          "type": "library",
206998          "bom-ref": "pkg:npm/timed-out@4.0.1?package-id=8c5219320754c34a",
206999          "supplier": {},
207000          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e",
207001          "name": "timed-out",
207002          "version": "4.0.1",
207003          "description": "Emit `ETIMEDOUT` or `ESOCKETTIMEDOUT` when ClientRequest is hanged",
207004          "licenses": [
207005            {
207006              "license": {
207007                "id": "MIT"
207008              }
207009            }
207010          ],
207011          "cpe": "cpe:2.3:a:floatdrop:timed-out:4.0.1:*:*:*:*:*:*:*",
207012          "purl": "pkg:npm/timed-out@4.0.1",
207013          "swid": {
207014            "attachment": {}
207015          },
207016          "pedigree": {},
207017          "externalReferences": [
207018            {
207019              "url": "git+https://github.com/floatdrop/timed-out.git",
207020              "type": "distribution"
207021            },
207022            {
207023              "url": "https://github.com/floatdrop/timed-out#readme",
207024              "type": "website"
207025            }
207026          ],
207027          "evidence": {},
207028          "signature": {
207029            "signature": {
207030              "publicKey": {}
207031            }
207032          },
207033          "modelCard": {
207034            "modelParameters": {
207035              "approach": {}
207036            },
207037            "quantitativeAnalysis": {
207038              "graphics": {}
207039            },
207040            "considerations": {}
207041          }
207042        },
207043        {
207044          "type": "library",
207045          "bom-ref": "pkg:npm/tiny-relative-date@1.3.0?package-id=192b923f399b9869",
207046          "supplier": {},
207047          "author": "Joseph Wynn \u003cjoseph@wildlyinaccurate.com\u003e (https://wildlyinaccurate.com/)",
207048          "name": "tiny-relative-date",
207049          "version": "1.3.0",
207050          "description": "Tiny function that provides relative, human-readable dates.",
207051          "licenses": [
207052            {
207053              "license": {
207054                "id": "MIT"
207055              }
207056            }
207057          ],
207058          "cpe": "cpe:2.3:a:tiny-relative-date:tiny-relative-date:1.3.0:*:*:*:*:*:*:*",
207059          "purl": "pkg:npm/tiny-relative-date@1.3.0",
207060          "swid": {
207061            "attachment": {}
207062          },
207063          "pedigree": {},
207064          "externalReferences": [
207065            {
207066              "url": "git+https://github.com/wildlyinaccurate/relative-date.git",
207067              "type": "distribution"
207068            },
207069            {
207070              "url": "https://github.com/wildlyinaccurate/relative-date#readme",
207071              "type": "website"
207072            }
207073          ],
207074          "evidence": {},
207075          "signature": {
207076            "signature": {
207077              "publicKey": {}
207078            }
207079          },
207080          "modelCard": {
207081            "modelParameters": {
207082              "approach": {}
207083            },
207084            "quantitativeAnalysis": {
207085              "graphics": {}
207086            },
207087            "considerations": {}
207088          }
207089        },
207090        {
207091          "type": "library",
207092          "bom-ref": "pkg:npm/toidentifier@1.0.0?package-id=b139c4c4805829ae",
207093          "supplier": {},
207094          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
207095          "name": "toidentifier",
207096          "version": "1.0.0",
207097          "description": "Convert a string of words to a JavaScript identifier",
207098          "licenses": [
207099            {
207100              "license": {
207101                "id": "MIT"
207102              }
207103            }
207104          ],
207105          "cpe": "cpe:2.3:a:toidentifier:toidentifier:1.0.0:*:*:*:*:*:*:*",
207106          "purl": "pkg:npm/toidentifier@1.0.0",
207107          "swid": {
207108            "attachment": {}
207109          },
207110          "pedigree": {},
207111          "externalReferences": [
207112            {
207113              "url": "git+https://github.com/component/toidentifier.git",
207114              "type": "distribution"
207115            },
207116            {
207117              "url": "https://github.com/component/toidentifier#readme",
207118              "type": "website"
207119            }
207120          ],
207121          "evidence": {},
207122          "signature": {
207123            "signature": {
207124              "publicKey": {}
207125            }
207126          },
207127          "modelCard": {
207128            "modelParameters": {
207129              "approach": {}
207130            },
207131            "quantitativeAnalysis": {
207132              "graphics": {}
207133            },
207134            "considerations": {}
207135          }
207136        },
207137        {
207138          "type": "library",
207139          "bom-ref": "pkg:npm/tough-cookie@2.4.3?package-id=13b418b16f100361",
207140          "supplier": {},
207141          "author": "Jeremy Stashewsky \u003cjstash@gmail.com\u003e",
207142          "name": "tough-cookie",
207143          "version": "2.4.3",
207144          "description": "RFC6265 Cookies and Cookie Jar for node.js",
207145          "licenses": [
207146            {
207147              "license": {
207148                "id": "BSD-3-Clause"
207149              }
207150            }
207151          ],
207152          "cpe": "cpe:2.3:a:tough-cookie:tough-cookie:2.4.3:*:*:*:*:*:*:*",
207153          "purl": "pkg:npm/tough-cookie@2.4.3",
207154          "swid": {
207155            "attachment": {}
207156          },
207157          "pedigree": {},
207158          "externalReferences": [
207159            {
207160              "url": "git://github.com/salesforce/tough-cookie.git",
207161              "type": "distribution"
207162            },
207163            {
207164              "url": "https://github.com/salesforce/tough-cookie",
207165              "type": "website"
207166            }
207167          ],
207168          "evidence": {},
207169          "signature": {
207170            "signature": {
207171              "publicKey": {}
207172            }
207173          },
207174          "modelCard": {
207175            "modelParameters": {
207176              "approach": {}
207177            },
207178            "quantitativeAnalysis": {
207179              "graphics": {}
207180            },
207181            "considerations": {}
207182          }
207183        },
207184        {
207185          "type": "library",
207186          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=6536b2dd10d6cbb5",
207187          "supplier": {},
207188          "author": "Microsoft Corp.",
207189          "name": "tslib",
207190          "version": "1.14.1",
207191          "description": "Runtime library for TypeScript helper functions",
207192          "licenses": [
207193            {
207194              "license": {
207195                "id": "0BSD"
207196              }
207197            }
207198          ],
207199          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
207200          "purl": "pkg:npm/tslib@1.14.1",
207201          "swid": {
207202            "attachment": {}
207203          },
207204          "pedigree": {},
207205          "externalReferences": [
207206            {
207207              "url": "git+https://github.com/Microsoft/tslib.git",
207208              "type": "distribution"
207209            },
207210            {
207211              "url": "https://www.typescriptlang.org/",
207212              "type": "website"
207213            }
207214          ],
207215          "evidence": {},
207216          "signature": {
207217            "signature": {
207218              "publicKey": {}
207219            }
207220          },
207221          "modelCard": {
207222            "modelParameters": {
207223              "approach": {}
207224            },
207225            "quantitativeAnalysis": {
207226              "graphics": {}
207227            },
207228            "considerations": {}
207229          }
207230        },
207231        {
207232          "type": "library",
207233          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=1d66cb61fb941655",
207234          "supplier": {},
207235          "author": "Microsoft Corp.",
207236          "name": "tslib",
207237          "version": "1.14.1",
207238          "description": "Runtime library for TypeScript helper functions",
207239          "licenses": [
207240            {
207241              "license": {
207242                "id": "0BSD"
207243              }
207244            }
207245          ],
207246          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
207247          "purl": "pkg:npm/tslib@1.14.1",
207248          "swid": {
207249            "attachment": {}
207250          },
207251          "pedigree": {},
207252          "externalReferences": [
207253            {
207254              "url": "git+https://github.com/Microsoft/tslib.git",
207255              "type": "distribution"
207256            },
207257            {
207258              "url": "https://www.typescriptlang.org/",
207259              "type": "website"
207260            }
207261          ],
207262          "evidence": {},
207263          "signature": {
207264            "signature": {
207265              "publicKey": {}
207266            }
207267          },
207268          "modelCard": {
207269            "modelParameters": {
207270              "approach": {}
207271            },
207272            "quantitativeAnalysis": {
207273              "graphics": {}
207274            },
207275            "considerations": {}
207276          }
207277        },
207278        {
207279          "type": "library",
207280          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=85f17f7fdbf8a5d0",
207281          "supplier": {},
207282          "author": "Microsoft Corp.",
207283          "name": "tslib",
207284          "version": "1.14.1",
207285          "description": "Runtime library for TypeScript helper functions",
207286          "licenses": [
207287            {
207288              "license": {
207289                "id": "0BSD"
207290              }
207291            }
207292          ],
207293          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
207294          "purl": "pkg:npm/tslib@1.14.1",
207295          "swid": {
207296            "attachment": {}
207297          },
207298          "pedigree": {},
207299          "externalReferences": [
207300            {
207301              "url": "git+https://github.com/Microsoft/tslib.git",
207302              "type": "distribution"
207303            },
207304            {
207305              "url": "https://www.typescriptlang.org/",
207306              "type": "website"
207307            }
207308          ],
207309          "evidence": {},
207310          "signature": {
207311            "signature": {
207312              "publicKey": {}
207313            }
207314          },
207315          "modelCard": {
207316            "modelParameters": {
207317              "approach": {}
207318            },
207319            "quantitativeAnalysis": {
207320              "graphics": {}
207321            },
207322            "considerations": {}
207323          }
207324        },
207325        {
207326          "type": "library",
207327          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=5529bb73f7015d14",
207328          "supplier": {},
207329          "author": "Microsoft Corp.",
207330          "name": "tslib",
207331          "version": "1.14.1",
207332          "description": "Runtime library for TypeScript helper functions",
207333          "licenses": [
207334            {
207335              "license": {
207336                "id": "0BSD"
207337              }
207338            }
207339          ],
207340          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
207341          "purl": "pkg:npm/tslib@1.14.1",
207342          "swid": {
207343            "attachment": {}
207344          },
207345          "pedigree": {},
207346          "externalReferences": [
207347            {
207348              "url": "git+https://github.com/Microsoft/tslib.git",
207349              "type": "distribution"
207350            },
207351            {
207352              "url": "https://www.typescriptlang.org/",
207353              "type": "website"
207354            }
207355          ],
207356          "evidence": {},
207357          "signature": {
207358            "signature": {
207359              "publicKey": {}
207360            }
207361          },
207362          "modelCard": {
207363            "modelParameters": {
207364              "approach": {}
207365            },
207366            "quantitativeAnalysis": {
207367              "graphics": {}
207368            },
207369            "considerations": {}
207370          }
207371        },
207372        {
207373          "type": "library",
207374          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=4a8087d9ced7b72a",
207375          "supplier": {},
207376          "author": "Microsoft Corp.",
207377          "name": "tslib",
207378          "version": "1.14.1",
207379          "description": "Runtime library for TypeScript helper functions",
207380          "licenses": [
207381            {
207382              "license": {
207383                "id": "0BSD"
207384              }
207385            }
207386          ],
207387          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
207388          "purl": "pkg:npm/tslib@1.14.1",
207389          "swid": {
207390            "attachment": {}
207391          },
207392          "pedigree": {},
207393          "externalReferences": [
207394            {
207395              "url": "git+https://github.com/Microsoft/tslib.git",
207396              "type": "distribution"
207397            },
207398            {
207399              "url": "https://www.typescriptlang.org/",
207400              "type": "website"
207401            }
207402          ],
207403          "evidence": {},
207404          "signature": {
207405            "signature": {
207406              "publicKey": {}
207407            }
207408          },
207409          "modelCard": {
207410            "modelParameters": {
207411              "approach": {}
207412            },
207413            "quantitativeAnalysis": {
207414              "graphics": {}
207415            },
207416            "considerations": {}
207417          }
207418        },
207419        {
207420          "type": "library",
207421          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=81b6a4b44008213",
207422          "supplier": {},
207423          "author": "Microsoft Corp.",
207424          "name": "tslib",
207425          "version": "1.14.1",
207426          "description": "Runtime library for TypeScript helper functions",
207427          "licenses": [
207428            {
207429              "license": {
207430                "id": "0BSD"
207431              }
207432            }
207433          ],
207434          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
207435          "purl": "pkg:npm/tslib@1.14.1",
207436          "swid": {
207437            "attachment": {}
207438          },
207439          "pedigree": {},
207440          "externalReferences": [
207441            {
207442              "url": "git+https://github.com/Microsoft/tslib.git",
207443              "type": "distribution"
207444            },
207445            {
207446              "url": "https://www.typescriptlang.org/",
207447              "type": "website"
207448            }
207449          ],
207450          "evidence": {},
207451          "signature": {
207452            "signature": {
207453              "publicKey": {}
207454            }
207455          },
207456          "modelCard": {
207457            "modelParameters": {
207458              "approach": {}
207459            },
207460            "quantitativeAnalysis": {
207461              "graphics": {}
207462            },
207463            "considerations": {}
207464          }
207465        },
207466        {
207467          "type": "library",
207468          "bom-ref": "pkg:npm/tslib@2.1.0?package-id=2fc99281bc7a8815",
207469          "supplier": {},
207470          "author": "Microsoft Corp.",
207471          "name": "tslib",
207472          "version": "2.1.0",
207473          "description": "Runtime library for TypeScript helper functions",
207474          "licenses": [
207475            {
207476              "license": {
207477                "id": "0BSD"
207478              }
207479            }
207480          ],
207481          "cpe": "cpe:2.3:a:tslib:tslib:2.1.0:*:*:*:*:*:*:*",
207482          "purl": "pkg:npm/tslib@2.1.0",
207483          "swid": {
207484            "attachment": {}
207485          },
207486          "pedigree": {},
207487          "externalReferences": [
207488            {
207489              "url": "git+https://github.com/Microsoft/tslib.git",
207490              "type": "distribution"
207491            },
207492            {
207493              "url": "https://www.typescriptlang.org/",
207494              "type": "website"
207495            }
207496          ],
207497          "evidence": {},
207498          "signature": {
207499            "signature": {
207500              "publicKey": {}
207501            }
207502          },
207503          "modelCard": {
207504            "modelParameters": {
207505              "approach": {}
207506            },
207507            "quantitativeAnalysis": {
207508              "graphics": {}
207509            },
207510            "considerations": {}
207511          }
207512        },
207513        {
207514          "type": "library",
207515          "bom-ref": "pkg:npm/tunnel-agent@0.6.0?package-id=5f666f5e908dfc65",
207516          "supplier": {},
207517          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
207518          "name": "tunnel-agent",
207519          "version": "0.6.0",
207520          "description": "HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.",
207521          "licenses": [
207522            {
207523              "license": {
207524                "id": "Apache-2.0"
207525              }
207526            }
207527          ],
207528          "cpe": "cpe:2.3:a:tunnel-agent:tunnel-agent:0.6.0:*:*:*:*:*:*:*",
207529          "purl": "pkg:npm/tunnel-agent@0.6.0",
207530          "swid": {
207531            "attachment": {}
207532          },
207533          "pedigree": {},
207534          "externalReferences": [
207535            {
207536              "url": "git+https://github.com/mikeal/tunnel-agent.git",
207537              "type": "distribution"
207538            },
207539            {
207540              "url": "https://github.com/mikeal/tunnel-agent#readme",
207541              "type": "website"
207542            }
207543          ],
207544          "evidence": {},
207545          "signature": {
207546            "signature": {
207547              "publicKey": {}
207548            }
207549          },
207550          "modelCard": {
207551            "modelParameters": {
207552              "approach": {}
207553            },
207554            "quantitativeAnalysis": {
207555              "graphics": {}
207556            },
207557            "considerations": {}
207558          }
207559        },
207560        {
207561          "type": "library",
207562          "bom-ref": "pkg:npm/tweetnacl@0.14.5?package-id=978333255b1b0435",
207563          "supplier": {},
207564          "author": "TweetNaCl-js contributors",
207565          "name": "tweetnacl",
207566          "version": "0.14.5",
207567          "description": "Port of TweetNaCl cryptographic library to JavaScript",
207568          "licenses": [
207569            {
207570              "license": {
207571                "id": "Unlicense"
207572              }
207573            }
207574          ],
207575          "cpe": "cpe:2.3:a:tweetnacl:tweetnacl:0.14.5:*:*:*:*:*:*:*",
207576          "purl": "pkg:npm/tweetnacl@0.14.5",
207577          "swid": {
207578            "attachment": {}
207579          },
207580          "pedigree": {},
207581          "externalReferences": [
207582            {
207583              "url": "git+https://github.com/dchest/tweetnacl-js.git",
207584              "type": "distribution"
207585            },
207586            {
207587              "url": "https://tweetnacl.js.org",
207588              "type": "website"
207589            }
207590          ],
207591          "evidence": {},
207592          "signature": {
207593            "signature": {
207594              "publicKey": {}
207595            }
207596          },
207597          "modelCard": {
207598            "modelParameters": {
207599              "approach": {}
207600            },
207601            "quantitativeAnalysis": {
207602              "graphics": {}
207603            },
207604            "considerations": {}
207605          }
207606        },
207607        {
207608          "type": "library",
207609          "bom-ref": "pkg:npm/type-fest@0.20.2?package-id=20a77ee3cf7802b3",
207610          "supplier": {},
207611          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
207612          "name": "type-fest",
207613          "version": "0.20.2",
207614          "description": "A collection of essential TypeScript types",
207615          "licenses": [
207616            {
207617              "license": {
207618                "name": "(MIT OR CC0-1.0)"
207619              }
207620            }
207621          ],
207622          "cpe": "cpe:2.3:a:sindresorhus:type-fest:0.20.2:*:*:*:*:*:*:*",
207623          "purl": "pkg:npm/type-fest@0.20.2",
207624          "swid": {
207625            "attachment": {}
207626          },
207627          "pedigree": {},
207628          "externalReferences": [
207629            {
207630              "url": "git+https://github.com/sindresorhus/type-fest.git",
207631              "type": "distribution"
207632            },
207633            {
207634              "url": "https://github.com/sindresorhus/type-fest#readme",
207635              "type": "website"
207636            }
207637          ],
207638          "evidence": {},
207639          "signature": {
207640            "signature": {
207641              "publicKey": {}
207642            }
207643          },
207644          "modelCard": {
207645            "modelParameters": {
207646              "approach": {}
207647            },
207648            "quantitativeAnalysis": {
207649              "graphics": {}
207650            },
207651            "considerations": {}
207652          }
207653        },
207654        {
207655          "type": "library",
207656          "bom-ref": "pkg:npm/type-fest@2.19.0?package-id=f8a109d13e380a83",
207657          "supplier": {},
207658          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
207659          "name": "type-fest",
207660          "version": "2.19.0",
207661          "description": "A collection of essential TypeScript types",
207662          "licenses": [
207663            {
207664              "license": {
207665                "name": "(MIT OR CC0-1.0)"
207666              }
207667            }
207668          ],
207669          "cpe": "cpe:2.3:a:sindresorhus:type-fest:2.19.0:*:*:*:*:*:*:*",
207670          "purl": "pkg:npm/type-fest@2.19.0",
207671          "swid": {
207672            "attachment": {}
207673          },
207674          "pedigree": {},
207675          "externalReferences": [
207676            {
207677              "url": "git+https://github.com/sindresorhus/type-fest.git",
207678              "type": "distribution"
207679            },
207680            {
207681              "url": "https://github.com/sindresorhus/type-fest#readme",
207682              "type": "website"
207683            }
207684          ],
207685          "evidence": {},
207686          "signature": {
207687            "signature": {
207688              "publicKey": {}
207689            }
207690          },
207691          "modelCard": {
207692            "modelParameters": {
207693              "approach": {}
207694            },
207695            "quantitativeAnalysis": {
207696              "graphics": {}
207697            },
207698            "considerations": {}
207699          }
207700        },
207701        {
207702          "type": "library",
207703          "bom-ref": "pkg:npm/type-is@1.6.18?package-id=a4eef9183b32a31",
207704          "supplier": {},
207705          "name": "type-is",
207706          "version": "1.6.18",
207707          "description": "Infer the content-type of a request.",
207708          "licenses": [
207709            {
207710              "license": {
207711                "id": "MIT"
207712              }
207713            }
207714          ],
207715          "cpe": "cpe:2.3:a:type-is:type-is:1.6.18:*:*:*:*:*:*:*",
207716          "purl": "pkg:npm/type-is@1.6.18",
207717          "swid": {
207718            "attachment": {}
207719          },
207720          "pedigree": {},
207721          "externalReferences": [
207722            {
207723              "url": "git+https://github.com/jshttp/type-is.git",
207724              "type": "distribution"
207725            },
207726            {
207727              "url": "https://github.com/jshttp/type-is#readme",
207728              "type": "website"
207729            }
207730          ],
207731          "evidence": {},
207732          "signature": {
207733            "signature": {
207734              "publicKey": {}
207735            }
207736          },
207737          "modelCard": {
207738            "modelParameters": {
207739              "approach": {}
207740            },
207741            "quantitativeAnalysis": {
207742              "graphics": {}
207743            },
207744            "considerations": {}
207745          }
207746        },
207747        {
207748          "type": "library",
207749          "bom-ref": "pkg:npm/typedarray@0.0.6?package-id=f7beac06324a3356",
207750          "supplier": {},
207751          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
207752          "name": "typedarray",
207753          "version": "0.0.6",
207754          "description": "TypedArray polyfill for old browsers",
207755          "licenses": [
207756            {
207757              "license": {
207758                "id": "MIT"
207759              }
207760            }
207761          ],
207762          "cpe": "cpe:2.3:a:typedarray:typedarray:0.0.6:*:*:*:*:*:*:*",
207763          "purl": "pkg:npm/typedarray@0.0.6",
207764          "swid": {
207765            "attachment": {}
207766          },
207767          "pedigree": {},
207768          "externalReferences": [
207769            {
207770              "url": "git://github.com/substack/typedarray.git",
207771              "type": "distribution"
207772            },
207773            {
207774              "url": "https://github.com/substack/typedarray",
207775              "type": "website"
207776            }
207777          ],
207778          "evidence": {},
207779          "signature": {
207780            "signature": {
207781              "publicKey": {}
207782            }
207783          },
207784          "modelCard": {
207785            "modelParameters": {
207786              "approach": {}
207787            },
207788            "quantitativeAnalysis": {
207789              "graphics": {}
207790            },
207791            "considerations": {}
207792          }
207793        },
207794        {
207795          "type": "library",
207796          "bom-ref": "pkg:npm/typedarray@0.0.6?package-id=8f3ba3a6a4336960",
207797          "supplier": {},
207798          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
207799          "name": "typedarray",
207800          "version": "0.0.6",
207801          "description": "TypedArray polyfill for old browsers",
207802          "licenses": [
207803            {
207804              "license": {
207805                "id": "MIT"
207806              }
207807            }
207808          ],
207809          "cpe": "cpe:2.3:a:typedarray:typedarray:0.0.6:*:*:*:*:*:*:*",
207810          "purl": "pkg:npm/typedarray@0.0.6",
207811          "swid": {
207812            "attachment": {}
207813          },
207814          "pedigree": {},
207815          "externalReferences": [
207816            {
207817              "url": "git://github.com/substack/typedarray.git",
207818              "type": "distribution"
207819            },
207820            {
207821              "url": "https://github.com/substack/typedarray",
207822              "type": "website"
207823            }
207824          ],
207825          "evidence": {},
207826          "signature": {
207827            "signature": {
207828              "publicKey": {}
207829            }
207830          },
207831          "modelCard": {
207832            "modelParameters": {
207833              "approach": {}
207834            },
207835            "quantitativeAnalysis": {
207836              "graphics": {}
207837            },
207838            "considerations": {}
207839          }
207840        },
207841        {
207842          "type": "library",
207843          "bom-ref": "pkg:npm/uid-number@0.0.6?package-id=c6b3a428d7d6414b",
207844          "supplier": {},
207845          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
207846          "name": "uid-number",
207847          "version": "0.0.6",
207848          "description": "Convert a username/group name to a uid/gid number",
207849          "licenses": [
207850            {
207851              "license": {
207852                "id": "ISC"
207853              }
207854            }
207855          ],
207856          "cpe": "cpe:2.3:a:uid-number:uid-number:0.0.6:*:*:*:*:*:*:*",
207857          "purl": "pkg:npm/uid-number@0.0.6",
207858          "swid": {
207859            "attachment": {}
207860          },
207861          "pedigree": {},
207862          "externalReferences": [
207863            {
207864              "url": "git://github.com/isaacs/uid-number.git",
207865              "type": "distribution"
207866            },
207867            {
207868              "url": "https://github.com/isaacs/uid-number#readme",
207869              "type": "website"
207870            }
207871          ],
207872          "evidence": {},
207873          "signature": {
207874            "signature": {
207875              "publicKey": {}
207876            }
207877          },
207878          "modelCard": {
207879            "modelParameters": {
207880              "approach": {}
207881            },
207882            "quantitativeAnalysis": {
207883              "graphics": {}
207884            },
207885            "considerations": {}
207886          }
207887        },
207888        {
207889          "type": "library",
207890          "bom-ref": "pkg:npm/umask@1.1.0?package-id=c2c1639822e8e1f2",
207891          "supplier": {},
207892          "author": "Sam Mikes \u003csmikes@cubane.com\u003e",
207893          "name": "umask",
207894          "version": "1.1.0",
207895          "description": "convert umask from string \u003c-\u003e number",
207896          "licenses": [
207897            {
207898              "license": {
207899                "id": "MIT"
207900              }
207901            }
207902          ],
207903          "cpe": "cpe:2.3:a:smikes:umask:1.1.0:*:*:*:*:*:*:*",
207904          "purl": "pkg:npm/umask@1.1.0",
207905          "swid": {
207906            "attachment": {}
207907          },
207908          "pedigree": {},
207909          "externalReferences": [
207910            {
207911              "url": "git+https://github.com/smikes/umask.git",
207912              "type": "distribution"
207913            },
207914            {
207915              "url": "https://github.com/smikes/umask",
207916              "type": "website"
207917            }
207918          ],
207919          "evidence": {},
207920          "signature": {
207921            "signature": {
207922              "publicKey": {}
207923            }
207924          },
207925          "modelCard": {
207926            "modelParameters": {
207927              "approach": {}
207928            },
207929            "quantitativeAnalysis": {
207930              "graphics": {}
207931            },
207932            "considerations": {}
207933          }
207934        },
207935        {
207936          "type": "library",
207937          "bom-ref": "pkg:npm/unique-filename@1.1.1?package-id=7ca7ff63263b2fc2",
207938          "supplier": {},
207939          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
207940          "name": "unique-filename",
207941          "version": "1.1.1",
207942          "description": "Generate a unique filename for use in temporary directories or caches.",
207943          "licenses": [
207944            {
207945              "license": {
207946                "id": "ISC"
207947              }
207948            }
207949          ],
207950          "cpe": "cpe:2.3:a:unique-filename:unique-filename:1.1.1:*:*:*:*:*:*:*",
207951          "purl": "pkg:npm/unique-filename@1.1.1",
207952          "swid": {
207953            "attachment": {}
207954          },
207955          "pedigree": {},
207956          "externalReferences": [
207957            {
207958              "url": "git+https://github.com/iarna/unique-filename.git",
207959              "type": "distribution"
207960            },
207961            {
207962              "url": "https://github.com/iarna/unique-filename",
207963              "type": "website"
207964            }
207965          ],
207966          "evidence": {},
207967          "signature": {
207968            "signature": {
207969              "publicKey": {}
207970            }
207971          },
207972          "modelCard": {
207973            "modelParameters": {
207974              "approach": {}
207975            },
207976            "quantitativeAnalysis": {
207977              "graphics": {}
207978            },
207979            "considerations": {}
207980          }
207981        },
207982        {
207983          "type": "library",
207984          "bom-ref": "pkg:npm/unique-slug@2.0.0?package-id=924ca3204f5aad87",
207985          "supplier": {},
207986          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org)",
207987          "name": "unique-slug",
207988          "version": "2.0.0",
207989          "description": "Generate a unique character string suitible for use in files and URLs.",
207990          "licenses": [
207991            {
207992              "license": {
207993                "id": "ISC"
207994              }
207995            }
207996          ],
207997          "cpe": "cpe:2.3:a:unique-slug:unique-slug:2.0.0:*:*:*:*:*:*:*",
207998          "purl": "pkg:npm/unique-slug@2.0.0",
207999          "swid": {
208000            "attachment": {}
208001          },
208002          "pedigree": {},
208003          "externalReferences": [
208004            {
208005              "url": "git://github.com/iarna/unique-slug.git",
208006              "type": "distribution"
208007            },
208008            {
208009              "url": "https://github.com/iarna/unique-slug#readme",
208010              "type": "website"
208011            }
208012          ],
208013          "evidence": {},
208014          "signature": {
208015            "signature": {
208016              "publicKey": {}
208017            }
208018          },
208019          "modelCard": {
208020            "modelParameters": {
208021              "approach": {}
208022            },
208023            "quantitativeAnalysis": {
208024              "graphics": {}
208025            },
208026            "considerations": {}
208027          }
208028        },
208029        {
208030          "type": "library",
208031          "bom-ref": "pkg:npm/unique-string@1.0.0?package-id=4e6b7ebbf2d6b0b2",
208032          "supplier": {},
208033          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
208034          "name": "unique-string",
208035          "version": "1.0.0",
208036          "description": "Generate a unique random string",
208037          "licenses": [
208038            {
208039              "license": {
208040                "id": "MIT"
208041              }
208042            }
208043          ],
208044          "cpe": "cpe:2.3:a:unique-string:unique-string:1.0.0:*:*:*:*:*:*:*",
208045          "purl": "pkg:npm/unique-string@1.0.0",
208046          "swid": {
208047            "attachment": {}
208048          },
208049          "pedigree": {},
208050          "externalReferences": [
208051            {
208052              "url": "git+https://github.com/sindresorhus/unique-string.git",
208053              "type": "distribution"
208054            },
208055            {
208056              "url": "https://github.com/sindresorhus/unique-string#readme",
208057              "type": "website"
208058            }
208059          ],
208060          "evidence": {},
208061          "signature": {
208062            "signature": {
208063              "publicKey": {}
208064            }
208065          },
208066          "modelCard": {
208067            "modelParameters": {
208068              "approach": {}
208069            },
208070            "quantitativeAnalysis": {
208071              "graphics": {}
208072            },
208073            "considerations": {}
208074          }
208075        },
208076        {
208077          "type": "library",
208078          "bom-ref": "pkg:npm/unpipe@1.0.0?package-id=5fde8937a7c37a7f",
208079          "supplier": {},
208080          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
208081          "name": "unpipe",
208082          "version": "1.0.0",
208083          "description": "Unpipe a stream from all destinations",
208084          "licenses": [
208085            {
208086              "license": {
208087                "id": "MIT"
208088              }
208089            }
208090          ],
208091          "cpe": "cpe:2.3:a:stream-utils:unpipe:1.0.0:*:*:*:*:*:*:*",
208092          "purl": "pkg:npm/unpipe@1.0.0",
208093          "swid": {
208094            "attachment": {}
208095          },
208096          "pedigree": {},
208097          "externalReferences": [
208098            {
208099              "url": "git+https://github.com/stream-utils/unpipe.git",
208100              "type": "distribution"
208101            },
208102            {
208103              "url": "https://github.com/stream-utils/unpipe#readme",
208104              "type": "website"
208105            }
208106          ],
208107          "evidence": {},
208108          "signature": {
208109            "signature": {
208110              "publicKey": {}
208111            }
208112          },
208113          "modelCard": {
208114            "modelParameters": {
208115              "approach": {}
208116            },
208117            "quantitativeAnalysis": {
208118              "graphics": {}
208119            },
208120            "considerations": {}
208121          }
208122        },
208123        {
208124          "type": "library",
208125          "bom-ref": "pkg:npm/unpipe@1.0.0?package-id=6e84e73fed0f90d9",
208126          "supplier": {},
208127          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
208128          "name": "unpipe",
208129          "version": "1.0.0",
208130          "description": "Unpipe a stream from all destinations",
208131          "licenses": [
208132            {
208133              "license": {
208134                "id": "MIT"
208135              }
208136            }
208137          ],
208138          "cpe": "cpe:2.3:a:stream-utils:unpipe:1.0.0:*:*:*:*:*:*:*",
208139          "purl": "pkg:npm/unpipe@1.0.0",
208140          "swid": {
208141            "attachment": {}
208142          },
208143          "pedigree": {},
208144          "externalReferences": [
208145            {
208146              "url": "git+https://github.com/stream-utils/unpipe.git",
208147              "type": "distribution"
208148            },
208149            {
208150              "url": "https://github.com/stream-utils/unpipe#readme",
208151              "type": "website"
208152            }
208153          ],
208154          "evidence": {},
208155          "signature": {
208156            "signature": {
208157              "publicKey": {}
208158            }
208159          },
208160          "modelCard": {
208161            "modelParameters": {
208162              "approach": {}
208163            },
208164            "quantitativeAnalysis": {
208165              "graphics": {}
208166            },
208167            "considerations": {}
208168          }
208169        },
208170        {
208171          "type": "library",
208172          "bom-ref": "pkg:npm/unzip-response@2.0.1?package-id=2f2960808396cad4",
208173          "supplier": {},
208174          "name": "unzip-response",
208175          "version": "2.0.1",
208176          "description": "Unzip a HTTP response if needed",
208177          "licenses": [
208178            {
208179              "license": {
208180                "id": "MIT"
208181              }
208182            }
208183          ],
208184          "cpe": "cpe:2.3:a:unzip-response:unzip-response:2.0.1:*:*:*:*:*:*:*",
208185          "purl": "pkg:npm/unzip-response@2.0.1",
208186          "swid": {
208187            "attachment": {}
208188          },
208189          "pedigree": {},
208190          "externalReferences": [
208191            {
208192              "url": "git+https://github.com/sindresorhus/unzip-response.git",
208193              "type": "distribution"
208194            },
208195            {
208196              "url": "https://github.com/sindresorhus/unzip-response#readme",
208197              "type": "website"
208198            }
208199          ],
208200          "evidence": {},
208201          "signature": {
208202            "signature": {
208203              "publicKey": {}
208204            }
208205          },
208206          "modelCard": {
208207            "modelParameters": {
208208              "approach": {}
208209            },
208210            "quantitativeAnalysis": {
208211              "graphics": {}
208212            },
208213            "considerations": {}
208214          }
208215        },
208216        {
208217          "type": "library",
208218          "bom-ref": "pkg:npm/update-notifier@2.5.0?package-id=e826782630303ce6",
208219          "supplier": {},
208220          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
208221          "name": "update-notifier",
208222          "version": "2.5.0",
208223          "description": "Update notifications for your CLI app",
208224          "licenses": [
208225            {
208226              "license": {
208227                "id": "BSD-2-Clause"
208228              }
208229            }
208230          ],
208231          "cpe": "cpe:2.3:a:update-notifier:update-notifier:2.5.0:*:*:*:*:*:*:*",
208232          "purl": "pkg:npm/update-notifier@2.5.0",
208233          "swid": {
208234            "attachment": {}
208235          },
208236          "pedigree": {},
208237          "externalReferences": [
208238            {
208239              "url": "git+https://github.com/yeoman/update-notifier.git",
208240              "type": "distribution"
208241            },
208242            {
208243              "url": "https://github.com/yeoman/update-notifier#readme",
208244              "type": "website"
208245            }
208246          ],
208247          "evidence": {},
208248          "signature": {
208249            "signature": {
208250              "publicKey": {}
208251            }
208252          },
208253          "modelCard": {
208254            "modelParameters": {
208255              "approach": {}
208256            },
208257            "quantitativeAnalysis": {
208258              "graphics": {}
208259            },
208260            "considerations": {}
208261          }
208262        },
208263        {
208264          "type": "library",
208265          "bom-ref": "pkg:npm/uri-js@4.4.0?package-id=2643142c0c55d592",
208266          "supplier": {},
208267          "author": "Gary Court \u003cgary.court@gmail.com\u003e",
208268          "name": "uri-js",
208269          "version": "4.4.0",
208270          "description": "An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.",
208271          "licenses": [
208272            {
208273              "license": {
208274                "id": "BSD-2-Clause"
208275              }
208276            }
208277          ],
208278          "cpe": "cpe:2.3:a:garycourt:uri-js:4.4.0:*:*:*:*:*:*:*",
208279          "purl": "pkg:npm/uri-js@4.4.0",
208280          "swid": {
208281            "attachment": {}
208282          },
208283          "pedigree": {},
208284          "externalReferences": [
208285            {
208286              "url": "git+ssh://git@github.com/garycourt/uri-js.git",
208287              "type": "distribution"
208288            },
208289            {
208290              "url": "https://github.com/garycourt/uri-js",
208291              "type": "website"
208292            }
208293          ],
208294          "evidence": {},
208295          "signature": {
208296            "signature": {
208297              "publicKey": {}
208298            }
208299          },
208300          "modelCard": {
208301            "modelParameters": {
208302              "approach": {}
208303            },
208304            "quantitativeAnalysis": {
208305              "graphics": {}
208306            },
208307            "considerations": {}
208308          }
208309        },
208310        {
208311          "type": "library",
208312          "bom-ref": "pkg:npm/uri-js@4.4.1?package-id=dfad1f1bc56159f9",
208313          "supplier": {},
208314          "author": "Gary Court \u003cgary.court@gmail.com\u003e",
208315          "name": "uri-js",
208316          "version": "4.4.1",
208317          "description": "An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.",
208318          "licenses": [
208319            {
208320              "license": {
208321                "id": "BSD-2-Clause"
208322              }
208323            }
208324          ],
208325          "cpe": "cpe:2.3:a:garycourt:uri-js:4.4.1:*:*:*:*:*:*:*",
208326          "purl": "pkg:npm/uri-js@4.4.1",
208327          "swid": {
208328            "attachment": {}
208329          },
208330          "pedigree": {},
208331          "externalReferences": [
208332            {
208333              "url": "git+ssh://git@github.com/garycourt/uri-js.git",
208334              "type": "distribution"
208335            },
208336            {
208337              "url": "https://github.com/garycourt/uri-js",
208338              "type": "website"
208339            }
208340          ],
208341          "evidence": {},
208342          "signature": {
208343            "signature": {
208344              "publicKey": {}
208345            }
208346          },
208347          "modelCard": {
208348            "modelParameters": {
208349              "approach": {}
208350            },
208351            "quantitativeAnalysis": {
208352              "graphics": {}
208353            },
208354            "considerations": {}
208355          }
208356        },
208357        {
208358          "type": "library",
208359          "bom-ref": "pkg:npm/url-parse-lax@1.0.0?package-id=66c52cc773273a82",
208360          "supplier": {},
208361          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
208362          "name": "url-parse-lax",
208363          "version": "1.0.0",
208364          "description": "url.parse() with support for protocol-less URLs \u0026 IPs",
208365          "licenses": [
208366            {
208367              "license": {
208368                "id": "MIT"
208369              }
208370            }
208371          ],
208372          "cpe": "cpe:2.3:a:url-parse-lax:url-parse-lax:1.0.0:*:*:*:*:*:*:*",
208373          "purl": "pkg:npm/url-parse-lax@1.0.0",
208374          "swid": {
208375            "attachment": {}
208376          },
208377          "pedigree": {},
208378          "externalReferences": [
208379            {
208380              "url": "git+https://github.com/sindresorhus/url-parse-lax.git",
208381              "type": "distribution"
208382            },
208383            {
208384              "url": "https://github.com/sindresorhus/url-parse-lax#readme",
208385              "type": "website"
208386            }
208387          ],
208388          "evidence": {},
208389          "signature": {
208390            "signature": {
208391              "publicKey": {}
208392            }
208393          },
208394          "modelCard": {
208395            "modelParameters": {
208396              "approach": {}
208397            },
208398            "quantitativeAnalysis": {
208399              "graphics": {}
208400            },
208401            "considerations": {}
208402          }
208403        },
208404        {
208405          "type": "library",
208406          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=adcfe60f42b3bf40",
208407          "supplier": {},
208408          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
208409          "name": "util-deprecate",
208410          "version": "1.0.2",
208411          "description": "The Node.js `util.deprecate()` function with browser support",
208412          "licenses": [
208413            {
208414              "license": {
208415                "id": "MIT"
208416              }
208417            }
208418          ],
208419          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
208420          "purl": "pkg:npm/util-deprecate@1.0.2",
208421          "swid": {
208422            "attachment": {}
208423          },
208424          "pedigree": {},
208425          "externalReferences": [
208426            {
208427              "url": "git://github.com/TooTallNate/util-deprecate.git",
208428              "type": "distribution"
208429            },
208430            {
208431              "url": "https://github.com/TooTallNate/util-deprecate",
208432              "type": "website"
208433            }
208434          ],
208435          "evidence": {},
208436          "signature": {
208437            "signature": {
208438              "publicKey": {}
208439            }
208440          },
208441          "modelCard": {
208442            "modelParameters": {
208443              "approach": {}
208444            },
208445            "quantitativeAnalysis": {
208446              "graphics": {}
208447            },
208448            "considerations": {}
208449          }
208450        },
208451        {
208452          "type": "library",
208453          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=ecf076cf26fe73d0",
208454          "supplier": {},
208455          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
208456          "name": "util-deprecate",
208457          "version": "1.0.2",
208458          "description": "The Node.js `util.deprecate()` function with browser support",
208459          "licenses": [
208460            {
208461              "license": {
208462                "id": "MIT"
208463              }
208464            }
208465          ],
208466          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
208467          "purl": "pkg:npm/util-deprecate@1.0.2",
208468          "swid": {
208469            "attachment": {}
208470          },
208471          "pedigree": {},
208472          "externalReferences": [
208473            {
208474              "url": "git://github.com/TooTallNate/util-deprecate.git",
208475              "type": "distribution"
208476            },
208477            {
208478              "url": "https://github.com/TooTallNate/util-deprecate",
208479              "type": "website"
208480            }
208481          ],
208482          "evidence": {},
208483          "signature": {
208484            "signature": {
208485              "publicKey": {}
208486            }
208487          },
208488          "modelCard": {
208489            "modelParameters": {
208490              "approach": {}
208491            },
208492            "quantitativeAnalysis": {
208493              "graphics": {}
208494            },
208495            "considerations": {}
208496          }
208497        },
208498        {
208499          "type": "library",
208500          "bom-ref": "pkg:npm/util-extend@1.0.3?package-id=b90581678f776d40",
208501          "supplier": {},
208502          "name": "util-extend",
208503          "version": "1.0.3",
208504          "description": "Node's internal object extension function",
208505          "licenses": [
208506            {
208507              "license": {
208508                "id": "MIT"
208509              }
208510            }
208511          ],
208512          "cpe": "cpe:2.3:a:util-extend:util-extend:1.0.3:*:*:*:*:*:*:*",
208513          "purl": "pkg:npm/util-extend@1.0.3",
208514          "swid": {
208515            "attachment": {}
208516          },
208517          "pedigree": {},
208518          "externalReferences": [
208519            {
208520              "url": "git://github.com/isaacs/util-extend.git",
208521              "type": "distribution"
208522            },
208523            {
208524              "url": "https://github.com/isaacs/util-extend#readme",
208525              "type": "website"
208526            }
208527          ],
208528          "evidence": {},
208529          "signature": {
208530            "signature": {
208531              "publicKey": {}
208532            }
208533          },
208534          "modelCard": {
208535            "modelParameters": {
208536              "approach": {}
208537            },
208538            "quantitativeAnalysis": {
208539              "graphics": {}
208540            },
208541            "considerations": {}
208542          }
208543        },
208544        {
208545          "type": "library",
208546          "bom-ref": "pkg:npm/util-promisify@2.1.0?package-id=a64f5f12cac515a2",
208547          "supplier": {},
208548          "name": "util-promisify",
208549          "version": "2.1.0",
208550          "description": "Node 8's util.promisify, as a node module",
208551          "licenses": [
208552            {
208553              "license": {
208554                "id": "MIT"
208555              }
208556            }
208557          ],
208558          "cpe": "cpe:2.3:a:util-promisify:util-promisify:2.1.0:*:*:*:*:*:*:*",
208559          "purl": "pkg:npm/util-promisify@2.1.0",
208560          "swid": {
208561            "attachment": {}
208562          },
208563          "pedigree": {},
208564          "externalReferences": [
208565            {
208566              "url": "git+https://github.com/juliangruber/util-promisify.git",
208567              "type": "distribution"
208568            },
208569            {
208570              "url": "https://github.com/juliangruber/util-promisify#readme",
208571              "type": "website"
208572            }
208573          ],
208574          "evidence": {},
208575          "signature": {
208576            "signature": {
208577              "publicKey": {}
208578            }
208579          },
208580          "modelCard": {
208581            "modelParameters": {
208582              "approach": {}
208583            },
208584            "quantitativeAnalysis": {
208585              "graphics": {}
208586            },
208587            "considerations": {}
208588          }
208589        },
208590        {
208591          "type": "library",
208592          "bom-ref": "pkg:npm/utils-merge@1.0.1?package-id=2c445cae22e4baa6",
208593          "supplier": {},
208594          "author": "Jared Hanson \u003cjaredhanson@gmail.com\u003e (http://www.jaredhanson.net/)",
208595          "name": "utils-merge",
208596          "version": "1.0.1",
208597          "description": "merge() utility function",
208598          "licenses": [
208599            {
208600              "license": {
208601                "id": "MIT"
208602              }
208603            }
208604          ],
208605          "cpe": "cpe:2.3:a:jaredhanson:utils-merge:1.0.1:*:*:*:*:*:*:*",
208606          "purl": "pkg:npm/utils-merge@1.0.1",
208607          "swid": {
208608            "attachment": {}
208609          },
208610          "pedigree": {},
208611          "externalReferences": [
208612            {
208613              "url": "git://github.com/jaredhanson/utils-merge.git",
208614              "type": "distribution"
208615            },
208616            {
208617              "url": "https://github.com/jaredhanson/utils-merge#readme",
208618              "type": "website"
208619            }
208620          ],
208621          "evidence": {},
208622          "signature": {
208623            "signature": {
208624              "publicKey": {}
208625            }
208626          },
208627          "modelCard": {
208628            "modelParameters": {
208629              "approach": {}
208630            },
208631            "quantitativeAnalysis": {
208632              "graphics": {}
208633            },
208634            "considerations": {}
208635          }
208636        },
208637        {
208638          "type": "library",
208639          "bom-ref": "pkg:npm/uuid@3.3.3?package-id=ae2a096a6bb42106",
208640          "supplier": {},
208641          "name": "uuid",
208642          "version": "3.3.3",
208643          "description": "RFC4122 (v1, v4, and v5) UUIDs",
208644          "licenses": [
208645            {
208646              "license": {
208647                "id": "MIT"
208648              }
208649            }
208650          ],
208651          "cpe": "cpe:2.3:a:kelektiv:uuid:3.3.3:*:*:*:*:*:*:*",
208652          "purl": "pkg:npm/uuid@3.3.3",
208653          "swid": {
208654            "attachment": {}
208655          },
208656          "pedigree": {},
208657          "externalReferences": [
208658            {
208659              "url": "git+https://github.com/kelektiv/node-uuid.git",
208660              "type": "distribution"
208661            },
208662            {
208663              "url": "https://github.com/kelektiv/node-uuid#readme",
208664              "type": "website"
208665            }
208666          ],
208667          "evidence": {},
208668          "signature": {
208669            "signature": {
208670              "publicKey": {}
208671            }
208672          },
208673          "modelCard": {
208674            "modelParameters": {
208675              "approach": {}
208676            },
208677            "quantitativeAnalysis": {
208678              "graphics": {}
208679            },
208680            "considerations": {}
208681          }
208682        },
208683        {
208684          "type": "library",
208685          "bom-ref": "pkg:npm/uuid@8.3.2?package-id=95a83579b4e2b728",
208686          "supplier": {},
208687          "name": "uuid",
208688          "version": "8.3.2",
208689          "description": "RFC4122 (v1, v4, and v5) UUIDs",
208690          "licenses": [
208691            {
208692              "license": {
208693                "id": "MIT"
208694              }
208695            }
208696          ],
208697          "cpe": "cpe:2.3:a:uuidjs:uuid:8.3.2:*:*:*:*:*:*:*",
208698          "purl": "pkg:npm/uuid@8.3.2",
208699          "swid": {
208700            "attachment": {}
208701          },
208702          "pedigree": {},
208703          "externalReferences": [
208704            {
208705              "url": "git+https://github.com/uuidjs/uuid.git",
208706              "type": "distribution"
208707            },
208708            {
208709              "url": "https://github.com/uuidjs/uuid#readme",
208710              "type": "website"
208711            }
208712          ],
208713          "evidence": {},
208714          "signature": {
208715            "signature": {
208716              "publicKey": {}
208717            }
208718          },
208719          "modelCard": {
208720            "modelParameters": {
208721              "approach": {}
208722            },
208723            "quantitativeAnalysis": {
208724              "graphics": {}
208725            },
208726            "considerations": {}
208727          }
208728        },
208729        {
208730          "type": "library",
208731          "bom-ref": "pkg:npm/validate-npm-package-license@3.0.4?package-id=33663eb8a236f357",
208732          "supplier": {},
208733          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
208734          "name": "validate-npm-package-license",
208735          "version": "3.0.4",
208736          "description": "Give me a string and I'll tell you if it's a valid npm package license string",
208737          "licenses": [
208738            {
208739              "license": {
208740                "id": "Apache-2.0"
208741              }
208742            }
208743          ],
208744          "cpe": "cpe:2.3:a:validate-npm-package-license:validate-npm-package-license:3.0.4:*:*:*:*:*:*:*",
208745          "purl": "pkg:npm/validate-npm-package-license@3.0.4",
208746          "swid": {
208747            "attachment": {}
208748          },
208749          "pedigree": {},
208750          "externalReferences": [
208751            {
208752              "url": "git+https://github.com/kemitchell/validate-npm-package-license.js.git",
208753              "type": "distribution"
208754            },
208755            {
208756              "url": "https://github.com/kemitchell/validate-npm-package-license.js#readme",
208757              "type": "website"
208758            }
208759          ],
208760          "evidence": {},
208761          "signature": {
208762            "signature": {
208763              "publicKey": {}
208764            }
208765          },
208766          "modelCard": {
208767            "modelParameters": {
208768              "approach": {}
208769            },
208770            "quantitativeAnalysis": {
208771              "graphics": {}
208772            },
208773            "considerations": {}
208774          }
208775        },
208776        {
208777          "type": "library",
208778          "bom-ref": "pkg:npm/validate-npm-package-name@3.0.0?package-id=57f9fd66d4ad5701",
208779          "supplier": {},
208780          "author": "zeke",
208781          "name": "validate-npm-package-name",
208782          "version": "3.0.0",
208783          "description": "Give me a string and I'll tell you if it's a valid npm package name",
208784          "licenses": [
208785            {
208786              "license": {
208787                "id": "ISC"
208788              }
208789            }
208790          ],
208791          "cpe": "cpe:2.3:a:validate-npm-package-name:validate-npm-package-name:3.0.0:*:*:*:*:*:*:*",
208792          "purl": "pkg:npm/validate-npm-package-name@3.0.0",
208793          "swid": {
208794            "attachment": {}
208795          },
208796          "pedigree": {},
208797          "externalReferences": [
208798            {
208799              "url": "git+https://github.com/npm/validate-npm-package-name.git",
208800              "type": "distribution"
208801            },
208802            {
208803              "url": "https://github.com/npm/validate-npm-package-name",
208804              "type": "website"
208805            }
208806          ],
208807          "evidence": {},
208808          "signature": {
208809            "signature": {
208810              "publicKey": {}
208811            }
208812          },
208813          "modelCard": {
208814            "modelParameters": {
208815              "approach": {}
208816            },
208817            "quantitativeAnalysis": {
208818              "graphics": {}
208819            },
208820            "considerations": {}
208821          }
208822        },
208823        {
208824          "type": "library",
208825          "bom-ref": "pkg:npm/validator@13.0.0?package-id=c822b35e061ecd32",
208826          "supplier": {},
208827          "author": "Chris O'Hara \u003ccohara87@gmail.com\u003e",
208828          "name": "validator",
208829          "version": "13.0.0",
208830          "description": "String validation and sanitization",
208831          "licenses": [
208832            {
208833              "license": {
208834                "id": "MIT"
208835              }
208836            }
208837          ],
208838          "cpe": "cpe:2.3:a:validator:validator:13.0.0:*:*:*:*:*:*:*",
208839          "purl": "pkg:npm/validator@13.0.0",
208840          "swid": {
208841            "attachment": {}
208842          },
208843          "pedigree": {},
208844          "externalReferences": [
208845            {
208846              "url": "git+https://github.com/chriso/validator.js.git",
208847              "type": "distribution"
208848            },
208849            {
208850              "url": "https://github.com/chriso/validator.js",
208851              "type": "website"
208852            }
208853          ],
208854          "evidence": {},
208855          "signature": {
208856            "signature": {
208857              "publicKey": {}
208858            }
208859          },
208860          "modelCard": {
208861            "modelParameters": {
208862              "approach": {}
208863            },
208864            "quantitativeAnalysis": {
208865              "graphics": {}
208866            },
208867            "considerations": {}
208868          }
208869        },
208870        {
208871          "type": "library",
208872          "bom-ref": "pkg:npm/vary@1.1.2?package-id=b22a107883a17598",
208873          "supplier": {},
208874          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
208875          "name": "vary",
208876          "version": "1.1.2",
208877          "description": "Manipulate the HTTP Vary header",
208878          "licenses": [
208879            {
208880              "license": {
208881                "id": "MIT"
208882              }
208883            }
208884          ],
208885          "cpe": "cpe:2.3:a:jshttp:vary:1.1.2:*:*:*:*:*:*:*",
208886          "purl": "pkg:npm/vary@1.1.2",
208887          "swid": {
208888            "attachment": {}
208889          },
208890          "pedigree": {},
208891          "externalReferences": [
208892            {
208893              "url": "git+https://github.com/jshttp/vary.git",
208894              "type": "distribution"
208895            },
208896            {
208897              "url": "https://github.com/jshttp/vary#readme",
208898              "type": "website"
208899            }
208900          ],
208901          "evidence": {},
208902          "signature": {
208903            "signature": {
208904              "publicKey": {}
208905            }
208906          },
208907          "modelCard": {
208908            "modelParameters": {
208909              "approach": {}
208910            },
208911            "quantitativeAnalysis": {
208912              "graphics": {}
208913            },
208914            "considerations": {}
208915          }
208916        },
208917        {
208918          "type": "library",
208919          "bom-ref": "pkg:npm/verror@1.10.0?package-id=be840953a9e5ca6a",
208920          "supplier": {},
208921          "name": "verror",
208922          "version": "1.10.0",
208923          "description": "richer JavaScript errors",
208924          "licenses": [
208925            {
208926              "license": {
208927                "id": "MIT"
208928              }
208929            }
208930          ],
208931          "cpe": "cpe:2.3:a:davepacheco:verror:1.10.0:*:*:*:*:*:*:*",
208932          "purl": "pkg:npm/verror@1.10.0",
208933          "swid": {
208934            "attachment": {}
208935          },
208936          "pedigree": {},
208937          "externalReferences": [
208938            {
208939              "url": "git://github.com/davepacheco/node-verror.git",
208940              "type": "distribution"
208941            },
208942            {
208943              "url": "https://github.com/davepacheco/node-verror#readme",
208944              "type": "website"
208945            }
208946          ],
208947          "evidence": {},
208948          "signature": {
208949            "signature": {
208950              "publicKey": {}
208951            }
208952          },
208953          "modelCard": {
208954            "modelParameters": {
208955              "approach": {}
208956            },
208957            "quantitativeAnalysis": {
208958              "graphics": {}
208959            },
208960            "considerations": {}
208961          }
208962        },
208963        {
208964          "type": "library",
208965          "bom-ref": "pkg:npm/wcwidth@1.0.1?package-id=ee54c63162090e16",
208966          "supplier": {},
208967          "author": "Tim Oxley",
208968          "name": "wcwidth",
208969          "version": "1.0.1",
208970          "description": "Port of C's wcwidth() and wcswidth()",
208971          "licenses": [
208972            {
208973              "license": {
208974                "id": "MIT"
208975              }
208976            }
208977          ],
208978          "cpe": "cpe:2.3:a:timoxley:wcwidth:1.0.1:*:*:*:*:*:*:*",
208979          "purl": "pkg:npm/wcwidth@1.0.1",
208980          "swid": {
208981            "attachment": {}
208982          },
208983          "pedigree": {},
208984          "externalReferences": [
208985            {
208986              "url": "git+https://github.com/timoxley/wcwidth.git",
208987              "type": "distribution"
208988            },
208989            {
208990              "url": "https://github.com/timoxley/wcwidth#readme",
208991              "type": "website"
208992            }
208993          ],
208994          "evidence": {},
208995          "signature": {
208996            "signature": {
208997              "publicKey": {}
208998            }
208999          },
209000          "modelCard": {
209001            "modelParameters": {
209002              "approach": {}
209003            },
209004            "quantitativeAnalysis": {
209005              "graphics": {}
209006            },
209007            "considerations": {}
209008          }
209009        },
209010        {
209011          "type": "library",
209012          "bom-ref": "pkg:npm/which@1.3.1?package-id=ace883b09cbe1ce",
209013          "supplier": {},
209014          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
209015          "name": "which",
209016          "version": "1.3.1",
209017          "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
209018          "licenses": [
209019            {
209020              "license": {
209021                "id": "ISC"
209022              }
209023            }
209024          ],
209025          "cpe": "cpe:2.3:a:isaacs:which:1.3.1:*:*:*:*:*:*:*",
209026          "purl": "pkg:npm/which@1.3.1",
209027          "swid": {
209028            "attachment": {}
209029          },
209030          "pedigree": {},
209031          "externalReferences": [
209032            {
209033              "url": "git://github.com/isaacs/node-which.git",
209034              "type": "distribution"
209035            },
209036            {
209037              "url": "https://github.com/isaacs/node-which#readme",
209038              "type": "website"
209039            }
209040          ],
209041          "evidence": {},
209042          "signature": {
209043            "signature": {
209044              "publicKey": {}
209045            }
209046          },
209047          "modelCard": {
209048            "modelParameters": {
209049              "approach": {}
209050            },
209051            "quantitativeAnalysis": {
209052              "graphics": {}
209053            },
209054            "considerations": {}
209055          }
209056        },
209057        {
209058          "type": "library",
209059          "bom-ref": "pkg:npm/which-module@2.0.0?package-id=5db3efe3b2bc298b",
209060          "supplier": {},
209061          "author": "nexdrew",
209062          "name": "which-module",
209063          "version": "2.0.0",
209064          "description": "Find the module object for something that was require()d",
209065          "licenses": [
209066            {
209067              "license": {
209068                "id": "ISC"
209069              }
209070            }
209071          ],
209072          "cpe": "cpe:2.3:a:which-module:which-module:2.0.0:*:*:*:*:*:*:*",
209073          "purl": "pkg:npm/which-module@2.0.0",
209074          "swid": {
209075            "attachment": {}
209076          },
209077          "pedigree": {},
209078          "externalReferences": [
209079            {
209080              "url": "git+https://github.com/nexdrew/which-module.git",
209081              "type": "distribution"
209082            },
209083            {
209084              "url": "https://github.com/nexdrew/which-module#readme",
209085              "type": "website"
209086            }
209087          ],
209088          "evidence": {},
209089          "signature": {
209090            "signature": {
209091              "publicKey": {}
209092            }
209093          },
209094          "modelCard": {
209095            "modelParameters": {
209096              "approach": {}
209097            },
209098            "quantitativeAnalysis": {
209099              "graphics": {}
209100            },
209101            "considerations": {}
209102          }
209103        },
209104        {
209105          "type": "library",
209106          "bom-ref": "pkg:npm/wide-align@1.1.2?package-id=7a2f1fc2f2c8bfd3",
209107          "supplier": {},
209108          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
209109          "name": "wide-align",
209110          "version": "1.1.2",
209111          "description": "A wide-character aware text alignment function for use on the console or with fixed width fonts.",
209112          "licenses": [
209113            {
209114              "license": {
209115                "id": "ISC"
209116              }
209117            }
209118          ],
209119          "cpe": "cpe:2.3:a:wide-align:wide-align:1.1.2:*:*:*:*:*:*:*",
209120          "purl": "pkg:npm/wide-align@1.1.2",
209121          "swid": {
209122            "attachment": {}
209123          },
209124          "pedigree": {},
209125          "externalReferences": [
209126            {
209127              "url": "git+https://github.com/iarna/wide-align.git",
209128              "type": "distribution"
209129            },
209130            {
209131              "url": "https://github.com/iarna/wide-align#readme",
209132              "type": "website"
209133            }
209134          ],
209135          "evidence": {},
209136          "signature": {
209137            "signature": {
209138              "publicKey": {}
209139            }
209140          },
209141          "modelCard": {
209142            "modelParameters": {
209143              "approach": {}
209144            },
209145            "quantitativeAnalysis": {
209146              "graphics": {}
209147            },
209148            "considerations": {}
209149          }
209150        },
209151        {
209152          "type": "library",
209153          "bom-ref": "pkg:npm/widest-line@2.0.1?package-id=8d53bbe290b5bf2",
209154          "supplier": {},
209155          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
209156          "name": "widest-line",
209157          "version": "2.0.1",
209158          "description": "Get the visual width of the widest line in a string - the number of columns required to display it",
209159          "licenses": [
209160            {
209161              "license": {
209162                "id": "MIT"
209163              }
209164            }
209165          ],
209166          "cpe": "cpe:2.3:a:sindresorhus:widest-line:2.0.1:*:*:*:*:*:*:*",
209167          "purl": "pkg:npm/widest-line@2.0.1",
209168          "swid": {
209169            "attachment": {}
209170          },
209171          "pedigree": {},
209172          "externalReferences": [
209173            {
209174              "url": "git+https://github.com/sindresorhus/widest-line.git",
209175              "type": "distribution"
209176            },
209177            {
209178              "url": "https://github.com/sindresorhus/widest-line#readme",
209179              "type": "website"
209180            }
209181          ],
209182          "evidence": {},
209183          "signature": {
209184            "signature": {
209185              "publicKey": {}
209186            }
209187          },
209188          "modelCard": {
209189            "modelParameters": {
209190              "approach": {}
209191            },
209192            "quantitativeAnalysis": {
209193              "graphics": {}
209194            },
209195            "considerations": {}
209196          }
209197        },
209198        {
209199          "type": "library",
209200          "bom-ref": "pkg:npm/worker-farm@1.7.0?package-id=485ea0f11314a814",
209201          "supplier": {},
209202          "name": "worker-farm",
209203          "version": "1.7.0",
209204          "description": "Distribute processing tasks to child processes with an über-simple API and baked-in durability \u0026 custom concurrency options.",
209205          "licenses": [
209206            {
209207              "license": {
209208                "id": "MIT"
209209              }
209210            }
209211          ],
209212          "cpe": "cpe:2.3:a:worker-farm:worker-farm:1.7.0:*:*:*:*:*:*:*",
209213          "purl": "pkg:npm/worker-farm@1.7.0",
209214          "swid": {
209215            "attachment": {}
209216          },
209217          "pedigree": {},
209218          "externalReferences": [
209219            {
209220              "url": "git+https://github.com/rvagg/node-worker-farm.git",
209221              "type": "distribution"
209222            },
209223            {
209224              "url": "https://github.com/rvagg/node-worker-farm",
209225              "type": "website"
209226            }
209227          ],
209228          "evidence": {},
209229          "signature": {
209230            "signature": {
209231              "publicKey": {}
209232            }
209233          },
209234          "modelCard": {
209235            "modelParameters": {
209236              "approach": {}
209237            },
209238            "quantitativeAnalysis": {
209239              "graphics": {}
209240            },
209241            "considerations": {}
209242          }
209243        },
209244        {
209245          "type": "library",
209246          "bom-ref": "pkg:npm/wrap-ansi@5.1.0?package-id=d8793c53891a3183",
209247          "supplier": {},
209248          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
209249          "name": "wrap-ansi",
209250          "version": "5.1.0",
209251          "description": "Wordwrap a string with ANSI escape codes",
209252          "licenses": [
209253            {
209254              "license": {
209255                "id": "MIT"
209256              }
209257            }
209258          ],
209259          "cpe": "cpe:2.3:a:wrap-ansi:wrap-ansi:5.1.0:*:*:*:*:*:*:*",
209260          "purl": "pkg:npm/wrap-ansi@5.1.0",
209261          "swid": {
209262            "attachment": {}
209263          },
209264          "pedigree": {},
209265          "externalReferences": [
209266            {
209267              "url": "git+https://github.com/chalk/wrap-ansi.git",
209268              "type": "distribution"
209269            },
209270            {
209271              "url": "https://github.com/chalk/wrap-ansi#readme",
209272              "type": "website"
209273            }
209274          ],
209275          "evidence": {},
209276          "signature": {
209277            "signature": {
209278              "publicKey": {}
209279            }
209280          },
209281          "modelCard": {
209282            "modelParameters": {
209283              "approach": {}
209284            },
209285            "quantitativeAnalysis": {
209286              "graphics": {}
209287            },
209288            "considerations": {}
209289          }
209290        },
209291        {
209292          "type": "library",
209293          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=3bac7a86a24db14e",
209294          "supplier": {},
209295          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
209296          "name": "wrappy",
209297          "version": "1.0.2",
209298          "description": "Callback wrapping utility",
209299          "licenses": [
209300            {
209301              "license": {
209302                "id": "ISC"
209303              }
209304            }
209305          ],
209306          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
209307          "purl": "pkg:npm/wrappy@1.0.2",
209308          "swid": {
209309            "attachment": {}
209310          },
209311          "pedigree": {},
209312          "externalReferences": [
209313            {
209314              "url": "git+https://github.com/npm/wrappy.git",
209315              "type": "distribution"
209316            },
209317            {
209318              "url": "https://github.com/npm/wrappy",
209319              "type": "website"
209320            }
209321          ],
209322          "evidence": {},
209323          "signature": {
209324            "signature": {
209325              "publicKey": {}
209326            }
209327          },
209328          "modelCard": {
209329            "modelParameters": {
209330              "approach": {}
209331            },
209332            "quantitativeAnalysis": {
209333              "graphics": {}
209334            },
209335            "considerations": {}
209336          }
209337        },
209338        {
209339          "type": "library",
209340          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=da7850cd4ce320be",
209341          "supplier": {},
209342          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
209343          "name": "wrappy",
209344          "version": "1.0.2",
209345          "description": "Callback wrapping utility",
209346          "licenses": [
209347            {
209348              "license": {
209349                "id": "ISC"
209350              }
209351            }
209352          ],
209353          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
209354          "purl": "pkg:npm/wrappy@1.0.2",
209355          "swid": {
209356            "attachment": {}
209357          },
209358          "pedigree": {},
209359          "externalReferences": [
209360            {
209361              "url": "git+https://github.com/npm/wrappy.git",
209362              "type": "distribution"
209363            },
209364            {
209365              "url": "https://github.com/npm/wrappy",
209366              "type": "website"
209367            }
209368          ],
209369          "evidence": {},
209370          "signature": {
209371            "signature": {
209372              "publicKey": {}
209373            }
209374          },
209375          "modelCard": {
209376            "modelParameters": {
209377              "approach": {}
209378            },
209379            "quantitativeAnalysis": {
209380              "graphics": {}
209381            },
209382            "considerations": {}
209383          }
209384        },
209385        {
209386          "type": "library",
209387          "bom-ref": "pkg:npm/write-file-atomic@2.4.3?package-id=7d4897c5064f974b",
209388          "supplier": {},
209389          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org)",
209390          "name": "write-file-atomic",
209391          "version": "2.4.3",
209392          "description": "Write files in an atomic fashion w/configurable ownership",
209393          "licenses": [
209394            {
209395              "license": {
209396                "id": "ISC"
209397              }
209398            }
209399          ],
209400          "cpe": "cpe:2.3:a:write-file-atomic:write-file-atomic:2.4.3:*:*:*:*:*:*:*",
209401          "purl": "pkg:npm/write-file-atomic@2.4.3",
209402          "swid": {
209403            "attachment": {}
209404          },
209405          "pedigree": {},
209406          "externalReferences": [
209407            {
209408              "url": "git+ssh://git@github.com/iarna/write-file-atomic.git",
209409              "type": "distribution"
209410            },
209411            {
209412              "url": "https://github.com/iarna/write-file-atomic",
209413              "type": "website"
209414            }
209415          ],
209416          "evidence": {},
209417          "signature": {
209418            "signature": {
209419              "publicKey": {}
209420            }
209421          },
209422          "modelCard": {
209423            "modelParameters": {
209424              "approach": {}
209425            },
209426            "quantitativeAnalysis": {
209427              "graphics": {}
209428            },
209429            "considerations": {}
209430          }
209431        },
209432        {
209433          "type": "library",
209434          "bom-ref": "pkg:npm/xdg-basedir@3.0.0?package-id=6cd97401957b6225",
209435          "supplier": {},
209436          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
209437          "name": "xdg-basedir",
209438          "version": "3.0.0",
209439          "description": "Get XDG Base Directory paths",
209440          "licenses": [
209441            {
209442              "license": {
209443                "id": "MIT"
209444              }
209445            }
209446          ],
209447          "cpe": "cpe:2.3:a:sindresorhus:xdg-basedir:3.0.0:*:*:*:*:*:*:*",
209448          "purl": "pkg:npm/xdg-basedir@3.0.0",
209449          "swid": {
209450            "attachment": {}
209451          },
209452          "pedigree": {},
209453          "externalReferences": [
209454            {
209455              "url": "git+https://github.com/sindresorhus/xdg-basedir.git",
209456              "type": "distribution"
209457            },
209458            {
209459              "url": "https://github.com/sindresorhus/xdg-basedir#readme",
209460              "type": "website"
209461            }
209462          ],
209463          "evidence": {},
209464          "signature": {
209465            "signature": {
209466              "publicKey": {}
209467            }
209468          },
209469          "modelCard": {
209470            "modelParameters": {
209471              "approach": {}
209472            },
209473            "quantitativeAnalysis": {
209474              "graphics": {}
209475            },
209476            "considerations": {}
209477          }
209478        },
209479        {
209480          "type": "library",
209481          "bom-ref": "pkg:npm/xtend@4.0.1?package-id=7f934d0a04b60a40",
209482          "supplier": {},
209483          "author": "Raynos \u003craynos2@gmail.com\u003e",
209484          "name": "xtend",
209485          "version": "4.0.1",
209486          "description": "extend like a boss",
209487          "licenses": [
209488            {
209489              "license": {
209490                "id": "MIT"
209491              }
209492            }
209493          ],
209494          "cpe": "cpe:2.3:a:Raynos:xtend:4.0.1:*:*:*:*:*:*:*",
209495          "purl": "pkg:npm/xtend@4.0.1",
209496          "swid": {
209497            "attachment": {}
209498          },
209499          "pedigree": {},
209500          "externalReferences": [
209501            {
209502              "url": "git://github.com/Raynos/xtend.git",
209503              "type": "distribution"
209504            },
209505            {
209506              "url": "https://github.com/Raynos/xtend",
209507              "type": "website"
209508            }
209509          ],
209510          "evidence": {},
209511          "signature": {
209512            "signature": {
209513              "publicKey": {}
209514            }
209515          },
209516          "modelCard": {
209517            "modelParameters": {
209518              "approach": {}
209519            },
209520            "quantitativeAnalysis": {
209521              "graphics": {}
209522            },
209523            "considerations": {}
209524          }
209525        },
209526        {
209527          "type": "library",
209528          "bom-ref": "pkg:npm/xtend@4.0.2?package-id=806268954298f9d0",
209529          "supplier": {},
209530          "author": "Raynos \u003craynos2@gmail.com\u003e",
209531          "name": "xtend",
209532          "version": "4.0.2",
209533          "description": "extend like a boss",
209534          "licenses": [
209535            {
209536              "license": {
209537                "id": "MIT"
209538              }
209539            }
209540          ],
209541          "cpe": "cpe:2.3:a:Raynos:xtend:4.0.2:*:*:*:*:*:*:*",
209542          "purl": "pkg:npm/xtend@4.0.2",
209543          "swid": {
209544            "attachment": {}
209545          },
209546          "pedigree": {},
209547          "externalReferences": [
209548            {
209549              "url": "git://github.com/Raynos/xtend.git",
209550              "type": "distribution"
209551            },
209552            {
209553              "url": "https://github.com/Raynos/xtend",
209554              "type": "website"
209555            }
209556          ],
209557          "evidence": {},
209558          "signature": {
209559            "signature": {
209560              "publicKey": {}
209561            }
209562          },
209563          "modelCard": {
209564            "modelParameters": {
209565              "approach": {}
209566            },
209567            "quantitativeAnalysis": {
209568              "graphics": {}
209569            },
209570            "considerations": {}
209571          }
209572        },
209573        {
209574          "type": "library",
209575          "bom-ref": "pkg:npm/y18n@4.0.1?package-id=59c84f1155aa57be",
209576          "supplier": {},
209577          "author": "Ben Coe \u003cben@npmjs.com\u003e",
209578          "name": "y18n",
209579          "version": "4.0.1",
209580          "description": "the bare-bones internationalization library used by yargs",
209581          "licenses": [
209582            {
209583              "license": {
209584                "id": "ISC"
209585              }
209586            }
209587          ],
209588          "cpe": "cpe:2.3:a:yargs:y18n:4.0.1:*:*:*:*:*:*:*",
209589          "purl": "pkg:npm/y18n@4.0.1",
209590          "swid": {
209591            "attachment": {}
209592          },
209593          "pedigree": {},
209594          "externalReferences": [
209595            {
209596              "url": "git+ssh://git@github.com/yargs/y18n.git",
209597              "type": "distribution"
209598            },
209599            {
209600              "url": "https://github.com/yargs/y18n",
209601              "type": "website"
209602            }
209603          ],
209604          "evidence": {},
209605          "signature": {
209606            "signature": {
209607              "publicKey": {}
209608            }
209609          },
209610          "modelCard": {
209611            "modelParameters": {
209612              "approach": {}
209613            },
209614            "quantitativeAnalysis": {
209615              "graphics": {}
209616            },
209617            "considerations": {}
209618          }
209619        },
209620        {
209621          "type": "library",
209622          "bom-ref": "pkg:npm/yallist@2.1.2?package-id=2dc35655140480b4",
209623          "supplier": {},
209624          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
209625          "name": "yallist",
209626          "version": "2.1.2",
209627          "description": "Yet Another Linked List",
209628          "licenses": [
209629            {
209630              "license": {
209631                "id": "ISC"
209632              }
209633            }
209634          ],
209635          "cpe": "cpe:2.3:a:yallist:yallist:2.1.2:*:*:*:*:*:*:*",
209636          "purl": "pkg:npm/yallist@2.1.2",
209637          "swid": {
209638            "attachment": {}
209639          },
209640          "pedigree": {},
209641          "externalReferences": [
209642            {
209643              "url": "git+https://github.com/isaacs/yallist.git",
209644              "type": "distribution"
209645            },
209646            {
209647              "url": "https://github.com/isaacs/yallist#readme",
209648              "type": "website"
209649            }
209650          ],
209651          "evidence": {},
209652          "signature": {
209653            "signature": {
209654              "publicKey": {}
209655            }
209656          },
209657          "modelCard": {
209658            "modelParameters": {
209659              "approach": {}
209660            },
209661            "quantitativeAnalysis": {
209662              "graphics": {}
209663            },
209664            "considerations": {}
209665          }
209666        },
209667        {
209668          "type": "library",
209669          "bom-ref": "pkg:npm/yallist@3.0.3?package-id=dba260e644a452f8",
209670          "supplier": {},
209671          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
209672          "name": "yallist",
209673          "version": "3.0.3",
209674          "description": "Yet Another Linked List",
209675          "licenses": [
209676            {
209677              "license": {
209678                "id": "ISC"
209679              }
209680            }
209681          ],
209682          "cpe": "cpe:2.3:a:yallist:yallist:3.0.3:*:*:*:*:*:*:*",
209683          "purl": "pkg:npm/yallist@3.0.3",
209684          "swid": {
209685            "attachment": {}
209686          },
209687          "pedigree": {},
209688          "externalReferences": [
209689            {
209690              "url": "git+https://github.com/isaacs/yallist.git",
209691              "type": "distribution"
209692            },
209693            {
209694              "url": "https://github.com/isaacs/yallist#readme",
209695              "type": "website"
209696            }
209697          ],
209698          "evidence": {},
209699          "signature": {
209700            "signature": {
209701              "publicKey": {}
209702            }
209703          },
209704          "modelCard": {
209705            "modelParameters": {
209706              "approach": {}
209707            },
209708            "quantitativeAnalysis": {
209709              "graphics": {}
209710            },
209711            "considerations": {}
209712          }
209713        },
209714        {
209715          "type": "library",
209716          "bom-ref": "pkg:npm/yallist@3.1.1?package-id=786b4b01dc63a464",
209717          "supplier": {},
209718          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
209719          "name": "yallist",
209720          "version": "3.1.1",
209721          "description": "Yet Another Linked List",
209722          "licenses": [
209723            {
209724              "license": {
209725                "id": "ISC"
209726              }
209727            }
209728          ],
209729          "cpe": "cpe:2.3:a:yallist:yallist:3.1.1:*:*:*:*:*:*:*",
209730          "purl": "pkg:npm/yallist@3.1.1",
209731          "swid": {
209732            "attachment": {}
209733          },
209734          "pedigree": {},
209735          "externalReferences": [
209736            {
209737              "url": "git+https://github.com/isaacs/yallist.git",
209738              "type": "distribution"
209739            },
209740            {
209741              "url": "https://github.com/isaacs/yallist#readme",
209742              "type": "website"
209743            }
209744          ],
209745          "evidence": {},
209746          "signature": {
209747            "signature": {
209748              "publicKey": {}
209749            }
209750          },
209751          "modelCard": {
209752            "modelParameters": {
209753              "approach": {}
209754            },
209755            "quantitativeAnalysis": {
209756              "graphics": {}
209757            },
209758            "considerations": {}
209759          }
209760        },
209761        {
209762          "type": "library",
209763          "bom-ref": "pkg:npm/yargs@14.2.3?package-id=2b0da698f823246",
209764          "supplier": {},
209765          "name": "yargs",
209766          "version": "14.2.3",
209767          "description": "yargs the modern, pirate-themed, successor to optimist.",
209768          "licenses": [
209769            {
209770              "license": {
209771                "id": "MIT"
209772              }
209773            }
209774          ],
209775          "cpe": "cpe:2.3:a:yargs:yargs:14.2.3:*:*:*:*:*:*:*",
209776          "purl": "pkg:npm/yargs@14.2.3",
209777          "swid": {
209778            "attachment": {}
209779          },
209780          "pedigree": {},
209781          "externalReferences": [
209782            {
209783              "url": "git+https://github.com/yargs/yargs.git",
209784              "type": "distribution"
209785            },
209786            {
209787              "url": "https://yargs.js.org/",
209788              "type": "website"
209789            }
209790          ],
209791          "evidence": {},
209792          "signature": {
209793            "signature": {
209794              "publicKey": {}
209795            }
209796          },
209797          "modelCard": {
209798            "modelParameters": {
209799              "approach": {}
209800            },
209801            "quantitativeAnalysis": {
209802              "graphics": {}
209803            },
209804            "considerations": {}
209805          }
209806        },
209807        {
209808          "type": "library",
209809          "bom-ref": "pkg:npm/yargs-parser@15.0.1?package-id=21203be018f57e45",
209810          "supplier": {},
209811          "author": "Ben Coe \u003cben@npmjs.com\u003e",
209812          "name": "yargs-parser",
209813          "version": "15.0.1",
209814          "description": "the mighty option parser used by yargs",
209815          "licenses": [
209816            {
209817              "license": {
209818                "id": "ISC"
209819              }
209820            }
209821          ],
209822          "cpe": "cpe:2.3:a:yargs-parser:yargs-parser:15.0.1:*:*:*:*:*:*:*",
209823          "purl": "pkg:npm/yargs-parser@15.0.1",
209824          "swid": {
209825            "attachment": {}
209826          },
209827          "pedigree": {},
209828          "externalReferences": [
209829            {
209830              "url": "git+ssh://git@github.com/yargs/yargs-parser.git",
209831              "type": "distribution"
209832            },
209833            {
209834              "url": "https://github.com/yargs/yargs-parser#readme",
209835              "type": "website"
209836            }
209837          ],
209838          "evidence": {},
209839          "signature": {
209840            "signature": {
209841              "publicKey": {}
209842            }
209843          },
209844          "modelCard": {
209845            "modelParameters": {
209846              "approach": {}
209847            },
209848            "quantitativeAnalysis": {
209849              "graphics": {}
209850            },
209851            "considerations": {}
209852          }
209853        },
209854        {
209855          "type": "library",
209856          "bom-ref": "pkg:npm/yarn@1.22.19?package-id=f2b974a78000b26b",
209857          "supplier": {},
209858          "name": "yarn",
209859          "version": "1.22.19",
209860          "description": "📦🐈 Fast, reliable, and secure dependency management.",
209861          "licenses": [
209862            {
209863              "license": {
209864                "id": "BSD-2-Clause"
209865              }
209866            }
209867          ],
209868          "cpe": "cpe:2.3:a:yarn:yarn:1.22.19:*:*:*:*:*:*:*",
209869          "purl": "pkg:npm/yarn@1.22.19",
209870          "swid": {
209871            "attachment": {}
209872          },
209873          "pedigree": {},
209874          "externalReferences": [
209875            {
209876              "url": "yarnpkg/yarn",
209877              "type": "distribution"
209878            }
209879          ],
209880          "evidence": {},
209881          "signature": {
209882            "signature": {
209883              "publicKey": {}
209884            }
209885          },
209886          "modelCard": {
209887            "modelParameters": {
209888              "approach": {}
209889            },
209890            "quantitativeAnalysis": {
209891              "graphics": {}
209892            },
209893            "considerations": {}
209894          }
209895        },
209896        {
209897          "type": "library",
209898          "bom-ref": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.1\u0026package-id=94014313cfcd2b71",
209899          "supplier": {},
209900          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
209901          "name": "zlib",
209902          "version": "1.2.13-r0",
209903          "description": "A compression/decompression Library",
209904          "licenses": [
209905            {
209906              "license": {
209907                "id": "Zlib"
209908              }
209909            }
209910          ],
209911          "cpe": "cpe:2.3:a:zlib:zlib:1.2.13-r0:*:*:*:*:*:*:*",
209912          "purl": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.1",
209913          "swid": {
209914            "attachment": {}
209915          },
209916          "pedigree": {},
209917          "externalReferences": [
209918            {
209919              "url": "https://zlib.net/",
209920              "type": "distribution"
209921            }
209922          ],
209923          "evidence": {},
209924          "signature": {
209925            "signature": {
209926              "publicKey": {}
209927            }
209928          },
209929          "modelCard": {
209930            "modelParameters": {
209931              "approach": {}
209932            },
209933            "quantitativeAnalysis": {
209934              "graphics": {}
209935            },
209936            "considerations": {}
209937          }
209938        },
209939        {
209940          "type": "operating-system",
209941          "supplier": {},
209942          "name": "alpine",
209943          "version": "3.17.1",
209944          "description": "Alpine Linux v3.17",
209945          "swid": {
209946            "tagId": "alpine",
209947            "name": "alpine",
209948            "version": "3.17.1",
209949            "attachment": {}
209950          },
209951          "pedigree": {},
209952          "externalReferences": [
209953            {
209954              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
209955              "type": "issue-tracker"
209956            },
209957            {
209958              "url": "https://alpinelinux.org/",
209959              "type": "website"
209960            }
209961          ],
209962          "evidence": {},
209963          "signature": {
209964            "signature": {
209965              "publicKey": {}
209966            }
209967          },
209968          "modelCard": {
209969            "modelParameters": {
209970              "approach": {}
209971            },
209972            "quantitativeAnalysis": {
209973              "graphics": {}
209974            },
209975            "considerations": {}
209976          }
209977        },
209978        {
209979          "type": "library",
209980          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r15?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=e9fa5a5914a9f876",
209981          "supplier": {},
209982          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
209983          "name": "alpine-baselayout",
209984          "version": "3.2.0-r15",
209985          "description": "Alpine base dir structure and init scripts",
209986          "licenses": [
209987            {
209988              "license": {
209989                "id": "GPL-2.0-only"
209990              }
209991            }
209992          ],
209993          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r15:*:*:*:*:*:*:*",
209994          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r15?arch=x86_64\u0026distro=alpine-3.14.0",
209995          "swid": {
209996            "attachment": {}
209997          },
209998          "pedigree": {},
209999          "externalReferences": [
210000            {
210001              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
210002              "type": "distribution"
210003            }
210004          ],
210005          "evidence": {},
210006          "signature": {
210007            "signature": {
210008              "publicKey": {}
210009            }
210010          },
210011          "modelCard": {
210012            "modelParameters": {
210013              "approach": {}
210014            },
210015            "quantitativeAnalysis": {
210016              "graphics": {}
210017            },
210018            "considerations": {}
210019          }
210020        },
210021        {
210022          "type": "library",
210023          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r16?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=99cf2e0f247af59f",
210024          "supplier": {},
210025          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210026          "name": "alpine-baselayout",
210027          "version": "3.2.0-r16",
210028          "description": "Alpine base dir structure and init scripts",
210029          "licenses": [
210030            {
210031              "license": {
210032                "id": "GPL-2.0-only"
210033              }
210034            }
210035          ],
210036          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r16:*:*:*:*:*:*:*",
210037          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r16?arch=x86_64\u0026distro=alpine-3.14.0",
210038          "swid": {
210039            "attachment": {}
210040          },
210041          "pedigree": {},
210042          "externalReferences": [
210043            {
210044              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
210045              "type": "distribution"
210046            }
210047          ],
210048          "evidence": {},
210049          "signature": {
210050            "signature": {
210051              "publicKey": {}
210052            }
210053          },
210054          "modelCard": {
210055            "modelParameters": {
210056              "approach": {}
210057            },
210058            "quantitativeAnalysis": {
210059              "graphics": {}
210060            },
210061            "considerations": {}
210062          }
210063        },
210064        {
210065          "type": "library",
210066          "bom-ref": "pkg:apk/alpine/alpine-keys@2.3-r1?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=d9b110f5aec37ab0",
210067          "supplier": {},
210068          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210069          "name": "alpine-keys",
210070          "version": "2.3-r1",
210071          "description": "Public keys for Alpine Linux packages",
210072          "licenses": [
210073            {
210074              "license": {
210075                "id": "MIT"
210076              }
210077            }
210078          ],
210079          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.3-r1:*:*:*:*:*:*:*",
210080          "purl": "pkg:apk/alpine/alpine-keys@2.3-r1?arch=x86_64\u0026distro=alpine-3.14.0",
210081          "swid": {
210082            "attachment": {}
210083          },
210084          "pedigree": {},
210085          "externalReferences": [
210086            {
210087              "url": "https://alpinelinux.org",
210088              "type": "distribution"
210089            }
210090          ],
210091          "evidence": {},
210092          "signature": {
210093            "signature": {
210094              "publicKey": {}
210095            }
210096          },
210097          "modelCard": {
210098            "modelParameters": {
210099              "approach": {}
210100            },
210101            "quantitativeAnalysis": {
210102              "graphics": {}
210103            },
210104            "considerations": {}
210105          }
210106        },
210107        {
210108          "type": "library",
210109          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r0?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=3129d951e009dfc8",
210110          "supplier": {},
210111          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210112          "name": "alpine-keys",
210113          "version": "2.4-r0",
210114          "description": "Public keys for Alpine Linux packages",
210115          "licenses": [
210116            {
210117              "license": {
210118                "id": "MIT"
210119              }
210120            }
210121          ],
210122          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r0:*:*:*:*:*:*:*",
210123          "purl": "pkg:apk/alpine/alpine-keys@2.4-r0?arch=x86_64\u0026distro=alpine-3.14.0",
210124          "swid": {
210125            "attachment": {}
210126          },
210127          "pedigree": {},
210128          "externalReferences": [
210129            {
210130              "url": "https://alpinelinux.org",
210131              "type": "distribution"
210132            }
210133          ],
210134          "evidence": {},
210135          "signature": {
210136            "signature": {
210137              "publicKey": {}
210138            }
210139          },
210140          "modelCard": {
210141            "modelParameters": {
210142              "approach": {}
210143            },
210144            "quantitativeAnalysis": {
210145              "graphics": {}
210146            },
210147            "considerations": {}
210148          }
210149        },
210150        {
210151          "type": "library",
210152          "bom-ref": "pkg:maven/org.glassfish.hk2.external/aopalliance-repackaged@2.5.0-b42?package-id=bb384db4fa883606",
210153          "supplier": {},
210154          "group": "org.glassfish.hk2.external",
210155          "name": "aopalliance-repackaged",
210156          "version": "2.5.0-b42",
210157          "licenses": [
210158            {
210159              "license": {
210160                "name": "https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html"
210161              }
210162            }
210163          ],
210164          "cpe": "cpe:2.3:a:aopalliance-repackaged:aopalliance-repackaged:2.5.0-b42:*:*:*:*:*:*:*",
210165          "purl": "pkg:maven/org.glassfish.hk2.external/aopalliance-repackaged@2.5.0-b42",
210166          "swid": {
210167            "attachment": {}
210168          },
210169          "pedigree": {},
210170          "externalReferences": [
210171            {
210172              "type": "build-meta",
210173              "hashes": [
210174                {
210175                  "alg": "SHA-1",
210176                  "content": "e74beab6ca12e9e745eb47ca61729d9452b96f0c"
210177                }
210178              ]
210179            }
210180          ],
210181          "evidence": {},
210182          "signature": {
210183            "signature": {
210184              "publicKey": {}
210185            }
210186          },
210187          "modelCard": {
210188            "modelParameters": {
210189              "approach": {}
210190            },
210191            "quantitativeAnalysis": {
210192              "graphics": {}
210193            },
210194            "considerations": {}
210195          }
210196        },
210197        {
210198          "type": "library",
210199          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.5-r1?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=e4b0dfa0167d1cc4",
210200          "supplier": {},
210201          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210202          "name": "apk-tools",
210203          "version": "2.12.5-r1",
210204          "description": "Alpine Package Keeper - package manager for alpine",
210205          "licenses": [
210206            {
210207              "license": {
210208                "id": "GPL-2.0-only"
210209              }
210210            }
210211          ],
210212          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.5-r1:*:*:*:*:*:*:*",
210213          "purl": "pkg:apk/alpine/apk-tools@2.12.5-r1?arch=x86_64\u0026distro=alpine-3.14.0",
210214          "swid": {
210215            "attachment": {}
210216          },
210217          "pedigree": {},
210218          "externalReferences": [
210219            {
210220              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
210221              "type": "distribution"
210222            }
210223          ],
210224          "evidence": {},
210225          "signature": {
210226            "signature": {
210227              "publicKey": {}
210228            }
210229          },
210230          "modelCard": {
210231            "modelParameters": {
210232              "approach": {}
210233            },
210234            "quantitativeAnalysis": {
210235              "graphics": {}
210236            },
210237            "considerations": {}
210238          }
210239        },
210240        {
210241          "type": "library",
210242          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.7-r0?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=3d3f539520a09439",
210243          "supplier": {},
210244          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210245          "name": "apk-tools",
210246          "version": "2.12.7-r0",
210247          "description": "Alpine Package Keeper - package manager for alpine",
210248          "licenses": [
210249            {
210250              "license": {
210251                "id": "GPL-2.0-only"
210252              }
210253            }
210254          ],
210255          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.7-r0:*:*:*:*:*:*:*",
210256          "purl": "pkg:apk/alpine/apk-tools@2.12.7-r0?arch=x86_64\u0026distro=alpine-3.14.0",
210257          "swid": {
210258            "attachment": {}
210259          },
210260          "pedigree": {},
210261          "externalReferences": [
210262            {
210263              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
210264              "type": "distribution"
210265            }
210266          ],
210267          "evidence": {},
210268          "signature": {
210269            "signature": {
210270              "publicKey": {}
210271            }
210272          },
210273          "modelCard": {
210274            "modelParameters": {
210275              "approach": {}
210276            },
210277            "quantitativeAnalysis": {
210278              "graphics": {}
210279            },
210280            "considerations": {}
210281          }
210282        },
210283        {
210284          "type": "application",
210285          "bom-ref": "a1a69d918cc41a1c",
210286          "supplier": {},
210287          "name": "busybox",
210288          "version": "1.33.1",
210289          "cpe": "cpe:2.3:a:busybox:busybox:1.33.1:*:*:*:*:*:*:*",
210290          "swid": {
210291            "attachment": {}
210292          },
210293          "pedigree": {},
210294          "evidence": {},
210295          "signature": {
210296            "signature": {
210297              "publicKey": {}
210298            }
210299          },
210300          "modelCard": {
210301            "modelParameters": {
210302              "approach": {}
210303            },
210304            "quantitativeAnalysis": {
210305              "graphics": {}
210306            },
210307            "considerations": {}
210308          }
210309        },
210310        {
210311          "type": "library",
210312          "bom-ref": "pkg:apk/alpine/busybox@1.33.1-r2?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=202ec46474524c4",
210313          "supplier": {},
210314          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210315          "name": "busybox",
210316          "version": "1.33.1-r2",
210317          "description": "Size optimized toolbox of many common UNIX utilities",
210318          "licenses": [
210319            {
210320              "license": {
210321                "id": "GPL-2.0-only"
210322              }
210323            }
210324          ],
210325          "cpe": "cpe:2.3:a:busybox:busybox:1.33.1-r2:*:*:*:*:*:*:*",
210326          "purl": "pkg:apk/alpine/busybox@1.33.1-r2?arch=x86_64\u0026distro=alpine-3.14.0",
210327          "swid": {
210328            "attachment": {}
210329          },
210330          "pedigree": {},
210331          "externalReferences": [
210332            {
210333              "url": "https://busybox.net/",
210334              "type": "distribution"
210335            }
210336          ],
210337          "evidence": {},
210338          "signature": {
210339            "signature": {
210340              "publicKey": {}
210341            }
210342          },
210343          "modelCard": {
210344            "modelParameters": {
210345              "approach": {}
210346            },
210347            "quantitativeAnalysis": {
210348              "graphics": {}
210349            },
210350            "considerations": {}
210351          }
210352        },
210353        {
210354          "type": "library",
210355          "bom-ref": "pkg:apk/alpine/busybox@1.33.1-r8?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=f930f5a430102cb5",
210356          "supplier": {},
210357          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210358          "name": "busybox",
210359          "version": "1.33.1-r8",
210360          "description": "Size optimized toolbox of many common UNIX utilities",
210361          "licenses": [
210362            {
210363              "license": {
210364                "id": "GPL-2.0-only"
210365              }
210366            }
210367          ],
210368          "cpe": "cpe:2.3:a:busybox:busybox:1.33.1-r8:*:*:*:*:*:*:*",
210369          "purl": "pkg:apk/alpine/busybox@1.33.1-r8?arch=x86_64\u0026distro=alpine-3.14.0",
210370          "swid": {
210371            "attachment": {}
210372          },
210373          "pedigree": {},
210374          "externalReferences": [
210375            {
210376              "url": "https://busybox.net/",
210377              "type": "distribution"
210378            }
210379          ],
210380          "evidence": {},
210381          "signature": {
210382            "signature": {
210383              "publicKey": {}
210384            }
210385          },
210386          "modelCard": {
210387            "modelParameters": {
210388              "approach": {}
210389            },
210390            "quantitativeAnalysis": {
210391              "graphics": {}
210392            },
210393            "considerations": {}
210394          }
210395        },
210396        {
210397          "type": "library",
210398          "bom-ref": "pkg:apk/alpine/ca-certificates@20191127-r5?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=59f0dfc47bad0b78",
210399          "supplier": {},
210400          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210401          "name": "ca-certificates",
210402          "version": "20191127-r5",
210403          "description": "Common CA certificates PEM files from Mozilla",
210404          "licenses": [
210405            {
210406              "license": {
210407                "id": "MPL-2.0"
210408              }
210409            },
210410            {
210411              "license": {
210412                "name": "AND"
210413              }
210414            },
210415            {
210416              "license": {
210417                "id": "MIT"
210418              }
210419            }
210420          ],
210421          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20191127-r5:*:*:*:*:*:*:*",
210422          "purl": "pkg:apk/alpine/ca-certificates@20191127-r5?arch=x86_64\u0026distro=alpine-3.14.0",
210423          "swid": {
210424            "attachment": {}
210425          },
210426          "pedigree": {},
210427          "externalReferences": [
210428            {
210429              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
210430              "type": "distribution"
210431            }
210432          ],
210433          "evidence": {},
210434          "signature": {
210435            "signature": {
210436              "publicKey": {}
210437            }
210438          },
210439          "modelCard": {
210440            "modelParameters": {
210441              "approach": {}
210442            },
210443            "quantitativeAnalysis": {
210444              "graphics": {}
210445            },
210446            "considerations": {}
210447          }
210448        },
210449        {
210450          "type": "library",
210451          "bom-ref": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=6f2c91b9b6c0161b",
210452          "supplier": {},
210453          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210454          "name": "ca-certificates",
210455          "version": "20220614-r0",
210456          "description": "Common CA certificates PEM files from Mozilla",
210457          "licenses": [
210458            {
210459              "license": {
210460                "id": "MPL-2.0"
210461              }
210462            },
210463            {
210464              "license": {
210465                "name": "AND"
210466              }
210467            },
210468            {
210469              "license": {
210470                "id": "MIT"
210471              }
210472            }
210473          ],
210474          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20220614-r0:*:*:*:*:*:*:*",
210475          "purl": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.14.0",
210476          "swid": {
210477            "attachment": {}
210478          },
210479          "pedigree": {},
210480          "externalReferences": [
210481            {
210482              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
210483              "type": "distribution"
210484            }
210485          ],
210486          "evidence": {},
210487          "signature": {
210488            "signature": {
210489              "publicKey": {}
210490            }
210491          },
210492          "modelCard": {
210493            "modelParameters": {
210494              "approach": {}
210495            },
210496            "quantitativeAnalysis": {
210497              "graphics": {}
210498            },
210499            "considerations": {}
210500          }
210501        },
210502        {
210503          "type": "library",
210504          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20191127-r5?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.14.0\u0026package-id=49b1d2868a3a2549",
210505          "supplier": {},
210506          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210507          "name": "ca-certificates-bundle",
210508          "version": "20191127-r5",
210509          "description": "Pre generated bundle of Mozilla certificates",
210510          "licenses": [
210511            {
210512              "license": {
210513                "id": "MPL-2.0"
210514              }
210515            },
210516            {
210517              "license": {
210518                "name": "AND"
210519              }
210520            },
210521            {
210522              "license": {
210523                "id": "MIT"
210524              }
210525            }
210526          ],
210527          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20191127-r5:*:*:*:*:*:*:*",
210528          "purl": "pkg:apk/alpine/ca-certificates-bundle@20191127-r5?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.14.0",
210529          "swid": {
210530            "attachment": {}
210531          },
210532          "pedigree": {},
210533          "externalReferences": [
210534            {
210535              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
210536              "type": "distribution"
210537            }
210538          ],
210539          "evidence": {},
210540          "signature": {
210541            "signature": {
210542              "publicKey": {}
210543            }
210544          },
210545          "modelCard": {
210546            "modelParameters": {
210547              "approach": {}
210548            },
210549            "quantitativeAnalysis": {
210550              "graphics": {}
210551            },
210552            "considerations": {}
210553          }
210554        },
210555        {
210556          "type": "library",
210557          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.14.0\u0026package-id=3442a80f36917ed5",
210558          "supplier": {},
210559          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
210560          "name": "ca-certificates-bundle",
210561          "version": "20220614-r0",
210562          "description": "Pre generated bundle of Mozilla certificates",
210563          "licenses": [
210564            {
210565              "license": {
210566                "id": "MPL-2.0"
210567              }
210568            },
210569            {
210570              "license": {
210571                "name": "AND"
210572              }
210573            },
210574            {
210575              "license": {
210576                "id": "MIT"
210577              }
210578            }
210579          ],
210580          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
210581          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.14.0",
210582          "swid": {
210583            "attachment": {}
210584          },
210585          "pedigree": {},
210586          "externalReferences": [
210587            {
210588              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
210589              "type": "distribution"
210590            }
210591          ],
210592          "evidence": {},
210593          "signature": {
210594            "signature": {
210595              "publicKey": {}
210596            }
210597          },
210598          "modelCard": {
210599            "modelParameters": {
210600              "approach": {}
210601            },
210602            "quantitativeAnalysis": {
210603              "graphics": {}
210604            },
210605            "considerations": {}
210606          }
210607        },
210608        {
210609          "type": "library",
210610          "bom-ref": "pkg:maven/org.glassfish.hk2/hk2-api@2.5.0-b42?package-id=45be60709aa9aec6",
210611          "supplier": {},
210612          "group": "org.glassfish.hk2",
210613          "name": "hk2-api",
210614          "version": "2.5.0-b42",
210615          "licenses": [
210616            {
210617              "license": {
210618                "name": "https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html"
210619              }
210620            }
210621          ],
210622          "cpe": "cpe:2.3:a:glassfish:hk2-api:2.5.0-b42:*:*:*:*:*:*:*",
210623          "purl": "pkg:maven/org.glassfish.hk2/hk2-api@2.5.0-b42",
210624          "swid": {
210625            "attachment": {}
210626          },
210627          "pedigree": {},
210628          "externalReferences": [
210629            {
210630              "type": "build-meta",
210631              "hashes": [
210632                {
210633                  "alg": "SHA-1",
210634                  "content": "7fd4e3d0f2cb37c80ad0dedee3f5ee69503eaf52"
210635                }
210636              ]
210637            }
210638          ],
210639          "evidence": {},
210640          "signature": {
210641            "signature": {
210642              "publicKey": {}
210643            }
210644          },
210645          "modelCard": {
210646            "modelParameters": {
210647              "approach": {}
210648            },
210649            "quantitativeAnalysis": {
210650              "graphics": {}
210651            },
210652            "considerations": {}
210653          }
210654        },
210655        {
210656          "type": "library",
210657          "bom-ref": "pkg:maven/org.glassfish.hk2/hk2-locator@2.5.0-b42?package-id=23cae187b997b45d",
210658          "supplier": {},
210659          "group": "org.glassfish.hk2",
210660          "name": "hk2-locator",
210661          "version": "2.5.0-b42",
210662          "licenses": [
210663            {
210664              "license": {
210665                "name": "https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html"
210666              }
210667            }
210668          ],
210669          "cpe": "cpe:2.3:a:hk2-locator:hk2-locator:2.5.0-b42:*:*:*:*:*:*:*",
210670          "purl": "pkg:maven/org.glassfish.hk2/hk2-locator@2.5.0-b42",
210671          "swid": {
210672            "attachment": {}
210673          },
210674          "pedigree": {},
210675          "externalReferences": [
210676            {
210677              "type": "build-meta",
210678              "hashes": [
210679                {
210680                  "alg": "SHA-1",
210681                  "content": "9d6edc0cb226401a8316e67d81bfc37cb626ef91"
210682                }
210683              ]
210684            }
210685          ],
210686          "evidence": {},
210687          "signature": {
210688            "signature": {
210689              "publicKey": {}
210690            }
210691          },
210692          "modelCard": {
210693            "modelParameters": {
210694              "approach": {}
210695            },
210696            "quantitativeAnalysis": {
210697              "graphics": {}
210698            },
210699            "considerations": {}
210700          }
210701        },
210702        {
210703          "type": "library",
210704          "bom-ref": "pkg:maven/org.glassfish.hk2/hk2-utils@2.5.0-b42?package-id=107583b5f4533036",
210705          "supplier": {},
210706          "group": "org.glassfish.hk2",
210707          "name": "hk2-utils",
210708          "version": "2.5.0-b42",
210709          "licenses": [
210710            {
210711              "license": {
210712                "name": "https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html"
210713              }
210714            }
210715          ],
210716          "cpe": "cpe:2.3:a:glassfish:hk2-utils:2.5.0-b42:*:*:*:*:*:*:*",
210717          "purl": "pkg:maven/org.glassfish.hk2/hk2-utils@2.5.0-b42",
210718          "swid": {
210719            "attachment": {}
210720          },
210721          "pedigree": {},
210722          "externalReferences": [
210723            {
210724              "type": "build-meta",
210725              "hashes": [
210726                {
210727                  "alg": "SHA-1",
210728                  "content": "102a344e1728825e865a8986d7605602aba3c3b6"
210729                }
210730              ]
210731            }
210732          ],
210733          "evidence": {},
210734          "signature": {
210735            "signature": {
210736              "publicKey": {}
210737            }
210738          },
210739          "modelCard": {
210740            "modelParameters": {
210741              "approach": {}
210742            },
210743            "quantitativeAnalysis": {
210744              "graphics": {}
210745            },
210746            "considerations": {}
210747          }
210748        },
210749        {
210750          "type": "library",
210751          "bom-ref": "pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.13.1?package-id=89e9ce0870de8124",
210752          "supplier": {},
210753          "group": "com.fasterxml.jackson.core",
210754          "name": "jackson-annotations",
210755          "version": "2.13.1",
210756          "licenses": [
210757            {
210758              "license": {
210759                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
210760              }
210761            }
210762          ],
210763          "cpe": "cpe:2.3:a:jackson-annotations:jackson-annotations:2.13.1:*:*:*:*:*:*:*",
210764          "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.13.1",
210765          "swid": {
210766            "attachment": {}
210767          },
210768          "pedigree": {},
210769          "externalReferences": [
210770            {
210771              "type": "build-meta",
210772              "hashes": [
210773                {
210774                  "alg": "SHA-1",
210775                  "content": "1cbcbe4623113e6af92ccaa89884a345270f1a87"
210776                }
210777              ]
210778            }
210779          ],
210780          "evidence": {},
210781          "signature": {
210782            "signature": {
210783              "publicKey": {}
210784            }
210785          },
210786          "modelCard": {
210787            "modelParameters": {
210788              "approach": {}
210789            },
210790            "quantitativeAnalysis": {
210791              "graphics": {}
210792            },
210793            "considerations": {}
210794          }
210795        },
210796        {
210797          "type": "library",
210798          "bom-ref": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.13.1?package-id=1f5b6adfe2f0a1bc",
210799          "supplier": {},
210800          "group": "com.fasterxml.jackson.core",
210801          "name": "jackson-core",
210802          "version": "2.13.1",
210803          "licenses": [
210804            {
210805              "license": {
210806                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
210807              }
210808            }
210809          ],
210810          "cpe": "cpe:2.3:a:jackson-core:jackson-core:2.13.1:*:*:*:*:*:*:*",
210811          "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-core@2.13.1",
210812          "swid": {
210813            "attachment": {}
210814          },
210815          "pedigree": {},
210816          "externalReferences": [
210817            {
210818              "type": "build-meta",
210819              "hashes": [
210820                {
210821                  "alg": "SHA-1",
210822                  "content": "51ae921a2ed1e06ca8876f12f32f265e83c0b2b8"
210823                }
210824              ]
210825            }
210826          ],
210827          "evidence": {},
210828          "signature": {
210829            "signature": {
210830              "publicKey": {}
210831            }
210832          },
210833          "modelCard": {
210834            "modelParameters": {
210835              "approach": {}
210836            },
210837            "quantitativeAnalysis": {
210838              "graphics": {}
210839            },
210840            "considerations": {}
210841          }
210842        },
210843        {
210844          "type": "library",
210845          "bom-ref": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.1?package-id=a57e1639b6ef14c0",
210846          "supplier": {},
210847          "group": "com.fasterxml.jackson.core",
210848          "name": "jackson-databind",
210849          "version": "2.13.1",
210850          "licenses": [
210851            {
210852              "license": {
210853                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
210854              }
210855            }
210856          ],
210857          "cpe": "cpe:2.3:a:jackson-databind:jackson-databind:2.13.1:*:*:*:*:*:*:*",
210858          "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.1",
210859          "swid": {
210860            "attachment": {}
210861          },
210862          "pedigree": {},
210863          "externalReferences": [
210864            {
210865              "type": "build-meta",
210866              "hashes": [
210867                {
210868                  "alg": "SHA-1",
210869                  "content": "698b2d2b15d9a1b7aae025f1d9f576842285e7f6"
210870                }
210871              ]
210872            }
210873          ],
210874          "evidence": {},
210875          "signature": {
210876            "signature": {
210877              "publicKey": {}
210878            }
210879          },
210880          "modelCard": {
210881            "modelParameters": {
210882              "approach": {}
210883            },
210884            "quantitativeAnalysis": {
210885              "graphics": {}
210886            },
210887            "considerations": {}
210888          }
210889        },
210890        {
210891          "type": "library",
210892          "bom-ref": "pkg:maven/com.fasterxml.jackson.module/jackson-module-jaxb-annotations@2.13.1?package-id=ecb3e710e9f4ac49",
210893          "supplier": {},
210894          "group": "com.fasterxml.jackson.module",
210895          "name": "jackson-module-jaxb-annotations",
210896          "version": "2.13.1",
210897          "licenses": [
210898            {
210899              "license": {
210900                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
210901              }
210902            }
210903          ],
210904          "cpe": "cpe:2.3:a:jackson-module-jaxb-annotations:jackson-module-jaxb-annotations:2.13.1:*:*:*:*:*:*:*",
210905          "purl": "pkg:maven/com.fasterxml.jackson.module/jackson-module-jaxb-annotations@2.13.1",
210906          "swid": {
210907            "attachment": {}
210908          },
210909          "pedigree": {},
210910          "externalReferences": [
210911            {
210912              "type": "build-meta",
210913              "hashes": [
210914                {
210915                  "alg": "SHA-1",
210916                  "content": "63de86abf14db6ef940b21a50eaf5cadce0a6627"
210917                }
210918              ]
210919            }
210920          ],
210921          "evidence": {},
210922          "signature": {
210923            "signature": {
210924              "publicKey": {}
210925            }
210926          },
210927          "modelCard": {
210928            "modelParameters": {
210929              "approach": {}
210930            },
210931            "quantitativeAnalysis": {
210932              "graphics": {}
210933            },
210934            "considerations": {}
210935          }
210936        },
210937        {
210938          "type": "library",
210939          "bom-ref": "pkg:maven/com.sun/jakarta.activation-api@1.2.2?package-id=350355945fc7b49c",
210940          "supplier": {},
210941          "group": "jakarta.activation",
210942          "name": "jakarta.activation-api",
210943          "version": "1.2.2",
210944          "licenses": [
210945            {
210946              "license": {
210947                "name": "http://www.eclipse.org/org/documents/edl-v10.php"
210948              }
210949            }
210950          ],
210951          "cpe": "cpe:2.3:a:jakarta.activation-api:jakarta.activation-api:1.2.2:*:*:*:*:*:*:*",
210952          "purl": "pkg:maven/com.sun/jakarta.activation-api@1.2.2",
210953          "swid": {
210954            "attachment": {}
210955          },
210956          "pedigree": {},
210957          "externalReferences": [
210958            {
210959              "type": "build-meta",
210960              "hashes": [
210961                {
210962                  "alg": "SHA-1",
210963                  "content": "99f53adba383cb1bf7c3862844488574b559621f"
210964                }
210965              ]
210966            }
210967          ],
210968          "evidence": {},
210969          "signature": {
210970            "signature": {
210971              "publicKey": {}
210972            }
210973          },
210974          "modelCard": {
210975            "modelParameters": {
210976              "approach": {}
210977            },
210978            "quantitativeAnalysis": {
210979              "graphics": {}
210980            },
210981            "considerations": {}
210982          }
210983        },
210984        {
210985          "type": "library",
210986          "bom-ref": "pkg:maven/org.glassfish/jakarta.annotation-api@1.3.5?package-id=fb9e1cad1b155a1b",
210987          "supplier": {},
210988          "group": "jakarta.annotation",
210989          "name": "jakarta.annotation-api",
210990          "version": "1.3.5",
210991          "licenses": [
210992            {
210993              "license": {
210994                "name": "http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html"
210995              }
210996            }
210997          ],
210998          "cpe": "cpe:2.3:a:jakarta.annotation-api:jakarta.annotation-api:1.3.5:*:*:*:*:*:*:*",
210999          "purl": "pkg:maven/org.glassfish/jakarta.annotation-api@1.3.5",
211000          "swid": {
211001            "attachment": {}
211002          },
211003          "pedigree": {},
211004          "externalReferences": [
211005            {
211006              "type": "build-meta",
211007              "hashes": [
211008                {
211009                  "alg": "SHA-1",
211010                  "content": "59eb84ee0d616332ff44aba065f3888cf002cd2d"
211011                }
211012              ]
211013            }
211014          ],
211015          "evidence": {},
211016          "signature": {
211017            "signature": {
211018              "publicKey": {}
211019            }
211020          },
211021          "modelCard": {
211022            "modelParameters": {
211023              "approach": {}
211024            },
211025            "quantitativeAnalysis": {
211026              "graphics": {}
211027            },
211028            "considerations": {}
211029          }
211030        },
211031        {
211032          "type": "library",
211033          "bom-ref": "pkg:maven/jakarta.xml.bind-api/jakarta.xml.bind-api@2.3.3?package-id=4ac61dac5750d2e3",
211034          "supplier": {},
211035          "group": "jakarta.xml.bind",
211036          "name": "jakarta.xml.bind-api",
211037          "version": "2.3.3",
211038          "licenses": [
211039            {
211040              "license": {
211041                "name": "http://www.eclipse.org/org/documents/edl-v10.php"
211042              }
211043            }
211044          ],
211045          "cpe": "cpe:2.3:a:jakarta.xml.bind-api:jakarta.xml.bind-api:2.3.3:*:*:*:*:*:*:*",
211046          "purl": "pkg:maven/jakarta.xml.bind-api/jakarta.xml.bind-api@2.3.3",
211047          "swid": {
211048            "attachment": {}
211049          },
211050          "pedigree": {},
211051          "externalReferences": [
211052            {
211053              "type": "build-meta",
211054              "hashes": [
211055                {
211056                  "alg": "SHA-1",
211057                  "content": "48e3b9cfc10752fba3521d6511f4165bea951801"
211058                }
211059              ]
211060            }
211061          ],
211062          "evidence": {},
211063          "signature": {
211064            "signature": {
211065              "publicKey": {}
211066            }
211067          },
211068          "modelCard": {
211069            "modelParameters": {
211070              "approach": {}
211071            },
211072            "quantitativeAnalysis": {
211073              "graphics": {}
211074            },
211075            "considerations": {}
211076          }
211077        },
211078        {
211079          "type": "application",
211080          "bom-ref": "pkg:generic/java@17-ea+14?package-id=fb1af09dc1b83573",
211081          "supplier": {},
211082          "name": "java",
211083          "version": "17-ea+14",
211084          "cpe": "cpe:2.3:a:oracle:openjdk:17-ea\\+14:*:*:*:*:*:*:*",
211085          "purl": "pkg:generic/java@17-ea+14",
211086          "swid": {
211087            "attachment": {}
211088          },
211089          "pedigree": {},
211090          "evidence": {},
211091          "signature": {
211092            "signature": {
211093              "publicKey": {}
211094            }
211095          },
211096          "modelCard": {
211097            "modelParameters": {
211098              "approach": {}
211099            },
211100            "quantitativeAnalysis": {
211101              "graphics": {}
211102            },
211103            "considerations": {}
211104          }
211105        },
211106        {
211107          "type": "library",
211108          "bom-ref": "pkg:apk/alpine/java-cacerts@1.0-r1?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=423274d2f2da67db",
211109          "supplier": {},
211110          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
211111          "name": "java-cacerts",
211112          "version": "1.0-r1",
211113          "description": "Script to update java cacerts store",
211114          "licenses": [
211115            {
211116              "license": {
211117                "id": "MIT"
211118              }
211119            }
211120          ],
211121          "cpe": "cpe:2.3:a:java-cacerts:java-cacerts:1.0-r1:*:*:*:*:*:*:*",
211122          "purl": "pkg:apk/alpine/java-cacerts@1.0-r1?arch=x86_64\u0026distro=alpine-3.14.0",
211123          "swid": {
211124            "attachment": {}
211125          },
211126          "pedigree": {},
211127          "externalReferences": [
211128            {
211129              "url": "https://git.alpinelinux.org/aports/tree/community/java-cacerts",
211130              "type": "distribution"
211131            }
211132          ],
211133          "evidence": {},
211134          "signature": {
211135            "signature": {
211136              "publicKey": {}
211137            }
211138          },
211139          "modelCard": {
211140            "modelParameters": {
211141              "approach": {}
211142            },
211143            "quantitativeAnalysis": {
211144              "graphics": {}
211145            },
211146            "considerations": {}
211147          }
211148        },
211149        {
211150          "type": "library",
211151          "bom-ref": "pkg:maven/org.javassist/javassist@3.22.0-CR2?package-id=71fc9d47cb1d25e0",
211152          "supplier": {},
211153          "group": "org.javassist",
211154          "name": "javassist",
211155          "version": "3.22.0-CR2",
211156          "licenses": [
211157            {
211158              "license": {
211159                "name": "http://www.mozilla.org/MPL/MPL-1.1.html, http://www.gnu.org/licenses/lgpl-2.1.html, http://www.apache.org/licenses/"
211160              }
211161            }
211162          ],
211163          "cpe": "cpe:2.3:a:shigeru-chiba\\,-www-javassist-org:javassist:3.22.0-CR2:*:*:*:*:*:*:*",
211164          "purl": "pkg:maven/org.javassist/javassist@3.22.0-CR2",
211165          "swid": {
211166            "attachment": {}
211167          },
211168          "pedigree": {},
211169          "externalReferences": [
211170            {
211171              "type": "build-meta",
211172              "hashes": [
211173                {
211174                  "alg": "SHA-1",
211175                  "content": "44eaf0990dea92f4bca4b9931b2239c0e8756ee7"
211176                }
211177              ]
211178            }
211179          ],
211180          "evidence": {},
211181          "signature": {
211182            "signature": {
211183              "publicKey": {}
211184            }
211185          },
211186          "modelCard": {
211187            "modelParameters": {
211188              "approach": {}
211189            },
211190            "quantitativeAnalysis": {
211191              "graphics": {}
211192            },
211193            "considerations": {}
211194          }
211195        },
211196        {
211197          "type": "library",
211198          "bom-ref": "pkg:maven/org.glassfish/javax.annotation-api@1.3.2?package-id=2b5b0da472e81775",
211199          "supplier": {},
211200          "group": "javax.annotation",
211201          "name": "javax.annotation-api",
211202          "version": "1.3.2",
211203          "licenses": [
211204            {
211205              "license": {
211206                "name": "https://github.com/javaee/javax.annotation/blob/master/LICENSE"
211207              }
211208            }
211209          ],
211210          "cpe": "cpe:2.3:a:javax.annotation-api:javax.annotation-api:1.3.2:*:*:*:*:*:*:*",
211211          "purl": "pkg:maven/org.glassfish/javax.annotation-api@1.3.2",
211212          "swid": {
211213            "attachment": {}
211214          },
211215          "pedigree": {},
211216          "externalReferences": [
211217            {
211218              "type": "build-meta",
211219              "hashes": [
211220                {
211221                  "alg": "SHA-1",
211222                  "content": "934c04d3cfef185a8008e7bf34331b79730a9d43"
211223                }
211224              ]
211225            }
211226          ],
211227          "evidence": {},
211228          "signature": {
211229            "signature": {
211230              "publicKey": {}
211231            }
211232          },
211233          "modelCard": {
211234            "modelParameters": {
211235              "approach": {}
211236            },
211237            "quantitativeAnalysis": {
211238              "graphics": {}
211239            },
211240            "considerations": {}
211241          }
211242        },
211243        {
211244          "type": "library",
211245          "bom-ref": "pkg:maven/org.glassfish.hk2.external/javax.inject@2.5.0-b42?package-id=98208f013fc569d6",
211246          "supplier": {},
211247          "group": "org.glassfish.hk2.external",
211248          "name": "javax.inject",
211249          "version": "2.5.0-b42",
211250          "licenses": [
211251            {
211252              "license": {
211253                "name": "https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html"
211254              }
211255            }
211256          ],
211257          "cpe": "cpe:2.3:a:javax.inject:javax.inject:2.5.0-b42:*:*:*:*:*:*:*",
211258          "purl": "pkg:maven/org.glassfish.hk2.external/javax.inject@2.5.0-b42",
211259          "swid": {
211260            "attachment": {}
211261          },
211262          "pedigree": {},
211263          "externalReferences": [
211264            {
211265              "type": "build-meta",
211266              "hashes": [
211267                {
211268                  "alg": "SHA-1",
211269                  "content": "98e0b7dcef77dc04809f0603868140a1c60bea71"
211270                }
211271              ]
211272            }
211273          ],
211274          "evidence": {},
211275          "signature": {
211276            "signature": {
211277              "publicKey": {}
211278            }
211279          },
211280          "modelCard": {
211281            "modelParameters": {
211282              "approach": {}
211283            },
211284            "quantitativeAnalysis": {
211285              "graphics": {}
211286            },
211287            "considerations": {}
211288          }
211289        },
211290        {
211291          "type": "library",
211292          "bom-ref": "pkg:maven/javax.ws.rs-api/javax.ws.rs-api@2.1?package-id=1a78ff1a5f581769",
211293          "supplier": {},
211294          "group": "javax.ws.rs",
211295          "name": "javax.ws.rs-api",
211296          "version": "2.1",
211297          "licenses": [
211298            {
211299              "license": {
211300                "name": "https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1"
211301              }
211302            }
211303          ],
211304          "cpe": "cpe:2.3:a:oracle-corporation:javax.ws.rs-api:2.1:*:*:*:*:*:*:*",
211305          "purl": "pkg:maven/javax.ws.rs-api/javax.ws.rs-api@2.1",
211306          "swid": {
211307            "attachment": {}
211308          },
211309          "pedigree": {},
211310          "externalReferences": [
211311            {
211312              "type": "build-meta",
211313              "hashes": [
211314                {
211315                  "alg": "SHA-1",
211316                  "content": "426a0862406536e690c7caa8bb6ed32191986fac"
211317                }
211318              ]
211319            }
211320          ],
211321          "evidence": {},
211322          "signature": {
211323            "signature": {
211324              "publicKey": {}
211325            }
211326          },
211327          "modelCard": {
211328            "modelParameters": {
211329              "approach": {}
211330            },
211331            "quantitativeAnalysis": {
211332              "graphics": {}
211333            },
211334            "considerations": {}
211335          }
211336        },
211337        {
211338          "type": "library",
211339          "bom-ref": "pkg:maven/org.glassfish.jersey.core/jersey-client@2.26?package-id=5c8461a7366022b7",
211340          "supplier": {},
211341          "group": "org.glassfish.jersey.core",
211342          "name": "jersey-client",
211343          "version": "2.26",
211344          "licenses": [
211345            {
211346              "license": {
211347                "name": "https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1"
211348              }
211349            }
211350          ],
211351          "cpe": "cpe:2.3:a:jersey-client:jersey-client:2.26:*:*:*:*:*:*:*",
211352          "purl": "pkg:maven/org.glassfish.jersey.core/jersey-client@2.26",
211353          "swid": {
211354            "attachment": {}
211355          },
211356          "pedigree": {},
211357          "externalReferences": [
211358            {
211359              "type": "build-meta",
211360              "hashes": [
211361                {
211362                  "alg": "SHA-1",
211363                  "content": "125b8d1040d121a5dc4ce6858e21a6160bed7afa"
211364                }
211365              ]
211366            }
211367          ],
211368          "evidence": {},
211369          "signature": {
211370            "signature": {
211371              "publicKey": {}
211372            }
211373          },
211374          "modelCard": {
211375            "modelParameters": {
211376              "approach": {}
211377            },
211378            "quantitativeAnalysis": {
211379              "graphics": {}
211380            },
211381            "considerations": {}
211382          }
211383        },
211384        {
211385          "type": "library",
211386          "bom-ref": "pkg:maven/org.glassfish.jersey.core/jersey-common@2.26?package-id=ad20887a916ee088",
211387          "supplier": {},
211388          "group": "org.glassfish.jersey.core",
211389          "name": "jersey-common",
211390          "version": "2.26",
211391          "licenses": [
211392            {
211393              "license": {
211394                "name": "https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1"
211395              }
211396            }
211397          ],
211398          "cpe": "cpe:2.3:a:jersey-common:jersey-common:2.26:*:*:*:*:*:*:*",
211399          "purl": "pkg:maven/org.glassfish.jersey.core/jersey-common@2.26",
211400          "swid": {
211401            "attachment": {}
211402          },
211403          "pedigree": {},
211404          "externalReferences": [
211405            {
211406              "type": "build-meta",
211407              "hashes": [
211408                {
211409                  "alg": "SHA-1",
211410                  "content": "d96475745c5e72cafcbc4dc9e2e725f4d9683f21"
211411                }
211412              ]
211413            }
211414          ],
211415          "evidence": {},
211416          "signature": {
211417            "signature": {
211418              "publicKey": {}
211419            }
211420          },
211421          "modelCard": {
211422            "modelParameters": {
211423              "approach": {}
211424            },
211425            "quantitativeAnalysis": {
211426              "graphics": {}
211427            },
211428            "considerations": {}
211429          }
211430        },
211431        {
211432          "type": "library",
211433          "bom-ref": "pkg:maven/org.glassfish.jersey.ext/jersey-entity-filtering@2.26?package-id=5ca13c1f3ffa6c4",
211434          "supplier": {},
211435          "group": "org.glassfish.jersey.ext",
211436          "name": "jersey-entity-filtering",
211437          "version": "2.26",
211438          "licenses": [
211439            {
211440              "license": {
211441                "name": "https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1"
211442              }
211443            }
211444          ],
211445          "cpe": "cpe:2.3:a:jersey-entity-filtering:jersey-entity-filtering:2.26:*:*:*:*:*:*:*",
211446          "purl": "pkg:maven/org.glassfish.jersey.ext/jersey-entity-filtering@2.26",
211447          "swid": {
211448            "attachment": {}
211449          },
211450          "pedigree": {},
211451          "externalReferences": [
211452            {
211453              "type": "build-meta",
211454              "hashes": [
211455                {
211456                  "alg": "SHA-1",
211457                  "content": "a8ea15c9cd0bd8b090dbbf0f0e43aa39604f3433"
211458                }
211459              ]
211460            }
211461          ],
211462          "evidence": {},
211463          "signature": {
211464            "signature": {
211465              "publicKey": {}
211466            }
211467          },
211468          "modelCard": {
211469            "modelParameters": {
211470              "approach": {}
211471            },
211472            "quantitativeAnalysis": {
211473              "graphics": {}
211474            },
211475            "considerations": {}
211476          }
211477        },
211478        {
211479          "type": "library",
211480          "bom-ref": "pkg:maven/org.glassfish.jersey.inject/jersey-hk2@2.26?package-id=58cbd95c762b612",
211481          "supplier": {},
211482          "group": "org.glassfish.jersey.inject",
211483          "name": "jersey-hk2",
211484          "version": "2.26",
211485          "licenses": [
211486            {
211487              "license": {
211488                "name": "https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1"
211489              }
211490            }
211491          ],
211492          "cpe": "cpe:2.3:a:jersey-hk2:jersey-hk2:2.26:*:*:*:*:*:*:*",
211493          "purl": "pkg:maven/org.glassfish.jersey.inject/jersey-hk2@2.26",
211494          "swid": {
211495            "attachment": {}
211496          },
211497          "pedigree": {},
211498          "externalReferences": [
211499            {
211500              "type": "build-meta",
211501              "hashes": [
211502                {
211503                  "alg": "SHA-1",
211504                  "content": "df27f7d7577acf4b532684448021632098924dab"
211505                }
211506              ]
211507            }
211508          ],
211509          "evidence": {},
211510          "signature": {
211511            "signature": {
211512              "publicKey": {}
211513            }
211514          },
211515          "modelCard": {
211516            "modelParameters": {
211517              "approach": {}
211518            },
211519            "quantitativeAnalysis": {
211520              "graphics": {}
211521            },
211522            "considerations": {}
211523          }
211524        },
211525        {
211526          "type": "library",
211527          "bom-ref": "pkg:maven/org.glassfish.jersey.media/jersey-media-json-jackson@2.26?package-id=a801d5f38afafe02",
211528          "supplier": {},
211529          "group": "org.glassfish.jersey.media",
211530          "name": "jersey-media-json-jackson",
211531          "version": "2.26",
211532          "licenses": [
211533            {
211534              "license": {
211535                "name": "https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1"
211536              }
211537            }
211538          ],
211539          "cpe": "cpe:2.3:a:jersey-media-json-jackson:jersey-media-json-jackson:2.26:*:*:*:*:*:*:*",
211540          "purl": "pkg:maven/org.glassfish.jersey.media/jersey-media-json-jackson@2.26",
211541          "swid": {
211542            "attachment": {}
211543          },
211544          "pedigree": {},
211545          "externalReferences": [
211546            {
211547              "type": "build-meta",
211548              "hashes": [
211549                {
211550                  "alg": "SHA-1",
211551                  "content": "ce3109479991527107921ca5e7943a6e7e20db80"
211552                }
211553              ]
211554            }
211555          ],
211556          "evidence": {},
211557          "signature": {
211558            "signature": {
211559              "publicKey": {}
211560            }
211561          },
211562          "modelCard": {
211563            "modelParameters": {
211564              "approach": {}
211565            },
211566            "quantitativeAnalysis": {
211567              "graphics": {}
211568            },
211569            "considerations": {}
211570          }
211571        },
211572        {
211573          "type": "library",
211574          "bom-ref": "pkg:maven/jrt-fs/jrt-fs@17-ea?package-id=da626d820e747d5f",
211575          "supplier": {},
211576          "name": "jrt-fs",
211577          "version": "17-ea",
211578          "cpe": "cpe:2.3:a:oracle-corporation:jrt-fs:17-ea:*:*:*:*:*:*:*",
211579          "purl": "pkg:maven/jrt-fs/jrt-fs@17-ea",
211580          "swid": {
211581            "attachment": {}
211582          },
211583          "pedigree": {},
211584          "externalReferences": [
211585            {
211586              "type": "build-meta",
211587              "hashes": [
211588                {
211589                  "alg": "SHA-1",
211590                  "content": "299abc6b65845de85d818d2ccff2ba68a75b7418"
211591                }
211592              ]
211593            }
211594          ],
211595          "evidence": {},
211596          "signature": {
211597            "signature": {
211598              "publicKey": {}
211599            }
211600          },
211601          "modelCard": {
211602            "modelParameters": {
211603              "approach": {}
211604            },
211605            "quantitativeAnalysis": {
211606              "graphics": {}
211607            },
211608            "considerations": {}
211609          }
211610        },
211611        {
211612          "type": "library",
211613          "bom-ref": "pkg:maven/org.slf4j/jul-to-slf4j@1.7.25?package-id=e7d1a290d9cb288a",
211614          "supplier": {},
211615          "group": "org.slf4j",
211616          "name": "jul-to-slf4j",
211617          "version": "1.7.25",
211618          "cpe": "cpe:2.3:a:jul-to-slf4j:jul-to-slf4j:1.7.25:*:*:*:*:*:*:*",
211619          "purl": "pkg:maven/org.slf4j/jul-to-slf4j@1.7.25",
211620          "swid": {
211621            "attachment": {}
211622          },
211623          "pedigree": {},
211624          "externalReferences": [
211625            {
211626              "type": "build-meta",
211627              "hashes": [
211628                {
211629                  "alg": "SHA-1",
211630                  "content": "0af5364cd6679bfffb114f0dec8a157aaa283b76"
211631                }
211632              ]
211633            }
211634          ],
211635          "evidence": {},
211636          "signature": {
211637            "signature": {
211638              "publicKey": {}
211639            }
211640          },
211641          "modelCard": {
211642            "modelParameters": {
211643              "approach": {}
211644            },
211645            "quantitativeAnalysis": {
211646              "graphics": {}
211647            },
211648            "considerations": {}
211649          }
211650        },
211651        {
211652          "type": "library",
211653          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.14.0\u0026package-id=76cb141a67eed50e",
211654          "supplier": {},
211655          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
211656          "name": "libc-utils",
211657          "version": "0.7.2-r3",
211658          "description": "Meta package to pull in correct libc",
211659          "licenses": [
211660            {
211661              "license": {
211662                "id": "BSD-2-Clause"
211663              }
211664            },
211665            {
211666              "license": {
211667                "name": "AND"
211668              }
211669            },
211670            {
211671              "license": {
211672                "id": "BSD-3-Clause"
211673              }
211674            }
211675          ],
211676          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
211677          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.14.0",
211678          "swid": {
211679            "attachment": {}
211680          },
211681          "pedigree": {},
211682          "externalReferences": [
211683            {
211684              "url": "https://alpinelinux.org",
211685              "type": "distribution"
211686            }
211687          ],
211688          "evidence": {},
211689          "signature": {
211690            "signature": {
211691              "publicKey": {}
211692            }
211693          },
211694          "modelCard": {
211695            "modelParameters": {
211696              "approach": {}
211697            },
211698            "quantitativeAnalysis": {
211699              "graphics": {}
211700            },
211701            "considerations": {}
211702          }
211703        },
211704        {
211705          "type": "library",
211706          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1k-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.14.0\u0026package-id=a8e4da1bd835ea49",
211707          "supplier": {},
211708          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
211709          "name": "libcrypto1.1",
211710          "version": "1.1.1k-r0",
211711          "description": "Crypto library from openssl",
211712          "licenses": [
211713            {
211714              "license": {
211715                "id": "OpenSSL"
211716              }
211717            }
211718          ],
211719          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1k-r0:*:*:*:*:*:*:*",
211720          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1k-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.14.0",
211721          "swid": {
211722            "attachment": {}
211723          },
211724          "pedigree": {},
211725          "externalReferences": [
211726            {
211727              "url": "https://www.openssl.org/",
211728              "type": "distribution"
211729            }
211730          ],
211731          "evidence": {},
211732          "signature": {
211733            "signature": {
211734              "publicKey": {}
211735            }
211736          },
211737          "modelCard": {
211738            "modelParameters": {
211739              "approach": {}
211740            },
211741            "quantitativeAnalysis": {
211742              "graphics": {}
211743            },
211744            "considerations": {}
211745          }
211746        },
211747        {
211748          "type": "library",
211749          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.14.0\u0026package-id=4f05bc02c33574a5",
211750          "supplier": {},
211751          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
211752          "name": "libcrypto1.1",
211753          "version": "1.1.1t-r2",
211754          "description": "Crypto library from openssl",
211755          "licenses": [
211756            {
211757              "license": {
211758                "id": "OpenSSL"
211759              }
211760            }
211761          ],
211762          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1t-r2:*:*:*:*:*:*:*",
211763          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.14.0",
211764          "swid": {
211765            "attachment": {}
211766          },
211767          "pedigree": {},
211768          "externalReferences": [
211769            {
211770              "url": "https://www.openssl.org/",
211771              "type": "distribution"
211772            }
211773          ],
211774          "evidence": {},
211775          "signature": {
211776            "signature": {
211777              "publicKey": {}
211778            }
211779          },
211780          "modelCard": {
211781            "modelParameters": {
211782              "approach": {}
211783            },
211784            "quantitativeAnalysis": {
211785              "graphics": {}
211786            },
211787            "considerations": {}
211788          }
211789        },
211790        {
211791          "type": "library",
211792          "bom-ref": "pkg:apk/alpine/libffi@3.3-r2?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=9e89f2d619383fa",
211793          "supplier": {},
211794          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
211795          "name": "libffi",
211796          "version": "3.3-r2",
211797          "description": "A portable, high level programming interface to various calling conventions.",
211798          "licenses": [
211799            {
211800              "license": {
211801                "id": "MIT"
211802              }
211803            }
211804          ],
211805          "cpe": "cpe:2.3:a:libffi:libffi:3.3-r2:*:*:*:*:*:*:*",
211806          "purl": "pkg:apk/alpine/libffi@3.3-r2?arch=x86_64\u0026distro=alpine-3.14.0",
211807          "swid": {
211808            "attachment": {}
211809          },
211810          "pedigree": {},
211811          "externalReferences": [
211812            {
211813              "url": "https://sourceware.org/libffi",
211814              "type": "distribution"
211815            }
211816          ],
211817          "evidence": {},
211818          "signature": {
211819            "signature": {
211820              "publicKey": {}
211821            }
211822          },
211823          "modelCard": {
211824            "modelParameters": {
211825              "approach": {}
211826            },
211827            "quantitativeAnalysis": {
211828              "graphics": {}
211829            },
211830            "considerations": {}
211831          }
211832        },
211833        {
211834          "type": "library",
211835          "bom-ref": "pkg:apk/alpine/libretls@3.3.3-r0?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=49022fa922cbbe4e",
211836          "supplier": {},
211837          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
211838          "name": "libretls",
211839          "version": "3.3.3-r0",
211840          "description": "port of libtls from libressl to openssl",
211841          "licenses": [
211842            {
211843              "license": {
211844                "id": "ISC"
211845              }
211846            },
211847            {
211848              "license": {
211849                "name": "AND"
211850              }
211851            },
211852            {
211853              "license": {
211854                "name": "(BSD-3-Clause"
211855              }
211856            },
211857            {
211858              "license": {
211859                "name": "OR"
211860              }
211861            },
211862            {
211863              "license": {
211864                "name": "MIT)"
211865              }
211866            }
211867          ],
211868          "cpe": "cpe:2.3:a:libretls:libretls:3.3.3-r0:*:*:*:*:*:*:*",
211869          "purl": "pkg:apk/alpine/libretls@3.3.3-r0?arch=x86_64\u0026distro=alpine-3.14.0",
211870          "swid": {
211871            "attachment": {}
211872          },
211873          "pedigree": {},
211874          "externalReferences": [
211875            {
211876              "url": "https://git.causal.agency/libretls/",
211877              "type": "distribution"
211878            }
211879          ],
211880          "evidence": {},
211881          "signature": {
211882            "signature": {
211883              "publicKey": {}
211884            }
211885          },
211886          "modelCard": {
211887            "modelParameters": {
211888              "approach": {}
211889            },
211890            "quantitativeAnalysis": {
211891              "graphics": {}
211892            },
211893            "considerations": {}
211894          }
211895        },
211896        {
211897          "type": "library",
211898          "bom-ref": "pkg:apk/alpine/libretls@3.3.3p1-r3?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=c50c962c5333e40a",
211899          "supplier": {},
211900          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
211901          "name": "libretls",
211902          "version": "3.3.3p1-r3",
211903          "description": "port of libtls from libressl to openssl",
211904          "licenses": [
211905            {
211906              "license": {
211907                "id": "ISC"
211908              }
211909            },
211910            {
211911              "license": {
211912                "name": "AND"
211913              }
211914            },
211915            {
211916              "license": {
211917                "name": "(BSD-3-Clause"
211918              }
211919            },
211920            {
211921              "license": {
211922                "name": "OR"
211923              }
211924            },
211925            {
211926              "license": {
211927                "name": "MIT)"
211928              }
211929            }
211930          ],
211931          "cpe": "cpe:2.3:a:libretls:libretls:3.3.3p1-r3:*:*:*:*:*:*:*",
211932          "purl": "pkg:apk/alpine/libretls@3.3.3p1-r3?arch=x86_64\u0026distro=alpine-3.14.0",
211933          "swid": {
211934            "attachment": {}
211935          },
211936          "pedigree": {},
211937          "externalReferences": [
211938            {
211939              "url": "https://git.causal.agency/libretls/",
211940              "type": "distribution"
211941            }
211942          ],
211943          "evidence": {},
211944          "signature": {
211945            "signature": {
211946              "publicKey": {}
211947            }
211948          },
211949          "modelCard": {
211950            "modelParameters": {
211951              "approach": {}
211952            },
211953            "quantitativeAnalysis": {
211954              "graphics": {}
211955            },
211956            "considerations": {}
211957          }
211958        },
211959        {
211960          "type": "library",
211961          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1k-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.14.0\u0026package-id=cce2236c3fac3c86",
211962          "supplier": {},
211963          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
211964          "name": "libssl1.1",
211965          "version": "1.1.1k-r0",
211966          "description": "SSL shared libraries",
211967          "licenses": [
211968            {
211969              "license": {
211970                "id": "OpenSSL"
211971              }
211972            }
211973          ],
211974          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1k-r0:*:*:*:*:*:*:*",
211975          "purl": "pkg:apk/alpine/libssl1.1@1.1.1k-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.14.0",
211976          "swid": {
211977            "attachment": {}
211978          },
211979          "pedigree": {},
211980          "externalReferences": [
211981            {
211982              "url": "https://www.openssl.org/",
211983              "type": "distribution"
211984            }
211985          ],
211986          "evidence": {},
211987          "signature": {
211988            "signature": {
211989              "publicKey": {}
211990            }
211991          },
211992          "modelCard": {
211993            "modelParameters": {
211994              "approach": {}
211995            },
211996            "quantitativeAnalysis": {
211997              "graphics": {}
211998            },
211999            "considerations": {}
212000          }
212001        },
212002        {
212003          "type": "library",
212004          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.14.0\u0026package-id=49466695c53c1135",
212005          "supplier": {},
212006          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
212007          "name": "libssl1.1",
212008          "version": "1.1.1t-r2",
212009          "description": "SSL shared libraries",
212010          "licenses": [
212011            {
212012              "license": {
212013                "id": "OpenSSL"
212014              }
212015            }
212016          ],
212017          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1t-r2:*:*:*:*:*:*:*",
212018          "purl": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.14.0",
212019          "swid": {
212020            "attachment": {}
212021          },
212022          "pedigree": {},
212023          "externalReferences": [
212024            {
212025              "url": "https://www.openssl.org/",
212026              "type": "distribution"
212027            }
212028          ],
212029          "evidence": {},
212030          "signature": {
212031            "signature": {
212032              "publicKey": {}
212033            }
212034          },
212035          "modelCard": {
212036            "modelParameters": {
212037              "approach": {}
212038            },
212039            "quantitativeAnalysis": {
212040              "graphics": {}
212041            },
212042            "considerations": {}
212043          }
212044        },
212045        {
212046          "type": "library",
212047          "bom-ref": "pkg:apk/alpine/libtasn1@4.17.0-r0?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=7ab7881e9d89ecad",
212048          "supplier": {},
212049          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
212050          "name": "libtasn1",
212051          "version": "4.17.0-r0",
212052          "description": "The ASN.1 library used in GNUTLS",
212053          "licenses": [
212054            {
212055              "license": {
212056                "id": "LGPL-2.1-or-later"
212057              }
212058            }
212059          ],
212060          "cpe": "cpe:2.3:a:libtasn1:libtasn1:4.17.0-r0:*:*:*:*:*:*:*",
212061          "purl": "pkg:apk/alpine/libtasn1@4.17.0-r0?arch=x86_64\u0026distro=alpine-3.14.0",
212062          "swid": {
212063            "attachment": {}
212064          },
212065          "pedigree": {},
212066          "externalReferences": [
212067            {
212068              "url": "https://www.gnu.org/software/gnutls/",
212069              "type": "distribution"
212070            }
212071          ],
212072          "evidence": {},
212073          "signature": {
212074            "signature": {
212075              "publicKey": {}
212076            }
212077          },
212078          "modelCard": {
212079            "modelParameters": {
212080              "approach": {}
212081            },
212082            "quantitativeAnalysis": {
212083              "graphics": {}
212084            },
212085            "considerations": {}
212086          }
212087        },
212088        {
212089          "type": "library",
212090          "bom-ref": "pkg:apk/alpine/libtasn1@4.17.0-r1?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=c9659bd74b33efff",
212091          "supplier": {},
212092          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
212093          "name": "libtasn1",
212094          "version": "4.17.0-r1",
212095          "description": "The ASN.1 library used in GNUTLS",
212096          "licenses": [
212097            {
212098              "license": {
212099                "id": "LGPL-2.1-or-later"
212100              }
212101            }
212102          ],
212103          "cpe": "cpe:2.3:a:libtasn1:libtasn1:4.17.0-r1:*:*:*:*:*:*:*",
212104          "purl": "pkg:apk/alpine/libtasn1@4.17.0-r1?arch=x86_64\u0026distro=alpine-3.14.0",
212105          "swid": {
212106            "attachment": {}
212107          },
212108          "pedigree": {},
212109          "externalReferences": [
212110            {
212111              "url": "https://www.gnu.org/software/gnutls/",
212112              "type": "distribution"
212113            }
212114          ],
212115          "evidence": {},
212116          "signature": {
212117            "signature": {
212118              "publicKey": {}
212119            }
212120          },
212121          "modelCard": {
212122            "modelParameters": {
212123              "approach": {}
212124            },
212125            "quantitativeAnalysis": {
212126              "graphics": {}
212127            },
212128            "considerations": {}
212129          }
212130        },
212131        {
212132          "type": "library",
212133          "bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-api@2.17.0?package-id=991c08e4ad4dcc14",
212134          "supplier": {},
212135          "group": "org.apache.logging.log4j",
212136          "name": "log4j-api",
212137          "version": "2.17.0",
212138          "licenses": [
212139            {
212140              "license": {
212141                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
212142              }
212143            }
212144          ],
212145          "cpe": "cpe:2.3:a:apache:log4j-api:2.17.0:*:*:*:*:*:*:*",
212146          "purl": "pkg:maven/org.apache.logging.log4j/log4j-api@2.17.0",
212147          "swid": {
212148            "attachment": {}
212149          },
212150          "pedigree": {},
212151          "externalReferences": [
212152            {
212153              "type": "build-meta",
212154              "hashes": [
212155                {
212156                  "alg": "SHA-1",
212157                  "content": "bbd791e9c8c9421e45337c4fe0a10851c086e36c"
212158                }
212159              ]
212160            }
212161          ],
212162          "evidence": {},
212163          "signature": {
212164            "signature": {
212165              "publicKey": {}
212166            }
212167          },
212168          "modelCard": {
212169            "modelParameters": {
212170              "approach": {}
212171            },
212172            "quantitativeAnalysis": {
212173              "graphics": {}
212174            },
212175            "considerations": {}
212176          }
212177        },
212178        {
212179          "type": "library",
212180          "bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.17.0?package-id=61df27c793dc0ec2",
212181          "supplier": {},
212182          "group": "org.apache.logging.log4j",
212183          "name": "log4j-to-slf4j",
212184          "version": "2.17.0",
212185          "licenses": [
212186            {
212187              "license": {
212188                "name": "https://www.apache.org/licenses/LICENSE-2.0.txt"
212189              }
212190            }
212191          ],
212192          "cpe": "cpe:2.3:a:apache:log4j-to-slf4j:2.17.0:*:*:*:*:*:*:*",
212193          "purl": "pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.17.0",
212194          "swid": {
212195            "attachment": {}
212196          },
212197          "pedigree": {},
212198          "externalReferences": [
212199            {
212200              "type": "build-meta",
212201              "hashes": [
212202                {
212203                  "alg": "SHA-1",
212204                  "content": "e50b82411b9ce9c204c938509f914b2bb887168b"
212205                }
212206              ]
212207            }
212208          ],
212209          "evidence": {},
212210          "signature": {
212211            "signature": {
212212              "publicKey": {}
212213            }
212214          },
212215          "modelCard": {
212216            "modelParameters": {
212217              "approach": {}
212218            },
212219            "quantitativeAnalysis": {
212220              "graphics": {}
212221            },
212222            "considerations": {}
212223          }
212224        },
212225        {
212226          "type": "library",
212227          "bom-ref": "pkg:maven/logback-classic/logback-classic@1.2.3?package-id=bbf59ed5da25a49b",
212228          "supplier": {},
212229          "group": "ch.qos.logback",
212230          "name": "logback-classic",
212231          "version": "1.2.3",
212232          "licenses": [
212233            {
212234              "license": {
212235                "name": "http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"
212236              }
212237            }
212238          ],
212239          "cpe": "cpe:2.3:a:logback-classic:logback-classic:1.2.3:*:*:*:*:*:*:*",
212240          "purl": "pkg:maven/logback-classic/logback-classic@1.2.3",
212241          "swid": {
212242            "attachment": {}
212243          },
212244          "pedigree": {},
212245          "externalReferences": [
212246            {
212247              "type": "build-meta",
212248              "hashes": [
212249                {
212250                  "alg": "SHA-1",
212251                  "content": "7c4f3c474fb2c041d8028740440937705ebb473a"
212252                }
212253              ]
212254            }
212255          ],
212256          "evidence": {},
212257          "signature": {
212258            "signature": {
212259              "publicKey": {}
212260            }
212261          },
212262          "modelCard": {
212263            "modelParameters": {
212264              "approach": {}
212265            },
212266            "quantitativeAnalysis": {
212267              "graphics": {}
212268            },
212269            "considerations": {}
212270          }
212271        },
212272        {
212273          "type": "library",
212274          "bom-ref": "pkg:maven/logback-core/logback-core@1.2.3?package-id=3fd3ba5508d97fd9",
212275          "supplier": {},
212276          "group": "ch.qos.logback",
212277          "name": "logback-core",
212278          "version": "1.2.3",
212279          "licenses": [
212280            {
212281              "license": {
212282                "name": "http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"
212283              }
212284            }
212285          ],
212286          "cpe": "cpe:2.3:a:logback-core:logback-core:1.2.3:*:*:*:*:*:*:*",
212287          "purl": "pkg:maven/logback-core/logback-core@1.2.3",
212288          "swid": {
212289            "attachment": {}
212290          },
212291          "pedigree": {},
212292          "externalReferences": [
212293            {
212294              "type": "build-meta",
212295              "hashes": [
212296                {
212297                  "alg": "SHA-1",
212298                  "content": "864344400c3d4d92dfeb0a305dc87d953677c03c"
212299                }
212300              ]
212301            }
212302          ],
212303          "evidence": {},
212304          "signature": {
212305            "signature": {
212306              "publicKey": {}
212307            }
212308          },
212309          "modelCard": {
212310            "modelParameters": {
212311              "approach": {}
212312            },
212313            "quantitativeAnalysis": {
212314              "graphics": {}
212315            },
212316            "considerations": {}
212317          }
212318        },
212319        {
212320          "type": "library",
212321          "bom-ref": "pkg:maven/lombok/lombok@1.18.22?package-id=55c274533d68b2ca",
212322          "supplier": {},
212323          "name": "lombok",
212324          "version": "1.18.22",
212325          "cpe": "cpe:2.3:a:lombok:lombok:1.18.22:*:*:*:*:*:*:*",
212326          "purl": "pkg:maven/lombok/lombok@1.18.22",
212327          "swid": {
212328            "attachment": {}
212329          },
212330          "pedigree": {},
212331          "externalReferences": [
212332            {
212333              "type": "build-meta",
212334              "hashes": [
212335                {
212336                  "alg": "SHA-1",
212337                  "content": "9c08ea24c6eb714e2d6170e8122c069a0ba9aacf"
212338                }
212339              ]
212340            }
212341          ],
212342          "evidence": {},
212343          "signature": {
212344            "signature": {
212345              "publicKey": {}
212346            }
212347          },
212348          "modelCard": {
212349            "modelParameters": {
212350              "approach": {}
212351            },
212352            "quantitativeAnalysis": {
212353              "graphics": {}
212354            },
212355            "considerations": {}
212356          }
212357        },
212358        {
212359          "type": "library",
212360          "bom-ref": "pkg:maven/com.mchange/mchange-commons-java@0.2.11?package-id=710e6cac5bf9d7a6",
212361          "supplier": {},
212362          "name": "mchange-commons-java",
212363          "version": "0.2.11",
212364          "cpe": "cpe:2.3:a:mchange-commons-java:mchange-commons-java:0.2.11:*:*:*:*:*:*:*",
212365          "purl": "pkg:maven/com.mchange/mchange-commons-java@0.2.11",
212366          "swid": {
212367            "attachment": {}
212368          },
212369          "pedigree": {},
212370          "externalReferences": [
212371            {
212372              "type": "build-meta",
212373              "hashes": [
212374                {
212375                  "alg": "SHA-1",
212376                  "content": "2a6a6c1fe25f28f5a073171956ce6250813467ef"
212377                }
212378              ]
212379            }
212380          ],
212381          "evidence": {},
212382          "signature": {
212383            "signature": {
212384              "publicKey": {}
212385            }
212386          },
212387          "modelCard": {
212388            "modelParameters": {
212389              "approach": {}
212390            },
212391            "quantitativeAnalysis": {
212392              "graphics": {}
212393            },
212394            "considerations": {}
212395          }
212396        },
212397        {
212398          "type": "library",
212399          "bom-ref": "pkg:apk/alpine/musl@1.2.2-r3?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=7122523f0dac0754",
212400          "supplier": {},
212401          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
212402          "name": "musl",
212403          "version": "1.2.2-r3",
212404          "description": "the musl c library (libc) implementation",
212405          "licenses": [
212406            {
212407              "license": {
212408                "id": "MIT"
212409              }
212410            }
212411          ],
212412          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.2-r3:*:*:*:*:*:*:*",
212413          "purl": "pkg:apk/alpine/musl@1.2.2-r3?arch=x86_64\u0026distro=alpine-3.14.0",
212414          "swid": {
212415            "attachment": {}
212416          },
212417          "pedigree": {},
212418          "externalReferences": [
212419            {
212420              "url": "https://musl.libc.org/",
212421              "type": "distribution"
212422            }
212423          ],
212424          "evidence": {},
212425          "signature": {
212426            "signature": {
212427              "publicKey": {}
212428            }
212429          },
212430          "modelCard": {
212431            "modelParameters": {
212432              "approach": {}
212433            },
212434            "quantitativeAnalysis": {
212435              "graphics": {}
212436            },
212437            "considerations": {}
212438          }
212439        },
212440        {
212441          "type": "library",
212442          "bom-ref": "pkg:apk/alpine/musl@1.2.2-r4?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=e981ed9fdcc8f274",
212443          "supplier": {},
212444          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
212445          "name": "musl",
212446          "version": "1.2.2-r4",
212447          "description": "the musl c library (libc) implementation",
212448          "licenses": [
212449            {
212450              "license": {
212451                "id": "MIT"
212452              }
212453            }
212454          ],
212455          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.2-r4:*:*:*:*:*:*:*",
212456          "purl": "pkg:apk/alpine/musl@1.2.2-r4?arch=x86_64\u0026distro=alpine-3.14.0",
212457          "swid": {
212458            "attachment": {}
212459          },
212460          "pedigree": {},
212461          "externalReferences": [
212462            {
212463              "url": "https://musl.libc.org/",
212464              "type": "distribution"
212465            }
212466          ],
212467          "evidence": {},
212468          "signature": {
212469            "signature": {
212470              "publicKey": {}
212471            }
212472          },
212473          "modelCard": {
212474            "modelParameters": {
212475              "approach": {}
212476            },
212477            "quantitativeAnalysis": {
212478              "graphics": {}
212479            },
212480            "considerations": {}
212481          }
212482        },
212483        {
212484          "type": "library",
212485          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.2-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.14.0\u0026package-id=6a9ab08217e03637",
212486          "supplier": {},
212487          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
212488          "name": "musl-utils",
212489          "version": "1.2.2-r3",
212490          "description": "the musl c library (libc) implementation",
212491          "licenses": [
212492            {
212493              "license": {
212494                "id": "MIT"
212495              }
212496            },
212497            {
212498              "license": {
212499                "name": "BSD"
212500              }
212501            },
212502            {
212503              "license": {
212504                "id": "GPL-2.0-or-later"
212505              }
212506            }
212507          ],
212508          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.2-r3:*:*:*:*:*:*:*",
212509          "purl": "pkg:apk/alpine/musl-utils@1.2.2-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.14.0",
212510          "swid": {
212511            "attachment": {}
212512          },
212513          "pedigree": {},
212514          "externalReferences": [
212515            {
212516              "url": "https://musl.libc.org/",
212517              "type": "distribution"
212518            }
212519          ],
212520          "evidence": {},
212521          "signature": {
212522            "signature": {
212523              "publicKey": {}
212524            }
212525          },
212526          "modelCard": {
212527            "modelParameters": {
212528              "approach": {}
212529            },
212530            "quantitativeAnalysis": {
212531              "graphics": {}
212532            },
212533            "considerations": {}
212534          }
212535        },
212536        {
212537          "type": "library",
212538          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.2-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.14.0\u0026package-id=254a7d4894b2b5f5",
212539          "supplier": {},
212540          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
212541          "name": "musl-utils",
212542          "version": "1.2.2-r4",
212543          "description": "the musl c library (libc) implementation",
212544          "licenses": [
212545            {
212546              "license": {
212547                "id": "MIT"
212548              }
212549            },
212550            {
212551              "license": {
212552                "name": "BSD"
212553              }
212554            },
212555            {
212556              "license": {
212557                "id": "GPL-2.0-or-later"
212558              }
212559            }
212560          ],
212561          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.2-r4:*:*:*:*:*:*:*",
212562          "purl": "pkg:apk/alpine/musl-utils@1.2.2-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.14.0",
212563          "swid": {
212564            "attachment": {}
212565          },
212566          "pedigree": {},
212567          "externalReferences": [
212568            {
212569              "url": "https://musl.libc.org/",
212570              "type": "distribution"
212571            }
212572          ],
212573          "evidence": {},
212574          "signature": {
212575            "signature": {
212576              "publicKey": {}
212577            }
212578          },
212579          "modelCard": {
212580            "modelParameters": {
212581              "approach": {}
212582            },
212583            "quantitativeAnalysis": {
212584              "graphics": {}
212585            },
212586            "considerations": {}
212587          }
212588        },
212589        {
212590          "type": "library",
212591          "bom-ref": "pkg:maven/org.glassfish.hk2/osgi-resource-locator@1.0.1?package-id=224cfe4676787d32",
212592          "supplier": {},
212593          "group": "org.glassfish.hk2",
212594          "name": "osgi-resource-locator",
212595          "version": "1.0.1",
212596          "licenses": [
212597            {
212598              "license": {
212599                "name": "https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html"
212600              }
212601            }
212602          ],
212603          "cpe": "cpe:2.3:a:osgi-resource-locator:osgi-resource-locator:1.0.1:*:*:*:*:*:*:*",
212604          "purl": "pkg:maven/org.glassfish.hk2/osgi-resource-locator@1.0.1",
212605          "swid": {
212606            "attachment": {}
212607          },
212608          "pedigree": {},
212609          "externalReferences": [
212610            {
212611              "type": "build-meta",
212612              "hashes": [
212613                {
212614                  "alg": "SHA-1",
212615                  "content": "4ed2b2d4738aed5786cfa64cba5a332779c4c708"
212616                }
212617              ]
212618            }
212619          ],
212620          "evidence": {},
212621          "signature": {
212622            "signature": {
212623              "publicKey": {}
212624            }
212625          },
212626          "modelCard": {
212627            "modelParameters": {
212628              "approach": {}
212629            },
212630            "quantitativeAnalysis": {
212631              "graphics": {}
212632            },
212633            "considerations": {}
212634          }
212635        },
212636        {
212637          "type": "library",
212638          "bom-ref": "pkg:apk/alpine/p11-kit@0.23.22-r0?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=f294a166107fe6e2",
212639          "supplier": {},
212640          "publisher": "Fabian Affolter \u003cfabian@affolter-engineering.ch\u003e",
212641          "name": "p11-kit",
212642          "version": "0.23.22-r0",
212643          "description": "Library for loading and sharing PKCS#11 modules",
212644          "licenses": [
212645            {
212646              "license": {
212647                "id": "BSD-3-Clause"
212648              }
212649            }
212650          ],
212651          "cpe": "cpe:2.3:a:p11-kit:p11-kit:0.23.22-r0:*:*:*:*:*:*:*",
212652          "purl": "pkg:apk/alpine/p11-kit@0.23.22-r0?arch=x86_64\u0026distro=alpine-3.14.0",
212653          "swid": {
212654            "attachment": {}
212655          },
212656          "pedigree": {},
212657          "externalReferences": [
212658            {
212659              "url": "https://p11-glue.freedesktop.org/",
212660              "type": "distribution"
212661            }
212662          ],
212663          "evidence": {},
212664          "signature": {
212665            "signature": {
212666              "publicKey": {}
212667            }
212668          },
212669          "modelCard": {
212670            "modelParameters": {
212671              "approach": {}
212672            },
212673            "quantitativeAnalysis": {
212674              "graphics": {}
212675            },
212676            "considerations": {}
212677          }
212678        },
212679        {
212680          "type": "library",
212681          "bom-ref": "pkg:apk/alpine/p11-kit-trust@0.23.22-r0?arch=x86_64\u0026upstream=p11-kit\u0026distro=alpine-3.14.0\u0026package-id=7217ba22f4c611cd",
212682          "supplier": {},
212683          "publisher": "Fabian Affolter \u003cfabian@affolter-engineering.ch\u003e",
212684          "name": "p11-kit-trust",
212685          "version": "0.23.22-r0",
212686          "description": "System trust module from p11-kit",
212687          "licenses": [
212688            {
212689              "license": {
212690                "id": "BSD-3-Clause"
212691              }
212692            }
212693          ],
212694          "cpe": "cpe:2.3:a:p11-kit-trust:p11-kit-trust:0.23.22-r0:*:*:*:*:*:*:*",
212695          "purl": "pkg:apk/alpine/p11-kit-trust@0.23.22-r0?arch=x86_64\u0026upstream=p11-kit\u0026distro=alpine-3.14.0",
212696          "swid": {
212697            "attachment": {}
212698          },
212699          "pedigree": {},
212700          "externalReferences": [
212701            {
212702              "url": "https://p11-glue.freedesktop.org/",
212703              "type": "distribution"
212704            }
212705          ],
212706          "evidence": {},
212707          "signature": {
212708            "signature": {
212709              "publicKey": {}
212710            }
212711          },
212712          "modelCard": {
212713            "modelParameters": {
212714              "approach": {}
212715            },
212716            "quantitativeAnalysis": {
212717              "graphics": {}
212718            },
212719            "considerations": {}
212720          }
212721        },
212722        {
212723          "type": "library",
212724          "bom-ref": "pkg:maven/org.quartz-scheduler/quartz@2.3.0?package-id=dc4697cb17463c55",
212725          "supplier": {},
212726          "group": "org.quartz-scheduler",
212727          "name": "quartz",
212728          "version": "2.3.0",
212729          "licenses": [
212730            {
212731              "license": {
212732                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
212733              }
212734            }
212735          ],
212736          "cpe": "cpe:2.3:a:quartz-scheduler:quartz:2.3.0:*:*:*:*:*:*:*",
212737          "purl": "pkg:maven/org.quartz-scheduler/quartz@2.3.0",
212738          "swid": {
212739            "attachment": {}
212740          },
212741          "pedigree": {},
212742          "externalReferences": [
212743            {
212744              "type": "build-meta",
212745              "hashes": [
212746                {
212747                  "alg": "SHA-1",
212748                  "content": "a090397102a12f6241177c5d501835334bb7662a"
212749                }
212750              ]
212751            }
212752          ],
212753          "evidence": {},
212754          "signature": {
212755            "signature": {
212756              "publicKey": {}
212757            }
212758          },
212759          "modelCard": {
212760            "modelParameters": {
212761              "approach": {}
212762            },
212763            "quantitativeAnalysis": {
212764              "graphics": {}
212765            },
212766            "considerations": {}
212767          }
212768        },
212769        {
212770          "type": "library",
212771          "bom-ref": "pkg:apk/alpine/scanelf@1.3.2-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.14.0\u0026package-id=f9f3f41ca590dd0a",
212772          "supplier": {},
212773          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
212774          "name": "scanelf",
212775          "version": "1.3.2-r0",
212776          "description": "Scan ELF binaries for stuff",
212777          "licenses": [
212778            {
212779              "license": {
212780                "id": "GPL-2.0-only"
212781              }
212782            }
212783          ],
212784          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.2-r0:*:*:*:*:*:*:*",
212785          "purl": "pkg:apk/alpine/scanelf@1.3.2-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.14.0",
212786          "swid": {
212787            "attachment": {}
212788          },
212789          "pedigree": {},
212790          "externalReferences": [
212791            {
212792              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
212793              "type": "distribution"
212794            }
212795          ],
212796          "evidence": {},
212797          "signature": {
212798            "signature": {
212799              "publicKey": {}
212800            }
212801          },
212802          "modelCard": {
212803            "modelParameters": {
212804              "approach": {}
212805            },
212806            "quantitativeAnalysis": {
212807              "graphics": {}
212808            },
212809            "considerations": {}
212810          }
212811        },
212812        {
212813          "type": "library",
212814          "bom-ref": "pkg:maven/io.pliant.scheduler/scheduler@0.0.1-SNAPSHOT?package-id=4eadbd304d6746af",
212815          "supplier": {},
212816          "group": "io.pliant.scheduler",
212817          "name": "scheduler",
212818          "version": "0.0.1-SNAPSHOT",
212819          "cpe": "cpe:2.3:a:springframework:scheduler:0.0.1-SNAPSHOT:*:*:*:*:*:*:*",
212820          "purl": "pkg:maven/io.pliant.scheduler/scheduler@0.0.1-SNAPSHOT",
212821          "swid": {
212822            "attachment": {}
212823          },
212824          "pedigree": {},
212825          "externalReferences": [
212826            {
212827              "type": "build-meta",
212828              "hashes": [
212829                {
212830                  "alg": "SHA-1",
212831                  "content": "36014b89b18b079f274062b23d4621d7a2c7599e"
212832                }
212833              ]
212834            }
212835          ],
212836          "evidence": {},
212837          "signature": {
212838            "signature": {
212839              "publicKey": {}
212840            }
212841          },
212842          "modelCard": {
212843            "modelParameters": {
212844              "approach": {}
212845            },
212846            "quantitativeAnalysis": {
212847              "graphics": {}
212848            },
212849            "considerations": {}
212850          }
212851        },
212852        {
212853          "type": "library",
212854          "bom-ref": "pkg:maven/org.slf4j/slf4j-api@1.7.25?package-id=acf3f11bdb789270",
212855          "supplier": {},
212856          "group": "org.slf4j",
212857          "name": "slf4j-api",
212858          "version": "1.7.25",
212859          "cpe": "cpe:2.3:a:slf4j-api:slf4j-api:1.7.25:*:*:*:*:*:*:*",
212860          "purl": "pkg:maven/org.slf4j/slf4j-api@1.7.25",
212861          "swid": {
212862            "attachment": {}
212863          },
212864          "pedigree": {},
212865          "externalReferences": [
212866            {
212867              "type": "build-meta",
212868              "hashes": [
212869                {
212870                  "alg": "SHA-1",
212871                  "content": "da76ca59f6a57ee3102f8f9bd9cee742973efa8a"
212872                }
212873              ]
212874            }
212875          ],
212876          "evidence": {},
212877          "signature": {
212878            "signature": {
212879              "publicKey": {}
212880            }
212881          },
212882          "modelCard": {
212883            "modelParameters": {
212884              "approach": {}
212885            },
212886            "quantitativeAnalysis": {
212887              "graphics": {}
212888            },
212889            "considerations": {}
212890          }
212891        },
212892        {
212893          "type": "library",
212894          "bom-ref": "pkg:maven/org.yaml/snakeyaml@1.29?package-id=721746b019aec5fd",
212895          "supplier": {},
212896          "group": "org.yaml",
212897          "name": "snakeyaml",
212898          "version": "1.29",
212899          "licenses": [
212900            {
212901              "license": {
212902                "name": "http://www.apache.org/licenses/LICENSE-2.0.txt"
212903              }
212904            }
212905          ],
212906          "cpe": "cpe:2.3:a:snakeyaml:snakeyaml:1.29:*:*:*:*:*:*:*",
212907          "purl": "pkg:maven/org.yaml/snakeyaml@1.29",
212908          "swid": {
212909            "attachment": {}
212910          },
212911          "pedigree": {},
212912          "externalReferences": [
212913            {
212914              "type": "build-meta",
212915              "hashes": [
212916                {
212917                  "alg": "SHA-1",
212918                  "content": "6d0cdafb2010f1297e574656551d7145240f6e25"
212919                }
212920              ]
212921            }
212922          ],
212923          "evidence": {},
212924          "signature": {
212925            "signature": {
212926              "publicKey": {}
212927            }
212928          },
212929          "modelCard": {
212930            "modelParameters": {
212931              "approach": {}
212932            },
212933            "quantitativeAnalysis": {
212934              "graphics": {}
212935            },
212936            "considerations": {}
212937          }
212938        },
212939        {
212940          "type": "library",
212941          "bom-ref": "pkg:maven/spring-aop/spring-aop@5.3.14?package-id=3ac76bc93e1a8f03",
212942          "supplier": {},
212943          "name": "spring-aop",
212944          "version": "5.3.14",
212945          "cpe": "cpe:2.3:a:spring-aop:spring-aop:5.3.14:*:*:*:*:*:*:*",
212946          "purl": "pkg:maven/spring-aop/spring-aop@5.3.14",
212947          "swid": {
212948            "attachment": {}
212949          },
212950          "pedigree": {},
212951          "externalReferences": [
212952            {
212953              "type": "build-meta",
212954              "hashes": [
212955                {
212956                  "alg": "SHA-1",
212957                  "content": "f049146a55991e89c0f04b9624f1f69e1763d80f"
212958                }
212959              ]
212960            }
212961          ],
212962          "evidence": {},
212963          "signature": {
212964            "signature": {
212965              "publicKey": {}
212966            }
212967          },
212968          "modelCard": {
212969            "modelParameters": {
212970              "approach": {}
212971            },
212972            "quantitativeAnalysis": {
212973              "graphics": {}
212974            },
212975            "considerations": {}
212976          }
212977        },
212978        {
212979          "type": "library",
212980          "bom-ref": "pkg:maven/spring-beans/spring-beans@5.3.14?package-id=99f686d0e15a48e0",
212981          "supplier": {},
212982          "name": "spring-beans",
212983          "version": "5.3.14",
212984          "cpe": "cpe:2.3:a:spring-beans:spring-beans:5.3.14:*:*:*:*:*:*:*",
212985          "purl": "pkg:maven/spring-beans/spring-beans@5.3.14",
212986          "swid": {
212987            "attachment": {}
212988          },
212989          "pedigree": {},
212990          "externalReferences": [
212991            {
212992              "type": "build-meta",
212993              "hashes": [
212994                {
212995                  "alg": "SHA-1",
212996                  "content": "24cc27af89edc1581a57bb15bc160d2353f40a0e"
212997                }
212998              ]
212999            }
213000          ],
213001          "evidence": {},
213002          "signature": {
213003            "signature": {
213004              "publicKey": {}
213005            }
213006          },
213007          "modelCard": {
213008            "modelParameters": {
213009              "approach": {}
213010            },
213011            "quantitativeAnalysis": {
213012              "graphics": {}
213013            },
213014            "considerations": {}
213015          }
213016        },
213017        {
213018          "type": "library",
213019          "bom-ref": "pkg:maven/spring-boot/spring-boot@2.6.2?package-id=15afccdb714652d8",
213020          "supplier": {},
213021          "name": "spring-boot",
213022          "version": "2.6.2",
213023          "cpe": "cpe:2.3:a:spring-boot:spring-boot:2.6.2:*:*:*:*:*:*:*",
213024          "purl": "pkg:maven/spring-boot/spring-boot@2.6.2",
213025          "swid": {
213026            "attachment": {}
213027          },
213028          "pedigree": {},
213029          "externalReferences": [
213030            {
213031              "type": "build-meta",
213032              "hashes": [
213033                {
213034                  "alg": "SHA-1",
213035                  "content": "bbf59f411320da665411692359ff511315d0ff91"
213036                }
213037              ]
213038            }
213039          ],
213040          "evidence": {},
213041          "signature": {
213042            "signature": {
213043              "publicKey": {}
213044            }
213045          },
213046          "modelCard": {
213047            "modelParameters": {
213048              "approach": {}
213049            },
213050            "quantitativeAnalysis": {
213051              "graphics": {}
213052            },
213053            "considerations": {}
213054          }
213055        },
213056        {
213057          "type": "library",
213058          "bom-ref": "pkg:maven/spring-boot-autoconfigure/spring-boot-autoconfigure@2.6.2?package-id=35315b62217fbe06",
213059          "supplier": {},
213060          "name": "spring-boot-autoconfigure",
213061          "version": "2.6.2",
213062          "cpe": "cpe:2.3:a:spring-boot-autoconfigure:spring-boot-autoconfigure:2.6.2:*:*:*:*:*:*:*",
213063          "purl": "pkg:maven/spring-boot-autoconfigure/spring-boot-autoconfigure@2.6.2",
213064          "swid": {
213065            "attachment": {}
213066          },
213067          "pedigree": {},
213068          "externalReferences": [
213069            {
213070              "type": "build-meta",
213071              "hashes": [
213072                {
213073                  "alg": "SHA-1",
213074                  "content": "7c91bce101d3f796cccbc1a6744c1ea389fff73f"
213075                }
213076              ]
213077            }
213078          ],
213079          "evidence": {},
213080          "signature": {
213081            "signature": {
213082              "publicKey": {}
213083            }
213084          },
213085          "modelCard": {
213086            "modelParameters": {
213087              "approach": {}
213088            },
213089            "quantitativeAnalysis": {
213090              "graphics": {}
213091            },
213092            "considerations": {}
213093          }
213094        },
213095        {
213096          "type": "library",
213097          "bom-ref": "pkg:maven/spring-boot-jarmode-layertools/spring-boot-jarmode-layertools@2.6.2?package-id=a6b8639052477852",
213098          "supplier": {},
213099          "name": "spring-boot-jarmode-layertools",
213100          "version": "2.6.2",
213101          "cpe": "cpe:2.3:a:spring-boot-jarmode-layertools:spring-boot-jarmode-layertools:2.6.2:*:*:*:*:*:*:*",
213102          "purl": "pkg:maven/spring-boot-jarmode-layertools/spring-boot-jarmode-layertools@2.6.2",
213103          "swid": {
213104            "attachment": {}
213105          },
213106          "pedigree": {},
213107          "externalReferences": [
213108            {
213109              "type": "build-meta",
213110              "hashes": [
213111                {
213112                  "alg": "SHA-1",
213113                  "content": "95f8a94acad93228895242b0bd5fa97e85529fd6"
213114                }
213115              ]
213116            }
213117          ],
213118          "evidence": {},
213119          "signature": {
213120            "signature": {
213121              "publicKey": {}
213122            }
213123          },
213124          "modelCard": {
213125            "modelParameters": {
213126              "approach": {}
213127            },
213128            "quantitativeAnalysis": {
213129              "graphics": {}
213130            },
213131            "considerations": {}
213132          }
213133        },
213134        {
213135          "type": "library",
213136          "bom-ref": "pkg:maven/spring-context/spring-context@5.3.14?package-id=c76f3604469161de",
213137          "supplier": {},
213138          "name": "spring-context",
213139          "version": "5.3.14",
213140          "cpe": "cpe:2.3:a:spring-context:spring-context:5.3.14:*:*:*:*:*:*:*",
213141          "purl": "pkg:maven/spring-context/spring-context@5.3.14",
213142          "swid": {
213143            "attachment": {}
213144          },
213145          "pedigree": {},
213146          "externalReferences": [
213147            {
213148              "type": "build-meta",
213149              "hashes": [
213150                {
213151                  "alg": "SHA-1",
213152                  "content": "ce6042492f042131f602bdc83fcb412b142bdac5"
213153                }
213154              ]
213155            }
213156          ],
213157          "evidence": {},
213158          "signature": {
213159            "signature": {
213160              "publicKey": {}
213161            }
213162          },
213163          "modelCard": {
213164            "modelParameters": {
213165              "approach": {}
213166            },
213167            "quantitativeAnalysis": {
213168              "graphics": {}
213169            },
213170            "considerations": {}
213171          }
213172        },
213173        {
213174          "type": "library",
213175          "bom-ref": "pkg:maven/spring-context-support/spring-context-support@5.3.14?package-id=507d3769f935823",
213176          "supplier": {},
213177          "name": "spring-context-support",
213178          "version": "5.3.14",
213179          "cpe": "cpe:2.3:a:spring-context-support:spring-context-support:5.3.14:*:*:*:*:*:*:*",
213180          "purl": "pkg:maven/spring-context-support/spring-context-support@5.3.14",
213181          "swid": {
213182            "attachment": {}
213183          },
213184          "pedigree": {},
213185          "externalReferences": [
213186            {
213187              "type": "build-meta",
213188              "hashes": [
213189                {
213190                  "alg": "SHA-1",
213191                  "content": "46292d1dbc02a0cc9a7850ec3165084a914da371"
213192                }
213193              ]
213194            }
213195          ],
213196          "evidence": {},
213197          "signature": {
213198            "signature": {
213199              "publicKey": {}
213200            }
213201          },
213202          "modelCard": {
213203            "modelParameters": {
213204              "approach": {}
213205            },
213206            "quantitativeAnalysis": {
213207              "graphics": {}
213208            },
213209            "considerations": {}
213210          }
213211        },
213212        {
213213          "type": "library",
213214          "bom-ref": "pkg:maven/spring-core/spring-core@5.3.14?package-id=82a5ba8580b81e15",
213215          "supplier": {},
213216          "name": "spring-core",
213217          "version": "5.3.14",
213218          "cpe": "cpe:2.3:a:springsource-spring-framework:springsource_spring_framework:5.3.14:*:*:*:*:*:*:*",
213219          "purl": "pkg:maven/spring-core/spring-core@5.3.14",
213220          "swid": {
213221            "attachment": {}
213222          },
213223          "pedigree": {},
213224          "externalReferences": [
213225            {
213226              "type": "build-meta",
213227              "hashes": [
213228                {
213229                  "alg": "SHA-1",
213230                  "content": "d87ad19f9d8b9a3f1a143db5a2be34c61751aaa2"
213231                }
213232              ]
213233            }
213234          ],
213235          "evidence": {},
213236          "signature": {
213237            "signature": {
213238              "publicKey": {}
213239            }
213240          },
213241          "modelCard": {
213242            "modelParameters": {
213243              "approach": {}
213244            },
213245            "quantitativeAnalysis": {
213246              "graphics": {}
213247            },
213248            "considerations": {}
213249          }
213250        },
213251        {
213252          "type": "library",
213253          "bom-ref": "pkg:maven/spring-expression/spring-expression@5.3.14?package-id=bb99db503aa6ef03",
213254          "supplier": {},
213255          "name": "spring-expression",
213256          "version": "5.3.14",
213257          "cpe": "cpe:2.3:a:spring-expression:spring-expression:5.3.14:*:*:*:*:*:*:*",
213258          "purl": "pkg:maven/spring-expression/spring-expression@5.3.14",
213259          "swid": {
213260            "attachment": {}
213261          },
213262          "pedigree": {},
213263          "externalReferences": [
213264            {
213265              "type": "build-meta",
213266              "hashes": [
213267                {
213268                  "alg": "SHA-1",
213269                  "content": "5cd4c568522b7084afac5d2ac6cb945b797b3f16"
213270                }
213271              ]
213272            }
213273          ],
213274          "evidence": {},
213275          "signature": {
213276            "signature": {
213277              "publicKey": {}
213278            }
213279          },
213280          "modelCard": {
213281            "modelParameters": {
213282              "approach": {}
213283            },
213284            "quantitativeAnalysis": {
213285              "graphics": {}
213286            },
213287            "considerations": {}
213288          }
213289        },
213290        {
213291          "type": "library",
213292          "bom-ref": "pkg:maven/spring-jcl/spring-jcl@5.3.14?package-id=6c6336b885ac413d",
213293          "supplier": {},
213294          "name": "spring-jcl",
213295          "version": "5.3.14",
213296          "cpe": "cpe:2.3:a:spring-jcl:spring-jcl:5.3.14:*:*:*:*:*:*:*",
213297          "purl": "pkg:maven/spring-jcl/spring-jcl@5.3.14",
213298          "swid": {
213299            "attachment": {}
213300          },
213301          "pedigree": {},
213302          "externalReferences": [
213303            {
213304              "type": "build-meta",
213305              "hashes": [
213306                {
213307                  "alg": "SHA-1",
213308                  "content": "ffcf745ed5ba32930771378316fd08e97986bec2"
213309                }
213310              ]
213311            }
213312          ],
213313          "evidence": {},
213314          "signature": {
213315            "signature": {
213316              "publicKey": {}
213317            }
213318          },
213319          "modelCard": {
213320            "modelParameters": {
213321              "approach": {}
213322            },
213323            "quantitativeAnalysis": {
213324              "graphics": {}
213325            },
213326            "considerations": {}
213327          }
213328        },
213329        {
213330          "type": "library",
213331          "bom-ref": "pkg:maven/spring-tx/spring-tx@5.3.14?package-id=d53221eed4fc721f",
213332          "supplier": {},
213333          "name": "spring-tx",
213334          "version": "5.3.14",
213335          "cpe": "cpe:2.3:a:spring-tx:spring-tx:5.3.14:*:*:*:*:*:*:*",
213336          "purl": "pkg:maven/spring-tx/spring-tx@5.3.14",
213337          "swid": {
213338            "attachment": {}
213339          },
213340          "pedigree": {},
213341          "externalReferences": [
213342            {
213343              "type": "build-meta",
213344              "hashes": [
213345                {
213346                  "alg": "SHA-1",
213347                  "content": "03d80a1e051f071e9cd42fc99698bf9022862b5c"
213348                }
213349              ]
213350            }
213351          ],
213352          "evidence": {},
213353          "signature": {
213354            "signature": {
213355              "publicKey": {}
213356            }
213357          },
213358          "modelCard": {
213359            "modelParameters": {
213360              "approach": {}
213361            },
213362            "quantitativeAnalysis": {
213363              "graphics": {}
213364            },
213365            "considerations": {}
213366          }
213367        },
213368        {
213369          "type": "library",
213370          "bom-ref": "pkg:apk/alpine/ssl_client@1.33.1-r2?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.14.0\u0026package-id=aadfbe26e0e8c00d",
213371          "supplier": {},
213372          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
213373          "name": "ssl_client",
213374          "version": "1.33.1-r2",
213375          "description": "EXternal ssl_client for busybox wget",
213376          "licenses": [
213377            {
213378              "license": {
213379                "id": "GPL-2.0-only"
213380              }
213381            }
213382          ],
213383          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.33.1-r2:*:*:*:*:*:*:*",
213384          "purl": "pkg:apk/alpine/ssl_client@1.33.1-r2?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.14.0",
213385          "swid": {
213386            "attachment": {}
213387          },
213388          "pedigree": {},
213389          "externalReferences": [
213390            {
213391              "url": "https://busybox.net/",
213392              "type": "distribution"
213393            }
213394          ],
213395          "evidence": {},
213396          "signature": {
213397            "signature": {
213398              "publicKey": {}
213399            }
213400          },
213401          "modelCard": {
213402            "modelParameters": {
213403              "approach": {}
213404            },
213405            "quantitativeAnalysis": {
213406              "graphics": {}
213407            },
213408            "considerations": {}
213409          }
213410        },
213411        {
213412          "type": "library",
213413          "bom-ref": "pkg:apk/alpine/ssl_client@1.33.1-r8?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.14.0\u0026package-id=3bf185518fada134",
213414          "supplier": {},
213415          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
213416          "name": "ssl_client",
213417          "version": "1.33.1-r8",
213418          "description": "EXternal ssl_client for busybox wget",
213419          "licenses": [
213420            {
213421              "license": {
213422                "id": "GPL-2.0-only"
213423              }
213424            }
213425          ],
213426          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.33.1-r8:*:*:*:*:*:*:*",
213427          "purl": "pkg:apk/alpine/ssl_client@1.33.1-r8?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.14.0",
213428          "swid": {
213429            "attachment": {}
213430          },
213431          "pedigree": {},
213432          "externalReferences": [
213433            {
213434              "url": "https://busybox.net/",
213435              "type": "distribution"
213436            }
213437          ],
213438          "evidence": {},
213439          "signature": {
213440            "signature": {
213441              "publicKey": {}
213442            }
213443          },
213444          "modelCard": {
213445            "modelParameters": {
213446              "approach": {}
213447            },
213448            "quantitativeAnalysis": {
213449              "graphics": {}
213450            },
213451            "considerations": {}
213452          }
213453        },
213454        {
213455          "type": "library",
213456          "bom-ref": "pkg:maven/org.jvnet/tiger-types@1.4?package-id=49d81aafceedc7c1",
213457          "supplier": {},
213458          "group": "org.jvnet",
213459          "name": "tiger-types",
213460          "version": "1.4",
213461          "cpe": "cpe:2.3:a:tiger-types:tiger-types:1.4:*:*:*:*:*:*:*",
213462          "purl": "pkg:maven/org.jvnet/tiger-types@1.4",
213463          "swid": {
213464            "attachment": {}
213465          },
213466          "pedigree": {},
213467          "evidence": {},
213468          "signature": {
213469            "signature": {
213470              "publicKey": {}
213471            }
213472          },
213473          "modelCard": {
213474            "modelParameters": {
213475              "approach": {}
213476            },
213477            "quantitativeAnalysis": {
213478              "graphics": {}
213479            },
213480            "considerations": {}
213481          }
213482        },
213483        {
213484          "type": "library",
213485          "bom-ref": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=3b72ad1745a99acd",
213486          "supplier": {},
213487          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
213488          "name": "zlib",
213489          "version": "1.2.11-r3",
213490          "description": "A compression/decompression Library",
213491          "licenses": [
213492            {
213493              "license": {
213494                "id": "Zlib"
213495              }
213496            }
213497          ],
213498          "cpe": "cpe:2.3:a:zlib:zlib:1.2.11-r3:*:*:*:*:*:*:*",
213499          "purl": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.14.0",
213500          "swid": {
213501            "attachment": {}
213502          },
213503          "pedigree": {},
213504          "externalReferences": [
213505            {
213506              "url": "https://zlib.net/",
213507              "type": "distribution"
213508            }
213509          ],
213510          "evidence": {},
213511          "signature": {
213512            "signature": {
213513              "publicKey": {}
213514            }
213515          },
213516          "modelCard": {
213517            "modelParameters": {
213518              "approach": {}
213519            },
213520            "quantitativeAnalysis": {
213521              "graphics": {}
213522            },
213523            "considerations": {}
213524          }
213525        },
213526        {
213527          "type": "library",
213528          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.14.0\u0026package-id=ff5aaa577609e046",
213529          "supplier": {},
213530          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
213531          "name": "zlib",
213532          "version": "1.2.12-r3",
213533          "description": "A compression/decompression Library",
213534          "licenses": [
213535            {
213536              "license": {
213537                "id": "Zlib"
213538              }
213539            }
213540          ],
213541          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
213542          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.14.0",
213543          "swid": {
213544            "attachment": {}
213545          },
213546          "pedigree": {},
213547          "externalReferences": [
213548            {
213549              "url": "https://zlib.net/",
213550              "type": "distribution"
213551            }
213552          ],
213553          "evidence": {},
213554          "signature": {
213555            "signature": {
213556              "publicKey": {}
213557            }
213558          },
213559          "modelCard": {
213560            "modelParameters": {
213561              "approach": {}
213562            },
213563            "quantitativeAnalysis": {
213564              "graphics": {}
213565            },
213566            "considerations": {}
213567          }
213568        },
213569        {
213570          "type": "operating-system",
213571          "supplier": {},
213572          "name": "alpine",
213573          "version": "3.14.0",
213574          "description": "Alpine Linux v3.14",
213575          "swid": {
213576            "tagId": "alpine",
213577            "name": "alpine",
213578            "version": "3.14.0",
213579            "attachment": {}
213580          },
213581          "pedigree": {},
213582          "externalReferences": [
213583            {
213584              "url": "https://bugs.alpinelinux.org/",
213585              "type": "issue-tracker"
213586            },
213587            {
213588              "url": "https://alpinelinux.org/",
213589              "type": "website"
213590            }
213591          ],
213592          "evidence": {},
213593          "signature": {
213594            "signature": {
213595              "publicKey": {}
213596            }
213597          },
213598          "modelCard": {
213599            "modelParameters": {
213600              "approach": {}
213601            },
213602            "quantitativeAnalysis": {
213603              "graphics": {}
213604            },
213605            "considerations": {}
213606          }
213607        },
213608        {
213609          "type": "library",
213610          "bom-ref": "pkg:npm/%40azure/abort-controller@1.1.0?package-id=11423cec834cf110",
213611          "supplier": {},
213612          "name": "@azure/abort-controller",
213613          "version": "1.1.0",
213614          "licenses": [
213615            {
213616              "license": {
213617                "id": "MIT"
213618              }
213619            }
213620          ],
213621          "cpe": "cpe:2.3:a:\\@azure\\/abort-controller:\\@azure\\/abort-controller:1.1.0:*:*:*:*:*:*:*",
213622          "purl": "pkg:npm/%40azure/abort-controller@1.1.0",
213623          "swid": {
213624            "attachment": {}
213625          },
213626          "pedigree": {},
213627          "evidence": {},
213628          "signature": {
213629            "signature": {
213630              "publicKey": {}
213631            }
213632          },
213633          "modelCard": {
213634            "modelParameters": {
213635              "approach": {}
213636            },
213637            "quantitativeAnalysis": {
213638              "graphics": {}
213639            },
213640            "considerations": {}
213641          }
213642        },
213643        {
213644          "type": "library",
213645          "bom-ref": "pkg:npm/%40azure/core-auth@1.4.0?package-id=2506dc6455323255",
213646          "supplier": {},
213647          "name": "@azure/core-auth",
213648          "version": "1.4.0",
213649          "licenses": [
213650            {
213651              "license": {
213652                "id": "MIT"
213653              }
213654            }
213655          ],
213656          "cpe": "cpe:2.3:a:\\@azure\\/core-auth:\\@azure\\/core-auth:1.4.0:*:*:*:*:*:*:*",
213657          "purl": "pkg:npm/%40azure/core-auth@1.4.0",
213658          "swid": {
213659            "attachment": {}
213660          },
213661          "pedigree": {},
213662          "evidence": {},
213663          "signature": {
213664            "signature": {
213665              "publicKey": {}
213666            }
213667          },
213668          "modelCard": {
213669            "modelParameters": {
213670              "approach": {}
213671            },
213672            "quantitativeAnalysis": {
213673              "graphics": {}
213674            },
213675            "considerations": {}
213676          }
213677        },
213678        {
213679          "type": "library",
213680          "bom-ref": "pkg:npm/%40azure/core-client@1.7.2?package-id=9ddd7665128ccdfb",
213681          "supplier": {},
213682          "name": "@azure/core-client",
213683          "version": "1.7.2",
213684          "licenses": [
213685            {
213686              "license": {
213687                "id": "MIT"
213688              }
213689            }
213690          ],
213691          "cpe": "cpe:2.3:a:\\@azure\\/core-client:\\@azure\\/core-client:1.7.2:*:*:*:*:*:*:*",
213692          "purl": "pkg:npm/%40azure/core-client@1.7.2",
213693          "swid": {
213694            "attachment": {}
213695          },
213696          "pedigree": {},
213697          "evidence": {},
213698          "signature": {
213699            "signature": {
213700              "publicKey": {}
213701            }
213702          },
213703          "modelCard": {
213704            "modelParameters": {
213705              "approach": {}
213706            },
213707            "quantitativeAnalysis": {
213708              "graphics": {}
213709            },
213710            "considerations": {}
213711          }
213712        },
213713        {
213714          "type": "library",
213715          "bom-ref": "pkg:npm/%40azure/core-http-compat@1.3.0?package-id=646436aa651ad071",
213716          "supplier": {},
213717          "name": "@azure/core-http-compat",
213718          "version": "1.3.0",
213719          "licenses": [
213720            {
213721              "license": {
213722                "id": "MIT"
213723              }
213724            }
213725          ],
213726          "cpe": "cpe:2.3:a:\\@azure\\/core-http-compat:\\@azure\\/core-http-compat:1.3.0:*:*:*:*:*:*:*",
213727          "purl": "pkg:npm/%40azure/core-http-compat@1.3.0",
213728          "swid": {
213729            "attachment": {}
213730          },
213731          "pedigree": {},
213732          "evidence": {},
213733          "signature": {
213734            "signature": {
213735              "publicKey": {}
213736            }
213737          },
213738          "modelCard": {
213739            "modelParameters": {
213740              "approach": {}
213741            },
213742            "quantitativeAnalysis": {
213743              "graphics": {}
213744            },
213745            "considerations": {}
213746          }
213747        },
213748        {
213749          "type": "library",
213750          "bom-ref": "pkg:npm/%40azure/core-lro@2.5.2?package-id=14c64e99ba30e9d3",
213751          "supplier": {},
213752          "name": "@azure/core-lro",
213753          "version": "2.5.2",
213754          "licenses": [
213755            {
213756              "license": {
213757                "id": "MIT"
213758              }
213759            }
213760          ],
213761          "cpe": "cpe:2.3:a:\\@azure\\/core-lro:\\@azure\\/core-lro:2.5.2:*:*:*:*:*:*:*",
213762          "purl": "pkg:npm/%40azure/core-lro@2.5.2",
213763          "swid": {
213764            "attachment": {}
213765          },
213766          "pedigree": {},
213767          "evidence": {},
213768          "signature": {
213769            "signature": {
213770              "publicKey": {}
213771            }
213772          },
213773          "modelCard": {
213774            "modelParameters": {
213775              "approach": {}
213776            },
213777            "quantitativeAnalysis": {
213778              "graphics": {}
213779            },
213780            "considerations": {}
213781          }
213782        },
213783        {
213784          "type": "library",
213785          "bom-ref": "pkg:npm/%40azure/core-paging@1.5.0?package-id=2041f5c065ffe83d",
213786          "supplier": {},
213787          "name": "@azure/core-paging",
213788          "version": "1.5.0",
213789          "licenses": [
213790            {
213791              "license": {
213792                "id": "MIT"
213793              }
213794            }
213795          ],
213796          "cpe": "cpe:2.3:a:\\@azure\\/core-paging:\\@azure\\/core-paging:1.5.0:*:*:*:*:*:*:*",
213797          "purl": "pkg:npm/%40azure/core-paging@1.5.0",
213798          "swid": {
213799            "attachment": {}
213800          },
213801          "pedigree": {},
213802          "evidence": {},
213803          "signature": {
213804            "signature": {
213805              "publicKey": {}
213806            }
213807          },
213808          "modelCard": {
213809            "modelParameters": {
213810              "approach": {}
213811            },
213812            "quantitativeAnalysis": {
213813              "graphics": {}
213814            },
213815            "considerations": {}
213816          }
213817        },
213818        {
213819          "type": "library",
213820          "bom-ref": "pkg:npm/%40azure/core-rest-pipeline@1.10.3?package-id=3a380141c5a2bf50",
213821          "supplier": {},
213822          "name": "@azure/core-rest-pipeline",
213823          "version": "1.10.3",
213824          "licenses": [
213825            {
213826              "license": {
213827                "id": "MIT"
213828              }
213829            }
213830          ],
213831          "cpe": "cpe:2.3:a:\\@azure\\/core-rest-pipeline:\\@azure\\/core-rest-pipeline:1.10.3:*:*:*:*:*:*:*",
213832          "purl": "pkg:npm/%40azure/core-rest-pipeline@1.10.3",
213833          "swid": {
213834            "attachment": {}
213835          },
213836          "pedigree": {},
213837          "evidence": {},
213838          "signature": {
213839            "signature": {
213840              "publicKey": {}
213841            }
213842          },
213843          "modelCard": {
213844            "modelParameters": {
213845              "approach": {}
213846            },
213847            "quantitativeAnalysis": {
213848              "graphics": {}
213849            },
213850            "considerations": {}
213851          }
213852        },
213853        {
213854          "type": "library",
213855          "bom-ref": "pkg:npm/%40azure/core-tracing@1.0.0-preview.12?package-id=b096e397ce2d81ff",
213856          "supplier": {},
213857          "name": "@azure/core-tracing",
213858          "version": "1.0.0-preview.12",
213859          "licenses": [
213860            {
213861              "license": {
213862                "id": "MIT"
213863              }
213864            }
213865          ],
213866          "cpe": "cpe:2.3:a:\\@azure\\/core-tracing:\\@azure\\/core-tracing:1.0.0-preview.12:*:*:*:*:*:*:*",
213867          "purl": "pkg:npm/%40azure/core-tracing@1.0.0-preview.12",
213868          "swid": {
213869            "attachment": {}
213870          },
213871          "pedigree": {},
213872          "evidence": {},
213873          "signature": {
213874            "signature": {
213875              "publicKey": {}
213876            }
213877          },
213878          "modelCard": {
213879            "modelParameters": {
213880              "approach": {}
213881            },
213882            "quantitativeAnalysis": {
213883              "graphics": {}
213884            },
213885            "considerations": {}
213886          }
213887        },
213888        {
213889          "type": "library",
213890          "bom-ref": "pkg:npm/%40azure/core-util@1.3.1?package-id=91868b86ed729c99",
213891          "supplier": {},
213892          "name": "@azure/core-util",
213893          "version": "1.3.1",
213894          "licenses": [
213895            {
213896              "license": {
213897                "id": "MIT"
213898              }
213899            }
213900          ],
213901          "cpe": "cpe:2.3:a:\\@azure\\/core-util:\\@azure\\/core-util:1.3.1:*:*:*:*:*:*:*",
213902          "purl": "pkg:npm/%40azure/core-util@1.3.1",
213903          "swid": {
213904            "attachment": {}
213905          },
213906          "pedigree": {},
213907          "evidence": {},
213908          "signature": {
213909            "signature": {
213910              "publicKey": {}
213911            }
213912          },
213913          "modelCard": {
213914            "modelParameters": {
213915              "approach": {}
213916            },
213917            "quantitativeAnalysis": {
213918              "graphics": {}
213919            },
213920            "considerations": {}
213921          }
213922        },
213923        {
213924          "type": "library",
213925          "bom-ref": "pkg:npm/%40azure/identity@1.5.2?package-id=224b1dc5564a6f07",
213926          "supplier": {},
213927          "name": "@azure/identity",
213928          "version": "1.5.2",
213929          "licenses": [
213930            {
213931              "license": {
213932                "id": "MIT"
213933              }
213934            }
213935          ],
213936          "cpe": "cpe:2.3:a:\\@azure\\/identity:\\@azure\\/identity:1.5.2:*:*:*:*:*:*:*",
213937          "purl": "pkg:npm/%40azure/identity@1.5.2",
213938          "swid": {
213939            "attachment": {}
213940          },
213941          "pedigree": {},
213942          "evidence": {},
213943          "signature": {
213944            "signature": {
213945              "publicKey": {}
213946            }
213947          },
213948          "modelCard": {
213949            "modelParameters": {
213950              "approach": {}
213951            },
213952            "quantitativeAnalysis": {
213953              "graphics": {}
213954            },
213955            "considerations": {}
213956          }
213957        },
213958        {
213959          "type": "library",
213960          "bom-ref": "pkg:npm/%40azure/keyvault-keys@4.7.0?package-id=aaf9835925fa72c",
213961          "supplier": {},
213962          "name": "@azure/keyvault-keys",
213963          "version": "4.7.0",
213964          "licenses": [
213965            {
213966              "license": {
213967                "id": "MIT"
213968              }
213969            }
213970          ],
213971          "cpe": "cpe:2.3:a:\\@azure\\/keyvault-keys:\\@azure\\/keyvault-keys:4.7.0:*:*:*:*:*:*:*",
213972          "purl": "pkg:npm/%40azure/keyvault-keys@4.7.0",
213973          "swid": {
213974            "attachment": {}
213975          },
213976          "pedigree": {},
213977          "evidence": {},
213978          "signature": {
213979            "signature": {
213980              "publicKey": {}
213981            }
213982          },
213983          "modelCard": {
213984            "modelParameters": {
213985              "approach": {}
213986            },
213987            "quantitativeAnalysis": {
213988              "graphics": {}
213989            },
213990            "considerations": {}
213991          }
213992        },
213993        {
213994          "type": "library",
213995          "bom-ref": "pkg:npm/%40azure/logger@1.0.4?package-id=651d30b616ff78f3",
213996          "supplier": {},
213997          "name": "@azure/logger",
213998          "version": "1.0.4",
213999          "licenses": [
214000            {
214001              "license": {
214002                "id": "MIT"
214003              }
214004            }
214005          ],
214006          "cpe": "cpe:2.3:a:\\@azure\\/logger:\\@azure\\/logger:1.0.4:*:*:*:*:*:*:*",
214007          "purl": "pkg:npm/%40azure/logger@1.0.4",
214008          "swid": {
214009            "attachment": {}
214010          },
214011          "pedigree": {},
214012          "evidence": {},
214013          "signature": {
214014            "signature": {
214015              "publicKey": {}
214016            }
214017          },
214018          "modelCard": {
214019            "modelParameters": {
214020              "approach": {}
214021            },
214022            "quantitativeAnalysis": {
214023              "graphics": {}
214024            },
214025            "considerations": {}
214026          }
214027        },
214028        {
214029          "type": "library",
214030          "bom-ref": "pkg:npm/%40azure/ms-rest-azure-env@2.0.0?package-id=d930d660843037c4",
214031          "supplier": {},
214032          "name": "@azure/ms-rest-azure-env",
214033          "version": "2.0.0",
214034          "licenses": [
214035            {
214036              "license": {
214037                "id": "MIT"
214038              }
214039            }
214040          ],
214041          "cpe": "cpe:2.3:a:\\@azure\\/ms-rest-azure-env:\\@azure\\/ms-rest-azure-env:2.0.0:*:*:*:*:*:*:*",
214042          "purl": "pkg:npm/%40azure/ms-rest-azure-env@2.0.0",
214043          "swid": {
214044            "attachment": {}
214045          },
214046          "pedigree": {},
214047          "evidence": {},
214048          "signature": {
214049            "signature": {
214050              "publicKey": {}
214051            }
214052          },
214053          "modelCard": {
214054            "modelParameters": {
214055              "approach": {}
214056            },
214057            "quantitativeAnalysis": {
214058              "graphics": {}
214059            },
214060            "considerations": {}
214061          }
214062        },
214063        {
214064          "type": "library",
214065          "bom-ref": "pkg:npm/%40azure/ms-rest-js@2.6.6?package-id=fe4f0295171d8d64",
214066          "supplier": {},
214067          "name": "@azure/ms-rest-js",
214068          "version": "2.6.6",
214069          "licenses": [
214070            {
214071              "license": {
214072                "id": "MIT"
214073              }
214074            }
214075          ],
214076          "cpe": "cpe:2.3:a:\\@azure\\/ms-rest-js:\\@azure\\/ms-rest-js:2.6.6:*:*:*:*:*:*:*",
214077          "purl": "pkg:npm/%40azure/ms-rest-js@2.6.6",
214078          "swid": {
214079            "attachment": {}
214080          },
214081          "pedigree": {},
214082          "evidence": {},
214083          "signature": {
214084            "signature": {
214085              "publicKey": {}
214086            }
214087          },
214088          "modelCard": {
214089            "modelParameters": {
214090              "approach": {}
214091            },
214092            "quantitativeAnalysis": {
214093              "graphics": {}
214094            },
214095            "considerations": {}
214096          }
214097        },
214098        {
214099          "type": "library",
214100          "bom-ref": "pkg:npm/%40azure/ms-rest-nodeauth@3.1.1?package-id=eab888787c00de5f",
214101          "supplier": {},
214102          "name": "@azure/ms-rest-nodeauth",
214103          "version": "3.1.1",
214104          "licenses": [
214105            {
214106              "license": {
214107                "id": "MIT"
214108              }
214109            }
214110          ],
214111          "cpe": "cpe:2.3:a:\\@azure\\/ms-rest-nodeauth:\\@azure\\/ms-rest-nodeauth:3.1.1:*:*:*:*:*:*:*",
214112          "purl": "pkg:npm/%40azure/ms-rest-nodeauth@3.1.1",
214113          "swid": {
214114            "attachment": {}
214115          },
214116          "pedigree": {},
214117          "evidence": {},
214118          "signature": {
214119            "signature": {
214120              "publicKey": {}
214121            }
214122          },
214123          "modelCard": {
214124            "modelParameters": {
214125              "approach": {}
214126            },
214127            "quantitativeAnalysis": {
214128              "graphics": {}
214129            },
214130            "considerations": {}
214131          }
214132        },
214133        {
214134          "type": "library",
214135          "bom-ref": "pkg:npm/%40azure/msal-common@4.5.1?package-id=8f6cb77bfb24c078",
214136          "supplier": {},
214137          "name": "@azure/msal-common",
214138          "version": "4.5.1",
214139          "licenses": [
214140            {
214141              "license": {
214142                "id": "MIT"
214143              }
214144            }
214145          ],
214146          "cpe": "cpe:2.3:a:\\@azure\\/msal-common:\\@azure\\/msal-common:4.5.1:*:*:*:*:*:*:*",
214147          "purl": "pkg:npm/%40azure/msal-common@4.5.1",
214148          "swid": {
214149            "attachment": {}
214150          },
214151          "pedigree": {},
214152          "evidence": {},
214153          "signature": {
214154            "signature": {
214155              "publicKey": {}
214156            }
214157          },
214158          "modelCard": {
214159            "modelParameters": {
214160              "approach": {}
214161            },
214162            "quantitativeAnalysis": {
214163              "graphics": {}
214164            },
214165            "considerations": {}
214166          }
214167        },
214168        {
214169          "type": "library",
214170          "bom-ref": "pkg:npm/%40azure/msal-node@1.0.0-beta.6?package-id=f6983ff1fffffbc7",
214171          "supplier": {},
214172          "name": "@azure/msal-node",
214173          "version": "1.0.0-beta.6",
214174          "licenses": [
214175            {
214176              "license": {
214177                "id": "MIT"
214178              }
214179            }
214180          ],
214181          "cpe": "cpe:2.3:a:\\@azure\\/msal-node:\\@azure\\/msal-node:1.0.0-beta.6:*:*:*:*:*:*:*",
214182          "purl": "pkg:npm/%40azure/msal-node@1.0.0-beta.6",
214183          "swid": {
214184            "attachment": {}
214185          },
214186          "pedigree": {},
214187          "evidence": {},
214188          "signature": {
214189            "signature": {
214190              "publicKey": {}
214191            }
214192          },
214193          "modelCard": {
214194            "modelParameters": {
214195              "approach": {}
214196            },
214197            "quantitativeAnalysis": {
214198              "graphics": {}
214199            },
214200            "considerations": {}
214201          }
214202        },
214203        {
214204          "type": "library",
214205          "bom-ref": "pkg:npm/%40fast-csv/format@4.3.5?package-id=d7bbf57d1524f794",
214206          "supplier": {},
214207          "name": "@fast-csv/format",
214208          "version": "4.3.5",
214209          "licenses": [
214210            {
214211              "license": {
214212                "id": "MIT"
214213              }
214214            }
214215          ],
214216          "cpe": "cpe:2.3:a:\\@fast-csv\\/format:\\@fast-csv\\/format:4.3.5:*:*:*:*:*:*:*",
214217          "purl": "pkg:npm/%40fast-csv/format@4.3.5",
214218          "swid": {
214219            "attachment": {}
214220          },
214221          "pedigree": {},
214222          "evidence": {},
214223          "signature": {
214224            "signature": {
214225              "publicKey": {}
214226            }
214227          },
214228          "modelCard": {
214229            "modelParameters": {
214230              "approach": {}
214231            },
214232            "quantitativeAnalysis": {
214233              "graphics": {}
214234            },
214235            "considerations": {}
214236          }
214237        },
214238        {
214239          "type": "library",
214240          "bom-ref": "pkg:npm/%40fast-csv/parse@4.3.6?package-id=a988c43ba1ede232",
214241          "supplier": {},
214242          "name": "@fast-csv/parse",
214243          "version": "4.3.6",
214244          "licenses": [
214245            {
214246              "license": {
214247                "id": "MIT"
214248              }
214249            }
214250          ],
214251          "cpe": "cpe:2.3:a:\\@fast-csv\\/parse:\\@fast-csv\\/parse:4.3.6:*:*:*:*:*:*:*",
214252          "purl": "pkg:npm/%40fast-csv/parse@4.3.6",
214253          "swid": {
214254            "attachment": {}
214255          },
214256          "pedigree": {},
214257          "evidence": {},
214258          "signature": {
214259            "signature": {
214260              "publicKey": {}
214261            }
214262          },
214263          "modelCard": {
214264            "modelParameters": {
214265              "approach": {}
214266            },
214267            "quantitativeAnalysis": {
214268              "graphics": {}
214269            },
214270            "considerations": {}
214271          }
214272        },
214273        {
214274          "type": "library",
214275          "bom-ref": "pkg:npm/%40hapi/hoek@9.3.0?package-id=dfc7ed4b61f06d8c",
214276          "supplier": {},
214277          "name": "@hapi/hoek",
214278          "version": "9.3.0",
214279          "licenses": [
214280            {
214281              "license": {
214282                "id": "BSD-3-Clause"
214283              }
214284            }
214285          ],
214286          "cpe": "cpe:2.3:a:\\@hapi\\/hoek:\\@hapi\\/hoek:9.3.0:*:*:*:*:*:*:*",
214287          "purl": "pkg:npm/%40hapi/hoek@9.3.0",
214288          "swid": {
214289            "attachment": {}
214290          },
214291          "pedigree": {},
214292          "evidence": {},
214293          "signature": {
214294            "signature": {
214295              "publicKey": {}
214296            }
214297          },
214298          "modelCard": {
214299            "modelParameters": {
214300              "approach": {}
214301            },
214302            "quantitativeAnalysis": {
214303              "graphics": {}
214304            },
214305            "considerations": {}
214306          }
214307        },
214308        {
214309          "type": "library",
214310          "bom-ref": "pkg:npm/%40hapi/topo@5.1.0?package-id=cb0bbf80daabb466",
214311          "supplier": {},
214312          "name": "@hapi/topo",
214313          "version": "5.1.0",
214314          "licenses": [
214315            {
214316              "license": {
214317                "id": "BSD-3-Clause"
214318              }
214319            }
214320          ],
214321          "cpe": "cpe:2.3:a:\\@hapi\\/topo:\\@hapi\\/topo:5.1.0:*:*:*:*:*:*:*",
214322          "purl": "pkg:npm/%40hapi/topo@5.1.0",
214323          "swid": {
214324            "attachment": {}
214325          },
214326          "pedigree": {},
214327          "evidence": {},
214328          "signature": {
214329            "signature": {
214330              "publicKey": {}
214331            }
214332          },
214333          "modelCard": {
214334            "modelParameters": {
214335              "approach": {}
214336            },
214337            "quantitativeAnalysis": {
214338              "graphics": {}
214339            },
214340            "considerations": {}
214341          }
214342        },
214343        {
214344          "type": "library",
214345          "bom-ref": "pkg:npm/%40js-joda/core@3.2.0?package-id=67b3b2f65b07adab",
214346          "supplier": {},
214347          "name": "@js-joda/core",
214348          "version": "3.2.0",
214349          "licenses": [
214350            {
214351              "license": {
214352                "id": "BSD-3-Clause"
214353              }
214354            }
214355          ],
214356          "cpe": "cpe:2.3:a:\\@js-joda\\/core:\\@js-joda\\/core:3.2.0:*:*:*:*:*:*:*",
214357          "purl": "pkg:npm/%40js-joda/core@3.2.0",
214358          "swid": {
214359            "attachment": {}
214360          },
214361          "pedigree": {},
214362          "evidence": {},
214363          "signature": {
214364            "signature": {
214365              "publicKey": {}
214366            }
214367          },
214368          "modelCard": {
214369            "modelParameters": {
214370              "approach": {}
214371            },
214372            "quantitativeAnalysis": {
214373              "graphics": {}
214374            },
214375            "considerations": {}
214376          }
214377        },
214378        {
214379          "type": "library",
214380          "bom-ref": "pkg:npm/%40opentelemetry/api@1.4.1?package-id=593eeeea33422937",
214381          "supplier": {},
214382          "name": "@opentelemetry/api",
214383          "version": "1.4.1",
214384          "licenses": [
214385            {
214386              "license": {
214387                "id": "Apache-2.0"
214388              }
214389            }
214390          ],
214391          "cpe": "cpe:2.3:a:\\@opentelemetry\\/api:\\@opentelemetry\\/api:1.4.1:*:*:*:*:*:*:*",
214392          "purl": "pkg:npm/%40opentelemetry/api@1.4.1",
214393          "swid": {
214394            "attachment": {}
214395          },
214396          "pedigree": {},
214397          "evidence": {},
214398          "signature": {
214399            "signature": {
214400              "publicKey": {}
214401            }
214402          },
214403          "modelCard": {
214404            "modelParameters": {
214405              "approach": {}
214406            },
214407            "quantitativeAnalysis": {
214408              "graphics": {}
214409            },
214410            "considerations": {}
214411          }
214412        },
214413        {
214414          "type": "library",
214415          "bom-ref": "pkg:npm/%40panva/asn1.js@1.0.0?package-id=c8e65302abe99479",
214416          "supplier": {},
214417          "name": "@panva/asn1.js",
214418          "version": "1.0.0",
214419          "licenses": [
214420            {
214421              "license": {
214422                "id": "MIT"
214423              }
214424            }
214425          ],
214426          "cpe": "cpe:2.3:a:\\@panva\\/asn1.js:\\@panva\\/asn1.js:1.0.0:*:*:*:*:*:*:*",
214427          "purl": "pkg:npm/%40panva/asn1.js@1.0.0",
214428          "swid": {
214429            "attachment": {}
214430          },
214431          "pedigree": {},
214432          "evidence": {},
214433          "signature": {
214434            "signature": {
214435              "publicKey": {}
214436            }
214437          },
214438          "modelCard": {
214439            "modelParameters": {
214440              "approach": {}
214441            },
214442            "quantitativeAnalysis": {
214443              "graphics": {}
214444            },
214445            "considerations": {}
214446          }
214447        },
214448        {
214449          "type": "library",
214450          "bom-ref": "pkg:npm/%40sideway/address@4.1.4?package-id=1ea2eefe06a54f25",
214451          "supplier": {},
214452          "name": "@sideway/address",
214453          "version": "4.1.4",
214454          "licenses": [
214455            {
214456              "license": {
214457                "id": "BSD-3-Clause"
214458              }
214459            }
214460          ],
214461          "cpe": "cpe:2.3:a:\\@sideway\\/address:\\@sideway\\/address:4.1.4:*:*:*:*:*:*:*",
214462          "purl": "pkg:npm/%40sideway/address@4.1.4",
214463          "swid": {
214464            "attachment": {}
214465          },
214466          "pedigree": {},
214467          "evidence": {},
214468          "signature": {
214469            "signature": {
214470              "publicKey": {}
214471            }
214472          },
214473          "modelCard": {
214474            "modelParameters": {
214475              "approach": {}
214476            },
214477            "quantitativeAnalysis": {
214478              "graphics": {}
214479            },
214480            "considerations": {}
214481          }
214482        },
214483        {
214484          "type": "library",
214485          "bom-ref": "pkg:npm/%40sideway/formula@3.0.1?package-id=e81f1bea574ff974",
214486          "supplier": {},
214487          "name": "@sideway/formula",
214488          "version": "3.0.1",
214489          "licenses": [
214490            {
214491              "license": {
214492                "id": "BSD-3-Clause"
214493              }
214494            }
214495          ],
214496          "cpe": "cpe:2.3:a:\\@sideway\\/formula:\\@sideway\\/formula:3.0.1:*:*:*:*:*:*:*",
214497          "purl": "pkg:npm/%40sideway/formula@3.0.1",
214498          "swid": {
214499            "attachment": {}
214500          },
214501          "pedigree": {},
214502          "evidence": {},
214503          "signature": {
214504            "signature": {
214505              "publicKey": {}
214506            }
214507          },
214508          "modelCard": {
214509            "modelParameters": {
214510              "approach": {}
214511            },
214512            "quantitativeAnalysis": {
214513              "graphics": {}
214514            },
214515            "considerations": {}
214516          }
214517        },
214518        {
214519          "type": "library",
214520          "bom-ref": "pkg:npm/%40sideway/pinpoint@2.0.0?package-id=f89ae43244c63b1f",
214521          "supplier": {},
214522          "name": "@sideway/pinpoint",
214523          "version": "2.0.0",
214524          "licenses": [
214525            {
214526              "license": {
214527                "id": "BSD-3-Clause"
214528              }
214529            }
214530          ],
214531          "cpe": "cpe:2.3:a:\\@sideway\\/pinpoint:\\@sideway\\/pinpoint:2.0.0:*:*:*:*:*:*:*",
214532          "purl": "pkg:npm/%40sideway/pinpoint@2.0.0",
214533          "swid": {
214534            "attachment": {}
214535          },
214536          "pedigree": {},
214537          "evidence": {},
214538          "signature": {
214539            "signature": {
214540              "publicKey": {}
214541            }
214542          },
214543          "modelCard": {
214544            "modelParameters": {
214545              "approach": {}
214546            },
214547            "quantitativeAnalysis": {
214548              "graphics": {}
214549            },
214550            "considerations": {}
214551          }
214552        },
214553        {
214554          "type": "library",
214555          "bom-ref": "pkg:npm/%40tediousjs/connection-string@0.3.0?package-id=10ad6ff87e2088f5",
214556          "supplier": {},
214557          "name": "@tediousjs/connection-string",
214558          "version": "0.3.0",
214559          "licenses": [
214560            {
214561              "license": {
214562                "id": "MIT"
214563              }
214564            }
214565          ],
214566          "cpe": "cpe:2.3:a:\\@tediousjs\\/connection-string:\\@tediousjs\\/connection-string:0.3.0:*:*:*:*:*:*:*",
214567          "purl": "pkg:npm/%40tediousjs/connection-string@0.3.0",
214568          "swid": {
214569            "attachment": {}
214570          },
214571          "pedigree": {},
214572          "evidence": {},
214573          "signature": {
214574            "signature": {
214575              "publicKey": {}
214576            }
214577          },
214578          "modelCard": {
214579            "modelParameters": {
214580              "approach": {}
214581            },
214582            "quantitativeAnalysis": {
214583              "graphics": {}
214584            },
214585            "considerations": {}
214586          }
214587        },
214588        {
214589          "type": "library",
214590          "bom-ref": "pkg:npm/%40tootallnate/once@2.0.0?package-id=72cdc9bd2ed3fd0f",
214591          "supplier": {},
214592          "name": "@tootallnate/once",
214593          "version": "2.0.0",
214594          "licenses": [
214595            {
214596              "license": {
214597                "id": "MIT"
214598              }
214599            }
214600          ],
214601          "cpe": "cpe:2.3:a:\\@tootallnate\\/once:\\@tootallnate\\/once:2.0.0:*:*:*:*:*:*:*",
214602          "purl": "pkg:npm/%40tootallnate/once@2.0.0",
214603          "swid": {
214604            "attachment": {}
214605          },
214606          "pedigree": {},
214607          "evidence": {},
214608          "signature": {
214609            "signature": {
214610              "publicKey": {}
214611            }
214612          },
214613          "modelCard": {
214614            "modelParameters": {
214615              "approach": {}
214616            },
214617            "quantitativeAnalysis": {
214618              "graphics": {}
214619            },
214620            "considerations": {}
214621          }
214622        },
214623        {
214624          "type": "library",
214625          "bom-ref": "pkg:npm/%40types/body-parser@1.19.2?package-id=6f9a5a97d256a43f",
214626          "supplier": {},
214627          "name": "@types/body-parser",
214628          "version": "1.19.2",
214629          "licenses": [
214630            {
214631              "license": {
214632                "id": "MIT"
214633              }
214634            }
214635          ],
214636          "cpe": "cpe:2.3:a:\\@types\\/body-parser:\\@types\\/body-parser:1.19.2:*:*:*:*:*:*:*",
214637          "purl": "pkg:npm/%40types/body-parser@1.19.2",
214638          "swid": {
214639            "attachment": {}
214640          },
214641          "pedigree": {},
214642          "evidence": {},
214643          "signature": {
214644            "signature": {
214645              "publicKey": {}
214646            }
214647          },
214648          "modelCard": {
214649            "modelParameters": {
214650              "approach": {}
214651            },
214652            "quantitativeAnalysis": {
214653              "graphics": {}
214654            },
214655            "considerations": {}
214656          }
214657        },
214658        {
214659          "type": "library",
214660          "bom-ref": "pkg:npm/%40types/connect@3.4.35?package-id=153356e88e8dda78",
214661          "supplier": {},
214662          "name": "@types/connect",
214663          "version": "3.4.35",
214664          "licenses": [
214665            {
214666              "license": {
214667                "id": "MIT"
214668              }
214669            }
214670          ],
214671          "cpe": "cpe:2.3:a:\\@types\\/connect:\\@types\\/connect:3.4.35:*:*:*:*:*:*:*",
214672          "purl": "pkg:npm/%40types/connect@3.4.35",
214673          "swid": {
214674            "attachment": {}
214675          },
214676          "pedigree": {},
214677          "evidence": {},
214678          "signature": {
214679            "signature": {
214680              "publicKey": {}
214681            }
214682          },
214683          "modelCard": {
214684            "modelParameters": {
214685              "approach": {}
214686            },
214687            "quantitativeAnalysis": {
214688              "graphics": {}
214689            },
214690            "considerations": {}
214691          }
214692        },
214693        {
214694          "type": "library",
214695          "bom-ref": "pkg:npm/%40types/express@4.17.17?package-id=5971111e043e694e",
214696          "supplier": {},
214697          "name": "@types/express",
214698          "version": "4.17.17",
214699          "licenses": [
214700            {
214701              "license": {
214702                "id": "MIT"
214703              }
214704            }
214705          ],
214706          "cpe": "cpe:2.3:a:\\@types\\/express:\\@types\\/express:4.17.17:*:*:*:*:*:*:*",
214707          "purl": "pkg:npm/%40types/express@4.17.17",
214708          "swid": {
214709            "attachment": {}
214710          },
214711          "pedigree": {},
214712          "evidence": {},
214713          "signature": {
214714            "signature": {
214715              "publicKey": {}
214716            }
214717          },
214718          "modelCard": {
214719            "modelParameters": {
214720              "approach": {}
214721            },
214722            "quantitativeAnalysis": {
214723              "graphics": {}
214724            },
214725            "considerations": {}
214726          }
214727        },
214728        {
214729          "type": "library",
214730          "bom-ref": "pkg:npm/%40types/express-serve-static-core@4.17.33?package-id=9dc9470269359489",
214731          "supplier": {},
214732          "name": "@types/express-serve-static-core",
214733          "version": "4.17.33",
214734          "licenses": [
214735            {
214736              "license": {
214737                "id": "MIT"
214738              }
214739            }
214740          ],
214741          "cpe": "cpe:2.3:a:\\@types\\/express-serve-static-core:\\@types\\/express-serve-static-core:4.17.33:*:*:*:*:*:*:*",
214742          "purl": "pkg:npm/%40types/express-serve-static-core@4.17.33",
214743          "swid": {
214744            "attachment": {}
214745          },
214746          "pedigree": {},
214747          "evidence": {},
214748          "signature": {
214749            "signature": {
214750              "publicKey": {}
214751            }
214752          },
214753          "modelCard": {
214754            "modelParameters": {
214755              "approach": {}
214756            },
214757            "quantitativeAnalysis": {
214758              "graphics": {}
214759            },
214760            "considerations": {}
214761          }
214762        },
214763        {
214764          "type": "library",
214765          "bom-ref": "pkg:npm/%40types/jsonwebtoken@8.5.9?package-id=247862396db178a8",
214766          "supplier": {},
214767          "name": "@types/jsonwebtoken",
214768          "version": "8.5.9",
214769          "licenses": [
214770            {
214771              "license": {
214772                "id": "MIT"
214773              }
214774            }
214775          ],
214776          "cpe": "cpe:2.3:a:\\@types\\/jsonwebtoken:\\@types\\/jsonwebtoken:8.5.9:*:*:*:*:*:*:*",
214777          "purl": "pkg:npm/%40types/jsonwebtoken@8.5.9",
214778          "swid": {
214779            "attachment": {}
214780          },
214781          "pedigree": {},
214782          "evidence": {},
214783          "signature": {
214784            "signature": {
214785              "publicKey": {}
214786            }
214787          },
214788          "modelCard": {
214789            "modelParameters": {
214790              "approach": {}
214791            },
214792            "quantitativeAnalysis": {
214793              "graphics": {}
214794            },
214795            "considerations": {}
214796          }
214797        },
214798        {
214799          "type": "library",
214800          "bom-ref": "pkg:npm/%40types/mime@3.0.1?package-id=60c5899602e48814",
214801          "supplier": {},
214802          "name": "@types/mime",
214803          "version": "3.0.1",
214804          "licenses": [
214805            {
214806              "license": {
214807                "id": "MIT"
214808              }
214809            }
214810          ],
214811          "cpe": "cpe:2.3:a:\\@types\\/mime:\\@types\\/mime:3.0.1:*:*:*:*:*:*:*",
214812          "purl": "pkg:npm/%40types/mime@3.0.1",
214813          "swid": {
214814            "attachment": {}
214815          },
214816          "pedigree": {},
214817          "evidence": {},
214818          "signature": {
214819            "signature": {
214820              "publicKey": {}
214821            }
214822          },
214823          "modelCard": {
214824            "modelParameters": {
214825              "approach": {}
214826            },
214827            "quantitativeAnalysis": {
214828              "graphics": {}
214829            },
214830            "considerations": {}
214831          }
214832        },
214833        {
214834          "type": "library",
214835          "bom-ref": "pkg:npm/%40types/node@14.18.42?package-id=6190c1b84651a693",
214836          "supplier": {},
214837          "name": "@types/node",
214838          "version": "14.18.42",
214839          "licenses": [
214840            {
214841              "license": {
214842                "id": "MIT"
214843              }
214844            }
214845          ],
214846          "cpe": "cpe:2.3:a:\\@types\\/node:\\@types\\/node:14.18.42:*:*:*:*:*:*:*",
214847          "purl": "pkg:npm/%40types/node@14.18.42",
214848          "swid": {
214849            "attachment": {}
214850          },
214851          "pedigree": {},
214852          "evidence": {},
214853          "signature": {
214854            "signature": {
214855              "publicKey": {}
214856            }
214857          },
214858          "modelCard": {
214859            "modelParameters": {
214860              "approach": {}
214861            },
214862            "quantitativeAnalysis": {
214863              "graphics": {}
214864            },
214865            "considerations": {}
214866          }
214867        },
214868        {
214869          "type": "library",
214870          "bom-ref": "pkg:npm/%40types/qs@6.9.7?package-id=b72bb411c6c145bc",
214871          "supplier": {},
214872          "name": "@types/qs",
214873          "version": "6.9.7",
214874          "licenses": [
214875            {
214876              "license": {
214877                "id": "MIT"
214878              }
214879            }
214880          ],
214881          "cpe": "cpe:2.3:a:\\@types\\/qs:\\@types\\/qs:6.9.7:*:*:*:*:*:*:*",
214882          "purl": "pkg:npm/%40types/qs@6.9.7",
214883          "swid": {
214884            "attachment": {}
214885          },
214886          "pedigree": {},
214887          "evidence": {},
214888          "signature": {
214889            "signature": {
214890              "publicKey": {}
214891            }
214892          },
214893          "modelCard": {
214894            "modelParameters": {
214895              "approach": {}
214896            },
214897            "quantitativeAnalysis": {
214898              "graphics": {}
214899            },
214900            "considerations": {}
214901          }
214902        },
214903        {
214904          "type": "library",
214905          "bom-ref": "pkg:npm/%40types/range-parser@1.2.4?package-id=b0e966b06d5708ba",
214906          "supplier": {},
214907          "name": "@types/range-parser",
214908          "version": "1.2.4",
214909          "licenses": [
214910            {
214911              "license": {
214912                "id": "MIT"
214913              }
214914            }
214915          ],
214916          "cpe": "cpe:2.3:a:\\@types\\/range-parser:\\@types\\/range-parser:1.2.4:*:*:*:*:*:*:*",
214917          "purl": "pkg:npm/%40types/range-parser@1.2.4",
214918          "swid": {
214919            "attachment": {}
214920          },
214921          "pedigree": {},
214922          "evidence": {},
214923          "signature": {
214924            "signature": {
214925              "publicKey": {}
214926            }
214927          },
214928          "modelCard": {
214929            "modelParameters": {
214930              "approach": {}
214931            },
214932            "quantitativeAnalysis": {
214933              "graphics": {}
214934            },
214935            "considerations": {}
214936          }
214937        },
214938        {
214939          "type": "library",
214940          "bom-ref": "pkg:npm/%40types/serve-static@1.15.1?package-id=968e77e09ffbea88",
214941          "supplier": {},
214942          "name": "@types/serve-static",
214943          "version": "1.15.1",
214944          "licenses": [
214945            {
214946              "license": {
214947                "id": "MIT"
214948              }
214949            }
214950          ],
214951          "cpe": "cpe:2.3:a:\\@types\\/serve-static:\\@types\\/serve-static:1.15.1:*:*:*:*:*:*:*",
214952          "purl": "pkg:npm/%40types/serve-static@1.15.1",
214953          "swid": {
214954            "attachment": {}
214955          },
214956          "pedigree": {},
214957          "evidence": {},
214958          "signature": {
214959            "signature": {
214960              "publicKey": {}
214961            }
214962          },
214963          "modelCard": {
214964            "modelParameters": {
214965              "approach": {}
214966            },
214967            "quantitativeAnalysis": {
214968              "graphics": {}
214969            },
214970            "considerations": {}
214971          }
214972        },
214973        {
214974          "type": "library",
214975          "bom-ref": "pkg:npm/%40types/stoppable@1.1.1?package-id=ffff93d62159b673",
214976          "supplier": {},
214977          "name": "@types/stoppable",
214978          "version": "1.1.1",
214979          "licenses": [
214980            {
214981              "license": {
214982                "id": "MIT"
214983              }
214984            }
214985          ],
214986          "cpe": "cpe:2.3:a:\\@types\\/stoppable:\\@types\\/stoppable:1.1.1:*:*:*:*:*:*:*",
214987          "purl": "pkg:npm/%40types/stoppable@1.1.1",
214988          "swid": {
214989            "attachment": {}
214990          },
214991          "pedigree": {},
214992          "evidence": {},
214993          "signature": {
214994            "signature": {
214995              "publicKey": {}
214996            }
214997          },
214998          "modelCard": {
214999            "modelParameters": {
215000              "approach": {}
215001            },
215002            "quantitativeAnalysis": {
215003              "graphics": {}
215004            },
215005            "considerations": {}
215006          }
215007        },
215008        {
215009          "type": "library",
215010          "bom-ref": "pkg:npm/%40xmldom/xmldom@0.8.7?package-id=70b6e12290b2ea87",
215011          "supplier": {},
215012          "name": "@xmldom/xmldom",
215013          "version": "0.8.7",
215014          "licenses": [
215015            {
215016              "license": {
215017                "id": "MIT"
215018              }
215019            }
215020          ],
215021          "cpe": "cpe:2.3:a:\\@xmldom\\/xmldom:\\@xmldom\\/xmldom:0.8.7:*:*:*:*:*:*:*",
215022          "purl": "pkg:npm/%40xmldom/xmldom@0.8.7",
215023          "swid": {
215024            "attachment": {}
215025          },
215026          "pedigree": {},
215027          "evidence": {},
215028          "signature": {
215029            "signature": {
215030              "publicKey": {}
215031            }
215032          },
215033          "modelCard": {
215034            "modelParameters": {
215035              "approach": {}
215036            },
215037            "quantitativeAnalysis": {
215038              "graphics": {}
215039            },
215040            "considerations": {}
215041          }
215042        },
215043        {
215044          "type": "library",
215045          "bom-ref": "pkg:npm/abort-controller@3.0.0?package-id=2d2118b0a97fb9c7",
215046          "supplier": {},
215047          "name": "abort-controller",
215048          "version": "3.0.0",
215049          "licenses": [
215050            {
215051              "license": {
215052                "id": "MIT"
215053              }
215054            }
215055          ],
215056          "cpe": "cpe:2.3:a:abort-controller:abort-controller:3.0.0:*:*:*:*:*:*:*",
215057          "purl": "pkg:npm/abort-controller@3.0.0",
215058          "swid": {
215059            "attachment": {}
215060          },
215061          "pedigree": {},
215062          "evidence": {},
215063          "signature": {
215064            "signature": {
215065              "publicKey": {}
215066            }
215067          },
215068          "modelCard": {
215069            "modelParameters": {
215070              "approach": {}
215071            },
215072            "quantitativeAnalysis": {
215073              "graphics": {}
215074            },
215075            "considerations": {}
215076          }
215077        },
215078        {
215079          "type": "library",
215080          "bom-ref": "pkg:npm/abstract-logging@2.0.1?package-id=366cc5c49b6b0cf5",
215081          "supplier": {},
215082          "name": "abstract-logging",
215083          "version": "2.0.1",
215084          "licenses": [
215085            {
215086              "license": {
215087                "id": "MIT"
215088              }
215089            }
215090          ],
215091          "cpe": "cpe:2.3:a:abstract-logging:abstract-logging:2.0.1:*:*:*:*:*:*:*",
215092          "purl": "pkg:npm/abstract-logging@2.0.1",
215093          "swid": {
215094            "attachment": {}
215095          },
215096          "pedigree": {},
215097          "evidence": {},
215098          "signature": {
215099            "signature": {
215100              "publicKey": {}
215101            }
215102          },
215103          "modelCard": {
215104            "modelParameters": {
215105              "approach": {}
215106            },
215107            "quantitativeAnalysis": {
215108              "graphics": {}
215109            },
215110            "considerations": {}
215111          }
215112        },
215113        {
215114          "type": "library",
215115          "bom-ref": "pkg:npm/acorn@8.8.2?package-id=4cee9549cfc133a5",
215116          "supplier": {},
215117          "name": "acorn",
215118          "version": "8.8.2",
215119          "licenses": [
215120            {
215121              "license": {
215122                "id": "MIT"
215123              }
215124            }
215125          ],
215126          "cpe": "cpe:2.3:a:acorn:acorn:8.8.2:*:*:*:*:*:*:*",
215127          "purl": "pkg:npm/acorn@8.8.2",
215128          "swid": {
215129            "attachment": {}
215130          },
215131          "pedigree": {},
215132          "evidence": {},
215133          "signature": {
215134            "signature": {
215135              "publicKey": {}
215136            }
215137          },
215138          "modelCard": {
215139            "modelParameters": {
215140              "approach": {}
215141            },
215142            "quantitativeAnalysis": {
215143              "graphics": {}
215144            },
215145            "considerations": {}
215146          }
215147        },
215148        {
215149          "type": "library",
215150          "bom-ref": "pkg:npm/acorn-walk@8.2.0?package-id=a1aa765228bf451f",
215151          "supplier": {},
215152          "name": "acorn-walk",
215153          "version": "8.2.0",
215154          "licenses": [
215155            {
215156              "license": {
215157                "id": "MIT"
215158              }
215159            }
215160          ],
215161          "cpe": "cpe:2.3:a:acorn-walk:acorn-walk:8.2.0:*:*:*:*:*:*:*",
215162          "purl": "pkg:npm/acorn-walk@8.2.0",
215163          "swid": {
215164            "attachment": {}
215165          },
215166          "pedigree": {},
215167          "evidence": {},
215168          "signature": {
215169            "signature": {
215170              "publicKey": {}
215171            }
215172          },
215173          "modelCard": {
215174            "modelParameters": {
215175              "approach": {}
215176            },
215177            "quantitativeAnalysis": {
215178              "graphics": {}
215179            },
215180            "considerations": {}
215181          }
215182        },
215183        {
215184          "type": "library",
215185          "bom-ref": "pkg:npm/adal-node@0.2.4?package-id=93a22c584b592ee2",
215186          "supplier": {},
215187          "name": "adal-node",
215188          "version": "0.2.4",
215189          "licenses": [
215190            {
215191              "license": {
215192                "id": "Apache-2.0"
215193              }
215194            }
215195          ],
215196          "cpe": "cpe:2.3:a:adal-node:adal-node:0.2.4:*:*:*:*:*:*:*",
215197          "purl": "pkg:npm/adal-node@0.2.4",
215198          "swid": {
215199            "attachment": {}
215200          },
215201          "pedigree": {},
215202          "evidence": {},
215203          "signature": {
215204            "signature": {
215205              "publicKey": {}
215206            }
215207          },
215208          "modelCard": {
215209            "modelParameters": {
215210              "approach": {}
215211            },
215212            "quantitativeAnalysis": {
215213              "graphics": {}
215214            },
215215            "considerations": {}
215216          }
215217        },
215218        {
215219          "type": "library",
215220          "bom-ref": "pkg:npm/adm-zip@0.5.10?package-id=c280ef75808fc160",
215221          "supplier": {},
215222          "name": "adm-zip",
215223          "version": "0.5.10",
215224          "licenses": [
215225            {
215226              "license": {
215227                "id": "MIT"
215228              }
215229            }
215230          ],
215231          "cpe": "cpe:2.3:a:adm-zip:adm-zip:0.5.10:*:*:*:*:*:*:*",
215232          "purl": "pkg:npm/adm-zip@0.5.10",
215233          "swid": {
215234            "attachment": {}
215235          },
215236          "pedigree": {},
215237          "evidence": {},
215238          "signature": {
215239            "signature": {
215240              "publicKey": {}
215241            }
215242          },
215243          "modelCard": {
215244            "modelParameters": {
215245              "approach": {}
215246            },
215247            "quantitativeAnalysis": {
215248              "graphics": {}
215249            },
215250            "considerations": {}
215251          }
215252        },
215253        {
215254          "type": "library",
215255          "bom-ref": "pkg:npm/agent-base@6.0.2?package-id=5108dbd3b615483c",
215256          "supplier": {},
215257          "name": "agent-base",
215258          "version": "6.0.2",
215259          "licenses": [
215260            {
215261              "license": {
215262                "id": "MIT"
215263              }
215264            }
215265          ],
215266          "cpe": "cpe:2.3:a:agent-base:agent-base:6.0.2:*:*:*:*:*:*:*",
215267          "purl": "pkg:npm/agent-base@6.0.2",
215268          "swid": {
215269            "attachment": {}
215270          },
215271          "pedigree": {},
215272          "evidence": {},
215273          "signature": {
215274            "signature": {
215275              "publicKey": {}
215276            }
215277          },
215278          "modelCard": {
215279            "modelParameters": {
215280              "approach": {}
215281            },
215282            "quantitativeAnalysis": {
215283              "graphics": {}
215284            },
215285            "considerations": {}
215286          }
215287        },
215288        {
215289          "type": "library",
215290          "bom-ref": "pkg:npm/ajv@6.10.0?package-id=eadf273c9f89d2f8",
215291          "supplier": {},
215292          "name": "ajv",
215293          "version": "6.10.0",
215294          "licenses": [
215295            {
215296              "license": {
215297                "id": "MIT"
215298              }
215299            }
215300          ],
215301          "cpe": "cpe:2.3:a:ajv:ajv:6.10.0:*:*:*:*:*:*:*",
215302          "purl": "pkg:npm/ajv@6.10.0",
215303          "swid": {
215304            "attachment": {}
215305          },
215306          "pedigree": {},
215307          "evidence": {},
215308          "signature": {
215309            "signature": {
215310              "publicKey": {}
215311            }
215312          },
215313          "modelCard": {
215314            "modelParameters": {
215315              "approach": {}
215316            },
215317            "quantitativeAnalysis": {
215318              "graphics": {}
215319            },
215320            "considerations": {}
215321          }
215322        },
215323        {
215324          "type": "library",
215325          "bom-ref": "pkg:npm/amqplib@0.8.0?package-id=ff9e9fce295201c6",
215326          "supplier": {},
215327          "name": "amqplib",
215328          "version": "0.8.0",
215329          "licenses": [
215330            {
215331              "license": {
215332                "id": "MIT"
215333              }
215334            }
215335          ],
215336          "cpe": "cpe:2.3:a:amqplib:amqplib:0.8.0:*:*:*:*:*:*:*",
215337          "purl": "pkg:npm/amqplib@0.8.0",
215338          "swid": {
215339            "attachment": {}
215340          },
215341          "pedigree": {},
215342          "evidence": {},
215343          "signature": {
215344            "signature": {
215345              "publicKey": {}
215346            }
215347          },
215348          "modelCard": {
215349            "modelParameters": {
215350              "approach": {}
215351            },
215352            "quantitativeAnalysis": {
215353              "graphics": {}
215354            },
215355            "considerations": {}
215356          }
215357        },
215358        {
215359          "type": "library",
215360          "bom-ref": "pkg:npm/ansi-regex@3.0.1?package-id=42c9e6d73f370617",
215361          "supplier": {},
215362          "name": "ansi-regex",
215363          "version": "3.0.1",
215364          "licenses": [
215365            {
215366              "license": {
215367                "id": "MIT"
215368              }
215369            }
215370          ],
215371          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:3.0.1:*:*:*:*:*:*:*",
215372          "purl": "pkg:npm/ansi-regex@3.0.1",
215373          "swid": {
215374            "attachment": {}
215375          },
215376          "pedigree": {},
215377          "evidence": {},
215378          "signature": {
215379            "signature": {
215380              "publicKey": {}
215381            }
215382          },
215383          "modelCard": {
215384            "modelParameters": {
215385              "approach": {}
215386            },
215387            "quantitativeAnalysis": {
215388              "graphics": {}
215389            },
215390            "considerations": {}
215391          }
215392        },
215393        {
215394          "type": "library",
215395          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=32a623a574dfd25",
215396          "supplier": {},
215397          "name": "ansi-styles",
215398          "version": "4.3.0",
215399          "licenses": [
215400            {
215401              "license": {
215402                "id": "MIT"
215403              }
215404            }
215405          ],
215406          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
215407          "purl": "pkg:npm/ansi-styles@4.3.0",
215408          "swid": {
215409            "attachment": {}
215410          },
215411          "pedigree": {},
215412          "evidence": {},
215413          "signature": {
215414            "signature": {
215415              "publicKey": {}
215416            }
215417          },
215418          "modelCard": {
215419            "modelParameters": {
215420              "approach": {}
215421            },
215422            "quantitativeAnalysis": {
215423              "graphics": {}
215424            },
215425            "considerations": {}
215426          }
215427        },
215428        {
215429          "type": "library",
215430          "bom-ref": "pkg:npm/archiver@5.3.1?package-id=7d1e6daa01902ab9",
215431          "supplier": {},
215432          "name": "archiver",
215433          "version": "5.3.1",
215434          "licenses": [
215435            {
215436              "license": {
215437                "id": "MIT"
215438              }
215439            }
215440          ],
215441          "cpe": "cpe:2.3:a:archiver:archiver:5.3.1:*:*:*:*:*:*:*",
215442          "purl": "pkg:npm/archiver@5.3.1",
215443          "swid": {
215444            "attachment": {}
215445          },
215446          "pedigree": {},
215447          "evidence": {},
215448          "signature": {
215449            "signature": {
215450              "publicKey": {}
215451            }
215452          },
215453          "modelCard": {
215454            "modelParameters": {
215455              "approach": {}
215456            },
215457            "quantitativeAnalysis": {
215458              "graphics": {}
215459            },
215460            "considerations": {}
215461          }
215462        },
215463        {
215464          "type": "library",
215465          "bom-ref": "pkg:npm/archiver-utils@2.1.0?package-id=fb8748d38a8f9d94",
215466          "supplier": {},
215467          "name": "archiver-utils",
215468          "version": "2.1.0",
215469          "licenses": [
215470            {
215471              "license": {
215472                "id": "MIT"
215473              }
215474            }
215475          ],
215476          "cpe": "cpe:2.3:a:archiver-utils:archiver-utils:2.1.0:*:*:*:*:*:*:*",
215477          "purl": "pkg:npm/archiver-utils@2.1.0",
215478          "swid": {
215479            "attachment": {}
215480          },
215481          "pedigree": {},
215482          "evidence": {},
215483          "signature": {
215484            "signature": {
215485              "publicKey": {}
215486            }
215487          },
215488          "modelCard": {
215489            "modelParameters": {
215490              "approach": {}
215491            },
215492            "quantitativeAnalysis": {
215493              "graphics": {}
215494            },
215495            "considerations": {}
215496          }
215497        },
215498        {
215499          "type": "library",
215500          "bom-ref": "pkg:npm/argparse@1.0.10?package-id=6f7ef639728134c2",
215501          "supplier": {},
215502          "name": "argparse",
215503          "version": "1.0.10",
215504          "licenses": [
215505            {
215506              "license": {
215507                "id": "MIT"
215508              }
215509            }
215510          ],
215511          "cpe": "cpe:2.3:a:argparse:argparse:1.0.10:*:*:*:*:*:*:*",
215512          "purl": "pkg:npm/argparse@1.0.10",
215513          "swid": {
215514            "attachment": {}
215515          },
215516          "pedigree": {},
215517          "evidence": {},
215518          "signature": {
215519            "signature": {
215520              "publicKey": {}
215521            }
215522          },
215523          "modelCard": {
215524            "modelParameters": {
215525              "approach": {}
215526            },
215527            "quantitativeAnalysis": {
215528              "graphics": {}
215529            },
215530            "considerations": {}
215531          }
215532        },
215533        {
215534          "type": "library",
215535          "bom-ref": "pkg:npm/arrify@2.0.1?package-id=173785c10c13c86",
215536          "supplier": {},
215537          "name": "arrify",
215538          "version": "2.0.1",
215539          "licenses": [
215540            {
215541              "license": {
215542                "id": "MIT"
215543              }
215544            }
215545          ],
215546          "cpe": "cpe:2.3:a:arrify:arrify:2.0.1:*:*:*:*:*:*:*",
215547          "purl": "pkg:npm/arrify@2.0.1",
215548          "swid": {
215549            "attachment": {}
215550          },
215551          "pedigree": {},
215552          "evidence": {},
215553          "signature": {
215554            "signature": {
215555              "publicKey": {}
215556            }
215557          },
215558          "modelCard": {
215559            "modelParameters": {
215560              "approach": {}
215561            },
215562            "quantitativeAnalysis": {
215563              "graphics": {}
215564            },
215565            "considerations": {}
215566          }
215567        },
215568        {
215569          "type": "library",
215570          "bom-ref": "pkg:npm/asn1@0.2.3?package-id=b15c6f19148d0d36",
215571          "supplier": {},
215572          "name": "asn1",
215573          "version": "0.2.3",
215574          "licenses": [
215575            {
215576              "license": {
215577                "id": "MIT"
215578              }
215579            }
215580          ],
215581          "cpe": "cpe:2.3:a:asn1:asn1:0.2.3:*:*:*:*:*:*:*",
215582          "purl": "pkg:npm/asn1@0.2.3",
215583          "swid": {
215584            "attachment": {}
215585          },
215586          "pedigree": {},
215587          "evidence": {},
215588          "signature": {
215589            "signature": {
215590              "publicKey": {}
215591            }
215592          },
215593          "modelCard": {
215594            "modelParameters": {
215595              "approach": {}
215596            },
215597            "quantitativeAnalysis": {
215598              "graphics": {}
215599            },
215600            "considerations": {}
215601          }
215602        },
215603        {
215604          "type": "library",
215605          "bom-ref": "pkg:npm/asn1-ber@1.2.2?package-id=1b5b706a7e5e39fc",
215606          "supplier": {},
215607          "name": "asn1-ber",
215608          "version": "1.2.2",
215609          "licenses": [
215610            {
215611              "license": {
215612                "id": "MIT"
215613              }
215614            }
215615          ],
215616          "cpe": "cpe:2.3:a:asn1-ber:asn1-ber:1.2.2:*:*:*:*:*:*:*",
215617          "purl": "pkg:npm/asn1-ber@1.2.2",
215618          "swid": {
215619            "attachment": {}
215620          },
215621          "pedigree": {},
215622          "evidence": {},
215623          "signature": {
215624            "signature": {
215625              "publicKey": {}
215626            }
215627          },
215628          "modelCard": {
215629            "modelParameters": {
215630              "approach": {}
215631            },
215632            "quantitativeAnalysis": {
215633              "graphics": {}
215634            },
215635            "considerations": {}
215636          }
215637        },
215638        {
215639          "type": "library",
215640          "bom-ref": "pkg:npm/assert-plus@1.0.0?package-id=5390131abace4c0",
215641          "supplier": {},
215642          "name": "assert-plus",
215643          "version": "1.0.0",
215644          "licenses": [
215645            {
215646              "license": {
215647                "id": "MIT"
215648              }
215649            }
215650          ],
215651          "cpe": "cpe:2.3:a:assert-plus:assert-plus:1.0.0:*:*:*:*:*:*:*",
215652          "purl": "pkg:npm/assert-plus@1.0.0",
215653          "swid": {
215654            "attachment": {}
215655          },
215656          "pedigree": {},
215657          "evidence": {},
215658          "signature": {
215659            "signature": {
215660              "publicKey": {}
215661            }
215662          },
215663          "modelCard": {
215664            "modelParameters": {
215665              "approach": {}
215666            },
215667            "quantitativeAnalysis": {
215668              "graphics": {}
215669            },
215670            "considerations": {}
215671          }
215672        },
215673        {
215674          "type": "library",
215675          "bom-ref": "pkg:npm/astral-regex@1.0.0?package-id=c211cde80b2c1f30",
215676          "supplier": {},
215677          "name": "astral-regex",
215678          "version": "1.0.0",
215679          "licenses": [
215680            {
215681              "license": {
215682                "id": "MIT"
215683              }
215684            }
215685          ],
215686          "cpe": "cpe:2.3:a:astral-regex:astral-regex:1.0.0:*:*:*:*:*:*:*",
215687          "purl": "pkg:npm/astral-regex@1.0.0",
215688          "swid": {
215689            "attachment": {}
215690          },
215691          "pedigree": {},
215692          "evidence": {},
215693          "signature": {
215694            "signature": {
215695              "publicKey": {}
215696            }
215697          },
215698          "modelCard": {
215699            "modelParameters": {
215700              "approach": {}
215701            },
215702            "quantitativeAnalysis": {
215703              "graphics": {}
215704            },
215705            "considerations": {}
215706          }
215707        },
215708        {
215709          "type": "library",
215710          "bom-ref": "pkg:npm/async@3.2.4?package-id=3b25272da5bf5383",
215711          "supplier": {},
215712          "name": "async",
215713          "version": "3.2.4",
215714          "licenses": [
215715            {
215716              "license": {
215717                "id": "MIT"
215718              }
215719            }
215720          ],
215721          "cpe": "cpe:2.3:a:async:async:3.2.4:*:*:*:*:*:*:*",
215722          "purl": "pkg:npm/async@3.2.4",
215723          "swid": {
215724            "attachment": {}
215725          },
215726          "pedigree": {},
215727          "evidence": {},
215728          "signature": {
215729            "signature": {
215730              "publicKey": {}
215731            }
215732          },
215733          "modelCard": {
215734            "modelParameters": {
215735              "approach": {}
215736            },
215737            "quantitativeAnalysis": {
215738              "graphics": {}
215739            },
215740            "considerations": {}
215741          }
215742        },
215743        {
215744          "type": "library",
215745          "bom-ref": "pkg:npm/async-limiter@1.0.1?package-id=37f39b275bd1ee5",
215746          "supplier": {},
215747          "name": "async-limiter",
215748          "version": "1.0.1",
215749          "licenses": [
215750            {
215751              "license": {
215752                "id": "MIT"
215753              }
215754            }
215755          ],
215756          "cpe": "cpe:2.3:a:async-limiter:async-limiter:1.0.1:*:*:*:*:*:*:*",
215757          "purl": "pkg:npm/async-limiter@1.0.1",
215758          "swid": {
215759            "attachment": {}
215760          },
215761          "pedigree": {},
215762          "evidence": {},
215763          "signature": {
215764            "signature": {
215765              "publicKey": {}
215766            }
215767          },
215768          "modelCard": {
215769            "modelParameters": {
215770              "approach": {}
215771            },
215772            "quantitativeAnalysis": {
215773              "graphics": {}
215774            },
215775            "considerations": {}
215776          }
215777        },
215778        {
215779          "type": "library",
215780          "bom-ref": "pkg:npm/asynckit@0.4.0?package-id=4cfcce01cadf2d8d",
215781          "supplier": {},
215782          "name": "asynckit",
215783          "version": "0.4.0",
215784          "licenses": [
215785            {
215786              "license": {
215787                "id": "MIT"
215788              }
215789            }
215790          ],
215791          "cpe": "cpe:2.3:a:asynckit:asynckit:0.4.0:*:*:*:*:*:*:*",
215792          "purl": "pkg:npm/asynckit@0.4.0",
215793          "swid": {
215794            "attachment": {}
215795          },
215796          "pedigree": {},
215797          "evidence": {},
215798          "signature": {
215799            "signature": {
215800              "publicKey": {}
215801            }
215802          },
215803          "modelCard": {
215804            "modelParameters": {
215805              "approach": {}
215806            },
215807            "quantitativeAnalysis": {
215808              "graphics": {}
215809            },
215810            "considerations": {}
215811          }
215812        },
215813        {
215814          "type": "library",
215815          "bom-ref": "pkg:npm/aws-sign2@0.7.0?package-id=f85b64dcabe1f3b7",
215816          "supplier": {},
215817          "name": "aws-sign2",
215818          "version": "0.7.0",
215819          "licenses": [
215820            {
215821              "license": {
215822                "id": "Apache-2.0"
215823              }
215824            }
215825          ],
215826          "cpe": "cpe:2.3:a:aws-sign2:aws-sign2:0.7.0:*:*:*:*:*:*:*",
215827          "purl": "pkg:npm/aws-sign2@0.7.0",
215828          "swid": {
215829            "attachment": {}
215830          },
215831          "pedigree": {},
215832          "evidence": {},
215833          "signature": {
215834            "signature": {
215835              "publicKey": {}
215836            }
215837          },
215838          "modelCard": {
215839            "modelParameters": {
215840              "approach": {}
215841            },
215842            "quantitativeAnalysis": {
215843              "graphics": {}
215844            },
215845            "considerations": {}
215846          }
215847        },
215848        {
215849          "type": "library",
215850          "bom-ref": "pkg:npm/aws4@1.8.0?package-id=b81f07df77ac4843",
215851          "supplier": {},
215852          "name": "aws4",
215853          "version": "1.8.0",
215854          "licenses": [
215855            {
215856              "license": {
215857                "id": "MIT"
215858              }
215859            }
215860          ],
215861          "cpe": "cpe:2.3:a:aws4:aws4:1.8.0:*:*:*:*:*:*:*",
215862          "purl": "pkg:npm/aws4@1.8.0",
215863          "swid": {
215864            "attachment": {}
215865          },
215866          "pedigree": {},
215867          "evidence": {},
215868          "signature": {
215869            "signature": {
215870              "publicKey": {}
215871            }
215872          },
215873          "modelCard": {
215874            "modelParameters": {
215875              "approach": {}
215876            },
215877            "quantitativeAnalysis": {
215878              "graphics": {}
215879            },
215880            "considerations": {}
215881          }
215882        },
215883        {
215884          "type": "library",
215885          "bom-ref": "pkg:npm/axios@0.21.4?package-id=b2963fcf94c5008f",
215886          "supplier": {},
215887          "name": "axios",
215888          "version": "0.21.4",
215889          "licenses": [
215890            {
215891              "license": {
215892                "id": "MIT"
215893              }
215894            }
215895          ],
215896          "cpe": "cpe:2.3:a:axios:axios:0.21.4:*:*:*:*:*:*:*",
215897          "purl": "pkg:npm/axios@0.21.4",
215898          "swid": {
215899            "attachment": {}
215900          },
215901          "pedigree": {},
215902          "evidence": {},
215903          "signature": {
215904            "signature": {
215905              "publicKey": {}
215906            }
215907          },
215908          "modelCard": {
215909            "modelParameters": {
215910              "approach": {}
215911            },
215912            "quantitativeAnalysis": {
215913              "graphics": {}
215914            },
215915            "considerations": {}
215916          }
215917        },
215918        {
215919          "type": "library",
215920          "bom-ref": "pkg:npm/backoff@2.5.0?package-id=b25215831e3b5aa1",
215921          "supplier": {},
215922          "name": "backoff",
215923          "version": "2.5.0",
215924          "licenses": [
215925            {
215926              "license": {
215927                "id": "MIT"
215928              }
215929            }
215930          ],
215931          "cpe": "cpe:2.3:a:backoff:backoff:2.5.0:*:*:*:*:*:*:*",
215932          "purl": "pkg:npm/backoff@2.5.0",
215933          "swid": {
215934            "attachment": {}
215935          },
215936          "pedigree": {},
215937          "evidence": {},
215938          "signature": {
215939            "signature": {
215940              "publicKey": {}
215941            }
215942          },
215943          "modelCard": {
215944            "modelParameters": {
215945              "approach": {}
215946            },
215947            "quantitativeAnalysis": {
215948              "graphics": {}
215949            },
215950            "considerations": {}
215951          }
215952        },
215953        {
215954          "type": "library",
215955          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=cb6b0119ddbab112",
215956          "supplier": {},
215957          "name": "balanced-match",
215958          "version": "1.0.2",
215959          "licenses": [
215960            {
215961              "license": {
215962                "id": "MIT"
215963              }
215964            }
215965          ],
215966          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
215967          "purl": "pkg:npm/balanced-match@1.0.2",
215968          "swid": {
215969            "attachment": {}
215970          },
215971          "pedigree": {},
215972          "evidence": {},
215973          "signature": {
215974            "signature": {
215975              "publicKey": {}
215976            }
215977          },
215978          "modelCard": {
215979            "modelParameters": {
215980              "approach": {}
215981            },
215982            "quantitativeAnalysis": {
215983              "graphics": {}
215984            },
215985            "considerations": {}
215986          }
215987        },
215988        {
215989          "type": "library",
215990          "bom-ref": "pkg:npm/base64-js@1.5.1?package-id=695551d0f1012f91",
215991          "supplier": {},
215992          "name": "base64-js",
215993          "version": "1.5.1",
215994          "licenses": [
215995            {
215996              "license": {
215997                "id": "MIT"
215998              }
215999            }
216000          ],
216001          "cpe": "cpe:2.3:a:base64-js:base64-js:1.5.1:*:*:*:*:*:*:*",
216002          "purl": "pkg:npm/base64-js@1.5.1",
216003          "swid": {
216004            "attachment": {}
216005          },
216006          "pedigree": {},
216007          "evidence": {},
216008          "signature": {
216009            "signature": {
216010              "publicKey": {}
216011            }
216012          },
216013          "modelCard": {
216014            "modelParameters": {
216015              "approach": {}
216016            },
216017            "quantitativeAnalysis": {
216018              "graphics": {}
216019            },
216020            "considerations": {}
216021          }
216022        },
216023        {
216024          "type": "library",
216025          "bom-ref": "pkg:npm/base64url@3.0.1?package-id=537ad19ac0056d7c",
216026          "supplier": {},
216027          "name": "base64url",
216028          "version": "3.0.1",
216029          "licenses": [
216030            {
216031              "license": {
216032                "id": "MIT"
216033              }
216034            }
216035          ],
216036          "cpe": "cpe:2.3:a:base64url:base64url:3.0.1:*:*:*:*:*:*:*",
216037          "purl": "pkg:npm/base64url@3.0.1",
216038          "swid": {
216039            "attachment": {}
216040          },
216041          "pedigree": {},
216042          "evidence": {},
216043          "signature": {
216044            "signature": {
216045              "publicKey": {}
216046            }
216047          },
216048          "modelCard": {
216049            "modelParameters": {
216050              "approach": {}
216051            },
216052            "quantitativeAnalysis": {
216053              "graphics": {}
216054            },
216055            "considerations": {}
216056          }
216057        },
216058        {
216059          "type": "library",
216060          "bom-ref": "pkg:npm/bcrypt-pbkdf@1.0.2?package-id=935adf4faa5810fe",
216061          "supplier": {},
216062          "name": "bcrypt-pbkdf",
216063          "version": "1.0.2",
216064          "licenses": [
216065            {
216066              "license": {
216067                "id": "BSD-3-Clause"
216068              }
216069            }
216070          ],
216071          "cpe": "cpe:2.3:a:bcrypt-pbkdf:bcrypt-pbkdf:1.0.2:*:*:*:*:*:*:*",
216072          "purl": "pkg:npm/bcrypt-pbkdf@1.0.2",
216073          "swid": {
216074            "attachment": {}
216075          },
216076          "pedigree": {},
216077          "evidence": {},
216078          "signature": {
216079            "signature": {
216080              "publicKey": {}
216081            }
216082          },
216083          "modelCard": {
216084            "modelParameters": {
216085              "approach": {}
216086            },
216087            "quantitativeAnalysis": {
216088              "graphics": {}
216089            },
216090            "considerations": {}
216091          }
216092        },
216093        {
216094          "type": "library",
216095          "bom-ref": "pkg:npm/big-integer@1.6.51?package-id=ceb6273775691db9",
216096          "supplier": {},
216097          "name": "big-integer",
216098          "version": "1.6.51",
216099          "licenses": [
216100            {
216101              "license": {
216102                "id": "Unlicense"
216103              }
216104            }
216105          ],
216106          "cpe": "cpe:2.3:a:big-integer:big-integer:1.6.51:*:*:*:*:*:*:*",
216107          "purl": "pkg:npm/big-integer@1.6.51",
216108          "swid": {
216109            "attachment": {}
216110          },
216111          "pedigree": {},
216112          "evidence": {},
216113          "signature": {
216114            "signature": {
216115              "publicKey": {}
216116            }
216117          },
216118          "modelCard": {
216119            "modelParameters": {
216120              "approach": {}
216121            },
216122            "quantitativeAnalysis": {
216123              "graphics": {}
216124            },
216125            "considerations": {}
216126          }
216127        },
216128        {
216129          "type": "library",
216130          "bom-ref": "pkg:npm/bignumber.js@9.1.1?package-id=5349ee3a177f8ae1",
216131          "supplier": {},
216132          "name": "bignumber.js",
216133          "version": "9.1.1",
216134          "licenses": [
216135            {
216136              "license": {
216137                "id": "MIT"
216138              }
216139            }
216140          ],
216141          "cpe": "cpe:2.3:a:bignumber.js:bignumber.js:9.1.1:*:*:*:*:*:*:*",
216142          "purl": "pkg:npm/bignumber.js@9.1.1",
216143          "swid": {
216144            "attachment": {}
216145          },
216146          "pedigree": {},
216147          "evidence": {},
216148          "signature": {
216149            "signature": {
216150              "publicKey": {}
216151            }
216152          },
216153          "modelCard": {
216154            "modelParameters": {
216155              "approach": {}
216156            },
216157            "quantitativeAnalysis": {
216158              "graphics": {}
216159            },
216160            "considerations": {}
216161          }
216162        },
216163        {
216164          "type": "library",
216165          "bom-ref": "pkg:npm/bin-build@3.0.0?package-id=d59b78bfb221e859",
216166          "supplier": {},
216167          "name": "bin-build",
216168          "version": "3.0.0",
216169          "licenses": [
216170            {
216171              "license": {
216172                "id": "MIT"
216173              }
216174            }
216175          ],
216176          "cpe": "cpe:2.3:a:bin-build:bin-build:3.0.0:*:*:*:*:*:*:*",
216177          "purl": "pkg:npm/bin-build@3.0.0",
216178          "swid": {
216179            "attachment": {}
216180          },
216181          "pedigree": {},
216182          "evidence": {},
216183          "signature": {
216184            "signature": {
216185              "publicKey": {}
216186            }
216187          },
216188          "modelCard": {
216189            "modelParameters": {
216190              "approach": {}
216191            },
216192            "quantitativeAnalysis": {
216193              "graphics": {}
216194            },
216195            "considerations": {}
216196          }
216197        },
216198        {
216199          "type": "library",
216200          "bom-ref": "pkg:npm/binary@0.3.0?package-id=246c87153112ab52",
216201          "supplier": {},
216202          "name": "binary",
216203          "version": "0.3.0",
216204          "licenses": [
216205            {
216206              "license": {
216207                "id": "MIT"
216208              }
216209            }
216210          ],
216211          "cpe": "cpe:2.3:a:binary:binary:0.3.0:*:*:*:*:*:*:*",
216212          "purl": "pkg:npm/binary@0.3.0",
216213          "swid": {
216214            "attachment": {}
216215          },
216216          "pedigree": {},
216217          "evidence": {},
216218          "signature": {
216219            "signature": {
216220              "publicKey": {}
216221            }
216222          },
216223          "modelCard": {
216224            "modelParameters": {
216225              "approach": {}
216226            },
216227            "quantitativeAnalysis": {
216228              "graphics": {}
216229            },
216230            "considerations": {}
216231          }
216232        },
216233        {
216234          "type": "library",
216235          "bom-ref": "pkg:npm/binaryheap@0.0.3?package-id=d33723c3648cad62",
216236          "supplier": {},
216237          "name": "binaryheap",
216238          "version": "0.0.3",
216239          "cpe": "cpe:2.3:a:binaryheap:binaryheap:0.0.3:*:*:*:*:*:*:*",
216240          "purl": "pkg:npm/binaryheap@0.0.3",
216241          "swid": {
216242            "attachment": {}
216243          },
216244          "pedigree": {},
216245          "evidence": {},
216246          "signature": {
216247            "signature": {
216248              "publicKey": {}
216249            }
216250          },
216251          "modelCard": {
216252            "modelParameters": {
216253              "approach": {}
216254            },
216255            "quantitativeAnalysis": {
216256              "graphics": {}
216257            },
216258            "considerations": {}
216259          }
216260        },
216261        {
216262          "type": "library",
216263          "bom-ref": "pkg:npm/bitsyntax@0.1.0?package-id=f0ea24159e69f491",
216264          "supplier": {},
216265          "name": "bitsyntax",
216266          "version": "0.1.0",
216267          "licenses": [
216268            {
216269              "license": {
216270                "id": "MIT"
216271              }
216272            }
216273          ],
216274          "cpe": "cpe:2.3:a:bitsyntax:bitsyntax:0.1.0:*:*:*:*:*:*:*",
216275          "purl": "pkg:npm/bitsyntax@0.1.0",
216276          "swid": {
216277            "attachment": {}
216278          },
216279          "pedigree": {},
216280          "evidence": {},
216281          "signature": {
216282            "signature": {
216283              "publicKey": {}
216284            }
216285          },
216286          "modelCard": {
216287            "modelParameters": {
216288              "approach": {}
216289            },
216290            "quantitativeAnalysis": {
216291              "graphics": {}
216292            },
216293            "considerations": {}
216294          }
216295        },
216296        {
216297          "type": "library",
216298          "bom-ref": "pkg:npm/bl@4.1.0?package-id=480c2300eda438dc",
216299          "supplier": {},
216300          "name": "bl",
216301          "version": "4.1.0",
216302          "licenses": [
216303            {
216304              "license": {
216305                "id": "MIT"
216306              }
216307            }
216308          ],
216309          "cpe": "cpe:2.3:a:bl:bl:4.1.0:*:*:*:*:*:*:*",
216310          "purl": "pkg:npm/bl@4.1.0",
216311          "swid": {
216312            "attachment": {}
216313          },
216314          "pedigree": {},
216315          "evidence": {},
216316          "signature": {
216317            "signature": {
216318              "publicKey": {}
216319            }
216320          },
216321          "modelCard": {
216322            "modelParameters": {
216323              "approach": {}
216324            },
216325            "quantitativeAnalysis": {
216326              "graphics": {}
216327            },
216328            "considerations": {}
216329          }
216330        },
216331        {
216332          "type": "library",
216333          "bom-ref": "pkg:npm/bluebird@3.7.2?package-id=b78a7f922dc9e95d",
216334          "supplier": {},
216335          "name": "bluebird",
216336          "version": "3.7.2",
216337          "licenses": [
216338            {
216339              "license": {
216340                "id": "MIT"
216341              }
216342            }
216343          ],
216344          "cpe": "cpe:2.3:a:bluebird:bluebird:3.7.2:*:*:*:*:*:*:*",
216345          "purl": "pkg:npm/bluebird@3.7.2",
216346          "swid": {
216347            "attachment": {}
216348          },
216349          "pedigree": {},
216350          "evidence": {},
216351          "signature": {
216352            "signature": {
216353              "publicKey": {}
216354            }
216355          },
216356          "modelCard": {
216357            "modelParameters": {
216358              "approach": {}
216359            },
216360            "quantitativeAnalysis": {
216361              "graphics": {}
216362            },
216363            "considerations": {}
216364          }
216365        },
216366        {
216367          "type": "library",
216368          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=5a34efcf67357245",
216369          "supplier": {},
216370          "name": "brace-expansion",
216371          "version": "1.1.11",
216372          "licenses": [
216373            {
216374              "license": {
216375                "id": "MIT"
216376              }
216377            }
216378          ],
216379          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
216380          "purl": "pkg:npm/brace-expansion@1.1.11",
216381          "swid": {
216382            "attachment": {}
216383          },
216384          "pedigree": {},
216385          "evidence": {},
216386          "signature": {
216387            "signature": {
216388              "publicKey": {}
216389            }
216390          },
216391          "modelCard": {
216392            "modelParameters": {
216393              "approach": {}
216394            },
216395            "quantitativeAnalysis": {
216396              "graphics": {}
216397            },
216398            "considerations": {}
216399          }
216400        },
216401        {
216402          "type": "library",
216403          "bom-ref": "pkg:npm/bson@1.1.6?package-id=ef159f383f13c1e1",
216404          "supplier": {},
216405          "name": "bson",
216406          "version": "1.1.6",
216407          "licenses": [
216408            {
216409              "license": {
216410                "id": "Apache-2.0"
216411              }
216412            }
216413          ],
216414          "cpe": "cpe:2.3:a:bson:bson:1.1.6:*:*:*:*:*:*:*",
216415          "purl": "pkg:npm/bson@1.1.6",
216416          "swid": {
216417            "attachment": {}
216418          },
216419          "pedigree": {},
216420          "evidence": {},
216421          "signature": {
216422            "signature": {
216423              "publicKey": {}
216424            }
216425          },
216426          "modelCard": {
216427            "modelParameters": {
216428              "approach": {}
216429            },
216430            "quantitativeAnalysis": {
216431              "graphics": {}
216432            },
216433            "considerations": {}
216434          }
216435        },
216436        {
216437          "type": "library",
216438          "bom-ref": "pkg:npm/buffer@5.7.1?package-id=2eb88003f2fa2648",
216439          "supplier": {},
216440          "name": "buffer",
216441          "version": "5.7.1",
216442          "licenses": [
216443            {
216444              "license": {
216445                "id": "MIT"
216446              }
216447            }
216448          ],
216449          "cpe": "cpe:2.3:a:buffer:buffer:5.7.1:*:*:*:*:*:*:*",
216450          "purl": "pkg:npm/buffer@5.7.1",
216451          "swid": {
216452            "attachment": {}
216453          },
216454          "pedigree": {},
216455          "evidence": {},
216456          "signature": {
216457            "signature": {
216458              "publicKey": {}
216459            }
216460          },
216461          "modelCard": {
216462            "modelParameters": {
216463              "approach": {}
216464            },
216465            "quantitativeAnalysis": {
216466              "graphics": {}
216467            },
216468            "considerations": {}
216469          }
216470        },
216471        {
216472          "type": "library",
216473          "bom-ref": "pkg:npm/buffer-alloc@1.2.0?package-id=927d6e2deda9b7fb",
216474          "supplier": {},
216475          "name": "buffer-alloc",
216476          "version": "1.2.0",
216477          "licenses": [
216478            {
216479              "license": {
216480                "id": "MIT"
216481              }
216482            }
216483          ],
216484          "cpe": "cpe:2.3:a:buffer-alloc:buffer-alloc:1.2.0:*:*:*:*:*:*:*",
216485          "purl": "pkg:npm/buffer-alloc@1.2.0",
216486          "swid": {
216487            "attachment": {}
216488          },
216489          "pedigree": {},
216490          "evidence": {},
216491          "signature": {
216492            "signature": {
216493              "publicKey": {}
216494            }
216495          },
216496          "modelCard": {
216497            "modelParameters": {
216498              "approach": {}
216499            },
216500            "quantitativeAnalysis": {
216501              "graphics": {}
216502            },
216503            "considerations": {}
216504          }
216505        },
216506        {
216507          "type": "library",
216508          "bom-ref": "pkg:npm/buffer-alloc-unsafe@1.1.0?package-id=951f5a542c211f90",
216509          "supplier": {},
216510          "name": "buffer-alloc-unsafe",
216511          "version": "1.1.0",
216512          "licenses": [
216513            {
216514              "license": {
216515                "id": "MIT"
216516              }
216517            }
216518          ],
216519          "cpe": "cpe:2.3:a:buffer-alloc-unsafe:buffer-alloc-unsafe:1.1.0:*:*:*:*:*:*:*",
216520          "purl": "pkg:npm/buffer-alloc-unsafe@1.1.0",
216521          "swid": {
216522            "attachment": {}
216523          },
216524          "pedigree": {},
216525          "evidence": {},
216526          "signature": {
216527            "signature": {
216528              "publicKey": {}
216529            }
216530          },
216531          "modelCard": {
216532            "modelParameters": {
216533              "approach": {}
216534            },
216535            "quantitativeAnalysis": {
216536              "graphics": {}
216537            },
216538            "considerations": {}
216539          }
216540        },
216541        {
216542          "type": "library",
216543          "bom-ref": "pkg:npm/buffer-crc32@0.2.13?package-id=b90b276a6ab8ea4b",
216544          "supplier": {},
216545          "name": "buffer-crc32",
216546          "version": "0.2.13",
216547          "licenses": [
216548            {
216549              "license": {
216550                "id": "MIT"
216551              }
216552            }
216553          ],
216554          "cpe": "cpe:2.3:a:buffer-crc32:buffer-crc32:0.2.13:*:*:*:*:*:*:*",
216555          "purl": "pkg:npm/buffer-crc32@0.2.13",
216556          "swid": {
216557            "attachment": {}
216558          },
216559          "pedigree": {},
216560          "evidence": {},
216561          "signature": {
216562            "signature": {
216563              "publicKey": {}
216564            }
216565          },
216566          "modelCard": {
216567            "modelParameters": {
216568              "approach": {}
216569            },
216570            "quantitativeAnalysis": {
216571              "graphics": {}
216572            },
216573            "considerations": {}
216574          }
216575        },
216576        {
216577          "type": "library",
216578          "bom-ref": "pkg:npm/buffer-equal-constant-time@1.0.1?package-id=ebc6cb6a4f293753",
216579          "supplier": {},
216580          "name": "buffer-equal-constant-time",
216581          "version": "1.0.1",
216582          "licenses": [
216583            {
216584              "license": {
216585                "id": "BSD-3-Clause"
216586              }
216587            }
216588          ],
216589          "cpe": "cpe:2.3:a:buffer-equal-constant-time:buffer-equal-constant-time:1.0.1:*:*:*:*:*:*:*",
216590          "purl": "pkg:npm/buffer-equal-constant-time@1.0.1",
216591          "swid": {
216592            "attachment": {}
216593          },
216594          "pedigree": {},
216595          "evidence": {},
216596          "signature": {
216597            "signature": {
216598              "publicKey": {}
216599            }
216600          },
216601          "modelCard": {
216602            "modelParameters": {
216603              "approach": {}
216604            },
216605            "quantitativeAnalysis": {
216606              "graphics": {}
216607            },
216608            "considerations": {}
216609          }
216610        },
216611        {
216612          "type": "library",
216613          "bom-ref": "pkg:npm/buffer-fill@1.0.0?package-id=5e1dbb9ba7ac1c8a",
216614          "supplier": {},
216615          "name": "buffer-fill",
216616          "version": "1.0.0",
216617          "licenses": [
216618            {
216619              "license": {
216620                "id": "MIT"
216621              }
216622            }
216623          ],
216624          "cpe": "cpe:2.3:a:buffer-fill:buffer-fill:1.0.0:*:*:*:*:*:*:*",
216625          "purl": "pkg:npm/buffer-fill@1.0.0",
216626          "swid": {
216627            "attachment": {}
216628          },
216629          "pedigree": {},
216630          "evidence": {},
216631          "signature": {
216632            "signature": {
216633              "publicKey": {}
216634            }
216635          },
216636          "modelCard": {
216637            "modelParameters": {
216638              "approach": {}
216639            },
216640            "quantitativeAnalysis": {
216641              "graphics": {}
216642            },
216643            "considerations": {}
216644          }
216645        },
216646        {
216647          "type": "library",
216648          "bom-ref": "pkg:npm/buffer-from@1.1.2?package-id=24ef8c5078f78a00",
216649          "supplier": {},
216650          "name": "buffer-from",
216651          "version": "1.1.2",
216652          "licenses": [
216653            {
216654              "license": {
216655                "id": "MIT"
216656              }
216657            }
216658          ],
216659          "cpe": "cpe:2.3:a:buffer-from:buffer-from:1.1.2:*:*:*:*:*:*:*",
216660          "purl": "pkg:npm/buffer-from@1.1.2",
216661          "swid": {
216662            "attachment": {}
216663          },
216664          "pedigree": {},
216665          "evidence": {},
216666          "signature": {
216667            "signature": {
216668              "publicKey": {}
216669            }
216670          },
216671          "modelCard": {
216672            "modelParameters": {
216673              "approach": {}
216674            },
216675            "quantitativeAnalysis": {
216676              "graphics": {}
216677            },
216678            "considerations": {}
216679          }
216680        },
216681        {
216682          "type": "library",
216683          "bom-ref": "pkg:npm/buffer-indexof-polyfill@1.0.2?package-id=1bf50c5676c8ed1",
216684          "supplier": {},
216685          "name": "buffer-indexof-polyfill",
216686          "version": "1.0.2",
216687          "licenses": [
216688            {
216689              "license": {
216690                "id": "MIT"
216691              }
216692            }
216693          ],
216694          "cpe": "cpe:2.3:a:buffer-indexof-polyfill:buffer-indexof-polyfill:1.0.2:*:*:*:*:*:*:*",
216695          "purl": "pkg:npm/buffer-indexof-polyfill@1.0.2",
216696          "swid": {
216697            "attachment": {}
216698          },
216699          "pedigree": {},
216700          "evidence": {},
216701          "signature": {
216702            "signature": {
216703              "publicKey": {}
216704            }
216705          },
216706          "modelCard": {
216707            "modelParameters": {
216708              "approach": {}
216709            },
216710            "quantitativeAnalysis": {
216711              "graphics": {}
216712            },
216713            "considerations": {}
216714          }
216715        },
216716        {
216717          "type": "library",
216718          "bom-ref": "pkg:npm/buffer-more-ints@1.0.0?package-id=bad5a95b993345e3",
216719          "supplier": {},
216720          "name": "buffer-more-ints",
216721          "version": "1.0.0",
216722          "licenses": [
216723            {
216724              "license": {
216725                "id": "MIT"
216726              }
216727            }
216728          ],
216729          "cpe": "cpe:2.3:a:buffer-more-ints:buffer-more-ints:1.0.0:*:*:*:*:*:*:*",
216730          "purl": "pkg:npm/buffer-more-ints@1.0.0",
216731          "swid": {
216732            "attachment": {}
216733          },
216734          "pedigree": {},
216735          "evidence": {},
216736          "signature": {
216737            "signature": {
216738              "publicKey": {}
216739            }
216740          },
216741          "modelCard": {
216742            "modelParameters": {
216743              "approach": {}
216744            },
216745            "quantitativeAnalysis": {
216746              "graphics": {}
216747            },
216748            "considerations": {}
216749          }
216750        },
216751        {
216752          "type": "library",
216753          "bom-ref": "pkg:npm/buffer-writer@2.0.0?package-id=b7c4bd65333b5a6e",
216754          "supplier": {},
216755          "name": "buffer-writer",
216756          "version": "2.0.0",
216757          "licenses": [
216758            {
216759              "license": {
216760                "id": "MIT"
216761              }
216762            }
216763          ],
216764          "cpe": "cpe:2.3:a:buffer-writer:buffer-writer:2.0.0:*:*:*:*:*:*:*",
216765          "purl": "pkg:npm/buffer-writer@2.0.0",
216766          "swid": {
216767            "attachment": {}
216768          },
216769          "pedigree": {},
216770          "evidence": {},
216771          "signature": {
216772            "signature": {
216773              "publicKey": {}
216774            }
216775          },
216776          "modelCard": {
216777            "modelParameters": {
216778              "approach": {}
216779            },
216780            "quantitativeAnalysis": {
216781              "graphics": {}
216782            },
216783            "considerations": {}
216784          }
216785        },
216786        {
216787          "type": "library",
216788          "bom-ref": "pkg:npm/buffercursor@0.0.12?package-id=ceb4c032f4af0d3a",
216789          "supplier": {},
216790          "name": "buffercursor",
216791          "version": "0.0.12",
216792          "cpe": "cpe:2.3:a:buffercursor:buffercursor:0.0.12:*:*:*:*:*:*:*",
216793          "purl": "pkg:npm/buffercursor@0.0.12",
216794          "swid": {
216795            "attachment": {}
216796          },
216797          "pedigree": {},
216798          "evidence": {},
216799          "signature": {
216800            "signature": {
216801              "publicKey": {}
216802            }
216803          },
216804          "modelCard": {
216805            "modelParameters": {
216806              "approach": {}
216807            },
216808            "quantitativeAnalysis": {
216809              "graphics": {}
216810            },
216811            "considerations": {}
216812          }
216813        },
216814        {
216815          "type": "library",
216816          "bom-ref": "pkg:npm/buffers@0.1.1?package-id=c23d403946247971",
216817          "supplier": {},
216818          "name": "buffers",
216819          "version": "0.1.1",
216820          "cpe": "cpe:2.3:a:buffers:buffers:0.1.1:*:*:*:*:*:*:*",
216821          "purl": "pkg:npm/buffers@0.1.1",
216822          "swid": {
216823            "attachment": {}
216824          },
216825          "pedigree": {},
216826          "evidence": {},
216827          "signature": {
216828            "signature": {
216829              "publicKey": {}
216830            }
216831          },
216832          "modelCard": {
216833            "modelParameters": {
216834              "approach": {}
216835            },
216836            "quantitativeAnalysis": {
216837              "graphics": {}
216838            },
216839            "considerations": {}
216840          }
216841        },
216842        {
216843          "type": "library",
216844          "bom-ref": "pkg:npm/buildcheck@0.0.6?package-id=b566387558aabe2e",
216845          "supplier": {},
216846          "name": "buildcheck",
216847          "version": "0.0.6",
216848          "cpe": "cpe:2.3:a:buildcheck:buildcheck:0.0.6:*:*:*:*:*:*:*",
216849          "purl": "pkg:npm/buildcheck@0.0.6",
216850          "swid": {
216851            "attachment": {}
216852          },
216853          "pedigree": {},
216854          "evidence": {},
216855          "signature": {
216856            "signature": {
216857              "publicKey": {}
216858            }
216859          },
216860          "modelCard": {
216861            "modelParameters": {
216862              "approach": {}
216863            },
216864            "quantitativeAnalysis": {
216865              "graphics": {}
216866            },
216867            "considerations": {}
216868          }
216869        },
216870        {
216871          "type": "library",
216872          "bom-ref": "pkg:npm/call-bind@1.0.2?package-id=3716eae3fd07393a",
216873          "supplier": {},
216874          "name": "call-bind",
216875          "version": "1.0.2",
216876          "licenses": [
216877            {
216878              "license": {
216879                "id": "MIT"
216880              }
216881            }
216882          ],
216883          "cpe": "cpe:2.3:a:call-bind:call-bind:1.0.2:*:*:*:*:*:*:*",
216884          "purl": "pkg:npm/call-bind@1.0.2",
216885          "swid": {
216886            "attachment": {}
216887          },
216888          "pedigree": {},
216889          "evidence": {},
216890          "signature": {
216891            "signature": {
216892              "publicKey": {}
216893            }
216894          },
216895          "modelCard": {
216896            "modelParameters": {
216897              "approach": {}
216898            },
216899            "quantitativeAnalysis": {
216900              "graphics": {}
216901            },
216902            "considerations": {}
216903          }
216904        },
216905        {
216906          "type": "library",
216907          "bom-ref": "pkg:npm/caseless@0.12.0?package-id=810c24f06aebfc6a",
216908          "supplier": {},
216909          "name": "caseless",
216910          "version": "0.12.0",
216911          "licenses": [
216912            {
216913              "license": {
216914                "id": "Apache-2.0"
216915              }
216916            }
216917          ],
216918          "cpe": "cpe:2.3:a:caseless:caseless:0.12.0:*:*:*:*:*:*:*",
216919          "purl": "pkg:npm/caseless@0.12.0",
216920          "swid": {
216921            "attachment": {}
216922          },
216923          "pedigree": {},
216924          "evidence": {},
216925          "signature": {
216926            "signature": {
216927              "publicKey": {}
216928            }
216929          },
216930          "modelCard": {
216931            "modelParameters": {
216932              "approach": {}
216933            },
216934            "quantitativeAnalysis": {
216935              "graphics": {}
216936            },
216937            "considerations": {}
216938          }
216939        },
216940        {
216941          "type": "library",
216942          "bom-ref": "pkg:npm/caw@2.0.1?package-id=bc45252557842f91",
216943          "supplier": {},
216944          "name": "caw",
216945          "version": "2.0.1",
216946          "licenses": [
216947            {
216948              "license": {
216949                "id": "MIT"
216950              }
216951            }
216952          ],
216953          "cpe": "cpe:2.3:a:caw:caw:2.0.1:*:*:*:*:*:*:*",
216954          "purl": "pkg:npm/caw@2.0.1",
216955          "swid": {
216956            "attachment": {}
216957          },
216958          "pedigree": {},
216959          "evidence": {},
216960          "signature": {
216961            "signature": {
216962              "publicKey": {}
216963            }
216964          },
216965          "modelCard": {
216966            "modelParameters": {
216967              "approach": {}
216968            },
216969            "quantitativeAnalysis": {
216970              "graphics": {}
216971            },
216972            "considerations": {}
216973          }
216974        },
216975        {
216976          "type": "library",
216977          "bom-ref": "pkg:npm/chainsaw@0.1.0?package-id=c10b4be093e9a307",
216978          "supplier": {},
216979          "name": "chainsaw",
216980          "version": "0.1.0",
216981          "licenses": [
216982            {
216983              "license": {
216984                "name": "MIT/X11"
216985              }
216986            }
216987          ],
216988          "cpe": "cpe:2.3:a:chainsaw:chainsaw:0.1.0:*:*:*:*:*:*:*",
216989          "purl": "pkg:npm/chainsaw@0.1.0",
216990          "swid": {
216991            "attachment": {}
216992          },
216993          "pedigree": {},
216994          "evidence": {},
216995          "signature": {
216996            "signature": {
216997              "publicKey": {}
216998            }
216999          },
217000          "modelCard": {
217001            "modelParameters": {
217002              "approach": {}
217003            },
217004            "quantitativeAnalysis": {
217005              "graphics": {}
217006            },
217007            "considerations": {}
217008          }
217009        },
217010        {
217011          "type": "library",
217012          "bom-ref": "pkg:npm/charenc@0.0.2?package-id=9a85c18b5f28e52c",
217013          "supplier": {},
217014          "name": "charenc",
217015          "version": "0.0.2",
217016          "licenses": [
217017            {
217018              "license": {
217019                "id": "BSD-3-Clause"
217020              }
217021            }
217022          ],
217023          "cpe": "cpe:2.3:a:charenc:charenc:0.0.2:*:*:*:*:*:*:*",
217024          "purl": "pkg:npm/charenc@0.0.2",
217025          "swid": {
217026            "attachment": {}
217027          },
217028          "pedigree": {},
217029          "evidence": {},
217030          "signature": {
217031            "signature": {
217032              "publicKey": {}
217033            }
217034          },
217035          "modelCard": {
217036            "modelParameters": {
217037              "approach": {}
217038            },
217039            "quantitativeAnalysis": {
217040              "graphics": {}
217041            },
217042            "considerations": {}
217043          }
217044        },
217045        {
217046          "type": "library",
217047          "bom-ref": "pkg:npm/chownr@1.1.4?package-id=8b60213f0177e0",
217048          "supplier": {},
217049          "name": "chownr",
217050          "version": "1.1.4",
217051          "licenses": [
217052            {
217053              "license": {
217054                "id": "ISC"
217055              }
217056            }
217057          ],
217058          "cpe": "cpe:2.3:a:chownr:chownr:1.1.4:*:*:*:*:*:*:*",
217059          "purl": "pkg:npm/chownr@1.1.4",
217060          "swid": {
217061            "attachment": {}
217062          },
217063          "pedigree": {},
217064          "evidence": {},
217065          "signature": {
217066            "signature": {
217067              "publicKey": {}
217068            }
217069          },
217070          "modelCard": {
217071            "modelParameters": {
217072              "approach": {}
217073            },
217074            "quantitativeAnalysis": {
217075              "graphics": {}
217076            },
217077            "considerations": {}
217078          }
217079        },
217080        {
217081          "type": "library",
217082          "bom-ref": "pkg:npm/cliui@8.0.1?package-id=50dbf73e876c2553",
217083          "supplier": {},
217084          "name": "cliui",
217085          "version": "8.0.1",
217086          "licenses": [
217087            {
217088              "license": {
217089                "id": "ISC"
217090              }
217091            }
217092          ],
217093          "cpe": "cpe:2.3:a:cliui:cliui:8.0.1:*:*:*:*:*:*:*",
217094          "purl": "pkg:npm/cliui@8.0.1",
217095          "swid": {
217096            "attachment": {}
217097          },
217098          "pedigree": {},
217099          "evidence": {},
217100          "signature": {
217101            "signature": {
217102              "publicKey": {}
217103            }
217104          },
217105          "modelCard": {
217106            "modelParameters": {
217107              "approach": {}
217108            },
217109            "quantitativeAnalysis": {
217110              "graphics": {}
217111            },
217112            "considerations": {}
217113          }
217114        },
217115        {
217116          "type": "library",
217117          "bom-ref": "pkg:npm/clone@2.1.2?package-id=4b667ae9156999fe",
217118          "supplier": {},
217119          "name": "clone",
217120          "version": "2.1.2",
217121          "licenses": [
217122            {
217123              "license": {
217124                "id": "MIT"
217125              }
217126            }
217127          ],
217128          "cpe": "cpe:2.3:a:clone:clone:2.1.2:*:*:*:*:*:*:*",
217129          "purl": "pkg:npm/clone@2.1.2",
217130          "swid": {
217131            "attachment": {}
217132          },
217133          "pedigree": {},
217134          "evidence": {},
217135          "signature": {
217136            "signature": {
217137              "publicKey": {}
217138            }
217139          },
217140          "modelCard": {
217141            "modelParameters": {
217142              "approach": {}
217143            },
217144            "quantitativeAnalysis": {
217145              "graphics": {}
217146            },
217147            "considerations": {}
217148          }
217149        },
217150        {
217151          "type": "library",
217152          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=7079296802bc0a1c",
217153          "supplier": {},
217154          "name": "color-convert",
217155          "version": "2.0.1",
217156          "licenses": [
217157            {
217158              "license": {
217159                "id": "MIT"
217160              }
217161            }
217162          ],
217163          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
217164          "purl": "pkg:npm/color-convert@2.0.1",
217165          "swid": {
217166            "attachment": {}
217167          },
217168          "pedigree": {},
217169          "evidence": {},
217170          "signature": {
217171            "signature": {
217172              "publicKey": {}
217173            }
217174          },
217175          "modelCard": {
217176            "modelParameters": {
217177              "approach": {}
217178            },
217179            "quantitativeAnalysis": {
217180              "graphics": {}
217181            },
217182            "considerations": {}
217183          }
217184        },
217185        {
217186          "type": "library",
217187          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=ac535df053d9fcde",
217188          "supplier": {},
217189          "name": "color-name",
217190          "version": "1.1.4",
217191          "licenses": [
217192            {
217193              "license": {
217194                "id": "MIT"
217195              }
217196            }
217197          ],
217198          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
217199          "purl": "pkg:npm/color-name@1.1.4",
217200          "swid": {
217201            "attachment": {}
217202          },
217203          "pedigree": {},
217204          "evidence": {},
217205          "signature": {
217206            "signature": {
217207              "publicKey": {}
217208            }
217209          },
217210          "modelCard": {
217211            "modelParameters": {
217212              "approach": {}
217213            },
217214            "quantitativeAnalysis": {
217215              "graphics": {}
217216            },
217217            "considerations": {}
217218          }
217219        },
217220        {
217221          "type": "library",
217222          "bom-ref": "pkg:npm/combined-stream@1.0.7?package-id=1b6c31aba554d18d",
217223          "supplier": {},
217224          "name": "combined-stream",
217225          "version": "1.0.7",
217226          "licenses": [
217227            {
217228              "license": {
217229                "id": "MIT"
217230              }
217231            }
217232          ],
217233          "cpe": "cpe:2.3:a:combined-stream:combined-stream:1.0.7:*:*:*:*:*:*:*",
217234          "purl": "pkg:npm/combined-stream@1.0.7",
217235          "swid": {
217236            "attachment": {}
217237          },
217238          "pedigree": {},
217239          "evidence": {},
217240          "signature": {
217241            "signature": {
217242              "publicKey": {}
217243            }
217244          },
217245          "modelCard": {
217246            "modelParameters": {
217247              "approach": {}
217248            },
217249            "quantitativeAnalysis": {
217250              "graphics": {}
217251            },
217252            "considerations": {}
217253          }
217254        },
217255        {
217256          "type": "library",
217257          "bom-ref": "pkg:npm/commander@2.20.3?package-id=c0490df2a859f33d",
217258          "supplier": {},
217259          "name": "commander",
217260          "version": "2.20.3",
217261          "licenses": [
217262            {
217263              "license": {
217264                "id": "MIT"
217265              }
217266            }
217267          ],
217268          "cpe": "cpe:2.3:a:commander:commander:2.20.3:*:*:*:*:*:*:*",
217269          "purl": "pkg:npm/commander@2.20.3",
217270          "swid": {
217271            "attachment": {}
217272          },
217273          "pedigree": {},
217274          "evidence": {},
217275          "signature": {
217276            "signature": {
217277              "publicKey": {}
217278            }
217279          },
217280          "modelCard": {
217281            "modelParameters": {
217282              "approach": {}
217283            },
217284            "quantitativeAnalysis": {
217285              "graphics": {}
217286            },
217287            "considerations": {}
217288          }
217289        },
217290        {
217291          "type": "library",
217292          "bom-ref": "pkg:npm/commist@1.1.0?package-id=79067e2b11ef98ef",
217293          "supplier": {},
217294          "name": "commist",
217295          "version": "1.1.0",
217296          "licenses": [
217297            {
217298              "license": {
217299                "id": "MIT"
217300              }
217301            }
217302          ],
217303          "cpe": "cpe:2.3:a:commist:commist:1.1.0:*:*:*:*:*:*:*",
217304          "purl": "pkg:npm/commist@1.1.0",
217305          "swid": {
217306            "attachment": {}
217307          },
217308          "pedigree": {},
217309          "evidence": {},
217310          "signature": {
217311            "signature": {
217312              "publicKey": {}
217313            }
217314          },
217315          "modelCard": {
217316            "modelParameters": {
217317              "approach": {}
217318            },
217319            "quantitativeAnalysis": {
217320              "graphics": {}
217321            },
217322            "considerations": {}
217323          }
217324        },
217325        {
217326          "type": "library",
217327          "bom-ref": "pkg:npm/compress-commons@4.1.1?package-id=ec9310f12bf9f6e5",
217328          "supplier": {},
217329          "name": "compress-commons",
217330          "version": "4.1.1",
217331          "licenses": [
217332            {
217333              "license": {
217334                "id": "MIT"
217335              }
217336            }
217337          ],
217338          "cpe": "cpe:2.3:a:compress-commons:compress-commons:4.1.1:*:*:*:*:*:*:*",
217339          "purl": "pkg:npm/compress-commons@4.1.1",
217340          "swid": {
217341            "attachment": {}
217342          },
217343          "pedigree": {},
217344          "evidence": {},
217345          "signature": {
217346            "signature": {
217347              "publicKey": {}
217348            }
217349          },
217350          "modelCard": {
217351            "modelParameters": {
217352              "approach": {}
217353            },
217354            "quantitativeAnalysis": {
217355              "graphics": {}
217356            },
217357            "considerations": {}
217358          }
217359        },
217360        {
217361          "type": "library",
217362          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=9a019e4863875fb3",
217363          "supplier": {},
217364          "name": "concat-map",
217365          "version": "0.0.1",
217366          "licenses": [
217367            {
217368              "license": {
217369                "id": "MIT"
217370              }
217371            }
217372          ],
217373          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
217374          "purl": "pkg:npm/concat-map@0.0.1",
217375          "swid": {
217376            "attachment": {}
217377          },
217378          "pedigree": {},
217379          "evidence": {},
217380          "signature": {
217381            "signature": {
217382              "publicKey": {}
217383            }
217384          },
217385          "modelCard": {
217386            "modelParameters": {
217387              "approach": {}
217388            },
217389            "quantitativeAnalysis": {
217390              "graphics": {}
217391            },
217392            "considerations": {}
217393          }
217394        },
217395        {
217396          "type": "library",
217397          "bom-ref": "pkg:npm/concat-stream@2.0.0?package-id=a7264ebd9a657cd7",
217398          "supplier": {},
217399          "name": "concat-stream",
217400          "version": "2.0.0",
217401          "licenses": [
217402            {
217403              "license": {
217404                "id": "MIT"
217405              }
217406            }
217407          ],
217408          "cpe": "cpe:2.3:a:concat-stream:concat-stream:2.0.0:*:*:*:*:*:*:*",
217409          "purl": "pkg:npm/concat-stream@2.0.0",
217410          "swid": {
217411            "attachment": {}
217412          },
217413          "pedigree": {},
217414          "evidence": {},
217415          "signature": {
217416            "signature": {
217417              "publicKey": {}
217418            }
217419          },
217420          "modelCard": {
217421            "modelParameters": {
217422              "approach": {}
217423            },
217424            "quantitativeAnalysis": {
217425              "graphics": {}
217426            },
217427            "considerations": {}
217428          }
217429        },
217430        {
217431          "type": "library",
217432          "bom-ref": "pkg:npm/config-chain@1.1.13?package-id=dbc6192261bb775b",
217433          "supplier": {},
217434          "name": "config-chain",
217435          "version": "1.1.13",
217436          "licenses": [
217437            {
217438              "license": {
217439                "id": "MIT"
217440              }
217441            }
217442          ],
217443          "cpe": "cpe:2.3:a:config-chain:config-chain:1.1.13:*:*:*:*:*:*:*",
217444          "purl": "pkg:npm/config-chain@1.1.13",
217445          "swid": {
217446            "attachment": {}
217447          },
217448          "pedigree": {},
217449          "evidence": {},
217450          "signature": {
217451            "signature": {
217452              "publicKey": {}
217453            }
217454          },
217455          "modelCard": {
217456            "modelParameters": {
217457              "approach": {}
217458            },
217459            "quantitativeAnalysis": {
217460              "graphics": {}
217461            },
217462            "considerations": {}
217463          }
217464        },
217465        {
217466          "type": "library",
217467          "bom-ref": "pkg:npm/content-disposition@0.5.4?package-id=3f23125685d33bb1",
217468          "supplier": {},
217469          "name": "content-disposition",
217470          "version": "0.5.4",
217471          "licenses": [
217472            {
217473              "license": {
217474                "id": "MIT"
217475              }
217476            }
217477          ],
217478          "cpe": "cpe:2.3:a:content-disposition:content-disposition:0.5.4:*:*:*:*:*:*:*",
217479          "purl": "pkg:npm/content-disposition@0.5.4",
217480          "swid": {
217481            "attachment": {}
217482          },
217483          "pedigree": {},
217484          "evidence": {},
217485          "signature": {
217486            "signature": {
217487              "publicKey": {}
217488            }
217489          },
217490          "modelCard": {
217491            "modelParameters": {
217492              "approach": {}
217493            },
217494            "quantitativeAnalysis": {
217495              "graphics": {}
217496            },
217497            "considerations": {}
217498          }
217499        },
217500        {
217501          "type": "library",
217502          "bom-ref": "pkg:npm/cookie@0.4.2?package-id=8fb98f10137c1f52",
217503          "supplier": {},
217504          "name": "cookie",
217505          "version": "0.4.2",
217506          "licenses": [
217507            {
217508              "license": {
217509                "id": "MIT"
217510              }
217511            }
217512          ],
217513          "cpe": "cpe:2.3:a:cookie:cookie:0.4.2:*:*:*:*:*:*:*",
217514          "purl": "pkg:npm/cookie@0.4.2",
217515          "swid": {
217516            "attachment": {}
217517          },
217518          "pedigree": {},
217519          "evidence": {},
217520          "signature": {
217521            "signature": {
217522              "publicKey": {}
217523            }
217524          },
217525          "modelCard": {
217526            "modelParameters": {
217527              "approach": {}
217528            },
217529            "quantitativeAnalysis": {
217530              "graphics": {}
217531            },
217532            "considerations": {}
217533          }
217534        },
217535        {
217536          "type": "library",
217537          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=fec8addd97f2c2cb",
217538          "supplier": {},
217539          "name": "core-util-is",
217540          "version": "1.0.2",
217541          "licenses": [
217542            {
217543              "license": {
217544                "id": "MIT"
217545              }
217546            }
217547          ],
217548          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
217549          "purl": "pkg:npm/core-util-is@1.0.2",
217550          "swid": {
217551            "attachment": {}
217552          },
217553          "pedigree": {},
217554          "evidence": {},
217555          "signature": {
217556            "signature": {
217557              "publicKey": {}
217558            }
217559          },
217560          "modelCard": {
217561            "modelParameters": {
217562              "approach": {}
217563            },
217564            "quantitativeAnalysis": {
217565              "graphics": {}
217566            },
217567            "considerations": {}
217568          }
217569        },
217570        {
217571          "type": "library",
217572          "bom-ref": "pkg:npm/cpu-features@0.0.7?package-id=1c9e7a840a1d5000",
217573          "supplier": {},
217574          "name": "cpu-features",
217575          "version": "0.0.7",
217576          "cpe": "cpe:2.3:a:cpu-features:cpu-features:0.0.7:*:*:*:*:*:*:*",
217577          "purl": "pkg:npm/cpu-features@0.0.7",
217578          "swid": {
217579            "attachment": {}
217580          },
217581          "pedigree": {},
217582          "evidence": {},
217583          "signature": {
217584            "signature": {
217585              "publicKey": {}
217586            }
217587          },
217588          "modelCard": {
217589            "modelParameters": {
217590              "approach": {}
217591            },
217592            "quantitativeAnalysis": {
217593              "graphics": {}
217594            },
217595            "considerations": {}
217596          }
217597        },
217598        {
217599          "type": "library",
217600          "bom-ref": "pkg:npm/crc-32@1.2.2?package-id=24b44b7c5a36d590",
217601          "supplier": {},
217602          "name": "crc-32",
217603          "version": "1.2.2",
217604          "licenses": [
217605            {
217606              "license": {
217607                "id": "Apache-2.0"
217608              }
217609            }
217610          ],
217611          "cpe": "cpe:2.3:a:crc-32:crc-32:1.2.2:*:*:*:*:*:*:*",
217612          "purl": "pkg:npm/crc-32@1.2.2",
217613          "swid": {
217614            "attachment": {}
217615          },
217616          "pedigree": {},
217617          "evidence": {},
217618          "signature": {
217619            "signature": {
217620              "publicKey": {}
217621            }
217622          },
217623          "modelCard": {
217624            "modelParameters": {
217625              "approach": {}
217626            },
217627            "quantitativeAnalysis": {
217628              "graphics": {}
217629            },
217630            "considerations": {}
217631          }
217632        },
217633        {
217634          "type": "library",
217635          "bom-ref": "pkg:npm/crc32-stream@4.0.2?package-id=14c2c8f54fab2e75",
217636          "supplier": {},
217637          "name": "crc32-stream",
217638          "version": "4.0.2",
217639          "licenses": [
217640            {
217641              "license": {
217642                "id": "MIT"
217643              }
217644            }
217645          ],
217646          "cpe": "cpe:2.3:a:crc32-stream:crc32-stream:4.0.2:*:*:*:*:*:*:*",
217647          "purl": "pkg:npm/crc32-stream@4.0.2",
217648          "swid": {
217649            "attachment": {}
217650          },
217651          "pedigree": {},
217652          "evidence": {},
217653          "signature": {
217654            "signature": {
217655              "publicKey": {}
217656            }
217657          },
217658          "modelCard": {
217659            "modelParameters": {
217660              "approach": {}
217661            },
217662            "quantitativeAnalysis": {
217663              "graphics": {}
217664            },
217665            "considerations": {}
217666          }
217667        },
217668        {
217669          "type": "library",
217670          "bom-ref": "pkg:npm/cross-spawn@5.1.0?package-id=da550a6c41ddb04d",
217671          "supplier": {},
217672          "name": "cross-spawn",
217673          "version": "5.1.0",
217674          "licenses": [
217675            {
217676              "license": {
217677                "id": "MIT"
217678              }
217679            }
217680          ],
217681          "cpe": "cpe:2.3:a:cross-spawn:cross-spawn:5.1.0:*:*:*:*:*:*:*",
217682          "purl": "pkg:npm/cross-spawn@5.1.0",
217683          "swid": {
217684            "attachment": {}
217685          },
217686          "pedigree": {},
217687          "evidence": {},
217688          "signature": {
217689            "signature": {
217690              "publicKey": {}
217691            }
217692          },
217693          "modelCard": {
217694            "modelParameters": {
217695              "approach": {}
217696            },
217697            "quantitativeAnalysis": {
217698              "graphics": {}
217699            },
217700            "considerations": {}
217701          }
217702        },
217703        {
217704          "type": "library",
217705          "bom-ref": "pkg:npm/crypt@0.0.2?package-id=da721c03add8f70a",
217706          "supplier": {},
217707          "name": "crypt",
217708          "version": "0.0.2",
217709          "licenses": [
217710            {
217711              "license": {
217712                "id": "BSD-3-Clause"
217713              }
217714            }
217715          ],
217716          "cpe": "cpe:2.3:a:crypt:crypt:0.0.2:*:*:*:*:*:*:*",
217717          "purl": "pkg:npm/crypt@0.0.2",
217718          "swid": {
217719            "attachment": {}
217720          },
217721          "pedigree": {},
217722          "evidence": {},
217723          "signature": {
217724            "signature": {
217725              "publicKey": {}
217726            }
217727          },
217728          "modelCard": {
217729            "modelParameters": {
217730              "approach": {}
217731            },
217732            "quantitativeAnalysis": {
217733              "graphics": {}
217734            },
217735            "considerations": {}
217736          }
217737        },
217738        {
217739          "type": "library",
217740          "bom-ref": "pkg:npm/dank-each@1.0.0?package-id=933fd4351eef0e51",
217741          "supplier": {},
217742          "name": "dank-each",
217743          "version": "1.0.0",
217744          "licenses": [
217745            {
217746              "license": {
217747                "id": "MIT"
217748              }
217749            }
217750          ],
217751          "cpe": "cpe:2.3:a:dank-each:dank-each:1.0.0:*:*:*:*:*:*:*",
217752          "purl": "pkg:npm/dank-each@1.0.0",
217753          "swid": {
217754            "attachment": {}
217755          },
217756          "pedigree": {},
217757          "evidence": {},
217758          "signature": {
217759            "signature": {
217760              "publicKey": {}
217761            }
217762          },
217763          "modelCard": {
217764            "modelParameters": {
217765              "approach": {}
217766            },
217767            "quantitativeAnalysis": {
217768              "graphics": {}
217769            },
217770            "considerations": {}
217771          }
217772        },
217773        {
217774          "type": "library",
217775          "bom-ref": "pkg:npm/dank-map@0.1.0?package-id=dcb70e5d584759cd",
217776          "supplier": {},
217777          "name": "dank-map",
217778          "version": "0.1.0",
217779          "licenses": [
217780            {
217781              "license": {
217782                "id": "MIT"
217783              }
217784            }
217785          ],
217786          "cpe": "cpe:2.3:a:dank-map:dank-map:0.1.0:*:*:*:*:*:*:*",
217787          "purl": "pkg:npm/dank-map@0.1.0",
217788          "swid": {
217789            "attachment": {}
217790          },
217791          "pedigree": {},
217792          "evidence": {},
217793          "signature": {
217794            "signature": {
217795              "publicKey": {}
217796            }
217797          },
217798          "modelCard": {
217799            "modelParameters": {
217800              "approach": {}
217801            },
217802            "quantitativeAnalysis": {
217803              "graphics": {}
217804            },
217805            "considerations": {}
217806          }
217807        },
217808        {
217809          "type": "library",
217810          "bom-ref": "pkg:npm/dashdash@1.14.1?package-id=1f0eeaff816ac0ca",
217811          "supplier": {},
217812          "name": "dashdash",
217813          "version": "1.14.1",
217814          "licenses": [
217815            {
217816              "license": {
217817                "id": "MIT"
217818              }
217819            }
217820          ],
217821          "cpe": "cpe:2.3:a:dashdash:dashdash:1.14.1:*:*:*:*:*:*:*",
217822          "purl": "pkg:npm/dashdash@1.14.1",
217823          "swid": {
217824            "attachment": {}
217825          },
217826          "pedigree": {},
217827          "evidence": {},
217828          "signature": {
217829            "signature": {
217830              "publicKey": {}
217831            }
217832          },
217833          "modelCard": {
217834            "modelParameters": {
217835              "approach": {}
217836            },
217837            "quantitativeAnalysis": {
217838              "graphics": {}
217839            },
217840            "considerations": {}
217841          }
217842        },
217843        {
217844          "type": "library",
217845          "bom-ref": "pkg:npm/date-utils@1.2.21?package-id=e6015b34c2d44f1",
217846          "supplier": {},
217847          "name": "date-utils",
217848          "version": "1.2.21",
217849          "licenses": [
217850            {
217851              "license": {
217852                "id": "MIT"
217853              }
217854            }
217855          ],
217856          "cpe": "cpe:2.3:a:date-utils:date-utils:1.2.21:*:*:*:*:*:*:*",
217857          "purl": "pkg:npm/date-utils@1.2.21",
217858          "swid": {
217859            "attachment": {}
217860          },
217861          "pedigree": {},
217862          "evidence": {},
217863          "signature": {
217864            "signature": {
217865              "publicKey": {}
217866            }
217867          },
217868          "modelCard": {
217869            "modelParameters": {
217870              "approach": {}
217871            },
217872            "quantitativeAnalysis": {
217873              "graphics": {}
217874            },
217875            "considerations": {}
217876          }
217877        },
217878        {
217879          "type": "library",
217880          "bom-ref": "pkg:npm/dayjs@1.11.7?package-id=c02da3e262cb73c9",
217881          "supplier": {},
217882          "name": "dayjs",
217883          "version": "1.11.7",
217884          "licenses": [
217885            {
217886              "license": {
217887                "id": "MIT"
217888              }
217889            }
217890          ],
217891          "cpe": "cpe:2.3:a:dayjs:dayjs:1.11.7:*:*:*:*:*:*:*",
217892          "purl": "pkg:npm/dayjs@1.11.7",
217893          "swid": {
217894            "attachment": {}
217895          },
217896          "pedigree": {},
217897          "evidence": {},
217898          "signature": {
217899            "signature": {
217900              "publicKey": {}
217901            }
217902          },
217903          "modelCard": {
217904            "modelParameters": {
217905              "approach": {}
217906            },
217907            "quantitativeAnalysis": {
217908              "graphics": {}
217909            },
217910            "considerations": {}
217911          }
217912        },
217913        {
217914          "type": "library",
217915          "bom-ref": "pkg:npm/debug@2.6.9?package-id=33eed526d342c333",
217916          "supplier": {},
217917          "name": "debug",
217918          "version": "2.6.9",
217919          "licenses": [
217920            {
217921              "license": {
217922                "id": "MIT"
217923              }
217924            }
217925          ],
217926          "cpe": "cpe:2.3:a:debug:debug:2.6.9:*:*:*:*:*:*:*",
217927          "purl": "pkg:npm/debug@2.6.9",
217928          "swid": {
217929            "attachment": {}
217930          },
217931          "pedigree": {},
217932          "evidence": {},
217933          "signature": {
217934            "signature": {
217935              "publicKey": {}
217936            }
217937          },
217938          "modelCard": {
217939            "modelParameters": {
217940              "approach": {}
217941            },
217942            "quantitativeAnalysis": {
217943              "graphics": {}
217944            },
217945            "considerations": {}
217946          }
217947        },
217948        {
217949          "type": "library",
217950          "bom-ref": "pkg:npm/decompress@4.2.1?package-id=5ea82c39344b2b2f",
217951          "supplier": {},
217952          "name": "decompress",
217953          "version": "4.2.1",
217954          "licenses": [
217955            {
217956              "license": {
217957                "id": "MIT"
217958              }
217959            }
217960          ],
217961          "cpe": "cpe:2.3:a:decompress:decompress:4.2.1:*:*:*:*:*:*:*",
217962          "purl": "pkg:npm/decompress@4.2.1",
217963          "swid": {
217964            "attachment": {}
217965          },
217966          "pedigree": {},
217967          "evidence": {},
217968          "signature": {
217969            "signature": {
217970              "publicKey": {}
217971            }
217972          },
217973          "modelCard": {
217974            "modelParameters": {
217975              "approach": {}
217976            },
217977            "quantitativeAnalysis": {
217978              "graphics": {}
217979            },
217980            "considerations": {}
217981          }
217982        },
217983        {
217984          "type": "library",
217985          "bom-ref": "pkg:npm/decompress-response@6.0.0?package-id=a5fd823feaa67a50",
217986          "supplier": {},
217987          "name": "decompress-response",
217988          "version": "6.0.0",
217989          "licenses": [
217990            {
217991              "license": {
217992                "id": "MIT"
217993              }
217994            }
217995          ],
217996          "cpe": "cpe:2.3:a:decompress-response:decompress-response:6.0.0:*:*:*:*:*:*:*",
217997          "purl": "pkg:npm/decompress-response@6.0.0",
217998          "swid": {
217999            "attachment": {}
218000          },
218001          "pedigree": {},
218002          "evidence": {},
218003          "signature": {
218004            "signature": {
218005              "publicKey": {}
218006            }
218007          },
218008          "modelCard": {
218009            "modelParameters": {
218010              "approach": {}
218011            },
218012            "quantitativeAnalysis": {
218013              "graphics": {}
218014            },
218015            "considerations": {}
218016          }
218017        },
218018        {
218019          "type": "library",
218020          "bom-ref": "pkg:npm/decompress-tar@4.1.1?package-id=41aeb43f6bc07d01",
218021          "supplier": {},
218022          "name": "decompress-tar",
218023          "version": "4.1.1",
218024          "licenses": [
218025            {
218026              "license": {
218027                "id": "MIT"
218028              }
218029            }
218030          ],
218031          "cpe": "cpe:2.3:a:decompress-tar:decompress-tar:4.1.1:*:*:*:*:*:*:*",
218032          "purl": "pkg:npm/decompress-tar@4.1.1",
218033          "swid": {
218034            "attachment": {}
218035          },
218036          "pedigree": {},
218037          "evidence": {},
218038          "signature": {
218039            "signature": {
218040              "publicKey": {}
218041            }
218042          },
218043          "modelCard": {
218044            "modelParameters": {
218045              "approach": {}
218046            },
218047            "quantitativeAnalysis": {
218048              "graphics": {}
218049            },
218050            "considerations": {}
218051          }
218052        },
218053        {
218054          "type": "library",
218055          "bom-ref": "pkg:npm/decompress-tarbz2@4.1.1?package-id=385b191ddfa126cf",
218056          "supplier": {},
218057          "name": "decompress-tarbz2",
218058          "version": "4.1.1",
218059          "licenses": [
218060            {
218061              "license": {
218062                "id": "MIT"
218063              }
218064            }
218065          ],
218066          "cpe": "cpe:2.3:a:decompress-tarbz2:decompress-tarbz2:4.1.1:*:*:*:*:*:*:*",
218067          "purl": "pkg:npm/decompress-tarbz2@4.1.1",
218068          "swid": {
218069            "attachment": {}
218070          },
218071          "pedigree": {},
218072          "evidence": {},
218073          "signature": {
218074            "signature": {
218075              "publicKey": {}
218076            }
218077          },
218078          "modelCard": {
218079            "modelParameters": {
218080              "approach": {}
218081            },
218082            "quantitativeAnalysis": {
218083              "graphics": {}
218084            },
218085            "considerations": {}
218086          }
218087        },
218088        {
218089          "type": "library",
218090          "bom-ref": "pkg:npm/decompress-targz@4.1.1?package-id=b1f1020b832cf5e6",
218091          "supplier": {},
218092          "name": "decompress-targz",
218093          "version": "4.1.1",
218094          "licenses": [
218095            {
218096              "license": {
218097                "id": "MIT"
218098              }
218099            }
218100          ],
218101          "cpe": "cpe:2.3:a:decompress-targz:decompress-targz:4.1.1:*:*:*:*:*:*:*",
218102          "purl": "pkg:npm/decompress-targz@4.1.1",
218103          "swid": {
218104            "attachment": {}
218105          },
218106          "pedigree": {},
218107          "evidence": {},
218108          "signature": {
218109            "signature": {
218110              "publicKey": {}
218111            }
218112          },
218113          "modelCard": {
218114            "modelParameters": {
218115              "approach": {}
218116            },
218117            "quantitativeAnalysis": {
218118              "graphics": {}
218119            },
218120            "considerations": {}
218121          }
218122        },
218123        {
218124          "type": "library",
218125          "bom-ref": "pkg:npm/decompress-unzip@4.0.1?package-id=14b41b679c8fae88",
218126          "supplier": {},
218127          "name": "decompress-unzip",
218128          "version": "4.0.1",
218129          "licenses": [
218130            {
218131              "license": {
218132                "id": "MIT"
218133              }
218134            }
218135          ],
218136          "cpe": "cpe:2.3:a:decompress-unzip:decompress-unzip:4.0.1:*:*:*:*:*:*:*",
218137          "purl": "pkg:npm/decompress-unzip@4.0.1",
218138          "swid": {
218139            "attachment": {}
218140          },
218141          "pedigree": {},
218142          "evidence": {},
218143          "signature": {
218144            "signature": {
218145              "publicKey": {}
218146            }
218147          },
218148          "modelCard": {
218149            "modelParameters": {
218150              "approach": {}
218151            },
218152            "quantitativeAnalysis": {
218153              "graphics": {}
218154            },
218155            "considerations": {}
218156          }
218157        },
218158        {
218159          "type": "library",
218160          "bom-ref": "pkg:npm/deep-extend@0.6.0?package-id=20cca47651026adb",
218161          "supplier": {},
218162          "name": "deep-extend",
218163          "version": "0.6.0",
218164          "licenses": [
218165            {
218166              "license": {
218167                "id": "MIT"
218168              }
218169            }
218170          ],
218171          "cpe": "cpe:2.3:a:deep-extend:deep-extend:0.6.0:*:*:*:*:*:*:*",
218172          "purl": "pkg:npm/deep-extend@0.6.0",
218173          "swid": {
218174            "attachment": {}
218175          },
218176          "pedigree": {},
218177          "evidence": {},
218178          "signature": {
218179            "signature": {
218180              "publicKey": {}
218181            }
218182          },
218183          "modelCard": {
218184            "modelParameters": {
218185              "approach": {}
218186            },
218187            "quantitativeAnalysis": {
218188              "graphics": {}
218189            },
218190            "considerations": {}
218191          }
218192        },
218193        {
218194          "type": "library",
218195          "bom-ref": "pkg:npm/delayed-stream@1.0.0?package-id=cd45040a62713265",
218196          "supplier": {},
218197          "name": "delayed-stream",
218198          "version": "1.0.0",
218199          "licenses": [
218200            {
218201              "license": {
218202                "id": "MIT"
218203              }
218204            }
218205          ],
218206          "cpe": "cpe:2.3:a:delayed-stream:delayed-stream:1.0.0:*:*:*:*:*:*:*",
218207          "purl": "pkg:npm/delayed-stream@1.0.0",
218208          "swid": {
218209            "attachment": {}
218210          },
218211          "pedigree": {},
218212          "evidence": {},
218213          "signature": {
218214            "signature": {
218215              "publicKey": {}
218216            }
218217          },
218218          "modelCard": {
218219            "modelParameters": {
218220              "approach": {}
218221            },
218222            "quantitativeAnalysis": {
218223              "graphics": {}
218224            },
218225            "considerations": {}
218226          }
218227        },
218228        {
218229          "type": "library",
218230          "bom-ref": "pkg:npm/denque@1.5.1?package-id=9b802287f4ae9f3c",
218231          "supplier": {},
218232          "name": "denque",
218233          "version": "1.5.1",
218234          "licenses": [
218235            {
218236              "license": {
218237                "id": "Apache-2.0"
218238              }
218239            }
218240          ],
218241          "cpe": "cpe:2.3:a:denque:denque:1.5.1:*:*:*:*:*:*:*",
218242          "purl": "pkg:npm/denque@1.5.1",
218243          "swid": {
218244            "attachment": {}
218245          },
218246          "pedigree": {},
218247          "evidence": {},
218248          "signature": {
218249            "signature": {
218250              "publicKey": {}
218251            }
218252          },
218253          "modelCard": {
218254            "modelParameters": {
218255              "approach": {}
218256            },
218257            "quantitativeAnalysis": {
218258              "graphics": {}
218259            },
218260            "considerations": {}
218261          }
218262        },
218263        {
218264          "type": "library",
218265          "bom-ref": "pkg:npm/depd@2.0.0?package-id=6dbb13190f2f1d86",
218266          "supplier": {},
218267          "name": "depd",
218268          "version": "2.0.0",
218269          "licenses": [
218270            {
218271              "license": {
218272                "id": "MIT"
218273              }
218274            }
218275          ],
218276          "cpe": "cpe:2.3:a:depd:depd:2.0.0:*:*:*:*:*:*:*",
218277          "purl": "pkg:npm/depd@2.0.0",
218278          "swid": {
218279            "attachment": {}
218280          },
218281          "pedigree": {},
218282          "evidence": {},
218283          "signature": {
218284            "signature": {
218285              "publicKey": {}
218286            }
218287          },
218288          "modelCard": {
218289            "modelParameters": {
218290              "approach": {}
218291            },
218292            "quantitativeAnalysis": {
218293              "graphics": {}
218294            },
218295            "considerations": {}
218296          }
218297        },
218298        {
218299          "type": "library",
218300          "bom-ref": "pkg:npm/detect-libc@2.0.1?package-id=899b76cb317fecaa",
218301          "supplier": {},
218302          "name": "detect-libc",
218303          "version": "2.0.1",
218304          "licenses": [
218305            {
218306              "license": {
218307                "id": "Apache-2.0"
218308              }
218309            }
218310          ],
218311          "cpe": "cpe:2.3:a:detect-libc:detect-libc:2.0.1:*:*:*:*:*:*:*",
218312          "purl": "pkg:npm/detect-libc@2.0.1",
218313          "swid": {
218314            "attachment": {}
218315          },
218316          "pedigree": {},
218317          "evidence": {},
218318          "signature": {
218319            "signature": {
218320              "publicKey": {}
218321            }
218322          },
218323          "modelCard": {
218324            "modelParameters": {
218325              "approach": {}
218326            },
218327            "quantitativeAnalysis": {
218328              "graphics": {}
218329            },
218330            "considerations": {}
218331          }
218332        },
218333        {
218334          "type": "library",
218335          "bom-ref": "pkg:npm/diff@3.5.0?package-id=435d3990ee2bbf96",
218336          "supplier": {},
218337          "name": "diff",
218338          "version": "3.5.0",
218339          "licenses": [
218340            {
218341              "license": {
218342                "id": "BSD-3-Clause"
218343              }
218344            }
218345          ],
218346          "cpe": "cpe:2.3:a:diff:diff:3.5.0:*:*:*:*:*:*:*",
218347          "purl": "pkg:npm/diff@3.5.0",
218348          "swid": {
218349            "attachment": {}
218350          },
218351          "pedigree": {},
218352          "evidence": {},
218353          "signature": {
218354            "signature": {
218355              "publicKey": {}
218356            }
218357          },
218358          "modelCard": {
218359            "modelParameters": {
218360              "approach": {}
218361            },
218362            "quantitativeAnalysis": {
218363              "graphics": {}
218364            },
218365            "considerations": {}
218366          }
218367        },
218368        {
218369          "type": "library",
218370          "bom-ref": "pkg:npm/diff-lines@1.1.1?package-id=4c419e71a85bdeb8",
218371          "supplier": {},
218372          "name": "diff-lines",
218373          "version": "1.1.1",
218374          "licenses": [
218375            {
218376              "license": {
218377                "id": "MIT"
218378              }
218379            }
218380          ],
218381          "cpe": "cpe:2.3:a:diff-lines:diff-lines:1.1.1:*:*:*:*:*:*:*",
218382          "purl": "pkg:npm/diff-lines@1.1.1",
218383          "swid": {
218384            "attachment": {}
218385          },
218386          "pedigree": {},
218387          "evidence": {},
218388          "signature": {
218389            "signature": {
218390              "publicKey": {}
218391            }
218392          },
218393          "modelCard": {
218394            "modelParameters": {
218395              "approach": {}
218396            },
218397            "quantitativeAnalysis": {
218398              "graphics": {}
218399            },
218400            "considerations": {}
218401          }
218402        },
218403        {
218404          "type": "library",
218405          "bom-ref": "pkg:npm/download@6.2.5?package-id=4e52499ce165e54f",
218406          "supplier": {},
218407          "name": "download",
218408          "version": "6.2.5",
218409          "licenses": [
218410            {
218411              "license": {
218412                "id": "MIT"
218413              }
218414            }
218415          ],
218416          "cpe": "cpe:2.3:a:download:download:6.2.5:*:*:*:*:*:*:*",
218417          "purl": "pkg:npm/download@6.2.5",
218418          "swid": {
218419            "attachment": {}
218420          },
218421          "pedigree": {},
218422          "evidence": {},
218423          "signature": {
218424            "signature": {
218425              "publicKey": {}
218426            }
218427          },
218428          "modelCard": {
218429            "modelParameters": {
218430              "approach": {}
218431            },
218432            "quantitativeAnalysis": {
218433              "graphics": {}
218434            },
218435            "considerations": {}
218436          }
218437        },
218438        {
218439          "type": "library",
218440          "bom-ref": "pkg:npm/duplexer2@0.1.4?package-id=514036286bddf371",
218441          "supplier": {},
218442          "name": "duplexer2",
218443          "version": "0.1.4",
218444          "licenses": [
218445            {
218446              "license": {
218447                "id": "BSD-3-Clause"
218448              }
218449            }
218450          ],
218451          "cpe": "cpe:2.3:a:duplexer2:duplexer2:0.1.4:*:*:*:*:*:*:*",
218452          "purl": "pkg:npm/duplexer2@0.1.4",
218453          "swid": {
218454            "attachment": {}
218455          },
218456          "pedigree": {},
218457          "evidence": {},
218458          "signature": {
218459            "signature": {
218460              "publicKey": {}
218461            }
218462          },
218463          "modelCard": {
218464            "modelParameters": {
218465              "approach": {}
218466            },
218467            "quantitativeAnalysis": {
218468              "graphics": {}
218469            },
218470            "considerations": {}
218471          }
218472        },
218473        {
218474          "type": "library",
218475          "bom-ref": "pkg:npm/duplexer3@0.1.5?package-id=540712303e0e5020",
218476          "supplier": {},
218477          "name": "duplexer3",
218478          "version": "0.1.5",
218479          "licenses": [
218480            {
218481              "license": {
218482                "id": "BSD-3-Clause"
218483              }
218484            }
218485          ],
218486          "cpe": "cpe:2.3:a:duplexer3:duplexer3:0.1.5:*:*:*:*:*:*:*",
218487          "purl": "pkg:npm/duplexer3@0.1.5",
218488          "swid": {
218489            "attachment": {}
218490          },
218491          "pedigree": {},
218492          "evidence": {},
218493          "signature": {
218494            "signature": {
218495              "publicKey": {}
218496            }
218497          },
218498          "modelCard": {
218499            "modelParameters": {
218500              "approach": {}
218501            },
218502            "quantitativeAnalysis": {
218503              "graphics": {}
218504            },
218505            "considerations": {}
218506          }
218507        },
218508        {
218509          "type": "library",
218510          "bom-ref": "pkg:npm/duplexify@3.7.1?package-id=db63fa71104335d3",
218511          "supplier": {},
218512          "name": "duplexify",
218513          "version": "3.7.1",
218514          "licenses": [
218515            {
218516              "license": {
218517                "id": "MIT"
218518              }
218519            }
218520          ],
218521          "cpe": "cpe:2.3:a:duplexify:duplexify:3.7.1:*:*:*:*:*:*:*",
218522          "purl": "pkg:npm/duplexify@3.7.1",
218523          "swid": {
218524            "attachment": {}
218525          },
218526          "pedigree": {},
218527          "evidence": {},
218528          "signature": {
218529            "signature": {
218530              "publicKey": {}
218531            }
218532          },
218533          "modelCard": {
218534            "modelParameters": {
218535              "approach": {}
218536            },
218537            "quantitativeAnalysis": {
218538              "graphics": {}
218539            },
218540            "considerations": {}
218541          }
218542        },
218543        {
218544          "type": "library",
218545          "bom-ref": "pkg:npm/ecc-jsbn@0.1.2?package-id=cc938104d42b6760",
218546          "supplier": {},
218547          "name": "ecc-jsbn",
218548          "version": "0.1.2",
218549          "licenses": [
218550            {
218551              "license": {
218552                "id": "MIT"
218553              }
218554            }
218555          ],
218556          "cpe": "cpe:2.3:a:ecc-jsbn:ecc-jsbn:0.1.2:*:*:*:*:*:*:*",
218557          "purl": "pkg:npm/ecc-jsbn@0.1.2",
218558          "swid": {
218559            "attachment": {}
218560          },
218561          "pedigree": {},
218562          "evidence": {},
218563          "signature": {
218564            "signature": {
218565              "publicKey": {}
218566            }
218567          },
218568          "modelCard": {
218569            "modelParameters": {
218570              "approach": {}
218571            },
218572            "quantitativeAnalysis": {
218573              "graphics": {}
218574            },
218575            "considerations": {}
218576          }
218577        },
218578        {
218579          "type": "library",
218580          "bom-ref": "pkg:npm/ecdsa-sig-formatter@1.0.11?package-id=cf5becb712919066",
218581          "supplier": {},
218582          "name": "ecdsa-sig-formatter",
218583          "version": "1.0.11",
218584          "licenses": [
218585            {
218586              "license": {
218587                "id": "Apache-2.0"
218588              }
218589            }
218590          ],
218591          "cpe": "cpe:2.3:a:ecdsa-sig-formatter:ecdsa-sig-formatter:1.0.11:*:*:*:*:*:*:*",
218592          "purl": "pkg:npm/ecdsa-sig-formatter@1.0.11",
218593          "swid": {
218594            "attachment": {}
218595          },
218596          "pedigree": {},
218597          "evidence": {},
218598          "signature": {
218599            "signature": {
218600              "publicKey": {}
218601            }
218602          },
218603          "modelCard": {
218604            "modelParameters": {
218605              "approach": {}
218606            },
218607            "quantitativeAnalysis": {
218608              "graphics": {}
218609            },
218610            "considerations": {}
218611          }
218612        },
218613        {
218614          "type": "library",
218615          "bom-ref": "pkg:npm/emitter-component@1.1.1?package-id=eb972e58579069f9",
218616          "supplier": {},
218617          "name": "emitter-component",
218618          "version": "1.1.1",
218619          "cpe": "cpe:2.3:a:emitter-component:emitter-component:1.1.1:*:*:*:*:*:*:*",
218620          "purl": "pkg:npm/emitter-component@1.1.1",
218621          "swid": {
218622            "attachment": {}
218623          },
218624          "pedigree": {},
218625          "evidence": {},
218626          "signature": {
218627            "signature": {
218628              "publicKey": {}
218629            }
218630          },
218631          "modelCard": {
218632            "modelParameters": {
218633              "approach": {}
218634            },
218635            "quantitativeAnalysis": {
218636              "graphics": {}
218637            },
218638            "considerations": {}
218639          }
218640        },
218641        {
218642          "type": "library",
218643          "bom-ref": "pkg:npm/emoji-regex@8.0.0?package-id=99ba91235e6f01bb",
218644          "supplier": {},
218645          "name": "emoji-regex",
218646          "version": "8.0.0",
218647          "licenses": [
218648            {
218649              "license": {
218650                "id": "MIT"
218651              }
218652            }
218653          ],
218654          "cpe": "cpe:2.3:a:emoji-regex:emoji-regex:8.0.0:*:*:*:*:*:*:*",
218655          "purl": "pkg:npm/emoji-regex@8.0.0",
218656          "swid": {
218657            "attachment": {}
218658          },
218659          "pedigree": {},
218660          "evidence": {},
218661          "signature": {
218662            "signature": {
218663              "publicKey": {}
218664            }
218665          },
218666          "modelCard": {
218667            "modelParameters": {
218668              "approach": {}
218669            },
218670            "quantitativeAnalysis": {
218671              "graphics": {}
218672            },
218673            "considerations": {}
218674          }
218675        },
218676        {
218677          "type": "library",
218678          "bom-ref": "pkg:npm/end-of-stream@1.4.4?package-id=4e51e9b811cd77c1",
218679          "supplier": {},
218680          "name": "end-of-stream",
218681          "version": "1.4.4",
218682          "licenses": [
218683            {
218684              "license": {
218685                "id": "MIT"
218686              }
218687            }
218688          ],
218689          "cpe": "cpe:2.3:a:end-of-stream:end-of-stream:1.4.4:*:*:*:*:*:*:*",
218690          "purl": "pkg:npm/end-of-stream@1.4.4",
218691          "swid": {
218692            "attachment": {}
218693          },
218694          "pedigree": {},
218695          "evidence": {},
218696          "signature": {
218697            "signature": {
218698              "publicKey": {}
218699            }
218700          },
218701          "modelCard": {
218702            "modelParameters": {
218703              "approach": {}
218704            },
218705            "quantitativeAnalysis": {
218706              "graphics": {}
218707            },
218708            "considerations": {}
218709          }
218710        },
218711        {
218712          "type": "library",
218713          "bom-ref": "pkg:npm/err-code@2.0.3?package-id=ecdcdaf74466154b",
218714          "supplier": {},
218715          "name": "err-code",
218716          "version": "2.0.3",
218717          "licenses": [
218718            {
218719              "license": {
218720                "id": "MIT"
218721              }
218722            }
218723          ],
218724          "cpe": "cpe:2.3:a:err-code:err-code:2.0.3:*:*:*:*:*:*:*",
218725          "purl": "pkg:npm/err-code@2.0.3",
218726          "swid": {
218727            "attachment": {}
218728          },
218729          "pedigree": {},
218730          "evidence": {},
218731          "signature": {
218732            "signature": {
218733              "publicKey": {}
218734            }
218735          },
218736          "modelCard": {
218737            "modelParameters": {
218738              "approach": {}
218739            },
218740            "quantitativeAnalysis": {
218741              "graphics": {}
218742            },
218743            "considerations": {}
218744          }
218745        },
218746        {
218747          "type": "library",
218748          "bom-ref": "pkg:npm/escalade@3.1.1?package-id=cde689cfccaa7d77",
218749          "supplier": {},
218750          "name": "escalade",
218751          "version": "3.1.1",
218752          "licenses": [
218753            {
218754              "license": {
218755                "id": "MIT"
218756              }
218757            }
218758          ],
218759          "cpe": "cpe:2.3:a:escalade:escalade:3.1.1:*:*:*:*:*:*:*",
218760          "purl": "pkg:npm/escalade@3.1.1",
218761          "swid": {
218762            "attachment": {}
218763          },
218764          "pedigree": {},
218765          "evidence": {},
218766          "signature": {
218767            "signature": {
218768              "publicKey": {}
218769            }
218770          },
218771          "modelCard": {
218772            "modelParameters": {
218773              "approach": {}
218774            },
218775            "quantitativeAnalysis": {
218776              "graphics": {}
218777            },
218778            "considerations": {}
218779          }
218780        },
218781        {
218782          "type": "library",
218783          "bom-ref": "pkg:npm/escape-string-regexp@1.0.5?package-id=a5426e144b8bae0e",
218784          "supplier": {},
218785          "name": "escape-string-regexp",
218786          "version": "1.0.5",
218787          "licenses": [
218788            {
218789              "license": {
218790                "id": "MIT"
218791              }
218792            }
218793          ],
218794          "cpe": "cpe:2.3:a:escape-string-regexp:escape-string-regexp:1.0.5:*:*:*:*:*:*:*",
218795          "purl": "pkg:npm/escape-string-regexp@1.0.5",
218796          "swid": {
218797            "attachment": {}
218798          },
218799          "pedigree": {},
218800          "evidence": {},
218801          "signature": {
218802            "signature": {
218803              "publicKey": {}
218804            }
218805          },
218806          "modelCard": {
218807            "modelParameters": {
218808              "approach": {}
218809            },
218810            "quantitativeAnalysis": {
218811              "graphics": {}
218812            },
218813            "considerations": {}
218814          }
218815        },
218816        {
218817          "type": "library",
218818          "bom-ref": "pkg:npm/event-target-shim@5.0.1?package-id=77f0beb7ac74ebf6",
218819          "supplier": {},
218820          "name": "event-target-shim",
218821          "version": "5.0.1",
218822          "licenses": [
218823            {
218824              "license": {
218825                "id": "MIT"
218826              }
218827            }
218828          ],
218829          "cpe": "cpe:2.3:a:event-target-shim:event-target-shim:5.0.1:*:*:*:*:*:*:*",
218830          "purl": "pkg:npm/event-target-shim@5.0.1",
218831          "swid": {
218832            "attachment": {}
218833          },
218834          "pedigree": {},
218835          "evidence": {},
218836          "signature": {
218837            "signature": {
218838              "publicKey": {}
218839            }
218840          },
218841          "modelCard": {
218842            "modelParameters": {
218843              "approach": {}
218844            },
218845            "quantitativeAnalysis": {
218846              "graphics": {}
218847            },
218848            "considerations": {}
218849          }
218850        },
218851        {
218852          "type": "library",
218853          "bom-ref": "pkg:npm/events@3.3.0?package-id=937b3024552d5a0d",
218854          "supplier": {},
218855          "name": "events",
218856          "version": "3.3.0",
218857          "licenses": [
218858            {
218859              "license": {
218860                "id": "MIT"
218861              }
218862            }
218863          ],
218864          "cpe": "cpe:2.3:a:events:events:3.3.0:*:*:*:*:*:*:*",
218865          "purl": "pkg:npm/events@3.3.0",
218866          "swid": {
218867            "attachment": {}
218868          },
218869          "pedigree": {},
218870          "evidence": {},
218871          "signature": {
218872            "signature": {
218873              "publicKey": {}
218874            }
218875          },
218876          "modelCard": {
218877            "modelParameters": {
218878              "approach": {}
218879            },
218880            "quantitativeAnalysis": {
218881              "graphics": {}
218882            },
218883            "considerations": {}
218884          }
218885        },
218886        {
218887          "type": "library",
218888          "bom-ref": "pkg:npm/exceljs@4.3.0?package-id=8d8d02274c0e030c",
218889          "supplier": {},
218890          "name": "exceljs",
218891          "version": "4.3.0",
218892          "licenses": [
218893            {
218894              "license": {
218895                "id": "MIT"
218896              }
218897            }
218898          ],
218899          "cpe": "cpe:2.3:a:exceljs:exceljs:4.3.0:*:*:*:*:*:*:*",
218900          "purl": "pkg:npm/exceljs@4.3.0",
218901          "swid": {
218902            "attachment": {}
218903          },
218904          "pedigree": {},
218905          "evidence": {},
218906          "signature": {
218907            "signature": {
218908              "publicKey": {}
218909            }
218910          },
218911          "modelCard": {
218912            "modelParameters": {
218913              "approach": {}
218914            },
218915            "quantitativeAnalysis": {
218916              "graphics": {}
218917            },
218918            "considerations": {}
218919          }
218920        },
218921        {
218922          "type": "library",
218923          "bom-ref": "pkg:npm/execa@0.7.0?package-id=6c84caa9fd62b313",
218924          "supplier": {},
218925          "name": "execa",
218926          "version": "0.7.0",
218927          "licenses": [
218928            {
218929              "license": {
218930                "id": "MIT"
218931              }
218932            }
218933          ],
218934          "cpe": "cpe:2.3:a:execa:execa:0.7.0:*:*:*:*:*:*:*",
218935          "purl": "pkg:npm/execa@0.7.0",
218936          "swid": {
218937            "attachment": {}
218938          },
218939          "pedigree": {},
218940          "evidence": {},
218941          "signature": {
218942            "signature": {
218943              "publicKey": {}
218944            }
218945          },
218946          "modelCard": {
218947            "modelParameters": {
218948              "approach": {}
218949            },
218950            "quantitativeAnalysis": {
218951              "graphics": {}
218952            },
218953            "considerations": {}
218954          }
218955        },
218956        {
218957          "type": "library",
218958          "bom-ref": "pkg:npm/expand-template@2.0.3?package-id=f97d55d03ec17cd4",
218959          "supplier": {},
218960          "name": "expand-template",
218961          "version": "2.0.3",
218962          "licenses": [
218963            {
218964              "license": {
218965                "name": "(MIT OR WTFPL)"
218966              }
218967            }
218968          ],
218969          "cpe": "cpe:2.3:a:expand-template:expand-template:2.0.3:*:*:*:*:*:*:*",
218970          "purl": "pkg:npm/expand-template@2.0.3",
218971          "swid": {
218972            "attachment": {}
218973          },
218974          "pedigree": {},
218975          "evidence": {},
218976          "signature": {
218977            "signature": {
218978              "publicKey": {}
218979            }
218980          },
218981          "modelCard": {
218982            "modelParameters": {
218983              "approach": {}
218984            },
218985            "quantitativeAnalysis": {
218986              "graphics": {}
218987            },
218988            "considerations": {}
218989          }
218990        },
218991        {
218992          "type": "library",
218993          "bom-ref": "pkg:npm/ext-list@2.2.2?package-id=227497a47356b4ad",
218994          "supplier": {},
218995          "name": "ext-list",
218996          "version": "2.2.2",
218997          "licenses": [
218998            {
218999              "license": {
219000                "id": "MIT"
219001              }
219002            }
219003          ],
219004          "cpe": "cpe:2.3:a:ext-list:ext-list:2.2.2:*:*:*:*:*:*:*",
219005          "purl": "pkg:npm/ext-list@2.2.2",
219006          "swid": {
219007            "attachment": {}
219008          },
219009          "pedigree": {},
219010          "evidence": {},
219011          "signature": {
219012            "signature": {
219013              "publicKey": {}
219014            }
219015          },
219016          "modelCard": {
219017            "modelParameters": {
219018              "approach": {}
219019            },
219020            "quantitativeAnalysis": {
219021              "graphics": {}
219022            },
219023            "considerations": {}
219024          }
219025        },
219026        {
219027          "type": "library",
219028          "bom-ref": "pkg:npm/ext-name@5.0.0?package-id=b127926513ba69ea",
219029          "supplier": {},
219030          "name": "ext-name",
219031          "version": "5.0.0",
219032          "licenses": [
219033            {
219034              "license": {
219035                "id": "MIT"
219036              }
219037            }
219038          ],
219039          "cpe": "cpe:2.3:a:ext-name:ext-name:5.0.0:*:*:*:*:*:*:*",
219040          "purl": "pkg:npm/ext-name@5.0.0",
219041          "swid": {
219042            "attachment": {}
219043          },
219044          "pedigree": {},
219045          "evidence": {},
219046          "signature": {
219047            "signature": {
219048              "publicKey": {}
219049            }
219050          },
219051          "modelCard": {
219052            "modelParameters": {
219053              "approach": {}
219054            },
219055            "quantitativeAnalysis": {
219056              "graphics": {}
219057            },
219058            "considerations": {}
219059          }
219060        },
219061        {
219062          "type": "library",
219063          "bom-ref": "pkg:npm/extend@3.0.2?package-id=1985b9e710517a00",
219064          "supplier": {},
219065          "name": "extend",
219066          "version": "3.0.2",
219067          "licenses": [
219068            {
219069              "license": {
219070                "id": "MIT"
219071              }
219072            }
219073          ],
219074          "cpe": "cpe:2.3:a:extend:extend:3.0.2:*:*:*:*:*:*:*",
219075          "purl": "pkg:npm/extend@3.0.2",
219076          "swid": {
219077            "attachment": {}
219078          },
219079          "pedigree": {},
219080          "evidence": {},
219081          "signature": {
219082            "signature": {
219083              "publicKey": {}
219084            }
219085          },
219086          "modelCard": {
219087            "modelParameters": {
219088              "approach": {}
219089            },
219090            "quantitativeAnalysis": {
219091              "graphics": {}
219092            },
219093            "considerations": {}
219094          }
219095        },
219096        {
219097          "type": "library",
219098          "bom-ref": "pkg:npm/extsprintf@1.3.0?package-id=6e3b15c094722f53",
219099          "supplier": {},
219100          "name": "extsprintf",
219101          "version": "1.3.0",
219102          "licenses": [
219103            {
219104              "license": {
219105                "id": "MIT"
219106              }
219107            }
219108          ],
219109          "cpe": "cpe:2.3:a:extsprintf:extsprintf:1.3.0:*:*:*:*:*:*:*",
219110          "purl": "pkg:npm/extsprintf@1.3.0",
219111          "swid": {
219112            "attachment": {}
219113          },
219114          "pedigree": {},
219115          "evidence": {},
219116          "signature": {
219117            "signature": {
219118              "publicKey": {}
219119            }
219120          },
219121          "modelCard": {
219122            "modelParameters": {
219123              "approach": {}
219124            },
219125            "quantitativeAnalysis": {
219126              "graphics": {}
219127            },
219128            "considerations": {}
219129          }
219130        },
219131        {
219132          "type": "library",
219133          "bom-ref": "pkg:npm/fast-chunk-string@1.0.1?package-id=8e4eb75995f5b533",
219134          "supplier": {},
219135          "name": "fast-chunk-string",
219136          "version": "1.0.1",
219137          "licenses": [
219138            {
219139              "license": {
219140                "id": "MIT"
219141              }
219142            }
219143          ],
219144          "cpe": "cpe:2.3:a:fast-chunk-string:fast-chunk-string:1.0.1:*:*:*:*:*:*:*",
219145          "purl": "pkg:npm/fast-chunk-string@1.0.1",
219146          "swid": {
219147            "attachment": {}
219148          },
219149          "pedigree": {},
219150          "evidence": {},
219151          "signature": {
219152            "signature": {
219153              "publicKey": {}
219154            }
219155          },
219156          "modelCard": {
219157            "modelParameters": {
219158              "approach": {}
219159            },
219160            "quantitativeAnalysis": {
219161              "graphics": {}
219162            },
219163            "considerations": {}
219164          }
219165        },
219166        {
219167          "type": "library",
219168          "bom-ref": "pkg:npm/fast-csv@4.3.6?package-id=83093c4ee1514c20",
219169          "supplier": {},
219170          "name": "fast-csv",
219171          "version": "4.3.6",
219172          "licenses": [
219173            {
219174              "license": {
219175                "id": "MIT"
219176              }
219177            }
219178          ],
219179          "cpe": "cpe:2.3:a:fast-csv:fast-csv:4.3.6:*:*:*:*:*:*:*",
219180          "purl": "pkg:npm/fast-csv@4.3.6",
219181          "swid": {
219182            "attachment": {}
219183          },
219184          "pedigree": {},
219185          "evidence": {},
219186          "signature": {
219187            "signature": {
219188              "publicKey": {}
219189            }
219190          },
219191          "modelCard": {
219192            "modelParameters": {
219193              "approach": {}
219194            },
219195            "quantitativeAnalysis": {
219196              "graphics": {}
219197            },
219198            "considerations": {}
219199          }
219200        },
219201        {
219202          "type": "library",
219203          "bom-ref": "pkg:npm/fast-deep-equal@3.1.3?package-id=2b7ef2a1cc68885b",
219204          "supplier": {},
219205          "name": "fast-deep-equal",
219206          "version": "3.1.3",
219207          "licenses": [
219208            {
219209              "license": {
219210                "id": "MIT"
219211              }
219212            }
219213          ],
219214          "cpe": "cpe:2.3:a:fast-deep-equal:fast-deep-equal:3.1.3:*:*:*:*:*:*:*",
219215          "purl": "pkg:npm/fast-deep-equal@3.1.3",
219216          "swid": {
219217            "attachment": {}
219218          },
219219          "pedigree": {},
219220          "evidence": {},
219221          "signature": {
219222            "signature": {
219223              "publicKey": {}
219224            }
219225          },
219226          "modelCard": {
219227            "modelParameters": {
219228              "approach": {}
219229            },
219230            "quantitativeAnalysis": {
219231              "graphics": {}
219232            },
219233            "considerations": {}
219234          }
219235        },
219236        {
219237          "type": "library",
219238          "bom-ref": "pkg:npm/fast-json-patch@3.1.1?package-id=dc1dc6cba523588d",
219239          "supplier": {},
219240          "name": "fast-json-patch",
219241          "version": "3.1.1",
219242          "licenses": [
219243            {
219244              "license": {
219245                "id": "MIT"
219246              }
219247            }
219248          ],
219249          "cpe": "cpe:2.3:a:fast-json-patch:fast-json-patch:3.1.1:*:*:*:*:*:*:*",
219250          "purl": "pkg:npm/fast-json-patch@3.1.1",
219251          "swid": {
219252            "attachment": {}
219253          },
219254          "pedigree": {},
219255          "evidence": {},
219256          "signature": {
219257            "signature": {
219258              "publicKey": {}
219259            }
219260          },
219261          "modelCard": {
219262            "modelParameters": {
219263              "approach": {}
219264            },
219265            "quantitativeAnalysis": {
219266              "graphics": {}
219267            },
219268            "considerations": {}
219269          }
219270        },
219271        {
219272          "type": "library",
219273          "bom-ref": "pkg:npm/fast-json-stable-stringify@2.0.0?package-id=4f3459ba7fc5deee",
219274          "supplier": {},
219275          "name": "fast-json-stable-stringify",
219276          "version": "2.0.0",
219277          "licenses": [
219278            {
219279              "license": {
219280                "id": "MIT"
219281              }
219282            }
219283          ],
219284          "cpe": "cpe:2.3:a:fast-json-stable-stringify:fast-json-stable-stringify:2.0.0:*:*:*:*:*:*:*",
219285          "purl": "pkg:npm/fast-json-stable-stringify@2.0.0",
219286          "swid": {
219287            "attachment": {}
219288          },
219289          "pedigree": {},
219290          "evidence": {},
219291          "signature": {
219292            "signature": {
219293              "publicKey": {}
219294            }
219295          },
219296          "modelCard": {
219297            "modelParameters": {
219298              "approach": {}
219299            },
219300            "quantitativeAnalysis": {
219301              "graphics": {}
219302            },
219303            "considerations": {}
219304          }
219305        },
219306        {
219307          "type": "library",
219308          "bom-ref": "pkg:npm/fast-text-encoding@1.0.6?package-id=3e4ec51769956bca",
219309          "supplier": {},
219310          "name": "fast-text-encoding",
219311          "version": "1.0.6",
219312          "licenses": [
219313            {
219314              "license": {
219315                "id": "Apache-2.0"
219316              }
219317            }
219318          ],
219319          "cpe": "cpe:2.3:a:fast-text-encoding:fast-text-encoding:1.0.6:*:*:*:*:*:*:*",
219320          "purl": "pkg:npm/fast-text-encoding@1.0.6",
219321          "swid": {
219322            "attachment": {}
219323          },
219324          "pedigree": {},
219325          "evidence": {},
219326          "signature": {
219327            "signature": {
219328              "publicKey": {}
219329            }
219330          },
219331          "modelCard": {
219332            "modelParameters": {
219333              "approach": {}
219334            },
219335            "quantitativeAnalysis": {
219336              "graphics": {}
219337            },
219338            "considerations": {}
219339          }
219340        },
219341        {
219342          "type": "library",
219343          "bom-ref": "pkg:npm/fd-slicer@1.1.0?package-id=7232ea3a7554f576",
219344          "supplier": {},
219345          "name": "fd-slicer",
219346          "version": "1.1.0",
219347          "licenses": [
219348            {
219349              "license": {
219350                "id": "MIT"
219351              }
219352            }
219353          ],
219354          "cpe": "cpe:2.3:a:fd-slicer:fd-slicer:1.1.0:*:*:*:*:*:*:*",
219355          "purl": "pkg:npm/fd-slicer@1.1.0",
219356          "swid": {
219357            "attachment": {}
219358          },
219359          "pedigree": {},
219360          "evidence": {},
219361          "signature": {
219362            "signature": {
219363              "publicKey": {}
219364            }
219365          },
219366          "modelCard": {
219367            "modelParameters": {
219368              "approach": {}
219369            },
219370            "quantitativeAnalysis": {
219371              "graphics": {}
219372            },
219373            "considerations": {}
219374          }
219375        },
219376        {
219377          "type": "library",
219378          "bom-ref": "pkg:npm/file-type@5.2.0?package-id=e69e1929f5bd16ca",
219379          "supplier": {},
219380          "name": "file-type",
219381          "version": "5.2.0",
219382          "licenses": [
219383            {
219384              "license": {
219385                "id": "MIT"
219386              }
219387            }
219388          ],
219389          "cpe": "cpe:2.3:a:file-type:file-type:5.2.0:*:*:*:*:*:*:*",
219390          "purl": "pkg:npm/file-type@5.2.0",
219391          "swid": {
219392            "attachment": {}
219393          },
219394          "pedigree": {},
219395          "evidence": {},
219396          "signature": {
219397            "signature": {
219398              "publicKey": {}
219399            }
219400          },
219401          "modelCard": {
219402            "modelParameters": {
219403              "approach": {}
219404            },
219405            "quantitativeAnalysis": {
219406              "graphics": {}
219407            },
219408            "considerations": {}
219409          }
219410        },
219411        {
219412          "type": "library",
219413          "bom-ref": "pkg:npm/filename-reserved-regex@2.0.0?package-id=b95fdaa6cde49484",
219414          "supplier": {},
219415          "name": "filename-reserved-regex",
219416          "version": "2.0.0",
219417          "licenses": [
219418            {
219419              "license": {
219420                "id": "MIT"
219421              }
219422            }
219423          ],
219424          "cpe": "cpe:2.3:a:filename-reserved-regex:filename-reserved-regex:2.0.0:*:*:*:*:*:*:*",
219425          "purl": "pkg:npm/filename-reserved-regex@2.0.0",
219426          "swid": {
219427            "attachment": {}
219428          },
219429          "pedigree": {},
219430          "evidence": {},
219431          "signature": {
219432            "signature": {
219433              "publicKey": {}
219434            }
219435          },
219436          "modelCard": {
219437            "modelParameters": {
219438              "approach": {}
219439            },
219440            "quantitativeAnalysis": {
219441              "graphics": {}
219442            },
219443            "considerations": {}
219444          }
219445        },
219446        {
219447          "type": "library",
219448          "bom-ref": "pkg:npm/filenamify@2.1.0?package-id=89f601871d8c7704",
219449          "supplier": {},
219450          "name": "filenamify",
219451          "version": "2.1.0",
219452          "licenses": [
219453            {
219454              "license": {
219455                "id": "MIT"
219456              }
219457            }
219458          ],
219459          "cpe": "cpe:2.3:a:filenamify:filenamify:2.1.0:*:*:*:*:*:*:*",
219460          "purl": "pkg:npm/filenamify@2.1.0",
219461          "swid": {
219462            "attachment": {}
219463          },
219464          "pedigree": {},
219465          "evidence": {},
219466          "signature": {
219467            "signature": {
219468              "publicKey": {}
219469            }
219470          },
219471          "modelCard": {
219472            "modelParameters": {
219473              "approach": {}
219474            },
219475            "quantitativeAnalysis": {
219476              "graphics": {}
219477            },
219478            "considerations": {}
219479          }
219480        },
219481        {
219482          "type": "library",
219483          "bom-ref": "pkg:npm/follow-redirects@1.15.2?package-id=3691791795751fe5",
219484          "supplier": {},
219485          "name": "follow-redirects",
219486          "version": "1.15.2",
219487          "licenses": [
219488            {
219489              "license": {
219490                "id": "MIT"
219491              }
219492            }
219493          ],
219494          "cpe": "cpe:2.3:a:follow-redirects:follow-redirects:1.15.2:*:*:*:*:*:*:*",
219495          "purl": "pkg:npm/follow-redirects@1.15.2",
219496          "swid": {
219497            "attachment": {}
219498          },
219499          "pedigree": {},
219500          "evidence": {},
219501          "signature": {
219502            "signature": {
219503              "publicKey": {}
219504            }
219505          },
219506          "modelCard": {
219507            "modelParameters": {
219508              "approach": {}
219509            },
219510            "quantitativeAnalysis": {
219511              "graphics": {}
219512            },
219513            "considerations": {}
219514          }
219515        },
219516        {
219517          "type": "library",
219518          "bom-ref": "pkg:npm/forever-agent@0.6.1?package-id=ba24fa234f7565ab",
219519          "supplier": {},
219520          "name": "forever-agent",
219521          "version": "0.6.1",
219522          "licenses": [
219523            {
219524              "license": {
219525                "id": "Apache-2.0"
219526              }
219527            }
219528          ],
219529          "cpe": "cpe:2.3:a:forever-agent:forever-agent:0.6.1:*:*:*:*:*:*:*",
219530          "purl": "pkg:npm/forever-agent@0.6.1",
219531          "swid": {
219532            "attachment": {}
219533          },
219534          "pedigree": {},
219535          "evidence": {},
219536          "signature": {
219537            "signature": {
219538              "publicKey": {}
219539            }
219540          },
219541          "modelCard": {
219542            "modelParameters": {
219543              "approach": {}
219544            },
219545            "quantitativeAnalysis": {
219546              "graphics": {}
219547            },
219548            "considerations": {}
219549          }
219550        },
219551        {
219552          "type": "library",
219553          "bom-ref": "pkg:npm/form-data@2.3.3?package-id=e8062fbce3e10599",
219554          "supplier": {},
219555          "name": "form-data",
219556          "version": "2.3.3",
219557          "licenses": [
219558            {
219559              "license": {
219560                "id": "MIT"
219561              }
219562            }
219563          ],
219564          "cpe": "cpe:2.3:a:form-data:form-data:2.3.3:*:*:*:*:*:*:*",
219565          "purl": "pkg:npm/form-data@2.3.3",
219566          "swid": {
219567            "attachment": {}
219568          },
219569          "pedigree": {},
219570          "evidence": {},
219571          "signature": {
219572            "signature": {
219573              "publicKey": {}
219574            }
219575          },
219576          "modelCard": {
219577            "modelParameters": {
219578              "approach": {}
219579            },
219580            "quantitativeAnalysis": {
219581              "graphics": {}
219582            },
219583            "considerations": {}
219584          }
219585        },
219586        {
219587          "type": "library",
219588          "bom-ref": "pkg:npm/fs-constants@1.0.0?package-id=d23cbb5d1e356eaa",
219589          "supplier": {},
219590          "name": "fs-constants",
219591          "version": "1.0.0",
219592          "licenses": [
219593            {
219594              "license": {
219595                "id": "MIT"
219596              }
219597            }
219598          ],
219599          "cpe": "cpe:2.3:a:fs-constants:fs-constants:1.0.0:*:*:*:*:*:*:*",
219600          "purl": "pkg:npm/fs-constants@1.0.0",
219601          "swid": {
219602            "attachment": {}
219603          },
219604          "pedigree": {},
219605          "evidence": {},
219606          "signature": {
219607            "signature": {
219608              "publicKey": {}
219609            }
219610          },
219611          "modelCard": {
219612            "modelParameters": {
219613              "approach": {}
219614            },
219615            "quantitativeAnalysis": {
219616              "graphics": {}
219617            },
219618            "considerations": {}
219619          }
219620        },
219621        {
219622          "type": "library",
219623          "bom-ref": "pkg:npm/fs-extra@10.1.0?package-id=cb1a020f99c3b34f",
219624          "supplier": {},
219625          "name": "fs-extra",
219626          "version": "10.1.0",
219627          "licenses": [
219628            {
219629              "license": {
219630                "id": "MIT"
219631              }
219632            }
219633          ],
219634          "cpe": "cpe:2.3:a:fs-extra:fs-extra:10.1.0:*:*:*:*:*:*:*",
219635          "purl": "pkg:npm/fs-extra@10.1.0",
219636          "swid": {
219637            "attachment": {}
219638          },
219639          "pedigree": {},
219640          "evidence": {},
219641          "signature": {
219642            "signature": {
219643              "publicKey": {}
219644            }
219645          },
219646          "modelCard": {
219647            "modelParameters": {
219648              "approach": {}
219649            },
219650            "quantitativeAnalysis": {
219651              "graphics": {}
219652            },
219653            "considerations": {}
219654          }
219655        },
219656        {
219657          "type": "library",
219658          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=4b68b3b85c9298b7",
219659          "supplier": {},
219660          "name": "fs.realpath",
219661          "version": "1.0.0",
219662          "licenses": [
219663            {
219664              "license": {
219665                "id": "ISC"
219666              }
219667            }
219668          ],
219669          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
219670          "purl": "pkg:npm/fs.realpath@1.0.0",
219671          "swid": {
219672            "attachment": {}
219673          },
219674          "pedigree": {},
219675          "evidence": {},
219676          "signature": {
219677            "signature": {
219678              "publicKey": {}
219679            }
219680          },
219681          "modelCard": {
219682            "modelParameters": {
219683              "approach": {}
219684            },
219685            "quantitativeAnalysis": {
219686              "graphics": {}
219687            },
219688            "considerations": {}
219689          }
219690        },
219691        {
219692          "type": "library",
219693          "bom-ref": "pkg:npm/fstream@1.0.12?package-id=6aa064dac7c55c50",
219694          "supplier": {},
219695          "name": "fstream",
219696          "version": "1.0.12",
219697          "licenses": [
219698            {
219699              "license": {
219700                "id": "ISC"
219701              }
219702            }
219703          ],
219704          "cpe": "cpe:2.3:a:fstream:fstream:1.0.12:*:*:*:*:*:*:*",
219705          "purl": "pkg:npm/fstream@1.0.12",
219706          "swid": {
219707            "attachment": {}
219708          },
219709          "pedigree": {},
219710          "evidence": {},
219711          "signature": {
219712            "signature": {
219713              "publicKey": {}
219714            }
219715          },
219716          "modelCard": {
219717            "modelParameters": {
219718              "approach": {}
219719            },
219720            "quantitativeAnalysis": {
219721              "graphics": {}
219722            },
219723            "considerations": {}
219724          }
219725        },
219726        {
219727          "type": "library",
219728          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=56c3a01f3c742c82",
219729          "supplier": {},
219730          "name": "function-bind",
219731          "version": "1.1.1",
219732          "licenses": [
219733            {
219734              "license": {
219735                "id": "MIT"
219736              }
219737            }
219738          ],
219739          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
219740          "purl": "pkg:npm/function-bind@1.1.1",
219741          "swid": {
219742            "attachment": {}
219743          },
219744          "pedigree": {},
219745          "evidence": {},
219746          "signature": {
219747            "signature": {
219748              "publicKey": {}
219749            }
219750          },
219751          "modelCard": {
219752            "modelParameters": {
219753              "approach": {}
219754            },
219755            "quantitativeAnalysis": {
219756              "graphics": {}
219757            },
219758            "considerations": {}
219759          }
219760        },
219761        {
219762          "type": "library",
219763          "bom-ref": "pkg:npm/gaxios@5.1.0?package-id=76ac5c02295c1ac9",
219764          "supplier": {},
219765          "name": "gaxios",
219766          "version": "5.1.0",
219767          "licenses": [
219768            {
219769              "license": {
219770                "id": "Apache-2.0"
219771              }
219772            }
219773          ],
219774          "cpe": "cpe:2.3:a:gaxios:gaxios:5.1.0:*:*:*:*:*:*:*",
219775          "purl": "pkg:npm/gaxios@5.1.0",
219776          "swid": {
219777            "attachment": {}
219778          },
219779          "pedigree": {},
219780          "evidence": {},
219781          "signature": {
219782            "signature": {
219783              "publicKey": {}
219784            }
219785          },
219786          "modelCard": {
219787            "modelParameters": {
219788              "approach": {}
219789            },
219790            "quantitativeAnalysis": {
219791              "graphics": {}
219792            },
219793            "considerations": {}
219794          }
219795        },
219796        {
219797          "type": "library",
219798          "bom-ref": "pkg:npm/gcp-metadata@5.2.0?package-id=8b09be7927d977e1",
219799          "supplier": {},
219800          "name": "gcp-metadata",
219801          "version": "5.2.0",
219802          "licenses": [
219803            {
219804              "license": {
219805                "id": "Apache-2.0"
219806              }
219807            }
219808          ],
219809          "cpe": "cpe:2.3:a:gcp-metadata:gcp-metadata:5.2.0:*:*:*:*:*:*:*",
219810          "purl": "pkg:npm/gcp-metadata@5.2.0",
219811          "swid": {
219812            "attachment": {}
219813          },
219814          "pedigree": {},
219815          "evidence": {},
219816          "signature": {
219817            "signature": {
219818              "publicKey": {}
219819            }
219820          },
219821          "modelCard": {
219822            "modelParameters": {
219823              "approach": {}
219824            },
219825            "quantitativeAnalysis": {
219826              "graphics": {}
219827            },
219828            "considerations": {}
219829          }
219830        },
219831        {
219832          "type": "library",
219833          "bom-ref": "pkg:npm/generate-function@2.3.1?package-id=cc8d8b1b871a73d6",
219834          "supplier": {},
219835          "name": "generate-function",
219836          "version": "2.3.1",
219837          "licenses": [
219838            {
219839              "license": {
219840                "id": "MIT"
219841              }
219842            }
219843          ],
219844          "cpe": "cpe:2.3:a:generate-function:generate-function:2.3.1:*:*:*:*:*:*:*",
219845          "purl": "pkg:npm/generate-function@2.3.1",
219846          "swid": {
219847            "attachment": {}
219848          },
219849          "pedigree": {},
219850          "evidence": {},
219851          "signature": {
219852            "signature": {
219853              "publicKey": {}
219854            }
219855          },
219856          "modelCard": {
219857            "modelParameters": {
219858              "approach": {}
219859            },
219860            "quantitativeAnalysis": {
219861              "graphics": {}
219862            },
219863            "considerations": {}
219864          }
219865        },
219866        {
219867          "type": "library",
219868          "bom-ref": "pkg:npm/get-caller-file@2.0.5?package-id=9dfebea6137e18ff",
219869          "supplier": {},
219870          "name": "get-caller-file",
219871          "version": "2.0.5",
219872          "licenses": [
219873            {
219874              "license": {
219875                "id": "ISC"
219876              }
219877            }
219878          ],
219879          "cpe": "cpe:2.3:a:get-caller-file:get-caller-file:2.0.5:*:*:*:*:*:*:*",
219880          "purl": "pkg:npm/get-caller-file@2.0.5",
219881          "swid": {
219882            "attachment": {}
219883          },
219884          "pedigree": {},
219885          "evidence": {},
219886          "signature": {
219887            "signature": {
219888              "publicKey": {}
219889            }
219890          },
219891          "modelCard": {
219892            "modelParameters": {
219893              "approach": {}
219894            },
219895            "quantitativeAnalysis": {
219896              "graphics": {}
219897            },
219898            "considerations": {}
219899          }
219900        },
219901        {
219902          "type": "library",
219903          "bom-ref": "pkg:npm/get-intrinsic@1.2.0?package-id=2f2414d89af5e416",
219904          "supplier": {},
219905          "name": "get-intrinsic",
219906          "version": "1.2.0",
219907          "licenses": [
219908            {
219909              "license": {
219910                "id": "MIT"
219911              }
219912            }
219913          ],
219914          "cpe": "cpe:2.3:a:get-intrinsic:get-intrinsic:1.2.0:*:*:*:*:*:*:*",
219915          "purl": "pkg:npm/get-intrinsic@1.2.0",
219916          "swid": {
219917            "attachment": {}
219918          },
219919          "pedigree": {},
219920          "evidence": {},
219921          "signature": {
219922            "signature": {
219923              "publicKey": {}
219924            }
219925          },
219926          "modelCard": {
219927            "modelParameters": {
219928              "approach": {}
219929            },
219930            "quantitativeAnalysis": {
219931              "graphics": {}
219932            },
219933            "considerations": {}
219934          }
219935        },
219936        {
219937          "type": "library",
219938          "bom-ref": "pkg:npm/get-proxy@2.1.0?package-id=e1d6d3a523c2194",
219939          "supplier": {},
219940          "name": "get-proxy",
219941          "version": "2.1.0",
219942          "licenses": [
219943            {
219944              "license": {
219945                "id": "MIT"
219946              }
219947            }
219948          ],
219949          "cpe": "cpe:2.3:a:get-proxy:get-proxy:2.1.0:*:*:*:*:*:*:*",
219950          "purl": "pkg:npm/get-proxy@2.1.0",
219951          "swid": {
219952            "attachment": {}
219953          },
219954          "pedigree": {},
219955          "evidence": {},
219956          "signature": {
219957            "signature": {
219958              "publicKey": {}
219959            }
219960          },
219961          "modelCard": {
219962            "modelParameters": {
219963              "approach": {}
219964            },
219965            "quantitativeAnalysis": {
219966              "graphics": {}
219967            },
219968            "considerations": {}
219969          }
219970        },
219971        {
219972          "type": "library",
219973          "bom-ref": "pkg:npm/get-ssl-certificate@2.3.3?package-id=8657a0f5de77391",
219974          "supplier": {},
219975          "name": "get-ssl-certificate",
219976          "version": "2.3.3",
219977          "licenses": [
219978            {
219979              "license": {
219980                "id": "MIT"
219981              }
219982            }
219983          ],
219984          "cpe": "cpe:2.3:a:get-ssl-certificate:get-ssl-certificate:2.3.3:*:*:*:*:*:*:*",
219985          "purl": "pkg:npm/get-ssl-certificate@2.3.3",
219986          "swid": {
219987            "attachment": {}
219988          },
219989          "pedigree": {},
219990          "evidence": {},
219991          "signature": {
219992            "signature": {
219993              "publicKey": {}
219994            }
219995          },
219996          "modelCard": {
219997            "modelParameters": {
219998              "approach": {}
219999            },
220000            "quantitativeAnalysis": {
220001              "graphics": {}
220002            },
220003            "considerations": {}
220004          }
220005        },
220006        {
220007          "type": "library",
220008          "bom-ref": "pkg:npm/get-stream@2.3.1?package-id=e5de72b525129103",
220009          "supplier": {},
220010          "name": "get-stream",
220011          "version": "2.3.1",
220012          "licenses": [
220013            {
220014              "license": {
220015                "id": "MIT"
220016              }
220017            }
220018          ],
220019          "cpe": "cpe:2.3:a:get-stream:get-stream:2.3.1:*:*:*:*:*:*:*",
220020          "purl": "pkg:npm/get-stream@2.3.1",
220021          "swid": {
220022            "attachment": {}
220023          },
220024          "pedigree": {},
220025          "evidence": {},
220026          "signature": {
220027            "signature": {
220028              "publicKey": {}
220029            }
220030          },
220031          "modelCard": {
220032            "modelParameters": {
220033              "approach": {}
220034            },
220035            "quantitativeAnalysis": {
220036              "graphics": {}
220037            },
220038            "considerations": {}
220039          }
220040        },
220041        {
220042          "type": "library",
220043          "bom-ref": "pkg:npm/getpass@0.1.7?package-id=8fbe9dc611eb5d31",
220044          "supplier": {},
220045          "name": "getpass",
220046          "version": "0.1.7",
220047          "licenses": [
220048            {
220049              "license": {
220050                "id": "MIT"
220051              }
220052            }
220053          ],
220054          "cpe": "cpe:2.3:a:getpass:getpass:0.1.7:*:*:*:*:*:*:*",
220055          "purl": "pkg:npm/getpass@0.1.7",
220056          "swid": {
220057            "attachment": {}
220058          },
220059          "pedigree": {},
220060          "evidence": {},
220061          "signature": {
220062            "signature": {
220063              "publicKey": {}
220064            }
220065          },
220066          "modelCard": {
220067            "modelParameters": {
220068              "approach": {}
220069            },
220070            "quantitativeAnalysis": {
220071              "graphics": {}
220072            },
220073            "considerations": {}
220074          }
220075        },
220076        {
220077          "type": "library",
220078          "bom-ref": "pkg:npm/github-from-package@0.0.0?package-id=8b04e173750b94fd",
220079          "supplier": {},
220080          "name": "github-from-package",
220081          "version": "0.0.0",
220082          "licenses": [
220083            {
220084              "license": {
220085                "id": "MIT"
220086              }
220087            }
220088          ],
220089          "cpe": "cpe:2.3:a:github-from-package:github-from-package:0.0.0:*:*:*:*:*:*:*",
220090          "purl": "pkg:npm/github-from-package@0.0.0",
220091          "swid": {
220092            "attachment": {}
220093          },
220094          "pedigree": {},
220095          "evidence": {},
220096          "signature": {
220097            "signature": {
220098              "publicKey": {}
220099            }
220100          },
220101          "modelCard": {
220102            "modelParameters": {
220103              "approach": {}
220104            },
220105            "quantitativeAnalysis": {
220106              "graphics": {}
220107            },
220108            "considerations": {}
220109          }
220110        },
220111        {
220112          "type": "library",
220113          "bom-ref": "pkg:npm/glob@7.2.3?package-id=773492798887d32d",
220114          "supplier": {},
220115          "name": "glob",
220116          "version": "7.2.3",
220117          "licenses": [
220118            {
220119              "license": {
220120                "id": "ISC"
220121              }
220122            }
220123          ],
220124          "cpe": "cpe:2.3:a:glob:glob:7.2.3:*:*:*:*:*:*:*",
220125          "purl": "pkg:npm/glob@7.2.3",
220126          "swid": {
220127            "attachment": {}
220128          },
220129          "pedigree": {},
220130          "evidence": {},
220131          "signature": {
220132            "signature": {
220133              "publicKey": {}
220134            }
220135          },
220136          "modelCard": {
220137            "modelParameters": {
220138              "approach": {}
220139            },
220140            "quantitativeAnalysis": {
220141              "graphics": {}
220142            },
220143            "considerations": {}
220144          }
220145        },
220146        {
220147          "type": "library",
220148          "bom-ref": "pkg:npm/google-auth-library@8.7.0?package-id=3c7a04514b954856",
220149          "supplier": {},
220150          "name": "google-auth-library",
220151          "version": "8.7.0",
220152          "licenses": [
220153            {
220154              "license": {
220155                "id": "Apache-2.0"
220156              }
220157            }
220158          ],
220159          "cpe": "cpe:2.3:a:google-auth-library:google-auth-library:8.7.0:*:*:*:*:*:*:*",
220160          "purl": "pkg:npm/google-auth-library@8.7.0",
220161          "swid": {
220162            "attachment": {}
220163          },
220164          "pedigree": {},
220165          "evidence": {},
220166          "signature": {
220167            "signature": {
220168              "publicKey": {}
220169            }
220170          },
220171          "modelCard": {
220172            "modelParameters": {
220173              "approach": {}
220174            },
220175            "quantitativeAnalysis": {
220176              "graphics": {}
220177            },
220178            "considerations": {}
220179          }
220180        },
220181        {
220182          "type": "library",
220183          "bom-ref": "pkg:npm/google-p12-pem@4.0.1?package-id=7a78023e3cb79f63",
220184          "supplier": {},
220185          "name": "google-p12-pem",
220186          "version": "4.0.1",
220187          "licenses": [
220188            {
220189              "license": {
220190                "id": "MIT"
220191              }
220192            }
220193          ],
220194          "cpe": "cpe:2.3:a:google-p12-pem:google-p12-pem:4.0.1:*:*:*:*:*:*:*",
220195          "purl": "pkg:npm/google-p12-pem@4.0.1",
220196          "swid": {
220197            "attachment": {}
220198          },
220199          "pedigree": {},
220200          "evidence": {},
220201          "signature": {
220202            "signature": {
220203              "publicKey": {}
220204            }
220205          },
220206          "modelCard": {
220207            "modelParameters": {
220208              "approach": {}
220209            },
220210            "quantitativeAnalysis": {
220211              "graphics": {}
220212            },
220213            "considerations": {}
220214          }
220215        },
220216        {
220217          "type": "library",
220218          "bom-ref": "pkg:npm/got@7.1.0?package-id=8923e1498bfd9dd4",
220219          "supplier": {},
220220          "name": "got",
220221          "version": "7.1.0",
220222          "licenses": [
220223            {
220224              "license": {
220225                "id": "MIT"
220226              }
220227            }
220228          ],
220229          "cpe": "cpe:2.3:a:got:got:7.1.0:*:*:*:*:*:*:*",
220230          "purl": "pkg:npm/got@7.1.0",
220231          "swid": {
220232            "attachment": {}
220233          },
220234          "pedigree": {},
220235          "evidence": {},
220236          "signature": {
220237            "signature": {
220238              "publicKey": {}
220239            }
220240          },
220241          "modelCard": {
220242            "modelParameters": {
220243              "approach": {}
220244            },
220245            "quantitativeAnalysis": {
220246              "graphics": {}
220247            },
220248            "considerations": {}
220249          }
220250        },
220251        {
220252          "type": "library",
220253          "bom-ref": "pkg:npm/graceful-fs@4.2.11?package-id=61ac1a1312177452",
220254          "supplier": {},
220255          "name": "graceful-fs",
220256          "version": "4.2.11",
220257          "licenses": [
220258            {
220259              "license": {
220260                "id": "ISC"
220261              }
220262            }
220263          ],
220264          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.11:*:*:*:*:*:*:*",
220265          "purl": "pkg:npm/graceful-fs@4.2.11",
220266          "swid": {
220267            "attachment": {}
220268          },
220269          "pedigree": {},
220270          "evidence": {},
220271          "signature": {
220272            "signature": {
220273              "publicKey": {}
220274            }
220275          },
220276          "modelCard": {
220277            "modelParameters": {
220278              "approach": {}
220279            },
220280            "quantitativeAnalysis": {
220281              "graphics": {}
220282            },
220283            "considerations": {}
220284          }
220285        },
220286        {
220287          "type": "library",
220288          "bom-ref": "pkg:npm/gtoken@6.1.2?package-id=73a563f8c7a5bd92",
220289          "supplier": {},
220290          "name": "gtoken",
220291          "version": "6.1.2",
220292          "licenses": [
220293            {
220294              "license": {
220295                "id": "MIT"
220296              }
220297            }
220298          ],
220299          "cpe": "cpe:2.3:a:gtoken:gtoken:6.1.2:*:*:*:*:*:*:*",
220300          "purl": "pkg:npm/gtoken@6.1.2",
220301          "swid": {
220302            "attachment": {}
220303          },
220304          "pedigree": {},
220305          "evidence": {},
220306          "signature": {
220307            "signature": {
220308              "publicKey": {}
220309            }
220310          },
220311          "modelCard": {
220312            "modelParameters": {
220313              "approach": {}
220314            },
220315            "quantitativeAnalysis": {
220316              "graphics": {}
220317            },
220318            "considerations": {}
220319          }
220320        },
220321        {
220322          "type": "library",
220323          "bom-ref": "pkg:npm/har-schema@2.0.0?package-id=b1a2ebde8b267bd6",
220324          "supplier": {},
220325          "name": "har-schema",
220326          "version": "2.0.0",
220327          "licenses": [
220328            {
220329              "license": {
220330                "id": "ISC"
220331              }
220332            }
220333          ],
220334          "cpe": "cpe:2.3:a:har-schema:har-schema:2.0.0:*:*:*:*:*:*:*",
220335          "purl": "pkg:npm/har-schema@2.0.0",
220336          "swid": {
220337            "attachment": {}
220338          },
220339          "pedigree": {},
220340          "evidence": {},
220341          "signature": {
220342            "signature": {
220343              "publicKey": {}
220344            }
220345          },
220346          "modelCard": {
220347            "modelParameters": {
220348              "approach": {}
220349            },
220350            "quantitativeAnalysis": {
220351              "graphics": {}
220352            },
220353            "considerations": {}
220354          }
220355        },
220356        {
220357          "type": "library",
220358          "bom-ref": "pkg:npm/har-validator@5.1.3?package-id=ac87909b9cd270ec",
220359          "supplier": {},
220360          "name": "har-validator",
220361          "version": "5.1.3",
220362          "licenses": [
220363            {
220364              "license": {
220365                "id": "MIT"
220366              }
220367            }
220368          ],
220369          "cpe": "cpe:2.3:a:har-validator:har-validator:5.1.3:*:*:*:*:*:*:*",
220370          "purl": "pkg:npm/har-validator@5.1.3",
220371          "swid": {
220372            "attachment": {}
220373          },
220374          "pedigree": {},
220375          "evidence": {},
220376          "signature": {
220377            "signature": {
220378              "publicKey": {}
220379            }
220380          },
220381          "modelCard": {
220382            "modelParameters": {
220383              "approach": {}
220384            },
220385            "quantitativeAnalysis": {
220386              "graphics": {}
220387            },
220388            "considerations": {}
220389          }
220390        },
220391        {
220392          "type": "library",
220393          "bom-ref": "pkg:npm/has@1.0.3?package-id=8c4936faeea3f824",
220394          "supplier": {},
220395          "name": "has",
220396          "version": "1.0.3",
220397          "licenses": [
220398            {
220399              "license": {
220400                "id": "MIT"
220401              }
220402            }
220403          ],
220404          "cpe": "cpe:2.3:a:has:has:1.0.3:*:*:*:*:*:*:*",
220405          "purl": "pkg:npm/has@1.0.3",
220406          "swid": {
220407            "attachment": {}
220408          },
220409          "pedigree": {},
220410          "evidence": {},
220411          "signature": {
220412            "signature": {
220413              "publicKey": {}
220414            }
220415          },
220416          "modelCard": {
220417            "modelParameters": {
220418              "approach": {}
220419            },
220420            "quantitativeAnalysis": {
220421              "graphics": {}
220422            },
220423            "considerations": {}
220424          }
220425        },
220426        {
220427          "type": "library",
220428          "bom-ref": "pkg:npm/has-symbol-support-x@1.4.2?package-id=5e9008252db5c744",
220429          "supplier": {},
220430          "name": "has-symbol-support-x",
220431          "version": "1.4.2",
220432          "licenses": [
220433            {
220434              "license": {
220435                "id": "MIT"
220436              }
220437            }
220438          ],
220439          "cpe": "cpe:2.3:a:has-symbol-support-x:has-symbol-support-x:1.4.2:*:*:*:*:*:*:*",
220440          "purl": "pkg:npm/has-symbol-support-x@1.4.2",
220441          "swid": {
220442            "attachment": {}
220443          },
220444          "pedigree": {},
220445          "evidence": {},
220446          "signature": {
220447            "signature": {
220448              "publicKey": {}
220449            }
220450          },
220451          "modelCard": {
220452            "modelParameters": {
220453              "approach": {}
220454            },
220455            "quantitativeAnalysis": {
220456              "graphics": {}
220457            },
220458            "considerations": {}
220459          }
220460        },
220461        {
220462          "type": "library",
220463          "bom-ref": "pkg:npm/has-symbols@1.0.3?package-id=7ce61f2841af382e",
220464          "supplier": {},
220465          "name": "has-symbols",
220466          "version": "1.0.3",
220467          "licenses": [
220468            {
220469              "license": {
220470                "id": "MIT"
220471              }
220472            }
220473          ],
220474          "cpe": "cpe:2.3:a:has-symbols:has-symbols:1.0.3:*:*:*:*:*:*:*",
220475          "purl": "pkg:npm/has-symbols@1.0.3",
220476          "swid": {
220477            "attachment": {}
220478          },
220479          "pedigree": {},
220480          "evidence": {},
220481          "signature": {
220482            "signature": {
220483              "publicKey": {}
220484            }
220485          },
220486          "modelCard": {
220487            "modelParameters": {
220488              "approach": {}
220489            },
220490            "quantitativeAnalysis": {
220491              "graphics": {}
220492            },
220493            "considerations": {}
220494          }
220495        },
220496        {
220497          "type": "library",
220498          "bom-ref": "pkg:npm/has-to-string-tag-x@1.4.1?package-id=2e0b4b9c0fc821b7",
220499          "supplier": {},
220500          "name": "has-to-string-tag-x",
220501          "version": "1.4.1",
220502          "licenses": [
220503            {
220504              "license": {
220505                "id": "MIT"
220506              }
220507            }
220508          ],
220509          "cpe": "cpe:2.3:a:has-to-string-tag-x:has-to-string-tag-x:1.4.1:*:*:*:*:*:*:*",
220510          "purl": "pkg:npm/has-to-string-tag-x@1.4.1",
220511          "swid": {
220512            "attachment": {}
220513          },
220514          "pedigree": {},
220515          "evidence": {},
220516          "signature": {
220517            "signature": {
220518              "publicKey": {}
220519            }
220520          },
220521          "modelCard": {
220522            "modelParameters": {
220523              "approach": {}
220524            },
220525            "quantitativeAnalysis": {
220526              "graphics": {}
220527            },
220528            "considerations": {}
220529          }
220530        },
220531        {
220532          "type": "library",
220533          "bom-ref": "pkg:npm/help-me@3.0.0?package-id=603d25f748e5e9e0",
220534          "supplier": {},
220535          "name": "help-me",
220536          "version": "3.0.0",
220537          "licenses": [
220538            {
220539              "license": {
220540                "id": "MIT"
220541              }
220542            }
220543          ],
220544          "cpe": "cpe:2.3:a:help-me:help-me:3.0.0:*:*:*:*:*:*:*",
220545          "purl": "pkg:npm/help-me@3.0.0",
220546          "swid": {
220547            "attachment": {}
220548          },
220549          "pedigree": {},
220550          "evidence": {},
220551          "signature": {
220552            "signature": {
220553              "publicKey": {}
220554            }
220555          },
220556          "modelCard": {
220557            "modelParameters": {
220558              "approach": {}
220559            },
220560            "quantitativeAnalysis": {
220561              "graphics": {}
220562            },
220563            "considerations": {}
220564          }
220565        },
220566        {
220567          "type": "library",
220568          "bom-ref": "pkg:npm/http-proxy-agent@5.0.0?package-id=1ea51dd78ab16e66",
220569          "supplier": {},
220570          "name": "http-proxy-agent",
220571          "version": "5.0.0",
220572          "licenses": [
220573            {
220574              "license": {
220575                "id": "MIT"
220576              }
220577            }
220578          ],
220579          "cpe": "cpe:2.3:a:http-proxy-agent:http-proxy-agent:5.0.0:*:*:*:*:*:*:*",
220580          "purl": "pkg:npm/http-proxy-agent@5.0.0",
220581          "swid": {
220582            "attachment": {}
220583          },
220584          "pedigree": {},
220585          "evidence": {},
220586          "signature": {
220587            "signature": {
220588              "publicKey": {}
220589            }
220590          },
220591          "modelCard": {
220592            "modelParameters": {
220593              "approach": {}
220594            },
220595            "quantitativeAnalysis": {
220596              "graphics": {}
220597            },
220598            "considerations": {}
220599          }
220600        },
220601        {
220602          "type": "library",
220603          "bom-ref": "pkg:npm/http-signature@1.2.0?package-id=eab31ef7fd190da4",
220604          "supplier": {},
220605          "name": "http-signature",
220606          "version": "1.2.0",
220607          "licenses": [
220608            {
220609              "license": {
220610                "id": "MIT"
220611              }
220612            }
220613          ],
220614          "cpe": "cpe:2.3:a:http-signature:http-signature:1.2.0:*:*:*:*:*:*:*",
220615          "purl": "pkg:npm/http-signature@1.2.0",
220616          "swid": {
220617            "attachment": {}
220618          },
220619          "pedigree": {},
220620          "evidence": {},
220621          "signature": {
220622            "signature": {
220623              "publicKey": {}
220624            }
220625          },
220626          "modelCard": {
220627            "modelParameters": {
220628              "approach": {}
220629            },
220630            "quantitativeAnalysis": {
220631              "graphics": {}
220632            },
220633            "considerations": {}
220634          }
220635        },
220636        {
220637          "type": "library",
220638          "bom-ref": "pkg:npm/httpntlm@1.7.7?package-id=686f85abe23b00de",
220639          "supplier": {},
220640          "name": "httpntlm",
220641          "version": "1.7.7",
220642          "licenses": [
220643            {
220644              "license": {
220645                "id": "MIT"
220646              }
220647            }
220648          ],
220649          "cpe": "cpe:2.3:a:httpntlm:httpntlm:1.7.7:*:*:*:*:*:*:*",
220650          "purl": "pkg:npm/httpntlm@1.7.7",
220651          "swid": {
220652            "attachment": {}
220653          },
220654          "pedigree": {},
220655          "evidence": {},
220656          "signature": {
220657            "signature": {
220658              "publicKey": {}
220659            }
220660          },
220661          "modelCard": {
220662            "modelParameters": {
220663              "approach": {}
220664            },
220665            "quantitativeAnalysis": {
220666              "graphics": {}
220667            },
220668            "considerations": {}
220669          }
220670        },
220671        {
220672          "type": "library",
220673          "bom-ref": "pkg:npm/httpreq@0.5.2?package-id=a117cb304356570d",
220674          "supplier": {},
220675          "name": "httpreq",
220676          "version": "0.5.2",
220677          "licenses": [
220678            {
220679              "license": {
220680                "id": "MIT"
220681              }
220682            }
220683          ],
220684          "cpe": "cpe:2.3:a:httpreq:httpreq:0.5.2:*:*:*:*:*:*:*",
220685          "purl": "pkg:npm/httpreq@0.5.2",
220686          "swid": {
220687            "attachment": {}
220688          },
220689          "pedigree": {},
220690          "evidence": {},
220691          "signature": {
220692            "signature": {
220693              "publicKey": {}
220694            }
220695          },
220696          "modelCard": {
220697            "modelParameters": {
220698              "approach": {}
220699            },
220700            "quantitativeAnalysis": {
220701              "graphics": {}
220702            },
220703            "considerations": {}
220704          }
220705        },
220706        {
220707          "type": "library",
220708          "bom-ref": "pkg:npm/https-proxy-agent@5.0.1?package-id=fa298b452afab32c",
220709          "supplier": {},
220710          "name": "https-proxy-agent",
220711          "version": "5.0.1",
220712          "licenses": [
220713            {
220714              "license": {
220715                "id": "MIT"
220716              }
220717            }
220718          ],
220719          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:5.0.1:*:*:*:*:*:*:*",
220720          "purl": "pkg:npm/https-proxy-agent@5.0.1",
220721          "swid": {
220722            "attachment": {}
220723          },
220724          "pedigree": {},
220725          "evidence": {},
220726          "signature": {
220727            "signature": {
220728              "publicKey": {}
220729            }
220730          },
220731          "modelCard": {
220732            "modelParameters": {
220733              "approach": {}
220734            },
220735            "quantitativeAnalysis": {
220736              "graphics": {}
220737            },
220738            "considerations": {}
220739          }
220740        },
220741        {
220742          "type": "library",
220743          "bom-ref": "pkg:npm/iconv-lite@0.6.3?package-id=d61ec7b4dcdc2ade",
220744          "supplier": {},
220745          "name": "iconv-lite",
220746          "version": "0.6.3",
220747          "licenses": [
220748            {
220749              "license": {
220750                "id": "MIT"
220751              }
220752            }
220753          ],
220754          "cpe": "cpe:2.3:a:iconv-lite:iconv-lite:0.6.3:*:*:*:*:*:*:*",
220755          "purl": "pkg:npm/iconv-lite@0.6.3",
220756          "swid": {
220757            "attachment": {}
220758          },
220759          "pedigree": {},
220760          "evidence": {},
220761          "signature": {
220762            "signature": {
220763              "publicKey": {}
220764            }
220765          },
220766          "modelCard": {
220767            "modelParameters": {
220768              "approach": {}
220769            },
220770            "quantitativeAnalysis": {
220771              "graphics": {}
220772            },
220773            "considerations": {}
220774          }
220775        },
220776        {
220777          "type": "library",
220778          "bom-ref": "pkg:npm/ieee754@1.2.1?package-id=50638262b62e811e",
220779          "supplier": {},
220780          "name": "ieee754",
220781          "version": "1.2.1",
220782          "licenses": [
220783            {
220784              "license": {
220785                "id": "BSD-3-Clause"
220786              }
220787            }
220788          ],
220789          "cpe": "cpe:2.3:a:ieee754:ieee754:1.2.1:*:*:*:*:*:*:*",
220790          "purl": "pkg:npm/ieee754@1.2.1",
220791          "swid": {
220792            "attachment": {}
220793          },
220794          "pedigree": {},
220795          "evidence": {},
220796          "signature": {
220797            "signature": {
220798              "publicKey": {}
220799            }
220800          },
220801          "modelCard": {
220802            "modelParameters": {
220803              "approach": {}
220804            },
220805            "quantitativeAnalysis": {
220806              "graphics": {}
220807            },
220808            "considerations": {}
220809          }
220810        },
220811        {
220812          "type": "library",
220813          "bom-ref": "pkg:npm/immediate@3.0.6?package-id=1b5cd6b87ec2fe33",
220814          "supplier": {},
220815          "name": "immediate",
220816          "version": "3.0.6",
220817          "licenses": [
220818            {
220819              "license": {
220820                "id": "MIT"
220821              }
220822            }
220823          ],
220824          "cpe": "cpe:2.3:a:immediate:immediate:3.0.6:*:*:*:*:*:*:*",
220825          "purl": "pkg:npm/immediate@3.0.6",
220826          "swid": {
220827            "attachment": {}
220828          },
220829          "pedigree": {},
220830          "evidence": {},
220831          "signature": {
220832            "signature": {
220833              "publicKey": {}
220834            }
220835          },
220836          "modelCard": {
220837            "modelParameters": {
220838              "approach": {}
220839            },
220840            "quantitativeAnalysis": {
220841              "graphics": {}
220842            },
220843            "considerations": {}
220844          }
220845        },
220846        {
220847          "type": "library",
220848          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=bb1fb09a39e4138f",
220849          "supplier": {},
220850          "name": "inflight",
220851          "version": "1.0.6",
220852          "licenses": [
220853            {
220854              "license": {
220855                "id": "ISC"
220856              }
220857            }
220858          ],
220859          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
220860          "purl": "pkg:npm/inflight@1.0.6",
220861          "swid": {
220862            "attachment": {}
220863          },
220864          "pedigree": {},
220865          "evidence": {},
220866          "signature": {
220867            "signature": {
220868              "publicKey": {}
220869            }
220870          },
220871          "modelCard": {
220872            "modelParameters": {
220873              "approach": {}
220874            },
220875            "quantitativeAnalysis": {
220876              "graphics": {}
220877            },
220878            "considerations": {}
220879          }
220880        },
220881        {
220882          "type": "library",
220883          "bom-ref": "pkg:npm/inherits@2.0.3?package-id=76c148c0e64d7ca9",
220884          "supplier": {},
220885          "name": "inherits",
220886          "version": "2.0.3",
220887          "licenses": [
220888            {
220889              "license": {
220890                "id": "ISC"
220891              }
220892            }
220893          ],
220894          "cpe": "cpe:2.3:a:inherits:inherits:2.0.3:*:*:*:*:*:*:*",
220895          "purl": "pkg:npm/inherits@2.0.3",
220896          "swid": {
220897            "attachment": {}
220898          },
220899          "pedigree": {},
220900          "evidence": {},
220901          "signature": {
220902            "signature": {
220903              "publicKey": {}
220904            }
220905          },
220906          "modelCard": {
220907            "modelParameters": {
220908              "approach": {}
220909            },
220910            "quantitativeAnalysis": {
220911              "graphics": {}
220912            },
220913            "considerations": {}
220914          }
220915        },
220916        {
220917          "type": "library",
220918          "bom-ref": "pkg:npm/ini@1.3.8?package-id=31d2f9dab70f6e2d",
220919          "supplier": {},
220920          "name": "ini",
220921          "version": "1.3.8",
220922          "licenses": [
220923            {
220924              "license": {
220925                "id": "ISC"
220926              }
220927            }
220928          ],
220929          "cpe": "cpe:2.3:a:ini:ini:1.3.8:*:*:*:*:*:*:*",
220930          "purl": "pkg:npm/ini@1.3.8",
220931          "swid": {
220932            "attachment": {}
220933          },
220934          "pedigree": {},
220935          "evidence": {},
220936          "signature": {
220937            "signature": {
220938              "publicKey": {}
220939            }
220940          },
220941          "modelCard": {
220942            "modelParameters": {
220943              "approach": {}
220944            },
220945            "quantitativeAnalysis": {
220946              "graphics": {}
220947            },
220948            "considerations": {}
220949          }
220950        },
220951        {
220952          "type": "library",
220953          "bom-ref": "pkg:npm/ip-regex@2.1.0?package-id=7145867c23651176",
220954          "supplier": {},
220955          "name": "ip-regex",
220956          "version": "2.1.0",
220957          "licenses": [
220958            {
220959              "license": {
220960                "id": "MIT"
220961              }
220962            }
220963          ],
220964          "cpe": "cpe:2.3:a:ip-regex:ip-regex:2.1.0:*:*:*:*:*:*:*",
220965          "purl": "pkg:npm/ip-regex@2.1.0",
220966          "swid": {
220967            "attachment": {}
220968          },
220969          "pedigree": {},
220970          "evidence": {},
220971          "signature": {
220972            "signature": {
220973              "publicKey": {}
220974            }
220975          },
220976          "modelCard": {
220977            "modelParameters": {
220978              "approach": {}
220979            },
220980            "quantitativeAnalysis": {
220981              "graphics": {}
220982            },
220983            "considerations": {}
220984          }
220985        },
220986        {
220987          "type": "library",
220988          "bom-ref": "pkg:npm/ipaddr.js@0.1.9?package-id=cdeccd7131cc7730",
220989          "supplier": {},
220990          "name": "ipaddr.js",
220991          "version": "0.1.9",
220992          "licenses": [
220993            {
220994              "license": {
220995                "id": "MIT"
220996              }
220997            }
220998          ],
220999          "cpe": "cpe:2.3:a:ipaddr.js:ipaddr.js:0.1.9:*:*:*:*:*:*:*",
221000          "purl": "pkg:npm/ipaddr.js@0.1.9",
221001          "swid": {
221002            "attachment": {}
221003          },
221004          "pedigree": {},
221005          "evidence": {},
221006          "signature": {
221007            "signature": {
221008              "publicKey": {}
221009            }
221010          },
221011          "modelCard": {
221012            "modelParameters": {
221013              "approach": {}
221014            },
221015            "quantitativeAnalysis": {
221016              "graphics": {}
221017            },
221018            "considerations": {}
221019          }
221020        },
221021        {
221022          "type": "library",
221023          "bom-ref": "pkg:npm/is-buffer@1.1.6?package-id=8a6b8aeccfd36bf9",
221024          "supplier": {},
221025          "name": "is-buffer",
221026          "version": "1.1.6",
221027          "licenses": [
221028            {
221029              "license": {
221030                "id": "MIT"
221031              }
221032            }
221033          ],
221034          "cpe": "cpe:2.3:a:is-buffer:is-buffer:1.1.6:*:*:*:*:*:*:*",
221035          "purl": "pkg:npm/is-buffer@1.1.6",
221036          "swid": {
221037            "attachment": {}
221038          },
221039          "pedigree": {},
221040          "evidence": {},
221041          "signature": {
221042            "signature": {
221043              "publicKey": {}
221044            }
221045          },
221046          "modelCard": {
221047            "modelParameters": {
221048              "approach": {}
221049            },
221050            "quantitativeAnalysis": {
221051              "graphics": {}
221052            },
221053            "considerations": {}
221054          }
221055        },
221056        {
221057          "type": "library",
221058          "bom-ref": "pkg:npm/is-docker@2.2.1?package-id=d1c8eece895a6a7c",
221059          "supplier": {},
221060          "name": "is-docker",
221061          "version": "2.2.1",
221062          "licenses": [
221063            {
221064              "license": {
221065                "id": "MIT"
221066              }
221067            }
221068          ],
221069          "cpe": "cpe:2.3:a:is-docker:is-docker:2.2.1:*:*:*:*:*:*:*",
221070          "purl": "pkg:npm/is-docker@2.2.1",
221071          "swid": {
221072            "attachment": {}
221073          },
221074          "pedigree": {},
221075          "evidence": {},
221076          "signature": {
221077            "signature": {
221078              "publicKey": {}
221079            }
221080          },
221081          "modelCard": {
221082            "modelParameters": {
221083              "approach": {}
221084            },
221085            "quantitativeAnalysis": {
221086              "graphics": {}
221087            },
221088            "considerations": {}
221089          }
221090        },
221091        {
221092          "type": "library",
221093          "bom-ref": "pkg:npm/is-extglob@1.0.0?package-id=9bd06efc38021620",
221094          "supplier": {},
221095          "name": "is-extglob",
221096          "version": "1.0.0",
221097          "licenses": [
221098            {
221099              "license": {
221100                "id": "MIT"
221101              }
221102            }
221103          ],
221104          "cpe": "cpe:2.3:a:is-extglob:is-extglob:1.0.0:*:*:*:*:*:*:*",
221105          "purl": "pkg:npm/is-extglob@1.0.0",
221106          "swid": {
221107            "attachment": {}
221108          },
221109          "pedigree": {},
221110          "evidence": {},
221111          "signature": {
221112            "signature": {
221113              "publicKey": {}
221114            }
221115          },
221116          "modelCard": {
221117            "modelParameters": {
221118              "approach": {}
221119            },
221120            "quantitativeAnalysis": {
221121              "graphics": {}
221122            },
221123            "considerations": {}
221124          }
221125        },
221126        {
221127          "type": "library",
221128          "bom-ref": "pkg:npm/is-fullwidth-code-point@3.0.0?package-id=4b31e427326967cf",
221129          "supplier": {},
221130          "name": "is-fullwidth-code-point",
221131          "version": "3.0.0",
221132          "licenses": [
221133            {
221134              "license": {
221135                "id": "MIT"
221136              }
221137            }
221138          ],
221139          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:3.0.0:*:*:*:*:*:*:*",
221140          "purl": "pkg:npm/is-fullwidth-code-point@3.0.0",
221141          "swid": {
221142            "attachment": {}
221143          },
221144          "pedigree": {},
221145          "evidence": {},
221146          "signature": {
221147            "signature": {
221148              "publicKey": {}
221149            }
221150          },
221151          "modelCard": {
221152            "modelParameters": {
221153              "approach": {}
221154            },
221155            "quantitativeAnalysis": {
221156              "graphics": {}
221157            },
221158            "considerations": {}
221159          }
221160        },
221161        {
221162          "type": "library",
221163          "bom-ref": "pkg:npm/is-glob@2.0.1?package-id=927d27e260c7aa94",
221164          "supplier": {},
221165          "name": "is-glob",
221166          "version": "2.0.1",
221167          "licenses": [
221168            {
221169              "license": {
221170                "id": "MIT"
221171              }
221172            }
221173          ],
221174          "cpe": "cpe:2.3:a:is-glob:is-glob:2.0.1:*:*:*:*:*:*:*",
221175          "purl": "pkg:npm/is-glob@2.0.1",
221176          "swid": {
221177            "attachment": {}
221178          },
221179          "pedigree": {},
221180          "evidence": {},
221181          "signature": {
221182            "signature": {
221183              "publicKey": {}
221184            }
221185          },
221186          "modelCard": {
221187            "modelParameters": {
221188              "approach": {}
221189            },
221190            "quantitativeAnalysis": {
221191              "graphics": {}
221192            },
221193            "considerations": {}
221194          }
221195        },
221196        {
221197          "type": "library",
221198          "bom-ref": "pkg:npm/is-invalid-path@0.1.0?package-id=b41f9cac05cb592b",
221199          "supplier": {},
221200          "name": "is-invalid-path",
221201          "version": "0.1.0",
221202          "licenses": [
221203            {
221204              "license": {
221205                "id": "MIT"
221206              }
221207            }
221208          ],
221209          "cpe": "cpe:2.3:a:is-invalid-path:is-invalid-path:0.1.0:*:*:*:*:*:*:*",
221210          "purl": "pkg:npm/is-invalid-path@0.1.0",
221211          "swid": {
221212            "attachment": {}
221213          },
221214          "pedigree": {},
221215          "evidence": {},
221216          "signature": {
221217            "signature": {
221218              "publicKey": {}
221219            }
221220          },
221221          "modelCard": {
221222            "modelParameters": {
221223              "approach": {}
221224            },
221225            "quantitativeAnalysis": {
221226              "graphics": {}
221227            },
221228            "considerations": {}
221229          }
221230        },
221231        {
221232          "type": "library",
221233          "bom-ref": "pkg:npm/is-natural-number@4.0.1?package-id=e6c93265936b6c47",
221234          "supplier": {},
221235          "name": "is-natural-number",
221236          "version": "4.0.1",
221237          "licenses": [
221238            {
221239              "license": {
221240                "id": "MIT"
221241              }
221242            }
221243          ],
221244          "cpe": "cpe:2.3:a:is-natural-number:is-natural-number:4.0.1:*:*:*:*:*:*:*",
221245          "purl": "pkg:npm/is-natural-number@4.0.1",
221246          "swid": {
221247            "attachment": {}
221248          },
221249          "pedigree": {},
221250          "evidence": {},
221251          "signature": {
221252            "signature": {
221253              "publicKey": {}
221254            }
221255          },
221256          "modelCard": {
221257            "modelParameters": {
221258              "approach": {}
221259            },
221260            "quantitativeAnalysis": {
221261              "graphics": {}
221262            },
221263            "considerations": {}
221264          }
221265        },
221266        {
221267          "type": "library",
221268          "bom-ref": "pkg:npm/is-object@1.0.2?package-id=34c318604551d0cf",
221269          "supplier": {},
221270          "name": "is-object",
221271          "version": "1.0.2",
221272          "licenses": [
221273            {
221274              "license": {
221275                "id": "MIT"
221276              }
221277            }
221278          ],
221279          "cpe": "cpe:2.3:a:is-object:is-object:1.0.2:*:*:*:*:*:*:*",
221280          "purl": "pkg:npm/is-object@1.0.2",
221281          "swid": {
221282            "attachment": {}
221283          },
221284          "pedigree": {},
221285          "evidence": {},
221286          "signature": {
221287            "signature": {
221288              "publicKey": {}
221289            }
221290          },
221291          "modelCard": {
221292            "modelParameters": {
221293              "approach": {}
221294            },
221295            "quantitativeAnalysis": {
221296              "graphics": {}
221297            },
221298            "considerations": {}
221299          }
221300        },
221301        {
221302          "type": "library",
221303          "bom-ref": "pkg:npm/is-plain-obj@1.1.0?package-id=2e3359b4a0319950",
221304          "supplier": {},
221305          "name": "is-plain-obj",
221306          "version": "1.1.0",
221307          "licenses": [
221308            {
221309              "license": {
221310                "id": "MIT"
221311              }
221312            }
221313          ],
221314          "cpe": "cpe:2.3:a:is-plain-obj:is-plain-obj:1.1.0:*:*:*:*:*:*:*",
221315          "purl": "pkg:npm/is-plain-obj@1.1.0",
221316          "swid": {
221317            "attachment": {}
221318          },
221319          "pedigree": {},
221320          "evidence": {},
221321          "signature": {
221322            "signature": {
221323              "publicKey": {}
221324            }
221325          },
221326          "modelCard": {
221327            "modelParameters": {
221328              "approach": {}
221329            },
221330            "quantitativeAnalysis": {
221331              "graphics": {}
221332            },
221333            "considerations": {}
221334          }
221335        },
221336        {
221337          "type": "library",
221338          "bom-ref": "pkg:npm/is-property@1.0.2?package-id=56ad99e7e3e52d48",
221339          "supplier": {},
221340          "name": "is-property",
221341          "version": "1.0.2",
221342          "licenses": [
221343            {
221344              "license": {
221345                "id": "MIT"
221346              }
221347            }
221348          ],
221349          "cpe": "cpe:2.3:a:is-property:is-property:1.0.2:*:*:*:*:*:*:*",
221350          "purl": "pkg:npm/is-property@1.0.2",
221351          "swid": {
221352            "attachment": {}
221353          },
221354          "pedigree": {},
221355          "evidence": {},
221356          "signature": {
221357            "signature": {
221358              "publicKey": {}
221359            }
221360          },
221361          "modelCard": {
221362            "modelParameters": {
221363              "approach": {}
221364            },
221365            "quantitativeAnalysis": {
221366              "graphics": {}
221367            },
221368            "considerations": {}
221369          }
221370        },
221371        {
221372          "type": "library",
221373          "bom-ref": "pkg:npm/is-retry-allowed@1.2.0?package-id=d3c2758210c3daf5",
221374          "supplier": {},
221375          "name": "is-retry-allowed",
221376          "version": "1.2.0",
221377          "licenses": [
221378            {
221379              "license": {
221380                "id": "MIT"
221381              }
221382            }
221383          ],
221384          "cpe": "cpe:2.3:a:is-retry-allowed:is-retry-allowed:1.2.0:*:*:*:*:*:*:*",
221385          "purl": "pkg:npm/is-retry-allowed@1.2.0",
221386          "swid": {
221387            "attachment": {}
221388          },
221389          "pedigree": {},
221390          "evidence": {},
221391          "signature": {
221392            "signature": {
221393              "publicKey": {}
221394            }
221395          },
221396          "modelCard": {
221397            "modelParameters": {
221398              "approach": {}
221399            },
221400            "quantitativeAnalysis": {
221401              "graphics": {}
221402            },
221403            "considerations": {}
221404          }
221405        },
221406        {
221407          "type": "library",
221408          "bom-ref": "pkg:npm/is-stream@2.0.1?package-id=b8ef357f765bad52",
221409          "supplier": {},
221410          "name": "is-stream",
221411          "version": "2.0.1",
221412          "licenses": [
221413            {
221414              "license": {
221415                "id": "MIT"
221416              }
221417            }
221418          ],
221419          "cpe": "cpe:2.3:a:is-stream:is-stream:2.0.1:*:*:*:*:*:*:*",
221420          "purl": "pkg:npm/is-stream@2.0.1",
221421          "swid": {
221422            "attachment": {}
221423          },
221424          "pedigree": {},
221425          "evidence": {},
221426          "signature": {
221427            "signature": {
221428              "publicKey": {}
221429            }
221430          },
221431          "modelCard": {
221432            "modelParameters": {
221433              "approach": {}
221434            },
221435            "quantitativeAnalysis": {
221436              "graphics": {}
221437            },
221438            "considerations": {}
221439          }
221440        },
221441        {
221442          "type": "library",
221443          "bom-ref": "pkg:npm/is-typedarray@1.0.0?package-id=a8a7526a7be6ffaf",
221444          "supplier": {},
221445          "name": "is-typedarray",
221446          "version": "1.0.0",
221447          "licenses": [
221448            {
221449              "license": {
221450                "id": "MIT"
221451              }
221452            }
221453          ],
221454          "cpe": "cpe:2.3:a:is-typedarray:is-typedarray:1.0.0:*:*:*:*:*:*:*",
221455          "purl": "pkg:npm/is-typedarray@1.0.0",
221456          "swid": {
221457            "attachment": {}
221458          },
221459          "pedigree": {},
221460          "evidence": {},
221461          "signature": {
221462            "signature": {
221463              "publicKey": {}
221464            }
221465          },
221466          "modelCard": {
221467            "modelParameters": {
221468              "approach": {}
221469            },
221470            "quantitativeAnalysis": {
221471              "graphics": {}
221472            },
221473            "considerations": {}
221474          }
221475        },
221476        {
221477          "type": "library",
221478          "bom-ref": "pkg:npm/is-valid-path@0.1.1?package-id=2254b989bf73c502",
221479          "supplier": {},
221480          "name": "is-valid-path",
221481          "version": "0.1.1",
221482          "licenses": [
221483            {
221484              "license": {
221485                "id": "MIT"
221486              }
221487            }
221488          ],
221489          "cpe": "cpe:2.3:a:is-valid-path:is-valid-path:0.1.1:*:*:*:*:*:*:*",
221490          "purl": "pkg:npm/is-valid-path@0.1.1",
221491          "swid": {
221492            "attachment": {}
221493          },
221494          "pedigree": {},
221495          "evidence": {},
221496          "signature": {
221497            "signature": {
221498              "publicKey": {}
221499            }
221500          },
221501          "modelCard": {
221502            "modelParameters": {
221503              "approach": {}
221504            },
221505            "quantitativeAnalysis": {
221506              "graphics": {}
221507            },
221508            "considerations": {}
221509          }
221510        },
221511        {
221512          "type": "library",
221513          "bom-ref": "pkg:npm/is-wsl@2.2.0?package-id=4d541859b87a4641",
221514          "supplier": {},
221515          "name": "is-wsl",
221516          "version": "2.2.0",
221517          "licenses": [
221518            {
221519              "license": {
221520                "id": "MIT"
221521              }
221522            }
221523          ],
221524          "cpe": "cpe:2.3:a:is-wsl:is-wsl:2.2.0:*:*:*:*:*:*:*",
221525          "purl": "pkg:npm/is-wsl@2.2.0",
221526          "swid": {
221527            "attachment": {}
221528          },
221529          "pedigree": {},
221530          "evidence": {},
221531          "signature": {
221532            "signature": {
221533              "publicKey": {}
221534            }
221535          },
221536          "modelCard": {
221537            "modelParameters": {
221538              "approach": {}
221539            },
221540            "quantitativeAnalysis": {
221541              "graphics": {}
221542            },
221543            "considerations": {}
221544          }
221545        },
221546        {
221547          "type": "library",
221548          "bom-ref": "pkg:npm/isarray@0.0.1?package-id=f2e7f731afad59b6",
221549          "supplier": {},
221550          "name": "isarray",
221551          "version": "0.0.1",
221552          "licenses": [
221553            {
221554              "license": {
221555                "id": "MIT"
221556              }
221557            }
221558          ],
221559          "cpe": "cpe:2.3:a:isarray:isarray:0.0.1:*:*:*:*:*:*:*",
221560          "purl": "pkg:npm/isarray@0.0.1",
221561          "swid": {
221562            "attachment": {}
221563          },
221564          "pedigree": {},
221565          "evidence": {},
221566          "signature": {
221567            "signature": {
221568              "publicKey": {}
221569            }
221570          },
221571          "modelCard": {
221572            "modelParameters": {
221573              "approach": {}
221574            },
221575            "quantitativeAnalysis": {
221576              "graphics": {}
221577            },
221578            "considerations": {}
221579          }
221580        },
221581        {
221582          "type": "library",
221583          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=52ecba3ab693bf39",
221584          "supplier": {},
221585          "name": "isexe",
221586          "version": "2.0.0",
221587          "licenses": [
221588            {
221589              "license": {
221590                "id": "ISC"
221591              }
221592            }
221593          ],
221594          "cpe": "cpe:2.3:a:isexe:isexe:2.0.0:*:*:*:*:*:*:*",
221595          "purl": "pkg:npm/isexe@2.0.0",
221596          "swid": {
221597            "attachment": {}
221598          },
221599          "pedigree": {},
221600          "evidence": {},
221601          "signature": {
221602            "signature": {
221603              "publicKey": {}
221604            }
221605          },
221606          "modelCard": {
221607            "modelParameters": {
221608              "approach": {}
221609            },
221610            "quantitativeAnalysis": {
221611              "graphics": {}
221612            },
221613            "considerations": {}
221614          }
221615        },
221616        {
221617          "type": "library",
221618          "bom-ref": "pkg:npm/isstream@0.1.2?package-id=6de000f9ce16c1f",
221619          "supplier": {},
221620          "name": "isstream",
221621          "version": "0.1.2",
221622          "licenses": [
221623            {
221624              "license": {
221625                "id": "MIT"
221626              }
221627            }
221628          ],
221629          "cpe": "cpe:2.3:a:isstream:isstream:0.1.2:*:*:*:*:*:*:*",
221630          "purl": "pkg:npm/isstream@0.1.2",
221631          "swid": {
221632            "attachment": {}
221633          },
221634          "pedigree": {},
221635          "evidence": {},
221636          "signature": {
221637            "signature": {
221638              "publicKey": {}
221639            }
221640          },
221641          "modelCard": {
221642            "modelParameters": {
221643              "approach": {}
221644            },
221645            "quantitativeAnalysis": {
221646              "graphics": {}
221647            },
221648            "considerations": {}
221649          }
221650        },
221651        {
221652          "type": "library",
221653          "bom-ref": "pkg:npm/isurl@1.0.0?package-id=e81c672d21cd7273",
221654          "supplier": {},
221655          "name": "isurl",
221656          "version": "1.0.0",
221657          "licenses": [
221658            {
221659              "license": {
221660                "id": "MIT"
221661              }
221662            }
221663          ],
221664          "cpe": "cpe:2.3:a:isurl:isurl:1.0.0:*:*:*:*:*:*:*",
221665          "purl": "pkg:npm/isurl@1.0.0",
221666          "swid": {
221667            "attachment": {}
221668          },
221669          "pedigree": {},
221670          "evidence": {},
221671          "signature": {
221672            "signature": {
221673              "publicKey": {}
221674            }
221675          },
221676          "modelCard": {
221677            "modelParameters": {
221678              "approach": {}
221679            },
221680            "quantitativeAnalysis": {
221681              "graphics": {}
221682            },
221683            "considerations": {}
221684          }
221685        },
221686        {
221687          "type": "library",
221688          "bom-ref": "pkg:npm/joi@17.9.1?package-id=63f4c46d01f7c012",
221689          "supplier": {},
221690          "name": "joi",
221691          "version": "17.9.1",
221692          "licenses": [
221693            {
221694              "license": {
221695                "id": "BSD-3-Clause"
221696              }
221697            }
221698          ],
221699          "cpe": "cpe:2.3:a:joi:joi:17.9.1:*:*:*:*:*:*:*",
221700          "purl": "pkg:npm/joi@17.9.1",
221701          "swid": {
221702            "attachment": {}
221703          },
221704          "pedigree": {},
221705          "evidence": {},
221706          "signature": {
221707            "signature": {
221708              "publicKey": {}
221709            }
221710          },
221711          "modelCard": {
221712            "modelParameters": {
221713              "approach": {}
221714            },
221715            "quantitativeAnalysis": {
221716              "graphics": {}
221717            },
221718            "considerations": {}
221719          }
221720        },
221721        {
221722          "type": "library",
221723          "bom-ref": "pkg:npm/jose@2.0.6?package-id=f76276a4f3e5a941",
221724          "supplier": {},
221725          "name": "jose",
221726          "version": "2.0.6",
221727          "licenses": [
221728            {
221729              "license": {
221730                "id": "MIT"
221731              }
221732            }
221733          ],
221734          "cpe": "cpe:2.3:a:jose:jose:2.0.6:*:*:*:*:*:*:*",
221735          "purl": "pkg:npm/jose@2.0.6",
221736          "swid": {
221737            "attachment": {}
221738          },
221739          "pedigree": {},
221740          "evidence": {},
221741          "signature": {
221742            "signature": {
221743              "publicKey": {}
221744            }
221745          },
221746          "modelCard": {
221747            "modelParameters": {
221748              "approach": {}
221749            },
221750            "quantitativeAnalysis": {
221751              "graphics": {}
221752            },
221753            "considerations": {}
221754          }
221755        },
221756        {
221757          "type": "library",
221758          "bom-ref": "pkg:npm/js-sdsl@4.3.0?package-id=ab665d09c6328b7d",
221759          "supplier": {},
221760          "name": "js-sdsl",
221761          "version": "4.3.0",
221762          "licenses": [
221763            {
221764              "license": {
221765                "id": "MIT"
221766              }
221767            }
221768          ],
221769          "cpe": "cpe:2.3:a:js-sdsl:js-sdsl:4.3.0:*:*:*:*:*:*:*",
221770          "purl": "pkg:npm/js-sdsl@4.3.0",
221771          "swid": {
221772            "attachment": {}
221773          },
221774          "pedigree": {},
221775          "evidence": {},
221776          "signature": {
221777            "signature": {
221778              "publicKey": {}
221779            }
221780          },
221781          "modelCard": {
221782            "modelParameters": {
221783              "approach": {}
221784            },
221785            "quantitativeAnalysis": {
221786              "graphics": {}
221787            },
221788            "considerations": {}
221789          }
221790        },
221791        {
221792          "type": "library",
221793          "bom-ref": "pkg:npm/jsbi@3.2.5?package-id=310cc3efe77a9210",
221794          "supplier": {},
221795          "name": "jsbi",
221796          "version": "3.2.5",
221797          "licenses": [
221798            {
221799              "license": {
221800                "id": "Apache-2.0"
221801              }
221802            }
221803          ],
221804          "cpe": "cpe:2.3:a:jsbi:jsbi:3.2.5:*:*:*:*:*:*:*",
221805          "purl": "pkg:npm/jsbi@3.2.5",
221806          "swid": {
221807            "attachment": {}
221808          },
221809          "pedigree": {},
221810          "evidence": {},
221811          "signature": {
221812            "signature": {
221813              "publicKey": {}
221814            }
221815          },
221816          "modelCard": {
221817            "modelParameters": {
221818              "approach": {}
221819            },
221820            "quantitativeAnalysis": {
221821              "graphics": {}
221822            },
221823            "considerations": {}
221824          }
221825        },
221826        {
221827          "type": "library",
221828          "bom-ref": "pkg:npm/jsbn@0.1.1?package-id=180bcccaba7b462f",
221829          "supplier": {},
221830          "name": "jsbn",
221831          "version": "0.1.1",
221832          "licenses": [
221833            {
221834              "license": {
221835                "id": "MIT"
221836              }
221837            }
221838          ],
221839          "cpe": "cpe:2.3:a:jsbn:jsbn:0.1.1:*:*:*:*:*:*:*",
221840          "purl": "pkg:npm/jsbn@0.1.1",
221841          "swid": {
221842            "attachment": {}
221843          },
221844          "pedigree": {},
221845          "evidence": {},
221846          "signature": {
221847            "signature": {
221848              "publicKey": {}
221849            }
221850          },
221851          "modelCard": {
221852            "modelParameters": {
221853              "approach": {}
221854            },
221855            "quantitativeAnalysis": {
221856              "graphics": {}
221857            },
221858            "considerations": {}
221859          }
221860        },
221861        {
221862          "type": "library",
221863          "bom-ref": "pkg:npm/json-bigint@1.0.0?package-id=316de12d7c18c3e0",
221864          "supplier": {},
221865          "name": "json-bigint",
221866          "version": "1.0.0",
221867          "licenses": [
221868            {
221869              "license": {
221870                "id": "MIT"
221871              }
221872            }
221873          ],
221874          "cpe": "cpe:2.3:a:json-bigint:json-bigint:1.0.0:*:*:*:*:*:*:*",
221875          "purl": "pkg:npm/json-bigint@1.0.0",
221876          "swid": {
221877            "attachment": {}
221878          },
221879          "pedigree": {},
221880          "evidence": {},
221881          "signature": {
221882            "signature": {
221883              "publicKey": {}
221884            }
221885          },
221886          "modelCard": {
221887            "modelParameters": {
221888              "approach": {}
221889            },
221890            "quantitativeAnalysis": {
221891              "graphics": {}
221892            },
221893            "considerations": {}
221894          }
221895        },
221896        {
221897          "type": "library",
221898          "bom-ref": "pkg:npm/json-cycle@1.3.0?package-id=47076b86e448a8a4",
221899          "supplier": {},
221900          "name": "json-cycle",
221901          "version": "1.3.0",
221902          "licenses": [
221903            {
221904              "license": {
221905                "id": "MIT"
221906              }
221907            }
221908          ],
221909          "cpe": "cpe:2.3:a:json-cycle:json-cycle:1.3.0:*:*:*:*:*:*:*",
221910          "purl": "pkg:npm/json-cycle@1.3.0",
221911          "swid": {
221912            "attachment": {}
221913          },
221914          "pedigree": {},
221915          "evidence": {},
221916          "signature": {
221917            "signature": {
221918              "publicKey": {}
221919            }
221920          },
221921          "modelCard": {
221922            "modelParameters": {
221923              "approach": {}
221924            },
221925            "quantitativeAnalysis": {
221926              "graphics": {}
221927            },
221928            "considerations": {}
221929          }
221930        },
221931        {
221932          "type": "library",
221933          "bom-ref": "pkg:npm/json-schema@0.2.3?package-id=e4cfa487fbbcfb8e",
221934          "supplier": {},
221935          "name": "json-schema",
221936          "version": "0.2.3",
221937          "licenses": [
221938            {
221939              "license": {
221940                "name": "AFLv2.1"
221941              }
221942            },
221943            {
221944              "license": {
221945                "name": "BSD"
221946              }
221947            }
221948          ],
221949          "cpe": "cpe:2.3:a:json-schema:json-schema:0.2.3:*:*:*:*:*:*:*",
221950          "purl": "pkg:npm/json-schema@0.2.3",
221951          "swid": {
221952            "attachment": {}
221953          },
221954          "pedigree": {},
221955          "evidence": {},
221956          "signature": {
221957            "signature": {
221958              "publicKey": {}
221959            }
221960          },
221961          "modelCard": {
221962            "modelParameters": {
221963              "approach": {}
221964            },
221965            "quantitativeAnalysis": {
221966              "graphics": {}
221967            },
221968            "considerations": {}
221969          }
221970        },
221971        {
221972          "type": "library",
221973          "bom-ref": "pkg:npm/json-schema-traverse@0.4.1?package-id=cbb857d85748c1e4",
221974          "supplier": {},
221975          "name": "json-schema-traverse",
221976          "version": "0.4.1",
221977          "licenses": [
221978            {
221979              "license": {
221980                "id": "MIT"
221981              }
221982            }
221983          ],
221984          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:0.4.1:*:*:*:*:*:*:*",
221985          "purl": "pkg:npm/json-schema-traverse@0.4.1",
221986          "swid": {
221987            "attachment": {}
221988          },
221989          "pedigree": {},
221990          "evidence": {},
221991          "signature": {
221992            "signature": {
221993              "publicKey": {}
221994            }
221995          },
221996          "modelCard": {
221997            "modelParameters": {
221998              "approach": {}
221999            },
222000            "quantitativeAnalysis": {
222001              "graphics": {}
222002            },
222003            "considerations": {}
222004          }
222005        },
222006        {
222007          "type": "library",
222008          "bom-ref": "pkg:npm/json-stringify-safe@5.0.1?package-id=2609f143751fda00",
222009          "supplier": {},
222010          "name": "json-stringify-safe",
222011          "version": "5.0.1",
222012          "licenses": [
222013            {
222014              "license": {
222015                "id": "ISC"
222016              }
222017            }
222018          ],
222019          "cpe": "cpe:2.3:a:json-stringify-safe:json-stringify-safe:5.0.1:*:*:*:*:*:*:*",
222020          "purl": "pkg:npm/json-stringify-safe@5.0.1",
222021          "swid": {
222022            "attachment": {}
222023          },
222024          "pedigree": {},
222025          "evidence": {},
222026          "signature": {
222027            "signature": {
222028              "publicKey": {}
222029            }
222030          },
222031          "modelCard": {
222032            "modelParameters": {
222033              "approach": {}
222034            },
222035            "quantitativeAnalysis": {
222036              "graphics": {}
222037            },
222038            "considerations": {}
222039          }
222040        },
222041        {
222042          "type": "library",
222043          "bom-ref": "pkg:npm/json-to-pretty-yaml@1.2.2?package-id=addb2f98a64e665d",
222044          "supplier": {},
222045          "name": "json-to-pretty-yaml",
222046          "version": "1.2.2",
222047          "licenses": [
222048            {
222049              "license": {
222050                "id": "Apache-2.0"
222051              }
222052            }
222053          ],
222054          "cpe": "cpe:2.3:a:json-to-pretty-yaml:json-to-pretty-yaml:1.2.2:*:*:*:*:*:*:*",
222055          "purl": "pkg:npm/json-to-pretty-yaml@1.2.2",
222056          "swid": {
222057            "attachment": {}
222058          },
222059          "pedigree": {},
222060          "evidence": {},
222061          "signature": {
222062            "signature": {
222063              "publicKey": {}
222064            }
222065          },
222066          "modelCard": {
222067            "modelParameters": {
222068              "approach": {}
222069            },
222070            "quantitativeAnalysis": {
222071              "graphics": {}
222072            },
222073            "considerations": {}
222074          }
222075        },
222076        {
222077          "type": "library",
222078          "bom-ref": "pkg:npm/jsonfile@6.1.0?package-id=5d5f4a3fabf683ed",
222079          "supplier": {},
222080          "name": "jsonfile",
222081          "version": "6.1.0",
222082          "licenses": [
222083            {
222084              "license": {
222085                "id": "MIT"
222086              }
222087            }
222088          ],
222089          "cpe": "cpe:2.3:a:jsonfile:jsonfile:6.1.0:*:*:*:*:*:*:*",
222090          "purl": "pkg:npm/jsonfile@6.1.0",
222091          "swid": {
222092            "attachment": {}
222093          },
222094          "pedigree": {},
222095          "evidence": {},
222096          "signature": {
222097            "signature": {
222098              "publicKey": {}
222099            }
222100          },
222101          "modelCard": {
222102            "modelParameters": {
222103              "approach": {}
222104            },
222105            "quantitativeAnalysis": {
222106              "graphics": {}
222107            },
222108            "considerations": {}
222109          }
222110        },
222111        {
222112          "type": "library",
222113          "bom-ref": "pkg:npm/jsonwebtoken@8.5.1?package-id=239172beb9f99257",
222114          "supplier": {},
222115          "name": "jsonwebtoken",
222116          "version": "8.5.1",
222117          "licenses": [
222118            {
222119              "license": {
222120                "id": "MIT"
222121              }
222122            }
222123          ],
222124          "cpe": "cpe:2.3:a:jsonwebtoken:jsonwebtoken:8.5.1:*:*:*:*:*:*:*",
222125          "purl": "pkg:npm/jsonwebtoken@8.5.1",
222126          "swid": {
222127            "attachment": {}
222128          },
222129          "pedigree": {},
222130          "evidence": {},
222131          "signature": {
222132            "signature": {
222133              "publicKey": {}
222134            }
222135          },
222136          "modelCard": {
222137            "modelParameters": {
222138              "approach": {}
222139            },
222140            "quantitativeAnalysis": {
222141              "graphics": {}
222142            },
222143            "considerations": {}
222144          }
222145        },
222146        {
222147          "type": "library",
222148          "bom-ref": "pkg:npm/jsprim@1.4.1?package-id=196b972bd5fc97eb",
222149          "supplier": {},
222150          "name": "jsprim",
222151          "version": "1.4.1",
222152          "licenses": [
222153            {
222154              "license": {
222155                "id": "MIT"
222156              }
222157            }
222158          ],
222159          "cpe": "cpe:2.3:a:jsprim:jsprim:1.4.1:*:*:*:*:*:*:*",
222160          "purl": "pkg:npm/jsprim@1.4.1",
222161          "swid": {
222162            "attachment": {}
222163          },
222164          "pedigree": {},
222165          "evidence": {},
222166          "signature": {
222167            "signature": {
222168              "publicKey": {}
222169            }
222170          },
222171          "modelCard": {
222172            "modelParameters": {
222173              "approach": {}
222174            },
222175            "quantitativeAnalysis": {
222176              "graphics": {}
222177            },
222178            "considerations": {}
222179          }
222180        },
222181        {
222182          "type": "library",
222183          "bom-ref": "pkg:npm/jszip@3.10.1?package-id=a09c134e88daa104",
222184          "supplier": {},
222185          "name": "jszip",
222186          "version": "3.10.1",
222187          "licenses": [
222188            {
222189              "license": {
222190                "name": "(MIT OR GPL-3.0-or-later)"
222191              }
222192            }
222193          ],
222194          "cpe": "cpe:2.3:a:jszip:jszip:3.10.1:*:*:*:*:*:*:*",
222195          "purl": "pkg:npm/jszip@3.10.1",
222196          "swid": {
222197            "attachment": {}
222198          },
222199          "pedigree": {},
222200          "evidence": {},
222201          "signature": {
222202            "signature": {
222203              "publicKey": {}
222204            }
222205          },
222206          "modelCard": {
222207            "modelParameters": {
222208              "approach": {}
222209            },
222210            "quantitativeAnalysis": {
222211              "graphics": {}
222212            },
222213            "considerations": {}
222214          }
222215        },
222216        {
222217          "type": "library",
222218          "bom-ref": "pkg:npm/jwa@2.0.0?package-id=f4fe935a19908bfd",
222219          "supplier": {},
222220          "name": "jwa",
222221          "version": "2.0.0",
222222          "licenses": [
222223            {
222224              "license": {
222225                "id": "MIT"
222226              }
222227            }
222228          ],
222229          "cpe": "cpe:2.3:a:jwa:jwa:2.0.0:*:*:*:*:*:*:*",
222230          "purl": "pkg:npm/jwa@2.0.0",
222231          "swid": {
222232            "attachment": {}
222233          },
222234          "pedigree": {},
222235          "evidence": {},
222236          "signature": {
222237            "signature": {
222238              "publicKey": {}
222239            }
222240          },
222241          "modelCard": {
222242            "modelParameters": {
222243              "approach": {}
222244            },
222245            "quantitativeAnalysis": {
222246              "graphics": {}
222247            },
222248            "considerations": {}
222249          }
222250        },
222251        {
222252          "type": "library",
222253          "bom-ref": "pkg:npm/jwks-rsa@2.1.5?package-id=5ae37b454e4725ca",
222254          "supplier": {},
222255          "name": "jwks-rsa",
222256          "version": "2.1.5",
222257          "licenses": [
222258            {
222259              "license": {
222260                "id": "MIT"
222261              }
222262            }
222263          ],
222264          "cpe": "cpe:2.3:a:jwks-rsa:jwks-rsa:2.1.5:*:*:*:*:*:*:*",
222265          "purl": "pkg:npm/jwks-rsa@2.1.5",
222266          "swid": {
222267            "attachment": {}
222268          },
222269          "pedigree": {},
222270          "evidence": {},
222271          "signature": {
222272            "signature": {
222273              "publicKey": {}
222274            }
222275          },
222276          "modelCard": {
222277            "modelParameters": {
222278              "approach": {}
222279            },
222280            "quantitativeAnalysis": {
222281              "graphics": {}
222282            },
222283            "considerations": {}
222284          }
222285        },
222286        {
222287          "type": "library",
222288          "bom-ref": "pkg:npm/jws@4.0.0?package-id=8d3629e6bf66d851",
222289          "supplier": {},
222290          "name": "jws",
222291          "version": "4.0.0",
222292          "licenses": [
222293            {
222294              "license": {
222295                "id": "MIT"
222296              }
222297            }
222298          ],
222299          "cpe": "cpe:2.3:a:jws:jws:4.0.0:*:*:*:*:*:*:*",
222300          "purl": "pkg:npm/jws@4.0.0",
222301          "swid": {
222302            "attachment": {}
222303          },
222304          "pedigree": {},
222305          "evidence": {},
222306          "signature": {
222307            "signature": {
222308              "publicKey": {}
222309            }
222310          },
222311          "modelCard": {
222312            "modelParameters": {
222313              "approach": {}
222314            },
222315            "quantitativeAnalysis": {
222316              "graphics": {}
222317            },
222318            "considerations": {}
222319          }
222320        },
222321        {
222322          "type": "library",
222323          "bom-ref": "pkg:npm/keypair@1.0.4?package-id=6bef9bc79912ca3c",
222324          "supplier": {},
222325          "name": "keypair",
222326          "version": "1.0.4",
222327          "licenses": [
222328            {
222329              "license": {
222330                "name": "BSD / GPL"
222331              }
222332            }
222333          ],
222334          "cpe": "cpe:2.3:a:keypair:keypair:1.0.4:*:*:*:*:*:*:*",
222335          "purl": "pkg:npm/keypair@1.0.4",
222336          "swid": {
222337            "attachment": {}
222338          },
222339          "pedigree": {},
222340          "evidence": {},
222341          "signature": {
222342            "signature": {
222343              "publicKey": {}
222344            }
222345          },
222346          "modelCard": {
222347            "modelParameters": {
222348              "approach": {}
222349            },
222350            "quantitativeAnalysis": {
222351              "graphics": {}
222352            },
222353            "considerations": {}
222354          }
222355        },
222356        {
222357          "type": "library",
222358          "bom-ref": "pkg:npm/keytar@7.9.0?package-id=77901beaec5aab3f",
222359          "supplier": {},
222360          "name": "keytar",
222361          "version": "7.9.0",
222362          "licenses": [
222363            {
222364              "license": {
222365                "id": "MIT"
222366              }
222367            }
222368          ],
222369          "cpe": "cpe:2.3:a:keytar:keytar:7.9.0:*:*:*:*:*:*:*",
222370          "purl": "pkg:npm/keytar@7.9.0",
222371          "swid": {
222372            "attachment": {}
222373          },
222374          "pedigree": {},
222375          "evidence": {},
222376          "signature": {
222377            "signature": {
222378              "publicKey": {}
222379            }
222380          },
222381          "modelCard": {
222382            "modelParameters": {
222383              "approach": {}
222384            },
222385            "quantitativeAnalysis": {
222386              "graphics": {}
222387            },
222388            "considerations": {}
222389          }
222390        },
222391        {
222392          "type": "library",
222393          "bom-ref": "pkg:npm/lazystream@1.0.1?package-id=512111df2c100d88",
222394          "supplier": {},
222395          "name": "lazystream",
222396          "version": "1.0.1",
222397          "licenses": [
222398            {
222399              "license": {
222400                "id": "MIT"
222401              }
222402            }
222403          ],
222404          "cpe": "cpe:2.3:a:lazystream:lazystream:1.0.1:*:*:*:*:*:*:*",
222405          "purl": "pkg:npm/lazystream@1.0.1",
222406          "swid": {
222407            "attachment": {}
222408          },
222409          "pedigree": {},
222410          "evidence": {},
222411          "signature": {
222412            "signature": {
222413              "publicKey": {}
222414            }
222415          },
222416          "modelCard": {
222417            "modelParameters": {
222418              "approach": {}
222419            },
222420            "quantitativeAnalysis": {
222421              "graphics": {}
222422            },
222423            "considerations": {}
222424          }
222425        },
222426        {
222427          "type": "library",
222428          "bom-ref": "pkg:npm/ldap-filter@0.3.3?package-id=a6b5e76554979e4a",
222429          "supplier": {},
222430          "name": "ldap-filter",
222431          "version": "0.3.3",
222432          "licenses": [
222433            {
222434              "license": {
222435                "id": "MIT"
222436              }
222437            }
222438          ],
222439          "cpe": "cpe:2.3:a:ldap-filter:ldap-filter:0.3.3:*:*:*:*:*:*:*",
222440          "purl": "pkg:npm/ldap-filter@0.3.3",
222441          "swid": {
222442            "attachment": {}
222443          },
222444          "pedigree": {},
222445          "evidence": {},
222446          "signature": {
222447            "signature": {
222448              "publicKey": {}
222449            }
222450          },
222451          "modelCard": {
222452            "modelParameters": {
222453              "approach": {}
222454            },
222455            "quantitativeAnalysis": {
222456              "graphics": {}
222457            },
222458            "considerations": {}
222459          }
222460        },
222461        {
222462          "type": "library",
222463          "bom-ref": "pkg:npm/ldapjs@2.3.3?package-id=186cb6e9d4994ec3",
222464          "supplier": {},
222465          "name": "ldapjs",
222466          "version": "2.3.3",
222467          "licenses": [
222468            {
222469              "license": {
222470                "id": "MIT"
222471              }
222472            }
222473          ],
222474          "cpe": "cpe:2.3:a:ldapjs:ldapjs:2.3.3:*:*:*:*:*:*:*",
222475          "purl": "pkg:npm/ldapjs@2.3.3",
222476          "swid": {
222477            "attachment": {}
222478          },
222479          "pedigree": {},
222480          "evidence": {},
222481          "signature": {
222482            "signature": {
222483              "publicKey": {}
222484            }
222485          },
222486          "modelCard": {
222487            "modelParameters": {
222488              "approach": {}
222489            },
222490            "quantitativeAnalysis": {
222491              "graphics": {}
222492            },
222493            "considerations": {}
222494          }
222495        },
222496        {
222497          "type": "library",
222498          "bom-ref": "pkg:npm/leven@2.1.0?package-id=3e4e6acddc385937",
222499          "supplier": {},
222500          "name": "leven",
222501          "version": "2.1.0",
222502          "licenses": [
222503            {
222504              "license": {
222505                "id": "MIT"
222506              }
222507            }
222508          ],
222509          "cpe": "cpe:2.3:a:leven:leven:2.1.0:*:*:*:*:*:*:*",
222510          "purl": "pkg:npm/leven@2.1.0",
222511          "swid": {
222512            "attachment": {}
222513          },
222514          "pedigree": {},
222515          "evidence": {},
222516          "signature": {
222517            "signature": {
222518              "publicKey": {}
222519            }
222520          },
222521          "modelCard": {
222522            "modelParameters": {
222523              "approach": {}
222524            },
222525            "quantitativeAnalysis": {
222526              "graphics": {}
222527            },
222528            "considerations": {}
222529          }
222530        },
222531        {
222532          "type": "library",
222533          "bom-ref": "pkg:npm/lie@3.3.0?package-id=c5fcf15e35110845",
222534          "supplier": {},
222535          "name": "lie",
222536          "version": "3.3.0",
222537          "licenses": [
222538            {
222539              "license": {
222540                "id": "MIT"
222541              }
222542            }
222543          ],
222544          "cpe": "cpe:2.3:a:lie:lie:3.3.0:*:*:*:*:*:*:*",
222545          "purl": "pkg:npm/lie@3.3.0",
222546          "swid": {
222547            "attachment": {}
222548          },
222549          "pedigree": {},
222550          "evidence": {},
222551          "signature": {
222552            "signature": {
222553              "publicKey": {}
222554            }
222555          },
222556          "modelCard": {
222557            "modelParameters": {
222558              "approach": {}
222559            },
222560            "quantitativeAnalysis": {
222561              "graphics": {}
222562            },
222563            "considerations": {}
222564          }
222565        },
222566        {
222567          "type": "library",
222568          "bom-ref": "pkg:npm/limiter@1.1.5?package-id=1a6cfa53ef5808c8",
222569          "supplier": {},
222570          "name": "limiter",
222571          "version": "1.1.5",
222572          "licenses": [
222573            {
222574              "license": {
222575                "id": "MIT"
222576              }
222577            }
222578          ],
222579          "cpe": "cpe:2.3:a:limiter:limiter:1.1.5:*:*:*:*:*:*:*",
222580          "purl": "pkg:npm/limiter@1.1.5",
222581          "swid": {
222582            "attachment": {}
222583          },
222584          "pedigree": {},
222585          "evidence": {},
222586          "signature": {
222587            "signature": {
222588              "publicKey": {}
222589            }
222590          },
222591          "modelCard": {
222592            "modelParameters": {
222593              "approach": {}
222594            },
222595            "quantitativeAnalysis": {
222596              "graphics": {}
222597            },
222598            "considerations": {}
222599          }
222600        },
222601        {
222602          "type": "library",
222603          "bom-ref": "pkg:npm/linked-queue@1.0.3?package-id=73d35dd58ea9f6a7",
222604          "supplier": {},
222605          "name": "linked-queue",
222606          "version": "1.0.3",
222607          "licenses": [
222608            {
222609              "license": {
222610                "id": "MIT"
222611              }
222612            }
222613          ],
222614          "cpe": "cpe:2.3:a:linked-queue:linked-queue:1.0.3:*:*:*:*:*:*:*",
222615          "purl": "pkg:npm/linked-queue@1.0.3",
222616          "swid": {
222617            "attachment": {}
222618          },
222619          "pedigree": {},
222620          "evidence": {},
222621          "signature": {
222622            "signature": {
222623              "publicKey": {}
222624            }
222625          },
222626          "modelCard": {
222627            "modelParameters": {
222628              "approach": {}
222629            },
222630            "quantitativeAnalysis": {
222631              "graphics": {}
222632            },
222633            "considerations": {}
222634          }
222635        },
222636        {
222637          "type": "library",
222638          "bom-ref": "pkg:npm/listenercount@1.0.1?package-id=2e936a5c015aafeb",
222639          "supplier": {},
222640          "name": "listenercount",
222641          "version": "1.0.1",
222642          "licenses": [
222643            {
222644              "license": {
222645                "id": "ISC"
222646              }
222647            }
222648          ],
222649          "cpe": "cpe:2.3:a:listenercount:listenercount:1.0.1:*:*:*:*:*:*:*",
222650          "purl": "pkg:npm/listenercount@1.0.1",
222651          "swid": {
222652            "attachment": {}
222653          },
222654          "pedigree": {},
222655          "evidence": {},
222656          "signature": {
222657            "signature": {
222658              "publicKey": {}
222659            }
222660          },
222661          "modelCard": {
222662            "modelParameters": {
222663              "approach": {}
222664            },
222665            "quantitativeAnalysis": {
222666              "graphics": {}
222667            },
222668            "considerations": {}
222669          }
222670        },
222671        {
222672          "type": "library",
222673          "bom-ref": "pkg:npm/lodash@4.17.21?package-id=7b2fcd3433197626",
222674          "supplier": {},
222675          "name": "lodash",
222676          "version": "4.17.21",
222677          "licenses": [
222678            {
222679              "license": {
222680                "id": "MIT"
222681              }
222682            }
222683          ],
222684          "cpe": "cpe:2.3:a:lodash:lodash:4.17.21:*:*:*:*:*:*:*",
222685          "purl": "pkg:npm/lodash@4.17.21",
222686          "swid": {
222687            "attachment": {}
222688          },
222689          "pedigree": {},
222690          "evidence": {},
222691          "signature": {
222692            "signature": {
222693              "publicKey": {}
222694            }
222695          },
222696          "modelCard": {
222697            "modelParameters": {
222698              "approach": {}
222699            },
222700            "quantitativeAnalysis": {
222701              "graphics": {}
222702            },
222703            "considerations": {}
222704          }
222705        },
222706        {
222707          "type": "library",
222708          "bom-ref": "pkg:npm/lodash.clonedeep@4.5.0?package-id=f763b6a52777c6a2",
222709          "supplier": {},
222710          "name": "lodash.clonedeep",
222711          "version": "4.5.0",
222712          "licenses": [
222713            {
222714              "license": {
222715                "id": "MIT"
222716              }
222717            }
222718          ],
222719          "cpe": "cpe:2.3:a:lodash.clonedeep:lodash.clonedeep:4.5.0:*:*:*:*:*:*:*",
222720          "purl": "pkg:npm/lodash.clonedeep@4.5.0",
222721          "swid": {
222722            "attachment": {}
222723          },
222724          "pedigree": {},
222725          "evidence": {},
222726          "signature": {
222727            "signature": {
222728              "publicKey": {}
222729            }
222730          },
222731          "modelCard": {
222732            "modelParameters": {
222733              "approach": {}
222734            },
222735            "quantitativeAnalysis": {
222736              "graphics": {}
222737            },
222738            "considerations": {}
222739          }
222740        },
222741        {
222742          "type": "library",
222743          "bom-ref": "pkg:npm/lodash.defaults@4.2.0?package-id=b9e19cde12279217",
222744          "supplier": {},
222745          "name": "lodash.defaults",
222746          "version": "4.2.0",
222747          "licenses": [
222748            {
222749              "license": {
222750                "id": "MIT"
222751              }
222752            }
222753          ],
222754          "cpe": "cpe:2.3:a:lodash.defaults:lodash.defaults:4.2.0:*:*:*:*:*:*:*",
222755          "purl": "pkg:npm/lodash.defaults@4.2.0",
222756          "swid": {
222757            "attachment": {}
222758          },
222759          "pedigree": {},
222760          "evidence": {},
222761          "signature": {
222762            "signature": {
222763              "publicKey": {}
222764            }
222765          },
222766          "modelCard": {
222767            "modelParameters": {
222768              "approach": {}
222769            },
222770            "quantitativeAnalysis": {
222771              "graphics": {}
222772            },
222773            "considerations": {}
222774          }
222775        },
222776        {
222777          "type": "library",
222778          "bom-ref": "pkg:npm/lodash.difference@4.5.0?package-id=1b83453e1f83ee57",
222779          "supplier": {},
222780          "name": "lodash.difference",
222781          "version": "4.5.0",
222782          "licenses": [
222783            {
222784              "license": {
222785                "id": "MIT"
222786              }
222787            }
222788          ],
222789          "cpe": "cpe:2.3:a:lodash.difference:lodash.difference:4.5.0:*:*:*:*:*:*:*",
222790          "purl": "pkg:npm/lodash.difference@4.5.0",
222791          "swid": {
222792            "attachment": {}
222793          },
222794          "pedigree": {},
222795          "evidence": {},
222796          "signature": {
222797            "signature": {
222798              "publicKey": {}
222799            }
222800          },
222801          "modelCard": {
222802            "modelParameters": {
222803              "approach": {}
222804            },
222805            "quantitativeAnalysis": {
222806              "graphics": {}
222807            },
222808            "considerations": {}
222809          }
222810        },
222811        {
222812          "type": "library",
222813          "bom-ref": "pkg:npm/lodash.escaperegexp@4.1.2?package-id=6f72a4ced382d171",
222814          "supplier": {},
222815          "name": "lodash.escaperegexp",
222816          "version": "4.1.2",
222817          "licenses": [
222818            {
222819              "license": {
222820                "id": "MIT"
222821              }
222822            }
222823          ],
222824          "cpe": "cpe:2.3:a:lodash.escaperegexp:lodash.escaperegexp:4.1.2:*:*:*:*:*:*:*",
222825          "purl": "pkg:npm/lodash.escaperegexp@4.1.2",
222826          "swid": {
222827            "attachment": {}
222828          },
222829          "pedigree": {},
222830          "evidence": {},
222831          "signature": {
222832            "signature": {
222833              "publicKey": {}
222834            }
222835          },
222836          "modelCard": {
222837            "modelParameters": {
222838              "approach": {}
222839            },
222840            "quantitativeAnalysis": {
222841              "graphics": {}
222842            },
222843            "considerations": {}
222844          }
222845        },
222846        {
222847          "type": "library",
222848          "bom-ref": "pkg:npm/lodash.flatten@4.4.0?package-id=14b40817f9764024",
222849          "supplier": {},
222850          "name": "lodash.flatten",
222851          "version": "4.4.0",
222852          "licenses": [
222853            {
222854              "license": {
222855                "id": "MIT"
222856              }
222857            }
222858          ],
222859          "cpe": "cpe:2.3:a:lodash.flatten:lodash.flatten:4.4.0:*:*:*:*:*:*:*",
222860          "purl": "pkg:npm/lodash.flatten@4.4.0",
222861          "swid": {
222862            "attachment": {}
222863          },
222864          "pedigree": {},
222865          "evidence": {},
222866          "signature": {
222867            "signature": {
222868              "publicKey": {}
222869            }
222870          },
222871          "modelCard": {
222872            "modelParameters": {
222873              "approach": {}
222874            },
222875            "quantitativeAnalysis": {
222876              "graphics": {}
222877            },
222878            "considerations": {}
222879          }
222880        },
222881        {
222882          "type": "library",
222883          "bom-ref": "pkg:npm/lodash.groupby@4.6.0?package-id=ca12556cff2112d1",
222884          "supplier": {},
222885          "name": "lodash.groupby",
222886          "version": "4.6.0",
222887          "licenses": [
222888            {
222889              "license": {
222890                "id": "MIT"
222891              }
222892            }
222893          ],
222894          "cpe": "cpe:2.3:a:lodash.groupby:lodash.groupby:4.6.0:*:*:*:*:*:*:*",
222895          "purl": "pkg:npm/lodash.groupby@4.6.0",
222896          "swid": {
222897            "attachment": {}
222898          },
222899          "pedigree": {},
222900          "evidence": {},
222901          "signature": {
222902            "signature": {
222903              "publicKey": {}
222904            }
222905          },
222906          "modelCard": {
222907            "modelParameters": {
222908              "approach": {}
222909            },
222910            "quantitativeAnalysis": {
222911              "graphics": {}
222912            },
222913            "considerations": {}
222914          }
222915        },
222916        {
222917          "type": "library",
222918          "bom-ref": "pkg:npm/lodash.includes@4.3.0?package-id=e585efeceee900f",
222919          "supplier": {},
222920          "name": "lodash.includes",
222921          "version": "4.3.0",
222922          "licenses": [
222923            {
222924              "license": {
222925                "id": "MIT"
222926              }
222927            }
222928          ],
222929          "cpe": "cpe:2.3:a:lodash.includes:lodash.includes:4.3.0:*:*:*:*:*:*:*",
222930          "purl": "pkg:npm/lodash.includes@4.3.0",
222931          "swid": {
222932            "attachment": {}
222933          },
222934          "pedigree": {},
222935          "evidence": {},
222936          "signature": {
222937            "signature": {
222938              "publicKey": {}
222939            }
222940          },
222941          "modelCard": {
222942            "modelParameters": {
222943              "approach": {}
222944            },
222945            "quantitativeAnalysis": {
222946              "graphics": {}
222947            },
222948            "considerations": {}
222949          }
222950        },
222951        {
222952          "type": "library",
222953          "bom-ref": "pkg:npm/lodash.isboolean@3.0.3?package-id=8335ba9468ec80f0",
222954          "supplier": {},
222955          "name": "lodash.isboolean",
222956          "version": "3.0.3",
222957          "licenses": [
222958            {
222959              "license": {
222960                "id": "MIT"
222961              }
222962            }
222963          ],
222964          "cpe": "cpe:2.3:a:lodash.isboolean:lodash.isboolean:3.0.3:*:*:*:*:*:*:*",
222965          "purl": "pkg:npm/lodash.isboolean@3.0.3",
222966          "swid": {
222967            "attachment": {}
222968          },
222969          "pedigree": {},
222970          "evidence": {},
222971          "signature": {
222972            "signature": {
222973              "publicKey": {}
222974            }
222975          },
222976          "modelCard": {
222977            "modelParameters": {
222978              "approach": {}
222979            },
222980            "quantitativeAnalysis": {
222981              "graphics": {}
222982            },
222983            "considerations": {}
222984          }
222985        },
222986        {
222987          "type": "library",
222988          "bom-ref": "pkg:npm/lodash.isequal@4.5.0?package-id=5251c4f818e928b1",
222989          "supplier": {},
222990          "name": "lodash.isequal",
222991          "version": "4.5.0",
222992          "licenses": [
222993            {
222994              "license": {
222995                "id": "MIT"
222996              }
222997            }
222998          ],
222999          "cpe": "cpe:2.3:a:lodash.isequal:lodash.isequal:4.5.0:*:*:*:*:*:*:*",
223000          "purl": "pkg:npm/lodash.isequal@4.5.0",
223001          "swid": {
223002            "attachment": {}
223003          },
223004          "pedigree": {},
223005          "evidence": {},
223006          "signature": {
223007            "signature": {
223008              "publicKey": {}
223009            }
223010          },
223011          "modelCard": {
223012            "modelParameters": {
223013              "approach": {}
223014            },
223015            "quantitativeAnalysis": {
223016              "graphics": {}
223017            },
223018            "considerations": {}
223019          }
223020        },
223021        {
223022          "type": "library",
223023          "bom-ref": "pkg:npm/lodash.isfunction@3.0.9?package-id=9c3a10266c70acb7",
223024          "supplier": {},
223025          "name": "lodash.isfunction",
223026          "version": "3.0.9",
223027          "licenses": [
223028            {
223029              "license": {
223030                "id": "MIT"
223031              }
223032            }
223033          ],
223034          "cpe": "cpe:2.3:a:lodash.isfunction:lodash.isfunction:3.0.9:*:*:*:*:*:*:*",
223035          "purl": "pkg:npm/lodash.isfunction@3.0.9",
223036          "swid": {
223037            "attachment": {}
223038          },
223039          "pedigree": {},
223040          "evidence": {},
223041          "signature": {
223042            "signature": {
223043              "publicKey": {}
223044            }
223045          },
223046          "modelCard": {
223047            "modelParameters": {
223048              "approach": {}
223049            },
223050            "quantitativeAnalysis": {
223051              "graphics": {}
223052            },
223053            "considerations": {}
223054          }
223055        },
223056        {
223057          "type": "library",
223058          "bom-ref": "pkg:npm/lodash.isinteger@4.0.4?package-id=bafca3985b5fdec1",
223059          "supplier": {},
223060          "name": "lodash.isinteger",
223061          "version": "4.0.4",
223062          "licenses": [
223063            {
223064              "license": {
223065                "id": "MIT"
223066              }
223067            }
223068          ],
223069          "cpe": "cpe:2.3:a:lodash.isinteger:lodash.isinteger:4.0.4:*:*:*:*:*:*:*",
223070          "purl": "pkg:npm/lodash.isinteger@4.0.4",
223071          "swid": {
223072            "attachment": {}
223073          },
223074          "pedigree": {},
223075          "evidence": {},
223076          "signature": {
223077            "signature": {
223078              "publicKey": {}
223079            }
223080          },
223081          "modelCard": {
223082            "modelParameters": {
223083              "approach": {}
223084            },
223085            "quantitativeAnalysis": {
223086              "graphics": {}
223087            },
223088            "considerations": {}
223089          }
223090        },
223091        {
223092          "type": "library",
223093          "bom-ref": "pkg:npm/lodash.isnil@4.0.0?package-id=431f88c7bfa63e04",
223094          "supplier": {},
223095          "name": "lodash.isnil",
223096          "version": "4.0.0",
223097          "licenses": [
223098            {
223099              "license": {
223100                "id": "MIT"
223101              }
223102            }
223103          ],
223104          "cpe": "cpe:2.3:a:lodash.isnil:lodash.isnil:4.0.0:*:*:*:*:*:*:*",
223105          "purl": "pkg:npm/lodash.isnil@4.0.0",
223106          "swid": {
223107            "attachment": {}
223108          },
223109          "pedigree": {},
223110          "evidence": {},
223111          "signature": {
223112            "signature": {
223113              "publicKey": {}
223114            }
223115          },
223116          "modelCard": {
223117            "modelParameters": {
223118              "approach": {}
223119            },
223120            "quantitativeAnalysis": {
223121              "graphics": {}
223122            },
223123            "considerations": {}
223124          }
223125        },
223126        {
223127          "type": "library",
223128          "bom-ref": "pkg:npm/lodash.isnumber@3.0.3?package-id=94c51348ad85344",
223129          "supplier": {},
223130          "name": "lodash.isnumber",
223131          "version": "3.0.3",
223132          "licenses": [
223133            {
223134              "license": {
223135                "id": "MIT"
223136              }
223137            }
223138          ],
223139          "cpe": "cpe:2.3:a:lodash.isnumber:lodash.isnumber:3.0.3:*:*:*:*:*:*:*",
223140          "purl": "pkg:npm/lodash.isnumber@3.0.3",
223141          "swid": {
223142            "attachment": {}
223143          },
223144          "pedigree": {},
223145          "evidence": {},
223146          "signature": {
223147            "signature": {
223148              "publicKey": {}
223149            }
223150          },
223151          "modelCard": {
223152            "modelParameters": {
223153              "approach": {}
223154            },
223155            "quantitativeAnalysis": {
223156              "graphics": {}
223157            },
223158            "considerations": {}
223159          }
223160        },
223161        {
223162          "type": "library",
223163          "bom-ref": "pkg:npm/lodash.isplainobject@4.0.6?package-id=7d6f7dea0776bfc",
223164          "supplier": {},
223165          "name": "lodash.isplainobject",
223166          "version": "4.0.6",
223167          "licenses": [
223168            {
223169              "license": {
223170                "id": "MIT"
223171              }
223172            }
223173          ],
223174          "cpe": "cpe:2.3:a:lodash.isplainobject:lodash.isplainobject:4.0.6:*:*:*:*:*:*:*",
223175          "purl": "pkg:npm/lodash.isplainobject@4.0.6",
223176          "swid": {
223177            "attachment": {}
223178          },
223179          "pedigree": {},
223180          "evidence": {},
223181          "signature": {
223182            "signature": {
223183              "publicKey": {}
223184            }
223185          },
223186          "modelCard": {
223187            "modelParameters": {
223188              "approach": {}
223189            },
223190            "quantitativeAnalysis": {
223191              "graphics": {}
223192            },
223193            "considerations": {}
223194          }
223195        },
223196        {
223197          "type": "library",
223198          "bom-ref": "pkg:npm/lodash.isstring@4.0.1?package-id=edda530a6a6d1b0d",
223199          "supplier": {},
223200          "name": "lodash.isstring",
223201          "version": "4.0.1",
223202          "licenses": [
223203            {
223204              "license": {
223205                "id": "MIT"
223206              }
223207            }
223208          ],
223209          "cpe": "cpe:2.3:a:lodash.isstring:lodash.isstring:4.0.1:*:*:*:*:*:*:*",
223210          "purl": "pkg:npm/lodash.isstring@4.0.1",
223211          "swid": {
223212            "attachment": {}
223213          },
223214          "pedigree": {},
223215          "evidence": {},
223216          "signature": {
223217            "signature": {
223218              "publicKey": {}
223219            }
223220          },
223221          "modelCard": {
223222            "modelParameters": {
223223              "approach": {}
223224            },
223225            "quantitativeAnalysis": {
223226              "graphics": {}
223227            },
223228            "considerations": {}
223229          }
223230        },
223231        {
223232          "type": "library",
223233          "bom-ref": "pkg:npm/lodash.isundefined@3.0.1?package-id=906abdda987ba4ec",
223234          "supplier": {},
223235          "name": "lodash.isundefined",
223236          "version": "3.0.1",
223237          "licenses": [
223238            {
223239              "license": {
223240                "id": "MIT"
223241              }
223242            }
223243          ],
223244          "cpe": "cpe:2.3:a:lodash.isundefined:lodash.isundefined:3.0.1:*:*:*:*:*:*:*",
223245          "purl": "pkg:npm/lodash.isundefined@3.0.1",
223246          "swid": {
223247            "attachment": {}
223248          },
223249          "pedigree": {},
223250          "evidence": {},
223251          "signature": {
223252            "signature": {
223253              "publicKey": {}
223254            }
223255          },
223256          "modelCard": {
223257            "modelParameters": {
223258              "approach": {}
223259            },
223260            "quantitativeAnalysis": {
223261              "graphics": {}
223262            },
223263            "considerations": {}
223264          }
223265        },
223266        {
223267          "type": "library",
223268          "bom-ref": "pkg:npm/lodash.once@4.1.1?package-id=1f367f2e40133d59",
223269          "supplier": {},
223270          "name": "lodash.once",
223271          "version": "4.1.1",
223272          "licenses": [
223273            {
223274              "license": {
223275                "id": "MIT"
223276              }
223277            }
223278          ],
223279          "cpe": "cpe:2.3:a:lodash.once:lodash.once:4.1.1:*:*:*:*:*:*:*",
223280          "purl": "pkg:npm/lodash.once@4.1.1",
223281          "swid": {
223282            "attachment": {}
223283          },
223284          "pedigree": {},
223285          "evidence": {},
223286          "signature": {
223287            "signature": {
223288              "publicKey": {}
223289            }
223290          },
223291          "modelCard": {
223292            "modelParameters": {
223293              "approach": {}
223294            },
223295            "quantitativeAnalysis": {
223296              "graphics": {}
223297            },
223298            "considerations": {}
223299          }
223300        },
223301        {
223302          "type": "library",
223303          "bom-ref": "pkg:npm/lodash.union@4.6.0?package-id=c586216ff13bb1a4",
223304          "supplier": {},
223305          "name": "lodash.union",
223306          "version": "4.6.0",
223307          "licenses": [
223308            {
223309              "license": {
223310                "id": "MIT"
223311              }
223312            }
223313          ],
223314          "cpe": "cpe:2.3:a:lodash.union:lodash.union:4.6.0:*:*:*:*:*:*:*",
223315          "purl": "pkg:npm/lodash.union@4.6.0",
223316          "swid": {
223317            "attachment": {}
223318          },
223319          "pedigree": {},
223320          "evidence": {},
223321          "signature": {
223322            "signature": {
223323              "publicKey": {}
223324            }
223325          },
223326          "modelCard": {
223327            "modelParameters": {
223328              "approach": {}
223329            },
223330            "quantitativeAnalysis": {
223331              "graphics": {}
223332            },
223333            "considerations": {}
223334          }
223335        },
223336        {
223337          "type": "library",
223338          "bom-ref": "pkg:npm/lodash.uniq@4.5.0?package-id=68eaf8085c8e0a06",
223339          "supplier": {},
223340          "name": "lodash.uniq",
223341          "version": "4.5.0",
223342          "licenses": [
223343            {
223344              "license": {
223345                "id": "MIT"
223346              }
223347            }
223348          ],
223349          "cpe": "cpe:2.3:a:lodash.uniq:lodash.uniq:4.5.0:*:*:*:*:*:*:*",
223350          "purl": "pkg:npm/lodash.uniq@4.5.0",
223351          "swid": {
223352            "attachment": {}
223353          },
223354          "pedigree": {},
223355          "evidence": {},
223356          "signature": {
223357            "signature": {
223358              "publicKey": {}
223359            }
223360          },
223361          "modelCard": {
223362            "modelParameters": {
223363              "approach": {}
223364            },
223365            "quantitativeAnalysis": {
223366              "graphics": {}
223367            },
223368            "considerations": {}
223369          }
223370        },
223371        {
223372          "type": "library",
223373          "bom-ref": "pkg:npm/long@4.0.0?package-id=7d0bb950e353c5d9",
223374          "supplier": {},
223375          "name": "long",
223376          "version": "4.0.0",
223377          "licenses": [
223378            {
223379              "license": {
223380                "id": "Apache-2.0"
223381              }
223382            }
223383          ],
223384          "cpe": "cpe:2.3:a:long:long:4.0.0:*:*:*:*:*:*:*",
223385          "purl": "pkg:npm/long@4.0.0",
223386          "swid": {
223387            "attachment": {}
223388          },
223389          "pedigree": {},
223390          "evidence": {},
223391          "signature": {
223392            "signature": {
223393              "publicKey": {}
223394            }
223395          },
223396          "modelCard": {
223397            "modelParameters": {
223398              "approach": {}
223399            },
223400            "quantitativeAnalysis": {
223401              "graphics": {}
223402            },
223403            "considerations": {}
223404          }
223405        },
223406        {
223407          "type": "library",
223408          "bom-ref": "pkg:npm/lowercase-keys@1.0.1?package-id=af1169441f2c0bdb",
223409          "supplier": {},
223410          "name": "lowercase-keys",
223411          "version": "1.0.1",
223412          "licenses": [
223413            {
223414              "license": {
223415                "id": "MIT"
223416              }
223417            }
223418          ],
223419          "cpe": "cpe:2.3:a:lowercase-keys:lowercase-keys:1.0.1:*:*:*:*:*:*:*",
223420          "purl": "pkg:npm/lowercase-keys@1.0.1",
223421          "swid": {
223422            "attachment": {}
223423          },
223424          "pedigree": {},
223425          "evidence": {},
223426          "signature": {
223427            "signature": {
223428              "publicKey": {}
223429            }
223430          },
223431          "modelCard": {
223432            "modelParameters": {
223433              "approach": {}
223434            },
223435            "quantitativeAnalysis": {
223436              "graphics": {}
223437            },
223438            "considerations": {}
223439          }
223440        },
223441        {
223442          "type": "library",
223443          "bom-ref": "pkg:npm/lru-cache@6.0.0?package-id=8c02d6ee9bbcd9da",
223444          "supplier": {},
223445          "name": "lru-cache",
223446          "version": "6.0.0",
223447          "licenses": [
223448            {
223449              "license": {
223450                "id": "ISC"
223451              }
223452            }
223453          ],
223454          "cpe": "cpe:2.3:a:lru-cache:lru-cache:6.0.0:*:*:*:*:*:*:*",
223455          "purl": "pkg:npm/lru-cache@6.0.0",
223456          "swid": {
223457            "attachment": {}
223458          },
223459          "pedigree": {},
223460          "evidence": {},
223461          "signature": {
223462            "signature": {
223463              "publicKey": {}
223464            }
223465          },
223466          "modelCard": {
223467            "modelParameters": {
223468              "approach": {}
223469            },
223470            "quantitativeAnalysis": {
223471              "graphics": {}
223472            },
223473            "considerations": {}
223474          }
223475        },
223476        {
223477          "type": "library",
223478          "bom-ref": "pkg:npm/lru-memoizer@2.2.0?package-id=5e77fb8f02f52e85",
223479          "supplier": {},
223480          "name": "lru-memoizer",
223481          "version": "2.2.0",
223482          "licenses": [
223483            {
223484              "license": {
223485                "id": "MIT"
223486              }
223487            }
223488          ],
223489          "cpe": "cpe:2.3:a:lru-memoizer:lru-memoizer:2.2.0:*:*:*:*:*:*:*",
223490          "purl": "pkg:npm/lru-memoizer@2.2.0",
223491          "swid": {
223492            "attachment": {}
223493          },
223494          "pedigree": {},
223495          "evidence": {},
223496          "signature": {
223497            "signature": {
223498              "publicKey": {}
223499            }
223500          },
223501          "modelCard": {
223502            "modelParameters": {
223503              "approach": {}
223504            },
223505            "quantitativeAnalysis": {
223506              "graphics": {}
223507            },
223508            "considerations": {}
223509          }
223510        },
223511        {
223512          "type": "library",
223513          "bom-ref": "pkg:npm/ltrim@1.0.1?package-id=6961f2176cd9da4",
223514          "supplier": {},
223515          "name": "ltrim",
223516          "version": "1.0.1",
223517          "licenses": [
223518            {
223519              "license": {
223520                "id": "MIT"
223521              }
223522            }
223523          ],
223524          "cpe": "cpe:2.3:a:ltrim:ltrim:1.0.1:*:*:*:*:*:*:*",
223525          "purl": "pkg:npm/ltrim@1.0.1",
223526          "swid": {
223527            "attachment": {}
223528          },
223529          "pedigree": {},
223530          "evidence": {},
223531          "signature": {
223532            "signature": {
223533              "publicKey": {}
223534            }
223535          },
223536          "modelCard": {
223537            "modelParameters": {
223538              "approach": {}
223539            },
223540            "quantitativeAnalysis": {
223541              "graphics": {}
223542            },
223543            "considerations": {}
223544          }
223545        },
223546        {
223547          "type": "library",
223548          "bom-ref": "pkg:npm/make-dir@1.3.0?package-id=e00431ed58e34879",
223549          "supplier": {},
223550          "name": "make-dir",
223551          "version": "1.3.0",
223552          "licenses": [
223553            {
223554              "license": {
223555                "id": "MIT"
223556              }
223557            }
223558          ],
223559          "cpe": "cpe:2.3:a:make-dir:make-dir:1.3.0:*:*:*:*:*:*:*",
223560          "purl": "pkg:npm/make-dir@1.3.0",
223561          "swid": {
223562            "attachment": {}
223563          },
223564          "pedigree": {},
223565          "evidence": {},
223566          "signature": {
223567            "signature": {
223568              "publicKey": {}
223569            }
223570          },
223571          "modelCard": {
223572            "modelParameters": {
223573              "approach": {}
223574            },
223575            "quantitativeAnalysis": {
223576              "graphics": {}
223577            },
223578            "considerations": {}
223579          }
223580        },
223581        {
223582          "type": "library",
223583          "bom-ref": "pkg:npm/md5@2.3.0?package-id=143470e05ab22daf",
223584          "supplier": {},
223585          "name": "md5",
223586          "version": "2.3.0",
223587          "licenses": [
223588            {
223589              "license": {
223590                "id": "BSD-3-Clause"
223591              }
223592            }
223593          ],
223594          "cpe": "cpe:2.3:a:md5:md5:2.3.0:*:*:*:*:*:*:*",
223595          "purl": "pkg:npm/md5@2.3.0",
223596          "swid": {
223597            "attachment": {}
223598          },
223599          "pedigree": {},
223600          "evidence": {},
223601          "signature": {
223602            "signature": {
223603              "publicKey": {}
223604            }
223605          },
223606          "modelCard": {
223607            "modelParameters": {
223608              "approach": {}
223609            },
223610            "quantitativeAnalysis": {
223611              "graphics": {}
223612            },
223613            "considerations": {}
223614          }
223615        },
223616        {
223617          "type": "library",
223618          "bom-ref": "pkg:npm/memory-pager@1.5.0?package-id=9cde7eea9b9531e8",
223619          "supplier": {},
223620          "name": "memory-pager",
223621          "version": "1.5.0",
223622          "licenses": [
223623            {
223624              "license": {
223625                "id": "MIT"
223626              }
223627            }
223628          ],
223629          "cpe": "cpe:2.3:a:memory-pager:memory-pager:1.5.0:*:*:*:*:*:*:*",
223630          "purl": "pkg:npm/memory-pager@1.5.0",
223631          "swid": {
223632            "attachment": {}
223633          },
223634          "pedigree": {},
223635          "evidence": {},
223636          "signature": {
223637            "signature": {
223638              "publicKey": {}
223639            }
223640          },
223641          "modelCard": {
223642            "modelParameters": {
223643              "approach": {}
223644            },
223645            "quantitativeAnalysis": {
223646              "graphics": {}
223647            },
223648            "considerations": {}
223649          }
223650        },
223651        {
223652          "type": "library",
223653          "bom-ref": "pkg:npm/mime@3.0.0?package-id=f8dfe8bc2bf8333c",
223654          "supplier": {},
223655          "name": "mime",
223656          "version": "3.0.0",
223657          "licenses": [
223658            {
223659              "license": {
223660                "id": "MIT"
223661              }
223662            }
223663          ],
223664          "cpe": "cpe:2.3:a:mime:mime:3.0.0:*:*:*:*:*:*:*",
223665          "purl": "pkg:npm/mime@3.0.0",
223666          "swid": {
223667            "attachment": {}
223668          },
223669          "pedigree": {},
223670          "evidence": {},
223671          "signature": {
223672            "signature": {
223673              "publicKey": {}
223674            }
223675          },
223676          "modelCard": {
223677            "modelParameters": {
223678              "approach": {}
223679            },
223680            "quantitativeAnalysis": {
223681              "graphics": {}
223682            },
223683            "considerations": {}
223684          }
223685        },
223686        {
223687          "type": "library",
223688          "bom-ref": "pkg:npm/mime-db@1.38.0?package-id=9c29c8dc2d02516c",
223689          "supplier": {},
223690          "name": "mime-db",
223691          "version": "1.38.0",
223692          "licenses": [
223693            {
223694              "license": {
223695                "id": "MIT"
223696              }
223697            }
223698          ],
223699          "cpe": "cpe:2.3:a:mime-db:mime-db:1.38.0:*:*:*:*:*:*:*",
223700          "purl": "pkg:npm/mime-db@1.38.0",
223701          "swid": {
223702            "attachment": {}
223703          },
223704          "pedigree": {},
223705          "evidence": {},
223706          "signature": {
223707            "signature": {
223708              "publicKey": {}
223709            }
223710          },
223711          "modelCard": {
223712            "modelParameters": {
223713              "approach": {}
223714            },
223715            "quantitativeAnalysis": {
223716              "graphics": {}
223717            },
223718            "considerations": {}
223719          }
223720        },
223721        {
223722          "type": "library",
223723          "bom-ref": "pkg:npm/mime-types@2.1.22?package-id=2b08e02a08672413",
223724          "supplier": {},
223725          "name": "mime-types",
223726          "version": "2.1.22",
223727          "licenses": [
223728            {
223729              "license": {
223730                "id": "MIT"
223731              }
223732            }
223733          ],
223734          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.22:*:*:*:*:*:*:*",
223735          "purl": "pkg:npm/mime-types@2.1.22",
223736          "swid": {
223737            "attachment": {}
223738          },
223739          "pedigree": {},
223740          "evidence": {},
223741          "signature": {
223742            "signature": {
223743              "publicKey": {}
223744            }
223745          },
223746          "modelCard": {
223747            "modelParameters": {
223748              "approach": {}
223749            },
223750            "quantitativeAnalysis": {
223751              "graphics": {}
223752            },
223753            "considerations": {}
223754          }
223755        },
223756        {
223757          "type": "library",
223758          "bom-ref": "pkg:npm/mimic-response@3.1.0?package-id=3e8f0e728acab9b8",
223759          "supplier": {},
223760          "name": "mimic-response",
223761          "version": "3.1.0",
223762          "licenses": [
223763            {
223764              "license": {
223765                "id": "MIT"
223766              }
223767            }
223768          ],
223769          "cpe": "cpe:2.3:a:mimic-response:mimic-response:3.1.0:*:*:*:*:*:*:*",
223770          "purl": "pkg:npm/mimic-response@3.1.0",
223771          "swid": {
223772            "attachment": {}
223773          },
223774          "pedigree": {},
223775          "evidence": {},
223776          "signature": {
223777            "signature": {
223778              "publicKey": {}
223779            }
223780          },
223781          "modelCard": {
223782            "modelParameters": {
223783              "approach": {}
223784            },
223785            "quantitativeAnalysis": {
223786              "graphics": {}
223787            },
223788            "considerations": {}
223789          }
223790        },
223791        {
223792          "type": "library",
223793          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=9c5f83fd6498349d",
223794          "supplier": {},
223795          "name": "minimatch",
223796          "version": "3.1.2",
223797          "licenses": [
223798            {
223799              "license": {
223800                "id": "ISC"
223801              }
223802            }
223803          ],
223804          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
223805          "purl": "pkg:npm/minimatch@3.1.2",
223806          "swid": {
223807            "attachment": {}
223808          },
223809          "pedigree": {},
223810          "evidence": {},
223811          "signature": {
223812            "signature": {
223813              "publicKey": {}
223814            }
223815          },
223816          "modelCard": {
223817            "modelParameters": {
223818              "approach": {}
223819            },
223820            "quantitativeAnalysis": {
223821              "graphics": {}
223822            },
223823            "considerations": {}
223824          }
223825        },
223826        {
223827          "type": "library",
223828          "bom-ref": "pkg:npm/minimist@1.2.8?package-id=872011e67dd733e4",
223829          "supplier": {},
223830          "name": "minimist",
223831          "version": "1.2.8",
223832          "licenses": [
223833            {
223834              "license": {
223835                "id": "MIT"
223836              }
223837            }
223838          ],
223839          "cpe": "cpe:2.3:a:minimist:minimist:1.2.8:*:*:*:*:*:*:*",
223840          "purl": "pkg:npm/minimist@1.2.8",
223841          "swid": {
223842            "attachment": {}
223843          },
223844          "pedigree": {},
223845          "evidence": {},
223846          "signature": {
223847            "signature": {
223848              "publicKey": {}
223849            }
223850          },
223851          "modelCard": {
223852            "modelParameters": {
223853              "approach": {}
223854            },
223855            "quantitativeAnalysis": {
223856              "graphics": {}
223857            },
223858            "considerations": {}
223859          }
223860        },
223861        {
223862          "type": "library",
223863          "bom-ref": "pkg:npm/mkdirp@0.5.6?package-id=e5d9aa06e4dc9993",
223864          "supplier": {},
223865          "name": "mkdirp",
223866          "version": "0.5.6",
223867          "licenses": [
223868            {
223869              "license": {
223870                "id": "MIT"
223871              }
223872            }
223873          ],
223874          "cpe": "cpe:2.3:a:mkdirp:mkdirp:0.5.6:*:*:*:*:*:*:*",
223875          "purl": "pkg:npm/mkdirp@0.5.6",
223876          "swid": {
223877            "attachment": {}
223878          },
223879          "pedigree": {},
223880          "evidence": {},
223881          "signature": {
223882            "signature": {
223883              "publicKey": {}
223884            }
223885          },
223886          "modelCard": {
223887            "modelParameters": {
223888              "approach": {}
223889            },
223890            "quantitativeAnalysis": {
223891              "graphics": {}
223892            },
223893            "considerations": {}
223894          }
223895        },
223896        {
223897          "type": "library",
223898          "bom-ref": "pkg:npm/mkdirp-classic@0.5.3?package-id=9209863aa2d1321a",
223899          "supplier": {},
223900          "name": "mkdirp-classic",
223901          "version": "0.5.3",
223902          "licenses": [
223903            {
223904              "license": {
223905                "id": "MIT"
223906              }
223907            }
223908          ],
223909          "cpe": "cpe:2.3:a:mkdirp-classic:mkdirp-classic:0.5.3:*:*:*:*:*:*:*",
223910          "purl": "pkg:npm/mkdirp-classic@0.5.3",
223911          "swid": {
223912            "attachment": {}
223913          },
223914          "pedigree": {},
223915          "evidence": {},
223916          "signature": {
223917            "signature": {
223918              "publicKey": {}
223919            }
223920          },
223921          "modelCard": {
223922            "modelParameters": {
223923              "approach": {}
223924            },
223925            "quantitativeAnalysis": {
223926              "graphics": {}
223927            },
223928            "considerations": {}
223929          }
223930        },
223931        {
223932          "type": "library",
223933          "bom-ref": "pkg:npm/module-alias@2.2.1?package-id=58aa72890d941581",
223934          "supplier": {},
223935          "name": "module-alias",
223936          "version": "2.2.1",
223937          "licenses": [
223938            {
223939              "license": {
223940                "id": "MIT"
223941              }
223942            }
223943          ],
223944          "cpe": "cpe:2.3:a:module-alias:module-alias:2.2.1:*:*:*:*:*:*:*",
223945          "purl": "pkg:npm/module-alias@2.2.1",
223946          "swid": {
223947            "attachment": {}
223948          },
223949          "pedigree": {},
223950          "evidence": {},
223951          "signature": {
223952            "signature": {
223953              "publicKey": {}
223954            }
223955          },
223956          "modelCard": {
223957            "modelParameters": {
223958              "approach": {}
223959            },
223960            "quantitativeAnalysis": {
223961              "graphics": {}
223962            },
223963            "considerations": {}
223964          }
223965        },
223966        {
223967          "type": "library",
223968          "bom-ref": "pkg:npm/moment@2.29.4?package-id=b2d2faac48e64687",
223969          "supplier": {},
223970          "name": "moment",
223971          "version": "2.29.4",
223972          "licenses": [
223973            {
223974              "license": {
223975                "id": "MIT"
223976              }
223977            }
223978          ],
223979          "cpe": "cpe:2.3:a:moment:moment:2.29.4:*:*:*:*:*:*:*",
223980          "purl": "pkg:npm/moment@2.29.4",
223981          "swid": {
223982            "attachment": {}
223983          },
223984          "pedigree": {},
223985          "evidence": {},
223986          "signature": {
223987            "signature": {
223988              "publicKey": {}
223989            }
223990          },
223991          "modelCard": {
223992            "modelParameters": {
223993              "approach": {}
223994            },
223995            "quantitativeAnalysis": {
223996              "graphics": {}
223997            },
223998            "considerations": {}
223999          }
224000        },
224001        {
224002          "type": "library",
224003          "bom-ref": "pkg:npm/mongodb@3.5.11?package-id=5c965149b57fc4c4",
224004          "supplier": {},
224005          "name": "mongodb",
224006          "version": "3.5.11",
224007          "licenses": [
224008            {
224009              "license": {
224010                "id": "Apache-2.0"
224011              }
224012            }
224013          ],
224014          "cpe": "cpe:2.3:a:mongodb:mongodb:3.5.11:*:*:*:*:*:*:*",
224015          "purl": "pkg:npm/mongodb@3.5.11",
224016          "swid": {
224017            "attachment": {}
224018          },
224019          "pedigree": {},
224020          "evidence": {},
224021          "signature": {
224022            "signature": {
224023              "publicKey": {}
224024            }
224025          },
224026          "modelCard": {
224027            "modelParameters": {
224028              "approach": {}
224029            },
224030            "quantitativeAnalysis": {
224031              "graphics": {}
224032            },
224033            "considerations": {}
224034          }
224035        },
224036        {
224037          "type": "library",
224038          "bom-ref": "pkg:npm/mqtt@4.3.7?package-id=3dfb9d92a32e39fb",
224039          "supplier": {},
224040          "name": "mqtt",
224041          "version": "4.3.7",
224042          "licenses": [
224043            {
224044              "license": {
224045                "id": "MIT"
224046              }
224047            }
224048          ],
224049          "cpe": "cpe:2.3:a:mqtt:mqtt:4.3.7:*:*:*:*:*:*:*",
224050          "purl": "pkg:npm/mqtt@4.3.7",
224051          "swid": {
224052            "attachment": {}
224053          },
224054          "pedigree": {},
224055          "evidence": {},
224056          "signature": {
224057            "signature": {
224058              "publicKey": {}
224059            }
224060          },
224061          "modelCard": {
224062            "modelParameters": {
224063              "approach": {}
224064            },
224065            "quantitativeAnalysis": {
224066              "graphics": {}
224067            },
224068            "considerations": {}
224069          }
224070        },
224071        {
224072          "type": "library",
224073          "bom-ref": "pkg:npm/mqtt-packet@6.10.0?package-id=6d4a13033efafbf1",
224074          "supplier": {},
224075          "name": "mqtt-packet",
224076          "version": "6.10.0",
224077          "licenses": [
224078            {
224079              "license": {
224080                "id": "MIT"
224081              }
224082            }
224083          ],
224084          "cpe": "cpe:2.3:a:mqtt-packet:mqtt-packet:6.10.0:*:*:*:*:*:*:*",
224085          "purl": "pkg:npm/mqtt-packet@6.10.0",
224086          "swid": {
224087            "attachment": {}
224088          },
224089          "pedigree": {},
224090          "evidence": {},
224091          "signature": {
224092            "signature": {
224093              "publicKey": {}
224094            }
224095          },
224096          "modelCard": {
224097            "modelParameters": {
224098              "approach": {}
224099            },
224100            "quantitativeAnalysis": {
224101              "graphics": {}
224102            },
224103            "considerations": {}
224104          }
224105        },
224106        {
224107          "type": "library",
224108          "bom-ref": "pkg:npm/mri@1.1.6?package-id=240a1fc952389136",
224109          "supplier": {},
224110          "name": "mri",
224111          "version": "1.1.6",
224112          "licenses": [
224113            {
224114              "license": {
224115                "id": "MIT"
224116              }
224117            }
224118          ],
224119          "cpe": "cpe:2.3:a:mri:mri:1.1.6:*:*:*:*:*:*:*",
224120          "purl": "pkg:npm/mri@1.1.6",
224121          "swid": {
224122            "attachment": {}
224123          },
224124          "pedigree": {},
224125          "evidence": {},
224126          "signature": {
224127            "signature": {
224128              "publicKey": {}
224129            }
224130          },
224131          "modelCard": {
224132            "modelParameters": {
224133              "approach": {}
224134            },
224135            "quantitativeAnalysis": {
224136              "graphics": {}
224137            },
224138            "considerations": {}
224139          }
224140        },
224141        {
224142          "type": "library",
224143          "bom-ref": "pkg:npm/ms@2.0.0?package-id=feb4188feae0109c",
224144          "supplier": {},
224145          "name": "ms",
224146          "version": "2.0.0",
224147          "licenses": [
224148            {
224149              "license": {
224150                "id": "MIT"
224151              }
224152            }
224153          ],
224154          "cpe": "cpe:2.3:a:ms:ms:2.0.0:*:*:*:*:*:*:*",
224155          "purl": "pkg:npm/ms@2.0.0",
224156          "swid": {
224157            "attachment": {}
224158          },
224159          "pedigree": {},
224160          "evidence": {},
224161          "signature": {
224162            "signature": {
224163              "publicKey": {}
224164            }
224165          },
224166          "modelCard": {
224167            "modelParameters": {
224168              "approach": {}
224169            },
224170            "quantitativeAnalysis": {
224171              "graphics": {}
224172            },
224173            "considerations": {}
224174          }
224175        },
224176        {
224177          "type": "library",
224178          "bom-ref": "pkg:npm/msal@1.4.17?package-id=490d9fb4508cdc94",
224179          "supplier": {},
224180          "name": "msal",
224181          "version": "1.4.17",
224182          "licenses": [
224183            {
224184              "license": {
224185                "id": "MIT"
224186              }
224187            }
224188          ],
224189          "cpe": "cpe:2.3:a:msal:msal:1.4.17:*:*:*:*:*:*:*",
224190          "purl": "pkg:npm/msal@1.4.17",
224191          "swid": {
224192            "attachment": {}
224193          },
224194          "pedigree": {},
224195          "evidence": {},
224196          "signature": {
224197            "signature": {
224198              "publicKey": {}
224199            }
224200          },
224201          "modelCard": {
224202            "modelParameters": {
224203              "approach": {}
224204            },
224205            "quantitativeAnalysis": {
224206              "graphics": {}
224207            },
224208            "considerations": {}
224209          }
224210        },
224211        {
224212          "type": "library",
224213          "bom-ref": "pkg:npm/mssql@7.3.5?package-id=9808e2811d48a6ce",
224214          "supplier": {},
224215          "name": "mssql",
224216          "version": "7.3.5",
224217          "licenses": [
224218            {
224219              "license": {
224220                "id": "MIT"
224221              }
224222            }
224223          ],
224224          "cpe": "cpe:2.3:a:mssql:mssql:7.3.5:*:*:*:*:*:*:*",
224225          "purl": "pkg:npm/mssql@7.3.5",
224226          "swid": {
224227            "attachment": {}
224228          },
224229          "pedigree": {},
224230          "evidence": {},
224231          "signature": {
224232            "signature": {
224233              "publicKey": {}
224234            }
224235          },
224236          "modelCard": {
224237            "modelParameters": {
224238              "approach": {}
224239            },
224240            "quantitativeAnalysis": {
224241              "graphics": {}
224242            },
224243            "considerations": {}
224244          }
224245        },
224246        {
224247          "type": "library",
224248          "bom-ref": "pkg:npm/mysql2@2.3.3?package-id=e58d18da22da6a83",
224249          "supplier": {},
224250          "name": "mysql2",
224251          "version": "2.3.3",
224252          "licenses": [
224253            {
224254              "license": {
224255                "id": "MIT"
224256              }
224257            }
224258          ],
224259          "cpe": "cpe:2.3:a:mysql2:mysql2:2.3.3:*:*:*:*:*:*:*",
224260          "purl": "pkg:npm/mysql2@2.3.3",
224261          "swid": {
224262            "attachment": {}
224263          },
224264          "pedigree": {},
224265          "evidence": {},
224266          "signature": {
224267            "signature": {
224268              "publicKey": {}
224269            }
224270          },
224271          "modelCard": {
224272            "modelParameters": {
224273              "approach": {}
224274            },
224275            "quantitativeAnalysis": {
224276              "graphics": {}
224277            },
224278            "considerations": {}
224279          }
224280        },
224281        {
224282          "type": "library",
224283          "bom-ref": "pkg:npm/named-placeholders@1.1.3?package-id=45591b6f07c34f9f",
224284          "supplier": {},
224285          "name": "named-placeholders",
224286          "version": "1.1.3",
224287          "licenses": [
224288            {
224289              "license": {
224290                "id": "MIT"
224291              }
224292            }
224293          ],
224294          "cpe": "cpe:2.3:a:named-placeholders:named-placeholders:1.1.3:*:*:*:*:*:*:*",
224295          "purl": "pkg:npm/named-placeholders@1.1.3",
224296          "swid": {
224297            "attachment": {}
224298          },
224299          "pedigree": {},
224300          "evidence": {},
224301          "signature": {
224302            "signature": {
224303              "publicKey": {}
224304            }
224305          },
224306          "modelCard": {
224307            "modelParameters": {
224308              "approach": {}
224309            },
224310            "quantitativeAnalysis": {
224311              "graphics": {}
224312            },
224313            "considerations": {}
224314          }
224315        },
224316        {
224317          "type": "library",
224318          "bom-ref": "pkg:npm/nan@2.17.0?package-id=30f65a817f752869",
224319          "supplier": {},
224320          "name": "nan",
224321          "version": "2.17.0",
224322          "licenses": [
224323            {
224324              "license": {
224325                "id": "MIT"
224326              }
224327            }
224328          ],
224329          "cpe": "cpe:2.3:a:nan:nan:2.17.0:*:*:*:*:*:*:*",
224330          "purl": "pkg:npm/nan@2.17.0",
224331          "swid": {
224332            "attachment": {}
224333          },
224334          "pedigree": {},
224335          "evidence": {},
224336          "signature": {
224337            "signature": {
224338              "publicKey": {}
224339            }
224340          },
224341          "modelCard": {
224342            "modelParameters": {
224343              "approach": {}
224344            },
224345            "quantitativeAnalysis": {
224346              "graphics": {}
224347            },
224348            "considerations": {}
224349          }
224350        },
224351        {
224352          "type": "library",
224353          "bom-ref": "pkg:npm/napi-build-utils@1.0.2?package-id=91fe8bb48c613d82",
224354          "supplier": {},
224355          "name": "napi-build-utils",
224356          "version": "1.0.2",
224357          "licenses": [
224358            {
224359              "license": {
224360                "id": "MIT"
224361              }
224362            }
224363          ],
224364          "cpe": "cpe:2.3:a:napi-build-utils:napi-build-utils:1.0.2:*:*:*:*:*:*:*",
224365          "purl": "pkg:npm/napi-build-utils@1.0.2",
224366          "swid": {
224367            "attachment": {}
224368          },
224369          "pedigree": {},
224370          "evidence": {},
224371          "signature": {
224372            "signature": {
224373              "publicKey": {}
224374            }
224375          },
224376          "modelCard": {
224377            "modelParameters": {
224378              "approach": {}
224379            },
224380            "quantitativeAnalysis": {
224381              "graphics": {}
224382            },
224383            "considerations": {}
224384          }
224385        },
224386        {
224387          "type": "library",
224388          "bom-ref": "pkg:npm/native-dns@0.7.0?package-id=4baf7a9de9c01aab",
224389          "supplier": {},
224390          "name": "native-dns",
224391          "version": "0.7.0",
224392          "cpe": "cpe:2.3:a:native-dns:native-dns:0.7.0:*:*:*:*:*:*:*",
224393          "purl": "pkg:npm/native-dns@0.7.0",
224394          "swid": {
224395            "attachment": {}
224396          },
224397          "pedigree": {},
224398          "evidence": {},
224399          "signature": {
224400            "signature": {
224401              "publicKey": {}
224402            }
224403          },
224404          "modelCard": {
224405            "modelParameters": {
224406              "approach": {}
224407            },
224408            "quantitativeAnalysis": {
224409              "graphics": {}
224410            },
224411            "considerations": {}
224412          }
224413        },
224414        {
224415          "type": "library",
224416          "bom-ref": "pkg:npm/native-dns-cache@0.0.2?package-id=90af90d700cf54d6",
224417          "supplier": {},
224418          "name": "native-dns-cache",
224419          "version": "0.0.2",
224420          "cpe": "cpe:2.3:a:native-dns-cache:native-dns-cache:0.0.2:*:*:*:*:*:*:*",
224421          "purl": "pkg:npm/native-dns-cache@0.0.2",
224422          "swid": {
224423            "attachment": {}
224424          },
224425          "pedigree": {},
224426          "evidence": {},
224427          "signature": {
224428            "signature": {
224429              "publicKey": {}
224430            }
224431          },
224432          "modelCard": {
224433            "modelParameters": {
224434              "approach": {}
224435            },
224436            "quantitativeAnalysis": {
224437              "graphics": {}
224438            },
224439            "considerations": {}
224440          }
224441        },
224442        {
224443          "type": "library",
224444          "bom-ref": "pkg:npm/native-dns-packet@0.1.1?package-id=7e525552d425530f",
224445          "supplier": {},
224446          "name": "native-dns-packet",
224447          "version": "0.1.1",
224448          "licenses": [
224449            {
224450              "license": {
224451                "id": "MIT"
224452              }
224453            }
224454          ],
224455          "cpe": "cpe:2.3:a:native-dns-packet:native-dns-packet:0.1.1:*:*:*:*:*:*:*",
224456          "purl": "pkg:npm/native-dns-packet@0.1.1",
224457          "swid": {
224458            "attachment": {}
224459          },
224460          "pedigree": {},
224461          "evidence": {},
224462          "signature": {
224463            "signature": {
224464              "publicKey": {}
224465            }
224466          },
224467          "modelCard": {
224468            "modelParameters": {
224469              "approach": {}
224470            },
224471            "quantitativeAnalysis": {
224472              "graphics": {}
224473            },
224474            "considerations": {}
224475          }
224476        },
224477        {
224478          "type": "library",
224479          "bom-ref": "pkg:npm/native-duplexpair@1.0.0?package-id=b53dc9479eefc91b",
224480          "supplier": {},
224481          "name": "native-duplexpair",
224482          "version": "1.0.0",
224483          "licenses": [
224484            {
224485              "license": {
224486                "id": "MIT"
224487              }
224488            }
224489          ],
224490          "cpe": "cpe:2.3:a:native-duplexpair:native-duplexpair:1.0.0:*:*:*:*:*:*:*",
224491          "purl": "pkg:npm/native-duplexpair@1.0.0",
224492          "swid": {
224493            "attachment": {}
224494          },
224495          "pedigree": {},
224496          "evidence": {},
224497          "signature": {
224498            "signature": {
224499              "publicKey": {}
224500            }
224501          },
224502          "modelCard": {
224503            "modelParameters": {
224504              "approach": {}
224505            },
224506            "quantitativeAnalysis": {
224507              "graphics": {}
224508            },
224509            "considerations": {}
224510          }
224511        },
224512        {
224513          "type": "library",
224514          "bom-ref": "pkg:npm/net@1.0.2?package-id=945c43271284705b",
224515          "supplier": {},
224516          "name": "net",
224517          "version": "1.0.2",
224518          "licenses": [
224519            {
224520              "license": {
224521                "id": "MIT"
224522              }
224523            }
224524          ],
224525          "cpe": "cpe:2.3:a:net:net:1.0.2:*:*:*:*:*:*:*",
224526          "purl": "pkg:npm/net@1.0.2",
224527          "swid": {
224528            "attachment": {}
224529          },
224530          "pedigree": {},
224531          "evidence": {},
224532          "signature": {
224533            "signature": {
224534              "publicKey": {}
224535            }
224536          },
224537          "modelCard": {
224538            "modelParameters": {
224539              "approach": {}
224540            },
224541            "quantitativeAnalysis": {
224542              "graphics": {}
224543            },
224544            "considerations": {}
224545          }
224546        },
224547        {
224548          "type": "library",
224549          "bom-ref": "pkg:npm/net-snmp@2.10.1?package-id=73bfaeb8ccc0620f",
224550          "supplier": {},
224551          "name": "net-snmp",
224552          "version": "2.10.1",
224553          "licenses": [
224554            {
224555              "license": {
224556                "id": "MIT"
224557              }
224558            }
224559          ],
224560          "cpe": "cpe:2.3:a:net-snmp:net-snmp:2.10.1:*:*:*:*:*:*:*",
224561          "purl": "pkg:npm/net-snmp@2.10.1",
224562          "swid": {
224563            "attachment": {}
224564          },
224565          "pedigree": {},
224566          "evidence": {},
224567          "signature": {
224568            "signature": {
224569              "publicKey": {}
224570            }
224571          },
224572          "modelCard": {
224573            "modelParameters": {
224574              "approach": {}
224575            },
224576            "quantitativeAnalysis": {
224577              "graphics": {}
224578            },
224579            "considerations": {}
224580          }
224581        },
224582        {
224583          "type": "library",
224584          "bom-ref": "pkg:npm/netmask@2.0.2?package-id=7b8a537382e19f84",
224585          "supplier": {},
224586          "name": "netmask",
224587          "version": "2.0.2",
224588          "licenses": [
224589            {
224590              "license": {
224591                "id": "MIT"
224592              }
224593            }
224594          ],
224595          "cpe": "cpe:2.3:a:netmask:netmask:2.0.2:*:*:*:*:*:*:*",
224596          "purl": "pkg:npm/netmask@2.0.2",
224597          "swid": {
224598            "attachment": {}
224599          },
224600          "pedigree": {},
224601          "evidence": {},
224602          "signature": {
224603            "signature": {
224604              "publicKey": {}
224605            }
224606          },
224607          "modelCard": {
224608            "modelParameters": {
224609              "approach": {}
224610            },
224611            "quantitativeAnalysis": {
224612              "graphics": {}
224613            },
224614            "considerations": {}
224615          }
224616        },
224617        {
224618          "type": "library",
224619          "bom-ref": "pkg:npm/node-abi@3.40.0?package-id=845e4dabbed5418c",
224620          "supplier": {},
224621          "name": "node-abi",
224622          "version": "3.40.0",
224623          "licenses": [
224624            {
224625              "license": {
224626                "id": "MIT"
224627              }
224628            }
224629          ],
224630          "cpe": "cpe:2.3:a:node-abi:node-abi:3.40.0:*:*:*:*:*:*:*",
224631          "purl": "pkg:npm/node-abi@3.40.0",
224632          "swid": {
224633            "attachment": {}
224634          },
224635          "pedigree": {},
224636          "evidence": {},
224637          "signature": {
224638            "signature": {
224639              "publicKey": {}
224640            }
224641          },
224642          "modelCard": {
224643            "modelParameters": {
224644              "approach": {}
224645            },
224646            "quantitativeAnalysis": {
224647              "graphics": {}
224648            },
224649            "considerations": {}
224650          }
224651        },
224652        {
224653          "type": "library",
224654          "bom-ref": "pkg:npm/node-abort-controller@2.0.0?package-id=365fc27f037b2dc9",
224655          "supplier": {},
224656          "name": "node-abort-controller",
224657          "version": "2.0.0",
224658          "licenses": [
224659            {
224660              "license": {
224661                "id": "MIT"
224662              }
224663            }
224664          ],
224665          "cpe": "cpe:2.3:a:node-abort-controller:node-abort-controller:2.0.0:*:*:*:*:*:*:*",
224666          "purl": "pkg:npm/node-abort-controller@2.0.0",
224667          "swid": {
224668            "attachment": {}
224669          },
224670          "pedigree": {},
224671          "evidence": {},
224672          "signature": {
224673            "signature": {
224674              "publicKey": {}
224675            }
224676          },
224677          "modelCard": {
224678            "modelParameters": {
224679              "approach": {}
224680            },
224681            "quantitativeAnalysis": {
224682              "graphics": {}
224683            },
224684            "considerations": {}
224685          }
224686        },
224687        {
224688          "type": "library",
224689          "bom-ref": "pkg:npm/node-addon-api@4.3.0?package-id=737c845459b5f28b",
224690          "supplier": {},
224691          "name": "node-addon-api",
224692          "version": "4.3.0",
224693          "licenses": [
224694            {
224695              "license": {
224696                "id": "MIT"
224697              }
224698            }
224699          ],
224700          "cpe": "cpe:2.3:a:node-addon-api:node-addon-api:4.3.0:*:*:*:*:*:*:*",
224701          "purl": "pkg:npm/node-addon-api@4.3.0",
224702          "swid": {
224703            "attachment": {}
224704          },
224705          "pedigree": {},
224706          "evidence": {},
224707          "signature": {
224708            "signature": {
224709              "publicKey": {}
224710            }
224711          },
224712          "modelCard": {
224713            "modelParameters": {
224714              "approach": {}
224715            },
224716            "quantitativeAnalysis": {
224717              "graphics": {}
224718            },
224719            "considerations": {}
224720          }
224721        },
224722        {
224723          "type": "library",
224724          "bom-ref": "pkg:npm/node-downloader-helper@2.1.6?package-id=9e9a8bd9d75dc13e",
224725          "supplier": {},
224726          "name": "node-downloader-helper",
224727          "version": "2.1.6",
224728          "licenses": [
224729            {
224730              "license": {
224731                "id": "MIT"
224732              }
224733            }
224734          ],
224735          "cpe": "cpe:2.3:a:node-downloader-helper:node-downloader-helper:2.1.6:*:*:*:*:*:*:*",
224736          "purl": "pkg:npm/node-downloader-helper@2.1.6",
224737          "swid": {
224738            "attachment": {}
224739          },
224740          "pedigree": {},
224741          "evidence": {},
224742          "signature": {
224743            "signature": {
224744              "publicKey": {}
224745            }
224746          },
224747          "modelCard": {
224748            "modelParameters": {
224749              "approach": {}
224750            },
224751            "quantitativeAnalysis": {
224752              "graphics": {}
224753            },
224754            "considerations": {}
224755          }
224756        },
224757        {
224758          "type": "library",
224759          "bom-ref": "pkg:npm/node-fetch@2.6.9?package-id=d393e37503d93a07",
224760          "supplier": {},
224761          "name": "node-fetch",
224762          "version": "2.6.9",
224763          "licenses": [
224764            {
224765              "license": {
224766                "id": "MIT"
224767              }
224768            }
224769          ],
224770          "cpe": "cpe:2.3:a:node-fetch:node-fetch:2.6.9:*:*:*:*:*:*:*",
224771          "purl": "pkg:npm/node-fetch@2.6.9",
224772          "swid": {
224773            "attachment": {}
224774          },
224775          "pedigree": {},
224776          "evidence": {},
224777          "signature": {
224778            "signature": {
224779              "publicKey": {}
224780            }
224781          },
224782          "modelCard": {
224783            "modelParameters": {
224784              "approach": {}
224785            },
224786            "quantitativeAnalysis": {
224787              "graphics": {}
224788            },
224789            "considerations": {}
224790          }
224791        },
224792        {
224793          "type": "library",
224794          "bom-ref": "pkg:npm/node-forge@0.9.2?package-id=63694c905ac251ac",
224795          "supplier": {},
224796          "name": "node-forge",
224797          "version": "0.9.2",
224798          "licenses": [
224799            {
224800              "license": {
224801                "name": "(BSD-3-Clause OR GPL-2.0)"
224802              }
224803            }
224804          ],
224805          "cpe": "cpe:2.3:a:node-forge:node-forge:0.9.2:*:*:*:*:*:*:*",
224806          "purl": "pkg:npm/node-forge@0.9.2",
224807          "swid": {
224808            "attachment": {}
224809          },
224810          "pedigree": {},
224811          "evidence": {},
224812          "signature": {
224813            "signature": {
224814              "publicKey": {}
224815            }
224816          },
224817          "modelCard": {
224818            "modelParameters": {
224819              "approach": {}
224820            },
224821            "quantitativeAnalysis": {
224822              "graphics": {}
224823            },
224824            "considerations": {}
224825          }
224826        },
224827        {
224828          "type": "library",
224829          "bom-ref": "pkg:npm/node-jq@2.3.5?package-id=3d658658aef7763",
224830          "supplier": {},
224831          "name": "node-jq",
224832          "version": "2.3.5",
224833          "licenses": [
224834            {
224835              "license": {
224836                "id": "MIT"
224837              }
224838            }
224839          ],
224840          "cpe": "cpe:2.3:a:node-jq:node-jq:2.3.5:*:*:*:*:*:*:*",
224841          "purl": "pkg:npm/node-jq@2.3.5",
224842          "swid": {
224843            "attachment": {}
224844          },
224845          "pedigree": {},
224846          "evidence": {},
224847          "signature": {
224848            "signature": {
224849              "publicKey": {}
224850            }
224851          },
224852          "modelCard": {
224853            "modelParameters": {
224854              "approach": {}
224855            },
224856            "quantitativeAnalysis": {
224857              "graphics": {}
224858            },
224859            "considerations": {}
224860          }
224861        },
224862        {
224863          "type": "library",
224864          "bom-ref": "pkg:npm/nodemailer@6.9.1?package-id=e3d87d856d4479cb",
224865          "supplier": {},
224866          "name": "nodemailer",
224867          "version": "6.9.1",
224868          "licenses": [
224869            {
224870              "license": {
224871                "id": "MIT"
224872              }
224873            }
224874          ],
224875          "cpe": "cpe:2.3:a:nodemailer:nodemailer:6.9.1:*:*:*:*:*:*:*",
224876          "purl": "pkg:npm/nodemailer@6.9.1",
224877          "swid": {
224878            "attachment": {}
224879          },
224880          "pedigree": {},
224881          "evidence": {},
224882          "signature": {
224883            "signature": {
224884              "publicKey": {}
224885            }
224886          },
224887          "modelCard": {
224888            "modelParameters": {
224889              "approach": {}
224890            },
224891            "quantitativeAnalysis": {
224892              "graphics": {}
224893            },
224894            "considerations": {}
224895          }
224896        },
224897        {
224898          "type": "library",
224899          "bom-ref": "pkg:npm/nodemailer-cram-md5@1.0.0?package-id=c6aaa4a77580698c",
224900          "supplier": {},
224901          "name": "nodemailer-cram-md5",
224902          "version": "1.0.0",
224903          "licenses": [
224904            {
224905              "license": {
224906                "id": "ISC"
224907              }
224908            }
224909          ],
224910          "cpe": "cpe:2.3:a:nodemailer-cram-md5:nodemailer-cram-md5:1.0.0:*:*:*:*:*:*:*",
224911          "purl": "pkg:npm/nodemailer-cram-md5@1.0.0",
224912          "swid": {
224913            "attachment": {}
224914          },
224915          "pedigree": {},
224916          "evidence": {},
224917          "signature": {
224918            "signature": {
224919              "publicKey": {}
224920            }
224921          },
224922          "modelCard": {
224923            "modelParameters": {
224924              "approach": {}
224925            },
224926            "quantitativeAnalysis": {
224927              "graphics": {}
224928            },
224929            "considerations": {}
224930          }
224931        },
224932        {
224933          "type": "library",
224934          "bom-ref": "pkg:npm/nodemailer-ntlm-auth@1.0.3?package-id=22141b4145606d8",
224935          "supplier": {},
224936          "name": "nodemailer-ntlm-auth",
224937          "version": "1.0.3",
224938          "licenses": [
224939            {
224940              "license": {
224941                "id": "ISC"
224942              }
224943            }
224944          ],
224945          "cpe": "cpe:2.3:a:nodemailer-ntlm-auth:nodemailer-ntlm-auth:1.0.3:*:*:*:*:*:*:*",
224946          "purl": "pkg:npm/nodemailer-ntlm-auth@1.0.3",
224947          "swid": {
224948            "attachment": {}
224949          },
224950          "pedigree": {},
224951          "evidence": {},
224952          "signature": {
224953            "signature": {
224954              "publicKey": {}
224955            }
224956          },
224957          "modelCard": {
224958            "modelParameters": {
224959              "approach": {}
224960            },
224961            "quantitativeAnalysis": {
224962              "graphics": {}
224963            },
224964            "considerations": {}
224965          }
224966        },
224967        {
224968          "type": "library",
224969          "bom-ref": "pkg:npm/normalize-path@3.0.0?package-id=f19edc9ce3987dc0",
224970          "supplier": {},
224971          "name": "normalize-path",
224972          "version": "3.0.0",
224973          "licenses": [
224974            {
224975              "license": {
224976                "id": "MIT"
224977              }
224978            }
224979          ],
224980          "cpe": "cpe:2.3:a:normalize-path:normalize-path:3.0.0:*:*:*:*:*:*:*",
224981          "purl": "pkg:npm/normalize-path@3.0.0",
224982          "swid": {
224983            "attachment": {}
224984          },
224985          "pedigree": {},
224986          "evidence": {},
224987          "signature": {
224988            "signature": {
224989              "publicKey": {}
224990            }
224991          },
224992          "modelCard": {
224993            "modelParameters": {
224994              "approach": {}
224995            },
224996            "quantitativeAnalysis": {
224997              "graphics": {}
224998            },
224999            "considerations": {}
225000          }
225001        },
225002        {
225003          "type": "library",
225004          "bom-ref": "pkg:npm/npm-conf@1.1.3?package-id=2ba23af7d43a4fe9",
225005          "supplier": {},
225006          "name": "npm-conf",
225007          "version": "1.1.3",
225008          "licenses": [
225009            {
225010              "license": {
225011                "id": "MIT"
225012              }
225013            }
225014          ],
225015          "cpe": "cpe:2.3:a:npm-conf:npm-conf:1.1.3:*:*:*:*:*:*:*",
225016          "purl": "pkg:npm/npm-conf@1.1.3",
225017          "swid": {
225018            "attachment": {}
225019          },
225020          "pedigree": {},
225021          "evidence": {},
225022          "signature": {
225023            "signature": {
225024              "publicKey": {}
225025            }
225026          },
225027          "modelCard": {
225028            "modelParameters": {
225029              "approach": {}
225030            },
225031            "quantitativeAnalysis": {
225032              "graphics": {}
225033            },
225034            "considerations": {}
225035          }
225036        },
225037        {
225038          "type": "library",
225039          "bom-ref": "pkg:npm/npm-run-path@2.0.2?package-id=e1df79664dbd98bd",
225040          "supplier": {},
225041          "name": "npm-run-path",
225042          "version": "2.0.2",
225043          "licenses": [
225044            {
225045              "license": {
225046                "id": "MIT"
225047              }
225048            }
225049          ],
225050          "cpe": "cpe:2.3:a:npm-run-path:npm-run-path:2.0.2:*:*:*:*:*:*:*",
225051          "purl": "pkg:npm/npm-run-path@2.0.2",
225052          "swid": {
225053            "attachment": {}
225054          },
225055          "pedigree": {},
225056          "evidence": {},
225057          "signature": {
225058            "signature": {
225059              "publicKey": {}
225060            }
225061          },
225062          "modelCard": {
225063            "modelParameters": {
225064              "approach": {}
225065            },
225066            "quantitativeAnalysis": {
225067              "graphics": {}
225068            },
225069            "considerations": {}
225070          }
225071        },
225072        {
225073          "type": "library",
225074          "bom-ref": "pkg:npm/nslookup@1.1.1?package-id=939a5a3901e2c380",
225075          "supplier": {},
225076          "name": "nslookup",
225077          "version": "1.1.1",
225078          "licenses": [
225079            {
225080              "license": {
225081                "id": "MIT"
225082              }
225083            }
225084          ],
225085          "cpe": "cpe:2.3:a:nslookup:nslookup:1.1.1:*:*:*:*:*:*:*",
225086          "purl": "pkg:npm/nslookup@1.1.1",
225087          "swid": {
225088            "attachment": {}
225089          },
225090          "pedigree": {},
225091          "evidence": {},
225092          "signature": {
225093            "signature": {
225094              "publicKey": {}
225095            }
225096          },
225097          "modelCard": {
225098            "modelParameters": {
225099              "approach": {}
225100            },
225101            "quantitativeAnalysis": {
225102              "graphics": {}
225103            },
225104            "considerations": {}
225105          }
225106        },
225107        {
225108          "type": "library",
225109          "bom-ref": "pkg:npm/number-allocator@1.0.14?package-id=c14821c5f37e4114",
225110          "supplier": {},
225111          "name": "number-allocator",
225112          "version": "1.0.14",
225113          "licenses": [
225114            {
225115              "license": {
225116                "id": "MIT"
225117              }
225118            }
225119          ],
225120          "cpe": "cpe:2.3:a:number-allocator:number-allocator:1.0.14:*:*:*:*:*:*:*",
225121          "purl": "pkg:npm/number-allocator@1.0.14",
225122          "swid": {
225123            "attachment": {}
225124          },
225125          "pedigree": {},
225126          "evidence": {},
225127          "signature": {
225128            "signature": {
225129              "publicKey": {}
225130            }
225131          },
225132          "modelCard": {
225133            "modelParameters": {
225134              "approach": {}
225135            },
225136            "quantitativeAnalysis": {
225137              "graphics": {}
225138            },
225139            "considerations": {}
225140          }
225141        },
225142        {
225143          "type": "library",
225144          "bom-ref": "pkg:npm/oauth-sign@0.9.0?package-id=cd8ae3e717266c46",
225145          "supplier": {},
225146          "name": "oauth-sign",
225147          "version": "0.9.0",
225148          "licenses": [
225149            {
225150              "license": {
225151                "id": "Apache-2.0"
225152              }
225153            }
225154          ],
225155          "cpe": "cpe:2.3:a:oauth-sign:oauth-sign:0.9.0:*:*:*:*:*:*:*",
225156          "purl": "pkg:npm/oauth-sign@0.9.0",
225157          "swid": {
225158            "attachment": {}
225159          },
225160          "pedigree": {},
225161          "evidence": {},
225162          "signature": {
225163            "signature": {
225164              "publicKey": {}
225165            }
225166          },
225167          "modelCard": {
225168            "modelParameters": {
225169              "approach": {}
225170            },
225171            "quantitativeAnalysis": {
225172              "graphics": {}
225173            },
225174            "considerations": {}
225175          }
225176        },
225177        {
225178          "type": "library",
225179          "bom-ref": "pkg:npm/object-assign@4.1.1?package-id=63fe6c472c96e9b5",
225180          "supplier": {},
225181          "name": "object-assign",
225182          "version": "4.1.1",
225183          "licenses": [
225184            {
225185              "license": {
225186                "id": "MIT"
225187              }
225188            }
225189          ],
225190          "cpe": "cpe:2.3:a:object-assign:object-assign:4.1.1:*:*:*:*:*:*:*",
225191          "purl": "pkg:npm/object-assign@4.1.1",
225192          "swid": {
225193            "attachment": {}
225194          },
225195          "pedigree": {},
225196          "evidence": {},
225197          "signature": {
225198            "signature": {
225199              "publicKey": {}
225200            }
225201          },
225202          "modelCard": {
225203            "modelParameters": {
225204              "approach": {}
225205            },
225206            "quantitativeAnalysis": {
225207              "graphics": {}
225208            },
225209            "considerations": {}
225210          }
225211        },
225212        {
225213          "type": "library",
225214          "bom-ref": "pkg:npm/object-inspect@1.12.3?package-id=a598678420ee2424",
225215          "supplier": {},
225216          "name": "object-inspect",
225217          "version": "1.12.3",
225218          "licenses": [
225219            {
225220              "license": {
225221                "id": "MIT"
225222              }
225223            }
225224          ],
225225          "cpe": "cpe:2.3:a:object-inspect:object-inspect:1.12.3:*:*:*:*:*:*:*",
225226          "purl": "pkg:npm/object-inspect@1.12.3",
225227          "swid": {
225228            "attachment": {}
225229          },
225230          "pedigree": {},
225231          "evidence": {},
225232          "signature": {
225233            "signature": {
225234              "publicKey": {}
225235            }
225236          },
225237          "modelCard": {
225238            "modelParameters": {
225239              "approach": {}
225240            },
225241            "quantitativeAnalysis": {
225242              "graphics": {}
225243            },
225244            "considerations": {}
225245          }
225246        },
225247        {
225248          "type": "library",
225249          "bom-ref": "pkg:npm/object-to-xml@2.0.0?package-id=9643952784075673",
225250          "supplier": {},
225251          "name": "object-to-xml",
225252          "version": "2.0.0",
225253          "licenses": [
225254            {
225255              "license": {
225256                "id": "MIT"
225257              }
225258            }
225259          ],
225260          "cpe": "cpe:2.3:a:object-to-xml:object-to-xml:2.0.0:*:*:*:*:*:*:*",
225261          "purl": "pkg:npm/object-to-xml@2.0.0",
225262          "swid": {
225263            "attachment": {}
225264          },
225265          "pedigree": {},
225266          "evidence": {},
225267          "signature": {
225268            "signature": {
225269              "publicKey": {}
225270            }
225271          },
225272          "modelCard": {
225273            "modelParameters": {
225274              "approach": {}
225275            },
225276            "quantitativeAnalysis": {
225277              "graphics": {}
225278            },
225279            "considerations": {}
225280          }
225281        },
225282        {
225283          "type": "library",
225284          "bom-ref": "pkg:npm/once@1.4.0?package-id=8c181f3657a90187",
225285          "supplier": {},
225286          "name": "once",
225287          "version": "1.4.0",
225288          "licenses": [
225289            {
225290              "license": {
225291                "id": "ISC"
225292              }
225293            }
225294          ],
225295          "cpe": "cpe:2.3:a:once:once:1.4.0:*:*:*:*:*:*:*",
225296          "purl": "pkg:npm/once@1.4.0",
225297          "swid": {
225298            "attachment": {}
225299          },
225300          "pedigree": {},
225301          "evidence": {},
225302          "signature": {
225303            "signature": {
225304              "publicKey": {}
225305            }
225306          },
225307          "modelCard": {
225308            "modelParameters": {
225309              "approach": {}
225310            },
225311            "quantitativeAnalysis": {
225312              "graphics": {}
225313            },
225314            "considerations": {}
225315          }
225316        },
225317        {
225318          "type": "library",
225319          "bom-ref": "pkg:npm/open@7.4.2?package-id=8ee0a1cd09b34e5d",
225320          "supplier": {},
225321          "name": "open",
225322          "version": "7.4.2",
225323          "licenses": [
225324            {
225325              "license": {
225326                "id": "MIT"
225327              }
225328            }
225329          ],
225330          "cpe": "cpe:2.3:a:open:open:7.4.2:*:*:*:*:*:*:*",
225331          "purl": "pkg:npm/open@7.4.2",
225332          "swid": {
225333            "attachment": {}
225334          },
225335          "pedigree": {},
225336          "evidence": {},
225337          "signature": {
225338            "signature": {
225339              "publicKey": {}
225340            }
225341          },
225342          "modelCard": {
225343            "modelParameters": {
225344              "approach": {}
225345            },
225346            "quantitativeAnalysis": {
225347              "graphics": {}
225348            },
225349            "considerations": {}
225350          }
225351        },
225352        {
225353          "type": "library",
225354          "bom-ref": "pkg:npm/p-cancelable@0.3.0?package-id=38a8c444277f3022",
225355          "supplier": {},
225356          "name": "p-cancelable",
225357          "version": "0.3.0",
225358          "licenses": [
225359            {
225360              "license": {
225361                "id": "MIT"
225362              }
225363            }
225364          ],
225365          "cpe": "cpe:2.3:a:p-cancelable:p-cancelable:0.3.0:*:*:*:*:*:*:*",
225366          "purl": "pkg:npm/p-cancelable@0.3.0",
225367          "swid": {
225368            "attachment": {}
225369          },
225370          "pedigree": {},
225371          "evidence": {},
225372          "signature": {
225373            "signature": {
225374              "publicKey": {}
225375            }
225376          },
225377          "modelCard": {
225378            "modelParameters": {
225379              "approach": {}
225380            },
225381            "quantitativeAnalysis": {
225382              "graphics": {}
225383            },
225384            "considerations": {}
225385          }
225386        },
225387        {
225388          "type": "library",
225389          "bom-ref": "pkg:npm/p-event@1.3.0?package-id=19bb01f39139ca0b",
225390          "supplier": {},
225391          "name": "p-event",
225392          "version": "1.3.0",
225393          "licenses": [
225394            {
225395              "license": {
225396                "id": "MIT"
225397              }
225398            }
225399          ],
225400          "cpe": "cpe:2.3:a:p-event:p-event:1.3.0:*:*:*:*:*:*:*",
225401          "purl": "pkg:npm/p-event@1.3.0",
225402          "swid": {
225403            "attachment": {}
225404          },
225405          "pedigree": {},
225406          "evidence": {},
225407          "signature": {
225408            "signature": {
225409              "publicKey": {}
225410            }
225411          },
225412          "modelCard": {
225413            "modelParameters": {
225414              "approach": {}
225415            },
225416            "quantitativeAnalysis": {
225417              "graphics": {}
225418            },
225419            "considerations": {}
225420          }
225421        },
225422        {
225423          "type": "library",
225424          "bom-ref": "pkg:npm/p-finally@1.0.0?package-id=d6d5e10d2f8c93f2",
225425          "supplier": {},
225426          "name": "p-finally",
225427          "version": "1.0.0",
225428          "licenses": [
225429            {
225430              "license": {
225431                "id": "MIT"
225432              }
225433            }
225434          ],
225435          "cpe": "cpe:2.3:a:p-finally:p-finally:1.0.0:*:*:*:*:*:*:*",
225436          "purl": "pkg:npm/p-finally@1.0.0",
225437          "swid": {
225438            "attachment": {}
225439          },
225440          "pedigree": {},
225441          "evidence": {},
225442          "signature": {
225443            "signature": {
225444              "publicKey": {}
225445            }
225446          },
225447          "modelCard": {
225448            "modelParameters": {
225449              "approach": {}
225450            },
225451            "quantitativeAnalysis": {
225452              "graphics": {}
225453            },
225454            "considerations": {}
225455          }
225456        },
225457        {
225458          "type": "library",
225459          "bom-ref": "pkg:npm/p-map-series@1.0.0?package-id=3a1ed4f0a02c2e01",
225460          "supplier": {},
225461          "name": "p-map-series",
225462          "version": "1.0.0",
225463          "licenses": [
225464            {
225465              "license": {
225466                "id": "MIT"
225467              }
225468            }
225469          ],
225470          "cpe": "cpe:2.3:a:p-map-series:p-map-series:1.0.0:*:*:*:*:*:*:*",
225471          "purl": "pkg:npm/p-map-series@1.0.0",
225472          "swid": {
225473            "attachment": {}
225474          },
225475          "pedigree": {},
225476          "evidence": {},
225477          "signature": {
225478            "signature": {
225479              "publicKey": {}
225480            }
225481          },
225482          "modelCard": {
225483            "modelParameters": {
225484              "approach": {}
225485            },
225486            "quantitativeAnalysis": {
225487              "graphics": {}
225488            },
225489            "considerations": {}
225490          }
225491        },
225492        {
225493          "type": "library",
225494          "bom-ref": "pkg:npm/p-reduce@1.0.0?package-id=55f25bcbca1e2bbe",
225495          "supplier": {},
225496          "name": "p-reduce",
225497          "version": "1.0.0",
225498          "licenses": [
225499            {
225500              "license": {
225501                "id": "MIT"
225502              }
225503            }
225504          ],
225505          "cpe": "cpe:2.3:a:p-reduce:p-reduce:1.0.0:*:*:*:*:*:*:*",
225506          "purl": "pkg:npm/p-reduce@1.0.0",
225507          "swid": {
225508            "attachment": {}
225509          },
225510          "pedigree": {},
225511          "evidence": {},
225512          "signature": {
225513            "signature": {
225514              "publicKey": {}
225515            }
225516          },
225517          "modelCard": {
225518            "modelParameters": {
225519              "approach": {}
225520            },
225521            "quantitativeAnalysis": {
225522              "graphics": {}
225523            },
225524            "considerations": {}
225525          }
225526        },
225527        {
225528          "type": "library",
225529          "bom-ref": "pkg:npm/p-timeout@1.2.1?package-id=9dff646575de5046",
225530          "supplier": {},
225531          "name": "p-timeout",
225532          "version": "1.2.1",
225533          "licenses": [
225534            {
225535              "license": {
225536                "id": "MIT"
225537              }
225538            }
225539          ],
225540          "cpe": "cpe:2.3:a:p-timeout:p-timeout:1.2.1:*:*:*:*:*:*:*",
225541          "purl": "pkg:npm/p-timeout@1.2.1",
225542          "swid": {
225543            "attachment": {}
225544          },
225545          "pedigree": {},
225546          "evidence": {},
225547          "signature": {
225548            "signature": {
225549              "publicKey": {}
225550            }
225551          },
225552          "modelCard": {
225553            "modelParameters": {
225554              "approach": {}
225555            },
225556            "quantitativeAnalysis": {
225557              "graphics": {}
225558            },
225559            "considerations": {}
225560          }
225561        },
225562        {
225563          "type": "library",
225564          "bom-ref": "pkg:npm/packet-reader@1.0.0?package-id=75df104dc2508940",
225565          "supplier": {},
225566          "name": "packet-reader",
225567          "version": "1.0.0",
225568          "licenses": [
225569            {
225570              "license": {
225571                "id": "MIT"
225572              }
225573            }
225574          ],
225575          "cpe": "cpe:2.3:a:packet-reader:packet-reader:1.0.0:*:*:*:*:*:*:*",
225576          "purl": "pkg:npm/packet-reader@1.0.0",
225577          "swid": {
225578            "attachment": {}
225579          },
225580          "pedigree": {},
225581          "evidence": {},
225582          "signature": {
225583            "signature": {
225584              "publicKey": {}
225585            }
225586          },
225587          "modelCard": {
225588            "modelParameters": {
225589              "approach": {}
225590            },
225591            "quantitativeAnalysis": {
225592              "graphics": {}
225593            },
225594            "considerations": {}
225595          }
225596        },
225597        {
225598          "type": "library",
225599          "bom-ref": "pkg:npm/pako@1.0.11?package-id=4ba4360c0ee4894b",
225600          "supplier": {},
225601          "name": "pako",
225602          "version": "1.0.11",
225603          "licenses": [
225604            {
225605              "license": {
225606                "name": "(MIT AND Zlib)"
225607              }
225608            }
225609          ],
225610          "cpe": "cpe:2.3:a:pako:pako:1.0.11:*:*:*:*:*:*:*",
225611          "purl": "pkg:npm/pako@1.0.11",
225612          "swid": {
225613            "attachment": {}
225614          },
225615          "pedigree": {},
225616          "evidence": {},
225617          "signature": {
225618            "signature": {
225619              "publicKey": {}
225620            }
225621          },
225622          "modelCard": {
225623            "modelParameters": {
225624              "approach": {}
225625            },
225626            "quantitativeAnalysis": {
225627              "graphics": {}
225628            },
225629            "considerations": {}
225630          }
225631        },
225632        {
225633          "type": "library",
225634          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=3d9c2ce1c4f890ec",
225635          "supplier": {},
225636          "name": "path-is-absolute",
225637          "version": "1.0.1",
225638          "licenses": [
225639            {
225640              "license": {
225641                "id": "MIT"
225642              }
225643            }
225644          ],
225645          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
225646          "purl": "pkg:npm/path-is-absolute@1.0.1",
225647          "swid": {
225648            "attachment": {}
225649          },
225650          "pedigree": {},
225651          "evidence": {},
225652          "signature": {
225653            "signature": {
225654              "publicKey": {}
225655            }
225656          },
225657          "modelCard": {
225658            "modelParameters": {
225659              "approach": {}
225660            },
225661            "quantitativeAnalysis": {
225662              "graphics": {}
225663            },
225664            "considerations": {}
225665          }
225666        },
225667        {
225668          "type": "library",
225669          "bom-ref": "pkg:npm/path-key@2.0.1?package-id=21cbd9787f5fce18",
225670          "supplier": {},
225671          "name": "path-key",
225672          "version": "2.0.1",
225673          "licenses": [
225674            {
225675              "license": {
225676                "id": "MIT"
225677              }
225678            }
225679          ],
225680          "cpe": "cpe:2.3:a:path-key:path-key:2.0.1:*:*:*:*:*:*:*",
225681          "purl": "pkg:npm/path-key@2.0.1",
225682          "swid": {
225683            "attachment": {}
225684          },
225685          "pedigree": {},
225686          "evidence": {},
225687          "signature": {
225688            "signature": {
225689              "publicKey": {}
225690            }
225691          },
225692          "modelCard": {
225693            "modelParameters": {
225694              "approach": {}
225695            },
225696            "quantitativeAnalysis": {
225697              "graphics": {}
225698            },
225699            "considerations": {}
225700          }
225701        },
225702        {
225703          "type": "library",
225704          "bom-ref": "pkg:npm/pend@1.2.0?package-id=457fc8a71608ab87",
225705          "supplier": {},
225706          "name": "pend",
225707          "version": "1.2.0",
225708          "licenses": [
225709            {
225710              "license": {
225711                "id": "MIT"
225712              }
225713            }
225714          ],
225715          "cpe": "cpe:2.3:a:pend:pend:1.2.0:*:*:*:*:*:*:*",
225716          "purl": "pkg:npm/pend@1.2.0",
225717          "swid": {
225718            "attachment": {}
225719          },
225720          "pedigree": {},
225721          "evidence": {},
225722          "signature": {
225723            "signature": {
225724              "publicKey": {}
225725            }
225726          },
225727          "modelCard": {
225728            "modelParameters": {
225729              "approach": {}
225730            },
225731            "quantitativeAnalysis": {
225732              "graphics": {}
225733            },
225734            "considerations": {}
225735          }
225736        },
225737        {
225738          "type": "library",
225739          "bom-ref": "pkg:npm/performance-now@2.1.0?package-id=1f9e7e0e96f42aad",
225740          "supplier": {},
225741          "name": "performance-now",
225742          "version": "2.1.0",
225743          "licenses": [
225744            {
225745              "license": {
225746                "id": "MIT"
225747              }
225748            }
225749          ],
225750          "cpe": "cpe:2.3:a:performance-now:performance-now:2.1.0:*:*:*:*:*:*:*",
225751          "purl": "pkg:npm/performance-now@2.1.0",
225752          "swid": {
225753            "attachment": {}
225754          },
225755          "pedigree": {},
225756          "evidence": {},
225757          "signature": {
225758            "signature": {
225759              "publicKey": {}
225760            }
225761          },
225762          "modelCard": {
225763            "modelParameters": {
225764              "approach": {}
225765            },
225766            "quantitativeAnalysis": {
225767              "graphics": {}
225768            },
225769            "considerations": {}
225770          }
225771        },
225772        {
225773          "type": "library",
225774          "bom-ref": "pkg:npm/pg@8.10.0?package-id=fc2d59094476740f",
225775          "supplier": {},
225776          "name": "pg",
225777          "version": "8.10.0",
225778          "licenses": [
225779            {
225780              "license": {
225781                "id": "MIT"
225782              }
225783            }
225784          ],
225785          "cpe": "cpe:2.3:a:pg:pg:8.10.0:*:*:*:*:*:*:*",
225786          "purl": "pkg:npm/pg@8.10.0",
225787          "swid": {
225788            "attachment": {}
225789          },
225790          "pedigree": {},
225791          "evidence": {},
225792          "signature": {
225793            "signature": {
225794              "publicKey": {}
225795            }
225796          },
225797          "modelCard": {
225798            "modelParameters": {
225799              "approach": {}
225800            },
225801            "quantitativeAnalysis": {
225802              "graphics": {}
225803            },
225804            "considerations": {}
225805          }
225806        },
225807        {
225808          "type": "library",
225809          "bom-ref": "pkg:npm/pg-connection-string@2.5.0?package-id=4bf430bf7b355676",
225810          "supplier": {},
225811          "name": "pg-connection-string",
225812          "version": "2.5.0",
225813          "licenses": [
225814            {
225815              "license": {
225816                "id": "MIT"
225817              }
225818            }
225819          ],
225820          "cpe": "cpe:2.3:a:pg-connection-string:pg-connection-string:2.5.0:*:*:*:*:*:*:*",
225821          "purl": "pkg:npm/pg-connection-string@2.5.0",
225822          "swid": {
225823            "attachment": {}
225824          },
225825          "pedigree": {},
225826          "evidence": {},
225827          "signature": {
225828            "signature": {
225829              "publicKey": {}
225830            }
225831          },
225832          "modelCard": {
225833            "modelParameters": {
225834              "approach": {}
225835            },
225836            "quantitativeAnalysis": {
225837              "graphics": {}
225838            },
225839            "considerations": {}
225840          }
225841        },
225842        {
225843          "type": "library",
225844          "bom-ref": "pkg:npm/pg-int8@1.0.1?package-id=5a327a9285807839",
225845          "supplier": {},
225846          "name": "pg-int8",
225847          "version": "1.0.1",
225848          "licenses": [
225849            {
225850              "license": {
225851                "id": "ISC"
225852              }
225853            }
225854          ],
225855          "cpe": "cpe:2.3:a:pg-int8:pg-int8:1.0.1:*:*:*:*:*:*:*",
225856          "purl": "pkg:npm/pg-int8@1.0.1",
225857          "swid": {
225858            "attachment": {}
225859          },
225860          "pedigree": {},
225861          "evidence": {},
225862          "signature": {
225863            "signature": {
225864              "publicKey": {}
225865            }
225866          },
225867          "modelCard": {
225868            "modelParameters": {
225869              "approach": {}
225870            },
225871            "quantitativeAnalysis": {
225872              "graphics": {}
225873            },
225874            "considerations": {}
225875          }
225876        },
225877        {
225878          "type": "library",
225879          "bom-ref": "pkg:npm/pg-pool@3.6.0?package-id=ddd8ac662bde1ee7",
225880          "supplier": {},
225881          "name": "pg-pool",
225882          "version": "3.6.0",
225883          "licenses": [
225884            {
225885              "license": {
225886                "id": "MIT"
225887              }
225888            }
225889          ],
225890          "cpe": "cpe:2.3:a:pg-pool:pg-pool:3.6.0:*:*:*:*:*:*:*",
225891          "purl": "pkg:npm/pg-pool@3.6.0",
225892          "swid": {
225893            "attachment": {}
225894          },
225895          "pedigree": {},
225896          "evidence": {},
225897          "signature": {
225898            "signature": {
225899              "publicKey": {}
225900            }
225901          },
225902          "modelCard": {
225903            "modelParameters": {
225904              "approach": {}
225905            },
225906            "quantitativeAnalysis": {
225907              "graphics": {}
225908            },
225909            "considerations": {}
225910          }
225911        },
225912        {
225913          "type": "library",
225914          "bom-ref": "pkg:npm/pg-protocol@1.6.0?package-id=d0aa079acaaa68db",
225915          "supplier": {},
225916          "name": "pg-protocol",
225917          "version": "1.6.0",
225918          "licenses": [
225919            {
225920              "license": {
225921                "id": "MIT"
225922              }
225923            }
225924          ],
225925          "cpe": "cpe:2.3:a:pg-protocol:pg-protocol:1.6.0:*:*:*:*:*:*:*",
225926          "purl": "pkg:npm/pg-protocol@1.6.0",
225927          "swid": {
225928            "attachment": {}
225929          },
225930          "pedigree": {},
225931          "evidence": {},
225932          "signature": {
225933            "signature": {
225934              "publicKey": {}
225935            }
225936          },
225937          "modelCard": {
225938            "modelParameters": {
225939              "approach": {}
225940            },
225941            "quantitativeAnalysis": {
225942              "graphics": {}
225943            },
225944            "considerations": {}
225945          }
225946        },
225947        {
225948          "type": "library",
225949          "bom-ref": "pkg:npm/pg-types@2.2.0?package-id=c76c4b7121c6ca47",
225950          "supplier": {},
225951          "name": "pg-types",
225952          "version": "2.2.0",
225953          "licenses": [
225954            {
225955              "license": {
225956                "id": "MIT"
225957              }
225958            }
225959          ],
225960          "cpe": "cpe:2.3:a:pg-types:pg-types:2.2.0:*:*:*:*:*:*:*",
225961          "purl": "pkg:npm/pg-types@2.2.0",
225962          "swid": {
225963            "attachment": {}
225964          },
225965          "pedigree": {},
225966          "evidence": {},
225967          "signature": {
225968            "signature": {
225969              "publicKey": {}
225970            }
225971          },
225972          "modelCard": {
225973            "modelParameters": {
225974              "approach": {}
225975            },
225976            "quantitativeAnalysis": {
225977              "graphics": {}
225978            },
225979            "considerations": {}
225980          }
225981        },
225982        {
225983          "type": "library",
225984          "bom-ref": "pkg:npm/pgpass@1.0.5?package-id=59fefb3e80424722",
225985          "supplier": {},
225986          "name": "pgpass",
225987          "version": "1.0.5",
225988          "licenses": [
225989            {
225990              "license": {
225991                "id": "MIT"
225992              }
225993            }
225994          ],
225995          "cpe": "cpe:2.3:a:pgpass:pgpass:1.0.5:*:*:*:*:*:*:*",
225996          "purl": "pkg:npm/pgpass@1.0.5",
225997          "swid": {
225998            "attachment": {}
225999          },
226000          "pedigree": {},
226001          "evidence": {},
226002          "signature": {
226003            "signature": {
226004              "publicKey": {}
226005            }
226006          },
226007          "modelCard": {
226008            "modelParameters": {
226009              "approach": {}
226010            },
226011            "quantitativeAnalysis": {
226012              "graphics": {}
226013            },
226014            "considerations": {}
226015          }
226016        },
226017        {
226018          "type": "library",
226019          "bom-ref": "pkg:npm/pify@2.3.0?package-id=55b205bbcedd5fa",
226020          "supplier": {},
226021          "name": "pify",
226022          "version": "2.3.0",
226023          "licenses": [
226024            {
226025              "license": {
226026                "id": "MIT"
226027              }
226028            }
226029          ],
226030          "cpe": "cpe:2.3:a:pify:pify:2.3.0:*:*:*:*:*:*:*",
226031          "purl": "pkg:npm/pify@2.3.0",
226032          "swid": {
226033            "attachment": {}
226034          },
226035          "pedigree": {},
226036          "evidence": {},
226037          "signature": {
226038            "signature": {
226039              "publicKey": {}
226040            }
226041          },
226042          "modelCard": {
226043            "modelParameters": {
226044              "approach": {}
226045            },
226046            "quantitativeAnalysis": {
226047              "graphics": {}
226048            },
226049            "considerations": {}
226050          }
226051        },
226052        {
226053          "type": "library",
226054          "bom-ref": "pkg:npm/ping@0.2.3?package-id=2a119b2683893b01",
226055          "supplier": {},
226056          "name": "ping",
226057          "version": "0.2.3",
226058          "licenses": [
226059            {
226060              "license": {
226061                "id": "MIT"
226062              }
226063            }
226064          ],
226065          "cpe": "cpe:2.3:a:ping:ping:0.2.3:*:*:*:*:*:*:*",
226066          "purl": "pkg:npm/ping@0.2.3",
226067          "swid": {
226068            "attachment": {}
226069          },
226070          "pedigree": {},
226071          "evidence": {},
226072          "signature": {
226073            "signature": {
226074              "publicKey": {}
226075            }
226076          },
226077          "modelCard": {
226078            "modelParameters": {
226079              "approach": {}
226080            },
226081            "quantitativeAnalysis": {
226082              "graphics": {}
226083            },
226084            "considerations": {}
226085          }
226086        },
226087        {
226088          "type": "library",
226089          "bom-ref": "pkg:npm/pinkie@2.0.4?package-id=b7c6ded513ccb743",
226090          "supplier": {},
226091          "name": "pinkie",
226092          "version": "2.0.4",
226093          "licenses": [
226094            {
226095              "license": {
226096                "id": "MIT"
226097              }
226098            }
226099          ],
226100          "cpe": "cpe:2.3:a:pinkie:pinkie:2.0.4:*:*:*:*:*:*:*",
226101          "purl": "pkg:npm/pinkie@2.0.4",
226102          "swid": {
226103            "attachment": {}
226104          },
226105          "pedigree": {},
226106          "evidence": {},
226107          "signature": {
226108            "signature": {
226109              "publicKey": {}
226110            }
226111          },
226112          "modelCard": {
226113            "modelParameters": {
226114              "approach": {}
226115            },
226116            "quantitativeAnalysis": {
226117              "graphics": {}
226118            },
226119            "considerations": {}
226120          }
226121        },
226122        {
226123          "type": "library",
226124          "bom-ref": "pkg:npm/pinkie-promise@2.0.1?package-id=645c9d6e7d684f97",
226125          "supplier": {},
226126          "name": "pinkie-promise",
226127          "version": "2.0.1",
226128          "licenses": [
226129            {
226130              "license": {
226131                "id": "MIT"
226132              }
226133            }
226134          ],
226135          "cpe": "cpe:2.3:a:pinkie-promise:pinkie-promise:2.0.1:*:*:*:*:*:*:*",
226136          "purl": "pkg:npm/pinkie-promise@2.0.1",
226137          "swid": {
226138            "attachment": {}
226139          },
226140          "pedigree": {},
226141          "evidence": {},
226142          "signature": {
226143            "signature": {
226144              "publicKey": {}
226145            }
226146          },
226147          "modelCard": {
226148            "modelParameters": {
226149              "approach": {}
226150            },
226151            "quantitativeAnalysis": {
226152              "graphics": {}
226153            },
226154            "considerations": {}
226155          }
226156        },
226157        {
226158          "type": "library",
226159          "bom-ref": "pkg:npm/postgres-array@2.0.0?package-id=a3ddeef146982962",
226160          "supplier": {},
226161          "name": "postgres-array",
226162          "version": "2.0.0",
226163          "licenses": [
226164            {
226165              "license": {
226166                "id": "MIT"
226167              }
226168            }
226169          ],
226170          "cpe": "cpe:2.3:a:postgres-array:postgres-array:2.0.0:*:*:*:*:*:*:*",
226171          "purl": "pkg:npm/postgres-array@2.0.0",
226172          "swid": {
226173            "attachment": {}
226174          },
226175          "pedigree": {},
226176          "evidence": {},
226177          "signature": {
226178            "signature": {
226179              "publicKey": {}
226180            }
226181          },
226182          "modelCard": {
226183            "modelParameters": {
226184              "approach": {}
226185            },
226186            "quantitativeAnalysis": {
226187              "graphics": {}
226188            },
226189            "considerations": {}
226190          }
226191        },
226192        {
226193          "type": "library",
226194          "bom-ref": "pkg:npm/postgres-bytea@1.0.0?package-id=cd979817d491b54f",
226195          "supplier": {},
226196          "name": "postgres-bytea",
226197          "version": "1.0.0",
226198          "licenses": [
226199            {
226200              "license": {
226201                "id": "MIT"
226202              }
226203            }
226204          ],
226205          "cpe": "cpe:2.3:a:postgres-bytea:postgres-bytea:1.0.0:*:*:*:*:*:*:*",
226206          "purl": "pkg:npm/postgres-bytea@1.0.0",
226207          "swid": {
226208            "attachment": {}
226209          },
226210          "pedigree": {},
226211          "evidence": {},
226212          "signature": {
226213            "signature": {
226214              "publicKey": {}
226215            }
226216          },
226217          "modelCard": {
226218            "modelParameters": {
226219              "approach": {}
226220            },
226221            "quantitativeAnalysis": {
226222              "graphics": {}
226223            },
226224            "considerations": {}
226225          }
226226        },
226227        {
226228          "type": "library",
226229          "bom-ref": "pkg:npm/postgres-date@1.0.7?package-id=14947a9420346c64",
226230          "supplier": {},
226231          "name": "postgres-date",
226232          "version": "1.0.7",
226233          "licenses": [
226234            {
226235              "license": {
226236                "id": "MIT"
226237              }
226238            }
226239          ],
226240          "cpe": "cpe:2.3:a:postgres-date:postgres-date:1.0.7:*:*:*:*:*:*:*",
226241          "purl": "pkg:npm/postgres-date@1.0.7",
226242          "swid": {
226243            "attachment": {}
226244          },
226245          "pedigree": {},
226246          "evidence": {},
226247          "signature": {
226248            "signature": {
226249              "publicKey": {}
226250            }
226251          },
226252          "modelCard": {
226253            "modelParameters": {
226254              "approach": {}
226255            },
226256            "quantitativeAnalysis": {
226257              "graphics": {}
226258            },
226259            "considerations": {}
226260          }
226261        },
226262        {
226263          "type": "library",
226264          "bom-ref": "pkg:npm/postgres-interval@1.2.0?package-id=3427cc0fa2dbad52",
226265          "supplier": {},
226266          "name": "postgres-interval",
226267          "version": "1.2.0",
226268          "licenses": [
226269            {
226270              "license": {
226271                "id": "MIT"
226272              }
226273            }
226274          ],
226275          "cpe": "cpe:2.3:a:postgres-interval:postgres-interval:1.2.0:*:*:*:*:*:*:*",
226276          "purl": "pkg:npm/postgres-interval@1.2.0",
226277          "swid": {
226278            "attachment": {}
226279          },
226280          "pedigree": {},
226281          "evidence": {},
226282          "signature": {
226283            "signature": {
226284              "publicKey": {}
226285            }
226286          },
226287          "modelCard": {
226288            "modelParameters": {
226289              "approach": {}
226290            },
226291            "quantitativeAnalysis": {
226292              "graphics": {}
226293            },
226294            "considerations": {}
226295          }
226296        },
226297        {
226298          "type": "library",
226299          "bom-ref": "pkg:npm/prebuild-install@7.1.1?package-id=26826962b14e8ff",
226300          "supplier": {},
226301          "name": "prebuild-install",
226302          "version": "7.1.1",
226303          "licenses": [
226304            {
226305              "license": {
226306                "id": "MIT"
226307              }
226308            }
226309          ],
226310          "cpe": "cpe:2.3:a:prebuild-install:prebuild-install:7.1.1:*:*:*:*:*:*:*",
226311          "purl": "pkg:npm/prebuild-install@7.1.1",
226312          "swid": {
226313            "attachment": {}
226314          },
226315          "pedigree": {},
226316          "evidence": {},
226317          "signature": {
226318            "signature": {
226319              "publicKey": {}
226320            }
226321          },
226322          "modelCard": {
226323            "modelParameters": {
226324              "approach": {}
226325            },
226326            "quantitativeAnalysis": {
226327              "graphics": {}
226328            },
226329            "considerations": {}
226330          }
226331        },
226332        {
226333          "type": "library",
226334          "bom-ref": "pkg:npm/precond@0.2.3?package-id=31f5729c7ac244df",
226335          "supplier": {},
226336          "name": "precond",
226337          "version": "0.2.3",
226338          "cpe": "cpe:2.3:a:precond:precond:0.2.3:*:*:*:*:*:*:*",
226339          "purl": "pkg:npm/precond@0.2.3",
226340          "swid": {
226341            "attachment": {}
226342          },
226343          "pedigree": {},
226344          "evidence": {},
226345          "signature": {
226346            "signature": {
226347              "publicKey": {}
226348            }
226349          },
226350          "modelCard": {
226351            "modelParameters": {
226352              "approach": {}
226353            },
226354            "quantitativeAnalysis": {
226355              "graphics": {}
226356            },
226357            "considerations": {}
226358          }
226359        },
226360        {
226361          "type": "library",
226362          "bom-ref": "pkg:npm/prepend-http@1.0.4?package-id=ca566c6220af4ac",
226363          "supplier": {},
226364          "name": "prepend-http",
226365          "version": "1.0.4",
226366          "licenses": [
226367            {
226368              "license": {
226369                "id": "MIT"
226370              }
226371            }
226372          ],
226373          "cpe": "cpe:2.3:a:prepend-http:prepend-http:1.0.4:*:*:*:*:*:*:*",
226374          "purl": "pkg:npm/prepend-http@1.0.4",
226375          "swid": {
226376            "attachment": {}
226377          },
226378          "pedigree": {},
226379          "evidence": {},
226380          "signature": {
226381            "signature": {
226382              "publicKey": {}
226383            }
226384          },
226385          "modelCard": {
226386            "modelParameters": {
226387              "approach": {}
226388            },
226389            "quantitativeAnalysis": {
226390              "graphics": {}
226391            },
226392            "considerations": {}
226393          }
226394        },
226395        {
226396          "type": "library",
226397          "bom-ref": "pkg:npm/process-nextick-args@2.0.1?package-id=c28603c1f456c61",
226398          "supplier": {},
226399          "name": "process-nextick-args",
226400          "version": "2.0.1",
226401          "licenses": [
226402            {
226403              "license": {
226404                "id": "MIT"
226405              }
226406            }
226407          ],
226408          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.1:*:*:*:*:*:*:*",
226409          "purl": "pkg:npm/process-nextick-args@2.0.1",
226410          "swid": {
226411            "attachment": {}
226412          },
226413          "pedigree": {},
226414          "evidence": {},
226415          "signature": {
226416            "signature": {
226417              "publicKey": {}
226418            }
226419          },
226420          "modelCard": {
226421            "modelParameters": {
226422              "approach": {}
226423            },
226424            "quantitativeAnalysis": {
226425              "graphics": {}
226426            },
226427            "considerations": {}
226428          }
226429        },
226430        {
226431          "type": "library",
226432          "bom-ref": "pkg:npm/promise-retry@2.0.1?package-id=5329cfb28c9e58ba",
226433          "supplier": {},
226434          "name": "promise-retry",
226435          "version": "2.0.1",
226436          "licenses": [
226437            {
226438              "license": {
226439                "id": "MIT"
226440              }
226441            }
226442          ],
226443          "cpe": "cpe:2.3:a:promise-retry:promise-retry:2.0.1:*:*:*:*:*:*:*",
226444          "purl": "pkg:npm/promise-retry@2.0.1",
226445          "swid": {
226446            "attachment": {}
226447          },
226448          "pedigree": {},
226449          "evidence": {},
226450          "signature": {
226451            "signature": {
226452              "publicKey": {}
226453            }
226454          },
226455          "modelCard": {
226456            "modelParameters": {
226457              "approach": {}
226458            },
226459            "quantitativeAnalysis": {
226460              "graphics": {}
226461            },
226462            "considerations": {}
226463          }
226464        },
226465        {
226466          "type": "library",
226467          "bom-ref": "pkg:npm/proto-list@1.2.4?package-id=d44eb14fee08fca8",
226468          "supplier": {},
226469          "name": "proto-list",
226470          "version": "1.2.4",
226471          "licenses": [
226472            {
226473              "license": {
226474                "id": "ISC"
226475              }
226476            }
226477          ],
226478          "cpe": "cpe:2.3:a:proto-list:proto-list:1.2.4:*:*:*:*:*:*:*",
226479          "purl": "pkg:npm/proto-list@1.2.4",
226480          "swid": {
226481            "attachment": {}
226482          },
226483          "pedigree": {},
226484          "evidence": {},
226485          "signature": {
226486            "signature": {
226487              "publicKey": {}
226488            }
226489          },
226490          "modelCard": {
226491            "modelParameters": {
226492              "approach": {}
226493            },
226494            "quantitativeAnalysis": {
226495              "graphics": {}
226496            },
226497            "considerations": {}
226498          }
226499        },
226500        {
226501          "type": "library",
226502          "bom-ref": "pkg:npm/pseudomap@1.0.2?package-id=43d1566857e4decb",
226503          "supplier": {},
226504          "name": "pseudomap",
226505          "version": "1.0.2",
226506          "licenses": [
226507            {
226508              "license": {
226509                "id": "ISC"
226510              }
226511            }
226512          ],
226513          "cpe": "cpe:2.3:a:pseudomap:pseudomap:1.0.2:*:*:*:*:*:*:*",
226514          "purl": "pkg:npm/pseudomap@1.0.2",
226515          "swid": {
226516            "attachment": {}
226517          },
226518          "pedigree": {},
226519          "evidence": {},
226520          "signature": {
226521            "signature": {
226522              "publicKey": {}
226523            }
226524          },
226525          "modelCard": {
226526            "modelParameters": {
226527              "approach": {}
226528            },
226529            "quantitativeAnalysis": {
226530              "graphics": {}
226531            },
226532            "considerations": {}
226533          }
226534        },
226535        {
226536          "type": "library",
226537          "bom-ref": "pkg:npm/psl@1.1.31?package-id=587802c2922e454c",
226538          "supplier": {},
226539          "name": "psl",
226540          "version": "1.1.31",
226541          "licenses": [
226542            {
226543              "license": {
226544                "id": "MIT"
226545              }
226546            }
226547          ],
226548          "cpe": "cpe:2.3:a:psl:psl:1.1.31:*:*:*:*:*:*:*",
226549          "purl": "pkg:npm/psl@1.1.31",
226550          "swid": {
226551            "attachment": {}
226552          },
226553          "pedigree": {},
226554          "evidence": {},
226555          "signature": {
226556            "signature": {
226557              "publicKey": {}
226558            }
226559          },
226560          "modelCard": {
226561            "modelParameters": {
226562              "approach": {}
226563            },
226564            "quantitativeAnalysis": {
226565              "graphics": {}
226566            },
226567            "considerations": {}
226568          }
226569        },
226570        {
226571          "type": "library",
226572          "bom-ref": "pkg:npm/pump@3.0.0?package-id=da201e2347bcef10",
226573          "supplier": {},
226574          "name": "pump",
226575          "version": "3.0.0",
226576          "licenses": [
226577            {
226578              "license": {
226579                "id": "MIT"
226580              }
226581            }
226582          ],
226583          "cpe": "cpe:2.3:a:pump:pump:3.0.0:*:*:*:*:*:*:*",
226584          "purl": "pkg:npm/pump@3.0.0",
226585          "swid": {
226586            "attachment": {}
226587          },
226588          "pedigree": {},
226589          "evidence": {},
226590          "signature": {
226591            "signature": {
226592              "publicKey": {}
226593            }
226594          },
226595          "modelCard": {
226596            "modelParameters": {
226597              "approach": {}
226598            },
226599            "quantitativeAnalysis": {
226600              "graphics": {}
226601            },
226602            "considerations": {}
226603          }
226604        },
226605        {
226606          "type": "library",
226607          "bom-ref": "pkg:npm/punycode@2.1.1?package-id=54ff6dfd577aea1f",
226608          "supplier": {},
226609          "name": "punycode",
226610          "version": "2.1.1",
226611          "licenses": [
226612            {
226613              "license": {
226614                "id": "MIT"
226615              }
226616            }
226617          ],
226618          "cpe": "cpe:2.3:a:punycode:punycode:2.1.1:*:*:*:*:*:*:*",
226619          "purl": "pkg:npm/punycode@2.1.1",
226620          "swid": {
226621            "attachment": {}
226622          },
226623          "pedigree": {},
226624          "evidence": {},
226625          "signature": {
226626            "signature": {
226627              "publicKey": {}
226628            }
226629          },
226630          "modelCard": {
226631            "modelParameters": {
226632              "approach": {}
226633            },
226634            "quantitativeAnalysis": {
226635              "graphics": {}
226636            },
226637            "considerations": {}
226638          }
226639        },
226640        {
226641          "type": "library",
226642          "bom-ref": "pkg:npm/q@1.5.1?package-id=6443ea5109bfc613",
226643          "supplier": {},
226644          "name": "q",
226645          "version": "1.5.1",
226646          "licenses": [
226647            {
226648              "license": {
226649                "id": "MIT"
226650              }
226651            }
226652          ],
226653          "cpe": "cpe:2.3:a:q:q:1.5.1:*:*:*:*:*:*:*",
226654          "purl": "pkg:npm/q@1.5.1",
226655          "swid": {
226656            "attachment": {}
226657          },
226658          "pedigree": {},
226659          "evidence": {},
226660          "signature": {
226661            "signature": {
226662              "publicKey": {}
226663            }
226664          },
226665          "modelCard": {
226666            "modelParameters": {
226667              "approach": {}
226668            },
226669            "quantitativeAnalysis": {
226670              "graphics": {}
226671            },
226672            "considerations": {}
226673          }
226674        },
226675        {
226676          "type": "library",
226677          "bom-ref": "pkg:npm/qs@6.11.1?package-id=c0e55e334ae8dd79",
226678          "supplier": {},
226679          "name": "qs",
226680          "version": "6.11.1",
226681          "licenses": [
226682            {
226683              "license": {
226684                "id": "BSD-3-Clause"
226685              }
226686            }
226687          ],
226688          "cpe": "cpe:2.3:a:qs:qs:6.11.1:*:*:*:*:*:*:*",
226689          "purl": "pkg:npm/qs@6.11.1",
226690          "swid": {
226691            "attachment": {}
226692          },
226693          "pedigree": {},
226694          "evidence": {},
226695          "signature": {
226696            "signature": {
226697              "publicKey": {}
226698            }
226699          },
226700          "modelCard": {
226701            "modelParameters": {
226702              "approach": {}
226703            },
226704            "quantitativeAnalysis": {
226705              "graphics": {}
226706            },
226707            "considerations": {}
226708          }
226709        },
226710        {
226711          "type": "library",
226712          "bom-ref": "pkg:npm/querystringify@2.2.0?package-id=24597ee2fc0e08d3",
226713          "supplier": {},
226714          "name": "querystringify",
226715          "version": "2.2.0",
226716          "licenses": [
226717            {
226718              "license": {
226719                "id": "MIT"
226720              }
226721            }
226722          ],
226723          "cpe": "cpe:2.3:a:querystringify:querystringify:2.2.0:*:*:*:*:*:*:*",
226724          "purl": "pkg:npm/querystringify@2.2.0",
226725          "swid": {
226726            "attachment": {}
226727          },
226728          "pedigree": {},
226729          "evidence": {},
226730          "signature": {
226731            "signature": {
226732              "publicKey": {}
226733            }
226734          },
226735          "modelCard": {
226736            "modelParameters": {
226737              "approach": {}
226738            },
226739            "quantitativeAnalysis": {
226740              "graphics": {}
226741            },
226742            "considerations": {}
226743          }
226744        },
226745        {
226746          "type": "library",
226747          "bom-ref": "pkg:npm/rc@1.2.8?package-id=480cef8701bbb78f",
226748          "supplier": {},
226749          "name": "rc",
226750          "version": "1.2.8",
226751          "licenses": [
226752            {
226753              "license": {
226754                "name": "(BSD-2-Clause OR MIT OR Apache-2.0)"
226755              }
226756            }
226757          ],
226758          "cpe": "cpe:2.3:a:rc:rc:1.2.8:*:*:*:*:*:*:*",
226759          "purl": "pkg:npm/rc@1.2.8",
226760          "swid": {
226761            "attachment": {}
226762          },
226763          "pedigree": {},
226764          "evidence": {},
226765          "signature": {
226766            "signature": {
226767              "publicKey": {}
226768            }
226769          },
226770          "modelCard": {
226771            "modelParameters": {
226772              "approach": {}
226773            },
226774            "quantitativeAnalysis": {
226775              "graphics": {}
226776            },
226777            "considerations": {}
226778          }
226779        },
226780        {
226781          "type": "library",
226782          "bom-ref": "pkg:npm/readable-stream@1.1.14?package-id=497e418df5c500b1",
226783          "supplier": {},
226784          "name": "readable-stream",
226785          "version": "1.1.14",
226786          "licenses": [
226787            {
226788              "license": {
226789                "id": "MIT"
226790              }
226791            }
226792          ],
226793          "cpe": "cpe:2.3:a:readable-stream:readable-stream:1.1.14:*:*:*:*:*:*:*",
226794          "purl": "pkg:npm/readable-stream@1.1.14",
226795          "swid": {
226796            "attachment": {}
226797          },
226798          "pedigree": {},
226799          "evidence": {},
226800          "signature": {
226801            "signature": {
226802              "publicKey": {}
226803            }
226804          },
226805          "modelCard": {
226806            "modelParameters": {
226807              "approach": {}
226808            },
226809            "quantitativeAnalysis": {
226810              "graphics": {}
226811            },
226812            "considerations": {}
226813          }
226814        },
226815        {
226816          "type": "library",
226817          "bom-ref": "pkg:npm/readdir-glob@1.1.3?package-id=fc4fe9d8037b845",
226818          "supplier": {},
226819          "name": "readdir-glob",
226820          "version": "1.1.3",
226821          "licenses": [
226822            {
226823              "license": {
226824                "id": "Apache-2.0"
226825              }
226826            }
226827          ],
226828          "cpe": "cpe:2.3:a:readdir-glob:readdir-glob:1.1.3:*:*:*:*:*:*:*",
226829          "purl": "pkg:npm/readdir-glob@1.1.3",
226830          "swid": {
226831            "attachment": {}
226832          },
226833          "pedigree": {},
226834          "evidence": {},
226835          "signature": {
226836            "signature": {
226837              "publicKey": {}
226838            }
226839          },
226840          "modelCard": {
226841            "modelParameters": {
226842              "approach": {}
226843            },
226844            "quantitativeAnalysis": {
226845              "graphics": {}
226846            },
226847            "considerations": {}
226848          }
226849        },
226850        {
226851          "type": "library",
226852          "bom-ref": "pkg:npm/reinterval@1.1.0?package-id=45a3d0f86d261b67",
226853          "supplier": {},
226854          "name": "reinterval",
226855          "version": "1.1.0",
226856          "licenses": [
226857            {
226858              "license": {
226859                "id": "MIT"
226860              }
226861            }
226862          ],
226863          "cpe": "cpe:2.3:a:reinterval:reinterval:1.1.0:*:*:*:*:*:*:*",
226864          "purl": "pkg:npm/reinterval@1.1.0",
226865          "swid": {
226866            "attachment": {}
226867          },
226868          "pedigree": {},
226869          "evidence": {},
226870          "signature": {
226871            "signature": {
226872              "publicKey": {}
226873            }
226874          },
226875          "modelCard": {
226876            "modelParameters": {
226877              "approach": {}
226878            },
226879            "quantitativeAnalysis": {
226880              "graphics": {}
226881            },
226882            "considerations": {}
226883          }
226884        },
226885        {
226886          "type": "library",
226887          "bom-ref": "pkg:npm/remedial@1.0.8?package-id=4460d0f4af3fbabb",
226888          "supplier": {},
226889          "name": "remedial",
226890          "version": "1.0.8",
226891          "licenses": [
226892            {
226893              "license": {
226894                "name": "(MIT OR Apache-2.0)"
226895              }
226896            }
226897          ],
226898          "cpe": "cpe:2.3:a:remedial:remedial:1.0.8:*:*:*:*:*:*:*",
226899          "purl": "pkg:npm/remedial@1.0.8",
226900          "swid": {
226901            "attachment": {}
226902          },
226903          "pedigree": {},
226904          "evidence": {},
226905          "signature": {
226906            "signature": {
226907              "publicKey": {}
226908            }
226909          },
226910          "modelCard": {
226911            "modelParameters": {
226912              "approach": {}
226913            },
226914            "quantitativeAnalysis": {
226915              "graphics": {}
226916            },
226917            "considerations": {}
226918          }
226919        },
226920        {
226921          "type": "library",
226922          "bom-ref": "pkg:npm/remove-trailing-spaces@1.0.8?package-id=d62246009db91041",
226923          "supplier": {},
226924          "name": "remove-trailing-spaces",
226925          "version": "1.0.8",
226926          "licenses": [
226927            {
226928              "license": {
226929                "id": "MIT"
226930              }
226931            }
226932          ],
226933          "cpe": "cpe:2.3:a:remove-trailing-spaces:remove-trailing-spaces:1.0.8:*:*:*:*:*:*:*",
226934          "purl": "pkg:npm/remove-trailing-spaces@1.0.8",
226935          "swid": {
226936            "attachment": {}
226937          },
226938          "pedigree": {},
226939          "evidence": {},
226940          "signature": {
226941            "signature": {
226942              "publicKey": {}
226943            }
226944          },
226945          "modelCard": {
226946            "modelParameters": {
226947              "approach": {}
226948            },
226949            "quantitativeAnalysis": {
226950              "graphics": {}
226951            },
226952            "considerations": {}
226953          }
226954        },
226955        {
226956          "type": "library",
226957          "bom-ref": "pkg:npm/request@2.88.0?package-id=e5c87bb07668db7d",
226958          "supplier": {},
226959          "name": "request",
226960          "version": "2.88.0",
226961          "licenses": [
226962            {
226963              "license": {
226964                "id": "Apache-2.0"
226965              }
226966            }
226967          ],
226968          "cpe": "cpe:2.3:a:request:request:2.88.0:*:*:*:*:*:*:*",
226969          "purl": "pkg:npm/request@2.88.0",
226970          "swid": {
226971            "attachment": {}
226972          },
226973          "pedigree": {},
226974          "evidence": {},
226975          "signature": {
226976            "signature": {
226977              "publicKey": {}
226978            }
226979          },
226980          "modelCard": {
226981            "modelParameters": {
226982              "approach": {}
226983            },
226984            "quantitativeAnalysis": {
226985              "graphics": {}
226986            },
226987            "considerations": {}
226988          }
226989        },
226990        {
226991          "type": "library",
226992          "bom-ref": "pkg:npm/request-promise@4.2.2?package-id=6261d3476fe7f423",
226993          "supplier": {},
226994          "name": "request-promise",
226995          "version": "4.2.2",
226996          "licenses": [
226997            {
226998              "license": {
226999                "id": "ISC"
227000              }
227001            }
227002          ],
227003          "cpe": "cpe:2.3:a:request-promise:request-promise:4.2.2:*:*:*:*:*:*:*",
227004          "purl": "pkg:npm/request-promise@4.2.2",
227005          "swid": {
227006            "attachment": {}
227007          },
227008          "pedigree": {},
227009          "evidence": {},
227010          "signature": {
227011            "signature": {
227012              "publicKey": {}
227013            }
227014          },
227015          "modelCard": {
227016            "modelParameters": {
227017              "approach": {}
227018            },
227019            "quantitativeAnalysis": {
227020              "graphics": {}
227021            },
227022            "considerations": {}
227023          }
227024        },
227025        {
227026          "type": "library",
227027          "bom-ref": "pkg:npm/request-promise-core@1.1.2?package-id=9e616d7cb63a8a71",
227028          "supplier": {},
227029          "name": "request-promise-core",
227030          "version": "1.1.2",
227031          "licenses": [
227032            {
227033              "license": {
227034                "id": "ISC"
227035              }
227036            }
227037          ],
227038          "cpe": "cpe:2.3:a:request-promise-core:request-promise-core:1.1.2:*:*:*:*:*:*:*",
227039          "purl": "pkg:npm/request-promise-core@1.1.2",
227040          "swid": {
227041            "attachment": {}
227042          },
227043          "pedigree": {},
227044          "evidence": {},
227045          "signature": {
227046            "signature": {
227047              "publicKey": {}
227048            }
227049          },
227050          "modelCard": {
227051            "modelParameters": {
227052              "approach": {}
227053            },
227054            "quantitativeAnalysis": {
227055              "graphics": {}
227056            },
227057            "considerations": {}
227058          }
227059        },
227060        {
227061          "type": "library",
227062          "bom-ref": "pkg:npm/request-promise-native@1.0.7?package-id=edbdd862a90272b3",
227063          "supplier": {},
227064          "name": "request-promise-native",
227065          "version": "1.0.7",
227066          "licenses": [
227067            {
227068              "license": {
227069                "id": "ISC"
227070              }
227071            }
227072          ],
227073          "cpe": "cpe:2.3:a:request-promise-native:request-promise-native:1.0.7:*:*:*:*:*:*:*",
227074          "purl": "pkg:npm/request-promise-native@1.0.7",
227075          "swid": {
227076            "attachment": {}
227077          },
227078          "pedigree": {},
227079          "evidence": {},
227080          "signature": {
227081            "signature": {
227082              "publicKey": {}
227083            }
227084          },
227085          "modelCard": {
227086            "modelParameters": {
227087              "approach": {}
227088            },
227089            "quantitativeAnalysis": {
227090              "graphics": {}
227091            },
227092            "considerations": {}
227093          }
227094        },
227095        {
227096          "type": "library",
227097          "bom-ref": "pkg:npm/require-directory@2.1.1?package-id=b8a78b7c52ddce8a",
227098          "supplier": {},
227099          "name": "require-directory",
227100          "version": "2.1.1",
227101          "licenses": [
227102            {
227103              "license": {
227104                "id": "MIT"
227105              }
227106            }
227107          ],
227108          "cpe": "cpe:2.3:a:require-directory:require-directory:2.1.1:*:*:*:*:*:*:*",
227109          "purl": "pkg:npm/require-directory@2.1.1",
227110          "swid": {
227111            "attachment": {}
227112          },
227113          "pedigree": {},
227114          "evidence": {},
227115          "signature": {
227116            "signature": {
227117              "publicKey": {}
227118            }
227119          },
227120          "modelCard": {
227121            "modelParameters": {
227122              "approach": {}
227123            },
227124            "quantitativeAnalysis": {
227125              "graphics": {}
227126            },
227127            "considerations": {}
227128          }
227129        },
227130        {
227131          "type": "library",
227132          "bom-ref": "pkg:npm/require-from-string@1.2.1?package-id=5fae4181be224cf7",
227133          "supplier": {},
227134          "name": "require-from-string",
227135          "version": "1.2.1",
227136          "licenses": [
227137            {
227138              "license": {
227139                "id": "MIT"
227140              }
227141            }
227142          ],
227143          "cpe": "cpe:2.3:a:require-from-string:require-from-string:1.2.1:*:*:*:*:*:*:*",
227144          "purl": "pkg:npm/require-from-string@1.2.1",
227145          "swid": {
227146            "attachment": {}
227147          },
227148          "pedigree": {},
227149          "evidence": {},
227150          "signature": {
227151            "signature": {
227152              "publicKey": {}
227153            }
227154          },
227155          "modelCard": {
227156            "modelParameters": {
227157              "approach": {}
227158            },
227159            "quantitativeAnalysis": {
227160              "graphics": {}
227161            },
227162            "considerations": {}
227163          }
227164        },
227165        {
227166          "type": "library",
227167          "bom-ref": "pkg:npm/require_optional@1.0.1?package-id=66249e18c6fbe4fb",
227168          "supplier": {},
227169          "name": "require_optional",
227170          "version": "1.0.1",
227171          "licenses": [
227172            {
227173              "license": {
227174                "id": "Apache-2.0"
227175              }
227176            }
227177          ],
227178          "cpe": "cpe:2.3:a:require-optional:require-optional:1.0.1:*:*:*:*:*:*:*",
227179          "purl": "pkg:npm/require_optional@1.0.1",
227180          "swid": {
227181            "attachment": {}
227182          },
227183          "pedigree": {},
227184          "evidence": {},
227185          "signature": {
227186            "signature": {
227187              "publicKey": {}
227188            }
227189          },
227190          "modelCard": {
227191            "modelParameters": {
227192              "approach": {}
227193            },
227194            "quantitativeAnalysis": {
227195              "graphics": {}
227196            },
227197            "considerations": {}
227198          }
227199        },
227200        {
227201          "type": "library",
227202          "bom-ref": "pkg:npm/requires-port@1.0.0?package-id=6a273325b79a1db9",
227203          "supplier": {},
227204          "name": "requires-port",
227205          "version": "1.0.0",
227206          "licenses": [
227207            {
227208              "license": {
227209                "id": "MIT"
227210              }
227211            }
227212          ],
227213          "cpe": "cpe:2.3:a:requires-port:requires-port:1.0.0:*:*:*:*:*:*:*",
227214          "purl": "pkg:npm/requires-port@1.0.0",
227215          "swid": {
227216            "attachment": {}
227217          },
227218          "pedigree": {},
227219          "evidence": {},
227220          "signature": {
227221            "signature": {
227222              "publicKey": {}
227223            }
227224          },
227225          "modelCard": {
227226            "modelParameters": {
227227              "approach": {}
227228            },
227229            "quantitativeAnalysis": {
227230              "graphics": {}
227231            },
227232            "considerations": {}
227233          }
227234        },
227235        {
227236          "type": "library",
227237          "bom-ref": "pkg:npm/resolve-from@2.0.0?package-id=bb677a96dd4fadb5",
227238          "supplier": {},
227239          "name": "resolve-from",
227240          "version": "2.0.0",
227241          "licenses": [
227242            {
227243              "license": {
227244                "id": "MIT"
227245              }
227246            }
227247          ],
227248          "cpe": "cpe:2.3:a:resolve-from:resolve-from:2.0.0:*:*:*:*:*:*:*",
227249          "purl": "pkg:npm/resolve-from@2.0.0",
227250          "swid": {
227251            "attachment": {}
227252          },
227253          "pedigree": {},
227254          "evidence": {},
227255          "signature": {
227256            "signature": {
227257              "publicKey": {}
227258            }
227259          },
227260          "modelCard": {
227261            "modelParameters": {
227262              "approach": {}
227263            },
227264            "quantitativeAnalysis": {
227265              "graphics": {}
227266            },
227267            "considerations": {}
227268          }
227269        },
227270        {
227271          "type": "library",
227272          "bom-ref": "pkg:npm/retry@0.12.0?package-id=1dfb175092fbc68",
227273          "supplier": {},
227274          "name": "retry",
227275          "version": "0.12.0",
227276          "licenses": [
227277            {
227278              "license": {
227279                "id": "MIT"
227280              }
227281            }
227282          ],
227283          "cpe": "cpe:2.3:a:retry:retry:0.12.0:*:*:*:*:*:*:*",
227284          "purl": "pkg:npm/retry@0.12.0",
227285          "swid": {
227286            "attachment": {}
227287          },
227288          "pedigree": {},
227289          "evidence": {},
227290          "signature": {
227291            "signature": {
227292              "publicKey": {}
227293            }
227294          },
227295          "modelCard": {
227296            "modelParameters": {
227297              "approach": {}
227298            },
227299            "quantitativeAnalysis": {
227300              "graphics": {}
227301            },
227302            "considerations": {}
227303          }
227304        },
227305        {
227306          "type": "library",
227307          "bom-ref": "pkg:npm/rfdc@1.3.0?package-id=81a08e2c21f173d9",
227308          "supplier": {},
227309          "name": "rfdc",
227310          "version": "1.3.0",
227311          "licenses": [
227312            {
227313              "license": {
227314                "id": "MIT"
227315              }
227316            }
227317          ],
227318          "cpe": "cpe:2.3:a:rfdc:rfdc:1.3.0:*:*:*:*:*:*:*",
227319          "purl": "pkg:npm/rfdc@1.3.0",
227320          "swid": {
227321            "attachment": {}
227322          },
227323          "pedigree": {},
227324          "evidence": {},
227325          "signature": {
227326            "signature": {
227327              "publicKey": {}
227328            }
227329          },
227330          "modelCard": {
227331            "modelParameters": {
227332              "approach": {}
227333            },
227334            "quantitativeAnalysis": {
227335              "graphics": {}
227336            },
227337            "considerations": {}
227338          }
227339        },
227340        {
227341          "type": "library",
227342          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=e94efbdfea35d1c0",
227343          "supplier": {},
227344          "name": "rimraf",
227345          "version": "3.0.2",
227346          "licenses": [
227347            {
227348              "license": {
227349                "id": "ISC"
227350              }
227351            }
227352          ],
227353          "cpe": "cpe:2.3:a:rimraf:rimraf:3.0.2:*:*:*:*:*:*:*",
227354          "purl": "pkg:npm/rimraf@3.0.2",
227355          "swid": {
227356            "attachment": {}
227357          },
227358          "pedigree": {},
227359          "evidence": {},
227360          "signature": {
227361            "signature": {
227362              "publicKey": {}
227363            }
227364          },
227365          "modelCard": {
227366            "modelParameters": {
227367              "approach": {}
227368            },
227369            "quantitativeAnalysis": {
227370              "graphics": {}
227371            },
227372            "considerations": {}
227373          }
227374        },
227375        {
227376          "type": "library",
227377          "bom-ref": "pkg:npm/rtrim@1.0.1?package-id=c3d41e2719500629",
227378          "supplier": {},
227379          "name": "rtrim",
227380          "version": "1.0.1",
227381          "licenses": [
227382            {
227383              "license": {
227384                "id": "MIT"
227385              }
227386            }
227387          ],
227388          "cpe": "cpe:2.3:a:rtrim:rtrim:1.0.1:*:*:*:*:*:*:*",
227389          "purl": "pkg:npm/rtrim@1.0.1",
227390          "swid": {
227391            "attachment": {}
227392          },
227393          "pedigree": {},
227394          "evidence": {},
227395          "signature": {
227396            "signature": {
227397              "publicKey": {}
227398            }
227399          },
227400          "modelCard": {
227401            "modelParameters": {
227402              "approach": {}
227403            },
227404            "quantitativeAnalysis": {
227405              "graphics": {}
227406            },
227407            "considerations": {}
227408          }
227409        },
227410        {
227411          "type": "library",
227412          "bom-ref": "pkg:npm/runes@0.4.3?package-id=559f935bcd31feef",
227413          "supplier": {},
227414          "name": "runes",
227415          "version": "0.4.3",
227416          "licenses": [
227417            {
227418              "license": {
227419                "id": "MIT"
227420              }
227421            }
227422          ],
227423          "cpe": "cpe:2.3:a:runes:runes:0.4.3:*:*:*:*:*:*:*",
227424          "purl": "pkg:npm/runes@0.4.3",
227425          "swid": {
227426            "attachment": {}
227427          },
227428          "pedigree": {},
227429          "evidence": {},
227430          "signature": {
227431            "signature": {
227432              "publicKey": {}
227433            }
227434          },
227435          "modelCard": {
227436            "modelParameters": {
227437              "approach": {}
227438            },
227439            "quantitativeAnalysis": {
227440              "graphics": {}
227441            },
227442            "considerations": {}
227443          }
227444        },
227445        {
227446          "type": "library",
227447          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=49d265d1cbcc6263",
227448          "supplier": {},
227449          "name": "safe-buffer",
227450          "version": "5.1.2",
227451          "licenses": [
227452            {
227453              "license": {
227454                "id": "MIT"
227455              }
227456            }
227457          ],
227458          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
227459          "purl": "pkg:npm/safe-buffer@5.1.2",
227460          "swid": {
227461            "attachment": {}
227462          },
227463          "pedigree": {},
227464          "evidence": {},
227465          "signature": {
227466            "signature": {
227467              "publicKey": {}
227468            }
227469          },
227470          "modelCard": {
227471            "modelParameters": {
227472              "approach": {}
227473            },
227474            "quantitativeAnalysis": {
227475              "graphics": {}
227476            },
227477            "considerations": {}
227478          }
227479        },
227480        {
227481          "type": "library",
227482          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=8590432c1ecbd629",
227483          "supplier": {},
227484          "name": "safer-buffer",
227485          "version": "2.1.2",
227486          "licenses": [
227487            {
227488              "license": {
227489                "id": "MIT"
227490              }
227491            }
227492          ],
227493          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
227494          "purl": "pkg:npm/safer-buffer@2.1.2",
227495          "swid": {
227496            "attachment": {}
227497          },
227498          "pedigree": {},
227499          "evidence": {},
227500          "signature": {
227501            "signature": {
227502              "publicKey": {}
227503            }
227504          },
227505          "modelCard": {
227506            "modelParameters": {
227507              "approach": {}
227508            },
227509            "quantitativeAnalysis": {
227510              "graphics": {}
227511            },
227512            "considerations": {}
227513          }
227514        },
227515        {
227516          "type": "library",
227517          "bom-ref": "pkg:npm/samba-client@3.4.0?package-id=eec0d4bf5678e7b3",
227518          "supplier": {},
227519          "name": "samba-client",
227520          "version": "3.4.0",
227521          "licenses": [
227522            {
227523              "license": {
227524                "id": "MIT"
227525              }
227526            }
227527          ],
227528          "cpe": "cpe:2.3:a:samba-client:samba-client:3.4.0:*:*:*:*:*:*:*",
227529          "purl": "pkg:npm/samba-client@3.4.0",
227530          "swid": {
227531            "attachment": {}
227532          },
227533          "pedigree": {},
227534          "evidence": {},
227535          "signature": {
227536            "signature": {
227537              "publicKey": {}
227538            }
227539          },
227540          "modelCard": {
227541            "modelParameters": {
227542              "approach": {}
227543            },
227544            "quantitativeAnalysis": {
227545              "graphics": {}
227546            },
227547            "considerations": {}
227548          }
227549        },
227550        {
227551          "type": "library",
227552          "bom-ref": "pkg:npm/sanitizer@0.1.3?package-id=3a4f9a89128c1755",
227553          "supplier": {},
227554          "name": "sanitizer",
227555          "version": "0.1.3",
227556          "licenses": [
227557            {
227558              "license": {
227559                "id": "Apache-2.0"
227560              }
227561            }
227562          ],
227563          "cpe": "cpe:2.3:a:sanitizer:sanitizer:0.1.3:*:*:*:*:*:*:*",
227564          "purl": "pkg:npm/sanitizer@0.1.3",
227565          "swid": {
227566            "attachment": {}
227567          },
227568          "pedigree": {},
227569          "evidence": {},
227570          "signature": {
227571            "signature": {
227572              "publicKey": {}
227573            }
227574          },
227575          "modelCard": {
227576            "modelParameters": {
227577              "approach": {}
227578            },
227579            "quantitativeAnalysis": {
227580              "graphics": {}
227581            },
227582            "considerations": {}
227583          }
227584        },
227585        {
227586          "type": "library",
227587          "bom-ref": "pkg:npm/saslprep@1.0.3?package-id=9f5ebf5e0291bf9d",
227588          "supplier": {},
227589          "name": "saslprep",
227590          "version": "1.0.3",
227591          "licenses": [
227592            {
227593              "license": {
227594                "id": "MIT"
227595              }
227596            }
227597          ],
227598          "cpe": "cpe:2.3:a:saslprep:saslprep:1.0.3:*:*:*:*:*:*:*",
227599          "purl": "pkg:npm/saslprep@1.0.3",
227600          "swid": {
227601            "attachment": {}
227602          },
227603          "pedigree": {},
227604          "evidence": {},
227605          "signature": {
227606            "signature": {
227607              "publicKey": {}
227608            }
227609          },
227610          "modelCard": {
227611            "modelParameters": {
227612              "approach": {}
227613            },
227614            "quantitativeAnalysis": {
227615              "graphics": {}
227616            },
227617            "considerations": {}
227618          }
227619        },
227620        {
227621          "type": "library",
227622          "bom-ref": "pkg:npm/sax@1.2.4?package-id=f596b5408ec8797f",
227623          "supplier": {},
227624          "name": "sax",
227625          "version": "1.2.4",
227626          "licenses": [
227627            {
227628              "license": {
227629                "id": "ISC"
227630              }
227631            }
227632          ],
227633          "cpe": "cpe:2.3:a:sax:sax:1.2.4:*:*:*:*:*:*:*",
227634          "purl": "pkg:npm/sax@1.2.4",
227635          "swid": {
227636            "attachment": {}
227637          },
227638          "pedigree": {},
227639          "evidence": {},
227640          "signature": {
227641            "signature": {
227642              "publicKey": {}
227643            }
227644          },
227645          "modelCard": {
227646            "modelParameters": {
227647              "approach": {}
227648            },
227649            "quantitativeAnalysis": {
227650              "graphics": {}
227651            },
227652            "considerations": {}
227653          }
227654        },
227655        {
227656          "type": "library",
227657          "bom-ref": "pkg:npm/saxes@5.0.1?package-id=9c1810a97a8dad06",
227658          "supplier": {},
227659          "name": "saxes",
227660          "version": "5.0.1",
227661          "licenses": [
227662            {
227663              "license": {
227664                "id": "ISC"
227665              }
227666            }
227667          ],
227668          "cpe": "cpe:2.3:a:saxes:saxes:5.0.1:*:*:*:*:*:*:*",
227669          "purl": "pkg:npm/saxes@5.0.1",
227670          "swid": {
227671            "attachment": {}
227672          },
227673          "pedigree": {},
227674          "evidence": {},
227675          "signature": {
227676            "signature": {
227677              "publicKey": {}
227678            }
227679          },
227680          "modelCard": {
227681            "modelParameters": {
227682              "approach": {}
227683            },
227684            "quantitativeAnalysis": {
227685              "graphics": {}
227686            },
227687            "considerations": {}
227688          }
227689        },
227690        {
227691          "type": "library",
227692          "bom-ref": "pkg:npm/seek-bzip@1.0.6?package-id=a15f66380e96498b",
227693          "supplier": {},
227694          "name": "seek-bzip",
227695          "version": "1.0.6",
227696          "licenses": [
227697            {
227698              "license": {
227699                "id": "MIT"
227700              }
227701            }
227702          ],
227703          "cpe": "cpe:2.3:a:seek-bzip:seek-bzip:1.0.6:*:*:*:*:*:*:*",
227704          "purl": "pkg:npm/seek-bzip@1.0.6",
227705          "swid": {
227706            "attachment": {}
227707          },
227708          "pedigree": {},
227709          "evidence": {},
227710          "signature": {
227711            "signature": {
227712              "publicKey": {}
227713            }
227714          },
227715          "modelCard": {
227716            "modelParameters": {
227717              "approach": {}
227718            },
227719            "quantitativeAnalysis": {
227720              "graphics": {}
227721            },
227722            "considerations": {}
227723          }
227724        },
227725        {
227726          "type": "library",
227727          "bom-ref": "pkg:npm/selfsigned@1.10.14?package-id=d45ddba3ded024e5",
227728          "supplier": {},
227729          "name": "selfsigned",
227730          "version": "1.10.14",
227731          "licenses": [
227732            {
227733              "license": {
227734                "id": "MIT"
227735              }
227736            }
227737          ],
227738          "cpe": "cpe:2.3:a:selfsigned:selfsigned:1.10.14:*:*:*:*:*:*:*",
227739          "purl": "pkg:npm/selfsigned@1.10.14",
227740          "swid": {
227741            "attachment": {}
227742          },
227743          "pedigree": {},
227744          "evidence": {},
227745          "signature": {
227746            "signature": {
227747              "publicKey": {}
227748            }
227749          },
227750          "modelCard": {
227751            "modelParameters": {
227752              "approach": {}
227753            },
227754            "quantitativeAnalysis": {
227755              "graphics": {}
227756            },
227757            "considerations": {}
227758          }
227759        },
227760        {
227761          "type": "library",
227762          "bom-ref": "pkg:npm/semver@5.7.1?package-id=5185dd7ea7f9862e",
227763          "supplier": {},
227764          "name": "semver",
227765          "version": "5.7.1",
227766          "licenses": [
227767            {
227768              "license": {
227769                "id": "ISC"
227770              }
227771            }
227772          ],
227773          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
227774          "purl": "pkg:npm/semver@5.7.1",
227775          "swid": {
227776            "attachment": {}
227777          },
227778          "pedigree": {},
227779          "evidence": {},
227780          "signature": {
227781            "signature": {
227782              "publicKey": {}
227783            }
227784          },
227785          "modelCard": {
227786            "modelParameters": {
227787              "approach": {}
227788            },
227789            "quantitativeAnalysis": {
227790              "graphics": {}
227791            },
227792            "considerations": {}
227793          }
227794        },
227795        {
227796          "type": "library",
227797          "bom-ref": "pkg:npm/seq-queue@0.0.5?package-id=9b717ee05a7d527b",
227798          "supplier": {},
227799          "name": "seq-queue",
227800          "version": "0.0.5",
227801          "cpe": "cpe:2.3:a:seq-queue:seq-queue:0.0.5:*:*:*:*:*:*:*",
227802          "purl": "pkg:npm/seq-queue@0.0.5",
227803          "swid": {
227804            "attachment": {}
227805          },
227806          "pedigree": {},
227807          "evidence": {},
227808          "signature": {
227809            "signature": {
227810              "publicKey": {}
227811            }
227812          },
227813          "modelCard": {
227814            "modelParameters": {
227815              "approach": {}
227816            },
227817            "quantitativeAnalysis": {
227818              "graphics": {}
227819            },
227820            "considerations": {}
227821          }
227822        },
227823        {
227824          "type": "library",
227825          "bom-ref": "pkg:npm/setimmediate@1.0.5?package-id=4b03a62d8669b95a",
227826          "supplier": {},
227827          "name": "setimmediate",
227828          "version": "1.0.5",
227829          "licenses": [
227830            {
227831              "license": {
227832                "id": "MIT"
227833              }
227834            }
227835          ],
227836          "cpe": "cpe:2.3:a:setimmediate:setimmediate:1.0.5:*:*:*:*:*:*:*",
227837          "purl": "pkg:npm/setimmediate@1.0.5",
227838          "swid": {
227839            "attachment": {}
227840          },
227841          "pedigree": {},
227842          "evidence": {},
227843          "signature": {
227844            "signature": {
227845              "publicKey": {}
227846            }
227847          },
227848          "modelCard": {
227849            "modelParameters": {
227850              "approach": {}
227851            },
227852            "quantitativeAnalysis": {
227853              "graphics": {}
227854            },
227855            "considerations": {}
227856          }
227857        },
227858        {
227859          "type": "library",
227860          "bom-ref": "pkg:npm/shebang-command@1.2.0?package-id=e4390e83449061fd",
227861          "supplier": {},
227862          "name": "shebang-command",
227863          "version": "1.2.0",
227864          "licenses": [
227865            {
227866              "license": {
227867                "id": "MIT"
227868              }
227869            }
227870          ],
227871          "cpe": "cpe:2.3:a:shebang-command:shebang-command:1.2.0:*:*:*:*:*:*:*",
227872          "purl": "pkg:npm/shebang-command@1.2.0",
227873          "swid": {
227874            "attachment": {}
227875          },
227876          "pedigree": {},
227877          "evidence": {},
227878          "signature": {
227879            "signature": {
227880              "publicKey": {}
227881            }
227882          },
227883          "modelCard": {
227884            "modelParameters": {
227885              "approach": {}
227886            },
227887            "quantitativeAnalysis": {
227888              "graphics": {}
227889            },
227890            "considerations": {}
227891          }
227892        },
227893        {
227894          "type": "library",
227895          "bom-ref": "pkg:npm/shebang-regex@1.0.0?package-id=765dd2a9bdfc7211",
227896          "supplier": {},
227897          "name": "shebang-regex",
227898          "version": "1.0.0",
227899          "licenses": [
227900            {
227901              "license": {
227902                "id": "MIT"
227903              }
227904            }
227905          ],
227906          "cpe": "cpe:2.3:a:shebang-regex:shebang-regex:1.0.0:*:*:*:*:*:*:*",
227907          "purl": "pkg:npm/shebang-regex@1.0.0",
227908          "swid": {
227909            "attachment": {}
227910          },
227911          "pedigree": {},
227912          "evidence": {},
227913          "signature": {
227914            "signature": {
227915              "publicKey": {}
227916            }
227917          },
227918          "modelCard": {
227919            "modelParameters": {
227920              "approach": {}
227921            },
227922            "quantitativeAnalysis": {
227923              "graphics": {}
227924            },
227925            "considerations": {}
227926          }
227927        },
227928        {
227929          "type": "library",
227930          "bom-ref": "pkg:npm/side-channel@1.0.4?package-id=aac091cedc631ec1",
227931          "supplier": {},
227932          "name": "side-channel",
227933          "version": "1.0.4",
227934          "licenses": [
227935            {
227936              "license": {
227937                "id": "MIT"
227938              }
227939            }
227940          ],
227941          "cpe": "cpe:2.3:a:side-channel:side-channel:1.0.4:*:*:*:*:*:*:*",
227942          "purl": "pkg:npm/side-channel@1.0.4",
227943          "swid": {
227944            "attachment": {}
227945          },
227946          "pedigree": {},
227947          "evidence": {},
227948          "signature": {
227949            "signature": {
227950              "publicKey": {}
227951            }
227952          },
227953          "modelCard": {
227954            "modelParameters": {
227955              "approach": {}
227956            },
227957            "quantitativeAnalysis": {
227958              "graphics": {}
227959            },
227960            "considerations": {}
227961          }
227962        },
227963        {
227964          "type": "library",
227965          "bom-ref": "pkg:npm/signal-exit@3.0.7?package-id=f77c386c34bd93bf",
227966          "supplier": {},
227967          "name": "signal-exit",
227968          "version": "3.0.7",
227969          "licenses": [
227970            {
227971              "license": {
227972                "id": "ISC"
227973              }
227974            }
227975          ],
227976          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.7:*:*:*:*:*:*:*",
227977          "purl": "pkg:npm/signal-exit@3.0.7",
227978          "swid": {
227979            "attachment": {}
227980          },
227981          "pedigree": {},
227982          "evidence": {},
227983          "signature": {
227984            "signature": {
227985              "publicKey": {}
227986            }
227987          },
227988          "modelCard": {
227989            "modelParameters": {
227990              "approach": {}
227991            },
227992            "quantitativeAnalysis": {
227993              "graphics": {}
227994            },
227995            "considerations": {}
227996          }
227997        },
227998        {
227999          "type": "library",
228000          "bom-ref": "pkg:npm/simple-concat@1.0.1?package-id=db88fdd27cdedb5d",
228001          "supplier": {},
228002          "name": "simple-concat",
228003          "version": "1.0.1",
228004          "licenses": [
228005            {
228006              "license": {
228007                "id": "MIT"
228008              }
228009            }
228010          ],
228011          "cpe": "cpe:2.3:a:simple-concat:simple-concat:1.0.1:*:*:*:*:*:*:*",
228012          "purl": "pkg:npm/simple-concat@1.0.1",
228013          "swid": {
228014            "attachment": {}
228015          },
228016          "pedigree": {},
228017          "evidence": {},
228018          "signature": {
228019            "signature": {
228020              "publicKey": {}
228021            }
228022          },
228023          "modelCard": {
228024            "modelParameters": {
228025              "approach": {}
228026            },
228027            "quantitativeAnalysis": {
228028              "graphics": {}
228029            },
228030            "considerations": {}
228031          }
228032        },
228033        {
228034          "type": "library",
228035          "bom-ref": "pkg:npm/simple-get@4.0.1?package-id=eeb7995aca6c24bd",
228036          "supplier": {},
228037          "name": "simple-get",
228038          "version": "4.0.1",
228039          "licenses": [
228040            {
228041              "license": {
228042                "id": "MIT"
228043              }
228044            }
228045          ],
228046          "cpe": "cpe:2.3:a:simple-get:simple-get:4.0.1:*:*:*:*:*:*:*",
228047          "purl": "pkg:npm/simple-get@4.0.1",
228048          "swid": {
228049            "attachment": {}
228050          },
228051          "pedigree": {},
228052          "evidence": {},
228053          "signature": {
228054            "signature": {
228055              "publicKey": {}
228056            }
228057          },
228058          "modelCard": {
228059            "modelParameters": {
228060              "approach": {}
228061            },
228062            "quantitativeAnalysis": {
228063              "graphics": {}
228064            },
228065            "considerations": {}
228066          }
228067        },
228068        {
228069          "type": "library",
228070          "bom-ref": "pkg:npm/smart-buffer@4.2.0?package-id=ebea64a17d71a1f",
228071          "supplier": {},
228072          "name": "smart-buffer",
228073          "version": "4.2.0",
228074          "licenses": [
228075            {
228076              "license": {
228077                "id": "MIT"
228078              }
228079            }
228080          ],
228081          "cpe": "cpe:2.3:a:smart-buffer:smart-buffer:4.2.0:*:*:*:*:*:*:*",
228082          "purl": "pkg:npm/smart-buffer@4.2.0",
228083          "swid": {
228084            "attachment": {}
228085          },
228086          "pedigree": {},
228087          "evidence": {},
228088          "signature": {
228089            "signature": {
228090              "publicKey": {}
228091            }
228092          },
228093          "modelCard": {
228094            "modelParameters": {
228095              "approach": {}
228096            },
228097            "quantitativeAnalysis": {
228098              "graphics": {}
228099            },
228100            "considerations": {}
228101          }
228102        },
228103        {
228104          "type": "library",
228105          "bom-ref": "pkg:npm/sort-keys@1.1.2?package-id=edd6027cc9ab9969",
228106          "supplier": {},
228107          "name": "sort-keys",
228108          "version": "1.1.2",
228109          "licenses": [
228110            {
228111              "license": {
228112                "id": "MIT"
228113              }
228114            }
228115          ],
228116          "cpe": "cpe:2.3:a:sort-keys:sort-keys:1.1.2:*:*:*:*:*:*:*",
228117          "purl": "pkg:npm/sort-keys@1.1.2",
228118          "swid": {
228119            "attachment": {}
228120          },
228121          "pedigree": {},
228122          "evidence": {},
228123          "signature": {
228124            "signature": {
228125              "publicKey": {}
228126            }
228127          },
228128          "modelCard": {
228129            "modelParameters": {
228130              "approach": {}
228131            },
228132            "quantitativeAnalysis": {
228133              "graphics": {}
228134            },
228135            "considerations": {}
228136          }
228137        },
228138        {
228139          "type": "library",
228140          "bom-ref": "pkg:npm/sort-keys-length@1.0.1?package-id=5e84f11b046b6f8a",
228141          "supplier": {},
228142          "name": "sort-keys-length",
228143          "version": "1.0.1",
228144          "licenses": [
228145            {
228146              "license": {
228147                "id": "MIT"
228148              }
228149            }
228150          ],
228151          "cpe": "cpe:2.3:a:sort-keys-length:sort-keys-length:1.0.1:*:*:*:*:*:*:*",
228152          "purl": "pkg:npm/sort-keys-length@1.0.1",
228153          "swid": {
228154            "attachment": {}
228155          },
228156          "pedigree": {},
228157          "evidence": {},
228158          "signature": {
228159            "signature": {
228160              "publicKey": {}
228161            }
228162          },
228163          "modelCard": {
228164            "modelParameters": {
228165              "approach": {}
228166            },
228167            "quantitativeAnalysis": {
228168              "graphics": {}
228169            },
228170            "considerations": {}
228171          }
228172        },
228173        {
228174          "type": "library",
228175          "bom-ref": "pkg:npm/sparse-bitfield@3.0.3?package-id=715fb89e60bb0037",
228176          "supplier": {},
228177          "name": "sparse-bitfield",
228178          "version": "3.0.3",
228179          "licenses": [
228180            {
228181              "license": {
228182                "id": "MIT"
228183              }
228184            }
228185          ],
228186          "cpe": "cpe:2.3:a:sparse-bitfield:sparse-bitfield:3.0.3:*:*:*:*:*:*:*",
228187          "purl": "pkg:npm/sparse-bitfield@3.0.3",
228188          "swid": {
228189            "attachment": {}
228190          },
228191          "pedigree": {},
228192          "evidence": {},
228193          "signature": {
228194            "signature": {
228195              "publicKey": {}
228196            }
228197          },
228198          "modelCard": {
228199            "modelParameters": {
228200              "approach": {}
228201            },
228202            "quantitativeAnalysis": {
228203              "graphics": {}
228204            },
228205            "considerations": {}
228206          }
228207        },
228208        {
228209          "type": "library",
228210          "bom-ref": "pkg:npm/split2@3.2.2?package-id=305d2d4a274748bb",
228211          "supplier": {},
228212          "name": "split2",
228213          "version": "3.2.2",
228214          "licenses": [
228215            {
228216              "license": {
228217                "id": "ISC"
228218              }
228219            }
228220          ],
228221          "cpe": "cpe:2.3:a:split2:split2:3.2.2:*:*:*:*:*:*:*",
228222          "purl": "pkg:npm/split2@3.2.2",
228223          "swid": {
228224            "attachment": {}
228225          },
228226          "pedigree": {},
228227          "evidence": {},
228228          "signature": {
228229            "signature": {
228230              "publicKey": {}
228231            }
228232          },
228233          "modelCard": {
228234            "modelParameters": {
228235              "approach": {}
228236            },
228237            "quantitativeAnalysis": {
228238              "graphics": {}
228239            },
228240            "considerations": {}
228241          }
228242        },
228243        {
228244          "type": "library",
228245          "bom-ref": "pkg:npm/sprintf-js@1.1.2?package-id=74e79f15ca88ecfc",
228246          "supplier": {},
228247          "name": "sprintf-js",
228248          "version": "1.1.2",
228249          "licenses": [
228250            {
228251              "license": {
228252                "id": "BSD-3-Clause"
228253              }
228254            }
228255          ],
228256          "cpe": "cpe:2.3:a:sprintf-js:sprintf-js:1.1.2:*:*:*:*:*:*:*",
228257          "purl": "pkg:npm/sprintf-js@1.1.2",
228258          "swid": {
228259            "attachment": {}
228260          },
228261          "pedigree": {},
228262          "evidence": {},
228263          "signature": {
228264            "signature": {
228265              "publicKey": {}
228266            }
228267          },
228268          "modelCard": {
228269            "modelParameters": {
228270              "approach": {}
228271            },
228272            "quantitativeAnalysis": {
228273              "graphics": {}
228274            },
228275            "considerations": {}
228276          }
228277        },
228278        {
228279          "type": "library",
228280          "bom-ref": "pkg:npm/sqlstring@2.3.3?package-id=49fd1186fd97d952",
228281          "supplier": {},
228282          "name": "sqlstring",
228283          "version": "2.3.3",
228284          "licenses": [
228285            {
228286              "license": {
228287                "id": "MIT"
228288              }
228289            }
228290          ],
228291          "cpe": "cpe:2.3:a:sqlstring:sqlstring:2.3.3:*:*:*:*:*:*:*",
228292          "purl": "pkg:npm/sqlstring@2.3.3",
228293          "swid": {
228294            "attachment": {}
228295          },
228296          "pedigree": {},
228297          "evidence": {},
228298          "signature": {
228299            "signature": {
228300              "publicKey": {}
228301            }
228302          },
228303          "modelCard": {
228304            "modelParameters": {
228305              "approach": {}
228306            },
228307            "quantitativeAnalysis": {
228308              "graphics": {}
228309            },
228310            "considerations": {}
228311          }
228312        },
228313        {
228314          "type": "library",
228315          "bom-ref": "pkg:npm/ssh2@1.11.0?package-id=c3b54ec578fb35bf",
228316          "supplier": {},
228317          "name": "ssh2",
228318          "version": "1.11.0",
228319          "licenses": [
228320            {
228321              "license": {
228322                "id": "MIT"
228323              }
228324            }
228325          ],
228326          "cpe": "cpe:2.3:a:ssh2:ssh2:1.11.0:*:*:*:*:*:*:*",
228327          "purl": "pkg:npm/ssh2@1.11.0",
228328          "swid": {
228329            "attachment": {}
228330          },
228331          "pedigree": {},
228332          "evidence": {},
228333          "signature": {
228334            "signature": {
228335              "publicKey": {}
228336            }
228337          },
228338          "modelCard": {
228339            "modelParameters": {
228340              "approach": {}
228341            },
228342            "quantitativeAnalysis": {
228343              "graphics": {}
228344            },
228345            "considerations": {}
228346          }
228347        },
228348        {
228349          "type": "library",
228350          "bom-ref": "pkg:npm/ssh2-sftp-client@9.0.4?package-id=cf14723b82cf691b",
228351          "supplier": {},
228352          "name": "ssh2-sftp-client",
228353          "version": "9.0.4",
228354          "licenses": [
228355            {
228356              "license": {
228357                "id": "Apache-2.0"
228358              }
228359            }
228360          ],
228361          "cpe": "cpe:2.3:a:ssh2-sftp-client:ssh2-sftp-client:9.0.4:*:*:*:*:*:*:*",
228362          "purl": "pkg:npm/ssh2-sftp-client@9.0.4",
228363          "swid": {
228364            "attachment": {}
228365          },
228366          "pedigree": {},
228367          "evidence": {},
228368          "signature": {
228369            "signature": {
228370              "publicKey": {}
228371            }
228372          },
228373          "modelCard": {
228374            "modelParameters": {
228375              "approach": {}
228376            },
228377            "quantitativeAnalysis": {
228378              "graphics": {}
228379            },
228380            "considerations": {}
228381          }
228382        },
228383        {
228384          "type": "library",
228385          "bom-ref": "pkg:npm/ssh2-streams@0.2.1?package-id=4148ca35eb134307",
228386          "supplier": {},
228387          "name": "ssh2-streams",
228388          "version": "0.2.1",
228389          "licenses": [
228390            {
228391              "license": {
228392                "id": "MIT"
228393              }
228394            }
228395          ],
228396          "cpe": "cpe:2.3:a:ssh2-streams:ssh2-streams:0.2.1:*:*:*:*:*:*:*",
228397          "purl": "pkg:npm/ssh2-streams@0.2.1",
228398          "swid": {
228399            "attachment": {}
228400          },
228401          "pedigree": {},
228402          "evidence": {},
228403          "signature": {
228404            "signature": {
228405              "publicKey": {}
228406            }
228407          },
228408          "modelCard": {
228409            "modelParameters": {
228410              "approach": {}
228411            },
228412            "quantitativeAnalysis": {
228413              "graphics": {}
228414            },
228415            "considerations": {}
228416          }
228417        },
228418        {
228419          "type": "library",
228420          "bom-ref": "pkg:npm/sshpk@1.16.1?package-id=86482c783da2ad02",
228421          "supplier": {},
228422          "name": "sshpk",
228423          "version": "1.16.1",
228424          "licenses": [
228425            {
228426              "license": {
228427                "id": "MIT"
228428              }
228429            }
228430          ],
228431          "cpe": "cpe:2.3:a:sshpk:sshpk:1.16.1:*:*:*:*:*:*:*",
228432          "purl": "pkg:npm/sshpk@1.16.1",
228433          "swid": {
228434            "attachment": {}
228435          },
228436          "pedigree": {},
228437          "evidence": {},
228438          "signature": {
228439            "signature": {
228440              "publicKey": {}
228441            }
228442          },
228443          "modelCard": {
228444            "modelParameters": {
228445              "approach": {}
228446            },
228447            "quantitativeAnalysis": {
228448              "graphics": {}
228449            },
228450            "considerations": {}
228451          }
228452        },
228453        {
228454          "type": "library",
228455          "bom-ref": "pkg:npm/stealthy-require@1.1.1?package-id=af959e080f157f47",
228456          "supplier": {},
228457          "name": "stealthy-require",
228458          "version": "1.1.1",
228459          "licenses": [
228460            {
228461              "license": {
228462                "id": "ISC"
228463              }
228464            }
228465          ],
228466          "cpe": "cpe:2.3:a:stealthy-require:stealthy-require:1.1.1:*:*:*:*:*:*:*",
228467          "purl": "pkg:npm/stealthy-require@1.1.1",
228468          "swid": {
228469            "attachment": {}
228470          },
228471          "pedigree": {},
228472          "evidence": {},
228473          "signature": {
228474            "signature": {
228475              "publicKey": {}
228476            }
228477          },
228478          "modelCard": {
228479            "modelParameters": {
228480              "approach": {}
228481            },
228482            "quantitativeAnalysis": {
228483              "graphics": {}
228484            },
228485            "considerations": {}
228486          }
228487        },
228488        {
228489          "type": "library",
228490          "bom-ref": "pkg:npm/stoppable@1.1.0?package-id=21eff745d7236cfa",
228491          "supplier": {},
228492          "name": "stoppable",
228493          "version": "1.1.0",
228494          "licenses": [
228495            {
228496              "license": {
228497                "id": "MIT"
228498              }
228499            }
228500          ],
228501          "cpe": "cpe:2.3:a:stoppable:stoppable:1.1.0:*:*:*:*:*:*:*",
228502          "purl": "pkg:npm/stoppable@1.1.0",
228503          "swid": {
228504            "attachment": {}
228505          },
228506          "pedigree": {},
228507          "evidence": {},
228508          "signature": {
228509            "signature": {
228510              "publicKey": {}
228511            }
228512          },
228513          "modelCard": {
228514            "modelParameters": {
228515              "approach": {}
228516            },
228517            "quantitativeAnalysis": {
228518              "graphics": {}
228519            },
228520            "considerations": {}
228521          }
228522        },
228523        {
228524          "type": "library",
228525          "bom-ref": "pkg:npm/stream@0.0.2?package-id=67ed72f3f05feca2",
228526          "supplier": {},
228527          "name": "stream",
228528          "version": "0.0.2",
228529          "licenses": [
228530            {
228531              "license": {
228532                "id": "MIT"
228533              }
228534            }
228535          ],
228536          "cpe": "cpe:2.3:a:stream:stream:0.0.2:*:*:*:*:*:*:*",
228537          "purl": "pkg:npm/stream@0.0.2",
228538          "swid": {
228539            "attachment": {}
228540          },
228541          "pedigree": {},
228542          "evidence": {},
228543          "signature": {
228544            "signature": {
228545              "publicKey": {}
228546            }
228547          },
228548          "modelCard": {
228549            "modelParameters": {
228550              "approach": {}
228551            },
228552            "quantitativeAnalysis": {
228553              "graphics": {}
228554            },
228555            "considerations": {}
228556          }
228557        },
228558        {
228559          "type": "library",
228560          "bom-ref": "pkg:npm/stream-shift@1.0.1?package-id=3eb8c981419452ac",
228561          "supplier": {},
228562          "name": "stream-shift",
228563          "version": "1.0.1",
228564          "licenses": [
228565            {
228566              "license": {
228567                "id": "MIT"
228568              }
228569            }
228570          ],
228571          "cpe": "cpe:2.3:a:stream-shift:stream-shift:1.0.1:*:*:*:*:*:*:*",
228572          "purl": "pkg:npm/stream-shift@1.0.1",
228573          "swid": {
228574            "attachment": {}
228575          },
228576          "pedigree": {},
228577          "evidence": {},
228578          "signature": {
228579            "signature": {
228580              "publicKey": {}
228581            }
228582          },
228583          "modelCard": {
228584            "modelParameters": {
228585              "approach": {}
228586            },
228587            "quantitativeAnalysis": {
228588              "graphics": {}
228589            },
228590            "considerations": {}
228591          }
228592        },
228593        {
228594          "type": "library",
228595          "bom-ref": "pkg:npm/streamsearch@0.1.2?package-id=bacba908aeedb20a",
228596          "supplier": {},
228597          "name": "streamsearch",
228598          "version": "0.1.2",
228599          "licenses": [
228600            {
228601              "license": {
228602                "id": "MIT"
228603              }
228604            }
228605          ],
228606          "cpe": "cpe:2.3:a:streamsearch:streamsearch:0.1.2:*:*:*:*:*:*:*",
228607          "purl": "pkg:npm/streamsearch@0.1.2",
228608          "swid": {
228609            "attachment": {}
228610          },
228611          "pedigree": {},
228612          "evidence": {},
228613          "signature": {
228614            "signature": {
228615              "publicKey": {}
228616            }
228617          },
228618          "modelCard": {
228619            "modelParameters": {
228620              "approach": {}
228621            },
228622            "quantitativeAnalysis": {
228623              "graphics": {}
228624            },
228625            "considerations": {}
228626          }
228627        },
228628        {
228629          "type": "library",
228630          "bom-ref": "pkg:npm/string-length@2.0.0?package-id=dcd437837b46e19",
228631          "supplier": {},
228632          "name": "string-length",
228633          "version": "2.0.0",
228634          "licenses": [
228635            {
228636              "license": {
228637                "id": "MIT"
228638              }
228639            }
228640          ],
228641          "cpe": "cpe:2.3:a:string-length:string-length:2.0.0:*:*:*:*:*:*:*",
228642          "purl": "pkg:npm/string-length@2.0.0",
228643          "swid": {
228644            "attachment": {}
228645          },
228646          "pedigree": {},
228647          "evidence": {},
228648          "signature": {
228649            "signature": {
228650              "publicKey": {}
228651            }
228652          },
228653          "modelCard": {
228654            "modelParameters": {
228655              "approach": {}
228656            },
228657            "quantitativeAnalysis": {
228658              "graphics": {}
228659            },
228660            "considerations": {}
228661          }
228662        },
228663        {
228664          "type": "library",
228665          "bom-ref": "pkg:npm/string-width@4.2.3?package-id=4fe676119af3c825",
228666          "supplier": {},
228667          "name": "string-width",
228668          "version": "4.2.3",
228669          "licenses": [
228670            {
228671              "license": {
228672                "id": "MIT"
228673              }
228674            }
228675          ],
228676          "cpe": "cpe:2.3:a:string-width:string-width:4.2.3:*:*:*:*:*:*:*",
228677          "purl": "pkg:npm/string-width@4.2.3",
228678          "swid": {
228679            "attachment": {}
228680          },
228681          "pedigree": {},
228682          "evidence": {},
228683          "signature": {
228684            "signature": {
228685              "publicKey": {}
228686            }
228687          },
228688          "modelCard": {
228689            "modelParameters": {
228690              "approach": {}
228691            },
228692            "quantitativeAnalysis": {
228693              "graphics": {}
228694            },
228695            "considerations": {}
228696          }
228697        },
228698        {
228699          "type": "library",
228700          "bom-ref": "pkg:npm/string_decoder@0.10.31?package-id=b0ce766a25d5c3c3",
228701          "supplier": {},
228702          "name": "string_decoder",
228703          "version": "0.10.31",
228704          "licenses": [
228705            {
228706              "license": {
228707                "id": "MIT"
228708              }
228709            }
228710          ],
228711          "cpe": "cpe:2.3:a:string-decoder:string-decoder:0.10.31:*:*:*:*:*:*:*",
228712          "purl": "pkg:npm/string_decoder@0.10.31",
228713          "swid": {
228714            "attachment": {}
228715          },
228716          "pedigree": {},
228717          "evidence": {},
228718          "signature": {
228719            "signature": {
228720              "publicKey": {}
228721            }
228722          },
228723          "modelCard": {
228724            "modelParameters": {
228725              "approach": {}
228726            },
228727            "quantitativeAnalysis": {
228728              "graphics": {}
228729            },
228730            "considerations": {}
228731          }
228732        },
228733        {
228734          "type": "library",
228735          "bom-ref": "pkg:npm/strip-ansi@4.0.0?package-id=bf00dc61dadf0fe9",
228736          "supplier": {},
228737          "name": "strip-ansi",
228738          "version": "4.0.0",
228739          "licenses": [
228740            {
228741              "license": {
228742                "id": "MIT"
228743              }
228744            }
228745          ],
228746          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:4.0.0:*:*:*:*:*:*:*",
228747          "purl": "pkg:npm/strip-ansi@4.0.0",
228748          "swid": {
228749            "attachment": {}
228750          },
228751          "pedigree": {},
228752          "evidence": {},
228753          "signature": {
228754            "signature": {
228755              "publicKey": {}
228756            }
228757          },
228758          "modelCard": {
228759            "modelParameters": {
228760              "approach": {}
228761            },
228762            "quantitativeAnalysis": {
228763              "graphics": {}
228764            },
228765            "considerations": {}
228766          }
228767        },
228768        {
228769          "type": "library",
228770          "bom-ref": "pkg:npm/strip-dirs@2.1.0?package-id=dfbb388ffc8babe2",
228771          "supplier": {},
228772          "name": "strip-dirs",
228773          "version": "2.1.0",
228774          "licenses": [
228775            {
228776              "license": {
228777                "id": "MIT"
228778              }
228779            }
228780          ],
228781          "cpe": "cpe:2.3:a:strip-dirs:strip-dirs:2.1.0:*:*:*:*:*:*:*",
228782          "purl": "pkg:npm/strip-dirs@2.1.0",
228783          "swid": {
228784            "attachment": {}
228785          },
228786          "pedigree": {},
228787          "evidence": {},
228788          "signature": {
228789            "signature": {
228790              "publicKey": {}
228791            }
228792          },
228793          "modelCard": {
228794            "modelParameters": {
228795              "approach": {}
228796            },
228797            "quantitativeAnalysis": {
228798              "graphics": {}
228799            },
228800            "considerations": {}
228801          }
228802        },
228803        {
228804          "type": "library",
228805          "bom-ref": "pkg:npm/strip-eof@1.0.0?package-id=1bfac392049f7cc3",
228806          "supplier": {},
228807          "name": "strip-eof",
228808          "version": "1.0.0",
228809          "licenses": [
228810            {
228811              "license": {
228812                "id": "MIT"
228813              }
228814            }
228815          ],
228816          "cpe": "cpe:2.3:a:strip-eof:strip-eof:1.0.0:*:*:*:*:*:*:*",
228817          "purl": "pkg:npm/strip-eof@1.0.0",
228818          "swid": {
228819            "attachment": {}
228820          },
228821          "pedigree": {},
228822          "evidence": {},
228823          "signature": {
228824            "signature": {
228825              "publicKey": {}
228826            }
228827          },
228828          "modelCard": {
228829            "modelParameters": {
228830              "approach": {}
228831            },
228832            "quantitativeAnalysis": {
228833              "graphics": {}
228834            },
228835            "considerations": {}
228836          }
228837        },
228838        {
228839          "type": "library",
228840          "bom-ref": "pkg:npm/strip-final-newline@2.0.0?package-id=49cbc7c9cf3c24c6",
228841          "supplier": {},
228842          "name": "strip-final-newline",
228843          "version": "2.0.0",
228844          "licenses": [
228845            {
228846              "license": {
228847                "id": "MIT"
228848              }
228849            }
228850          ],
228851          "cpe": "cpe:2.3:a:strip-final-newline:strip-final-newline:2.0.0:*:*:*:*:*:*:*",
228852          "purl": "pkg:npm/strip-final-newline@2.0.0",
228853          "swid": {
228854            "attachment": {}
228855          },
228856          "pedigree": {},
228857          "evidence": {},
228858          "signature": {
228859            "signature": {
228860              "publicKey": {}
228861            }
228862          },
228863          "modelCard": {
228864            "modelParameters": {
228865              "approach": {}
228866            },
228867            "quantitativeAnalysis": {
228868              "graphics": {}
228869            },
228870            "considerations": {}
228871          }
228872        },
228873        {
228874          "type": "library",
228875          "bom-ref": "pkg:npm/strip-json-comments@2.0.1?package-id=1435ab4349134f2c",
228876          "supplier": {},
228877          "name": "strip-json-comments",
228878          "version": "2.0.1",
228879          "licenses": [
228880            {
228881              "license": {
228882                "id": "MIT"
228883              }
228884            }
228885          ],
228886          "cpe": "cpe:2.3:a:strip-json-comments:strip-json-comments:2.0.1:*:*:*:*:*:*:*",
228887          "purl": "pkg:npm/strip-json-comments@2.0.1",
228888          "swid": {
228889            "attachment": {}
228890          },
228891          "pedigree": {},
228892          "evidence": {},
228893          "signature": {
228894            "signature": {
228895              "publicKey": {}
228896            }
228897          },
228898          "modelCard": {
228899            "modelParameters": {
228900              "approach": {}
228901            },
228902            "quantitativeAnalysis": {
228903              "graphics": {}
228904            },
228905            "considerations": {}
228906          }
228907        },
228908        {
228909          "type": "library",
228910          "bom-ref": "pkg:npm/strip-outer@1.0.1?package-id=83335ae7dd346793",
228911          "supplier": {},
228912          "name": "strip-outer",
228913          "version": "1.0.1",
228914          "licenses": [
228915            {
228916              "license": {
228917                "id": "MIT"
228918              }
228919            }
228920          ],
228921          "cpe": "cpe:2.3:a:strip-outer:strip-outer:1.0.1:*:*:*:*:*:*:*",
228922          "purl": "pkg:npm/strip-outer@1.0.1",
228923          "swid": {
228924            "attachment": {}
228925          },
228926          "pedigree": {},
228927          "evidence": {},
228928          "signature": {
228929            "signature": {
228930              "publicKey": {}
228931            }
228932          },
228933          "modelCard": {
228934            "modelParameters": {
228935              "approach": {}
228936            },
228937            "quantitativeAnalysis": {
228938              "graphics": {}
228939            },
228940            "considerations": {}
228941          }
228942        },
228943        {
228944          "type": "library",
228945          "bom-ref": "pkg:npm/syslog-client-tls@1.2.1?package-id=50db31ee2355e3f1",
228946          "supplier": {},
228947          "name": "syslog-client-tls",
228948          "version": "1.2.1",
228949          "licenses": [
228950            {
228951              "license": {
228952                "id": "MIT"
228953              }
228954            }
228955          ],
228956          "cpe": "cpe:2.3:a:syslog-client-tls:syslog-client-tls:1.2.1:*:*:*:*:*:*:*",
228957          "purl": "pkg:npm/syslog-client-tls@1.2.1",
228958          "swid": {
228959            "attachment": {}
228960          },
228961          "pedigree": {},
228962          "evidence": {},
228963          "signature": {
228964            "signature": {
228965              "publicKey": {}
228966            }
228967          },
228968          "modelCard": {
228969            "modelParameters": {
228970              "approach": {}
228971            },
228972            "quantitativeAnalysis": {
228973              "graphics": {}
228974            },
228975            "considerations": {}
228976          }
228977        },
228978        {
228979          "type": "library",
228980          "bom-ref": "pkg:npm/tar-fs@2.1.1?package-id=3d824bed6c00ea98",
228981          "supplier": {},
228982          "name": "tar-fs",
228983          "version": "2.1.1",
228984          "licenses": [
228985            {
228986              "license": {
228987                "id": "MIT"
228988              }
228989            }
228990          ],
228991          "cpe": "cpe:2.3:a:tar-fs:tar-fs:2.1.1:*:*:*:*:*:*:*",
228992          "purl": "pkg:npm/tar-fs@2.1.1",
228993          "swid": {
228994            "attachment": {}
228995          },
228996          "pedigree": {},
228997          "evidence": {},
228998          "signature": {
228999            "signature": {
229000              "publicKey": {}
229001            }
229002          },
229003          "modelCard": {
229004            "modelParameters": {
229005              "approach": {}
229006            },
229007            "quantitativeAnalysis": {
229008              "graphics": {}
229009            },
229010            "considerations": {}
229011          }
229012        },
229013        {
229014          "type": "library",
229015          "bom-ref": "pkg:npm/tar-stream@2.2.0?package-id=cb576c49f2bef8dc",
229016          "supplier": {},
229017          "name": "tar-stream",
229018          "version": "2.2.0",
229019          "licenses": [
229020            {
229021              "license": {
229022                "id": "MIT"
229023              }
229024            }
229025          ],
229026          "cpe": "cpe:2.3:a:tar-stream:tar-stream:2.2.0:*:*:*:*:*:*:*",
229027          "purl": "pkg:npm/tar-stream@2.2.0",
229028          "swid": {
229029            "attachment": {}
229030          },
229031          "pedigree": {},
229032          "evidence": {},
229033          "signature": {
229034            "signature": {
229035              "publicKey": {}
229036            }
229037          },
229038          "modelCard": {
229039            "modelParameters": {
229040              "approach": {}
229041            },
229042            "quantitativeAnalysis": {
229043              "graphics": {}
229044            },
229045            "considerations": {}
229046          }
229047        },
229048        {
229049          "type": "library",
229050          "bom-ref": "pkg:npm/tarn@3.0.2?package-id=e063df59cb414f88",
229051          "supplier": {},
229052          "name": "tarn",
229053          "version": "3.0.2",
229054          "licenses": [
229055            {
229056              "license": {
229057                "id": "MIT"
229058              }
229059            }
229060          ],
229061          "cpe": "cpe:2.3:a:tarn:tarn:3.0.2:*:*:*:*:*:*:*",
229062          "purl": "pkg:npm/tarn@3.0.2",
229063          "swid": {
229064            "attachment": {}
229065          },
229066          "pedigree": {},
229067          "evidence": {},
229068          "signature": {
229069            "signature": {
229070              "publicKey": {}
229071            }
229072          },
229073          "modelCard": {
229074            "modelParameters": {
229075              "approach": {}
229076            },
229077            "quantitativeAnalysis": {
229078              "graphics": {}
229079            },
229080            "considerations": {}
229081          }
229082        },
229083        {
229084          "type": "library",
229085          "bom-ref": "pkg:npm/tcp-over-websockets@2.0.0?package-id=2b9da4871a2543a7",
229086          "supplier": {},
229087          "name": "tcp-over-websockets",
229088          "version": "2.0.0",
229089          "licenses": [
229090            {
229091              "license": {
229092                "id": "ISC"
229093              }
229094            }
229095          ],
229096          "cpe": "cpe:2.3:a:tcp-over-websockets:tcp-over-websockets:2.0.0:*:*:*:*:*:*:*",
229097          "purl": "pkg:npm/tcp-over-websockets@2.0.0",
229098          "swid": {
229099            "attachment": {}
229100          },
229101          "pedigree": {},
229102          "evidence": {},
229103          "signature": {
229104            "signature": {
229105              "publicKey": {}
229106            }
229107          },
229108          "modelCard": {
229109            "modelParameters": {
229110              "approach": {}
229111            },
229112            "quantitativeAnalysis": {
229113              "graphics": {}
229114            },
229115            "considerations": {}
229116          }
229117        },
229118        {
229119          "type": "library",
229120          "bom-ref": "pkg:npm/tedious@11.8.0?package-id=cdc93fd7edc921f2",
229121          "supplier": {},
229122          "name": "tedious",
229123          "version": "11.8.0",
229124          "licenses": [
229125            {
229126              "license": {
229127                "id": "MIT"
229128              }
229129            }
229130          ],
229131          "cpe": "cpe:2.3:a:tedious:tedious:11.8.0:*:*:*:*:*:*:*",
229132          "purl": "pkg:npm/tedious@11.8.0",
229133          "swid": {
229134            "attachment": {}
229135          },
229136          "pedigree": {},
229137          "evidence": {},
229138          "signature": {
229139            "signature": {
229140              "publicKey": {}
229141            }
229142          },
229143          "modelCard": {
229144            "modelParameters": {
229145              "approach": {}
229146            },
229147            "quantitativeAnalysis": {
229148              "graphics": {}
229149            },
229150            "considerations": {}
229151          }
229152        },
229153        {
229154          "type": "library",
229155          "bom-ref": "pkg:npm/telnet-client@2.0.8?package-id=c1992eefa5dbbbe2",
229156          "supplier": {},
229157          "name": "telnet-client",
229158          "version": "2.0.8",
229159          "licenses": [
229160            {
229161              "license": {
229162                "id": "MIT"
229163              }
229164            }
229165          ],
229166          "cpe": "cpe:2.3:a:telnet-client:telnet-client:2.0.8:*:*:*:*:*:*:*",
229167          "purl": "pkg:npm/telnet-client@2.0.8",
229168          "swid": {
229169            "attachment": {}
229170          },
229171          "pedigree": {},
229172          "evidence": {},
229173          "signature": {
229174            "signature": {
229175              "publicKey": {}
229176            }
229177          },
229178          "modelCard": {
229179            "modelParameters": {
229180              "approach": {}
229181            },
229182            "quantitativeAnalysis": {
229183              "graphics": {}
229184            },
229185            "considerations": {}
229186          }
229187        },
229188        {
229189          "type": "library",
229190          "bom-ref": "pkg:npm/temp-dir@1.0.0?package-id=69a30ea8bc89a443",
229191          "supplier": {},
229192          "name": "temp-dir",
229193          "version": "1.0.0",
229194          "licenses": [
229195            {
229196              "license": {
229197                "id": "MIT"
229198              }
229199            }
229200          ],
229201          "cpe": "cpe:2.3:a:temp-dir:temp-dir:1.0.0:*:*:*:*:*:*:*",
229202          "purl": "pkg:npm/temp-dir@1.0.0",
229203          "swid": {
229204            "attachment": {}
229205          },
229206          "pedigree": {},
229207          "evidence": {},
229208          "signature": {
229209            "signature": {
229210              "publicKey": {}
229211            }
229212          },
229213          "modelCard": {
229214            "modelParameters": {
229215              "approach": {}
229216            },
229217            "quantitativeAnalysis": {
229218              "graphics": {}
229219            },
229220            "considerations": {}
229221          }
229222        },
229223        {
229224          "type": "library",
229225          "bom-ref": "pkg:npm/tempfile@3.0.0?package-id=56ad1dc67a2459bd",
229226          "supplier": {},
229227          "name": "tempfile",
229228          "version": "3.0.0",
229229          "licenses": [
229230            {
229231              "license": {
229232                "id": "MIT"
229233              }
229234            }
229235          ],
229236          "cpe": "cpe:2.3:a:tempfile:tempfile:3.0.0:*:*:*:*:*:*:*",
229237          "purl": "pkg:npm/tempfile@3.0.0",
229238          "swid": {
229239            "attachment": {}
229240          },
229241          "pedigree": {},
229242          "evidence": {},
229243          "signature": {
229244            "signature": {
229245              "publicKey": {}
229246            }
229247          },
229248          "modelCard": {
229249            "modelParameters": {
229250              "approach": {}
229251            },
229252            "quantitativeAnalysis": {
229253              "graphics": {}
229254            },
229255            "considerations": {}
229256          }
229257        },
229258        {
229259          "type": "library",
229260          "bom-ref": "pkg:npm/through@2.3.8?package-id=9fb5b0ac7a8f80d3",
229261          "supplier": {},
229262          "name": "through",
229263          "version": "2.3.8",
229264          "licenses": [
229265            {
229266              "license": {
229267                "id": "MIT"
229268              }
229269            }
229270          ],
229271          "cpe": "cpe:2.3:a:through:through:2.3.8:*:*:*:*:*:*:*",
229272          "purl": "pkg:npm/through@2.3.8",
229273          "swid": {
229274            "attachment": {}
229275          },
229276          "pedigree": {},
229277          "evidence": {},
229278          "signature": {
229279            "signature": {
229280              "publicKey": {}
229281            }
229282          },
229283          "modelCard": {
229284            "modelParameters": {
229285              "approach": {}
229286            },
229287            "quantitativeAnalysis": {
229288              "graphics": {}
229289            },
229290            "considerations": {}
229291          }
229292        },
229293        {
229294          "type": "library",
229295          "bom-ref": "pkg:npm/timed-out@4.0.1?package-id=1285acf491264495",
229296          "supplier": {},
229297          "name": "timed-out",
229298          "version": "4.0.1",
229299          "licenses": [
229300            {
229301              "license": {
229302                "id": "MIT"
229303              }
229304            }
229305          ],
229306          "cpe": "cpe:2.3:a:timed-out:timed-out:4.0.1:*:*:*:*:*:*:*",
229307          "purl": "pkg:npm/timed-out@4.0.1",
229308          "swid": {
229309            "attachment": {}
229310          },
229311          "pedigree": {},
229312          "evidence": {},
229313          "signature": {
229314            "signature": {
229315              "publicKey": {}
229316            }
229317          },
229318          "modelCard": {
229319            "modelParameters": {
229320              "approach": {}
229321            },
229322            "quantitativeAnalysis": {
229323              "graphics": {}
229324            },
229325            "considerations": {}
229326          }
229327        },
229328        {
229329          "type": "library",
229330          "bom-ref": "pkg:npm/tmp@0.2.1?package-id=2331b71ccf2b4583",
229331          "supplier": {},
229332          "name": "tmp",
229333          "version": "0.2.1",
229334          "licenses": [
229335            {
229336              "license": {
229337                "id": "MIT"
229338              }
229339            }
229340          ],
229341          "cpe": "cpe:2.3:a:tmp:tmp:0.2.1:*:*:*:*:*:*:*",
229342          "purl": "pkg:npm/tmp@0.2.1",
229343          "swid": {
229344            "attachment": {}
229345          },
229346          "pedigree": {},
229347          "evidence": {},
229348          "signature": {
229349            "signature": {
229350              "publicKey": {}
229351            }
229352          },
229353          "modelCard": {
229354            "modelParameters": {
229355              "approach": {}
229356            },
229357            "quantitativeAnalysis": {
229358              "graphics": {}
229359            },
229360            "considerations": {}
229361          }
229362        },
229363        {
229364          "type": "library",
229365          "bom-ref": "pkg:npm/to-buffer@1.1.1?package-id=e00d416d2ea1399b",
229366          "supplier": {},
229367          "name": "to-buffer",
229368          "version": "1.1.1",
229369          "licenses": [
229370            {
229371              "license": {
229372                "id": "MIT"
229373              }
229374            }
229375          ],
229376          "cpe": "cpe:2.3:a:to-buffer:to-buffer:1.1.1:*:*:*:*:*:*:*",
229377          "purl": "pkg:npm/to-buffer@1.1.1",
229378          "swid": {
229379            "attachment": {}
229380          },
229381          "pedigree": {},
229382          "evidence": {},
229383          "signature": {
229384            "signature": {
229385              "publicKey": {}
229386            }
229387          },
229388          "modelCard": {
229389            "modelParameters": {
229390              "approach": {}
229391            },
229392            "quantitativeAnalysis": {
229393              "graphics": {}
229394            },
229395            "considerations": {}
229396          }
229397        },
229398        {
229399          "type": "library",
229400          "bom-ref": "pkg:npm/tough-cookie@2.4.3?package-id=df86e1683e982f52",
229401          "supplier": {},
229402          "name": "tough-cookie",
229403          "version": "2.4.3",
229404          "licenses": [
229405            {
229406              "license": {
229407                "id": "BSD-3-Clause"
229408              }
229409            }
229410          ],
229411          "cpe": "cpe:2.3:a:tough-cookie:tough-cookie:2.4.3:*:*:*:*:*:*:*",
229412          "purl": "pkg:npm/tough-cookie@2.4.3",
229413          "swid": {
229414            "attachment": {}
229415          },
229416          "pedigree": {},
229417          "evidence": {},
229418          "signature": {
229419            "signature": {
229420              "publicKey": {}
229421            }
229422          },
229423          "modelCard": {
229424            "modelParameters": {
229425              "approach": {}
229426            },
229427            "quantitativeAnalysis": {
229428              "graphics": {}
229429            },
229430            "considerations": {}
229431          }
229432        },
229433        {
229434          "type": "library",
229435          "bom-ref": "pkg:npm/tr46@0.0.3?package-id=ff1ef2214c0d3e88",
229436          "supplier": {},
229437          "name": "tr46",
229438          "version": "0.0.3",
229439          "licenses": [
229440            {
229441              "license": {
229442                "id": "MIT"
229443              }
229444            }
229445          ],
229446          "cpe": "cpe:2.3:a:tr46:tr46:0.0.3:*:*:*:*:*:*:*",
229447          "purl": "pkg:npm/tr46@0.0.3",
229448          "swid": {
229449            "attachment": {}
229450          },
229451          "pedigree": {},
229452          "evidence": {},
229453          "signature": {
229454            "signature": {
229455              "publicKey": {}
229456            }
229457          },
229458          "modelCard": {
229459            "modelParameters": {
229460              "approach": {}
229461            },
229462            "quantitativeAnalysis": {
229463              "graphics": {}
229464            },
229465            "considerations": {}
229466          }
229467        },
229468        {
229469          "type": "library",
229470          "bom-ref": "pkg:npm/traverse@0.3.9?package-id=53adc222fde681b4",
229471          "supplier": {},
229472          "name": "traverse",
229473          "version": "0.3.9",
229474          "licenses": [
229475            {
229476              "license": {
229477                "name": "MIT/X11"
229478              }
229479            }
229480          ],
229481          "cpe": "cpe:2.3:a:traverse:traverse:0.3.9:*:*:*:*:*:*:*",
229482          "purl": "pkg:npm/traverse@0.3.9",
229483          "swid": {
229484            "attachment": {}
229485          },
229486          "pedigree": {},
229487          "evidence": {},
229488          "signature": {
229489            "signature": {
229490              "publicKey": {}
229491            }
229492          },
229493          "modelCard": {
229494            "modelParameters": {
229495              "approach": {}
229496            },
229497            "quantitativeAnalysis": {
229498              "graphics": {}
229499            },
229500            "considerations": {}
229501          }
229502        },
229503        {
229504          "type": "library",
229505          "bom-ref": "pkg:npm/trim-repeated@1.0.0?package-id=89f93d149e5cf575",
229506          "supplier": {},
229507          "name": "trim-repeated",
229508          "version": "1.0.0",
229509          "licenses": [
229510            {
229511              "license": {
229512                "id": "MIT"
229513              }
229514            }
229515          ],
229516          "cpe": "cpe:2.3:a:trim-repeated:trim-repeated:1.0.0:*:*:*:*:*:*:*",
229517          "purl": "pkg:npm/trim-repeated@1.0.0",
229518          "swid": {
229519            "attachment": {}
229520          },
229521          "pedigree": {},
229522          "evidence": {},
229523          "signature": {
229524            "signature": {
229525              "publicKey": {}
229526            }
229527          },
229528          "modelCard": {
229529            "modelParameters": {
229530              "approach": {}
229531            },
229532            "quantitativeAnalysis": {
229533              "graphics": {}
229534            },
229535            "considerations": {}
229536          }
229537        },
229538        {
229539          "type": "library",
229540          "bom-ref": "pkg:npm/truncate@2.1.0?package-id=d91226667033e23a",
229541          "supplier": {},
229542          "name": "truncate",
229543          "version": "2.1.0",
229544          "licenses": [
229545            {
229546              "license": {
229547                "id": "MIT"
229548              }
229549            }
229550          ],
229551          "cpe": "cpe:2.3:a:truncate:truncate:2.1.0:*:*:*:*:*:*:*",
229552          "purl": "pkg:npm/truncate@2.1.0",
229553          "swid": {
229554            "attachment": {}
229555          },
229556          "pedigree": {},
229557          "evidence": {},
229558          "signature": {
229559            "signature": {
229560              "publicKey": {}
229561            }
229562          },
229563          "modelCard": {
229564            "modelParameters": {
229565              "approach": {}
229566            },
229567            "quantitativeAnalysis": {
229568              "graphics": {}
229569            },
229570            "considerations": {}
229571          }
229572        },
229573        {
229574          "type": "library",
229575          "bom-ref": "pkg:npm/truncate-words@1.0.0?package-id=f397da253b12bb5d",
229576          "supplier": {},
229577          "name": "truncate-words",
229578          "version": "1.0.0",
229579          "licenses": [
229580            {
229581              "license": {
229582                "id": "MIT"
229583              }
229584            }
229585          ],
229586          "cpe": "cpe:2.3:a:truncate-words:truncate-words:1.0.0:*:*:*:*:*:*:*",
229587          "purl": "pkg:npm/truncate-words@1.0.0",
229588          "swid": {
229589            "attachment": {}
229590          },
229591          "pedigree": {},
229592          "evidence": {},
229593          "signature": {
229594            "signature": {
229595              "publicKey": {}
229596            }
229597          },
229598          "modelCard": {
229599            "modelParameters": {
229600              "approach": {}
229601            },
229602            "quantitativeAnalysis": {
229603              "graphics": {}
229604            },
229605            "considerations": {}
229606          }
229607        },
229608        {
229609          "type": "library",
229610          "bom-ref": "pkg:npm/tslib@2.5.0?package-id=7677506dae7c7968",
229611          "supplier": {},
229612          "name": "tslib",
229613          "version": "2.5.0",
229614          "licenses": [
229615            {
229616              "license": {
229617                "id": "0BSD"
229618              }
229619            }
229620          ],
229621          "cpe": "cpe:2.3:a:tslib:tslib:2.5.0:*:*:*:*:*:*:*",
229622          "purl": "pkg:npm/tslib@2.5.0",
229623          "swid": {
229624            "attachment": {}
229625          },
229626          "pedigree": {},
229627          "evidence": {},
229628          "signature": {
229629            "signature": {
229630              "publicKey": {}
229631            }
229632          },
229633          "modelCard": {
229634            "modelParameters": {
229635              "approach": {}
229636            },
229637            "quantitativeAnalysis": {
229638              "graphics": {}
229639            },
229640            "considerations": {}
229641          }
229642        },
229643        {
229644          "type": "library",
229645          "bom-ref": "pkg:npm/tunnel@0.0.6?package-id=9b7ac0b204ad2036",
229646          "supplier": {},
229647          "name": "tunnel",
229648          "version": "0.0.6",
229649          "licenses": [
229650            {
229651              "license": {
229652                "id": "MIT"
229653              }
229654            }
229655          ],
229656          "cpe": "cpe:2.3:a:tunnel:tunnel:0.0.6:*:*:*:*:*:*:*",
229657          "purl": "pkg:npm/tunnel@0.0.6",
229658          "swid": {
229659            "attachment": {}
229660          },
229661          "pedigree": {},
229662          "evidence": {},
229663          "signature": {
229664            "signature": {
229665              "publicKey": {}
229666            }
229667          },
229668          "modelCard": {
229669            "modelParameters": {
229670              "approach": {}
229671            },
229672            "quantitativeAnalysis": {
229673              "graphics": {}
229674            },
229675            "considerations": {}
229676          }
229677        },
229678        {
229679          "type": "library",
229680          "bom-ref": "pkg:npm/tunnel-agent@0.6.0?package-id=ca049987a582a89c",
229681          "supplier": {},
229682          "name": "tunnel-agent",
229683          "version": "0.6.0",
229684          "licenses": [
229685            {
229686              "license": {
229687                "id": "Apache-2.0"
229688              }
229689            }
229690          ],
229691          "cpe": "cpe:2.3:a:tunnel-agent:tunnel-agent:0.6.0:*:*:*:*:*:*:*",
229692          "purl": "pkg:npm/tunnel-agent@0.6.0",
229693          "swid": {
229694            "attachment": {}
229695          },
229696          "pedigree": {},
229697          "evidence": {},
229698          "signature": {
229699            "signature": {
229700              "publicKey": {}
229701            }
229702          },
229703          "modelCard": {
229704            "modelParameters": {
229705              "approach": {}
229706            },
229707            "quantitativeAnalysis": {
229708              "graphics": {}
229709            },
229710            "considerations": {}
229711          }
229712        },
229713        {
229714          "type": "library",
229715          "bom-ref": "pkg:npm/tweetnacl@0.14.5?package-id=49aff99863163f8d",
229716          "supplier": {},
229717          "name": "tweetnacl",
229718          "version": "0.14.5",
229719          "licenses": [
229720            {
229721              "license": {
229722                "id": "Unlicense"
229723              }
229724            }
229725          ],
229726          "cpe": "cpe:2.3:a:tweetnacl:tweetnacl:0.14.5:*:*:*:*:*:*:*",
229727          "purl": "pkg:npm/tweetnacl@0.14.5",
229728          "swid": {
229729            "attachment": {}
229730          },
229731          "pedigree": {},
229732          "evidence": {},
229733          "signature": {
229734            "signature": {
229735              "publicKey": {}
229736            }
229737          },
229738          "modelCard": {
229739            "modelParameters": {
229740              "approach": {}
229741            },
229742            "quantitativeAnalysis": {
229743              "graphics": {}
229744            },
229745            "considerations": {}
229746          }
229747        },
229748        {
229749          "type": "library",
229750          "bom-ref": "pkg:npm/typedarray@0.0.6?package-id=4f11f2d8665a995",
229751          "supplier": {},
229752          "name": "typedarray",
229753          "version": "0.0.6",
229754          "licenses": [
229755            {
229756              "license": {
229757                "id": "MIT"
229758              }
229759            }
229760          ],
229761          "cpe": "cpe:2.3:a:typedarray:typedarray:0.0.6:*:*:*:*:*:*:*",
229762          "purl": "pkg:npm/typedarray@0.0.6",
229763          "swid": {
229764            "attachment": {}
229765          },
229766          "pedigree": {},
229767          "evidence": {},
229768          "signature": {
229769            "signature": {
229770              "publicKey": {}
229771            }
229772          },
229773          "modelCard": {
229774            "modelParameters": {
229775              "approach": {}
229776            },
229777            "quantitativeAnalysis": {
229778              "graphics": {}
229779            },
229780            "considerations": {}
229781          }
229782        },
229783        {
229784          "type": "library",
229785          "bom-ref": "pkg:npm/ultron@1.1.1?package-id=7afe554e7e1e2c78",
229786          "supplier": {},
229787          "name": "ultron",
229788          "version": "1.1.1",
229789          "licenses": [
229790            {
229791              "license": {
229792                "id": "MIT"
229793              }
229794            }
229795          ],
229796          "cpe": "cpe:2.3:a:ultron:ultron:1.1.1:*:*:*:*:*:*:*",
229797          "purl": "pkg:npm/ultron@1.1.1",
229798          "swid": {
229799            "attachment": {}
229800          },
229801          "pedigree": {},
229802          "evidence": {},
229803          "signature": {
229804            "signature": {
229805              "publicKey": {}
229806            }
229807          },
229808          "modelCard": {
229809            "modelParameters": {
229810              "approach": {}
229811            },
229812            "quantitativeAnalysis": {
229813              "graphics": {}
229814            },
229815            "considerations": {}
229816          }
229817        },
229818        {
229819          "type": "library",
229820          "bom-ref": "pkg:npm/unbzip2-stream@1.4.3?package-id=e94ada5ff807aa4e",
229821          "supplier": {},
229822          "name": "unbzip2-stream",
229823          "version": "1.4.3",
229824          "licenses": [
229825            {
229826              "license": {
229827                "id": "MIT"
229828              }
229829            }
229830          ],
229831          "cpe": "cpe:2.3:a:unbzip2-stream:unbzip2-stream:1.4.3:*:*:*:*:*:*:*",
229832          "purl": "pkg:npm/unbzip2-stream@1.4.3",
229833          "swid": {
229834            "attachment": {}
229835          },
229836          "pedigree": {},
229837          "evidence": {},
229838          "signature": {
229839            "signature": {
229840              "publicKey": {}
229841            }
229842          },
229843          "modelCard": {
229844            "modelParameters": {
229845              "approach": {}
229846            },
229847            "quantitativeAnalysis": {
229848              "graphics": {}
229849            },
229850            "considerations": {}
229851          }
229852        },
229853        {
229854          "type": "library",
229855          "bom-ref": "pkg:npm/underscore@1.13.6?package-id=a2d4ac377c698f3c",
229856          "supplier": {},
229857          "name": "underscore",
229858          "version": "1.13.6",
229859          "licenses": [
229860            {
229861              "license": {
229862                "id": "MIT"
229863              }
229864            }
229865          ],
229866          "cpe": "cpe:2.3:a:underscore:underscore:1.13.6:*:*:*:*:*:*:*",
229867          "purl": "pkg:npm/underscore@1.13.6",
229868          "swid": {
229869            "attachment": {}
229870          },
229871          "pedigree": {},
229872          "evidence": {},
229873          "signature": {
229874            "signature": {
229875              "publicKey": {}
229876            }
229877          },
229878          "modelCard": {
229879            "modelParameters": {
229880              "approach": {}
229881            },
229882            "quantitativeAnalysis": {
229883              "graphics": {}
229884            },
229885            "considerations": {}
229886          }
229887        },
229888        {
229889          "type": "library",
229890          "bom-ref": "pkg:npm/universalify@2.0.0?package-id=77c593967ba910e6",
229891          "supplier": {},
229892          "name": "universalify",
229893          "version": "2.0.0",
229894          "licenses": [
229895            {
229896              "license": {
229897                "id": "MIT"
229898              }
229899            }
229900          ],
229901          "cpe": "cpe:2.3:a:universalify:universalify:2.0.0:*:*:*:*:*:*:*",
229902          "purl": "pkg:npm/universalify@2.0.0",
229903          "swid": {
229904            "attachment": {}
229905          },
229906          "pedigree": {},
229907          "evidence": {},
229908          "signature": {
229909            "signature": {
229910              "publicKey": {}
229911            }
229912          },
229913          "modelCard": {
229914            "modelParameters": {
229915              "approach": {}
229916            },
229917            "quantitativeAnalysis": {
229918              "graphics": {}
229919            },
229920            "considerations": {}
229921          }
229922        },
229923        {
229924          "type": "library",
229925          "bom-ref": "pkg:npm/unzipper@0.10.11?package-id=779c93967d20dda4",
229926          "supplier": {},
229927          "name": "unzipper",
229928          "version": "0.10.11",
229929          "licenses": [
229930            {
229931              "license": {
229932                "id": "MIT"
229933              }
229934            }
229935          ],
229936          "cpe": "cpe:2.3:a:unzipper:unzipper:0.10.11:*:*:*:*:*:*:*",
229937          "purl": "pkg:npm/unzipper@0.10.11",
229938          "swid": {
229939            "attachment": {}
229940          },
229941          "pedigree": {},
229942          "evidence": {},
229943          "signature": {
229944            "signature": {
229945              "publicKey": {}
229946            }
229947          },
229948          "modelCard": {
229949            "modelParameters": {
229950              "approach": {}
229951            },
229952            "quantitativeAnalysis": {
229953              "graphics": {}
229954            },
229955            "considerations": {}
229956          }
229957        },
229958        {
229959          "type": "library",
229960          "bom-ref": "pkg:npm/uri-js@4.2.2?package-id=bdb26b64854d360e",
229961          "supplier": {},
229962          "name": "uri-js",
229963          "version": "4.2.2",
229964          "licenses": [
229965            {
229966              "license": {
229967                "id": "BSD-2-Clause"
229968              }
229969            }
229970          ],
229971          "cpe": "cpe:2.3:a:uri-js:uri-js:4.2.2:*:*:*:*:*:*:*",
229972          "purl": "pkg:npm/uri-js@4.2.2",
229973          "swid": {
229974            "attachment": {}
229975          },
229976          "pedigree": {},
229977          "evidence": {},
229978          "signature": {
229979            "signature": {
229980              "publicKey": {}
229981            }
229982          },
229983          "modelCard": {
229984            "modelParameters": {
229985              "approach": {}
229986            },
229987            "quantitativeAnalysis": {
229988              "graphics": {}
229989            },
229990            "considerations": {}
229991          }
229992        },
229993        {
229994          "type": "library",
229995          "bom-ref": "pkg:npm/url-parse@1.5.3?package-id=1079a2de95d8b792",
229996          "supplier": {},
229997          "name": "url-parse",
229998          "version": "1.5.3",
229999          "licenses": [
230000            {
230001              "license": {
230002                "id": "MIT"
230003              }
230004            }
230005          ],
230006          "cpe": "cpe:2.3:a:url-parse:url-parse:1.5.3:*:*:*:*:*:*:*",
230007          "purl": "pkg:npm/url-parse@1.5.3",
230008          "swid": {
230009            "attachment": {}
230010          },
230011          "pedigree": {},
230012          "evidence": {},
230013          "signature": {
230014            "signature": {
230015              "publicKey": {}
230016            }
230017          },
230018          "modelCard": {
230019            "modelParameters": {
230020              "approach": {}
230021            },
230022            "quantitativeAnalysis": {
230023              "graphics": {}
230024            },
230025            "considerations": {}
230026          }
230027        },
230028        {
230029          "type": "library",
230030          "bom-ref": "pkg:npm/url-parse-lax@1.0.0?package-id=128b7dd8377294e5",
230031          "supplier": {},
230032          "name": "url-parse-lax",
230033          "version": "1.0.0",
230034          "licenses": [
230035            {
230036              "license": {
230037                "id": "MIT"
230038              }
230039            }
230040          ],
230041          "cpe": "cpe:2.3:a:url-parse-lax:url-parse-lax:1.0.0:*:*:*:*:*:*:*",
230042          "purl": "pkg:npm/url-parse-lax@1.0.0",
230043          "swid": {
230044            "attachment": {}
230045          },
230046          "pedigree": {},
230047          "evidence": {},
230048          "signature": {
230049            "signature": {
230050              "publicKey": {}
230051            }
230052          },
230053          "modelCard": {
230054            "modelParameters": {
230055              "approach": {}
230056            },
230057            "quantitativeAnalysis": {
230058              "graphics": {}
230059            },
230060            "considerations": {}
230061          }
230062        },
230063        {
230064          "type": "library",
230065          "bom-ref": "pkg:npm/url-to-options@1.0.1?package-id=4b2d010d7f0f658a",
230066          "supplier": {},
230067          "name": "url-to-options",
230068          "version": "1.0.1",
230069          "licenses": [
230070            {
230071              "license": {
230072                "id": "MIT"
230073              }
230074            }
230075          ],
230076          "cpe": "cpe:2.3:a:url-to-options:url-to-options:1.0.1:*:*:*:*:*:*:*",
230077          "purl": "pkg:npm/url-to-options@1.0.1",
230078          "swid": {
230079            "attachment": {}
230080          },
230081          "pedigree": {},
230082          "evidence": {},
230083          "signature": {
230084            "signature": {
230085              "publicKey": {}
230086            }
230087          },
230088          "modelCard": {
230089            "modelParameters": {
230090              "approach": {}
230091            },
230092            "quantitativeAnalysis": {
230093              "graphics": {}
230094            },
230095            "considerations": {}
230096          }
230097        },
230098        {
230099          "type": "library",
230100          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=9f39f1de5aacfdc1",
230101          "supplier": {},
230102          "name": "util-deprecate",
230103          "version": "1.0.2",
230104          "licenses": [
230105            {
230106              "license": {
230107                "id": "MIT"
230108              }
230109            }
230110          ],
230111          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
230112          "purl": "pkg:npm/util-deprecate@1.0.2",
230113          "swid": {
230114            "attachment": {}
230115          },
230116          "pedigree": {},
230117          "evidence": {},
230118          "signature": {
230119            "signature": {
230120              "publicKey": {}
230121            }
230122          },
230123          "modelCard": {
230124            "modelParameters": {
230125              "approach": {}
230126            },
230127            "quantitativeAnalysis": {
230128              "graphics": {}
230129            },
230130            "considerations": {}
230131          }
230132        },
230133        {
230134          "type": "library",
230135          "bom-ref": "pkg:npm/uuid@3.3.2?package-id=c14730b3aa075c3",
230136          "supplier": {},
230137          "name": "uuid",
230138          "version": "3.3.2",
230139          "licenses": [
230140            {
230141              "license": {
230142                "id": "MIT"
230143              }
230144            }
230145          ],
230146          "cpe": "cpe:2.3:a:uuid:uuid:3.3.2:*:*:*:*:*:*:*",
230147          "purl": "pkg:npm/uuid@3.3.2",
230148          "swid": {
230149            "attachment": {}
230150          },
230151          "pedigree": {},
230152          "evidence": {},
230153          "signature": {
230154            "signature": {
230155              "publicKey": {}
230156            }
230157          },
230158          "modelCard": {
230159            "modelParameters": {
230160              "approach": {}
230161            },
230162            "quantitativeAnalysis": {
230163              "graphics": {}
230164            },
230165            "considerations": {}
230166          }
230167        },
230168        {
230169          "type": "library",
230170          "bom-ref": "pkg:npm/vasync@2.2.1?package-id=a74a0eb0e1192243",
230171          "supplier": {},
230172          "name": "vasync",
230173          "version": "2.2.1",
230174          "licenses": [
230175            {
230176              "license": {
230177                "id": "MIT"
230178              }
230179            }
230180          ],
230181          "cpe": "cpe:2.3:a:vasync:vasync:2.2.1:*:*:*:*:*:*:*",
230182          "purl": "pkg:npm/vasync@2.2.1",
230183          "swid": {
230184            "attachment": {}
230185          },
230186          "pedigree": {},
230187          "evidence": {},
230188          "signature": {
230189            "signature": {
230190              "publicKey": {}
230191            }
230192          },
230193          "modelCard": {
230194            "modelParameters": {
230195              "approach": {}
230196            },
230197            "quantitativeAnalysis": {
230198              "graphics": {}
230199            },
230200            "considerations": {}
230201          }
230202        },
230203        {
230204          "type": "library",
230205          "bom-ref": "pkg:npm/verror@1.10.0?package-id=7d34167865ed5df2",
230206          "supplier": {},
230207          "name": "verror",
230208          "version": "1.10.0",
230209          "licenses": [
230210            {
230211              "license": {
230212                "id": "MIT"
230213              }
230214            }
230215          ],
230216          "cpe": "cpe:2.3:a:verror:verror:1.10.0:*:*:*:*:*:*:*",
230217          "purl": "pkg:npm/verror@1.10.0",
230218          "swid": {
230219            "attachment": {}
230220          },
230221          "pedigree": {},
230222          "evidence": {},
230223          "signature": {
230224            "signature": {
230225              "publicKey": {}
230226            }
230227          },
230228          "modelCard": {
230229            "modelParameters": {
230230              "approach": {}
230231            },
230232            "quantitativeAnalysis": {
230233              "graphics": {}
230234            },
230235            "considerations": {}
230236          }
230237        },
230238        {
230239          "type": "library",
230240          "bom-ref": "pkg:npm/vm2@3.9.17?package-id=2a67bae6147150f6",
230241          "supplier": {},
230242          "name": "vm2",
230243          "version": "3.9.17",
230244          "licenses": [
230245            {
230246              "license": {
230247                "id": "MIT"
230248              }
230249            }
230250          ],
230251          "cpe": "cpe:2.3:a:vm2:vm2:3.9.17:*:*:*:*:*:*:*",
230252          "purl": "pkg:npm/vm2@3.9.17",
230253          "swid": {
230254            "attachment": {}
230255          },
230256          "pedigree": {},
230257          "evidence": {},
230258          "signature": {
230259            "signature": {
230260              "publicKey": {}
230261            }
230262          },
230263          "modelCard": {
230264            "modelParameters": {
230265              "approach": {}
230266            },
230267            "quantitativeAnalysis": {
230268              "graphics": {}
230269            },
230270            "considerations": {}
230271          }
230272        },
230273        {
230274          "type": "library",
230275          "bom-ref": "pkg:npm/webidl-conversions@3.0.1?package-id=e4d685e7c081d58a",
230276          "supplier": {},
230277          "name": "webidl-conversions",
230278          "version": "3.0.1",
230279          "licenses": [
230280            {
230281              "license": {
230282                "id": "BSD-2-Clause"
230283              }
230284            }
230285          ],
230286          "cpe": "cpe:2.3:a:webidl-conversions:webidl-conversions:3.0.1:*:*:*:*:*:*:*",
230287          "purl": "pkg:npm/webidl-conversions@3.0.1",
230288          "swid": {
230289            "attachment": {}
230290          },
230291          "pedigree": {},
230292          "evidence": {},
230293          "signature": {
230294            "signature": {
230295              "publicKey": {}
230296            }
230297          },
230298          "modelCard": {
230299            "modelParameters": {
230300              "approach": {}
230301            },
230302            "quantitativeAnalysis": {
230303              "graphics": {}
230304            },
230305            "considerations": {}
230306          }
230307        },
230308        {
230309          "type": "library",
230310          "bom-ref": "pkg:npm/websocket-stream@5.5.2?package-id=aee8d7a01a1a4d8a",
230311          "supplier": {},
230312          "name": "websocket-stream",
230313          "version": "5.5.2",
230314          "licenses": [
230315            {
230316              "license": {
230317                "id": "BSD-2-Clause"
230318              }
230319            }
230320          ],
230321          "cpe": "cpe:2.3:a:websocket-stream:websocket-stream:5.5.2:*:*:*:*:*:*:*",
230322          "purl": "pkg:npm/websocket-stream@5.5.2",
230323          "swid": {
230324            "attachment": {}
230325          },
230326          "pedigree": {},
230327          "evidence": {},
230328          "signature": {
230329            "signature": {
230330              "publicKey": {}
230331            }
230332          },
230333          "modelCard": {
230334            "modelParameters": {
230335              "approach": {}
230336            },
230337            "quantitativeAnalysis": {
230338              "graphics": {}
230339            },
230340            "considerations": {}
230341          }
230342        },
230343        {
230344          "type": "library",
230345          "bom-ref": "pkg:npm/whatwg-url@5.0.0?package-id=f773ab8ee6c0a467",
230346          "supplier": {},
230347          "name": "whatwg-url",
230348          "version": "5.0.0",
230349          "licenses": [
230350            {
230351              "license": {
230352                "id": "MIT"
230353              }
230354            }
230355          ],
230356          "cpe": "cpe:2.3:a:whatwg-url:whatwg-url:5.0.0:*:*:*:*:*:*:*",
230357          "purl": "pkg:npm/whatwg-url@5.0.0",
230358          "swid": {
230359            "attachment": {}
230360          },
230361          "pedigree": {},
230362          "evidence": {},
230363          "signature": {
230364            "signature": {
230365              "publicKey": {}
230366            }
230367          },
230368          "modelCard": {
230369            "modelParameters": {
230370              "approach": {}
230371            },
230372            "quantitativeAnalysis": {
230373              "graphics": {}
230374            },
230375            "considerations": {}
230376          }
230377        },
230378        {
230379          "type": "library",
230380          "bom-ref": "pkg:npm/which@1.3.1?package-id=c6dc767d8b803349",
230381          "supplier": {},
230382          "name": "which",
230383          "version": "1.3.1",
230384          "licenses": [
230385            {
230386              "license": {
230387                "id": "ISC"
230388              }
230389            }
230390          ],
230391          "cpe": "cpe:2.3:a:which:which:1.3.1:*:*:*:*:*:*:*",
230392          "purl": "pkg:npm/which@1.3.1",
230393          "swid": {
230394            "attachment": {}
230395          },
230396          "pedigree": {},
230397          "evidence": {},
230398          "signature": {
230399            "signature": {
230400              "publicKey": {}
230401            }
230402          },
230403          "modelCard": {
230404            "modelParameters": {
230405              "approach": {}
230406            },
230407            "quantitativeAnalysis": {
230408              "graphics": {}
230409            },
230410            "considerations": {}
230411          }
230412        },
230413        {
230414          "type": "library",
230415          "bom-ref": "pkg:npm/wrap-ansi@7.0.0?package-id=a7ec557ea4be7637",
230416          "supplier": {},
230417          "name": "wrap-ansi",
230418          "version": "7.0.0",
230419          "licenses": [
230420            {
230421              "license": {
230422                "id": "MIT"
230423              }
230424            }
230425          ],
230426          "cpe": "cpe:2.3:a:wrap-ansi:wrap-ansi:7.0.0:*:*:*:*:*:*:*",
230427          "purl": "pkg:npm/wrap-ansi@7.0.0",
230428          "swid": {
230429            "attachment": {}
230430          },
230431          "pedigree": {},
230432          "evidence": {},
230433          "signature": {
230434            "signature": {
230435              "publicKey": {}
230436            }
230437          },
230438          "modelCard": {
230439            "modelParameters": {
230440              "approach": {}
230441            },
230442            "quantitativeAnalysis": {
230443              "graphics": {}
230444            },
230445            "considerations": {}
230446          }
230447        },
230448        {
230449          "type": "library",
230450          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=dd6d0718da9fb963",
230451          "supplier": {},
230452          "name": "wrappy",
230453          "version": "1.0.2",
230454          "licenses": [
230455            {
230456              "license": {
230457                "id": "ISC"
230458              }
230459            }
230460          ],
230461          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
230462          "purl": "pkg:npm/wrappy@1.0.2",
230463          "swid": {
230464            "attachment": {}
230465          },
230466          "pedigree": {},
230467          "evidence": {},
230468          "signature": {
230469            "signature": {
230470              "publicKey": {}
230471            }
230472          },
230473          "modelCard": {
230474            "modelParameters": {
230475              "approach": {}
230476            },
230477            "quantitativeAnalysis": {
230478              "graphics": {}
230479            },
230480            "considerations": {}
230481          }
230482        },
230483        {
230484          "type": "library",
230485          "bom-ref": "pkg:npm/ws@3.3.3?package-id=8f22f16bf14cdcb1",
230486          "supplier": {},
230487          "name": "ws",
230488          "version": "3.3.3",
230489          "licenses": [
230490            {
230491              "license": {
230492                "id": "MIT"
230493              }
230494            }
230495          ],
230496          "cpe": "cpe:2.3:a:ws:ws:3.3.3:*:*:*:*:*:*:*",
230497          "purl": "pkg:npm/ws@3.3.3",
230498          "swid": {
230499            "attachment": {}
230500          },
230501          "pedigree": {},
230502          "evidence": {},
230503          "signature": {
230504            "signature": {
230505              "publicKey": {}
230506            }
230507          },
230508          "modelCard": {
230509            "modelParameters": {
230510              "approach": {}
230511            },
230512            "quantitativeAnalysis": {
230513              "graphics": {}
230514            },
230515            "considerations": {}
230516          }
230517        },
230518        {
230519          "type": "library",
230520          "bom-ref": "pkg:npm/xml2js@0.4.23?package-id=8a1a1332606bd50f",
230521          "supplier": {},
230522          "name": "xml2js",
230523          "version": "0.4.23",
230524          "licenses": [
230525            {
230526              "license": {
230527                "id": "MIT"
230528              }
230529            }
230530          ],
230531          "cpe": "cpe:2.3:a:xml2js:xml2js:0.4.23:*:*:*:*:*:*:*",
230532          "purl": "pkg:npm/xml2js@0.4.23",
230533          "swid": {
230534            "attachment": {}
230535          },
230536          "pedigree": {},
230537          "evidence": {},
230538          "signature": {
230539            "signature": {
230540              "publicKey": {}
230541            }
230542          },
230543          "modelCard": {
230544            "modelParameters": {
230545              "approach": {}
230546            },
230547            "quantitativeAnalysis": {
230548              "graphics": {}
230549            },
230550            "considerations": {}
230551          }
230552        },
230553        {
230554          "type": "library",
230555          "bom-ref": "pkg:npm/xmlbuilder@11.0.1?package-id=ea247fd9c6bc1e81",
230556          "supplier": {},
230557          "name": "xmlbuilder",
230558          "version": "11.0.1",
230559          "licenses": [
230560            {
230561              "license": {
230562                "id": "MIT"
230563              }
230564            }
230565          ],
230566          "cpe": "cpe:2.3:a:xmlbuilder:xmlbuilder:11.0.1:*:*:*:*:*:*:*",
230567          "purl": "pkg:npm/xmlbuilder@11.0.1",
230568          "swid": {
230569            "attachment": {}
230570          },
230571          "pedigree": {},
230572          "evidence": {},
230573          "signature": {
230574            "signature": {
230575              "publicKey": {}
230576            }
230577          },
230578          "modelCard": {
230579            "modelParameters": {
230580              "approach": {}
230581            },
230582            "quantitativeAnalysis": {
230583              "graphics": {}
230584            },
230585            "considerations": {}
230586          }
230587        },
230588        {
230589          "type": "library",
230590          "bom-ref": "pkg:npm/xmlchars@2.2.0?package-id=652829b3677ee0df",
230591          "supplier": {},
230592          "name": "xmlchars",
230593          "version": "2.2.0",
230594          "licenses": [
230595            {
230596              "license": {
230597                "id": "MIT"
230598              }
230599            }
230600          ],
230601          "cpe": "cpe:2.3:a:xmlchars:xmlchars:2.2.0:*:*:*:*:*:*:*",
230602          "purl": "pkg:npm/xmlchars@2.2.0",
230603          "swid": {
230604            "attachment": {}
230605          },
230606          "pedigree": {},
230607          "evidence": {},
230608          "signature": {
230609            "signature": {
230610              "publicKey": {}
230611            }
230612          },
230613          "modelCard": {
230614            "modelParameters": {
230615              "approach": {}
230616            },
230617            "quantitativeAnalysis": {
230618              "graphics": {}
230619            },
230620            "considerations": {}
230621          }
230622        },
230623        {
230624          "type": "library",
230625          "bom-ref": "pkg:npm/xmldom@0.3.0?package-id=fa680282cd6f4515",
230626          "supplier": {},
230627          "name": "xmldom",
230628          "version": "0.3.0",
230629          "licenses": [
230630            {
230631              "license": {
230632                "name": "(LGPL-2.0 OR MIT)"
230633              }
230634            }
230635          ],
230636          "cpe": "cpe:2.3:a:xmldom:xmldom:0.3.0:*:*:*:*:*:*:*",
230637          "purl": "pkg:npm/xmldom@0.3.0",
230638          "swid": {
230639            "attachment": {}
230640          },
230641          "pedigree": {},
230642          "evidence": {},
230643          "signature": {
230644            "signature": {
230645              "publicKey": {}
230646            }
230647          },
230648          "modelCard": {
230649            "modelParameters": {
230650              "approach": {}
230651            },
230652            "quantitativeAnalysis": {
230653              "graphics": {}
230654            },
230655            "considerations": {}
230656          }
230657        },
230658        {
230659          "type": "library",
230660          "bom-ref": "pkg:npm/xpath@0.0.27?package-id=7b0515ef49c37f21",
230661          "supplier": {},
230662          "name": "xpath",
230663          "version": "0.0.27",
230664          "licenses": [
230665            {
230666              "license": {
230667                "id": "MIT"
230668              }
230669            }
230670          ],
230671          "cpe": "cpe:2.3:a:xpath:xpath:0.0.27:*:*:*:*:*:*:*",
230672          "purl": "pkg:npm/xpath@0.0.27",
230673          "swid": {
230674            "attachment": {}
230675          },
230676          "pedigree": {},
230677          "evidence": {},
230678          "signature": {
230679            "signature": {
230680              "publicKey": {}
230681            }
230682          },
230683          "modelCard": {
230684            "modelParameters": {
230685              "approach": {}
230686            },
230687            "quantitativeAnalysis": {
230688              "graphics": {}
230689            },
230690            "considerations": {}
230691          }
230692        },
230693        {
230694          "type": "library",
230695          "bom-ref": "pkg:npm/xpath.js@1.1.0?package-id=57a2a0e61dfcfd91",
230696          "supplier": {},
230697          "name": "xpath.js",
230698          "version": "1.1.0",
230699          "licenses": [
230700            {
230701              "license": {
230702                "id": "MIT"
230703              }
230704            }
230705          ],
230706          "cpe": "cpe:2.3:a:xpath.js:xpath.js:1.1.0:*:*:*:*:*:*:*",
230707          "purl": "pkg:npm/xpath.js@1.1.0",
230708          "swid": {
230709            "attachment": {}
230710          },
230711          "pedigree": {},
230712          "evidence": {},
230713          "signature": {
230714            "signature": {
230715              "publicKey": {}
230716            }
230717          },
230718          "modelCard": {
230719            "modelParameters": {
230720              "approach": {}
230721            },
230722            "quantitativeAnalysis": {
230723              "graphics": {}
230724            },
230725            "considerations": {}
230726          }
230727        },
230728        {
230729          "type": "library",
230730          "bom-ref": "pkg:npm/xtend@4.0.2?package-id=b451db5ef40dd530",
230731          "supplier": {},
230732          "name": "xtend",
230733          "version": "4.0.2",
230734          "licenses": [
230735            {
230736              "license": {
230737                "id": "MIT"
230738              }
230739            }
230740          ],
230741          "cpe": "cpe:2.3:a:xtend:xtend:4.0.2:*:*:*:*:*:*:*",
230742          "purl": "pkg:npm/xtend@4.0.2",
230743          "swid": {
230744            "attachment": {}
230745          },
230746          "pedigree": {},
230747          "evidence": {},
230748          "signature": {
230749            "signature": {
230750              "publicKey": {}
230751            }
230752          },
230753          "modelCard": {
230754            "modelParameters": {
230755              "approach": {}
230756            },
230757            "quantitativeAnalysis": {
230758              "graphics": {}
230759            },
230760            "considerations": {}
230761          }
230762        },
230763        {
230764          "type": "library",
230765          "bom-ref": "pkg:npm/y18n@5.0.8?package-id=5ea6ad91a0da81b9",
230766          "supplier": {},
230767          "name": "y18n",
230768          "version": "5.0.8",
230769          "licenses": [
230770            {
230771              "license": {
230772                "id": "ISC"
230773              }
230774            }
230775          ],
230776          "cpe": "cpe:2.3:a:y18n:y18n:5.0.8:*:*:*:*:*:*:*",
230777          "purl": "pkg:npm/y18n@5.0.8",
230778          "swid": {
230779            "attachment": {}
230780          },
230781          "pedigree": {},
230782          "evidence": {},
230783          "signature": {
230784            "signature": {
230785              "publicKey": {}
230786            }
230787          },
230788          "modelCard": {
230789            "modelParameters": {
230790              "approach": {}
230791            },
230792            "quantitativeAnalysis": {
230793              "graphics": {}
230794            },
230795            "considerations": {}
230796          }
230797        },
230798        {
230799          "type": "library",
230800          "bom-ref": "pkg:npm/yallist@4.0.0?package-id=b9ba8a2c34ea0780",
230801          "supplier": {},
230802          "name": "yallist",
230803          "version": "4.0.0",
230804          "licenses": [
230805            {
230806              "license": {
230807                "id": "ISC"
230808              }
230809            }
230810          ],
230811          "cpe": "cpe:2.3:a:yallist:yallist:4.0.0:*:*:*:*:*:*:*",
230812          "purl": "pkg:npm/yallist@4.0.0",
230813          "swid": {
230814            "attachment": {}
230815          },
230816          "pedigree": {},
230817          "evidence": {},
230818          "signature": {
230819            "signature": {
230820              "publicKey": {}
230821            }
230822          },
230823          "modelCard": {
230824            "modelParameters": {
230825              "approach": {}
230826            },
230827            "quantitativeAnalysis": {
230828              "graphics": {}
230829            },
230830            "considerations": {}
230831          }
230832        },
230833        {
230834          "type": "library",
230835          "bom-ref": "pkg:npm/yamljs@0.3.0?package-id=3d288a204b7dca48",
230836          "supplier": {},
230837          "name": "yamljs",
230838          "version": "0.3.0",
230839          "licenses": [
230840            {
230841              "license": {
230842                "id": "MIT"
230843              }
230844            }
230845          ],
230846          "cpe": "cpe:2.3:a:yamljs:yamljs:0.3.0:*:*:*:*:*:*:*",
230847          "purl": "pkg:npm/yamljs@0.3.0",
230848          "swid": {
230849            "attachment": {}
230850          },
230851          "pedigree": {},
230852          "evidence": {},
230853          "signature": {
230854            "signature": {
230855              "publicKey": {}
230856            }
230857          },
230858          "modelCard": {
230859            "modelParameters": {
230860              "approach": {}
230861            },
230862            "quantitativeAnalysis": {
230863              "graphics": {}
230864            },
230865            "considerations": {}
230866          }
230867        },
230868        {
230869          "type": "library",
230870          "bom-ref": "pkg:npm/yargs@17.7.1?package-id=2273b4a5f5593327",
230871          "supplier": {},
230872          "name": "yargs",
230873          "version": "17.7.1",
230874          "licenses": [
230875            {
230876              "license": {
230877                "id": "MIT"
230878              }
230879            }
230880          ],
230881          "cpe": "cpe:2.3:a:yargs:yargs:17.7.1:*:*:*:*:*:*:*",
230882          "purl": "pkg:npm/yargs@17.7.1",
230883          "swid": {
230884            "attachment": {}
230885          },
230886          "pedigree": {},
230887          "evidence": {},
230888          "signature": {
230889            "signature": {
230890              "publicKey": {}
230891            }
230892          },
230893          "modelCard": {
230894            "modelParameters": {
230895              "approach": {}
230896            },
230897            "quantitativeAnalysis": {
230898              "graphics": {}
230899            },
230900            "considerations": {}
230901          }
230902        },
230903        {
230904          "type": "library",
230905          "bom-ref": "pkg:npm/yargs-parser@21.1.1?package-id=848966d4da7d78d2",
230906          "supplier": {},
230907          "name": "yargs-parser",
230908          "version": "21.1.1",
230909          "licenses": [
230910            {
230911              "license": {
230912                "id": "ISC"
230913              }
230914            }
230915          ],
230916          "cpe": "cpe:2.3:a:yargs-parser:yargs-parser:21.1.1:*:*:*:*:*:*:*",
230917          "purl": "pkg:npm/yargs-parser@21.1.1",
230918          "swid": {
230919            "attachment": {}
230920          },
230921          "pedigree": {},
230922          "evidence": {},
230923          "signature": {
230924            "signature": {
230925              "publicKey": {}
230926            }
230927          },
230928          "modelCard": {
230929            "modelParameters": {
230930              "approach": {}
230931            },
230932            "quantitativeAnalysis": {
230933              "graphics": {}
230934            },
230935            "considerations": {}
230936          }
230937        },
230938        {
230939          "type": "library",
230940          "bom-ref": "pkg:npm/yauzl@2.10.0?package-id=e24663c0b2257231",
230941          "supplier": {},
230942          "name": "yauzl",
230943          "version": "2.10.0",
230944          "licenses": [
230945            {
230946              "license": {
230947                "id": "MIT"
230948              }
230949            }
230950          ],
230951          "cpe": "cpe:2.3:a:yauzl:yauzl:2.10.0:*:*:*:*:*:*:*",
230952          "purl": "pkg:npm/yauzl@2.10.0",
230953          "swid": {
230954            "attachment": {}
230955          },
230956          "pedigree": {},
230957          "evidence": {},
230958          "signature": {
230959            "signature": {
230960              "publicKey": {}
230961            }
230962          },
230963          "modelCard": {
230964            "modelParameters": {
230965              "approach": {}
230966            },
230967            "quantitativeAnalysis": {
230968              "graphics": {}
230969            },
230970            "considerations": {}
230971          }
230972        },
230973        {
230974          "type": "library",
230975          "bom-ref": "pkg:npm/zip-stream@4.1.0?package-id=3112e7c8747f2b66",
230976          "supplier": {},
230977          "name": "zip-stream",
230978          "version": "4.1.0",
230979          "licenses": [
230980            {
230981              "license": {
230982                "id": "MIT"
230983              }
230984            }
230985          ],
230986          "cpe": "cpe:2.3:a:zip-stream:zip-stream:4.1.0:*:*:*:*:*:*:*",
230987          "purl": "pkg:npm/zip-stream@4.1.0",
230988          "swid": {
230989            "attachment": {}
230990          },
230991          "pedigree": {},
230992          "evidence": {},
230993          "signature": {
230994            "signature": {
230995              "publicKey": {}
230996            }
230997          },
230998          "modelCard": {
230999            "modelParameters": {
231000              "approach": {}
231001            },
231002            "quantitativeAnalysis": {
231003              "graphics": {}
231004            },
231005            "considerations": {}
231006          }
231007        },
231008        {
231009          "type": "library",
231010          "bom-ref": "pkg:golang/./staging/src/k8s.io/api@(devel)?package-id=8c504ee48620498a",
231011          "supplier": {},
231012          "name": "./staging/src/k8s.io/api",
231013          "version": "(devel)",
231014          "cpe": "cpe:2.3:a:staging:src\\/k8s.io\\/api:\\(devel\\):*:*:*:*:*:*:*",
231015          "purl": "pkg:golang/./staging/src/k8s.io/api@(devel)",
231016          "swid": {
231017            "attachment": {}
231018          },
231019          "pedigree": {},
231020          "evidence": {},
231021          "signature": {
231022            "signature": {
231023              "publicKey": {}
231024            }
231025          },
231026          "modelCard": {
231027            "modelParameters": {
231028              "approach": {}
231029            },
231030            "quantitativeAnalysis": {
231031              "graphics": {}
231032            },
231033            "considerations": {}
231034          }
231035        },
231036        {
231037          "type": "library",
231038          "bom-ref": "pkg:golang/./staging/src/k8s.io/apimachinery@(devel)?package-id=220bb807a073597d",
231039          "supplier": {},
231040          "name": "./staging/src/k8s.io/apimachinery",
231041          "version": "(devel)",
231042          "cpe": "cpe:2.3:a:staging:src\\/k8s.io\\/apimachinery:\\(devel\\):*:*:*:*:*:*:*",
231043          "purl": "pkg:golang/./staging/src/k8s.io/apimachinery@(devel)",
231044          "swid": {
231045            "attachment": {}
231046          },
231047          "pedigree": {},
231048          "evidence": {},
231049          "signature": {
231050            "signature": {
231051              "publicKey": {}
231052            }
231053          },
231054          "modelCard": {
231055            "modelParameters": {
231056              "approach": {}
231057            },
231058            "quantitativeAnalysis": {
231059              "graphics": {}
231060            },
231061            "considerations": {}
231062          }
231063        },
231064        {
231065          "type": "library",
231066          "bom-ref": "pkg:golang/./staging/src/k8s.io/cli-runtime@(devel)?package-id=c03ef8ed2db7d259",
231067          "supplier": {},
231068          "name": "./staging/src/k8s.io/cli-runtime",
231069          "version": "(devel)",
231070          "cpe": "cpe:2.3:a:staging:src\\/k8s.io\\/cli-runtime:\\(devel\\):*:*:*:*:*:*:*",
231071          "purl": "pkg:golang/./staging/src/k8s.io/cli-runtime@(devel)",
231072          "swid": {
231073            "attachment": {}
231074          },
231075          "pedigree": {},
231076          "evidence": {},
231077          "signature": {
231078            "signature": {
231079              "publicKey": {}
231080            }
231081          },
231082          "modelCard": {
231083            "modelParameters": {
231084              "approach": {}
231085            },
231086            "quantitativeAnalysis": {
231087              "graphics": {}
231088            },
231089            "considerations": {}
231090          }
231091        },
231092        {
231093          "type": "library",
231094          "bom-ref": "pkg:golang/./staging/src/k8s.io/client-go@(devel)?package-id=3da4e7a1466b3dea",
231095          "supplier": {},
231096          "name": "./staging/src/k8s.io/client-go",
231097          "version": "(devel)",
231098          "cpe": "cpe:2.3:a:staging:src\\/k8s.io\\/client-go:\\(devel\\):*:*:*:*:*:*:*",
231099          "purl": "pkg:golang/./staging/src/k8s.io/client-go@(devel)",
231100          "swid": {
231101            "attachment": {}
231102          },
231103          "pedigree": {},
231104          "evidence": {},
231105          "signature": {
231106            "signature": {
231107              "publicKey": {}
231108            }
231109          },
231110          "modelCard": {
231111            "modelParameters": {
231112              "approach": {}
231113            },
231114            "quantitativeAnalysis": {
231115              "graphics": {}
231116            },
231117            "considerations": {}
231118          }
231119        },
231120        {
231121          "type": "library",
231122          "bom-ref": "pkg:golang/./staging/src/k8s.io/component-base@(devel)?package-id=a449ca6151d5ecf1",
231123          "supplier": {},
231124          "name": "./staging/src/k8s.io/component-base",
231125          "version": "(devel)",
231126          "cpe": "cpe:2.3:a:staging:src\\/k8s.io\\/component-base:\\(devel\\):*:*:*:*:*:*:*",
231127          "purl": "pkg:golang/./staging/src/k8s.io/component-base@(devel)",
231128          "swid": {
231129            "attachment": {}
231130          },
231131          "pedigree": {},
231132          "evidence": {},
231133          "signature": {
231134            "signature": {
231135              "publicKey": {}
231136            }
231137          },
231138          "modelCard": {
231139            "modelParameters": {
231140              "approach": {}
231141            },
231142            "quantitativeAnalysis": {
231143              "graphics": {}
231144            },
231145            "considerations": {}
231146          }
231147        },
231148        {
231149          "type": "library",
231150          "bom-ref": "pkg:golang/./staging/src/k8s.io/component-helpers@(devel)?package-id=2eed2e7145e62a15",
231151          "supplier": {},
231152          "name": "./staging/src/k8s.io/component-helpers",
231153          "version": "(devel)",
231154          "cpe": "cpe:2.3:a:staging:src\\/k8s.io\\/component-helpers:\\(devel\\):*:*:*:*:*:*:*",
231155          "purl": "pkg:golang/./staging/src/k8s.io/component-helpers@(devel)",
231156          "swid": {
231157            "attachment": {}
231158          },
231159          "pedigree": {},
231160          "evidence": {},
231161          "signature": {
231162            "signature": {
231163              "publicKey": {}
231164            }
231165          },
231166          "modelCard": {
231167            "modelParameters": {
231168              "approach": {}
231169            },
231170            "quantitativeAnalysis": {
231171              "graphics": {}
231172            },
231173            "considerations": {}
231174          }
231175        },
231176        {
231177          "type": "library",
231178          "bom-ref": "pkg:golang/./staging/src/k8s.io/kubectl@(devel)?package-id=de0a9f8a5d651442",
231179          "supplier": {},
231180          "name": "./staging/src/k8s.io/kubectl",
231181          "version": "(devel)",
231182          "cpe": "cpe:2.3:a:staging:src\\/k8s.io\\/kubectl:\\(devel\\):*:*:*:*:*:*:*",
231183          "purl": "pkg:golang/./staging/src/k8s.io/kubectl@(devel)",
231184          "swid": {
231185            "attachment": {}
231186          },
231187          "pedigree": {},
231188          "evidence": {},
231189          "signature": {
231190            "signature": {
231191              "publicKey": {}
231192            }
231193          },
231194          "modelCard": {
231195            "modelParameters": {
231196              "approach": {}
231197            },
231198            "quantitativeAnalysis": {
231199              "graphics": {}
231200            },
231201            "considerations": {}
231202          }
231203        },
231204        {
231205          "type": "library",
231206          "bom-ref": "pkg:golang/./staging/src/k8s.io/metrics@(devel)?package-id=4fdf96d4b53f374e",
231207          "supplier": {},
231208          "name": "./staging/src/k8s.io/metrics",
231209          "version": "(devel)",
231210          "cpe": "cpe:2.3:a:staging:src\\/k8s.io\\/metrics:\\(devel\\):*:*:*:*:*:*:*",
231211          "purl": "pkg:golang/./staging/src/k8s.io/metrics@(devel)",
231212          "swid": {
231213            "attachment": {}
231214          },
231215          "pedigree": {},
231216          "evidence": {},
231217          "signature": {
231218            "signature": {
231219              "publicKey": {}
231220            }
231221          },
231222          "modelCard": {
231223            "modelParameters": {
231224              "approach": {}
231225            },
231226            "quantitativeAnalysis": {
231227              "graphics": {}
231228            },
231229            "considerations": {}
231230          }
231231        },
231232        {
231233          "type": "library",
231234          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=61f27796f703939",
231235          "supplier": {},
231236          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
231237          "name": "alpine-baselayout",
231238          "version": "3.2.0-r3",
231239          "description": "Alpine base dir structure and init scripts",
231240          "licenses": [
231241            {
231242              "license": {
231243                "id": "GPL-2.0-only"
231244              }
231245            }
231246          ],
231247          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r3:*:*:*:*:*:*:*",
231248          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r3?arch=x86_64\u0026distro=alpine-3.11.13",
231249          "swid": {
231250            "attachment": {}
231251          },
231252          "pedigree": {},
231253          "externalReferences": [
231254            {
231255              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
231256              "type": "distribution"
231257            }
231258          ],
231259          "evidence": {},
231260          "signature": {
231261            "signature": {
231262              "publicKey": {}
231263            }
231264          },
231265          "modelCard": {
231266            "modelParameters": {
231267              "approach": {}
231268            },
231269            "quantitativeAnalysis": {
231270              "graphics": {}
231271            },
231272            "considerations": {}
231273          }
231274        },
231275        {
231276          "type": "library",
231277          "bom-ref": "pkg:apk/alpine/alpine-keys@2.1-r2?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=79f884384758c443",
231278          "supplier": {},
231279          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
231280          "name": "alpine-keys",
231281          "version": "2.1-r2",
231282          "description": "Public keys for Alpine Linux packages",
231283          "licenses": [
231284            {
231285              "license": {
231286                "id": "MIT"
231287              }
231288            }
231289          ],
231290          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.1-r2:*:*:*:*:*:*:*",
231291          "purl": "pkg:apk/alpine/alpine-keys@2.1-r2?arch=x86_64\u0026distro=alpine-3.11.13",
231292          "swid": {
231293            "attachment": {}
231294          },
231295          "pedigree": {},
231296          "externalReferences": [
231297            {
231298              "url": "https://alpinelinux.org",
231299              "type": "distribution"
231300            }
231301          ],
231302          "evidence": {},
231303          "signature": {
231304            "signature": {
231305              "publicKey": {}
231306            }
231307          },
231308          "modelCard": {
231309            "modelParameters": {
231310              "approach": {}
231311            },
231312            "quantitativeAnalysis": {
231313              "graphics": {}
231314            },
231315            "considerations": {}
231316          }
231317        },
231318        {
231319          "type": "library",
231320          "bom-ref": "pkg:apk/alpine/apk-tools@2.10.8-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=28993d8277c2c4f",
231321          "supplier": {},
231322          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
231323          "name": "apk-tools",
231324          "version": "2.10.8-r0",
231325          "description": "Alpine Package Keeper - package manager for alpine",
231326          "licenses": [
231327            {
231328              "license": {
231329                "id": "GPL-2.0-only"
231330              }
231331            }
231332          ],
231333          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.10.8-r0:*:*:*:*:*:*:*",
231334          "purl": "pkg:apk/alpine/apk-tools@2.10.8-r0?arch=x86_64\u0026distro=alpine-3.11.13",
231335          "swid": {
231336            "attachment": {}
231337          },
231338          "pedigree": {},
231339          "externalReferences": [
231340            {
231341              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
231342              "type": "distribution"
231343            }
231344          ],
231345          "evidence": {},
231346          "signature": {
231347            "signature": {
231348              "publicKey": {}
231349            }
231350          },
231351          "modelCard": {
231352            "modelParameters": {
231353              "approach": {}
231354            },
231355            "quantitativeAnalysis": {
231356              "graphics": {}
231357            },
231358            "considerations": {}
231359          }
231360        },
231361        {
231362          "type": "application",
231363          "bom-ref": "eb62c645e9680ee0",
231364          "supplier": {},
231365          "name": "busybox",
231366          "version": "1.31.1",
231367          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1:*:*:*:*:*:*:*",
231368          "swid": {
231369            "attachment": {}
231370          },
231371          "pedigree": {},
231372          "evidence": {},
231373          "signature": {
231374            "signature": {
231375              "publicKey": {}
231376            }
231377          },
231378          "modelCard": {
231379            "modelParameters": {
231380              "approach": {}
231381            },
231382            "quantitativeAnalysis": {
231383              "graphics": {}
231384            },
231385            "considerations": {}
231386          }
231387        },
231388        {
231389          "type": "library",
231390          "bom-ref": "pkg:apk/alpine/busybox@1.31.1-r11?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=3f3095cbef6e353",
231391          "supplier": {},
231392          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
231393          "name": "busybox",
231394          "version": "1.31.1-r11",
231395          "description": "Size optimized toolbox of many common UNIX utilities",
231396          "licenses": [
231397            {
231398              "license": {
231399                "id": "GPL-2.0-only"
231400              }
231401            }
231402          ],
231403          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1-r11:*:*:*:*:*:*:*",
231404          "purl": "pkg:apk/alpine/busybox@1.31.1-r11?arch=x86_64\u0026distro=alpine-3.11.13",
231405          "swid": {
231406            "attachment": {}
231407          },
231408          "pedigree": {},
231409          "externalReferences": [
231410            {
231411              "url": "https://busybox.net/",
231412              "type": "distribution"
231413            }
231414          ],
231415          "evidence": {},
231416          "signature": {
231417            "signature": {
231418              "publicKey": {}
231419            }
231420          },
231421          "modelCard": {
231422            "modelParameters": {
231423              "approach": {}
231424            },
231425            "quantitativeAnalysis": {
231426              "graphics": {}
231427            },
231428            "considerations": {}
231429          }
231430        },
231431        {
231432          "type": "library",
231433          "bom-ref": "pkg:apk/alpine/ca-certificates@20191127-r2?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=91490583c2f9b81b",
231434          "supplier": {},
231435          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
231436          "name": "ca-certificates",
231437          "version": "20191127-r2",
231438          "description": "Common CA certificates PEM files from Mozilla",
231439          "licenses": [
231440            {
231441              "license": {
231442                "id": "MPL-2.0"
231443              }
231444            },
231445            {
231446              "license": {
231447                "id": "GPL-2.0-or-later"
231448              }
231449            }
231450          ],
231451          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20191127-r2:*:*:*:*:*:*:*",
231452          "purl": "pkg:apk/alpine/ca-certificates@20191127-r2?arch=x86_64\u0026distro=alpine-3.11.13",
231453          "swid": {
231454            "attachment": {}
231455          },
231456          "pedigree": {},
231457          "externalReferences": [
231458            {
231459              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
231460              "type": "distribution"
231461            }
231462          ],
231463          "evidence": {},
231464          "signature": {
231465            "signature": {
231466              "publicKey": {}
231467            }
231468          },
231469          "modelCard": {
231470            "modelParameters": {
231471              "approach": {}
231472            },
231473            "quantitativeAnalysis": {
231474              "graphics": {}
231475            },
231476            "considerations": {}
231477          }
231478        },
231479        {
231480          "type": "library",
231481          "bom-ref": "pkg:apk/alpine/ca-certificates-cacert@20191127-r2?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.11.13\u0026package-id=e135ce85ed757130",
231482          "supplier": {},
231483          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
231484          "name": "ca-certificates-cacert",
231485          "version": "20191127-r2",
231486          "description": "Mozilla bundled certificates",
231487          "licenses": [
231488            {
231489              "license": {
231490                "id": "MPL-2.0"
231491              }
231492            },
231493            {
231494              "license": {
231495                "id": "GPL-2.0-or-later"
231496              }
231497            }
231498          ],
231499          "cpe": "cpe:2.3:a:ca-certificates-cacert:ca-certificates-cacert:20191127-r2:*:*:*:*:*:*:*",
231500          "purl": "pkg:apk/alpine/ca-certificates-cacert@20191127-r2?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.11.13",
231501          "swid": {
231502            "attachment": {}
231503          },
231504          "pedigree": {},
231505          "externalReferences": [
231506            {
231507              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
231508              "type": "distribution"
231509            }
231510          ],
231511          "evidence": {},
231512          "signature": {
231513            "signature": {
231514              "publicKey": {}
231515            }
231516          },
231517          "modelCard": {
231518            "modelParameters": {
231519              "approach": {}
231520            },
231521            "quantitativeAnalysis": {
231522              "graphics": {}
231523            },
231524            "considerations": {}
231525          }
231526        },
231527        {
231528          "type": "library",
231529          "bom-ref": "pkg:golang/cloud.google.com/go@v0.97.0?package-id=c19586b9df3c7a14",
231530          "supplier": {},
231531          "name": "cloud.google.com/go",
231532          "version": "v0.97.0",
231533          "purl": "pkg:golang/cloud.google.com/go@v0.97.0",
231534          "swid": {
231535            "attachment": {}
231536          },
231537          "pedigree": {},
231538          "evidence": {},
231539          "signature": {
231540            "signature": {
231541              "publicKey": {}
231542            }
231543          },
231544          "modelCard": {
231545            "modelParameters": {
231546              "approach": {}
231547            },
231548            "quantitativeAnalysis": {
231549              "graphics": {}
231550            },
231551            "considerations": {}
231552          }
231553        },
231554        {
231555          "type": "library",
231556          "bom-ref": "pkg:apk/alpine/curl@7.79.1-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=d9c1833e179a6443",
231557          "supplier": {},
231558          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
231559          "name": "curl",
231560          "version": "7.79.1-r0",
231561          "description": "URL retrival utility and library",
231562          "licenses": [
231563            {
231564              "license": {
231565                "id": "MIT"
231566              }
231567            }
231568          ],
231569          "cpe": "cpe:2.3:a:curl:curl:7.79.1-r0:*:*:*:*:*:*:*",
231570          "purl": "pkg:apk/alpine/curl@7.79.1-r0?arch=x86_64\u0026distro=alpine-3.11.13",
231571          "swid": {
231572            "attachment": {}
231573          },
231574          "pedigree": {},
231575          "externalReferences": [
231576            {
231577              "url": "https://curl.haxx.se/",
231578              "type": "distribution"
231579            }
231580          ],
231581          "evidence": {},
231582          "signature": {
231583            "signature": {
231584              "publicKey": {}
231585            }
231586          },
231587          "modelCard": {
231588            "modelParameters": {
231589              "approach": {}
231590            },
231591            "quantitativeAnalysis": {
231592              "graphics": {}
231593            },
231594            "considerations": {}
231595          }
231596        },
231597        {
231598          "type": "library",
231599          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest@v0.11.27?package-id=fe60404b9e3c0866",
231600          "supplier": {},
231601          "name": "github.com/Azure/go-autorest/autorest",
231602          "version": "v0.11.27",
231603          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest:v0.11.27:*:*:*:*:*:*:*",
231604          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest@v0.11.27",
231605          "swid": {
231606            "attachment": {}
231607          },
231608          "pedigree": {},
231609          "evidence": {},
231610          "signature": {
231611            "signature": {
231612              "publicKey": {}
231613            }
231614          },
231615          "modelCard": {
231616            "modelParameters": {
231617              "approach": {}
231618            },
231619            "quantitativeAnalysis": {
231620              "graphics": {}
231621            },
231622            "considerations": {}
231623          }
231624        },
231625        {
231626          "type": "library",
231627          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest/adal@v0.9.20?package-id=873ac1fa330e8fe1",
231628          "supplier": {},
231629          "name": "github.com/Azure/go-autorest/autorest/adal",
231630          "version": "v0.9.20",
231631          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest\\/adal:v0.9.20:*:*:*:*:*:*:*",
231632          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest/adal@v0.9.20",
231633          "swid": {
231634            "attachment": {}
231635          },
231636          "pedigree": {},
231637          "evidence": {},
231638          "signature": {
231639            "signature": {
231640              "publicKey": {}
231641            }
231642          },
231643          "modelCard": {
231644            "modelParameters": {
231645              "approach": {}
231646            },
231647            "quantitativeAnalysis": {
231648              "graphics": {}
231649            },
231650            "considerations": {}
231651          }
231652        },
231653        {
231654          "type": "library",
231655          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest/date@v0.3.0?package-id=78f14f0bb0400efc",
231656          "supplier": {},
231657          "name": "github.com/Azure/go-autorest/autorest/date",
231658          "version": "v0.3.0",
231659          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest\\/date:v0.3.0:*:*:*:*:*:*:*",
231660          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest/date@v0.3.0",
231661          "swid": {
231662            "attachment": {}
231663          },
231664          "pedigree": {},
231665          "evidence": {},
231666          "signature": {
231667            "signature": {
231668              "publicKey": {}
231669            }
231670          },
231671          "modelCard": {
231672            "modelParameters": {
231673              "approach": {}
231674            },
231675            "quantitativeAnalysis": {
231676              "graphics": {}
231677            },
231678            "considerations": {}
231679          }
231680        },
231681        {
231682          "type": "library",
231683          "bom-ref": "pkg:golang/github.com/azure/go-autorest/logger@v0.2.1?package-id=f0f891d194b0a30b",
231684          "supplier": {},
231685          "name": "github.com/Azure/go-autorest/logger",
231686          "version": "v0.2.1",
231687          "cpe": "cpe:2.3:a:Azure:go-autorest\\/logger:v0.2.1:*:*:*:*:*:*:*",
231688          "purl": "pkg:golang/github.com/Azure/go-autorest/logger@v0.2.1",
231689          "swid": {
231690            "attachment": {}
231691          },
231692          "pedigree": {},
231693          "evidence": {},
231694          "signature": {
231695            "signature": {
231696              "publicKey": {}
231697            }
231698          },
231699          "modelCard": {
231700            "modelParameters": {
231701              "approach": {}
231702            },
231703            "quantitativeAnalysis": {
231704              "graphics": {}
231705            },
231706            "considerations": {}
231707          }
231708        },
231709        {
231710          "type": "library",
231711          "bom-ref": "pkg:golang/github.com/azure/go-autorest/tracing@v0.6.0?package-id=6c81ba59d97a8733",
231712          "supplier": {},
231713          "name": "github.com/Azure/go-autorest/tracing",
231714          "version": "v0.6.0",
231715          "cpe": "cpe:2.3:a:Azure:go-autorest\\/tracing:v0.6.0:*:*:*:*:*:*:*",
231716          "purl": "pkg:golang/github.com/Azure/go-autorest/tracing@v0.6.0",
231717          "swid": {
231718            "attachment": {}
231719          },
231720          "pedigree": {},
231721          "evidence": {},
231722          "signature": {
231723            "signature": {
231724              "publicKey": {}
231725            }
231726          },
231727          "modelCard": {
231728            "modelParameters": {
231729              "approach": {}
231730            },
231731            "quantitativeAnalysis": {
231732              "graphics": {}
231733            },
231734            "considerations": {}
231735          }
231736        },
231737        {
231738          "type": "library",
231739          "bom-ref": "pkg:golang/github.com/makenowjust/heredoc@v1.0.0?package-id=c62cf0203fee57b2",
231740          "supplier": {},
231741          "name": "github.com/MakeNowJust/heredoc",
231742          "version": "v1.0.0",
231743          "cpe": "cpe:2.3:a:MakeNowJust:heredoc:v1.0.0:*:*:*:*:*:*:*",
231744          "purl": "pkg:golang/github.com/MakeNowJust/heredoc@v1.0.0",
231745          "swid": {
231746            "attachment": {}
231747          },
231748          "pedigree": {},
231749          "evidence": {},
231750          "signature": {
231751            "signature": {
231752              "publicKey": {}
231753            }
231754          },
231755          "modelCard": {
231756            "modelParameters": {
231757              "approach": {}
231758            },
231759            "quantitativeAnalysis": {
231760              "graphics": {}
231761            },
231762            "considerations": {}
231763          }
231764        },
231765        {
231766          "type": "library",
231767          "bom-ref": "pkg:golang/github.com/puerkitobio/purell@v1.1.1?package-id=6e3fe172793f5f",
231768          "supplier": {},
231769          "name": "github.com/PuerkitoBio/purell",
231770          "version": "v1.1.1",
231771          "cpe": "cpe:2.3:a:PuerkitoBio:purell:v1.1.1:*:*:*:*:*:*:*",
231772          "purl": "pkg:golang/github.com/PuerkitoBio/purell@v1.1.1",
231773          "swid": {
231774            "attachment": {}
231775          },
231776          "pedigree": {},
231777          "evidence": {},
231778          "signature": {
231779            "signature": {
231780              "publicKey": {}
231781            }
231782          },
231783          "modelCard": {
231784            "modelParameters": {
231785              "approach": {}
231786            },
231787            "quantitativeAnalysis": {
231788              "graphics": {}
231789            },
231790            "considerations": {}
231791          }
231792        },
231793        {
231794          "type": "library",
231795          "bom-ref": "pkg:golang/github.com/puerkitobio/urlesc@v0.0.0-20170810143723-de5bf2ad4578?package-id=eb8d0318308efc37",
231796          "supplier": {},
231797          "name": "github.com/PuerkitoBio/urlesc",
231798          "version": "v0.0.0-20170810143723-de5bf2ad4578",
231799          "cpe": "cpe:2.3:a:PuerkitoBio:urlesc:v0.0.0-20170810143723-de5bf2ad4578:*:*:*:*:*:*:*",
231800          "purl": "pkg:golang/github.com/PuerkitoBio/urlesc@v0.0.0-20170810143723-de5bf2ad4578",
231801          "swid": {
231802            "attachment": {}
231803          },
231804          "pedigree": {},
231805          "evidence": {},
231806          "signature": {
231807            "signature": {
231808              "publicKey": {}
231809            }
231810          },
231811          "modelCard": {
231812            "modelParameters": {
231813              "approach": {}
231814            },
231815            "quantitativeAnalysis": {
231816              "graphics": {}
231817            },
231818            "considerations": {}
231819          }
231820        },
231821        {
231822          "type": "library",
231823          "bom-ref": "pkg:golang/github.com/chai2010/gettext-go@v1.0.2?package-id=b9404182e4ac7886",
231824          "supplier": {},
231825          "name": "github.com/chai2010/gettext-go",
231826          "version": "v1.0.2",
231827          "cpe": "cpe:2.3:a:chai2010:gettext-go:v1.0.2:*:*:*:*:*:*:*",
231828          "purl": "pkg:golang/github.com/chai2010/gettext-go@v1.0.2",
231829          "swid": {
231830            "attachment": {}
231831          },
231832          "pedigree": {},
231833          "evidence": {},
231834          "signature": {
231835            "signature": {
231836              "publicKey": {}
231837            }
231838          },
231839          "modelCard": {
231840            "modelParameters": {
231841              "approach": {}
231842            },
231843            "quantitativeAnalysis": {
231844              "graphics": {}
231845            },
231846            "considerations": {}
231847          }
231848        },
231849        {
231850          "type": "library",
231851          "bom-ref": "pkg:golang/github.com/davecgh/go-spew@v1.1.1?package-id=c6969379e4ccf85d",
231852          "supplier": {},
231853          "name": "github.com/davecgh/go-spew",
231854          "version": "v1.1.1",
231855          "cpe": "cpe:2.3:a:davecgh:go-spew:v1.1.1:*:*:*:*:*:*:*",
231856          "purl": "pkg:golang/github.com/davecgh/go-spew@v1.1.1",
231857          "swid": {
231858            "attachment": {}
231859          },
231860          "pedigree": {},
231861          "evidence": {},
231862          "signature": {
231863            "signature": {
231864              "publicKey": {}
231865            }
231866          },
231867          "modelCard": {
231868            "modelParameters": {
231869              "approach": {}
231870            },
231871            "quantitativeAnalysis": {
231872              "graphics": {}
231873            },
231874            "considerations": {}
231875          }
231876        },
231877        {
231878          "type": "library",
231879          "bom-ref": "pkg:golang/github.com/daviddengcn/go-colortext@v1.0.0?package-id=1c57de1c1df43d89",
231880          "supplier": {},
231881          "name": "github.com/daviddengcn/go-colortext",
231882          "version": "v1.0.0",
231883          "cpe": "cpe:2.3:a:daviddengcn:go-colortext:v1.0.0:*:*:*:*:*:*:*",
231884          "purl": "pkg:golang/github.com/daviddengcn/go-colortext@v1.0.0",
231885          "swid": {
231886            "attachment": {}
231887          },
231888          "pedigree": {},
231889          "evidence": {},
231890          "signature": {
231891            "signature": {
231892              "publicKey": {}
231893            }
231894          },
231895          "modelCard": {
231896            "modelParameters": {
231897              "approach": {}
231898            },
231899            "quantitativeAnalysis": {
231900              "graphics": {}
231901            },
231902            "considerations": {}
231903          }
231904        },
231905        {
231906          "type": "library",
231907          "bom-ref": "pkg:golang/github.com/docker/distribution@v2.8.1+incompatible?package-id=ef2706a361249766",
231908          "supplier": {},
231909          "name": "github.com/docker/distribution",
231910          "version": "v2.8.1+incompatible",
231911          "cpe": "cpe:2.3:a:docker:distribution:v2.8.1\\+incompatible:*:*:*:*:*:*:*",
231912          "purl": "pkg:golang/github.com/docker/distribution@v2.8.1+incompatible",
231913          "swid": {
231914            "attachment": {}
231915          },
231916          "pedigree": {},
231917          "evidence": {},
231918          "signature": {
231919            "signature": {
231920              "publicKey": {}
231921            }
231922          },
231923          "modelCard": {
231924            "modelParameters": {
231925              "approach": {}
231926            },
231927            "quantitativeAnalysis": {
231928              "graphics": {}
231929            },
231930            "considerations": {}
231931          }
231932        },
231933        {
231934          "type": "library",
231935          "bom-ref": "pkg:golang/github.com/emicklei/go-restful/v3@v3.8.0?package-id=fc2ca4a8df2bd60b",
231936          "supplier": {},
231937          "name": "github.com/emicklei/go-restful/v3",
231938          "version": "v3.8.0",
231939          "cpe": "cpe:2.3:a:emicklei:go-restful\\/v3:v3.8.0:*:*:*:*:*:*:*",
231940          "purl": "pkg:golang/github.com/emicklei/go-restful/v3@v3.8.0",
231941          "swid": {
231942            "attachment": {}
231943          },
231944          "pedigree": {},
231945          "evidence": {},
231946          "signature": {
231947            "signature": {
231948              "publicKey": {}
231949            }
231950          },
231951          "modelCard": {
231952            "modelParameters": {
231953              "approach": {}
231954            },
231955            "quantitativeAnalysis": {
231956              "graphics": {}
231957            },
231958            "considerations": {}
231959          }
231960        },
231961        {
231962          "type": "library",
231963          "bom-ref": "pkg:golang/github.com/evanphx/json-patch@v4.12.0+incompatible?package-id=e145ece2c9466355",
231964          "supplier": {},
231965          "name": "github.com/evanphx/json-patch",
231966          "version": "v4.12.0+incompatible",
231967          "cpe": "cpe:2.3:a:evanphx:json-patch:v4.12.0\\+incompatible:*:*:*:*:*:*:*",
231968          "purl": "pkg:golang/github.com/evanphx/json-patch@v4.12.0+incompatible",
231969          "swid": {
231970            "attachment": {}
231971          },
231972          "pedigree": {},
231973          "evidence": {},
231974          "signature": {
231975            "signature": {
231976              "publicKey": {}
231977            }
231978          },
231979          "modelCard": {
231980            "modelParameters": {
231981              "approach": {}
231982            },
231983            "quantitativeAnalysis": {
231984              "graphics": {}
231985            },
231986            "considerations": {}
231987          }
231988        },
231989        {
231990          "type": "library",
231991          "bom-ref": "pkg:golang/github.com/exponent-io/jsonpath@v0.0.0-20151013193312-d6023ce2651d?package-id=449d65077b2ab2bd",
231992          "supplier": {},
231993          "name": "github.com/exponent-io/jsonpath",
231994          "version": "v0.0.0-20151013193312-d6023ce2651d",
231995          "cpe": "cpe:2.3:a:exponent-io:jsonpath:v0.0.0-20151013193312-d6023ce2651d:*:*:*:*:*:*:*",
231996          "purl": "pkg:golang/github.com/exponent-io/jsonpath@v0.0.0-20151013193312-d6023ce2651d",
231997          "swid": {
231998            "attachment": {}
231999          },
232000          "pedigree": {},
232001          "evidence": {},
232002          "signature": {
232003            "signature": {
232004              "publicKey": {}
232005            }
232006          },
232007          "modelCard": {
232008            "modelParameters": {
232009              "approach": {}
232010            },
232011            "quantitativeAnalysis": {
232012              "graphics": {}
232013            },
232014            "considerations": {}
232015          }
232016        },
232017        {
232018          "type": "library",
232019          "bom-ref": "pkg:golang/github.com/fatih/camelcase@v1.0.0?package-id=e6c83c1797b8b972",
232020          "supplier": {},
232021          "name": "github.com/fatih/camelcase",
232022          "version": "v1.0.0",
232023          "cpe": "cpe:2.3:a:fatih:camelcase:v1.0.0:*:*:*:*:*:*:*",
232024          "purl": "pkg:golang/github.com/fatih/camelcase@v1.0.0",
232025          "swid": {
232026            "attachment": {}
232027          },
232028          "pedigree": {},
232029          "evidence": {},
232030          "signature": {
232031            "signature": {
232032              "publicKey": {}
232033            }
232034          },
232035          "modelCard": {
232036            "modelParameters": {
232037              "approach": {}
232038            },
232039            "quantitativeAnalysis": {
232040              "graphics": {}
232041            },
232042            "considerations": {}
232043          }
232044        },
232045        {
232046          "type": "library",
232047          "bom-ref": "pkg:golang/github.com/fvbommel/sortorder@v1.0.1?package-id=5fd7c07954ce275e",
232048          "supplier": {},
232049          "name": "github.com/fvbommel/sortorder",
232050          "version": "v1.0.1",
232051          "cpe": "cpe:2.3:a:fvbommel:sortorder:v1.0.1:*:*:*:*:*:*:*",
232052          "purl": "pkg:golang/github.com/fvbommel/sortorder@v1.0.1",
232053          "swid": {
232054            "attachment": {}
232055          },
232056          "pedigree": {},
232057          "evidence": {},
232058          "signature": {
232059            "signature": {
232060              "publicKey": {}
232061            }
232062          },
232063          "modelCard": {
232064            "modelParameters": {
232065              "approach": {}
232066            },
232067            "quantitativeAnalysis": {
232068              "graphics": {}
232069            },
232070            "considerations": {}
232071          }
232072        },
232073        {
232074          "type": "library",
232075          "bom-ref": "pkg:golang/github.com/go-errors/errors@v1.0.1?package-id=c0affd76def6a291",
232076          "supplier": {},
232077          "name": "github.com/go-errors/errors",
232078          "version": "v1.0.1",
232079          "cpe": "cpe:2.3:a:go-errors:errors:v1.0.1:*:*:*:*:*:*:*",
232080          "purl": "pkg:golang/github.com/go-errors/errors@v1.0.1",
232081          "swid": {
232082            "attachment": {}
232083          },
232084          "pedigree": {},
232085          "evidence": {},
232086          "signature": {
232087            "signature": {
232088              "publicKey": {}
232089            }
232090          },
232091          "modelCard": {
232092            "modelParameters": {
232093              "approach": {}
232094            },
232095            "quantitativeAnalysis": {
232096              "graphics": {}
232097            },
232098            "considerations": {}
232099          }
232100        },
232101        {
232102          "type": "library",
232103          "bom-ref": "pkg:golang/github.com/go-logr/logr@v1.2.3?package-id=d5d0c25145ac4bbe",
232104          "supplier": {},
232105          "name": "github.com/go-logr/logr",
232106          "version": "v1.2.3",
232107          "cpe": "cpe:2.3:a:go-logr:logr:v1.2.3:*:*:*:*:*:*:*",
232108          "purl": "pkg:golang/github.com/go-logr/logr@v1.2.3",
232109          "swid": {
232110            "attachment": {}
232111          },
232112          "pedigree": {},
232113          "evidence": {},
232114          "signature": {
232115            "signature": {
232116              "publicKey": {}
232117            }
232118          },
232119          "modelCard": {
232120            "modelParameters": {
232121              "approach": {}
232122            },
232123            "quantitativeAnalysis": {
232124              "graphics": {}
232125            },
232126            "considerations": {}
232127          }
232128        },
232129        {
232130          "type": "library",
232131          "bom-ref": "pkg:golang/github.com/go-openapi/jsonpointer@v0.19.5?package-id=d829f38ba86c2cb3",
232132          "supplier": {},
232133          "name": "github.com/go-openapi/jsonpointer",
232134          "version": "v0.19.5",
232135          "cpe": "cpe:2.3:a:go-openapi:jsonpointer:v0.19.5:*:*:*:*:*:*:*",
232136          "purl": "pkg:golang/github.com/go-openapi/jsonpointer@v0.19.5",
232137          "swid": {
232138            "attachment": {}
232139          },
232140          "pedigree": {},
232141          "evidence": {},
232142          "signature": {
232143            "signature": {
232144              "publicKey": {}
232145            }
232146          },
232147          "modelCard": {
232148            "modelParameters": {
232149              "approach": {}
232150            },
232151            "quantitativeAnalysis": {
232152              "graphics": {}
232153            },
232154            "considerations": {}
232155          }
232156        },
232157        {
232158          "type": "library",
232159          "bom-ref": "pkg:golang/github.com/go-openapi/jsonreference@v0.19.5?package-id=dc40d16551a1fb96",
232160          "supplier": {},
232161          "name": "github.com/go-openapi/jsonreference",
232162          "version": "v0.19.5",
232163          "cpe": "cpe:2.3:a:go-openapi:jsonreference:v0.19.5:*:*:*:*:*:*:*",
232164          "purl": "pkg:golang/github.com/go-openapi/jsonreference@v0.19.5",
232165          "swid": {
232166            "attachment": {}
232167          },
232168          "pedigree": {},
232169          "evidence": {},
232170          "signature": {
232171            "signature": {
232172              "publicKey": {}
232173            }
232174          },
232175          "modelCard": {
232176            "modelParameters": {
232177              "approach": {}
232178            },
232179            "quantitativeAnalysis": {
232180              "graphics": {}
232181            },
232182            "considerations": {}
232183          }
232184        },
232185        {
232186          "type": "library",
232187          "bom-ref": "pkg:golang/github.com/go-openapi/swag@v0.19.14?package-id=be19e7e1a88c805c",
232188          "supplier": {},
232189          "name": "github.com/go-openapi/swag",
232190          "version": "v0.19.14",
232191          "cpe": "cpe:2.3:a:go-openapi:swag:v0.19.14:*:*:*:*:*:*:*",
232192          "purl": "pkg:golang/github.com/go-openapi/swag@v0.19.14",
232193          "swid": {
232194            "attachment": {}
232195          },
232196          "pedigree": {},
232197          "evidence": {},
232198          "signature": {
232199            "signature": {
232200              "publicKey": {}
232201            }
232202          },
232203          "modelCard": {
232204            "modelParameters": {
232205              "approach": {}
232206            },
232207            "quantitativeAnalysis": {
232208              "graphics": {}
232209            },
232210            "considerations": {}
232211          }
232212        },
232213        {
232214          "type": "library",
232215          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.2?package-id=362fd233d97a1f20",
232216          "supplier": {},
232217          "name": "github.com/gogo/protobuf",
232218          "version": "v1.3.2",
232219          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.2:*:*:*:*:*:*:*",
232220          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.2",
232221          "swid": {
232222            "attachment": {}
232223          },
232224          "pedigree": {},
232225          "evidence": {},
232226          "signature": {
232227            "signature": {
232228              "publicKey": {}
232229            }
232230          },
232231          "modelCard": {
232232            "modelParameters": {
232233              "approach": {}
232234            },
232235            "quantitativeAnalysis": {
232236              "graphics": {}
232237            },
232238            "considerations": {}
232239          }
232240        },
232241        {
232242          "type": "library",
232243          "bom-ref": "pkg:golang/github.com/golang-jwt/jwt/v4@v4.2.0?package-id=ad6ea524b86e63d9",
232244          "supplier": {},
232245          "name": "github.com/golang-jwt/jwt/v4",
232246          "version": "v4.2.0",
232247          "cpe": "cpe:2.3:a:golang-jwt:jwt\\/v4:v4.2.0:*:*:*:*:*:*:*",
232248          "purl": "pkg:golang/github.com/golang-jwt/jwt/v4@v4.2.0",
232249          "swid": {
232250            "attachment": {}
232251          },
232252          "pedigree": {},
232253          "evidence": {},
232254          "signature": {
232255            "signature": {
232256              "publicKey": {}
232257            }
232258          },
232259          "modelCard": {
232260            "modelParameters": {
232261              "approach": {}
232262            },
232263            "quantitativeAnalysis": {
232264              "graphics": {}
232265            },
232266            "considerations": {}
232267          }
232268        },
232269        {
232270          "type": "library",
232271          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.5.2?package-id=c27e8e22a6267096",
232272          "supplier": {},
232273          "name": "github.com/golang/protobuf",
232274          "version": "v1.5.2",
232275          "cpe": "cpe:2.3:a:golang:protobuf:v1.5.2:*:*:*:*:*:*:*",
232276          "purl": "pkg:golang/github.com/golang/protobuf@v1.5.2",
232277          "swid": {
232278            "attachment": {}
232279          },
232280          "pedigree": {},
232281          "evidence": {},
232282          "signature": {
232283            "signature": {
232284              "publicKey": {}
232285            }
232286          },
232287          "modelCard": {
232288            "modelParameters": {
232289              "approach": {}
232290            },
232291            "quantitativeAnalysis": {
232292              "graphics": {}
232293            },
232294            "considerations": {}
232295          }
232296        },
232297        {
232298          "type": "library",
232299          "bom-ref": "pkg:golang/github.com/google/btree@v1.0.1?package-id=81173f3262ddde3a",
232300          "supplier": {},
232301          "name": "github.com/google/btree",
232302          "version": "v1.0.1",
232303          "cpe": "cpe:2.3:a:google:btree:v1.0.1:*:*:*:*:*:*:*",
232304          "purl": "pkg:golang/github.com/google/btree@v1.0.1",
232305          "swid": {
232306            "attachment": {}
232307          },
232308          "pedigree": {},
232309          "evidence": {},
232310          "signature": {
232311            "signature": {
232312              "publicKey": {}
232313            }
232314          },
232315          "modelCard": {
232316            "modelParameters": {
232317              "approach": {}
232318            },
232319            "quantitativeAnalysis": {
232320              "graphics": {}
232321            },
232322            "considerations": {}
232323          }
232324        },
232325        {
232326          "type": "library",
232327          "bom-ref": "pkg:golang/github.com/google/gnostic@v0.5.7-v3refs?package-id=2981a0d4c6890d54",
232328          "supplier": {},
232329          "name": "github.com/google/gnostic",
232330          "version": "v0.5.7-v3refs",
232331          "cpe": "cpe:2.3:a:google:gnostic:v0.5.7-v3refs:*:*:*:*:*:*:*",
232332          "purl": "pkg:golang/github.com/google/gnostic@v0.5.7-v3refs",
232333          "swid": {
232334            "attachment": {}
232335          },
232336          "pedigree": {},
232337          "evidence": {},
232338          "signature": {
232339            "signature": {
232340              "publicKey": {}
232341            }
232342          },
232343          "modelCard": {
232344            "modelParameters": {
232345              "approach": {}
232346            },
232347            "quantitativeAnalysis": {
232348              "graphics": {}
232349            },
232350            "considerations": {}
232351          }
232352        },
232353        {
232354          "type": "library",
232355          "bom-ref": "pkg:golang/github.com/google/go-cmp@v0.5.8?package-id=6534056ab5e93ecd",
232356          "supplier": {},
232357          "name": "github.com/google/go-cmp",
232358          "version": "v0.5.8",
232359          "cpe": "cpe:2.3:a:google:go-cmp:v0.5.8:*:*:*:*:*:*:*",
232360          "purl": "pkg:golang/github.com/google/go-cmp@v0.5.8",
232361          "swid": {
232362            "attachment": {}
232363          },
232364          "pedigree": {},
232365          "evidence": {},
232366          "signature": {
232367            "signature": {
232368              "publicKey": {}
232369            }
232370          },
232371          "modelCard": {
232372            "modelParameters": {
232373              "approach": {}
232374            },
232375            "quantitativeAnalysis": {
232376              "graphics": {}
232377            },
232378            "considerations": {}
232379          }
232380        },
232381        {
232382          "type": "library",
232383          "bom-ref": "pkg:golang/github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510?package-id=8e9d52f012e4d305",
232384          "supplier": {},
232385          "name": "github.com/google/shlex",
232386          "version": "v0.0.0-20191202100458-e7afc7fbc510",
232387          "cpe": "cpe:2.3:a:google:shlex:v0.0.0-20191202100458-e7afc7fbc510:*:*:*:*:*:*:*",
232388          "purl": "pkg:golang/github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510",
232389          "swid": {
232390            "attachment": {}
232391          },
232392          "pedigree": {},
232393          "evidence": {},
232394          "signature": {
232395            "signature": {
232396              "publicKey": {}
232397            }
232398          },
232399          "modelCard": {
232400            "modelParameters": {
232401              "approach": {}
232402            },
232403            "quantitativeAnalysis": {
232404              "graphics": {}
232405            },
232406            "considerations": {}
232407          }
232408        },
232409        {
232410          "type": "library",
232411          "bom-ref": "pkg:golang/github.com/google/uuid@v1.1.2?package-id=a053a4a8bc52d233",
232412          "supplier": {},
232413          "name": "github.com/google/uuid",
232414          "version": "v1.1.2",
232415          "cpe": "cpe:2.3:a:google:uuid:v1.1.2:*:*:*:*:*:*:*",
232416          "purl": "pkg:golang/github.com/google/uuid@v1.1.2",
232417          "swid": {
232418            "attachment": {}
232419          },
232420          "pedigree": {},
232421          "evidence": {},
232422          "signature": {
232423            "signature": {
232424              "publicKey": {}
232425            }
232426          },
232427          "modelCard": {
232428            "modelParameters": {
232429              "approach": {}
232430            },
232431            "quantitativeAnalysis": {
232432              "graphics": {}
232433            },
232434            "considerations": {}
232435          }
232436        },
232437        {
232438          "type": "library",
232439          "bom-ref": "pkg:golang/github.com/gregjones/httpcache@v0.0.0-20180305231024-9cad4c3443a7?package-id=4e2fa5e092935c9e",
232440          "supplier": {},
232441          "name": "github.com/gregjones/httpcache",
232442          "version": "v0.0.0-20180305231024-9cad4c3443a7",
232443          "cpe": "cpe:2.3:a:gregjones:httpcache:v0.0.0-20180305231024-9cad4c3443a7:*:*:*:*:*:*:*",
232444          "purl": "pkg:golang/github.com/gregjones/httpcache@v0.0.0-20180305231024-9cad4c3443a7",
232445          "swid": {
232446            "attachment": {}
232447          },
232448          "pedigree": {},
232449          "evidence": {},
232450          "signature": {
232451            "signature": {
232452              "publicKey": {}
232453            }
232454          },
232455          "modelCard": {
232456            "modelParameters": {
232457              "approach": {}
232458            },
232459            "quantitativeAnalysis": {
232460              "graphics": {}
232461            },
232462            "considerations": {}
232463          }
232464        },
232465        {
232466          "type": "library",
232467          "bom-ref": "pkg:golang/github.com/imdario/mergo@v0.3.6?package-id=77417b387c901877",
232468          "supplier": {},
232469          "name": "github.com/imdario/mergo",
232470          "version": "v0.3.6",
232471          "cpe": "cpe:2.3:a:imdario:mergo:v0.3.6:*:*:*:*:*:*:*",
232472          "purl": "pkg:golang/github.com/imdario/mergo@v0.3.6",
232473          "swid": {
232474            "attachment": {}
232475          },
232476          "pedigree": {},
232477          "evidence": {},
232478          "signature": {
232479            "signature": {
232480              "publicKey": {}
232481            }
232482          },
232483          "modelCard": {
232484            "modelParameters": {
232485              "approach": {}
232486            },
232487            "quantitativeAnalysis": {
232488              "graphics": {}
232489            },
232490            "considerations": {}
232491          }
232492        },
232493        {
232494          "type": "library",
232495          "bom-ref": "pkg:golang/github.com/jonboulle/clockwork@v0.2.2?package-id=c8a4ae29897a05c3",
232496          "supplier": {},
232497          "name": "github.com/jonboulle/clockwork",
232498          "version": "v0.2.2",
232499          "cpe": "cpe:2.3:a:jonboulle:clockwork:v0.2.2:*:*:*:*:*:*:*",
232500          "purl": "pkg:golang/github.com/jonboulle/clockwork@v0.2.2",
232501          "swid": {
232502            "attachment": {}
232503          },
232504          "pedigree": {},
232505          "evidence": {},
232506          "signature": {
232507            "signature": {
232508              "publicKey": {}
232509            }
232510          },
232511          "modelCard": {
232512            "modelParameters": {
232513              "approach": {}
232514            },
232515            "quantitativeAnalysis": {
232516              "graphics": {}
232517            },
232518            "considerations": {}
232519          }
232520        },
232521        {
232522          "type": "library",
232523          "bom-ref": "pkg:golang/github.com/josharian/intern@v1.0.0?package-id=48b2b098ac0eff27",
232524          "supplier": {},
232525          "name": "github.com/josharian/intern",
232526          "version": "v1.0.0",
232527          "cpe": "cpe:2.3:a:josharian:intern:v1.0.0:*:*:*:*:*:*:*",
232528          "purl": "pkg:golang/github.com/josharian/intern@v1.0.0",
232529          "swid": {
232530            "attachment": {}
232531          },
232532          "pedigree": {},
232533          "evidence": {},
232534          "signature": {
232535            "signature": {
232536              "publicKey": {}
232537            }
232538          },
232539          "modelCard": {
232540            "modelParameters": {
232541              "approach": {}
232542            },
232543            "quantitativeAnalysis": {
232544              "graphics": {}
232545            },
232546            "considerations": {}
232547          }
232548        },
232549        {
232550          "type": "library",
232551          "bom-ref": "pkg:golang/github.com/json-iterator/go@v1.1.12?package-id=8ded29bb7799ebbd",
232552          "supplier": {},
232553          "name": "github.com/json-iterator/go",
232554          "version": "v1.1.12",
232555          "cpe": "cpe:2.3:a:json-iterator:go:v1.1.12:*:*:*:*:*:*:*",
232556          "purl": "pkg:golang/github.com/json-iterator/go@v1.1.12",
232557          "swid": {
232558            "attachment": {}
232559          },
232560          "pedigree": {},
232561          "evidence": {},
232562          "signature": {
232563            "signature": {
232564              "publicKey": {}
232565            }
232566          },
232567          "modelCard": {
232568            "modelParameters": {
232569              "approach": {}
232570            },
232571            "quantitativeAnalysis": {
232572              "graphics": {}
232573            },
232574            "considerations": {}
232575          }
232576        },
232577        {
232578          "type": "library",
232579          "bom-ref": "pkg:golang/github.com/liggitt/tabwriter@v0.0.0-20181228230101-89fcab3d43de?package-id=9fddb2784a091432",
232580          "supplier": {},
232581          "name": "github.com/liggitt/tabwriter",
232582          "version": "v0.0.0-20181228230101-89fcab3d43de",
232583          "cpe": "cpe:2.3:a:liggitt:tabwriter:v0.0.0-20181228230101-89fcab3d43de:*:*:*:*:*:*:*",
232584          "purl": "pkg:golang/github.com/liggitt/tabwriter@v0.0.0-20181228230101-89fcab3d43de",
232585          "swid": {
232586            "attachment": {}
232587          },
232588          "pedigree": {},
232589          "evidence": {},
232590          "signature": {
232591            "signature": {
232592              "publicKey": {}
232593            }
232594          },
232595          "modelCard": {
232596            "modelParameters": {
232597              "approach": {}
232598            },
232599            "quantitativeAnalysis": {
232600              "graphics": {}
232601            },
232602            "considerations": {}
232603          }
232604        },
232605        {
232606          "type": "library",
232607          "bom-ref": "pkg:golang/github.com/lithammer/dedent@v1.1.0?package-id=b98e3af513ea0ef6",
232608          "supplier": {},
232609          "name": "github.com/lithammer/dedent",
232610          "version": "v1.1.0",
232611          "cpe": "cpe:2.3:a:lithammer:dedent:v1.1.0:*:*:*:*:*:*:*",
232612          "purl": "pkg:golang/github.com/lithammer/dedent@v1.1.0",
232613          "swid": {
232614            "attachment": {}
232615          },
232616          "pedigree": {},
232617          "evidence": {},
232618          "signature": {
232619            "signature": {
232620              "publicKey": {}
232621            }
232622          },
232623          "modelCard": {
232624            "modelParameters": {
232625              "approach": {}
232626            },
232627            "quantitativeAnalysis": {
232628              "graphics": {}
232629            },
232630            "considerations": {}
232631          }
232632        },
232633        {
232634          "type": "library",
232635          "bom-ref": "pkg:golang/github.com/mailru/easyjson@v0.7.6?package-id=92ec11262cb43e7a",
232636          "supplier": {},
232637          "name": "github.com/mailru/easyjson",
232638          "version": "v0.7.6",
232639          "cpe": "cpe:2.3:a:mailru:easyjson:v0.7.6:*:*:*:*:*:*:*",
232640          "purl": "pkg:golang/github.com/mailru/easyjson@v0.7.6",
232641          "swid": {
232642            "attachment": {}
232643          },
232644          "pedigree": {},
232645          "evidence": {},
232646          "signature": {
232647            "signature": {
232648              "publicKey": {}
232649            }
232650          },
232651          "modelCard": {
232652            "modelParameters": {
232653              "approach": {}
232654            },
232655            "quantitativeAnalysis": {
232656              "graphics": {}
232657            },
232658            "considerations": {}
232659          }
232660        },
232661        {
232662          "type": "library",
232663          "bom-ref": "pkg:golang/github.com/mitchellh/go-wordwrap@v1.0.0?package-id=c11099fad78fdc18",
232664          "supplier": {},
232665          "name": "github.com/mitchellh/go-wordwrap",
232666          "version": "v1.0.0",
232667          "cpe": "cpe:2.3:a:mitchellh:go-wordwrap:v1.0.0:*:*:*:*:*:*:*",
232668          "purl": "pkg:golang/github.com/mitchellh/go-wordwrap@v1.0.0",
232669          "swid": {
232670            "attachment": {}
232671          },
232672          "pedigree": {},
232673          "evidence": {},
232674          "signature": {
232675            "signature": {
232676              "publicKey": {}
232677            }
232678          },
232679          "modelCard": {
232680            "modelParameters": {
232681              "approach": {}
232682            },
232683            "quantitativeAnalysis": {
232684              "graphics": {}
232685            },
232686            "considerations": {}
232687          }
232688        },
232689        {
232690          "type": "library",
232691          "bom-ref": "pkg:golang/github.com/moby/spdystream@v0.2.0?package-id=b6166b4b884fc733",
232692          "supplier": {},
232693          "name": "github.com/moby/spdystream",
232694          "version": "v0.2.0",
232695          "cpe": "cpe:2.3:a:moby:spdystream:v0.2.0:*:*:*:*:*:*:*",
232696          "purl": "pkg:golang/github.com/moby/spdystream@v0.2.0",
232697          "swid": {
232698            "attachment": {}
232699          },
232700          "pedigree": {},
232701          "evidence": {},
232702          "signature": {
232703            "signature": {
232704              "publicKey": {}
232705            }
232706          },
232707          "modelCard": {
232708            "modelParameters": {
232709              "approach": {}
232710            },
232711            "quantitativeAnalysis": {
232712              "graphics": {}
232713            },
232714            "considerations": {}
232715          }
232716        },
232717        {
232718          "type": "library",
232719          "bom-ref": "pkg:golang/github.com/moby/term@v0.0.0-20210619224110-3f7ff695adc6?package-id=50d59ad7963a7c61",
232720          "supplier": {},
232721          "name": "github.com/moby/term",
232722          "version": "v0.0.0-20210619224110-3f7ff695adc6",
232723          "cpe": "cpe:2.3:a:moby:term:v0.0.0-20210619224110-3f7ff695adc6:*:*:*:*:*:*:*",
232724          "purl": "pkg:golang/github.com/moby/term@v0.0.0-20210619224110-3f7ff695adc6",
232725          "swid": {
232726            "attachment": {}
232727          },
232728          "pedigree": {},
232729          "evidence": {},
232730          "signature": {
232731            "signature": {
232732              "publicKey": {}
232733            }
232734          },
232735          "modelCard": {
232736            "modelParameters": {
232737              "approach": {}
232738            },
232739            "quantitativeAnalysis": {
232740              "graphics": {}
232741            },
232742            "considerations": {}
232743          }
232744        },
232745        {
232746          "type": "library",
232747          "bom-ref": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd?package-id=b7c1f35358263fbe",
232748          "supplier": {},
232749          "name": "github.com/modern-go/concurrent",
232750          "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
232751          "cpe": "cpe:2.3:a:modern-go:concurrent:v0.0.0-20180306012644-bacd9c7ef1dd:*:*:*:*:*:*:*",
232752          "purl": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd",
232753          "swid": {
232754            "attachment": {}
232755          },
232756          "pedigree": {},
232757          "evidence": {},
232758          "signature": {
232759            "signature": {
232760              "publicKey": {}
232761            }
232762          },
232763          "modelCard": {
232764            "modelParameters": {
232765              "approach": {}
232766            },
232767            "quantitativeAnalysis": {
232768              "graphics": {}
232769            },
232770            "considerations": {}
232771          }
232772        },
232773        {
232774          "type": "library",
232775          "bom-ref": "pkg:golang/github.com/modern-go/reflect2@v1.0.2?package-id=2780c28b00a46731",
232776          "supplier": {},
232777          "name": "github.com/modern-go/reflect2",
232778          "version": "v1.0.2",
232779          "cpe": "cpe:2.3:a:modern-go:reflect2:v1.0.2:*:*:*:*:*:*:*",
232780          "purl": "pkg:golang/github.com/modern-go/reflect2@v1.0.2",
232781          "swid": {
232782            "attachment": {}
232783          },
232784          "pedigree": {},
232785          "evidence": {},
232786          "signature": {
232787            "signature": {
232788              "publicKey": {}
232789            }
232790          },
232791          "modelCard": {
232792            "modelParameters": {
232793              "approach": {}
232794            },
232795            "quantitativeAnalysis": {
232796              "graphics": {}
232797            },
232798            "considerations": {}
232799          }
232800        },
232801        {
232802          "type": "library",
232803          "bom-ref": "pkg:golang/github.com/monochromegane/go-gitignore@v0.0.0-20200626010858-205db1a8cc00?package-id=63c0fbf15c9553f8",
232804          "supplier": {},
232805          "name": "github.com/monochromegane/go-gitignore",
232806          "version": "v0.0.0-20200626010858-205db1a8cc00",
232807          "cpe": "cpe:2.3:a:monochromegane:go-gitignore:v0.0.0-20200626010858-205db1a8cc00:*:*:*:*:*:*:*",
232808          "purl": "pkg:golang/github.com/monochromegane/go-gitignore@v0.0.0-20200626010858-205db1a8cc00",
232809          "swid": {
232810            "attachment": {}
232811          },
232812          "pedigree": {},
232813          "evidence": {},
232814          "signature": {
232815            "signature": {
232816              "publicKey": {}
232817            }
232818          },
232819          "modelCard": {
232820            "modelParameters": {
232821              "approach": {}
232822            },
232823            "quantitativeAnalysis": {
232824              "graphics": {}
232825            },
232826            "considerations": {}
232827          }
232828        },
232829        {
232830          "type": "library",
232831          "bom-ref": "pkg:golang/github.com/munnerz/goautoneg@v0.0.0-20191010083416-a7dc8b61c822?package-id=3d6c515e5279b09f",
232832          "supplier": {},
232833          "name": "github.com/munnerz/goautoneg",
232834          "version": "v0.0.0-20191010083416-a7dc8b61c822",
232835          "cpe": "cpe:2.3:a:munnerz:goautoneg:v0.0.0-20191010083416-a7dc8b61c822:*:*:*:*:*:*:*",
232836          "purl": "pkg:golang/github.com/munnerz/goautoneg@v0.0.0-20191010083416-a7dc8b61c822",
232837          "swid": {
232838            "attachment": {}
232839          },
232840          "pedigree": {},
232841          "evidence": {},
232842          "signature": {
232843            "signature": {
232844              "publicKey": {}
232845            }
232846          },
232847          "modelCard": {
232848            "modelParameters": {
232849              "approach": {}
232850            },
232851            "quantitativeAnalysis": {
232852              "graphics": {}
232853            },
232854            "considerations": {}
232855          }
232856        },
232857        {
232858          "type": "library",
232859          "bom-ref": "pkg:golang/github.com/mxk/go-flowrate@v0.0.0-20140419014527-cca7078d478f?package-id=efb647ed9b49a5dd",
232860          "supplier": {},
232861          "name": "github.com/mxk/go-flowrate",
232862          "version": "v0.0.0-20140419014527-cca7078d478f",
232863          "cpe": "cpe:2.3:a:mxk:go-flowrate:v0.0.0-20140419014527-cca7078d478f:*:*:*:*:*:*:*",
232864          "purl": "pkg:golang/github.com/mxk/go-flowrate@v0.0.0-20140419014527-cca7078d478f",
232865          "swid": {
232866            "attachment": {}
232867          },
232868          "pedigree": {},
232869          "evidence": {},
232870          "signature": {
232871            "signature": {
232872              "publicKey": {}
232873            }
232874          },
232875          "modelCard": {
232876            "modelParameters": {
232877              "approach": {}
232878            },
232879            "quantitativeAnalysis": {
232880              "graphics": {}
232881            },
232882            "considerations": {}
232883          }
232884        },
232885        {
232886          "type": "library",
232887          "bom-ref": "pkg:golang/github.com/opencontainers/go-digest@v1.0.0?package-id=36d3c6d356fc6c74",
232888          "supplier": {},
232889          "name": "github.com/opencontainers/go-digest",
232890          "version": "v1.0.0",
232891          "cpe": "cpe:2.3:a:opencontainers:go-digest:v1.0.0:*:*:*:*:*:*:*",
232892          "purl": "pkg:golang/github.com/opencontainers/go-digest@v1.0.0",
232893          "swid": {
232894            "attachment": {}
232895          },
232896          "pedigree": {},
232897          "evidence": {},
232898          "signature": {
232899            "signature": {
232900              "publicKey": {}
232901            }
232902          },
232903          "modelCard": {
232904            "modelParameters": {
232905              "approach": {}
232906            },
232907            "quantitativeAnalysis": {
232908              "graphics": {}
232909            },
232910            "considerations": {}
232911          }
232912        },
232913        {
232914          "type": "library",
232915          "bom-ref": "pkg:golang/github.com/peterbourgon/diskv@v2.0.1+incompatible?package-id=db146f4f4d89c741",
232916          "supplier": {},
232917          "name": "github.com/peterbourgon/diskv",
232918          "version": "v2.0.1+incompatible",
232919          "cpe": "cpe:2.3:a:peterbourgon:diskv:v2.0.1\\+incompatible:*:*:*:*:*:*:*",
232920          "purl": "pkg:golang/github.com/peterbourgon/diskv@v2.0.1+incompatible",
232921          "swid": {
232922            "attachment": {}
232923          },
232924          "pedigree": {},
232925          "evidence": {},
232926          "signature": {
232927            "signature": {
232928              "publicKey": {}
232929            }
232930          },
232931          "modelCard": {
232932            "modelParameters": {
232933              "approach": {}
232934            },
232935            "quantitativeAnalysis": {
232936              "graphics": {}
232937            },
232938            "considerations": {}
232939          }
232940        },
232941        {
232942          "type": "library",
232943          "bom-ref": "pkg:golang/github.com/pkg/errors@v0.9.1?package-id=cb00a4938728f837",
232944          "supplier": {},
232945          "name": "github.com/pkg/errors",
232946          "version": "v0.9.1",
232947          "cpe": "cpe:2.3:a:pkg:errors:v0.9.1:*:*:*:*:*:*:*",
232948          "purl": "pkg:golang/github.com/pkg/errors@v0.9.1",
232949          "swid": {
232950            "attachment": {}
232951          },
232952          "pedigree": {},
232953          "evidence": {},
232954          "signature": {
232955            "signature": {
232956              "publicKey": {}
232957            }
232958          },
232959          "modelCard": {
232960            "modelParameters": {
232961              "approach": {}
232962            },
232963            "quantitativeAnalysis": {
232964              "graphics": {}
232965            },
232966            "considerations": {}
232967          }
232968        },
232969        {
232970          "type": "library",
232971          "bom-ref": "pkg:golang/github.com/russross/blackfriday@v1.5.2?package-id=f1eb3fcbd723d6c9",
232972          "supplier": {},
232973          "name": "github.com/russross/blackfriday",
232974          "version": "v1.5.2",
232975          "cpe": "cpe:2.3:a:russross:blackfriday:v1.5.2:*:*:*:*:*:*:*",
232976          "purl": "pkg:golang/github.com/russross/blackfriday@v1.5.2",
232977          "swid": {
232978            "attachment": {}
232979          },
232980          "pedigree": {},
232981          "evidence": {},
232982          "signature": {
232983            "signature": {
232984              "publicKey": {}
232985            }
232986          },
232987          "modelCard": {
232988            "modelParameters": {
232989              "approach": {}
232990            },
232991            "quantitativeAnalysis": {
232992              "graphics": {}
232993            },
232994            "considerations": {}
232995          }
232996        },
232997        {
232998          "type": "library",
232999          "bom-ref": "pkg:golang/github.com/spf13/cobra@v1.4.0?package-id=665df81804ec1bc",
233000          "supplier": {},
233001          "name": "github.com/spf13/cobra",
233002          "version": "v1.4.0",
233003          "cpe": "cpe:2.3:a:spf13:cobra:v1.4.0:*:*:*:*:*:*:*",
233004          "purl": "pkg:golang/github.com/spf13/cobra@v1.4.0",
233005          "swid": {
233006            "attachment": {}
233007          },
233008          "pedigree": {},
233009          "evidence": {},
233010          "signature": {
233011            "signature": {
233012              "publicKey": {}
233013            }
233014          },
233015          "modelCard": {
233016            "modelParameters": {
233017              "approach": {}
233018            },
233019            "quantitativeAnalysis": {
233020              "graphics": {}
233021            },
233022            "considerations": {}
233023          }
233024        },
233025        {
233026          "type": "library",
233027          "bom-ref": "pkg:golang/github.com/spf13/pflag@v1.0.5?package-id=f63680d8ec6c8a18",
233028          "supplier": {},
233029          "name": "github.com/spf13/pflag",
233030          "version": "v1.0.5",
233031          "cpe": "cpe:2.3:a:spf13:pflag:v1.0.5:*:*:*:*:*:*:*",
233032          "purl": "pkg:golang/github.com/spf13/pflag@v1.0.5",
233033          "swid": {
233034            "attachment": {}
233035          },
233036          "pedigree": {},
233037          "evidence": {},
233038          "signature": {
233039            "signature": {
233040              "publicKey": {}
233041            }
233042          },
233043          "modelCard": {
233044            "modelParameters": {
233045              "approach": {}
233046            },
233047            "quantitativeAnalysis": {
233048              "graphics": {}
233049            },
233050            "considerations": {}
233051          }
233052        },
233053        {
233054          "type": "library",
233055          "bom-ref": "pkg:golang/github.com/xlab/treeprint@v1.1.0?package-id=a04bcc27e24695ad",
233056          "supplier": {},
233057          "name": "github.com/xlab/treeprint",
233058          "version": "v1.1.0",
233059          "cpe": "cpe:2.3:a:xlab:treeprint:v1.1.0:*:*:*:*:*:*:*",
233060          "purl": "pkg:golang/github.com/xlab/treeprint@v1.1.0",
233061          "swid": {
233062            "attachment": {}
233063          },
233064          "pedigree": {},
233065          "evidence": {},
233066          "signature": {
233067            "signature": {
233068              "publicKey": {}
233069            }
233070          },
233071          "modelCard": {
233072            "modelParameters": {
233073              "approach": {}
233074            },
233075            "quantitativeAnalysis": {
233076              "graphics": {}
233077            },
233078            "considerations": {}
233079          }
233080        },
233081        {
233082          "type": "library",
233083          "bom-ref": "pkg:golang/go.starlark.net@v0.0.0-20200306205701-8dd3e2ee1dd5?package-id=f902a2778df87f2d",
233084          "supplier": {},
233085          "name": "go.starlark.net",
233086          "version": "v0.0.0-20200306205701-8dd3e2ee1dd5",
233087          "purl": "pkg:golang/go.starlark.net@v0.0.0-20200306205701-8dd3e2ee1dd5",
233088          "swid": {
233089            "attachment": {}
233090          },
233091          "pedigree": {},
233092          "evidence": {},
233093          "signature": {
233094            "signature": {
233095              "publicKey": {}
233096            }
233097          },
233098          "modelCard": {
233099            "modelParameters": {
233100              "approach": {}
233101            },
233102            "quantitativeAnalysis": {
233103              "graphics": {}
233104            },
233105            "considerations": {}
233106          }
233107        },
233108        {
233109          "type": "library",
233110          "bom-ref": "pkg:golang/golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd?package-id=c04279ea9cbe904b",
233111          "supplier": {},
233112          "name": "golang.org/x/crypto",
233113          "version": "v0.0.0-20220315160706-3147a52a75dd",
233114          "cpe": "cpe:2.3:a:golang:x\\/crypto:v0.0.0-20220315160706-3147a52a75dd:*:*:*:*:*:*:*",
233115          "purl": "pkg:golang/golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd",
233116          "swid": {
233117            "attachment": {}
233118          },
233119          "pedigree": {},
233120          "evidence": {},
233121          "signature": {
233122            "signature": {
233123              "publicKey": {}
233124            }
233125          },
233126          "modelCard": {
233127            "modelParameters": {
233128              "approach": {}
233129            },
233130            "quantitativeAnalysis": {
233131              "graphics": {}
233132            },
233133            "considerations": {}
233134          }
233135        },
233136        {
233137          "type": "library",
233138          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20220722155237-a158d28d115b?package-id=f7308ab8f20527d9",
233139          "supplier": {},
233140          "name": "golang.org/x/net",
233141          "version": "v0.0.0-20220722155237-a158d28d115b",
233142          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20220722155237-a158d28d115b:*:*:*:*:*:*:*",
233143          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20220722155237-a158d28d115b",
233144          "swid": {
233145            "attachment": {}
233146          },
233147          "pedigree": {},
233148          "evidence": {},
233149          "signature": {
233150            "signature": {
233151              "publicKey": {}
233152            }
233153          },
233154          "modelCard": {
233155            "modelParameters": {
233156              "approach": {}
233157            },
233158            "quantitativeAnalysis": {
233159              "graphics": {}
233160            },
233161            "considerations": {}
233162          }
233163        },
233164        {
233165          "type": "library",
233166          "bom-ref": "pkg:golang/golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8?package-id=e9093cc6436d9400",
233167          "supplier": {},
233168          "name": "golang.org/x/oauth2",
233169          "version": "v0.0.0-20211104180415-d3ed0bb246c8",
233170          "cpe": "cpe:2.3:a:golang:x\\/oauth2:v0.0.0-20211104180415-d3ed0bb246c8:*:*:*:*:*:*:*",
233171          "purl": "pkg:golang/golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8",
233172          "swid": {
233173            "attachment": {}
233174          },
233175          "pedigree": {},
233176          "evidence": {},
233177          "signature": {
233178            "signature": {
233179              "publicKey": {}
233180            }
233181          },
233182          "modelCard": {
233183            "modelParameters": {
233184              "approach": {}
233185            },
233186            "quantitativeAnalysis": {
233187              "graphics": {}
233188            },
233189            "considerations": {}
233190          }
233191        },
233192        {
233193          "type": "library",
233194          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f?package-id=4ff632baacccabf3",
233195          "supplier": {},
233196          "name": "golang.org/x/sys",
233197          "version": "v0.0.0-20220722155257-8c9f86f7a55f",
233198          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20220722155257-8c9f86f7a55f:*:*:*:*:*:*:*",
233199          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20220722155257-8c9f86f7a55f",
233200          "swid": {
233201            "attachment": {}
233202          },
233203          "pedigree": {},
233204          "evidence": {},
233205          "signature": {
233206            "signature": {
233207              "publicKey": {}
233208            }
233209          },
233210          "modelCard": {
233211            "modelParameters": {
233212              "approach": {}
233213            },
233214            "quantitativeAnalysis": {
233215              "graphics": {}
233216            },
233217            "considerations": {}
233218          }
233219        },
233220        {
233221          "type": "library",
233222          "bom-ref": "pkg:golang/golang.org/x/term@v0.0.0-20210927222741-03fcf44c2211?package-id=3d4ef2cd90e25ba7",
233223          "supplier": {},
233224          "name": "golang.org/x/term",
233225          "version": "v0.0.0-20210927222741-03fcf44c2211",
233226          "cpe": "cpe:2.3:a:golang:x\\/term:v0.0.0-20210927222741-03fcf44c2211:*:*:*:*:*:*:*",
233227          "purl": "pkg:golang/golang.org/x/term@v0.0.0-20210927222741-03fcf44c2211",
233228          "swid": {
233229            "attachment": {}
233230          },
233231          "pedigree": {},
233232          "evidence": {},
233233          "signature": {
233234            "signature": {
233235              "publicKey": {}
233236            }
233237          },
233238          "modelCard": {
233239            "modelParameters": {
233240              "approach": {}
233241            },
233242            "quantitativeAnalysis": {
233243              "graphics": {}
233244            },
233245            "considerations": {}
233246          }
233247        },
233248        {
233249          "type": "library",
233250          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.7?package-id=3a726cad0263b37b",
233251          "supplier": {},
233252          "name": "golang.org/x/text",
233253          "version": "v0.3.7",
233254          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.7:*:*:*:*:*:*:*",
233255          "purl": "pkg:golang/golang.org/x/text@v0.3.7",
233256          "swid": {
233257            "attachment": {}
233258          },
233259          "pedigree": {},
233260          "evidence": {},
233261          "signature": {
233262            "signature": {
233263              "publicKey": {}
233264            }
233265          },
233266          "modelCard": {
233267            "modelParameters": {
233268              "approach": {}
233269            },
233270            "quantitativeAnalysis": {
233271              "graphics": {}
233272            },
233273            "considerations": {}
233274          }
233275        },
233276        {
233277          "type": "library",
233278          "bom-ref": "pkg:golang/golang.org/x/time@v0.0.0-20220210224613-90d013bbcef8?package-id=1d11ff6ba712efe",
233279          "supplier": {},
233280          "name": "golang.org/x/time",
233281          "version": "v0.0.0-20220210224613-90d013bbcef8",
233282          "cpe": "cpe:2.3:a:golang:x\\/time:v0.0.0-20220210224613-90d013bbcef8:*:*:*:*:*:*:*",
233283          "purl": "pkg:golang/golang.org/x/time@v0.0.0-20220210224613-90d013bbcef8",
233284          "swid": {
233285            "attachment": {}
233286          },
233287          "pedigree": {},
233288          "evidence": {},
233289          "signature": {
233290            "signature": {
233291              "publicKey": {}
233292            }
233293          },
233294          "modelCard": {
233295            "modelParameters": {
233296              "approach": {}
233297            },
233298            "quantitativeAnalysis": {
233299              "graphics": {}
233300            },
233301            "considerations": {}
233302          }
233303        },
233304        {
233305          "type": "library",
233306          "bom-ref": "pkg:golang/google.golang.org/protobuf@v1.28.0?package-id=f80825fabf9c7634",
233307          "supplier": {},
233308          "name": "google.golang.org/protobuf",
233309          "version": "v1.28.0",
233310          "cpe": "cpe:2.3:a:google:protobuf:v1.28.0:*:*:*:*:*:*:*",
233311          "purl": "pkg:golang/google.golang.org/protobuf@v1.28.0",
233312          "swid": {
233313            "attachment": {}
233314          },
233315          "pedigree": {},
233316          "evidence": {},
233317          "signature": {
233318            "signature": {
233319              "publicKey": {}
233320            }
233321          },
233322          "modelCard": {
233323            "modelParameters": {
233324              "approach": {}
233325            },
233326            "quantitativeAnalysis": {
233327              "graphics": {}
233328            },
233329            "considerations": {}
233330          }
233331        },
233332        {
233333          "type": "library",
233334          "bom-ref": "pkg:golang/gopkg.in/inf.v0@v0.9.1?package-id=f09a07a4292d1673",
233335          "supplier": {},
233336          "name": "gopkg.in/inf.v0",
233337          "version": "v0.9.1",
233338          "purl": "pkg:golang/gopkg.in/inf.v0@v0.9.1",
233339          "swid": {
233340            "attachment": {}
233341          },
233342          "pedigree": {},
233343          "evidence": {},
233344          "signature": {
233345            "signature": {
233346              "publicKey": {}
233347            }
233348          },
233349          "modelCard": {
233350            "modelParameters": {
233351              "approach": {}
233352            },
233353            "quantitativeAnalysis": {
233354              "graphics": {}
233355            },
233356            "considerations": {}
233357          }
233358        },
233359        {
233360          "type": "library",
233361          "bom-ref": "pkg:golang/gopkg.in/yaml.v2@v2.4.0?package-id=587a54deb8faba65",
233362          "supplier": {},
233363          "name": "gopkg.in/yaml.v2",
233364          "version": "v2.4.0",
233365          "purl": "pkg:golang/gopkg.in/yaml.v2@v2.4.0",
233366          "swid": {
233367            "attachment": {}
233368          },
233369          "pedigree": {},
233370          "evidence": {},
233371          "signature": {
233372            "signature": {
233373              "publicKey": {}
233374            }
233375          },
233376          "modelCard": {
233377            "modelParameters": {
233378              "approach": {}
233379            },
233380            "quantitativeAnalysis": {
233381              "graphics": {}
233382            },
233383            "considerations": {}
233384          }
233385        },
233386        {
233387          "type": "library",
233388          "bom-ref": "pkg:golang/gopkg.in/yaml.v3@v3.0.1?package-id=62c132701753ef85",
233389          "supplier": {},
233390          "name": "gopkg.in/yaml.v3",
233391          "version": "v3.0.1",
233392          "purl": "pkg:golang/gopkg.in/yaml.v3@v3.0.1",
233393          "swid": {
233394            "attachment": {}
233395          },
233396          "pedigree": {},
233397          "evidence": {},
233398          "signature": {
233399            "signature": {
233400              "publicKey": {}
233401            }
233402          },
233403          "modelCard": {
233404            "modelParameters": {
233405              "approach": {}
233406            },
233407            "quantitativeAnalysis": {
233408              "graphics": {}
233409            },
233410            "considerations": {}
233411          }
233412        },
233413        {
233414          "type": "library",
233415          "bom-ref": "pkg:apk/alpine/grep@3.3-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=a00894042b8b026d",
233416          "supplier": {},
233417          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
233418          "name": "grep",
233419          "version": "3.3-r0",
233420          "description": "Searches input files for lines containing a match to a specified pattern",
233421          "licenses": [
233422            {
233423              "license": {
233424                "id": "GPL-3.0-or-later"
233425              }
233426            }
233427          ],
233428          "cpe": "cpe:2.3:a:grep:grep:3.3-r0:*:*:*:*:*:*:*",
233429          "purl": "pkg:apk/alpine/grep@3.3-r0?arch=x86_64\u0026distro=alpine-3.11.13",
233430          "swid": {
233431            "attachment": {}
233432          },
233433          "pedigree": {},
233434          "externalReferences": [
233435            {
233436              "url": "https://www.gnu.org/software/grep/grep.html",
233437              "type": "distribution"
233438            }
233439          ],
233440          "evidence": {},
233441          "signature": {
233442            "signature": {
233443              "publicKey": {}
233444            }
233445          },
233446          "modelCard": {
233447            "modelParameters": {
233448              "approach": {}
233449            },
233450            "quantitativeAnalysis": {
233451              "graphics": {}
233452            },
233453            "considerations": {}
233454          }
233455        },
233456        {
233457          "type": "library",
233458          "bom-ref": "pkg:golang/k8s.io/klog/v2@v2.70.1?package-id=ecf6f5624bc14b4e",
233459          "supplier": {},
233460          "name": "k8s.io/klog/v2",
233461          "version": "v2.70.1",
233462          "cpe": "cpe:2.3:a:klog:v2:v2.70.1:*:*:*:*:*:*:*",
233463          "purl": "pkg:golang/k8s.io/klog/v2@v2.70.1",
233464          "swid": {
233465            "attachment": {}
233466          },
233467          "pedigree": {},
233468          "evidence": {},
233469          "signature": {
233470            "signature": {
233471              "publicKey": {}
233472            }
233473          },
233474          "modelCard": {
233475            "modelParameters": {
233476              "approach": {}
233477            },
233478            "quantitativeAnalysis": {
233479              "graphics": {}
233480            },
233481            "considerations": {}
233482          }
233483        },
233484        {
233485          "type": "library",
233486          "bom-ref": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20220803162953-67bda5d908f1?package-id=9571920a550513e3",
233487          "supplier": {},
233488          "name": "k8s.io/kube-openapi",
233489          "version": "v0.0.0-20220803162953-67bda5d908f1",
233490          "purl": "pkg:golang/k8s.io/kube-openapi@v0.0.0-20220803162953-67bda5d908f1",
233491          "swid": {
233492            "attachment": {}
233493          },
233494          "pedigree": {},
233495          "evidence": {},
233496          "signature": {
233497            "signature": {
233498              "publicKey": {}
233499            }
233500          },
233501          "modelCard": {
233502            "modelParameters": {
233503              "approach": {}
233504            },
233505            "quantitativeAnalysis": {
233506              "graphics": {}
233507            },
233508            "considerations": {}
233509          }
233510        },
233511        {
233512          "type": "library",
233513          "bom-ref": "pkg:golang/k8s.io/kubernetes@v0.0.0-20221012104725-434bfd82814a?package-id=7c7559392b0efde9",
233514          "supplier": {},
233515          "name": "k8s.io/kubernetes",
233516          "version": "v0.0.0-20221012104725-434bfd82814a",
233517          "purl": "pkg:golang/k8s.io/kubernetes@v0.0.0-20221012104725-434bfd82814a",
233518          "swid": {
233519            "attachment": {}
233520          },
233521          "pedigree": {},
233522          "evidence": {},
233523          "signature": {
233524            "signature": {
233525              "publicKey": {}
233526            }
233527          },
233528          "modelCard": {
233529            "modelParameters": {
233530              "approach": {}
233531            },
233532            "quantitativeAnalysis": {
233533              "graphics": {}
233534            },
233535            "considerations": {}
233536          }
233537        },
233538        {
233539          "type": "library",
233540          "bom-ref": "pkg:golang/k8s.io/utils@v0.0.0-20220728103510-ee6ede2d64ed?package-id=e9909dc0931261fa",
233541          "supplier": {},
233542          "name": "k8s.io/utils",
233543          "version": "v0.0.0-20220728103510-ee6ede2d64ed",
233544          "purl": "pkg:golang/k8s.io/utils@v0.0.0-20220728103510-ee6ede2d64ed",
233545          "swid": {
233546            "attachment": {}
233547          },
233548          "pedigree": {},
233549          "evidence": {},
233550          "signature": {
233551            "signature": {
233552              "publicKey": {}
233553            }
233554          },
233555          "modelCard": {
233556            "modelParameters": {
233557              "approach": {}
233558            },
233559            "quantitativeAnalysis": {
233560              "graphics": {}
233561            },
233562            "considerations": {}
233563          }
233564        },
233565        {
233566          "type": "application",
233567          "bom-ref": "pkg:golang/k8s.io/kubectl@1.25.3?package-id=fdfe149ef621c365",
233568          "supplier": {},
233569          "name": "kubectl",
233570          "version": "1.25.3",
233571          "cpe": "cpe:2.3:a:kubectl:kubectl:1.25.3:*:*:*:*:*:*:*",
233572          "purl": "pkg:golang/k8s.io/kubectl@1.25.3",
233573          "swid": {
233574            "attachment": {}
233575          },
233576          "pedigree": {},
233577          "evidence": {},
233578          "signature": {
233579            "signature": {
233580              "publicKey": {}
233581            }
233582          },
233583          "modelCard": {
233584            "modelParameters": {
233585              "approach": {}
233586            },
233587            "quantitativeAnalysis": {
233588              "graphics": {}
233589            },
233590            "considerations": {}
233591          }
233592        },
233593        {
233594          "type": "library",
233595          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.11.13\u0026package-id=22b2a81fa39d5dd2",
233596          "supplier": {},
233597          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
233598          "name": "libc-utils",
233599          "version": "0.7.2-r0",
233600          "description": "Meta package to pull in correct libc",
233601          "licenses": [
233602            {
233603              "license": {
233604                "name": "BSD"
233605              }
233606            }
233607          ],
233608          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r0:*:*:*:*:*:*:*",
233609          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.11.13",
233610          "swid": {
233611            "attachment": {}
233612          },
233613          "pedigree": {},
233614          "externalReferences": [
233615            {
233616              "url": "http://alpinelinux.org",
233617              "type": "distribution"
233618            }
233619          ],
233620          "evidence": {},
233621          "signature": {
233622            "signature": {
233623              "publicKey": {}
233624            }
233625          },
233626          "modelCard": {
233627            "modelParameters": {
233628              "approach": {}
233629            },
233630            "quantitativeAnalysis": {
233631              "graphics": {}
233632            },
233633            "considerations": {}
233634          }
233635        },
233636        {
233637          "type": "library",
233638          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13\u0026package-id=9dc8a627b3dc6e7c",
233639          "supplier": {},
233640          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
233641          "name": "libcrypto1.1",
233642          "version": "1.1.1l-r0",
233643          "description": "Crypto library from openssl",
233644          "licenses": [
233645            {
233646              "license": {
233647                "id": "OpenSSL"
233648              }
233649            }
233650          ],
233651          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1l-r0:*:*:*:*:*:*:*",
233652          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13",
233653          "swid": {
233654            "attachment": {}
233655          },
233656          "pedigree": {},
233657          "externalReferences": [
233658            {
233659              "url": "https://www.openssl.org",
233660              "type": "distribution"
233661            }
233662          ],
233663          "evidence": {},
233664          "signature": {
233665            "signature": {
233666              "publicKey": {}
233667            }
233668          },
233669          "modelCard": {
233670            "modelParameters": {
233671              "approach": {}
233672            },
233673            "quantitativeAnalysis": {
233674              "graphics": {}
233675            },
233676            "considerations": {}
233677          }
233678        },
233679        {
233680          "type": "library",
233681          "bom-ref": "pkg:apk/alpine/libcurl@7.79.1-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.11.13\u0026package-id=b055e046cf7212a1",
233682          "supplier": {},
233683          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
233684          "name": "libcurl",
233685          "version": "7.79.1-r0",
233686          "description": "The multiprotocol file transfer library",
233687          "licenses": [
233688            {
233689              "license": {
233690                "id": "MIT"
233691              }
233692            }
233693          ],
233694          "cpe": "cpe:2.3:a:libcurl:libcurl:7.79.1-r0:*:*:*:*:*:*:*",
233695          "purl": "pkg:apk/alpine/libcurl@7.79.1-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.11.13",
233696          "swid": {
233697            "attachment": {}
233698          },
233699          "pedigree": {},
233700          "externalReferences": [
233701            {
233702              "url": "https://curl.haxx.se/",
233703              "type": "distribution"
233704            }
233705          ],
233706          "evidence": {},
233707          "signature": {
233708            "signature": {
233709              "publicKey": {}
233710            }
233711          },
233712          "modelCard": {
233713            "modelParameters": {
233714              "approach": {}
233715            },
233716            "quantitativeAnalysis": {
233717              "graphics": {}
233718            },
233719            "considerations": {}
233720          }
233721        },
233722        {
233723          "type": "library",
233724          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13\u0026package-id=286e1bd630e38068",
233725          "supplier": {},
233726          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
233727          "name": "libssl1.1",
233728          "version": "1.1.1l-r0",
233729          "description": "SSL shared libraries",
233730          "licenses": [
233731            {
233732              "license": {
233733                "id": "OpenSSL"
233734              }
233735            }
233736          ],
233737          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1l-r0:*:*:*:*:*:*:*",
233738          "purl": "pkg:apk/alpine/libssl1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13",
233739          "swid": {
233740            "attachment": {}
233741          },
233742          "pedigree": {},
233743          "externalReferences": [
233744            {
233745              "url": "https://www.openssl.org",
233746              "type": "distribution"
233747            }
233748          ],
233749          "evidence": {},
233750          "signature": {
233751            "signature": {
233752              "publicKey": {}
233753            }
233754          },
233755          "modelCard": {
233756            "modelParameters": {
233757              "approach": {}
233758            },
233759            "quantitativeAnalysis": {
233760              "graphics": {}
233761            },
233762            "considerations": {}
233763          }
233764        },
233765        {
233766          "type": "library",
233767          "bom-ref": "pkg:apk/alpine/libtls-standalone@2.9.1-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=44d013a47dc758aa",
233768          "supplier": {},
233769          "name": "libtls-standalone",
233770          "version": "2.9.1-r0",
233771          "description": "libtls extricated from libressl sources",
233772          "licenses": [
233773            {
233774              "license": {
233775                "id": "ISC"
233776              }
233777            }
233778          ],
233779          "cpe": "cpe:2.3:a:libtls-standalone:libtls-standalone:2.9.1-r0:*:*:*:*:*:*:*",
233780          "purl": "pkg:apk/alpine/libtls-standalone@2.9.1-r0?arch=x86_64\u0026distro=alpine-3.11.13",
233781          "swid": {
233782            "attachment": {}
233783          },
233784          "pedigree": {},
233785          "externalReferences": [
233786            {
233787              "url": "https://www.libressl.org/",
233788              "type": "distribution"
233789            }
233790          ],
233791          "evidence": {},
233792          "signature": {
233793            "signature": {
233794              "publicKey": {}
233795            }
233796          },
233797          "modelCard": {
233798            "modelParameters": {
233799              "approach": {}
233800            },
233801            "quantitativeAnalysis": {
233802              "graphics": {}
233803            },
233804            "considerations": {}
233805          }
233806        },
233807        {
233808          "type": "library",
233809          "bom-ref": "pkg:apk/alpine/musl@1.1.24-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=485b70fc6d5760",
233810          "supplier": {},
233811          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
233812          "name": "musl",
233813          "version": "1.1.24-r3",
233814          "description": "the musl c library (libc) implementation",
233815          "licenses": [
233816            {
233817              "license": {
233818                "id": "MIT"
233819              }
233820            }
233821          ],
233822          "cpe": "cpe:2.3:a:musl-libc:musl:1.1.24-r3:*:*:*:*:*:*:*",
233823          "purl": "pkg:apk/alpine/musl@1.1.24-r3?arch=x86_64\u0026distro=alpine-3.11.13",
233824          "swid": {
233825            "attachment": {}
233826          },
233827          "pedigree": {},
233828          "externalReferences": [
233829            {
233830              "url": "https://musl.libc.org/",
233831              "type": "distribution"
233832            }
233833          ],
233834          "evidence": {},
233835          "signature": {
233836            "signature": {
233837              "publicKey": {}
233838            }
233839          },
233840          "modelCard": {
233841            "modelParameters": {
233842              "approach": {}
233843            },
233844            "quantitativeAnalysis": {
233845              "graphics": {}
233846            },
233847            "considerations": {}
233848          }
233849        },
233850        {
233851          "type": "library",
233852          "bom-ref": "pkg:apk/alpine/musl-utils@1.1.24-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.11.13\u0026package-id=fc850f3aca8a5da",
233853          "supplier": {},
233854          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
233855          "name": "musl-utils",
233856          "version": "1.1.24-r3",
233857          "description": "the musl c library (libc) implementation",
233858          "licenses": [
233859            {
233860              "license": {
233861                "id": "MIT"
233862              }
233863            },
233864            {
233865              "license": {
233866                "name": "BSD"
233867              }
233868            },
233869            {
233870              "license": {
233871                "id": "GPL-2.0-or-later"
233872              }
233873            }
233874          ],
233875          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.1.24-r3:*:*:*:*:*:*:*",
233876          "purl": "pkg:apk/alpine/musl-utils@1.1.24-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.11.13",
233877          "swid": {
233878            "attachment": {}
233879          },
233880          "pedigree": {},
233881          "externalReferences": [
233882            {
233883              "url": "https://musl.libc.org/",
233884              "type": "distribution"
233885            }
233886          ],
233887          "evidence": {},
233888          "signature": {
233889            "signature": {
233890              "publicKey": {}
233891            }
233892          },
233893          "modelCard": {
233894            "modelParameters": {
233895              "approach": {}
233896            },
233897            "quantitativeAnalysis": {
233898              "graphics": {}
233899            },
233900            "considerations": {}
233901          }
233902        },
233903        {
233904          "type": "library",
233905          "bom-ref": "pkg:apk/alpine/nghttp2-libs@1.40.0-r1?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.11.13\u0026package-id=569777ff2f19d9f3",
233906          "supplier": {},
233907          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
233908          "name": "nghttp2-libs",
233909          "version": "1.40.0-r1",
233910          "description": "Experimental HTTP/2 client, server and proxy (libraries)",
233911          "licenses": [
233912            {
233913              "license": {
233914                "id": "MIT"
233915              }
233916            }
233917          ],
233918          "cpe": "cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.40.0-r1:*:*:*:*:*:*:*",
233919          "purl": "pkg:apk/alpine/nghttp2-libs@1.40.0-r1?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.11.13",
233920          "swid": {
233921            "attachment": {}
233922          },
233923          "pedigree": {},
233924          "externalReferences": [
233925            {
233926              "url": "https://nghttp2.org",
233927              "type": "distribution"
233928            }
233929          ],
233930          "evidence": {},
233931          "signature": {
233932            "signature": {
233933              "publicKey": {}
233934            }
233935          },
233936          "modelCard": {
233937            "modelParameters": {
233938              "approach": {}
233939            },
233940            "quantitativeAnalysis": {
233941              "graphics": {}
233942            },
233943            "considerations": {}
233944          }
233945        },
233946        {
233947          "type": "library",
233948          "bom-ref": "pkg:apk/alpine/pcre@8.43-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=be1b5b15b01eec50",
233949          "supplier": {},
233950          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
233951          "name": "pcre",
233952          "version": "8.43-r1",
233953          "description": "Perl-compatible regular expression library",
233954          "licenses": [
233955            {
233956              "license": {
233957                "id": "BSD-3-Clause"
233958              }
233959            }
233960          ],
233961          "cpe": "cpe:2.3:a:pcre:pcre:8.43-r1:*:*:*:*:*:*:*",
233962          "purl": "pkg:apk/alpine/pcre@8.43-r1?arch=x86_64\u0026distro=alpine-3.11.13",
233963          "swid": {
233964            "attachment": {}
233965          },
233966          "pedigree": {},
233967          "externalReferences": [
233968            {
233969              "url": "http://pcre.sourceforge.net",
233970              "type": "distribution"
233971            }
233972          ],
233973          "evidence": {},
233974          "signature": {
233975            "signature": {
233976              "publicKey": {}
233977            }
233978          },
233979          "modelCard": {
233980            "modelParameters": {
233981              "approach": {}
233982            },
233983            "quantitativeAnalysis": {
233984              "graphics": {}
233985            },
233986            "considerations": {}
233987          }
233988        },
233989        {
233990          "type": "library",
233991          "bom-ref": "pkg:apk/alpine/scanelf@1.2.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.11.13\u0026package-id=d7d0b4983b78c706",
233992          "supplier": {},
233993          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
233994          "name": "scanelf",
233995          "version": "1.2.4-r0",
233996          "description": "Scan ELF binaries for stuff",
233997          "licenses": [
233998            {
233999              "license": {
234000                "id": "GPL-2.0-only"
234001              }
234002            }
234003          ],
234004          "cpe": "cpe:2.3:a:scanelf:scanelf:1.2.4-r0:*:*:*:*:*:*:*",
234005          "purl": "pkg:apk/alpine/scanelf@1.2.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.11.13",
234006          "swid": {
234007            "attachment": {}
234008          },
234009          "pedigree": {},
234010          "externalReferences": [
234011            {
234012              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
234013              "type": "distribution"
234014            }
234015          ],
234016          "evidence": {},
234017          "signature": {
234018            "signature": {
234019              "publicKey": {}
234020            }
234021          },
234022          "modelCard": {
234023            "modelParameters": {
234024              "approach": {}
234025            },
234026            "quantitativeAnalysis": {
234027              "graphics": {}
234028            },
234029            "considerations": {}
234030          }
234031        },
234032        {
234033          "type": "library",
234034          "bom-ref": "pkg:golang/sigs.k8s.io/json@v0.0.0-20220713155537-f223a00ba0e2?package-id=d741e5ed9ff6dc56",
234035          "supplier": {},
234036          "name": "sigs.k8s.io/json",
234037          "version": "v0.0.0-20220713155537-f223a00ba0e2",
234038          "purl": "pkg:golang/sigs.k8s.io/json@v0.0.0-20220713155537-f223a00ba0e2",
234039          "swid": {
234040            "attachment": {}
234041          },
234042          "pedigree": {},
234043          "evidence": {},
234044          "signature": {
234045            "signature": {
234046              "publicKey": {}
234047            }
234048          },
234049          "modelCard": {
234050            "modelParameters": {
234051              "approach": {}
234052            },
234053            "quantitativeAnalysis": {
234054              "graphics": {}
234055            },
234056            "considerations": {}
234057          }
234058        },
234059        {
234060          "type": "library",
234061          "bom-ref": "pkg:golang/sigs.k8s.io/kustomize/api@v0.12.1?package-id=62abdaa20c0c5d6f",
234062          "supplier": {},
234063          "name": "sigs.k8s.io/kustomize/api",
234064          "version": "v0.12.1",
234065          "cpe": "cpe:2.3:a:kustomize:api:v0.12.1:*:*:*:*:*:*:*",
234066          "purl": "pkg:golang/sigs.k8s.io/kustomize/api@v0.12.1",
234067          "swid": {
234068            "attachment": {}
234069          },
234070          "pedigree": {},
234071          "evidence": {},
234072          "signature": {
234073            "signature": {
234074              "publicKey": {}
234075            }
234076          },
234077          "modelCard": {
234078            "modelParameters": {
234079              "approach": {}
234080            },
234081            "quantitativeAnalysis": {
234082              "graphics": {}
234083            },
234084            "considerations": {}
234085          }
234086        },
234087        {
234088          "type": "library",
234089          "bom-ref": "pkg:golang/sigs.k8s.io/kustomize/kustomize/v4@v4.5.7?package-id=639fff7501878120",
234090          "supplier": {},
234091          "name": "sigs.k8s.io/kustomize/kustomize/v4",
234092          "version": "v4.5.7",
234093          "cpe": "cpe:2.3:a:kustomize:kustomize\\/v4:v4.5.7:*:*:*:*:*:*:*",
234094          "purl": "pkg:golang/sigs.k8s.io/kustomize/kustomize/v4@v4.5.7",
234095          "swid": {
234096            "attachment": {}
234097          },
234098          "pedigree": {},
234099          "evidence": {},
234100          "signature": {
234101            "signature": {
234102              "publicKey": {}
234103            }
234104          },
234105          "modelCard": {
234106            "modelParameters": {
234107              "approach": {}
234108            },
234109            "quantitativeAnalysis": {
234110              "graphics": {}
234111            },
234112            "considerations": {}
234113          }
234114        },
234115        {
234116          "type": "library",
234117          "bom-ref": "pkg:golang/sigs.k8s.io/kustomize/kyaml@v0.13.9?package-id=cc0f7082592466ec",
234118          "supplier": {},
234119          "name": "sigs.k8s.io/kustomize/kyaml",
234120          "version": "v0.13.9",
234121          "cpe": "cpe:2.3:a:kustomize:kyaml:v0.13.9:*:*:*:*:*:*:*",
234122          "purl": "pkg:golang/sigs.k8s.io/kustomize/kyaml@v0.13.9",
234123          "swid": {
234124            "attachment": {}
234125          },
234126          "pedigree": {},
234127          "evidence": {},
234128          "signature": {
234129            "signature": {
234130              "publicKey": {}
234131            }
234132          },
234133          "modelCard": {
234134            "modelParameters": {
234135              "approach": {}
234136            },
234137            "quantitativeAnalysis": {
234138              "graphics": {}
234139            },
234140            "considerations": {}
234141          }
234142        },
234143        {
234144          "type": "library",
234145          "bom-ref": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.2.3?package-id=1c1000ac48c38798",
234146          "supplier": {},
234147          "name": "sigs.k8s.io/structured-merge-diff/v4",
234148          "version": "v4.2.3",
234149          "cpe": "cpe:2.3:a:structured-merge-diff:v4:v4.2.3:*:*:*:*:*:*:*",
234150          "purl": "pkg:golang/sigs.k8s.io/structured-merge-diff/v4@v4.2.3",
234151          "swid": {
234152            "attachment": {}
234153          },
234154          "pedigree": {},
234155          "evidence": {},
234156          "signature": {
234157            "signature": {
234158              "publicKey": {}
234159            }
234160          },
234161          "modelCard": {
234162            "modelParameters": {
234163              "approach": {}
234164            },
234165            "quantitativeAnalysis": {
234166              "graphics": {}
234167            },
234168            "considerations": {}
234169          }
234170        },
234171        {
234172          "type": "library",
234173          "bom-ref": "pkg:golang/sigs.k8s.io/yaml@v1.2.0?package-id=82cff49cd29939e5",
234174          "supplier": {},
234175          "name": "sigs.k8s.io/yaml",
234176          "version": "v1.2.0",
234177          "purl": "pkg:golang/sigs.k8s.io/yaml@v1.2.0",
234178          "swid": {
234179            "attachment": {}
234180          },
234181          "pedigree": {},
234182          "evidence": {},
234183          "signature": {
234184            "signature": {
234185              "publicKey": {}
234186            }
234187          },
234188          "modelCard": {
234189            "modelParameters": {
234190              "approach": {}
234191            },
234192            "quantitativeAnalysis": {
234193              "graphics": {}
234194            },
234195            "considerations": {}
234196          }
234197        },
234198        {
234199          "type": "library",
234200          "bom-ref": "pkg:apk/alpine/ssl_client@1.31.1-r11?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.11.13\u0026package-id=685c6f235663ea24",
234201          "supplier": {},
234202          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
234203          "name": "ssl_client",
234204          "version": "1.31.1-r11",
234205          "description": "EXternal ssl_client for busybox wget",
234206          "licenses": [
234207            {
234208              "license": {
234209                "id": "GPL-2.0-only"
234210              }
234211            }
234212          ],
234213          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.31.1-r11:*:*:*:*:*:*:*",
234214          "purl": "pkg:apk/alpine/ssl_client@1.31.1-r11?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.11.13",
234215          "swid": {
234216            "attachment": {}
234217          },
234218          "pedigree": {},
234219          "externalReferences": [
234220            {
234221              "url": "https://busybox.net/",
234222              "type": "distribution"
234223            }
234224          ],
234225          "evidence": {},
234226          "signature": {
234227            "signature": {
234228              "publicKey": {}
234229            }
234230          },
234231          "modelCard": {
234232            "modelParameters": {
234233              "approach": {}
234234            },
234235            "quantitativeAnalysis": {
234236              "graphics": {}
234237            },
234238            "considerations": {}
234239          }
234240        },
234241        {
234242          "type": "library",
234243          "bom-ref": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=9886c2465766333f",
234244          "supplier": {},
234245          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
234246          "name": "zlib",
234247          "version": "1.2.11-r3",
234248          "description": "A compression/decompression Library",
234249          "licenses": [
234250            {
234251              "license": {
234252                "id": "Zlib"
234253              }
234254            }
234255          ],
234256          "cpe": "cpe:2.3:a:zlib:zlib:1.2.11-r3:*:*:*:*:*:*:*",
234257          "purl": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.11.13",
234258          "swid": {
234259            "attachment": {}
234260          },
234261          "pedigree": {},
234262          "externalReferences": [
234263            {
234264              "url": "https://zlib.net/",
234265              "type": "distribution"
234266            }
234267          ],
234268          "evidence": {},
234269          "signature": {
234270            "signature": {
234271              "publicKey": {}
234272            }
234273          },
234274          "modelCard": {
234275            "modelParameters": {
234276              "approach": {}
234277            },
234278            "quantitativeAnalysis": {
234279              "graphics": {}
234280            },
234281            "considerations": {}
234282          }
234283        },
234284        {
234285          "type": "operating-system",
234286          "supplier": {},
234287          "name": "alpine",
234288          "version": "3.11.13",
234289          "description": "Alpine Linux v3.11",
234290          "swid": {
234291            "tagId": "alpine",
234292            "name": "alpine",
234293            "version": "3.11.13",
234294            "attachment": {}
234295          },
234296          "pedigree": {},
234297          "externalReferences": [
234298            {
234299              "url": "https://bugs.alpinelinux.org/",
234300              "type": "issue-tracker"
234301            },
234302            {
234303              "url": "https://alpinelinux.org/",
234304              "type": "website"
234305            }
234306          ],
234307          "evidence": {},
234308          "signature": {
234309            "signature": {
234310              "publicKey": {}
234311            }
234312          },
234313          "modelCard": {
234314            "modelParameters": {
234315              "approach": {}
234316            },
234317            "quantitativeAnalysis": {
234318              "graphics": {}
234319            },
234320            "considerations": {}
234321          }
234322        },
234323        {
234324          "type": "library",
234325          "bom-ref": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04\u0026package-id=69d1980477020fa3",
234326          "supplier": {},
234327          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234328          "name": "adduser",
234329          "version": "3.118ubuntu2",
234330          "licenses": [
234331            {
234332              "license": {
234333                "id": "GPL-2.0-only"
234334              }
234335            }
234336          ],
234337          "cpe": "cpe:2.3:a:adduser:adduser:3.118ubuntu2:*:*:*:*:*:*:*",
234338          "purl": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04",
234339          "swid": {
234340            "attachment": {}
234341          },
234342          "pedigree": {},
234343          "evidence": {},
234344          "signature": {
234345            "signature": {
234346              "publicKey": {}
234347            }
234348          },
234349          "modelCard": {
234350            "modelParameters": {
234351              "approach": {}
234352            },
234353            "quantitativeAnalysis": {
234354              "graphics": {}
234355            },
234356            "considerations": {}
234357          }
234358        },
234359        {
234360          "type": "library",
234361          "bom-ref": "pkg:deb/ubuntu/apt@2.0.8?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e15dc7ed115af27",
234362          "supplier": {},
234363          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234364          "name": "apt",
234365          "version": "2.0.8",
234366          "licenses": [
234367            {
234368              "license": {
234369                "id": "GPL-2.0-only"
234370              }
234371            },
234372            {
234373              "license": {
234374                "name": "GPLv2+"
234375              }
234376            }
234377          ],
234378          "cpe": "cpe:2.3:a:apt:apt:2.0.8:*:*:*:*:*:*:*",
234379          "purl": "pkg:deb/ubuntu/apt@2.0.8?arch=amd64\u0026distro=ubuntu-20.04",
234380          "swid": {
234381            "attachment": {}
234382          },
234383          "pedigree": {},
234384          "evidence": {},
234385          "signature": {
234386            "signature": {
234387              "publicKey": {}
234388            }
234389          },
234390          "modelCard": {
234391            "modelParameters": {
234392              "approach": {}
234393            },
234394            "quantitativeAnalysis": {
234395              "graphics": {}
234396            },
234397            "considerations": {}
234398          }
234399        },
234400        {
234401          "type": "library",
234402          "bom-ref": "pkg:deb/ubuntu/base-files@11ubuntu5.5?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=195c402cc18c6ec8",
234403          "supplier": {},
234404          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234405          "name": "base-files",
234406          "version": "11ubuntu5.5",
234407          "licenses": [
234408            {
234409              "license": {
234410                "name": "GPL"
234411              }
234412            }
234413          ],
234414          "cpe": "cpe:2.3:a:base-files:base-files:11ubuntu5.5:*:*:*:*:*:*:*",
234415          "purl": "pkg:deb/ubuntu/base-files@11ubuntu5.5?arch=amd64\u0026distro=ubuntu-20.04",
234416          "swid": {
234417            "attachment": {}
234418          },
234419          "pedigree": {},
234420          "evidence": {},
234421          "signature": {
234422            "signature": {
234423              "publicKey": {}
234424            }
234425          },
234426          "modelCard": {
234427            "modelParameters": {
234428              "approach": {}
234429            },
234430            "quantitativeAnalysis": {
234431              "graphics": {}
234432            },
234433            "considerations": {}
234434          }
234435        },
234436        {
234437          "type": "library",
234438          "bom-ref": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=8b6e494dac6dab09",
234439          "supplier": {},
234440          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
234441          "name": "base-passwd",
234442          "version": "3.5.47",
234443          "licenses": [
234444            {
234445              "license": {
234446                "id": "GPL-2.0-only"
234447              }
234448            },
234449            {
234450              "license": {
234451                "name": "PD"
234452              }
234453            }
234454          ],
234455          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.47:*:*:*:*:*:*:*",
234456          "purl": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04",
234457          "swid": {
234458            "attachment": {}
234459          },
234460          "pedigree": {},
234461          "evidence": {},
234462          "signature": {
234463            "signature": {
234464              "publicKey": {}
234465            }
234466          },
234467          "modelCard": {
234468            "modelParameters": {
234469              "approach": {}
234470            },
234471            "quantitativeAnalysis": {
234472              "graphics": {}
234473            },
234474            "considerations": {}
234475          }
234476        },
234477        {
234478          "type": "library",
234479          "bom-ref": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=9b2a88643de9f471",
234480          "supplier": {},
234481          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234482          "name": "bash",
234483          "version": "5.0-6ubuntu1.2",
234484          "licenses": [
234485            {
234486              "license": {
234487                "id": "GPL-3.0-only"
234488              }
234489            }
234490          ],
234491          "cpe": "cpe:2.3:a:bash:bash:5.0-6ubuntu1.2:*:*:*:*:*:*:*",
234492          "purl": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.2?arch=amd64\u0026distro=ubuntu-20.04",
234493          "swid": {
234494            "attachment": {}
234495          },
234496          "pedigree": {},
234497          "evidence": {},
234498          "signature": {
234499            "signature": {
234500              "publicKey": {}
234501            }
234502          },
234503          "modelCard": {
234504            "modelParameters": {
234505              "approach": {}
234506            },
234507            "quantitativeAnalysis": {
234508              "graphics": {}
234509            },
234510            "considerations": {}
234511          }
234512        },
234513        {
234514          "type": "library",
234515          "bom-ref": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.3\u0026distro=ubuntu-20.04\u0026package-id=f059f1effc2759b2",
234516          "supplier": {},
234517          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234518          "name": "bsdutils",
234519          "version": "1:2.34-0.1ubuntu9.3",
234520          "licenses": [
234521            {
234522              "license": {
234523                "id": "BSD-2-Clause"
234524              }
234525            },
234526            {
234527              "license": {
234528                "id": "BSD-3-Clause"
234529              }
234530            },
234531            {
234532              "license": {
234533                "id": "BSD-4-Clause"
234534              }
234535            },
234536            {
234537              "license": {
234538                "id": "GPL-2.0-only"
234539              }
234540            },
234541            {
234542              "license": {
234543                "id": "GPL-2.0-or-later"
234544              }
234545            },
234546            {
234547              "license": {
234548                "id": "GPL-3.0-only"
234549              }
234550            },
234551            {
234552              "license": {
234553                "id": "GPL-3.0-or-later"
234554              }
234555            },
234556            {
234557              "license": {
234558                "name": "LGPL"
234559              }
234560            },
234561            {
234562              "license": {
234563                "id": "LGPL-2.0-only"
234564              }
234565            },
234566            {
234567              "license": {
234568                "id": "LGPL-2.0-or-later"
234569              }
234570            },
234571            {
234572              "license": {
234573                "id": "LGPL-2.1-only"
234574              }
234575            },
234576            {
234577              "license": {
234578                "id": "LGPL-2.1-or-later"
234579              }
234580            },
234581            {
234582              "license": {
234583                "id": "LGPL-3.0-only"
234584              }
234585            },
234586            {
234587              "license": {
234588                "id": "LGPL-3.0-or-later"
234589              }
234590            },
234591            {
234592              "license": {
234593                "id": "MIT"
234594              }
234595            },
234596            {
234597              "license": {
234598                "name": "public-domain"
234599              }
234600            }
234601          ],
234602          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.34-0.1ubuntu9.3:*:*:*:*:*:*:*",
234603          "purl": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.3\u0026distro=ubuntu-20.04",
234604          "swid": {
234605            "attachment": {}
234606          },
234607          "pedigree": {},
234608          "evidence": {},
234609          "signature": {
234610            "signature": {
234611              "publicKey": {}
234612            }
234613          },
234614          "modelCard": {
234615            "modelParameters": {
234616              "approach": {}
234617            },
234618            "quantitativeAnalysis": {
234619              "graphics": {}
234620            },
234621            "considerations": {}
234622          }
234623        },
234624        {
234625          "type": "library",
234626          "bom-ref": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=97dab883cac4c956",
234627          "supplier": {},
234628          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234629          "name": "bzip2",
234630          "version": "1.0.8-2",
234631          "licenses": [
234632            {
234633              "license": {
234634                "name": "BSD-variant"
234635              }
234636            },
234637            {
234638              "license": {
234639                "id": "GPL-2.0-only"
234640              }
234641            }
234642          ],
234643          "cpe": "cpe:2.3:a:bzip2:bzip2:1.0.8-2:*:*:*:*:*:*:*",
234644          "purl": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04",
234645          "swid": {
234646            "attachment": {}
234647          },
234648          "pedigree": {},
234649          "evidence": {},
234650          "signature": {
234651            "signature": {
234652              "publicKey": {}
234653            }
234654          },
234655          "modelCard": {
234656            "modelParameters": {
234657              "approach": {}
234658            },
234659            "quantitativeAnalysis": {
234660              "graphics": {}
234661            },
234662            "considerations": {}
234663          }
234664        },
234665        {
234666          "type": "library",
234667          "bom-ref": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f77283ee51e117fa",
234668          "supplier": {},
234669          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234670          "name": "coreutils",
234671          "version": "8.30-3ubuntu2",
234672          "licenses": [
234673            {
234674              "license": {
234675                "id": "GPL-3.0-only"
234676              }
234677            }
234678          ],
234679          "cpe": "cpe:2.3:a:coreutils:coreutils:8.30-3ubuntu2:*:*:*:*:*:*:*",
234680          "purl": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
234681          "swid": {
234682            "attachment": {}
234683          },
234684          "pedigree": {},
234685          "evidence": {},
234686          "signature": {
234687            "signature": {
234688              "publicKey": {}
234689            }
234690          },
234691          "modelCard": {
234692            "modelParameters": {
234693              "approach": {}
234694            },
234695            "quantitativeAnalysis": {
234696              "graphics": {}
234697            },
234698            "considerations": {}
234699          }
234700        },
234701        {
234702          "type": "library",
234703          "bom-ref": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=fa0f613df8411b7",
234704          "supplier": {},
234705          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234706          "name": "dash",
234707          "version": "0.5.10.2-6",
234708          "licenses": [
234709            {
234710              "license": {
234711                "name": "GPL"
234712              }
234713            }
234714          ],
234715          "cpe": "cpe:2.3:a:dash:dash:0.5.10.2-6:*:*:*:*:*:*:*",
234716          "purl": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04",
234717          "swid": {
234718            "attachment": {}
234719          },
234720          "pedigree": {},
234721          "evidence": {},
234722          "signature": {
234723            "signature": {
234724              "publicKey": {}
234725            }
234726          },
234727          "modelCard": {
234728            "modelParameters": {
234729              "approach": {}
234730            },
234731            "quantitativeAnalysis": {
234732              "graphics": {}
234733            },
234734            "considerations": {}
234735          }
234736        },
234737        {
234738          "type": "library",
234739          "bom-ref": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04\u0026package-id=128eb6066f5ec19c",
234740          "supplier": {},
234741          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234742          "name": "debconf",
234743          "version": "1.5.73",
234744          "licenses": [
234745            {
234746              "license": {
234747                "id": "BSD-2-Clause"
234748              }
234749            }
234750          ],
234751          "cpe": "cpe:2.3:a:debconf:debconf:1.5.73:*:*:*:*:*:*:*",
234752          "purl": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04",
234753          "swid": {
234754            "attachment": {}
234755          },
234756          "pedigree": {},
234757          "evidence": {},
234758          "signature": {
234759            "signature": {
234760              "publicKey": {}
234761            }
234762          },
234763          "modelCard": {
234764            "modelParameters": {
234765              "approach": {}
234766            },
234767            "quantitativeAnalysis": {
234768              "graphics": {}
234769            },
234770            "considerations": {}
234771          }
234772        },
234773        {
234774          "type": "library",
234775          "bom-ref": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=328b1094024bda26",
234776          "supplier": {},
234777          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234778          "name": "debianutils",
234779          "version": "4.9.1",
234780          "licenses": [
234781            {
234782              "license": {
234783                "name": "GPL"
234784              }
234785            }
234786          ],
234787          "cpe": "cpe:2.3:a:debianutils:debianutils:4.9.1:*:*:*:*:*:*:*",
234788          "purl": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04",
234789          "swid": {
234790            "attachment": {}
234791          },
234792          "pedigree": {},
234793          "evidence": {},
234794          "signature": {
234795            "signature": {
234796              "publicKey": {}
234797            }
234798          },
234799          "modelCard": {
234800            "modelParameters": {
234801              "approach": {}
234802            },
234803            "quantitativeAnalysis": {
234804              "graphics": {}
234805            },
234806            "considerations": {}
234807          }
234808        },
234809        {
234810          "type": "library",
234811          "bom-ref": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=d21aefcaf9c9c9b6",
234812          "supplier": {},
234813          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234814          "name": "diffutils",
234815          "version": "1:3.7-3",
234816          "licenses": [
234817            {
234818              "license": {
234819                "name": "GFDL"
234820              }
234821            },
234822            {
234823              "license": {
234824                "name": "GPL"
234825              }
234826            }
234827          ],
234828          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-3:*:*:*:*:*:*:*",
234829          "purl": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04",
234830          "swid": {
234831            "attachment": {}
234832          },
234833          "pedigree": {},
234834          "evidence": {},
234835          "signature": {
234836            "signature": {
234837              "publicKey": {}
234838            }
234839          },
234840          "modelCard": {
234841            "modelParameters": {
234842              "approach": {}
234843            },
234844            "quantitativeAnalysis": {
234845              "graphics": {}
234846            },
234847            "considerations": {}
234848          }
234849        },
234850        {
234851          "type": "library",
234852          "bom-ref": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=c04e8d0994357312",
234853          "supplier": {},
234854          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234855          "name": "dpkg",
234856          "version": "1.19.7ubuntu3.2",
234857          "licenses": [
234858            {
234859              "license": {
234860                "id": "BSD-2-Clause"
234861              }
234862            },
234863            {
234864              "license": {
234865                "id": "GPL-2.0-only"
234866              }
234867            },
234868            {
234869              "license": {
234870                "id": "GPL-2.0-or-later"
234871              }
234872            },
234873            {
234874              "license": {
234875                "name": "public-domain-md5"
234876              }
234877            },
234878            {
234879              "license": {
234880                "name": "public-domain-s-s-d"
234881              }
234882            }
234883          ],
234884          "cpe": "cpe:2.3:a:dpkg:dpkg:1.19.7ubuntu3.2:*:*:*:*:*:*:*",
234885          "purl": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3.2?arch=amd64\u0026distro=ubuntu-20.04",
234886          "swid": {
234887            "attachment": {}
234888          },
234889          "pedigree": {},
234890          "evidence": {},
234891          "signature": {
234892            "signature": {
234893              "publicKey": {}
234894            }
234895          },
234896          "modelCard": {
234897            "modelParameters": {
234898              "approach": {}
234899            },
234900            "quantitativeAnalysis": {
234901              "graphics": {}
234902            },
234903            "considerations": {}
234904          }
234905        },
234906        {
234907          "type": "library",
234908          "bom-ref": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=6a037357f3ebf47a",
234909          "supplier": {},
234910          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234911          "name": "e2fsprogs",
234912          "version": "1.45.5-2ubuntu1",
234913          "licenses": [
234914            {
234915              "license": {
234916                "id": "GPL-2.0-only"
234917              }
234918            },
234919            {
234920              "license": {
234921                "id": "LGPL-2.0-only"
234922              }
234923            }
234924          ],
234925          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
234926          "purl": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
234927          "swid": {
234928            "attachment": {}
234929          },
234930          "pedigree": {},
234931          "evidence": {},
234932          "signature": {
234933            "signature": {
234934              "publicKey": {}
234935            }
234936          },
234937          "modelCard": {
234938            "modelParameters": {
234939              "approach": {}
234940            },
234941            "quantitativeAnalysis": {
234942              "graphics": {}
234943            },
234944            "considerations": {}
234945          }
234946        },
234947        {
234948          "type": "library",
234949          "bom-ref": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=c1731913519805c2",
234950          "supplier": {},
234951          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
234952          "name": "fdisk",
234953          "version": "2.34-0.1ubuntu9.3",
234954          "licenses": [
234955            {
234956              "license": {
234957                "id": "BSD-2-Clause"
234958              }
234959            },
234960            {
234961              "license": {
234962                "id": "BSD-3-Clause"
234963              }
234964            },
234965            {
234966              "license": {
234967                "id": "BSD-4-Clause"
234968              }
234969            },
234970            {
234971              "license": {
234972                "id": "GPL-2.0-only"
234973              }
234974            },
234975            {
234976              "license": {
234977                "id": "GPL-2.0-or-later"
234978              }
234979            },
234980            {
234981              "license": {
234982                "id": "GPL-3.0-only"
234983              }
234984            },
234985            {
234986              "license": {
234987                "id": "GPL-3.0-or-later"
234988              }
234989            },
234990            {
234991              "license": {
234992                "name": "LGPL"
234993              }
234994            },
234995            {
234996              "license": {
234997                "id": "LGPL-2.0-only"
234998              }
234999            },
235000            {
235001              "license": {
235002                "id": "LGPL-2.0-or-later"
235003              }
235004            },
235005            {
235006              "license": {
235007                "id": "LGPL-2.1-only"
235008              }
235009            },
235010            {
235011              "license": {
235012                "id": "LGPL-2.1-or-later"
235013              }
235014            },
235015            {
235016              "license": {
235017                "id": "LGPL-3.0-only"
235018              }
235019            },
235020            {
235021              "license": {
235022                "id": "LGPL-3.0-or-later"
235023              }
235024            },
235025            {
235026              "license": {
235027                "id": "MIT"
235028              }
235029            },
235030            {
235031              "license": {
235032                "name": "public-domain"
235033              }
235034            }
235035          ],
235036          "cpe": "cpe:2.3:a:fdisk:fdisk:2.34-0.1ubuntu9.3:*:*:*:*:*:*:*",
235037          "purl": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
235038          "swid": {
235039            "attachment": {}
235040          },
235041          "pedigree": {},
235042          "evidence": {},
235043          "signature": {
235044            "signature": {
235045              "publicKey": {}
235046            }
235047          },
235048          "modelCard": {
235049            "modelParameters": {
235050              "approach": {}
235051            },
235052            "quantitativeAnalysis": {
235053              "graphics": {}
235054            },
235055            "considerations": {}
235056          }
235057        },
235058        {
235059          "type": "library",
235060          "bom-ref": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=103a5999463b7e08",
235061          "supplier": {},
235062          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235063          "name": "findutils",
235064          "version": "4.7.0-1ubuntu1",
235065          "licenses": [
235066            {
235067              "license": {
235068                "id": "GFDL-1.3-only"
235069              }
235070            },
235071            {
235072              "license": {
235073                "id": "GPL-3.0-only"
235074              }
235075            }
235076          ],
235077          "cpe": "cpe:2.3:a:findutils:findutils:4.7.0-1ubuntu1:*:*:*:*:*:*:*",
235078          "purl": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
235079          "swid": {
235080            "attachment": {}
235081          },
235082          "pedigree": {},
235083          "evidence": {},
235084          "signature": {
235085            "signature": {
235086              "publicKey": {}
235087            }
235088          },
235089          "modelCard": {
235090            "modelParameters": {
235091              "approach": {}
235092            },
235093            "quantitativeAnalysis": {
235094              "graphics": {}
235095            },
235096            "considerations": {}
235097          }
235098        },
235099        {
235100          "type": "library",
235101          "bom-ref": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=a268d6ad2986f239",
235102          "supplier": {},
235103          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235104          "name": "gcc-10-base",
235105          "version": "10.3.0-1ubuntu1~20.04",
235106          "licenses": [
235107            {
235108              "license": {
235109                "name": "Artistic"
235110              }
235111            },
235112            {
235113              "license": {
235114                "id": "GFDL-1.2-only"
235115              }
235116            },
235117            {
235118              "license": {
235119                "name": "GPL"
235120              }
235121            },
235122            {
235123              "license": {
235124                "id": "GPL-2.0-only"
235125              }
235126            },
235127            {
235128              "license": {
235129                "id": "GPL-3.0-only"
235130              }
235131            },
235132            {
235133              "license": {
235134                "name": "LGPL"
235135              }
235136            }
235137          ],
235138          "cpe": "cpe:2.3:a:gcc-10-base:gcc-10-base:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
235139          "purl": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
235140          "swid": {
235141            "attachment": {}
235142          },
235143          "pedigree": {},
235144          "evidence": {},
235145          "signature": {
235146            "signature": {
235147              "publicKey": {}
235148            }
235149          },
235150          "modelCard": {
235151            "modelParameters": {
235152              "approach": {}
235153            },
235154            "quantitativeAnalysis": {
235155              "graphics": {}
235156            },
235157            "considerations": {}
235158          }
235159        },
235160        {
235161          "type": "library",
235162          "bom-ref": "pkg:deb/ubuntu/gcc-9-base@9.4.0-1ubuntu1~20.04.1?arch=amd64\u0026upstream=gcc-9\u0026distro=ubuntu-20.04\u0026package-id=3ba6275fbc717c77",
235163          "supplier": {},
235164          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235165          "name": "gcc-9-base",
235166          "version": "9.4.0-1ubuntu1~20.04.1",
235167          "licenses": [
235168            {
235169              "license": {
235170                "name": "Artistic"
235171              }
235172            },
235173            {
235174              "license": {
235175                "id": "GFDL-1.2-only"
235176              }
235177            },
235178            {
235179              "license": {
235180                "name": "GPL"
235181              }
235182            },
235183            {
235184              "license": {
235185                "id": "GPL-2.0-only"
235186              }
235187            },
235188            {
235189              "license": {
235190                "id": "GPL-3.0-only"
235191              }
235192            },
235193            {
235194              "license": {
235195                "name": "LGPL"
235196              }
235197            },
235198            {
235199              "license": {
235200                "id": "LGPL-2.1-or-later"
235201              }
235202            }
235203          ],
235204          "cpe": "cpe:2.3:a:gcc-9-base:gcc-9-base:9.4.0-1ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
235205          "purl": "pkg:deb/ubuntu/gcc-9-base@9.4.0-1ubuntu1~20.04.1?arch=amd64\u0026upstream=gcc-9\u0026distro=ubuntu-20.04",
235206          "swid": {
235207            "attachment": {}
235208          },
235209          "pedigree": {},
235210          "evidence": {},
235211          "signature": {
235212            "signature": {
235213              "publicKey": {}
235214            }
235215          },
235216          "modelCard": {
235217            "modelParameters": {
235218              "approach": {}
235219            },
235220            "quantitativeAnalysis": {
235221              "graphics": {}
235222            },
235223            "considerations": {}
235224          }
235225        },
235226        {
235227          "type": "library",
235228          "bom-ref": "pkg:deb/ubuntu/gosu@1.10-1ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=2f8c6c9669b24c1d",
235229          "supplier": {},
235230          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235231          "name": "gosu",
235232          "version": "1.10-1ubuntu0.20.04.1",
235233          "licenses": [
235234            {
235235              "license": {
235236                "id": "GPL-3.0-only"
235237              }
235238            },
235239            {
235240              "license": {
235241                "id": "GPL-3.0-or-later"
235242              }
235243            }
235244          ],
235245          "cpe": "cpe:2.3:a:gosu:gosu:1.10-1ubuntu0.20.04.1:*:*:*:*:*:*:*",
235246          "purl": "pkg:deb/ubuntu/gosu@1.10-1ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
235247          "swid": {
235248            "attachment": {}
235249          },
235250          "pedigree": {},
235251          "evidence": {},
235252          "signature": {
235253            "signature": {
235254              "publicKey": {}
235255            }
235256          },
235257          "modelCard": {
235258            "modelParameters": {
235259              "approach": {}
235260            },
235261            "quantitativeAnalysis": {
235262              "graphics": {}
235263            },
235264            "considerations": {}
235265          }
235266        },
235267        {
235268          "type": "library",
235269          "bom-ref": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04\u0026package-id=b3a56223224b45d2",
235270          "supplier": {},
235271          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235272          "name": "gpgv",
235273          "version": "2.2.19-3ubuntu2.1",
235274          "licenses": [
235275            {
235276              "license": {
235277                "id": "BSD-3-Clause"
235278              }
235279            },
235280            {
235281              "license": {
235282                "id": "CC0-1.0"
235283              }
235284            },
235285            {
235286              "license": {
235287                "name": "Expat"
235288              }
235289            },
235290            {
235291              "license": {
235292                "id": "GPL-3.0-only"
235293              }
235294            },
235295            {
235296              "license": {
235297                "id": "GPL-3.0-or-later"
235298              }
235299            },
235300            {
235301              "license": {
235302                "id": "LGPL-2.1-only"
235303              }
235304            },
235305            {
235306              "license": {
235307                "id": "LGPL-2.1-or-later"
235308              }
235309            },
235310            {
235311              "license": {
235312                "id": "LGPL-3.0-only"
235313              }
235314            },
235315            {
235316              "license": {
235317                "id": "LGPL-3.0-or-later"
235318              }
235319            },
235320            {
235321              "license": {
235322                "name": "RFC-Reference"
235323              }
235324            },
235325            {
235326              "license": {
235327                "name": "TinySCHEME"
235328              }
235329            },
235330            {
235331              "license": {
235332                "name": "permissive"
235333              }
235334            }
235335          ],
235336          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.19-3ubuntu2.1:*:*:*:*:*:*:*",
235337          "purl": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04",
235338          "swid": {
235339            "attachment": {}
235340          },
235341          "pedigree": {},
235342          "evidence": {},
235343          "signature": {
235344            "signature": {
235345              "publicKey": {}
235346            }
235347          },
235348          "modelCard": {
235349            "modelParameters": {
235350              "approach": {}
235351            },
235352            "quantitativeAnalysis": {
235353              "graphics": {}
235354            },
235355            "considerations": {}
235356          }
235357        },
235358        {
235359          "type": "library",
235360          "bom-ref": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7af9af4b90473f",
235361          "supplier": {},
235362          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235363          "name": "grep",
235364          "version": "3.4-1",
235365          "licenses": [
235366            {
235367              "license": {
235368                "id": "GPL-3.0-only"
235369              }
235370            },
235371            {
235372              "license": {
235373                "id": "GPL-3.0-or-later"
235374              }
235375            }
235376          ],
235377          "cpe": "cpe:2.3:a:grep:grep:3.4-1:*:*:*:*:*:*:*",
235378          "purl": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04",
235379          "swid": {
235380            "attachment": {}
235381          },
235382          "pedigree": {},
235383          "evidence": {},
235384          "signature": {
235385            "signature": {
235386              "publicKey": {}
235387            }
235388          },
235389          "modelCard": {
235390            "modelParameters": {
235391              "approach": {}
235392            },
235393            "quantitativeAnalysis": {
235394              "graphics": {}
235395            },
235396            "considerations": {}
235397          }
235398        },
235399        {
235400          "type": "library",
235401          "bom-ref": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=733a6389eeaa99c9",
235402          "supplier": {},
235403          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235404          "name": "gzip",
235405          "version": "1.10-0ubuntu4.1",
235406          "licenses": [
235407            {
235408              "license": {
235409                "name": "GPL"
235410              }
235411            }
235412          ],
235413          "cpe": "cpe:2.3:a:gzip:gzip:1.10-0ubuntu4.1:*:*:*:*:*:*:*",
235414          "purl": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4.1?arch=amd64\u0026distro=ubuntu-20.04",
235415          "swid": {
235416            "attachment": {}
235417          },
235418          "pedigree": {},
235419          "evidence": {},
235420          "signature": {
235421            "signature": {
235422              "publicKey": {}
235423            }
235424          },
235425          "modelCard": {
235426            "modelParameters": {
235427              "approach": {}
235428            },
235429            "quantitativeAnalysis": {
235430              "graphics": {}
235431            },
235432            "considerations": {}
235433          }
235434        },
235435        {
235436          "type": "library",
235437          "bom-ref": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=263dae70cc8e6a4f",
235438          "supplier": {},
235439          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235440          "name": "hostname",
235441          "version": "3.23",
235442          "licenses": [
235443            {
235444              "license": {
235445                "id": "GPL-2.0-only"
235446              }
235447            }
235448          ],
235449          "cpe": "cpe:2.3:a:hostname:hostname:3.23:*:*:*:*:*:*:*",
235450          "purl": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04",
235451          "swid": {
235452            "attachment": {}
235453          },
235454          "pedigree": {},
235455          "evidence": {},
235456          "signature": {
235457            "signature": {
235458              "publicKey": {}
235459            }
235460          },
235461          "modelCard": {
235462            "modelParameters": {
235463              "approach": {}
235464            },
235465            "quantitativeAnalysis": {
235466              "graphics": {}
235467            },
235468            "considerations": {}
235469          }
235470        },
235471        {
235472          "type": "library",
235473          "bom-ref": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04\u0026package-id=b0e335d96f12154d",
235474          "supplier": {},
235475          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235476          "name": "init-system-helpers",
235477          "version": "1.57",
235478          "licenses": [
235479            {
235480              "license": {
235481                "id": "BSD-3-Clause"
235482              }
235483            },
235484            {
235485              "license": {
235486                "id": "GPL-2.0-only"
235487              }
235488            },
235489            {
235490              "license": {
235491                "id": "GPL-2.0-or-later"
235492              }
235493            }
235494          ],
235495          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.57:*:*:*:*:*:*:*",
235496          "purl": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04",
235497          "swid": {
235498            "attachment": {}
235499          },
235500          "pedigree": {},
235501          "evidence": {},
235502          "signature": {
235503            "signature": {
235504              "publicKey": {}
235505            }
235506          },
235507          "modelCard": {
235508            "modelParameters": {
235509              "approach": {}
235510            },
235511            "quantitativeAnalysis": {
235512              "graphics": {}
235513            },
235514            "considerations": {}
235515          }
235516        },
235517        {
235518          "type": "library",
235519          "bom-ref": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04\u0026package-id=5cec2c2009596050",
235520          "supplier": {},
235521          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235522          "name": "libacl1",
235523          "version": "2.2.53-6",
235524          "licenses": [
235525            {
235526              "license": {
235527                "id": "GPL-2.0-only"
235528              }
235529            },
235530            {
235531              "license": {
235532                "id": "GPL-2.0-or-later"
235533              }
235534            },
235535            {
235536              "license": {
235537                "id": "LGPL-2.0-or-later"
235538              }
235539            },
235540            {
235541              "license": {
235542                "id": "LGPL-2.1-only"
235543              }
235544            }
235545          ],
235546          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-6:*:*:*:*:*:*:*",
235547          "purl": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04",
235548          "swid": {
235549            "attachment": {}
235550          },
235551          "pedigree": {},
235552          "evidence": {},
235553          "signature": {
235554            "signature": {
235555              "publicKey": {}
235556            }
235557          },
235558          "modelCard": {
235559            "modelParameters": {
235560              "approach": {}
235561            },
235562            "quantitativeAnalysis": {
235563              "graphics": {}
235564            },
235565            "considerations": {}
235566          }
235567        },
235568        {
235569          "type": "library",
235570          "bom-ref": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.8?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04\u0026package-id=a53aba344e652eae",
235571          "supplier": {},
235572          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235573          "name": "libapt-pkg6.0",
235574          "version": "2.0.8",
235575          "licenses": [
235576            {
235577              "license": {
235578                "id": "GPL-2.0-only"
235579              }
235580            },
235581            {
235582              "license": {
235583                "name": "GPLv2+"
235584              }
235585            }
235586          ],
235587          "cpe": "cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.0.8:*:*:*:*:*:*:*",
235588          "purl": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.8?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04",
235589          "swid": {
235590            "attachment": {}
235591          },
235592          "pedigree": {},
235593          "evidence": {},
235594          "signature": {
235595            "signature": {
235596              "publicKey": {}
235597            }
235598          },
235599          "modelCard": {
235600            "modelParameters": {
235601              "approach": {}
235602            },
235603            "quantitativeAnalysis": {
235604              "graphics": {}
235605            },
235606            "considerations": {}
235607          }
235608        },
235609        {
235610          "type": "library",
235611          "bom-ref": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04\u0026package-id=edf8dd62bd537bd5",
235612          "supplier": {},
235613          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235614          "name": "libattr1",
235615          "version": "1:2.4.48-5",
235616          "licenses": [
235617            {
235618              "license": {
235619                "id": "GPL-2.0-only"
235620              }
235621            },
235622            {
235623              "license": {
235624                "id": "GPL-2.0-or-later"
235625              }
235626            },
235627            {
235628              "license": {
235629                "id": "LGPL-2.0-or-later"
235630              }
235631            },
235632            {
235633              "license": {
235634                "id": "LGPL-2.1-only"
235635              }
235636            }
235637          ],
235638          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-5:*:*:*:*:*:*:*",
235639          "purl": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04",
235640          "swid": {
235641            "attachment": {}
235642          },
235643          "pedigree": {},
235644          "evidence": {},
235645          "signature": {
235646            "signature": {
235647              "publicKey": {}
235648            }
235649          },
235650          "modelCard": {
235651            "modelParameters": {
235652              "approach": {}
235653            },
235654            "quantitativeAnalysis": {
235655              "graphics": {}
235656            },
235657            "considerations": {}
235658          }
235659        },
235660        {
235661          "type": "library",
235662          "bom-ref": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=4a463ab850d7c68c",
235663          "supplier": {},
235664          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235665          "name": "libaudit-common",
235666          "version": "1:2.8.5-2ubuntu6",
235667          "licenses": [
235668            {
235669              "license": {
235670                "id": "GPL-1.0-only"
235671              }
235672            },
235673            {
235674              "license": {
235675                "id": "GPL-2.0-only"
235676              }
235677            },
235678            {
235679              "license": {
235680                "id": "LGPL-2.1-only"
235681              }
235682            }
235683          ],
235684          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
235685          "purl": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04",
235686          "swid": {
235687            "attachment": {}
235688          },
235689          "pedigree": {},
235690          "evidence": {},
235691          "signature": {
235692            "signature": {
235693              "publicKey": {}
235694            }
235695          },
235696          "modelCard": {
235697            "modelParameters": {
235698              "approach": {}
235699            },
235700            "quantitativeAnalysis": {
235701              "graphics": {}
235702            },
235703            "considerations": {}
235704          }
235705        },
235706        {
235707          "type": "library",
235708          "bom-ref": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=be9537deb8db616e",
235709          "supplier": {},
235710          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235711          "name": "libaudit1",
235712          "version": "1:2.8.5-2ubuntu6",
235713          "licenses": [
235714            {
235715              "license": {
235716                "id": "GPL-1.0-only"
235717              }
235718            },
235719            {
235720              "license": {
235721                "id": "GPL-2.0-only"
235722              }
235723            },
235724            {
235725              "license": {
235726                "id": "LGPL-2.1-only"
235727              }
235728            }
235729          ],
235730          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
235731          "purl": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04",
235732          "swid": {
235733            "attachment": {}
235734          },
235735          "pedigree": {},
235736          "evidence": {},
235737          "signature": {
235738            "signature": {
235739              "publicKey": {}
235740            }
235741          },
235742          "modelCard": {
235743            "modelParameters": {
235744              "approach": {}
235745            },
235746            "quantitativeAnalysis": {
235747              "graphics": {}
235748            },
235749            "considerations": {}
235750          }
235751        },
235752        {
235753          "type": "library",
235754          "bom-ref": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=8668ed2232ebc357",
235755          "supplier": {},
235756          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235757          "name": "libblkid1",
235758          "version": "2.34-0.1ubuntu9.3",
235759          "licenses": [
235760            {
235761              "license": {
235762                "id": "BSD-2-Clause"
235763              }
235764            },
235765            {
235766              "license": {
235767                "id": "BSD-3-Clause"
235768              }
235769            },
235770            {
235771              "license": {
235772                "id": "BSD-4-Clause"
235773              }
235774            },
235775            {
235776              "license": {
235777                "id": "GPL-2.0-only"
235778              }
235779            },
235780            {
235781              "license": {
235782                "id": "GPL-2.0-or-later"
235783              }
235784            },
235785            {
235786              "license": {
235787                "id": "GPL-3.0-only"
235788              }
235789            },
235790            {
235791              "license": {
235792                "id": "GPL-3.0-or-later"
235793              }
235794            },
235795            {
235796              "license": {
235797                "name": "LGPL"
235798              }
235799            },
235800            {
235801              "license": {
235802                "id": "LGPL-2.0-only"
235803              }
235804            },
235805            {
235806              "license": {
235807                "id": "LGPL-2.0-or-later"
235808              }
235809            },
235810            {
235811              "license": {
235812                "id": "LGPL-2.1-only"
235813              }
235814            },
235815            {
235816              "license": {
235817                "id": "LGPL-2.1-or-later"
235818              }
235819            },
235820            {
235821              "license": {
235822                "id": "LGPL-3.0-only"
235823              }
235824            },
235825            {
235826              "license": {
235827                "id": "LGPL-3.0-or-later"
235828              }
235829            },
235830            {
235831              "license": {
235832                "id": "MIT"
235833              }
235834            },
235835            {
235836              "license": {
235837                "name": "public-domain"
235838              }
235839            }
235840          ],
235841          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.34-0.1ubuntu9.3:*:*:*:*:*:*:*",
235842          "purl": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
235843          "swid": {
235844            "attachment": {}
235845          },
235846          "pedigree": {},
235847          "evidence": {},
235848          "signature": {
235849            "signature": {
235850              "publicKey": {}
235851            }
235852          },
235853          "modelCard": {
235854            "modelParameters": {
235855              "approach": {}
235856            },
235857            "quantitativeAnalysis": {
235858              "graphics": {}
235859            },
235860            "considerations": {}
235861          }
235862        },
235863        {
235864          "type": "library",
235865          "bom-ref": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04\u0026package-id=fd8b0edf257b69b7",
235866          "supplier": {},
235867          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235868          "name": "libbz2-1.0",
235869          "version": "1.0.8-2",
235870          "licenses": [
235871            {
235872              "license": {
235873                "name": "BSD-variant"
235874              }
235875            },
235876            {
235877              "license": {
235878                "id": "GPL-2.0-only"
235879              }
235880            }
235881          ],
235882          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-2:*:*:*:*:*:*:*",
235883          "purl": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04",
235884          "swid": {
235885            "attachment": {}
235886          },
235887          "pedigree": {},
235888          "evidence": {},
235889          "signature": {
235890            "signature": {
235891              "publicKey": {}
235892            }
235893          },
235894          "modelCard": {
235895            "modelParameters": {
235896              "approach": {}
235897            },
235898            "quantitativeAnalysis": {
235899              "graphics": {}
235900            },
235901            "considerations": {}
235902          }
235903        },
235904        {
235905          "type": "library",
235906          "bom-ref": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.9?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=57986ecc4347eed4",
235907          "supplier": {},
235908          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235909          "name": "libc-bin",
235910          "version": "2.31-0ubuntu9.9",
235911          "licenses": [
235912            {
235913              "license": {
235914                "id": "GPL-2.0-only"
235915              }
235916            },
235917            {
235918              "license": {
235919                "id": "LGPL-2.1-only"
235920              }
235921            }
235922          ],
235923          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.31-0ubuntu9.9:*:*:*:*:*:*:*",
235924          "purl": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.9?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
235925          "swid": {
235926            "attachment": {}
235927          },
235928          "pedigree": {},
235929          "evidence": {},
235930          "signature": {
235931            "signature": {
235932              "publicKey": {}
235933            }
235934          },
235935          "modelCard": {
235936            "modelParameters": {
235937              "approach": {}
235938            },
235939            "quantitativeAnalysis": {
235940              "graphics": {}
235941            },
235942            "considerations": {}
235943          }
235944        },
235945        {
235946          "type": "library",
235947          "bom-ref": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.9?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=8e27f98d9024ca2a",
235948          "supplier": {},
235949          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235950          "name": "libc6",
235951          "version": "2.31-0ubuntu9.9",
235952          "licenses": [
235953            {
235954              "license": {
235955                "id": "GPL-2.0-only"
235956              }
235957            },
235958            {
235959              "license": {
235960                "id": "LGPL-2.1-only"
235961              }
235962            }
235963          ],
235964          "cpe": "cpe:2.3:a:libc6:libc6:2.31-0ubuntu9.9:*:*:*:*:*:*:*",
235965          "purl": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.9?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
235966          "swid": {
235967            "attachment": {}
235968          },
235969          "pedigree": {},
235970          "evidence": {},
235971          "signature": {
235972            "signature": {
235973              "publicKey": {}
235974            }
235975          },
235976          "modelCard": {
235977            "modelParameters": {
235978              "approach": {}
235979            },
235980            "quantitativeAnalysis": {
235981              "graphics": {}
235982            },
235983            "considerations": {}
235984          }
235985        },
235986        {
235987          "type": "library",
235988          "bom-ref": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04\u0026package-id=57ceb68462a99cb4",
235989          "supplier": {},
235990          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
235991          "name": "libcap-ng0",
235992          "version": "0.7.9-2.1build1",
235993          "licenses": [
235994            {
235995              "license": {
235996                "id": "GPL-2.0-only"
235997              }
235998            },
235999            {
236000              "license": {
236001                "id": "GPL-3.0-only"
236002              }
236003            },
236004            {
236005              "license": {
236006                "id": "LGPL-2.1-only"
236007              }
236008            }
236009          ],
236010          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2.1build1:*:*:*:*:*:*:*",
236011          "purl": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04",
236012          "swid": {
236013            "attachment": {}
236014          },
236015          "pedigree": {},
236016          "evidence": {},
236017          "signature": {
236018            "signature": {
236019              "publicKey": {}
236020            }
236021          },
236022          "modelCard": {
236023            "modelParameters": {
236024              "approach": {}
236025            },
236026            "quantitativeAnalysis": {
236027              "graphics": {}
236028            },
236029            "considerations": {}
236030          }
236031        },
236032        {
236033          "type": "library",
236034          "bom-ref": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=fbaeb4c3d5d0f976",
236035          "supplier": {},
236036          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236037          "name": "libcom-err2",
236038          "version": "1.45.5-2ubuntu1",
236039          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
236040          "purl": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
236041          "swid": {
236042            "attachment": {}
236043          },
236044          "pedigree": {},
236045          "evidence": {},
236046          "signature": {
236047            "signature": {
236048              "publicKey": {}
236049            }
236050          },
236051          "modelCard": {
236052            "modelParameters": {
236053              "approach": {}
236054            },
236055            "quantitativeAnalysis": {
236056              "graphics": {}
236057            },
236058            "considerations": {}
236059          }
236060        },
236061        {
236062          "type": "library",
236063          "bom-ref": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04\u0026package-id=8a4302e2e7027353",
236064          "supplier": {},
236065          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236066          "name": "libcrypt1",
236067          "version": "1:4.4.10-10ubuntu4",
236068          "cpe": "cpe:2.3:a:libcrypt1:libcrypt1:1\\:4.4.10-10ubuntu4:*:*:*:*:*:*:*",
236069          "purl": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04",
236070          "swid": {
236071            "attachment": {}
236072          },
236073          "pedigree": {},
236074          "evidence": {},
236075          "signature": {
236076            "signature": {
236077              "publicKey": {}
236078            }
236079          },
236080          "modelCard": {
236081            "modelParameters": {
236082              "approach": {}
236083            },
236084            "quantitativeAnalysis": {
236085              "graphics": {}
236086            },
236087            "considerations": {}
236088          }
236089        },
236090        {
236091          "type": "library",
236092          "bom-ref": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04\u0026package-id=bc84b4da0031640d",
236093          "supplier": {},
236094          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236095          "name": "libdb5.3",
236096          "version": "5.3.28+dfsg1-0.6ubuntu2",
236097          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.6ubuntu2:*:*:*:*:*:*:*",
236098          "purl": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04",
236099          "swid": {
236100            "attachment": {}
236101          },
236102          "pedigree": {},
236103          "evidence": {},
236104          "signature": {
236105            "signature": {
236106              "publicKey": {}
236107            }
236108          },
236109          "modelCard": {
236110            "modelParameters": {
236111              "approach": {}
236112            },
236113            "quantitativeAnalysis": {
236114              "graphics": {}
236115            },
236116            "considerations": {}
236117          }
236118        },
236119        {
236120          "type": "library",
236121          "bom-ref": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04\u0026package-id=78bbe40d9c2ef9b5",
236122          "supplier": {},
236123          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236124          "name": "libdebconfclient0",
236125          "version": "0.251ubuntu1",
236126          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.251ubuntu1:*:*:*:*:*:*:*",
236127          "purl": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04",
236128          "swid": {
236129            "attachment": {}
236130          },
236131          "pedigree": {},
236132          "evidence": {},
236133          "signature": {
236134            "signature": {
236135              "publicKey": {}
236136            }
236137          },
236138          "modelCard": {
236139            "modelParameters": {
236140              "approach": {}
236141            },
236142            "quantitativeAnalysis": {
236143              "graphics": {}
236144            },
236145            "considerations": {}
236146          }
236147        },
236148        {
236149          "type": "library",
236150          "bom-ref": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=ec6113f55e73d1fd",
236151          "supplier": {},
236152          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236153          "name": "libext2fs2",
236154          "version": "1.45.5-2ubuntu1",
236155          "licenses": [
236156            {
236157              "license": {
236158                "id": "GPL-2.0-only"
236159              }
236160            },
236161            {
236162              "license": {
236163                "id": "LGPL-2.0-only"
236164              }
236165            }
236166          ],
236167          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
236168          "purl": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
236169          "swid": {
236170            "attachment": {}
236171          },
236172          "pedigree": {},
236173          "evidence": {},
236174          "signature": {
236175            "signature": {
236176              "publicKey": {}
236177            }
236178          },
236179          "modelCard": {
236180            "modelParameters": {
236181              "approach": {}
236182            },
236183            "quantitativeAnalysis": {
236184              "graphics": {}
236185            },
236186            "considerations": {}
236187          }
236188        },
236189        {
236190          "type": "library",
236191          "bom-ref": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=95ad31e81a712549",
236192          "supplier": {},
236193          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236194          "name": "libfdisk1",
236195          "version": "2.34-0.1ubuntu9.3",
236196          "licenses": [
236197            {
236198              "license": {
236199                "id": "BSD-2-Clause"
236200              }
236201            },
236202            {
236203              "license": {
236204                "id": "BSD-3-Clause"
236205              }
236206            },
236207            {
236208              "license": {
236209                "id": "BSD-4-Clause"
236210              }
236211            },
236212            {
236213              "license": {
236214                "id": "GPL-2.0-only"
236215              }
236216            },
236217            {
236218              "license": {
236219                "id": "GPL-2.0-or-later"
236220              }
236221            },
236222            {
236223              "license": {
236224                "id": "GPL-3.0-only"
236225              }
236226            },
236227            {
236228              "license": {
236229                "id": "GPL-3.0-or-later"
236230              }
236231            },
236232            {
236233              "license": {
236234                "name": "LGPL"
236235              }
236236            },
236237            {
236238              "license": {
236239                "id": "LGPL-2.0-only"
236240              }
236241            },
236242            {
236243              "license": {
236244                "id": "LGPL-2.0-or-later"
236245              }
236246            },
236247            {
236248              "license": {
236249                "id": "LGPL-2.1-only"
236250              }
236251            },
236252            {
236253              "license": {
236254                "id": "LGPL-2.1-or-later"
236255              }
236256            },
236257            {
236258              "license": {
236259                "id": "LGPL-3.0-only"
236260              }
236261            },
236262            {
236263              "license": {
236264                "id": "LGPL-3.0-or-later"
236265              }
236266            },
236267            {
236268              "license": {
236269                "id": "MIT"
236270              }
236271            },
236272            {
236273              "license": {
236274                "name": "public-domain"
236275              }
236276            }
236277          ],
236278          "cpe": "cpe:2.3:a:libfdisk1:libfdisk1:2.34-0.1ubuntu9.3:*:*:*:*:*:*:*",
236279          "purl": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
236280          "swid": {
236281            "attachment": {}
236282          },
236283          "pedigree": {},
236284          "evidence": {},
236285          "signature": {
236286            "signature": {
236287              "publicKey": {}
236288            }
236289          },
236290          "modelCard": {
236291            "modelParameters": {
236292              "approach": {}
236293            },
236294            "quantitativeAnalysis": {
236295              "graphics": {}
236296            },
236297            "considerations": {}
236298          }
236299        },
236300        {
236301          "type": "library",
236302          "bom-ref": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04\u0026package-id=b43b799d45da9d97",
236303          "supplier": {},
236304          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236305          "name": "libffi7",
236306          "version": "3.3-4",
236307          "licenses": [
236308            {
236309              "license": {
236310                "name": "GPL"
236311              }
236312            }
236313          ],
236314          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-4:*:*:*:*:*:*:*",
236315          "purl": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04",
236316          "swid": {
236317            "attachment": {}
236318          },
236319          "pedigree": {},
236320          "evidence": {},
236321          "signature": {
236322            "signature": {
236323              "publicKey": {}
236324            }
236325          },
236326          "modelCard": {
236327            "modelParameters": {
236328              "approach": {}
236329            },
236330            "quantitativeAnalysis": {
236331              "graphics": {}
236332            },
236333            "considerations": {}
236334          }
236335        },
236336        {
236337          "type": "library",
236338          "bom-ref": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=f98ce69fd9e55bb8",
236339          "supplier": {},
236340          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236341          "name": "libgcc-s1",
236342          "version": "10.3.0-1ubuntu1~20.04",
236343          "licenses": [
236344            {
236345              "license": {
236346                "name": "Artistic"
236347              }
236348            },
236349            {
236350              "license": {
236351                "id": "GFDL-1.2-only"
236352              }
236353            },
236354            {
236355              "license": {
236356                "name": "GPL"
236357              }
236358            },
236359            {
236360              "license": {
236361                "id": "GPL-2.0-only"
236362              }
236363            },
236364            {
236365              "license": {
236366                "id": "GPL-3.0-only"
236367              }
236368            },
236369            {
236370              "license": {
236371                "name": "LGPL"
236372              }
236373            }
236374          ],
236375          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
236376          "purl": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
236377          "swid": {
236378            "attachment": {}
236379          },
236380          "pedigree": {},
236381          "evidence": {},
236382          "signature": {
236383            "signature": {
236384              "publicKey": {}
236385            }
236386          },
236387          "modelCard": {
236388            "modelParameters": {
236389              "approach": {}
236390            },
236391            "quantitativeAnalysis": {
236392              "graphics": {}
236393            },
236394            "considerations": {}
236395          }
236396        },
236397        {
236398          "type": "library",
236399          "bom-ref": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=779dc4322dee5841",
236400          "supplier": {},
236401          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236402          "name": "libgcrypt20",
236403          "version": "1.8.5-5ubuntu1.1",
236404          "licenses": [
236405            {
236406              "license": {
236407                "id": "GPL-2.0-only"
236408              }
236409            },
236410            {
236411              "license": {
236412                "name": "LGPL"
236413              }
236414            }
236415          ],
236416          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.5-5ubuntu1.1:*:*:*:*:*:*:*",
236417          "purl": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04",
236418          "swid": {
236419            "attachment": {}
236420          },
236421          "pedigree": {},
236422          "evidence": {},
236423          "signature": {
236424            "signature": {
236425              "publicKey": {}
236426            }
236427          },
236428          "modelCard": {
236429            "modelParameters": {
236430              "approach": {}
236431            },
236432            "quantitativeAnalysis": {
236433              "graphics": {}
236434            },
236435            "considerations": {}
236436          }
236437        },
236438        {
236439          "type": "library",
236440          "bom-ref": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04\u0026package-id=40fc269dcb8b3369",
236441          "supplier": {},
236442          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236443          "name": "libgmp10",
236444          "version": "2:6.2.0+dfsg-4",
236445          "licenses": [
236446            {
236447              "license": {
236448                "name": "GPL"
236449              }
236450            },
236451            {
236452              "license": {
236453                "id": "GPL-2.0-only"
236454              }
236455            },
236456            {
236457              "license": {
236458                "id": "GPL-3.0-only"
236459              }
236460            },
236461            {
236462              "license": {
236463                "id": "LGPL-3.0-only"
236464              }
236465            }
236466          ],
236467          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.0\\+dfsg-4:*:*:*:*:*:*:*",
236468          "purl": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04",
236469          "swid": {
236470            "attachment": {}
236471          },
236472          "pedigree": {},
236473          "evidence": {},
236474          "signature": {
236475            "signature": {
236476              "publicKey": {}
236477            }
236478          },
236479          "modelCard": {
236480            "modelParameters": {
236481              "approach": {}
236482            },
236483            "quantitativeAnalysis": {
236484              "graphics": {}
236485            },
236486            "considerations": {}
236487          }
236488        },
236489        {
236490          "type": "library",
236491          "bom-ref": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04\u0026package-id=7490f76da775c6e",
236492          "supplier": {},
236493          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236494          "name": "libgnutls30",
236495          "version": "3.6.13-2ubuntu1.6",
236496          "licenses": [
236497            {
236498              "license": {
236499                "id": "Apache-2.0"
236500              }
236501            },
236502            {
236503              "license": {
236504                "id": "BSD-3-Clause"
236505              }
236506            },
236507            {
236508              "license": {
236509                "name": "CC0"
236510              }
236511            },
236512            {
236513              "license": {
236514                "name": "Expat"
236515              }
236516            },
236517            {
236518              "license": {
236519                "id": "GFDL-1.3-only"
236520              }
236521            },
236522            {
236523              "license": {
236524                "name": "GPL"
236525              }
236526            },
236527            {
236528              "license": {
236529                "id": "GPL-3.0-only"
236530              }
236531            },
236532            {
236533              "license": {
236534                "name": "GPLv3+"
236535              }
236536            },
236537            {
236538              "license": {
236539                "name": "LGPL"
236540              }
236541            },
236542            {
236543              "license": {
236544                "id": "LGPL-3.0-only"
236545              }
236546            },
236547            {
236548              "license": {
236549                "name": "LGPLv2.1+"
236550              }
236551            },
236552            {
236553              "license": {
236554                "name": "LGPLv3+_or_GPLv2+"
236555              }
236556            },
236557            {
236558              "license": {
236559                "name": "The"
236560              }
236561            }
236562          ],
236563          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.13-2ubuntu1.6:*:*:*:*:*:*:*",
236564          "purl": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04",
236565          "swid": {
236566            "attachment": {}
236567          },
236568          "pedigree": {},
236569          "evidence": {},
236570          "signature": {
236571            "signature": {
236572              "publicKey": {}
236573            }
236574          },
236575          "modelCard": {
236576            "modelParameters": {
236577              "approach": {}
236578            },
236579            "quantitativeAnalysis": {
236580              "graphics": {}
236581            },
236582            "considerations": {}
236583          }
236584        },
236585        {
236586          "type": "library",
236587          "bom-ref": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04\u0026package-id=37ef62d87edfe03",
236588          "supplier": {},
236589          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236590          "name": "libgpg-error0",
236591          "version": "1.37-1",
236592          "licenses": [
236593            {
236594              "license": {
236595                "id": "BSD-3-Clause"
236596              }
236597            },
236598            {
236599              "license": {
236600                "id": "GPL-3.0-only"
236601              }
236602            },
236603            {
236604              "license": {
236605                "id": "GPL-3.0-or-later"
236606              }
236607            },
236608            {
236609              "license": {
236610                "id": "LGPL-2.1-only"
236611              }
236612            },
236613            {
236614              "license": {
236615                "id": "LGPL-2.1-or-later"
236616              }
236617            },
236618            {
236619              "license": {
236620                "name": "g10-permissive"
236621              }
236622            }
236623          ],
236624          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.37-1:*:*:*:*:*:*:*",
236625          "purl": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04",
236626          "swid": {
236627            "attachment": {}
236628          },
236629          "pedigree": {},
236630          "evidence": {},
236631          "signature": {
236632            "signature": {
236633              "publicKey": {}
236634            }
236635          },
236636          "modelCard": {
236637            "modelParameters": {
236638              "approach": {}
236639            },
236640            "quantitativeAnalysis": {
236641              "graphics": {}
236642            },
236643            "considerations": {}
236644          }
236645        },
236646        {
236647          "type": "library",
236648          "bom-ref": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3caecccf070e6760",
236649          "supplier": {},
236650          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236651          "name": "libhogweed5",
236652          "version": "3.5.1+really3.5.1-2ubuntu0.2",
236653          "licenses": [
236654            {
236655              "license": {
236656                "name": "GAP"
236657              }
236658            },
236659            {
236660              "license": {
236661                "name": "GPL"
236662              }
236663            },
236664            {
236665              "license": {
236666                "id": "GPL-2.0-only"
236667              }
236668            },
236669            {
236670              "license": {
236671                "id": "GPL-2.0-or-later"
236672              }
236673            },
236674            {
236675              "license": {
236676                "name": "LGPL"
236677              }
236678            },
236679            {
236680              "license": {
236681                "id": "LGPL-2.0-only"
236682              }
236683            },
236684            {
236685              "license": {
236686                "id": "LGPL-2.0-or-later"
236687              }
236688            },
236689            {
236690              "license": {
236691                "id": "LGPL-2.1-or-later"
236692              }
236693            },
236694            {
236695              "license": {
236696                "name": "other"
236697              }
236698            },
236699            {
236700              "license": {
236701                "name": "public-domain"
236702              }
236703            }
236704          ],
236705          "cpe": "cpe:2.3:a:libhogweed5:libhogweed5:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
236706          "purl": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
236707          "swid": {
236708            "attachment": {}
236709          },
236710          "pedigree": {},
236711          "evidence": {},
236712          "signature": {
236713            "signature": {
236714              "publicKey": {}
236715            }
236716          },
236717          "modelCard": {
236718            "modelParameters": {
236719              "approach": {}
236720            },
236721            "quantitativeAnalysis": {
236722              "graphics": {}
236723            },
236724            "considerations": {}
236725          }
236726        },
236727        {
236728          "type": "library",
236729          "bom-ref": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04\u0026package-id=d2a82c3e28413bc1",
236730          "supplier": {},
236731          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236732          "name": "libidn2-0",
236733          "version": "2.2.0-2",
236734          "licenses": [
236735            {
236736              "license": {
236737                "id": "GPL-2.0-only"
236738              }
236739            },
236740            {
236741              "license": {
236742                "id": "GPL-2.0-or-later"
236743              }
236744            },
236745            {
236746              "license": {
236747                "id": "GPL-3.0-only"
236748              }
236749            },
236750            {
236751              "license": {
236752                "id": "GPL-3.0-or-later"
236753              }
236754            },
236755            {
236756              "license": {
236757                "id": "LGPL-3.0-only"
236758              }
236759            },
236760            {
236761              "license": {
236762                "id": "LGPL-3.0-or-later"
236763              }
236764            },
236765            {
236766              "license": {
236767                "name": "Unicode"
236768              }
236769            }
236770          ],
236771          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.2.0-2:*:*:*:*:*:*:*",
236772          "purl": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04",
236773          "swid": {
236774            "attachment": {}
236775          },
236776          "pedigree": {},
236777          "evidence": {},
236778          "signature": {
236779            "signature": {
236780              "publicKey": {}
236781            }
236782          },
236783          "modelCard": {
236784            "modelParameters": {
236785              "approach": {}
236786            },
236787            "quantitativeAnalysis": {
236788              "graphics": {}
236789            },
236790            "considerations": {}
236791          }
236792        },
236793        {
236794          "type": "library",
236795          "bom-ref": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04\u0026package-id=6f2c431caeb4980a",
236796          "supplier": {},
236797          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236798          "name": "liblz4-1",
236799          "version": "1.9.2-2ubuntu0.20.04.1",
236800          "licenses": [
236801            {
236802              "license": {
236803                "id": "BSD-2-Clause"
236804              }
236805            },
236806            {
236807              "license": {
236808                "id": "GPL-2.0-only"
236809              }
236810            },
236811            {
236812              "license": {
236813                "id": "GPL-2.0-or-later"
236814              }
236815            }
236816          ],
236817          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.2-2ubuntu0.20.04.1:*:*:*:*:*:*:*",
236818          "purl": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04",
236819          "swid": {
236820            "attachment": {}
236821          },
236822          "pedigree": {},
236823          "evidence": {},
236824          "signature": {
236825            "signature": {
236826              "publicKey": {}
236827            }
236828          },
236829          "modelCard": {
236830            "modelParameters": {
236831              "approach": {}
236832            },
236833            "quantitativeAnalysis": {
236834              "graphics": {}
236835            },
236836            "considerations": {}
236837          }
236838        },
236839        {
236840          "type": "library",
236841          "bom-ref": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1.1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04\u0026package-id=a8f6e2f0d5df075c",
236842          "supplier": {},
236843          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236844          "name": "liblzma5",
236845          "version": "5.2.4-1ubuntu1.1",
236846          "licenses": [
236847            {
236848              "license": {
236849                "name": "Autoconf"
236850              }
236851            },
236852            {
236853              "license": {
236854                "id": "GPL-2.0-only"
236855              }
236856            },
236857            {
236858              "license": {
236859                "id": "GPL-2.0-or-later"
236860              }
236861            },
236862            {
236863              "license": {
236864                "id": "GPL-3.0-only"
236865              }
236866            },
236867            {
236868              "license": {
236869                "id": "LGPL-2.0-only"
236870              }
236871            },
236872            {
236873              "license": {
236874                "id": "LGPL-2.1-only"
236875              }
236876            },
236877            {
236878              "license": {
236879                "id": "LGPL-2.1-or-later"
236880              }
236881            },
236882            {
236883              "license": {
236884                "name": "PD"
236885              }
236886            },
236887            {
236888              "license": {
236889                "name": "PD-debian"
236890              }
236891            },
236892            {
236893              "license": {
236894                "name": "config-h"
236895              }
236896            },
236897            {
236898              "license": {
236899                "name": "noderivs"
236900              }
236901            },
236902            {
236903              "license": {
236904                "name": "permissive-fsf"
236905              }
236906            },
236907            {
236908              "license": {
236909                "name": "permissive-nowarranty"
236910              }
236911            },
236912            {
236913              "license": {
236914                "name": "probably-PD"
236915              }
236916            }
236917          ],
236918          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.4-1ubuntu1.1:*:*:*:*:*:*:*",
236919          "purl": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1.1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04",
236920          "swid": {
236921            "attachment": {}
236922          },
236923          "pedigree": {},
236924          "evidence": {},
236925          "signature": {
236926            "signature": {
236927              "publicKey": {}
236928            }
236929          },
236930          "modelCard": {
236931            "modelParameters": {
236932              "approach": {}
236933            },
236934            "quantitativeAnalysis": {
236935              "graphics": {}
236936            },
236937            "considerations": {}
236938          }
236939        },
236940        {
236941          "type": "library",
236942          "bom-ref": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=73e2bbfe6d27dd86",
236943          "supplier": {},
236944          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
236945          "name": "libmount1",
236946          "version": "2.34-0.1ubuntu9.3",
236947          "licenses": [
236948            {
236949              "license": {
236950                "id": "BSD-2-Clause"
236951              }
236952            },
236953            {
236954              "license": {
236955                "id": "BSD-3-Clause"
236956              }
236957            },
236958            {
236959              "license": {
236960                "id": "BSD-4-Clause"
236961              }
236962            },
236963            {
236964              "license": {
236965                "id": "GPL-2.0-only"
236966              }
236967            },
236968            {
236969              "license": {
236970                "id": "GPL-2.0-or-later"
236971              }
236972            },
236973            {
236974              "license": {
236975                "id": "GPL-3.0-only"
236976              }
236977            },
236978            {
236979              "license": {
236980                "id": "GPL-3.0-or-later"
236981              }
236982            },
236983            {
236984              "license": {
236985                "name": "LGPL"
236986              }
236987            },
236988            {
236989              "license": {
236990                "id": "LGPL-2.0-only"
236991              }
236992            },
236993            {
236994              "license": {
236995                "id": "LGPL-2.0-or-later"
236996              }
236997            },
236998            {
236999              "license": {
237000                "id": "LGPL-2.1-only"
237001              }
237002            },
237003            {
237004              "license": {
237005                "id": "LGPL-2.1-or-later"
237006              }
237007            },
237008            {
237009              "license": {
237010                "id": "LGPL-3.0-only"
237011              }
237012            },
237013            {
237014              "license": {
237015                "id": "LGPL-3.0-or-later"
237016              }
237017            },
237018            {
237019              "license": {
237020                "id": "MIT"
237021              }
237022            },
237023            {
237024              "license": {
237025                "name": "public-domain"
237026              }
237027            }
237028          ],
237029          "cpe": "cpe:2.3:a:libmount1:libmount1:2.34-0.1ubuntu9.3:*:*:*:*:*:*:*",
237030          "purl": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
237031          "swid": {
237032            "attachment": {}
237033          },
237034          "pedigree": {},
237035          "evidence": {},
237036          "signature": {
237037            "signature": {
237038              "publicKey": {}
237039            }
237040          },
237041          "modelCard": {
237042            "modelParameters": {
237043              "approach": {}
237044            },
237045            "quantitativeAnalysis": {
237046              "graphics": {}
237047            },
237048            "considerations": {}
237049          }
237050        },
237051        {
237052          "type": "library",
237053          "bom-ref": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=ed8fb166163a75b8",
237054          "supplier": {},
237055          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237056          "name": "libncurses6",
237057          "version": "6.2-0ubuntu2",
237058          "cpe": "cpe:2.3:a:libncurses6:libncurses6:6.2-0ubuntu2:*:*:*:*:*:*:*",
237059          "purl": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
237060          "swid": {
237061            "attachment": {}
237062          },
237063          "pedigree": {},
237064          "evidence": {},
237065          "signature": {
237066            "signature": {
237067              "publicKey": {}
237068            }
237069          },
237070          "modelCard": {
237071            "modelParameters": {
237072              "approach": {}
237073            },
237074            "quantitativeAnalysis": {
237075              "graphics": {}
237076            },
237077            "considerations": {}
237078          }
237079        },
237080        {
237081          "type": "library",
237082          "bom-ref": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=58525ddc073a008a",
237083          "supplier": {},
237084          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237085          "name": "libncursesw6",
237086          "version": "6.2-0ubuntu2",
237087          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.2-0ubuntu2:*:*:*:*:*:*:*",
237088          "purl": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
237089          "swid": {
237090            "attachment": {}
237091          },
237092          "pedigree": {},
237093          "evidence": {},
237094          "signature": {
237095            "signature": {
237096              "publicKey": {}
237097            }
237098          },
237099          "modelCard": {
237100            "modelParameters": {
237101              "approach": {}
237102            },
237103            "quantitativeAnalysis": {
237104              "graphics": {}
237105            },
237106            "considerations": {}
237107          }
237108        },
237109        {
237110          "type": "library",
237111          "bom-ref": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3d185fbd6a7e56f",
237112          "supplier": {},
237113          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237114          "name": "libnettle7",
237115          "version": "3.5.1+really3.5.1-2ubuntu0.2",
237116          "licenses": [
237117            {
237118              "license": {
237119                "name": "GAP"
237120              }
237121            },
237122            {
237123              "license": {
237124                "name": "GPL"
237125              }
237126            },
237127            {
237128              "license": {
237129                "id": "GPL-2.0-only"
237130              }
237131            },
237132            {
237133              "license": {
237134                "id": "GPL-2.0-or-later"
237135              }
237136            },
237137            {
237138              "license": {
237139                "name": "LGPL"
237140              }
237141            },
237142            {
237143              "license": {
237144                "id": "LGPL-2.0-only"
237145              }
237146            },
237147            {
237148              "license": {
237149                "id": "LGPL-2.0-or-later"
237150              }
237151            },
237152            {
237153              "license": {
237154                "id": "LGPL-2.1-or-later"
237155              }
237156            },
237157            {
237158              "license": {
237159                "name": "other"
237160              }
237161            },
237162            {
237163              "license": {
237164                "name": "public-domain"
237165              }
237166            }
237167          ],
237168          "cpe": "cpe:2.3:a:libnettle7:libnettle7:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
237169          "purl": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
237170          "swid": {
237171            "attachment": {}
237172          },
237173          "pedigree": {},
237174          "evidence": {},
237175          "signature": {
237176            "signature": {
237177              "publicKey": {}
237178            }
237179          },
237180          "modelCard": {
237181            "modelParameters": {
237182              "approach": {}
237183            },
237184            "quantitativeAnalysis": {
237185              "graphics": {}
237186            },
237187            "considerations": {}
237188          }
237189        },
237190        {
237191          "type": "library",
237192          "bom-ref": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04\u0026package-id=9fc0ca46e6d21557",
237193          "supplier": {},
237194          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237195          "name": "libp11-kit0",
237196          "version": "0.23.20-1ubuntu0.1",
237197          "licenses": [
237198            {
237199              "license": {
237200                "id": "BSD-3-Clause"
237201              }
237202            },
237203            {
237204              "license": {
237205                "id": "ISC"
237206              }
237207            },
237208            {
237209              "license": {
237210                "name": "ISC+IBM"
237211              }
237212            },
237213            {
237214              "license": {
237215                "name": "permissive-like-automake-output"
237216              }
237217            },
237218            {
237219              "license": {
237220                "name": "same-as-rest-of-p11kit"
237221              }
237222            }
237223          ],
237224          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.20-1ubuntu0.1:*:*:*:*:*:*:*",
237225          "purl": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04",
237226          "swid": {
237227            "attachment": {}
237228          },
237229          "pedigree": {},
237230          "evidence": {},
237231          "signature": {
237232            "signature": {
237233              "publicKey": {}
237234            }
237235          },
237236          "modelCard": {
237237            "modelParameters": {
237238              "approach": {}
237239            },
237240            "quantitativeAnalysis": {
237241              "graphics": {}
237242            },
237243            "considerations": {}
237244          }
237245        },
237246        {
237247          "type": "library",
237248          "bom-ref": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=563cd7ffd9ad09e2",
237249          "supplier": {},
237250          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237251          "name": "libpam-modules",
237252          "version": "1.3.1-5ubuntu4.3",
237253          "licenses": [
237254            {
237255              "license": {
237256                "name": "GPL"
237257              }
237258            }
237259          ],
237260          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.3.1-5ubuntu4.3:*:*:*:*:*:*:*",
237261          "purl": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
237262          "swid": {
237263            "attachment": {}
237264          },
237265          "pedigree": {},
237266          "evidence": {},
237267          "signature": {
237268            "signature": {
237269              "publicKey": {}
237270            }
237271          },
237272          "modelCard": {
237273            "modelParameters": {
237274              "approach": {}
237275            },
237276            "quantitativeAnalysis": {
237277              "graphics": {}
237278            },
237279            "considerations": {}
237280          }
237281        },
237282        {
237283          "type": "library",
237284          "bom-ref": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=2fef7b748bc46246",
237285          "supplier": {},
237286          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237287          "name": "libpam-modules-bin",
237288          "version": "1.3.1-5ubuntu4.3",
237289          "licenses": [
237290            {
237291              "license": {
237292                "name": "GPL"
237293              }
237294            }
237295          ],
237296          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.3.1-5ubuntu4.3:*:*:*:*:*:*:*",
237297          "purl": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
237298          "swid": {
237299            "attachment": {}
237300          },
237301          "pedigree": {},
237302          "evidence": {},
237303          "signature": {
237304            "signature": {
237305              "publicKey": {}
237306            }
237307          },
237308          "modelCard": {
237309            "modelParameters": {
237310              "approach": {}
237311            },
237312            "quantitativeAnalysis": {
237313              "graphics": {}
237314            },
237315            "considerations": {}
237316          }
237317        },
237318        {
237319          "type": "library",
237320          "bom-ref": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.3?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=ee86ac677ddf58c5",
237321          "supplier": {},
237322          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237323          "name": "libpam-runtime",
237324          "version": "1.3.1-5ubuntu4.3",
237325          "licenses": [
237326            {
237327              "license": {
237328                "name": "GPL"
237329              }
237330            }
237331          ],
237332          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.3.1-5ubuntu4.3:*:*:*:*:*:*:*",
237333          "purl": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.3?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04",
237334          "swid": {
237335            "attachment": {}
237336          },
237337          "pedigree": {},
237338          "evidence": {},
237339          "signature": {
237340            "signature": {
237341              "publicKey": {}
237342            }
237343          },
237344          "modelCard": {
237345            "modelParameters": {
237346              "approach": {}
237347            },
237348            "quantitativeAnalysis": {
237349              "graphics": {}
237350            },
237351            "considerations": {}
237352          }
237353        },
237354        {
237355          "type": "library",
237356          "bom-ref": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=473c40bcd3d2ef2d",
237357          "supplier": {},
237358          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237359          "name": "libpam0g",
237360          "version": "1.3.1-5ubuntu4.3",
237361          "licenses": [
237362            {
237363              "license": {
237364                "name": "GPL"
237365              }
237366            }
237367          ],
237368          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.3.1-5ubuntu4.3:*:*:*:*:*:*:*",
237369          "purl": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.3?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
237370          "swid": {
237371            "attachment": {}
237372          },
237373          "pedigree": {},
237374          "evidence": {},
237375          "signature": {
237376            "signature": {
237377              "publicKey": {}
237378            }
237379          },
237380          "modelCard": {
237381            "modelParameters": {
237382              "approach": {}
237383            },
237384            "quantitativeAnalysis": {
237385              "graphics": {}
237386            },
237387            "considerations": {}
237388          }
237389        },
237390        {
237391          "type": "library",
237392          "bom-ref": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04\u0026package-id=ec9eb70008ed8b14",
237393          "supplier": {},
237394          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237395          "name": "libpcre2-8-0",
237396          "version": "10.34-7",
237397          "cpe": "cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.34-7:*:*:*:*:*:*:*",
237398          "purl": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04",
237399          "swid": {
237400            "attachment": {}
237401          },
237402          "pedigree": {},
237403          "evidence": {},
237404          "signature": {
237405            "signature": {
237406              "publicKey": {}
237407            }
237408          },
237409          "modelCard": {
237410            "modelParameters": {
237411              "approach": {}
237412            },
237413            "quantitativeAnalysis": {
237414              "graphics": {}
237415            },
237416            "considerations": {}
237417          }
237418        },
237419        {
237420          "type": "library",
237421          "bom-ref": "pkg:deb/ubuntu/libpcre3@2:8.39-12ubuntu0.1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04\u0026package-id=28df348f627128bf",
237422          "supplier": {},
237423          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237424          "name": "libpcre3",
237425          "version": "2:8.39-12ubuntu0.1",
237426          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-12ubuntu0.1:*:*:*:*:*:*:*",
237427          "purl": "pkg:deb/ubuntu/libpcre3@2:8.39-12ubuntu0.1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04",
237428          "swid": {
237429            "attachment": {}
237430          },
237431          "pedigree": {},
237432          "evidence": {},
237433          "signature": {
237434            "signature": {
237435              "publicKey": {}
237436            }
237437          },
237438          "modelCard": {
237439            "modelParameters": {
237440              "approach": {}
237441            },
237442            "quantitativeAnalysis": {
237443              "graphics": {}
237444            },
237445            "considerations": {}
237446          }
237447        },
237448        {
237449          "type": "library",
237450          "bom-ref": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.3?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04\u0026package-id=393a438be5ba5065",
237451          "supplier": {},
237452          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237453          "name": "libprocps8",
237454          "version": "2:3.3.16-1ubuntu2.3",
237455          "licenses": [
237456            {
237457              "license": {
237458                "id": "GPL-2.0-only"
237459              }
237460            },
237461            {
237462              "license": {
237463                "id": "GPL-2.0-or-later"
237464              }
237465            },
237466            {
237467              "license": {
237468                "id": "LGPL-2.0-only"
237469              }
237470            },
237471            {
237472              "license": {
237473                "id": "LGPL-2.0-or-later"
237474              }
237475            },
237476            {
237477              "license": {
237478                "id": "LGPL-2.1-only"
237479              }
237480            },
237481            {
237482              "license": {
237483                "id": "LGPL-2.1-or-later"
237484              }
237485            }
237486          ],
237487          "cpe": "cpe:2.3:a:libprocps8:libprocps8:2\\:3.3.16-1ubuntu2.3:*:*:*:*:*:*:*",
237488          "purl": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.3?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04",
237489          "swid": {
237490            "attachment": {}
237491          },
237492          "pedigree": {},
237493          "evidence": {},
237494          "signature": {
237495            "signature": {
237496              "publicKey": {}
237497            }
237498          },
237499          "modelCard": {
237500            "modelParameters": {
237501              "approach": {}
237502            },
237503            "quantitativeAnalysis": {
237504              "graphics": {}
237505            },
237506            "considerations": {}
237507          }
237508        },
237509        {
237510          "type": "library",
237511          "bom-ref": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.2?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04\u0026package-id=355e0292bcd139c5",
237512          "supplier": {},
237513          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237514          "name": "libseccomp2",
237515          "version": "2.5.1-1ubuntu1~20.04.2",
237516          "licenses": [
237517            {
237518              "license": {
237519                "id": "LGPL-2.1-only"
237520              }
237521            }
237522          ],
237523          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.5.1-1ubuntu1\\~20.04.2:*:*:*:*:*:*:*",
237524          "purl": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.2?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04",
237525          "swid": {
237526            "attachment": {}
237527          },
237528          "pedigree": {},
237529          "evidence": {},
237530          "signature": {
237531            "signature": {
237532              "publicKey": {}
237533            }
237534          },
237535          "modelCard": {
237536            "modelParameters": {
237537              "approach": {}
237538            },
237539            "quantitativeAnalysis": {
237540              "graphics": {}
237541            },
237542            "considerations": {}
237543          }
237544        },
237545        {
237546          "type": "library",
237547          "bom-ref": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04\u0026package-id=e5d4ae16ac79b901",
237548          "supplier": {},
237549          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237550          "name": "libselinux1",
237551          "version": "3.0-1build2",
237552          "licenses": [
237553            {
237554              "license": {
237555                "id": "GPL-2.0-only"
237556              }
237557            },
237558            {
237559              "license": {
237560                "id": "LGPL-2.1-only"
237561              }
237562            }
237563          ],
237564          "cpe": "cpe:2.3:a:libselinux1:libselinux1:3.0-1build2:*:*:*:*:*:*:*",
237565          "purl": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04",
237566          "swid": {
237567            "attachment": {}
237568          },
237569          "pedigree": {},
237570          "evidence": {},
237571          "signature": {
237572            "signature": {
237573              "publicKey": {}
237574            }
237575          },
237576          "modelCard": {
237577            "modelParameters": {
237578              "approach": {}
237579            },
237580            "quantitativeAnalysis": {
237581              "graphics": {}
237582            },
237583            "considerations": {}
237584          }
237585        },
237586        {
237587          "type": "library",
237588          "bom-ref": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=4c6cd9f68ce53262",
237589          "supplier": {},
237590          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237591          "name": "libsemanage-common",
237592          "version": "3.0-1build2",
237593          "licenses": [
237594            {
237595              "license": {
237596                "name": "GPL"
237597              }
237598            },
237599            {
237600              "license": {
237601                "name": "LGPL"
237602              }
237603            }
237604          ],
237605          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:3.0-1build2:*:*:*:*:*:*:*",
237606          "purl": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
237607          "swid": {
237608            "attachment": {}
237609          },
237610          "pedigree": {},
237611          "evidence": {},
237612          "signature": {
237613            "signature": {
237614              "publicKey": {}
237615            }
237616          },
237617          "modelCard": {
237618            "modelParameters": {
237619              "approach": {}
237620            },
237621            "quantitativeAnalysis": {
237622              "graphics": {}
237623            },
237624            "considerations": {}
237625          }
237626        },
237627        {
237628          "type": "library",
237629          "bom-ref": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=963297f19b339026",
237630          "supplier": {},
237631          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237632          "name": "libsemanage1",
237633          "version": "3.0-1build2",
237634          "licenses": [
237635            {
237636              "license": {
237637                "name": "GPL"
237638              }
237639            },
237640            {
237641              "license": {
237642                "name": "LGPL"
237643              }
237644            }
237645          ],
237646          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:3.0-1build2:*:*:*:*:*:*:*",
237647          "purl": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
237648          "swid": {
237649            "attachment": {}
237650          },
237651          "pedigree": {},
237652          "evidence": {},
237653          "signature": {
237654            "signature": {
237655              "publicKey": {}
237656            }
237657          },
237658          "modelCard": {
237659            "modelParameters": {
237660              "approach": {}
237661            },
237662            "quantitativeAnalysis": {
237663              "graphics": {}
237664            },
237665            "considerations": {}
237666          }
237667        },
237668        {
237669          "type": "library",
237670          "bom-ref": "pkg:deb/ubuntu/libsepol1@3.0-1ubuntu0.1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04\u0026package-id=7c862941a3db7eb2",
237671          "supplier": {},
237672          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237673          "name": "libsepol1",
237674          "version": "3.0-1ubuntu0.1",
237675          "licenses": [
237676            {
237677              "license": {
237678                "name": "GPL"
237679              }
237680            },
237681            {
237682              "license": {
237683                "name": "LGPL"
237684              }
237685            }
237686          ],
237687          "cpe": "cpe:2.3:a:libsepol1:libsepol1:3.0-1ubuntu0.1:*:*:*:*:*:*:*",
237688          "purl": "pkg:deb/ubuntu/libsepol1@3.0-1ubuntu0.1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04",
237689          "swid": {
237690            "attachment": {}
237691          },
237692          "pedigree": {},
237693          "evidence": {},
237694          "signature": {
237695            "signature": {
237696              "publicKey": {}
237697            }
237698          },
237699          "modelCard": {
237700            "modelParameters": {
237701              "approach": {}
237702            },
237703            "quantitativeAnalysis": {
237704              "graphics": {}
237705            },
237706            "considerations": {}
237707          }
237708        },
237709        {
237710          "type": "library",
237711          "bom-ref": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=4c497aae80a33ecf",
237712          "supplier": {},
237713          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237714          "name": "libsmartcols1",
237715          "version": "2.34-0.1ubuntu9.3",
237716          "licenses": [
237717            {
237718              "license": {
237719                "id": "BSD-2-Clause"
237720              }
237721            },
237722            {
237723              "license": {
237724                "id": "BSD-3-Clause"
237725              }
237726            },
237727            {
237728              "license": {
237729                "id": "BSD-4-Clause"
237730              }
237731            },
237732            {
237733              "license": {
237734                "id": "GPL-2.0-only"
237735              }
237736            },
237737            {
237738              "license": {
237739                "id": "GPL-2.0-or-later"
237740              }
237741            },
237742            {
237743              "license": {
237744                "id": "GPL-3.0-only"
237745              }
237746            },
237747            {
237748              "license": {
237749                "id": "GPL-3.0-or-later"
237750              }
237751            },
237752            {
237753              "license": {
237754                "name": "LGPL"
237755              }
237756            },
237757            {
237758              "license": {
237759                "id": "LGPL-2.0-only"
237760              }
237761            },
237762            {
237763              "license": {
237764                "id": "LGPL-2.0-or-later"
237765              }
237766            },
237767            {
237768              "license": {
237769                "id": "LGPL-2.1-only"
237770              }
237771            },
237772            {
237773              "license": {
237774                "id": "LGPL-2.1-or-later"
237775              }
237776            },
237777            {
237778              "license": {
237779                "id": "LGPL-3.0-only"
237780              }
237781            },
237782            {
237783              "license": {
237784                "id": "LGPL-3.0-or-later"
237785              }
237786            },
237787            {
237788              "license": {
237789                "id": "MIT"
237790              }
237791            },
237792            {
237793              "license": {
237794                "name": "public-domain"
237795              }
237796            }
237797          ],
237798          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.34-0.1ubuntu9.3:*:*:*:*:*:*:*",
237799          "purl": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
237800          "swid": {
237801            "attachment": {}
237802          },
237803          "pedigree": {},
237804          "evidence": {},
237805          "signature": {
237806            "signature": {
237807              "publicKey": {}
237808            }
237809          },
237810          "modelCard": {
237811            "modelParameters": {
237812              "approach": {}
237813            },
237814            "quantitativeAnalysis": {
237815              "graphics": {}
237816            },
237817            "considerations": {}
237818          }
237819        },
237820        {
237821          "type": "library",
237822          "bom-ref": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4715894cb8165c",
237823          "supplier": {},
237824          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237825          "name": "libss2",
237826          "version": "1.45.5-2ubuntu1",
237827          "cpe": "cpe:2.3:a:libss2:libss2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
237828          "purl": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
237829          "swid": {
237830            "attachment": {}
237831          },
237832          "pedigree": {},
237833          "evidence": {},
237834          "signature": {
237835            "signature": {
237836              "publicKey": {}
237837            }
237838          },
237839          "modelCard": {
237840            "modelParameters": {
237841              "approach": {}
237842            },
237843            "quantitativeAnalysis": {
237844              "graphics": {}
237845            },
237846            "considerations": {}
237847          }
237848        },
237849        {
237850          "type": "library",
237851          "bom-ref": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=241fcb3d9b65153a",
237852          "supplier": {},
237853          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237854          "name": "libstdc++6",
237855          "version": "10.3.0-1ubuntu1~20.04",
237856          "licenses": [
237857            {
237858              "license": {
237859                "name": "Artistic"
237860              }
237861            },
237862            {
237863              "license": {
237864                "id": "GFDL-1.2-only"
237865              }
237866            },
237867            {
237868              "license": {
237869                "name": "GPL"
237870              }
237871            },
237872            {
237873              "license": {
237874                "id": "GPL-2.0-only"
237875              }
237876            },
237877            {
237878              "license": {
237879                "id": "GPL-3.0-only"
237880              }
237881            },
237882            {
237883              "license": {
237884                "name": "LGPL"
237885              }
237886            }
237887          ],
237888          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
237889          "purl": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
237890          "swid": {
237891            "attachment": {}
237892          },
237893          "pedigree": {},
237894          "evidence": {},
237895          "signature": {
237896            "signature": {
237897              "publicKey": {}
237898            }
237899          },
237900          "modelCard": {
237901            "modelParameters": {
237902              "approach": {}
237903            },
237904            "quantitativeAnalysis": {
237905              "graphics": {}
237906            },
237907            "considerations": {}
237908          }
237909        },
237910        {
237911          "type": "library",
237912          "bom-ref": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.17?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=3d3e78a58ecc55ae",
237913          "supplier": {},
237914          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237915          "name": "libsystemd0",
237916          "version": "245.4-4ubuntu3.17",
237917          "licenses": [
237918            {
237919              "license": {
237920                "id": "CC0-1.0"
237921              }
237922            },
237923            {
237924              "license": {
237925                "name": "Expat"
237926              }
237927            },
237928            {
237929              "license": {
237930                "id": "GPL-2.0-only"
237931              }
237932            },
237933            {
237934              "license": {
237935                "id": "GPL-2.0-or-later"
237936              }
237937            },
237938            {
237939              "license": {
237940                "id": "LGPL-2.1-only"
237941              }
237942            },
237943            {
237944              "license": {
237945                "id": "LGPL-2.1-or-later"
237946              }
237947            },
237948            {
237949              "license": {
237950                "name": "public-domain"
237951              }
237952            }
237953          ],
237954          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:245.4-4ubuntu3.17:*:*:*:*:*:*:*",
237955          "purl": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.17?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
237956          "swid": {
237957            "attachment": {}
237958          },
237959          "pedigree": {},
237960          "evidence": {},
237961          "signature": {
237962            "signature": {
237963              "publicKey": {}
237964            }
237965          },
237966          "modelCard": {
237967            "modelParameters": {
237968              "approach": {}
237969            },
237970            "quantitativeAnalysis": {
237971              "graphics": {}
237972            },
237973            "considerations": {}
237974          }
237975        },
237976        {
237977          "type": "library",
237978          "bom-ref": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a290c35fc0220ba0",
237979          "supplier": {},
237980          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
237981          "name": "libtasn1-6",
237982          "version": "4.16.0-2",
237983          "licenses": [
237984            {
237985              "license": {
237986                "id": "GFDL-1.3-only"
237987              }
237988            },
237989            {
237990              "license": {
237991                "id": "GPL-3.0-only"
237992              }
237993            },
237994            {
237995              "license": {
237996                "name": "LGPL"
237997              }
237998            },
237999            {
238000              "license": {
238001                "id": "LGPL-2.1-only"
238002              }
238003            }
238004          ],
238005          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2:*:*:*:*:*:*:*",
238006          "purl": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04",
238007          "swid": {
238008            "attachment": {}
238009          },
238010          "pedigree": {},
238011          "evidence": {},
238012          "signature": {
238013            "signature": {
238014              "publicKey": {}
238015            }
238016          },
238017          "modelCard": {
238018            "modelParameters": {
238019              "approach": {}
238020            },
238021            "quantitativeAnalysis": {
238022              "graphics": {}
238023            },
238024            "considerations": {}
238025          }
238026        },
238027        {
238028          "type": "library",
238029          "bom-ref": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=72ad56d118fefea3",
238030          "supplier": {},
238031          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238032          "name": "libtinfo6",
238033          "version": "6.2-0ubuntu2",
238034          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.2-0ubuntu2:*:*:*:*:*:*:*",
238035          "purl": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
238036          "swid": {
238037            "attachment": {}
238038          },
238039          "pedigree": {},
238040          "evidence": {},
238041          "signature": {
238042            "signature": {
238043              "publicKey": {}
238044            }
238045          },
238046          "modelCard": {
238047            "modelParameters": {
238048              "approach": {}
238049            },
238050            "quantitativeAnalysis": {
238051              "graphics": {}
238052            },
238053            "considerations": {}
238054          }
238055        },
238056        {
238057          "type": "library",
238058          "bom-ref": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.17?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=f583490c60e22ba9",
238059          "supplier": {},
238060          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238061          "name": "libudev1",
238062          "version": "245.4-4ubuntu3.17",
238063          "licenses": [
238064            {
238065              "license": {
238066                "id": "CC0-1.0"
238067              }
238068            },
238069            {
238070              "license": {
238071                "name": "Expat"
238072              }
238073            },
238074            {
238075              "license": {
238076                "id": "GPL-2.0-only"
238077              }
238078            },
238079            {
238080              "license": {
238081                "id": "GPL-2.0-or-later"
238082              }
238083            },
238084            {
238085              "license": {
238086                "id": "LGPL-2.1-only"
238087              }
238088            },
238089            {
238090              "license": {
238091                "id": "LGPL-2.1-or-later"
238092              }
238093            },
238094            {
238095              "license": {
238096                "name": "public-domain"
238097              }
238098            }
238099          ],
238100          "cpe": "cpe:2.3:a:libudev1:libudev1:245.4-4ubuntu3.17:*:*:*:*:*:*:*",
238101          "purl": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.17?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
238102          "swid": {
238103            "attachment": {}
238104          },
238105          "pedigree": {},
238106          "evidence": {},
238107          "signature": {
238108            "signature": {
238109              "publicKey": {}
238110            }
238111          },
238112          "modelCard": {
238113            "modelParameters": {
238114              "approach": {}
238115            },
238116            "quantitativeAnalysis": {
238117              "graphics": {}
238118            },
238119            "considerations": {}
238120          }
238121        },
238122        {
238123          "type": "library",
238124          "bom-ref": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04\u0026package-id=3140ffa70dcd9831",
238125          "supplier": {},
238126          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238127          "name": "libunistring2",
238128          "version": "0.9.10-2",
238129          "licenses": [
238130            {
238131              "license": {
238132                "name": "FreeSoftware"
238133              }
238134            },
238135            {
238136              "license": {
238137                "id": "GFDL-1.2-only"
238138              }
238139            },
238140            {
238141              "license": {
238142                "name": "GFDL-1.2+"
238143              }
238144            },
238145            {
238146              "license": {
238147                "id": "GPL-2.0-only"
238148              }
238149            },
238150            {
238151              "license": {
238152                "id": "GPL-2.0-or-later"
238153              }
238154            },
238155            {
238156              "license": {
238157                "id": "GPL-3.0-only"
238158              }
238159            },
238160            {
238161              "license": {
238162                "id": "GPL-3.0-or-later"
238163              }
238164            },
238165            {
238166              "license": {
238167                "id": "LGPL-3.0-only"
238168              }
238169            },
238170            {
238171              "license": {
238172                "id": "LGPL-3.0-or-later"
238173              }
238174            },
238175            {
238176              "license": {
238177                "id": "MIT"
238178              }
238179            }
238180          ],
238181          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-2:*:*:*:*:*:*:*",
238182          "purl": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04",
238183          "swid": {
238184            "attachment": {}
238185          },
238186          "pedigree": {},
238187          "evidence": {},
238188          "signature": {
238189            "signature": {
238190              "publicKey": {}
238191            }
238192          },
238193          "modelCard": {
238194            "modelParameters": {
238195              "approach": {}
238196            },
238197            "quantitativeAnalysis": {
238198              "graphics": {}
238199            },
238200            "considerations": {}
238201          }
238202        },
238203        {
238204          "type": "library",
238205          "bom-ref": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=309202d9f4bbb363",
238206          "supplier": {},
238207          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238208          "name": "libuuid1",
238209          "version": "2.34-0.1ubuntu9.3",
238210          "licenses": [
238211            {
238212              "license": {
238213                "id": "BSD-2-Clause"
238214              }
238215            },
238216            {
238217              "license": {
238218                "id": "BSD-3-Clause"
238219              }
238220            },
238221            {
238222              "license": {
238223                "id": "BSD-4-Clause"
238224              }
238225            },
238226            {
238227              "license": {
238228                "id": "GPL-2.0-only"
238229              }
238230            },
238231            {
238232              "license": {
238233                "id": "GPL-2.0-or-later"
238234              }
238235            },
238236            {
238237              "license": {
238238                "id": "GPL-3.0-only"
238239              }
238240            },
238241            {
238242              "license": {
238243                "id": "GPL-3.0-or-later"
238244              }
238245            },
238246            {
238247              "license": {
238248                "name": "LGPL"
238249              }
238250            },
238251            {
238252              "license": {
238253                "id": "LGPL-2.0-only"
238254              }
238255            },
238256            {
238257              "license": {
238258                "id": "LGPL-2.0-or-later"
238259              }
238260            },
238261            {
238262              "license": {
238263                "id": "LGPL-2.1-only"
238264              }
238265            },
238266            {
238267              "license": {
238268                "id": "LGPL-2.1-or-later"
238269              }
238270            },
238271            {
238272              "license": {
238273                "id": "LGPL-3.0-only"
238274              }
238275            },
238276            {
238277              "license": {
238278                "id": "LGPL-3.0-or-later"
238279              }
238280            },
238281            {
238282              "license": {
238283                "id": "MIT"
238284              }
238285            },
238286            {
238287              "license": {
238288                "name": "public-domain"
238289              }
238290            }
238291          ],
238292          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.34-0.1ubuntu9.3:*:*:*:*:*:*:*",
238293          "purl": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
238294          "swid": {
238295            "attachment": {}
238296          },
238297          "pedigree": {},
238298          "evidence": {},
238299          "signature": {
238300            "signature": {
238301              "publicKey": {}
238302            }
238303          },
238304          "modelCard": {
238305            "modelParameters": {
238306              "approach": {}
238307            },
238308            "quantitativeAnalysis": {
238309              "graphics": {}
238310            },
238311            "considerations": {}
238312          }
238313        },
238314        {
238315          "type": "library",
238316          "bom-ref": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04\u0026package-id=47cff0564e160066",
238317          "supplier": {},
238318          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238319          "name": "libzstd1",
238320          "version": "1.4.4+dfsg-3ubuntu0.1",
238321          "licenses": [
238322            {
238323              "license": {
238324                "id": "BSD-3-Clause"
238325              }
238326            },
238327            {
238328              "license": {
238329                "name": "Expat"
238330              }
238331            },
238332            {
238333              "license": {
238334                "id": "GPL-2.0-only"
238335              }
238336            },
238337            {
238338              "license": {
238339                "id": "GPL-2.0-or-later"
238340              }
238341            },
238342            {
238343              "license": {
238344                "id": "Zlib"
238345              }
238346            }
238347          ],
238348          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.4\\+dfsg-3ubuntu0.1:*:*:*:*:*:*:*",
238349          "purl": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04",
238350          "swid": {
238351            "attachment": {}
238352          },
238353          "pedigree": {},
238354          "evidence": {},
238355          "signature": {
238356            "signature": {
238357              "publicKey": {}
238358            }
238359          },
238360          "modelCard": {
238361            "modelParameters": {
238362              "approach": {}
238363            },
238364            "quantitativeAnalysis": {
238365              "graphics": {}
238366            },
238367            "considerations": {}
238368          }
238369        },
238370        {
238371          "type": "library",
238372          "bom-ref": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.2?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=6e31c2fd9fc25f2e",
238373          "supplier": {},
238374          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238375          "name": "login",
238376          "version": "1:4.8.1-1ubuntu5.20.04.2",
238377          "licenses": [
238378            {
238379              "license": {
238380                "id": "GPL-2.0-only"
238381              }
238382            }
238383          ],
238384          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1ubuntu5.20.04.2:*:*:*:*:*:*:*",
238385          "purl": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.2?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
238386          "swid": {
238387            "attachment": {}
238388          },
238389          "pedigree": {},
238390          "evidence": {},
238391          "signature": {
238392            "signature": {
238393              "publicKey": {}
238394            }
238395          },
238396          "modelCard": {
238397            "modelParameters": {
238398              "approach": {}
238399            },
238400            "quantitativeAnalysis": {
238401              "graphics": {}
238402            },
238403            "considerations": {}
238404          }
238405        },
238406        {
238407          "type": "library",
238408          "bom-ref": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4a92556bee4b4f91",
238409          "supplier": {},
238410          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238411          "name": "logsave",
238412          "version": "1.45.5-2ubuntu1",
238413          "licenses": [
238414            {
238415              "license": {
238416                "id": "GPL-2.0-only"
238417              }
238418            },
238419            {
238420              "license": {
238421                "id": "LGPL-2.0-only"
238422              }
238423            }
238424          ],
238425          "cpe": "cpe:2.3:a:logsave:logsave:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
238426          "purl": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
238427          "swid": {
238428            "attachment": {}
238429          },
238430          "pedigree": {},
238431          "evidence": {},
238432          "signature": {
238433            "signature": {
238434              "publicKey": {}
238435            }
238436          },
238437          "modelCard": {
238438            "modelParameters": {
238439              "approach": {}
238440            },
238441            "quantitativeAnalysis": {
238442              "graphics": {}
238443            },
238444            "considerations": {}
238445          }
238446        },
238447        {
238448          "type": "library",
238449          "bom-ref": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04\u0026package-id=b76348b7f1282c61",
238450          "supplier": {},
238451          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238452          "name": "lsb-base",
238453          "version": "11.1.0ubuntu2",
238454          "licenses": [
238455            {
238456              "license": {
238457                "id": "BSD-3-Clause"
238458              }
238459            },
238460            {
238461              "license": {
238462                "id": "GPL-2.0-only"
238463              }
238464            }
238465          ],
238466          "cpe": "cpe:2.3:a:lsb-base:lsb-base:11.1.0ubuntu2:*:*:*:*:*:*:*",
238467          "purl": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04",
238468          "swid": {
238469            "attachment": {}
238470          },
238471          "pedigree": {},
238472          "evidence": {},
238473          "signature": {
238474            "signature": {
238475              "publicKey": {}
238476            }
238477          },
238478          "modelCard": {
238479            "modelParameters": {
238480              "approach": {}
238481            },
238482            "quantitativeAnalysis": {
238483              "graphics": {}
238484            },
238485            "considerations": {}
238486          }
238487        },
238488        {
238489          "type": "library",
238490          "bom-ref": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=435885c82afbf721",
238491          "supplier": {},
238492          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238493          "name": "mawk",
238494          "version": "1.3.4.20200120-2",
238495          "licenses": [
238496            {
238497              "license": {
238498                "id": "GPL-2.0-only"
238499              }
238500            }
238501          ],
238502          "cpe": "cpe:2.3:a:mawk:mawk:1.3.4.20200120-2:*:*:*:*:*:*:*",
238503          "purl": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04",
238504          "swid": {
238505            "attachment": {}
238506          },
238507          "pedigree": {},
238508          "evidence": {},
238509          "signature": {
238510            "signature": {
238511              "publicKey": {}
238512            }
238513          },
238514          "modelCard": {
238515            "modelParameters": {
238516              "approach": {}
238517            },
238518            "quantitativeAnalysis": {
238519              "graphics": {}
238520            },
238521            "considerations": {}
238522          }
238523        },
238524        {
238525          "type": "library",
238526          "bom-ref": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=20e03a37af64e56c",
238527          "supplier": {},
238528          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238529          "name": "mount",
238530          "version": "2.34-0.1ubuntu9.3",
238531          "licenses": [
238532            {
238533              "license": {
238534                "id": "BSD-2-Clause"
238535              }
238536            },
238537            {
238538              "license": {
238539                "id": "BSD-3-Clause"
238540              }
238541            },
238542            {
238543              "license": {
238544                "id": "BSD-4-Clause"
238545              }
238546            },
238547            {
238548              "license": {
238549                "id": "GPL-2.0-only"
238550              }
238551            },
238552            {
238553              "license": {
238554                "id": "GPL-2.0-or-later"
238555              }
238556            },
238557            {
238558              "license": {
238559                "id": "GPL-3.0-only"
238560              }
238561            },
238562            {
238563              "license": {
238564                "id": "GPL-3.0-or-later"
238565              }
238566            },
238567            {
238568              "license": {
238569                "name": "LGPL"
238570              }
238571            },
238572            {
238573              "license": {
238574                "id": "LGPL-2.0-only"
238575              }
238576            },
238577            {
238578              "license": {
238579                "id": "LGPL-2.0-or-later"
238580              }
238581            },
238582            {
238583              "license": {
238584                "id": "LGPL-2.1-only"
238585              }
238586            },
238587            {
238588              "license": {
238589                "id": "LGPL-2.1-or-later"
238590              }
238591            },
238592            {
238593              "license": {
238594                "id": "LGPL-3.0-only"
238595              }
238596            },
238597            {
238598              "license": {
238599                "id": "LGPL-3.0-or-later"
238600              }
238601            },
238602            {
238603              "license": {
238604                "id": "MIT"
238605              }
238606            },
238607            {
238608              "license": {
238609                "name": "public-domain"
238610              }
238611            }
238612          ],
238613          "cpe": "cpe:2.3:a:mount:mount:2.34-0.1ubuntu9.3:*:*:*:*:*:*:*",
238614          "purl": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.3?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
238615          "swid": {
238616            "attachment": {}
238617          },
238618          "pedigree": {},
238619          "evidence": {},
238620          "signature": {
238621            "signature": {
238622              "publicKey": {}
238623            }
238624          },
238625          "modelCard": {
238626            "modelParameters": {
238627              "approach": {}
238628            },
238629            "quantitativeAnalysis": {
238630              "graphics": {}
238631            },
238632            "considerations": {}
238633          }
238634        },
238635        {
238636          "type": "library",
238637          "bom-ref": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d7393defd95e4554",
238638          "supplier": {},
238639          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238640          "name": "ncurses-base",
238641          "version": "6.2-0ubuntu2",
238642          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.2-0ubuntu2:*:*:*:*:*:*:*",
238643          "purl": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
238644          "swid": {
238645            "attachment": {}
238646          },
238647          "pedigree": {},
238648          "evidence": {},
238649          "signature": {
238650            "signature": {
238651              "publicKey": {}
238652            }
238653          },
238654          "modelCard": {
238655            "modelParameters": {
238656              "approach": {}
238657            },
238658            "quantitativeAnalysis": {
238659              "graphics": {}
238660            },
238661            "considerations": {}
238662          }
238663        },
238664        {
238665          "type": "library",
238666          "bom-ref": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d6bdd43961b680f6",
238667          "supplier": {},
238668          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238669          "name": "ncurses-bin",
238670          "version": "6.2-0ubuntu2",
238671          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.2-0ubuntu2:*:*:*:*:*:*:*",
238672          "purl": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
238673          "swid": {
238674            "attachment": {}
238675          },
238676          "pedigree": {},
238677          "evidence": {},
238678          "signature": {
238679            "signature": {
238680              "publicKey": {}
238681            }
238682          },
238683          "modelCard": {
238684            "modelParameters": {
238685              "approach": {}
238686            },
238687            "quantitativeAnalysis": {
238688              "graphics": {}
238689            },
238690            "considerations": {}
238691          }
238692        },
238693        {
238694          "type": "library",
238695          "bom-ref": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.2?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=858f573489f83f86",
238696          "supplier": {},
238697          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238698          "name": "passwd",
238699          "version": "1:4.8.1-1ubuntu5.20.04.2",
238700          "licenses": [
238701            {
238702              "license": {
238703                "id": "GPL-2.0-only"
238704              }
238705            }
238706          ],
238707          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1ubuntu5.20.04.2:*:*:*:*:*:*:*",
238708          "purl": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.2?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
238709          "swid": {
238710            "attachment": {}
238711          },
238712          "pedigree": {},
238713          "evidence": {},
238714          "signature": {
238715            "signature": {
238716              "publicKey": {}
238717            }
238718          },
238719          "modelCard": {
238720            "modelParameters": {
238721              "approach": {}
238722            },
238723            "quantitativeAnalysis": {
238724              "graphics": {}
238725            },
238726            "considerations": {}
238727          }
238728        },
238729        {
238730          "type": "library",
238731          "bom-ref": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=eab1752e76cf29f",
238732          "supplier": {},
238733          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238734          "name": "perl-base",
238735          "version": "5.30.0-9ubuntu0.2",
238736          "licenses": [
238737            {
238738              "license": {
238739                "name": "Artistic"
238740              }
238741            },
238742            {
238743              "license": {
238744                "id": "Artistic-2.0"
238745              }
238746            },
238747            {
238748              "license": {
238749                "name": "Artistic-dist"
238750              }
238751            },
238752            {
238753              "license": {
238754                "id": "BSD-3-Clause"
238755              }
238756            },
238757            {
238758              "license": {
238759                "name": "BSD-3-clause-GENERIC"
238760              }
238761            },
238762            {
238763              "license": {
238764                "name": "BSD-3-clause-with-weird-numbering"
238765              }
238766            },
238767            {
238768              "license": {
238769                "name": "BSD-4-clause-POWERDOG"
238770              }
238771            },
238772            {
238773              "license": {
238774                "name": "BZIP"
238775              }
238776            },
238777            {
238778              "license": {
238779                "name": "DONT-CHANGE-THE-GPL"
238780              }
238781            },
238782            {
238783              "license": {
238784                "name": "Expat"
238785              }
238786            },
238787            {
238788              "license": {
238789                "id": "GPL-1.0-only"
238790              }
238791            },
238792            {
238793              "license": {
238794                "id": "GPL-1.0-or-later"
238795              }
238796            },
238797            {
238798              "license": {
238799                "id": "GPL-2.0-only"
238800              }
238801            },
238802            {
238803              "license": {
238804                "id": "GPL-2.0-or-later"
238805              }
238806            },
238807            {
238808              "license": {
238809                "name": "GPL-3+-WITH-BISON-EXCEPTION"
238810              }
238811            },
238812            {
238813              "license": {
238814                "name": "HSIEH-BSD"
238815              }
238816            },
238817            {
238818              "license": {
238819                "name": "HSIEH-DERIVATIVE"
238820              }
238821            },
238822            {
238823              "license": {
238824                "id": "LGPL-2.1-only"
238825              }
238826            },
238827            {
238828              "license": {
238829                "name": "REGCOMP"
238830              }
238831            },
238832            {
238833              "license": {
238834                "name": "REGCOMP,"
238835              }
238836            },
238837            {
238838              "license": {
238839                "name": "RRA-KEEP-THIS-NOTICE"
238840              }
238841            },
238842            {
238843              "license": {
238844                "name": "SDBM-PUBLIC-DOMAIN"
238845              }
238846            },
238847            {
238848              "license": {
238849                "name": "TEXT-TABS"
238850              }
238851            },
238852            {
238853              "license": {
238854                "name": "Unicode"
238855              }
238856            },
238857            {
238858              "license": {
238859                "id": "Zlib"
238860              }
238861            }
238862          ],
238863          "cpe": "cpe:2.3:a:perl-base:perl-base:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
238864          "purl": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04",
238865          "swid": {
238866            "attachment": {}
238867          },
238868          "pedigree": {},
238869          "evidence": {},
238870          "signature": {
238871            "signature": {
238872              "publicKey": {}
238873            }
238874          },
238875          "modelCard": {
238876            "modelParameters": {
238877              "approach": {}
238878            },
238879            "quantitativeAnalysis": {
238880              "graphics": {}
238881            },
238882            "considerations": {}
238883          }
238884        },
238885        {
238886          "type": "library",
238887          "bom-ref": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=1b952d75ffac7280",
238888          "supplier": {},
238889          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238890          "name": "procps",
238891          "version": "2:3.3.16-1ubuntu2.3",
238892          "licenses": [
238893            {
238894              "license": {
238895                "id": "GPL-2.0-only"
238896              }
238897            },
238898            {
238899              "license": {
238900                "id": "GPL-2.0-or-later"
238901              }
238902            },
238903            {
238904              "license": {
238905                "id": "LGPL-2.0-only"
238906              }
238907            },
238908            {
238909              "license": {
238910                "id": "LGPL-2.0-or-later"
238911              }
238912            },
238913            {
238914              "license": {
238915                "id": "LGPL-2.1-only"
238916              }
238917            },
238918            {
238919              "license": {
238920                "id": "LGPL-2.1-or-later"
238921              }
238922            }
238923          ],
238924          "cpe": "cpe:2.3:a:procps:procps:2\\:3.3.16-1ubuntu2.3:*:*:*:*:*:*:*",
238925          "purl": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.3?arch=amd64\u0026distro=ubuntu-20.04",
238926          "swid": {
238927            "attachment": {}
238928          },
238929          "pedigree": {},
238930          "evidence": {},
238931          "signature": {
238932            "signature": {
238933              "publicKey": {}
238934            }
238935          },
238936          "modelCard": {
238937            "modelParameters": {
238938              "approach": {}
238939            },
238940            "quantitativeAnalysis": {
238941              "graphics": {}
238942            },
238943            "considerations": {}
238944          }
238945        },
238946        {
238947          "type": "library",
238948          "bom-ref": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=24bbb8989a1870c7",
238949          "supplier": {},
238950          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238951          "name": "sed",
238952          "version": "4.7-1",
238953          "licenses": [
238954            {
238955              "license": {
238956                "id": "GPL-3.0-only"
238957              }
238958            }
238959          ],
238960          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
238961          "purl": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04",
238962          "swid": {
238963            "attachment": {}
238964          },
238965          "pedigree": {},
238966          "evidence": {},
238967          "signature": {
238968            "signature": {
238969              "publicKey": {}
238970            }
238971          },
238972          "modelCard": {
238973            "modelParameters": {
238974              "approach": {}
238975            },
238976            "quantitativeAnalysis": {
238977              "graphics": {}
238978            },
238979            "considerations": {}
238980          }
238981        },
238982        {
238983          "type": "library",
238984          "bom-ref": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=7e50cf6ac335106e",
238985          "supplier": {},
238986          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
238987          "name": "sensible-utils",
238988          "version": "0.0.12+nmu1",
238989          "licenses": [
238990            {
238991              "license": {
238992                "name": "All-permissive"
238993              }
238994            },
238995            {
238996              "license": {
238997                "id": "GPL-2.0-only"
238998              }
238999            },
239000            {
239001              "license": {
239002                "id": "GPL-2.0-or-later"
239003              }
239004            },
239005            {
239006              "license": {
239007                "name": "configure"
239008              }
239009            },
239010            {
239011              "license": {
239012                "name": "installsh"
239013              }
239014            }
239015          ],
239016          "cpe": "cpe:2.3:a:sensible-utils:sensible-utils:0.0.12\\+nmu1:*:*:*:*:*:*:*",
239017          "purl": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04",
239018          "swid": {
239019            "attachment": {}
239020          },
239021          "pedigree": {},
239022          "evidence": {},
239023          "signature": {
239024            "signature": {
239025              "publicKey": {}
239026            }
239027          },
239028          "modelCard": {
239029            "modelParameters": {
239030              "approach": {}
239031            },
239032            "quantitativeAnalysis": {
239033              "graphics": {}
239034            },
239035            "considerations": {}
239036          }
239037        },
239038        {
239039          "type": "library",
239040          "bom-ref": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04\u0026package-id=abc451774789c392",
239041          "supplier": {},
239042          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
239043          "name": "sysvinit-utils",
239044          "version": "2.96-2.1ubuntu1",
239045          "licenses": [
239046            {
239047              "license": {
239048                "id": "GPL-2.0-only"
239049              }
239050            },
239051            {
239052              "license": {
239053                "id": "GPL-2.0-or-later"
239054              }
239055            }
239056          ],
239057          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.96-2.1ubuntu1:*:*:*:*:*:*:*",
239058          "purl": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04",
239059          "swid": {
239060            "attachment": {}
239061          },
239062          "pedigree": {},
239063          "evidence": {},
239064          "signature": {
239065            "signature": {
239066              "publicKey": {}
239067            }
239068          },
239069          "modelCard": {
239070            "modelParameters": {
239071              "approach": {}
239072            },
239073            "quantitativeAnalysis": {
239074              "graphics": {}
239075            },
239076            "considerations": {}
239077          }
239078        },
239079        {
239080          "type": "library",
239081          "bom-ref": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a57014f4a463478d",
239082          "supplier": {},
239083          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
239084          "name": "tar",
239085          "version": "1.30+dfsg-7ubuntu0.20.04.2",
239086          "licenses": [
239087            {
239088              "license": {
239089                "id": "GPL-2.0-only"
239090              }
239091            },
239092            {
239093              "license": {
239094                "id": "GPL-3.0-only"
239095              }
239096            }
239097          ],
239098          "cpe": "cpe:2.3:a:tar:tar:1.30\\+dfsg-7ubuntu0.20.04.2:*:*:*:*:*:*:*",
239099          "purl": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.2?arch=amd64\u0026distro=ubuntu-20.04",
239100          "swid": {
239101            "attachment": {}
239102          },
239103          "pedigree": {},
239104          "evidence": {},
239105          "signature": {
239106            "signature": {
239107              "publicKey": {}
239108            }
239109          },
239110          "modelCard": {
239111            "modelParameters": {
239112              "approach": {}
239113            },
239114            "quantitativeAnalysis": {
239115              "graphics": {}
239116            },
239117            "considerations": {}
239118          }
239119        },
239120        {
239121          "type": "library",
239122          "bom-ref": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04\u0026package-id=6d2b18ebcbe1dab7",
239123          "supplier": {},
239124          "publisher": "Dimitri John Ledkov \u003cdimitri.ledkov@canonical.com\u003e",
239125          "name": "ubuntu-keyring",
239126          "version": "2020.02.11.4",
239127          "licenses": [
239128            {
239129              "license": {
239130                "name": "GPL"
239131              }
239132            }
239133          ],
239134          "cpe": "cpe:2.3:a:ubuntu-keyring:ubuntu-keyring:2020.02.11.4:*:*:*:*:*:*:*",
239135          "purl": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04",
239136          "swid": {
239137            "attachment": {}
239138          },
239139          "pedigree": {},
239140          "evidence": {},
239141          "signature": {
239142            "signature": {
239143              "publicKey": {}
239144            }
239145          },
239146          "modelCard": {
239147            "modelParameters": {
239148              "approach": {}
239149            },
239150            "quantitativeAnalysis": {
239151              "graphics": {}
239152            },
239153            "considerations": {}
239154          }
239155        },
239156        {
239157          "type": "library",
239158          "bom-ref": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=980ca6ad8f0b50ad",
239159          "supplier": {},
239160          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
239161          "name": "util-linux",
239162          "version": "2.34-0.1ubuntu9.3",
239163          "licenses": [
239164            {
239165              "license": {
239166                "id": "BSD-2-Clause"
239167              }
239168            },
239169            {
239170              "license": {
239171                "id": "BSD-3-Clause"
239172              }
239173            },
239174            {
239175              "license": {
239176                "id": "BSD-4-Clause"
239177              }
239178            },
239179            {
239180              "license": {
239181                "id": "GPL-2.0-only"
239182              }
239183            },
239184            {
239185              "license": {
239186                "id": "GPL-2.0-or-later"
239187              }
239188            },
239189            {
239190              "license": {
239191                "id": "GPL-3.0-only"
239192              }
239193            },
239194            {
239195              "license": {
239196                "id": "GPL-3.0-or-later"
239197              }
239198            },
239199            {
239200              "license": {
239201                "name": "LGPL"
239202              }
239203            },
239204            {
239205              "license": {
239206                "id": "LGPL-2.0-only"
239207              }
239208            },
239209            {
239210              "license": {
239211                "id": "LGPL-2.0-or-later"
239212              }
239213            },
239214            {
239215              "license": {
239216                "id": "LGPL-2.1-only"
239217              }
239218            },
239219            {
239220              "license": {
239221                "id": "LGPL-2.1-or-later"
239222              }
239223            },
239224            {
239225              "license": {
239226                "id": "LGPL-3.0-only"
239227              }
239228            },
239229            {
239230              "license": {
239231                "id": "LGPL-3.0-or-later"
239232              }
239233            },
239234            {
239235              "license": {
239236                "id": "MIT"
239237              }
239238            },
239239            {
239240              "license": {
239241                "name": "public-domain"
239242              }
239243            }
239244          ],
239245          "cpe": "cpe:2.3:a:util-linux:util-linux:2.34-0.1ubuntu9.3:*:*:*:*:*:*:*",
239246          "purl": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.3?arch=amd64\u0026distro=ubuntu-20.04",
239247          "swid": {
239248            "attachment": {}
239249          },
239250          "pedigree": {},
239251          "evidence": {},
239252          "signature": {
239253            "signature": {
239254              "publicKey": {}
239255            }
239256          },
239257          "modelCard": {
239258            "modelParameters": {
239259              "approach": {}
239260            },
239261            "quantitativeAnalysis": {
239262              "graphics": {}
239263            },
239264            "considerations": {}
239265          }
239266        },
239267        {
239268          "type": "library",
239269          "bom-ref": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.3?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04\u0026package-id=45609aec77ee2abd",
239270          "supplier": {},
239271          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
239272          "name": "zlib1g",
239273          "version": "1:1.2.11.dfsg-2ubuntu1.3",
239274          "licenses": [
239275            {
239276              "license": {
239277                "id": "Zlib"
239278              }
239279            }
239280          ],
239281          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2ubuntu1.3:*:*:*:*:*:*:*",
239282          "purl": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.3?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04",
239283          "swid": {
239284            "attachment": {}
239285          },
239286          "pedigree": {},
239287          "evidence": {},
239288          "signature": {
239289            "signature": {
239290              "publicKey": {}
239291            }
239292          },
239293          "modelCard": {
239294            "modelParameters": {
239295              "approach": {}
239296            },
239297            "quantitativeAnalysis": {
239298              "graphics": {}
239299            },
239300            "considerations": {}
239301          }
239302        },
239303        {
239304          "type": "operating-system",
239305          "supplier": {},
239306          "name": "ubuntu",
239307          "version": "20.04",
239308          "description": "Ubuntu 20.04.4 LTS",
239309          "swid": {
239310            "tagId": "ubuntu",
239311            "name": "ubuntu",
239312            "version": "20.04",
239313            "attachment": {}
239314          },
239315          "pedigree": {},
239316          "externalReferences": [
239317            {
239318              "url": "https://bugs.launchpad.net/ubuntu/",
239319              "type": "issue-tracker"
239320            },
239321            {
239322              "url": "https://www.ubuntu.com/",
239323              "type": "website"
239324            },
239325            {
239326              "url": "https://help.ubuntu.com/",
239327              "comment": "support",
239328              "type": "other"
239329            },
239330            {
239331              "url": "https://www.ubuntu.com/legal/terms-and-policies/privacy-policy",
239332              "comment": "privacyPolicy",
239333              "type": "other"
239334            }
239335          ],
239336          "evidence": {},
239337          "signature": {
239338            "signature": {
239339              "publicKey": {}
239340            }
239341          },
239342          "modelCard": {
239343            "modelParameters": {
239344              "approach": {}
239345            },
239346            "quantitativeAnalysis": {
239347              "graphics": {}
239348            },
239349            "considerations": {}
239350          }
239351        },
239352        {
239353          "type": "library",
239354          "bom-ref": "pkg:npm/%40nestjs/common@7.6.18?package-id=d73b1ee7c4c93551",
239355          "supplier": {},
239356          "author": "Kamil Mysliwiec",
239357          "name": "@nestjs/common",
239358          "version": "7.6.18",
239359          "description": "Nest - modern, fast, powerful node.js web framework (@common)",
239360          "licenses": [
239361            {
239362              "license": {
239363                "id": "MIT"
239364              }
239365            }
239366          ],
239367          "cpe": "cpe:2.3:a:\\@nestjs\\/common:\\@nestjs\\/common:7.6.18:*:*:*:*:*:*:*",
239368          "purl": "pkg:npm/%40nestjs/common@7.6.18",
239369          "swid": {
239370            "attachment": {}
239371          },
239372          "pedigree": {},
239373          "externalReferences": [
239374            {
239375              "url": "https://github.com/nestjs/nest",
239376              "type": "distribution"
239377            },
239378            {
239379              "url": "https://nestjs.com",
239380              "type": "website"
239381            }
239382          ],
239383          "evidence": {},
239384          "signature": {
239385            "signature": {
239386              "publicKey": {}
239387            }
239388          },
239389          "modelCard": {
239390            "modelParameters": {
239391              "approach": {}
239392            },
239393            "quantitativeAnalysis": {
239394              "graphics": {}
239395            },
239396            "considerations": {}
239397          }
239398        },
239399        {
239400          "type": "library",
239401          "bom-ref": "pkg:npm/%40nestjs/core@7.6.18?package-id=8a5e3048e90617fc",
239402          "supplier": {},
239403          "author": "Kamil Mysliwiec",
239404          "name": "@nestjs/core",
239405          "version": "7.6.18",
239406          "description": "Nest - modern, fast, powerful node.js web framework (@core)",
239407          "licenses": [
239408            {
239409              "license": {
239410                "id": "MIT"
239411              }
239412            }
239413          ],
239414          "cpe": "cpe:2.3:a:\\@nestjs\\/core:\\@nestjs\\/core:7.6.18:*:*:*:*:*:*:*",
239415          "purl": "pkg:npm/%40nestjs/core@7.6.18",
239416          "swid": {
239417            "attachment": {}
239418          },
239419          "pedigree": {},
239420          "externalReferences": [
239421            {
239422              "url": "https://github.com/nestjs/nest",
239423              "type": "distribution"
239424            },
239425            {
239426              "url": "https://nestjs.com",
239427              "type": "website"
239428            }
239429          ],
239430          "evidence": {},
239431          "signature": {
239432            "signature": {
239433              "publicKey": {}
239434            }
239435          },
239436          "modelCard": {
239437            "modelParameters": {
239438              "approach": {}
239439            },
239440            "quantitativeAnalysis": {
239441              "graphics": {}
239442            },
239443            "considerations": {}
239444          }
239445        },
239446        {
239447          "type": "library",
239448          "bom-ref": "pkg:npm/%40nestjs/mapped-types@0.4.1?package-id=f831d8d988bed4d4",
239449          "supplier": {},
239450          "author": "Kamil Mysliwiec",
239451          "name": "@nestjs/mapped-types",
239452          "version": "0.4.1",
239453          "description": "Nest - modern, fast, powerful node.js web framework (@mapped-types)",
239454          "licenses": [
239455            {
239456              "license": {
239457                "id": "MIT"
239458              }
239459            }
239460          ],
239461          "cpe": "cpe:2.3:a:\\@nestjs\\/mapped-types:\\@nestjs\\/mapped-types:0.4.1:*:*:*:*:*:*:*",
239462          "purl": "pkg:npm/%40nestjs/mapped-types@0.4.1",
239463          "swid": {
239464            "attachment": {}
239465          },
239466          "pedigree": {},
239467          "externalReferences": [
239468            {
239469              "url": "https://github.com/nestjs/mapped-types",
239470              "type": "distribution"
239471            }
239472          ],
239473          "evidence": {},
239474          "signature": {
239475            "signature": {
239476              "publicKey": {}
239477            }
239478          },
239479          "modelCard": {
239480            "modelParameters": {
239481              "approach": {}
239482            },
239483            "quantitativeAnalysis": {
239484              "graphics": {}
239485            },
239486            "considerations": {}
239487          }
239488        },
239489        {
239490          "type": "library",
239491          "bom-ref": "pkg:npm/%40nestjs/platform-express@7.6.18?package-id=31183ee6d4dba244",
239492          "supplier": {},
239493          "author": "Kamil Mysliwiec",
239494          "name": "@nestjs/platform-express",
239495          "version": "7.6.18",
239496          "description": "Nest - modern, fast, powerful node.js web framework (@platform-express)",
239497          "licenses": [
239498            {
239499              "license": {
239500                "id": "MIT"
239501              }
239502            }
239503          ],
239504          "cpe": "cpe:2.3:a:\\@nestjs\\/platform-express:\\@nestjs\\/platform-express:7.6.18:*:*:*:*:*:*:*",
239505          "purl": "pkg:npm/%40nestjs/platform-express@7.6.18",
239506          "swid": {
239507            "attachment": {}
239508          },
239509          "pedigree": {},
239510          "externalReferences": [
239511            {
239512              "url": "https://github.com/nestjs/nest",
239513              "type": "distribution"
239514            },
239515            {
239516              "url": "https://nestjs.com",
239517              "type": "website"
239518            }
239519          ],
239520          "evidence": {},
239521          "signature": {
239522            "signature": {
239523              "publicKey": {}
239524            }
239525          },
239526          "modelCard": {
239527            "modelParameters": {
239528              "approach": {}
239529            },
239530            "quantitativeAnalysis": {
239531              "graphics": {}
239532            },
239533            "considerations": {}
239534          }
239535        },
239536        {
239537          "type": "library",
239538          "bom-ref": "pkg:npm/%40nestjs/swagger@4.8.2?package-id=e9c35d1ea263f2c4",
239539          "supplier": {},
239540          "author": "Kamil Mysliwiec",
239541          "name": "@nestjs/swagger",
239542          "version": "4.8.2",
239543          "description": "Nest - modern, fast, powerful node.js web framework (@swagger)",
239544          "licenses": [
239545            {
239546              "license": {
239547                "id": "MIT"
239548              }
239549            }
239550          ],
239551          "cpe": "cpe:2.3:a:\\@nestjs\\/swagger:\\@nestjs\\/swagger:4.8.2:*:*:*:*:*:*:*",
239552          "purl": "pkg:npm/%40nestjs/swagger@4.8.2",
239553          "swid": {
239554            "attachment": {}
239555          },
239556          "pedigree": {},
239557          "externalReferences": [
239558            {
239559              "url": "https://github.com/nestjs/swagger",
239560              "type": "distribution"
239561            }
239562          ],
239563          "evidence": {},
239564          "signature": {
239565            "signature": {
239566              "publicKey": {}
239567            }
239568          },
239569          "modelCard": {
239570            "modelParameters": {
239571              "approach": {}
239572            },
239573            "quantitativeAnalysis": {
239574              "graphics": {}
239575            },
239576            "considerations": {}
239577          }
239578        },
239579        {
239580          "type": "library",
239581          "bom-ref": "pkg:npm/%40nuxtjs/opencollective@0.3.2?package-id=e5c4143197893d11",
239582          "supplier": {},
239583          "name": "@nuxtjs/opencollective",
239584          "version": "0.3.2",
239585          "licenses": [
239586            {
239587              "license": {
239588                "id": "MIT"
239589              }
239590            }
239591          ],
239592          "cpe": "cpe:2.3:a:\\@nuxtjs\\/opencollective:\\@nuxtjs\\/opencollective:0.3.2:*:*:*:*:*:*:*",
239593          "purl": "pkg:npm/%40nuxtjs/opencollective@0.3.2",
239594          "swid": {
239595            "attachment": {}
239596          },
239597          "pedigree": {},
239598          "externalReferences": [
239599            {
239600              "url": "nuxt-contrib/opencollective",
239601              "type": "distribution"
239602            }
239603          ],
239604          "evidence": {},
239605          "signature": {
239606            "signature": {
239607              "publicKey": {}
239608            }
239609          },
239610          "modelCard": {
239611            "modelParameters": {
239612              "approach": {}
239613            },
239614            "quantitativeAnalysis": {
239615              "graphics": {}
239616            },
239617            "considerations": {}
239618          }
239619        },
239620        {
239621          "type": "library",
239622          "bom-ref": "pkg:npm/%40types/swagger-schema-official@2.0.22?package-id=3ff0206ece91290b",
239623          "supplier": {},
239624          "name": "@types/swagger-schema-official",
239625          "version": "2.0.22",
239626          "description": "TypeScript definitions for swagger-schema-official",
239627          "licenses": [
239628            {
239629              "license": {
239630                "id": "MIT"
239631              }
239632            }
239633          ],
239634          "cpe": "cpe:2.3:a:\\@types\\/swagger-schema-official:\\@types\\/swagger-schema-official:2.0.22:*:*:*:*:*:*:*",
239635          "purl": "pkg:npm/%40types/swagger-schema-official@2.0.22",
239636          "swid": {
239637            "attachment": {}
239638          },
239639          "pedigree": {},
239640          "externalReferences": [
239641            {
239642              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
239643              "type": "distribution"
239644            },
239645            {
239646              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/swagger-schema-official",
239647              "type": "website"
239648            }
239649          ],
239650          "evidence": {},
239651          "signature": {
239652            "signature": {
239653              "publicKey": {}
239654            }
239655          },
239656          "modelCard": {
239657            "modelParameters": {
239658              "approach": {}
239659            },
239660            "quantitativeAnalysis": {
239661              "graphics": {}
239662            },
239663            "considerations": {}
239664          }
239665        },
239666        {
239667          "type": "library",
239668          "bom-ref": "pkg:npm/%40types/validator@13.0.0?package-id=200f68cb0085ca75",
239669          "supplier": {},
239670          "name": "@types/validator",
239671          "version": "13.0.0",
239672          "description": "TypeScript definitions for validator.js",
239673          "licenses": [
239674            {
239675              "license": {
239676                "id": "MIT"
239677              }
239678            }
239679          ],
239680          "cpe": "cpe:2.3:a:\\@types\\/validator:\\@types\\/validator:13.0.0:*:*:*:*:*:*:*",
239681          "purl": "pkg:npm/%40types/validator@13.0.0",
239682          "swid": {
239683            "attachment": {}
239684          },
239685          "pedigree": {},
239686          "externalReferences": [
239687            {
239688              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
239689              "type": "distribution"
239690            }
239691          ],
239692          "evidence": {},
239693          "signature": {
239694            "signature": {
239695              "publicKey": {}
239696            }
239697          },
239698          "modelCard": {
239699            "modelParameters": {
239700              "approach": {}
239701            },
239702            "quantitativeAnalysis": {
239703              "graphics": {}
239704            },
239705            "considerations": {}
239706          }
239707        },
239708        {
239709          "type": "library",
239710          "bom-ref": "pkg:npm/accepts@1.3.8?package-id=1e782728d2f96ad5",
239711          "supplier": {},
239712          "name": "accepts",
239713          "version": "1.3.8",
239714          "description": "Higher-level content negotiation",
239715          "licenses": [
239716            {
239717              "license": {
239718                "id": "MIT"
239719              }
239720            }
239721          ],
239722          "cpe": "cpe:2.3:a:accepts:accepts:1.3.8:*:*:*:*:*:*:*",
239723          "purl": "pkg:npm/accepts@1.3.8",
239724          "swid": {
239725            "attachment": {}
239726          },
239727          "pedigree": {},
239728          "externalReferences": [
239729            {
239730              "url": "jshttp/accepts",
239731              "type": "distribution"
239732            }
239733          ],
239734          "evidence": {},
239735          "signature": {
239736            "signature": {
239737              "publicKey": {}
239738            }
239739          },
239740          "modelCard": {
239741            "modelParameters": {
239742              "approach": {}
239743            },
239744            "quantitativeAnalysis": {
239745              "graphics": {}
239746            },
239747            "considerations": {}
239748          }
239749        },
239750        {
239751          "type": "library",
239752          "bom-ref": "pkg:npm/acorn@8.8.0?package-id=abca65515accbcbb",
239753          "supplier": {},
239754          "name": "acorn",
239755          "version": "8.8.0",
239756          "description": "ECMAScript parser",
239757          "licenses": [
239758            {
239759              "license": {
239760                "id": "MIT"
239761              }
239762            }
239763          ],
239764          "cpe": "cpe:2.3:a:acornjs:acorn:8.8.0:*:*:*:*:*:*:*",
239765          "purl": "pkg:npm/acorn@8.8.0",
239766          "swid": {
239767            "attachment": {}
239768          },
239769          "pedigree": {},
239770          "externalReferences": [
239771            {
239772              "url": "https://github.com/acornjs/acorn.git",
239773              "type": "distribution"
239774            },
239775            {
239776              "url": "https://github.com/acornjs/acorn",
239777              "type": "website"
239778            }
239779          ],
239780          "evidence": {},
239781          "signature": {
239782            "signature": {
239783              "publicKey": {}
239784            }
239785          },
239786          "modelCard": {
239787            "modelParameters": {
239788              "approach": {}
239789            },
239790            "quantitativeAnalysis": {
239791              "graphics": {}
239792            },
239793            "considerations": {}
239794          }
239795        },
239796        {
239797          "type": "library",
239798          "bom-ref": "pkg:npm/acorn-walk@8.2.0?package-id=e867131972437532",
239799          "supplier": {},
239800          "name": "acorn-walk",
239801          "version": "8.2.0",
239802          "description": "ECMAScript (ESTree) AST walker",
239803          "licenses": [
239804            {
239805              "license": {
239806                "id": "MIT"
239807              }
239808            }
239809          ],
239810          "cpe": "cpe:2.3:a:acorn-walk:acorn-walk:8.2.0:*:*:*:*:*:*:*",
239811          "purl": "pkg:npm/acorn-walk@8.2.0",
239812          "swid": {
239813            "attachment": {}
239814          },
239815          "pedigree": {},
239816          "externalReferences": [
239817            {
239818              "url": "https://github.com/acornjs/acorn.git",
239819              "type": "distribution"
239820            },
239821            {
239822              "url": "https://github.com/acornjs/acorn",
239823              "type": "website"
239824            }
239825          ],
239826          "evidence": {},
239827          "signature": {
239828            "signature": {
239829              "publicKey": {}
239830            }
239831          },
239832          "modelCard": {
239833            "modelParameters": {
239834              "approach": {}
239835            },
239836            "quantitativeAnalysis": {
239837              "graphics": {}
239838            },
239839            "considerations": {}
239840          }
239841        },
239842        {
239843          "type": "library",
239844          "bom-ref": "pkg:npm/ajv@6.12.6?package-id=d848ab675d068d7e",
239845          "supplier": {},
239846          "author": "Evgeny Poberezkin",
239847          "name": "ajv",
239848          "version": "6.12.6",
239849          "description": "Another JSON Schema Validator",
239850          "licenses": [
239851            {
239852              "license": {
239853                "id": "MIT"
239854              }
239855            }
239856          ],
239857          "cpe": "cpe:2.3:a:ajv-validator:ajv:6.12.6:*:*:*:*:*:*:*",
239858          "purl": "pkg:npm/ajv@6.12.6",
239859          "swid": {
239860            "attachment": {}
239861          },
239862          "pedigree": {},
239863          "externalReferences": [
239864            {
239865              "url": "https://github.com/ajv-validator/ajv.git",
239866              "type": "distribution"
239867            },
239868            {
239869              "url": "https://github.com/ajv-validator/ajv",
239870              "type": "website"
239871            }
239872          ],
239873          "evidence": {},
239874          "signature": {
239875            "signature": {
239876              "publicKey": {}
239877            }
239878          },
239879          "modelCard": {
239880            "modelParameters": {
239881              "approach": {}
239882            },
239883            "quantitativeAnalysis": {
239884              "graphics": {}
239885            },
239886            "considerations": {}
239887          }
239888        },
239889        {
239890          "type": "library",
239891          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=61f27796f703939",
239892          "supplier": {},
239893          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
239894          "name": "alpine-baselayout",
239895          "version": "3.2.0-r3",
239896          "description": "Alpine base dir structure and init scripts",
239897          "licenses": [
239898            {
239899              "license": {
239900                "id": "GPL-2.0-only"
239901              }
239902            }
239903          ],
239904          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r3:*:*:*:*:*:*:*",
239905          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r3?arch=x86_64\u0026distro=alpine-3.11.13",
239906          "swid": {
239907            "attachment": {}
239908          },
239909          "pedigree": {},
239910          "externalReferences": [
239911            {
239912              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
239913              "type": "distribution"
239914            }
239915          ],
239916          "evidence": {},
239917          "signature": {
239918            "signature": {
239919              "publicKey": {}
239920            }
239921          },
239922          "modelCard": {
239923            "modelParameters": {
239924              "approach": {}
239925            },
239926            "quantitativeAnalysis": {
239927              "graphics": {}
239928            },
239929            "considerations": {}
239930          }
239931        },
239932        {
239933          "type": "library",
239934          "bom-ref": "pkg:apk/alpine/alpine-keys@2.1-r2?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=79f884384758c443",
239935          "supplier": {},
239936          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
239937          "name": "alpine-keys",
239938          "version": "2.1-r2",
239939          "description": "Public keys for Alpine Linux packages",
239940          "licenses": [
239941            {
239942              "license": {
239943                "id": "MIT"
239944              }
239945            }
239946          ],
239947          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.1-r2:*:*:*:*:*:*:*",
239948          "purl": "pkg:apk/alpine/alpine-keys@2.1-r2?arch=x86_64\u0026distro=alpine-3.11.13",
239949          "swid": {
239950            "attachment": {}
239951          },
239952          "pedigree": {},
239953          "externalReferences": [
239954            {
239955              "url": "https://alpinelinux.org",
239956              "type": "distribution"
239957            }
239958          ],
239959          "evidence": {},
239960          "signature": {
239961            "signature": {
239962              "publicKey": {}
239963            }
239964          },
239965          "modelCard": {
239966            "modelParameters": {
239967              "approach": {}
239968            },
239969            "quantitativeAnalysis": {
239970              "graphics": {}
239971            },
239972            "considerations": {}
239973          }
239974        },
239975        {
239976          "type": "library",
239977          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=5f44e0d6870d0e9f",
239978          "supplier": {},
239979          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
239980          "name": "ansi-styles",
239981          "version": "4.3.0",
239982          "description": "ANSI escape codes for styling strings in the terminal",
239983          "licenses": [
239984            {
239985              "license": {
239986                "id": "MIT"
239987              }
239988            }
239989          ],
239990          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
239991          "purl": "pkg:npm/ansi-styles@4.3.0",
239992          "swid": {
239993            "attachment": {}
239994          },
239995          "pedigree": {},
239996          "externalReferences": [
239997            {
239998              "url": "chalk/ansi-styles",
239999              "type": "distribution"
240000            }
240001          ],
240002          "evidence": {},
240003          "signature": {
240004            "signature": {
240005              "publicKey": {}
240006            }
240007          },
240008          "modelCard": {
240009            "modelParameters": {
240010              "approach": {}
240011            },
240012            "quantitativeAnalysis": {
240013              "graphics": {}
240014            },
240015            "considerations": {}
240016          }
240017        },
240018        {
240019          "type": "library",
240020          "bom-ref": "pkg:apk/alpine/apk-tools@2.10.8-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=28993d8277c2c4f",
240021          "supplier": {},
240022          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
240023          "name": "apk-tools",
240024          "version": "2.10.8-r0",
240025          "description": "Alpine Package Keeper - package manager for alpine",
240026          "licenses": [
240027            {
240028              "license": {
240029                "id": "GPL-2.0-only"
240030              }
240031            }
240032          ],
240033          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.10.8-r0:*:*:*:*:*:*:*",
240034          "purl": "pkg:apk/alpine/apk-tools@2.10.8-r0?arch=x86_64\u0026distro=alpine-3.11.13",
240035          "swid": {
240036            "attachment": {}
240037          },
240038          "pedigree": {},
240039          "externalReferences": [
240040            {
240041              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
240042              "type": "distribution"
240043            }
240044          ],
240045          "evidence": {},
240046          "signature": {
240047            "signature": {
240048              "publicKey": {}
240049            }
240050          },
240051          "modelCard": {
240052            "modelParameters": {
240053              "approach": {}
240054            },
240055            "quantitativeAnalysis": {
240056              "graphics": {}
240057            },
240058            "considerations": {}
240059          }
240060        },
240061        {
240062          "type": "library",
240063          "bom-ref": "pkg:npm/append-field@1.0.0?package-id=61114d940dc42e53",
240064          "supplier": {},
240065          "author": "Linus Unnebäck \u003clinus@folkdatorn.se\u003e",
240066          "name": "append-field",
240067          "version": "1.0.0",
240068          "licenses": [
240069            {
240070              "license": {
240071                "id": "MIT"
240072              }
240073            }
240074          ],
240075          "cpe": "cpe:2.3:a:append-field:append-field:1.0.0:*:*:*:*:*:*:*",
240076          "purl": "pkg:npm/append-field@1.0.0",
240077          "swid": {
240078            "attachment": {}
240079          },
240080          "pedigree": {},
240081          "externalReferences": [
240082            {
240083              "url": "http://github.com/LinusU/node-append-field.git",
240084              "type": "distribution"
240085            }
240086          ],
240087          "evidence": {},
240088          "signature": {
240089            "signature": {
240090              "publicKey": {}
240091            }
240092          },
240093          "modelCard": {
240094            "modelParameters": {
240095              "approach": {}
240096            },
240097            "quantitativeAnalysis": {
240098              "graphics": {}
240099            },
240100            "considerations": {}
240101          }
240102        },
240103        {
240104          "type": "library",
240105          "bom-ref": "pkg:npm/argparse@1.0.10?package-id=a8c08d35b24bfc06",
240106          "supplier": {},
240107          "name": "argparse",
240108          "version": "1.0.10",
240109          "description": "Very powerful CLI arguments parser. Native port of argparse - python's options parsing library",
240110          "licenses": [
240111            {
240112              "license": {
240113                "id": "MIT"
240114              }
240115            }
240116          ],
240117          "cpe": "cpe:2.3:a:argparse:argparse:1.0.10:*:*:*:*:*:*:*",
240118          "purl": "pkg:npm/argparse@1.0.10",
240119          "swid": {
240120            "attachment": {}
240121          },
240122          "pedigree": {},
240123          "externalReferences": [
240124            {
240125              "url": "nodeca/argparse",
240126              "type": "distribution"
240127            }
240128          ],
240129          "evidence": {},
240130          "signature": {
240131            "signature": {
240132              "publicKey": {}
240133            }
240134          },
240135          "modelCard": {
240136            "modelParameters": {
240137              "approach": {}
240138            },
240139            "quantitativeAnalysis": {
240140              "graphics": {}
240141            },
240142            "considerations": {}
240143          }
240144        },
240145        {
240146          "type": "library",
240147          "bom-ref": "pkg:npm/array-flatten@1.1.1?package-id=a0792ccdcca020ca",
240148          "supplier": {},
240149          "author": "Blake Embrey \u003chello@blakeembrey.com\u003e (http://blakeembrey.me)",
240150          "name": "array-flatten",
240151          "version": "1.1.1",
240152          "description": "Flatten an array of nested arrays into a single flat array",
240153          "licenses": [
240154            {
240155              "license": {
240156                "id": "MIT"
240157              }
240158            }
240159          ],
240160          "cpe": "cpe:2.3:a:array-flatten:array-flatten:1.1.1:*:*:*:*:*:*:*",
240161          "purl": "pkg:npm/array-flatten@1.1.1",
240162          "swid": {
240163            "attachment": {}
240164          },
240165          "pedigree": {},
240166          "externalReferences": [
240167            {
240168              "url": "git://github.com/blakeembrey/array-flatten.git",
240169              "type": "distribution"
240170            },
240171            {
240172              "url": "https://github.com/blakeembrey/array-flatten",
240173              "type": "website"
240174            }
240175          ],
240176          "evidence": {},
240177          "signature": {
240178            "signature": {
240179              "publicKey": {}
240180            }
240181          },
240182          "modelCard": {
240183            "modelParameters": {
240184              "approach": {}
240185            },
240186            "quantitativeAnalysis": {
240187              "graphics": {}
240188            },
240189            "considerations": {}
240190          }
240191        },
240192        {
240193          "type": "library",
240194          "bom-ref": "pkg:npm/asn1@0.2.6?package-id=fcf616ea5d0cab3",
240195          "supplier": {},
240196          "author": "Joyent (joyent.com)",
240197          "name": "asn1",
240198          "version": "0.2.6",
240199          "description": "Contains parsers and serializers for ASN.1 (currently BER only)",
240200          "licenses": [
240201            {
240202              "license": {
240203                "id": "MIT"
240204              }
240205            }
240206          ],
240207          "cpe": "cpe:2.3:a:joyent:asn1:0.2.6:*:*:*:*:*:*:*",
240208          "purl": "pkg:npm/asn1@0.2.6",
240209          "swid": {
240210            "attachment": {}
240211          },
240212          "pedigree": {},
240213          "externalReferences": [
240214            {
240215              "url": "https://github.com/joyent/node-asn1.git",
240216              "type": "distribution"
240217            }
240218          ],
240219          "evidence": {},
240220          "signature": {
240221            "signature": {
240222              "publicKey": {}
240223            }
240224          },
240225          "modelCard": {
240226            "modelParameters": {
240227              "approach": {}
240228            },
240229            "quantitativeAnalysis": {
240230              "graphics": {}
240231            },
240232            "considerations": {}
240233          }
240234        },
240235        {
240236          "type": "library",
240237          "bom-ref": "pkg:npm/assert-plus@1.0.0?package-id=cc913262afbe8a5f",
240238          "supplier": {},
240239          "author": "Mark Cavage \u003cmcavage@gmail.com\u003e",
240240          "name": "assert-plus",
240241          "version": "1.0.0",
240242          "description": "Extra assertions on top of node's assert module",
240243          "licenses": [
240244            {
240245              "license": {
240246                "id": "MIT"
240247              }
240248            }
240249          ],
240250          "cpe": "cpe:2.3:a:assert-plus:assert-plus:1.0.0:*:*:*:*:*:*:*",
240251          "purl": "pkg:npm/assert-plus@1.0.0",
240252          "swid": {
240253            "attachment": {}
240254          },
240255          "pedigree": {},
240256          "externalReferences": [
240257            {
240258              "url": "https://github.com/mcavage/node-assert-plus.git",
240259              "type": "distribution"
240260            }
240261          ],
240262          "evidence": {},
240263          "signature": {
240264            "signature": {
240265              "publicKey": {}
240266            }
240267          },
240268          "modelCard": {
240269            "modelParameters": {
240270              "approach": {}
240271            },
240272            "quantitativeAnalysis": {
240273              "graphics": {}
240274            },
240275            "considerations": {}
240276          }
240277        },
240278        {
240279          "type": "library",
240280          "bom-ref": "pkg:npm/asynckit@0.4.0?package-id=1f30a832887b0ff8",
240281          "supplier": {},
240282          "author": "Alex Indigo \u003ciam@alexindigo.com\u003e",
240283          "name": "asynckit",
240284          "version": "0.4.0",
240285          "description": "Minimal async jobs utility library, with streams support",
240286          "licenses": [
240287            {
240288              "license": {
240289                "id": "MIT"
240290              }
240291            }
240292          ],
240293          "cpe": "cpe:2.3:a:alexindigo:asynckit:0.4.0:*:*:*:*:*:*:*",
240294          "purl": "pkg:npm/asynckit@0.4.0",
240295          "swid": {
240296            "attachment": {}
240297          },
240298          "pedigree": {},
240299          "externalReferences": [
240300            {
240301              "url": "git+https://github.com/alexindigo/asynckit.git",
240302              "type": "distribution"
240303            },
240304            {
240305              "url": "https://github.com/alexindigo/asynckit#readme",
240306              "type": "website"
240307            }
240308          ],
240309          "evidence": {},
240310          "signature": {
240311            "signature": {
240312              "publicKey": {}
240313            }
240314          },
240315          "modelCard": {
240316            "modelParameters": {
240317              "approach": {}
240318            },
240319            "quantitativeAnalysis": {
240320              "graphics": {}
240321            },
240322            "considerations": {}
240323          }
240324        },
240325        {
240326          "type": "library",
240327          "bom-ref": "pkg:npm/aws-sign2@0.7.0?package-id=ecb4a9d1efb7a585",
240328          "supplier": {},
240329          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
240330          "name": "aws-sign2",
240331          "version": "0.7.0",
240332          "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
240333          "licenses": [
240334            {
240335              "license": {
240336                "id": "Apache-2.0"
240337              }
240338            }
240339          ],
240340          "cpe": "cpe:2.3:a:aws-sign2:aws-sign2:0.7.0:*:*:*:*:*:*:*",
240341          "purl": "pkg:npm/aws-sign2@0.7.0",
240342          "swid": {
240343            "attachment": {}
240344          },
240345          "pedigree": {},
240346          "externalReferences": [
240347            {
240348              "url": "https://github.com/mikeal/aws-sign",
240349              "type": "distribution"
240350            }
240351          ],
240352          "evidence": {},
240353          "signature": {
240354            "signature": {
240355              "publicKey": {}
240356            }
240357          },
240358          "modelCard": {
240359            "modelParameters": {
240360              "approach": {}
240361            },
240362            "quantitativeAnalysis": {
240363              "graphics": {}
240364            },
240365            "considerations": {}
240366          }
240367        },
240368        {
240369          "type": "library",
240370          "bom-ref": "pkg:npm/aws4@1.11.0?package-id=9a100f91453a7603",
240371          "supplier": {},
240372          "author": "Michael Hart \u003cmichael.hart.au@gmail.com\u003e (https://github.com/mhart)",
240373          "name": "aws4",
240374          "version": "1.11.0",
240375          "description": "Signs and prepares requests using AWS Signature Version 4",
240376          "licenses": [
240377            {
240378              "license": {
240379                "id": "MIT"
240380              }
240381            }
240382          ],
240383          "cpe": "cpe:2.3:a:aws4:aws4:1.11.0:*:*:*:*:*:*:*",
240384          "purl": "pkg:npm/aws4@1.11.0",
240385          "swid": {
240386            "attachment": {}
240387          },
240388          "pedigree": {},
240389          "externalReferences": [
240390            {
240391              "url": "github:mhart/aws4",
240392              "type": "distribution"
240393            }
240394          ],
240395          "evidence": {},
240396          "signature": {
240397            "signature": {
240398              "publicKey": {}
240399            }
240400          },
240401          "modelCard": {
240402            "modelParameters": {
240403              "approach": {}
240404            },
240405            "quantitativeAnalysis": {
240406              "graphics": {}
240407            },
240408            "considerations": {}
240409          }
240410        },
240411        {
240412          "type": "library",
240413          "bom-ref": "pkg:npm/axios@0.21.1?package-id=41cbd58df24630d7",
240414          "supplier": {},
240415          "author": "Matt Zabriskie",
240416          "name": "axios",
240417          "version": "0.21.1",
240418          "description": "Promise based HTTP client for the browser and node.js",
240419          "licenses": [
240420            {
240421              "license": {
240422                "id": "MIT"
240423              }
240424            }
240425          ],
240426          "cpe": "cpe:2.3:a:axios:axios:0.21.1:*:*:*:*:*:*:*",
240427          "purl": "pkg:npm/axios@0.21.1",
240428          "swid": {
240429            "attachment": {}
240430          },
240431          "pedigree": {},
240432          "externalReferences": [
240433            {
240434              "url": "https://github.com/axios/axios.git",
240435              "type": "distribution"
240436            },
240437            {
240438              "url": "https://github.com/axios/axios",
240439              "type": "website"
240440            }
240441          ],
240442          "evidence": {},
240443          "signature": {
240444            "signature": {
240445              "publicKey": {}
240446            }
240447          },
240448          "modelCard": {
240449            "modelParameters": {
240450              "approach": {}
240451            },
240452            "quantitativeAnalysis": {
240453              "graphics": {}
240454            },
240455            "considerations": {}
240456          }
240457        },
240458        {
240459          "type": "library",
240460          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=adb20dac41a9f796",
240461          "supplier": {},
240462          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
240463          "name": "balanced-match",
240464          "version": "1.0.2",
240465          "description": "Match balanced character pairs, like \"{\" and \"}\"",
240466          "licenses": [
240467            {
240468              "license": {
240469                "id": "MIT"
240470              }
240471            }
240472          ],
240473          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
240474          "purl": "pkg:npm/balanced-match@1.0.2",
240475          "swid": {
240476            "attachment": {}
240477          },
240478          "pedigree": {},
240479          "externalReferences": [
240480            {
240481              "url": "git://github.com/juliangruber/balanced-match.git",
240482              "type": "distribution"
240483            },
240484            {
240485              "url": "https://github.com/juliangruber/balanced-match",
240486              "type": "website"
240487            }
240488          ],
240489          "evidence": {},
240490          "signature": {
240491            "signature": {
240492              "publicKey": {}
240493            }
240494          },
240495          "modelCard": {
240496            "modelParameters": {
240497              "approach": {}
240498            },
240499            "quantitativeAnalysis": {
240500              "graphics": {}
240501            },
240502            "considerations": {}
240503          }
240504        },
240505        {
240506          "type": "library",
240507          "bom-ref": "pkg:npm/bcrypt-pbkdf@1.0.2?package-id=c90f98bc05501cc0",
240508          "supplier": {},
240509          "name": "bcrypt-pbkdf",
240510          "version": "1.0.2",
240511          "description": "Port of the OpenBSD bcrypt_pbkdf function to pure JS",
240512          "licenses": [
240513            {
240514              "license": {
240515                "id": "BSD-3-Clause"
240516              }
240517            }
240518          ],
240519          "cpe": "cpe:2.3:a:bcrypt-pbkdf:bcrypt-pbkdf:1.0.2:*:*:*:*:*:*:*",
240520          "purl": "pkg:npm/bcrypt-pbkdf@1.0.2",
240521          "swid": {
240522            "attachment": {}
240523          },
240524          "pedigree": {},
240525          "externalReferences": [
240526            {
240527              "url": "git://github.com/joyent/node-bcrypt-pbkdf.git",
240528              "type": "distribution"
240529            }
240530          ],
240531          "evidence": {},
240532          "signature": {
240533            "signature": {
240534              "publicKey": {}
240535            }
240536          },
240537          "modelCard": {
240538            "modelParameters": {
240539              "approach": {}
240540            },
240541            "quantitativeAnalysis": {
240542              "graphics": {}
240543            },
240544            "considerations": {}
240545          }
240546        },
240547        {
240548          "type": "library",
240549          "bom-ref": "pkg:npm/body-parser@1.19.0?package-id=75f0fd44f4a12452",
240550          "supplier": {},
240551          "name": "body-parser",
240552          "version": "1.19.0",
240553          "description": "Node.js body parsing middleware",
240554          "licenses": [
240555            {
240556              "license": {
240557                "id": "MIT"
240558              }
240559            }
240560          ],
240561          "cpe": "cpe:2.3:a:body-parser:body-parser:1.19.0:*:*:*:*:*:*:*",
240562          "purl": "pkg:npm/body-parser@1.19.0",
240563          "swid": {
240564            "attachment": {}
240565          },
240566          "pedigree": {},
240567          "externalReferences": [
240568            {
240569              "url": "expressjs/body-parser",
240570              "type": "distribution"
240571            }
240572          ],
240573          "evidence": {},
240574          "signature": {
240575            "signature": {
240576              "publicKey": {}
240577            }
240578          },
240579          "modelCard": {
240580            "modelParameters": {
240581              "approach": {}
240582            },
240583            "quantitativeAnalysis": {
240584              "graphics": {}
240585            },
240586            "considerations": {}
240587          }
240588        },
240589        {
240590          "type": "library",
240591          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=b2f1259ad317cd31",
240592          "supplier": {},
240593          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
240594          "name": "brace-expansion",
240595          "version": "1.1.11",
240596          "description": "Brace expansion as known from sh/bash",
240597          "licenses": [
240598            {
240599              "license": {
240600                "id": "MIT"
240601              }
240602            }
240603          ],
240604          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
240605          "purl": "pkg:npm/brace-expansion@1.1.11",
240606          "swid": {
240607            "attachment": {}
240608          },
240609          "pedigree": {},
240610          "externalReferences": [
240611            {
240612              "url": "git://github.com/juliangruber/brace-expansion.git",
240613              "type": "distribution"
240614            },
240615            {
240616              "url": "https://github.com/juliangruber/brace-expansion",
240617              "type": "website"
240618            }
240619          ],
240620          "evidence": {},
240621          "signature": {
240622            "signature": {
240623              "publicKey": {}
240624            }
240625          },
240626          "modelCard": {
240627            "modelParameters": {
240628              "approach": {}
240629            },
240630            "quantitativeAnalysis": {
240631              "graphics": {}
240632            },
240633            "considerations": {}
240634          }
240635        },
240636        {
240637          "type": "library",
240638          "bom-ref": "pkg:npm/buffer-from@1.1.2?package-id=9fbdf57a30df513b",
240639          "supplier": {},
240640          "name": "buffer-from",
240641          "version": "1.1.2",
240642          "licenses": [
240643            {
240644              "license": {
240645                "id": "MIT"
240646              }
240647            }
240648          ],
240649          "cpe": "cpe:2.3:a:buffer-from:buffer-from:1.1.2:*:*:*:*:*:*:*",
240650          "purl": "pkg:npm/buffer-from@1.1.2",
240651          "swid": {
240652            "attachment": {}
240653          },
240654          "pedigree": {},
240655          "externalReferences": [
240656            {
240657              "url": "LinusU/buffer-from",
240658              "type": "distribution"
240659            }
240660          ],
240661          "evidence": {},
240662          "signature": {
240663            "signature": {
240664              "publicKey": {}
240665            }
240666          },
240667          "modelCard": {
240668            "modelParameters": {
240669              "approach": {}
240670            },
240671            "quantitativeAnalysis": {
240672              "graphics": {}
240673            },
240674            "considerations": {}
240675          }
240676        },
240677        {
240678          "type": "library",
240679          "bom-ref": "pkg:npm/busboy@0.2.14?package-id=bcc00af63882763b",
240680          "supplier": {},
240681          "author": "Brian White \u003cmscdex@mscdex.net\u003e",
240682          "name": "busboy",
240683          "version": "0.2.14",
240684          "description": "A streaming parser for HTML form data for node.js",
240685          "licenses": [
240686            {
240687              "license": {
240688                "id": "MIT"
240689              }
240690            }
240691          ],
240692          "cpe": "cpe:2.3:a:busboy:busboy:0.2.14:*:*:*:*:*:*:*",
240693          "purl": "pkg:npm/busboy@0.2.14",
240694          "swid": {
240695            "attachment": {}
240696          },
240697          "pedigree": {},
240698          "externalReferences": [
240699            {
240700              "url": "http://github.com/mscdex/busboy.git",
240701              "type": "distribution"
240702            }
240703          ],
240704          "evidence": {},
240705          "signature": {
240706            "signature": {
240707              "publicKey": {}
240708            }
240709          },
240710          "modelCard": {
240711            "modelParameters": {
240712              "approach": {}
240713            },
240714            "quantitativeAnalysis": {
240715              "graphics": {}
240716            },
240717            "considerations": {}
240718          }
240719        },
240720        {
240721          "type": "application",
240722          "bom-ref": "eb62c645e9680ee0",
240723          "supplier": {},
240724          "name": "busybox",
240725          "version": "1.31.1",
240726          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1:*:*:*:*:*:*:*",
240727          "swid": {
240728            "attachment": {}
240729          },
240730          "pedigree": {},
240731          "evidence": {},
240732          "signature": {
240733            "signature": {
240734              "publicKey": {}
240735            }
240736          },
240737          "modelCard": {
240738            "modelParameters": {
240739              "approach": {}
240740            },
240741            "quantitativeAnalysis": {
240742              "graphics": {}
240743            },
240744            "considerations": {}
240745          }
240746        },
240747        {
240748          "type": "library",
240749          "bom-ref": "pkg:apk/alpine/busybox@1.31.1-r11?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=3f3095cbef6e353",
240750          "supplier": {},
240751          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
240752          "name": "busybox",
240753          "version": "1.31.1-r11",
240754          "description": "Size optimized toolbox of many common UNIX utilities",
240755          "licenses": [
240756            {
240757              "license": {
240758                "id": "GPL-2.0-only"
240759              }
240760            }
240761          ],
240762          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1-r11:*:*:*:*:*:*:*",
240763          "purl": "pkg:apk/alpine/busybox@1.31.1-r11?arch=x86_64\u0026distro=alpine-3.11.13",
240764          "swid": {
240765            "attachment": {}
240766          },
240767          "pedigree": {},
240768          "externalReferences": [
240769            {
240770              "url": "https://busybox.net/",
240771              "type": "distribution"
240772            }
240773          ],
240774          "evidence": {},
240775          "signature": {
240776            "signature": {
240777              "publicKey": {}
240778            }
240779          },
240780          "modelCard": {
240781            "modelParameters": {
240782              "approach": {}
240783            },
240784            "quantitativeAnalysis": {
240785              "graphics": {}
240786            },
240787            "considerations": {}
240788          }
240789        },
240790        {
240791          "type": "library",
240792          "bom-ref": "pkg:npm/bytes@3.1.0?package-id=9b9980bcb7763199",
240793          "supplier": {},
240794          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
240795          "name": "bytes",
240796          "version": "3.1.0",
240797          "description": "Utility to parse a string bytes to bytes and vice-versa",
240798          "licenses": [
240799            {
240800              "license": {
240801                "id": "MIT"
240802              }
240803            }
240804          ],
240805          "cpe": "cpe:2.3:a:bytes:bytes:3.1.0:*:*:*:*:*:*:*",
240806          "purl": "pkg:npm/bytes@3.1.0",
240807          "swid": {
240808            "attachment": {}
240809          },
240810          "pedigree": {},
240811          "externalReferences": [
240812            {
240813              "url": "visionmedia/bytes.js",
240814              "type": "distribution"
240815            }
240816          ],
240817          "evidence": {},
240818          "signature": {
240819            "signature": {
240820              "publicKey": {}
240821            }
240822          },
240823          "modelCard": {
240824            "modelParameters": {
240825              "approach": {}
240826            },
240827            "quantitativeAnalysis": {
240828              "graphics": {}
240829            },
240830            "considerations": {}
240831          }
240832        },
240833        {
240834          "type": "library",
240835          "bom-ref": "pkg:apk/alpine/ca-certificates-cacert@20191127-r2?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.11.13\u0026package-id=e135ce85ed757130",
240836          "supplier": {},
240837          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
240838          "name": "ca-certificates-cacert",
240839          "version": "20191127-r2",
240840          "description": "Mozilla bundled certificates",
240841          "licenses": [
240842            {
240843              "license": {
240844                "id": "MPL-2.0"
240845              }
240846            },
240847            {
240848              "license": {
240849                "id": "GPL-2.0-or-later"
240850              }
240851            }
240852          ],
240853          "cpe": "cpe:2.3:a:ca-certificates-cacert:ca-certificates-cacert:20191127-r2:*:*:*:*:*:*:*",
240854          "purl": "pkg:apk/alpine/ca-certificates-cacert@20191127-r2?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.11.13",
240855          "swid": {
240856            "attachment": {}
240857          },
240858          "pedigree": {},
240859          "externalReferences": [
240860            {
240861              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
240862              "type": "distribution"
240863            }
240864          ],
240865          "evidence": {},
240866          "signature": {
240867            "signature": {
240868              "publicKey": {}
240869            }
240870          },
240871          "modelCard": {
240872            "modelParameters": {
240873              "approach": {}
240874            },
240875            "quantitativeAnalysis": {
240876              "graphics": {}
240877            },
240878            "considerations": {}
240879          }
240880        },
240881        {
240882          "type": "library",
240883          "bom-ref": "pkg:npm/caseless@0.12.0?package-id=221908f94b11f2bf",
240884          "supplier": {},
240885          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
240886          "name": "caseless",
240887          "version": "0.12.0",
240888          "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
240889          "licenses": [
240890            {
240891              "license": {
240892                "id": "Apache-2.0"
240893              }
240894            }
240895          ],
240896          "cpe": "cpe:2.3:a:caseless:caseless:0.12.0:*:*:*:*:*:*:*",
240897          "purl": "pkg:npm/caseless@0.12.0",
240898          "swid": {
240899            "attachment": {}
240900          },
240901          "pedigree": {},
240902          "externalReferences": [
240903            {
240904              "url": "https://github.com/mikeal/caseless",
240905              "type": "distribution"
240906            }
240907          ],
240908          "evidence": {},
240909          "signature": {
240910            "signature": {
240911              "publicKey": {}
240912            }
240913          },
240914          "modelCard": {
240915            "modelParameters": {
240916              "approach": {}
240917            },
240918            "quantitativeAnalysis": {
240919              "graphics": {}
240920            },
240921            "considerations": {}
240922          }
240923        },
240924        {
240925          "type": "library",
240926          "bom-ref": "pkg:npm/chalk@4.1.2?package-id=fa63c4db8c85f06e",
240927          "supplier": {},
240928          "name": "chalk",
240929          "version": "4.1.2",
240930          "description": "Terminal string styling done right",
240931          "licenses": [
240932            {
240933              "license": {
240934                "id": "MIT"
240935              }
240936            }
240937          ],
240938          "cpe": "cpe:2.3:a:chalk:chalk:4.1.2:*:*:*:*:*:*:*",
240939          "purl": "pkg:npm/chalk@4.1.2",
240940          "swid": {
240941            "attachment": {}
240942          },
240943          "pedigree": {},
240944          "externalReferences": [
240945            {
240946              "url": "chalk/chalk",
240947              "type": "distribution"
240948            }
240949          ],
240950          "evidence": {},
240951          "signature": {
240952            "signature": {
240953              "publicKey": {}
240954            }
240955          },
240956          "modelCard": {
240957            "modelParameters": {
240958              "approach": {}
240959            },
240960            "quantitativeAnalysis": {
240961              "graphics": {}
240962            },
240963            "considerations": {}
240964          }
240965        },
240966        {
240967          "type": "library",
240968          "bom-ref": "pkg:npm/class-transformer@0.3.1?package-id=6d35b09acf35095e",
240969          "supplier": {},
240970          "author": "Umed Khudoiberdiev \u003cpleerock.me@gmail.com\u003e",
240971          "name": "class-transformer",
240972          "version": "0.3.1",
240973          "description": "Proper decorator-based transformation / serialization / deserialization of plain javascript objects to class constructors",
240974          "licenses": [
240975            {
240976              "license": {
240977                "id": "MIT"
240978              }
240979            }
240980          ],
240981          "cpe": "cpe:2.3:a:class-transformer:class-transformer:0.3.1:*:*:*:*:*:*:*",
240982          "purl": "pkg:npm/class-transformer@0.3.1",
240983          "swid": {
240984            "attachment": {}
240985          },
240986          "pedigree": {},
240987          "externalReferences": [
240988            {
240989              "url": "https://github.com/typestack/class-transformer.git",
240990              "type": "distribution"
240991            }
240992          ],
240993          "evidence": {},
240994          "signature": {
240995            "signature": {
240996              "publicKey": {}
240997            }
240998          },
240999          "modelCard": {
241000            "modelParameters": {
241001              "approach": {}
241002            },
241003            "quantitativeAnalysis": {
241004              "graphics": {}
241005            },
241006            "considerations": {}
241007          }
241008        },
241009        {
241010          "type": "library",
241011          "bom-ref": "pkg:npm/class-validator@0.12.2?package-id=643573d629b73678",
241012          "supplier": {},
241013          "author": "Umed Khudoiberdiev \u003cpleerock.me@gmail.com\u003e",
241014          "name": "class-validator",
241015          "version": "0.12.2",
241016          "description": "Class-based validation with Typescript / ES6 / ES5 using decorators or validation schemas. Supports both node.js and browser",
241017          "licenses": [
241018            {
241019              "license": {
241020                "id": "MIT"
241021              }
241022            }
241023          ],
241024          "cpe": "cpe:2.3:a:class-validator:class-validator:0.12.2:*:*:*:*:*:*:*",
241025          "purl": "pkg:npm/class-validator@0.12.2",
241026          "swid": {
241027            "attachment": {}
241028          },
241029          "pedigree": {},
241030          "externalReferences": [
241031            {
241032              "url": "https://github.com/typestack/class-validator.git",
241033              "type": "distribution"
241034            }
241035          ],
241036          "evidence": {},
241037          "signature": {
241038            "signature": {
241039              "publicKey": {}
241040            }
241041          },
241042          "modelCard": {
241043            "modelParameters": {
241044              "approach": {}
241045            },
241046            "quantitativeAnalysis": {
241047              "graphics": {}
241048            },
241049            "considerations": {}
241050          }
241051        },
241052        {
241053          "type": "library",
241054          "bom-ref": "pkg:npm/clone@2.1.2?package-id=ddeefb9a5c39ff9d",
241055          "supplier": {},
241056          "author": "Paul Vorbach \u003cpaul@vorba.ch\u003e (http://paul.vorba.ch/)",
241057          "name": "clone",
241058          "version": "2.1.2",
241059          "description": "deep cloning of objects and arrays",
241060          "licenses": [
241061            {
241062              "license": {
241063                "id": "MIT"
241064              }
241065            }
241066          ],
241067          "cpe": "cpe:2.3:a:clone:clone:2.1.2:*:*:*:*:*:*:*",
241068          "purl": "pkg:npm/clone@2.1.2",
241069          "swid": {
241070            "attachment": {}
241071          },
241072          "pedigree": {},
241073          "externalReferences": [
241074            {
241075              "url": "git://github.com/pvorb/node-clone.git",
241076              "type": "distribution"
241077            }
241078          ],
241079          "evidence": {},
241080          "signature": {
241081            "signature": {
241082              "publicKey": {}
241083            }
241084          },
241085          "modelCard": {
241086            "modelParameters": {
241087              "approach": {}
241088            },
241089            "quantitativeAnalysis": {
241090              "graphics": {}
241091            },
241092            "considerations": {}
241093          }
241094        },
241095        {
241096          "type": "library",
241097          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=ede9e43092bb946",
241098          "supplier": {},
241099          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
241100          "name": "color-convert",
241101          "version": "2.0.1",
241102          "description": "Plain color conversion functions",
241103          "licenses": [
241104            {
241105              "license": {
241106                "id": "MIT"
241107              }
241108            }
241109          ],
241110          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
241111          "purl": "pkg:npm/color-convert@2.0.1",
241112          "swid": {
241113            "attachment": {}
241114          },
241115          "pedigree": {},
241116          "externalReferences": [
241117            {
241118              "url": "Qix-/color-convert",
241119              "type": "distribution"
241120            }
241121          ],
241122          "evidence": {},
241123          "signature": {
241124            "signature": {
241125              "publicKey": {}
241126            }
241127          },
241128          "modelCard": {
241129            "modelParameters": {
241130              "approach": {}
241131            },
241132            "quantitativeAnalysis": {
241133              "graphics": {}
241134            },
241135            "considerations": {}
241136          }
241137        },
241138        {
241139          "type": "library",
241140          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=1b53bfdbf817bc09",
241141          "supplier": {},
241142          "author": "DY \u003cdfcreative@gmail.com\u003e",
241143          "name": "color-name",
241144          "version": "1.1.4",
241145          "description": "A list of color names and its values",
241146          "licenses": [
241147            {
241148              "license": {
241149                "id": "MIT"
241150              }
241151            }
241152          ],
241153          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
241154          "purl": "pkg:npm/color-name@1.1.4",
241155          "swid": {
241156            "attachment": {}
241157          },
241158          "pedigree": {},
241159          "externalReferences": [
241160            {
241161              "url": "git@github.com:colorjs/color-name.git",
241162              "type": "distribution"
241163            },
241164            {
241165              "url": "https://github.com/colorjs/color-name",
241166              "type": "website"
241167            }
241168          ],
241169          "evidence": {},
241170          "signature": {
241171            "signature": {
241172              "publicKey": {}
241173            }
241174          },
241175          "modelCard": {
241176            "modelParameters": {
241177              "approach": {}
241178            },
241179            "quantitativeAnalysis": {
241180              "graphics": {}
241181            },
241182            "considerations": {}
241183          }
241184        },
241185        {
241186          "type": "library",
241187          "bom-ref": "pkg:npm/combined-stream@1.0.8?package-id=1815a102a95b1ebf",
241188          "supplier": {},
241189          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
241190          "name": "combined-stream",
241191          "version": "1.0.8",
241192          "description": "A stream that emits multiple other streams one after another.",
241193          "licenses": [
241194            {
241195              "license": {
241196                "id": "MIT"
241197              }
241198            }
241199          ],
241200          "cpe": "cpe:2.3:a:combined-stream:combined-stream:1.0.8:*:*:*:*:*:*:*",
241201          "purl": "pkg:npm/combined-stream@1.0.8",
241202          "swid": {
241203            "attachment": {}
241204          },
241205          "pedigree": {},
241206          "externalReferences": [
241207            {
241208              "url": "git://github.com/felixge/node-combined-stream.git",
241209              "type": "distribution"
241210            },
241211            {
241212              "url": "https://github.com/felixge/node-combined-stream",
241213              "type": "website"
241214            }
241215          ],
241216          "evidence": {},
241217          "signature": {
241218            "signature": {
241219              "publicKey": {}
241220            }
241221          },
241222          "modelCard": {
241223            "modelParameters": {
241224              "approach": {}
241225            },
241226            "quantitativeAnalysis": {
241227              "graphics": {}
241228            },
241229            "considerations": {}
241230          }
241231        },
241232        {
241233          "type": "library",
241234          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=365c0e5852decdee",
241235          "supplier": {},
241236          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
241237          "name": "concat-map",
241238          "version": "0.0.1",
241239          "description": "concatenative mapdashery",
241240          "licenses": [
241241            {
241242              "license": {
241243                "id": "MIT"
241244              }
241245            }
241246          ],
241247          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
241248          "purl": "pkg:npm/concat-map@0.0.1",
241249          "swid": {
241250            "attachment": {}
241251          },
241252          "pedigree": {},
241253          "externalReferences": [
241254            {
241255              "url": "git://github.com/substack/node-concat-map.git",
241256              "type": "distribution"
241257            }
241258          ],
241259          "evidence": {},
241260          "signature": {
241261            "signature": {
241262              "publicKey": {}
241263            }
241264          },
241265          "modelCard": {
241266            "modelParameters": {
241267              "approach": {}
241268            },
241269            "quantitativeAnalysis": {
241270              "graphics": {}
241271            },
241272            "considerations": {}
241273          }
241274        },
241275        {
241276          "type": "library",
241277          "bom-ref": "pkg:npm/concat-stream@1.6.2?package-id=625928c8328aeef2",
241278          "supplier": {},
241279          "author": "Max Ogden \u003cmax@maxogden.com\u003e",
241280          "name": "concat-stream",
241281          "version": "1.6.2",
241282          "description": "writable stream that concatenates strings or binary data and calls a callback with the result",
241283          "licenses": [
241284            {
241285              "license": {
241286                "id": "MIT"
241287              }
241288            }
241289          ],
241290          "cpe": "cpe:2.3:a:concat-stream:concat-stream:1.6.2:*:*:*:*:*:*:*",
241291          "purl": "pkg:npm/concat-stream@1.6.2",
241292          "swid": {
241293            "attachment": {}
241294          },
241295          "pedigree": {},
241296          "externalReferences": [
241297            {
241298              "url": "http://github.com/maxogden/concat-stream.git",
241299              "type": "distribution"
241300            }
241301          ],
241302          "evidence": {},
241303          "signature": {
241304            "signature": {
241305              "publicKey": {}
241306            }
241307          },
241308          "modelCard": {
241309            "modelParameters": {
241310              "approach": {}
241311            },
241312            "quantitativeAnalysis": {
241313              "graphics": {}
241314            },
241315            "considerations": {}
241316          }
241317        },
241318        {
241319          "type": "library",
241320          "bom-ref": "pkg:npm/consola@2.15.3?package-id=8e45836dee2f9a42",
241321          "supplier": {},
241322          "name": "consola",
241323          "version": "2.15.3",
241324          "description": "Elegant Console Logger for Node.js and Browser",
241325          "licenses": [
241326            {
241327              "license": {
241328                "id": "MIT"
241329              }
241330            }
241331          ],
241332          "cpe": "cpe:2.3:a:consola:consola:2.15.3:*:*:*:*:*:*:*",
241333          "purl": "pkg:npm/consola@2.15.3",
241334          "swid": {
241335            "attachment": {}
241336          },
241337          "pedigree": {},
241338          "externalReferences": [
241339            {
241340              "url": "nuxt/consola",
241341              "type": "distribution"
241342            }
241343          ],
241344          "evidence": {},
241345          "signature": {
241346            "signature": {
241347              "publicKey": {}
241348            }
241349          },
241350          "modelCard": {
241351            "modelParameters": {
241352              "approach": {}
241353            },
241354            "quantitativeAnalysis": {
241355              "graphics": {}
241356            },
241357            "considerations": {}
241358          }
241359        },
241360        {
241361          "type": "library",
241362          "bom-ref": "pkg:npm/content-disposition@0.5.3?package-id=c38707d4f6028283",
241363          "supplier": {},
241364          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
241365          "name": "content-disposition",
241366          "version": "0.5.3",
241367          "description": "Create and parse Content-Disposition header",
241368          "licenses": [
241369            {
241370              "license": {
241371                "id": "MIT"
241372              }
241373            }
241374          ],
241375          "cpe": "cpe:2.3:a:content-disposition:content-disposition:0.5.3:*:*:*:*:*:*:*",
241376          "purl": "pkg:npm/content-disposition@0.5.3",
241377          "swid": {
241378            "attachment": {}
241379          },
241380          "pedigree": {},
241381          "externalReferences": [
241382            {
241383              "url": "jshttp/content-disposition",
241384              "type": "distribution"
241385            }
241386          ],
241387          "evidence": {},
241388          "signature": {
241389            "signature": {
241390              "publicKey": {}
241391            }
241392          },
241393          "modelCard": {
241394            "modelParameters": {
241395              "approach": {}
241396            },
241397            "quantitativeAnalysis": {
241398              "graphics": {}
241399            },
241400            "considerations": {}
241401          }
241402        },
241403        {
241404          "type": "library",
241405          "bom-ref": "pkg:npm/content-type@1.0.4?package-id=a628c8ecfea96934",
241406          "supplier": {},
241407          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
241408          "name": "content-type",
241409          "version": "1.0.4",
241410          "description": "Create and parse HTTP Content-Type header",
241411          "licenses": [
241412            {
241413              "license": {
241414                "id": "MIT"
241415              }
241416            }
241417          ],
241418          "cpe": "cpe:2.3:a:content-type:content-type:1.0.4:*:*:*:*:*:*:*",
241419          "purl": "pkg:npm/content-type@1.0.4",
241420          "swid": {
241421            "attachment": {}
241422          },
241423          "pedigree": {},
241424          "externalReferences": [
241425            {
241426              "url": "jshttp/content-type",
241427              "type": "distribution"
241428            }
241429          ],
241430          "evidence": {},
241431          "signature": {
241432            "signature": {
241433              "publicKey": {}
241434            }
241435          },
241436          "modelCard": {
241437            "modelParameters": {
241438              "approach": {}
241439            },
241440            "quantitativeAnalysis": {
241441              "graphics": {}
241442            },
241443            "considerations": {}
241444          }
241445        },
241446        {
241447          "type": "library",
241448          "bom-ref": "pkg:npm/cookie@0.4.0?package-id=db0f82a3b6498333",
241449          "supplier": {},
241450          "author": "Roman Shtylman \u003cshtylman@gmail.com\u003e",
241451          "name": "cookie",
241452          "version": "0.4.0",
241453          "description": "HTTP server cookie parsing and serialization",
241454          "licenses": [
241455            {
241456              "license": {
241457                "id": "MIT"
241458              }
241459            }
241460          ],
241461          "cpe": "cpe:2.3:a:cookie:cookie:0.4.0:*:*:*:*:*:*:*",
241462          "purl": "pkg:npm/cookie@0.4.0",
241463          "swid": {
241464            "attachment": {}
241465          },
241466          "pedigree": {},
241467          "externalReferences": [
241468            {
241469              "url": "jshttp/cookie",
241470              "type": "distribution"
241471            }
241472          ],
241473          "evidence": {},
241474          "signature": {
241475            "signature": {
241476              "publicKey": {}
241477            }
241478          },
241479          "modelCard": {
241480            "modelParameters": {
241481              "approach": {}
241482            },
241483            "quantitativeAnalysis": {
241484              "graphics": {}
241485            },
241486            "considerations": {}
241487          }
241488        },
241489        {
241490          "type": "library",
241491          "bom-ref": "pkg:npm/cookie-signature@1.0.6?package-id=5f31fb3f87889ab8",
241492          "supplier": {},
241493          "author": "TJ Holowaychuk \u003ctj@learnboost.com\u003e",
241494          "name": "cookie-signature",
241495          "version": "1.0.6",
241496          "description": "Sign and unsign cookies",
241497          "licenses": [
241498            {
241499              "license": {
241500                "id": "MIT"
241501              }
241502            }
241503          ],
241504          "cpe": "cpe:2.3:a:cookie-signature:cookie-signature:1.0.6:*:*:*:*:*:*:*",
241505          "purl": "pkg:npm/cookie-signature@1.0.6",
241506          "swid": {
241507            "attachment": {}
241508          },
241509          "pedigree": {},
241510          "externalReferences": [
241511            {
241512              "url": "https://github.com/visionmedia/node-cookie-signature.git",
241513              "type": "distribution"
241514            }
241515          ],
241516          "evidence": {},
241517          "signature": {
241518            "signature": {
241519              "publicKey": {}
241520            }
241521          },
241522          "modelCard": {
241523            "modelParameters": {
241524              "approach": {}
241525            },
241526            "quantitativeAnalysis": {
241527              "graphics": {}
241528            },
241529            "considerations": {}
241530          }
241531        },
241532        {
241533          "type": "library",
241534          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=c983dd40d7978937",
241535          "supplier": {},
241536          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
241537          "name": "core-util-is",
241538          "version": "1.0.2",
241539          "description": "The `util.is*` functions introduced in Node v0.12.",
241540          "licenses": [
241541            {
241542              "license": {
241543                "id": "MIT"
241544              }
241545            }
241546          ],
241547          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
241548          "purl": "pkg:npm/core-util-is@1.0.2",
241549          "swid": {
241550            "attachment": {}
241551          },
241552          "pedigree": {},
241553          "externalReferences": [
241554            {
241555              "url": "git://github.com/isaacs/core-util-is",
241556              "type": "distribution"
241557            }
241558          ],
241559          "evidence": {},
241560          "signature": {
241561            "signature": {
241562              "publicKey": {}
241563            }
241564          },
241565          "modelCard": {
241566            "modelParameters": {
241567              "approach": {}
241568            },
241569            "quantitativeAnalysis": {
241570              "graphics": {}
241571            },
241572            "considerations": {}
241573          }
241574        },
241575        {
241576          "type": "library",
241577          "bom-ref": "pkg:npm/core-util-is@1.0.3?package-id=dbb820a659873e98",
241578          "supplier": {},
241579          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
241580          "name": "core-util-is",
241581          "version": "1.0.3",
241582          "description": "The `util.is*` functions introduced in Node v0.12.",
241583          "licenses": [
241584            {
241585              "license": {
241586                "id": "MIT"
241587              }
241588            }
241589          ],
241590          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.3:*:*:*:*:*:*:*",
241591          "purl": "pkg:npm/core-util-is@1.0.3",
241592          "swid": {
241593            "attachment": {}
241594          },
241595          "pedigree": {},
241596          "externalReferences": [
241597            {
241598              "url": "git://github.com/isaacs/core-util-is",
241599              "type": "distribution"
241600            }
241601          ],
241602          "evidence": {},
241603          "signature": {
241604            "signature": {
241605              "publicKey": {}
241606            }
241607          },
241608          "modelCard": {
241609            "modelParameters": {
241610              "approach": {}
241611            },
241612            "quantitativeAnalysis": {
241613              "graphics": {}
241614            },
241615            "considerations": {}
241616          }
241617        },
241618        {
241619          "type": "library",
241620          "bom-ref": "pkg:npm/cors@2.8.5?package-id=b5af6190b535a540",
241621          "supplier": {},
241622          "author": "Troy Goode \u003ctroygoode@gmail.com\u003e (https://github.com/troygoode/)",
241623          "name": "cors",
241624          "version": "2.8.5",
241625          "description": "Node.js CORS middleware",
241626          "licenses": [
241627            {
241628              "license": {
241629                "id": "MIT"
241630              }
241631            }
241632          ],
241633          "cpe": "cpe:2.3:a:cors:cors:2.8.5:*:*:*:*:*:*:*",
241634          "purl": "pkg:npm/cors@2.8.5",
241635          "swid": {
241636            "attachment": {}
241637          },
241638          "pedigree": {},
241639          "externalReferences": [
241640            {
241641              "url": "expressjs/cors",
241642              "type": "distribution"
241643            }
241644          ],
241645          "evidence": {},
241646          "signature": {
241647            "signature": {
241648              "publicKey": {}
241649            }
241650          },
241651          "modelCard": {
241652            "modelParameters": {
241653              "approach": {}
241654            },
241655            "quantitativeAnalysis": {
241656              "graphics": {}
241657            },
241658            "considerations": {}
241659          }
241660        },
241661        {
241662          "type": "library",
241663          "bom-ref": "pkg:npm/dashdash@1.14.1?package-id=bfb8c12a112d1919",
241664          "supplier": {},
241665          "author": "Trent Mick \u003ctrentm@gmail.com\u003e (http://trentm.com)",
241666          "name": "dashdash",
241667          "version": "1.14.1",
241668          "description": "A light, featureful and explicit option parsing library.",
241669          "licenses": [
241670            {
241671              "license": {
241672                "id": "MIT"
241673              }
241674            }
241675          ],
241676          "cpe": "cpe:2.3:a:dashdash:dashdash:1.14.1:*:*:*:*:*:*:*",
241677          "purl": "pkg:npm/dashdash@1.14.1",
241678          "swid": {
241679            "attachment": {}
241680          },
241681          "pedigree": {},
241682          "externalReferences": [
241683            {
241684              "url": "git://github.com/trentm/node-dashdash.git",
241685              "type": "distribution"
241686            }
241687          ],
241688          "evidence": {},
241689          "signature": {
241690            "signature": {
241691              "publicKey": {}
241692            }
241693          },
241694          "modelCard": {
241695            "modelParameters": {
241696              "approach": {}
241697            },
241698            "quantitativeAnalysis": {
241699              "graphics": {}
241700            },
241701            "considerations": {}
241702          }
241703        },
241704        {
241705          "type": "library",
241706          "bom-ref": "pkg:npm/debug@2.6.9?package-id=3da4c2c2cbfbb047",
241707          "supplier": {},
241708          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
241709          "name": "debug",
241710          "version": "2.6.9",
241711          "description": "small debugging utility",
241712          "licenses": [
241713            {
241714              "license": {
241715                "id": "MIT"
241716              }
241717            }
241718          ],
241719          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
241720          "purl": "pkg:npm/debug@2.6.9",
241721          "swid": {
241722            "attachment": {}
241723          },
241724          "pedigree": {},
241725          "externalReferences": [
241726            {
241727              "url": "git://github.com/visionmedia/debug.git",
241728              "type": "distribution"
241729            }
241730          ],
241731          "evidence": {},
241732          "signature": {
241733            "signature": {
241734              "publicKey": {}
241735            }
241736          },
241737          "modelCard": {
241738            "modelParameters": {
241739              "approach": {}
241740            },
241741            "quantitativeAnalysis": {
241742              "graphics": {}
241743            },
241744            "considerations": {}
241745          }
241746        },
241747        {
241748          "type": "library",
241749          "bom-ref": "pkg:npm/debug@4.3.4?package-id=b12ad427500f6c64",
241750          "supplier": {},
241751          "author": "Josh Junon \u003cjosh.junon@protonmail.com\u003e",
241752          "name": "debug",
241753          "version": "4.3.4",
241754          "description": "Lightweight debugging utility for Node.js and the browser",
241755          "licenses": [
241756            {
241757              "license": {
241758                "id": "MIT"
241759              }
241760            }
241761          ],
241762          "cpe": "cpe:2.3:a:debug-js:debug:4.3.4:*:*:*:*:*:*:*",
241763          "purl": "pkg:npm/debug@4.3.4",
241764          "swid": {
241765            "attachment": {}
241766          },
241767          "pedigree": {},
241768          "externalReferences": [
241769            {
241770              "url": "git://github.com/debug-js/debug.git",
241771              "type": "distribution"
241772            }
241773          ],
241774          "evidence": {},
241775          "signature": {
241776            "signature": {
241777              "publicKey": {}
241778            }
241779          },
241780          "modelCard": {
241781            "modelParameters": {
241782              "approach": {}
241783            },
241784            "quantitativeAnalysis": {
241785              "graphics": {}
241786            },
241787            "considerations": {}
241788          }
241789        },
241790        {
241791          "type": "library",
241792          "bom-ref": "pkg:npm/delayed-stream@1.0.0?package-id=f797cfc3ebbb05a9",
241793          "supplier": {},
241794          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
241795          "name": "delayed-stream",
241796          "version": "1.0.0",
241797          "description": "Buffers events from a stream until you are ready to handle them.",
241798          "licenses": [
241799            {
241800              "license": {
241801                "id": "MIT"
241802              }
241803            }
241804          ],
241805          "cpe": "cpe:2.3:a:delayed-stream:delayed-stream:1.0.0:*:*:*:*:*:*:*",
241806          "purl": "pkg:npm/delayed-stream@1.0.0",
241807          "swid": {
241808            "attachment": {}
241809          },
241810          "pedigree": {},
241811          "externalReferences": [
241812            {
241813              "url": "git://github.com/felixge/node-delayed-stream.git",
241814              "type": "distribution"
241815            },
241816            {
241817              "url": "https://github.com/felixge/node-delayed-stream",
241818              "type": "website"
241819            }
241820          ],
241821          "evidence": {},
241822          "signature": {
241823            "signature": {
241824              "publicKey": {}
241825            }
241826          },
241827          "modelCard": {
241828            "modelParameters": {
241829              "approach": {}
241830            },
241831            "quantitativeAnalysis": {
241832              "graphics": {}
241833            },
241834            "considerations": {}
241835          }
241836        },
241837        {
241838          "type": "library",
241839          "bom-ref": "pkg:npm/depd@1.1.2?package-id=a2a20b51e5e43d41",
241840          "supplier": {},
241841          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
241842          "name": "depd",
241843          "version": "1.1.2",
241844          "description": "Deprecate all the things",
241845          "licenses": [
241846            {
241847              "license": {
241848                "id": "MIT"
241849              }
241850            }
241851          ],
241852          "cpe": "cpe:2.3:a:depd:depd:1.1.2:*:*:*:*:*:*:*",
241853          "purl": "pkg:npm/depd@1.1.2",
241854          "swid": {
241855            "attachment": {}
241856          },
241857          "pedigree": {},
241858          "externalReferences": [
241859            {
241860              "url": "dougwilson/nodejs-depd",
241861              "type": "distribution"
241862            }
241863          ],
241864          "evidence": {},
241865          "signature": {
241866            "signature": {
241867              "publicKey": {}
241868            }
241869          },
241870          "modelCard": {
241871            "modelParameters": {
241872              "approach": {}
241873            },
241874            "quantitativeAnalysis": {
241875              "graphics": {}
241876            },
241877            "considerations": {}
241878          }
241879        },
241880        {
241881          "type": "library",
241882          "bom-ref": "pkg:npm/destroy@1.0.4?package-id=a53fa70769e7c0c",
241883          "supplier": {},
241884          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
241885          "name": "destroy",
241886          "version": "1.0.4",
241887          "description": "destroy a stream if possible",
241888          "licenses": [
241889            {
241890              "license": {
241891                "id": "MIT"
241892              }
241893            }
241894          ],
241895          "cpe": "cpe:2.3:a:destroy:destroy:1.0.4:*:*:*:*:*:*:*",
241896          "purl": "pkg:npm/destroy@1.0.4",
241897          "swid": {
241898            "attachment": {}
241899          },
241900          "pedigree": {},
241901          "externalReferences": [
241902            {
241903              "url": "stream-utils/destroy",
241904              "type": "distribution"
241905            }
241906          ],
241907          "evidence": {},
241908          "signature": {
241909            "signature": {
241910              "publicKey": {}
241911            }
241912          },
241913          "modelCard": {
241914            "modelParameters": {
241915              "approach": {}
241916            },
241917            "quantitativeAnalysis": {
241918              "graphics": {}
241919            },
241920            "considerations": {}
241921          }
241922        },
241923        {
241924          "type": "library",
241925          "bom-ref": "pkg:npm/dicer@0.2.5?package-id=2d612385fedcdd75",
241926          "supplier": {},
241927          "author": "Brian White \u003cmscdex@mscdex.net\u003e",
241928          "name": "dicer",
241929          "version": "0.2.5",
241930          "description": "A very fast streaming multipart parser for node.js",
241931          "licenses": [
241932            {
241933              "license": {
241934                "id": "MIT"
241935              }
241936            }
241937          ],
241938          "cpe": "cpe:2.3:a:mscdex:dicer:0.2.5:*:*:*:*:*:*:*",
241939          "purl": "pkg:npm/dicer@0.2.5",
241940          "swid": {
241941            "attachment": {}
241942          },
241943          "pedigree": {},
241944          "externalReferences": [
241945            {
241946              "url": "http://github.com/mscdex/dicer.git",
241947              "type": "distribution"
241948            }
241949          ],
241950          "evidence": {},
241951          "signature": {
241952            "signature": {
241953              "publicKey": {}
241954            }
241955          },
241956          "modelCard": {
241957            "modelParameters": {
241958              "approach": {}
241959            },
241960            "quantitativeAnalysis": {
241961              "graphics": {}
241962            },
241963            "considerations": {}
241964          }
241965        },
241966        {
241967          "type": "library",
241968          "bom-ref": "pkg:npm/dotenv@16.0.2?package-id=37d1fe9c9157abb4",
241969          "supplier": {},
241970          "name": "dotenv",
241971          "version": "16.0.2",
241972          "description": "Loads environment variables from .env file",
241973          "licenses": [
241974            {
241975              "license": {
241976                "id": "BSD-2-Clause"
241977              }
241978            }
241979          ],
241980          "cpe": "cpe:2.3:a:motdotla:dotenv:16.0.2:*:*:*:*:*:*:*",
241981          "purl": "pkg:npm/dotenv@16.0.2",
241982          "swid": {
241983            "attachment": {}
241984          },
241985          "pedigree": {},
241986          "externalReferences": [
241987            {
241988              "url": "git://github.com/motdotla/dotenv.git",
241989              "type": "distribution"
241990            }
241991          ],
241992          "evidence": {},
241993          "signature": {
241994            "signature": {
241995              "publicKey": {}
241996            }
241997          },
241998          "modelCard": {
241999            "modelParameters": {
242000              "approach": {}
242001            },
242002            "quantitativeAnalysis": {
242003              "graphics": {}
242004            },
242005            "considerations": {}
242006          }
242007        },
242008        {
242009          "type": "library",
242010          "bom-ref": "pkg:npm/ecc-jsbn@0.1.2?package-id=ffebd35e64a63a04",
242011          "supplier": {},
242012          "author": "Jeremie Miller \u003cjeremie@jabber.org\u003e (http://jeremie.com/)",
242013          "name": "ecc-jsbn",
242014          "version": "0.1.2",
242015          "description": "ECC JS code based on JSBN",
242016          "licenses": [
242017            {
242018              "license": {
242019                "id": "MIT"
242020              }
242021            }
242022          ],
242023          "cpe": "cpe:2.3:a:quartzjer:ecc-jsbn:0.1.2:*:*:*:*:*:*:*",
242024          "purl": "pkg:npm/ecc-jsbn@0.1.2",
242025          "swid": {
242026            "attachment": {}
242027          },
242028          "pedigree": {},
242029          "externalReferences": [
242030            {
242031              "url": "https://github.com/quartzjer/ecc-jsbn.git",
242032              "type": "distribution"
242033            },
242034            {
242035              "url": "https://github.com/quartzjer/ecc-jsbn",
242036              "type": "website"
242037            }
242038          ],
242039          "evidence": {},
242040          "signature": {
242041            "signature": {
242042              "publicKey": {}
242043            }
242044          },
242045          "modelCard": {
242046            "modelParameters": {
242047              "approach": {}
242048            },
242049            "quantitativeAnalysis": {
242050              "graphics": {}
242051            },
242052            "considerations": {}
242053          }
242054        },
242055        {
242056          "type": "library",
242057          "bom-ref": "pkg:npm/ee-first@1.1.1?package-id=ecddedc37ff4e45a",
242058          "supplier": {},
242059          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
242060          "name": "ee-first",
242061          "version": "1.1.1",
242062          "description": "return the first event in a set of ee/event pairs",
242063          "licenses": [
242064            {
242065              "license": {
242066                "id": "MIT"
242067              }
242068            }
242069          ],
242070          "cpe": "cpe:2.3:a:ee-first:ee-first:1.1.1:*:*:*:*:*:*:*",
242071          "purl": "pkg:npm/ee-first@1.1.1",
242072          "swid": {
242073            "attachment": {}
242074          },
242075          "pedigree": {},
242076          "externalReferences": [
242077            {
242078              "url": "jonathanong/ee-first",
242079              "type": "distribution"
242080            }
242081          ],
242082          "evidence": {},
242083          "signature": {
242084            "signature": {
242085              "publicKey": {}
242086            }
242087          },
242088          "modelCard": {
242089            "modelParameters": {
242090              "approach": {}
242091            },
242092            "quantitativeAnalysis": {
242093              "graphics": {}
242094            },
242095            "considerations": {}
242096          }
242097        },
242098        {
242099          "type": "library",
242100          "bom-ref": "pkg:npm/encodeurl@1.0.2?package-id=4372fc523e1c5977",
242101          "supplier": {},
242102          "name": "encodeurl",
242103          "version": "1.0.2",
242104          "description": "Encode a URL to a percent-encoded form, excluding already-encoded sequences",
242105          "licenses": [
242106            {
242107              "license": {
242108                "id": "MIT"
242109              }
242110            }
242111          ],
242112          "cpe": "cpe:2.3:a:encodeurl:encodeurl:1.0.2:*:*:*:*:*:*:*",
242113          "purl": "pkg:npm/encodeurl@1.0.2",
242114          "swid": {
242115            "attachment": {}
242116          },
242117          "pedigree": {},
242118          "externalReferences": [
242119            {
242120              "url": "pillarjs/encodeurl",
242121              "type": "distribution"
242122            }
242123          ],
242124          "evidence": {},
242125          "signature": {
242126            "signature": {
242127              "publicKey": {}
242128            }
242129          },
242130          "modelCard": {
242131            "modelParameters": {
242132              "approach": {}
242133            },
242134            "quantitativeAnalysis": {
242135              "graphics": {}
242136            },
242137            "considerations": {}
242138          }
242139        },
242140        {
242141          "type": "library",
242142          "bom-ref": "pkg:npm/escape-html@1.0.3?package-id=f531ef9b02f6376",
242143          "supplier": {},
242144          "name": "escape-html",
242145          "version": "1.0.3",
242146          "description": "Escape string for use in HTML",
242147          "licenses": [
242148            {
242149              "license": {
242150                "id": "MIT"
242151              }
242152            }
242153          ],
242154          "cpe": "cpe:2.3:a:escape-html:escape-html:1.0.3:*:*:*:*:*:*:*",
242155          "purl": "pkg:npm/escape-html@1.0.3",
242156          "swid": {
242157            "attachment": {}
242158          },
242159          "pedigree": {},
242160          "externalReferences": [
242161            {
242162              "url": "component/escape-html",
242163              "type": "distribution"
242164            }
242165          ],
242166          "evidence": {},
242167          "signature": {
242168            "signature": {
242169              "publicKey": {}
242170            }
242171          },
242172          "modelCard": {
242173            "modelParameters": {
242174              "approach": {}
242175            },
242176            "quantitativeAnalysis": {
242177              "graphics": {}
242178            },
242179            "considerations": {}
242180          }
242181        },
242182        {
242183          "type": "library",
242184          "bom-ref": "pkg:npm/esprima@4.0.1?package-id=3c7a8491f8e708ec",
242185          "supplier": {},
242186          "author": "Ariya Hidayat \u003cariya.hidayat@gmail.com\u003e",
242187          "name": "esprima",
242188          "version": "4.0.1",
242189          "description": "ECMAScript parsing infrastructure for multipurpose analysis",
242190          "licenses": [
242191            {
242192              "license": {
242193                "id": "BSD-2-Clause"
242194              }
242195            }
242196          ],
242197          "cpe": "cpe:2.3:a:esprima:esprima:4.0.1:*:*:*:*:*:*:*",
242198          "purl": "pkg:npm/esprima@4.0.1",
242199          "swid": {
242200            "attachment": {}
242201          },
242202          "pedigree": {},
242203          "externalReferences": [
242204            {
242205              "url": "https://github.com/jquery/esprima.git",
242206              "type": "distribution"
242207            },
242208            {
242209              "url": "http://esprima.org",
242210              "type": "website"
242211            }
242212          ],
242213          "evidence": {},
242214          "signature": {
242215            "signature": {
242216              "publicKey": {}
242217            }
242218          },
242219          "modelCard": {
242220            "modelParameters": {
242221              "approach": {}
242222            },
242223            "quantitativeAnalysis": {
242224              "graphics": {}
242225            },
242226            "considerations": {}
242227          }
242228        },
242229        {
242230          "type": "library",
242231          "bom-ref": "pkg:npm/etag@1.8.1?package-id=ceaf0764c2d4213b",
242232          "supplier": {},
242233          "name": "etag",
242234          "version": "1.8.1",
242235          "description": "Create simple HTTP ETags",
242236          "licenses": [
242237            {
242238              "license": {
242239                "id": "MIT"
242240              }
242241            }
242242          ],
242243          "cpe": "cpe:2.3:a:etag:etag:1.8.1:*:*:*:*:*:*:*",
242244          "purl": "pkg:npm/etag@1.8.1",
242245          "swid": {
242246            "attachment": {}
242247          },
242248          "pedigree": {},
242249          "externalReferences": [
242250            {
242251              "url": "jshttp/etag",
242252              "type": "distribution"
242253            }
242254          ],
242255          "evidence": {},
242256          "signature": {
242257            "signature": {
242258              "publicKey": {}
242259            }
242260          },
242261          "modelCard": {
242262            "modelParameters": {
242263              "approach": {}
242264            },
242265            "quantitativeAnalysis": {
242266              "graphics": {}
242267            },
242268            "considerations": {}
242269          }
242270        },
242271        {
242272          "type": "library",
242273          "bom-ref": "pkg:npm/express@4.17.1?package-id=10b8669cbfa1e704",
242274          "supplier": {},
242275          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
242276          "name": "express",
242277          "version": "4.17.1",
242278          "description": "Fast, unopinionated, minimalist web framework",
242279          "licenses": [
242280            {
242281              "license": {
242282                "id": "MIT"
242283              }
242284            }
242285          ],
242286          "cpe": "cpe:2.3:a:express:express:4.17.1:*:*:*:*:*:*:*",
242287          "purl": "pkg:npm/express@4.17.1",
242288          "swid": {
242289            "attachment": {}
242290          },
242291          "pedigree": {},
242292          "externalReferences": [
242293            {
242294              "url": "expressjs/express",
242295              "type": "distribution"
242296            },
242297            {
242298              "url": "http://expressjs.com/",
242299              "type": "website"
242300            }
242301          ],
242302          "evidence": {},
242303          "signature": {
242304            "signature": {
242305              "publicKey": {}
242306            }
242307          },
242308          "modelCard": {
242309            "modelParameters": {
242310              "approach": {}
242311            },
242312            "quantitativeAnalysis": {
242313              "graphics": {}
242314            },
242315            "considerations": {}
242316          }
242317        },
242318        {
242319          "type": "library",
242320          "bom-ref": "pkg:npm/extend@3.0.2?package-id=7791e2e67d96bf70",
242321          "supplier": {},
242322          "author": "Stefan Thomas \u003cjustmoon@members.fsf.org\u003e (http://www.justmoon.net)",
242323          "name": "extend",
242324          "version": "3.0.2",
242325          "description": "Port of jQuery.extend for node.js and the browser",
242326          "licenses": [
242327            {
242328              "license": {
242329                "id": "MIT"
242330              }
242331            }
242332          ],
242333          "cpe": "cpe:2.3:a:justmoon:extend:3.0.2:*:*:*:*:*:*:*",
242334          "purl": "pkg:npm/extend@3.0.2",
242335          "swid": {
242336            "attachment": {}
242337          },
242338          "pedigree": {},
242339          "externalReferences": [
242340            {
242341              "url": "https://github.com/justmoon/node-extend.git",
242342              "type": "distribution"
242343            }
242344          ],
242345          "evidence": {},
242346          "signature": {
242347            "signature": {
242348              "publicKey": {}
242349            }
242350          },
242351          "modelCard": {
242352            "modelParameters": {
242353              "approach": {}
242354            },
242355            "quantitativeAnalysis": {
242356              "graphics": {}
242357            },
242358            "considerations": {}
242359          }
242360        },
242361        {
242362          "type": "library",
242363          "bom-ref": "pkg:npm/extsprintf@1.3.0?package-id=25826531f96c075b",
242364          "supplier": {},
242365          "name": "extsprintf",
242366          "version": "1.3.0",
242367          "description": "extended POSIX-style sprintf",
242368          "licenses": [
242369            {
242370              "license": {
242371                "id": "MIT"
242372              }
242373            }
242374          ],
242375          "cpe": "cpe:2.3:a:davepacheco:extsprintf:1.3.0:*:*:*:*:*:*:*",
242376          "purl": "pkg:npm/extsprintf@1.3.0",
242377          "swid": {
242378            "attachment": {}
242379          },
242380          "pedigree": {},
242381          "externalReferences": [
242382            {
242383              "url": "git://github.com/davepacheco/node-extsprintf.git",
242384              "type": "distribution"
242385            }
242386          ],
242387          "evidence": {},
242388          "signature": {
242389            "signature": {
242390              "publicKey": {}
242391            }
242392          },
242393          "modelCard": {
242394            "modelParameters": {
242395              "approach": {}
242396            },
242397            "quantitativeAnalysis": {
242398              "graphics": {}
242399            },
242400            "considerations": {}
242401          }
242402        },
242403        {
242404          "type": "library",
242405          "bom-ref": "pkg:npm/fast-deep-equal@3.1.3?package-id=50fc8df9c652bfea",
242406          "supplier": {},
242407          "author": "Evgeny Poberezkin",
242408          "name": "fast-deep-equal",
242409          "version": "3.1.3",
242410          "description": "Fast deep equal",
242411          "licenses": [
242412            {
242413              "license": {
242414                "id": "MIT"
242415              }
242416            }
242417          ],
242418          "cpe": "cpe:2.3:a:fast-deep-equal:fast-deep-equal:3.1.3:*:*:*:*:*:*:*",
242419          "purl": "pkg:npm/fast-deep-equal@3.1.3",
242420          "swid": {
242421            "attachment": {}
242422          },
242423          "pedigree": {},
242424          "externalReferences": [
242425            {
242426              "url": "git+https://github.com/epoberezkin/fast-deep-equal.git",
242427              "type": "distribution"
242428            },
242429            {
242430              "url": "https://github.com/epoberezkin/fast-deep-equal#readme",
242431              "type": "website"
242432            }
242433          ],
242434          "evidence": {},
242435          "signature": {
242436            "signature": {
242437              "publicKey": {}
242438            }
242439          },
242440          "modelCard": {
242441            "modelParameters": {
242442              "approach": {}
242443            },
242444            "quantitativeAnalysis": {
242445              "graphics": {}
242446            },
242447            "considerations": {}
242448          }
242449        },
242450        {
242451          "type": "library",
242452          "bom-ref": "pkg:npm/fast-json-stable-stringify@2.1.0?package-id=4c56416a0a0165fc",
242453          "supplier": {},
242454          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
242455          "name": "fast-json-stable-stringify",
242456          "version": "2.1.0",
242457          "description": "deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify",
242458          "licenses": [
242459            {
242460              "license": {
242461                "id": "MIT"
242462              }
242463            }
242464          ],
242465          "cpe": "cpe:2.3:a:fast-json-stable-stringify:fast-json-stable-stringify:2.1.0:*:*:*:*:*:*:*",
242466          "purl": "pkg:npm/fast-json-stable-stringify@2.1.0",
242467          "swid": {
242468            "attachment": {}
242469          },
242470          "pedigree": {},
242471          "externalReferences": [
242472            {
242473              "url": "git://github.com/epoberezkin/fast-json-stable-stringify.git",
242474              "type": "distribution"
242475            },
242476            {
242477              "url": "https://github.com/epoberezkin/fast-json-stable-stringify",
242478              "type": "website"
242479            }
242480          ],
242481          "evidence": {},
242482          "signature": {
242483            "signature": {
242484              "publicKey": {}
242485            }
242486          },
242487          "modelCard": {
242488            "modelParameters": {
242489              "approach": {}
242490            },
242491            "quantitativeAnalysis": {
242492              "graphics": {}
242493            },
242494            "considerations": {}
242495          }
242496        },
242497        {
242498          "type": "library",
242499          "bom-ref": "pkg:npm/fast-safe-stringify@2.0.7?package-id=c12cba20e0a81013",
242500          "supplier": {},
242501          "author": "David Mark Clements",
242502          "name": "fast-safe-stringify",
242503          "version": "2.0.7",
242504          "description": "Safely and quickly serialize JavaScript objects",
242505          "licenses": [
242506            {
242507              "license": {
242508                "id": "MIT"
242509              }
242510            }
242511          ],
242512          "cpe": "cpe:2.3:a:fast-safe-stringify:fast-safe-stringify:2.0.7:*:*:*:*:*:*:*",
242513          "purl": "pkg:npm/fast-safe-stringify@2.0.7",
242514          "swid": {
242515            "attachment": {}
242516          },
242517          "pedigree": {},
242518          "externalReferences": [
242519            {
242520              "url": "git+https://github.com/davidmarkclements/fast-safe-stringify.git",
242521              "type": "distribution"
242522            },
242523            {
242524              "url": "https://github.com/davidmarkclements/fast-safe-stringify#readme",
242525              "type": "website"
242526            }
242527          ],
242528          "evidence": {},
242529          "signature": {
242530            "signature": {
242531              "publicKey": {}
242532            }
242533          },
242534          "modelCard": {
242535            "modelParameters": {
242536              "approach": {}
242537            },
242538            "quantitativeAnalysis": {
242539              "graphics": {}
242540            },
242541            "considerations": {}
242542          }
242543        },
242544        {
242545          "type": "library",
242546          "bom-ref": "pkg:npm/fastify-plugin@3.0.1?package-id=8ce5710fd62dc089",
242547          "supplier": {},
242548          "author": "Tomas Della Vedova - @delvedor (http://delved.org)",
242549          "name": "fastify-plugin",
242550          "version": "3.0.1",
242551          "description": "Plugin helper for Fastify",
242552          "licenses": [
242553            {
242554              "license": {
242555                "id": "MIT"
242556              }
242557            }
242558          ],
242559          "cpe": "cpe:2.3:a:fastify-plugin:fastify-plugin:3.0.1:*:*:*:*:*:*:*",
242560          "purl": "pkg:npm/fastify-plugin@3.0.1",
242561          "swid": {
242562            "attachment": {}
242563          },
242564          "pedigree": {},
242565          "externalReferences": [
242566            {
242567              "url": "git+https://github.com/fastify/fastify-plugin.git",
242568              "type": "distribution"
242569            },
242570            {
242571              "url": "https://github.com/fastify/fastify-plugin#readme",
242572              "type": "website"
242573            }
242574          ],
242575          "evidence": {},
242576          "signature": {
242577            "signature": {
242578              "publicKey": {}
242579            }
242580          },
242581          "modelCard": {
242582            "modelParameters": {
242583              "approach": {}
242584            },
242585            "quantitativeAnalysis": {
242586              "graphics": {}
242587            },
242588            "considerations": {}
242589          }
242590        },
242591        {
242592          "type": "library",
242593          "bom-ref": "pkg:npm/fastify-static@3.4.0?package-id=7e49a469dea6cf1",
242594          "supplier": {},
242595          "author": "Tommaso Allevi - @allevo",
242596          "name": "fastify-static",
242597          "version": "3.4.0",
242598          "description": "Plugin for serving static files as fast as possible.",
242599          "licenses": [
242600            {
242601              "license": {
242602                "id": "MIT"
242603              }
242604            }
242605          ],
242606          "cpe": "cpe:2.3:a:fastify-static:fastify-static:3.4.0:*:*:*:*:*:*:*",
242607          "purl": "pkg:npm/fastify-static@3.4.0",
242608          "swid": {
242609            "attachment": {}
242610          },
242611          "pedigree": {},
242612          "externalReferences": [
242613            {
242614              "url": "https://github.com/fastify/fastify-static.git",
242615              "type": "distribution"
242616            },
242617            {
242618              "url": "https://github.com/fastify/fastify-static",
242619              "type": "website"
242620            }
242621          ],
242622          "evidence": {},
242623          "signature": {
242624            "signature": {
242625              "publicKey": {}
242626            }
242627          },
242628          "modelCard": {
242629            "modelParameters": {
242630              "approach": {}
242631            },
242632            "quantitativeAnalysis": {
242633              "graphics": {}
242634            },
242635            "considerations": {}
242636          }
242637        },
242638        {
242639          "type": "library",
242640          "bom-ref": "pkg:npm/fastify-swagger@3.5.0?package-id=36ac3481c48adce7",
242641          "supplier": {},
242642          "author": "Tomas Della Vedova - @delvedor (http://delved.org)",
242643          "name": "fastify-swagger",
242644          "version": "3.5.0",
242645          "description": "Generate Swagger files automatically for Fastify.",
242646          "licenses": [
242647            {
242648              "license": {
242649                "id": "MIT"
242650              }
242651            }
242652          ],
242653          "cpe": "cpe:2.3:a:fastify-swagger:fastify-swagger:3.5.0:*:*:*:*:*:*:*",
242654          "purl": "pkg:npm/fastify-swagger@3.5.0",
242655          "swid": {
242656            "attachment": {}
242657          },
242658          "pedigree": {},
242659          "externalReferences": [
242660            {
242661              "url": "git+https://github.com/fastify/fastify-swagger.git",
242662              "type": "distribution"
242663            },
242664            {
242665              "url": "https://github.com/fastify/fastify-swagger#readme",
242666              "type": "website"
242667            }
242668          ],
242669          "evidence": {},
242670          "signature": {
242671            "signature": {
242672              "publicKey": {}
242673            }
242674          },
242675          "modelCard": {
242676            "modelParameters": {
242677              "approach": {}
242678            },
242679            "quantitativeAnalysis": {
242680              "graphics": {}
242681            },
242682            "considerations": {}
242683          }
242684        },
242685        {
242686          "type": "library",
242687          "bom-ref": "pkg:npm/finalhandler@1.1.2?package-id=c5db4477c66cef3d",
242688          "supplier": {},
242689          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
242690          "name": "finalhandler",
242691          "version": "1.1.2",
242692          "description": "Node.js final http responder",
242693          "licenses": [
242694            {
242695              "license": {
242696                "id": "MIT"
242697              }
242698            }
242699          ],
242700          "cpe": "cpe:2.3:a:finalhandler:finalhandler:1.1.2:*:*:*:*:*:*:*",
242701          "purl": "pkg:npm/finalhandler@1.1.2",
242702          "swid": {
242703            "attachment": {}
242704          },
242705          "pedigree": {},
242706          "externalReferences": [
242707            {
242708              "url": "pillarjs/finalhandler",
242709              "type": "distribution"
242710            }
242711          ],
242712          "evidence": {},
242713          "signature": {
242714            "signature": {
242715              "publicKey": {}
242716            }
242717          },
242718          "modelCard": {
242719            "modelParameters": {
242720              "approach": {}
242721            },
242722            "quantitativeAnalysis": {
242723              "graphics": {}
242724            },
242725            "considerations": {}
242726          }
242727        },
242728        {
242729          "type": "library",
242730          "bom-ref": "pkg:npm/follow-redirects@1.15.2?package-id=f99b748737390e38",
242731          "supplier": {},
242732          "author": "Ruben Verborgh \u003cruben@verborgh.org\u003e (https://ruben.verborgh.org/)",
242733          "name": "follow-redirects",
242734          "version": "1.15.2",
242735          "description": "HTTP and HTTPS modules that follow redirects.",
242736          "licenses": [
242737            {
242738              "license": {
242739                "id": "MIT"
242740              }
242741            }
242742          ],
242743          "cpe": "cpe:2.3:a:follow-redirects:follow-redirects:1.15.2:*:*:*:*:*:*:*",
242744          "purl": "pkg:npm/follow-redirects@1.15.2",
242745          "swid": {
242746            "attachment": {}
242747          },
242748          "pedigree": {},
242749          "externalReferences": [
242750            {
242751              "url": "git@github.com:follow-redirects/follow-redirects.git",
242752              "type": "distribution"
242753            },
242754            {
242755              "url": "https://github.com/follow-redirects/follow-redirects",
242756              "type": "website"
242757            }
242758          ],
242759          "evidence": {},
242760          "signature": {
242761            "signature": {
242762              "publicKey": {}
242763            }
242764          },
242765          "modelCard": {
242766            "modelParameters": {
242767              "approach": {}
242768            },
242769            "quantitativeAnalysis": {
242770              "graphics": {}
242771            },
242772            "considerations": {}
242773          }
242774        },
242775        {
242776          "type": "library",
242777          "bom-ref": "pkg:npm/forever-agent@0.6.1?package-id=c25138b8f27cb6de",
242778          "supplier": {},
242779          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
242780          "name": "forever-agent",
242781          "version": "0.6.1",
242782          "description": "HTTP Agent that keeps socket connections alive between keep-alive requests. Formerly part of mikeal/request, now a standalone module.",
242783          "licenses": [
242784            {
242785              "license": {
242786                "id": "Apache-2.0"
242787              }
242788            }
242789          ],
242790          "cpe": "cpe:2.3:a:forever-agent:forever-agent:0.6.1:*:*:*:*:*:*:*",
242791          "purl": "pkg:npm/forever-agent@0.6.1",
242792          "swid": {
242793            "attachment": {}
242794          },
242795          "pedigree": {},
242796          "externalReferences": [
242797            {
242798              "url": "https://github.com/mikeal/forever-agent",
242799              "type": "distribution"
242800            }
242801          ],
242802          "evidence": {},
242803          "signature": {
242804            "signature": {
242805              "publicKey": {}
242806            }
242807          },
242808          "modelCard": {
242809            "modelParameters": {
242810              "approach": {}
242811            },
242812            "quantitativeAnalysis": {
242813              "graphics": {}
242814            },
242815            "considerations": {}
242816          }
242817        },
242818        {
242819          "type": "library",
242820          "bom-ref": "pkg:npm/form-data@2.3.3?package-id=a4db7a65123703d7",
242821          "supplier": {},
242822          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
242823          "name": "form-data",
242824          "version": "2.3.3",
242825          "description": "A library to create readable \"multipart/form-data\" streams. Can be used to submit forms and file uploads to other web applications.",
242826          "licenses": [
242827            {
242828              "license": {
242829                "id": "MIT"
242830              }
242831            }
242832          ],
242833          "cpe": "cpe:2.3:a:form-data:form-data:2.3.3:*:*:*:*:*:*:*",
242834          "purl": "pkg:npm/form-data@2.3.3",
242835          "swid": {
242836            "attachment": {}
242837          },
242838          "pedigree": {},
242839          "externalReferences": [
242840            {
242841              "url": "git://github.com/form-data/form-data.git",
242842              "type": "distribution"
242843            }
242844          ],
242845          "evidence": {},
242846          "signature": {
242847            "signature": {
242848              "publicKey": {}
242849            }
242850          },
242851          "modelCard": {
242852            "modelParameters": {
242853              "approach": {}
242854            },
242855            "quantitativeAnalysis": {
242856              "graphics": {}
242857            },
242858            "considerations": {}
242859          }
242860        },
242861        {
242862          "type": "library",
242863          "bom-ref": "pkg:npm/forwarded@0.2.0?package-id=ad40eb2bb2cdc901",
242864          "supplier": {},
242865          "name": "forwarded",
242866          "version": "0.2.0",
242867          "description": "Parse HTTP X-Forwarded-For header",
242868          "licenses": [
242869            {
242870              "license": {
242871                "id": "MIT"
242872              }
242873            }
242874          ],
242875          "cpe": "cpe:2.3:a:forwarded:forwarded:0.2.0:*:*:*:*:*:*:*",
242876          "purl": "pkg:npm/forwarded@0.2.0",
242877          "swid": {
242878            "attachment": {}
242879          },
242880          "pedigree": {},
242881          "externalReferences": [
242882            {
242883              "url": "jshttp/forwarded",
242884              "type": "distribution"
242885            }
242886          ],
242887          "evidence": {},
242888          "signature": {
242889            "signature": {
242890              "publicKey": {}
242891            }
242892          },
242893          "modelCard": {
242894            "modelParameters": {
242895              "approach": {}
242896            },
242897            "quantitativeAnalysis": {
242898              "graphics": {}
242899            },
242900            "considerations": {}
242901          }
242902        },
242903        {
242904          "type": "library",
242905          "bom-ref": "pkg:npm/fresh@0.5.2?package-id=611b251fb71eb02",
242906          "supplier": {},
242907          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
242908          "name": "fresh",
242909          "version": "0.5.2",
242910          "description": "HTTP response freshness testing",
242911          "licenses": [
242912            {
242913              "license": {
242914                "id": "MIT"
242915              }
242916            }
242917          ],
242918          "cpe": "cpe:2.3:a:fresh:fresh:0.5.2:*:*:*:*:*:*:*",
242919          "purl": "pkg:npm/fresh@0.5.2",
242920          "swid": {
242921            "attachment": {}
242922          },
242923          "pedigree": {},
242924          "externalReferences": [
242925            {
242926              "url": "jshttp/fresh",
242927              "type": "distribution"
242928            }
242929          ],
242930          "evidence": {},
242931          "signature": {
242932            "signature": {
242933              "publicKey": {}
242934            }
242935          },
242936          "modelCard": {
242937            "modelParameters": {
242938              "approach": {}
242939            },
242940            "quantitativeAnalysis": {
242941              "graphics": {}
242942            },
242943            "considerations": {}
242944          }
242945        },
242946        {
242947          "type": "library",
242948          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=e3859c9f856fd75c",
242949          "supplier": {},
242950          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
242951          "name": "fs.realpath",
242952          "version": "1.0.0",
242953          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
242954          "licenses": [
242955            {
242956              "license": {
242957                "id": "ISC"
242958              }
242959            }
242960          ],
242961          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
242962          "purl": "pkg:npm/fs.realpath@1.0.0",
242963          "swid": {
242964            "attachment": {}
242965          },
242966          "pedigree": {},
242967          "externalReferences": [
242968            {
242969              "url": "git+https://github.com/isaacs/fs.realpath.git",
242970              "type": "distribution"
242971            }
242972          ],
242973          "evidence": {},
242974          "signature": {
242975            "signature": {
242976              "publicKey": {}
242977            }
242978          },
242979          "modelCard": {
242980            "modelParameters": {
242981              "approach": {}
242982            },
242983            "quantitativeAnalysis": {
242984              "graphics": {}
242985            },
242986            "considerations": {}
242987          }
242988        },
242989        {
242990          "type": "library",
242991          "bom-ref": "pkg:npm/getpass@0.1.7?package-id=15b9f67c553ff142",
242992          "supplier": {},
242993          "author": "Alex Wilson \u003calex.wilson@joyent.com\u003e",
242994          "name": "getpass",
242995          "version": "0.1.7",
242996          "description": "getpass for node.js",
242997          "licenses": [
242998            {
242999              "license": {
243000                "id": "MIT"
243001              }
243002            }
243003          ],
243004          "cpe": "cpe:2.3:a:arekinath:getpass:0.1.7:*:*:*:*:*:*:*",
243005          "purl": "pkg:npm/getpass@0.1.7",
243006          "swid": {
243007            "attachment": {}
243008          },
243009          "pedigree": {},
243010          "externalReferences": [
243011            {
243012              "url": "https://github.com/arekinath/node-getpass.git",
243013              "type": "distribution"
243014            }
243015          ],
243016          "evidence": {},
243017          "signature": {
243018            "signature": {
243019              "publicKey": {}
243020            }
243021          },
243022          "modelCard": {
243023            "modelParameters": {
243024              "approach": {}
243025            },
243026            "quantitativeAnalysis": {
243027              "graphics": {}
243028            },
243029            "considerations": {}
243030          }
243031        },
243032        {
243033          "type": "library",
243034          "bom-ref": "pkg:npm/glob@7.2.3?package-id=50a57845f8268bd9",
243035          "supplier": {},
243036          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
243037          "name": "glob",
243038          "version": "7.2.3",
243039          "description": "a little globber",
243040          "licenses": [
243041            {
243042              "license": {
243043                "id": "ISC"
243044              }
243045            }
243046          ],
243047          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
243048          "purl": "pkg:npm/glob@7.2.3",
243049          "swid": {
243050            "attachment": {}
243051          },
243052          "pedigree": {},
243053          "externalReferences": [
243054            {
243055              "url": "git://github.com/isaacs/node-glob.git",
243056              "type": "distribution"
243057            }
243058          ],
243059          "evidence": {},
243060          "signature": {
243061            "signature": {
243062              "publicKey": {}
243063            }
243064          },
243065          "modelCard": {
243066            "modelParameters": {
243067              "approach": {}
243068            },
243069            "quantitativeAnalysis": {
243070              "graphics": {}
243071            },
243072            "considerations": {}
243073          }
243074        },
243075        {
243076          "type": "library",
243077          "bom-ref": "pkg:npm/google-libphonenumber@3.2.31?package-id=d2704c6162061356",
243078          "supplier": {},
243079          "author": "Rui Marinho \u003cruipmarinho@gmail.com\u003e",
243080          "name": "google-libphonenumber",
243081          "version": "3.2.31",
243082          "description": "The up-to-date and reliable Google's libphonenumber package for node.js.",
243083          "licenses": [
243084            {
243085              "license": {
243086                "name": "(MIT AND Apache-2.0)"
243087              }
243088            }
243089          ],
243090          "cpe": "cpe:2.3:a:google-libphonenumber:google-libphonenumber:3.2.31:*:*:*:*:*:*:*",
243091          "purl": "pkg:npm/google-libphonenumber@3.2.31",
243092          "swid": {
243093            "attachment": {}
243094          },
243095          "pedigree": {},
243096          "externalReferences": [
243097            {
243098              "url": "https://github.com/ruimarinho/google-libphonenumber.git",
243099              "type": "distribution"
243100            },
243101            {
243102              "url": "https://ruimarinho.github.io/google-libphonenumber/",
243103              "type": "website"
243104            }
243105          ],
243106          "evidence": {},
243107          "signature": {
243108            "signature": {
243109              "publicKey": {}
243110            }
243111          },
243112          "modelCard": {
243113            "modelParameters": {
243114              "approach": {}
243115            },
243116            "quantitativeAnalysis": {
243117              "graphics": {}
243118            },
243119            "considerations": {}
243120          }
243121        },
243122        {
243123          "type": "library",
243124          "bom-ref": "pkg:npm/har-schema@2.0.0?package-id=5f7076af7b8ab3b6",
243125          "supplier": {},
243126          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
243127          "name": "har-schema",
243128          "version": "2.0.0",
243129          "description": "JSON Schema for HTTP Archive (HAR)",
243130          "licenses": [
243131            {
243132              "license": {
243133                "id": "ISC"
243134              }
243135            }
243136          ],
243137          "cpe": "cpe:2.3:a:ahmadnassri:har-schema:2.0.0:*:*:*:*:*:*:*",
243138          "purl": "pkg:npm/har-schema@2.0.0",
243139          "swid": {
243140            "attachment": {}
243141          },
243142          "pedigree": {},
243143          "externalReferences": [
243144            {
243145              "url": "https://github.com/ahmadnassri/har-schema.git",
243146              "type": "distribution"
243147            },
243148            {
243149              "url": "https://github.com/ahmadnassri/har-schema",
243150              "type": "website"
243151            }
243152          ],
243153          "evidence": {},
243154          "signature": {
243155            "signature": {
243156              "publicKey": {}
243157            }
243158          },
243159          "modelCard": {
243160            "modelParameters": {
243161              "approach": {}
243162            },
243163            "quantitativeAnalysis": {
243164              "graphics": {}
243165            },
243166            "considerations": {}
243167          }
243168        },
243169        {
243170          "type": "library",
243171          "bom-ref": "pkg:npm/har-validator@5.1.5?package-id=e50dc896c187031b",
243172          "supplier": {},
243173          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
243174          "name": "har-validator",
243175          "version": "5.1.5",
243176          "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
243177          "licenses": [
243178            {
243179              "license": {
243180                "id": "MIT"
243181              }
243182            }
243183          ],
243184          "cpe": "cpe:2.3:a:har-validator:har-validator:5.1.5:*:*:*:*:*:*:*",
243185          "purl": "pkg:npm/har-validator@5.1.5",
243186          "swid": {
243187            "attachment": {}
243188          },
243189          "pedigree": {},
243190          "externalReferences": [
243191            {
243192              "url": "https://github.com/ahmadnassri/node-har-validator.git",
243193              "type": "distribution"
243194            },
243195            {
243196              "url": "https://github.com/ahmadnassri/node-har-validator",
243197              "type": "website"
243198            }
243199          ],
243200          "evidence": {},
243201          "signature": {
243202            "signature": {
243203              "publicKey": {}
243204            }
243205          },
243206          "modelCard": {
243207            "modelParameters": {
243208              "approach": {}
243209            },
243210            "quantitativeAnalysis": {
243211              "graphics": {}
243212            },
243213            "considerations": {}
243214          }
243215        },
243216        {
243217          "type": "library",
243218          "bom-ref": "pkg:npm/has-flag@4.0.0?package-id=f69253adfef44160",
243219          "supplier": {},
243220          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
243221          "name": "has-flag",
243222          "version": "4.0.0",
243223          "description": "Check if argv has a specific flag",
243224          "licenses": [
243225            {
243226              "license": {
243227                "id": "MIT"
243228              }
243229            }
243230          ],
243231          "cpe": "cpe:2.3:a:has-flag:has-flag:4.0.0:*:*:*:*:*:*:*",
243232          "purl": "pkg:npm/has-flag@4.0.0",
243233          "swid": {
243234            "attachment": {}
243235          },
243236          "pedigree": {},
243237          "externalReferences": [
243238            {
243239              "url": "sindresorhus/has-flag",
243240              "type": "distribution"
243241            }
243242          ],
243243          "evidence": {},
243244          "signature": {
243245            "signature": {
243246              "publicKey": {}
243247            }
243248          },
243249          "modelCard": {
243250            "modelParameters": {
243251              "approach": {}
243252            },
243253            "quantitativeAnalysis": {
243254              "graphics": {}
243255            },
243256            "considerations": {}
243257          }
243258        },
243259        {
243260          "type": "library",
243261          "bom-ref": "pkg:npm/http-errors@1.7.2?package-id=4c85a4da72f2dbad",
243262          "supplier": {},
243263          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
243264          "name": "http-errors",
243265          "version": "1.7.2",
243266          "description": "Create HTTP error objects",
243267          "licenses": [
243268            {
243269              "license": {
243270                "id": "MIT"
243271              }
243272            }
243273          ],
243274          "cpe": "cpe:2.3:a:http-errors:http-errors:1.7.2:*:*:*:*:*:*:*",
243275          "purl": "pkg:npm/http-errors@1.7.2",
243276          "swid": {
243277            "attachment": {}
243278          },
243279          "pedigree": {},
243280          "externalReferences": [
243281            {
243282              "url": "jshttp/http-errors",
243283              "type": "distribution"
243284            }
243285          ],
243286          "evidence": {},
243287          "signature": {
243288            "signature": {
243289              "publicKey": {}
243290            }
243291          },
243292          "modelCard": {
243293            "modelParameters": {
243294              "approach": {}
243295            },
243296            "quantitativeAnalysis": {
243297              "graphics": {}
243298            },
243299            "considerations": {}
243300          }
243301        },
243302        {
243303          "type": "library",
243304          "bom-ref": "pkg:npm/http-signature@1.2.0?package-id=9a991d3938b7d038",
243305          "supplier": {},
243306          "author": "Joyent, Inc",
243307          "name": "http-signature",
243308          "version": "1.2.0",
243309          "description": "Reference implementation of Joyent's HTTP Signature scheme.",
243310          "licenses": [
243311            {
243312              "license": {
243313                "id": "MIT"
243314              }
243315            }
243316          ],
243317          "cpe": "cpe:2.3:a:http-signature:http-signature:1.2.0:*:*:*:*:*:*:*",
243318          "purl": "pkg:npm/http-signature@1.2.0",
243319          "swid": {
243320            "attachment": {}
243321          },
243322          "pedigree": {},
243323          "externalReferences": [
243324            {
243325              "url": "git://github.com/joyent/node-http-signature.git",
243326              "type": "distribution"
243327            },
243328            {
243329              "url": "https://github.com/joyent/node-http-signature/",
243330              "type": "website"
243331            }
243332          ],
243333          "evidence": {},
243334          "signature": {
243335            "signature": {
243336              "publicKey": {}
243337            }
243338          },
243339          "modelCard": {
243340            "modelParameters": {
243341              "approach": {}
243342            },
243343            "quantitativeAnalysis": {
243344              "graphics": {}
243345            },
243346            "considerations": {}
243347          }
243348        },
243349        {
243350          "type": "library",
243351          "bom-ref": "pkg:npm/iconv-lite@0.4.24?package-id=5b9a586d4ff6589f",
243352          "supplier": {},
243353          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
243354          "name": "iconv-lite",
243355          "version": "0.4.24",
243356          "description": "Convert character encodings in pure javascript.",
243357          "licenses": [
243358            {
243359              "license": {
243360                "id": "MIT"
243361              }
243362            }
243363          ],
243364          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.4.24:*:*:*:*:*:*:*",
243365          "purl": "pkg:npm/iconv-lite@0.4.24",
243366          "swid": {
243367            "attachment": {}
243368          },
243369          "pedigree": {},
243370          "externalReferences": [
243371            {
243372              "url": "git://github.com/ashtuchkin/iconv-lite.git",
243373              "type": "distribution"
243374            },
243375            {
243376              "url": "https://github.com/ashtuchkin/iconv-lite",
243377              "type": "website"
243378            }
243379          ],
243380          "evidence": {},
243381          "signature": {
243382            "signature": {
243383              "publicKey": {}
243384            }
243385          },
243386          "modelCard": {
243387            "modelParameters": {
243388              "approach": {}
243389            },
243390            "quantitativeAnalysis": {
243391              "graphics": {}
243392            },
243393            "considerations": {}
243394          }
243395        },
243396        {
243397          "type": "library",
243398          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=30c024273863343f",
243399          "supplier": {},
243400          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
243401          "name": "inflight",
243402          "version": "1.0.6",
243403          "description": "Add callbacks to requests in flight to avoid async duplication",
243404          "licenses": [
243405            {
243406              "license": {
243407                "id": "ISC"
243408              }
243409            }
243410          ],
243411          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
243412          "purl": "pkg:npm/inflight@1.0.6",
243413          "swid": {
243414            "attachment": {}
243415          },
243416          "pedigree": {},
243417          "externalReferences": [
243418            {
243419              "url": "https://github.com/npm/inflight.git",
243420              "type": "distribution"
243421            },
243422            {
243423              "url": "https://github.com/isaacs/inflight",
243424              "type": "website"
243425            }
243426          ],
243427          "evidence": {},
243428          "signature": {
243429            "signature": {
243430              "publicKey": {}
243431            }
243432          },
243433          "modelCard": {
243434            "modelParameters": {
243435              "approach": {}
243436            },
243437            "quantitativeAnalysis": {
243438              "graphics": {}
243439            },
243440            "considerations": {}
243441          }
243442        },
243443        {
243444          "type": "library",
243445          "bom-ref": "pkg:npm/inherits@2.0.3?package-id=8f61c802178ab66a",
243446          "supplier": {},
243447          "name": "inherits",
243448          "version": "2.0.3",
243449          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
243450          "licenses": [
243451            {
243452              "license": {
243453                "id": "ISC"
243454              }
243455            }
243456          ],
243457          "cpe": "cpe:2.3:a:inherits:inherits:2.0.3:*:*:*:*:*:*:*",
243458          "purl": "pkg:npm/inherits@2.0.3",
243459          "swid": {
243460            "attachment": {}
243461          },
243462          "pedigree": {},
243463          "externalReferences": [
243464            {
243465              "url": "git://github.com/isaacs/inherits",
243466              "type": "distribution"
243467            }
243468          ],
243469          "evidence": {},
243470          "signature": {
243471            "signature": {
243472              "publicKey": {}
243473            }
243474          },
243475          "modelCard": {
243476            "modelParameters": {
243477              "approach": {}
243478            },
243479            "quantitativeAnalysis": {
243480              "graphics": {}
243481            },
243482            "considerations": {}
243483          }
243484        },
243485        {
243486          "type": "library",
243487          "bom-ref": "pkg:npm/ipaddr.js@1.9.1?package-id=a33cb559fc812015",
243488          "supplier": {},
243489          "author": "whitequark \u003cwhitequark@whitequark.org\u003e",
243490          "name": "ipaddr.js",
243491          "version": "1.9.1",
243492          "description": "A library for manipulating IPv4 and IPv6 addresses in JavaScript.",
243493          "licenses": [
243494            {
243495              "license": {
243496                "id": "MIT"
243497              }
243498            }
243499          ],
243500          "cpe": "cpe:2.3:a:whitequark:ipaddr.js:1.9.1:*:*:*:*:*:*:*",
243501          "purl": "pkg:npm/ipaddr.js@1.9.1",
243502          "swid": {
243503            "attachment": {}
243504          },
243505          "pedigree": {},
243506          "externalReferences": [
243507            {
243508              "url": "git://github.com/whitequark/ipaddr.js",
243509              "type": "distribution"
243510            }
243511          ],
243512          "evidence": {},
243513          "signature": {
243514            "signature": {
243515              "publicKey": {}
243516            }
243517          },
243518          "modelCard": {
243519            "modelParameters": {
243520              "approach": {}
243521            },
243522            "quantitativeAnalysis": {
243523              "graphics": {}
243524            },
243525            "considerations": {}
243526          }
243527        },
243528        {
243529          "type": "library",
243530          "bom-ref": "pkg:npm/is-typedarray@1.0.0?package-id=e719ed77b7d38e33",
243531          "supplier": {},
243532          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
243533          "name": "is-typedarray",
243534          "version": "1.0.0",
243535          "description": "Detect whether or not an object is a Typed Array",
243536          "licenses": [
243537            {
243538              "license": {
243539                "id": "MIT"
243540              }
243541            }
243542          ],
243543          "cpe": "cpe:2.3:a:is-typedarray:is-typedarray:1.0.0:*:*:*:*:*:*:*",
243544          "purl": "pkg:npm/is-typedarray@1.0.0",
243545          "swid": {
243546            "attachment": {}
243547          },
243548          "pedigree": {},
243549          "externalReferences": [
243550            {
243551              "url": "git://github.com/hughsk/is-typedarray.git",
243552              "type": "distribution"
243553            },
243554            {
243555              "url": "https://github.com/hughsk/is-typedarray",
243556              "type": "website"
243557            }
243558          ],
243559          "evidence": {},
243560          "signature": {
243561            "signature": {
243562              "publicKey": {}
243563            }
243564          },
243565          "modelCard": {
243566            "modelParameters": {
243567              "approach": {}
243568            },
243569            "quantitativeAnalysis": {
243570              "graphics": {}
243571            },
243572            "considerations": {}
243573          }
243574        },
243575        {
243576          "type": "library",
243577          "bom-ref": "pkg:npm/isarray@0.0.1?package-id=4eab13fd6138583f",
243578          "supplier": {},
243579          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
243580          "name": "isarray",
243581          "version": "0.0.1",
243582          "description": "Array#isArray for older browsers",
243583          "licenses": [
243584            {
243585              "license": {
243586                "id": "MIT"
243587              }
243588            }
243589          ],
243590          "cpe": "cpe:2.3:a:juliangruber:isarray:0.0.1:*:*:*:*:*:*:*",
243591          "purl": "pkg:npm/isarray@0.0.1",
243592          "swid": {
243593            "attachment": {}
243594          },
243595          "pedigree": {},
243596          "externalReferences": [
243597            {
243598              "url": "git://github.com/juliangruber/isarray.git",
243599              "type": "distribution"
243600            },
243601            {
243602              "url": "https://github.com/juliangruber/isarray",
243603              "type": "website"
243604            }
243605          ],
243606          "evidence": {},
243607          "signature": {
243608            "signature": {
243609              "publicKey": {}
243610            }
243611          },
243612          "modelCard": {
243613            "modelParameters": {
243614              "approach": {}
243615            },
243616            "quantitativeAnalysis": {
243617              "graphics": {}
243618            },
243619            "considerations": {}
243620          }
243621        },
243622        {
243623          "type": "library",
243624          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=67e7a38d852b614a",
243625          "supplier": {},
243626          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
243627          "name": "isarray",
243628          "version": "1.0.0",
243629          "description": "Array#isArray for older browsers",
243630          "licenses": [
243631            {
243632              "license": {
243633                "id": "MIT"
243634              }
243635            }
243636          ],
243637          "cpe": "cpe:2.3:a:juliangruber:isarray:1.0.0:*:*:*:*:*:*:*",
243638          "purl": "pkg:npm/isarray@1.0.0",
243639          "swid": {
243640            "attachment": {}
243641          },
243642          "pedigree": {},
243643          "externalReferences": [
243644            {
243645              "url": "git://github.com/juliangruber/isarray.git",
243646              "type": "distribution"
243647            },
243648            {
243649              "url": "https://github.com/juliangruber/isarray",
243650              "type": "website"
243651            }
243652          ],
243653          "evidence": {},
243654          "signature": {
243655            "signature": {
243656              "publicKey": {}
243657            }
243658          },
243659          "modelCard": {
243660            "modelParameters": {
243661              "approach": {}
243662            },
243663            "quantitativeAnalysis": {
243664              "graphics": {}
243665            },
243666            "considerations": {}
243667          }
243668        },
243669        {
243670          "type": "library",
243671          "bom-ref": "pkg:npm/isstream@0.1.2?package-id=1796db715939d54d",
243672          "supplier": {},
243673          "author": "Rod Vagg \u003crod@vagg.org\u003e",
243674          "name": "isstream",
243675          "version": "0.1.2",
243676          "description": "Determine if an object is a Stream",
243677          "licenses": [
243678            {
243679              "license": {
243680                "id": "MIT"
243681              }
243682            }
243683          ],
243684          "cpe": "cpe:2.3:a:isstream:isstream:0.1.2:*:*:*:*:*:*:*",
243685          "purl": "pkg:npm/isstream@0.1.2",
243686          "swid": {
243687            "attachment": {}
243688          },
243689          "pedigree": {},
243690          "externalReferences": [
243691            {
243692              "url": "https://github.com/rvagg/isstream.git",
243693              "type": "distribution"
243694            },
243695            {
243696              "url": "https://github.com/rvagg/isstream",
243697              "type": "website"
243698            }
243699          ],
243700          "evidence": {},
243701          "signature": {
243702            "signature": {
243703              "publicKey": {}
243704            }
243705          },
243706          "modelCard": {
243707            "modelParameters": {
243708              "approach": {}
243709            },
243710            "quantitativeAnalysis": {
243711              "graphics": {}
243712            },
243713            "considerations": {}
243714          }
243715        },
243716        {
243717          "type": "library",
243718          "bom-ref": "pkg:npm/iterare@1.2.1?package-id=45a8c745e9393653",
243719          "supplier": {},
243720          "author": "Felix Becker \u003cfelix.b@outlook.com\u003e",
243721          "name": "iterare",
243722          "version": "1.2.1",
243723          "description": "Array methods for ES6 Iterators",
243724          "licenses": [
243725            {
243726              "license": {
243727                "id": "ISC"
243728              }
243729            }
243730          ],
243731          "cpe": "cpe:2.3:a:felixfbecker:iterare:1.2.1:*:*:*:*:*:*:*",
243732          "purl": "pkg:npm/iterare@1.2.1",
243733          "swid": {
243734            "attachment": {}
243735          },
243736          "pedigree": {},
243737          "externalReferences": [
243738            {
243739              "url": "https://github.com/felixfbecker/iterare",
243740              "type": "distribution"
243741            }
243742          ],
243743          "evidence": {},
243744          "signature": {
243745            "signature": {
243746              "publicKey": {}
243747            }
243748          },
243749          "modelCard": {
243750            "modelParameters": {
243751              "approach": {}
243752            },
243753            "quantitativeAnalysis": {
243754              "graphics": {}
243755            },
243756            "considerations": {}
243757          }
243758        },
243759        {
243760          "type": "library",
243761          "bom-ref": "pkg:npm/js-yaml@3.14.1?package-id=936abc8eee132e4",
243762          "supplier": {},
243763          "author": "Vladimir Zapparov \u003cdervus.grim@gmail.com\u003e",
243764          "name": "js-yaml",
243765          "version": "3.14.1",
243766          "description": "YAML 1.2 parser and serializer",
243767          "licenses": [
243768            {
243769              "license": {
243770                "id": "MIT"
243771              }
243772            }
243773          ],
243774          "cpe": "cpe:2.3:a:js-yaml:js-yaml:3.14.1:*:*:*:*:*:*:*",
243775          "purl": "pkg:npm/js-yaml@3.14.1",
243776          "swid": {
243777            "attachment": {}
243778          },
243779          "pedigree": {},
243780          "externalReferences": [
243781            {
243782              "url": "nodeca/js-yaml",
243783              "type": "distribution"
243784            },
243785            {
243786              "url": "https://github.com/nodeca/js-yaml",
243787              "type": "website"
243788            }
243789          ],
243790          "evidence": {},
243791          "signature": {
243792            "signature": {
243793              "publicKey": {}
243794            }
243795          },
243796          "modelCard": {
243797            "modelParameters": {
243798              "approach": {}
243799            },
243800            "quantitativeAnalysis": {
243801              "graphics": {}
243802            },
243803            "considerations": {}
243804          }
243805        },
243806        {
243807          "type": "library",
243808          "bom-ref": "pkg:npm/jsbn@0.1.1?package-id=221bb7ced8fe5a78",
243809          "supplier": {},
243810          "author": "Tom Wu",
243811          "name": "jsbn",
243812          "version": "0.1.1",
243813          "description": "The jsbn library is a fast, portable implementation of large-number math in pure JavaScript, enabling public-key crypto and other applications on desktop and mobile browsers.",
243814          "licenses": [
243815            {
243816              "license": {
243817                "id": "MIT"
243818              }
243819            }
243820          ],
243821          "cpe": "cpe:2.3:a:andyperlitch:jsbn:0.1.1:*:*:*:*:*:*:*",
243822          "purl": "pkg:npm/jsbn@0.1.1",
243823          "swid": {
243824            "attachment": {}
243825          },
243826          "pedigree": {},
243827          "externalReferences": [
243828            {
243829              "url": "https://github.com/andyperlitch/jsbn.git",
243830              "type": "distribution"
243831            }
243832          ],
243833          "evidence": {},
243834          "signature": {
243835            "signature": {
243836              "publicKey": {}
243837            }
243838          },
243839          "modelCard": {
243840            "modelParameters": {
243841              "approach": {}
243842            },
243843            "quantitativeAnalysis": {
243844              "graphics": {}
243845            },
243846            "considerations": {}
243847          }
243848        },
243849        {
243850          "type": "library",
243851          "bom-ref": "pkg:npm/json-schema@0.4.0?package-id=ca754b1364dba8bb",
243852          "supplier": {},
243853          "author": "Kris Zyp",
243854          "name": "json-schema",
243855          "version": "0.4.0",
243856          "description": "JSON Schema validation and specifications",
243857          "licenses": [
243858            {
243859              "license": {
243860                "name": "(AFL-2.1 OR BSD-3-Clause)"
243861              }
243862            }
243863          ],
243864          "cpe": "cpe:2.3:a:json-schema:json-schema:0.4.0:*:*:*:*:*:*:*",
243865          "purl": "pkg:npm/json-schema@0.4.0",
243866          "swid": {
243867            "attachment": {}
243868          },
243869          "pedigree": {},
243870          "externalReferences": [
243871            {
243872              "url": "http://github.com/kriszyp/json-schema",
243873              "type": "distribution"
243874            }
243875          ],
243876          "evidence": {},
243877          "signature": {
243878            "signature": {
243879              "publicKey": {}
243880            }
243881          },
243882          "modelCard": {
243883            "modelParameters": {
243884              "approach": {}
243885            },
243886            "quantitativeAnalysis": {
243887              "graphics": {}
243888            },
243889            "considerations": {}
243890          }
243891        },
243892        {
243893          "type": "library",
243894          "bom-ref": "pkg:npm/json-schema-resolver@1.3.0?package-id=a6561614e3c31970",
243895          "supplier": {},
243896          "author": "Manuel Spigolon \u003cbehemoth89@gmail.com\u003e (https://github.com/Eomm)",
243897          "name": "json-schema-resolver",
243898          "version": "1.3.0",
243899          "description": "Resolve all your $refs",
243900          "licenses": [
243901            {
243902              "license": {
243903                "id": "MIT"
243904              }
243905            }
243906          ],
243907          "cpe": "cpe:2.3:a:json-schema-resolver:json-schema-resolver:1.3.0:*:*:*:*:*:*:*",
243908          "purl": "pkg:npm/json-schema-resolver@1.3.0",
243909          "swid": {
243910            "attachment": {}
243911          },
243912          "pedigree": {},
243913          "externalReferences": [
243914            {
243915              "url": "git+https://github.com/Eomm/json-schema-resolver.git",
243916              "type": "distribution"
243917            },
243918            {
243919              "url": "https://github.com/Eomm/json-schema-resolver#readme",
243920              "type": "website"
243921            }
243922          ],
243923          "evidence": {},
243924          "signature": {
243925            "signature": {
243926              "publicKey": {}
243927            }
243928          },
243929          "modelCard": {
243930            "modelParameters": {
243931              "approach": {}
243932            },
243933            "quantitativeAnalysis": {
243934              "graphics": {}
243935            },
243936            "considerations": {}
243937          }
243938        },
243939        {
243940          "type": "library",
243941          "bom-ref": "pkg:npm/json-schema-traverse@0.4.1?package-id=285c4d6d5ff842",
243942          "supplier": {},
243943          "author": "Evgeny Poberezkin",
243944          "name": "json-schema-traverse",
243945          "version": "0.4.1",
243946          "description": "Traverse JSON Schema passing each schema object to callback",
243947          "licenses": [
243948            {
243949              "license": {
243950                "id": "MIT"
243951              }
243952            }
243953          ],
243954          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:0.4.1:*:*:*:*:*:*:*",
243955          "purl": "pkg:npm/json-schema-traverse@0.4.1",
243956          "swid": {
243957            "attachment": {}
243958          },
243959          "pedigree": {},
243960          "externalReferences": [
243961            {
243962              "url": "git+https://github.com/epoberezkin/json-schema-traverse.git",
243963              "type": "distribution"
243964            },
243965            {
243966              "url": "https://github.com/epoberezkin/json-schema-traverse#readme",
243967              "type": "website"
243968            }
243969          ],
243970          "evidence": {},
243971          "signature": {
243972            "signature": {
243973              "publicKey": {}
243974            }
243975          },
243976          "modelCard": {
243977            "modelParameters": {
243978              "approach": {}
243979            },
243980            "quantitativeAnalysis": {
243981              "graphics": {}
243982            },
243983            "considerations": {}
243984          }
243985        },
243986        {
243987          "type": "library",
243988          "bom-ref": "pkg:npm/json-stringify-safe@5.0.1?package-id=a160b0f4a9bea77e",
243989          "supplier": {},
243990          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
243991          "name": "json-stringify-safe",
243992          "version": "5.0.1",
243993          "description": "Like JSON.stringify, but doesn't blow up on circular refs.",
243994          "licenses": [
243995            {
243996              "license": {
243997                "id": "ISC"
243998              }
243999            }
244000          ],
244001          "cpe": "cpe:2.3:a:json-stringify-safe:json-stringify-safe:5.0.1:*:*:*:*:*:*:*",
244002          "purl": "pkg:npm/json-stringify-safe@5.0.1",
244003          "swid": {
244004            "attachment": {}
244005          },
244006          "pedigree": {},
244007          "externalReferences": [
244008            {
244009              "url": "git://github.com/isaacs/json-stringify-safe",
244010              "type": "distribution"
244011            },
244012            {
244013              "url": "https://github.com/isaacs/json-stringify-safe",
244014              "type": "website"
244015            }
244016          ],
244017          "evidence": {},
244018          "signature": {
244019            "signature": {
244020              "publicKey": {}
244021            }
244022          },
244023          "modelCard": {
244024            "modelParameters": {
244025              "approach": {}
244026            },
244027            "quantitativeAnalysis": {
244028              "graphics": {}
244029            },
244030            "considerations": {}
244031          }
244032        },
244033        {
244034          "type": "library",
244035          "bom-ref": "pkg:npm/jsonschema@1.4.1?package-id=144a946eabfa9c32",
244036          "supplier": {},
244037          "author": "Tom de Grunt \u003ctom@degrunt.nl\u003e",
244038          "name": "jsonschema",
244039          "version": "1.4.1",
244040          "description": "A fast and easy to use JSON Schema validator",
244041          "licenses": [
244042            {
244043              "license": {
244044                "id": "MIT"
244045              }
244046            }
244047          ],
244048          "cpe": "cpe:2.3:a:jsonschema:jsonschema:1.4.1:*:*:*:*:*:*:*",
244049          "purl": "pkg:npm/jsonschema@1.4.1",
244050          "swid": {
244051            "attachment": {}
244052          },
244053          "pedigree": {},
244054          "externalReferences": [
244055            {
244056              "url": "git://github.com/tdegrunt/jsonschema.git",
244057              "type": "distribution"
244058            }
244059          ],
244060          "evidence": {},
244061          "signature": {
244062            "signature": {
244063              "publicKey": {}
244064            }
244065          },
244066          "modelCard": {
244067            "modelParameters": {
244068              "approach": {}
244069            },
244070            "quantitativeAnalysis": {
244071              "graphics": {}
244072            },
244073            "considerations": {}
244074          }
244075        },
244076        {
244077          "type": "library",
244078          "bom-ref": "pkg:npm/jsprim@1.4.2?package-id=bec0b682350f7528",
244079          "supplier": {},
244080          "name": "jsprim",
244081          "version": "1.4.2",
244082          "description": "utilities for primitive JavaScript types",
244083          "licenses": [
244084            {
244085              "license": {
244086                "id": "MIT"
244087              }
244088            }
244089          ],
244090          "cpe": "cpe:2.3:a:joyent:jsprim:1.4.2:*:*:*:*:*:*:*",
244091          "purl": "pkg:npm/jsprim@1.4.2",
244092          "swid": {
244093            "attachment": {}
244094          },
244095          "pedigree": {},
244096          "externalReferences": [
244097            {
244098              "url": "git://github.com/joyent/node-jsprim.git",
244099              "type": "distribution"
244100            }
244101          ],
244102          "evidence": {},
244103          "signature": {
244104            "signature": {
244105              "publicKey": {}
244106            }
244107          },
244108          "modelCard": {
244109            "modelParameters": {
244110              "approach": {}
244111            },
244112            "quantitativeAnalysis": {
244113              "graphics": {}
244114            },
244115            "considerations": {}
244116          }
244117        },
244118        {
244119          "type": "library",
244120          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.11.13\u0026package-id=22b2a81fa39d5dd2",
244121          "supplier": {},
244122          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
244123          "name": "libc-utils",
244124          "version": "0.7.2-r0",
244125          "description": "Meta package to pull in correct libc",
244126          "licenses": [
244127            {
244128              "license": {
244129                "name": "BSD"
244130              }
244131            }
244132          ],
244133          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r0:*:*:*:*:*:*:*",
244134          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.11.13",
244135          "swid": {
244136            "attachment": {}
244137          },
244138          "pedigree": {},
244139          "externalReferences": [
244140            {
244141              "url": "http://alpinelinux.org",
244142              "type": "distribution"
244143            }
244144          ],
244145          "evidence": {},
244146          "signature": {
244147            "signature": {
244148              "publicKey": {}
244149            }
244150          },
244151          "modelCard": {
244152            "modelParameters": {
244153              "approach": {}
244154            },
244155            "quantitativeAnalysis": {
244156              "graphics": {}
244157            },
244158            "considerations": {}
244159          }
244160        },
244161        {
244162          "type": "library",
244163          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13\u0026package-id=9dc8a627b3dc6e7c",
244164          "supplier": {},
244165          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
244166          "name": "libcrypto1.1",
244167          "version": "1.1.1l-r0",
244168          "description": "Crypto library from openssl",
244169          "licenses": [
244170            {
244171              "license": {
244172                "id": "OpenSSL"
244173              }
244174            }
244175          ],
244176          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1l-r0:*:*:*:*:*:*:*",
244177          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13",
244178          "swid": {
244179            "attachment": {}
244180          },
244181          "pedigree": {},
244182          "externalReferences": [
244183            {
244184              "url": "https://www.openssl.org",
244185              "type": "distribution"
244186            }
244187          ],
244188          "evidence": {},
244189          "signature": {
244190            "signature": {
244191              "publicKey": {}
244192            }
244193          },
244194          "modelCard": {
244195            "modelParameters": {
244196              "approach": {}
244197            },
244198            "quantitativeAnalysis": {
244199              "graphics": {}
244200            },
244201            "considerations": {}
244202          }
244203        },
244204        {
244205          "type": "library",
244206          "bom-ref": "pkg:apk/alpine/libgcc@9.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.11.13\u0026package-id=89cc23c6449d2429",
244207          "supplier": {},
244208          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
244209          "name": "libgcc",
244210          "version": "9.3.0-r0",
244211          "description": "GNU C compiler runtime libraries",
244212          "licenses": [
244213            {
244214              "license": {
244215                "name": "GPL"
244216              }
244217            },
244218            {
244219              "license": {
244220                "name": "LGPL"
244221              }
244222            }
244223          ],
244224          "cpe": "cpe:2.3:a:libgcc:libgcc:9.3.0-r0:*:*:*:*:*:*:*",
244225          "purl": "pkg:apk/alpine/libgcc@9.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.11.13",
244226          "swid": {
244227            "attachment": {}
244228          },
244229          "pedigree": {},
244230          "externalReferences": [
244231            {
244232              "url": "http://gcc.gnu.org",
244233              "type": "distribution"
244234            }
244235          ],
244236          "evidence": {},
244237          "signature": {
244238            "signature": {
244239              "publicKey": {}
244240            }
244241          },
244242          "modelCard": {
244243            "modelParameters": {
244244              "approach": {}
244245            },
244246            "quantitativeAnalysis": {
244247              "graphics": {}
244248            },
244249            "considerations": {}
244250          }
244251        },
244252        {
244253          "type": "library",
244254          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13\u0026package-id=286e1bd630e38068",
244255          "supplier": {},
244256          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
244257          "name": "libssl1.1",
244258          "version": "1.1.1l-r0",
244259          "description": "SSL shared libraries",
244260          "licenses": [
244261            {
244262              "license": {
244263                "id": "OpenSSL"
244264              }
244265            }
244266          ],
244267          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1l-r0:*:*:*:*:*:*:*",
244268          "purl": "pkg:apk/alpine/libssl1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13",
244269          "swid": {
244270            "attachment": {}
244271          },
244272          "pedigree": {},
244273          "externalReferences": [
244274            {
244275              "url": "https://www.openssl.org",
244276              "type": "distribution"
244277            }
244278          ],
244279          "evidence": {},
244280          "signature": {
244281            "signature": {
244282              "publicKey": {}
244283            }
244284          },
244285          "modelCard": {
244286            "modelParameters": {
244287              "approach": {}
244288            },
244289            "quantitativeAnalysis": {
244290              "graphics": {}
244291            },
244292            "considerations": {}
244293          }
244294        },
244295        {
244296          "type": "library",
244297          "bom-ref": "pkg:apk/alpine/libstdc++@9.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.11.13\u0026package-id=6fd631fecbbb6585",
244298          "supplier": {},
244299          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
244300          "name": "libstdc++",
244301          "version": "9.3.0-r0",
244302          "description": "GNU C++ standard runtime library",
244303          "licenses": [
244304            {
244305              "license": {
244306                "name": "GPL"
244307              }
244308            },
244309            {
244310              "license": {
244311                "name": "LGPL"
244312              }
244313            }
244314          ],
244315          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:9.3.0-r0:*:*:*:*:*:*:*",
244316          "purl": "pkg:apk/alpine/libstdc++@9.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.11.13",
244317          "swid": {
244318            "attachment": {}
244319          },
244320          "pedigree": {},
244321          "externalReferences": [
244322            {
244323              "url": "http://gcc.gnu.org",
244324              "type": "distribution"
244325            }
244326          ],
244327          "evidence": {},
244328          "signature": {
244329            "signature": {
244330              "publicKey": {}
244331            }
244332          },
244333          "modelCard": {
244334            "modelParameters": {
244335              "approach": {}
244336            },
244337            "quantitativeAnalysis": {
244338              "graphics": {}
244339            },
244340            "considerations": {}
244341          }
244342        },
244343        {
244344          "type": "library",
244345          "bom-ref": "pkg:apk/alpine/libtls-standalone@2.9.1-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=44d013a47dc758aa",
244346          "supplier": {},
244347          "name": "libtls-standalone",
244348          "version": "2.9.1-r0",
244349          "description": "libtls extricated from libressl sources",
244350          "licenses": [
244351            {
244352              "license": {
244353                "id": "ISC"
244354              }
244355            }
244356          ],
244357          "cpe": "cpe:2.3:a:libtls-standalone:libtls-standalone:2.9.1-r0:*:*:*:*:*:*:*",
244358          "purl": "pkg:apk/alpine/libtls-standalone@2.9.1-r0?arch=x86_64\u0026distro=alpine-3.11.13",
244359          "swid": {
244360            "attachment": {}
244361          },
244362          "pedigree": {},
244363          "externalReferences": [
244364            {
244365              "url": "https://www.libressl.org/",
244366              "type": "distribution"
244367            }
244368          ],
244369          "evidence": {},
244370          "signature": {
244371            "signature": {
244372              "publicKey": {}
244373            }
244374          },
244375          "modelCard": {
244376            "modelParameters": {
244377              "approach": {}
244378            },
244379            "quantitativeAnalysis": {
244380              "graphics": {}
244381            },
244382            "considerations": {}
244383          }
244384        },
244385        {
244386          "type": "library",
244387          "bom-ref": "pkg:npm/linked-queue@1.0.3?package-id=6a98e1e0c1c18f8a",
244388          "supplier": {},
244389          "author": "Hung Nguyen \u003chungnt.it@gmail.com\u003e",
244390          "name": "linked-queue",
244391          "version": "1.0.3",
244392          "description": "Queues using linked list, faster than array.shift(),  support enqueue,dequeue,enqueue all, dequeue all, clear, forEach, first, last",
244393          "licenses": [
244394            {
244395              "license": {
244396                "id": "MIT"
244397              }
244398            }
244399          ],
244400          "cpe": "cpe:2.3:a:linked-queue:linked-queue:1.0.3:*:*:*:*:*:*:*",
244401          "purl": "pkg:npm/linked-queue@1.0.3",
244402          "swid": {
244403            "attachment": {}
244404          },
244405          "pedigree": {},
244406          "externalReferences": [
244407            {
244408              "url": "git+https://github.com/hungntit/lqueue.git",
244409              "type": "distribution"
244410            },
244411            {
244412              "url": "https://github.com/hungntit/lqueue#readme",
244413              "type": "website"
244414            }
244415          ],
244416          "evidence": {},
244417          "signature": {
244418            "signature": {
244419              "publicKey": {}
244420            }
244421          },
244422          "modelCard": {
244423            "modelParameters": {
244424              "approach": {}
244425            },
244426            "quantitativeAnalysis": {
244427              "graphics": {}
244428            },
244429            "considerations": {}
244430          }
244431        },
244432        {
244433          "type": "library",
244434          "bom-ref": "pkg:npm/lodash@4.17.21?package-id=6047cd16d33b78f4",
244435          "supplier": {},
244436          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e",
244437          "name": "lodash",
244438          "version": "4.17.21",
244439          "description": "Lodash modular utilities.",
244440          "licenses": [
244441            {
244442              "license": {
244443                "id": "MIT"
244444              }
244445            }
244446          ],
244447          "cpe": "cpe:2.3:a:lodash:lodash:4.17.21:*:*:*:*:*:*:*",
244448          "purl": "pkg:npm/lodash@4.17.21",
244449          "swid": {
244450            "attachment": {}
244451          },
244452          "pedigree": {},
244453          "externalReferences": [
244454            {
244455              "url": "lodash/lodash",
244456              "type": "distribution"
244457            },
244458            {
244459              "url": "https://lodash.com/",
244460              "type": "website"
244461            }
244462          ],
244463          "evidence": {},
244464          "signature": {
244465            "signature": {
244466              "publicKey": {}
244467            }
244468          },
244469          "modelCard": {
244470            "modelParameters": {
244471              "approach": {}
244472            },
244473            "quantitativeAnalysis": {
244474              "graphics": {}
244475            },
244476            "considerations": {}
244477          }
244478        },
244479        {
244480          "type": "library",
244481          "bom-ref": "pkg:npm/media-typer@0.3.0?package-id=5ee412145f832035",
244482          "supplier": {},
244483          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
244484          "name": "media-typer",
244485          "version": "0.3.0",
244486          "description": "Simple RFC 6838 media type parser and formatter",
244487          "licenses": [
244488            {
244489              "license": {
244490                "id": "MIT"
244491              }
244492            }
244493          ],
244494          "cpe": "cpe:2.3:a:media-typer:media-typer:0.3.0:*:*:*:*:*:*:*",
244495          "purl": "pkg:npm/media-typer@0.3.0",
244496          "swid": {
244497            "attachment": {}
244498          },
244499          "pedigree": {},
244500          "externalReferences": [
244501            {
244502              "url": "jshttp/media-typer",
244503              "type": "distribution"
244504            }
244505          ],
244506          "evidence": {},
244507          "signature": {
244508            "signature": {
244509              "publicKey": {}
244510            }
244511          },
244512          "modelCard": {
244513            "modelParameters": {
244514              "approach": {}
244515            },
244516            "quantitativeAnalysis": {
244517              "graphics": {}
244518            },
244519            "considerations": {}
244520          }
244521        },
244522        {
244523          "type": "library",
244524          "bom-ref": "pkg:npm/merge-descriptors@1.0.1?package-id=3f6c0ab125751474",
244525          "supplier": {},
244526          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
244527          "name": "merge-descriptors",
244528          "version": "1.0.1",
244529          "description": "Merge objects using descriptors",
244530          "licenses": [
244531            {
244532              "license": {
244533                "id": "MIT"
244534              }
244535            }
244536          ],
244537          "cpe": "cpe:2.3:a:merge-descriptors:merge-descriptors:1.0.1:*:*:*:*:*:*:*",
244538          "purl": "pkg:npm/merge-descriptors@1.0.1",
244539          "swid": {
244540            "attachment": {}
244541          },
244542          "pedigree": {},
244543          "externalReferences": [
244544            {
244545              "url": "component/merge-descriptors",
244546              "type": "distribution"
244547            }
244548          ],
244549          "evidence": {},
244550          "signature": {
244551            "signature": {
244552              "publicKey": {}
244553            }
244554          },
244555          "modelCard": {
244556            "modelParameters": {
244557              "approach": {}
244558            },
244559            "quantitativeAnalysis": {
244560              "graphics": {}
244561            },
244562            "considerations": {}
244563          }
244564        },
244565        {
244566          "type": "library",
244567          "bom-ref": "pkg:npm/methods@1.1.2?package-id=15a8c45d09fc8d99",
244568          "supplier": {},
244569          "name": "methods",
244570          "version": "1.1.2",
244571          "description": "HTTP methods that node supports",
244572          "licenses": [
244573            {
244574              "license": {
244575                "id": "MIT"
244576              }
244577            }
244578          ],
244579          "cpe": "cpe:2.3:a:methods:methods:1.1.2:*:*:*:*:*:*:*",
244580          "purl": "pkg:npm/methods@1.1.2",
244581          "swid": {
244582            "attachment": {}
244583          },
244584          "pedigree": {},
244585          "externalReferences": [
244586            {
244587              "url": "jshttp/methods",
244588              "type": "distribution"
244589            }
244590          ],
244591          "evidence": {},
244592          "signature": {
244593            "signature": {
244594              "publicKey": {}
244595            }
244596          },
244597          "modelCard": {
244598            "modelParameters": {
244599              "approach": {}
244600            },
244601            "quantitativeAnalysis": {
244602              "graphics": {}
244603            },
244604            "considerations": {}
244605          }
244606        },
244607        {
244608          "type": "library",
244609          "bom-ref": "pkg:npm/mime@1.6.0?package-id=6f5b549e9935a4d3",
244610          "supplier": {},
244611          "author": "Robert Kieffer \u003crobert@broofa.com\u003e (http://github.com/broofa)",
244612          "name": "mime",
244613          "version": "1.6.0",
244614          "description": "A comprehensive library for mime-type mapping",
244615          "licenses": [
244616            {
244617              "license": {
244618                "id": "MIT"
244619              }
244620            }
244621          ],
244622          "cpe": "cpe:2.3:a:broofa:mime:1.6.0:*:*:*:*:*:*:*",
244623          "purl": "pkg:npm/mime@1.6.0",
244624          "swid": {
244625            "attachment": {}
244626          },
244627          "pedigree": {},
244628          "externalReferences": [
244629            {
244630              "url": "https://github.com/broofa/node-mime",
244631              "type": "distribution"
244632            }
244633          ],
244634          "evidence": {},
244635          "signature": {
244636            "signature": {
244637              "publicKey": {}
244638            }
244639          },
244640          "modelCard": {
244641            "modelParameters": {
244642              "approach": {}
244643            },
244644            "quantitativeAnalysis": {
244645              "graphics": {}
244646            },
244647            "considerations": {}
244648          }
244649        },
244650        {
244651          "type": "library",
244652          "bom-ref": "pkg:npm/mime-db@1.52.0?package-id=403a2724d6dab6f1",
244653          "supplier": {},
244654          "name": "mime-db",
244655          "version": "1.52.0",
244656          "description": "Media Type Database",
244657          "licenses": [
244658            {
244659              "license": {
244660                "id": "MIT"
244661              }
244662            }
244663          ],
244664          "cpe": "cpe:2.3:a:mime-db:mime-db:1.52.0:*:*:*:*:*:*:*",
244665          "purl": "pkg:npm/mime-db@1.52.0",
244666          "swid": {
244667            "attachment": {}
244668          },
244669          "pedigree": {},
244670          "externalReferences": [
244671            {
244672              "url": "jshttp/mime-db",
244673              "type": "distribution"
244674            }
244675          ],
244676          "evidence": {},
244677          "signature": {
244678            "signature": {
244679              "publicKey": {}
244680            }
244681          },
244682          "modelCard": {
244683            "modelParameters": {
244684              "approach": {}
244685            },
244686            "quantitativeAnalysis": {
244687              "graphics": {}
244688            },
244689            "considerations": {}
244690          }
244691        },
244692        {
244693          "type": "library",
244694          "bom-ref": "pkg:npm/mime-types@2.1.35?package-id=761ad31d16a93070",
244695          "supplier": {},
244696          "name": "mime-types",
244697          "version": "2.1.35",
244698          "description": "The ultimate javascript content-type utility.",
244699          "licenses": [
244700            {
244701              "license": {
244702                "id": "MIT"
244703              }
244704            }
244705          ],
244706          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.35:*:*:*:*:*:*:*",
244707          "purl": "pkg:npm/mime-types@2.1.35",
244708          "swid": {
244709            "attachment": {}
244710          },
244711          "pedigree": {},
244712          "externalReferences": [
244713            {
244714              "url": "jshttp/mime-types",
244715              "type": "distribution"
244716            }
244717          ],
244718          "evidence": {},
244719          "signature": {
244720            "signature": {
244721              "publicKey": {}
244722            }
244723          },
244724          "modelCard": {
244725            "modelParameters": {
244726              "approach": {}
244727            },
244728            "quantitativeAnalysis": {
244729              "graphics": {}
244730            },
244731            "considerations": {}
244732          }
244733        },
244734        {
244735          "type": "library",
244736          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=9b77623d14038b42",
244737          "supplier": {},
244738          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
244739          "name": "minimatch",
244740          "version": "3.1.2",
244741          "description": "a glob matcher in javascript",
244742          "licenses": [
244743            {
244744              "license": {
244745                "id": "ISC"
244746              }
244747            }
244748          ],
244749          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
244750          "purl": "pkg:npm/minimatch@3.1.2",
244751          "swid": {
244752            "attachment": {}
244753          },
244754          "pedigree": {},
244755          "externalReferences": [
244756            {
244757              "url": "git://github.com/isaacs/minimatch.git",
244758              "type": "distribution"
244759            }
244760          ],
244761          "evidence": {},
244762          "signature": {
244763            "signature": {
244764              "publicKey": {}
244765            }
244766          },
244767          "modelCard": {
244768            "modelParameters": {
244769              "approach": {}
244770            },
244771            "quantitativeAnalysis": {
244772              "graphics": {}
244773            },
244774            "considerations": {}
244775          }
244776        },
244777        {
244778          "type": "library",
244779          "bom-ref": "pkg:npm/minimist@1.2.6?package-id=b432279d3f151180",
244780          "supplier": {},
244781          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
244782          "name": "minimist",
244783          "version": "1.2.6",
244784          "description": "parse argument options",
244785          "licenses": [
244786            {
244787              "license": {
244788                "id": "MIT"
244789              }
244790            }
244791          ],
244792          "cpe": "cpe:2.3:a:minimist:minimist:1.2.6:*:*:*:*:*:*:*",
244793          "purl": "pkg:npm/minimist@1.2.6",
244794          "swid": {
244795            "attachment": {}
244796          },
244797          "pedigree": {},
244798          "externalReferences": [
244799            {
244800              "url": "git://github.com/substack/minimist.git",
244801              "type": "distribution"
244802            },
244803            {
244804              "url": "https://github.com/substack/minimist",
244805              "type": "website"
244806            }
244807          ],
244808          "evidence": {},
244809          "signature": {
244810            "signature": {
244811              "publicKey": {}
244812            }
244813          },
244814          "modelCard": {
244815            "modelParameters": {
244816              "approach": {}
244817            },
244818            "quantitativeAnalysis": {
244819              "graphics": {}
244820            },
244821            "considerations": {}
244822          }
244823        },
244824        {
244825          "type": "library",
244826          "bom-ref": "pkg:npm/mkdirp@0.5.6?package-id=8fe2c2c6668f6890",
244827          "supplier": {},
244828          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
244829          "name": "mkdirp",
244830          "version": "0.5.6",
244831          "description": "Recursively mkdir, like `mkdir -p`",
244832          "licenses": [
244833            {
244834              "license": {
244835                "id": "MIT"
244836              }
244837            }
244838          ],
244839          "cpe": "cpe:2.3:a:substack:mkdirp:0.5.6:*:*:*:*:*:*:*",
244840          "purl": "pkg:npm/mkdirp@0.5.6",
244841          "swid": {
244842            "attachment": {}
244843          },
244844          "pedigree": {},
244845          "externalReferences": [
244846            {
244847              "url": "https://github.com/substack/node-mkdirp.git",
244848              "type": "distribution"
244849            }
244850          ],
244851          "evidence": {},
244852          "signature": {
244853            "signature": {
244854              "publicKey": {}
244855            }
244856          },
244857          "modelCard": {
244858            "modelParameters": {
244859              "approach": {}
244860            },
244861            "quantitativeAnalysis": {
244862              "graphics": {}
244863            },
244864            "considerations": {}
244865          }
244866        },
244867        {
244868          "type": "library",
244869          "bom-ref": "pkg:npm/ms@2.0.0?package-id=188f44433460d00d",
244870          "supplier": {},
244871          "name": "ms",
244872          "version": "2.0.0",
244873          "description": "Tiny milisecond conversion utility",
244874          "licenses": [
244875            {
244876              "license": {
244877                "id": "MIT"
244878              }
244879            }
244880          ],
244881          "cpe": "cpe:2.3:a:ms:ms:2.0.0:*:*:*:*:*:*:*",
244882          "purl": "pkg:npm/ms@2.0.0",
244883          "swid": {
244884            "attachment": {}
244885          },
244886          "pedigree": {},
244887          "externalReferences": [
244888            {
244889              "url": "zeit/ms",
244890              "type": "distribution"
244891            }
244892          ],
244893          "evidence": {},
244894          "signature": {
244895            "signature": {
244896              "publicKey": {}
244897            }
244898          },
244899          "modelCard": {
244900            "modelParameters": {
244901              "approach": {}
244902            },
244903            "quantitativeAnalysis": {
244904              "graphics": {}
244905            },
244906            "considerations": {}
244907          }
244908        },
244909        {
244910          "type": "library",
244911          "bom-ref": "pkg:npm/ms@2.1.1?package-id=945089044e883417",
244912          "supplier": {},
244913          "name": "ms",
244914          "version": "2.1.1",
244915          "description": "Tiny millisecond conversion utility",
244916          "licenses": [
244917            {
244918              "license": {
244919                "id": "MIT"
244920              }
244921            }
244922          ],
244923          "cpe": "cpe:2.3:a:ms:ms:2.1.1:*:*:*:*:*:*:*",
244924          "purl": "pkg:npm/ms@2.1.1",
244925          "swid": {
244926            "attachment": {}
244927          },
244928          "pedigree": {},
244929          "externalReferences": [
244930            {
244931              "url": "zeit/ms",
244932              "type": "distribution"
244933            }
244934          ],
244935          "evidence": {},
244936          "signature": {
244937            "signature": {
244938              "publicKey": {}
244939            }
244940          },
244941          "modelCard": {
244942            "modelParameters": {
244943              "approach": {}
244944            },
244945            "quantitativeAnalysis": {
244946              "graphics": {}
244947            },
244948            "considerations": {}
244949          }
244950        },
244951        {
244952          "type": "library",
244953          "bom-ref": "pkg:npm/ms@2.1.2?package-id=4ce80519f65a6aeb",
244954          "supplier": {},
244955          "name": "ms",
244956          "version": "2.1.2",
244957          "description": "Tiny millisecond conversion utility",
244958          "licenses": [
244959            {
244960              "license": {
244961                "id": "MIT"
244962              }
244963            }
244964          ],
244965          "cpe": "cpe:2.3:a:ms:ms:2.1.2:*:*:*:*:*:*:*",
244966          "purl": "pkg:npm/ms@2.1.2",
244967          "swid": {
244968            "attachment": {}
244969          },
244970          "pedigree": {},
244971          "externalReferences": [
244972            {
244973              "url": "zeit/ms",
244974              "type": "distribution"
244975            }
244976          ],
244977          "evidence": {},
244978          "signature": {
244979            "signature": {
244980              "publicKey": {}
244981            }
244982          },
244983          "modelCard": {
244984            "modelParameters": {
244985              "approach": {}
244986            },
244987            "quantitativeAnalysis": {
244988              "graphics": {}
244989            },
244990            "considerations": {}
244991          }
244992        },
244993        {
244994          "type": "library",
244995          "bom-ref": "pkg:npm/multer@1.4.2?package-id=250b8ef9ecf095fd",
244996          "supplier": {},
244997          "name": "multer",
244998          "version": "1.4.2",
244999          "description": "Middleware for handling `multipart/form-data`.",
245000          "licenses": [
245001            {
245002              "license": {
245003                "id": "MIT"
245004              }
245005            }
245006          ],
245007          "cpe": "cpe:2.3:a:multer:multer:1.4.2:*:*:*:*:*:*:*",
245008          "purl": "pkg:npm/multer@1.4.2",
245009          "swid": {
245010            "attachment": {}
245011          },
245012          "pedigree": {},
245013          "externalReferences": [
245014            {
245015              "url": "expressjs/multer",
245016              "type": "distribution"
245017            }
245018          ],
245019          "evidence": {},
245020          "signature": {
245021            "signature": {
245022              "publicKey": {}
245023            }
245024          },
245025          "modelCard": {
245026            "modelParameters": {
245027              "approach": {}
245028            },
245029            "quantitativeAnalysis": {
245030              "graphics": {}
245031            },
245032            "considerations": {}
245033          }
245034        },
245035        {
245036          "type": "library",
245037          "bom-ref": "pkg:apk/alpine/musl@1.1.24-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=485b70fc6d5760",
245038          "supplier": {},
245039          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
245040          "name": "musl",
245041          "version": "1.1.24-r3",
245042          "description": "the musl c library (libc) implementation",
245043          "licenses": [
245044            {
245045              "license": {
245046                "id": "MIT"
245047              }
245048            }
245049          ],
245050          "cpe": "cpe:2.3:a:musl-libc:musl:1.1.24-r3:*:*:*:*:*:*:*",
245051          "purl": "pkg:apk/alpine/musl@1.1.24-r3?arch=x86_64\u0026distro=alpine-3.11.13",
245052          "swid": {
245053            "attachment": {}
245054          },
245055          "pedigree": {},
245056          "externalReferences": [
245057            {
245058              "url": "https://musl.libc.org/",
245059              "type": "distribution"
245060            }
245061          ],
245062          "evidence": {},
245063          "signature": {
245064            "signature": {
245065              "publicKey": {}
245066            }
245067          },
245068          "modelCard": {
245069            "modelParameters": {
245070              "approach": {}
245071            },
245072            "quantitativeAnalysis": {
245073              "graphics": {}
245074            },
245075            "considerations": {}
245076          }
245077        },
245078        {
245079          "type": "library",
245080          "bom-ref": "pkg:apk/alpine/musl-utils@1.1.24-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.11.13\u0026package-id=fc850f3aca8a5da",
245081          "supplier": {},
245082          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
245083          "name": "musl-utils",
245084          "version": "1.1.24-r3",
245085          "description": "the musl c library (libc) implementation",
245086          "licenses": [
245087            {
245088              "license": {
245089                "id": "MIT"
245090              }
245091            },
245092            {
245093              "license": {
245094                "name": "BSD"
245095              }
245096            },
245097            {
245098              "license": {
245099                "id": "GPL-2.0-or-later"
245100              }
245101            }
245102          ],
245103          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.1.24-r3:*:*:*:*:*:*:*",
245104          "purl": "pkg:apk/alpine/musl-utils@1.1.24-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.11.13",
245105          "swid": {
245106            "attachment": {}
245107          },
245108          "pedigree": {},
245109          "externalReferences": [
245110            {
245111              "url": "https://musl.libc.org/",
245112              "type": "distribution"
245113            }
245114          ],
245115          "evidence": {},
245116          "signature": {
245117            "signature": {
245118              "publicKey": {}
245119            }
245120          },
245121          "modelCard": {
245122            "modelParameters": {
245123              "approach": {}
245124            },
245125            "quantitativeAnalysis": {
245126              "graphics": {}
245127            },
245128            "considerations": {}
245129          }
245130        },
245131        {
245132          "type": "library",
245133          "bom-ref": "pkg:npm/negotiator@0.6.3?package-id=bb169d2c6ba1f856",
245134          "supplier": {},
245135          "name": "negotiator",
245136          "version": "0.6.3",
245137          "description": "HTTP content negotiation",
245138          "licenses": [
245139            {
245140              "license": {
245141                "id": "MIT"
245142              }
245143            }
245144          ],
245145          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.3:*:*:*:*:*:*:*",
245146          "purl": "pkg:npm/negotiator@0.6.3",
245147          "swid": {
245148            "attachment": {}
245149          },
245150          "pedigree": {},
245151          "externalReferences": [
245152            {
245153              "url": "jshttp/negotiator",
245154              "type": "distribution"
245155            }
245156          ],
245157          "evidence": {},
245158          "signature": {
245159            "signature": {
245160              "publicKey": {}
245161            }
245162          },
245163          "modelCard": {
245164            "modelParameters": {
245165              "approach": {}
245166            },
245167            "quantitativeAnalysis": {
245168              "graphics": {}
245169            },
245170            "considerations": {}
245171          }
245172        },
245173        {
245174          "type": "application",
245175          "bom-ref": "pkg:generic/node@15.12.0?package-id=35373778dc80f093",
245176          "supplier": {},
245177          "name": "node",
245178          "version": "15.12.0",
245179          "cpe": "cpe:2.3:a:nodejs:node.js:15.12.0:*:*:*:*:*:*:*",
245180          "purl": "pkg:generic/node@15.12.0",
245181          "swid": {
245182            "attachment": {}
245183          },
245184          "pedigree": {},
245185          "evidence": {},
245186          "signature": {
245187            "signature": {
245188              "publicKey": {}
245189            }
245190          },
245191          "modelCard": {
245192            "modelParameters": {
245193              "approach": {}
245194            },
245195            "quantitativeAnalysis": {
245196              "graphics": {}
245197            },
245198            "considerations": {}
245199          }
245200        },
245201        {
245202          "type": "library",
245203          "bom-ref": "pkg:npm/node-fetch@2.6.7?package-id=f88958d48d9976b4",
245204          "supplier": {},
245205          "author": "David Frank",
245206          "name": "node-fetch",
245207          "version": "2.6.7",
245208          "description": "A light-weight module that brings window.fetch to node.js",
245209          "licenses": [
245210            {
245211              "license": {
245212                "id": "MIT"
245213              }
245214            }
245215          ],
245216          "cpe": "cpe:2.3:a:node-fetch:node-fetch:2.6.7:*:*:*:*:*:*:*",
245217          "purl": "pkg:npm/node-fetch@2.6.7",
245218          "swid": {
245219            "attachment": {}
245220          },
245221          "pedigree": {},
245222          "externalReferences": [
245223            {
245224              "url": "https://github.com/bitinn/node-fetch.git",
245225              "type": "distribution"
245226            },
245227            {
245228              "url": "https://github.com/bitinn/node-fetch",
245229              "type": "website"
245230            }
245231          ],
245232          "evidence": {},
245233          "signature": {
245234            "signature": {
245235              "publicKey": {}
245236            }
245237          },
245238          "modelCard": {
245239            "modelParameters": {
245240              "approach": {}
245241            },
245242            "quantitativeAnalysis": {
245243              "graphics": {}
245244            },
245245            "considerations": {}
245246          }
245247        },
245248        {
245249          "type": "library",
245250          "bom-ref": "pkg:npm/oauth-sign@0.9.0?package-id=b618b0fa581b813f",
245251          "supplier": {},
245252          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
245253          "name": "oauth-sign",
245254          "version": "0.9.0",
245255          "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
245256          "licenses": [
245257            {
245258              "license": {
245259                "id": "Apache-2.0"
245260              }
245261            }
245262          ],
245263          "cpe": "cpe:2.3:a:oauth-sign:oauth-sign:0.9.0:*:*:*:*:*:*:*",
245264          "purl": "pkg:npm/oauth-sign@0.9.0",
245265          "swid": {
245266            "attachment": {}
245267          },
245268          "pedigree": {},
245269          "externalReferences": [
245270            {
245271              "url": "https://github.com/mikeal/oauth-sign",
245272              "type": "distribution"
245273            }
245274          ],
245275          "evidence": {},
245276          "signature": {
245277            "signature": {
245278              "publicKey": {}
245279            }
245280          },
245281          "modelCard": {
245282            "modelParameters": {
245283              "approach": {}
245284            },
245285            "quantitativeAnalysis": {
245286              "graphics": {}
245287            },
245288            "considerations": {}
245289          }
245290        },
245291        {
245292          "type": "library",
245293          "bom-ref": "pkg:npm/object-assign@4.1.1?package-id=9d2fa57337157e31",
245294          "supplier": {},
245295          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
245296          "name": "object-assign",
245297          "version": "4.1.1",
245298          "description": "ES2015 `Object.assign()` ponyfill",
245299          "licenses": [
245300            {
245301              "license": {
245302                "id": "MIT"
245303              }
245304            }
245305          ],
245306          "cpe": "cpe:2.3:a:object-assign:object-assign:4.1.1:*:*:*:*:*:*:*",
245307          "purl": "pkg:npm/object-assign@4.1.1",
245308          "swid": {
245309            "attachment": {}
245310          },
245311          "pedigree": {},
245312          "externalReferences": [
245313            {
245314              "url": "sindresorhus/object-assign",
245315              "type": "distribution"
245316            }
245317          ],
245318          "evidence": {},
245319          "signature": {
245320            "signature": {
245321              "publicKey": {}
245322            }
245323          },
245324          "modelCard": {
245325            "modelParameters": {
245326              "approach": {}
245327            },
245328            "quantitativeAnalysis": {
245329              "graphics": {}
245330            },
245331            "considerations": {}
245332          }
245333        },
245334        {
245335          "type": "library",
245336          "bom-ref": "pkg:npm/object-hash@2.1.1?package-id=a9e2e73b131ec362",
245337          "supplier": {},
245338          "author": "Scott Puleo \u003cpuleos@gmail.com\u003e",
245339          "name": "object-hash",
245340          "version": "2.1.1",
245341          "description": "Generate hashes from javascript objects in node and the browser.",
245342          "licenses": [
245343            {
245344              "license": {
245345                "id": "MIT"
245346              }
245347            }
245348          ],
245349          "cpe": "cpe:2.3:a:object-hash:object-hash:2.1.1:*:*:*:*:*:*:*",
245350          "purl": "pkg:npm/object-hash@2.1.1",
245351          "swid": {
245352            "attachment": {}
245353          },
245354          "pedigree": {},
245355          "externalReferences": [
245356            {
245357              "url": "https://github.com/puleos/object-hash",
245358              "type": "distribution"
245359            },
245360            {
245361              "url": "https://github.com/puleos/object-hash",
245362              "type": "website"
245363            }
245364          ],
245365          "evidence": {},
245366          "signature": {
245367            "signature": {
245368              "publicKey": {}
245369            }
245370          },
245371          "modelCard": {
245372            "modelParameters": {
245373              "approach": {}
245374            },
245375            "quantitativeAnalysis": {
245376              "graphics": {}
245377            },
245378            "considerations": {}
245379          }
245380        },
245381        {
245382          "type": "library",
245383          "bom-ref": "pkg:npm/on-finished@2.3.0?package-id=3c6c0c8ba3bf4ee6",
245384          "supplier": {},
245385          "name": "on-finished",
245386          "version": "2.3.0",
245387          "description": "Execute a callback when a request closes, finishes, or errors",
245388          "licenses": [
245389            {
245390              "license": {
245391                "id": "MIT"
245392              }
245393            }
245394          ],
245395          "cpe": "cpe:2.3:a:on-finished:on-finished:2.3.0:*:*:*:*:*:*:*",
245396          "purl": "pkg:npm/on-finished@2.3.0",
245397          "swid": {
245398            "attachment": {}
245399          },
245400          "pedigree": {},
245401          "externalReferences": [
245402            {
245403              "url": "jshttp/on-finished",
245404              "type": "distribution"
245405            }
245406          ],
245407          "evidence": {},
245408          "signature": {
245409            "signature": {
245410              "publicKey": {}
245411            }
245412          },
245413          "modelCard": {
245414            "modelParameters": {
245415              "approach": {}
245416            },
245417            "quantitativeAnalysis": {
245418              "graphics": {}
245419            },
245420            "considerations": {}
245421          }
245422        },
245423        {
245424          "type": "library",
245425          "bom-ref": "pkg:npm/once@1.4.0?package-id=6a66d209255e8adb",
245426          "supplier": {},
245427          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
245428          "name": "once",
245429          "version": "1.4.0",
245430          "description": "Run a function exactly one time",
245431          "licenses": [
245432            {
245433              "license": {
245434                "id": "ISC"
245435              }
245436            }
245437          ],
245438          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
245439          "purl": "pkg:npm/once@1.4.0",
245440          "swid": {
245441            "attachment": {}
245442          },
245443          "pedigree": {},
245444          "externalReferences": [
245445            {
245446              "url": "git://github.com/isaacs/once",
245447              "type": "distribution"
245448            }
245449          ],
245450          "evidence": {},
245451          "signature": {
245452            "signature": {
245453              "publicKey": {}
245454            }
245455          },
245456          "modelCard": {
245457            "modelParameters": {
245458              "approach": {}
245459            },
245460            "quantitativeAnalysis": {
245461              "graphics": {}
245462            },
245463            "considerations": {}
245464          }
245465        },
245466        {
245467          "type": "library",
245468          "bom-ref": "pkg:npm/parseurl@1.3.3?package-id=2af9256e9eccb4f5",
245469          "supplier": {},
245470          "name": "parseurl",
245471          "version": "1.3.3",
245472          "description": "parse a url with memoization",
245473          "licenses": [
245474            {
245475              "license": {
245476                "id": "MIT"
245477              }
245478            }
245479          ],
245480          "cpe": "cpe:2.3:a:parseurl:parseurl:1.3.3:*:*:*:*:*:*:*",
245481          "purl": "pkg:npm/parseurl@1.3.3",
245482          "swid": {
245483            "attachment": {}
245484          },
245485          "pedigree": {},
245486          "externalReferences": [
245487            {
245488              "url": "pillarjs/parseurl",
245489              "type": "distribution"
245490            }
245491          ],
245492          "evidence": {},
245493          "signature": {
245494            "signature": {
245495              "publicKey": {}
245496            }
245497          },
245498          "modelCard": {
245499            "modelParameters": {
245500              "approach": {}
245501            },
245502            "quantitativeAnalysis": {
245503              "graphics": {}
245504            },
245505            "considerations": {}
245506          }
245507        },
245508        {
245509          "type": "library",
245510          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=ca0320bcc1f00114",
245511          "supplier": {},
245512          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
245513          "name": "path-is-absolute",
245514          "version": "1.0.1",
245515          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
245516          "licenses": [
245517            {
245518              "license": {
245519                "id": "MIT"
245520              }
245521            }
245522          ],
245523          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
245524          "purl": "pkg:npm/path-is-absolute@1.0.1",
245525          "swid": {
245526            "attachment": {}
245527          },
245528          "pedigree": {},
245529          "externalReferences": [
245530            {
245531              "url": "sindresorhus/path-is-absolute",
245532              "type": "distribution"
245533            }
245534          ],
245535          "evidence": {},
245536          "signature": {
245537            "signature": {
245538              "publicKey": {}
245539            }
245540          },
245541          "modelCard": {
245542            "modelParameters": {
245543              "approach": {}
245544            },
245545            "quantitativeAnalysis": {
245546              "graphics": {}
245547            },
245548            "considerations": {}
245549          }
245550        },
245551        {
245552          "type": "library",
245553          "bom-ref": "pkg:npm/path-to-regexp@0.1.7?package-id=33dc602dbc9c9fbf",
245554          "supplier": {},
245555          "name": "path-to-regexp",
245556          "version": "0.1.7",
245557          "description": "Express style path to RegExp utility",
245558          "licenses": [
245559            {
245560              "license": {
245561                "id": "MIT"
245562              }
245563            }
245564          ],
245565          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:0.1.7:*:*:*:*:*:*:*",
245566          "purl": "pkg:npm/path-to-regexp@0.1.7",
245567          "swid": {
245568            "attachment": {}
245569          },
245570          "pedigree": {},
245571          "externalReferences": [
245572            {
245573              "url": "https://github.com/component/path-to-regexp.git",
245574              "type": "distribution"
245575            }
245576          ],
245577          "evidence": {},
245578          "signature": {
245579            "signature": {
245580              "publicKey": {}
245581            }
245582          },
245583          "modelCard": {
245584            "modelParameters": {
245585              "approach": {}
245586            },
245587            "quantitativeAnalysis": {
245588              "graphics": {}
245589            },
245590            "considerations": {}
245591          }
245592        },
245593        {
245594          "type": "library",
245595          "bom-ref": "pkg:npm/path-to-regexp@3.2.0?package-id=d3cca60b642f3825",
245596          "supplier": {},
245597          "name": "path-to-regexp",
245598          "version": "3.2.0",
245599          "description": "Express style path to RegExp utility",
245600          "licenses": [
245601            {
245602              "license": {
245603                "id": "MIT"
245604              }
245605            }
245606          ],
245607          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:3.2.0:*:*:*:*:*:*:*",
245608          "purl": "pkg:npm/path-to-regexp@3.2.0",
245609          "swid": {
245610            "attachment": {}
245611          },
245612          "pedigree": {},
245613          "externalReferences": [
245614            {
245615              "url": "https://github.com/pillarjs/path-to-regexp.git",
245616              "type": "distribution"
245617            }
245618          ],
245619          "evidence": {},
245620          "signature": {
245621            "signature": {
245622              "publicKey": {}
245623            }
245624          },
245625          "modelCard": {
245626            "modelParameters": {
245627              "approach": {}
245628            },
245629            "quantitativeAnalysis": {
245630              "graphics": {}
245631            },
245632            "considerations": {}
245633          }
245634        },
245635        {
245636          "type": "library",
245637          "bom-ref": "pkg:npm/performance-now@2.1.0?package-id=33fda45cab4efc34",
245638          "supplier": {},
245639          "author": "Braveg1rl \u003cbraveg1rl@outlook.com\u003e",
245640          "name": "performance-now",
245641          "version": "2.1.0",
245642          "description": "Implements performance.now (based on process.hrtime).",
245643          "licenses": [
245644            {
245645              "license": {
245646                "id": "MIT"
245647              }
245648            }
245649          ],
245650          "cpe": "cpe:2.3:a:performance-now:performance-now:2.1.0:*:*:*:*:*:*:*",
245651          "purl": "pkg:npm/performance-now@2.1.0",
245652          "swid": {
245653            "attachment": {}
245654          },
245655          "pedigree": {},
245656          "externalReferences": [
245657            {
245658              "url": "git://github.com/braveg1rl/performance-now.git",
245659              "type": "distribution"
245660            },
245661            {
245662              "url": "https://github.com/braveg1rl/performance-now",
245663              "type": "website"
245664            }
245665          ],
245666          "evidence": {},
245667          "signature": {
245668            "signature": {
245669              "publicKey": {}
245670            }
245671          },
245672          "modelCard": {
245673            "modelParameters": {
245674              "approach": {}
245675            },
245676            "quantitativeAnalysis": {
245677              "graphics": {}
245678            },
245679            "considerations": {}
245680          }
245681        },
245682        {
245683          "type": "library",
245684          "bom-ref": "pkg:npm/pliant-flow-converter@0.0.1?package-id=1ac38d88d18bd4c5",
245685          "supplier": {},
245686          "name": "pliant-flow-converter",
245687          "version": "0.0.1",
245688          "licenses": [
245689            {
245690              "license": {
245691                "name": "UNLICENSED"
245692              }
245693            }
245694          ],
245695          "cpe": "cpe:2.3:a:pliant-flow-converter:pliant-flow-converter:0.0.1:*:*:*:*:*:*:*",
245696          "purl": "pkg:npm/pliant-flow-converter@0.0.1",
245697          "swid": {
245698            "attachment": {}
245699          },
245700          "pedigree": {},
245701          "evidence": {},
245702          "signature": {
245703            "signature": {
245704              "publicKey": {}
245705            }
245706          },
245707          "modelCard": {
245708            "modelParameters": {
245709              "approach": {}
245710            },
245711            "quantitativeAnalysis": {
245712              "graphics": {}
245713            },
245714            "considerations": {}
245715          }
245716        },
245717        {
245718          "type": "library",
245719          "bom-ref": "pkg:npm/process-nextick-args@2.0.1?package-id=e40e9e1f49dce12f",
245720          "supplier": {},
245721          "name": "process-nextick-args",
245722          "version": "2.0.1",
245723          "description": "process.nextTick but always with args",
245724          "licenses": [
245725            {
245726              "license": {
245727                "id": "MIT"
245728              }
245729            }
245730          ],
245731          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.1:*:*:*:*:*:*:*",
245732          "purl": "pkg:npm/process-nextick-args@2.0.1",
245733          "swid": {
245734            "attachment": {}
245735          },
245736          "pedigree": {},
245737          "externalReferences": [
245738            {
245739              "url": "https://github.com/calvinmetcalf/process-nextick-args.git",
245740              "type": "distribution"
245741            },
245742            {
245743              "url": "https://github.com/calvinmetcalf/process-nextick-args",
245744              "type": "website"
245745            }
245746          ],
245747          "evidence": {},
245748          "signature": {
245749            "signature": {
245750              "publicKey": {}
245751            }
245752          },
245753          "modelCard": {
245754            "modelParameters": {
245755              "approach": {}
245756            },
245757            "quantitativeAnalysis": {
245758              "graphics": {}
245759            },
245760            "considerations": {}
245761          }
245762        },
245763        {
245764          "type": "library",
245765          "bom-ref": "pkg:npm/proxy-addr@2.0.7?package-id=37d1d32cf6c7543a",
245766          "supplier": {},
245767          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
245768          "name": "proxy-addr",
245769          "version": "2.0.7",
245770          "description": "Determine address of proxied request",
245771          "licenses": [
245772            {
245773              "license": {
245774                "id": "MIT"
245775              }
245776            }
245777          ],
245778          "cpe": "cpe:2.3:a:proxy-addr:proxy-addr:2.0.7:*:*:*:*:*:*:*",
245779          "purl": "pkg:npm/proxy-addr@2.0.7",
245780          "swid": {
245781            "attachment": {}
245782          },
245783          "pedigree": {},
245784          "externalReferences": [
245785            {
245786              "url": "jshttp/proxy-addr",
245787              "type": "distribution"
245788            }
245789          ],
245790          "evidence": {},
245791          "signature": {
245792            "signature": {
245793              "publicKey": {}
245794            }
245795          },
245796          "modelCard": {
245797            "modelParameters": {
245798              "approach": {}
245799            },
245800            "quantitativeAnalysis": {
245801              "graphics": {}
245802            },
245803            "considerations": {}
245804          }
245805        },
245806        {
245807          "type": "library",
245808          "bom-ref": "pkg:npm/psl@1.9.0?package-id=ab1c072ffd28101b",
245809          "supplier": {},
245810          "author": "Lupo Montero \u003clupomontero@gmail.com\u003e (https://lupomontero.com/)",
245811          "name": "psl",
245812          "version": "1.9.0",
245813          "description": "Domain name parser based on the Public Suffix List",
245814          "licenses": [
245815            {
245816              "license": {
245817                "id": "MIT"
245818              }
245819            }
245820          ],
245821          "cpe": "cpe:2.3:a:psl:psl:1.9.0:*:*:*:*:*:*:*",
245822          "purl": "pkg:npm/psl@1.9.0",
245823          "swid": {
245824            "attachment": {}
245825          },
245826          "pedigree": {},
245827          "externalReferences": [
245828            {
245829              "url": "git@github.com:lupomontero/psl.git",
245830              "type": "distribution"
245831            }
245832          ],
245833          "evidence": {},
245834          "signature": {
245835            "signature": {
245836              "publicKey": {}
245837            }
245838          },
245839          "modelCard": {
245840            "modelParameters": {
245841              "approach": {}
245842            },
245843            "quantitativeAnalysis": {
245844              "graphics": {}
245845            },
245846            "considerations": {}
245847          }
245848        },
245849        {
245850          "type": "library",
245851          "bom-ref": "pkg:npm/punycode@2.1.1?package-id=fcf18547b0e856e5",
245852          "supplier": {},
245853          "author": "Mathias Bynens (https://mathiasbynens.be/)",
245854          "name": "punycode",
245855          "version": "2.1.1",
245856          "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
245857          "licenses": [
245858            {
245859              "license": {
245860                "id": "MIT"
245861              }
245862            }
245863          ],
245864          "cpe": "cpe:2.3:a:bestiejs:punycode:2.1.1:*:*:*:*:*:*:*",
245865          "purl": "pkg:npm/punycode@2.1.1",
245866          "swid": {
245867            "attachment": {}
245868          },
245869          "pedigree": {},
245870          "externalReferences": [
245871            {
245872              "url": "https://github.com/bestiejs/punycode.js.git",
245873              "type": "distribution"
245874            },
245875            {
245876              "url": "https://mths.be/punycode",
245877              "type": "website"
245878            }
245879          ],
245880          "evidence": {},
245881          "signature": {
245882            "signature": {
245883              "publicKey": {}
245884            }
245885          },
245886          "modelCard": {
245887            "modelParameters": {
245888              "approach": {}
245889            },
245890            "quantitativeAnalysis": {
245891              "graphics": {}
245892            },
245893            "considerations": {}
245894          }
245895        },
245896        {
245897          "type": "library",
245898          "bom-ref": "pkg:npm/qs@6.5.3?package-id=bb49b99015745f72",
245899          "supplier": {},
245900          "name": "qs",
245901          "version": "6.5.3",
245902          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
245903          "licenses": [
245904            {
245905              "license": {
245906                "id": "BSD-3-Clause"
245907              }
245908            }
245909          ],
245910          "cpe": "cpe:2.3:a:ljharb:qs:6.5.3:*:*:*:*:*:*:*",
245911          "purl": "pkg:npm/qs@6.5.3",
245912          "swid": {
245913            "attachment": {}
245914          },
245915          "pedigree": {},
245916          "externalReferences": [
245917            {
245918              "url": "https://github.com/ljharb/qs.git",
245919              "type": "distribution"
245920            },
245921            {
245922              "url": "https://github.com/ljharb/qs",
245923              "type": "website"
245924            }
245925          ],
245926          "evidence": {},
245927          "signature": {
245928            "signature": {
245929              "publicKey": {}
245930            }
245931          },
245932          "modelCard": {
245933            "modelParameters": {
245934              "approach": {}
245935            },
245936            "quantitativeAnalysis": {
245937              "graphics": {}
245938            },
245939            "considerations": {}
245940          }
245941        },
245942        {
245943          "type": "library",
245944          "bom-ref": "pkg:npm/qs@6.7.0?package-id=14cc4b940f3dada7",
245945          "supplier": {},
245946          "name": "qs",
245947          "version": "6.7.0",
245948          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
245949          "licenses": [
245950            {
245951              "license": {
245952                "id": "BSD-3-Clause"
245953              }
245954            }
245955          ],
245956          "cpe": "cpe:2.3:a:ljharb:qs:6.7.0:*:*:*:*:*:*:*",
245957          "purl": "pkg:npm/qs@6.7.0",
245958          "swid": {
245959            "attachment": {}
245960          },
245961          "pedigree": {},
245962          "externalReferences": [
245963            {
245964              "url": "https://github.com/ljharb/qs.git",
245965              "type": "distribution"
245966            },
245967            {
245968              "url": "https://github.com/ljharb/qs",
245969              "type": "website"
245970            }
245971          ],
245972          "evidence": {},
245973          "signature": {
245974            "signature": {
245975              "publicKey": {}
245976            }
245977          },
245978          "modelCard": {
245979            "modelParameters": {
245980              "approach": {}
245981            },
245982            "quantitativeAnalysis": {
245983              "graphics": {}
245984            },
245985            "considerations": {}
245986          }
245987        },
245988        {
245989          "type": "library",
245990          "bom-ref": "pkg:npm/range-parser@1.2.1?package-id=c2944ba157538539",
245991          "supplier": {},
245992          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
245993          "name": "range-parser",
245994          "version": "1.2.1",
245995          "description": "Range header field string parser",
245996          "licenses": [
245997            {
245998              "license": {
245999                "id": "MIT"
246000              }
246001            }
246002          ],
246003          "cpe": "cpe:2.3:a:range-parser:range-parser:1.2.1:*:*:*:*:*:*:*",
246004          "purl": "pkg:npm/range-parser@1.2.1",
246005          "swid": {
246006            "attachment": {}
246007          },
246008          "pedigree": {},
246009          "externalReferences": [
246010            {
246011              "url": "jshttp/range-parser",
246012              "type": "distribution"
246013            }
246014          ],
246015          "evidence": {},
246016          "signature": {
246017            "signature": {
246018              "publicKey": {}
246019            }
246020          },
246021          "modelCard": {
246022            "modelParameters": {
246023              "approach": {}
246024            },
246025            "quantitativeAnalysis": {
246026              "graphics": {}
246027            },
246028            "considerations": {}
246029          }
246030        },
246031        {
246032          "type": "library",
246033          "bom-ref": "pkg:npm/raw-body@2.4.0?package-id=9f97269c1ea647f4",
246034          "supplier": {},
246035          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
246036          "name": "raw-body",
246037          "version": "2.4.0",
246038          "description": "Get and validate the raw body of a readable stream.",
246039          "licenses": [
246040            {
246041              "license": {
246042                "id": "MIT"
246043              }
246044            }
246045          ],
246046          "cpe": "cpe:2.3:a:raw-body:raw-body:2.4.0:*:*:*:*:*:*:*",
246047          "purl": "pkg:npm/raw-body@2.4.0",
246048          "swid": {
246049            "attachment": {}
246050          },
246051          "pedigree": {},
246052          "externalReferences": [
246053            {
246054              "url": "stream-utils/raw-body",
246055              "type": "distribution"
246056            }
246057          ],
246058          "evidence": {},
246059          "signature": {
246060            "signature": {
246061              "publicKey": {}
246062            }
246063          },
246064          "modelCard": {
246065            "modelParameters": {
246066              "approach": {}
246067            },
246068            "quantitativeAnalysis": {
246069              "graphics": {}
246070            },
246071            "considerations": {}
246072          }
246073        },
246074        {
246075          "type": "library",
246076          "bom-ref": "pkg:npm/readable-stream@1.1.14?package-id=3dc690cb53b2e336",
246077          "supplier": {},
246078          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
246079          "name": "readable-stream",
246080          "version": "1.1.14",
246081          "description": "Streams3, a user-land copy of the stream library from Node.js v0.11.x",
246082          "licenses": [
246083            {
246084              "license": {
246085                "id": "MIT"
246086              }
246087            }
246088          ],
246089          "cpe": "cpe:2.3:a:readable-stream:readable-stream:1.1.14:*:*:*:*:*:*:*",
246090          "purl": "pkg:npm/readable-stream@1.1.14",
246091          "swid": {
246092            "attachment": {}
246093          },
246094          "pedigree": {},
246095          "externalReferences": [
246096            {
246097              "url": "git://github.com/isaacs/readable-stream",
246098              "type": "distribution"
246099            }
246100          ],
246101          "evidence": {},
246102          "signature": {
246103            "signature": {
246104              "publicKey": {}
246105            }
246106          },
246107          "modelCard": {
246108            "modelParameters": {
246109              "approach": {}
246110            },
246111            "quantitativeAnalysis": {
246112              "graphics": {}
246113            },
246114            "considerations": {}
246115          }
246116        },
246117        {
246118          "type": "library",
246119          "bom-ref": "pkg:npm/readable-stream@2.3.7?package-id=9e96f166ea078b0b",
246120          "supplier": {},
246121          "name": "readable-stream",
246122          "version": "2.3.7",
246123          "description": "Streams3, a user-land copy of the stream library from Node.js",
246124          "licenses": [
246125            {
246126              "license": {
246127                "id": "MIT"
246128              }
246129            }
246130          ],
246131          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.7:*:*:*:*:*:*:*",
246132          "purl": "pkg:npm/readable-stream@2.3.7",
246133          "swid": {
246134            "attachment": {}
246135          },
246136          "pedigree": {},
246137          "externalReferences": [
246138            {
246139              "url": "git://github.com/nodejs/readable-stream",
246140              "type": "distribution"
246141            }
246142          ],
246143          "evidence": {},
246144          "signature": {
246145            "signature": {
246146              "publicKey": {}
246147            }
246148          },
246149          "modelCard": {
246150            "modelParameters": {
246151              "approach": {}
246152            },
246153            "quantitativeAnalysis": {
246154              "graphics": {}
246155            },
246156            "considerations": {}
246157          }
246158        },
246159        {
246160          "type": "library",
246161          "bom-ref": "pkg:npm/readable-stream@3.6.0?package-id=5f6e30ef9202613f",
246162          "supplier": {},
246163          "name": "readable-stream",
246164          "version": "3.6.0",
246165          "description": "Streams3, a user-land copy of the stream library from Node.js",
246166          "licenses": [
246167            {
246168              "license": {
246169                "id": "MIT"
246170              }
246171            }
246172          ],
246173          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.0:*:*:*:*:*:*:*",
246174          "purl": "pkg:npm/readable-stream@3.6.0",
246175          "swid": {
246176            "attachment": {}
246177          },
246178          "pedigree": {},
246179          "externalReferences": [
246180            {
246181              "url": "git://github.com/nodejs/readable-stream",
246182              "type": "distribution"
246183            }
246184          ],
246185          "evidence": {},
246186          "signature": {
246187            "signature": {
246188              "publicKey": {}
246189            }
246190          },
246191          "modelCard": {
246192            "modelParameters": {
246193              "approach": {}
246194            },
246195            "quantitativeAnalysis": {
246196              "graphics": {}
246197            },
246198            "considerations": {}
246199          }
246200        },
246201        {
246202          "type": "library",
246203          "bom-ref": "pkg:npm/reflect-metadata@0.1.13?package-id=fd6c3616d9a1ea26",
246204          "supplier": {},
246205          "author": "Ron Buckton \u003cron.buckton@microsoft.com\u003e (http://github.com/rbuckton)",
246206          "name": "reflect-metadata",
246207          "version": "0.1.13",
246208          "description": "Polyfill for Metadata Reflection API",
246209          "licenses": [
246210            {
246211              "license": {
246212                "id": "Apache-2.0"
246213              }
246214            }
246215          ],
246216          "cpe": "cpe:2.3:a:reflect-metadata:reflect-metadata:0.1.13:*:*:*:*:*:*:*",
246217          "purl": "pkg:npm/reflect-metadata@0.1.13",
246218          "swid": {
246219            "attachment": {}
246220          },
246221          "pedigree": {},
246222          "externalReferences": [
246223            {
246224              "url": "https://github.com/rbuckton/reflect-metadata.git",
246225              "type": "distribution"
246226            },
246227            {
246228              "url": "http://rbuckton.github.io/reflect-metadata",
246229              "type": "website"
246230            }
246231          ],
246232          "evidence": {},
246233          "signature": {
246234            "signature": {
246235              "publicKey": {}
246236            }
246237          },
246238          "modelCard": {
246239            "modelParameters": {
246240              "approach": {}
246241            },
246242            "quantitativeAnalysis": {
246243              "graphics": {}
246244            },
246245            "considerations": {}
246246          }
246247        },
246248        {
246249          "type": "library",
246250          "bom-ref": "pkg:npm/request@2.88.2?package-id=6e967c01797dfee7",
246251          "supplier": {},
246252          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
246253          "name": "request",
246254          "version": "2.88.2",
246255          "description": "Simplified HTTP request client.",
246256          "licenses": [
246257            {
246258              "license": {
246259                "id": "Apache-2.0"
246260              }
246261            }
246262          ],
246263          "cpe": "cpe:2.3:a:request:request:2.88.2:*:*:*:*:*:*:*",
246264          "purl": "pkg:npm/request@2.88.2",
246265          "swid": {
246266            "attachment": {}
246267          },
246268          "pedigree": {},
246269          "externalReferences": [
246270            {
246271              "url": "https://github.com/request/request.git",
246272              "type": "distribution"
246273            }
246274          ],
246275          "evidence": {},
246276          "signature": {
246277            "signature": {
246278              "publicKey": {}
246279            }
246280          },
246281          "modelCard": {
246282            "modelParameters": {
246283              "approach": {}
246284            },
246285            "quantitativeAnalysis": {
246286              "graphics": {}
246287            },
246288            "considerations": {}
246289          }
246290        },
246291        {
246292          "type": "library",
246293          "bom-ref": "pkg:npm/request-promise-core@1.1.4?package-id=cace198e93a0ac1a",
246294          "supplier": {},
246295          "author": "Nicolai Kamenzky (https://github.com/analog-nico)",
246296          "name": "request-promise-core",
246297          "version": "1.1.4",
246298          "description": "Core Promise support implementation for the simplified HTTP request client 'request'.",
246299          "licenses": [
246300            {
246301              "license": {
246302                "id": "ISC"
246303              }
246304            }
246305          ],
246306          "cpe": "cpe:2.3:a:request-promise-core:request-promise-core:1.1.4:*:*:*:*:*:*:*",
246307          "purl": "pkg:npm/request-promise-core@1.1.4",
246308          "swid": {
246309            "attachment": {}
246310          },
246311          "pedigree": {},
246312          "externalReferences": [
246313            {
246314              "url": "git+https://github.com/request/promise-core.git",
246315              "type": "distribution"
246316            },
246317            {
246318              "url": "https://github.com/request/promise-core#readme",
246319              "type": "website"
246320            }
246321          ],
246322          "evidence": {},
246323          "signature": {
246324            "signature": {
246325              "publicKey": {}
246326            }
246327          },
246328          "modelCard": {
246329            "modelParameters": {
246330              "approach": {}
246331            },
246332            "quantitativeAnalysis": {
246333              "graphics": {}
246334            },
246335            "considerations": {}
246336          }
246337        },
246338        {
246339          "type": "library",
246340          "bom-ref": "pkg:npm/request-promise-native@1.0.9?package-id=aaa680f997a6fc93",
246341          "supplier": {},
246342          "author": "Nicolai Kamenzky (https://github.com/analog-nico)",
246343          "name": "request-promise-native",
246344          "version": "1.0.9",
246345          "description": "The simplified HTTP request client 'request' with Promise support. Powered by native ES6 promises.",
246346          "licenses": [
246347            {
246348              "license": {
246349                "id": "ISC"
246350              }
246351            }
246352          ],
246353          "cpe": "cpe:2.3:a:request-promise-native:request-promise-native:1.0.9:*:*:*:*:*:*:*",
246354          "purl": "pkg:npm/request-promise-native@1.0.9",
246355          "swid": {
246356            "attachment": {}
246357          },
246358          "pedigree": {},
246359          "externalReferences": [
246360            {
246361              "url": "git+https://github.com/request/request-promise-native.git",
246362              "type": "distribution"
246363            },
246364            {
246365              "url": "https://github.com/request/request-promise-native#readme",
246366              "type": "website"
246367            }
246368          ],
246369          "evidence": {},
246370          "signature": {
246371            "signature": {
246372              "publicKey": {}
246373            }
246374          },
246375          "modelCard": {
246376            "modelParameters": {
246377              "approach": {}
246378            },
246379            "quantitativeAnalysis": {
246380              "graphics": {}
246381            },
246382            "considerations": {}
246383          }
246384        },
246385        {
246386          "type": "library",
246387          "bom-ref": "pkg:npm/require-from-string@2.0.2?package-id=739c440c697446fc",
246388          "supplier": {},
246389          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
246390          "name": "require-from-string",
246391          "version": "2.0.2",
246392          "description": "Require module from string",
246393          "licenses": [
246394            {
246395              "license": {
246396                "id": "MIT"
246397              }
246398            }
246399          ],
246400          "cpe": "cpe:2.3:a:require-from-string:require-from-string:2.0.2:*:*:*:*:*:*:*",
246401          "purl": "pkg:npm/require-from-string@2.0.2",
246402          "swid": {
246403            "attachment": {}
246404          },
246405          "pedigree": {},
246406          "externalReferences": [
246407            {
246408              "url": "floatdrop/require-from-string",
246409              "type": "distribution"
246410            }
246411          ],
246412          "evidence": {},
246413          "signature": {
246414            "signature": {
246415              "publicKey": {}
246416            }
246417          },
246418          "modelCard": {
246419            "modelParameters": {
246420              "approach": {}
246421            },
246422            "quantitativeAnalysis": {
246423              "graphics": {}
246424            },
246425            "considerations": {}
246426          }
246427        },
246428        {
246429          "type": "library",
246430          "bom-ref": "pkg:npm/require-module@0.1.0?package-id=c8de46f8af77b22a",
246431          "supplier": {},
246432          "author": "Thorsten Lorenz \u003cthlorenz@gmx.de\u003e (http://thlorenz.com)",
246433          "name": "require-module",
246434          "version": "0.1.0",
246435          "description": "Requires a module found relative to given root or working directory.",
246436          "licenses": [
246437            {
246438              "license": {
246439                "id": "MIT"
246440              }
246441            }
246442          ],
246443          "cpe": "cpe:2.3:a:require-module:require-module:0.1.0:*:*:*:*:*:*:*",
246444          "purl": "pkg:npm/require-module@0.1.0",
246445          "swid": {
246446            "attachment": {}
246447          },
246448          "pedigree": {},
246449          "externalReferences": [
246450            {
246451              "url": "git://github.com/thlorenz/require-module.git",
246452              "type": "distribution"
246453            },
246454            {
246455              "url": "https://github.com/thlorenz/require-module",
246456              "type": "website"
246457            }
246458          ],
246459          "evidence": {},
246460          "signature": {
246461            "signature": {
246462              "publicKey": {}
246463            }
246464          },
246465          "modelCard": {
246466            "modelParameters": {
246467              "approach": {}
246468            },
246469            "quantitativeAnalysis": {
246470              "graphics": {}
246471            },
246472            "considerations": {}
246473          }
246474        },
246475        {
246476          "type": "library",
246477          "bom-ref": "pkg:npm/resolve@0.6.3?package-id=644481495e094d7e",
246478          "supplier": {},
246479          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
246480          "name": "resolve",
246481          "version": "0.6.3",
246482          "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
246483          "licenses": [
246484            {
246485              "license": {
246486                "id": "MIT"
246487              }
246488            }
246489          ],
246490          "cpe": "cpe:2.3:a:substack:resolve:0.6.3:*:*:*:*:*:*:*",
246491          "purl": "pkg:npm/resolve@0.6.3",
246492          "swid": {
246493            "attachment": {}
246494          },
246495          "pedigree": {},
246496          "externalReferences": [
246497            {
246498              "url": "git://github.com/substack/node-resolve.git",
246499              "type": "distribution"
246500            }
246501          ],
246502          "evidence": {},
246503          "signature": {
246504            "signature": {
246505              "publicKey": {}
246506            }
246507          },
246508          "modelCard": {
246509            "modelParameters": {
246510              "approach": {}
246511            },
246512            "quantitativeAnalysis": {
246513              "graphics": {}
246514            },
246515            "considerations": {}
246516          }
246517        },
246518        {
246519          "type": "library",
246520          "bom-ref": "pkg:npm/rfdc@1.3.0?package-id=c42ea943f6301922",
246521          "supplier": {},
246522          "author": "David Mark Clements \u003cdavid.clements@nearform.com\u003e",
246523          "name": "rfdc",
246524          "version": "1.3.0",
246525          "description": "Really Fast Deep Clone",
246526          "licenses": [
246527            {
246528              "license": {
246529                "id": "MIT"
246530              }
246531            }
246532          ],
246533          "cpe": "cpe:2.3:a:davidmarkclements:rfdc:1.3.0:*:*:*:*:*:*:*",
246534          "purl": "pkg:npm/rfdc@1.3.0",
246535          "swid": {
246536            "attachment": {}
246537          },
246538          "pedigree": {},
246539          "externalReferences": [
246540            {
246541              "url": "git+https://github.com/davidmarkclements/rfdc.git",
246542              "type": "distribution"
246543            },
246544            {
246545              "url": "https://github.com/davidmarkclements/rfdc#readme",
246546              "type": "website"
246547            }
246548          ],
246549          "evidence": {},
246550          "signature": {
246551            "signature": {
246552              "publicKey": {}
246553            }
246554          },
246555          "modelCard": {
246556            "modelParameters": {
246557              "approach": {}
246558            },
246559            "quantitativeAnalysis": {
246560              "graphics": {}
246561            },
246562            "considerations": {}
246563          }
246564        },
246565        {
246566          "type": "library",
246567          "bom-ref": "pkg:npm/rxjs@6.6.7?package-id=4f05fae8827c5fc3",
246568          "supplier": {},
246569          "author": "Ben Lesh \u003cben@benlesh.com\u003e",
246570          "name": "rxjs",
246571          "version": "6.6.7",
246572          "description": "Reactive Extensions for modern JavaScript",
246573          "licenses": [
246574            {
246575              "license": {
246576                "id": "Apache-2.0"
246577              }
246578            }
246579          ],
246580          "cpe": "cpe:2.3:a:ReactiveX:rxjs:6.6.7:*:*:*:*:*:*:*",
246581          "purl": "pkg:npm/rxjs@6.6.7",
246582          "swid": {
246583            "attachment": {}
246584          },
246585          "pedigree": {},
246586          "externalReferences": [
246587            {
246588              "url": "https://github.com/reactivex/rxjs.git",
246589              "type": "distribution"
246590            },
246591            {
246592              "url": "https://github.com/ReactiveX/RxJS",
246593              "type": "website"
246594            }
246595          ],
246596          "evidence": {},
246597          "signature": {
246598            "signature": {
246599              "publicKey": {}
246600            }
246601          },
246602          "modelCard": {
246603            "modelParameters": {
246604              "approach": {}
246605            },
246606            "quantitativeAnalysis": {
246607              "graphics": {}
246608            },
246609            "considerations": {}
246610          }
246611        },
246612        {
246613          "type": "library",
246614          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=ad8e4b783ec0cc69",
246615          "supplier": {},
246616          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
246617          "name": "safe-buffer",
246618          "version": "5.1.2",
246619          "description": "Safer Node.js Buffer API",
246620          "licenses": [
246621            {
246622              "license": {
246623                "id": "MIT"
246624              }
246625            }
246626          ],
246627          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
246628          "purl": "pkg:npm/safe-buffer@5.1.2",
246629          "swid": {
246630            "attachment": {}
246631          },
246632          "pedigree": {},
246633          "externalReferences": [
246634            {
246635              "url": "git://github.com/feross/safe-buffer.git",
246636              "type": "distribution"
246637            },
246638            {
246639              "url": "https://github.com/feross/safe-buffer",
246640              "type": "website"
246641            }
246642          ],
246643          "evidence": {},
246644          "signature": {
246645            "signature": {
246646              "publicKey": {}
246647            }
246648          },
246649          "modelCard": {
246650            "modelParameters": {
246651              "approach": {}
246652            },
246653            "quantitativeAnalysis": {
246654              "graphics": {}
246655            },
246656            "considerations": {}
246657          }
246658        },
246659        {
246660          "type": "library",
246661          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=dea359a9da63b3e8",
246662          "supplier": {},
246663          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
246664          "name": "safe-buffer",
246665          "version": "5.2.1",
246666          "description": "Safer Node.js Buffer API",
246667          "licenses": [
246668            {
246669              "license": {
246670                "id": "MIT"
246671              }
246672            }
246673          ],
246674          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
246675          "purl": "pkg:npm/safe-buffer@5.2.1",
246676          "swid": {
246677            "attachment": {}
246678          },
246679          "pedigree": {},
246680          "externalReferences": [
246681            {
246682              "url": "git://github.com/feross/safe-buffer.git",
246683              "type": "distribution"
246684            },
246685            {
246686              "url": "https://github.com/feross/safe-buffer",
246687              "type": "website"
246688            }
246689          ],
246690          "evidence": {},
246691          "signature": {
246692            "signature": {
246693              "publicKey": {}
246694            }
246695          },
246696          "modelCard": {
246697            "modelParameters": {
246698              "approach": {}
246699            },
246700            "quantitativeAnalysis": {
246701              "graphics": {}
246702            },
246703            "considerations": {}
246704          }
246705        },
246706        {
246707          "type": "library",
246708          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=80f8422ca3238468",
246709          "supplier": {},
246710          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
246711          "name": "safer-buffer",
246712          "version": "2.1.2",
246713          "description": "Modern Buffer API polyfill without footguns",
246714          "licenses": [
246715            {
246716              "license": {
246717                "id": "MIT"
246718              }
246719            }
246720          ],
246721          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
246722          "purl": "pkg:npm/safer-buffer@2.1.2",
246723          "swid": {
246724            "attachment": {}
246725          },
246726          "pedigree": {},
246727          "externalReferences": [
246728            {
246729              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
246730              "type": "distribution"
246731            }
246732          ],
246733          "evidence": {},
246734          "signature": {
246735            "signature": {
246736              "publicKey": {}
246737            }
246738          },
246739          "modelCard": {
246740            "modelParameters": {
246741              "approach": {}
246742            },
246743            "quantitativeAnalysis": {
246744              "graphics": {}
246745            },
246746            "considerations": {}
246747          }
246748        },
246749        {
246750          "type": "library",
246751          "bom-ref": "pkg:apk/alpine/scanelf@1.2.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.11.13\u0026package-id=d7d0b4983b78c706",
246752          "supplier": {},
246753          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
246754          "name": "scanelf",
246755          "version": "1.2.4-r0",
246756          "description": "Scan ELF binaries for stuff",
246757          "licenses": [
246758            {
246759              "license": {
246760                "id": "GPL-2.0-only"
246761              }
246762            }
246763          ],
246764          "cpe": "cpe:2.3:a:scanelf:scanelf:1.2.4-r0:*:*:*:*:*:*:*",
246765          "purl": "pkg:apk/alpine/scanelf@1.2.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.11.13",
246766          "swid": {
246767            "attachment": {}
246768          },
246769          "pedigree": {},
246770          "externalReferences": [
246771            {
246772              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
246773              "type": "distribution"
246774            }
246775          ],
246776          "evidence": {},
246777          "signature": {
246778            "signature": {
246779              "publicKey": {}
246780            }
246781          },
246782          "modelCard": {
246783            "modelParameters": {
246784              "approach": {}
246785            },
246786            "quantitativeAnalysis": {
246787              "graphics": {}
246788            },
246789            "considerations": {}
246790          }
246791        },
246792        {
246793          "type": "library",
246794          "bom-ref": "pkg:npm/send@0.17.1?package-id=7dffc1d2e3f92043",
246795          "supplier": {},
246796          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
246797          "name": "send",
246798          "version": "0.17.1",
246799          "description": "Better streaming static file server with Range and conditional-GET support",
246800          "licenses": [
246801            {
246802              "license": {
246803                "id": "MIT"
246804              }
246805            }
246806          ],
246807          "cpe": "cpe:2.3:a:send:send:0.17.1:*:*:*:*:*:*:*",
246808          "purl": "pkg:npm/send@0.17.1",
246809          "swid": {
246810            "attachment": {}
246811          },
246812          "pedigree": {},
246813          "externalReferences": [
246814            {
246815              "url": "pillarjs/send",
246816              "type": "distribution"
246817            }
246818          ],
246819          "evidence": {},
246820          "signature": {
246821            "signature": {
246822              "publicKey": {}
246823            }
246824          },
246825          "modelCard": {
246826            "modelParameters": {
246827              "approach": {}
246828            },
246829            "quantitativeAnalysis": {
246830              "graphics": {}
246831            },
246832            "considerations": {}
246833          }
246834        },
246835        {
246836          "type": "library",
246837          "bom-ref": "pkg:npm/serve-static@1.14.1?package-id=f832e52e2d8996cb",
246838          "supplier": {},
246839          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
246840          "name": "serve-static",
246841          "version": "1.14.1",
246842          "description": "Serve static files",
246843          "licenses": [
246844            {
246845              "license": {
246846                "id": "MIT"
246847              }
246848            }
246849          ],
246850          "cpe": "cpe:2.3:a:serve-static:serve-static:1.14.1:*:*:*:*:*:*:*",
246851          "purl": "pkg:npm/serve-static@1.14.1",
246852          "swid": {
246853            "attachment": {}
246854          },
246855          "pedigree": {},
246856          "externalReferences": [
246857            {
246858              "url": "expressjs/serve-static",
246859              "type": "distribution"
246860            }
246861          ],
246862          "evidence": {},
246863          "signature": {
246864            "signature": {
246865              "publicKey": {}
246866            }
246867          },
246868          "modelCard": {
246869            "modelParameters": {
246870              "approach": {}
246871            },
246872            "quantitativeAnalysis": {
246873              "graphics": {}
246874            },
246875            "considerations": {}
246876          }
246877        },
246878        {
246879          "type": "library",
246880          "bom-ref": "pkg:npm/setprototypeof@1.1.1?package-id=32889ff192d43014",
246881          "supplier": {},
246882          "author": "Wes Todd",
246883          "name": "setprototypeof",
246884          "version": "1.1.1",
246885          "description": "A small polyfill for Object.setprototypeof",
246886          "licenses": [
246887            {
246888              "license": {
246889                "id": "ISC"
246890              }
246891            }
246892          ],
246893          "cpe": "cpe:2.3:a:setprototypeof:setprototypeof:1.1.1:*:*:*:*:*:*:*",
246894          "purl": "pkg:npm/setprototypeof@1.1.1",
246895          "swid": {
246896            "attachment": {}
246897          },
246898          "pedigree": {},
246899          "externalReferences": [
246900            {
246901              "url": "https://github.com/wesleytodd/setprototypeof.git",
246902              "type": "distribution"
246903            },
246904            {
246905              "url": "https://github.com/wesleytodd/setprototypeof",
246906              "type": "website"
246907            }
246908          ],
246909          "evidence": {},
246910          "signature": {
246911            "signature": {
246912              "publicKey": {}
246913            }
246914          },
246915          "modelCard": {
246916            "modelParameters": {
246917              "approach": {}
246918            },
246919            "quantitativeAnalysis": {
246920              "graphics": {}
246921            },
246922            "considerations": {}
246923          }
246924        },
246925        {
246926          "type": "library",
246927          "bom-ref": "pkg:npm/sprintf-js@1.0.3?package-id=e69a185108240b00",
246928          "supplier": {},
246929          "author": "Alexandru Marasteanu \u003chello@alexei.ro\u003e (http://alexei.ro/)",
246930          "name": "sprintf-js",
246931          "version": "1.0.3",
246932          "description": "JavaScript sprintf implementation",
246933          "licenses": [
246934            {
246935              "license": {
246936                "id": "BSD-3-Clause"
246937              }
246938            }
246939          ],
246940          "cpe": "cpe:2.3:a:sprintf-js:sprintf-js:1.0.3:*:*:*:*:*:*:*",
246941          "purl": "pkg:npm/sprintf-js@1.0.3",
246942          "swid": {
246943            "attachment": {}
246944          },
246945          "pedigree": {},
246946          "externalReferences": [
246947            {
246948              "url": "https://github.com/alexei/sprintf.js.git",
246949              "type": "distribution"
246950            }
246951          ],
246952          "evidence": {},
246953          "signature": {
246954            "signature": {
246955              "publicKey": {}
246956            }
246957          },
246958          "modelCard": {
246959            "modelParameters": {
246960              "approach": {}
246961            },
246962            "quantitativeAnalysis": {
246963              "graphics": {}
246964            },
246965            "considerations": {}
246966          }
246967        },
246968        {
246969          "type": "library",
246970          "bom-ref": "pkg:npm/sshpk@1.17.0?package-id=7fcc111acb9b8e10",
246971          "supplier": {},
246972          "author": "Joyent, Inc",
246973          "name": "sshpk",
246974          "version": "1.17.0",
246975          "description": "A library for finding and using SSH public keys",
246976          "licenses": [
246977            {
246978              "license": {
246979                "id": "MIT"
246980              }
246981            }
246982          ],
246983          "cpe": "cpe:2.3:a:arekinath:sshpk:1.17.0:*:*:*:*:*:*:*",
246984          "purl": "pkg:npm/sshpk@1.17.0",
246985          "swid": {
246986            "attachment": {}
246987          },
246988          "pedigree": {},
246989          "externalReferences": [
246990            {
246991              "url": "git+https://github.com/joyent/node-sshpk.git",
246992              "type": "distribution"
246993            },
246994            {
246995              "url": "https://github.com/arekinath/node-sshpk#readme",
246996              "type": "website"
246997            }
246998          ],
246999          "evidence": {},
247000          "signature": {
247001            "signature": {
247002              "publicKey": {}
247003            }
247004          },
247005          "modelCard": {
247006            "modelParameters": {
247007              "approach": {}
247008            },
247009            "quantitativeAnalysis": {
247010              "graphics": {}
247011            },
247012            "considerations": {}
247013          }
247014        },
247015        {
247016          "type": "library",
247017          "bom-ref": "pkg:apk/alpine/ssl_client@1.31.1-r11?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.11.13\u0026package-id=685c6f235663ea24",
247018          "supplier": {},
247019          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
247020          "name": "ssl_client",
247021          "version": "1.31.1-r11",
247022          "description": "EXternal ssl_client for busybox wget",
247023          "licenses": [
247024            {
247025              "license": {
247026                "id": "GPL-2.0-only"
247027              }
247028            }
247029          ],
247030          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.31.1-r11:*:*:*:*:*:*:*",
247031          "purl": "pkg:apk/alpine/ssl_client@1.31.1-r11?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.11.13",
247032          "swid": {
247033            "attachment": {}
247034          },
247035          "pedigree": {},
247036          "externalReferences": [
247037            {
247038              "url": "https://busybox.net/",
247039              "type": "distribution"
247040            }
247041          ],
247042          "evidence": {},
247043          "signature": {
247044            "signature": {
247045              "publicKey": {}
247046            }
247047          },
247048          "modelCard": {
247049            "modelParameters": {
247050              "approach": {}
247051            },
247052            "quantitativeAnalysis": {
247053              "graphics": {}
247054            },
247055            "considerations": {}
247056          }
247057        },
247058        {
247059          "type": "library",
247060          "bom-ref": "pkg:npm/statuses@1.5.0?package-id=7ab4b68e7e88520b",
247061          "supplier": {},
247062          "name": "statuses",
247063          "version": "1.5.0",
247064          "description": "HTTP status utility",
247065          "licenses": [
247066            {
247067              "license": {
247068                "id": "MIT"
247069              }
247070            }
247071          ],
247072          "cpe": "cpe:2.3:a:statuses:statuses:1.5.0:*:*:*:*:*:*:*",
247073          "purl": "pkg:npm/statuses@1.5.0",
247074          "swid": {
247075            "attachment": {}
247076          },
247077          "pedigree": {},
247078          "externalReferences": [
247079            {
247080              "url": "jshttp/statuses",
247081              "type": "distribution"
247082            }
247083          ],
247084          "evidence": {},
247085          "signature": {
247086            "signature": {
247087              "publicKey": {}
247088            }
247089          },
247090          "modelCard": {
247091            "modelParameters": {
247092              "approach": {}
247093            },
247094            "quantitativeAnalysis": {
247095              "graphics": {}
247096            },
247097            "considerations": {}
247098          }
247099        },
247100        {
247101          "type": "library",
247102          "bom-ref": "pkg:npm/stealthy-require@1.1.1?package-id=c9d362abc885b44",
247103          "supplier": {},
247104          "author": "Nicolai Kamenzky (https://github.com/analog-nico)",
247105          "name": "stealthy-require",
247106          "version": "1.1.1",
247107          "description": "The closest you can get to require something with bypassing the require cache",
247108          "licenses": [
247109            {
247110              "license": {
247111                "id": "ISC"
247112              }
247113            }
247114          ],
247115          "cpe": "cpe:2.3:a:stealthy-require:stealthy-require:1.1.1:*:*:*:*:*:*:*",
247116          "purl": "pkg:npm/stealthy-require@1.1.1",
247117          "swid": {
247118            "attachment": {}
247119          },
247120          "pedigree": {},
247121          "externalReferences": [
247122            {
247123              "url": "git+https://github.com/analog-nico/stealthy-require.git",
247124              "type": "distribution"
247125            },
247126            {
247127              "url": "https://github.com/analog-nico/stealthy-require#readme",
247128              "type": "website"
247129            }
247130          ],
247131          "evidence": {},
247132          "signature": {
247133            "signature": {
247134              "publicKey": {}
247135            }
247136          },
247137          "modelCard": {
247138            "modelParameters": {
247139              "approach": {}
247140            },
247141            "quantitativeAnalysis": {
247142              "graphics": {}
247143            },
247144            "considerations": {}
247145          }
247146        },
247147        {
247148          "type": "library",
247149          "bom-ref": "pkg:npm/streamsearch@0.1.2?package-id=816d843ca19c8f00",
247150          "supplier": {},
247151          "author": "Brian White \u003cmscdex@mscdex.net\u003e",
247152          "name": "streamsearch",
247153          "version": "0.1.2",
247154          "description": "Streaming Boyer-Moore-Horspool searching for node.js",
247155          "licenses": [
247156            {
247157              "license": {
247158                "id": "MIT"
247159              }
247160            }
247161          ],
247162          "cpe": "cpe:2.3:a:streamsearch:streamsearch:0.1.2:*:*:*:*:*:*:*",
247163          "purl": "pkg:npm/streamsearch@0.1.2",
247164          "swid": {
247165            "attachment": {}
247166          },
247167          "pedigree": {},
247168          "externalReferences": [
247169            {
247170              "url": "http://github.com/mscdex/streamsearch.git",
247171              "type": "distribution"
247172            }
247173          ],
247174          "evidence": {},
247175          "signature": {
247176            "signature": {
247177              "publicKey": {}
247178            }
247179          },
247180          "modelCard": {
247181            "modelParameters": {
247182              "approach": {}
247183            },
247184            "quantitativeAnalysis": {
247185              "graphics": {}
247186            },
247187            "considerations": {}
247188          }
247189        },
247190        {
247191          "type": "library",
247192          "bom-ref": "pkg:npm/string_decoder@0.10.31?package-id=842458f1d210431a",
247193          "supplier": {},
247194          "name": "string_decoder",
247195          "version": "0.10.31",
247196          "description": "The string_decoder module from Node core",
247197          "licenses": [
247198            {
247199              "license": {
247200                "id": "MIT"
247201              }
247202            }
247203          ],
247204          "cpe": "cpe:2.3:a:string-decoder:string-decoder:0.10.31:*:*:*:*:*:*:*",
247205          "purl": "pkg:npm/string_decoder@0.10.31",
247206          "swid": {
247207            "attachment": {}
247208          },
247209          "pedigree": {},
247210          "externalReferences": [
247211            {
247212              "url": "git://github.com/rvagg/string_decoder.git",
247213              "type": "distribution"
247214            },
247215            {
247216              "url": "https://github.com/rvagg/string_decoder",
247217              "type": "website"
247218            }
247219          ],
247220          "evidence": {},
247221          "signature": {
247222            "signature": {
247223              "publicKey": {}
247224            }
247225          },
247226          "modelCard": {
247227            "modelParameters": {
247228              "approach": {}
247229            },
247230            "quantitativeAnalysis": {
247231              "graphics": {}
247232            },
247233            "considerations": {}
247234          }
247235        },
247236        {
247237          "type": "library",
247238          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=a6eeeaeb8b6353ea",
247239          "supplier": {},
247240          "name": "string_decoder",
247241          "version": "1.1.1",
247242          "description": "The string_decoder module from Node core",
247243          "licenses": [
247244            {
247245              "license": {
247246                "id": "MIT"
247247              }
247248            }
247249          ],
247250          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
247251          "purl": "pkg:npm/string_decoder@1.1.1",
247252          "swid": {
247253            "attachment": {}
247254          },
247255          "pedigree": {},
247256          "externalReferences": [
247257            {
247258              "url": "git://github.com/nodejs/string_decoder.git",
247259              "type": "distribution"
247260            },
247261            {
247262              "url": "https://github.com/nodejs/string_decoder",
247263              "type": "website"
247264            }
247265          ],
247266          "evidence": {},
247267          "signature": {
247268            "signature": {
247269              "publicKey": {}
247270            }
247271          },
247272          "modelCard": {
247273            "modelParameters": {
247274              "approach": {}
247275            },
247276            "quantitativeAnalysis": {
247277              "graphics": {}
247278            },
247279            "considerations": {}
247280          }
247281        },
247282        {
247283          "type": "library",
247284          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=804f0a28a30f2774",
247285          "supplier": {},
247286          "name": "string_decoder",
247287          "version": "1.3.0",
247288          "description": "The string_decoder module from Node core",
247289          "licenses": [
247290            {
247291              "license": {
247292                "id": "MIT"
247293              }
247294            }
247295          ],
247296          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
247297          "purl": "pkg:npm/string_decoder@1.3.0",
247298          "swid": {
247299            "attachment": {}
247300          },
247301          "pedigree": {},
247302          "externalReferences": [
247303            {
247304              "url": "git://github.com/nodejs/string_decoder.git",
247305              "type": "distribution"
247306            },
247307            {
247308              "url": "https://github.com/nodejs/string_decoder",
247309              "type": "website"
247310            }
247311          ],
247312          "evidence": {},
247313          "signature": {
247314            "signature": {
247315              "publicKey": {}
247316            }
247317          },
247318          "modelCard": {
247319            "modelParameters": {
247320              "approach": {}
247321            },
247322            "quantitativeAnalysis": {
247323              "graphics": {}
247324            },
247325            "considerations": {}
247326          }
247327        },
247328        {
247329          "type": "library",
247330          "bom-ref": "pkg:npm/supports-color@7.2.0?package-id=b12cfc056aff0a2a",
247331          "supplier": {},
247332          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
247333          "name": "supports-color",
247334          "version": "7.2.0",
247335          "description": "Detect whether a terminal supports color",
247336          "licenses": [
247337            {
247338              "license": {
247339                "id": "MIT"
247340              }
247341            }
247342          ],
247343          "cpe": "cpe:2.3:a:supports-color:supports-color:7.2.0:*:*:*:*:*:*:*",
247344          "purl": "pkg:npm/supports-color@7.2.0",
247345          "swid": {
247346            "attachment": {}
247347          },
247348          "pedigree": {},
247349          "externalReferences": [
247350            {
247351              "url": "chalk/supports-color",
247352              "type": "distribution"
247353            }
247354          ],
247355          "evidence": {},
247356          "signature": {
247357            "signature": {
247358              "publicKey": {}
247359            }
247360          },
247361          "modelCard": {
247362            "modelParameters": {
247363              "approach": {}
247364            },
247365            "quantitativeAnalysis": {
247366              "graphics": {}
247367            },
247368            "considerations": {}
247369          }
247370        },
247371        {
247372          "type": "library",
247373          "bom-ref": "pkg:npm/swagger-ui-dist@4.14.2?package-id=d5d4acd98ac04772",
247374          "supplier": {},
247375          "name": "swagger-ui-dist",
247376          "version": "4.14.2",
247377          "licenses": [
247378            {
247379              "license": {
247380                "id": "Apache-2.0"
247381              }
247382            }
247383          ],
247384          "cpe": "cpe:2.3:a:swagger-ui-dist:swagger-ui-dist:4.14.2:*:*:*:*:*:*:*",
247385          "purl": "pkg:npm/swagger-ui-dist@4.14.2",
247386          "swid": {
247387            "attachment": {}
247388          },
247389          "pedigree": {},
247390          "externalReferences": [
247391            {
247392              "url": "git@github.com:swagger-api/swagger-ui.git",
247393              "type": "distribution"
247394            }
247395          ],
247396          "evidence": {},
247397          "signature": {
247398            "signature": {
247399              "publicKey": {}
247400            }
247401          },
247402          "modelCard": {
247403            "modelParameters": {
247404              "approach": {}
247405            },
247406            "quantitativeAnalysis": {
247407              "graphics": {}
247408            },
247409            "considerations": {}
247410          }
247411        },
247412        {
247413          "type": "library",
247414          "bom-ref": "pkg:npm/swagger-ui-express@4.5.0?package-id=2634b6d602813a49",
247415          "supplier": {},
247416          "author": "Stephen Scott \u003cscottie1984@gmail.com\u003e",
247417          "name": "swagger-ui-express",
247418          "version": "4.5.0",
247419          "description": "Swagger UI Express",
247420          "licenses": [
247421            {
247422              "license": {
247423                "id": "MIT"
247424              }
247425            }
247426          ],
247427          "cpe": "cpe:2.3:a:swagger-ui-express:swagger-ui-express:4.5.0:*:*:*:*:*:*:*",
247428          "purl": "pkg:npm/swagger-ui-express@4.5.0",
247429          "swid": {
247430            "attachment": {}
247431          },
247432          "pedigree": {},
247433          "externalReferences": [
247434            {
247435              "url": "git@github.com:scottie1984/swagger-ui-express.git",
247436              "type": "distribution"
247437            },
247438            {
247439              "url": "https://github.com/scottie1984/swagger-ui-express",
247440              "type": "website"
247441            }
247442          ],
247443          "evidence": {},
247444          "signature": {
247445            "signature": {
247446              "publicKey": {}
247447            }
247448          },
247449          "modelCard": {
247450            "modelParameters": {
247451              "approach": {}
247452            },
247453            "quantitativeAnalysis": {
247454              "graphics": {}
247455            },
247456            "considerations": {}
247457          }
247458        },
247459        {
247460          "type": "library",
247461          "bom-ref": "pkg:npm/toidentifier@1.0.0?package-id=73e3300187220c93",
247462          "supplier": {},
247463          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
247464          "name": "toidentifier",
247465          "version": "1.0.0",
247466          "description": "Convert a string of words to a JavaScript identifier",
247467          "licenses": [
247468            {
247469              "license": {
247470                "id": "MIT"
247471              }
247472            }
247473          ],
247474          "cpe": "cpe:2.3:a:toidentifier:toidentifier:1.0.0:*:*:*:*:*:*:*",
247475          "purl": "pkg:npm/toidentifier@1.0.0",
247476          "swid": {
247477            "attachment": {}
247478          },
247479          "pedigree": {},
247480          "externalReferences": [
247481            {
247482              "url": "component/toidentifier",
247483              "type": "distribution"
247484            }
247485          ],
247486          "evidence": {},
247487          "signature": {
247488            "signature": {
247489              "publicKey": {}
247490            }
247491          },
247492          "modelCard": {
247493            "modelParameters": {
247494              "approach": {}
247495            },
247496            "quantitativeAnalysis": {
247497              "graphics": {}
247498            },
247499            "considerations": {}
247500          }
247501        },
247502        {
247503          "type": "library",
247504          "bom-ref": "pkg:npm/tough-cookie@2.5.0?package-id=84ac1ba3e7a7e035",
247505          "supplier": {},
247506          "author": "Jeremy Stashewsky \u003cjstash@gmail.com\u003e",
247507          "name": "tough-cookie",
247508          "version": "2.5.0",
247509          "description": "RFC6265 Cookies and Cookie Jar for node.js",
247510          "licenses": [
247511            {
247512              "license": {
247513                "id": "BSD-3-Clause"
247514              }
247515            }
247516          ],
247517          "cpe": "cpe:2.3:a:tough-cookie:tough-cookie:2.5.0:*:*:*:*:*:*:*",
247518          "purl": "pkg:npm/tough-cookie@2.5.0",
247519          "swid": {
247520            "attachment": {}
247521          },
247522          "pedigree": {},
247523          "externalReferences": [
247524            {
247525              "url": "git://github.com/salesforce/tough-cookie.git",
247526              "type": "distribution"
247527            },
247528            {
247529              "url": "https://github.com/salesforce/tough-cookie",
247530              "type": "website"
247531            }
247532          ],
247533          "evidence": {},
247534          "signature": {
247535            "signature": {
247536              "publicKey": {}
247537            }
247538          },
247539          "modelCard": {
247540            "modelParameters": {
247541              "approach": {}
247542            },
247543            "quantitativeAnalysis": {
247544              "graphics": {}
247545            },
247546            "considerations": {}
247547          }
247548        },
247549        {
247550          "type": "library",
247551          "bom-ref": "pkg:npm/tr46@0.0.3?package-id=d3c5ac58d5c51d2a",
247552          "supplier": {},
247553          "author": "Sebastian Mayr \u003cnpm@smayr.name\u003e",
247554          "name": "tr46",
247555          "version": "0.0.3",
247556          "description": "An implementation of the Unicode TR46 spec",
247557          "licenses": [
247558            {
247559              "license": {
247560                "id": "MIT"
247561              }
247562            }
247563          ],
247564          "cpe": "cpe:2.3:a:Sebmaster:tr46:0.0.3:*:*:*:*:*:*:*",
247565          "purl": "pkg:npm/tr46@0.0.3",
247566          "swid": {
247567            "attachment": {}
247568          },
247569          "pedigree": {},
247570          "externalReferences": [
247571            {
247572              "url": "git+https://github.com/Sebmaster/tr46.js.git",
247573              "type": "distribution"
247574            },
247575            {
247576              "url": "https://github.com/Sebmaster/tr46.js#readme",
247577              "type": "website"
247578            }
247579          ],
247580          "evidence": {},
247581          "signature": {
247582            "signature": {
247583              "publicKey": {}
247584            }
247585          },
247586          "modelCard": {
247587            "modelParameters": {
247588              "approach": {}
247589            },
247590            "quantitativeAnalysis": {
247591              "graphics": {}
247592            },
247593            "considerations": {}
247594          }
247595        },
247596        {
247597          "type": "library",
247598          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=111a065e7906003c",
247599          "supplier": {},
247600          "author": "Microsoft Corp.",
247601          "name": "tslib",
247602          "version": "1.14.1",
247603          "description": "Runtime library for TypeScript helper functions",
247604          "licenses": [
247605            {
247606              "license": {
247607                "id": "0BSD"
247608              }
247609            }
247610          ],
247611          "cpe": "cpe:2.3:a:Microsoft:tslib:1.14.1:*:*:*:*:*:*:*",
247612          "purl": "pkg:npm/tslib@1.14.1",
247613          "swid": {
247614            "attachment": {}
247615          },
247616          "pedigree": {},
247617          "externalReferences": [
247618            {
247619              "url": "https://github.com/Microsoft/tslib.git",
247620              "type": "distribution"
247621            },
247622            {
247623              "url": "https://www.typescriptlang.org/",
247624              "type": "website"
247625            }
247626          ],
247627          "evidence": {},
247628          "signature": {
247629            "signature": {
247630              "publicKey": {}
247631            }
247632          },
247633          "modelCard": {
247634            "modelParameters": {
247635              "approach": {}
247636            },
247637            "quantitativeAnalysis": {
247638              "graphics": {}
247639            },
247640            "considerations": {}
247641          }
247642        },
247643        {
247644          "type": "library",
247645          "bom-ref": "pkg:npm/tslib@2.2.0?package-id=eff17310e4ba5bda",
247646          "supplier": {},
247647          "author": "Microsoft Corp.",
247648          "name": "tslib",
247649          "version": "2.2.0",
247650          "description": "Runtime library for TypeScript helper functions",
247651          "licenses": [
247652            {
247653              "license": {
247654                "id": "0BSD"
247655              }
247656            }
247657          ],
247658          "cpe": "cpe:2.3:a:Microsoft:tslib:2.2.0:*:*:*:*:*:*:*",
247659          "purl": "pkg:npm/tslib@2.2.0",
247660          "swid": {
247661            "attachment": {}
247662          },
247663          "pedigree": {},
247664          "externalReferences": [
247665            {
247666              "url": "https://github.com/Microsoft/tslib.git",
247667              "type": "distribution"
247668            },
247669            {
247670              "url": "https://www.typescriptlang.org/",
247671              "type": "website"
247672            }
247673          ],
247674          "evidence": {},
247675          "signature": {
247676            "signature": {
247677              "publicKey": {}
247678            }
247679          },
247680          "modelCard": {
247681            "modelParameters": {
247682              "approach": {}
247683            },
247684            "quantitativeAnalysis": {
247685              "graphics": {}
247686            },
247687            "considerations": {}
247688          }
247689        },
247690        {
247691          "type": "library",
247692          "bom-ref": "pkg:npm/tunnel-agent@0.6.0?package-id=69b71945e64f48cf",
247693          "supplier": {},
247694          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
247695          "name": "tunnel-agent",
247696          "version": "0.6.0",
247697          "description": "HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.",
247698          "licenses": [
247699            {
247700              "license": {
247701                "id": "Apache-2.0"
247702              }
247703            }
247704          ],
247705          "cpe": "cpe:2.3:a:tunnel-agent:tunnel-agent:0.6.0:*:*:*:*:*:*:*",
247706          "purl": "pkg:npm/tunnel-agent@0.6.0",
247707          "swid": {
247708            "attachment": {}
247709          },
247710          "pedigree": {},
247711          "externalReferences": [
247712            {
247713              "url": "https://github.com/mikeal/tunnel-agent",
247714              "type": "distribution"
247715            }
247716          ],
247717          "evidence": {},
247718          "signature": {
247719            "signature": {
247720              "publicKey": {}
247721            }
247722          },
247723          "modelCard": {
247724            "modelParameters": {
247725              "approach": {}
247726            },
247727            "quantitativeAnalysis": {
247728              "graphics": {}
247729            },
247730            "considerations": {}
247731          }
247732        },
247733        {
247734          "type": "library",
247735          "bom-ref": "pkg:npm/tweetnacl@0.14.5?package-id=50d7cd01e6907a9a",
247736          "supplier": {},
247737          "author": "TweetNaCl-js contributors",
247738          "name": "tweetnacl",
247739          "version": "0.14.5",
247740          "description": "Port of TweetNaCl cryptographic library to JavaScript",
247741          "licenses": [
247742            {
247743              "license": {
247744                "id": "Unlicense"
247745              }
247746            }
247747          ],
247748          "cpe": "cpe:2.3:a:tweetnacl:tweetnacl:0.14.5:*:*:*:*:*:*:*",
247749          "purl": "pkg:npm/tweetnacl@0.14.5",
247750          "swid": {
247751            "attachment": {}
247752          },
247753          "pedigree": {},
247754          "externalReferences": [
247755            {
247756              "url": "https://github.com/dchest/tweetnacl-js.git",
247757              "type": "distribution"
247758            },
247759            {
247760              "url": "https://tweetnacl.js.org",
247761              "type": "website"
247762            }
247763          ],
247764          "evidence": {},
247765          "signature": {
247766            "signature": {
247767              "publicKey": {}
247768            }
247769          },
247770          "modelCard": {
247771            "modelParameters": {
247772              "approach": {}
247773            },
247774            "quantitativeAnalysis": {
247775              "graphics": {}
247776            },
247777            "considerations": {}
247778          }
247779        },
247780        {
247781          "type": "library",
247782          "bom-ref": "pkg:npm/type-is@1.6.18?package-id=9b3a78dcc8cb74b9",
247783          "supplier": {},
247784          "name": "type-is",
247785          "version": "1.6.18",
247786          "description": "Infer the content-type of a request.",
247787          "licenses": [
247788            {
247789              "license": {
247790                "id": "MIT"
247791              }
247792            }
247793          ],
247794          "cpe": "cpe:2.3:a:type-is:type-is:1.6.18:*:*:*:*:*:*:*",
247795          "purl": "pkg:npm/type-is@1.6.18",
247796          "swid": {
247797            "attachment": {}
247798          },
247799          "pedigree": {},
247800          "externalReferences": [
247801            {
247802              "url": "jshttp/type-is",
247803              "type": "distribution"
247804            }
247805          ],
247806          "evidence": {},
247807          "signature": {
247808            "signature": {
247809              "publicKey": {}
247810            }
247811          },
247812          "modelCard": {
247813            "modelParameters": {
247814              "approach": {}
247815            },
247816            "quantitativeAnalysis": {
247817              "graphics": {}
247818            },
247819            "considerations": {}
247820          }
247821        },
247822        {
247823          "type": "library",
247824          "bom-ref": "pkg:npm/typedarray@0.0.6?package-id=f7beac06324a3356",
247825          "supplier": {},
247826          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
247827          "name": "typedarray",
247828          "version": "0.0.6",
247829          "description": "TypedArray polyfill for old browsers",
247830          "licenses": [
247831            {
247832              "license": {
247833                "id": "MIT"
247834              }
247835            }
247836          ],
247837          "cpe": "cpe:2.3:a:typedarray:typedarray:0.0.6:*:*:*:*:*:*:*",
247838          "purl": "pkg:npm/typedarray@0.0.6",
247839          "swid": {
247840            "attachment": {}
247841          },
247842          "pedigree": {},
247843          "externalReferences": [
247844            {
247845              "url": "git://github.com/substack/typedarray.git",
247846              "type": "distribution"
247847            },
247848            {
247849              "url": "https://github.com/substack/typedarray",
247850              "type": "website"
247851            }
247852          ],
247853          "evidence": {},
247854          "signature": {
247855            "signature": {
247856              "publicKey": {}
247857            }
247858          },
247859          "modelCard": {
247860            "modelParameters": {
247861              "approach": {}
247862            },
247863            "quantitativeAnalysis": {
247864              "graphics": {}
247865            },
247866            "considerations": {}
247867          }
247868        },
247869        {
247870          "type": "library",
247871          "bom-ref": "pkg:npm/unpipe@1.0.0?package-id=fae35ea8f5714b2b",
247872          "supplier": {},
247873          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
247874          "name": "unpipe",
247875          "version": "1.0.0",
247876          "description": "Unpipe a stream from all destinations",
247877          "licenses": [
247878            {
247879              "license": {
247880                "id": "MIT"
247881              }
247882            }
247883          ],
247884          "cpe": "cpe:2.3:a:unpipe:unpipe:1.0.0:*:*:*:*:*:*:*",
247885          "purl": "pkg:npm/unpipe@1.0.0",
247886          "swid": {
247887            "attachment": {}
247888          },
247889          "pedigree": {},
247890          "externalReferences": [
247891            {
247892              "url": "stream-utils/unpipe",
247893              "type": "distribution"
247894            }
247895          ],
247896          "evidence": {},
247897          "signature": {
247898            "signature": {
247899              "publicKey": {}
247900            }
247901          },
247902          "modelCard": {
247903            "modelParameters": {
247904              "approach": {}
247905            },
247906            "quantitativeAnalysis": {
247907              "graphics": {}
247908            },
247909            "considerations": {}
247910          }
247911        },
247912        {
247913          "type": "library",
247914          "bom-ref": "pkg:npm/uri-js@4.4.1?package-id=a32c58744bdbe4c2",
247915          "supplier": {},
247916          "author": "Gary Court \u003cgary.court@gmail.com\u003e",
247917          "name": "uri-js",
247918          "version": "4.4.1",
247919          "description": "An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.",
247920          "licenses": [
247921            {
247922              "license": {
247923                "id": "BSD-2-Clause"
247924              }
247925            }
247926          ],
247927          "cpe": "cpe:2.3:a:garycourt:uri-js:4.4.1:*:*:*:*:*:*:*",
247928          "purl": "pkg:npm/uri-js@4.4.1",
247929          "swid": {
247930            "attachment": {}
247931          },
247932          "pedigree": {},
247933          "externalReferences": [
247934            {
247935              "url": "http://github.com/garycourt/uri-js",
247936              "type": "distribution"
247937            },
247938            {
247939              "url": "https://github.com/garycourt/uri-js",
247940              "type": "website"
247941            }
247942          ],
247943          "evidence": {},
247944          "signature": {
247945            "signature": {
247946              "publicKey": {}
247947            }
247948          },
247949          "modelCard": {
247950            "modelParameters": {
247951              "approach": {}
247952            },
247953            "quantitativeAnalysis": {
247954              "graphics": {}
247955            },
247956            "considerations": {}
247957          }
247958        },
247959        {
247960          "type": "library",
247961          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=adcfe60f42b3bf40",
247962          "supplier": {},
247963          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
247964          "name": "util-deprecate",
247965          "version": "1.0.2",
247966          "description": "The Node.js `util.deprecate()` function with browser support",
247967          "licenses": [
247968            {
247969              "license": {
247970                "id": "MIT"
247971              }
247972            }
247973          ],
247974          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
247975          "purl": "pkg:npm/util-deprecate@1.0.2",
247976          "swid": {
247977            "attachment": {}
247978          },
247979          "pedigree": {},
247980          "externalReferences": [
247981            {
247982              "url": "git://github.com/TooTallNate/util-deprecate.git",
247983              "type": "distribution"
247984            },
247985            {
247986              "url": "https://github.com/TooTallNate/util-deprecate",
247987              "type": "website"
247988            }
247989          ],
247990          "evidence": {},
247991          "signature": {
247992            "signature": {
247993              "publicKey": {}
247994            }
247995          },
247996          "modelCard": {
247997            "modelParameters": {
247998              "approach": {}
247999            },
248000            "quantitativeAnalysis": {
248001              "graphics": {}
248002            },
248003            "considerations": {}
248004          }
248005        },
248006        {
248007          "type": "library",
248008          "bom-ref": "pkg:npm/utils-merge@1.0.1?package-id=64d85338bee3696b",
248009          "supplier": {},
248010          "author": "Jared Hanson \u003cjaredhanson@gmail.com\u003e (http://www.jaredhanson.net/)",
248011          "name": "utils-merge",
248012          "version": "1.0.1",
248013          "description": "merge() utility function",
248014          "licenses": [
248015            {
248016              "license": {
248017                "id": "MIT"
248018              }
248019            }
248020          ],
248021          "cpe": "cpe:2.3:a:jaredhanson:utils-merge:1.0.1:*:*:*:*:*:*:*",
248022          "purl": "pkg:npm/utils-merge@1.0.1",
248023          "swid": {
248024            "attachment": {}
248025          },
248026          "pedigree": {},
248027          "externalReferences": [
248028            {
248029              "url": "git://github.com/jaredhanson/utils-merge.git",
248030              "type": "distribution"
248031            }
248032          ],
248033          "evidence": {},
248034          "signature": {
248035            "signature": {
248036              "publicKey": {}
248037            }
248038          },
248039          "modelCard": {
248040            "modelParameters": {
248041              "approach": {}
248042            },
248043            "quantitativeAnalysis": {
248044              "graphics": {}
248045            },
248046            "considerations": {}
248047          }
248048        },
248049        {
248050          "type": "library",
248051          "bom-ref": "pkg:npm/uuid@3.4.0?package-id=91ce0de869a58a0b",
248052          "supplier": {},
248053          "name": "uuid",
248054          "version": "3.4.0",
248055          "description": "RFC4122 (v1, v4, and v5) UUIDs",
248056          "licenses": [
248057            {
248058              "license": {
248059                "id": "MIT"
248060              }
248061            }
248062          ],
248063          "cpe": "cpe:2.3:a:uuidjs:uuid:3.4.0:*:*:*:*:*:*:*",
248064          "purl": "pkg:npm/uuid@3.4.0",
248065          "swid": {
248066            "attachment": {}
248067          },
248068          "pedigree": {},
248069          "externalReferences": [
248070            {
248071              "url": "https://github.com/uuidjs/uuid.git",
248072              "type": "distribution"
248073            }
248074          ],
248075          "evidence": {},
248076          "signature": {
248077            "signature": {
248078              "publicKey": {}
248079            }
248080          },
248081          "modelCard": {
248082            "modelParameters": {
248083              "approach": {}
248084            },
248085            "quantitativeAnalysis": {
248086              "graphics": {}
248087            },
248088            "considerations": {}
248089          }
248090        },
248091        {
248092          "type": "library",
248093          "bom-ref": "pkg:npm/uuid@8.3.2?package-id=dfc52717da1a2dfb",
248094          "supplier": {},
248095          "name": "uuid",
248096          "version": "8.3.2",
248097          "description": "RFC4122 (v1, v4, and v5) UUIDs",
248098          "licenses": [
248099            {
248100              "license": {
248101                "id": "MIT"
248102              }
248103            }
248104          ],
248105          "cpe": "cpe:2.3:a:uuidjs:uuid:8.3.2:*:*:*:*:*:*:*",
248106          "purl": "pkg:npm/uuid@8.3.2",
248107          "swid": {
248108            "attachment": {}
248109          },
248110          "pedigree": {},
248111          "externalReferences": [
248112            {
248113              "url": "https://github.com/uuidjs/uuid.git",
248114              "type": "distribution"
248115            }
248116          ],
248117          "evidence": {},
248118          "signature": {
248119            "signature": {
248120              "publicKey": {}
248121            }
248122          },
248123          "modelCard": {
248124            "modelParameters": {
248125              "approach": {}
248126            },
248127            "quantitativeAnalysis": {
248128              "graphics": {}
248129            },
248130            "considerations": {}
248131          }
248132        },
248133        {
248134          "type": "library",
248135          "bom-ref": "pkg:npm/validator@13.0.0?package-id=b1acf0481cccb1e7",
248136          "supplier": {},
248137          "author": "Chris O'Hara \u003ccohara87@gmail.com\u003e",
248138          "name": "validator",
248139          "version": "13.0.0",
248140          "description": "String validation and sanitization",
248141          "licenses": [
248142            {
248143              "license": {
248144                "id": "MIT"
248145              }
248146            }
248147          ],
248148          "cpe": "cpe:2.3:a:validator:validator:13.0.0:*:*:*:*:*:*:*",
248149          "purl": "pkg:npm/validator@13.0.0",
248150          "swid": {
248151            "attachment": {}
248152          },
248153          "pedigree": {},
248154          "externalReferences": [
248155            {
248156              "url": "https://github.com/chriso/validator.js.git",
248157              "type": "distribution"
248158            },
248159            {
248160              "url": "https://github.com/chriso/validator.js",
248161              "type": "website"
248162            }
248163          ],
248164          "evidence": {},
248165          "signature": {
248166            "signature": {
248167              "publicKey": {}
248168            }
248169          },
248170          "modelCard": {
248171            "modelParameters": {
248172              "approach": {}
248173            },
248174            "quantitativeAnalysis": {
248175              "graphics": {}
248176            },
248177            "considerations": {}
248178          }
248179        },
248180        {
248181          "type": "library",
248182          "bom-ref": "pkg:npm/vary@1.1.2?package-id=5c4e624911744e1d",
248183          "supplier": {},
248184          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
248185          "name": "vary",
248186          "version": "1.1.2",
248187          "description": "Manipulate the HTTP Vary header",
248188          "licenses": [
248189            {
248190              "license": {
248191                "id": "MIT"
248192              }
248193            }
248194          ],
248195          "cpe": "cpe:2.3:a:vary:vary:1.1.2:*:*:*:*:*:*:*",
248196          "purl": "pkg:npm/vary@1.1.2",
248197          "swid": {
248198            "attachment": {}
248199          },
248200          "pedigree": {},
248201          "externalReferences": [
248202            {
248203              "url": "jshttp/vary",
248204              "type": "distribution"
248205            }
248206          ],
248207          "evidence": {},
248208          "signature": {
248209            "signature": {
248210              "publicKey": {}
248211            }
248212          },
248213          "modelCard": {
248214            "modelParameters": {
248215              "approach": {}
248216            },
248217            "quantitativeAnalysis": {
248218              "graphics": {}
248219            },
248220            "considerations": {}
248221          }
248222        },
248223        {
248224          "type": "library",
248225          "bom-ref": "pkg:npm/verror@1.10.0?package-id=a12cc8f9f8f6def3",
248226          "supplier": {},
248227          "name": "verror",
248228          "version": "1.10.0",
248229          "description": "richer JavaScript errors",
248230          "licenses": [
248231            {
248232              "license": {
248233                "id": "MIT"
248234              }
248235            }
248236          ],
248237          "cpe": "cpe:2.3:a:davepacheco:verror:1.10.0:*:*:*:*:*:*:*",
248238          "purl": "pkg:npm/verror@1.10.0",
248239          "swid": {
248240            "attachment": {}
248241          },
248242          "pedigree": {},
248243          "externalReferences": [
248244            {
248245              "url": "git://github.com/davepacheco/node-verror.git",
248246              "type": "distribution"
248247            }
248248          ],
248249          "evidence": {},
248250          "signature": {
248251            "signature": {
248252              "publicKey": {}
248253            }
248254          },
248255          "modelCard": {
248256            "modelParameters": {
248257              "approach": {}
248258            },
248259            "quantitativeAnalysis": {
248260              "graphics": {}
248261            },
248262            "considerations": {}
248263          }
248264        },
248265        {
248266          "type": "library",
248267          "bom-ref": "pkg:npm/vm2@3.9.17?package-id=3b1db33ba6d7e81a",
248268          "supplier": {},
248269          "author": "Patrik Simek (https://patriksimek.cz)",
248270          "name": "vm2",
248271          "version": "3.9.17",
248272          "description": "vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Securely!",
248273          "licenses": [
248274            {
248275              "license": {
248276                "id": "MIT"
248277              }
248278            }
248279          ],
248280          "cpe": "cpe:2.3:a:vm2:vm2:3.9.17:*:*:*:*:*:*:*",
248281          "purl": "pkg:npm/vm2@3.9.17",
248282          "swid": {
248283            "attachment": {}
248284          },
248285          "pedigree": {},
248286          "externalReferences": [
248287            {
248288              "url": "github:patriksimek/vm2",
248289              "type": "distribution"
248290            }
248291          ],
248292          "evidence": {},
248293          "signature": {
248294            "signature": {
248295              "publicKey": {}
248296            }
248297          },
248298          "modelCard": {
248299            "modelParameters": {
248300              "approach": {}
248301            },
248302            "quantitativeAnalysis": {
248303              "graphics": {}
248304            },
248305            "considerations": {}
248306          }
248307        },
248308        {
248309          "type": "library",
248310          "bom-ref": "pkg:npm/webidl-conversions@3.0.1?package-id=a41caedf689f369e",
248311          "supplier": {},
248312          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me/)",
248313          "name": "webidl-conversions",
248314          "version": "3.0.1",
248315          "description": "Implements the WebIDL algorithms for converting to and from JavaScript values",
248316          "licenses": [
248317            {
248318              "license": {
248319                "id": "BSD-2-Clause"
248320              }
248321            }
248322          ],
248323          "cpe": "cpe:2.3:a:webidl-conversions:webidl-conversions:3.0.1:*:*:*:*:*:*:*",
248324          "purl": "pkg:npm/webidl-conversions@3.0.1",
248325          "swid": {
248326            "attachment": {}
248327          },
248328          "pedigree": {},
248329          "externalReferences": [
248330            {
248331              "url": "jsdom/webidl-conversions",
248332              "type": "distribution"
248333            }
248334          ],
248335          "evidence": {},
248336          "signature": {
248337            "signature": {
248338              "publicKey": {}
248339            }
248340          },
248341          "modelCard": {
248342            "modelParameters": {
248343              "approach": {}
248344            },
248345            "quantitativeAnalysis": {
248346              "graphics": {}
248347            },
248348            "considerations": {}
248349          }
248350        },
248351        {
248352          "type": "library",
248353          "bom-ref": "pkg:npm/whatwg-url@5.0.0?package-id=e27e9c90c3de3771",
248354          "supplier": {},
248355          "author": "Sebastian Mayr \u003cgithub@smayr.name\u003e",
248356          "name": "whatwg-url",
248357          "version": "5.0.0",
248358          "description": "An implementation of the WHATWG URL Standard's URL API and parsing machinery",
248359          "licenses": [
248360            {
248361              "license": {
248362                "id": "MIT"
248363              }
248364            }
248365          ],
248366          "cpe": "cpe:2.3:a:whatwg-url:whatwg-url:5.0.0:*:*:*:*:*:*:*",
248367          "purl": "pkg:npm/whatwg-url@5.0.0",
248368          "swid": {
248369            "attachment": {}
248370          },
248371          "pedigree": {},
248372          "externalReferences": [
248373            {
248374              "url": "jsdom/whatwg-url",
248375              "type": "distribution"
248376            }
248377          ],
248378          "evidence": {},
248379          "signature": {
248380            "signature": {
248381              "publicKey": {}
248382            }
248383          },
248384          "modelCard": {
248385            "modelParameters": {
248386              "approach": {}
248387            },
248388            "quantitativeAnalysis": {
248389              "graphics": {}
248390            },
248391            "considerations": {}
248392          }
248393        },
248394        {
248395          "type": "library",
248396          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=ce6ead4039a1b1e8",
248397          "supplier": {},
248398          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
248399          "name": "wrappy",
248400          "version": "1.0.2",
248401          "description": "Callback wrapping utility",
248402          "licenses": [
248403            {
248404              "license": {
248405                "id": "ISC"
248406              }
248407            }
248408          ],
248409          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
248410          "purl": "pkg:npm/wrappy@1.0.2",
248411          "swid": {
248412            "attachment": {}
248413          },
248414          "pedigree": {},
248415          "externalReferences": [
248416            {
248417              "url": "https://github.com/npm/wrappy",
248418              "type": "distribution"
248419            },
248420            {
248421              "url": "https://github.com/npm/wrappy",
248422              "type": "website"
248423            }
248424          ],
248425          "evidence": {},
248426          "signature": {
248427            "signature": {
248428              "publicKey": {}
248429            }
248430          },
248431          "modelCard": {
248432            "modelParameters": {
248433              "approach": {}
248434            },
248435            "quantitativeAnalysis": {
248436              "graphics": {}
248437            },
248438            "considerations": {}
248439          }
248440        },
248441        {
248442          "type": "library",
248443          "bom-ref": "pkg:npm/xtend@4.0.2?package-id=806268954298f9d0",
248444          "supplier": {},
248445          "author": "Raynos \u003craynos2@gmail.com\u003e",
248446          "name": "xtend",
248447          "version": "4.0.2",
248448          "description": "extend like a boss",
248449          "licenses": [
248450            {
248451              "license": {
248452                "id": "MIT"
248453              }
248454            }
248455          ],
248456          "cpe": "cpe:2.3:a:Raynos:xtend:4.0.2:*:*:*:*:*:*:*",
248457          "purl": "pkg:npm/xtend@4.0.2",
248458          "swid": {
248459            "attachment": {}
248460          },
248461          "pedigree": {},
248462          "externalReferences": [
248463            {
248464              "url": "git://github.com/Raynos/xtend.git",
248465              "type": "distribution"
248466            },
248467            {
248468              "url": "https://github.com/Raynos/xtend",
248469              "type": "website"
248470            }
248471          ],
248472          "evidence": {},
248473          "signature": {
248474            "signature": {
248475              "publicKey": {}
248476            }
248477          },
248478          "modelCard": {
248479            "modelParameters": {
248480              "approach": {}
248481            },
248482            "quantitativeAnalysis": {
248483              "graphics": {}
248484            },
248485            "considerations": {}
248486          }
248487        },
248488        {
248489          "type": "library",
248490          "bom-ref": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=9886c2465766333f",
248491          "supplier": {},
248492          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
248493          "name": "zlib",
248494          "version": "1.2.11-r3",
248495          "description": "A compression/decompression Library",
248496          "licenses": [
248497            {
248498              "license": {
248499                "id": "Zlib"
248500              }
248501            }
248502          ],
248503          "cpe": "cpe:2.3:a:zlib:zlib:1.2.11-r3:*:*:*:*:*:*:*",
248504          "purl": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.11.13",
248505          "swid": {
248506            "attachment": {}
248507          },
248508          "pedigree": {},
248509          "externalReferences": [
248510            {
248511              "url": "https://zlib.net/",
248512              "type": "distribution"
248513            }
248514          ],
248515          "evidence": {},
248516          "signature": {
248517            "signature": {
248518              "publicKey": {}
248519            }
248520          },
248521          "modelCard": {
248522            "modelParameters": {
248523              "approach": {}
248524            },
248525            "quantitativeAnalysis": {
248526              "graphics": {}
248527            },
248528            "considerations": {}
248529          }
248530        },
248531        {
248532          "type": "operating-system",
248533          "supplier": {},
248534          "name": "alpine",
248535          "version": "3.11.13",
248536          "description": "Alpine Linux v3.11",
248537          "swid": {
248538            "tagId": "alpine",
248539            "name": "alpine",
248540            "version": "3.11.13",
248541            "attachment": {}
248542          },
248543          "pedigree": {},
248544          "externalReferences": [
248545            {
248546              "url": "https://bugs.alpinelinux.org/",
248547              "type": "issue-tracker"
248548            },
248549            {
248550              "url": "https://alpinelinux.org/",
248551              "type": "website"
248552            }
248553          ],
248554          "evidence": {},
248555          "signature": {
248556            "signature": {
248557              "publicKey": {}
248558            }
248559          },
248560          "modelCard": {
248561            "modelParameters": {
248562              "approach": {}
248563            },
248564            "quantitativeAnalysis": {
248565              "graphics": {}
248566            },
248567            "considerations": {}
248568          }
248569        },
248570        {
248571          "type": "library",
248572          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=61eac5ce8105d394",
248573          "supplier": {},
248574          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
248575          "name": "alpine-baselayout",
248576          "version": "3.2.0-r23",
248577          "description": "Alpine base dir structure and init scripts",
248578          "licenses": [
248579            {
248580              "license": {
248581                "id": "GPL-2.0-only"
248582              }
248583            }
248584          ],
248585          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r23:*:*:*:*:*:*:*",
248586          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5",
248587          "swid": {
248588            "attachment": {}
248589          },
248590          "pedigree": {},
248591          "externalReferences": [
248592            {
248593              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
248594              "type": "distribution"
248595            }
248596          ],
248597          "evidence": {},
248598          "signature": {
248599            "signature": {
248600              "publicKey": {}
248601            }
248602          },
248603          "modelCard": {
248604            "modelParameters": {
248605              "approach": {}
248606            },
248607            "quantitativeAnalysis": {
248608              "graphics": {}
248609            },
248610            "considerations": {}
248611          }
248612        },
248613        {
248614          "type": "library",
248615          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5\u0026package-id=e8c6fcc3a282ed4f",
248616          "supplier": {},
248617          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
248618          "name": "alpine-baselayout-data",
248619          "version": "3.2.0-r23",
248620          "description": "Alpine base dir structure and init scripts",
248621          "licenses": [
248622            {
248623              "license": {
248624                "id": "GPL-2.0-only"
248625              }
248626            }
248627          ],
248628          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.2.0-r23:*:*:*:*:*:*:*",
248629          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5",
248630          "swid": {
248631            "attachment": {}
248632          },
248633          "pedigree": {},
248634          "externalReferences": [
248635            {
248636              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
248637              "type": "distribution"
248638            }
248639          ],
248640          "evidence": {},
248641          "signature": {
248642            "signature": {
248643              "publicKey": {}
248644            }
248645          },
248646          "modelCard": {
248647            "modelParameters": {
248648              "approach": {}
248649            },
248650            "quantitativeAnalysis": {
248651              "graphics": {}
248652            },
248653            "considerations": {}
248654          }
248655        },
248656        {
248657          "type": "library",
248658          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=82d183eb300978cc",
248659          "supplier": {},
248660          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
248661          "name": "alpine-keys",
248662          "version": "2.4-r1",
248663          "description": "Public keys for Alpine Linux packages",
248664          "licenses": [
248665            {
248666              "license": {
248667                "id": "MIT"
248668              }
248669            }
248670          ],
248671          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
248672          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5",
248673          "swid": {
248674            "attachment": {}
248675          },
248676          "pedigree": {},
248677          "externalReferences": [
248678            {
248679              "url": "https://alpinelinux.org",
248680              "type": "distribution"
248681            }
248682          ],
248683          "evidence": {},
248684          "signature": {
248685            "signature": {
248686              "publicKey": {}
248687            }
248688          },
248689          "modelCard": {
248690            "modelParameters": {
248691              "approach": {}
248692            },
248693            "quantitativeAnalysis": {
248694              "graphics": {}
248695            },
248696            "considerations": {}
248697          }
248698        },
248699        {
248700          "type": "library",
248701          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=42d502b764a37310",
248702          "supplier": {},
248703          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
248704          "name": "apk-tools",
248705          "version": "2.12.9-r3",
248706          "description": "Alpine Package Keeper - package manager for alpine",
248707          "licenses": [
248708            {
248709              "license": {
248710                "id": "GPL-2.0-only"
248711              }
248712            }
248713          ],
248714          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.9-r3:*:*:*:*:*:*:*",
248715          "purl": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5",
248716          "swid": {
248717            "attachment": {}
248718          },
248719          "pedigree": {},
248720          "externalReferences": [
248721            {
248722              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
248723              "type": "distribution"
248724            }
248725          ],
248726          "evidence": {},
248727          "signature": {
248728            "signature": {
248729              "publicKey": {}
248730            }
248731          },
248732          "modelCard": {
248733            "modelParameters": {
248734              "approach": {}
248735            },
248736            "quantitativeAnalysis": {
248737              "graphics": {}
248738            },
248739            "considerations": {}
248740          }
248741        },
248742        {
248743          "type": "application",
248744          "bom-ref": "e14718c64f5147f4",
248745          "supplier": {},
248746          "name": "busybox",
248747          "version": "1.35.0",
248748          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
248749          "swid": {
248750            "attachment": {}
248751          },
248752          "pedigree": {},
248753          "evidence": {},
248754          "signature": {
248755            "signature": {
248756              "publicKey": {}
248757            }
248758          },
248759          "modelCard": {
248760            "modelParameters": {
248761              "approach": {}
248762            },
248763            "quantitativeAnalysis": {
248764              "graphics": {}
248765            },
248766            "considerations": {}
248767          }
248768        },
248769        {
248770          "type": "library",
248771          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=4b48ef6f6b983526",
248772          "supplier": {},
248773          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
248774          "name": "busybox",
248775          "version": "1.35.0-r17",
248776          "description": "Size optimized toolbox of many common UNIX utilities",
248777          "licenses": [
248778            {
248779              "license": {
248780                "id": "GPL-2.0-only"
248781              }
248782            }
248783          ],
248784          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r17:*:*:*:*:*:*:*",
248785          "purl": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5",
248786          "swid": {
248787            "attachment": {}
248788          },
248789          "pedigree": {},
248790          "externalReferences": [
248791            {
248792              "url": "https://busybox.net/",
248793              "type": "distribution"
248794            }
248795          ],
248796          "evidence": {},
248797          "signature": {
248798            "signature": {
248799              "publicKey": {}
248800            }
248801          },
248802          "modelCard": {
248803            "modelParameters": {
248804              "approach": {}
248805            },
248806            "quantitativeAnalysis": {
248807              "graphics": {}
248808            },
248809            "considerations": {}
248810          }
248811        },
248812        {
248813          "type": "library",
248814          "bom-ref": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=fbb1924ff870cc71",
248815          "supplier": {},
248816          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
248817          "name": "ca-certificates",
248818          "version": "20220614-r0",
248819          "description": "Common CA certificates PEM files from Mozilla",
248820          "licenses": [
248821            {
248822              "license": {
248823                "id": "MPL-2.0"
248824              }
248825            },
248826            {
248827              "license": {
248828                "name": "AND"
248829              }
248830            },
248831            {
248832              "license": {
248833                "id": "MIT"
248834              }
248835            }
248836          ],
248837          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20220614-r0:*:*:*:*:*:*:*",
248838          "purl": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5",
248839          "swid": {
248840            "attachment": {}
248841          },
248842          "pedigree": {},
248843          "externalReferences": [
248844            {
248845              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
248846              "type": "distribution"
248847            }
248848          ],
248849          "evidence": {},
248850          "signature": {
248851            "signature": {
248852              "publicKey": {}
248853            }
248854          },
248855          "modelCard": {
248856            "modelParameters": {
248857              "approach": {}
248858            },
248859            "quantitativeAnalysis": {
248860              "graphics": {}
248861            },
248862            "considerations": {}
248863          }
248864        },
248865        {
248866          "type": "library",
248867          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5\u0026package-id=30622a1848b22bca",
248868          "supplier": {},
248869          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
248870          "name": "ca-certificates-bundle",
248871          "version": "20220614-r0",
248872          "description": "Pre generated bundle of Mozilla certificates",
248873          "licenses": [
248874            {
248875              "license": {
248876                "id": "MPL-2.0"
248877              }
248878            },
248879            {
248880              "license": {
248881                "name": "AND"
248882              }
248883            },
248884            {
248885              "license": {
248886                "id": "MIT"
248887              }
248888            }
248889          ],
248890          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
248891          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5",
248892          "swid": {
248893            "attachment": {}
248894          },
248895          "pedigree": {},
248896          "externalReferences": [
248897            {
248898              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
248899              "type": "distribution"
248900            }
248901          ],
248902          "evidence": {},
248903          "signature": {
248904            "signature": {
248905              "publicKey": {}
248906            }
248907          },
248908          "modelCard": {
248909            "modelParameters": {
248910              "approach": {}
248911            },
248912            "quantitativeAnalysis": {
248913              "graphics": {}
248914            },
248915            "considerations": {}
248916          }
248917        },
248918        {
248919          "type": "library",
248920          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5\u0026package-id=2abd3b45f6fa4702",
248921          "supplier": {},
248922          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
248923          "name": "libc-utils",
248924          "version": "0.7.2-r3",
248925          "description": "Meta package to pull in correct libc",
248926          "licenses": [
248927            {
248928              "license": {
248929                "id": "BSD-2-Clause"
248930              }
248931            },
248932            {
248933              "license": {
248934                "name": "AND"
248935              }
248936            },
248937            {
248938              "license": {
248939                "id": "BSD-3-Clause"
248940              }
248941            }
248942          ],
248943          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
248944          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5",
248945          "swid": {
248946            "attachment": {}
248947          },
248948          "pedigree": {},
248949          "externalReferences": [
248950            {
248951              "url": "https://alpinelinux.org",
248952              "type": "distribution"
248953            }
248954          ],
248955          "evidence": {},
248956          "signature": {
248957            "signature": {
248958              "publicKey": {}
248959            }
248960          },
248961          "modelCard": {
248962            "modelParameters": {
248963              "approach": {}
248964            },
248965            "quantitativeAnalysis": {
248966              "graphics": {}
248967            },
248968            "considerations": {}
248969          }
248970        },
248971        {
248972          "type": "library",
248973          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=13bc051822a24e8d",
248974          "supplier": {},
248975          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
248976          "name": "libcrypto1.1",
248977          "version": "1.1.1t-r2",
248978          "description": "Crypto library from openssl",
248979          "licenses": [
248980            {
248981              "license": {
248982                "id": "OpenSSL"
248983              }
248984            }
248985          ],
248986          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1t-r2:*:*:*:*:*:*:*",
248987          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
248988          "swid": {
248989            "attachment": {}
248990          },
248991          "pedigree": {},
248992          "externalReferences": [
248993            {
248994              "url": "https://www.openssl.org/",
248995              "type": "distribution"
248996            }
248997          ],
248998          "evidence": {},
248999          "signature": {
249000            "signature": {
249001              "publicKey": {}
249002            }
249003          },
249004          "modelCard": {
249005            "modelParameters": {
249006              "approach": {}
249007            },
249008            "quantitativeAnalysis": {
249009              "graphics": {}
249010            },
249011            "considerations": {}
249012          }
249013        },
249014        {
249015          "type": "library",
249016          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=609cb94e63dc06dd",
249017          "supplier": {},
249018          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
249019          "name": "libssl1.1",
249020          "version": "1.1.1t-r2",
249021          "description": "SSL shared libraries",
249022          "licenses": [
249023            {
249024              "license": {
249025                "id": "OpenSSL"
249026              }
249027            }
249028          ],
249029          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1t-r2:*:*:*:*:*:*:*",
249030          "purl": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
249031          "swid": {
249032            "attachment": {}
249033          },
249034          "pedigree": {},
249035          "externalReferences": [
249036            {
249037              "url": "https://www.openssl.org/",
249038              "type": "distribution"
249039            }
249040          ],
249041          "evidence": {},
249042          "signature": {
249043            "signature": {
249044              "publicKey": {}
249045            }
249046          },
249047          "modelCard": {
249048            "modelParameters": {
249049              "approach": {}
249050            },
249051            "quantitativeAnalysis": {
249052              "graphics": {}
249053            },
249054            "considerations": {}
249055          }
249056        },
249057        {
249058          "type": "library",
249059          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=24c6089b81ca7d19",
249060          "supplier": {},
249061          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
249062          "name": "musl",
249063          "version": "1.2.3-r2",
249064          "description": "the musl c library (libc) implementation",
249065          "licenses": [
249066            {
249067              "license": {
249068                "id": "MIT"
249069              }
249070            }
249071          ],
249072          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r2:*:*:*:*:*:*:*",
249073          "purl": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5",
249074          "swid": {
249075            "attachment": {}
249076          },
249077          "pedigree": {},
249078          "externalReferences": [
249079            {
249080              "url": "https://musl.libc.org/",
249081              "type": "distribution"
249082            }
249083          ],
249084          "evidence": {},
249085          "signature": {
249086            "signature": {
249087              "publicKey": {}
249088            }
249089          },
249090          "modelCard": {
249091            "modelParameters": {
249092              "approach": {}
249093            },
249094            "quantitativeAnalysis": {
249095              "graphics": {}
249096            },
249097            "considerations": {}
249098          }
249099        },
249100        {
249101          "type": "library",
249102          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5\u0026package-id=d33c14d727ae74d1",
249103          "supplier": {},
249104          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
249105          "name": "musl-utils",
249106          "version": "1.2.3-r2",
249107          "description": "the musl c library (libc) implementation",
249108          "licenses": [
249109            {
249110              "license": {
249111                "id": "MIT"
249112              }
249113            },
249114            {
249115              "license": {
249116                "name": "BSD"
249117              }
249118            },
249119            {
249120              "license": {
249121                "id": "GPL-2.0-or-later"
249122              }
249123            }
249124          ],
249125          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r2:*:*:*:*:*:*:*",
249126          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5",
249127          "swid": {
249128            "attachment": {}
249129          },
249130          "pedigree": {},
249131          "externalReferences": [
249132            {
249133              "url": "https://musl.libc.org/",
249134              "type": "distribution"
249135            }
249136          ],
249137          "evidence": {},
249138          "signature": {
249139            "signature": {
249140              "publicKey": {}
249141            }
249142          },
249143          "modelCard": {
249144            "modelParameters": {
249145              "approach": {}
249146            },
249147            "quantitativeAnalysis": {
249148              "graphics": {}
249149            },
249150            "considerations": {}
249151          }
249152        },
249153        {
249154          "type": "library",
249155          "bom-ref": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5\u0026package-id=206fdb47b3e980eb",
249156          "supplier": {},
249157          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
249158          "name": "scanelf",
249159          "version": "1.3.4-r0",
249160          "description": "Scan ELF binaries for stuff",
249161          "licenses": [
249162            {
249163              "license": {
249164                "id": "GPL-2.0-only"
249165              }
249166            }
249167          ],
249168          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.4-r0:*:*:*:*:*:*:*",
249169          "purl": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5",
249170          "swid": {
249171            "attachment": {}
249172          },
249173          "pedigree": {},
249174          "externalReferences": [
249175            {
249176              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
249177              "type": "distribution"
249178            }
249179          ],
249180          "evidence": {},
249181          "signature": {
249182            "signature": {
249183              "publicKey": {}
249184            }
249185          },
249186          "modelCard": {
249187            "modelParameters": {
249188              "approach": {}
249189            },
249190            "quantitativeAnalysis": {
249191              "graphics": {}
249192            },
249193            "considerations": {}
249194          }
249195        },
249196        {
249197          "type": "library",
249198          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5\u0026package-id=674d1e2fba4d633a",
249199          "supplier": {},
249200          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
249201          "name": "ssl_client",
249202          "version": "1.35.0-r17",
249203          "description": "EXternal ssl_client for busybox wget",
249204          "licenses": [
249205            {
249206              "license": {
249207                "id": "GPL-2.0-only"
249208              }
249209            }
249210          ],
249211          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r17:*:*:*:*:*:*:*",
249212          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5",
249213          "swid": {
249214            "attachment": {}
249215          },
249216          "pedigree": {},
249217          "externalReferences": [
249218            {
249219              "url": "https://busybox.net/",
249220              "type": "distribution"
249221            }
249222          ],
249223          "evidence": {},
249224          "signature": {
249225            "signature": {
249226              "publicKey": {}
249227            }
249228          },
249229          "modelCard": {
249230            "modelParameters": {
249231              "approach": {}
249232            },
249233            "quantitativeAnalysis": {
249234              "graphics": {}
249235            },
249236            "considerations": {}
249237          }
249238        },
249239        {
249240          "type": "library",
249241          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=75f0d92f695b4303",
249242          "supplier": {},
249243          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
249244          "name": "zlib",
249245          "version": "1.2.12-r3",
249246          "description": "A compression/decompression Library",
249247          "licenses": [
249248            {
249249              "license": {
249250                "id": "Zlib"
249251              }
249252            }
249253          ],
249254          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
249255          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5",
249256          "swid": {
249257            "attachment": {}
249258          },
249259          "pedigree": {},
249260          "externalReferences": [
249261            {
249262              "url": "https://zlib.net/",
249263              "type": "distribution"
249264            }
249265          ],
249266          "evidence": {},
249267          "signature": {
249268            "signature": {
249269              "publicKey": {}
249270            }
249271          },
249272          "modelCard": {
249273            "modelParameters": {
249274              "approach": {}
249275            },
249276            "quantitativeAnalysis": {
249277              "graphics": {}
249278            },
249279            "considerations": {}
249280          }
249281        },
249282        {
249283          "type": "operating-system",
249284          "supplier": {},
249285          "name": "alpine",
249286          "version": "3.16.5",
249287          "description": "Alpine Linux v3.16",
249288          "swid": {
249289            "tagId": "alpine",
249290            "name": "alpine",
249291            "version": "3.16.5",
249292            "attachment": {}
249293          },
249294          "pedigree": {},
249295          "externalReferences": [
249296            {
249297              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
249298              "type": "issue-tracker"
249299            },
249300            {
249301              "url": "https://alpinelinux.org/",
249302              "type": "website"
249303            }
249304          ],
249305          "evidence": {},
249306          "signature": {
249307            "signature": {
249308              "publicKey": {}
249309            }
249310          },
249311          "modelCard": {
249312            "modelParameters": {
249313              "approach": {}
249314            },
249315            "quantitativeAnalysis": {
249316              "graphics": {}
249317            },
249318            "considerations": {}
249319          }
249320        },
249321        {
249322          "type": "library",
249323          "bom-ref": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-10\u0026package-id=3e9282034226b93f",
249324          "supplier": {},
249325          "publisher": "Debian Adduser Developers \u003cadduser@packages.debian.org\u003e",
249326          "name": "adduser",
249327          "version": "3.118",
249328          "licenses": [
249329            {
249330              "license": {
249331                "id": "GPL-2.0-only"
249332              }
249333            }
249334          ],
249335          "cpe": "cpe:2.3:a:adduser:adduser:3.118:*:*:*:*:*:*:*",
249336          "purl": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-10",
249337          "swid": {
249338            "attachment": {}
249339          },
249340          "pedigree": {},
249341          "evidence": {},
249342          "signature": {
249343            "signature": {
249344              "publicKey": {}
249345            }
249346          },
249347          "modelCard": {
249348            "modelParameters": {
249349              "approach": {}
249350            },
249351            "quantitativeAnalysis": {
249352              "graphics": {}
249353            },
249354            "considerations": {}
249355          }
249356        },
249357        {
249358          "type": "library",
249359          "bom-ref": "pkg:deb/debian/apt@1.8.2.3?arch=amd64\u0026distro=debian-10\u0026package-id=c780dc7f69abdf78",
249360          "supplier": {},
249361          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
249362          "name": "apt",
249363          "version": "1.8.2.3",
249364          "licenses": [
249365            {
249366              "license": {
249367                "id": "GPL-2.0-only"
249368              }
249369            },
249370            {
249371              "license": {
249372                "name": "GPLv2+"
249373              }
249374            }
249375          ],
249376          "cpe": "cpe:2.3:a:apt:apt:1.8.2.3:*:*:*:*:*:*:*",
249377          "purl": "pkg:deb/debian/apt@1.8.2.3?arch=amd64\u0026distro=debian-10",
249378          "swid": {
249379            "attachment": {}
249380          },
249381          "pedigree": {},
249382          "evidence": {},
249383          "signature": {
249384            "signature": {
249385              "publicKey": {}
249386            }
249387          },
249388          "modelCard": {
249389            "modelParameters": {
249390              "approach": {}
249391            },
249392            "quantitativeAnalysis": {
249393              "graphics": {}
249394            },
249395            "considerations": {}
249396          }
249397        },
249398        {
249399          "type": "library",
249400          "bom-ref": "pkg:deb/debian/base-files@10.3+deb10u10?arch=amd64\u0026distro=debian-10\u0026package-id=11919a287d510b6c",
249401          "supplier": {},
249402          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
249403          "name": "base-files",
249404          "version": "10.3+deb10u10",
249405          "licenses": [
249406            {
249407              "license": {
249408                "name": "GPL"
249409              }
249410            }
249411          ],
249412          "cpe": "cpe:2.3:a:base-files:base-files:10.3\\+deb10u10:*:*:*:*:*:*:*",
249413          "purl": "pkg:deb/debian/base-files@10.3+deb10u10?arch=amd64\u0026distro=debian-10",
249414          "swid": {
249415            "attachment": {}
249416          },
249417          "pedigree": {},
249418          "evidence": {},
249419          "signature": {
249420            "signature": {
249421              "publicKey": {}
249422            }
249423          },
249424          "modelCard": {
249425            "modelParameters": {
249426              "approach": {}
249427            },
249428            "quantitativeAnalysis": {
249429              "graphics": {}
249430            },
249431            "considerations": {}
249432          }
249433        },
249434        {
249435          "type": "library",
249436          "bom-ref": "pkg:deb/debian/base-passwd@3.5.46?arch=amd64\u0026distro=debian-10\u0026package-id=8c36ab474a82d3ae",
249437          "supplier": {},
249438          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
249439          "name": "base-passwd",
249440          "version": "3.5.46",
249441          "licenses": [
249442            {
249443              "license": {
249444                "id": "GPL-2.0-only"
249445              }
249446            },
249447            {
249448              "license": {
249449                "name": "PD"
249450              }
249451            }
249452          ],
249453          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.46:*:*:*:*:*:*:*",
249454          "purl": "pkg:deb/debian/base-passwd@3.5.46?arch=amd64\u0026distro=debian-10",
249455          "swid": {
249456            "attachment": {}
249457          },
249458          "pedigree": {},
249459          "evidence": {},
249460          "signature": {
249461            "signature": {
249462              "publicKey": {}
249463            }
249464          },
249465          "modelCard": {
249466            "modelParameters": {
249467              "approach": {}
249468            },
249469            "quantitativeAnalysis": {
249470              "graphics": {}
249471            },
249472            "considerations": {}
249473          }
249474        },
249475        {
249476          "type": "library",
249477          "bom-ref": "pkg:deb/debian/bash@5.0-4?arch=amd64\u0026distro=debian-10\u0026package-id=1307b253f0761292",
249478          "supplier": {},
249479          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
249480          "name": "bash",
249481          "version": "5.0-4",
249482          "licenses": [
249483            {
249484              "license": {
249485                "id": "GPL-3.0-only"
249486              }
249487            }
249488          ],
249489          "cpe": "cpe:2.3:a:bash:bash:5.0-4:*:*:*:*:*:*:*",
249490          "purl": "pkg:deb/debian/bash@5.0-4?arch=amd64\u0026distro=debian-10",
249491          "swid": {
249492            "attachment": {}
249493          },
249494          "pedigree": {},
249495          "evidence": {},
249496          "signature": {
249497            "signature": {
249498              "publicKey": {}
249499            }
249500          },
249501          "modelCard": {
249502            "modelParameters": {
249503              "approach": {}
249504            },
249505            "quantitativeAnalysis": {
249506              "graphics": {}
249507            },
249508            "considerations": {}
249509          }
249510        },
249511        {
249512          "type": "library",
249513          "bom-ref": "pkg:deb/debian/bsdutils@1:2.33.1-0.1?arch=amd64\u0026upstream=util-linux%402.33.1-0.1\u0026distro=debian-10\u0026package-id=344ffe16352c1b24",
249514          "supplier": {},
249515          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
249516          "name": "bsdutils",
249517          "version": "1:2.33.1-0.1",
249518          "licenses": [
249519            {
249520              "license": {
249521                "id": "BSD-2-Clause"
249522              }
249523            },
249524            {
249525              "license": {
249526                "id": "BSD-3-Clause"
249527              }
249528            },
249529            {
249530              "license": {
249531                "id": "BSD-4-Clause"
249532              }
249533            },
249534            {
249535              "license": {
249536                "id": "GPL-2.0-only"
249537              }
249538            },
249539            {
249540              "license": {
249541                "id": "GPL-2.0-or-later"
249542              }
249543            },
249544            {
249545              "license": {
249546                "id": "GPL-3.0-only"
249547              }
249548            },
249549            {
249550              "license": {
249551                "id": "GPL-3.0-or-later"
249552              }
249553            },
249554            {
249555              "license": {
249556                "name": "LGPL"
249557              }
249558            },
249559            {
249560              "license": {
249561                "id": "LGPL-2.0-only"
249562              }
249563            },
249564            {
249565              "license": {
249566                "id": "LGPL-2.0-or-later"
249567              }
249568            },
249569            {
249570              "license": {
249571                "id": "LGPL-2.1-only"
249572              }
249573            },
249574            {
249575              "license": {
249576                "id": "LGPL-2.1-or-later"
249577              }
249578            },
249579            {
249580              "license": {
249581                "id": "LGPL-3.0-only"
249582              }
249583            },
249584            {
249585              "license": {
249586                "id": "LGPL-3.0-or-later"
249587              }
249588            },
249589            {
249590              "license": {
249591                "id": "MIT"
249592              }
249593            },
249594            {
249595              "license": {
249596                "name": "public-domain"
249597              }
249598            }
249599          ],
249600          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.33.1-0.1:*:*:*:*:*:*:*",
249601          "purl": "pkg:deb/debian/bsdutils@1:2.33.1-0.1?arch=amd64\u0026upstream=util-linux%402.33.1-0.1\u0026distro=debian-10",
249602          "swid": {
249603            "attachment": {}
249604          },
249605          "pedigree": {},
249606          "evidence": {},
249607          "signature": {
249608            "signature": {
249609              "publicKey": {}
249610            }
249611          },
249612          "modelCard": {
249613            "modelParameters": {
249614              "approach": {}
249615            },
249616            "quantitativeAnalysis": {
249617              "graphics": {}
249618            },
249619            "considerations": {}
249620          }
249621        },
249622        {
249623          "type": "library",
249624          "bom-ref": "pkg:deb/debian/coreutils@8.30-3?arch=amd64\u0026distro=debian-10\u0026package-id=46b6002891a4d405",
249625          "supplier": {},
249626          "publisher": "Michael Stone \u003cmstone@debian.org\u003e",
249627          "name": "coreutils",
249628          "version": "8.30-3",
249629          "licenses": [
249630            {
249631              "license": {
249632                "id": "GPL-3.0-only"
249633              }
249634            }
249635          ],
249636          "cpe": "cpe:2.3:a:coreutils:coreutils:8.30-3:*:*:*:*:*:*:*",
249637          "purl": "pkg:deb/debian/coreutils@8.30-3?arch=amd64\u0026distro=debian-10",
249638          "swid": {
249639            "attachment": {}
249640          },
249641          "pedigree": {},
249642          "evidence": {},
249643          "signature": {
249644            "signature": {
249645              "publicKey": {}
249646            }
249647          },
249648          "modelCard": {
249649            "modelParameters": {
249650              "approach": {}
249651            },
249652            "quantitativeAnalysis": {
249653              "graphics": {}
249654            },
249655            "considerations": {}
249656          }
249657        },
249658        {
249659          "type": "library",
249660          "bom-ref": "pkg:deb/debian/dash@0.5.10.2-5?arch=amd64\u0026distro=debian-10\u0026package-id=567db85af6d6aaf3",
249661          "supplier": {},
249662          "publisher": "Andrej Shadura \u003candrewsh@debian.org\u003e",
249663          "name": "dash",
249664          "version": "0.5.10.2-5",
249665          "licenses": [
249666            {
249667              "license": {
249668                "name": "GPL"
249669              }
249670            }
249671          ],
249672          "cpe": "cpe:2.3:a:dash:dash:0.5.10.2-5:*:*:*:*:*:*:*",
249673          "purl": "pkg:deb/debian/dash@0.5.10.2-5?arch=amd64\u0026distro=debian-10",
249674          "swid": {
249675            "attachment": {}
249676          },
249677          "pedigree": {},
249678          "evidence": {},
249679          "signature": {
249680            "signature": {
249681              "publicKey": {}
249682            }
249683          },
249684          "modelCard": {
249685            "modelParameters": {
249686              "approach": {}
249687            },
249688            "quantitativeAnalysis": {
249689              "graphics": {}
249690            },
249691            "considerations": {}
249692          }
249693        },
249694        {
249695          "type": "library",
249696          "bom-ref": "pkg:deb/debian/debconf@1.5.71?arch=all\u0026distro=debian-10\u0026package-id=9470bfee238208a1",
249697          "supplier": {},
249698          "publisher": "Debconf Developers \u003cdebconf-devel@lists.alioth.debian.org\u003e",
249699          "name": "debconf",
249700          "version": "1.5.71",
249701          "licenses": [
249702            {
249703              "license": {
249704                "id": "BSD-2-Clause"
249705              }
249706            }
249707          ],
249708          "cpe": "cpe:2.3:a:debconf:debconf:1.5.71:*:*:*:*:*:*:*",
249709          "purl": "pkg:deb/debian/debconf@1.5.71?arch=all\u0026distro=debian-10",
249710          "swid": {
249711            "attachment": {}
249712          },
249713          "pedigree": {},
249714          "evidence": {},
249715          "signature": {
249716            "signature": {
249717              "publicKey": {}
249718            }
249719          },
249720          "modelCard": {
249721            "modelParameters": {
249722              "approach": {}
249723            },
249724            "quantitativeAnalysis": {
249725              "graphics": {}
249726            },
249727            "considerations": {}
249728          }
249729        },
249730        {
249731          "type": "library",
249732          "bom-ref": "pkg:deb/debian/debian-archive-keyring@2019.1+deb10u1?arch=all\u0026distro=debian-10\u0026package-id=f9b380da454eddb4",
249733          "supplier": {},
249734          "publisher": "Debian Release Team \u003cpackages@release.debian.org\u003e",
249735          "name": "debian-archive-keyring",
249736          "version": "2019.1+deb10u1",
249737          "licenses": [
249738            {
249739              "license": {
249740                "name": "GPL"
249741              }
249742            }
249743          ],
249744          "cpe": "cpe:2.3:a:debian-archive-keyring:debian-archive-keyring:2019.1\\+deb10u1:*:*:*:*:*:*:*",
249745          "purl": "pkg:deb/debian/debian-archive-keyring@2019.1+deb10u1?arch=all\u0026distro=debian-10",
249746          "swid": {
249747            "attachment": {}
249748          },
249749          "pedigree": {},
249750          "evidence": {},
249751          "signature": {
249752            "signature": {
249753              "publicKey": {}
249754            }
249755          },
249756          "modelCard": {
249757            "modelParameters": {
249758              "approach": {}
249759            },
249760            "quantitativeAnalysis": {
249761              "graphics": {}
249762            },
249763            "considerations": {}
249764          }
249765        },
249766        {
249767          "type": "library",
249768          "bom-ref": "pkg:deb/debian/debianutils@4.8.6.1?arch=amd64\u0026distro=debian-10\u0026package-id=a28bc35fdac63cd4",
249769          "supplier": {},
249770          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
249771          "name": "debianutils",
249772          "version": "4.8.6.1",
249773          "licenses": [
249774            {
249775              "license": {
249776                "name": "GPL"
249777              }
249778            }
249779          ],
249780          "cpe": "cpe:2.3:a:debianutils:debianutils:4.8.6.1:*:*:*:*:*:*:*",
249781          "purl": "pkg:deb/debian/debianutils@4.8.6.1?arch=amd64\u0026distro=debian-10",
249782          "swid": {
249783            "attachment": {}
249784          },
249785          "pedigree": {},
249786          "evidence": {},
249787          "signature": {
249788            "signature": {
249789              "publicKey": {}
249790            }
249791          },
249792          "modelCard": {
249793            "modelParameters": {
249794              "approach": {}
249795            },
249796            "quantitativeAnalysis": {
249797              "graphics": {}
249798            },
249799            "considerations": {}
249800          }
249801        },
249802        {
249803          "type": "library",
249804          "bom-ref": "pkg:deb/debian/diffutils@1:3.7-3?arch=amd64\u0026distro=debian-10\u0026package-id=6d51f5deb90deb06",
249805          "supplier": {},
249806          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
249807          "name": "diffutils",
249808          "version": "1:3.7-3",
249809          "licenses": [
249810            {
249811              "license": {
249812                "name": "GFDL"
249813              }
249814            },
249815            {
249816              "license": {
249817                "name": "GPL"
249818              }
249819            }
249820          ],
249821          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-3:*:*:*:*:*:*:*",
249822          "purl": "pkg:deb/debian/diffutils@1:3.7-3?arch=amd64\u0026distro=debian-10",
249823          "swid": {
249824            "attachment": {}
249825          },
249826          "pedigree": {},
249827          "evidence": {},
249828          "signature": {
249829            "signature": {
249830              "publicKey": {}
249831            }
249832          },
249833          "modelCard": {
249834            "modelParameters": {
249835              "approach": {}
249836            },
249837            "quantitativeAnalysis": {
249838              "graphics": {}
249839            },
249840            "considerations": {}
249841          }
249842        },
249843        {
249844          "type": "library",
249845          "bom-ref": "pkg:deb/debian/dpkg@1.19.7?arch=amd64\u0026distro=debian-10\u0026package-id=826669ee9d8b4b93",
249846          "supplier": {},
249847          "publisher": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e",
249848          "name": "dpkg",
249849          "version": "1.19.7",
249850          "licenses": [
249851            {
249852              "license": {
249853                "id": "BSD-2-Clause"
249854              }
249855            },
249856            {
249857              "license": {
249858                "id": "GPL-2.0-only"
249859              }
249860            },
249861            {
249862              "license": {
249863                "id": "GPL-2.0-or-later"
249864              }
249865            },
249866            {
249867              "license": {
249868                "name": "public-domain-md5"
249869              }
249870            },
249871            {
249872              "license": {
249873                "name": "public-domain-s-s-d"
249874              }
249875            }
249876          ],
249877          "cpe": "cpe:2.3:a:dpkg:dpkg:1.19.7:*:*:*:*:*:*:*",
249878          "purl": "pkg:deb/debian/dpkg@1.19.7?arch=amd64\u0026distro=debian-10",
249879          "swid": {
249880            "attachment": {}
249881          },
249882          "pedigree": {},
249883          "evidence": {},
249884          "signature": {
249885            "signature": {
249886              "publicKey": {}
249887            }
249888          },
249889          "modelCard": {
249890            "modelParameters": {
249891              "approach": {}
249892            },
249893            "quantitativeAnalysis": {
249894              "graphics": {}
249895            },
249896            "considerations": {}
249897          }
249898        },
249899        {
249900          "type": "library",
249901          "bom-ref": "pkg:deb/debian/e2fsprogs@1.44.5-1+deb10u3?arch=amd64\u0026distro=debian-10\u0026package-id=af000c00a7621537",
249902          "supplier": {},
249903          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
249904          "name": "e2fsprogs",
249905          "version": "1.44.5-1+deb10u3",
249906          "licenses": [
249907            {
249908              "license": {
249909                "id": "GPL-2.0-only"
249910              }
249911            },
249912            {
249913              "license": {
249914                "id": "LGPL-2.0-only"
249915              }
249916            }
249917          ],
249918          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.44.5-1\\+deb10u3:*:*:*:*:*:*:*",
249919          "purl": "pkg:deb/debian/e2fsprogs@1.44.5-1+deb10u3?arch=amd64\u0026distro=debian-10",
249920          "swid": {
249921            "attachment": {}
249922          },
249923          "pedigree": {},
249924          "evidence": {},
249925          "signature": {
249926            "signature": {
249927              "publicKey": {}
249928            }
249929          },
249930          "modelCard": {
249931            "modelParameters": {
249932              "approach": {}
249933            },
249934            "quantitativeAnalysis": {
249935              "graphics": {}
249936            },
249937            "considerations": {}
249938          }
249939        },
249940        {
249941          "type": "library",
249942          "bom-ref": "pkg:deb/debian/fdisk@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=743bbe9c435d52f3",
249943          "supplier": {},
249944          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
249945          "name": "fdisk",
249946          "version": "2.33.1-0.1",
249947          "licenses": [
249948            {
249949              "license": {
249950                "id": "BSD-2-Clause"
249951              }
249952            },
249953            {
249954              "license": {
249955                "id": "BSD-3-Clause"
249956              }
249957            },
249958            {
249959              "license": {
249960                "id": "BSD-4-Clause"
249961              }
249962            },
249963            {
249964              "license": {
249965                "id": "GPL-2.0-only"
249966              }
249967            },
249968            {
249969              "license": {
249970                "id": "GPL-2.0-or-later"
249971              }
249972            },
249973            {
249974              "license": {
249975                "id": "GPL-3.0-only"
249976              }
249977            },
249978            {
249979              "license": {
249980                "id": "GPL-3.0-or-later"
249981              }
249982            },
249983            {
249984              "license": {
249985                "name": "LGPL"
249986              }
249987            },
249988            {
249989              "license": {
249990                "id": "LGPL-2.0-only"
249991              }
249992            },
249993            {
249994              "license": {
249995                "id": "LGPL-2.0-or-later"
249996              }
249997            },
249998            {
249999              "license": {
250000                "id": "LGPL-2.1-only"
250001              }
250002            },
250003            {
250004              "license": {
250005                "id": "LGPL-2.1-or-later"
250006              }
250007            },
250008            {
250009              "license": {
250010                "id": "LGPL-3.0-only"
250011              }
250012            },
250013            {
250014              "license": {
250015                "id": "LGPL-3.0-or-later"
250016              }
250017            },
250018            {
250019              "license": {
250020                "id": "MIT"
250021              }
250022            },
250023            {
250024              "license": {
250025                "name": "public-domain"
250026              }
250027            }
250028          ],
250029          "cpe": "cpe:2.3:a:fdisk:fdisk:2.33.1-0.1:*:*:*:*:*:*:*",
250030          "purl": "pkg:deb/debian/fdisk@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
250031          "swid": {
250032            "attachment": {}
250033          },
250034          "pedigree": {},
250035          "evidence": {},
250036          "signature": {
250037            "signature": {
250038              "publicKey": {}
250039            }
250040          },
250041          "modelCard": {
250042            "modelParameters": {
250043              "approach": {}
250044            },
250045            "quantitativeAnalysis": {
250046              "graphics": {}
250047            },
250048            "considerations": {}
250049          }
250050        },
250051        {
250052          "type": "library",
250053          "bom-ref": "pkg:deb/debian/findutils@4.6.0+git+20190209-2?arch=amd64\u0026distro=debian-10\u0026package-id=38adf8ca435355da",
250054          "supplier": {},
250055          "publisher": "Andreas Metzler \u003cametzler@debian.org\u003e",
250056          "name": "findutils",
250057          "version": "4.6.0+git+20190209-2",
250058          "licenses": [
250059            {
250060              "license": {
250061                "id": "GFDL-1.3-only"
250062              }
250063            },
250064            {
250065              "license": {
250066                "id": "GPL-3.0-only"
250067              }
250068            }
250069          ],
250070          "cpe": "cpe:2.3:a:findutils:findutils:4.6.0\\+git\\+20190209-2:*:*:*:*:*:*:*",
250071          "purl": "pkg:deb/debian/findutils@4.6.0+git+20190209-2?arch=amd64\u0026distro=debian-10",
250072          "swid": {
250073            "attachment": {}
250074          },
250075          "pedigree": {},
250076          "evidence": {},
250077          "signature": {
250078            "signature": {
250079              "publicKey": {}
250080            }
250081          },
250082          "modelCard": {
250083            "modelParameters": {
250084              "approach": {}
250085            },
250086            "quantitativeAnalysis": {
250087              "graphics": {}
250088            },
250089            "considerations": {}
250090          }
250091        },
250092        {
250093          "type": "library",
250094          "bom-ref": "pkg:deb/debian/gcc-8-base@8.3.0-6?arch=amd64\u0026upstream=gcc-8\u0026distro=debian-10\u0026package-id=a958e0e726fb519d",
250095          "supplier": {},
250096          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
250097          "name": "gcc-8-base",
250098          "version": "8.3.0-6",
250099          "licenses": [
250100            {
250101              "license": {
250102                "name": "Artistic"
250103              }
250104            },
250105            {
250106              "license": {
250107                "id": "GFDL-1.2-only"
250108              }
250109            },
250110            {
250111              "license": {
250112                "name": "GPL"
250113              }
250114            },
250115            {
250116              "license": {
250117                "id": "GPL-2.0-only"
250118              }
250119            },
250120            {
250121              "license": {
250122                "id": "GPL-3.0-only"
250123              }
250124            },
250125            {
250126              "license": {
250127                "name": "LGPL"
250128              }
250129            }
250130          ],
250131          "cpe": "cpe:2.3:a:gcc-8-base:gcc-8-base:8.3.0-6:*:*:*:*:*:*:*",
250132          "purl": "pkg:deb/debian/gcc-8-base@8.3.0-6?arch=amd64\u0026upstream=gcc-8\u0026distro=debian-10",
250133          "swid": {
250134            "attachment": {}
250135          },
250136          "pedigree": {},
250137          "evidence": {},
250138          "signature": {
250139            "signature": {
250140              "publicKey": {}
250141            }
250142          },
250143          "modelCard": {
250144            "modelParameters": {
250145              "approach": {}
250146            },
250147            "quantitativeAnalysis": {
250148              "graphics": {}
250149            },
250150            "considerations": {}
250151          }
250152        },
250153        {
250154          "type": "library",
250155          "bom-ref": "pkg:deb/debian/gpgv@2.2.12-1+deb10u1?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-10\u0026package-id=1ffde2f3ed358894",
250156          "supplier": {},
250157          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
250158          "name": "gpgv",
250159          "version": "2.2.12-1+deb10u1",
250160          "licenses": [
250161            {
250162              "license": {
250163                "id": "BSD-3-Clause"
250164              }
250165            },
250166            {
250167              "license": {
250168                "id": "CC0-1.0"
250169              }
250170            },
250171            {
250172              "license": {
250173                "name": "Expat"
250174              }
250175            },
250176            {
250177              "license": {
250178                "id": "GPL-3.0-only"
250179              }
250180            },
250181            {
250182              "license": {
250183                "id": "GPL-3.0-or-later"
250184              }
250185            },
250186            {
250187              "license": {
250188                "id": "LGPL-2.1-only"
250189              }
250190            },
250191            {
250192              "license": {
250193                "id": "LGPL-2.1-or-later"
250194              }
250195            },
250196            {
250197              "license": {
250198                "id": "LGPL-3.0-only"
250199              }
250200            },
250201            {
250202              "license": {
250203                "id": "LGPL-3.0-or-later"
250204              }
250205            },
250206            {
250207              "license": {
250208                "name": "RFC-Reference"
250209              }
250210            },
250211            {
250212              "license": {
250213                "name": "TinySCHEME"
250214              }
250215            },
250216            {
250217              "license": {
250218                "name": "permissive"
250219              }
250220            }
250221          ],
250222          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.12-1\\+deb10u1:*:*:*:*:*:*:*",
250223          "purl": "pkg:deb/debian/gpgv@2.2.12-1+deb10u1?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-10",
250224          "swid": {
250225            "attachment": {}
250226          },
250227          "pedigree": {},
250228          "evidence": {},
250229          "signature": {
250230            "signature": {
250231              "publicKey": {}
250232            }
250233          },
250234          "modelCard": {
250235            "modelParameters": {
250236              "approach": {}
250237            },
250238            "quantitativeAnalysis": {
250239              "graphics": {}
250240            },
250241            "considerations": {}
250242          }
250243        },
250244        {
250245          "type": "library",
250246          "bom-ref": "pkg:deb/debian/grep@3.3-1?arch=amd64\u0026distro=debian-10\u0026package-id=e19c01918650b778",
250247          "supplier": {},
250248          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
250249          "name": "grep",
250250          "version": "3.3-1",
250251          "licenses": [
250252            {
250253              "license": {
250254                "id": "GPL-3.0-only"
250255              }
250256            },
250257            {
250258              "license": {
250259                "id": "GPL-3.0-or-later"
250260              }
250261            }
250262          ],
250263          "cpe": "cpe:2.3:a:grep:grep:3.3-1:*:*:*:*:*:*:*",
250264          "purl": "pkg:deb/debian/grep@3.3-1?arch=amd64\u0026distro=debian-10",
250265          "swid": {
250266            "attachment": {}
250267          },
250268          "pedigree": {},
250269          "evidence": {},
250270          "signature": {
250271            "signature": {
250272              "publicKey": {}
250273            }
250274          },
250275          "modelCard": {
250276            "modelParameters": {
250277              "approach": {}
250278            },
250279            "quantitativeAnalysis": {
250280              "graphics": {}
250281            },
250282            "considerations": {}
250283          }
250284        },
250285        {
250286          "type": "library",
250287          "bom-ref": "pkg:deb/debian/gzip@1.9-3?arch=amd64\u0026distro=debian-10\u0026package-id=7de3a8e52e2d2e8b",
250288          "supplier": {},
250289          "publisher": "Bdale Garbee \u003cbdale@gag.com\u003e",
250290          "name": "gzip",
250291          "version": "1.9-3",
250292          "licenses": [
250293            {
250294              "license": {
250295                "name": "GPL"
250296              }
250297            }
250298          ],
250299          "cpe": "cpe:2.3:a:gzip:gzip:1.9-3:*:*:*:*:*:*:*",
250300          "purl": "pkg:deb/debian/gzip@1.9-3?arch=amd64\u0026distro=debian-10",
250301          "swid": {
250302            "attachment": {}
250303          },
250304          "pedigree": {},
250305          "evidence": {},
250306          "signature": {
250307            "signature": {
250308              "publicKey": {}
250309            }
250310          },
250311          "modelCard": {
250312            "modelParameters": {
250313              "approach": {}
250314            },
250315            "quantitativeAnalysis": {
250316              "graphics": {}
250317            },
250318            "considerations": {}
250319          }
250320        },
250321        {
250322          "type": "library",
250323          "bom-ref": "pkg:deb/debian/hostname@3.21?arch=amd64\u0026distro=debian-10\u0026package-id=9deb64db83d5e7c0",
250324          "supplier": {},
250325          "publisher": "Michael Meskes \u003cmeskes@debian.org\u003e",
250326          "name": "hostname",
250327          "version": "3.21",
250328          "licenses": [
250329            {
250330              "license": {
250331                "id": "GPL-2.0-only"
250332              }
250333            }
250334          ],
250335          "cpe": "cpe:2.3:a:hostname:hostname:3.21:*:*:*:*:*:*:*",
250336          "purl": "pkg:deb/debian/hostname@3.21?arch=amd64\u0026distro=debian-10",
250337          "swid": {
250338            "attachment": {}
250339          },
250340          "pedigree": {},
250341          "evidence": {},
250342          "signature": {
250343            "signature": {
250344              "publicKey": {}
250345            }
250346          },
250347          "modelCard": {
250348            "modelParameters": {
250349              "approach": {}
250350            },
250351            "quantitativeAnalysis": {
250352              "graphics": {}
250353            },
250354            "considerations": {}
250355          }
250356        },
250357        {
250358          "type": "library",
250359          "bom-ref": "pkg:deb/debian/init-system-helpers@1.56+nmu1?arch=all\u0026distro=debian-10\u0026package-id=7d7ed30b1f37bb0",
250360          "supplier": {},
250361          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
250362          "name": "init-system-helpers",
250363          "version": "1.56+nmu1",
250364          "licenses": [
250365            {
250366              "license": {
250367                "id": "BSD-3-Clause"
250368              }
250369            },
250370            {
250371              "license": {
250372                "id": "GPL-2.0-only"
250373              }
250374            },
250375            {
250376              "license": {
250377                "id": "GPL-2.0-or-later"
250378              }
250379            }
250380          ],
250381          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.56\\+nmu1:*:*:*:*:*:*:*",
250382          "purl": "pkg:deb/debian/init-system-helpers@1.56+nmu1?arch=all\u0026distro=debian-10",
250383          "swid": {
250384            "attachment": {}
250385          },
250386          "pedigree": {},
250387          "evidence": {},
250388          "signature": {
250389            "signature": {
250390              "publicKey": {}
250391            }
250392          },
250393          "modelCard": {
250394            "modelParameters": {
250395              "approach": {}
250396            },
250397            "quantitativeAnalysis": {
250398              "graphics": {}
250399            },
250400            "considerations": {}
250401          }
250402        },
250403        {
250404          "type": "library",
250405          "bom-ref": "pkg:deb/debian/libacl1@2.2.53-4?arch=amd64\u0026upstream=acl\u0026distro=debian-10\u0026package-id=a6d0197dab539e98",
250406          "supplier": {},
250407          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
250408          "name": "libacl1",
250409          "version": "2.2.53-4",
250410          "licenses": [
250411            {
250412              "license": {
250413                "id": "GPL-2.0-only"
250414              }
250415            },
250416            {
250417              "license": {
250418                "id": "GPL-2.0-or-later"
250419              }
250420            },
250421            {
250422              "license": {
250423                "id": "LGPL-2.0-or-later"
250424              }
250425            },
250426            {
250427              "license": {
250428                "id": "LGPL-2.1-only"
250429              }
250430            }
250431          ],
250432          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-4:*:*:*:*:*:*:*",
250433          "purl": "pkg:deb/debian/libacl1@2.2.53-4?arch=amd64\u0026upstream=acl\u0026distro=debian-10",
250434          "swid": {
250435            "attachment": {}
250436          },
250437          "pedigree": {},
250438          "evidence": {},
250439          "signature": {
250440            "signature": {
250441              "publicKey": {}
250442            }
250443          },
250444          "modelCard": {
250445            "modelParameters": {
250446              "approach": {}
250447            },
250448            "quantitativeAnalysis": {
250449              "graphics": {}
250450            },
250451            "considerations": {}
250452          }
250453        },
250454        {
250455          "type": "library",
250456          "bom-ref": "pkg:deb/debian/libapt-pkg5.0@1.8.2.3?arch=amd64\u0026upstream=apt\u0026distro=debian-10\u0026package-id=a54bb5db29539ed0",
250457          "supplier": {},
250458          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
250459          "name": "libapt-pkg5.0",
250460          "version": "1.8.2.3",
250461          "licenses": [
250462            {
250463              "license": {
250464                "id": "GPL-2.0-only"
250465              }
250466            },
250467            {
250468              "license": {
250469                "name": "GPLv2+"
250470              }
250471            }
250472          ],
250473          "cpe": "cpe:2.3:a:libapt-pkg5.0:libapt-pkg5.0:1.8.2.3:*:*:*:*:*:*:*",
250474          "purl": "pkg:deb/debian/libapt-pkg5.0@1.8.2.3?arch=amd64\u0026upstream=apt\u0026distro=debian-10",
250475          "swid": {
250476            "attachment": {}
250477          },
250478          "pedigree": {},
250479          "evidence": {},
250480          "signature": {
250481            "signature": {
250482              "publicKey": {}
250483            }
250484          },
250485          "modelCard": {
250486            "modelParameters": {
250487              "approach": {}
250488            },
250489            "quantitativeAnalysis": {
250490              "graphics": {}
250491            },
250492            "considerations": {}
250493          }
250494        },
250495        {
250496          "type": "library",
250497          "bom-ref": "pkg:deb/debian/libattr1@1:2.4.48-4?arch=amd64\u0026upstream=attr\u0026distro=debian-10\u0026package-id=26f28a682fbbe026",
250498          "supplier": {},
250499          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
250500          "name": "libattr1",
250501          "version": "1:2.4.48-4",
250502          "licenses": [
250503            {
250504              "license": {
250505                "id": "GPL-2.0-only"
250506              }
250507            },
250508            {
250509              "license": {
250510                "id": "GPL-2.0-or-later"
250511              }
250512            },
250513            {
250514              "license": {
250515                "id": "LGPL-2.0-or-later"
250516              }
250517            },
250518            {
250519              "license": {
250520                "id": "LGPL-2.1-only"
250521              }
250522            }
250523          ],
250524          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-4:*:*:*:*:*:*:*",
250525          "purl": "pkg:deb/debian/libattr1@1:2.4.48-4?arch=amd64\u0026upstream=attr\u0026distro=debian-10",
250526          "swid": {
250527            "attachment": {}
250528          },
250529          "pedigree": {},
250530          "evidence": {},
250531          "signature": {
250532            "signature": {
250533              "publicKey": {}
250534            }
250535          },
250536          "modelCard": {
250537            "modelParameters": {
250538              "approach": {}
250539            },
250540            "quantitativeAnalysis": {
250541              "graphics": {}
250542            },
250543            "considerations": {}
250544          }
250545        },
250546        {
250547          "type": "library",
250548          "bom-ref": "pkg:deb/debian/libaudit-common@1:2.8.4-3?arch=all\u0026upstream=audit\u0026distro=debian-10\u0026package-id=eacb6fb921d6e85e",
250549          "supplier": {},
250550          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
250551          "name": "libaudit-common",
250552          "version": "1:2.8.4-3",
250553          "licenses": [
250554            {
250555              "license": {
250556                "id": "GPL-1.0-only"
250557              }
250558            },
250559            {
250560              "license": {
250561                "id": "GPL-2.0-only"
250562              }
250563            },
250564            {
250565              "license": {
250566                "id": "LGPL-2.1-only"
250567              }
250568            }
250569          ],
250570          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:2.8.4-3:*:*:*:*:*:*:*",
250571          "purl": "pkg:deb/debian/libaudit-common@1:2.8.4-3?arch=all\u0026upstream=audit\u0026distro=debian-10",
250572          "swid": {
250573            "attachment": {}
250574          },
250575          "pedigree": {},
250576          "evidence": {},
250577          "signature": {
250578            "signature": {
250579              "publicKey": {}
250580            }
250581          },
250582          "modelCard": {
250583            "modelParameters": {
250584              "approach": {}
250585            },
250586            "quantitativeAnalysis": {
250587              "graphics": {}
250588            },
250589            "considerations": {}
250590          }
250591        },
250592        {
250593          "type": "library",
250594          "bom-ref": "pkg:deb/debian/libaudit1@1:2.8.4-3?arch=amd64\u0026upstream=audit\u0026distro=debian-10\u0026package-id=74f57d9ce0c68d86",
250595          "supplier": {},
250596          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
250597          "name": "libaudit1",
250598          "version": "1:2.8.4-3",
250599          "licenses": [
250600            {
250601              "license": {
250602                "id": "GPL-1.0-only"
250603              }
250604            },
250605            {
250606              "license": {
250607                "id": "GPL-2.0-only"
250608              }
250609            },
250610            {
250611              "license": {
250612                "id": "LGPL-2.1-only"
250613              }
250614            }
250615          ],
250616          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:2.8.4-3:*:*:*:*:*:*:*",
250617          "purl": "pkg:deb/debian/libaudit1@1:2.8.4-3?arch=amd64\u0026upstream=audit\u0026distro=debian-10",
250618          "swid": {
250619            "attachment": {}
250620          },
250621          "pedigree": {},
250622          "evidence": {},
250623          "signature": {
250624            "signature": {
250625              "publicKey": {}
250626            }
250627          },
250628          "modelCard": {
250629            "modelParameters": {
250630              "approach": {}
250631            },
250632            "quantitativeAnalysis": {
250633              "graphics": {}
250634            },
250635            "considerations": {}
250636          }
250637        },
250638        {
250639          "type": "library",
250640          "bom-ref": "pkg:deb/debian/libblkid1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=c70296289994443b",
250641          "supplier": {},
250642          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
250643          "name": "libblkid1",
250644          "version": "2.33.1-0.1",
250645          "licenses": [
250646            {
250647              "license": {
250648                "id": "BSD-2-Clause"
250649              }
250650            },
250651            {
250652              "license": {
250653                "id": "BSD-3-Clause"
250654              }
250655            },
250656            {
250657              "license": {
250658                "id": "BSD-4-Clause"
250659              }
250660            },
250661            {
250662              "license": {
250663                "id": "GPL-2.0-only"
250664              }
250665            },
250666            {
250667              "license": {
250668                "id": "GPL-2.0-or-later"
250669              }
250670            },
250671            {
250672              "license": {
250673                "id": "GPL-3.0-only"
250674              }
250675            },
250676            {
250677              "license": {
250678                "id": "GPL-3.0-or-later"
250679              }
250680            },
250681            {
250682              "license": {
250683                "name": "LGPL"
250684              }
250685            },
250686            {
250687              "license": {
250688                "id": "LGPL-2.0-only"
250689              }
250690            },
250691            {
250692              "license": {
250693                "id": "LGPL-2.0-or-later"
250694              }
250695            },
250696            {
250697              "license": {
250698                "id": "LGPL-2.1-only"
250699              }
250700            },
250701            {
250702              "license": {
250703                "id": "LGPL-2.1-or-later"
250704              }
250705            },
250706            {
250707              "license": {
250708                "id": "LGPL-3.0-only"
250709              }
250710            },
250711            {
250712              "license": {
250713                "id": "LGPL-3.0-or-later"
250714              }
250715            },
250716            {
250717              "license": {
250718                "id": "MIT"
250719              }
250720            },
250721            {
250722              "license": {
250723                "name": "public-domain"
250724              }
250725            }
250726          ],
250727          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.33.1-0.1:*:*:*:*:*:*:*",
250728          "purl": "pkg:deb/debian/libblkid1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
250729          "swid": {
250730            "attachment": {}
250731          },
250732          "pedigree": {},
250733          "evidence": {},
250734          "signature": {
250735            "signature": {
250736              "publicKey": {}
250737            }
250738          },
250739          "modelCard": {
250740            "modelParameters": {
250741              "approach": {}
250742            },
250743            "quantitativeAnalysis": {
250744              "graphics": {}
250745            },
250746            "considerations": {}
250747          }
250748        },
250749        {
250750          "type": "library",
250751          "bom-ref": "pkg:deb/debian/libbz2-1.0@1.0.6-9.2~deb10u1?arch=amd64\u0026upstream=bzip2\u0026distro=debian-10\u0026package-id=2cf51f0ebe123d92",
250752          "supplier": {},
250753          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
250754          "name": "libbz2-1.0",
250755          "version": "1.0.6-9.2~deb10u1",
250756          "licenses": [
250757            {
250758              "license": {
250759                "name": "BSD-variant"
250760              }
250761            },
250762            {
250763              "license": {
250764                "id": "GPL-2.0-only"
250765              }
250766            }
250767          ],
250768          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.6-9.2\\~deb10u1:*:*:*:*:*:*:*",
250769          "purl": "pkg:deb/debian/libbz2-1.0@1.0.6-9.2~deb10u1?arch=amd64\u0026upstream=bzip2\u0026distro=debian-10",
250770          "swid": {
250771            "attachment": {}
250772          },
250773          "pedigree": {},
250774          "evidence": {},
250775          "signature": {
250776            "signature": {
250777              "publicKey": {}
250778            }
250779          },
250780          "modelCard": {
250781            "modelParameters": {
250782              "approach": {}
250783            },
250784            "quantitativeAnalysis": {
250785              "graphics": {}
250786            },
250787            "considerations": {}
250788          }
250789        },
250790        {
250791          "type": "library",
250792          "bom-ref": "pkg:deb/debian/libc-bin@2.28-10?arch=amd64\u0026upstream=glibc\u0026distro=debian-10\u0026package-id=e79c24d81f90a0f7",
250793          "supplier": {},
250794          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
250795          "name": "libc-bin",
250796          "version": "2.28-10",
250797          "licenses": [
250798            {
250799              "license": {
250800                "id": "GPL-2.0-only"
250801              }
250802            },
250803            {
250804              "license": {
250805                "id": "LGPL-2.1-only"
250806              }
250807            }
250808          ],
250809          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.28-10:*:*:*:*:*:*:*",
250810          "purl": "pkg:deb/debian/libc-bin@2.28-10?arch=amd64\u0026upstream=glibc\u0026distro=debian-10",
250811          "swid": {
250812            "attachment": {}
250813          },
250814          "pedigree": {},
250815          "evidence": {},
250816          "signature": {
250817            "signature": {
250818              "publicKey": {}
250819            }
250820          },
250821          "modelCard": {
250822            "modelParameters": {
250823              "approach": {}
250824            },
250825            "quantitativeAnalysis": {
250826              "graphics": {}
250827            },
250828            "considerations": {}
250829          }
250830        },
250831        {
250832          "type": "library",
250833          "bom-ref": "pkg:deb/debian/libc6@2.28-10?arch=amd64\u0026upstream=glibc\u0026distro=debian-10\u0026package-id=b5ff55594183baf5",
250834          "supplier": {},
250835          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
250836          "name": "libc6",
250837          "version": "2.28-10",
250838          "licenses": [
250839            {
250840              "license": {
250841                "id": "GPL-2.0-only"
250842              }
250843            },
250844            {
250845              "license": {
250846                "id": "LGPL-2.1-only"
250847              }
250848            }
250849          ],
250850          "cpe": "cpe:2.3:a:libc6:libc6:2.28-10:*:*:*:*:*:*:*",
250851          "purl": "pkg:deb/debian/libc6@2.28-10?arch=amd64\u0026upstream=glibc\u0026distro=debian-10",
250852          "swid": {
250853            "attachment": {}
250854          },
250855          "pedigree": {},
250856          "evidence": {},
250857          "signature": {
250858            "signature": {
250859              "publicKey": {}
250860            }
250861          },
250862          "modelCard": {
250863            "modelParameters": {
250864              "approach": {}
250865            },
250866            "quantitativeAnalysis": {
250867              "graphics": {}
250868            },
250869            "considerations": {}
250870          }
250871        },
250872        {
250873          "type": "library",
250874          "bom-ref": "pkg:deb/debian/libcap-ng0@0.7.9-2?arch=amd64\u0026upstream=libcap-ng\u0026distro=debian-10\u0026package-id=801e27b4655082f1",
250875          "supplier": {},
250876          "publisher": "Pierre Chifflier \u003cpollux@debian.org\u003e",
250877          "name": "libcap-ng0",
250878          "version": "0.7.9-2",
250879          "licenses": [
250880            {
250881              "license": {
250882                "id": "GPL-2.0-only"
250883              }
250884            },
250885            {
250886              "license": {
250887                "id": "GPL-3.0-only"
250888              }
250889            },
250890            {
250891              "license": {
250892                "id": "LGPL-2.1-only"
250893              }
250894            }
250895          ],
250896          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2:*:*:*:*:*:*:*",
250897          "purl": "pkg:deb/debian/libcap-ng0@0.7.9-2?arch=amd64\u0026upstream=libcap-ng\u0026distro=debian-10",
250898          "swid": {
250899            "attachment": {}
250900          },
250901          "pedigree": {},
250902          "evidence": {},
250903          "signature": {
250904            "signature": {
250905              "publicKey": {}
250906            }
250907          },
250908          "modelCard": {
250909            "modelParameters": {
250910              "approach": {}
250911            },
250912            "quantitativeAnalysis": {
250913              "graphics": {}
250914            },
250915            "considerations": {}
250916          }
250917        },
250918        {
250919          "type": "library",
250920          "bom-ref": "pkg:deb/debian/libcom-err2@1.44.5-1+deb10u3?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-10\u0026package-id=c05feef9d71ff201",
250921          "supplier": {},
250922          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
250923          "name": "libcom-err2",
250924          "version": "1.44.5-1+deb10u3",
250925          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.44.5-1\\+deb10u3:*:*:*:*:*:*:*",
250926          "purl": "pkg:deb/debian/libcom-err2@1.44.5-1+deb10u3?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-10",
250927          "swid": {
250928            "attachment": {}
250929          },
250930          "pedigree": {},
250931          "evidence": {},
250932          "signature": {
250933            "signature": {
250934              "publicKey": {}
250935            }
250936          },
250937          "modelCard": {
250938            "modelParameters": {
250939              "approach": {}
250940            },
250941            "quantitativeAnalysis": {
250942              "graphics": {}
250943            },
250944            "considerations": {}
250945          }
250946        },
250947        {
250948          "type": "library",
250949          "bom-ref": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.5?arch=amd64\u0026upstream=db5.3\u0026distro=debian-10\u0026package-id=5f1d8daf8bc92e9d",
250950          "supplier": {},
250951          "publisher": "Debian Berkeley DB Team \u003cteam+bdb@tracker.debian.org\u003e",
250952          "name": "libdb5.3",
250953          "version": "5.3.28+dfsg1-0.5",
250954          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.5:*:*:*:*:*:*:*",
250955          "purl": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.5?arch=amd64\u0026upstream=db5.3\u0026distro=debian-10",
250956          "swid": {
250957            "attachment": {}
250958          },
250959          "pedigree": {},
250960          "evidence": {},
250961          "signature": {
250962            "signature": {
250963              "publicKey": {}
250964            }
250965          },
250966          "modelCard": {
250967            "modelParameters": {
250968              "approach": {}
250969            },
250970            "quantitativeAnalysis": {
250971              "graphics": {}
250972            },
250973            "considerations": {}
250974          }
250975        },
250976        {
250977          "type": "library",
250978          "bom-ref": "pkg:deb/debian/libdebconfclient0@0.249?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-10\u0026package-id=6872b9d4842b81ec",
250979          "supplier": {},
250980          "publisher": "Debian Install System Team \u003cdebian-boot@lists.debian.org\u003e",
250981          "name": "libdebconfclient0",
250982          "version": "0.249",
250983          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.249:*:*:*:*:*:*:*",
250984          "purl": "pkg:deb/debian/libdebconfclient0@0.249?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-10",
250985          "swid": {
250986            "attachment": {}
250987          },
250988          "pedigree": {},
250989          "evidence": {},
250990          "signature": {
250991            "signature": {
250992              "publicKey": {}
250993            }
250994          },
250995          "modelCard": {
250996            "modelParameters": {
250997              "approach": {}
250998            },
250999            "quantitativeAnalysis": {
251000              "graphics": {}
251001            },
251002            "considerations": {}
251003          }
251004        },
251005        {
251006          "type": "library",
251007          "bom-ref": "pkg:deb/debian/libext2fs2@1.44.5-1+deb10u3?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-10\u0026package-id=182468cb92f6dd82",
251008          "supplier": {},
251009          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
251010          "name": "libext2fs2",
251011          "version": "1.44.5-1+deb10u3",
251012          "licenses": [
251013            {
251014              "license": {
251015                "id": "GPL-2.0-only"
251016              }
251017            },
251018            {
251019              "license": {
251020                "id": "LGPL-2.0-only"
251021              }
251022            }
251023          ],
251024          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.44.5-1\\+deb10u3:*:*:*:*:*:*:*",
251025          "purl": "pkg:deb/debian/libext2fs2@1.44.5-1+deb10u3?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-10",
251026          "swid": {
251027            "attachment": {}
251028          },
251029          "pedigree": {},
251030          "evidence": {},
251031          "signature": {
251032            "signature": {
251033              "publicKey": {}
251034            }
251035          },
251036          "modelCard": {
251037            "modelParameters": {
251038              "approach": {}
251039            },
251040            "quantitativeAnalysis": {
251041              "graphics": {}
251042            },
251043            "considerations": {}
251044          }
251045        },
251046        {
251047          "type": "library",
251048          "bom-ref": "pkg:deb/debian/libfdisk1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=6c6e62c52a86ba09",
251049          "supplier": {},
251050          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
251051          "name": "libfdisk1",
251052          "version": "2.33.1-0.1",
251053          "licenses": [
251054            {
251055              "license": {
251056                "id": "BSD-2-Clause"
251057              }
251058            },
251059            {
251060              "license": {
251061                "id": "BSD-3-Clause"
251062              }
251063            },
251064            {
251065              "license": {
251066                "id": "BSD-4-Clause"
251067              }
251068            },
251069            {
251070              "license": {
251071                "id": "GPL-2.0-only"
251072              }
251073            },
251074            {
251075              "license": {
251076                "id": "GPL-2.0-or-later"
251077              }
251078            },
251079            {
251080              "license": {
251081                "id": "GPL-3.0-only"
251082              }
251083            },
251084            {
251085              "license": {
251086                "id": "GPL-3.0-or-later"
251087              }
251088            },
251089            {
251090              "license": {
251091                "name": "LGPL"
251092              }
251093            },
251094            {
251095              "license": {
251096                "id": "LGPL-2.0-only"
251097              }
251098            },
251099            {
251100              "license": {
251101                "id": "LGPL-2.0-or-later"
251102              }
251103            },
251104            {
251105              "license": {
251106                "id": "LGPL-2.1-only"
251107              }
251108            },
251109            {
251110              "license": {
251111                "id": "LGPL-2.1-or-later"
251112              }
251113            },
251114            {
251115              "license": {
251116                "id": "LGPL-3.0-only"
251117              }
251118            },
251119            {
251120              "license": {
251121                "id": "LGPL-3.0-or-later"
251122              }
251123            },
251124            {
251125              "license": {
251126                "id": "MIT"
251127              }
251128            },
251129            {
251130              "license": {
251131                "name": "public-domain"
251132              }
251133            }
251134          ],
251135          "cpe": "cpe:2.3:a:libfdisk1:libfdisk1:2.33.1-0.1:*:*:*:*:*:*:*",
251136          "purl": "pkg:deb/debian/libfdisk1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
251137          "swid": {
251138            "attachment": {}
251139          },
251140          "pedigree": {},
251141          "evidence": {},
251142          "signature": {
251143            "signature": {
251144              "publicKey": {}
251145            }
251146          },
251147          "modelCard": {
251148            "modelParameters": {
251149              "approach": {}
251150            },
251151            "quantitativeAnalysis": {
251152              "graphics": {}
251153            },
251154            "considerations": {}
251155          }
251156        },
251157        {
251158          "type": "library",
251159          "bom-ref": "pkg:deb/debian/libffi6@3.2.1-9?arch=amd64\u0026upstream=libffi\u0026distro=debian-10\u0026package-id=40f6d811db6b6459",
251160          "supplier": {},
251161          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
251162          "name": "libffi6",
251163          "version": "3.2.1-9",
251164          "licenses": [
251165            {
251166              "license": {
251167                "name": "GPL"
251168              }
251169            }
251170          ],
251171          "cpe": "cpe:2.3:a:libffi6:libffi6:3.2.1-9:*:*:*:*:*:*:*",
251172          "purl": "pkg:deb/debian/libffi6@3.2.1-9?arch=amd64\u0026upstream=libffi\u0026distro=debian-10",
251173          "swid": {
251174            "attachment": {}
251175          },
251176          "pedigree": {},
251177          "evidence": {},
251178          "signature": {
251179            "signature": {
251180              "publicKey": {}
251181            }
251182          },
251183          "modelCard": {
251184            "modelParameters": {
251185              "approach": {}
251186            },
251187            "quantitativeAnalysis": {
251188              "graphics": {}
251189            },
251190            "considerations": {}
251191          }
251192        },
251193        {
251194          "type": "library",
251195          "bom-ref": "pkg:deb/debian/libgcc1@1:8.3.0-6?arch=amd64\u0026upstream=gcc-8%408.3.0-6\u0026distro=debian-10\u0026package-id=a4ec20e9bb10a790",
251196          "supplier": {},
251197          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
251198          "name": "libgcc1",
251199          "version": "1:8.3.0-6",
251200          "licenses": [
251201            {
251202              "license": {
251203                "name": "Artistic"
251204              }
251205            },
251206            {
251207              "license": {
251208                "id": "GFDL-1.2-only"
251209              }
251210            },
251211            {
251212              "license": {
251213                "name": "GPL"
251214              }
251215            },
251216            {
251217              "license": {
251218                "id": "GPL-2.0-only"
251219              }
251220            },
251221            {
251222              "license": {
251223                "id": "GPL-3.0-only"
251224              }
251225            },
251226            {
251227              "license": {
251228                "name": "LGPL"
251229              }
251230            }
251231          ],
251232          "cpe": "cpe:2.3:a:libgcc1:libgcc1:1\\:8.3.0-6:*:*:*:*:*:*:*",
251233          "purl": "pkg:deb/debian/libgcc1@1:8.3.0-6?arch=amd64\u0026upstream=gcc-8%408.3.0-6\u0026distro=debian-10",
251234          "swid": {
251235            "attachment": {}
251236          },
251237          "pedigree": {},
251238          "evidence": {},
251239          "signature": {
251240            "signature": {
251241              "publicKey": {}
251242            }
251243          },
251244          "modelCard": {
251245            "modelParameters": {
251246              "approach": {}
251247            },
251248            "quantitativeAnalysis": {
251249              "graphics": {}
251250            },
251251            "considerations": {}
251252          }
251253        },
251254        {
251255          "type": "library",
251256          "bom-ref": "pkg:deb/debian/libgcrypt20@1.8.4-5+deb10u1?arch=amd64\u0026distro=debian-10\u0026package-id=3e78c615e5274de",
251257          "supplier": {},
251258          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
251259          "name": "libgcrypt20",
251260          "version": "1.8.4-5+deb10u1",
251261          "licenses": [
251262            {
251263              "license": {
251264                "id": "GPL-2.0-only"
251265              }
251266            },
251267            {
251268              "license": {
251269                "name": "LGPL"
251270              }
251271            }
251272          ],
251273          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.4-5\\+deb10u1:*:*:*:*:*:*:*",
251274          "purl": "pkg:deb/debian/libgcrypt20@1.8.4-5+deb10u1?arch=amd64\u0026distro=debian-10",
251275          "swid": {
251276            "attachment": {}
251277          },
251278          "pedigree": {},
251279          "evidence": {},
251280          "signature": {
251281            "signature": {
251282              "publicKey": {}
251283            }
251284          },
251285          "modelCard": {
251286            "modelParameters": {
251287              "approach": {}
251288            },
251289            "quantitativeAnalysis": {
251290              "graphics": {}
251291            },
251292            "considerations": {}
251293          }
251294        },
251295        {
251296          "type": "library",
251297          "bom-ref": "pkg:deb/debian/libgmp10@2:6.1.2+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=debian-10\u0026package-id=8681d22eff791901",
251298          "supplier": {},
251299          "publisher": "Debian Science Team \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e",
251300          "name": "libgmp10",
251301          "version": "2:6.1.2+dfsg-4",
251302          "licenses": [
251303            {
251304              "license": {
251305                "name": "GPL"
251306              }
251307            },
251308            {
251309              "license": {
251310                "id": "GPL-2.0-only"
251311              }
251312            },
251313            {
251314              "license": {
251315                "id": "GPL-3.0-only"
251316              }
251317            },
251318            {
251319              "license": {
251320                "id": "LGPL-3.0-only"
251321              }
251322            }
251323          ],
251324          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.1.2\\+dfsg-4:*:*:*:*:*:*:*",
251325          "purl": "pkg:deb/debian/libgmp10@2:6.1.2+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=debian-10",
251326          "swid": {
251327            "attachment": {}
251328          },
251329          "pedigree": {},
251330          "evidence": {},
251331          "signature": {
251332            "signature": {
251333              "publicKey": {}
251334            }
251335          },
251336          "modelCard": {
251337            "modelParameters": {
251338              "approach": {}
251339            },
251340            "quantitativeAnalysis": {
251341              "graphics": {}
251342            },
251343            "considerations": {}
251344          }
251345        },
251346        {
251347          "type": "library",
251348          "bom-ref": "pkg:deb/debian/libgnutls30@3.6.7-4+deb10u7?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-10\u0026package-id=1af9b360964e957b",
251349          "supplier": {},
251350          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
251351          "name": "libgnutls30",
251352          "version": "3.6.7-4+deb10u7",
251353          "licenses": [
251354            {
251355              "license": {
251356                "id": "Apache-2.0"
251357              }
251358            },
251359            {
251360              "license": {
251361                "name": "CC0"
251362              }
251363            },
251364            {
251365              "license": {
251366                "id": "GFDL-1.3-only"
251367              }
251368            },
251369            {
251370              "license": {
251371                "name": "GPL"
251372              }
251373            },
251374            {
251375              "license": {
251376                "id": "GPL-3.0-only"
251377              }
251378            },
251379            {
251380              "license": {
251381                "name": "GPLv3+"
251382              }
251383            },
251384            {
251385              "license": {
251386                "name": "LGPL"
251387              }
251388            },
251389            {
251390              "license": {
251391                "id": "LGPL-3.0-only"
251392              }
251393            },
251394            {
251395              "license": {
251396                "name": "LGPLv3+_or_GPLv2+"
251397              }
251398            },
251399            {
251400              "license": {
251401                "name": "The"
251402              }
251403            }
251404          ],
251405          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.7-4\\+deb10u7:*:*:*:*:*:*:*",
251406          "purl": "pkg:deb/debian/libgnutls30@3.6.7-4+deb10u7?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-10",
251407          "swid": {
251408            "attachment": {}
251409          },
251410          "pedigree": {},
251411          "evidence": {},
251412          "signature": {
251413            "signature": {
251414              "publicKey": {}
251415            }
251416          },
251417          "modelCard": {
251418            "modelParameters": {
251419              "approach": {}
251420            },
251421            "quantitativeAnalysis": {
251422              "graphics": {}
251423            },
251424            "considerations": {}
251425          }
251426        },
251427        {
251428          "type": "library",
251429          "bom-ref": "pkg:deb/debian/libgpg-error0@1.35-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-10\u0026package-id=e650eaf4629b1d02",
251430          "supplier": {},
251431          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
251432          "name": "libgpg-error0",
251433          "version": "1.35-1",
251434          "licenses": [
251435            {
251436              "license": {
251437                "id": "BSD-3-Clause"
251438              }
251439            },
251440            {
251441              "license": {
251442                "id": "GPL-3.0-only"
251443              }
251444            },
251445            {
251446              "license": {
251447                "id": "GPL-3.0-or-later"
251448              }
251449            },
251450            {
251451              "license": {
251452                "id": "LGPL-2.1-only"
251453              }
251454            },
251455            {
251456              "license": {
251457                "id": "LGPL-2.1-or-later"
251458              }
251459            },
251460            {
251461              "license": {
251462                "name": "g10-permissive"
251463              }
251464            }
251465          ],
251466          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.35-1:*:*:*:*:*:*:*",
251467          "purl": "pkg:deb/debian/libgpg-error0@1.35-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-10",
251468          "swid": {
251469            "attachment": {}
251470          },
251471          "pedigree": {},
251472          "evidence": {},
251473          "signature": {
251474            "signature": {
251475              "publicKey": {}
251476            }
251477          },
251478          "modelCard": {
251479            "modelParameters": {
251480              "approach": {}
251481            },
251482            "quantitativeAnalysis": {
251483              "graphics": {}
251484            },
251485            "considerations": {}
251486          }
251487        },
251488        {
251489          "type": "library",
251490          "bom-ref": "pkg:deb/debian/libhogweed4@3.4.1-1+deb10u1?arch=amd64\u0026upstream=nettle\u0026distro=debian-10\u0026package-id=57eaf28dd9e5956e",
251491          "supplier": {},
251492          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
251493          "name": "libhogweed4",
251494          "version": "3.4.1-1+deb10u1",
251495          "licenses": [
251496            {
251497              "license": {
251498                "name": "GAP"
251499              }
251500            },
251501            {
251502              "license": {
251503                "name": "GPL"
251504              }
251505            },
251506            {
251507              "license": {
251508                "id": "GPL-2.0-only"
251509              }
251510            },
251511            {
251512              "license": {
251513                "id": "GPL-2.0-or-later"
251514              }
251515            },
251516            {
251517              "license": {
251518                "name": "LGPL"
251519              }
251520            },
251521            {
251522              "license": {
251523                "id": "LGPL-2.0-only"
251524              }
251525            },
251526            {
251527              "license": {
251528                "id": "LGPL-2.0-or-later"
251529              }
251530            },
251531            {
251532              "license": {
251533                "id": "LGPL-2.1-or-later"
251534              }
251535            },
251536            {
251537              "license": {
251538                "name": "other"
251539              }
251540            },
251541            {
251542              "license": {
251543                "name": "public-domain"
251544              }
251545            }
251546          ],
251547          "cpe": "cpe:2.3:a:libhogweed4:libhogweed4:3.4.1-1\\+deb10u1:*:*:*:*:*:*:*",
251548          "purl": "pkg:deb/debian/libhogweed4@3.4.1-1+deb10u1?arch=amd64\u0026upstream=nettle\u0026distro=debian-10",
251549          "swid": {
251550            "attachment": {}
251551          },
251552          "pedigree": {},
251553          "evidence": {},
251554          "signature": {
251555            "signature": {
251556              "publicKey": {}
251557            }
251558          },
251559          "modelCard": {
251560            "modelParameters": {
251561              "approach": {}
251562            },
251563            "quantitativeAnalysis": {
251564              "graphics": {}
251565            },
251566            "considerations": {}
251567          }
251568        },
251569        {
251570          "type": "library",
251571          "bom-ref": "pkg:deb/debian/libidn2-0@2.0.5-1+deb10u1?arch=amd64\u0026upstream=libidn2\u0026distro=debian-10\u0026package-id=fb57203f630b9840",
251572          "supplier": {},
251573          "publisher": "Debian Libidn team \u003chelp-libidn@gnu.org\u003e",
251574          "name": "libidn2-0",
251575          "version": "2.0.5-1+deb10u1",
251576          "licenses": [
251577            {
251578              "license": {
251579                "id": "GPL-2.0-only"
251580              }
251581            },
251582            {
251583              "license": {
251584                "id": "GPL-2.0-or-later"
251585              }
251586            },
251587            {
251588              "license": {
251589                "id": "GPL-3.0-only"
251590              }
251591            },
251592            {
251593              "license": {
251594                "id": "GPL-3.0-or-later"
251595              }
251596            },
251597            {
251598              "license": {
251599                "id": "LGPL-3.0-only"
251600              }
251601            },
251602            {
251603              "license": {
251604                "id": "LGPL-3.0-or-later"
251605              }
251606            },
251607            {
251608              "license": {
251609                "name": "Unicode"
251610              }
251611            }
251612          ],
251613          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.0.5-1\\+deb10u1:*:*:*:*:*:*:*",
251614          "purl": "pkg:deb/debian/libidn2-0@2.0.5-1+deb10u1?arch=amd64\u0026upstream=libidn2\u0026distro=debian-10",
251615          "swid": {
251616            "attachment": {}
251617          },
251618          "pedigree": {},
251619          "evidence": {},
251620          "signature": {
251621            "signature": {
251622              "publicKey": {}
251623            }
251624          },
251625          "modelCard": {
251626            "modelParameters": {
251627              "approach": {}
251628            },
251629            "quantitativeAnalysis": {
251630              "graphics": {}
251631            },
251632            "considerations": {}
251633          }
251634        },
251635        {
251636          "type": "library",
251637          "bom-ref": "pkg:deb/debian/liblz4-1@1.8.3-1+deb10u1?arch=amd64\u0026upstream=lz4\u0026distro=debian-10\u0026package-id=3703c0e5f7c5fec2",
251638          "supplier": {},
251639          "publisher": "Nobuhiro Iwamatsu \u003ciwamatsu@debian.org\u003e",
251640          "name": "liblz4-1",
251641          "version": "1.8.3-1+deb10u1",
251642          "licenses": [
251643            {
251644              "license": {
251645                "id": "BSD-2-Clause"
251646              }
251647            },
251648            {
251649              "license": {
251650                "id": "GPL-2.0-only"
251651              }
251652            },
251653            {
251654              "license": {
251655                "id": "GPL-2.0-or-later"
251656              }
251657            }
251658          ],
251659          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.8.3-1\\+deb10u1:*:*:*:*:*:*:*",
251660          "purl": "pkg:deb/debian/liblz4-1@1.8.3-1+deb10u1?arch=amd64\u0026upstream=lz4\u0026distro=debian-10",
251661          "swid": {
251662            "attachment": {}
251663          },
251664          "pedigree": {},
251665          "evidence": {},
251666          "signature": {
251667            "signature": {
251668              "publicKey": {}
251669            }
251670          },
251671          "modelCard": {
251672            "modelParameters": {
251673              "approach": {}
251674            },
251675            "quantitativeAnalysis": {
251676              "graphics": {}
251677            },
251678            "considerations": {}
251679          }
251680        },
251681        {
251682          "type": "library",
251683          "bom-ref": "pkg:deb/debian/liblzma5@5.2.4-1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-10\u0026package-id=711120f227a4ca8",
251684          "supplier": {},
251685          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
251686          "name": "liblzma5",
251687          "version": "5.2.4-1",
251688          "licenses": [
251689            {
251690              "license": {
251691                "name": "Autoconf"
251692              }
251693            },
251694            {
251695              "license": {
251696                "id": "GPL-2.0-only"
251697              }
251698            },
251699            {
251700              "license": {
251701                "id": "GPL-2.0-or-later"
251702              }
251703            },
251704            {
251705              "license": {
251706                "id": "GPL-3.0-only"
251707              }
251708            },
251709            {
251710              "license": {
251711                "id": "LGPL-2.0-only"
251712              }
251713            },
251714            {
251715              "license": {
251716                "id": "LGPL-2.1-only"
251717              }
251718            },
251719            {
251720              "license": {
251721                "id": "LGPL-2.1-or-later"
251722              }
251723            },
251724            {
251725              "license": {
251726                "name": "PD"
251727              }
251728            },
251729            {
251730              "license": {
251731                "name": "PD-debian"
251732              }
251733            },
251734            {
251735              "license": {
251736                "name": "config-h"
251737              }
251738            },
251739            {
251740              "license": {
251741                "name": "noderivs"
251742              }
251743            },
251744            {
251745              "license": {
251746                "name": "permissive-fsf"
251747              }
251748            },
251749            {
251750              "license": {
251751                "name": "permissive-nowarranty"
251752              }
251753            },
251754            {
251755              "license": {
251756                "name": "probably-PD"
251757              }
251758            }
251759          ],
251760          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.4-1:*:*:*:*:*:*:*",
251761          "purl": "pkg:deb/debian/liblzma5@5.2.4-1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-10",
251762          "swid": {
251763            "attachment": {}
251764          },
251765          "pedigree": {},
251766          "evidence": {},
251767          "signature": {
251768            "signature": {
251769              "publicKey": {}
251770            }
251771          },
251772          "modelCard": {
251773            "modelParameters": {
251774              "approach": {}
251775            },
251776            "quantitativeAnalysis": {
251777              "graphics": {}
251778            },
251779            "considerations": {}
251780          }
251781        },
251782        {
251783          "type": "library",
251784          "bom-ref": "pkg:deb/debian/libmount1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=e7866651c1082fc0",
251785          "supplier": {},
251786          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
251787          "name": "libmount1",
251788          "version": "2.33.1-0.1",
251789          "licenses": [
251790            {
251791              "license": {
251792                "id": "BSD-2-Clause"
251793              }
251794            },
251795            {
251796              "license": {
251797                "id": "BSD-3-Clause"
251798              }
251799            },
251800            {
251801              "license": {
251802                "id": "BSD-4-Clause"
251803              }
251804            },
251805            {
251806              "license": {
251807                "id": "GPL-2.0-only"
251808              }
251809            },
251810            {
251811              "license": {
251812                "id": "GPL-2.0-or-later"
251813              }
251814            },
251815            {
251816              "license": {
251817                "id": "GPL-3.0-only"
251818              }
251819            },
251820            {
251821              "license": {
251822                "id": "GPL-3.0-or-later"
251823              }
251824            },
251825            {
251826              "license": {
251827                "name": "LGPL"
251828              }
251829            },
251830            {
251831              "license": {
251832                "id": "LGPL-2.0-only"
251833              }
251834            },
251835            {
251836              "license": {
251837                "id": "LGPL-2.0-or-later"
251838              }
251839            },
251840            {
251841              "license": {
251842                "id": "LGPL-2.1-only"
251843              }
251844            },
251845            {
251846              "license": {
251847                "id": "LGPL-2.1-or-later"
251848              }
251849            },
251850            {
251851              "license": {
251852                "id": "LGPL-3.0-only"
251853              }
251854            },
251855            {
251856              "license": {
251857                "id": "LGPL-3.0-or-later"
251858              }
251859            },
251860            {
251861              "license": {
251862                "id": "MIT"
251863              }
251864            },
251865            {
251866              "license": {
251867                "name": "public-domain"
251868              }
251869            }
251870          ],
251871          "cpe": "cpe:2.3:a:libmount1:libmount1:2.33.1-0.1:*:*:*:*:*:*:*",
251872          "purl": "pkg:deb/debian/libmount1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
251873          "swid": {
251874            "attachment": {}
251875          },
251876          "pedigree": {},
251877          "evidence": {},
251878          "signature": {
251879            "signature": {
251880              "publicKey": {}
251881            }
251882          },
251883          "modelCard": {
251884            "modelParameters": {
251885              "approach": {}
251886            },
251887            "quantitativeAnalysis": {
251888              "graphics": {}
251889            },
251890            "considerations": {}
251891          }
251892        },
251893        {
251894          "type": "library",
251895          "bom-ref": "pkg:deb/debian/libncursesw6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10\u0026package-id=71854d05b1ca05ab",
251896          "supplier": {},
251897          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
251898          "name": "libncursesw6",
251899          "version": "6.1+20181013-2+deb10u2",
251900          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.1\\+20181013-2\\+deb10u2:*:*:*:*:*:*:*",
251901          "purl": "pkg:deb/debian/libncursesw6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10",
251902          "swid": {
251903            "attachment": {}
251904          },
251905          "pedigree": {},
251906          "evidence": {},
251907          "signature": {
251908            "signature": {
251909              "publicKey": {}
251910            }
251911          },
251912          "modelCard": {
251913            "modelParameters": {
251914              "approach": {}
251915            },
251916            "quantitativeAnalysis": {
251917              "graphics": {}
251918            },
251919            "considerations": {}
251920          }
251921        },
251922        {
251923          "type": "library",
251924          "bom-ref": "pkg:deb/debian/libnettle6@3.4.1-1+deb10u1?arch=amd64\u0026upstream=nettle\u0026distro=debian-10\u0026package-id=7d68638a3712de41",
251925          "supplier": {},
251926          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
251927          "name": "libnettle6",
251928          "version": "3.4.1-1+deb10u1",
251929          "licenses": [
251930            {
251931              "license": {
251932                "name": "GAP"
251933              }
251934            },
251935            {
251936              "license": {
251937                "name": "GPL"
251938              }
251939            },
251940            {
251941              "license": {
251942                "id": "GPL-2.0-only"
251943              }
251944            },
251945            {
251946              "license": {
251947                "id": "GPL-2.0-or-later"
251948              }
251949            },
251950            {
251951              "license": {
251952                "name": "LGPL"
251953              }
251954            },
251955            {
251956              "license": {
251957                "id": "LGPL-2.0-only"
251958              }
251959            },
251960            {
251961              "license": {
251962                "id": "LGPL-2.0-or-later"
251963              }
251964            },
251965            {
251966              "license": {
251967                "id": "LGPL-2.1-or-later"
251968              }
251969            },
251970            {
251971              "license": {
251972                "name": "other"
251973              }
251974            },
251975            {
251976              "license": {
251977                "name": "public-domain"
251978              }
251979            }
251980          ],
251981          "cpe": "cpe:2.3:a:libnettle6:libnettle6:3.4.1-1\\+deb10u1:*:*:*:*:*:*:*",
251982          "purl": "pkg:deb/debian/libnettle6@3.4.1-1+deb10u1?arch=amd64\u0026upstream=nettle\u0026distro=debian-10",
251983          "swid": {
251984            "attachment": {}
251985          },
251986          "pedigree": {},
251987          "evidence": {},
251988          "signature": {
251989            "signature": {
251990              "publicKey": {}
251991            }
251992          },
251993          "modelCard": {
251994            "modelParameters": {
251995              "approach": {}
251996            },
251997            "quantitativeAnalysis": {
251998              "graphics": {}
251999            },
252000            "considerations": {}
252001          }
252002        },
252003        {
252004          "type": "library",
252005          "bom-ref": "pkg:deb/debian/libp11-kit0@0.23.15-2+deb10u1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-10\u0026package-id=d609c3d39a184627",
252006          "supplier": {},
252007          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
252008          "name": "libp11-kit0",
252009          "version": "0.23.15-2+deb10u1",
252010          "licenses": [
252011            {
252012              "license": {
252013                "id": "BSD-3-Clause"
252014              }
252015            },
252016            {
252017              "license": {
252018                "id": "ISC"
252019              }
252020            },
252021            {
252022              "license": {
252023                "name": "ISC+IBM"
252024              }
252025            },
252026            {
252027              "license": {
252028                "name": "permissive-like-automake-output"
252029              }
252030            },
252031            {
252032              "license": {
252033                "name": "same-as-rest-of-p11kit"
252034              }
252035            }
252036          ],
252037          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.15-2\\+deb10u1:*:*:*:*:*:*:*",
252038          "purl": "pkg:deb/debian/libp11-kit0@0.23.15-2+deb10u1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-10",
252039          "swid": {
252040            "attachment": {}
252041          },
252042          "pedigree": {},
252043          "evidence": {},
252044          "signature": {
252045            "signature": {
252046              "publicKey": {}
252047            }
252048          },
252049          "modelCard": {
252050            "modelParameters": {
252051              "approach": {}
252052            },
252053            "quantitativeAnalysis": {
252054              "graphics": {}
252055            },
252056            "considerations": {}
252057          }
252058        },
252059        {
252060          "type": "library",
252061          "bom-ref": "pkg:deb/debian/libpam-modules@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10\u0026package-id=aab3cfb1d218fd23",
252062          "supplier": {},
252063          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
252064          "name": "libpam-modules",
252065          "version": "1.3.1-5",
252066          "licenses": [
252067            {
252068              "license": {
252069                "name": "GPL"
252070              }
252071            }
252072          ],
252073          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.3.1-5:*:*:*:*:*:*:*",
252074          "purl": "pkg:deb/debian/libpam-modules@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10",
252075          "swid": {
252076            "attachment": {}
252077          },
252078          "pedigree": {},
252079          "evidence": {},
252080          "signature": {
252081            "signature": {
252082              "publicKey": {}
252083            }
252084          },
252085          "modelCard": {
252086            "modelParameters": {
252087              "approach": {}
252088            },
252089            "quantitativeAnalysis": {
252090              "graphics": {}
252091            },
252092            "considerations": {}
252093          }
252094        },
252095        {
252096          "type": "library",
252097          "bom-ref": "pkg:deb/debian/libpam-modules-bin@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10\u0026package-id=12161ce3bab02f2",
252098          "supplier": {},
252099          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
252100          "name": "libpam-modules-bin",
252101          "version": "1.3.1-5",
252102          "licenses": [
252103            {
252104              "license": {
252105                "name": "GPL"
252106              }
252107            }
252108          ],
252109          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.3.1-5:*:*:*:*:*:*:*",
252110          "purl": "pkg:deb/debian/libpam-modules-bin@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10",
252111          "swid": {
252112            "attachment": {}
252113          },
252114          "pedigree": {},
252115          "evidence": {},
252116          "signature": {
252117            "signature": {
252118              "publicKey": {}
252119            }
252120          },
252121          "modelCard": {
252122            "modelParameters": {
252123              "approach": {}
252124            },
252125            "quantitativeAnalysis": {
252126              "graphics": {}
252127            },
252128            "considerations": {}
252129          }
252130        },
252131        {
252132          "type": "library",
252133          "bom-ref": "pkg:deb/debian/libpam-runtime@1.3.1-5?arch=all\u0026upstream=pam\u0026distro=debian-10\u0026package-id=6db7f7079130ac03",
252134          "supplier": {},
252135          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
252136          "name": "libpam-runtime",
252137          "version": "1.3.1-5",
252138          "licenses": [
252139            {
252140              "license": {
252141                "name": "GPL"
252142              }
252143            }
252144          ],
252145          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.3.1-5:*:*:*:*:*:*:*",
252146          "purl": "pkg:deb/debian/libpam-runtime@1.3.1-5?arch=all\u0026upstream=pam\u0026distro=debian-10",
252147          "swid": {
252148            "attachment": {}
252149          },
252150          "pedigree": {},
252151          "evidence": {},
252152          "signature": {
252153            "signature": {
252154              "publicKey": {}
252155            }
252156          },
252157          "modelCard": {
252158            "modelParameters": {
252159              "approach": {}
252160            },
252161            "quantitativeAnalysis": {
252162              "graphics": {}
252163            },
252164            "considerations": {}
252165          }
252166        },
252167        {
252168          "type": "library",
252169          "bom-ref": "pkg:deb/debian/libpam0g@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10\u0026package-id=91c506d4399b261f",
252170          "supplier": {},
252171          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
252172          "name": "libpam0g",
252173          "version": "1.3.1-5",
252174          "licenses": [
252175            {
252176              "license": {
252177                "name": "GPL"
252178              }
252179            }
252180          ],
252181          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.3.1-5:*:*:*:*:*:*:*",
252182          "purl": "pkg:deb/debian/libpam0g@1.3.1-5?arch=amd64\u0026upstream=pam\u0026distro=debian-10",
252183          "swid": {
252184            "attachment": {}
252185          },
252186          "pedigree": {},
252187          "evidence": {},
252188          "signature": {
252189            "signature": {
252190              "publicKey": {}
252191            }
252192          },
252193          "modelCard": {
252194            "modelParameters": {
252195              "approach": {}
252196            },
252197            "quantitativeAnalysis": {
252198              "graphics": {}
252199            },
252200            "considerations": {}
252201          }
252202        },
252203        {
252204          "type": "library",
252205          "bom-ref": "pkg:deb/debian/libpcre3@2:8.39-12?arch=amd64\u0026upstream=pcre3\u0026distro=debian-10\u0026package-id=d463b0783493ae72",
252206          "supplier": {},
252207          "publisher": "Matthew Vernon \u003cmatthew@debian.org\u003e",
252208          "name": "libpcre3",
252209          "version": "2:8.39-12",
252210          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-12:*:*:*:*:*:*:*",
252211          "purl": "pkg:deb/debian/libpcre3@2:8.39-12?arch=amd64\u0026upstream=pcre3\u0026distro=debian-10",
252212          "swid": {
252213            "attachment": {}
252214          },
252215          "pedigree": {},
252216          "evidence": {},
252217          "signature": {
252218            "signature": {
252219              "publicKey": {}
252220            }
252221          },
252222          "modelCard": {
252223            "modelParameters": {
252224              "approach": {}
252225            },
252226            "quantitativeAnalysis": {
252227              "graphics": {}
252228            },
252229            "considerations": {}
252230          }
252231        },
252232        {
252233          "type": "library",
252234          "bom-ref": "pkg:deb/debian/libseccomp2@2.3.3-4?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-10\u0026package-id=b751700bd628a765",
252235          "supplier": {},
252236          "publisher": "Kees Cook \u003ckees@debian.org\u003e",
252237          "name": "libseccomp2",
252238          "version": "2.3.3-4",
252239          "licenses": [
252240            {
252241              "license": {
252242                "id": "LGPL-2.1-only"
252243              }
252244            }
252245          ],
252246          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.3.3-4:*:*:*:*:*:*:*",
252247          "purl": "pkg:deb/debian/libseccomp2@2.3.3-4?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-10",
252248          "swid": {
252249            "attachment": {}
252250          },
252251          "pedigree": {},
252252          "evidence": {},
252253          "signature": {
252254            "signature": {
252255              "publicKey": {}
252256            }
252257          },
252258          "modelCard": {
252259            "modelParameters": {
252260              "approach": {}
252261            },
252262            "quantitativeAnalysis": {
252263              "graphics": {}
252264            },
252265            "considerations": {}
252266          }
252267        },
252268        {
252269          "type": "library",
252270          "bom-ref": "pkg:deb/debian/libselinux1@2.8-1+b1?arch=amd64\u0026upstream=libselinux%402.8-1\u0026distro=debian-10\u0026package-id=123a35c7043b0a0",
252271          "supplier": {},
252272          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
252273          "name": "libselinux1",
252274          "version": "2.8-1+b1",
252275          "licenses": [
252276            {
252277              "license": {
252278                "id": "GPL-2.0-only"
252279              }
252280            },
252281            {
252282              "license": {
252283                "id": "LGPL-2.1-only"
252284              }
252285            }
252286          ],
252287          "cpe": "cpe:2.3:a:libselinux1:libselinux1:2.8-1\\+b1:*:*:*:*:*:*:*",
252288          "purl": "pkg:deb/debian/libselinux1@2.8-1+b1?arch=amd64\u0026upstream=libselinux%402.8-1\u0026distro=debian-10",
252289          "swid": {
252290            "attachment": {}
252291          },
252292          "pedigree": {},
252293          "evidence": {},
252294          "signature": {
252295            "signature": {
252296              "publicKey": {}
252297            }
252298          },
252299          "modelCard": {
252300            "modelParameters": {
252301              "approach": {}
252302            },
252303            "quantitativeAnalysis": {
252304              "graphics": {}
252305            },
252306            "considerations": {}
252307          }
252308        },
252309        {
252310          "type": "library",
252311          "bom-ref": "pkg:deb/debian/libsemanage-common@2.8-2?arch=all\u0026upstream=libsemanage\u0026distro=debian-10\u0026package-id=720058c21890c44f",
252312          "supplier": {},
252313          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
252314          "name": "libsemanage-common",
252315          "version": "2.8-2",
252316          "licenses": [
252317            {
252318              "license": {
252319                "name": "GPL"
252320              }
252321            },
252322            {
252323              "license": {
252324                "name": "LGPL"
252325              }
252326            }
252327          ],
252328          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:2.8-2:*:*:*:*:*:*:*",
252329          "purl": "pkg:deb/debian/libsemanage-common@2.8-2?arch=all\u0026upstream=libsemanage\u0026distro=debian-10",
252330          "swid": {
252331            "attachment": {}
252332          },
252333          "pedigree": {},
252334          "evidence": {},
252335          "signature": {
252336            "signature": {
252337              "publicKey": {}
252338            }
252339          },
252340          "modelCard": {
252341            "modelParameters": {
252342              "approach": {}
252343            },
252344            "quantitativeAnalysis": {
252345              "graphics": {}
252346            },
252347            "considerations": {}
252348          }
252349        },
252350        {
252351          "type": "library",
252352          "bom-ref": "pkg:deb/debian/libsemanage1@2.8-2?arch=amd64\u0026upstream=libsemanage\u0026distro=debian-10\u0026package-id=cd3c06cc7a1130a4",
252353          "supplier": {},
252354          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
252355          "name": "libsemanage1",
252356          "version": "2.8-2",
252357          "licenses": [
252358            {
252359              "license": {
252360                "name": "GPL"
252361              }
252362            },
252363            {
252364              "license": {
252365                "name": "LGPL"
252366              }
252367            }
252368          ],
252369          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:2.8-2:*:*:*:*:*:*:*",
252370          "purl": "pkg:deb/debian/libsemanage1@2.8-2?arch=amd64\u0026upstream=libsemanage\u0026distro=debian-10",
252371          "swid": {
252372            "attachment": {}
252373          },
252374          "pedigree": {},
252375          "evidence": {},
252376          "signature": {
252377            "signature": {
252378              "publicKey": {}
252379            }
252380          },
252381          "modelCard": {
252382            "modelParameters": {
252383              "approach": {}
252384            },
252385            "quantitativeAnalysis": {
252386              "graphics": {}
252387            },
252388            "considerations": {}
252389          }
252390        },
252391        {
252392          "type": "library",
252393          "bom-ref": "pkg:deb/debian/libsepol1@2.8-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-10\u0026package-id=b33fd215afdc5714",
252394          "supplier": {},
252395          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
252396          "name": "libsepol1",
252397          "version": "2.8-1",
252398          "licenses": [
252399            {
252400              "license": {
252401                "name": "GPL"
252402              }
252403            },
252404            {
252405              "license": {
252406                "name": "LGPL"
252407              }
252408            }
252409          ],
252410          "cpe": "cpe:2.3:a:libsepol1:libsepol1:2.8-1:*:*:*:*:*:*:*",
252411          "purl": "pkg:deb/debian/libsepol1@2.8-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-10",
252412          "swid": {
252413            "attachment": {}
252414          },
252415          "pedigree": {},
252416          "evidence": {},
252417          "signature": {
252418            "signature": {
252419              "publicKey": {}
252420            }
252421          },
252422          "modelCard": {
252423            "modelParameters": {
252424              "approach": {}
252425            },
252426            "quantitativeAnalysis": {
252427              "graphics": {}
252428            },
252429            "considerations": {}
252430          }
252431        },
252432        {
252433          "type": "library",
252434          "bom-ref": "pkg:deb/debian/libsmartcols1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=fc03f42224a52138",
252435          "supplier": {},
252436          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
252437          "name": "libsmartcols1",
252438          "version": "2.33.1-0.1",
252439          "licenses": [
252440            {
252441              "license": {
252442                "id": "BSD-2-Clause"
252443              }
252444            },
252445            {
252446              "license": {
252447                "id": "BSD-3-Clause"
252448              }
252449            },
252450            {
252451              "license": {
252452                "id": "BSD-4-Clause"
252453              }
252454            },
252455            {
252456              "license": {
252457                "id": "GPL-2.0-only"
252458              }
252459            },
252460            {
252461              "license": {
252462                "id": "GPL-2.0-or-later"
252463              }
252464            },
252465            {
252466              "license": {
252467                "id": "GPL-3.0-only"
252468              }
252469            },
252470            {
252471              "license": {
252472                "id": "GPL-3.0-or-later"
252473              }
252474            },
252475            {
252476              "license": {
252477                "name": "LGPL"
252478              }
252479            },
252480            {
252481              "license": {
252482                "id": "LGPL-2.0-only"
252483              }
252484            },
252485            {
252486              "license": {
252487                "id": "LGPL-2.0-or-later"
252488              }
252489            },
252490            {
252491              "license": {
252492                "id": "LGPL-2.1-only"
252493              }
252494            },
252495            {
252496              "license": {
252497                "id": "LGPL-2.1-or-later"
252498              }
252499            },
252500            {
252501              "license": {
252502                "id": "LGPL-3.0-only"
252503              }
252504            },
252505            {
252506              "license": {
252507                "id": "LGPL-3.0-or-later"
252508              }
252509            },
252510            {
252511              "license": {
252512                "id": "MIT"
252513              }
252514            },
252515            {
252516              "license": {
252517                "name": "public-domain"
252518              }
252519            }
252520          ],
252521          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.33.1-0.1:*:*:*:*:*:*:*",
252522          "purl": "pkg:deb/debian/libsmartcols1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
252523          "swid": {
252524            "attachment": {}
252525          },
252526          "pedigree": {},
252527          "evidence": {},
252528          "signature": {
252529            "signature": {
252530              "publicKey": {}
252531            }
252532          },
252533          "modelCard": {
252534            "modelParameters": {
252535              "approach": {}
252536            },
252537            "quantitativeAnalysis": {
252538              "graphics": {}
252539            },
252540            "considerations": {}
252541          }
252542        },
252543        {
252544          "type": "library",
252545          "bom-ref": "pkg:deb/debian/libss2@1.44.5-1+deb10u3?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-10\u0026package-id=d0b160fc178bbb5b",
252546          "supplier": {},
252547          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
252548          "name": "libss2",
252549          "version": "1.44.5-1+deb10u3",
252550          "cpe": "cpe:2.3:a:libss2:libss2:1.44.5-1\\+deb10u3:*:*:*:*:*:*:*",
252551          "purl": "pkg:deb/debian/libss2@1.44.5-1+deb10u3?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-10",
252552          "swid": {
252553            "attachment": {}
252554          },
252555          "pedigree": {},
252556          "evidence": {},
252557          "signature": {
252558            "signature": {
252559              "publicKey": {}
252560            }
252561          },
252562          "modelCard": {
252563            "modelParameters": {
252564              "approach": {}
252565            },
252566            "quantitativeAnalysis": {
252567              "graphics": {}
252568            },
252569            "considerations": {}
252570          }
252571        },
252572        {
252573          "type": "library",
252574          "bom-ref": "pkg:deb/debian/libssl1.1@1.1.1d-0+deb10u7?arch=amd64\u0026upstream=openssl\u0026distro=debian-10\u0026package-id=a5f1f1afa4da3bb8",
252575          "supplier": {},
252576          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
252577          "name": "libssl1.1",
252578          "version": "1.1.1d-0+deb10u7",
252579          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1d-0\\+deb10u7:*:*:*:*:*:*:*",
252580          "purl": "pkg:deb/debian/libssl1.1@1.1.1d-0+deb10u7?arch=amd64\u0026upstream=openssl\u0026distro=debian-10",
252581          "swid": {
252582            "attachment": {}
252583          },
252584          "pedigree": {},
252585          "evidence": {},
252586          "signature": {
252587            "signature": {
252588              "publicKey": {}
252589            }
252590          },
252591          "modelCard": {
252592            "modelParameters": {
252593              "approach": {}
252594            },
252595            "quantitativeAnalysis": {
252596              "graphics": {}
252597            },
252598            "considerations": {}
252599          }
252600        },
252601        {
252602          "type": "library",
252603          "bom-ref": "pkg:deb/debian/libstdc++6@8.3.0-6?arch=amd64\u0026upstream=gcc-8\u0026distro=debian-10\u0026package-id=d05459fba83fc410",
252604          "supplier": {},
252605          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
252606          "name": "libstdc++6",
252607          "version": "8.3.0-6",
252608          "licenses": [
252609            {
252610              "license": {
252611                "name": "Artistic"
252612              }
252613            },
252614            {
252615              "license": {
252616                "id": "GFDL-1.2-only"
252617              }
252618            },
252619            {
252620              "license": {
252621                "name": "GPL"
252622              }
252623            },
252624            {
252625              "license": {
252626                "id": "GPL-2.0-only"
252627              }
252628            },
252629            {
252630              "license": {
252631                "id": "GPL-3.0-only"
252632              }
252633            },
252634            {
252635              "license": {
252636                "name": "LGPL"
252637              }
252638            }
252639          ],
252640          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:8.3.0-6:*:*:*:*:*:*:*",
252641          "purl": "pkg:deb/debian/libstdc++6@8.3.0-6?arch=amd64\u0026upstream=gcc-8\u0026distro=debian-10",
252642          "swid": {
252643            "attachment": {}
252644          },
252645          "pedigree": {},
252646          "evidence": {},
252647          "signature": {
252648            "signature": {
252649              "publicKey": {}
252650            }
252651          },
252652          "modelCard": {
252653            "modelParameters": {
252654              "approach": {}
252655            },
252656            "quantitativeAnalysis": {
252657              "graphics": {}
252658            },
252659            "considerations": {}
252660          }
252661        },
252662        {
252663          "type": "library",
252664          "bom-ref": "pkg:deb/debian/libsystemd0@241-7~deb10u8?arch=amd64\u0026upstream=systemd\u0026distro=debian-10\u0026package-id=855ac19a48989126",
252665          "supplier": {},
252666          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
252667          "name": "libsystemd0",
252668          "version": "241-7~deb10u8",
252669          "licenses": [
252670            {
252671              "license": {
252672                "id": "CC0-1.0"
252673              }
252674            },
252675            {
252676              "license": {
252677                "name": "Expat"
252678              }
252679            },
252680            {
252681              "license": {
252682                "id": "GPL-2.0-only"
252683              }
252684            },
252685            {
252686              "license": {
252687                "id": "GPL-2.0-or-later"
252688              }
252689            },
252690            {
252691              "license": {
252692                "id": "LGPL-2.1-only"
252693              }
252694            },
252695            {
252696              "license": {
252697                "id": "LGPL-2.1-or-later"
252698              }
252699            },
252700            {
252701              "license": {
252702                "name": "public-domain"
252703              }
252704            }
252705          ],
252706          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:241-7\\~deb10u8:*:*:*:*:*:*:*",
252707          "purl": "pkg:deb/debian/libsystemd0@241-7~deb10u8?arch=amd64\u0026upstream=systemd\u0026distro=debian-10",
252708          "swid": {
252709            "attachment": {}
252710          },
252711          "pedigree": {},
252712          "evidence": {},
252713          "signature": {
252714            "signature": {
252715              "publicKey": {}
252716            }
252717          },
252718          "modelCard": {
252719            "modelParameters": {
252720              "approach": {}
252721            },
252722            "quantitativeAnalysis": {
252723              "graphics": {}
252724            },
252725            "considerations": {}
252726          }
252727        },
252728        {
252729          "type": "library",
252730          "bom-ref": "pkg:deb/debian/libtasn1-6@4.13-3?arch=amd64\u0026distro=debian-10\u0026package-id=692d7710a71ec82b",
252731          "supplier": {},
252732          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
252733          "name": "libtasn1-6",
252734          "version": "4.13-3",
252735          "licenses": [
252736            {
252737              "license": {
252738                "id": "GFDL-1.3-only"
252739              }
252740            },
252741            {
252742              "license": {
252743                "id": "GPL-3.0-only"
252744              }
252745            },
252746            {
252747              "license": {
252748                "name": "LGPL"
252749              }
252750            },
252751            {
252752              "license": {
252753                "id": "LGPL-2.1-only"
252754              }
252755            }
252756          ],
252757          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.13-3:*:*:*:*:*:*:*",
252758          "purl": "pkg:deb/debian/libtasn1-6@4.13-3?arch=amd64\u0026distro=debian-10",
252759          "swid": {
252760            "attachment": {}
252761          },
252762          "pedigree": {},
252763          "evidence": {},
252764          "signature": {
252765            "signature": {
252766              "publicKey": {}
252767            }
252768          },
252769          "modelCard": {
252770            "modelParameters": {
252771              "approach": {}
252772            },
252773            "quantitativeAnalysis": {
252774              "graphics": {}
252775            },
252776            "considerations": {}
252777          }
252778        },
252779        {
252780          "type": "library",
252781          "bom-ref": "pkg:deb/debian/libtinfo6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10\u0026package-id=9e8c05e586cbb968",
252782          "supplier": {},
252783          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
252784          "name": "libtinfo6",
252785          "version": "6.1+20181013-2+deb10u2",
252786          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.1\\+20181013-2\\+deb10u2:*:*:*:*:*:*:*",
252787          "purl": "pkg:deb/debian/libtinfo6@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10",
252788          "swid": {
252789            "attachment": {}
252790          },
252791          "pedigree": {},
252792          "evidence": {},
252793          "signature": {
252794            "signature": {
252795              "publicKey": {}
252796            }
252797          },
252798          "modelCard": {
252799            "modelParameters": {
252800              "approach": {}
252801            },
252802            "quantitativeAnalysis": {
252803              "graphics": {}
252804            },
252805            "considerations": {}
252806          }
252807        },
252808        {
252809          "type": "library",
252810          "bom-ref": "pkg:deb/debian/libudev1@241-7~deb10u8?arch=amd64\u0026upstream=systemd\u0026distro=debian-10\u0026package-id=362a85019c976a00",
252811          "supplier": {},
252812          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
252813          "name": "libudev1",
252814          "version": "241-7~deb10u8",
252815          "licenses": [
252816            {
252817              "license": {
252818                "id": "CC0-1.0"
252819              }
252820            },
252821            {
252822              "license": {
252823                "name": "Expat"
252824              }
252825            },
252826            {
252827              "license": {
252828                "id": "GPL-2.0-only"
252829              }
252830            },
252831            {
252832              "license": {
252833                "id": "GPL-2.0-or-later"
252834              }
252835            },
252836            {
252837              "license": {
252838                "id": "LGPL-2.1-only"
252839              }
252840            },
252841            {
252842              "license": {
252843                "id": "LGPL-2.1-or-later"
252844              }
252845            },
252846            {
252847              "license": {
252848                "name": "public-domain"
252849              }
252850            }
252851          ],
252852          "cpe": "cpe:2.3:a:libudev1:libudev1:241-7\\~deb10u8:*:*:*:*:*:*:*",
252853          "purl": "pkg:deb/debian/libudev1@241-7~deb10u8?arch=amd64\u0026upstream=systemd\u0026distro=debian-10",
252854          "swid": {
252855            "attachment": {}
252856          },
252857          "pedigree": {},
252858          "evidence": {},
252859          "signature": {
252860            "signature": {
252861              "publicKey": {}
252862            }
252863          },
252864          "modelCard": {
252865            "modelParameters": {
252866              "approach": {}
252867            },
252868            "quantitativeAnalysis": {
252869              "graphics": {}
252870            },
252871            "considerations": {}
252872          }
252873        },
252874        {
252875          "type": "library",
252876          "bom-ref": "pkg:deb/debian/libunistring2@0.9.10-1?arch=amd64\u0026upstream=libunistring\u0026distro=debian-10\u0026package-id=b394fd46c85f8bb7",
252877          "supplier": {},
252878          "publisher": "Jörg Frings-Fürst \u003cdebian@jff.email\u003e",
252879          "name": "libunistring2",
252880          "version": "0.9.10-1",
252881          "licenses": [
252882            {
252883              "license": {
252884                "name": "FreeSoftware"
252885              }
252886            },
252887            {
252888              "license": {
252889                "id": "GFDL-1.2-only"
252890              }
252891            },
252892            {
252893              "license": {
252894                "name": "GFDL-1.2+"
252895              }
252896            },
252897            {
252898              "license": {
252899                "id": "GPL-2.0-only"
252900              }
252901            },
252902            {
252903              "license": {
252904                "id": "GPL-2.0-or-later"
252905              }
252906            },
252907            {
252908              "license": {
252909                "id": "GPL-3.0-only"
252910              }
252911            },
252912            {
252913              "license": {
252914                "id": "GPL-3.0-or-later"
252915              }
252916            },
252917            {
252918              "license": {
252919                "id": "LGPL-3.0-only"
252920              }
252921            },
252922            {
252923              "license": {
252924                "id": "LGPL-3.0-or-later"
252925              }
252926            },
252927            {
252928              "license": {
252929                "id": "MIT"
252930              }
252931            }
252932          ],
252933          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-1:*:*:*:*:*:*:*",
252934          "purl": "pkg:deb/debian/libunistring2@0.9.10-1?arch=amd64\u0026upstream=libunistring\u0026distro=debian-10",
252935          "swid": {
252936            "attachment": {}
252937          },
252938          "pedigree": {},
252939          "evidence": {},
252940          "signature": {
252941            "signature": {
252942              "publicKey": {}
252943            }
252944          },
252945          "modelCard": {
252946            "modelParameters": {
252947              "approach": {}
252948            },
252949            "quantitativeAnalysis": {
252950              "graphics": {}
252951            },
252952            "considerations": {}
252953          }
252954        },
252955        {
252956          "type": "library",
252957          "bom-ref": "pkg:deb/debian/libuuid1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=69873dc165cbbd6e",
252958          "supplier": {},
252959          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
252960          "name": "libuuid1",
252961          "version": "2.33.1-0.1",
252962          "licenses": [
252963            {
252964              "license": {
252965                "id": "BSD-2-Clause"
252966              }
252967            },
252968            {
252969              "license": {
252970                "id": "BSD-3-Clause"
252971              }
252972            },
252973            {
252974              "license": {
252975                "id": "BSD-4-Clause"
252976              }
252977            },
252978            {
252979              "license": {
252980                "id": "GPL-2.0-only"
252981              }
252982            },
252983            {
252984              "license": {
252985                "id": "GPL-2.0-or-later"
252986              }
252987            },
252988            {
252989              "license": {
252990                "id": "GPL-3.0-only"
252991              }
252992            },
252993            {
252994              "license": {
252995                "id": "GPL-3.0-or-later"
252996              }
252997            },
252998            {
252999              "license": {
253000                "name": "LGPL"
253001              }
253002            },
253003            {
253004              "license": {
253005                "id": "LGPL-2.0-only"
253006              }
253007            },
253008            {
253009              "license": {
253010                "id": "LGPL-2.0-or-later"
253011              }
253012            },
253013            {
253014              "license": {
253015                "id": "LGPL-2.1-only"
253016              }
253017            },
253018            {
253019              "license": {
253020                "id": "LGPL-2.1-or-later"
253021              }
253022            },
253023            {
253024              "license": {
253025                "id": "LGPL-3.0-only"
253026              }
253027            },
253028            {
253029              "license": {
253030                "id": "LGPL-3.0-or-later"
253031              }
253032            },
253033            {
253034              "license": {
253035                "id": "MIT"
253036              }
253037            },
253038            {
253039              "license": {
253040                "name": "public-domain"
253041              }
253042            }
253043          ],
253044          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.33.1-0.1:*:*:*:*:*:*:*",
253045          "purl": "pkg:deb/debian/libuuid1@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
253046          "swid": {
253047            "attachment": {}
253048          },
253049          "pedigree": {},
253050          "evidence": {},
253051          "signature": {
253052            "signature": {
253053              "publicKey": {}
253054            }
253055          },
253056          "modelCard": {
253057            "modelParameters": {
253058              "approach": {}
253059            },
253060            "quantitativeAnalysis": {
253061              "graphics": {}
253062            },
253063            "considerations": {}
253064          }
253065        },
253066        {
253067          "type": "library",
253068          "bom-ref": "pkg:deb/debian/libzstd1@1.3.8+dfsg-3+deb10u2?arch=amd64\u0026upstream=libzstd\u0026distro=debian-10\u0026package-id=b90d64adc03a2a50",
253069          "supplier": {},
253070          "publisher": "Debian Med Packaging Team \u003cdebian-med-packaging@lists.alioth.debian.org\u003e",
253071          "name": "libzstd1",
253072          "version": "1.3.8+dfsg-3+deb10u2",
253073          "licenses": [
253074            {
253075              "license": {
253076                "id": "BSD-3-Clause"
253077              }
253078            },
253079            {
253080              "license": {
253081                "name": "Expat"
253082              }
253083            },
253084            {
253085              "license": {
253086                "id": "GPL-2.0-only"
253087              }
253088            },
253089            {
253090              "license": {
253091                "id": "GPL-2.0-or-later"
253092              }
253093            },
253094            {
253095              "license": {
253096                "id": "Zlib"
253097              }
253098            }
253099          ],
253100          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.3.8\\+dfsg-3\\+deb10u2:*:*:*:*:*:*:*",
253101          "purl": "pkg:deb/debian/libzstd1@1.3.8+dfsg-3+deb10u2?arch=amd64\u0026upstream=libzstd\u0026distro=debian-10",
253102          "swid": {
253103            "attachment": {}
253104          },
253105          "pedigree": {},
253106          "evidence": {},
253107          "signature": {
253108            "signature": {
253109              "publicKey": {}
253110            }
253111          },
253112          "modelCard": {
253113            "modelParameters": {
253114              "approach": {}
253115            },
253116            "quantitativeAnalysis": {
253117              "graphics": {}
253118            },
253119            "considerations": {}
253120          }
253121        },
253122        {
253123          "type": "library",
253124          "bom-ref": "pkg:deb/debian/login@1:4.5-1.1?arch=amd64\u0026upstream=shadow\u0026distro=debian-10\u0026package-id=98839d2adee55b56",
253125          "supplier": {},
253126          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
253127          "name": "login",
253128          "version": "1:4.5-1.1",
253129          "licenses": [
253130            {
253131              "license": {
253132                "id": "GPL-2.0-only"
253133              }
253134            }
253135          ],
253136          "cpe": "cpe:2.3:a:login:login:1\\:4.5-1.1:*:*:*:*:*:*:*",
253137          "purl": "pkg:deb/debian/login@1:4.5-1.1?arch=amd64\u0026upstream=shadow\u0026distro=debian-10",
253138          "swid": {
253139            "attachment": {}
253140          },
253141          "pedigree": {},
253142          "evidence": {},
253143          "signature": {
253144            "signature": {
253145              "publicKey": {}
253146            }
253147          },
253148          "modelCard": {
253149            "modelParameters": {
253150              "approach": {}
253151            },
253152            "quantitativeAnalysis": {
253153              "graphics": {}
253154            },
253155            "considerations": {}
253156          }
253157        },
253158        {
253159          "type": "library",
253160          "bom-ref": "pkg:deb/debian/lsb-base@10.2019051400?arch=all\u0026upstream=lsb\u0026distro=debian-10\u0026package-id=4986087322566df",
253161          "supplier": {},
253162          "publisher": "Debian LSB Team \u003cdebian-lsb@lists.debian.org\u003e",
253163          "name": "lsb-base",
253164          "version": "10.2019051400",
253165          "licenses": [
253166            {
253167              "license": {
253168                "id": "BSD-3-Clause"
253169              }
253170            },
253171            {
253172              "license": {
253173                "id": "GPL-2.0-only"
253174              }
253175            }
253176          ],
253177          "cpe": "cpe:2.3:a:lsb-base:lsb-base:10.2019051400:*:*:*:*:*:*:*",
253178          "purl": "pkg:deb/debian/lsb-base@10.2019051400?arch=all\u0026upstream=lsb\u0026distro=debian-10",
253179          "swid": {
253180            "attachment": {}
253181          },
253182          "pedigree": {},
253183          "evidence": {},
253184          "signature": {
253185            "signature": {
253186              "publicKey": {}
253187            }
253188          },
253189          "modelCard": {
253190            "modelParameters": {
253191              "approach": {}
253192            },
253193            "quantitativeAnalysis": {
253194              "graphics": {}
253195            },
253196            "considerations": {}
253197          }
253198        },
253199        {
253200          "type": "library",
253201          "bom-ref": "pkg:deb/debian/mawk@1.3.3-17+b3?arch=amd64\u0026upstream=mawk%401.3.3-17\u0026distro=debian-10\u0026package-id=2aa71b5a2c22f638",
253202          "supplier": {},
253203          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
253204          "name": "mawk",
253205          "version": "1.3.3-17+b3",
253206          "licenses": [
253207            {
253208              "license": {
253209                "id": "GPL-2.0-only"
253210              }
253211            }
253212          ],
253213          "cpe": "cpe:2.3:a:mawk:mawk:1.3.3-17\\+b3:*:*:*:*:*:*:*",
253214          "purl": "pkg:deb/debian/mawk@1.3.3-17+b3?arch=amd64\u0026upstream=mawk%401.3.3-17\u0026distro=debian-10",
253215          "swid": {
253216            "attachment": {}
253217          },
253218          "pedigree": {},
253219          "evidence": {},
253220          "signature": {
253221            "signature": {
253222              "publicKey": {}
253223            }
253224          },
253225          "modelCard": {
253226            "modelParameters": {
253227              "approach": {}
253228            },
253229            "quantitativeAnalysis": {
253230              "graphics": {}
253231            },
253232            "considerations": {}
253233          }
253234        },
253235        {
253236          "type": "library",
253237          "bom-ref": "pkg:deb/debian/mount@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10\u0026package-id=d4b73315d7d26098",
253238          "supplier": {},
253239          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
253240          "name": "mount",
253241          "version": "2.33.1-0.1",
253242          "licenses": [
253243            {
253244              "license": {
253245                "id": "BSD-2-Clause"
253246              }
253247            },
253248            {
253249              "license": {
253250                "id": "BSD-3-Clause"
253251              }
253252            },
253253            {
253254              "license": {
253255                "id": "BSD-4-Clause"
253256              }
253257            },
253258            {
253259              "license": {
253260                "id": "GPL-2.0-only"
253261              }
253262            },
253263            {
253264              "license": {
253265                "id": "GPL-2.0-or-later"
253266              }
253267            },
253268            {
253269              "license": {
253270                "id": "GPL-3.0-only"
253271              }
253272            },
253273            {
253274              "license": {
253275                "id": "GPL-3.0-or-later"
253276              }
253277            },
253278            {
253279              "license": {
253280                "name": "LGPL"
253281              }
253282            },
253283            {
253284              "license": {
253285                "id": "LGPL-2.0-only"
253286              }
253287            },
253288            {
253289              "license": {
253290                "id": "LGPL-2.0-or-later"
253291              }
253292            },
253293            {
253294              "license": {
253295                "id": "LGPL-2.1-only"
253296              }
253297            },
253298            {
253299              "license": {
253300                "id": "LGPL-2.1-or-later"
253301              }
253302            },
253303            {
253304              "license": {
253305                "id": "LGPL-3.0-only"
253306              }
253307            },
253308            {
253309              "license": {
253310                "id": "LGPL-3.0-or-later"
253311              }
253312            },
253313            {
253314              "license": {
253315                "id": "MIT"
253316              }
253317            },
253318            {
253319              "license": {
253320                "name": "public-domain"
253321              }
253322            }
253323          ],
253324          "cpe": "cpe:2.3:a:mount:mount:2.33.1-0.1:*:*:*:*:*:*:*",
253325          "purl": "pkg:deb/debian/mount@2.33.1-0.1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-10",
253326          "swid": {
253327            "attachment": {}
253328          },
253329          "pedigree": {},
253330          "evidence": {},
253331          "signature": {
253332            "signature": {
253333              "publicKey": {}
253334            }
253335          },
253336          "modelCard": {
253337            "modelParameters": {
253338              "approach": {}
253339            },
253340            "quantitativeAnalysis": {
253341              "graphics": {}
253342            },
253343            "considerations": {}
253344          }
253345        },
253346        {
253347          "type": "library",
253348          "bom-ref": "pkg:deb/debian/ncurses-base@6.1+20181013-2+deb10u2?arch=all\u0026upstream=ncurses\u0026distro=debian-10\u0026package-id=a9450a198d2ae455",
253349          "supplier": {},
253350          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
253351          "name": "ncurses-base",
253352          "version": "6.1+20181013-2+deb10u2",
253353          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.1\\+20181013-2\\+deb10u2:*:*:*:*:*:*:*",
253354          "purl": "pkg:deb/debian/ncurses-base@6.1+20181013-2+deb10u2?arch=all\u0026upstream=ncurses\u0026distro=debian-10",
253355          "swid": {
253356            "attachment": {}
253357          },
253358          "pedigree": {},
253359          "evidence": {},
253360          "signature": {
253361            "signature": {
253362              "publicKey": {}
253363            }
253364          },
253365          "modelCard": {
253366            "modelParameters": {
253367              "approach": {}
253368            },
253369            "quantitativeAnalysis": {
253370              "graphics": {}
253371            },
253372            "considerations": {}
253373          }
253374        },
253375        {
253376          "type": "library",
253377          "bom-ref": "pkg:deb/debian/ncurses-bin@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10\u0026package-id=2d41aa0664b272f4",
253378          "supplier": {},
253379          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
253380          "name": "ncurses-bin",
253381          "version": "6.1+20181013-2+deb10u2",
253382          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.1\\+20181013-2\\+deb10u2:*:*:*:*:*:*:*",
253383          "purl": "pkg:deb/debian/ncurses-bin@6.1+20181013-2+deb10u2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-10",
253384          "swid": {
253385            "attachment": {}
253386          },
253387          "pedigree": {},
253388          "evidence": {},
253389          "signature": {
253390            "signature": {
253391              "publicKey": {}
253392            }
253393          },
253394          "modelCard": {
253395            "modelParameters": {
253396              "approach": {}
253397            },
253398            "quantitativeAnalysis": {
253399              "graphics": {}
253400            },
253401            "considerations": {}
253402          }
253403        },
253404        {
253405          "type": "library",
253406          "bom-ref": "pkg:deb/debian/passwd@1:4.5-1.1?arch=amd64\u0026upstream=shadow\u0026distro=debian-10\u0026package-id=6a37b96614be0ad8",
253407          "supplier": {},
253408          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
253409          "name": "passwd",
253410          "version": "1:4.5-1.1",
253411          "licenses": [
253412            {
253413              "license": {
253414                "id": "GPL-2.0-only"
253415              }
253416            }
253417          ],
253418          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.5-1.1:*:*:*:*:*:*:*",
253419          "purl": "pkg:deb/debian/passwd@1:4.5-1.1?arch=amd64\u0026upstream=shadow\u0026distro=debian-10",
253420          "swid": {
253421            "attachment": {}
253422          },
253423          "pedigree": {},
253424          "evidence": {},
253425          "signature": {
253426            "signature": {
253427              "publicKey": {}
253428            }
253429          },
253430          "modelCard": {
253431            "modelParameters": {
253432              "approach": {}
253433            },
253434            "quantitativeAnalysis": {
253435              "graphics": {}
253436            },
253437            "considerations": {}
253438          }
253439        },
253440        {
253441          "type": "library",
253442          "bom-ref": "pkg:deb/debian/perl-base@5.28.1-6+deb10u1?arch=amd64\u0026upstream=perl\u0026distro=debian-10\u0026package-id=99c7261aa39b37e1",
253443          "supplier": {},
253444          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
253445          "name": "perl-base",
253446          "version": "5.28.1-6+deb10u1",
253447          "licenses": [
253448            {
253449              "license": {
253450                "name": "Artistic"
253451              }
253452            },
253453            {
253454              "license": {
253455                "id": "Artistic-2.0"
253456              }
253457            },
253458            {
253459              "license": {
253460                "name": "Artistic-dist"
253461              }
253462            },
253463            {
253464              "license": {
253465                "id": "BSD-3-Clause"
253466              }
253467            },
253468            {
253469              "license": {
253470                "name": "BSD-3-clause-GENERIC"
253471              }
253472            },
253473            {
253474              "license": {
253475                "name": "BSD-3-clause-with-weird-numbering"
253476              }
253477            },
253478            {
253479              "license": {
253480                "name": "BSD-4-clause-POWERDOG"
253481              }
253482            },
253483            {
253484              "license": {
253485                "name": "BZIP"
253486              }
253487            },
253488            {
253489              "license": {
253490                "name": "DONT-CHANGE-THE-GPL"
253491              }
253492            },
253493            {
253494              "license": {
253495                "name": "Expat"
253496              }
253497            },
253498            {
253499              "license": {
253500                "id": "GPL-1.0-only"
253501              }
253502            },
253503            {
253504              "license": {
253505                "id": "GPL-1.0-or-later"
253506              }
253507            },
253508            {
253509              "license": {
253510                "id": "GPL-2.0-only"
253511              }
253512            },
253513            {
253514              "license": {
253515                "id": "GPL-2.0-or-later"
253516              }
253517            },
253518            {
253519              "license": {
253520                "name": "GPL-3+-WITH-BISON-EXCEPTION"
253521              }
253522            },
253523            {
253524              "license": {
253525                "name": "HSIEH-BSD"
253526              }
253527            },
253528            {
253529              "license": {
253530                "name": "HSIEH-DERIVATIVE"
253531              }
253532            },
253533            {
253534              "license": {
253535                "id": "LGPL-2.1-only"
253536              }
253537            },
253538            {
253539              "license": {
253540                "name": "REGCOMP"
253541              }
253542            },
253543            {
253544              "license": {
253545                "name": "REGCOMP,"
253546              }
253547            },
253548            {
253549              "license": {
253550                "name": "RRA-KEEP-THIS-NOTICE"
253551              }
253552            },
253553            {
253554              "license": {
253555                "name": "S2P"
253556              }
253557            },
253558            {
253559              "license": {
253560                "name": "SDBM-PUBLIC-DOMAIN"
253561              }
253562            },
253563            {
253564              "license": {
253565                "name": "TEXT-TABS"
253566              }
253567            },
253568            {
253569              "license": {
253570                "name": "Unicode"
253571              }
253572            },
253573            {
253574              "license": {
253575                "id": "Zlib"
253576              }
253577            }
253578          ],
253579          "cpe": "cpe:2.3:a:perl-base:perl-base:5.28.1-6\\+deb10u1:*:*:*:*:*:*:*",
253580          "purl": "pkg:deb/debian/perl-base@5.28.1-6+deb10u1?arch=amd64\u0026upstream=perl\u0026distro=debian-10",
253581          "swid": {
253582            "attachment": {}
253583          },
253584          "pedigree": {},
253585          "evidence": {},
253586          "signature": {
253587            "signature": {
253588              "publicKey": {}
253589            }
253590          },
253591          "modelCard": {
253592            "modelParameters": {
253593              "approach": {}
253594            },
253595            "quantitativeAnalysis": {
253596              "graphics": {}
253597            },
253598            "considerations": {}
253599          }
253600        },
253601        {
253602          "type": "application",
253603          "bom-ref": "pkg:generic/redis@6.2.5?package-id=2a035ccef527ad12",
253604          "supplier": {},
253605          "name": "redis",
253606          "version": "6.2.5",
253607          "cpe": "cpe:2.3:a:redislabs:redis:6.2.5:*:*:*:*:*:*:*",
253608          "purl": "pkg:generic/redis@6.2.5",
253609          "swid": {
253610            "attachment": {}
253611          },
253612          "pedigree": {},
253613          "evidence": {},
253614          "signature": {
253615            "signature": {
253616              "publicKey": {}
253617            }
253618          },
253619          "modelCard": {
253620            "modelParameters": {
253621              "approach": {}
253622            },
253623            "quantitativeAnalysis": {
253624              "graphics": {}
253625            },
253626            "considerations": {}
253627          }
253628        },
253629        {
253630          "type": "library",
253631          "bom-ref": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-10\u0026package-id=cd24b1a69c7b788a",
253632          "supplier": {},
253633          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
253634          "name": "sed",
253635          "version": "4.7-1",
253636          "licenses": [
253637            {
253638              "license": {
253639                "id": "GPL-3.0-only"
253640              }
253641            }
253642          ],
253643          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
253644          "purl": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-10",
253645          "swid": {
253646            "attachment": {}
253647          },
253648          "pedigree": {},
253649          "evidence": {},
253650          "signature": {
253651            "signature": {
253652              "publicKey": {}
253653            }
253654          },
253655          "modelCard": {
253656            "modelParameters": {
253657              "approach": {}
253658            },
253659            "quantitativeAnalysis": {
253660              "graphics": {}
253661            },
253662            "considerations": {}
253663          }
253664        },
253665        {
253666          "type": "library",
253667          "bom-ref": "pkg:deb/debian/sysvinit-utils@2.93-8?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-10\u0026package-id=9762b89f96a3933c",
253668          "supplier": {},
253669          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
253670          "name": "sysvinit-utils",
253671          "version": "2.93-8",
253672          "licenses": [
253673            {
253674              "license": {
253675                "id": "GPL-2.0-only"
253676              }
253677            },
253678            {
253679              "license": {
253680                "id": "GPL-2.0-or-later"
253681              }
253682            }
253683          ],
253684          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.93-8:*:*:*:*:*:*:*",
253685          "purl": "pkg:deb/debian/sysvinit-utils@2.93-8?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-10",
253686          "swid": {
253687            "attachment": {}
253688          },
253689          "pedigree": {},
253690          "evidence": {},
253691          "signature": {
253692            "signature": {
253693              "publicKey": {}
253694            }
253695          },
253696          "modelCard": {
253697            "modelParameters": {
253698              "approach": {}
253699            },
253700            "quantitativeAnalysis": {
253701              "graphics": {}
253702            },
253703            "considerations": {}
253704          }
253705        },
253706        {
253707          "type": "library",
253708          "bom-ref": "pkg:deb/debian/tar@1.30+dfsg-6?arch=amd64\u0026distro=debian-10\u0026package-id=c194088099b2a715",
253709          "supplier": {},
253710          "publisher": "Bdale Garbee \u003cbdale@gag.com\u003e",
253711          "name": "tar",
253712          "version": "1.30+dfsg-6",
253713          "licenses": [
253714            {
253715              "license": {
253716                "id": "GPL-2.0-only"
253717              }
253718            },
253719            {
253720              "license": {
253721                "id": "GPL-3.0-only"
253722              }
253723            }
253724          ],
253725          "cpe": "cpe:2.3:a:tar:tar:1.30\\+dfsg-6:*:*:*:*:*:*:*",
253726          "purl": "pkg:deb/debian/tar@1.30+dfsg-6?arch=amd64\u0026distro=debian-10",
253727          "swid": {
253728            "attachment": {}
253729          },
253730          "pedigree": {},
253731          "evidence": {},
253732          "signature": {
253733            "signature": {
253734              "publicKey": {}
253735            }
253736          },
253737          "modelCard": {
253738            "modelParameters": {
253739              "approach": {}
253740            },
253741            "quantitativeAnalysis": {
253742              "graphics": {}
253743            },
253744            "considerations": {}
253745          }
253746        },
253747        {
253748          "type": "library",
253749          "bom-ref": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10\u0026package-id=382d46893fab7c54",
253750          "supplier": {},
253751          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
253752          "name": "tzdata",
253753          "version": "2021a-0+deb10u1",
253754          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0\\+deb10u1:*:*:*:*:*:*:*",
253755          "purl": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10",
253756          "swid": {
253757            "attachment": {}
253758          },
253759          "pedigree": {},
253760          "evidence": {},
253761          "signature": {
253762            "signature": {
253763              "publicKey": {}
253764            }
253765          },
253766          "modelCard": {
253767            "modelParameters": {
253768              "approach": {}
253769            },
253770            "quantitativeAnalysis": {
253771              "graphics": {}
253772            },
253773            "considerations": {}
253774          }
253775        },
253776        {
253777          "type": "library",
253778          "bom-ref": "pkg:deb/debian/util-linux@2.33.1-0.1?arch=amd64\u0026distro=debian-10\u0026package-id=cc8d30d3a3bc01b6",
253779          "supplier": {},
253780          "publisher": "LaMont Jones \u003clamont@debian.org\u003e",
253781          "name": "util-linux",
253782          "version": "2.33.1-0.1",
253783          "licenses": [
253784            {
253785              "license": {
253786                "id": "BSD-2-Clause"
253787              }
253788            },
253789            {
253790              "license": {
253791                "id": "BSD-3-Clause"
253792              }
253793            },
253794            {
253795              "license": {
253796                "id": "BSD-4-Clause"
253797              }
253798            },
253799            {
253800              "license": {
253801                "id": "GPL-2.0-only"
253802              }
253803            },
253804            {
253805              "license": {
253806                "id": "GPL-2.0-or-later"
253807              }
253808            },
253809            {
253810              "license": {
253811                "id": "GPL-3.0-only"
253812              }
253813            },
253814            {
253815              "license": {
253816                "id": "GPL-3.0-or-later"
253817              }
253818            },
253819            {
253820              "license": {
253821                "name": "LGPL"
253822              }
253823            },
253824            {
253825              "license": {
253826                "id": "LGPL-2.0-only"
253827              }
253828            },
253829            {
253830              "license": {
253831                "id": "LGPL-2.0-or-later"
253832              }
253833            },
253834            {
253835              "license": {
253836                "id": "LGPL-2.1-only"
253837              }
253838            },
253839            {
253840              "license": {
253841                "id": "LGPL-2.1-or-later"
253842              }
253843            },
253844            {
253845              "license": {
253846                "id": "LGPL-3.0-only"
253847              }
253848            },
253849            {
253850              "license": {
253851                "id": "LGPL-3.0-or-later"
253852              }
253853            },
253854            {
253855              "license": {
253856                "id": "MIT"
253857              }
253858            },
253859            {
253860              "license": {
253861                "name": "public-domain"
253862              }
253863            }
253864          ],
253865          "cpe": "cpe:2.3:a:util-linux:util-linux:2.33.1-0.1:*:*:*:*:*:*:*",
253866          "purl": "pkg:deb/debian/util-linux@2.33.1-0.1?arch=amd64\u0026distro=debian-10",
253867          "swid": {
253868            "attachment": {}
253869          },
253870          "pedigree": {},
253871          "evidence": {},
253872          "signature": {
253873            "signature": {
253874              "publicKey": {}
253875            }
253876          },
253877          "modelCard": {
253878            "modelParameters": {
253879              "approach": {}
253880            },
253881            "quantitativeAnalysis": {
253882              "graphics": {}
253883            },
253884            "considerations": {}
253885          }
253886        },
253887        {
253888          "type": "library",
253889          "bom-ref": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-1?arch=amd64\u0026upstream=zlib\u0026distro=debian-10\u0026package-id=462eb7255c2bc918",
253890          "supplier": {},
253891          "publisher": "Mark Brown \u003cbroonie@debian.org\u003e",
253892          "name": "zlib1g",
253893          "version": "1:1.2.11.dfsg-1",
253894          "licenses": [
253895            {
253896              "license": {
253897                "id": "Zlib"
253898              }
253899            }
253900          ],
253901          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-1:*:*:*:*:*:*:*",
253902          "purl": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-1?arch=amd64\u0026upstream=zlib\u0026distro=debian-10",
253903          "swid": {
253904            "attachment": {}
253905          },
253906          "pedigree": {},
253907          "evidence": {},
253908          "signature": {
253909            "signature": {
253910              "publicKey": {}
253911            }
253912          },
253913          "modelCard": {
253914            "modelParameters": {
253915              "approach": {}
253916            },
253917            "quantitativeAnalysis": {
253918              "graphics": {}
253919            },
253920            "considerations": {}
253921          }
253922        },
253923        {
253924          "type": "operating-system",
253925          "supplier": {},
253926          "name": "debian",
253927          "version": "10",
253928          "description": "Debian GNU/Linux 10 (buster)",
253929          "swid": {
253930            "tagId": "debian",
253931            "name": "debian",
253932            "version": "10",
253933            "attachment": {}
253934          },
253935          "pedigree": {},
253936          "externalReferences": [
253937            {
253938              "url": "https://bugs.debian.org/",
253939              "type": "issue-tracker"
253940            },
253941            {
253942              "url": "https://www.debian.org/",
253943              "type": "website"
253944            },
253945            {
253946              "url": "https://www.debian.org/support",
253947              "comment": "support",
253948              "type": "other"
253949            }
253950          ],
253951          "evidence": {},
253952          "signature": {
253953            "signature": {
253954              "publicKey": {}
253955            }
253956          },
253957          "modelCard": {
253958            "modelParameters": {
253959              "approach": {}
253960            },
253961            "quantitativeAnalysis": {
253962              "graphics": {}
253963            },
253964            "considerations": {}
253965          }
253966        },
253967        {
253968          "type": "library",
253969          "bom-ref": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-11\u0026package-id=3e9282034226b93f",
253970          "supplier": {},
253971          "publisher": "Debian Adduser Developers \u003cadduser@packages.debian.org\u003e",
253972          "name": "adduser",
253973          "version": "3.118",
253974          "licenses": [
253975            {
253976              "license": {
253977                "id": "GPL-2.0-only"
253978              }
253979            }
253980          ],
253981          "cpe": "cpe:2.3:a:adduser:adduser:3.118:*:*:*:*:*:*:*",
253982          "purl": "pkg:deb/debian/adduser@3.118?arch=all\u0026distro=debian-11",
253983          "swid": {
253984            "attachment": {}
253985          },
253986          "pedigree": {},
253987          "evidence": {},
253988          "signature": {
253989            "signature": {
253990              "publicKey": {}
253991            }
253992          },
253993          "modelCard": {
253994            "modelParameters": {
253995              "approach": {}
253996            },
253997            "quantitativeAnalysis": {
253998              "graphics": {}
253999            },
254000            "considerations": {}
254001          }
254002        },
254003        {
254004          "type": "library",
254005          "bom-ref": "pkg:deb/debian/adwaita-icon-theme@3.38.0-1?arch=all\u0026distro=debian-11\u0026package-id=f681011a16c62101",
254006          "supplier": {},
254007          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
254008          "name": "adwaita-icon-theme",
254009          "version": "3.38.0-1",
254010          "licenses": [
254011            {
254012              "license": {
254013                "id": "CC-BY-3.0-US"
254014              }
254015            },
254016            {
254017              "license": {
254018                "name": "CC-BY-SA-2.0-IT"
254019              }
254020            },
254021            {
254022              "license": {
254023                "id": "CC-BY-SA-3.0"
254024              }
254025            },
254026            {
254027              "license": {
254028                "name": "CC-BY-SA-3.0-US"
254029              }
254030            },
254031            {
254032              "license": {
254033                "name": "CC-BY-SA-3.0-Unported"
254034              }
254035            },
254036            {
254037              "license": {
254038                "id": "CC-BY-SA-4.0"
254039              }
254040            },
254041            {
254042              "license": {
254043                "id": "GFDL-1.2-only"
254044              }
254045            },
254046            {
254047              "license": {
254048                "name": "GFDL-1.2+"
254049              }
254050            },
254051            {
254052              "license": {
254053                "name": "GPL"
254054              }
254055            },
254056            {
254057              "license": {
254058                "name": "GPL-unspecified"
254059              }
254060            },
254061            {
254062              "license": {
254063                "id": "LGPL-3.0-only"
254064              }
254065            }
254066          ],
254067          "cpe": "cpe:2.3:a:adwaita-icon-theme:adwaita-icon-theme:3.38.0-1:*:*:*:*:*:*:*",
254068          "purl": "pkg:deb/debian/adwaita-icon-theme@3.38.0-1?arch=all\u0026distro=debian-11",
254069          "swid": {
254070            "attachment": {}
254071          },
254072          "pedigree": {},
254073          "evidence": {},
254074          "signature": {
254075            "signature": {
254076              "publicKey": {}
254077            }
254078          },
254079          "modelCard": {
254080            "modelParameters": {
254081              "approach": {}
254082            },
254083            "quantitativeAnalysis": {
254084              "graphics": {}
254085            },
254086            "considerations": {}
254087          }
254088        },
254089        {
254090          "type": "library",
254091          "bom-ref": "pkg:deb/debian/apt@2.2.4?arch=amd64\u0026distro=debian-11\u0026package-id=1cce537379623b25",
254092          "supplier": {},
254093          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
254094          "name": "apt",
254095          "version": "2.2.4",
254096          "licenses": [
254097            {
254098              "license": {
254099                "id": "GPL-2.0-only"
254100              }
254101            },
254102            {
254103              "license": {
254104                "name": "GPLv2+"
254105              }
254106            }
254107          ],
254108          "cpe": "cpe:2.3:a:apt:apt:2.2.4:*:*:*:*:*:*:*",
254109          "purl": "pkg:deb/debian/apt@2.2.4?arch=amd64\u0026distro=debian-11",
254110          "swid": {
254111            "attachment": {}
254112          },
254113          "pedigree": {},
254114          "evidence": {},
254115          "signature": {
254116            "signature": {
254117              "publicKey": {}
254118            }
254119          },
254120          "modelCard": {
254121            "modelParameters": {
254122              "approach": {}
254123            },
254124            "quantitativeAnalysis": {
254125              "graphics": {}
254126            },
254127            "considerations": {}
254128          }
254129        },
254130        {
254131          "type": "library",
254132          "bom-ref": "pkg:deb/debian/atop@2.6.0-2?arch=amd64\u0026distro=debian-11\u0026package-id=79fa69727b8cd928",
254133          "supplier": {},
254134          "publisher": "Marc Haber \u003catop@packages.debian.org\u003e",
254135          "name": "atop",
254136          "version": "2.6.0-2",
254137          "licenses": [
254138            {
254139              "license": {
254140                "id": "GPL-2.0-only"
254141              }
254142            },
254143            {
254144              "license": {
254145                "id": "GPL-2.0-or-later"
254146              }
254147            }
254148          ],
254149          "cpe": "cpe:2.3:a:atop:atop:2.6.0-2:*:*:*:*:*:*:*",
254150          "purl": "pkg:deb/debian/atop@2.6.0-2?arch=amd64\u0026distro=debian-11",
254151          "swid": {
254152            "attachment": {}
254153          },
254154          "pedigree": {},
254155          "evidence": {},
254156          "signature": {
254157            "signature": {
254158              "publicKey": {}
254159            }
254160          },
254161          "modelCard": {
254162            "modelParameters": {
254163              "approach": {}
254164            },
254165            "quantitativeAnalysis": {
254166              "graphics": {}
254167            },
254168            "considerations": {}
254169          }
254170        },
254171        {
254172          "type": "library",
254173          "bom-ref": "pkg:deb/debian/base-files@11.1+deb11u5?arch=amd64\u0026distro=debian-11\u0026package-id=8a4d0a5e2afa8cb4",
254174          "supplier": {},
254175          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
254176          "name": "base-files",
254177          "version": "11.1+deb11u5",
254178          "licenses": [
254179            {
254180              "license": {
254181                "name": "GPL"
254182              }
254183            }
254184          ],
254185          "cpe": "cpe:2.3:a:base-files:base-files:11.1\\+deb11u5:*:*:*:*:*:*:*",
254186          "purl": "pkg:deb/debian/base-files@11.1+deb11u5?arch=amd64\u0026distro=debian-11",
254187          "swid": {
254188            "attachment": {}
254189          },
254190          "pedigree": {},
254191          "evidence": {},
254192          "signature": {
254193            "signature": {
254194              "publicKey": {}
254195            }
254196          },
254197          "modelCard": {
254198            "modelParameters": {
254199              "approach": {}
254200            },
254201            "quantitativeAnalysis": {
254202              "graphics": {}
254203            },
254204            "considerations": {}
254205          }
254206        },
254207        {
254208          "type": "library",
254209          "bom-ref": "pkg:deb/debian/base-passwd@3.5.51?arch=amd64\u0026distro=debian-11\u0026package-id=7ae3e2ba2e10f31",
254210          "supplier": {},
254211          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
254212          "name": "base-passwd",
254213          "version": "3.5.51",
254214          "licenses": [
254215            {
254216              "license": {
254217                "id": "GPL-2.0-only"
254218              }
254219            },
254220            {
254221              "license": {
254222                "name": "public-domain"
254223              }
254224            }
254225          ],
254226          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.51:*:*:*:*:*:*:*",
254227          "purl": "pkg:deb/debian/base-passwd@3.5.51?arch=amd64\u0026distro=debian-11",
254228          "swid": {
254229            "attachment": {}
254230          },
254231          "pedigree": {},
254232          "evidence": {},
254233          "signature": {
254234            "signature": {
254235              "publicKey": {}
254236            }
254237          },
254238          "modelCard": {
254239            "modelParameters": {
254240              "approach": {}
254241            },
254242            "quantitativeAnalysis": {
254243              "graphics": {}
254244            },
254245            "considerations": {}
254246          }
254247        },
254248        {
254249          "type": "library",
254250          "bom-ref": "pkg:deb/debian/bash@5.1-2+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=94b35b4f7d874a43",
254251          "supplier": {},
254252          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
254253          "name": "bash",
254254          "version": "5.1-2+deb11u1",
254255          "licenses": [
254256            {
254257              "license": {
254258                "id": "GPL-3.0-only"
254259              }
254260            }
254261          ],
254262          "cpe": "cpe:2.3:a:bash:bash:5.1-2\\+deb11u1:*:*:*:*:*:*:*",
254263          "purl": "pkg:deb/debian/bash@5.1-2+deb11u1?arch=amd64\u0026distro=debian-11",
254264          "swid": {
254265            "attachment": {}
254266          },
254267          "pedigree": {},
254268          "evidence": {},
254269          "signature": {
254270            "signature": {
254271              "publicKey": {}
254272            }
254273          },
254274          "modelCard": {
254275            "modelParameters": {
254276              "approach": {}
254277            },
254278            "quantitativeAnalysis": {
254279              "graphics": {}
254280            },
254281            "considerations": {}
254282          }
254283        },
254284        {
254285          "type": "library",
254286          "bom-ref": "pkg:deb/debian/bash-completion@1:2.11-2?arch=all\u0026distro=debian-11\u0026package-id=8d5f9acd2065a143",
254287          "supplier": {},
254288          "publisher": "Gabriel F. T. Gomes \u003cgabriel@debian.org\u003e",
254289          "name": "bash-completion",
254290          "version": "1:2.11-2",
254291          "licenses": [
254292            {
254293              "license": {
254294                "id": "GPL-2.0-only"
254295              }
254296            },
254297            {
254298              "license": {
254299                "id": "GPL-2.0-or-later"
254300              }
254301            }
254302          ],
254303          "cpe": "cpe:2.3:a:bash-completion:bash-completion:1\\:2.11-2:*:*:*:*:*:*:*",
254304          "purl": "pkg:deb/debian/bash-completion@1:2.11-2?arch=all\u0026distro=debian-11",
254305          "swid": {
254306            "attachment": {}
254307          },
254308          "pedigree": {},
254309          "evidence": {},
254310          "signature": {
254311            "signature": {
254312              "publicKey": {}
254313            }
254314          },
254315          "modelCard": {
254316            "modelParameters": {
254317              "approach": {}
254318            },
254319            "quantitativeAnalysis": {
254320              "graphics": {}
254321            },
254322            "considerations": {}
254323          }
254324        },
254325        {
254326          "type": "library",
254327          "bom-ref": "pkg:deb/debian/bind9-dnsutils@1:9.16.33-1~deb11u1?arch=amd64\u0026upstream=bind9\u0026distro=debian-11\u0026package-id=80903b8263a99b29",
254328          "supplier": {},
254329          "publisher": "Debian DNS Team \u003cteam+dns@tracker.debian.org\u003e",
254330          "name": "bind9-dnsutils",
254331          "version": "1:9.16.33-1~deb11u1",
254332          "licenses": [
254333            {
254334              "license": {
254335                "id": "BSD-2-Clause"
254336              }
254337            },
254338            {
254339              "license": {
254340                "id": "BSD-3-Clause"
254341              }
254342            },
254343            {
254344              "license": {
254345                "id": "CC0-1.0"
254346              }
254347            },
254348            {
254349              "license": {
254350                "id": "ISC"
254351              }
254352            },
254353            {
254354              "license": {
254355                "id": "MPL-2.0"
254356              }
254357            }
254358          ],
254359          "cpe": "cpe:2.3:a:bind9-dnsutils:bind9-dnsutils:1\\:9.16.33-1\\~deb11u1:*:*:*:*:*:*:*",
254360          "purl": "pkg:deb/debian/bind9-dnsutils@1:9.16.33-1~deb11u1?arch=amd64\u0026upstream=bind9\u0026distro=debian-11",
254361          "swid": {
254362            "attachment": {}
254363          },
254364          "pedigree": {},
254365          "evidence": {},
254366          "signature": {
254367            "signature": {
254368              "publicKey": {}
254369            }
254370          },
254371          "modelCard": {
254372            "modelParameters": {
254373              "approach": {}
254374            },
254375            "quantitativeAnalysis": {
254376              "graphics": {}
254377            },
254378            "considerations": {}
254379          }
254380        },
254381        {
254382          "type": "library",
254383          "bom-ref": "pkg:deb/debian/bind9-host@1:9.16.33-1~deb11u1?arch=amd64\u0026upstream=bind9\u0026distro=debian-11\u0026package-id=97b475e67f54ca10",
254384          "supplier": {},
254385          "publisher": "Debian DNS Team \u003cteam+dns@tracker.debian.org\u003e",
254386          "name": "bind9-host",
254387          "version": "1:9.16.33-1~deb11u1",
254388          "licenses": [
254389            {
254390              "license": {
254391                "id": "BSD-2-Clause"
254392              }
254393            },
254394            {
254395              "license": {
254396                "id": "BSD-3-Clause"
254397              }
254398            },
254399            {
254400              "license": {
254401                "id": "CC0-1.0"
254402              }
254403            },
254404            {
254405              "license": {
254406                "id": "ISC"
254407              }
254408            },
254409            {
254410              "license": {
254411                "id": "MPL-2.0"
254412              }
254413            }
254414          ],
254415          "cpe": "cpe:2.3:a:bind9-host:bind9-host:1\\:9.16.33-1\\~deb11u1:*:*:*:*:*:*:*",
254416          "purl": "pkg:deb/debian/bind9-host@1:9.16.33-1~deb11u1?arch=amd64\u0026upstream=bind9\u0026distro=debian-11",
254417          "swid": {
254418            "attachment": {}
254419          },
254420          "pedigree": {},
254421          "evidence": {},
254422          "signature": {
254423            "signature": {
254424              "publicKey": {}
254425            }
254426          },
254427          "modelCard": {
254428            "modelParameters": {
254429              "approach": {}
254430            },
254431            "quantitativeAnalysis": {
254432              "graphics": {}
254433            },
254434            "considerations": {}
254435          }
254436        },
254437        {
254438          "type": "library",
254439          "bom-ref": "pkg:deb/debian/bind9-libs@1:9.16.33-1~deb11u1?arch=amd64\u0026upstream=bind9\u0026distro=debian-11\u0026package-id=d2478f04be0bf1f4",
254440          "supplier": {},
254441          "publisher": "Debian DNS Team \u003cteam+dns@tracker.debian.org\u003e",
254442          "name": "bind9-libs",
254443          "version": "1:9.16.33-1~deb11u1",
254444          "licenses": [
254445            {
254446              "license": {
254447                "id": "BSD-2-Clause"
254448              }
254449            },
254450            {
254451              "license": {
254452                "id": "BSD-3-Clause"
254453              }
254454            },
254455            {
254456              "license": {
254457                "id": "CC0-1.0"
254458              }
254459            },
254460            {
254461              "license": {
254462                "id": "ISC"
254463              }
254464            },
254465            {
254466              "license": {
254467                "id": "MPL-2.0"
254468              }
254469            }
254470          ],
254471          "cpe": "cpe:2.3:a:bind9-libs:bind9-libs:1\\:9.16.33-1\\~deb11u1:*:*:*:*:*:*:*",
254472          "purl": "pkg:deb/debian/bind9-libs@1:9.16.33-1~deb11u1?arch=amd64\u0026upstream=bind9\u0026distro=debian-11",
254473          "swid": {
254474            "attachment": {}
254475          },
254476          "pedigree": {},
254477          "evidence": {},
254478          "signature": {
254479            "signature": {
254480              "publicKey": {}
254481            }
254482          },
254483          "modelCard": {
254484            "modelParameters": {
254485              "approach": {}
254486            },
254487            "quantitativeAnalysis": {
254488              "graphics": {}
254489            },
254490            "considerations": {}
254491          }
254492        },
254493        {
254494          "type": "library",
254495          "bom-ref": "pkg:deb/debian/binutils@2.35.2-2?arch=amd64\u0026distro=debian-11\u0026package-id=d3f194b20dd87044",
254496          "supplier": {},
254497          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
254498          "name": "binutils",
254499          "version": "2.35.2-2",
254500          "licenses": [
254501            {
254502              "license": {
254503                "name": "GFDL"
254504              }
254505            },
254506            {
254507              "license": {
254508                "name": "GPL"
254509              }
254510            },
254511            {
254512              "license": {
254513                "name": "LGPL"
254514              }
254515            }
254516          ],
254517          "cpe": "cpe:2.3:a:binutils:binutils:2.35.2-2:*:*:*:*:*:*:*",
254518          "purl": "pkg:deb/debian/binutils@2.35.2-2?arch=amd64\u0026distro=debian-11",
254519          "swid": {
254520            "attachment": {}
254521          },
254522          "pedigree": {},
254523          "evidence": {},
254524          "signature": {
254525            "signature": {
254526              "publicKey": {}
254527            }
254528          },
254529          "modelCard": {
254530            "modelParameters": {
254531              "approach": {}
254532            },
254533            "quantitativeAnalysis": {
254534              "graphics": {}
254535            },
254536            "considerations": {}
254537          }
254538        },
254539        {
254540          "type": "library",
254541          "bom-ref": "pkg:deb/debian/binutils-common@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11\u0026package-id=a3c60c2527e62ea5",
254542          "supplier": {},
254543          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
254544          "name": "binutils-common",
254545          "version": "2.35.2-2",
254546          "licenses": [
254547            {
254548              "license": {
254549                "name": "GFDL"
254550              }
254551            },
254552            {
254553              "license": {
254554                "name": "GPL"
254555              }
254556            },
254557            {
254558              "license": {
254559                "name": "LGPL"
254560              }
254561            }
254562          ],
254563          "cpe": "cpe:2.3:a:binutils-common:binutils-common:2.35.2-2:*:*:*:*:*:*:*",
254564          "purl": "pkg:deb/debian/binutils-common@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11",
254565          "swid": {
254566            "attachment": {}
254567          },
254568          "pedigree": {},
254569          "evidence": {},
254570          "signature": {
254571            "signature": {
254572              "publicKey": {}
254573            }
254574          },
254575          "modelCard": {
254576            "modelParameters": {
254577              "approach": {}
254578            },
254579            "quantitativeAnalysis": {
254580              "graphics": {}
254581            },
254582            "considerations": {}
254583          }
254584        },
254585        {
254586          "type": "library",
254587          "bom-ref": "pkg:deb/debian/binutils-x86-64-linux-gnu@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11\u0026package-id=8ebf803eb42ea096",
254588          "supplier": {},
254589          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
254590          "name": "binutils-x86-64-linux-gnu",
254591          "version": "2.35.2-2",
254592          "licenses": [
254593            {
254594              "license": {
254595                "name": "GFDL"
254596              }
254597            },
254598            {
254599              "license": {
254600                "name": "GPL"
254601              }
254602            },
254603            {
254604              "license": {
254605                "name": "LGPL"
254606              }
254607            }
254608          ],
254609          "cpe": "cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.35.2-2:*:*:*:*:*:*:*",
254610          "purl": "pkg:deb/debian/binutils-x86-64-linux-gnu@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11",
254611          "swid": {
254612            "attachment": {}
254613          },
254614          "pedigree": {},
254615          "evidence": {},
254616          "signature": {
254617            "signature": {
254618              "publicKey": {}
254619            }
254620          },
254621          "modelCard": {
254622            "modelParameters": {
254623              "approach": {}
254624            },
254625            "quantitativeAnalysis": {
254626              "graphics": {}
254627            },
254628            "considerations": {}
254629          }
254630        },
254631        {
254632          "type": "library",
254633          "bom-ref": "pkg:deb/debian/bridge-utils@1.7-1?arch=amd64\u0026distro=debian-11\u0026package-id=1d6017f4b2cecaac",
254634          "supplier": {},
254635          "publisher": "Santiago Garcia Mantinan \u003cmanty@debian.org\u003e",
254636          "name": "bridge-utils",
254637          "version": "1.7-1",
254638          "licenses": [
254639            {
254640              "license": {
254641                "id": "GPL-2.0-only"
254642              }
254643            }
254644          ],
254645          "cpe": "cpe:2.3:a:bridge-utils:bridge-utils:1.7-1:*:*:*:*:*:*:*",
254646          "purl": "pkg:deb/debian/bridge-utils@1.7-1?arch=amd64\u0026distro=debian-11",
254647          "swid": {
254648            "attachment": {}
254649          },
254650          "pedigree": {},
254651          "evidence": {},
254652          "signature": {
254653            "signature": {
254654              "publicKey": {}
254655            }
254656          },
254657          "modelCard": {
254658            "modelParameters": {
254659              "approach": {}
254660            },
254661            "quantitativeAnalysis": {
254662              "graphics": {}
254663            },
254664            "considerations": {}
254665          }
254666        },
254667        {
254668          "type": "library",
254669          "bom-ref": "pkg:deb/debian/bsdutils@1:2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux%402.36.1-8+deb11u1\u0026distro=debian-11\u0026package-id=677e6ace24dce684",
254670          "supplier": {},
254671          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
254672          "name": "bsdutils",
254673          "version": "1:2.36.1-8+deb11u1",
254674          "licenses": [
254675            {
254676              "license": {
254677                "id": "BSD-2-Clause"
254678              }
254679            },
254680            {
254681              "license": {
254682                "id": "BSD-3-Clause"
254683              }
254684            },
254685            {
254686              "license": {
254687                "id": "BSD-4-Clause"
254688              }
254689            },
254690            {
254691              "license": {
254692                "id": "GPL-2.0-only"
254693              }
254694            },
254695            {
254696              "license": {
254697                "id": "GPL-2.0-or-later"
254698              }
254699            },
254700            {
254701              "license": {
254702                "id": "GPL-3.0-only"
254703              }
254704            },
254705            {
254706              "license": {
254707                "id": "GPL-3.0-or-later"
254708              }
254709            },
254710            {
254711              "license": {
254712                "name": "LGPL"
254713              }
254714            },
254715            {
254716              "license": {
254717                "id": "LGPL-2.0-only"
254718              }
254719            },
254720            {
254721              "license": {
254722                "id": "LGPL-2.0-or-later"
254723              }
254724            },
254725            {
254726              "license": {
254727                "id": "LGPL-2.1-only"
254728              }
254729            },
254730            {
254731              "license": {
254732                "id": "LGPL-2.1-or-later"
254733              }
254734            },
254735            {
254736              "license": {
254737                "id": "LGPL-3.0-only"
254738              }
254739            },
254740            {
254741              "license": {
254742                "id": "LGPL-3.0-or-later"
254743              }
254744            },
254745            {
254746              "license": {
254747                "id": "MIT"
254748              }
254749            },
254750            {
254751              "license": {
254752                "name": "public-domain"
254753              }
254754            }
254755          ],
254756          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
254757          "purl": "pkg:deb/debian/bsdutils@1:2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux%402.36.1-8+deb11u1\u0026distro=debian-11",
254758          "swid": {
254759            "attachment": {}
254760          },
254761          "pedigree": {},
254762          "evidence": {},
254763          "signature": {
254764            "signature": {
254765              "publicKey": {}
254766            }
254767          },
254768          "modelCard": {
254769            "modelParameters": {
254770              "approach": {}
254771            },
254772            "quantitativeAnalysis": {
254773              "graphics": {}
254774            },
254775            "considerations": {}
254776          }
254777        },
254778        {
254779          "type": "library",
254780          "bom-ref": "pkg:deb/debian/build-essential@12.9?arch=amd64\u0026distro=debian-11\u0026package-id=5050a7461db58e1b",
254781          "supplier": {},
254782          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
254783          "name": "build-essential",
254784          "version": "12.9",
254785          "licenses": [
254786            {
254787              "license": {
254788                "name": "GPL"
254789              }
254790            }
254791          ],
254792          "cpe": "cpe:2.3:a:build-essential:build-essential:12.9:*:*:*:*:*:*:*",
254793          "purl": "pkg:deb/debian/build-essential@12.9?arch=amd64\u0026distro=debian-11",
254794          "swid": {
254795            "attachment": {}
254796          },
254797          "pedigree": {},
254798          "evidence": {},
254799          "signature": {
254800            "signature": {
254801              "publicKey": {}
254802            }
254803          },
254804          "modelCard": {
254805            "modelParameters": {
254806              "approach": {}
254807            },
254808            "quantitativeAnalysis": {
254809              "graphics": {}
254810            },
254811            "considerations": {}
254812          }
254813        },
254814        {
254815          "type": "library",
254816          "bom-ref": "pkg:deb/debian/bzip2@1.0.8-4?arch=amd64\u0026distro=debian-11\u0026package-id=ad55a67b4d12349e",
254817          "supplier": {},
254818          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
254819          "name": "bzip2",
254820          "version": "1.0.8-4",
254821          "licenses": [
254822            {
254823              "license": {
254824                "name": "BSD-variant"
254825              }
254826            },
254827            {
254828              "license": {
254829                "id": "GPL-2.0-only"
254830              }
254831            }
254832          ],
254833          "cpe": "cpe:2.3:a:bzip2:bzip2:1.0.8-4:*:*:*:*:*:*:*",
254834          "purl": "pkg:deb/debian/bzip2@1.0.8-4?arch=amd64\u0026distro=debian-11",
254835          "swid": {
254836            "attachment": {}
254837          },
254838          "pedigree": {},
254839          "evidence": {},
254840          "signature": {
254841            "signature": {
254842              "publicKey": {}
254843            }
254844          },
254845          "modelCard": {
254846            "modelParameters": {
254847              "approach": {}
254848            },
254849            "quantitativeAnalysis": {
254850              "graphics": {}
254851            },
254852            "considerations": {}
254853          }
254854        },
254855        {
254856          "type": "library",
254857          "bom-ref": "pkg:deb/debian/ca-certificates@20210119?arch=all\u0026distro=debian-11\u0026package-id=6b7e2b0745c43628",
254858          "supplier": {},
254859          "publisher": "Julien Cristau \u003cjcristau@debian.org\u003e",
254860          "name": "ca-certificates",
254861          "version": "20210119",
254862          "licenses": [
254863            {
254864              "license": {
254865                "id": "GPL-2.0-only"
254866              }
254867            },
254868            {
254869              "license": {
254870                "id": "GPL-2.0-or-later"
254871              }
254872            },
254873            {
254874              "license": {
254875                "id": "MPL-2.0"
254876              }
254877            }
254878          ],
254879          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20210119:*:*:*:*:*:*:*",
254880          "purl": "pkg:deb/debian/ca-certificates@20210119?arch=all\u0026distro=debian-11",
254881          "swid": {
254882            "attachment": {}
254883          },
254884          "pedigree": {},
254885          "evidence": {},
254886          "signature": {
254887            "signature": {
254888              "publicKey": {}
254889            }
254890          },
254891          "modelCard": {
254892            "modelParameters": {
254893              "approach": {}
254894            },
254895            "quantitativeAnalysis": {
254896              "graphics": {}
254897            },
254898            "considerations": {}
254899          }
254900        },
254901        {
254902          "type": "library",
254903          "bom-ref": "pkg:deb/debian/coreutils@8.32-4+b1?arch=amd64\u0026upstream=coreutils%408.32-4\u0026distro=debian-11\u0026package-id=65bac153c492b66e",
254904          "supplier": {},
254905          "publisher": "Michael Stone \u003cmstone@debian.org\u003e",
254906          "name": "coreutils",
254907          "version": "8.32-4+b1",
254908          "licenses": [
254909            {
254910              "license": {
254911                "id": "GPL-3.0-only"
254912              }
254913            }
254914          ],
254915          "cpe": "cpe:2.3:a:coreutils:coreutils:8.32-4\\+b1:*:*:*:*:*:*:*",
254916          "purl": "pkg:deb/debian/coreutils@8.32-4+b1?arch=amd64\u0026upstream=coreutils%408.32-4\u0026distro=debian-11",
254917          "swid": {
254918            "attachment": {}
254919          },
254920          "pedigree": {},
254921          "evidence": {},
254922          "signature": {
254923            "signature": {
254924              "publicKey": {}
254925            }
254926          },
254927          "modelCard": {
254928            "modelParameters": {
254929              "approach": {}
254930            },
254931            "quantitativeAnalysis": {
254932              "graphics": {}
254933            },
254934            "considerations": {}
254935          }
254936        },
254937        {
254938          "type": "library",
254939          "bom-ref": "pkg:deb/debian/cpp@4:10.2.1-1?arch=amd64\u0026upstream=gcc-defaults%401.190\u0026distro=debian-11\u0026package-id=e516dbbaa98e2923",
254940          "supplier": {},
254941          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
254942          "name": "cpp",
254943          "version": "4:10.2.1-1",
254944          "licenses": [
254945            {
254946              "license": {
254947                "id": "GPL-2.0-only"
254948              }
254949            }
254950          ],
254951          "cpe": "cpe:2.3:a:cpp:cpp:4\\:10.2.1-1:*:*:*:*:*:*:*",
254952          "purl": "pkg:deb/debian/cpp@4:10.2.1-1?arch=amd64\u0026upstream=gcc-defaults%401.190\u0026distro=debian-11",
254953          "swid": {
254954            "attachment": {}
254955          },
254956          "pedigree": {},
254957          "evidence": {},
254958          "signature": {
254959            "signature": {
254960              "publicKey": {}
254961            }
254962          },
254963          "modelCard": {
254964            "modelParameters": {
254965              "approach": {}
254966            },
254967            "quantitativeAnalysis": {
254968              "graphics": {}
254969            },
254970            "considerations": {}
254971          }
254972        },
254973        {
254974          "type": "library",
254975          "bom-ref": "pkg:deb/debian/cpp-10@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=dc45592ad23e2d35",
254976          "supplier": {},
254977          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
254978          "name": "cpp-10",
254979          "version": "10.2.1-6",
254980          "licenses": [
254981            {
254982              "license": {
254983                "name": "Artistic"
254984              }
254985            },
254986            {
254987              "license": {
254988                "id": "GFDL-1.2-only"
254989              }
254990            },
254991            {
254992              "license": {
254993                "name": "GPL"
254994              }
254995            },
254996            {
254997              "license": {
254998                "id": "GPL-2.0-only"
254999              }
255000            },
255001            {
255002              "license": {
255003                "id": "GPL-3.0-only"
255004              }
255005            },
255006            {
255007              "license": {
255008                "name": "LGPL"
255009              }
255010            }
255011          ],
255012          "cpe": "cpe:2.3:a:cpp-10:cpp-10:10.2.1-6:*:*:*:*:*:*:*",
255013          "purl": "pkg:deb/debian/cpp-10@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
255014          "swid": {
255015            "attachment": {}
255016          },
255017          "pedigree": {},
255018          "evidence": {},
255019          "signature": {
255020            "signature": {
255021              "publicKey": {}
255022            }
255023          },
255024          "modelCard": {
255025            "modelParameters": {
255026              "approach": {}
255027            },
255028            "quantitativeAnalysis": {
255029              "graphics": {}
255030            },
255031            "considerations": {}
255032          }
255033        },
255034        {
255035          "type": "library",
255036          "bom-ref": "pkg:deb/debian/cron@3.0pl1-137?arch=amd64\u0026distro=debian-11\u0026package-id=1c68faf525e1be27",
255037          "supplier": {},
255038          "publisher": "Javier Fernández-Sanguino Peña \u003cjfs@debian.org\u003e",
255039          "name": "cron",
255040          "version": "3.0pl1-137",
255041          "licenses": [
255042            {
255043              "license": {
255044                "name": "Artistic"
255045              }
255046            },
255047            {
255048              "license": {
255049                "id": "GPL-2.0-only"
255050              }
255051            },
255052            {
255053              "license": {
255054                "id": "GPL-2.0-or-later"
255055              }
255056            },
255057            {
255058              "license": {
255059                "id": "ISC"
255060              }
255061            },
255062            {
255063              "license": {
255064                "name": "Paul-Vixie's-license"
255065              }
255066            }
255067          ],
255068          "cpe": "cpe:2.3:a:cron:cron:3.0pl1-137:*:*:*:*:*:*:*",
255069          "purl": "pkg:deb/debian/cron@3.0pl1-137?arch=amd64\u0026distro=debian-11",
255070          "swid": {
255071            "attachment": {}
255072          },
255073          "pedigree": {},
255074          "evidence": {},
255075          "signature": {
255076            "signature": {
255077              "publicKey": {}
255078            }
255079          },
255080          "modelCard": {
255081            "modelParameters": {
255082              "approach": {}
255083            },
255084            "quantitativeAnalysis": {
255085              "graphics": {}
255086            },
255087            "considerations": {}
255088          }
255089        },
255090        {
255091          "type": "library",
255092          "bom-ref": "pkg:deb/debian/curl@7.74.0-1.3+deb11u3?arch=amd64\u0026distro=debian-11\u0026package-id=61cfce17f478a6e",
255093          "supplier": {},
255094          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
255095          "name": "curl",
255096          "version": "7.74.0-1.3+deb11u3",
255097          "licenses": [
255098            {
255099              "license": {
255100                "id": "BSD-3-Clause"
255101              }
255102            },
255103            {
255104              "license": {
255105                "id": "BSD-4-Clause"
255106              }
255107            },
255108            {
255109              "license": {
255110                "id": "ISC"
255111              }
255112            },
255113            {
255114              "license": {
255115                "id": "curl"
255116              }
255117            },
255118            {
255119              "license": {
255120                "name": "other"
255121              }
255122            },
255123            {
255124              "license": {
255125                "name": "public-domain"
255126              }
255127            }
255128          ],
255129          "cpe": "cpe:2.3:a:curl:curl:7.74.0-1.3\\+deb11u3:*:*:*:*:*:*:*",
255130          "purl": "pkg:deb/debian/curl@7.74.0-1.3+deb11u3?arch=amd64\u0026distro=debian-11",
255131          "swid": {
255132            "attachment": {}
255133          },
255134          "pedigree": {},
255135          "evidence": {},
255136          "signature": {
255137            "signature": {
255138              "publicKey": {}
255139            }
255140          },
255141          "modelCard": {
255142            "modelParameters": {
255143              "approach": {}
255144            },
255145            "quantitativeAnalysis": {
255146              "graphics": {}
255147            },
255148            "considerations": {}
255149          }
255150        },
255151        {
255152          "type": "library",
255153          "bom-ref": "pkg:deb/debian/dash@0.5.11+git20200708+dd9ef66-5?arch=amd64\u0026distro=debian-11\u0026package-id=19db7775ce4c27be",
255154          "supplier": {},
255155          "publisher": "Andrej Shadura \u003candrewsh@debian.org\u003e",
255156          "name": "dash",
255157          "version": "0.5.11+git20200708+dd9ef66-5",
255158          "licenses": [
255159            {
255160              "license": {
255161                "id": "BSD-3-Clause"
255162              }
255163            },
255164            {
255165              "license": {
255166                "id": "BSD-3-Clause"
255167              }
255168            },
255169            {
255170              "license": {
255171                "name": "Expat"
255172              }
255173            },
255174            {
255175              "license": {
255176                "id": "FSFUL"
255177              }
255178            },
255179            {
255180              "license": {
255181                "id": "FSFULLR"
255182              }
255183            },
255184            {
255185              "license": {
255186                "id": "GPL-2.0-only"
255187              }
255188            },
255189            {
255190              "license": {
255191                "id": "GPL-2.0-or-later"
255192              }
255193            },
255194            {
255195              "license": {
255196                "name": "public-domain"
255197              }
255198            }
255199          ],
255200          "cpe": "cpe:2.3:a:dash:dash:0.5.11\\+git20200708\\+dd9ef66-5:*:*:*:*:*:*:*",
255201          "purl": "pkg:deb/debian/dash@0.5.11+git20200708+dd9ef66-5?arch=amd64\u0026distro=debian-11",
255202          "swid": {
255203            "attachment": {}
255204          },
255205          "pedigree": {},
255206          "evidence": {},
255207          "signature": {
255208            "signature": {
255209              "publicKey": {}
255210            }
255211          },
255212          "modelCard": {
255213            "modelParameters": {
255214              "approach": {}
255215            },
255216            "quantitativeAnalysis": {
255217              "graphics": {}
255218            },
255219            "considerations": {}
255220          }
255221        },
255222        {
255223          "type": "library",
255224          "bom-ref": "pkg:deb/debian/debconf@1.5.77?arch=all\u0026distro=debian-11\u0026package-id=99525df5637687bd",
255225          "supplier": {},
255226          "publisher": "Debconf Developers \u003cdebconf-devel@lists.alioth.debian.org\u003e",
255227          "name": "debconf",
255228          "version": "1.5.77",
255229          "licenses": [
255230            {
255231              "license": {
255232                "id": "BSD-2-Clause"
255233              }
255234            }
255235          ],
255236          "cpe": "cpe:2.3:a:debconf:debconf:1.5.77:*:*:*:*:*:*:*",
255237          "purl": "pkg:deb/debian/debconf@1.5.77?arch=all\u0026distro=debian-11",
255238          "swid": {
255239            "attachment": {}
255240          },
255241          "pedigree": {},
255242          "evidence": {},
255243          "signature": {
255244            "signature": {
255245              "publicKey": {}
255246            }
255247          },
255248          "modelCard": {
255249            "modelParameters": {
255250              "approach": {}
255251            },
255252            "quantitativeAnalysis": {
255253              "graphics": {}
255254            },
255255            "considerations": {}
255256          }
255257        },
255258        {
255259          "type": "library",
255260          "bom-ref": "pkg:deb/debian/debian-archive-keyring@2021.1.1?arch=all\u0026distro=debian-11\u0026package-id=f7fcb44a58e72708",
255261          "supplier": {},
255262          "publisher": "Debian Release Team \u003cpackages@release.debian.org\u003e",
255263          "name": "debian-archive-keyring",
255264          "version": "2021.1.1",
255265          "licenses": [
255266            {
255267              "license": {
255268                "name": "GPL"
255269              }
255270            }
255271          ],
255272          "cpe": "cpe:2.3:a:debian-archive-keyring:debian-archive-keyring:2021.1.1:*:*:*:*:*:*:*",
255273          "purl": "pkg:deb/debian/debian-archive-keyring@2021.1.1?arch=all\u0026distro=debian-11",
255274          "swid": {
255275            "attachment": {}
255276          },
255277          "pedigree": {},
255278          "evidence": {},
255279          "signature": {
255280            "signature": {
255281              "publicKey": {}
255282            }
255283          },
255284          "modelCard": {
255285            "modelParameters": {
255286              "approach": {}
255287            },
255288            "quantitativeAnalysis": {
255289              "graphics": {}
255290            },
255291            "considerations": {}
255292          }
255293        },
255294        {
255295          "type": "library",
255296          "bom-ref": "pkg:deb/debian/debianutils@4.11.2?arch=amd64\u0026distro=debian-11\u0026package-id=4cd4f150dae8c295",
255297          "supplier": {},
255298          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
255299          "name": "debianutils",
255300          "version": "4.11.2",
255301          "licenses": [
255302            {
255303              "license": {
255304                "id": "GPL-2.0-only"
255305              }
255306            }
255307          ],
255308          "cpe": "cpe:2.3:a:debianutils:debianutils:4.11.2:*:*:*:*:*:*:*",
255309          "purl": "pkg:deb/debian/debianutils@4.11.2?arch=amd64\u0026distro=debian-11",
255310          "swid": {
255311            "attachment": {}
255312          },
255313          "pedigree": {},
255314          "evidence": {},
255315          "signature": {
255316            "signature": {
255317              "publicKey": {}
255318            }
255319          },
255320          "modelCard": {
255321            "modelParameters": {
255322              "approach": {}
255323            },
255324            "quantitativeAnalysis": {
255325              "graphics": {}
255326            },
255327            "considerations": {}
255328          }
255329        },
255330        {
255331          "type": "library",
255332          "bom-ref": "pkg:deb/debian/diffutils@1:3.7-5?arch=amd64\u0026distro=debian-11\u0026package-id=9133f9a320bf77e1",
255333          "supplier": {},
255334          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
255335          "name": "diffutils",
255336          "version": "1:3.7-5",
255337          "licenses": [
255338            {
255339              "license": {
255340                "name": "GFDL"
255341              }
255342            },
255343            {
255344              "license": {
255345                "name": "GPL"
255346              }
255347            }
255348          ],
255349          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-5:*:*:*:*:*:*:*",
255350          "purl": "pkg:deb/debian/diffutils@1:3.7-5?arch=amd64\u0026distro=debian-11",
255351          "swid": {
255352            "attachment": {}
255353          },
255354          "pedigree": {},
255355          "evidence": {},
255356          "signature": {
255357            "signature": {
255358              "publicKey": {}
255359            }
255360          },
255361          "modelCard": {
255362            "modelParameters": {
255363              "approach": {}
255364            },
255365            "quantitativeAnalysis": {
255366              "graphics": {}
255367            },
255368            "considerations": {}
255369          }
255370        },
255371        {
255372          "type": "library",
255373          "bom-ref": "pkg:deb/debian/dnsutils@1:9.16.33-1~deb11u1?arch=all\u0026upstream=bind9\u0026distro=debian-11\u0026package-id=8fad8800619a3fcd",
255374          "supplier": {},
255375          "publisher": "Debian DNS Team \u003cteam+dns@tracker.debian.org\u003e",
255376          "name": "dnsutils",
255377          "version": "1:9.16.33-1~deb11u1",
255378          "licenses": [
255379            {
255380              "license": {
255381                "id": "BSD-2-Clause"
255382              }
255383            },
255384            {
255385              "license": {
255386                "id": "BSD-3-Clause"
255387              }
255388            },
255389            {
255390              "license": {
255391                "id": "CC0-1.0"
255392              }
255393            },
255394            {
255395              "license": {
255396                "id": "ISC"
255397              }
255398            },
255399            {
255400              "license": {
255401                "id": "MPL-2.0"
255402              }
255403            }
255404          ],
255405          "cpe": "cpe:2.3:a:dnsutils:dnsutils:1\\:9.16.33-1\\~deb11u1:*:*:*:*:*:*:*",
255406          "purl": "pkg:deb/debian/dnsutils@1:9.16.33-1~deb11u1?arch=all\u0026upstream=bind9\u0026distro=debian-11",
255407          "swid": {
255408            "attachment": {}
255409          },
255410          "pedigree": {},
255411          "evidence": {},
255412          "signature": {
255413            "signature": {
255414              "publicKey": {}
255415            }
255416          },
255417          "modelCard": {
255418            "modelParameters": {
255419              "approach": {}
255420            },
255421            "quantitativeAnalysis": {
255422              "graphics": {}
255423            },
255424            "considerations": {}
255425          }
255426        },
255427        {
255428          "type": "library",
255429          "bom-ref": "pkg:deb/debian/dpkg@1.20.12?arch=amd64\u0026distro=debian-11\u0026package-id=3dbbad249b74a866",
255430          "supplier": {},
255431          "publisher": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e",
255432          "name": "dpkg",
255433          "version": "1.20.12",
255434          "licenses": [
255435            {
255436              "license": {
255437                "id": "BSD-2-Clause"
255438              }
255439            },
255440            {
255441              "license": {
255442                "id": "GPL-2.0-only"
255443              }
255444            },
255445            {
255446              "license": {
255447                "id": "GPL-2.0-or-later"
255448              }
255449            },
255450            {
255451              "license": {
255452                "name": "public-domain-md5"
255453              }
255454            },
255455            {
255456              "license": {
255457                "name": "public-domain-s-s-d"
255458              }
255459            }
255460          ],
255461          "cpe": "cpe:2.3:a:dpkg:dpkg:1.20.12:*:*:*:*:*:*:*",
255462          "purl": "pkg:deb/debian/dpkg@1.20.12?arch=amd64\u0026distro=debian-11",
255463          "swid": {
255464            "attachment": {}
255465          },
255466          "pedigree": {},
255467          "evidence": {},
255468          "signature": {
255469            "signature": {
255470              "publicKey": {}
255471            }
255472          },
255473          "modelCard": {
255474            "modelParameters": {
255475              "approach": {}
255476            },
255477            "quantitativeAnalysis": {
255478              "graphics": {}
255479            },
255480            "considerations": {}
255481          }
255482        },
255483        {
255484          "type": "library",
255485          "bom-ref": "pkg:deb/debian/dpkg-dev@1.20.12?arch=all\u0026upstream=dpkg\u0026distro=debian-11\u0026package-id=5d8445b8e65f0cdd",
255486          "supplier": {},
255487          "publisher": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e",
255488          "name": "dpkg-dev",
255489          "version": "1.20.12",
255490          "licenses": [
255491            {
255492              "license": {
255493                "id": "BSD-2-Clause"
255494              }
255495            },
255496            {
255497              "license": {
255498                "id": "GPL-2.0-only"
255499              }
255500            },
255501            {
255502              "license": {
255503                "id": "GPL-2.0-or-later"
255504              }
255505            },
255506            {
255507              "license": {
255508                "name": "public-domain-md5"
255509              }
255510            },
255511            {
255512              "license": {
255513                "name": "public-domain-s-s-d"
255514              }
255515            }
255516          ],
255517          "cpe": "cpe:2.3:a:dpkg-dev:dpkg-dev:1.20.12:*:*:*:*:*:*:*",
255518          "purl": "pkg:deb/debian/dpkg-dev@1.20.12?arch=all\u0026upstream=dpkg\u0026distro=debian-11",
255519          "swid": {
255520            "attachment": {}
255521          },
255522          "pedigree": {},
255523          "evidence": {},
255524          "signature": {
255525            "signature": {
255526              "publicKey": {}
255527            }
255528          },
255529          "modelCard": {
255530            "modelParameters": {
255531              "approach": {}
255532            },
255533            "quantitativeAnalysis": {
255534              "graphics": {}
255535            },
255536            "considerations": {}
255537          }
255538        },
255539        {
255540          "type": "library",
255541          "bom-ref": "pkg:deb/debian/e2fsprogs@1.46.2-2?arch=amd64\u0026distro=debian-11\u0026package-id=7c4baa682137e759",
255542          "supplier": {},
255543          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
255544          "name": "e2fsprogs",
255545          "version": "1.46.2-2",
255546          "licenses": [
255547            {
255548              "license": {
255549                "id": "GPL-2.0-only"
255550              }
255551            },
255552            {
255553              "license": {
255554                "id": "LGPL-2.0-only"
255555              }
255556            }
255557          ],
255558          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.46.2-2:*:*:*:*:*:*:*",
255559          "purl": "pkg:deb/debian/e2fsprogs@1.46.2-2?arch=amd64\u0026distro=debian-11",
255560          "swid": {
255561            "attachment": {}
255562          },
255563          "pedigree": {},
255564          "evidence": {},
255565          "signature": {
255566            "signature": {
255567              "publicKey": {}
255568            }
255569          },
255570          "modelCard": {
255571            "modelParameters": {
255572              "approach": {}
255573            },
255574            "quantitativeAnalysis": {
255575              "graphics": {}
255576            },
255577            "considerations": {}
255578          }
255579        },
255580        {
255581          "type": "library",
255582          "bom-ref": "pkg:deb/debian/findutils@4.8.0-1?arch=amd64\u0026distro=debian-11\u0026package-id=b503e3d45616f33c",
255583          "supplier": {},
255584          "publisher": "Andreas Metzler \u003cametzler@debian.org\u003e",
255585          "name": "findutils",
255586          "version": "4.8.0-1",
255587          "licenses": [
255588            {
255589              "license": {
255590                "id": "GFDL-1.3-only"
255591              }
255592            },
255593            {
255594              "license": {
255595                "id": "GPL-3.0-only"
255596              }
255597            }
255598          ],
255599          "cpe": "cpe:2.3:a:findutils:findutils:4.8.0-1:*:*:*:*:*:*:*",
255600          "purl": "pkg:deb/debian/findutils@4.8.0-1?arch=amd64\u0026distro=debian-11",
255601          "swid": {
255602            "attachment": {}
255603          },
255604          "pedigree": {},
255605          "evidence": {},
255606          "signature": {
255607            "signature": {
255608              "publicKey": {}
255609            }
255610          },
255611          "modelCard": {
255612            "modelParameters": {
255613              "approach": {}
255614            },
255615            "quantitativeAnalysis": {
255616              "graphics": {}
255617            },
255618            "considerations": {}
255619          }
255620        },
255621        {
255622          "type": "library",
255623          "bom-ref": "pkg:deb/debian/fontconfig@2.13.1-4.2?arch=amd64\u0026distro=debian-11\u0026package-id=3c9030a6708e02d",
255624          "supplier": {},
255625          "publisher": "Debian freedesktop.org maintainers \u003cpkg-freedesktop-maintainers@lists.alioth.debian.org\u003e",
255626          "name": "fontconfig",
255627          "version": "2.13.1-4.2",
255628          "cpe": "cpe:2.3:a:fontconfig:fontconfig:2.13.1-4.2:*:*:*:*:*:*:*",
255629          "purl": "pkg:deb/debian/fontconfig@2.13.1-4.2?arch=amd64\u0026distro=debian-11",
255630          "swid": {
255631            "attachment": {}
255632          },
255633          "pedigree": {},
255634          "evidence": {},
255635          "signature": {
255636            "signature": {
255637              "publicKey": {}
255638            }
255639          },
255640          "modelCard": {
255641            "modelParameters": {
255642              "approach": {}
255643            },
255644            "quantitativeAnalysis": {
255645              "graphics": {}
255646            },
255647            "considerations": {}
255648          }
255649        },
255650        {
255651          "type": "library",
255652          "bom-ref": "pkg:deb/debian/fontconfig-config@2.13.1-4.2?arch=all\u0026upstream=fontconfig\u0026distro=debian-11\u0026package-id=4cbb1169d85c98",
255653          "supplier": {},
255654          "publisher": "Debian freedesktop.org maintainers \u003cpkg-freedesktop-maintainers@lists.alioth.debian.org\u003e",
255655          "name": "fontconfig-config",
255656          "version": "2.13.1-4.2",
255657          "cpe": "cpe:2.3:a:fontconfig-config:fontconfig-config:2.13.1-4.2:*:*:*:*:*:*:*",
255658          "purl": "pkg:deb/debian/fontconfig-config@2.13.1-4.2?arch=all\u0026upstream=fontconfig\u0026distro=debian-11",
255659          "swid": {
255660            "attachment": {}
255661          },
255662          "pedigree": {},
255663          "evidence": {},
255664          "signature": {
255665            "signature": {
255666              "publicKey": {}
255667            }
255668          },
255669          "modelCard": {
255670            "modelParameters": {
255671              "approach": {}
255672            },
255673            "quantitativeAnalysis": {
255674              "graphics": {}
255675            },
255676            "considerations": {}
255677          }
255678        },
255679        {
255680          "type": "library",
255681          "bom-ref": "pkg:deb/debian/fonts-dejavu-core@2.37-2?arch=all\u0026upstream=fonts-dejavu\u0026distro=debian-11\u0026package-id=6c1e339e269277ec",
255682          "supplier": {},
255683          "publisher": "Debian Fonts Task Force \u003cdebian-fonts@lists.debian.org\u003e",
255684          "name": "fonts-dejavu-core",
255685          "version": "2.37-2",
255686          "licenses": [
255687            {
255688              "license": {
255689                "id": "GPL-2.0-only"
255690              }
255691            },
255692            {
255693              "license": {
255694                "id": "GPL-2.0-or-later"
255695              }
255696            },
255697            {
255698              "license": {
255699                "id": "Bitstream-Vera"
255700              }
255701            }
255702          ],
255703          "cpe": "cpe:2.3:a:fonts-dejavu-core:fonts-dejavu-core:2.37-2:*:*:*:*:*:*:*",
255704          "purl": "pkg:deb/debian/fonts-dejavu-core@2.37-2?arch=all\u0026upstream=fonts-dejavu\u0026distro=debian-11",
255705          "swid": {
255706            "attachment": {}
255707          },
255708          "pedigree": {},
255709          "evidence": {},
255710          "signature": {
255711            "signature": {
255712              "publicKey": {}
255713            }
255714          },
255715          "modelCard": {
255716            "modelParameters": {
255717              "approach": {}
255718            },
255719            "quantitativeAnalysis": {
255720              "graphics": {}
255721            },
255722            "considerations": {}
255723          }
255724        },
255725        {
255726          "type": "library",
255727          "bom-ref": "pkg:deb/debian/g++@4:10.2.1-1?arch=amd64\u0026upstream=gcc-defaults%401.190\u0026distro=debian-11\u0026package-id=6b6519c4607e45e",
255728          "supplier": {},
255729          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
255730          "name": "g++",
255731          "version": "4:10.2.1-1",
255732          "licenses": [
255733            {
255734              "license": {
255735                "id": "GPL-2.0-only"
255736              }
255737            }
255738          ],
255739          "cpe": "cpe:2.3:a:g\\+\\+:g\\+\\+:4\\:10.2.1-1:*:*:*:*:*:*:*",
255740          "purl": "pkg:deb/debian/g++@4:10.2.1-1?arch=amd64\u0026upstream=gcc-defaults%401.190\u0026distro=debian-11",
255741          "swid": {
255742            "attachment": {}
255743          },
255744          "pedigree": {},
255745          "evidence": {},
255746          "signature": {
255747            "signature": {
255748              "publicKey": {}
255749            }
255750          },
255751          "modelCard": {
255752            "modelParameters": {
255753              "approach": {}
255754            },
255755            "quantitativeAnalysis": {
255756              "graphics": {}
255757            },
255758            "considerations": {}
255759          }
255760        },
255761        {
255762          "type": "library",
255763          "bom-ref": "pkg:deb/debian/g++-10@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=51dfb6b320067d0f",
255764          "supplier": {},
255765          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
255766          "name": "g++-10",
255767          "version": "10.2.1-6",
255768          "licenses": [
255769            {
255770              "license": {
255771                "name": "Artistic"
255772              }
255773            },
255774            {
255775              "license": {
255776                "id": "GFDL-1.2-only"
255777              }
255778            },
255779            {
255780              "license": {
255781                "name": "GPL"
255782              }
255783            },
255784            {
255785              "license": {
255786                "id": "GPL-2.0-only"
255787              }
255788            },
255789            {
255790              "license": {
255791                "id": "GPL-3.0-only"
255792              }
255793            },
255794            {
255795              "license": {
255796                "name": "LGPL"
255797              }
255798            }
255799          ],
255800          "cpe": "cpe:2.3:a:g\\+\\+-10:g\\+\\+-10:10.2.1-6:*:*:*:*:*:*:*",
255801          "purl": "pkg:deb/debian/g++-10@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
255802          "swid": {
255803            "attachment": {}
255804          },
255805          "pedigree": {},
255806          "evidence": {},
255807          "signature": {
255808            "signature": {
255809              "publicKey": {}
255810            }
255811          },
255812          "modelCard": {
255813            "modelParameters": {
255814              "approach": {}
255815            },
255816            "quantitativeAnalysis": {
255817              "graphics": {}
255818            },
255819            "considerations": {}
255820          }
255821        },
255822        {
255823          "type": "library",
255824          "bom-ref": "pkg:deb/debian/gcc@4:10.2.1-1?arch=amd64\u0026upstream=gcc-defaults%401.190\u0026distro=debian-11\u0026package-id=a6ecfb912c8833e4",
255825          "supplier": {},
255826          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
255827          "name": "gcc",
255828          "version": "4:10.2.1-1",
255829          "licenses": [
255830            {
255831              "license": {
255832                "id": "GPL-2.0-only"
255833              }
255834            }
255835          ],
255836          "cpe": "cpe:2.3:a:gcc:gcc:4\\:10.2.1-1:*:*:*:*:*:*:*",
255837          "purl": "pkg:deb/debian/gcc@4:10.2.1-1?arch=amd64\u0026upstream=gcc-defaults%401.190\u0026distro=debian-11",
255838          "swid": {
255839            "attachment": {}
255840          },
255841          "pedigree": {},
255842          "evidence": {},
255843          "signature": {
255844            "signature": {
255845              "publicKey": {}
255846            }
255847          },
255848          "modelCard": {
255849            "modelParameters": {
255850              "approach": {}
255851            },
255852            "quantitativeAnalysis": {
255853              "graphics": {}
255854            },
255855            "considerations": {}
255856          }
255857        },
255858        {
255859          "type": "library",
255860          "bom-ref": "pkg:deb/debian/gcc-10@10.2.1-6?arch=amd64\u0026distro=debian-11\u0026package-id=50efe1856f600714",
255861          "supplier": {},
255862          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
255863          "name": "gcc-10",
255864          "version": "10.2.1-6",
255865          "licenses": [
255866            {
255867              "license": {
255868                "name": "Artistic"
255869              }
255870            },
255871            {
255872              "license": {
255873                "id": "GFDL-1.2-only"
255874              }
255875            },
255876            {
255877              "license": {
255878                "name": "GPL"
255879              }
255880            },
255881            {
255882              "license": {
255883                "id": "GPL-2.0-only"
255884              }
255885            },
255886            {
255887              "license": {
255888                "id": "GPL-3.0-only"
255889              }
255890            },
255891            {
255892              "license": {
255893                "name": "LGPL"
255894              }
255895            }
255896          ],
255897          "cpe": "cpe:2.3:a:gcc-10:gcc-10:10.2.1-6:*:*:*:*:*:*:*",
255898          "purl": "pkg:deb/debian/gcc-10@10.2.1-6?arch=amd64\u0026distro=debian-11",
255899          "swid": {
255900            "attachment": {}
255901          },
255902          "pedigree": {},
255903          "evidence": {},
255904          "signature": {
255905            "signature": {
255906              "publicKey": {}
255907            }
255908          },
255909          "modelCard": {
255910            "modelParameters": {
255911              "approach": {}
255912            },
255913            "quantitativeAnalysis": {
255914              "graphics": {}
255915            },
255916            "considerations": {}
255917          }
255918        },
255919        {
255920          "type": "library",
255921          "bom-ref": "pkg:deb/debian/gcc-10-base@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=742204f033ae5a1e",
255922          "supplier": {},
255923          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
255924          "name": "gcc-10-base",
255925          "version": "10.2.1-6",
255926          "licenses": [
255927            {
255928              "license": {
255929                "name": "Artistic"
255930              }
255931            },
255932            {
255933              "license": {
255934                "id": "GFDL-1.2-only"
255935              }
255936            },
255937            {
255938              "license": {
255939                "name": "GPL"
255940              }
255941            },
255942            {
255943              "license": {
255944                "id": "GPL-2.0-only"
255945              }
255946            },
255947            {
255948              "license": {
255949                "id": "GPL-3.0-only"
255950              }
255951            },
255952            {
255953              "license": {
255954                "name": "LGPL"
255955              }
255956            }
255957          ],
255958          "cpe": "cpe:2.3:a:gcc-10-base:gcc-10-base:10.2.1-6:*:*:*:*:*:*:*",
255959          "purl": "pkg:deb/debian/gcc-10-base@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
255960          "swid": {
255961            "attachment": {}
255962          },
255963          "pedigree": {},
255964          "evidence": {},
255965          "signature": {
255966            "signature": {
255967              "publicKey": {}
255968            }
255969          },
255970          "modelCard": {
255971            "modelParameters": {
255972              "approach": {}
255973            },
255974            "quantitativeAnalysis": {
255975              "graphics": {}
255976            },
255977            "considerations": {}
255978          }
255979        },
255980        {
255981          "type": "library",
255982          "bom-ref": "pkg:deb/debian/gcc-9-base@9.3.0-22?arch=amd64\u0026upstream=gcc-9\u0026distro=debian-11\u0026package-id=57c0768e353bbfc8",
255983          "supplier": {},
255984          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
255985          "name": "gcc-9-base",
255986          "version": "9.3.0-22",
255987          "licenses": [
255988            {
255989              "license": {
255990                "name": "Artistic"
255991              }
255992            },
255993            {
255994              "license": {
255995                "id": "GFDL-1.2-only"
255996              }
255997            },
255998            {
255999              "license": {
256000                "name": "GPL"
256001              }
256002            },
256003            {
256004              "license": {
256005                "id": "GPL-2.0-only"
256006              }
256007            },
256008            {
256009              "license": {
256010                "id": "GPL-3.0-only"
256011              }
256012            },
256013            {
256014              "license": {
256015                "name": "LGPL"
256016              }
256017            },
256018            {
256019              "license": {
256020                "id": "LGPL-2.1-or-later"
256021              }
256022            }
256023          ],
256024          "cpe": "cpe:2.3:a:gcc-9-base:gcc-9-base:9.3.0-22:*:*:*:*:*:*:*",
256025          "purl": "pkg:deb/debian/gcc-9-base@9.3.0-22?arch=amd64\u0026upstream=gcc-9\u0026distro=debian-11",
256026          "swid": {
256027            "attachment": {}
256028          },
256029          "pedigree": {},
256030          "evidence": {},
256031          "signature": {
256032            "signature": {
256033              "publicKey": {}
256034            }
256035          },
256036          "modelCard": {
256037            "modelParameters": {
256038              "approach": {}
256039            },
256040            "quantitativeAnalysis": {
256041              "graphics": {}
256042            },
256043            "considerations": {}
256044          }
256045        },
256046        {
256047          "type": "library",
256048          "bom-ref": "pkg:deb/debian/gdb@10.1-1.7?arch=amd64\u0026distro=debian-11\u0026package-id=907d43bc4c1c8d83",
256049          "supplier": {},
256050          "publisher": "Héctor Orón Martínez \u003czumbi@debian.org\u003e",
256051          "name": "gdb",
256052          "version": "10.1-1.7",
256053          "licenses": [
256054            {
256055              "license": {
256056                "id": "BSD-3-Clause"
256057              }
256058            },
256059            {
256060              "license": {
256061                "id": "GPL-2.0-only"
256062              }
256063            },
256064            {
256065              "license": {
256066                "id": "GPL-2.0-or-later"
256067              }
256068            },
256069            {
256070              "license": {
256071                "id": "GPL-3.0-only"
256072              }
256073            },
256074            {
256075              "license": {
256076                "id": "GPL-3.0-or-later"
256077              }
256078            },
256079            {
256080              "license": {
256081                "id": "LGPL-2.0-only"
256082              }
256083            },
256084            {
256085              "license": {
256086                "id": "LGPL-2.0-or-later"
256087              }
256088            },
256089            {
256090              "license": {
256091                "id": "LGPL-2.1-only"
256092              }
256093            },
256094            {
256095              "license": {
256096                "id": "LGPL-2.1-or-later"
256097              }
256098            }
256099          ],
256100          "cpe": "cpe:2.3:a:gdb:gdb:10.1-1.7:*:*:*:*:*:*:*",
256101          "purl": "pkg:deb/debian/gdb@10.1-1.7?arch=amd64\u0026distro=debian-11",
256102          "swid": {
256103            "attachment": {}
256104          },
256105          "pedigree": {},
256106          "evidence": {},
256107          "signature": {
256108            "signature": {
256109              "publicKey": {}
256110            }
256111          },
256112          "modelCard": {
256113            "modelParameters": {
256114              "approach": {}
256115            },
256116            "quantitativeAnalysis": {
256117              "graphics": {}
256118            },
256119            "considerations": {}
256120          }
256121        },
256122        {
256123          "type": "library",
256124          "bom-ref": "pkg:deb/debian/git@1:2.30.2-1?arch=amd64\u0026distro=debian-11\u0026package-id=7be419089a488288",
256125          "supplier": {},
256126          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
256127          "name": "git",
256128          "version": "1:2.30.2-1",
256129          "licenses": [
256130            {
256131              "license": {
256132                "id": "Apache-2.0"
256133              }
256134            },
256135            {
256136              "license": {
256137                "name": "Artistic"
256138              }
256139            },
256140            {
256141              "license": {
256142                "name": "Boost"
256143              }
256144            },
256145            {
256146              "license": {
256147                "name": "EDL-1.0"
256148              }
256149            },
256150            {
256151              "license": {
256152                "name": "Expat"
256153              }
256154            },
256155            {
256156              "license": {
256157                "name": "GPL"
256158              }
256159            },
256160            {
256161              "license": {
256162                "id": "GPL-1.0-or-later"
256163              }
256164            },
256165            {
256166              "license": {
256167                "id": "GPL-2.0-only"
256168              }
256169            },
256170            {
256171              "license": {
256172                "id": "GPL-2.0-or-later"
256173              }
256174            },
256175            {
256176              "license": {
256177                "id": "ISC"
256178              }
256179            },
256180            {
256181              "license": {
256182                "id": "LGPL-2.0-only"
256183              }
256184            },
256185            {
256186              "license": {
256187                "id": "LGPL-2.0-or-later"
256188              }
256189            },
256190            {
256191              "license": {
256192                "id": "LGPL-2.1-only"
256193              }
256194            },
256195            {
256196              "license": {
256197                "id": "LGPL-2.1-or-later"
256198              }
256199            },
256200            {
256201              "license": {
256202                "name": "dlmalloc"
256203              }
256204            },
256205            {
256206              "license": {
256207                "name": "mingw-runtime"
256208              }
256209            }
256210          ],
256211          "cpe": "cpe:2.3:a:git:git:1\\:2.30.2-1:*:*:*:*:*:*:*",
256212          "purl": "pkg:deb/debian/git@1:2.30.2-1?arch=amd64\u0026distro=debian-11",
256213          "swid": {
256214            "attachment": {}
256215          },
256216          "pedigree": {},
256217          "evidence": {},
256218          "signature": {
256219            "signature": {
256220              "publicKey": {}
256221            }
256222          },
256223          "modelCard": {
256224            "modelParameters": {
256225              "approach": {}
256226            },
256227            "quantitativeAnalysis": {
256228              "graphics": {}
256229            },
256230            "considerations": {}
256231          }
256232        },
256233        {
256234          "type": "library",
256235          "bom-ref": "pkg:deb/debian/git-man@1:2.30.2-1?arch=all\u0026upstream=git\u0026distro=debian-11\u0026package-id=a785f12138249f6",
256236          "supplier": {},
256237          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
256238          "name": "git-man",
256239          "version": "1:2.30.2-1",
256240          "licenses": [
256241            {
256242              "license": {
256243                "id": "Apache-2.0"
256244              }
256245            },
256246            {
256247              "license": {
256248                "name": "Artistic"
256249              }
256250            },
256251            {
256252              "license": {
256253                "name": "Boost"
256254              }
256255            },
256256            {
256257              "license": {
256258                "name": "EDL-1.0"
256259              }
256260            },
256261            {
256262              "license": {
256263                "name": "Expat"
256264              }
256265            },
256266            {
256267              "license": {
256268                "name": "GPL"
256269              }
256270            },
256271            {
256272              "license": {
256273                "id": "GPL-1.0-or-later"
256274              }
256275            },
256276            {
256277              "license": {
256278                "id": "GPL-2.0-only"
256279              }
256280            },
256281            {
256282              "license": {
256283                "id": "GPL-2.0-or-later"
256284              }
256285            },
256286            {
256287              "license": {
256288                "id": "ISC"
256289              }
256290            },
256291            {
256292              "license": {
256293                "id": "LGPL-2.0-only"
256294              }
256295            },
256296            {
256297              "license": {
256298                "id": "LGPL-2.0-or-later"
256299              }
256300            },
256301            {
256302              "license": {
256303                "id": "LGPL-2.1-only"
256304              }
256305            },
256306            {
256307              "license": {
256308                "id": "LGPL-2.1-or-later"
256309              }
256310            },
256311            {
256312              "license": {
256313                "name": "dlmalloc"
256314              }
256315            },
256316            {
256317              "license": {
256318                "name": "mingw-runtime"
256319              }
256320            }
256321          ],
256322          "cpe": "cpe:2.3:a:git-man:git-man:1\\:2.30.2-1:*:*:*:*:*:*:*",
256323          "purl": "pkg:deb/debian/git-man@1:2.30.2-1?arch=all\u0026upstream=git\u0026distro=debian-11",
256324          "swid": {
256325            "attachment": {}
256326          },
256327          "pedigree": {},
256328          "evidence": {},
256329          "signature": {
256330            "signature": {
256331              "publicKey": {}
256332            }
256333          },
256334          "modelCard": {
256335            "modelParameters": {
256336              "approach": {}
256337            },
256338            "quantitativeAnalysis": {
256339              "graphics": {}
256340            },
256341            "considerations": {}
256342          }
256343        },
256344        {
256345          "type": "library",
256346          "bom-ref": "pkg:deb/debian/gpgv@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11\u0026package-id=b6346590c45ba7ab",
256347          "supplier": {},
256348          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
256349          "name": "gpgv",
256350          "version": "2.2.27-2+deb11u2",
256351          "licenses": [
256352            {
256353              "license": {
256354                "id": "BSD-3-Clause"
256355              }
256356            },
256357            {
256358              "license": {
256359                "id": "CC0-1.0"
256360              }
256361            },
256362            {
256363              "license": {
256364                "name": "Expat"
256365              }
256366            },
256367            {
256368              "license": {
256369                "id": "GPL-3.0-only"
256370              }
256371            },
256372            {
256373              "license": {
256374                "id": "GPL-3.0-or-later"
256375              }
256376            },
256377            {
256378              "license": {
256379                "id": "LGPL-2.1-only"
256380              }
256381            },
256382            {
256383              "license": {
256384                "id": "LGPL-2.1-or-later"
256385              }
256386            },
256387            {
256388              "license": {
256389                "id": "LGPL-3.0-only"
256390              }
256391            },
256392            {
256393              "license": {
256394                "id": "LGPL-3.0-or-later"
256395              }
256396            },
256397            {
256398              "license": {
256399                "name": "RFC-Reference"
256400              }
256401            },
256402            {
256403              "license": {
256404                "name": "TinySCHEME"
256405              }
256406            },
256407            {
256408              "license": {
256409                "name": "permissive"
256410              }
256411            }
256412          ],
256413          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.27-2\\+deb11u2:*:*:*:*:*:*:*",
256414          "purl": "pkg:deb/debian/gpgv@2.2.27-2+deb11u2?arch=amd64\u0026upstream=gnupg2\u0026distro=debian-11",
256415          "swid": {
256416            "attachment": {}
256417          },
256418          "pedigree": {},
256419          "evidence": {},
256420          "signature": {
256421            "signature": {
256422              "publicKey": {}
256423            }
256424          },
256425          "modelCard": {
256426            "modelParameters": {
256427              "approach": {}
256428            },
256429            "quantitativeAnalysis": {
256430              "graphics": {}
256431            },
256432            "considerations": {}
256433          }
256434        },
256435        {
256436          "type": "library",
256437          "bom-ref": "pkg:deb/debian/grep@3.6-1?arch=amd64\u0026distro=debian-11\u0026package-id=9ed140c6f7959d",
256438          "supplier": {},
256439          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
256440          "name": "grep",
256441          "version": "3.6-1",
256442          "licenses": [
256443            {
256444              "license": {
256445                "id": "GPL-3.0-only"
256446              }
256447            },
256448            {
256449              "license": {
256450                "id": "GPL-3.0-or-later"
256451              }
256452            }
256453          ],
256454          "cpe": "cpe:2.3:a:grep:grep:3.6-1:*:*:*:*:*:*:*",
256455          "purl": "pkg:deb/debian/grep@3.6-1?arch=amd64\u0026distro=debian-11",
256456          "swid": {
256457            "attachment": {}
256458          },
256459          "pedigree": {},
256460          "evidence": {},
256461          "signature": {
256462            "signature": {
256463              "publicKey": {}
256464            }
256465          },
256466          "modelCard": {
256467            "modelParameters": {
256468              "approach": {}
256469            },
256470            "quantitativeAnalysis": {
256471              "graphics": {}
256472            },
256473            "considerations": {}
256474          }
256475        },
256476        {
256477          "type": "library",
256478          "bom-ref": "pkg:deb/debian/gtk-update-icon-cache@3.24.24-4+deb11u2?arch=amd64\u0026upstream=gtk+3.0\u0026distro=debian-11\u0026package-id=2526fea62442389c",
256479          "supplier": {},
256480          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
256481          "name": "gtk-update-icon-cache",
256482          "version": "3.24.24-4+deb11u2",
256483          "licenses": [
256484            {
256485              "license": {
256486                "id": "Apache-2.0"
256487              }
256488            },
256489            {
256490              "license": {
256491                "name": "Expat"
256492              }
256493            },
256494            {
256495              "license": {
256496                "id": "LGPL-2.0-only"
256497              }
256498            },
256499            {
256500              "license": {
256501                "id": "LGPL-2.0-or-later"
256502              }
256503            },
256504            {
256505              "license": {
256506                "id": "LGPL-2.1-only"
256507              }
256508            },
256509            {
256510              "license": {
256511                "id": "LGPL-2.1-or-later"
256512              }
256513            },
256514            {
256515              "license": {
256516                "id": "SWL"
256517              }
256518            },
256519            {
256520              "license": {
256521                "name": "X11R5-permissive"
256522              }
256523            },
256524            {
256525              "license": {
256526                "name": "check-gdk-cairo-permissive"
256527              }
256528            },
256529            {
256530              "license": {
256531                "name": "other"
256532              }
256533            }
256534          ],
256535          "cpe": "cpe:2.3:a:gtk-update-icon-cache:gtk-update-icon-cache:3.24.24-4\\+deb11u2:*:*:*:*:*:*:*",
256536          "purl": "pkg:deb/debian/gtk-update-icon-cache@3.24.24-4+deb11u2?arch=amd64\u0026upstream=gtk+3.0\u0026distro=debian-11",
256537          "swid": {
256538            "attachment": {}
256539          },
256540          "pedigree": {},
256541          "evidence": {},
256542          "signature": {
256543            "signature": {
256544              "publicKey": {}
256545            }
256546          },
256547          "modelCard": {
256548            "modelParameters": {
256549              "approach": {}
256550            },
256551            "quantitativeAnalysis": {
256552              "graphics": {}
256553            },
256554            "considerations": {}
256555          }
256556        },
256557        {
256558          "type": "library",
256559          "bom-ref": "pkg:deb/debian/gzip@1.10-4+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=ade955af6710751d",
256560          "supplier": {},
256561          "publisher": "Milan Kupcevic \u003cmilan@debian.org\u003e",
256562          "name": "gzip",
256563          "version": "1.10-4+deb11u1",
256564          "licenses": [
256565            {
256566              "license": {
256567                "name": "FSF-manpages"
256568              }
256569            },
256570            {
256571              "license": {
256572                "name": "GFDL-1.3+-no-invariant"
256573              }
256574            },
256575            {
256576              "license": {
256577                "name": "GFDL-3"
256578              }
256579            },
256580            {
256581              "license": {
256582                "id": "GPL-3.0-only"
256583              }
256584            },
256585            {
256586              "license": {
256587                "id": "GPL-3.0-or-later"
256588              }
256589            }
256590          ],
256591          "cpe": "cpe:2.3:a:gzip:gzip:1.10-4\\+deb11u1:*:*:*:*:*:*:*",
256592          "purl": "pkg:deb/debian/gzip@1.10-4+deb11u1?arch=amd64\u0026distro=debian-11",
256593          "swid": {
256594            "attachment": {}
256595          },
256596          "pedigree": {},
256597          "evidence": {},
256598          "signature": {
256599            "signature": {
256600              "publicKey": {}
256601            }
256602          },
256603          "modelCard": {
256604            "modelParameters": {
256605              "approach": {}
256606            },
256607            "quantitativeAnalysis": {
256608              "graphics": {}
256609            },
256610            "considerations": {}
256611          }
256612        },
256613        {
256614          "type": "library",
256615          "bom-ref": "pkg:deb/debian/hdparm@9.60+ds-1?arch=amd64\u0026distro=debian-11\u0026package-id=2713d6f4d6a293cf",
256616          "supplier": {},
256617          "publisher": "Alexandre Mestiashvili \u003cmestia@debian.org\u003e",
256618          "name": "hdparm",
256619          "version": "9.60+ds-1",
256620          "licenses": [
256621            {
256622              "license": {
256623                "id": "BSD-2-Clause"
256624              }
256625            },
256626            {
256627              "license": {
256628                "id": "GPL-2.0-only"
256629              }
256630            },
256631            {
256632              "license": {
256633                "id": "GPL-2.0-or-later"
256634              }
256635            },
256636            {
256637              "license": {
256638                "name": "hdparm"
256639              }
256640            }
256641          ],
256642          "cpe": "cpe:2.3:a:hdparm:hdparm:9.60\\+ds-1:*:*:*:*:*:*:*",
256643          "purl": "pkg:deb/debian/hdparm@9.60+ds-1?arch=amd64\u0026distro=debian-11",
256644          "swid": {
256645            "attachment": {}
256646          },
256647          "pedigree": {},
256648          "evidence": {},
256649          "signature": {
256650            "signature": {
256651              "publicKey": {}
256652            }
256653          },
256654          "modelCard": {
256655            "modelParameters": {
256656              "approach": {}
256657            },
256658            "quantitativeAnalysis": {
256659              "graphics": {}
256660            },
256661            "considerations": {}
256662          }
256663        },
256664        {
256665          "type": "library",
256666          "bom-ref": "pkg:deb/debian/hicolor-icon-theme@0.17-2?arch=all\u0026distro=debian-11\u0026package-id=a830a0ef5701c9aa",
256667          "supplier": {},
256668          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
256669          "name": "hicolor-icon-theme",
256670          "version": "0.17-2",
256671          "licenses": [
256672            {
256673              "license": {
256674                "id": "GPL-2.0-only"
256675              }
256676            },
256677            {
256678              "license": {
256679                "id": "GPL-2.0-or-later"
256680              }
256681            }
256682          ],
256683          "cpe": "cpe:2.3:a:hicolor-icon-theme:hicolor-icon-theme:0.17-2:*:*:*:*:*:*:*",
256684          "purl": "pkg:deb/debian/hicolor-icon-theme@0.17-2?arch=all\u0026distro=debian-11",
256685          "swid": {
256686            "attachment": {}
256687          },
256688          "pedigree": {},
256689          "evidence": {},
256690          "signature": {
256691            "signature": {
256692              "publicKey": {}
256693            }
256694          },
256695          "modelCard": {
256696            "modelParameters": {
256697              "approach": {}
256698            },
256699            "quantitativeAnalysis": {
256700              "graphics": {}
256701            },
256702            "considerations": {}
256703          }
256704        },
256705        {
256706          "type": "library",
256707          "bom-ref": "pkg:deb/debian/hostname@3.23?arch=amd64\u0026distro=debian-11\u0026package-id=fec906d1ab1d9712",
256708          "supplier": {},
256709          "publisher": "Michael Meskes \u003cmeskes@debian.org\u003e",
256710          "name": "hostname",
256711          "version": "3.23",
256712          "licenses": [
256713            {
256714              "license": {
256715                "id": "GPL-2.0-only"
256716              }
256717            }
256718          ],
256719          "cpe": "cpe:2.3:a:hostname:hostname:3.23:*:*:*:*:*:*:*",
256720          "purl": "pkg:deb/debian/hostname@3.23?arch=amd64\u0026distro=debian-11",
256721          "swid": {
256722            "attachment": {}
256723          },
256724          "pedigree": {},
256725          "evidence": {},
256726          "signature": {
256727            "signature": {
256728              "publicKey": {}
256729            }
256730          },
256731          "modelCard": {
256732            "modelParameters": {
256733              "approach": {}
256734            },
256735            "quantitativeAnalysis": {
256736              "graphics": {}
256737            },
256738            "considerations": {}
256739          }
256740        },
256741        {
256742          "type": "library",
256743          "bom-ref": "pkg:deb/debian/htop@3.0.5-7?arch=amd64\u0026distro=debian-11\u0026package-id=a453d84b1f10d0ac",
256744          "supplier": {},
256745          "publisher": "Daniel Lange \u003cDLange@debian.org\u003e",
256746          "name": "htop",
256747          "version": "3.0.5-7",
256748          "licenses": [
256749            {
256750              "license": {
256751                "id": "GPL-2.0-only"
256752              }
256753            },
256754            {
256755              "license": {
256756                "id": "GPL-2.0-or-later"
256757              }
256758            }
256759          ],
256760          "cpe": "cpe:2.3:a:htop:htop:3.0.5-7:*:*:*:*:*:*:*",
256761          "purl": "pkg:deb/debian/htop@3.0.5-7?arch=amd64\u0026distro=debian-11",
256762          "swid": {
256763            "attachment": {}
256764          },
256765          "pedigree": {},
256766          "evidence": {},
256767          "signature": {
256768            "signature": {
256769              "publicKey": {}
256770            }
256771          },
256772          "modelCard": {
256773            "modelParameters": {
256774              "approach": {}
256775            },
256776            "quantitativeAnalysis": {
256777              "graphics": {}
256778            },
256779            "considerations": {}
256780          }
256781        },
256782        {
256783          "type": "library",
256784          "bom-ref": "pkg:deb/debian/iftop@1.0~pre4-7?arch=amd64\u0026distro=debian-11\u0026package-id=69076acf974ed92b",
256785          "supplier": {},
256786          "publisher": "Markus Koschany \u003capo@debian.org\u003e",
256787          "name": "iftop",
256788          "version": "1.0~pre4-7",
256789          "licenses": [
256790            {
256791              "license": {
256792                "id": "BSD-2-Clause"
256793              }
256794            },
256795            {
256796              "license": {
256797                "id": "BSD-3-Clause"
256798              }
256799            },
256800            {
256801              "license": {
256802                "name": "BSD-like"
256803              }
256804            },
256805            {
256806              "license": {
256807                "id": "GPL-2.0-only"
256808              }
256809            },
256810            {
256811              "license": {
256812                "id": "GPL-2.0-or-later"
256813              }
256814            }
256815          ],
256816          "cpe": "cpe:2.3:a:iftop:iftop:1.0\\~pre4-7:*:*:*:*:*:*:*",
256817          "purl": "pkg:deb/debian/iftop@1.0~pre4-7?arch=amd64\u0026distro=debian-11",
256818          "swid": {
256819            "attachment": {}
256820          },
256821          "pedigree": {},
256822          "evidence": {},
256823          "signature": {
256824            "signature": {
256825              "publicKey": {}
256826            }
256827          },
256828          "modelCard": {
256829            "modelParameters": {
256830              "approach": {}
256831            },
256832            "quantitativeAnalysis": {
256833              "graphics": {}
256834            },
256835            "considerations": {}
256836          }
256837        },
256838        {
256839          "type": "library",
256840          "bom-ref": "pkg:deb/debian/init-system-helpers@1.60?arch=all\u0026distro=debian-11\u0026package-id=9853db6c4e48777f",
256841          "supplier": {},
256842          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
256843          "name": "init-system-helpers",
256844          "version": "1.60",
256845          "licenses": [
256846            {
256847              "license": {
256848                "id": "BSD-3-Clause"
256849              }
256850            },
256851            {
256852              "license": {
256853                "id": "GPL-2.0-only"
256854              }
256855            },
256856            {
256857              "license": {
256858                "id": "GPL-2.0-or-later"
256859              }
256860            }
256861          ],
256862          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.60:*:*:*:*:*:*:*",
256863          "purl": "pkg:deb/debian/init-system-helpers@1.60?arch=all\u0026distro=debian-11",
256864          "swid": {
256865            "attachment": {}
256866          },
256867          "pedigree": {},
256868          "evidence": {},
256869          "signature": {
256870            "signature": {
256871              "publicKey": {}
256872            }
256873          },
256874          "modelCard": {
256875            "modelParameters": {
256876              "approach": {}
256877            },
256878            "quantitativeAnalysis": {
256879              "graphics": {}
256880            },
256881            "considerations": {}
256882          }
256883        },
256884        {
256885          "type": "library",
256886          "bom-ref": "pkg:pypi/iotop@0.6?package-id=3d5ee3626c3c6617",
256887          "supplier": {},
256888          "author": "Guillaume Chazarain \u003cguichaz@gmail.com\u003e",
256889          "name": "iotop",
256890          "version": "0.6",
256891          "licenses": [
256892            {
256893              "license": {
256894                "name": "GPL"
256895              }
256896            }
256897          ],
256898          "cpe": "cpe:2.3:a:guillaume_chazarain_project:python-iotop:0.6:*:*:*:*:*:*:*",
256899          "purl": "pkg:pypi/iotop@0.6",
256900          "swid": {
256901            "attachment": {}
256902          },
256903          "pedigree": {},
256904          "evidence": {},
256905          "signature": {
256906            "signature": {
256907              "publicKey": {}
256908            }
256909          },
256910          "modelCard": {
256911            "modelParameters": {
256912              "approach": {}
256913            },
256914            "quantitativeAnalysis": {
256915              "graphics": {}
256916            },
256917            "considerations": {}
256918          }
256919        },
256920        {
256921          "type": "library",
256922          "bom-ref": "pkg:deb/debian/iotop@0.6-24-g733f3f8-1.1?arch=amd64\u0026distro=debian-11\u0026package-id=dfee60c7465df37e",
256923          "supplier": {},
256924          "publisher": "Paul Wise \u003cpabs@debian.org\u003e",
256925          "name": "iotop",
256926          "version": "0.6-24-g733f3f8-1.1",
256927          "licenses": [
256928            {
256929              "license": {
256930                "id": "GPL-2.0-only"
256931              }
256932            },
256933            {
256934              "license": {
256935                "id": "GPL-2.0-or-later"
256936              }
256937            }
256938          ],
256939          "cpe": "cpe:2.3:a:iotop:iotop:0.6-24-g733f3f8-1.1:*:*:*:*:*:*:*",
256940          "purl": "pkg:deb/debian/iotop@0.6-24-g733f3f8-1.1?arch=amd64\u0026distro=debian-11",
256941          "swid": {
256942            "attachment": {}
256943          },
256944          "pedigree": {},
256945          "evidence": {},
256946          "signature": {
256947            "signature": {
256948              "publicKey": {}
256949            }
256950          },
256951          "modelCard": {
256952            "modelParameters": {
256953              "approach": {}
256954            },
256955            "quantitativeAnalysis": {
256956              "graphics": {}
256957            },
256958            "considerations": {}
256959          }
256960        },
256961        {
256962          "type": "library",
256963          "bom-ref": "pkg:deb/debian/iperf@2.0.14a+dfsg1-1?arch=amd64\u0026distro=debian-11\u0026package-id=79f9d5ca79cfafb0",
256964          "supplier": {},
256965          "publisher": "Roberto Lumbreras \u003crover@debian.org\u003e",
256966          "name": "iperf",
256967          "version": "2.0.14a+dfsg1-1",
256968          "licenses": [
256969            {
256970              "license": {
256971                "id": "BSD-3-Clause"
256972              }
256973            },
256974            {
256975              "license": {
256976                "name": "FSF-something"
256977              }
256978            },
256979            {
256980              "license": {
256981                "id": "GPL-2.0-only"
256982              }
256983            },
256984            {
256985              "license": {
256986                "id": "GPL-2.0-or-later"
256987              }
256988            },
256989            {
256990              "license": {
256991                "name": "GPL-2-WithACException"
256992              }
256993            },
256994            {
256995              "license": {
256996                "id": "GPL-3.0-only"
256997              }
256998            },
256999            {
257000              "license": {
257001                "name": "GPL-3-WithACException"
257002              }
257003            },
257004            {
257005              "license": {
257006                "id": "ISC"
257007              }
257008            },
257009            {
257010              "license": {
257011                "id": "LGPL-2.0-only"
257012              }
257013            },
257014            {
257015              "license": {
257016                "id": "LGPL-2.0-or-later"
257017              }
257018            },
257019            {
257020              "license": {
257021                "id": "MIT"
257022              }
257023            }
257024          ],
257025          "cpe": "cpe:2.3:a:iperf:iperf:2.0.14a\\+dfsg1-1:*:*:*:*:*:*:*",
257026          "purl": "pkg:deb/debian/iperf@2.0.14a+dfsg1-1?arch=amd64\u0026distro=debian-11",
257027          "swid": {
257028            "attachment": {}
257029          },
257030          "pedigree": {},
257031          "evidence": {},
257032          "signature": {
257033            "signature": {
257034              "publicKey": {}
257035            }
257036          },
257037          "modelCard": {
257038            "modelParameters": {
257039              "approach": {}
257040            },
257041            "quantitativeAnalysis": {
257042              "graphics": {}
257043            },
257044            "considerations": {}
257045          }
257046        },
257047        {
257048          "type": "library",
257049          "bom-ref": "pkg:deb/debian/iputils-arping@3:20210202-1?arch=amd64\u0026upstream=iputils\u0026distro=debian-11\u0026package-id=1d68a57dae47d198",
257050          "supplier": {},
257051          "publisher": "Noah Meyerhans \u003cnoahm@debian.org\u003e",
257052          "name": "iputils-arping",
257053          "version": "3:20210202-1",
257054          "licenses": [
257055            {
257056              "license": {
257057                "name": "GPL"
257058              }
257059            }
257060          ],
257061          "cpe": "cpe:2.3:a:iputils-arping:iputils-arping:3\\:20210202-1:*:*:*:*:*:*:*",
257062          "purl": "pkg:deb/debian/iputils-arping@3:20210202-1?arch=amd64\u0026upstream=iputils\u0026distro=debian-11",
257063          "swid": {
257064            "attachment": {}
257065          },
257066          "pedigree": {},
257067          "evidence": {},
257068          "signature": {
257069            "signature": {
257070              "publicKey": {}
257071            }
257072          },
257073          "modelCard": {
257074            "modelParameters": {
257075              "approach": {}
257076            },
257077            "quantitativeAnalysis": {
257078              "graphics": {}
257079            },
257080            "considerations": {}
257081          }
257082        },
257083        {
257084          "type": "library",
257085          "bom-ref": "pkg:deb/debian/iputils-clockdiff@3:20210202-1?arch=amd64\u0026upstream=iputils\u0026distro=debian-11\u0026package-id=679c714f319c04cb",
257086          "supplier": {},
257087          "publisher": "Noah Meyerhans \u003cnoahm@debian.org\u003e",
257088          "name": "iputils-clockdiff",
257089          "version": "3:20210202-1",
257090          "licenses": [
257091            {
257092              "license": {
257093                "name": "GPL"
257094              }
257095            }
257096          ],
257097          "cpe": "cpe:2.3:a:iputils-clockdiff:iputils-clockdiff:3\\:20210202-1:*:*:*:*:*:*:*",
257098          "purl": "pkg:deb/debian/iputils-clockdiff@3:20210202-1?arch=amd64\u0026upstream=iputils\u0026distro=debian-11",
257099          "swid": {
257100            "attachment": {}
257101          },
257102          "pedigree": {},
257103          "evidence": {},
257104          "signature": {
257105            "signature": {
257106              "publicKey": {}
257107            }
257108          },
257109          "modelCard": {
257110            "modelParameters": {
257111              "approach": {}
257112            },
257113            "quantitativeAnalysis": {
257114              "graphics": {}
257115            },
257116            "considerations": {}
257117          }
257118        },
257119        {
257120          "type": "library",
257121          "bom-ref": "pkg:deb/debian/iputils-ping@3:20210202-1?arch=amd64\u0026upstream=iputils\u0026distro=debian-11\u0026package-id=6faf0749d49d1121",
257122          "supplier": {},
257123          "publisher": "Noah Meyerhans \u003cnoahm@debian.org\u003e",
257124          "name": "iputils-ping",
257125          "version": "3:20210202-1",
257126          "licenses": [
257127            {
257128              "license": {
257129                "name": "GPL"
257130              }
257131            }
257132          ],
257133          "cpe": "cpe:2.3:a:iputils-ping:iputils-ping:3\\:20210202-1:*:*:*:*:*:*:*",
257134          "purl": "pkg:deb/debian/iputils-ping@3:20210202-1?arch=amd64\u0026upstream=iputils\u0026distro=debian-11",
257135          "swid": {
257136            "attachment": {}
257137          },
257138          "pedigree": {},
257139          "evidence": {},
257140          "signature": {
257141            "signature": {
257142              "publicKey": {}
257143            }
257144          },
257145          "modelCard": {
257146            "modelParameters": {
257147              "approach": {}
257148            },
257149            "quantitativeAnalysis": {
257150              "graphics": {}
257151            },
257152            "considerations": {}
257153          }
257154        },
257155        {
257156          "type": "library",
257157          "bom-ref": "pkg:deb/debian/iputils-tracepath@3:20210202-1?arch=amd64\u0026upstream=iputils\u0026distro=debian-11\u0026package-id=81cf5e85c67e6623",
257158          "supplier": {},
257159          "publisher": "Noah Meyerhans \u003cnoahm@debian.org\u003e",
257160          "name": "iputils-tracepath",
257161          "version": "3:20210202-1",
257162          "licenses": [
257163            {
257164              "license": {
257165                "name": "GPL"
257166              }
257167            }
257168          ],
257169          "cpe": "cpe:2.3:a:iputils-tracepath:iputils-tracepath:3\\:20210202-1:*:*:*:*:*:*:*",
257170          "purl": "pkg:deb/debian/iputils-tracepath@3:20210202-1?arch=amd64\u0026upstream=iputils\u0026distro=debian-11",
257171          "swid": {
257172            "attachment": {}
257173          },
257174          "pedigree": {},
257175          "evidence": {},
257176          "signature": {
257177            "signature": {
257178              "publicKey": {}
257179            }
257180          },
257181          "modelCard": {
257182            "modelParameters": {
257183              "approach": {}
257184            },
257185            "quantitativeAnalysis": {
257186              "graphics": {}
257187            },
257188            "considerations": {}
257189          }
257190        },
257191        {
257192          "type": "library",
257193          "bom-ref": "pkg:deb/debian/jq@1.6-2.1?arch=amd64\u0026distro=debian-11\u0026package-id=e3f3c6b4cef4fa4b",
257194          "supplier": {},
257195          "publisher": "ChangZhuo Chen (陳昌倬) \u003cczchen@debian.org\u003e",
257196          "name": "jq",
257197          "version": "1.6-2.1",
257198          "licenses": [
257199            {
257200              "license": {
257201                "id": "CC-BY-3.0"
257202              }
257203            },
257204            {
257205              "license": {
257206                "name": "Expat"
257207              }
257208            },
257209            {
257210              "license": {
257211                "id": "GPL-2.0-only"
257212              }
257213            },
257214            {
257215              "license": {
257216                "id": "GPL-2.0-or-later"
257217              }
257218            },
257219            {
257220              "license": {
257221                "id": "MIT"
257222              }
257223            }
257224          ],
257225          "cpe": "cpe:2.3:a:jq:jq:1.6-2.1:*:*:*:*:*:*:*",
257226          "purl": "pkg:deb/debian/jq@1.6-2.1?arch=amd64\u0026distro=debian-11",
257227          "swid": {
257228            "attachment": {}
257229          },
257230          "pedigree": {},
257231          "evidence": {},
257232          "signature": {
257233            "signature": {
257234              "publicKey": {}
257235            }
257236          },
257237          "modelCard": {
257238            "modelParameters": {
257239              "approach": {}
257240            },
257241            "quantitativeAnalysis": {
257242              "graphics": {}
257243            },
257244            "considerations": {}
257245          }
257246        },
257247        {
257248          "type": "library",
257249          "bom-ref": "pkg:deb/debian/libacl1@2.2.53-10?arch=amd64\u0026upstream=acl\u0026distro=debian-11\u0026package-id=e26fd10cf6ff246",
257250          "supplier": {},
257251          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
257252          "name": "libacl1",
257253          "version": "2.2.53-10",
257254          "licenses": [
257255            {
257256              "license": {
257257                "id": "GPL-2.0-only"
257258              }
257259            },
257260            {
257261              "license": {
257262                "id": "GPL-2.0-or-later"
257263              }
257264            },
257265            {
257266              "license": {
257267                "id": "LGPL-2.0-or-later"
257268              }
257269            },
257270            {
257271              "license": {
257272                "id": "LGPL-2.1-only"
257273              }
257274            }
257275          ],
257276          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-10:*:*:*:*:*:*:*",
257277          "purl": "pkg:deb/debian/libacl1@2.2.53-10?arch=amd64\u0026upstream=acl\u0026distro=debian-11",
257278          "swid": {
257279            "attachment": {}
257280          },
257281          "pedigree": {},
257282          "evidence": {},
257283          "signature": {
257284            "signature": {
257285              "publicKey": {}
257286            }
257287          },
257288          "modelCard": {
257289            "modelParameters": {
257290              "approach": {}
257291            },
257292            "quantitativeAnalysis": {
257293              "graphics": {}
257294            },
257295            "considerations": {}
257296          }
257297        },
257298        {
257299          "type": "library",
257300          "bom-ref": "pkg:deb/debian/libapt-pkg6.0@2.2.4?arch=amd64\u0026upstream=apt\u0026distro=debian-11\u0026package-id=da442f0998cccf2b",
257301          "supplier": {},
257302          "publisher": "APT Development Team \u003cdeity@lists.debian.org\u003e",
257303          "name": "libapt-pkg6.0",
257304          "version": "2.2.4",
257305          "licenses": [
257306            {
257307              "license": {
257308                "id": "GPL-2.0-only"
257309              }
257310            },
257311            {
257312              "license": {
257313                "name": "GPLv2+"
257314              }
257315            }
257316          ],
257317          "cpe": "cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.2.4:*:*:*:*:*:*:*",
257318          "purl": "pkg:deb/debian/libapt-pkg6.0@2.2.4?arch=amd64\u0026upstream=apt\u0026distro=debian-11",
257319          "swid": {
257320            "attachment": {}
257321          },
257322          "pedigree": {},
257323          "evidence": {},
257324          "signature": {
257325            "signature": {
257326              "publicKey": {}
257327            }
257328          },
257329          "modelCard": {
257330            "modelParameters": {
257331              "approach": {}
257332            },
257333            "quantitativeAnalysis": {
257334              "graphics": {}
257335            },
257336            "considerations": {}
257337          }
257338        },
257339        {
257340          "type": "library",
257341          "bom-ref": "pkg:deb/debian/libasan6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=7b2bbb7b9367d33b",
257342          "supplier": {},
257343          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
257344          "name": "libasan6",
257345          "version": "10.2.1-6",
257346          "licenses": [
257347            {
257348              "license": {
257349                "name": "Artistic"
257350              }
257351            },
257352            {
257353              "license": {
257354                "id": "GFDL-1.2-only"
257355              }
257356            },
257357            {
257358              "license": {
257359                "name": "GPL"
257360              }
257361            },
257362            {
257363              "license": {
257364                "id": "GPL-2.0-only"
257365              }
257366            },
257367            {
257368              "license": {
257369                "id": "GPL-3.0-only"
257370              }
257371            },
257372            {
257373              "license": {
257374                "name": "LGPL"
257375              }
257376            }
257377          ],
257378          "cpe": "cpe:2.3:a:libasan6:libasan6:10.2.1-6:*:*:*:*:*:*:*",
257379          "purl": "pkg:deb/debian/libasan6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
257380          "swid": {
257381            "attachment": {}
257382          },
257383          "pedigree": {},
257384          "evidence": {},
257385          "signature": {
257386            "signature": {
257387              "publicKey": {}
257388            }
257389          },
257390          "modelCard": {
257391            "modelParameters": {
257392              "approach": {}
257393            },
257394            "quantitativeAnalysis": {
257395              "graphics": {}
257396            },
257397            "considerations": {}
257398          }
257399        },
257400        {
257401          "type": "library",
257402          "bom-ref": "pkg:deb/debian/libatk1.0-0@2.36.0-2?arch=amd64\u0026upstream=atk1.0\u0026distro=debian-11\u0026package-id=29be3deb7a055b39",
257403          "supplier": {},
257404          "publisher": "Debian Accessibility Team \u003cpkg-a11y-devel@lists.alioth.debian.org\u003e",
257405          "name": "libatk1.0-0",
257406          "version": "2.36.0-2",
257407          "licenses": [
257408            {
257409              "license": {
257410                "id": "LGPL-2.0-only"
257411              }
257412            }
257413          ],
257414          "cpe": "cpe:2.3:a:libatk1.0-0:libatk1.0-0:2.36.0-2:*:*:*:*:*:*:*",
257415          "purl": "pkg:deb/debian/libatk1.0-0@2.36.0-2?arch=amd64\u0026upstream=atk1.0\u0026distro=debian-11",
257416          "swid": {
257417            "attachment": {}
257418          },
257419          "pedigree": {},
257420          "evidence": {},
257421          "signature": {
257422            "signature": {
257423              "publicKey": {}
257424            }
257425          },
257426          "modelCard": {
257427            "modelParameters": {
257428              "approach": {}
257429            },
257430            "quantitativeAnalysis": {
257431              "graphics": {}
257432            },
257433            "considerations": {}
257434          }
257435        },
257436        {
257437          "type": "library",
257438          "bom-ref": "pkg:deb/debian/libatk1.0-data@2.36.0-2?arch=all\u0026upstream=atk1.0\u0026distro=debian-11\u0026package-id=8e0f51bd2ccb2ded",
257439          "supplier": {},
257440          "publisher": "Debian Accessibility Team \u003cpkg-a11y-devel@lists.alioth.debian.org\u003e",
257441          "name": "libatk1.0-data",
257442          "version": "2.36.0-2",
257443          "licenses": [
257444            {
257445              "license": {
257446                "id": "LGPL-2.0-only"
257447              }
257448            }
257449          ],
257450          "cpe": "cpe:2.3:a:libatk1.0-data:libatk1.0-data:2.36.0-2:*:*:*:*:*:*:*",
257451          "purl": "pkg:deb/debian/libatk1.0-data@2.36.0-2?arch=all\u0026upstream=atk1.0\u0026distro=debian-11",
257452          "swid": {
257453            "attachment": {}
257454          },
257455          "pedigree": {},
257456          "evidence": {},
257457          "signature": {
257458            "signature": {
257459              "publicKey": {}
257460            }
257461          },
257462          "modelCard": {
257463            "modelParameters": {
257464              "approach": {}
257465            },
257466            "quantitativeAnalysis": {
257467              "graphics": {}
257468            },
257469            "considerations": {}
257470          }
257471        },
257472        {
257473          "type": "library",
257474          "bom-ref": "pkg:deb/debian/libatomic1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=3cc56d6c19b5e9ee",
257475          "supplier": {},
257476          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
257477          "name": "libatomic1",
257478          "version": "10.2.1-6",
257479          "licenses": [
257480            {
257481              "license": {
257482                "name": "Artistic"
257483              }
257484            },
257485            {
257486              "license": {
257487                "id": "GFDL-1.2-only"
257488              }
257489            },
257490            {
257491              "license": {
257492                "name": "GPL"
257493              }
257494            },
257495            {
257496              "license": {
257497                "id": "GPL-2.0-only"
257498              }
257499            },
257500            {
257501              "license": {
257502                "id": "GPL-3.0-only"
257503              }
257504            },
257505            {
257506              "license": {
257507                "name": "LGPL"
257508              }
257509            }
257510          ],
257511          "cpe": "cpe:2.3:a:libatomic1:libatomic1:10.2.1-6:*:*:*:*:*:*:*",
257512          "purl": "pkg:deb/debian/libatomic1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
257513          "swid": {
257514            "attachment": {}
257515          },
257516          "pedigree": {},
257517          "evidence": {},
257518          "signature": {
257519            "signature": {
257520              "publicKey": {}
257521            }
257522          },
257523          "modelCard": {
257524            "modelParameters": {
257525              "approach": {}
257526            },
257527            "quantitativeAnalysis": {
257528              "graphics": {}
257529            },
257530            "considerations": {}
257531          }
257532        },
257533        {
257534          "type": "library",
257535          "bom-ref": "pkg:deb/debian/libattr1@1:2.4.48-6?arch=amd64\u0026upstream=attr\u0026distro=debian-11\u0026package-id=254a97dd16e20391",
257536          "supplier": {},
257537          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
257538          "name": "libattr1",
257539          "version": "1:2.4.48-6",
257540          "licenses": [
257541            {
257542              "license": {
257543                "id": "GPL-2.0-only"
257544              }
257545            },
257546            {
257547              "license": {
257548                "id": "GPL-2.0-or-later"
257549              }
257550            },
257551            {
257552              "license": {
257553                "id": "LGPL-2.0-or-later"
257554              }
257555            },
257556            {
257557              "license": {
257558                "id": "LGPL-2.1-only"
257559              }
257560            }
257561          ],
257562          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-6:*:*:*:*:*:*:*",
257563          "purl": "pkg:deb/debian/libattr1@1:2.4.48-6?arch=amd64\u0026upstream=attr\u0026distro=debian-11",
257564          "swid": {
257565            "attachment": {}
257566          },
257567          "pedigree": {},
257568          "evidence": {},
257569          "signature": {
257570            "signature": {
257571              "publicKey": {}
257572            }
257573          },
257574          "modelCard": {
257575            "modelParameters": {
257576              "approach": {}
257577            },
257578            "quantitativeAnalysis": {
257579              "graphics": {}
257580            },
257581            "considerations": {}
257582          }
257583        },
257584        {
257585          "type": "library",
257586          "bom-ref": "pkg:deb/debian/libaudit-common@1:3.0-2?arch=all\u0026upstream=audit\u0026distro=debian-11\u0026package-id=e666dc18886f28ff",
257587          "supplier": {},
257588          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
257589          "name": "libaudit-common",
257590          "version": "1:3.0-2",
257591          "licenses": [
257592            {
257593              "license": {
257594                "id": "GPL-1.0-only"
257595              }
257596            },
257597            {
257598              "license": {
257599                "id": "GPL-2.0-only"
257600              }
257601            },
257602            {
257603              "license": {
257604                "id": "LGPL-2.1-only"
257605              }
257606            }
257607          ],
257608          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:3.0-2:*:*:*:*:*:*:*",
257609          "purl": "pkg:deb/debian/libaudit-common@1:3.0-2?arch=all\u0026upstream=audit\u0026distro=debian-11",
257610          "swid": {
257611            "attachment": {}
257612          },
257613          "pedigree": {},
257614          "evidence": {},
257615          "signature": {
257616            "signature": {
257617              "publicKey": {}
257618            }
257619          },
257620          "modelCard": {
257621            "modelParameters": {
257622              "approach": {}
257623            },
257624            "quantitativeAnalysis": {
257625              "graphics": {}
257626            },
257627            "considerations": {}
257628          }
257629        },
257630        {
257631          "type": "library",
257632          "bom-ref": "pkg:deb/debian/libaudit1@1:3.0-2?arch=amd64\u0026upstream=audit\u0026distro=debian-11\u0026package-id=ae77fe6c43b7188d",
257633          "supplier": {},
257634          "publisher": "Laurent Bigonville \u003cbigon@debian.org\u003e",
257635          "name": "libaudit1",
257636          "version": "1:3.0-2",
257637          "licenses": [
257638            {
257639              "license": {
257640                "id": "GPL-1.0-only"
257641              }
257642            },
257643            {
257644              "license": {
257645                "id": "GPL-2.0-only"
257646              }
257647            },
257648            {
257649              "license": {
257650                "id": "LGPL-2.1-only"
257651              }
257652            }
257653          ],
257654          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:3.0-2:*:*:*:*:*:*:*",
257655          "purl": "pkg:deb/debian/libaudit1@1:3.0-2?arch=amd64\u0026upstream=audit\u0026distro=debian-11",
257656          "swid": {
257657            "attachment": {}
257658          },
257659          "pedigree": {},
257660          "evidence": {},
257661          "signature": {
257662            "signature": {
257663              "publicKey": {}
257664            }
257665          },
257666          "modelCard": {
257667            "modelParameters": {
257668              "approach": {}
257669            },
257670            "quantitativeAnalysis": {
257671              "graphics": {}
257672            },
257673            "considerations": {}
257674          }
257675        },
257676        {
257677          "type": "library",
257678          "bom-ref": "pkg:deb/debian/libavahi-client3@0.8-5+deb11u1?arch=amd64\u0026upstream=avahi\u0026distro=debian-11\u0026package-id=6b5e18bf7ed72322",
257679          "supplier": {},
257680          "publisher": "Utopia Maintenance Team \u003cpkg-utopia-maintainers@lists.alioth.debian.org\u003e",
257681          "name": "libavahi-client3",
257682          "version": "0.8-5+deb11u1",
257683          "licenses": [
257684            {
257685              "license": {
257686                "name": "GPL"
257687              }
257688            },
257689            {
257690              "license": {
257691                "id": "GPL-2.0-only"
257692              }
257693            },
257694            {
257695              "license": {
257696                "id": "LGPL-2.1-only"
257697              }
257698            }
257699          ],
257700          "cpe": "cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-5\\+deb11u1:*:*:*:*:*:*:*",
257701          "purl": "pkg:deb/debian/libavahi-client3@0.8-5+deb11u1?arch=amd64\u0026upstream=avahi\u0026distro=debian-11",
257702          "swid": {
257703            "attachment": {}
257704          },
257705          "pedigree": {},
257706          "evidence": {},
257707          "signature": {
257708            "signature": {
257709              "publicKey": {}
257710            }
257711          },
257712          "modelCard": {
257713            "modelParameters": {
257714              "approach": {}
257715            },
257716            "quantitativeAnalysis": {
257717              "graphics": {}
257718            },
257719            "considerations": {}
257720          }
257721        },
257722        {
257723          "type": "library",
257724          "bom-ref": "pkg:deb/debian/libavahi-common-data@0.8-5+deb11u1?arch=amd64\u0026upstream=avahi\u0026distro=debian-11\u0026package-id=d37e1fbe59a6768d",
257725          "supplier": {},
257726          "publisher": "Utopia Maintenance Team \u003cpkg-utopia-maintainers@lists.alioth.debian.org\u003e",
257727          "name": "libavahi-common-data",
257728          "version": "0.8-5+deb11u1",
257729          "licenses": [
257730            {
257731              "license": {
257732                "name": "GPL"
257733              }
257734            },
257735            {
257736              "license": {
257737                "id": "GPL-2.0-only"
257738              }
257739            },
257740            {
257741              "license": {
257742                "id": "LGPL-2.1-only"
257743              }
257744            }
257745          ],
257746          "cpe": "cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-5\\+deb11u1:*:*:*:*:*:*:*",
257747          "purl": "pkg:deb/debian/libavahi-common-data@0.8-5+deb11u1?arch=amd64\u0026upstream=avahi\u0026distro=debian-11",
257748          "swid": {
257749            "attachment": {}
257750          },
257751          "pedigree": {},
257752          "evidence": {},
257753          "signature": {
257754            "signature": {
257755              "publicKey": {}
257756            }
257757          },
257758          "modelCard": {
257759            "modelParameters": {
257760              "approach": {}
257761            },
257762            "quantitativeAnalysis": {
257763              "graphics": {}
257764            },
257765            "considerations": {}
257766          }
257767        },
257768        {
257769          "type": "library",
257770          "bom-ref": "pkg:deb/debian/libavahi-common3@0.8-5+deb11u1?arch=amd64\u0026upstream=avahi\u0026distro=debian-11\u0026package-id=8e732ab2d4aef5ce",
257771          "supplier": {},
257772          "publisher": "Utopia Maintenance Team \u003cpkg-utopia-maintainers@lists.alioth.debian.org\u003e",
257773          "name": "libavahi-common3",
257774          "version": "0.8-5+deb11u1",
257775          "licenses": [
257776            {
257777              "license": {
257778                "name": "GPL"
257779              }
257780            },
257781            {
257782              "license": {
257783                "id": "GPL-2.0-only"
257784              }
257785            },
257786            {
257787              "license": {
257788                "id": "LGPL-2.1-only"
257789              }
257790            }
257791          ],
257792          "cpe": "cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-5\\+deb11u1:*:*:*:*:*:*:*",
257793          "purl": "pkg:deb/debian/libavahi-common3@0.8-5+deb11u1?arch=amd64\u0026upstream=avahi\u0026distro=debian-11",
257794          "swid": {
257795            "attachment": {}
257796          },
257797          "pedigree": {},
257798          "evidence": {},
257799          "signature": {
257800            "signature": {
257801              "publicKey": {}
257802            }
257803          },
257804          "modelCard": {
257805            "modelParameters": {
257806              "approach": {}
257807            },
257808            "quantitativeAnalysis": {
257809              "graphics": {}
257810            },
257811            "considerations": {}
257812          }
257813        },
257814        {
257815          "type": "library",
257816          "bom-ref": "pkg:deb/debian/libbabeltrace1@1.5.8-1+b3?arch=amd64\u0026upstream=babeltrace%401.5.8-1\u0026distro=debian-11\u0026package-id=c606b237b63fe870",
257817          "supplier": {},
257818          "publisher": "Jon Bernard \u003cjbernard@debian.org\u003e",
257819          "name": "libbabeltrace1",
257820          "version": "1.5.8-1+b3",
257821          "licenses": [
257822            {
257823              "license": {
257824                "id": "GPL-2.0-only"
257825              }
257826            },
257827            {
257828              "license": {
257829                "id": "GPL-3.0-only"
257830              }
257831            },
257832            {
257833              "license": {
257834                "id": "GPL-3.0-or-later"
257835              }
257836            },
257837            {
257838              "license": {
257839                "id": "LGPL-2.1-only"
257840              }
257841            },
257842            {
257843              "license": {
257844                "id": "MIT"
257845              }
257846            }
257847          ],
257848          "cpe": "cpe:2.3:a:libbabeltrace1:libbabeltrace1:1.5.8-1\\+b3:*:*:*:*:*:*:*",
257849          "purl": "pkg:deb/debian/libbabeltrace1@1.5.8-1+b3?arch=amd64\u0026upstream=babeltrace%401.5.8-1\u0026distro=debian-11",
257850          "swid": {
257851            "attachment": {}
257852          },
257853          "pedigree": {},
257854          "evidence": {},
257855          "signature": {
257856            "signature": {
257857              "publicKey": {}
257858            }
257859          },
257860          "modelCard": {
257861            "modelParameters": {
257862              "approach": {}
257863            },
257864            "quantitativeAnalysis": {
257865              "graphics": {}
257866            },
257867            "considerations": {}
257868          }
257869        },
257870        {
257871          "type": "library",
257872          "bom-ref": "pkg:deb/debian/libbinutils@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11\u0026package-id=d2b9a8a8509edd7f",
257873          "supplier": {},
257874          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
257875          "name": "libbinutils",
257876          "version": "2.35.2-2",
257877          "licenses": [
257878            {
257879              "license": {
257880                "name": "GFDL"
257881              }
257882            },
257883            {
257884              "license": {
257885                "name": "GPL"
257886              }
257887            },
257888            {
257889              "license": {
257890                "name": "LGPL"
257891              }
257892            }
257893          ],
257894          "cpe": "cpe:2.3:a:libbinutils:libbinutils:2.35.2-2:*:*:*:*:*:*:*",
257895          "purl": "pkg:deb/debian/libbinutils@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11",
257896          "swid": {
257897            "attachment": {}
257898          },
257899          "pedigree": {},
257900          "evidence": {},
257901          "signature": {
257902            "signature": {
257903              "publicKey": {}
257904            }
257905          },
257906          "modelCard": {
257907            "modelParameters": {
257908              "approach": {}
257909            },
257910            "quantitativeAnalysis": {
257911              "graphics": {}
257912            },
257913            "considerations": {}
257914          }
257915        },
257916        {
257917          "type": "library",
257918          "bom-ref": "pkg:deb/debian/libblas3@3.9.0-3?arch=amd64\u0026upstream=lapack\u0026distro=debian-11\u0026package-id=d66a0658bd3f26ae",
257919          "supplier": {},
257920          "publisher": "Debian Science Team \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e",
257921          "name": "libblas3",
257922          "version": "3.9.0-3",
257923          "licenses": [
257924            {
257925              "license": {
257926                "id": "BSD-3-Clause"
257927              }
257928            },
257929            {
257930              "license": {
257931                "name": "BSD-3-clause-intel"
257932              }
257933            }
257934          ],
257935          "cpe": "cpe:2.3:a:libblas3:libblas3:3.9.0-3:*:*:*:*:*:*:*",
257936          "purl": "pkg:deb/debian/libblas3@3.9.0-3?arch=amd64\u0026upstream=lapack\u0026distro=debian-11",
257937          "swid": {
257938            "attachment": {}
257939          },
257940          "pedigree": {},
257941          "evidence": {},
257942          "signature": {
257943            "signature": {
257944              "publicKey": {}
257945            }
257946          },
257947          "modelCard": {
257948            "modelParameters": {
257949              "approach": {}
257950            },
257951            "quantitativeAnalysis": {
257952              "graphics": {}
257953            },
257954            "considerations": {}
257955          }
257956        },
257957        {
257958          "type": "library",
257959          "bom-ref": "pkg:deb/debian/libblkid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=f235c9c5cb7b4190",
257960          "supplier": {},
257961          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
257962          "name": "libblkid1",
257963          "version": "2.36.1-8+deb11u1",
257964          "licenses": [
257965            {
257966              "license": {
257967                "id": "BSD-2-Clause"
257968              }
257969            },
257970            {
257971              "license": {
257972                "id": "BSD-3-Clause"
257973              }
257974            },
257975            {
257976              "license": {
257977                "id": "BSD-4-Clause"
257978              }
257979            },
257980            {
257981              "license": {
257982                "id": "GPL-2.0-only"
257983              }
257984            },
257985            {
257986              "license": {
257987                "id": "GPL-2.0-or-later"
257988              }
257989            },
257990            {
257991              "license": {
257992                "id": "GPL-3.0-only"
257993              }
257994            },
257995            {
257996              "license": {
257997                "id": "GPL-3.0-or-later"
257998              }
257999            },
258000            {
258001              "license": {
258002                "name": "LGPL"
258003              }
258004            },
258005            {
258006              "license": {
258007                "id": "LGPL-2.0-only"
258008              }
258009            },
258010            {
258011              "license": {
258012                "id": "LGPL-2.0-or-later"
258013              }
258014            },
258015            {
258016              "license": {
258017                "id": "LGPL-2.1-only"
258018              }
258019            },
258020            {
258021              "license": {
258022                "id": "LGPL-2.1-or-later"
258023              }
258024            },
258025            {
258026              "license": {
258027                "id": "LGPL-3.0-only"
258028              }
258029            },
258030            {
258031              "license": {
258032                "id": "LGPL-3.0-or-later"
258033              }
258034            },
258035            {
258036              "license": {
258037                "id": "MIT"
258038              }
258039            },
258040            {
258041              "license": {
258042                "name": "public-domain"
258043              }
258044            }
258045          ],
258046          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
258047          "purl": "pkg:deb/debian/libblkid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
258048          "swid": {
258049            "attachment": {}
258050          },
258051          "pedigree": {},
258052          "evidence": {},
258053          "signature": {
258054            "signature": {
258055              "publicKey": {}
258056            }
258057          },
258058          "modelCard": {
258059            "modelParameters": {
258060              "approach": {}
258061            },
258062            "quantitativeAnalysis": {
258063              "graphics": {}
258064            },
258065            "considerations": {}
258066          }
258067        },
258068        {
258069          "type": "library",
258070          "bom-ref": "pkg:deb/debian/libboost-regex1.74.0@1.74.0-9?arch=amd64\u0026upstream=boost1.74\u0026distro=debian-11\u0026package-id=bcdeea51cd7769e2",
258071          "supplier": {},
258072          "publisher": "Debian Boost Team \u003cteam+boost@tracker.debian.org\u003e",
258073          "name": "libboost-regex1.74.0",
258074          "version": "1.74.0-9",
258075          "licenses": [
258076            {
258077              "license": {
258078                "id": "Apache-2.0"
258079              }
258080            },
258081            {
258082              "license": {
258083                "name": "BSD2"
258084              }
258085            },
258086            {
258087              "license": {
258088                "name": "BSD3_DEShaw"
258089              }
258090            },
258091            {
258092              "license": {
258093                "name": "BSD3_Google"
258094              }
258095            },
258096            {
258097              "license": {
258098                "id": "BSL-1.0"
258099              }
258100            },
258101            {
258102              "license": {
258103                "name": "Caramel"
258104              }
258105            },
258106            {
258107              "license": {
258108                "name": "CrystalClear"
258109              }
258110            },
258111            {
258112              "license": {
258113                "name": "HP"
258114              }
258115            },
258116            {
258117              "license": {
258118                "id": "Jam"
258119              }
258120            },
258121            {
258122              "license": {
258123                "name": "Kempf"
258124              }
258125            },
258126            {
258127              "license": {
258128                "id": "MIT"
258129              }
258130            },
258131            {
258132              "license": {
258133                "name": "NIST"
258134              }
258135            },
258136            {
258137              "license": {
258138                "name": "OldBoost1"
258139              }
258140            },
258141            {
258142              "license": {
258143                "name": "OldBoost2"
258144              }
258145            },
258146            {
258147              "license": {
258148                "name": "OldBoost3"
258149              }
258150            },
258151            {
258152              "license": {
258153                "name": "Python"
258154              }
258155            },
258156            {
258157              "license": {
258158                "name": "SGI"
258159              }
258160            },
258161            {
258162              "license": {
258163                "name": "Spencer"
258164              }
258165            },
258166            {
258167              "license": {
258168                "id": "Zlib"
258169              }
258170            }
258171          ],
258172          "cpe": "cpe:2.3:a:libboost-regex1.74.0:libboost-regex1.74.0:1.74.0-9:*:*:*:*:*:*:*",
258173          "purl": "pkg:deb/debian/libboost-regex1.74.0@1.74.0-9?arch=amd64\u0026upstream=boost1.74\u0026distro=debian-11",
258174          "swid": {
258175            "attachment": {}
258176          },
258177          "pedigree": {},
258178          "evidence": {},
258179          "signature": {
258180            "signature": {
258181              "publicKey": {}
258182            }
258183          },
258184          "modelCard": {
258185            "modelParameters": {
258186              "approach": {}
258187            },
258188            "quantitativeAnalysis": {
258189              "graphics": {}
258190            },
258191            "considerations": {}
258192          }
258193        },
258194        {
258195          "type": "library",
258196          "bom-ref": "pkg:deb/debian/libbrotli1@1.0.9-2+b2?arch=amd64\u0026upstream=brotli%401.0.9-2\u0026distro=debian-11\u0026package-id=56558463e048d713",
258197          "supplier": {},
258198          "publisher": "Tomasz Buchert \u003ctomasz@debian.org\u003e",
258199          "name": "libbrotli1",
258200          "version": "1.0.9-2+b2",
258201          "licenses": [
258202            {
258203              "license": {
258204                "id": "MIT"
258205              }
258206            }
258207          ],
258208          "cpe": "cpe:2.3:a:libbrotli1:libbrotli1:1.0.9-2\\+b2:*:*:*:*:*:*:*",
258209          "purl": "pkg:deb/debian/libbrotli1@1.0.9-2+b2?arch=amd64\u0026upstream=brotli%401.0.9-2\u0026distro=debian-11",
258210          "swid": {
258211            "attachment": {}
258212          },
258213          "pedigree": {},
258214          "evidence": {},
258215          "signature": {
258216            "signature": {
258217              "publicKey": {}
258218            }
258219          },
258220          "modelCard": {
258221            "modelParameters": {
258222              "approach": {}
258223            },
258224            "quantitativeAnalysis": {
258225              "graphics": {}
258226            },
258227            "considerations": {}
258228          }
258229        },
258230        {
258231          "type": "library",
258232          "bom-ref": "pkg:deb/debian/libbsd0@0.11.3-1?arch=amd64\u0026upstream=libbsd\u0026distro=debian-11\u0026package-id=19b310b25a33fc08",
258233          "supplier": {},
258234          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
258235          "name": "libbsd0",
258236          "version": "0.11.3-1",
258237          "licenses": [
258238            {
258239              "license": {
258240                "id": "BSD-2-Clause"
258241              }
258242            },
258243            {
258244              "license": {
258245                "id": "BSD-2-Clause"
258246              }
258247            },
258248            {
258249              "license": {
258250                "name": "BSD-2-clause-author"
258251              }
258252            },
258253            {
258254              "license": {
258255                "name": "BSD-2-clause-verbatim"
258256              }
258257            },
258258            {
258259              "license": {
258260                "id": "BSD-3-Clause"
258261              }
258262            },
258263            {
258264              "license": {
258265                "name": "BSD-3-clause-John-Birrell"
258266              }
258267            },
258268            {
258269              "license": {
258270                "name": "BSD-3-clause-Regents"
258271              }
258272            },
258273            {
258274              "license": {
258275                "name": "BSD-3-clause-author"
258276              }
258277            },
258278            {
258279              "license": {
258280                "name": "BSD-4-clause-Christopher-G-Demetriou"
258281              }
258282            },
258283            {
258284              "license": {
258285                "name": "BSD-4-clause-Niels-Provos"
258286              }
258287            },
258288            {
258289              "license": {
258290                "name": "BSD-5-clause-Peter-Wemm"
258291              }
258292            },
258293            {
258294              "license": {
258295                "id": "Beerware"
258296              }
258297            },
258298            {
258299              "license": {
258300                "name": "Expat"
258301              }
258302            },
258303            {
258304              "license": {
258305                "id": "ISC"
258306              }
258307            },
258308            {
258309              "license": {
258310                "name": "ISC-Original"
258311              }
258312            },
258313            {
258314              "license": {
258315                "name": "public-domain"
258316              }
258317            }
258318          ],
258319          "cpe": "cpe:2.3:a:libbsd0:libbsd0:0.11.3-1:*:*:*:*:*:*:*",
258320          "purl": "pkg:deb/debian/libbsd0@0.11.3-1?arch=amd64\u0026upstream=libbsd\u0026distro=debian-11",
258321          "swid": {
258322            "attachment": {}
258323          },
258324          "pedigree": {},
258325          "evidence": {},
258326          "signature": {
258327            "signature": {
258328              "publicKey": {}
258329            }
258330          },
258331          "modelCard": {
258332            "modelParameters": {
258333              "approach": {}
258334            },
258335            "quantitativeAnalysis": {
258336              "graphics": {}
258337            },
258338            "considerations": {}
258339          }
258340        },
258341        {
258342          "type": "library",
258343          "bom-ref": "pkg:deb/debian/libbz2-1.0@1.0.8-4?arch=amd64\u0026upstream=bzip2\u0026distro=debian-11\u0026package-id=120fe415369d1784",
258344          "supplier": {},
258345          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
258346          "name": "libbz2-1.0",
258347          "version": "1.0.8-4",
258348          "licenses": [
258349            {
258350              "license": {
258351                "name": "BSD-variant"
258352              }
258353            },
258354            {
258355              "license": {
258356                "id": "GPL-2.0-only"
258357              }
258358            }
258359          ],
258360          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-4:*:*:*:*:*:*:*",
258361          "purl": "pkg:deb/debian/libbz2-1.0@1.0.8-4?arch=amd64\u0026upstream=bzip2\u0026distro=debian-11",
258362          "swid": {
258363            "attachment": {}
258364          },
258365          "pedigree": {},
258366          "evidence": {},
258367          "signature": {
258368            "signature": {
258369              "publicKey": {}
258370            }
258371          },
258372          "modelCard": {
258373            "modelParameters": {
258374              "approach": {}
258375            },
258376            "quantitativeAnalysis": {
258377              "graphics": {}
258378            },
258379            "considerations": {}
258380          }
258381        },
258382        {
258383          "type": "library",
258384          "bom-ref": "pkg:deb/debian/libc-bin@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=228ff11572a24b74",
258385          "supplier": {},
258386          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
258387          "name": "libc-bin",
258388          "version": "2.31-13+deb11u5",
258389          "licenses": [
258390            {
258391              "license": {
258392                "id": "GPL-2.0-only"
258393              }
258394            },
258395            {
258396              "license": {
258397                "id": "LGPL-2.1-only"
258398              }
258399            }
258400          ],
258401          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
258402          "purl": "pkg:deb/debian/libc-bin@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
258403          "swid": {
258404            "attachment": {}
258405          },
258406          "pedigree": {},
258407          "evidence": {},
258408          "signature": {
258409            "signature": {
258410              "publicKey": {}
258411            }
258412          },
258413          "modelCard": {
258414            "modelParameters": {
258415              "approach": {}
258416            },
258417            "quantitativeAnalysis": {
258418              "graphics": {}
258419            },
258420            "considerations": {}
258421          }
258422        },
258423        {
258424          "type": "library",
258425          "bom-ref": "pkg:deb/debian/libc-dev-bin@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=e6850f78fed7a84a",
258426          "supplier": {},
258427          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
258428          "name": "libc-dev-bin",
258429          "version": "2.31-13+deb11u5",
258430          "licenses": [
258431            {
258432              "license": {
258433                "id": "GPL-2.0-only"
258434              }
258435            },
258436            {
258437              "license": {
258438                "id": "LGPL-2.1-only"
258439              }
258440            }
258441          ],
258442          "cpe": "cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
258443          "purl": "pkg:deb/debian/libc-dev-bin@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
258444          "swid": {
258445            "attachment": {}
258446          },
258447          "pedigree": {},
258448          "evidence": {},
258449          "signature": {
258450            "signature": {
258451              "publicKey": {}
258452            }
258453          },
258454          "modelCard": {
258455            "modelParameters": {
258456              "approach": {}
258457            },
258458            "quantitativeAnalysis": {
258459              "graphics": {}
258460            },
258461            "considerations": {}
258462          }
258463        },
258464        {
258465          "type": "library",
258466          "bom-ref": "pkg:deb/debian/libc6@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=abe2c3f30be707e3",
258467          "supplier": {},
258468          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
258469          "name": "libc6",
258470          "version": "2.31-13+deb11u5",
258471          "licenses": [
258472            {
258473              "license": {
258474                "id": "GPL-2.0-only"
258475              }
258476            },
258477            {
258478              "license": {
258479                "id": "LGPL-2.1-only"
258480              }
258481            }
258482          ],
258483          "cpe": "cpe:2.3:a:libc6:libc6:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
258484          "purl": "pkg:deb/debian/libc6@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
258485          "swid": {
258486            "attachment": {}
258487          },
258488          "pedigree": {},
258489          "evidence": {},
258490          "signature": {
258491            "signature": {
258492              "publicKey": {}
258493            }
258494          },
258495          "modelCard": {
258496            "modelParameters": {
258497              "approach": {}
258498            },
258499            "quantitativeAnalysis": {
258500              "graphics": {}
258501            },
258502            "considerations": {}
258503          }
258504        },
258505        {
258506          "type": "library",
258507          "bom-ref": "pkg:deb/debian/libc6-dbg@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=8a9d416cb54a01f7",
258508          "supplier": {},
258509          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
258510          "name": "libc6-dbg",
258511          "version": "2.31-13+deb11u5",
258512          "licenses": [
258513            {
258514              "license": {
258515                "id": "GPL-2.0-only"
258516              }
258517            },
258518            {
258519              "license": {
258520                "id": "LGPL-2.1-only"
258521              }
258522            }
258523          ],
258524          "cpe": "cpe:2.3:a:libc6-dbg:libc6-dbg:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
258525          "purl": "pkg:deb/debian/libc6-dbg@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
258526          "swid": {
258527            "attachment": {}
258528          },
258529          "pedigree": {},
258530          "evidence": {},
258531          "signature": {
258532            "signature": {
258533              "publicKey": {}
258534            }
258535          },
258536          "modelCard": {
258537            "modelParameters": {
258538              "approach": {}
258539            },
258540            "quantitativeAnalysis": {
258541              "graphics": {}
258542            },
258543            "considerations": {}
258544          }
258545        },
258546        {
258547          "type": "library",
258548          "bom-ref": "pkg:deb/debian/libc6-dev@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=8e26a90b08552057",
258549          "supplier": {},
258550          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
258551          "name": "libc6-dev",
258552          "version": "2.31-13+deb11u5",
258553          "licenses": [
258554            {
258555              "license": {
258556                "id": "GPL-2.0-only"
258557              }
258558            },
258559            {
258560              "license": {
258561                "id": "LGPL-2.1-only"
258562              }
258563            }
258564          ],
258565          "cpe": "cpe:2.3:a:libc6-dev:libc6-dev:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
258566          "purl": "pkg:deb/debian/libc6-dev@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
258567          "swid": {
258568            "attachment": {}
258569          },
258570          "pedigree": {},
258571          "evidence": {},
258572          "signature": {
258573            "signature": {
258574              "publicKey": {}
258575            }
258576          },
258577          "modelCard": {
258578            "modelParameters": {
258579              "approach": {}
258580            },
258581            "quantitativeAnalysis": {
258582              "graphics": {}
258583            },
258584            "considerations": {}
258585          }
258586        },
258587        {
258588          "type": "library",
258589          "bom-ref": "pkg:deb/debian/libcairo2@1.16.0-5?arch=amd64\u0026upstream=cairo\u0026distro=debian-11\u0026package-id=259764e52a1f36ec",
258590          "supplier": {},
258591          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
258592          "name": "libcairo2",
258593          "version": "1.16.0-5",
258594          "licenses": [
258595            {
258596              "license": {
258597                "id": "LGPL-2.1-only"
258598              }
258599            }
258600          ],
258601          "cpe": "cpe:2.3:a:libcairo2:libcairo2:1.16.0-5:*:*:*:*:*:*:*",
258602          "purl": "pkg:deb/debian/libcairo2@1.16.0-5?arch=amd64\u0026upstream=cairo\u0026distro=debian-11",
258603          "swid": {
258604            "attachment": {}
258605          },
258606          "pedigree": {},
258607          "evidence": {},
258608          "signature": {
258609            "signature": {
258610              "publicKey": {}
258611            }
258612          },
258613          "modelCard": {
258614            "modelParameters": {
258615              "approach": {}
258616            },
258617            "quantitativeAnalysis": {
258618              "graphics": {}
258619            },
258620            "considerations": {}
258621          }
258622        },
258623        {
258624          "type": "library",
258625          "bom-ref": "pkg:deb/debian/libcap-ng0@0.7.9-2.2+b1?arch=amd64\u0026upstream=libcap-ng%400.7.9-2.2\u0026distro=debian-11\u0026package-id=77d3f745010c245",
258626          "supplier": {},
258627          "publisher": "Pierre Chifflier \u003cpollux@debian.org\u003e",
258628          "name": "libcap-ng0",
258629          "version": "0.7.9-2.2+b1",
258630          "licenses": [
258631            {
258632              "license": {
258633                "id": "GPL-2.0-only"
258634              }
258635            },
258636            {
258637              "license": {
258638                "id": "GPL-3.0-only"
258639              }
258640            },
258641            {
258642              "license": {
258643                "id": "LGPL-2.1-only"
258644              }
258645            }
258646          ],
258647          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2.2\\+b1:*:*:*:*:*:*:*",
258648          "purl": "pkg:deb/debian/libcap-ng0@0.7.9-2.2+b1?arch=amd64\u0026upstream=libcap-ng%400.7.9-2.2\u0026distro=debian-11",
258649          "swid": {
258650            "attachment": {}
258651          },
258652          "pedigree": {},
258653          "evidence": {},
258654          "signature": {
258655            "signature": {
258656              "publicKey": {}
258657            }
258658          },
258659          "modelCard": {
258660            "modelParameters": {
258661              "approach": {}
258662            },
258663            "quantitativeAnalysis": {
258664              "graphics": {}
258665            },
258666            "considerations": {}
258667          }
258668        },
258669        {
258670          "type": "library",
258671          "bom-ref": "pkg:deb/debian/libcap2@1:2.44-1?arch=amd64\u0026distro=debian-11\u0026package-id=e072c59707c90e6f",
258672          "supplier": {},
258673          "publisher": "Christian Kastner \u003cckk@debian.org\u003e",
258674          "name": "libcap2",
258675          "version": "1:2.44-1",
258676          "licenses": [
258677            {
258678              "license": {
258679                "id": "BSD-3-Clause"
258680              }
258681            },
258682            {
258683              "license": {
258684                "id": "GPL-2.0-only"
258685              }
258686            },
258687            {
258688              "license": {
258689                "id": "GPL-2.0-or-later"
258690              }
258691            }
258692          ],
258693          "cpe": "cpe:2.3:a:libcap2:libcap2:1\\:2.44-1:*:*:*:*:*:*:*",
258694          "purl": "pkg:deb/debian/libcap2@1:2.44-1?arch=amd64\u0026distro=debian-11",
258695          "swid": {
258696            "attachment": {}
258697          },
258698          "pedigree": {},
258699          "evidence": {},
258700          "signature": {
258701            "signature": {
258702              "publicKey": {}
258703            }
258704          },
258705          "modelCard": {
258706            "modelParameters": {
258707              "approach": {}
258708            },
258709            "quantitativeAnalysis": {
258710              "graphics": {}
258711            },
258712            "considerations": {}
258713          }
258714        },
258715        {
258716          "type": "library",
258717          "bom-ref": "pkg:deb/debian/libcap2-bin@1:2.44-1?arch=amd64\u0026upstream=libcap2\u0026distro=debian-11\u0026package-id=947be301d335f82a",
258718          "supplier": {},
258719          "publisher": "Christian Kastner \u003cckk@debian.org\u003e",
258720          "name": "libcap2-bin",
258721          "version": "1:2.44-1",
258722          "licenses": [
258723            {
258724              "license": {
258725                "id": "BSD-3-Clause"
258726              }
258727            },
258728            {
258729              "license": {
258730                "id": "GPL-2.0-only"
258731              }
258732            },
258733            {
258734              "license": {
258735                "id": "GPL-2.0-or-later"
258736              }
258737            }
258738          ],
258739          "cpe": "cpe:2.3:a:libcap2-bin:libcap2-bin:1\\:2.44-1:*:*:*:*:*:*:*",
258740          "purl": "pkg:deb/debian/libcap2-bin@1:2.44-1?arch=amd64\u0026upstream=libcap2\u0026distro=debian-11",
258741          "swid": {
258742            "attachment": {}
258743          },
258744          "pedigree": {},
258745          "evidence": {},
258746          "signature": {
258747            "signature": {
258748              "publicKey": {}
258749            }
258750          },
258751          "modelCard": {
258752            "modelParameters": {
258753              "approach": {}
258754            },
258755            "quantitativeAnalysis": {
258756              "graphics": {}
258757            },
258758            "considerations": {}
258759          }
258760        },
258761        {
258762          "type": "library",
258763          "bom-ref": "pkg:deb/debian/libcc1-0@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=9324050ed0fc149",
258764          "supplier": {},
258765          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
258766          "name": "libcc1-0",
258767          "version": "10.2.1-6",
258768          "licenses": [
258769            {
258770              "license": {
258771                "name": "Artistic"
258772              }
258773            },
258774            {
258775              "license": {
258776                "id": "GFDL-1.2-only"
258777              }
258778            },
258779            {
258780              "license": {
258781                "name": "GPL"
258782              }
258783            },
258784            {
258785              "license": {
258786                "id": "GPL-2.0-only"
258787              }
258788            },
258789            {
258790              "license": {
258791                "id": "GPL-3.0-only"
258792              }
258793            },
258794            {
258795              "license": {
258796                "name": "LGPL"
258797              }
258798            }
258799          ],
258800          "cpe": "cpe:2.3:a:libcc1-0:libcc1-0:10.2.1-6:*:*:*:*:*:*:*",
258801          "purl": "pkg:deb/debian/libcc1-0@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
258802          "swid": {
258803            "attachment": {}
258804          },
258805          "pedigree": {},
258806          "evidence": {},
258807          "signature": {
258808            "signature": {
258809              "publicKey": {}
258810            }
258811          },
258812          "modelCard": {
258813            "modelParameters": {
258814              "approach": {}
258815            },
258816            "quantitativeAnalysis": {
258817              "graphics": {}
258818            },
258819            "considerations": {}
258820          }
258821        },
258822        {
258823          "type": "library",
258824          "bom-ref": "pkg:deb/debian/libcom-err2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=c3e2285fd362b920",
258825          "supplier": {},
258826          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
258827          "name": "libcom-err2",
258828          "version": "1.46.2-2",
258829          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.46.2-2:*:*:*:*:*:*:*",
258830          "purl": "pkg:deb/debian/libcom-err2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
258831          "swid": {
258832            "attachment": {}
258833          },
258834          "pedigree": {},
258835          "evidence": {},
258836          "signature": {
258837            "signature": {
258838              "publicKey": {}
258839            }
258840          },
258841          "modelCard": {
258842            "modelParameters": {
258843              "approach": {}
258844            },
258845            "quantitativeAnalysis": {
258846              "graphics": {}
258847            },
258848            "considerations": {}
258849          }
258850        },
258851        {
258852          "type": "library",
258853          "bom-ref": "pkg:deb/debian/libcrypt-dev@1:4.4.18-4?arch=amd64\u0026upstream=libxcrypt\u0026distro=debian-11\u0026package-id=5f0f760a471b910b",
258854          "supplier": {},
258855          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
258856          "name": "libcrypt-dev",
258857          "version": "1:4.4.18-4",
258858          "cpe": "cpe:2.3:a:libcrypt-dev:libcrypt-dev:1\\:4.4.18-4:*:*:*:*:*:*:*",
258859          "purl": "pkg:deb/debian/libcrypt-dev@1:4.4.18-4?arch=amd64\u0026upstream=libxcrypt\u0026distro=debian-11",
258860          "swid": {
258861            "attachment": {}
258862          },
258863          "pedigree": {},
258864          "evidence": {},
258865          "signature": {
258866            "signature": {
258867              "publicKey": {}
258868            }
258869          },
258870          "modelCard": {
258871            "modelParameters": {
258872              "approach": {}
258873            },
258874            "quantitativeAnalysis": {
258875              "graphics": {}
258876            },
258877            "considerations": {}
258878          }
258879        },
258880        {
258881          "type": "library",
258882          "bom-ref": "pkg:deb/debian/libcrypt1@1:4.4.18-4?arch=amd64\u0026upstream=libxcrypt\u0026distro=debian-11\u0026package-id=4d32f8aeb497b2e2",
258883          "supplier": {},
258884          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
258885          "name": "libcrypt1",
258886          "version": "1:4.4.18-4",
258887          "cpe": "cpe:2.3:a:libcrypt1:libcrypt1:1\\:4.4.18-4:*:*:*:*:*:*:*",
258888          "purl": "pkg:deb/debian/libcrypt1@1:4.4.18-4?arch=amd64\u0026upstream=libxcrypt\u0026distro=debian-11",
258889          "swid": {
258890            "attachment": {}
258891          },
258892          "pedigree": {},
258893          "evidence": {},
258894          "signature": {
258895            "signature": {
258896              "publicKey": {}
258897            }
258898          },
258899          "modelCard": {
258900            "modelParameters": {
258901              "approach": {}
258902            },
258903            "quantitativeAnalysis": {
258904              "graphics": {}
258905            },
258906            "considerations": {}
258907          }
258908        },
258909        {
258910          "type": "library",
258911          "bom-ref": "pkg:deb/debian/libctf-nobfd0@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11\u0026package-id=d44ea0845aeea037",
258912          "supplier": {},
258913          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
258914          "name": "libctf-nobfd0",
258915          "version": "2.35.2-2",
258916          "licenses": [
258917            {
258918              "license": {
258919                "name": "GFDL"
258920              }
258921            },
258922            {
258923              "license": {
258924                "name": "GPL"
258925              }
258926            },
258927            {
258928              "license": {
258929                "name": "LGPL"
258930              }
258931            }
258932          ],
258933          "cpe": "cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.35.2-2:*:*:*:*:*:*:*",
258934          "purl": "pkg:deb/debian/libctf-nobfd0@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11",
258935          "swid": {
258936            "attachment": {}
258937          },
258938          "pedigree": {},
258939          "evidence": {},
258940          "signature": {
258941            "signature": {
258942              "publicKey": {}
258943            }
258944          },
258945          "modelCard": {
258946            "modelParameters": {
258947              "approach": {}
258948            },
258949            "quantitativeAnalysis": {
258950              "graphics": {}
258951            },
258952            "considerations": {}
258953          }
258954        },
258955        {
258956          "type": "library",
258957          "bom-ref": "pkg:deb/debian/libctf0@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11\u0026package-id=6c48848dd231991f",
258958          "supplier": {},
258959          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
258960          "name": "libctf0",
258961          "version": "2.35.2-2",
258962          "licenses": [
258963            {
258964              "license": {
258965                "name": "GFDL"
258966              }
258967            },
258968            {
258969              "license": {
258970                "name": "GPL"
258971              }
258972            },
258973            {
258974              "license": {
258975                "name": "LGPL"
258976              }
258977            }
258978          ],
258979          "cpe": "cpe:2.3:a:libctf0:libctf0:2.35.2-2:*:*:*:*:*:*:*",
258980          "purl": "pkg:deb/debian/libctf0@2.35.2-2?arch=amd64\u0026upstream=binutils\u0026distro=debian-11",
258981          "swid": {
258982            "attachment": {}
258983          },
258984          "pedigree": {},
258985          "evidence": {},
258986          "signature": {
258987            "signature": {
258988              "publicKey": {}
258989            }
258990          },
258991          "modelCard": {
258992            "modelParameters": {
258993              "approach": {}
258994            },
258995            "quantitativeAnalysis": {
258996              "graphics": {}
258997            },
258998            "considerations": {}
258999          }
259000        },
259001        {
259002          "type": "library",
259003          "bom-ref": "pkg:deb/debian/libcups2@2.3.3op2-3+deb11u2?arch=amd64\u0026upstream=cups\u0026distro=debian-11\u0026package-id=de95652ff6b6f5cc",
259004          "supplier": {},
259005          "publisher": "Debian Printing Team \u003cdebian-printing@lists.debian.org\u003e",
259006          "name": "libcups2",
259007          "version": "2.3.3op2-3+deb11u2",
259008          "licenses": [
259009            {
259010              "license": {
259011                "id": "Apache-2.0"
259012              }
259013            },
259014            {
259015              "license": {
259016                "name": "Apache-2.0-with-GPL2-LGPL2-Exception"
259017              }
259018            },
259019            {
259020              "license": {
259021                "id": "BSD-2-Clause"
259022              }
259023            },
259024            {
259025              "license": {
259026                "id": "BSD-3-Clause"
259027              }
259028            },
259029            {
259030              "license": {
259031                "id": "FSFUL"
259032              }
259033            },
259034            {
259035              "license": {
259036                "id": "Zlib"
259037              }
259038            }
259039          ],
259040          "cpe": "cpe:2.3:a:libcups2:libcups2:2.3.3op2-3\\+deb11u2:*:*:*:*:*:*:*",
259041          "purl": "pkg:deb/debian/libcups2@2.3.3op2-3+deb11u2?arch=amd64\u0026upstream=cups\u0026distro=debian-11",
259042          "swid": {
259043            "attachment": {}
259044          },
259045          "pedigree": {},
259046          "evidence": {},
259047          "signature": {
259048            "signature": {
259049              "publicKey": {}
259050            }
259051          },
259052          "modelCard": {
259053            "modelParameters": {
259054              "approach": {}
259055            },
259056            "quantitativeAnalysis": {
259057              "graphics": {}
259058            },
259059            "considerations": {}
259060          }
259061        },
259062        {
259063          "type": "library",
259064          "bom-ref": "pkg:deb/debian/libcurl3-gnutls@7.74.0-1.3+deb11u3?arch=amd64\u0026upstream=curl\u0026distro=debian-11\u0026package-id=86d0f9e8bf25fb5a",
259065          "supplier": {},
259066          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
259067          "name": "libcurl3-gnutls",
259068          "version": "7.74.0-1.3+deb11u3",
259069          "licenses": [
259070            {
259071              "license": {
259072                "id": "BSD-3-Clause"
259073              }
259074            },
259075            {
259076              "license": {
259077                "id": "BSD-4-Clause"
259078              }
259079            },
259080            {
259081              "license": {
259082                "id": "ISC"
259083              }
259084            },
259085            {
259086              "license": {
259087                "id": "curl"
259088              }
259089            },
259090            {
259091              "license": {
259092                "name": "other"
259093              }
259094            },
259095            {
259096              "license": {
259097                "name": "public-domain"
259098              }
259099            }
259100          ],
259101          "cpe": "cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.74.0-1.3\\+deb11u3:*:*:*:*:*:*:*",
259102          "purl": "pkg:deb/debian/libcurl3-gnutls@7.74.0-1.3+deb11u3?arch=amd64\u0026upstream=curl\u0026distro=debian-11",
259103          "swid": {
259104            "attachment": {}
259105          },
259106          "pedigree": {},
259107          "evidence": {},
259108          "signature": {
259109            "signature": {
259110              "publicKey": {}
259111            }
259112          },
259113          "modelCard": {
259114            "modelParameters": {
259115              "approach": {}
259116            },
259117            "quantitativeAnalysis": {
259118              "graphics": {}
259119            },
259120            "considerations": {}
259121          }
259122        },
259123        {
259124          "type": "library",
259125          "bom-ref": "pkg:deb/debian/libcurl4@7.74.0-1.3+deb11u3?arch=amd64\u0026upstream=curl\u0026distro=debian-11\u0026package-id=49f31c785a42021",
259126          "supplier": {},
259127          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
259128          "name": "libcurl4",
259129          "version": "7.74.0-1.3+deb11u3",
259130          "licenses": [
259131            {
259132              "license": {
259133                "id": "BSD-3-Clause"
259134              }
259135            },
259136            {
259137              "license": {
259138                "id": "BSD-4-Clause"
259139              }
259140            },
259141            {
259142              "license": {
259143                "id": "ISC"
259144              }
259145            },
259146            {
259147              "license": {
259148                "id": "curl"
259149              }
259150            },
259151            {
259152              "license": {
259153                "name": "other"
259154              }
259155            },
259156            {
259157              "license": {
259158                "name": "public-domain"
259159              }
259160            }
259161          ],
259162          "cpe": "cpe:2.3:a:libcurl4:libcurl4:7.74.0-1.3\\+deb11u3:*:*:*:*:*:*:*",
259163          "purl": "pkg:deb/debian/libcurl4@7.74.0-1.3+deb11u3?arch=amd64\u0026upstream=curl\u0026distro=debian-11",
259164          "swid": {
259165            "attachment": {}
259166          },
259167          "pedigree": {},
259168          "evidence": {},
259169          "signature": {
259170            "signature": {
259171              "publicKey": {}
259172            }
259173          },
259174          "modelCard": {
259175            "modelParameters": {
259176              "approach": {}
259177            },
259178            "quantitativeAnalysis": {
259179              "graphics": {}
259180            },
259181            "considerations": {}
259182          }
259183        },
259184        {
259185          "type": "library",
259186          "bom-ref": "pkg:deb/debian/libdatrie1@0.2.13-1?arch=amd64\u0026upstream=libdatrie\u0026distro=debian-11\u0026package-id=133a81bae05d7d0b",
259187          "supplier": {},
259188          "publisher": "Theppitak Karoonboonyanan \u003cthep@debian.org\u003e",
259189          "name": "libdatrie1",
259190          "version": "0.2.13-1",
259191          "licenses": [
259192            {
259193              "license": {
259194                "id": "GPL-2.0-only"
259195              }
259196            },
259197            {
259198              "license": {
259199                "id": "GPL-2.0-or-later"
259200              }
259201            },
259202            {
259203              "license": {
259204                "id": "LGPL-2.1-only"
259205              }
259206            },
259207            {
259208              "license": {
259209                "id": "LGPL-2.1-or-later"
259210              }
259211            }
259212          ],
259213          "cpe": "cpe:2.3:a:libdatrie1:libdatrie1:0.2.13-1:*:*:*:*:*:*:*",
259214          "purl": "pkg:deb/debian/libdatrie1@0.2.13-1?arch=amd64\u0026upstream=libdatrie\u0026distro=debian-11",
259215          "swid": {
259216            "attachment": {}
259217          },
259218          "pedigree": {},
259219          "evidence": {},
259220          "signature": {
259221            "signature": {
259222              "publicKey": {}
259223            }
259224          },
259225          "modelCard": {
259226            "modelParameters": {
259227              "approach": {}
259228            },
259229            "quantitativeAnalysis": {
259230              "graphics": {}
259231            },
259232            "considerations": {}
259233          }
259234        },
259235        {
259236          "type": "library",
259237          "bom-ref": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.8?arch=amd64\u0026upstream=db5.3\u0026distro=debian-11\u0026package-id=bd40bf11043e04a6",
259238          "supplier": {},
259239          "publisher": "Debian Berkeley DB Team \u003cteam+bdb@tracker.debian.org\u003e",
259240          "name": "libdb5.3",
259241          "version": "5.3.28+dfsg1-0.8",
259242          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.8:*:*:*:*:*:*:*",
259243          "purl": "pkg:deb/debian/libdb5.3@5.3.28+dfsg1-0.8?arch=amd64\u0026upstream=db5.3\u0026distro=debian-11",
259244          "swid": {
259245            "attachment": {}
259246          },
259247          "pedigree": {},
259248          "evidence": {},
259249          "signature": {
259250            "signature": {
259251              "publicKey": {}
259252            }
259253          },
259254          "modelCard": {
259255            "modelParameters": {
259256              "approach": {}
259257            },
259258            "quantitativeAnalysis": {
259259              "graphics": {}
259260            },
259261            "considerations": {}
259262          }
259263        },
259264        {
259265          "type": "library",
259266          "bom-ref": "pkg:deb/debian/libdbus-1-3@1.12.24-0+deb11u1?arch=amd64\u0026upstream=dbus\u0026distro=debian-11\u0026package-id=e8b953d2ddcce10b",
259267          "supplier": {},
259268          "publisher": "Utopia Maintenance Team \u003cpkg-utopia-maintainers@lists.alioth.debian.org\u003e",
259269          "name": "libdbus-1-3",
259270          "version": "1.12.24-0+deb11u1",
259271          "licenses": [
259272            {
259273              "license": {
259274                "id": "AFL-2.1"
259275              }
259276            },
259277            {
259278              "license": {
259279                "id": "BSD-3-Clause"
259280              }
259281            },
259282            {
259283              "license": {
259284                "name": "BSD-3-clause-generic"
259285              }
259286            },
259287            {
259288              "license": {
259289                "name": "Expat"
259290              }
259291            },
259292            {
259293              "license": {
259294                "id": "GPL-2.0-only"
259295              }
259296            },
259297            {
259298              "license": {
259299                "id": "GPL-2.0-or-later"
259300              }
259301            },
259302            {
259303              "license": {
259304                "name": "Tcl-BSDish"
259305              }
259306            },
259307            {
259308              "license": {
259309                "name": "g10-permissive"
259310              }
259311            }
259312          ],
259313          "cpe": "cpe:2.3:a:libdbus-1-3:libdbus-1-3:1.12.24-0\\+deb11u1:*:*:*:*:*:*:*",
259314          "purl": "pkg:deb/debian/libdbus-1-3@1.12.24-0+deb11u1?arch=amd64\u0026upstream=dbus\u0026distro=debian-11",
259315          "swid": {
259316            "attachment": {}
259317          },
259318          "pedigree": {},
259319          "evidence": {},
259320          "signature": {
259321            "signature": {
259322              "publicKey": {}
259323            }
259324          },
259325          "modelCard": {
259326            "modelParameters": {
259327              "approach": {}
259328            },
259329            "quantitativeAnalysis": {
259330              "graphics": {}
259331            },
259332            "considerations": {}
259333          }
259334        },
259335        {
259336          "type": "library",
259337          "bom-ref": "pkg:deb/debian/libdebconfclient0@0.260?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-11\u0026package-id=f46e6be545ae8a8c",
259338          "supplier": {},
259339          "publisher": "Debian Install System Team \u003cdebian-boot@lists.debian.org\u003e",
259340          "name": "libdebconfclient0",
259341          "version": "0.260",
259342          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.260:*:*:*:*:*:*:*",
259343          "purl": "pkg:deb/debian/libdebconfclient0@0.260?arch=amd64\u0026upstream=cdebconf\u0026distro=debian-11",
259344          "swid": {
259345            "attachment": {}
259346          },
259347          "pedigree": {},
259348          "evidence": {},
259349          "signature": {
259350            "signature": {
259351              "publicKey": {}
259352            }
259353          },
259354          "modelCard": {
259355            "modelParameters": {
259356              "approach": {}
259357            },
259358            "quantitativeAnalysis": {
259359              "graphics": {}
259360            },
259361            "considerations": {}
259362          }
259363        },
259364        {
259365          "type": "library",
259366          "bom-ref": "pkg:deb/debian/libdebuginfod1@0.183-1?arch=amd64\u0026upstream=elfutils\u0026distro=debian-11\u0026package-id=c4de0d218fbac992",
259367          "supplier": {},
259368          "publisher": "Debian Elfutils Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
259369          "name": "libdebuginfod1",
259370          "version": "0.183-1",
259371          "licenses": [
259372            {
259373              "license": {
259374                "id": "GPL-2.0-only"
259375              }
259376            },
259377            {
259378              "license": {
259379                "id": "GPL-3.0-only"
259380              }
259381            },
259382            {
259383              "license": {
259384                "id": "LGPL-3.0-only"
259385              }
259386            }
259387          ],
259388          "cpe": "cpe:2.3:a:libdebuginfod1:libdebuginfod1:0.183-1:*:*:*:*:*:*:*",
259389          "purl": "pkg:deb/debian/libdebuginfod1@0.183-1?arch=amd64\u0026upstream=elfutils\u0026distro=debian-11",
259390          "swid": {
259391            "attachment": {}
259392          },
259393          "pedigree": {},
259394          "evidence": {},
259395          "signature": {
259396            "signature": {
259397              "publicKey": {}
259398            }
259399          },
259400          "modelCard": {
259401            "modelParameters": {
259402              "approach": {}
259403            },
259404            "quantitativeAnalysis": {
259405              "graphics": {}
259406            },
259407            "considerations": {}
259408          }
259409        },
259410        {
259411          "type": "library",
259412          "bom-ref": "pkg:deb/debian/libdeflate0@1.7-1?arch=amd64\u0026upstream=libdeflate\u0026distro=debian-11\u0026package-id=6d2c83972d64bdfd",
259413          "supplier": {},
259414          "publisher": "Debian Med Packaging Team \u003cdebian-med-packaging@lists.alioth.debian.org\u003e",
259415          "name": "libdeflate0",
259416          "version": "1.7-1",
259417          "licenses": [
259418            {
259419              "license": {
259420                "name": "Expat"
259421              }
259422            }
259423          ],
259424          "cpe": "cpe:2.3:a:libdeflate0:libdeflate0:1.7-1:*:*:*:*:*:*:*",
259425          "purl": "pkg:deb/debian/libdeflate0@1.7-1?arch=amd64\u0026upstream=libdeflate\u0026distro=debian-11",
259426          "swid": {
259427            "attachment": {}
259428          },
259429          "pedigree": {},
259430          "evidence": {},
259431          "signature": {
259432            "signature": {
259433              "publicKey": {}
259434            }
259435          },
259436          "modelCard": {
259437            "modelParameters": {
259438              "approach": {}
259439            },
259440            "quantitativeAnalysis": {
259441              "graphics": {}
259442            },
259443            "considerations": {}
259444          }
259445        },
259446        {
259447          "type": "library",
259448          "bom-ref": "pkg:deb/debian/libdpkg-perl@1.20.12?arch=all\u0026upstream=dpkg\u0026distro=debian-11\u0026package-id=e27c59e3ebbbfb59",
259449          "supplier": {},
259450          "publisher": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e",
259451          "name": "libdpkg-perl",
259452          "version": "1.20.12",
259453          "licenses": [
259454            {
259455              "license": {
259456                "id": "BSD-2-Clause"
259457              }
259458            },
259459            {
259460              "license": {
259461                "id": "GPL-2.0-only"
259462              }
259463            },
259464            {
259465              "license": {
259466                "id": "GPL-2.0-or-later"
259467              }
259468            },
259469            {
259470              "license": {
259471                "name": "public-domain-md5"
259472              }
259473            },
259474            {
259475              "license": {
259476                "name": "public-domain-s-s-d"
259477              }
259478            }
259479          ],
259480          "cpe": "cpe:2.3:a:libdpkg-perl:libdpkg-perl:1.20.12:*:*:*:*:*:*:*",
259481          "purl": "pkg:deb/debian/libdpkg-perl@1.20.12?arch=all\u0026upstream=dpkg\u0026distro=debian-11",
259482          "swid": {
259483            "attachment": {}
259484          },
259485          "pedigree": {},
259486          "evidence": {},
259487          "signature": {
259488            "signature": {
259489              "publicKey": {}
259490            }
259491          },
259492          "modelCard": {
259493            "modelParameters": {
259494              "approach": {}
259495            },
259496            "quantitativeAnalysis": {
259497              "graphics": {}
259498            },
259499            "considerations": {}
259500          }
259501        },
259502        {
259503          "type": "library",
259504          "bom-ref": "pkg:deb/debian/libdw1@0.183-1?arch=amd64\u0026upstream=elfutils\u0026distro=debian-11\u0026package-id=f50fed65709c52a7",
259505          "supplier": {},
259506          "publisher": "Debian Elfutils Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
259507          "name": "libdw1",
259508          "version": "0.183-1",
259509          "licenses": [
259510            {
259511              "license": {
259512                "id": "GPL-2.0-only"
259513              }
259514            },
259515            {
259516              "license": {
259517                "id": "GPL-3.0-only"
259518              }
259519            },
259520            {
259521              "license": {
259522                "id": "LGPL-3.0-only"
259523              }
259524            }
259525          ],
259526          "cpe": "cpe:2.3:a:libdw1:libdw1:0.183-1:*:*:*:*:*:*:*",
259527          "purl": "pkg:deb/debian/libdw1@0.183-1?arch=amd64\u0026upstream=elfutils\u0026distro=debian-11",
259528          "swid": {
259529            "attachment": {}
259530          },
259531          "pedigree": {},
259532          "evidence": {},
259533          "signature": {
259534            "signature": {
259535              "publicKey": {}
259536            }
259537          },
259538          "modelCard": {
259539            "modelParameters": {
259540              "approach": {}
259541            },
259542            "quantitativeAnalysis": {
259543              "graphics": {}
259544            },
259545            "considerations": {}
259546          }
259547        },
259548        {
259549          "type": "library",
259550          "bom-ref": "pkg:deb/debian/libedit2@3.1-20191231-2+b1?arch=amd64\u0026upstream=libedit%403.1-20191231-2\u0026distro=debian-11\u0026package-id=82ba53f03f3bc29a",
259551          "supplier": {},
259552          "publisher": "LLVM Packaging Team \u003cpkg-llvm-team@lists.alioth.debian.org\u003e",
259553          "name": "libedit2",
259554          "version": "3.1-20191231-2+b1",
259555          "licenses": [
259556            {
259557              "license": {
259558                "id": "BSD-3-Clause"
259559              }
259560            }
259561          ],
259562          "cpe": "cpe:2.3:a:libedit2:libedit2:3.1-20191231-2\\+b1:*:*:*:*:*:*:*",
259563          "purl": "pkg:deb/debian/libedit2@3.1-20191231-2+b1?arch=amd64\u0026upstream=libedit%403.1-20191231-2\u0026distro=debian-11",
259564          "swid": {
259565            "attachment": {}
259566          },
259567          "pedigree": {},
259568          "evidence": {},
259569          "signature": {
259570            "signature": {
259571              "publicKey": {}
259572            }
259573          },
259574          "modelCard": {
259575            "modelParameters": {
259576              "approach": {}
259577            },
259578            "quantitativeAnalysis": {
259579              "graphics": {}
259580            },
259581            "considerations": {}
259582          }
259583        },
259584        {
259585          "type": "library",
259586          "bom-ref": "pkg:deb/debian/libelf1@0.183-1?arch=amd64\u0026upstream=elfutils\u0026distro=debian-11\u0026package-id=9dca3dea199ddb18",
259587          "supplier": {},
259588          "publisher": "Debian Elfutils Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
259589          "name": "libelf1",
259590          "version": "0.183-1",
259591          "licenses": [
259592            {
259593              "license": {
259594                "id": "GPL-2.0-only"
259595              }
259596            },
259597            {
259598              "license": {
259599                "id": "GPL-3.0-only"
259600              }
259601            },
259602            {
259603              "license": {
259604                "id": "LGPL-3.0-only"
259605              }
259606            }
259607          ],
259608          "cpe": "cpe:2.3:a:libelf1:libelf1:0.183-1:*:*:*:*:*:*:*",
259609          "purl": "pkg:deb/debian/libelf1@0.183-1?arch=amd64\u0026upstream=elfutils\u0026distro=debian-11",
259610          "swid": {
259611            "attachment": {}
259612          },
259613          "pedigree": {},
259614          "evidence": {},
259615          "signature": {
259616            "signature": {
259617              "publicKey": {}
259618            }
259619          },
259620          "modelCard": {
259621            "modelParameters": {
259622              "approach": {}
259623            },
259624            "quantitativeAnalysis": {
259625              "graphics": {}
259626            },
259627            "considerations": {}
259628          }
259629        },
259630        {
259631          "type": "library",
259632          "bom-ref": "pkg:deb/debian/liberror-perl@0.17029-1?arch=all\u0026distro=debian-11\u0026package-id=283ecec26ab1cb92",
259633          "supplier": {},
259634          "publisher": "Debian Perl Group \u003cpkg-perl-maintainers@lists.alioth.debian.org\u003e",
259635          "name": "liberror-perl",
259636          "version": "0.17029-1",
259637          "licenses": [
259638            {
259639              "license": {
259640                "name": "Artistic"
259641              }
259642            },
259643            {
259644              "license": {
259645                "id": "GPL-1.0-only"
259646              }
259647            },
259648            {
259649              "license": {
259650                "id": "GPL-1.0-or-later"
259651              }
259652            },
259653            {
259654              "license": {
259655                "name": "MIT/X11"
259656              }
259657            }
259658          ],
259659          "cpe": "cpe:2.3:a:liberror-perl:liberror-perl:0.17029-1:*:*:*:*:*:*:*",
259660          "purl": "pkg:deb/debian/liberror-perl@0.17029-1?arch=all\u0026distro=debian-11",
259661          "swid": {
259662            "attachment": {}
259663          },
259664          "pedigree": {},
259665          "evidence": {},
259666          "signature": {
259667            "signature": {
259668              "publicKey": {}
259669            }
259670          },
259671          "modelCard": {
259672            "modelParameters": {
259673              "approach": {}
259674            },
259675            "quantitativeAnalysis": {
259676              "graphics": {}
259677            },
259678            "considerations": {}
259679          }
259680        },
259681        {
259682          "type": "library",
259683          "bom-ref": "pkg:deb/debian/libevent-2.1-7@2.1.12-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=debian-11\u0026package-id=ece57e6e93801664",
259684          "supplier": {},
259685          "publisher": "Balint Reczey \u003crbalint@ubuntu.com\u003e",
259686          "name": "libevent-2.1-7",
259687          "version": "2.1.12-stable-1",
259688          "licenses": [
259689            {
259690              "license": {
259691                "id": "BSD-2-Clause"
259692              }
259693            },
259694            {
259695              "license": {
259696                "name": "BSD-3-Clause~Kitware"
259697              }
259698            },
259699            {
259700              "license": {
259701                "id": "BSD-3-Clause"
259702              }
259703            },
259704            {
259705              "license": {
259706                "name": "BSL"
259707              }
259708            },
259709            {
259710              "license": {
259711                "name": "Expat"
259712              }
259713            },
259714            {
259715              "license": {
259716                "id": "FSFUL"
259717              }
259718            },
259719            {
259720              "license": {
259721                "id": "FSFULLR"
259722              }
259723            },
259724            {
259725              "license": {
259726                "name": "FSFULLR-No-Warranty"
259727              }
259728            },
259729            {
259730              "license": {
259731                "id": "GPL-2.0-only"
259732              }
259733            },
259734            {
259735              "license": {
259736                "id": "GPL-2.0-or-later"
259737              }
259738            },
259739            {
259740              "license": {
259741                "id": "GPL-3.0-only"
259742              }
259743            },
259744            {
259745              "license": {
259746                "id": "GPL-3.0-or-later"
259747              }
259748            },
259749            {
259750              "license": {
259751                "id": "ISC"
259752              }
259753            },
259754            {
259755              "license": {
259756                "id": "curl"
259757              }
259758            }
259759          ],
259760          "cpe": "cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.12-stable-1:*:*:*:*:*:*:*",
259761          "purl": "pkg:deb/debian/libevent-2.1-7@2.1.12-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=debian-11",
259762          "swid": {
259763            "attachment": {}
259764          },
259765          "pedigree": {},
259766          "evidence": {},
259767          "signature": {
259768            "signature": {
259769              "publicKey": {}
259770            }
259771          },
259772          "modelCard": {
259773            "modelParameters": {
259774              "approach": {}
259775            },
259776            "quantitativeAnalysis": {
259777              "graphics": {}
259778            },
259779            "considerations": {}
259780          }
259781        },
259782        {
259783          "type": "library",
259784          "bom-ref": "pkg:deb/debian/libexpat1@2.2.10-2+deb11u5?arch=amd64\u0026upstream=expat\u0026distro=debian-11\u0026package-id=a3394c6f61c6d6ab",
259785          "supplier": {},
259786          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
259787          "name": "libexpat1",
259788          "version": "2.2.10-2+deb11u5",
259789          "licenses": [
259790            {
259791              "license": {
259792                "id": "MIT"
259793              }
259794            }
259795          ],
259796          "cpe": "cpe:2.3:a:libexpat1:libexpat1:2.2.10-2\\+deb11u5:*:*:*:*:*:*:*",
259797          "purl": "pkg:deb/debian/libexpat1@2.2.10-2+deb11u5?arch=amd64\u0026upstream=expat\u0026distro=debian-11",
259798          "swid": {
259799            "attachment": {}
259800          },
259801          "pedigree": {},
259802          "evidence": {},
259803          "signature": {
259804            "signature": {
259805              "publicKey": {}
259806            }
259807          },
259808          "modelCard": {
259809            "modelParameters": {
259810              "approach": {}
259811            },
259812            "quantitativeAnalysis": {
259813              "graphics": {}
259814            },
259815            "considerations": {}
259816          }
259817        },
259818        {
259819          "type": "library",
259820          "bom-ref": "pkg:deb/debian/libext2fs2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=78620e65fcd780c3",
259821          "supplier": {},
259822          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
259823          "name": "libext2fs2",
259824          "version": "1.46.2-2",
259825          "licenses": [
259826            {
259827              "license": {
259828                "id": "GPL-2.0-only"
259829              }
259830            },
259831            {
259832              "license": {
259833                "id": "LGPL-2.0-only"
259834              }
259835            }
259836          ],
259837          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.46.2-2:*:*:*:*:*:*:*",
259838          "purl": "pkg:deb/debian/libext2fs2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
259839          "swid": {
259840            "attachment": {}
259841          },
259842          "pedigree": {},
259843          "evidence": {},
259844          "signature": {
259845            "signature": {
259846              "publicKey": {}
259847            }
259848          },
259849          "modelCard": {
259850            "modelParameters": {
259851              "approach": {}
259852            },
259853            "quantitativeAnalysis": {
259854              "graphics": {}
259855            },
259856            "considerations": {}
259857          }
259858        },
259859        {
259860          "type": "library",
259861          "bom-ref": "pkg:deb/debian/libffi7@3.3-6?arch=amd64\u0026upstream=libffi\u0026distro=debian-11\u0026package-id=b76aa1c712147c28",
259862          "supplier": {},
259863          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
259864          "name": "libffi7",
259865          "version": "3.3-6",
259866          "licenses": [
259867            {
259868              "license": {
259869                "name": "GPL"
259870              }
259871            }
259872          ],
259873          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-6:*:*:*:*:*:*:*",
259874          "purl": "pkg:deb/debian/libffi7@3.3-6?arch=amd64\u0026upstream=libffi\u0026distro=debian-11",
259875          "swid": {
259876            "attachment": {}
259877          },
259878          "pedigree": {},
259879          "evidence": {},
259880          "signature": {
259881            "signature": {
259882              "publicKey": {}
259883            }
259884          },
259885          "modelCard": {
259886            "modelParameters": {
259887              "approach": {}
259888            },
259889            "quantitativeAnalysis": {
259890              "graphics": {}
259891            },
259892            "considerations": {}
259893          }
259894        },
259895        {
259896          "type": "library",
259897          "bom-ref": "pkg:deb/debian/libfontconfig1@2.13.1-4.2?arch=amd64\u0026upstream=fontconfig\u0026distro=debian-11\u0026package-id=f0e377aa1de8214e",
259898          "supplier": {},
259899          "publisher": "Debian freedesktop.org maintainers \u003cpkg-freedesktop-maintainers@lists.alioth.debian.org\u003e",
259900          "name": "libfontconfig1",
259901          "version": "2.13.1-4.2",
259902          "cpe": "cpe:2.3:a:libfontconfig1:libfontconfig1:2.13.1-4.2:*:*:*:*:*:*:*",
259903          "purl": "pkg:deb/debian/libfontconfig1@2.13.1-4.2?arch=amd64\u0026upstream=fontconfig\u0026distro=debian-11",
259904          "swid": {
259905            "attachment": {}
259906          },
259907          "pedigree": {},
259908          "evidence": {},
259909          "signature": {
259910            "signature": {
259911              "publicKey": {}
259912            }
259913          },
259914          "modelCard": {
259915            "modelParameters": {
259916              "approach": {}
259917            },
259918            "quantitativeAnalysis": {
259919              "graphics": {}
259920            },
259921            "considerations": {}
259922          }
259923        },
259924        {
259925          "type": "library",
259926          "bom-ref": "pkg:deb/debian/libfreetype6@2.10.4+dfsg-1+deb11u1?arch=amd64\u0026upstream=freetype\u0026distro=debian-11\u0026package-id=55f5893ecb8315bb",
259927          "supplier": {},
259928          "publisher": "Hugh McMaster \u003chugh.mcmaster@outlook.com\u003e",
259929          "name": "libfreetype6",
259930          "version": "2.10.4+dfsg-1+deb11u1",
259931          "licenses": [
259932            {
259933              "license": {
259934                "id": "Apache-2.0"
259935              }
259936            },
259937            {
259938              "license": {
259939                "id": "BSD-3-Clause"
259940              }
259941            },
259942            {
259943              "license": {
259944                "id": "FSFAP"
259945              }
259946            },
259947            {
259948              "license": {
259949                "id": "FSFUL"
259950              }
259951            },
259952            {
259953              "license": {
259954                "id": "FSFULLR"
259955              }
259956            },
259957            {
259958              "license": {
259959                "id": "FTL"
259960              }
259961            },
259962            {
259963              "license": {
259964                "id": "GPL-2.0-only"
259965              }
259966            },
259967            {
259968              "license": {
259969                "id": "GPL-2.0-or-later"
259970              }
259971            },
259972            {
259973              "license": {
259974                "id": "GPL-3.0-only"
259975              }
259976            },
259977            {
259978              "license": {
259979                "id": "GPL-3.0-or-later"
259980              }
259981            },
259982            {
259983              "license": {
259984                "id": "MIT"
259985              }
259986            },
259987            {
259988              "license": {
259989                "id": "OFL-1.1"
259990              }
259991            },
259992            {
259993              "license": {
259994                "name": "OpenGroup-BSD-like"
259995              }
259996            },
259997            {
259998              "license": {
259999                "name": "Permissive"
260000              }
260001            },
260002            {
260003              "license": {
260004                "name": "Public-Domain"
260005              }
260006            },
260007            {
260008              "license": {
260009                "id": "Zlib"
260010              }
260011            }
260012          ],
260013          "cpe": "cpe:2.3:a:libfreetype6:libfreetype6:2.10.4\\+dfsg-1\\+deb11u1:*:*:*:*:*:*:*",
260014          "purl": "pkg:deb/debian/libfreetype6@2.10.4+dfsg-1+deb11u1?arch=amd64\u0026upstream=freetype\u0026distro=debian-11",
260015          "swid": {
260016            "attachment": {}
260017          },
260018          "pedigree": {},
260019          "evidence": {},
260020          "signature": {
260021            "signature": {
260022              "publicKey": {}
260023            }
260024          },
260025          "modelCard": {
260026            "modelParameters": {
260027              "approach": {}
260028            },
260029            "quantitativeAnalysis": {
260030              "graphics": {}
260031            },
260032            "considerations": {}
260033          }
260034        },
260035        {
260036          "type": "library",
260037          "bom-ref": "pkg:deb/debian/libfribidi0@1.0.8-2+deb11u1?arch=amd64\u0026upstream=fribidi\u0026distro=debian-11\u0026package-id=1ee2bb298a6b642d",
260038          "supplier": {},
260039          "publisher": "Debian Hebrew Packaging Team \u003cteam+hebrew@tracker.debian.org\u003e",
260040          "name": "libfribidi0",
260041          "version": "1.0.8-2+deb11u1",
260042          "licenses": [
260043            {
260044              "license": {
260045                "id": "LGPL-2.1-only"
260046              }
260047            },
260048            {
260049              "license": {
260050                "id": "LGPL-2.1-or-later"
260051              }
260052            }
260053          ],
260054          "cpe": "cpe:2.3:a:libfribidi0:libfribidi0:1.0.8-2\\+deb11u1:*:*:*:*:*:*:*",
260055          "purl": "pkg:deb/debian/libfribidi0@1.0.8-2+deb11u1?arch=amd64\u0026upstream=fribidi\u0026distro=debian-11",
260056          "swid": {
260057            "attachment": {}
260058          },
260059          "pedigree": {},
260060          "evidence": {},
260061          "signature": {
260062            "signature": {
260063              "publicKey": {}
260064            }
260065          },
260066          "modelCard": {
260067            "modelParameters": {
260068              "approach": {}
260069            },
260070            "quantitativeAnalysis": {
260071              "graphics": {}
260072            },
260073            "considerations": {}
260074          }
260075        },
260076        {
260077          "type": "library",
260078          "bom-ref": "pkg:deb/debian/libfstrm0@0.6.0-1+b1?arch=amd64\u0026upstream=fstrm%400.6.0-1\u0026distro=debian-11\u0026package-id=e9d6cf983a9519b4",
260079          "supplier": {},
260080          "publisher": "Robert Edmonds \u003cedmonds@debian.org\u003e",
260081          "name": "libfstrm0",
260082          "version": "0.6.0-1+b1",
260083          "licenses": [
260084            {
260085              "license": {
260086                "name": "Gray-Watson"
260087              }
260088            },
260089            {
260090              "license": {
260091                "id": "MIT"
260092              }
260093            }
260094          ],
260095          "cpe": "cpe:2.3:a:libfstrm0:libfstrm0:0.6.0-1\\+b1:*:*:*:*:*:*:*",
260096          "purl": "pkg:deb/debian/libfstrm0@0.6.0-1+b1?arch=amd64\u0026upstream=fstrm%400.6.0-1\u0026distro=debian-11",
260097          "swid": {
260098            "attachment": {}
260099          },
260100          "pedigree": {},
260101          "evidence": {},
260102          "signature": {
260103            "signature": {
260104              "publicKey": {}
260105            }
260106          },
260107          "modelCard": {
260108            "modelParameters": {
260109              "approach": {}
260110            },
260111            "quantitativeAnalysis": {
260112              "graphics": {}
260113            },
260114            "considerations": {}
260115          }
260116        },
260117        {
260118          "type": "library",
260119          "bom-ref": "pkg:deb/debian/libgcc-10-dev@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=be33e75e9891e290",
260120          "supplier": {},
260121          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
260122          "name": "libgcc-10-dev",
260123          "version": "10.2.1-6",
260124          "licenses": [
260125            {
260126              "license": {
260127                "name": "Artistic"
260128              }
260129            },
260130            {
260131              "license": {
260132                "id": "GFDL-1.2-only"
260133              }
260134            },
260135            {
260136              "license": {
260137                "name": "GPL"
260138              }
260139            },
260140            {
260141              "license": {
260142                "id": "GPL-2.0-only"
260143              }
260144            },
260145            {
260146              "license": {
260147                "id": "GPL-3.0-only"
260148              }
260149            },
260150            {
260151              "license": {
260152                "name": "LGPL"
260153              }
260154            }
260155          ],
260156          "cpe": "cpe:2.3:a:libgcc-10-dev:libgcc-10-dev:10.2.1-6:*:*:*:*:*:*:*",
260157          "purl": "pkg:deb/debian/libgcc-10-dev@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
260158          "swid": {
260159            "attachment": {}
260160          },
260161          "pedigree": {},
260162          "evidence": {},
260163          "signature": {
260164            "signature": {
260165              "publicKey": {}
260166            }
260167          },
260168          "modelCard": {
260169            "modelParameters": {
260170              "approach": {}
260171            },
260172            "quantitativeAnalysis": {
260173              "graphics": {}
260174            },
260175            "considerations": {}
260176          }
260177        },
260178        {
260179          "type": "library",
260180          "bom-ref": "pkg:deb/debian/libgcc-s1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=ddb4ba0153b59955",
260181          "supplier": {},
260182          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
260183          "name": "libgcc-s1",
260184          "version": "10.2.1-6",
260185          "licenses": [
260186            {
260187              "license": {
260188                "name": "Artistic"
260189              }
260190            },
260191            {
260192              "license": {
260193                "id": "GFDL-1.2-only"
260194              }
260195            },
260196            {
260197              "license": {
260198                "name": "GPL"
260199              }
260200            },
260201            {
260202              "license": {
260203                "id": "GPL-2.0-only"
260204              }
260205            },
260206            {
260207              "license": {
260208                "id": "GPL-3.0-only"
260209              }
260210            },
260211            {
260212              "license": {
260213                "name": "LGPL"
260214              }
260215            }
260216          ],
260217          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.2.1-6:*:*:*:*:*:*:*",
260218          "purl": "pkg:deb/debian/libgcc-s1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
260219          "swid": {
260220            "attachment": {}
260221          },
260222          "pedigree": {},
260223          "evidence": {},
260224          "signature": {
260225            "signature": {
260226              "publicKey": {}
260227            }
260228          },
260229          "modelCard": {
260230            "modelParameters": {
260231              "approach": {}
260232            },
260233            "quantitativeAnalysis": {
260234              "graphics": {}
260235            },
260236            "considerations": {}
260237          }
260238        },
260239        {
260240          "type": "library",
260241          "bom-ref": "pkg:deb/debian/libgcrypt20@1.8.7-6?arch=amd64\u0026distro=debian-11\u0026package-id=7bc9b7389c934ca8",
260242          "supplier": {},
260243          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
260244          "name": "libgcrypt20",
260245          "version": "1.8.7-6",
260246          "licenses": [
260247            {
260248              "license": {
260249                "id": "GPL-2.0-only"
260250              }
260251            },
260252            {
260253              "license": {
260254                "name": "LGPL"
260255              }
260256            }
260257          ],
260258          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.7-6:*:*:*:*:*:*:*",
260259          "purl": "pkg:deb/debian/libgcrypt20@1.8.7-6?arch=amd64\u0026distro=debian-11",
260260          "swid": {
260261            "attachment": {}
260262          },
260263          "pedigree": {},
260264          "evidence": {},
260265          "signature": {
260266            "signature": {
260267              "publicKey": {}
260268            }
260269          },
260270          "modelCard": {
260271            "modelParameters": {
260272              "approach": {}
260273            },
260274            "quantitativeAnalysis": {
260275              "graphics": {}
260276            },
260277            "considerations": {}
260278          }
260279        },
260280        {
260281          "type": "library",
260282          "bom-ref": "pkg:deb/debian/libgdbm-compat4@1.19-2?arch=amd64\u0026upstream=gdbm\u0026distro=debian-11\u0026package-id=90dd9f99ee3321b8",
260283          "supplier": {},
260284          "publisher": "Dmitry Bogatov \u003cKAction@debian.org\u003e",
260285          "name": "libgdbm-compat4",
260286          "version": "1.19-2",
260287          "licenses": [
260288            {
260289              "license": {
260290                "name": "GFDL-NIV-1.3+"
260291              }
260292            },
260293            {
260294              "license": {
260295                "id": "GPL-2.0-only"
260296              }
260297            },
260298            {
260299              "license": {
260300                "id": "GPL-2.0-or-later"
260301              }
260302            },
260303            {
260304              "license": {
260305                "id": "GPL-3.0-only"
260306              }
260307            },
260308            {
260309              "license": {
260310                "id": "GPL-3.0-or-later"
260311              }
260312            }
260313          ],
260314          "cpe": "cpe:2.3:a:libgdbm-compat4:libgdbm-compat4:1.19-2:*:*:*:*:*:*:*",
260315          "purl": "pkg:deb/debian/libgdbm-compat4@1.19-2?arch=amd64\u0026upstream=gdbm\u0026distro=debian-11",
260316          "swid": {
260317            "attachment": {}
260318          },
260319          "pedigree": {},
260320          "evidence": {},
260321          "signature": {
260322            "signature": {
260323              "publicKey": {}
260324            }
260325          },
260326          "modelCard": {
260327            "modelParameters": {
260328              "approach": {}
260329            },
260330            "quantitativeAnalysis": {
260331              "graphics": {}
260332            },
260333            "considerations": {}
260334          }
260335        },
260336        {
260337          "type": "library",
260338          "bom-ref": "pkg:deb/debian/libgdbm6@1.19-2?arch=amd64\u0026upstream=gdbm\u0026distro=debian-11\u0026package-id=9ed3d476ab3ead1e",
260339          "supplier": {},
260340          "publisher": "Dmitry Bogatov \u003cKAction@debian.org\u003e",
260341          "name": "libgdbm6",
260342          "version": "1.19-2",
260343          "licenses": [
260344            {
260345              "license": {
260346                "name": "GFDL-NIV-1.3+"
260347              }
260348            },
260349            {
260350              "license": {
260351                "id": "GPL-2.0-only"
260352              }
260353            },
260354            {
260355              "license": {
260356                "id": "GPL-2.0-or-later"
260357              }
260358            },
260359            {
260360              "license": {
260361                "id": "GPL-3.0-only"
260362              }
260363            },
260364            {
260365              "license": {
260366                "id": "GPL-3.0-or-later"
260367              }
260368            }
260369          ],
260370          "cpe": "cpe:2.3:a:libgdbm6:libgdbm6:1.19-2:*:*:*:*:*:*:*",
260371          "purl": "pkg:deb/debian/libgdbm6@1.19-2?arch=amd64\u0026upstream=gdbm\u0026distro=debian-11",
260372          "swid": {
260373            "attachment": {}
260374          },
260375          "pedigree": {},
260376          "evidence": {},
260377          "signature": {
260378            "signature": {
260379              "publicKey": {}
260380            }
260381          },
260382          "modelCard": {
260383            "modelParameters": {
260384              "approach": {}
260385            },
260386            "quantitativeAnalysis": {
260387              "graphics": {}
260388            },
260389            "considerations": {}
260390          }
260391        },
260392        {
260393          "type": "library",
260394          "bom-ref": "pkg:deb/debian/libgdk-pixbuf-2.0-0@2.42.2+dfsg-1+deb11u1?arch=amd64\u0026upstream=gdk-pixbuf\u0026distro=debian-11\u0026package-id=9bdad52748b9d133",
260395          "supplier": {},
260396          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
260397          "name": "libgdk-pixbuf-2.0-0",
260398          "version": "2.42.2+dfsg-1+deb11u1",
260399          "licenses": [
260400            {
260401              "license": {
260402                "id": "GPL-2.0-only"
260403              }
260404            },
260405            {
260406              "license": {
260407                "id": "GPL-2.0-or-later"
260408              }
260409            },
260410            {
260411              "license": {
260412                "id": "LGPL-2.0-only"
260413              }
260414            },
260415            {
260416              "license": {
260417                "id": "LGPL-2.0-or-later"
260418              }
260419            }
260420          ],
260421          "cpe": "cpe:2.3:a:libgdk-pixbuf-2.0-0:libgdk-pixbuf-2.0-0:2.42.2\\+dfsg-1\\+deb11u1:*:*:*:*:*:*:*",
260422          "purl": "pkg:deb/debian/libgdk-pixbuf-2.0-0@2.42.2+dfsg-1+deb11u1?arch=amd64\u0026upstream=gdk-pixbuf\u0026distro=debian-11",
260423          "swid": {
260424            "attachment": {}
260425          },
260426          "pedigree": {},
260427          "evidence": {},
260428          "signature": {
260429            "signature": {
260430              "publicKey": {}
260431            }
260432          },
260433          "modelCard": {
260434            "modelParameters": {
260435              "approach": {}
260436            },
260437            "quantitativeAnalysis": {
260438              "graphics": {}
260439            },
260440            "considerations": {}
260441          }
260442        },
260443        {
260444          "type": "library",
260445          "bom-ref": "pkg:deb/debian/libgdk-pixbuf2.0-common@2.42.2+dfsg-1+deb11u1?arch=all\u0026upstream=gdk-pixbuf\u0026distro=debian-11\u0026package-id=423ac90f801992cb",
260446          "supplier": {},
260447          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
260448          "name": "libgdk-pixbuf2.0-common",
260449          "version": "2.42.2+dfsg-1+deb11u1",
260450          "licenses": [
260451            {
260452              "license": {
260453                "id": "GPL-2.0-only"
260454              }
260455            },
260456            {
260457              "license": {
260458                "id": "GPL-2.0-or-later"
260459              }
260460            },
260461            {
260462              "license": {
260463                "id": "LGPL-2.0-only"
260464              }
260465            },
260466            {
260467              "license": {
260468                "id": "LGPL-2.0-or-later"
260469              }
260470            }
260471          ],
260472          "cpe": "cpe:2.3:a:libgdk-pixbuf2.0-common:libgdk-pixbuf2.0-common:2.42.2\\+dfsg-1\\+deb11u1:*:*:*:*:*:*:*",
260473          "purl": "pkg:deb/debian/libgdk-pixbuf2.0-common@2.42.2+dfsg-1+deb11u1?arch=all\u0026upstream=gdk-pixbuf\u0026distro=debian-11",
260474          "swid": {
260475            "attachment": {}
260476          },
260477          "pedigree": {},
260478          "evidence": {},
260479          "signature": {
260480            "signature": {
260481              "publicKey": {}
260482            }
260483          },
260484          "modelCard": {
260485            "modelParameters": {
260486              "approach": {}
260487            },
260488            "quantitativeAnalysis": {
260489              "graphics": {}
260490            },
260491            "considerations": {}
260492          }
260493        },
260494        {
260495          "type": "library",
260496          "bom-ref": "pkg:deb/debian/libglib2.0-0@2.66.8-1?arch=amd64\u0026upstream=glib2.0\u0026distro=debian-11\u0026package-id=d91983e4d7618554",
260497          "supplier": {},
260498          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
260499          "name": "libglib2.0-0",
260500          "version": "2.66.8-1",
260501          "licenses": [
260502            {
260503              "license": {
260504                "name": "Expat"
260505              }
260506            },
260507            {
260508              "license": {
260509                "id": "GPL-2.0-or-later"
260510              }
260511            },
260512            {
260513              "license": {
260514                "name": "LGPL"
260515              }
260516            }
260517          ],
260518          "cpe": "cpe:2.3:a:libglib2.0-0:libglib2.0-0:2.66.8-1:*:*:*:*:*:*:*",
260519          "purl": "pkg:deb/debian/libglib2.0-0@2.66.8-1?arch=amd64\u0026upstream=glib2.0\u0026distro=debian-11",
260520          "swid": {
260521            "attachment": {}
260522          },
260523          "pedigree": {},
260524          "evidence": {},
260525          "signature": {
260526            "signature": {
260527              "publicKey": {}
260528            }
260529          },
260530          "modelCard": {
260531            "modelParameters": {
260532              "approach": {}
260533            },
260534            "quantitativeAnalysis": {
260535              "graphics": {}
260536            },
260537            "considerations": {}
260538          }
260539        },
260540        {
260541          "type": "library",
260542          "bom-ref": "pkg:deb/debian/libgmp10@2:6.2.1+dfsg-1+deb11u1?arch=amd64\u0026upstream=gmp\u0026distro=debian-11\u0026package-id=b8566db47d8d4ddc",
260543          "supplier": {},
260544          "publisher": "Debian Science Team \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e",
260545          "name": "libgmp10",
260546          "version": "2:6.2.1+dfsg-1+deb11u1",
260547          "licenses": [
260548            {
260549              "license": {
260550                "name": "GPL"
260551              }
260552            },
260553            {
260554              "license": {
260555                "id": "GPL-2.0-only"
260556              }
260557            },
260558            {
260559              "license": {
260560                "id": "GPL-3.0-only"
260561              }
260562            },
260563            {
260564              "license": {
260565                "id": "LGPL-3.0-only"
260566              }
260567            }
260568          ],
260569          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.1\\+dfsg-1\\+deb11u1:*:*:*:*:*:*:*",
260570          "purl": "pkg:deb/debian/libgmp10@2:6.2.1+dfsg-1+deb11u1?arch=amd64\u0026upstream=gmp\u0026distro=debian-11",
260571          "swid": {
260572            "attachment": {}
260573          },
260574          "pedigree": {},
260575          "evidence": {},
260576          "signature": {
260577            "signature": {
260578              "publicKey": {}
260579            }
260580          },
260581          "modelCard": {
260582            "modelParameters": {
260583              "approach": {}
260584            },
260585            "quantitativeAnalysis": {
260586              "graphics": {}
260587            },
260588            "considerations": {}
260589          }
260590        },
260591        {
260592          "type": "library",
260593          "bom-ref": "pkg:deb/debian/libgnutls30@3.7.1-5+deb11u2?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-11\u0026package-id=9ba32f357c27d6bd",
260594          "supplier": {},
260595          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
260596          "name": "libgnutls30",
260597          "version": "3.7.1-5+deb11u2",
260598          "licenses": [
260599            {
260600              "license": {
260601                "id": "Apache-2.0"
260602              }
260603            },
260604            {
260605              "license": {
260606                "id": "BSD-3-Clause"
260607              }
260608            },
260609            {
260610              "license": {
260611                "name": "CC0"
260612              }
260613            },
260614            {
260615              "license": {
260616                "name": "Expat"
260617              }
260618            },
260619            {
260620              "license": {
260621                "id": "GFDL-1.3-only"
260622              }
260623            },
260624            {
260625              "license": {
260626                "name": "GPL"
260627              }
260628            },
260629            {
260630              "license": {
260631                "id": "GPL-3.0-only"
260632              }
260633            },
260634            {
260635              "license": {
260636                "name": "GPLv3+"
260637              }
260638            },
260639            {
260640              "license": {
260641                "name": "LGPL"
260642              }
260643            },
260644            {
260645              "license": {
260646                "id": "LGPL-3.0-only"
260647              }
260648            },
260649            {
260650              "license": {
260651                "name": "LGPLv2.1+"
260652              }
260653            },
260654            {
260655              "license": {
260656                "name": "LGPLv3+_or_GPLv2+"
260657              }
260658            },
260659            {
260660              "license": {
260661                "name": "The"
260662              }
260663            }
260664          ],
260665          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.7.1-5\\+deb11u2:*:*:*:*:*:*:*",
260666          "purl": "pkg:deb/debian/libgnutls30@3.7.1-5+deb11u2?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-11",
260667          "swid": {
260668            "attachment": {}
260669          },
260670          "pedigree": {},
260671          "evidence": {},
260672          "signature": {
260673            "signature": {
260674              "publicKey": {}
260675            }
260676          },
260677          "modelCard": {
260678            "modelParameters": {
260679              "approach": {}
260680            },
260681            "quantitativeAnalysis": {
260682              "graphics": {}
260683            },
260684            "considerations": {}
260685          }
260686        },
260687        {
260688          "type": "library",
260689          "bom-ref": "pkg:deb/debian/libgomp1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=fee45961a9f5626b",
260690          "supplier": {},
260691          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
260692          "name": "libgomp1",
260693          "version": "10.2.1-6",
260694          "licenses": [
260695            {
260696              "license": {
260697                "name": "Artistic"
260698              }
260699            },
260700            {
260701              "license": {
260702                "id": "GFDL-1.2-only"
260703              }
260704            },
260705            {
260706              "license": {
260707                "name": "GPL"
260708              }
260709            },
260710            {
260711              "license": {
260712                "id": "GPL-2.0-only"
260713              }
260714            },
260715            {
260716              "license": {
260717                "id": "GPL-3.0-only"
260718              }
260719            },
260720            {
260721              "license": {
260722                "name": "LGPL"
260723              }
260724            }
260725          ],
260726          "cpe": "cpe:2.3:a:libgomp1:libgomp1:10.2.1-6:*:*:*:*:*:*:*",
260727          "purl": "pkg:deb/debian/libgomp1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
260728          "swid": {
260729            "attachment": {}
260730          },
260731          "pedigree": {},
260732          "evidence": {},
260733          "signature": {
260734            "signature": {
260735              "publicKey": {}
260736            }
260737          },
260738          "modelCard": {
260739            "modelParameters": {
260740              "approach": {}
260741            },
260742            "quantitativeAnalysis": {
260743              "graphics": {}
260744            },
260745            "considerations": {}
260746          }
260747        },
260748        {
260749          "type": "library",
260750          "bom-ref": "pkg:deb/debian/libgpg-error0@1.38-2?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-11\u0026package-id=2391ec82a95e1b79",
260751          "supplier": {},
260752          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
260753          "name": "libgpg-error0",
260754          "version": "1.38-2",
260755          "licenses": [
260756            {
260757              "license": {
260758                "id": "BSD-3-Clause"
260759              }
260760            },
260761            {
260762              "license": {
260763                "id": "GPL-3.0-only"
260764              }
260765            },
260766            {
260767              "license": {
260768                "id": "GPL-3.0-or-later"
260769              }
260770            },
260771            {
260772              "license": {
260773                "id": "LGPL-2.1-only"
260774              }
260775            },
260776            {
260777              "license": {
260778                "id": "LGPL-2.1-or-later"
260779              }
260780            },
260781            {
260782              "license": {
260783                "name": "g10-permissive"
260784              }
260785            }
260786          ],
260787          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.38-2:*:*:*:*:*:*:*",
260788          "purl": "pkg:deb/debian/libgpg-error0@1.38-2?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-11",
260789          "swid": {
260790            "attachment": {}
260791          },
260792          "pedigree": {},
260793          "evidence": {},
260794          "signature": {
260795            "signature": {
260796              "publicKey": {}
260797            }
260798          },
260799          "modelCard": {
260800            "modelParameters": {
260801              "approach": {}
260802            },
260803            "quantitativeAnalysis": {
260804              "graphics": {}
260805            },
260806            "considerations": {}
260807          }
260808        },
260809        {
260810          "type": "library",
260811          "bom-ref": "pkg:deb/debian/libgpm2@1.20.7-8?arch=amd64\u0026upstream=gpm\u0026distro=debian-11\u0026package-id=5a5861d941b8b3e9",
260812          "supplier": {},
260813          "publisher": "Axel Beckert \u003cabe@debian.org\u003e",
260814          "name": "libgpm2",
260815          "version": "1.20.7-8",
260816          "licenses": [
260817            {
260818              "license": {
260819                "id": "GPL-2.0-only"
260820              }
260821            },
260822            {
260823              "license": {
260824                "id": "GPL-2.0-or-later"
260825              }
260826            },
260827            {
260828              "license": {
260829                "id": "GPL-3.0-only"
260830              }
260831            },
260832            {
260833              "license": {
260834                "id": "GPL-3.0-or-later"
260835              }
260836            }
260837          ],
260838          "cpe": "cpe:2.3:a:libgpm2:libgpm2:1.20.7-8:*:*:*:*:*:*:*",
260839          "purl": "pkg:deb/debian/libgpm2@1.20.7-8?arch=amd64\u0026upstream=gpm\u0026distro=debian-11",
260840          "swid": {
260841            "attachment": {}
260842          },
260843          "pedigree": {},
260844          "evidence": {},
260845          "signature": {
260846            "signature": {
260847              "publicKey": {}
260848            }
260849          },
260850          "modelCard": {
260851            "modelParameters": {
260852              "approach": {}
260853            },
260854            "quantitativeAnalysis": {
260855              "graphics": {}
260856            },
260857            "considerations": {}
260858          }
260859        },
260860        {
260861          "type": "library",
260862          "bom-ref": "pkg:deb/debian/libgraphite2-3@1.3.14-1?arch=amd64\u0026upstream=graphite2\u0026distro=debian-11\u0026package-id=9a1127616d55e8d8",
260863          "supplier": {},
260864          "publisher": "Debian LibreOffice Maintainers \u003cdebian-openoffice@lists.debian.org\u003e",
260865          "name": "libgraphite2-3",
260866          "version": "1.3.14-1",
260867          "licenses": [
260868            {
260869              "license": {
260870                "name": "Artistic"
260871              }
260872            },
260873            {
260874              "license": {
260875                "id": "GPL-1.0-only"
260876              }
260877            },
260878            {
260879              "license": {
260880                "id": "GPL-1.0-or-later"
260881              }
260882            },
260883            {
260884              "license": {
260885                "id": "GPL-2.0-only"
260886              }
260887            },
260888            {
260889              "license": {
260890                "id": "GPL-2.0-or-later"
260891              }
260892            },
260893            {
260894              "license": {
260895                "id": "LGPL-2.1-only"
260896              }
260897            },
260898            {
260899              "license": {
260900                "id": "LGPL-2.1-or-later"
260901              }
260902            },
260903            {
260904              "license": {
260905                "id": "MPL-1.1"
260906              }
260907            },
260908            {
260909              "license": {
260910                "name": "custom-sil-open-font-license"
260911              }
260912            },
260913            {
260914              "license": {
260915                "name": "public-domain"
260916              }
260917            }
260918          ],
260919          "cpe": "cpe:2.3:a:libgraphite2-3:libgraphite2-3:1.3.14-1:*:*:*:*:*:*:*",
260920          "purl": "pkg:deb/debian/libgraphite2-3@1.3.14-1?arch=amd64\u0026upstream=graphite2\u0026distro=debian-11",
260921          "swid": {
260922            "attachment": {}
260923          },
260924          "pedigree": {},
260925          "evidence": {},
260926          "signature": {
260927            "signature": {
260928              "publicKey": {}
260929            }
260930          },
260931          "modelCard": {
260932            "modelParameters": {
260933              "approach": {}
260934            },
260935            "quantitativeAnalysis": {
260936              "graphics": {}
260937            },
260938            "considerations": {}
260939          }
260940        },
260941        {
260942          "type": "library",
260943          "bom-ref": "pkg:deb/debian/libgssapi-krb5-2@1.18.3-6+deb11u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=939119995ec5c771",
260944          "supplier": {},
260945          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
260946          "name": "libgssapi-krb5-2",
260947          "version": "1.18.3-6+deb11u2",
260948          "licenses": [
260949            {
260950              "license": {
260951                "id": "GPL-2.0-only"
260952              }
260953            }
260954          ],
260955          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.18.3-6\\+deb11u2:*:*:*:*:*:*:*",
260956          "purl": "pkg:deb/debian/libgssapi-krb5-2@1.18.3-6+deb11u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
260957          "swid": {
260958            "attachment": {}
260959          },
260960          "pedigree": {},
260961          "evidence": {},
260962          "signature": {
260963            "signature": {
260964              "publicKey": {}
260965            }
260966          },
260967          "modelCard": {
260968            "modelParameters": {
260969              "approach": {}
260970            },
260971            "quantitativeAnalysis": {
260972              "graphics": {}
260973            },
260974            "considerations": {}
260975          }
260976        },
260977        {
260978          "type": "library",
260979          "bom-ref": "pkg:deb/debian/libgtk2.0-0@2.24.33-2?arch=amd64\u0026upstream=gtk+2.0\u0026distro=debian-11\u0026package-id=80d08798df8a6ad3",
260980          "supplier": {},
260981          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
260982          "name": "libgtk2.0-0",
260983          "version": "2.24.33-2",
260984          "licenses": [
260985            {
260986              "license": {
260987                "id": "LGPL-2.0-only"
260988              }
260989            },
260990            {
260991              "license": {
260992                "name": "other"
260993              }
260994            }
260995          ],
260996          "cpe": "cpe:2.3:a:libgtk2.0-0:libgtk2.0-0:2.24.33-2:*:*:*:*:*:*:*",
260997          "purl": "pkg:deb/debian/libgtk2.0-0@2.24.33-2?arch=amd64\u0026upstream=gtk+2.0\u0026distro=debian-11",
260998          "swid": {
260999            "attachment": {}
261000          },
261001          "pedigree": {},
261002          "evidence": {},
261003          "signature": {
261004            "signature": {
261005              "publicKey": {}
261006            }
261007          },
261008          "modelCard": {
261009            "modelParameters": {
261010              "approach": {}
261011            },
261012            "quantitativeAnalysis": {
261013              "graphics": {}
261014            },
261015            "considerations": {}
261016          }
261017        },
261018        {
261019          "type": "library",
261020          "bom-ref": "pkg:deb/debian/libgtk2.0-common@2.24.33-2?arch=all\u0026upstream=gtk+2.0\u0026distro=debian-11\u0026package-id=8064722b08ef354f",
261021          "supplier": {},
261022          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
261023          "name": "libgtk2.0-common",
261024          "version": "2.24.33-2",
261025          "licenses": [
261026            {
261027              "license": {
261028                "id": "LGPL-2.0-only"
261029              }
261030            },
261031            {
261032              "license": {
261033                "name": "other"
261034              }
261035            }
261036          ],
261037          "cpe": "cpe:2.3:a:libgtk2.0-common:libgtk2.0-common:2.24.33-2:*:*:*:*:*:*:*",
261038          "purl": "pkg:deb/debian/libgtk2.0-common@2.24.33-2?arch=all\u0026upstream=gtk+2.0\u0026distro=debian-11",
261039          "swid": {
261040            "attachment": {}
261041          },
261042          "pedigree": {},
261043          "evidence": {},
261044          "signature": {
261045            "signature": {
261046              "publicKey": {}
261047            }
261048          },
261049          "modelCard": {
261050            "modelParameters": {
261051              "approach": {}
261052            },
261053            "quantitativeAnalysis": {
261054              "graphics": {}
261055            },
261056            "considerations": {}
261057          }
261058        },
261059        {
261060          "type": "library",
261061          "bom-ref": "pkg:deb/debian/libharfbuzz0b@2.7.4-1?arch=amd64\u0026upstream=harfbuzz\u0026distro=debian-11\u0026package-id=e3de93324e0a53b5",
261062          "supplier": {},
261063          "publisher": "أحمد المحمودي (Ahmed El-Mahmoudy) \u003caelmahmoudy@users.sourceforge.net\u003e",
261064          "name": "libharfbuzz0b",
261065          "version": "2.7.4-1",
261066          "licenses": [
261067            {
261068              "license": {
261069                "id": "MIT"
261070              }
261071            }
261072          ],
261073          "cpe": "cpe:2.3:a:libharfbuzz0b:libharfbuzz0b:2.7.4-1:*:*:*:*:*:*:*",
261074          "purl": "pkg:deb/debian/libharfbuzz0b@2.7.4-1?arch=amd64\u0026upstream=harfbuzz\u0026distro=debian-11",
261075          "swid": {
261076            "attachment": {}
261077          },
261078          "pedigree": {},
261079          "evidence": {},
261080          "signature": {
261081            "signature": {
261082              "publicKey": {}
261083            }
261084          },
261085          "modelCard": {
261086            "modelParameters": {
261087              "approach": {}
261088            },
261089            "quantitativeAnalysis": {
261090              "graphics": {}
261091            },
261092            "considerations": {}
261093          }
261094        },
261095        {
261096          "type": "library",
261097          "bom-ref": "pkg:deb/debian/libhogweed6@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11\u0026package-id=5e22b39e8cb919f6",
261098          "supplier": {},
261099          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
261100          "name": "libhogweed6",
261101          "version": "3.7.3-1",
261102          "licenses": [
261103            {
261104              "license": {
261105                "name": "Expat"
261106              }
261107            },
261108            {
261109              "license": {
261110                "name": "GAP"
261111              }
261112            },
261113            {
261114              "license": {
261115                "name": "GPL"
261116              }
261117            },
261118            {
261119              "license": {
261120                "id": "GPL-2.0-only"
261121              }
261122            },
261123            {
261124              "license": {
261125                "id": "GPL-2.0-or-later"
261126              }
261127            },
261128            {
261129              "license": {
261130                "id": "GPL-3.0-or-later"
261131              }
261132            },
261133            {
261134              "license": {
261135                "name": "LGPL"
261136              }
261137            },
261138            {
261139              "license": {
261140                "id": "LGPL-2.0-only"
261141              }
261142            },
261143            {
261144              "license": {
261145                "id": "LGPL-2.0-or-later"
261146              }
261147            },
261148            {
261149              "license": {
261150                "id": "LGPL-3.0-or-later"
261151              }
261152            },
261153            {
261154              "license": {
261155                "name": "public-domain"
261156              }
261157            }
261158          ],
261159          "cpe": "cpe:2.3:a:libhogweed6:libhogweed6:3.7.3-1:*:*:*:*:*:*:*",
261160          "purl": "pkg:deb/debian/libhogweed6@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11",
261161          "swid": {
261162            "attachment": {}
261163          },
261164          "pedigree": {},
261165          "evidence": {},
261166          "signature": {
261167            "signature": {
261168              "publicKey": {}
261169            }
261170          },
261171          "modelCard": {
261172            "modelParameters": {
261173              "approach": {}
261174            },
261175            "quantitativeAnalysis": {
261176              "graphics": {}
261177            },
261178            "considerations": {}
261179          }
261180        },
261181        {
261182          "type": "library",
261183          "bom-ref": "pkg:deb/debian/libhttp-parser2.9@2.9.4-4+deb11u1?arch=amd64\u0026upstream=http-parser\u0026distro=debian-11\u0026package-id=741ccf3f007628b8",
261184          "supplier": {},
261185          "publisher": "Christoph Biedl \u003cdebian.axhn@manchmal.in-ulm.de\u003e",
261186          "name": "libhttp-parser2.9",
261187          "version": "2.9.4-4+deb11u1",
261188          "licenses": [
261189            {
261190              "license": {
261191                "name": "Expat"
261192              }
261193            },
261194            {
261195              "license": {
261196                "name": "Expat-nginx"
261197              }
261198            }
261199          ],
261200          "cpe": "cpe:2.3:a:libhttp-parser2.9:libhttp-parser2.9:2.9.4-4\\+deb11u1:*:*:*:*:*:*:*",
261201          "purl": "pkg:deb/debian/libhttp-parser2.9@2.9.4-4+deb11u1?arch=amd64\u0026upstream=http-parser\u0026distro=debian-11",
261202          "swid": {
261203            "attachment": {}
261204          },
261205          "pedigree": {},
261206          "evidence": {},
261207          "signature": {
261208            "signature": {
261209              "publicKey": {}
261210            }
261211          },
261212          "modelCard": {
261213            "modelParameters": {
261214              "approach": {}
261215            },
261216            "quantitativeAnalysis": {
261217              "graphics": {}
261218            },
261219            "considerations": {}
261220          }
261221        },
261222        {
261223          "type": "library",
261224          "bom-ref": "pkg:deb/debian/libicu67@67.1-7?arch=amd64\u0026upstream=icu\u0026distro=debian-11\u0026package-id=52bb142f2f6f57d4",
261225          "supplier": {},
261226          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
261227          "name": "libicu67",
261228          "version": "67.1-7",
261229          "cpe": "cpe:2.3:a:libicu67:libicu67:67.1-7:*:*:*:*:*:*:*",
261230          "purl": "pkg:deb/debian/libicu67@67.1-7?arch=amd64\u0026upstream=icu\u0026distro=debian-11",
261231          "swid": {
261232            "attachment": {}
261233          },
261234          "pedigree": {},
261235          "evidence": {},
261236          "signature": {
261237            "signature": {
261238              "publicKey": {}
261239            }
261240          },
261241          "modelCard": {
261242            "modelParameters": {
261243              "approach": {}
261244            },
261245            "quantitativeAnalysis": {
261246              "graphics": {}
261247            },
261248            "considerations": {}
261249          }
261250        },
261251        {
261252          "type": "library",
261253          "bom-ref": "pkg:deb/debian/libidn2-0@2.3.0-5?arch=amd64\u0026upstream=libidn2\u0026distro=debian-11\u0026package-id=8eb1c8304ad48ef2",
261254          "supplier": {},
261255          "publisher": "Debian Libidn team \u003chelp-libidn@gnu.org\u003e",
261256          "name": "libidn2-0",
261257          "version": "2.3.0-5",
261258          "licenses": [
261259            {
261260              "license": {
261261                "id": "GPL-2.0-only"
261262              }
261263            },
261264            {
261265              "license": {
261266                "id": "GPL-2.0-or-later"
261267              }
261268            },
261269            {
261270              "license": {
261271                "id": "GPL-3.0-only"
261272              }
261273            },
261274            {
261275              "license": {
261276                "id": "GPL-3.0-or-later"
261277              }
261278            },
261279            {
261280              "license": {
261281                "id": "LGPL-3.0-only"
261282              }
261283            },
261284            {
261285              "license": {
261286                "id": "LGPL-3.0-or-later"
261287              }
261288            },
261289            {
261290              "license": {
261291                "name": "Unicode"
261292              }
261293            }
261294          ],
261295          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.3.0-5:*:*:*:*:*:*:*",
261296          "purl": "pkg:deb/debian/libidn2-0@2.3.0-5?arch=amd64\u0026upstream=libidn2\u0026distro=debian-11",
261297          "swid": {
261298            "attachment": {}
261299          },
261300          "pedigree": {},
261301          "evidence": {},
261302          "signature": {
261303            "signature": {
261304              "publicKey": {}
261305            }
261306          },
261307          "modelCard": {
261308            "modelParameters": {
261309              "approach": {}
261310            },
261311            "quantitativeAnalysis": {
261312              "graphics": {}
261313            },
261314            "considerations": {}
261315          }
261316        },
261317        {
261318          "type": "library",
261319          "bom-ref": "pkg:deb/debian/libipt2@2.0.3-1?arch=amd64\u0026upstream=intel-processor-trace\u0026distro=debian-11\u0026package-id=1d478f1cfa95ed86",
261320          "supplier": {},
261321          "publisher": "Victor Seva \u003cvseva@debian.org\u003e",
261322          "name": "libipt2",
261323          "version": "2.0.3-1",
261324          "licenses": [
261325            {
261326              "license": {
261327                "name": "Expat"
261328              }
261329            }
261330          ],
261331          "cpe": "cpe:2.3:a:libipt2:libipt2:2.0.3-1:*:*:*:*:*:*:*",
261332          "purl": "pkg:deb/debian/libipt2@2.0.3-1?arch=amd64\u0026upstream=intel-processor-trace\u0026distro=debian-11",
261333          "swid": {
261334            "attachment": {}
261335          },
261336          "pedigree": {},
261337          "evidence": {},
261338          "signature": {
261339            "signature": {
261340              "publicKey": {}
261341            }
261342          },
261343          "modelCard": {
261344            "modelParameters": {
261345              "approach": {}
261346            },
261347            "quantitativeAnalysis": {
261348              "graphics": {}
261349            },
261350            "considerations": {}
261351          }
261352        },
261353        {
261354          "type": "library",
261355          "bom-ref": "pkg:deb/debian/libisl23@0.23-1?arch=amd64\u0026upstream=isl\u0026distro=debian-11\u0026package-id=6678b90c2b92f785",
261356          "supplier": {},
261357          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
261358          "name": "libisl23",
261359          "version": "0.23-1",
261360          "licenses": [
261361            {
261362              "license": {
261363                "id": "BSD-2-Clause"
261364              }
261365            },
261366            {
261367              "license": {
261368                "id": "LGPL-2.0-only"
261369              }
261370            },
261371            {
261372              "license": {
261373                "id": "LGPL-2.1-or-later"
261374              }
261375            },
261376            {
261377              "license": {
261378                "id": "MIT"
261379              }
261380            }
261381          ],
261382          "cpe": "cpe:2.3:a:libisl23:libisl23:0.23-1:*:*:*:*:*:*:*",
261383          "purl": "pkg:deb/debian/libisl23@0.23-1?arch=amd64\u0026upstream=isl\u0026distro=debian-11",
261384          "swid": {
261385            "attachment": {}
261386          },
261387          "pedigree": {},
261388          "evidence": {},
261389          "signature": {
261390            "signature": {
261391              "publicKey": {}
261392            }
261393          },
261394          "modelCard": {
261395            "modelParameters": {
261396              "approach": {}
261397            },
261398            "quantitativeAnalysis": {
261399              "graphics": {}
261400            },
261401            "considerations": {}
261402          }
261403        },
261404        {
261405          "type": "library",
261406          "bom-ref": "pkg:deb/debian/libitm1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=879d46ac73134aff",
261407          "supplier": {},
261408          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
261409          "name": "libitm1",
261410          "version": "10.2.1-6",
261411          "licenses": [
261412            {
261413              "license": {
261414                "name": "Artistic"
261415              }
261416            },
261417            {
261418              "license": {
261419                "id": "GFDL-1.2-only"
261420              }
261421            },
261422            {
261423              "license": {
261424                "name": "GPL"
261425              }
261426            },
261427            {
261428              "license": {
261429                "id": "GPL-2.0-only"
261430              }
261431            },
261432            {
261433              "license": {
261434                "id": "GPL-3.0-only"
261435              }
261436            },
261437            {
261438              "license": {
261439                "name": "LGPL"
261440              }
261441            }
261442          ],
261443          "cpe": "cpe:2.3:a:libitm1:libitm1:10.2.1-6:*:*:*:*:*:*:*",
261444          "purl": "pkg:deb/debian/libitm1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
261445          "swid": {
261446            "attachment": {}
261447          },
261448          "pedigree": {},
261449          "evidence": {},
261450          "signature": {
261451            "signature": {
261452              "publicKey": {}
261453            }
261454          },
261455          "modelCard": {
261456            "modelParameters": {
261457              "approach": {}
261458            },
261459            "quantitativeAnalysis": {
261460              "graphics": {}
261461            },
261462            "considerations": {}
261463          }
261464        },
261465        {
261466          "type": "library",
261467          "bom-ref": "pkg:deb/debian/libjansson4@2.13.1-1.1?arch=amd64\u0026upstream=jansson\u0026distro=debian-11\u0026package-id=dd055046a425296c",
261468          "supplier": {},
261469          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
261470          "name": "libjansson4",
261471          "version": "2.13.1-1.1",
261472          "licenses": [
261473            {
261474              "license": {
261475                "name": "Expat"
261476              }
261477            }
261478          ],
261479          "cpe": "cpe:2.3:a:libjansson4:libjansson4:2.13.1-1.1:*:*:*:*:*:*:*",
261480          "purl": "pkg:deb/debian/libjansson4@2.13.1-1.1?arch=amd64\u0026upstream=jansson\u0026distro=debian-11",
261481          "swid": {
261482            "attachment": {}
261483          },
261484          "pedigree": {},
261485          "evidence": {},
261486          "signature": {
261487            "signature": {
261488              "publicKey": {}
261489            }
261490          },
261491          "modelCard": {
261492            "modelParameters": {
261493              "approach": {}
261494            },
261495            "quantitativeAnalysis": {
261496              "graphics": {}
261497            },
261498            "considerations": {}
261499          }
261500        },
261501        {
261502          "type": "library",
261503          "bom-ref": "pkg:deb/debian/libjbig0@2.1-3.1+b2?arch=amd64\u0026upstream=jbigkit%402.1-3.1\u0026distro=debian-11\u0026package-id=ccf2e13886894508",
261504          "supplier": {},
261505          "publisher": "Michael van der Kolff \u003cmvanderkolff@gmail.com\u003e",
261506          "name": "libjbig0",
261507          "version": "2.1-3.1+b2",
261508          "licenses": [
261509            {
261510              "license": {
261511                "id": "GPL-2.0-only"
261512              }
261513            },
261514            {
261515              "license": {
261516                "id": "GPL-2.0-or-later"
261517              }
261518            }
261519          ],
261520          "cpe": "cpe:2.3:a:libjbig0:libjbig0:2.1-3.1\\+b2:*:*:*:*:*:*:*",
261521          "purl": "pkg:deb/debian/libjbig0@2.1-3.1+b2?arch=amd64\u0026upstream=jbigkit%402.1-3.1\u0026distro=debian-11",
261522          "swid": {
261523            "attachment": {}
261524          },
261525          "pedigree": {},
261526          "evidence": {},
261527          "signature": {
261528            "signature": {
261529              "publicKey": {}
261530            }
261531          },
261532          "modelCard": {
261533            "modelParameters": {
261534              "approach": {}
261535            },
261536            "quantitativeAnalysis": {
261537              "graphics": {}
261538            },
261539            "considerations": {}
261540          }
261541        },
261542        {
261543          "type": "library",
261544          "bom-ref": "pkg:deb/debian/libjpeg62-turbo@1:2.0.6-4?arch=amd64\u0026upstream=libjpeg-turbo\u0026distro=debian-11\u0026package-id=2e17533511143831",
261545          "supplier": {},
261546          "publisher": "Ondřej Surý \u003condrej@debian.org\u003e",
261547          "name": "libjpeg62-turbo",
261548          "version": "1:2.0.6-4",
261549          "licenses": [
261550            {
261551              "license": {
261552                "name": "BSD-3"
261553              }
261554            },
261555            {
261556              "license": {
261557                "name": "BSD-BY-LC-NE"
261558              }
261559            },
261560            {
261561              "license": {
261562                "name": "Expat"
261563              }
261564            },
261565            {
261566              "license": {
261567                "id": "NTP"
261568              }
261569            },
261570            {
261571              "license": {
261572                "id": "Zlib"
261573              }
261574            }
261575          ],
261576          "cpe": "cpe:2.3:a:libjpeg62-turbo:libjpeg62-turbo:1\\:2.0.6-4:*:*:*:*:*:*:*",
261577          "purl": "pkg:deb/debian/libjpeg62-turbo@1:2.0.6-4?arch=amd64\u0026upstream=libjpeg-turbo\u0026distro=debian-11",
261578          "swid": {
261579            "attachment": {}
261580          },
261581          "pedigree": {},
261582          "evidence": {},
261583          "signature": {
261584            "signature": {
261585              "publicKey": {}
261586            }
261587          },
261588          "modelCard": {
261589            "modelParameters": {
261590              "approach": {}
261591            },
261592            "quantitativeAnalysis": {
261593              "graphics": {}
261594            },
261595            "considerations": {}
261596          }
261597        },
261598        {
261599          "type": "library",
261600          "bom-ref": "pkg:deb/debian/libjq1@1.6-2.1?arch=amd64\u0026upstream=jq\u0026distro=debian-11\u0026package-id=35feed02a5ab7792",
261601          "supplier": {},
261602          "publisher": "ChangZhuo Chen (陳昌倬) \u003cczchen@debian.org\u003e",
261603          "name": "libjq1",
261604          "version": "1.6-2.1",
261605          "licenses": [
261606            {
261607              "license": {
261608                "id": "CC-BY-3.0"
261609              }
261610            },
261611            {
261612              "license": {
261613                "name": "Expat"
261614              }
261615            },
261616            {
261617              "license": {
261618                "id": "GPL-2.0-only"
261619              }
261620            },
261621            {
261622              "license": {
261623                "id": "GPL-2.0-or-later"
261624              }
261625            },
261626            {
261627              "license": {
261628                "id": "MIT"
261629              }
261630            }
261631          ],
261632          "cpe": "cpe:2.3:a:libjq1:libjq1:1.6-2.1:*:*:*:*:*:*:*",
261633          "purl": "pkg:deb/debian/libjq1@1.6-2.1?arch=amd64\u0026upstream=jq\u0026distro=debian-11",
261634          "swid": {
261635            "attachment": {}
261636          },
261637          "pedigree": {},
261638          "evidence": {},
261639          "signature": {
261640            "signature": {
261641              "publicKey": {}
261642            }
261643          },
261644          "modelCard": {
261645            "modelParameters": {
261646              "approach": {}
261647            },
261648            "quantitativeAnalysis": {
261649              "graphics": {}
261650            },
261651            "considerations": {}
261652          }
261653        },
261654        {
261655          "type": "library",
261656          "bom-ref": "pkg:deb/debian/libjson-c5@0.15-2?arch=amd64\u0026upstream=json-c\u0026distro=debian-11\u0026package-id=578da518c638c2b0",
261657          "supplier": {},
261658          "publisher": "Nicolas Mora \u003cbabelouest@debian.org\u003e",
261659          "name": "libjson-c5",
261660          "version": "0.15-2",
261661          "licenses": [
261662            {
261663              "license": {
261664                "name": "Expat"
261665              }
261666            }
261667          ],
261668          "cpe": "cpe:2.3:a:libjson-c5:libjson-c5:0.15-2:*:*:*:*:*:*:*",
261669          "purl": "pkg:deb/debian/libjson-c5@0.15-2?arch=amd64\u0026upstream=json-c\u0026distro=debian-11",
261670          "swid": {
261671            "attachment": {}
261672          },
261673          "pedigree": {},
261674          "evidence": {},
261675          "signature": {
261676            "signature": {
261677              "publicKey": {}
261678            }
261679          },
261680          "modelCard": {
261681            "modelParameters": {
261682              "approach": {}
261683            },
261684            "quantitativeAnalysis": {
261685              "graphics": {}
261686            },
261687            "considerations": {}
261688          }
261689        },
261690        {
261691          "type": "library",
261692          "bom-ref": "pkg:deb/debian/libk5crypto3@1.18.3-6+deb11u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=2c74d8b8e84dd04b",
261693          "supplier": {},
261694          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
261695          "name": "libk5crypto3",
261696          "version": "1.18.3-6+deb11u2",
261697          "licenses": [
261698            {
261699              "license": {
261700                "id": "GPL-2.0-only"
261701              }
261702            }
261703          ],
261704          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.18.3-6\\+deb11u2:*:*:*:*:*:*:*",
261705          "purl": "pkg:deb/debian/libk5crypto3@1.18.3-6+deb11u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
261706          "swid": {
261707            "attachment": {}
261708          },
261709          "pedigree": {},
261710          "evidence": {},
261711          "signature": {
261712            "signature": {
261713              "publicKey": {}
261714            }
261715          },
261716          "modelCard": {
261717            "modelParameters": {
261718              "approach": {}
261719            },
261720            "quantitativeAnalysis": {
261721              "graphics": {}
261722            },
261723            "considerations": {}
261724          }
261725        },
261726        {
261727          "type": "library",
261728          "bom-ref": "pkg:deb/debian/libkeyutils1@1.6.1-2?arch=amd64\u0026upstream=keyutils\u0026distro=debian-11\u0026package-id=308487f5f23bf878",
261729          "supplier": {},
261730          "publisher": "Christian Kastner \u003cckk@debian.org\u003e",
261731          "name": "libkeyutils1",
261732          "version": "1.6.1-2",
261733          "licenses": [
261734            {
261735              "license": {
261736                "id": "GPL-2.0-only"
261737              }
261738            },
261739            {
261740              "license": {
261741                "id": "GPL-2.0-or-later"
261742              }
261743            },
261744            {
261745              "license": {
261746                "id": "LGPL-2.0-only"
261747              }
261748            },
261749            {
261750              "license": {
261751                "id": "LGPL-2.0-or-later"
261752              }
261753            }
261754          ],
261755          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6.1-2:*:*:*:*:*:*:*",
261756          "purl": "pkg:deb/debian/libkeyutils1@1.6.1-2?arch=amd64\u0026upstream=keyutils\u0026distro=debian-11",
261757          "swid": {
261758            "attachment": {}
261759          },
261760          "pedigree": {},
261761          "evidence": {},
261762          "signature": {
261763            "signature": {
261764              "publicKey": {}
261765            }
261766          },
261767          "modelCard": {
261768            "modelParameters": {
261769              "approach": {}
261770            },
261771            "quantitativeAnalysis": {
261772              "graphics": {}
261773            },
261774            "considerations": {}
261775          }
261776        },
261777        {
261778          "type": "library",
261779          "bom-ref": "pkg:deb/debian/libkmod2@28-1?arch=amd64\u0026upstream=kmod\u0026distro=debian-11\u0026package-id=5e06037b7cd9c087",
261780          "supplier": {},
261781          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
261782          "name": "libkmod2",
261783          "version": "28-1",
261784          "licenses": [
261785            {
261786              "license": {
261787                "id": "GPL-2.0-only"
261788              }
261789            }
261790          ],
261791          "cpe": "cpe:2.3:a:libkmod2:libkmod2:28-1:*:*:*:*:*:*:*",
261792          "purl": "pkg:deb/debian/libkmod2@28-1?arch=amd64\u0026upstream=kmod\u0026distro=debian-11",
261793          "swid": {
261794            "attachment": {}
261795          },
261796          "pedigree": {},
261797          "evidence": {},
261798          "signature": {
261799            "signature": {
261800              "publicKey": {}
261801            }
261802          },
261803          "modelCard": {
261804            "modelParameters": {
261805              "approach": {}
261806            },
261807            "quantitativeAnalysis": {
261808              "graphics": {}
261809            },
261810            "considerations": {}
261811          }
261812        },
261813        {
261814          "type": "library",
261815          "bom-ref": "pkg:deb/debian/libkrb5-3@1.18.3-6+deb11u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=74e136490fc32e51",
261816          "supplier": {},
261817          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
261818          "name": "libkrb5-3",
261819          "version": "1.18.3-6+deb11u2",
261820          "licenses": [
261821            {
261822              "license": {
261823                "id": "GPL-2.0-only"
261824              }
261825            }
261826          ],
261827          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.18.3-6\\+deb11u2:*:*:*:*:*:*:*",
261828          "purl": "pkg:deb/debian/libkrb5-3@1.18.3-6+deb11u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
261829          "swid": {
261830            "attachment": {}
261831          },
261832          "pedigree": {},
261833          "evidence": {},
261834          "signature": {
261835            "signature": {
261836              "publicKey": {}
261837            }
261838          },
261839          "modelCard": {
261840            "modelParameters": {
261841              "approach": {}
261842            },
261843            "quantitativeAnalysis": {
261844              "graphics": {}
261845            },
261846            "considerations": {}
261847          }
261848        },
261849        {
261850          "type": "library",
261851          "bom-ref": "pkg:deb/debian/libkrb5support0@1.18.3-6+deb11u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=6e5b5ddd0b83ce02",
261852          "supplier": {},
261853          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
261854          "name": "libkrb5support0",
261855          "version": "1.18.3-6+deb11u2",
261856          "licenses": [
261857            {
261858              "license": {
261859                "id": "GPL-2.0-only"
261860              }
261861            }
261862          ],
261863          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.18.3-6\\+deb11u2:*:*:*:*:*:*:*",
261864          "purl": "pkg:deb/debian/libkrb5support0@1.18.3-6+deb11u2?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
261865          "swid": {
261866            "attachment": {}
261867          },
261868          "pedigree": {},
261869          "evidence": {},
261870          "signature": {
261871            "signature": {
261872              "publicKey": {}
261873            }
261874          },
261875          "modelCard": {
261876            "modelParameters": {
261877              "approach": {}
261878            },
261879            "quantitativeAnalysis": {
261880              "graphics": {}
261881            },
261882            "considerations": {}
261883          }
261884        },
261885        {
261886          "type": "library",
261887          "bom-ref": "pkg:deb/debian/libldap-2.4-2@2.4.57+dfsg-3+deb11u1?arch=amd64\u0026upstream=openldap\u0026distro=debian-11\u0026package-id=796a192b709a2a2b",
261888          "supplier": {},
261889          "publisher": "Debian OpenLDAP Maintainers \u003cpkg-openldap-devel@lists.alioth.debian.org\u003e",
261890          "name": "libldap-2.4-2",
261891          "version": "2.4.57+dfsg-3+deb11u1",
261892          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.57\\+dfsg-3\\+deb11u1:*:*:*:*:*:*:*",
261893          "purl": "pkg:deb/debian/libldap-2.4-2@2.4.57+dfsg-3+deb11u1?arch=amd64\u0026upstream=openldap\u0026distro=debian-11",
261894          "swid": {
261895            "attachment": {}
261896          },
261897          "pedigree": {},
261898          "evidence": {},
261899          "signature": {
261900            "signature": {
261901              "publicKey": {}
261902            }
261903          },
261904          "modelCard": {
261905            "modelParameters": {
261906              "approach": {}
261907            },
261908            "quantitativeAnalysis": {
261909              "graphics": {}
261910            },
261911            "considerations": {}
261912          }
261913        },
261914        {
261915          "type": "library",
261916          "bom-ref": "pkg:deb/debian/liblinear4@2.3.0+dfsg-5?arch=amd64\u0026upstream=liblinear\u0026distro=debian-11\u0026package-id=77ce23fef5f89dc5",
261917          "supplier": {},
261918          "publisher": "Debian Science Maintainers \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e",
261919          "name": "liblinear4",
261920          "version": "2.3.0+dfsg-5",
261921          "licenses": [
261922            {
261923              "license": {
261924                "id": "BSD-3-Clause"
261925              }
261926            }
261927          ],
261928          "cpe": "cpe:2.3:a:liblinear4:liblinear4:2.3.0\\+dfsg-5:*:*:*:*:*:*:*",
261929          "purl": "pkg:deb/debian/liblinear4@2.3.0+dfsg-5?arch=amd64\u0026upstream=liblinear\u0026distro=debian-11",
261930          "swid": {
261931            "attachment": {}
261932          },
261933          "pedigree": {},
261934          "evidence": {},
261935          "signature": {
261936            "signature": {
261937              "publicKey": {}
261938            }
261939          },
261940          "modelCard": {
261941            "modelParameters": {
261942              "approach": {}
261943            },
261944            "quantitativeAnalysis": {
261945              "graphics": {}
261946            },
261947            "considerations": {}
261948          }
261949        },
261950        {
261951          "type": "library",
261952          "bom-ref": "pkg:deb/debian/liblmdb0@0.9.24-1?arch=amd64\u0026upstream=lmdb\u0026distro=debian-11\u0026package-id=cfbf2c4fd501829d",
261953          "supplier": {},
261954          "publisher": "LMDB \u003clmdb@packages.debian.org\u003e",
261955          "name": "liblmdb0",
261956          "version": "0.9.24-1",
261957          "licenses": [
261958            {
261959              "license": {
261960                "name": "OpenLDAP-2.8"
261961              }
261962            }
261963          ],
261964          "cpe": "cpe:2.3:a:liblmdb0:liblmdb0:0.9.24-1:*:*:*:*:*:*:*",
261965          "purl": "pkg:deb/debian/liblmdb0@0.9.24-1?arch=amd64\u0026upstream=lmdb\u0026distro=debian-11",
261966          "swid": {
261967            "attachment": {}
261968          },
261969          "pedigree": {},
261970          "evidence": {},
261971          "signature": {
261972            "signature": {
261973              "publicKey": {}
261974            }
261975          },
261976          "modelCard": {
261977            "modelParameters": {
261978              "approach": {}
261979            },
261980            "quantitativeAnalysis": {
261981              "graphics": {}
261982            },
261983            "considerations": {}
261984          }
261985        },
261986        {
261987          "type": "library",
261988          "bom-ref": "pkg:deb/debian/liblsan0@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=e282c94440156007",
261989          "supplier": {},
261990          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
261991          "name": "liblsan0",
261992          "version": "10.2.1-6",
261993          "licenses": [
261994            {
261995              "license": {
261996                "name": "Artistic"
261997              }
261998            },
261999            {
262000              "license": {
262001                "id": "GFDL-1.2-only"
262002              }
262003            },
262004            {
262005              "license": {
262006                "name": "GPL"
262007              }
262008            },
262009            {
262010              "license": {
262011                "id": "GPL-2.0-only"
262012              }
262013            },
262014            {
262015              "license": {
262016                "id": "GPL-3.0-only"
262017              }
262018            },
262019            {
262020              "license": {
262021                "name": "LGPL"
262022              }
262023            }
262024          ],
262025          "cpe": "cpe:2.3:a:liblsan0:liblsan0:10.2.1-6:*:*:*:*:*:*:*",
262026          "purl": "pkg:deb/debian/liblsan0@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
262027          "swid": {
262028            "attachment": {}
262029          },
262030          "pedigree": {},
262031          "evidence": {},
262032          "signature": {
262033            "signature": {
262034              "publicKey": {}
262035            }
262036          },
262037          "modelCard": {
262038            "modelParameters": {
262039              "approach": {}
262040            },
262041            "quantitativeAnalysis": {
262042              "graphics": {}
262043            },
262044            "considerations": {}
262045          }
262046        },
262047        {
262048          "type": "library",
262049          "bom-ref": "pkg:deb/debian/liblua5.3-0@5.3.3-1.1+b1?arch=amd64\u0026upstream=lua5.3%405.3.3-1.1\u0026distro=debian-11\u0026package-id=92a6d9ca129f4c8",
262050          "supplier": {},
262051          "publisher": "Enrico Tassi \u003cgareuselesinge@debian.org\u003e",
262052          "name": "liblua5.3-0",
262053          "version": "5.3.3-1.1+b1",
262054          "licenses": [
262055            {
262056              "license": {
262057                "name": "Expat"
262058              }
262059            }
262060          ],
262061          "cpe": "cpe:2.3:a:liblua5.3-0:liblua5.3-0:5.3.3-1.1\\+b1:*:*:*:*:*:*:*",
262062          "purl": "pkg:deb/debian/liblua5.3-0@5.3.3-1.1+b1?arch=amd64\u0026upstream=lua5.3%405.3.3-1.1\u0026distro=debian-11",
262063          "swid": {
262064            "attachment": {}
262065          },
262066          "pedigree": {},
262067          "evidence": {},
262068          "signature": {
262069            "signature": {
262070              "publicKey": {}
262071            }
262072          },
262073          "modelCard": {
262074            "modelParameters": {
262075              "approach": {}
262076            },
262077            "quantitativeAnalysis": {
262078              "graphics": {}
262079            },
262080            "considerations": {}
262081          }
262082        },
262083        {
262084          "type": "library",
262085          "bom-ref": "pkg:deb/debian/liblz4-1@1.9.3-2?arch=amd64\u0026upstream=lz4\u0026distro=debian-11\u0026package-id=b59e208fb7f8bae4",
262086          "supplier": {},
262087          "publisher": "Nobuhiro Iwamatsu \u003ciwamatsu@debian.org\u003e",
262088          "name": "liblz4-1",
262089          "version": "1.9.3-2",
262090          "licenses": [
262091            {
262092              "license": {
262093                "id": "BSD-2-Clause"
262094              }
262095            },
262096            {
262097              "license": {
262098                "id": "GPL-2.0-only"
262099              }
262100            },
262101            {
262102              "license": {
262103                "id": "GPL-2.0-or-later"
262104              }
262105            }
262106          ],
262107          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.3-2:*:*:*:*:*:*:*",
262108          "purl": "pkg:deb/debian/liblz4-1@1.9.3-2?arch=amd64\u0026upstream=lz4\u0026distro=debian-11",
262109          "swid": {
262110            "attachment": {}
262111          },
262112          "pedigree": {},
262113          "evidence": {},
262114          "signature": {
262115            "signature": {
262116              "publicKey": {}
262117            }
262118          },
262119          "modelCard": {
262120            "modelParameters": {
262121              "approach": {}
262122            },
262123            "quantitativeAnalysis": {
262124              "graphics": {}
262125            },
262126            "considerations": {}
262127          }
262128        },
262129        {
262130          "type": "library",
262131          "bom-ref": "pkg:deb/debian/liblzma5@5.2.5-2.1~deb11u1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-11\u0026package-id=b95662a389d30c72",
262132          "supplier": {},
262133          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
262134          "name": "liblzma5",
262135          "version": "5.2.5-2.1~deb11u1",
262136          "licenses": [
262137            {
262138              "license": {
262139                "name": "Autoconf"
262140              }
262141            },
262142            {
262143              "license": {
262144                "id": "GPL-2.0-only"
262145              }
262146            },
262147            {
262148              "license": {
262149                "id": "GPL-2.0-or-later"
262150              }
262151            },
262152            {
262153              "license": {
262154                "id": "GPL-3.0-only"
262155              }
262156            },
262157            {
262158              "license": {
262159                "id": "LGPL-2.0-only"
262160              }
262161            },
262162            {
262163              "license": {
262164                "id": "LGPL-2.1-only"
262165              }
262166            },
262167            {
262168              "license": {
262169                "id": "LGPL-2.1-or-later"
262170              }
262171            },
262172            {
262173              "license": {
262174                "name": "PD"
262175              }
262176            },
262177            {
262178              "license": {
262179                "name": "PD-debian"
262180              }
262181            },
262182            {
262183              "license": {
262184                "name": "config-h"
262185              }
262186            },
262187            {
262188              "license": {
262189                "name": "noderivs"
262190              }
262191            },
262192            {
262193              "license": {
262194                "name": "permissive-fsf"
262195              }
262196            },
262197            {
262198              "license": {
262199                "name": "permissive-nowarranty"
262200              }
262201            },
262202            {
262203              "license": {
262204                "name": "probably-PD"
262205              }
262206            }
262207          ],
262208          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.5-2.1\\~deb11u1:*:*:*:*:*:*:*",
262209          "purl": "pkg:deb/debian/liblzma5@5.2.5-2.1~deb11u1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-11",
262210          "swid": {
262211            "attachment": {}
262212          },
262213          "pedigree": {},
262214          "evidence": {},
262215          "signature": {
262216            "signature": {
262217              "publicKey": {}
262218            }
262219          },
262220          "modelCard": {
262221            "modelParameters": {
262222              "approach": {}
262223            },
262224            "quantitativeAnalysis": {
262225              "graphics": {}
262226            },
262227            "considerations": {}
262228          }
262229        },
262230        {
262231          "type": "library",
262232          "bom-ref": "pkg:deb/debian/libmaxminddb0@1.5.2-1?arch=amd64\u0026upstream=libmaxminddb\u0026distro=debian-11\u0026package-id=55e1638fcb0edbb2",
262233          "supplier": {},
262234          "publisher": "Faidon Liambotis \u003cparavoid@debian.org\u003e",
262235          "name": "libmaxminddb0",
262236          "version": "1.5.2-1",
262237          "licenses": [
262238            {
262239              "license": {
262240                "id": "Apache-2.0"
262241              }
262242            },
262243            {
262244              "license": {
262245                "id": "BSD-2-Clause"
262246              }
262247            },
262248            {
262249              "license": {
262250                "id": "CC-BY-SA-3.0"
262251              }
262252            },
262253            {
262254              "license": {
262255                "id": "GPL-2.0-only"
262256              }
262257            },
262258            {
262259              "license": {
262260                "id": "GPL-2.0-or-later"
262261              }
262262            }
262263          ],
262264          "cpe": "cpe:2.3:a:libmaxminddb0:libmaxminddb0:1.5.2-1:*:*:*:*:*:*:*",
262265          "purl": "pkg:deb/debian/libmaxminddb0@1.5.2-1?arch=amd64\u0026upstream=libmaxminddb\u0026distro=debian-11",
262266          "swid": {
262267            "attachment": {}
262268          },
262269          "pedigree": {},
262270          "evidence": {},
262271          "signature": {
262272            "signature": {
262273              "publicKey": {}
262274            }
262275          },
262276          "modelCard": {
262277            "modelParameters": {
262278              "approach": {}
262279            },
262280            "quantitativeAnalysis": {
262281              "graphics": {}
262282            },
262283            "considerations": {}
262284          }
262285        },
262286        {
262287          "type": "library",
262288          "bom-ref": "pkg:deb/debian/libmd0@1.0.3-3?arch=amd64\u0026upstream=libmd\u0026distro=debian-11\u0026package-id=331d8d42d5fc0777",
262289          "supplier": {},
262290          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
262291          "name": "libmd0",
262292          "version": "1.0.3-3",
262293          "licenses": [
262294            {
262295              "license": {
262296                "id": "BSD-2-Clause"
262297              }
262298            },
262299            {
262300              "license": {
262301                "id": "BSD-2-Clause"
262302              }
262303            },
262304            {
262305              "license": {
262306                "id": "BSD-3-Clause"
262307              }
262308            },
262309            {
262310              "license": {
262311                "name": "BSD-3-clause-Aaron-D-Gifford"
262312              }
262313            },
262314            {
262315              "license": {
262316                "id": "Beerware"
262317              }
262318            },
262319            {
262320              "license": {
262321                "id": "ISC"
262322              }
262323            },
262324            {
262325              "license": {
262326                "name": "public-domain-md4"
262327              }
262328            },
262329            {
262330              "license": {
262331                "name": "public-domain-md5"
262332              }
262333            },
262334            {
262335              "license": {
262336                "name": "public-domain-sha1"
262337              }
262338            }
262339          ],
262340          "cpe": "cpe:2.3:a:libmd0:libmd0:1.0.3-3:*:*:*:*:*:*:*",
262341          "purl": "pkg:deb/debian/libmd0@1.0.3-3?arch=amd64\u0026upstream=libmd\u0026distro=debian-11",
262342          "swid": {
262343            "attachment": {}
262344          },
262345          "pedigree": {},
262346          "evidence": {},
262347          "signature": {
262348            "signature": {
262349              "publicKey": {}
262350            }
262351          },
262352          "modelCard": {
262353            "modelParameters": {
262354              "approach": {}
262355            },
262356            "quantitativeAnalysis": {
262357              "graphics": {}
262358            },
262359            "considerations": {}
262360          }
262361        },
262362        {
262363          "type": "library",
262364          "bom-ref": "pkg:deb/debian/libmount1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=afd0c3536366dc2c",
262365          "supplier": {},
262366          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
262367          "name": "libmount1",
262368          "version": "2.36.1-8+deb11u1",
262369          "licenses": [
262370            {
262371              "license": {
262372                "id": "BSD-2-Clause"
262373              }
262374            },
262375            {
262376              "license": {
262377                "id": "BSD-3-Clause"
262378              }
262379            },
262380            {
262381              "license": {
262382                "id": "BSD-4-Clause"
262383              }
262384            },
262385            {
262386              "license": {
262387                "id": "GPL-2.0-only"
262388              }
262389            },
262390            {
262391              "license": {
262392                "id": "GPL-2.0-or-later"
262393              }
262394            },
262395            {
262396              "license": {
262397                "id": "GPL-3.0-only"
262398              }
262399            },
262400            {
262401              "license": {
262402                "id": "GPL-3.0-or-later"
262403              }
262404            },
262405            {
262406              "license": {
262407                "name": "LGPL"
262408              }
262409            },
262410            {
262411              "license": {
262412                "id": "LGPL-2.0-only"
262413              }
262414            },
262415            {
262416              "license": {
262417                "id": "LGPL-2.0-or-later"
262418              }
262419            },
262420            {
262421              "license": {
262422                "id": "LGPL-2.1-only"
262423              }
262424            },
262425            {
262426              "license": {
262427                "id": "LGPL-2.1-or-later"
262428              }
262429            },
262430            {
262431              "license": {
262432                "id": "LGPL-3.0-only"
262433              }
262434            },
262435            {
262436              "license": {
262437                "id": "LGPL-3.0-or-later"
262438              }
262439            },
262440            {
262441              "license": {
262442                "id": "MIT"
262443              }
262444            },
262445            {
262446              "license": {
262447                "name": "public-domain"
262448              }
262449            }
262450          ],
262451          "cpe": "cpe:2.3:a:libmount1:libmount1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
262452          "purl": "pkg:deb/debian/libmount1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
262453          "swid": {
262454            "attachment": {}
262455          },
262456          "pedigree": {},
262457          "evidence": {},
262458          "signature": {
262459            "signature": {
262460              "publicKey": {}
262461            }
262462          },
262463          "modelCard": {
262464            "modelParameters": {
262465              "approach": {}
262466            },
262467            "quantitativeAnalysis": {
262468              "graphics": {}
262469            },
262470            "considerations": {}
262471          }
262472        },
262473        {
262474          "type": "library",
262475          "bom-ref": "pkg:deb/debian/libmpc3@1.2.0-1?arch=amd64\u0026upstream=mpclib3\u0026distro=debian-11\u0026package-id=85fd2c8d9e7b2289",
262476          "supplier": {},
262477          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
262478          "name": "libmpc3",
262479          "version": "1.2.0-1",
262480          "licenses": [
262481            {
262482              "license": {
262483                "id": "LGPL-3.0-only"
262484              }
262485            }
262486          ],
262487          "cpe": "cpe:2.3:a:libmpc3:libmpc3:1.2.0-1:*:*:*:*:*:*:*",
262488          "purl": "pkg:deb/debian/libmpc3@1.2.0-1?arch=amd64\u0026upstream=mpclib3\u0026distro=debian-11",
262489          "swid": {
262490            "attachment": {}
262491          },
262492          "pedigree": {},
262493          "evidence": {},
262494          "signature": {
262495            "signature": {
262496              "publicKey": {}
262497            }
262498          },
262499          "modelCard": {
262500            "modelParameters": {
262501              "approach": {}
262502            },
262503            "quantitativeAnalysis": {
262504              "graphics": {}
262505            },
262506            "considerations": {}
262507          }
262508        },
262509        {
262510          "type": "library",
262511          "bom-ref": "pkg:deb/debian/libmpdec3@2.5.1-1?arch=amd64\u0026upstream=mpdecimal\u0026distro=debian-11\u0026package-id=a54659e4774c2bea",
262512          "supplier": {},
262513          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
262514          "name": "libmpdec3",
262515          "version": "2.5.1-1",
262516          "licenses": [
262517            {
262518              "license": {
262519                "name": "BSD"
262520              }
262521            },
262522            {
262523              "license": {
262524                "id": "GPL-2.0-only"
262525              }
262526            },
262527            {
262528              "license": {
262529                "id": "GPL-2.0-or-later"
262530              }
262531            }
262532          ],
262533          "cpe": "cpe:2.3:a:libmpdec3:libmpdec3:2.5.1-1:*:*:*:*:*:*:*",
262534          "purl": "pkg:deb/debian/libmpdec3@2.5.1-1?arch=amd64\u0026upstream=mpdecimal\u0026distro=debian-11",
262535          "swid": {
262536            "attachment": {}
262537          },
262538          "pedigree": {},
262539          "evidence": {},
262540          "signature": {
262541            "signature": {
262542              "publicKey": {}
262543            }
262544          },
262545          "modelCard": {
262546            "modelParameters": {
262547              "approach": {}
262548            },
262549            "quantitativeAnalysis": {
262550              "graphics": {}
262551            },
262552            "considerations": {}
262553          }
262554        },
262555        {
262556          "type": "library",
262557          "bom-ref": "pkg:deb/debian/libmpfr6@4.1.0-3?arch=amd64\u0026upstream=mpfr4\u0026distro=debian-11\u0026package-id=25a396a34cfda6a8",
262558          "supplier": {},
262559          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
262560          "name": "libmpfr6",
262561          "version": "4.1.0-3",
262562          "licenses": [
262563            {
262564              "license": {
262565                "id": "LGPL-3.0-only"
262566              }
262567            }
262568          ],
262569          "cpe": "cpe:2.3:a:libmpfr6:libmpfr6:4.1.0-3:*:*:*:*:*:*:*",
262570          "purl": "pkg:deb/debian/libmpfr6@4.1.0-3?arch=amd64\u0026upstream=mpfr4\u0026distro=debian-11",
262571          "swid": {
262572            "attachment": {}
262573          },
262574          "pedigree": {},
262575          "evidence": {},
262576          "signature": {
262577            "signature": {
262578              "publicKey": {}
262579            }
262580          },
262581          "modelCard": {
262582            "modelParameters": {
262583              "approach": {}
262584            },
262585            "quantitativeAnalysis": {
262586              "graphics": {}
262587            },
262588            "considerations": {}
262589          }
262590        },
262591        {
262592          "type": "library",
262593          "bom-ref": "pkg:deb/debian/libncurses6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=f539b9c0b1c439cc",
262594          "supplier": {},
262595          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
262596          "name": "libncurses6",
262597          "version": "6.2+20201114-2",
262598          "licenses": [
262599            {
262600              "license": {
262601                "id": "BSD-3-Clause"
262602              }
262603            },
262604            {
262605              "license": {
262606                "name": "MIT/X11"
262607              }
262608            },
262609            {
262610              "license": {
262611                "id": "X11"
262612              }
262613            }
262614          ],
262615          "cpe": "cpe:2.3:a:libncurses6:libncurses6:6.2\\+20201114-2:*:*:*:*:*:*:*",
262616          "purl": "pkg:deb/debian/libncurses6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11",
262617          "swid": {
262618            "attachment": {}
262619          },
262620          "pedigree": {},
262621          "evidence": {},
262622          "signature": {
262623            "signature": {
262624              "publicKey": {}
262625            }
262626          },
262627          "modelCard": {
262628            "modelParameters": {
262629              "approach": {}
262630            },
262631            "quantitativeAnalysis": {
262632              "graphics": {}
262633            },
262634            "considerations": {}
262635          }
262636        },
262637        {
262638          "type": "library",
262639          "bom-ref": "pkg:deb/debian/libncursesw6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=9eba19a6d4dcd7de",
262640          "supplier": {},
262641          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
262642          "name": "libncursesw6",
262643          "version": "6.2+20201114-2",
262644          "licenses": [
262645            {
262646              "license": {
262647                "id": "BSD-3-Clause"
262648              }
262649            },
262650            {
262651              "license": {
262652                "name": "MIT/X11"
262653              }
262654            },
262655            {
262656              "license": {
262657                "id": "X11"
262658              }
262659            }
262660          ],
262661          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.2\\+20201114-2:*:*:*:*:*:*:*",
262662          "purl": "pkg:deb/debian/libncursesw6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11",
262663          "swid": {
262664            "attachment": {}
262665          },
262666          "pedigree": {},
262667          "evidence": {},
262668          "signature": {
262669            "signature": {
262670              "publicKey": {}
262671            }
262672          },
262673          "modelCard": {
262674            "modelParameters": {
262675              "approach": {}
262676            },
262677            "quantitativeAnalysis": {
262678              "graphics": {}
262679            },
262680            "considerations": {}
262681          }
262682        },
262683        {
262684          "type": "library",
262685          "bom-ref": "pkg:deb/debian/libnet1@1.1.6+dfsg-3.1?arch=amd64\u0026upstream=libnet\u0026distro=debian-11\u0026package-id=8fc9735913a7d9d2",
262686          "supplier": {},
262687          "publisher": "Stefanos Harhalakis \u003cv13@v13.gr\u003e",
262688          "name": "libnet1",
262689          "version": "1.1.6+dfsg-3.1",
262690          "licenses": [
262691            {
262692              "license": {
262693                "name": "BSD-2"
262694              }
262695            },
262696            {
262697              "license": {
262698                "name": "BSD-3"
262699              }
262700            },
262701            {
262702              "license": {
262703                "name": "BSD-4"
262704              }
262705            },
262706            {
262707              "license": {
262708                "name": "other"
262709              }
262710            }
262711          ],
262712          "cpe": "cpe:2.3:a:libnet1:libnet1:1.1.6\\+dfsg-3.1:*:*:*:*:*:*:*",
262713          "purl": "pkg:deb/debian/libnet1@1.1.6+dfsg-3.1?arch=amd64\u0026upstream=libnet\u0026distro=debian-11",
262714          "swid": {
262715            "attachment": {}
262716          },
262717          "pedigree": {},
262718          "evidence": {},
262719          "signature": {
262720            "signature": {
262721              "publicKey": {}
262722            }
262723          },
262724          "modelCard": {
262725            "modelParameters": {
262726              "approach": {}
262727            },
262728            "quantitativeAnalysis": {
262729              "graphics": {}
262730            },
262731            "considerations": {}
262732          }
262733        },
262734        {
262735          "type": "library",
262736          "bom-ref": "pkg:deb/debian/libnettle8@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11\u0026package-id=ceff94b390c9bf61",
262737          "supplier": {},
262738          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
262739          "name": "libnettle8",
262740          "version": "3.7.3-1",
262741          "licenses": [
262742            {
262743              "license": {
262744                "name": "Expat"
262745              }
262746            },
262747            {
262748              "license": {
262749                "name": "GAP"
262750              }
262751            },
262752            {
262753              "license": {
262754                "name": "GPL"
262755              }
262756            },
262757            {
262758              "license": {
262759                "id": "GPL-2.0-only"
262760              }
262761            },
262762            {
262763              "license": {
262764                "id": "GPL-2.0-or-later"
262765              }
262766            },
262767            {
262768              "license": {
262769                "id": "GPL-3.0-or-later"
262770              }
262771            },
262772            {
262773              "license": {
262774                "name": "LGPL"
262775              }
262776            },
262777            {
262778              "license": {
262779                "id": "LGPL-2.0-only"
262780              }
262781            },
262782            {
262783              "license": {
262784                "id": "LGPL-2.0-or-later"
262785              }
262786            },
262787            {
262788              "license": {
262789                "id": "LGPL-3.0-or-later"
262790              }
262791            },
262792            {
262793              "license": {
262794                "name": "public-domain"
262795              }
262796            }
262797          ],
262798          "cpe": "cpe:2.3:a:libnettle8:libnettle8:3.7.3-1:*:*:*:*:*:*:*",
262799          "purl": "pkg:deb/debian/libnettle8@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11",
262800          "swid": {
262801            "attachment": {}
262802          },
262803          "pedigree": {},
262804          "evidence": {},
262805          "signature": {
262806            "signature": {
262807              "publicKey": {}
262808            }
262809          },
262810          "modelCard": {
262811            "modelParameters": {
262812              "approach": {}
262813            },
262814            "quantitativeAnalysis": {
262815              "graphics": {}
262816            },
262817            "considerations": {}
262818          }
262819        },
262820        {
262821          "type": "library",
262822          "bom-ref": "pkg:deb/debian/libnghttp2-14@1.43.0-1?arch=amd64\u0026upstream=nghttp2\u0026distro=debian-11\u0026package-id=cfb81461ba0ee3f7",
262823          "supplier": {},
262824          "publisher": "Tomasz Buchert \u003ctomasz@debian.org\u003e",
262825          "name": "libnghttp2-14",
262826          "version": "1.43.0-1",
262827          "licenses": [
262828            {
262829              "license": {
262830                "id": "BSD-2-Clause"
262831              }
262832            },
262833            {
262834              "license": {
262835                "name": "Expat"
262836              }
262837            },
262838            {
262839              "license": {
262840                "id": "GPL-3.0-only"
262841              }
262842            },
262843            {
262844              "license": {
262845                "id": "GPL-3.0-or-later"
262846              }
262847            },
262848            {
262849              "license": {
262850                "id": "MIT"
262851              }
262852            },
262853            {
262854              "license": {
262855                "name": "SIL-OFL-1.1"
262856              }
262857            },
262858            {
262859              "license": {
262860                "name": "all-permissive"
262861              }
262862            }
262863          ],
262864          "cpe": "cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.43.0-1:*:*:*:*:*:*:*",
262865          "purl": "pkg:deb/debian/libnghttp2-14@1.43.0-1?arch=amd64\u0026upstream=nghttp2\u0026distro=debian-11",
262866          "swid": {
262867            "attachment": {}
262868          },
262869          "pedigree": {},
262870          "evidence": {},
262871          "signature": {
262872            "signature": {
262873              "publicKey": {}
262874            }
262875          },
262876          "modelCard": {
262877            "modelParameters": {
262878              "approach": {}
262879            },
262880            "quantitativeAnalysis": {
262881              "graphics": {}
262882            },
262883            "considerations": {}
262884          }
262885        },
262886        {
262887          "type": "library",
262888          "bom-ref": "pkg:deb/debian/libnl-3-200@3.4.0-1+b1?arch=amd64\u0026upstream=libnl3%403.4.0-1\u0026distro=debian-11\u0026package-id=ad90f043b9966ef2",
262889          "supplier": {},
262890          "publisher": "Heiko Stuebner \u003cmmind@debian.org\u003e",
262891          "name": "libnl-3-200",
262892          "version": "3.4.0-1+b1",
262893          "licenses": [
262894            {
262895              "license": {
262896                "id": "GPL-2.0-only"
262897              }
262898            },
262899            {
262900              "license": {
262901                "id": "LGPL-2.1-only"
262902              }
262903            }
262904          ],
262905          "cpe": "cpe:2.3:a:libnl-3-200:libnl-3-200:3.4.0-1\\+b1:*:*:*:*:*:*:*",
262906          "purl": "pkg:deb/debian/libnl-3-200@3.4.0-1+b1?arch=amd64\u0026upstream=libnl3%403.4.0-1\u0026distro=debian-11",
262907          "swid": {
262908            "attachment": {}
262909          },
262910          "pedigree": {},
262911          "evidence": {},
262912          "signature": {
262913            "signature": {
262914              "publicKey": {}
262915            }
262916          },
262917          "modelCard": {
262918            "modelParameters": {
262919              "approach": {}
262920            },
262921            "quantitativeAnalysis": {
262922              "graphics": {}
262923            },
262924            "considerations": {}
262925          }
262926        },
262927        {
262928          "type": "library",
262929          "bom-ref": "pkg:deb/debian/libnl-genl-3-200@3.4.0-1+b1?arch=amd64\u0026upstream=libnl3%403.4.0-1\u0026distro=debian-11\u0026package-id=77b7843058b162e5",
262930          "supplier": {},
262931          "publisher": "Heiko Stuebner \u003cmmind@debian.org\u003e",
262932          "name": "libnl-genl-3-200",
262933          "version": "3.4.0-1+b1",
262934          "licenses": [
262935            {
262936              "license": {
262937                "id": "GPL-2.0-only"
262938              }
262939            },
262940            {
262941              "license": {
262942                "id": "LGPL-2.1-only"
262943              }
262944            }
262945          ],
262946          "cpe": "cpe:2.3:a:libnl-genl-3-200:libnl-genl-3-200:3.4.0-1\\+b1:*:*:*:*:*:*:*",
262947          "purl": "pkg:deb/debian/libnl-genl-3-200@3.4.0-1+b1?arch=amd64\u0026upstream=libnl3%403.4.0-1\u0026distro=debian-11",
262948          "swid": {
262949            "attachment": {}
262950          },
262951          "pedigree": {},
262952          "evidence": {},
262953          "signature": {
262954            "signature": {
262955              "publicKey": {}
262956            }
262957          },
262958          "modelCard": {
262959            "modelParameters": {
262960              "approach": {}
262961            },
262962            "quantitativeAnalysis": {
262963              "graphics": {}
262964            },
262965            "considerations": {}
262966          }
262967        },
262968        {
262969          "type": "library",
262970          "bom-ref": "pkg:deb/debian/libnsl-dev@1.3.0-2?arch=amd64\u0026upstream=libnsl\u0026distro=debian-11\u0026package-id=272daa220241ae9c",
262971          "supplier": {},
262972          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
262973          "name": "libnsl-dev",
262974          "version": "1.3.0-2",
262975          "licenses": [
262976            {
262977              "license": {
262978                "id": "BSD-3-Clause"
262979              }
262980            },
262981            {
262982              "license": {
262983                "id": "GPL-2.0-only"
262984              }
262985            },
262986            {
262987              "license": {
262988                "name": "GPL-2+-autoconf-exception"
262989              }
262990            },
262991            {
262992              "license": {
262993                "name": "GPL-2+-libtool-exception"
262994              }
262995            },
262996            {
262997              "license": {
262998                "id": "GPL-3.0-only"
262999              }
263000            },
263001            {
263002              "license": {
263003                "name": "GPL-3+-autoconf-exception"
263004              }
263005            },
263006            {
263007              "license": {
263008                "id": "LGPL-2.1-only"
263009              }
263010            },
263011            {
263012              "license": {
263013                "id": "LGPL-2.1-or-later"
263014              }
263015            },
263016            {
263017              "license": {
263018                "id": "MIT"
263019              }
263020            },
263021            {
263022              "license": {
263023                "name": "permissive-autoconf-m4"
263024              }
263025            },
263026            {
263027              "license": {
263028                "name": "permissive-autoconf-m4-no-warranty"
263029              }
263030            },
263031            {
263032              "license": {
263033                "name": "permissive-configure"
263034              }
263035            },
263036            {
263037              "license": {
263038                "name": "permissive-fsf"
263039              }
263040            },
263041            {
263042              "license": {
263043                "name": "permissive-makefile-in"
263044              }
263045            }
263046          ],
263047          "cpe": "cpe:2.3:a:libnsl-dev:libnsl-dev:1.3.0-2:*:*:*:*:*:*:*",
263048          "purl": "pkg:deb/debian/libnsl-dev@1.3.0-2?arch=amd64\u0026upstream=libnsl\u0026distro=debian-11",
263049          "swid": {
263050            "attachment": {}
263051          },
263052          "pedigree": {},
263053          "evidence": {},
263054          "signature": {
263055            "signature": {
263056              "publicKey": {}
263057            }
263058          },
263059          "modelCard": {
263060            "modelParameters": {
263061              "approach": {}
263062            },
263063            "quantitativeAnalysis": {
263064              "graphics": {}
263065            },
263066            "considerations": {}
263067          }
263068        },
263069        {
263070          "type": "library",
263071          "bom-ref": "pkg:deb/debian/libnsl2@1.3.0-2?arch=amd64\u0026upstream=libnsl\u0026distro=debian-11\u0026package-id=fc8ac2f1807436d9",
263072          "supplier": {},
263073          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
263074          "name": "libnsl2",
263075          "version": "1.3.0-2",
263076          "licenses": [
263077            {
263078              "license": {
263079                "id": "BSD-3-Clause"
263080              }
263081            },
263082            {
263083              "license": {
263084                "id": "GPL-2.0-only"
263085              }
263086            },
263087            {
263088              "license": {
263089                "name": "GPL-2+-autoconf-exception"
263090              }
263091            },
263092            {
263093              "license": {
263094                "name": "GPL-2+-libtool-exception"
263095              }
263096            },
263097            {
263098              "license": {
263099                "id": "GPL-3.0-only"
263100              }
263101            },
263102            {
263103              "license": {
263104                "name": "GPL-3+-autoconf-exception"
263105              }
263106            },
263107            {
263108              "license": {
263109                "id": "LGPL-2.1-only"
263110              }
263111            },
263112            {
263113              "license": {
263114                "id": "LGPL-2.1-or-later"
263115              }
263116            },
263117            {
263118              "license": {
263119                "id": "MIT"
263120              }
263121            },
263122            {
263123              "license": {
263124                "name": "permissive-autoconf-m4"
263125              }
263126            },
263127            {
263128              "license": {
263129                "name": "permissive-autoconf-m4-no-warranty"
263130              }
263131            },
263132            {
263133              "license": {
263134                "name": "permissive-configure"
263135              }
263136            },
263137            {
263138              "license": {
263139                "name": "permissive-fsf"
263140              }
263141            },
263142            {
263143              "license": {
263144                "name": "permissive-makefile-in"
263145              }
263146            }
263147          ],
263148          "cpe": "cpe:2.3:a:libnsl2:libnsl2:1.3.0-2:*:*:*:*:*:*:*",
263149          "purl": "pkg:deb/debian/libnsl2@1.3.0-2?arch=amd64\u0026upstream=libnsl\u0026distro=debian-11",
263150          "swid": {
263151            "attachment": {}
263152          },
263153          "pedigree": {},
263154          "evidence": {},
263155          "signature": {
263156            "signature": {
263157              "publicKey": {}
263158            }
263159          },
263160          "modelCard": {
263161            "modelParameters": {
263162              "approach": {}
263163            },
263164            "quantitativeAnalysis": {
263165              "graphics": {}
263166            },
263167            "considerations": {}
263168          }
263169        },
263170        {
263171          "type": "library",
263172          "bom-ref": "pkg:deb/debian/libonig5@6.9.6-1.1?arch=amd64\u0026upstream=libonig\u0026distro=debian-11\u0026package-id=77b70f9f005a3a90",
263173          "supplier": {},
263174          "publisher": "Jörg Frings-Fürst \u003cdebian@jff.email\u003e",
263175          "name": "libonig5",
263176          "version": "6.9.6-1.1",
263177          "licenses": [
263178            {
263179              "license": {
263180                "id": "BSD-2-Clause"
263181              }
263182            },
263183            {
263184              "license": {
263185                "id": "GPL-2.0-only"
263186              }
263187            },
263188            {
263189              "license": {
263190                "id": "GPL-2.0-or-later"
263191              }
263192            }
263193          ],
263194          "cpe": "cpe:2.3:a:libonig5:libonig5:6.9.6-1.1:*:*:*:*:*:*:*",
263195          "purl": "pkg:deb/debian/libonig5@6.9.6-1.1?arch=amd64\u0026upstream=libonig\u0026distro=debian-11",
263196          "swid": {
263197            "attachment": {}
263198          },
263199          "pedigree": {},
263200          "evidence": {},
263201          "signature": {
263202            "signature": {
263203              "publicKey": {}
263204            }
263205          },
263206          "modelCard": {
263207            "modelParameters": {
263208              "approach": {}
263209            },
263210            "quantitativeAnalysis": {
263211              "graphics": {}
263212            },
263213            "considerations": {}
263214          }
263215        },
263216        {
263217          "type": "library",
263218          "bom-ref": "pkg:deb/debian/libp11-kit0@0.23.22-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-11\u0026package-id=a2ce6d1eb48ab956",
263219          "supplier": {},
263220          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
263221          "name": "libp11-kit0",
263222          "version": "0.23.22-1",
263223          "licenses": [
263224            {
263225              "license": {
263226                "id": "BSD-3-Clause"
263227              }
263228            },
263229            {
263230              "license": {
263231                "id": "ISC"
263232              }
263233            },
263234            {
263235              "license": {
263236                "name": "ISC+IBM"
263237              }
263238            },
263239            {
263240              "license": {
263241                "name": "permissive-like-automake-output"
263242              }
263243            },
263244            {
263245              "license": {
263246                "name": "same-as-rest-of-p11kit"
263247              }
263248            }
263249          ],
263250          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.22-1:*:*:*:*:*:*:*",
263251          "purl": "pkg:deb/debian/libp11-kit0@0.23.22-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-11",
263252          "swid": {
263253            "attachment": {}
263254          },
263255          "pedigree": {},
263256          "evidence": {},
263257          "signature": {
263258            "signature": {
263259              "publicKey": {}
263260            }
263261          },
263262          "modelCard": {
263263            "modelParameters": {
263264              "approach": {}
263265            },
263266            "quantitativeAnalysis": {
263267              "graphics": {}
263268            },
263269            "considerations": {}
263270          }
263271        },
263272        {
263273          "type": "library",
263274          "bom-ref": "pkg:deb/debian/libpam-modules@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11\u0026package-id=903eac5974d73705",
263275          "supplier": {},
263276          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
263277          "name": "libpam-modules",
263278          "version": "1.4.0-9+deb11u1",
263279          "licenses": [
263280            {
263281              "license": {
263282                "name": "GPL"
263283              }
263284            }
263285          ],
263286          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
263287          "purl": "pkg:deb/debian/libpam-modules@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11",
263288          "swid": {
263289            "attachment": {}
263290          },
263291          "pedigree": {},
263292          "evidence": {},
263293          "signature": {
263294            "signature": {
263295              "publicKey": {}
263296            }
263297          },
263298          "modelCard": {
263299            "modelParameters": {
263300              "approach": {}
263301            },
263302            "quantitativeAnalysis": {
263303              "graphics": {}
263304            },
263305            "considerations": {}
263306          }
263307        },
263308        {
263309          "type": "library",
263310          "bom-ref": "pkg:deb/debian/libpam-modules-bin@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11\u0026package-id=2dc3f20bb97e020d",
263311          "supplier": {},
263312          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
263313          "name": "libpam-modules-bin",
263314          "version": "1.4.0-9+deb11u1",
263315          "licenses": [
263316            {
263317              "license": {
263318                "name": "GPL"
263319              }
263320            }
263321          ],
263322          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
263323          "purl": "pkg:deb/debian/libpam-modules-bin@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11",
263324          "swid": {
263325            "attachment": {}
263326          },
263327          "pedigree": {},
263328          "evidence": {},
263329          "signature": {
263330            "signature": {
263331              "publicKey": {}
263332            }
263333          },
263334          "modelCard": {
263335            "modelParameters": {
263336              "approach": {}
263337            },
263338            "quantitativeAnalysis": {
263339              "graphics": {}
263340            },
263341            "considerations": {}
263342          }
263343        },
263344        {
263345          "type": "library",
263346          "bom-ref": "pkg:deb/debian/libpam-runtime@1.4.0-9+deb11u1?arch=all\u0026upstream=pam\u0026distro=debian-11\u0026package-id=1238d07342abe7a3",
263347          "supplier": {},
263348          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
263349          "name": "libpam-runtime",
263350          "version": "1.4.0-9+deb11u1",
263351          "licenses": [
263352            {
263353              "license": {
263354                "name": "GPL"
263355              }
263356            }
263357          ],
263358          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
263359          "purl": "pkg:deb/debian/libpam-runtime@1.4.0-9+deb11u1?arch=all\u0026upstream=pam\u0026distro=debian-11",
263360          "swid": {
263361            "attachment": {}
263362          },
263363          "pedigree": {},
263364          "evidence": {},
263365          "signature": {
263366            "signature": {
263367              "publicKey": {}
263368            }
263369          },
263370          "modelCard": {
263371            "modelParameters": {
263372              "approach": {}
263373            },
263374            "quantitativeAnalysis": {
263375              "graphics": {}
263376            },
263377            "considerations": {}
263378          }
263379        },
263380        {
263381          "type": "library",
263382          "bom-ref": "pkg:deb/debian/libpam0g@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11\u0026package-id=70917c5424d601fa",
263383          "supplier": {},
263384          "publisher": "Steve Langasek \u003cvorlon@debian.org\u003e",
263385          "name": "libpam0g",
263386          "version": "1.4.0-9+deb11u1",
263387          "licenses": [
263388            {
263389              "license": {
263390                "name": "GPL"
263391              }
263392            }
263393          ],
263394          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.4.0-9\\+deb11u1:*:*:*:*:*:*:*",
263395          "purl": "pkg:deb/debian/libpam0g@1.4.0-9+deb11u1?arch=amd64\u0026upstream=pam\u0026distro=debian-11",
263396          "swid": {
263397            "attachment": {}
263398          },
263399          "pedigree": {},
263400          "evidence": {},
263401          "signature": {
263402            "signature": {
263403              "publicKey": {}
263404            }
263405          },
263406          "modelCard": {
263407            "modelParameters": {
263408              "approach": {}
263409            },
263410            "quantitativeAnalysis": {
263411              "graphics": {}
263412            },
263413            "considerations": {}
263414          }
263415        },
263416        {
263417          "type": "library",
263418          "bom-ref": "pkg:deb/debian/libpango-1.0-0@1.46.2-3?arch=amd64\u0026upstream=pango1.0\u0026distro=debian-11\u0026package-id=96fa4f5edb516162",
263419          "supplier": {},
263420          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
263421          "name": "libpango-1.0-0",
263422          "version": "1.46.2-3",
263423          "licenses": [
263424            {
263425              "license": {
263426                "name": "Chromium-BSD-style"
263427              }
263428            },
263429            {
263430              "license": {
263431                "name": "Example"
263432              }
263433            },
263434            {
263435              "license": {
263436                "id": "ICU"
263437              }
263438            },
263439            {
263440              "license": {
263441                "id": "LGPL-2.0-only"
263442              }
263443            },
263444            {
263445              "license": {
263446                "id": "LGPL-2.0-or-later"
263447              }
263448            },
263449            {
263450              "license": {
263451                "id": "TCL"
263452              }
263453            },
263454            {
263455              "license": {
263456                "name": "Unicode"
263457              }
263458            }
263459          ],
263460          "cpe": "cpe:2.3:a:libpango-1.0-0:libpango-1.0-0:1.46.2-3:*:*:*:*:*:*:*",
263461          "purl": "pkg:deb/debian/libpango-1.0-0@1.46.2-3?arch=amd64\u0026upstream=pango1.0\u0026distro=debian-11",
263462          "swid": {
263463            "attachment": {}
263464          },
263465          "pedigree": {},
263466          "evidence": {},
263467          "signature": {
263468            "signature": {
263469              "publicKey": {}
263470            }
263471          },
263472          "modelCard": {
263473            "modelParameters": {
263474              "approach": {}
263475            },
263476            "quantitativeAnalysis": {
263477              "graphics": {}
263478            },
263479            "considerations": {}
263480          }
263481        },
263482        {
263483          "type": "library",
263484          "bom-ref": "pkg:deb/debian/libpangocairo-1.0-0@1.46.2-3?arch=amd64\u0026upstream=pango1.0\u0026distro=debian-11\u0026package-id=7567383a7569f75d",
263485          "supplier": {},
263486          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
263487          "name": "libpangocairo-1.0-0",
263488          "version": "1.46.2-3",
263489          "licenses": [
263490            {
263491              "license": {
263492                "name": "Chromium-BSD-style"
263493              }
263494            },
263495            {
263496              "license": {
263497                "name": "Example"
263498              }
263499            },
263500            {
263501              "license": {
263502                "id": "ICU"
263503              }
263504            },
263505            {
263506              "license": {
263507                "id": "LGPL-2.0-only"
263508              }
263509            },
263510            {
263511              "license": {
263512                "id": "LGPL-2.0-or-later"
263513              }
263514            },
263515            {
263516              "license": {
263517                "id": "TCL"
263518              }
263519            },
263520            {
263521              "license": {
263522                "name": "Unicode"
263523              }
263524            }
263525          ],
263526          "cpe": "cpe:2.3:a:libpangocairo-1.0-0:libpangocairo-1.0-0:1.46.2-3:*:*:*:*:*:*:*",
263527          "purl": "pkg:deb/debian/libpangocairo-1.0-0@1.46.2-3?arch=amd64\u0026upstream=pango1.0\u0026distro=debian-11",
263528          "swid": {
263529            "attachment": {}
263530          },
263531          "pedigree": {},
263532          "evidence": {},
263533          "signature": {
263534            "signature": {
263535              "publicKey": {}
263536            }
263537          },
263538          "modelCard": {
263539            "modelParameters": {
263540              "approach": {}
263541            },
263542            "quantitativeAnalysis": {
263543              "graphics": {}
263544            },
263545            "considerations": {}
263546          }
263547        },
263548        {
263549          "type": "library",
263550          "bom-ref": "pkg:deb/debian/libpangoft2-1.0-0@1.46.2-3?arch=amd64\u0026upstream=pango1.0\u0026distro=debian-11\u0026package-id=b3636c41d4fd4ff9",
263551          "supplier": {},
263552          "publisher": "Debian GNOME Maintainers \u003cpkg-gnome-maintainers@lists.alioth.debian.org\u003e",
263553          "name": "libpangoft2-1.0-0",
263554          "version": "1.46.2-3",
263555          "licenses": [
263556            {
263557              "license": {
263558                "name": "Chromium-BSD-style"
263559              }
263560            },
263561            {
263562              "license": {
263563                "name": "Example"
263564              }
263565            },
263566            {
263567              "license": {
263568                "id": "ICU"
263569              }
263570            },
263571            {
263572              "license": {
263573                "id": "LGPL-2.0-only"
263574              }
263575            },
263576            {
263577              "license": {
263578                "id": "LGPL-2.0-or-later"
263579              }
263580            },
263581            {
263582              "license": {
263583                "id": "TCL"
263584              }
263585            },
263586            {
263587              "license": {
263588                "name": "Unicode"
263589              }
263590            }
263591          ],
263592          "cpe": "cpe:2.3:a:libpangoft2-1.0-0:libpangoft2-1.0-0:1.46.2-3:*:*:*:*:*:*:*",
263593          "purl": "pkg:deb/debian/libpangoft2-1.0-0@1.46.2-3?arch=amd64\u0026upstream=pango1.0\u0026distro=debian-11",
263594          "swid": {
263595            "attachment": {}
263596          },
263597          "pedigree": {},
263598          "evidence": {},
263599          "signature": {
263600            "signature": {
263601              "publicKey": {}
263602            }
263603          },
263604          "modelCard": {
263605            "modelParameters": {
263606              "approach": {}
263607            },
263608            "quantitativeAnalysis": {
263609              "graphics": {}
263610            },
263611            "considerations": {}
263612          }
263613        },
263614        {
263615          "type": "library",
263616          "bom-ref": "pkg:deb/debian/libpcap0.8@1.10.0-2?arch=amd64\u0026upstream=libpcap\u0026distro=debian-11\u0026package-id=44b99d669ec6a4e",
263617          "supplier": {},
263618          "publisher": "Romain Francoise \u003crfrancoise@debian.org\u003e",
263619          "name": "libpcap0.8",
263620          "version": "1.10.0-2",
263621          "cpe": "cpe:2.3:a:libpcap0.8:libpcap0.8:1.10.0-2:*:*:*:*:*:*:*",
263622          "purl": "pkg:deb/debian/libpcap0.8@1.10.0-2?arch=amd64\u0026upstream=libpcap\u0026distro=debian-11",
263623          "swid": {
263624            "attachment": {}
263625          },
263626          "pedigree": {},
263627          "evidence": {},
263628          "signature": {
263629            "signature": {
263630              "publicKey": {}
263631            }
263632          },
263633          "modelCard": {
263634            "modelParameters": {
263635              "approach": {}
263636            },
263637            "quantitativeAnalysis": {
263638              "graphics": {}
263639            },
263640            "considerations": {}
263641          }
263642        },
263643        {
263644          "type": "library",
263645          "bom-ref": "pkg:deb/debian/libpci3@1:3.7.0-5?arch=amd64\u0026upstream=pciutils\u0026distro=debian-11\u0026package-id=81d8df8d8f28e135",
263646          "supplier": {},
263647          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
263648          "name": "libpci3",
263649          "version": "1:3.7.0-5",
263650          "licenses": [
263651            {
263652              "license": {
263653                "id": "GPL-2.0-only"
263654              }
263655            },
263656            {
263657              "license": {
263658                "id": "GPL-2.0-or-later"
263659              }
263660            }
263661          ],
263662          "cpe": "cpe:2.3:a:libpci3:libpci3:1\\:3.7.0-5:*:*:*:*:*:*:*",
263663          "purl": "pkg:deb/debian/libpci3@1:3.7.0-5?arch=amd64\u0026upstream=pciutils\u0026distro=debian-11",
263664          "swid": {
263665            "attachment": {}
263666          },
263667          "pedigree": {},
263668          "evidence": {},
263669          "signature": {
263670            "signature": {
263671              "publicKey": {}
263672            }
263673          },
263674          "modelCard": {
263675            "modelParameters": {
263676              "approach": {}
263677            },
263678            "quantitativeAnalysis": {
263679              "graphics": {}
263680            },
263681            "considerations": {}
263682          }
263683        },
263684        {
263685          "type": "library",
263686          "bom-ref": "pkg:deb/debian/libpcre2-8-0@10.36-2+deb11u1?arch=amd64\u0026upstream=pcre2\u0026distro=debian-11\u0026package-id=5d07d7ec308f6bb2",
263687          "supplier": {},
263688          "publisher": "Matthew Vernon \u003cmatthew@debian.org\u003e",
263689          "name": "libpcre2-8-0",
263690          "version": "10.36-2+deb11u1",
263691          "cpe": "cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.36-2\\+deb11u1:*:*:*:*:*:*:*",
263692          "purl": "pkg:deb/debian/libpcre2-8-0@10.36-2+deb11u1?arch=amd64\u0026upstream=pcre2\u0026distro=debian-11",
263693          "swid": {
263694            "attachment": {}
263695          },
263696          "pedigree": {},
263697          "evidence": {},
263698          "signature": {
263699            "signature": {
263700              "publicKey": {}
263701            }
263702          },
263703          "modelCard": {
263704            "modelParameters": {
263705              "approach": {}
263706            },
263707            "quantitativeAnalysis": {
263708              "graphics": {}
263709            },
263710            "considerations": {}
263711          }
263712        },
263713        {
263714          "type": "library",
263715          "bom-ref": "pkg:deb/debian/libpcre3@2:8.39-13?arch=amd64\u0026upstream=pcre3\u0026distro=debian-11\u0026package-id=1c1641a0882b431f",
263716          "supplier": {},
263717          "publisher": "Matthew Vernon \u003cmatthew@debian.org\u003e",
263718          "name": "libpcre3",
263719          "version": "2:8.39-13",
263720          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-13:*:*:*:*:*:*:*",
263721          "purl": "pkg:deb/debian/libpcre3@2:8.39-13?arch=amd64\u0026upstream=pcre3\u0026distro=debian-11",
263722          "swid": {
263723            "attachment": {}
263724          },
263725          "pedigree": {},
263726          "evidence": {},
263727          "signature": {
263728            "signature": {
263729              "publicKey": {}
263730            }
263731          },
263732          "modelCard": {
263733            "modelParameters": {
263734              "approach": {}
263735            },
263736            "quantitativeAnalysis": {
263737              "graphics": {}
263738            },
263739            "considerations": {}
263740          }
263741        },
263742        {
263743          "type": "library",
263744          "bom-ref": "pkg:deb/debian/libperl5.32@5.32.1-4+deb11u2?arch=amd64\u0026upstream=perl\u0026distro=debian-11\u0026package-id=ea44a16f7932b5f8",
263745          "supplier": {},
263746          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
263747          "name": "libperl5.32",
263748          "version": "5.32.1-4+deb11u2",
263749          "licenses": [
263750            {
263751              "license": {
263752                "name": "Artistic"
263753              }
263754            },
263755            {
263756              "license": {
263757                "id": "Artistic-2.0"
263758              }
263759            },
263760            {
263761              "license": {
263762                "name": "Artistic-dist"
263763              }
263764            },
263765            {
263766              "license": {
263767                "id": "BSD-3-Clause"
263768              }
263769            },
263770            {
263771              "license": {
263772                "name": "BSD-3-clause-GENERIC"
263773              }
263774            },
263775            {
263776              "license": {
263777                "name": "BSD-3-clause-with-weird-numbering"
263778              }
263779            },
263780            {
263781              "license": {
263782                "name": "BSD-4-clause-POWERDOG"
263783              }
263784            },
263785            {
263786              "license": {
263787                "name": "BZIP"
263788              }
263789            },
263790            {
263791              "license": {
263792                "name": "DONT-CHANGE-THE-GPL"
263793              }
263794            },
263795            {
263796              "license": {
263797                "name": "Expat"
263798              }
263799            },
263800            {
263801              "license": {
263802                "id": "GPL-1.0-only"
263803              }
263804            },
263805            {
263806              "license": {
263807                "id": "GPL-1.0-or-later"
263808              }
263809            },
263810            {
263811              "license": {
263812                "id": "GPL-2.0-only"
263813              }
263814            },
263815            {
263816              "license": {
263817                "id": "GPL-2.0-or-later"
263818              }
263819            },
263820            {
263821              "license": {
263822                "name": "GPL-3+-WITH-BISON-EXCEPTION"
263823              }
263824            },
263825            {
263826              "license": {
263827                "name": "HSIEH-BSD"
263828              }
263829            },
263830            {
263831              "license": {
263832                "name": "HSIEH-DERIVATIVE"
263833              }
263834            },
263835            {
263836              "license": {
263837                "id": "LGPL-2.1-only"
263838              }
263839            },
263840            {
263841              "license": {
263842                "name": "REGCOMP"
263843              }
263844            },
263845            {
263846              "license": {
263847                "name": "REGCOMP,"
263848              }
263849            },
263850            {
263851              "license": {
263852                "name": "RRA-KEEP-THIS-NOTICE"
263853              }
263854            },
263855            {
263856              "license": {
263857                "name": "SDBM-PUBLIC-DOMAIN"
263858              }
263859            },
263860            {
263861              "license": {
263862                "name": "TEXT-TABS"
263863              }
263864            },
263865            {
263866              "license": {
263867                "name": "Unicode"
263868              }
263869            },
263870            {
263871              "license": {
263872                "id": "Zlib"
263873              }
263874            }
263875          ],
263876          "cpe": "cpe:2.3:a:libperl5.32:libperl5.32:5.32.1-4\\+deb11u2:*:*:*:*:*:*:*",
263877          "purl": "pkg:deb/debian/libperl5.32@5.32.1-4+deb11u2?arch=amd64\u0026upstream=perl\u0026distro=debian-11",
263878          "swid": {
263879            "attachment": {}
263880          },
263881          "pedigree": {},
263882          "evidence": {},
263883          "signature": {
263884            "signature": {
263885              "publicKey": {}
263886            }
263887          },
263888          "modelCard": {
263889            "modelParameters": {
263890              "approach": {}
263891            },
263892            "quantitativeAnalysis": {
263893              "graphics": {}
263894            },
263895            "considerations": {}
263896          }
263897        },
263898        {
263899          "type": "library",
263900          "bom-ref": "pkg:deb/debian/libpixman-1-0@0.40.0-1.1~deb11u1?arch=amd64\u0026upstream=pixman\u0026distro=debian-11\u0026package-id=e7ecd44c3b7fdac8",
263901          "supplier": {},
263902          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
263903          "name": "libpixman-1-0",
263904          "version": "0.40.0-1.1~deb11u1",
263905          "cpe": "cpe:2.3:a:libpixman-1-0:libpixman-1-0:0.40.0-1.1\\~deb11u1:*:*:*:*:*:*:*",
263906          "purl": "pkg:deb/debian/libpixman-1-0@0.40.0-1.1~deb11u1?arch=amd64\u0026upstream=pixman\u0026distro=debian-11",
263907          "swid": {
263908            "attachment": {}
263909          },
263910          "pedigree": {},
263911          "evidence": {},
263912          "signature": {
263913            "signature": {
263914              "publicKey": {}
263915            }
263916          },
263917          "modelCard": {
263918            "modelParameters": {
263919              "approach": {}
263920            },
263921            "quantitativeAnalysis": {
263922              "graphics": {}
263923            },
263924            "considerations": {}
263925          }
263926        },
263927        {
263928          "type": "library",
263929          "bom-ref": "pkg:deb/debian/libpng16-16@1.6.37-3?arch=amd64\u0026upstream=libpng1.6\u0026distro=debian-11\u0026package-id=9821c1ad36f085c7",
263930          "supplier": {},
263931          "publisher": "Maintainers of libpng1.6 packages \u003clibpng1.6@packages.debian.org\u003e",
263932          "name": "libpng16-16",
263933          "version": "1.6.37-3",
263934          "licenses": [
263935            {
263936              "license": {
263937                "id": "Apache-2.0"
263938              }
263939            },
263940            {
263941              "license": {
263942                "id": "BSD-3-Clause"
263943              }
263944            },
263945            {
263946              "license": {
263947                "name": "BSD-like-with-advertising-clause"
263948              }
263949            },
263950            {
263951              "license": {
263952                "id": "GPL-2.0-only"
263953              }
263954            },
263955            {
263956              "license": {
263957                "id": "GPL-2.0-or-later"
263958              }
263959            },
263960            {
263961              "license": {
263962                "name": "expat"
263963              }
263964            },
263965            {
263966              "license": {
263967                "id": "Libpng"
263968              }
263969            }
263970          ],
263971          "cpe": "cpe:2.3:a:libpng16-16:libpng16-16:1.6.37-3:*:*:*:*:*:*:*",
263972          "purl": "pkg:deb/debian/libpng16-16@1.6.37-3?arch=amd64\u0026upstream=libpng1.6\u0026distro=debian-11",
263973          "swid": {
263974            "attachment": {}
263975          },
263976          "pedigree": {},
263977          "evidence": {},
263978          "signature": {
263979            "signature": {
263980              "publicKey": {}
263981            }
263982          },
263983          "modelCard": {
263984            "modelParameters": {
263985              "approach": {}
263986            },
263987            "quantitativeAnalysis": {
263988              "graphics": {}
263989            },
263990            "considerations": {}
263991          }
263992        },
263993        {
263994          "type": "library",
263995          "bom-ref": "pkg:deb/debian/libpopt0@1.18-2?arch=amd64\u0026upstream=popt\u0026distro=debian-11\u0026package-id=c5395fb489d0398d",
263996          "supplier": {},
263997          "publisher": "Michael Jeanson \u003cmjeanson@debian.org\u003e",
263998          "name": "libpopt0",
263999          "version": "1.18-2",
264000          "licenses": [
264001            {
264002              "license": {
264003                "id": "GPL-2.0-only"
264004              }
264005            },
264006            {
264007              "license": {
264008                "id": "GPL-2.0-or-later"
264009              }
264010            },
264011            {
264012              "license": {
264013                "name": "X-Consortium"
264014              }
264015            }
264016          ],
264017          "cpe": "cpe:2.3:a:libpopt0:libpopt0:1.18-2:*:*:*:*:*:*:*",
264018          "purl": "pkg:deb/debian/libpopt0@1.18-2?arch=amd64\u0026upstream=popt\u0026distro=debian-11",
264019          "swid": {
264020            "attachment": {}
264021          },
264022          "pedigree": {},
264023          "evidence": {},
264024          "signature": {
264025            "signature": {
264026              "publicKey": {}
264027            }
264028          },
264029          "modelCard": {
264030            "modelParameters": {
264031              "approach": {}
264032            },
264033            "quantitativeAnalysis": {
264034              "graphics": {}
264035            },
264036            "considerations": {}
264037          }
264038        },
264039        {
264040          "type": "library",
264041          "bom-ref": "pkg:deb/debian/libpq5@13.8-0+deb11u1?arch=amd64\u0026upstream=postgresql-13\u0026distro=debian-11\u0026package-id=f2714dd821f9d3e5",
264042          "supplier": {},
264043          "publisher": "Debian PostgreSQL Maintainers \u003cteam+postgresql@tracker.debian.org\u003e",
264044          "name": "libpq5",
264045          "version": "13.8-0+deb11u1",
264046          "licenses": [
264047            {
264048              "license": {
264049                "name": "Artistic"
264050              }
264051            },
264052            {
264053              "license": {
264054                "id": "BSD-2-Clause"
264055              }
264056            },
264057            {
264058              "license": {
264059                "id": "BSD-3-Clause"
264060              }
264061            },
264062            {
264063              "license": {
264064                "id": "BSD-3-Clause"
264065              }
264066            },
264067            {
264068              "license": {
264069                "name": "Custom-Unicode"
264070              }
264071            },
264072            {
264073              "license": {
264074                "name": "Custom-pg_dump"
264075              }
264076            },
264077            {
264078              "license": {
264079                "name": "Custom-regex"
264080              }
264081            },
264082            {
264083              "license": {
264084                "id": "GPL-1.0-only"
264085              }
264086            },
264087            {
264088              "license": {
264089                "id": "PostgreSQL"
264090              }
264091            },
264092            {
264093              "license": {
264094                "id": "TCL"
264095              }
264096            },
264097            {
264098              "license": {
264099                "name": "blf"
264100              }
264101            },
264102            {
264103              "license": {
264104                "name": "double-metaphone"
264105              }
264106            },
264107            {
264108              "license": {
264109                "name": "imath"
264110              }
264111            },
264112            {
264113              "license": {
264114                "name": "nagaysau-ishii"
264115              }
264116            },
264117            {
264118              "license": {
264119                "name": "rijndael"
264120              }
264121            }
264122          ],
264123          "cpe": "cpe:2.3:a:libpq5:libpq5:13.8-0\\+deb11u1:*:*:*:*:*:*:*",
264124          "purl": "pkg:deb/debian/libpq5@13.8-0+deb11u1?arch=amd64\u0026upstream=postgresql-13\u0026distro=debian-11",
264125          "swid": {
264126            "attachment": {}
264127          },
264128          "pedigree": {},
264129          "evidence": {},
264130          "signature": {
264131            "signature": {
264132              "publicKey": {}
264133            }
264134          },
264135          "modelCard": {
264136            "modelParameters": {
264137              "approach": {}
264138            },
264139            "quantitativeAnalysis": {
264140              "graphics": {}
264141            },
264142            "considerations": {}
264143          }
264144        },
264145        {
264146          "type": "library",
264147          "bom-ref": "pkg:deb/debian/libprotobuf-c1@1.3.3-1+b2?arch=amd64\u0026upstream=protobuf-c%401.3.3-1\u0026distro=debian-11\u0026package-id=1f15c1e3949aef7c",
264148          "supplier": {},
264149          "publisher": "Robert Edmonds \u003cedmonds@debian.org\u003e",
264150          "name": "libprotobuf-c1",
264151          "version": "1.3.3-1+b2",
264152          "licenses": [
264153            {
264154              "license": {
264155                "id": "BSD-2-Clause"
264156              }
264157            },
264158            {
264159              "license": {
264160                "id": "BSD-3-Clause"
264161              }
264162            },
264163            {
264164              "license": {
264165                "name": "permissive"
264166              }
264167            }
264168          ],
264169          "cpe": "cpe:2.3:a:libprotobuf-c1:libprotobuf-c1:1.3.3-1\\+b2:*:*:*:*:*:*:*",
264170          "purl": "pkg:deb/debian/libprotobuf-c1@1.3.3-1+b2?arch=amd64\u0026upstream=protobuf-c%401.3.3-1\u0026distro=debian-11",
264171          "swid": {
264172            "attachment": {}
264173          },
264174          "pedigree": {},
264175          "evidence": {},
264176          "signature": {
264177            "signature": {
264178              "publicKey": {}
264179            }
264180          },
264181          "modelCard": {
264182            "modelParameters": {
264183              "approach": {}
264184            },
264185            "quantitativeAnalysis": {
264186              "graphics": {}
264187            },
264188            "considerations": {}
264189          }
264190        },
264191        {
264192          "type": "library",
264193          "bom-ref": "pkg:deb/debian/libpsl5@0.21.0-1.2?arch=amd64\u0026upstream=libpsl\u0026distro=debian-11\u0026package-id=3409718c91a2d222",
264194          "supplier": {},
264195          "publisher": "Tim Rühsen \u003ctim.ruehsen@gmx.de\u003e",
264196          "name": "libpsl5",
264197          "version": "0.21.0-1.2",
264198          "licenses": [
264199            {
264200              "license": {
264201                "name": "Chromium"
264202              }
264203            },
264204            {
264205              "license": {
264206                "id": "MIT"
264207              }
264208            }
264209          ],
264210          "cpe": "cpe:2.3:a:libpsl5:libpsl5:0.21.0-1.2:*:*:*:*:*:*:*",
264211          "purl": "pkg:deb/debian/libpsl5@0.21.0-1.2?arch=amd64\u0026upstream=libpsl\u0026distro=debian-11",
264212          "swid": {
264213            "attachment": {}
264214          },
264215          "pedigree": {},
264216          "evidence": {},
264217          "signature": {
264218            "signature": {
264219              "publicKey": {}
264220            }
264221          },
264222          "modelCard": {
264223            "modelParameters": {
264224              "approach": {}
264225            },
264226            "quantitativeAnalysis": {
264227              "graphics": {}
264228            },
264229            "considerations": {}
264230          }
264231        },
264232        {
264233          "type": "library",
264234          "bom-ref": "pkg:deb/debian/libpython3-stdlib@3.9.2-3?arch=amd64\u0026upstream=python3-defaults\u0026distro=debian-11\u0026package-id=99db392d77306819",
264235          "supplier": {},
264236          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
264237          "name": "libpython3-stdlib",
264238          "version": "3.9.2-3",
264239          "cpe": "cpe:2.3:a:libpython3-stdlib:libpython3-stdlib:3.9.2-3:*:*:*:*:*:*:*",
264240          "purl": "pkg:deb/debian/libpython3-stdlib@3.9.2-3?arch=amd64\u0026upstream=python3-defaults\u0026distro=debian-11",
264241          "swid": {
264242            "attachment": {}
264243          },
264244          "pedigree": {},
264245          "evidence": {},
264246          "signature": {
264247            "signature": {
264248              "publicKey": {}
264249            }
264250          },
264251          "modelCard": {
264252            "modelParameters": {
264253              "approach": {}
264254            },
264255            "quantitativeAnalysis": {
264256              "graphics": {}
264257            },
264258            "considerations": {}
264259          }
264260        },
264261        {
264262          "type": "library",
264263          "bom-ref": "pkg:deb/debian/libpython3.9@3.9.2-1?arch=amd64\u0026upstream=python3.9\u0026distro=debian-11\u0026package-id=23ca0958a8aee622",
264264          "supplier": {},
264265          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
264266          "name": "libpython3.9",
264267          "version": "3.9.2-1",
264268          "licenses": [
264269            {
264270              "license": {
264271                "name": "By"
264272              }
264273            },
264274            {
264275              "license": {
264276                "id": "GPL-2.0-only"
264277              }
264278            },
264279            {
264280              "license": {
264281                "name": "Permission"
264282              }
264283            },
264284            {
264285              "license": {
264286                "name": "Redistribution"
264287              }
264288            },
264289            {
264290              "license": {
264291                "name": "This"
264292              }
264293            }
264294          ],
264295          "cpe": "cpe:2.3:a:libpython3.9:libpython3.9:3.9.2-1:*:*:*:*:*:*:*",
264296          "purl": "pkg:deb/debian/libpython3.9@3.9.2-1?arch=amd64\u0026upstream=python3.9\u0026distro=debian-11",
264297          "swid": {
264298            "attachment": {}
264299          },
264300          "pedigree": {},
264301          "evidence": {},
264302          "signature": {
264303            "signature": {
264304              "publicKey": {}
264305            }
264306          },
264307          "modelCard": {
264308            "modelParameters": {
264309              "approach": {}
264310            },
264311            "quantitativeAnalysis": {
264312              "graphics": {}
264313            },
264314            "considerations": {}
264315          }
264316        },
264317        {
264318          "type": "library",
264319          "bom-ref": "pkg:deb/debian/libpython3.9-minimal@3.9.2-1?arch=amd64\u0026upstream=python3.9\u0026distro=debian-11\u0026package-id=4de115782307e751",
264320          "supplier": {},
264321          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
264322          "name": "libpython3.9-minimal",
264323          "version": "3.9.2-1",
264324          "licenses": [
264325            {
264326              "license": {
264327                "name": "By"
264328              }
264329            },
264330            {
264331              "license": {
264332                "id": "GPL-2.0-only"
264333              }
264334            },
264335            {
264336              "license": {
264337                "name": "Permission"
264338              }
264339            },
264340            {
264341              "license": {
264342                "name": "Redistribution"
264343              }
264344            },
264345            {
264346              "license": {
264347                "name": "This"
264348              }
264349            }
264350          ],
264351          "cpe": "cpe:2.3:a:libpython3.9-minimal:libpython3.9-minimal:3.9.2-1:*:*:*:*:*:*:*",
264352          "purl": "pkg:deb/debian/libpython3.9-minimal@3.9.2-1?arch=amd64\u0026upstream=python3.9\u0026distro=debian-11",
264353          "swid": {
264354            "attachment": {}
264355          },
264356          "pedigree": {},
264357          "evidence": {},
264358          "signature": {
264359            "signature": {
264360              "publicKey": {}
264361            }
264362          },
264363          "modelCard": {
264364            "modelParameters": {
264365              "approach": {}
264366            },
264367            "quantitativeAnalysis": {
264368              "graphics": {}
264369            },
264370            "considerations": {}
264371          }
264372        },
264373        {
264374          "type": "library",
264375          "bom-ref": "pkg:deb/debian/libpython3.9-stdlib@3.9.2-1?arch=amd64\u0026upstream=python3.9\u0026distro=debian-11\u0026package-id=f151291f1a87d4bb",
264376          "supplier": {},
264377          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
264378          "name": "libpython3.9-stdlib",
264379          "version": "3.9.2-1",
264380          "licenses": [
264381            {
264382              "license": {
264383                "name": "By"
264384              }
264385            },
264386            {
264387              "license": {
264388                "id": "GPL-2.0-only"
264389              }
264390            },
264391            {
264392              "license": {
264393                "name": "Permission"
264394              }
264395            },
264396            {
264397              "license": {
264398                "name": "Redistribution"
264399              }
264400            },
264401            {
264402              "license": {
264403                "name": "This"
264404              }
264405            }
264406          ],
264407          "cpe": "cpe:2.3:a:libpython3.9-stdlib:libpython3.9-stdlib:3.9.2-1:*:*:*:*:*:*:*",
264408          "purl": "pkg:deb/debian/libpython3.9-stdlib@3.9.2-1?arch=amd64\u0026upstream=python3.9\u0026distro=debian-11",
264409          "swid": {
264410            "attachment": {}
264411          },
264412          "pedigree": {},
264413          "evidence": {},
264414          "signature": {
264415            "signature": {
264416              "publicKey": {}
264417            }
264418          },
264419          "modelCard": {
264420            "modelParameters": {
264421              "approach": {}
264422            },
264423            "quantitativeAnalysis": {
264424              "graphics": {}
264425            },
264426            "considerations": {}
264427          }
264428        },
264429        {
264430          "type": "library",
264431          "bom-ref": "pkg:deb/debian/libquadmath0@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=48f5f166b613dcea",
264432          "supplier": {},
264433          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
264434          "name": "libquadmath0",
264435          "version": "10.2.1-6",
264436          "licenses": [
264437            {
264438              "license": {
264439                "name": "Artistic"
264440              }
264441            },
264442            {
264443              "license": {
264444                "id": "GFDL-1.2-only"
264445              }
264446            },
264447            {
264448              "license": {
264449                "name": "GPL"
264450              }
264451            },
264452            {
264453              "license": {
264454                "id": "GPL-2.0-only"
264455              }
264456            },
264457            {
264458              "license": {
264459                "id": "GPL-3.0-only"
264460              }
264461            },
264462            {
264463              "license": {
264464                "name": "LGPL"
264465              }
264466            }
264467          ],
264468          "cpe": "cpe:2.3:a:libquadmath0:libquadmath0:10.2.1-6:*:*:*:*:*:*:*",
264469          "purl": "pkg:deb/debian/libquadmath0@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
264470          "swid": {
264471            "attachment": {}
264472          },
264473          "pedigree": {},
264474          "evidence": {},
264475          "signature": {
264476            "signature": {
264477              "publicKey": {}
264478            }
264479          },
264480          "modelCard": {
264481            "modelParameters": {
264482              "approach": {}
264483            },
264484            "quantitativeAnalysis": {
264485              "graphics": {}
264486            },
264487            "considerations": {}
264488          }
264489        },
264490        {
264491          "type": "library",
264492          "bom-ref": "pkg:deb/debian/libreadline8@8.1-1?arch=amd64\u0026upstream=readline\u0026distro=debian-11\u0026package-id=348793ec2b579ee6",
264493          "supplier": {},
264494          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
264495          "name": "libreadline8",
264496          "version": "8.1-1",
264497          "licenses": [
264498            {
264499              "license": {
264500                "name": "GFDL"
264501              }
264502            },
264503            {
264504              "license": {
264505                "id": "GPL-3.0-only"
264506              }
264507            }
264508          ],
264509          "cpe": "cpe:2.3:a:libreadline8:libreadline8:8.1-1:*:*:*:*:*:*:*",
264510          "purl": "pkg:deb/debian/libreadline8@8.1-1?arch=amd64\u0026upstream=readline\u0026distro=debian-11",
264511          "swid": {
264512            "attachment": {}
264513          },
264514          "pedigree": {},
264515          "evidence": {},
264516          "signature": {
264517            "signature": {
264518              "publicKey": {}
264519            }
264520          },
264521          "modelCard": {
264522            "modelParameters": {
264523              "approach": {}
264524            },
264525            "quantitativeAnalysis": {
264526              "graphics": {}
264527            },
264528            "considerations": {}
264529          }
264530        },
264531        {
264532          "type": "library",
264533          "bom-ref": "pkg:deb/debian/librtmp1@2.4+20151223.gitfa8646d.1-2+b2?arch=amd64\u0026upstream=rtmpdump%402.4+20151223.gitfa8646d.1-2\u0026distro=debian-11\u0026package-id=4f5f3212d3812c5d",
264534          "supplier": {},
264535          "publisher": "Debian Multimedia Maintainers \u003cdebian-multimedia@lists.debian.org\u003e",
264536          "name": "librtmp1",
264537          "version": "2.4+20151223.gitfa8646d.1-2+b2",
264538          "licenses": [
264539            {
264540              "license": {
264541                "id": "GPL-2.0-only"
264542              }
264543            },
264544            {
264545              "license": {
264546                "id": "LGPL-2.1-only"
264547              }
264548            }
264549          ],
264550          "cpe": "cpe:2.3:a:librtmp1:librtmp1:2.4\\+20151223.gitfa8646d.1-2\\+b2:*:*:*:*:*:*:*",
264551          "purl": "pkg:deb/debian/librtmp1@2.4+20151223.gitfa8646d.1-2+b2?arch=amd64\u0026upstream=rtmpdump%402.4+20151223.gitfa8646d.1-2\u0026distro=debian-11",
264552          "swid": {
264553            "attachment": {}
264554          },
264555          "pedigree": {},
264556          "evidence": {},
264557          "signature": {
264558            "signature": {
264559              "publicKey": {}
264560            }
264561          },
264562          "modelCard": {
264563            "modelParameters": {
264564              "approach": {}
264565            },
264566            "quantitativeAnalysis": {
264567              "graphics": {}
264568            },
264569            "considerations": {}
264570          }
264571        },
264572        {
264573          "type": "library",
264574          "bom-ref": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11\u0026package-id=77ea74a82c5fc951",
264575          "supplier": {},
264576          "publisher": "Debian Cyrus Team \u003cteam+cyrus@tracker.debian.org\u003e",
264577          "name": "libsasl2-2",
264578          "version": "2.1.27+dfsg-2.1+deb11u1",
264579          "licenses": [
264580            {
264581              "license": {
264582                "id": "BSD-4-Clause"
264583              }
264584            },
264585            {
264586              "license": {
264587                "id": "GPL-3.0-only"
264588              }
264589            },
264590            {
264591              "license": {
264592                "id": "GPL-3.0-or-later"
264593              }
264594            }
264595          ],
264596          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-2.1\\+deb11u1:*:*:*:*:*:*:*",
264597          "purl": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11",
264598          "swid": {
264599            "attachment": {}
264600          },
264601          "pedigree": {},
264602          "evidence": {},
264603          "signature": {
264604            "signature": {
264605              "publicKey": {}
264606            }
264607          },
264608          "modelCard": {
264609            "modelParameters": {
264610              "approach": {}
264611            },
264612            "quantitativeAnalysis": {
264613              "graphics": {}
264614            },
264615            "considerations": {}
264616          }
264617        },
264618        {
264619          "type": "library",
264620          "bom-ref": "pkg:deb/debian/libsasl2-modules-db@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11\u0026package-id=1e10a1d2edb3e77a",
264621          "supplier": {},
264622          "publisher": "Debian Cyrus Team \u003cteam+cyrus@tracker.debian.org\u003e",
264623          "name": "libsasl2-modules-db",
264624          "version": "2.1.27+dfsg-2.1+deb11u1",
264625          "licenses": [
264626            {
264627              "license": {
264628                "id": "BSD-4-Clause"
264629              }
264630            },
264631            {
264632              "license": {
264633                "id": "GPL-3.0-only"
264634              }
264635            },
264636            {
264637              "license": {
264638                "id": "GPL-3.0-or-later"
264639              }
264640            }
264641          ],
264642          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\+dfsg-2.1\\+deb11u1:*:*:*:*:*:*:*",
264643          "purl": "pkg:deb/debian/libsasl2-modules-db@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11",
264644          "swid": {
264645            "attachment": {}
264646          },
264647          "pedigree": {},
264648          "evidence": {},
264649          "signature": {
264650            "signature": {
264651              "publicKey": {}
264652            }
264653          },
264654          "modelCard": {
264655            "modelParameters": {
264656              "approach": {}
264657            },
264658            "quantitativeAnalysis": {
264659              "graphics": {}
264660            },
264661            "considerations": {}
264662          }
264663        },
264664        {
264665          "type": "library",
264666          "bom-ref": "pkg:deb/debian/libseccomp2@2.5.1-1+deb11u1?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-11\u0026package-id=bb0878d1437830b4",
264667          "supplier": {},
264668          "publisher": "Kees Cook \u003ckees@debian.org\u003e",
264669          "name": "libseccomp2",
264670          "version": "2.5.1-1+deb11u1",
264671          "licenses": [
264672            {
264673              "license": {
264674                "id": "LGPL-2.1-only"
264675              }
264676            }
264677          ],
264678          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.5.1-1\\+deb11u1:*:*:*:*:*:*:*",
264679          "purl": "pkg:deb/debian/libseccomp2@2.5.1-1+deb11u1?arch=amd64\u0026upstream=libseccomp\u0026distro=debian-11",
264680          "swid": {
264681            "attachment": {}
264682          },
264683          "pedigree": {},
264684          "evidence": {},
264685          "signature": {
264686            "signature": {
264687              "publicKey": {}
264688            }
264689          },
264690          "modelCard": {
264691            "modelParameters": {
264692              "approach": {}
264693            },
264694            "quantitativeAnalysis": {
264695              "graphics": {}
264696            },
264697            "considerations": {}
264698          }
264699        },
264700        {
264701          "type": "library",
264702          "bom-ref": "pkg:deb/debian/libselinux1@3.1-3?arch=amd64\u0026upstream=libselinux\u0026distro=debian-11\u0026package-id=bb9d0a1adefb7931",
264703          "supplier": {},
264704          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
264705          "name": "libselinux1",
264706          "version": "3.1-3",
264707          "licenses": [
264708            {
264709              "license": {
264710                "id": "GPL-2.0-only"
264711              }
264712            },
264713            {
264714              "license": {
264715                "id": "LGPL-2.1-only"
264716              }
264717            }
264718          ],
264719          "cpe": "cpe:2.3:a:libselinux1:libselinux1:3.1-3:*:*:*:*:*:*:*",
264720          "purl": "pkg:deb/debian/libselinux1@3.1-3?arch=amd64\u0026upstream=libselinux\u0026distro=debian-11",
264721          "swid": {
264722            "attachment": {}
264723          },
264724          "pedigree": {},
264725          "evidence": {},
264726          "signature": {
264727            "signature": {
264728              "publicKey": {}
264729            }
264730          },
264731          "modelCard": {
264732            "modelParameters": {
264733              "approach": {}
264734            },
264735            "quantitativeAnalysis": {
264736              "graphics": {}
264737            },
264738            "considerations": {}
264739          }
264740        },
264741        {
264742          "type": "library",
264743          "bom-ref": "pkg:deb/debian/libsemanage-common@3.1-1?arch=all\u0026upstream=libsemanage\u0026distro=debian-11\u0026package-id=f41fe741bd23f493",
264744          "supplier": {},
264745          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
264746          "name": "libsemanage-common",
264747          "version": "3.1-1",
264748          "licenses": [
264749            {
264750              "license": {
264751                "name": "GPL"
264752              }
264753            },
264754            {
264755              "license": {
264756                "name": "LGPL"
264757              }
264758            }
264759          ],
264760          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:3.1-1:*:*:*:*:*:*:*",
264761          "purl": "pkg:deb/debian/libsemanage-common@3.1-1?arch=all\u0026upstream=libsemanage\u0026distro=debian-11",
264762          "swid": {
264763            "attachment": {}
264764          },
264765          "pedigree": {},
264766          "evidence": {},
264767          "signature": {
264768            "signature": {
264769              "publicKey": {}
264770            }
264771          },
264772          "modelCard": {
264773            "modelParameters": {
264774              "approach": {}
264775            },
264776            "quantitativeAnalysis": {
264777              "graphics": {}
264778            },
264779            "considerations": {}
264780          }
264781        },
264782        {
264783          "type": "library",
264784          "bom-ref": "pkg:deb/debian/libsemanage1@3.1-1+b2?arch=amd64\u0026upstream=libsemanage%403.1-1\u0026distro=debian-11\u0026package-id=fa4813c20a8027a6",
264785          "supplier": {},
264786          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
264787          "name": "libsemanage1",
264788          "version": "3.1-1+b2",
264789          "licenses": [
264790            {
264791              "license": {
264792                "name": "GPL"
264793              }
264794            },
264795            {
264796              "license": {
264797                "name": "LGPL"
264798              }
264799            }
264800          ],
264801          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:3.1-1\\+b2:*:*:*:*:*:*:*",
264802          "purl": "pkg:deb/debian/libsemanage1@3.1-1+b2?arch=amd64\u0026upstream=libsemanage%403.1-1\u0026distro=debian-11",
264803          "swid": {
264804            "attachment": {}
264805          },
264806          "pedigree": {},
264807          "evidence": {},
264808          "signature": {
264809            "signature": {
264810              "publicKey": {}
264811            }
264812          },
264813          "modelCard": {
264814            "modelParameters": {
264815              "approach": {}
264816            },
264817            "quantitativeAnalysis": {
264818              "graphics": {}
264819            },
264820            "considerations": {}
264821          }
264822        },
264823        {
264824          "type": "library",
264825          "bom-ref": "pkg:deb/debian/libsensors-config@1:3.6.0-7?arch=all\u0026upstream=lm-sensors\u0026distro=debian-11\u0026package-id=8bdfd0c7b4bd6",
264826          "supplier": {},
264827          "publisher": "Aurelien Jarno \u003caurel32@debian.org\u003e",
264828          "name": "libsensors-config",
264829          "version": "1:3.6.0-7",
264830          "licenses": [
264831            {
264832              "license": {
264833                "id": "GPL-2.0-only"
264834              }
264835            },
264836            {
264837              "license": {
264838                "id": "LGPL-2.1-only"
264839              }
264840            }
264841          ],
264842          "cpe": "cpe:2.3:a:libsensors-config:libsensors-config:1\\:3.6.0-7:*:*:*:*:*:*:*",
264843          "purl": "pkg:deb/debian/libsensors-config@1:3.6.0-7?arch=all\u0026upstream=lm-sensors\u0026distro=debian-11",
264844          "swid": {
264845            "attachment": {}
264846          },
264847          "pedigree": {},
264848          "evidence": {},
264849          "signature": {
264850            "signature": {
264851              "publicKey": {}
264852            }
264853          },
264854          "modelCard": {
264855            "modelParameters": {
264856              "approach": {}
264857            },
264858            "quantitativeAnalysis": {
264859              "graphics": {}
264860            },
264861            "considerations": {}
264862          }
264863        },
264864        {
264865          "type": "library",
264866          "bom-ref": "pkg:deb/debian/libsensors5@1:3.6.0-7?arch=amd64\u0026upstream=lm-sensors\u0026distro=debian-11\u0026package-id=af14da8cfedd8260",
264867          "supplier": {},
264868          "publisher": "Aurelien Jarno \u003caurel32@debian.org\u003e",
264869          "name": "libsensors5",
264870          "version": "1:3.6.0-7",
264871          "licenses": [
264872            {
264873              "license": {
264874                "id": "GPL-2.0-only"
264875              }
264876            },
264877            {
264878              "license": {
264879                "id": "LGPL-2.1-only"
264880              }
264881            }
264882          ],
264883          "cpe": "cpe:2.3:a:libsensors5:libsensors5:1\\:3.6.0-7:*:*:*:*:*:*:*",
264884          "purl": "pkg:deb/debian/libsensors5@1:3.6.0-7?arch=amd64\u0026upstream=lm-sensors\u0026distro=debian-11",
264885          "swid": {
264886            "attachment": {}
264887          },
264888          "pedigree": {},
264889          "evidence": {},
264890          "signature": {
264891            "signature": {
264892              "publicKey": {}
264893            }
264894          },
264895          "modelCard": {
264896            "modelParameters": {
264897              "approach": {}
264898            },
264899            "quantitativeAnalysis": {
264900              "graphics": {}
264901            },
264902            "considerations": {}
264903          }
264904        },
264905        {
264906          "type": "library",
264907          "bom-ref": "pkg:deb/debian/libsepol1@3.1-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-11\u0026package-id=cfa6f496d2fd049",
264908          "supplier": {},
264909          "publisher": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e",
264910          "name": "libsepol1",
264911          "version": "3.1-1",
264912          "licenses": [
264913            {
264914              "license": {
264915                "name": "GPL"
264916              }
264917            },
264918            {
264919              "license": {
264920                "name": "LGPL"
264921              }
264922            }
264923          ],
264924          "cpe": "cpe:2.3:a:libsepol1:libsepol1:3.1-1:*:*:*:*:*:*:*",
264925          "purl": "pkg:deb/debian/libsepol1@3.1-1?arch=amd64\u0026upstream=libsepol\u0026distro=debian-11",
264926          "swid": {
264927            "attachment": {}
264928          },
264929          "pedigree": {},
264930          "evidence": {},
264931          "signature": {
264932            "signature": {
264933              "publicKey": {}
264934            }
264935          },
264936          "modelCard": {
264937            "modelParameters": {
264938              "approach": {}
264939            },
264940            "quantitativeAnalysis": {
264941              "graphics": {}
264942            },
264943            "considerations": {}
264944          }
264945        },
264946        {
264947          "type": "library",
264948          "bom-ref": "pkg:deb/debian/libsmartcols1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=cf3b22adc552a311",
264949          "supplier": {},
264950          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
264951          "name": "libsmartcols1",
264952          "version": "2.36.1-8+deb11u1",
264953          "licenses": [
264954            {
264955              "license": {
264956                "id": "BSD-2-Clause"
264957              }
264958            },
264959            {
264960              "license": {
264961                "id": "BSD-3-Clause"
264962              }
264963            },
264964            {
264965              "license": {
264966                "id": "BSD-4-Clause"
264967              }
264968            },
264969            {
264970              "license": {
264971                "id": "GPL-2.0-only"
264972              }
264973            },
264974            {
264975              "license": {
264976                "id": "GPL-2.0-or-later"
264977              }
264978            },
264979            {
264980              "license": {
264981                "id": "GPL-3.0-only"
264982              }
264983            },
264984            {
264985              "license": {
264986                "id": "GPL-3.0-or-later"
264987              }
264988            },
264989            {
264990              "license": {
264991                "name": "LGPL"
264992              }
264993            },
264994            {
264995              "license": {
264996                "id": "LGPL-2.0-only"
264997              }
264998            },
264999            {
265000              "license": {
265001                "id": "LGPL-2.0-or-later"
265002              }
265003            },
265004            {
265005              "license": {
265006                "id": "LGPL-2.1-only"
265007              }
265008            },
265009            {
265010              "license": {
265011                "id": "LGPL-2.1-or-later"
265012              }
265013            },
265014            {
265015              "license": {
265016                "id": "LGPL-3.0-only"
265017              }
265018            },
265019            {
265020              "license": {
265021                "id": "LGPL-3.0-or-later"
265022              }
265023            },
265024            {
265025              "license": {
265026                "id": "MIT"
265027              }
265028            },
265029            {
265030              "license": {
265031                "name": "public-domain"
265032              }
265033            }
265034          ],
265035          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
265036          "purl": "pkg:deb/debian/libsmartcols1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
265037          "swid": {
265038            "attachment": {}
265039          },
265040          "pedigree": {},
265041          "evidence": {},
265042          "signature": {
265043            "signature": {
265044              "publicKey": {}
265045            }
265046          },
265047          "modelCard": {
265048            "modelParameters": {
265049              "approach": {}
265050            },
265051            "quantitativeAnalysis": {
265052              "graphics": {}
265053            },
265054            "considerations": {}
265055          }
265056        },
265057        {
265058          "type": "library",
265059          "bom-ref": "pkg:deb/debian/libsource-highlight-common@3.1.9-3?arch=all\u0026upstream=source-highlight\u0026distro=debian-11\u0026package-id=871404b6164e4cc6",
265060          "supplier": {},
265061          "publisher": "Kartik Kulkarni \u003ckartik.koolks@gmail.com\u003e",
265062          "name": "libsource-highlight-common",
265063          "version": "3.1.9-3",
265064          "licenses": [
265065            {
265066              "license": {
265067                "name": "Expat"
265068              }
265069            },
265070            {
265071              "license": {
265072                "id": "GPL-3.0-only"
265073              }
265074            },
265075            {
265076              "license": {
265077                "id": "GPL-3.0-or-later"
265078              }
265079            }
265080          ],
265081          "cpe": "cpe:2.3:a:libsource-highlight-common:libsource-highlight-common:3.1.9-3:*:*:*:*:*:*:*",
265082          "purl": "pkg:deb/debian/libsource-highlight-common@3.1.9-3?arch=all\u0026upstream=source-highlight\u0026distro=debian-11",
265083          "swid": {
265084            "attachment": {}
265085          },
265086          "pedigree": {},
265087          "evidence": {},
265088          "signature": {
265089            "signature": {
265090              "publicKey": {}
265091            }
265092          },
265093          "modelCard": {
265094            "modelParameters": {
265095              "approach": {}
265096            },
265097            "quantitativeAnalysis": {
265098              "graphics": {}
265099            },
265100            "considerations": {}
265101          }
265102        },
265103        {
265104          "type": "library",
265105          "bom-ref": "pkg:deb/debian/libsource-highlight4v5@3.1.9-3+b1?arch=amd64\u0026upstream=source-highlight%403.1.9-3\u0026distro=debian-11\u0026package-id=afd27e834ad2c5b6",
265106          "supplier": {},
265107          "publisher": "Kartik Kulkarni \u003ckartik.koolks@gmail.com\u003e",
265108          "name": "libsource-highlight4v5",
265109          "version": "3.1.9-3+b1",
265110          "licenses": [
265111            {
265112              "license": {
265113                "name": "Expat"
265114              }
265115            },
265116            {
265117              "license": {
265118                "id": "GPL-3.0-only"
265119              }
265120            },
265121            {
265122              "license": {
265123                "id": "GPL-3.0-or-later"
265124              }
265125            }
265126          ],
265127          "cpe": "cpe:2.3:a:libsource-highlight4v5:libsource-highlight4v5:3.1.9-3\\+b1:*:*:*:*:*:*:*",
265128          "purl": "pkg:deb/debian/libsource-highlight4v5@3.1.9-3+b1?arch=amd64\u0026upstream=source-highlight%403.1.9-3\u0026distro=debian-11",
265129          "swid": {
265130            "attachment": {}
265131          },
265132          "pedigree": {},
265133          "evidence": {},
265134          "signature": {
265135            "signature": {
265136              "publicKey": {}
265137            }
265138          },
265139          "modelCard": {
265140            "modelParameters": {
265141              "approach": {}
265142            },
265143            "quantitativeAnalysis": {
265144              "graphics": {}
265145            },
265146            "considerations": {}
265147          }
265148        },
265149        {
265150          "type": "library",
265151          "bom-ref": "pkg:deb/debian/libsqlite3-0@3.34.1-3?arch=amd64\u0026upstream=sqlite3\u0026distro=debian-11\u0026package-id=373ed1f8b8bffc03",
265152          "supplier": {},
265153          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
265154          "name": "libsqlite3-0",
265155          "version": "3.34.1-3",
265156          "licenses": [
265157            {
265158              "license": {
265159                "id": "GPL-2.0-only"
265160              }
265161            },
265162            {
265163              "license": {
265164                "id": "GPL-2.0-or-later"
265165              }
265166            },
265167            {
265168              "license": {
265169                "name": "public-domain"
265170              }
265171            }
265172          ],
265173          "cpe": "cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.34.1-3:*:*:*:*:*:*:*",
265174          "purl": "pkg:deb/debian/libsqlite3-0@3.34.1-3?arch=amd64\u0026upstream=sqlite3\u0026distro=debian-11",
265175          "swid": {
265176            "attachment": {}
265177          },
265178          "pedigree": {},
265179          "evidence": {},
265180          "signature": {
265181            "signature": {
265182              "publicKey": {}
265183            }
265184          },
265185          "modelCard": {
265186            "modelParameters": {
265187              "approach": {}
265188            },
265189            "quantitativeAnalysis": {
265190              "graphics": {}
265191            },
265192            "considerations": {}
265193          }
265194        },
265195        {
265196          "type": "library",
265197          "bom-ref": "pkg:deb/debian/libss2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=4ba13b2c11cb0876",
265198          "supplier": {},
265199          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
265200          "name": "libss2",
265201          "version": "1.46.2-2",
265202          "cpe": "cpe:2.3:a:libss2:libss2:1.46.2-2:*:*:*:*:*:*:*",
265203          "purl": "pkg:deb/debian/libss2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
265204          "swid": {
265205            "attachment": {}
265206          },
265207          "pedigree": {},
265208          "evidence": {},
265209          "signature": {
265210            "signature": {
265211              "publicKey": {}
265212            }
265213          },
265214          "modelCard": {
265215            "modelParameters": {
265216              "approach": {}
265217            },
265218            "quantitativeAnalysis": {
265219              "graphics": {}
265220            },
265221            "considerations": {}
265222          }
265223        },
265224        {
265225          "type": "library",
265226          "bom-ref": "pkg:deb/debian/libssh2-1@1.9.0-2?arch=amd64\u0026upstream=libssh2\u0026distro=debian-11\u0026package-id=7b11dbeecfce2854",
265227          "supplier": {},
265228          "publisher": "Nicolas Mora \u003cbabelouest@debian.org\u003e",
265229          "name": "libssh2-1",
265230          "version": "1.9.0-2",
265231          "licenses": [
265232            {
265233              "license": {
265234                "name": "BSD3"
265235              }
265236            }
265237          ],
265238          "cpe": "cpe:2.3:a:libssh2-1:libssh2-1:1.9.0-2:*:*:*:*:*:*:*",
265239          "purl": "pkg:deb/debian/libssh2-1@1.9.0-2?arch=amd64\u0026upstream=libssh2\u0026distro=debian-11",
265240          "swid": {
265241            "attachment": {}
265242          },
265243          "pedigree": {},
265244          "evidence": {},
265245          "signature": {
265246            "signature": {
265247              "publicKey": {}
265248            }
265249          },
265250          "modelCard": {
265251            "modelParameters": {
265252              "approach": {}
265253            },
265254            "quantitativeAnalysis": {
265255              "graphics": {}
265256            },
265257            "considerations": {}
265258          }
265259        },
265260        {
265261          "type": "library",
265262          "bom-ref": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u3?arch=amd64\u0026upstream=openssl\u0026distro=debian-11\u0026package-id=1f1a72119651ccc9",
265263          "supplier": {},
265264          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
265265          "name": "libssl1.1",
265266          "version": "1.1.1n-0+deb11u3",
265267          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1n-0\\+deb11u3:*:*:*:*:*:*:*",
265268          "purl": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u3?arch=amd64\u0026upstream=openssl\u0026distro=debian-11",
265269          "swid": {
265270            "attachment": {}
265271          },
265272          "pedigree": {},
265273          "evidence": {},
265274          "signature": {
265275            "signature": {
265276              "publicKey": {}
265277            }
265278          },
265279          "modelCard": {
265280            "modelParameters": {
265281              "approach": {}
265282            },
265283            "quantitativeAnalysis": {
265284              "graphics": {}
265285            },
265286            "considerations": {}
265287          }
265288        },
265289        {
265290          "type": "library",
265291          "bom-ref": "pkg:deb/debian/libstdc++-10-dev@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=a8bb337f3114d06f",
265292          "supplier": {},
265293          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
265294          "name": "libstdc++-10-dev",
265295          "version": "10.2.1-6",
265296          "licenses": [
265297            {
265298              "license": {
265299                "name": "Artistic"
265300              }
265301            },
265302            {
265303              "license": {
265304                "id": "GFDL-1.2-only"
265305              }
265306            },
265307            {
265308              "license": {
265309                "name": "GPL"
265310              }
265311            },
265312            {
265313              "license": {
265314                "id": "GPL-2.0-only"
265315              }
265316            },
265317            {
265318              "license": {
265319                "id": "GPL-3.0-only"
265320              }
265321            },
265322            {
265323              "license": {
265324                "name": "LGPL"
265325              }
265326            }
265327          ],
265328          "cpe": "cpe:2.3:a:libstdc\\+\\+-10-dev:libstdc\\+\\+-10-dev:10.2.1-6:*:*:*:*:*:*:*",
265329          "purl": "pkg:deb/debian/libstdc++-10-dev@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
265330          "swid": {
265331            "attachment": {}
265332          },
265333          "pedigree": {},
265334          "evidence": {},
265335          "signature": {
265336            "signature": {
265337              "publicKey": {}
265338            }
265339          },
265340          "modelCard": {
265341            "modelParameters": {
265342              "approach": {}
265343            },
265344            "quantitativeAnalysis": {
265345              "graphics": {}
265346            },
265347            "considerations": {}
265348          }
265349        },
265350        {
265351          "type": "library",
265352          "bom-ref": "pkg:deb/debian/libstdc++6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=748369630632944",
265353          "supplier": {},
265354          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
265355          "name": "libstdc++6",
265356          "version": "10.2.1-6",
265357          "licenses": [
265358            {
265359              "license": {
265360                "name": "Artistic"
265361              }
265362            },
265363            {
265364              "license": {
265365                "id": "GFDL-1.2-only"
265366              }
265367            },
265368            {
265369              "license": {
265370                "name": "GPL"
265371              }
265372            },
265373            {
265374              "license": {
265375                "id": "GPL-2.0-only"
265376              }
265377            },
265378            {
265379              "license": {
265380                "id": "GPL-3.0-only"
265381              }
265382            },
265383            {
265384              "license": {
265385                "name": "LGPL"
265386              }
265387            }
265388          ],
265389          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.2.1-6:*:*:*:*:*:*:*",
265390          "purl": "pkg:deb/debian/libstdc++6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
265391          "swid": {
265392            "attachment": {}
265393          },
265394          "pedigree": {},
265395          "evidence": {},
265396          "signature": {
265397            "signature": {
265398              "publicKey": {}
265399            }
265400          },
265401          "modelCard": {
265402            "modelParameters": {
265403              "approach": {}
265404            },
265405            "quantitativeAnalysis": {
265406              "graphics": {}
265407            },
265408            "considerations": {}
265409          }
265410        },
265411        {
265412          "type": "library",
265413          "bom-ref": "pkg:deb/debian/libsystemd0@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11\u0026package-id=4c258dc3b086d634",
265414          "supplier": {},
265415          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
265416          "name": "libsystemd0",
265417          "version": "247.3-7+deb11u1",
265418          "licenses": [
265419            {
265420              "license": {
265421                "id": "CC0-1.0"
265422              }
265423            },
265424            {
265425              "license": {
265426                "name": "Expat"
265427              }
265428            },
265429            {
265430              "license": {
265431                "id": "GPL-2.0-only"
265432              }
265433            },
265434            {
265435              "license": {
265436                "id": "GPL-2.0-or-later"
265437              }
265438            },
265439            {
265440              "license": {
265441                "id": "LGPL-2.1-only"
265442              }
265443            },
265444            {
265445              "license": {
265446                "id": "LGPL-2.1-or-later"
265447              }
265448            },
265449            {
265450              "license": {
265451                "name": "public-domain"
265452              }
265453            }
265454          ],
265455          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:247.3-7\\+deb11u1:*:*:*:*:*:*:*",
265456          "purl": "pkg:deb/debian/libsystemd0@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11",
265457          "swid": {
265458            "attachment": {}
265459          },
265460          "pedigree": {},
265461          "evidence": {},
265462          "signature": {
265463            "signature": {
265464              "publicKey": {}
265465            }
265466          },
265467          "modelCard": {
265468            "modelParameters": {
265469              "approach": {}
265470            },
265471            "quantitativeAnalysis": {
265472              "graphics": {}
265473            },
265474            "considerations": {}
265475          }
265476        },
265477        {
265478          "type": "library",
265479          "bom-ref": "pkg:deb/debian/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=debian-11\u0026package-id=8385ea5e56a5fca9",
265480          "supplier": {},
265481          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
265482          "name": "libtasn1-6",
265483          "version": "4.16.0-2",
265484          "licenses": [
265485            {
265486              "license": {
265487                "id": "GFDL-1.3-only"
265488              }
265489            },
265490            {
265491              "license": {
265492                "id": "GPL-3.0-only"
265493              }
265494            },
265495            {
265496              "license": {
265497                "name": "LGPL"
265498              }
265499            },
265500            {
265501              "license": {
265502                "id": "LGPL-2.1-only"
265503              }
265504            }
265505          ],
265506          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2:*:*:*:*:*:*:*",
265507          "purl": "pkg:deb/debian/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=debian-11",
265508          "swid": {
265509            "attachment": {}
265510          },
265511          "pedigree": {},
265512          "evidence": {},
265513          "signature": {
265514            "signature": {
265515              "publicKey": {}
265516            }
265517          },
265518          "modelCard": {
265519            "modelParameters": {
265520              "approach": {}
265521            },
265522            "quantitativeAnalysis": {
265523              "graphics": {}
265524            },
265525            "considerations": {}
265526          }
265527        },
265528        {
265529          "type": "library",
265530          "bom-ref": "pkg:deb/debian/libthai-data@0.1.28-3?arch=all\u0026upstream=libthai\u0026distro=debian-11\u0026package-id=a45678a4f884dbc7",
265531          "supplier": {},
265532          "publisher": "Theppitak Karoonboonyanan \u003cthep@debian.org\u003e",
265533          "name": "libthai-data",
265534          "version": "0.1.28-3",
265535          "licenses": [
265536            {
265537              "license": {
265538                "id": "GPL-2.0-only"
265539              }
265540            },
265541            {
265542              "license": {
265543                "id": "GPL-2.0-or-later"
265544              }
265545            },
265546            {
265547              "license": {
265548                "id": "LGPL-2.1-only"
265549              }
265550            },
265551            {
265552              "license": {
265553                "id": "LGPL-2.1-or-later"
265554              }
265555            }
265556          ],
265557          "cpe": "cpe:2.3:a:libthai-data:libthai-data:0.1.28-3:*:*:*:*:*:*:*",
265558          "purl": "pkg:deb/debian/libthai-data@0.1.28-3?arch=all\u0026upstream=libthai\u0026distro=debian-11",
265559          "swid": {
265560            "attachment": {}
265561          },
265562          "pedigree": {},
265563          "evidence": {},
265564          "signature": {
265565            "signature": {
265566              "publicKey": {}
265567            }
265568          },
265569          "modelCard": {
265570            "modelParameters": {
265571              "approach": {}
265572            },
265573            "quantitativeAnalysis": {
265574              "graphics": {}
265575            },
265576            "considerations": {}
265577          }
265578        },
265579        {
265580          "type": "library",
265581          "bom-ref": "pkg:deb/debian/libthai0@0.1.28-3?arch=amd64\u0026upstream=libthai\u0026distro=debian-11\u0026package-id=df056741aa45e5f9",
265582          "supplier": {},
265583          "publisher": "Theppitak Karoonboonyanan \u003cthep@debian.org\u003e",
265584          "name": "libthai0",
265585          "version": "0.1.28-3",
265586          "licenses": [
265587            {
265588              "license": {
265589                "id": "GPL-2.0-only"
265590              }
265591            },
265592            {
265593              "license": {
265594                "id": "GPL-2.0-or-later"
265595              }
265596            },
265597            {
265598              "license": {
265599                "id": "LGPL-2.1-only"
265600              }
265601            },
265602            {
265603              "license": {
265604                "id": "LGPL-2.1-or-later"
265605              }
265606            }
265607          ],
265608          "cpe": "cpe:2.3:a:libthai0:libthai0:0.1.28-3:*:*:*:*:*:*:*",
265609          "purl": "pkg:deb/debian/libthai0@0.1.28-3?arch=amd64\u0026upstream=libthai\u0026distro=debian-11",
265610          "swid": {
265611            "attachment": {}
265612          },
265613          "pedigree": {},
265614          "evidence": {},
265615          "signature": {
265616            "signature": {
265617              "publicKey": {}
265618            }
265619          },
265620          "modelCard": {
265621            "modelParameters": {
265622              "approach": {}
265623            },
265624            "quantitativeAnalysis": {
265625              "graphics": {}
265626            },
265627            "considerations": {}
265628          }
265629        },
265630        {
265631          "type": "library",
265632          "bom-ref": "pkg:deb/debian/libtiff5@4.2.0-1+deb11u1?arch=amd64\u0026upstream=tiff\u0026distro=debian-11\u0026package-id=38e84af4b5984ce3",
265633          "supplier": {},
265634          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
265635          "name": "libtiff5",
265636          "version": "4.2.0-1+deb11u1",
265637          "licenses": [
265638            {
265639              "license": {
265640                "name": "Hylafax"
265641              }
265642            }
265643          ],
265644          "cpe": "cpe:2.3:a:libtiff5:libtiff5:4.2.0-1\\+deb11u1:*:*:*:*:*:*:*",
265645          "purl": "pkg:deb/debian/libtiff5@4.2.0-1+deb11u1?arch=amd64\u0026upstream=tiff\u0026distro=debian-11",
265646          "swid": {
265647            "attachment": {}
265648          },
265649          "pedigree": {},
265650          "evidence": {},
265651          "signature": {
265652            "signature": {
265653              "publicKey": {}
265654            }
265655          },
265656          "modelCard": {
265657            "modelParameters": {
265658              "approach": {}
265659            },
265660            "quantitativeAnalysis": {
265661              "graphics": {}
265662            },
265663            "considerations": {}
265664          }
265665        },
265666        {
265667          "type": "library",
265668          "bom-ref": "pkg:deb/debian/libtinfo6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=9e96601b60336037",
265669          "supplier": {},
265670          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
265671          "name": "libtinfo6",
265672          "version": "6.2+20201114-2",
265673          "licenses": [
265674            {
265675              "license": {
265676                "id": "BSD-3-Clause"
265677              }
265678            },
265679            {
265680              "license": {
265681                "name": "MIT/X11"
265682              }
265683            },
265684            {
265685              "license": {
265686                "id": "X11"
265687              }
265688            }
265689          ],
265690          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.2\\+20201114-2:*:*:*:*:*:*:*",
265691          "purl": "pkg:deb/debian/libtinfo6@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11",
265692          "swid": {
265693            "attachment": {}
265694          },
265695          "pedigree": {},
265696          "evidence": {},
265697          "signature": {
265698            "signature": {
265699              "publicKey": {}
265700            }
265701          },
265702          "modelCard": {
265703            "modelParameters": {
265704              "approach": {}
265705            },
265706            "quantitativeAnalysis": {
265707              "graphics": {}
265708            },
265709            "considerations": {}
265710          }
265711        },
265712        {
265713          "type": "library",
265714          "bom-ref": "pkg:deb/debian/libtirpc-common@1.3.1-1+deb11u1?arch=all\u0026upstream=libtirpc\u0026distro=debian-11\u0026package-id=3623a1ef0b5b63b9",
265715          "supplier": {},
265716          "publisher": "Josue Ortega \u003cjosue@debian.org\u003e",
265717          "name": "libtirpc-common",
265718          "version": "1.3.1-1+deb11u1",
265719          "licenses": [
265720            {
265721              "license": {
265722                "id": "BSD-3-Clause"
265723              }
265724            },
265725            {
265726              "license": {
265727                "id": "GPL-2.0-only"
265728              }
265729            },
265730            {
265731              "license": {
265732                "id": "LGPL-2.1-only"
265733              }
265734            }
265735          ],
265736          "cpe": "cpe:2.3:a:libtirpc-common:libtirpc-common:1.3.1-1\\+deb11u1:*:*:*:*:*:*:*",
265737          "purl": "pkg:deb/debian/libtirpc-common@1.3.1-1+deb11u1?arch=all\u0026upstream=libtirpc\u0026distro=debian-11",
265738          "swid": {
265739            "attachment": {}
265740          },
265741          "pedigree": {},
265742          "evidence": {},
265743          "signature": {
265744            "signature": {
265745              "publicKey": {}
265746            }
265747          },
265748          "modelCard": {
265749            "modelParameters": {
265750              "approach": {}
265751            },
265752            "quantitativeAnalysis": {
265753              "graphics": {}
265754            },
265755            "considerations": {}
265756          }
265757        },
265758        {
265759          "type": "library",
265760          "bom-ref": "pkg:deb/debian/libtirpc-dev@1.3.1-1+deb11u1?arch=amd64\u0026upstream=libtirpc\u0026distro=debian-11\u0026package-id=7e633fe46be14994",
265761          "supplier": {},
265762          "publisher": "Josue Ortega \u003cjosue@debian.org\u003e",
265763          "name": "libtirpc-dev",
265764          "version": "1.3.1-1+deb11u1",
265765          "licenses": [
265766            {
265767              "license": {
265768                "id": "BSD-3-Clause"
265769              }
265770            },
265771            {
265772              "license": {
265773                "id": "GPL-2.0-only"
265774              }
265775            },
265776            {
265777              "license": {
265778                "id": "LGPL-2.1-only"
265779              }
265780            }
265781          ],
265782          "cpe": "cpe:2.3:a:libtirpc-dev:libtirpc-dev:1.3.1-1\\+deb11u1:*:*:*:*:*:*:*",
265783          "purl": "pkg:deb/debian/libtirpc-dev@1.3.1-1+deb11u1?arch=amd64\u0026upstream=libtirpc\u0026distro=debian-11",
265784          "swid": {
265785            "attachment": {}
265786          },
265787          "pedigree": {},
265788          "evidence": {},
265789          "signature": {
265790            "signature": {
265791              "publicKey": {}
265792            }
265793          },
265794          "modelCard": {
265795            "modelParameters": {
265796              "approach": {}
265797            },
265798            "quantitativeAnalysis": {
265799              "graphics": {}
265800            },
265801            "considerations": {}
265802          }
265803        },
265804        {
265805          "type": "library",
265806          "bom-ref": "pkg:deb/debian/libtirpc3@1.3.1-1+deb11u1?arch=amd64\u0026upstream=libtirpc\u0026distro=debian-11\u0026package-id=c7b97f0b9d21e851",
265807          "supplier": {},
265808          "publisher": "Josue Ortega \u003cjosue@debian.org\u003e",
265809          "name": "libtirpc3",
265810          "version": "1.3.1-1+deb11u1",
265811          "licenses": [
265812            {
265813              "license": {
265814                "id": "BSD-3-Clause"
265815              }
265816            },
265817            {
265818              "license": {
265819                "id": "GPL-2.0-only"
265820              }
265821            },
265822            {
265823              "license": {
265824                "id": "LGPL-2.1-only"
265825              }
265826            }
265827          ],
265828          "cpe": "cpe:2.3:a:libtirpc3:libtirpc3:1.3.1-1\\+deb11u1:*:*:*:*:*:*:*",
265829          "purl": "pkg:deb/debian/libtirpc3@1.3.1-1+deb11u1?arch=amd64\u0026upstream=libtirpc\u0026distro=debian-11",
265830          "swid": {
265831            "attachment": {}
265832          },
265833          "pedigree": {},
265834          "evidence": {},
265835          "signature": {
265836            "signature": {
265837              "publicKey": {}
265838            }
265839          },
265840          "modelCard": {
265841            "modelParameters": {
265842              "approach": {}
265843            },
265844            "quantitativeAnalysis": {
265845              "graphics": {}
265846            },
265847            "considerations": {}
265848          }
265849        },
265850        {
265851          "type": "library",
265852          "bom-ref": "pkg:deb/debian/libtsan0@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=83a443dc658b63f",
265853          "supplier": {},
265854          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
265855          "name": "libtsan0",
265856          "version": "10.2.1-6",
265857          "licenses": [
265858            {
265859              "license": {
265860                "name": "Artistic"
265861              }
265862            },
265863            {
265864              "license": {
265865                "id": "GFDL-1.2-only"
265866              }
265867            },
265868            {
265869              "license": {
265870                "name": "GPL"
265871              }
265872            },
265873            {
265874              "license": {
265875                "id": "GPL-2.0-only"
265876              }
265877            },
265878            {
265879              "license": {
265880                "id": "GPL-3.0-only"
265881              }
265882            },
265883            {
265884              "license": {
265885                "name": "LGPL"
265886              }
265887            }
265888          ],
265889          "cpe": "cpe:2.3:a:libtsan0:libtsan0:10.2.1-6:*:*:*:*:*:*:*",
265890          "purl": "pkg:deb/debian/libtsan0@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
265891          "swid": {
265892            "attachment": {}
265893          },
265894          "pedigree": {},
265895          "evidence": {},
265896          "signature": {
265897            "signature": {
265898              "publicKey": {}
265899            }
265900          },
265901          "modelCard": {
265902            "modelParameters": {
265903              "approach": {}
265904            },
265905            "quantitativeAnalysis": {
265906              "graphics": {}
265907            },
265908            "considerations": {}
265909          }
265910        },
265911        {
265912          "type": "library",
265913          "bom-ref": "pkg:deb/debian/libubsan1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=8aaa96ac167225f2",
265914          "supplier": {},
265915          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
265916          "name": "libubsan1",
265917          "version": "10.2.1-6",
265918          "licenses": [
265919            {
265920              "license": {
265921                "name": "Artistic"
265922              }
265923            },
265924            {
265925              "license": {
265926                "id": "GFDL-1.2-only"
265927              }
265928            },
265929            {
265930              "license": {
265931                "name": "GPL"
265932              }
265933            },
265934            {
265935              "license": {
265936                "id": "GPL-2.0-only"
265937              }
265938            },
265939            {
265940              "license": {
265941                "id": "GPL-3.0-only"
265942              }
265943            },
265944            {
265945              "license": {
265946                "name": "LGPL"
265947              }
265948            }
265949          ],
265950          "cpe": "cpe:2.3:a:libubsan1:libubsan1:10.2.1-6:*:*:*:*:*:*:*",
265951          "purl": "pkg:deb/debian/libubsan1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
265952          "swid": {
265953            "attachment": {}
265954          },
265955          "pedigree": {},
265956          "evidence": {},
265957          "signature": {
265958            "signature": {
265959              "publicKey": {}
265960            }
265961          },
265962          "modelCard": {
265963            "modelParameters": {
265964              "approach": {}
265965            },
265966            "quantitativeAnalysis": {
265967              "graphics": {}
265968            },
265969            "considerations": {}
265970          }
265971        },
265972        {
265973          "type": "library",
265974          "bom-ref": "pkg:deb/debian/libudev1@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11\u0026package-id=79c718cff72e218e",
265975          "supplier": {},
265976          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
265977          "name": "libudev1",
265978          "version": "247.3-7+deb11u1",
265979          "licenses": [
265980            {
265981              "license": {
265982                "id": "CC0-1.0"
265983              }
265984            },
265985            {
265986              "license": {
265987                "name": "Expat"
265988              }
265989            },
265990            {
265991              "license": {
265992                "id": "GPL-2.0-only"
265993              }
265994            },
265995            {
265996              "license": {
265997                "id": "GPL-2.0-or-later"
265998              }
265999            },
266000            {
266001              "license": {
266002                "id": "LGPL-2.1-only"
266003              }
266004            },
266005            {
266006              "license": {
266007                "id": "LGPL-2.1-or-later"
266008              }
266009            },
266010            {
266011              "license": {
266012                "name": "public-domain"
266013              }
266014            }
266015          ],
266016          "cpe": "cpe:2.3:a:libudev1:libudev1:247.3-7\\+deb11u1:*:*:*:*:*:*:*",
266017          "purl": "pkg:deb/debian/libudev1@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11",
266018          "swid": {
266019            "attachment": {}
266020          },
266021          "pedigree": {},
266022          "evidence": {},
266023          "signature": {
266024            "signature": {
266025              "publicKey": {}
266026            }
266027          },
266028          "modelCard": {
266029            "modelParameters": {
266030              "approach": {}
266031            },
266032            "quantitativeAnalysis": {
266033              "graphics": {}
266034            },
266035            "considerations": {}
266036          }
266037        },
266038        {
266039          "type": "library",
266040          "bom-ref": "pkg:deb/debian/libunistring2@0.9.10-4?arch=amd64\u0026upstream=libunistring\u0026distro=debian-11\u0026package-id=dc7fcfc9dde2b703",
266041          "supplier": {},
266042          "publisher": "Jörg Frings-Fürst \u003cdebian@jff.email\u003e",
266043          "name": "libunistring2",
266044          "version": "0.9.10-4",
266045          "licenses": [
266046            {
266047              "license": {
266048                "name": "FreeSoftware"
266049              }
266050            },
266051            {
266052              "license": {
266053                "id": "GFDL-1.2-only"
266054              }
266055            },
266056            {
266057              "license": {
266058                "name": "GFDL-1.2+"
266059              }
266060            },
266061            {
266062              "license": {
266063                "id": "GPL-2.0-only"
266064              }
266065            },
266066            {
266067              "license": {
266068                "id": "GPL-2.0-or-later"
266069              }
266070            },
266071            {
266072              "license": {
266073                "id": "GPL-3.0-only"
266074              }
266075            },
266076            {
266077              "license": {
266078                "id": "GPL-3.0-or-later"
266079              }
266080            },
266081            {
266082              "license": {
266083                "id": "LGPL-3.0-only"
266084              }
266085            },
266086            {
266087              "license": {
266088                "id": "LGPL-3.0-or-later"
266089              }
266090            },
266091            {
266092              "license": {
266093                "id": "MIT"
266094              }
266095            }
266096          ],
266097          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-4:*:*:*:*:*:*:*",
266098          "purl": "pkg:deb/debian/libunistring2@0.9.10-4?arch=amd64\u0026upstream=libunistring\u0026distro=debian-11",
266099          "swid": {
266100            "attachment": {}
266101          },
266102          "pedigree": {},
266103          "evidence": {},
266104          "signature": {
266105            "signature": {
266106              "publicKey": {}
266107            }
266108          },
266109          "modelCard": {
266110            "modelParameters": {
266111              "approach": {}
266112            },
266113            "quantitativeAnalysis": {
266114              "graphics": {}
266115            },
266116            "considerations": {}
266117          }
266118        },
266119        {
266120          "type": "library",
266121          "bom-ref": "pkg:deb/debian/libunwind8@1.3.2-2?arch=amd64\u0026upstream=libunwind\u0026distro=debian-11\u0026package-id=a6684a06050b7d94",
266122          "supplier": {},
266123          "publisher": "Adrian Bunk \u003cbunk@debian.org\u003e",
266124          "name": "libunwind8",
266125          "version": "1.3.2-2",
266126          "licenses": [
266127            {
266128              "license": {
266129                "name": "Expat"
266130              }
266131            },
266132            {
266133              "license": {
266134                "id": "GPL-2.0-only"
266135              }
266136            },
266137            {
266138              "license": {
266139                "id": "GPL-2.0-or-later"
266140              }
266141            }
266142          ],
266143          "cpe": "cpe:2.3:a:libunwind8:libunwind8:1.3.2-2:*:*:*:*:*:*:*",
266144          "purl": "pkg:deb/debian/libunwind8@1.3.2-2?arch=amd64\u0026upstream=libunwind\u0026distro=debian-11",
266145          "swid": {
266146            "attachment": {}
266147          },
266148          "pedigree": {},
266149          "evidence": {},
266150          "signature": {
266151            "signature": {
266152              "publicKey": {}
266153            }
266154          },
266155          "modelCard": {
266156            "modelParameters": {
266157              "approach": {}
266158            },
266159            "quantitativeAnalysis": {
266160              "graphics": {}
266161            },
266162            "considerations": {}
266163          }
266164        },
266165        {
266166          "type": "library",
266167          "bom-ref": "pkg:deb/debian/libutempter0@1.2.1-2?arch=amd64\u0026upstream=libutempter\u0026distro=debian-11\u0026package-id=35c6b4894b99c171",
266168          "supplier": {},
266169          "publisher": "Christian Göttsche \u003ccgzones@googlemail.com\u003e",
266170          "name": "libutempter0",
266171          "version": "1.2.1-2",
266172          "licenses": [
266173            {
266174              "license": {
266175                "id": "LGPL-2.1-only"
266176              }
266177            }
266178          ],
266179          "cpe": "cpe:2.3:a:libutempter0:libutempter0:1.2.1-2:*:*:*:*:*:*:*",
266180          "purl": "pkg:deb/debian/libutempter0@1.2.1-2?arch=amd64\u0026upstream=libutempter\u0026distro=debian-11",
266181          "swid": {
266182            "attachment": {}
266183          },
266184          "pedigree": {},
266185          "evidence": {},
266186          "signature": {
266187            "signature": {
266188              "publicKey": {}
266189            }
266190          },
266191          "modelCard": {
266192            "modelParameters": {
266193              "approach": {}
266194            },
266195            "quantitativeAnalysis": {
266196              "graphics": {}
266197            },
266198            "considerations": {}
266199          }
266200        },
266201        {
266202          "type": "library",
266203          "bom-ref": "pkg:deb/debian/libuuid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=e87310d3e1426d6c",
266204          "supplier": {},
266205          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
266206          "name": "libuuid1",
266207          "version": "2.36.1-8+deb11u1",
266208          "licenses": [
266209            {
266210              "license": {
266211                "id": "BSD-2-Clause"
266212              }
266213            },
266214            {
266215              "license": {
266216                "id": "BSD-3-Clause"
266217              }
266218            },
266219            {
266220              "license": {
266221                "id": "BSD-4-Clause"
266222              }
266223            },
266224            {
266225              "license": {
266226                "id": "GPL-2.0-only"
266227              }
266228            },
266229            {
266230              "license": {
266231                "id": "GPL-2.0-or-later"
266232              }
266233            },
266234            {
266235              "license": {
266236                "id": "GPL-3.0-only"
266237              }
266238            },
266239            {
266240              "license": {
266241                "id": "GPL-3.0-or-later"
266242              }
266243            },
266244            {
266245              "license": {
266246                "name": "LGPL"
266247              }
266248            },
266249            {
266250              "license": {
266251                "id": "LGPL-2.0-only"
266252              }
266253            },
266254            {
266255              "license": {
266256                "id": "LGPL-2.0-or-later"
266257              }
266258            },
266259            {
266260              "license": {
266261                "id": "LGPL-2.1-only"
266262              }
266263            },
266264            {
266265              "license": {
266266                "id": "LGPL-2.1-or-later"
266267              }
266268            },
266269            {
266270              "license": {
266271                "id": "LGPL-3.0-only"
266272              }
266273            },
266274            {
266275              "license": {
266276                "id": "LGPL-3.0-or-later"
266277              }
266278            },
266279            {
266280              "license": {
266281                "id": "MIT"
266282              }
266283            },
266284            {
266285              "license": {
266286                "name": "public-domain"
266287              }
266288            }
266289          ],
266290          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
266291          "purl": "pkg:deb/debian/libuuid1@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
266292          "swid": {
266293            "attachment": {}
266294          },
266295          "pedigree": {},
266296          "evidence": {},
266297          "signature": {
266298            "signature": {
266299              "publicKey": {}
266300            }
266301          },
266302          "modelCard": {
266303            "modelParameters": {
266304              "approach": {}
266305            },
266306            "quantitativeAnalysis": {
266307              "graphics": {}
266308            },
266309            "considerations": {}
266310          }
266311        },
266312        {
266313          "type": "library",
266314          "bom-ref": "pkg:deb/debian/libuv1@1.40.0-2?arch=amd64\u0026distro=debian-11\u0026package-id=c148a0e42edb5812",
266315          "supplier": {},
266316          "publisher": "Dominique Dumont \u003cdod@debian.org\u003e",
266317          "name": "libuv1",
266318          "version": "1.40.0-2",
266319          "licenses": [
266320            {
266321              "license": {
266322                "id": "BSD-1-Clause"
266323              }
266324            },
266325            {
266326              "license": {
266327                "id": "BSD-2-Clause"
266328              }
266329            },
266330            {
266331              "license": {
266332                "id": "BSD-3-Clause"
266333              }
266334            },
266335            {
266336              "license": {
266337                "id": "CC-BY-4.0"
266338              }
266339            },
266340            {
266341              "license": {
266342                "name": "Expat"
266343              }
266344            },
266345            {
266346              "license": {
266347                "id": "GPL-3.0-or-later"
266348              }
266349            },
266350            {
266351              "license": {
266352                "id": "ISC"
266353              }
266354            }
266355          ],
266356          "cpe": "cpe:2.3:a:libuv1:libuv1:1.40.0-2:*:*:*:*:*:*:*",
266357          "purl": "pkg:deb/debian/libuv1@1.40.0-2?arch=amd64\u0026distro=debian-11",
266358          "swid": {
266359            "attachment": {}
266360          },
266361          "pedigree": {},
266362          "evidence": {},
266363          "signature": {
266364            "signature": {
266365              "publicKey": {}
266366            }
266367          },
266368          "modelCard": {
266369            "modelParameters": {
266370              "approach": {}
266371            },
266372            "quantitativeAnalysis": {
266373              "graphics": {}
266374            },
266375            "considerations": {}
266376          }
266377        },
266378        {
266379          "type": "library",
266380          "bom-ref": "pkg:deb/debian/libwebp6@0.6.1-2.1?arch=amd64\u0026upstream=libwebp\u0026distro=debian-11\u0026package-id=88ca886298d7e0b",
266381          "supplier": {},
266382          "publisher": "Jeff Breidenbach \u003cjab@debian.org\u003e",
266383          "name": "libwebp6",
266384          "version": "0.6.1-2.1",
266385          "licenses": [
266386            {
266387              "license": {
266388                "id": "Apache-2.0"
266389              }
266390            }
266391          ],
266392          "cpe": "cpe:2.3:a:libwebp6:libwebp6:0.6.1-2.1:*:*:*:*:*:*:*",
266393          "purl": "pkg:deb/debian/libwebp6@0.6.1-2.1?arch=amd64\u0026upstream=libwebp\u0026distro=debian-11",
266394          "swid": {
266395            "attachment": {}
266396          },
266397          "pedigree": {},
266398          "evidence": {},
266399          "signature": {
266400            "signature": {
266401              "publicKey": {}
266402            }
266403          },
266404          "modelCard": {
266405            "modelParameters": {
266406              "approach": {}
266407            },
266408            "quantitativeAnalysis": {
266409              "graphics": {}
266410            },
266411            "considerations": {}
266412          }
266413        },
266414        {
266415          "type": "library",
266416          "bom-ref": "pkg:deb/debian/libx11-6@2:1.7.2-1?arch=amd64\u0026upstream=libx11\u0026distro=debian-11\u0026package-id=ce4e2010925a4939",
266417          "supplier": {},
266418          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266419          "name": "libx11-6",
266420          "version": "2:1.7.2-1",
266421          "cpe": "cpe:2.3:a:libx11-6:libx11-6:2\\:1.7.2-1:*:*:*:*:*:*:*",
266422          "purl": "pkg:deb/debian/libx11-6@2:1.7.2-1?arch=amd64\u0026upstream=libx11\u0026distro=debian-11",
266423          "swid": {
266424            "attachment": {}
266425          },
266426          "pedigree": {},
266427          "evidence": {},
266428          "signature": {
266429            "signature": {
266430              "publicKey": {}
266431            }
266432          },
266433          "modelCard": {
266434            "modelParameters": {
266435              "approach": {}
266436            },
266437            "quantitativeAnalysis": {
266438              "graphics": {}
266439            },
266440            "considerations": {}
266441          }
266442        },
266443        {
266444          "type": "library",
266445          "bom-ref": "pkg:deb/debian/libx11-data@2:1.7.2-1?arch=all\u0026upstream=libx11\u0026distro=debian-11\u0026package-id=8defa9b2d11078dc",
266446          "supplier": {},
266447          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266448          "name": "libx11-data",
266449          "version": "2:1.7.2-1",
266450          "cpe": "cpe:2.3:a:libx11-data:libx11-data:2\\:1.7.2-1:*:*:*:*:*:*:*",
266451          "purl": "pkg:deb/debian/libx11-data@2:1.7.2-1?arch=all\u0026upstream=libx11\u0026distro=debian-11",
266452          "swid": {
266453            "attachment": {}
266454          },
266455          "pedigree": {},
266456          "evidence": {},
266457          "signature": {
266458            "signature": {
266459              "publicKey": {}
266460            }
266461          },
266462          "modelCard": {
266463            "modelParameters": {
266464              "approach": {}
266465            },
266466            "quantitativeAnalysis": {
266467              "graphics": {}
266468            },
266469            "considerations": {}
266470          }
266471        },
266472        {
266473          "type": "library",
266474          "bom-ref": "pkg:deb/debian/libxau6@1:1.0.9-1?arch=amd64\u0026upstream=libxau\u0026distro=debian-11\u0026package-id=e6c254c1e56081d8",
266475          "supplier": {},
266476          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266477          "name": "libxau6",
266478          "version": "1:1.0.9-1",
266479          "cpe": "cpe:2.3:a:libxau6:libxau6:1\\:1.0.9-1:*:*:*:*:*:*:*",
266480          "purl": "pkg:deb/debian/libxau6@1:1.0.9-1?arch=amd64\u0026upstream=libxau\u0026distro=debian-11",
266481          "swid": {
266482            "attachment": {}
266483          },
266484          "pedigree": {},
266485          "evidence": {},
266486          "signature": {
266487            "signature": {
266488              "publicKey": {}
266489            }
266490          },
266491          "modelCard": {
266492            "modelParameters": {
266493              "approach": {}
266494            },
266495            "quantitativeAnalysis": {
266496              "graphics": {}
266497            },
266498            "considerations": {}
266499          }
266500        },
266501        {
266502          "type": "library",
266503          "bom-ref": "pkg:deb/debian/libxcb-render0@1.14-3?arch=amd64\u0026upstream=libxcb\u0026distro=debian-11\u0026package-id=3155b288526dcd63",
266504          "supplier": {},
266505          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266506          "name": "libxcb-render0",
266507          "version": "1.14-3",
266508          "cpe": "cpe:2.3:a:libxcb-render0:libxcb-render0:1.14-3:*:*:*:*:*:*:*",
266509          "purl": "pkg:deb/debian/libxcb-render0@1.14-3?arch=amd64\u0026upstream=libxcb\u0026distro=debian-11",
266510          "swid": {
266511            "attachment": {}
266512          },
266513          "pedigree": {},
266514          "evidence": {},
266515          "signature": {
266516            "signature": {
266517              "publicKey": {}
266518            }
266519          },
266520          "modelCard": {
266521            "modelParameters": {
266522              "approach": {}
266523            },
266524            "quantitativeAnalysis": {
266525              "graphics": {}
266526            },
266527            "considerations": {}
266528          }
266529        },
266530        {
266531          "type": "library",
266532          "bom-ref": "pkg:deb/debian/libxcb-shm0@1.14-3?arch=amd64\u0026upstream=libxcb\u0026distro=debian-11\u0026package-id=3a21b443c8a292e1",
266533          "supplier": {},
266534          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266535          "name": "libxcb-shm0",
266536          "version": "1.14-3",
266537          "cpe": "cpe:2.3:a:libxcb-shm0:libxcb-shm0:1.14-3:*:*:*:*:*:*:*",
266538          "purl": "pkg:deb/debian/libxcb-shm0@1.14-3?arch=amd64\u0026upstream=libxcb\u0026distro=debian-11",
266539          "swid": {
266540            "attachment": {}
266541          },
266542          "pedigree": {},
266543          "evidence": {},
266544          "signature": {
266545            "signature": {
266546              "publicKey": {}
266547            }
266548          },
266549          "modelCard": {
266550            "modelParameters": {
266551              "approach": {}
266552            },
266553            "quantitativeAnalysis": {
266554              "graphics": {}
266555            },
266556            "considerations": {}
266557          }
266558        },
266559        {
266560          "type": "library",
266561          "bom-ref": "pkg:deb/debian/libxcb1@1.14-3?arch=amd64\u0026upstream=libxcb\u0026distro=debian-11\u0026package-id=9281d5ec3fb0ebd8",
266562          "supplier": {},
266563          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266564          "name": "libxcb1",
266565          "version": "1.14-3",
266566          "cpe": "cpe:2.3:a:libxcb1:libxcb1:1.14-3:*:*:*:*:*:*:*",
266567          "purl": "pkg:deb/debian/libxcb1@1.14-3?arch=amd64\u0026upstream=libxcb\u0026distro=debian-11",
266568          "swid": {
266569            "attachment": {}
266570          },
266571          "pedigree": {},
266572          "evidence": {},
266573          "signature": {
266574            "signature": {
266575              "publicKey": {}
266576            }
266577          },
266578          "modelCard": {
266579            "modelParameters": {
266580              "approach": {}
266581            },
266582            "quantitativeAnalysis": {
266583              "graphics": {}
266584            },
266585            "considerations": {}
266586          }
266587        },
266588        {
266589          "type": "library",
266590          "bom-ref": "pkg:deb/debian/libxcomposite1@1:0.4.5-1?arch=amd64\u0026upstream=libxcomposite\u0026distro=debian-11\u0026package-id=213069b92189166",
266591          "supplier": {},
266592          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266593          "name": "libxcomposite1",
266594          "version": "1:0.4.5-1",
266595          "cpe": "cpe:2.3:a:libxcomposite1:libxcomposite1:1\\:0.4.5-1:*:*:*:*:*:*:*",
266596          "purl": "pkg:deb/debian/libxcomposite1@1:0.4.5-1?arch=amd64\u0026upstream=libxcomposite\u0026distro=debian-11",
266597          "swid": {
266598            "attachment": {}
266599          },
266600          "pedigree": {},
266601          "evidence": {},
266602          "signature": {
266603            "signature": {
266604              "publicKey": {}
266605            }
266606          },
266607          "modelCard": {
266608            "modelParameters": {
266609              "approach": {}
266610            },
266611            "quantitativeAnalysis": {
266612              "graphics": {}
266613            },
266614            "considerations": {}
266615          }
266616        },
266617        {
266618          "type": "library",
266619          "bom-ref": "pkg:deb/debian/libxcursor1@1:1.2.0-2?arch=amd64\u0026upstream=libxcursor\u0026distro=debian-11\u0026package-id=b76001f5b07d32c7",
266620          "supplier": {},
266621          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266622          "name": "libxcursor1",
266623          "version": "1:1.2.0-2",
266624          "cpe": "cpe:2.3:a:libxcursor1:libxcursor1:1\\:1.2.0-2:*:*:*:*:*:*:*",
266625          "purl": "pkg:deb/debian/libxcursor1@1:1.2.0-2?arch=amd64\u0026upstream=libxcursor\u0026distro=debian-11",
266626          "swid": {
266627            "attachment": {}
266628          },
266629          "pedigree": {},
266630          "evidence": {},
266631          "signature": {
266632            "signature": {
266633              "publicKey": {}
266634            }
266635          },
266636          "modelCard": {
266637            "modelParameters": {
266638              "approach": {}
266639            },
266640            "quantitativeAnalysis": {
266641              "graphics": {}
266642            },
266643            "considerations": {}
266644          }
266645        },
266646        {
266647          "type": "library",
266648          "bom-ref": "pkg:deb/debian/libxdamage1@1:1.1.5-2?arch=amd64\u0026upstream=libxdamage\u0026distro=debian-11\u0026package-id=4c83a910129b29fb",
266649          "supplier": {},
266650          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266651          "name": "libxdamage1",
266652          "version": "1:1.1.5-2",
266653          "cpe": "cpe:2.3:a:libxdamage1:libxdamage1:1\\:1.1.5-2:*:*:*:*:*:*:*",
266654          "purl": "pkg:deb/debian/libxdamage1@1:1.1.5-2?arch=amd64\u0026upstream=libxdamage\u0026distro=debian-11",
266655          "swid": {
266656            "attachment": {}
266657          },
266658          "pedigree": {},
266659          "evidence": {},
266660          "signature": {
266661            "signature": {
266662              "publicKey": {}
266663            }
266664          },
266665          "modelCard": {
266666            "modelParameters": {
266667              "approach": {}
266668            },
266669            "quantitativeAnalysis": {
266670              "graphics": {}
266671            },
266672            "considerations": {}
266673          }
266674        },
266675        {
266676          "type": "library",
266677          "bom-ref": "pkg:deb/debian/libxdmcp6@1:1.1.2-3?arch=amd64\u0026upstream=libxdmcp\u0026distro=debian-11\u0026package-id=4005b45e460ecaca",
266678          "supplier": {},
266679          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266680          "name": "libxdmcp6",
266681          "version": "1:1.1.2-3",
266682          "cpe": "cpe:2.3:a:libxdmcp6:libxdmcp6:1\\:1.1.2-3:*:*:*:*:*:*:*",
266683          "purl": "pkg:deb/debian/libxdmcp6@1:1.1.2-3?arch=amd64\u0026upstream=libxdmcp\u0026distro=debian-11",
266684          "swid": {
266685            "attachment": {}
266686          },
266687          "pedigree": {},
266688          "evidence": {},
266689          "signature": {
266690            "signature": {
266691              "publicKey": {}
266692            }
266693          },
266694          "modelCard": {
266695            "modelParameters": {
266696              "approach": {}
266697            },
266698            "quantitativeAnalysis": {
266699              "graphics": {}
266700            },
266701            "considerations": {}
266702          }
266703        },
266704        {
266705          "type": "library",
266706          "bom-ref": "pkg:deb/debian/libxext6@2:1.3.3-1.1?arch=amd64\u0026upstream=libxext\u0026distro=debian-11\u0026package-id=5b7fd9c7f30d7df8",
266707          "supplier": {},
266708          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266709          "name": "libxext6",
266710          "version": "2:1.3.3-1.1",
266711          "cpe": "cpe:2.3:a:libxext6:libxext6:2\\:1.3.3-1.1:*:*:*:*:*:*:*",
266712          "purl": "pkg:deb/debian/libxext6@2:1.3.3-1.1?arch=amd64\u0026upstream=libxext\u0026distro=debian-11",
266713          "swid": {
266714            "attachment": {}
266715          },
266716          "pedigree": {},
266717          "evidence": {},
266718          "signature": {
266719            "signature": {
266720              "publicKey": {}
266721            }
266722          },
266723          "modelCard": {
266724            "modelParameters": {
266725              "approach": {}
266726            },
266727            "quantitativeAnalysis": {
266728              "graphics": {}
266729            },
266730            "considerations": {}
266731          }
266732        },
266733        {
266734          "type": "library",
266735          "bom-ref": "pkg:deb/debian/libxfixes3@1:5.0.3-2?arch=amd64\u0026upstream=libxfixes\u0026distro=debian-11\u0026package-id=e3618c5fcc11ca54",
266736          "supplier": {},
266737          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266738          "name": "libxfixes3",
266739          "version": "1:5.0.3-2",
266740          "cpe": "cpe:2.3:a:libxfixes3:libxfixes3:1\\:5.0.3-2:*:*:*:*:*:*:*",
266741          "purl": "pkg:deb/debian/libxfixes3@1:5.0.3-2?arch=amd64\u0026upstream=libxfixes\u0026distro=debian-11",
266742          "swid": {
266743            "attachment": {}
266744          },
266745          "pedigree": {},
266746          "evidence": {},
266747          "signature": {
266748            "signature": {
266749              "publicKey": {}
266750            }
266751          },
266752          "modelCard": {
266753            "modelParameters": {
266754              "approach": {}
266755            },
266756            "quantitativeAnalysis": {
266757              "graphics": {}
266758            },
266759            "considerations": {}
266760          }
266761        },
266762        {
266763          "type": "library",
266764          "bom-ref": "pkg:deb/debian/libxi6@2:1.7.10-1?arch=amd64\u0026upstream=libxi\u0026distro=debian-11\u0026package-id=7f9e16f9019fd76a",
266765          "supplier": {},
266766          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266767          "name": "libxi6",
266768          "version": "2:1.7.10-1",
266769          "cpe": "cpe:2.3:a:libxi6:libxi6:2\\:1.7.10-1:*:*:*:*:*:*:*",
266770          "purl": "pkg:deb/debian/libxi6@2:1.7.10-1?arch=amd64\u0026upstream=libxi\u0026distro=debian-11",
266771          "swid": {
266772            "attachment": {}
266773          },
266774          "pedigree": {},
266775          "evidence": {},
266776          "signature": {
266777            "signature": {
266778              "publicKey": {}
266779            }
266780          },
266781          "modelCard": {
266782            "modelParameters": {
266783              "approach": {}
266784            },
266785            "quantitativeAnalysis": {
266786              "graphics": {}
266787            },
266788            "considerations": {}
266789          }
266790        },
266791        {
266792          "type": "library",
266793          "bom-ref": "pkg:deb/debian/libxinerama1@2:1.1.4-2?arch=amd64\u0026upstream=libxinerama\u0026distro=debian-11\u0026package-id=d95c5d714ff087f2",
266794          "supplier": {},
266795          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266796          "name": "libxinerama1",
266797          "version": "2:1.1.4-2",
266798          "cpe": "cpe:2.3:a:libxinerama1:libxinerama1:2\\:1.1.4-2:*:*:*:*:*:*:*",
266799          "purl": "pkg:deb/debian/libxinerama1@2:1.1.4-2?arch=amd64\u0026upstream=libxinerama\u0026distro=debian-11",
266800          "swid": {
266801            "attachment": {}
266802          },
266803          "pedigree": {},
266804          "evidence": {},
266805          "signature": {
266806            "signature": {
266807              "publicKey": {}
266808            }
266809          },
266810          "modelCard": {
266811            "modelParameters": {
266812              "approach": {}
266813            },
266814            "quantitativeAnalysis": {
266815              "graphics": {}
266816            },
266817            "considerations": {}
266818          }
266819        },
266820        {
266821          "type": "library",
266822          "bom-ref": "pkg:deb/debian/libxml2@2.9.10+dfsg-6.7+deb11u3?arch=amd64\u0026distro=debian-11\u0026package-id=17dda21225ad6175",
266823          "supplier": {},
266824          "publisher": "Debian XML/SGML Group \u003cdebian-xml-sgml-pkgs@lists.alioth.debian.org\u003e",
266825          "name": "libxml2",
266826          "version": "2.9.10+dfsg-6.7+deb11u3",
266827          "licenses": [
266828            {
266829              "license": {
266830                "id": "ISC"
266831              }
266832            },
266833            {
266834              "license": {
266835                "name": "MIT-1"
266836              }
266837            }
266838          ],
266839          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.10\\+dfsg-6.7\\+deb11u3:*:*:*:*:*:*:*",
266840          "purl": "pkg:deb/debian/libxml2@2.9.10+dfsg-6.7+deb11u3?arch=amd64\u0026distro=debian-11",
266841          "swid": {
266842            "attachment": {}
266843          },
266844          "pedigree": {},
266845          "evidence": {},
266846          "signature": {
266847            "signature": {
266848              "publicKey": {}
266849            }
266850          },
266851          "modelCard": {
266852            "modelParameters": {
266853              "approach": {}
266854            },
266855            "quantitativeAnalysis": {
266856              "graphics": {}
266857            },
266858            "considerations": {}
266859          }
266860        },
266861        {
266862          "type": "library",
266863          "bom-ref": "pkg:deb/debian/libxrandr2@2:1.5.1-1?arch=amd64\u0026upstream=libxrandr\u0026distro=debian-11\u0026package-id=453a5e24b42f10c1",
266864          "supplier": {},
266865          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266866          "name": "libxrandr2",
266867          "version": "2:1.5.1-1",
266868          "cpe": "cpe:2.3:a:libxrandr2:libxrandr2:2\\:1.5.1-1:*:*:*:*:*:*:*",
266869          "purl": "pkg:deb/debian/libxrandr2@2:1.5.1-1?arch=amd64\u0026upstream=libxrandr\u0026distro=debian-11",
266870          "swid": {
266871            "attachment": {}
266872          },
266873          "pedigree": {},
266874          "evidence": {},
266875          "signature": {
266876            "signature": {
266877              "publicKey": {}
266878            }
266879          },
266880          "modelCard": {
266881            "modelParameters": {
266882              "approach": {}
266883            },
266884            "quantitativeAnalysis": {
266885              "graphics": {}
266886            },
266887            "considerations": {}
266888          }
266889        },
266890        {
266891          "type": "library",
266892          "bom-ref": "pkg:deb/debian/libxrender1@1:0.9.10-1?arch=amd64\u0026upstream=libxrender\u0026distro=debian-11\u0026package-id=c0f2f2de266b969a",
266893          "supplier": {},
266894          "publisher": "Debian X Strike Force \u003cdebian-x@lists.debian.org\u003e",
266895          "name": "libxrender1",
266896          "version": "1:0.9.10-1",
266897          "cpe": "cpe:2.3:a:libxrender1:libxrender1:1\\:0.9.10-1:*:*:*:*:*:*:*",
266898          "purl": "pkg:deb/debian/libxrender1@1:0.9.10-1?arch=amd64\u0026upstream=libxrender\u0026distro=debian-11",
266899          "swid": {
266900            "attachment": {}
266901          },
266902          "pedigree": {},
266903          "evidence": {},
266904          "signature": {
266905            "signature": {
266906              "publicKey": {}
266907            }
266908          },
266909          "modelCard": {
266910            "modelParameters": {
266911              "approach": {}
266912            },
266913            "quantitativeAnalysis": {
266914              "graphics": {}
266915            },
266916            "considerations": {}
266917          }
266918        },
266919        {
266920          "type": "library",
266921          "bom-ref": "pkg:deb/debian/libxxhash0@0.8.0-2?arch=amd64\u0026upstream=xxhash\u0026distro=debian-11\u0026package-id=edc71d7591d40133",
266922          "supplier": {},
266923          "publisher": "Norbert Preining \u003cnorbert@preining.info\u003e",
266924          "name": "libxxhash0",
266925          "version": "0.8.0-2",
266926          "licenses": [
266927            {
266928              "license": {
266929                "id": "BSD-2-Clause"
266930              }
266931            },
266932            {
266933              "license": {
266934                "id": "GPL-2.0-only"
266935              }
266936            }
266937          ],
266938          "cpe": "cpe:2.3:a:libxxhash0:libxxhash0:0.8.0-2:*:*:*:*:*:*:*",
266939          "purl": "pkg:deb/debian/libxxhash0@0.8.0-2?arch=amd64\u0026upstream=xxhash\u0026distro=debian-11",
266940          "swid": {
266941            "attachment": {}
266942          },
266943          "pedigree": {},
266944          "evidence": {},
266945          "signature": {
266946            "signature": {
266947              "publicKey": {}
266948            }
266949          },
266950          "modelCard": {
266951            "modelParameters": {
266952              "approach": {}
266953            },
266954            "quantitativeAnalysis": {
266955              "graphics": {}
266956            },
266957            "considerations": {}
266958          }
266959        },
266960        {
266961          "type": "library",
266962          "bom-ref": "pkg:deb/debian/libyaml-0-2@0.2.2-1?arch=amd64\u0026upstream=libyaml\u0026distro=debian-11\u0026package-id=6a475ea76d7af8e2",
266963          "supplier": {},
266964          "publisher": "Anders Kaseorg \u003candersk@mit.edu\u003e",
266965          "name": "libyaml-0-2",
266966          "version": "0.2.2-1",
266967          "licenses": [
266968            {
266969              "license": {
266970                "name": "Expat"
266971              }
266972            },
266973            {
266974              "license": {
266975                "name": "permissive"
266976              }
266977            }
266978          ],
266979          "cpe": "cpe:2.3:a:libyaml-0-2:libyaml-0-2:0.2.2-1:*:*:*:*:*:*:*",
266980          "purl": "pkg:deb/debian/libyaml-0-2@0.2.2-1?arch=amd64\u0026upstream=libyaml\u0026distro=debian-11",
266981          "swid": {
266982            "attachment": {}
266983          },
266984          "pedigree": {},
266985          "evidence": {},
266986          "signature": {
266987            "signature": {
266988              "publicKey": {}
266989            }
266990          },
266991          "modelCard": {
266992            "modelParameters": {
266993              "approach": {}
266994            },
266995            "quantitativeAnalysis": {
266996              "graphics": {}
266997            },
266998            "considerations": {}
266999          }
267000        },
267001        {
267002          "type": "library",
267003          "bom-ref": "pkg:deb/debian/libzstd1@1.4.8+dfsg-2.1?arch=amd64\u0026upstream=libzstd\u0026distro=debian-11\u0026package-id=90e1680def07a674",
267004          "supplier": {},
267005          "publisher": "Debian Med Packaging Team \u003cdebian-med-packaging@lists.alioth.debian.org\u003e",
267006          "name": "libzstd1",
267007          "version": "1.4.8+dfsg-2.1",
267008          "licenses": [
267009            {
267010              "license": {
267011                "id": "BSD-3-Clause"
267012              }
267013            },
267014            {
267015              "license": {
267016                "name": "Expat"
267017              }
267018            },
267019            {
267020              "license": {
267021                "id": "GPL-2.0-only"
267022              }
267023            },
267024            {
267025              "license": {
267026                "id": "Zlib"
267027              }
267028            }
267029          ],
267030          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.8\\+dfsg-2.1:*:*:*:*:*:*:*",
267031          "purl": "pkg:deb/debian/libzstd1@1.4.8+dfsg-2.1?arch=amd64\u0026upstream=libzstd\u0026distro=debian-11",
267032          "swid": {
267033            "attachment": {}
267034          },
267035          "pedigree": {},
267036          "evidence": {},
267037          "signature": {
267038            "signature": {
267039              "publicKey": {}
267040            }
267041          },
267042          "modelCard": {
267043            "modelParameters": {
267044              "approach": {}
267045            },
267046            "quantitativeAnalysis": {
267047              "graphics": {}
267048            },
267049            "considerations": {}
267050          }
267051        },
267052        {
267053          "type": "library",
267054          "bom-ref": "pkg:deb/debian/linux-libc-dev@5.10.149-2?arch=amd64\u0026upstream=linux\u0026distro=debian-11\u0026package-id=369b8494e28fd277",
267055          "supplier": {},
267056          "publisher": "Debian Kernel Team \u003cdebian-kernel@lists.debian.org\u003e",
267057          "name": "linux-libc-dev",
267058          "version": "5.10.149-2",
267059          "licenses": [
267060            {
267061              "license": {
267062                "id": "BSD-2-Clause"
267063              }
267064            },
267065            {
267066              "license": {
267067                "name": "CRYPTOGAMS"
267068              }
267069            },
267070            {
267071              "license": {
267072                "id": "GPL-2.0-only"
267073              }
267074            },
267075            {
267076              "license": {
267077                "id": "GPL-2.0-or-later"
267078              }
267079            },
267080            {
267081              "license": {
267082                "id": "LGPL-2.1-only"
267083              }
267084            },
267085            {
267086              "license": {
267087                "name": "Unicode-data"
267088              }
267089            },
267090            {
267091              "license": {
267092                "name": "Xen-interface"
267093              }
267094            }
267095          ],
267096          "cpe": "cpe:2.3:a:linux-libc-dev:linux-libc-dev:5.10.149-2:*:*:*:*:*:*:*",
267097          "purl": "pkg:deb/debian/linux-libc-dev@5.10.149-2?arch=amd64\u0026upstream=linux\u0026distro=debian-11",
267098          "swid": {
267099            "attachment": {}
267100          },
267101          "pedigree": {},
267102          "evidence": {},
267103          "signature": {
267104            "signature": {
267105              "publicKey": {}
267106            }
267107          },
267108          "modelCard": {
267109            "modelParameters": {
267110              "approach": {}
267111            },
267112            "quantitativeAnalysis": {
267113              "graphics": {}
267114            },
267115            "considerations": {}
267116          }
267117        },
267118        {
267119          "type": "library",
267120          "bom-ref": "pkg:deb/debian/login@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11\u0026package-id=9cdbb92ea69c08a1",
267121          "supplier": {},
267122          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
267123          "name": "login",
267124          "version": "1:4.8.1-1",
267125          "licenses": [
267126            {
267127              "license": {
267128                "id": "GPL-2.0-only"
267129              }
267130            }
267131          ],
267132          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1:*:*:*:*:*:*:*",
267133          "purl": "pkg:deb/debian/login@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11",
267134          "swid": {
267135            "attachment": {}
267136          },
267137          "pedigree": {},
267138          "evidence": {},
267139          "signature": {
267140            "signature": {
267141              "publicKey": {}
267142            }
267143          },
267144          "modelCard": {
267145            "modelParameters": {
267146              "approach": {}
267147            },
267148            "quantitativeAnalysis": {
267149              "graphics": {}
267150            },
267151            "considerations": {}
267152          }
267153        },
267154        {
267155          "type": "library",
267156          "bom-ref": "pkg:deb/debian/logrotate@3.18.0-2+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=660e7d1ac851e6d9",
267157          "supplier": {},
267158          "publisher": "Christian Göttsche \u003ccgzones@googlemail.com\u003e",
267159          "name": "logrotate",
267160          "version": "3.18.0-2+deb11u1",
267161          "licenses": [
267162            {
267163              "license": {
267164                "id": "BSD-3-Clause"
267165              }
267166            },
267167            {
267168              "license": {
267169                "id": "GPL-2.0-only"
267170              }
267171            },
267172            {
267173              "license": {
267174                "id": "GPL-3.0-only"
267175              }
267176            },
267177            {
267178              "license": {
267179                "id": "GPL-3.0-or-later"
267180              }
267181            }
267182          ],
267183          "cpe": "cpe:2.3:a:logrotate:logrotate:3.18.0-2\\+deb11u1:*:*:*:*:*:*:*",
267184          "purl": "pkg:deb/debian/logrotate@3.18.0-2+deb11u1?arch=amd64\u0026distro=debian-11",
267185          "swid": {
267186            "attachment": {}
267187          },
267188          "pedigree": {},
267189          "evidence": {},
267190          "signature": {
267191            "signature": {
267192              "publicKey": {}
267193            }
267194          },
267195          "modelCard": {
267196            "modelParameters": {
267197              "approach": {}
267198            },
267199            "quantitativeAnalysis": {
267200              "graphics": {}
267201            },
267202            "considerations": {}
267203          }
267204        },
267205        {
267206          "type": "library",
267207          "bom-ref": "pkg:deb/debian/logsave@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=77e8cce6db62952b",
267208          "supplier": {},
267209          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
267210          "name": "logsave",
267211          "version": "1.46.2-2",
267212          "licenses": [
267213            {
267214              "license": {
267215                "id": "GPL-2.0-only"
267216              }
267217            },
267218            {
267219              "license": {
267220                "id": "LGPL-2.0-only"
267221              }
267222            }
267223          ],
267224          "cpe": "cpe:2.3:a:logsave:logsave:1.46.2-2:*:*:*:*:*:*:*",
267225          "purl": "pkg:deb/debian/logsave@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
267226          "swid": {
267227            "attachment": {}
267228          },
267229          "pedigree": {},
267230          "evidence": {},
267231          "signature": {
267232            "signature": {
267233              "publicKey": {}
267234            }
267235          },
267236          "modelCard": {
267237            "modelParameters": {
267238              "approach": {}
267239            },
267240            "quantitativeAnalysis": {
267241              "graphics": {}
267242            },
267243            "considerations": {}
267244          }
267245        },
267246        {
267247          "type": "library",
267248          "bom-ref": "pkg:deb/debian/lsb-base@11.1.0?arch=all\u0026upstream=lsb\u0026distro=debian-11\u0026package-id=67f43d818d5952cf",
267249          "supplier": {},
267250          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
267251          "name": "lsb-base",
267252          "version": "11.1.0",
267253          "licenses": [
267254            {
267255              "license": {
267256                "id": "BSD-3-Clause"
267257              }
267258            },
267259            {
267260              "license": {
267261                "id": "GPL-2.0-only"
267262              }
267263            }
267264          ],
267265          "cpe": "cpe:2.3:a:lsb-base:lsb-base:11.1.0:*:*:*:*:*:*:*",
267266          "purl": "pkg:deb/debian/lsb-base@11.1.0?arch=all\u0026upstream=lsb\u0026distro=debian-11",
267267          "swid": {
267268            "attachment": {}
267269          },
267270          "pedigree": {},
267271          "evidence": {},
267272          "signature": {
267273            "signature": {
267274              "publicKey": {}
267275            }
267276          },
267277          "modelCard": {
267278            "modelParameters": {
267279              "approach": {}
267280            },
267281            "quantitativeAnalysis": {
267282              "graphics": {}
267283            },
267284            "considerations": {}
267285          }
267286        },
267287        {
267288          "type": "library",
267289          "bom-ref": "pkg:deb/debian/lua-lpeg@1.0.2-1?arch=amd64\u0026distro=debian-11\u0026package-id=5b88e65f195b13f5",
267290          "supplier": {},
267291          "publisher": "Enrico Tassi \u003cgareuselesinge@debian.org\u003e",
267292          "name": "lua-lpeg",
267293          "version": "1.0.2-1",
267294          "licenses": [
267295            {
267296              "license": {
267297                "name": "MIT/X"
267298              }
267299            }
267300          ],
267301          "cpe": "cpe:2.3:a:lua-lpeg:lua-lpeg:1.0.2-1:*:*:*:*:*:*:*",
267302          "purl": "pkg:deb/debian/lua-lpeg@1.0.2-1?arch=amd64\u0026distro=debian-11",
267303          "swid": {
267304            "attachment": {}
267305          },
267306          "pedigree": {},
267307          "evidence": {},
267308          "signature": {
267309            "signature": {
267310              "publicKey": {}
267311            }
267312          },
267313          "modelCard": {
267314            "modelParameters": {
267315              "approach": {}
267316            },
267317            "quantitativeAnalysis": {
267318              "graphics": {}
267319            },
267320            "considerations": {}
267321          }
267322        },
267323        {
267324          "type": "library",
267325          "bom-ref": "pkg:deb/debian/make@4.3-4.1?arch=amd64\u0026upstream=make-dfsg\u0026distro=debian-11\u0026package-id=54606893b2e0c6b3",
267326          "supplier": {},
267327          "publisher": "Manoj Srivastava \u003csrivasta@debian.org\u003e",
267328          "name": "make",
267329          "version": "4.3-4.1",
267330          "licenses": [
267331            {
267332              "license": {
267333                "id": "GPL-3.0-only"
267334              }
267335            },
267336            {
267337              "license": {
267338                "id": "GPL-3.0-or-later"
267339              }
267340            }
267341          ],
267342          "cpe": "cpe:2.3:a:make:make:4.3-4.1:*:*:*:*:*:*:*",
267343          "purl": "pkg:deb/debian/make@4.3-4.1?arch=amd64\u0026upstream=make-dfsg\u0026distro=debian-11",
267344          "swid": {
267345            "attachment": {}
267346          },
267347          "pedigree": {},
267348          "evidence": {},
267349          "signature": {
267350            "signature": {
267351              "publicKey": {}
267352            }
267353          },
267354          "modelCard": {
267355            "modelParameters": {
267356              "approach": {}
267357            },
267358            "quantitativeAnalysis": {
267359              "graphics": {}
267360            },
267361            "considerations": {}
267362          }
267363        },
267364        {
267365          "type": "library",
267366          "bom-ref": "pkg:deb/debian/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=debian-11\u0026package-id=b91e181aea759ff5",
267367          "supplier": {},
267368          "publisher": "Boyuan Yang \u003cbyang@debian.org\u003e",
267369          "name": "mawk",
267370          "version": "1.3.4.20200120-2",
267371          "licenses": [
267372            {
267373              "license": {
267374                "id": "GPL-2.0-only"
267375              }
267376            }
267377          ],
267378          "cpe": "cpe:2.3:a:mawk:mawk:1.3.4.20200120-2:*:*:*:*:*:*:*",
267379          "purl": "pkg:deb/debian/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=debian-11",
267380          "swid": {
267381            "attachment": {}
267382          },
267383          "pedigree": {},
267384          "evidence": {},
267385          "signature": {
267386            "signature": {
267387              "publicKey": {}
267388            }
267389          },
267390          "modelCard": {
267391            "modelParameters": {
267392              "approach": {}
267393            },
267394            "quantitativeAnalysis": {
267395              "graphics": {}
267396            },
267397            "considerations": {}
267398          }
267399        },
267400        {
267401          "type": "library",
267402          "bom-ref": "pkg:deb/debian/media-types@4.0.0?arch=all\u0026distro=debian-11\u0026package-id=8ad043b7c85813ad",
267403          "supplier": {},
267404          "publisher": "Mime-Support Packagers \u003cteam+debian-mimesupport-packagers@tracker.debian.org\u003e",
267405          "name": "media-types",
267406          "version": "4.0.0",
267407          "licenses": [
267408            {
267409              "license": {
267410                "name": "ad-hoc"
267411              }
267412            }
267413          ],
267414          "cpe": "cpe:2.3:a:media-types:media-types:4.0.0:*:*:*:*:*:*:*",
267415          "purl": "pkg:deb/debian/media-types@4.0.0?arch=all\u0026distro=debian-11",
267416          "swid": {
267417            "attachment": {}
267418          },
267419          "pedigree": {},
267420          "evidence": {},
267421          "signature": {
267422            "signature": {
267423              "publicKey": {}
267424            }
267425          },
267426          "modelCard": {
267427            "modelParameters": {
267428              "approach": {}
267429            },
267430            "quantitativeAnalysis": {
267431              "graphics": {}
267432            },
267433            "considerations": {}
267434          }
267435        },
267436        {
267437          "type": "library",
267438          "bom-ref": "pkg:deb/debian/mount@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11\u0026package-id=c7ff86ae9a8937ca",
267439          "supplier": {},
267440          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
267441          "name": "mount",
267442          "version": "2.36.1-8+deb11u1",
267443          "licenses": [
267444            {
267445              "license": {
267446                "id": "BSD-2-Clause"
267447              }
267448            },
267449            {
267450              "license": {
267451                "id": "BSD-3-Clause"
267452              }
267453            },
267454            {
267455              "license": {
267456                "id": "BSD-4-Clause"
267457              }
267458            },
267459            {
267460              "license": {
267461                "id": "GPL-2.0-only"
267462              }
267463            },
267464            {
267465              "license": {
267466                "id": "GPL-2.0-or-later"
267467              }
267468            },
267469            {
267470              "license": {
267471                "id": "GPL-3.0-only"
267472              }
267473            },
267474            {
267475              "license": {
267476                "id": "GPL-3.0-or-later"
267477              }
267478            },
267479            {
267480              "license": {
267481                "name": "LGPL"
267482              }
267483            },
267484            {
267485              "license": {
267486                "id": "LGPL-2.0-only"
267487              }
267488            },
267489            {
267490              "license": {
267491                "id": "LGPL-2.0-or-later"
267492              }
267493            },
267494            {
267495              "license": {
267496                "id": "LGPL-2.1-only"
267497              }
267498            },
267499            {
267500              "license": {
267501                "id": "LGPL-2.1-or-later"
267502              }
267503            },
267504            {
267505              "license": {
267506                "id": "LGPL-3.0-only"
267507              }
267508            },
267509            {
267510              "license": {
267511                "id": "LGPL-3.0-or-later"
267512              }
267513            },
267514            {
267515              "license": {
267516                "id": "MIT"
267517              }
267518            },
267519            {
267520              "license": {
267521                "name": "public-domain"
267522              }
267523            }
267524          ],
267525          "cpe": "cpe:2.3:a:mount:mount:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
267526          "purl": "pkg:deb/debian/mount@2.36.1-8+deb11u1?arch=amd64\u0026upstream=util-linux\u0026distro=debian-11",
267527          "swid": {
267528            "attachment": {}
267529          },
267530          "pedigree": {},
267531          "evidence": {},
267532          "signature": {
267533            "signature": {
267534              "publicKey": {}
267535            }
267536          },
267537          "modelCard": {
267538            "modelParameters": {
267539              "approach": {}
267540            },
267541            "quantitativeAnalysis": {
267542              "graphics": {}
267543            },
267544            "considerations": {}
267545          }
267546        },
267547        {
267548          "type": "library",
267549          "bom-ref": "pkg:deb/debian/mtr@0.94-1+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=89b7573a9b715efa",
267550          "supplier": {},
267551          "publisher": "Robert Woodcock \u003crcw@debian.org\u003e",
267552          "name": "mtr",
267553          "version": "0.94-1+deb11u1",
267554          "licenses": [
267555            {
267556              "license": {
267557                "id": "GPL-2.0-only"
267558              }
267559            },
267560            {
267561              "license": {
267562                "id": "GPL-2.0-or-later"
267563              }
267564            }
267565          ],
267566          "cpe": "cpe:2.3:a:mtr:mtr:0.94-1\\+deb11u1:*:*:*:*:*:*:*",
267567          "purl": "pkg:deb/debian/mtr@0.94-1+deb11u1?arch=amd64\u0026distro=debian-11",
267568          "swid": {
267569            "attachment": {}
267570          },
267571          "pedigree": {},
267572          "evidence": {},
267573          "signature": {
267574            "signature": {
267575              "publicKey": {}
267576            }
267577          },
267578          "modelCard": {
267579            "modelParameters": {
267580              "approach": {}
267581            },
267582            "quantitativeAnalysis": {
267583              "graphics": {}
267584            },
267585            "considerations": {}
267586          }
267587        },
267588        {
267589          "type": "library",
267590          "bom-ref": "pkg:deb/debian/ncdu@1.15.1-1?arch=amd64\u0026distro=debian-11\u0026package-id=226ba65f099181fa",
267591          "supplier": {},
267592          "publisher": "Eugene V. Lyubimkin \u003cjackyf@debian.org\u003e",
267593          "name": "ncdu",
267594          "version": "1.15.1-1",
267595          "licenses": [
267596            {
267597              "license": {
267598                "name": "GPL"
267599              }
267600            },
267601            {
267602              "license": {
267603                "id": "MIT"
267604              }
267605            }
267606          ],
267607          "cpe": "cpe:2.3:a:ncdu:ncdu:1.15.1-1:*:*:*:*:*:*:*",
267608          "purl": "pkg:deb/debian/ncdu@1.15.1-1?arch=amd64\u0026distro=debian-11",
267609          "swid": {
267610            "attachment": {}
267611          },
267612          "pedigree": {},
267613          "evidence": {},
267614          "signature": {
267615            "signature": {
267616              "publicKey": {}
267617            }
267618          },
267619          "modelCard": {
267620            "modelParameters": {
267621              "approach": {}
267622            },
267623            "quantitativeAnalysis": {
267624              "graphics": {}
267625            },
267626            "considerations": {}
267627          }
267628        },
267629        {
267630          "type": "library",
267631          "bom-ref": "pkg:deb/debian/ncurses-base@6.2+20201114-2?arch=all\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=9c2239a948284096",
267632          "supplier": {},
267633          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
267634          "name": "ncurses-base",
267635          "version": "6.2+20201114-2",
267636          "licenses": [
267637            {
267638              "license": {
267639                "id": "BSD-3-Clause"
267640              }
267641            },
267642            {
267643              "license": {
267644                "name": "MIT/X11"
267645              }
267646            },
267647            {
267648              "license": {
267649                "id": "X11"
267650              }
267651            }
267652          ],
267653          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.2\\+20201114-2:*:*:*:*:*:*:*",
267654          "purl": "pkg:deb/debian/ncurses-base@6.2+20201114-2?arch=all\u0026upstream=ncurses\u0026distro=debian-11",
267655          "swid": {
267656            "attachment": {}
267657          },
267658          "pedigree": {},
267659          "evidence": {},
267660          "signature": {
267661            "signature": {
267662              "publicKey": {}
267663            }
267664          },
267665          "modelCard": {
267666            "modelParameters": {
267667              "approach": {}
267668            },
267669            "quantitativeAnalysis": {
267670              "graphics": {}
267671            },
267672            "considerations": {}
267673          }
267674        },
267675        {
267676          "type": "library",
267677          "bom-ref": "pkg:deb/debian/ncurses-bin@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11\u0026package-id=d98c3c34aac1c97c",
267678          "supplier": {},
267679          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
267680          "name": "ncurses-bin",
267681          "version": "6.2+20201114-2",
267682          "licenses": [
267683            {
267684              "license": {
267685                "id": "BSD-3-Clause"
267686              }
267687            },
267688            {
267689              "license": {
267690                "name": "MIT/X11"
267691              }
267692            },
267693            {
267694              "license": {
267695                "id": "X11"
267696              }
267697            }
267698          ],
267699          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.2\\+20201114-2:*:*:*:*:*:*:*",
267700          "purl": "pkg:deb/debian/ncurses-bin@6.2+20201114-2?arch=amd64\u0026upstream=ncurses\u0026distro=debian-11",
267701          "swid": {
267702            "attachment": {}
267703          },
267704          "pedigree": {},
267705          "evidence": {},
267706          "signature": {
267707            "signature": {
267708              "publicKey": {}
267709            }
267710          },
267711          "modelCard": {
267712            "modelParameters": {
267713              "approach": {}
267714            },
267715            "quantitativeAnalysis": {
267716              "graphics": {}
267717            },
267718            "considerations": {}
267719          }
267720        },
267721        {
267722          "type": "library",
267723          "bom-ref": "pkg:deb/debian/net-tools@1.60+git20181103.0eebece-1?arch=amd64\u0026distro=debian-11\u0026package-id=81c1633d72b6611d",
267724          "supplier": {},
267725          "publisher": "net-tools Team \u003cteam+net-tools@tracker.debian.org\u003e",
267726          "name": "net-tools",
267727          "version": "1.60+git20181103.0eebece-1",
267728          "licenses": [
267729            {
267730              "license": {
267731                "id": "GPL-2.0-only"
267732              }
267733            },
267734            {
267735              "license": {
267736                "id": "GPL-2.0-or-later"
267737              }
267738            }
267739          ],
267740          "cpe": "cpe:2.3:a:net-tools:net-tools:1.60\\+git20181103.0eebece-1:*:*:*:*:*:*:*",
267741          "purl": "pkg:deb/debian/net-tools@1.60+git20181103.0eebece-1?arch=amd64\u0026distro=debian-11",
267742          "swid": {
267743            "attachment": {}
267744          },
267745          "pedigree": {},
267746          "evidence": {},
267747          "signature": {
267748            "signature": {
267749              "publicKey": {}
267750            }
267751          },
267752          "modelCard": {
267753            "modelParameters": {
267754              "approach": {}
267755            },
267756            "quantitativeAnalysis": {
267757              "graphics": {}
267758            },
267759            "considerations": {}
267760          }
267761        },
267762        {
267763          "type": "library",
267764          "bom-ref": "pkg:deb/debian/netcat-openbsd@1.217-3?arch=amd64\u0026distro=debian-11\u0026package-id=9432e634f83ba46",
267765          "supplier": {},
267766          "publisher": "Aron Xu \u003caron@debian.org\u003e",
267767          "name": "netcat-openbsd",
267768          "version": "1.217-3",
267769          "licenses": [
267770            {
267771              "license": {
267772                "id": "BSD-2-Clause"
267773              }
267774            },
267775            {
267776              "license": {
267777                "id": "BSD-3-Clause"
267778              }
267779            }
267780          ],
267781          "cpe": "cpe:2.3:a:netcat-openbsd:netcat-openbsd:1.217-3:*:*:*:*:*:*:*",
267782          "purl": "pkg:deb/debian/netcat-openbsd@1.217-3?arch=amd64\u0026distro=debian-11",
267783          "swid": {
267784            "attachment": {}
267785          },
267786          "pedigree": {},
267787          "evidence": {},
267788          "signature": {
267789            "signature": {
267790              "publicKey": {}
267791            }
267792          },
267793          "modelCard": {
267794            "modelParameters": {
267795              "approach": {}
267796            },
267797            "quantitativeAnalysis": {
267798              "graphics": {}
267799            },
267800            "considerations": {}
267801          }
267802        },
267803        {
267804          "type": "library",
267805          "bom-ref": "pkg:deb/debian/ngrep@1.47+ds1-2?arch=amd64\u0026distro=debian-11\u0026package-id=8961eb2703fc2bbc",
267806          "supplier": {},
267807          "publisher": "Romain Francoise \u003crfrancoise@debian.org\u003e",
267808          "name": "ngrep",
267809          "version": "1.47+ds1-2",
267810          "cpe": "cpe:2.3:a:ngrep:ngrep:1.47\\+ds1-2:*:*:*:*:*:*:*",
267811          "purl": "pkg:deb/debian/ngrep@1.47+ds1-2?arch=amd64\u0026distro=debian-11",
267812          "swid": {
267813            "attachment": {}
267814          },
267815          "pedigree": {},
267816          "evidence": {},
267817          "signature": {
267818            "signature": {
267819              "publicKey": {}
267820            }
267821          },
267822          "modelCard": {
267823            "modelParameters": {
267824              "approach": {}
267825            },
267826            "quantitativeAnalysis": {
267827              "graphics": {}
267828            },
267829            "considerations": {}
267830          }
267831        },
267832        {
267833          "type": "library",
267834          "bom-ref": "pkg:deb/debian/nmap@7.91+dfsg1+really7.80+dfsg1-2?arch=amd64\u0026distro=debian-11\u0026package-id=344051c446c019fc",
267835          "supplier": {},
267836          "publisher": "Debian Security Tools \u003cteam+pkg-security@tracker.debian.org\u003e",
267837          "name": "nmap",
267838          "version": "7.91+dfsg1+really7.80+dfsg1-2",
267839          "licenses": [
267840            {
267841              "license": {
267842                "name": "BSD-3-clause-author1"
267843              }
267844            },
267845            {
267846              "license": {
267847                "name": "BSD-3-clause-author2"
267848              }
267849            },
267850            {
267851              "license": {
267852                "name": "BSD-3-clause-authors-copyright-holders"
267853              }
267854            },
267855            {
267856              "license": {
267857                "name": "BSD-3-clause-copyright-holders-contributors"
267858              }
267859            },
267860            {
267861              "license": {
267862                "name": "BSD-3-clause-institute"
267863              }
267864            },
267865            {
267866              "license": {
267867                "id": "BSD-4-Clause"
267868              }
267869            },
267870            {
267871              "license": {
267872                "name": "BSD-like-SVN"
267873              }
267874            },
267875            {
267876              "license": {
267877                "name": "Expat"
267878              }
267879            },
267880            {
267881              "license": {
267882                "id": "GPL-2.0-only"
267883              }
267884            },
267885            {
267886              "license": {
267887                "id": "GPL-2.0-or-later"
267888              }
267889            },
267890            {
267891              "license": {
267892                "id": "ISC"
267893              }
267894            },
267895            {
267896              "license": {
267897                "name": "nmap-GPL-2"
267898              }
267899            },
267900            {
267901              "license": {
267902                "name": "preserve-copyright"
267903              }
267904            },
267905            {
267906              "license": {
267907                "name": "retain-copyright-cisco"
267908              }
267909            },
267910            {
267911              "license": {
267912                "name": "unlimited-retain-copyright"
267913              }
267914            }
267915          ],
267916          "cpe": "cpe:2.3:a:nmap:nmap:7.91\\+dfsg1\\+really7.80\\+dfsg1-2:*:*:*:*:*:*:*",
267917          "purl": "pkg:deb/debian/nmap@7.91+dfsg1+really7.80+dfsg1-2?arch=amd64\u0026distro=debian-11",
267918          "swid": {
267919            "attachment": {}
267920          },
267921          "pedigree": {},
267922          "evidence": {},
267923          "signature": {
267924            "signature": {
267925              "publicKey": {}
267926            }
267927          },
267928          "modelCard": {
267929            "modelParameters": {
267930              "approach": {}
267931            },
267932            "quantitativeAnalysis": {
267933              "graphics": {}
267934            },
267935            "considerations": {}
267936          }
267937        },
267938        {
267939          "type": "library",
267940          "bom-ref": "pkg:deb/debian/nmap-common@7.91+dfsg1+really7.80+dfsg1-2?arch=all\u0026upstream=nmap\u0026distro=debian-11\u0026package-id=5802d12ee3c0ba5e",
267941          "supplier": {},
267942          "publisher": "Debian Security Tools \u003cteam+pkg-security@tracker.debian.org\u003e",
267943          "name": "nmap-common",
267944          "version": "7.91+dfsg1+really7.80+dfsg1-2",
267945          "licenses": [
267946            {
267947              "license": {
267948                "name": "BSD-3-clause-author1"
267949              }
267950            },
267951            {
267952              "license": {
267953                "name": "BSD-3-clause-author2"
267954              }
267955            },
267956            {
267957              "license": {
267958                "name": "BSD-3-clause-authors-copyright-holders"
267959              }
267960            },
267961            {
267962              "license": {
267963                "name": "BSD-3-clause-copyright-holders-contributors"
267964              }
267965            },
267966            {
267967              "license": {
267968                "name": "BSD-3-clause-institute"
267969              }
267970            },
267971            {
267972              "license": {
267973                "id": "BSD-4-Clause"
267974              }
267975            },
267976            {
267977              "license": {
267978                "name": "BSD-like-SVN"
267979              }
267980            },
267981            {
267982              "license": {
267983                "name": "Expat"
267984              }
267985            },
267986            {
267987              "license": {
267988                "id": "GPL-2.0-only"
267989              }
267990            },
267991            {
267992              "license": {
267993                "id": "GPL-2.0-or-later"
267994              }
267995            },
267996            {
267997              "license": {
267998                "id": "ISC"
267999              }
268000            },
268001            {
268002              "license": {
268003                "name": "nmap-GPL-2"
268004              }
268005            },
268006            {
268007              "license": {
268008                "name": "preserve-copyright"
268009              }
268010            },
268011            {
268012              "license": {
268013                "name": "retain-copyright-cisco"
268014              }
268015            },
268016            {
268017              "license": {
268018                "name": "unlimited-retain-copyright"
268019              }
268020            }
268021          ],
268022          "cpe": "cpe:2.3:a:nmap-common:nmap-common:7.91\\+dfsg1\\+really7.80\\+dfsg1-2:*:*:*:*:*:*:*",
268023          "purl": "pkg:deb/debian/nmap-common@7.91+dfsg1+really7.80+dfsg1-2?arch=all\u0026upstream=nmap\u0026distro=debian-11",
268024          "swid": {
268025            "attachment": {}
268026          },
268027          "pedigree": {},
268028          "evidence": {},
268029          "signature": {
268030            "signature": {
268031              "publicKey": {}
268032            }
268033          },
268034          "modelCard": {
268035            "modelParameters": {
268036              "approach": {}
268037            },
268038            "quantitativeAnalysis": {
268039              "graphics": {}
268040            },
268041            "considerations": {}
268042          }
268043        },
268044        {
268045          "type": "library",
268046          "bom-ref": "pkg:deb/debian/openssl@1.1.1n-0+deb11u3?arch=amd64\u0026distro=debian-11\u0026package-id=265e51164bd97a68",
268047          "supplier": {},
268048          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
268049          "name": "openssl",
268050          "version": "1.1.1n-0+deb11u3",
268051          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1n-0\\+deb11u3:*:*:*:*:*:*:*",
268052          "purl": "pkg:deb/debian/openssl@1.1.1n-0+deb11u3?arch=amd64\u0026distro=debian-11",
268053          "swid": {
268054            "attachment": {}
268055          },
268056          "pedigree": {},
268057          "evidence": {},
268058          "signature": {
268059            "signature": {
268060              "publicKey": {}
268061            }
268062          },
268063          "modelCard": {
268064            "modelParameters": {
268065              "approach": {}
268066            },
268067            "quantitativeAnalysis": {
268068              "graphics": {}
268069            },
268070            "considerations": {}
268071          }
268072        },
268073        {
268074          "type": "library",
268075          "bom-ref": "pkg:deb/debian/passwd@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11\u0026package-id=fdca5992b8d73b50",
268076          "supplier": {},
268077          "publisher": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e",
268078          "name": "passwd",
268079          "version": "1:4.8.1-1",
268080          "licenses": [
268081            {
268082              "license": {
268083                "id": "GPL-2.0-only"
268084              }
268085            }
268086          ],
268087          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1:*:*:*:*:*:*:*",
268088          "purl": "pkg:deb/debian/passwd@1:4.8.1-1?arch=amd64\u0026upstream=shadow\u0026distro=debian-11",
268089          "swid": {
268090            "attachment": {}
268091          },
268092          "pedigree": {},
268093          "evidence": {},
268094          "signature": {
268095            "signature": {
268096              "publicKey": {}
268097            }
268098          },
268099          "modelCard": {
268100            "modelParameters": {
268101              "approach": {}
268102            },
268103            "quantitativeAnalysis": {
268104              "graphics": {}
268105            },
268106            "considerations": {}
268107          }
268108        },
268109        {
268110          "type": "library",
268111          "bom-ref": "pkg:deb/debian/patch@2.7.6-7?arch=amd64\u0026distro=debian-11\u0026package-id=d244a2dc66a77548",
268112          "supplier": {},
268113          "publisher": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e",
268114          "name": "patch",
268115          "version": "2.7.6-7",
268116          "licenses": [
268117            {
268118              "license": {
268119                "name": "GPL"
268120              }
268121            }
268122          ],
268123          "cpe": "cpe:2.3:a:patch:patch:2.7.6-7:*:*:*:*:*:*:*",
268124          "purl": "pkg:deb/debian/patch@2.7.6-7?arch=amd64\u0026distro=debian-11",
268125          "swid": {
268126            "attachment": {}
268127          },
268128          "pedigree": {},
268129          "evidence": {},
268130          "signature": {
268131            "signature": {
268132              "publicKey": {}
268133            }
268134          },
268135          "modelCard": {
268136            "modelParameters": {
268137              "approach": {}
268138            },
268139            "quantitativeAnalysis": {
268140              "graphics": {}
268141            },
268142            "considerations": {}
268143          }
268144        },
268145        {
268146          "type": "library",
268147          "bom-ref": "pkg:deb/debian/pci.ids@0.0~2021.02.08-1?arch=all\u0026distro=debian-11\u0026package-id=ffd90b5684d6b1f",
268148          "supplier": {},
268149          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
268150          "name": "pci.ids",
268151          "version": "0.0~2021.02.08-1",
268152          "licenses": [
268153            {
268154              "license": {
268155                "id": "BSD-3-Clause"
268156              }
268157            },
268158            {
268159              "license": {
268160                "id": "GPL-2.0-only"
268161              }
268162            },
268163            {
268164              "license": {
268165                "id": "GPL-2.0-or-later"
268166              }
268167            }
268168          ],
268169          "cpe": "cpe:2.3:a:pci.ids:pci.ids:0.0\\~2021.02.08-1:*:*:*:*:*:*:*",
268170          "purl": "pkg:deb/debian/pci.ids@0.0~2021.02.08-1?arch=all\u0026distro=debian-11",
268171          "swid": {
268172            "attachment": {}
268173          },
268174          "pedigree": {},
268175          "evidence": {},
268176          "signature": {
268177            "signature": {
268178              "publicKey": {}
268179            }
268180          },
268181          "modelCard": {
268182            "modelParameters": {
268183              "approach": {}
268184            },
268185            "quantitativeAnalysis": {
268186              "graphics": {}
268187            },
268188            "considerations": {}
268189          }
268190        },
268191        {
268192          "type": "library",
268193          "bom-ref": "pkg:deb/debian/pciutils@1:3.7.0-5?arch=amd64\u0026distro=debian-11\u0026package-id=7f10ca5515fc096a",
268194          "supplier": {},
268195          "publisher": "Guillem Jover \u003cguillem@debian.org\u003e",
268196          "name": "pciutils",
268197          "version": "1:3.7.0-5",
268198          "licenses": [
268199            {
268200              "license": {
268201                "id": "GPL-2.0-only"
268202              }
268203            },
268204            {
268205              "license": {
268206                "id": "GPL-2.0-or-later"
268207              }
268208            }
268209          ],
268210          "cpe": "cpe:2.3:a:pciutils:pciutils:1\\:3.7.0-5:*:*:*:*:*:*:*",
268211          "purl": "pkg:deb/debian/pciutils@1:3.7.0-5?arch=amd64\u0026distro=debian-11",
268212          "swid": {
268213            "attachment": {}
268214          },
268215          "pedigree": {},
268216          "evidence": {},
268217          "signature": {
268218            "signature": {
268219              "publicKey": {}
268220            }
268221          },
268222          "modelCard": {
268223            "modelParameters": {
268224              "approach": {}
268225            },
268226            "quantitativeAnalysis": {
268227              "graphics": {}
268228            },
268229            "considerations": {}
268230          }
268231        },
268232        {
268233          "type": "library",
268234          "bom-ref": "pkg:deb/debian/perl@5.32.1-4+deb11u2?arch=amd64\u0026distro=debian-11\u0026package-id=4e5da8d7b4296672",
268235          "supplier": {},
268236          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
268237          "name": "perl",
268238          "version": "5.32.1-4+deb11u2",
268239          "licenses": [
268240            {
268241              "license": {
268242                "name": "Artistic"
268243              }
268244            },
268245            {
268246              "license": {
268247                "id": "Artistic-2.0"
268248              }
268249            },
268250            {
268251              "license": {
268252                "name": "Artistic-dist"
268253              }
268254            },
268255            {
268256              "license": {
268257                "id": "BSD-3-Clause"
268258              }
268259            },
268260            {
268261              "license": {
268262                "name": "BSD-3-clause-GENERIC"
268263              }
268264            },
268265            {
268266              "license": {
268267                "name": "BSD-3-clause-with-weird-numbering"
268268              }
268269            },
268270            {
268271              "license": {
268272                "name": "BSD-4-clause-POWERDOG"
268273              }
268274            },
268275            {
268276              "license": {
268277                "name": "BZIP"
268278              }
268279            },
268280            {
268281              "license": {
268282                "name": "DONT-CHANGE-THE-GPL"
268283              }
268284            },
268285            {
268286              "license": {
268287                "name": "Expat"
268288              }
268289            },
268290            {
268291              "license": {
268292                "id": "GPL-1.0-only"
268293              }
268294            },
268295            {
268296              "license": {
268297                "id": "GPL-1.0-or-later"
268298              }
268299            },
268300            {
268301              "license": {
268302                "id": "GPL-2.0-only"
268303              }
268304            },
268305            {
268306              "license": {
268307                "id": "GPL-2.0-or-later"
268308              }
268309            },
268310            {
268311              "license": {
268312                "name": "GPL-3+-WITH-BISON-EXCEPTION"
268313              }
268314            },
268315            {
268316              "license": {
268317                "name": "HSIEH-BSD"
268318              }
268319            },
268320            {
268321              "license": {
268322                "name": "HSIEH-DERIVATIVE"
268323              }
268324            },
268325            {
268326              "license": {
268327                "id": "LGPL-2.1-only"
268328              }
268329            },
268330            {
268331              "license": {
268332                "name": "REGCOMP"
268333              }
268334            },
268335            {
268336              "license": {
268337                "name": "REGCOMP,"
268338              }
268339            },
268340            {
268341              "license": {
268342                "name": "RRA-KEEP-THIS-NOTICE"
268343              }
268344            },
268345            {
268346              "license": {
268347                "name": "SDBM-PUBLIC-DOMAIN"
268348              }
268349            },
268350            {
268351              "license": {
268352                "name": "TEXT-TABS"
268353              }
268354            },
268355            {
268356              "license": {
268357                "name": "Unicode"
268358              }
268359            },
268360            {
268361              "license": {
268362                "id": "Zlib"
268363              }
268364            }
268365          ],
268366          "cpe": "cpe:2.3:a:perl:perl:5.32.1-4\\+deb11u2:*:*:*:*:*:*:*",
268367          "purl": "pkg:deb/debian/perl@5.32.1-4+deb11u2?arch=amd64\u0026distro=debian-11",
268368          "swid": {
268369            "attachment": {}
268370          },
268371          "pedigree": {},
268372          "evidence": {},
268373          "signature": {
268374            "signature": {
268375              "publicKey": {}
268376            }
268377          },
268378          "modelCard": {
268379            "modelParameters": {
268380              "approach": {}
268381            },
268382            "quantitativeAnalysis": {
268383              "graphics": {}
268384            },
268385            "considerations": {}
268386          }
268387        },
268388        {
268389          "type": "library",
268390          "bom-ref": "pkg:deb/debian/perl-base@5.32.1-4+deb11u2?arch=amd64\u0026upstream=perl\u0026distro=debian-11\u0026package-id=96ea9246284c94e6",
268391          "supplier": {},
268392          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
268393          "name": "perl-base",
268394          "version": "5.32.1-4+deb11u2",
268395          "licenses": [
268396            {
268397              "license": {
268398                "name": "Artistic"
268399              }
268400            },
268401            {
268402              "license": {
268403                "id": "Artistic-2.0"
268404              }
268405            },
268406            {
268407              "license": {
268408                "name": "Artistic-dist"
268409              }
268410            },
268411            {
268412              "license": {
268413                "id": "BSD-3-Clause"
268414              }
268415            },
268416            {
268417              "license": {
268418                "name": "BSD-3-clause-GENERIC"
268419              }
268420            },
268421            {
268422              "license": {
268423                "name": "BSD-3-clause-with-weird-numbering"
268424              }
268425            },
268426            {
268427              "license": {
268428                "name": "BSD-4-clause-POWERDOG"
268429              }
268430            },
268431            {
268432              "license": {
268433                "name": "BZIP"
268434              }
268435            },
268436            {
268437              "license": {
268438                "name": "DONT-CHANGE-THE-GPL"
268439              }
268440            },
268441            {
268442              "license": {
268443                "name": "Expat"
268444              }
268445            },
268446            {
268447              "license": {
268448                "id": "GPL-1.0-only"
268449              }
268450            },
268451            {
268452              "license": {
268453                "id": "GPL-1.0-or-later"
268454              }
268455            },
268456            {
268457              "license": {
268458                "id": "GPL-2.0-only"
268459              }
268460            },
268461            {
268462              "license": {
268463                "id": "GPL-2.0-or-later"
268464              }
268465            },
268466            {
268467              "license": {
268468                "name": "GPL-3+-WITH-BISON-EXCEPTION"
268469              }
268470            },
268471            {
268472              "license": {
268473                "name": "HSIEH-BSD"
268474              }
268475            },
268476            {
268477              "license": {
268478                "name": "HSIEH-DERIVATIVE"
268479              }
268480            },
268481            {
268482              "license": {
268483                "id": "LGPL-2.1-only"
268484              }
268485            },
268486            {
268487              "license": {
268488                "name": "REGCOMP"
268489              }
268490            },
268491            {
268492              "license": {
268493                "name": "REGCOMP,"
268494              }
268495            },
268496            {
268497              "license": {
268498                "name": "RRA-KEEP-THIS-NOTICE"
268499              }
268500            },
268501            {
268502              "license": {
268503                "name": "SDBM-PUBLIC-DOMAIN"
268504              }
268505            },
268506            {
268507              "license": {
268508                "name": "TEXT-TABS"
268509              }
268510            },
268511            {
268512              "license": {
268513                "name": "Unicode"
268514              }
268515            },
268516            {
268517              "license": {
268518                "id": "Zlib"
268519              }
268520            }
268521          ],
268522          "cpe": "cpe:2.3:a:perl-base:perl-base:5.32.1-4\\+deb11u2:*:*:*:*:*:*:*",
268523          "purl": "pkg:deb/debian/perl-base@5.32.1-4+deb11u2?arch=amd64\u0026upstream=perl\u0026distro=debian-11",
268524          "swid": {
268525            "attachment": {}
268526          },
268527          "pedigree": {},
268528          "evidence": {},
268529          "signature": {
268530            "signature": {
268531              "publicKey": {}
268532            }
268533          },
268534          "modelCard": {
268535            "modelParameters": {
268536              "approach": {}
268537            },
268538            "quantitativeAnalysis": {
268539              "graphics": {}
268540            },
268541            "considerations": {}
268542          }
268543        },
268544        {
268545          "type": "library",
268546          "bom-ref": "pkg:deb/debian/perl-modules-5.32@5.32.1-4+deb11u2?arch=all\u0026upstream=perl\u0026distro=debian-11\u0026package-id=e2a13f824792ebe3",
268547          "supplier": {},
268548          "publisher": "Niko Tyni \u003cntyni@debian.org\u003e",
268549          "name": "perl-modules-5.32",
268550          "version": "5.32.1-4+deb11u2",
268551          "licenses": [
268552            {
268553              "license": {
268554                "name": "Artistic"
268555              }
268556            },
268557            {
268558              "license": {
268559                "id": "Artistic-2.0"
268560              }
268561            },
268562            {
268563              "license": {
268564                "name": "Artistic-dist"
268565              }
268566            },
268567            {
268568              "license": {
268569                "id": "BSD-3-Clause"
268570              }
268571            },
268572            {
268573              "license": {
268574                "name": "BSD-3-clause-GENERIC"
268575              }
268576            },
268577            {
268578              "license": {
268579                "name": "BSD-3-clause-with-weird-numbering"
268580              }
268581            },
268582            {
268583              "license": {
268584                "name": "BSD-4-clause-POWERDOG"
268585              }
268586            },
268587            {
268588              "license": {
268589                "name": "BZIP"
268590              }
268591            },
268592            {
268593              "license": {
268594                "name": "DONT-CHANGE-THE-GPL"
268595              }
268596            },
268597            {
268598              "license": {
268599                "name": "Expat"
268600              }
268601            },
268602            {
268603              "license": {
268604                "id": "GPL-1.0-only"
268605              }
268606            },
268607            {
268608              "license": {
268609                "id": "GPL-1.0-or-later"
268610              }
268611            },
268612            {
268613              "license": {
268614                "id": "GPL-2.0-only"
268615              }
268616            },
268617            {
268618              "license": {
268619                "id": "GPL-2.0-or-later"
268620              }
268621            },
268622            {
268623              "license": {
268624                "name": "GPL-3+-WITH-BISON-EXCEPTION"
268625              }
268626            },
268627            {
268628              "license": {
268629                "name": "HSIEH-BSD"
268630              }
268631            },
268632            {
268633              "license": {
268634                "name": "HSIEH-DERIVATIVE"
268635              }
268636            },
268637            {
268638              "license": {
268639                "id": "LGPL-2.1-only"
268640              }
268641            },
268642            {
268643              "license": {
268644                "name": "REGCOMP"
268645              }
268646            },
268647            {
268648              "license": {
268649                "name": "REGCOMP,"
268650              }
268651            },
268652            {
268653              "license": {
268654                "name": "RRA-KEEP-THIS-NOTICE"
268655              }
268656            },
268657            {
268658              "license": {
268659                "name": "SDBM-PUBLIC-DOMAIN"
268660              }
268661            },
268662            {
268663              "license": {
268664                "name": "TEXT-TABS"
268665              }
268666            },
268667            {
268668              "license": {
268669                "name": "Unicode"
268670              }
268671            },
268672            {
268673              "license": {
268674                "id": "Zlib"
268675              }
268676            }
268677          ],
268678          "cpe": "cpe:2.3:a:perl-modules-5.32:perl-modules-5.32:5.32.1-4\\+deb11u2:*:*:*:*:*:*:*",
268679          "purl": "pkg:deb/debian/perl-modules-5.32@5.32.1-4+deb11u2?arch=all\u0026upstream=perl\u0026distro=debian-11",
268680          "swid": {
268681            "attachment": {}
268682          },
268683          "pedigree": {},
268684          "evidence": {},
268685          "signature": {
268686            "signature": {
268687              "publicKey": {}
268688            }
268689          },
268690          "modelCard": {
268691            "modelParameters": {
268692              "approach": {}
268693            },
268694            "quantitativeAnalysis": {
268695              "graphics": {}
268696            },
268697            "considerations": {}
268698          }
268699        },
268700        {
268701          "type": "library",
268702          "bom-ref": "pkg:deb/debian/pkg-config@0.29.2-1?arch=amd64\u0026distro=debian-11\u0026package-id=1bfe7c497852bb22",
268703          "supplier": {},
268704          "publisher": "Tollef Fog Heen \u003ctfheen@debian.org\u003e",
268705          "name": "pkg-config",
268706          "version": "0.29.2-1",
268707          "licenses": [
268708            {
268709              "license": {
268710                "name": "GPL"
268711              }
268712            }
268713          ],
268714          "cpe": "cpe:2.3:a:pkg-config:pkg-config:0.29.2-1:*:*:*:*:*:*:*",
268715          "purl": "pkg:deb/debian/pkg-config@0.29.2-1?arch=amd64\u0026distro=debian-11",
268716          "swid": {
268717            "attachment": {}
268718          },
268719          "pedigree": {},
268720          "evidence": {},
268721          "signature": {
268722            "signature": {
268723              "publicKey": {}
268724            }
268725          },
268726          "modelCard": {
268727            "modelParameters": {
268728              "approach": {}
268729            },
268730            "quantitativeAnalysis": {
268731              "graphics": {}
268732            },
268733            "considerations": {}
268734          }
268735        },
268736        {
268737          "type": "library",
268738          "bom-ref": "pkg:deb/debian/psmisc@23.4-2?arch=amd64\u0026distro=debian-11\u0026package-id=e6500613920b6f91",
268739          "supplier": {},
268740          "publisher": "Craig Small \u003ccsmall@debian.org\u003e",
268741          "name": "psmisc",
268742          "version": "23.4-2",
268743          "licenses": [
268744            {
268745              "license": {
268746                "id": "GPL-2.0-only"
268747              }
268748            },
268749            {
268750              "license": {
268751                "id": "GPL-2.0-or-later"
268752              }
268753            }
268754          ],
268755          "cpe": "cpe:2.3:a:psmisc:psmisc:23.4-2:*:*:*:*:*:*:*",
268756          "purl": "pkg:deb/debian/psmisc@23.4-2?arch=amd64\u0026distro=debian-11",
268757          "swid": {
268758            "attachment": {}
268759          },
268760          "pedigree": {},
268761          "evidence": {},
268762          "signature": {
268763            "signature": {
268764              "publicKey": {}
268765            }
268766          },
268767          "modelCard": {
268768            "modelParameters": {
268769              "approach": {}
268770            },
268771            "quantitativeAnalysis": {
268772              "graphics": {}
268773            },
268774            "considerations": {}
268775          }
268776        },
268777        {
268778          "type": "library",
268779          "bom-ref": "pkg:deb/debian/pv@1.6.6-1+b1?arch=amd64\u0026upstream=pv%401.6.6-1\u0026distro=debian-11\u0026package-id=52298b1053c4f509",
268780          "supplier": {},
268781          "publisher": "Antoine Beaupré \u003canarcat@debian.org\u003e",
268782          "name": "pv",
268783          "version": "1.6.6-1+b1",
268784          "licenses": [
268785            {
268786              "license": {
268787                "name": "Artistic"
268788              }
268789            },
268790            {
268791              "license": {
268792                "id": "GPL-2.0-only"
268793              }
268794            },
268795            {
268796              "license": {
268797                "id": "GPL-2.0-or-later"
268798              }
268799            }
268800          ],
268801          "cpe": "cpe:2.3:a:pv:pv:1.6.6-1\\+b1:*:*:*:*:*:*:*",
268802          "purl": "pkg:deb/debian/pv@1.6.6-1+b1?arch=amd64\u0026upstream=pv%401.6.6-1\u0026distro=debian-11",
268803          "swid": {
268804            "attachment": {}
268805          },
268806          "pedigree": {},
268807          "evidence": {},
268808          "signature": {
268809            "signature": {
268810              "publicKey": {}
268811            }
268812          },
268813          "modelCard": {
268814            "modelParameters": {
268815              "approach": {}
268816            },
268817            "quantitativeAnalysis": {
268818              "graphics": {}
268819            },
268820            "considerations": {}
268821          }
268822        },
268823        {
268824          "type": "application",
268825          "bom-ref": "pkg:generic/python@3.9.2?package-id=25c86cd31edb4ea2",
268826          "supplier": {},
268827          "name": "python",
268828          "version": "3.9.2",
268829          "cpe": "cpe:2.3:a:python_software_foundation:python:3.9.2:*:*:*:*:*:*:*",
268830          "purl": "pkg:generic/python@3.9.2",
268831          "swid": {
268832            "attachment": {}
268833          },
268834          "pedigree": {},
268835          "evidence": {},
268836          "signature": {
268837            "signature": {
268838              "publicKey": {}
268839            }
268840          },
268841          "modelCard": {
268842            "modelParameters": {
268843              "approach": {}
268844            },
268845            "quantitativeAnalysis": {
268846              "graphics": {}
268847            },
268848            "considerations": {}
268849          }
268850        },
268851        {
268852          "type": "library",
268853          "bom-ref": "pkg:deb/debian/python3@3.9.2-3?arch=amd64\u0026upstream=python3-defaults\u0026distro=debian-11\u0026package-id=bcf7a2732ad48999",
268854          "supplier": {},
268855          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
268856          "name": "python3",
268857          "version": "3.9.2-3",
268858          "cpe": "cpe:2.3:a:python3:python3:3.9.2-3:*:*:*:*:*:*:*",
268859          "purl": "pkg:deb/debian/python3@3.9.2-3?arch=amd64\u0026upstream=python3-defaults\u0026distro=debian-11",
268860          "swid": {
268861            "attachment": {}
268862          },
268863          "pedigree": {},
268864          "evidence": {},
268865          "signature": {
268866            "signature": {
268867              "publicKey": {}
268868            }
268869          },
268870          "modelCard": {
268871            "modelParameters": {
268872              "approach": {}
268873            },
268874            "quantitativeAnalysis": {
268875              "graphics": {}
268876            },
268877            "considerations": {}
268878          }
268879        },
268880        {
268881          "type": "library",
268882          "bom-ref": "pkg:deb/debian/python3-minimal@3.9.2-3?arch=amd64\u0026upstream=python3-defaults\u0026distro=debian-11\u0026package-id=68272ff45d5cac4b",
268883          "supplier": {},
268884          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
268885          "name": "python3-minimal",
268886          "version": "3.9.2-3",
268887          "cpe": "cpe:2.3:a:python3-minimal:python3-minimal:3.9.2-3:*:*:*:*:*:*:*",
268888          "purl": "pkg:deb/debian/python3-minimal@3.9.2-3?arch=amd64\u0026upstream=python3-defaults\u0026distro=debian-11",
268889          "swid": {
268890            "attachment": {}
268891          },
268892          "pedigree": {},
268893          "evidence": {},
268894          "signature": {
268895            "signature": {
268896              "publicKey": {}
268897            }
268898          },
268899          "modelCard": {
268900            "modelParameters": {
268901              "approach": {}
268902            },
268903            "quantitativeAnalysis": {
268904              "graphics": {}
268905            },
268906            "considerations": {}
268907          }
268908        },
268909        {
268910          "type": "library",
268911          "bom-ref": "pkg:deb/debian/python3.9@3.9.2-1?arch=amd64\u0026distro=debian-11\u0026package-id=2d05b0fb271e9f7f",
268912          "supplier": {},
268913          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
268914          "name": "python3.9",
268915          "version": "3.9.2-1",
268916          "licenses": [
268917            {
268918              "license": {
268919                "name": "By"
268920              }
268921            },
268922            {
268923              "license": {
268924                "id": "GPL-2.0-only"
268925              }
268926            },
268927            {
268928              "license": {
268929                "name": "Permission"
268930              }
268931            },
268932            {
268933              "license": {
268934                "name": "Redistribution"
268935              }
268936            },
268937            {
268938              "license": {
268939                "name": "This"
268940              }
268941            }
268942          ],
268943          "cpe": "cpe:2.3:a:python3.9:python3.9:3.9.2-1:*:*:*:*:*:*:*",
268944          "purl": "pkg:deb/debian/python3.9@3.9.2-1?arch=amd64\u0026distro=debian-11",
268945          "swid": {
268946            "attachment": {}
268947          },
268948          "pedigree": {},
268949          "evidence": {},
268950          "signature": {
268951            "signature": {
268952              "publicKey": {}
268953            }
268954          },
268955          "modelCard": {
268956            "modelParameters": {
268957              "approach": {}
268958            },
268959            "quantitativeAnalysis": {
268960              "graphics": {}
268961            },
268962            "considerations": {}
268963          }
268964        },
268965        {
268966          "type": "library",
268967          "bom-ref": "pkg:deb/debian/python3.9-minimal@3.9.2-1?arch=amd64\u0026upstream=python3.9\u0026distro=debian-11\u0026package-id=6068520cd08c8f05",
268968          "supplier": {},
268969          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
268970          "name": "python3.9-minimal",
268971          "version": "3.9.2-1",
268972          "licenses": [
268973            {
268974              "license": {
268975                "name": "By"
268976              }
268977            },
268978            {
268979              "license": {
268980                "id": "GPL-2.0-only"
268981              }
268982            },
268983            {
268984              "license": {
268985                "name": "Permission"
268986              }
268987            },
268988            {
268989              "license": {
268990                "name": "Redistribution"
268991              }
268992            },
268993            {
268994              "license": {
268995                "name": "This"
268996              }
268997            }
268998          ],
268999          "cpe": "cpe:2.3:a:python3.9-minimal:python3.9-minimal:3.9.2-1:*:*:*:*:*:*:*",
269000          "purl": "pkg:deb/debian/python3.9-minimal@3.9.2-1?arch=amd64\u0026upstream=python3.9\u0026distro=debian-11",
269001          "swid": {
269002            "attachment": {}
269003          },
269004          "pedigree": {},
269005          "evidence": {},
269006          "signature": {
269007            "signature": {
269008              "publicKey": {}
269009            }
269010          },
269011          "modelCard": {
269012            "modelParameters": {
269013              "approach": {}
269014            },
269015            "quantitativeAnalysis": {
269016              "graphics": {}
269017            },
269018            "considerations": {}
269019          }
269020        },
269021        {
269022          "type": "library",
269023          "bom-ref": "pkg:deb/debian/readline-common@8.1-1?arch=all\u0026upstream=readline\u0026distro=debian-11\u0026package-id=1db616197859926a",
269024          "supplier": {},
269025          "publisher": "Matthias Klose \u003cdoko@debian.org\u003e",
269026          "name": "readline-common",
269027          "version": "8.1-1",
269028          "licenses": [
269029            {
269030              "license": {
269031                "name": "GFDL"
269032              }
269033            },
269034            {
269035              "license": {
269036                "id": "GPL-3.0-only"
269037              }
269038            }
269039          ],
269040          "cpe": "cpe:2.3:a:readline-common:readline-common:8.1-1:*:*:*:*:*:*:*",
269041          "purl": "pkg:deb/debian/readline-common@8.1-1?arch=all\u0026upstream=readline\u0026distro=debian-11",
269042          "swid": {
269043            "attachment": {}
269044          },
269045          "pedigree": {},
269046          "evidence": {},
269047          "signature": {
269048            "signature": {
269049              "publicKey": {}
269050            }
269051          },
269052          "modelCard": {
269053            "modelParameters": {
269054              "approach": {}
269055            },
269056            "quantitativeAnalysis": {
269057              "graphics": {}
269058            },
269059            "considerations": {}
269060          }
269061        },
269062        {
269063          "type": "library",
269064          "bom-ref": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-11\u0026package-id=cd24b1a69c7b788a",
269065          "supplier": {},
269066          "publisher": "Clint Adams \u003cclint@debian.org\u003e",
269067          "name": "sed",
269068          "version": "4.7-1",
269069          "licenses": [
269070            {
269071              "license": {
269072                "id": "GPL-3.0-only"
269073              }
269074            }
269075          ],
269076          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
269077          "purl": "pkg:deb/debian/sed@4.7-1?arch=amd64\u0026distro=debian-11",
269078          "swid": {
269079            "attachment": {}
269080          },
269081          "pedigree": {},
269082          "evidence": {},
269083          "signature": {
269084            "signature": {
269085              "publicKey": {}
269086            }
269087          },
269088          "modelCard": {
269089            "modelParameters": {
269090              "approach": {}
269091            },
269092            "quantitativeAnalysis": {
269093              "graphics": {}
269094            },
269095            "considerations": {}
269096          }
269097        },
269098        {
269099          "type": "library",
269100          "bom-ref": "pkg:deb/debian/sensible-utils@0.0.14?arch=all\u0026distro=debian-11\u0026package-id=56274a0c1bc0afa2",
269101          "supplier": {},
269102          "publisher": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e",
269103          "name": "sensible-utils",
269104          "version": "0.0.14",
269105          "licenses": [
269106            {
269107              "license": {
269108                "name": "All-permissive"
269109              }
269110            },
269111            {
269112              "license": {
269113                "id": "GPL-2.0-only"
269114              }
269115            },
269116            {
269117              "license": {
269118                "id": "GPL-2.0-or-later"
269119              }
269120            },
269121            {
269122              "license": {
269123                "name": "configure"
269124              }
269125            },
269126            {
269127              "license": {
269128                "name": "installsh"
269129              }
269130            }
269131          ],
269132          "cpe": "cpe:2.3:a:sensible-utils:sensible-utils:0.0.14:*:*:*:*:*:*:*",
269133          "purl": "pkg:deb/debian/sensible-utils@0.0.14?arch=all\u0026distro=debian-11",
269134          "swid": {
269135            "attachment": {}
269136          },
269137          "pedigree": {},
269138          "evidence": {},
269139          "signature": {
269140            "signature": {
269141              "publicKey": {}
269142            }
269143          },
269144          "modelCard": {
269145            "modelParameters": {
269146              "approach": {}
269147            },
269148            "quantitativeAnalysis": {
269149              "graphics": {}
269150            },
269151            "considerations": {}
269152          }
269153        },
269154        {
269155          "type": "library",
269156          "bom-ref": "pkg:deb/debian/shared-mime-info@2.0-1?arch=amd64\u0026distro=debian-11\u0026package-id=4d8d941a94c5ae02",
269157          "supplier": {},
269158          "publisher": "Debian freedesktop.org maintainers \u003cpkg-freedesktop-maintainers@lists.alioth.debian.org\u003e",
269159          "name": "shared-mime-info",
269160          "version": "2.0-1",
269161          "licenses": [
269162            {
269163              "license": {
269164                "name": "GPL"
269165              }
269166            }
269167          ],
269168          "cpe": "cpe:2.3:a:shared-mime-info:shared-mime-info:2.0-1:*:*:*:*:*:*:*",
269169          "purl": "pkg:deb/debian/shared-mime-info@2.0-1?arch=amd64\u0026distro=debian-11",
269170          "swid": {
269171            "attachment": {}
269172          },
269173          "pedigree": {},
269174          "evidence": {},
269175          "signature": {
269176            "signature": {
269177              "publicKey": {}
269178            }
269179          },
269180          "modelCard": {
269181            "modelParameters": {
269182              "approach": {}
269183            },
269184            "quantitativeAnalysis": {
269185              "graphics": {}
269186            },
269187            "considerations": {}
269188          }
269189        },
269190        {
269191          "type": "library",
269192          "bom-ref": "pkg:deb/debian/strace@5.10-1?arch=amd64\u0026distro=debian-11\u0026package-id=90641fcb37751807",
269193          "supplier": {},
269194          "publisher": "Steve McIntyre \u003c93sam@debian.org\u003e",
269195          "name": "strace",
269196          "version": "5.10-1",
269197          "cpe": "cpe:2.3:a:strace:strace:5.10-1:*:*:*:*:*:*:*",
269198          "purl": "pkg:deb/debian/strace@5.10-1?arch=amd64\u0026distro=debian-11",
269199          "swid": {
269200            "attachment": {}
269201          },
269202          "pedigree": {},
269203          "evidence": {},
269204          "signature": {
269205            "signature": {
269206              "publicKey": {}
269207            }
269208          },
269209          "modelCard": {
269210            "modelParameters": {
269211              "approach": {}
269212            },
269213            "quantitativeAnalysis": {
269214              "graphics": {}
269215            },
269216            "considerations": {}
269217          }
269218        },
269219        {
269220          "type": "library",
269221          "bom-ref": "pkg:deb/debian/sysstat@12.5.2-2?arch=amd64\u0026distro=debian-11\u0026package-id=1a0e9434e2978afd",
269222          "supplier": {},
269223          "publisher": "Robert Luberda \u003crobert@debian.org\u003e",
269224          "name": "sysstat",
269225          "version": "12.5.2-2",
269226          "licenses": [
269227            {
269228              "license": {
269229                "id": "GPL-2.0-only"
269230              }
269231            },
269232            {
269233              "license": {
269234                "id": "GPL-2.0-or-later"
269235              }
269236            }
269237          ],
269238          "cpe": "cpe:2.3:a:sysstat:sysstat:12.5.2-2:*:*:*:*:*:*:*",
269239          "purl": "pkg:deb/debian/sysstat@12.5.2-2?arch=amd64\u0026distro=debian-11",
269240          "swid": {
269241            "attachment": {}
269242          },
269243          "pedigree": {},
269244          "evidence": {},
269245          "signature": {
269246            "signature": {
269247              "publicKey": {}
269248            }
269249          },
269250          "modelCard": {
269251            "modelParameters": {
269252              "approach": {}
269253            },
269254            "quantitativeAnalysis": {
269255              "graphics": {}
269256            },
269257            "considerations": {}
269258          }
269259        },
269260        {
269261          "type": "library",
269262          "bom-ref": "pkg:deb/debian/sysvinit-utils@2.96-7+deb11u1?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-11\u0026package-id=e0e95f2e10cb825e",
269263          "supplier": {},
269264          "publisher": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e",
269265          "name": "sysvinit-utils",
269266          "version": "2.96-7+deb11u1",
269267          "licenses": [
269268            {
269269              "license": {
269270                "id": "GPL-2.0-only"
269271              }
269272            },
269273            {
269274              "license": {
269275                "id": "GPL-2.0-or-later"
269276              }
269277            }
269278          ],
269279          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.96-7\\+deb11u1:*:*:*:*:*:*:*",
269280          "purl": "pkg:deb/debian/sysvinit-utils@2.96-7+deb11u1?arch=amd64\u0026upstream=sysvinit\u0026distro=debian-11",
269281          "swid": {
269282            "attachment": {}
269283          },
269284          "pedigree": {},
269285          "evidence": {},
269286          "signature": {
269287            "signature": {
269288              "publicKey": {}
269289            }
269290          },
269291          "modelCard": {
269292            "modelParameters": {
269293              "approach": {}
269294            },
269295            "quantitativeAnalysis": {
269296              "graphics": {}
269297            },
269298            "considerations": {}
269299          }
269300        },
269301        {
269302          "type": "library",
269303          "bom-ref": "pkg:deb/debian/tar@1.34+dfsg-1?arch=amd64\u0026distro=debian-11\u0026package-id=9511efaff0991270",
269304          "supplier": {},
269305          "publisher": "Janos Lenart \u003cocsi@debian.org\u003e",
269306          "name": "tar",
269307          "version": "1.34+dfsg-1",
269308          "licenses": [
269309            {
269310              "license": {
269311                "id": "GPL-2.0-only"
269312              }
269313            },
269314            {
269315              "license": {
269316                "id": "GPL-3.0-only"
269317              }
269318            }
269319          ],
269320          "cpe": "cpe:2.3:a:tar:tar:1.34\\+dfsg-1:*:*:*:*:*:*:*",
269321          "purl": "pkg:deb/debian/tar@1.34+dfsg-1?arch=amd64\u0026distro=debian-11",
269322          "swid": {
269323            "attachment": {}
269324          },
269325          "pedigree": {},
269326          "evidence": {},
269327          "signature": {
269328            "signature": {
269329              "publicKey": {}
269330            }
269331          },
269332          "modelCard": {
269333            "modelParameters": {
269334              "approach": {}
269335            },
269336            "quantitativeAnalysis": {
269337              "graphics": {}
269338            },
269339            "considerations": {}
269340          }
269341        },
269342        {
269343          "type": "library",
269344          "bom-ref": "pkg:deb/debian/tcpdump@4.99.0-2+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=1f6f78dd6ed77517",
269345          "supplier": {},
269346          "publisher": "Romain Francoise \u003crfrancoise@debian.org\u003e",
269347          "name": "tcpdump",
269348          "version": "4.99.0-2+deb11u1",
269349          "cpe": "cpe:2.3:a:tcpdump:tcpdump:4.99.0-2\\+deb11u1:*:*:*:*:*:*:*",
269350          "purl": "pkg:deb/debian/tcpdump@4.99.0-2+deb11u1?arch=amd64\u0026distro=debian-11",
269351          "swid": {
269352            "attachment": {}
269353          },
269354          "pedigree": {},
269355          "evidence": {},
269356          "signature": {
269357            "signature": {
269358              "publicKey": {}
269359            }
269360          },
269361          "modelCard": {
269362            "modelParameters": {
269363              "approach": {}
269364            },
269365            "quantitativeAnalysis": {
269366              "graphics": {}
269367            },
269368            "considerations": {}
269369          }
269370        },
269371        {
269372          "type": "library",
269373          "bom-ref": "pkg:deb/debian/tcpflow@1.5.2+repack1-1+b1?arch=amd64\u0026upstream=tcpflow%401.5.2+repack1-1\u0026distro=debian-11\u0026package-id=4da2fbdbb9da176e",
269374          "supplier": {},
269375          "publisher": "Dima Kogan \u003cdkogan@debian.org\u003e",
269376          "name": "tcpflow",
269377          "version": "1.5.2+repack1-1+b1",
269378          "licenses": [
269379            {
269380              "license": {
269381                "id": "BSD-2-Clause"
269382              }
269383            },
269384            {
269385              "license": {
269386                "name": "BSD-2clause-MadoryPang"
269387              }
269388            },
269389            {
269390              "license": {
269391                "name": "BSD-3clause-Young"
269392              }
269393            },
269394            {
269395              "license": {
269396                "name": "BSD-3clause-uni"
269397              }
269398            },
269399            {
269400              "license": {
269401                "id": "BSD-4-Clause"
269402              }
269403            },
269404            {
269405              "license": {
269406                "name": "Expat-Trifunovic"
269407              }
269408            },
269409            {
269410              "license": {
269411                "id": "GPL-2.0-only"
269412              }
269413            },
269414            {
269415              "license": {
269416                "id": "GPL-2.0-or-later"
269417              }
269418            },
269419            {
269420              "license": {
269421                "id": "GPL-3.0-only"
269422              }
269423            },
269424            {
269425              "license": {
269426                "id": "LGPL-2.1-only"
269427              }
269428            },
269429            {
269430              "license": {
269431                "id": "LGPL-2.1-or-later"
269432              }
269433            },
269434            {
269435              "license": {
269436                "name": "public-domain"
269437              }
269438            }
269439          ],
269440          "cpe": "cpe:2.3:a:tcpflow:tcpflow:1.5.2\\+repack1-1\\+b1:*:*:*:*:*:*:*",
269441          "purl": "pkg:deb/debian/tcpflow@1.5.2+repack1-1+b1?arch=amd64\u0026upstream=tcpflow%401.5.2+repack1-1\u0026distro=debian-11",
269442          "swid": {
269443            "attachment": {}
269444          },
269445          "pedigree": {},
269446          "evidence": {},
269447          "signature": {
269448            "signature": {
269449              "publicKey": {}
269450            }
269451          },
269452          "modelCard": {
269453            "modelParameters": {
269454              "approach": {}
269455            },
269456            "quantitativeAnalysis": {
269457              "graphics": {}
269458            },
269459            "considerations": {}
269460          }
269461        },
269462        {
269463          "type": "library",
269464          "bom-ref": "pkg:deb/debian/tmux@3.1c-1+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=6992e6b0a0b2a36",
269465          "supplier": {},
269466          "publisher": "Romain Francoise \u003crfrancoise@debian.org\u003e",
269467          "name": "tmux",
269468          "version": "3.1c-1+deb11u1",
269469          "licenses": [
269470            {
269471              "license": {
269472                "name": "BSD-2"
269473              }
269474            },
269475            {
269476              "license": {
269477                "name": "BSD-3"
269478              }
269479            }
269480          ],
269481          "cpe": "cpe:2.3:a:tmux:tmux:3.1c-1\\+deb11u1:*:*:*:*:*:*:*",
269482          "purl": "pkg:deb/debian/tmux@3.1c-1+deb11u1?arch=amd64\u0026distro=debian-11",
269483          "swid": {
269484            "attachment": {}
269485          },
269486          "pedigree": {},
269487          "evidence": {},
269488          "signature": {
269489            "signature": {
269490              "publicKey": {}
269491            }
269492          },
269493          "modelCard": {
269494            "modelParameters": {
269495              "approach": {}
269496            },
269497            "quantitativeAnalysis": {
269498              "graphics": {}
269499            },
269500            "considerations": {}
269501          }
269502        },
269503        {
269504          "type": "library",
269505          "bom-ref": "pkg:deb/debian/tree@1.8.0-1+b1?arch=amd64\u0026upstream=tree%401.8.0-1\u0026distro=debian-11\u0026package-id=f01533e2596b8293",
269506          "supplier": {},
269507          "publisher": "Florian Ernst \u003cflorian@debian.org\u003e",
269508          "name": "tree",
269509          "version": "1.8.0-1+b1",
269510          "licenses": [
269511            {
269512              "license": {
269513                "name": "GPL"
269514              }
269515            },
269516            {
269517              "license": {
269518                "id": "GPL-2.0-only"
269519              }
269520            }
269521          ],
269522          "cpe": "cpe:2.3:a:tree:tree:1.8.0-1\\+b1:*:*:*:*:*:*:*",
269523          "purl": "pkg:deb/debian/tree@1.8.0-1+b1?arch=amd64\u0026upstream=tree%401.8.0-1\u0026distro=debian-11",
269524          "swid": {
269525            "attachment": {}
269526          },
269527          "pedigree": {},
269528          "evidence": {},
269529          "signature": {
269530            "signature": {
269531              "publicKey": {}
269532            }
269533          },
269534          "modelCard": {
269535            "modelParameters": {
269536              "approach": {}
269537            },
269538            "quantitativeAnalysis": {
269539              "graphics": {}
269540            },
269541            "considerations": {}
269542          }
269543        },
269544        {
269545          "type": "library",
269546          "bom-ref": "pkg:deb/debian/tzdata@2021a-1+deb11u8?arch=all\u0026distro=debian-11\u0026package-id=116b456bca0486d4",
269547          "supplier": {},
269548          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
269549          "name": "tzdata",
269550          "version": "2021a-1+deb11u8",
269551          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-1\\+deb11u8:*:*:*:*:*:*:*",
269552          "purl": "pkg:deb/debian/tzdata@2021a-1+deb11u8?arch=all\u0026distro=debian-11",
269553          "swid": {
269554            "attachment": {}
269555          },
269556          "pedigree": {},
269557          "evidence": {},
269558          "signature": {
269559            "signature": {
269560              "publicKey": {}
269561            }
269562          },
269563          "modelCard": {
269564            "modelParameters": {
269565              "approach": {}
269566            },
269567            "quantitativeAnalysis": {
269568              "graphics": {}
269569            },
269570            "considerations": {}
269571          }
269572        },
269573        {
269574          "type": "library",
269575          "bom-ref": "pkg:deb/debian/ucf@3.0043?arch=all\u0026distro=debian-11\u0026package-id=dfbd4fe9d1f6c201",
269576          "supplier": {},
269577          "publisher": "Manoj Srivastava \u003csrivasta@debian.org\u003e",
269578          "name": "ucf",
269579          "version": "3.0043",
269580          "licenses": [
269581            {
269582              "license": {
269583                "id": "GPL-2.0-only"
269584              }
269585            }
269586          ],
269587          "cpe": "cpe:2.3:a:ucf:ucf:3.0043:*:*:*:*:*:*:*",
269588          "purl": "pkg:deb/debian/ucf@3.0043?arch=all\u0026distro=debian-11",
269589          "swid": {
269590            "attachment": {}
269591          },
269592          "pedigree": {},
269593          "evidence": {},
269594          "signature": {
269595            "signature": {
269596              "publicKey": {}
269597            }
269598          },
269599          "modelCard": {
269600            "modelParameters": {
269601              "approach": {}
269602            },
269603            "quantitativeAnalysis": {
269604              "graphics": {}
269605            },
269606            "considerations": {}
269607          }
269608        },
269609        {
269610          "type": "library",
269611          "bom-ref": "pkg:deb/debian/util-linux@2.36.1-8+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=b8c872368f65d4a3",
269612          "supplier": {},
269613          "publisher": "util-linux packagers \u003cutil-linux@packages.debian.org\u003e",
269614          "name": "util-linux",
269615          "version": "2.36.1-8+deb11u1",
269616          "licenses": [
269617            {
269618              "license": {
269619                "id": "BSD-2-Clause"
269620              }
269621            },
269622            {
269623              "license": {
269624                "id": "BSD-3-Clause"
269625              }
269626            },
269627            {
269628              "license": {
269629                "id": "BSD-4-Clause"
269630              }
269631            },
269632            {
269633              "license": {
269634                "id": "GPL-2.0-only"
269635              }
269636            },
269637            {
269638              "license": {
269639                "id": "GPL-2.0-or-later"
269640              }
269641            },
269642            {
269643              "license": {
269644                "id": "GPL-3.0-only"
269645              }
269646            },
269647            {
269648              "license": {
269649                "id": "GPL-3.0-or-later"
269650              }
269651            },
269652            {
269653              "license": {
269654                "name": "LGPL"
269655              }
269656            },
269657            {
269658              "license": {
269659                "id": "LGPL-2.0-only"
269660              }
269661            },
269662            {
269663              "license": {
269664                "id": "LGPL-2.0-or-later"
269665              }
269666            },
269667            {
269668              "license": {
269669                "id": "LGPL-2.1-only"
269670              }
269671            },
269672            {
269673              "license": {
269674                "id": "LGPL-2.1-or-later"
269675              }
269676            },
269677            {
269678              "license": {
269679                "id": "LGPL-3.0-only"
269680              }
269681            },
269682            {
269683              "license": {
269684                "id": "LGPL-3.0-or-later"
269685              }
269686            },
269687            {
269688              "license": {
269689                "id": "MIT"
269690              }
269691            },
269692            {
269693              "license": {
269694                "name": "public-domain"
269695              }
269696            }
269697          ],
269698          "cpe": "cpe:2.3:a:util-linux:util-linux:2.36.1-8\\+deb11u1:*:*:*:*:*:*:*",
269699          "purl": "pkg:deb/debian/util-linux@2.36.1-8+deb11u1?arch=amd64\u0026distro=debian-11",
269700          "swid": {
269701            "attachment": {}
269702          },
269703          "pedigree": {},
269704          "evidence": {},
269705          "signature": {
269706            "signature": {
269707              "publicKey": {}
269708            }
269709          },
269710          "modelCard": {
269711            "modelParameters": {
269712              "approach": {}
269713            },
269714            "quantitativeAnalysis": {
269715              "graphics": {}
269716            },
269717            "considerations": {}
269718          }
269719        },
269720        {
269721          "type": "library",
269722          "bom-ref": "pkg:deb/debian/valgrind@1:3.16.1-1?arch=amd64\u0026distro=debian-11\u0026package-id=4463102b9d928a92",
269723          "supplier": {},
269724          "publisher": "Alessandro Ghedini \u003cghedo@debian.org\u003e",
269725          "name": "valgrind",
269726          "version": "1:3.16.1-1",
269727          "licenses": [
269728            {
269729              "license": {
269730                "id": "BSD-3-Clause"
269731              }
269732            },
269733            {
269734              "license": {
269735                "id": "GPL-2.0-only"
269736              }
269737            },
269738            {
269739              "license": {
269740                "id": "GPL-2.0-or-later"
269741              }
269742            },
269743            {
269744              "license": {
269745                "id": "LGPL-2.0-only"
269746              }
269747            },
269748            {
269749              "license": {
269750                "id": "LGPL-2.0-or-later"
269751              }
269752            },
269753            {
269754              "license": {
269755                "id": "LGPL-2.1-only"
269756              }
269757            },
269758            {
269759              "license": {
269760                "id": "LGPL-2.1-or-later"
269761              }
269762            },
269763            {
269764              "license": {
269765                "name": "other"
269766              }
269767            }
269768          ],
269769          "cpe": "cpe:2.3:a:valgrind:valgrind:1\\:3.16.1-1:*:*:*:*:*:*:*",
269770          "purl": "pkg:deb/debian/valgrind@1:3.16.1-1?arch=amd64\u0026distro=debian-11",
269771          "swid": {
269772            "attachment": {}
269773          },
269774          "pedigree": {},
269775          "evidence": {},
269776          "signature": {
269777            "signature": {
269778              "publicKey": {}
269779            }
269780          },
269781          "modelCard": {
269782            "modelParameters": {
269783              "approach": {}
269784            },
269785            "quantitativeAnalysis": {
269786              "graphics": {}
269787            },
269788            "considerations": {}
269789          }
269790        },
269791        {
269792          "type": "library",
269793          "bom-ref": "pkg:deb/debian/vim@2:8.2.2434-3+deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=80d543c9baabc796",
269794          "supplier": {},
269795          "publisher": "Debian Vim Maintainers \u003cteam+vim@tracker.debian.org\u003e",
269796          "name": "vim",
269797          "version": "2:8.2.2434-3+deb11u1",
269798          "licenses": [
269799            {
269800              "license": {
269801                "name": "Apache"
269802              }
269803            },
269804            {
269805              "license": {
269806                "id": "Apache-2.0"
269807              }
269808            },
269809            {
269810              "license": {
269811                "name": "Artistic"
269812              }
269813            },
269814            {
269815              "license": {
269816                "id": "Artistic-1.0"
269817              }
269818            },
269819            {
269820              "license": {
269821                "id": "BSD-2-Clause"
269822              }
269823            },
269824            {
269825              "license": {
269826                "id": "BSD-3-Clause"
269827              }
269828            },
269829            {
269830              "license": {
269831                "name": "Compaq"
269832              }
269833            },
269834            {
269835              "license": {
269836                "name": "EDL-1"
269837              }
269838            },
269839            {
269840              "license": {
269841                "name": "Expat"
269842              }
269843            },
269844            {
269845              "license": {
269846                "id": "GPL-1.0-only"
269847              }
269848            },
269849            {
269850              "license": {
269851                "id": "GPL-1.0-or-later"
269852              }
269853            },
269854            {
269855              "license": {
269856                "id": "GPL-2.0-only"
269857              }
269858            },
269859            {
269860              "license": {
269861                "id": "GPL-2.0-or-later"
269862              }
269863            },
269864            {
269865              "license": {
269866                "id": "LGPL-2.1-only"
269867              }
269868            },
269869            {
269870              "license": {
269871                "id": "LGPL-2.1-or-later"
269872              }
269873            },
269874            {
269875              "license": {
269876                "name": "OPL-1+"
269877              }
269878            },
269879            {
269880              "license": {
269881                "name": "SRA"
269882              }
269883            },
269884            {
269885              "license": {
269886                "name": "UC"
269887              }
269888            },
269889            {
269890              "license": {
269891                "id": "Vim"
269892              }
269893            },
269894            {
269895              "license": {
269896                "name": "Vim-Regexp"
269897              }
269898            },
269899            {
269900              "license": {
269901                "id": "X11"
269902              }
269903            },
269904            {
269905              "license": {
269906                "name": "XPM"
269907              }
269908            },
269909            {
269910              "license": {
269911                "name": "public-domain"
269912              }
269913            }
269914          ],
269915          "cpe": "cpe:2.3:a:vim:vim:2\\:8.2.2434-3\\+deb11u1:*:*:*:*:*:*:*",
269916          "purl": "pkg:deb/debian/vim@2:8.2.2434-3+deb11u1?arch=amd64\u0026distro=debian-11",
269917          "swid": {
269918            "attachment": {}
269919          },
269920          "pedigree": {},
269921          "evidence": {},
269922          "signature": {
269923            "signature": {
269924              "publicKey": {}
269925            }
269926          },
269927          "modelCard": {
269928            "modelParameters": {
269929              "approach": {}
269930            },
269931            "quantitativeAnalysis": {
269932              "graphics": {}
269933            },
269934            "considerations": {}
269935          }
269936        },
269937        {
269938          "type": "library",
269939          "bom-ref": "pkg:deb/debian/vim-common@2:8.2.2434-3+deb11u1?arch=all\u0026upstream=vim\u0026distro=debian-11\u0026package-id=ae1df820fcbdf74c",
269940          "supplier": {},
269941          "publisher": "Debian Vim Maintainers \u003cteam+vim@tracker.debian.org\u003e",
269942          "name": "vim-common",
269943          "version": "2:8.2.2434-3+deb11u1",
269944          "licenses": [
269945            {
269946              "license": {
269947                "name": "Apache"
269948              }
269949            },
269950            {
269951              "license": {
269952                "id": "Apache-2.0"
269953              }
269954            },
269955            {
269956              "license": {
269957                "name": "Artistic"
269958              }
269959            },
269960            {
269961              "license": {
269962                "id": "Artistic-1.0"
269963              }
269964            },
269965            {
269966              "license": {
269967                "id": "BSD-2-Clause"
269968              }
269969            },
269970            {
269971              "license": {
269972                "id": "BSD-3-Clause"
269973              }
269974            },
269975            {
269976              "license": {
269977                "name": "Compaq"
269978              }
269979            },
269980            {
269981              "license": {
269982                "name": "EDL-1"
269983              }
269984            },
269985            {
269986              "license": {
269987                "name": "Expat"
269988              }
269989            },
269990            {
269991              "license": {
269992                "id": "GPL-1.0-only"
269993              }
269994            },
269995            {
269996              "license": {
269997                "id": "GPL-1.0-or-later"
269998              }
269999            },
270000            {
270001              "license": {
270002                "id": "GPL-2.0-only"
270003              }
270004            },
270005            {
270006              "license": {
270007                "id": "GPL-2.0-or-later"
270008              }
270009            },
270010            {
270011              "license": {
270012                "id": "LGPL-2.1-only"
270013              }
270014            },
270015            {
270016              "license": {
270017                "id": "LGPL-2.1-or-later"
270018              }
270019            },
270020            {
270021              "license": {
270022                "name": "OPL-1+"
270023              }
270024            },
270025            {
270026              "license": {
270027                "name": "SRA"
270028              }
270029            },
270030            {
270031              "license": {
270032                "name": "UC"
270033              }
270034            },
270035            {
270036              "license": {
270037                "id": "Vim"
270038              }
270039            },
270040            {
270041              "license": {
270042                "name": "Vim-Regexp"
270043              }
270044            },
270045            {
270046              "license": {
270047                "id": "X11"
270048              }
270049            },
270050            {
270051              "license": {
270052                "name": "XPM"
270053              }
270054            },
270055            {
270056              "license": {
270057                "name": "public-domain"
270058              }
270059            }
270060          ],
270061          "cpe": "cpe:2.3:a:vim-common:vim-common:2\\:8.2.2434-3\\+deb11u1:*:*:*:*:*:*:*",
270062          "purl": "pkg:deb/debian/vim-common@2:8.2.2434-3+deb11u1?arch=all\u0026upstream=vim\u0026distro=debian-11",
270063          "swid": {
270064            "attachment": {}
270065          },
270066          "pedigree": {},
270067          "evidence": {},
270068          "signature": {
270069            "signature": {
270070              "publicKey": {}
270071            }
270072          },
270073          "modelCard": {
270074            "modelParameters": {
270075              "approach": {}
270076            },
270077            "quantitativeAnalysis": {
270078              "graphics": {}
270079            },
270080            "considerations": {}
270081          }
270082        },
270083        {
270084          "type": "library",
270085          "bom-ref": "pkg:deb/debian/vim-runtime@2:8.2.2434-3+deb11u1?arch=all\u0026upstream=vim\u0026distro=debian-11\u0026package-id=6254b405280fe12b",
270086          "supplier": {},
270087          "publisher": "Debian Vim Maintainers \u003cteam+vim@tracker.debian.org\u003e",
270088          "name": "vim-runtime",
270089          "version": "2:8.2.2434-3+deb11u1",
270090          "licenses": [
270091            {
270092              "license": {
270093                "name": "Apache"
270094              }
270095            },
270096            {
270097              "license": {
270098                "id": "Apache-2.0"
270099              }
270100            },
270101            {
270102              "license": {
270103                "name": "Artistic"
270104              }
270105            },
270106            {
270107              "license": {
270108                "id": "Artistic-1.0"
270109              }
270110            },
270111            {
270112              "license": {
270113                "id": "BSD-2-Clause"
270114              }
270115            },
270116            {
270117              "license": {
270118                "id": "BSD-3-Clause"
270119              }
270120            },
270121            {
270122              "license": {
270123                "name": "Compaq"
270124              }
270125            },
270126            {
270127              "license": {
270128                "name": "EDL-1"
270129              }
270130            },
270131            {
270132              "license": {
270133                "name": "Expat"
270134              }
270135            },
270136            {
270137              "license": {
270138                "id": "GPL-1.0-only"
270139              }
270140            },
270141            {
270142              "license": {
270143                "id": "GPL-1.0-or-later"
270144              }
270145            },
270146            {
270147              "license": {
270148                "id": "GPL-2.0-only"
270149              }
270150            },
270151            {
270152              "license": {
270153                "id": "GPL-2.0-or-later"
270154              }
270155            },
270156            {
270157              "license": {
270158                "id": "LGPL-2.1-only"
270159              }
270160            },
270161            {
270162              "license": {
270163                "id": "LGPL-2.1-or-later"
270164              }
270165            },
270166            {
270167              "license": {
270168                "name": "OPL-1+"
270169              }
270170            },
270171            {
270172              "license": {
270173                "name": "SRA"
270174              }
270175            },
270176            {
270177              "license": {
270178                "name": "UC"
270179              }
270180            },
270181            {
270182              "license": {
270183                "id": "Vim"
270184              }
270185            },
270186            {
270187              "license": {
270188                "name": "Vim-Regexp"
270189              }
270190            },
270191            {
270192              "license": {
270193                "id": "X11"
270194              }
270195            },
270196            {
270197              "license": {
270198                "name": "XPM"
270199              }
270200            },
270201            {
270202              "license": {
270203                "name": "public-domain"
270204              }
270205            }
270206          ],
270207          "cpe": "cpe:2.3:a:vim-runtime:vim-runtime:2\\:8.2.2434-3\\+deb11u1:*:*:*:*:*:*:*",
270208          "purl": "pkg:deb/debian/vim-runtime@2:8.2.2434-3+deb11u1?arch=all\u0026upstream=vim\u0026distro=debian-11",
270209          "swid": {
270210            "attachment": {}
270211          },
270212          "pedigree": {},
270213          "evidence": {},
270214          "signature": {
270215            "signature": {
270216              "publicKey": {}
270217            }
270218          },
270219          "modelCard": {
270220            "modelParameters": {
270221              "approach": {}
270222            },
270223            "quantitativeAnalysis": {
270224              "graphics": {}
270225            },
270226            "considerations": {}
270227          }
270228        },
270229        {
270230          "type": "library",
270231          "bom-ref": "pkg:deb/debian/xxd@2:8.2.2434-3+deb11u1?arch=amd64\u0026upstream=vim\u0026distro=debian-11\u0026package-id=2bc0641b2bda5a70",
270232          "supplier": {},
270233          "publisher": "Debian Vim Maintainers \u003cteam+vim@tracker.debian.org\u003e",
270234          "name": "xxd",
270235          "version": "2:8.2.2434-3+deb11u1",
270236          "licenses": [
270237            {
270238              "license": {
270239                "name": "Apache"
270240              }
270241            },
270242            {
270243              "license": {
270244                "id": "Apache-2.0"
270245              }
270246            },
270247            {
270248              "license": {
270249                "name": "Artistic"
270250              }
270251            },
270252            {
270253              "license": {
270254                "id": "Artistic-1.0"
270255              }
270256            },
270257            {
270258              "license": {
270259                "id": "BSD-2-Clause"
270260              }
270261            },
270262            {
270263              "license": {
270264                "id": "BSD-3-Clause"
270265              }
270266            },
270267            {
270268              "license": {
270269                "name": "Compaq"
270270              }
270271            },
270272            {
270273              "license": {
270274                "name": "EDL-1"
270275              }
270276            },
270277            {
270278              "license": {
270279                "name": "Expat"
270280              }
270281            },
270282            {
270283              "license": {
270284                "id": "GPL-1.0-only"
270285              }
270286            },
270287            {
270288              "license": {
270289                "id": "GPL-1.0-or-later"
270290              }
270291            },
270292            {
270293              "license": {
270294                "id": "GPL-2.0-only"
270295              }
270296            },
270297            {
270298              "license": {
270299                "id": "GPL-2.0-or-later"
270300              }
270301            },
270302            {
270303              "license": {
270304                "id": "LGPL-2.1-only"
270305              }
270306            },
270307            {
270308              "license": {
270309                "id": "LGPL-2.1-or-later"
270310              }
270311            },
270312            {
270313              "license": {
270314                "name": "OPL-1+"
270315              }
270316            },
270317            {
270318              "license": {
270319                "name": "SRA"
270320              }
270321            },
270322            {
270323              "license": {
270324                "name": "UC"
270325              }
270326            },
270327            {
270328              "license": {
270329                "id": "Vim"
270330              }
270331            },
270332            {
270333              "license": {
270334                "name": "Vim-Regexp"
270335              }
270336            },
270337            {
270338              "license": {
270339                "id": "X11"
270340              }
270341            },
270342            {
270343              "license": {
270344                "name": "XPM"
270345              }
270346            },
270347            {
270348              "license": {
270349                "name": "public-domain"
270350              }
270351            }
270352          ],
270353          "cpe": "cpe:2.3:a:xxd:xxd:2\\:8.2.2434-3\\+deb11u1:*:*:*:*:*:*:*",
270354          "purl": "pkg:deb/debian/xxd@2:8.2.2434-3+deb11u1?arch=amd64\u0026upstream=vim\u0026distro=debian-11",
270355          "swid": {
270356            "attachment": {}
270357          },
270358          "pedigree": {},
270359          "evidence": {},
270360          "signature": {
270361            "signature": {
270362              "publicKey": {}
270363            }
270364          },
270365          "modelCard": {
270366            "modelParameters": {
270367              "approach": {}
270368            },
270369            "quantitativeAnalysis": {
270370              "graphics": {}
270371            },
270372            "considerations": {}
270373          }
270374        },
270375        {
270376          "type": "library",
270377          "bom-ref": "pkg:deb/debian/xz-utils@5.2.5-2.1~deb11u1?arch=amd64\u0026distro=debian-11\u0026package-id=2dc48701dfba1308",
270378          "supplier": {},
270379          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
270380          "name": "xz-utils",
270381          "version": "5.2.5-2.1~deb11u1",
270382          "licenses": [
270383            {
270384              "license": {
270385                "name": "Autoconf"
270386              }
270387            },
270388            {
270389              "license": {
270390                "id": "GPL-2.0-only"
270391              }
270392            },
270393            {
270394              "license": {
270395                "id": "GPL-2.0-or-later"
270396              }
270397            },
270398            {
270399              "license": {
270400                "id": "GPL-3.0-only"
270401              }
270402            },
270403            {
270404              "license": {
270405                "id": "LGPL-2.0-only"
270406              }
270407            },
270408            {
270409              "license": {
270410                "id": "LGPL-2.1-only"
270411              }
270412            },
270413            {
270414              "license": {
270415                "id": "LGPL-2.1-or-later"
270416              }
270417            },
270418            {
270419              "license": {
270420                "name": "PD"
270421              }
270422            },
270423            {
270424              "license": {
270425                "name": "PD-debian"
270426              }
270427            },
270428            {
270429              "license": {
270430                "name": "config-h"
270431              }
270432            },
270433            {
270434              "license": {
270435                "name": "noderivs"
270436              }
270437            },
270438            {
270439              "license": {
270440                "name": "permissive-fsf"
270441              }
270442            },
270443            {
270444              "license": {
270445                "name": "permissive-nowarranty"
270446              }
270447            },
270448            {
270449              "license": {
270450                "name": "probably-PD"
270451              }
270452            }
270453          ],
270454          "cpe": "cpe:2.3:a:xz-utils:xz-utils:5.2.5-2.1\\~deb11u1:*:*:*:*:*:*:*",
270455          "purl": "pkg:deb/debian/xz-utils@5.2.5-2.1~deb11u1?arch=amd64\u0026distro=debian-11",
270456          "swid": {
270457            "attachment": {}
270458          },
270459          "pedigree": {},
270460          "evidence": {},
270461          "signature": {
270462            "signature": {
270463              "publicKey": {}
270464            }
270465          },
270466          "modelCard": {
270467            "modelParameters": {
270468              "approach": {}
270469            },
270470            "quantitativeAnalysis": {
270471              "graphics": {}
270472            },
270473            "considerations": {}
270474          }
270475        },
270476        {
270477          "type": "library",
270478          "bom-ref": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-2+deb11u2?arch=amd64\u0026upstream=zlib\u0026distro=debian-11\u0026package-id=369e996115240b62",
270479          "supplier": {},
270480          "publisher": "Mark Brown \u003cbroonie@debian.org\u003e",
270481          "name": "zlib1g",
270482          "version": "1:1.2.11.dfsg-2+deb11u2",
270483          "licenses": [
270484            {
270485              "license": {
270486                "id": "Zlib"
270487              }
270488            }
270489          ],
270490          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2\\+deb11u2:*:*:*:*:*:*:*",
270491          "purl": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-2+deb11u2?arch=amd64\u0026upstream=zlib\u0026distro=debian-11",
270492          "swid": {
270493            "attachment": {}
270494          },
270495          "pedigree": {},
270496          "evidence": {},
270497          "signature": {
270498            "signature": {
270499              "publicKey": {}
270500            }
270501          },
270502          "modelCard": {
270503            "modelParameters": {
270504              "approach": {}
270505            },
270506            "quantitativeAnalysis": {
270507              "graphics": {}
270508            },
270509            "considerations": {}
270510          }
270511        },
270512        {
270513          "type": "operating-system",
270514          "supplier": {},
270515          "name": "debian",
270516          "version": "11",
270517          "description": "Debian GNU/Linux 11 (bullseye)",
270518          "swid": {
270519            "tagId": "debian",
270520            "name": "debian",
270521            "version": "11",
270522            "attachment": {}
270523          },
270524          "pedigree": {},
270525          "externalReferences": [
270526            {
270527              "url": "https://bugs.debian.org/",
270528              "type": "issue-tracker"
270529            },
270530            {
270531              "url": "https://www.debian.org/",
270532              "type": "website"
270533            },
270534            {
270535              "url": "https://www.debian.org/support",
270536              "comment": "support",
270537              "type": "other"
270538            }
270539          ],
270540          "evidence": {},
270541          "signature": {
270542            "signature": {
270543              "publicKey": {}
270544            }
270545          },
270546          "modelCard": {
270547            "modelParameters": {
270548              "approach": {}
270549            },
270550            "quantitativeAnalysis": {
270551              "graphics": {}
270552            },
270553            "considerations": {}
270554          }
270555        },
270556        {
270557          "type": "library",
270558          "bom-ref": "pkg:deb/debian/base-files@11.1+deb11u5?arch=amd64\u0026distro=debian-11\u0026package-id=f3f2a2ef549813e7",
270559          "supplier": {},
270560          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
270561          "name": "base-files",
270562          "version": "11.1+deb11u5",
270563          "licenses": [
270564            {
270565              "license": {
270566                "name": "GPL"
270567              }
270568            }
270569          ],
270570          "cpe": "cpe:2.3:a:base-files:base-files:11.1\\+deb11u5:*:*:*:*:*:*:*",
270571          "purl": "pkg:deb/debian/base-files@11.1+deb11u5?arch=amd64\u0026distro=debian-11",
270572          "swid": {
270573            "attachment": {}
270574          },
270575          "pedigree": {},
270576          "evidence": {},
270577          "signature": {
270578            "signature": {
270579              "publicKey": {}
270580            }
270581          },
270582          "modelCard": {
270583            "modelParameters": {
270584              "approach": {}
270585            },
270586            "quantitativeAnalysis": {
270587              "graphics": {}
270588            },
270589            "considerations": {}
270590          }
270591        },
270592        {
270593          "type": "library",
270594          "bom-ref": "pkg:deb/debian/ca-certificates@20210119?arch=all\u0026distro=debian-11\u0026package-id=21646239c6ab680a",
270595          "supplier": {},
270596          "publisher": "Julien Cristau \u003cjcristau@debian.org\u003e",
270597          "name": "ca-certificates",
270598          "version": "20210119",
270599          "licenses": [
270600            {
270601              "license": {
270602                "id": "GPL-2.0-only"
270603              }
270604            },
270605            {
270606              "license": {
270607                "id": "GPL-2.0-or-later"
270608              }
270609            },
270610            {
270611              "license": {
270612                "id": "MPL-2.0"
270613              }
270614            }
270615          ],
270616          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20210119:*:*:*:*:*:*:*",
270617          "purl": "pkg:deb/debian/ca-certificates@20210119?arch=all\u0026distro=debian-11",
270618          "swid": {
270619            "attachment": {}
270620          },
270621          "pedigree": {},
270622          "evidence": {},
270623          "signature": {
270624            "signature": {
270625              "publicKey": {}
270626            }
270627          },
270628          "modelCard": {
270629            "modelParameters": {
270630              "approach": {}
270631            },
270632            "quantitativeAnalysis": {
270633              "graphics": {}
270634            },
270635            "considerations": {}
270636          }
270637        },
270638        {
270639          "type": "library",
270640          "bom-ref": "pkg:deb/debian/libatomic1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=66ead67846bafb00",
270641          "supplier": {},
270642          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
270643          "name": "libatomic1",
270644          "version": "10.2.1-6",
270645          "cpe": "cpe:2.3:a:libatomic1:libatomic1:10.2.1-6:*:*:*:*:*:*:*",
270646          "purl": "pkg:deb/debian/libatomic1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
270647          "swid": {
270648            "attachment": {}
270649          },
270650          "pedigree": {},
270651          "evidence": {},
270652          "signature": {
270653            "signature": {
270654              "publicKey": {}
270655            }
270656          },
270657          "modelCard": {
270658            "modelParameters": {
270659              "approach": {}
270660            },
270661            "quantitativeAnalysis": {
270662              "graphics": {}
270663            },
270664            "considerations": {}
270665          }
270666        },
270667        {
270668          "type": "library",
270669          "bom-ref": "pkg:deb/debian/libc6@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11\u0026package-id=9d4972f76613a7a8",
270670          "supplier": {},
270671          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
270672          "name": "libc6",
270673          "version": "2.31-13+deb11u5",
270674          "licenses": [
270675            {
270676              "license": {
270677                "id": "GPL-2.0-only"
270678              }
270679            },
270680            {
270681              "license": {
270682                "id": "LGPL-2.1-only"
270683              }
270684            }
270685          ],
270686          "cpe": "cpe:2.3:a:libc6:libc6:2.31-13\\+deb11u5:*:*:*:*:*:*:*",
270687          "purl": "pkg:deb/debian/libc6@2.31-13+deb11u5?arch=amd64\u0026upstream=glibc\u0026distro=debian-11",
270688          "swid": {
270689            "attachment": {}
270690          },
270691          "pedigree": {},
270692          "evidence": {},
270693          "signature": {
270694            "signature": {
270695              "publicKey": {}
270696            }
270697          },
270698          "modelCard": {
270699            "modelParameters": {
270700              "approach": {}
270701            },
270702            "quantitativeAnalysis": {
270703              "graphics": {}
270704            },
270705            "considerations": {}
270706          }
270707        },
270708        {
270709          "type": "library",
270710          "bom-ref": "pkg:deb/debian/libcom-err2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11\u0026package-id=39da134bbf8f09e3",
270711          "supplier": {},
270712          "publisher": "Theodore Y. Ts'o \u003ctytso@mit.edu\u003e",
270713          "name": "libcom-err2",
270714          "version": "1.46.2-2",
270715          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.46.2-2:*:*:*:*:*:*:*",
270716          "purl": "pkg:deb/debian/libcom-err2@1.46.2-2?arch=amd64\u0026upstream=e2fsprogs\u0026distro=debian-11",
270717          "swid": {
270718            "attachment": {}
270719          },
270720          "pedigree": {},
270721          "evidence": {},
270722          "signature": {
270723            "signature": {
270724              "publicKey": {}
270725            }
270726          },
270727          "modelCard": {
270728            "modelParameters": {
270729              "approach": {}
270730            },
270731            "quantitativeAnalysis": {
270732              "graphics": {}
270733            },
270734            "considerations": {}
270735          }
270736        },
270737        {
270738          "type": "library",
270739          "bom-ref": "pkg:deb/debian/libffi7@3.3-6?arch=amd64\u0026upstream=libffi\u0026distro=debian-11\u0026package-id=c9a6310f4b1e892a",
270740          "supplier": {},
270741          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
270742          "name": "libffi7",
270743          "version": "3.3-6",
270744          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-6:*:*:*:*:*:*:*",
270745          "purl": "pkg:deb/debian/libffi7@3.3-6?arch=amd64\u0026upstream=libffi\u0026distro=debian-11",
270746          "swid": {
270747            "attachment": {}
270748          },
270749          "pedigree": {},
270750          "evidence": {},
270751          "signature": {
270752            "signature": {
270753              "publicKey": {}
270754            }
270755          },
270756          "modelCard": {
270757            "modelParameters": {
270758              "approach": {}
270759            },
270760            "quantitativeAnalysis": {
270761              "graphics": {}
270762            },
270763            "considerations": {}
270764          }
270765        },
270766        {
270767          "type": "library",
270768          "bom-ref": "pkg:deb/debian/libgcc-s1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=a34cfbb99331195b",
270769          "supplier": {},
270770          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
270771          "name": "libgcc-s1",
270772          "version": "10.2.1-6",
270773          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.2.1-6:*:*:*:*:*:*:*",
270774          "purl": "pkg:deb/debian/libgcc-s1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
270775          "swid": {
270776            "attachment": {}
270777          },
270778          "pedigree": {},
270779          "evidence": {},
270780          "signature": {
270781            "signature": {
270782              "publicKey": {}
270783            }
270784          },
270785          "modelCard": {
270786            "modelParameters": {
270787              "approach": {}
270788            },
270789            "quantitativeAnalysis": {
270790              "graphics": {}
270791            },
270792            "considerations": {}
270793          }
270794        },
270795        {
270796          "type": "library",
270797          "bom-ref": "pkg:deb/debian/libgcrypt20@1.8.7-6?arch=amd64\u0026distro=debian-11\u0026package-id=e4322ae6de6194e3",
270798          "supplier": {},
270799          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
270800          "name": "libgcrypt20",
270801          "version": "1.8.7-6",
270802          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.7-6:*:*:*:*:*:*:*",
270803          "purl": "pkg:deb/debian/libgcrypt20@1.8.7-6?arch=amd64\u0026distro=debian-11",
270804          "swid": {
270805            "attachment": {}
270806          },
270807          "pedigree": {},
270808          "evidence": {},
270809          "signature": {
270810            "signature": {
270811              "publicKey": {}
270812            }
270813          },
270814          "modelCard": {
270815            "modelParameters": {
270816              "approach": {}
270817            },
270818            "quantitativeAnalysis": {
270819              "graphics": {}
270820            },
270821            "considerations": {}
270822          }
270823        },
270824        {
270825          "type": "library",
270826          "bom-ref": "pkg:deb/debian/libgmp10@2:6.2.1+dfsg-1+deb11u1?arch=amd64\u0026upstream=gmp\u0026distro=debian-11\u0026package-id=fd50a8afffdb05ea",
270827          "supplier": {},
270828          "publisher": "Debian Science Team \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e",
270829          "name": "libgmp10",
270830          "version": "2:6.2.1+dfsg-1+deb11u1",
270831          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.1\\+dfsg-1\\+deb11u1:*:*:*:*:*:*:*",
270832          "purl": "pkg:deb/debian/libgmp10@2:6.2.1+dfsg-1+deb11u1?arch=amd64\u0026upstream=gmp\u0026distro=debian-11",
270833          "swid": {
270834            "attachment": {}
270835          },
270836          "pedigree": {},
270837          "evidence": {},
270838          "signature": {
270839            "signature": {
270840              "publicKey": {}
270841            }
270842          },
270843          "modelCard": {
270844            "modelParameters": {
270845              "approach": {}
270846            },
270847            "quantitativeAnalysis": {
270848              "graphics": {}
270849            },
270850            "considerations": {}
270851          }
270852        },
270853        {
270854          "type": "library",
270855          "bom-ref": "pkg:deb/debian/libgnutls30@3.7.1-5+deb11u2?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-11\u0026package-id=a7fb37e64b53a117",
270856          "supplier": {},
270857          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
270858          "name": "libgnutls30",
270859          "version": "3.7.1-5+deb11u2",
270860          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.7.1-5\\+deb11u2:*:*:*:*:*:*:*",
270861          "purl": "pkg:deb/debian/libgnutls30@3.7.1-5+deb11u2?arch=amd64\u0026upstream=gnutls28\u0026distro=debian-11",
270862          "swid": {
270863            "attachment": {}
270864          },
270865          "pedigree": {},
270866          "evidence": {},
270867          "signature": {
270868            "signature": {
270869              "publicKey": {}
270870            }
270871          },
270872          "modelCard": {
270873            "modelParameters": {
270874              "approach": {}
270875            },
270876            "quantitativeAnalysis": {
270877              "graphics": {}
270878            },
270879            "considerations": {}
270880          }
270881        },
270882        {
270883          "type": "library",
270884          "bom-ref": "pkg:deb/debian/libgomp1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=64874408d63158d7",
270885          "supplier": {},
270886          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
270887          "name": "libgomp1",
270888          "version": "10.2.1-6",
270889          "cpe": "cpe:2.3:a:libgomp1:libgomp1:10.2.1-6:*:*:*:*:*:*:*",
270890          "purl": "pkg:deb/debian/libgomp1@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
270891          "swid": {
270892            "attachment": {}
270893          },
270894          "pedigree": {},
270895          "evidence": {},
270896          "signature": {
270897            "signature": {
270898              "publicKey": {}
270899            }
270900          },
270901          "modelCard": {
270902            "modelParameters": {
270903              "approach": {}
270904            },
270905            "quantitativeAnalysis": {
270906              "graphics": {}
270907            },
270908            "considerations": {}
270909          }
270910        },
270911        {
270912          "type": "library",
270913          "bom-ref": "pkg:deb/debian/libgpg-error0@1.38-2?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-11\u0026package-id=adbdf6119b3038eb",
270914          "supplier": {},
270915          "publisher": "Debian GnuPG Maintainers \u003cpkg-gnupg-maint@lists.alioth.debian.org\u003e",
270916          "name": "libgpg-error0",
270917          "version": "1.38-2",
270918          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.38-2:*:*:*:*:*:*:*",
270919          "purl": "pkg:deb/debian/libgpg-error0@1.38-2?arch=amd64\u0026upstream=libgpg-error\u0026distro=debian-11",
270920          "swid": {
270921            "attachment": {}
270922          },
270923          "pedigree": {},
270924          "evidence": {},
270925          "signature": {
270926            "signature": {
270927              "publicKey": {}
270928            }
270929          },
270930          "modelCard": {
270931            "modelParameters": {
270932              "approach": {}
270933            },
270934            "quantitativeAnalysis": {
270935              "graphics": {}
270936            },
270937            "considerations": {}
270938          }
270939        },
270940        {
270941          "type": "library",
270942          "bom-ref": "pkg:deb/debian/libgssapi-krb5-2@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=934eca1b2c81a866",
270943          "supplier": {},
270944          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
270945          "name": "libgssapi-krb5-2",
270946          "version": "1.18.3-6+deb11u3",
270947          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
270948          "purl": "pkg:deb/debian/libgssapi-krb5-2@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
270949          "swid": {
270950            "attachment": {}
270951          },
270952          "pedigree": {},
270953          "evidence": {},
270954          "signature": {
270955            "signature": {
270956              "publicKey": {}
270957            }
270958          },
270959          "modelCard": {
270960            "modelParameters": {
270961              "approach": {}
270962            },
270963            "quantitativeAnalysis": {
270964              "graphics": {}
270965            },
270966            "considerations": {}
270967          }
270968        },
270969        {
270970          "type": "library",
270971          "bom-ref": "pkg:deb/debian/libhogweed6@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11\u0026package-id=f6875fb73ea89a12",
270972          "supplier": {},
270973          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
270974          "name": "libhogweed6",
270975          "version": "3.7.3-1",
270976          "cpe": "cpe:2.3:a:libhogweed6:libhogweed6:3.7.3-1:*:*:*:*:*:*:*",
270977          "purl": "pkg:deb/debian/libhogweed6@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11",
270978          "swid": {
270979            "attachment": {}
270980          },
270981          "pedigree": {},
270982          "evidence": {},
270983          "signature": {
270984            "signature": {
270985              "publicKey": {}
270986            }
270987          },
270988          "modelCard": {
270989            "modelParameters": {
270990              "approach": {}
270991            },
270992            "quantitativeAnalysis": {
270993              "graphics": {}
270994            },
270995            "considerations": {}
270996          }
270997        },
270998        {
270999          "type": "library",
271000          "bom-ref": "pkg:deb/debian/libidn2-0@2.3.0-5?arch=amd64\u0026upstream=libidn2\u0026distro=debian-11\u0026package-id=742c5fa2e37418ba",
271001          "supplier": {},
271002          "publisher": "Debian Libidn team \u003chelp-libidn@gnu.org\u003e",
271003          "name": "libidn2-0",
271004          "version": "2.3.0-5",
271005          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.3.0-5:*:*:*:*:*:*:*",
271006          "purl": "pkg:deb/debian/libidn2-0@2.3.0-5?arch=amd64\u0026upstream=libidn2\u0026distro=debian-11",
271007          "swid": {
271008            "attachment": {}
271009          },
271010          "pedigree": {},
271011          "evidence": {},
271012          "signature": {
271013            "signature": {
271014              "publicKey": {}
271015            }
271016          },
271017          "modelCard": {
271018            "modelParameters": {
271019              "approach": {}
271020            },
271021            "quantitativeAnalysis": {
271022              "graphics": {}
271023            },
271024            "considerations": {}
271025          }
271026        },
271027        {
271028          "type": "library",
271029          "bom-ref": "pkg:deb/debian/libk5crypto3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=163ad6c7e8920e2f",
271030          "supplier": {},
271031          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
271032          "name": "libk5crypto3",
271033          "version": "1.18.3-6+deb11u3",
271034          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
271035          "purl": "pkg:deb/debian/libk5crypto3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
271036          "swid": {
271037            "attachment": {}
271038          },
271039          "pedigree": {},
271040          "evidence": {},
271041          "signature": {
271042            "signature": {
271043              "publicKey": {}
271044            }
271045          },
271046          "modelCard": {
271047            "modelParameters": {
271048              "approach": {}
271049            },
271050            "quantitativeAnalysis": {
271051              "graphics": {}
271052            },
271053            "considerations": {}
271054          }
271055        },
271056        {
271057          "type": "library",
271058          "bom-ref": "pkg:deb/debian/libkeyutils1@1.6.1-2?arch=amd64\u0026upstream=keyutils\u0026distro=debian-11\u0026package-id=5210e45c85e35975",
271059          "supplier": {},
271060          "publisher": "Christian Kastner \u003cckk@debian.org\u003e",
271061          "name": "libkeyutils1",
271062          "version": "1.6.1-2",
271063          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6.1-2:*:*:*:*:*:*:*",
271064          "purl": "pkg:deb/debian/libkeyutils1@1.6.1-2?arch=amd64\u0026upstream=keyutils\u0026distro=debian-11",
271065          "swid": {
271066            "attachment": {}
271067          },
271068          "pedigree": {},
271069          "evidence": {},
271070          "signature": {
271071            "signature": {
271072              "publicKey": {}
271073            }
271074          },
271075          "modelCard": {
271076            "modelParameters": {
271077              "approach": {}
271078            },
271079            "quantitativeAnalysis": {
271080              "graphics": {}
271081            },
271082            "considerations": {}
271083          }
271084        },
271085        {
271086          "type": "library",
271087          "bom-ref": "pkg:deb/debian/libkrb5-3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=b7be2a5d0c5273d0",
271088          "supplier": {},
271089          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
271090          "name": "libkrb5-3",
271091          "version": "1.18.3-6+deb11u3",
271092          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
271093          "purl": "pkg:deb/debian/libkrb5-3@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
271094          "swid": {
271095            "attachment": {}
271096          },
271097          "pedigree": {},
271098          "evidence": {},
271099          "signature": {
271100            "signature": {
271101              "publicKey": {}
271102            }
271103          },
271104          "modelCard": {
271105            "modelParameters": {
271106              "approach": {}
271107            },
271108            "quantitativeAnalysis": {
271109              "graphics": {}
271110            },
271111            "considerations": {}
271112          }
271113        },
271114        {
271115          "type": "library",
271116          "bom-ref": "pkg:deb/debian/libkrb5support0@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11\u0026package-id=1b425f24967037f8",
271117          "supplier": {},
271118          "publisher": "Sam Hartman \u003chartmans@debian.org\u003e",
271119          "name": "libkrb5support0",
271120          "version": "1.18.3-6+deb11u3",
271121          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.18.3-6\\+deb11u3:*:*:*:*:*:*:*",
271122          "purl": "pkg:deb/debian/libkrb5support0@1.18.3-6+deb11u3?arch=amd64\u0026upstream=krb5\u0026distro=debian-11",
271123          "swid": {
271124            "attachment": {}
271125          },
271126          "pedigree": {},
271127          "evidence": {},
271128          "signature": {
271129            "signature": {
271130              "publicKey": {}
271131            }
271132          },
271133          "modelCard": {
271134            "modelParameters": {
271135              "approach": {}
271136            },
271137            "quantitativeAnalysis": {
271138              "graphics": {}
271139            },
271140            "considerations": {}
271141          }
271142        },
271143        {
271144          "type": "library",
271145          "bom-ref": "pkg:deb/debian/libldap-2.4-2@2.4.57+dfsg-3+deb11u1?arch=amd64\u0026upstream=openldap\u0026distro=debian-11\u0026package-id=95095bfb4d81b655",
271146          "supplier": {},
271147          "publisher": "Debian OpenLDAP Maintainers \u003cpkg-openldap-devel@lists.alioth.debian.org\u003e",
271148          "name": "libldap-2.4-2",
271149          "version": "2.4.57+dfsg-3+deb11u1",
271150          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.57\\+dfsg-3\\+deb11u1:*:*:*:*:*:*:*",
271151          "purl": "pkg:deb/debian/libldap-2.4-2@2.4.57+dfsg-3+deb11u1?arch=amd64\u0026upstream=openldap\u0026distro=debian-11",
271152          "swid": {
271153            "attachment": {}
271154          },
271155          "pedigree": {},
271156          "evidence": {},
271157          "signature": {
271158            "signature": {
271159              "publicKey": {}
271160            }
271161          },
271162          "modelCard": {
271163            "modelParameters": {
271164              "approach": {}
271165            },
271166            "quantitativeAnalysis": {
271167              "graphics": {}
271168            },
271169            "considerations": {}
271170          }
271171        },
271172        {
271173          "type": "library",
271174          "bom-ref": "pkg:deb/debian/liblz4-1@1.9.3-2?arch=amd64\u0026upstream=lz4\u0026distro=debian-11\u0026package-id=8adf5003e74a859",
271175          "supplier": {},
271176          "publisher": "Nobuhiro Iwamatsu \u003ciwamatsu@debian.org\u003e",
271177          "name": "liblz4-1",
271178          "version": "1.9.3-2",
271179          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.3-2:*:*:*:*:*:*:*",
271180          "purl": "pkg:deb/debian/liblz4-1@1.9.3-2?arch=amd64\u0026upstream=lz4\u0026distro=debian-11",
271181          "swid": {
271182            "attachment": {}
271183          },
271184          "pedigree": {},
271185          "evidence": {},
271186          "signature": {
271187            "signature": {
271188              "publicKey": {}
271189            }
271190          },
271191          "modelCard": {
271192            "modelParameters": {
271193              "approach": {}
271194            },
271195            "quantitativeAnalysis": {
271196              "graphics": {}
271197            },
271198            "considerations": {}
271199          }
271200        },
271201        {
271202          "type": "library",
271203          "bom-ref": "pkg:deb/debian/liblzma5@5.2.5-2.1~deb11u1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-11\u0026package-id=d65da095c33495e",
271204          "supplier": {},
271205          "publisher": "Jonathan Nieder \u003cjrnieder@gmail.com\u003e",
271206          "name": "liblzma5",
271207          "version": "5.2.5-2.1~deb11u1",
271208          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.5-2.1\\~deb11u1:*:*:*:*:*:*:*",
271209          "purl": "pkg:deb/debian/liblzma5@5.2.5-2.1~deb11u1?arch=amd64\u0026upstream=xz-utils\u0026distro=debian-11",
271210          "swid": {
271211            "attachment": {}
271212          },
271213          "pedigree": {},
271214          "evidence": {},
271215          "signature": {
271216            "signature": {
271217              "publicKey": {}
271218            }
271219          },
271220          "modelCard": {
271221            "modelParameters": {
271222              "approach": {}
271223            },
271224            "quantitativeAnalysis": {
271225              "graphics": {}
271226            },
271227            "considerations": {}
271228          }
271229        },
271230        {
271231          "type": "library",
271232          "bom-ref": "pkg:deb/debian/libnettle8@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11\u0026package-id=7e23fb3542638810",
271233          "supplier": {},
271234          "publisher": "Magnus Holmgren \u003cholmgren@debian.org\u003e",
271235          "name": "libnettle8",
271236          "version": "3.7.3-1",
271237          "cpe": "cpe:2.3:a:libnettle8:libnettle8:3.7.3-1:*:*:*:*:*:*:*",
271238          "purl": "pkg:deb/debian/libnettle8@3.7.3-1?arch=amd64\u0026upstream=nettle\u0026distro=debian-11",
271239          "swid": {
271240            "attachment": {}
271241          },
271242          "pedigree": {},
271243          "evidence": {},
271244          "signature": {
271245            "signature": {
271246              "publicKey": {}
271247            }
271248          },
271249          "modelCard": {
271250            "modelParameters": {
271251              "approach": {}
271252            },
271253            "quantitativeAnalysis": {
271254              "graphics": {}
271255            },
271256            "considerations": {}
271257          }
271258        },
271259        {
271260          "type": "library",
271261          "bom-ref": "pkg:deb/debian/libp11-kit0@0.23.22-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-11\u0026package-id=184f52603068dcd6",
271262          "supplier": {},
271263          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
271264          "name": "libp11-kit0",
271265          "version": "0.23.22-1",
271266          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.22-1:*:*:*:*:*:*:*",
271267          "purl": "pkg:deb/debian/libp11-kit0@0.23.22-1?arch=amd64\u0026upstream=p11-kit\u0026distro=debian-11",
271268          "swid": {
271269            "attachment": {}
271270          },
271271          "pedigree": {},
271272          "evidence": {},
271273          "signature": {
271274            "signature": {
271275              "publicKey": {}
271276            }
271277          },
271278          "modelCard": {
271279            "modelParameters": {
271280              "approach": {}
271281            },
271282            "quantitativeAnalysis": {
271283              "graphics": {}
271284            },
271285            "considerations": {}
271286          }
271287        },
271288        {
271289          "type": "library",
271290          "bom-ref": "pkg:deb/debian/libpq5@13.8-0+deb11u1?arch=amd64\u0026upstream=postgresql-13\u0026distro=debian-11\u0026package-id=c5bc819225796bb5",
271291          "supplier": {},
271292          "publisher": "Debian PostgreSQL Maintainers \u003cteam+postgresql@tracker.debian.org\u003e",
271293          "name": "libpq5",
271294          "version": "13.8-0+deb11u1",
271295          "cpe": "cpe:2.3:a:libpq5:libpq5:13.8-0\\+deb11u1:*:*:*:*:*:*:*",
271296          "purl": "pkg:deb/debian/libpq5@13.8-0+deb11u1?arch=amd64\u0026upstream=postgresql-13\u0026distro=debian-11",
271297          "swid": {
271298            "attachment": {}
271299          },
271300          "pedigree": {},
271301          "evidence": {},
271302          "signature": {
271303            "signature": {
271304              "publicKey": {}
271305            }
271306          },
271307          "modelCard": {
271308            "modelParameters": {
271309              "approach": {}
271310            },
271311            "quantitativeAnalysis": {
271312              "graphics": {}
271313            },
271314            "considerations": {}
271315          }
271316        },
271317        {
271318          "type": "library",
271319          "bom-ref": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11\u0026package-id=770be1c1426e93f9",
271320          "supplier": {},
271321          "publisher": "Debian Cyrus Team \u003cteam+cyrus@tracker.debian.org\u003e",
271322          "name": "libsasl2-2",
271323          "version": "2.1.27+dfsg-2.1+deb11u1",
271324          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-2.1\\+deb11u1:*:*:*:*:*:*:*",
271325          "purl": "pkg:deb/debian/libsasl2-2@2.1.27+dfsg-2.1+deb11u1?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=debian-11",
271326          "swid": {
271327            "attachment": {}
271328          },
271329          "pedigree": {},
271330          "evidence": {},
271331          "signature": {
271332            "signature": {
271333              "publicKey": {}
271334            }
271335          },
271336          "modelCard": {
271337            "modelParameters": {
271338              "approach": {}
271339            },
271340            "quantitativeAnalysis": {
271341              "graphics": {}
271342            },
271343            "considerations": {}
271344          }
271345        },
271346        {
271347          "type": "library",
271348          "bom-ref": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u3?arch=amd64\u0026upstream=openssl\u0026distro=debian-11\u0026package-id=cc7cadd9628284e3",
271349          "supplier": {},
271350          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
271351          "name": "libssl1.1",
271352          "version": "1.1.1n-0+deb11u3",
271353          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1n-0\\+deb11u3:*:*:*:*:*:*:*",
271354          "purl": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u3?arch=amd64\u0026upstream=openssl\u0026distro=debian-11",
271355          "swid": {
271356            "attachment": {}
271357          },
271358          "pedigree": {},
271359          "evidence": {},
271360          "signature": {
271361            "signature": {
271362              "publicKey": {}
271363            }
271364          },
271365          "modelCard": {
271366            "modelParameters": {
271367              "approach": {}
271368            },
271369            "quantitativeAnalysis": {
271370              "graphics": {}
271371            },
271372            "considerations": {}
271373          }
271374        },
271375        {
271376          "type": "library",
271377          "bom-ref": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u3?arch=amd64\u0026upstream=openssl\u0026distro=debian-11\u0026package-id=9fe2917c593fd4df",
271378          "supplier": {},
271379          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
271380          "name": "libssl1.1",
271381          "version": "1.1.1n-0+deb11u3",
271382          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1n-0\\+deb11u3:*:*:*:*:*:*:*",
271383          "purl": "pkg:deb/debian/libssl1.1@1.1.1n-0+deb11u3?arch=amd64\u0026upstream=openssl\u0026distro=debian-11",
271384          "swid": {
271385            "attachment": {}
271386          },
271387          "pedigree": {},
271388          "evidence": {},
271389          "signature": {
271390            "signature": {
271391              "publicKey": {}
271392            }
271393          },
271394          "modelCard": {
271395            "modelParameters": {
271396              "approach": {}
271397            },
271398            "quantitativeAnalysis": {
271399              "graphics": {}
271400            },
271401            "considerations": {}
271402          }
271403        },
271404        {
271405          "type": "library",
271406          "bom-ref": "pkg:deb/debian/libstdc++6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11\u0026package-id=f0a0f8c906e2c621",
271407          "supplier": {},
271408          "publisher": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e",
271409          "name": "libstdc++6",
271410          "version": "10.2.1-6",
271411          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.2.1-6:*:*:*:*:*:*:*",
271412          "purl": "pkg:deb/debian/libstdc++6@10.2.1-6?arch=amd64\u0026upstream=gcc-10\u0026distro=debian-11",
271413          "swid": {
271414            "attachment": {}
271415          },
271416          "pedigree": {},
271417          "evidence": {},
271418          "signature": {
271419            "signature": {
271420              "publicKey": {}
271421            }
271422          },
271423          "modelCard": {
271424            "modelParameters": {
271425              "approach": {}
271426            },
271427            "quantitativeAnalysis": {
271428              "graphics": {}
271429            },
271430            "considerations": {}
271431          }
271432        },
271433        {
271434          "type": "library",
271435          "bom-ref": "pkg:deb/debian/libsystemd0@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11\u0026package-id=c7bb0d22fd707d2e",
271436          "supplier": {},
271437          "publisher": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e",
271438          "name": "libsystemd0",
271439          "version": "247.3-7+deb11u1",
271440          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:247.3-7\\+deb11u1:*:*:*:*:*:*:*",
271441          "purl": "pkg:deb/debian/libsystemd0@247.3-7+deb11u1?arch=amd64\u0026upstream=systemd\u0026distro=debian-11",
271442          "swid": {
271443            "attachment": {}
271444          },
271445          "pedigree": {},
271446          "evidence": {},
271447          "signature": {
271448            "signature": {
271449              "publicKey": {}
271450            }
271451          },
271452          "modelCard": {
271453            "modelParameters": {
271454              "approach": {}
271455            },
271456            "quantitativeAnalysis": {
271457              "graphics": {}
271458            },
271459            "considerations": {}
271460          }
271461        },
271462        {
271463          "type": "library",
271464          "bom-ref": "pkg:deb/debian/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=debian-11\u0026package-id=ec9cc001dc839288",
271465          "supplier": {},
271466          "publisher": "Debian GnuTLS Maintainers \u003cpkg-gnutls-maint@lists.alioth.debian.org\u003e",
271467          "name": "libtasn1-6",
271468          "version": "4.16.0-2",
271469          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2:*:*:*:*:*:*:*",
271470          "purl": "pkg:deb/debian/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=debian-11",
271471          "swid": {
271472            "attachment": {}
271473          },
271474          "pedigree": {},
271475          "evidence": {},
271476          "signature": {
271477            "signature": {
271478              "publicKey": {}
271479            }
271480          },
271481          "modelCard": {
271482            "modelParameters": {
271483              "approach": {}
271484            },
271485            "quantitativeAnalysis": {
271486              "graphics": {}
271487            },
271488            "considerations": {}
271489          }
271490        },
271491        {
271492          "type": "library",
271493          "bom-ref": "pkg:deb/debian/libunistring2@0.9.10-4?arch=amd64\u0026upstream=libunistring\u0026distro=debian-11\u0026package-id=88a830d75a1b25bf",
271494          "supplier": {},
271495          "publisher": "Jörg Frings-Fürst \u003cdebian@jff.email\u003e",
271496          "name": "libunistring2",
271497          "version": "0.9.10-4",
271498          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-4:*:*:*:*:*:*:*",
271499          "purl": "pkg:deb/debian/libunistring2@0.9.10-4?arch=amd64\u0026upstream=libunistring\u0026distro=debian-11",
271500          "swid": {
271501            "attachment": {}
271502          },
271503          "pedigree": {},
271504          "evidence": {},
271505          "signature": {
271506            "signature": {
271507              "publicKey": {}
271508            }
271509          },
271510          "modelCard": {
271511            "modelParameters": {
271512              "approach": {}
271513            },
271514            "quantitativeAnalysis": {
271515              "graphics": {}
271516            },
271517            "considerations": {}
271518          }
271519        },
271520        {
271521          "type": "library",
271522          "bom-ref": "pkg:deb/debian/libyaml-0-2@0.2.2-1?arch=amd64\u0026upstream=libyaml\u0026distro=debian-11\u0026package-id=e47482fee132aef7",
271523          "supplier": {},
271524          "publisher": "Anders Kaseorg \u003candersk@mit.edu\u003e",
271525          "name": "libyaml-0-2",
271526          "version": "0.2.2-1",
271527          "cpe": "cpe:2.3:a:libyaml-0-2:libyaml-0-2:0.2.2-1:*:*:*:*:*:*:*",
271528          "purl": "pkg:deb/debian/libyaml-0-2@0.2.2-1?arch=amd64\u0026upstream=libyaml\u0026distro=debian-11",
271529          "swid": {
271530            "attachment": {}
271531          },
271532          "pedigree": {},
271533          "evidence": {},
271534          "signature": {
271535            "signature": {
271536              "publicKey": {}
271537            }
271538          },
271539          "modelCard": {
271540            "modelParameters": {
271541              "approach": {}
271542            },
271543            "quantitativeAnalysis": {
271544              "graphics": {}
271545            },
271546            "considerations": {}
271547          }
271548        },
271549        {
271550          "type": "library",
271551          "bom-ref": "pkg:deb/debian/libzstd1@1.4.8+dfsg-2.1?arch=amd64\u0026upstream=libzstd\u0026distro=debian-11\u0026package-id=ab332bfa1875542b",
271552          "supplier": {},
271553          "publisher": "Debian Med Packaging Team \u003cdebian-med-packaging@lists.alioth.debian.org\u003e",
271554          "name": "libzstd1",
271555          "version": "1.4.8+dfsg-2.1",
271556          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.8\\+dfsg-2.1:*:*:*:*:*:*:*",
271557          "purl": "pkg:deb/debian/libzstd1@1.4.8+dfsg-2.1?arch=amd64\u0026upstream=libzstd\u0026distro=debian-11",
271558          "swid": {
271559            "attachment": {}
271560          },
271561          "pedigree": {},
271562          "evidence": {},
271563          "signature": {
271564            "signature": {
271565              "publicKey": {}
271566            }
271567          },
271568          "modelCard": {
271569            "modelParameters": {
271570              "approach": {}
271571            },
271572            "quantitativeAnalysis": {
271573              "graphics": {}
271574            },
271575            "considerations": {}
271576          }
271577        },
271578        {
271579          "type": "library",
271580          "bom-ref": "pkg:deb/debian/netbase@6.3?arch=all\u0026distro=debian-11\u0026package-id=fdbf312837579aa",
271581          "supplier": {},
271582          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
271583          "name": "netbase",
271584          "version": "6.3",
271585          "licenses": [
271586            {
271587              "license": {
271588                "id": "GPL-2.0-only"
271589              }
271590            }
271591          ],
271592          "cpe": "cpe:2.3:a:netbase:netbase:6.3:*:*:*:*:*:*:*",
271593          "purl": "pkg:deb/debian/netbase@6.3?arch=all\u0026distro=debian-11",
271594          "swid": {
271595            "attachment": {}
271596          },
271597          "pedigree": {},
271598          "evidence": {},
271599          "signature": {
271600            "signature": {
271601              "publicKey": {}
271602            }
271603          },
271604          "modelCard": {
271605            "modelParameters": {
271606              "approach": {}
271607            },
271608            "quantitativeAnalysis": {
271609              "graphics": {}
271610            },
271611            "considerations": {}
271612          }
271613        },
271614        {
271615          "type": "library",
271616          "bom-ref": "pkg:deb/debian/openssl@1.1.1n-0+deb11u3?arch=amd64\u0026distro=debian-11\u0026package-id=cba49180f2456de6",
271617          "supplier": {},
271618          "publisher": "Debian OpenSSL Team \u003cpkg-openssl-devel@lists.alioth.debian.org\u003e",
271619          "name": "openssl",
271620          "version": "1.1.1n-0+deb11u3",
271621          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1n-0\\+deb11u3:*:*:*:*:*:*:*",
271622          "purl": "pkg:deb/debian/openssl@1.1.1n-0+deb11u3?arch=amd64\u0026distro=debian-11",
271623          "swid": {
271624            "attachment": {}
271625          },
271626          "pedigree": {},
271627          "evidence": {},
271628          "signature": {
271629            "signature": {
271630              "publicKey": {}
271631            }
271632          },
271633          "modelCard": {
271634            "modelParameters": {
271635              "approach": {}
271636            },
271637            "quantitativeAnalysis": {
271638              "graphics": {}
271639            },
271640            "considerations": {}
271641          }
271642        },
271643        {
271644          "type": "library",
271645          "bom-ref": "pkg:deb/debian/pkg-config@0.29.2-1?arch=amd64\u0026distro=debian-11\u0026package-id=52f98f355dc272b4",
271646          "supplier": {},
271647          "publisher": "Tollef Fog Heen \u003ctfheen@debian.org\u003e",
271648          "name": "pkg-config",
271649          "version": "0.29.2-1",
271650          "cpe": "cpe:2.3:a:pkg-config:pkg-config:0.29.2-1:*:*:*:*:*:*:*",
271651          "purl": "pkg:deb/debian/pkg-config@0.29.2-1?arch=amd64\u0026distro=debian-11",
271652          "swid": {
271653            "attachment": {}
271654          },
271655          "pedigree": {},
271656          "evidence": {},
271657          "signature": {
271658            "signature": {
271659              "publicKey": {}
271660            }
271661          },
271662          "modelCard": {
271663            "modelParameters": {
271664              "approach": {}
271665            },
271666            "quantitativeAnalysis": {
271667              "graphics": {}
271668            },
271669            "considerations": {}
271670          }
271671        },
271672        {
271673          "type": "library",
271674          "bom-ref": "pkg:deb/debian/tzdata@2021a-1+deb11u8?arch=all\u0026distro=debian-11\u0026package-id=353681e57b634ada",
271675          "supplier": {},
271676          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
271677          "name": "tzdata",
271678          "version": "2021a-1+deb11u8",
271679          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-1\\+deb11u8:*:*:*:*:*:*:*",
271680          "purl": "pkg:deb/debian/tzdata@2021a-1+deb11u8?arch=all\u0026distro=debian-11",
271681          "swid": {
271682            "attachment": {}
271683          },
271684          "pedigree": {},
271685          "evidence": {},
271686          "signature": {
271687            "signature": {
271688              "publicKey": {}
271689            }
271690          },
271691          "modelCard": {
271692            "modelParameters": {
271693              "approach": {}
271694            },
271695            "quantitativeAnalysis": {
271696              "graphics": {}
271697            },
271698            "considerations": {}
271699          }
271700        },
271701        {
271702          "type": "library",
271703          "bom-ref": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-2+deb11u2?arch=amd64\u0026upstream=zlib\u0026distro=debian-11\u0026package-id=f6e0ab41c080f2fb",
271704          "supplier": {},
271705          "publisher": "Mark Brown \u003cbroonie@debian.org\u003e",
271706          "name": "zlib1g",
271707          "version": "1:1.2.11.dfsg-2+deb11u2",
271708          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2\\+deb11u2:*:*:*:*:*:*:*",
271709          "purl": "pkg:deb/debian/zlib1g@1:1.2.11.dfsg-2+deb11u2?arch=amd64\u0026upstream=zlib\u0026distro=debian-11",
271710          "swid": {
271711            "attachment": {}
271712          },
271713          "pedigree": {},
271714          "evidence": {},
271715          "signature": {
271716            "signature": {
271717              "publicKey": {}
271718            }
271719          },
271720          "modelCard": {
271721            "modelParameters": {
271722              "approach": {}
271723            },
271724            "quantitativeAnalysis": {
271725              "graphics": {}
271726            },
271727            "considerations": {}
271728          }
271729        },
271730        {
271731          "type": "operating-system",
271732          "supplier": {},
271733          "name": "debian",
271734          "version": "11",
271735          "description": "Distroless",
271736          "swid": {
271737            "tagId": "debian",
271738            "name": "debian",
271739            "version": "11",
271740            "attachment": {}
271741          },
271742          "pedigree": {},
271743          "externalReferences": [
271744            {
271745              "url": "https://github.com/GoogleContainerTools/distroless/issues/new",
271746              "type": "issue-tracker"
271747            },
271748            {
271749              "url": "https://github.com/GoogleContainerTools/distroless",
271750              "type": "website"
271751            },
271752            {
271753              "url": "https://github.com/GoogleContainerTools/distroless/blob/master/README.md",
271754              "comment": "support",
271755              "type": "other"
271756            }
271757          ],
271758          "evidence": {},
271759          "signature": {
271760            "signature": {
271761              "publicKey": {}
271762            }
271763          },
271764          "modelCard": {
271765            "modelParameters": {
271766              "approach": {}
271767            },
271768            "quantitativeAnalysis": {
271769              "graphics": {}
271770            },
271771            "considerations": {}
271772          }
271773        },
271774        {
271775          "type": "library",
271776          "bom-ref": "pkg:pypi/pynacl@1.4.0?package-id=6a95d529d7ec5789",
271777          "supplier": {},
271778          "author": "The PyNaCl developers \u003ccryptography-dev@python.org\u003e",
271779          "name": "PyNaCl",
271780          "version": "1.4.0",
271781          "licenses": [
271782            {
271783              "license": {
271784                "name": "Apache License 2.0"
271785              }
271786            }
271787          ],
271788          "cpe": "cpe:2.3:a:pynacl_developers_project:python-PyNaCl:1.4.0:*:*:*:*:*:*:*",
271789          "purl": "pkg:pypi/PyNaCl@1.4.0",
271790          "swid": {
271791            "attachment": {}
271792          },
271793          "pedigree": {},
271794          "externalReferences": [
271795            {
271796              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/cc/00/90/ef78796a9e7a492642aaf74b0c6d2759eef89decf7e3fc2221/PyNaCl-1.4.0-cp39-cp39-linux_x86_64.whl",
271797              "type": "vcs"
271798            }
271799          ],
271800          "evidence": {},
271801          "signature": {
271802            "signature": {
271803              "publicKey": {}
271804            }
271805          },
271806          "modelCard": {
271807            "modelParameters": {
271808              "approach": {}
271809            },
271810            "quantitativeAnalysis": {
271811              "graphics": {}
271812            },
271813            "considerations": {}
271814          }
271815        },
271816        {
271817          "type": "library",
271818          "bom-ref": "pkg:pypi/pyyaml@6.0?package-id=28b02e3a891344ca",
271819          "supplier": {},
271820          "author": "Kirill Simonov \u003cxi@resolvent.net\u003e",
271821          "name": "PyYAML",
271822          "version": "6.0",
271823          "licenses": [
271824            {
271825              "license": {
271826                "id": "MIT"
271827              }
271828            }
271829          ],
271830          "cpe": "cpe:2.3:a:kirill_simonov_project:python-PyYAML:6.0:*:*:*:*:*:*:*",
271831          "purl": "pkg:pypi/PyYAML@6.0",
271832          "swid": {
271833            "attachment": {}
271834          },
271835          "pedigree": {},
271836          "externalReferences": [
271837            {
271838              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/84/6b/7a/345964be4a602a502c5d16f126be67047adf2ec55b7e80bda6/PyYAML-6.0-cp39-cp39-linux_x86_64.whl",
271839              "type": "vcs"
271840            }
271841          ],
271842          "evidence": {},
271843          "signature": {
271844            "signature": {
271845              "publicKey": {}
271846            }
271847          },
271848          "modelCard": {
271849            "modelParameters": {
271850              "approach": {}
271851            },
271852            "quantitativeAnalysis": {
271853              "graphics": {}
271854            },
271855            "considerations": {}
271856          }
271857        },
271858        {
271859          "type": "library",
271860          "bom-ref": "pkg:rpm/ol/audit-libs@3.0.7-4.el8?arch=x86_64\u0026upstream=audit-3.0.7-4.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=72d440769b4fc89f",
271861          "supplier": {},
271862          "publisher": "Oracle America",
271863          "name": "audit-libs",
271864          "version": "3.0.7-4.el8",
271865          "licenses": [
271866            {
271867              "license": {
271868                "name": "LGPLv2+"
271869              }
271870            }
271871          ],
271872          "cpe": "cpe:2.3:a:oracleamerica:audit-libs:3.0.7-4.el8:*:*:*:*:*:*:*",
271873          "purl": "pkg:rpm/ol/audit-libs@3.0.7-4.el8?arch=x86_64\u0026upstream=audit-3.0.7-4.el8.src.rpm\u0026distro=ol-8.7",
271874          "swid": {
271875            "attachment": {}
271876          },
271877          "pedigree": {},
271878          "evidence": {},
271879          "signature": {
271880            "signature": {
271881              "publicKey": {}
271882            }
271883          },
271884          "modelCard": {
271885            "modelParameters": {
271886              "approach": {}
271887            },
271888            "quantitativeAnalysis": {
271889              "graphics": {}
271890            },
271891            "considerations": {}
271892          }
271893        },
271894        {
271895          "type": "library",
271896          "bom-ref": "pkg:rpm/ol/basesystem@11-5.el8?arch=noarch\u0026upstream=basesystem-11-5.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=1e5af1bf1a956925",
271897          "supplier": {},
271898          "publisher": "Oracle America",
271899          "name": "basesystem",
271900          "version": "11-5.el8",
271901          "licenses": [
271902            {
271903              "license": {
271904                "name": "Public Domain"
271905              }
271906            }
271907          ],
271908          "cpe": "cpe:2.3:a:oracleamerica:basesystem:11-5.el8:*:*:*:*:*:*:*",
271909          "purl": "pkg:rpm/ol/basesystem@11-5.el8?arch=noarch\u0026upstream=basesystem-11-5.el8.src.rpm\u0026distro=ol-8.7",
271910          "swid": {
271911            "attachment": {}
271912          },
271913          "pedigree": {},
271914          "evidence": {},
271915          "signature": {
271916            "signature": {
271917              "publicKey": {}
271918            }
271919          },
271920          "modelCard": {
271921            "modelParameters": {
271922              "approach": {}
271923            },
271924            "quantitativeAnalysis": {
271925              "graphics": {}
271926            },
271927            "considerations": {}
271928          }
271929        },
271930        {
271931          "type": "library",
271932          "bom-ref": "pkg:rpm/ol/bash@4.4.20-4.el8_6?arch=x86_64\u0026upstream=bash-4.4.20-4.el8_6.src.rpm\u0026distro=ol-8.7\u0026package-id=97279da901f8ca4d",
271933          "supplier": {},
271934          "publisher": "Oracle America",
271935          "name": "bash",
271936          "version": "4.4.20-4.el8_6",
271937          "licenses": [
271938            {
271939              "license": {
271940                "name": "GPLv3+"
271941              }
271942            }
271943          ],
271944          "cpe": "cpe:2.3:a:oracleamerica:bash:4.4.20-4.el8_6:*:*:*:*:*:*:*",
271945          "purl": "pkg:rpm/ol/bash@4.4.20-4.el8_6?arch=x86_64\u0026upstream=bash-4.4.20-4.el8_6.src.rpm\u0026distro=ol-8.7",
271946          "swid": {
271947            "attachment": {}
271948          },
271949          "pedigree": {},
271950          "evidence": {},
271951          "signature": {
271952            "signature": {
271953              "publicKey": {}
271954            }
271955          },
271956          "modelCard": {
271957            "modelParameters": {
271958              "approach": {}
271959            },
271960            "quantitativeAnalysis": {
271961              "graphics": {}
271962            },
271963            "considerations": {}
271964          }
271965        },
271966        {
271967          "type": "library",
271968          "bom-ref": "pkg:pypi/bcrypt@3.2.2?package-id=e79c0d5020b0364d",
271969          "supplier": {},
271970          "author": "The Python Cryptographic Authority developers \u003ccryptography-dev@python.org\u003e",
271971          "name": "bcrypt",
271972          "version": "3.2.2",
271973          "licenses": [
271974            {
271975              "license": {
271976                "name": "Apache License, Version 2.0"
271977              }
271978            }
271979          ],
271980          "cpe": "cpe:2.3:a:python_cryptographic_authority_developers_project:python-bcrypt:3.2.2:*:*:*:*:*:*:*",
271981          "purl": "pkg:pypi/bcrypt@3.2.2",
271982          "swid": {
271983            "attachment": {}
271984          },
271985          "pedigree": {},
271986          "externalReferences": [
271987            {
271988              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/82/c7/41/3adc9e77f41856f1b7db31df8d5dd050e344407ddac232f9b3/bcrypt-3.2.2-cp39-cp39-linux_x86_64.whl",
271989              "type": "vcs"
271990            }
271991          ],
271992          "evidence": {},
271993          "signature": {
271994            "signature": {
271995              "publicKey": {}
271996            }
271997          },
271998          "modelCard": {
271999            "modelParameters": {
272000              "approach": {}
272001            },
272002            "quantitativeAnalysis": {
272003              "graphics": {}
272004            },
272005            "considerations": {}
272006          }
272007        },
272008        {
272009          "type": "library",
272010          "bom-ref": "pkg:rpm/ol/brotli@1.0.6-3.el8?arch=x86_64\u0026upstream=brotli-1.0.6-3.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=38fe1d3e6e44c60d",
272011          "supplier": {},
272012          "publisher": "Oracle America",
272013          "name": "brotli",
272014          "version": "1.0.6-3.el8",
272015          "licenses": [
272016            {
272017              "license": {
272018                "id": "MIT"
272019              }
272020            }
272021          ],
272022          "cpe": "cpe:2.3:a:oracleamerica:brotli:1.0.6-3.el8:*:*:*:*:*:*:*",
272023          "purl": "pkg:rpm/ol/brotli@1.0.6-3.el8?arch=x86_64\u0026upstream=brotli-1.0.6-3.el8.src.rpm\u0026distro=ol-8.7",
272024          "swid": {
272025            "attachment": {}
272026          },
272027          "pedigree": {},
272028          "evidence": {},
272029          "signature": {
272030            "signature": {
272031              "publicKey": {}
272032            }
272033          },
272034          "modelCard": {
272035            "modelParameters": {
272036              "approach": {}
272037            },
272038            "quantitativeAnalysis": {
272039              "graphics": {}
272040            },
272041            "considerations": {}
272042          }
272043        },
272044        {
272045          "type": "library",
272046          "bom-ref": "pkg:rpm/ol/bzip2@1.0.6-26.el8?arch=x86_64\u0026upstream=bzip2-1.0.6-26.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=41333bf009bf2a5c",
272047          "supplier": {},
272048          "publisher": "Oracle America",
272049          "name": "bzip2",
272050          "version": "1.0.6-26.el8",
272051          "licenses": [
272052            {
272053              "license": {
272054                "name": "BSD"
272055              }
272056            }
272057          ],
272058          "cpe": "cpe:2.3:a:oracleamerica:bzip2:1.0.6-26.el8:*:*:*:*:*:*:*",
272059          "purl": "pkg:rpm/ol/bzip2@1.0.6-26.el8?arch=x86_64\u0026upstream=bzip2-1.0.6-26.el8.src.rpm\u0026distro=ol-8.7",
272060          "swid": {
272061            "attachment": {}
272062          },
272063          "pedigree": {},
272064          "evidence": {},
272065          "signature": {
272066            "signature": {
272067              "publicKey": {}
272068            }
272069          },
272070          "modelCard": {
272071            "modelParameters": {
272072              "approach": {}
272073            },
272074            "quantitativeAnalysis": {
272075              "graphics": {}
272076            },
272077            "considerations": {}
272078          }
272079        },
272080        {
272081          "type": "library",
272082          "bom-ref": "pkg:rpm/ol/bzip2-libs@1.0.6-26.el8?arch=x86_64\u0026upstream=bzip2-1.0.6-26.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=d402bb048f15a4e5",
272083          "supplier": {},
272084          "publisher": "Oracle America",
272085          "name": "bzip2-libs",
272086          "version": "1.0.6-26.el8",
272087          "licenses": [
272088            {
272089              "license": {
272090                "name": "BSD"
272091              }
272092            }
272093          ],
272094          "cpe": "cpe:2.3:a:oracleamerica:bzip2-libs:1.0.6-26.el8:*:*:*:*:*:*:*",
272095          "purl": "pkg:rpm/ol/bzip2-libs@1.0.6-26.el8?arch=x86_64\u0026upstream=bzip2-1.0.6-26.el8.src.rpm\u0026distro=ol-8.7",
272096          "swid": {
272097            "attachment": {}
272098          },
272099          "pedigree": {},
272100          "evidence": {},
272101          "signature": {
272102            "signature": {
272103              "publicKey": {}
272104            }
272105          },
272106          "modelCard": {
272107            "modelParameters": {
272108              "approach": {}
272109            },
272110            "quantitativeAnalysis": {
272111              "graphics": {}
272112            },
272113            "considerations": {}
272114          }
272115        },
272116        {
272117          "type": "library",
272118          "bom-ref": "pkg:rpm/ol/ca-certificates@2022.2.54-80.2.el8_6?arch=noarch\u0026upstream=ca-certificates-2022.2.54-80.2.el8_6.src.rpm\u0026distro=ol-8.7\u0026package-id=c03be3db2a449eb4",
272119          "supplier": {},
272120          "publisher": "Oracle America",
272121          "name": "ca-certificates",
272122          "version": "2022.2.54-80.2.el8_6",
272123          "licenses": [
272124            {
272125              "license": {
272126                "name": "Public Domain"
272127              }
272128            }
272129          ],
272130          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:2022.2.54-80.2.el8_6:*:*:*:*:*:*:*",
272131          "purl": "pkg:rpm/ol/ca-certificates@2022.2.54-80.2.el8_6?arch=noarch\u0026upstream=ca-certificates-2022.2.54-80.2.el8_6.src.rpm\u0026distro=ol-8.7",
272132          "swid": {
272133            "attachment": {}
272134          },
272135          "pedigree": {},
272136          "evidence": {},
272137          "signature": {
272138            "signature": {
272139              "publicKey": {}
272140            }
272141          },
272142          "modelCard": {
272143            "modelParameters": {
272144              "approach": {}
272145            },
272146            "quantitativeAnalysis": {
272147              "graphics": {}
272148            },
272149            "considerations": {}
272150          }
272151        },
272152        {
272153          "type": "library",
272154          "bom-ref": "pkg:pypi/certifi@2022.12.7?package-id=5da3481ce07f8998",
272155          "supplier": {},
272156          "author": "Kenneth Reitz \u003cme@kennethreitz.com\u003e",
272157          "name": "certifi",
272158          "version": "2022.12.7",
272159          "licenses": [
272160            {
272161              "license": {
272162                "id": "MPL-2.0"
272163              }
272164            }
272165          ],
272166          "cpe": "cpe:2.3:a:kenneth_reitz_project:python-certifi:2022.12.7:*:*:*:*:*:*:*",
272167          "purl": "pkg:pypi/certifi@2022.12.7",
272168          "swid": {
272169            "attachment": {}
272170          },
272171          "pedigree": {},
272172          "externalReferences": [
272173            {
272174              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/dc/0e/84/89514a3ad2036e12ac0886723fb2f4d89f8ba76aefec8dce2f/certifi-2022.12.7-py3-none-any.whl",
272175              "type": "vcs"
272176            }
272177          ],
272178          "evidence": {},
272179          "signature": {
272180            "signature": {
272181              "publicKey": {}
272182            }
272183          },
272184          "modelCard": {
272185            "modelParameters": {
272186              "approach": {}
272187            },
272188            "quantitativeAnalysis": {
272189              "graphics": {}
272190            },
272191            "considerations": {}
272192          }
272193        },
272194        {
272195          "type": "library",
272196          "bom-ref": "pkg:pypi/cffi@1.15.1?package-id=2f0ee0e0b9aafaf0",
272197          "supplier": {},
272198          "author": "Armin Rigo, Maciej Fijalkowski \u003cpython-cffi@googlegroups.com\u003e",
272199          "name": "cffi",
272200          "version": "1.15.1",
272201          "licenses": [
272202            {
272203              "license": {
272204                "id": "MIT"
272205              }
272206            }
272207          ],
272208          "cpe": "cpe:2.3:a:armin_rigo\\,_maciej_fijalkowski_project:python-cffi:1.15.1:*:*:*:*:*:*:*",
272209          "purl": "pkg:pypi/cffi@1.15.1",
272210          "swid": {
272211            "attachment": {}
272212          },
272213          "pedigree": {},
272214          "externalReferences": [
272215            {
272216              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/73/fe/16/c42d972e7e7e450c9cfbb51fc5c77239ec1a674f2fdad9167a/cffi-1.15.1-cp39-cp39-linux_x86_64.whl",
272217              "type": "vcs"
272218            }
272219          ],
272220          "evidence": {},
272221          "signature": {
272222            "signature": {
272223              "publicKey": {}
272224            }
272225          },
272226          "modelCard": {
272227            "modelParameters": {
272228              "approach": {}
272229            },
272230            "quantitativeAnalysis": {
272231              "graphics": {}
272232            },
272233            "considerations": {}
272234          }
272235        },
272236        {
272237          "type": "library",
272238          "bom-ref": "pkg:rpm/ol/chkconfig@1.19.1-1.0.1.el8?arch=x86_64\u0026upstream=chkconfig-1.19.1-1.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=7a246beb95abafdb",
272239          "supplier": {},
272240          "publisher": "Oracle America",
272241          "name": "chkconfig",
272242          "version": "1.19.1-1.0.1.el8",
272243          "licenses": [
272244            {
272245              "license": {
272246                "name": "GPLv2"
272247              }
272248            }
272249          ],
272250          "cpe": "cpe:2.3:a:oracleamerica:chkconfig:1.19.1-1.0.1.el8:*:*:*:*:*:*:*",
272251          "purl": "pkg:rpm/ol/chkconfig@1.19.1-1.0.1.el8?arch=x86_64\u0026upstream=chkconfig-1.19.1-1.0.1.el8.src.rpm\u0026distro=ol-8.7",
272252          "swid": {
272253            "attachment": {}
272254          },
272255          "pedigree": {},
272256          "evidence": {},
272257          "signature": {
272258            "signature": {
272259              "publicKey": {}
272260            }
272261          },
272262          "modelCard": {
272263            "modelParameters": {
272264              "approach": {}
272265            },
272266            "quantitativeAnalysis": {
272267              "graphics": {}
272268            },
272269            "considerations": {}
272270          }
272271        },
272272        {
272273          "type": "library",
272274          "bom-ref": "pkg:pypi/circuitbreaker@1.4.0?package-id=cf5c41ed652728da",
272275          "supplier": {},
272276          "author": "Fabian Fuelling \u003cpypi@fabfuel.de\u003e",
272277          "name": "circuitbreaker",
272278          "version": "1.4.0",
272279          "licenses": [
272280            {
272281              "license": {
272282                "id": "BSD-3-Clause"
272283              }
272284            }
272285          ],
272286          "cpe": "cpe:2.3:a:fabian_fuelling_project:python-circuitbreaker:1.4.0:*:*:*:*:*:*:*",
272287          "purl": "pkg:pypi/circuitbreaker@1.4.0",
272288          "swid": {
272289            "attachment": {}
272290          },
272291          "pedigree": {},
272292          "externalReferences": [
272293            {
272294              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/95/50/c0/04ebbea6ff75a6482af2ad0241be2a795a7d00b4cd6863f76e/circuitbreaker-1.4.0-py3-none-any.whl",
272295              "type": "vcs"
272296            }
272297          ],
272298          "evidence": {},
272299          "signature": {
272300            "signature": {
272301              "publicKey": {}
272302            }
272303          },
272304          "modelCard": {
272305            "modelParameters": {
272306              "approach": {}
272307            },
272308            "quantitativeAnalysis": {
272309              "graphics": {}
272310            },
272311            "considerations": {}
272312          }
272313        },
272314        {
272315          "type": "library",
272316          "bom-ref": "pkg:rpm/ol/coreutils-single@8.30-13.0.1.el8?arch=x86_64\u0026upstream=coreutils-8.30-13.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=6921e1f650e2fff6",
272317          "supplier": {},
272318          "publisher": "Oracle America",
272319          "name": "coreutils-single",
272320          "version": "8.30-13.0.1.el8",
272321          "licenses": [
272322            {
272323              "license": {
272324                "name": "GPLv3+"
272325              }
272326            }
272327          ],
272328          "cpe": "cpe:2.3:a:coreutils-single:coreutils-single:8.30-13.0.1.el8:*:*:*:*:*:*:*",
272329          "purl": "pkg:rpm/ol/coreutils-single@8.30-13.0.1.el8?arch=x86_64\u0026upstream=coreutils-8.30-13.0.1.el8.src.rpm\u0026distro=ol-8.7",
272330          "swid": {
272331            "attachment": {}
272332          },
272333          "pedigree": {},
272334          "evidence": {},
272335          "signature": {
272336            "signature": {
272337              "publicKey": {}
272338            }
272339          },
272340          "modelCard": {
272341            "modelParameters": {
272342              "approach": {}
272343            },
272344            "quantitativeAnalysis": {
272345              "graphics": {}
272346            },
272347            "considerations": {}
272348          }
272349        },
272350        {
272351          "type": "library",
272352          "bom-ref": "pkg:rpm/ol/crypto-policies@20211116-1.gitae470d6.el8?arch=noarch\u0026upstream=crypto-policies-20211116-1.gitae470d6.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=af518f988ecc36d3",
272353          "supplier": {},
272354          "publisher": "Oracle America",
272355          "name": "crypto-policies",
272356          "version": "20211116-1.gitae470d6.el8",
272357          "licenses": [
272358            {
272359              "license": {
272360                "name": "LGPLv2+"
272361              }
272362            }
272363          ],
272364          "cpe": "cpe:2.3:a:crypto-policies:crypto-policies:20211116-1.gitae470d6.el8:*:*:*:*:*:*:*",
272365          "purl": "pkg:rpm/ol/crypto-policies@20211116-1.gitae470d6.el8?arch=noarch\u0026upstream=crypto-policies-20211116-1.gitae470d6.el8.src.rpm\u0026distro=ol-8.7",
272366          "swid": {
272367            "attachment": {}
272368          },
272369          "pedigree": {},
272370          "evidence": {},
272371          "signature": {
272372            "signature": {
272373              "publicKey": {}
272374            }
272375          },
272376          "modelCard": {
272377            "modelParameters": {
272378              "approach": {}
272379            },
272380            "quantitativeAnalysis": {
272381              "graphics": {}
272382            },
272383            "considerations": {}
272384          }
272385        },
272386        {
272387          "type": "library",
272388          "bom-ref": "pkg:pypi/cryptography@38.0.4?package-id=863ec3e60660431",
272389          "supplier": {},
272390          "author": "The Python Cryptographic Authority and individual contributors \u003ccryptography-dev@python.org\u003e",
272391          "name": "cryptography",
272392          "version": "38.0.4",
272393          "licenses": [
272394            {
272395              "license": {
272396                "name": "BSD-3-Clause OR Apache-2.0"
272397              }
272398            }
272399          ],
272400          "cpe": "cpe:2.3:a:python_cryptographic_authority_and_individual_contributors_project:python-cryptography:38.0.4:*:*:*:*:*:*:*",
272401          "purl": "pkg:pypi/cryptography@38.0.4",
272402          "swid": {
272403            "attachment": {}
272404          },
272405          "pedigree": {},
272406          "externalReferences": [
272407            {
272408              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/bb/f3/07/5cb7a2af9be33b679dcc0f8444961074085140e939bb9dee82/cryptography-38.0.4-cp39-cp39-linux_x86_64.whl",
272409              "type": "vcs"
272410            }
272411          ],
272412          "evidence": {},
272413          "signature": {
272414            "signature": {
272415              "publicKey": {}
272416            }
272417          },
272418          "modelCard": {
272419            "modelParameters": {
272420              "approach": {}
272421            },
272422            "quantitativeAnalysis": {
272423              "graphics": {}
272424            },
272425            "considerations": {}
272426          }
272427        },
272428        {
272429          "type": "library",
272430          "bom-ref": "pkg:rpm/ol/curl@7.61.1-25.el8_7.3?arch=x86_64\u0026upstream=curl-7.61.1-25.el8_7.3.src.rpm\u0026distro=ol-8.7\u0026package-id=93373e170c6ee494",
272431          "supplier": {},
272432          "publisher": "Oracle America",
272433          "name": "curl",
272434          "version": "7.61.1-25.el8_7.3",
272435          "licenses": [
272436            {
272437              "license": {
272438                "id": "MIT"
272439              }
272440            }
272441          ],
272442          "cpe": "cpe:2.3:a:oracleamerica:curl:7.61.1-25.el8_7.3:*:*:*:*:*:*:*",
272443          "purl": "pkg:rpm/ol/curl@7.61.1-25.el8_7.3?arch=x86_64\u0026upstream=curl-7.61.1-25.el8_7.3.src.rpm\u0026distro=ol-8.7",
272444          "swid": {
272445            "attachment": {}
272446          },
272447          "pedigree": {},
272448          "evidence": {},
272449          "signature": {
272450            "signature": {
272451              "publicKey": {}
272452            }
272453          },
272454          "modelCard": {
272455            "modelParameters": {
272456              "approach": {}
272457            },
272458            "quantitativeAnalysis": {
272459              "graphics": {}
272460            },
272461            "considerations": {}
272462          }
272463        },
272464        {
272465          "type": "library",
272466          "bom-ref": "pkg:rpm/ol/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64\u0026upstream=cyrus-sasl-2.1.27-6.el8_5.src.rpm\u0026distro=ol-8.7\u0026package-id=666d92486a364948",
272467          "supplier": {},
272468          "publisher": "Oracle America",
272469          "name": "cyrus-sasl-lib",
272470          "version": "2.1.27-6.el8_5",
272471          "licenses": [
272472            {
272473              "license": {
272474                "name": "BSD with advertising"
272475              }
272476            }
272477          ],
272478          "cpe": "cpe:2.3:a:cyrus-sasl-lib:cyrus-sasl-lib:2.1.27-6.el8_5:*:*:*:*:*:*:*",
272479          "purl": "pkg:rpm/ol/cyrus-sasl-lib@2.1.27-6.el8_5?arch=x86_64\u0026upstream=cyrus-sasl-2.1.27-6.el8_5.src.rpm\u0026distro=ol-8.7",
272480          "swid": {
272481            "attachment": {}
272482          },
272483          "pedigree": {},
272484          "evidence": {},
272485          "signature": {
272486            "signature": {
272487              "publicKey": {}
272488            }
272489          },
272490          "modelCard": {
272491            "modelParameters": {
272492              "approach": {}
272493            },
272494            "quantitativeAnalysis": {
272495              "graphics": {}
272496            },
272497            "considerations": {}
272498          }
272499        },
272500        {
272501          "type": "library",
272502          "bom-ref": "pkg:rpm/ol/elfutils-libelf@0.187-4.el8?arch=x86_64\u0026upstream=elfutils-0.187-4.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=c8d0b08a66c7d941",
272503          "supplier": {},
272504          "publisher": "Oracle America",
272505          "name": "elfutils-libelf",
272506          "version": "0.187-4.el8",
272507          "licenses": [
272508            {
272509              "license": {
272510                "name": "GPLv2+ or LGPLv3+"
272511              }
272512            }
272513          ],
272514          "cpe": "cpe:2.3:a:elfutils-libelf:elfutils-libelf:0.187-4.el8:*:*:*:*:*:*:*",
272515          "purl": "pkg:rpm/ol/elfutils-libelf@0.187-4.el8?arch=x86_64\u0026upstream=elfutils-0.187-4.el8.src.rpm\u0026distro=ol-8.7",
272516          "swid": {
272517            "attachment": {}
272518          },
272519          "pedigree": {},
272520          "evidence": {},
272521          "signature": {
272522            "signature": {
272523              "publicKey": {}
272524            }
272525          },
272526          "modelCard": {
272527            "modelParameters": {
272528              "approach": {}
272529            },
272530            "quantitativeAnalysis": {
272531              "graphics": {}
272532            },
272533            "considerations": {}
272534          }
272535        },
272536        {
272537          "type": "library",
272538          "bom-ref": "pkg:rpm/ol/expat@2.2.5-10.0.1.el8_7.1?arch=x86_64\u0026upstream=expat-2.2.5-10.0.1.el8_7.1.src.rpm\u0026distro=ol-8.7\u0026package-id=7c3625052ee3f0a2",
272539          "supplier": {},
272540          "publisher": "Oracle America",
272541          "name": "expat",
272542          "version": "2.2.5-10.0.1.el8_7.1",
272543          "licenses": [
272544            {
272545              "license": {
272546                "id": "MIT"
272547              }
272548            }
272549          ],
272550          "cpe": "cpe:2.3:a:oracleamerica:expat:2.2.5-10.0.1.el8_7.1:*:*:*:*:*:*:*",
272551          "purl": "pkg:rpm/ol/expat@2.2.5-10.0.1.el8_7.1?arch=x86_64\u0026upstream=expat-2.2.5-10.0.1.el8_7.1.src.rpm\u0026distro=ol-8.7",
272552          "swid": {
272553            "attachment": {}
272554          },
272555          "pedigree": {},
272556          "evidence": {},
272557          "signature": {
272558            "signature": {
272559              "publicKey": {}
272560            }
272561          },
272562          "modelCard": {
272563            "modelParameters": {
272564              "approach": {}
272565            },
272566            "quantitativeAnalysis": {
272567              "graphics": {}
272568            },
272569            "considerations": {}
272570          }
272571        },
272572        {
272573          "type": "library",
272574          "bom-ref": "pkg:rpm/ol/file-libs@5.33-21.el8?arch=x86_64\u0026upstream=file-5.33-21.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=3bbde9dce6d295f5",
272575          "supplier": {},
272576          "publisher": "Oracle America",
272577          "name": "file-libs",
272578          "version": "5.33-21.el8",
272579          "licenses": [
272580            {
272581              "license": {
272582                "name": "BSD"
272583              }
272584            }
272585          ],
272586          "cpe": "cpe:2.3:a:oracleamerica:file-libs:5.33-21.el8:*:*:*:*:*:*:*",
272587          "purl": "pkg:rpm/ol/file-libs@5.33-21.el8?arch=x86_64\u0026upstream=file-5.33-21.el8.src.rpm\u0026distro=ol-8.7",
272588          "swid": {
272589            "attachment": {}
272590          },
272591          "pedigree": {},
272592          "evidence": {},
272593          "signature": {
272594            "signature": {
272595              "publicKey": {}
272596            }
272597          },
272598          "modelCard": {
272599            "modelParameters": {
272600              "approach": {}
272601            },
272602            "quantitativeAnalysis": {
272603              "graphics": {}
272604            },
272605            "considerations": {}
272606          }
272607        },
272608        {
272609          "type": "library",
272610          "bom-ref": "pkg:rpm/ol/filesystem@3.8-6.el8?arch=x86_64\u0026upstream=filesystem-3.8-6.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=8be707f9aeb3382e",
272611          "supplier": {},
272612          "publisher": "Oracle America",
272613          "name": "filesystem",
272614          "version": "3.8-6.el8",
272615          "licenses": [
272616            {
272617              "license": {
272618                "name": "Public Domain"
272619              }
272620            }
272621          ],
272622          "cpe": "cpe:2.3:a:oracleamerica:filesystem:3.8-6.el8:*:*:*:*:*:*:*",
272623          "purl": "pkg:rpm/ol/filesystem@3.8-6.el8?arch=x86_64\u0026upstream=filesystem-3.8-6.el8.src.rpm\u0026distro=ol-8.7",
272624          "swid": {
272625            "attachment": {}
272626          },
272627          "pedigree": {},
272628          "evidence": {},
272629          "signature": {
272630            "signature": {
272631              "publicKey": {}
272632            }
272633          },
272634          "modelCard": {
272635            "modelParameters": {
272636              "approach": {}
272637            },
272638            "quantitativeAnalysis": {
272639              "graphics": {}
272640            },
272641            "considerations": {}
272642          }
272643        },
272644        {
272645          "type": "library",
272646          "bom-ref": "pkg:rpm/ol/findutils@4.6.0-20.el8?arch=x86_64\u0026epoch=1\u0026upstream=findutils-4.6.0-20.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=9d8a854098c296a7",
272647          "supplier": {},
272648          "publisher": "Oracle America",
272649          "name": "findutils",
272650          "version": "1:4.6.0-20.el8",
272651          "licenses": [
272652            {
272653              "license": {
272654                "name": "GPLv3+"
272655              }
272656            }
272657          ],
272658          "cpe": "cpe:2.3:a:oracleamerica:findutils:1\\:4.6.0-20.el8:*:*:*:*:*:*:*",
272659          "purl": "pkg:rpm/ol/findutils@4.6.0-20.el8?arch=x86_64\u0026epoch=1\u0026upstream=findutils-4.6.0-20.el8.src.rpm\u0026distro=ol-8.7",
272660          "swid": {
272661            "attachment": {}
272662          },
272663          "pedigree": {},
272664          "evidence": {},
272665          "signature": {
272666            "signature": {
272667              "publicKey": {}
272668            }
272669          },
272670          "modelCard": {
272671            "modelParameters": {
272672              "approach": {}
272673            },
272674            "quantitativeAnalysis": {
272675              "graphics": {}
272676            },
272677            "considerations": {}
272678          }
272679        },
272680        {
272681          "type": "library",
272682          "bom-ref": "pkg:rpm/ol/gawk@4.2.1-4.el8?arch=x86_64\u0026upstream=gawk-4.2.1-4.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=8786cc2accbc8fa5",
272683          "supplier": {},
272684          "publisher": "Oracle America",
272685          "name": "gawk",
272686          "version": "4.2.1-4.el8",
272687          "licenses": [
272688            {
272689              "license": {
272690                "name": "GPLv3+ and GPLv2+ and LGPLv2+ and BSD"
272691              }
272692            }
272693          ],
272694          "cpe": "cpe:2.3:a:oracleamerica:gawk:4.2.1-4.el8:*:*:*:*:*:*:*",
272695          "purl": "pkg:rpm/ol/gawk@4.2.1-4.el8?arch=x86_64\u0026upstream=gawk-4.2.1-4.el8.src.rpm\u0026distro=ol-8.7",
272696          "swid": {
272697            "attachment": {}
272698          },
272699          "pedigree": {},
272700          "evidence": {},
272701          "signature": {
272702            "signature": {
272703              "publicKey": {}
272704            }
272705          },
272706          "modelCard": {
272707            "modelParameters": {
272708              "approach": {}
272709            },
272710            "quantitativeAnalysis": {
272711              "graphics": {}
272712            },
272713            "considerations": {}
272714          }
272715        },
272716        {
272717          "type": "library",
272718          "bom-ref": "pkg:rpm/ol/gdbm-libs@1.18-2.el8?arch=x86_64\u0026epoch=1\u0026upstream=gdbm-1.18-2.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=ab433ce5a4c81fd6",
272719          "supplier": {},
272720          "publisher": "Oracle America",
272721          "name": "gdbm-libs",
272722          "version": "1:1.18-2.el8",
272723          "licenses": [
272724            {
272725              "license": {
272726                "name": "GPLv3+"
272727              }
272728            }
272729          ],
272730          "cpe": "cpe:2.3:a:oracleamerica:gdbm-libs:1\\:1.18-2.el8:*:*:*:*:*:*:*",
272731          "purl": "pkg:rpm/ol/gdbm-libs@1.18-2.el8?arch=x86_64\u0026epoch=1\u0026upstream=gdbm-1.18-2.el8.src.rpm\u0026distro=ol-8.7",
272732          "swid": {
272733            "attachment": {}
272734          },
272735          "pedigree": {},
272736          "evidence": {},
272737          "signature": {
272738            "signature": {
272739              "publicKey": {}
272740            }
272741          },
272742          "modelCard": {
272743            "modelParameters": {
272744              "approach": {}
272745            },
272746            "quantitativeAnalysis": {
272747              "graphics": {}
272748            },
272749            "considerations": {}
272750          }
272751        },
272752        {
272753          "type": "library",
272754          "bom-ref": "pkg:golang/github.com/opencontainers/runc@v1.1.0?package-id=acbe2d30b51946b3",
272755          "supplier": {},
272756          "name": "github.com/opencontainers/runc",
272757          "version": "v1.1.0",
272758          "cpe": "cpe:2.3:a:opencontainers:runc:v1.1.0:*:*:*:*:*:*:*",
272759          "purl": "pkg:golang/github.com/opencontainers/runc@v1.1.0",
272760          "swid": {
272761            "attachment": {}
272762          },
272763          "pedigree": {},
272764          "evidence": {},
272765          "signature": {
272766            "signature": {
272767              "publicKey": {}
272768            }
272769          },
272770          "modelCard": {
272771            "modelParameters": {
272772              "approach": {}
272773            },
272774            "quantitativeAnalysis": {
272775              "graphics": {}
272776            },
272777            "considerations": {}
272778          }
272779        },
272780        {
272781          "type": "library",
272782          "bom-ref": "pkg:golang/github.com/tianon/gosu@(devel)?package-id=e8b054e24eb96bc6",
272783          "supplier": {},
272784          "name": "github.com/tianon/gosu",
272785          "version": "(devel)",
272786          "cpe": "cpe:2.3:a:tianon:gosu:\\(devel\\):*:*:*:*:*:*:*",
272787          "purl": "pkg:golang/github.com/tianon/gosu@(devel)",
272788          "swid": {
272789            "attachment": {}
272790          },
272791          "pedigree": {},
272792          "evidence": {},
272793          "signature": {
272794            "signature": {
272795              "publicKey": {}
272796            }
272797          },
272798          "modelCard": {
272799            "modelParameters": {
272800              "approach": {}
272801            },
272802            "quantitativeAnalysis": {
272803              "graphics": {}
272804            },
272805            "considerations": {}
272806          }
272807        },
272808        {
272809          "type": "library",
272810          "bom-ref": "pkg:rpm/ol/glib2@2.56.4-159.0.1.el8?arch=x86_64\u0026upstream=glib2-2.56.4-159.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=bb0970beb154ce2b",
272811          "supplier": {},
272812          "publisher": "Oracle America",
272813          "name": "glib2",
272814          "version": "2.56.4-159.0.1.el8",
272815          "licenses": [
272816            {
272817              "license": {
272818                "name": "LGPLv2+"
272819              }
272820            }
272821          ],
272822          "cpe": "cpe:2.3:a:oracleamerica:glib2:2.56.4-159.0.1.el8:*:*:*:*:*:*:*",
272823          "purl": "pkg:rpm/ol/glib2@2.56.4-159.0.1.el8?arch=x86_64\u0026upstream=glib2-2.56.4-159.0.1.el8.src.rpm\u0026distro=ol-8.7",
272824          "swid": {
272825            "attachment": {}
272826          },
272827          "pedigree": {},
272828          "evidence": {},
272829          "signature": {
272830            "signature": {
272831              "publicKey": {}
272832            }
272833          },
272834          "modelCard": {
272835            "modelParameters": {
272836              "approach": {}
272837            },
272838            "quantitativeAnalysis": {
272839              "graphics": {}
272840            },
272841            "considerations": {}
272842          }
272843        },
272844        {
272845          "type": "library",
272846          "bom-ref": "pkg:rpm/ol/glibc@2.28-211.0.1.el8?arch=x86_64\u0026upstream=glibc-2.28-211.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=c976ebab7eedfc9b",
272847          "supplier": {},
272848          "publisher": "Oracle America",
272849          "name": "glibc",
272850          "version": "2.28-211.0.1.el8",
272851          "licenses": [
272852            {
272853              "license": {
272854                "name": "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
272855              }
272856            }
272857          ],
272858          "cpe": "cpe:2.3:a:oracleamerica:glibc:2.28-211.0.1.el8:*:*:*:*:*:*:*",
272859          "purl": "pkg:rpm/ol/glibc@2.28-211.0.1.el8?arch=x86_64\u0026upstream=glibc-2.28-211.0.1.el8.src.rpm\u0026distro=ol-8.7",
272860          "swid": {
272861            "attachment": {}
272862          },
272863          "pedigree": {},
272864          "evidence": {},
272865          "signature": {
272866            "signature": {
272867              "publicKey": {}
272868            }
272869          },
272870          "modelCard": {
272871            "modelParameters": {
272872              "approach": {}
272873            },
272874            "quantitativeAnalysis": {
272875              "graphics": {}
272876            },
272877            "considerations": {}
272878          }
272879        },
272880        {
272881          "type": "library",
272882          "bom-ref": "pkg:rpm/ol/glibc-common@2.28-211.0.1.el8?arch=x86_64\u0026upstream=glibc-2.28-211.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=2a2eafc336ce7843",
272883          "supplier": {},
272884          "publisher": "Oracle America",
272885          "name": "glibc-common",
272886          "version": "2.28-211.0.1.el8",
272887          "licenses": [
272888            {
272889              "license": {
272890                "name": "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
272891              }
272892            }
272893          ],
272894          "cpe": "cpe:2.3:a:oracleamerica:glibc-common:2.28-211.0.1.el8:*:*:*:*:*:*:*",
272895          "purl": "pkg:rpm/ol/glibc-common@2.28-211.0.1.el8?arch=x86_64\u0026upstream=glibc-2.28-211.0.1.el8.src.rpm\u0026distro=ol-8.7",
272896          "swid": {
272897            "attachment": {}
272898          },
272899          "pedigree": {},
272900          "evidence": {},
272901          "signature": {
272902            "signature": {
272903              "publicKey": {}
272904            }
272905          },
272906          "modelCard": {
272907            "modelParameters": {
272908              "approach": {}
272909            },
272910            "quantitativeAnalysis": {
272911              "graphics": {}
272912            },
272913            "considerations": {}
272914          }
272915        },
272916        {
272917          "type": "library",
272918          "bom-ref": "pkg:rpm/ol/glibc-minimal-langpack@2.28-211.0.1.el8?arch=x86_64\u0026upstream=glibc-2.28-211.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=591b724235023c14",
272919          "supplier": {},
272920          "publisher": "Oracle America",
272921          "name": "glibc-minimal-langpack",
272922          "version": "2.28-211.0.1.el8",
272923          "licenses": [
272924            {
272925              "license": {
272926                "name": "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"
272927              }
272928            }
272929          ],
272930          "cpe": "cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-211.0.1.el8:*:*:*:*:*:*:*",
272931          "purl": "pkg:rpm/ol/glibc-minimal-langpack@2.28-211.0.1.el8?arch=x86_64\u0026upstream=glibc-2.28-211.0.1.el8.src.rpm\u0026distro=ol-8.7",
272932          "swid": {
272933            "attachment": {}
272934          },
272935          "pedigree": {},
272936          "evidence": {},
272937          "signature": {
272938            "signature": {
272939              "publicKey": {}
272940            }
272941          },
272942          "modelCard": {
272943            "modelParameters": {
272944              "approach": {}
272945            },
272946            "quantitativeAnalysis": {
272947              "graphics": {}
272948            },
272949            "considerations": {}
272950          }
272951        },
272952        {
272953          "type": "library",
272954          "bom-ref": "pkg:rpm/ol/gmp@6.1.2-10.el8?arch=x86_64\u0026epoch=1\u0026upstream=gmp-6.1.2-10.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=ef1b37e39954f409",
272955          "supplier": {},
272956          "publisher": "Oracle America",
272957          "name": "gmp",
272958          "version": "1:6.1.2-10.el8",
272959          "licenses": [
272960            {
272961              "license": {
272962                "name": "LGPLv3+ or GPLv2+"
272963              }
272964            }
272965          ],
272966          "cpe": "cpe:2.3:a:oracleamerica:gmp:1\\:6.1.2-10.el8:*:*:*:*:*:*:*",
272967          "purl": "pkg:rpm/ol/gmp@6.1.2-10.el8?arch=x86_64\u0026epoch=1\u0026upstream=gmp-6.1.2-10.el8.src.rpm\u0026distro=ol-8.7",
272968          "swid": {
272969            "attachment": {}
272970          },
272971          "pedigree": {},
272972          "evidence": {},
272973          "signature": {
272974            "signature": {
272975              "publicKey": {}
272976            }
272977          },
272978          "modelCard": {
272979            "modelParameters": {
272980              "approach": {}
272981            },
272982            "quantitativeAnalysis": {
272983              "graphics": {}
272984            },
272985            "considerations": {}
272986          }
272987        },
272988        {
272989          "type": "library",
272990          "bom-ref": "pkg:rpm/ol/gnupg2@2.2.20-3.el8_6?arch=x86_64\u0026upstream=gnupg2-2.2.20-3.el8_6.src.rpm\u0026distro=ol-8.7\u0026package-id=a3b856b0ed9f2ddc",
272991          "supplier": {},
272992          "publisher": "Oracle America",
272993          "name": "gnupg2",
272994          "version": "2.2.20-3.el8_6",
272995          "licenses": [
272996            {
272997              "license": {
272998                "name": "GPLv3+"
272999              }
273000            }
273001          ],
273002          "cpe": "cpe:2.3:a:oracleamerica:gnupg2:2.2.20-3.el8_6:*:*:*:*:*:*:*",
273003          "purl": "pkg:rpm/ol/gnupg2@2.2.20-3.el8_6?arch=x86_64\u0026upstream=gnupg2-2.2.20-3.el8_6.src.rpm\u0026distro=ol-8.7",
273004          "swid": {
273005            "attachment": {}
273006          },
273007          "pedigree": {},
273008          "evidence": {},
273009          "signature": {
273010            "signature": {
273011              "publicKey": {}
273012            }
273013          },
273014          "modelCard": {
273015            "modelParameters": {
273016              "approach": {}
273017            },
273018            "quantitativeAnalysis": {
273019              "graphics": {}
273020            },
273021            "considerations": {}
273022          }
273023        },
273024        {
273025          "type": "library",
273026          "bom-ref": "pkg:rpm/ol/gnutls@3.6.16-6.el8_7?arch=x86_64\u0026upstream=gnutls-3.6.16-6.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=2bfdd2b55dc81f31",
273027          "supplier": {},
273028          "publisher": "Oracle America",
273029          "name": "gnutls",
273030          "version": "3.6.16-6.el8_7",
273031          "licenses": [
273032            {
273033              "license": {
273034                "name": "GPLv3+ and LGPLv2+"
273035              }
273036            }
273037          ],
273038          "cpe": "cpe:2.3:a:oracleamerica:gnutls:3.6.16-6.el8_7:*:*:*:*:*:*:*",
273039          "purl": "pkg:rpm/ol/gnutls@3.6.16-6.el8_7?arch=x86_64\u0026upstream=gnutls-3.6.16-6.el8_7.src.rpm\u0026distro=ol-8.7",
273040          "swid": {
273041            "attachment": {}
273042          },
273043          "pedigree": {},
273044          "evidence": {},
273045          "signature": {
273046            "signature": {
273047              "publicKey": {}
273048            }
273049          },
273050          "modelCard": {
273051            "modelParameters": {
273052              "approach": {}
273053            },
273054            "quantitativeAnalysis": {
273055              "graphics": {}
273056            },
273057            "considerations": {}
273058          }
273059        },
273060        {
273061          "type": "library",
273062          "bom-ref": "pkg:rpm/ol/gobject-introspection@1.56.1-1.el8?arch=x86_64\u0026upstream=gobject-introspection-1.56.1-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=32657c95510a09e1",
273063          "supplier": {},
273064          "publisher": "Oracle America",
273065          "name": "gobject-introspection",
273066          "version": "1.56.1-1.el8",
273067          "licenses": [
273068            {
273069              "license": {
273070                "name": "GPLv2+, LGPLv2+, MIT"
273071              }
273072            }
273073          ],
273074          "cpe": "cpe:2.3:a:gobject-introspection:gobject-introspection:1.56.1-1.el8:*:*:*:*:*:*:*",
273075          "purl": "pkg:rpm/ol/gobject-introspection@1.56.1-1.el8?arch=x86_64\u0026upstream=gobject-introspection-1.56.1-1.el8.src.rpm\u0026distro=ol-8.7",
273076          "swid": {
273077            "attachment": {}
273078          },
273079          "pedigree": {},
273080          "evidence": {},
273081          "signature": {
273082            "signature": {
273083              "publicKey": {}
273084            }
273085          },
273086          "modelCard": {
273087            "modelParameters": {
273088              "approach": {}
273089            },
273090            "quantitativeAnalysis": {
273091              "graphics": {}
273092            },
273093            "considerations": {}
273094          }
273095        },
273096        {
273097          "type": "library",
273098          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd?package-id=3aa15d4598a266eb",
273099          "supplier": {},
273100          "name": "golang.org/x/sys",
273101          "version": "v0.0.0-20220907062415-87db552b00fd",
273102          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20220907062415-87db552b00fd:*:*:*:*:*:*:*",
273103          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20220907062415-87db552b00fd",
273104          "swid": {
273105            "attachment": {}
273106          },
273107          "pedigree": {},
273108          "evidence": {},
273109          "signature": {
273110            "signature": {
273111              "publicKey": {}
273112            }
273113          },
273114          "modelCard": {
273115            "modelParameters": {
273116              "approach": {}
273117            },
273118            "quantitativeAnalysis": {
273119              "graphics": {}
273120            },
273121            "considerations": {}
273122          }
273123        },
273124        {
273125          "type": "library",
273126          "bom-ref": "pkg:rpm/ol/gpg-pubkey@ad986da3-5cabf60d?distro=ol-8.7\u0026package-id=7e39bb17ee46a24e",
273127          "supplier": {},
273128          "name": "gpg-pubkey",
273129          "version": "ad986da3-5cabf60d",
273130          "licenses": [
273131            {
273132              "license": {
273133                "name": "pubkey"
273134              }
273135            }
273136          ],
273137          "cpe": "cpe:2.3:a:gpg-pubkey:gpg-pubkey:ad986da3-5cabf60d:*:*:*:*:*:*:*",
273138          "purl": "pkg:rpm/ol/gpg-pubkey@ad986da3-5cabf60d?distro=ol-8.7",
273139          "swid": {
273140            "attachment": {}
273141          },
273142          "pedigree": {},
273143          "evidence": {},
273144          "signature": {
273145            "signature": {
273146              "publicKey": {}
273147            }
273148          },
273149          "modelCard": {
273150            "modelParameters": {
273151              "approach": {}
273152            },
273153            "quantitativeAnalysis": {
273154              "graphics": {}
273155            },
273156            "considerations": {}
273157          }
273158        },
273159        {
273160          "type": "library",
273161          "bom-ref": "pkg:rpm/ol/gpgme@1.13.1-11.el8?arch=x86_64\u0026upstream=gpgme-1.13.1-11.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=10a5d40d8cf22f7",
273162          "supplier": {},
273163          "publisher": "Oracle America",
273164          "name": "gpgme",
273165          "version": "1.13.1-11.el8",
273166          "licenses": [
273167            {
273168              "license": {
273169                "name": "LGPLv2+ and GPLv3+"
273170              }
273171            }
273172          ],
273173          "cpe": "cpe:2.3:a:oracleamerica:gpgme:1.13.1-11.el8:*:*:*:*:*:*:*",
273174          "purl": "pkg:rpm/ol/gpgme@1.13.1-11.el8?arch=x86_64\u0026upstream=gpgme-1.13.1-11.el8.src.rpm\u0026distro=ol-8.7",
273175          "swid": {
273176            "attachment": {}
273177          },
273178          "pedigree": {},
273179          "evidence": {},
273180          "signature": {
273181            "signature": {
273182              "publicKey": {}
273183            }
273184          },
273185          "modelCard": {
273186            "modelParameters": {
273187              "approach": {}
273188            },
273189            "quantitativeAnalysis": {
273190              "graphics": {}
273191            },
273192            "considerations": {}
273193          }
273194        },
273195        {
273196          "type": "library",
273197          "bom-ref": "pkg:rpm/ol/grep@3.1-6.el8?arch=x86_64\u0026upstream=grep-3.1-6.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=1d4afcece34988b5",
273198          "supplier": {},
273199          "publisher": "Oracle America",
273200          "name": "grep",
273201          "version": "3.1-6.el8",
273202          "licenses": [
273203            {
273204              "license": {
273205                "name": "GPLv3+"
273206              }
273207            }
273208          ],
273209          "cpe": "cpe:2.3:a:oracleamerica:grep:3.1-6.el8:*:*:*:*:*:*:*",
273210          "purl": "pkg:rpm/ol/grep@3.1-6.el8?arch=x86_64\u0026upstream=grep-3.1-6.el8.src.rpm\u0026distro=ol-8.7",
273211          "swid": {
273212            "attachment": {}
273213          },
273214          "pedigree": {},
273215          "evidence": {},
273216          "signature": {
273217            "signature": {
273218              "publicKey": {}
273219            }
273220          },
273221          "modelCard": {
273222            "modelParameters": {
273223              "approach": {}
273224            },
273225            "quantitativeAnalysis": {
273226              "graphics": {}
273227            },
273228            "considerations": {}
273229          }
273230        },
273231        {
273232          "type": "library",
273233          "bom-ref": "pkg:rpm/ol/gzip@1.9-13.el8_5?arch=x86_64\u0026upstream=gzip-1.9-13.el8_5.src.rpm\u0026distro=ol-8.7\u0026package-id=76a65536dee19f37",
273234          "supplier": {},
273235          "publisher": "Oracle America",
273236          "name": "gzip",
273237          "version": "1.9-13.el8_5",
273238          "licenses": [
273239            {
273240              "license": {
273241                "name": "GPLv3+ and GFDL"
273242              }
273243            }
273244          ],
273245          "cpe": "cpe:2.3:a:oracleamerica:gzip:1.9-13.el8_5:*:*:*:*:*:*:*",
273246          "purl": "pkg:rpm/ol/gzip@1.9-13.el8_5?arch=x86_64\u0026upstream=gzip-1.9-13.el8_5.src.rpm\u0026distro=ol-8.7",
273247          "swid": {
273248            "attachment": {}
273249          },
273250          "pedigree": {},
273251          "evidence": {},
273252          "signature": {
273253            "signature": {
273254              "publicKey": {}
273255            }
273256          },
273257          "modelCard": {
273258            "modelParameters": {
273259              "approach": {}
273260            },
273261            "quantitativeAnalysis": {
273262              "graphics": {}
273263            },
273264            "considerations": {}
273265          }
273266        },
273267        {
273268          "type": "library",
273269          "bom-ref": "pkg:rpm/ol/info@6.5-7.el8?arch=x86_64\u0026upstream=texinfo-6.5-7.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=429de88a1da8ab52",
273270          "supplier": {},
273271          "publisher": "Oracle America",
273272          "name": "info",
273273          "version": "6.5-7.el8",
273274          "licenses": [
273275            {
273276              "license": {
273277                "name": "GPLv3+"
273278              }
273279            }
273280          ],
273281          "cpe": "cpe:2.3:a:oracleamerica:info:6.5-7.el8:*:*:*:*:*:*:*",
273282          "purl": "pkg:rpm/ol/info@6.5-7.el8?arch=x86_64\u0026upstream=texinfo-6.5-7.el8.src.rpm\u0026distro=ol-8.7",
273283          "swid": {
273284            "attachment": {}
273285          },
273286          "pedigree": {},
273287          "evidence": {},
273288          "signature": {
273289            "signature": {
273290              "publicKey": {}
273291            }
273292          },
273293          "modelCard": {
273294            "modelParameters": {
273295              "approach": {}
273296            },
273297            "quantitativeAnalysis": {
273298              "graphics": {}
273299            },
273300            "considerations": {}
273301          }
273302        },
273303        {
273304          "type": "library",
273305          "bom-ref": "pkg:rpm/ol/json-c@0.13.1-3.el8?arch=x86_64\u0026upstream=json-c-0.13.1-3.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=bb1712edac77b57d",
273306          "supplier": {},
273307          "publisher": "Oracle America",
273308          "name": "json-c",
273309          "version": "0.13.1-3.el8",
273310          "licenses": [
273311            {
273312              "license": {
273313                "id": "MIT"
273314              }
273315            }
273316          ],
273317          "cpe": "cpe:2.3:a:oracleamerica:json-c:0.13.1-3.el8:*:*:*:*:*:*:*",
273318          "purl": "pkg:rpm/ol/json-c@0.13.1-3.el8?arch=x86_64\u0026upstream=json-c-0.13.1-3.el8.src.rpm\u0026distro=ol-8.7",
273319          "swid": {
273320            "attachment": {}
273321          },
273322          "pedigree": {},
273323          "evidence": {},
273324          "signature": {
273325            "signature": {
273326              "publicKey": {}
273327            }
273328          },
273329          "modelCard": {
273330            "modelParameters": {
273331              "approach": {}
273332            },
273333            "quantitativeAnalysis": {
273334              "graphics": {}
273335            },
273336            "considerations": {}
273337          }
273338        },
273339        {
273340          "type": "library",
273341          "bom-ref": "pkg:rpm/ol/keyutils-libs@1.5.10-9.el8?arch=x86_64\u0026upstream=keyutils-1.5.10-9.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=2b8a9b00346b56d7",
273342          "supplier": {},
273343          "publisher": "Oracle America",
273344          "name": "keyutils-libs",
273345          "version": "1.5.10-9.el8",
273346          "licenses": [
273347            {
273348              "license": {
273349                "name": "GPLv2+ and LGPLv2+"
273350              }
273351            }
273352          ],
273353          "cpe": "cpe:2.3:a:keyutils-libs:keyutils-libs:1.5.10-9.el8:*:*:*:*:*:*:*",
273354          "purl": "pkg:rpm/ol/keyutils-libs@1.5.10-9.el8?arch=x86_64\u0026upstream=keyutils-1.5.10-9.el8.src.rpm\u0026distro=ol-8.7",
273355          "swid": {
273356            "attachment": {}
273357          },
273358          "pedigree": {},
273359          "evidence": {},
273360          "signature": {
273361            "signature": {
273362              "publicKey": {}
273363            }
273364          },
273365          "modelCard": {
273366            "modelParameters": {
273367              "approach": {}
273368            },
273369            "quantitativeAnalysis": {
273370              "graphics": {}
273371            },
273372            "considerations": {}
273373          }
273374        },
273375        {
273376          "type": "library",
273377          "bom-ref": "pkg:rpm/ol/krb5-libs@1.18.2-22.0.1.el8_7?arch=x86_64\u0026upstream=krb5-1.18.2-22.0.1.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=3efe7515888f4dbc",
273378          "supplier": {},
273379          "publisher": "Oracle America",
273380          "name": "krb5-libs",
273381          "version": "1.18.2-22.0.1.el8_7",
273382          "licenses": [
273383            {
273384              "license": {
273385                "id": "MIT"
273386              }
273387            }
273388          ],
273389          "cpe": "cpe:2.3:a:oracleamerica:krb5-libs:1.18.2-22.0.1.el8_7:*:*:*:*:*:*:*",
273390          "purl": "pkg:rpm/ol/krb5-libs@1.18.2-22.0.1.el8_7?arch=x86_64\u0026upstream=krb5-1.18.2-22.0.1.el8_7.src.rpm\u0026distro=ol-8.7",
273391          "swid": {
273392            "attachment": {}
273393          },
273394          "pedigree": {},
273395          "evidence": {},
273396          "signature": {
273397            "signature": {
273398              "publicKey": {}
273399            }
273400          },
273401          "modelCard": {
273402            "modelParameters": {
273403              "approach": {}
273404            },
273405            "quantitativeAnalysis": {
273406              "graphics": {}
273407            },
273408            "considerations": {}
273409          }
273410        },
273411        {
273412          "type": "library",
273413          "bom-ref": "pkg:rpm/ol/libacl@2.2.53-1.el8?arch=x86_64\u0026upstream=acl-2.2.53-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=947a345f9aea6e23",
273414          "supplier": {},
273415          "publisher": "Oracle America",
273416          "name": "libacl",
273417          "version": "2.2.53-1.el8",
273418          "licenses": [
273419            {
273420              "license": {
273421                "name": "LGPLv2+"
273422              }
273423            }
273424          ],
273425          "cpe": "cpe:2.3:a:oracleamerica:libacl:2.2.53-1.el8:*:*:*:*:*:*:*",
273426          "purl": "pkg:rpm/ol/libacl@2.2.53-1.el8?arch=x86_64\u0026upstream=acl-2.2.53-1.el8.src.rpm\u0026distro=ol-8.7",
273427          "swid": {
273428            "attachment": {}
273429          },
273430          "pedigree": {},
273431          "evidence": {},
273432          "signature": {
273433            "signature": {
273434              "publicKey": {}
273435            }
273436          },
273437          "modelCard": {
273438            "modelParameters": {
273439              "approach": {}
273440            },
273441            "quantitativeAnalysis": {
273442              "graphics": {}
273443            },
273444            "considerations": {}
273445          }
273446        },
273447        {
273448          "type": "library",
273449          "bom-ref": "pkg:rpm/ol/libaio@0.3.112-1.el8?arch=x86_64\u0026upstream=libaio-0.3.112-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=6f33dd1d6c2f4f17",
273450          "supplier": {},
273451          "publisher": "Oracle America",
273452          "name": "libaio",
273453          "version": "0.3.112-1.el8",
273454          "licenses": [
273455            {
273456              "license": {
273457                "name": "LGPLv2+"
273458              }
273459            }
273460          ],
273461          "cpe": "cpe:2.3:a:oracleamerica:libaio:0.3.112-1.el8:*:*:*:*:*:*:*",
273462          "purl": "pkg:rpm/ol/libaio@0.3.112-1.el8?arch=x86_64\u0026upstream=libaio-0.3.112-1.el8.src.rpm\u0026distro=ol-8.7",
273463          "swid": {
273464            "attachment": {}
273465          },
273466          "pedigree": {},
273467          "evidence": {},
273468          "signature": {
273469            "signature": {
273470              "publicKey": {}
273471            }
273472          },
273473          "modelCard": {
273474            "modelParameters": {
273475              "approach": {}
273476            },
273477            "quantitativeAnalysis": {
273478              "graphics": {}
273479            },
273480            "considerations": {}
273481          }
273482        },
273483        {
273484          "type": "library",
273485          "bom-ref": "pkg:rpm/ol/libarchive@3.3.3-4.el8?arch=x86_64\u0026upstream=libarchive-3.3.3-4.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=f73c9e5edab41106",
273486          "supplier": {},
273487          "publisher": "Oracle America",
273488          "name": "libarchive",
273489          "version": "3.3.3-4.el8",
273490          "licenses": [
273491            {
273492              "license": {
273493                "name": "BSD"
273494              }
273495            }
273496          ],
273497          "cpe": "cpe:2.3:a:oracleamerica:libarchive:3.3.3-4.el8:*:*:*:*:*:*:*",
273498          "purl": "pkg:rpm/ol/libarchive@3.3.3-4.el8?arch=x86_64\u0026upstream=libarchive-3.3.3-4.el8.src.rpm\u0026distro=ol-8.7",
273499          "swid": {
273500            "attachment": {}
273501          },
273502          "pedigree": {},
273503          "evidence": {},
273504          "signature": {
273505            "signature": {
273506              "publicKey": {}
273507            }
273508          },
273509          "modelCard": {
273510            "modelParameters": {
273511              "approach": {}
273512            },
273513            "quantitativeAnalysis": {
273514              "graphics": {}
273515            },
273516            "considerations": {}
273517          }
273518        },
273519        {
273520          "type": "library",
273521          "bom-ref": "pkg:rpm/ol/libassuan@2.5.1-3.el8?arch=x86_64\u0026upstream=libassuan-2.5.1-3.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=be435c1a75778ca5",
273522          "supplier": {},
273523          "publisher": "Oracle America",
273524          "name": "libassuan",
273525          "version": "2.5.1-3.el8",
273526          "licenses": [
273527            {
273528              "license": {
273529                "name": "LGPLv2+ and GPLv3+"
273530              }
273531            }
273532          ],
273533          "cpe": "cpe:2.3:a:oracleamerica:libassuan:2.5.1-3.el8:*:*:*:*:*:*:*",
273534          "purl": "pkg:rpm/ol/libassuan@2.5.1-3.el8?arch=x86_64\u0026upstream=libassuan-2.5.1-3.el8.src.rpm\u0026distro=ol-8.7",
273535          "swid": {
273536            "attachment": {}
273537          },
273538          "pedigree": {},
273539          "evidence": {},
273540          "signature": {
273541            "signature": {
273542              "publicKey": {}
273543            }
273544          },
273545          "modelCard": {
273546            "modelParameters": {
273547              "approach": {}
273548            },
273549            "quantitativeAnalysis": {
273550              "graphics": {}
273551            },
273552            "considerations": {}
273553          }
273554        },
273555        {
273556          "type": "library",
273557          "bom-ref": "pkg:rpm/ol/libattr@2.4.48-3.el8?arch=x86_64\u0026upstream=attr-2.4.48-3.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=d841cc67da1171d0",
273558          "supplier": {},
273559          "publisher": "Oracle America",
273560          "name": "libattr",
273561          "version": "2.4.48-3.el8",
273562          "licenses": [
273563            {
273564              "license": {
273565                "name": "LGPLv2+"
273566              }
273567            }
273568          ],
273569          "cpe": "cpe:2.3:a:oracleamerica:libattr:2.4.48-3.el8:*:*:*:*:*:*:*",
273570          "purl": "pkg:rpm/ol/libattr@2.4.48-3.el8?arch=x86_64\u0026upstream=attr-2.4.48-3.el8.src.rpm\u0026distro=ol-8.7",
273571          "swid": {
273572            "attachment": {}
273573          },
273574          "pedigree": {},
273575          "evidence": {},
273576          "signature": {
273577            "signature": {
273578              "publicKey": {}
273579            }
273580          },
273581          "modelCard": {
273582            "modelParameters": {
273583              "approach": {}
273584            },
273585            "quantitativeAnalysis": {
273586              "graphics": {}
273587            },
273588            "considerations": {}
273589          }
273590        },
273591        {
273592          "type": "library",
273593          "bom-ref": "pkg:rpm/ol/libblkid@2.32.1-39.el8_7?arch=x86_64\u0026upstream=util-linux-2.32.1-39.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=1a0cc7d8b79b1e17",
273594          "supplier": {},
273595          "publisher": "Oracle America",
273596          "name": "libblkid",
273597          "version": "2.32.1-39.el8_7",
273598          "licenses": [
273599            {
273600              "license": {
273601                "name": "LGPLv2+"
273602              }
273603            }
273604          ],
273605          "cpe": "cpe:2.3:a:oracleamerica:libblkid:2.32.1-39.el8_7:*:*:*:*:*:*:*",
273606          "purl": "pkg:rpm/ol/libblkid@2.32.1-39.el8_7?arch=x86_64\u0026upstream=util-linux-2.32.1-39.el8_7.src.rpm\u0026distro=ol-8.7",
273607          "swid": {
273608            "attachment": {}
273609          },
273610          "pedigree": {},
273611          "evidence": {},
273612          "signature": {
273613            "signature": {
273614              "publicKey": {}
273615            }
273616          },
273617          "modelCard": {
273618            "modelParameters": {
273619              "approach": {}
273620            },
273621            "quantitativeAnalysis": {
273622              "graphics": {}
273623            },
273624            "considerations": {}
273625          }
273626        },
273627        {
273628          "type": "library",
273629          "bom-ref": "pkg:rpm/ol/libcap@2.48-4.el8?arch=x86_64\u0026upstream=libcap-2.48-4.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=767cfbbf82a6dd0d",
273630          "supplier": {},
273631          "publisher": "Oracle America",
273632          "name": "libcap",
273633          "version": "2.48-4.el8",
273634          "licenses": [
273635            {
273636              "license": {
273637                "name": "BSD or GPLv2"
273638              }
273639            }
273640          ],
273641          "cpe": "cpe:2.3:a:oracleamerica:libcap:2.48-4.el8:*:*:*:*:*:*:*",
273642          "purl": "pkg:rpm/ol/libcap@2.48-4.el8?arch=x86_64\u0026upstream=libcap-2.48-4.el8.src.rpm\u0026distro=ol-8.7",
273643          "swid": {
273644            "attachment": {}
273645          },
273646          "pedigree": {},
273647          "evidence": {},
273648          "signature": {
273649            "signature": {
273650              "publicKey": {}
273651            }
273652          },
273653          "modelCard": {
273654            "modelParameters": {
273655              "approach": {}
273656            },
273657            "quantitativeAnalysis": {
273658              "graphics": {}
273659            },
273660            "considerations": {}
273661          }
273662        },
273663        {
273664          "type": "library",
273665          "bom-ref": "pkg:rpm/ol/libcap-ng@0.7.11-1.el8?arch=x86_64\u0026upstream=libcap-ng-0.7.11-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=a62c0fc807c78067",
273666          "supplier": {},
273667          "publisher": "Oracle America",
273668          "name": "libcap-ng",
273669          "version": "0.7.11-1.el8",
273670          "licenses": [
273671            {
273672              "license": {
273673                "name": "LGPLv2+"
273674              }
273675            }
273676          ],
273677          "cpe": "cpe:2.3:a:oracleamerica:libcap-ng:0.7.11-1.el8:*:*:*:*:*:*:*",
273678          "purl": "pkg:rpm/ol/libcap-ng@0.7.11-1.el8?arch=x86_64\u0026upstream=libcap-ng-0.7.11-1.el8.src.rpm\u0026distro=ol-8.7",
273679          "swid": {
273680            "attachment": {}
273681          },
273682          "pedigree": {},
273683          "evidence": {},
273684          "signature": {
273685            "signature": {
273686              "publicKey": {}
273687            }
273688          },
273689          "modelCard": {
273690            "modelParameters": {
273691              "approach": {}
273692            },
273693            "quantitativeAnalysis": {
273694              "graphics": {}
273695            },
273696            "considerations": {}
273697          }
273698        },
273699        {
273700          "type": "library",
273701          "bom-ref": "pkg:rpm/ol/libcom_err@1.45.6-5.el8?arch=x86_64\u0026upstream=e2fsprogs-1.45.6-5.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=6cc3b4cf91eedd1f",
273702          "supplier": {},
273703          "publisher": "Oracle America",
273704          "name": "libcom_err",
273705          "version": "1.45.6-5.el8",
273706          "licenses": [
273707            {
273708              "license": {
273709                "id": "MIT"
273710              }
273711            }
273712          ],
273713          "cpe": "cpe:2.3:a:oracleamerica:libcom-err:1.45.6-5.el8:*:*:*:*:*:*:*",
273714          "purl": "pkg:rpm/ol/libcom_err@1.45.6-5.el8?arch=x86_64\u0026upstream=e2fsprogs-1.45.6-5.el8.src.rpm\u0026distro=ol-8.7",
273715          "swid": {
273716            "attachment": {}
273717          },
273718          "pedigree": {},
273719          "evidence": {},
273720          "signature": {
273721            "signature": {
273722              "publicKey": {}
273723            }
273724          },
273725          "modelCard": {
273726            "modelParameters": {
273727              "approach": {}
273728            },
273729            "quantitativeAnalysis": {
273730              "graphics": {}
273731            },
273732            "considerations": {}
273733          }
273734        },
273735        {
273736          "type": "library",
273737          "bom-ref": "pkg:rpm/ol/libcurl@7.61.1-25.el8_7.3?arch=x86_64\u0026upstream=curl-7.61.1-25.el8_7.3.src.rpm\u0026distro=ol-8.7\u0026package-id=919eee383ee97744",
273738          "supplier": {},
273739          "publisher": "Oracle America",
273740          "name": "libcurl",
273741          "version": "7.61.1-25.el8_7.3",
273742          "licenses": [
273743            {
273744              "license": {
273745                "id": "MIT"
273746              }
273747            }
273748          ],
273749          "cpe": "cpe:2.3:a:oracleamerica:libcurl:7.61.1-25.el8_7.3:*:*:*:*:*:*:*",
273750          "purl": "pkg:rpm/ol/libcurl@7.61.1-25.el8_7.3?arch=x86_64\u0026upstream=curl-7.61.1-25.el8_7.3.src.rpm\u0026distro=ol-8.7",
273751          "swid": {
273752            "attachment": {}
273753          },
273754          "pedigree": {},
273755          "evidence": {},
273756          "signature": {
273757            "signature": {
273758              "publicKey": {}
273759            }
273760          },
273761          "modelCard": {
273762            "modelParameters": {
273763              "approach": {}
273764            },
273765            "quantitativeAnalysis": {
273766              "graphics": {}
273767            },
273768            "considerations": {}
273769          }
273770        },
273771        {
273772          "type": "library",
273773          "bom-ref": "pkg:rpm/ol/libdb@5.3.28-42.el8_4?arch=x86_64\u0026upstream=libdb-5.3.28-42.el8_4.src.rpm\u0026distro=ol-8.7\u0026package-id=76062f478c25488c",
273774          "supplier": {},
273775          "publisher": "Oracle America",
273776          "name": "libdb",
273777          "version": "5.3.28-42.el8_4",
273778          "licenses": [
273779            {
273780              "license": {
273781                "name": "BSD and LGPLv2 and Sleepycat"
273782              }
273783            }
273784          ],
273785          "cpe": "cpe:2.3:a:oracleamerica:libdb:5.3.28-42.el8_4:*:*:*:*:*:*:*",
273786          "purl": "pkg:rpm/ol/libdb@5.3.28-42.el8_4?arch=x86_64\u0026upstream=libdb-5.3.28-42.el8_4.src.rpm\u0026distro=ol-8.7",
273787          "swid": {
273788            "attachment": {}
273789          },
273790          "pedigree": {},
273791          "evidence": {},
273792          "signature": {
273793            "signature": {
273794              "publicKey": {}
273795            }
273796          },
273797          "modelCard": {
273798            "modelParameters": {
273799              "approach": {}
273800            },
273801            "quantitativeAnalysis": {
273802              "graphics": {}
273803            },
273804            "considerations": {}
273805          }
273806        },
273807        {
273808          "type": "library",
273809          "bom-ref": "pkg:rpm/ol/libdb-utils@5.3.28-42.el8_4?arch=x86_64\u0026upstream=libdb-5.3.28-42.el8_4.src.rpm\u0026distro=ol-8.7\u0026package-id=ed14a1b76ea03928",
273810          "supplier": {},
273811          "publisher": "Oracle America",
273812          "name": "libdb-utils",
273813          "version": "5.3.28-42.el8_4",
273814          "licenses": [
273815            {
273816              "license": {
273817                "name": "BSD and LGPLv2 and Sleepycat"
273818              }
273819            }
273820          ],
273821          "cpe": "cpe:2.3:a:oracleamerica:libdb-utils:5.3.28-42.el8_4:*:*:*:*:*:*:*",
273822          "purl": "pkg:rpm/ol/libdb-utils@5.3.28-42.el8_4?arch=x86_64\u0026upstream=libdb-5.3.28-42.el8_4.src.rpm\u0026distro=ol-8.7",
273823          "swid": {
273824            "attachment": {}
273825          },
273826          "pedigree": {},
273827          "evidence": {},
273828          "signature": {
273829            "signature": {
273830              "publicKey": {}
273831            }
273832          },
273833          "modelCard": {
273834            "modelParameters": {
273835              "approach": {}
273836            },
273837            "quantitativeAnalysis": {
273838              "graphics": {}
273839            },
273840            "considerations": {}
273841          }
273842        },
273843        {
273844          "type": "library",
273845          "bom-ref": "pkg:rpm/ol/libdnf@0.63.0-11.1.0.1.el8?arch=x86_64\u0026upstream=libdnf-0.63.0-11.1.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=858d2edb994f03b",
273846          "supplier": {},
273847          "publisher": "Oracle America",
273848          "name": "libdnf",
273849          "version": "0.63.0-11.1.0.1.el8",
273850          "licenses": [
273851            {
273852              "license": {
273853                "name": "LGPLv2+"
273854              }
273855            }
273856          ],
273857          "cpe": "cpe:2.3:a:oracleamerica:libdnf:0.63.0-11.1.0.1.el8:*:*:*:*:*:*:*",
273858          "purl": "pkg:rpm/ol/libdnf@0.63.0-11.1.0.1.el8?arch=x86_64\u0026upstream=libdnf-0.63.0-11.1.0.1.el8.src.rpm\u0026distro=ol-8.7",
273859          "swid": {
273860            "attachment": {}
273861          },
273862          "pedigree": {},
273863          "evidence": {},
273864          "signature": {
273865            "signature": {
273866              "publicKey": {}
273867            }
273868          },
273869          "modelCard": {
273870            "modelParameters": {
273871              "approach": {}
273872            },
273873            "quantitativeAnalysis": {
273874              "graphics": {}
273875            },
273876            "considerations": {}
273877          }
273878        },
273879        {
273880          "type": "library",
273881          "bom-ref": "pkg:rpm/ol/libffi@3.1-23.el8?arch=x86_64\u0026upstream=libffi-3.1-23.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=ded74aa373c2cd7a",
273882          "supplier": {},
273883          "publisher": "Oracle America",
273884          "name": "libffi",
273885          "version": "3.1-23.el8",
273886          "licenses": [
273887            {
273888              "license": {
273889                "id": "MIT"
273890              }
273891            }
273892          ],
273893          "cpe": "cpe:2.3:a:oracleamerica:libffi:3.1-23.el8:*:*:*:*:*:*:*",
273894          "purl": "pkg:rpm/ol/libffi@3.1-23.el8?arch=x86_64\u0026upstream=libffi-3.1-23.el8.src.rpm\u0026distro=ol-8.7",
273895          "swid": {
273896            "attachment": {}
273897          },
273898          "pedigree": {},
273899          "evidence": {},
273900          "signature": {
273901            "signature": {
273902              "publicKey": {}
273903            }
273904          },
273905          "modelCard": {
273906            "modelParameters": {
273907              "approach": {}
273908            },
273909            "quantitativeAnalysis": {
273910              "graphics": {}
273911            },
273912            "considerations": {}
273913          }
273914        },
273915        {
273916          "type": "library",
273917          "bom-ref": "pkg:rpm/ol/libgcc@8.5.0-16.0.2.el8_7?arch=x86_64\u0026upstream=gcc-8.5.0-16.0.2.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=cda803488f9e07c4",
273918          "supplier": {},
273919          "publisher": "Oracle America",
273920          "name": "libgcc",
273921          "version": "8.5.0-16.0.2.el8_7",
273922          "licenses": [
273923            {
273924              "license": {
273925                "name": "GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"
273926              }
273927            }
273928          ],
273929          "cpe": "cpe:2.3:a:oracleamerica:libgcc:8.5.0-16.0.2.el8_7:*:*:*:*:*:*:*",
273930          "purl": "pkg:rpm/ol/libgcc@8.5.0-16.0.2.el8_7?arch=x86_64\u0026upstream=gcc-8.5.0-16.0.2.el8_7.src.rpm\u0026distro=ol-8.7",
273931          "swid": {
273932            "attachment": {}
273933          },
273934          "pedigree": {},
273935          "evidence": {},
273936          "signature": {
273937            "signature": {
273938              "publicKey": {}
273939            }
273940          },
273941          "modelCard": {
273942            "modelParameters": {
273943              "approach": {}
273944            },
273945            "quantitativeAnalysis": {
273946              "graphics": {}
273947            },
273948            "considerations": {}
273949          }
273950        },
273951        {
273952          "type": "library",
273953          "bom-ref": "pkg:rpm/ol/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm\u0026distro=ol-8.7\u0026package-id=88aa3a119bed5db7",
273954          "supplier": {},
273955          "publisher": "Oracle America",
273956          "name": "libgcrypt",
273957          "version": "1.8.5-7.el8_6",
273958          "licenses": [
273959            {
273960              "license": {
273961                "name": "LGPLv2+"
273962              }
273963            }
273964          ],
273965          "cpe": "cpe:2.3:a:oracleamerica:libgcrypt:1.8.5-7.el8_6:*:*:*:*:*:*:*",
273966          "purl": "pkg:rpm/ol/libgcrypt@1.8.5-7.el8_6?arch=x86_64\u0026upstream=libgcrypt-1.8.5-7.el8_6.src.rpm\u0026distro=ol-8.7",
273967          "swid": {
273968            "attachment": {}
273969          },
273970          "pedigree": {},
273971          "evidence": {},
273972          "signature": {
273973            "signature": {
273974              "publicKey": {}
273975            }
273976          },
273977          "modelCard": {
273978            "modelParameters": {
273979              "approach": {}
273980            },
273981            "quantitativeAnalysis": {
273982              "graphics": {}
273983            },
273984            "considerations": {}
273985          }
273986        },
273987        {
273988          "type": "library",
273989          "bom-ref": "pkg:rpm/ol/libgpg-error@1.31-1.el8?arch=x86_64\u0026upstream=libgpg-error-1.31-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=d3de1bbfffb2fc8c",
273990          "supplier": {},
273991          "publisher": "Oracle America",
273992          "name": "libgpg-error",
273993          "version": "1.31-1.el8",
273994          "licenses": [
273995            {
273996              "license": {
273997                "name": "LGPLv2+"
273998              }
273999            }
274000          ],
274001          "cpe": "cpe:2.3:a:oracleamerica:libgpg-error:1.31-1.el8:*:*:*:*:*:*:*",
274002          "purl": "pkg:rpm/ol/libgpg-error@1.31-1.el8?arch=x86_64\u0026upstream=libgpg-error-1.31-1.el8.src.rpm\u0026distro=ol-8.7",
274003          "swid": {
274004            "attachment": {}
274005          },
274006          "pedigree": {},
274007          "evidence": {},
274008          "signature": {
274009            "signature": {
274010              "publicKey": {}
274011            }
274012          },
274013          "modelCard": {
274014            "modelParameters": {
274015              "approach": {}
274016            },
274017            "quantitativeAnalysis": {
274018              "graphics": {}
274019            },
274020            "considerations": {}
274021          }
274022        },
274023        {
274024          "type": "library",
274025          "bom-ref": "pkg:rpm/ol/libidn2@2.2.0-1.el8?arch=x86_64\u0026upstream=libidn2-2.2.0-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=c77c3918713346a2",
274026          "supplier": {},
274027          "publisher": "Oracle America",
274028          "name": "libidn2",
274029          "version": "2.2.0-1.el8",
274030          "licenses": [
274031            {
274032              "license": {
274033                "name": "(GPLv2+ or LGPLv3+) and GPLv3+"
274034              }
274035            }
274036          ],
274037          "cpe": "cpe:2.3:a:oracleamerica:libidn2:2.2.0-1.el8:*:*:*:*:*:*:*",
274038          "purl": "pkg:rpm/ol/libidn2@2.2.0-1.el8?arch=x86_64\u0026upstream=libidn2-2.2.0-1.el8.src.rpm\u0026distro=ol-8.7",
274039          "swid": {
274040            "attachment": {}
274041          },
274042          "pedigree": {},
274043          "evidence": {},
274044          "signature": {
274045            "signature": {
274046              "publicKey": {}
274047            }
274048          },
274049          "modelCard": {
274050            "modelParameters": {
274051              "approach": {}
274052            },
274053            "quantitativeAnalysis": {
274054              "graphics": {}
274055            },
274056            "considerations": {}
274057          }
274058        },
274059        {
274060          "type": "library",
274061          "bom-ref": "pkg:rpm/ol/libksba@1.3.5-9.el8_7?arch=x86_64\u0026upstream=libksba-1.3.5-9.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=bbc57a6342de112c",
274062          "supplier": {},
274063          "publisher": "Oracle America",
274064          "name": "libksba",
274065          "version": "1.3.5-9.el8_7",
274066          "licenses": [
274067            {
274068              "license": {
274069                "name": "(LGPLv3+ or GPLv2+) and GPLv3+"
274070              }
274071            }
274072          ],
274073          "cpe": "cpe:2.3:a:oracleamerica:libksba:1.3.5-9.el8_7:*:*:*:*:*:*:*",
274074          "purl": "pkg:rpm/ol/libksba@1.3.5-9.el8_7?arch=x86_64\u0026upstream=libksba-1.3.5-9.el8_7.src.rpm\u0026distro=ol-8.7",
274075          "swid": {
274076            "attachment": {}
274077          },
274078          "pedigree": {},
274079          "evidence": {},
274080          "signature": {
274081            "signature": {
274082              "publicKey": {}
274083            }
274084          },
274085          "modelCard": {
274086            "modelParameters": {
274087              "approach": {}
274088            },
274089            "quantitativeAnalysis": {
274090              "graphics": {}
274091            },
274092            "considerations": {}
274093          }
274094        },
274095        {
274096          "type": "library",
274097          "bom-ref": "pkg:rpm/ol/libmodulemd@2.13.0-1.el8?arch=x86_64\u0026upstream=libmodulemd-2.13.0-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=5a4435a8150c8412",
274098          "supplier": {},
274099          "publisher": "Oracle America",
274100          "name": "libmodulemd",
274101          "version": "2.13.0-1.el8",
274102          "licenses": [
274103            {
274104              "license": {
274105                "id": "MIT"
274106              }
274107            }
274108          ],
274109          "cpe": "cpe:2.3:a:oracleamerica:libmodulemd:2.13.0-1.el8:*:*:*:*:*:*:*",
274110          "purl": "pkg:rpm/ol/libmodulemd@2.13.0-1.el8?arch=x86_64\u0026upstream=libmodulemd-2.13.0-1.el8.src.rpm\u0026distro=ol-8.7",
274111          "swid": {
274112            "attachment": {}
274113          },
274114          "pedigree": {},
274115          "evidence": {},
274116          "signature": {
274117            "signature": {
274118              "publicKey": {}
274119            }
274120          },
274121          "modelCard": {
274122            "modelParameters": {
274123              "approach": {}
274124            },
274125            "quantitativeAnalysis": {
274126              "graphics": {}
274127            },
274128            "considerations": {}
274129          }
274130        },
274131        {
274132          "type": "library",
274133          "bom-ref": "pkg:rpm/ol/libmount@2.32.1-39.el8_7?arch=x86_64\u0026upstream=util-linux-2.32.1-39.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=68eef99727f4a61c",
274134          "supplier": {},
274135          "publisher": "Oracle America",
274136          "name": "libmount",
274137          "version": "2.32.1-39.el8_7",
274138          "licenses": [
274139            {
274140              "license": {
274141                "name": "LGPLv2+"
274142              }
274143            }
274144          ],
274145          "cpe": "cpe:2.3:a:oracleamerica:libmount:2.32.1-39.el8_7:*:*:*:*:*:*:*",
274146          "purl": "pkg:rpm/ol/libmount@2.32.1-39.el8_7?arch=x86_64\u0026upstream=util-linux-2.32.1-39.el8_7.src.rpm\u0026distro=ol-8.7",
274147          "swid": {
274148            "attachment": {}
274149          },
274150          "pedigree": {},
274151          "evidence": {},
274152          "signature": {
274153            "signature": {
274154              "publicKey": {}
274155            }
274156          },
274157          "modelCard": {
274158            "modelParameters": {
274159              "approach": {}
274160            },
274161            "quantitativeAnalysis": {
274162              "graphics": {}
274163            },
274164            "considerations": {}
274165          }
274166        },
274167        {
274168          "type": "library",
274169          "bom-ref": "pkg:rpm/ol/libnghttp2@1.33.0-3.el8_2.1?arch=x86_64\u0026upstream=nghttp2-1.33.0-3.el8_2.1.src.rpm\u0026distro=ol-8.7\u0026package-id=6dfb319411881b5c",
274170          "supplier": {},
274171          "publisher": "Oracle America",
274172          "name": "libnghttp2",
274173          "version": "1.33.0-3.el8_2.1",
274174          "licenses": [
274175            {
274176              "license": {
274177                "id": "MIT"
274178              }
274179            }
274180          ],
274181          "cpe": "cpe:2.3:a:oracleamerica:libnghttp2:1.33.0-3.el8_2.1:*:*:*:*:*:*:*",
274182          "purl": "pkg:rpm/ol/libnghttp2@1.33.0-3.el8_2.1?arch=x86_64\u0026upstream=nghttp2-1.33.0-3.el8_2.1.src.rpm\u0026distro=ol-8.7",
274183          "swid": {
274184            "attachment": {}
274185          },
274186          "pedigree": {},
274187          "evidence": {},
274188          "signature": {
274189            "signature": {
274190              "publicKey": {}
274191            }
274192          },
274193          "modelCard": {
274194            "modelParameters": {
274195              "approach": {}
274196            },
274197            "quantitativeAnalysis": {
274198              "graphics": {}
274199            },
274200            "considerations": {}
274201          }
274202        },
274203        {
274204          "type": "library",
274205          "bom-ref": "pkg:rpm/ol/libnsl2@1.2.0-2.20180605git4a062cf.el8?arch=x86_64\u0026upstream=libnsl2-1.2.0-2.20180605git4a062cf.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=58f5061bc8a025eb",
274206          "supplier": {},
274207          "publisher": "Oracle America",
274208          "name": "libnsl2",
274209          "version": "1.2.0-2.20180605git4a062cf.el8",
274210          "licenses": [
274211            {
274212              "license": {
274213                "name": "BSD and LGPLv2+"
274214              }
274215            }
274216          ],
274217          "cpe": "cpe:2.3:a:oracleamerica:libnsl2:1.2.0-2.20180605git4a062cf.el8:*:*:*:*:*:*:*",
274218          "purl": "pkg:rpm/ol/libnsl2@1.2.0-2.20180605git4a062cf.el8?arch=x86_64\u0026upstream=libnsl2-1.2.0-2.20180605git4a062cf.el8.src.rpm\u0026distro=ol-8.7",
274219          "swid": {
274220            "attachment": {}
274221          },
274222          "pedigree": {},
274223          "evidence": {},
274224          "signature": {
274225            "signature": {
274226              "publicKey": {}
274227            }
274228          },
274229          "modelCard": {
274230            "modelParameters": {
274231              "approach": {}
274232            },
274233            "quantitativeAnalysis": {
274234              "graphics": {}
274235            },
274236            "considerations": {}
274237          }
274238        },
274239        {
274240          "type": "library",
274241          "bom-ref": "pkg:rpm/ol/libpeas@1.22.0-6.el8?arch=x86_64\u0026upstream=libpeas-1.22.0-6.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=bf861813cb90a1f1",
274242          "supplier": {},
274243          "publisher": "Oracle America",
274244          "name": "libpeas",
274245          "version": "1.22.0-6.el8",
274246          "licenses": [
274247            {
274248              "license": {
274249                "name": "LGPLv2+"
274250              }
274251            }
274252          ],
274253          "cpe": "cpe:2.3:a:oracleamerica:libpeas:1.22.0-6.el8:*:*:*:*:*:*:*",
274254          "purl": "pkg:rpm/ol/libpeas@1.22.0-6.el8?arch=x86_64\u0026upstream=libpeas-1.22.0-6.el8.src.rpm\u0026distro=ol-8.7",
274255          "swid": {
274256            "attachment": {}
274257          },
274258          "pedigree": {},
274259          "evidence": {},
274260          "signature": {
274261            "signature": {
274262              "publicKey": {}
274263            }
274264          },
274265          "modelCard": {
274266            "modelParameters": {
274267              "approach": {}
274268            },
274269            "quantitativeAnalysis": {
274270              "graphics": {}
274271            },
274272            "considerations": {}
274273          }
274274        },
274275        {
274276          "type": "library",
274277          "bom-ref": "pkg:rpm/ol/libpsl@0.20.2-6.el8?arch=x86_64\u0026upstream=libpsl-0.20.2-6.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=58693d112aa15906",
274278          "supplier": {},
274279          "publisher": "Oracle America",
274280          "name": "libpsl",
274281          "version": "0.20.2-6.el8",
274282          "licenses": [
274283            {
274284              "license": {
274285                "id": "MIT"
274286              }
274287            }
274288          ],
274289          "cpe": "cpe:2.3:a:oracleamerica:libpsl:0.20.2-6.el8:*:*:*:*:*:*:*",
274290          "purl": "pkg:rpm/ol/libpsl@0.20.2-6.el8?arch=x86_64\u0026upstream=libpsl-0.20.2-6.el8.src.rpm\u0026distro=ol-8.7",
274291          "swid": {
274292            "attachment": {}
274293          },
274294          "pedigree": {},
274295          "evidence": {},
274296          "signature": {
274297            "signature": {
274298              "publicKey": {}
274299            }
274300          },
274301          "modelCard": {
274302            "modelParameters": {
274303              "approach": {}
274304            },
274305            "quantitativeAnalysis": {
274306              "graphics": {}
274307            },
274308            "considerations": {}
274309          }
274310        },
274311        {
274312          "type": "library",
274313          "bom-ref": "pkg:rpm/ol/librepo@1.14.2-3.el8?arch=x86_64\u0026upstream=librepo-1.14.2-3.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=6f6b6b5b95acf4ba",
274314          "supplier": {},
274315          "publisher": "Oracle America",
274316          "name": "librepo",
274317          "version": "1.14.2-3.el8",
274318          "licenses": [
274319            {
274320              "license": {
274321                "name": "LGPLv2+"
274322              }
274323            }
274324          ],
274325          "cpe": "cpe:2.3:a:oracleamerica:librepo:1.14.2-3.el8:*:*:*:*:*:*:*",
274326          "purl": "pkg:rpm/ol/librepo@1.14.2-3.el8?arch=x86_64\u0026upstream=librepo-1.14.2-3.el8.src.rpm\u0026distro=ol-8.7",
274327          "swid": {
274328            "attachment": {}
274329          },
274330          "pedigree": {},
274331          "evidence": {},
274332          "signature": {
274333            "signature": {
274334              "publicKey": {}
274335            }
274336          },
274337          "modelCard": {
274338            "modelParameters": {
274339              "approach": {}
274340            },
274341            "quantitativeAnalysis": {
274342              "graphics": {}
274343            },
274344            "considerations": {}
274345          }
274346        },
274347        {
274348          "type": "library",
274349          "bom-ref": "pkg:rpm/ol/libselinux@2.9-6.el8?arch=x86_64\u0026upstream=libselinux-2.9-6.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=1c8d7d0c0cc9ce82",
274350          "supplier": {},
274351          "publisher": "Oracle America",
274352          "name": "libselinux",
274353          "version": "2.9-6.el8",
274354          "licenses": [
274355            {
274356              "license": {
274357                "name": "Public Domain"
274358              }
274359            }
274360          ],
274361          "cpe": "cpe:2.3:a:oracleamerica:libselinux:2.9-6.el8:*:*:*:*:*:*:*",
274362          "purl": "pkg:rpm/ol/libselinux@2.9-6.el8?arch=x86_64\u0026upstream=libselinux-2.9-6.el8.src.rpm\u0026distro=ol-8.7",
274363          "swid": {
274364            "attachment": {}
274365          },
274366          "pedigree": {},
274367          "evidence": {},
274368          "signature": {
274369            "signature": {
274370              "publicKey": {}
274371            }
274372          },
274373          "modelCard": {
274374            "modelParameters": {
274375              "approach": {}
274376            },
274377            "quantitativeAnalysis": {
274378              "graphics": {}
274379            },
274380            "considerations": {}
274381          }
274382        },
274383        {
274384          "type": "library",
274385          "bom-ref": "pkg:rpm/ol/libsemanage@2.9-9.el8_6?arch=x86_64\u0026upstream=libsemanage-2.9-9.el8_6.src.rpm\u0026distro=ol-8.7\u0026package-id=254dfe945417481a",
274386          "supplier": {},
274387          "publisher": "Oracle America",
274388          "name": "libsemanage",
274389          "version": "2.9-9.el8_6",
274390          "licenses": [
274391            {
274392              "license": {
274393                "name": "LGPLv2+"
274394              }
274395            }
274396          ],
274397          "cpe": "cpe:2.3:a:oracleamerica:libsemanage:2.9-9.el8_6:*:*:*:*:*:*:*",
274398          "purl": "pkg:rpm/ol/libsemanage@2.9-9.el8_6?arch=x86_64\u0026upstream=libsemanage-2.9-9.el8_6.src.rpm\u0026distro=ol-8.7",
274399          "swid": {
274400            "attachment": {}
274401          },
274402          "pedigree": {},
274403          "evidence": {},
274404          "signature": {
274405            "signature": {
274406              "publicKey": {}
274407            }
274408          },
274409          "modelCard": {
274410            "modelParameters": {
274411              "approach": {}
274412            },
274413            "quantitativeAnalysis": {
274414              "graphics": {}
274415            },
274416            "considerations": {}
274417          }
274418        },
274419        {
274420          "type": "library",
274421          "bom-ref": "pkg:rpm/ol/libsepol@2.9-3.el8?arch=x86_64\u0026upstream=libsepol-2.9-3.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=8bc10f2c92887a7c",
274422          "supplier": {},
274423          "publisher": "Oracle America",
274424          "name": "libsepol",
274425          "version": "2.9-3.el8",
274426          "licenses": [
274427            {
274428              "license": {
274429                "name": "LGPLv2+"
274430              }
274431            }
274432          ],
274433          "cpe": "cpe:2.3:a:oracleamerica:libsepol:2.9-3.el8:*:*:*:*:*:*:*",
274434          "purl": "pkg:rpm/ol/libsepol@2.9-3.el8?arch=x86_64\u0026upstream=libsepol-2.9-3.el8.src.rpm\u0026distro=ol-8.7",
274435          "swid": {
274436            "attachment": {}
274437          },
274438          "pedigree": {},
274439          "evidence": {},
274440          "signature": {
274441            "signature": {
274442              "publicKey": {}
274443            }
274444          },
274445          "modelCard": {
274446            "modelParameters": {
274447              "approach": {}
274448            },
274449            "quantitativeAnalysis": {
274450              "graphics": {}
274451            },
274452            "considerations": {}
274453          }
274454        },
274455        {
274456          "type": "library",
274457          "bom-ref": "pkg:rpm/ol/libsigsegv@2.11-5.el8?arch=x86_64\u0026upstream=libsigsegv-2.11-5.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=3dd0b34668c25f8f",
274458          "supplier": {},
274459          "publisher": "Oracle America",
274460          "name": "libsigsegv",
274461          "version": "2.11-5.el8",
274462          "licenses": [
274463            {
274464              "license": {
274465                "name": "GPLv2+"
274466              }
274467            }
274468          ],
274469          "cpe": "cpe:2.3:a:oracleamerica:libsigsegv:2.11-5.el8:*:*:*:*:*:*:*",
274470          "purl": "pkg:rpm/ol/libsigsegv@2.11-5.el8?arch=x86_64\u0026upstream=libsigsegv-2.11-5.el8.src.rpm\u0026distro=ol-8.7",
274471          "swid": {
274472            "attachment": {}
274473          },
274474          "pedigree": {},
274475          "evidence": {},
274476          "signature": {
274477            "signature": {
274478              "publicKey": {}
274479            }
274480          },
274481          "modelCard": {
274482            "modelParameters": {
274483              "approach": {}
274484            },
274485            "quantitativeAnalysis": {
274486              "graphics": {}
274487            },
274488            "considerations": {}
274489          }
274490        },
274491        {
274492          "type": "library",
274493          "bom-ref": "pkg:rpm/ol/libsmartcols@2.32.1-39.el8_7?arch=x86_64\u0026upstream=util-linux-2.32.1-39.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=13fae55b6eee01d6",
274494          "supplier": {},
274495          "publisher": "Oracle America",
274496          "name": "libsmartcols",
274497          "version": "2.32.1-39.el8_7",
274498          "licenses": [
274499            {
274500              "license": {
274501                "name": "LGPLv2+"
274502              }
274503            }
274504          ],
274505          "cpe": "cpe:2.3:a:oracleamerica:libsmartcols:2.32.1-39.el8_7:*:*:*:*:*:*:*",
274506          "purl": "pkg:rpm/ol/libsmartcols@2.32.1-39.el8_7?arch=x86_64\u0026upstream=util-linux-2.32.1-39.el8_7.src.rpm\u0026distro=ol-8.7",
274507          "swid": {
274508            "attachment": {}
274509          },
274510          "pedigree": {},
274511          "evidence": {},
274512          "signature": {
274513            "signature": {
274514              "publicKey": {}
274515            }
274516          },
274517          "modelCard": {
274518            "modelParameters": {
274519              "approach": {}
274520            },
274521            "quantitativeAnalysis": {
274522              "graphics": {}
274523            },
274524            "considerations": {}
274525          }
274526        },
274527        {
274528          "type": "library",
274529          "bom-ref": "pkg:rpm/ol/libsolv@0.7.20-4.el8_7?arch=x86_64\u0026upstream=libsolv-0.7.20-4.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=7acb1b46b8ef74ca",
274530          "supplier": {},
274531          "publisher": "Oracle America",
274532          "name": "libsolv",
274533          "version": "0.7.20-4.el8_7",
274534          "licenses": [
274535            {
274536              "license": {
274537                "name": "BSD"
274538              }
274539            }
274540          ],
274541          "cpe": "cpe:2.3:a:oracleamerica:libsolv:0.7.20-4.el8_7:*:*:*:*:*:*:*",
274542          "purl": "pkg:rpm/ol/libsolv@0.7.20-4.el8_7?arch=x86_64\u0026upstream=libsolv-0.7.20-4.el8_7.src.rpm\u0026distro=ol-8.7",
274543          "swid": {
274544            "attachment": {}
274545          },
274546          "pedigree": {},
274547          "evidence": {},
274548          "signature": {
274549            "signature": {
274550              "publicKey": {}
274551            }
274552          },
274553          "modelCard": {
274554            "modelParameters": {
274555              "approach": {}
274556            },
274557            "quantitativeAnalysis": {
274558              "graphics": {}
274559            },
274560            "considerations": {}
274561          }
274562        },
274563        {
274564          "type": "library",
274565          "bom-ref": "pkg:rpm/ol/libssh@0.9.6-3.el8?arch=x86_64\u0026upstream=libssh-0.9.6-3.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=f91185faca80875c",
274566          "supplier": {},
274567          "publisher": "Oracle America",
274568          "name": "libssh",
274569          "version": "0.9.6-3.el8",
274570          "licenses": [
274571            {
274572              "license": {
274573                "name": "LGPLv2+"
274574              }
274575            }
274576          ],
274577          "cpe": "cpe:2.3:a:oracleamerica:libssh:0.9.6-3.el8:*:*:*:*:*:*:*",
274578          "purl": "pkg:rpm/ol/libssh@0.9.6-3.el8?arch=x86_64\u0026upstream=libssh-0.9.6-3.el8.src.rpm\u0026distro=ol-8.7",
274579          "swid": {
274580            "attachment": {}
274581          },
274582          "pedigree": {},
274583          "evidence": {},
274584          "signature": {
274585            "signature": {
274586              "publicKey": {}
274587            }
274588          },
274589          "modelCard": {
274590            "modelParameters": {
274591              "approach": {}
274592            },
274593            "quantitativeAnalysis": {
274594              "graphics": {}
274595            },
274596            "considerations": {}
274597          }
274598        },
274599        {
274600          "type": "library",
274601          "bom-ref": "pkg:rpm/ol/libssh-config@0.9.6-3.el8?arch=noarch\u0026upstream=libssh-0.9.6-3.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=671fc31e1cabe36d",
274602          "supplier": {},
274603          "publisher": "Oracle America",
274604          "name": "libssh-config",
274605          "version": "0.9.6-3.el8",
274606          "licenses": [
274607            {
274608              "license": {
274609                "name": "LGPLv2+"
274610              }
274611            }
274612          ],
274613          "cpe": "cpe:2.3:a:libssh-config:libssh-config:0.9.6-3.el8:*:*:*:*:*:*:*",
274614          "purl": "pkg:rpm/ol/libssh-config@0.9.6-3.el8?arch=noarch\u0026upstream=libssh-0.9.6-3.el8.src.rpm\u0026distro=ol-8.7",
274615          "swid": {
274616            "attachment": {}
274617          },
274618          "pedigree": {},
274619          "evidence": {},
274620          "signature": {
274621            "signature": {
274622              "publicKey": {}
274623            }
274624          },
274625          "modelCard": {
274626            "modelParameters": {
274627              "approach": {}
274628            },
274629            "quantitativeAnalysis": {
274630              "graphics": {}
274631            },
274632            "considerations": {}
274633          }
274634        },
274635        {
274636          "type": "library",
274637          "bom-ref": "pkg:rpm/ol/libstdc++@8.5.0-16.0.2.el8_7?arch=x86_64\u0026upstream=gcc-8.5.0-16.0.2.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=c2136b2c3c7ba1de",
274638          "supplier": {},
274639          "publisher": "Oracle America",
274640          "name": "libstdc++",
274641          "version": "8.5.0-16.0.2.el8_7",
274642          "licenses": [
274643            {
274644              "license": {
274645                "name": "GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"
274646              }
274647            }
274648          ],
274649          "cpe": "cpe:2.3:a:oracleamerica:libstdc\\+\\+:8.5.0-16.0.2.el8_7:*:*:*:*:*:*:*",
274650          "purl": "pkg:rpm/ol/libstdc++@8.5.0-16.0.2.el8_7?arch=x86_64\u0026upstream=gcc-8.5.0-16.0.2.el8_7.src.rpm\u0026distro=ol-8.7",
274651          "swid": {
274652            "attachment": {}
274653          },
274654          "pedigree": {},
274655          "evidence": {},
274656          "signature": {
274657            "signature": {
274658              "publicKey": {}
274659            }
274660          },
274661          "modelCard": {
274662            "modelParameters": {
274663              "approach": {}
274664            },
274665            "quantitativeAnalysis": {
274666              "graphics": {}
274667            },
274668            "considerations": {}
274669          }
274670        },
274671        {
274672          "type": "library",
274673          "bom-ref": "pkg:rpm/ol/libtasn1@4.13-4.el8_7?arch=x86_64\u0026upstream=libtasn1-4.13-4.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=ab8d2660032a506b",
274674          "supplier": {},
274675          "publisher": "Oracle America",
274676          "name": "libtasn1",
274677          "version": "4.13-4.el8_7",
274678          "licenses": [
274679            {
274680              "license": {
274681                "name": "GPLv3+ and LGPLv2+"
274682              }
274683            }
274684          ],
274685          "cpe": "cpe:2.3:a:oracleamerica:libtasn1:4.13-4.el8_7:*:*:*:*:*:*:*",
274686          "purl": "pkg:rpm/ol/libtasn1@4.13-4.el8_7?arch=x86_64\u0026upstream=libtasn1-4.13-4.el8_7.src.rpm\u0026distro=ol-8.7",
274687          "swid": {
274688            "attachment": {}
274689          },
274690          "pedigree": {},
274691          "evidence": {},
274692          "signature": {
274693            "signature": {
274694              "publicKey": {}
274695            }
274696          },
274697          "modelCard": {
274698            "modelParameters": {
274699              "approach": {}
274700            },
274701            "quantitativeAnalysis": {
274702              "graphics": {}
274703            },
274704            "considerations": {}
274705          }
274706        },
274707        {
274708          "type": "library",
274709          "bom-ref": "pkg:rpm/ol/libtirpc@1.1.4-8.el8?arch=x86_64\u0026upstream=libtirpc-1.1.4-8.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=a74a2463b1f0aed5",
274710          "supplier": {},
274711          "publisher": "Oracle America",
274712          "name": "libtirpc",
274713          "version": "1.1.4-8.el8",
274714          "licenses": [
274715            {
274716              "license": {
274717                "name": "SISSL and BSD"
274718              }
274719            }
274720          ],
274721          "cpe": "cpe:2.3:a:oracleamerica:libtirpc:1.1.4-8.el8:*:*:*:*:*:*:*",
274722          "purl": "pkg:rpm/ol/libtirpc@1.1.4-8.el8?arch=x86_64\u0026upstream=libtirpc-1.1.4-8.el8.src.rpm\u0026distro=ol-8.7",
274723          "swid": {
274724            "attachment": {}
274725          },
274726          "pedigree": {},
274727          "evidence": {},
274728          "signature": {
274729            "signature": {
274730              "publicKey": {}
274731            }
274732          },
274733          "modelCard": {
274734            "modelParameters": {
274735              "approach": {}
274736            },
274737            "quantitativeAnalysis": {
274738              "graphics": {}
274739            },
274740            "considerations": {}
274741          }
274742        },
274743        {
274744          "type": "library",
274745          "bom-ref": "pkg:rpm/ol/libunistring@0.9.9-3.el8?arch=x86_64\u0026upstream=libunistring-0.9.9-3.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=b33dd68084d51a1a",
274746          "supplier": {},
274747          "publisher": "Oracle America",
274748          "name": "libunistring",
274749          "version": "0.9.9-3.el8",
274750          "licenses": [
274751            {
274752              "license": {
274753                "name": "GPLv2+ or LGPLv3+"
274754              }
274755            }
274756          ],
274757          "cpe": "cpe:2.3:a:oracleamerica:libunistring:0.9.9-3.el8:*:*:*:*:*:*:*",
274758          "purl": "pkg:rpm/ol/libunistring@0.9.9-3.el8?arch=x86_64\u0026upstream=libunistring-0.9.9-3.el8.src.rpm\u0026distro=ol-8.7",
274759          "swid": {
274760            "attachment": {}
274761          },
274762          "pedigree": {},
274763          "evidence": {},
274764          "signature": {
274765            "signature": {
274766              "publicKey": {}
274767            }
274768          },
274769          "modelCard": {
274770            "modelParameters": {
274771              "approach": {}
274772            },
274773            "quantitativeAnalysis": {
274774              "graphics": {}
274775            },
274776            "considerations": {}
274777          }
274778        },
274779        {
274780          "type": "library",
274781          "bom-ref": "pkg:rpm/ol/libusbx@1.0.23-4.el8?arch=x86_64\u0026upstream=libusbx-1.0.23-4.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=691946e9302c756f",
274782          "supplier": {},
274783          "publisher": "Oracle America",
274784          "name": "libusbx",
274785          "version": "1.0.23-4.el8",
274786          "licenses": [
274787            {
274788              "license": {
274789                "name": "LGPLv2+"
274790              }
274791            }
274792          ],
274793          "cpe": "cpe:2.3:a:oracleamerica:libusbx:1.0.23-4.el8:*:*:*:*:*:*:*",
274794          "purl": "pkg:rpm/ol/libusbx@1.0.23-4.el8?arch=x86_64\u0026upstream=libusbx-1.0.23-4.el8.src.rpm\u0026distro=ol-8.7",
274795          "swid": {
274796            "attachment": {}
274797          },
274798          "pedigree": {},
274799          "evidence": {},
274800          "signature": {
274801            "signature": {
274802              "publicKey": {}
274803            }
274804          },
274805          "modelCard": {
274806            "modelParameters": {
274807              "approach": {}
274808            },
274809            "quantitativeAnalysis": {
274810              "graphics": {}
274811            },
274812            "considerations": {}
274813          }
274814        },
274815        {
274816          "type": "library",
274817          "bom-ref": "pkg:rpm/ol/libuuid@2.32.1-39.el8_7?arch=x86_64\u0026upstream=util-linux-2.32.1-39.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=41299e31e11888ac",
274818          "supplier": {},
274819          "publisher": "Oracle America",
274820          "name": "libuuid",
274821          "version": "2.32.1-39.el8_7",
274822          "licenses": [
274823            {
274824              "license": {
274825                "name": "BSD"
274826              }
274827            }
274828          ],
274829          "cpe": "cpe:2.3:a:oracleamerica:libuuid:2.32.1-39.el8_7:*:*:*:*:*:*:*",
274830          "purl": "pkg:rpm/ol/libuuid@2.32.1-39.el8_7?arch=x86_64\u0026upstream=util-linux-2.32.1-39.el8_7.src.rpm\u0026distro=ol-8.7",
274831          "swid": {
274832            "attachment": {}
274833          },
274834          "pedigree": {},
274835          "evidence": {},
274836          "signature": {
274837            "signature": {
274838              "publicKey": {}
274839            }
274840          },
274841          "modelCard": {
274842            "modelParameters": {
274843              "approach": {}
274844            },
274845            "quantitativeAnalysis": {
274846              "graphics": {}
274847            },
274848            "considerations": {}
274849          }
274850        },
274851        {
274852          "type": "library",
274853          "bom-ref": "pkg:rpm/ol/libverto@0.3.2-2.el8?arch=x86_64\u0026upstream=libverto-0.3.2-2.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=6b382e0882feb5c3",
274854          "supplier": {},
274855          "publisher": "Oracle America",
274856          "name": "libverto",
274857          "version": "0.3.2-2.el8",
274858          "licenses": [
274859            {
274860              "license": {
274861                "id": "MIT"
274862              }
274863            }
274864          ],
274865          "cpe": "cpe:2.3:a:oracleamerica:libverto:0.3.2-2.el8:*:*:*:*:*:*:*",
274866          "purl": "pkg:rpm/ol/libverto@0.3.2-2.el8?arch=x86_64\u0026upstream=libverto-0.3.2-2.el8.src.rpm\u0026distro=ol-8.7",
274867          "swid": {
274868            "attachment": {}
274869          },
274870          "pedigree": {},
274871          "evidence": {},
274872          "signature": {
274873            "signature": {
274874              "publicKey": {}
274875            }
274876          },
274877          "modelCard": {
274878            "modelParameters": {
274879              "approach": {}
274880            },
274881            "quantitativeAnalysis": {
274882              "graphics": {}
274883            },
274884            "considerations": {}
274885          }
274886        },
274887        {
274888          "type": "library",
274889          "bom-ref": "pkg:rpm/ol/libxcrypt@4.1.1-6.el8?arch=x86_64\u0026upstream=libxcrypt-4.1.1-6.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=e91ea013c4fb9f33",
274890          "supplier": {},
274891          "publisher": "Oracle America",
274892          "name": "libxcrypt",
274893          "version": "4.1.1-6.el8",
274894          "licenses": [
274895            {
274896              "license": {
274897                "name": "LGPLv2+ and BSD and Public Domain"
274898              }
274899            }
274900          ],
274901          "cpe": "cpe:2.3:a:oracleamerica:libxcrypt:4.1.1-6.el8:*:*:*:*:*:*:*",
274902          "purl": "pkg:rpm/ol/libxcrypt@4.1.1-6.el8?arch=x86_64\u0026upstream=libxcrypt-4.1.1-6.el8.src.rpm\u0026distro=ol-8.7",
274903          "swid": {
274904            "attachment": {}
274905          },
274906          "pedigree": {},
274907          "evidence": {},
274908          "signature": {
274909            "signature": {
274910              "publicKey": {}
274911            }
274912          },
274913          "modelCard": {
274914            "modelParameters": {
274915              "approach": {}
274916            },
274917            "quantitativeAnalysis": {
274918              "graphics": {}
274919            },
274920            "considerations": {}
274921          }
274922        },
274923        {
274924          "type": "library",
274925          "bom-ref": "pkg:rpm/ol/libxml2@2.9.7-15.el8_7.1?arch=x86_64\u0026upstream=libxml2-2.9.7-15.el8_7.1.src.rpm\u0026distro=ol-8.7\u0026package-id=500ca92c011313ee",
274926          "supplier": {},
274927          "publisher": "Oracle America",
274928          "name": "libxml2",
274929          "version": "2.9.7-15.el8_7.1",
274930          "licenses": [
274931            {
274932              "license": {
274933                "id": "MIT"
274934              }
274935            }
274936          ],
274937          "cpe": "cpe:2.3:a:oracleamerica:libxml2:2.9.7-15.el8_7.1:*:*:*:*:*:*:*",
274938          "purl": "pkg:rpm/ol/libxml2@2.9.7-15.el8_7.1?arch=x86_64\u0026upstream=libxml2-2.9.7-15.el8_7.1.src.rpm\u0026distro=ol-8.7",
274939          "swid": {
274940            "attachment": {}
274941          },
274942          "pedigree": {},
274943          "evidence": {},
274944          "signature": {
274945            "signature": {
274946              "publicKey": {}
274947            }
274948          },
274949          "modelCard": {
274950            "modelParameters": {
274951              "approach": {}
274952            },
274953            "quantitativeAnalysis": {
274954              "graphics": {}
274955            },
274956            "considerations": {}
274957          }
274958        },
274959        {
274960          "type": "library",
274961          "bom-ref": "pkg:rpm/ol/libyaml@0.1.7-5.el8?arch=x86_64\u0026upstream=libyaml-0.1.7-5.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=4b5582801a6068fa",
274962          "supplier": {},
274963          "publisher": "Oracle America",
274964          "name": "libyaml",
274965          "version": "0.1.7-5.el8",
274966          "licenses": [
274967            {
274968              "license": {
274969                "id": "MIT"
274970              }
274971            }
274972          ],
274973          "cpe": "cpe:2.3:a:oracleamerica:libyaml:0.1.7-5.el8:*:*:*:*:*:*:*",
274974          "purl": "pkg:rpm/ol/libyaml@0.1.7-5.el8?arch=x86_64\u0026upstream=libyaml-0.1.7-5.el8.src.rpm\u0026distro=ol-8.7",
274975          "swid": {
274976            "attachment": {}
274977          },
274978          "pedigree": {},
274979          "evidence": {},
274980          "signature": {
274981            "signature": {
274982              "publicKey": {}
274983            }
274984          },
274985          "modelCard": {
274986            "modelParameters": {
274987              "approach": {}
274988            },
274989            "quantitativeAnalysis": {
274990              "graphics": {}
274991            },
274992            "considerations": {}
274993          }
274994        },
274995        {
274996          "type": "library",
274997          "bom-ref": "pkg:rpm/ol/libzstd@1.4.4-1.0.1.el8?arch=x86_64\u0026upstream=zstd-1.4.4-1.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=a0e95baed275968a",
274998          "supplier": {},
274999          "publisher": "Oracle America",
275000          "name": "libzstd",
275001          "version": "1.4.4-1.0.1.el8",
275002          "licenses": [
275003            {
275004              "license": {
275005                "name": "BSD and GPLv2"
275006              }
275007            }
275008          ],
275009          "cpe": "cpe:2.3:a:oracleamerica:libzstd:1.4.4-1.0.1.el8:*:*:*:*:*:*:*",
275010          "purl": "pkg:rpm/ol/libzstd@1.4.4-1.0.1.el8?arch=x86_64\u0026upstream=zstd-1.4.4-1.0.1.el8.src.rpm\u0026distro=ol-8.7",
275011          "swid": {
275012            "attachment": {}
275013          },
275014          "pedigree": {},
275015          "evidence": {},
275016          "signature": {
275017            "signature": {
275018              "publicKey": {}
275019            }
275020          },
275021          "modelCard": {
275022            "modelParameters": {
275023              "approach": {}
275024            },
275025            "quantitativeAnalysis": {
275026              "graphics": {}
275027            },
275028            "considerations": {}
275029          }
275030        },
275031        {
275032          "type": "library",
275033          "bom-ref": "pkg:rpm/ol/lua-libs@5.3.4-12.el8?arch=x86_64\u0026upstream=lua-5.3.4-12.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=c37eda33497510c1",
275034          "supplier": {},
275035          "publisher": "Oracle America",
275036          "name": "lua-libs",
275037          "version": "5.3.4-12.el8",
275038          "licenses": [
275039            {
275040              "license": {
275041                "id": "MIT"
275042              }
275043            }
275044          ],
275045          "cpe": "cpe:2.3:a:oracleamerica:lua-libs:5.3.4-12.el8:*:*:*:*:*:*:*",
275046          "purl": "pkg:rpm/ol/lua-libs@5.3.4-12.el8?arch=x86_64\u0026upstream=lua-5.3.4-12.el8.src.rpm\u0026distro=ol-8.7",
275047          "swid": {
275048            "attachment": {}
275049          },
275050          "pedigree": {},
275051          "evidence": {},
275052          "signature": {
275053            "signature": {
275054              "publicKey": {}
275055            }
275056          },
275057          "modelCard": {
275058            "modelParameters": {
275059              "approach": {}
275060            },
275061            "quantitativeAnalysis": {
275062              "graphics": {}
275063            },
275064            "considerations": {}
275065          }
275066        },
275067        {
275068          "type": "library",
275069          "bom-ref": "pkg:rpm/ol/lz4-libs@1.8.3-3.el8_4?arch=x86_64\u0026upstream=lz4-1.8.3-3.el8_4.src.rpm\u0026distro=ol-8.7\u0026package-id=be86401f2c718b8d",
275070          "supplier": {},
275071          "publisher": "Oracle America",
275072          "name": "lz4-libs",
275073          "version": "1.8.3-3.el8_4",
275074          "licenses": [
275075            {
275076              "license": {
275077                "name": "GPLv2+ and BSD"
275078              }
275079            }
275080          ],
275081          "cpe": "cpe:2.3:a:oracleamerica:lz4-libs:1.8.3-3.el8_4:*:*:*:*:*:*:*",
275082          "purl": "pkg:rpm/ol/lz4-libs@1.8.3-3.el8_4?arch=x86_64\u0026upstream=lz4-1.8.3-3.el8_4.src.rpm\u0026distro=ol-8.7",
275083          "swid": {
275084            "attachment": {}
275085          },
275086          "pedigree": {},
275087          "evidence": {},
275088          "signature": {
275089            "signature": {
275090              "publicKey": {}
275091            }
275092          },
275093          "modelCard": {
275094            "modelParameters": {
275095              "approach": {}
275096            },
275097            "quantitativeAnalysis": {
275098              "graphics": {}
275099            },
275100            "considerations": {}
275101          }
275102        },
275103        {
275104          "type": "library",
275105          "bom-ref": "pkg:rpm/ol/microdnf@3.8.0-2.el8?arch=x86_64\u0026upstream=microdnf-3.8.0-2.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=9c575ad34c969036",
275106          "supplier": {},
275107          "publisher": "Oracle America",
275108          "name": "microdnf",
275109          "version": "3.8.0-2.el8",
275110          "licenses": [
275111            {
275112              "license": {
275113                "name": "GPLv2+"
275114              }
275115            }
275116          ],
275117          "cpe": "cpe:2.3:a:oracleamerica:microdnf:3.8.0-2.el8:*:*:*:*:*:*:*",
275118          "purl": "pkg:rpm/ol/microdnf@3.8.0-2.el8?arch=x86_64\u0026upstream=microdnf-3.8.0-2.el8.src.rpm\u0026distro=ol-8.7",
275119          "swid": {
275120            "attachment": {}
275121          },
275122          "pedigree": {},
275123          "evidence": {},
275124          "signature": {
275125            "signature": {
275126              "publicKey": {}
275127            }
275128          },
275129          "modelCard": {
275130            "modelParameters": {
275131              "approach": {}
275132            },
275133            "quantitativeAnalysis": {
275134              "graphics": {}
275135            },
275136            "considerations": {}
275137          }
275138        },
275139        {
275140          "type": "library",
275141          "bom-ref": "pkg:rpm/ol/mpfr@3.1.6-1.el8?arch=x86_64\u0026upstream=mpfr-3.1.6-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=bd41794f5f68c1f1",
275142          "supplier": {},
275143          "publisher": "Oracle America",
275144          "name": "mpfr",
275145          "version": "3.1.6-1.el8",
275146          "licenses": [
275147            {
275148              "license": {
275149                "name": "LGPLv3+ and GPLv3+ and GFDL"
275150              }
275151            }
275152          ],
275153          "cpe": "cpe:2.3:a:oracleamerica:mpfr:3.1.6-1.el8:*:*:*:*:*:*:*",
275154          "purl": "pkg:rpm/ol/mpfr@3.1.6-1.el8?arch=x86_64\u0026upstream=mpfr-3.1.6-1.el8.src.rpm\u0026distro=ol-8.7",
275155          "swid": {
275156            "attachment": {}
275157          },
275158          "pedigree": {},
275159          "evidence": {},
275160          "signature": {
275161            "signature": {
275162              "publicKey": {}
275163            }
275164          },
275165          "modelCard": {
275166            "modelParameters": {
275167              "approach": {}
275168            },
275169            "quantitativeAnalysis": {
275170              "graphics": {}
275171            },
275172            "considerations": {}
275173          }
275174        },
275175        {
275176          "type": "library",
275177          "bom-ref": "pkg:rpm/ol/mysql-community-server-minimal@8.0.33-1.el8?arch=x86_64\u0026upstream=mysql-community-minimal-8.0.33-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=d8d79cfe19830b75",
275178          "supplier": {},
275179          "publisher": "Oracle and/or its affiliates",
275180          "name": "mysql-community-server-minimal",
275181          "version": "8.0.33-1.el8",
275182          "licenses": [
275183            {
275184              "license": {
275185                "name": "Copyright (c) 2000, 2023, Oracle and/or its affiliates. Under GPLv2 license as shown in the Description field."
275186              }
275187            }
275188          ],
275189          "cpe": "cpe:2.3:a:mysql-community-server-minimal:mysql-community-server-minimal:8.0.33-1.el8:*:*:*:*:*:*:*",
275190          "purl": "pkg:rpm/ol/mysql-community-server-minimal@8.0.33-1.el8?arch=x86_64\u0026upstream=mysql-community-minimal-8.0.33-1.el8.src.rpm\u0026distro=ol-8.7",
275191          "swid": {
275192            "attachment": {}
275193          },
275194          "pedigree": {},
275195          "evidence": {},
275196          "signature": {
275197            "signature": {
275198              "publicKey": {}
275199            }
275200          },
275201          "modelCard": {
275202            "modelParameters": {
275203              "approach": {}
275204            },
275205            "quantitativeAnalysis": {
275206              "graphics": {}
275207            },
275208            "considerations": {}
275209          }
275210        },
275211        {
275212          "type": "library",
275213          "bom-ref": "pkg:rpm/ol/mysql-shell@8.0.33-1.el8?arch=x86_64\u0026upstream=mysql-shell-8.0.33-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=857236a38e621f4f",
275214          "supplier": {},
275215          "name": "mysql-shell",
275216          "version": "8.0.33-1.el8",
275217          "licenses": [
275218            {
275219              "license": {
275220                "name": "GPLv2"
275221              }
275222            }
275223          ],
275224          "cpe": "cpe:2.3:a:mysql-shell:mysql-shell:8.0.33-1.el8:*:*:*:*:*:*:*",
275225          "purl": "pkg:rpm/ol/mysql-shell@8.0.33-1.el8?arch=x86_64\u0026upstream=mysql-shell-8.0.33-1.el8.src.rpm\u0026distro=ol-8.7",
275226          "swid": {
275227            "attachment": {}
275228          },
275229          "pedigree": {},
275230          "evidence": {},
275231          "signature": {
275232            "signature": {
275233              "publicKey": {}
275234            }
275235          },
275236          "modelCard": {
275237            "modelParameters": {
275238              "approach": {}
275239            },
275240            "quantitativeAnalysis": {
275241              "graphics": {}
275242            },
275243            "considerations": {}
275244          }
275245        },
275246        {
275247          "type": "library",
275248          "bom-ref": "pkg:rpm/ol/ncurses-base@6.1-9.20180224.el8?arch=noarch\u0026upstream=ncurses-6.1-9.20180224.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=472d1235a72f8987",
275249          "supplier": {},
275250          "publisher": "Oracle America",
275251          "name": "ncurses-base",
275252          "version": "6.1-9.20180224.el8",
275253          "licenses": [
275254            {
275255              "license": {
275256                "id": "MIT"
275257              }
275258            }
275259          ],
275260          "cpe": "cpe:2.3:a:oracleamerica:ncurses-base:6.1-9.20180224.el8:*:*:*:*:*:*:*",
275261          "purl": "pkg:rpm/ol/ncurses-base@6.1-9.20180224.el8?arch=noarch\u0026upstream=ncurses-6.1-9.20180224.el8.src.rpm\u0026distro=ol-8.7",
275262          "swid": {
275263            "attachment": {}
275264          },
275265          "pedigree": {},
275266          "evidence": {},
275267          "signature": {
275268            "signature": {
275269              "publicKey": {}
275270            }
275271          },
275272          "modelCard": {
275273            "modelParameters": {
275274              "approach": {}
275275            },
275276            "quantitativeAnalysis": {
275277              "graphics": {}
275278            },
275279            "considerations": {}
275280          }
275281        },
275282        {
275283          "type": "library",
275284          "bom-ref": "pkg:rpm/ol/ncurses-libs@6.1-9.20180224.el8?arch=x86_64\u0026upstream=ncurses-6.1-9.20180224.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=ca1f9d1000109598",
275285          "supplier": {},
275286          "publisher": "Oracle America",
275287          "name": "ncurses-libs",
275288          "version": "6.1-9.20180224.el8",
275289          "licenses": [
275290            {
275291              "license": {
275292                "id": "MIT"
275293              }
275294            }
275295          ],
275296          "cpe": "cpe:2.3:a:oracleamerica:ncurses-libs:6.1-9.20180224.el8:*:*:*:*:*:*:*",
275297          "purl": "pkg:rpm/ol/ncurses-libs@6.1-9.20180224.el8?arch=x86_64\u0026upstream=ncurses-6.1-9.20180224.el8.src.rpm\u0026distro=ol-8.7",
275298          "swid": {
275299            "attachment": {}
275300          },
275301          "pedigree": {},
275302          "evidence": {},
275303          "signature": {
275304            "signature": {
275305              "publicKey": {}
275306            }
275307          },
275308          "modelCard": {
275309            "modelParameters": {
275310              "approach": {}
275311            },
275312            "quantitativeAnalysis": {
275313              "graphics": {}
275314            },
275315            "considerations": {}
275316          }
275317        },
275318        {
275319          "type": "library",
275320          "bom-ref": "pkg:rpm/ol/nettle@3.4.1-7.el8?arch=x86_64\u0026upstream=nettle-3.4.1-7.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=957b73d7046982e1",
275321          "supplier": {},
275322          "publisher": "Oracle America",
275323          "name": "nettle",
275324          "version": "3.4.1-7.el8",
275325          "licenses": [
275326            {
275327              "license": {
275328                "name": "LGPLv3+ or GPLv2+"
275329              }
275330            }
275331          ],
275332          "cpe": "cpe:2.3:a:oracleamerica:nettle:3.4.1-7.el8:*:*:*:*:*:*:*",
275333          "purl": "pkg:rpm/ol/nettle@3.4.1-7.el8?arch=x86_64\u0026upstream=nettle-3.4.1-7.el8.src.rpm\u0026distro=ol-8.7",
275334          "swid": {
275335            "attachment": {}
275336          },
275337          "pedigree": {},
275338          "evidence": {},
275339          "signature": {
275340            "signature": {
275341              "publicKey": {}
275342            }
275343          },
275344          "modelCard": {
275345            "modelParameters": {
275346              "approach": {}
275347            },
275348            "quantitativeAnalysis": {
275349              "graphics": {}
275350            },
275351            "considerations": {}
275352          }
275353        },
275354        {
275355          "type": "library",
275356          "bom-ref": "pkg:rpm/ol/npth@1.5-4.el8?arch=x86_64\u0026upstream=npth-1.5-4.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=6a18d496b862d465",
275357          "supplier": {},
275358          "publisher": "Oracle America",
275359          "name": "npth",
275360          "version": "1.5-4.el8",
275361          "licenses": [
275362            {
275363              "license": {
275364                "name": "LGPLv2+"
275365              }
275366            }
275367          ],
275368          "cpe": "cpe:2.3:a:oracleamerica:npth:1.5-4.el8:*:*:*:*:*:*:*",
275369          "purl": "pkg:rpm/ol/npth@1.5-4.el8?arch=x86_64\u0026upstream=npth-1.5-4.el8.src.rpm\u0026distro=ol-8.7",
275370          "swid": {
275371            "attachment": {}
275372          },
275373          "pedigree": {},
275374          "evidence": {},
275375          "signature": {
275376            "signature": {
275377              "publicKey": {}
275378            }
275379          },
275380          "modelCard": {
275381            "modelParameters": {
275382              "approach": {}
275383            },
275384            "quantitativeAnalysis": {
275385              "graphics": {}
275386            },
275387            "considerations": {}
275388          }
275389        },
275390        {
275391          "type": "library",
275392          "bom-ref": "pkg:pypi/oci@2.90.2?package-id=5613828303c541bf",
275393          "supplier": {},
275394          "author": "Oracle \u003cjoe.levy@oracle.com\u003e",
275395          "name": "oci",
275396          "version": "2.90.2",
275397          "licenses": [
275398            {
275399              "license": {
275400                "name": "Universal Permissive License 1.0 or Apache License 2.0"
275401              }
275402            }
275403          ],
275404          "cpe": "cpe:2.3:a:joe_levy_project:python-oci:2.90.2:*:*:*:*:*:*:*",
275405          "purl": "pkg:pypi/oci@2.90.2",
275406          "swid": {
275407            "attachment": {}
275408          },
275409          "pedigree": {},
275410          "externalReferences": [
275411            {
275412              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/ae/b9/d5/f4e02150fe72eb4a3a498b88a7c1b710698297308782982c60/oci-2.90.2-py2.py3-none-any.whl",
275413              "type": "vcs"
275414            }
275415          ],
275416          "evidence": {},
275417          "signature": {
275418            "signature": {
275419              "publicKey": {}
275420            }
275421          },
275422          "modelCard": {
275423            "modelParameters": {
275424              "approach": {}
275425            },
275426            "quantitativeAnalysis": {
275427              "graphics": {}
275428            },
275429            "considerations": {}
275430          }
275431        },
275432        {
275433          "type": "library",
275434          "bom-ref": "pkg:rpm/ol/openldap@2.4.46-18.el8?arch=x86_64\u0026upstream=openldap-2.4.46-18.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=16036542ca1d4138",
275435          "supplier": {},
275436          "publisher": "Oracle America",
275437          "name": "openldap",
275438          "version": "2.4.46-18.el8",
275439          "licenses": [
275440            {
275441              "license": {
275442                "name": "OpenLDAP"
275443              }
275444            }
275445          ],
275446          "cpe": "cpe:2.3:a:oracleamerica:openldap:2.4.46-18.el8:*:*:*:*:*:*:*",
275447          "purl": "pkg:rpm/ol/openldap@2.4.46-18.el8?arch=x86_64\u0026upstream=openldap-2.4.46-18.el8.src.rpm\u0026distro=ol-8.7",
275448          "swid": {
275449            "attachment": {}
275450          },
275451          "pedigree": {},
275452          "evidence": {},
275453          "signature": {
275454            "signature": {
275455              "publicKey": {}
275456            }
275457          },
275458          "modelCard": {
275459            "modelParameters": {
275460              "approach": {}
275461            },
275462            "quantitativeAnalysis": {
275463              "graphics": {}
275464            },
275465            "considerations": {}
275466          }
275467        },
275468        {
275469          "type": "library",
275470          "bom-ref": "pkg:rpm/ol/openssl@1.1.1k-9.el8_7?arch=x86_64\u0026epoch=1\u0026upstream=openssl-1.1.1k-9.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=d3f79ca423d643e3",
275471          "supplier": {},
275472          "publisher": "Oracle America",
275473          "name": "openssl",
275474          "version": "1:1.1.1k-9.el8_7",
275475          "licenses": [
275476            {
275477              "license": {
275478                "name": "OpenSSL and ASL 2.0"
275479              }
275480            }
275481          ],
275482          "cpe": "cpe:2.3:a:oracleamerica:openssl:1\\:1.1.1k-9.el8_7:*:*:*:*:*:*:*",
275483          "purl": "pkg:rpm/ol/openssl@1.1.1k-9.el8_7?arch=x86_64\u0026epoch=1\u0026upstream=openssl-1.1.1k-9.el8_7.src.rpm\u0026distro=ol-8.7",
275484          "swid": {
275485            "attachment": {}
275486          },
275487          "pedigree": {},
275488          "evidence": {},
275489          "signature": {
275490            "signature": {
275491              "publicKey": {}
275492            }
275493          },
275494          "modelCard": {
275495            "modelParameters": {
275496              "approach": {}
275497            },
275498            "quantitativeAnalysis": {
275499              "graphics": {}
275500            },
275501            "considerations": {}
275502          }
275503        },
275504        {
275505          "type": "library",
275506          "bom-ref": "pkg:rpm/ol/openssl-libs@1.1.1k-9.el8_7?arch=x86_64\u0026epoch=1\u0026upstream=openssl-1.1.1k-9.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=6c3510e13fd97d1b",
275507          "supplier": {},
275508          "publisher": "Oracle America",
275509          "name": "openssl-libs",
275510          "version": "1:1.1.1k-9.el8_7",
275511          "licenses": [
275512            {
275513              "license": {
275514                "name": "OpenSSL and ASL 2.0"
275515              }
275516            }
275517          ],
275518          "cpe": "cpe:2.3:a:oracleamerica:openssl-libs:1\\:1.1.1k-9.el8_7:*:*:*:*:*:*:*",
275519          "purl": "pkg:rpm/ol/openssl-libs@1.1.1k-9.el8_7?arch=x86_64\u0026epoch=1\u0026upstream=openssl-1.1.1k-9.el8_7.src.rpm\u0026distro=ol-8.7",
275520          "swid": {
275521            "attachment": {}
275522          },
275523          "pedigree": {},
275524          "evidence": {},
275525          "signature": {
275526            "signature": {
275527              "publicKey": {}
275528            }
275529          },
275530          "modelCard": {
275531            "modelParameters": {
275532              "approach": {}
275533            },
275534            "quantitativeAnalysis": {
275535              "graphics": {}
275536            },
275537            "considerations": {}
275538          }
275539        },
275540        {
275541          "type": "library",
275542          "bom-ref": "pkg:rpm/ol/oraclelinux-release@8.7-1.0.6.el8?arch=x86_64\u0026epoch=8\u0026upstream=oraclelinux-release-8.7-1.0.6.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=565cf53eae1d4083",
275543          "supplier": {},
275544          "publisher": "Oracle America",
275545          "name": "oraclelinux-release",
275546          "version": "8:8.7-1.0.6.el8",
275547          "licenses": [
275548            {
275549              "license": {
275550                "name": "GPL"
275551              }
275552            }
275553          ],
275554          "cpe": "cpe:2.3:a:oraclelinux-release:oraclelinux-release:8\\:8.7-1.0.6.el8:*:*:*:*:*:*:*",
275555          "purl": "pkg:rpm/ol/oraclelinux-release@8.7-1.0.6.el8?arch=x86_64\u0026epoch=8\u0026upstream=oraclelinux-release-8.7-1.0.6.el8.src.rpm\u0026distro=ol-8.7",
275556          "swid": {
275557            "attachment": {}
275558          },
275559          "pedigree": {},
275560          "evidence": {},
275561          "signature": {
275562            "signature": {
275563              "publicKey": {}
275564            }
275565          },
275566          "modelCard": {
275567            "modelParameters": {
275568              "approach": {}
275569            },
275570            "quantitativeAnalysis": {
275571              "graphics": {}
275572            },
275573            "considerations": {}
275574          }
275575        },
275576        {
275577          "type": "library",
275578          "bom-ref": "pkg:rpm/ol/oraclelinux-release-el8@1.0-28.el8?arch=x86_64\u0026upstream=oraclelinux-release-el8-1.0-28.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=c9b289ea3be674f1",
275579          "supplier": {},
275580          "publisher": "Oracle America",
275581          "name": "oraclelinux-release-el8",
275582          "version": "1.0-28.el8",
275583          "licenses": [
275584            {
275585              "license": {
275586                "name": "GPLv2"
275587              }
275588            }
275589          ],
275590          "cpe": "cpe:2.3:a:oraclelinux-release-el8:oraclelinux-release-el8:1.0-28.el8:*:*:*:*:*:*:*",
275591          "purl": "pkg:rpm/ol/oraclelinux-release-el8@1.0-28.el8?arch=x86_64\u0026upstream=oraclelinux-release-el8-1.0-28.el8.src.rpm\u0026distro=ol-8.7",
275592          "swid": {
275593            "attachment": {}
275594          },
275595          "pedigree": {},
275596          "evidence": {},
275597          "signature": {
275598            "signature": {
275599              "publicKey": {}
275600            }
275601          },
275602          "modelCard": {
275603            "modelParameters": {
275604              "approach": {}
275605            },
275606            "quantitativeAnalysis": {
275607              "graphics": {}
275608            },
275609            "considerations": {}
275610          }
275611        },
275612        {
275613          "type": "library",
275614          "bom-ref": "pkg:rpm/ol/p11-kit@0.23.22-1.el8?arch=x86_64\u0026upstream=p11-kit-0.23.22-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=4479333660e38f31",
275615          "supplier": {},
275616          "publisher": "Oracle America",
275617          "name": "p11-kit",
275618          "version": "0.23.22-1.el8",
275619          "licenses": [
275620            {
275621              "license": {
275622                "name": "BSD"
275623              }
275624            }
275625          ],
275626          "cpe": "cpe:2.3:a:oracleamerica:p11-kit:0.23.22-1.el8:*:*:*:*:*:*:*",
275627          "purl": "pkg:rpm/ol/p11-kit@0.23.22-1.el8?arch=x86_64\u0026upstream=p11-kit-0.23.22-1.el8.src.rpm\u0026distro=ol-8.7",
275628          "swid": {
275629            "attachment": {}
275630          },
275631          "pedigree": {},
275632          "evidence": {},
275633          "signature": {
275634            "signature": {
275635              "publicKey": {}
275636            }
275637          },
275638          "modelCard": {
275639            "modelParameters": {
275640              "approach": {}
275641            },
275642            "quantitativeAnalysis": {
275643              "graphics": {}
275644            },
275645            "considerations": {}
275646          }
275647        },
275648        {
275649          "type": "library",
275650          "bom-ref": "pkg:rpm/ol/p11-kit-trust@0.23.22-1.el8?arch=x86_64\u0026upstream=p11-kit-0.23.22-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=2e85f931f211b34a",
275651          "supplier": {},
275652          "publisher": "Oracle America",
275653          "name": "p11-kit-trust",
275654          "version": "0.23.22-1.el8",
275655          "licenses": [
275656            {
275657              "license": {
275658                "name": "BSD"
275659              }
275660            }
275661          ],
275662          "cpe": "cpe:2.3:a:oracleamerica:p11-kit-trust:0.23.22-1.el8:*:*:*:*:*:*:*",
275663          "purl": "pkg:rpm/ol/p11-kit-trust@0.23.22-1.el8?arch=x86_64\u0026upstream=p11-kit-0.23.22-1.el8.src.rpm\u0026distro=ol-8.7",
275664          "swid": {
275665            "attachment": {}
275666          },
275667          "pedigree": {},
275668          "evidence": {},
275669          "signature": {
275670            "signature": {
275671              "publicKey": {}
275672            }
275673          },
275674          "modelCard": {
275675            "modelParameters": {
275676              "approach": {}
275677            },
275678            "quantitativeAnalysis": {
275679              "graphics": {}
275680            },
275681            "considerations": {}
275682          }
275683        },
275684        {
275685          "type": "library",
275686          "bom-ref": "pkg:pypi/paramiko@2.11.0?package-id=21e0517702bc0916",
275687          "supplier": {},
275688          "author": "Jeff Forcier \u003cjeff@bitprophet.org\u003e",
275689          "name": "paramiko",
275690          "version": "2.11.0",
275691          "licenses": [
275692            {
275693              "license": {
275694                "name": "LGPL"
275695              }
275696            }
275697          ],
275698          "cpe": "cpe:2.3:a:jeff_forcier_project:python-paramiko:2.11.0:*:*:*:*:*:*:*",
275699          "purl": "pkg:pypi/paramiko@2.11.0",
275700          "swid": {
275701            "attachment": {}
275702          },
275703          "pedigree": {},
275704          "externalReferences": [
275705            {
275706              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/2c/d7/e5/2ec6bec7d1fb4a0210da4f1351f5be832a0309dbe7b6cdb69f/paramiko-2.11.0-py2.py3-none-any.whl",
275707              "type": "vcs"
275708            }
275709          ],
275710          "evidence": {},
275711          "signature": {
275712            "signature": {
275713              "publicKey": {}
275714            }
275715          },
275716          "modelCard": {
275717            "modelParameters": {
275718              "approach": {}
275719            },
275720            "quantitativeAnalysis": {
275721              "graphics": {}
275722            },
275723            "considerations": {}
275724          }
275725        },
275726        {
275727          "type": "library",
275728          "bom-ref": "pkg:rpm/ol/pcre@8.42-6.el8?arch=x86_64\u0026upstream=pcre-8.42-6.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=daf362191df22d01",
275729          "supplier": {},
275730          "publisher": "Oracle America",
275731          "name": "pcre",
275732          "version": "8.42-6.el8",
275733          "licenses": [
275734            {
275735              "license": {
275736                "name": "BSD"
275737              }
275738            }
275739          ],
275740          "cpe": "cpe:2.3:a:oracleamerica:pcre:8.42-6.el8:*:*:*:*:*:*:*",
275741          "purl": "pkg:rpm/ol/pcre@8.42-6.el8?arch=x86_64\u0026upstream=pcre-8.42-6.el8.src.rpm\u0026distro=ol-8.7",
275742          "swid": {
275743            "attachment": {}
275744          },
275745          "pedigree": {},
275746          "evidence": {},
275747          "signature": {
275748            "signature": {
275749              "publicKey": {}
275750            }
275751          },
275752          "modelCard": {
275753            "modelParameters": {
275754              "approach": {}
275755            },
275756            "quantitativeAnalysis": {
275757              "graphics": {}
275758            },
275759            "considerations": {}
275760          }
275761        },
275762        {
275763          "type": "library",
275764          "bom-ref": "pkg:rpm/ol/pcre2@10.32-3.el8_6?arch=x86_64\u0026upstream=pcre2-10.32-3.el8_6.src.rpm\u0026distro=ol-8.7\u0026package-id=70339746572b0789",
275765          "supplier": {},
275766          "publisher": "Oracle America",
275767          "name": "pcre2",
275768          "version": "10.32-3.el8_6",
275769          "licenses": [
275770            {
275771              "license": {
275772                "name": "BSD"
275773              }
275774            }
275775          ],
275776          "cpe": "cpe:2.3:a:oracleamerica:pcre2:10.32-3.el8_6:*:*:*:*:*:*:*",
275777          "purl": "pkg:rpm/ol/pcre2@10.32-3.el8_6?arch=x86_64\u0026upstream=pcre2-10.32-3.el8_6.src.rpm\u0026distro=ol-8.7",
275778          "swid": {
275779            "attachment": {}
275780          },
275781          "pedigree": {},
275782          "evidence": {},
275783          "signature": {
275784            "signature": {
275785              "publicKey": {}
275786            }
275787          },
275788          "modelCard": {
275789            "modelParameters": {
275790              "approach": {}
275791            },
275792            "quantitativeAnalysis": {
275793              "graphics": {}
275794            },
275795            "considerations": {}
275796          }
275797        },
275798        {
275799          "type": "library",
275800          "bom-ref": "pkg:pypi/pip@20.2.4?package-id=9f4fb97730eff790",
275801          "supplier": {},
275802          "author": "The pip developers \u003cdistutils-sig@python.org\u003e",
275803          "name": "pip",
275804          "version": "20.2.4",
275805          "licenses": [
275806            {
275807              "license": {
275808                "id": "MIT"
275809              }
275810            }
275811          ],
275812          "cpe": "cpe:2.3:a:pip_developers_project:python-pip:20.2.4:*:*:*:*:*:*:*",
275813          "purl": "pkg:pypi/pip@20.2.4",
275814          "swid": {
275815            "attachment": {}
275816          },
275817          "pedigree": {},
275818          "evidence": {},
275819          "signature": {
275820            "signature": {
275821              "publicKey": {}
275822            }
275823          },
275824          "modelCard": {
275825            "modelParameters": {
275826              "approach": {}
275827            },
275828            "quantitativeAnalysis": {
275829              "graphics": {}
275830            },
275831            "considerations": {}
275832          }
275833        },
275834        {
275835          "type": "library",
275836          "bom-ref": "pkg:rpm/ol/popt@1.18-1.el8?arch=x86_64\u0026upstream=popt-1.18-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=11dad195e8f044bb",
275837          "supplier": {},
275838          "publisher": "Oracle America",
275839          "name": "popt",
275840          "version": "1.18-1.el8",
275841          "licenses": [
275842            {
275843              "license": {
275844                "id": "MIT"
275845              }
275846            }
275847          ],
275848          "cpe": "cpe:2.3:a:oracleamerica:popt:1.18-1.el8:*:*:*:*:*:*:*",
275849          "purl": "pkg:rpm/ol/popt@1.18-1.el8?arch=x86_64\u0026upstream=popt-1.18-1.el8.src.rpm\u0026distro=ol-8.7",
275850          "swid": {
275851            "attachment": {}
275852          },
275853          "pedigree": {},
275854          "evidence": {},
275855          "signature": {
275856            "signature": {
275857              "publicKey": {}
275858            }
275859          },
275860          "modelCard": {
275861            "modelParameters": {
275862              "approach": {}
275863            },
275864            "quantitativeAnalysis": {
275865              "graphics": {}
275866            },
275867            "considerations": {}
275868          }
275869        },
275870        {
275871          "type": "library",
275872          "bom-ref": "pkg:rpm/ol/publicsuffix-list-dafsa@20180723-1.el8?arch=noarch\u0026upstream=publicsuffix-list-20180723-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=8b83ee6c7ce59ffb",
275873          "supplier": {},
275874          "publisher": "Oracle America",
275875          "name": "publicsuffix-list-dafsa",
275876          "version": "20180723-1.el8",
275877          "licenses": [
275878            {
275879              "license": {
275880                "name": "MPLv2.0"
275881              }
275882            }
275883          ],
275884          "cpe": "cpe:2.3:a:publicsuffix-list-dafsa:publicsuffix-list-dafsa:20180723-1.el8:*:*:*:*:*:*:*",
275885          "purl": "pkg:rpm/ol/publicsuffix-list-dafsa@20180723-1.el8?arch=noarch\u0026upstream=publicsuffix-list-20180723-1.el8.src.rpm\u0026distro=ol-8.7",
275886          "swid": {
275887            "attachment": {}
275888          },
275889          "pedigree": {},
275890          "evidence": {},
275891          "signature": {
275892            "signature": {
275893              "publicKey": {}
275894            }
275895          },
275896          "modelCard": {
275897            "modelParameters": {
275898              "approach": {}
275899            },
275900            "quantitativeAnalysis": {
275901              "graphics": {}
275902            },
275903            "considerations": {}
275904          }
275905        },
275906        {
275907          "type": "library",
275908          "bom-ref": "pkg:pypi/pyopenssl@22.1.0?package-id=87e045a78914624a",
275909          "supplier": {},
275910          "author": "The pyOpenSSL developers \u003ccryptography-dev@python.org\u003e",
275911          "name": "pyOpenSSL",
275912          "version": "22.1.0",
275913          "licenses": [
275914            {
275915              "license": {
275916                "name": "Apache License, Version 2.0"
275917              }
275918            }
275919          ],
275920          "cpe": "cpe:2.3:a:pyopenssl_developers_project:python-pyOpenSSL:22.1.0:*:*:*:*:*:*:*",
275921          "purl": "pkg:pypi/pyOpenSSL@22.1.0",
275922          "swid": {
275923            "attachment": {}
275924          },
275925          "pedigree": {},
275926          "externalReferences": [
275927            {
275928              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/ac/f7/26/1ba45f8cd29b474d7690287c4d2874df6cc3f8c032750e8b52/pyOpenSSL-22.1.0-py3-none-any.whl",
275929              "type": "vcs"
275930            }
275931          ],
275932          "evidence": {},
275933          "signature": {
275934            "signature": {
275935              "publicKey": {}
275936            }
275937          },
275938          "modelCard": {
275939            "modelParameters": {
275940              "approach": {}
275941            },
275942            "quantitativeAnalysis": {
275943              "graphics": {}
275944            },
275945            "considerations": {}
275946          }
275947        },
275948        {
275949          "type": "library",
275950          "bom-ref": "pkg:pypi/pycparser@2.21?package-id=ab21419f0cb124ef",
275951          "supplier": {},
275952          "author": "Eli Bendersky \u003celiben@gmail.com\u003e",
275953          "name": "pycparser",
275954          "version": "2.21",
275955          "licenses": [
275956            {
275957              "license": {
275958                "name": "BSD"
275959              }
275960            }
275961          ],
275962          "cpe": "cpe:2.3:a:eli_bendersky_project:python-pycparser:2.21:*:*:*:*:*:*:*",
275963          "purl": "pkg:pypi/pycparser@2.21",
275964          "swid": {
275965            "attachment": {}
275966          },
275967          "pedigree": {},
275968          "externalReferences": [
275969            {
275970              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/25/4d/3e/18277469ffdbb7d91cf12f8cb58f69be429e1fa8c1443493ed/pycparser-2.21-py2.py3-none-any.whl",
275971              "type": "vcs"
275972            }
275973          ],
275974          "evidence": {},
275975          "signature": {
275976            "signature": {
275977              "publicKey": {}
275978            }
275979          },
275980          "modelCard": {
275981            "modelParameters": {
275982              "approach": {}
275983            },
275984            "quantitativeAnalysis": {
275985              "graphics": {}
275986            },
275987            "considerations": {}
275988          }
275989        },
275990        {
275991          "type": "application",
275992          "bom-ref": "pkg:generic/python@3.9.13?package-id=a8d7190987c6e1c1",
275993          "supplier": {},
275994          "name": "python",
275995          "version": "3.9.13",
275996          "cpe": "cpe:2.3:a:python_software_foundation:python:3.9.13:*:*:*:*:*:*:*",
275997          "purl": "pkg:generic/python@3.9.13",
275998          "swid": {
275999            "attachment": {}
276000          },
276001          "pedigree": {},
276002          "evidence": {},
276003          "signature": {
276004            "signature": {
276005              "publicKey": {}
276006            }
276007          },
276008          "modelCard": {
276009            "modelParameters": {
276010              "approach": {}
276011            },
276012            "quantitativeAnalysis": {
276013              "graphics": {}
276014            },
276015            "considerations": {}
276016          }
276017        },
276018        {
276019          "type": "library",
276020          "bom-ref": "pkg:pypi/python-dateutil@2.8.2?package-id=cce32312149a9e3b",
276021          "supplier": {},
276022          "author": "Gustavo Niemeyer \u003cgustavo@niemeyer.net\u003e",
276023          "name": "python-dateutil",
276024          "version": "2.8.2",
276025          "licenses": [
276026            {
276027              "license": {
276028                "name": "Dual License"
276029              }
276030            }
276031          ],
276032          "cpe": "cpe:2.3:a:gustavo_niemeyer_project:python-dateutil:2.8.2:*:*:*:*:*:*:*",
276033          "purl": "pkg:pypi/python-dateutil@2.8.2",
276034          "swid": {
276035            "attachment": {}
276036          },
276037          "pedigree": {},
276038          "externalReferences": [
276039            {
276040              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/60/2e/f5/a018dabdf32658543060730e246fa03a24b41db63e7c4ed8a4/python_dateutil-2.8.2-py2.py3-none-any.whl",
276041              "type": "vcs"
276042            }
276043          ],
276044          "evidence": {},
276045          "signature": {
276046            "signature": {
276047              "publicKey": {}
276048            }
276049          },
276050          "modelCard": {
276051            "modelParameters": {
276052              "approach": {}
276053            },
276054            "quantitativeAnalysis": {
276055              "graphics": {}
276056            },
276057            "considerations": {}
276058          }
276059        },
276060        {
276061          "type": "library",
276062          "bom-ref": "pkg:rpm/ol/python39@3.9.13-2.module+el8.7.0+20879+a85b87b0?arch=x86_64\u0026upstream=python39-3.9.13-2.module+el8.7.0+20879+a85b87b0.src.rpm\u0026distro=ol-8.7\u0026package-id=70659ab06fa85e0",
276063          "supplier": {},
276064          "publisher": "Oracle America",
276065          "name": "python39",
276066          "version": "3.9.13-2.module+el8.7.0+20879+a85b87b0",
276067          "licenses": [
276068            {
276069              "license": {
276070                "name": "Python"
276071              }
276072            }
276073          ],
276074          "cpe": "cpe:2.3:a:oracleamerica:python39:3.9.13-2.module\\+el8.7.0\\+20879\\+a85b87b0:*:*:*:*:*:*:*",
276075          "purl": "pkg:rpm/ol/python39@3.9.13-2.module+el8.7.0+20879+a85b87b0?arch=x86_64\u0026upstream=python39-3.9.13-2.module+el8.7.0+20879+a85b87b0.src.rpm\u0026distro=ol-8.7",
276076          "swid": {
276077            "attachment": {}
276078          },
276079          "pedigree": {},
276080          "evidence": {},
276081          "signature": {
276082            "signature": {
276083              "publicKey": {}
276084            }
276085          },
276086          "modelCard": {
276087            "modelParameters": {
276088              "approach": {}
276089            },
276090            "quantitativeAnalysis": {
276091              "graphics": {}
276092            },
276093            "considerations": {}
276094          }
276095        },
276096        {
276097          "type": "library",
276098          "bom-ref": "pkg:rpm/ol/python39-libs@3.9.13-2.module+el8.7.0+20879+a85b87b0?arch=x86_64\u0026upstream=python39-3.9.13-2.module+el8.7.0+20879+a85b87b0.src.rpm\u0026distro=ol-8.7\u0026package-id=f3922b0b0b3c7316",
276099          "supplier": {},
276100          "publisher": "Oracle America",
276101          "name": "python39-libs",
276102          "version": "3.9.13-2.module+el8.7.0+20879+a85b87b0",
276103          "licenses": [
276104            {
276105              "license": {
276106                "name": "Python"
276107              }
276108            }
276109          ],
276110          "cpe": "cpe:2.3:a:oracleamerica:python39-libs:3.9.13-2.module\\+el8.7.0\\+20879\\+a85b87b0:*:*:*:*:*:*:*",
276111          "purl": "pkg:rpm/ol/python39-libs@3.9.13-2.module+el8.7.0+20879+a85b87b0?arch=x86_64\u0026upstream=python39-3.9.13-2.module+el8.7.0+20879+a85b87b0.src.rpm\u0026distro=ol-8.7",
276112          "swid": {
276113            "attachment": {}
276114          },
276115          "pedigree": {},
276116          "evidence": {},
276117          "signature": {
276118            "signature": {
276119              "publicKey": {}
276120            }
276121          },
276122          "modelCard": {
276123            "modelParameters": {
276124              "approach": {}
276125            },
276126            "quantitativeAnalysis": {
276127              "graphics": {}
276128            },
276129            "considerations": {}
276130          }
276131        },
276132        {
276133          "type": "library",
276134          "bom-ref": "pkg:rpm/ol/python39-pip@20.2.4-7.module+el8.6.0+20625+ee813db2?arch=noarch\u0026upstream=python3x-pip-20.2.4-7.module+el8.6.0+20625+ee813db2.src.rpm\u0026distro=ol-8.7\u0026package-id=e55991233c680d8d",
276135          "supplier": {},
276136          "publisher": "Oracle America",
276137          "name": "python39-pip",
276138          "version": "20.2.4-7.module+el8.6.0+20625+ee813db2",
276139          "licenses": [
276140            {
276141              "license": {
276142                "name": "MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"
276143              }
276144            }
276145          ],
276146          "cpe": "cpe:2.3:a:oracleamerica:python39-pip:20.2.4-7.module\\+el8.6.0\\+20625\\+ee813db2:*:*:*:*:*:*:*",
276147          "purl": "pkg:rpm/ol/python39-pip@20.2.4-7.module+el8.6.0+20625+ee813db2?arch=noarch\u0026upstream=python3x-pip-20.2.4-7.module+el8.6.0+20625+ee813db2.src.rpm\u0026distro=ol-8.7",
276148          "swid": {
276149            "attachment": {}
276150          },
276151          "pedigree": {},
276152          "evidence": {},
276153          "signature": {
276154            "signature": {
276155              "publicKey": {}
276156            }
276157          },
276158          "modelCard": {
276159            "modelParameters": {
276160              "approach": {}
276161            },
276162            "quantitativeAnalysis": {
276163              "graphics": {}
276164            },
276165            "considerations": {}
276166          }
276167        },
276168        {
276169          "type": "library",
276170          "bom-ref": "pkg:rpm/ol/python39-pip-wheel@20.2.4-7.module+el8.6.0+20625+ee813db2?arch=noarch\u0026upstream=python3x-pip-20.2.4-7.module+el8.6.0+20625+ee813db2.src.rpm\u0026distro=ol-8.7\u0026package-id=bc1784baa6ce6064",
276171          "supplier": {},
276172          "publisher": "Oracle America",
276173          "name": "python39-pip-wheel",
276174          "version": "20.2.4-7.module+el8.6.0+20625+ee813db2",
276175          "licenses": [
276176            {
276177              "license": {
276178                "name": "MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"
276179              }
276180            }
276181          ],
276182          "cpe": "cpe:2.3:a:python39-pip-wheel:python39-pip-wheel:20.2.4-7.module\\+el8.6.0\\+20625\\+ee813db2:*:*:*:*:*:*:*",
276183          "purl": "pkg:rpm/ol/python39-pip-wheel@20.2.4-7.module+el8.6.0+20625+ee813db2?arch=noarch\u0026upstream=python3x-pip-20.2.4-7.module+el8.6.0+20625+ee813db2.src.rpm\u0026distro=ol-8.7",
276184          "swid": {
276185            "attachment": {}
276186          },
276187          "pedigree": {},
276188          "evidence": {},
276189          "signature": {
276190            "signature": {
276191              "publicKey": {}
276192            }
276193          },
276194          "modelCard": {
276195            "modelParameters": {
276196              "approach": {}
276197            },
276198            "quantitativeAnalysis": {
276199              "graphics": {}
276200            },
276201            "considerations": {}
276202          }
276203        },
276204        {
276205          "type": "library",
276206          "bom-ref": "pkg:rpm/ol/python39-setuptools@50.3.2-4.module+el8.5.0+20364+c7fe1181?arch=noarch\u0026upstream=python3x-setuptools-50.3.2-4.module+el8.5.0+20364+c7fe1181.src.rpm\u0026distro=ol-8.7\u0026package-id=45e36d78301d04ae",
276207          "supplier": {},
276208          "publisher": "Oracle America",
276209          "name": "python39-setuptools",
276210          "version": "50.3.2-4.module+el8.5.0+20364+c7fe1181",
276211          "licenses": [
276212            {
276213              "license": {
276214                "name": "MIT and (BSD or ASL 2.0)"
276215              }
276216            }
276217          ],
276218          "cpe": "cpe:2.3:a:python39-setuptools:python39-setuptools:50.3.2-4.module\\+el8.5.0\\+20364\\+c7fe1181:*:*:*:*:*:*:*",
276219          "purl": "pkg:rpm/ol/python39-setuptools@50.3.2-4.module+el8.5.0+20364+c7fe1181?arch=noarch\u0026upstream=python3x-setuptools-50.3.2-4.module+el8.5.0+20364+c7fe1181.src.rpm\u0026distro=ol-8.7",
276220          "swid": {
276221            "attachment": {}
276222          },
276223          "pedigree": {},
276224          "evidence": {},
276225          "signature": {
276226            "signature": {
276227              "publicKey": {}
276228            }
276229          },
276230          "modelCard": {
276231            "modelParameters": {
276232              "approach": {}
276233            },
276234            "quantitativeAnalysis": {
276235              "graphics": {}
276236            },
276237            "considerations": {}
276238          }
276239        },
276240        {
276241          "type": "library",
276242          "bom-ref": "pkg:rpm/ol/python39-setuptools-wheel@50.3.2-4.module+el8.5.0+20364+c7fe1181?arch=noarch\u0026upstream=python3x-setuptools-50.3.2-4.module+el8.5.0+20364+c7fe1181.src.rpm\u0026distro=ol-8.7\u0026package-id=d8e0aae00d12b93f",
276243          "supplier": {},
276244          "publisher": "Oracle America",
276245          "name": "python39-setuptools-wheel",
276246          "version": "50.3.2-4.module+el8.5.0+20364+c7fe1181",
276247          "licenses": [
276248            {
276249              "license": {
276250                "name": "MIT and (BSD or ASL 2.0)"
276251              }
276252            }
276253          ],
276254          "cpe": "cpe:2.3:a:python39-setuptools-wheel:python39-setuptools-wheel:50.3.2-4.module\\+el8.5.0\\+20364\\+c7fe1181:*:*:*:*:*:*:*",
276255          "purl": "pkg:rpm/ol/python39-setuptools-wheel@50.3.2-4.module+el8.5.0+20364+c7fe1181?arch=noarch\u0026upstream=python3x-setuptools-50.3.2-4.module+el8.5.0+20364+c7fe1181.src.rpm\u0026distro=ol-8.7",
276256          "swid": {
276257            "attachment": {}
276258          },
276259          "pedigree": {},
276260          "evidence": {},
276261          "signature": {
276262            "signature": {
276263              "publicKey": {}
276264            }
276265          },
276266          "modelCard": {
276267            "modelParameters": {
276268              "approach": {}
276269            },
276270            "quantitativeAnalysis": {
276271              "graphics": {}
276272            },
276273            "considerations": {}
276274          }
276275        },
276276        {
276277          "type": "library",
276278          "bom-ref": "pkg:pypi/pytz@2022.7.1?package-id=6dcad9fac9ee238e",
276279          "supplier": {},
276280          "author": "Stuart Bishop \u003cstuart@stuartbishop.net\u003e",
276281          "name": "pytz",
276282          "version": "2022.7.1",
276283          "licenses": [
276284            {
276285              "license": {
276286                "id": "MIT"
276287              }
276288            }
276289          ],
276290          "cpe": "cpe:2.3:a:stuart_bishop_project:python-pytz:2022.7.1:*:*:*:*:*:*:*",
276291          "purl": "pkg:pypi/pytz@2022.7.1",
276292          "swid": {
276293            "attachment": {}
276294          },
276295          "pedigree": {},
276296          "externalReferences": [
276297            {
276298              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/60/f7/41/190ae491adea3f866dbb51eaca6c8ed8c436c0791a44094027/pytz-2022.7.1-py3-none-any.whl",
276299              "type": "vcs"
276300            }
276301          ],
276302          "evidence": {},
276303          "signature": {
276304            "signature": {
276305              "publicKey": {}
276306            }
276307          },
276308          "modelCard": {
276309            "modelParameters": {
276310              "approach": {}
276311            },
276312            "quantitativeAnalysis": {
276313              "graphics": {}
276314            },
276315            "considerations": {}
276316          }
276317        },
276318        {
276319          "type": "library",
276320          "bom-ref": "pkg:rpm/ol/readline@7.0-10.el8?arch=x86_64\u0026upstream=readline-7.0-10.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=d14cbfeb7aa11f0",
276321          "supplier": {},
276322          "publisher": "Oracle America",
276323          "name": "readline",
276324          "version": "7.0-10.el8",
276325          "licenses": [
276326            {
276327              "license": {
276328                "name": "GPLv3+"
276329              }
276330            }
276331          ],
276332          "cpe": "cpe:2.3:a:oracleamerica:readline:7.0-10.el8:*:*:*:*:*:*:*",
276333          "purl": "pkg:rpm/ol/readline@7.0-10.el8?arch=x86_64\u0026upstream=readline-7.0-10.el8.src.rpm\u0026distro=ol-8.7",
276334          "swid": {
276335            "attachment": {}
276336          },
276337          "pedigree": {},
276338          "evidence": {},
276339          "signature": {
276340            "signature": {
276341              "publicKey": {}
276342            }
276343          },
276344          "modelCard": {
276345            "modelParameters": {
276346              "approach": {}
276347            },
276348            "quantitativeAnalysis": {
276349              "graphics": {}
276350            },
276351            "considerations": {}
276352          }
276353        },
276354        {
276355          "type": "library",
276356          "bom-ref": "pkg:rpm/ol/redhat-release@8.7-0.3.0.1.el8?arch=x86_64\u0026epoch=2\u0026upstream=redhat-release-8.7-0.3.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=abf8958baac35f9a",
276357          "supplier": {},
276358          "publisher": "Oracle America",
276359          "name": "redhat-release",
276360          "version": "2:8.7-0.3.0.1.el8",
276361          "licenses": [
276362            {
276363              "license": {
276364                "name": "GPLv2"
276365              }
276366            }
276367          ],
276368          "cpe": "cpe:2.3:a:redhat-release:redhat-release:2\\:8.7-0.3.0.1.el8:*:*:*:*:*:*:*",
276369          "purl": "pkg:rpm/ol/redhat-release@8.7-0.3.0.1.el8?arch=x86_64\u0026epoch=2\u0026upstream=redhat-release-8.7-0.3.0.1.el8.src.rpm\u0026distro=ol-8.7",
276370          "swid": {
276371            "attachment": {}
276372          },
276373          "pedigree": {},
276374          "evidence": {},
276375          "signature": {
276376            "signature": {
276377              "publicKey": {}
276378            }
276379          },
276380          "modelCard": {
276381            "modelParameters": {
276382              "approach": {}
276383            },
276384            "quantitativeAnalysis": {
276385              "graphics": {}
276386            },
276387            "considerations": {}
276388          }
276389        },
276390        {
276391          "type": "library",
276392          "bom-ref": "pkg:rpm/ol/rpm@4.14.3-24.el8_7?arch=x86_64\u0026upstream=rpm-4.14.3-24.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=123a2bc82c27aedc",
276393          "supplier": {},
276394          "publisher": "Oracle America",
276395          "name": "rpm",
276396          "version": "4.14.3-24.el8_7",
276397          "licenses": [
276398            {
276399              "license": {
276400                "name": "GPLv2+"
276401              }
276402            }
276403          ],
276404          "cpe": "cpe:2.3:a:oracleamerica:rpm:4.14.3-24.el8_7:*:*:*:*:*:*:*",
276405          "purl": "pkg:rpm/ol/rpm@4.14.3-24.el8_7?arch=x86_64\u0026upstream=rpm-4.14.3-24.el8_7.src.rpm\u0026distro=ol-8.7",
276406          "swid": {
276407            "attachment": {}
276408          },
276409          "pedigree": {},
276410          "evidence": {},
276411          "signature": {
276412            "signature": {
276413              "publicKey": {}
276414            }
276415          },
276416          "modelCard": {
276417            "modelParameters": {
276418              "approach": {}
276419            },
276420            "quantitativeAnalysis": {
276421              "graphics": {}
276422            },
276423            "considerations": {}
276424          }
276425        },
276426        {
276427          "type": "library",
276428          "bom-ref": "pkg:rpm/ol/rpm-libs@4.14.3-24.el8_7?arch=x86_64\u0026upstream=rpm-4.14.3-24.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=beeb757503028b29",
276429          "supplier": {},
276430          "publisher": "Oracle America",
276431          "name": "rpm-libs",
276432          "version": "4.14.3-24.el8_7",
276433          "licenses": [
276434            {
276435              "license": {
276436                "name": "GPLv2+ and LGPLv2+ with exceptions"
276437              }
276438            }
276439          ],
276440          "cpe": "cpe:2.3:a:oracleamerica:rpm-libs:4.14.3-24.el8_7:*:*:*:*:*:*:*",
276441          "purl": "pkg:rpm/ol/rpm-libs@4.14.3-24.el8_7?arch=x86_64\u0026upstream=rpm-4.14.3-24.el8_7.src.rpm\u0026distro=ol-8.7",
276442          "swid": {
276443            "attachment": {}
276444          },
276445          "pedigree": {},
276446          "evidence": {},
276447          "signature": {
276448            "signature": {
276449              "publicKey": {}
276450            }
276451          },
276452          "modelCard": {
276453            "modelParameters": {
276454              "approach": {}
276455            },
276456            "quantitativeAnalysis": {
276457              "graphics": {}
276458            },
276459            "considerations": {}
276460          }
276461        },
276462        {
276463          "type": "library",
276464          "bom-ref": "pkg:rpm/ol/sed@4.5-5.el8?arch=x86_64\u0026upstream=sed-4.5-5.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=11fa6095ad0bf98a",
276465          "supplier": {},
276466          "publisher": "Oracle America",
276467          "name": "sed",
276468          "version": "4.5-5.el8",
276469          "licenses": [
276470            {
276471              "license": {
276472                "name": "GPLv3+"
276473              }
276474            }
276475          ],
276476          "cpe": "cpe:2.3:a:oracleamerica:sed:4.5-5.el8:*:*:*:*:*:*:*",
276477          "purl": "pkg:rpm/ol/sed@4.5-5.el8?arch=x86_64\u0026upstream=sed-4.5-5.el8.src.rpm\u0026distro=ol-8.7",
276478          "swid": {
276479            "attachment": {}
276480          },
276481          "pedigree": {},
276482          "evidence": {},
276483          "signature": {
276484            "signature": {
276485              "publicKey": {}
276486            }
276487          },
276488          "modelCard": {
276489            "modelParameters": {
276490              "approach": {}
276491            },
276492            "quantitativeAnalysis": {
276493              "graphics": {}
276494            },
276495            "considerations": {}
276496          }
276497        },
276498        {
276499          "type": "library",
276500          "bom-ref": "pkg:rpm/ol/setup@2.12.2-7.el8?arch=noarch\u0026upstream=setup-2.12.2-7.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=8d6dc6de2fa84f88",
276501          "supplier": {},
276502          "publisher": "Oracle America",
276503          "name": "setup",
276504          "version": "2.12.2-7.el8",
276505          "licenses": [
276506            {
276507              "license": {
276508                "name": "Public Domain"
276509              }
276510            }
276511          ],
276512          "cpe": "cpe:2.3:a:oracleamerica:setup:2.12.2-7.el8:*:*:*:*:*:*:*",
276513          "purl": "pkg:rpm/ol/setup@2.12.2-7.el8?arch=noarch\u0026upstream=setup-2.12.2-7.el8.src.rpm\u0026distro=ol-8.7",
276514          "swid": {
276515            "attachment": {}
276516          },
276517          "pedigree": {},
276518          "evidence": {},
276519          "signature": {
276520            "signature": {
276521              "publicKey": {}
276522            }
276523          },
276524          "modelCard": {
276525            "modelParameters": {
276526              "approach": {}
276527            },
276528            "quantitativeAnalysis": {
276529              "graphics": {}
276530            },
276531            "considerations": {}
276532          }
276533        },
276534        {
276535          "type": "library",
276536          "bom-ref": "pkg:pypi/setuptools@50.3.2?package-id=7e493d729111ea48",
276537          "supplier": {},
276538          "author": "Python Packaging Authority \u003cdistutils-sig@python.org\u003e",
276539          "name": "setuptools",
276540          "version": "50.3.2",
276541          "licenses": [
276542            {
276543              "license": {
276544                "name": "UNKNOWN"
276545              }
276546            }
276547          ],
276548          "cpe": "cpe:2.3:a:python_packaging_authority_project:python-setuptools:50.3.2:*:*:*:*:*:*:*",
276549          "purl": "pkg:pypi/setuptools@50.3.2",
276550          "swid": {
276551            "attachment": {}
276552          },
276553          "pedigree": {},
276554          "evidence": {},
276555          "signature": {
276556            "signature": {
276557              "publicKey": {}
276558            }
276559          },
276560          "modelCard": {
276561            "modelParameters": {
276562              "approach": {}
276563            },
276564            "quantitativeAnalysis": {
276565              "graphics": {}
276566            },
276567            "considerations": {}
276568          }
276569        },
276570        {
276571          "type": "library",
276572          "bom-ref": "pkg:rpm/ol/shadow-utils@4.6-17.el8?arch=x86_64\u0026epoch=2\u0026upstream=shadow-utils-4.6-17.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=4d525b5700d8c2d0",
276573          "supplier": {},
276574          "publisher": "Oracle America",
276575          "name": "shadow-utils",
276576          "version": "2:4.6-17.el8",
276577          "licenses": [
276578            {
276579              "license": {
276580                "name": "BSD and GPLv2+"
276581              }
276582            }
276583          ],
276584          "cpe": "cpe:2.3:a:oracleamerica:shadow-utils:2\\:4.6-17.el8:*:*:*:*:*:*:*",
276585          "purl": "pkg:rpm/ol/shadow-utils@4.6-17.el8?arch=x86_64\u0026epoch=2\u0026upstream=shadow-utils-4.6-17.el8.src.rpm\u0026distro=ol-8.7",
276586          "swid": {
276587            "attachment": {}
276588          },
276589          "pedigree": {},
276590          "evidence": {},
276591          "signature": {
276592            "signature": {
276593              "publicKey": {}
276594            }
276595          },
276596          "modelCard": {
276597            "modelParameters": {
276598              "approach": {}
276599            },
276600            "quantitativeAnalysis": {
276601              "graphics": {}
276602            },
276603            "considerations": {}
276604          }
276605        },
276606        {
276607          "type": "library",
276608          "bom-ref": "pkg:pypi/six@1.16.0?package-id=5cca85e19738e858",
276609          "supplier": {},
276610          "author": "Benjamin Peterson \u003cbenjamin@python.org\u003e",
276611          "name": "six",
276612          "version": "1.16.0",
276613          "licenses": [
276614            {
276615              "license": {
276616                "id": "MIT"
276617              }
276618            }
276619          ],
276620          "cpe": "cpe:2.3:a:benjamin_peterson_project:python-six:1.16.0:*:*:*:*:*:*:*",
276621          "purl": "pkg:pypi/six@1.16.0",
276622          "swid": {
276623            "attachment": {}
276624          },
276625          "pedigree": {},
276626          "externalReferences": [
276627            {
276628              "url": "file:///var/lib/pb2/sb_1-10866539-1679468854.52/workdir/cache/wheels/0d/b1/8d/6e1174b514b0582907d2a8c31d4ad28a1d0852ac79265617a6/six-1.16.0-py2.py3-none-any.whl",
276629              "type": "vcs"
276630            }
276631          ],
276632          "evidence": {},
276633          "signature": {
276634            "signature": {
276635              "publicKey": {}
276636            }
276637          },
276638          "modelCard": {
276639            "modelParameters": {
276640              "approach": {}
276641            },
276642            "quantitativeAnalysis": {
276643              "graphics": {}
276644            },
276645            "considerations": {}
276646          }
276647        },
276648        {
276649          "type": "library",
276650          "bom-ref": "pkg:rpm/ol/sqlite-libs@3.26.0-17.el8_7?arch=x86_64\u0026upstream=sqlite-3.26.0-17.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=385ef50a325d1018",
276651          "supplier": {},
276652          "publisher": "Oracle America",
276653          "name": "sqlite-libs",
276654          "version": "3.26.0-17.el8_7",
276655          "licenses": [
276656            {
276657              "license": {
276658                "name": "Public Domain"
276659              }
276660            }
276661          ],
276662          "cpe": "cpe:2.3:a:oracleamerica:sqlite-libs:3.26.0-17.el8_7:*:*:*:*:*:*:*",
276663          "purl": "pkg:rpm/ol/sqlite-libs@3.26.0-17.el8_7?arch=x86_64\u0026upstream=sqlite-3.26.0-17.el8_7.src.rpm\u0026distro=ol-8.7",
276664          "swid": {
276665            "attachment": {}
276666          },
276667          "pedigree": {},
276668          "evidence": {},
276669          "signature": {
276670            "signature": {
276671              "publicKey": {}
276672            }
276673          },
276674          "modelCard": {
276675            "modelParameters": {
276676              "approach": {}
276677            },
276678            "quantitativeAnalysis": {
276679              "graphics": {}
276680            },
276681            "considerations": {}
276682          }
276683        },
276684        {
276685          "type": "library",
276686          "bom-ref": "pkg:rpm/ol/systemd-libs@239-68.0.2.el8_7.4?arch=x86_64\u0026upstream=systemd-239-68.0.2.el8_7.4.src.rpm\u0026distro=ol-8.7\u0026package-id=9dd1e178fb91163",
276687          "supplier": {},
276688          "publisher": "Oracle America",
276689          "name": "systemd-libs",
276690          "version": "239-68.0.2.el8_7.4",
276691          "licenses": [
276692            {
276693              "license": {
276694                "name": "LGPLv2+ and MIT"
276695              }
276696            }
276697          ],
276698          "cpe": "cpe:2.3:a:oracleamerica:systemd-libs:239-68.0.2.el8_7.4:*:*:*:*:*:*:*",
276699          "purl": "pkg:rpm/ol/systemd-libs@239-68.0.2.el8_7.4?arch=x86_64\u0026upstream=systemd-239-68.0.2.el8_7.4.src.rpm\u0026distro=ol-8.7",
276700          "swid": {
276701            "attachment": {}
276702          },
276703          "pedigree": {},
276704          "evidence": {},
276705          "signature": {
276706            "signature": {
276707              "publicKey": {}
276708            }
276709          },
276710          "modelCard": {
276711            "modelParameters": {
276712              "approach": {}
276713            },
276714            "quantitativeAnalysis": {
276715              "graphics": {}
276716            },
276717            "considerations": {}
276718          }
276719        },
276720        {
276721          "type": "library",
276722          "bom-ref": "pkg:rpm/ol/tar@1.30-6.el8_7.1?arch=x86_64\u0026epoch=2\u0026upstream=tar-1.30-6.el8_7.1.src.rpm\u0026distro=ol-8.7\u0026package-id=bd4a8fafe7ceb5fd",
276723          "supplier": {},
276724          "publisher": "Oracle America",
276725          "name": "tar",
276726          "version": "2:1.30-6.el8_7.1",
276727          "licenses": [
276728            {
276729              "license": {
276730                "name": "GPLv3+"
276731              }
276732            }
276733          ],
276734          "cpe": "cpe:2.3:a:oracleamerica:tar:2\\:1.30-6.el8_7.1:*:*:*:*:*:*:*",
276735          "purl": "pkg:rpm/ol/tar@1.30-6.el8_7.1?arch=x86_64\u0026epoch=2\u0026upstream=tar-1.30-6.el8_7.1.src.rpm\u0026distro=ol-8.7",
276736          "swid": {
276737            "attachment": {}
276738          },
276739          "pedigree": {},
276740          "evidence": {},
276741          "signature": {
276742            "signature": {
276743              "publicKey": {}
276744            }
276745          },
276746          "modelCard": {
276747            "modelParameters": {
276748              "approach": {}
276749            },
276750            "quantitativeAnalysis": {
276751              "graphics": {}
276752            },
276753            "considerations": {}
276754          }
276755        },
276756        {
276757          "type": "library",
276758          "bom-ref": "pkg:rpm/ol/tzdata@2023c-1.el8?arch=noarch\u0026upstream=tzdata-2023c-1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=77bc22ad98bc0cd6",
276759          "supplier": {},
276760          "publisher": "Oracle America",
276761          "name": "tzdata",
276762          "version": "2023c-1.el8",
276763          "licenses": [
276764            {
276765              "license": {
276766                "name": "Public Domain"
276767              }
276768            }
276769          ],
276770          "cpe": "cpe:2.3:a:oracleamerica:tzdata:2023c-1.el8:*:*:*:*:*:*:*",
276771          "purl": "pkg:rpm/ol/tzdata@2023c-1.el8?arch=noarch\u0026upstream=tzdata-2023c-1.el8.src.rpm\u0026distro=ol-8.7",
276772          "swid": {
276773            "attachment": {}
276774          },
276775          "pedigree": {},
276776          "evidence": {},
276777          "signature": {
276778            "signature": {
276779              "publicKey": {}
276780            }
276781          },
276782          "modelCard": {
276783            "modelParameters": {
276784              "approach": {}
276785            },
276786            "quantitativeAnalysis": {
276787              "graphics": {}
276788            },
276789            "considerations": {}
276790          }
276791        },
276792        {
276793          "type": "library",
276794          "bom-ref": "pkg:rpm/ol/xz@5.2.4-4.el8_6?arch=x86_64\u0026upstream=xz-5.2.4-4.el8_6.src.rpm\u0026distro=ol-8.7\u0026package-id=f0b4af1378e0a971",
276795          "supplier": {},
276796          "publisher": "Oracle America",
276797          "name": "xz",
276798          "version": "5.2.4-4.el8_6",
276799          "licenses": [
276800            {
276801              "license": {
276802                "name": "GPLv2+ and Public Domain"
276803              }
276804            }
276805          ],
276806          "cpe": "cpe:2.3:a:oracleamerica:xz:5.2.4-4.el8_6:*:*:*:*:*:*:*",
276807          "purl": "pkg:rpm/ol/xz@5.2.4-4.el8_6?arch=x86_64\u0026upstream=xz-5.2.4-4.el8_6.src.rpm\u0026distro=ol-8.7",
276808          "swid": {
276809            "attachment": {}
276810          },
276811          "pedigree": {},
276812          "evidence": {},
276813          "signature": {
276814            "signature": {
276815              "publicKey": {}
276816            }
276817          },
276818          "modelCard": {
276819            "modelParameters": {
276820              "approach": {}
276821            },
276822            "quantitativeAnalysis": {
276823              "graphics": {}
276824            },
276825            "considerations": {}
276826          }
276827        },
276828        {
276829          "type": "library",
276830          "bom-ref": "pkg:rpm/ol/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026upstream=xz-5.2.4-4.el8_6.src.rpm\u0026distro=ol-8.7\u0026package-id=11e2b6636c8e566f",
276831          "supplier": {},
276832          "publisher": "Oracle America",
276833          "name": "xz-libs",
276834          "version": "5.2.4-4.el8_6",
276835          "licenses": [
276836            {
276837              "license": {
276838                "name": "Public Domain"
276839              }
276840            }
276841          ],
276842          "cpe": "cpe:2.3:a:oracleamerica:xz-libs:5.2.4-4.el8_6:*:*:*:*:*:*:*",
276843          "purl": "pkg:rpm/ol/xz-libs@5.2.4-4.el8_6?arch=x86_64\u0026upstream=xz-5.2.4-4.el8_6.src.rpm\u0026distro=ol-8.7",
276844          "swid": {
276845            "attachment": {}
276846          },
276847          "pedigree": {},
276848          "evidence": {},
276849          "signature": {
276850            "signature": {
276851              "publicKey": {}
276852            }
276853          },
276854          "modelCard": {
276855            "modelParameters": {
276856              "approach": {}
276857            },
276858            "quantitativeAnalysis": {
276859              "graphics": {}
276860            },
276861            "considerations": {}
276862          }
276863        },
276864        {
276865          "type": "library",
276866          "bom-ref": "pkg:rpm/ol/zlib@1.2.11-21.el8_7?arch=x86_64\u0026upstream=zlib-1.2.11-21.el8_7.src.rpm\u0026distro=ol-8.7\u0026package-id=9e29c03d605a517",
276867          "supplier": {},
276868          "publisher": "Oracle America",
276869          "name": "zlib",
276870          "version": "1.2.11-21.el8_7",
276871          "licenses": [
276872            {
276873              "license": {
276874                "name": "zlib and Boost"
276875              }
276876            }
276877          ],
276878          "cpe": "cpe:2.3:a:oracleamerica:zlib:1.2.11-21.el8_7:*:*:*:*:*:*:*",
276879          "purl": "pkg:rpm/ol/zlib@1.2.11-21.el8_7?arch=x86_64\u0026upstream=zlib-1.2.11-21.el8_7.src.rpm\u0026distro=ol-8.7",
276880          "swid": {
276881            "attachment": {}
276882          },
276883          "pedigree": {},
276884          "evidence": {},
276885          "signature": {
276886            "signature": {
276887              "publicKey": {}
276888            }
276889          },
276890          "modelCard": {
276891            "modelParameters": {
276892              "approach": {}
276893            },
276894            "quantitativeAnalysis": {
276895              "graphics": {}
276896            },
276897            "considerations": {}
276898          }
276899        },
276900        {
276901          "type": "library",
276902          "bom-ref": "pkg:rpm/ol/zstd@1.4.4-1.0.1.el8?arch=x86_64\u0026upstream=zstd-1.4.4-1.0.1.el8.src.rpm\u0026distro=ol-8.7\u0026package-id=484a99a19892d833",
276903          "supplier": {},
276904          "publisher": "Oracle America",
276905          "name": "zstd",
276906          "version": "1.4.4-1.0.1.el8",
276907          "licenses": [
276908            {
276909              "license": {
276910                "name": "BSD and GPLv2"
276911              }
276912            }
276913          ],
276914          "cpe": "cpe:2.3:a:oracleamerica:zstd:1.4.4-1.0.1.el8:*:*:*:*:*:*:*",
276915          "purl": "pkg:rpm/ol/zstd@1.4.4-1.0.1.el8?arch=x86_64\u0026upstream=zstd-1.4.4-1.0.1.el8.src.rpm\u0026distro=ol-8.7",
276916          "swid": {
276917            "attachment": {}
276918          },
276919          "pedigree": {},
276920          "evidence": {},
276921          "signature": {
276922            "signature": {
276923              "publicKey": {}
276924            }
276925          },
276926          "modelCard": {
276927            "modelParameters": {
276928              "approach": {}
276929            },
276930            "quantitativeAnalysis": {
276931              "graphics": {}
276932            },
276933            "considerations": {}
276934          }
276935        },
276936        {
276937          "type": "operating-system",
276938          "supplier": {},
276939          "name": "ol",
276940          "version": "8.7",
276941          "description": "Oracle Linux Server 8.7",
276942          "cpe": "cpe:2.3:o:oracle:linux:8:7:server:*:*:*:*:*",
276943          "swid": {
276944            "tagId": "ol",
276945            "name": "ol",
276946            "version": "8.7",
276947            "attachment": {}
276948          },
276949          "pedigree": {},
276950          "externalReferences": [
276951            {
276952              "url": "https://bugzilla.oracle.com/",
276953              "type": "issue-tracker"
276954            },
276955            {
276956              "url": "https://linux.oracle.com/",
276957              "type": "website"
276958            }
276959          ],
276960          "evidence": {},
276961          "signature": {
276962            "signature": {
276963              "publicKey": {}
276964            }
276965          },
276966          "modelCard": {
276967            "modelParameters": {
276968              "approach": {}
276969            },
276970            "quantitativeAnalysis": {
276971              "graphics": {}
276972            },
276973            "considerations": {}
276974          }
276975        },
276976        {
276977          "type": "library",
276978          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.1.0-r0?arch=x86_64\u0026distro=alpine-3.8.4\u0026package-id=e56f802bf50c3ebc",
276979          "supplier": {},
276980          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
276981          "name": "alpine-baselayout",
276982          "version": "3.1.0-r0",
276983          "description": "Alpine base dir structure and init scripts",
276984          "licenses": [
276985            {
276986              "license": {
276987                "id": "GPL-2.0-only"
276988              }
276989            }
276990          ],
276991          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.1.0-r0:*:*:*:*:*:*:*",
276992          "purl": "pkg:apk/alpine/alpine-baselayout@3.1.0-r0?arch=x86_64\u0026distro=alpine-3.8.4",
276993          "swid": {
276994            "attachment": {}
276995          },
276996          "pedigree": {},
276997          "externalReferences": [
276998            {
276999              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
277000              "type": "distribution"
277001            }
277002          ],
277003          "evidence": {},
277004          "signature": {
277005            "signature": {
277006              "publicKey": {}
277007            }
277008          },
277009          "modelCard": {
277010            "modelParameters": {
277011              "approach": {}
277012            },
277013            "quantitativeAnalysis": {
277014              "graphics": {}
277015            },
277016            "considerations": {}
277017          }
277018        },
277019        {
277020          "type": "library",
277021          "bom-ref": "pkg:apk/alpine/alpine-keys@2.1-r1?arch=x86_64\u0026distro=alpine-3.8.4\u0026package-id=b4351671de76187a",
277022          "supplier": {},
277023          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
277024          "name": "alpine-keys",
277025          "version": "2.1-r1",
277026          "description": "Public keys for Alpine Linux packages",
277027          "licenses": [
277028            {
277029              "license": {
277030                "id": "MIT"
277031              }
277032            }
277033          ],
277034          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.1-r1:*:*:*:*:*:*:*",
277035          "purl": "pkg:apk/alpine/alpine-keys@2.1-r1?arch=x86_64\u0026distro=alpine-3.8.4",
277036          "swid": {
277037            "attachment": {}
277038          },
277039          "pedigree": {},
277040          "externalReferences": [
277041            {
277042              "url": "http://alpinelinux.org",
277043              "type": "distribution"
277044            }
277045          ],
277046          "evidence": {},
277047          "signature": {
277048            "signature": {
277049              "publicKey": {}
277050            }
277051          },
277052          "modelCard": {
277053            "modelParameters": {
277054              "approach": {}
277055            },
277056            "quantitativeAnalysis": {
277057              "graphics": {}
277058            },
277059            "considerations": {}
277060          }
277061        },
277062        {
277063          "type": "library",
277064          "bom-ref": "pkg:apk/alpine/apk-tools@2.10.1-r0?arch=x86_64\u0026distro=alpine-3.8.4\u0026package-id=e3a82a72fffc0cef",
277065          "supplier": {},
277066          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
277067          "name": "apk-tools",
277068          "version": "2.10.1-r0",
277069          "description": "Alpine Package Keeper - package manager for alpine",
277070          "licenses": [
277071            {
277072              "license": {
277073                "id": "GPL-2.0-only"
277074              }
277075            }
277076          ],
277077          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.10.1-r0:*:*:*:*:*:*:*",
277078          "purl": "pkg:apk/alpine/apk-tools@2.10.1-r0?arch=x86_64\u0026distro=alpine-3.8.4",
277079          "swid": {
277080            "attachment": {}
277081          },
277082          "pedigree": {},
277083          "externalReferences": [
277084            {
277085              "url": "https://git.alpinelinux.org/cgit/apk-tools/",
277086              "type": "distribution"
277087            }
277088          ],
277089          "evidence": {},
277090          "signature": {
277091            "signature": {
277092              "publicKey": {}
277093            }
277094          },
277095          "modelCard": {
277096            "modelParameters": {
277097              "approach": {}
277098            },
277099            "quantitativeAnalysis": {
277100              "graphics": {}
277101            },
277102            "considerations": {}
277103          }
277104        },
277105        {
277106          "type": "application",
277107          "bom-ref": "dec3f65e3de0551c",
277108          "supplier": {},
277109          "name": "busybox",
277110          "version": "1.28.4",
277111          "cpe": "cpe:2.3:a:busybox:busybox:1.28.4:*:*:*:*:*:*:*",
277112          "swid": {
277113            "attachment": {}
277114          },
277115          "pedigree": {},
277116          "evidence": {},
277117          "signature": {
277118            "signature": {
277119              "publicKey": {}
277120            }
277121          },
277122          "modelCard": {
277123            "modelParameters": {
277124              "approach": {}
277125            },
277126            "quantitativeAnalysis": {
277127              "graphics": {}
277128            },
277129            "considerations": {}
277130          }
277131        },
277132        {
277133          "type": "library",
277134          "bom-ref": "pkg:apk/alpine/busybox@1.28.4-r3?arch=x86_64\u0026distro=alpine-3.8.4\u0026package-id=fb08fd4ae3bd1b14",
277135          "supplier": {},
277136          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
277137          "name": "busybox",
277138          "version": "1.28.4-r3",
277139          "description": "Size optimized toolbox of many common UNIX utilities",
277140          "licenses": [
277141            {
277142              "license": {
277143                "id": "GPL-2.0-only"
277144              }
277145            }
277146          ],
277147          "cpe": "cpe:2.3:a:busybox:busybox:1.28.4-r3:*:*:*:*:*:*:*",
277148          "purl": "pkg:apk/alpine/busybox@1.28.4-r3?arch=x86_64\u0026distro=alpine-3.8.4",
277149          "swid": {
277150            "attachment": {}
277151          },
277152          "pedigree": {},
277153          "externalReferences": [
277154            {
277155              "url": "http://busybox.net",
277156              "type": "distribution"
277157            }
277158          ],
277159          "evidence": {},
277160          "signature": {
277161            "signature": {
277162              "publicKey": {}
277163            }
277164          },
277165          "modelCard": {
277166            "modelParameters": {
277167              "approach": {}
277168            },
277169            "quantitativeAnalysis": {
277170              "graphics": {}
277171            },
277172            "considerations": {}
277173          }
277174        },
277175        {
277176          "type": "library",
277177          "bom-ref": "pkg:apk/alpine/iptables@1.6.2-r0?arch=x86_64\u0026distro=alpine-3.8.4\u0026package-id=dfe40eb2abdb26eb",
277178          "supplier": {},
277179          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
277180          "name": "iptables",
277181          "version": "1.6.2-r0",
277182          "description": "Linux kernel firewall, NAT and packet mangling tools",
277183          "licenses": [
277184            {
277185              "license": {
277186                "id": "GPL-2.0-or-later"
277187              }
277188            }
277189          ],
277190          "cpe": "cpe:2.3:a:iptables:iptables:1.6.2-r0:*:*:*:*:*:*:*",
277191          "purl": "pkg:apk/alpine/iptables@1.6.2-r0?arch=x86_64\u0026distro=alpine-3.8.4",
277192          "swid": {
277193            "attachment": {}
277194          },
277195          "pedigree": {},
277196          "externalReferences": [
277197            {
277198              "url": "http://www.netfilter.org/projects/iptables/index.html",
277199              "type": "distribution"
277200            }
277201          ],
277202          "evidence": {},
277203          "signature": {
277204            "signature": {
277205              "publicKey": {}
277206            }
277207          },
277208          "modelCard": {
277209            "modelParameters": {
277210              "approach": {}
277211            },
277212            "quantitativeAnalysis": {
277213              "graphics": {}
277214            },
277215            "considerations": {}
277216          }
277217        },
277218        {
277219          "type": "library",
277220          "bom-ref": "pkg:apk/alpine/jansson@2.11-r0?arch=x86_64\u0026distro=alpine-3.8.4\u0026package-id=36cff64285183ba9",
277221          "supplier": {},
277222          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
277223          "name": "jansson",
277224          "version": "2.11-r0",
277225          "description": "lightweight JSON library",
277226          "licenses": [
277227            {
277228              "license": {
277229                "id": "MIT"
277230              }
277231            }
277232          ],
277233          "cpe": "cpe:2.3:a:jansson:jansson:2.11-r0:*:*:*:*:*:*:*",
277234          "purl": "pkg:apk/alpine/jansson@2.11-r0?arch=x86_64\u0026distro=alpine-3.8.4",
277235          "swid": {
277236            "attachment": {}
277237          },
277238          "pedigree": {},
277239          "externalReferences": [
277240            {
277241              "url": "http://www.digip.org/jansson/",
277242              "type": "distribution"
277243            }
277244          ],
277245          "evidence": {},
277246          "signature": {
277247            "signature": {
277248              "publicKey": {}
277249            }
277250          },
277251          "modelCard": {
277252            "modelParameters": {
277253              "approach": {}
277254            },
277255            "quantitativeAnalysis": {
277256              "graphics": {}
277257            },
277258            "considerations": {}
277259          }
277260        },
277261        {
277262          "type": "library",
277263          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.1-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.8.4\u0026package-id=3bb228b328e73aaa",
277264          "supplier": {},
277265          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
277266          "name": "libc-utils",
277267          "version": "0.7.1-r0",
277268          "description": "Meta package to pull in correct libc",
277269          "licenses": [
277270            {
277271              "license": {
277272                "name": "BSD"
277273              }
277274            }
277275          ],
277276          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.1-r0:*:*:*:*:*:*:*",
277277          "purl": "pkg:apk/alpine/libc-utils@0.7.1-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.8.4",
277278          "swid": {
277279            "attachment": {}
277280          },
277281          "pedigree": {},
277282          "externalReferences": [
277283            {
277284              "url": "http://alpinelinux.org",
277285              "type": "distribution"
277286            }
277287          ],
277288          "evidence": {},
277289          "signature": {
277290            "signature": {
277291              "publicKey": {}
277292            }
277293          },
277294          "modelCard": {
277295            "modelParameters": {
277296              "approach": {}
277297            },
277298            "quantitativeAnalysis": {
277299              "graphics": {}
277300            },
277301            "considerations": {}
277302          }
277303        },
277304        {
277305          "type": "library",
277306          "bom-ref": "pkg:apk/alpine/libmnl@1.0.4-r0?arch=x86_64\u0026distro=alpine-3.8.4\u0026package-id=adf77cd7d691a4a3",
277307          "supplier": {},
277308          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
277309          "name": "libmnl",
277310          "version": "1.0.4-r0",
277311          "description": "Library for minimalistic netlink",
277312          "licenses": [
277313            {
277314              "license": {
277315                "name": "GPL"
277316              }
277317            }
277318          ],
277319          "cpe": "cpe:2.3:a:libmnl:libmnl:1.0.4-r0:*:*:*:*:*:*:*",
277320          "purl": "pkg:apk/alpine/libmnl@1.0.4-r0?arch=x86_64\u0026distro=alpine-3.8.4",
277321          "swid": {
277322            "attachment": {}
277323          },
277324          "pedigree": {},
277325          "externalReferences": [
277326            {
277327              "url": "http://www.netfilter.org/projects/libmnl/",
277328              "type": "distribution"
277329            }
277330          ],
277331          "evidence": {},
277332          "signature": {
277333            "signature": {
277334              "publicKey": {}
277335            }
277336          },
277337          "modelCard": {
277338            "modelParameters": {
277339              "approach": {}
277340            },
277341            "quantitativeAnalysis": {
277342              "graphics": {}
277343            },
277344            "considerations": {}
277345          }
277346        },
277347        {
277348          "type": "library",
277349          "bom-ref": "pkg:apk/alpine/libnftnl-libs@1.1.1-r0?arch=x86_64\u0026upstream=libnftnl\u0026distro=alpine-3.8.4\u0026package-id=24060b5e43a280f0",
277350          "supplier": {},
277351          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
277352          "name": "libnftnl-libs",
277353          "version": "1.1.1-r0",
277354          "description": "Netfilter library providing interface to the nf_tables subsystem (libraries)",
277355          "licenses": [
277356            {
277357              "license": {
277358                "id": "GPL-2.0-or-later"
277359              }
277360            }
277361          ],
277362          "cpe": "cpe:2.3:a:libnftnl-libs:libnftnl-libs:1.1.1-r0:*:*:*:*:*:*:*",
277363          "purl": "pkg:apk/alpine/libnftnl-libs@1.1.1-r0?arch=x86_64\u0026upstream=libnftnl\u0026distro=alpine-3.8.4",
277364          "swid": {
277365            "attachment": {}
277366          },
277367          "pedigree": {},
277368          "externalReferences": [
277369            {
277370              "url": "https://netfilter.org/projects/libnftnl",
277371              "type": "distribution"
277372            }
277373          ],
277374          "evidence": {},
277375          "signature": {
277376            "signature": {
277377              "publicKey": {}
277378            }
277379          },
277380          "modelCard": {
277381            "modelParameters": {
277382              "approach": {}
277383            },
277384            "quantitativeAnalysis": {
277385              "graphics": {}
277386            },
277387            "considerations": {}
277388          }
277389        },
277390        {
277391          "type": "library",
277392          "bom-ref": "pkg:apk/alpine/libressl2.7-libcrypto@2.7.5-r0?arch=x86_64\u0026upstream=libressl\u0026distro=alpine-3.8.4\u0026package-id=5146260aae7c273",
277393          "supplier": {},
277394          "publisher": "Orion \u003csystmkor@gmail.com\u003e",
277395          "name": "libressl2.7-libcrypto",
277396          "version": "2.7.5-r0",
277397          "description": "libressl libcrypto library",
277398          "licenses": [
277399            {
277400              "license": {
277401                "name": "custom"
277402              }
277403            }
277404          ],
277405          "cpe": "cpe:2.3:a:libressl2.7-libcrypto:libressl2.7-libcrypto:2.7.5-r0:*:*:*:*:*:*:*",
277406          "purl": "pkg:apk/alpine/libressl2.7-libcrypto@2.7.5-r0?arch=x86_64\u0026upstream=libressl\u0026distro=alpine-3.8.4",
277407          "swid": {
277408            "attachment": {}
277409          },
277410          "pedigree": {},
277411          "externalReferences": [
277412            {
277413              "url": "https://www.libressl.org/",
277414              "type": "distribution"
277415            }
277416          ],
277417          "evidence": {},
277418          "signature": {
277419            "signature": {
277420              "publicKey": {}
277421            }
277422          },
277423          "modelCard": {
277424            "modelParameters": {
277425              "approach": {}
277426            },
277427            "quantitativeAnalysis": {
277428              "graphics": {}
277429            },
277430            "considerations": {}
277431          }
277432        },
277433        {
277434          "type": "library",
277435          "bom-ref": "pkg:apk/alpine/libressl2.7-libssl@2.7.5-r0?arch=x86_64\u0026upstream=libressl\u0026distro=alpine-3.8.4\u0026package-id=a0d4a5c231780c49",
277436          "supplier": {},
277437          "publisher": "Orion \u003csystmkor@gmail.com\u003e",
277438          "name": "libressl2.7-libssl",
277439          "version": "2.7.5-r0",
277440          "description": "libressl libssl library",
277441          "licenses": [
277442            {
277443              "license": {
277444                "name": "custom"
277445              }
277446            }
277447          ],
277448          "cpe": "cpe:2.3:a:libressl2.7-libssl:libressl2.7-libssl:2.7.5-r0:*:*:*:*:*:*:*",
277449          "purl": "pkg:apk/alpine/libressl2.7-libssl@2.7.5-r0?arch=x86_64\u0026upstream=libressl\u0026distro=alpine-3.8.4",
277450          "swid": {
277451            "attachment": {}
277452          },
277453          "pedigree": {},
277454          "externalReferences": [
277455            {
277456              "url": "https://www.libressl.org/",
277457              "type": "distribution"
277458            }
277459          ],
277460          "evidence": {},
277461          "signature": {
277462            "signature": {
277463              "publicKey": {}
277464            }
277465          },
277466          "modelCard": {
277467            "modelParameters": {
277468              "approach": {}
277469            },
277470            "quantitativeAnalysis": {
277471              "graphics": {}
277472            },
277473            "considerations": {}
277474          }
277475        },
277476        {
277477          "type": "library",
277478          "bom-ref": "pkg:apk/alpine/libressl2.7-libtls@2.7.5-r0?arch=x86_64\u0026upstream=libressl\u0026distro=alpine-3.8.4\u0026package-id=4c55afdaf10e2a",
277479          "supplier": {},
277480          "publisher": "Orion \u003csystmkor@gmail.com\u003e",
277481          "name": "libressl2.7-libtls",
277482          "version": "2.7.5-r0",
277483          "description": "libressl libtls library",
277484          "licenses": [
277485            {
277486              "license": {
277487                "name": "custom"
277488              }
277489            }
277490          ],
277491          "cpe": "cpe:2.3:a:libressl2.7-libtls:libressl2.7-libtls:2.7.5-r0:*:*:*:*:*:*:*",
277492          "purl": "pkg:apk/alpine/libressl2.7-libtls@2.7.5-r0?arch=x86_64\u0026upstream=libressl\u0026distro=alpine-3.8.4",
277493          "swid": {
277494            "attachment": {}
277495          },
277496          "pedigree": {},
277497          "externalReferences": [
277498            {
277499              "url": "https://www.libressl.org/",
277500              "type": "distribution"
277501            }
277502          ],
277503          "evidence": {},
277504          "signature": {
277505            "signature": {
277506              "publicKey": {}
277507            }
277508          },
277509          "modelCard": {
277510            "modelParameters": {
277511              "approach": {}
277512            },
277513            "quantitativeAnalysis": {
277514              "graphics": {}
277515            },
277516            "considerations": {}
277517          }
277518        },
277519        {
277520          "type": "library",
277521          "bom-ref": "pkg:apk/alpine/musl@1.1.19-r10?arch=x86_64\u0026distro=alpine-3.8.4\u0026package-id=b43d3dffedfa0034",
277522          "supplier": {},
277523          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
277524          "name": "musl",
277525          "version": "1.1.19-r10",
277526          "description": "the musl c library (libc) implementation",
277527          "licenses": [
277528            {
277529              "license": {
277530                "id": "MIT"
277531              }
277532            }
277533          ],
277534          "cpe": "cpe:2.3:a:musl-libc:musl:1.1.19-r10:*:*:*:*:*:*:*",
277535          "purl": "pkg:apk/alpine/musl@1.1.19-r10?arch=x86_64\u0026distro=alpine-3.8.4",
277536          "swid": {
277537            "attachment": {}
277538          },
277539          "pedigree": {},
277540          "externalReferences": [
277541            {
277542              "url": "http://www.musl-libc.org/",
277543              "type": "distribution"
277544            }
277545          ],
277546          "evidence": {},
277547          "signature": {
277548            "signature": {
277549              "publicKey": {}
277550            }
277551          },
277552          "modelCard": {
277553            "modelParameters": {
277554              "approach": {}
277555            },
277556            "quantitativeAnalysis": {
277557              "graphics": {}
277558            },
277559            "considerations": {}
277560          }
277561        },
277562        {
277563          "type": "library",
277564          "bom-ref": "pkg:apk/alpine/musl-utils@1.1.19-r10?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.8.4\u0026package-id=a8132acb12c92c11",
277565          "supplier": {},
277566          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
277567          "name": "musl-utils",
277568          "version": "1.1.19-r10",
277569          "description": "the musl c library (libc) implementation",
277570          "licenses": [
277571            {
277572              "license": {
277573                "id": "MIT"
277574              }
277575            },
277576            {
277577              "license": {
277578                "name": "BSD"
277579              }
277580            },
277581            {
277582              "license": {
277583                "id": "GPL-2.0-or-later"
277584              }
277585            }
277586          ],
277587          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.1.19-r10:*:*:*:*:*:*:*",
277588          "purl": "pkg:apk/alpine/musl-utils@1.1.19-r10?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.8.4",
277589          "swid": {
277590            "attachment": {}
277591          },
277592          "pedigree": {},
277593          "externalReferences": [
277594            {
277595              "url": "http://www.musl-libc.org/",
277596              "type": "distribution"
277597            }
277598          ],
277599          "evidence": {},
277600          "signature": {
277601            "signature": {
277602              "publicKey": {}
277603            }
277604          },
277605          "modelCard": {
277606            "modelParameters": {
277607              "approach": {}
277608            },
277609            "quantitativeAnalysis": {
277610              "graphics": {}
277611            },
277612            "considerations": {}
277613          }
277614        },
277615        {
277616          "type": "library",
277617          "bom-ref": "pkg:apk/alpine/scanelf@1.2.3-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.8.4\u0026package-id=ef1ed8f4e16adccc",
277618          "supplier": {},
277619          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
277620          "name": "scanelf",
277621          "version": "1.2.3-r0",
277622          "description": "Scan ELF binaries for stuff",
277623          "licenses": [
277624            {
277625              "license": {
277626                "id": "GPL-2.0-only"
277627              }
277628            }
277629          ],
277630          "cpe": "cpe:2.3:a:scanelf:scanelf:1.2.3-r0:*:*:*:*:*:*:*",
277631          "purl": "pkg:apk/alpine/scanelf@1.2.3-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.8.4",
277632          "swid": {
277633            "attachment": {}
277634          },
277635          "pedigree": {},
277636          "externalReferences": [
277637            {
277638              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
277639              "type": "distribution"
277640            }
277641          ],
277642          "evidence": {},
277643          "signature": {
277644            "signature": {
277645              "publicKey": {}
277646            }
277647          },
277648          "modelCard": {
277649            "modelParameters": {
277650              "approach": {}
277651            },
277652            "quantitativeAnalysis": {
277653              "graphics": {}
277654            },
277655            "considerations": {}
277656          }
277657        },
277658        {
277659          "type": "library",
277660          "bom-ref": "pkg:apk/alpine/ssl_client@1.28.4-r3?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.8.4\u0026package-id=cd5ebd3f135c0c9c",
277661          "supplier": {},
277662          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
277663          "name": "ssl_client",
277664          "version": "1.28.4-r3",
277665          "description": "EXternal ssl_client for busybox wget",
277666          "licenses": [
277667            {
277668              "license": {
277669                "id": "GPL-2.0-only"
277670              }
277671            }
277672          ],
277673          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.28.4-r3:*:*:*:*:*:*:*",
277674          "purl": "pkg:apk/alpine/ssl_client@1.28.4-r3?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.8.4",
277675          "swid": {
277676            "attachment": {}
277677          },
277678          "pedigree": {},
277679          "externalReferences": [
277680            {
277681              "url": "http://busybox.net",
277682              "type": "distribution"
277683            }
277684          ],
277685          "evidence": {},
277686          "signature": {
277687            "signature": {
277688              "publicKey": {}
277689            }
277690          },
277691          "modelCard": {
277692            "modelParameters": {
277693              "approach": {}
277694            },
277695            "quantitativeAnalysis": {
277696              "graphics": {}
277697            },
277698            "considerations": {}
277699          }
277700        },
277701        {
277702          "type": "library",
277703          "bom-ref": "pkg:apk/alpine/zlib@1.2.11-r1?arch=x86_64\u0026distro=alpine-3.8.4\u0026package-id=a42a0fc199f14a0c",
277704          "supplier": {},
277705          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
277706          "name": "zlib",
277707          "version": "1.2.11-r1",
277708          "description": "A compression/decompression Library",
277709          "licenses": [
277710            {
277711              "license": {
277712                "id": "Zlib"
277713              }
277714            }
277715          ],
277716          "cpe": "cpe:2.3:a:zlib:zlib:1.2.11-r1:*:*:*:*:*:*:*",
277717          "purl": "pkg:apk/alpine/zlib@1.2.11-r1?arch=x86_64\u0026distro=alpine-3.8.4",
277718          "swid": {
277719            "attachment": {}
277720          },
277721          "pedigree": {},
277722          "externalReferences": [
277723            {
277724              "url": "http://zlib.net",
277725              "type": "distribution"
277726            }
277727          ],
277728          "evidence": {},
277729          "signature": {
277730            "signature": {
277731              "publicKey": {}
277732            }
277733          },
277734          "modelCard": {
277735            "modelParameters": {
277736              "approach": {}
277737            },
277738            "quantitativeAnalysis": {
277739              "graphics": {}
277740            },
277741            "considerations": {}
277742          }
277743        },
277744        {
277745          "type": "operating-system",
277746          "supplier": {},
277747          "name": "alpine",
277748          "version": "3.8.4",
277749          "description": "Alpine Linux v3.8",
277750          "swid": {
277751            "tagId": "alpine",
277752            "name": "alpine",
277753            "version": "3.8.4",
277754            "attachment": {}
277755          },
277756          "pedigree": {},
277757          "externalReferences": [
277758            {
277759              "url": "http://bugs.alpinelinux.org",
277760              "type": "issue-tracker"
277761            },
277762            {
277763              "url": "http://alpinelinux.org",
277764              "type": "website"
277765            }
277766          ],
277767          "evidence": {},
277768          "signature": {
277769            "signature": {
277770              "publicKey": {}
277771            }
277772          },
277773          "modelCard": {
277774            "modelParameters": {
277775              "approach": {}
277776            },
277777            "quantitativeAnalysis": {
277778              "graphics": {}
277779            },
277780            "considerations": {}
277781          }
277782        },
277783        {
277784          "type": "library",
277785          "bom-ref": "pkg:apk/alpine/.python-rundeps@20230405.233153?arch=noarch\u0026distro=alpine-3.16.5\u0026package-id=e9dfc81376fa3d93",
277786          "supplier": {},
277787          "name": ".python-rundeps",
277788          "version": "20230405.233153",
277789          "description": "virtual meta package",
277790          "licenses": [
277791            {}
277792          ],
277793          "cpe": "cpe:2.3:a:.python-rundeps:.python-rundeps:20230405.233153:*:*:*:*:*:*:*",
277794          "purl": "pkg:apk/alpine/.python-rundeps@20230405.233153?arch=noarch\u0026distro=alpine-3.16.5",
277795          "swid": {
277796            "attachment": {}
277797          },
277798          "pedigree": {},
277799          "evidence": {},
277800          "signature": {
277801            "signature": {
277802              "publicKey": {}
277803            }
277804          },
277805          "modelCard": {
277806            "modelParameters": {
277807              "approach": {}
277808            },
277809            "quantitativeAnalysis": {
277810              "graphics": {}
277811            },
277812            "considerations": {}
277813          }
277814        },
277815        {
277816          "type": "library",
277817          "bom-ref": "pkg:pypi/datetime@5.1?package-id=c98b2f849408ee70",
277818          "supplier": {},
277819          "author": "Zope Foundation and Contributors \u003czope-dev@zope.org\u003e",
277820          "name": "DateTime",
277821          "version": "5.1",
277822          "licenses": [
277823            {
277824              "license": {
277825                "name": "ZPL 2.1"
277826              }
277827            }
277828          ],
277829          "cpe": "cpe:2.3:a:zope_foundation_and_contributors_project:python-DateTime:5.1:*:*:*:*:*:*:*",
277830          "purl": "pkg:pypi/DateTime@5.1",
277831          "swid": {
277832            "attachment": {}
277833          },
277834          "pedigree": {},
277835          "evidence": {},
277836          "signature": {
277837            "signature": {
277838              "publicKey": {}
277839            }
277840          },
277841          "modelCard": {
277842            "modelParameters": {
277843              "approach": {}
277844            },
277845            "quantitativeAnalysis": {
277846              "graphics": {}
277847            },
277848            "considerations": {}
277849          }
277850        },
277851        {
277852          "type": "library",
277853          "bom-ref": "pkg:pypi/flask@2.0.2?package-id=168c7508d027efb3",
277854          "supplier": {},
277855          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
277856          "name": "Flask",
277857          "version": "2.0.2",
277858          "licenses": [
277859            {
277860              "license": {
277861                "id": "BSD-3-Clause"
277862              }
277863            }
277864          ],
277865          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Flask:2.0.2:*:*:*:*:*:*:*",
277866          "purl": "pkg:pypi/Flask@2.0.2",
277867          "swid": {
277868            "attachment": {}
277869          },
277870          "pedigree": {},
277871          "evidence": {},
277872          "signature": {
277873            "signature": {
277874              "publicKey": {}
277875            }
277876          },
277877          "modelCard": {
277878            "modelParameters": {
277879              "approach": {}
277880            },
277881            "quantitativeAnalysis": {
277882              "graphics": {}
277883            },
277884            "considerations": {}
277885          }
277886        },
277887        {
277888          "type": "library",
277889          "bom-ref": "pkg:pypi/flask-restful@0.3.9?package-id=97e28f1301f3f0f6",
277890          "supplier": {},
277891          "author": "Twilio API Team \u003chelp@twilio.com\u003e",
277892          "name": "Flask-RESTful",
277893          "version": "0.3.9",
277894          "licenses": [
277895            {
277896              "license": {
277897                "name": "BSD"
277898              }
277899            }
277900          ],
277901          "cpe": "cpe:2.3:a:twilio_api_team_project:python-Flask-RESTful:0.3.9:*:*:*:*:*:*:*",
277902          "purl": "pkg:pypi/Flask-RESTful@0.3.9",
277903          "swid": {
277904            "attachment": {}
277905          },
277906          "pedigree": {},
277907          "evidence": {},
277908          "signature": {
277909            "signature": {
277910              "publicKey": {}
277911            }
277912          },
277913          "modelCard": {
277914            "modelParameters": {
277915              "approach": {}
277916            },
277917            "quantitativeAnalysis": {
277918              "graphics": {}
277919            },
277920            "considerations": {}
277921          }
277922        },
277923        {
277924          "type": "library",
277925          "bom-ref": "pkg:pypi/jinja2@3.1.2?package-id=97594fade9112a12",
277926          "supplier": {},
277927          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
277928          "name": "Jinja2",
277929          "version": "3.1.2",
277930          "licenses": [
277931            {
277932              "license": {
277933                "id": "BSD-3-Clause"
277934              }
277935            }
277936          ],
277937          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Jinja2:3.1.2:*:*:*:*:*:*:*",
277938          "purl": "pkg:pypi/Jinja2@3.1.2",
277939          "swid": {
277940            "attachment": {}
277941          },
277942          "pedigree": {},
277943          "evidence": {},
277944          "signature": {
277945            "signature": {
277946              "publicKey": {}
277947            }
277948          },
277949          "modelCard": {
277950            "modelParameters": {
277951              "approach": {}
277952            },
277953            "quantitativeAnalysis": {
277954              "graphics": {}
277955            },
277956            "considerations": {}
277957          }
277958        },
277959        {
277960          "type": "library",
277961          "bom-ref": "pkg:pypi/markupsafe@2.1.2?package-id=994782edc4e3c1ef",
277962          "supplier": {},
277963          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
277964          "name": "MarkupSafe",
277965          "version": "2.1.2",
277966          "licenses": [
277967            {
277968              "license": {
277969                "id": "BSD-3-Clause"
277970              }
277971            }
277972          ],
277973          "cpe": "cpe:2.3:a:armin_ronacher_project:python-MarkupSafe:2.1.2:*:*:*:*:*:*:*",
277974          "purl": "pkg:pypi/MarkupSafe@2.1.2",
277975          "swid": {
277976            "attachment": {}
277977          },
277978          "pedigree": {},
277979          "evidence": {},
277980          "signature": {
277981            "signature": {
277982              "publicKey": {}
277983            }
277984          },
277985          "modelCard": {
277986            "modelParameters": {
277987              "approach": {}
277988            },
277989            "quantitativeAnalysis": {
277990              "graphics": {}
277991            },
277992            "considerations": {}
277993          }
277994        },
277995        {
277996          "type": "library",
277997          "bom-ref": "pkg:pypi/pynacl@1.5.0?package-id=5d4270bfbe9cd87b",
277998          "supplier": {},
277999          "author": "The PyNaCl developers \u003ccryptography-dev@python.org\u003e",
278000          "name": "PyNaCl",
278001          "version": "1.5.0",
278002          "licenses": [
278003            {
278004              "license": {
278005                "name": "Apache License 2.0"
278006              }
278007            }
278008          ],
278009          "cpe": "cpe:2.3:a:pynacl_developers_project:python-PyNaCl:1.5.0:*:*:*:*:*:*:*",
278010          "purl": "pkg:pypi/PyNaCl@1.5.0",
278011          "swid": {
278012            "attachment": {}
278013          },
278014          "pedigree": {},
278015          "evidence": {},
278016          "signature": {
278017            "signature": {
278018              "publicKey": {}
278019            }
278020          },
278021          "modelCard": {
278022            "modelParameters": {
278023              "approach": {}
278024            },
278025            "quantitativeAnalysis": {
278026              "graphics": {}
278027            },
278028            "considerations": {}
278029          }
278030        },
278031        {
278032          "type": "library",
278033          "bom-ref": "pkg:pypi/pyyaml@6.0?package-id=e2779300e3649026",
278034          "supplier": {},
278035          "author": "Kirill Simonov \u003cxi@resolvent.net\u003e",
278036          "name": "PyYAML",
278037          "version": "6.0",
278038          "licenses": [
278039            {
278040              "license": {
278041                "id": "MIT"
278042              }
278043            }
278044          ],
278045          "cpe": "cpe:2.3:a:kirill_simonov_project:python-PyYAML:6.0:*:*:*:*:*:*:*",
278046          "purl": "pkg:pypi/PyYAML@6.0",
278047          "swid": {
278048            "attachment": {}
278049          },
278050          "pedigree": {},
278051          "evidence": {},
278052          "signature": {
278053            "signature": {
278054              "publicKey": {}
278055            }
278056          },
278057          "modelCard": {
278058            "modelParameters": {
278059              "approach": {}
278060            },
278061            "quantitativeAnalysis": {
278062              "graphics": {}
278063            },
278064            "considerations": {}
278065          }
278066        },
278067        {
278068          "type": "library",
278069          "bom-ref": "pkg:pypi/werkzeug@2.2.3?package-id=e1312db9b042abe6",
278070          "supplier": {},
278071          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
278072          "name": "Werkzeug",
278073          "version": "2.2.3",
278074          "licenses": [
278075            {
278076              "license": {
278077                "id": "BSD-3-Clause"
278078              }
278079            }
278080          ],
278081          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Werkzeug:2.2.3:*:*:*:*:*:*:*",
278082          "purl": "pkg:pypi/Werkzeug@2.2.3",
278083          "swid": {
278084            "attachment": {}
278085          },
278086          "pedigree": {},
278087          "evidence": {},
278088          "signature": {
278089            "signature": {
278090              "publicKey": {}
278091            }
278092          },
278093          "modelCard": {
278094            "modelParameters": {
278095              "approach": {}
278096            },
278097            "quantitativeAnalysis": {
278098              "graphics": {}
278099            },
278100            "considerations": {}
278101          }
278102        },
278103        {
278104          "type": "library",
278105          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=61eac5ce8105d394",
278106          "supplier": {},
278107          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
278108          "name": "alpine-baselayout",
278109          "version": "3.2.0-r23",
278110          "description": "Alpine base dir structure and init scripts",
278111          "licenses": [
278112            {
278113              "license": {
278114                "id": "GPL-2.0-only"
278115              }
278116            }
278117          ],
278118          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r23:*:*:*:*:*:*:*",
278119          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5",
278120          "swid": {
278121            "attachment": {}
278122          },
278123          "pedigree": {},
278124          "externalReferences": [
278125            {
278126              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
278127              "type": "distribution"
278128            }
278129          ],
278130          "evidence": {},
278131          "signature": {
278132            "signature": {
278133              "publicKey": {}
278134            }
278135          },
278136          "modelCard": {
278137            "modelParameters": {
278138              "approach": {}
278139            },
278140            "quantitativeAnalysis": {
278141              "graphics": {}
278142            },
278143            "considerations": {}
278144          }
278145        },
278146        {
278147          "type": "library",
278148          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5\u0026package-id=e8c6fcc3a282ed4f",
278149          "supplier": {},
278150          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
278151          "name": "alpine-baselayout-data",
278152          "version": "3.2.0-r23",
278153          "description": "Alpine base dir structure and init scripts",
278154          "licenses": [
278155            {
278156              "license": {
278157                "id": "GPL-2.0-only"
278158              }
278159            }
278160          ],
278161          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.2.0-r23:*:*:*:*:*:*:*",
278162          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5",
278163          "swid": {
278164            "attachment": {}
278165          },
278166          "pedigree": {},
278167          "externalReferences": [
278168            {
278169              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
278170              "type": "distribution"
278171            }
278172          ],
278173          "evidence": {},
278174          "signature": {
278175            "signature": {
278176              "publicKey": {}
278177            }
278178          },
278179          "modelCard": {
278180            "modelParameters": {
278181              "approach": {}
278182            },
278183            "quantitativeAnalysis": {
278184              "graphics": {}
278185            },
278186            "considerations": {}
278187          }
278188        },
278189        {
278190          "type": "library",
278191          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=82d183eb300978cc",
278192          "supplier": {},
278193          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
278194          "name": "alpine-keys",
278195          "version": "2.4-r1",
278196          "description": "Public keys for Alpine Linux packages",
278197          "licenses": [
278198            {
278199              "license": {
278200                "id": "MIT"
278201              }
278202            }
278203          ],
278204          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
278205          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5",
278206          "swid": {
278207            "attachment": {}
278208          },
278209          "pedigree": {},
278210          "externalReferences": [
278211            {
278212              "url": "https://alpinelinux.org",
278213              "type": "distribution"
278214            }
278215          ],
278216          "evidence": {},
278217          "signature": {
278218            "signature": {
278219              "publicKey": {}
278220            }
278221          },
278222          "modelCard": {
278223            "modelParameters": {
278224              "approach": {}
278225            },
278226            "quantitativeAnalysis": {
278227              "graphics": {}
278228            },
278229            "considerations": {}
278230          }
278231        },
278232        {
278233          "type": "library",
278234          "bom-ref": "pkg:pypi/aniso8601@9.0.1?package-id=c43f7de45e50a68",
278235          "supplier": {},
278236          "author": "Brandon Nielsen \u003cnielsenb@jetfuse.net\u003e",
278237          "name": "aniso8601",
278238          "version": "9.0.1",
278239          "licenses": [
278240            {
278241              "license": {
278242                "name": "UNKNOWN"
278243              }
278244            }
278245          ],
278246          "cpe": "cpe:2.3:a:brandon_nielsen_project:python-aniso8601:9.0.1:*:*:*:*:*:*:*",
278247          "purl": "pkg:pypi/aniso8601@9.0.1",
278248          "swid": {
278249            "attachment": {}
278250          },
278251          "pedigree": {},
278252          "evidence": {},
278253          "signature": {
278254            "signature": {
278255              "publicKey": {}
278256            }
278257          },
278258          "modelCard": {
278259            "modelParameters": {
278260              "approach": {}
278261            },
278262            "quantitativeAnalysis": {
278263              "graphics": {}
278264            },
278265            "considerations": {}
278266          }
278267        },
278268        {
278269          "type": "library",
278270          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=42d502b764a37310",
278271          "supplier": {},
278272          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
278273          "name": "apk-tools",
278274          "version": "2.12.9-r3",
278275          "description": "Alpine Package Keeper - package manager for alpine",
278276          "licenses": [
278277            {
278278              "license": {
278279                "id": "GPL-2.0-only"
278280              }
278281            }
278282          ],
278283          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.9-r3:*:*:*:*:*:*:*",
278284          "purl": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5",
278285          "swid": {
278286            "attachment": {}
278287          },
278288          "pedigree": {},
278289          "externalReferences": [
278290            {
278291              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
278292              "type": "distribution"
278293            }
278294          ],
278295          "evidence": {},
278296          "signature": {
278297            "signature": {
278298              "publicKey": {}
278299            }
278300          },
278301          "modelCard": {
278302            "modelParameters": {
278303              "approach": {}
278304            },
278305            "quantitativeAnalysis": {
278306              "graphics": {}
278307            },
278308            "considerations": {}
278309          }
278310        },
278311        {
278312          "type": "library",
278313          "bom-ref": "pkg:pypi/bcrypt@4.0.1?package-id=5e17286c761d6c53",
278314          "supplier": {},
278315          "author": "The Python Cryptographic Authority developers \u003ccryptography-dev@python.org\u003e",
278316          "name": "bcrypt",
278317          "version": "4.0.1",
278318          "licenses": [
278319            {
278320              "license": {
278321                "name": "Apache License, Version 2.0"
278322              }
278323            }
278324          ],
278325          "cpe": "cpe:2.3:a:python_cryptographic_authority_developers_project:python-bcrypt:4.0.1:*:*:*:*:*:*:*",
278326          "purl": "pkg:pypi/bcrypt@4.0.1",
278327          "swid": {
278328            "attachment": {}
278329          },
278330          "pedigree": {},
278331          "evidence": {},
278332          "signature": {
278333            "signature": {
278334              "publicKey": {}
278335            }
278336          },
278337          "modelCard": {
278338            "modelParameters": {
278339              "approach": {}
278340            },
278341            "quantitativeAnalysis": {
278342              "graphics": {}
278343            },
278344            "considerations": {}
278345          }
278346        },
278347        {
278348          "type": "application",
278349          "bom-ref": "e14718c64f5147f4",
278350          "supplier": {},
278351          "name": "busybox",
278352          "version": "1.35.0",
278353          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
278354          "swid": {
278355            "attachment": {}
278356          },
278357          "pedigree": {},
278358          "evidence": {},
278359          "signature": {
278360            "signature": {
278361              "publicKey": {}
278362            }
278363          },
278364          "modelCard": {
278365            "modelParameters": {
278366              "approach": {}
278367            },
278368            "quantitativeAnalysis": {
278369              "graphics": {}
278370            },
278371            "considerations": {}
278372          }
278373        },
278374        {
278375          "type": "library",
278376          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=4b48ef6f6b983526",
278377          "supplier": {},
278378          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
278379          "name": "busybox",
278380          "version": "1.35.0-r17",
278381          "description": "Size optimized toolbox of many common UNIX utilities",
278382          "licenses": [
278383            {
278384              "license": {
278385                "id": "GPL-2.0-only"
278386              }
278387            }
278388          ],
278389          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r17:*:*:*:*:*:*:*",
278390          "purl": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5",
278391          "swid": {
278392            "attachment": {}
278393          },
278394          "pedigree": {},
278395          "externalReferences": [
278396            {
278397              "url": "https://busybox.net/",
278398              "type": "distribution"
278399            }
278400          ],
278401          "evidence": {},
278402          "signature": {
278403            "signature": {
278404              "publicKey": {}
278405            }
278406          },
278407          "modelCard": {
278408            "modelParameters": {
278409              "approach": {}
278410            },
278411            "quantitativeAnalysis": {
278412              "graphics": {}
278413            },
278414            "considerations": {}
278415          }
278416        },
278417        {
278418          "type": "library",
278419          "bom-ref": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=fbb1924ff870cc71",
278420          "supplier": {},
278421          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
278422          "name": "ca-certificates",
278423          "version": "20220614-r0",
278424          "description": "Common CA certificates PEM files from Mozilla",
278425          "licenses": [
278426            {
278427              "license": {
278428                "id": "MPL-2.0"
278429              }
278430            },
278431            {
278432              "license": {
278433                "name": "AND"
278434              }
278435            },
278436            {
278437              "license": {
278438                "id": "MIT"
278439              }
278440            }
278441          ],
278442          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20220614-r0:*:*:*:*:*:*:*",
278443          "purl": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5",
278444          "swid": {
278445            "attachment": {}
278446          },
278447          "pedigree": {},
278448          "externalReferences": [
278449            {
278450              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
278451              "type": "distribution"
278452            }
278453          ],
278454          "evidence": {},
278455          "signature": {
278456            "signature": {
278457              "publicKey": {}
278458            }
278459          },
278460          "modelCard": {
278461            "modelParameters": {
278462              "approach": {}
278463            },
278464            "quantitativeAnalysis": {
278465              "graphics": {}
278466            },
278467            "considerations": {}
278468          }
278469        },
278470        {
278471          "type": "library",
278472          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5\u0026package-id=30622a1848b22bca",
278473          "supplier": {},
278474          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
278475          "name": "ca-certificates-bundle",
278476          "version": "20220614-r0",
278477          "description": "Pre generated bundle of Mozilla certificates",
278478          "licenses": [
278479            {
278480              "license": {
278481                "id": "MPL-2.0"
278482              }
278483            },
278484            {
278485              "license": {
278486                "name": "AND"
278487              }
278488            },
278489            {
278490              "license": {
278491                "id": "MIT"
278492              }
278493            }
278494          ],
278495          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
278496          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5",
278497          "swid": {
278498            "attachment": {}
278499          },
278500          "pedigree": {},
278501          "externalReferences": [
278502            {
278503              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
278504              "type": "distribution"
278505            }
278506          ],
278507          "evidence": {},
278508          "signature": {
278509            "signature": {
278510              "publicKey": {}
278511            }
278512          },
278513          "modelCard": {
278514            "modelParameters": {
278515              "approach": {}
278516            },
278517            "quantitativeAnalysis": {
278518              "graphics": {}
278519            },
278520            "considerations": {}
278521          }
278522        },
278523        {
278524          "type": "library",
278525          "bom-ref": "pkg:pypi/certifi@2022.12.7?package-id=8ed6b1902e8d327d",
278526          "supplier": {},
278527          "author": "Kenneth Reitz \u003cme@kennethreitz.com\u003e",
278528          "name": "certifi",
278529          "version": "2022.12.7",
278530          "licenses": [
278531            {
278532              "license": {
278533                "id": "MPL-2.0"
278534              }
278535            }
278536          ],
278537          "cpe": "cpe:2.3:a:kenneth_reitz_project:python-certifi:2022.12.7:*:*:*:*:*:*:*",
278538          "purl": "pkg:pypi/certifi@2022.12.7",
278539          "swid": {
278540            "attachment": {}
278541          },
278542          "pedigree": {},
278543          "evidence": {},
278544          "signature": {
278545            "signature": {
278546              "publicKey": {}
278547            }
278548          },
278549          "modelCard": {
278550            "modelParameters": {
278551              "approach": {}
278552            },
278553            "quantitativeAnalysis": {
278554              "graphics": {}
278555            },
278556            "considerations": {}
278557          }
278558        },
278559        {
278560          "type": "library",
278561          "bom-ref": "pkg:pypi/cffi@1.15.1?package-id=cfa0bf0d260d6cea",
278562          "supplier": {},
278563          "author": "Armin Rigo, Maciej Fijalkowski \u003cpython-cffi@googlegroups.com\u003e",
278564          "name": "cffi",
278565          "version": "1.15.1",
278566          "licenses": [
278567            {
278568              "license": {
278569                "id": "MIT"
278570              }
278571            }
278572          ],
278573          "cpe": "cpe:2.3:a:armin_rigo\\,_maciej_fijalkowski_project:python-cffi:1.15.1:*:*:*:*:*:*:*",
278574          "purl": "pkg:pypi/cffi@1.15.1",
278575          "swid": {
278576            "attachment": {}
278577          },
278578          "pedigree": {},
278579          "evidence": {},
278580          "signature": {
278581            "signature": {
278582              "publicKey": {}
278583            }
278584          },
278585          "modelCard": {
278586            "modelParameters": {
278587              "approach": {}
278588            },
278589            "quantitativeAnalysis": {
278590              "graphics": {}
278591            },
278592            "considerations": {}
278593          }
278594        },
278595        {
278596          "type": "library",
278597          "bom-ref": "pkg:pypi/charset-normalizer@3.1.0?package-id=34faaf9d0ad0949a",
278598          "supplier": {},
278599          "author": "Ahmed TAHRI \u003cahmed.tahri@cloudnursery.dev\u003e",
278600          "name": "charset-normalizer",
278601          "version": "3.1.0",
278602          "licenses": [
278603            {
278604              "license": {
278605                "id": "MIT"
278606              }
278607            }
278608          ],
278609          "cpe": "cpe:2.3:a:python-charset-normalizer:python-charset-normalizer:3.1.0:*:*:*:*:*:*:*",
278610          "purl": "pkg:pypi/charset-normalizer@3.1.0",
278611          "swid": {
278612            "attachment": {}
278613          },
278614          "pedigree": {},
278615          "evidence": {},
278616          "signature": {
278617            "signature": {
278618              "publicKey": {}
278619            }
278620          },
278621          "modelCard": {
278622            "modelParameters": {
278623              "approach": {}
278624            },
278625            "quantitativeAnalysis": {
278626              "graphics": {}
278627            },
278628            "considerations": {}
278629          }
278630        },
278631        {
278632          "type": "library",
278633          "bom-ref": "pkg:pypi/ciscoconfparse@1.7.18?package-id=becf5390e3d03897",
278634          "supplier": {},
278635          "author": "Mike Pennington \u003cmike@pennington.net\u003e",
278636          "name": "ciscoconfparse",
278637          "version": "1.7.18",
278638          "licenses": [
278639            {
278640              "license": {
278641                "id": "GPL-3.0-only"
278642              }
278643            }
278644          ],
278645          "cpe": "cpe:2.3:a:mike_pennington_project:python-ciscoconfparse:1.7.18:*:*:*:*:*:*:*",
278646          "purl": "pkg:pypi/ciscoconfparse@1.7.18",
278647          "swid": {
278648            "attachment": {}
278649          },
278650          "pedigree": {},
278651          "evidence": {},
278652          "signature": {
278653            "signature": {
278654              "publicKey": {}
278655            }
278656          },
278657          "modelCard": {
278658            "modelParameters": {
278659              "approach": {}
278660            },
278661            "quantitativeAnalysis": {
278662              "graphics": {}
278663            },
278664            "considerations": {}
278665          }
278666        },
278667        {
278668          "type": "library",
278669          "bom-ref": "pkg:pypi/click@8.1.3?package-id=4f79f04c757ac8c4",
278670          "supplier": {},
278671          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
278672          "name": "click",
278673          "version": "8.1.3",
278674          "licenses": [
278675            {
278676              "license": {
278677                "id": "BSD-3-Clause"
278678              }
278679            }
278680          ],
278681          "cpe": "cpe:2.3:a:armin_ronacher_project:python-click:8.1.3:*:*:*:*:*:*:*",
278682          "purl": "pkg:pypi/click@8.1.3",
278683          "swid": {
278684            "attachment": {}
278685          },
278686          "pedigree": {},
278687          "evidence": {},
278688          "signature": {
278689            "signature": {
278690              "publicKey": {}
278691            }
278692          },
278693          "modelCard": {
278694            "modelParameters": {
278695              "approach": {}
278696            },
278697            "quantitativeAnalysis": {
278698              "graphics": {}
278699            },
278700            "considerations": {}
278701          }
278702        },
278703        {
278704          "type": "library",
278705          "bom-ref": "pkg:pypi/cryptography@40.0.1?package-id=9c8ef417fdbe8e31",
278706          "supplier": {},
278707          "author": "The Python Cryptographic Authority and individual contributors \u003ccryptography-dev@python.org\u003e",
278708          "name": "cryptography",
278709          "version": "40.0.1",
278710          "licenses": [
278711            {
278712              "license": {
278713                "name": "(Apache-2.0 OR BSD-3-Clause) AND PSF-2.0"
278714              }
278715            }
278716          ],
278717          "cpe": "cpe:2.3:a:python_cryptographic_authority_and_individual_contributors_project:python-cryptography:40.0.1:*:*:*:*:*:*:*",
278718          "purl": "pkg:pypi/cryptography@40.0.1",
278719          "swid": {
278720            "attachment": {}
278721          },
278722          "pedigree": {},
278723          "evidence": {},
278724          "signature": {
278725            "signature": {
278726              "publicKey": {}
278727            }
278728          },
278729          "modelCard": {
278730            "modelParameters": {
278731              "approach": {}
278732            },
278733            "quantitativeAnalysis": {
278734              "graphics": {}
278735            },
278736            "considerations": {}
278737          }
278738        },
278739        {
278740          "type": "library",
278741          "bom-ref": "pkg:pypi/deprecat@2.1.1?package-id=914b179b6f388736",
278742          "supplier": {},
278743          "author": "Meenal Jhajharia \u003cmeenal@mjhajharia.com\u003e",
278744          "name": "deprecat",
278745          "version": "2.1.1",
278746          "licenses": [
278747            {
278748              "license": {
278749                "id": "MIT"
278750              }
278751            }
278752          ],
278753          "cpe": "cpe:2.3:a:meenal_jhajharia_project:python-deprecat:2.1.1:*:*:*:*:*:*:*",
278754          "purl": "pkg:pypi/deprecat@2.1.1",
278755          "swid": {
278756            "attachment": {}
278757          },
278758          "pedigree": {},
278759          "evidence": {},
278760          "signature": {
278761            "signature": {
278762              "publicKey": {}
278763            }
278764          },
278765          "modelCard": {
278766            "modelParameters": {
278767              "approach": {}
278768            },
278769            "quantitativeAnalysis": {
278770              "graphics": {}
278771            },
278772            "considerations": {}
278773          }
278774        },
278775        {
278776          "type": "library",
278777          "bom-ref": "pkg:pypi/dictdiffer@0.9.0?package-id=d89647248de0017e",
278778          "supplier": {},
278779          "author": "Invenio Collaboration \u003cinfo@inveniosoftware.org\u003e",
278780          "name": "dictdiffer",
278781          "version": "0.9.0",
278782          "licenses": [
278783            {
278784              "license": {
278785                "name": "UNKNOWN"
278786              }
278787            }
278788          ],
278789          "cpe": "cpe:2.3:a:invenio_collaboration_project:python-dictdiffer:0.9.0:*:*:*:*:*:*:*",
278790          "purl": "pkg:pypi/dictdiffer@0.9.0",
278791          "swid": {
278792            "attachment": {}
278793          },
278794          "pedigree": {},
278795          "evidence": {},
278796          "signature": {
278797            "signature": {
278798              "publicKey": {}
278799            }
278800          },
278801          "modelCard": {
278802            "modelParameters": {
278803              "approach": {}
278804            },
278805            "quantitativeAnalysis": {
278806              "graphics": {}
278807            },
278808            "considerations": {}
278809          }
278810        },
278811        {
278812          "type": "library",
278813          "bom-ref": "pkg:pypi/dnspython@2.3.0?package-id=1a2c3a7b6a7e57f3",
278814          "supplier": {},
278815          "author": "Bob Halley \u003challey@dnspython.org\u003e",
278816          "name": "dnspython",
278817          "version": "2.3.0",
278818          "licenses": [
278819            {
278820              "license": {
278821                "id": "ISC"
278822              }
278823            }
278824          ],
278825          "cpe": "cpe:2.3:a:bob_halley_project:python-dnspython:2.3.0:*:*:*:*:*:*:*",
278826          "purl": "pkg:pypi/dnspython@2.3.0",
278827          "swid": {
278828            "attachment": {}
278829          },
278830          "pedigree": {},
278831          "evidence": {},
278832          "signature": {
278833            "signature": {
278834              "publicKey": {}
278835            }
278836          },
278837          "modelCard": {
278838            "modelParameters": {
278839              "approach": {}
278840            },
278841            "quantitativeAnalysis": {
278842              "graphics": {}
278843            },
278844            "considerations": {}
278845          }
278846        },
278847        {
278848          "type": "library",
278849          "bom-ref": "pkg:apk/alpine/expat@2.5.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=473c10d9103a81b0",
278850          "supplier": {},
278851          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
278852          "name": "expat",
278853          "version": "2.5.0-r0",
278854          "description": "XML Parser library written in C",
278855          "licenses": [
278856            {
278857              "license": {
278858                "id": "MIT"
278859              }
278860            }
278861          ],
278862          "cpe": "cpe:2.3:a:expat:expat:2.5.0-r0:*:*:*:*:*:*:*",
278863          "purl": "pkg:apk/alpine/expat@2.5.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
278864          "swid": {
278865            "attachment": {}
278866          },
278867          "pedigree": {},
278868          "externalReferences": [
278869            {
278870              "url": "https://libexpat.github.io/",
278871              "type": "distribution"
278872            }
278873          ],
278874          "evidence": {},
278875          "signature": {
278876            "signature": {
278877              "publicKey": {}
278878            }
278879          },
278880          "modelCard": {
278881            "modelParameters": {
278882              "approach": {}
278883            },
278884            "quantitativeAnalysis": {
278885              "graphics": {}
278886            },
278887            "considerations": {}
278888          }
278889        },
278890        {
278891          "type": "library",
278892          "bom-ref": "pkg:pypi/future@0.18.3?package-id=e924c380b5788b59",
278893          "supplier": {},
278894          "author": "Ed Schofield \u003ced@pythoncharmers.com\u003e",
278895          "name": "future",
278896          "version": "0.18.3",
278897          "licenses": [
278898            {
278899              "license": {
278900                "id": "MIT"
278901              }
278902            }
278903          ],
278904          "cpe": "cpe:2.3:a:ed_schofield_project:python-future:0.18.3:*:*:*:*:*:*:*",
278905          "purl": "pkg:pypi/future@0.18.3",
278906          "swid": {
278907            "attachment": {}
278908          },
278909          "pedigree": {},
278910          "evidence": {},
278911          "signature": {
278912            "signature": {
278913              "publicKey": {}
278914            }
278915          },
278916          "modelCard": {
278917            "modelParameters": {
278918              "approach": {}
278919            },
278920            "quantitativeAnalysis": {
278921              "graphics": {}
278922            },
278923            "considerations": {}
278924          }
278925        },
278926        {
278927          "type": "library",
278928          "bom-ref": "pkg:apk/alpine/gdbm@1.23-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=5a60c1f034fa6943",
278929          "supplier": {},
278930          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
278931          "name": "gdbm",
278932          "version": "1.23-r0",
278933          "description": "GNU dbm is a set of database routines that use extensible hashing",
278934          "licenses": [
278935            {
278936              "license": {
278937                "id": "GPL-3.0-or-later"
278938              }
278939            }
278940          ],
278941          "cpe": "cpe:2.3:a:gdbm:gdbm:1.23-r0:*:*:*:*:*:*:*",
278942          "purl": "pkg:apk/alpine/gdbm@1.23-r0?arch=x86_64\u0026distro=alpine-3.16.5",
278943          "swid": {
278944            "attachment": {}
278945          },
278946          "pedigree": {},
278947          "externalReferences": [
278948            {
278949              "url": "https://www.gnu.org/software/gdbm/",
278950              "type": "distribution"
278951            }
278952          ],
278953          "evidence": {},
278954          "signature": {
278955            "signature": {
278956              "publicKey": {}
278957            }
278958          },
278959          "modelCard": {
278960            "modelParameters": {
278961              "approach": {}
278962            },
278963            "quantitativeAnalysis": {
278964              "graphics": {}
278965            },
278966            "considerations": {}
278967          }
278968        },
278969        {
278970          "type": "library",
278971          "bom-ref": "pkg:pypi/gunicorn@20.1.0?package-id=24954f5c8ff06380",
278972          "supplier": {},
278973          "author": "Benoit Chesneau \u003cbenoitc@e-engura.com\u003e",
278974          "name": "gunicorn",
278975          "version": "20.1.0",
278976          "licenses": [
278977            {
278978              "license": {
278979                "id": "MIT"
278980              }
278981            }
278982          ],
278983          "cpe": "cpe:2.3:a:benoit_chesneau_project:python-gunicorn:20.1.0:*:*:*:*:*:*:*",
278984          "purl": "pkg:pypi/gunicorn@20.1.0",
278985          "swid": {
278986            "attachment": {}
278987          },
278988          "pedigree": {},
278989          "evidence": {},
278990          "signature": {
278991            "signature": {
278992              "publicKey": {}
278993            }
278994          },
278995          "modelCard": {
278996            "modelParameters": {
278997              "approach": {}
278998            },
278999            "quantitativeAnalysis": {
279000              "graphics": {}
279001            },
279002            "considerations": {}
279003          }
279004        },
279005        {
279006          "type": "library",
279007          "bom-ref": "pkg:pypi/idna@3.4?package-id=8d9319999a190c4e",
279008          "supplier": {},
279009          "author": "Kim Davies \u003ckim@cynosure.com.au\u003e",
279010          "name": "idna",
279011          "version": "3.4",
279012          "cpe": "cpe:2.3:a:kim_davies_\\\u003ckim_project:python-idna:3.4:*:*:*:*:*:*:*",
279013          "purl": "pkg:pypi/idna@3.4",
279014          "swid": {
279015            "attachment": {}
279016          },
279017          "pedigree": {},
279018          "evidence": {},
279019          "signature": {
279020            "signature": {
279021              "publicKey": {}
279022            }
279023          },
279024          "modelCard": {
279025            "modelParameters": {
279026              "approach": {}
279027            },
279028            "quantitativeAnalysis": {
279029              "graphics": {}
279030            },
279031            "considerations": {}
279032          }
279033        },
279034        {
279035          "type": "library",
279036          "bom-ref": "pkg:pypi/iniconfig@2.0.0?package-id=c0c19a63f93e01b1",
279037          "supplier": {},
279038          "author": "Ronny Pfannschmidt \u003copensource@ronnypfannschmidt.de\u003e, Holger Krekel \u003cholger.krekel@gmail.com\u003e",
279039          "name": "iniconfig",
279040          "version": "2.0.0",
279041          "cpe": "cpe:2.3:a:ronny_pfannschmidt_\\\u003copensource_project:python-iniconfig:2.0.0:*:*:*:*:*:*:*",
279042          "purl": "pkg:pypi/iniconfig@2.0.0",
279043          "swid": {
279044            "attachment": {}
279045          },
279046          "pedigree": {},
279047          "evidence": {},
279048          "signature": {
279049            "signature": {
279050              "publicKey": {}
279051            }
279052          },
279053          "modelCard": {
279054            "modelParameters": {
279055              "approach": {}
279056            },
279057            "quantitativeAnalysis": {
279058              "graphics": {}
279059            },
279060            "considerations": {}
279061          }
279062        },
279063        {
279064          "type": "library",
279065          "bom-ref": "pkg:pypi/itsdangerous@2.1.2?package-id=cbcc6ff7e3f6dccf",
279066          "supplier": {},
279067          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
279068          "name": "itsdangerous",
279069          "version": "2.1.2",
279070          "licenses": [
279071            {
279072              "license": {
279073                "id": "BSD-3-Clause"
279074              }
279075            }
279076          ],
279077          "cpe": "cpe:2.3:a:armin_ronacher_project:python-itsdangerous:2.1.2:*:*:*:*:*:*:*",
279078          "purl": "pkg:pypi/itsdangerous@2.1.2",
279079          "swid": {
279080            "attachment": {}
279081          },
279082          "pedigree": {},
279083          "evidence": {},
279084          "signature": {
279085            "signature": {
279086              "publicKey": {}
279087            }
279088          },
279089          "modelCard": {
279090            "modelParameters": {
279091              "approach": {}
279092            },
279093            "quantitativeAnalysis": {
279094              "graphics": {}
279095            },
279096            "considerations": {}
279097          }
279098        },
279099        {
279100          "type": "library",
279101          "bom-ref": "pkg:pypi/junos-eznc@2.6.7?package-id=3b69d9bcdb015215",
279102          "supplier": {},
279103          "author": "Jeremy Schulman, Nitin Kumar, Rick Sherman, Stacy Smith \u003cjnpr-community-netdev@juniper.net\u003e",
279104          "name": "junos-eznc",
279105          "version": "2.6.7",
279106          "licenses": [
279107            {
279108              "license": {
279109                "name": "Apache 2.0"
279110              }
279111            }
279112          ],
279113          "cpe": "cpe:2.3:a:jeremy_schulman\\,_nitin_kumar\\,_rick_sherman\\,_stacy_smith_project:python-junos-eznc:2.6.7:*:*:*:*:*:*:*",
279114          "purl": "pkg:pypi/junos-eznc@2.6.7",
279115          "swid": {
279116            "attachment": {}
279117          },
279118          "pedigree": {},
279119          "evidence": {},
279120          "signature": {
279121            "signature": {
279122              "publicKey": {}
279123            }
279124          },
279125          "modelCard": {
279126            "modelParameters": {
279127              "approach": {}
279128            },
279129            "quantitativeAnalysis": {
279130              "graphics": {}
279131            },
279132            "considerations": {}
279133          }
279134        },
279135        {
279136          "type": "library",
279137          "bom-ref": "pkg:apk/alpine/keyutils-libs@1.6.3-r1?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.16.5\u0026package-id=8ee597dfe194ab60",
279138          "supplier": {},
279139          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279140          "name": "keyutils-libs",
279141          "version": "1.6.3-r1",
279142          "description": "Key utilities library",
279143          "licenses": [
279144            {
279145              "license": {
279146                "id": "GPL-2.0-or-later"
279147              }
279148            },
279149            {
279150              "license": {
279151                "id": "LGPL-2.0-or-later"
279152              }
279153            }
279154          ],
279155          "cpe": "cpe:2.3:a:keyutils-libs:keyutils-libs:1.6.3-r1:*:*:*:*:*:*:*",
279156          "purl": "pkg:apk/alpine/keyutils-libs@1.6.3-r1?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.16.5",
279157          "swid": {
279158            "attachment": {}
279159          },
279160          "pedigree": {},
279161          "externalReferences": [
279162            {
279163              "url": "https://people.redhat.com/~dhowells/keyutils/",
279164              "type": "distribution"
279165            }
279166          ],
279167          "evidence": {},
279168          "signature": {
279169            "signature": {
279170              "publicKey": {}
279171            }
279172          },
279173          "modelCard": {
279174            "modelParameters": {
279175              "approach": {}
279176            },
279177            "quantitativeAnalysis": {
279178              "graphics": {}
279179            },
279180            "considerations": {}
279181          }
279182        },
279183        {
279184          "type": "library",
279185          "bom-ref": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=50afffc56cc7e53",
279186          "supplier": {},
279187          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279188          "name": "krb5-conf",
279189          "version": "1.0-r2",
279190          "description": "Shared krb5.conf for both MIT krb5 and heimdal",
279191          "licenses": [
279192            {
279193              "license": {
279194                "id": "MIT"
279195              }
279196            }
279197          ],
279198          "cpe": "cpe:2.3:a:krb5-conf:krb5-conf:1.0-r2:*:*:*:*:*:*:*",
279199          "purl": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=alpine-3.16.5",
279200          "swid": {
279201            "attachment": {}
279202          },
279203          "pedigree": {},
279204          "externalReferences": [
279205            {
279206              "url": "https://web.mit.edu/kerberos/www/",
279207              "type": "distribution"
279208            }
279209          ],
279210          "evidence": {},
279211          "signature": {
279212            "signature": {
279213              "publicKey": {}
279214            }
279215          },
279216          "modelCard": {
279217            "modelParameters": {
279218              "approach": {}
279219            },
279220            "quantitativeAnalysis": {
279221              "graphics": {}
279222            },
279223            "considerations": {}
279224          }
279225        },
279226        {
279227          "type": "library",
279228          "bom-ref": "pkg:apk/alpine/krb5-libs@1.19.4-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.16.5\u0026package-id=4cdf917c85417723",
279229          "supplier": {},
279230          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279231          "name": "krb5-libs",
279232          "version": "1.19.4-r0",
279233          "description": "The shared libraries used by Kerberos 5",
279234          "licenses": [
279235            {
279236              "license": {
279237                "id": "MIT"
279238              }
279239            }
279240          ],
279241          "cpe": "cpe:2.3:a:krb5-libs:krb5-libs:1.19.4-r0:*:*:*:*:*:*:*",
279242          "purl": "pkg:apk/alpine/krb5-libs@1.19.4-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.16.5",
279243          "swid": {
279244            "attachment": {}
279245          },
279246          "pedigree": {},
279247          "externalReferences": [
279248            {
279249              "url": "https://web.mit.edu/kerberos/www/",
279250              "type": "distribution"
279251            }
279252          ],
279253          "evidence": {},
279254          "signature": {
279255            "signature": {
279256              "publicKey": {}
279257            }
279258          },
279259          "modelCard": {
279260            "modelParameters": {
279261              "approach": {}
279262            },
279263            "quantitativeAnalysis": {
279264              "graphics": {}
279265            },
279266            "considerations": {}
279267          }
279268        },
279269        {
279270          "type": "library",
279271          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.16.5\u0026package-id=b681aee18ae0aa50",
279272          "supplier": {},
279273          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279274          "name": "libbz2",
279275          "version": "1.0.8-r1",
279276          "description": "Shared library for bz2",
279277          "licenses": [
279278            {
279279              "license": {
279280                "id": "bzip2-1.0.6"
279281              }
279282            }
279283          ],
279284          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r1:*:*:*:*:*:*:*",
279285          "purl": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.16.5",
279286          "swid": {
279287            "attachment": {}
279288          },
279289          "pedigree": {},
279290          "externalReferences": [
279291            {
279292              "url": "http://sources.redhat.com/bzip2",
279293              "type": "distribution"
279294            }
279295          ],
279296          "evidence": {},
279297          "signature": {
279298            "signature": {
279299              "publicKey": {}
279300            }
279301          },
279302          "modelCard": {
279303            "modelParameters": {
279304              "approach": {}
279305            },
279306            "quantitativeAnalysis": {
279307              "graphics": {}
279308            },
279309            "considerations": {}
279310          }
279311        },
279312        {
279313          "type": "library",
279314          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5\u0026package-id=2abd3b45f6fa4702",
279315          "supplier": {},
279316          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279317          "name": "libc-utils",
279318          "version": "0.7.2-r3",
279319          "description": "Meta package to pull in correct libc",
279320          "licenses": [
279321            {
279322              "license": {
279323                "id": "BSD-2-Clause"
279324              }
279325            },
279326            {
279327              "license": {
279328                "name": "AND"
279329              }
279330            },
279331            {
279332              "license": {
279333                "id": "BSD-3-Clause"
279334              }
279335            }
279336          ],
279337          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
279338          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5",
279339          "swid": {
279340            "attachment": {}
279341          },
279342          "pedigree": {},
279343          "externalReferences": [
279344            {
279345              "url": "https://alpinelinux.org",
279346              "type": "distribution"
279347            }
279348          ],
279349          "evidence": {},
279350          "signature": {
279351            "signature": {
279352              "publicKey": {}
279353            }
279354          },
279355          "modelCard": {
279356            "modelParameters": {
279357              "approach": {}
279358            },
279359            "quantitativeAnalysis": {
279360              "graphics": {}
279361            },
279362            "considerations": {}
279363          }
279364        },
279365        {
279366          "type": "library",
279367          "bom-ref": "pkg:apk/alpine/libcom_err@1.46.6-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.16.5\u0026package-id=25b329ab3289e91c",
279368          "supplier": {},
279369          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279370          "name": "libcom_err",
279371          "version": "1.46.6-r0",
279372          "description": "Common error description library",
279373          "licenses": [
279374            {
279375              "license": {
279376                "id": "GPL-2.0-or-later"
279377              }
279378            },
279379            {
279380              "license": {
279381                "name": "AND"
279382              }
279383            },
279384            {
279385              "license": {
279386                "id": "LGPL-2.0-or-later"
279387              }
279388            },
279389            {
279390              "license": {
279391                "name": "AND"
279392              }
279393            },
279394            {
279395              "license": {
279396                "id": "BSD-3-Clause"
279397              }
279398            },
279399            {
279400              "license": {
279401                "name": "AND"
279402              }
279403            },
279404            {
279405              "license": {
279406                "id": "MIT"
279407              }
279408            }
279409          ],
279410          "cpe": "cpe:2.3:a:libcom-err:libcom-err:1.46.6-r0:*:*:*:*:*:*:*",
279411          "purl": "pkg:apk/alpine/libcom_err@1.46.6-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.16.5",
279412          "swid": {
279413            "attachment": {}
279414          },
279415          "pedigree": {},
279416          "externalReferences": [
279417            {
279418              "url": "http://e2fsprogs.sourceforge.net",
279419              "type": "distribution"
279420            }
279421          ],
279422          "evidence": {},
279423          "signature": {
279424            "signature": {
279425              "publicKey": {}
279426            }
279427          },
279428          "modelCard": {
279429            "modelParameters": {
279430              "approach": {}
279431            },
279432            "quantitativeAnalysis": {
279433              "graphics": {}
279434            },
279435            "considerations": {}
279436          }
279437        },
279438        {
279439          "type": "library",
279440          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=13bc051822a24e8d",
279441          "supplier": {},
279442          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
279443          "name": "libcrypto1.1",
279444          "version": "1.1.1t-r2",
279445          "description": "Crypto library from openssl",
279446          "licenses": [
279447            {
279448              "license": {
279449                "id": "OpenSSL"
279450              }
279451            }
279452          ],
279453          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1t-r2:*:*:*:*:*:*:*",
279454          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
279455          "swid": {
279456            "attachment": {}
279457          },
279458          "pedigree": {},
279459          "externalReferences": [
279460            {
279461              "url": "https://www.openssl.org/",
279462              "type": "distribution"
279463            }
279464          ],
279465          "evidence": {},
279466          "signature": {
279467            "signature": {
279468              "publicKey": {}
279469            }
279470          },
279471          "modelCard": {
279472            "modelParameters": {
279473              "approach": {}
279474            },
279475            "quantitativeAnalysis": {
279476              "graphics": {}
279477            },
279478            "considerations": {}
279479          }
279480        },
279481        {
279482          "type": "library",
279483          "bom-ref": "pkg:apk/alpine/libedit@20210910.3.1-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=306ebeb39081e8f5",
279484          "supplier": {},
279485          "publisher": "Drew DeVault \u003csir@cmpwn.com\u003e",
279486          "name": "libedit",
279487          "version": "20210910.3.1-r0",
279488          "description": "BSD line editing library",
279489          "licenses": [
279490            {
279491              "license": {
279492                "id": "BSD-3-Clause"
279493              }
279494            }
279495          ],
279496          "cpe": "cpe:2.3:a:libedit:libedit:20210910.3.1-r0:*:*:*:*:*:*:*",
279497          "purl": "pkg:apk/alpine/libedit@20210910.3.1-r0?arch=x86_64\u0026distro=alpine-3.16.5",
279498          "swid": {
279499            "attachment": {}
279500          },
279501          "pedigree": {},
279502          "externalReferences": [
279503            {
279504              "url": "https://www.thrysoee.dk/editline",
279505              "type": "distribution"
279506            }
279507          ],
279508          "evidence": {},
279509          "signature": {
279510            "signature": {
279511              "publicKey": {}
279512            }
279513          },
279514          "modelCard": {
279515            "modelParameters": {
279516              "approach": {}
279517            },
279518            "quantitativeAnalysis": {
279519              "graphics": {}
279520            },
279521            "considerations": {}
279522          }
279523        },
279524        {
279525          "type": "library",
279526          "bom-ref": "pkg:apk/alpine/libffi@3.4.2-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=d9c90e0c86210cde",
279527          "supplier": {},
279528          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279529          "name": "libffi",
279530          "version": "3.4.2-r1",
279531          "description": "portable, high level programming interface to various calling conventions.",
279532          "licenses": [
279533            {
279534              "license": {
279535                "id": "MIT"
279536              }
279537            }
279538          ],
279539          "cpe": "cpe:2.3:a:libffi:libffi:3.4.2-r1:*:*:*:*:*:*:*",
279540          "purl": "pkg:apk/alpine/libffi@3.4.2-r1?arch=x86_64\u0026distro=alpine-3.16.5",
279541          "swid": {
279542            "attachment": {}
279543          },
279544          "pedigree": {},
279545          "externalReferences": [
279546            {
279547              "url": "https://sourceware.org/libffi/",
279548              "type": "distribution"
279549            }
279550          ],
279551          "evidence": {},
279552          "signature": {
279553            "signature": {
279554              "publicKey": {}
279555            }
279556          },
279557          "modelCard": {
279558            "modelParameters": {
279559              "approach": {}
279560            },
279561            "quantitativeAnalysis": {
279562              "graphics": {}
279563            },
279564            "considerations": {}
279565          }
279566        },
279567        {
279568          "type": "library",
279569          "bom-ref": "pkg:apk/alpine/libintl@0.21-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.16.5\u0026package-id=8a4b8fffbba0af61",
279570          "supplier": {},
279571          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
279572          "name": "libintl",
279573          "version": "0.21-r2",
279574          "description": "GNU gettext runtime library",
279575          "licenses": [
279576            {
279577              "license": {
279578                "id": "LGPL-2.1-or-later"
279579              }
279580            }
279581          ],
279582          "cpe": "cpe:2.3:a:libintl:libintl:0.21-r2:*:*:*:*:*:*:*",
279583          "purl": "pkg:apk/alpine/libintl@0.21-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.16.5",
279584          "swid": {
279585            "attachment": {}
279586          },
279587          "pedigree": {},
279588          "externalReferences": [
279589            {
279590              "url": "https://www.gnu.org/software/gettext/gettext.html",
279591              "type": "distribution"
279592            }
279593          ],
279594          "evidence": {},
279595          "signature": {
279596            "signature": {
279597              "publicKey": {}
279598            }
279599          },
279600          "modelCard": {
279601            "modelParameters": {
279602              "approach": {}
279603            },
279604            "quantitativeAnalysis": {
279605              "graphics": {}
279606            },
279607            "considerations": {}
279608          }
279609        },
279610        {
279611          "type": "library",
279612          "bom-ref": "pkg:apk/alpine/libnsl@2.0.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=684ad1c4c0c42987",
279613          "supplier": {},
279614          "publisher": "Valery Kartel \u003cvalery.kartel@gmail.com\u003e",
279615          "name": "libnsl",
279616          "version": "2.0.0-r0",
279617          "description": "Public client interface for NIS(YP) and NIS+ in a IPv6 ready version",
279618          "licenses": [
279619            {
279620              "license": {
279621                "id": "LGPL-2.0-or-later"
279622              }
279623            }
279624          ],
279625          "cpe": "cpe:2.3:a:thkukuk:libnsl:2.0.0-r0:*:*:*:*:*:*:*",
279626          "purl": "pkg:apk/alpine/libnsl@2.0.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
279627          "swid": {
279628            "attachment": {}
279629          },
279630          "pedigree": {},
279631          "externalReferences": [
279632            {
279633              "url": "https://github.com/thkukuk/libnsl",
279634              "type": "distribution"
279635            }
279636          ],
279637          "evidence": {},
279638          "signature": {
279639            "signature": {
279640              "publicKey": {}
279641            }
279642          },
279643          "modelCard": {
279644            "modelParameters": {
279645              "approach": {}
279646            },
279647            "quantitativeAnalysis": {
279648              "graphics": {}
279649            },
279650            "considerations": {}
279651          }
279652        },
279653        {
279654          "type": "library",
279655          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=609cb94e63dc06dd",
279656          "supplier": {},
279657          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
279658          "name": "libssl1.1",
279659          "version": "1.1.1t-r2",
279660          "description": "SSL shared libraries",
279661          "licenses": [
279662            {
279663              "license": {
279664                "id": "OpenSSL"
279665              }
279666            }
279667          ],
279668          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1t-r2:*:*:*:*:*:*:*",
279669          "purl": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
279670          "swid": {
279671            "attachment": {}
279672          },
279673          "pedigree": {},
279674          "externalReferences": [
279675            {
279676              "url": "https://www.openssl.org/",
279677              "type": "distribution"
279678            }
279679          ],
279680          "evidence": {},
279681          "signature": {
279682            "signature": {
279683              "publicKey": {}
279684            }
279685          },
279686          "modelCard": {
279687            "modelParameters": {
279688              "approach": {}
279689            },
279690            "quantitativeAnalysis": {
279691              "graphics": {}
279692            },
279693            "considerations": {}
279694          }
279695        },
279696        {
279697          "type": "library",
279698          "bom-ref": "pkg:apk/alpine/libtirpc@1.3.2-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=7879d46219520605",
279699          "supplier": {},
279700          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279701          "name": "libtirpc",
279702          "version": "1.3.2-r1",
279703          "description": "Transport Independent RPC library (SunRPC replacement)",
279704          "licenses": [
279705            {
279706              "license": {
279707                "id": "BSD-3-Clause"
279708              }
279709            }
279710          ],
279711          "cpe": "cpe:2.3:a:libtirpc:libtirpc:1.3.2-r1:*:*:*:*:*:*:*",
279712          "purl": "pkg:apk/alpine/libtirpc@1.3.2-r1?arch=x86_64\u0026distro=alpine-3.16.5",
279713          "swid": {
279714            "attachment": {}
279715          },
279716          "pedigree": {},
279717          "externalReferences": [
279718            {
279719              "url": "https://sourceforge.net/projects/libtirpc",
279720              "type": "distribution"
279721            }
279722          ],
279723          "evidence": {},
279724          "signature": {
279725            "signature": {
279726              "publicKey": {}
279727            }
279728          },
279729          "modelCard": {
279730            "modelParameters": {
279731              "approach": {}
279732            },
279733            "quantitativeAnalysis": {
279734              "graphics": {}
279735            },
279736            "considerations": {}
279737          }
279738        },
279739        {
279740          "type": "library",
279741          "bom-ref": "pkg:apk/alpine/libtirpc-conf@1.3.2-r1?arch=x86_64\u0026upstream=libtirpc\u0026distro=alpine-3.16.5\u0026package-id=2473c071ab562d92",
279742          "supplier": {},
279743          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279744          "name": "libtirpc-conf",
279745          "version": "1.3.2-r1",
279746          "description": "Configuration files for TI-RPC",
279747          "licenses": [
279748            {
279749              "license": {
279750                "id": "BSD-3-Clause"
279751              }
279752            }
279753          ],
279754          "cpe": "cpe:2.3:a:libtirpc-conf:libtirpc-conf:1.3.2-r1:*:*:*:*:*:*:*",
279755          "purl": "pkg:apk/alpine/libtirpc-conf@1.3.2-r1?arch=x86_64\u0026upstream=libtirpc\u0026distro=alpine-3.16.5",
279756          "swid": {
279757            "attachment": {}
279758          },
279759          "pedigree": {},
279760          "externalReferences": [
279761            {
279762              "url": "https://sourceforge.net/projects/libtirpc",
279763              "type": "distribution"
279764            }
279765          ],
279766          "evidence": {},
279767          "signature": {
279768            "signature": {
279769              "publicKey": {}
279770            }
279771          },
279772          "modelCard": {
279773            "modelParameters": {
279774              "approach": {}
279775            },
279776            "quantitativeAnalysis": {
279777              "graphics": {}
279778            },
279779            "considerations": {}
279780          }
279781        },
279782        {
279783          "type": "library",
279784          "bom-ref": "pkg:apk/alpine/libuuid@2.38-r1?arch=x86_64\u0026upstream=util-linux\u0026distro=alpine-3.16.5\u0026package-id=8732526a564c0dca",
279785          "supplier": {},
279786          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
279787          "name": "libuuid",
279788          "version": "2.38-r1",
279789          "description": "DCE compatible Universally Unique Identifier library",
279790          "licenses": [
279791            {
279792              "license": {
279793                "id": "GPL-3.0-or-later"
279794              }
279795            },
279796            {
279797              "license": {
279798                "name": "AND"
279799              }
279800            },
279801            {
279802              "license": {
279803                "id": "GPL-2.0-or-later"
279804              }
279805            },
279806            {
279807              "license": {
279808                "name": "AND"
279809              }
279810            },
279811            {
279812              "license": {
279813                "id": "GPL-2.0-only"
279814              }
279815            },
279816            {
279817              "license": {
279818                "name": "AND"
279819              }
279820            }
279821          ],
279822          "cpe": "cpe:2.3:a:libuuid:libuuid:2.38-r1:*:*:*:*:*:*:*",
279823          "purl": "pkg:apk/alpine/libuuid@2.38-r1?arch=x86_64\u0026upstream=util-linux\u0026distro=alpine-3.16.5",
279824          "swid": {
279825            "attachment": {}
279826          },
279827          "pedigree": {},
279828          "externalReferences": [
279829            {
279830              "url": "https://git.kernel.org/cgit/utils/util-linux/util-linux.git",
279831              "type": "distribution"
279832            }
279833          ],
279834          "evidence": {},
279835          "signature": {
279836            "signature": {
279837              "publicKey": {}
279838            }
279839          },
279840          "modelCard": {
279841            "modelParameters": {
279842              "approach": {}
279843            },
279844            "quantitativeAnalysis": {
279845              "graphics": {}
279846            },
279847            "considerations": {}
279848          }
279849        },
279850        {
279851          "type": "library",
279852          "bom-ref": "pkg:apk/alpine/libverto@0.3.2-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=b3642afc50cf09b9",
279853          "supplier": {},
279854          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
279855          "name": "libverto",
279856          "version": "0.3.2-r0",
279857          "description": "Main loop abstraction library",
279858          "licenses": [
279859            {
279860              "license": {
279861                "id": "MIT"
279862              }
279863            }
279864          ],
279865          "cpe": "cpe:2.3:a:npmccallum:libverto:0.3.2-r0:*:*:*:*:*:*:*",
279866          "purl": "pkg:apk/alpine/libverto@0.3.2-r0?arch=x86_64\u0026distro=alpine-3.16.5",
279867          "swid": {
279868            "attachment": {}
279869          },
279870          "pedigree": {},
279871          "externalReferences": [
279872            {
279873              "url": "https://github.com/npmccallum/libverto",
279874              "type": "distribution"
279875            }
279876          ],
279877          "evidence": {},
279878          "signature": {
279879            "signature": {
279880              "publicKey": {}
279881            }
279882          },
279883          "modelCard": {
279884            "modelParameters": {
279885              "approach": {}
279886            },
279887            "quantitativeAnalysis": {
279888              "graphics": {}
279889            },
279890            "considerations": {}
279891          }
279892        },
279893        {
279894          "type": "library",
279895          "bom-ref": "pkg:pypi/loguru@0.6.0?package-id=1f020ceb98fc515d",
279896          "supplier": {},
279897          "author": "Delgan \u003cdelgan.py@gmail.com\u003e",
279898          "name": "loguru",
279899          "version": "0.6.0",
279900          "licenses": [
279901            {
279902              "license": {
279903                "name": "MIT license"
279904              }
279905            }
279906          ],
279907          "cpe": "cpe:2.3:a:delgan_py_project:python-loguru:0.6.0:*:*:*:*:*:*:*",
279908          "purl": "pkg:pypi/loguru@0.6.0",
279909          "swid": {
279910            "attachment": {}
279911          },
279912          "pedigree": {},
279913          "evidence": {},
279914          "signature": {
279915            "signature": {
279916              "publicKey": {}
279917            }
279918          },
279919          "modelCard": {
279920            "modelParameters": {
279921              "approach": {}
279922            },
279923            "quantitativeAnalysis": {
279924              "graphics": {}
279925            },
279926            "considerations": {}
279927          }
279928        },
279929        {
279930          "type": "library",
279931          "bom-ref": "pkg:pypi/lxml@4.9.2?package-id=3bf469ca0cb0292c",
279932          "supplier": {},
279933          "author": "lxml dev team \u003clxml-dev@lxml.de\u003e",
279934          "name": "lxml",
279935          "version": "4.9.2",
279936          "licenses": [
279937            {
279938              "license": {
279939                "id": "BSD-3-Clause"
279940              }
279941            }
279942          ],
279943          "cpe": "cpe:2.3:a:lxml_dev_team_project:python-lxml:4.9.2:*:*:*:*:*:*:*",
279944          "purl": "pkg:pypi/lxml@4.9.2",
279945          "swid": {
279946            "attachment": {}
279947          },
279948          "pedigree": {},
279949          "evidence": {},
279950          "signature": {
279951            "signature": {
279952              "publicKey": {}
279953            }
279954          },
279955          "modelCard": {
279956            "modelParameters": {
279957              "approach": {}
279958            },
279959            "quantitativeAnalysis": {
279960              "graphics": {}
279961            },
279962            "considerations": {}
279963          }
279964        },
279965        {
279966          "type": "library",
279967          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=24c6089b81ca7d19",
279968          "supplier": {},
279969          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
279970          "name": "musl",
279971          "version": "1.2.3-r2",
279972          "description": "the musl c library (libc) implementation",
279973          "licenses": [
279974            {
279975              "license": {
279976                "id": "MIT"
279977              }
279978            }
279979          ],
279980          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r2:*:*:*:*:*:*:*",
279981          "purl": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5",
279982          "swid": {
279983            "attachment": {}
279984          },
279985          "pedigree": {},
279986          "externalReferences": [
279987            {
279988              "url": "https://musl.libc.org/",
279989              "type": "distribution"
279990            }
279991          ],
279992          "evidence": {},
279993          "signature": {
279994            "signature": {
279995              "publicKey": {}
279996            }
279997          },
279998          "modelCard": {
279999            "modelParameters": {
280000              "approach": {}
280001            },
280002            "quantitativeAnalysis": {
280003              "graphics": {}
280004            },
280005            "considerations": {}
280006          }
280007        },
280008        {
280009          "type": "library",
280010          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5\u0026package-id=d33c14d727ae74d1",
280011          "supplier": {},
280012          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
280013          "name": "musl-utils",
280014          "version": "1.2.3-r2",
280015          "description": "the musl c library (libc) implementation",
280016          "licenses": [
280017            {
280018              "license": {
280019                "id": "MIT"
280020              }
280021            },
280022            {
280023              "license": {
280024                "name": "BSD"
280025              }
280026            },
280027            {
280028              "license": {
280029                "id": "GPL-2.0-or-later"
280030              }
280031            }
280032          ],
280033          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r2:*:*:*:*:*:*:*",
280034          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5",
280035          "swid": {
280036            "attachment": {}
280037          },
280038          "pedigree": {},
280039          "externalReferences": [
280040            {
280041              "url": "https://musl.libc.org/",
280042              "type": "distribution"
280043            }
280044          ],
280045          "evidence": {},
280046          "signature": {
280047            "signature": {
280048              "publicKey": {}
280049            }
280050          },
280051          "modelCard": {
280052            "modelParameters": {
280053              "approach": {}
280054            },
280055            "quantitativeAnalysis": {
280056              "graphics": {}
280057            },
280058            "considerations": {}
280059          }
280060        },
280061        {
280062          "type": "library",
280063          "bom-ref": "pkg:pypi/napalm@3.3.1?package-id=4915e25f7f2f7086",
280064          "supplier": {},
280065          "author": "David Barroso, Kirk Byers, Mircea Ulinic \u003cdbarrosop@dravetech.com, ping@mirceaulinic.net, ktbyers@twb-tech.com\u003e",
280066          "name": "napalm",
280067          "version": "3.3.1",
280068          "licenses": [
280069            {
280070              "license": {
280071                "name": "Apache 2.0"
280072              }
280073            }
280074          ],
280075          "cpe": "cpe:2.3:a:david_barroso\\,_kirk_byers\\,_mircea_ulinic_project:python-napalm:3.3.1:*:*:*:*:*:*:*",
280076          "purl": "pkg:pypi/napalm@3.3.1",
280077          "swid": {
280078            "attachment": {}
280079          },
280080          "pedigree": {},
280081          "evidence": {},
280082          "signature": {
280083            "signature": {
280084              "publicKey": {}
280085            }
280086          },
280087          "modelCard": {
280088            "modelParameters": {
280089              "approach": {}
280090            },
280091            "quantitativeAnalysis": {
280092              "graphics": {}
280093            },
280094            "considerations": {}
280095          }
280096        },
280097        {
280098          "type": "library",
280099          "bom-ref": "pkg:pypi/napalm-sros@1.0.0?package-id=e812bfbdc7e04221",
280100          "supplier": {},
280101          "author": "Nokia",
280102          "name": "napalm-sros",
280103          "version": "1.0.0",
280104          "licenses": [
280105            {
280106              "license": {
280107                "name": "UNKNOWN"
280108              }
280109            }
280110          ],
280111          "cpe": "cpe:2.3:a:python-napalm-sros:python-napalm-sros:1.0.0:*:*:*:*:*:*:*",
280112          "purl": "pkg:pypi/napalm-sros@1.0.0",
280113          "swid": {
280114            "attachment": {}
280115          },
280116          "pedigree": {},
280117          "evidence": {},
280118          "signature": {
280119            "signature": {
280120              "publicKey": {}
280121            }
280122          },
280123          "modelCard": {
280124            "modelParameters": {
280125              "approach": {}
280126            },
280127            "quantitativeAnalysis": {
280128              "graphics": {}
280129            },
280130            "considerations": {}
280131          }
280132        },
280133        {
280134          "type": "library",
280135          "bom-ref": "pkg:pypi/ncclient@0.6.13?package-id=b140dd2f97fa242b",
280136          "supplier": {},
280137          "author": "Shikhar Bhushan, Leonidas Poulopoulos, Ebben Aries, Einar Nilsen-Nygaard \u003cshikhar@schmizz.net, lpoulopoulos@verisign.com, exa@dscp.org, einarnn@gmail.com\u003e",
280138          "name": "ncclient",
280139          "version": "0.6.13",
280140          "licenses": [
280141            {
280142              "license": {
280143                "name": "Apache 2.0"
280144              }
280145            }
280146          ],
280147          "cpe": "cpe:2.3:a:shikhar_bhushan\\,_leonidas_poulopoulos\\,_ebben_aries\\,_einar_nilsen_nygaard_project:python-ncclient:0.6.13:*:*:*:*:*:*:*",
280148          "purl": "pkg:pypi/ncclient@0.6.13",
280149          "swid": {
280150            "attachment": {}
280151          },
280152          "pedigree": {},
280153          "evidence": {},
280154          "signature": {
280155            "signature": {
280156              "publicKey": {}
280157            }
280158          },
280159          "modelCard": {
280160            "modelParameters": {
280161              "approach": {}
280162            },
280163            "quantitativeAnalysis": {
280164              "graphics": {}
280165            },
280166            "considerations": {}
280167          }
280168        },
280169        {
280170          "type": "library",
280171          "bom-ref": "pkg:apk/alpine/ncurses-libs@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5\u0026package-id=c2bd1192d3d60d2c",
280172          "supplier": {},
280173          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
280174          "name": "ncurses-libs",
280175          "version": "6.3_p20220521-r0",
280176          "description": "Ncurses libraries",
280177          "licenses": [
280178            {
280179              "license": {
280180                "id": "MIT"
280181              }
280182            }
280183          ],
280184          "cpe": "cpe:2.3:a:ncurses-libs:ncurses-libs:6.3_p20220521-r0:*:*:*:*:*:*:*",
280185          "purl": "pkg:apk/alpine/ncurses-libs@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5",
280186          "swid": {
280187            "attachment": {}
280188          },
280189          "pedigree": {},
280190          "externalReferences": [
280191            {
280192              "url": "https://invisible-island.net/ncurses/",
280193              "type": "distribution"
280194            }
280195          ],
280196          "evidence": {},
280197          "signature": {
280198            "signature": {
280199              "publicKey": {}
280200            }
280201          },
280202          "modelCard": {
280203            "modelParameters": {
280204              "approach": {}
280205            },
280206            "quantitativeAnalysis": {
280207              "graphics": {}
280208            },
280209            "considerations": {}
280210          }
280211        },
280212        {
280213          "type": "library",
280214          "bom-ref": "pkg:apk/alpine/ncurses-terminfo-base@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5\u0026package-id=28679685d0eccfdc",
280215          "supplier": {},
280216          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
280217          "name": "ncurses-terminfo-base",
280218          "version": "6.3_p20220521-r0",
280219          "description": "Descriptions of common terminals",
280220          "licenses": [
280221            {
280222              "license": {
280223                "id": "MIT"
280224              }
280225            }
280226          ],
280227          "cpe": "cpe:2.3:a:ncurses-terminfo-base:ncurses-terminfo-base:6.3_p20220521-r0:*:*:*:*:*:*:*",
280228          "purl": "pkg:apk/alpine/ncurses-terminfo-base@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5",
280229          "swid": {
280230            "attachment": {}
280231          },
280232          "pedigree": {},
280233          "externalReferences": [
280234            {
280235              "url": "https://invisible-island.net/ncurses/",
280236              "type": "distribution"
280237            }
280238          ],
280239          "evidence": {},
280240          "signature": {
280241            "signature": {
280242              "publicKey": {}
280243            }
280244          },
280245          "modelCard": {
280246            "modelParameters": {
280247              "approach": {}
280248            },
280249            "quantitativeAnalysis": {
280250              "graphics": {}
280251            },
280252            "considerations": {}
280253          }
280254        },
280255        {
280256          "type": "library",
280257          "bom-ref": "pkg:pypi/netaddr@0.8.0?package-id=59d7a4595f698ba9",
280258          "supplier": {},
280259          "author": "David P. D. Moss, Stefan Nordhausen et al \u003cdrkjam@gmail.com\u003e",
280260          "name": "netaddr",
280261          "version": "0.8.0",
280262          "licenses": [
280263            {
280264              "license": {
280265                "name": "BSD License"
280266              }
280267            }
280268          ],
280269          "cpe": "cpe:2.3:a:david_p__d__moss\\,_stefan_nordhausen_et_al_project:python-netaddr:0.8.0:*:*:*:*:*:*:*",
280270          "purl": "pkg:pypi/netaddr@0.8.0",
280271          "swid": {
280272            "attachment": {}
280273          },
280274          "pedigree": {},
280275          "evidence": {},
280276          "signature": {
280277            "signature": {
280278              "publicKey": {}
280279            }
280280          },
280281          "modelCard": {
280282            "modelParameters": {
280283              "approach": {}
280284            },
280285            "quantitativeAnalysis": {
280286              "graphics": {}
280287            },
280288            "considerations": {}
280289          }
280290        },
280291        {
280292          "type": "library",
280293          "bom-ref": "pkg:pypi/netmiko@3.4.0?package-id=cfb93ff534049a84",
280294          "supplier": {},
280295          "author": "Kirk Byers \u003cktbyers@twb-tech.com\u003e",
280296          "name": "netmiko",
280297          "version": "3.4.0",
280298          "licenses": [
280299            {
280300              "license": {
280301                "id": "MIT"
280302              }
280303            }
280304          ],
280305          "cpe": "cpe:2.3:a:kirk_byers_project:python-netmiko:3.4.0:*:*:*:*:*:*:*",
280306          "purl": "pkg:pypi/netmiko@3.4.0",
280307          "swid": {
280308            "attachment": {}
280309          },
280310          "pedigree": {},
280311          "evidence": {},
280312          "signature": {
280313            "signature": {
280314              "publicKey": {}
280315            }
280316          },
280317          "modelCard": {
280318            "modelParameters": {
280319              "approach": {}
280320            },
280321            "quantitativeAnalysis": {
280322              "graphics": {}
280323            },
280324            "considerations": {}
280325          }
280326        },
280327        {
280328          "type": "library",
280329          "bom-ref": "pkg:pypi/ntc-templates@3.3.0?package-id=a372be663225eb7e",
280330          "supplier": {},
280331          "author": "Network to Code \u003cinfo@networktocode.com\u003e",
280332          "name": "ntc-templates",
280333          "version": "3.3.0",
280334          "licenses": [
280335            {
280336              "license": {
280337                "id": "Apache-2.0"
280338              }
280339            }
280340          ],
280341          "cpe": "cpe:2.3:a:network_to_code_project:python-ntc-templates:3.3.0:*:*:*:*:*:*:*",
280342          "purl": "pkg:pypi/ntc-templates@3.3.0",
280343          "swid": {
280344            "attachment": {}
280345          },
280346          "pedigree": {},
280347          "evidence": {},
280348          "signature": {
280349            "signature": {
280350              "publicKey": {}
280351            }
280352          },
280353          "modelCard": {
280354            "modelParameters": {
280355              "approach": {}
280356            },
280357            "quantitativeAnalysis": {
280358              "graphics": {}
280359            },
280360            "considerations": {}
280361          }
280362        },
280363        {
280364          "type": "library",
280365          "bom-ref": "pkg:apk/alpine/openssh@9.0_p1-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=be35bb8e9f7dd701",
280366          "supplier": {},
280367          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
280368          "name": "openssh",
280369          "version": "9.0_p1-r2",
280370          "description": "Port of OpenBSD's free SSH release",
280371          "licenses": [
280372            {
280373              "license": {
280374                "name": "BSD"
280375              }
280376            }
280377          ],
280378          "cpe": "cpe:2.3:a:openssh:openssh:9.0_p1-r2:*:*:*:*:*:*:*",
280379          "purl": "pkg:apk/alpine/openssh@9.0_p1-r2?arch=x86_64\u0026distro=alpine-3.16.5",
280380          "swid": {
280381            "attachment": {}
280382          },
280383          "pedigree": {},
280384          "externalReferences": [
280385            {
280386              "url": "https://www.openssh.com/portable.html",
280387              "type": "distribution"
280388            }
280389          ],
280390          "evidence": {},
280391          "signature": {
280392            "signature": {
280393              "publicKey": {}
280394            }
280395          },
280396          "modelCard": {
280397            "modelParameters": {
280398              "approach": {}
280399            },
280400            "quantitativeAnalysis": {
280401              "graphics": {}
280402            },
280403            "considerations": {}
280404          }
280405        },
280406        {
280407          "type": "library",
280408          "bom-ref": "pkg:apk/alpine/openssh-client-common@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=3fa98e2b8fec2d35",
280409          "supplier": {},
280410          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
280411          "name": "openssh-client-common",
280412          "version": "9.0_p1-r2",
280413          "description": "OpenBSD's SSH client common files",
280414          "licenses": [
280415            {
280416              "license": {
280417                "name": "BSD"
280418              }
280419            }
280420          ],
280421          "cpe": "cpe:2.3:a:openssh-client-common:openssh-client-common:9.0_p1-r2:*:*:*:*:*:*:*",
280422          "purl": "pkg:apk/alpine/openssh-client-common@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
280423          "swid": {
280424            "attachment": {}
280425          },
280426          "pedigree": {},
280427          "externalReferences": [
280428            {
280429              "url": "https://www.openssh.com/portable.html",
280430              "type": "distribution"
280431            }
280432          ],
280433          "evidence": {},
280434          "signature": {
280435            "signature": {
280436              "publicKey": {}
280437            }
280438          },
280439          "modelCard": {
280440            "modelParameters": {
280441              "approach": {}
280442            },
280443            "quantitativeAnalysis": {
280444              "graphics": {}
280445            },
280446            "considerations": {}
280447          }
280448        },
280449        {
280450          "type": "library",
280451          "bom-ref": "pkg:apk/alpine/openssh-client-default@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=e25c4647c0a314b5",
280452          "supplier": {},
280453          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
280454          "name": "openssh-client-default",
280455          "version": "9.0_p1-r2",
280456          "description": "OpenBSD's SSH client",
280457          "licenses": [
280458            {
280459              "license": {
280460                "name": "BSD"
280461              }
280462            }
280463          ],
280464          "cpe": "cpe:2.3:a:openssh-client-default:openssh-client-default:9.0_p1-r2:*:*:*:*:*:*:*",
280465          "purl": "pkg:apk/alpine/openssh-client-default@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
280466          "swid": {
280467            "attachment": {}
280468          },
280469          "pedigree": {},
280470          "externalReferences": [
280471            {
280472              "url": "https://www.openssh.com/portable.html",
280473              "type": "distribution"
280474            }
280475          ],
280476          "evidence": {},
280477          "signature": {
280478            "signature": {
280479              "publicKey": {}
280480            }
280481          },
280482          "modelCard": {
280483            "modelParameters": {
280484              "approach": {}
280485            },
280486            "quantitativeAnalysis": {
280487              "graphics": {}
280488            },
280489            "considerations": {}
280490          }
280491        },
280492        {
280493          "type": "library",
280494          "bom-ref": "pkg:apk/alpine/openssh-keygen@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=f68b16c70b1e9cd5",
280495          "supplier": {},
280496          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
280497          "name": "openssh-keygen",
280498          "version": "9.0_p1-r2",
280499          "description": "ssh helper program for generating keys",
280500          "licenses": [
280501            {
280502              "license": {
280503                "name": "BSD"
280504              }
280505            }
280506          ],
280507          "cpe": "cpe:2.3:a:openssh-keygen:openssh-keygen:9.0_p1-r2:*:*:*:*:*:*:*",
280508          "purl": "pkg:apk/alpine/openssh-keygen@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
280509          "swid": {
280510            "attachment": {}
280511          },
280512          "pedigree": {},
280513          "externalReferences": [
280514            {
280515              "url": "https://www.openssh.com/portable.html",
280516              "type": "distribution"
280517            }
280518          ],
280519          "evidence": {},
280520          "signature": {
280521            "signature": {
280522              "publicKey": {}
280523            }
280524          },
280525          "modelCard": {
280526            "modelParameters": {
280527              "approach": {}
280528            },
280529            "quantitativeAnalysis": {
280530              "graphics": {}
280531            },
280532            "considerations": {}
280533          }
280534        },
280535        {
280536          "type": "library",
280537          "bom-ref": "pkg:apk/alpine/openssh-server@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=c965d48edfd50c41",
280538          "supplier": {},
280539          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
280540          "name": "openssh-server",
280541          "version": "9.0_p1-r2",
280542          "description": "OpenSSH server",
280543          "licenses": [
280544            {
280545              "license": {
280546                "name": "BSD"
280547              }
280548            }
280549          ],
280550          "cpe": "cpe:2.3:a:openssh-server:openssh-server:9.0_p1-r2:*:*:*:*:*:*:*",
280551          "purl": "pkg:apk/alpine/openssh-server@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
280552          "swid": {
280553            "attachment": {}
280554          },
280555          "pedigree": {},
280556          "externalReferences": [
280557            {
280558              "url": "https://www.openssh.com/portable.html",
280559              "type": "distribution"
280560            }
280561          ],
280562          "evidence": {},
280563          "signature": {
280564            "signature": {
280565              "publicKey": {}
280566            }
280567          },
280568          "modelCard": {
280569            "modelParameters": {
280570              "approach": {}
280571            },
280572            "quantitativeAnalysis": {
280573              "graphics": {}
280574            },
280575            "considerations": {}
280576          }
280577        },
280578        {
280579          "type": "library",
280580          "bom-ref": "pkg:apk/alpine/openssh-server-common@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=28229e04c06729a4",
280581          "supplier": {},
280582          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
280583          "name": "openssh-server-common",
280584          "version": "9.0_p1-r2",
280585          "description": "OpenSSH server configuration files",
280586          "licenses": [
280587            {
280588              "license": {
280589                "name": "BSD"
280590              }
280591            }
280592          ],
280593          "cpe": "cpe:2.3:a:openssh-server-common:openssh-server-common:9.0_p1-r2:*:*:*:*:*:*:*",
280594          "purl": "pkg:apk/alpine/openssh-server-common@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
280595          "swid": {
280596            "attachment": {}
280597          },
280598          "pedigree": {},
280599          "externalReferences": [
280600            {
280601              "url": "https://www.openssh.com/portable.html",
280602              "type": "distribution"
280603            }
280604          ],
280605          "evidence": {},
280606          "signature": {
280607            "signature": {
280608              "publicKey": {}
280609            }
280610          },
280611          "modelCard": {
280612            "modelParameters": {
280613              "approach": {}
280614            },
280615            "quantitativeAnalysis": {
280616              "graphics": {}
280617            },
280618            "considerations": {}
280619          }
280620        },
280621        {
280622          "type": "library",
280623          "bom-ref": "pkg:apk/alpine/openssh-sftp-server@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=6fe5b21b307e0521",
280624          "supplier": {},
280625          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
280626          "name": "openssh-sftp-server",
280627          "version": "9.0_p1-r2",
280628          "description": "ssh sftp server module",
280629          "licenses": [
280630            {
280631              "license": {
280632                "name": "BSD"
280633              }
280634            }
280635          ],
280636          "cpe": "cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:9.0_p1-r2:*:*:*:*:*:*:*",
280637          "purl": "pkg:apk/alpine/openssh-sftp-server@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
280638          "swid": {
280639            "attachment": {}
280640          },
280641          "pedigree": {},
280642          "externalReferences": [
280643            {
280644              "url": "https://www.openssh.com/portable.html",
280645              "type": "distribution"
280646            }
280647          ],
280648          "evidence": {},
280649          "signature": {
280650            "signature": {
280651              "publicKey": {}
280652            }
280653          },
280654          "modelCard": {
280655            "modelParameters": {
280656              "approach": {}
280657            },
280658            "quantitativeAnalysis": {
280659              "graphics": {}
280660            },
280661            "considerations": {}
280662          }
280663        },
280664        {
280665          "type": "library",
280666          "bom-ref": "pkg:pypi/packaging@23.1?package-id=5c5e049735e6f2b5",
280667          "supplier": {},
280668          "author": "Donald Stufft \u003cdonald@stufft.io\u003e",
280669          "name": "packaging",
280670          "version": "23.1",
280671          "cpe": "cpe:2.3:a:donald_stufft_\\\u003cdonald_project:python-packaging:23.1:*:*:*:*:*:*:*",
280672          "purl": "pkg:pypi/packaging@23.1",
280673          "swid": {
280674            "attachment": {}
280675          },
280676          "pedigree": {},
280677          "evidence": {},
280678          "signature": {
280679            "signature": {
280680              "publicKey": {}
280681            }
280682          },
280683          "modelCard": {
280684            "modelParameters": {
280685              "approach": {}
280686            },
280687            "quantitativeAnalysis": {
280688              "graphics": {}
280689            },
280690            "considerations": {}
280691          }
280692        },
280693        {
280694          "type": "library",
280695          "bom-ref": "pkg:pypi/paramiko@3.1.0?package-id=90aef40539d7d14",
280696          "supplier": {},
280697          "author": "Jeff Forcier \u003cjeff@bitprophet.org\u003e",
280698          "name": "paramiko",
280699          "version": "3.1.0",
280700          "licenses": [
280701            {
280702              "license": {
280703                "name": "LGPL"
280704              }
280705            }
280706          ],
280707          "cpe": "cpe:2.3:a:jeff_forcier_project:python-paramiko:3.1.0:*:*:*:*:*:*:*",
280708          "purl": "pkg:pypi/paramiko@3.1.0",
280709          "swid": {
280710            "attachment": {}
280711          },
280712          "pedigree": {},
280713          "evidence": {},
280714          "signature": {
280715            "signature": {
280716              "publicKey": {}
280717            }
280718          },
280719          "modelCard": {
280720            "modelParameters": {
280721              "approach": {}
280722            },
280723            "quantitativeAnalysis": {
280724              "graphics": {}
280725            },
280726            "considerations": {}
280727          }
280728        },
280729        {
280730          "type": "library",
280731          "bom-ref": "pkg:pypi/passlib@1.7.4?package-id=76971a360532b0d8",
280732          "supplier": {},
280733          "author": "Eli Collins \u003celic@assurancetechnologies.com\u003e",
280734          "name": "passlib",
280735          "version": "1.7.4",
280736          "licenses": [
280737            {
280738              "license": {
280739                "name": "BSD"
280740              }
280741            }
280742          ],
280743          "cpe": "cpe:2.3:a:eli_collins_project:python-passlib:1.7.4:*:*:*:*:*:*:*",
280744          "purl": "pkg:pypi/passlib@1.7.4",
280745          "swid": {
280746            "attachment": {}
280747          },
280748          "pedigree": {},
280749          "evidence": {},
280750          "signature": {
280751            "signature": {
280752              "publicKey": {}
280753            }
280754          },
280755          "modelCard": {
280756            "modelParameters": {
280757              "approach": {}
280758            },
280759            "quantitativeAnalysis": {
280760              "graphics": {}
280761            },
280762            "considerations": {}
280763          }
280764        },
280765        {
280766          "type": "library",
280767          "bom-ref": "pkg:pypi/pip@22.3.1?package-id=3100cd295b5bdd40",
280768          "supplier": {},
280769          "author": "The pip developers \u003cdistutils-sig@python.org\u003e",
280770          "name": "pip",
280771          "version": "22.3.1",
280772          "licenses": [
280773            {
280774              "license": {
280775                "id": "MIT"
280776              }
280777            }
280778          ],
280779          "cpe": "cpe:2.3:a:pip_developers_project:python-pip:22.3.1:*:*:*:*:*:*:*",
280780          "purl": "pkg:pypi/pip@22.3.1",
280781          "swid": {
280782            "attachment": {}
280783          },
280784          "pedigree": {},
280785          "evidence": {},
280786          "signature": {
280787            "signature": {
280788              "publicKey": {}
280789            }
280790          },
280791          "modelCard": {
280792            "modelParameters": {
280793              "approach": {}
280794            },
280795            "quantitativeAnalysis": {
280796              "graphics": {}
280797            },
280798            "considerations": {}
280799          }
280800        },
280801        {
280802          "type": "library",
280803          "bom-ref": "pkg:pypi/pluggy@1.0.0?package-id=184fbb45f182aa4a",
280804          "supplier": {},
280805          "author": "Holger Krekel \u003cholger@merlinux.eu\u003e",
280806          "name": "pluggy",
280807          "version": "1.0.0",
280808          "licenses": [
280809            {
280810              "license": {
280811                "id": "MIT"
280812              }
280813            }
280814          ],
280815          "cpe": "cpe:2.3:a:holger_krekel_project:python-pluggy:1.0.0:*:*:*:*:*:*:*",
280816          "purl": "pkg:pypi/pluggy@1.0.0",
280817          "swid": {
280818            "attachment": {}
280819          },
280820          "pedigree": {},
280821          "evidence": {},
280822          "signature": {
280823            "signature": {
280824              "publicKey": {}
280825            }
280826          },
280827          "modelCard": {
280828            "modelParameters": {
280829              "approach": {}
280830            },
280831            "quantitativeAnalysis": {
280832              "graphics": {}
280833            },
280834            "considerations": {}
280835          }
280836        },
280837        {
280838          "type": "library",
280839          "bom-ref": "pkg:pypi/pycparser@2.21?package-id=f34437f2d84117a3",
280840          "supplier": {},
280841          "author": "Eli Bendersky \u003celiben@gmail.com\u003e",
280842          "name": "pycparser",
280843          "version": "2.21",
280844          "licenses": [
280845            {
280846              "license": {
280847                "name": "BSD"
280848              }
280849            }
280850          ],
280851          "cpe": "cpe:2.3:a:eli_bendersky_project:python-pycparser:2.21:*:*:*:*:*:*:*",
280852          "purl": "pkg:pypi/pycparser@2.21",
280853          "swid": {
280854            "attachment": {}
280855          },
280856          "pedigree": {},
280857          "evidence": {},
280858          "signature": {
280859            "signature": {
280860              "publicKey": {}
280861            }
280862          },
280863          "modelCard": {
280864            "modelParameters": {
280865              "approach": {}
280866            },
280867            "quantitativeAnalysis": {
280868              "graphics": {}
280869            },
280870            "considerations": {}
280871          }
280872        },
280873        {
280874          "type": "library",
280875          "bom-ref": "pkg:pypi/pyeapi@0.8.4?package-id=529f6aea31ff502d",
280876          "supplier": {},
280877          "author": "Arista EOS+ CS \u003ceosplus-dev@arista.com\u003e",
280878          "name": "pyeapi",
280879          "version": "0.8.4",
280880          "licenses": [
280881            {
280882              "license": {
280883                "name": "BSD-3"
280884              }
280885            }
280886          ],
280887          "cpe": "cpe:2.3:a:arista_eos\\+_cs_project:python-pyeapi:0.8.4:*:*:*:*:*:*:*",
280888          "purl": "pkg:pypi/pyeapi@0.8.4",
280889          "swid": {
280890            "attachment": {}
280891          },
280892          "pedigree": {},
280893          "evidence": {},
280894          "signature": {
280895            "signature": {
280896              "publicKey": {}
280897            }
280898          },
280899          "modelCard": {
280900            "modelParameters": {
280901              "approach": {}
280902            },
280903            "quantitativeAnalysis": {
280904              "graphics": {}
280905            },
280906            "considerations": {}
280907          }
280908        },
280909        {
280910          "type": "library",
280911          "bom-ref": "pkg:pypi/pyparsing@3.0.9?package-id=fc99d3a216f5e080",
280912          "supplier": {},
280913          "author": "Paul McGuire \u003cptmcg.gm+pyparsing@gmail.com\u003e",
280914          "name": "pyparsing",
280915          "version": "3.0.9",
280916          "cpe": "cpe:2.3:a:paul_mcguire_\\\u003cptmcg_gm\\+pyparsing_project:python-pyparsing:3.0.9:*:*:*:*:*:*:*",
280917          "purl": "pkg:pypi/pyparsing@3.0.9",
280918          "swid": {
280919            "attachment": {}
280920          },
280921          "pedigree": {},
280922          "evidence": {},
280923          "signature": {
280924            "signature": {
280925              "publicKey": {}
280926            }
280927          },
280928          "modelCard": {
280929            "modelParameters": {
280930              "approach": {}
280931            },
280932            "quantitativeAnalysis": {
280933              "graphics": {}
280934            },
280935            "considerations": {}
280936          }
280937        },
280938        {
280939          "type": "library",
280940          "bom-ref": "pkg:pypi/pyserial@3.5?package-id=87570748f4e813be",
280941          "supplier": {},
280942          "author": "Chris Liechti \u003ccliechti@gmx.net\u003e",
280943          "name": "pyserial",
280944          "version": "3.5",
280945          "licenses": [
280946            {
280947              "license": {
280948                "name": "BSD"
280949              }
280950            }
280951          ],
280952          "cpe": "cpe:2.3:a:chris_liechti_project:python-pyserial:3.5:*:*:*:*:*:*:*",
280953          "purl": "pkg:pypi/pyserial@3.5",
280954          "swid": {
280955            "attachment": {}
280956          },
280957          "pedigree": {},
280958          "evidence": {},
280959          "signature": {
280960            "signature": {
280961              "publicKey": {}
280962            }
280963          },
280964          "modelCard": {
280965            "modelParameters": {
280966              "approach": {}
280967            },
280968            "quantitativeAnalysis": {
280969              "graphics": {}
280970            },
280971            "considerations": {}
280972          }
280973        },
280974        {
280975          "type": "library",
280976          "bom-ref": "pkg:pypi/pytest@7.3.0?package-id=32a2626534b62af2",
280977          "supplier": {},
280978          "author": "Holger Krekel, Bruno Oliveira, Ronny Pfannschmidt, Floris Bruynooghe, Brianna Laugher, Florian Bruhin and others",
280979          "name": "pytest",
280980          "version": "7.3.0",
280981          "licenses": [
280982            {
280983              "license": {
280984                "id": "MIT"
280985              }
280986            }
280987          ],
280988          "cpe": "cpe:2.3:a:holger_krekel\\,_bruno_oliveira\\,_ronny_pfannschmidt\\,_floris_bruynooghe\\,_brianna_laugher\\,_florian_bruhin_and_others_project:python-pytest:7.3.0:*:*:*:*:*:*:*",
280989          "purl": "pkg:pypi/pytest@7.3.0",
280990          "swid": {
280991            "attachment": {}
280992          },
280993          "pedigree": {},
280994          "evidence": {},
280995          "signature": {
280996            "signature": {
280997              "publicKey": {}
280998            }
280999          },
281000          "modelCard": {
281001            "modelParameters": {
281002              "approach": {}
281003            },
281004            "quantitativeAnalysis": {
281005              "graphics": {}
281006            },
281007            "considerations": {}
281008          }
281009        },
281010        {
281011          "type": "application",
281012          "bom-ref": "pkg:generic/python@3.11.3?package-id=275c59959aad4c7",
281013          "supplier": {},
281014          "name": "python",
281015          "version": "3.11.3",
281016          "cpe": "cpe:2.3:a:python_software_foundation:python:3.11.3:*:*:*:*:*:*:*",
281017          "purl": "pkg:generic/python@3.11.3",
281018          "swid": {
281019            "attachment": {}
281020          },
281021          "pedigree": {},
281022          "evidence": {},
281023          "signature": {
281024            "signature": {
281025              "publicKey": {}
281026            }
281027          },
281028          "modelCard": {
281029            "modelParameters": {
281030              "approach": {}
281031            },
281032            "quantitativeAnalysis": {
281033              "graphics": {}
281034            },
281035            "considerations": {}
281036          }
281037        },
281038        {
281039          "type": "library",
281040          "bom-ref": "pkg:pypi/pytz@2023.3?package-id=4809bae2b964082",
281041          "supplier": {},
281042          "author": "Stuart Bishop \u003cstuart@stuartbishop.net\u003e",
281043          "name": "pytz",
281044          "version": "2023.3",
281045          "licenses": [
281046            {
281047              "license": {
281048                "id": "MIT"
281049              }
281050            }
281051          ],
281052          "cpe": "cpe:2.3:a:stuart_bishop_project:python-pytz:2023.3:*:*:*:*:*:*:*",
281053          "purl": "pkg:pypi/pytz@2023.3",
281054          "swid": {
281055            "attachment": {}
281056          },
281057          "pedigree": {},
281058          "evidence": {},
281059          "signature": {
281060            "signature": {
281061              "publicKey": {}
281062            }
281063          },
281064          "modelCard": {
281065            "modelParameters": {
281066              "approach": {}
281067            },
281068            "quantitativeAnalysis": {
281069              "graphics": {}
281070            },
281071            "considerations": {}
281072          }
281073        },
281074        {
281075          "type": "library",
281076          "bom-ref": "pkg:apk/alpine/readline@8.1.2-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=bb734bcc27e60920",
281077          "supplier": {},
281078          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
281079          "name": "readline",
281080          "version": "8.1.2-r0",
281081          "description": "GNU readline library",
281082          "licenses": [
281083            {
281084              "license": {
281085                "id": "GPL-2.0-or-later"
281086              }
281087            }
281088          ],
281089          "cpe": "cpe:2.3:a:readline:readline:8.1.2-r0:*:*:*:*:*:*:*",
281090          "purl": "pkg:apk/alpine/readline@8.1.2-r0?arch=x86_64\u0026distro=alpine-3.16.5",
281091          "swid": {
281092            "attachment": {}
281093          },
281094          "pedigree": {},
281095          "externalReferences": [
281096            {
281097              "url": "https://tiswww.cwru.edu/php/chet/readline/rltop.html",
281098              "type": "distribution"
281099            }
281100          ],
281101          "evidence": {},
281102          "signature": {
281103            "signature": {
281104              "publicKey": {}
281105            }
281106          },
281107          "modelCard": {
281108            "modelParameters": {
281109              "approach": {}
281110            },
281111            "quantitativeAnalysis": {
281112              "graphics": {}
281113            },
281114            "considerations": {}
281115          }
281116        },
281117        {
281118          "type": "library",
281119          "bom-ref": "pkg:pypi/requests@2.28.2?package-id=e59e5e16dc2d6839",
281120          "supplier": {},
281121          "author": "Kenneth Reitz \u003cme@kennethreitz.org\u003e",
281122          "name": "requests",
281123          "version": "2.28.2",
281124          "licenses": [
281125            {
281126              "license": {
281127                "name": "Apache 2.0"
281128              }
281129            }
281130          ],
281131          "cpe": "cpe:2.3:a:kenneth_reitz_project:python-requests:2.28.2:*:*:*:*:*:*:*",
281132          "purl": "pkg:pypi/requests@2.28.2",
281133          "swid": {
281134            "attachment": {}
281135          },
281136          "pedigree": {},
281137          "evidence": {},
281138          "signature": {
281139            "signature": {
281140              "publicKey": {}
281141            }
281142          },
281143          "modelCard": {
281144            "modelParameters": {
281145              "approach": {}
281146            },
281147            "quantitativeAnalysis": {
281148              "graphics": {}
281149            },
281150            "considerations": {}
281151          }
281152        },
281153        {
281154          "type": "library",
281155          "bom-ref": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5\u0026package-id=206fdb47b3e980eb",
281156          "supplier": {},
281157          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
281158          "name": "scanelf",
281159          "version": "1.3.4-r0",
281160          "description": "Scan ELF binaries for stuff",
281161          "licenses": [
281162            {
281163              "license": {
281164                "id": "GPL-2.0-only"
281165              }
281166            }
281167          ],
281168          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.4-r0:*:*:*:*:*:*:*",
281169          "purl": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5",
281170          "swid": {
281171            "attachment": {}
281172          },
281173          "pedigree": {},
281174          "externalReferences": [
281175            {
281176              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
281177              "type": "distribution"
281178            }
281179          ],
281180          "evidence": {},
281181          "signature": {
281182            "signature": {
281183              "publicKey": {}
281184            }
281185          },
281186          "modelCard": {
281187            "modelParameters": {
281188              "approach": {}
281189            },
281190            "quantitativeAnalysis": {
281191              "graphics": {}
281192            },
281193            "considerations": {}
281194          }
281195        },
281196        {
281197          "type": "library",
281198          "bom-ref": "pkg:pypi/scp@0.14.5?package-id=7c66efd43ff9715d",
281199          "supplier": {},
281200          "author": "James Bardin \u003cj.bardin@gmail.com\u003e",
281201          "name": "scp",
281202          "version": "0.14.5",
281203          "licenses": [
281204            {
281205              "license": {
281206                "id": "LGPL-2.1-or-later"
281207              }
281208            }
281209          ],
281210          "cpe": "cpe:2.3:a:james_bardin_project:python-scp:0.14.5:*:*:*:*:*:*:*",
281211          "purl": "pkg:pypi/scp@0.14.5",
281212          "swid": {
281213            "attachment": {}
281214          },
281215          "pedigree": {},
281216          "evidence": {},
281217          "signature": {
281218            "signature": {
281219              "publicKey": {}
281220            }
281221          },
281222          "modelCard": {
281223            "modelParameters": {
281224              "approach": {}
281225            },
281226            "quantitativeAnalysis": {
281227              "graphics": {}
281228            },
281229            "considerations": {}
281230          }
281231        },
281232        {
281233          "type": "library",
281234          "bom-ref": "pkg:pypi/semantic-version@2.10.0?package-id=94885c64cc6167f5",
281235          "supplier": {},
281236          "author": "Raphaël Barrois \u003craphael.barrois+semver@polytechnique.org\u003e",
281237          "name": "semantic-version",
281238          "version": "2.10.0",
281239          "licenses": [
281240            {
281241              "license": {
281242                "name": "BSD"
281243              }
281244            }
281245          ],
281246          "cpe": "cpe:2.3:a:raphael_barrois\\+semver_project:python-semantic-version:2.10.0:*:*:*:*:*:*:*",
281247          "purl": "pkg:pypi/semantic-version@2.10.0",
281248          "swid": {
281249            "attachment": {}
281250          },
281251          "pedigree": {},
281252          "evidence": {},
281253          "signature": {
281254            "signature": {
281255              "publicKey": {}
281256            }
281257          },
281258          "modelCard": {
281259            "modelParameters": {
281260              "approach": {}
281261            },
281262            "quantitativeAnalysis": {
281263              "graphics": {}
281264            },
281265            "considerations": {}
281266          }
281267        },
281268        {
281269          "type": "library",
281270          "bom-ref": "pkg:pypi/setuptools@65.5.1?package-id=e46aceb087f273c",
281271          "supplier": {},
281272          "author": "Python Packaging Authority \u003cdistutils-sig@python.org\u003e",
281273          "name": "setuptools",
281274          "version": "65.5.1",
281275          "cpe": "cpe:2.3:a:python_packaging_authority_project:python-setuptools:65.5.1:*:*:*:*:*:*:*",
281276          "purl": "pkg:pypi/setuptools@65.5.1",
281277          "swid": {
281278            "attachment": {}
281279          },
281280          "pedigree": {},
281281          "evidence": {},
281282          "signature": {
281283            "signature": {
281284              "publicKey": {}
281285            }
281286          },
281287          "modelCard": {
281288            "modelParameters": {
281289              "approach": {}
281290            },
281291            "quantitativeAnalysis": {
281292              "graphics": {}
281293            },
281294            "considerations": {}
281295          }
281296        },
281297        {
281298          "type": "library",
281299          "bom-ref": "pkg:pypi/setuptools-rust@1.1.2?package-id=c6369cc9951ff5dd",
281300          "supplier": {},
281301          "author": "Nikolay Kim \u003cfafhrd91@gmail.com\u003e",
281302          "name": "setuptools-rust",
281303          "version": "1.1.2",
281304          "licenses": [
281305            {
281306              "license": {
281307                "id": "MIT"
281308              }
281309            }
281310          ],
281311          "cpe": "cpe:2.3:a:python-setuptools-rust:python-setuptools-rust:1.1.2:*:*:*:*:*:*:*",
281312          "purl": "pkg:pypi/setuptools-rust@1.1.2",
281313          "swid": {
281314            "attachment": {}
281315          },
281316          "pedigree": {},
281317          "evidence": {},
281318          "signature": {
281319            "signature": {
281320              "publicKey": {}
281321            }
281322          },
281323          "modelCard": {
281324            "modelParameters": {
281325              "approach": {}
281326            },
281327            "quantitativeAnalysis": {
281328              "graphics": {}
281329            },
281330            "considerations": {}
281331          }
281332        },
281333        {
281334          "type": "library",
281335          "bom-ref": "pkg:pypi/six@1.16.0?package-id=a4a34c5ad714238e",
281336          "supplier": {},
281337          "author": "Benjamin Peterson \u003cbenjamin@python.org\u003e",
281338          "name": "six",
281339          "version": "1.16.0",
281340          "licenses": [
281341            {
281342              "license": {
281343                "id": "MIT"
281344              }
281345            }
281346          ],
281347          "cpe": "cpe:2.3:a:benjamin_peterson_project:python-six:1.16.0:*:*:*:*:*:*:*",
281348          "purl": "pkg:pypi/six@1.16.0",
281349          "swid": {
281350            "attachment": {}
281351          },
281352          "pedigree": {},
281353          "evidence": {},
281354          "signature": {
281355            "signature": {
281356              "publicKey": {}
281357            }
281358          },
281359          "modelCard": {
281360            "modelParameters": {
281361              "approach": {}
281362            },
281363            "quantitativeAnalysis": {
281364              "graphics": {}
281365            },
281366            "considerations": {}
281367          }
281368        },
281369        {
281370          "type": "library",
281371          "bom-ref": "pkg:apk/alpine/sqlite-libs@3.38.5-r0?arch=x86_64\u0026upstream=sqlite\u0026distro=alpine-3.16.5\u0026package-id=6127833655f3995a",
281372          "supplier": {},
281373          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
281374          "name": "sqlite-libs",
281375          "version": "3.38.5-r0",
281376          "description": "Sqlite3 library",
281377          "licenses": [
281378            {
281379              "license": {
281380                "id": "blessing"
281381              }
281382            }
281383          ],
281384          "cpe": "cpe:2.3:a:sqlite-libs:sqlite-libs:3.38.5-r0:*:*:*:*:*:*:*",
281385          "purl": "pkg:apk/alpine/sqlite-libs@3.38.5-r0?arch=x86_64\u0026upstream=sqlite\u0026distro=alpine-3.16.5",
281386          "swid": {
281387            "attachment": {}
281388          },
281389          "pedigree": {},
281390          "externalReferences": [
281391            {
281392              "url": "https://www.sqlite.org/",
281393              "type": "distribution"
281394            }
281395          ],
281396          "evidence": {},
281397          "signature": {
281398            "signature": {
281399              "publicKey": {}
281400            }
281401          },
281402          "modelCard": {
281403            "modelParameters": {
281404              "approach": {}
281405            },
281406            "quantitativeAnalysis": {
281407              "graphics": {}
281408            },
281409            "considerations": {}
281410          }
281411        },
281412        {
281413          "type": "library",
281414          "bom-ref": "pkg:apk/alpine/sshpass@1.09-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=df8f395bc1f8e878",
281415          "supplier": {},
281416          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
281417          "name": "sshpass",
281418          "version": "1.09-r0",
281419          "description": "Non-interactive SSH authentication utility",
281420          "licenses": [
281421            {
281422              "license": {
281423                "id": "GPL-2.0-or-later"
281424              }
281425            }
281426          ],
281427          "cpe": "cpe:2.3:a:sshpass:sshpass:1.09-r0:*:*:*:*:*:*:*",
281428          "purl": "pkg:apk/alpine/sshpass@1.09-r0?arch=x86_64\u0026distro=alpine-3.16.5",
281429          "swid": {
281430            "attachment": {}
281431          },
281432          "pedigree": {},
281433          "externalReferences": [
281434            {
281435              "url": "https://sourceforge.net/projects/sshpass/",
281436              "type": "distribution"
281437            }
281438          ],
281439          "evidence": {},
281440          "signature": {
281441            "signature": {
281442              "publicKey": {}
281443            }
281444          },
281445          "modelCard": {
281446            "modelParameters": {
281447              "approach": {}
281448            },
281449            "quantitativeAnalysis": {
281450              "graphics": {}
281451            },
281452            "considerations": {}
281453          }
281454        },
281455        {
281456          "type": "library",
281457          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5\u0026package-id=674d1e2fba4d633a",
281458          "supplier": {},
281459          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
281460          "name": "ssl_client",
281461          "version": "1.35.0-r17",
281462          "description": "EXternal ssl_client for busybox wget",
281463          "licenses": [
281464            {
281465              "license": {
281466                "id": "GPL-2.0-only"
281467              }
281468            }
281469          ],
281470          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r17:*:*:*:*:*:*:*",
281471          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5",
281472          "swid": {
281473            "attachment": {}
281474          },
281475          "pedigree": {},
281476          "externalReferences": [
281477            {
281478              "url": "https://busybox.net/",
281479              "type": "distribution"
281480            }
281481          ],
281482          "evidence": {},
281483          "signature": {
281484            "signature": {
281485              "publicKey": {}
281486            }
281487          },
281488          "modelCard": {
281489            "modelParameters": {
281490              "approach": {}
281491            },
281492            "quantitativeAnalysis": {
281493              "graphics": {}
281494            },
281495            "considerations": {}
281496          }
281497        },
281498        {
281499          "type": "library",
281500          "bom-ref": "pkg:pypi/tenacity@8.2.2?package-id=d0539dcd5ce128de",
281501          "supplier": {},
281502          "author": "Julien Danjou \u003cjulien@danjou.info\u003e",
281503          "name": "tenacity",
281504          "version": "8.2.2",
281505          "licenses": [
281506            {
281507              "license": {
281508                "name": "Apache 2.0"
281509              }
281510            }
281511          ],
281512          "cpe": "cpe:2.3:a:julien_danjou_project:python-tenacity:8.2.2:*:*:*:*:*:*:*",
281513          "purl": "pkg:pypi/tenacity@8.2.2",
281514          "swid": {
281515            "attachment": {}
281516          },
281517          "pedigree": {},
281518          "evidence": {},
281519          "signature": {
281520            "signature": {
281521              "publicKey": {}
281522            }
281523          },
281524          "modelCard": {
281525            "modelParameters": {
281526              "approach": {}
281527            },
281528            "quantitativeAnalysis": {
281529              "graphics": {}
281530            },
281531            "considerations": {}
281532          }
281533        },
281534        {
281535          "type": "library",
281536          "bom-ref": "pkg:pypi/textfsm@1.1.3?package-id=47205a218197a630",
281537          "supplier": {},
281538          "name": "textfsm",
281539          "version": "1.1.3",
281540          "licenses": [
281541            {
281542              "license": {
281543                "name": "Apache License, Version 2.0"
281544              }
281545            }
281546          ],
281547          "cpe": "cpe:2.3:a:python-textfsm:python-textfsm:1.1.3:*:*:*:*:*:*:*",
281548          "purl": "pkg:pypi/textfsm@1.1.3",
281549          "swid": {
281550            "attachment": {}
281551          },
281552          "pedigree": {},
281553          "evidence": {},
281554          "signature": {
281555            "signature": {
281556              "publicKey": {}
281557            }
281558          },
281559          "modelCard": {
281560            "modelParameters": {
281561              "approach": {}
281562            },
281563            "quantitativeAnalysis": {
281564              "graphics": {}
281565            },
281566            "considerations": {}
281567          }
281568        },
281569        {
281570          "type": "library",
281571          "bom-ref": "pkg:pypi/toml@0.10.2?package-id=40954de8de37c66b",
281572          "supplier": {},
281573          "author": "William Pearson \u003cuiri@xqz.ca\u003e",
281574          "name": "toml",
281575          "version": "0.10.2",
281576          "licenses": [
281577            {
281578              "license": {
281579                "id": "MIT"
281580              }
281581            }
281582          ],
281583          "cpe": "cpe:2.3:a:william_pearson_project:python-toml:0.10.2:*:*:*:*:*:*:*",
281584          "purl": "pkg:pypi/toml@0.10.2",
281585          "swid": {
281586            "attachment": {}
281587          },
281588          "pedigree": {},
281589          "evidence": {},
281590          "signature": {
281591            "signature": {
281592              "publicKey": {}
281593            }
281594          },
281595          "modelCard": {
281596            "modelParameters": {
281597              "approach": {}
281598            },
281599            "quantitativeAnalysis": {
281600              "graphics": {}
281601            },
281602            "considerations": {}
281603          }
281604        },
281605        {
281606          "type": "library",
281607          "bom-ref": "pkg:pypi/transitions@0.9.0?package-id=5cae5b615a5badb8",
281608          "supplier": {},
281609          "author": "Tal Yarkoni \u003ctyarkoni@gmail.com\u003e",
281610          "name": "transitions",
281611          "version": "0.9.0",
281612          "licenses": [
281613            {
281614              "license": {
281615                "id": "MIT"
281616              }
281617            }
281618          ],
281619          "cpe": "cpe:2.3:a:tal_yarkoni_project:python-transitions:0.9.0:*:*:*:*:*:*:*",
281620          "purl": "pkg:pypi/transitions@0.9.0",
281621          "swid": {
281622            "attachment": {}
281623          },
281624          "pedigree": {},
281625          "evidence": {},
281626          "signature": {
281627            "signature": {
281628              "publicKey": {}
281629            }
281630          },
281631          "modelCard": {
281632            "modelParameters": {
281633              "approach": {}
281634            },
281635            "quantitativeAnalysis": {
281636              "graphics": {}
281637            },
281638            "considerations": {}
281639          }
281640        },
281641        {
281642          "type": "library",
281643          "bom-ref": "pkg:pypi/typing-extensions@4.5.0?package-id=acfb35510a672980",
281644          "supplier": {},
281645          "author": "\"Guido van Rossum, Jukka Lehtosalo, Łukasz Langa, Michael Lee\" \u003clevkivskyi@gmail.com\u003e",
281646          "name": "typing_extensions",
281647          "version": "4.5.0",
281648          "cpe": "cpe:2.3:a:python-typing-extensions:python-typing-extensions:4.5.0:*:*:*:*:*:*:*",
281649          "purl": "pkg:pypi/typing_extensions@4.5.0",
281650          "swid": {
281651            "attachment": {}
281652          },
281653          "pedigree": {},
281654          "evidence": {},
281655          "signature": {
281656            "signature": {
281657              "publicKey": {}
281658            }
281659          },
281660          "modelCard": {
281661            "modelParameters": {
281662              "approach": {}
281663            },
281664            "quantitativeAnalysis": {
281665              "graphics": {}
281666            },
281667            "considerations": {}
281668          }
281669        },
281670        {
281671          "type": "library",
281672          "bom-ref": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=c6c9b0e0277783a2",
281673          "supplier": {},
281674          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
281675          "name": "tzdata",
281676          "version": "2023c-r0",
281677          "description": "Timezone data",
281678          "licenses": [
281679            {
281680              "license": {
281681                "name": "Public-Domain"
281682              }
281683            }
281684          ],
281685          "cpe": "cpe:2.3:a:tzdata:tzdata:2023c-r0:*:*:*:*:*:*:*",
281686          "purl": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.16.5",
281687          "swid": {
281688            "attachment": {}
281689          },
281690          "pedigree": {},
281691          "externalReferences": [
281692            {
281693              "url": "https://www.iana.org/time-zones",
281694              "type": "distribution"
281695            }
281696          ],
281697          "evidence": {},
281698          "signature": {
281699            "signature": {
281700              "publicKey": {}
281701            }
281702          },
281703          "modelCard": {
281704            "modelParameters": {
281705              "approach": {}
281706            },
281707            "quantitativeAnalysis": {
281708              "graphics": {}
281709            },
281710            "considerations": {}
281711          }
281712        },
281713        {
281714          "type": "library",
281715          "bom-ref": "pkg:pypi/urllib3@1.26.15?package-id=25acf2f0c10fb6d2",
281716          "supplier": {},
281717          "author": "Andrey Petrov \u003candrey.petrov@shazow.net\u003e",
281718          "name": "urllib3",
281719          "version": "1.26.15",
281720          "licenses": [
281721            {
281722              "license": {
281723                "id": "MIT"
281724              }
281725            }
281726          ],
281727          "cpe": "cpe:2.3:a:andrey_petrov_project:python-urllib3:1.26.15:*:*:*:*:*:*:*",
281728          "purl": "pkg:pypi/urllib3@1.26.15",
281729          "swid": {
281730            "attachment": {}
281731          },
281732          "pedigree": {},
281733          "evidence": {},
281734          "signature": {
281735            "signature": {
281736              "publicKey": {}
281737            }
281738          },
281739          "modelCard": {
281740            "modelParameters": {
281741              "approach": {}
281742            },
281743            "quantitativeAnalysis": {
281744              "graphics": {}
281745            },
281746            "considerations": {}
281747          }
281748        },
281749        {
281750          "type": "library",
281751          "bom-ref": "pkg:pypi/wheel@0.40.0?package-id=b5901a77ad9bd010",
281752          "supplier": {},
281753          "author": "Daniel Holth \u003cdholth@fastmail.fm\u003e",
281754          "name": "wheel",
281755          "version": "0.40.0",
281756          "cpe": "cpe:2.3:a:daniel_holth_\\\u003cdholth_project:python-wheel:0.40.0:*:*:*:*:*:*:*",
281757          "purl": "pkg:pypi/wheel@0.40.0",
281758          "swid": {
281759            "attachment": {}
281760          },
281761          "pedigree": {},
281762          "evidence": {},
281763          "signature": {
281764            "signature": {
281765              "publicKey": {}
281766            }
281767          },
281768          "modelCard": {
281769            "modelParameters": {
281770              "approach": {}
281771            },
281772            "quantitativeAnalysis": {
281773              "graphics": {}
281774            },
281775            "considerations": {}
281776          }
281777        },
281778        {
281779          "type": "library",
281780          "bom-ref": "pkg:pypi/wrapt@1.15.0?package-id=3e39dd67028b755e",
281781          "supplier": {},
281782          "author": "Graham Dumpleton \u003cGraham.Dumpleton@gmail.com\u003e",
281783          "name": "wrapt",
281784          "version": "1.15.0",
281785          "licenses": [
281786            {
281787              "license": {
281788                "name": "BSD"
281789              }
281790            }
281791          ],
281792          "cpe": "cpe:2.3:a:graham_dumpleton_project:python-wrapt:1.15.0:*:*:*:*:*:*:*",
281793          "purl": "pkg:pypi/wrapt@1.15.0",
281794          "swid": {
281795            "attachment": {}
281796          },
281797          "pedigree": {},
281798          "evidence": {},
281799          "signature": {
281800            "signature": {
281801              "publicKey": {}
281802            }
281803          },
281804          "modelCard": {
281805            "modelParameters": {
281806              "approach": {}
281807            },
281808            "quantitativeAnalysis": {
281809              "graphics": {}
281810            },
281811            "considerations": {}
281812          }
281813        },
281814        {
281815          "type": "library",
281816          "bom-ref": "pkg:pypi/xmltodict@0.13.0?package-id=8b8fec688a305949",
281817          "supplier": {},
281818          "author": "Martin Blech \u003cmartinblech@gmail.com\u003e",
281819          "name": "xmltodict",
281820          "version": "0.13.0",
281821          "licenses": [
281822            {
281823              "license": {
281824                "id": "MIT"
281825              }
281826            }
281827          ],
281828          "cpe": "cpe:2.3:a:martin_blech_project:python-xmltodict:0.13.0:*:*:*:*:*:*:*",
281829          "purl": "pkg:pypi/xmltodict@0.13.0",
281830          "swid": {
281831            "attachment": {}
281832          },
281833          "pedigree": {},
281834          "evidence": {},
281835          "signature": {
281836            "signature": {
281837              "publicKey": {}
281838            }
281839          },
281840          "modelCard": {
281841            "modelParameters": {
281842              "approach": {}
281843            },
281844            "quantitativeAnalysis": {
281845              "graphics": {}
281846            },
281847            "considerations": {}
281848          }
281849        },
281850        {
281851          "type": "library",
281852          "bom-ref": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.5\u0026package-id=168e14fa822d49a0",
281853          "supplier": {},
281854          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
281855          "name": "xz-libs",
281856          "version": "5.2.5-r1",
281857          "description": "Library and CLI tools for XZ and LZMA compressed files (libraries)",
281858          "licenses": [
281859            {
281860              "license": {
281861                "id": "GPL-2.0-or-later"
281862              }
281863            },
281864            {
281865              "license": {
281866                "name": "AND"
281867              }
281868            },
281869            {
281870              "license": {
281871                "name": "Public-Domain"
281872              }
281873            },
281874            {
281875              "license": {
281876                "name": "AND"
281877              }
281878            },
281879            {
281880              "license": {
281881                "id": "LGPL-2.1-or-later"
281882              }
281883            }
281884          ],
281885          "cpe": "cpe:2.3:a:xz-libs:xz-libs:5.2.5-r1:*:*:*:*:*:*:*",
281886          "purl": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.5",
281887          "swid": {
281888            "attachment": {}
281889          },
281890          "pedigree": {},
281891          "externalReferences": [
281892            {
281893              "url": "https://tukaani.org/xz",
281894              "type": "distribution"
281895            }
281896          ],
281897          "evidence": {},
281898          "signature": {
281899            "signature": {
281900              "publicKey": {}
281901            }
281902          },
281903          "modelCard": {
281904            "modelParameters": {
281905              "approach": {}
281906            },
281907            "quantitativeAnalysis": {
281908              "graphics": {}
281909            },
281910            "considerations": {}
281911          }
281912        },
281913        {
281914          "type": "library",
281915          "bom-ref": "pkg:pypi/yamlordereddictloader@0.4.0?package-id=404a2c9cc53e974e",
281916          "supplier": {},
281917          "author": "François Ménabé \u003cfrancois.menabe@gmail.com\u003e",
281918          "name": "yamlordereddictloader",
281919          "version": "0.4.0",
281920          "licenses": [
281921            {
281922              "license": {
281923                "name": "MIT License"
281924              }
281925            }
281926          ],
281927          "cpe": "cpe:2.3:a:python-yamlordereddictloader:python-yamlordereddictloader:0.4.0:*:*:*:*:*:*:*",
281928          "purl": "pkg:pypi/yamlordereddictloader@0.4.0",
281929          "swid": {
281930            "attachment": {}
281931          },
281932          "pedigree": {},
281933          "evidence": {},
281934          "signature": {
281935            "signature": {
281936              "publicKey": {}
281937            }
281938          },
281939          "modelCard": {
281940            "modelParameters": {
281941              "approach": {}
281942            },
281943            "quantitativeAnalysis": {
281944              "graphics": {}
281945            },
281946            "considerations": {}
281947          }
281948        },
281949        {
281950          "type": "library",
281951          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=75f0d92f695b4303",
281952          "supplier": {},
281953          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
281954          "name": "zlib",
281955          "version": "1.2.12-r3",
281956          "description": "A compression/decompression Library",
281957          "licenses": [
281958            {
281959              "license": {
281960                "id": "Zlib"
281961              }
281962            }
281963          ],
281964          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
281965          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5",
281966          "swid": {
281967            "attachment": {}
281968          },
281969          "pedigree": {},
281970          "externalReferences": [
281971            {
281972              "url": "https://zlib.net/",
281973              "type": "distribution"
281974            }
281975          ],
281976          "evidence": {},
281977          "signature": {
281978            "signature": {
281979              "publicKey": {}
281980            }
281981          },
281982          "modelCard": {
281983            "modelParameters": {
281984              "approach": {}
281985            },
281986            "quantitativeAnalysis": {
281987              "graphics": {}
281988            },
281989            "considerations": {}
281990          }
281991        },
281992        {
281993          "type": "library",
281994          "bom-ref": "pkg:pypi/zope.interface@6.0?package-id=5c2141abb7c153a7",
281995          "supplier": {},
281996          "author": "Zope Foundation and Contributors \u003czope-dev@zope.org\u003e",
281997          "name": "zope.interface",
281998          "version": "6.0",
281999          "licenses": [
282000            {
282001              "license": {
282002                "name": "ZPL 2.1"
282003              }
282004            }
282005          ],
282006          "cpe": "cpe:2.3:a:zope_foundation_and_contributors_project:python-zope.interface:6.0:*:*:*:*:*:*:*",
282007          "purl": "pkg:pypi/zope.interface@6.0",
282008          "swid": {
282009            "attachment": {}
282010          },
282011          "pedigree": {},
282012          "evidence": {},
282013          "signature": {
282014            "signature": {
282015              "publicKey": {}
282016            }
282017          },
282018          "modelCard": {
282019            "modelParameters": {
282020              "approach": {}
282021            },
282022            "quantitativeAnalysis": {
282023              "graphics": {}
282024            },
282025            "considerations": {}
282026          }
282027        },
282028        {
282029          "type": "operating-system",
282030          "supplier": {},
282031          "name": "alpine",
282032          "version": "3.16.5",
282033          "description": "Alpine Linux v3.16",
282034          "swid": {
282035            "tagId": "alpine",
282036            "name": "alpine",
282037            "version": "3.16.5",
282038            "attachment": {}
282039          },
282040          "pedigree": {},
282041          "externalReferences": [
282042            {
282043              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
282044              "type": "issue-tracker"
282045            },
282046            {
282047              "url": "https://alpinelinux.org/",
282048              "type": "website"
282049            }
282050          ],
282051          "evidence": {},
282052          "signature": {
282053            "signature": {
282054              "publicKey": {}
282055            }
282056          },
282057          "modelCard": {
282058            "modelParameters": {
282059              "approach": {}
282060            },
282061            "quantitativeAnalysis": {
282062              "graphics": {}
282063            },
282064            "considerations": {}
282065          }
282066        },
282067        {
282068          "type": "library",
282069          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=92b19c7750fb559d",
282070          "supplier": {},
282071          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
282072          "name": "alpine-baselayout",
282073          "version": "3.4.0-r0",
282074          "description": "Alpine base dir structure and init scripts",
282075          "licenses": [
282076            {
282077              "license": {
282078                "id": "GPL-2.0-only"
282079              }
282080            }
282081          ],
282082          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.4.0-r0:*:*:*:*:*:*:*",
282083          "purl": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.2",
282084          "swid": {
282085            "attachment": {}
282086          },
282087          "pedigree": {},
282088          "externalReferences": [
282089            {
282090              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
282091              "type": "distribution"
282092            }
282093          ],
282094          "evidence": {},
282095          "signature": {
282096            "signature": {
282097              "publicKey": {}
282098            }
282099          },
282100          "modelCard": {
282101            "modelParameters": {
282102              "approach": {}
282103            },
282104            "quantitativeAnalysis": {
282105              "graphics": {}
282106            },
282107            "considerations": {}
282108          }
282109        },
282110        {
282111          "type": "library",
282112          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.2\u0026package-id=291d1267b40d636f",
282113          "supplier": {},
282114          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
282115          "name": "alpine-baselayout-data",
282116          "version": "3.4.0-r0",
282117          "description": "Alpine base dir structure and init scripts",
282118          "licenses": [
282119            {
282120              "license": {
282121                "id": "GPL-2.0-only"
282122              }
282123            }
282124          ],
282125          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.4.0-r0:*:*:*:*:*:*:*",
282126          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.2",
282127          "swid": {
282128            "attachment": {}
282129          },
282130          "pedigree": {},
282131          "externalReferences": [
282132            {
282133              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
282134              "type": "distribution"
282135            }
282136          ],
282137          "evidence": {},
282138          "signature": {
282139            "signature": {
282140              "publicKey": {}
282141            }
282142          },
282143          "modelCard": {
282144            "modelParameters": {
282145              "approach": {}
282146            },
282147            "quantitativeAnalysis": {
282148              "graphics": {}
282149            },
282150            "considerations": {}
282151          }
282152        },
282153        {
282154          "type": "library",
282155          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=2b5e23d349b556cf",
282156          "supplier": {},
282157          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
282158          "name": "alpine-keys",
282159          "version": "2.4-r1",
282160          "description": "Public keys for Alpine Linux packages",
282161          "licenses": [
282162            {
282163              "license": {
282164                "id": "MIT"
282165              }
282166            }
282167          ],
282168          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
282169          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.2",
282170          "swid": {
282171            "attachment": {}
282172          },
282173          "pedigree": {},
282174          "externalReferences": [
282175            {
282176              "url": "https://alpinelinux.org",
282177              "type": "distribution"
282178            }
282179          ],
282180          "evidence": {},
282181          "signature": {
282182            "signature": {
282183              "publicKey": {}
282184            }
282185          },
282186          "modelCard": {
282187            "modelParameters": {
282188              "approach": {}
282189            },
282190            "quantitativeAnalysis": {
282191              "graphics": {}
282192            },
282193            "considerations": {}
282194          }
282195        },
282196        {
282197          "type": "library",
282198          "bom-ref": "pkg:apk/alpine/aom-libs@3.5.0-r0?arch=x86_64\u0026upstream=aom\u0026distro=alpine-3.17.2\u0026package-id=dda899beeecf55cd",
282199          "supplier": {},
282200          "publisher": "Oleg Titov \u003coleg.titov@gmail.com\u003e",
282201          "name": "aom-libs",
282202          "version": "3.5.0-r0",
282203          "description": "Alliance for Open Media (AOM) AV1 codec SDK (libraries)",
282204          "licenses": [
282205            {
282206              "license": {
282207                "id": "BSD-2-Clause"
282208              }
282209            },
282210            {
282211              "license": {
282212                "name": "AND"
282213              }
282214            },
282215            {
282216              "license": {
282217                "name": "custom"
282218              }
282219            }
282220          ],
282221          "cpe": "cpe:2.3:a:aom-libs:aom-libs:3.5.0-r0:*:*:*:*:*:*:*",
282222          "purl": "pkg:apk/alpine/aom-libs@3.5.0-r0?arch=x86_64\u0026upstream=aom\u0026distro=alpine-3.17.2",
282223          "swid": {
282224            "attachment": {}
282225          },
282226          "pedigree": {},
282227          "externalReferences": [
282228            {
282229              "url": "https://aomedia.org/",
282230              "type": "distribution"
282231            }
282232          ],
282233          "evidence": {},
282234          "signature": {
282235            "signature": {
282236              "publicKey": {}
282237            }
282238          },
282239          "modelCard": {
282240            "modelParameters": {
282241              "approach": {}
282242            },
282243            "quantitativeAnalysis": {
282244              "graphics": {}
282245            },
282246            "considerations": {}
282247          }
282248        },
282249        {
282250          "type": "library",
282251          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=e5f757b0df1f62bc",
282252          "supplier": {},
282253          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
282254          "name": "apk-tools",
282255          "version": "2.12.10-r1",
282256          "description": "Alpine Package Keeper - package manager for alpine",
282257          "licenses": [
282258            {
282259              "license": {
282260                "id": "GPL-2.0-only"
282261              }
282262            }
282263          ],
282264          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.10-r1:*:*:*:*:*:*:*",
282265          "purl": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.2",
282266          "swid": {
282267            "attachment": {}
282268          },
282269          "pedigree": {},
282270          "externalReferences": [
282271            {
282272              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
282273              "type": "distribution"
282274            }
282275          ],
282276          "evidence": {},
282277          "signature": {
282278            "signature": {
282279              "publicKey": {}
282280            }
282281          },
282282          "modelCard": {
282283            "modelParameters": {
282284              "approach": {}
282285            },
282286            "quantitativeAnalysis": {
282287              "graphics": {}
282288            },
282289            "considerations": {}
282290          }
282291        },
282292        {
282293          "type": "library",
282294          "bom-ref": "pkg:apk/alpine/brotli-libs@1.0.9-r9?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.17.2\u0026package-id=b908173dd9145006",
282295          "supplier": {},
282296          "publisher": "prspkt \u003cprspkt@protonmail.com\u003e",
282297          "name": "brotli-libs",
282298          "version": "1.0.9-r9",
282299          "description": "Generic lossless compressor (libraries)",
282300          "licenses": [
282301            {
282302              "license": {
282303                "id": "MIT"
282304              }
282305            }
282306          ],
282307          "cpe": "cpe:2.3:a:brotli-libs:brotli-libs:1.0.9-r9:*:*:*:*:*:*:*",
282308          "purl": "pkg:apk/alpine/brotli-libs@1.0.9-r9?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.17.2",
282309          "swid": {
282310            "attachment": {}
282311          },
282312          "pedigree": {},
282313          "externalReferences": [
282314            {
282315              "url": "https://github.com/google/brotli",
282316              "type": "distribution"
282317            }
282318          ],
282319          "evidence": {},
282320          "signature": {
282321            "signature": {
282322              "publicKey": {}
282323            }
282324          },
282325          "modelCard": {
282326            "modelParameters": {
282327              "approach": {}
282328            },
282329            "quantitativeAnalysis": {
282330              "graphics": {}
282331            },
282332            "considerations": {}
282333          }
282334        },
282335        {
282336          "type": "application",
282337          "bom-ref": "aa1ac704d327fec",
282338          "supplier": {},
282339          "name": "busybox",
282340          "version": "1.35.0",
282341          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
282342          "swid": {
282343            "attachment": {}
282344          },
282345          "pedigree": {},
282346          "evidence": {},
282347          "signature": {
282348            "signature": {
282349              "publicKey": {}
282350            }
282351          },
282352          "modelCard": {
282353            "modelParameters": {
282354              "approach": {}
282355            },
282356            "quantitativeAnalysis": {
282357              "graphics": {}
282358            },
282359            "considerations": {}
282360          }
282361        },
282362        {
282363          "type": "library",
282364          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=623d53216342d45e",
282365          "supplier": {},
282366          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
282367          "name": "busybox",
282368          "version": "1.35.0-r29",
282369          "description": "Size optimized toolbox of many common UNIX utilities",
282370          "licenses": [
282371            {
282372              "license": {
282373                "id": "GPL-2.0-only"
282374              }
282375            }
282376          ],
282377          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r29:*:*:*:*:*:*:*",
282378          "purl": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.2",
282379          "swid": {
282380            "attachment": {}
282381          },
282382          "pedigree": {},
282383          "externalReferences": [
282384            {
282385              "url": "https://busybox.net/",
282386              "type": "distribution"
282387            }
282388          ],
282389          "evidence": {},
282390          "signature": {
282391            "signature": {
282392              "publicKey": {}
282393            }
282394          },
282395          "modelCard": {
282396            "modelParameters": {
282397              "approach": {}
282398            },
282399            "quantitativeAnalysis": {
282400              "graphics": {}
282401            },
282402            "considerations": {}
282403          }
282404        },
282405        {
282406          "type": "library",
282407          "bom-ref": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.2\u0026package-id=256fc96b4a8c4da8",
282408          "supplier": {},
282409          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
282410          "name": "busybox-binsh",
282411          "version": "1.35.0-r29",
282412          "description": "busybox ash /bin/sh",
282413          "licenses": [
282414            {
282415              "license": {
282416                "id": "GPL-2.0-only"
282417              }
282418            }
282419          ],
282420          "cpe": "cpe:2.3:a:busybox-binsh:busybox-binsh:1.35.0-r29:*:*:*:*:*:*:*",
282421          "purl": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.2",
282422          "swid": {
282423            "attachment": {}
282424          },
282425          "pedigree": {},
282426          "externalReferences": [
282427            {
282428              "url": "https://busybox.net/",
282429              "type": "distribution"
282430            }
282431          ],
282432          "evidence": {},
282433          "signature": {
282434            "signature": {
282435              "publicKey": {}
282436            }
282437          },
282438          "modelCard": {
282439            "modelParameters": {
282440              "approach": {}
282441            },
282442            "quantitativeAnalysis": {
282443              "graphics": {}
282444            },
282445            "considerations": {}
282446          }
282447        },
282448        {
282449          "type": "library",
282450          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.2\u0026package-id=b805d823ae624f04",
282451          "supplier": {},
282452          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
282453          "name": "ca-certificates-bundle",
282454          "version": "20220614-r4",
282455          "description": "Pre generated bundle of Mozilla certificates",
282456          "licenses": [
282457            {
282458              "license": {
282459                "id": "MPL-2.0"
282460              }
282461            },
282462            {
282463              "license": {
282464                "name": "AND"
282465              }
282466            },
282467            {
282468              "license": {
282469                "id": "MIT"
282470              }
282471            }
282472          ],
282473          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r4:*:*:*:*:*:*:*",
282474          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.2",
282475          "swid": {
282476            "attachment": {}
282477          },
282478          "pedigree": {},
282479          "externalReferences": [
282480            {
282481              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
282482              "type": "distribution"
282483            }
282484          ],
282485          "evidence": {},
282486          "signature": {
282487            "signature": {
282488              "publicKey": {}
282489            }
282490          },
282491          "modelCard": {
282492            "modelParameters": {
282493              "approach": {}
282494            },
282495            "quantitativeAnalysis": {
282496              "graphics": {}
282497            },
282498            "considerations": {}
282499          }
282500        },
282501        {
282502          "type": "library",
282503          "bom-ref": "pkg:apk/alpine/fontconfig@2.14.1-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=adae4094ba998368",
282504          "supplier": {},
282505          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
282506          "name": "fontconfig",
282507          "version": "2.14.1-r0",
282508          "description": "Library for configuring and customizing font access",
282509          "licenses": [
282510            {
282511              "license": {
282512                "id": "MIT"
282513              }
282514            }
282515          ],
282516          "cpe": "cpe:2.3:a:fontconfig:fontconfig:2.14.1-r0:*:*:*:*:*:*:*",
282517          "purl": "pkg:apk/alpine/fontconfig@2.14.1-r0?arch=x86_64\u0026distro=alpine-3.17.2",
282518          "swid": {
282519            "attachment": {}
282520          },
282521          "pedigree": {},
282522          "externalReferences": [
282523            {
282524              "url": "https://www.freedesktop.org/wiki/Software/fontconfig",
282525              "type": "distribution"
282526            }
282527          ],
282528          "evidence": {},
282529          "signature": {
282530            "signature": {
282531              "publicKey": {}
282532            }
282533          },
282534          "modelCard": {
282535            "modelParameters": {
282536              "approach": {}
282537            },
282538            "quantitativeAnalysis": {
282539              "graphics": {}
282540            },
282541            "considerations": {}
282542          }
282543        },
282544        {
282545          "type": "library",
282546          "bom-ref": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=2b1bfc10343b9080",
282547          "supplier": {},
282548          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
282549          "name": "freetype",
282550          "version": "2.12.1-r0",
282551          "description": "TrueType font rendering library",
282552          "licenses": [
282553            {
282554              "license": {
282555                "id": "FTL"
282556              }
282557            },
282558            {
282559              "license": {
282560                "id": "GPL-2.0-or-later"
282561              }
282562            }
282563          ],
282564          "cpe": "cpe:2.3:a:freetype:freetype:2.12.1-r0:*:*:*:*:*:*:*",
282565          "purl": "pkg:apk/alpine/freetype@2.12.1-r0?arch=x86_64\u0026distro=alpine-3.17.2",
282566          "swid": {
282567            "attachment": {}
282568          },
282569          "pedigree": {},
282570          "externalReferences": [
282571            {
282572              "url": "https://www.freetype.org/",
282573              "type": "distribution"
282574            }
282575          ],
282576          "evidence": {},
282577          "signature": {
282578            "signature": {
282579              "publicKey": {}
282580            }
282581          },
282582          "modelCard": {
282583            "modelParameters": {
282584              "approach": {}
282585            },
282586            "quantitativeAnalysis": {
282587              "graphics": {}
282588            },
282589            "considerations": {}
282590          }
282591        },
282592        {
282593          "type": "library",
282594          "bom-ref": "pkg:apk/alpine/gd@2.3.3-r3?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=2510ca36802a2636",
282595          "supplier": {},
282596          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
282597          "name": "gd",
282598          "version": "2.3.3-r3",
282599          "description": "Library for the dynamic creation of images by programmers",
282600          "licenses": [
282601            {
282602              "license": {
282603                "name": "custom"
282604              }
282605            }
282606          ],
282607          "cpe": "cpe:2.3:a:gd:gd:2.3.3-r3:*:*:*:*:*:*:*",
282608          "purl": "pkg:apk/alpine/gd@2.3.3-r3?arch=x86_64\u0026distro=alpine-3.17.2",
282609          "swid": {
282610            "attachment": {}
282611          },
282612          "pedigree": {},
282613          "externalReferences": [
282614            {
282615              "url": "https://libgd.github.io/",
282616              "type": "distribution"
282617            }
282618          ],
282619          "evidence": {},
282620          "signature": {
282621            "signature": {
282622              "publicKey": {}
282623            }
282624          },
282625          "modelCard": {
282626            "modelParameters": {
282627              "approach": {}
282628            },
282629            "quantitativeAnalysis": {
282630              "graphics": {}
282631            },
282632            "considerations": {}
282633          }
282634        },
282635        {
282636          "type": "library",
282637          "bom-ref": "pkg:apk/alpine/geoip@1.6.12-r3?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=f4075f408016ba5b",
282638          "supplier": {},
282639          "publisher": "Leonardo Arena \u003crnalrd@alpinelinux.org\u003e",
282640          "name": "geoip",
282641          "version": "1.6.12-r3",
282642          "description": "Lookup countries by IP addresses",
282643          "licenses": [
282644            {
282645              "license": {
282646                "name": "GPL"
282647              }
282648            }
282649          ],
282650          "cpe": "cpe:2.3:a:geoip:geoip:1.6.12-r3:*:*:*:*:*:*:*",
282651          "purl": "pkg:apk/alpine/geoip@1.6.12-r3?arch=x86_64\u0026distro=alpine-3.17.2",
282652          "swid": {
282653            "attachment": {}
282654          },
282655          "pedigree": {},
282656          "externalReferences": [
282657            {
282658              "url": "http://www.maxmind.com/app/ip-location",
282659              "type": "distribution"
282660            }
282661          ],
282662          "evidence": {},
282663          "signature": {
282664            "signature": {
282665              "publicKey": {}
282666            }
282667          },
282668          "modelCard": {
282669            "modelParameters": {
282670              "approach": {}
282671            },
282672            "quantitativeAnalysis": {
282673              "graphics": {}
282674            },
282675            "considerations": {}
282676          }
282677        },
282678        {
282679          "type": "library",
282680          "bom-ref": "pkg:apk/alpine/libavif@0.11.1-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=f100fe0aa4e2f851",
282681          "supplier": {},
282682          "publisher": "Bart Ribbers \u003cbribbers@disroot.org\u003e",
282683          "name": "libavif",
282684          "version": "0.11.1-r0",
282685          "description": "Library for encoding and decoding .avif files",
282686          "licenses": [
282687            {
282688              "license": {
282689                "id": "BSD-2-Clause"
282690              }
282691            }
282692          ],
282693          "cpe": "cpe:2.3:a:libavif:libavif:0.11.1-r0:*:*:*:*:*:*:*",
282694          "purl": "pkg:apk/alpine/libavif@0.11.1-r0?arch=x86_64\u0026distro=alpine-3.17.2",
282695          "swid": {
282696            "attachment": {}
282697          },
282698          "pedigree": {},
282699          "externalReferences": [
282700            {
282701              "url": "https://aomediacodec.github.io/av1-avif/",
282702              "type": "distribution"
282703            }
282704          ],
282705          "evidence": {},
282706          "signature": {
282707            "signature": {
282708              "publicKey": {}
282709            }
282710          },
282711          "modelCard": {
282712            "modelParameters": {
282713              "approach": {}
282714            },
282715            "quantitativeAnalysis": {
282716              "graphics": {}
282717            },
282718            "considerations": {}
282719          }
282720        },
282721        {
282722          "type": "library",
282723          "bom-ref": "pkg:apk/alpine/libbsd@0.11.7-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=d55431c5897f9ced",
282724          "supplier": {},
282725          "publisher": "Drew DeVault \u003csir@cmpwn.com\u003e",
282726          "name": "libbsd",
282727          "version": "0.11.7-r0",
282728          "description": "commonly-used BSD functions not implemented by all libcs",
282729          "licenses": [
282730            {
282731              "license": {
282732                "id": "BSD-3-Clause"
282733              }
282734            }
282735          ],
282736          "cpe": "cpe:2.3:a:libbsd:libbsd:0.11.7-r0:*:*:*:*:*:*:*",
282737          "purl": "pkg:apk/alpine/libbsd@0.11.7-r0?arch=x86_64\u0026distro=alpine-3.17.2",
282738          "swid": {
282739            "attachment": {}
282740          },
282741          "pedigree": {},
282742          "externalReferences": [
282743            {
282744              "url": "https://libbsd.freedesktop.org/",
282745              "type": "distribution"
282746            }
282747          ],
282748          "evidence": {},
282749          "signature": {
282750            "signature": {
282751              "publicKey": {}
282752            }
282753          },
282754          "modelCard": {
282755            "modelParameters": {
282756              "approach": {}
282757            },
282758            "quantitativeAnalysis": {
282759              "graphics": {}
282760            },
282761            "considerations": {}
282762          }
282763        },
282764        {
282765          "type": "library",
282766          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r4?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.17.2\u0026package-id=60a12fd5038efa61",
282767          "supplier": {},
282768          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
282769          "name": "libbz2",
282770          "version": "1.0.8-r4",
282771          "description": "Shared library for bz2",
282772          "licenses": [
282773            {
282774              "license": {
282775                "id": "bzip2-1.0.6"
282776              }
282777            }
282778          ],
282779          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r4:*:*:*:*:*:*:*",
282780          "purl": "pkg:apk/alpine/libbz2@1.0.8-r4?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.17.2",
282781          "swid": {
282782            "attachment": {}
282783          },
282784          "pedigree": {},
282785          "externalReferences": [
282786            {
282787              "url": "https://sourceware.org/bzip2/",
282788              "type": "distribution"
282789            }
282790          ],
282791          "evidence": {},
282792          "signature": {
282793            "signature": {
282794              "publicKey": {}
282795            }
282796          },
282797          "modelCard": {
282798            "modelParameters": {
282799              "approach": {}
282800            },
282801            "quantitativeAnalysis": {
282802              "graphics": {}
282803            },
282804            "considerations": {}
282805          }
282806        },
282807        {
282808          "type": "library",
282809          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.2\u0026package-id=8126b232e2d3c608",
282810          "supplier": {},
282811          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
282812          "name": "libc-utils",
282813          "version": "0.7.2-r3",
282814          "description": "Meta package to pull in correct libc",
282815          "licenses": [
282816            {
282817              "license": {
282818                "id": "BSD-2-Clause"
282819              }
282820            },
282821            {
282822              "license": {
282823                "name": "AND"
282824              }
282825            },
282826            {
282827              "license": {
282828                "id": "BSD-3-Clause"
282829              }
282830            }
282831          ],
282832          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
282833          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.2",
282834          "swid": {
282835            "attachment": {}
282836          },
282837          "pedigree": {},
282838          "externalReferences": [
282839            {
282840              "url": "https://alpinelinux.org",
282841              "type": "distribution"
282842            }
282843          ],
282844          "evidence": {},
282845          "signature": {
282846            "signature": {
282847              "publicKey": {}
282848            }
282849          },
282850          "modelCard": {
282851            "modelParameters": {
282852              "approach": {}
282853            },
282854            "quantitativeAnalysis": {
282855              "graphics": {}
282856            },
282857            "considerations": {}
282858          }
282859        },
282860        {
282861          "type": "library",
282862          "bom-ref": "pkg:apk/alpine/libcrypto3@3.0.8-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.2\u0026package-id=b0e92b2ef962ab6d",
282863          "supplier": {},
282864          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
282865          "name": "libcrypto3",
282866          "version": "3.0.8-r0",
282867          "description": "Crypto library from openssl",
282868          "licenses": [
282869            {
282870              "license": {
282871                "id": "Apache-2.0"
282872              }
282873            }
282874          ],
282875          "cpe": "cpe:2.3:a:libcrypto3:libcrypto3:3.0.8-r0:*:*:*:*:*:*:*",
282876          "purl": "pkg:apk/alpine/libcrypto3@3.0.8-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.2",
282877          "swid": {
282878            "attachment": {}
282879          },
282880          "pedigree": {},
282881          "externalReferences": [
282882            {
282883              "url": "https://www.openssl.org/",
282884              "type": "distribution"
282885            }
282886          ],
282887          "evidence": {},
282888          "signature": {
282889            "signature": {
282890              "publicKey": {}
282891            }
282892          },
282893          "modelCard": {
282894            "modelParameters": {
282895              "approach": {}
282896            },
282897            "quantitativeAnalysis": {
282898              "graphics": {}
282899            },
282900            "considerations": {}
282901          }
282902        },
282903        {
282904          "type": "library",
282905          "bom-ref": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.2\u0026package-id=d3084c788891fb28",
282906          "supplier": {},
282907          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
282908          "name": "libcrypto3",
282909          "version": "3.0.8-r3",
282910          "description": "Crypto library from openssl",
282911          "licenses": [
282912            {
282913              "license": {
282914                "id": "Apache-2.0"
282915              }
282916            }
282917          ],
282918          "cpe": "cpe:2.3:a:libcrypto3:libcrypto3:3.0.8-r3:*:*:*:*:*:*:*",
282919          "purl": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.2",
282920          "swid": {
282921            "attachment": {}
282922          },
282923          "pedigree": {},
282924          "externalReferences": [
282925            {
282926              "url": "https://www.openssl.org/",
282927              "type": "distribution"
282928            }
282929          ],
282930          "evidence": {},
282931          "signature": {
282932            "signature": {
282933              "publicKey": {}
282934            }
282935          },
282936          "modelCard": {
282937            "modelParameters": {
282938              "approach": {}
282939            },
282940            "quantitativeAnalysis": {
282941              "graphics": {}
282942            },
282943            "considerations": {}
282944          }
282945        },
282946        {
282947          "type": "library",
282948          "bom-ref": "pkg:apk/alpine/libdav1d@1.0.0-r2?arch=x86_64\u0026upstream=dav1d\u0026distro=alpine-3.17.2\u0026package-id=e65bcf5fb90c2e84",
282949          "supplier": {},
282950          "publisher": "Bart Ribbers \u003cbribbers@disroot.org\u003e",
282951          "name": "libdav1d",
282952          "version": "1.0.0-r2",
282953          "description": "small and fast AV1 Decoder (libraries)",
282954          "licenses": [
282955            {
282956              "license": {
282957                "id": "BSD-2-Clause"
282958              }
282959            }
282960          ],
282961          "cpe": "cpe:2.3:a:libdav1d:libdav1d:1.0.0-r2:*:*:*:*:*:*:*",
282962          "purl": "pkg:apk/alpine/libdav1d@1.0.0-r2?arch=x86_64\u0026upstream=dav1d\u0026distro=alpine-3.17.2",
282963          "swid": {
282964            "attachment": {}
282965          },
282966          "pedigree": {},
282967          "externalReferences": [
282968            {
282969              "url": "https://code.videolan.org/videolan/dav1d",
282970              "type": "distribution"
282971            }
282972          ],
282973          "evidence": {},
282974          "signature": {
282975            "signature": {
282976              "publicKey": {}
282977            }
282978          },
282979          "modelCard": {
282980            "modelParameters": {
282981              "approach": {}
282982            },
282983            "quantitativeAnalysis": {
282984              "graphics": {}
282985            },
282986            "considerations": {}
282987          }
282988        },
282989        {
282990          "type": "library",
282991          "bom-ref": "pkg:apk/alpine/libexpat@2.5.0-r0?arch=x86_64\u0026upstream=expat\u0026distro=alpine-3.17.2\u0026package-id=3230d7655464b5cd",
282992          "supplier": {},
282993          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
282994          "name": "libexpat",
282995          "version": "2.5.0-r0",
282996          "description": "XML Parser library written in C (libraries)",
282997          "licenses": [
282998            {
282999              "license": {
283000                "id": "MIT"
283001              }
283002            }
283003          ],
283004          "cpe": "cpe:2.3:a:libexpat:libexpat:2.5.0-r0:*:*:*:*:*:*:*",
283005          "purl": "pkg:apk/alpine/libexpat@2.5.0-r0?arch=x86_64\u0026upstream=expat\u0026distro=alpine-3.17.2",
283006          "swid": {
283007            "attachment": {}
283008          },
283009          "pedigree": {},
283010          "externalReferences": [
283011            {
283012              "url": "https://libexpat.github.io/",
283013              "type": "distribution"
283014            }
283015          ],
283016          "evidence": {},
283017          "signature": {
283018            "signature": {
283019              "publicKey": {}
283020            }
283021          },
283022          "modelCard": {
283023            "modelParameters": {
283024              "approach": {}
283025            },
283026            "quantitativeAnalysis": {
283027              "graphics": {}
283028            },
283029            "considerations": {}
283030          }
283031        },
283032        {
283033          "type": "library",
283034          "bom-ref": "pkg:apk/alpine/libgcc@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.2\u0026package-id=4dbb63d06d9618e9",
283035          "supplier": {},
283036          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
283037          "name": "libgcc",
283038          "version": "12.2.1_git20220924-r4",
283039          "description": "GNU C compiler runtime libraries",
283040          "licenses": [
283041            {
283042              "license": {
283043                "id": "GPL-2.0-or-later"
283044              }
283045            },
283046            {
283047              "license": {
283048                "id": "LGPL-2.1-or-later"
283049              }
283050            }
283051          ],
283052          "cpe": "cpe:2.3:a:libgcc:libgcc:12.2.1_git20220924-r4:*:*:*:*:*:*:*",
283053          "purl": "pkg:apk/alpine/libgcc@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.2",
283054          "swid": {
283055            "attachment": {}
283056          },
283057          "pedigree": {},
283058          "externalReferences": [
283059            {
283060              "url": "https://gcc.gnu.org",
283061              "type": "distribution"
283062            }
283063          ],
283064          "evidence": {},
283065          "signature": {
283066            "signature": {
283067              "publicKey": {}
283068            }
283069          },
283070          "modelCard": {
283071            "modelParameters": {
283072              "approach": {}
283073            },
283074            "quantitativeAnalysis": {
283075              "graphics": {}
283076            },
283077            "considerations": {}
283078          }
283079        },
283080        {
283081          "type": "library",
283082          "bom-ref": "pkg:apk/alpine/libgcrypt@1.10.1-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=19cda171af31bddf",
283083          "supplier": {},
283084          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283085          "name": "libgcrypt",
283086          "version": "1.10.1-r0",
283087          "description": "General purpose crypto library based on the code used in GnuPG",
283088          "licenses": [
283089            {
283090              "license": {
283091                "id": "LGPL-2.1-or-later"
283092              }
283093            }
283094          ],
283095          "cpe": "cpe:2.3:a:libgcrypt:libgcrypt:1.10.1-r0:*:*:*:*:*:*:*",
283096          "purl": "pkg:apk/alpine/libgcrypt@1.10.1-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283097          "swid": {
283098            "attachment": {}
283099          },
283100          "pedigree": {},
283101          "externalReferences": [
283102            {
283103              "url": "https://www.gnupg.org/",
283104              "type": "distribution"
283105            }
283106          ],
283107          "evidence": {},
283108          "signature": {
283109            "signature": {
283110              "publicKey": {}
283111            }
283112          },
283113          "modelCard": {
283114            "modelParameters": {
283115              "approach": {}
283116            },
283117            "quantitativeAnalysis": {
283118              "graphics": {}
283119            },
283120            "considerations": {}
283121          }
283122        },
283123        {
283124          "type": "library",
283125          "bom-ref": "pkg:apk/alpine/libgd@2.3.3-r3?arch=x86_64\u0026upstream=gd\u0026distro=alpine-3.17.2\u0026package-id=c2197bc58668f729",
283126          "supplier": {},
283127          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
283128          "name": "libgd",
283129          "version": "2.3.3-r3",
283130          "description": "Library for the dynamic creation of images by programmers (libraries)",
283131          "licenses": [
283132            {
283133              "license": {
283134                "name": "custom"
283135              }
283136            }
283137          ],
283138          "cpe": "cpe:2.3:a:libgd:libgd:2.3.3-r3:*:*:*:*:*:*:*",
283139          "purl": "pkg:apk/alpine/libgd@2.3.3-r3?arch=x86_64\u0026upstream=gd\u0026distro=alpine-3.17.2",
283140          "swid": {
283141            "attachment": {}
283142          },
283143          "pedigree": {},
283144          "externalReferences": [
283145            {
283146              "url": "https://libgd.github.io/",
283147              "type": "distribution"
283148            }
283149          ],
283150          "evidence": {},
283151          "signature": {
283152            "signature": {
283153              "publicKey": {}
283154            }
283155          },
283156          "modelCard": {
283157            "modelParameters": {
283158              "approach": {}
283159            },
283160            "quantitativeAnalysis": {
283161              "graphics": {}
283162            },
283163            "considerations": {}
283164          }
283165        },
283166        {
283167          "type": "library",
283168          "bom-ref": "pkg:apk/alpine/libgpg-error@1.46-r1?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=a2ff8bdcd7e1dd79",
283169          "supplier": {},
283170          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283171          "name": "libgpg-error",
283172          "version": "1.46-r1",
283173          "description": "Support library for libgcrypt",
283174          "licenses": [
283175            {
283176              "license": {
283177                "id": "GPL-2.0-or-later"
283178              }
283179            },
283180            {
283181              "license": {
283182                "id": "LGPL-2.1-or-later"
283183              }
283184            }
283185          ],
283186          "cpe": "cpe:2.3:a:libgpg-error:libgpg-error:1.46-r1:*:*:*:*:*:*:*",
283187          "purl": "pkg:apk/alpine/libgpg-error@1.46-r1?arch=x86_64\u0026distro=alpine-3.17.2",
283188          "swid": {
283189            "attachment": {}
283190          },
283191          "pedigree": {},
283192          "externalReferences": [
283193            {
283194              "url": "https://www.gnupg.org/",
283195              "type": "distribution"
283196            }
283197          ],
283198          "evidence": {},
283199          "signature": {
283200            "signature": {
283201              "publicKey": {}
283202            }
283203          },
283204          "modelCard": {
283205            "modelParameters": {
283206              "approach": {}
283207            },
283208            "quantitativeAnalysis": {
283209              "graphics": {}
283210            },
283211            "considerations": {}
283212          }
283213        },
283214        {
283215          "type": "library",
283216          "bom-ref": "pkg:apk/alpine/libice@1.0.10-r1?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=9972a03c39962bb9",
283217          "supplier": {},
283218          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283219          "name": "libice",
283220          "version": "1.0.10-r1",
283221          "description": "X11 Inter-Client Exchange library",
283222          "licenses": [
283223            {
283224              "license": {
283225                "id": "X11"
283226              }
283227            }
283228          ],
283229          "cpe": "cpe:2.3:a:libice:libice:1.0.10-r1:*:*:*:*:*:*:*",
283230          "purl": "pkg:apk/alpine/libice@1.0.10-r1?arch=x86_64\u0026distro=alpine-3.17.2",
283231          "swid": {
283232            "attachment": {}
283233          },
283234          "pedigree": {},
283235          "externalReferences": [
283236            {
283237              "url": "http://xorg.freedesktop.org/",
283238              "type": "distribution"
283239            }
283240          ],
283241          "evidence": {},
283242          "signature": {
283243            "signature": {
283244              "publicKey": {}
283245            }
283246          },
283247          "modelCard": {
283248            "modelParameters": {
283249              "approach": {}
283250            },
283251            "quantitativeAnalysis": {
283252              "graphics": {}
283253            },
283254            "considerations": {}
283255          }
283256        },
283257        {
283258          "type": "library",
283259          "bom-ref": "pkg:apk/alpine/libjpeg-turbo@2.1.4-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=f1b99d9aedffa0e8",
283260          "supplier": {},
283261          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283262          "name": "libjpeg-turbo",
283263          "version": "2.1.4-r0",
283264          "description": "Accelerated baseline JPEG compression and decompression library",
283265          "licenses": [
283266            {
283267              "license": {
283268                "id": "BSD-3-Clause"
283269              }
283270            },
283271            {
283272              "license": {
283273                "name": "AND"
283274              }
283275            },
283276            {
283277              "license": {
283278                "id": "IJG"
283279              }
283280            },
283281            {
283282              "license": {
283283                "name": "AND"
283284              }
283285            },
283286            {
283287              "license": {
283288                "id": "Zlib"
283289              }
283290            }
283291          ],
283292          "cpe": "cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:2.1.4-r0:*:*:*:*:*:*:*",
283293          "purl": "pkg:apk/alpine/libjpeg-turbo@2.1.4-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283294          "swid": {
283295            "attachment": {}
283296          },
283297          "pedigree": {},
283298          "externalReferences": [
283299            {
283300              "url": "https://libjpeg-turbo.org/",
283301              "type": "distribution"
283302            }
283303          ],
283304          "evidence": {},
283305          "signature": {
283306            "signature": {
283307              "publicKey": {}
283308            }
283309          },
283310          "modelCard": {
283311            "modelParameters": {
283312              "approach": {}
283313            },
283314            "quantitativeAnalysis": {
283315              "graphics": {}
283316            },
283317            "considerations": {}
283318          }
283319        },
283320        {
283321          "type": "library",
283322          "bom-ref": "pkg:apk/alpine/libmd@1.0.4-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=813b4dc93a907c78",
283323          "supplier": {},
283324          "publisher": "omni \u003comni+alpine@hack.org\u003e",
283325          "name": "libmd",
283326          "version": "1.0.4-r0",
283327          "description": "Message Digest functions from BSD systems",
283328          "licenses": [
283329            {
283330              "license": {
283331                "name": "Public"
283332              }
283333            },
283334            {
283335              "license": {
283336                "name": "Domain"
283337              }
283338            }
283339          ],
283340          "cpe": "cpe:2.3:a:libmd:libmd:1.0.4-r0:*:*:*:*:*:*:*",
283341          "purl": "pkg:apk/alpine/libmd@1.0.4-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283342          "swid": {
283343            "attachment": {}
283344          },
283345          "pedigree": {},
283346          "externalReferences": [
283347            {
283348              "url": "https://www.hadrons.org/software/libmd/",
283349              "type": "distribution"
283350            }
283351          ],
283352          "evidence": {},
283353          "signature": {
283354            "signature": {
283355              "publicKey": {}
283356            }
283357          },
283358          "modelCard": {
283359            "modelParameters": {
283360              "approach": {}
283361            },
283362            "quantitativeAnalysis": {
283363              "graphics": {}
283364            },
283365            "considerations": {}
283366          }
283367        },
283368        {
283369          "type": "library",
283370          "bom-ref": "pkg:apk/alpine/libpng@1.6.38-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=de4865c94634be51",
283371          "supplier": {},
283372          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283373          "name": "libpng",
283374          "version": "1.6.38-r0",
283375          "description": "Portable Network Graphics library",
283376          "licenses": [
283377            {
283378              "license": {
283379                "id": "Libpng"
283380              }
283381            }
283382          ],
283383          "cpe": "cpe:2.3:a:libpng:libpng:1.6.38-r0:*:*:*:*:*:*:*",
283384          "purl": "pkg:apk/alpine/libpng@1.6.38-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283385          "swid": {
283386            "attachment": {}
283387          },
283388          "pedigree": {},
283389          "externalReferences": [
283390            {
283391              "url": "http://www.libpng.org",
283392              "type": "distribution"
283393            }
283394          ],
283395          "evidence": {},
283396          "signature": {
283397            "signature": {
283398              "publicKey": {}
283399            }
283400          },
283401          "modelCard": {
283402            "modelParameters": {
283403              "approach": {}
283404            },
283405            "quantitativeAnalysis": {
283406              "graphics": {}
283407            },
283408            "considerations": {}
283409          }
283410        },
283411        {
283412          "type": "library",
283413          "bom-ref": "pkg:apk/alpine/libsm@1.2.3-r1?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=30bd714a5c7898c3",
283414          "supplier": {},
283415          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283416          "name": "libsm",
283417          "version": "1.2.3-r1",
283418          "description": "X11 Session Management library",
283419          "licenses": [
283420            {
283421              "license": {
283422                "id": "MIT"
283423              }
283424            }
283425          ],
283426          "cpe": "cpe:2.3:a:libsm:libsm:1.2.3-r1:*:*:*:*:*:*:*",
283427          "purl": "pkg:apk/alpine/libsm@1.2.3-r1?arch=x86_64\u0026distro=alpine-3.17.2",
283428          "swid": {
283429            "attachment": {}
283430          },
283431          "pedigree": {},
283432          "externalReferences": [
283433            {
283434              "url": "https://xorg.freedesktop.org/",
283435              "type": "distribution"
283436            }
283437          ],
283438          "evidence": {},
283439          "signature": {
283440            "signature": {
283441              "publicKey": {}
283442            }
283443          },
283444          "modelCard": {
283445            "modelParameters": {
283446              "approach": {}
283447            },
283448            "quantitativeAnalysis": {
283449              "graphics": {}
283450            },
283451            "considerations": {}
283452          }
283453        },
283454        {
283455          "type": "library",
283456          "bom-ref": "pkg:apk/alpine/libssl3@3.0.8-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.2\u0026package-id=9005623d3896bb87",
283457          "supplier": {},
283458          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
283459          "name": "libssl3",
283460          "version": "3.0.8-r0",
283461          "description": "SSL shared libraries",
283462          "licenses": [
283463            {
283464              "license": {
283465                "id": "Apache-2.0"
283466              }
283467            }
283468          ],
283469          "cpe": "cpe:2.3:a:libssl3:libssl3:3.0.8-r0:*:*:*:*:*:*:*",
283470          "purl": "pkg:apk/alpine/libssl3@3.0.8-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.2",
283471          "swid": {
283472            "attachment": {}
283473          },
283474          "pedigree": {},
283475          "externalReferences": [
283476            {
283477              "url": "https://www.openssl.org/",
283478              "type": "distribution"
283479            }
283480          ],
283481          "evidence": {},
283482          "signature": {
283483            "signature": {
283484              "publicKey": {}
283485            }
283486          },
283487          "modelCard": {
283488            "modelParameters": {
283489              "approach": {}
283490            },
283491            "quantitativeAnalysis": {
283492              "graphics": {}
283493            },
283494            "considerations": {}
283495          }
283496        },
283497        {
283498          "type": "library",
283499          "bom-ref": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.2\u0026package-id=2a95f0251fba7a33",
283500          "supplier": {},
283501          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
283502          "name": "libssl3",
283503          "version": "3.0.8-r3",
283504          "description": "SSL shared libraries",
283505          "licenses": [
283506            {
283507              "license": {
283508                "id": "Apache-2.0"
283509              }
283510            }
283511          ],
283512          "cpe": "cpe:2.3:a:libssl3:libssl3:3.0.8-r3:*:*:*:*:*:*:*",
283513          "purl": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.2",
283514          "swid": {
283515            "attachment": {}
283516          },
283517          "pedigree": {},
283518          "externalReferences": [
283519            {
283520              "url": "https://www.openssl.org/",
283521              "type": "distribution"
283522            }
283523          ],
283524          "evidence": {},
283525          "signature": {
283526            "signature": {
283527              "publicKey": {}
283528            }
283529          },
283530          "modelCard": {
283531            "modelParameters": {
283532              "approach": {}
283533            },
283534            "quantitativeAnalysis": {
283535              "graphics": {}
283536            },
283537            "considerations": {}
283538          }
283539        },
283540        {
283541          "type": "library",
283542          "bom-ref": "pkg:apk/alpine/libuuid@2.38.1-r1?arch=x86_64\u0026upstream=util-linux\u0026distro=alpine-3.17.2\u0026package-id=f15daab9c9959397",
283543          "supplier": {},
283544          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283545          "name": "libuuid",
283546          "version": "2.38.1-r1",
283547          "description": "DCE compatible Universally Unique Identifier library",
283548          "licenses": [
283549            {
283550              "license": {
283551                "id": "BSD-3-Clause"
283552              }
283553            }
283554          ],
283555          "cpe": "cpe:2.3:a:libuuid:libuuid:2.38.1-r1:*:*:*:*:*:*:*",
283556          "purl": "pkg:apk/alpine/libuuid@2.38.1-r1?arch=x86_64\u0026upstream=util-linux\u0026distro=alpine-3.17.2",
283557          "swid": {
283558            "attachment": {}
283559          },
283560          "pedigree": {},
283561          "externalReferences": [
283562            {
283563              "url": "https://git.kernel.org/cgit/utils/util-linux/util-linux.git",
283564              "type": "distribution"
283565            }
283566          ],
283567          "evidence": {},
283568          "signature": {
283569            "signature": {
283570              "publicKey": {}
283571            }
283572          },
283573          "modelCard": {
283574            "modelParameters": {
283575              "approach": {}
283576            },
283577            "quantitativeAnalysis": {
283578              "graphics": {}
283579            },
283580            "considerations": {}
283581          }
283582        },
283583        {
283584          "type": "library",
283585          "bom-ref": "pkg:apk/alpine/libwebp@1.2.4-r1?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=a51ecbb112e053a",
283586          "supplier": {},
283587          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283588          "name": "libwebp",
283589          "version": "1.2.4-r1",
283590          "description": "Libraries for working with WebP images",
283591          "licenses": [
283592            {
283593              "license": {
283594                "id": "BSD-3-Clause"
283595              }
283596            }
283597          ],
283598          "cpe": "cpe:2.3:a:libwebp:libwebp:1.2.4-r1:*:*:*:*:*:*:*",
283599          "purl": "pkg:apk/alpine/libwebp@1.2.4-r1?arch=x86_64\u0026distro=alpine-3.17.2",
283600          "swid": {
283601            "attachment": {}
283602          },
283603          "pedigree": {},
283604          "externalReferences": [
283605            {
283606              "url": "https://developers.google.com/speed/webp",
283607              "type": "distribution"
283608            }
283609          ],
283610          "evidence": {},
283611          "signature": {
283612            "signature": {
283613              "publicKey": {}
283614            }
283615          },
283616          "modelCard": {
283617            "modelParameters": {
283618              "approach": {}
283619            },
283620            "quantitativeAnalysis": {
283621              "graphics": {}
283622            },
283623            "considerations": {}
283624          }
283625        },
283626        {
283627          "type": "library",
283628          "bom-ref": "pkg:apk/alpine/libx11@1.8.4-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=40301bca6410af1",
283629          "supplier": {},
283630          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283631          "name": "libx11",
283632          "version": "1.8.4-r0",
283633          "description": "X11 client-side library",
283634          "licenses": [
283635            {
283636              "license": {
283637                "name": "custom:XFREE86"
283638              }
283639            }
283640          ],
283641          "cpe": "cpe:2.3:a:libx11:libx11:1.8.4-r0:*:*:*:*:*:*:*",
283642          "purl": "pkg:apk/alpine/libx11@1.8.4-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283643          "swid": {
283644            "attachment": {}
283645          },
283646          "pedigree": {},
283647          "externalReferences": [
283648            {
283649              "url": "http://xorg.freedesktop.org/",
283650              "type": "distribution"
283651            }
283652          ],
283653          "evidence": {},
283654          "signature": {
283655            "signature": {
283656              "publicKey": {}
283657            }
283658          },
283659          "modelCard": {
283660            "modelParameters": {
283661              "approach": {}
283662            },
283663            "quantitativeAnalysis": {
283664              "graphics": {}
283665            },
283666            "considerations": {}
283667          }
283668        },
283669        {
283670          "type": "library",
283671          "bom-ref": "pkg:apk/alpine/libxau@1.0.10-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=e2e56f47e511df94",
283672          "supplier": {},
283673          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283674          "name": "libxau",
283675          "version": "1.0.10-r0",
283676          "description": "X11 authorisation library",
283677          "licenses": [
283678            {
283679              "license": {
283680                "id": "MIT"
283681              }
283682            }
283683          ],
283684          "cpe": "cpe:2.3:a:libxau:libxau:1.0.10-r0:*:*:*:*:*:*:*",
283685          "purl": "pkg:apk/alpine/libxau@1.0.10-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283686          "swid": {
283687            "attachment": {}
283688          },
283689          "pedigree": {},
283690          "externalReferences": [
283691            {
283692              "url": "http://xorg.freedesktop.org/",
283693              "type": "distribution"
283694            }
283695          ],
283696          "evidence": {},
283697          "signature": {
283698            "signature": {
283699              "publicKey": {}
283700            }
283701          },
283702          "modelCard": {
283703            "modelParameters": {
283704              "approach": {}
283705            },
283706            "quantitativeAnalysis": {
283707              "graphics": {}
283708            },
283709            "considerations": {}
283710          }
283711        },
283712        {
283713          "type": "library",
283714          "bom-ref": "pkg:apk/alpine/libxcb@1.15-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=e9bc45b3f25e9dff",
283715          "supplier": {},
283716          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283717          "name": "libxcb",
283718          "version": "1.15-r0",
283719          "description": "X11 client-side library",
283720          "licenses": [
283721            {
283722              "license": {
283723                "id": "MIT"
283724              }
283725            }
283726          ],
283727          "cpe": "cpe:2.3:a:libxcb:libxcb:1.15-r0:*:*:*:*:*:*:*",
283728          "purl": "pkg:apk/alpine/libxcb@1.15-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283729          "swid": {
283730            "attachment": {}
283731          },
283732          "pedigree": {},
283733          "externalReferences": [
283734            {
283735              "url": "https://xcb.freedesktop.org",
283736              "type": "distribution"
283737            }
283738          ],
283739          "evidence": {},
283740          "signature": {
283741            "signature": {
283742              "publicKey": {}
283743            }
283744          },
283745          "modelCard": {
283746            "modelParameters": {
283747              "approach": {}
283748            },
283749            "quantitativeAnalysis": {
283750              "graphics": {}
283751            },
283752            "considerations": {}
283753          }
283754        },
283755        {
283756          "type": "library",
283757          "bom-ref": "pkg:apk/alpine/libxdmcp@1.1.4-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=6bbb1cd47f559f9a",
283758          "supplier": {},
283759          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283760          "name": "libxdmcp",
283761          "version": "1.1.4-r0",
283762          "description": "X11 Display Manager Control Protocol library",
283763          "licenses": [
283764            {
283765              "license": {
283766                "id": "MIT"
283767              }
283768            }
283769          ],
283770          "cpe": "cpe:2.3:a:libxdmcp:libxdmcp:1.1.4-r0:*:*:*:*:*:*:*",
283771          "purl": "pkg:apk/alpine/libxdmcp@1.1.4-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283772          "swid": {
283773            "attachment": {}
283774          },
283775          "pedigree": {},
283776          "externalReferences": [
283777            {
283778              "url": "http://xorg.freedesktop.org/",
283779              "type": "distribution"
283780            }
283781          ],
283782          "evidence": {},
283783          "signature": {
283784            "signature": {
283785              "publicKey": {}
283786            }
283787          },
283788          "modelCard": {
283789            "modelParameters": {
283790              "approach": {}
283791            },
283792            "quantitativeAnalysis": {
283793              "graphics": {}
283794            },
283795            "considerations": {}
283796          }
283797        },
283798        {
283799          "type": "library",
283800          "bom-ref": "pkg:apk/alpine/libxext@1.3.5-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=ed11ed05f407d310",
283801          "supplier": {},
283802          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283803          "name": "libxext",
283804          "version": "1.3.5-r0",
283805          "description": "X11 miscellaneous extensions library",
283806          "licenses": [
283807            {
283808              "license": {
283809                "id": "MIT"
283810              }
283811            }
283812          ],
283813          "cpe": "cpe:2.3:a:libxext:libxext:1.3.5-r0:*:*:*:*:*:*:*",
283814          "purl": "pkg:apk/alpine/libxext@1.3.5-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283815          "swid": {
283816            "attachment": {}
283817          },
283818          "pedigree": {},
283819          "externalReferences": [
283820            {
283821              "url": "http://xorg.freedesktop.org/",
283822              "type": "distribution"
283823            }
283824          ],
283825          "evidence": {},
283826          "signature": {
283827            "signature": {
283828              "publicKey": {}
283829            }
283830          },
283831          "modelCard": {
283832            "modelParameters": {
283833              "approach": {}
283834            },
283835            "quantitativeAnalysis": {
283836              "graphics": {}
283837            },
283838            "considerations": {}
283839          }
283840        },
283841        {
283842          "type": "library",
283843          "bom-ref": "pkg:apk/alpine/libxml2@2.10.3-r1?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=50c4714b5db74ae3",
283844          "supplier": {},
283845          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
283846          "name": "libxml2",
283847          "version": "2.10.3-r1",
283848          "description": "XML parsing library, version 2",
283849          "licenses": [
283850            {
283851              "license": {
283852                "id": "MIT"
283853              }
283854            }
283855          ],
283856          "cpe": "cpe:2.3:a:libxml2:libxml2:2.10.3-r1:*:*:*:*:*:*:*",
283857          "purl": "pkg:apk/alpine/libxml2@2.10.3-r1?arch=x86_64\u0026distro=alpine-3.17.2",
283858          "swid": {
283859            "attachment": {}
283860          },
283861          "pedigree": {},
283862          "externalReferences": [
283863            {
283864              "url": "http://www.xmlsoft.org/",
283865              "type": "distribution"
283866            }
283867          ],
283868          "evidence": {},
283869          "signature": {
283870            "signature": {
283871              "publicKey": {}
283872            }
283873          },
283874          "modelCard": {
283875            "modelParameters": {
283876              "approach": {}
283877            },
283878            "quantitativeAnalysis": {
283879              "graphics": {}
283880            },
283881            "considerations": {}
283882          }
283883        },
283884        {
283885          "type": "library",
283886          "bom-ref": "pkg:apk/alpine/libxpm@3.5.15-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=f8f56cc3f4eddcb4",
283887          "supplier": {},
283888          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283889          "name": "libxpm",
283890          "version": "3.5.15-r0",
283891          "description": "X11 pixmap library",
283892          "licenses": [
283893            {
283894              "license": {
283895                "name": "custom:BELL"
283896              }
283897            }
283898          ],
283899          "cpe": "cpe:2.3:a:libxpm-project:libxpm:3.5.15-r0:*:*:*:*:*:*:*",
283900          "purl": "pkg:apk/alpine/libxpm@3.5.15-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283901          "swid": {
283902            "attachment": {}
283903          },
283904          "pedigree": {},
283905          "externalReferences": [
283906            {
283907              "url": "http://xorg.freedesktop.org/",
283908              "type": "distribution"
283909            }
283910          ],
283911          "evidence": {},
283912          "signature": {
283913            "signature": {
283914              "publicKey": {}
283915            }
283916          },
283917          "modelCard": {
283918            "modelParameters": {
283919              "approach": {}
283920            },
283921            "quantitativeAnalysis": {
283922              "graphics": {}
283923            },
283924            "considerations": {}
283925          }
283926        },
283927        {
283928          "type": "library",
283929          "bom-ref": "pkg:apk/alpine/libxslt@1.1.37-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=67ac2ca91d10cec4",
283930          "supplier": {},
283931          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283932          "name": "libxslt",
283933          "version": "1.1.37-r0",
283934          "description": "XML stylesheet transformation library",
283935          "licenses": [
283936            {
283937              "license": {
283938                "name": "custom"
283939              }
283940            }
283941          ],
283942          "cpe": "cpe:2.3:a:libxslt:libxslt:1.1.37-r0:*:*:*:*:*:*:*",
283943          "purl": "pkg:apk/alpine/libxslt@1.1.37-r0?arch=x86_64\u0026distro=alpine-3.17.2",
283944          "swid": {
283945            "attachment": {}
283946          },
283947          "pedigree": {},
283948          "externalReferences": [
283949            {
283950              "url": "http://xmlsoft.org/XSLT/",
283951              "type": "distribution"
283952            }
283953          ],
283954          "evidence": {},
283955          "signature": {
283956            "signature": {
283957              "publicKey": {}
283958            }
283959          },
283960          "modelCard": {
283961            "modelParameters": {
283962              "approach": {}
283963            },
283964            "quantitativeAnalysis": {
283965              "graphics": {}
283966            },
283967            "considerations": {}
283968          }
283969        },
283970        {
283971          "type": "library",
283972          "bom-ref": "pkg:apk/alpine/libxslt@1.1.37-r1?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=df5746a44775ab80",
283973          "supplier": {},
283974          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
283975          "name": "libxslt",
283976          "version": "1.1.37-r1",
283977          "description": "XML stylesheet transformation library",
283978          "licenses": [
283979            {
283980              "license": {
283981                "name": "custom"
283982              }
283983            }
283984          ],
283985          "cpe": "cpe:2.3:a:libxslt:libxslt:1.1.37-r1:*:*:*:*:*:*:*",
283986          "purl": "pkg:apk/alpine/libxslt@1.1.37-r1?arch=x86_64\u0026distro=alpine-3.17.2",
283987          "swid": {
283988            "attachment": {}
283989          },
283990          "pedigree": {},
283991          "externalReferences": [
283992            {
283993              "url": "http://xmlsoft.org/XSLT/",
283994              "type": "distribution"
283995            }
283996          ],
283997          "evidence": {},
283998          "signature": {
283999            "signature": {
284000              "publicKey": {}
284001            }
284002          },
284003          "modelCard": {
284004            "modelParameters": {
284005              "approach": {}
284006            },
284007            "quantitativeAnalysis": {
284008              "graphics": {}
284009            },
284010            "considerations": {}
284011          }
284012        },
284013        {
284014          "type": "library",
284015          "bom-ref": "pkg:apk/alpine/libxt@1.2.1-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=ab1ee951123527a2",
284016          "supplier": {},
284017          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
284018          "name": "libxt",
284019          "version": "1.2.1-r0",
284020          "description": "X11 toolkit intrinsics library",
284021          "licenses": [
284022            {
284023              "license": {
284024                "name": "custom"
284025              }
284026            }
284027          ],
284028          "cpe": "cpe:2.3:a:libxt:libxt:1.2.1-r0:*:*:*:*:*:*:*",
284029          "purl": "pkg:apk/alpine/libxt@1.2.1-r0?arch=x86_64\u0026distro=alpine-3.17.2",
284030          "swid": {
284031            "attachment": {}
284032          },
284033          "pedigree": {},
284034          "externalReferences": [
284035            {
284036              "url": "http://xorg.freedesktop.org/",
284037              "type": "distribution"
284038            }
284039          ],
284040          "evidence": {},
284041          "signature": {
284042            "signature": {
284043              "publicKey": {}
284044            }
284045          },
284046          "modelCard": {
284047            "modelParameters": {
284048              "approach": {}
284049            },
284050            "quantitativeAnalysis": {
284051              "graphics": {}
284052            },
284053            "considerations": {}
284054          }
284055        },
284056        {
284057          "type": "library",
284058          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=d9700f02cf26e8b8",
284059          "supplier": {},
284060          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
284061          "name": "musl",
284062          "version": "1.2.3-r4",
284063          "description": "the musl c library (libc) implementation",
284064          "licenses": [
284065            {
284066              "license": {
284067                "id": "MIT"
284068              }
284069            }
284070          ],
284071          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r4:*:*:*:*:*:*:*",
284072          "purl": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.2",
284073          "swid": {
284074            "attachment": {}
284075          },
284076          "pedigree": {},
284077          "externalReferences": [
284078            {
284079              "url": "https://musl.libc.org/",
284080              "type": "distribution"
284081            }
284082          ],
284083          "evidence": {},
284084          "signature": {
284085            "signature": {
284086              "publicKey": {}
284087            }
284088          },
284089          "modelCard": {
284090            "modelParameters": {
284091              "approach": {}
284092            },
284093            "quantitativeAnalysis": {
284094              "graphics": {}
284095            },
284096            "considerations": {}
284097          }
284098        },
284099        {
284100          "type": "library",
284101          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.2\u0026package-id=f71ecf5267e6c37b",
284102          "supplier": {},
284103          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
284104          "name": "musl-utils",
284105          "version": "1.2.3-r4",
284106          "description": "the musl c library (libc) implementation",
284107          "licenses": [
284108            {
284109              "license": {
284110                "id": "MIT"
284111              }
284112            },
284113            {
284114              "license": {
284115                "name": "AND"
284116              }
284117            },
284118            {
284119              "license": {
284120                "id": "BSD-2-Clause"
284121              }
284122            },
284123            {
284124              "license": {
284125                "name": "AND"
284126              }
284127            },
284128            {
284129              "license": {
284130                "id": "GPL-2.0-or-later"
284131              }
284132            }
284133          ],
284134          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r4:*:*:*:*:*:*:*",
284135          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.2",
284136          "swid": {
284137            "attachment": {}
284138          },
284139          "pedigree": {},
284140          "externalReferences": [
284141            {
284142              "url": "https://musl.libc.org/",
284143              "type": "distribution"
284144            }
284145          ],
284146          "evidence": {},
284147          "signature": {
284148            "signature": {
284149              "publicKey": {}
284150            }
284151          },
284152          "modelCard": {
284153            "modelParameters": {
284154              "approach": {}
284155            },
284156            "quantitativeAnalysis": {
284157              "graphics": {}
284158            },
284159            "considerations": {}
284160          }
284161        },
284162        {
284163          "type": "library",
284164          "bom-ref": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.2\u0026package-id=e903138d19e85b80",
284165          "supplier": {},
284166          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
284167          "name": "scanelf",
284168          "version": "1.3.5-r1",
284169          "description": "Scan ELF binaries for stuff",
284170          "licenses": [
284171            {
284172              "license": {
284173                "id": "GPL-2.0-only"
284174              }
284175            }
284176          ],
284177          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.5-r1:*:*:*:*:*:*:*",
284178          "purl": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.2",
284179          "swid": {
284180            "attachment": {}
284181          },
284182          "pedigree": {},
284183          "externalReferences": [
284184            {
284185              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
284186              "type": "distribution"
284187            }
284188          ],
284189          "evidence": {},
284190          "signature": {
284191            "signature": {
284192              "publicKey": {}
284193            }
284194          },
284195          "modelCard": {
284196            "modelParameters": {
284197              "approach": {}
284198            },
284199            "quantitativeAnalysis": {
284200              "graphics": {}
284201            },
284202            "considerations": {}
284203          }
284204        },
284205        {
284206          "type": "library",
284207          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.2\u0026package-id=b15247aafcd4a647",
284208          "supplier": {},
284209          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
284210          "name": "ssl_client",
284211          "version": "1.35.0-r29",
284212          "description": "EXternal ssl_client for busybox wget",
284213          "licenses": [
284214            {
284215              "license": {
284216                "id": "GPL-2.0-only"
284217              }
284218            }
284219          ],
284220          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r29:*:*:*:*:*:*:*",
284221          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.2",
284222          "swid": {
284223            "attachment": {}
284224          },
284225          "pedigree": {},
284226          "externalReferences": [
284227            {
284228              "url": "https://busybox.net/",
284229              "type": "distribution"
284230            }
284231          ],
284232          "evidence": {},
284233          "signature": {
284234            "signature": {
284235              "publicKey": {}
284236            }
284237          },
284238          "modelCard": {
284239            "modelParameters": {
284240              "approach": {}
284241            },
284242            "quantitativeAnalysis": {
284243              "graphics": {}
284244            },
284245            "considerations": {}
284246          }
284247        },
284248        {
284249          "type": "library",
284250          "bom-ref": "pkg:apk/alpine/tiff@4.4.0-r1?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=e076958ae2c1ba97",
284251          "supplier": {},
284252          "publisher": "Michael Mason \u003cms13sp@gmail.com\u003e",
284253          "name": "tiff",
284254          "version": "4.4.0-r1",
284255          "description": "Provides support for the Tag Image File Format or TIFF",
284256          "licenses": [
284257            {
284258              "license": {
284259                "id": "libtiff"
284260              }
284261            }
284262          ],
284263          "cpe": "cpe:2.3:a:libtiff:libtiff:4.4.0-r1:*:*:*:*:*:*:*",
284264          "purl": "pkg:apk/alpine/tiff@4.4.0-r1?arch=x86_64\u0026distro=alpine-3.17.2",
284265          "swid": {
284266            "attachment": {}
284267          },
284268          "pedigree": {},
284269          "externalReferences": [
284270            {
284271              "url": "https://gitlab.com/libtiff/libtiff",
284272              "type": "distribution"
284273            }
284274          ],
284275          "evidence": {},
284276          "signature": {
284277            "signature": {
284278              "publicKey": {}
284279            }
284280          },
284281          "modelCard": {
284282            "modelParameters": {
284283              "approach": {}
284284            },
284285            "quantitativeAnalysis": {
284286              "graphics": {}
284287            },
284288            "considerations": {}
284289          }
284290        },
284291        {
284292          "type": "library",
284293          "bom-ref": "pkg:apk/alpine/tiff@4.4.0-r3?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=fb358c813513b33d",
284294          "supplier": {},
284295          "publisher": "Michael Mason \u003cms13sp@gmail.com\u003e",
284296          "name": "tiff",
284297          "version": "4.4.0-r3",
284298          "description": "Provides support for the Tag Image File Format or TIFF",
284299          "licenses": [
284300            {
284301              "license": {
284302                "id": "libtiff"
284303              }
284304            }
284305          ],
284306          "cpe": "cpe:2.3:a:libtiff:libtiff:4.4.0-r3:*:*:*:*:*:*:*",
284307          "purl": "pkg:apk/alpine/tiff@4.4.0-r3?arch=x86_64\u0026distro=alpine-3.17.2",
284308          "swid": {
284309            "attachment": {}
284310          },
284311          "pedigree": {},
284312          "externalReferences": [
284313            {
284314              "url": "https://gitlab.com/libtiff/libtiff",
284315              "type": "distribution"
284316            }
284317          ],
284318          "evidence": {},
284319          "signature": {
284320            "signature": {
284321              "publicKey": {}
284322            }
284323          },
284324          "modelCard": {
284325            "modelParameters": {
284326              "approach": {}
284327            },
284328            "quantitativeAnalysis": {
284329              "graphics": {}
284330            },
284331            "considerations": {}
284332          }
284333        },
284334        {
284335          "type": "library",
284336          "bom-ref": "pkg:apk/alpine/xz-libs@5.2.9-r0?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.17.2\u0026package-id=e48961a4a3ae9884",
284337          "supplier": {},
284338          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
284339          "name": "xz-libs",
284340          "version": "5.2.9-r0",
284341          "description": "Library and CLI tools for XZ and LZMA compressed files (libraries)",
284342          "licenses": [
284343            {
284344              "license": {
284345                "id": "GPL-2.0-or-later"
284346              }
284347            },
284348            {
284349              "license": {
284350                "name": "AND"
284351              }
284352            },
284353            {
284354              "license": {
284355                "name": "Public-Domain"
284356              }
284357            },
284358            {
284359              "license": {
284360                "name": "AND"
284361              }
284362            },
284363            {
284364              "license": {
284365                "id": "LGPL-2.1-or-later"
284366              }
284367            }
284368          ],
284369          "cpe": "cpe:2.3:a:xz-libs:xz-libs:5.2.9-r0:*:*:*:*:*:*:*",
284370          "purl": "pkg:apk/alpine/xz-libs@5.2.9-r0?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.17.2",
284371          "swid": {
284372            "attachment": {}
284373          },
284374          "pedigree": {},
284375          "externalReferences": [
284376            {
284377              "url": "https://tukaani.org/xz",
284378              "type": "distribution"
284379            }
284380          ],
284381          "evidence": {},
284382          "signature": {
284383            "signature": {
284384              "publicKey": {}
284385            }
284386          },
284387          "modelCard": {
284388            "modelParameters": {
284389              "approach": {}
284390            },
284391            "quantitativeAnalysis": {
284392              "graphics": {}
284393            },
284394            "considerations": {}
284395          }
284396        },
284397        {
284398          "type": "library",
284399          "bom-ref": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.2\u0026package-id=94014313cfcd2b71",
284400          "supplier": {},
284401          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
284402          "name": "zlib",
284403          "version": "1.2.13-r0",
284404          "description": "A compression/decompression Library",
284405          "licenses": [
284406            {
284407              "license": {
284408                "id": "Zlib"
284409              }
284410            }
284411          ],
284412          "cpe": "cpe:2.3:a:zlib:zlib:1.2.13-r0:*:*:*:*:*:*:*",
284413          "purl": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.2",
284414          "swid": {
284415            "attachment": {}
284416          },
284417          "pedigree": {},
284418          "externalReferences": [
284419            {
284420              "url": "https://zlib.net/",
284421              "type": "distribution"
284422            }
284423          ],
284424          "evidence": {},
284425          "signature": {
284426            "signature": {
284427              "publicKey": {}
284428            }
284429          },
284430          "modelCard": {
284431            "modelParameters": {
284432              "approach": {}
284433            },
284434            "quantitativeAnalysis": {
284435              "graphics": {}
284436            },
284437            "considerations": {}
284438          }
284439        },
284440        {
284441          "type": "library",
284442          "bom-ref": "pkg:apk/alpine/zstd-libs@1.5.2-r9?arch=x86_64\u0026upstream=zstd\u0026distro=alpine-3.17.2\u0026package-id=5b84a9f1259e3066",
284443          "supplier": {},
284444          "publisher": "psykose \u003calice@ayaya.dev\u003e",
284445          "name": "zstd-libs",
284446          "version": "1.5.2-r9",
284447          "description": "Zstandard - Fast real-time compression algorithm (libraries)",
284448          "licenses": [
284449            {
284450              "license": {
284451                "id": "BSD-3-Clause"
284452              }
284453            },
284454            {
284455              "license": {
284456                "id": "GPL-2.0-or-later"
284457              }
284458            }
284459          ],
284460          "cpe": "cpe:2.3:a:zstd-libs:zstd-libs:1.5.2-r9:*:*:*:*:*:*:*",
284461          "purl": "pkg:apk/alpine/zstd-libs@1.5.2-r9?arch=x86_64\u0026upstream=zstd\u0026distro=alpine-3.17.2",
284462          "swid": {
284463            "attachment": {}
284464          },
284465          "pedigree": {},
284466          "externalReferences": [
284467            {
284468              "url": "https://www.zstd.net/",
284469              "type": "distribution"
284470            }
284471          ],
284472          "evidence": {},
284473          "signature": {
284474            "signature": {
284475              "publicKey": {}
284476            }
284477          },
284478          "modelCard": {
284479            "modelParameters": {
284480              "approach": {}
284481            },
284482            "quantitativeAnalysis": {
284483              "graphics": {}
284484            },
284485            "considerations": {}
284486          }
284487        },
284488        {
284489          "type": "library",
284490          "bom-ref": "pkg:apk/alpine/zstd-libs@1.5.5-r0?arch=x86_64\u0026upstream=zstd\u0026distro=alpine-3.17.2\u0026package-id=63fdcc1e9d0cee84",
284491          "supplier": {},
284492          "publisher": "psykose \u003calice@ayaya.dev\u003e",
284493          "name": "zstd-libs",
284494          "version": "1.5.5-r0",
284495          "description": "Zstandard - Fast real-time compression algorithm (libraries)",
284496          "licenses": [
284497            {
284498              "license": {
284499                "id": "BSD-3-Clause"
284500              }
284501            },
284502            {
284503              "license": {
284504                "id": "GPL-2.0-or-later"
284505              }
284506            }
284507          ],
284508          "cpe": "cpe:2.3:a:zstd-libs:zstd-libs:1.5.5-r0:*:*:*:*:*:*:*",
284509          "purl": "pkg:apk/alpine/zstd-libs@1.5.5-r0?arch=x86_64\u0026upstream=zstd\u0026distro=alpine-3.17.2",
284510          "swid": {
284511            "attachment": {}
284512          },
284513          "pedigree": {},
284514          "externalReferences": [
284515            {
284516              "url": "https://www.zstd.net/",
284517              "type": "distribution"
284518            }
284519          ],
284520          "evidence": {},
284521          "signature": {
284522            "signature": {
284523              "publicKey": {}
284524            }
284525          },
284526          "modelCard": {
284527            "modelParameters": {
284528              "approach": {}
284529            },
284530            "quantitativeAnalysis": {
284531              "graphics": {}
284532            },
284533            "considerations": {}
284534          }
284535        },
284536        {
284537          "type": "operating-system",
284538          "supplier": {},
284539          "name": "alpine",
284540          "version": "3.17.2",
284541          "description": "Alpine Linux v3.17",
284542          "swid": {
284543            "tagId": "alpine",
284544            "name": "alpine",
284545            "version": "3.17.2",
284546            "attachment": {}
284547          },
284548          "pedigree": {},
284549          "externalReferences": [
284550            {
284551              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
284552              "type": "issue-tracker"
284553            },
284554            {
284555              "url": "https://alpinelinux.org/",
284556              "type": "website"
284557            }
284558          ],
284559          "evidence": {},
284560          "signature": {
284561            "signature": {
284562              "publicKey": {}
284563            }
284564          },
284565          "modelCard": {
284566            "modelParameters": {
284567              "approach": {}
284568            },
284569            "quantitativeAnalysis": {
284570              "graphics": {}
284571            },
284572            "considerations": {}
284573          }
284574        },
284575        {
284576          "type": "library",
284577          "bom-ref": "pkg:apk/alpine/.python-rundeps@20230330.012037?arch=noarch\u0026distro=alpine-3.16.5\u0026package-id=f4d111cafc76519b",
284578          "supplier": {},
284579          "name": ".python-rundeps",
284580          "version": "20230330.012037",
284581          "description": "virtual meta package",
284582          "licenses": [
284583            {}
284584          ],
284585          "cpe": "cpe:2.3:a:.python-rundeps:.python-rundeps:20230330.012037:*:*:*:*:*:*:*",
284586          "purl": "pkg:apk/alpine/.python-rundeps@20230330.012037?arch=noarch\u0026distro=alpine-3.16.5",
284587          "swid": {
284588            "attachment": {}
284589          },
284590          "pedigree": {},
284591          "evidence": {},
284592          "signature": {
284593            "signature": {
284594              "publicKey": {}
284595            }
284596          },
284597          "modelCard": {
284598            "modelParameters": {
284599              "approach": {}
284600            },
284601            "quantitativeAnalysis": {
284602              "graphics": {}
284603            },
284604            "considerations": {}
284605          }
284606        },
284607        {
284608          "type": "library",
284609          "bom-ref": "pkg:pypi/click@7.0?package-id=3a58fdeeff83cd9f",
284610          "supplier": {},
284611          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
284612          "name": "Click",
284613          "version": "7.0",
284614          "licenses": [
284615            {
284616              "license": {
284617                "name": "BSD"
284618              }
284619            }
284620          ],
284621          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Click:7.0:*:*:*:*:*:*:*",
284622          "purl": "pkg:pypi/Click@7.0",
284623          "swid": {
284624            "attachment": {}
284625          },
284626          "pedigree": {},
284627          "evidence": {},
284628          "signature": {
284629            "signature": {
284630              "publicKey": {}
284631            }
284632          },
284633          "modelCard": {
284634            "modelParameters": {
284635              "approach": {}
284636            },
284637            "quantitativeAnalysis": {
284638              "graphics": {}
284639            },
284640            "considerations": {}
284641          }
284642        },
284643        {
284644          "type": "library",
284645          "bom-ref": "pkg:pypi/flask@1.0.3?package-id=c490aa95964872bc",
284646          "supplier": {},
284647          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
284648          "name": "Flask",
284649          "version": "1.0.3",
284650          "licenses": [
284651            {
284652              "license": {
284653                "name": "BSD"
284654              }
284655            }
284656          ],
284657          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Flask:1.0.3:*:*:*:*:*:*:*",
284658          "purl": "pkg:pypi/Flask@1.0.3",
284659          "swid": {
284660            "attachment": {}
284661          },
284662          "pedigree": {},
284663          "evidence": {},
284664          "signature": {
284665            "signature": {
284666              "publicKey": {}
284667            }
284668          },
284669          "modelCard": {
284670            "modelParameters": {
284671              "approach": {}
284672            },
284673            "quantitativeAnalysis": {
284674              "graphics": {}
284675            },
284676            "considerations": {}
284677          }
284678        },
284679        {
284680          "type": "library",
284681          "bom-ref": "pkg:pypi/flask-restful@0.3.7?package-id=36f0193ab85cdce",
284682          "supplier": {},
284683          "author": "Twilio API Team \u003chelp@twilio.com\u003e",
284684          "name": "Flask-RESTful",
284685          "version": "0.3.7",
284686          "licenses": [
284687            {
284688              "license": {
284689                "name": "BSD"
284690              }
284691            }
284692          ],
284693          "cpe": "cpe:2.3:a:twilio_api_team_project:python-Flask-RESTful:0.3.7:*:*:*:*:*:*:*",
284694          "purl": "pkg:pypi/Flask-RESTful@0.3.7",
284695          "swid": {
284696            "attachment": {}
284697          },
284698          "pedigree": {},
284699          "evidence": {},
284700          "signature": {
284701            "signature": {
284702              "publicKey": {}
284703            }
284704          },
284705          "modelCard": {
284706            "modelParameters": {
284707              "approach": {}
284708            },
284709            "quantitativeAnalysis": {
284710              "graphics": {}
284711            },
284712            "considerations": {}
284713          }
284714        },
284715        {
284716          "type": "library",
284717          "bom-ref": "pkg:pypi/jinja2@2.10.1?package-id=17f1f8c145b55f04",
284718          "supplier": {},
284719          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
284720          "name": "Jinja2",
284721          "version": "2.10.1",
284722          "licenses": [
284723            {
284724              "license": {
284725                "name": "BSD"
284726              }
284727            }
284728          ],
284729          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Jinja2:2.10.1:*:*:*:*:*:*:*",
284730          "purl": "pkg:pypi/Jinja2@2.10.1",
284731          "swid": {
284732            "attachment": {}
284733          },
284734          "pedigree": {},
284735          "evidence": {},
284736          "signature": {
284737            "signature": {
284738              "publicKey": {}
284739            }
284740          },
284741          "modelCard": {
284742            "modelParameters": {
284743              "approach": {}
284744            },
284745            "quantitativeAnalysis": {
284746              "graphics": {}
284747            },
284748            "considerations": {}
284749          }
284750        },
284751        {
284752          "type": "library",
284753          "bom-ref": "pkg:pypi/markupsafe@1.1.1?package-id=ab14f0ee3d649e1c",
284754          "supplier": {},
284755          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
284756          "name": "MarkupSafe",
284757          "version": "1.1.1",
284758          "licenses": [
284759            {
284760              "license": {
284761                "id": "BSD-3-Clause"
284762              }
284763            }
284764          ],
284765          "cpe": "cpe:2.3:a:armin_ronacher_project:python-MarkupSafe:1.1.1:*:*:*:*:*:*:*",
284766          "purl": "pkg:pypi/MarkupSafe@1.1.1",
284767          "swid": {
284768            "attachment": {}
284769          },
284770          "pedigree": {},
284771          "evidence": {},
284772          "signature": {
284773            "signature": {
284774              "publicKey": {}
284775            }
284776          },
284777          "modelCard": {
284778            "modelParameters": {
284779              "approach": {}
284780            },
284781            "quantitativeAnalysis": {
284782              "graphics": {}
284783            },
284784            "considerations": {}
284785          }
284786        },
284787        {
284788          "type": "library",
284789          "bom-ref": "pkg:pypi/pynacl@1.3.0?package-id=2a6bf39644edbb42",
284790          "supplier": {},
284791          "author": "The PyNaCl developers \u003ccryptography-dev@python.org\u003e",
284792          "name": "PyNaCl",
284793          "version": "1.3.0",
284794          "licenses": [
284795            {
284796              "license": {
284797                "name": "Apache License 2.0"
284798              }
284799            }
284800          ],
284801          "cpe": "cpe:2.3:a:pynacl_developers_project:python-PyNaCl:1.3.0:*:*:*:*:*:*:*",
284802          "purl": "pkg:pypi/PyNaCl@1.3.0",
284803          "swid": {
284804            "attachment": {}
284805          },
284806          "pedigree": {},
284807          "evidence": {},
284808          "signature": {
284809            "signature": {
284810              "publicKey": {}
284811            }
284812          },
284813          "modelCard": {
284814            "modelParameters": {
284815              "approach": {}
284816            },
284817            "quantitativeAnalysis": {
284818              "graphics": {}
284819            },
284820            "considerations": {}
284821          }
284822        },
284823        {
284824          "type": "library",
284825          "bom-ref": "pkg:pypi/pyyaml@5.1.1?package-id=f01fe7b1c18abc40",
284826          "supplier": {},
284827          "author": "Kirill Simonov \u003cxi@resolvent.net\u003e",
284828          "name": "PyYAML",
284829          "version": "5.1.1",
284830          "licenses": [
284831            {
284832              "license": {
284833                "id": "MIT"
284834              }
284835            }
284836          ],
284837          "cpe": "cpe:2.3:a:kirill_simonov_project:python-PyYAML:5.1.1:*:*:*:*:*:*:*",
284838          "purl": "pkg:pypi/PyYAML@5.1.1",
284839          "swid": {
284840            "attachment": {}
284841          },
284842          "pedigree": {},
284843          "evidence": {},
284844          "signature": {
284845            "signature": {
284846              "publicKey": {}
284847            }
284848          },
284849          "modelCard": {
284850            "modelParameters": {
284851              "approach": {}
284852            },
284853            "quantitativeAnalysis": {
284854              "graphics": {}
284855            },
284856            "considerations": {}
284857          }
284858        },
284859        {
284860          "type": "library",
284861          "bom-ref": "pkg:pypi/werkzeug@2.1.2?package-id=c996e87894c79078",
284862          "supplier": {},
284863          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
284864          "name": "Werkzeug",
284865          "version": "2.1.2",
284866          "licenses": [
284867            {
284868              "license": {
284869                "id": "BSD-3-Clause"
284870              }
284871            }
284872          ],
284873          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Werkzeug:2.1.2:*:*:*:*:*:*:*",
284874          "purl": "pkg:pypi/Werkzeug@2.1.2",
284875          "swid": {
284876            "attachment": {}
284877          },
284878          "pedigree": {},
284879          "evidence": {},
284880          "signature": {
284881            "signature": {
284882              "publicKey": {}
284883            }
284884          },
284885          "modelCard": {
284886            "modelParameters": {
284887              "approach": {}
284888            },
284889            "quantitativeAnalysis": {
284890              "graphics": {}
284891            },
284892            "considerations": {}
284893          }
284894        },
284895        {
284896          "type": "library",
284897          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=61eac5ce8105d394",
284898          "supplier": {},
284899          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
284900          "name": "alpine-baselayout",
284901          "version": "3.2.0-r23",
284902          "description": "Alpine base dir structure and init scripts",
284903          "licenses": [
284904            {
284905              "license": {
284906                "id": "GPL-2.0-only"
284907              }
284908            }
284909          ],
284910          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r23:*:*:*:*:*:*:*",
284911          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5",
284912          "swid": {
284913            "attachment": {}
284914          },
284915          "pedigree": {},
284916          "externalReferences": [
284917            {
284918              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
284919              "type": "distribution"
284920            }
284921          ],
284922          "evidence": {},
284923          "signature": {
284924            "signature": {
284925              "publicKey": {}
284926            }
284927          },
284928          "modelCard": {
284929            "modelParameters": {
284930              "approach": {}
284931            },
284932            "quantitativeAnalysis": {
284933              "graphics": {}
284934            },
284935            "considerations": {}
284936          }
284937        },
284938        {
284939          "type": "library",
284940          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5\u0026package-id=e8c6fcc3a282ed4f",
284941          "supplier": {},
284942          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
284943          "name": "alpine-baselayout-data",
284944          "version": "3.2.0-r23",
284945          "description": "Alpine base dir structure and init scripts",
284946          "licenses": [
284947            {
284948              "license": {
284949                "id": "GPL-2.0-only"
284950              }
284951            }
284952          ],
284953          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.2.0-r23:*:*:*:*:*:*:*",
284954          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5",
284955          "swid": {
284956            "attachment": {}
284957          },
284958          "pedigree": {},
284959          "externalReferences": [
284960            {
284961              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
284962              "type": "distribution"
284963            }
284964          ],
284965          "evidence": {},
284966          "signature": {
284967            "signature": {
284968              "publicKey": {}
284969            }
284970          },
284971          "modelCard": {
284972            "modelParameters": {
284973              "approach": {}
284974            },
284975            "quantitativeAnalysis": {
284976              "graphics": {}
284977            },
284978            "considerations": {}
284979          }
284980        },
284981        {
284982          "type": "library",
284983          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=82d183eb300978cc",
284984          "supplier": {},
284985          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
284986          "name": "alpine-keys",
284987          "version": "2.4-r1",
284988          "description": "Public keys for Alpine Linux packages",
284989          "licenses": [
284990            {
284991              "license": {
284992                "id": "MIT"
284993              }
284994            }
284995          ],
284996          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
284997          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5",
284998          "swid": {
284999            "attachment": {}
285000          },
285001          "pedigree": {},
285002          "externalReferences": [
285003            {
285004              "url": "https://alpinelinux.org",
285005              "type": "distribution"
285006            }
285007          ],
285008          "evidence": {},
285009          "signature": {
285010            "signature": {
285011              "publicKey": {}
285012            }
285013          },
285014          "modelCard": {
285015            "modelParameters": {
285016              "approach": {}
285017            },
285018            "quantitativeAnalysis": {
285019              "graphics": {}
285020            },
285021            "considerations": {}
285022          }
285023        },
285024        {
285025          "type": "library",
285026          "bom-ref": "pkg:pypi/aniso8601@7.0.0?package-id=6c5ef38e1512239c",
285027          "supplier": {},
285028          "author": "Brandon Nielsen \u003cnielsenb@jetfuse.net\u003e",
285029          "name": "aniso8601",
285030          "version": "7.0.0",
285031          "licenses": [
285032            {
285033              "license": {
285034                "name": "UNKNOWN"
285035              }
285036            }
285037          ],
285038          "cpe": "cpe:2.3:a:brandon_nielsen_project:python-aniso8601:7.0.0:*:*:*:*:*:*:*",
285039          "purl": "pkg:pypi/aniso8601@7.0.0",
285040          "swid": {
285041            "attachment": {}
285042          },
285043          "pedigree": {},
285044          "evidence": {},
285045          "signature": {
285046            "signature": {
285047              "publicKey": {}
285048            }
285049          },
285050          "modelCard": {
285051            "modelParameters": {
285052              "approach": {}
285053            },
285054            "quantitativeAnalysis": {
285055              "graphics": {}
285056            },
285057            "considerations": {}
285058          }
285059        },
285060        {
285061          "type": "library",
285062          "bom-ref": "pkg:pypi/ansible@2.10.5?package-id=91615183194d623c",
285063          "supplier": {},
285064          "author": "Ansible, Inc. \u003cinfo@ansible.com\u003e",
285065          "name": "ansible",
285066          "version": "2.10.5",
285067          "licenses": [
285068            {
285069              "license": {
285070                "name": "GPLv3+"
285071              }
285072            }
285073          ],
285074          "cpe": "cpe:2.3:a:ansible\\,_inc__project:python-ansible:2.10.5:*:*:*:*:*:*:*",
285075          "purl": "pkg:pypi/ansible@2.10.5",
285076          "swid": {
285077            "attachment": {}
285078          },
285079          "pedigree": {},
285080          "evidence": {},
285081          "signature": {
285082            "signature": {
285083              "publicKey": {}
285084            }
285085          },
285086          "modelCard": {
285087            "modelParameters": {
285088              "approach": {}
285089            },
285090            "quantitativeAnalysis": {
285091              "graphics": {}
285092            },
285093            "considerations": {}
285094          }
285095        },
285096        {
285097          "type": "library",
285098          "bom-ref": "pkg:pypi/ansible-base@2.10.17?package-id=f42670f5f93216c4",
285099          "supplier": {},
285100          "author": "Ansible, Inc. \u003cinfo@ansible.com\u003e",
285101          "name": "ansible-base",
285102          "version": "2.10.17",
285103          "licenses": [
285104            {
285105              "license": {
285106                "name": "GPLv3+"
285107              }
285108            }
285109          ],
285110          "cpe": "cpe:2.3:a:ansible\\,_inc__project:python-ansible-base:2.10.17:*:*:*:*:*:*:*",
285111          "purl": "pkg:pypi/ansible-base@2.10.17",
285112          "swid": {
285113            "attachment": {}
285114          },
285115          "pedigree": {},
285116          "evidence": {},
285117          "signature": {
285118            "signature": {
285119              "publicKey": {}
285120            }
285121          },
285122          "modelCard": {
285123            "modelParameters": {
285124              "approach": {}
285125            },
285126            "quantitativeAnalysis": {
285127              "graphics": {}
285128            },
285129            "considerations": {}
285130          }
285131        },
285132        {
285133          "type": "library",
285134          "bom-ref": "pkg:pypi/ansible-runner@1.4.6?package-id=475f032d9bf23eb9",
285135          "supplier": {},
285136          "author": "Red Hat Ansible",
285137          "name": "ansible-runner",
285138          "version": "1.4.6",
285139          "licenses": [
285140            {
285141              "license": {
285142                "name": "Apache"
285143              }
285144            }
285145          ],
285146          "cpe": "cpe:2.3:a:red_hat_ansible_project:python-ansible-runner:1.4.6:*:*:*:*:*:*:*",
285147          "purl": "pkg:pypi/ansible-runner@1.4.6",
285148          "swid": {
285149            "attachment": {}
285150          },
285151          "pedigree": {},
285152          "evidence": {},
285153          "signature": {
285154            "signature": {
285155              "publicKey": {}
285156            }
285157          },
285158          "modelCard": {
285159            "modelParameters": {
285160              "approach": {}
285161            },
285162            "quantitativeAnalysis": {
285163              "graphics": {}
285164            },
285165            "considerations": {}
285166          }
285167        },
285168        {
285169          "type": "library",
285170          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=42d502b764a37310",
285171          "supplier": {},
285172          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
285173          "name": "apk-tools",
285174          "version": "2.12.9-r3",
285175          "description": "Alpine Package Keeper - package manager for alpine",
285176          "licenses": [
285177            {
285178              "license": {
285179                "id": "GPL-2.0-only"
285180              }
285181            }
285182          ],
285183          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.9-r3:*:*:*:*:*:*:*",
285184          "purl": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5",
285185          "swid": {
285186            "attachment": {}
285187          },
285188          "pedigree": {},
285189          "externalReferences": [
285190            {
285191              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
285192              "type": "distribution"
285193            }
285194          ],
285195          "evidence": {},
285196          "signature": {
285197            "signature": {
285198              "publicKey": {}
285199            }
285200          },
285201          "modelCard": {
285202            "modelParameters": {
285203              "approach": {}
285204            },
285205            "quantitativeAnalysis": {
285206              "graphics": {}
285207            },
285208            "considerations": {}
285209          }
285210        },
285211        {
285212          "type": "library",
285213          "bom-ref": "pkg:pypi/appdirs@1.4.4?package-id=cb1ac44a9663d17e",
285214          "supplier": {},
285215          "author": "Jeff Rouse \u003cjr@its.to\u003e",
285216          "name": "appdirs",
285217          "version": "1.4.4",
285218          "licenses": [
285219            {
285220              "license": {
285221                "id": "MIT"
285222              }
285223            }
285224          ],
285225          "cpe": "cpe:2.3:a:jeff_rouse_project:python-appdirs:1.4.4:*:*:*:*:*:*:*",
285226          "purl": "pkg:pypi/appdirs@1.4.4",
285227          "swid": {
285228            "attachment": {}
285229          },
285230          "pedigree": {},
285231          "evidence": {},
285232          "signature": {
285233            "signature": {
285234              "publicKey": {}
285235            }
285236          },
285237          "modelCard": {
285238            "modelParameters": {
285239              "approach": {}
285240            },
285241            "quantitativeAnalysis": {
285242              "graphics": {}
285243            },
285244            "considerations": {}
285245          }
285246        },
285247        {
285248          "type": "library",
285249          "bom-ref": "pkg:pypi/asn1crypto@0.24.0?package-id=42c09b43cf6cc05d",
285250          "supplier": {},
285251          "author": "wbond \u003cwill@wbond.net\u003e",
285252          "name": "asn1crypto",
285253          "version": "0.24.0",
285254          "licenses": [
285255            {
285256              "license": {
285257                "id": "MIT"
285258              }
285259            }
285260          ],
285261          "cpe": "cpe:2.3:a:python-asn1crypto:python-asn1crypto:0.24.0:*:*:*:*:*:*:*",
285262          "purl": "pkg:pypi/asn1crypto@0.24.0",
285263          "swid": {
285264            "attachment": {}
285265          },
285266          "pedigree": {},
285267          "evidence": {},
285268          "signature": {
285269            "signature": {
285270              "publicKey": {}
285271            }
285272          },
285273          "modelCard": {
285274            "modelParameters": {
285275              "approach": {}
285276            },
285277            "quantitativeAnalysis": {
285278              "graphics": {}
285279            },
285280            "considerations": {}
285281          }
285282        },
285283        {
285284          "type": "library",
285285          "bom-ref": "pkg:pypi/bcrypt@3.1.7?package-id=3abd7c44943769c3",
285286          "supplier": {},
285287          "author": "The Python Cryptographic Authority developers \u003ccryptography-dev@python.org\u003e",
285288          "name": "bcrypt",
285289          "version": "3.1.7",
285290          "licenses": [
285291            {
285292              "license": {
285293                "name": "Apache License, Version 2.0"
285294              }
285295            }
285296          ],
285297          "cpe": "cpe:2.3:a:python_cryptographic_authority_developers_project:python-bcrypt:3.1.7:*:*:*:*:*:*:*",
285298          "purl": "pkg:pypi/bcrypt@3.1.7",
285299          "swid": {
285300            "attachment": {}
285301          },
285302          "pedigree": {},
285303          "evidence": {},
285304          "signature": {
285305            "signature": {
285306              "publicKey": {}
285307            }
285308          },
285309          "modelCard": {
285310            "modelParameters": {
285311              "approach": {}
285312            },
285313            "quantitativeAnalysis": {
285314              "graphics": {}
285315            },
285316            "considerations": {}
285317          }
285318        },
285319        {
285320          "type": "library",
285321          "bom-ref": "pkg:apk/alpine/binutils@2.38-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=2ac308a9a0122ed5",
285322          "supplier": {},
285323          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
285324          "name": "binutils",
285325          "version": "2.38-r3",
285326          "description": "Tools necessary to build programs",
285327          "licenses": [
285328            {
285329              "license": {
285330                "id": "GPL-2.0-only"
285331              }
285332            },
285333            {
285334              "license": {
285335                "id": "GPL-3.0-or-later"
285336              }
285337            },
285338            {
285339              "license": {
285340                "id": "LGPL-2.0-only"
285341              }
285342            },
285343            {
285344              "license": {
285345                "name": "BSD"
285346              }
285347            }
285348          ],
285349          "cpe": "cpe:2.3:a:binutils:binutils:2.38-r3:*:*:*:*:*:*:*",
285350          "purl": "pkg:apk/alpine/binutils@2.38-r3?arch=x86_64\u0026distro=alpine-3.16.5",
285351          "swid": {
285352            "attachment": {}
285353          },
285354          "pedigree": {},
285355          "externalReferences": [
285356            {
285357              "url": "https://www.gnu.org/software/binutils/",
285358              "type": "distribution"
285359            }
285360          ],
285361          "evidence": {},
285362          "signature": {
285363            "signature": {
285364              "publicKey": {}
285365            }
285366          },
285367          "modelCard": {
285368            "modelParameters": {
285369              "approach": {}
285370            },
285371            "quantitativeAnalysis": {
285372              "graphics": {}
285373            },
285374            "considerations": {}
285375          }
285376        },
285377        {
285378          "type": "library",
285379          "bom-ref": "pkg:apk/alpine/build-base@0.5-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=680d5addf26f58dc",
285380          "supplier": {},
285381          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
285382          "name": "build-base",
285383          "version": "0.5-r3",
285384          "description": "Meta package for build base",
285385          "licenses": [
285386            {
285387              "license": {
285388                "id": "MIT"
285389              }
285390            }
285391          ],
285392          "cpe": "cpe:2.3:a:build-base:build-base:0.5-r3:*:*:*:*:*:*:*",
285393          "purl": "pkg:apk/alpine/build-base@0.5-r3?arch=x86_64\u0026distro=alpine-3.16.5",
285394          "swid": {
285395            "attachment": {}
285396          },
285397          "pedigree": {},
285398          "externalReferences": [
285399            {
285400              "url": "http://dev.alpinelinux.org/cgit",
285401              "type": "distribution"
285402            }
285403          ],
285404          "evidence": {},
285405          "signature": {
285406            "signature": {
285407              "publicKey": {}
285408            }
285409          },
285410          "modelCard": {
285411            "modelParameters": {
285412              "approach": {}
285413            },
285414            "quantitativeAnalysis": {
285415              "graphics": {}
285416            },
285417            "considerations": {}
285418          }
285419        },
285420        {
285421          "type": "library",
285422          "bom-ref": "pkg:apk/alpine/build-dependencies@20230412.220958?arch=noarch\u0026distro=alpine-3.16.5\u0026package-id=67aa61f73951db66",
285423          "supplier": {},
285424          "name": "build-dependencies",
285425          "version": "20230412.220958",
285426          "description": "virtual meta package",
285427          "licenses": [
285428            {}
285429          ],
285430          "cpe": "cpe:2.3:a:build-dependencies:build-dependencies:20230412.220958:*:*:*:*:*:*:*",
285431          "purl": "pkg:apk/alpine/build-dependencies@20230412.220958?arch=noarch\u0026distro=alpine-3.16.5",
285432          "swid": {
285433            "attachment": {}
285434          },
285435          "pedigree": {},
285436          "evidence": {},
285437          "signature": {
285438            "signature": {
285439              "publicKey": {}
285440            }
285441          },
285442          "modelCard": {
285443            "modelParameters": {
285444              "approach": {}
285445            },
285446            "quantitativeAnalysis": {
285447              "graphics": {}
285448            },
285449            "considerations": {}
285450          }
285451        },
285452        {
285453          "type": "application",
285454          "bom-ref": "e14718c64f5147f4",
285455          "supplier": {},
285456          "name": "busybox",
285457          "version": "1.35.0",
285458          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
285459          "swid": {
285460            "attachment": {}
285461          },
285462          "pedigree": {},
285463          "evidence": {},
285464          "signature": {
285465            "signature": {
285466              "publicKey": {}
285467            }
285468          },
285469          "modelCard": {
285470            "modelParameters": {
285471              "approach": {}
285472            },
285473            "quantitativeAnalysis": {
285474              "graphics": {}
285475            },
285476            "considerations": {}
285477          }
285478        },
285479        {
285480          "type": "library",
285481          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=4b48ef6f6b983526",
285482          "supplier": {},
285483          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
285484          "name": "busybox",
285485          "version": "1.35.0-r17",
285486          "description": "Size optimized toolbox of many common UNIX utilities",
285487          "licenses": [
285488            {
285489              "license": {
285490                "id": "GPL-2.0-only"
285491              }
285492            }
285493          ],
285494          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r17:*:*:*:*:*:*:*",
285495          "purl": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5",
285496          "swid": {
285497            "attachment": {}
285498          },
285499          "pedigree": {},
285500          "externalReferences": [
285501            {
285502              "url": "https://busybox.net/",
285503              "type": "distribution"
285504            }
285505          ],
285506          "evidence": {},
285507          "signature": {
285508            "signature": {
285509              "publicKey": {}
285510            }
285511          },
285512          "modelCard": {
285513            "modelParameters": {
285514              "approach": {}
285515            },
285516            "quantitativeAnalysis": {
285517              "graphics": {}
285518            },
285519            "considerations": {}
285520          }
285521        },
285522        {
285523          "type": "library",
285524          "bom-ref": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=fbb1924ff870cc71",
285525          "supplier": {},
285526          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
285527          "name": "ca-certificates",
285528          "version": "20220614-r0",
285529          "description": "Common CA certificates PEM files from Mozilla",
285530          "licenses": [
285531            {
285532              "license": {
285533                "id": "MPL-2.0"
285534              }
285535            },
285536            {
285537              "license": {
285538                "name": "AND"
285539              }
285540            },
285541            {
285542              "license": {
285543                "id": "MIT"
285544              }
285545            }
285546          ],
285547          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20220614-r0:*:*:*:*:*:*:*",
285548          "purl": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5",
285549          "swid": {
285550            "attachment": {}
285551          },
285552          "pedigree": {},
285553          "externalReferences": [
285554            {
285555              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
285556              "type": "distribution"
285557            }
285558          ],
285559          "evidence": {},
285560          "signature": {
285561            "signature": {
285562              "publicKey": {}
285563            }
285564          },
285565          "modelCard": {
285566            "modelParameters": {
285567              "approach": {}
285568            },
285569            "quantitativeAnalysis": {
285570              "graphics": {}
285571            },
285572            "considerations": {}
285573          }
285574        },
285575        {
285576          "type": "library",
285577          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5\u0026package-id=30622a1848b22bca",
285578          "supplier": {},
285579          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
285580          "name": "ca-certificates-bundle",
285581          "version": "20220614-r0",
285582          "description": "Pre generated bundle of Mozilla certificates",
285583          "licenses": [
285584            {
285585              "license": {
285586                "id": "MPL-2.0"
285587              }
285588            },
285589            {
285590              "license": {
285591                "name": "AND"
285592              }
285593            },
285594            {
285595              "license": {
285596                "id": "MIT"
285597              }
285598            }
285599          ],
285600          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
285601          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5",
285602          "swid": {
285603            "attachment": {}
285604          },
285605          "pedigree": {},
285606          "externalReferences": [
285607            {
285608              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
285609              "type": "distribution"
285610            }
285611          ],
285612          "evidence": {},
285613          "signature": {
285614            "signature": {
285615              "publicKey": {}
285616            }
285617          },
285618          "modelCard": {
285619            "modelParameters": {
285620              "approach": {}
285621            },
285622            "quantitativeAnalysis": {
285623              "graphics": {}
285624            },
285625            "considerations": {}
285626          }
285627        },
285628        {
285629          "type": "library",
285630          "bom-ref": "pkg:pypi/certifi@2022.12.7?package-id=2842baa8fb4c9e59",
285631          "supplier": {},
285632          "author": "Kenneth Reitz \u003cme@kennethreitz.com\u003e",
285633          "name": "certifi",
285634          "version": "2022.12.7",
285635          "licenses": [
285636            {
285637              "license": {
285638                "id": "MPL-2.0"
285639              }
285640            }
285641          ],
285642          "cpe": "cpe:2.3:a:kenneth_reitz_project:python-certifi:2022.12.7:*:*:*:*:*:*:*",
285643          "purl": "pkg:pypi/certifi@2022.12.7",
285644          "swid": {
285645            "attachment": {}
285646          },
285647          "pedigree": {},
285648          "evidence": {},
285649          "signature": {
285650            "signature": {
285651              "publicKey": {}
285652            }
285653          },
285654          "modelCard": {
285655            "modelParameters": {
285656              "approach": {}
285657            },
285658            "quantitativeAnalysis": {
285659              "graphics": {}
285660            },
285661            "considerations": {}
285662          }
285663        },
285664        {
285665          "type": "library",
285666          "bom-ref": "pkg:pypi/cffi@1.12.3?package-id=705e5de3088777d9",
285667          "supplier": {},
285668          "author": "Armin Rigo, Maciej Fijalkowski \u003cpython-cffi@googlegroups.com\u003e",
285669          "name": "cffi",
285670          "version": "1.12.3",
285671          "licenses": [
285672            {
285673              "license": {
285674                "id": "MIT"
285675              }
285676            }
285677          ],
285678          "cpe": "cpe:2.3:a:armin_rigo\\,_maciej_fijalkowski_project:python-cffi:1.12.3:*:*:*:*:*:*:*",
285679          "purl": "pkg:pypi/cffi@1.12.3",
285680          "swid": {
285681            "attachment": {}
285682          },
285683          "pedigree": {},
285684          "evidence": {},
285685          "signature": {
285686            "signature": {
285687              "publicKey": {}
285688            }
285689          },
285690          "modelCard": {
285691            "modelParameters": {
285692              "approach": {}
285693            },
285694            "quantitativeAnalysis": {
285695              "graphics": {}
285696            },
285697            "considerations": {}
285698          }
285699        },
285700        {
285701          "type": "library",
285702          "bom-ref": "pkg:pypi/cffi@1.15.0?package-id=f72b5cfdb7616b9b",
285703          "supplier": {},
285704          "author": "Armin Rigo, Maciej Fijalkowski \u003cpython-cffi@googlegroups.com\u003e",
285705          "name": "cffi",
285706          "version": "1.15.0",
285707          "licenses": [
285708            {
285709              "license": {
285710                "id": "MIT"
285711              }
285712            }
285713          ],
285714          "cpe": "cpe:2.3:a:armin_rigo\\,_maciej_fijalkowski_project:python-cffi:1.15.0:*:*:*:*:*:*:*",
285715          "purl": "pkg:pypi/cffi@1.15.0",
285716          "swid": {
285717            "attachment": {}
285718          },
285719          "pedigree": {},
285720          "evidence": {},
285721          "signature": {
285722            "signature": {
285723              "publicKey": {}
285724            }
285725          },
285726          "modelCard": {
285727            "modelParameters": {
285728              "approach": {}
285729            },
285730            "quantitativeAnalysis": {
285731              "graphics": {}
285732            },
285733            "considerations": {}
285734          }
285735        },
285736        {
285737          "type": "library",
285738          "bom-ref": "pkg:pypi/charset-normalizer@3.1.0?package-id=bd5220db061862d8",
285739          "supplier": {},
285740          "author": "Ahmed TAHRI \u003cahmed.tahri@cloudnursery.dev\u003e",
285741          "name": "charset-normalizer",
285742          "version": "3.1.0",
285743          "licenses": [
285744            {
285745              "license": {
285746                "id": "MIT"
285747              }
285748            }
285749          ],
285750          "cpe": "cpe:2.3:a:python-charset-normalizer:python-charset-normalizer:3.1.0:*:*:*:*:*:*:*",
285751          "purl": "pkg:pypi/charset-normalizer@3.1.0",
285752          "swid": {
285753            "attachment": {}
285754          },
285755          "pedigree": {},
285756          "evidence": {},
285757          "signature": {
285758            "signature": {
285759              "publicKey": {}
285760            }
285761          },
285762          "modelCard": {
285763            "modelParameters": {
285764              "approach": {}
285765            },
285766            "quantitativeAnalysis": {
285767              "graphics": {}
285768            },
285769            "considerations": {}
285770          }
285771        },
285772        {
285773          "type": "library",
285774          "bom-ref": "pkg:pypi/contextlib2@21.6.0?package-id=33fd175a78c9d13b",
285775          "supplier": {},
285776          "author": "Nick Coghlan \u003cncoghlan@gmail.com\u003e",
285777          "name": "contextlib2",
285778          "version": "21.6.0",
285779          "licenses": [
285780            {
285781              "license": {
285782                "name": "PSF License"
285783              }
285784            }
285785          ],
285786          "cpe": "cpe:2.3:a:nick_coghlan_project:python-contextlib2:21.6.0:*:*:*:*:*:*:*",
285787          "purl": "pkg:pypi/contextlib2@21.6.0",
285788          "swid": {
285789            "attachment": {}
285790          },
285791          "pedigree": {},
285792          "evidence": {},
285793          "signature": {
285794            "signature": {
285795              "publicKey": {}
285796            }
285797          },
285798          "modelCard": {
285799            "modelParameters": {
285800              "approach": {}
285801            },
285802            "quantitativeAnalysis": {
285803              "graphics": {}
285804            },
285805            "considerations": {}
285806          }
285807        },
285808        {
285809          "type": "library",
285810          "bom-ref": "pkg:pypi/cryptography@2.7?package-id=7349ba37dbf17083",
285811          "supplier": {},
285812          "author": "The cryptography developers \u003ccryptography-dev@python.org\u003e",
285813          "name": "cryptography",
285814          "version": "2.7",
285815          "licenses": [
285816            {
285817              "license": {
285818                "name": "BSD or Apache License, Version 2.0"
285819              }
285820            }
285821          ],
285822          "cpe": "cpe:2.3:a:cryptography_developers_project:python-cryptography:2.7:*:*:*:*:*:*:*",
285823          "purl": "pkg:pypi/cryptography@2.7",
285824          "swid": {
285825            "attachment": {}
285826          },
285827          "pedigree": {},
285828          "evidence": {},
285829          "signature": {
285830            "signature": {
285831              "publicKey": {}
285832            }
285833          },
285834          "modelCard": {
285835            "modelParameters": {
285836              "approach": {}
285837            },
285838            "quantitativeAnalysis": {
285839              "graphics": {}
285840            },
285841            "considerations": {}
285842          }
285843        },
285844        {
285845          "type": "library",
285846          "bom-ref": "pkg:pypi/cryptography@3.4.8?package-id=6a15128fa64273e1",
285847          "supplier": {},
285848          "author": "The Python Cryptographic Authority and individual contributors \u003ccryptography-dev@python.org\u003e",
285849          "name": "cryptography",
285850          "version": "3.4.8",
285851          "licenses": [
285852            {
285853              "license": {
285854                "name": "BSD or Apache License, Version 2.0"
285855              }
285856            }
285857          ],
285858          "cpe": "cpe:2.3:a:python_cryptographic_authority_and_individual_contributors_project:python-cryptography:3.4.8:*:*:*:*:*:*:*",
285859          "purl": "pkg:pypi/cryptography@3.4.8",
285860          "swid": {
285861            "attachment": {}
285862          },
285863          "pedigree": {},
285864          "evidence": {},
285865          "signature": {
285866            "signature": {
285867              "publicKey": {}
285868            }
285869          },
285870          "modelCard": {
285871            "modelParameters": {
285872              "approach": {}
285873            },
285874            "quantitativeAnalysis": {
285875              "graphics": {}
285876            },
285877            "considerations": {}
285878          }
285879        },
285880        {
285881          "type": "library",
285882          "bom-ref": "pkg:pypi/docutils@0.15.2?package-id=e5f409c603928af3",
285883          "supplier": {},
285884          "author": "David Goodger \u003cgoodger@python.org\u003e",
285885          "name": "docutils",
285886          "version": "0.15.2",
285887          "licenses": [
285888            {
285889              "license": {
285890                "name": "public domain, Python, 2-Clause BSD, GPL 3 (see COPYING.txt)"
285891              }
285892            }
285893          ],
285894          "cpe": "cpe:2.3:a:david_goodger_project:python-docutils:0.15.2:*:*:*:*:*:*:*",
285895          "purl": "pkg:pypi/docutils@0.15.2",
285896          "swid": {
285897            "attachment": {}
285898          },
285899          "pedigree": {},
285900          "evidence": {},
285901          "signature": {
285902            "signature": {
285903              "publicKey": {}
285904            }
285905          },
285906          "modelCard": {
285907            "modelParameters": {
285908              "approach": {}
285909            },
285910            "quantitativeAnalysis": {
285911              "graphics": {}
285912            },
285913            "considerations": {}
285914          }
285915        },
285916        {
285917          "type": "library",
285918          "bom-ref": "pkg:apk/alpine/expat@2.5.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=473c10d9103a81b0",
285919          "supplier": {},
285920          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
285921          "name": "expat",
285922          "version": "2.5.0-r0",
285923          "description": "XML Parser library written in C",
285924          "licenses": [
285925            {
285926              "license": {
285927                "id": "MIT"
285928              }
285929            }
285930          ],
285931          "cpe": "cpe:2.3:a:expat:expat:2.5.0-r0:*:*:*:*:*:*:*",
285932          "purl": "pkg:apk/alpine/expat@2.5.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
285933          "swid": {
285934            "attachment": {}
285935          },
285936          "pedigree": {},
285937          "externalReferences": [
285938            {
285939              "url": "https://libexpat.github.io/",
285940              "type": "distribution"
285941            }
285942          ],
285943          "evidence": {},
285944          "signature": {
285945            "signature": {
285946              "publicKey": {}
285947            }
285948          },
285949          "modelCard": {
285950            "modelParameters": {
285951              "approach": {}
285952            },
285953            "quantitativeAnalysis": {
285954              "graphics": {}
285955            },
285956            "considerations": {}
285957          }
285958        },
285959        {
285960          "type": "library",
285961          "bom-ref": "pkg:apk/alpine/file@5.41-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=3f0372cf7b07c5e3",
285962          "supplier": {},
285963          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
285964          "name": "file",
285965          "version": "5.41-r0",
285966          "description": "File type identification utility",
285967          "licenses": [
285968            {
285969              "license": {
285970                "id": "BSD-2-Clause"
285971              }
285972            }
285973          ],
285974          "cpe": "cpe:2.3:a:file:file:5.41-r0:*:*:*:*:*:*:*",
285975          "purl": "pkg:apk/alpine/file@5.41-r0?arch=x86_64\u0026distro=alpine-3.16.5",
285976          "swid": {
285977            "attachment": {}
285978          },
285979          "pedigree": {},
285980          "externalReferences": [
285981            {
285982              "url": "https://www.darwinsys.com/file/",
285983              "type": "distribution"
285984            }
285985          ],
285986          "evidence": {},
285987          "signature": {
285988            "signature": {
285989              "publicKey": {}
285990            }
285991          },
285992          "modelCard": {
285993            "modelParameters": {
285994              "approach": {}
285995            },
285996            "quantitativeAnalysis": {
285997              "graphics": {}
285998            },
285999            "considerations": {}
286000          }
286001        },
286002        {
286003          "type": "library",
286004          "bom-ref": "pkg:apk/alpine/fortify-headers@1.1-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=7f54e229047913d6",
286005          "supplier": {},
286006          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
286007          "name": "fortify-headers",
286008          "version": "1.1-r1",
286009          "description": "standalone fortify source implementation",
286010          "licenses": [
286011            {
286012              "license": {
286013                "name": "BSD-0"
286014              }
286015            }
286016          ],
286017          "cpe": "cpe:2.3:a:fortify-headers:fortify-headers:1.1-r1:*:*:*:*:*:*:*",
286018          "purl": "pkg:apk/alpine/fortify-headers@1.1-r1?arch=x86_64\u0026distro=alpine-3.16.5",
286019          "swid": {
286020            "attachment": {}
286021          },
286022          "pedigree": {},
286023          "externalReferences": [
286024            {
286025              "url": "http://git.2f30.org/fortify-headers/",
286026              "type": "distribution"
286027            }
286028          ],
286029          "evidence": {},
286030          "signature": {
286031            "signature": {
286032              "publicKey": {}
286033            }
286034          },
286035          "modelCard": {
286036            "modelParameters": {
286037              "approach": {}
286038            },
286039            "quantitativeAnalysis": {
286040              "graphics": {}
286041            },
286042            "considerations": {}
286043          }
286044        },
286045        {
286046          "type": "library",
286047          "bom-ref": "pkg:pypi/future@0.18.3?package-id=4d495d06d1d5bacd",
286048          "supplier": {},
286049          "author": "Ed Schofield \u003ced@pythoncharmers.com\u003e",
286050          "name": "future",
286051          "version": "0.18.3",
286052          "licenses": [
286053            {
286054              "license": {
286055                "id": "MIT"
286056              }
286057            }
286058          ],
286059          "cpe": "cpe:2.3:a:ed_schofield_project:python-future:0.18.3:*:*:*:*:*:*:*",
286060          "purl": "pkg:pypi/future@0.18.3",
286061          "swid": {
286062            "attachment": {}
286063          },
286064          "pedigree": {},
286065          "evidence": {},
286066          "signature": {
286067            "signature": {
286068              "publicKey": {}
286069            }
286070          },
286071          "modelCard": {
286072            "modelParameters": {
286073              "approach": {}
286074            },
286075            "quantitativeAnalysis": {
286076              "graphics": {}
286077            },
286078            "considerations": {}
286079          }
286080        },
286081        {
286082          "type": "library",
286083          "bom-ref": "pkg:apk/alpine/g++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=eea03beb8fdff2d5",
286084          "supplier": {},
286085          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
286086          "name": "g++",
286087          "version": "11.2.1_git20220219-r2",
286088          "description": "GNU C++ standard library and compiler",
286089          "licenses": [
286090            {
286091              "license": {
286092                "id": "GPL-2.0-or-later"
286093              }
286094            },
286095            {
286096              "license": {
286097                "id": "LGPL-2.1-or-later"
286098              }
286099            }
286100          ],
286101          "cpe": "cpe:2.3:a:g\\+\\+:g\\+\\+:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
286102          "purl": "pkg:apk/alpine/g++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
286103          "swid": {
286104            "attachment": {}
286105          },
286106          "pedigree": {},
286107          "externalReferences": [
286108            {
286109              "url": "https://gcc.gnu.org",
286110              "type": "distribution"
286111            }
286112          ],
286113          "evidence": {},
286114          "signature": {
286115            "signature": {
286116              "publicKey": {}
286117            }
286118          },
286119          "modelCard": {
286120            "modelParameters": {
286121              "approach": {}
286122            },
286123            "quantitativeAnalysis": {
286124              "graphics": {}
286125            },
286126            "considerations": {}
286127          }
286128        },
286129        {
286130          "type": "library",
286131          "bom-ref": "pkg:apk/alpine/gcc@11.2.1_git20220219-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=d036a3d91251717e",
286132          "supplier": {},
286133          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
286134          "name": "gcc",
286135          "version": "11.2.1_git20220219-r2",
286136          "description": "The GNU Compiler Collection",
286137          "licenses": [
286138            {
286139              "license": {
286140                "id": "GPL-2.0-or-later"
286141              }
286142            },
286143            {
286144              "license": {
286145                "id": "LGPL-2.1-or-later"
286146              }
286147            }
286148          ],
286149          "cpe": "cpe:2.3:a:gcc:gcc:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
286150          "purl": "pkg:apk/alpine/gcc@11.2.1_git20220219-r2?arch=x86_64\u0026distro=alpine-3.16.5",
286151          "swid": {
286152            "attachment": {}
286153          },
286154          "pedigree": {},
286155          "externalReferences": [
286156            {
286157              "url": "https://gcc.gnu.org",
286158              "type": "distribution"
286159            }
286160          ],
286161          "evidence": {},
286162          "signature": {
286163            "signature": {
286164              "publicKey": {}
286165            }
286166          },
286167          "modelCard": {
286168            "modelParameters": {
286169              "approach": {}
286170            },
286171            "quantitativeAnalysis": {
286172              "graphics": {}
286173            },
286174            "considerations": {}
286175          }
286176        },
286177        {
286178          "type": "library",
286179          "bom-ref": "pkg:apk/alpine/gdbm@1.23-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=5a60c1f034fa6943",
286180          "supplier": {},
286181          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
286182          "name": "gdbm",
286183          "version": "1.23-r0",
286184          "description": "GNU dbm is a set of database routines that use extensible hashing",
286185          "licenses": [
286186            {
286187              "license": {
286188                "id": "GPL-3.0-or-later"
286189              }
286190            }
286191          ],
286192          "cpe": "cpe:2.3:a:gdbm:gdbm:1.23-r0:*:*:*:*:*:*:*",
286193          "purl": "pkg:apk/alpine/gdbm@1.23-r0?arch=x86_64\u0026distro=alpine-3.16.5",
286194          "swid": {
286195            "attachment": {}
286196          },
286197          "pedigree": {},
286198          "externalReferences": [
286199            {
286200              "url": "https://www.gnu.org/software/gdbm/",
286201              "type": "distribution"
286202            }
286203          ],
286204          "evidence": {},
286205          "signature": {
286206            "signature": {
286207              "publicKey": {}
286208            }
286209          },
286210          "modelCard": {
286211            "modelParameters": {
286212              "approach": {}
286213            },
286214            "quantitativeAnalysis": {
286215              "graphics": {}
286216            },
286217            "considerations": {}
286218          }
286219        },
286220        {
286221          "type": "library",
286222          "bom-ref": "pkg:pypi/gevent@1.4.0?package-id=feb0a63c7d504da1",
286223          "supplier": {},
286224          "author": "Denis Bilenko \u003cdenis.bilenko@gmail.com\u003e",
286225          "name": "gevent",
286226          "version": "1.4.0",
286227          "licenses": [
286228            {
286229              "license": {
286230                "id": "MIT"
286231              }
286232            }
286233          ],
286234          "cpe": "cpe:2.3:a:denis_bilenko_project:python-gevent:1.4.0:*:*:*:*:*:*:*",
286235          "purl": "pkg:pypi/gevent@1.4.0",
286236          "swid": {
286237            "attachment": {}
286238          },
286239          "pedigree": {},
286240          "evidence": {},
286241          "signature": {
286242            "signature": {
286243              "publicKey": {}
286244            }
286245          },
286246          "modelCard": {
286247            "modelParameters": {
286248              "approach": {}
286249            },
286250            "quantitativeAnalysis": {
286251              "graphics": {}
286252            },
286253            "considerations": {}
286254          }
286255        },
286256        {
286257          "type": "library",
286258          "bom-ref": "pkg:apk/alpine/gmp@6.2.1-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=f6304e3cf143d3ea",
286259          "supplier": {},
286260          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
286261          "name": "gmp",
286262          "version": "6.2.1-r2",
286263          "description": "free library for arbitrary precision arithmetic",
286264          "licenses": [
286265            {
286266              "license": {
286267                "id": "LGPL-3.0-or-later"
286268              }
286269            },
286270            {
286271              "license": {
286272                "name": "OR"
286273              }
286274            },
286275            {
286276              "license": {
286277                "id": "GPL-2.0-or-later"
286278              }
286279            }
286280          ],
286281          "cpe": "cpe:2.3:a:gmp:gmp:6.2.1-r2:*:*:*:*:*:*:*",
286282          "purl": "pkg:apk/alpine/gmp@6.2.1-r2?arch=x86_64\u0026distro=alpine-3.16.5",
286283          "swid": {
286284            "attachment": {}
286285          },
286286          "pedigree": {},
286287          "externalReferences": [
286288            {
286289              "url": "https://gmplib.org/",
286290              "type": "distribution"
286291            }
286292          ],
286293          "evidence": {},
286294          "signature": {
286295            "signature": {
286296              "publicKey": {}
286297            }
286298          },
286299          "modelCard": {
286300            "modelParameters": {
286301              "approach": {}
286302            },
286303            "quantitativeAnalysis": {
286304              "graphics": {}
286305            },
286306            "considerations": {}
286307          }
286308        },
286309        {
286310          "type": "library",
286311          "bom-ref": "pkg:pypi/greenlet@0.4.15?package-id=7bf0a63a71eda55d",
286312          "supplier": {},
286313          "name": "greenlet",
286314          "version": "0.4.15",
286315          "licenses": [
286316            {
286317              "license": {
286318                "name": "MIT License"
286319              }
286320            }
286321          ],
286322          "cpe": "cpe:2.3:a:python-greenlet:python-greenlet:0.4.15:*:*:*:*:*:*:*",
286323          "purl": "pkg:pypi/greenlet@0.4.15",
286324          "swid": {
286325            "attachment": {}
286326          },
286327          "pedigree": {},
286328          "evidence": {},
286329          "signature": {
286330            "signature": {
286331              "publicKey": {}
286332            }
286333          },
286334          "modelCard": {
286335            "modelParameters": {
286336              "approach": {}
286337            },
286338            "quantitativeAnalysis": {
286339              "graphics": {}
286340            },
286341            "considerations": {}
286342          }
286343        },
286344        {
286345          "type": "library",
286346          "bom-ref": "pkg:pypi/gunicorn@19.9.0?package-id=541fb1f7a37c872d",
286347          "supplier": {},
286348          "author": "Benoit Chesneau \u003cbenoitc@e-engura.com\u003e",
286349          "name": "gunicorn",
286350          "version": "19.9.0",
286351          "licenses": [
286352            {
286353              "license": {
286354                "id": "MIT"
286355              }
286356            }
286357          ],
286358          "cpe": "cpe:2.3:a:benoit_chesneau_project:python-gunicorn:19.9.0:*:*:*:*:*:*:*",
286359          "purl": "pkg:pypi/gunicorn@19.9.0",
286360          "swid": {
286361            "attachment": {}
286362          },
286363          "pedigree": {},
286364          "evidence": {},
286365          "signature": {
286366            "signature": {
286367              "publicKey": {}
286368            }
286369          },
286370          "modelCard": {
286371            "modelParameters": {
286372              "approach": {}
286373            },
286374            "quantitativeAnalysis": {
286375              "graphics": {}
286376            },
286377            "considerations": {}
286378          }
286379        },
286380        {
286381          "type": "library",
286382          "bom-ref": "pkg:pypi/idna@3.3?package-id=69b0bf94e8a5e80",
286383          "supplier": {},
286384          "author": "Kim Davies \u003ckim@cynosure.com.au\u003e",
286385          "name": "idna",
286386          "version": "3.3",
286387          "licenses": [
286388            {
286389              "license": {
286390                "id": "BSD-3-Clause"
286391              }
286392            }
286393          ],
286394          "cpe": "cpe:2.3:a:kim_davies_project:python-idna:3.3:*:*:*:*:*:*:*",
286395          "purl": "pkg:pypi/idna@3.3",
286396          "swid": {
286397            "attachment": {}
286398          },
286399          "pedigree": {},
286400          "evidence": {},
286401          "signature": {
286402            "signature": {
286403              "publicKey": {}
286404            }
286405          },
286406          "modelCard": {
286407            "modelParameters": {
286408              "approach": {}
286409            },
286410            "quantitativeAnalysis": {
286411              "graphics": {}
286412            },
286413            "considerations": {}
286414          }
286415        },
286416        {
286417          "type": "library",
286418          "bom-ref": "pkg:pypi/idna@3.4?package-id=a31834d389e46e0",
286419          "supplier": {},
286420          "author": "Kim Davies \u003ckim@cynosure.com.au\u003e",
286421          "name": "idna",
286422          "version": "3.4",
286423          "cpe": "cpe:2.3:a:kim_davies_\\\u003ckim_project:python-idna:3.4:*:*:*:*:*:*:*",
286424          "purl": "pkg:pypi/idna@3.4",
286425          "swid": {
286426            "attachment": {}
286427          },
286428          "pedigree": {},
286429          "evidence": {},
286430          "signature": {
286431            "signature": {
286432              "publicKey": {}
286433            }
286434          },
286435          "modelCard": {
286436            "modelParameters": {
286437              "approach": {}
286438            },
286439            "quantitativeAnalysis": {
286440              "graphics": {}
286441            },
286442            "considerations": {}
286443          }
286444        },
286445        {
286446          "type": "library",
286447          "bom-ref": "pkg:pypi/ipaddress@1.0.23?package-id=efd6c2c737e4b01c",
286448          "supplier": {},
286449          "author": "Philipp Hagemeister \u003cphihag@phihag.de\u003e",
286450          "name": "ipaddress",
286451          "version": "1.0.23",
286452          "licenses": [
286453            {
286454              "license": {
286455                "name": "Python Software Foundation License"
286456              }
286457            }
286458          ],
286459          "cpe": "cpe:2.3:a:philipp_hagemeister_project:python-ipaddress:1.0.23:*:*:*:*:*:*:*",
286460          "purl": "pkg:pypi/ipaddress@1.0.23",
286461          "swid": {
286462            "attachment": {}
286463          },
286464          "pedigree": {},
286465          "evidence": {},
286466          "signature": {
286467            "signature": {
286468              "publicKey": {}
286469            }
286470          },
286471          "modelCard": {
286472            "modelParameters": {
286473              "approach": {}
286474            },
286475            "quantitativeAnalysis": {
286476              "graphics": {}
286477            },
286478            "considerations": {}
286479          }
286480        },
286481        {
286482          "type": "library",
286483          "bom-ref": "pkg:apk/alpine/isl22@0.22-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=fe68ca8546c4e97d",
286484          "supplier": {},
286485          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
286486          "name": "isl22",
286487          "version": "0.22-r0",
286488          "description": "An Integer Set Library for the Polyhedral Model",
286489          "licenses": [
286490            {
286491              "license": {
286492                "id": "MIT"
286493              }
286494            }
286495          ],
286496          "cpe": "cpe:2.3:a:isl22:isl22:0.22-r0:*:*:*:*:*:*:*",
286497          "purl": "pkg:apk/alpine/isl22@0.22-r0?arch=x86_64\u0026distro=alpine-3.16.5",
286498          "swid": {
286499            "attachment": {}
286500          },
286501          "pedigree": {},
286502          "externalReferences": [
286503            {
286504              "url": "http://isl.gforge.inria.fr/",
286505              "type": "distribution"
286506            }
286507          ],
286508          "evidence": {},
286509          "signature": {
286510            "signature": {
286511              "publicKey": {}
286512            }
286513          },
286514          "modelCard": {
286515            "modelParameters": {
286516              "approach": {}
286517            },
286518            "quantitativeAnalysis": {
286519              "graphics": {}
286520            },
286521            "considerations": {}
286522          }
286523        },
286524        {
286525          "type": "library",
286526          "bom-ref": "pkg:pypi/itsdangerous@1.1.0?package-id=633bec45aabde3ce",
286527          "supplier": {},
286528          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
286529          "name": "itsdangerous",
286530          "version": "1.1.0",
286531          "licenses": [
286532            {
286533              "license": {
286534                "name": "BSD"
286535              }
286536            }
286537          ],
286538          "cpe": "cpe:2.3:a:armin_ronacher_project:python-itsdangerous:1.1.0:*:*:*:*:*:*:*",
286539          "purl": "pkg:pypi/itsdangerous@1.1.0",
286540          "swid": {
286541            "attachment": {}
286542          },
286543          "pedigree": {},
286544          "evidence": {},
286545          "signature": {
286546            "signature": {
286547              "publicKey": {}
286548            }
286549          },
286550          "modelCard": {
286551            "modelParameters": {
286552              "approach": {}
286553            },
286554            "quantitativeAnalysis": {
286555              "graphics": {}
286556            },
286557            "considerations": {}
286558          }
286559        },
286560        {
286561          "type": "library",
286562          "bom-ref": "pkg:apk/alpine/keyutils-libs@1.6.3-r1?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.16.5\u0026package-id=8ee597dfe194ab60",
286563          "supplier": {},
286564          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
286565          "name": "keyutils-libs",
286566          "version": "1.6.3-r1",
286567          "description": "Key utilities library",
286568          "licenses": [
286569            {
286570              "license": {
286571                "id": "GPL-2.0-or-later"
286572              }
286573            },
286574            {
286575              "license": {
286576                "id": "LGPL-2.0-or-later"
286577              }
286578            }
286579          ],
286580          "cpe": "cpe:2.3:a:keyutils-libs:keyutils-libs:1.6.3-r1:*:*:*:*:*:*:*",
286581          "purl": "pkg:apk/alpine/keyutils-libs@1.6.3-r1?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.16.5",
286582          "swid": {
286583            "attachment": {}
286584          },
286585          "pedigree": {},
286586          "externalReferences": [
286587            {
286588              "url": "https://people.redhat.com/~dhowells/keyutils/",
286589              "type": "distribution"
286590            }
286591          ],
286592          "evidence": {},
286593          "signature": {
286594            "signature": {
286595              "publicKey": {}
286596            }
286597          },
286598          "modelCard": {
286599            "modelParameters": {
286600              "approach": {}
286601            },
286602            "quantitativeAnalysis": {
286603              "graphics": {}
286604            },
286605            "considerations": {}
286606          }
286607        },
286608        {
286609          "type": "library",
286610          "bom-ref": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=50afffc56cc7e53",
286611          "supplier": {},
286612          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
286613          "name": "krb5-conf",
286614          "version": "1.0-r2",
286615          "description": "Shared krb5.conf for both MIT krb5 and heimdal",
286616          "licenses": [
286617            {
286618              "license": {
286619                "id": "MIT"
286620              }
286621            }
286622          ],
286623          "cpe": "cpe:2.3:a:krb5-conf:krb5-conf:1.0-r2:*:*:*:*:*:*:*",
286624          "purl": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=alpine-3.16.5",
286625          "swid": {
286626            "attachment": {}
286627          },
286628          "pedigree": {},
286629          "externalReferences": [
286630            {
286631              "url": "https://web.mit.edu/kerberos/www/",
286632              "type": "distribution"
286633            }
286634          ],
286635          "evidence": {},
286636          "signature": {
286637            "signature": {
286638              "publicKey": {}
286639            }
286640          },
286641          "modelCard": {
286642            "modelParameters": {
286643              "approach": {}
286644            },
286645            "quantitativeAnalysis": {
286646              "graphics": {}
286647            },
286648            "considerations": {}
286649          }
286650        },
286651        {
286652          "type": "library",
286653          "bom-ref": "pkg:apk/alpine/krb5-libs@1.19.4-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.16.5\u0026package-id=4cdf917c85417723",
286654          "supplier": {},
286655          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
286656          "name": "krb5-libs",
286657          "version": "1.19.4-r0",
286658          "description": "The shared libraries used by Kerberos 5",
286659          "licenses": [
286660            {
286661              "license": {
286662                "id": "MIT"
286663              }
286664            }
286665          ],
286666          "cpe": "cpe:2.3:a:krb5-libs:krb5-libs:1.19.4-r0:*:*:*:*:*:*:*",
286667          "purl": "pkg:apk/alpine/krb5-libs@1.19.4-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.16.5",
286668          "swid": {
286669            "attachment": {}
286670          },
286671          "pedigree": {},
286672          "externalReferences": [
286673            {
286674              "url": "https://web.mit.edu/kerberos/www/",
286675              "type": "distribution"
286676            }
286677          ],
286678          "evidence": {},
286679          "signature": {
286680            "signature": {
286681              "publicKey": {}
286682            }
286683          },
286684          "modelCard": {
286685            "modelParameters": {
286686              "approach": {}
286687            },
286688            "quantitativeAnalysis": {
286689              "graphics": {}
286690            },
286691            "considerations": {}
286692          }
286693        },
286694        {
286695          "type": "library",
286696          "bom-ref": "pkg:apk/alpine/libatomic@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=391e506485915ed6",
286697          "supplier": {},
286698          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
286699          "name": "libatomic",
286700          "version": "11.2.1_git20220219-r2",
286701          "description": "GCC Atomic library",
286702          "licenses": [
286703            {
286704              "license": {
286705                "id": "GPL-2.0-or-later"
286706              }
286707            },
286708            {
286709              "license": {
286710                "id": "LGPL-2.1-or-later"
286711              }
286712            }
286713          ],
286714          "cpe": "cpe:2.3:a:libatomic:libatomic:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
286715          "purl": "pkg:apk/alpine/libatomic@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
286716          "swid": {
286717            "attachment": {}
286718          },
286719          "pedigree": {},
286720          "externalReferences": [
286721            {
286722              "url": "https://gcc.gnu.org",
286723              "type": "distribution"
286724            }
286725          ],
286726          "evidence": {},
286727          "signature": {
286728            "signature": {
286729              "publicKey": {}
286730            }
286731          },
286732          "modelCard": {
286733            "modelParameters": {
286734              "approach": {}
286735            },
286736            "quantitativeAnalysis": {
286737              "graphics": {}
286738            },
286739            "considerations": {}
286740          }
286741        },
286742        {
286743          "type": "library",
286744          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.16.5\u0026package-id=b681aee18ae0aa50",
286745          "supplier": {},
286746          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
286747          "name": "libbz2",
286748          "version": "1.0.8-r1",
286749          "description": "Shared library for bz2",
286750          "licenses": [
286751            {
286752              "license": {
286753                "id": "bzip2-1.0.6"
286754              }
286755            }
286756          ],
286757          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r1:*:*:*:*:*:*:*",
286758          "purl": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.16.5",
286759          "swid": {
286760            "attachment": {}
286761          },
286762          "pedigree": {},
286763          "externalReferences": [
286764            {
286765              "url": "http://sources.redhat.com/bzip2",
286766              "type": "distribution"
286767            }
286768          ],
286769          "evidence": {},
286770          "signature": {
286771            "signature": {
286772              "publicKey": {}
286773            }
286774          },
286775          "modelCard": {
286776            "modelParameters": {
286777              "approach": {}
286778            },
286779            "quantitativeAnalysis": {
286780              "graphics": {}
286781            },
286782            "considerations": {}
286783          }
286784        },
286785        {
286786          "type": "library",
286787          "bom-ref": "pkg:apk/alpine/libc-dev@0.7.2-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=ffa8d1e8b50ff4be",
286788          "supplier": {},
286789          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
286790          "name": "libc-dev",
286791          "version": "0.7.2-r3",
286792          "description": "Meta package to pull in correct libc",
286793          "licenses": [
286794            {
286795              "license": {
286796                "id": "BSD-2-Clause"
286797              }
286798            },
286799            {
286800              "license": {
286801                "name": "AND"
286802              }
286803            },
286804            {
286805              "license": {
286806                "id": "BSD-3-Clause"
286807              }
286808            }
286809          ],
286810          "cpe": "cpe:2.3:a:libc-dev:libc-dev:0.7.2-r3:*:*:*:*:*:*:*",
286811          "purl": "pkg:apk/alpine/libc-dev@0.7.2-r3?arch=x86_64\u0026distro=alpine-3.16.5",
286812          "swid": {
286813            "attachment": {}
286814          },
286815          "pedigree": {},
286816          "externalReferences": [
286817            {
286818              "url": "https://alpinelinux.org",
286819              "type": "distribution"
286820            }
286821          ],
286822          "evidence": {},
286823          "signature": {
286824            "signature": {
286825              "publicKey": {}
286826            }
286827          },
286828          "modelCard": {
286829            "modelParameters": {
286830              "approach": {}
286831            },
286832            "quantitativeAnalysis": {
286833              "graphics": {}
286834            },
286835            "considerations": {}
286836          }
286837        },
286838        {
286839          "type": "library",
286840          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5\u0026package-id=2abd3b45f6fa4702",
286841          "supplier": {},
286842          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
286843          "name": "libc-utils",
286844          "version": "0.7.2-r3",
286845          "description": "Meta package to pull in correct libc",
286846          "licenses": [
286847            {
286848              "license": {
286849                "id": "BSD-2-Clause"
286850              }
286851            },
286852            {
286853              "license": {
286854                "name": "AND"
286855              }
286856            },
286857            {
286858              "license": {
286859                "id": "BSD-3-Clause"
286860              }
286861            }
286862          ],
286863          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
286864          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5",
286865          "swid": {
286866            "attachment": {}
286867          },
286868          "pedigree": {},
286869          "externalReferences": [
286870            {
286871              "url": "https://alpinelinux.org",
286872              "type": "distribution"
286873            }
286874          ],
286875          "evidence": {},
286876          "signature": {
286877            "signature": {
286878              "publicKey": {}
286879            }
286880          },
286881          "modelCard": {
286882            "modelParameters": {
286883              "approach": {}
286884            },
286885            "quantitativeAnalysis": {
286886              "graphics": {}
286887            },
286888            "considerations": {}
286889          }
286890        },
286891        {
286892          "type": "library",
286893          "bom-ref": "pkg:apk/alpine/libcom_err@1.46.6-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.16.5\u0026package-id=25b329ab3289e91c",
286894          "supplier": {},
286895          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
286896          "name": "libcom_err",
286897          "version": "1.46.6-r0",
286898          "description": "Common error description library",
286899          "licenses": [
286900            {
286901              "license": {
286902                "id": "GPL-2.0-or-later"
286903              }
286904            },
286905            {
286906              "license": {
286907                "name": "AND"
286908              }
286909            },
286910            {
286911              "license": {
286912                "id": "LGPL-2.0-or-later"
286913              }
286914            },
286915            {
286916              "license": {
286917                "name": "AND"
286918              }
286919            },
286920            {
286921              "license": {
286922                "id": "BSD-3-Clause"
286923              }
286924            },
286925            {
286926              "license": {
286927                "name": "AND"
286928              }
286929            },
286930            {
286931              "license": {
286932                "id": "MIT"
286933              }
286934            }
286935          ],
286936          "cpe": "cpe:2.3:a:libcom-err:libcom-err:1.46.6-r0:*:*:*:*:*:*:*",
286937          "purl": "pkg:apk/alpine/libcom_err@1.46.6-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.16.5",
286938          "swid": {
286939            "attachment": {}
286940          },
286941          "pedigree": {},
286942          "externalReferences": [
286943            {
286944              "url": "http://e2fsprogs.sourceforge.net",
286945              "type": "distribution"
286946            }
286947          ],
286948          "evidence": {},
286949          "signature": {
286950            "signature": {
286951              "publicKey": {}
286952            }
286953          },
286954          "modelCard": {
286955            "modelParameters": {
286956              "approach": {}
286957            },
286958            "quantitativeAnalysis": {
286959              "graphics": {}
286960            },
286961            "considerations": {}
286962          }
286963        },
286964        {
286965          "type": "library",
286966          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=13bc051822a24e8d",
286967          "supplier": {},
286968          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
286969          "name": "libcrypto1.1",
286970          "version": "1.1.1t-r2",
286971          "description": "Crypto library from openssl",
286972          "licenses": [
286973            {
286974              "license": {
286975                "id": "OpenSSL"
286976              }
286977            }
286978          ],
286979          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1t-r2:*:*:*:*:*:*:*",
286980          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
286981          "swid": {
286982            "attachment": {}
286983          },
286984          "pedigree": {},
286985          "externalReferences": [
286986            {
286987              "url": "https://www.openssl.org/",
286988              "type": "distribution"
286989            }
286990          ],
286991          "evidence": {},
286992          "signature": {
286993            "signature": {
286994              "publicKey": {}
286995            }
286996          },
286997          "modelCard": {
286998            "modelParameters": {
286999              "approach": {}
287000            },
287001            "quantitativeAnalysis": {
287002              "graphics": {}
287003            },
287004            "considerations": {}
287005          }
287006        },
287007        {
287008          "type": "library",
287009          "bom-ref": "pkg:apk/alpine/libedit@20210910.3.1-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=306ebeb39081e8f5",
287010          "supplier": {},
287011          "publisher": "Drew DeVault \u003csir@cmpwn.com\u003e",
287012          "name": "libedit",
287013          "version": "20210910.3.1-r0",
287014          "description": "BSD line editing library",
287015          "licenses": [
287016            {
287017              "license": {
287018                "id": "BSD-3-Clause"
287019              }
287020            }
287021          ],
287022          "cpe": "cpe:2.3:a:libedit:libedit:20210910.3.1-r0:*:*:*:*:*:*:*",
287023          "purl": "pkg:apk/alpine/libedit@20210910.3.1-r0?arch=x86_64\u0026distro=alpine-3.16.5",
287024          "swid": {
287025            "attachment": {}
287026          },
287027          "pedigree": {},
287028          "externalReferences": [
287029            {
287030              "url": "https://www.thrysoee.dk/editline",
287031              "type": "distribution"
287032            }
287033          ],
287034          "evidence": {},
287035          "signature": {
287036            "signature": {
287037              "publicKey": {}
287038            }
287039          },
287040          "modelCard": {
287041            "modelParameters": {
287042              "approach": {}
287043            },
287044            "quantitativeAnalysis": {
287045              "graphics": {}
287046            },
287047            "considerations": {}
287048          }
287049        },
287050        {
287051          "type": "library",
287052          "bom-ref": "pkg:apk/alpine/libffi@3.4.2-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=d9c90e0c86210cde",
287053          "supplier": {},
287054          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287055          "name": "libffi",
287056          "version": "3.4.2-r1",
287057          "description": "portable, high level programming interface to various calling conventions.",
287058          "licenses": [
287059            {
287060              "license": {
287061                "id": "MIT"
287062              }
287063            }
287064          ],
287065          "cpe": "cpe:2.3:a:libffi:libffi:3.4.2-r1:*:*:*:*:*:*:*",
287066          "purl": "pkg:apk/alpine/libffi@3.4.2-r1?arch=x86_64\u0026distro=alpine-3.16.5",
287067          "swid": {
287068            "attachment": {}
287069          },
287070          "pedigree": {},
287071          "externalReferences": [
287072            {
287073              "url": "https://sourceware.org/libffi/",
287074              "type": "distribution"
287075            }
287076          ],
287077          "evidence": {},
287078          "signature": {
287079            "signature": {
287080              "publicKey": {}
287081            }
287082          },
287083          "modelCard": {
287084            "modelParameters": {
287085              "approach": {}
287086            },
287087            "quantitativeAnalysis": {
287088              "graphics": {}
287089            },
287090            "considerations": {}
287091          }
287092        },
287093        {
287094          "type": "library",
287095          "bom-ref": "pkg:apk/alpine/libffi-dev@3.4.2-r1?arch=x86_64\u0026upstream=libffi\u0026distro=alpine-3.16.5\u0026package-id=7a3db6fd86ea285",
287096          "supplier": {},
287097          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287098          "name": "libffi-dev",
287099          "version": "3.4.2-r1",
287100          "description": "portable, high level programming interface to various calling conventions. (development files)",
287101          "licenses": [
287102            {
287103              "license": {
287104                "id": "MIT"
287105              }
287106            }
287107          ],
287108          "cpe": "cpe:2.3:a:libffi-dev:libffi-dev:3.4.2-r1:*:*:*:*:*:*:*",
287109          "purl": "pkg:apk/alpine/libffi-dev@3.4.2-r1?arch=x86_64\u0026upstream=libffi\u0026distro=alpine-3.16.5",
287110          "swid": {
287111            "attachment": {}
287112          },
287113          "pedigree": {},
287114          "externalReferences": [
287115            {
287116              "url": "https://sourceware.org/libffi/",
287117              "type": "distribution"
287118            }
287119          ],
287120          "evidence": {},
287121          "signature": {
287122            "signature": {
287123              "publicKey": {}
287124            }
287125          },
287126          "modelCard": {
287127            "modelParameters": {
287128              "approach": {}
287129            },
287130            "quantitativeAnalysis": {
287131              "graphics": {}
287132            },
287133            "considerations": {}
287134          }
287135        },
287136        {
287137          "type": "library",
287138          "bom-ref": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=d2886381f1e7cdb2",
287139          "supplier": {},
287140          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
287141          "name": "libgcc",
287142          "version": "11.2.1_git20220219-r2",
287143          "description": "GNU C compiler runtime libraries",
287144          "licenses": [
287145            {
287146              "license": {
287147                "id": "GPL-2.0-or-later"
287148              }
287149            },
287150            {
287151              "license": {
287152                "id": "LGPL-2.1-or-later"
287153              }
287154            }
287155          ],
287156          "cpe": "cpe:2.3:a:libgcc:libgcc:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
287157          "purl": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
287158          "swid": {
287159            "attachment": {}
287160          },
287161          "pedigree": {},
287162          "externalReferences": [
287163            {
287164              "url": "https://gcc.gnu.org",
287165              "type": "distribution"
287166            }
287167          ],
287168          "evidence": {},
287169          "signature": {
287170            "signature": {
287171              "publicKey": {}
287172            }
287173          },
287174          "modelCard": {
287175            "modelParameters": {
287176              "approach": {}
287177            },
287178            "quantitativeAnalysis": {
287179              "graphics": {}
287180            },
287181            "considerations": {}
287182          }
287183        },
287184        {
287185          "type": "library",
287186          "bom-ref": "pkg:apk/alpine/libgomp@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=d3d0296e3355a335",
287187          "supplier": {},
287188          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
287189          "name": "libgomp",
287190          "version": "11.2.1_git20220219-r2",
287191          "description": "GCC shared-memory parallel programming API library",
287192          "licenses": [
287193            {
287194              "license": {
287195                "id": "GPL-2.0-or-later"
287196              }
287197            },
287198            {
287199              "license": {
287200                "id": "LGPL-2.1-or-later"
287201              }
287202            }
287203          ],
287204          "cpe": "cpe:2.3:a:libgomp:libgomp:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
287205          "purl": "pkg:apk/alpine/libgomp@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
287206          "swid": {
287207            "attachment": {}
287208          },
287209          "pedigree": {},
287210          "externalReferences": [
287211            {
287212              "url": "https://gcc.gnu.org",
287213              "type": "distribution"
287214            }
287215          ],
287216          "evidence": {},
287217          "signature": {
287218            "signature": {
287219              "publicKey": {}
287220            }
287221          },
287222          "modelCard": {
287223            "modelParameters": {
287224              "approach": {}
287225            },
287226            "quantitativeAnalysis": {
287227              "graphics": {}
287228            },
287229            "considerations": {}
287230          }
287231        },
287232        {
287233          "type": "library",
287234          "bom-ref": "pkg:apk/alpine/libintl@0.21-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.16.5\u0026package-id=8a4b8fffbba0af61",
287235          "supplier": {},
287236          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
287237          "name": "libintl",
287238          "version": "0.21-r2",
287239          "description": "GNU gettext runtime library",
287240          "licenses": [
287241            {
287242              "license": {
287243                "id": "LGPL-2.1-or-later"
287244              }
287245            }
287246          ],
287247          "cpe": "cpe:2.3:a:libintl:libintl:0.21-r2:*:*:*:*:*:*:*",
287248          "purl": "pkg:apk/alpine/libintl@0.21-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.16.5",
287249          "swid": {
287250            "attachment": {}
287251          },
287252          "pedigree": {},
287253          "externalReferences": [
287254            {
287255              "url": "https://www.gnu.org/software/gettext/gettext.html",
287256              "type": "distribution"
287257            }
287258          ],
287259          "evidence": {},
287260          "signature": {
287261            "signature": {
287262              "publicKey": {}
287263            }
287264          },
287265          "modelCard": {
287266            "modelParameters": {
287267              "approach": {}
287268            },
287269            "quantitativeAnalysis": {
287270              "graphics": {}
287271            },
287272            "considerations": {}
287273          }
287274        },
287275        {
287276          "type": "library",
287277          "bom-ref": "pkg:apk/alpine/libmagic@5.41-r0?arch=x86_64\u0026upstream=file\u0026distro=alpine-3.16.5\u0026package-id=cb8a148cd2dc6b35",
287278          "supplier": {},
287279          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287280          "name": "libmagic",
287281          "version": "5.41-r0",
287282          "description": "File type identification library",
287283          "licenses": [
287284            {
287285              "license": {
287286                "id": "BSD-2-Clause"
287287              }
287288            }
287289          ],
287290          "cpe": "cpe:2.3:a:libmagic:libmagic:5.41-r0:*:*:*:*:*:*:*",
287291          "purl": "pkg:apk/alpine/libmagic@5.41-r0?arch=x86_64\u0026upstream=file\u0026distro=alpine-3.16.5",
287292          "swid": {
287293            "attachment": {}
287294          },
287295          "pedigree": {},
287296          "externalReferences": [
287297            {
287298              "url": "https://www.darwinsys.com/file/",
287299              "type": "distribution"
287300            }
287301          ],
287302          "evidence": {},
287303          "signature": {
287304            "signature": {
287305              "publicKey": {}
287306            }
287307          },
287308          "modelCard": {
287309            "modelParameters": {
287310              "approach": {}
287311            },
287312            "quantitativeAnalysis": {
287313              "graphics": {}
287314            },
287315            "considerations": {}
287316          }
287317        },
287318        {
287319          "type": "library",
287320          "bom-ref": "pkg:apk/alpine/libnsl@2.0.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=684ad1c4c0c42987",
287321          "supplier": {},
287322          "publisher": "Valery Kartel \u003cvalery.kartel@gmail.com\u003e",
287323          "name": "libnsl",
287324          "version": "2.0.0-r0",
287325          "description": "Public client interface for NIS(YP) and NIS+ in a IPv6 ready version",
287326          "licenses": [
287327            {
287328              "license": {
287329                "id": "LGPL-2.0-or-later"
287330              }
287331            }
287332          ],
287333          "cpe": "cpe:2.3:a:thkukuk:libnsl:2.0.0-r0:*:*:*:*:*:*:*",
287334          "purl": "pkg:apk/alpine/libnsl@2.0.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
287335          "swid": {
287336            "attachment": {}
287337          },
287338          "pedigree": {},
287339          "externalReferences": [
287340            {
287341              "url": "https://github.com/thkukuk/libnsl",
287342              "type": "distribution"
287343            }
287344          ],
287345          "evidence": {},
287346          "signature": {
287347            "signature": {
287348              "publicKey": {}
287349            }
287350          },
287351          "modelCard": {
287352            "modelParameters": {
287353              "approach": {}
287354            },
287355            "quantitativeAnalysis": {
287356              "graphics": {}
287357            },
287358            "considerations": {}
287359          }
287360        },
287361        {
287362          "type": "library",
287363          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=609cb94e63dc06dd",
287364          "supplier": {},
287365          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
287366          "name": "libssl1.1",
287367          "version": "1.1.1t-r2",
287368          "description": "SSL shared libraries",
287369          "licenses": [
287370            {
287371              "license": {
287372                "id": "OpenSSL"
287373              }
287374            }
287375          ],
287376          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1t-r2:*:*:*:*:*:*:*",
287377          "purl": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
287378          "swid": {
287379            "attachment": {}
287380          },
287381          "pedigree": {},
287382          "externalReferences": [
287383            {
287384              "url": "https://www.openssl.org/",
287385              "type": "distribution"
287386            }
287387          ],
287388          "evidence": {},
287389          "signature": {
287390            "signature": {
287391              "publicKey": {}
287392            }
287393          },
287394          "modelCard": {
287395            "modelParameters": {
287396              "approach": {}
287397            },
287398            "quantitativeAnalysis": {
287399              "graphics": {}
287400            },
287401            "considerations": {}
287402          }
287403        },
287404        {
287405          "type": "library",
287406          "bom-ref": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=9913678ca8fd323d",
287407          "supplier": {},
287408          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
287409          "name": "libstdc++",
287410          "version": "11.2.1_git20220219-r2",
287411          "description": "GNU C++ standard runtime library",
287412          "licenses": [
287413            {
287414              "license": {
287415                "id": "GPL-2.0-or-later"
287416              }
287417            },
287418            {
287419              "license": {
287420                "id": "LGPL-2.1-or-later"
287421              }
287422            }
287423          ],
287424          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
287425          "purl": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
287426          "swid": {
287427            "attachment": {}
287428          },
287429          "pedigree": {},
287430          "externalReferences": [
287431            {
287432              "url": "https://gcc.gnu.org",
287433              "type": "distribution"
287434            }
287435          ],
287436          "evidence": {},
287437          "signature": {
287438            "signature": {
287439              "publicKey": {}
287440            }
287441          },
287442          "modelCard": {
287443            "modelParameters": {
287444              "approach": {}
287445            },
287446            "quantitativeAnalysis": {
287447              "graphics": {}
287448            },
287449            "considerations": {}
287450          }
287451        },
287452        {
287453          "type": "library",
287454          "bom-ref": "pkg:apk/alpine/libtirpc@1.3.2-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=7879d46219520605",
287455          "supplier": {},
287456          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287457          "name": "libtirpc",
287458          "version": "1.3.2-r1",
287459          "description": "Transport Independent RPC library (SunRPC replacement)",
287460          "licenses": [
287461            {
287462              "license": {
287463                "id": "BSD-3-Clause"
287464              }
287465            }
287466          ],
287467          "cpe": "cpe:2.3:a:libtirpc:libtirpc:1.3.2-r1:*:*:*:*:*:*:*",
287468          "purl": "pkg:apk/alpine/libtirpc@1.3.2-r1?arch=x86_64\u0026distro=alpine-3.16.5",
287469          "swid": {
287470            "attachment": {}
287471          },
287472          "pedigree": {},
287473          "externalReferences": [
287474            {
287475              "url": "https://sourceforge.net/projects/libtirpc",
287476              "type": "distribution"
287477            }
287478          ],
287479          "evidence": {},
287480          "signature": {
287481            "signature": {
287482              "publicKey": {}
287483            }
287484          },
287485          "modelCard": {
287486            "modelParameters": {
287487              "approach": {}
287488            },
287489            "quantitativeAnalysis": {
287490              "graphics": {}
287491            },
287492            "considerations": {}
287493          }
287494        },
287495        {
287496          "type": "library",
287497          "bom-ref": "pkg:apk/alpine/libtirpc-conf@1.3.2-r1?arch=x86_64\u0026upstream=libtirpc\u0026distro=alpine-3.16.5\u0026package-id=2473c071ab562d92",
287498          "supplier": {},
287499          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287500          "name": "libtirpc-conf",
287501          "version": "1.3.2-r1",
287502          "description": "Configuration files for TI-RPC",
287503          "licenses": [
287504            {
287505              "license": {
287506                "id": "BSD-3-Clause"
287507              }
287508            }
287509          ],
287510          "cpe": "cpe:2.3:a:libtirpc-conf:libtirpc-conf:1.3.2-r1:*:*:*:*:*:*:*",
287511          "purl": "pkg:apk/alpine/libtirpc-conf@1.3.2-r1?arch=x86_64\u0026upstream=libtirpc\u0026distro=alpine-3.16.5",
287512          "swid": {
287513            "attachment": {}
287514          },
287515          "pedigree": {},
287516          "externalReferences": [
287517            {
287518              "url": "https://sourceforge.net/projects/libtirpc",
287519              "type": "distribution"
287520            }
287521          ],
287522          "evidence": {},
287523          "signature": {
287524            "signature": {
287525              "publicKey": {}
287526            }
287527          },
287528          "modelCard": {
287529            "modelParameters": {
287530              "approach": {}
287531            },
287532            "quantitativeAnalysis": {
287533              "graphics": {}
287534            },
287535            "considerations": {}
287536          }
287537        },
287538        {
287539          "type": "library",
287540          "bom-ref": "pkg:apk/alpine/libuuid@2.38-r1?arch=x86_64\u0026upstream=util-linux\u0026distro=alpine-3.16.5\u0026package-id=8732526a564c0dca",
287541          "supplier": {},
287542          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287543          "name": "libuuid",
287544          "version": "2.38-r1",
287545          "description": "DCE compatible Universally Unique Identifier library",
287546          "licenses": [
287547            {
287548              "license": {
287549                "id": "GPL-3.0-or-later"
287550              }
287551            },
287552            {
287553              "license": {
287554                "name": "AND"
287555              }
287556            },
287557            {
287558              "license": {
287559                "id": "GPL-2.0-or-later"
287560              }
287561            },
287562            {
287563              "license": {
287564                "name": "AND"
287565              }
287566            },
287567            {
287568              "license": {
287569                "id": "GPL-2.0-only"
287570              }
287571            },
287572            {
287573              "license": {
287574                "name": "AND"
287575              }
287576            }
287577          ],
287578          "cpe": "cpe:2.3:a:libuuid:libuuid:2.38-r1:*:*:*:*:*:*:*",
287579          "purl": "pkg:apk/alpine/libuuid@2.38-r1?arch=x86_64\u0026upstream=util-linux\u0026distro=alpine-3.16.5",
287580          "swid": {
287581            "attachment": {}
287582          },
287583          "pedigree": {},
287584          "externalReferences": [
287585            {
287586              "url": "https://git.kernel.org/cgit/utils/util-linux/util-linux.git",
287587              "type": "distribution"
287588            }
287589          ],
287590          "evidence": {},
287591          "signature": {
287592            "signature": {
287593              "publicKey": {}
287594            }
287595          },
287596          "modelCard": {
287597            "modelParameters": {
287598              "approach": {}
287599            },
287600            "quantitativeAnalysis": {
287601              "graphics": {}
287602            },
287603            "considerations": {}
287604          }
287605        },
287606        {
287607          "type": "library",
287608          "bom-ref": "pkg:apk/alpine/libverto@0.3.2-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=b3642afc50cf09b9",
287609          "supplier": {},
287610          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
287611          "name": "libverto",
287612          "version": "0.3.2-r0",
287613          "description": "Main loop abstraction library",
287614          "licenses": [
287615            {
287616              "license": {
287617                "id": "MIT"
287618              }
287619            }
287620          ],
287621          "cpe": "cpe:2.3:a:npmccallum:libverto:0.3.2-r0:*:*:*:*:*:*:*",
287622          "purl": "pkg:apk/alpine/libverto@0.3.2-r0?arch=x86_64\u0026distro=alpine-3.16.5",
287623          "swid": {
287624            "attachment": {}
287625          },
287626          "pedigree": {},
287627          "externalReferences": [
287628            {
287629              "url": "https://github.com/npmccallum/libverto",
287630              "type": "distribution"
287631            }
287632          ],
287633          "evidence": {},
287634          "signature": {
287635            "signature": {
287636              "publicKey": {}
287637            }
287638          },
287639          "modelCard": {
287640            "modelParameters": {
287641              "approach": {}
287642            },
287643            "quantitativeAnalysis": {
287644              "graphics": {}
287645            },
287646            "considerations": {}
287647          }
287648        },
287649        {
287650          "type": "library",
287651          "bom-ref": "pkg:apk/alpine/linux-headers@5.16.7-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=43e9a2c98b57e350",
287652          "supplier": {},
287653          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287654          "name": "linux-headers",
287655          "version": "5.16.7-r1",
287656          "description": "Linux system headers",
287657          "licenses": [
287658            {
287659              "license": {
287660                "id": "GPL-2.0-only"
287661              }
287662            }
287663          ],
287664          "cpe": "cpe:2.3:a:linux-headers:linux-headers:5.16.7-r1:*:*:*:*:*:*:*",
287665          "purl": "pkg:apk/alpine/linux-headers@5.16.7-r1?arch=x86_64\u0026distro=alpine-3.16.5",
287666          "swid": {
287667            "attachment": {}
287668          },
287669          "pedigree": {},
287670          "externalReferences": [
287671            {
287672              "url": "https://kernel.org/",
287673              "type": "distribution"
287674            }
287675          ],
287676          "evidence": {},
287677          "signature": {
287678            "signature": {
287679              "publicKey": {}
287680            }
287681          },
287682          "modelCard": {
287683            "modelParameters": {
287684              "approach": {}
287685            },
287686            "quantitativeAnalysis": {
287687              "graphics": {}
287688            },
287689            "considerations": {}
287690          }
287691        },
287692        {
287693          "type": "library",
287694          "bom-ref": "pkg:pypi/lockfile@0.12.2?package-id=10b97a5fb853fc77",
287695          "supplier": {},
287696          "author": "OpenStack \u003copenstack-dev@lists.openstack.org\u003e",
287697          "name": "lockfile",
287698          "version": "0.12.2",
287699          "licenses": [
287700            {
287701              "license": {
287702                "name": "UNKNOWN"
287703              }
287704            }
287705          ],
287706          "cpe": "cpe:2.3:a:openstack_dev_project:python-lockfile:0.12.2:*:*:*:*:*:*:*",
287707          "purl": "pkg:pypi/lockfile@0.12.2",
287708          "swid": {
287709            "attachment": {}
287710          },
287711          "pedigree": {},
287712          "evidence": {},
287713          "signature": {
287714            "signature": {
287715              "publicKey": {}
287716            }
287717          },
287718          "modelCard": {
287719            "modelParameters": {
287720              "approach": {}
287721            },
287722            "quantitativeAnalysis": {
287723              "graphics": {}
287724            },
287725            "considerations": {}
287726          }
287727        },
287728        {
287729          "type": "library",
287730          "bom-ref": "pkg:apk/alpine/make@4.3-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=d80635964dcc0aa2",
287731          "supplier": {},
287732          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287733          "name": "make",
287734          "version": "4.3-r0",
287735          "description": "GNU make utility to maintain groups of programs",
287736          "licenses": [
287737            {
287738              "license": {
287739                "id": "GPL-3.0-or-later"
287740              }
287741            }
287742          ],
287743          "cpe": "cpe:2.3:a:make:make:4.3-r0:*:*:*:*:*:*:*",
287744          "purl": "pkg:apk/alpine/make@4.3-r0?arch=x86_64\u0026distro=alpine-3.16.5",
287745          "swid": {
287746            "attachment": {}
287747          },
287748          "pedigree": {},
287749          "externalReferences": [
287750            {
287751              "url": "https://www.gnu.org/software/make",
287752              "type": "distribution"
287753            }
287754          ],
287755          "evidence": {},
287756          "signature": {
287757            "signature": {
287758              "publicKey": {}
287759            }
287760          },
287761          "modelCard": {
287762            "modelParameters": {
287763              "approach": {}
287764            },
287765            "quantitativeAnalysis": {
287766              "graphics": {}
287767            },
287768            "considerations": {}
287769          }
287770        },
287771        {
287772          "type": "library",
287773          "bom-ref": "pkg:pypi/more-itertools@8.13.0?package-id=54ab8b44d8723662",
287774          "supplier": {},
287775          "author": "Erik Rose \u003cerikrose@grinchcentral.com\u003e",
287776          "name": "more-itertools",
287777          "version": "8.13.0",
287778          "cpe": "cpe:2.3:a:erik_rose_\\\u003cerikrose_project:python-more-itertools:8.13.0:*:*:*:*:*:*:*",
287779          "purl": "pkg:pypi/more-itertools@8.13.0",
287780          "swid": {
287781            "attachment": {}
287782          },
287783          "pedigree": {},
287784          "evidence": {},
287785          "signature": {
287786            "signature": {
287787              "publicKey": {}
287788            }
287789          },
287790          "modelCard": {
287791            "modelParameters": {
287792              "approach": {}
287793            },
287794            "quantitativeAnalysis": {
287795              "graphics": {}
287796            },
287797            "considerations": {}
287798          }
287799        },
287800        {
287801          "type": "library",
287802          "bom-ref": "pkg:apk/alpine/mpc1@1.2.1-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=452ef5d5542bf30d",
287803          "supplier": {},
287804          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287805          "name": "mpc1",
287806          "version": "1.2.1-r0",
287807          "description": "Multiprecision C library",
287808          "licenses": [
287809            {
287810              "license": {
287811                "id": "LGPL-3.0-or-later"
287812              }
287813            }
287814          ],
287815          "cpe": "cpe:2.3:a:mpc1:mpc1:1.2.1-r0:*:*:*:*:*:*:*",
287816          "purl": "pkg:apk/alpine/mpc1@1.2.1-r0?arch=x86_64\u0026distro=alpine-3.16.5",
287817          "swid": {
287818            "attachment": {}
287819          },
287820          "pedigree": {},
287821          "externalReferences": [
287822            {
287823              "url": "http://www.multiprecision.org/",
287824              "type": "distribution"
287825            }
287826          ],
287827          "evidence": {},
287828          "signature": {
287829            "signature": {
287830              "publicKey": {}
287831            }
287832          },
287833          "modelCard": {
287834            "modelParameters": {
287835              "approach": {}
287836            },
287837            "quantitativeAnalysis": {
287838              "graphics": {}
287839            },
287840            "considerations": {}
287841          }
287842        },
287843        {
287844          "type": "library",
287845          "bom-ref": "pkg:apk/alpine/mpdecimal@2.5.1-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=7451f4ae27110f16",
287846          "supplier": {},
287847          "publisher": "Stefan Stutz \u003cstutz@pm.me\u003e",
287848          "name": "mpdecimal",
287849          "version": "2.5.1-r1",
287850          "description": "complete implementation of the General Decimal Arithmetic Specification",
287851          "licenses": [
287852            {
287853              "license": {
287854                "id": "BSD-2-Clause"
287855              }
287856            }
287857          ],
287858          "cpe": "cpe:2.3:a:mpdecimal:mpdecimal:2.5.1-r1:*:*:*:*:*:*:*",
287859          "purl": "pkg:apk/alpine/mpdecimal@2.5.1-r1?arch=x86_64\u0026distro=alpine-3.16.5",
287860          "swid": {
287861            "attachment": {}
287862          },
287863          "pedigree": {},
287864          "externalReferences": [
287865            {
287866              "url": "https://www.bytereef.org/mpdecimal/index.html",
287867              "type": "distribution"
287868            }
287869          ],
287870          "evidence": {},
287871          "signature": {
287872            "signature": {
287873              "publicKey": {}
287874            }
287875          },
287876          "modelCard": {
287877            "modelParameters": {
287878              "approach": {}
287879            },
287880            "quantitativeAnalysis": {
287881              "graphics": {}
287882            },
287883            "considerations": {}
287884          }
287885        },
287886        {
287887          "type": "library",
287888          "bom-ref": "pkg:apk/alpine/mpfr4@4.1.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=c45fe989339766c4",
287889          "supplier": {},
287890          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
287891          "name": "mpfr4",
287892          "version": "4.1.0-r0",
287893          "description": "multiple-precision floating-point library",
287894          "licenses": [
287895            {
287896              "license": {
287897                "id": "LGPL-3.0-or-later"
287898              }
287899            }
287900          ],
287901          "cpe": "cpe:2.3:a:mpfr4:mpfr4:4.1.0-r0:*:*:*:*:*:*:*",
287902          "purl": "pkg:apk/alpine/mpfr4@4.1.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
287903          "swid": {
287904            "attachment": {}
287905          },
287906          "pedigree": {},
287907          "externalReferences": [
287908            {
287909              "url": "https://www.mpfr.org/",
287910              "type": "distribution"
287911            }
287912          ],
287913          "evidence": {},
287914          "signature": {
287915            "signature": {
287916              "publicKey": {}
287917            }
287918          },
287919          "modelCard": {
287920            "modelParameters": {
287921              "approach": {}
287922            },
287923            "quantitativeAnalysis": {
287924              "graphics": {}
287925            },
287926            "considerations": {}
287927          }
287928        },
287929        {
287930          "type": "library",
287931          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=24c6089b81ca7d19",
287932          "supplier": {},
287933          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
287934          "name": "musl",
287935          "version": "1.2.3-r2",
287936          "description": "the musl c library (libc) implementation",
287937          "licenses": [
287938            {
287939              "license": {
287940                "id": "MIT"
287941              }
287942            }
287943          ],
287944          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r2:*:*:*:*:*:*:*",
287945          "purl": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5",
287946          "swid": {
287947            "attachment": {}
287948          },
287949          "pedigree": {},
287950          "externalReferences": [
287951            {
287952              "url": "https://musl.libc.org/",
287953              "type": "distribution"
287954            }
287955          ],
287956          "evidence": {},
287957          "signature": {
287958            "signature": {
287959              "publicKey": {}
287960            }
287961          },
287962          "modelCard": {
287963            "modelParameters": {
287964              "approach": {}
287965            },
287966            "quantitativeAnalysis": {
287967              "graphics": {}
287968            },
287969            "considerations": {}
287970          }
287971        },
287972        {
287973          "type": "library",
287974          "bom-ref": "pkg:apk/alpine/musl-dev@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5\u0026package-id=d85a38b286a3bde1",
287975          "supplier": {},
287976          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
287977          "name": "musl-dev",
287978          "version": "1.2.3-r2",
287979          "description": "the musl c library (libc) implementation (development files)",
287980          "licenses": [
287981            {
287982              "license": {
287983                "id": "MIT"
287984              }
287985            }
287986          ],
287987          "cpe": "cpe:2.3:a:musl-libc:musl-dev:1.2.3-r2:*:*:*:*:*:*:*",
287988          "purl": "pkg:apk/alpine/musl-dev@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5",
287989          "swid": {
287990            "attachment": {}
287991          },
287992          "pedigree": {},
287993          "externalReferences": [
287994            {
287995              "url": "https://musl.libc.org/",
287996              "type": "distribution"
287997            }
287998          ],
287999          "evidence": {},
288000          "signature": {
288001            "signature": {
288002              "publicKey": {}
288003            }
288004          },
288005          "modelCard": {
288006            "modelParameters": {
288007              "approach": {}
288008            },
288009            "quantitativeAnalysis": {
288010              "graphics": {}
288011            },
288012            "considerations": {}
288013          }
288014        },
288015        {
288016          "type": "library",
288017          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5\u0026package-id=d33c14d727ae74d1",
288018          "supplier": {},
288019          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
288020          "name": "musl-utils",
288021          "version": "1.2.3-r2",
288022          "description": "the musl c library (libc) implementation",
288023          "licenses": [
288024            {
288025              "license": {
288026                "id": "MIT"
288027              }
288028            },
288029            {
288030              "license": {
288031                "name": "BSD"
288032              }
288033            },
288034            {
288035              "license": {
288036                "id": "GPL-2.0-or-later"
288037              }
288038            }
288039          ],
288040          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r2:*:*:*:*:*:*:*",
288041          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5",
288042          "swid": {
288043            "attachment": {}
288044          },
288045          "pedigree": {},
288046          "externalReferences": [
288047            {
288048              "url": "https://musl.libc.org/",
288049              "type": "distribution"
288050            }
288051          ],
288052          "evidence": {},
288053          "signature": {
288054            "signature": {
288055              "publicKey": {}
288056            }
288057          },
288058          "modelCard": {
288059            "modelParameters": {
288060              "approach": {}
288061            },
288062            "quantitativeAnalysis": {
288063              "graphics": {}
288064            },
288065            "considerations": {}
288066          }
288067        },
288068        {
288069          "type": "library",
288070          "bom-ref": "pkg:apk/alpine/ncurses-libs@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5\u0026package-id=c2bd1192d3d60d2c",
288071          "supplier": {},
288072          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288073          "name": "ncurses-libs",
288074          "version": "6.3_p20220521-r0",
288075          "description": "Ncurses libraries",
288076          "licenses": [
288077            {
288078              "license": {
288079                "id": "MIT"
288080              }
288081            }
288082          ],
288083          "cpe": "cpe:2.3:a:ncurses-libs:ncurses-libs:6.3_p20220521-r0:*:*:*:*:*:*:*",
288084          "purl": "pkg:apk/alpine/ncurses-libs@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5",
288085          "swid": {
288086            "attachment": {}
288087          },
288088          "pedigree": {},
288089          "externalReferences": [
288090            {
288091              "url": "https://invisible-island.net/ncurses/",
288092              "type": "distribution"
288093            }
288094          ],
288095          "evidence": {},
288096          "signature": {
288097            "signature": {
288098              "publicKey": {}
288099            }
288100          },
288101          "modelCard": {
288102            "modelParameters": {
288103              "approach": {}
288104            },
288105            "quantitativeAnalysis": {
288106              "graphics": {}
288107            },
288108            "considerations": {}
288109          }
288110        },
288111        {
288112          "type": "library",
288113          "bom-ref": "pkg:apk/alpine/ncurses-terminfo-base@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5\u0026package-id=28679685d0eccfdc",
288114          "supplier": {},
288115          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288116          "name": "ncurses-terminfo-base",
288117          "version": "6.3_p20220521-r0",
288118          "description": "Descriptions of common terminals",
288119          "licenses": [
288120            {
288121              "license": {
288122                "id": "MIT"
288123              }
288124            }
288125          ],
288126          "cpe": "cpe:2.3:a:ncurses-terminfo-base:ncurses-terminfo-base:6.3_p20220521-r0:*:*:*:*:*:*:*",
288127          "purl": "pkg:apk/alpine/ncurses-terminfo-base@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5",
288128          "swid": {
288129            "attachment": {}
288130          },
288131          "pedigree": {},
288132          "externalReferences": [
288133            {
288134              "url": "https://invisible-island.net/ncurses/",
288135              "type": "distribution"
288136            }
288137          ],
288138          "evidence": {},
288139          "signature": {
288140            "signature": {
288141              "publicKey": {}
288142            }
288143          },
288144          "modelCard": {
288145            "modelParameters": {
288146              "approach": {}
288147            },
288148            "quantitativeAnalysis": {
288149              "graphics": {}
288150            },
288151            "considerations": {}
288152          }
288153        },
288154        {
288155          "type": "library",
288156          "bom-ref": "pkg:pypi/omsdk@1.2.503?package-id=4a4dbc5de5d52aeb",
288157          "supplier": {},
288158          "author": "Vaideeswaran Ganesan \u003cvaideeswaran_ganesan@dell.com\u003e",
288159          "name": "omsdk",
288160          "version": "1.2.503",
288161          "licenses": [
288162            {
288163              "license": {
288164                "name": "Apache Software License"
288165              }
288166            }
288167          ],
288168          "cpe": "cpe:2.3:a:vaideeswaran_ganesan_project:python-omsdk:1.2.503:*:*:*:*:*:*:*",
288169          "purl": "pkg:pypi/omsdk@1.2.503",
288170          "swid": {
288171            "attachment": {}
288172          },
288173          "pedigree": {},
288174          "evidence": {},
288175          "signature": {
288176            "signature": {
288177              "publicKey": {}
288178            }
288179          },
288180          "modelCard": {
288181            "modelParameters": {
288182              "approach": {}
288183            },
288184            "quantitativeAnalysis": {
288185              "graphics": {}
288186            },
288187            "considerations": {}
288188          }
288189        },
288190        {
288191          "type": "library",
288192          "bom-ref": "pkg:apk/alpine/openssh@9.0_p1-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=be35bb8e9f7dd701",
288193          "supplier": {},
288194          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288195          "name": "openssh",
288196          "version": "9.0_p1-r2",
288197          "description": "Port of OpenBSD's free SSH release",
288198          "licenses": [
288199            {
288200              "license": {
288201                "name": "BSD"
288202              }
288203            }
288204          ],
288205          "cpe": "cpe:2.3:a:openssh:openssh:9.0_p1-r2:*:*:*:*:*:*:*",
288206          "purl": "pkg:apk/alpine/openssh@9.0_p1-r2?arch=x86_64\u0026distro=alpine-3.16.5",
288207          "swid": {
288208            "attachment": {}
288209          },
288210          "pedigree": {},
288211          "externalReferences": [
288212            {
288213              "url": "https://www.openssh.com/portable.html",
288214              "type": "distribution"
288215            }
288216          ],
288217          "evidence": {},
288218          "signature": {
288219            "signature": {
288220              "publicKey": {}
288221            }
288222          },
288223          "modelCard": {
288224            "modelParameters": {
288225              "approach": {}
288226            },
288227            "quantitativeAnalysis": {
288228              "graphics": {}
288229            },
288230            "considerations": {}
288231          }
288232        },
288233        {
288234          "type": "library",
288235          "bom-ref": "pkg:apk/alpine/openssh-client-common@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=3fa98e2b8fec2d35",
288236          "supplier": {},
288237          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288238          "name": "openssh-client-common",
288239          "version": "9.0_p1-r2",
288240          "description": "OpenBSD's SSH client common files",
288241          "licenses": [
288242            {
288243              "license": {
288244                "name": "BSD"
288245              }
288246            }
288247          ],
288248          "cpe": "cpe:2.3:a:openssh-client-common:openssh-client-common:9.0_p1-r2:*:*:*:*:*:*:*",
288249          "purl": "pkg:apk/alpine/openssh-client-common@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
288250          "swid": {
288251            "attachment": {}
288252          },
288253          "pedigree": {},
288254          "externalReferences": [
288255            {
288256              "url": "https://www.openssh.com/portable.html",
288257              "type": "distribution"
288258            }
288259          ],
288260          "evidence": {},
288261          "signature": {
288262            "signature": {
288263              "publicKey": {}
288264            }
288265          },
288266          "modelCard": {
288267            "modelParameters": {
288268              "approach": {}
288269            },
288270            "quantitativeAnalysis": {
288271              "graphics": {}
288272            },
288273            "considerations": {}
288274          }
288275        },
288276        {
288277          "type": "library",
288278          "bom-ref": "pkg:apk/alpine/openssh-client-default@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=e25c4647c0a314b5",
288279          "supplier": {},
288280          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288281          "name": "openssh-client-default",
288282          "version": "9.0_p1-r2",
288283          "description": "OpenBSD's SSH client",
288284          "licenses": [
288285            {
288286              "license": {
288287                "name": "BSD"
288288              }
288289            }
288290          ],
288291          "cpe": "cpe:2.3:a:openssh-client-default:openssh-client-default:9.0_p1-r2:*:*:*:*:*:*:*",
288292          "purl": "pkg:apk/alpine/openssh-client-default@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
288293          "swid": {
288294            "attachment": {}
288295          },
288296          "pedigree": {},
288297          "externalReferences": [
288298            {
288299              "url": "https://www.openssh.com/portable.html",
288300              "type": "distribution"
288301            }
288302          ],
288303          "evidence": {},
288304          "signature": {
288305            "signature": {
288306              "publicKey": {}
288307            }
288308          },
288309          "modelCard": {
288310            "modelParameters": {
288311              "approach": {}
288312            },
288313            "quantitativeAnalysis": {
288314              "graphics": {}
288315            },
288316            "considerations": {}
288317          }
288318        },
288319        {
288320          "type": "library",
288321          "bom-ref": "pkg:apk/alpine/openssh-keygen@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=f68b16c70b1e9cd5",
288322          "supplier": {},
288323          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288324          "name": "openssh-keygen",
288325          "version": "9.0_p1-r2",
288326          "description": "ssh helper program for generating keys",
288327          "licenses": [
288328            {
288329              "license": {
288330                "name": "BSD"
288331              }
288332            }
288333          ],
288334          "cpe": "cpe:2.3:a:openssh-keygen:openssh-keygen:9.0_p1-r2:*:*:*:*:*:*:*",
288335          "purl": "pkg:apk/alpine/openssh-keygen@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
288336          "swid": {
288337            "attachment": {}
288338          },
288339          "pedigree": {},
288340          "externalReferences": [
288341            {
288342              "url": "https://www.openssh.com/portable.html",
288343              "type": "distribution"
288344            }
288345          ],
288346          "evidence": {},
288347          "signature": {
288348            "signature": {
288349              "publicKey": {}
288350            }
288351          },
288352          "modelCard": {
288353            "modelParameters": {
288354              "approach": {}
288355            },
288356            "quantitativeAnalysis": {
288357              "graphics": {}
288358            },
288359            "considerations": {}
288360          }
288361        },
288362        {
288363          "type": "library",
288364          "bom-ref": "pkg:apk/alpine/openssh-server@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=c965d48edfd50c41",
288365          "supplier": {},
288366          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288367          "name": "openssh-server",
288368          "version": "9.0_p1-r2",
288369          "description": "OpenSSH server",
288370          "licenses": [
288371            {
288372              "license": {
288373                "name": "BSD"
288374              }
288375            }
288376          ],
288377          "cpe": "cpe:2.3:a:openssh-server:openssh-server:9.0_p1-r2:*:*:*:*:*:*:*",
288378          "purl": "pkg:apk/alpine/openssh-server@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
288379          "swid": {
288380            "attachment": {}
288381          },
288382          "pedigree": {},
288383          "externalReferences": [
288384            {
288385              "url": "https://www.openssh.com/portable.html",
288386              "type": "distribution"
288387            }
288388          ],
288389          "evidence": {},
288390          "signature": {
288391            "signature": {
288392              "publicKey": {}
288393            }
288394          },
288395          "modelCard": {
288396            "modelParameters": {
288397              "approach": {}
288398            },
288399            "quantitativeAnalysis": {
288400              "graphics": {}
288401            },
288402            "considerations": {}
288403          }
288404        },
288405        {
288406          "type": "library",
288407          "bom-ref": "pkg:apk/alpine/openssh-server-common@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=28229e04c06729a4",
288408          "supplier": {},
288409          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288410          "name": "openssh-server-common",
288411          "version": "9.0_p1-r2",
288412          "description": "OpenSSH server configuration files",
288413          "licenses": [
288414            {
288415              "license": {
288416                "name": "BSD"
288417              }
288418            }
288419          ],
288420          "cpe": "cpe:2.3:a:openssh-server-common:openssh-server-common:9.0_p1-r2:*:*:*:*:*:*:*",
288421          "purl": "pkg:apk/alpine/openssh-server-common@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
288422          "swid": {
288423            "attachment": {}
288424          },
288425          "pedigree": {},
288426          "externalReferences": [
288427            {
288428              "url": "https://www.openssh.com/portable.html",
288429              "type": "distribution"
288430            }
288431          ],
288432          "evidence": {},
288433          "signature": {
288434            "signature": {
288435              "publicKey": {}
288436            }
288437          },
288438          "modelCard": {
288439            "modelParameters": {
288440              "approach": {}
288441            },
288442            "quantitativeAnalysis": {
288443              "graphics": {}
288444            },
288445            "considerations": {}
288446          }
288447        },
288448        {
288449          "type": "library",
288450          "bom-ref": "pkg:apk/alpine/openssh-sftp-server@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5\u0026package-id=6fe5b21b307e0521",
288451          "supplier": {},
288452          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288453          "name": "openssh-sftp-server",
288454          "version": "9.0_p1-r2",
288455          "description": "ssh sftp server module",
288456          "licenses": [
288457            {
288458              "license": {
288459                "name": "BSD"
288460              }
288461            }
288462          ],
288463          "cpe": "cpe:2.3:a:openssh-sftp-server:openssh-sftp-server:9.0_p1-r2:*:*:*:*:*:*:*",
288464          "purl": "pkg:apk/alpine/openssh-sftp-server@9.0_p1-r2?arch=x86_64\u0026upstream=openssh\u0026distro=alpine-3.16.5",
288465          "swid": {
288466            "attachment": {}
288467          },
288468          "pedigree": {},
288469          "externalReferences": [
288470            {
288471              "url": "https://www.openssh.com/portable.html",
288472              "type": "distribution"
288473            }
288474          ],
288475          "evidence": {},
288476          "signature": {
288477            "signature": {
288478              "publicKey": {}
288479            }
288480          },
288481          "modelCard": {
288482            "modelParameters": {
288483              "approach": {}
288484            },
288485            "quantitativeAnalysis": {
288486              "graphics": {}
288487            },
288488            "considerations": {}
288489          }
288490        },
288491        {
288492          "type": "library",
288493          "bom-ref": "pkg:apk/alpine/openssl@1.1.1t-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=d95cfbb74f91afb7",
288494          "supplier": {},
288495          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
288496          "name": "openssl",
288497          "version": "1.1.1t-r2",
288498          "description": "toolkit for transport layer security (TLS) - version 1.1",
288499          "licenses": [
288500            {
288501              "license": {
288502                "id": "OpenSSL"
288503              }
288504            }
288505          ],
288506          "cpe": "cpe:2.3:a:openssl:openssl:1.1.1t-r2:*:*:*:*:*:*:*",
288507          "purl": "pkg:apk/alpine/openssl@1.1.1t-r2?arch=x86_64\u0026distro=alpine-3.16.5",
288508          "swid": {
288509            "attachment": {}
288510          },
288511          "pedigree": {},
288512          "externalReferences": [
288513            {
288514              "url": "https://www.openssl.org/",
288515              "type": "distribution"
288516            }
288517          ],
288518          "evidence": {},
288519          "signature": {
288520            "signature": {
288521              "publicKey": {}
288522            }
288523          },
288524          "modelCard": {
288525            "modelParameters": {
288526              "approach": {}
288527            },
288528            "quantitativeAnalysis": {
288529              "graphics": {}
288530            },
288531            "considerations": {}
288532          }
288533        },
288534        {
288535          "type": "library",
288536          "bom-ref": "pkg:apk/alpine/openssl-dev@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=cb7667934e8f9a17",
288537          "supplier": {},
288538          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
288539          "name": "openssl-dev",
288540          "version": "1.1.1t-r2",
288541          "description": "toolkit for transport layer security (TLS) - version 1.1 (development files)",
288542          "licenses": [
288543            {
288544              "license": {
288545                "id": "OpenSSL"
288546              }
288547            }
288548          ],
288549          "cpe": "cpe:2.3:a:openssl-dev:openssl-dev:1.1.1t-r2:*:*:*:*:*:*:*",
288550          "purl": "pkg:apk/alpine/openssl-dev@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
288551          "swid": {
288552            "attachment": {}
288553          },
288554          "pedigree": {},
288555          "externalReferences": [
288556            {
288557              "url": "https://www.openssl.org/",
288558              "type": "distribution"
288559            }
288560          ],
288561          "evidence": {},
288562          "signature": {
288563            "signature": {
288564              "publicKey": {}
288565            }
288566          },
288567          "modelCard": {
288568            "modelParameters": {
288569              "approach": {}
288570            },
288571            "quantitativeAnalysis": {
288572              "graphics": {}
288573            },
288574            "considerations": {}
288575          }
288576        },
288577        {
288578          "type": "library",
288579          "bom-ref": "pkg:pypi/ordered-set@4.0.2?package-id=e389023f44616ed7",
288580          "supplier": {},
288581          "name": "ordered-set",
288582          "version": "4.0.2",
288583          "licenses": [
288584            {
288585              "license": {
288586                "name": "MIT-LICENSE"
288587              }
288588            }
288589          ],
288590          "cpe": "cpe:2.3:a:python-ordered-set:python-ordered-set:4.0.2:*:*:*:*:*:*:*",
288591          "purl": "pkg:pypi/ordered-set@4.0.2",
288592          "swid": {
288593            "attachment": {}
288594          },
288595          "pedigree": {},
288596          "evidence": {},
288597          "signature": {
288598            "signature": {
288599              "publicKey": {}
288600            }
288601          },
288602          "modelCard": {
288603            "modelParameters": {
288604              "approach": {}
288605            },
288606            "quantitativeAnalysis": {
288607              "graphics": {}
288608            },
288609            "considerations": {}
288610          }
288611        },
288612        {
288613          "type": "library",
288614          "bom-ref": "pkg:pypi/packaging@21.3?package-id=8adac1d6361364de",
288615          "supplier": {},
288616          "author": "Donald Stufft and individual contributors \u003cdonald@stufft.io\u003e",
288617          "name": "packaging",
288618          "version": "21.3",
288619          "licenses": [
288620            {
288621              "license": {
288622                "name": "BSD-2-Clause or Apache-2.0"
288623              }
288624            }
288625          ],
288626          "cpe": "cpe:2.3:a:donald_stufft_and_individual_contributors_project:python-packaging:21.3:*:*:*:*:*:*:*",
288627          "purl": "pkg:pypi/packaging@21.3",
288628          "swid": {
288629            "attachment": {}
288630          },
288631          "pedigree": {},
288632          "evidence": {},
288633          "signature": {
288634            "signature": {
288635              "publicKey": {}
288636            }
288637          },
288638          "modelCard": {
288639            "modelParameters": {
288640              "approach": {}
288641            },
288642            "quantitativeAnalysis": {
288643              "graphics": {}
288644            },
288645            "considerations": {}
288646          }
288647        },
288648        {
288649          "type": "library",
288650          "bom-ref": "pkg:pypi/packaging@23.1?package-id=5a324951ccac3547",
288651          "supplier": {},
288652          "author": "Donald Stufft \u003cdonald@stufft.io\u003e",
288653          "name": "packaging",
288654          "version": "23.1",
288655          "cpe": "cpe:2.3:a:donald_stufft_\\\u003cdonald_project:python-packaging:23.1:*:*:*:*:*:*:*",
288656          "purl": "pkg:pypi/packaging@23.1",
288657          "swid": {
288658            "attachment": {}
288659          },
288660          "pedigree": {},
288661          "evidence": {},
288662          "signature": {
288663            "signature": {
288664              "publicKey": {}
288665            }
288666          },
288667          "modelCard": {
288668            "modelParameters": {
288669              "approach": {}
288670            },
288671            "quantitativeAnalysis": {
288672              "graphics": {}
288673            },
288674            "considerations": {}
288675          }
288676        },
288677        {
288678          "type": "library",
288679          "bom-ref": "pkg:pypi/paramiko@2.6.0?package-id=e4ce51e56faa9ae6",
288680          "supplier": {},
288681          "author": "Jeff Forcier \u003cjeff@bitprophet.org\u003e",
288682          "name": "paramiko",
288683          "version": "2.6.0",
288684          "licenses": [
288685            {
288686              "license": {
288687                "name": "LGPL"
288688              }
288689            }
288690          ],
288691          "cpe": "cpe:2.3:a:jeff_forcier_project:python-paramiko:2.6.0:*:*:*:*:*:*:*",
288692          "purl": "pkg:pypi/paramiko@2.6.0",
288693          "swid": {
288694            "attachment": {}
288695          },
288696          "pedigree": {},
288697          "evidence": {},
288698          "signature": {
288699            "signature": {
288700              "publicKey": {}
288701            }
288702          },
288703          "modelCard": {
288704            "modelParameters": {
288705              "approach": {}
288706            },
288707            "quantitativeAnalysis": {
288708              "graphics": {}
288709            },
288710            "considerations": {}
288711          }
288712        },
288713        {
288714          "type": "library",
288715          "bom-ref": "pkg:apk/alpine/patch@2.7.6-r7?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=74b77c27934e2cfc",
288716          "supplier": {},
288717          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
288718          "name": "patch",
288719          "version": "2.7.6-r7",
288720          "description": "Utility to apply diffs to files",
288721          "licenses": [
288722            {
288723              "license": {
288724                "id": "GPL-3.0-or-later"
288725              }
288726            }
288727          ],
288728          "cpe": "cpe:2.3:a:patch:patch:2.7.6-r7:*:*:*:*:*:*:*",
288729          "purl": "pkg:apk/alpine/patch@2.7.6-r7?arch=x86_64\u0026distro=alpine-3.16.5",
288730          "swid": {
288731            "attachment": {}
288732          },
288733          "pedigree": {},
288734          "externalReferences": [
288735            {
288736              "url": "https://www.gnu.org/software/patch/patch.html",
288737              "type": "distribution"
288738            }
288739          ],
288740          "evidence": {},
288741          "signature": {
288742            "signature": {
288743              "publicKey": {}
288744            }
288745          },
288746          "modelCard": {
288747            "modelParameters": {
288748              "approach": {}
288749            },
288750            "quantitativeAnalysis": {
288751              "graphics": {}
288752            },
288753            "considerations": {}
288754          }
288755        },
288756        {
288757          "type": "library",
288758          "bom-ref": "pkg:pypi/pep517@0.12.0?package-id=6112c8190029179c",
288759          "supplier": {},
288760          "author": "Thomas Kluyver \u003cthomas@kluyver.me.uk\u003e",
288761          "name": "pep517",
288762          "version": "0.12.0",
288763          "licenses": [
288764            {
288765              "license": {
288766                "name": "UNKNOWN"
288767              }
288768            }
288769          ],
288770          "cpe": "cpe:2.3:a:thomas_kluyver_project:python-pep517:0.12.0:*:*:*:*:*:*:*",
288771          "purl": "pkg:pypi/pep517@0.12.0",
288772          "swid": {
288773            "attachment": {}
288774          },
288775          "pedigree": {},
288776          "evidence": {},
288777          "signature": {
288778            "signature": {
288779              "publicKey": {}
288780            }
288781          },
288782          "modelCard": {
288783            "modelParameters": {
288784              "approach": {}
288785            },
288786            "quantitativeAnalysis": {
288787              "graphics": {}
288788            },
288789            "considerations": {}
288790          }
288791        },
288792        {
288793          "type": "library",
288794          "bom-ref": "pkg:pypi/pexpect@4.7.0?package-id=7774c979cf213f91",
288795          "supplier": {},
288796          "author": "Noah Spurrier; Thomas Kluyver; Jeff Quast \u003cnoah@noah.org, thomas@kluyver.me.uk, contact@jeffquast.com\u003e",
288797          "name": "pexpect",
288798          "version": "4.7.0",
288799          "licenses": [
288800            {
288801              "license": {
288802                "name": "ISC license"
288803              }
288804            }
288805          ],
288806          "cpe": "cpe:2.3:a:noah_spurrier\\;_thomas_kluyver\\;_jeff_quast_project:python-pexpect:4.7.0:*:*:*:*:*:*:*",
288807          "purl": "pkg:pypi/pexpect@4.7.0",
288808          "swid": {
288809            "attachment": {}
288810          },
288811          "pedigree": {},
288812          "evidence": {},
288813          "signature": {
288814            "signature": {
288815              "publicKey": {}
288816            }
288817          },
288818          "modelCard": {
288819            "modelParameters": {
288820              "approach": {}
288821            },
288822            "quantitativeAnalysis": {
288823              "graphics": {}
288824            },
288825            "considerations": {}
288826          }
288827        },
288828        {
288829          "type": "library",
288830          "bom-ref": "pkg:pypi/pip@22.0.4?package-id=2662dd9050ca781b",
288831          "supplier": {},
288832          "author": "The pip developers \u003cdistutils-sig@python.org\u003e",
288833          "name": "pip",
288834          "version": "22.0.4",
288835          "licenses": [
288836            {
288837              "license": {
288838                "id": "MIT"
288839              }
288840            }
288841          ],
288842          "cpe": "cpe:2.3:a:pip_developers_project:python-pip:22.0.4:*:*:*:*:*:*:*",
288843          "purl": "pkg:pypi/pip@22.0.4",
288844          "swid": {
288845            "attachment": {}
288846          },
288847          "pedigree": {},
288848          "evidence": {},
288849          "signature": {
288850            "signature": {
288851              "publicKey": {}
288852            }
288853          },
288854          "modelCard": {
288855            "modelParameters": {
288856              "approach": {}
288857            },
288858            "quantitativeAnalysis": {
288859              "graphics": {}
288860            },
288861            "considerations": {}
288862          }
288863        },
288864        {
288865          "type": "library",
288866          "bom-ref": "pkg:pypi/pip@22.1.1?package-id=1446eeabf64d1c52",
288867          "supplier": {},
288868          "author": "The pip developers \u003cdistutils-sig@python.org\u003e",
288869          "name": "pip",
288870          "version": "22.1.1",
288871          "licenses": [
288872            {
288873              "license": {
288874                "id": "MIT"
288875              }
288876            }
288877          ],
288878          "cpe": "cpe:2.3:a:pip_developers_project:python-pip:22.1.1:*:*:*:*:*:*:*",
288879          "purl": "pkg:pypi/pip@22.1.1",
288880          "swid": {
288881            "attachment": {}
288882          },
288883          "pedigree": {},
288884          "evidence": {},
288885          "signature": {
288886            "signature": {
288887              "publicKey": {}
288888            }
288889          },
288890          "modelCard": {
288891            "modelParameters": {
288892              "approach": {}
288893            },
288894            "quantitativeAnalysis": {
288895              "graphics": {}
288896            },
288897            "considerations": {}
288898          }
288899        },
288900        {
288901          "type": "library",
288902          "bom-ref": "pkg:pypi/pip@23.0.1?package-id=5db0c62dfc43a949",
288903          "supplier": {},
288904          "author": "The pip developers \u003cdistutils-sig@python.org\u003e",
288905          "name": "pip",
288906          "version": "23.0.1",
288907          "licenses": [
288908            {
288909              "license": {
288910                "id": "MIT"
288911              }
288912            }
288913          ],
288914          "cpe": "cpe:2.3:a:pip_developers_project:python-pip:23.0.1:*:*:*:*:*:*:*",
288915          "purl": "pkg:pypi/pip@23.0.1",
288916          "swid": {
288917            "attachment": {}
288918          },
288919          "pedigree": {},
288920          "evidence": {},
288921          "signature": {
288922            "signature": {
288923              "publicKey": {}
288924            }
288925          },
288926          "modelCard": {
288927            "modelParameters": {
288928              "approach": {}
288929            },
288930            "quantitativeAnalysis": {
288931              "graphics": {}
288932            },
288933            "considerations": {}
288934          }
288935        },
288936        {
288937          "type": "library",
288938          "bom-ref": "pkg:pypi/pip-licenses@4.2.0?package-id=60dc224797b0c9ce",
288939          "supplier": {},
288940          "author": "raimon \u003craimon49@hotmail.com\u003e",
288941          "name": "pip-licenses",
288942          "version": "4.2.0",
288943          "licenses": [
288944            {
288945              "license": {
288946                "id": "MIT"
288947              }
288948            }
288949          ],
288950          "cpe": "cpe:2.3:a:python-pip-licenses:python-pip-licenses:4.2.0:*:*:*:*:*:*:*",
288951          "purl": "pkg:pypi/pip-licenses@4.2.0",
288952          "swid": {
288953            "attachment": {}
288954          },
288955          "pedigree": {},
288956          "evidence": {},
288957          "signature": {
288958            "signature": {
288959              "publicKey": {}
288960            }
288961          },
288962          "modelCard": {
288963            "modelParameters": {
288964              "approach": {}
288965            },
288966            "quantitativeAnalysis": {
288967              "graphics": {}
288968            },
288969            "considerations": {}
288970          }
288971        },
288972        {
288973          "type": "library",
288974          "bom-ref": "pkg:apk/alpine/pkgconf@1.8.1-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=54d74b2ddb213964",
288975          "supplier": {},
288976          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
288977          "name": "pkgconf",
288978          "version": "1.8.1-r0",
288979          "description": "development framework configuration tools",
288980          "licenses": [
288981            {
288982              "license": {
288983                "id": "ISC"
288984              }
288985            }
288986          ],
288987          "cpe": "cpe:2.3:a:pkgconf:pkgconf:1.8.1-r0:*:*:*:*:*:*:*",
288988          "purl": "pkg:apk/alpine/pkgconf@1.8.1-r0?arch=x86_64\u0026distro=alpine-3.16.5",
288989          "swid": {
288990            "attachment": {}
288991          },
288992          "pedigree": {},
288993          "externalReferences": [
288994            {
288995              "url": "https://git.sr.ht/~kaniini/pkgconf",
288996              "type": "distribution"
288997            }
288998          ],
288999          "evidence": {},
289000          "signature": {
289001            "signature": {
289002              "publicKey": {}
289003            }
289004          },
289005          "modelCard": {
289006            "modelParameters": {
289007              "approach": {}
289008            },
289009            "quantitativeAnalysis": {
289010              "graphics": {}
289011            },
289012            "considerations": {}
289013          }
289014        },
289015        {
289016          "type": "library",
289017          "bom-ref": "pkg:pypi/ply@3.11?package-id=88cf0fb6dd1ec938",
289018          "supplier": {},
289019          "author": "David Beazley \u003cdave@dabeaz.com\u003e",
289020          "name": "ply",
289021          "version": "3.11",
289022          "licenses": [
289023            {
289024              "license": {
289025                "name": "BSD"
289026              }
289027            }
289028          ],
289029          "cpe": "cpe:2.3:a:david_beazley_project:python-ply:3.11:*:*:*:*:*:*:*",
289030          "purl": "pkg:pypi/ply@3.11",
289031          "swid": {
289032            "attachment": {}
289033          },
289034          "pedigree": {},
289035          "evidence": {},
289036          "signature": {
289037            "signature": {
289038              "publicKey": {}
289039            }
289040          },
289041          "modelCard": {
289042            "modelParameters": {
289043              "approach": {}
289044            },
289045            "quantitativeAnalysis": {
289046              "graphics": {}
289047            },
289048            "considerations": {}
289049          }
289050        },
289051        {
289052          "type": "library",
289053          "bom-ref": "pkg:pypi/prettytable@3.7.0?package-id=b276023c781fad69",
289054          "supplier": {},
289055          "author": "Luke Maurits \u003cluke@maurits.id.au\u003e",
289056          "name": "prettytable",
289057          "version": "3.7.0",
289058          "licenses": [
289059            {
289060              "license": {
289061                "name": "BSD (3 clause)"
289062              }
289063            }
289064          ],
289065          "cpe": "cpe:2.3:a:luke_maurits_\\\u003cluke_project:python-prettytable:3.7.0:*:*:*:*:*:*:*",
289066          "purl": "pkg:pypi/prettytable@3.7.0",
289067          "swid": {
289068            "attachment": {}
289069          },
289070          "pedigree": {},
289071          "evidence": {},
289072          "signature": {
289073            "signature": {
289074              "publicKey": {}
289075            }
289076          },
289077          "modelCard": {
289078            "modelParameters": {
289079              "approach": {}
289080            },
289081            "quantitativeAnalysis": {
289082              "graphics": {}
289083            },
289084            "considerations": {}
289085          }
289086        },
289087        {
289088          "type": "library",
289089          "bom-ref": "pkg:pypi/psutil@5.6.3?package-id=ea6f035c5fabe817",
289090          "supplier": {},
289091          "author": "Giampaolo Rodola \u003cg.rodola@gmail.com\u003e",
289092          "name": "psutil",
289093          "version": "5.6.3",
289094          "licenses": [
289095            {
289096              "license": {
289097                "name": "BSD"
289098              }
289099            }
289100          ],
289101          "cpe": "cpe:2.3:a:giampaolo_rodola_project:python-psutil:5.6.3:*:*:*:*:*:*:*",
289102          "purl": "pkg:pypi/psutil@5.6.3",
289103          "swid": {
289104            "attachment": {}
289105          },
289106          "pedigree": {},
289107          "evidence": {},
289108          "signature": {
289109            "signature": {
289110              "publicKey": {}
289111            }
289112          },
289113          "modelCard": {
289114            "modelParameters": {
289115              "approach": {}
289116            },
289117            "quantitativeAnalysis": {
289118              "graphics": {}
289119            },
289120            "considerations": {}
289121          }
289122        },
289123        {
289124          "type": "library",
289125          "bom-ref": "pkg:pypi/ptyprocess@0.6.0?package-id=f5f209a3f8eea68d",
289126          "supplier": {},
289127          "author": "Thomas Kluyver \u003cthomas@kluyver.me.uk\u003e",
289128          "name": "ptyprocess",
289129          "version": "0.6.0",
289130          "licenses": [
289131            {
289132              "license": {
289133                "name": "UNKNOWN"
289134              }
289135            }
289136          ],
289137          "cpe": "cpe:2.3:a:thomas_kluyver_project:python-ptyprocess:0.6.0:*:*:*:*:*:*:*",
289138          "purl": "pkg:pypi/ptyprocess@0.6.0",
289139          "swid": {
289140            "attachment": {}
289141          },
289142          "pedigree": {},
289143          "evidence": {},
289144          "signature": {
289145            "signature": {
289146              "publicKey": {}
289147            }
289148          },
289149          "modelCard": {
289150            "modelParameters": {
289151              "approach": {}
289152            },
289153            "quantitativeAnalysis": {
289154              "graphics": {}
289155            },
289156            "considerations": {}
289157          }
289158        },
289159        {
289160          "type": "library",
289161          "bom-ref": "pkg:apk/alpine/py3-appdirs@1.4.4-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=485881cbb9104991",
289162          "supplier": {},
289163          "publisher": "Keith Maxwell \u003ckeith.maxwell@gmail.com\u003e",
289164          "name": "py3-appdirs",
289165          "version": "1.4.4-r3",
289166          "description": "A small Python module for determining appropriate platform-specific dirs.",
289167          "licenses": [
289168            {
289169              "license": {
289170                "id": "MIT"
289171              }
289172            }
289173          ],
289174          "cpe": "cpe:2.3:a:appdirs-project:py3-appdirs:1.4.4-r3:*:*:*:*:*:*:*",
289175          "purl": "pkg:apk/alpine/py3-appdirs@1.4.4-r3?arch=x86_64\u0026distro=alpine-3.16.5",
289176          "swid": {
289177            "attachment": {}
289178          },
289179          "pedigree": {},
289180          "externalReferences": [
289181            {
289182              "url": "https://pypi.org/project/appdirs/",
289183              "type": "distribution"
289184            }
289185          ],
289186          "evidence": {},
289187          "signature": {
289188            "signature": {
289189              "publicKey": {}
289190            }
289191          },
289192          "modelCard": {
289193            "modelParameters": {
289194              "approach": {}
289195            },
289196            "quantitativeAnalysis": {
289197              "graphics": {}
289198            },
289199            "considerations": {}
289200          }
289201        },
289202        {
289203          "type": "library",
289204          "bom-ref": "pkg:apk/alpine/py3-cffi@1.15.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=e841a659b3479dc4",
289205          "supplier": {},
289206          "name": "py3-cffi",
289207          "version": "1.15.0-r0",
289208          "description": "Foreign function interface for calling C code from Python3",
289209          "licenses": [
289210            {
289211              "license": {
289212                "id": "MIT"
289213              }
289214            }
289215          ],
289216          "cpe": "cpe:2.3:a:cffi-project:py3-cffi:1.15.0-r0:*:*:*:*:*:*:*",
289217          "purl": "pkg:apk/alpine/py3-cffi@1.15.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
289218          "swid": {
289219            "attachment": {}
289220          },
289221          "pedigree": {},
289222          "externalReferences": [
289223            {
289224              "url": "http://cffi.readthedocs.org/",
289225              "type": "distribution"
289226            }
289227          ],
289228          "evidence": {},
289229          "signature": {
289230            "signature": {
289231              "publicKey": {}
289232            }
289233          },
289234          "modelCard": {
289235            "modelParameters": {
289236              "approach": {}
289237            },
289238            "quantitativeAnalysis": {
289239              "graphics": {}
289240            },
289241            "considerations": {}
289242          }
289243        },
289244        {
289245          "type": "library",
289246          "bom-ref": "pkg:apk/alpine/py3-contextlib2@21.6.0-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=8e76c74c36f884f8",
289247          "supplier": {},
289248          "name": "py3-contextlib2",
289249          "version": "21.6.0-r2",
289250          "description": "Proving ground for contextlib from Python3",
289251          "licenses": [
289252            {
289253              "license": {
289254                "id": "PSF-2.0"
289255              }
289256            },
289257            {
289258              "license": {
289259                "name": "AND"
289260              }
289261            },
289262            {
289263              "license": {
289264                "id": "Apache-2.0"
289265              }
289266            }
289267          ],
289268          "cpe": "cpe:2.3:a:contextlib2-project:py3-contextlib2:21.6.0-r2:*:*:*:*:*:*:*",
289269          "purl": "pkg:apk/alpine/py3-contextlib2@21.6.0-r2?arch=x86_64\u0026distro=alpine-3.16.5",
289270          "swid": {
289271            "attachment": {}
289272          },
289273          "pedigree": {},
289274          "externalReferences": [
289275            {
289276              "url": "https://github.com/jazzband/contextlib2",
289277              "type": "distribution"
289278            }
289279          ],
289280          "evidence": {},
289281          "signature": {
289282            "signature": {
289283              "publicKey": {}
289284            }
289285          },
289286          "modelCard": {
289287            "modelParameters": {
289288              "approach": {}
289289            },
289290            "quantitativeAnalysis": {
289291              "graphics": {}
289292            },
289293            "considerations": {}
289294          }
289295        },
289296        {
289297          "type": "library",
289298          "bom-ref": "pkg:apk/alpine/py3-cparser@2.20-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=bdddc91ccde91e0f",
289299          "supplier": {},
289300          "name": "py3-cparser",
289301          "version": "2.20-r2",
289302          "description": "C parser written in Python3",
289303          "licenses": [
289304            {
289305              "license": {
289306                "id": "BSD-3-Clause"
289307              }
289308            }
289309          ],
289310          "cpe": "cpe:2.3:a:cparser-project:py3-cparser:2.20-r2:*:*:*:*:*:*:*",
289311          "purl": "pkg:apk/alpine/py3-cparser@2.20-r2?arch=x86_64\u0026distro=alpine-3.16.5",
289312          "swid": {
289313            "attachment": {}
289314          },
289315          "pedigree": {},
289316          "externalReferences": [
289317            {
289318              "url": "https://github.com/eliben/pycparser",
289319              "type": "distribution"
289320            }
289321          ],
289322          "evidence": {},
289323          "signature": {
289324            "signature": {
289325              "publicKey": {}
289326            }
289327          },
289328          "modelCard": {
289329            "modelParameters": {
289330              "approach": {}
289331            },
289332            "quantitativeAnalysis": {
289333              "graphics": {}
289334            },
289335            "considerations": {}
289336          }
289337        },
289338        {
289339          "type": "library",
289340          "bom-ref": "pkg:apk/alpine/py3-cryptography@3.4.8-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=9a8ae52a62e5a5af",
289341          "supplier": {},
289342          "publisher": "August Klein \u003camatcoder@gmail.com\u003e",
289343          "name": "py3-cryptography",
289344          "version": "3.4.8-r1",
289345          "description": "Cryptographic recipes and primitives for Python",
289346          "licenses": [
289347            {
289348              "license": {
289349                "id": "Apache-2.0"
289350              }
289351            },
289352            {
289353              "license": {
289354                "name": "OR"
289355              }
289356            },
289357            {
289358              "license": {
289359                "id": "BSD-3-Clause"
289360              }
289361            }
289362          ],
289363          "cpe": "cpe:2.3:a:python-cryptography-project:python-cryptography:3.4.8-r1:*:*:*:*:*:*:*",
289364          "purl": "pkg:apk/alpine/py3-cryptography@3.4.8-r1?arch=x86_64\u0026distro=alpine-3.16.5",
289365          "swid": {
289366            "attachment": {}
289367          },
289368          "pedigree": {},
289369          "externalReferences": [
289370            {
289371              "url": "https://cryptography.io/",
289372              "type": "distribution"
289373            }
289374          ],
289375          "evidence": {},
289376          "signature": {
289377            "signature": {
289378              "publicKey": {}
289379            }
289380          },
289381          "modelCard": {
289382            "modelParameters": {
289383              "approach": {}
289384            },
289385            "quantitativeAnalysis": {
289386              "graphics": {}
289387            },
289388            "considerations": {}
289389          }
289390        },
289391        {
289392          "type": "library",
289393          "bom-ref": "pkg:apk/alpine/py3-idna@3.3-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=92925b85f40ff209",
289394          "supplier": {},
289395          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
289396          "name": "py3-idna",
289397          "version": "3.3-r2",
289398          "description": "IDNA 2008 and UTS #46 for Python3",
289399          "licenses": [
289400            {
289401              "license": {
289402                "id": "BSD-3-Clause"
289403              }
289404            }
289405          ],
289406          "cpe": "cpe:2.3:a:idna-project:py3-idna:3.3-r2:*:*:*:*:*:*:*",
289407          "purl": "pkg:apk/alpine/py3-idna@3.3-r2?arch=x86_64\u0026distro=alpine-3.16.5",
289408          "swid": {
289409            "attachment": {}
289410          },
289411          "pedigree": {},
289412          "externalReferences": [
289413            {
289414              "url": "https://github.com/kjd/idna",
289415              "type": "distribution"
289416            }
289417          ],
289418          "evidence": {},
289419          "signature": {
289420            "signature": {
289421              "publicKey": {}
289422            }
289423          },
289424          "modelCard": {
289425            "modelParameters": {
289426              "approach": {}
289427            },
289428            "quantitativeAnalysis": {
289429              "graphics": {}
289430            },
289431            "considerations": {}
289432          }
289433        },
289434        {
289435          "type": "library",
289436          "bom-ref": "pkg:apk/alpine/py3-more-itertools@8.13.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=c539a2cdeed7752b",
289437          "supplier": {},
289438          "publisher": "TBK \u003calpine@jjtc.eu\u003e",
289439          "name": "py3-more-itertools",
289440          "version": "8.13.0-r0",
289441          "description": "More routines for operating on iterables, beyond itertools",
289442          "licenses": [
289443            {
289444              "license": {
289445                "id": "MIT"
289446              }
289447            }
289448          ],
289449          "cpe": "cpe:2.3:a:more-itertools-project:py3-more-itertools:8.13.0-r0:*:*:*:*:*:*:*",
289450          "purl": "pkg:apk/alpine/py3-more-itertools@8.13.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
289451          "swid": {
289452            "attachment": {}
289453          },
289454          "pedigree": {},
289455          "externalReferences": [
289456            {
289457              "url": "https://github.com/more-itertools/more-itertools",
289458              "type": "distribution"
289459            }
289460          ],
289461          "evidence": {},
289462          "signature": {
289463            "signature": {
289464              "publicKey": {}
289465            }
289466          },
289467          "modelCard": {
289468            "modelParameters": {
289469              "approach": {}
289470            },
289471            "quantitativeAnalysis": {
289472              "graphics": {}
289473            },
289474            "considerations": {}
289475          }
289476        },
289477        {
289478          "type": "library",
289479          "bom-ref": "pkg:apk/alpine/py3-openssl@21.0.0-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=8e5b8dfff545e548",
289480          "supplier": {},
289481          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
289482          "name": "py3-openssl",
289483          "version": "21.0.0-r1",
289484          "description": "Python3 wrapper module around the OpenSSL library",
289485          "licenses": [
289486            {
289487              "license": {
289488                "id": "Apache-2.0"
289489              }
289490            }
289491          ],
289492          "cpe": "cpe:2.3:a:openssl-project:py3-openssl:21.0.0-r1:*:*:*:*:*:*:*",
289493          "purl": "pkg:apk/alpine/py3-openssl@21.0.0-r1?arch=x86_64\u0026distro=alpine-3.16.5",
289494          "swid": {
289495            "attachment": {}
289496          },
289497          "pedigree": {},
289498          "externalReferences": [
289499            {
289500              "url": "https://github.com/pyca/pyopenssl",
289501              "type": "distribution"
289502            }
289503          ],
289504          "evidence": {},
289505          "signature": {
289506            "signature": {
289507              "publicKey": {}
289508            }
289509          },
289510          "modelCard": {
289511            "modelParameters": {
289512              "approach": {}
289513            },
289514            "quantitativeAnalysis": {
289515              "graphics": {}
289516            },
289517            "considerations": {}
289518          }
289519        },
289520        {
289521          "type": "library",
289522          "bom-ref": "pkg:apk/alpine/py3-ordered-set@4.0.2-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=ffc2d715e09abd5b",
289523          "supplier": {},
289524          "name": "py3-ordered-set",
289525          "version": "4.0.2-r3",
289526          "description": "MutableSet that remembers its order",
289527          "licenses": [
289528            {
289529              "license": {
289530                "id": "MIT"
289531              }
289532            }
289533          ],
289534          "cpe": "cpe:2.3:a:ordered-set-project:py3-ordered-set:4.0.2-r3:*:*:*:*:*:*:*",
289535          "purl": "pkg:apk/alpine/py3-ordered-set@4.0.2-r3?arch=x86_64\u0026distro=alpine-3.16.5",
289536          "swid": {
289537            "attachment": {}
289538          },
289539          "pedigree": {},
289540          "externalReferences": [
289541            {
289542              "url": "https://github.com/LuminosoInsight/ordered-set",
289543              "type": "distribution"
289544            }
289545          ],
289546          "evidence": {},
289547          "signature": {
289548            "signature": {
289549              "publicKey": {}
289550            }
289551          },
289552          "modelCard": {
289553            "modelParameters": {
289554              "approach": {}
289555            },
289556            "quantitativeAnalysis": {
289557              "graphics": {}
289558            },
289559            "considerations": {}
289560          }
289561        },
289562        {
289563          "type": "library",
289564          "bom-ref": "pkg:apk/alpine/py3-packaging@21.3-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=96cbdd2443a73b87",
289565          "supplier": {},
289566          "name": "py3-packaging",
289567          "version": "21.3-r0",
289568          "description": "Core utilities for Python3 packages",
289569          "licenses": [
289570            {
289571              "license": {
289572                "id": "Apache-2.0"
289573              }
289574            },
289575            {
289576              "license": {
289577                "name": "AND"
289578              }
289579            },
289580            {
289581              "license": {
289582                "id": "BSD-2-Clause"
289583              }
289584            }
289585          ],
289586          "cpe": "cpe:2.3:a:packaging-project:py3-packaging:21.3-r0:*:*:*:*:*:*:*",
289587          "purl": "pkg:apk/alpine/py3-packaging@21.3-r0?arch=x86_64\u0026distro=alpine-3.16.5",
289588          "swid": {
289589            "attachment": {}
289590          },
289591          "pedigree": {},
289592          "externalReferences": [
289593            {
289594              "url": "https://pypi.python.org/pypi/packaging",
289595              "type": "distribution"
289596            }
289597          ],
289598          "evidence": {},
289599          "signature": {
289600            "signature": {
289601              "publicKey": {}
289602            }
289603          },
289604          "modelCard": {
289605            "modelParameters": {
289606              "approach": {}
289607            },
289608            "quantitativeAnalysis": {
289609              "graphics": {}
289610            },
289611            "considerations": {}
289612          }
289613        },
289614        {
289615          "type": "library",
289616          "bom-ref": "pkg:apk/alpine/py3-parsing@2.4.7-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=56d00708afeded71",
289617          "supplier": {},
289618          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
289619          "name": "py3-parsing",
289620          "version": "2.4.7-r3",
289621          "description": "An object-oriented approach to text processing",
289622          "licenses": [
289623            {
289624              "license": {
289625                "id": "MIT"
289626              }
289627            }
289628          ],
289629          "cpe": "cpe:2.3:a:parsing-project:py3-parsing:2.4.7-r3:*:*:*:*:*:*:*",
289630          "purl": "pkg:apk/alpine/py3-parsing@2.4.7-r3?arch=x86_64\u0026distro=alpine-3.16.5",
289631          "swid": {
289632            "attachment": {}
289633          },
289634          "pedigree": {},
289635          "externalReferences": [
289636            {
289637              "url": "https://github.com/pyparsing/pyparsing",
289638              "type": "distribution"
289639            }
289640          ],
289641          "evidence": {},
289642          "signature": {
289643            "signature": {
289644              "publicKey": {}
289645            }
289646          },
289647          "modelCard": {
289648            "modelParameters": {
289649              "approach": {}
289650            },
289651            "quantitativeAnalysis": {
289652              "graphics": {}
289653            },
289654            "considerations": {}
289655          }
289656        },
289657        {
289658          "type": "library",
289659          "bom-ref": "pkg:apk/alpine/py3-pep517@0.12.0-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=ab4e2526e5fa9d87",
289660          "supplier": {},
289661          "publisher": "psykose \u003calice@ayaya.dev\u003e",
289662          "name": "py3-pep517",
289663          "version": "0.12.0-r2",
289664          "description": "Wrappers to build python3 packgaes with PEP 517 hooks",
289665          "licenses": [
289666            {
289667              "license": {
289668                "id": "MIT"
289669              }
289670            }
289671          ],
289672          "cpe": "cpe:2.3:a:pep517-project:py3-pep517:0.12.0-r2:*:*:*:*:*:*:*",
289673          "purl": "pkg:apk/alpine/py3-pep517@0.12.0-r2?arch=x86_64\u0026distro=alpine-3.16.5",
289674          "swid": {
289675            "attachment": {}
289676          },
289677          "pedigree": {},
289678          "externalReferences": [
289679            {
289680              "url": "https://github.com/pypa/pep517",
289681              "type": "distribution"
289682            }
289683          ],
289684          "evidence": {},
289685          "signature": {
289686            "signature": {
289687              "publicKey": {}
289688            }
289689          },
289690          "modelCard": {
289691            "modelParameters": {
289692              "approach": {}
289693            },
289694            "quantitativeAnalysis": {
289695              "graphics": {}
289696            },
289697            "considerations": {}
289698          }
289699        },
289700        {
289701          "type": "library",
289702          "bom-ref": "pkg:apk/alpine/py3-pip@22.1.1-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=f3ffc4c5baf06fc0",
289703          "supplier": {},
289704          "publisher": "Fabian Affolter \u003cfabian@affolter-engineering.ch\u003e",
289705          "name": "py3-pip",
289706          "version": "22.1.1-r0",
289707          "description": "Tool for installing and managing Python packages",
289708          "licenses": [
289709            {
289710              "license": {
289711                "id": "MIT"
289712              }
289713            }
289714          ],
289715          "cpe": "cpe:2.3:a:pip-project:py3-pip:22.1.1-r0:*:*:*:*:*:*:*",
289716          "purl": "pkg:apk/alpine/py3-pip@22.1.1-r0?arch=x86_64\u0026distro=alpine-3.16.5",
289717          "swid": {
289718            "attachment": {}
289719          },
289720          "pedigree": {},
289721          "externalReferences": [
289722            {
289723              "url": "http://www.pip-installer.org",
289724              "type": "distribution"
289725            }
289726          ],
289727          "evidence": {},
289728          "signature": {
289729            "signature": {
289730              "publicKey": {}
289731            }
289732          },
289733          "modelCard": {
289734            "modelParameters": {
289735              "approach": {}
289736            },
289737            "quantitativeAnalysis": {
289738              "graphics": {}
289739            },
289740            "considerations": {}
289741          }
289742        },
289743        {
289744          "type": "library",
289745          "bom-ref": "pkg:apk/alpine/py3-retrying@1.3.3-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=33fa125381bfce5b",
289746          "supplier": {},
289747          "name": "py3-retrying",
289748          "version": "1.3.3-r3",
289749          "description": "General purpose Python3 retrying library",
289750          "licenses": [
289751            {
289752              "license": {
289753                "id": "Apache-2.0"
289754              }
289755            }
289756          ],
289757          "cpe": "cpe:2.3:a:retrying-project:py3-retrying:1.3.3-r3:*:*:*:*:*:*:*",
289758          "purl": "pkg:apk/alpine/py3-retrying@1.3.3-r3?arch=x86_64\u0026distro=alpine-3.16.5",
289759          "swid": {
289760            "attachment": {}
289761          },
289762          "pedigree": {},
289763          "externalReferences": [
289764            {
289765              "url": "https://github.com/rholder/retrying/releases",
289766              "type": "distribution"
289767            }
289768          ],
289769          "evidence": {},
289770          "signature": {
289771            "signature": {
289772              "publicKey": {}
289773            }
289774          },
289775          "modelCard": {
289776            "modelParameters": {
289777              "approach": {}
289778            },
289779            "quantitativeAnalysis": {
289780              "graphics": {}
289781            },
289782            "considerations": {}
289783          }
289784        },
289785        {
289786          "type": "library",
289787          "bom-ref": "pkg:apk/alpine/py3-setuptools@59.4.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=52cce1a31d4319c7",
289788          "supplier": {},
289789          "publisher": "psykose \u003calice@ayaya.dev\u003e",
289790          "name": "py3-setuptools",
289791          "version": "59.4.0-r0",
289792          "description": "Collection of enhancements to the Python3 distutils",
289793          "licenses": [
289794            {
289795              "license": {
289796                "id": "MIT"
289797              }
289798            }
289799          ],
289800          "cpe": "cpe:2.3:a:setuptools-project:py3-setuptools:59.4.0-r0:*:*:*:*:*:*:*",
289801          "purl": "pkg:apk/alpine/py3-setuptools@59.4.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
289802          "swid": {
289803            "attachment": {}
289804          },
289805          "pedigree": {},
289806          "externalReferences": [
289807            {
289808              "url": "https://pypi.python.org/pypi/setuptools",
289809              "type": "distribution"
289810            }
289811          ],
289812          "evidence": {},
289813          "signature": {
289814            "signature": {
289815              "publicKey": {}
289816            }
289817          },
289818          "modelCard": {
289819            "modelParameters": {
289820              "approach": {}
289821            },
289822            "quantitativeAnalysis": {
289823              "graphics": {}
289824            },
289825            "considerations": {}
289826          }
289827        },
289828        {
289829          "type": "library",
289830          "bom-ref": "pkg:apk/alpine/py3-six@1.16.0-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=b3b1371f747548ed",
289831          "supplier": {},
289832          "publisher": "Drew DeVault \u003csir@cmpwn.com\u003e",
289833          "name": "py3-six",
289834          "version": "1.16.0-r1",
289835          "description": "Python 2 and 3 compatibility library",
289836          "licenses": [
289837            {
289838              "license": {
289839                "id": "MIT"
289840              }
289841            }
289842          ],
289843          "cpe": "cpe:2.3:a:six-project:py3-six:1.16.0-r1:*:*:*:*:*:*:*",
289844          "purl": "pkg:apk/alpine/py3-six@1.16.0-r1?arch=x86_64\u0026distro=alpine-3.16.5",
289845          "swid": {
289846            "attachment": {}
289847          },
289848          "pedigree": {},
289849          "externalReferences": [
289850            {
289851              "url": "https://pypi.python.org/pypi/six",
289852              "type": "distribution"
289853            }
289854          ],
289855          "evidence": {},
289856          "signature": {
289857            "signature": {
289858              "publicKey": {}
289859            }
289860          },
289861          "modelCard": {
289862            "modelParameters": {
289863              "approach": {}
289864            },
289865            "quantitativeAnalysis": {
289866              "graphics": {}
289867            },
289868            "considerations": {}
289869          }
289870        },
289871        {
289872          "type": "library",
289873          "bom-ref": "pkg:apk/alpine/py3-tomli@2.0.1-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=bb3a54ee1a02f369",
289874          "supplier": {},
289875          "publisher": "Michał Polański \u003cmichal@polanski.me\u003e",
289876          "name": "py3-tomli",
289877          "version": "2.0.1-r1",
289878          "description": "Lil' TOML parser",
289879          "licenses": [
289880            {
289881              "license": {
289882                "id": "MIT"
289883              }
289884            }
289885          ],
289886          "cpe": "cpe:2.3:a:tomli-project:py3-tomli:2.0.1-r1:*:*:*:*:*:*:*",
289887          "purl": "pkg:apk/alpine/py3-tomli@2.0.1-r1?arch=x86_64\u0026distro=alpine-3.16.5",
289888          "swid": {
289889            "attachment": {}
289890          },
289891          "pedigree": {},
289892          "externalReferences": [
289893            {
289894              "url": "https://github.com/hukkin/tomli",
289895              "type": "distribution"
289896            }
289897          ],
289898          "evidence": {},
289899          "signature": {
289900            "signature": {
289901              "publicKey": {}
289902            }
289903          },
289904          "modelCard": {
289905            "modelParameters": {
289906              "approach": {}
289907            },
289908            "quantitativeAnalysis": {
289909              "graphics": {}
289910            },
289911            "considerations": {}
289912          }
289913        },
289914        {
289915          "type": "library",
289916          "bom-ref": "pkg:pypi/pyopenssl@21.0.0?package-id=1a476668d87426c5",
289917          "supplier": {},
289918          "author": "The pyOpenSSL developers \u003ccryptography-dev@python.org\u003e",
289919          "name": "pyOpenSSL",
289920          "version": "21.0.0",
289921          "licenses": [
289922            {
289923              "license": {
289924                "name": "Apache License, Version 2.0"
289925              }
289926            }
289927          ],
289928          "cpe": "cpe:2.3:a:pyopenssl_developers_project:python-pyOpenSSL:21.0.0:*:*:*:*:*:*:*",
289929          "purl": "pkg:pypi/pyOpenSSL@21.0.0",
289930          "swid": {
289931            "attachment": {}
289932          },
289933          "pedigree": {},
289934          "evidence": {},
289935          "signature": {
289936            "signature": {
289937              "publicKey": {}
289938            }
289939          },
289940          "modelCard": {
289941            "modelParameters": {
289942              "approach": {}
289943            },
289944            "quantitativeAnalysis": {
289945              "graphics": {}
289946            },
289947            "considerations": {}
289948          }
289949        },
289950        {
289951          "type": "library",
289952          "bom-ref": "pkg:pypi/pyasn1@0.4.8?package-id=f1700db45a9a2342",
289953          "supplier": {},
289954          "author": "Ilya Etingof \u003cetingof@gmail.com\u003e",
289955          "name": "pyasn1",
289956          "version": "0.4.8",
289957          "licenses": [
289958            {
289959              "license": {
289960                "name": "BSD"
289961              }
289962            }
289963          ],
289964          "cpe": "cpe:2.3:a:ilya_etingof_project:python-pyasn1:0.4.8:*:*:*:*:*:*:*",
289965          "purl": "pkg:pypi/pyasn1@0.4.8",
289966          "swid": {
289967            "attachment": {}
289968          },
289969          "pedigree": {},
289970          "evidence": {},
289971          "signature": {
289972            "signature": {
289973              "publicKey": {}
289974            }
289975          },
289976          "modelCard": {
289977            "modelParameters": {
289978              "approach": {}
289979            },
289980            "quantitativeAnalysis": {
289981              "graphics": {}
289982            },
289983            "considerations": {}
289984          }
289985        },
289986        {
289987          "type": "library",
289988          "bom-ref": "pkg:pypi/pycparser@2.19?package-id=2faf97ff113f6455",
289989          "supplier": {},
289990          "author": "Eli Bendersky \u003celiben@gmail.com\u003e",
289991          "name": "pycparser",
289992          "version": "2.19",
289993          "licenses": [
289994            {
289995              "license": {
289996                "name": "BSD"
289997              }
289998            }
289999          ],
290000          "cpe": "cpe:2.3:a:eli_bendersky_project:python-pycparser:2.19:*:*:*:*:*:*:*",
290001          "purl": "pkg:pypi/pycparser@2.19",
290002          "swid": {
290003            "attachment": {}
290004          },
290005          "pedigree": {},
290006          "evidence": {},
290007          "signature": {
290008            "signature": {
290009              "publicKey": {}
290010            }
290011          },
290012          "modelCard": {
290013            "modelParameters": {
290014              "approach": {}
290015            },
290016            "quantitativeAnalysis": {
290017              "graphics": {}
290018            },
290019            "considerations": {}
290020          }
290021        },
290022        {
290023          "type": "library",
290024          "bom-ref": "pkg:pypi/pycparser@2.20?package-id=2873718085b009eb",
290025          "supplier": {},
290026          "author": "Eli Bendersky \u003celiben@gmail.com\u003e",
290027          "name": "pycparser",
290028          "version": "2.20",
290029          "licenses": [
290030            {
290031              "license": {
290032                "name": "BSD"
290033              }
290034            }
290035          ],
290036          "cpe": "cpe:2.3:a:eli_bendersky_project:python-pycparser:2.20:*:*:*:*:*:*:*",
290037          "purl": "pkg:pypi/pycparser@2.20",
290038          "swid": {
290039            "attachment": {}
290040          },
290041          "pedigree": {},
290042          "evidence": {},
290043          "signature": {
290044            "signature": {
290045              "publicKey": {}
290046            }
290047          },
290048          "modelCard": {
290049            "modelParameters": {
290050              "approach": {}
290051            },
290052            "quantitativeAnalysis": {
290053              "graphics": {}
290054            },
290055            "considerations": {}
290056          }
290057        },
290058        {
290059          "type": "library",
290060          "bom-ref": "pkg:pypi/pycryptodomex@3.17?package-id=f00de750531e88db",
290061          "supplier": {},
290062          "author": "Helder Eijs \u003chelderijs@gmail.com\u003e",
290063          "name": "pycryptodomex",
290064          "version": "3.17",
290065          "licenses": [
290066            {
290067              "license": {
290068                "name": "BSD, Public Domain"
290069              }
290070            }
290071          ],
290072          "cpe": "cpe:2.3:a:python-pycryptodomex:python-pycryptodomex:3.17:*:*:*:*:*:*:*",
290073          "purl": "pkg:pypi/pycryptodomex@3.17",
290074          "swid": {
290075            "attachment": {}
290076          },
290077          "pedigree": {},
290078          "evidence": {},
290079          "signature": {
290080            "signature": {
290081              "publicKey": {}
290082            }
290083          },
290084          "modelCard": {
290085            "modelParameters": {
290086              "approach": {}
290087            },
290088            "quantitativeAnalysis": {
290089              "graphics": {}
290090            },
290091            "considerations": {}
290092          }
290093        },
290094        {
290095          "type": "library",
290096          "bom-ref": "pkg:pypi/pyparsing@2.4.7?package-id=489cb6c6c4b7eef",
290097          "supplier": {},
290098          "author": "Paul McGuire \u003cptmcg@users.sourceforge.net\u003e",
290099          "name": "pyparsing",
290100          "version": "2.4.7",
290101          "licenses": [
290102            {
290103              "license": {
290104                "name": "MIT License"
290105              }
290106            }
290107          ],
290108          "cpe": "cpe:2.3:a:paul_mcguire_project:python-pyparsing:2.4.7:*:*:*:*:*:*:*",
290109          "purl": "pkg:pypi/pyparsing@2.4.7",
290110          "swid": {
290111            "attachment": {}
290112          },
290113          "pedigree": {},
290114          "evidence": {},
290115          "signature": {
290116            "signature": {
290117              "publicKey": {}
290118            }
290119          },
290120          "modelCard": {
290121            "modelParameters": {
290122              "approach": {}
290123            },
290124            "quantitativeAnalysis": {
290125              "graphics": {}
290126            },
290127            "considerations": {}
290128          }
290129        },
290130        {
290131          "type": "library",
290132          "bom-ref": "pkg:pypi/pysmi@0.3.4?package-id=36f78e07dd7a0a77",
290133          "supplier": {},
290134          "author": "Ilya Etingof \u003cetingof@gmail.com\u003e",
290135          "name": "pysmi",
290136          "version": "0.3.4",
290137          "licenses": [
290138            {
290139              "license": {
290140                "name": "BSD"
290141              }
290142            }
290143          ],
290144          "cpe": "cpe:2.3:a:ilya_etingof_project:python-pysmi:0.3.4:*:*:*:*:*:*:*",
290145          "purl": "pkg:pypi/pysmi@0.3.4",
290146          "swid": {
290147            "attachment": {}
290148          },
290149          "pedigree": {},
290150          "evidence": {},
290151          "signature": {
290152            "signature": {
290153              "publicKey": {}
290154            }
290155          },
290156          "modelCard": {
290157            "modelParameters": {
290158              "approach": {}
290159            },
290160            "quantitativeAnalysis": {
290161              "graphics": {}
290162            },
290163            "considerations": {}
290164          }
290165        },
290166        {
290167          "type": "library",
290168          "bom-ref": "pkg:pypi/pysnmp@4.4.12?package-id=8681507cf69b2f2d",
290169          "supplier": {},
290170          "author": "Ilya Etingof \u003cetingof@gmail.com\u003e",
290171          "name": "pysnmp",
290172          "version": "4.4.12",
290173          "licenses": [
290174            {
290175              "license": {
290176                "name": "BSD"
290177              }
290178            }
290179          ],
290180          "cpe": "cpe:2.3:a:ilya_etingof_project:python-pysnmp:4.4.12:*:*:*:*:*:*:*",
290181          "purl": "pkg:pypi/pysnmp@4.4.12",
290182          "swid": {
290183            "attachment": {}
290184          },
290185          "pedigree": {},
290186          "evidence": {},
290187          "signature": {
290188            "signature": {
290189              "publicKey": {}
290190            }
290191          },
290192          "modelCard": {
290193            "modelParameters": {
290194              "approach": {}
290195            },
290196            "quantitativeAnalysis": {
290197              "graphics": {}
290198            },
290199            "considerations": {}
290200          }
290201        },
290202        {
290203          "type": "library",
290204          "bom-ref": "pkg:pypi/pysnmp-mibs@0.1.6?package-id=905d41feb3c02905",
290205          "supplier": {},
290206          "author": "Ilya Etingof \u003cilya@glas.net\u003e \u003cilya@glas.net\u003e",
290207          "name": "pysnmp-mibs",
290208          "version": "0.1.6",
290209          "licenses": [
290210            {
290211              "license": {
290212                "name": "BSD"
290213              }
290214            }
290215          ],
290216          "cpe": "cpe:2.3:a:ilya_etingof_\\\u003cilya\\@glas_net\\\u003e_project:python-pysnmp-mibs:0.1.6:*:*:*:*:*:*:*",
290217          "purl": "pkg:pypi/pysnmp-mibs@0.1.6",
290218          "swid": {
290219            "attachment": {}
290220          },
290221          "pedigree": {},
290222          "evidence": {},
290223          "signature": {
290224            "signature": {
290225              "publicKey": {}
290226            }
290227          },
290228          "modelCard": {
290229            "modelParameters": {
290230              "approach": {}
290231            },
290232            "quantitativeAnalysis": {
290233              "graphics": {}
290234            },
290235            "considerations": {}
290236          }
290237        },
290238        {
290239          "type": "application",
290240          "bom-ref": "pkg:generic/python@3.10.11?package-id=4427f0aa35e83204",
290241          "supplier": {},
290242          "name": "python",
290243          "version": "3.10.11",
290244          "cpe": "cpe:2.3:a:python_software_foundation:python:3.10.11:*:*:*:*:*:*:*",
290245          "purl": "pkg:generic/python@3.10.11",
290246          "swid": {
290247            "attachment": {}
290248          },
290249          "pedigree": {},
290250          "evidence": {},
290251          "signature": {
290252            "signature": {
290253              "publicKey": {}
290254            }
290255          },
290256          "modelCard": {
290257            "modelParameters": {
290258              "approach": {}
290259            },
290260            "quantitativeAnalysis": {
290261              "graphics": {}
290262            },
290263            "considerations": {}
290264          }
290265        },
290266        {
290267          "type": "application",
290268          "bom-ref": "pkg:generic/python@3.8.16?package-id=92f8822938c7aca6",
290269          "supplier": {},
290270          "name": "python",
290271          "version": "3.8.16",
290272          "cpe": "cpe:2.3:a:python_software_foundation:python:3.8.16:*:*:*:*:*:*:*",
290273          "purl": "pkg:generic/python@3.8.16",
290274          "swid": {
290275            "attachment": {}
290276          },
290277          "pedigree": {},
290278          "evidence": {},
290279          "signature": {
290280            "signature": {
290281              "publicKey": {}
290282            }
290283          },
290284          "modelCard": {
290285            "modelParameters": {
290286              "approach": {}
290287            },
290288            "quantitativeAnalysis": {
290289              "graphics": {}
290290            },
290291            "considerations": {}
290292          }
290293        },
290294        {
290295          "type": "library",
290296          "bom-ref": "pkg:pypi/python-daemon@2.2.3?package-id=7645ea87205522b3",
290297          "supplier": {},
290298          "author": "Ben Finney \u003cben+python@benfinney.id.au\u003e",
290299          "name": "python-daemon",
290300          "version": "2.2.3",
290301          "licenses": [
290302            {
290303              "license": {
290304                "id": "Apache-2.0"
290305              }
290306            }
290307          ],
290308          "cpe": "cpe:2.3:a:ben\\+python_project:python-daemon:2.2.3:*:*:*:*:*:*:*",
290309          "purl": "pkg:pypi/python-daemon@2.2.3",
290310          "swid": {
290311            "attachment": {}
290312          },
290313          "pedigree": {},
290314          "evidence": {},
290315          "signature": {
290316            "signature": {
290317              "publicKey": {}
290318            }
290319          },
290320          "modelCard": {
290321            "modelParameters": {
290322              "approach": {}
290323            },
290324            "quantitativeAnalysis": {
290325              "graphics": {}
290326            },
290327            "considerations": {}
290328          }
290329        },
290330        {
290331          "type": "library",
290332          "bom-ref": "pkg:apk/alpine/python3@3.10.11-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=99c3fcfdc2714e19",
290333          "supplier": {},
290334          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
290335          "name": "python3",
290336          "version": "3.10.11-r0",
290337          "description": "A high-level scripting language",
290338          "licenses": [
290339            {
290340              "license": {
290341                "id": "PSF-2.0"
290342              }
290343            }
290344          ],
290345          "cpe": "cpe:2.3:a:python-software-foundation:python3:3.10.11-r0:*:*:*:*:*:*:*",
290346          "purl": "pkg:apk/alpine/python3@3.10.11-r0?arch=x86_64\u0026distro=alpine-3.16.5",
290347          "swid": {
290348            "attachment": {}
290349          },
290350          "pedigree": {},
290351          "externalReferences": [
290352            {
290353              "url": "https://www.python.org/",
290354              "type": "distribution"
290355            }
290356          ],
290357          "evidence": {},
290358          "signature": {
290359            "signature": {
290360              "publicKey": {}
290361            }
290362          },
290363          "modelCard": {
290364            "modelParameters": {
290365              "approach": {}
290366            },
290367            "quantitativeAnalysis": {
290368              "graphics": {}
290369            },
290370            "considerations": {}
290371          }
290372        },
290373        {
290374          "type": "library",
290375          "bom-ref": "pkg:apk/alpine/python3-dev@3.10.11-r0?arch=x86_64\u0026upstream=python3\u0026distro=alpine-3.16.5\u0026package-id=8cbfce2c6879df2d",
290376          "supplier": {},
290377          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
290378          "name": "python3-dev",
290379          "version": "3.10.11-r0",
290380          "description": "A high-level scripting language (development files)",
290381          "licenses": [
290382            {
290383              "license": {
290384                "id": "PSF-2.0"
290385              }
290386            }
290387          ],
290388          "cpe": "cpe:2.3:a:python3-dev:python3-dev:3.10.11-r0:*:*:*:*:*:*:*",
290389          "purl": "pkg:apk/alpine/python3-dev@3.10.11-r0?arch=x86_64\u0026upstream=python3\u0026distro=alpine-3.16.5",
290390          "swid": {
290391            "attachment": {}
290392          },
290393          "pedigree": {},
290394          "externalReferences": [
290395            {
290396              "url": "https://www.python.org/",
290397              "type": "distribution"
290398            }
290399          ],
290400          "evidence": {},
290401          "signature": {
290402            "signature": {
290403              "publicKey": {}
290404            }
290405          },
290406          "modelCard": {
290407            "modelParameters": {
290408              "approach": {}
290409            },
290410            "quantitativeAnalysis": {
290411              "graphics": {}
290412            },
290413            "considerations": {}
290414          }
290415        },
290416        {
290417          "type": "library",
290418          "bom-ref": "pkg:pypi/pytz@2019.1?package-id=5349819edf2c8f6d",
290419          "supplier": {},
290420          "author": "Stuart Bishop \u003cstuart@stuartbishop.net\u003e",
290421          "name": "pytz",
290422          "version": "2019.1",
290423          "licenses": [
290424            {
290425              "license": {
290426                "id": "MIT"
290427              }
290428            }
290429          ],
290430          "cpe": "cpe:2.3:a:stuart_bishop_project:python-pytz:2019.1:*:*:*:*:*:*:*",
290431          "purl": "pkg:pypi/pytz@2019.1",
290432          "swid": {
290433            "attachment": {}
290434          },
290435          "pedigree": {},
290436          "evidence": {},
290437          "signature": {
290438            "signature": {
290439              "publicKey": {}
290440            }
290441          },
290442          "modelCard": {
290443            "modelParameters": {
290444              "approach": {}
290445            },
290446            "quantitativeAnalysis": {
290447              "graphics": {}
290448            },
290449            "considerations": {}
290450          }
290451        },
290452        {
290453          "type": "library",
290454          "bom-ref": "pkg:apk/alpine/readline@8.1.2-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=bb734bcc27e60920",
290455          "supplier": {},
290456          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
290457          "name": "readline",
290458          "version": "8.1.2-r0",
290459          "description": "GNU readline library",
290460          "licenses": [
290461            {
290462              "license": {
290463                "id": "GPL-2.0-or-later"
290464              }
290465            }
290466          ],
290467          "cpe": "cpe:2.3:a:readline:readline:8.1.2-r0:*:*:*:*:*:*:*",
290468          "purl": "pkg:apk/alpine/readline@8.1.2-r0?arch=x86_64\u0026distro=alpine-3.16.5",
290469          "swid": {
290470            "attachment": {}
290471          },
290472          "pedigree": {},
290473          "externalReferences": [
290474            {
290475              "url": "https://tiswww.cwru.edu/php/chet/readline/rltop.html",
290476              "type": "distribution"
290477            }
290478          ],
290479          "evidence": {},
290480          "signature": {
290481            "signature": {
290482              "publicKey": {}
290483            }
290484          },
290485          "modelCard": {
290486            "modelParameters": {
290487              "approach": {}
290488            },
290489            "quantitativeAnalysis": {
290490              "graphics": {}
290491            },
290492            "considerations": {}
290493          }
290494        },
290495        {
290496          "type": "library",
290497          "bom-ref": "pkg:pypi/requests@2.28.2?package-id=f088117d32fc1dd2",
290498          "supplier": {},
290499          "author": "Kenneth Reitz \u003cme@kennethreitz.org\u003e",
290500          "name": "requests",
290501          "version": "2.28.2",
290502          "licenses": [
290503            {
290504              "license": {
290505                "name": "Apache 2.0"
290506              }
290507            }
290508          ],
290509          "cpe": "cpe:2.3:a:kenneth_reitz_project:python-requests:2.28.2:*:*:*:*:*:*:*",
290510          "purl": "pkg:pypi/requests@2.28.2",
290511          "swid": {
290512            "attachment": {}
290513          },
290514          "pedigree": {},
290515          "evidence": {},
290516          "signature": {
290517            "signature": {
290518              "publicKey": {}
290519            }
290520          },
290521          "modelCard": {
290522            "modelParameters": {
290523              "approach": {}
290524            },
290525            "quantitativeAnalysis": {
290526              "graphics": {}
290527            },
290528            "considerations": {}
290529          }
290530        },
290531        {
290532          "type": "library",
290533          "bom-ref": "pkg:pypi/retrying@1.3.3?package-id=ad684810dbe6c655",
290534          "supplier": {},
290535          "author": "Ray Holder",
290536          "name": "retrying",
290537          "version": "1.3.3",
290538          "licenses": [
290539            {
290540              "license": {
290541                "name": "Apache 2.0"
290542              }
290543            }
290544          ],
290545          "cpe": "cpe:2.3:a:ray_holder_project:python-retrying:1.3.3:*:*:*:*:*:*:*",
290546          "purl": "pkg:pypi/retrying@1.3.3",
290547          "swid": {
290548            "attachment": {}
290549          },
290550          "pedigree": {},
290551          "evidence": {},
290552          "signature": {
290553            "signature": {
290554              "publicKey": {}
290555            }
290556          },
290557          "modelCard": {
290558            "modelParameters": {
290559              "approach": {}
290560            },
290561            "quantitativeAnalysis": {
290562              "graphics": {}
290563            },
290564            "considerations": {}
290565          }
290566        },
290567        {
290568          "type": "library",
290569          "bom-ref": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5\u0026package-id=206fdb47b3e980eb",
290570          "supplier": {},
290571          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
290572          "name": "scanelf",
290573          "version": "1.3.4-r0",
290574          "description": "Scan ELF binaries for stuff",
290575          "licenses": [
290576            {
290577              "license": {
290578                "id": "GPL-2.0-only"
290579              }
290580            }
290581          ],
290582          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.4-r0:*:*:*:*:*:*:*",
290583          "purl": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5",
290584          "swid": {
290585            "attachment": {}
290586          },
290587          "pedigree": {},
290588          "externalReferences": [
290589            {
290590              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
290591              "type": "distribution"
290592            }
290593          ],
290594          "evidence": {},
290595          "signature": {
290596            "signature": {
290597              "publicKey": {}
290598            }
290599          },
290600          "modelCard": {
290601            "modelParameters": {
290602              "approach": {}
290603            },
290604            "quantitativeAnalysis": {
290605              "graphics": {}
290606            },
290607            "considerations": {}
290608          }
290609        },
290610        {
290611          "type": "library",
290612          "bom-ref": "pkg:pypi/setuptools@57.5.0?package-id=85835c335c6d8275",
290613          "supplier": {},
290614          "author": "Python Packaging Authority \u003cdistutils-sig@python.org\u003e",
290615          "name": "setuptools",
290616          "version": "57.5.0",
290617          "licenses": [
290618            {
290619              "license": {
290620                "name": "UNKNOWN"
290621              }
290622            }
290623          ],
290624          "cpe": "cpe:2.3:a:python_packaging_authority_project:python-setuptools:57.5.0:*:*:*:*:*:*:*",
290625          "purl": "pkg:pypi/setuptools@57.5.0",
290626          "swid": {
290627            "attachment": {}
290628          },
290629          "pedigree": {},
290630          "evidence": {},
290631          "signature": {
290632            "signature": {
290633              "publicKey": {}
290634            }
290635          },
290636          "modelCard": {
290637            "modelParameters": {
290638              "approach": {}
290639            },
290640            "quantitativeAnalysis": {
290641              "graphics": {}
290642            },
290643            "considerations": {}
290644          }
290645        },
290646        {
290647          "type": "library",
290648          "bom-ref": "pkg:pypi/setuptools@59.4.0?package-id=81f8baf91e27227f",
290649          "supplier": {},
290650          "author": "Python Packaging Authority \u003cdistutils-sig@python.org\u003e",
290651          "name": "setuptools",
290652          "version": "59.4.0",
290653          "licenses": [
290654            {
290655              "license": {
290656                "name": "UNKNOWN"
290657              }
290658            }
290659          ],
290660          "cpe": "cpe:2.3:a:python_packaging_authority_project:python-setuptools:59.4.0:*:*:*:*:*:*:*",
290661          "purl": "pkg:pypi/setuptools@59.4.0",
290662          "swid": {
290663            "attachment": {}
290664          },
290665          "pedigree": {},
290666          "evidence": {},
290667          "signature": {
290668            "signature": {
290669              "publicKey": {}
290670            }
290671          },
290672          "modelCard": {
290673            "modelParameters": {
290674              "approach": {}
290675            },
290676            "quantitativeAnalysis": {
290677              "graphics": {}
290678            },
290679            "considerations": {}
290680          }
290681        },
290682        {
290683          "type": "library",
290684          "bom-ref": "pkg:pypi/six@1.12.0?package-id=54167c3927512610",
290685          "supplier": {},
290686          "author": "Benjamin Peterson \u003cbenjamin@python.org\u003e",
290687          "name": "six",
290688          "version": "1.12.0",
290689          "licenses": [
290690            {
290691              "license": {
290692                "id": "MIT"
290693              }
290694            }
290695          ],
290696          "cpe": "cpe:2.3:a:benjamin_peterson_project:python-six:1.12.0:*:*:*:*:*:*:*",
290697          "purl": "pkg:pypi/six@1.12.0",
290698          "swid": {
290699            "attachment": {}
290700          },
290701          "pedigree": {},
290702          "evidence": {},
290703          "signature": {
290704            "signature": {
290705              "publicKey": {}
290706            }
290707          },
290708          "modelCard": {
290709            "modelParameters": {
290710              "approach": {}
290711            },
290712            "quantitativeAnalysis": {
290713              "graphics": {}
290714            },
290715            "considerations": {}
290716          }
290717        },
290718        {
290719          "type": "library",
290720          "bom-ref": "pkg:pypi/six@1.16.0?package-id=d474e456e4b17d48",
290721          "supplier": {},
290722          "author": "Benjamin Peterson \u003cbenjamin@python.org\u003e",
290723          "name": "six",
290724          "version": "1.16.0",
290725          "licenses": [
290726            {
290727              "license": {
290728                "id": "MIT"
290729              }
290730            }
290731          ],
290732          "cpe": "cpe:2.3:a:benjamin_peterson_project:python-six:1.16.0:*:*:*:*:*:*:*",
290733          "purl": "pkg:pypi/six@1.16.0",
290734          "swid": {
290735            "attachment": {}
290736          },
290737          "pedigree": {},
290738          "evidence": {},
290739          "signature": {
290740            "signature": {
290741              "publicKey": {}
290742            }
290743          },
290744          "modelCard": {
290745            "modelParameters": {
290746              "approach": {}
290747            },
290748            "quantitativeAnalysis": {
290749              "graphics": {}
290750            },
290751            "considerations": {}
290752          }
290753        },
290754        {
290755          "type": "library",
290756          "bom-ref": "pkg:apk/alpine/sqlite-libs@3.38.5-r0?arch=x86_64\u0026upstream=sqlite\u0026distro=alpine-3.16.5\u0026package-id=6127833655f3995a",
290757          "supplier": {},
290758          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
290759          "name": "sqlite-libs",
290760          "version": "3.38.5-r0",
290761          "description": "Sqlite3 library",
290762          "licenses": [
290763            {
290764              "license": {
290765                "id": "blessing"
290766              }
290767            }
290768          ],
290769          "cpe": "cpe:2.3:a:sqlite-libs:sqlite-libs:3.38.5-r0:*:*:*:*:*:*:*",
290770          "purl": "pkg:apk/alpine/sqlite-libs@3.38.5-r0?arch=x86_64\u0026upstream=sqlite\u0026distro=alpine-3.16.5",
290771          "swid": {
290772            "attachment": {}
290773          },
290774          "pedigree": {},
290775          "externalReferences": [
290776            {
290777              "url": "https://www.sqlite.org/",
290778              "type": "distribution"
290779            }
290780          ],
290781          "evidence": {},
290782          "signature": {
290783            "signature": {
290784              "publicKey": {}
290785            }
290786          },
290787          "modelCard": {
290788            "modelParameters": {
290789              "approach": {}
290790            },
290791            "quantitativeAnalysis": {
290792              "graphics": {}
290793            },
290794            "considerations": {}
290795          }
290796        },
290797        {
290798          "type": "library",
290799          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5\u0026package-id=674d1e2fba4d633a",
290800          "supplier": {},
290801          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
290802          "name": "ssl_client",
290803          "version": "1.35.0-r17",
290804          "description": "EXternal ssl_client for busybox wget",
290805          "licenses": [
290806            {
290807              "license": {
290808                "id": "GPL-2.0-only"
290809              }
290810            }
290811          ],
290812          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r17:*:*:*:*:*:*:*",
290813          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5",
290814          "swid": {
290815            "attachment": {}
290816          },
290817          "pedigree": {},
290818          "externalReferences": [
290819            {
290820              "url": "https://busybox.net/",
290821              "type": "distribution"
290822            }
290823          ],
290824          "evidence": {},
290825          "signature": {
290826            "signature": {
290827              "publicKey": {}
290828            }
290829          },
290830          "modelCard": {
290831            "modelParameters": {
290832              "approach": {}
290833            },
290834            "quantitativeAnalysis": {
290835              "graphics": {}
290836            },
290837            "considerations": {}
290838          }
290839        },
290840        {
290841          "type": "library",
290842          "bom-ref": "pkg:pypi/tomli@2.0.1?package-id=f75bcb5aa2886364",
290843          "supplier": {},
290844          "author": "Taneli Hukkinen \u003chukkin@users.noreply.github.com\u003e",
290845          "name": "tomli",
290846          "version": "2.0.1",
290847          "cpe": "cpe:2.3:a:taneli_hukkinen_\\\u003chukkin_project:python-tomli:2.0.1:*:*:*:*:*:*:*",
290848          "purl": "pkg:pypi/tomli@2.0.1",
290849          "swid": {
290850            "attachment": {}
290851          },
290852          "pedigree": {},
290853          "evidence": {},
290854          "signature": {
290855            "signature": {
290856              "publicKey": {}
290857            }
290858          },
290859          "modelCard": {
290860            "modelParameters": {
290861              "approach": {}
290862            },
290863            "quantitativeAnalysis": {
290864              "graphics": {}
290865            },
290866            "considerations": {}
290867          }
290868        },
290869        {
290870          "type": "library",
290871          "bom-ref": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=c6c9b0e0277783a2",
290872          "supplier": {},
290873          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
290874          "name": "tzdata",
290875          "version": "2023c-r0",
290876          "description": "Timezone data",
290877          "licenses": [
290878            {
290879              "license": {
290880                "name": "Public-Domain"
290881              }
290882            }
290883          ],
290884          "cpe": "cpe:2.3:a:tzdata:tzdata:2023c-r0:*:*:*:*:*:*:*",
290885          "purl": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.16.5",
290886          "swid": {
290887            "attachment": {}
290888          },
290889          "pedigree": {},
290890          "externalReferences": [
290891            {
290892              "url": "https://www.iana.org/time-zones",
290893              "type": "distribution"
290894            }
290895          ],
290896          "evidence": {},
290897          "signature": {
290898            "signature": {
290899              "publicKey": {}
290900            }
290901          },
290902          "modelCard": {
290903            "modelParameters": {
290904              "approach": {}
290905            },
290906            "quantitativeAnalysis": {
290907              "graphics": {}
290908            },
290909            "considerations": {}
290910          }
290911        },
290912        {
290913          "type": "library",
290914          "bom-ref": "pkg:pypi/urllib3@1.26.15?package-id=57647ba98106cfc3",
290915          "supplier": {},
290916          "author": "Andrey Petrov \u003candrey.petrov@shazow.net\u003e",
290917          "name": "urllib3",
290918          "version": "1.26.15",
290919          "licenses": [
290920            {
290921              "license": {
290922                "id": "MIT"
290923              }
290924            }
290925          ],
290926          "cpe": "cpe:2.3:a:andrey_petrov_project:python-urllib3:1.26.15:*:*:*:*:*:*:*",
290927          "purl": "pkg:pypi/urllib3@1.26.15",
290928          "swid": {
290929            "attachment": {}
290930          },
290931          "pedigree": {},
290932          "evidence": {},
290933          "signature": {
290934            "signature": {
290935              "publicKey": {}
290936            }
290937          },
290938          "modelCard": {
290939            "modelParameters": {
290940              "approach": {}
290941            },
290942            "quantitativeAnalysis": {
290943              "graphics": {}
290944            },
290945            "considerations": {}
290946          }
290947        },
290948        {
290949          "type": "library",
290950          "bom-ref": "pkg:pypi/wcwidth@0.2.6?package-id=12cb303b2017161f",
290951          "supplier": {},
290952          "author": "Jeff Quast \u003ccontact@jeffquast.com\u003e",
290953          "name": "wcwidth",
290954          "version": "0.2.6",
290955          "licenses": [
290956            {
290957              "license": {
290958                "id": "MIT"
290959              }
290960            }
290961          ],
290962          "cpe": "cpe:2.3:a:jeff_quast_project:python-wcwidth:0.2.6:*:*:*:*:*:*:*",
290963          "purl": "pkg:pypi/wcwidth@0.2.6",
290964          "swid": {
290965            "attachment": {}
290966          },
290967          "pedigree": {},
290968          "evidence": {},
290969          "signature": {
290970            "signature": {
290971              "publicKey": {}
290972            }
290973          },
290974          "modelCard": {
290975            "modelParameters": {
290976              "approach": {}
290977            },
290978            "quantitativeAnalysis": {
290979              "graphics": {}
290980            },
290981            "considerations": {}
290982          }
290983        },
290984        {
290985          "type": "library",
290986          "bom-ref": "pkg:pypi/wheel@0.40.0?package-id=a5bbcb2514f67f7a",
290987          "supplier": {},
290988          "author": "Daniel Holth \u003cdholth@fastmail.fm\u003e",
290989          "name": "wheel",
290990          "version": "0.40.0",
290991          "cpe": "cpe:2.3:a:daniel_holth_\\\u003cdholth_project:python-wheel:0.40.0:*:*:*:*:*:*:*",
290992          "purl": "pkg:pypi/wheel@0.40.0",
290993          "swid": {
290994            "attachment": {}
290995          },
290996          "pedigree": {},
290997          "evidence": {},
290998          "signature": {
290999            "signature": {
291000              "publicKey": {}
291001            }
291002          },
291003          "modelCard": {
291004            "modelParameters": {
291005              "approach": {}
291006            },
291007            "quantitativeAnalysis": {
291008              "graphics": {}
291009            },
291010            "considerations": {}
291011          }
291012        },
291013        {
291014          "type": "library",
291015          "bom-ref": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.5\u0026package-id=168e14fa822d49a0",
291016          "supplier": {},
291017          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
291018          "name": "xz-libs",
291019          "version": "5.2.5-r1",
291020          "description": "Library and CLI tools for XZ and LZMA compressed files (libraries)",
291021          "licenses": [
291022            {
291023              "license": {
291024                "id": "GPL-2.0-or-later"
291025              }
291026            },
291027            {
291028              "license": {
291029                "name": "AND"
291030              }
291031            },
291032            {
291033              "license": {
291034                "name": "Public-Domain"
291035              }
291036            },
291037            {
291038              "license": {
291039                "name": "AND"
291040              }
291041            },
291042            {
291043              "license": {
291044                "id": "LGPL-2.1-or-later"
291045              }
291046            }
291047          ],
291048          "cpe": "cpe:2.3:a:xz-libs:xz-libs:5.2.5-r1:*:*:*:*:*:*:*",
291049          "purl": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.5",
291050          "swid": {
291051            "attachment": {}
291052          },
291053          "pedigree": {},
291054          "externalReferences": [
291055            {
291056              "url": "https://tukaani.org/xz",
291057              "type": "distribution"
291058            }
291059          ],
291060          "evidence": {},
291061          "signature": {
291062            "signature": {
291063              "publicKey": {}
291064            }
291065          },
291066          "modelCard": {
291067            "modelParameters": {
291068              "approach": {}
291069            },
291070            "quantitativeAnalysis": {
291071              "graphics": {}
291072            },
291073            "considerations": {}
291074          }
291075        },
291076        {
291077          "type": "library",
291078          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=75f0d92f695b4303",
291079          "supplier": {},
291080          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
291081          "name": "zlib",
291082          "version": "1.2.12-r3",
291083          "description": "A compression/decompression Library",
291084          "licenses": [
291085            {
291086              "license": {
291087                "id": "Zlib"
291088              }
291089            }
291090          ],
291091          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
291092          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5",
291093          "swid": {
291094            "attachment": {}
291095          },
291096          "pedigree": {},
291097          "externalReferences": [
291098            {
291099              "url": "https://zlib.net/",
291100              "type": "distribution"
291101            }
291102          ],
291103          "evidence": {},
291104          "signature": {
291105            "signature": {
291106              "publicKey": {}
291107            }
291108          },
291109          "modelCard": {
291110            "modelParameters": {
291111              "approach": {}
291112            },
291113            "quantitativeAnalysis": {
291114              "graphics": {}
291115            },
291116            "considerations": {}
291117          }
291118        },
291119        {
291120          "type": "operating-system",
291121          "supplier": {},
291122          "name": "alpine",
291123          "version": "3.16.5",
291124          "description": "Alpine Linux v3.16",
291125          "swid": {
291126            "tagId": "alpine",
291127            "name": "alpine",
291128            "version": "3.16.5",
291129            "attachment": {}
291130          },
291131          "pedigree": {},
291132          "externalReferences": [
291133            {
291134              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
291135              "type": "issue-tracker"
291136            },
291137            {
291138              "url": "https://alpinelinux.org/",
291139              "type": "website"
291140            }
291141          ],
291142          "evidence": {},
291143          "signature": {
291144            "signature": {
291145              "publicKey": {}
291146            }
291147          },
291148          "modelCard": {
291149            "modelParameters": {
291150              "approach": {}
291151            },
291152            "quantitativeAnalysis": {
291153              "graphics": {}
291154            },
291155            "considerations": {}
291156          }
291157        },
291158        {
291159          "type": "library",
291160          "bom-ref": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04\u0026package-id=69d1980477020fa3",
291161          "supplier": {},
291162          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291163          "name": "adduser",
291164          "version": "3.118ubuntu2",
291165          "licenses": [
291166            {
291167              "license": {
291168                "id": "GPL-2.0-only"
291169              }
291170            }
291171          ],
291172          "cpe": "cpe:2.3:a:adduser:adduser:3.118ubuntu2:*:*:*:*:*:*:*",
291173          "purl": "pkg:deb/ubuntu/adduser@3.118ubuntu2?arch=all\u0026distro=ubuntu-20.04",
291174          "swid": {
291175            "attachment": {}
291176          },
291177          "pedigree": {},
291178          "evidence": {},
291179          "signature": {
291180            "signature": {
291181              "publicKey": {}
291182            }
291183          },
291184          "modelCard": {
291185            "modelParameters": {
291186              "approach": {}
291187            },
291188            "quantitativeAnalysis": {
291189              "graphics": {}
291190            },
291191            "considerations": {}
291192          }
291193        },
291194        {
291195          "type": "library",
291196          "bom-ref": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=55988ea1c6f336e3",
291197          "supplier": {},
291198          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291199          "name": "apt",
291200          "version": "2.0.6",
291201          "licenses": [
291202            {
291203              "license": {
291204                "id": "GPL-2.0-only"
291205              }
291206            },
291207            {
291208              "license": {
291209                "name": "GPLv2+"
291210              }
291211            }
291212          ],
291213          "cpe": "cpe:2.3:a:apt:apt:2.0.6:*:*:*:*:*:*:*",
291214          "purl": "pkg:deb/ubuntu/apt@2.0.6?arch=amd64\u0026distro=ubuntu-20.04",
291215          "swid": {
291216            "attachment": {}
291217          },
291218          "pedigree": {},
291219          "evidence": {},
291220          "signature": {
291221            "signature": {
291222              "publicKey": {}
291223            }
291224          },
291225          "modelCard": {
291226            "modelParameters": {
291227              "approach": {}
291228            },
291229            "quantitativeAnalysis": {
291230              "graphics": {}
291231            },
291232            "considerations": {}
291233          }
291234        },
291235        {
291236          "type": "library",
291237          "bom-ref": "pkg:deb/ubuntu/base-files@11ubuntu5.3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=1c2af4464cd392e1",
291238          "supplier": {},
291239          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291240          "name": "base-files",
291241          "version": "11ubuntu5.3",
291242          "licenses": [
291243            {
291244              "license": {
291245                "name": "GPL"
291246              }
291247            }
291248          ],
291249          "cpe": "cpe:2.3:a:base-files:base-files:11ubuntu5.3:*:*:*:*:*:*:*",
291250          "purl": "pkg:deb/ubuntu/base-files@11ubuntu5.3?arch=amd64\u0026distro=ubuntu-20.04",
291251          "swid": {
291252            "attachment": {}
291253          },
291254          "pedigree": {},
291255          "evidence": {},
291256          "signature": {
291257            "signature": {
291258              "publicKey": {}
291259            }
291260          },
291261          "modelCard": {
291262            "modelParameters": {
291263              "approach": {}
291264            },
291265            "quantitativeAnalysis": {
291266              "graphics": {}
291267            },
291268            "considerations": {}
291269          }
291270        },
291271        {
291272          "type": "library",
291273          "bom-ref": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=63c89c28c512e1db",
291274          "supplier": {},
291275          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291276          "name": "base-files",
291277          "version": "11ubuntu5.4",
291278          "licenses": [
291279            {
291280              "license": {
291281                "name": "GPL"
291282              }
291283            }
291284          ],
291285          "cpe": "cpe:2.3:a:base-files:base-files:11ubuntu5.4:*:*:*:*:*:*:*",
291286          "purl": "pkg:deb/ubuntu/base-files@11ubuntu5.4?arch=amd64\u0026distro=ubuntu-20.04",
291287          "swid": {
291288            "attachment": {}
291289          },
291290          "pedigree": {},
291291          "evidence": {},
291292          "signature": {
291293            "signature": {
291294              "publicKey": {}
291295            }
291296          },
291297          "modelCard": {
291298            "modelParameters": {
291299              "approach": {}
291300            },
291301            "quantitativeAnalysis": {
291302              "graphics": {}
291303            },
291304            "considerations": {}
291305          }
291306        },
291307        {
291308          "type": "library",
291309          "bom-ref": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=8b6e494dac6dab09",
291310          "supplier": {},
291311          "publisher": "Colin Watson \u003ccjwatson@debian.org\u003e",
291312          "name": "base-passwd",
291313          "version": "3.5.47",
291314          "licenses": [
291315            {
291316              "license": {
291317                "id": "GPL-2.0-only"
291318              }
291319            },
291320            {
291321              "license": {
291322                "name": "PD"
291323              }
291324            }
291325          ],
291326          "cpe": "cpe:2.3:a:base-passwd:base-passwd:3.5.47:*:*:*:*:*:*:*",
291327          "purl": "pkg:deb/ubuntu/base-passwd@3.5.47?arch=amd64\u0026distro=ubuntu-20.04",
291328          "swid": {
291329            "attachment": {}
291330          },
291331          "pedigree": {},
291332          "evidence": {},
291333          "signature": {
291334            "signature": {
291335              "publicKey": {}
291336            }
291337          },
291338          "modelCard": {
291339            "modelParameters": {
291340              "approach": {}
291341            },
291342            "quantitativeAnalysis": {
291343              "graphics": {}
291344            },
291345            "considerations": {}
291346          }
291347        },
291348        {
291349          "type": "library",
291350          "bom-ref": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e774a3e87113196b",
291351          "supplier": {},
291352          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291353          "name": "bash",
291354          "version": "5.0-6ubuntu1.1",
291355          "licenses": [
291356            {
291357              "license": {
291358                "id": "GPL-3.0-only"
291359              }
291360            }
291361          ],
291362          "cpe": "cpe:2.3:a:bash:bash:5.0-6ubuntu1.1:*:*:*:*:*:*:*",
291363          "purl": "pkg:deb/ubuntu/bash@5.0-6ubuntu1.1?arch=amd64\u0026distro=ubuntu-20.04",
291364          "swid": {
291365            "attachment": {}
291366          },
291367          "pedigree": {},
291368          "evidence": {},
291369          "signature": {
291370            "signature": {
291371              "publicKey": {}
291372            }
291373          },
291374          "modelCard": {
291375            "modelParameters": {
291376              "approach": {}
291377            },
291378            "quantitativeAnalysis": {
291379              "graphics": {}
291380            },
291381            "considerations": {}
291382          }
291383        },
291384        {
291385          "type": "library",
291386          "bom-ref": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04\u0026package-id=20018d8de777eda9",
291387          "supplier": {},
291388          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291389          "name": "bsdutils",
291390          "version": "1:2.34-0.1ubuntu9.1",
291391          "licenses": [
291392            {
291393              "license": {
291394                "id": "BSD-2-Clause"
291395              }
291396            },
291397            {
291398              "license": {
291399                "id": "BSD-3-Clause"
291400              }
291401            },
291402            {
291403              "license": {
291404                "id": "BSD-4-Clause"
291405              }
291406            },
291407            {
291408              "license": {
291409                "id": "GPL-2.0-only"
291410              }
291411            },
291412            {
291413              "license": {
291414                "id": "GPL-2.0-or-later"
291415              }
291416            },
291417            {
291418              "license": {
291419                "id": "GPL-3.0-only"
291420              }
291421            },
291422            {
291423              "license": {
291424                "id": "GPL-3.0-or-later"
291425              }
291426            },
291427            {
291428              "license": {
291429                "name": "LGPL"
291430              }
291431            },
291432            {
291433              "license": {
291434                "id": "LGPL-2.0-only"
291435              }
291436            },
291437            {
291438              "license": {
291439                "id": "LGPL-2.0-or-later"
291440              }
291441            },
291442            {
291443              "license": {
291444                "id": "LGPL-2.1-only"
291445              }
291446            },
291447            {
291448              "license": {
291449                "id": "LGPL-2.1-or-later"
291450              }
291451            },
291452            {
291453              "license": {
291454                "id": "LGPL-3.0-only"
291455              }
291456            },
291457            {
291458              "license": {
291459                "id": "LGPL-3.0-or-later"
291460              }
291461            },
291462            {
291463              "license": {
291464                "id": "MIT"
291465              }
291466            },
291467            {
291468              "license": {
291469                "name": "public-domain"
291470              }
291471            }
291472          ],
291473          "cpe": "cpe:2.3:a:bsdutils:bsdutils:1\\:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
291474          "purl": "pkg:deb/ubuntu/bsdutils@1:2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux%402.34-0.1ubuntu9.1\u0026distro=ubuntu-20.04",
291475          "swid": {
291476            "attachment": {}
291477          },
291478          "pedigree": {},
291479          "evidence": {},
291480          "signature": {
291481            "signature": {
291482              "publicKey": {}
291483            }
291484          },
291485          "modelCard": {
291486            "modelParameters": {
291487              "approach": {}
291488            },
291489            "quantitativeAnalysis": {
291490              "graphics": {}
291491            },
291492            "considerations": {}
291493          }
291494        },
291495        {
291496          "type": "library",
291497          "bom-ref": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=97dab883cac4c956",
291498          "supplier": {},
291499          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291500          "name": "bzip2",
291501          "version": "1.0.8-2",
291502          "licenses": [
291503            {
291504              "license": {
291505                "name": "BSD-variant"
291506              }
291507            },
291508            {
291509              "license": {
291510                "id": "GPL-2.0-only"
291511              }
291512            }
291513          ],
291514          "cpe": "cpe:2.3:a:bzip2:bzip2:1.0.8-2:*:*:*:*:*:*:*",
291515          "purl": "pkg:deb/ubuntu/bzip2@1.0.8-2?arch=amd64\u0026distro=ubuntu-20.04",
291516          "swid": {
291517            "attachment": {}
291518          },
291519          "pedigree": {},
291520          "evidence": {},
291521          "signature": {
291522            "signature": {
291523              "publicKey": {}
291524            }
291525          },
291526          "modelCard": {
291527            "modelParameters": {
291528              "approach": {}
291529            },
291530            "quantitativeAnalysis": {
291531              "graphics": {}
291532            },
291533            "considerations": {}
291534          }
291535        },
291536        {
291537          "type": "library",
291538          "bom-ref": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f77283ee51e117fa",
291539          "supplier": {},
291540          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291541          "name": "coreutils",
291542          "version": "8.30-3ubuntu2",
291543          "licenses": [
291544            {
291545              "license": {
291546                "id": "GPL-3.0-only"
291547              }
291548            }
291549          ],
291550          "cpe": "cpe:2.3:a:coreutils:coreutils:8.30-3ubuntu2:*:*:*:*:*:*:*",
291551          "purl": "pkg:deb/ubuntu/coreutils@8.30-3ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
291552          "swid": {
291553            "attachment": {}
291554          },
291555          "pedigree": {},
291556          "evidence": {},
291557          "signature": {
291558            "signature": {
291559              "publicKey": {}
291560            }
291561          },
291562          "modelCard": {
291563            "modelParameters": {
291564              "approach": {}
291565            },
291566            "quantitativeAnalysis": {
291567              "graphics": {}
291568            },
291569            "considerations": {}
291570          }
291571        },
291572        {
291573          "type": "library",
291574          "bom-ref": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=fa0f613df8411b7",
291575          "supplier": {},
291576          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291577          "name": "dash",
291578          "version": "0.5.10.2-6",
291579          "licenses": [
291580            {
291581              "license": {
291582                "name": "GPL"
291583              }
291584            }
291585          ],
291586          "cpe": "cpe:2.3:a:dash:dash:0.5.10.2-6:*:*:*:*:*:*:*",
291587          "purl": "pkg:deb/ubuntu/dash@0.5.10.2-6?arch=amd64\u0026distro=ubuntu-20.04",
291588          "swid": {
291589            "attachment": {}
291590          },
291591          "pedigree": {},
291592          "evidence": {},
291593          "signature": {
291594            "signature": {
291595              "publicKey": {}
291596            }
291597          },
291598          "modelCard": {
291599            "modelParameters": {
291600              "approach": {}
291601            },
291602            "quantitativeAnalysis": {
291603              "graphics": {}
291604            },
291605            "considerations": {}
291606          }
291607        },
291608        {
291609          "type": "library",
291610          "bom-ref": "pkg:deb/ubuntu/dbus@1.12.16-2ubuntu2.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=d48cd057ec28b1c0",
291611          "supplier": {},
291612          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291613          "name": "dbus",
291614          "version": "1.12.16-2ubuntu2.1",
291615          "licenses": [
291616            {
291617              "license": {
291618                "id": "AFL-2.1"
291619              }
291620            },
291621            {
291622              "license": {
291623                "id": "BSD-3-Clause"
291624              }
291625            },
291626            {
291627              "license": {
291628                "name": "BSD-3-clause-generic"
291629              }
291630            },
291631            {
291632              "license": {
291633                "name": "Expat"
291634              }
291635            },
291636            {
291637              "license": {
291638                "id": "GPL-2.0-only"
291639              }
291640            },
291641            {
291642              "license": {
291643                "id": "GPL-2.0-or-later"
291644              }
291645            },
291646            {
291647              "license": {
291648                "name": "Tcl-BSDish"
291649              }
291650            },
291651            {
291652              "license": {
291653                "name": "g10-permissive"
291654              }
291655            }
291656          ],
291657          "cpe": "cpe:2.3:a:dbus:dbus:1.12.16-2ubuntu2.1:*:*:*:*:*:*:*",
291658          "purl": "pkg:deb/ubuntu/dbus@1.12.16-2ubuntu2.1?arch=amd64\u0026distro=ubuntu-20.04",
291659          "swid": {
291660            "attachment": {}
291661          },
291662          "pedigree": {},
291663          "evidence": {},
291664          "signature": {
291665            "signature": {
291666              "publicKey": {}
291667            }
291668          },
291669          "modelCard": {
291670            "modelParameters": {
291671              "approach": {}
291672            },
291673            "quantitativeAnalysis": {
291674              "graphics": {}
291675            },
291676            "considerations": {}
291677          }
291678        },
291679        {
291680          "type": "library",
291681          "bom-ref": "pkg:deb/ubuntu/dbus-x11@1.12.16-2ubuntu2.1?arch=amd64\u0026upstream=dbus\u0026distro=ubuntu-20.04\u0026package-id=ab4fab48ce6c6367",
291682          "supplier": {},
291683          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291684          "name": "dbus-x11",
291685          "version": "1.12.16-2ubuntu2.1",
291686          "licenses": [
291687            {
291688              "license": {
291689                "id": "AFL-2.1"
291690              }
291691            },
291692            {
291693              "license": {
291694                "id": "BSD-3-Clause"
291695              }
291696            },
291697            {
291698              "license": {
291699                "name": "BSD-3-clause-generic"
291700              }
291701            },
291702            {
291703              "license": {
291704                "name": "Expat"
291705              }
291706            },
291707            {
291708              "license": {
291709                "id": "GPL-2.0-only"
291710              }
291711            },
291712            {
291713              "license": {
291714                "id": "GPL-2.0-or-later"
291715              }
291716            },
291717            {
291718              "license": {
291719                "name": "Tcl-BSDish"
291720              }
291721            },
291722            {
291723              "license": {
291724                "name": "g10-permissive"
291725              }
291726            }
291727          ],
291728          "cpe": "cpe:2.3:a:dbus-x11:dbus-x11:1.12.16-2ubuntu2.1:*:*:*:*:*:*:*",
291729          "purl": "pkg:deb/ubuntu/dbus-x11@1.12.16-2ubuntu2.1?arch=amd64\u0026upstream=dbus\u0026distro=ubuntu-20.04",
291730          "swid": {
291731            "attachment": {}
291732          },
291733          "pedigree": {},
291734          "evidence": {},
291735          "signature": {
291736            "signature": {
291737              "publicKey": {}
291738            }
291739          },
291740          "modelCard": {
291741            "modelParameters": {
291742              "approach": {}
291743            },
291744            "quantitativeAnalysis": {
291745              "graphics": {}
291746            },
291747            "considerations": {}
291748          }
291749        },
291750        {
291751          "type": "library",
291752          "bom-ref": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04\u0026package-id=128eb6066f5ec19c",
291753          "supplier": {},
291754          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291755          "name": "debconf",
291756          "version": "1.5.73",
291757          "licenses": [
291758            {
291759              "license": {
291760                "id": "BSD-2-Clause"
291761              }
291762            }
291763          ],
291764          "cpe": "cpe:2.3:a:debconf:debconf:1.5.73:*:*:*:*:*:*:*",
291765          "purl": "pkg:deb/ubuntu/debconf@1.5.73?arch=all\u0026distro=ubuntu-20.04",
291766          "swid": {
291767            "attachment": {}
291768          },
291769          "pedigree": {},
291770          "evidence": {},
291771          "signature": {
291772            "signature": {
291773              "publicKey": {}
291774            }
291775          },
291776          "modelCard": {
291777            "modelParameters": {
291778              "approach": {}
291779            },
291780            "quantitativeAnalysis": {
291781              "graphics": {}
291782            },
291783            "considerations": {}
291784          }
291785        },
291786        {
291787          "type": "library",
291788          "bom-ref": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=328b1094024bda26",
291789          "supplier": {},
291790          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291791          "name": "debianutils",
291792          "version": "4.9.1",
291793          "licenses": [
291794            {
291795              "license": {
291796                "name": "GPL"
291797              }
291798            }
291799          ],
291800          "cpe": "cpe:2.3:a:debianutils:debianutils:4.9.1:*:*:*:*:*:*:*",
291801          "purl": "pkg:deb/ubuntu/debianutils@4.9.1?arch=amd64\u0026distro=ubuntu-20.04",
291802          "swid": {
291803            "attachment": {}
291804          },
291805          "pedigree": {},
291806          "evidence": {},
291807          "signature": {
291808            "signature": {
291809              "publicKey": {}
291810            }
291811          },
291812          "modelCard": {
291813            "modelParameters": {
291814              "approach": {}
291815            },
291816            "quantitativeAnalysis": {
291817              "graphics": {}
291818            },
291819            "considerations": {}
291820          }
291821        },
291822        {
291823          "type": "library",
291824          "bom-ref": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=d21aefcaf9c9c9b6",
291825          "supplier": {},
291826          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291827          "name": "diffutils",
291828          "version": "1:3.7-3",
291829          "licenses": [
291830            {
291831              "license": {
291832                "name": "GFDL"
291833              }
291834            },
291835            {
291836              "license": {
291837                "name": "GPL"
291838              }
291839            }
291840          ],
291841          "cpe": "cpe:2.3:a:diffutils:diffutils:1\\:3.7-3:*:*:*:*:*:*:*",
291842          "purl": "pkg:deb/ubuntu/diffutils@1:3.7-3?arch=amd64\u0026distro=ubuntu-20.04",
291843          "swid": {
291844            "attachment": {}
291845          },
291846          "pedigree": {},
291847          "evidence": {},
291848          "signature": {
291849            "signature": {
291850              "publicKey": {}
291851            }
291852          },
291853          "modelCard": {
291854            "modelParameters": {
291855              "approach": {}
291856            },
291857            "quantitativeAnalysis": {
291858              "graphics": {}
291859            },
291860            "considerations": {}
291861          }
291862        },
291863        {
291864          "type": "library",
291865          "bom-ref": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=c0d6316be2747294",
291866          "supplier": {},
291867          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291868          "name": "dmsetup",
291869          "version": "2:1.02.167-1ubuntu1",
291870          "licenses": [
291871            {
291872              "license": {
291873                "id": "BSD-2-Clause"
291874              }
291875            },
291876            {
291877              "license": {
291878                "id": "GPL-2.0-only"
291879              }
291880            },
291881            {
291882              "license": {
291883                "id": "GPL-2.0-only"
291884              }
291885            },
291886            {
291887              "license": {
291888                "id": "GPL-2.0-or-later"
291889              }
291890            },
291891            {
291892              "license": {
291893                "id": "LGPL-2.0-only"
291894              }
291895            },
291896            {
291897              "license": {
291898                "id": "LGPL-2.1-only"
291899              }
291900            }
291901          ],
291902          "cpe": "cpe:2.3:a:dmsetup:dmsetup:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
291903          "purl": "pkg:deb/ubuntu/dmsetup@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
291904          "swid": {
291905            "attachment": {}
291906          },
291907          "pedigree": {},
291908          "evidence": {},
291909          "signature": {
291910            "signature": {
291911              "publicKey": {}
291912            }
291913          },
291914          "modelCard": {
291915            "modelParameters": {
291916              "approach": {}
291917            },
291918            "quantitativeAnalysis": {
291919              "graphics": {}
291920            },
291921            "considerations": {}
291922          }
291923        },
291924        {
291925          "type": "library",
291926          "bom-ref": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e28aea5c134a7f8",
291927          "supplier": {},
291928          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291929          "name": "dpkg",
291930          "version": "1.19.7ubuntu3",
291931          "licenses": [
291932            {
291933              "license": {
291934                "id": "BSD-2-Clause"
291935              }
291936            },
291937            {
291938              "license": {
291939                "id": "GPL-2.0-only"
291940              }
291941            },
291942            {
291943              "license": {
291944                "id": "GPL-2.0-or-later"
291945              }
291946            },
291947            {
291948              "license": {
291949                "name": "public-domain-md5"
291950              }
291951            },
291952            {
291953              "license": {
291954                "name": "public-domain-s-s-d"
291955              }
291956            }
291957          ],
291958          "cpe": "cpe:2.3:a:dpkg:dpkg:1.19.7ubuntu3:*:*:*:*:*:*:*",
291959          "purl": "pkg:deb/ubuntu/dpkg@1.19.7ubuntu3?arch=amd64\u0026distro=ubuntu-20.04",
291960          "swid": {
291961            "attachment": {}
291962          },
291963          "pedigree": {},
291964          "evidence": {},
291965          "signature": {
291966            "signature": {
291967              "publicKey": {}
291968            }
291969          },
291970          "modelCard": {
291971            "modelParameters": {
291972              "approach": {}
291973            },
291974            "quantitativeAnalysis": {
291975              "graphics": {}
291976            },
291977            "considerations": {}
291978          }
291979        },
291980        {
291981          "type": "library",
291982          "bom-ref": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=6a037357f3ebf47a",
291983          "supplier": {},
291984          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
291985          "name": "e2fsprogs",
291986          "version": "1.45.5-2ubuntu1",
291987          "licenses": [
291988            {
291989              "license": {
291990                "id": "GPL-2.0-only"
291991              }
291992            },
291993            {
291994              "license": {
291995                "id": "LGPL-2.0-only"
291996              }
291997            }
291998          ],
291999          "cpe": "cpe:2.3:a:e2fsprogs:e2fsprogs:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
292000          "purl": "pkg:deb/ubuntu/e2fsprogs@1.45.5-2ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
292001          "swid": {
292002            "attachment": {}
292003          },
292004          "pedigree": {},
292005          "evidence": {},
292006          "signature": {
292007            "signature": {
292008              "publicKey": {}
292009            }
292010          },
292011          "modelCard": {
292012            "modelParameters": {
292013              "approach": {}
292014            },
292015            "quantitativeAnalysis": {
292016              "graphics": {}
292017            },
292018            "considerations": {}
292019          }
292020        },
292021        {
292022          "type": "library",
292023          "bom-ref": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=a57a5f37c7970fe9",
292024          "supplier": {},
292025          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292026          "name": "fdisk",
292027          "version": "2.34-0.1ubuntu9.1",
292028          "licenses": [
292029            {
292030              "license": {
292031                "id": "BSD-2-Clause"
292032              }
292033            },
292034            {
292035              "license": {
292036                "id": "BSD-3-Clause"
292037              }
292038            },
292039            {
292040              "license": {
292041                "id": "BSD-4-Clause"
292042              }
292043            },
292044            {
292045              "license": {
292046                "id": "GPL-2.0-only"
292047              }
292048            },
292049            {
292050              "license": {
292051                "id": "GPL-2.0-or-later"
292052              }
292053            },
292054            {
292055              "license": {
292056                "id": "GPL-3.0-only"
292057              }
292058            },
292059            {
292060              "license": {
292061                "id": "GPL-3.0-or-later"
292062              }
292063            },
292064            {
292065              "license": {
292066                "name": "LGPL"
292067              }
292068            },
292069            {
292070              "license": {
292071                "id": "LGPL-2.0-only"
292072              }
292073            },
292074            {
292075              "license": {
292076                "id": "LGPL-2.0-or-later"
292077              }
292078            },
292079            {
292080              "license": {
292081                "id": "LGPL-2.1-only"
292082              }
292083            },
292084            {
292085              "license": {
292086                "id": "LGPL-2.1-or-later"
292087              }
292088            },
292089            {
292090              "license": {
292091                "id": "LGPL-3.0-only"
292092              }
292093            },
292094            {
292095              "license": {
292096                "id": "LGPL-3.0-or-later"
292097              }
292098            },
292099            {
292100              "license": {
292101                "id": "MIT"
292102              }
292103            },
292104            {
292105              "license": {
292106                "name": "public-domain"
292107              }
292108            }
292109          ],
292110          "cpe": "cpe:2.3:a:fdisk:fdisk:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
292111          "purl": "pkg:deb/ubuntu/fdisk@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
292112          "swid": {
292113            "attachment": {}
292114          },
292115          "pedigree": {},
292116          "evidence": {},
292117          "signature": {
292118            "signature": {
292119              "publicKey": {}
292120            }
292121          },
292122          "modelCard": {
292123            "modelParameters": {
292124              "approach": {}
292125            },
292126            "quantitativeAnalysis": {
292127              "graphics": {}
292128            },
292129            "considerations": {}
292130          }
292131        },
292132        {
292133          "type": "library",
292134          "bom-ref": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7f183ce6dc05cfb",
292135          "supplier": {},
292136          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292137          "name": "file",
292138          "version": "1:5.38-4",
292139          "licenses": [
292140            {
292141              "license": {
292142                "name": "BSD-2-Clause-alike"
292143              }
292144            },
292145            {
292146              "license": {
292147                "id": "BSD-2-Clause"
292148              }
292149            },
292150            {
292151              "license": {
292152                "name": "BSD-2-Clause-regents"
292153              }
292154            },
292155            {
292156              "license": {
292157                "name": "MIT-Old-Style-with-legal-disclaimer-2"
292158              }
292159            },
292160            {
292161              "license": {
292162                "name": "public-domain"
292163              }
292164            }
292165          ],
292166          "cpe": "cpe:2.3:a:file:file:1\\:5.38-4:*:*:*:*:*:*:*",
292167          "purl": "pkg:deb/ubuntu/file@1:5.38-4?arch=amd64\u0026distro=ubuntu-20.04",
292168          "swid": {
292169            "attachment": {}
292170          },
292171          "pedigree": {},
292172          "evidence": {},
292173          "signature": {
292174            "signature": {
292175              "publicKey": {}
292176            }
292177          },
292178          "modelCard": {
292179            "modelParameters": {
292180              "approach": {}
292181            },
292182            "quantitativeAnalysis": {
292183              "graphics": {}
292184            },
292185            "considerations": {}
292186          }
292187        },
292188        {
292189          "type": "library",
292190          "bom-ref": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=103a5999463b7e08",
292191          "supplier": {},
292192          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292193          "name": "findutils",
292194          "version": "4.7.0-1ubuntu1",
292195          "licenses": [
292196            {
292197              "license": {
292198                "id": "GFDL-1.3-only"
292199              }
292200            },
292201            {
292202              "license": {
292203                "id": "GPL-3.0-only"
292204              }
292205            }
292206          ],
292207          "cpe": "cpe:2.3:a:findutils:findutils:4.7.0-1ubuntu1:*:*:*:*:*:*:*",
292208          "purl": "pkg:deb/ubuntu/findutils@4.7.0-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
292209          "swid": {
292210            "attachment": {}
292211          },
292212          "pedigree": {},
292213          "evidence": {},
292214          "signature": {
292215            "signature": {
292216              "publicKey": {}
292217            }
292218          },
292219          "modelCard": {
292220            "modelParameters": {
292221              "approach": {}
292222            },
292223            "quantitativeAnalysis": {
292224              "graphics": {}
292225            },
292226            "considerations": {}
292227          }
292228        },
292229        {
292230          "type": "library",
292231          "bom-ref": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=a268d6ad2986f239",
292232          "supplier": {},
292233          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292234          "name": "gcc-10-base",
292235          "version": "10.3.0-1ubuntu1~20.04",
292236          "licenses": [
292237            {
292238              "license": {
292239                "name": "Artistic"
292240              }
292241            },
292242            {
292243              "license": {
292244                "id": "GFDL-1.2-only"
292245              }
292246            },
292247            {
292248              "license": {
292249                "name": "GPL"
292250              }
292251            },
292252            {
292253              "license": {
292254                "id": "GPL-2.0-only"
292255              }
292256            },
292257            {
292258              "license": {
292259                "id": "GPL-3.0-only"
292260              }
292261            },
292262            {
292263              "license": {
292264                "name": "LGPL"
292265              }
292266            }
292267          ],
292268          "cpe": "cpe:2.3:a:gcc-10-base:gcc-10-base:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
292269          "purl": "pkg:deb/ubuntu/gcc-10-base@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
292270          "swid": {
292271            "attachment": {}
292272          },
292273          "pedigree": {},
292274          "evidence": {},
292275          "signature": {
292276            "signature": {
292277              "publicKey": {}
292278            }
292279          },
292280          "modelCard": {
292281            "modelParameters": {
292282              "approach": {}
292283            },
292284            "quantitativeAnalysis": {
292285              "graphics": {}
292286            },
292287            "considerations": {}
292288          }
292289        },
292290        {
292291          "type": "library",
292292          "bom-ref": "pkg:golang/github.com/c9s/goprocinfo@v0.0.0-20170724085704-0010a05ce49f?package-id=5afefb79ba65d0ad",
292293          "supplier": {},
292294          "name": "github.com/c9s/goprocinfo",
292295          "version": "v0.0.0-20170724085704-0010a05ce49f",
292296          "cpe": "cpe:2.3:a:c9s:goprocinfo:v0.0.0-20170724085704-0010a05ce49f:*:*:*:*:*:*:*",
292297          "purl": "pkg:golang/github.com/c9s/goprocinfo@v0.0.0-20170724085704-0010a05ce49f",
292298          "swid": {
292299            "attachment": {}
292300          },
292301          "pedigree": {},
292302          "evidence": {},
292303          "signature": {
292304            "signature": {
292305              "publicKey": {}
292306            }
292307          },
292308          "modelCard": {
292309            "modelParameters": {
292310              "approach": {}
292311            },
292312            "quantitativeAnalysis": {
292313              "graphics": {}
292314            },
292315            "considerations": {}
292316          }
292317        },
292318        {
292319          "type": "library",
292320          "bom-ref": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d?package-id=aba9920ef814788c",
292321          "supplier": {},
292322          "name": "github.com/cpuguy83/go-md2man/v2",
292323          "version": "v2.0.0-20190314233015-f79a8a8ca69d",
292324          "cpe": "cpe:2.3:a:cpuguy83:go-md2man\\/v2:v2.0.0-20190314233015-f79a8a8ca69d:*:*:*:*:*:*:*",
292325          "purl": "pkg:golang/github.com/cpuguy83/go-md2man/v2@v2.0.0-20190314233015-f79a8a8ca69d",
292326          "swid": {
292327            "attachment": {}
292328          },
292329          "pedigree": {},
292330          "evidence": {},
292331          "signature": {
292332            "signature": {
292333              "publicKey": {}
292334            }
292335          },
292336          "modelCard": {
292337            "modelParameters": {
292338              "approach": {}
292339            },
292340            "quantitativeAnalysis": {
292341              "graphics": {}
292342            },
292343            "considerations": {}
292344          }
292345        },
292346        {
292347          "type": "library",
292348          "bom-ref": "pkg:golang/github.com/longhorn/go-iscsi-helper@v0.0.0-20210330030558-49a327fb024e?package-id=8f8714a0cea08362",
292349          "supplier": {},
292350          "name": "github.com/longhorn/go-iscsi-helper",
292351          "version": "v0.0.0-20210330030558-49a327fb024e",
292352          "cpe": "cpe:2.3:a:longhorn:go-iscsi-helper:v0.0.0-20210330030558-49a327fb024e:*:*:*:*:*:*:*",
292353          "purl": "pkg:golang/github.com/longhorn/go-iscsi-helper@v0.0.0-20210330030558-49a327fb024e",
292354          "swid": {
292355            "attachment": {}
292356          },
292357          "pedigree": {},
292358          "evidence": {},
292359          "signature": {
292360            "signature": {
292361              "publicKey": {}
292362            }
292363          },
292364          "modelCard": {
292365            "modelParameters": {
292366              "approach": {}
292367            },
292368            "quantitativeAnalysis": {
292369              "graphics": {}
292370            },
292371            "considerations": {}
292372          }
292373        },
292374        {
292375          "type": "library",
292376          "bom-ref": "pkg:golang/github.com/longhorn/longhorn-share-manager@(devel)?package-id=a622c42a40ecccff",
292377          "supplier": {},
292378          "name": "github.com/longhorn/longhorn-share-manager",
292379          "version": "(devel)",
292380          "cpe": "cpe:2.3:a:longhorn:longhorn-share-manager:\\(devel\\):*:*:*:*:*:*:*",
292381          "purl": "pkg:golang/github.com/longhorn/longhorn-share-manager@(devel)",
292382          "swid": {
292383            "attachment": {}
292384          },
292385          "pedigree": {},
292386          "evidence": {},
292387          "signature": {
292388            "signature": {
292389              "publicKey": {}
292390            }
292391          },
292392          "modelCard": {
292393            "modelParameters": {
292394              "approach": {}
292395            },
292396            "quantitativeAnalysis": {
292397              "graphics": {}
292398            },
292399            "considerations": {}
292400          }
292401        },
292402        {
292403          "type": "library",
292404          "bom-ref": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1?package-id=16d5d3d84d04c2ea",
292405          "supplier": {},
292406          "name": "github.com/russross/blackfriday/v2",
292407          "version": "v2.0.1",
292408          "cpe": "cpe:2.3:a:russross:blackfriday\\/v2:v2.0.1:*:*:*:*:*:*:*",
292409          "purl": "pkg:golang/github.com/russross/blackfriday/v2@v2.0.1",
292410          "swid": {
292411            "attachment": {}
292412          },
292413          "pedigree": {},
292414          "evidence": {},
292415          "signature": {
292416            "signature": {
292417              "publicKey": {}
292418            }
292419          },
292420          "modelCard": {
292421            "modelParameters": {
292422              "approach": {}
292423            },
292424            "quantitativeAnalysis": {
292425              "graphics": {}
292426            },
292427            "considerations": {}
292428          }
292429        },
292430        {
292431          "type": "library",
292432          "bom-ref": "pkg:golang/github.com/shurcool/sanitized_anchor_name@v1.0.0?package-id=249f5a2feb25f602",
292433          "supplier": {},
292434          "name": "github.com/shurcooL/sanitized_anchor_name",
292435          "version": "v1.0.0",
292436          "cpe": "cpe:2.3:a:shurcooL:sanitized-anchor-name:v1.0.0:*:*:*:*:*:*:*",
292437          "purl": "pkg:golang/github.com/shurcooL/sanitized_anchor_name@v1.0.0",
292438          "swid": {
292439            "attachment": {}
292440          },
292441          "pedigree": {},
292442          "evidence": {},
292443          "signature": {
292444            "signature": {
292445              "publicKey": {}
292446            }
292447          },
292448          "modelCard": {
292449            "modelParameters": {
292450              "approach": {}
292451            },
292452            "quantitativeAnalysis": {
292453              "graphics": {}
292454            },
292455            "considerations": {}
292456          }
292457        },
292458        {
292459          "type": "library",
292460          "bom-ref": "pkg:golang/github.com/sirupsen/logrus@v1.4.2?package-id=c5b63fc8fe490fde",
292461          "supplier": {},
292462          "name": "github.com/sirupsen/logrus",
292463          "version": "v1.4.2",
292464          "cpe": "cpe:2.3:a:sirupsen:logrus:v1.4.2:*:*:*:*:*:*:*",
292465          "purl": "pkg:golang/github.com/sirupsen/logrus@v1.4.2",
292466          "swid": {
292467            "attachment": {}
292468          },
292469          "pedigree": {},
292470          "evidence": {},
292471          "signature": {
292472            "signature": {
292473              "publicKey": {}
292474            }
292475          },
292476          "modelCard": {
292477            "modelParameters": {
292478              "approach": {}
292479            },
292480            "quantitativeAnalysis": {
292481              "graphics": {}
292482            },
292483            "considerations": {}
292484          }
292485        },
292486        {
292487          "type": "library",
292488          "bom-ref": "pkg:golang/github.com/urfave/cli@v1.22.1?package-id=2191036db3d08d14",
292489          "supplier": {},
292490          "name": "github.com/urfave/cli",
292491          "version": "v1.22.1",
292492          "cpe": "cpe:2.3:a:urfave:cli:v1.22.1:*:*:*:*:*:*:*",
292493          "purl": "pkg:golang/github.com/urfave/cli@v1.22.1",
292494          "swid": {
292495            "attachment": {}
292496          },
292497          "pedigree": {},
292498          "evidence": {},
292499          "signature": {
292500            "signature": {
292501              "publicKey": {}
292502            }
292503          },
292504          "modelCard": {
292505            "modelParameters": {
292506              "approach": {}
292507            },
292508            "quantitativeAnalysis": {
292509              "graphics": {}
292510            },
292511            "considerations": {}
292512          }
292513        },
292514        {
292515          "type": "library",
292516          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f?package-id=86f4aba6305ceccc",
292517          "supplier": {},
292518          "name": "golang.org/x/sys",
292519          "version": "v0.0.0-20200930185726-fdedc70b468f",
292520          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20200930185726-fdedc70b468f:*:*:*:*:*:*:*",
292521          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20200930185726-fdedc70b468f",
292522          "swid": {
292523            "attachment": {}
292524          },
292525          "pedigree": {},
292526          "evidence": {},
292527          "signature": {
292528            "signature": {
292529              "publicKey": {}
292530            }
292531          },
292532          "modelCard": {
292533            "modelParameters": {
292534              "approach": {}
292535            },
292536            "quantitativeAnalysis": {
292537              "graphics": {}
292538            },
292539            "considerations": {}
292540          }
292541        },
292542        {
292543          "type": "library",
292544          "bom-ref": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04\u0026package-id=b3a56223224b45d2",
292545          "supplier": {},
292546          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292547          "name": "gpgv",
292548          "version": "2.2.19-3ubuntu2.1",
292549          "licenses": [
292550            {
292551              "license": {
292552                "id": "BSD-3-Clause"
292553              }
292554            },
292555            {
292556              "license": {
292557                "id": "CC0-1.0"
292558              }
292559            },
292560            {
292561              "license": {
292562                "name": "Expat"
292563              }
292564            },
292565            {
292566              "license": {
292567                "id": "GPL-3.0-only"
292568              }
292569            },
292570            {
292571              "license": {
292572                "id": "GPL-3.0-or-later"
292573              }
292574            },
292575            {
292576              "license": {
292577                "id": "LGPL-2.1-only"
292578              }
292579            },
292580            {
292581              "license": {
292582                "id": "LGPL-2.1-or-later"
292583              }
292584            },
292585            {
292586              "license": {
292587                "id": "LGPL-3.0-only"
292588              }
292589            },
292590            {
292591              "license": {
292592                "id": "LGPL-3.0-or-later"
292593              }
292594            },
292595            {
292596              "license": {
292597                "name": "RFC-Reference"
292598              }
292599            },
292600            {
292601              "license": {
292602                "name": "TinySCHEME"
292603              }
292604            },
292605            {
292606              "license": {
292607                "name": "permissive"
292608              }
292609            }
292610          ],
292611          "cpe": "cpe:2.3:a:gpgv:gpgv:2.2.19-3ubuntu2.1:*:*:*:*:*:*:*",
292612          "purl": "pkg:deb/ubuntu/gpgv@2.2.19-3ubuntu2.1?arch=amd64\u0026upstream=gnupg2\u0026distro=ubuntu-20.04",
292613          "swid": {
292614            "attachment": {}
292615          },
292616          "pedigree": {},
292617          "evidence": {},
292618          "signature": {
292619            "signature": {
292620              "publicKey": {}
292621            }
292622          },
292623          "modelCard": {
292624            "modelParameters": {
292625              "approach": {}
292626            },
292627            "quantitativeAnalysis": {
292628              "graphics": {}
292629            },
292630            "considerations": {}
292631          }
292632        },
292633        {
292634          "type": "library",
292635          "bom-ref": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e7af9af4b90473f",
292636          "supplier": {},
292637          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292638          "name": "grep",
292639          "version": "3.4-1",
292640          "licenses": [
292641            {
292642              "license": {
292643                "id": "GPL-3.0-only"
292644              }
292645            },
292646            {
292647              "license": {
292648                "id": "GPL-3.0-or-later"
292649              }
292650            }
292651          ],
292652          "cpe": "cpe:2.3:a:grep:grep:3.4-1:*:*:*:*:*:*:*",
292653          "purl": "pkg:deb/ubuntu/grep@3.4-1?arch=amd64\u0026distro=ubuntu-20.04",
292654          "swid": {
292655            "attachment": {}
292656          },
292657          "pedigree": {},
292658          "evidence": {},
292659          "signature": {
292660            "signature": {
292661              "publicKey": {}
292662            }
292663          },
292664          "modelCard": {
292665            "modelParameters": {
292666              "approach": {}
292667            },
292668            "quantitativeAnalysis": {
292669              "graphics": {}
292670            },
292671            "considerations": {}
292672          }
292673        },
292674        {
292675          "type": "library",
292676          "bom-ref": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a9696917d3b9f9fc",
292677          "supplier": {},
292678          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292679          "name": "gzip",
292680          "version": "1.10-0ubuntu4",
292681          "licenses": [
292682            {
292683              "license": {
292684                "name": "GPL"
292685              }
292686            }
292687          ],
292688          "cpe": "cpe:2.3:a:gzip:gzip:1.10-0ubuntu4:*:*:*:*:*:*:*",
292689          "purl": "pkg:deb/ubuntu/gzip@1.10-0ubuntu4?arch=amd64\u0026distro=ubuntu-20.04",
292690          "swid": {
292691            "attachment": {}
292692          },
292693          "pedigree": {},
292694          "evidence": {},
292695          "signature": {
292696            "signature": {
292697              "publicKey": {}
292698            }
292699          },
292700          "modelCard": {
292701            "modelParameters": {
292702              "approach": {}
292703            },
292704            "quantitativeAnalysis": {
292705              "graphics": {}
292706            },
292707            "considerations": {}
292708          }
292709        },
292710        {
292711          "type": "library",
292712          "bom-ref": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=263dae70cc8e6a4f",
292713          "supplier": {},
292714          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292715          "name": "hostname",
292716          "version": "3.23",
292717          "licenses": [
292718            {
292719              "license": {
292720                "id": "GPL-2.0-only"
292721              }
292722            }
292723          ],
292724          "cpe": "cpe:2.3:a:hostname:hostname:3.23:*:*:*:*:*:*:*",
292725          "purl": "pkg:deb/ubuntu/hostname@3.23?arch=amd64\u0026distro=ubuntu-20.04",
292726          "swid": {
292727            "attachment": {}
292728          },
292729          "pedigree": {},
292730          "evidence": {},
292731          "signature": {
292732            "signature": {
292733              "publicKey": {}
292734            }
292735          },
292736          "modelCard": {
292737            "modelParameters": {
292738              "approach": {}
292739            },
292740            "quantitativeAnalysis": {
292741              "graphics": {}
292742            },
292743            "considerations": {}
292744          }
292745        },
292746        {
292747          "type": "library",
292748          "bom-ref": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04\u0026package-id=b0e335d96f12154d",
292749          "supplier": {},
292750          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292751          "name": "init-system-helpers",
292752          "version": "1.57",
292753          "licenses": [
292754            {
292755              "license": {
292756                "id": "BSD-3-Clause"
292757              }
292758            },
292759            {
292760              "license": {
292761                "id": "GPL-2.0-only"
292762              }
292763            },
292764            {
292765              "license": {
292766                "id": "GPL-2.0-or-later"
292767              }
292768            }
292769          ],
292770          "cpe": "cpe:2.3:a:init-system-helpers:init-system-helpers:1.57:*:*:*:*:*:*:*",
292771          "purl": "pkg:deb/ubuntu/init-system-helpers@1.57?arch=all\u0026distro=ubuntu-20.04",
292772          "swid": {
292773            "attachment": {}
292774          },
292775          "pedigree": {},
292776          "evidence": {},
292777          "signature": {
292778            "signature": {
292779              "publicKey": {}
292780            }
292781          },
292782          "modelCard": {
292783            "modelParameters": {
292784              "approach": {}
292785            },
292786            "quantitativeAnalysis": {
292787              "graphics": {}
292788            },
292789            "considerations": {}
292790          }
292791        },
292792        {
292793          "type": "library",
292794          "bom-ref": "pkg:golang/k8s.io/klog@v1.0.0?package-id=7a29956a571778b7",
292795          "supplier": {},
292796          "name": "k8s.io/klog",
292797          "version": "v1.0.0",
292798          "purl": "pkg:golang/k8s.io/klog@v1.0.0",
292799          "swid": {
292800            "attachment": {}
292801          },
292802          "pedigree": {},
292803          "evidence": {},
292804          "signature": {
292805            "signature": {
292806              "publicKey": {}
292807            }
292808          },
292809          "modelCard": {
292810            "modelParameters": {
292811              "approach": {}
292812            },
292813            "quantitativeAnalysis": {
292814              "graphics": {}
292815            },
292816            "considerations": {}
292817          }
292818        },
292819        {
292820          "type": "library",
292821          "bom-ref": "pkg:golang/k8s.io/kubernetes@v1.16.15?package-id=e6f002049b6fc2e4",
292822          "supplier": {},
292823          "name": "k8s.io/kubernetes",
292824          "version": "v1.16.15",
292825          "purl": "pkg:golang/k8s.io/kubernetes@v1.16.15",
292826          "swid": {
292827            "attachment": {}
292828          },
292829          "pedigree": {},
292830          "evidence": {},
292831          "signature": {
292832            "signature": {
292833              "publicKey": {}
292834            }
292835          },
292836          "modelCard": {
292837            "modelParameters": {
292838              "approach": {}
292839            },
292840            "quantitativeAnalysis": {
292841              "graphics": {}
292842            },
292843            "considerations": {}
292844          }
292845        },
292846        {
292847          "type": "library",
292848          "bom-ref": "pkg:golang/k8s.io/utils@v0.0.0-20190801114015-581e00157fb1?package-id=3a47bbf26714fca6",
292849          "supplier": {},
292850          "name": "k8s.io/utils",
292851          "version": "v0.0.0-20190801114015-581e00157fb1",
292852          "purl": "pkg:golang/k8s.io/utils@v0.0.0-20190801114015-581e00157fb1",
292853          "swid": {
292854            "attachment": {}
292855          },
292856          "pedigree": {},
292857          "evidence": {},
292858          "signature": {
292859            "signature": {
292860              "publicKey": {}
292861            }
292862          },
292863          "modelCard": {
292864            "modelParameters": {
292865              "approach": {}
292866            },
292867            "quantitativeAnalysis": {
292868              "graphics": {}
292869            },
292870            "considerations": {}
292871          }
292872        },
292873        {
292874          "type": "library",
292875          "bom-ref": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a61b8b47cf58815b",
292876          "supplier": {},
292877          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292878          "name": "keyutils",
292879          "version": "1.6-6ubuntu1",
292880          "licenses": [
292881            {
292882              "license": {
292883                "id": "GPL-2.0-only"
292884              }
292885            },
292886            {
292887              "license": {
292888                "id": "GPL-2.0-or-later"
292889              }
292890            },
292891            {
292892              "license": {
292893                "id": "LGPL-2.0-only"
292894              }
292895            },
292896            {
292897              "license": {
292898                "id": "LGPL-2.0-or-later"
292899              }
292900            }
292901          ],
292902          "cpe": "cpe:2.3:a:keyutils:keyutils:1.6-6ubuntu1:*:*:*:*:*:*:*",
292903          "purl": "pkg:deb/ubuntu/keyutils@1.6-6ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
292904          "swid": {
292905            "attachment": {}
292906          },
292907          "pedigree": {},
292908          "evidence": {},
292909          "signature": {
292910            "signature": {
292911              "publicKey": {}
292912            }
292913          },
292914          "modelCard": {
292915            "modelParameters": {
292916              "approach": {}
292917            },
292918            "quantitativeAnalysis": {
292919              "graphics": {}
292920            },
292921            "considerations": {}
292922          }
292923        },
292924        {
292925          "type": "library",
292926          "bom-ref": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=87ea48972fb4adab",
292927          "supplier": {},
292928          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292929          "name": "krb5-locales",
292930          "version": "1.17-6ubuntu4.1",
292931          "licenses": [
292932            {
292933              "license": {
292934                "id": "GPL-2.0-only"
292935              }
292936            }
292937          ],
292938          "cpe": "cpe:2.3:a:krb5-locales:krb5-locales:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
292939          "purl": "pkg:deb/ubuntu/krb5-locales@1.17-6ubuntu4.1?arch=all\u0026upstream=krb5\u0026distro=ubuntu-20.04",
292940          "swid": {
292941            "attachment": {}
292942          },
292943          "pedigree": {},
292944          "evidence": {},
292945          "signature": {
292946            "signature": {
292947              "publicKey": {}
292948            }
292949          },
292950          "modelCard": {
292951            "modelParameters": {
292952              "approach": {}
292953            },
292954            "quantitativeAnalysis": {
292955              "graphics": {}
292956            },
292957            "considerations": {}
292958          }
292959        },
292960        {
292961          "type": "library",
292962          "bom-ref": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04\u0026package-id=5cec2c2009596050",
292963          "supplier": {},
292964          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
292965          "name": "libacl1",
292966          "version": "2.2.53-6",
292967          "licenses": [
292968            {
292969              "license": {
292970                "id": "GPL-2.0-only"
292971              }
292972            },
292973            {
292974              "license": {
292975                "id": "GPL-2.0-or-later"
292976              }
292977            },
292978            {
292979              "license": {
292980                "id": "LGPL-2.0-or-later"
292981              }
292982            },
292983            {
292984              "license": {
292985                "id": "LGPL-2.1-only"
292986              }
292987            }
292988          ],
292989          "cpe": "cpe:2.3:a:libacl1:libacl1:2.2.53-6:*:*:*:*:*:*:*",
292990          "purl": "pkg:deb/ubuntu/libacl1@2.2.53-6?arch=amd64\u0026upstream=acl\u0026distro=ubuntu-20.04",
292991          "swid": {
292992            "attachment": {}
292993          },
292994          "pedigree": {},
292995          "evidence": {},
292996          "signature": {
292997            "signature": {
292998              "publicKey": {}
292999            }
293000          },
293001          "modelCard": {
293002            "modelParameters": {
293003              "approach": {}
293004            },
293005            "quantitativeAnalysis": {
293006              "graphics": {}
293007            },
293008            "considerations": {}
293009          }
293010        },
293011        {
293012          "type": "library",
293013          "bom-ref": "pkg:deb/ubuntu/libapparmor1@2.13.3-7ubuntu5.1?arch=amd64\u0026upstream=apparmor\u0026distro=ubuntu-20.04\u0026package-id=efab527cfb41aa1b",
293014          "supplier": {},
293015          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293016          "name": "libapparmor1",
293017          "version": "2.13.3-7ubuntu5.1",
293018          "licenses": [
293019            {
293020              "license": {
293021                "id": "BSD-3-Clause"
293022              }
293023            },
293024            {
293025              "license": {
293026                "id": "GPL-2.0-only"
293027              }
293028            },
293029            {
293030              "license": {
293031                "id": "GPL-2.0-or-later"
293032              }
293033            },
293034            {
293035              "license": {
293036                "id": "LGPL-2.1-only"
293037              }
293038            },
293039            {
293040              "license": {
293041                "id": "LGPL-2.1-or-later"
293042              }
293043            }
293044          ],
293045          "cpe": "cpe:2.3:a:libapparmor1:libapparmor1:2.13.3-7ubuntu5.1:*:*:*:*:*:*:*",
293046          "purl": "pkg:deb/ubuntu/libapparmor1@2.13.3-7ubuntu5.1?arch=amd64\u0026upstream=apparmor\u0026distro=ubuntu-20.04",
293047          "swid": {
293048            "attachment": {}
293049          },
293050          "pedigree": {},
293051          "evidence": {},
293052          "signature": {
293053            "signature": {
293054              "publicKey": {}
293055            }
293056          },
293057          "modelCard": {
293058            "modelParameters": {
293059              "approach": {}
293060            },
293061            "quantitativeAnalysis": {
293062              "graphics": {}
293063            },
293064            "considerations": {}
293065          }
293066        },
293067        {
293068          "type": "library",
293069          "bom-ref": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04\u0026package-id=864e143f4c606a6c",
293070          "supplier": {},
293071          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293072          "name": "libapt-pkg6.0",
293073          "version": "2.0.6",
293074          "licenses": [
293075            {
293076              "license": {
293077                "id": "GPL-2.0-only"
293078              }
293079            },
293080            {
293081              "license": {
293082                "name": "GPLv2+"
293083              }
293084            }
293085          ],
293086          "cpe": "cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.0.6:*:*:*:*:*:*:*",
293087          "purl": "pkg:deb/ubuntu/libapt-pkg6.0@2.0.6?arch=amd64\u0026upstream=apt\u0026distro=ubuntu-20.04",
293088          "swid": {
293089            "attachment": {}
293090          },
293091          "pedigree": {},
293092          "evidence": {},
293093          "signature": {
293094            "signature": {
293095              "publicKey": {}
293096            }
293097          },
293098          "modelCard": {
293099            "modelParameters": {
293100              "approach": {}
293101            },
293102            "quantitativeAnalysis": {
293103              "graphics": {}
293104            },
293105            "considerations": {}
293106          }
293107        },
293108        {
293109          "type": "library",
293110          "bom-ref": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=915f8cf154d1b7ce",
293111          "supplier": {},
293112          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293113          "name": "libasn1-8-heimdal",
293114          "version": "7.7.0+dfsg-1ubuntu1",
293115          "licenses": [
293116            {
293117              "license": {
293118                "id": "BSD-3-Clause"
293119              }
293120            },
293121            {
293122              "license": {
293123                "id": "GPL-2.0-only"
293124              }
293125            },
293126            {
293127              "license": {
293128                "id": "GPL-2.0-or-later"
293129              }
293130            },
293131            {
293132              "license": {
293133                "name": "custom"
293134              }
293135            }
293136          ],
293137          "cpe": "cpe:2.3:a:libasn1-8-heimdal:libasn1-8-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
293138          "purl": "pkg:deb/ubuntu/libasn1-8-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
293139          "swid": {
293140            "attachment": {}
293141          },
293142          "pedigree": {},
293143          "evidence": {},
293144          "signature": {
293145            "signature": {
293146              "publicKey": {}
293147            }
293148          },
293149          "modelCard": {
293150            "modelParameters": {
293151              "approach": {}
293152            },
293153            "quantitativeAnalysis": {
293154              "graphics": {}
293155            },
293156            "considerations": {}
293157          }
293158        },
293159        {
293160          "type": "library",
293161          "bom-ref": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04\u0026package-id=edf8dd62bd537bd5",
293162          "supplier": {},
293163          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293164          "name": "libattr1",
293165          "version": "1:2.4.48-5",
293166          "licenses": [
293167            {
293168              "license": {
293169                "id": "GPL-2.0-only"
293170              }
293171            },
293172            {
293173              "license": {
293174                "id": "GPL-2.0-or-later"
293175              }
293176            },
293177            {
293178              "license": {
293179                "id": "LGPL-2.0-or-later"
293180              }
293181            },
293182            {
293183              "license": {
293184                "id": "LGPL-2.1-only"
293185              }
293186            }
293187          ],
293188          "cpe": "cpe:2.3:a:libattr1:libattr1:1\\:2.4.48-5:*:*:*:*:*:*:*",
293189          "purl": "pkg:deb/ubuntu/libattr1@1:2.4.48-5?arch=amd64\u0026upstream=attr\u0026distro=ubuntu-20.04",
293190          "swid": {
293191            "attachment": {}
293192          },
293193          "pedigree": {},
293194          "evidence": {},
293195          "signature": {
293196            "signature": {
293197              "publicKey": {}
293198            }
293199          },
293200          "modelCard": {
293201            "modelParameters": {
293202              "approach": {}
293203            },
293204            "quantitativeAnalysis": {
293205              "graphics": {}
293206            },
293207            "considerations": {}
293208          }
293209        },
293210        {
293211          "type": "library",
293212          "bom-ref": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=4a463ab850d7c68c",
293213          "supplier": {},
293214          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293215          "name": "libaudit-common",
293216          "version": "1:2.8.5-2ubuntu6",
293217          "licenses": [
293218            {
293219              "license": {
293220                "id": "GPL-1.0-only"
293221              }
293222            },
293223            {
293224              "license": {
293225                "id": "GPL-2.0-only"
293226              }
293227            },
293228            {
293229              "license": {
293230                "id": "LGPL-2.1-only"
293231              }
293232            }
293233          ],
293234          "cpe": "cpe:2.3:a:libaudit-common:libaudit-common:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
293235          "purl": "pkg:deb/ubuntu/libaudit-common@1:2.8.5-2ubuntu6?arch=all\u0026upstream=audit\u0026distro=ubuntu-20.04",
293236          "swid": {
293237            "attachment": {}
293238          },
293239          "pedigree": {},
293240          "evidence": {},
293241          "signature": {
293242            "signature": {
293243              "publicKey": {}
293244            }
293245          },
293246          "modelCard": {
293247            "modelParameters": {
293248              "approach": {}
293249            },
293250            "quantitativeAnalysis": {
293251              "graphics": {}
293252            },
293253            "considerations": {}
293254          }
293255        },
293256        {
293257          "type": "library",
293258          "bom-ref": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04\u0026package-id=be9537deb8db616e",
293259          "supplier": {},
293260          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293261          "name": "libaudit1",
293262          "version": "1:2.8.5-2ubuntu6",
293263          "licenses": [
293264            {
293265              "license": {
293266                "id": "GPL-1.0-only"
293267              }
293268            },
293269            {
293270              "license": {
293271                "id": "GPL-2.0-only"
293272              }
293273            },
293274            {
293275              "license": {
293276                "id": "LGPL-2.1-only"
293277              }
293278            }
293279          ],
293280          "cpe": "cpe:2.3:a:libaudit1:libaudit1:1\\:2.8.5-2ubuntu6:*:*:*:*:*:*:*",
293281          "purl": "pkg:deb/ubuntu/libaudit1@1:2.8.5-2ubuntu6?arch=amd64\u0026upstream=audit\u0026distro=ubuntu-20.04",
293282          "swid": {
293283            "attachment": {}
293284          },
293285          "pedigree": {},
293286          "evidence": {},
293287          "signature": {
293288            "signature": {
293289              "publicKey": {}
293290            }
293291          },
293292          "modelCard": {
293293            "modelParameters": {
293294              "approach": {}
293295            },
293296            "quantitativeAnalysis": {
293297              "graphics": {}
293298            },
293299            "considerations": {}
293300          }
293301        },
293302        {
293303          "type": "library",
293304          "bom-ref": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=e1d6f2e998332d7d",
293305          "supplier": {},
293306          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293307          "name": "libblkid1",
293308          "version": "2.34-0.1ubuntu9.1",
293309          "licenses": [
293310            {
293311              "license": {
293312                "id": "BSD-2-Clause"
293313              }
293314            },
293315            {
293316              "license": {
293317                "id": "BSD-3-Clause"
293318              }
293319            },
293320            {
293321              "license": {
293322                "id": "BSD-4-Clause"
293323              }
293324            },
293325            {
293326              "license": {
293327                "id": "GPL-2.0-only"
293328              }
293329            },
293330            {
293331              "license": {
293332                "id": "GPL-2.0-or-later"
293333              }
293334            },
293335            {
293336              "license": {
293337                "id": "GPL-3.0-only"
293338              }
293339            },
293340            {
293341              "license": {
293342                "id": "GPL-3.0-or-later"
293343              }
293344            },
293345            {
293346              "license": {
293347                "name": "LGPL"
293348              }
293349            },
293350            {
293351              "license": {
293352                "id": "LGPL-2.0-only"
293353              }
293354            },
293355            {
293356              "license": {
293357                "id": "LGPL-2.0-or-later"
293358              }
293359            },
293360            {
293361              "license": {
293362                "id": "LGPL-2.1-only"
293363              }
293364            },
293365            {
293366              "license": {
293367                "id": "LGPL-2.1-or-later"
293368              }
293369            },
293370            {
293371              "license": {
293372                "id": "LGPL-3.0-only"
293373              }
293374            },
293375            {
293376              "license": {
293377                "id": "LGPL-3.0-or-later"
293378              }
293379            },
293380            {
293381              "license": {
293382                "id": "MIT"
293383              }
293384            },
293385            {
293386              "license": {
293387                "name": "public-domain"
293388              }
293389            }
293390          ],
293391          "cpe": "cpe:2.3:a:libblkid1:libblkid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
293392          "purl": "pkg:deb/ubuntu/libblkid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
293393          "swid": {
293394            "attachment": {}
293395          },
293396          "pedigree": {},
293397          "evidence": {},
293398          "signature": {
293399            "signature": {
293400              "publicKey": {}
293401            }
293402          },
293403          "modelCard": {
293404            "modelParameters": {
293405              "approach": {}
293406            },
293407            "quantitativeAnalysis": {
293408              "graphics": {}
293409            },
293410            "considerations": {}
293411          }
293412        },
293413        {
293414          "type": "library",
293415          "bom-ref": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04\u0026package-id=88ee716d66a17869",
293416          "supplier": {},
293417          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293418          "name": "libbsd0",
293419          "version": "0.10.0-1",
293420          "licenses": [
293421            {
293422              "license": {
293423                "id": "BSD-2-Clause"
293424              }
293425            },
293426            {
293427              "license": {
293428                "id": "BSD-2-Clause"
293429              }
293430            },
293431            {
293432              "license": {
293433                "name": "BSD-2-clause-author"
293434              }
293435            },
293436            {
293437              "license": {
293438                "name": "BSD-2-clause-verbatim"
293439              }
293440            },
293441            {
293442              "license": {
293443                "id": "BSD-3-Clause"
293444              }
293445            },
293446            {
293447              "license": {
293448                "name": "BSD-3-clause-John-Birrell"
293449              }
293450            },
293451            {
293452              "license": {
293453                "name": "BSD-3-clause-Regents"
293454              }
293455            },
293456            {
293457              "license": {
293458                "name": "BSD-3-clause-author"
293459              }
293460            },
293461            {
293462              "license": {
293463                "name": "BSD-4-clause-Christopher-G-Demetriou"
293464              }
293465            },
293466            {
293467              "license": {
293468                "name": "BSD-4-clause-Niels-Provos"
293469              }
293470            },
293471            {
293472              "license": {
293473                "name": "BSD-5-clause-Peter-Wemm"
293474              }
293475            },
293476            {
293477              "license": {
293478                "id": "Beerware"
293479              }
293480            },
293481            {
293482              "license": {
293483                "name": "Expat"
293484              }
293485            },
293486            {
293487              "license": {
293488                "id": "ISC"
293489              }
293490            },
293491            {
293492              "license": {
293493                "name": "ISC-Original"
293494              }
293495            },
293496            {
293497              "license": {
293498                "name": "public-domain"
293499              }
293500            },
293501            {
293502              "license": {
293503                "name": "public-domain-Colin-Plumb"
293504              }
293505            }
293506          ],
293507          "cpe": "cpe:2.3:a:libbsd0:libbsd0:0.10.0-1:*:*:*:*:*:*:*",
293508          "purl": "pkg:deb/ubuntu/libbsd0@0.10.0-1?arch=amd64\u0026upstream=libbsd\u0026distro=ubuntu-20.04",
293509          "swid": {
293510            "attachment": {}
293511          },
293512          "pedigree": {},
293513          "evidence": {},
293514          "signature": {
293515            "signature": {
293516              "publicKey": {}
293517            }
293518          },
293519          "modelCard": {
293520            "modelParameters": {
293521              "approach": {}
293522            },
293523            "quantitativeAnalysis": {
293524              "graphics": {}
293525            },
293526            "considerations": {}
293527          }
293528        },
293529        {
293530          "type": "library",
293531          "bom-ref": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04\u0026package-id=fd8b0edf257b69b7",
293532          "supplier": {},
293533          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293534          "name": "libbz2-1.0",
293535          "version": "1.0.8-2",
293536          "licenses": [
293537            {
293538              "license": {
293539                "name": "BSD-variant"
293540              }
293541            },
293542            {
293543              "license": {
293544                "id": "GPL-2.0-only"
293545              }
293546            }
293547          ],
293548          "cpe": "cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-2:*:*:*:*:*:*:*",
293549          "purl": "pkg:deb/ubuntu/libbz2-1.0@1.0.8-2?arch=amd64\u0026upstream=bzip2\u0026distro=ubuntu-20.04",
293550          "swid": {
293551            "attachment": {}
293552          },
293553          "pedigree": {},
293554          "evidence": {},
293555          "signature": {
293556            "signature": {
293557              "publicKey": {}
293558            }
293559          },
293560          "modelCard": {
293561            "modelParameters": {
293562              "approach": {}
293563            },
293564            "quantitativeAnalysis": {
293565              "graphics": {}
293566            },
293567            "considerations": {}
293568          }
293569        },
293570        {
293571          "type": "library",
293572          "bom-ref": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=256facf7cbb95a65",
293573          "supplier": {},
293574          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293575          "name": "libc-bin",
293576          "version": "2.31-0ubuntu9.2",
293577          "licenses": [
293578            {
293579              "license": {
293580                "id": "GPL-2.0-only"
293581              }
293582            },
293583            {
293584              "license": {
293585                "id": "LGPL-2.1-only"
293586              }
293587            }
293588          ],
293589          "cpe": "cpe:2.3:a:libc-bin:libc-bin:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
293590          "purl": "pkg:deb/ubuntu/libc-bin@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
293591          "swid": {
293592            "attachment": {}
293593          },
293594          "pedigree": {},
293595          "evidence": {},
293596          "signature": {
293597            "signature": {
293598              "publicKey": {}
293599            }
293600          },
293601          "modelCard": {
293602            "modelParameters": {
293603              "approach": {}
293604            },
293605            "quantitativeAnalysis": {
293606              "graphics": {}
293607            },
293608            "considerations": {}
293609          }
293610        },
293611        {
293612          "type": "library",
293613          "bom-ref": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04\u0026package-id=2a96b94fa4db214",
293614          "supplier": {},
293615          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293616          "name": "libc6",
293617          "version": "2.31-0ubuntu9.2",
293618          "licenses": [
293619            {
293620              "license": {
293621                "id": "GPL-2.0-only"
293622              }
293623            },
293624            {
293625              "license": {
293626                "id": "LGPL-2.1-only"
293627              }
293628            }
293629          ],
293630          "cpe": "cpe:2.3:a:libc6:libc6:2.31-0ubuntu9.2:*:*:*:*:*:*:*",
293631          "purl": "pkg:deb/ubuntu/libc6@2.31-0ubuntu9.2?arch=amd64\u0026upstream=glibc\u0026distro=ubuntu-20.04",
293632          "swid": {
293633            "attachment": {}
293634          },
293635          "pedigree": {},
293636          "evidence": {},
293637          "signature": {
293638            "signature": {
293639              "publicKey": {}
293640            }
293641          },
293642          "modelCard": {
293643            "modelParameters": {
293644              "approach": {}
293645            },
293646            "quantitativeAnalysis": {
293647              "graphics": {}
293648            },
293649            "considerations": {}
293650          }
293651        },
293652        {
293653          "type": "library",
293654          "bom-ref": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04\u0026package-id=57ceb68462a99cb4",
293655          "supplier": {},
293656          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293657          "name": "libcap-ng0",
293658          "version": "0.7.9-2.1build1",
293659          "licenses": [
293660            {
293661              "license": {
293662                "id": "GPL-2.0-only"
293663              }
293664            },
293665            {
293666              "license": {
293667                "id": "GPL-3.0-only"
293668              }
293669            },
293670            {
293671              "license": {
293672                "id": "LGPL-2.1-only"
293673              }
293674            }
293675          ],
293676          "cpe": "cpe:2.3:a:libcap-ng0:libcap-ng0:0.7.9-2.1build1:*:*:*:*:*:*:*",
293677          "purl": "pkg:deb/ubuntu/libcap-ng0@0.7.9-2.1build1?arch=amd64\u0026upstream=libcap-ng\u0026distro=ubuntu-20.04",
293678          "swid": {
293679            "attachment": {}
293680          },
293681          "pedigree": {},
293682          "evidence": {},
293683          "signature": {
293684            "signature": {
293685              "publicKey": {}
293686            }
293687          },
293688          "modelCard": {
293689            "modelParameters": {
293690              "approach": {}
293691            },
293692            "quantitativeAnalysis": {
293693              "graphics": {}
293694            },
293695            "considerations": {}
293696          }
293697        },
293698        {
293699          "type": "library",
293700          "bom-ref": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=682f3e304c127762",
293701          "supplier": {},
293702          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293703          "name": "libcap2",
293704          "version": "1:2.32-1",
293705          "licenses": [
293706            {
293707              "license": {
293708                "id": "BSD-3-Clause"
293709              }
293710            },
293711            {
293712              "license": {
293713                "id": "GPL-2.0-only"
293714              }
293715            },
293716            {
293717              "license": {
293718                "id": "GPL-2.0-or-later"
293719              }
293720            }
293721          ],
293722          "cpe": "cpe:2.3:a:libcap2:libcap2:1\\:2.32-1:*:*:*:*:*:*:*",
293723          "purl": "pkg:deb/ubuntu/libcap2@1:2.32-1?arch=amd64\u0026distro=ubuntu-20.04",
293724          "swid": {
293725            "attachment": {}
293726          },
293727          "pedigree": {},
293728          "evidence": {},
293729          "signature": {
293730            "signature": {
293731              "publicKey": {}
293732            }
293733          },
293734          "modelCard": {
293735            "modelParameters": {
293736              "approach": {}
293737            },
293738            "quantitativeAnalysis": {
293739              "graphics": {}
293740            },
293741            "considerations": {}
293742          }
293743        },
293744        {
293745          "type": "library",
293746          "bom-ref": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=fbaeb4c3d5d0f976",
293747          "supplier": {},
293748          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293749          "name": "libcom-err2",
293750          "version": "1.45.5-2ubuntu1",
293751          "cpe": "cpe:2.3:a:libcom-err2:libcom-err2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
293752          "purl": "pkg:deb/ubuntu/libcom-err2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
293753          "swid": {
293754            "attachment": {}
293755          },
293756          "pedigree": {},
293757          "evidence": {},
293758          "signature": {
293759            "signature": {
293760              "publicKey": {}
293761            }
293762          },
293763          "modelCard": {
293764            "modelParameters": {
293765              "approach": {}
293766            },
293767            "quantitativeAnalysis": {
293768              "graphics": {}
293769            },
293770            "considerations": {}
293771          }
293772        },
293773        {
293774          "type": "library",
293775          "bom-ref": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04\u0026package-id=8a4302e2e7027353",
293776          "supplier": {},
293777          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293778          "name": "libcrypt1",
293779          "version": "1:4.4.10-10ubuntu4",
293780          "cpe": "cpe:2.3:a:libcrypt1:libcrypt1:1\\:4.4.10-10ubuntu4:*:*:*:*:*:*:*",
293781          "purl": "pkg:deb/ubuntu/libcrypt1@1:4.4.10-10ubuntu4?arch=amd64\u0026upstream=libxcrypt\u0026distro=ubuntu-20.04",
293782          "swid": {
293783            "attachment": {}
293784          },
293785          "pedigree": {},
293786          "evidence": {},
293787          "signature": {
293788            "signature": {
293789              "publicKey": {}
293790            }
293791          },
293792          "modelCard": {
293793            "modelParameters": {
293794              "approach": {}
293795            },
293796            "quantitativeAnalysis": {
293797              "graphics": {}
293798            },
293799            "considerations": {}
293800          }
293801        },
293802        {
293803          "type": "library",
293804          "bom-ref": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04\u0026package-id=bc84b4da0031640d",
293805          "supplier": {},
293806          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293807          "name": "libdb5.3",
293808          "version": "5.3.28+dfsg1-0.6ubuntu2",
293809          "cpe": "cpe:2.3:a:libdb5.3:libdb5.3:5.3.28\\+dfsg1-0.6ubuntu2:*:*:*:*:*:*:*",
293810          "purl": "pkg:deb/ubuntu/libdb5.3@5.3.28+dfsg1-0.6ubuntu2?arch=amd64\u0026upstream=db5.3\u0026distro=ubuntu-20.04",
293811          "swid": {
293812            "attachment": {}
293813          },
293814          "pedigree": {},
293815          "evidence": {},
293816          "signature": {
293817            "signature": {
293818              "publicKey": {}
293819            }
293820          },
293821          "modelCard": {
293822            "modelParameters": {
293823              "approach": {}
293824            },
293825            "quantitativeAnalysis": {
293826              "graphics": {}
293827            },
293828            "considerations": {}
293829          }
293830        },
293831        {
293832          "type": "library",
293833          "bom-ref": "pkg:deb/ubuntu/libdbus-1-3@1.12.16-2ubuntu2.1?arch=amd64\u0026upstream=dbus\u0026distro=ubuntu-20.04\u0026package-id=4d71ded07a82a0c8",
293834          "supplier": {},
293835          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293836          "name": "libdbus-1-3",
293837          "version": "1.12.16-2ubuntu2.1",
293838          "licenses": [
293839            {
293840              "license": {
293841                "id": "AFL-2.1"
293842              }
293843            },
293844            {
293845              "license": {
293846                "id": "BSD-3-Clause"
293847              }
293848            },
293849            {
293850              "license": {
293851                "name": "BSD-3-clause-generic"
293852              }
293853            },
293854            {
293855              "license": {
293856                "name": "Expat"
293857              }
293858            },
293859            {
293860              "license": {
293861                "id": "GPL-2.0-only"
293862              }
293863            },
293864            {
293865              "license": {
293866                "id": "GPL-2.0-or-later"
293867              }
293868            },
293869            {
293870              "license": {
293871                "name": "Tcl-BSDish"
293872              }
293873            },
293874            {
293875              "license": {
293876                "name": "g10-permissive"
293877              }
293878            }
293879          ],
293880          "cpe": "cpe:2.3:a:libdbus-1-3:libdbus-1-3:1.12.16-2ubuntu2.1:*:*:*:*:*:*:*",
293881          "purl": "pkg:deb/ubuntu/libdbus-1-3@1.12.16-2ubuntu2.1?arch=amd64\u0026upstream=dbus\u0026distro=ubuntu-20.04",
293882          "swid": {
293883            "attachment": {}
293884          },
293885          "pedigree": {},
293886          "evidence": {},
293887          "signature": {
293888            "signature": {
293889              "publicKey": {}
293890            }
293891          },
293892          "modelCard": {
293893            "modelParameters": {
293894              "approach": {}
293895            },
293896            "quantitativeAnalysis": {
293897              "graphics": {}
293898            },
293899            "considerations": {}
293900          }
293901        },
293902        {
293903          "type": "library",
293904          "bom-ref": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04\u0026package-id=78bbe40d9c2ef9b5",
293905          "supplier": {},
293906          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293907          "name": "libdebconfclient0",
293908          "version": "0.251ubuntu1",
293909          "cpe": "cpe:2.3:a:libdebconfclient0:libdebconfclient0:0.251ubuntu1:*:*:*:*:*:*:*",
293910          "purl": "pkg:deb/ubuntu/libdebconfclient0@0.251ubuntu1?arch=amd64\u0026upstream=cdebconf\u0026distro=ubuntu-20.04",
293911          "swid": {
293912            "attachment": {}
293913          },
293914          "pedigree": {},
293915          "evidence": {},
293916          "signature": {
293917            "signature": {
293918              "publicKey": {}
293919            }
293920          },
293921          "modelCard": {
293922            "modelParameters": {
293923              "approach": {}
293924            },
293925            "quantitativeAnalysis": {
293926              "graphics": {}
293927            },
293928            "considerations": {}
293929          }
293930        },
293931        {
293932          "type": "library",
293933          "bom-ref": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04\u0026package-id=30b70188951a65f0",
293934          "supplier": {},
293935          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
293936          "name": "libdevmapper1.02.1",
293937          "version": "2:1.02.167-1ubuntu1",
293938          "licenses": [
293939            {
293940              "license": {
293941                "id": "BSD-2-Clause"
293942              }
293943            },
293944            {
293945              "license": {
293946                "id": "GPL-2.0-only"
293947              }
293948            },
293949            {
293950              "license": {
293951                "id": "GPL-2.0-only"
293952              }
293953            },
293954            {
293955              "license": {
293956                "id": "GPL-2.0-or-later"
293957              }
293958            },
293959            {
293960              "license": {
293961                "id": "LGPL-2.0-only"
293962              }
293963            },
293964            {
293965              "license": {
293966                "id": "LGPL-2.1-only"
293967              }
293968            }
293969          ],
293970          "cpe": "cpe:2.3:a:libdevmapper1.02.1:libdevmapper1.02.1:2\\:1.02.167-1ubuntu1:*:*:*:*:*:*:*",
293971          "purl": "pkg:deb/ubuntu/libdevmapper1.02.1@2:1.02.167-1ubuntu1?arch=amd64\u0026upstream=lvm2%402.03.07-1ubuntu1\u0026distro=ubuntu-20.04",
293972          "swid": {
293973            "attachment": {}
293974          },
293975          "pedigree": {},
293976          "evidence": {},
293977          "signature": {
293978            "signature": {
293979              "publicKey": {}
293980            }
293981          },
293982          "modelCard": {
293983            "modelParameters": {
293984              "approach": {}
293985            },
293986            "quantitativeAnalysis": {
293987              "graphics": {}
293988            },
293989            "considerations": {}
293990          }
293991        },
293992        {
293993          "type": "library",
293994          "bom-ref": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04\u0026package-id=6b93a7dccfeb49e0",
293995          "supplier": {},
293996          "publisher": "Balint Reczey \u003crbalint@ubuntu.com\u003e",
293997          "name": "libevent-2.1-7",
293998          "version": "2.1.11-stable-1",
293999          "licenses": [
294000            {
294001              "license": {
294002                "id": "BSD-2-Clause"
294003              }
294004            },
294005            {
294006              "license": {
294007                "name": "BSD-3-Clause~Kitware"
294008              }
294009            },
294010            {
294011              "license": {
294012                "id": "BSD-3-Clause"
294013              }
294014            },
294015            {
294016              "license": {
294017                "name": "BSL"
294018              }
294019            },
294020            {
294021              "license": {
294022                "name": "Expat"
294023              }
294024            },
294025            {
294026              "license": {
294027                "id": "FSFUL"
294028              }
294029            },
294030            {
294031              "license": {
294032                "id": "FSFULLR"
294033              }
294034            },
294035            {
294036              "license": {
294037                "name": "FSFULLR-No-Warranty"
294038              }
294039            },
294040            {
294041              "license": {
294042                "id": "GPL-2.0-only"
294043              }
294044            },
294045            {
294046              "license": {
294047                "id": "GPL-2.0-or-later"
294048              }
294049            },
294050            {
294051              "license": {
294052                "id": "GPL-3.0-only"
294053              }
294054            },
294055            {
294056              "license": {
294057                "id": "GPL-3.0-or-later"
294058              }
294059            },
294060            {
294061              "license": {
294062                "id": "ISC"
294063              }
294064            },
294065            {
294066              "license": {
294067                "id": "curl"
294068              }
294069            }
294070          ],
294071          "cpe": "cpe:2.3:a:libevent-2.1-7:libevent-2.1-7:2.1.11-stable-1:*:*:*:*:*:*:*",
294072          "purl": "pkg:deb/ubuntu/libevent-2.1-7@2.1.11-stable-1?arch=amd64\u0026upstream=libevent\u0026distro=ubuntu-20.04",
294073          "swid": {
294074            "attachment": {}
294075          },
294076          "pedigree": {},
294077          "evidence": {},
294078          "signature": {
294079            "signature": {
294080              "publicKey": {}
294081            }
294082          },
294083          "modelCard": {
294084            "modelParameters": {
294085              "approach": {}
294086            },
294087            "quantitativeAnalysis": {
294088              "graphics": {}
294089            },
294090            "considerations": {}
294091          }
294092        },
294093        {
294094          "type": "library",
294095          "bom-ref": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04\u0026package-id=f3ac75cd161f13c6",
294096          "supplier": {},
294097          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294098          "name": "libexpat1",
294099          "version": "2.2.9-1build1",
294100          "licenses": [
294101            {
294102              "license": {
294103                "id": "MIT"
294104              }
294105            }
294106          ],
294107          "cpe": "cpe:2.3:a:libexpat1:libexpat1:2.2.9-1build1:*:*:*:*:*:*:*",
294108          "purl": "pkg:deb/ubuntu/libexpat1@2.2.9-1build1?arch=amd64\u0026upstream=expat\u0026distro=ubuntu-20.04",
294109          "swid": {
294110            "attachment": {}
294111          },
294112          "pedigree": {},
294113          "evidence": {},
294114          "signature": {
294115            "signature": {
294116              "publicKey": {}
294117            }
294118          },
294119          "modelCard": {
294120            "modelParameters": {
294121              "approach": {}
294122            },
294123            "quantitativeAnalysis": {
294124              "graphics": {}
294125            },
294126            "considerations": {}
294127          }
294128        },
294129        {
294130          "type": "library",
294131          "bom-ref": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=ec6113f55e73d1fd",
294132          "supplier": {},
294133          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294134          "name": "libext2fs2",
294135          "version": "1.45.5-2ubuntu1",
294136          "licenses": [
294137            {
294138              "license": {
294139                "id": "GPL-2.0-only"
294140              }
294141            },
294142            {
294143              "license": {
294144                "id": "LGPL-2.0-only"
294145              }
294146            }
294147          ],
294148          "cpe": "cpe:2.3:a:libext2fs2:libext2fs2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
294149          "purl": "pkg:deb/ubuntu/libext2fs2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
294150          "swid": {
294151            "attachment": {}
294152          },
294153          "pedigree": {},
294154          "evidence": {},
294155          "signature": {
294156            "signature": {
294157              "publicKey": {}
294158            }
294159          },
294160          "modelCard": {
294161            "modelParameters": {
294162              "approach": {}
294163            },
294164            "quantitativeAnalysis": {
294165              "graphics": {}
294166            },
294167            "considerations": {}
294168          }
294169        },
294170        {
294171          "type": "library",
294172          "bom-ref": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=486ce61647644619",
294173          "supplier": {},
294174          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294175          "name": "libfdisk1",
294176          "version": "2.34-0.1ubuntu9.1",
294177          "licenses": [
294178            {
294179              "license": {
294180                "id": "BSD-2-Clause"
294181              }
294182            },
294183            {
294184              "license": {
294185                "id": "BSD-3-Clause"
294186              }
294187            },
294188            {
294189              "license": {
294190                "id": "BSD-4-Clause"
294191              }
294192            },
294193            {
294194              "license": {
294195                "id": "GPL-2.0-only"
294196              }
294197            },
294198            {
294199              "license": {
294200                "id": "GPL-2.0-or-later"
294201              }
294202            },
294203            {
294204              "license": {
294205                "id": "GPL-3.0-only"
294206              }
294207            },
294208            {
294209              "license": {
294210                "id": "GPL-3.0-or-later"
294211              }
294212            },
294213            {
294214              "license": {
294215                "name": "LGPL"
294216              }
294217            },
294218            {
294219              "license": {
294220                "id": "LGPL-2.0-only"
294221              }
294222            },
294223            {
294224              "license": {
294225                "id": "LGPL-2.0-or-later"
294226              }
294227            },
294228            {
294229              "license": {
294230                "id": "LGPL-2.1-only"
294231              }
294232            },
294233            {
294234              "license": {
294235                "id": "LGPL-2.1-or-later"
294236              }
294237            },
294238            {
294239              "license": {
294240                "id": "LGPL-3.0-only"
294241              }
294242            },
294243            {
294244              "license": {
294245                "id": "LGPL-3.0-or-later"
294246              }
294247            },
294248            {
294249              "license": {
294250                "id": "MIT"
294251              }
294252            },
294253            {
294254              "license": {
294255                "name": "public-domain"
294256              }
294257            }
294258          ],
294259          "cpe": "cpe:2.3:a:libfdisk1:libfdisk1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
294260          "purl": "pkg:deb/ubuntu/libfdisk1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
294261          "swid": {
294262            "attachment": {}
294263          },
294264          "pedigree": {},
294265          "evidence": {},
294266          "signature": {
294267            "signature": {
294268              "publicKey": {}
294269            }
294270          },
294271          "modelCard": {
294272            "modelParameters": {
294273              "approach": {}
294274            },
294275            "quantitativeAnalysis": {
294276              "graphics": {}
294277            },
294278            "considerations": {}
294279          }
294280        },
294281        {
294282          "type": "library",
294283          "bom-ref": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04\u0026package-id=b43b799d45da9d97",
294284          "supplier": {},
294285          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294286          "name": "libffi7",
294287          "version": "3.3-4",
294288          "licenses": [
294289            {
294290              "license": {
294291                "name": "GPL"
294292              }
294293            }
294294          ],
294295          "cpe": "cpe:2.3:a:libffi7:libffi7:3.3-4:*:*:*:*:*:*:*",
294296          "purl": "pkg:deb/ubuntu/libffi7@3.3-4?arch=amd64\u0026upstream=libffi\u0026distro=ubuntu-20.04",
294297          "swid": {
294298            "attachment": {}
294299          },
294300          "pedigree": {},
294301          "evidence": {},
294302          "signature": {
294303            "signature": {
294304              "publicKey": {}
294305            }
294306          },
294307          "modelCard": {
294308            "modelParameters": {
294309              "approach": {}
294310            },
294311            "quantitativeAnalysis": {
294312              "graphics": {}
294313            },
294314            "considerations": {}
294315          }
294316        },
294317        {
294318          "type": "library",
294319          "bom-ref": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=f98ce69fd9e55bb8",
294320          "supplier": {},
294321          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294322          "name": "libgcc-s1",
294323          "version": "10.3.0-1ubuntu1~20.04",
294324          "licenses": [
294325            {
294326              "license": {
294327                "name": "Artistic"
294328              }
294329            },
294330            {
294331              "license": {
294332                "id": "GFDL-1.2-only"
294333              }
294334            },
294335            {
294336              "license": {
294337                "name": "GPL"
294338              }
294339            },
294340            {
294341              "license": {
294342                "id": "GPL-2.0-only"
294343              }
294344            },
294345            {
294346              "license": {
294347                "id": "GPL-3.0-only"
294348              }
294349            },
294350            {
294351              "license": {
294352                "name": "LGPL"
294353              }
294354            }
294355          ],
294356          "cpe": "cpe:2.3:a:libgcc-s1:libgcc-s1:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
294357          "purl": "pkg:deb/ubuntu/libgcc-s1@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
294358          "swid": {
294359            "attachment": {}
294360          },
294361          "pedigree": {},
294362          "evidence": {},
294363          "signature": {
294364            "signature": {
294365              "publicKey": {}
294366            }
294367          },
294368          "modelCard": {
294369            "modelParameters": {
294370              "approach": {}
294371            },
294372            "quantitativeAnalysis": {
294373              "graphics": {}
294374            },
294375            "considerations": {}
294376          }
294377        },
294378        {
294379          "type": "library",
294380          "bom-ref": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=c8a43aa5b28727a1",
294381          "supplier": {},
294382          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294383          "name": "libgcrypt20",
294384          "version": "1.8.5-5ubuntu1",
294385          "licenses": [
294386            {
294387              "license": {
294388                "id": "GPL-2.0-only"
294389              }
294390            },
294391            {
294392              "license": {
294393                "name": "LGPL"
294394              }
294395            }
294396          ],
294397          "cpe": "cpe:2.3:a:libgcrypt20:libgcrypt20:1.8.5-5ubuntu1:*:*:*:*:*:*:*",
294398          "purl": "pkg:deb/ubuntu/libgcrypt20@1.8.5-5ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
294399          "swid": {
294400            "attachment": {}
294401          },
294402          "pedigree": {},
294403          "evidence": {},
294404          "signature": {
294405            "signature": {
294406              "publicKey": {}
294407            }
294408          },
294409          "modelCard": {
294410            "modelParameters": {
294411              "approach": {}
294412            },
294413            "quantitativeAnalysis": {
294414              "graphics": {}
294415            },
294416            "considerations": {}
294417          }
294418        },
294419        {
294420          "type": "library",
294421          "bom-ref": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04\u0026package-id=40fc269dcb8b3369",
294422          "supplier": {},
294423          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294424          "name": "libgmp10",
294425          "version": "2:6.2.0+dfsg-4",
294426          "licenses": [
294427            {
294428              "license": {
294429                "name": "GPL"
294430              }
294431            },
294432            {
294433              "license": {
294434                "id": "GPL-2.0-only"
294435              }
294436            },
294437            {
294438              "license": {
294439                "id": "GPL-3.0-only"
294440              }
294441            },
294442            {
294443              "license": {
294444                "id": "LGPL-3.0-only"
294445              }
294446            }
294447          ],
294448          "cpe": "cpe:2.3:a:libgmp10:libgmp10:2\\:6.2.0\\+dfsg-4:*:*:*:*:*:*:*",
294449          "purl": "pkg:deb/ubuntu/libgmp10@2:6.2.0+dfsg-4?arch=amd64\u0026upstream=gmp\u0026distro=ubuntu-20.04",
294450          "swid": {
294451            "attachment": {}
294452          },
294453          "pedigree": {},
294454          "evidence": {},
294455          "signature": {
294456            "signature": {
294457              "publicKey": {}
294458            }
294459          },
294460          "modelCard": {
294461            "modelParameters": {
294462              "approach": {}
294463            },
294464            "quantitativeAnalysis": {
294465              "graphics": {}
294466            },
294467            "considerations": {}
294468          }
294469        },
294470        {
294471          "type": "library",
294472          "bom-ref": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.3?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04\u0026package-id=209bb478086322a1",
294473          "supplier": {},
294474          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294475          "name": "libgnutls30",
294476          "version": "3.6.13-2ubuntu1.3",
294477          "licenses": [
294478            {
294479              "license": {
294480                "id": "Apache-2.0"
294481              }
294482            },
294483            {
294484              "license": {
294485                "id": "BSD-3-Clause"
294486              }
294487            },
294488            {
294489              "license": {
294490                "name": "CC0"
294491              }
294492            },
294493            {
294494              "license": {
294495                "name": "Expat"
294496              }
294497            },
294498            {
294499              "license": {
294500                "id": "GFDL-1.3-only"
294501              }
294502            },
294503            {
294504              "license": {
294505                "name": "GPL"
294506              }
294507            },
294508            {
294509              "license": {
294510                "id": "GPL-3.0-only"
294511              }
294512            },
294513            {
294514              "license": {
294515                "name": "GPLv3+"
294516              }
294517            },
294518            {
294519              "license": {
294520                "name": "LGPL"
294521              }
294522            },
294523            {
294524              "license": {
294525                "id": "LGPL-3.0-only"
294526              }
294527            },
294528            {
294529              "license": {
294530                "name": "LGPLv2.1+"
294531              }
294532            },
294533            {
294534              "license": {
294535                "name": "LGPLv3+_or_GPLv2+"
294536              }
294537            },
294538            {
294539              "license": {
294540                "name": "The"
294541              }
294542            }
294543          ],
294544          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.13-2ubuntu1.3:*:*:*:*:*:*:*",
294545          "purl": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.3?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04",
294546          "swid": {
294547            "attachment": {}
294548          },
294549          "pedigree": {},
294550          "evidence": {},
294551          "signature": {
294552            "signature": {
294553              "publicKey": {}
294554            }
294555          },
294556          "modelCard": {
294557            "modelParameters": {
294558              "approach": {}
294559            },
294560            "quantitativeAnalysis": {
294561              "graphics": {}
294562            },
294563            "considerations": {}
294564          }
294565        },
294566        {
294567          "type": "library",
294568          "bom-ref": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04\u0026package-id=7490f76da775c6e",
294569          "supplier": {},
294570          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294571          "name": "libgnutls30",
294572          "version": "3.6.13-2ubuntu1.6",
294573          "licenses": [
294574            {
294575              "license": {
294576                "id": "Apache-2.0"
294577              }
294578            },
294579            {
294580              "license": {
294581                "id": "BSD-3-Clause"
294582              }
294583            },
294584            {
294585              "license": {
294586                "name": "CC0"
294587              }
294588            },
294589            {
294590              "license": {
294591                "name": "Expat"
294592              }
294593            },
294594            {
294595              "license": {
294596                "id": "GFDL-1.3-only"
294597              }
294598            },
294599            {
294600              "license": {
294601                "name": "GPL"
294602              }
294603            },
294604            {
294605              "license": {
294606                "id": "GPL-3.0-only"
294607              }
294608            },
294609            {
294610              "license": {
294611                "name": "GPLv3+"
294612              }
294613            },
294614            {
294615              "license": {
294616                "name": "LGPL"
294617              }
294618            },
294619            {
294620              "license": {
294621                "id": "LGPL-3.0-only"
294622              }
294623            },
294624            {
294625              "license": {
294626                "name": "LGPLv2.1+"
294627              }
294628            },
294629            {
294630              "license": {
294631                "name": "LGPLv3+_or_GPLv2+"
294632              }
294633            },
294634            {
294635              "license": {
294636                "name": "The"
294637              }
294638            }
294639          ],
294640          "cpe": "cpe:2.3:a:libgnutls30:libgnutls30:3.6.13-2ubuntu1.6:*:*:*:*:*:*:*",
294641          "purl": "pkg:deb/ubuntu/libgnutls30@3.6.13-2ubuntu1.6?arch=amd64\u0026upstream=gnutls28\u0026distro=ubuntu-20.04",
294642          "swid": {
294643            "attachment": {}
294644          },
294645          "pedigree": {},
294646          "evidence": {},
294647          "signature": {
294648            "signature": {
294649              "publicKey": {}
294650            }
294651          },
294652          "modelCard": {
294653            "modelParameters": {
294654              "approach": {}
294655            },
294656            "quantitativeAnalysis": {
294657              "graphics": {}
294658            },
294659            "considerations": {}
294660          }
294661        },
294662        {
294663          "type": "library",
294664          "bom-ref": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04\u0026package-id=37ef62d87edfe03",
294665          "supplier": {},
294666          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294667          "name": "libgpg-error0",
294668          "version": "1.37-1",
294669          "licenses": [
294670            {
294671              "license": {
294672                "id": "BSD-3-Clause"
294673              }
294674            },
294675            {
294676              "license": {
294677                "id": "GPL-3.0-only"
294678              }
294679            },
294680            {
294681              "license": {
294682                "id": "GPL-3.0-or-later"
294683              }
294684            },
294685            {
294686              "license": {
294687                "id": "LGPL-2.1-only"
294688              }
294689            },
294690            {
294691              "license": {
294692                "id": "LGPL-2.1-or-later"
294693              }
294694            },
294695            {
294696              "license": {
294697                "name": "g10-permissive"
294698              }
294699            }
294700          ],
294701          "cpe": "cpe:2.3:a:libgpg-error0:libgpg-error0:1.37-1:*:*:*:*:*:*:*",
294702          "purl": "pkg:deb/ubuntu/libgpg-error0@1.37-1?arch=amd64\u0026upstream=libgpg-error\u0026distro=ubuntu-20.04",
294703          "swid": {
294704            "attachment": {}
294705          },
294706          "pedigree": {},
294707          "evidence": {},
294708          "signature": {
294709            "signature": {
294710              "publicKey": {}
294711            }
294712          },
294713          "modelCard": {
294714            "modelParameters": {
294715              "approach": {}
294716            },
294717            "quantitativeAnalysis": {
294718              "graphics": {}
294719            },
294720            "considerations": {}
294721          }
294722        },
294723        {
294724          "type": "library",
294725          "bom-ref": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=443eafe2785f5a4c",
294726          "supplier": {},
294727          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294728          "name": "libgssapi-krb5-2",
294729          "version": "1.17-6ubuntu4.1",
294730          "licenses": [
294731            {
294732              "license": {
294733                "id": "GPL-2.0-only"
294734              }
294735            }
294736          ],
294737          "cpe": "cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
294738          "purl": "pkg:deb/ubuntu/libgssapi-krb5-2@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
294739          "swid": {
294740            "attachment": {}
294741          },
294742          "pedigree": {},
294743          "evidence": {},
294744          "signature": {
294745            "signature": {
294746              "publicKey": {}
294747            }
294748          },
294749          "modelCard": {
294750            "modelParameters": {
294751              "approach": {}
294752            },
294753            "quantitativeAnalysis": {
294754              "graphics": {}
294755            },
294756            "considerations": {}
294757          }
294758        },
294759        {
294760          "type": "library",
294761          "bom-ref": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=17a37cca2446b615",
294762          "supplier": {},
294763          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294764          "name": "libgssapi3-heimdal",
294765          "version": "7.7.0+dfsg-1ubuntu1",
294766          "licenses": [
294767            {
294768              "license": {
294769                "id": "BSD-3-Clause"
294770              }
294771            },
294772            {
294773              "license": {
294774                "id": "GPL-2.0-only"
294775              }
294776            },
294777            {
294778              "license": {
294779                "id": "GPL-2.0-or-later"
294780              }
294781            },
294782            {
294783              "license": {
294784                "name": "custom"
294785              }
294786            }
294787          ],
294788          "cpe": "cpe:2.3:a:libgssapi3-heimdal:libgssapi3-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
294789          "purl": "pkg:deb/ubuntu/libgssapi3-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
294790          "swid": {
294791            "attachment": {}
294792          },
294793          "pedigree": {},
294794          "evidence": {},
294795          "signature": {
294796            "signature": {
294797              "publicKey": {}
294798            }
294799          },
294800          "modelCard": {
294801            "modelParameters": {
294802              "approach": {}
294803            },
294804            "quantitativeAnalysis": {
294805              "graphics": {}
294806            },
294807            "considerations": {}
294808          }
294809        },
294810        {
294811          "type": "library",
294812          "bom-ref": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=98098d582df76b44",
294813          "supplier": {},
294814          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294815          "name": "libhcrypto4-heimdal",
294816          "version": "7.7.0+dfsg-1ubuntu1",
294817          "licenses": [
294818            {
294819              "license": {
294820                "id": "BSD-3-Clause"
294821              }
294822            },
294823            {
294824              "license": {
294825                "id": "GPL-2.0-only"
294826              }
294827            },
294828            {
294829              "license": {
294830                "id": "GPL-2.0-or-later"
294831              }
294832            },
294833            {
294834              "license": {
294835                "name": "custom"
294836              }
294837            }
294838          ],
294839          "cpe": "cpe:2.3:a:libhcrypto4-heimdal:libhcrypto4-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
294840          "purl": "pkg:deb/ubuntu/libhcrypto4-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
294841          "swid": {
294842            "attachment": {}
294843          },
294844          "pedigree": {},
294845          "evidence": {},
294846          "signature": {
294847            "signature": {
294848              "publicKey": {}
294849            }
294850          },
294851          "modelCard": {
294852            "modelParameters": {
294853              "approach": {}
294854            },
294855            "quantitativeAnalysis": {
294856              "graphics": {}
294857            },
294858            "considerations": {}
294859          }
294860        },
294861        {
294862          "type": "library",
294863          "bom-ref": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=f8dfc9a84c337835",
294864          "supplier": {},
294865          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294866          "name": "libheimbase1-heimdal",
294867          "version": "7.7.0+dfsg-1ubuntu1",
294868          "licenses": [
294869            {
294870              "license": {
294871                "id": "BSD-3-Clause"
294872              }
294873            },
294874            {
294875              "license": {
294876                "id": "GPL-2.0-only"
294877              }
294878            },
294879            {
294880              "license": {
294881                "id": "GPL-2.0-or-later"
294882              }
294883            },
294884            {
294885              "license": {
294886                "name": "custom"
294887              }
294888            }
294889          ],
294890          "cpe": "cpe:2.3:a:libheimbase1-heimdal:libheimbase1-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
294891          "purl": "pkg:deb/ubuntu/libheimbase1-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
294892          "swid": {
294893            "attachment": {}
294894          },
294895          "pedigree": {},
294896          "evidence": {},
294897          "signature": {
294898            "signature": {
294899              "publicKey": {}
294900            }
294901          },
294902          "modelCard": {
294903            "modelParameters": {
294904              "approach": {}
294905            },
294906            "quantitativeAnalysis": {
294907              "graphics": {}
294908            },
294909            "considerations": {}
294910          }
294911        },
294912        {
294913          "type": "library",
294914          "bom-ref": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=9992d88ac7d6e8e3",
294915          "supplier": {},
294916          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294917          "name": "libheimntlm0-heimdal",
294918          "version": "7.7.0+dfsg-1ubuntu1",
294919          "licenses": [
294920            {
294921              "license": {
294922                "id": "BSD-3-Clause"
294923              }
294924            },
294925            {
294926              "license": {
294927                "id": "GPL-2.0-only"
294928              }
294929            },
294930            {
294931              "license": {
294932                "id": "GPL-2.0-or-later"
294933              }
294934            },
294935            {
294936              "license": {
294937                "name": "custom"
294938              }
294939            }
294940          ],
294941          "cpe": "cpe:2.3:a:libheimntlm0-heimdal:libheimntlm0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
294942          "purl": "pkg:deb/ubuntu/libheimntlm0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
294943          "swid": {
294944            "attachment": {}
294945          },
294946          "pedigree": {},
294947          "evidence": {},
294948          "signature": {
294949            "signature": {
294950              "publicKey": {}
294951            }
294952          },
294953          "modelCard": {
294954            "modelParameters": {
294955              "approach": {}
294956            },
294957            "quantitativeAnalysis": {
294958              "graphics": {}
294959            },
294960            "considerations": {}
294961          }
294962        },
294963        {
294964          "type": "library",
294965          "bom-ref": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3caecccf070e6760",
294966          "supplier": {},
294967          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
294968          "name": "libhogweed5",
294969          "version": "3.5.1+really3.5.1-2ubuntu0.2",
294970          "licenses": [
294971            {
294972              "license": {
294973                "name": "GAP"
294974              }
294975            },
294976            {
294977              "license": {
294978                "name": "GPL"
294979              }
294980            },
294981            {
294982              "license": {
294983                "id": "GPL-2.0-only"
294984              }
294985            },
294986            {
294987              "license": {
294988                "id": "GPL-2.0-or-later"
294989              }
294990            },
294991            {
294992              "license": {
294993                "name": "LGPL"
294994              }
294995            },
294996            {
294997              "license": {
294998                "id": "LGPL-2.0-only"
294999              }
295000            },
295001            {
295002              "license": {
295003                "id": "LGPL-2.0-or-later"
295004              }
295005            },
295006            {
295007              "license": {
295008                "id": "LGPL-2.1-or-later"
295009              }
295010            },
295011            {
295012              "license": {
295013                "name": "other"
295014              }
295015            },
295016            {
295017              "license": {
295018                "name": "public-domain"
295019              }
295020            }
295021          ],
295022          "cpe": "cpe:2.3:a:libhogweed5:libhogweed5:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
295023          "purl": "pkg:deb/ubuntu/libhogweed5@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
295024          "swid": {
295025            "attachment": {}
295026          },
295027          "pedigree": {},
295028          "evidence": {},
295029          "signature": {
295030            "signature": {
295031              "publicKey": {}
295032            }
295033          },
295034          "modelCard": {
295035            "modelParameters": {
295036              "approach": {}
295037            },
295038            "quantitativeAnalysis": {
295039              "graphics": {}
295040            },
295041            "considerations": {}
295042          }
295043        },
295044        {
295045          "type": "library",
295046          "bom-ref": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=3b0bac5e4e8f23c5",
295047          "supplier": {},
295048          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295049          "name": "libhx509-5-heimdal",
295050          "version": "7.7.0+dfsg-1ubuntu1",
295051          "licenses": [
295052            {
295053              "license": {
295054                "id": "BSD-3-Clause"
295055              }
295056            },
295057            {
295058              "license": {
295059                "id": "GPL-2.0-only"
295060              }
295061            },
295062            {
295063              "license": {
295064                "id": "GPL-2.0-or-later"
295065              }
295066            },
295067            {
295068              "license": {
295069                "name": "custom"
295070              }
295071            }
295072          ],
295073          "cpe": "cpe:2.3:a:libhx509-5-heimdal:libhx509-5-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
295074          "purl": "pkg:deb/ubuntu/libhx509-5-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
295075          "swid": {
295076            "attachment": {}
295077          },
295078          "pedigree": {},
295079          "evidence": {},
295080          "signature": {
295081            "signature": {
295082              "publicKey": {}
295083            }
295084          },
295085          "modelCard": {
295086            "modelParameters": {
295087              "approach": {}
295088            },
295089            "quantitativeAnalysis": {
295090              "graphics": {}
295091            },
295092            "considerations": {}
295093          }
295094        },
295095        {
295096          "type": "library",
295097          "bom-ref": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04\u0026package-id=bcf598a9dea4cd38",
295098          "supplier": {},
295099          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295100          "name": "libicu66",
295101          "version": "66.1-2ubuntu2",
295102          "cpe": "cpe:2.3:a:libicu66:libicu66:66.1-2ubuntu2:*:*:*:*:*:*:*",
295103          "purl": "pkg:deb/ubuntu/libicu66@66.1-2ubuntu2?arch=amd64\u0026upstream=icu\u0026distro=ubuntu-20.04",
295104          "swid": {
295105            "attachment": {}
295106          },
295107          "pedigree": {},
295108          "evidence": {},
295109          "signature": {
295110            "signature": {
295111              "publicKey": {}
295112            }
295113          },
295114          "modelCard": {
295115            "modelParameters": {
295116              "approach": {}
295117            },
295118            "quantitativeAnalysis": {
295119              "graphics": {}
295120            },
295121            "considerations": {}
295122          }
295123        },
295124        {
295125          "type": "library",
295126          "bom-ref": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04\u0026package-id=d2a82c3e28413bc1",
295127          "supplier": {},
295128          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295129          "name": "libidn2-0",
295130          "version": "2.2.0-2",
295131          "licenses": [
295132            {
295133              "license": {
295134                "id": "GPL-2.0-only"
295135              }
295136            },
295137            {
295138              "license": {
295139                "id": "GPL-2.0-or-later"
295140              }
295141            },
295142            {
295143              "license": {
295144                "id": "GPL-3.0-only"
295145              }
295146            },
295147            {
295148              "license": {
295149                "id": "GPL-3.0-or-later"
295150              }
295151            },
295152            {
295153              "license": {
295154                "id": "LGPL-3.0-only"
295155              }
295156            },
295157            {
295158              "license": {
295159                "id": "LGPL-3.0-or-later"
295160              }
295161            },
295162            {
295163              "license": {
295164                "name": "Unicode"
295165              }
295166            }
295167          ],
295168          "cpe": "cpe:2.3:a:libidn2-0:libidn2-0:2.2.0-2:*:*:*:*:*:*:*",
295169          "purl": "pkg:deb/ubuntu/libidn2-0@2.2.0-2?arch=amd64\u0026upstream=libidn2\u0026distro=ubuntu-20.04",
295170          "swid": {
295171            "attachment": {}
295172          },
295173          "pedigree": {},
295174          "evidence": {},
295175          "signature": {
295176            "signature": {
295177              "publicKey": {}
295178            }
295179          },
295180          "modelCard": {
295181            "modelParameters": {
295182              "approach": {}
295183            },
295184            "quantitativeAnalysis": {
295185              "graphics": {}
295186            },
295187            "considerations": {}
295188          }
295189        },
295190        {
295191          "type": "library",
295192          "bom-ref": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=f9479050b59432b4",
295193          "supplier": {},
295194          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295195          "name": "libk5crypto3",
295196          "version": "1.17-6ubuntu4.1",
295197          "licenses": [
295198            {
295199              "license": {
295200                "id": "GPL-2.0-only"
295201              }
295202            }
295203          ],
295204          "cpe": "cpe:2.3:a:libk5crypto3:libk5crypto3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
295205          "purl": "pkg:deb/ubuntu/libk5crypto3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
295206          "swid": {
295207            "attachment": {}
295208          },
295209          "pedigree": {},
295210          "evidence": {},
295211          "signature": {
295212            "signature": {
295213              "publicKey": {}
295214            }
295215          },
295216          "modelCard": {
295217            "modelParameters": {
295218              "approach": {}
295219            },
295220            "quantitativeAnalysis": {
295221              "graphics": {}
295222            },
295223            "considerations": {}
295224          }
295225        },
295226        {
295227          "type": "library",
295228          "bom-ref": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04\u0026package-id=e8692427b123ea73",
295229          "supplier": {},
295230          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295231          "name": "libkeyutils1",
295232          "version": "1.6-6ubuntu1",
295233          "licenses": [
295234            {
295235              "license": {
295236                "id": "GPL-2.0-only"
295237              }
295238            },
295239            {
295240              "license": {
295241                "id": "GPL-2.0-or-later"
295242              }
295243            },
295244            {
295245              "license": {
295246                "id": "LGPL-2.0-only"
295247              }
295248            },
295249            {
295250              "license": {
295251                "id": "LGPL-2.0-or-later"
295252              }
295253            }
295254          ],
295255          "cpe": "cpe:2.3:a:libkeyutils1:libkeyutils1:1.6-6ubuntu1:*:*:*:*:*:*:*",
295256          "purl": "pkg:deb/ubuntu/libkeyutils1@1.6-6ubuntu1?arch=amd64\u0026upstream=keyutils\u0026distro=ubuntu-20.04",
295257          "swid": {
295258            "attachment": {}
295259          },
295260          "pedigree": {},
295261          "evidence": {},
295262          "signature": {
295263            "signature": {
295264              "publicKey": {}
295265            }
295266          },
295267          "modelCard": {
295268            "modelParameters": {
295269              "approach": {}
295270            },
295271            "quantitativeAnalysis": {
295272              "graphics": {}
295273            },
295274            "considerations": {}
295275          }
295276        },
295277        {
295278          "type": "library",
295279          "bom-ref": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=2beb670b9378498e",
295280          "supplier": {},
295281          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295282          "name": "libkrb5-26-heimdal",
295283          "version": "7.7.0+dfsg-1ubuntu1",
295284          "licenses": [
295285            {
295286              "license": {
295287                "id": "BSD-3-Clause"
295288              }
295289            },
295290            {
295291              "license": {
295292                "id": "GPL-2.0-only"
295293              }
295294            },
295295            {
295296              "license": {
295297                "id": "GPL-2.0-or-later"
295298              }
295299            },
295300            {
295301              "license": {
295302                "name": "custom"
295303              }
295304            }
295305          ],
295306          "cpe": "cpe:2.3:a:libkrb5-26-heimdal:libkrb5-26-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
295307          "purl": "pkg:deb/ubuntu/libkrb5-26-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
295308          "swid": {
295309            "attachment": {}
295310          },
295311          "pedigree": {},
295312          "evidence": {},
295313          "signature": {
295314            "signature": {
295315              "publicKey": {}
295316            }
295317          },
295318          "modelCard": {
295319            "modelParameters": {
295320              "approach": {}
295321            },
295322            "quantitativeAnalysis": {
295323              "graphics": {}
295324            },
295325            "considerations": {}
295326          }
295327        },
295328        {
295329          "type": "library",
295330          "bom-ref": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=fdb5970d8394a182",
295331          "supplier": {},
295332          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295333          "name": "libkrb5-3",
295334          "version": "1.17-6ubuntu4.1",
295335          "licenses": [
295336            {
295337              "license": {
295338                "id": "GPL-2.0-only"
295339              }
295340            }
295341          ],
295342          "cpe": "cpe:2.3:a:libkrb5-3:libkrb5-3:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
295343          "purl": "pkg:deb/ubuntu/libkrb5-3@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
295344          "swid": {
295345            "attachment": {}
295346          },
295347          "pedigree": {},
295348          "evidence": {},
295349          "signature": {
295350            "signature": {
295351              "publicKey": {}
295352            }
295353          },
295354          "modelCard": {
295355            "modelParameters": {
295356              "approach": {}
295357            },
295358            "quantitativeAnalysis": {
295359              "graphics": {}
295360            },
295361            "considerations": {}
295362          }
295363        },
295364        {
295365          "type": "library",
295366          "bom-ref": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04\u0026package-id=a8d21a32e178b211",
295367          "supplier": {},
295368          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295369          "name": "libkrb5support0",
295370          "version": "1.17-6ubuntu4.1",
295371          "licenses": [
295372            {
295373              "license": {
295374                "id": "GPL-2.0-only"
295375              }
295376            }
295377          ],
295378          "cpe": "cpe:2.3:a:libkrb5support0:libkrb5support0:1.17-6ubuntu4.1:*:*:*:*:*:*:*",
295379          "purl": "pkg:deb/ubuntu/libkrb5support0@1.17-6ubuntu4.1?arch=amd64\u0026upstream=krb5\u0026distro=ubuntu-20.04",
295380          "swid": {
295381            "attachment": {}
295382          },
295383          "pedigree": {},
295384          "evidence": {},
295385          "signature": {
295386            "signature": {
295387              "publicKey": {}
295388            }
295389          },
295390          "modelCard": {
295391            "modelParameters": {
295392              "approach": {}
295393            },
295394            "quantitativeAnalysis": {
295395              "graphics": {}
295396            },
295397            "considerations": {}
295398          }
295399        },
295400        {
295401          "type": "library",
295402          "bom-ref": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=efdc80a7ae6eae19",
295403          "supplier": {},
295404          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295405          "name": "libldap-2.4-2",
295406          "version": "2.4.49+dfsg-2ubuntu1.8",
295407          "cpe": "cpe:2.3:a:libldap-2.4-2:libldap-2.4-2:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
295408          "purl": "pkg:deb/ubuntu/libldap-2.4-2@2.4.49+dfsg-2ubuntu1.8?arch=amd64\u0026upstream=openldap\u0026distro=ubuntu-20.04",
295409          "swid": {
295410            "attachment": {}
295411          },
295412          "pedigree": {},
295413          "evidence": {},
295414          "signature": {
295415            "signature": {
295416              "publicKey": {}
295417            }
295418          },
295419          "modelCard": {
295420            "modelParameters": {
295421              "approach": {}
295422            },
295423            "quantitativeAnalysis": {
295424              "graphics": {}
295425            },
295426            "considerations": {}
295427          }
295428        },
295429        {
295430          "type": "library",
295431          "bom-ref": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04\u0026package-id=4d0b88f98b40786b",
295432          "supplier": {},
295433          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295434          "name": "libldap-common",
295435          "version": "2.4.49+dfsg-2ubuntu1.8",
295436          "cpe": "cpe:2.3:a:libldap-common:libldap-common:2.4.49\\+dfsg-2ubuntu1.8:*:*:*:*:*:*:*",
295437          "purl": "pkg:deb/ubuntu/libldap-common@2.4.49+dfsg-2ubuntu1.8?arch=all\u0026upstream=openldap\u0026distro=ubuntu-20.04",
295438          "swid": {
295439            "attachment": {}
295440          },
295441          "pedigree": {},
295442          "evidence": {},
295443          "signature": {
295444            "signature": {
295445              "publicKey": {}
295446            }
295447          },
295448          "modelCard": {
295449            "modelParameters": {
295450              "approach": {}
295451            },
295452            "quantitativeAnalysis": {
295453              "graphics": {}
295454            },
295455            "considerations": {}
295456          }
295457        },
295458        {
295459          "type": "library",
295460          "bom-ref": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04\u0026package-id=6f2c431caeb4980a",
295461          "supplier": {},
295462          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295463          "name": "liblz4-1",
295464          "version": "1.9.2-2ubuntu0.20.04.1",
295465          "licenses": [
295466            {
295467              "license": {
295468                "id": "BSD-2-Clause"
295469              }
295470            },
295471            {
295472              "license": {
295473                "id": "GPL-2.0-only"
295474              }
295475            },
295476            {
295477              "license": {
295478                "id": "GPL-2.0-or-later"
295479              }
295480            }
295481          ],
295482          "cpe": "cpe:2.3:a:liblz4-1:liblz4-1:1.9.2-2ubuntu0.20.04.1:*:*:*:*:*:*:*",
295483          "purl": "pkg:deb/ubuntu/liblz4-1@1.9.2-2ubuntu0.20.04.1?arch=amd64\u0026upstream=lz4\u0026distro=ubuntu-20.04",
295484          "swid": {
295485            "attachment": {}
295486          },
295487          "pedigree": {},
295488          "evidence": {},
295489          "signature": {
295490            "signature": {
295491              "publicKey": {}
295492            }
295493          },
295494          "modelCard": {
295495            "modelParameters": {
295496              "approach": {}
295497            },
295498            "quantitativeAnalysis": {
295499              "graphics": {}
295500            },
295501            "considerations": {}
295502          }
295503        },
295504        {
295505          "type": "library",
295506          "bom-ref": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04\u0026package-id=f1e9f3b6205a664a",
295507          "supplier": {},
295508          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295509          "name": "liblzma5",
295510          "version": "5.2.4-1ubuntu1",
295511          "licenses": [
295512            {
295513              "license": {
295514                "name": "Autoconf"
295515              }
295516            },
295517            {
295518              "license": {
295519                "id": "GPL-2.0-only"
295520              }
295521            },
295522            {
295523              "license": {
295524                "id": "GPL-2.0-or-later"
295525              }
295526            },
295527            {
295528              "license": {
295529                "id": "GPL-3.0-only"
295530              }
295531            },
295532            {
295533              "license": {
295534                "id": "LGPL-2.0-only"
295535              }
295536            },
295537            {
295538              "license": {
295539                "id": "LGPL-2.1-only"
295540              }
295541            },
295542            {
295543              "license": {
295544                "id": "LGPL-2.1-or-later"
295545              }
295546            },
295547            {
295548              "license": {
295549                "name": "PD"
295550              }
295551            },
295552            {
295553              "license": {
295554                "name": "PD-debian"
295555              }
295556            },
295557            {
295558              "license": {
295559                "name": "config-h"
295560              }
295561            },
295562            {
295563              "license": {
295564                "name": "noderivs"
295565              }
295566            },
295567            {
295568              "license": {
295569                "name": "permissive-fsf"
295570              }
295571            },
295572            {
295573              "license": {
295574                "name": "permissive-nowarranty"
295575              }
295576            },
295577            {
295578              "license": {
295579                "name": "probably-PD"
295580              }
295581            }
295582          ],
295583          "cpe": "cpe:2.3:a:liblzma5:liblzma5:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
295584          "purl": "pkg:deb/ubuntu/liblzma5@5.2.4-1ubuntu1?arch=amd64\u0026upstream=xz-utils\u0026distro=ubuntu-20.04",
295585          "swid": {
295586            "attachment": {}
295587          },
295588          "pedigree": {},
295589          "evidence": {},
295590          "signature": {
295591            "signature": {
295592              "publicKey": {}
295593            }
295594          },
295595          "modelCard": {
295596            "modelParameters": {
295597              "approach": {}
295598            },
295599            "quantitativeAnalysis": {
295600              "graphics": {}
295601            },
295602            "considerations": {}
295603          }
295604        },
295605        {
295606          "type": "library",
295607          "bom-ref": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=3b4f02792ccf99bb",
295608          "supplier": {},
295609          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295610          "name": "libmagic-mgc",
295611          "version": "1:5.38-4",
295612          "licenses": [
295613            {
295614              "license": {
295615                "name": "BSD-2-Clause-alike"
295616              }
295617            },
295618            {
295619              "license": {
295620                "id": "BSD-2-Clause"
295621              }
295622            },
295623            {
295624              "license": {
295625                "name": "BSD-2-Clause-regents"
295626              }
295627            },
295628            {
295629              "license": {
295630                "name": "MIT-Old-Style-with-legal-disclaimer-2"
295631              }
295632            },
295633            {
295634              "license": {
295635                "name": "public-domain"
295636              }
295637            }
295638          ],
295639          "cpe": "cpe:2.3:a:libmagic-mgc:libmagic-mgc:1\\:5.38-4:*:*:*:*:*:*:*",
295640          "purl": "pkg:deb/ubuntu/libmagic-mgc@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
295641          "swid": {
295642            "attachment": {}
295643          },
295644          "pedigree": {},
295645          "evidence": {},
295646          "signature": {
295647            "signature": {
295648              "publicKey": {}
295649            }
295650          },
295651          "modelCard": {
295652            "modelParameters": {
295653              "approach": {}
295654            },
295655            "quantitativeAnalysis": {
295656              "graphics": {}
295657            },
295658            "considerations": {}
295659          }
295660        },
295661        {
295662          "type": "library",
295663          "bom-ref": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04\u0026package-id=302b8497a938556",
295664          "supplier": {},
295665          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295666          "name": "libmagic1",
295667          "version": "1:5.38-4",
295668          "licenses": [
295669            {
295670              "license": {
295671                "name": "BSD-2-Clause-alike"
295672              }
295673            },
295674            {
295675              "license": {
295676                "id": "BSD-2-Clause"
295677              }
295678            },
295679            {
295680              "license": {
295681                "name": "BSD-2-Clause-regents"
295682              }
295683            },
295684            {
295685              "license": {
295686                "name": "MIT-Old-Style-with-legal-disclaimer-2"
295687              }
295688            },
295689            {
295690              "license": {
295691                "name": "public-domain"
295692              }
295693            }
295694          ],
295695          "cpe": "cpe:2.3:a:libmagic1:libmagic1:1\\:5.38-4:*:*:*:*:*:*:*",
295696          "purl": "pkg:deb/ubuntu/libmagic1@1:5.38-4?arch=amd64\u0026upstream=file\u0026distro=ubuntu-20.04",
295697          "swid": {
295698            "attachment": {}
295699          },
295700          "pedigree": {},
295701          "evidence": {},
295702          "signature": {
295703            "signature": {
295704              "publicKey": {}
295705            }
295706          },
295707          "modelCard": {
295708            "modelParameters": {
295709              "approach": {}
295710            },
295711            "quantitativeAnalysis": {
295712              "graphics": {}
295713            },
295714            "considerations": {}
295715          }
295716        },
295717        {
295718          "type": "library",
295719          "bom-ref": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=39446194385ebce5",
295720          "supplier": {},
295721          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295722          "name": "libmount1",
295723          "version": "2.34-0.1ubuntu9.1",
295724          "licenses": [
295725            {
295726              "license": {
295727                "id": "BSD-2-Clause"
295728              }
295729            },
295730            {
295731              "license": {
295732                "id": "BSD-3-Clause"
295733              }
295734            },
295735            {
295736              "license": {
295737                "id": "BSD-4-Clause"
295738              }
295739            },
295740            {
295741              "license": {
295742                "id": "GPL-2.0-only"
295743              }
295744            },
295745            {
295746              "license": {
295747                "id": "GPL-2.0-or-later"
295748              }
295749            },
295750            {
295751              "license": {
295752                "id": "GPL-3.0-only"
295753              }
295754            },
295755            {
295756              "license": {
295757                "id": "GPL-3.0-or-later"
295758              }
295759            },
295760            {
295761              "license": {
295762                "name": "LGPL"
295763              }
295764            },
295765            {
295766              "license": {
295767                "id": "LGPL-2.0-only"
295768              }
295769            },
295770            {
295771              "license": {
295772                "id": "LGPL-2.0-or-later"
295773              }
295774            },
295775            {
295776              "license": {
295777                "id": "LGPL-2.1-only"
295778              }
295779            },
295780            {
295781              "license": {
295782                "id": "LGPL-2.1-or-later"
295783              }
295784            },
295785            {
295786              "license": {
295787                "id": "LGPL-3.0-only"
295788              }
295789            },
295790            {
295791              "license": {
295792                "id": "LGPL-3.0-or-later"
295793              }
295794            },
295795            {
295796              "license": {
295797                "id": "MIT"
295798              }
295799            },
295800            {
295801              "license": {
295802                "name": "public-domain"
295803              }
295804            }
295805          ],
295806          "cpe": "cpe:2.3:a:libmount1:libmount1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
295807          "purl": "pkg:deb/ubuntu/libmount1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
295808          "swid": {
295809            "attachment": {}
295810          },
295811          "pedigree": {},
295812          "evidence": {},
295813          "signature": {
295814            "signature": {
295815              "publicKey": {}
295816            }
295817          },
295818          "modelCard": {
295819            "modelParameters": {
295820              "approach": {}
295821            },
295822            "quantitativeAnalysis": {
295823              "graphics": {}
295824            },
295825            "considerations": {}
295826          }
295827        },
295828        {
295829          "type": "library",
295830          "bom-ref": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04\u0026package-id=b45a0d57576ce262",
295831          "supplier": {},
295832          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295833          "name": "libmpdec2",
295834          "version": "2.4.2-3",
295835          "licenses": [
295836            {
295837              "license": {
295838                "name": "BSD"
295839              }
295840            },
295841            {
295842              "license": {
295843                "id": "GPL-2.0-only"
295844              }
295845            },
295846            {
295847              "license": {
295848                "id": "GPL-2.0-or-later"
295849              }
295850            }
295851          ],
295852          "cpe": "cpe:2.3:a:libmpdec2:libmpdec2:2.4.2-3:*:*:*:*:*:*:*",
295853          "purl": "pkg:deb/ubuntu/libmpdec2@2.4.2-3?arch=amd64\u0026upstream=mpdecimal\u0026distro=ubuntu-20.04",
295854          "swid": {
295855            "attachment": {}
295856          },
295857          "pedigree": {},
295858          "evidence": {},
295859          "signature": {
295860            "signature": {
295861              "publicKey": {}
295862            }
295863          },
295864          "modelCard": {
295865            "modelParameters": {
295866              "approach": {}
295867            },
295868            "quantitativeAnalysis": {
295869              "graphics": {}
295870            },
295871            "considerations": {}
295872          }
295873        },
295874        {
295875          "type": "library",
295876          "bom-ref": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=ed8fb166163a75b8",
295877          "supplier": {},
295878          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295879          "name": "libncurses6",
295880          "version": "6.2-0ubuntu2",
295881          "cpe": "cpe:2.3:a:libncurses6:libncurses6:6.2-0ubuntu2:*:*:*:*:*:*:*",
295882          "purl": "pkg:deb/ubuntu/libncurses6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
295883          "swid": {
295884            "attachment": {}
295885          },
295886          "pedigree": {},
295887          "evidence": {},
295888          "signature": {
295889            "signature": {
295890              "publicKey": {}
295891            }
295892          },
295893          "modelCard": {
295894            "modelParameters": {
295895              "approach": {}
295896            },
295897            "quantitativeAnalysis": {
295898              "graphics": {}
295899            },
295900            "considerations": {}
295901          }
295902        },
295903        {
295904          "type": "library",
295905          "bom-ref": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=58525ddc073a008a",
295906          "supplier": {},
295907          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295908          "name": "libncursesw6",
295909          "version": "6.2-0ubuntu2",
295910          "cpe": "cpe:2.3:a:libncursesw6:libncursesw6:6.2-0ubuntu2:*:*:*:*:*:*:*",
295911          "purl": "pkg:deb/ubuntu/libncursesw6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
295912          "swid": {
295913            "attachment": {}
295914          },
295915          "pedigree": {},
295916          "evidence": {},
295917          "signature": {
295918            "signature": {
295919              "publicKey": {}
295920            }
295921          },
295922          "modelCard": {
295923            "modelParameters": {
295924              "approach": {}
295925            },
295926            "quantitativeAnalysis": {
295927              "graphics": {}
295928            },
295929            "considerations": {}
295930          }
295931        },
295932        {
295933          "type": "library",
295934          "bom-ref": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04\u0026package-id=3d185fbd6a7e56f",
295935          "supplier": {},
295936          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
295937          "name": "libnettle7",
295938          "version": "3.5.1+really3.5.1-2ubuntu0.2",
295939          "licenses": [
295940            {
295941              "license": {
295942                "name": "GAP"
295943              }
295944            },
295945            {
295946              "license": {
295947                "name": "GPL"
295948              }
295949            },
295950            {
295951              "license": {
295952                "id": "GPL-2.0-only"
295953              }
295954            },
295955            {
295956              "license": {
295957                "id": "GPL-2.0-or-later"
295958              }
295959            },
295960            {
295961              "license": {
295962                "name": "LGPL"
295963              }
295964            },
295965            {
295966              "license": {
295967                "id": "LGPL-2.0-only"
295968              }
295969            },
295970            {
295971              "license": {
295972                "id": "LGPL-2.0-or-later"
295973              }
295974            },
295975            {
295976              "license": {
295977                "id": "LGPL-2.1-or-later"
295978              }
295979            },
295980            {
295981              "license": {
295982                "name": "other"
295983              }
295984            },
295985            {
295986              "license": {
295987                "name": "public-domain"
295988              }
295989            }
295990          ],
295991          "cpe": "cpe:2.3:a:libnettle7:libnettle7:3.5.1\\+really3.5.1-2ubuntu0.2:*:*:*:*:*:*:*",
295992          "purl": "pkg:deb/ubuntu/libnettle7@3.5.1+really3.5.1-2ubuntu0.2?arch=amd64\u0026upstream=nettle\u0026distro=ubuntu-20.04",
295993          "swid": {
295994            "attachment": {}
295995          },
295996          "pedigree": {},
295997          "evidence": {},
295998          "signature": {
295999            "signature": {
296000              "publicKey": {}
296001            }
296002          },
296003          "modelCard": {
296004            "modelParameters": {
296005              "approach": {}
296006            },
296007            "quantitativeAnalysis": {
296008              "graphics": {}
296009            },
296010            "considerations": {}
296011          }
296012        },
296013        {
296014          "type": "library",
296015          "bom-ref": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04\u0026package-id=71bd574c47c02b75",
296016          "supplier": {},
296017          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296018          "name": "libnfsidmap2",
296019          "version": "0.25-5.1ubuntu1",
296020          "cpe": "cpe:2.3:a:libnfsidmap2:libnfsidmap2:0.25-5.1ubuntu1:*:*:*:*:*:*:*",
296021          "purl": "pkg:deb/ubuntu/libnfsidmap2@0.25-5.1ubuntu1?arch=amd64\u0026upstream=libnfsidmap\u0026distro=ubuntu-20.04",
296022          "swid": {
296023            "attachment": {}
296024          },
296025          "pedigree": {},
296026          "evidence": {},
296027          "signature": {
296028            "signature": {
296029              "publicKey": {}
296030            }
296031          },
296032          "modelCard": {
296033            "modelParameters": {
296034              "approach": {}
296035            },
296036            "quantitativeAnalysis": {
296037              "graphics": {}
296038            },
296039            "considerations": {}
296040          }
296041        },
296042        {
296043          "type": "library",
296044          "bom-ref": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04\u0026package-id=9fc0ca46e6d21557",
296045          "supplier": {},
296046          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296047          "name": "libp11-kit0",
296048          "version": "0.23.20-1ubuntu0.1",
296049          "licenses": [
296050            {
296051              "license": {
296052                "id": "BSD-3-Clause"
296053              }
296054            },
296055            {
296056              "license": {
296057                "id": "ISC"
296058              }
296059            },
296060            {
296061              "license": {
296062                "name": "ISC+IBM"
296063              }
296064            },
296065            {
296066              "license": {
296067                "name": "permissive-like-automake-output"
296068              }
296069            },
296070            {
296071              "license": {
296072                "name": "same-as-rest-of-p11kit"
296073              }
296074            }
296075          ],
296076          "cpe": "cpe:2.3:a:libp11-kit0:libp11-kit0:0.23.20-1ubuntu0.1:*:*:*:*:*:*:*",
296077          "purl": "pkg:deb/ubuntu/libp11-kit0@0.23.20-1ubuntu0.1?arch=amd64\u0026upstream=p11-kit\u0026distro=ubuntu-20.04",
296078          "swid": {
296079            "attachment": {}
296080          },
296081          "pedigree": {},
296082          "evidence": {},
296083          "signature": {
296084            "signature": {
296085              "publicKey": {}
296086            }
296087          },
296088          "modelCard": {
296089            "modelParameters": {
296090              "approach": {}
296091            },
296092            "quantitativeAnalysis": {
296093              "graphics": {}
296094            },
296095            "considerations": {}
296096          }
296097        },
296098        {
296099          "type": "library",
296100          "bom-ref": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=e7be6c0ad703fc9a",
296101          "supplier": {},
296102          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296103          "name": "libpam-modules",
296104          "version": "1.3.1-5ubuntu4.2",
296105          "licenses": [
296106            {
296107              "license": {
296108                "name": "GPL"
296109              }
296110            }
296111          ],
296112          "cpe": "cpe:2.3:a:libpam-modules:libpam-modules:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
296113          "purl": "pkg:deb/ubuntu/libpam-modules@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
296114          "swid": {
296115            "attachment": {}
296116          },
296117          "pedigree": {},
296118          "evidence": {},
296119          "signature": {
296120            "signature": {
296121              "publicKey": {}
296122            }
296123          },
296124          "modelCard": {
296125            "modelParameters": {
296126              "approach": {}
296127            },
296128            "quantitativeAnalysis": {
296129              "graphics": {}
296130            },
296131            "considerations": {}
296132          }
296133        },
296134        {
296135          "type": "library",
296136          "bom-ref": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=7ff667273975da27",
296137          "supplier": {},
296138          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296139          "name": "libpam-modules-bin",
296140          "version": "1.3.1-5ubuntu4.2",
296141          "licenses": [
296142            {
296143              "license": {
296144                "name": "GPL"
296145              }
296146            }
296147          ],
296148          "cpe": "cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
296149          "purl": "pkg:deb/ubuntu/libpam-modules-bin@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
296150          "swid": {
296151            "attachment": {}
296152          },
296153          "pedigree": {},
296154          "evidence": {},
296155          "signature": {
296156            "signature": {
296157              "publicKey": {}
296158            }
296159          },
296160          "modelCard": {
296161            "modelParameters": {
296162              "approach": {}
296163            },
296164            "quantitativeAnalysis": {
296165              "graphics": {}
296166            },
296167            "considerations": {}
296168          }
296169        },
296170        {
296171          "type": "library",
296172          "bom-ref": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.2?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=47a743e8128a9af6",
296173          "supplier": {},
296174          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296175          "name": "libpam-runtime",
296176          "version": "1.3.1-5ubuntu4.2",
296177          "licenses": [
296178            {
296179              "license": {
296180                "name": "GPL"
296181              }
296182            }
296183          ],
296184          "cpe": "cpe:2.3:a:libpam-runtime:libpam-runtime:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
296185          "purl": "pkg:deb/ubuntu/libpam-runtime@1.3.1-5ubuntu4.2?arch=all\u0026upstream=pam\u0026distro=ubuntu-20.04",
296186          "swid": {
296187            "attachment": {}
296188          },
296189          "pedigree": {},
296190          "evidence": {},
296191          "signature": {
296192            "signature": {
296193              "publicKey": {}
296194            }
296195          },
296196          "modelCard": {
296197            "modelParameters": {
296198              "approach": {}
296199            },
296200            "quantitativeAnalysis": {
296201              "graphics": {}
296202            },
296203            "considerations": {}
296204          }
296205        },
296206        {
296207          "type": "library",
296208          "bom-ref": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04\u0026package-id=e57fbdd1e7d57983",
296209          "supplier": {},
296210          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296211          "name": "libpam0g",
296212          "version": "1.3.1-5ubuntu4.2",
296213          "licenses": [
296214            {
296215              "license": {
296216                "name": "GPL"
296217              }
296218            }
296219          ],
296220          "cpe": "cpe:2.3:a:libpam0g:libpam0g:1.3.1-5ubuntu4.2:*:*:*:*:*:*:*",
296221          "purl": "pkg:deb/ubuntu/libpam0g@1.3.1-5ubuntu4.2?arch=amd64\u0026upstream=pam\u0026distro=ubuntu-20.04",
296222          "swid": {
296223            "attachment": {}
296224          },
296225          "pedigree": {},
296226          "evidence": {},
296227          "signature": {
296228            "signature": {
296229              "publicKey": {}
296230            }
296231          },
296232          "modelCard": {
296233            "modelParameters": {
296234              "approach": {}
296235            },
296236            "quantitativeAnalysis": {
296237              "graphics": {}
296238            },
296239            "considerations": {}
296240          }
296241        },
296242        {
296243          "type": "library",
296244          "bom-ref": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04\u0026package-id=ec9eb70008ed8b14",
296245          "supplier": {},
296246          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296247          "name": "libpcre2-8-0",
296248          "version": "10.34-7",
296249          "cpe": "cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.34-7:*:*:*:*:*:*:*",
296250          "purl": "pkg:deb/ubuntu/libpcre2-8-0@10.34-7?arch=amd64\u0026upstream=pcre2\u0026distro=ubuntu-20.04",
296251          "swid": {
296252            "attachment": {}
296253          },
296254          "pedigree": {},
296255          "evidence": {},
296256          "signature": {
296257            "signature": {
296258              "publicKey": {}
296259            }
296260          },
296261          "modelCard": {
296262            "modelParameters": {
296263              "approach": {}
296264            },
296265            "quantitativeAnalysis": {
296266              "graphics": {}
296267            },
296268            "considerations": {}
296269          }
296270        },
296271        {
296272          "type": "library",
296273          "bom-ref": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04\u0026package-id=f2af8e66c60a624",
296274          "supplier": {},
296275          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296276          "name": "libpcre3",
296277          "version": "2:8.39-12build1",
296278          "cpe": "cpe:2.3:a:libpcre3:libpcre3:2\\:8.39-12build1:*:*:*:*:*:*:*",
296279          "purl": "pkg:deb/ubuntu/libpcre3@2:8.39-12build1?arch=amd64\u0026upstream=pcre3\u0026distro=ubuntu-20.04",
296280          "swid": {
296281            "attachment": {}
296282          },
296283          "pedigree": {},
296284          "evidence": {},
296285          "signature": {
296286            "signature": {
296287              "publicKey": {}
296288            }
296289          },
296290          "modelCard": {
296291            "modelParameters": {
296292              "approach": {}
296293            },
296294            "quantitativeAnalysis": {
296295              "graphics": {}
296296            },
296297            "considerations": {}
296298          }
296299        },
296300        {
296301          "type": "library",
296302          "bom-ref": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.2?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04\u0026package-id=1444db6c35de79c6",
296303          "supplier": {},
296304          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296305          "name": "libprocps8",
296306          "version": "2:3.3.16-1ubuntu2.2",
296307          "licenses": [
296308            {
296309              "license": {
296310                "id": "GPL-2.0-only"
296311              }
296312            },
296313            {
296314              "license": {
296315                "id": "GPL-2.0-or-later"
296316              }
296317            },
296318            {
296319              "license": {
296320                "id": "LGPL-2.0-only"
296321              }
296322            },
296323            {
296324              "license": {
296325                "id": "LGPL-2.0-or-later"
296326              }
296327            },
296328            {
296329              "license": {
296330                "id": "LGPL-2.1-only"
296331              }
296332            },
296333            {
296334              "license": {
296335                "id": "LGPL-2.1-or-later"
296336              }
296337            }
296338          ],
296339          "cpe": "cpe:2.3:a:libprocps8:libprocps8:2\\:3.3.16-1ubuntu2.2:*:*:*:*:*:*:*",
296340          "purl": "pkg:deb/ubuntu/libprocps8@2:3.3.16-1ubuntu2.2?arch=amd64\u0026upstream=procps\u0026distro=ubuntu-20.04",
296341          "swid": {
296342            "attachment": {}
296343          },
296344          "pedigree": {},
296345          "evidence": {},
296346          "signature": {
296347            "signature": {
296348              "publicKey": {}
296349            }
296350          },
296351          "modelCard": {
296352            "modelParameters": {
296353              "approach": {}
296354            },
296355            "quantitativeAnalysis": {
296356              "graphics": {}
296357            },
296358            "considerations": {}
296359          }
296360        },
296361        {
296362          "type": "library",
296363          "bom-ref": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=b40e3316416bbdaf",
296364          "supplier": {},
296365          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296366          "name": "libpython3-stdlib",
296367          "version": "3.8.2-0ubuntu2",
296368          "cpe": "cpe:2.3:a:libpython3-stdlib:libpython3-stdlib:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
296369          "purl": "pkg:deb/ubuntu/libpython3-stdlib@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
296370          "swid": {
296371            "attachment": {}
296372          },
296373          "pedigree": {},
296374          "evidence": {},
296375          "signature": {
296376            "signature": {
296377              "publicKey": {}
296378            }
296379          },
296380          "modelCard": {
296381            "modelParameters": {
296382              "approach": {}
296383            },
296384            "quantitativeAnalysis": {
296385              "graphics": {}
296386            },
296387            "considerations": {}
296388          }
296389        },
296390        {
296391          "type": "library",
296392          "bom-ref": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=fb58dad98da64e3b",
296393          "supplier": {},
296394          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296395          "name": "libpython3.8-minimal",
296396          "version": "3.8.10-0ubuntu1~20.04",
296397          "licenses": [
296398            {
296399              "license": {
296400                "name": "By"
296401              }
296402            },
296403            {
296404              "license": {
296405                "id": "GPL-2.0-only"
296406              }
296407            },
296408            {
296409              "license": {
296410                "name": "Permission"
296411              }
296412            },
296413            {
296414              "license": {
296415                "name": "Redistribution"
296416              }
296417            },
296418            {
296419              "license": {
296420                "name": "This"
296421              }
296422            }
296423          ],
296424          "cpe": "cpe:2.3:a:libpython3.8-minimal:libpython3.8-minimal:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
296425          "purl": "pkg:deb/ubuntu/libpython3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
296426          "swid": {
296427            "attachment": {}
296428          },
296429          "pedigree": {},
296430          "evidence": {},
296431          "signature": {
296432            "signature": {
296433              "publicKey": {}
296434            }
296435          },
296436          "modelCard": {
296437            "modelParameters": {
296438              "approach": {}
296439            },
296440            "quantitativeAnalysis": {
296441              "graphics": {}
296442            },
296443            "considerations": {}
296444          }
296445        },
296446        {
296447          "type": "library",
296448          "bom-ref": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=54e48e611df3b41d",
296449          "supplier": {},
296450          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296451          "name": "libpython3.8-stdlib",
296452          "version": "3.8.10-0ubuntu1~20.04",
296453          "licenses": [
296454            {
296455              "license": {
296456                "name": "By"
296457              }
296458            },
296459            {
296460              "license": {
296461                "id": "GPL-2.0-only"
296462              }
296463            },
296464            {
296465              "license": {
296466                "name": "Permission"
296467              }
296468            },
296469            {
296470              "license": {
296471                "name": "Redistribution"
296472              }
296473            },
296474            {
296475              "license": {
296476                "name": "This"
296477              }
296478            }
296479          ],
296480          "cpe": "cpe:2.3:a:libpython3.8-stdlib:libpython3.8-stdlib:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
296481          "purl": "pkg:deb/ubuntu/libpython3.8-stdlib@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
296482          "swid": {
296483            "attachment": {}
296484          },
296485          "pedigree": {},
296486          "evidence": {},
296487          "signature": {
296488            "signature": {
296489              "publicKey": {}
296490            }
296491          },
296492          "modelCard": {
296493            "modelParameters": {
296494              "approach": {}
296495            },
296496            "quantitativeAnalysis": {
296497              "graphics": {}
296498            },
296499            "considerations": {}
296500          }
296501        },
296502        {
296503          "type": "library",
296504          "bom-ref": "pkg:deb/ubuntu/libreadline5@5.2+dfsg-3build3?arch=amd64\u0026upstream=readline5\u0026distro=ubuntu-20.04\u0026package-id=5763fb43bb0ba51a",
296505          "supplier": {},
296506          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296507          "name": "libreadline5",
296508          "version": "5.2+dfsg-3build3",
296509          "licenses": [
296510            {
296511              "license": {
296512                "id": "GPL-2.0-only"
296513              }
296514            }
296515          ],
296516          "cpe": "cpe:2.3:a:libreadline5:libreadline5:5.2\\+dfsg-3build3:*:*:*:*:*:*:*",
296517          "purl": "pkg:deb/ubuntu/libreadline5@5.2+dfsg-3build3?arch=amd64\u0026upstream=readline5\u0026distro=ubuntu-20.04",
296518          "swid": {
296519            "attachment": {}
296520          },
296521          "pedigree": {},
296522          "evidence": {},
296523          "signature": {
296524            "signature": {
296525              "publicKey": {}
296526            }
296527          },
296528          "modelCard": {
296529            "modelParameters": {
296530              "approach": {}
296531            },
296532            "quantitativeAnalysis": {
296533              "graphics": {}
296534            },
296535            "considerations": {}
296536          }
296537        },
296538        {
296539          "type": "library",
296540          "bom-ref": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=67b876656fcd9e68",
296541          "supplier": {},
296542          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296543          "name": "libreadline8",
296544          "version": "8.0-4",
296545          "licenses": [
296546            {
296547              "license": {
296548                "name": "GFDL"
296549              }
296550            },
296551            {
296552              "license": {
296553                "id": "GPL-3.0-only"
296554              }
296555            }
296556          ],
296557          "cpe": "cpe:2.3:a:libreadline8:libreadline8:8.0-4:*:*:*:*:*:*:*",
296558          "purl": "pkg:deb/ubuntu/libreadline8@8.0-4?arch=amd64\u0026upstream=readline\u0026distro=ubuntu-20.04",
296559          "swid": {
296560            "attachment": {}
296561          },
296562          "pedigree": {},
296563          "evidence": {},
296564          "signature": {
296565            "signature": {
296566              "publicKey": {}
296567            }
296568          },
296569          "modelCard": {
296570            "modelParameters": {
296571              "approach": {}
296572            },
296573            "quantitativeAnalysis": {
296574              "graphics": {}
296575            },
296576            "considerations": {}
296577          }
296578        },
296579        {
296580          "type": "library",
296581          "bom-ref": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=68e35bc456818613",
296582          "supplier": {},
296583          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296584          "name": "libroken18-heimdal",
296585          "version": "7.7.0+dfsg-1ubuntu1",
296586          "licenses": [
296587            {
296588              "license": {
296589                "id": "BSD-3-Clause"
296590              }
296591            },
296592            {
296593              "license": {
296594                "id": "GPL-2.0-only"
296595              }
296596            },
296597            {
296598              "license": {
296599                "id": "GPL-2.0-or-later"
296600              }
296601            },
296602            {
296603              "license": {
296604                "name": "custom"
296605              }
296606            }
296607          ],
296608          "cpe": "cpe:2.3:a:libroken18-heimdal:libroken18-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
296609          "purl": "pkg:deb/ubuntu/libroken18-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
296610          "swid": {
296611            "attachment": {}
296612          },
296613          "pedigree": {},
296614          "evidence": {},
296615          "signature": {
296616            "signature": {
296617              "publicKey": {}
296618            }
296619          },
296620          "modelCard": {
296621            "modelParameters": {
296622              "approach": {}
296623            },
296624            "quantitativeAnalysis": {
296625              "graphics": {}
296626            },
296627            "considerations": {}
296628          }
296629        },
296630        {
296631          "type": "library",
296632          "bom-ref": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=374396d82667544d",
296633          "supplier": {},
296634          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296635          "name": "libsasl2-2",
296636          "version": "2.1.27+dfsg-2",
296637          "licenses": [
296638            {
296639              "license": {
296640                "id": "BSD-4-Clause"
296641              }
296642            },
296643            {
296644              "license": {
296645                "id": "GPL-3.0-only"
296646              }
296647            },
296648            {
296649              "license": {
296650                "id": "GPL-3.0-or-later"
296651              }
296652            }
296653          ],
296654          "cpe": "cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
296655          "purl": "pkg:deb/ubuntu/libsasl2-2@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
296656          "swid": {
296657            "attachment": {}
296658          },
296659          "pedigree": {},
296660          "evidence": {},
296661          "signature": {
296662            "signature": {
296663              "publicKey": {}
296664            }
296665          },
296666          "modelCard": {
296667            "modelParameters": {
296668              "approach": {}
296669            },
296670            "quantitativeAnalysis": {
296671              "graphics": {}
296672            },
296673            "considerations": {}
296674          }
296675        },
296676        {
296677          "type": "library",
296678          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=fb8d278d10c4a3cf",
296679          "supplier": {},
296680          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296681          "name": "libsasl2-modules",
296682          "version": "2.1.27+dfsg-2",
296683          "licenses": [
296684            {
296685              "license": {
296686                "id": "BSD-4-Clause"
296687              }
296688            },
296689            {
296690              "license": {
296691                "id": "GPL-3.0-only"
296692              }
296693            },
296694            {
296695              "license": {
296696                "id": "GPL-3.0-or-later"
296697              }
296698            }
296699          ],
296700          "cpe": "cpe:2.3:a:libsasl2-modules:libsasl2-modules:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
296701          "purl": "pkg:deb/ubuntu/libsasl2-modules@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
296702          "swid": {
296703            "attachment": {}
296704          },
296705          "pedigree": {},
296706          "evidence": {},
296707          "signature": {
296708            "signature": {
296709              "publicKey": {}
296710            }
296711          },
296712          "modelCard": {
296713            "modelParameters": {
296714              "approach": {}
296715            },
296716            "quantitativeAnalysis": {
296717              "graphics": {}
296718            },
296719            "considerations": {}
296720          }
296721        },
296722        {
296723          "type": "library",
296724          "bom-ref": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04\u0026package-id=63c3c50d36ec1d13",
296725          "supplier": {},
296726          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296727          "name": "libsasl2-modules-db",
296728          "version": "2.1.27+dfsg-2",
296729          "licenses": [
296730            {
296731              "license": {
296732                "id": "BSD-4-Clause"
296733              }
296734            },
296735            {
296736              "license": {
296737                "id": "GPL-3.0-only"
296738              }
296739            },
296740            {
296741              "license": {
296742                "id": "GPL-3.0-or-later"
296743              }
296744            }
296745          ],
296746          "cpe": "cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.27\\+dfsg-2:*:*:*:*:*:*:*",
296747          "purl": "pkg:deb/ubuntu/libsasl2-modules-db@2.1.27+dfsg-2?arch=amd64\u0026upstream=cyrus-sasl2\u0026distro=ubuntu-20.04",
296748          "swid": {
296749            "attachment": {}
296750          },
296751          "pedigree": {},
296752          "evidence": {},
296753          "signature": {
296754            "signature": {
296755              "publicKey": {}
296756            }
296757          },
296758          "modelCard": {
296759            "modelParameters": {
296760              "approach": {}
296761            },
296762            "quantitativeAnalysis": {
296763              "graphics": {}
296764            },
296765            "considerations": {}
296766          }
296767        },
296768        {
296769          "type": "library",
296770          "bom-ref": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04\u0026package-id=b2fd79b9c242e8e8",
296771          "supplier": {},
296772          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296773          "name": "libseccomp2",
296774          "version": "2.5.1-1ubuntu1~20.04.1",
296775          "licenses": [
296776            {
296777              "license": {
296778                "id": "LGPL-2.1-only"
296779              }
296780            }
296781          ],
296782          "cpe": "cpe:2.3:a:libseccomp2:libseccomp2:2.5.1-1ubuntu1\\~20.04.1:*:*:*:*:*:*:*",
296783          "purl": "pkg:deb/ubuntu/libseccomp2@2.5.1-1ubuntu1~20.04.1?arch=amd64\u0026upstream=libseccomp\u0026distro=ubuntu-20.04",
296784          "swid": {
296785            "attachment": {}
296786          },
296787          "pedigree": {},
296788          "evidence": {},
296789          "signature": {
296790            "signature": {
296791              "publicKey": {}
296792            }
296793          },
296794          "modelCard": {
296795            "modelParameters": {
296796              "approach": {}
296797            },
296798            "quantitativeAnalysis": {
296799              "graphics": {}
296800            },
296801            "considerations": {}
296802          }
296803        },
296804        {
296805          "type": "library",
296806          "bom-ref": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04\u0026package-id=e5d4ae16ac79b901",
296807          "supplier": {},
296808          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296809          "name": "libselinux1",
296810          "version": "3.0-1build2",
296811          "licenses": [
296812            {
296813              "license": {
296814                "id": "GPL-2.0-only"
296815              }
296816            },
296817            {
296818              "license": {
296819                "id": "LGPL-2.1-only"
296820              }
296821            }
296822          ],
296823          "cpe": "cpe:2.3:a:libselinux1:libselinux1:3.0-1build2:*:*:*:*:*:*:*",
296824          "purl": "pkg:deb/ubuntu/libselinux1@3.0-1build2?arch=amd64\u0026upstream=libselinux\u0026distro=ubuntu-20.04",
296825          "swid": {
296826            "attachment": {}
296827          },
296828          "pedigree": {},
296829          "evidence": {},
296830          "signature": {
296831            "signature": {
296832              "publicKey": {}
296833            }
296834          },
296835          "modelCard": {
296836            "modelParameters": {
296837              "approach": {}
296838            },
296839            "quantitativeAnalysis": {
296840              "graphics": {}
296841            },
296842            "considerations": {}
296843          }
296844        },
296845        {
296846          "type": "library",
296847          "bom-ref": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=4c6cd9f68ce53262",
296848          "supplier": {},
296849          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296850          "name": "libsemanage-common",
296851          "version": "3.0-1build2",
296852          "licenses": [
296853            {
296854              "license": {
296855                "name": "GPL"
296856              }
296857            },
296858            {
296859              "license": {
296860                "name": "LGPL"
296861              }
296862            }
296863          ],
296864          "cpe": "cpe:2.3:a:libsemanage-common:libsemanage-common:3.0-1build2:*:*:*:*:*:*:*",
296865          "purl": "pkg:deb/ubuntu/libsemanage-common@3.0-1build2?arch=all\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
296866          "swid": {
296867            "attachment": {}
296868          },
296869          "pedigree": {},
296870          "evidence": {},
296871          "signature": {
296872            "signature": {
296873              "publicKey": {}
296874            }
296875          },
296876          "modelCard": {
296877            "modelParameters": {
296878              "approach": {}
296879            },
296880            "quantitativeAnalysis": {
296881              "graphics": {}
296882            },
296883            "considerations": {}
296884          }
296885        },
296886        {
296887          "type": "library",
296888          "bom-ref": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04\u0026package-id=963297f19b339026",
296889          "supplier": {},
296890          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296891          "name": "libsemanage1",
296892          "version": "3.0-1build2",
296893          "licenses": [
296894            {
296895              "license": {
296896                "name": "GPL"
296897              }
296898            },
296899            {
296900              "license": {
296901                "name": "LGPL"
296902              }
296903            }
296904          ],
296905          "cpe": "cpe:2.3:a:libsemanage1:libsemanage1:3.0-1build2:*:*:*:*:*:*:*",
296906          "purl": "pkg:deb/ubuntu/libsemanage1@3.0-1build2?arch=amd64\u0026upstream=libsemanage\u0026distro=ubuntu-20.04",
296907          "swid": {
296908            "attachment": {}
296909          },
296910          "pedigree": {},
296911          "evidence": {},
296912          "signature": {
296913            "signature": {
296914              "publicKey": {}
296915            }
296916          },
296917          "modelCard": {
296918            "modelParameters": {
296919              "approach": {}
296920            },
296921            "quantitativeAnalysis": {
296922              "graphics": {}
296923            },
296924            "considerations": {}
296925          }
296926        },
296927        {
296928          "type": "library",
296929          "bom-ref": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04\u0026package-id=991afdd7bf17200c",
296930          "supplier": {},
296931          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296932          "name": "libsepol1",
296933          "version": "3.0-1",
296934          "licenses": [
296935            {
296936              "license": {
296937                "name": "GPL"
296938              }
296939            },
296940            {
296941              "license": {
296942                "name": "LGPL"
296943              }
296944            }
296945          ],
296946          "cpe": "cpe:2.3:a:libsepol1:libsepol1:3.0-1:*:*:*:*:*:*:*",
296947          "purl": "pkg:deb/ubuntu/libsepol1@3.0-1?arch=amd64\u0026upstream=libsepol\u0026distro=ubuntu-20.04",
296948          "swid": {
296949            "attachment": {}
296950          },
296951          "pedigree": {},
296952          "evidence": {},
296953          "signature": {
296954            "signature": {
296955              "publicKey": {}
296956            }
296957          },
296958          "modelCard": {
296959            "modelParameters": {
296960              "approach": {}
296961            },
296962            "quantitativeAnalysis": {
296963              "graphics": {}
296964            },
296965            "considerations": {}
296966          }
296967        },
296968        {
296969          "type": "library",
296970          "bom-ref": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=b47d3a935260c518",
296971          "supplier": {},
296972          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
296973          "name": "libsmartcols1",
296974          "version": "2.34-0.1ubuntu9.1",
296975          "licenses": [
296976            {
296977              "license": {
296978                "id": "BSD-2-Clause"
296979              }
296980            },
296981            {
296982              "license": {
296983                "id": "BSD-3-Clause"
296984              }
296985            },
296986            {
296987              "license": {
296988                "id": "BSD-4-Clause"
296989              }
296990            },
296991            {
296992              "license": {
296993                "id": "GPL-2.0-only"
296994              }
296995            },
296996            {
296997              "license": {
296998                "id": "GPL-2.0-or-later"
296999              }
297000            },
297001            {
297002              "license": {
297003                "id": "GPL-3.0-only"
297004              }
297005            },
297006            {
297007              "license": {
297008                "id": "GPL-3.0-or-later"
297009              }
297010            },
297011            {
297012              "license": {
297013                "name": "LGPL"
297014              }
297015            },
297016            {
297017              "license": {
297018                "id": "LGPL-2.0-only"
297019              }
297020            },
297021            {
297022              "license": {
297023                "id": "LGPL-2.0-or-later"
297024              }
297025            },
297026            {
297027              "license": {
297028                "id": "LGPL-2.1-only"
297029              }
297030            },
297031            {
297032              "license": {
297033                "id": "LGPL-2.1-or-later"
297034              }
297035            },
297036            {
297037              "license": {
297038                "id": "LGPL-3.0-only"
297039              }
297040            },
297041            {
297042              "license": {
297043                "id": "LGPL-3.0-or-later"
297044              }
297045            },
297046            {
297047              "license": {
297048                "id": "MIT"
297049              }
297050            },
297051            {
297052              "license": {
297053                "name": "public-domain"
297054              }
297055            }
297056          ],
297057          "cpe": "cpe:2.3:a:libsmartcols1:libsmartcols1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
297058          "purl": "pkg:deb/ubuntu/libsmartcols1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
297059          "swid": {
297060            "attachment": {}
297061          },
297062          "pedigree": {},
297063          "evidence": {},
297064          "signature": {
297065            "signature": {
297066              "publicKey": {}
297067            }
297068          },
297069          "modelCard": {
297070            "modelParameters": {
297071              "approach": {}
297072            },
297073            "quantitativeAnalysis": {
297074              "graphics": {}
297075            },
297076            "considerations": {}
297077          }
297078        },
297079        {
297080          "type": "library",
297081          "bom-ref": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04\u0026package-id=a7c7ccf11d3583d1",
297082          "supplier": {},
297083          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297084          "name": "libsqlite3-0",
297085          "version": "3.31.1-4ubuntu0.2",
297086          "licenses": [
297087            {
297088              "license": {
297089                "id": "GPL-2.0-only"
297090              }
297091            },
297092            {
297093              "license": {
297094                "id": "GPL-2.0-or-later"
297095              }
297096            },
297097            {
297098              "license": {
297099                "name": "public-domain"
297100              }
297101            }
297102          ],
297103          "cpe": "cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.31.1-4ubuntu0.2:*:*:*:*:*:*:*",
297104          "purl": "pkg:deb/ubuntu/libsqlite3-0@3.31.1-4ubuntu0.2?arch=amd64\u0026upstream=sqlite3\u0026distro=ubuntu-20.04",
297105          "swid": {
297106            "attachment": {}
297107          },
297108          "pedigree": {},
297109          "evidence": {},
297110          "signature": {
297111            "signature": {
297112              "publicKey": {}
297113            }
297114          },
297115          "modelCard": {
297116            "modelParameters": {
297117              "approach": {}
297118            },
297119            "quantitativeAnalysis": {
297120              "graphics": {}
297121            },
297122            "considerations": {}
297123          }
297124        },
297125        {
297126          "type": "library",
297127          "bom-ref": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4715894cb8165c",
297128          "supplier": {},
297129          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297130          "name": "libss2",
297131          "version": "1.45.5-2ubuntu1",
297132          "cpe": "cpe:2.3:a:libss2:libss2:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
297133          "purl": "pkg:deb/ubuntu/libss2@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
297134          "swid": {
297135            "attachment": {}
297136          },
297137          "pedigree": {},
297138          "evidence": {},
297139          "signature": {
297140            "signature": {
297141              "publicKey": {}
297142            }
297143          },
297144          "modelCard": {
297145            "modelParameters": {
297146              "approach": {}
297147            },
297148            "quantitativeAnalysis": {
297149              "graphics": {}
297150            },
297151            "considerations": {}
297152          }
297153        },
297154        {
297155          "type": "library",
297156          "bom-ref": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.8?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04\u0026package-id=9228d1481eea75e3",
297157          "supplier": {},
297158          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297159          "name": "libssl1.1",
297160          "version": "1.1.1f-1ubuntu2.8",
297161          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1f-1ubuntu2.8:*:*:*:*:*:*:*",
297162          "purl": "pkg:deb/ubuntu/libssl1.1@1.1.1f-1ubuntu2.8?arch=amd64\u0026upstream=openssl\u0026distro=ubuntu-20.04",
297163          "swid": {
297164            "attachment": {}
297165          },
297166          "pedigree": {},
297167          "evidence": {},
297168          "signature": {
297169            "signature": {
297170              "publicKey": {}
297171            }
297172          },
297173          "modelCard": {
297174            "modelParameters": {
297175              "approach": {}
297176            },
297177            "quantitativeAnalysis": {
297178              "graphics": {}
297179            },
297180            "considerations": {}
297181          }
297182        },
297183        {
297184          "type": "library",
297185          "bom-ref": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04\u0026package-id=241fcb3d9b65153a",
297186          "supplier": {},
297187          "publisher": "Ubuntu Core developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297188          "name": "libstdc++6",
297189          "version": "10.3.0-1ubuntu1~20.04",
297190          "licenses": [
297191            {
297192              "license": {
297193                "name": "Artistic"
297194              }
297195            },
297196            {
297197              "license": {
297198                "id": "GFDL-1.2-only"
297199              }
297200            },
297201            {
297202              "license": {
297203                "name": "GPL"
297204              }
297205            },
297206            {
297207              "license": {
297208                "id": "GPL-2.0-only"
297209              }
297210            },
297211            {
297212              "license": {
297213                "id": "GPL-3.0-only"
297214              }
297215            },
297216            {
297217              "license": {
297218                "name": "LGPL"
297219              }
297220            }
297221          ],
297222          "cpe": "cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:10.3.0-1ubuntu1\\~20.04:*:*:*:*:*:*:*",
297223          "purl": "pkg:deb/ubuntu/libstdc++6@10.3.0-1ubuntu1~20.04?arch=amd64\u0026upstream=gcc-10\u0026distro=ubuntu-20.04",
297224          "swid": {
297225            "attachment": {}
297226          },
297227          "pedigree": {},
297228          "evidence": {},
297229          "signature": {
297230            "signature": {
297231              "publicKey": {}
297232            }
297233          },
297234          "modelCard": {
297235            "modelParameters": {
297236              "approach": {}
297237            },
297238            "quantitativeAnalysis": {
297239              "graphics": {}
297240            },
297241            "considerations": {}
297242          }
297243        },
297244        {
297245          "type": "library",
297246          "bom-ref": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=72d1f4b2fda6e155",
297247          "supplier": {},
297248          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297249          "name": "libsystemd0",
297250          "version": "245.4-4ubuntu3.11",
297251          "licenses": [
297252            {
297253              "license": {
297254                "id": "CC0-1.0"
297255              }
297256            },
297257            {
297258              "license": {
297259                "name": "Expat"
297260              }
297261            },
297262            {
297263              "license": {
297264                "id": "GPL-2.0-only"
297265              }
297266            },
297267            {
297268              "license": {
297269                "id": "GPL-2.0-or-later"
297270              }
297271            },
297272            {
297273              "license": {
297274                "id": "LGPL-2.1-only"
297275              }
297276            },
297277            {
297278              "license": {
297279                "id": "LGPL-2.1-or-later"
297280              }
297281            },
297282            {
297283              "license": {
297284                "name": "public-domain"
297285              }
297286            }
297287          ],
297288          "cpe": "cpe:2.3:a:libsystemd0:libsystemd0:245.4-4ubuntu3.11:*:*:*:*:*:*:*",
297289          "purl": "pkg:deb/ubuntu/libsystemd0@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
297290          "swid": {
297291            "attachment": {}
297292          },
297293          "pedigree": {},
297294          "evidence": {},
297295          "signature": {
297296            "signature": {
297297              "publicKey": {}
297298            }
297299          },
297300          "modelCard": {
297301            "modelParameters": {
297302              "approach": {}
297303            },
297304            "quantitativeAnalysis": {
297305              "graphics": {}
297306            },
297307            "considerations": {}
297308          }
297309        },
297310        {
297311          "type": "library",
297312          "bom-ref": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=a290c35fc0220ba0",
297313          "supplier": {},
297314          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297315          "name": "libtasn1-6",
297316          "version": "4.16.0-2",
297317          "licenses": [
297318            {
297319              "license": {
297320                "id": "GFDL-1.3-only"
297321              }
297322            },
297323            {
297324              "license": {
297325                "id": "GPL-3.0-only"
297326              }
297327            },
297328            {
297329              "license": {
297330                "name": "LGPL"
297331              }
297332            },
297333            {
297334              "license": {
297335                "id": "LGPL-2.1-only"
297336              }
297337            }
297338          ],
297339          "cpe": "cpe:2.3:a:libtasn1-6:libtasn1-6:4.16.0-2:*:*:*:*:*:*:*",
297340          "purl": "pkg:deb/ubuntu/libtasn1-6@4.16.0-2?arch=amd64\u0026distro=ubuntu-20.04",
297341          "swid": {
297342            "attachment": {}
297343          },
297344          "pedigree": {},
297345          "evidence": {},
297346          "signature": {
297347            "signature": {
297348              "publicKey": {}
297349            }
297350          },
297351          "modelCard": {
297352            "modelParameters": {
297353              "approach": {}
297354            },
297355            "quantitativeAnalysis": {
297356              "graphics": {}
297357            },
297358            "considerations": {}
297359          }
297360        },
297361        {
297362          "type": "library",
297363          "bom-ref": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=72ad56d118fefea3",
297364          "supplier": {},
297365          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297366          "name": "libtinfo6",
297367          "version": "6.2-0ubuntu2",
297368          "cpe": "cpe:2.3:a:libtinfo6:libtinfo6:6.2-0ubuntu2:*:*:*:*:*:*:*",
297369          "purl": "pkg:deb/ubuntu/libtinfo6@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
297370          "swid": {
297371            "attachment": {}
297372          },
297373          "pedigree": {},
297374          "evidence": {},
297375          "signature": {
297376            "signature": {
297377              "publicKey": {}
297378            }
297379          },
297380          "modelCard": {
297381            "modelParameters": {
297382              "approach": {}
297383            },
297384            "quantitativeAnalysis": {
297385              "graphics": {}
297386            },
297387            "considerations": {}
297388          }
297389        },
297390        {
297391          "type": "library",
297392          "bom-ref": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=ba22fe8af5722b24",
297393          "supplier": {},
297394          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297395          "name": "libtirpc-common",
297396          "version": "1.2.5-1",
297397          "licenses": [
297398            {
297399              "license": {
297400                "id": "BSD-3-Clause"
297401              }
297402            },
297403            {
297404              "license": {
297405                "id": "GPL-2.0-only"
297406              }
297407            },
297408            {
297409              "license": {
297410                "id": "LGPL-2.1-only"
297411              }
297412            }
297413          ],
297414          "cpe": "cpe:2.3:a:libtirpc-common:libtirpc-common:1.2.5-1:*:*:*:*:*:*:*",
297415          "purl": "pkg:deb/ubuntu/libtirpc-common@1.2.5-1?arch=all\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
297416          "swid": {
297417            "attachment": {}
297418          },
297419          "pedigree": {},
297420          "evidence": {},
297421          "signature": {
297422            "signature": {
297423              "publicKey": {}
297424            }
297425          },
297426          "modelCard": {
297427            "modelParameters": {
297428              "approach": {}
297429            },
297430            "quantitativeAnalysis": {
297431              "graphics": {}
297432            },
297433            "considerations": {}
297434          }
297435        },
297436        {
297437          "type": "library",
297438          "bom-ref": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04\u0026package-id=57b2bfa0a8467ab7",
297439          "supplier": {},
297440          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297441          "name": "libtirpc3",
297442          "version": "1.2.5-1",
297443          "licenses": [
297444            {
297445              "license": {
297446                "id": "BSD-3-Clause"
297447              }
297448            },
297449            {
297450              "license": {
297451                "id": "GPL-2.0-only"
297452              }
297453            },
297454            {
297455              "license": {
297456                "id": "LGPL-2.1-only"
297457              }
297458            }
297459          ],
297460          "cpe": "cpe:2.3:a:libtirpc3:libtirpc3:1.2.5-1:*:*:*:*:*:*:*",
297461          "purl": "pkg:deb/ubuntu/libtirpc3@1.2.5-1?arch=amd64\u0026upstream=libtirpc\u0026distro=ubuntu-20.04",
297462          "swid": {
297463            "attachment": {}
297464          },
297465          "pedigree": {},
297466          "evidence": {},
297467          "signature": {
297468            "signature": {
297469              "publicKey": {}
297470            }
297471          },
297472          "modelCard": {
297473            "modelParameters": {
297474              "approach": {}
297475            },
297476            "quantitativeAnalysis": {
297477              "graphics": {}
297478            },
297479            "considerations": {}
297480          }
297481        },
297482        {
297483          "type": "library",
297484          "bom-ref": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04\u0026package-id=28d962536291b482",
297485          "supplier": {},
297486          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297487          "name": "libudev1",
297488          "version": "245.4-4ubuntu3.11",
297489          "licenses": [
297490            {
297491              "license": {
297492                "id": "CC0-1.0"
297493              }
297494            },
297495            {
297496              "license": {
297497                "name": "Expat"
297498              }
297499            },
297500            {
297501              "license": {
297502                "id": "GPL-2.0-only"
297503              }
297504            },
297505            {
297506              "license": {
297507                "id": "GPL-2.0-or-later"
297508              }
297509            },
297510            {
297511              "license": {
297512                "id": "LGPL-2.1-only"
297513              }
297514            },
297515            {
297516              "license": {
297517                "id": "LGPL-2.1-or-later"
297518              }
297519            },
297520            {
297521              "license": {
297522                "name": "public-domain"
297523              }
297524            }
297525          ],
297526          "cpe": "cpe:2.3:a:libudev1:libudev1:245.4-4ubuntu3.11:*:*:*:*:*:*:*",
297527          "purl": "pkg:deb/ubuntu/libudev1@245.4-4ubuntu3.11?arch=amd64\u0026upstream=systemd\u0026distro=ubuntu-20.04",
297528          "swid": {
297529            "attachment": {}
297530          },
297531          "pedigree": {},
297532          "evidence": {},
297533          "signature": {
297534            "signature": {
297535              "publicKey": {}
297536            }
297537          },
297538          "modelCard": {
297539            "modelParameters": {
297540              "approach": {}
297541            },
297542            "quantitativeAnalysis": {
297543              "graphics": {}
297544            },
297545            "considerations": {}
297546          }
297547        },
297548        {
297549          "type": "library",
297550          "bom-ref": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04\u0026package-id=3140ffa70dcd9831",
297551          "supplier": {},
297552          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297553          "name": "libunistring2",
297554          "version": "0.9.10-2",
297555          "licenses": [
297556            {
297557              "license": {
297558                "name": "FreeSoftware"
297559              }
297560            },
297561            {
297562              "license": {
297563                "id": "GFDL-1.2-only"
297564              }
297565            },
297566            {
297567              "license": {
297568                "name": "GFDL-1.2+"
297569              }
297570            },
297571            {
297572              "license": {
297573                "id": "GPL-2.0-only"
297574              }
297575            },
297576            {
297577              "license": {
297578                "id": "GPL-2.0-or-later"
297579              }
297580            },
297581            {
297582              "license": {
297583                "id": "GPL-3.0-only"
297584              }
297585            },
297586            {
297587              "license": {
297588                "id": "GPL-3.0-or-later"
297589              }
297590            },
297591            {
297592              "license": {
297593                "id": "LGPL-3.0-only"
297594              }
297595            },
297596            {
297597              "license": {
297598                "id": "LGPL-3.0-or-later"
297599              }
297600            },
297601            {
297602              "license": {
297603                "id": "MIT"
297604              }
297605            }
297606          ],
297607          "cpe": "cpe:2.3:a:libunistring2:libunistring2:0.9.10-2:*:*:*:*:*:*:*",
297608          "purl": "pkg:deb/ubuntu/libunistring2@0.9.10-2?arch=amd64\u0026upstream=libunistring\u0026distro=ubuntu-20.04",
297609          "swid": {
297610            "attachment": {}
297611          },
297612          "pedigree": {},
297613          "evidence": {},
297614          "signature": {
297615            "signature": {
297616              "publicKey": {}
297617            }
297618          },
297619          "modelCard": {
297620            "modelParameters": {
297621              "approach": {}
297622            },
297623            "quantitativeAnalysis": {
297624              "graphics": {}
297625            },
297626            "considerations": {}
297627          }
297628        },
297629        {
297630          "type": "library",
297631          "bom-ref": "pkg:deb/ubuntu/liburcu6@0.11.1-2?arch=amd64\u0026upstream=liburcu\u0026distro=ubuntu-20.04\u0026package-id=555d9abce2448934",
297632          "supplier": {},
297633          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297634          "name": "liburcu6",
297635          "version": "0.11.1-2",
297636          "licenses": [
297637            {
297638              "license": {
297639                "id": "BSD-2-Clause"
297640              }
297641            },
297642            {
297643              "license": {
297644                "name": "Expat"
297645              }
297646            },
297647            {
297648              "license": {
297649                "id": "FSFUL"
297650              }
297651            },
297652            {
297653              "license": {
297654                "id": "GPL-2.0-only"
297655              }
297656            },
297657            {
297658              "license": {
297659                "id": "GPL-2.0-or-later"
297660              }
297661            },
297662            {
297663              "license": {
297664                "id": "GPL-3.0-only"
297665              }
297666            },
297667            {
297668              "license": {
297669                "id": "GPL-3.0-or-later"
297670              }
297671            },
297672            {
297673              "license": {
297674                "id": "LGPL-2.1-only"
297675              }
297676            },
297677            {
297678              "license": {
297679                "id": "LGPL-2.1-or-later"
297680              }
297681            },
297682            {
297683              "license": {
297684                "name": "MIT-MINIMAL"
297685              }
297686            }
297687          ],
297688          "cpe": "cpe:2.3:a:liburcu6:liburcu6:0.11.1-2:*:*:*:*:*:*:*",
297689          "purl": "pkg:deb/ubuntu/liburcu6@0.11.1-2?arch=amd64\u0026upstream=liburcu\u0026distro=ubuntu-20.04",
297690          "swid": {
297691            "attachment": {}
297692          },
297693          "pedigree": {},
297694          "evidence": {},
297695          "signature": {
297696            "signature": {
297697              "publicKey": {}
297698            }
297699          },
297700          "modelCard": {
297701            "modelParameters": {
297702              "approach": {}
297703            },
297704            "quantitativeAnalysis": {
297705              "graphics": {}
297706            },
297707            "considerations": {}
297708          }
297709        },
297710        {
297711          "type": "library",
297712          "bom-ref": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=5395a07c00002ea6",
297713          "supplier": {},
297714          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297715          "name": "libuuid1",
297716          "version": "2.34-0.1ubuntu9.1",
297717          "licenses": [
297718            {
297719              "license": {
297720                "id": "BSD-2-Clause"
297721              }
297722            },
297723            {
297724              "license": {
297725                "id": "BSD-3-Clause"
297726              }
297727            },
297728            {
297729              "license": {
297730                "id": "BSD-4-Clause"
297731              }
297732            },
297733            {
297734              "license": {
297735                "id": "GPL-2.0-only"
297736              }
297737            },
297738            {
297739              "license": {
297740                "id": "GPL-2.0-or-later"
297741              }
297742            },
297743            {
297744              "license": {
297745                "id": "GPL-3.0-only"
297746              }
297747            },
297748            {
297749              "license": {
297750                "id": "GPL-3.0-or-later"
297751              }
297752            },
297753            {
297754              "license": {
297755                "name": "LGPL"
297756              }
297757            },
297758            {
297759              "license": {
297760                "id": "LGPL-2.0-only"
297761              }
297762            },
297763            {
297764              "license": {
297765                "id": "LGPL-2.0-or-later"
297766              }
297767            },
297768            {
297769              "license": {
297770                "id": "LGPL-2.1-only"
297771              }
297772            },
297773            {
297774              "license": {
297775                "id": "LGPL-2.1-or-later"
297776              }
297777            },
297778            {
297779              "license": {
297780                "id": "LGPL-3.0-only"
297781              }
297782            },
297783            {
297784              "license": {
297785                "id": "LGPL-3.0-or-later"
297786              }
297787            },
297788            {
297789              "license": {
297790                "id": "MIT"
297791              }
297792            },
297793            {
297794              "license": {
297795                "name": "public-domain"
297796              }
297797            }
297798          ],
297799          "cpe": "cpe:2.3:a:libuuid1:libuuid1:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
297800          "purl": "pkg:deb/ubuntu/libuuid1@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
297801          "swid": {
297802            "attachment": {}
297803          },
297804          "pedigree": {},
297805          "evidence": {},
297806          "signature": {
297807            "signature": {
297808              "publicKey": {}
297809            }
297810          },
297811          "modelCard": {
297812            "modelParameters": {
297813              "approach": {}
297814            },
297815            "quantitativeAnalysis": {
297816              "graphics": {}
297817            },
297818            "considerations": {}
297819          }
297820        },
297821        {
297822          "type": "library",
297823          "bom-ref": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04\u0026package-id=7b0e172efdb36a99",
297824          "supplier": {},
297825          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297826          "name": "libwind0-heimdal",
297827          "version": "7.7.0+dfsg-1ubuntu1",
297828          "licenses": [
297829            {
297830              "license": {
297831                "id": "BSD-3-Clause"
297832              }
297833            },
297834            {
297835              "license": {
297836                "id": "GPL-2.0-only"
297837              }
297838            },
297839            {
297840              "license": {
297841                "id": "GPL-2.0-or-later"
297842              }
297843            },
297844            {
297845              "license": {
297846                "name": "custom"
297847              }
297848            }
297849          ],
297850          "cpe": "cpe:2.3:a:libwind0-heimdal:libwind0-heimdal:7.7.0\\+dfsg-1ubuntu1:*:*:*:*:*:*:*",
297851          "purl": "pkg:deb/ubuntu/libwind0-heimdal@7.7.0+dfsg-1ubuntu1?arch=amd64\u0026upstream=heimdal\u0026distro=ubuntu-20.04",
297852          "swid": {
297853            "attachment": {}
297854          },
297855          "pedigree": {},
297856          "evidence": {},
297857          "signature": {
297858            "signature": {
297859              "publicKey": {}
297860            }
297861          },
297862          "modelCard": {
297863            "modelParameters": {
297864              "approach": {}
297865            },
297866            "quantitativeAnalysis": {
297867              "graphics": {}
297868            },
297869            "considerations": {}
297870          }
297871        },
297872        {
297873          "type": "library",
297874          "bom-ref": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04\u0026package-id=5b14391c61bb94f1",
297875          "supplier": {},
297876          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297877          "name": "libwrap0",
297878          "version": "7.6.q-30",
297879          "cpe": "cpe:2.3:a:libwrap0:libwrap0:7.6.q-30:*:*:*:*:*:*:*",
297880          "purl": "pkg:deb/ubuntu/libwrap0@7.6.q-30?arch=amd64\u0026upstream=tcp-wrappers\u0026distro=ubuntu-20.04",
297881          "swid": {
297882            "attachment": {}
297883          },
297884          "pedigree": {},
297885          "evidence": {},
297886          "signature": {
297887            "signature": {
297888              "publicKey": {}
297889            }
297890          },
297891          "modelCard": {
297892            "modelParameters": {
297893              "approach": {}
297894            },
297895            "quantitativeAnalysis": {
297896              "graphics": {}
297897            },
297898            "considerations": {}
297899          }
297900        },
297901        {
297902          "type": "library",
297903          "bom-ref": "pkg:deb/ubuntu/libx11-6@2:1.6.9-2ubuntu1.2?arch=amd64\u0026upstream=libx11\u0026distro=ubuntu-20.04\u0026package-id=50dc1220c10262c7",
297904          "supplier": {},
297905          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297906          "name": "libx11-6",
297907          "version": "2:1.6.9-2ubuntu1.2",
297908          "cpe": "cpe:2.3:a:libx11-6:libx11-6:2\\:1.6.9-2ubuntu1.2:*:*:*:*:*:*:*",
297909          "purl": "pkg:deb/ubuntu/libx11-6@2:1.6.9-2ubuntu1.2?arch=amd64\u0026upstream=libx11\u0026distro=ubuntu-20.04",
297910          "swid": {
297911            "attachment": {}
297912          },
297913          "pedigree": {},
297914          "evidence": {},
297915          "signature": {
297916            "signature": {
297917              "publicKey": {}
297918            }
297919          },
297920          "modelCard": {
297921            "modelParameters": {
297922              "approach": {}
297923            },
297924            "quantitativeAnalysis": {
297925              "graphics": {}
297926            },
297927            "considerations": {}
297928          }
297929        },
297930        {
297931          "type": "library",
297932          "bom-ref": "pkg:deb/ubuntu/libx11-data@2:1.6.9-2ubuntu1.2?arch=all\u0026upstream=libx11\u0026distro=ubuntu-20.04\u0026package-id=353f558ef0dbc884",
297933          "supplier": {},
297934          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297935          "name": "libx11-data",
297936          "version": "2:1.6.9-2ubuntu1.2",
297937          "cpe": "cpe:2.3:a:libx11-data:libx11-data:2\\:1.6.9-2ubuntu1.2:*:*:*:*:*:*:*",
297938          "purl": "pkg:deb/ubuntu/libx11-data@2:1.6.9-2ubuntu1.2?arch=all\u0026upstream=libx11\u0026distro=ubuntu-20.04",
297939          "swid": {
297940            "attachment": {}
297941          },
297942          "pedigree": {},
297943          "evidence": {},
297944          "signature": {
297945            "signature": {
297946              "publicKey": {}
297947            }
297948          },
297949          "modelCard": {
297950            "modelParameters": {
297951              "approach": {}
297952            },
297953            "quantitativeAnalysis": {
297954              "graphics": {}
297955            },
297956            "considerations": {}
297957          }
297958        },
297959        {
297960          "type": "library",
297961          "bom-ref": "pkg:deb/ubuntu/libxau6@1:1.0.9-0ubuntu1?arch=amd64\u0026upstream=libxau\u0026distro=ubuntu-20.04\u0026package-id=34dd47f551a496c4",
297962          "supplier": {},
297963          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297964          "name": "libxau6",
297965          "version": "1:1.0.9-0ubuntu1",
297966          "cpe": "cpe:2.3:a:libxau6:libxau6:1\\:1.0.9-0ubuntu1:*:*:*:*:*:*:*",
297967          "purl": "pkg:deb/ubuntu/libxau6@1:1.0.9-0ubuntu1?arch=amd64\u0026upstream=libxau\u0026distro=ubuntu-20.04",
297968          "swid": {
297969            "attachment": {}
297970          },
297971          "pedigree": {},
297972          "evidence": {},
297973          "signature": {
297974            "signature": {
297975              "publicKey": {}
297976            }
297977          },
297978          "modelCard": {
297979            "modelParameters": {
297980              "approach": {}
297981            },
297982            "quantitativeAnalysis": {
297983              "graphics": {}
297984            },
297985            "considerations": {}
297986          }
297987        },
297988        {
297989          "type": "library",
297990          "bom-ref": "pkg:deb/ubuntu/libxcb1@1.14-2?arch=amd64\u0026upstream=libxcb\u0026distro=ubuntu-20.04\u0026package-id=52f01a8807bc3bdf",
297991          "supplier": {},
297992          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
297993          "name": "libxcb1",
297994          "version": "1.14-2",
297995          "cpe": "cpe:2.3:a:libxcb1:libxcb1:1.14-2:*:*:*:*:*:*:*",
297996          "purl": "pkg:deb/ubuntu/libxcb1@1.14-2?arch=amd64\u0026upstream=libxcb\u0026distro=ubuntu-20.04",
297997          "swid": {
297998            "attachment": {}
297999          },
298000          "pedigree": {},
298001          "evidence": {},
298002          "signature": {
298003            "signature": {
298004              "publicKey": {}
298005            }
298006          },
298007          "modelCard": {
298008            "modelParameters": {
298009              "approach": {}
298010            },
298011            "quantitativeAnalysis": {
298012              "graphics": {}
298013            },
298014            "considerations": {}
298015          }
298016        },
298017        {
298018          "type": "library",
298019          "bom-ref": "pkg:deb/ubuntu/libxdmcp6@1:1.1.3-0ubuntu1?arch=amd64\u0026upstream=libxdmcp\u0026distro=ubuntu-20.04\u0026package-id=491fd9e95ef4ddf4",
298020          "supplier": {},
298021          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298022          "name": "libxdmcp6",
298023          "version": "1:1.1.3-0ubuntu1",
298024          "cpe": "cpe:2.3:a:libxdmcp6:libxdmcp6:1\\:1.1.3-0ubuntu1:*:*:*:*:*:*:*",
298025          "purl": "pkg:deb/ubuntu/libxdmcp6@1:1.1.3-0ubuntu1?arch=amd64\u0026upstream=libxdmcp\u0026distro=ubuntu-20.04",
298026          "swid": {
298027            "attachment": {}
298028          },
298029          "pedigree": {},
298030          "evidence": {},
298031          "signature": {
298032            "signature": {
298033              "publicKey": {}
298034            }
298035          },
298036          "modelCard": {
298037            "modelParameters": {
298038              "approach": {}
298039            },
298040            "quantitativeAnalysis": {
298041              "graphics": {}
298042            },
298043            "considerations": {}
298044          }
298045        },
298046        {
298047          "type": "library",
298048          "bom-ref": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04\u0026package-id=47cff0564e160066",
298049          "supplier": {},
298050          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298051          "name": "libzstd1",
298052          "version": "1.4.4+dfsg-3ubuntu0.1",
298053          "licenses": [
298054            {
298055              "license": {
298056                "id": "BSD-3-Clause"
298057              }
298058            },
298059            {
298060              "license": {
298061                "name": "Expat"
298062              }
298063            },
298064            {
298065              "license": {
298066                "id": "GPL-2.0-only"
298067              }
298068            },
298069            {
298070              "license": {
298071                "id": "GPL-2.0-or-later"
298072              }
298073            },
298074            {
298075              "license": {
298076                "id": "Zlib"
298077              }
298078            }
298079          ],
298080          "cpe": "cpe:2.3:a:libzstd1:libzstd1:1.4.4\\+dfsg-3ubuntu0.1:*:*:*:*:*:*:*",
298081          "purl": "pkg:deb/ubuntu/libzstd1@1.4.4+dfsg-3ubuntu0.1?arch=amd64\u0026upstream=libzstd\u0026distro=ubuntu-20.04",
298082          "swid": {
298083            "attachment": {}
298084          },
298085          "pedigree": {},
298086          "evidence": {},
298087          "signature": {
298088            "signature": {
298089              "publicKey": {}
298090            }
298091          },
298092          "modelCard": {
298093            "modelParameters": {
298094              "approach": {}
298095            },
298096            "quantitativeAnalysis": {
298097              "graphics": {}
298098            },
298099            "considerations": {}
298100          }
298101        },
298102        {
298103          "type": "library",
298104          "bom-ref": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=bb92db08e65352ae",
298105          "supplier": {},
298106          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298107          "name": "login",
298108          "version": "1:4.8.1-1ubuntu5.20.04",
298109          "licenses": [
298110            {
298111              "license": {
298112                "id": "GPL-2.0-only"
298113              }
298114            }
298115          ],
298116          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1ubuntu5.20.04:*:*:*:*:*:*:*",
298117          "purl": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
298118          "swid": {
298119            "attachment": {}
298120          },
298121          "pedigree": {},
298122          "evidence": {},
298123          "signature": {
298124            "signature": {
298125              "publicKey": {}
298126            }
298127          },
298128          "modelCard": {
298129            "modelParameters": {
298130              "approach": {}
298131            },
298132            "quantitativeAnalysis": {
298133              "graphics": {}
298134            },
298135            "considerations": {}
298136          }
298137        },
298138        {
298139          "type": "library",
298140          "bom-ref": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=cb23947502a7c38d",
298141          "supplier": {},
298142          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298143          "name": "login",
298144          "version": "1:4.8.1-1ubuntu5.20.04.1",
298145          "licenses": [
298146            {
298147              "license": {
298148                "id": "GPL-2.0-only"
298149              }
298150            }
298151          ],
298152          "cpe": "cpe:2.3:a:login:login:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
298153          "purl": "pkg:deb/ubuntu/login@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
298154          "swid": {
298155            "attachment": {}
298156          },
298157          "pedigree": {},
298158          "evidence": {},
298159          "signature": {
298160            "signature": {
298161              "publicKey": {}
298162            }
298163          },
298164          "modelCard": {
298165            "modelParameters": {
298166              "approach": {}
298167            },
298168            "quantitativeAnalysis": {
298169              "graphics": {}
298170            },
298171            "considerations": {}
298172          }
298173        },
298174        {
298175          "type": "library",
298176          "bom-ref": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04\u0026package-id=4a92556bee4b4f91",
298177          "supplier": {},
298178          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298179          "name": "logsave",
298180          "version": "1.45.5-2ubuntu1",
298181          "licenses": [
298182            {
298183              "license": {
298184                "id": "GPL-2.0-only"
298185              }
298186            },
298187            {
298188              "license": {
298189                "id": "LGPL-2.0-only"
298190              }
298191            }
298192          ],
298193          "cpe": "cpe:2.3:a:logsave:logsave:1.45.5-2ubuntu1:*:*:*:*:*:*:*",
298194          "purl": "pkg:deb/ubuntu/logsave@1.45.5-2ubuntu1?arch=amd64\u0026upstream=e2fsprogs\u0026distro=ubuntu-20.04",
298195          "swid": {
298196            "attachment": {}
298197          },
298198          "pedigree": {},
298199          "evidence": {},
298200          "signature": {
298201            "signature": {
298202              "publicKey": {}
298203            }
298204          },
298205          "modelCard": {
298206            "modelParameters": {
298207              "approach": {}
298208            },
298209            "quantitativeAnalysis": {
298210              "graphics": {}
298211            },
298212            "considerations": {}
298213          }
298214        },
298215        {
298216          "type": "library",
298217          "bom-ref": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04\u0026package-id=b76348b7f1282c61",
298218          "supplier": {},
298219          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298220          "name": "lsb-base",
298221          "version": "11.1.0ubuntu2",
298222          "licenses": [
298223            {
298224              "license": {
298225                "id": "BSD-3-Clause"
298226              }
298227            },
298228            {
298229              "license": {
298230                "id": "GPL-2.0-only"
298231              }
298232            }
298233          ],
298234          "cpe": "cpe:2.3:a:lsb-base:lsb-base:11.1.0ubuntu2:*:*:*:*:*:*:*",
298235          "purl": "pkg:deb/ubuntu/lsb-base@11.1.0ubuntu2?arch=all\u0026upstream=lsb\u0026distro=ubuntu-20.04",
298236          "swid": {
298237            "attachment": {}
298238          },
298239          "pedigree": {},
298240          "evidence": {},
298241          "signature": {
298242            "signature": {
298243              "publicKey": {}
298244            }
298245          },
298246          "modelCard": {
298247            "modelParameters": {
298248              "approach": {}
298249            },
298250            "quantitativeAnalysis": {
298251              "graphics": {}
298252            },
298253            "considerations": {}
298254          }
298255        },
298256        {
298257          "type": "library",
298258          "bom-ref": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=435885c82afbf721",
298259          "supplier": {},
298260          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298261          "name": "mawk",
298262          "version": "1.3.4.20200120-2",
298263          "licenses": [
298264            {
298265              "license": {
298266                "id": "GPL-2.0-only"
298267              }
298268            }
298269          ],
298270          "cpe": "cpe:2.3:a:mawk:mawk:1.3.4.20200120-2:*:*:*:*:*:*:*",
298271          "purl": "pkg:deb/ubuntu/mawk@1.3.4.20200120-2?arch=amd64\u0026distro=ubuntu-20.04",
298272          "swid": {
298273            "attachment": {}
298274          },
298275          "pedigree": {},
298276          "evidence": {},
298277          "signature": {
298278            "signature": {
298279              "publicKey": {}
298280            }
298281          },
298282          "modelCard": {
298283            "modelParameters": {
298284              "approach": {}
298285            },
298286            "quantitativeAnalysis": {
298287              "graphics": {}
298288            },
298289            "considerations": {}
298290          }
298291        },
298292        {
298293          "type": "library",
298294          "bom-ref": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=405891a224258a92",
298295          "supplier": {},
298296          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298297          "name": "mime-support",
298298          "version": "3.64ubuntu1",
298299          "licenses": [
298300            {
298301              "license": {
298302                "name": "Bellcore"
298303              }
298304            },
298305            {
298306              "license": {
298307                "name": "ad-hoc"
298308              }
298309            }
298310          ],
298311          "cpe": "cpe:2.3:a:mime-support:mime-support:3.64ubuntu1:*:*:*:*:*:*:*",
298312          "purl": "pkg:deb/ubuntu/mime-support@3.64ubuntu1?arch=all\u0026distro=ubuntu-20.04",
298313          "swid": {
298314            "attachment": {}
298315          },
298316          "pedigree": {},
298317          "evidence": {},
298318          "signature": {
298319            "signature": {
298320              "publicKey": {}
298321            }
298322          },
298323          "modelCard": {
298324            "modelParameters": {
298325              "approach": {}
298326            },
298327            "quantitativeAnalysis": {
298328              "graphics": {}
298329            },
298330            "considerations": {}
298331          }
298332        },
298333        {
298334          "type": "library",
298335          "bom-ref": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04\u0026package-id=fa4ef6b12af7900c",
298336          "supplier": {},
298337          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298338          "name": "mount",
298339          "version": "2.34-0.1ubuntu9.1",
298340          "licenses": [
298341            {
298342              "license": {
298343                "id": "BSD-2-Clause"
298344              }
298345            },
298346            {
298347              "license": {
298348                "id": "BSD-3-Clause"
298349              }
298350            },
298351            {
298352              "license": {
298353                "id": "BSD-4-Clause"
298354              }
298355            },
298356            {
298357              "license": {
298358                "id": "GPL-2.0-only"
298359              }
298360            },
298361            {
298362              "license": {
298363                "id": "GPL-2.0-or-later"
298364              }
298365            },
298366            {
298367              "license": {
298368                "id": "GPL-3.0-only"
298369              }
298370            },
298371            {
298372              "license": {
298373                "id": "GPL-3.0-or-later"
298374              }
298375            },
298376            {
298377              "license": {
298378                "name": "LGPL"
298379              }
298380            },
298381            {
298382              "license": {
298383                "id": "LGPL-2.0-only"
298384              }
298385            },
298386            {
298387              "license": {
298388                "id": "LGPL-2.0-or-later"
298389              }
298390            },
298391            {
298392              "license": {
298393                "id": "LGPL-2.1-only"
298394              }
298395            },
298396            {
298397              "license": {
298398                "id": "LGPL-2.1-or-later"
298399              }
298400            },
298401            {
298402              "license": {
298403                "id": "LGPL-3.0-only"
298404              }
298405            },
298406            {
298407              "license": {
298408                "id": "LGPL-3.0-or-later"
298409              }
298410            },
298411            {
298412              "license": {
298413                "id": "MIT"
298414              }
298415            },
298416            {
298417              "license": {
298418                "name": "public-domain"
298419              }
298420            }
298421          ],
298422          "cpe": "cpe:2.3:a:mount:mount:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
298423          "purl": "pkg:deb/ubuntu/mount@2.34-0.1ubuntu9.1?arch=amd64\u0026upstream=util-linux\u0026distro=ubuntu-20.04",
298424          "swid": {
298425            "attachment": {}
298426          },
298427          "pedigree": {},
298428          "evidence": {},
298429          "signature": {
298430            "signature": {
298431              "publicKey": {}
298432            }
298433          },
298434          "modelCard": {
298435            "modelParameters": {
298436              "approach": {}
298437            },
298438            "quantitativeAnalysis": {
298439              "graphics": {}
298440            },
298441            "considerations": {}
298442          }
298443        },
298444        {
298445          "type": "library",
298446          "bom-ref": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d7393defd95e4554",
298447          "supplier": {},
298448          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298449          "name": "ncurses-base",
298450          "version": "6.2-0ubuntu2",
298451          "cpe": "cpe:2.3:a:ncurses-base:ncurses-base:6.2-0ubuntu2:*:*:*:*:*:*:*",
298452          "purl": "pkg:deb/ubuntu/ncurses-base@6.2-0ubuntu2?arch=all\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
298453          "swid": {
298454            "attachment": {}
298455          },
298456          "pedigree": {},
298457          "evidence": {},
298458          "signature": {
298459            "signature": {
298460              "publicKey": {}
298461            }
298462          },
298463          "modelCard": {
298464            "modelParameters": {
298465              "approach": {}
298466            },
298467            "quantitativeAnalysis": {
298468              "graphics": {}
298469            },
298470            "considerations": {}
298471          }
298472        },
298473        {
298474          "type": "library",
298475          "bom-ref": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04\u0026package-id=d6bdd43961b680f6",
298476          "supplier": {},
298477          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298478          "name": "ncurses-bin",
298479          "version": "6.2-0ubuntu2",
298480          "cpe": "cpe:2.3:a:ncurses-bin:ncurses-bin:6.2-0ubuntu2:*:*:*:*:*:*:*",
298481          "purl": "pkg:deb/ubuntu/ncurses-bin@6.2-0ubuntu2?arch=amd64\u0026upstream=ncurses\u0026distro=ubuntu-20.04",
298482          "swid": {
298483            "attachment": {}
298484          },
298485          "pedigree": {},
298486          "evidence": {},
298487          "signature": {
298488            "signature": {
298489              "publicKey": {}
298490            }
298491          },
298492          "modelCard": {
298493            "modelParameters": {
298494              "approach": {}
298495            },
298496            "quantitativeAnalysis": {
298497              "graphics": {}
298498            },
298499            "considerations": {}
298500          }
298501        },
298502        {
298503          "type": "library",
298504          "bom-ref": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04\u0026package-id=6a00c331080f32b7",
298505          "supplier": {},
298506          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298507          "name": "nfs-common",
298508          "version": "1:1.3.4-2.5ubuntu3.4",
298509          "licenses": [
298510            {
298511              "license": {
298512                "id": "GPL-2.0-only"
298513              }
298514            }
298515          ],
298516          "cpe": "cpe:2.3:a:nfs-common:nfs-common:1\\:1.3.4-2.5ubuntu3.4:*:*:*:*:*:*:*",
298517          "purl": "pkg:deb/ubuntu/nfs-common@1:1.3.4-2.5ubuntu3.4?arch=amd64\u0026upstream=nfs-utils\u0026distro=ubuntu-20.04",
298518          "swid": {
298519            "attachment": {}
298520          },
298521          "pedigree": {},
298522          "evidence": {},
298523          "signature": {
298524            "signature": {
298525              "publicKey": {}
298526            }
298527          },
298528          "modelCard": {
298529            "modelParameters": {
298530              "approach": {}
298531            },
298532            "quantitativeAnalysis": {
298533              "graphics": {}
298534            },
298535            "considerations": {}
298536          }
298537        },
298538        {
298539          "type": "library",
298540          "bom-ref": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=d99390960eea7b3e",
298541          "supplier": {},
298542          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298543          "name": "passwd",
298544          "version": "1:4.8.1-1ubuntu5.20.04",
298545          "licenses": [
298546            {
298547              "license": {
298548                "id": "GPL-2.0-only"
298549              }
298550            }
298551          ],
298552          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1ubuntu5.20.04:*:*:*:*:*:*:*",
298553          "purl": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
298554          "swid": {
298555            "attachment": {}
298556          },
298557          "pedigree": {},
298558          "evidence": {},
298559          "signature": {
298560            "signature": {
298561              "publicKey": {}
298562            }
298563          },
298564          "modelCard": {
298565            "modelParameters": {
298566              "approach": {}
298567            },
298568            "quantitativeAnalysis": {
298569              "graphics": {}
298570            },
298571            "considerations": {}
298572          }
298573        },
298574        {
298575          "type": "library",
298576          "bom-ref": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04\u0026package-id=c4a1ed5267891532",
298577          "supplier": {},
298578          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298579          "name": "passwd",
298580          "version": "1:4.8.1-1ubuntu5.20.04.1",
298581          "licenses": [
298582            {
298583              "license": {
298584                "id": "GPL-2.0-only"
298585              }
298586            }
298587          ],
298588          "cpe": "cpe:2.3:a:passwd:passwd:1\\:4.8.1-1ubuntu5.20.04.1:*:*:*:*:*:*:*",
298589          "purl": "pkg:deb/ubuntu/passwd@1:4.8.1-1ubuntu5.20.04.1?arch=amd64\u0026upstream=shadow\u0026distro=ubuntu-20.04",
298590          "swid": {
298591            "attachment": {}
298592          },
298593          "pedigree": {},
298594          "evidence": {},
298595          "signature": {
298596            "signature": {
298597              "publicKey": {}
298598            }
298599          },
298600          "modelCard": {
298601            "modelParameters": {
298602              "approach": {}
298603            },
298604            "quantitativeAnalysis": {
298605              "graphics": {}
298606            },
298607            "considerations": {}
298608          }
298609        },
298610        {
298611          "type": "library",
298612          "bom-ref": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04\u0026package-id=eab1752e76cf29f",
298613          "supplier": {},
298614          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298615          "name": "perl-base",
298616          "version": "5.30.0-9ubuntu0.2",
298617          "licenses": [
298618            {
298619              "license": {
298620                "name": "Artistic"
298621              }
298622            },
298623            {
298624              "license": {
298625                "id": "Artistic-2.0"
298626              }
298627            },
298628            {
298629              "license": {
298630                "name": "Artistic-dist"
298631              }
298632            },
298633            {
298634              "license": {
298635                "id": "BSD-3-Clause"
298636              }
298637            },
298638            {
298639              "license": {
298640                "name": "BSD-3-clause-GENERIC"
298641              }
298642            },
298643            {
298644              "license": {
298645                "name": "BSD-3-clause-with-weird-numbering"
298646              }
298647            },
298648            {
298649              "license": {
298650                "name": "BSD-4-clause-POWERDOG"
298651              }
298652            },
298653            {
298654              "license": {
298655                "name": "BZIP"
298656              }
298657            },
298658            {
298659              "license": {
298660                "name": "DONT-CHANGE-THE-GPL"
298661              }
298662            },
298663            {
298664              "license": {
298665                "name": "Expat"
298666              }
298667            },
298668            {
298669              "license": {
298670                "id": "GPL-1.0-only"
298671              }
298672            },
298673            {
298674              "license": {
298675                "id": "GPL-1.0-or-later"
298676              }
298677            },
298678            {
298679              "license": {
298680                "id": "GPL-2.0-only"
298681              }
298682            },
298683            {
298684              "license": {
298685                "id": "GPL-2.0-or-later"
298686              }
298687            },
298688            {
298689              "license": {
298690                "name": "GPL-3+-WITH-BISON-EXCEPTION"
298691              }
298692            },
298693            {
298694              "license": {
298695                "name": "HSIEH-BSD"
298696              }
298697            },
298698            {
298699              "license": {
298700                "name": "HSIEH-DERIVATIVE"
298701              }
298702            },
298703            {
298704              "license": {
298705                "id": "LGPL-2.1-only"
298706              }
298707            },
298708            {
298709              "license": {
298710                "name": "REGCOMP"
298711              }
298712            },
298713            {
298714              "license": {
298715                "name": "REGCOMP,"
298716              }
298717            },
298718            {
298719              "license": {
298720                "name": "RRA-KEEP-THIS-NOTICE"
298721              }
298722            },
298723            {
298724              "license": {
298725                "name": "SDBM-PUBLIC-DOMAIN"
298726              }
298727            },
298728            {
298729              "license": {
298730                "name": "TEXT-TABS"
298731              }
298732            },
298733            {
298734              "license": {
298735                "name": "Unicode"
298736              }
298737            },
298738            {
298739              "license": {
298740                "id": "Zlib"
298741              }
298742            }
298743          ],
298744          "cpe": "cpe:2.3:a:perl-base:perl-base:5.30.0-9ubuntu0.2:*:*:*:*:*:*:*",
298745          "purl": "pkg:deb/ubuntu/perl-base@5.30.0-9ubuntu0.2?arch=amd64\u0026upstream=perl\u0026distro=ubuntu-20.04",
298746          "swid": {
298747            "attachment": {}
298748          },
298749          "pedigree": {},
298750          "evidence": {},
298751          "signature": {
298752            "signature": {
298753              "publicKey": {}
298754            }
298755          },
298756          "modelCard": {
298757            "modelParameters": {
298758              "approach": {}
298759            },
298760            "quantitativeAnalysis": {
298761              "graphics": {}
298762            },
298763            "considerations": {}
298764          }
298765        },
298766        {
298767          "type": "library",
298768          "bom-ref": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=f177d21a50776ea7",
298769          "supplier": {},
298770          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298771          "name": "procps",
298772          "version": "2:3.3.16-1ubuntu2.2",
298773          "licenses": [
298774            {
298775              "license": {
298776                "id": "GPL-2.0-only"
298777              }
298778            },
298779            {
298780              "license": {
298781                "id": "GPL-2.0-or-later"
298782              }
298783            },
298784            {
298785              "license": {
298786                "id": "LGPL-2.0-only"
298787              }
298788            },
298789            {
298790              "license": {
298791                "id": "LGPL-2.0-or-later"
298792              }
298793            },
298794            {
298795              "license": {
298796                "id": "LGPL-2.1-only"
298797              }
298798            },
298799            {
298800              "license": {
298801                "id": "LGPL-2.1-or-later"
298802              }
298803            }
298804          ],
298805          "cpe": "cpe:2.3:a:procps:procps:2\\:3.3.16-1ubuntu2.2:*:*:*:*:*:*:*",
298806          "purl": "pkg:deb/ubuntu/procps@2:3.3.16-1ubuntu2.2?arch=amd64\u0026distro=ubuntu-20.04",
298807          "swid": {
298808            "attachment": {}
298809          },
298810          "pedigree": {},
298811          "evidence": {},
298812          "signature": {
298813            "signature": {
298814              "publicKey": {}
298815            }
298816          },
298817          "modelCard": {
298818            "modelParameters": {
298819              "approach": {}
298820            },
298821            "quantitativeAnalysis": {
298822              "graphics": {}
298823            },
298824            "considerations": {}
298825          }
298826        },
298827        {
298828          "type": "application",
298829          "bom-ref": "pkg:generic/python@3.8.10?package-id=6a7506a1082aa1fd",
298830          "supplier": {},
298831          "name": "python",
298832          "version": "3.8.10",
298833          "cpe": "cpe:2.3:a:python_software_foundation:python:3.8.10:*:*:*:*:*:*:*",
298834          "purl": "pkg:generic/python@3.8.10",
298835          "swid": {
298836            "attachment": {}
298837          },
298838          "pedigree": {},
298839          "evidence": {},
298840          "signature": {
298841            "signature": {
298842              "publicKey": {}
298843            }
298844          },
298845          "modelCard": {
298846            "modelParameters": {
298847              "approach": {}
298848            },
298849            "quantitativeAnalysis": {
298850              "graphics": {}
298851            },
298852            "considerations": {}
298853          }
298854        },
298855        {
298856          "type": "library",
298857          "bom-ref": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=ca939acbf264771",
298858          "supplier": {},
298859          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298860          "name": "python3",
298861          "version": "3.8.2-0ubuntu2",
298862          "cpe": "cpe:2.3:a:python3:python3:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
298863          "purl": "pkg:deb/ubuntu/python3@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
298864          "swid": {
298865            "attachment": {}
298866          },
298867          "pedigree": {},
298868          "evidence": {},
298869          "signature": {
298870            "signature": {
298871              "publicKey": {}
298872            }
298873          },
298874          "modelCard": {
298875            "modelParameters": {
298876              "approach": {}
298877            },
298878            "quantitativeAnalysis": {
298879              "graphics": {}
298880            },
298881            "considerations": {}
298882          }
298883        },
298884        {
298885          "type": "library",
298886          "bom-ref": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04\u0026package-id=26eebf392e0b02cf",
298887          "supplier": {},
298888          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298889          "name": "python3-minimal",
298890          "version": "3.8.2-0ubuntu2",
298891          "cpe": "cpe:2.3:a:python3-minimal:python3-minimal:3.8.2-0ubuntu2:*:*:*:*:*:*:*",
298892          "purl": "pkg:deb/ubuntu/python3-minimal@3.8.2-0ubuntu2?arch=amd64\u0026upstream=python3-defaults\u0026distro=ubuntu-20.04",
298893          "swid": {
298894            "attachment": {}
298895          },
298896          "pedigree": {},
298897          "evidence": {},
298898          "signature": {
298899            "signature": {
298900              "publicKey": {}
298901            }
298902          },
298903          "modelCard": {
298904            "modelParameters": {
298905              "approach": {}
298906            },
298907            "quantitativeAnalysis": {
298908              "graphics": {}
298909            },
298910            "considerations": {}
298911          }
298912        },
298913        {
298914          "type": "library",
298915          "bom-ref": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=b1de928401abc554",
298916          "supplier": {},
298917          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298918          "name": "python3.8",
298919          "version": "3.8.10-0ubuntu1~20.04",
298920          "licenses": [
298921            {
298922              "license": {
298923                "name": "By"
298924              }
298925            },
298926            {
298927              "license": {
298928                "id": "GPL-2.0-only"
298929              }
298930            },
298931            {
298932              "license": {
298933                "name": "Permission"
298934              }
298935            },
298936            {
298937              "license": {
298938                "name": "Redistribution"
298939              }
298940            },
298941            {
298942              "license": {
298943                "name": "This"
298944              }
298945            }
298946          ],
298947          "cpe": "cpe:2.3:a:python3.8:python3.8:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
298948          "purl": "pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04?arch=amd64\u0026distro=ubuntu-20.04",
298949          "swid": {
298950            "attachment": {}
298951          },
298952          "pedigree": {},
298953          "evidence": {},
298954          "signature": {
298955            "signature": {
298956              "publicKey": {}
298957            }
298958          },
298959          "modelCard": {
298960            "modelParameters": {
298961              "approach": {}
298962            },
298963            "quantitativeAnalysis": {
298964              "graphics": {}
298965            },
298966            "considerations": {}
298967          }
298968        },
298969        {
298970          "type": "library",
298971          "bom-ref": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04\u0026package-id=91fa2bead1762d08",
298972          "supplier": {},
298973          "publisher": "Ubuntu Core Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
298974          "name": "python3.8-minimal",
298975          "version": "3.8.10-0ubuntu1~20.04",
298976          "licenses": [
298977            {
298978              "license": {
298979                "name": "By"
298980              }
298981            },
298982            {
298983              "license": {
298984                "id": "GPL-2.0-only"
298985              }
298986            },
298987            {
298988              "license": {
298989                "name": "Permission"
298990              }
298991            },
298992            {
298993              "license": {
298994                "name": "Redistribution"
298995              }
298996            },
298997            {
298998              "license": {
298999                "name": "This"
299000              }
299001            }
299002          ],
299003          "cpe": "cpe:2.3:a:python3.8-minimal:python3.8-minimal:3.8.10-0ubuntu1\\~20.04:*:*:*:*:*:*:*",
299004          "purl": "pkg:deb/ubuntu/python3.8-minimal@3.8.10-0ubuntu1~20.04?arch=amd64\u0026upstream=python3.8\u0026distro=ubuntu-20.04",
299005          "swid": {
299006            "attachment": {}
299007          },
299008          "pedigree": {},
299009          "evidence": {},
299010          "signature": {
299011            "signature": {
299012              "publicKey": {}
299013            }
299014          },
299015          "modelCard": {
299016            "modelParameters": {
299017              "approach": {}
299018            },
299019            "quantitativeAnalysis": {
299020              "graphics": {}
299021            },
299022            "considerations": {}
299023          }
299024        },
299025        {
299026          "type": "library",
299027          "bom-ref": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04\u0026package-id=34a85b4423ecbe7",
299028          "supplier": {},
299029          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299030          "name": "readline-common",
299031          "version": "8.0-4",
299032          "licenses": [
299033            {
299034              "license": {
299035                "name": "GFDL"
299036              }
299037            },
299038            {
299039              "license": {
299040                "id": "GPL-3.0-only"
299041              }
299042            }
299043          ],
299044          "cpe": "cpe:2.3:a:readline-common:readline-common:8.0-4:*:*:*:*:*:*:*",
299045          "purl": "pkg:deb/ubuntu/readline-common@8.0-4?arch=all\u0026upstream=readline\u0026distro=ubuntu-20.04",
299046          "swid": {
299047            "attachment": {}
299048          },
299049          "pedigree": {},
299050          "evidence": {},
299051          "signature": {
299052            "signature": {
299053              "publicKey": {}
299054            }
299055          },
299056          "modelCard": {
299057            "modelParameters": {
299058              "approach": {}
299059            },
299060            "quantitativeAnalysis": {
299061              "graphics": {}
299062            },
299063            "considerations": {}
299064          }
299065        },
299066        {
299067          "type": "library",
299068          "bom-ref": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=e98d3334085e4495",
299069          "supplier": {},
299070          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299071          "name": "rpcbind",
299072          "version": "1.2.5-8",
299073          "licenses": [
299074            {
299075              "license": {
299076                "id": "BSD-3-Clause"
299077              }
299078            },
299079            {
299080              "license": {
299081                "id": "BSD-4-Clause"
299082              }
299083            },
299084            {
299085              "license": {
299086                "id": "BSD-4-Clause"
299087              }
299088            },
299089            {
299090              "license": {
299091                "id": "GPL-2.0-only"
299092              }
299093            },
299094            {
299095              "license": {
299096                "id": "GPL-2.0-or-later"
299097              }
299098            },
299099            {
299100              "license": {
299101                "id": "GPL-3.0-only"
299102              }
299103            },
299104            {
299105              "license": {
299106                "id": "MIT"
299107              }
299108            },
299109            {
299110              "license": {
299111                "name": "PERMISSIVE"
299112              }
299113            }
299114          ],
299115          "cpe": "cpe:2.3:a:rpcbind:rpcbind:1.2.5-8:*:*:*:*:*:*:*",
299116          "purl": "pkg:deb/ubuntu/rpcbind@1.2.5-8?arch=amd64\u0026distro=ubuntu-20.04",
299117          "swid": {
299118            "attachment": {}
299119          },
299120          "pedigree": {},
299121          "evidence": {},
299122          "signature": {
299123            "signature": {
299124              "publicKey": {}
299125            }
299126          },
299127          "modelCard": {
299128            "modelParameters": {
299129              "approach": {}
299130            },
299131            "quantitativeAnalysis": {
299132              "graphics": {}
299133            },
299134            "considerations": {}
299135          }
299136        },
299137        {
299138          "type": "library",
299139          "bom-ref": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=24bbb8989a1870c7",
299140          "supplier": {},
299141          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299142          "name": "sed",
299143          "version": "4.7-1",
299144          "licenses": [
299145            {
299146              "license": {
299147                "id": "GPL-3.0-only"
299148              }
299149            }
299150          ],
299151          "cpe": "cpe:2.3:a:sed:sed:4.7-1:*:*:*:*:*:*:*",
299152          "purl": "pkg:deb/ubuntu/sed@4.7-1?arch=amd64\u0026distro=ubuntu-20.04",
299153          "swid": {
299154            "attachment": {}
299155          },
299156          "pedigree": {},
299157          "evidence": {},
299158          "signature": {
299159            "signature": {
299160              "publicKey": {}
299161            }
299162          },
299163          "modelCard": {
299164            "modelParameters": {
299165              "approach": {}
299166            },
299167            "quantitativeAnalysis": {
299168              "graphics": {}
299169            },
299170            "considerations": {}
299171          }
299172        },
299173        {
299174          "type": "library",
299175          "bom-ref": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=7e50cf6ac335106e",
299176          "supplier": {},
299177          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299178          "name": "sensible-utils",
299179          "version": "0.0.12+nmu1",
299180          "licenses": [
299181            {
299182              "license": {
299183                "name": "All-permissive"
299184              }
299185            },
299186            {
299187              "license": {
299188                "id": "GPL-2.0-only"
299189              }
299190            },
299191            {
299192              "license": {
299193                "id": "GPL-2.0-or-later"
299194              }
299195            },
299196            {
299197              "license": {
299198                "name": "configure"
299199              }
299200            },
299201            {
299202              "license": {
299203                "name": "installsh"
299204              }
299205            }
299206          ],
299207          "cpe": "cpe:2.3:a:sensible-utils:sensible-utils:0.0.12\\+nmu1:*:*:*:*:*:*:*",
299208          "purl": "pkg:deb/ubuntu/sensible-utils@0.0.12+nmu1?arch=all\u0026distro=ubuntu-20.04",
299209          "swid": {
299210            "attachment": {}
299211          },
299212          "pedigree": {},
299213          "evidence": {},
299214          "signature": {
299215            "signature": {
299216              "publicKey": {}
299217            }
299218          },
299219          "modelCard": {
299220            "modelParameters": {
299221              "approach": {}
299222            },
299223            "quantitativeAnalysis": {
299224              "graphics": {}
299225            },
299226            "considerations": {}
299227          }
299228        },
299229        {
299230          "type": "library",
299231          "bom-ref": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04\u0026package-id=abc451774789c392",
299232          "supplier": {},
299233          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299234          "name": "sysvinit-utils",
299235          "version": "2.96-2.1ubuntu1",
299236          "licenses": [
299237            {
299238              "license": {
299239                "id": "GPL-2.0-only"
299240              }
299241            },
299242            {
299243              "license": {
299244                "id": "GPL-2.0-or-later"
299245              }
299246            }
299247          ],
299248          "cpe": "cpe:2.3:a:sysvinit-utils:sysvinit-utils:2.96-2.1ubuntu1:*:*:*:*:*:*:*",
299249          "purl": "pkg:deb/ubuntu/sysvinit-utils@2.96-2.1ubuntu1?arch=amd64\u0026upstream=sysvinit\u0026distro=ubuntu-20.04",
299250          "swid": {
299251            "attachment": {}
299252          },
299253          "pedigree": {},
299254          "evidence": {},
299255          "signature": {
299256            "signature": {
299257              "publicKey": {}
299258            }
299259          },
299260          "modelCard": {
299261            "modelParameters": {
299262              "approach": {}
299263            },
299264            "quantitativeAnalysis": {
299265              "graphics": {}
299266            },
299267            "considerations": {}
299268          }
299269        },
299270        {
299271          "type": "library",
299272          "bom-ref": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=4c6cd0d17cc842e",
299273          "supplier": {},
299274          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299275          "name": "tar",
299276          "version": "1.30+dfsg-7ubuntu0.20.04.1",
299277          "licenses": [
299278            {
299279              "license": {
299280                "id": "GPL-2.0-only"
299281              }
299282            },
299283            {
299284              "license": {
299285                "id": "GPL-3.0-only"
299286              }
299287            }
299288          ],
299289          "cpe": "cpe:2.3:a:tar:tar:1.30\\+dfsg-7ubuntu0.20.04.1:*:*:*:*:*:*:*",
299290          "purl": "pkg:deb/ubuntu/tar@1.30+dfsg-7ubuntu0.20.04.1?arch=amd64\u0026distro=ubuntu-20.04",
299291          "swid": {
299292            "attachment": {}
299293          },
299294          "pedigree": {},
299295          "evidence": {},
299296          "signature": {
299297            "signature": {
299298              "publicKey": {}
299299            }
299300          },
299301          "modelCard": {
299302            "modelParameters": {
299303              "approach": {}
299304            },
299305            "quantitativeAnalysis": {
299306              "graphics": {}
299307            },
299308            "considerations": {}
299309          }
299310        },
299311        {
299312          "type": "library",
299313          "bom-ref": "pkg:deb/ubuntu/tzdata@2021a-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04\u0026package-id=aaae4a94d26494c0",
299314          "supplier": {},
299315          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299316          "name": "tzdata",
299317          "version": "2021a-0ubuntu0.20.04",
299318          "licenses": [
299319            {
299320              "license": {
299321                "id": "ICU"
299322              }
299323            }
299324          ],
299325          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0ubuntu0.20.04:*:*:*:*:*:*:*",
299326          "purl": "pkg:deb/ubuntu/tzdata@2021a-0ubuntu0.20.04?arch=all\u0026distro=ubuntu-20.04",
299327          "swid": {
299328            "attachment": {}
299329          },
299330          "pedigree": {},
299331          "evidence": {},
299332          "signature": {
299333            "signature": {
299334              "publicKey": {}
299335            }
299336          },
299337          "modelCard": {
299338            "modelParameters": {
299339              "approach": {}
299340            },
299341            "quantitativeAnalysis": {
299342              "graphics": {}
299343            },
299344            "considerations": {}
299345          }
299346        },
299347        {
299348          "type": "library",
299349          "bom-ref": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04\u0026package-id=6d2b18ebcbe1dab7",
299350          "supplier": {},
299351          "publisher": "Dimitri John Ledkov \u003cdimitri.ledkov@canonical.com\u003e",
299352          "name": "ubuntu-keyring",
299353          "version": "2020.02.11.4",
299354          "licenses": [
299355            {
299356              "license": {
299357                "name": "GPL"
299358              }
299359            }
299360          ],
299361          "cpe": "cpe:2.3:a:ubuntu-keyring:ubuntu-keyring:2020.02.11.4:*:*:*:*:*:*:*",
299362          "purl": "pkg:deb/ubuntu/ubuntu-keyring@2020.02.11.4?arch=all\u0026distro=ubuntu-20.04",
299363          "swid": {
299364            "attachment": {}
299365          },
299366          "pedigree": {},
299367          "evidence": {},
299368          "signature": {
299369            "signature": {
299370              "publicKey": {}
299371            }
299372          },
299373          "modelCard": {
299374            "modelParameters": {
299375              "approach": {}
299376            },
299377            "quantitativeAnalysis": {
299378              "graphics": {}
299379            },
299380            "considerations": {}
299381          }
299382        },
299383        {
299384          "type": "library",
299385          "bom-ref": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04\u0026package-id=ab3b8cc8be7b5655",
299386          "supplier": {},
299387          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299388          "name": "ucf",
299389          "version": "3.0038+nmu1",
299390          "licenses": [
299391            {
299392              "license": {
299393                "id": "GPL-2.0-only"
299394              }
299395            }
299396          ],
299397          "cpe": "cpe:2.3:a:ucf:ucf:3.0038\\+nmu1:*:*:*:*:*:*:*",
299398          "purl": "pkg:deb/ubuntu/ucf@3.0038+nmu1?arch=all\u0026distro=ubuntu-20.04",
299399          "swid": {
299400            "attachment": {}
299401          },
299402          "pedigree": {},
299403          "evidence": {},
299404          "signature": {
299405            "signature": {
299406              "publicKey": {}
299407            }
299408          },
299409          "modelCard": {
299410            "modelParameters": {
299411              "approach": {}
299412            },
299413            "quantitativeAnalysis": {
299414              "graphics": {}
299415            },
299416            "considerations": {}
299417          }
299418        },
299419        {
299420          "type": "library",
299421          "bom-ref": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=33e86bd94ef763b6",
299422          "supplier": {},
299423          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299424          "name": "util-linux",
299425          "version": "2.34-0.1ubuntu9.1",
299426          "licenses": [
299427            {
299428              "license": {
299429                "id": "BSD-2-Clause"
299430              }
299431            },
299432            {
299433              "license": {
299434                "id": "BSD-3-Clause"
299435              }
299436            },
299437            {
299438              "license": {
299439                "id": "BSD-4-Clause"
299440              }
299441            },
299442            {
299443              "license": {
299444                "id": "GPL-2.0-only"
299445              }
299446            },
299447            {
299448              "license": {
299449                "id": "GPL-2.0-or-later"
299450              }
299451            },
299452            {
299453              "license": {
299454                "id": "GPL-3.0-only"
299455              }
299456            },
299457            {
299458              "license": {
299459                "id": "GPL-3.0-or-later"
299460              }
299461            },
299462            {
299463              "license": {
299464                "name": "LGPL"
299465              }
299466            },
299467            {
299468              "license": {
299469                "id": "LGPL-2.0-only"
299470              }
299471            },
299472            {
299473              "license": {
299474                "id": "LGPL-2.0-or-later"
299475              }
299476            },
299477            {
299478              "license": {
299479                "id": "LGPL-2.1-only"
299480              }
299481            },
299482            {
299483              "license": {
299484                "id": "LGPL-2.1-or-later"
299485              }
299486            },
299487            {
299488              "license": {
299489                "id": "LGPL-3.0-only"
299490              }
299491            },
299492            {
299493              "license": {
299494                "id": "LGPL-3.0-or-later"
299495              }
299496            },
299497            {
299498              "license": {
299499                "id": "MIT"
299500              }
299501            },
299502            {
299503              "license": {
299504                "name": "public-domain"
299505              }
299506            }
299507          ],
299508          "cpe": "cpe:2.3:a:util-linux:util-linux:2.34-0.1ubuntu9.1:*:*:*:*:*:*:*",
299509          "purl": "pkg:deb/ubuntu/util-linux@2.34-0.1ubuntu9.1?arch=amd64\u0026distro=ubuntu-20.04",
299510          "swid": {
299511            "attachment": {}
299512          },
299513          "pedigree": {},
299514          "evidence": {},
299515          "signature": {
299516            "signature": {
299517              "publicKey": {}
299518            }
299519          },
299520          "modelCard": {
299521            "modelParameters": {
299522              "approach": {}
299523            },
299524            "quantitativeAnalysis": {
299525              "graphics": {}
299526            },
299527            "considerations": {}
299528          }
299529        },
299530        {
299531          "type": "library",
299532          "bom-ref": "pkg:deb/ubuntu/xfsprogs@5.3.0-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=bbefdc57cc2f7b90",
299533          "supplier": {},
299534          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299535          "name": "xfsprogs",
299536          "version": "5.3.0-1ubuntu2",
299537          "licenses": [
299538            {
299539              "license": {
299540                "name": "GPL"
299541              }
299542            },
299543            {
299544              "license": {
299545                "id": "LGPL-2.1-only"
299546              }
299547            }
299548          ],
299549          "cpe": "cpe:2.3:a:xfsprogs:xfsprogs:5.3.0-1ubuntu2:*:*:*:*:*:*:*",
299550          "purl": "pkg:deb/ubuntu/xfsprogs@5.3.0-1ubuntu2?arch=amd64\u0026distro=ubuntu-20.04",
299551          "swid": {
299552            "attachment": {}
299553          },
299554          "pedigree": {},
299555          "evidence": {},
299556          "signature": {
299557            "signature": {
299558              "publicKey": {}
299559            }
299560          },
299561          "modelCard": {
299562            "modelParameters": {
299563              "approach": {}
299564            },
299565            "quantitativeAnalysis": {
299566              "graphics": {}
299567            },
299568            "considerations": {}
299569          }
299570        },
299571        {
299572          "type": "library",
299573          "bom-ref": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04\u0026package-id=46271b3ba3de19b6",
299574          "supplier": {},
299575          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299576          "name": "xz-utils",
299577          "version": "5.2.4-1ubuntu1",
299578          "licenses": [
299579            {
299580              "license": {
299581                "name": "Autoconf"
299582              }
299583            },
299584            {
299585              "license": {
299586                "id": "GPL-2.0-only"
299587              }
299588            },
299589            {
299590              "license": {
299591                "id": "GPL-2.0-or-later"
299592              }
299593            },
299594            {
299595              "license": {
299596                "id": "GPL-3.0-only"
299597              }
299598            },
299599            {
299600              "license": {
299601                "id": "LGPL-2.0-only"
299602              }
299603            },
299604            {
299605              "license": {
299606                "id": "LGPL-2.1-only"
299607              }
299608            },
299609            {
299610              "license": {
299611                "id": "LGPL-2.1-or-later"
299612              }
299613            },
299614            {
299615              "license": {
299616                "name": "PD"
299617              }
299618            },
299619            {
299620              "license": {
299621                "name": "PD-debian"
299622              }
299623            },
299624            {
299625              "license": {
299626                "name": "config-h"
299627              }
299628            },
299629            {
299630              "license": {
299631                "name": "noderivs"
299632              }
299633            },
299634            {
299635              "license": {
299636                "name": "permissive-fsf"
299637              }
299638            },
299639            {
299640              "license": {
299641                "name": "permissive-nowarranty"
299642              }
299643            },
299644            {
299645              "license": {
299646                "name": "probably-PD"
299647              }
299648            }
299649          ],
299650          "cpe": "cpe:2.3:a:xz-utils:xz-utils:5.2.4-1ubuntu1:*:*:*:*:*:*:*",
299651          "purl": "pkg:deb/ubuntu/xz-utils@5.2.4-1ubuntu1?arch=amd64\u0026distro=ubuntu-20.04",
299652          "swid": {
299653            "attachment": {}
299654          },
299655          "pedigree": {},
299656          "evidence": {},
299657          "signature": {
299658            "signature": {
299659              "publicKey": {}
299660            }
299661          },
299662          "modelCard": {
299663            "modelParameters": {
299664              "approach": {}
299665            },
299666            "quantitativeAnalysis": {
299667              "graphics": {}
299668            },
299669            "considerations": {}
299670          }
299671        },
299672        {
299673          "type": "library",
299674          "bom-ref": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04\u0026package-id=65361fdd213cfcf7",
299675          "supplier": {},
299676          "publisher": "Ubuntu Developers \u003cubuntu-devel-discuss@lists.ubuntu.com\u003e",
299677          "name": "zlib1g",
299678          "version": "1:1.2.11.dfsg-2ubuntu1.2",
299679          "licenses": [
299680            {
299681              "license": {
299682                "id": "Zlib"
299683              }
299684            }
299685          ],
299686          "cpe": "cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.11.dfsg-2ubuntu1.2:*:*:*:*:*:*:*",
299687          "purl": "pkg:deb/ubuntu/zlib1g@1:1.2.11.dfsg-2ubuntu1.2?arch=amd64\u0026upstream=zlib\u0026distro=ubuntu-20.04",
299688          "swid": {
299689            "attachment": {}
299690          },
299691          "pedigree": {},
299692          "evidence": {},
299693          "signature": {
299694            "signature": {
299695              "publicKey": {}
299696            }
299697          },
299698          "modelCard": {
299699            "modelParameters": {
299700              "approach": {}
299701            },
299702            "quantitativeAnalysis": {
299703              "graphics": {}
299704            },
299705            "considerations": {}
299706          }
299707        },
299708        {
299709          "type": "operating-system",
299710          "supplier": {},
299711          "name": "ubuntu",
299712          "version": "20.04",
299713          "description": "Ubuntu 20.04.2 LTS",
299714          "swid": {
299715            "tagId": "ubuntu",
299716            "name": "ubuntu",
299717            "version": "20.04",
299718            "attachment": {}
299719          },
299720          "pedigree": {},
299721          "externalReferences": [
299722            {
299723              "url": "https://bugs.launchpad.net/ubuntu/",
299724              "type": "issue-tracker"
299725            },
299726            {
299727              "url": "https://www.ubuntu.com/",
299728              "type": "website"
299729            },
299730            {
299731              "url": "https://help.ubuntu.com/",
299732              "comment": "support",
299733              "type": "other"
299734            },
299735            {
299736              "url": "https://www.ubuntu.com/legal/terms-and-policies/privacy-policy",
299737              "comment": "privacyPolicy",
299738              "type": "other"
299739            }
299740          ],
299741          "evidence": {},
299742          "signature": {
299743            "signature": {
299744              "publicKey": {}
299745            }
299746          },
299747          "modelCard": {
299748            "modelParameters": {
299749              "approach": {}
299750            },
299751            "quantitativeAnalysis": {
299752              "graphics": {}
299753            },
299754            "considerations": {}
299755          }
299756        },
299757        {
299758          "type": "library",
299759          "bom-ref": "pkg:npm/%40angular-builders/custom-webpack@8.4.1?package-id=65a6a85a9461c339",
299760          "supplier": {},
299761          "name": "@angular-builders/custom-webpack",
299762          "version": "8.4.1",
299763          "licenses": [
299764            {
299765              "license": {
299766                "id": "MIT"
299767              }
299768            }
299769          ],
299770          "cpe": "cpe:2.3:a:\\@angular-builders\\/custom-webpack:\\@angular-builders\\/custom-webpack:8.4.1:*:*:*:*:*:*:*",
299771          "purl": "pkg:npm/%40angular-builders/custom-webpack@8.4.1",
299772          "swid": {
299773            "attachment": {}
299774          },
299775          "pedigree": {},
299776          "evidence": {},
299777          "signature": {
299778            "signature": {
299779              "publicKey": {}
299780            }
299781          },
299782          "modelCard": {
299783            "modelParameters": {
299784              "approach": {}
299785            },
299786            "quantitativeAnalysis": {
299787              "graphics": {}
299788            },
299789            "considerations": {}
299790          }
299791        },
299792        {
299793          "type": "library",
299794          "bom-ref": "pkg:npm/%40angular-devkit/architect@0.901.5?package-id=20c970ba017e9289",
299795          "supplier": {},
299796          "name": "@angular-devkit/architect",
299797          "version": "0.901.5",
299798          "licenses": [
299799            {
299800              "license": {
299801                "id": "MIT"
299802              }
299803            }
299804          ],
299805          "cpe": "cpe:2.3:a:\\@angular-devkit\\/architect:\\@angular-devkit\\/architect:0.901.5:*:*:*:*:*:*:*",
299806          "purl": "pkg:npm/%40angular-devkit/architect@0.901.5",
299807          "swid": {
299808            "attachment": {}
299809          },
299810          "pedigree": {},
299811          "evidence": {},
299812          "signature": {
299813            "signature": {
299814              "publicKey": {}
299815            }
299816          },
299817          "modelCard": {
299818            "modelParameters": {
299819              "approach": {}
299820            },
299821            "quantitativeAnalysis": {
299822              "graphics": {}
299823            },
299824            "considerations": {}
299825          }
299826        },
299827        {
299828          "type": "library",
299829          "bom-ref": "pkg:npm/%40angular-devkit/build-angular@0.901.5?package-id=3b82877558261dc8",
299830          "supplier": {},
299831          "name": "@angular-devkit/build-angular",
299832          "version": "0.901.5",
299833          "licenses": [
299834            {
299835              "license": {
299836                "id": "MIT"
299837              }
299838            }
299839          ],
299840          "cpe": "cpe:2.3:a:\\@angular-devkit\\/build-angular:\\@angular-devkit\\/build-angular:0.901.5:*:*:*:*:*:*:*",
299841          "purl": "pkg:npm/%40angular-devkit/build-angular@0.901.5",
299842          "swid": {
299843            "attachment": {}
299844          },
299845          "pedigree": {},
299846          "evidence": {},
299847          "signature": {
299848            "signature": {
299849              "publicKey": {}
299850            }
299851          },
299852          "modelCard": {
299853            "modelParameters": {
299854              "approach": {}
299855            },
299856            "quantitativeAnalysis": {
299857              "graphics": {}
299858            },
299859            "considerations": {}
299860          }
299861        },
299862        {
299863          "type": "library",
299864          "bom-ref": "pkg:npm/%40angular-devkit/build-ng-packagr@0.901.5?package-id=a6a8045ac0dfbed5",
299865          "supplier": {},
299866          "name": "@angular-devkit/build-ng-packagr",
299867          "version": "0.901.5",
299868          "licenses": [
299869            {
299870              "license": {
299871                "id": "MIT"
299872              }
299873            }
299874          ],
299875          "cpe": "cpe:2.3:a:\\@angular-devkit\\/build-ng-packagr:\\@angular-devkit\\/build-ng-packagr:0.901.5:*:*:*:*:*:*:*",
299876          "purl": "pkg:npm/%40angular-devkit/build-ng-packagr@0.901.5",
299877          "swid": {
299878            "attachment": {}
299879          },
299880          "pedigree": {},
299881          "evidence": {},
299882          "signature": {
299883            "signature": {
299884              "publicKey": {}
299885            }
299886          },
299887          "modelCard": {
299888            "modelParameters": {
299889              "approach": {}
299890            },
299891            "quantitativeAnalysis": {
299892              "graphics": {}
299893            },
299894            "considerations": {}
299895          }
299896        },
299897        {
299898          "type": "library",
299899          "bom-ref": "pkg:npm/%40angular-devkit/build-optimizer@0.901.5?package-id=469615eb77adea78",
299900          "supplier": {},
299901          "name": "@angular-devkit/build-optimizer",
299902          "version": "0.901.5",
299903          "licenses": [
299904            {
299905              "license": {
299906                "id": "MIT"
299907              }
299908            }
299909          ],
299910          "cpe": "cpe:2.3:a:\\@angular-devkit\\/build-optimizer:\\@angular-devkit\\/build-optimizer:0.901.5:*:*:*:*:*:*:*",
299911          "purl": "pkg:npm/%40angular-devkit/build-optimizer@0.901.5",
299912          "swid": {
299913            "attachment": {}
299914          },
299915          "pedigree": {},
299916          "evidence": {},
299917          "signature": {
299918            "signature": {
299919              "publicKey": {}
299920            }
299921          },
299922          "modelCard": {
299923            "modelParameters": {
299924              "approach": {}
299925            },
299926            "quantitativeAnalysis": {
299927              "graphics": {}
299928            },
299929            "considerations": {}
299930          }
299931        },
299932        {
299933          "type": "library",
299934          "bom-ref": "pkg:npm/%40angular-devkit/build-webpack@0.901.5?package-id=3356633268fe407c",
299935          "supplier": {},
299936          "name": "@angular-devkit/build-webpack",
299937          "version": "0.901.5",
299938          "licenses": [
299939            {
299940              "license": {
299941                "id": "MIT"
299942              }
299943            }
299944          ],
299945          "cpe": "cpe:2.3:a:\\@angular-devkit\\/build-webpack:\\@angular-devkit\\/build-webpack:0.901.5:*:*:*:*:*:*:*",
299946          "purl": "pkg:npm/%40angular-devkit/build-webpack@0.901.5",
299947          "swid": {
299948            "attachment": {}
299949          },
299950          "pedigree": {},
299951          "evidence": {},
299952          "signature": {
299953            "signature": {
299954              "publicKey": {}
299955            }
299956          },
299957          "modelCard": {
299958            "modelParameters": {
299959              "approach": {}
299960            },
299961            "quantitativeAnalysis": {
299962              "graphics": {}
299963            },
299964            "considerations": {}
299965          }
299966        },
299967        {
299968          "type": "library",
299969          "bom-ref": "pkg:npm/%40angular-devkit/core@9.1.5?package-id=b1dfcb2b39b04984",
299970          "supplier": {},
299971          "name": "@angular-devkit/core",
299972          "version": "9.1.5",
299973          "licenses": [
299974            {
299975              "license": {
299976                "id": "MIT"
299977              }
299978            }
299979          ],
299980          "cpe": "cpe:2.3:a:\\@angular-devkit\\/core:\\@angular-devkit\\/core:9.1.5:*:*:*:*:*:*:*",
299981          "purl": "pkg:npm/%40angular-devkit/core@9.1.5",
299982          "swid": {
299983            "attachment": {}
299984          },
299985          "pedigree": {},
299986          "evidence": {},
299987          "signature": {
299988            "signature": {
299989              "publicKey": {}
299990            }
299991          },
299992          "modelCard": {
299993            "modelParameters": {
299994              "approach": {}
299995            },
299996            "quantitativeAnalysis": {
299997              "graphics": {}
299998            },
299999            "considerations": {}
300000          }
300001        },
300002        {
300003          "type": "library",
300004          "bom-ref": "pkg:npm/%40angular-devkit/schematics@9.1.5?package-id=483bb688c0e6d34d",
300005          "supplier": {},
300006          "name": "@angular-devkit/schematics",
300007          "version": "9.1.5",
300008          "licenses": [
300009            {
300010              "license": {
300011                "id": "MIT"
300012              }
300013            }
300014          ],
300015          "cpe": "cpe:2.3:a:\\@angular-devkit\\/schematics:\\@angular-devkit\\/schematics:9.1.5:*:*:*:*:*:*:*",
300016          "purl": "pkg:npm/%40angular-devkit/schematics@9.1.5",
300017          "swid": {
300018            "attachment": {}
300019          },
300020          "pedigree": {},
300021          "evidence": {},
300022          "signature": {
300023            "signature": {
300024              "publicKey": {}
300025            }
300026          },
300027          "modelCard": {
300028            "modelParameters": {
300029              "approach": {}
300030            },
300031            "quantitativeAnalysis": {
300032              "graphics": {}
300033            },
300034            "considerations": {}
300035          }
300036        },
300037        {
300038          "type": "library",
300039          "bom-ref": "pkg:npm/%40angular/animations@9.1.6?package-id=8b4a0fab4da7409d",
300040          "supplier": {},
300041          "name": "@angular/animations",
300042          "version": "9.1.6",
300043          "licenses": [
300044            {
300045              "license": {
300046                "id": "MIT"
300047              }
300048            }
300049          ],
300050          "cpe": "cpe:2.3:a:\\@angular\\/animations:\\@angular\\/animations:9.1.6:*:*:*:*:*:*:*",
300051          "purl": "pkg:npm/%40angular/animations@9.1.6",
300052          "swid": {
300053            "attachment": {}
300054          },
300055          "pedigree": {},
300056          "evidence": {},
300057          "signature": {
300058            "signature": {
300059              "publicKey": {}
300060            }
300061          },
300062          "modelCard": {
300063            "modelParameters": {
300064              "approach": {}
300065            },
300066            "quantitativeAnalysis": {
300067              "graphics": {}
300068            },
300069            "considerations": {}
300070          }
300071        },
300072        {
300073          "type": "library",
300074          "bom-ref": "pkg:npm/%40angular/cdk@9.2.4?package-id=8bc107834503fff9",
300075          "supplier": {},
300076          "name": "@angular/cdk",
300077          "version": "9.2.4",
300078          "licenses": [
300079            {
300080              "license": {
300081                "id": "MIT"
300082              }
300083            }
300084          ],
300085          "cpe": "cpe:2.3:a:\\@angular\\/cdk:\\@angular\\/cdk:9.2.4:*:*:*:*:*:*:*",
300086          "purl": "pkg:npm/%40angular/cdk@9.2.4",
300087          "swid": {
300088            "attachment": {}
300089          },
300090          "pedigree": {},
300091          "evidence": {},
300092          "signature": {
300093            "signature": {
300094              "publicKey": {}
300095            }
300096          },
300097          "modelCard": {
300098            "modelParameters": {
300099              "approach": {}
300100            },
300101            "quantitativeAnalysis": {
300102              "graphics": {}
300103            },
300104            "considerations": {}
300105          }
300106        },
300107        {
300108          "type": "library",
300109          "bom-ref": "pkg:npm/%40angular/cli@9.1.5?package-id=7dfcfe5bf1764697",
300110          "supplier": {},
300111          "name": "@angular/cli",
300112          "version": "9.1.5",
300113          "licenses": [
300114            {
300115              "license": {
300116                "id": "MIT"
300117              }
300118            }
300119          ],
300120          "cpe": "cpe:2.3:a:\\@angular\\/cli:\\@angular\\/cli:9.1.5:*:*:*:*:*:*:*",
300121          "purl": "pkg:npm/%40angular/cli@9.1.5",
300122          "swid": {
300123            "attachment": {}
300124          },
300125          "pedigree": {},
300126          "evidence": {},
300127          "signature": {
300128            "signature": {
300129              "publicKey": {}
300130            }
300131          },
300132          "modelCard": {
300133            "modelParameters": {
300134              "approach": {}
300135            },
300136            "quantitativeAnalysis": {
300137              "graphics": {}
300138            },
300139            "considerations": {}
300140          }
300141        },
300142        {
300143          "type": "library",
300144          "bom-ref": "pkg:npm/%40angular/common@9.1.6?package-id=3bdc31324c9141ab",
300145          "supplier": {},
300146          "name": "@angular/common",
300147          "version": "9.1.6",
300148          "licenses": [
300149            {
300150              "license": {
300151                "id": "MIT"
300152              }
300153            }
300154          ],
300155          "cpe": "cpe:2.3:a:\\@angular\\/common:\\@angular\\/common:9.1.6:*:*:*:*:*:*:*",
300156          "purl": "pkg:npm/%40angular/common@9.1.6",
300157          "swid": {
300158            "attachment": {}
300159          },
300160          "pedigree": {},
300161          "evidence": {},
300162          "signature": {
300163            "signature": {
300164              "publicKey": {}
300165            }
300166          },
300167          "modelCard": {
300168            "modelParameters": {
300169              "approach": {}
300170            },
300171            "quantitativeAnalysis": {
300172              "graphics": {}
300173            },
300174            "considerations": {}
300175          }
300176        },
300177        {
300178          "type": "library",
300179          "bom-ref": "pkg:npm/%40angular/compiler@9.1.6?package-id=d0b2cf9472eb09b3",
300180          "supplier": {},
300181          "name": "@angular/compiler",
300182          "version": "9.1.6",
300183          "licenses": [
300184            {
300185              "license": {
300186                "id": "MIT"
300187              }
300188            }
300189          ],
300190          "cpe": "cpe:2.3:a:\\@angular\\/compiler:\\@angular\\/compiler:9.1.6:*:*:*:*:*:*:*",
300191          "purl": "pkg:npm/%40angular/compiler@9.1.6",
300192          "swid": {
300193            "attachment": {}
300194          },
300195          "pedigree": {},
300196          "evidence": {},
300197          "signature": {
300198            "signature": {
300199              "publicKey": {}
300200            }
300201          },
300202          "modelCard": {
300203            "modelParameters": {
300204              "approach": {}
300205            },
300206            "quantitativeAnalysis": {
300207              "graphics": {}
300208            },
300209            "considerations": {}
300210          }
300211        },
300212        {
300213          "type": "library",
300214          "bom-ref": "pkg:npm/%40angular/compiler-cli@9.1.6?package-id=c92beed6ee1f2512",
300215          "supplier": {},
300216          "name": "@angular/compiler-cli",
300217          "version": "9.1.6",
300218          "licenses": [
300219            {
300220              "license": {
300221                "id": "MIT"
300222              }
300223            }
300224          ],
300225          "cpe": "cpe:2.3:a:\\@angular\\/compiler-cli:\\@angular\\/compiler-cli:9.1.6:*:*:*:*:*:*:*",
300226          "purl": "pkg:npm/%40angular/compiler-cli@9.1.6",
300227          "swid": {
300228            "attachment": {}
300229          },
300230          "pedigree": {},
300231          "evidence": {},
300232          "signature": {
300233            "signature": {
300234              "publicKey": {}
300235            }
300236          },
300237          "modelCard": {
300238            "modelParameters": {
300239              "approach": {}
300240            },
300241            "quantitativeAnalysis": {
300242              "graphics": {}
300243            },
300244            "considerations": {}
300245          }
300246        },
300247        {
300248          "type": "library",
300249          "bom-ref": "pkg:npm/%40angular/core@9.1.6?package-id=adc97d9579952242",
300250          "supplier": {},
300251          "name": "@angular/core",
300252          "version": "9.1.6",
300253          "licenses": [
300254            {
300255              "license": {
300256                "id": "MIT"
300257              }
300258            }
300259          ],
300260          "cpe": "cpe:2.3:a:\\@angular\\/core:\\@angular\\/core:9.1.6:*:*:*:*:*:*:*",
300261          "purl": "pkg:npm/%40angular/core@9.1.6",
300262          "swid": {
300263            "attachment": {}
300264          },
300265          "pedigree": {},
300266          "evidence": {},
300267          "signature": {
300268            "signature": {
300269              "publicKey": {}
300270            }
300271          },
300272          "modelCard": {
300273            "modelParameters": {
300274              "approach": {}
300275            },
300276            "quantitativeAnalysis": {
300277              "graphics": {}
300278            },
300279            "considerations": {}
300280          }
300281        },
300282        {
300283          "type": "library",
300284          "bom-ref": "pkg:npm/%40angular/flex-layout@9.0.0-beta.29?package-id=1c707a58bda8926f",
300285          "supplier": {},
300286          "name": "@angular/flex-layout",
300287          "version": "9.0.0-beta.29",
300288          "licenses": [
300289            {
300290              "license": {
300291                "id": "MIT"
300292              }
300293            }
300294          ],
300295          "cpe": "cpe:2.3:a:\\@angular\\/flex-layout:\\@angular\\/flex-layout:9.0.0-beta.29:*:*:*:*:*:*:*",
300296          "purl": "pkg:npm/%40angular/flex-layout@9.0.0-beta.29",
300297          "swid": {
300298            "attachment": {}
300299          },
300300          "pedigree": {},
300301          "evidence": {},
300302          "signature": {
300303            "signature": {
300304              "publicKey": {}
300305            }
300306          },
300307          "modelCard": {
300308            "modelParameters": {
300309              "approach": {}
300310            },
300311            "quantitativeAnalysis": {
300312              "graphics": {}
300313            },
300314            "considerations": {}
300315          }
300316        },
300317        {
300318          "type": "library",
300319          "bom-ref": "pkg:npm/%40angular/forms@9.1.6?package-id=c3c27873b11cbb62",
300320          "supplier": {},
300321          "name": "@angular/forms",
300322          "version": "9.1.6",
300323          "licenses": [
300324            {
300325              "license": {
300326                "id": "MIT"
300327              }
300328            }
300329          ],
300330          "cpe": "cpe:2.3:a:\\@angular\\/forms:\\@angular\\/forms:9.1.6:*:*:*:*:*:*:*",
300331          "purl": "pkg:npm/%40angular/forms@9.1.6",
300332          "swid": {
300333            "attachment": {}
300334          },
300335          "pedigree": {},
300336          "evidence": {},
300337          "signature": {
300338            "signature": {
300339              "publicKey": {}
300340            }
300341          },
300342          "modelCard": {
300343            "modelParameters": {
300344              "approach": {}
300345            },
300346            "quantitativeAnalysis": {
300347              "graphics": {}
300348            },
300349            "considerations": {}
300350          }
300351        },
300352        {
300353          "type": "library",
300354          "bom-ref": "pkg:npm/%40angular/language-service@9.1.6?package-id=96daab093c63c94b",
300355          "supplier": {},
300356          "name": "@angular/language-service",
300357          "version": "9.1.6",
300358          "licenses": [
300359            {
300360              "license": {
300361                "id": "MIT"
300362              }
300363            }
300364          ],
300365          "cpe": "cpe:2.3:a:\\@angular\\/language-service:\\@angular\\/language-service:9.1.6:*:*:*:*:*:*:*",
300366          "purl": "pkg:npm/%40angular/language-service@9.1.6",
300367          "swid": {
300368            "attachment": {}
300369          },
300370          "pedigree": {},
300371          "evidence": {},
300372          "signature": {
300373            "signature": {
300374              "publicKey": {}
300375            }
300376          },
300377          "modelCard": {
300378            "modelParameters": {
300379              "approach": {}
300380            },
300381            "quantitativeAnalysis": {
300382              "graphics": {}
300383            },
300384            "considerations": {}
300385          }
300386        },
300387        {
300388          "type": "library",
300389          "bom-ref": "pkg:npm/%40angular/material@9.2.3?package-id=725e46d7723454aa",
300390          "supplier": {},
300391          "name": "@angular/material",
300392          "version": "9.2.3",
300393          "licenses": [
300394            {
300395              "license": {
300396                "id": "MIT"
300397              }
300398            }
300399          ],
300400          "cpe": "cpe:2.3:a:\\@angular\\/material:\\@angular\\/material:9.2.3:*:*:*:*:*:*:*",
300401          "purl": "pkg:npm/%40angular/material@9.2.3",
300402          "swid": {
300403            "attachment": {}
300404          },
300405          "pedigree": {},
300406          "evidence": {},
300407          "signature": {
300408            "signature": {
300409              "publicKey": {}
300410            }
300411          },
300412          "modelCard": {
300413            "modelParameters": {
300414              "approach": {}
300415            },
300416            "quantitativeAnalysis": {
300417              "graphics": {}
300418            },
300419            "considerations": {}
300420          }
300421        },
300422        {
300423          "type": "library",
300424          "bom-ref": "pkg:npm/%40angular/platform-browser@9.1.12?package-id=afaac4964b462152",
300425          "supplier": {},
300426          "name": "@angular/platform-browser",
300427          "version": "9.1.12",
300428          "licenses": [
300429            {
300430              "license": {
300431                "id": "MIT"
300432              }
300433            }
300434          ],
300435          "cpe": "cpe:2.3:a:\\@angular\\/platform-browser:\\@angular\\/platform-browser:9.1.12:*:*:*:*:*:*:*",
300436          "purl": "pkg:npm/%40angular/platform-browser@9.1.12",
300437          "swid": {
300438            "attachment": {}
300439          },
300440          "pedigree": {},
300441          "evidence": {},
300442          "signature": {
300443            "signature": {
300444              "publicKey": {}
300445            }
300446          },
300447          "modelCard": {
300448            "modelParameters": {
300449              "approach": {}
300450            },
300451            "quantitativeAnalysis": {
300452              "graphics": {}
300453            },
300454            "considerations": {}
300455          }
300456        },
300457        {
300458          "type": "library",
300459          "bom-ref": "pkg:npm/%40angular/platform-browser-dynamic@9.1.12?package-id=414b3fd15a2a5303",
300460          "supplier": {},
300461          "name": "@angular/platform-browser-dynamic",
300462          "version": "9.1.12",
300463          "licenses": [
300464            {
300465              "license": {
300466                "id": "MIT"
300467              }
300468            }
300469          ],
300470          "cpe": "cpe:2.3:a:\\@angular\\/platform-browser-dynamic:\\@angular\\/platform-browser-dynamic:9.1.12:*:*:*:*:*:*:*",
300471          "purl": "pkg:npm/%40angular/platform-browser-dynamic@9.1.12",
300472          "swid": {
300473            "attachment": {}
300474          },
300475          "pedigree": {},
300476          "evidence": {},
300477          "signature": {
300478            "signature": {
300479              "publicKey": {}
300480            }
300481          },
300482          "modelCard": {
300483            "modelParameters": {
300484              "approach": {}
300485            },
300486            "quantitativeAnalysis": {
300487              "graphics": {}
300488            },
300489            "considerations": {}
300490          }
300491        },
300492        {
300493          "type": "library",
300494          "bom-ref": "pkg:npm/%40angular/router@9.1.6?package-id=807c39b67e76af25",
300495          "supplier": {},
300496          "name": "@angular/router",
300497          "version": "9.1.6",
300498          "licenses": [
300499            {
300500              "license": {
300501                "id": "MIT"
300502              }
300503            }
300504          ],
300505          "cpe": "cpe:2.3:a:\\@angular\\/router:\\@angular\\/router:9.1.6:*:*:*:*:*:*:*",
300506          "purl": "pkg:npm/%40angular/router@9.1.6",
300507          "swid": {
300508            "attachment": {}
300509          },
300510          "pedigree": {},
300511          "evidence": {},
300512          "signature": {
300513            "signature": {
300514              "publicKey": {}
300515            }
300516          },
300517          "modelCard": {
300518            "modelParameters": {
300519              "approach": {}
300520            },
300521            "quantitativeAnalysis": {
300522              "graphics": {}
300523            },
300524            "considerations": {}
300525          }
300526        },
300527        {
300528          "type": "library",
300529          "bom-ref": "pkg:npm/%40auth0/angular-jwt@4.0.0?package-id=830a1d453a317d71",
300530          "supplier": {},
300531          "name": "@auth0/angular-jwt",
300532          "version": "4.0.0",
300533          "licenses": [
300534            {
300535              "license": {
300536                "id": "MIT"
300537              }
300538            }
300539          ],
300540          "cpe": "cpe:2.3:a:\\@auth0\\/angular-jwt:\\@auth0\\/angular-jwt:4.0.0:*:*:*:*:*:*:*",
300541          "purl": "pkg:npm/%40auth0/angular-jwt@4.0.0",
300542          "swid": {
300543            "attachment": {}
300544          },
300545          "pedigree": {},
300546          "evidence": {},
300547          "signature": {
300548            "signature": {
300549              "publicKey": {}
300550            }
300551          },
300552          "modelCard": {
300553            "modelParameters": {
300554              "approach": {}
300555            },
300556            "quantitativeAnalysis": {
300557              "graphics": {}
300558            },
300559            "considerations": {}
300560          }
300561        },
300562        {
300563          "type": "library",
300564          "bom-ref": "pkg:npm/%40babel/code-frame@7.16.0?package-id=bee470a99e4b72bd",
300565          "supplier": {},
300566          "name": "@babel/code-frame",
300567          "version": "7.16.0",
300568          "cpe": "cpe:2.3:a:\\@babel\\/code-frame:\\@babel\\/code-frame:7.16.0:*:*:*:*:*:*:*",
300569          "purl": "pkg:npm/%40babel/code-frame@7.16.0",
300570          "swid": {
300571            "attachment": {}
300572          },
300573          "pedigree": {},
300574          "evidence": {},
300575          "signature": {
300576            "signature": {
300577              "publicKey": {}
300578            }
300579          },
300580          "modelCard": {
300581            "modelParameters": {
300582              "approach": {}
300583            },
300584            "quantitativeAnalysis": {
300585              "graphics": {}
300586            },
300587            "considerations": {}
300588          }
300589        },
300590        {
300591          "type": "library",
300592          "bom-ref": "pkg:npm/%40babel/code-frame@7.8.3?package-id=9ca105f273df8d67",
300593          "supplier": {},
300594          "name": "@babel/code-frame",
300595          "version": "7.8.3",
300596          "licenses": [
300597            {
300598              "license": {
300599                "id": "MIT"
300600              }
300601            }
300602          ],
300603          "cpe": "cpe:2.3:a:\\@babel\\/code-frame:\\@babel\\/code-frame:7.8.3:*:*:*:*:*:*:*",
300604          "purl": "pkg:npm/%40babel/code-frame@7.8.3",
300605          "swid": {
300606            "attachment": {}
300607          },
300608          "pedigree": {},
300609          "evidence": {},
300610          "signature": {
300611            "signature": {
300612              "publicKey": {}
300613            }
300614          },
300615          "modelCard": {
300616            "modelParameters": {
300617              "approach": {}
300618            },
300619            "quantitativeAnalysis": {
300620              "graphics": {}
300621            },
300622            "considerations": {}
300623          }
300624        },
300625        {
300626          "type": "library",
300627          "bom-ref": "pkg:npm/%40babel/compat-data@7.16.4?package-id=bc8dc757b0d00c5f",
300628          "supplier": {},
300629          "name": "@babel/compat-data",
300630          "version": "7.16.4",
300631          "cpe": "cpe:2.3:a:\\@babel\\/compat-data:\\@babel\\/compat-data:7.16.4:*:*:*:*:*:*:*",
300632          "purl": "pkg:npm/%40babel/compat-data@7.16.4",
300633          "swid": {
300634            "attachment": {}
300635          },
300636          "pedigree": {},
300637          "evidence": {},
300638          "signature": {
300639            "signature": {
300640              "publicKey": {}
300641            }
300642          },
300643          "modelCard": {
300644            "modelParameters": {
300645              "approach": {}
300646            },
300647            "quantitativeAnalysis": {
300648              "graphics": {}
300649            },
300650            "considerations": {}
300651          }
300652        },
300653        {
300654          "type": "library",
300655          "bom-ref": "pkg:npm/%40babel/compat-data@7.9.6?package-id=f8494aeaba94e8c5",
300656          "supplier": {},
300657          "name": "@babel/compat-data",
300658          "version": "7.9.6",
300659          "licenses": [
300660            {
300661              "license": {
300662                "id": "MIT"
300663              }
300664            }
300665          ],
300666          "cpe": "cpe:2.3:a:\\@babel\\/compat-data:\\@babel\\/compat-data:7.9.6:*:*:*:*:*:*:*",
300667          "purl": "pkg:npm/%40babel/compat-data@7.9.6",
300668          "swid": {
300669            "attachment": {}
300670          },
300671          "pedigree": {},
300672          "evidence": {},
300673          "signature": {
300674            "signature": {
300675              "publicKey": {}
300676            }
300677          },
300678          "modelCard": {
300679            "modelParameters": {
300680              "approach": {}
300681            },
300682            "quantitativeAnalysis": {
300683              "graphics": {}
300684            },
300685            "considerations": {}
300686          }
300687        },
300688        {
300689          "type": "library",
300690          "bom-ref": "pkg:npm/%40babel/core@7.16.0?package-id=b1c39ba071ca671e",
300691          "supplier": {},
300692          "name": "@babel/core",
300693          "version": "7.16.0",
300694          "cpe": "cpe:2.3:a:\\@babel\\/core:\\@babel\\/core:7.16.0:*:*:*:*:*:*:*",
300695          "purl": "pkg:npm/%40babel/core@7.16.0",
300696          "swid": {
300697            "attachment": {}
300698          },
300699          "pedigree": {},
300700          "evidence": {},
300701          "signature": {
300702            "signature": {
300703              "publicKey": {}
300704            }
300705          },
300706          "modelCard": {
300707            "modelParameters": {
300708              "approach": {}
300709            },
300710            "quantitativeAnalysis": {
300711              "graphics": {}
300712            },
300713            "considerations": {}
300714          }
300715        },
300716        {
300717          "type": "library",
300718          "bom-ref": "pkg:npm/%40babel/core@7.9.0?package-id=6ade38a7ccf25dc",
300719          "supplier": {},
300720          "name": "@babel/core",
300721          "version": "7.9.0",
300722          "licenses": [
300723            {
300724              "license": {
300725                "id": "MIT"
300726              }
300727            }
300728          ],
300729          "cpe": "cpe:2.3:a:\\@babel\\/core:\\@babel\\/core:7.9.0:*:*:*:*:*:*:*",
300730          "purl": "pkg:npm/%40babel/core@7.9.0",
300731          "swid": {
300732            "attachment": {}
300733          },
300734          "pedigree": {},
300735          "evidence": {},
300736          "signature": {
300737            "signature": {
300738              "publicKey": {}
300739            }
300740          },
300741          "modelCard": {
300742            "modelParameters": {
300743              "approach": {}
300744            },
300745            "quantitativeAnalysis": {
300746              "graphics": {}
300747            },
300748            "considerations": {}
300749          }
300750        },
300751        {
300752          "type": "library",
300753          "bom-ref": "pkg:npm/%40babel/generator@7.16.0?package-id=6caa7df3c62b8fb5",
300754          "supplier": {},
300755          "name": "@babel/generator",
300756          "version": "7.16.0",
300757          "cpe": "cpe:2.3:a:\\@babel\\/generator:\\@babel\\/generator:7.16.0:*:*:*:*:*:*:*",
300758          "purl": "pkg:npm/%40babel/generator@7.16.0",
300759          "swid": {
300760            "attachment": {}
300761          },
300762          "pedigree": {},
300763          "evidence": {},
300764          "signature": {
300765            "signature": {
300766              "publicKey": {}
300767            }
300768          },
300769          "modelCard": {
300770            "modelParameters": {
300771              "approach": {}
300772            },
300773            "quantitativeAnalysis": {
300774              "graphics": {}
300775            },
300776            "considerations": {}
300777          }
300778        },
300779        {
300780          "type": "library",
300781          "bom-ref": "pkg:npm/%40babel/generator@7.7.7?package-id=4483f97d87906db9",
300782          "supplier": {},
300783          "name": "@babel/generator",
300784          "version": "7.7.7",
300785          "licenses": [
300786            {
300787              "license": {
300788                "id": "MIT"
300789              }
300790            }
300791          ],
300792          "cpe": "cpe:2.3:a:\\@babel\\/generator:\\@babel\\/generator:7.7.7:*:*:*:*:*:*:*",
300793          "purl": "pkg:npm/%40babel/generator@7.7.7",
300794          "swid": {
300795            "attachment": {}
300796          },
300797          "pedigree": {},
300798          "evidence": {},
300799          "signature": {
300800            "signature": {
300801              "publicKey": {}
300802            }
300803          },
300804          "modelCard": {
300805            "modelParameters": {
300806              "approach": {}
300807            },
300808            "quantitativeAnalysis": {
300809              "graphics": {}
300810            },
300811            "considerations": {}
300812          }
300813        },
300814        {
300815          "type": "library",
300816          "bom-ref": "pkg:npm/%40babel/helper-annotate-as-pure@7.8.3?package-id=7b145ba77c592d9c",
300817          "supplier": {},
300818          "name": "@babel/helper-annotate-as-pure",
300819          "version": "7.8.3",
300820          "licenses": [
300821            {
300822              "license": {
300823                "id": "MIT"
300824              }
300825            }
300826          ],
300827          "cpe": "cpe:2.3:a:\\@babel\\/helper-annotate-as-pure:\\@babel\\/helper-annotate-as-pure:7.8.3:*:*:*:*:*:*:*",
300828          "purl": "pkg:npm/%40babel/helper-annotate-as-pure@7.8.3",
300829          "swid": {
300830            "attachment": {}
300831          },
300832          "pedigree": {},
300833          "evidence": {},
300834          "signature": {
300835            "signature": {
300836              "publicKey": {}
300837            }
300838          },
300839          "modelCard": {
300840            "modelParameters": {
300841              "approach": {}
300842            },
300843            "quantitativeAnalysis": {
300844              "graphics": {}
300845            },
300846            "considerations": {}
300847          }
300848        },
300849        {
300850          "type": "library",
300851          "bom-ref": "pkg:npm/%40babel/helper-builder-binary-assignment-operator-visitor@7.8.3?package-id=42c29b761549cf9f",
300852          "supplier": {},
300853          "name": "@babel/helper-builder-binary-assignment-operator-visitor",
300854          "version": "7.8.3",
300855          "licenses": [
300856            {
300857              "license": {
300858                "id": "MIT"
300859              }
300860            }
300861          ],
300862          "cpe": "cpe:2.3:a:\\@babel\\/helper-builder-binary-assignment-operator-visitor:\\@babel\\/helper-builder-binary-assignment-operator-visitor:7.8.3:*:*:*:*:*:*:*",
300863          "purl": "pkg:npm/%40babel/helper-builder-binary-assignment-operator-visitor@7.8.3",
300864          "swid": {
300865            "attachment": {}
300866          },
300867          "pedigree": {},
300868          "evidence": {},
300869          "signature": {
300870            "signature": {
300871              "publicKey": {}
300872            }
300873          },
300874          "modelCard": {
300875            "modelParameters": {
300876              "approach": {}
300877            },
300878            "quantitativeAnalysis": {
300879              "graphics": {}
300880            },
300881            "considerations": {}
300882          }
300883        },
300884        {
300885          "type": "library",
300886          "bom-ref": "pkg:npm/%40babel/helper-compilation-targets@7.16.3?package-id=829d4599c14988af",
300887          "supplier": {},
300888          "name": "@babel/helper-compilation-targets",
300889          "version": "7.16.3",
300890          "cpe": "cpe:2.3:a:\\@babel\\/helper-compilation-targets:\\@babel\\/helper-compilation-targets:7.16.3:*:*:*:*:*:*:*",
300891          "purl": "pkg:npm/%40babel/helper-compilation-targets@7.16.3",
300892          "swid": {
300893            "attachment": {}
300894          },
300895          "pedigree": {},
300896          "evidence": {},
300897          "signature": {
300898            "signature": {
300899              "publicKey": {}
300900            }
300901          },
300902          "modelCard": {
300903            "modelParameters": {
300904              "approach": {}
300905            },
300906            "quantitativeAnalysis": {
300907              "graphics": {}
300908            },
300909            "considerations": {}
300910          }
300911        },
300912        {
300913          "type": "library",
300914          "bom-ref": "pkg:npm/%40babel/helper-compilation-targets@7.9.6?package-id=f6baae0091194cba",
300915          "supplier": {},
300916          "name": "@babel/helper-compilation-targets",
300917          "version": "7.9.6",
300918          "licenses": [
300919            {
300920              "license": {
300921                "id": "MIT"
300922              }
300923            }
300924          ],
300925          "cpe": "cpe:2.3:a:\\@babel\\/helper-compilation-targets:\\@babel\\/helper-compilation-targets:7.9.6:*:*:*:*:*:*:*",
300926          "purl": "pkg:npm/%40babel/helper-compilation-targets@7.9.6",
300927          "swid": {
300928            "attachment": {}
300929          },
300930          "pedigree": {},
300931          "evidence": {},
300932          "signature": {
300933            "signature": {
300934              "publicKey": {}
300935            }
300936          },
300937          "modelCard": {
300938            "modelParameters": {
300939              "approach": {}
300940            },
300941            "quantitativeAnalysis": {
300942              "graphics": {}
300943            },
300944            "considerations": {}
300945          }
300946        },
300947        {
300948          "type": "library",
300949          "bom-ref": "pkg:npm/%40babel/helper-create-regexp-features-plugin@7.8.8?package-id=9ee5b6fa8f863806",
300950          "supplier": {},
300951          "name": "@babel/helper-create-regexp-features-plugin",
300952          "version": "7.8.8",
300953          "licenses": [
300954            {
300955              "license": {
300956                "id": "MIT"
300957              }
300958            }
300959          ],
300960          "cpe": "cpe:2.3:a:\\@babel\\/helper-create-regexp-features-plugin:\\@babel\\/helper-create-regexp-features-plugin:7.8.8:*:*:*:*:*:*:*",
300961          "purl": "pkg:npm/%40babel/helper-create-regexp-features-plugin@7.8.8",
300962          "swid": {
300963            "attachment": {}
300964          },
300965          "pedigree": {},
300966          "evidence": {},
300967          "signature": {
300968            "signature": {
300969              "publicKey": {}
300970            }
300971          },
300972          "modelCard": {
300973            "modelParameters": {
300974              "approach": {}
300975            },
300976            "quantitativeAnalysis": {
300977              "graphics": {}
300978            },
300979            "considerations": {}
300980          }
300981        },
300982        {
300983          "type": "library",
300984          "bom-ref": "pkg:npm/%40babel/helper-define-map@7.8.3?package-id=b4973563eb9e3109",
300985          "supplier": {},
300986          "name": "@babel/helper-define-map",
300987          "version": "7.8.3",
300988          "licenses": [
300989            {
300990              "license": {
300991                "id": "MIT"
300992              }
300993            }
300994          ],
300995          "cpe": "cpe:2.3:a:\\@babel\\/helper-define-map:\\@babel\\/helper-define-map:7.8.3:*:*:*:*:*:*:*",
300996          "purl": "pkg:npm/%40babel/helper-define-map@7.8.3",
300997          "swid": {
300998            "attachment": {}
300999          },
301000          "pedigree": {},
301001          "evidence": {},
301002          "signature": {
301003            "signature": {
301004              "publicKey": {}
301005            }
301006          },
301007          "modelCard": {
301008            "modelParameters": {
301009              "approach": {}
301010            },
301011            "quantitativeAnalysis": {
301012              "graphics": {}
301013            },
301014            "considerations": {}
301015          }
301016        },
301017        {
301018          "type": "library",
301019          "bom-ref": "pkg:npm/%40babel/helper-explode-assignable-expression@7.8.3?package-id=d5e096d13eb77ada",
301020          "supplier": {},
301021          "name": "@babel/helper-explode-assignable-expression",
301022          "version": "7.8.3",
301023          "licenses": [
301024            {
301025              "license": {
301026                "id": "MIT"
301027              }
301028            }
301029          ],
301030          "cpe": "cpe:2.3:a:\\@babel\\/helper-explode-assignable-expression:\\@babel\\/helper-explode-assignable-expression:7.8.3:*:*:*:*:*:*:*",
301031          "purl": "pkg:npm/%40babel/helper-explode-assignable-expression@7.8.3",
301032          "swid": {
301033            "attachment": {}
301034          },
301035          "pedigree": {},
301036          "evidence": {},
301037          "signature": {
301038            "signature": {
301039              "publicKey": {}
301040            }
301041          },
301042          "modelCard": {
301043            "modelParameters": {
301044              "approach": {}
301045            },
301046            "quantitativeAnalysis": {
301047              "graphics": {}
301048            },
301049            "considerations": {}
301050          }
301051        },
301052        {
301053          "type": "library",
301054          "bom-ref": "pkg:npm/%40babel/helper-function-name@7.16.0?package-id=4644724a9b7aa68b",
301055          "supplier": {},
301056          "name": "@babel/helper-function-name",
301057          "version": "7.16.0",
301058          "cpe": "cpe:2.3:a:\\@babel\\/helper-function-name:\\@babel\\/helper-function-name:7.16.0:*:*:*:*:*:*:*",
301059          "purl": "pkg:npm/%40babel/helper-function-name@7.16.0",
301060          "swid": {
301061            "attachment": {}
301062          },
301063          "pedigree": {},
301064          "evidence": {},
301065          "signature": {
301066            "signature": {
301067              "publicKey": {}
301068            }
301069          },
301070          "modelCard": {
301071            "modelParameters": {
301072              "approach": {}
301073            },
301074            "quantitativeAnalysis": {
301075              "graphics": {}
301076            },
301077            "considerations": {}
301078          }
301079        },
301080        {
301081          "type": "library",
301082          "bom-ref": "pkg:npm/%40babel/helper-function-name@7.8.3?package-id=1ee3e14d1dcda792",
301083          "supplier": {},
301084          "name": "@babel/helper-function-name",
301085          "version": "7.8.3",
301086          "licenses": [
301087            {
301088              "license": {
301089                "id": "MIT"
301090              }
301091            }
301092          ],
301093          "cpe": "cpe:2.3:a:\\@babel\\/helper-function-name:\\@babel\\/helper-function-name:7.8.3:*:*:*:*:*:*:*",
301094          "purl": "pkg:npm/%40babel/helper-function-name@7.8.3",
301095          "swid": {
301096            "attachment": {}
301097          },
301098          "pedigree": {},
301099          "evidence": {},
301100          "signature": {
301101            "signature": {
301102              "publicKey": {}
301103            }
301104          },
301105          "modelCard": {
301106            "modelParameters": {
301107              "approach": {}
301108            },
301109            "quantitativeAnalysis": {
301110              "graphics": {}
301111            },
301112            "considerations": {}
301113          }
301114        },
301115        {
301116          "type": "library",
301117          "bom-ref": "pkg:npm/%40babel/helper-get-function-arity@7.16.0?package-id=4fc4c2d36f247154",
301118          "supplier": {},
301119          "name": "@babel/helper-get-function-arity",
301120          "version": "7.16.0",
301121          "cpe": "cpe:2.3:a:\\@babel\\/helper-get-function-arity:\\@babel\\/helper-get-function-arity:7.16.0:*:*:*:*:*:*:*",
301122          "purl": "pkg:npm/%40babel/helper-get-function-arity@7.16.0",
301123          "swid": {
301124            "attachment": {}
301125          },
301126          "pedigree": {},
301127          "evidence": {},
301128          "signature": {
301129            "signature": {
301130              "publicKey": {}
301131            }
301132          },
301133          "modelCard": {
301134            "modelParameters": {
301135              "approach": {}
301136            },
301137            "quantitativeAnalysis": {
301138              "graphics": {}
301139            },
301140            "considerations": {}
301141          }
301142        },
301143        {
301144          "type": "library",
301145          "bom-ref": "pkg:npm/%40babel/helper-get-function-arity@7.8.3?package-id=90fe11d7659dd69",
301146          "supplier": {},
301147          "name": "@babel/helper-get-function-arity",
301148          "version": "7.8.3",
301149          "licenses": [
301150            {
301151              "license": {
301152                "id": "MIT"
301153              }
301154            }
301155          ],
301156          "cpe": "cpe:2.3:a:\\@babel\\/helper-get-function-arity:\\@babel\\/helper-get-function-arity:7.8.3:*:*:*:*:*:*:*",
301157          "purl": "pkg:npm/%40babel/helper-get-function-arity@7.8.3",
301158          "swid": {
301159            "attachment": {}
301160          },
301161          "pedigree": {},
301162          "evidence": {},
301163          "signature": {
301164            "signature": {
301165              "publicKey": {}
301166            }
301167          },
301168          "modelCard": {
301169            "modelParameters": {
301170              "approach": {}
301171            },
301172            "quantitativeAnalysis": {
301173              "graphics": {}
301174            },
301175            "considerations": {}
301176          }
301177        },
301178        {
301179          "type": "library",
301180          "bom-ref": "pkg:npm/%40babel/helper-hoist-variables@7.16.0?package-id=9b3f77bb939160eb",
301181          "supplier": {},
301182          "name": "@babel/helper-hoist-variables",
301183          "version": "7.16.0",
301184          "cpe": "cpe:2.3:a:\\@babel\\/helper-hoist-variables:\\@babel\\/helper-hoist-variables:7.16.0:*:*:*:*:*:*:*",
301185          "purl": "pkg:npm/%40babel/helper-hoist-variables@7.16.0",
301186          "swid": {
301187            "attachment": {}
301188          },
301189          "pedigree": {},
301190          "evidence": {},
301191          "signature": {
301192            "signature": {
301193              "publicKey": {}
301194            }
301195          },
301196          "modelCard": {
301197            "modelParameters": {
301198              "approach": {}
301199            },
301200            "quantitativeAnalysis": {
301201              "graphics": {}
301202            },
301203            "considerations": {}
301204          }
301205        },
301206        {
301207          "type": "library",
301208          "bom-ref": "pkg:npm/%40babel/helper-hoist-variables@7.8.3?package-id=668dfde0b760ca58",
301209          "supplier": {},
301210          "name": "@babel/helper-hoist-variables",
301211          "version": "7.8.3",
301212          "licenses": [
301213            {
301214              "license": {
301215                "id": "MIT"
301216              }
301217            }
301218          ],
301219          "cpe": "cpe:2.3:a:\\@babel\\/helper-hoist-variables:\\@babel\\/helper-hoist-variables:7.8.3:*:*:*:*:*:*:*",
301220          "purl": "pkg:npm/%40babel/helper-hoist-variables@7.8.3",
301221          "swid": {
301222            "attachment": {}
301223          },
301224          "pedigree": {},
301225          "evidence": {},
301226          "signature": {
301227            "signature": {
301228              "publicKey": {}
301229            }
301230          },
301231          "modelCard": {
301232            "modelParameters": {
301233              "approach": {}
301234            },
301235            "quantitativeAnalysis": {
301236              "graphics": {}
301237            },
301238            "considerations": {}
301239          }
301240        },
301241        {
301242          "type": "library",
301243          "bom-ref": "pkg:npm/%40babel/helper-member-expression-to-functions@7.16.0?package-id=1fa4354257b57aae",
301244          "supplier": {},
301245          "name": "@babel/helper-member-expression-to-functions",
301246          "version": "7.16.0",
301247          "cpe": "cpe:2.3:a:\\@babel\\/helper-member-expression-to-functions:\\@babel\\/helper-member-expression-to-functions:7.16.0:*:*:*:*:*:*:*",
301248          "purl": "pkg:npm/%40babel/helper-member-expression-to-functions@7.16.0",
301249          "swid": {
301250            "attachment": {}
301251          },
301252          "pedigree": {},
301253          "evidence": {},
301254          "signature": {
301255            "signature": {
301256              "publicKey": {}
301257            }
301258          },
301259          "modelCard": {
301260            "modelParameters": {
301261              "approach": {}
301262            },
301263            "quantitativeAnalysis": {
301264              "graphics": {}
301265            },
301266            "considerations": {}
301267          }
301268        },
301269        {
301270          "type": "library",
301271          "bom-ref": "pkg:npm/%40babel/helper-member-expression-to-functions@7.8.3?package-id=692b82bcb37a0044",
301272          "supplier": {},
301273          "name": "@babel/helper-member-expression-to-functions",
301274          "version": "7.8.3",
301275          "licenses": [
301276            {
301277              "license": {
301278                "id": "MIT"
301279              }
301280            }
301281          ],
301282          "cpe": "cpe:2.3:a:\\@babel\\/helper-member-expression-to-functions:\\@babel\\/helper-member-expression-to-functions:7.8.3:*:*:*:*:*:*:*",
301283          "purl": "pkg:npm/%40babel/helper-member-expression-to-functions@7.8.3",
301284          "swid": {
301285            "attachment": {}
301286          },
301287          "pedigree": {},
301288          "evidence": {},
301289          "signature": {
301290            "signature": {
301291              "publicKey": {}
301292            }
301293          },
301294          "modelCard": {
301295            "modelParameters": {
301296              "approach": {}
301297            },
301298            "quantitativeAnalysis": {
301299              "graphics": {}
301300            },
301301            "considerations": {}
301302          }
301303        },
301304        {
301305          "type": "library",
301306          "bom-ref": "pkg:npm/%40babel/helper-module-imports@7.16.0?package-id=3dd1245f9190ab36",
301307          "supplier": {},
301308          "name": "@babel/helper-module-imports",
301309          "version": "7.16.0",
301310          "cpe": "cpe:2.3:a:\\@babel\\/helper-module-imports:\\@babel\\/helper-module-imports:7.16.0:*:*:*:*:*:*:*",
301311          "purl": "pkg:npm/%40babel/helper-module-imports@7.16.0",
301312          "swid": {
301313            "attachment": {}
301314          },
301315          "pedigree": {},
301316          "evidence": {},
301317          "signature": {
301318            "signature": {
301319              "publicKey": {}
301320            }
301321          },
301322          "modelCard": {
301323            "modelParameters": {
301324              "approach": {}
301325            },
301326            "quantitativeAnalysis": {
301327              "graphics": {}
301328            },
301329            "considerations": {}
301330          }
301331        },
301332        {
301333          "type": "library",
301334          "bom-ref": "pkg:npm/%40babel/helper-module-imports@7.8.3?package-id=4fabcbb147622b98",
301335          "supplier": {},
301336          "name": "@babel/helper-module-imports",
301337          "version": "7.8.3",
301338          "licenses": [
301339            {
301340              "license": {
301341                "id": "MIT"
301342              }
301343            }
301344          ],
301345          "cpe": "cpe:2.3:a:\\@babel\\/helper-module-imports:\\@babel\\/helper-module-imports:7.8.3:*:*:*:*:*:*:*",
301346          "purl": "pkg:npm/%40babel/helper-module-imports@7.8.3",
301347          "swid": {
301348            "attachment": {}
301349          },
301350          "pedigree": {},
301351          "evidence": {},
301352          "signature": {
301353            "signature": {
301354              "publicKey": {}
301355            }
301356          },
301357          "modelCard": {
301358            "modelParameters": {
301359              "approach": {}
301360            },
301361            "quantitativeAnalysis": {
301362              "graphics": {}
301363            },
301364            "considerations": {}
301365          }
301366        },
301367        {
301368          "type": "library",
301369          "bom-ref": "pkg:npm/%40babel/helper-module-transforms@7.16.0?package-id=627b6b30f99931d3",
301370          "supplier": {},
301371          "name": "@babel/helper-module-transforms",
301372          "version": "7.16.0",
301373          "cpe": "cpe:2.3:a:\\@babel\\/helper-module-transforms:\\@babel\\/helper-module-transforms:7.16.0:*:*:*:*:*:*:*",
301374          "purl": "pkg:npm/%40babel/helper-module-transforms@7.16.0",
301375          "swid": {
301376            "attachment": {}
301377          },
301378          "pedigree": {},
301379          "evidence": {},
301380          "signature": {
301381            "signature": {
301382              "publicKey": {}
301383            }
301384          },
301385          "modelCard": {
301386            "modelParameters": {
301387              "approach": {}
301388            },
301389            "quantitativeAnalysis": {
301390              "graphics": {}
301391            },
301392            "considerations": {}
301393          }
301394        },
301395        {
301396          "type": "library",
301397          "bom-ref": "pkg:npm/%40babel/helper-module-transforms@7.9.0?package-id=bcd7b3259cf77aa7",
301398          "supplier": {},
301399          "name": "@babel/helper-module-transforms",
301400          "version": "7.9.0",
301401          "licenses": [
301402            {
301403              "license": {
301404                "id": "MIT"
301405              }
301406            }
301407          ],
301408          "cpe": "cpe:2.3:a:\\@babel\\/helper-module-transforms:\\@babel\\/helper-module-transforms:7.9.0:*:*:*:*:*:*:*",
301409          "purl": "pkg:npm/%40babel/helper-module-transforms@7.9.0",
301410          "swid": {
301411            "attachment": {}
301412          },
301413          "pedigree": {},
301414          "evidence": {},
301415          "signature": {
301416            "signature": {
301417              "publicKey": {}
301418            }
301419          },
301420          "modelCard": {
301421            "modelParameters": {
301422              "approach": {}
301423            },
301424            "quantitativeAnalysis": {
301425              "graphics": {}
301426            },
301427            "considerations": {}
301428          }
301429        },
301430        {
301431          "type": "library",
301432          "bom-ref": "pkg:npm/%40babel/helper-optimise-call-expression@7.16.0?package-id=699ba633ce3382f5",
301433          "supplier": {},
301434          "name": "@babel/helper-optimise-call-expression",
301435          "version": "7.16.0",
301436          "cpe": "cpe:2.3:a:\\@babel\\/helper-optimise-call-expression:\\@babel\\/helper-optimise-call-expression:7.16.0:*:*:*:*:*:*:*",
301437          "purl": "pkg:npm/%40babel/helper-optimise-call-expression@7.16.0",
301438          "swid": {
301439            "attachment": {}
301440          },
301441          "pedigree": {},
301442          "evidence": {},
301443          "signature": {
301444            "signature": {
301445              "publicKey": {}
301446            }
301447          },
301448          "modelCard": {
301449            "modelParameters": {
301450              "approach": {}
301451            },
301452            "quantitativeAnalysis": {
301453              "graphics": {}
301454            },
301455            "considerations": {}
301456          }
301457        },
301458        {
301459          "type": "library",
301460          "bom-ref": "pkg:npm/%40babel/helper-optimise-call-expression@7.8.3?package-id=8d6729b1808f23bc",
301461          "supplier": {},
301462          "name": "@babel/helper-optimise-call-expression",
301463          "version": "7.8.3",
301464          "licenses": [
301465            {
301466              "license": {
301467                "id": "MIT"
301468              }
301469            }
301470          ],
301471          "cpe": "cpe:2.3:a:\\@babel\\/helper-optimise-call-expression:\\@babel\\/helper-optimise-call-expression:7.8.3:*:*:*:*:*:*:*",
301472          "purl": "pkg:npm/%40babel/helper-optimise-call-expression@7.8.3",
301473          "swid": {
301474            "attachment": {}
301475          },
301476          "pedigree": {},
301477          "evidence": {},
301478          "signature": {
301479            "signature": {
301480              "publicKey": {}
301481            }
301482          },
301483          "modelCard": {
301484            "modelParameters": {
301485              "approach": {}
301486            },
301487            "quantitativeAnalysis": {
301488              "graphics": {}
301489            },
301490            "considerations": {}
301491          }
301492        },
301493        {
301494          "type": "library",
301495          "bom-ref": "pkg:npm/%40babel/helper-plugin-utils@7.8.3?package-id=336e40e60c6d9cca",
301496          "supplier": {},
301497          "name": "@babel/helper-plugin-utils",
301498          "version": "7.8.3",
301499          "licenses": [
301500            {
301501              "license": {
301502                "id": "MIT"
301503              }
301504            }
301505          ],
301506          "cpe": "cpe:2.3:a:\\@babel\\/helper-plugin-utils:\\@babel\\/helper-plugin-utils:7.8.3:*:*:*:*:*:*:*",
301507          "purl": "pkg:npm/%40babel/helper-plugin-utils@7.8.3",
301508          "swid": {
301509            "attachment": {}
301510          },
301511          "pedigree": {},
301512          "evidence": {},
301513          "signature": {
301514            "signature": {
301515              "publicKey": {}
301516            }
301517          },
301518          "modelCard": {
301519            "modelParameters": {
301520              "approach": {}
301521            },
301522            "quantitativeAnalysis": {
301523              "graphics": {}
301524            },
301525            "considerations": {}
301526          }
301527        },
301528        {
301529          "type": "library",
301530          "bom-ref": "pkg:npm/%40babel/helper-regex@7.8.3?package-id=ae72b4e36781d118",
301531          "supplier": {},
301532          "name": "@babel/helper-regex",
301533          "version": "7.8.3",
301534          "licenses": [
301535            {
301536              "license": {
301537                "id": "MIT"
301538              }
301539            }
301540          ],
301541          "cpe": "cpe:2.3:a:\\@babel\\/helper-regex:\\@babel\\/helper-regex:7.8.3:*:*:*:*:*:*:*",
301542          "purl": "pkg:npm/%40babel/helper-regex@7.8.3",
301543          "swid": {
301544            "attachment": {}
301545          },
301546          "pedigree": {},
301547          "evidence": {},
301548          "signature": {
301549            "signature": {
301550              "publicKey": {}
301551            }
301552          },
301553          "modelCard": {
301554            "modelParameters": {
301555              "approach": {}
301556            },
301557            "quantitativeAnalysis": {
301558              "graphics": {}
301559            },
301560            "considerations": {}
301561          }
301562        },
301563        {
301564          "type": "library",
301565          "bom-ref": "pkg:npm/%40babel/helper-remap-async-to-generator@7.8.3?package-id=a6a2b9bd6dbec36e",
301566          "supplier": {},
301567          "name": "@babel/helper-remap-async-to-generator",
301568          "version": "7.8.3",
301569          "licenses": [
301570            {
301571              "license": {
301572                "id": "MIT"
301573              }
301574            }
301575          ],
301576          "cpe": "cpe:2.3:a:\\@babel\\/helper-remap-async-to-generator:\\@babel\\/helper-remap-async-to-generator:7.8.3:*:*:*:*:*:*:*",
301577          "purl": "pkg:npm/%40babel/helper-remap-async-to-generator@7.8.3",
301578          "swid": {
301579            "attachment": {}
301580          },
301581          "pedigree": {},
301582          "evidence": {},
301583          "signature": {
301584            "signature": {
301585              "publicKey": {}
301586            }
301587          },
301588          "modelCard": {
301589            "modelParameters": {
301590              "approach": {}
301591            },
301592            "quantitativeAnalysis": {
301593              "graphics": {}
301594            },
301595            "considerations": {}
301596          }
301597        },
301598        {
301599          "type": "library",
301600          "bom-ref": "pkg:npm/%40babel/helper-replace-supers@7.16.0?package-id=697998e25a48bf1f",
301601          "supplier": {},
301602          "name": "@babel/helper-replace-supers",
301603          "version": "7.16.0",
301604          "cpe": "cpe:2.3:a:\\@babel\\/helper-replace-supers:\\@babel\\/helper-replace-supers:7.16.0:*:*:*:*:*:*:*",
301605          "purl": "pkg:npm/%40babel/helper-replace-supers@7.16.0",
301606          "swid": {
301607            "attachment": {}
301608          },
301609          "pedigree": {},
301610          "evidence": {},
301611          "signature": {
301612            "signature": {
301613              "publicKey": {}
301614            }
301615          },
301616          "modelCard": {
301617            "modelParameters": {
301618              "approach": {}
301619            },
301620            "quantitativeAnalysis": {
301621              "graphics": {}
301622            },
301623            "considerations": {}
301624          }
301625        },
301626        {
301627          "type": "library",
301628          "bom-ref": "pkg:npm/%40babel/helper-replace-supers@7.9.6?package-id=4f435516289e65fd",
301629          "supplier": {},
301630          "name": "@babel/helper-replace-supers",
301631          "version": "7.9.6",
301632          "licenses": [
301633            {
301634              "license": {
301635                "id": "MIT"
301636              }
301637            }
301638          ],
301639          "cpe": "cpe:2.3:a:\\@babel\\/helper-replace-supers:\\@babel\\/helper-replace-supers:7.9.6:*:*:*:*:*:*:*",
301640          "purl": "pkg:npm/%40babel/helper-replace-supers@7.9.6",
301641          "swid": {
301642            "attachment": {}
301643          },
301644          "pedigree": {},
301645          "evidence": {},
301646          "signature": {
301647            "signature": {
301648              "publicKey": {}
301649            }
301650          },
301651          "modelCard": {
301652            "modelParameters": {
301653              "approach": {}
301654            },
301655            "quantitativeAnalysis": {
301656              "graphics": {}
301657            },
301658            "considerations": {}
301659          }
301660        },
301661        {
301662          "type": "library",
301663          "bom-ref": "pkg:npm/%40babel/helper-simple-access@7.16.0?package-id=dd74a9684a296589",
301664          "supplier": {},
301665          "name": "@babel/helper-simple-access",
301666          "version": "7.16.0",
301667          "cpe": "cpe:2.3:a:\\@babel\\/helper-simple-access:\\@babel\\/helper-simple-access:7.16.0:*:*:*:*:*:*:*",
301668          "purl": "pkg:npm/%40babel/helper-simple-access@7.16.0",
301669          "swid": {
301670            "attachment": {}
301671          },
301672          "pedigree": {},
301673          "evidence": {},
301674          "signature": {
301675            "signature": {
301676              "publicKey": {}
301677            }
301678          },
301679          "modelCard": {
301680            "modelParameters": {
301681              "approach": {}
301682            },
301683            "quantitativeAnalysis": {
301684              "graphics": {}
301685            },
301686            "considerations": {}
301687          }
301688        },
301689        {
301690          "type": "library",
301691          "bom-ref": "pkg:npm/%40babel/helper-simple-access@7.8.3?package-id=ef91b1be670ec20c",
301692          "supplier": {},
301693          "name": "@babel/helper-simple-access",
301694          "version": "7.8.3",
301695          "licenses": [
301696            {
301697              "license": {
301698                "id": "MIT"
301699              }
301700            }
301701          ],
301702          "cpe": "cpe:2.3:a:\\@babel\\/helper-simple-access:\\@babel\\/helper-simple-access:7.8.3:*:*:*:*:*:*:*",
301703          "purl": "pkg:npm/%40babel/helper-simple-access@7.8.3",
301704          "swid": {
301705            "attachment": {}
301706          },
301707          "pedigree": {},
301708          "evidence": {},
301709          "signature": {
301710            "signature": {
301711              "publicKey": {}
301712            }
301713          },
301714          "modelCard": {
301715            "modelParameters": {
301716              "approach": {}
301717            },
301718            "quantitativeAnalysis": {
301719              "graphics": {}
301720            },
301721            "considerations": {}
301722          }
301723        },
301724        {
301725          "type": "library",
301726          "bom-ref": "pkg:npm/%40babel/helper-split-export-declaration@7.16.0?package-id=c39852d92c0ac21c",
301727          "supplier": {},
301728          "name": "@babel/helper-split-export-declaration",
301729          "version": "7.16.0",
301730          "cpe": "cpe:2.3:a:\\@babel\\/helper-split-export-declaration:\\@babel\\/helper-split-export-declaration:7.16.0:*:*:*:*:*:*:*",
301731          "purl": "pkg:npm/%40babel/helper-split-export-declaration@7.16.0",
301732          "swid": {
301733            "attachment": {}
301734          },
301735          "pedigree": {},
301736          "evidence": {},
301737          "signature": {
301738            "signature": {
301739              "publicKey": {}
301740            }
301741          },
301742          "modelCard": {
301743            "modelParameters": {
301744              "approach": {}
301745            },
301746            "quantitativeAnalysis": {
301747              "graphics": {}
301748            },
301749            "considerations": {}
301750          }
301751        },
301752        {
301753          "type": "library",
301754          "bom-ref": "pkg:npm/%40babel/helper-split-export-declaration@7.8.3?package-id=6094414cd49cb945",
301755          "supplier": {},
301756          "name": "@babel/helper-split-export-declaration",
301757          "version": "7.8.3",
301758          "licenses": [
301759            {
301760              "license": {
301761                "id": "MIT"
301762              }
301763            }
301764          ],
301765          "cpe": "cpe:2.3:a:\\@babel\\/helper-split-export-declaration:\\@babel\\/helper-split-export-declaration:7.8.3:*:*:*:*:*:*:*",
301766          "purl": "pkg:npm/%40babel/helper-split-export-declaration@7.8.3",
301767          "swid": {
301768            "attachment": {}
301769          },
301770          "pedigree": {},
301771          "evidence": {},
301772          "signature": {
301773            "signature": {
301774              "publicKey": {}
301775            }
301776          },
301777          "modelCard": {
301778            "modelParameters": {
301779              "approach": {}
301780            },
301781            "quantitativeAnalysis": {
301782              "graphics": {}
301783            },
301784            "considerations": {}
301785          }
301786        },
301787        {
301788          "type": "library",
301789          "bom-ref": "pkg:npm/%40babel/helper-validator-identifier@7.15.7?package-id=89582dfacb43b62b",
301790          "supplier": {},
301791          "name": "@babel/helper-validator-identifier",
301792          "version": "7.15.7",
301793          "cpe": "cpe:2.3:a:\\@babel\\/helper-validator-identifier:\\@babel\\/helper-validator-identifier:7.15.7:*:*:*:*:*:*:*",
301794          "purl": "pkg:npm/%40babel/helper-validator-identifier@7.15.7",
301795          "swid": {
301796            "attachment": {}
301797          },
301798          "pedigree": {},
301799          "evidence": {},
301800          "signature": {
301801            "signature": {
301802              "publicKey": {}
301803            }
301804          },
301805          "modelCard": {
301806            "modelParameters": {
301807              "approach": {}
301808            },
301809            "quantitativeAnalysis": {
301810              "graphics": {}
301811            },
301812            "considerations": {}
301813          }
301814        },
301815        {
301816          "type": "library",
301817          "bom-ref": "pkg:npm/%40babel/helper-validator-identifier@7.9.0?package-id=229ebec2a4162a2f",
301818          "supplier": {},
301819          "name": "@babel/helper-validator-identifier",
301820          "version": "7.9.0",
301821          "licenses": [
301822            {
301823              "license": {
301824                "id": "MIT"
301825              }
301826            }
301827          ],
301828          "cpe": "cpe:2.3:a:\\@babel\\/helper-validator-identifier:\\@babel\\/helper-validator-identifier:7.9.0:*:*:*:*:*:*:*",
301829          "purl": "pkg:npm/%40babel/helper-validator-identifier@7.9.0",
301830          "swid": {
301831            "attachment": {}
301832          },
301833          "pedigree": {},
301834          "evidence": {},
301835          "signature": {
301836            "signature": {
301837              "publicKey": {}
301838            }
301839          },
301840          "modelCard": {
301841            "modelParameters": {
301842              "approach": {}
301843            },
301844            "quantitativeAnalysis": {
301845              "graphics": {}
301846            },
301847            "considerations": {}
301848          }
301849        },
301850        {
301851          "type": "library",
301852          "bom-ref": "pkg:npm/%40babel/helper-validator-option@7.14.5?package-id=f609e7e49eaf98ee",
301853          "supplier": {},
301854          "name": "@babel/helper-validator-option",
301855          "version": "7.14.5",
301856          "cpe": "cpe:2.3:a:\\@babel\\/helper-validator-option:\\@babel\\/helper-validator-option:7.14.5:*:*:*:*:*:*:*",
301857          "purl": "pkg:npm/%40babel/helper-validator-option@7.14.5",
301858          "swid": {
301859            "attachment": {}
301860          },
301861          "pedigree": {},
301862          "evidence": {},
301863          "signature": {
301864            "signature": {
301865              "publicKey": {}
301866            }
301867          },
301868          "modelCard": {
301869            "modelParameters": {
301870              "approach": {}
301871            },
301872            "quantitativeAnalysis": {
301873              "graphics": {}
301874            },
301875            "considerations": {}
301876          }
301877        },
301878        {
301879          "type": "library",
301880          "bom-ref": "pkg:npm/%40babel/helper-wrap-function@7.8.3?package-id=d187d308a7b0f64f",
301881          "supplier": {},
301882          "name": "@babel/helper-wrap-function",
301883          "version": "7.8.3",
301884          "licenses": [
301885            {
301886              "license": {
301887                "id": "MIT"
301888              }
301889            }
301890          ],
301891          "cpe": "cpe:2.3:a:\\@babel\\/helper-wrap-function:\\@babel\\/helper-wrap-function:7.8.3:*:*:*:*:*:*:*",
301892          "purl": "pkg:npm/%40babel/helper-wrap-function@7.8.3",
301893          "swid": {
301894            "attachment": {}
301895          },
301896          "pedigree": {},
301897          "evidence": {},
301898          "signature": {
301899            "signature": {
301900              "publicKey": {}
301901            }
301902          },
301903          "modelCard": {
301904            "modelParameters": {
301905              "approach": {}
301906            },
301907            "quantitativeAnalysis": {
301908              "graphics": {}
301909            },
301910            "considerations": {}
301911          }
301912        },
301913        {
301914          "type": "library",
301915          "bom-ref": "pkg:npm/%40babel/helpers@7.16.3?package-id=3368bdd7cfb5147e",
301916          "supplier": {},
301917          "name": "@babel/helpers",
301918          "version": "7.16.3",
301919          "cpe": "cpe:2.3:a:\\@babel\\/helpers:\\@babel\\/helpers:7.16.3:*:*:*:*:*:*:*",
301920          "purl": "pkg:npm/%40babel/helpers@7.16.3",
301921          "swid": {
301922            "attachment": {}
301923          },
301924          "pedigree": {},
301925          "evidence": {},
301926          "signature": {
301927            "signature": {
301928              "publicKey": {}
301929            }
301930          },
301931          "modelCard": {
301932            "modelParameters": {
301933              "approach": {}
301934            },
301935            "quantitativeAnalysis": {
301936              "graphics": {}
301937            },
301938            "considerations": {}
301939          }
301940        },
301941        {
301942          "type": "library",
301943          "bom-ref": "pkg:npm/%40babel/helpers@7.9.6?package-id=4dad7d3a654ba583",
301944          "supplier": {},
301945          "name": "@babel/helpers",
301946          "version": "7.9.6",
301947          "licenses": [
301948            {
301949              "license": {
301950                "id": "MIT"
301951              }
301952            }
301953          ],
301954          "cpe": "cpe:2.3:a:\\@babel\\/helpers:\\@babel\\/helpers:7.9.6:*:*:*:*:*:*:*",
301955          "purl": "pkg:npm/%40babel/helpers@7.9.6",
301956          "swid": {
301957            "attachment": {}
301958          },
301959          "pedigree": {},
301960          "evidence": {},
301961          "signature": {
301962            "signature": {
301963              "publicKey": {}
301964            }
301965          },
301966          "modelCard": {
301967            "modelParameters": {
301968              "approach": {}
301969            },
301970            "quantitativeAnalysis": {
301971              "graphics": {}
301972            },
301973            "considerations": {}
301974          }
301975        },
301976        {
301977          "type": "library",
301978          "bom-ref": "pkg:npm/%40babel/highlight@7.16.0?package-id=97d77e48713a7bd2",
301979          "supplier": {},
301980          "name": "@babel/highlight",
301981          "version": "7.16.0",
301982          "cpe": "cpe:2.3:a:\\@babel\\/highlight:\\@babel\\/highlight:7.16.0:*:*:*:*:*:*:*",
301983          "purl": "pkg:npm/%40babel/highlight@7.16.0",
301984          "swid": {
301985            "attachment": {}
301986          },
301987          "pedigree": {},
301988          "evidence": {},
301989          "signature": {
301990            "signature": {
301991              "publicKey": {}
301992            }
301993          },
301994          "modelCard": {
301995            "modelParameters": {
301996              "approach": {}
301997            },
301998            "quantitativeAnalysis": {
301999              "graphics": {}
302000            },
302001            "considerations": {}
302002          }
302003        },
302004        {
302005          "type": "library",
302006          "bom-ref": "pkg:npm/%40babel/highlight@7.9.0?package-id=9ae6242c096ddbb9",
302007          "supplier": {},
302008          "name": "@babel/highlight",
302009          "version": "7.9.0",
302010          "licenses": [
302011            {
302012              "license": {
302013                "id": "MIT"
302014              }
302015            }
302016          ],
302017          "cpe": "cpe:2.3:a:\\@babel\\/highlight:\\@babel\\/highlight:7.9.0:*:*:*:*:*:*:*",
302018          "purl": "pkg:npm/%40babel/highlight@7.9.0",
302019          "swid": {
302020            "attachment": {}
302021          },
302022          "pedigree": {},
302023          "evidence": {},
302024          "signature": {
302025            "signature": {
302026              "publicKey": {}
302027            }
302028          },
302029          "modelCard": {
302030            "modelParameters": {
302031              "approach": {}
302032            },
302033            "quantitativeAnalysis": {
302034              "graphics": {}
302035            },
302036            "considerations": {}
302037          }
302038        },
302039        {
302040          "type": "library",
302041          "bom-ref": "pkg:npm/%40babel/parser@7.16.4?package-id=b3119cd619e83667",
302042          "supplier": {},
302043          "name": "@babel/parser",
302044          "version": "7.16.4",
302045          "cpe": "cpe:2.3:a:\\@babel\\/parser:\\@babel\\/parser:7.16.4:*:*:*:*:*:*:*",
302046          "purl": "pkg:npm/%40babel/parser@7.16.4",
302047          "swid": {
302048            "attachment": {}
302049          },
302050          "pedigree": {},
302051          "evidence": {},
302052          "signature": {
302053            "signature": {
302054              "publicKey": {}
302055            }
302056          },
302057          "modelCard": {
302058            "modelParameters": {
302059              "approach": {}
302060            },
302061            "quantitativeAnalysis": {
302062              "graphics": {}
302063            },
302064            "considerations": {}
302065          }
302066        },
302067        {
302068          "type": "library",
302069          "bom-ref": "pkg:npm/%40babel/parser@7.9.3?package-id=5bc9e941dc82ed2e",
302070          "supplier": {},
302071          "name": "@babel/parser",
302072          "version": "7.9.3",
302073          "licenses": [
302074            {
302075              "license": {
302076                "id": "MIT"
302077              }
302078            }
302079          ],
302080          "cpe": "cpe:2.3:a:\\@babel\\/parser:\\@babel\\/parser:7.9.3:*:*:*:*:*:*:*",
302081          "purl": "pkg:npm/%40babel/parser@7.9.3",
302082          "swid": {
302083            "attachment": {}
302084          },
302085          "pedigree": {},
302086          "evidence": {},
302087          "signature": {
302088            "signature": {
302089              "publicKey": {}
302090            }
302091          },
302092          "modelCard": {
302093            "modelParameters": {
302094              "approach": {}
302095            },
302096            "quantitativeAnalysis": {
302097              "graphics": {}
302098            },
302099            "considerations": {}
302100          }
302101        },
302102        {
302103          "type": "library",
302104          "bom-ref": "pkg:npm/%40babel/plugin-proposal-async-generator-functions@7.8.3?package-id=42ea39c7e504aee7",
302105          "supplier": {},
302106          "name": "@babel/plugin-proposal-async-generator-functions",
302107          "version": "7.8.3",
302108          "licenses": [
302109            {
302110              "license": {
302111                "id": "MIT"
302112              }
302113            }
302114          ],
302115          "cpe": "cpe:2.3:a:\\@babel\\/plugin-proposal-async-generator-functions:\\@babel\\/plugin-proposal-async-generator-functions:7.8.3:*:*:*:*:*:*:*",
302116          "purl": "pkg:npm/%40babel/plugin-proposal-async-generator-functions@7.8.3",
302117          "swid": {
302118            "attachment": {}
302119          },
302120          "pedigree": {},
302121          "evidence": {},
302122          "signature": {
302123            "signature": {
302124              "publicKey": {}
302125            }
302126          },
302127          "modelCard": {
302128            "modelParameters": {
302129              "approach": {}
302130            },
302131            "quantitativeAnalysis": {
302132              "graphics": {}
302133            },
302134            "considerations": {}
302135          }
302136        },
302137        {
302138          "type": "library",
302139          "bom-ref": "pkg:npm/%40babel/plugin-proposal-dynamic-import@7.8.3?package-id=de8f272e2e2eccc6",
302140          "supplier": {},
302141          "name": "@babel/plugin-proposal-dynamic-import",
302142          "version": "7.8.3",
302143          "licenses": [
302144            {
302145              "license": {
302146                "id": "MIT"
302147              }
302148            }
302149          ],
302150          "cpe": "cpe:2.3:a:\\@babel\\/plugin-proposal-dynamic-import:\\@babel\\/plugin-proposal-dynamic-import:7.8.3:*:*:*:*:*:*:*",
302151          "purl": "pkg:npm/%40babel/plugin-proposal-dynamic-import@7.8.3",
302152          "swid": {
302153            "attachment": {}
302154          },
302155          "pedigree": {},
302156          "evidence": {},
302157          "signature": {
302158            "signature": {
302159              "publicKey": {}
302160            }
302161          },
302162          "modelCard": {
302163            "modelParameters": {
302164              "approach": {}
302165            },
302166            "quantitativeAnalysis": {
302167              "graphics": {}
302168            },
302169            "considerations": {}
302170          }
302171        },
302172        {
302173          "type": "library",
302174          "bom-ref": "pkg:npm/%40babel/plugin-proposal-json-strings@7.8.3?package-id=6288c9a9d74eeab9",
302175          "supplier": {},
302176          "name": "@babel/plugin-proposal-json-strings",
302177          "version": "7.8.3",
302178          "licenses": [
302179            {
302180              "license": {
302181                "id": "MIT"
302182              }
302183            }
302184          ],
302185          "cpe": "cpe:2.3:a:\\@babel\\/plugin-proposal-json-strings:\\@babel\\/plugin-proposal-json-strings:7.8.3:*:*:*:*:*:*:*",
302186          "purl": "pkg:npm/%40babel/plugin-proposal-json-strings@7.8.3",
302187          "swid": {
302188            "attachment": {}
302189          },
302190          "pedigree": {},
302191          "evidence": {},
302192          "signature": {
302193            "signature": {
302194              "publicKey": {}
302195            }
302196          },
302197          "modelCard": {
302198            "modelParameters": {
302199              "approach": {}
302200            },
302201            "quantitativeAnalysis": {
302202              "graphics": {}
302203            },
302204            "considerations": {}
302205          }
302206        },
302207        {
302208          "type": "library",
302209          "bom-ref": "pkg:npm/%40babel/plugin-proposal-nullish-coalescing-operator@7.8.3?package-id=76633ca0f7062ece",
302210          "supplier": {},
302211          "name": "@babel/plugin-proposal-nullish-coalescing-operator",
302212          "version": "7.8.3",
302213          "licenses": [
302214            {
302215              "license": {
302216                "id": "MIT"
302217              }
302218            }
302219          ],
302220          "cpe": "cpe:2.3:a:\\@babel\\/plugin-proposal-nullish-coalescing-operator:\\@babel\\/plugin-proposal-nullish-coalescing-operator:7.8.3:*:*:*:*:*:*:*",
302221          "purl": "pkg:npm/%40babel/plugin-proposal-nullish-coalescing-operator@7.8.3",
302222          "swid": {
302223            "attachment": {}
302224          },
302225          "pedigree": {},
302226          "evidence": {},
302227          "signature": {
302228            "signature": {
302229              "publicKey": {}
302230            }
302231          },
302232          "modelCard": {
302233            "modelParameters": {
302234              "approach": {}
302235            },
302236            "quantitativeAnalysis": {
302237              "graphics": {}
302238            },
302239            "considerations": {}
302240          }
302241        },
302242        {
302243          "type": "library",
302244          "bom-ref": "pkg:npm/%40babel/plugin-proposal-numeric-separator@7.8.3?package-id=f04378ac7fadaeed",
302245          "supplier": {},
302246          "name": "@babel/plugin-proposal-numeric-separator",
302247          "version": "7.8.3",
302248          "licenses": [
302249            {
302250              "license": {
302251                "id": "MIT"
302252              }
302253            }
302254          ],
302255          "cpe": "cpe:2.3:a:\\@babel\\/plugin-proposal-numeric-separator:\\@babel\\/plugin-proposal-numeric-separator:7.8.3:*:*:*:*:*:*:*",
302256          "purl": "pkg:npm/%40babel/plugin-proposal-numeric-separator@7.8.3",
302257          "swid": {
302258            "attachment": {}
302259          },
302260          "pedigree": {},
302261          "evidence": {},
302262          "signature": {
302263            "signature": {
302264              "publicKey": {}
302265            }
302266          },
302267          "modelCard": {
302268            "modelParameters": {
302269              "approach": {}
302270            },
302271            "quantitativeAnalysis": {
302272              "graphics": {}
302273            },
302274            "considerations": {}
302275          }
302276        },
302277        {
302278          "type": "library",
302279          "bom-ref": "pkg:npm/%40babel/plugin-proposal-object-rest-spread@7.9.6?package-id=cd5a480d1b63514e",
302280          "supplier": {},
302281          "name": "@babel/plugin-proposal-object-rest-spread",
302282          "version": "7.9.6",
302283          "licenses": [
302284            {
302285              "license": {
302286                "id": "MIT"
302287              }
302288            }
302289          ],
302290          "cpe": "cpe:2.3:a:\\@babel\\/plugin-proposal-object-rest-spread:\\@babel\\/plugin-proposal-object-rest-spread:7.9.6:*:*:*:*:*:*:*",
302291          "purl": "pkg:npm/%40babel/plugin-proposal-object-rest-spread@7.9.6",
302292          "swid": {
302293            "attachment": {}
302294          },
302295          "pedigree": {},
302296          "evidence": {},
302297          "signature": {
302298            "signature": {
302299              "publicKey": {}
302300            }
302301          },
302302          "modelCard": {
302303            "modelParameters": {
302304              "approach": {}
302305            },
302306            "quantitativeAnalysis": {
302307              "graphics": {}
302308            },
302309            "considerations": {}
302310          }
302311        },
302312        {
302313          "type": "library",
302314          "bom-ref": "pkg:npm/%40babel/plugin-proposal-optional-catch-binding@7.8.3?package-id=6b5aa5d7d155dedc",
302315          "supplier": {},
302316          "name": "@babel/plugin-proposal-optional-catch-binding",
302317          "version": "7.8.3",
302318          "licenses": [
302319            {
302320              "license": {
302321                "id": "MIT"
302322              }
302323            }
302324          ],
302325          "cpe": "cpe:2.3:a:\\@babel\\/plugin-proposal-optional-catch-binding:\\@babel\\/plugin-proposal-optional-catch-binding:7.8.3:*:*:*:*:*:*:*",
302326          "purl": "pkg:npm/%40babel/plugin-proposal-optional-catch-binding@7.8.3",
302327          "swid": {
302328            "attachment": {}
302329          },
302330          "pedigree": {},
302331          "evidence": {},
302332          "signature": {
302333            "signature": {
302334              "publicKey": {}
302335            }
302336          },
302337          "modelCard": {
302338            "modelParameters": {
302339              "approach": {}
302340            },
302341            "quantitativeAnalysis": {
302342              "graphics": {}
302343            },
302344            "considerations": {}
302345          }
302346        },
302347        {
302348          "type": "library",
302349          "bom-ref": "pkg:npm/%40babel/plugin-proposal-optional-chaining@7.9.0?package-id=824b9237010c1110",
302350          "supplier": {},
302351          "name": "@babel/plugin-proposal-optional-chaining",
302352          "version": "7.9.0",
302353          "licenses": [
302354            {
302355              "license": {
302356                "id": "MIT"
302357              }
302358            }
302359          ],
302360          "cpe": "cpe:2.3:a:\\@babel\\/plugin-proposal-optional-chaining:\\@babel\\/plugin-proposal-optional-chaining:7.9.0:*:*:*:*:*:*:*",
302361          "purl": "pkg:npm/%40babel/plugin-proposal-optional-chaining@7.9.0",
302362          "swid": {
302363            "attachment": {}
302364          },
302365          "pedigree": {},
302366          "evidence": {},
302367          "signature": {
302368            "signature": {
302369              "publicKey": {}
302370            }
302371          },
302372          "modelCard": {
302373            "modelParameters": {
302374              "approach": {}
302375            },
302376            "quantitativeAnalysis": {
302377              "graphics": {}
302378            },
302379            "considerations": {}
302380          }
302381        },
302382        {
302383          "type": "library",
302384          "bom-ref": "pkg:npm/%40babel/plugin-proposal-unicode-property-regex@7.8.8?package-id=f9b2b0a59f380474",
302385          "supplier": {},
302386          "name": "@babel/plugin-proposal-unicode-property-regex",
302387          "version": "7.8.8",
302388          "licenses": [
302389            {
302390              "license": {
302391                "id": "MIT"
302392              }
302393            }
302394          ],
302395          "cpe": "cpe:2.3:a:\\@babel\\/plugin-proposal-unicode-property-regex:\\@babel\\/plugin-proposal-unicode-property-regex:7.8.8:*:*:*:*:*:*:*",
302396          "purl": "pkg:npm/%40babel/plugin-proposal-unicode-property-regex@7.8.8",
302397          "swid": {
302398            "attachment": {}
302399          },
302400          "pedigree": {},
302401          "evidence": {},
302402          "signature": {
302403            "signature": {
302404              "publicKey": {}
302405            }
302406          },
302407          "modelCard": {
302408            "modelParameters": {
302409              "approach": {}
302410            },
302411            "quantitativeAnalysis": {
302412              "graphics": {}
302413            },
302414            "considerations": {}
302415          }
302416        },
302417        {
302418          "type": "library",
302419          "bom-ref": "pkg:npm/%40babel/plugin-syntax-async-generators@7.8.4?package-id=a5b2fcd86fd50f83",
302420          "supplier": {},
302421          "name": "@babel/plugin-syntax-async-generators",
302422          "version": "7.8.4",
302423          "licenses": [
302424            {
302425              "license": {
302426                "id": "MIT"
302427              }
302428            }
302429          ],
302430          "cpe": "cpe:2.3:a:\\@babel\\/plugin-syntax-async-generators:\\@babel\\/plugin-syntax-async-generators:7.8.4:*:*:*:*:*:*:*",
302431          "purl": "pkg:npm/%40babel/plugin-syntax-async-generators@7.8.4",
302432          "swid": {
302433            "attachment": {}
302434          },
302435          "pedigree": {},
302436          "evidence": {},
302437          "signature": {
302438            "signature": {
302439              "publicKey": {}
302440            }
302441          },
302442          "modelCard": {
302443            "modelParameters": {
302444              "approach": {}
302445            },
302446            "quantitativeAnalysis": {
302447              "graphics": {}
302448            },
302449            "considerations": {}
302450          }
302451        },
302452        {
302453          "type": "library",
302454          "bom-ref": "pkg:npm/%40babel/plugin-syntax-dynamic-import@7.8.3?package-id=2b9ab2f1c2c512cb",
302455          "supplier": {},
302456          "name": "@babel/plugin-syntax-dynamic-import",
302457          "version": "7.8.3",
302458          "licenses": [
302459            {
302460              "license": {
302461                "id": "MIT"
302462              }
302463            }
302464          ],
302465          "cpe": "cpe:2.3:a:\\@babel\\/plugin-syntax-dynamic-import:\\@babel\\/plugin-syntax-dynamic-import:7.8.3:*:*:*:*:*:*:*",
302466          "purl": "pkg:npm/%40babel/plugin-syntax-dynamic-import@7.8.3",
302467          "swid": {
302468            "attachment": {}
302469          },
302470          "pedigree": {},
302471          "evidence": {},
302472          "signature": {
302473            "signature": {
302474              "publicKey": {}
302475            }
302476          },
302477          "modelCard": {
302478            "modelParameters": {
302479              "approach": {}
302480            },
302481            "quantitativeAnalysis": {
302482              "graphics": {}
302483            },
302484            "considerations": {}
302485          }
302486        },
302487        {
302488          "type": "library",
302489          "bom-ref": "pkg:npm/%40babel/plugin-syntax-json-strings@7.8.3?package-id=9cd9eb0c5bb74e95",
302490          "supplier": {},
302491          "name": "@babel/plugin-syntax-json-strings",
302492          "version": "7.8.3",
302493          "licenses": [
302494            {
302495              "license": {
302496                "id": "MIT"
302497              }
302498            }
302499          ],
302500          "cpe": "cpe:2.3:a:\\@babel\\/plugin-syntax-json-strings:\\@babel\\/plugin-syntax-json-strings:7.8.3:*:*:*:*:*:*:*",
302501          "purl": "pkg:npm/%40babel/plugin-syntax-json-strings@7.8.3",
302502          "swid": {
302503            "attachment": {}
302504          },
302505          "pedigree": {},
302506          "evidence": {},
302507          "signature": {
302508            "signature": {
302509              "publicKey": {}
302510            }
302511          },
302512          "modelCard": {
302513            "modelParameters": {
302514              "approach": {}
302515            },
302516            "quantitativeAnalysis": {
302517              "graphics": {}
302518            },
302519            "considerations": {}
302520          }
302521        },
302522        {
302523          "type": "library",
302524          "bom-ref": "pkg:npm/%40babel/plugin-syntax-nullish-coalescing-operator@7.8.3?package-id=bb6420e9088d2514",
302525          "supplier": {},
302526          "name": "@babel/plugin-syntax-nullish-coalescing-operator",
302527          "version": "7.8.3",
302528          "licenses": [
302529            {
302530              "license": {
302531                "id": "MIT"
302532              }
302533            }
302534          ],
302535          "cpe": "cpe:2.3:a:\\@babel\\/plugin-syntax-nullish-coalescing-operator:\\@babel\\/plugin-syntax-nullish-coalescing-operator:7.8.3:*:*:*:*:*:*:*",
302536          "purl": "pkg:npm/%40babel/plugin-syntax-nullish-coalescing-operator@7.8.3",
302537          "swid": {
302538            "attachment": {}
302539          },
302540          "pedigree": {},
302541          "evidence": {},
302542          "signature": {
302543            "signature": {
302544              "publicKey": {}
302545            }
302546          },
302547          "modelCard": {
302548            "modelParameters": {
302549              "approach": {}
302550            },
302551            "quantitativeAnalysis": {
302552              "graphics": {}
302553            },
302554            "considerations": {}
302555          }
302556        },
302557        {
302558          "type": "library",
302559          "bom-ref": "pkg:npm/%40babel/plugin-syntax-numeric-separator@7.8.3?package-id=cb5eb414aab76ed2",
302560          "supplier": {},
302561          "name": "@babel/plugin-syntax-numeric-separator",
302562          "version": "7.8.3",
302563          "licenses": [
302564            {
302565              "license": {
302566                "id": "MIT"
302567              }
302568            }
302569          ],
302570          "cpe": "cpe:2.3:a:\\@babel\\/plugin-syntax-numeric-separator:\\@babel\\/plugin-syntax-numeric-separator:7.8.3:*:*:*:*:*:*:*",
302571          "purl": "pkg:npm/%40babel/plugin-syntax-numeric-separator@7.8.3",
302572          "swid": {
302573            "attachment": {}
302574          },
302575          "pedigree": {},
302576          "evidence": {},
302577          "signature": {
302578            "signature": {
302579              "publicKey": {}
302580            }
302581          },
302582          "modelCard": {
302583            "modelParameters": {
302584              "approach": {}
302585            },
302586            "quantitativeAnalysis": {
302587              "graphics": {}
302588            },
302589            "considerations": {}
302590          }
302591        },
302592        {
302593          "type": "library",
302594          "bom-ref": "pkg:npm/%40babel/plugin-syntax-object-rest-spread@7.8.3?package-id=e0e4b24163fa804d",
302595          "supplier": {},
302596          "name": "@babel/plugin-syntax-object-rest-spread",
302597          "version": "7.8.3",
302598          "licenses": [
302599            {
302600              "license": {
302601                "id": "MIT"
302602              }
302603            }
302604          ],
302605          "cpe": "cpe:2.3:a:\\@babel\\/plugin-syntax-object-rest-spread:\\@babel\\/plugin-syntax-object-rest-spread:7.8.3:*:*:*:*:*:*:*",
302606          "purl": "pkg:npm/%40babel/plugin-syntax-object-rest-spread@7.8.3",
302607          "swid": {
302608            "attachment": {}
302609          },
302610          "pedigree": {},
302611          "evidence": {},
302612          "signature": {
302613            "signature": {
302614              "publicKey": {}
302615            }
302616          },
302617          "modelCard": {
302618            "modelParameters": {
302619              "approach": {}
302620            },
302621            "quantitativeAnalysis": {
302622              "graphics": {}
302623            },
302624            "considerations": {}
302625          }
302626        },
302627        {
302628          "type": "library",
302629          "bom-ref": "pkg:npm/%40babel/plugin-syntax-optional-catch-binding@7.8.3?package-id=5d6d49f1a6ee8f52",
302630          "supplier": {},
302631          "name": "@babel/plugin-syntax-optional-catch-binding",
302632          "version": "7.8.3",
302633          "licenses": [
302634            {
302635              "license": {
302636                "id": "MIT"
302637              }
302638            }
302639          ],
302640          "cpe": "cpe:2.3:a:\\@babel\\/plugin-syntax-optional-catch-binding:\\@babel\\/plugin-syntax-optional-catch-binding:7.8.3:*:*:*:*:*:*:*",
302641          "purl": "pkg:npm/%40babel/plugin-syntax-optional-catch-binding@7.8.3",
302642          "swid": {
302643            "attachment": {}
302644          },
302645          "pedigree": {},
302646          "evidence": {},
302647          "signature": {
302648            "signature": {
302649              "publicKey": {}
302650            }
302651          },
302652          "modelCard": {
302653            "modelParameters": {
302654              "approach": {}
302655            },
302656            "quantitativeAnalysis": {
302657              "graphics": {}
302658            },
302659            "considerations": {}
302660          }
302661        },
302662        {
302663          "type": "library",
302664          "bom-ref": "pkg:npm/%40babel/plugin-syntax-optional-chaining@7.8.3?package-id=92d1da1c193f5f8f",
302665          "supplier": {},
302666          "name": "@babel/plugin-syntax-optional-chaining",
302667          "version": "7.8.3",
302668          "licenses": [
302669            {
302670              "license": {
302671                "id": "MIT"
302672              }
302673            }
302674          ],
302675          "cpe": "cpe:2.3:a:\\@babel\\/plugin-syntax-optional-chaining:\\@babel\\/plugin-syntax-optional-chaining:7.8.3:*:*:*:*:*:*:*",
302676          "purl": "pkg:npm/%40babel/plugin-syntax-optional-chaining@7.8.3",
302677          "swid": {
302678            "attachment": {}
302679          },
302680          "pedigree": {},
302681          "evidence": {},
302682          "signature": {
302683            "signature": {
302684              "publicKey": {}
302685            }
302686          },
302687          "modelCard": {
302688            "modelParameters": {
302689              "approach": {}
302690            },
302691            "quantitativeAnalysis": {
302692              "graphics": {}
302693            },
302694            "considerations": {}
302695          }
302696        },
302697        {
302698          "type": "library",
302699          "bom-ref": "pkg:npm/%40babel/plugin-syntax-top-level-await@7.8.3?package-id=724fa3d0f2e3fbf0",
302700          "supplier": {},
302701          "name": "@babel/plugin-syntax-top-level-await",
302702          "version": "7.8.3",
302703          "licenses": [
302704            {
302705              "license": {
302706                "id": "MIT"
302707              }
302708            }
302709          ],
302710          "cpe": "cpe:2.3:a:\\@babel\\/plugin-syntax-top-level-await:\\@babel\\/plugin-syntax-top-level-await:7.8.3:*:*:*:*:*:*:*",
302711          "purl": "pkg:npm/%40babel/plugin-syntax-top-level-await@7.8.3",
302712          "swid": {
302713            "attachment": {}
302714          },
302715          "pedigree": {},
302716          "evidence": {},
302717          "signature": {
302718            "signature": {
302719              "publicKey": {}
302720            }
302721          },
302722          "modelCard": {
302723            "modelParameters": {
302724              "approach": {}
302725            },
302726            "quantitativeAnalysis": {
302727              "graphics": {}
302728            },
302729            "considerations": {}
302730          }
302731        },
302732        {
302733          "type": "library",
302734          "bom-ref": "pkg:npm/%40babel/plugin-transform-arrow-functions@7.8.3?package-id=376ffafc440e5aa7",
302735          "supplier": {},
302736          "name": "@babel/plugin-transform-arrow-functions",
302737          "version": "7.8.3",
302738          "licenses": [
302739            {
302740              "license": {
302741                "id": "MIT"
302742              }
302743            }
302744          ],
302745          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-arrow-functions:\\@babel\\/plugin-transform-arrow-functions:7.8.3:*:*:*:*:*:*:*",
302746          "purl": "pkg:npm/%40babel/plugin-transform-arrow-functions@7.8.3",
302747          "swid": {
302748            "attachment": {}
302749          },
302750          "pedigree": {},
302751          "evidence": {},
302752          "signature": {
302753            "signature": {
302754              "publicKey": {}
302755            }
302756          },
302757          "modelCard": {
302758            "modelParameters": {
302759              "approach": {}
302760            },
302761            "quantitativeAnalysis": {
302762              "graphics": {}
302763            },
302764            "considerations": {}
302765          }
302766        },
302767        {
302768          "type": "library",
302769          "bom-ref": "pkg:npm/%40babel/plugin-transform-async-to-generator@7.8.3?package-id=763edda70ca558ba",
302770          "supplier": {},
302771          "name": "@babel/plugin-transform-async-to-generator",
302772          "version": "7.8.3",
302773          "licenses": [
302774            {
302775              "license": {
302776                "id": "MIT"
302777              }
302778            }
302779          ],
302780          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-async-to-generator:\\@babel\\/plugin-transform-async-to-generator:7.8.3:*:*:*:*:*:*:*",
302781          "purl": "pkg:npm/%40babel/plugin-transform-async-to-generator@7.8.3",
302782          "swid": {
302783            "attachment": {}
302784          },
302785          "pedigree": {},
302786          "evidence": {},
302787          "signature": {
302788            "signature": {
302789              "publicKey": {}
302790            }
302791          },
302792          "modelCard": {
302793            "modelParameters": {
302794              "approach": {}
302795            },
302796            "quantitativeAnalysis": {
302797              "graphics": {}
302798            },
302799            "considerations": {}
302800          }
302801        },
302802        {
302803          "type": "library",
302804          "bom-ref": "pkg:npm/%40babel/plugin-transform-block-scoped-functions@7.8.3?package-id=bfa8d481233f4c0b",
302805          "supplier": {},
302806          "name": "@babel/plugin-transform-block-scoped-functions",
302807          "version": "7.8.3",
302808          "licenses": [
302809            {
302810              "license": {
302811                "id": "MIT"
302812              }
302813            }
302814          ],
302815          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-block-scoped-functions:\\@babel\\/plugin-transform-block-scoped-functions:7.8.3:*:*:*:*:*:*:*",
302816          "purl": "pkg:npm/%40babel/plugin-transform-block-scoped-functions@7.8.3",
302817          "swid": {
302818            "attachment": {}
302819          },
302820          "pedigree": {},
302821          "evidence": {},
302822          "signature": {
302823            "signature": {
302824              "publicKey": {}
302825            }
302826          },
302827          "modelCard": {
302828            "modelParameters": {
302829              "approach": {}
302830            },
302831            "quantitativeAnalysis": {
302832              "graphics": {}
302833            },
302834            "considerations": {}
302835          }
302836        },
302837        {
302838          "type": "library",
302839          "bom-ref": "pkg:npm/%40babel/plugin-transform-block-scoping@7.8.3?package-id=b05b0226ef72745b",
302840          "supplier": {},
302841          "name": "@babel/plugin-transform-block-scoping",
302842          "version": "7.8.3",
302843          "licenses": [
302844            {
302845              "license": {
302846                "id": "MIT"
302847              }
302848            }
302849          ],
302850          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-block-scoping:\\@babel\\/plugin-transform-block-scoping:7.8.3:*:*:*:*:*:*:*",
302851          "purl": "pkg:npm/%40babel/plugin-transform-block-scoping@7.8.3",
302852          "swid": {
302853            "attachment": {}
302854          },
302855          "pedigree": {},
302856          "evidence": {},
302857          "signature": {
302858            "signature": {
302859              "publicKey": {}
302860            }
302861          },
302862          "modelCard": {
302863            "modelParameters": {
302864              "approach": {}
302865            },
302866            "quantitativeAnalysis": {
302867              "graphics": {}
302868            },
302869            "considerations": {}
302870          }
302871        },
302872        {
302873          "type": "library",
302874          "bom-ref": "pkg:npm/%40babel/plugin-transform-classes@7.9.5?package-id=19497cd3085287b6",
302875          "supplier": {},
302876          "name": "@babel/plugin-transform-classes",
302877          "version": "7.9.5",
302878          "licenses": [
302879            {
302880              "license": {
302881                "id": "MIT"
302882              }
302883            }
302884          ],
302885          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-classes:\\@babel\\/plugin-transform-classes:7.9.5:*:*:*:*:*:*:*",
302886          "purl": "pkg:npm/%40babel/plugin-transform-classes@7.9.5",
302887          "swid": {
302888            "attachment": {}
302889          },
302890          "pedigree": {},
302891          "evidence": {},
302892          "signature": {
302893            "signature": {
302894              "publicKey": {}
302895            }
302896          },
302897          "modelCard": {
302898            "modelParameters": {
302899              "approach": {}
302900            },
302901            "quantitativeAnalysis": {
302902              "graphics": {}
302903            },
302904            "considerations": {}
302905          }
302906        },
302907        {
302908          "type": "library",
302909          "bom-ref": "pkg:npm/%40babel/plugin-transform-computed-properties@7.8.3?package-id=990cd68175d40a17",
302910          "supplier": {},
302911          "name": "@babel/plugin-transform-computed-properties",
302912          "version": "7.8.3",
302913          "licenses": [
302914            {
302915              "license": {
302916                "id": "MIT"
302917              }
302918            }
302919          ],
302920          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-computed-properties:\\@babel\\/plugin-transform-computed-properties:7.8.3:*:*:*:*:*:*:*",
302921          "purl": "pkg:npm/%40babel/plugin-transform-computed-properties@7.8.3",
302922          "swid": {
302923            "attachment": {}
302924          },
302925          "pedigree": {},
302926          "evidence": {},
302927          "signature": {
302928            "signature": {
302929              "publicKey": {}
302930            }
302931          },
302932          "modelCard": {
302933            "modelParameters": {
302934              "approach": {}
302935            },
302936            "quantitativeAnalysis": {
302937              "graphics": {}
302938            },
302939            "considerations": {}
302940          }
302941        },
302942        {
302943          "type": "library",
302944          "bom-ref": "pkg:npm/%40babel/plugin-transform-destructuring@7.9.5?package-id=6fd673beeb619fad",
302945          "supplier": {},
302946          "name": "@babel/plugin-transform-destructuring",
302947          "version": "7.9.5",
302948          "licenses": [
302949            {
302950              "license": {
302951                "id": "MIT"
302952              }
302953            }
302954          ],
302955          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-destructuring:\\@babel\\/plugin-transform-destructuring:7.9.5:*:*:*:*:*:*:*",
302956          "purl": "pkg:npm/%40babel/plugin-transform-destructuring@7.9.5",
302957          "swid": {
302958            "attachment": {}
302959          },
302960          "pedigree": {},
302961          "evidence": {},
302962          "signature": {
302963            "signature": {
302964              "publicKey": {}
302965            }
302966          },
302967          "modelCard": {
302968            "modelParameters": {
302969              "approach": {}
302970            },
302971            "quantitativeAnalysis": {
302972              "graphics": {}
302973            },
302974            "considerations": {}
302975          }
302976        },
302977        {
302978          "type": "library",
302979          "bom-ref": "pkg:npm/%40babel/plugin-transform-dotall-regex@7.8.3?package-id=c906b380ccf53d3b",
302980          "supplier": {},
302981          "name": "@babel/plugin-transform-dotall-regex",
302982          "version": "7.8.3",
302983          "licenses": [
302984            {
302985              "license": {
302986                "id": "MIT"
302987              }
302988            }
302989          ],
302990          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-dotall-regex:\\@babel\\/plugin-transform-dotall-regex:7.8.3:*:*:*:*:*:*:*",
302991          "purl": "pkg:npm/%40babel/plugin-transform-dotall-regex@7.8.3",
302992          "swid": {
302993            "attachment": {}
302994          },
302995          "pedigree": {},
302996          "evidence": {},
302997          "signature": {
302998            "signature": {
302999              "publicKey": {}
303000            }
303001          },
303002          "modelCard": {
303003            "modelParameters": {
303004              "approach": {}
303005            },
303006            "quantitativeAnalysis": {
303007              "graphics": {}
303008            },
303009            "considerations": {}
303010          }
303011        },
303012        {
303013          "type": "library",
303014          "bom-ref": "pkg:npm/%40babel/plugin-transform-duplicate-keys@7.8.3?package-id=7b28b004bd7eac67",
303015          "supplier": {},
303016          "name": "@babel/plugin-transform-duplicate-keys",
303017          "version": "7.8.3",
303018          "licenses": [
303019            {
303020              "license": {
303021                "id": "MIT"
303022              }
303023            }
303024          ],
303025          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-duplicate-keys:\\@babel\\/plugin-transform-duplicate-keys:7.8.3:*:*:*:*:*:*:*",
303026          "purl": "pkg:npm/%40babel/plugin-transform-duplicate-keys@7.8.3",
303027          "swid": {
303028            "attachment": {}
303029          },
303030          "pedigree": {},
303031          "evidence": {},
303032          "signature": {
303033            "signature": {
303034              "publicKey": {}
303035            }
303036          },
303037          "modelCard": {
303038            "modelParameters": {
303039              "approach": {}
303040            },
303041            "quantitativeAnalysis": {
303042              "graphics": {}
303043            },
303044            "considerations": {}
303045          }
303046        },
303047        {
303048          "type": "library",
303049          "bom-ref": "pkg:npm/%40babel/plugin-transform-exponentiation-operator@7.8.3?package-id=9cd81e6127d1b968",
303050          "supplier": {},
303051          "name": "@babel/plugin-transform-exponentiation-operator",
303052          "version": "7.8.3",
303053          "licenses": [
303054            {
303055              "license": {
303056                "id": "MIT"
303057              }
303058            }
303059          ],
303060          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-exponentiation-operator:\\@babel\\/plugin-transform-exponentiation-operator:7.8.3:*:*:*:*:*:*:*",
303061          "purl": "pkg:npm/%40babel/plugin-transform-exponentiation-operator@7.8.3",
303062          "swid": {
303063            "attachment": {}
303064          },
303065          "pedigree": {},
303066          "evidence": {},
303067          "signature": {
303068            "signature": {
303069              "publicKey": {}
303070            }
303071          },
303072          "modelCard": {
303073            "modelParameters": {
303074              "approach": {}
303075            },
303076            "quantitativeAnalysis": {
303077              "graphics": {}
303078            },
303079            "considerations": {}
303080          }
303081        },
303082        {
303083          "type": "library",
303084          "bom-ref": "pkg:npm/%40babel/plugin-transform-for-of@7.9.0?package-id=66c5377010dedc14",
303085          "supplier": {},
303086          "name": "@babel/plugin-transform-for-of",
303087          "version": "7.9.0",
303088          "licenses": [
303089            {
303090              "license": {
303091                "id": "MIT"
303092              }
303093            }
303094          ],
303095          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-for-of:\\@babel\\/plugin-transform-for-of:7.9.0:*:*:*:*:*:*:*",
303096          "purl": "pkg:npm/%40babel/plugin-transform-for-of@7.9.0",
303097          "swid": {
303098            "attachment": {}
303099          },
303100          "pedigree": {},
303101          "evidence": {},
303102          "signature": {
303103            "signature": {
303104              "publicKey": {}
303105            }
303106          },
303107          "modelCard": {
303108            "modelParameters": {
303109              "approach": {}
303110            },
303111            "quantitativeAnalysis": {
303112              "graphics": {}
303113            },
303114            "considerations": {}
303115          }
303116        },
303117        {
303118          "type": "library",
303119          "bom-ref": "pkg:npm/%40babel/plugin-transform-function-name@7.8.3?package-id=4e4d1ac81be58da3",
303120          "supplier": {},
303121          "name": "@babel/plugin-transform-function-name",
303122          "version": "7.8.3",
303123          "licenses": [
303124            {
303125              "license": {
303126                "id": "MIT"
303127              }
303128            }
303129          ],
303130          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-function-name:\\@babel\\/plugin-transform-function-name:7.8.3:*:*:*:*:*:*:*",
303131          "purl": "pkg:npm/%40babel/plugin-transform-function-name@7.8.3",
303132          "swid": {
303133            "attachment": {}
303134          },
303135          "pedigree": {},
303136          "evidence": {},
303137          "signature": {
303138            "signature": {
303139              "publicKey": {}
303140            }
303141          },
303142          "modelCard": {
303143            "modelParameters": {
303144              "approach": {}
303145            },
303146            "quantitativeAnalysis": {
303147              "graphics": {}
303148            },
303149            "considerations": {}
303150          }
303151        },
303152        {
303153          "type": "library",
303154          "bom-ref": "pkg:npm/%40babel/plugin-transform-literals@7.8.3?package-id=2a36fc82aafe4d25",
303155          "supplier": {},
303156          "name": "@babel/plugin-transform-literals",
303157          "version": "7.8.3",
303158          "licenses": [
303159            {
303160              "license": {
303161                "id": "MIT"
303162              }
303163            }
303164          ],
303165          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-literals:\\@babel\\/plugin-transform-literals:7.8.3:*:*:*:*:*:*:*",
303166          "purl": "pkg:npm/%40babel/plugin-transform-literals@7.8.3",
303167          "swid": {
303168            "attachment": {}
303169          },
303170          "pedigree": {},
303171          "evidence": {},
303172          "signature": {
303173            "signature": {
303174              "publicKey": {}
303175            }
303176          },
303177          "modelCard": {
303178            "modelParameters": {
303179              "approach": {}
303180            },
303181            "quantitativeAnalysis": {
303182              "graphics": {}
303183            },
303184            "considerations": {}
303185          }
303186        },
303187        {
303188          "type": "library",
303189          "bom-ref": "pkg:npm/%40babel/plugin-transform-member-expression-literals@7.8.3?package-id=df930e219dd1a131",
303190          "supplier": {},
303191          "name": "@babel/plugin-transform-member-expression-literals",
303192          "version": "7.8.3",
303193          "licenses": [
303194            {
303195              "license": {
303196                "id": "MIT"
303197              }
303198            }
303199          ],
303200          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-member-expression-literals:\\@babel\\/plugin-transform-member-expression-literals:7.8.3:*:*:*:*:*:*:*",
303201          "purl": "pkg:npm/%40babel/plugin-transform-member-expression-literals@7.8.3",
303202          "swid": {
303203            "attachment": {}
303204          },
303205          "pedigree": {},
303206          "evidence": {},
303207          "signature": {
303208            "signature": {
303209              "publicKey": {}
303210            }
303211          },
303212          "modelCard": {
303213            "modelParameters": {
303214              "approach": {}
303215            },
303216            "quantitativeAnalysis": {
303217              "graphics": {}
303218            },
303219            "considerations": {}
303220          }
303221        },
303222        {
303223          "type": "library",
303224          "bom-ref": "pkg:npm/%40babel/plugin-transform-modules-amd@7.9.6?package-id=481e380d0013659c",
303225          "supplier": {},
303226          "name": "@babel/plugin-transform-modules-amd",
303227          "version": "7.9.6",
303228          "licenses": [
303229            {
303230              "license": {
303231                "id": "MIT"
303232              }
303233            }
303234          ],
303235          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-modules-amd:\\@babel\\/plugin-transform-modules-amd:7.9.6:*:*:*:*:*:*:*",
303236          "purl": "pkg:npm/%40babel/plugin-transform-modules-amd@7.9.6",
303237          "swid": {
303238            "attachment": {}
303239          },
303240          "pedigree": {},
303241          "evidence": {},
303242          "signature": {
303243            "signature": {
303244              "publicKey": {}
303245            }
303246          },
303247          "modelCard": {
303248            "modelParameters": {
303249              "approach": {}
303250            },
303251            "quantitativeAnalysis": {
303252              "graphics": {}
303253            },
303254            "considerations": {}
303255          }
303256        },
303257        {
303258          "type": "library",
303259          "bom-ref": "pkg:npm/%40babel/plugin-transform-modules-commonjs@7.9.6?package-id=8d671e16bd543a5",
303260          "supplier": {},
303261          "name": "@babel/plugin-transform-modules-commonjs",
303262          "version": "7.9.6",
303263          "licenses": [
303264            {
303265              "license": {
303266                "id": "MIT"
303267              }
303268            }
303269          ],
303270          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-modules-commonjs:\\@babel\\/plugin-transform-modules-commonjs:7.9.6:*:*:*:*:*:*:*",
303271          "purl": "pkg:npm/%40babel/plugin-transform-modules-commonjs@7.9.6",
303272          "swid": {
303273            "attachment": {}
303274          },
303275          "pedigree": {},
303276          "evidence": {},
303277          "signature": {
303278            "signature": {
303279              "publicKey": {}
303280            }
303281          },
303282          "modelCard": {
303283            "modelParameters": {
303284              "approach": {}
303285            },
303286            "quantitativeAnalysis": {
303287              "graphics": {}
303288            },
303289            "considerations": {}
303290          }
303291        },
303292        {
303293          "type": "library",
303294          "bom-ref": "pkg:npm/%40babel/plugin-transform-modules-systemjs@7.9.6?package-id=8cc2c10038ad5ffe",
303295          "supplier": {},
303296          "name": "@babel/plugin-transform-modules-systemjs",
303297          "version": "7.9.6",
303298          "licenses": [
303299            {
303300              "license": {
303301                "id": "MIT"
303302              }
303303            }
303304          ],
303305          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-modules-systemjs:\\@babel\\/plugin-transform-modules-systemjs:7.9.6:*:*:*:*:*:*:*",
303306          "purl": "pkg:npm/%40babel/plugin-transform-modules-systemjs@7.9.6",
303307          "swid": {
303308            "attachment": {}
303309          },
303310          "pedigree": {},
303311          "evidence": {},
303312          "signature": {
303313            "signature": {
303314              "publicKey": {}
303315            }
303316          },
303317          "modelCard": {
303318            "modelParameters": {
303319              "approach": {}
303320            },
303321            "quantitativeAnalysis": {
303322              "graphics": {}
303323            },
303324            "considerations": {}
303325          }
303326        },
303327        {
303328          "type": "library",
303329          "bom-ref": "pkg:npm/%40babel/plugin-transform-modules-umd@7.9.0?package-id=719dccaf8412875a",
303330          "supplier": {},
303331          "name": "@babel/plugin-transform-modules-umd",
303332          "version": "7.9.0",
303333          "licenses": [
303334            {
303335              "license": {
303336                "id": "MIT"
303337              }
303338            }
303339          ],
303340          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-modules-umd:\\@babel\\/plugin-transform-modules-umd:7.9.0:*:*:*:*:*:*:*",
303341          "purl": "pkg:npm/%40babel/plugin-transform-modules-umd@7.9.0",
303342          "swid": {
303343            "attachment": {}
303344          },
303345          "pedigree": {},
303346          "evidence": {},
303347          "signature": {
303348            "signature": {
303349              "publicKey": {}
303350            }
303351          },
303352          "modelCard": {
303353            "modelParameters": {
303354              "approach": {}
303355            },
303356            "quantitativeAnalysis": {
303357              "graphics": {}
303358            },
303359            "considerations": {}
303360          }
303361        },
303362        {
303363          "type": "library",
303364          "bom-ref": "pkg:npm/%40babel/plugin-transform-named-capturing-groups-regex@7.8.3?package-id=a6c1df4f0b37343e",
303365          "supplier": {},
303366          "name": "@babel/plugin-transform-named-capturing-groups-regex",
303367          "version": "7.8.3",
303368          "licenses": [
303369            {
303370              "license": {
303371                "id": "MIT"
303372              }
303373            }
303374          ],
303375          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-named-capturing-groups-regex:\\@babel\\/plugin-transform-named-capturing-groups-regex:7.8.3:*:*:*:*:*:*:*",
303376          "purl": "pkg:npm/%40babel/plugin-transform-named-capturing-groups-regex@7.8.3",
303377          "swid": {
303378            "attachment": {}
303379          },
303380          "pedigree": {},
303381          "evidence": {},
303382          "signature": {
303383            "signature": {
303384              "publicKey": {}
303385            }
303386          },
303387          "modelCard": {
303388            "modelParameters": {
303389              "approach": {}
303390            },
303391            "quantitativeAnalysis": {
303392              "graphics": {}
303393            },
303394            "considerations": {}
303395          }
303396        },
303397        {
303398          "type": "library",
303399          "bom-ref": "pkg:npm/%40babel/plugin-transform-new-target@7.8.3?package-id=cf362202094bf57a",
303400          "supplier": {},
303401          "name": "@babel/plugin-transform-new-target",
303402          "version": "7.8.3",
303403          "licenses": [
303404            {
303405              "license": {
303406                "id": "MIT"
303407              }
303408            }
303409          ],
303410          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-new-target:\\@babel\\/plugin-transform-new-target:7.8.3:*:*:*:*:*:*:*",
303411          "purl": "pkg:npm/%40babel/plugin-transform-new-target@7.8.3",
303412          "swid": {
303413            "attachment": {}
303414          },
303415          "pedigree": {},
303416          "evidence": {},
303417          "signature": {
303418            "signature": {
303419              "publicKey": {}
303420            }
303421          },
303422          "modelCard": {
303423            "modelParameters": {
303424              "approach": {}
303425            },
303426            "quantitativeAnalysis": {
303427              "graphics": {}
303428            },
303429            "considerations": {}
303430          }
303431        },
303432        {
303433          "type": "library",
303434          "bom-ref": "pkg:npm/%40babel/plugin-transform-object-super@7.8.3?package-id=b17795f428821730",
303435          "supplier": {},
303436          "name": "@babel/plugin-transform-object-super",
303437          "version": "7.8.3",
303438          "licenses": [
303439            {
303440              "license": {
303441                "id": "MIT"
303442              }
303443            }
303444          ],
303445          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-object-super:\\@babel\\/plugin-transform-object-super:7.8.3:*:*:*:*:*:*:*",
303446          "purl": "pkg:npm/%40babel/plugin-transform-object-super@7.8.3",
303447          "swid": {
303448            "attachment": {}
303449          },
303450          "pedigree": {},
303451          "evidence": {},
303452          "signature": {
303453            "signature": {
303454              "publicKey": {}
303455            }
303456          },
303457          "modelCard": {
303458            "modelParameters": {
303459              "approach": {}
303460            },
303461            "quantitativeAnalysis": {
303462              "graphics": {}
303463            },
303464            "considerations": {}
303465          }
303466        },
303467        {
303468          "type": "library",
303469          "bom-ref": "pkg:npm/%40babel/plugin-transform-parameters@7.9.5?package-id=62a808b7386fffcb",
303470          "supplier": {},
303471          "name": "@babel/plugin-transform-parameters",
303472          "version": "7.9.5",
303473          "licenses": [
303474            {
303475              "license": {
303476                "id": "MIT"
303477              }
303478            }
303479          ],
303480          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-parameters:\\@babel\\/plugin-transform-parameters:7.9.5:*:*:*:*:*:*:*",
303481          "purl": "pkg:npm/%40babel/plugin-transform-parameters@7.9.5",
303482          "swid": {
303483            "attachment": {}
303484          },
303485          "pedigree": {},
303486          "evidence": {},
303487          "signature": {
303488            "signature": {
303489              "publicKey": {}
303490            }
303491          },
303492          "modelCard": {
303493            "modelParameters": {
303494              "approach": {}
303495            },
303496            "quantitativeAnalysis": {
303497              "graphics": {}
303498            },
303499            "considerations": {}
303500          }
303501        },
303502        {
303503          "type": "library",
303504          "bom-ref": "pkg:npm/%40babel/plugin-transform-property-literals@7.8.3?package-id=67a7ba3381d8d371",
303505          "supplier": {},
303506          "name": "@babel/plugin-transform-property-literals",
303507          "version": "7.8.3",
303508          "licenses": [
303509            {
303510              "license": {
303511                "id": "MIT"
303512              }
303513            }
303514          ],
303515          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-property-literals:\\@babel\\/plugin-transform-property-literals:7.8.3:*:*:*:*:*:*:*",
303516          "purl": "pkg:npm/%40babel/plugin-transform-property-literals@7.8.3",
303517          "swid": {
303518            "attachment": {}
303519          },
303520          "pedigree": {},
303521          "evidence": {},
303522          "signature": {
303523            "signature": {
303524              "publicKey": {}
303525            }
303526          },
303527          "modelCard": {
303528            "modelParameters": {
303529              "approach": {}
303530            },
303531            "quantitativeAnalysis": {
303532              "graphics": {}
303533            },
303534            "considerations": {}
303535          }
303536        },
303537        {
303538          "type": "library",
303539          "bom-ref": "pkg:npm/%40babel/plugin-transform-regenerator@7.8.7?package-id=848f305780c0445b",
303540          "supplier": {},
303541          "name": "@babel/plugin-transform-regenerator",
303542          "version": "7.8.7",
303543          "licenses": [
303544            {
303545              "license": {
303546                "id": "MIT"
303547              }
303548            }
303549          ],
303550          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-regenerator:\\@babel\\/plugin-transform-regenerator:7.8.7:*:*:*:*:*:*:*",
303551          "purl": "pkg:npm/%40babel/plugin-transform-regenerator@7.8.7",
303552          "swid": {
303553            "attachment": {}
303554          },
303555          "pedigree": {},
303556          "evidence": {},
303557          "signature": {
303558            "signature": {
303559              "publicKey": {}
303560            }
303561          },
303562          "modelCard": {
303563            "modelParameters": {
303564              "approach": {}
303565            },
303566            "quantitativeAnalysis": {
303567              "graphics": {}
303568            },
303569            "considerations": {}
303570          }
303571        },
303572        {
303573          "type": "library",
303574          "bom-ref": "pkg:npm/%40babel/plugin-transform-reserved-words@7.8.3?package-id=182f4fc93a66510d",
303575          "supplier": {},
303576          "name": "@babel/plugin-transform-reserved-words",
303577          "version": "7.8.3",
303578          "licenses": [
303579            {
303580              "license": {
303581                "id": "MIT"
303582              }
303583            }
303584          ],
303585          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-reserved-words:\\@babel\\/plugin-transform-reserved-words:7.8.3:*:*:*:*:*:*:*",
303586          "purl": "pkg:npm/%40babel/plugin-transform-reserved-words@7.8.3",
303587          "swid": {
303588            "attachment": {}
303589          },
303590          "pedigree": {},
303591          "evidence": {},
303592          "signature": {
303593            "signature": {
303594              "publicKey": {}
303595            }
303596          },
303597          "modelCard": {
303598            "modelParameters": {
303599              "approach": {}
303600            },
303601            "quantitativeAnalysis": {
303602              "graphics": {}
303603            },
303604            "considerations": {}
303605          }
303606        },
303607        {
303608          "type": "library",
303609          "bom-ref": "pkg:npm/%40babel/plugin-transform-shorthand-properties@7.8.3?package-id=d896029a1725dcc2",
303610          "supplier": {},
303611          "name": "@babel/plugin-transform-shorthand-properties",
303612          "version": "7.8.3",
303613          "licenses": [
303614            {
303615              "license": {
303616                "id": "MIT"
303617              }
303618            }
303619          ],
303620          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-shorthand-properties:\\@babel\\/plugin-transform-shorthand-properties:7.8.3:*:*:*:*:*:*:*",
303621          "purl": "pkg:npm/%40babel/plugin-transform-shorthand-properties@7.8.3",
303622          "swid": {
303623            "attachment": {}
303624          },
303625          "pedigree": {},
303626          "evidence": {},
303627          "signature": {
303628            "signature": {
303629              "publicKey": {}
303630            }
303631          },
303632          "modelCard": {
303633            "modelParameters": {
303634              "approach": {}
303635            },
303636            "quantitativeAnalysis": {
303637              "graphics": {}
303638            },
303639            "considerations": {}
303640          }
303641        },
303642        {
303643          "type": "library",
303644          "bom-ref": "pkg:npm/%40babel/plugin-transform-spread@7.8.3?package-id=3365398a5759255a",
303645          "supplier": {},
303646          "name": "@babel/plugin-transform-spread",
303647          "version": "7.8.3",
303648          "licenses": [
303649            {
303650              "license": {
303651                "id": "MIT"
303652              }
303653            }
303654          ],
303655          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-spread:\\@babel\\/plugin-transform-spread:7.8.3:*:*:*:*:*:*:*",
303656          "purl": "pkg:npm/%40babel/plugin-transform-spread@7.8.3",
303657          "swid": {
303658            "attachment": {}
303659          },
303660          "pedigree": {},
303661          "evidence": {},
303662          "signature": {
303663            "signature": {
303664              "publicKey": {}
303665            }
303666          },
303667          "modelCard": {
303668            "modelParameters": {
303669              "approach": {}
303670            },
303671            "quantitativeAnalysis": {
303672              "graphics": {}
303673            },
303674            "considerations": {}
303675          }
303676        },
303677        {
303678          "type": "library",
303679          "bom-ref": "pkg:npm/%40babel/plugin-transform-sticky-regex@7.8.3?package-id=51734186e74bd3c3",
303680          "supplier": {},
303681          "name": "@babel/plugin-transform-sticky-regex",
303682          "version": "7.8.3",
303683          "licenses": [
303684            {
303685              "license": {
303686                "id": "MIT"
303687              }
303688            }
303689          ],
303690          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-sticky-regex:\\@babel\\/plugin-transform-sticky-regex:7.8.3:*:*:*:*:*:*:*",
303691          "purl": "pkg:npm/%40babel/plugin-transform-sticky-regex@7.8.3",
303692          "swid": {
303693            "attachment": {}
303694          },
303695          "pedigree": {},
303696          "evidence": {},
303697          "signature": {
303698            "signature": {
303699              "publicKey": {}
303700            }
303701          },
303702          "modelCard": {
303703            "modelParameters": {
303704              "approach": {}
303705            },
303706            "quantitativeAnalysis": {
303707              "graphics": {}
303708            },
303709            "considerations": {}
303710          }
303711        },
303712        {
303713          "type": "library",
303714          "bom-ref": "pkg:npm/%40babel/plugin-transform-template-literals@7.8.3?package-id=e9bbd1906620ee39",
303715          "supplier": {},
303716          "name": "@babel/plugin-transform-template-literals",
303717          "version": "7.8.3",
303718          "licenses": [
303719            {
303720              "license": {
303721                "id": "MIT"
303722              }
303723            }
303724          ],
303725          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-template-literals:\\@babel\\/plugin-transform-template-literals:7.8.3:*:*:*:*:*:*:*",
303726          "purl": "pkg:npm/%40babel/plugin-transform-template-literals@7.8.3",
303727          "swid": {
303728            "attachment": {}
303729          },
303730          "pedigree": {},
303731          "evidence": {},
303732          "signature": {
303733            "signature": {
303734              "publicKey": {}
303735            }
303736          },
303737          "modelCard": {
303738            "modelParameters": {
303739              "approach": {}
303740            },
303741            "quantitativeAnalysis": {
303742              "graphics": {}
303743            },
303744            "considerations": {}
303745          }
303746        },
303747        {
303748          "type": "library",
303749          "bom-ref": "pkg:npm/%40babel/plugin-transform-typeof-symbol@7.8.4?package-id=1bcbbb9d469c0574",
303750          "supplier": {},
303751          "name": "@babel/plugin-transform-typeof-symbol",
303752          "version": "7.8.4",
303753          "licenses": [
303754            {
303755              "license": {
303756                "id": "MIT"
303757              }
303758            }
303759          ],
303760          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-typeof-symbol:\\@babel\\/plugin-transform-typeof-symbol:7.8.4:*:*:*:*:*:*:*",
303761          "purl": "pkg:npm/%40babel/plugin-transform-typeof-symbol@7.8.4",
303762          "swid": {
303763            "attachment": {}
303764          },
303765          "pedigree": {},
303766          "evidence": {},
303767          "signature": {
303768            "signature": {
303769              "publicKey": {}
303770            }
303771          },
303772          "modelCard": {
303773            "modelParameters": {
303774              "approach": {}
303775            },
303776            "quantitativeAnalysis": {
303777              "graphics": {}
303778            },
303779            "considerations": {}
303780          }
303781        },
303782        {
303783          "type": "library",
303784          "bom-ref": "pkg:npm/%40babel/plugin-transform-unicode-regex@7.8.3?package-id=4cf39fe4bada5ea5",
303785          "supplier": {},
303786          "name": "@babel/plugin-transform-unicode-regex",
303787          "version": "7.8.3",
303788          "licenses": [
303789            {
303790              "license": {
303791                "id": "MIT"
303792              }
303793            }
303794          ],
303795          "cpe": "cpe:2.3:a:\\@babel\\/plugin-transform-unicode-regex:\\@babel\\/plugin-transform-unicode-regex:7.8.3:*:*:*:*:*:*:*",
303796          "purl": "pkg:npm/%40babel/plugin-transform-unicode-regex@7.8.3",
303797          "swid": {
303798            "attachment": {}
303799          },
303800          "pedigree": {},
303801          "evidence": {},
303802          "signature": {
303803            "signature": {
303804              "publicKey": {}
303805            }
303806          },
303807          "modelCard": {
303808            "modelParameters": {
303809              "approach": {}
303810            },
303811            "quantitativeAnalysis": {
303812              "graphics": {}
303813            },
303814            "considerations": {}
303815          }
303816        },
303817        {
303818          "type": "library",
303819          "bom-ref": "pkg:npm/%40babel/preset-env@7.9.0?package-id=8c805bfa8e62bda8",
303820          "supplier": {},
303821          "name": "@babel/preset-env",
303822          "version": "7.9.0",
303823          "licenses": [
303824            {
303825              "license": {
303826                "id": "MIT"
303827              }
303828            }
303829          ],
303830          "cpe": "cpe:2.3:a:\\@babel\\/preset-env:\\@babel\\/preset-env:7.9.0:*:*:*:*:*:*:*",
303831          "purl": "pkg:npm/%40babel/preset-env@7.9.0",
303832          "swid": {
303833            "attachment": {}
303834          },
303835          "pedigree": {},
303836          "evidence": {},
303837          "signature": {
303838            "signature": {
303839              "publicKey": {}
303840            }
303841          },
303842          "modelCard": {
303843            "modelParameters": {
303844              "approach": {}
303845            },
303846            "quantitativeAnalysis": {
303847              "graphics": {}
303848            },
303849            "considerations": {}
303850          }
303851        },
303852        {
303853          "type": "library",
303854          "bom-ref": "pkg:npm/%40babel/preset-modules@0.1.3?package-id=468495008edf04a",
303855          "supplier": {},
303856          "name": "@babel/preset-modules",
303857          "version": "0.1.3",
303858          "licenses": [
303859            {
303860              "license": {
303861                "id": "MIT"
303862              }
303863            }
303864          ],
303865          "cpe": "cpe:2.3:a:\\@babel\\/preset-modules:\\@babel\\/preset-modules:0.1.3:*:*:*:*:*:*:*",
303866          "purl": "pkg:npm/%40babel/preset-modules@0.1.3",
303867          "swid": {
303868            "attachment": {}
303869          },
303870          "pedigree": {},
303871          "evidence": {},
303872          "signature": {
303873            "signature": {
303874              "publicKey": {}
303875            }
303876          },
303877          "modelCard": {
303878            "modelParameters": {
303879              "approach": {}
303880            },
303881            "quantitativeAnalysis": {
303882              "graphics": {}
303883            },
303884            "considerations": {}
303885          }
303886        },
303887        {
303888          "type": "library",
303889          "bom-ref": "pkg:npm/%40babel/runtime@7.9.6?package-id=3eeeda72ef9ff35c",
303890          "supplier": {},
303891          "name": "@babel/runtime",
303892          "version": "7.9.6",
303893          "licenses": [
303894            {
303895              "license": {
303896                "id": "MIT"
303897              }
303898            }
303899          ],
303900          "cpe": "cpe:2.3:a:\\@babel\\/runtime:\\@babel\\/runtime:7.9.6:*:*:*:*:*:*:*",
303901          "purl": "pkg:npm/%40babel/runtime@7.9.6",
303902          "swid": {
303903            "attachment": {}
303904          },
303905          "pedigree": {},
303906          "evidence": {},
303907          "signature": {
303908            "signature": {
303909              "publicKey": {}
303910            }
303911          },
303912          "modelCard": {
303913            "modelParameters": {
303914              "approach": {}
303915            },
303916            "quantitativeAnalysis": {
303917              "graphics": {}
303918            },
303919            "considerations": {}
303920          }
303921        },
303922        {
303923          "type": "library",
303924          "bom-ref": "pkg:npm/%40babel/template@7.16.0?package-id=8e8c991aee661483",
303925          "supplier": {},
303926          "name": "@babel/template",
303927          "version": "7.16.0",
303928          "cpe": "cpe:2.3:a:\\@babel\\/template:\\@babel\\/template:7.16.0:*:*:*:*:*:*:*",
303929          "purl": "pkg:npm/%40babel/template@7.16.0",
303930          "swid": {
303931            "attachment": {}
303932          },
303933          "pedigree": {},
303934          "evidence": {},
303935          "signature": {
303936            "signature": {
303937              "publicKey": {}
303938            }
303939          },
303940          "modelCard": {
303941            "modelParameters": {
303942              "approach": {}
303943            },
303944            "quantitativeAnalysis": {
303945              "graphics": {}
303946            },
303947            "considerations": {}
303948          }
303949        },
303950        {
303951          "type": "library",
303952          "bom-ref": "pkg:npm/%40babel/template@7.8.6?package-id=52137a9ea9752332",
303953          "supplier": {},
303954          "name": "@babel/template",
303955          "version": "7.8.6",
303956          "licenses": [
303957            {
303958              "license": {
303959                "id": "MIT"
303960              }
303961            }
303962          ],
303963          "cpe": "cpe:2.3:a:\\@babel\\/template:\\@babel\\/template:7.8.6:*:*:*:*:*:*:*",
303964          "purl": "pkg:npm/%40babel/template@7.8.6",
303965          "swid": {
303966            "attachment": {}
303967          },
303968          "pedigree": {},
303969          "evidence": {},
303970          "signature": {
303971            "signature": {
303972              "publicKey": {}
303973            }
303974          },
303975          "modelCard": {
303976            "modelParameters": {
303977              "approach": {}
303978            },
303979            "quantitativeAnalysis": {
303980              "graphics": {}
303981            },
303982            "considerations": {}
303983          }
303984        },
303985        {
303986          "type": "library",
303987          "bom-ref": "pkg:npm/%40babel/traverse@7.16.3?package-id=ad159e6b788dfed",
303988          "supplier": {},
303989          "name": "@babel/traverse",
303990          "version": "7.16.3",
303991          "cpe": "cpe:2.3:a:\\@babel\\/traverse:\\@babel\\/traverse:7.16.3:*:*:*:*:*:*:*",
303992          "purl": "pkg:npm/%40babel/traverse@7.16.3",
303993          "swid": {
303994            "attachment": {}
303995          },
303996          "pedigree": {},
303997          "evidence": {},
303998          "signature": {
303999            "signature": {
304000              "publicKey": {}
304001            }
304002          },
304003          "modelCard": {
304004            "modelParameters": {
304005              "approach": {}
304006            },
304007            "quantitativeAnalysis": {
304008              "graphics": {}
304009            },
304010            "considerations": {}
304011          }
304012        },
304013        {
304014          "type": "library",
304015          "bom-ref": "pkg:npm/%40babel/traverse@7.9.0?package-id=47e8aabd72855d28",
304016          "supplier": {},
304017          "name": "@babel/traverse",
304018          "version": "7.9.0",
304019          "licenses": [
304020            {
304021              "license": {
304022                "id": "MIT"
304023              }
304024            }
304025          ],
304026          "cpe": "cpe:2.3:a:\\@babel\\/traverse:\\@babel\\/traverse:7.9.0:*:*:*:*:*:*:*",
304027          "purl": "pkg:npm/%40babel/traverse@7.9.0",
304028          "swid": {
304029            "attachment": {}
304030          },
304031          "pedigree": {},
304032          "evidence": {},
304033          "signature": {
304034            "signature": {
304035              "publicKey": {}
304036            }
304037          },
304038          "modelCard": {
304039            "modelParameters": {
304040              "approach": {}
304041            },
304042            "quantitativeAnalysis": {
304043              "graphics": {}
304044            },
304045            "considerations": {}
304046          }
304047        },
304048        {
304049          "type": "library",
304050          "bom-ref": "pkg:npm/%40babel/types@7.16.0?package-id=da26d6635bf027ef",
304051          "supplier": {},
304052          "name": "@babel/types",
304053          "version": "7.16.0",
304054          "cpe": "cpe:2.3:a:\\@babel\\/types:\\@babel\\/types:7.16.0:*:*:*:*:*:*:*",
304055          "purl": "pkg:npm/%40babel/types@7.16.0",
304056          "swid": {
304057            "attachment": {}
304058          },
304059          "pedigree": {},
304060          "evidence": {},
304061          "signature": {
304062            "signature": {
304063              "publicKey": {}
304064            }
304065          },
304066          "modelCard": {
304067            "modelParameters": {
304068              "approach": {}
304069            },
304070            "quantitativeAnalysis": {
304071              "graphics": {}
304072            },
304073            "considerations": {}
304074          }
304075        },
304076        {
304077          "type": "library",
304078          "bom-ref": "pkg:npm/%40babel/types@7.9.0?package-id=41107ac5f721106",
304079          "supplier": {},
304080          "name": "@babel/types",
304081          "version": "7.9.0",
304082          "licenses": [
304083            {
304084              "license": {
304085                "id": "MIT"
304086              }
304087            }
304088          ],
304089          "cpe": "cpe:2.3:a:\\@babel\\/types:\\@babel\\/types:7.9.0:*:*:*:*:*:*:*",
304090          "purl": "pkg:npm/%40babel/types@7.9.0",
304091          "swid": {
304092            "attachment": {}
304093          },
304094          "pedigree": {},
304095          "evidence": {},
304096          "signature": {
304097            "signature": {
304098              "publicKey": {}
304099            }
304100          },
304101          "modelCard": {
304102            "modelParameters": {
304103              "approach": {}
304104            },
304105            "quantitativeAnalysis": {
304106              "graphics": {}
304107            },
304108            "considerations": {}
304109          }
304110        },
304111        {
304112          "type": "library",
304113          "bom-ref": "pkg:npm/%40danielmoncada/angular-datetime-picker@9.2.2?package-id=ecc3079f36271532",
304114          "supplier": {},
304115          "name": "@danielmoncada/angular-datetime-picker",
304116          "version": "9.2.2",
304117          "licenses": [
304118            {
304119              "license": {
304120                "id": "MIT"
304121              }
304122            }
304123          ],
304124          "cpe": "cpe:2.3:a:\\@danielmoncada\\/angular-datetime-picker:\\@danielmoncada\\/angular-datetime-picker:9.2.2:*:*:*:*:*:*:*",
304125          "purl": "pkg:npm/%40danielmoncada/angular-datetime-picker@9.2.2",
304126          "swid": {
304127            "attachment": {}
304128          },
304129          "pedigree": {},
304130          "evidence": {},
304131          "signature": {
304132            "signature": {
304133              "publicKey": {}
304134            }
304135          },
304136          "modelCard": {
304137            "modelParameters": {
304138              "approach": {}
304139            },
304140            "quantitativeAnalysis": {
304141              "graphics": {}
304142            },
304143            "considerations": {}
304144          }
304145        },
304146        {
304147          "type": "library",
304148          "bom-ref": "pkg:npm/%40fortawesome/fontawesome-free@5.13.0?package-id=5745cff27cbf8704",
304149          "supplier": {},
304150          "name": "@fortawesome/fontawesome-free",
304151          "version": "5.13.0",
304152          "licenses": [
304153            {
304154              "license": {
304155                "name": "(CC-BY-4.0 AND OFL-1.1 AND MIT)"
304156              }
304157            }
304158          ],
304159          "cpe": "cpe:2.3:a:\\@fortawesome\\/fontawesome-free:\\@fortawesome\\/fontawesome-free:5.13.0:*:*:*:*:*:*:*",
304160          "purl": "pkg:npm/%40fortawesome/fontawesome-free@5.13.0",
304161          "swid": {
304162            "attachment": {}
304163          },
304164          "pedigree": {},
304165          "evidence": {},
304166          "signature": {
304167            "signature": {
304168              "publicKey": {}
304169            }
304170          },
304171          "modelCard": {
304172            "modelParameters": {
304173              "approach": {}
304174            },
304175            "quantitativeAnalysis": {
304176              "graphics": {}
304177            },
304178            "considerations": {}
304179          }
304180        },
304181        {
304182          "type": "library",
304183          "bom-ref": "pkg:npm/%40fusioncharts/accessibility@1.5.0?package-id=ccaac893cfa8d5b5",
304184          "supplier": {},
304185          "name": "@fusioncharts/accessibility",
304186          "version": "1.5.0",
304187          "licenses": [
304188            {
304189              "license": {
304190                "name": "https://www.fusioncharts.com/buy/"
304191              }
304192            }
304193          ],
304194          "cpe": "cpe:2.3:a:\\@fusioncharts\\/accessibility:\\@fusioncharts\\/accessibility:1.5.0:*:*:*:*:*:*:*",
304195          "purl": "pkg:npm/%40fusioncharts/accessibility@1.5.0",
304196          "swid": {
304197            "attachment": {}
304198          },
304199          "pedigree": {},
304200          "evidence": {},
304201          "signature": {
304202            "signature": {
304203              "publicKey": {}
304204            }
304205          },
304206          "modelCard": {
304207            "modelParameters": {
304208              "approach": {}
304209            },
304210            "quantitativeAnalysis": {
304211              "graphics": {}
304212            },
304213            "considerations": {}
304214          }
304215        },
304216        {
304217          "type": "library",
304218          "bom-ref": "pkg:npm/%40fusioncharts/charts@3.18.0?package-id=e8c58a09e0903572",
304219          "supplier": {},
304220          "name": "@fusioncharts/charts",
304221          "version": "3.18.0",
304222          "licenses": [
304223            {
304224              "license": {
304225                "name": "https://www.fusioncharts.com/buy/"
304226              }
304227            }
304228          ],
304229          "cpe": "cpe:2.3:a:\\@fusioncharts\\/charts:\\@fusioncharts\\/charts:3.18.0:*:*:*:*:*:*:*",
304230          "purl": "pkg:npm/%40fusioncharts/charts@3.18.0",
304231          "swid": {
304232            "attachment": {}
304233          },
304234          "pedigree": {},
304235          "evidence": {},
304236          "signature": {
304237            "signature": {
304238              "publicKey": {}
304239            }
304240          },
304241          "modelCard": {
304242            "modelParameters": {
304243              "approach": {}
304244            },
304245            "quantitativeAnalysis": {
304246              "graphics": {}
304247            },
304248            "considerations": {}
304249          }
304250        },
304251        {
304252          "type": "library",
304253          "bom-ref": "pkg:npm/%40fusioncharts/constructor@1.5.0?package-id=a25e0e6b4e7f76af",
304254          "supplier": {},
304255          "name": "@fusioncharts/constructor",
304256          "version": "1.5.0",
304257          "licenses": [
304258            {
304259              "license": {
304260                "name": "https://www.fusioncharts.com/buy/"
304261              }
304262            }
304263          ],
304264          "cpe": "cpe:2.3:a:\\@fusioncharts\\/constructor:\\@fusioncharts\\/constructor:1.5.0:*:*:*:*:*:*:*",
304265          "purl": "pkg:npm/%40fusioncharts/constructor@1.5.0",
304266          "swid": {
304267            "attachment": {}
304268          },
304269          "pedigree": {},
304270          "evidence": {},
304271          "signature": {
304272            "signature": {
304273              "publicKey": {}
304274            }
304275          },
304276          "modelCard": {
304277            "modelParameters": {
304278              "approach": {}
304279            },
304280            "quantitativeAnalysis": {
304281              "graphics": {}
304282            },
304283            "considerations": {}
304284          }
304285        },
304286        {
304287          "type": "library",
304288          "bom-ref": "pkg:npm/%40fusioncharts/core@1.5.0?package-id=52994e30a525bf2c",
304289          "supplier": {},
304290          "name": "@fusioncharts/core",
304291          "version": "1.5.0",
304292          "licenses": [
304293            {
304294              "license": {
304295                "name": "https://www.fusioncharts.com/buy/"
304296              }
304297            }
304298          ],
304299          "cpe": "cpe:2.3:a:\\@fusioncharts\\/core:\\@fusioncharts\\/core:1.5.0:*:*:*:*:*:*:*",
304300          "purl": "pkg:npm/%40fusioncharts/core@1.5.0",
304301          "swid": {
304302            "attachment": {}
304303          },
304304          "pedigree": {},
304305          "evidence": {},
304306          "signature": {
304307            "signature": {
304308              "publicKey": {}
304309            }
304310          },
304311          "modelCard": {
304312            "modelParameters": {
304313              "approach": {}
304314            },
304315            "quantitativeAnalysis": {
304316              "graphics": {}
304317            },
304318            "considerations": {}
304319          }
304320        },
304321        {
304322          "type": "library",
304323          "bom-ref": "pkg:npm/%40fusioncharts/datatable@1.5.0?package-id=133f60ce1e679d89",
304324          "supplier": {},
304325          "name": "@fusioncharts/datatable",
304326          "version": "1.5.0",
304327          "licenses": [
304328            {
304329              "license": {
304330                "name": "https://www.fusioncharts.com/buy/"
304331              }
304332            }
304333          ],
304334          "cpe": "cpe:2.3:a:\\@fusioncharts\\/datatable:\\@fusioncharts\\/datatable:1.5.0:*:*:*:*:*:*:*",
304335          "purl": "pkg:npm/%40fusioncharts/datatable@1.5.0",
304336          "swid": {
304337            "attachment": {}
304338          },
304339          "pedigree": {},
304340          "evidence": {},
304341          "signature": {
304342            "signature": {
304343              "publicKey": {}
304344            }
304345          },
304346          "modelCard": {
304347            "modelParameters": {
304348              "approach": {}
304349            },
304350            "quantitativeAnalysis": {
304351              "graphics": {}
304352            },
304353            "considerations": {}
304354          }
304355        },
304356        {
304357          "type": "library",
304358          "bom-ref": "pkg:npm/%40fusioncharts/features@1.5.0?package-id=3513eeb2f8d2984d",
304359          "supplier": {},
304360          "name": "@fusioncharts/features",
304361          "version": "1.5.0",
304362          "licenses": [
304363            {
304364              "license": {
304365                "name": "https://www.fusioncharts.com/buy/"
304366              }
304367            }
304368          ],
304369          "cpe": "cpe:2.3:a:\\@fusioncharts\\/features:\\@fusioncharts\\/features:1.5.0:*:*:*:*:*:*:*",
304370          "purl": "pkg:npm/%40fusioncharts/features@1.5.0",
304371          "swid": {
304372            "attachment": {}
304373          },
304374          "pedigree": {},
304375          "evidence": {},
304376          "signature": {
304377            "signature": {
304378              "publicKey": {}
304379            }
304380          },
304381          "modelCard": {
304382            "modelParameters": {
304383              "approach": {}
304384            },
304385            "quantitativeAnalysis": {
304386              "graphics": {}
304387            },
304388            "considerations": {}
304389          }
304390        },
304391        {
304392          "type": "library",
304393          "bom-ref": "pkg:npm/%40fusioncharts/fusiontime@2.6.0?package-id=ea7b517fcdf8499b",
304394          "supplier": {},
304395          "name": "@fusioncharts/fusiontime",
304396          "version": "2.6.0",
304397          "licenses": [
304398            {
304399              "license": {
304400                "name": "https://www.fusioncharts.com/buy/"
304401              }
304402            }
304403          ],
304404          "cpe": "cpe:2.3:a:\\@fusioncharts\\/fusiontime:\\@fusioncharts\\/fusiontime:2.6.0:*:*:*:*:*:*:*",
304405          "purl": "pkg:npm/%40fusioncharts/fusiontime@2.6.0",
304406          "swid": {
304407            "attachment": {}
304408          },
304409          "pedigree": {},
304410          "evidence": {},
304411          "signature": {
304412            "signature": {
304413              "publicKey": {}
304414            }
304415          },
304416          "modelCard": {
304417            "modelParameters": {
304418              "approach": {}
304419            },
304420            "quantitativeAnalysis": {
304421              "graphics": {}
304422            },
304423            "considerations": {}
304424          }
304425        },
304426        {
304427          "type": "library",
304428          "bom-ref": "pkg:npm/%40fusioncharts/maps@3.18.0?package-id=ddeb948a0e76454e",
304429          "supplier": {},
304430          "name": "@fusioncharts/maps",
304431          "version": "3.18.0",
304432          "licenses": [
304433            {
304434              "license": {
304435                "name": "https://www.fusioncharts.com/buy/"
304436              }
304437            }
304438          ],
304439          "cpe": "cpe:2.3:a:\\@fusioncharts\\/maps:\\@fusioncharts\\/maps:3.18.0:*:*:*:*:*:*:*",
304440          "purl": "pkg:npm/%40fusioncharts/maps@3.18.0",
304441          "swid": {
304442            "attachment": {}
304443          },
304444          "pedigree": {},
304445          "evidence": {},
304446          "signature": {
304447            "signature": {
304448              "publicKey": {}
304449            }
304450          },
304451          "modelCard": {
304452            "modelParameters": {
304453              "approach": {}
304454            },
304455            "quantitativeAnalysis": {
304456              "graphics": {}
304457            },
304458            "considerations": {}
304459          }
304460        },
304461        {
304462          "type": "library",
304463          "bom-ref": "pkg:npm/%40fusioncharts/powercharts@3.18.0?package-id=fba29609e85a5317",
304464          "supplier": {},
304465          "name": "@fusioncharts/powercharts",
304466          "version": "3.18.0",
304467          "licenses": [
304468            {
304469              "license": {
304470                "name": "https://www.fusioncharts.com/buy/"
304471              }
304472            }
304473          ],
304474          "cpe": "cpe:2.3:a:\\@fusioncharts\\/powercharts:\\@fusioncharts\\/powercharts:3.18.0:*:*:*:*:*:*:*",
304475          "purl": "pkg:npm/%40fusioncharts/powercharts@3.18.0",
304476          "swid": {
304477            "attachment": {}
304478          },
304479          "pedigree": {},
304480          "evidence": {},
304481          "signature": {
304482            "signature": {
304483              "publicKey": {}
304484            }
304485          },
304486          "modelCard": {
304487            "modelParameters": {
304488              "approach": {}
304489            },
304490            "quantitativeAnalysis": {
304491              "graphics": {}
304492            },
304493            "considerations": {}
304494          }
304495        },
304496        {
304497          "type": "library",
304498          "bom-ref": "pkg:npm/%40fusioncharts/utils@1.5.0?package-id=c4521bdf2ed42757",
304499          "supplier": {},
304500          "name": "@fusioncharts/utils",
304501          "version": "1.5.0",
304502          "licenses": [
304503            {
304504              "license": {
304505                "name": "https://www.fusioncharts.com/buy/"
304506              }
304507            }
304508          ],
304509          "cpe": "cpe:2.3:a:\\@fusioncharts\\/utils:\\@fusioncharts\\/utils:1.5.0:*:*:*:*:*:*:*",
304510          "purl": "pkg:npm/%40fusioncharts/utils@1.5.0",
304511          "swid": {
304512            "attachment": {}
304513          },
304514          "pedigree": {},
304515          "evidence": {},
304516          "signature": {
304517            "signature": {
304518              "publicKey": {}
304519            }
304520          },
304521          "modelCard": {
304522            "modelParameters": {
304523              "approach": {}
304524            },
304525            "quantitativeAnalysis": {
304526              "graphics": {}
304527            },
304528            "considerations": {}
304529          }
304530        },
304531        {
304532          "type": "library",
304533          "bom-ref": "pkg:npm/%40fusioncharts/widgets@3.18.0?package-id=76752811338fb1ee",
304534          "supplier": {},
304535          "name": "@fusioncharts/widgets",
304536          "version": "3.18.0",
304537          "licenses": [
304538            {
304539              "license": {
304540                "name": "https://www.fusioncharts.com/buy/"
304541              }
304542            }
304543          ],
304544          "cpe": "cpe:2.3:a:\\@fusioncharts\\/widgets:\\@fusioncharts\\/widgets:3.18.0:*:*:*:*:*:*:*",
304545          "purl": "pkg:npm/%40fusioncharts/widgets@3.18.0",
304546          "swid": {
304547            "attachment": {}
304548          },
304549          "pedigree": {},
304550          "evidence": {},
304551          "signature": {
304552            "signature": {
304553              "publicKey": {}
304554            }
304555          },
304556          "modelCard": {
304557            "modelParameters": {
304558              "approach": {}
304559            },
304560            "quantitativeAnalysis": {
304561              "graphics": {}
304562            },
304563            "considerations": {}
304564          }
304565        },
304566        {
304567          "type": "library",
304568          "bom-ref": "pkg:npm/%40istanbuljs/load-nyc-config@1.1.0?package-id=ffc1250b23ab4f66",
304569          "supplier": {},
304570          "name": "@istanbuljs/load-nyc-config",
304571          "version": "1.1.0",
304572          "cpe": "cpe:2.3:a:\\@istanbuljs\\/load-nyc-config:\\@istanbuljs\\/load-nyc-config:1.1.0:*:*:*:*:*:*:*",
304573          "purl": "pkg:npm/%40istanbuljs/load-nyc-config@1.1.0",
304574          "swid": {
304575            "attachment": {}
304576          },
304577          "pedigree": {},
304578          "evidence": {},
304579          "signature": {
304580            "signature": {
304581              "publicKey": {}
304582            }
304583          },
304584          "modelCard": {
304585            "modelParameters": {
304586              "approach": {}
304587            },
304588            "quantitativeAnalysis": {
304589              "graphics": {}
304590            },
304591            "considerations": {}
304592          }
304593        },
304594        {
304595          "type": "library",
304596          "bom-ref": "pkg:npm/%40istanbuljs/nyc-config-typescript@1.0.2?package-id=a61ff9b0683bbe10",
304597          "supplier": {},
304598          "name": "@istanbuljs/nyc-config-typescript",
304599          "version": "1.0.2",
304600          "cpe": "cpe:2.3:a:\\@istanbuljs\\/nyc-config-typescript:\\@istanbuljs\\/nyc-config-typescript:1.0.2:*:*:*:*:*:*:*",
304601          "purl": "pkg:npm/%40istanbuljs/nyc-config-typescript@1.0.2",
304602          "swid": {
304603            "attachment": {}
304604          },
304605          "pedigree": {},
304606          "evidence": {},
304607          "signature": {
304608            "signature": {
304609              "publicKey": {}
304610            }
304611          },
304612          "modelCard": {
304613            "modelParameters": {
304614              "approach": {}
304615            },
304616            "quantitativeAnalysis": {
304617              "graphics": {}
304618            },
304619            "considerations": {}
304620          }
304621        },
304622        {
304623          "type": "library",
304624          "bom-ref": "pkg:npm/%40istanbuljs/schema@0.1.2?package-id=14140c9f62a6d1af",
304625          "supplier": {},
304626          "name": "@istanbuljs/schema",
304627          "version": "0.1.2",
304628          "licenses": [
304629            {
304630              "license": {
304631                "id": "MIT"
304632              }
304633            }
304634          ],
304635          "cpe": "cpe:2.3:a:\\@istanbuljs\\/schema:\\@istanbuljs\\/schema:0.1.2:*:*:*:*:*:*:*",
304636          "purl": "pkg:npm/%40istanbuljs/schema@0.1.2",
304637          "swid": {
304638            "attachment": {}
304639          },
304640          "pedigree": {},
304641          "evidence": {},
304642          "signature": {
304643            "signature": {
304644              "publicKey": {}
304645            }
304646          },
304647          "modelCard": {
304648            "modelParameters": {
304649              "approach": {}
304650            },
304651            "quantitativeAnalysis": {
304652              "graphics": {}
304653            },
304654            "considerations": {}
304655          }
304656        },
304657        {
304658          "type": "library",
304659          "bom-ref": "pkg:npm/%40istanbuljs/schema@0.1.3?package-id=de00d81bf9e1c2f0",
304660          "supplier": {},
304661          "name": "@istanbuljs/schema",
304662          "version": "0.1.3",
304663          "cpe": "cpe:2.3:a:\\@istanbuljs\\/schema:\\@istanbuljs\\/schema:0.1.3:*:*:*:*:*:*:*",
304664          "purl": "pkg:npm/%40istanbuljs/schema@0.1.3",
304665          "swid": {
304666            "attachment": {}
304667          },
304668          "pedigree": {},
304669          "evidence": {},
304670          "signature": {
304671            "signature": {
304672              "publicKey": {}
304673            }
304674          },
304675          "modelCard": {
304676            "modelParameters": {
304677              "approach": {}
304678            },
304679            "quantitativeAnalysis": {
304680              "graphics": {}
304681            },
304682            "considerations": {}
304683          }
304684        },
304685        {
304686          "type": "library",
304687          "bom-ref": "pkg:npm/%40jsdevtools/coverage-istanbul-loader@3.0.3?package-id=6bf8dd60eda8fd70",
304688          "supplier": {},
304689          "name": "@jsdevtools/coverage-istanbul-loader",
304690          "version": "3.0.3",
304691          "licenses": [
304692            {
304693              "license": {
304694                "id": "MIT"
304695              }
304696            }
304697          ],
304698          "cpe": "cpe:2.3:a:\\@jsdevtools\\/coverage-istanbul-loader:\\@jsdevtools\\/coverage-istanbul-loader:3.0.3:*:*:*:*:*:*:*",
304699          "purl": "pkg:npm/%40jsdevtools/coverage-istanbul-loader@3.0.3",
304700          "swid": {
304701            "attachment": {}
304702          },
304703          "pedigree": {},
304704          "evidence": {},
304705          "signature": {
304706            "signature": {
304707              "publicKey": {}
304708            }
304709          },
304710          "modelCard": {
304711            "modelParameters": {
304712              "approach": {}
304713            },
304714            "quantitativeAnalysis": {
304715              "graphics": {}
304716            },
304717            "considerations": {}
304718          }
304719        },
304720        {
304721          "type": "library",
304722          "bom-ref": "pkg:npm/%40ng-idle/core@8.0.0-beta.4?package-id=d231fc6f1a18706b",
304723          "supplier": {},
304724          "name": "@ng-idle/core",
304725          "version": "8.0.0-beta.4",
304726          "licenses": [
304727            {
304728              "license": {
304729                "id": "Apache-2.0"
304730              }
304731            }
304732          ],
304733          "cpe": "cpe:2.3:a:\\@ng-idle\\/core:\\@ng-idle\\/core:8.0.0-beta.4:*:*:*:*:*:*:*",
304734          "purl": "pkg:npm/%40ng-idle/core@8.0.0-beta.4",
304735          "swid": {
304736            "attachment": {}
304737          },
304738          "pedigree": {},
304739          "evidence": {},
304740          "signature": {
304741            "signature": {
304742              "publicKey": {}
304743            }
304744          },
304745          "modelCard": {
304746            "modelParameters": {
304747              "approach": {}
304748            },
304749            "quantitativeAnalysis": {
304750              "graphics": {}
304751            },
304752            "considerations": {}
304753          }
304754        },
304755        {
304756          "type": "library",
304757          "bom-ref": "pkg:npm/%40ng-idle/keepalive@8.0.0-beta.4?package-id=8e1ba6a985f12b6b",
304758          "supplier": {},
304759          "name": "@ng-idle/keepalive",
304760          "version": "8.0.0-beta.4",
304761          "licenses": [
304762            {
304763              "license": {
304764                "id": "Apache-2.0"
304765              }
304766            }
304767          ],
304768          "cpe": "cpe:2.3:a:\\@ng-idle\\/keepalive:\\@ng-idle\\/keepalive:8.0.0-beta.4:*:*:*:*:*:*:*",
304769          "purl": "pkg:npm/%40ng-idle/keepalive@8.0.0-beta.4",
304770          "swid": {
304771            "attachment": {}
304772          },
304773          "pedigree": {},
304774          "evidence": {},
304775          "signature": {
304776            "signature": {
304777              "publicKey": {}
304778            }
304779          },
304780          "modelCard": {
304781            "modelParameters": {
304782              "approach": {}
304783            },
304784            "quantitativeAnalysis": {
304785              "graphics": {}
304786            },
304787            "considerations": {}
304788          }
304789        },
304790        {
304791          "type": "library",
304792          "bom-ref": "pkg:npm/%40ngtools/webpack@9.1.5?package-id=61b2231ee647c46e",
304793          "supplier": {},
304794          "name": "@ngtools/webpack",
304795          "version": "9.1.5",
304796          "licenses": [
304797            {
304798              "license": {
304799                "id": "MIT"
304800              }
304801            }
304802          ],
304803          "cpe": "cpe:2.3:a:\\@ngtools\\/webpack:\\@ngtools\\/webpack:9.1.5:*:*:*:*:*:*:*",
304804          "purl": "pkg:npm/%40ngtools/webpack@9.1.5",
304805          "swid": {
304806            "attachment": {}
304807          },
304808          "pedigree": {},
304809          "evidence": {},
304810          "signature": {
304811            "signature": {
304812              "publicKey": {}
304813            }
304814          },
304815          "modelCard": {
304816            "modelParameters": {
304817              "approach": {}
304818            },
304819            "quantitativeAnalysis": {
304820              "graphics": {}
304821            },
304822            "considerations": {}
304823          }
304824        },
304825        {
304826          "type": "library",
304827          "bom-ref": "pkg:npm/%40ngx-translate/core@12.1.2?package-id=bb0b519f24e1e0a0",
304828          "supplier": {},
304829          "name": "@ngx-translate/core",
304830          "version": "12.1.2",
304831          "licenses": [
304832            {
304833              "license": {
304834                "id": "MIT"
304835              }
304836            }
304837          ],
304838          "cpe": "cpe:2.3:a:\\@ngx-translate\\/core:\\@ngx-translate\\/core:12.1.2:*:*:*:*:*:*:*",
304839          "purl": "pkg:npm/%40ngx-translate/core@12.1.2",
304840          "swid": {
304841            "attachment": {}
304842          },
304843          "pedigree": {},
304844          "evidence": {},
304845          "signature": {
304846            "signature": {
304847              "publicKey": {}
304848            }
304849          },
304850          "modelCard": {
304851            "modelParameters": {
304852              "approach": {}
304853            },
304854            "quantitativeAnalysis": {
304855              "graphics": {}
304856            },
304857            "considerations": {}
304858          }
304859        },
304860        {
304861          "type": "library",
304862          "bom-ref": "pkg:npm/%40ngx-translate/http-loader@4.0.0?package-id=623d2531d1c584dd",
304863          "supplier": {},
304864          "name": "@ngx-translate/http-loader",
304865          "version": "4.0.0",
304866          "licenses": [
304867            {
304868              "license": {
304869                "id": "MIT"
304870              }
304871            }
304872          ],
304873          "cpe": "cpe:2.3:a:\\@ngx-translate\\/http-loader:\\@ngx-translate\\/http-loader:4.0.0:*:*:*:*:*:*:*",
304874          "purl": "pkg:npm/%40ngx-translate/http-loader@4.0.0",
304875          "swid": {
304876            "attachment": {}
304877          },
304878          "pedigree": {},
304879          "evidence": {},
304880          "signature": {
304881            "signature": {
304882              "publicKey": {}
304883            }
304884          },
304885          "modelCard": {
304886            "modelParameters": {
304887              "approach": {}
304888            },
304889            "quantitativeAnalysis": {
304890              "graphics": {}
304891            },
304892            "considerations": {}
304893          }
304894        },
304895        {
304896          "type": "library",
304897          "bom-ref": "pkg:npm/%40ngxd/core@9.0.4?package-id=f69b6f926eb9ed5b",
304898          "supplier": {},
304899          "name": "@ngxd/core",
304900          "version": "9.0.4",
304901          "licenses": [
304902            {
304903              "license": {
304904                "id": "MIT"
304905              }
304906            }
304907          ],
304908          "cpe": "cpe:2.3:a:\\@ngxd\\/core:\\@ngxd\\/core:9.0.4:*:*:*:*:*:*:*",
304909          "purl": "pkg:npm/%40ngxd/core@9.0.4",
304910          "swid": {
304911            "attachment": {}
304912          },
304913          "pedigree": {},
304914          "evidence": {},
304915          "signature": {
304916            "signature": {
304917              "publicKey": {}
304918            }
304919          },
304920          "modelCard": {
304921            "modelParameters": {
304922              "approach": {}
304923            },
304924            "quantitativeAnalysis": {
304925              "graphics": {}
304926            },
304927            "considerations": {}
304928          }
304929        },
304930        {
304931          "type": "library",
304932          "bom-ref": "pkg:npm/%40pliant/front-common@1.40.0?package-id=4b4ad3e4787cbe52",
304933          "supplier": {},
304934          "name": "@pliant/front-common",
304935          "version": "1.40.0",
304936          "cpe": "cpe:2.3:a:\\@pliant\\/front-common:\\@pliant\\/front-common:1.40.0:*:*:*:*:*:*:*",
304937          "purl": "pkg:npm/%40pliant/front-common@1.40.0",
304938          "swid": {
304939            "attachment": {}
304940          },
304941          "pedigree": {},
304942          "evidence": {},
304943          "signature": {
304944            "signature": {
304945              "publicKey": {}
304946            }
304947          },
304948          "modelCard": {
304949            "modelParameters": {
304950              "approach": {}
304951            },
304952            "quantitativeAnalysis": {
304953              "graphics": {}
304954            },
304955            "considerations": {}
304956          }
304957        },
304958        {
304959          "type": "library",
304960          "bom-ref": "pkg:npm/%40scarf/scarf@0.1.5?package-id=6d9fd92722bd54ba",
304961          "supplier": {},
304962          "name": "@scarf/scarf",
304963          "version": "0.1.5",
304964          "licenses": [
304965            {
304966              "license": {
304967                "id": "MIT"
304968              }
304969            }
304970          ],
304971          "cpe": "cpe:2.3:a:\\@scarf\\/scarf:\\@scarf\\/scarf:0.1.5:*:*:*:*:*:*:*",
304972          "purl": "pkg:npm/%40scarf/scarf@0.1.5",
304973          "swid": {
304974            "attachment": {}
304975          },
304976          "pedigree": {},
304977          "evidence": {},
304978          "signature": {
304979            "signature": {
304980              "publicKey": {}
304981            }
304982          },
304983          "modelCard": {
304984            "modelParameters": {
304985              "approach": {}
304986            },
304987            "quantitativeAnalysis": {
304988              "graphics": {}
304989            },
304990            "considerations": {}
304991          }
304992        },
304993        {
304994          "type": "library",
304995          "bom-ref": "pkg:npm/%40schematics/angular@9.1.5?package-id=25852a1240f02a56",
304996          "supplier": {},
304997          "name": "@schematics/angular",
304998          "version": "9.1.5",
304999          "licenses": [
305000            {
305001              "license": {
305002                "id": "MIT"
305003              }
305004            }
305005          ],
305006          "cpe": "cpe:2.3:a:\\@schematics\\/angular:\\@schematics\\/angular:9.1.5:*:*:*:*:*:*:*",
305007          "purl": "pkg:npm/%40schematics/angular@9.1.5",
305008          "swid": {
305009            "attachment": {}
305010          },
305011          "pedigree": {},
305012          "evidence": {},
305013          "signature": {
305014            "signature": {
305015              "publicKey": {}
305016            }
305017          },
305018          "modelCard": {
305019            "modelParameters": {
305020              "approach": {}
305021            },
305022            "quantitativeAnalysis": {
305023              "graphics": {}
305024            },
305025            "considerations": {}
305026          }
305027        },
305028        {
305029          "type": "library",
305030          "bom-ref": "pkg:npm/%40schematics/update@0.901.5?package-id=34af53a28c36635",
305031          "supplier": {},
305032          "name": "@schematics/update",
305033          "version": "0.901.5",
305034          "licenses": [
305035            {
305036              "license": {
305037                "id": "MIT"
305038              }
305039            }
305040          ],
305041          "cpe": "cpe:2.3:a:\\@schematics\\/update:\\@schematics\\/update:0.901.5:*:*:*:*:*:*:*",
305042          "purl": "pkg:npm/%40schematics/update@0.901.5",
305043          "swid": {
305044            "attachment": {}
305045          },
305046          "pedigree": {},
305047          "evidence": {},
305048          "signature": {
305049            "signature": {
305050              "publicKey": {}
305051            }
305052          },
305053          "modelCard": {
305054            "modelParameters": {
305055              "approach": {}
305056            },
305057            "quantitativeAnalysis": {
305058              "graphics": {}
305059            },
305060            "considerations": {}
305061          }
305062        },
305063        {
305064          "type": "library",
305065          "bom-ref": "pkg:npm/%40types/adm-zip@0.4.32?package-id=1e8013f3d387caa7",
305066          "supplier": {},
305067          "name": "@types/adm-zip",
305068          "version": "0.4.32",
305069          "licenses": [
305070            {
305071              "license": {
305072                "id": "MIT"
305073              }
305074            }
305075          ],
305076          "cpe": "cpe:2.3:a:\\@types\\/adm-zip:\\@types\\/adm-zip:0.4.32:*:*:*:*:*:*:*",
305077          "purl": "pkg:npm/%40types/adm-zip@0.4.32",
305078          "swid": {
305079            "attachment": {}
305080          },
305081          "pedigree": {},
305082          "evidence": {},
305083          "signature": {
305084            "signature": {
305085              "publicKey": {}
305086            }
305087          },
305088          "modelCard": {
305089            "modelParameters": {
305090              "approach": {}
305091            },
305092            "quantitativeAnalysis": {
305093              "graphics": {}
305094            },
305095            "considerations": {}
305096          }
305097        },
305098        {
305099          "type": "library",
305100          "bom-ref": "pkg:npm/%40types/caseless@0.12.2?package-id=75897190b3b61e35",
305101          "supplier": {},
305102          "name": "@types/caseless",
305103          "version": "0.12.2",
305104          "licenses": [
305105            {
305106              "license": {
305107                "id": "MIT"
305108              }
305109            }
305110          ],
305111          "cpe": "cpe:2.3:a:\\@types\\/caseless:\\@types\\/caseless:0.12.2:*:*:*:*:*:*:*",
305112          "purl": "pkg:npm/%40types/caseless@0.12.2",
305113          "swid": {
305114            "attachment": {}
305115          },
305116          "pedigree": {},
305117          "evidence": {},
305118          "signature": {
305119            "signature": {
305120              "publicKey": {}
305121            }
305122          },
305123          "modelCard": {
305124            "modelParameters": {
305125              "approach": {}
305126            },
305127            "quantitativeAnalysis": {
305128              "graphics": {}
305129            },
305130            "considerations": {}
305131          }
305132        },
305133        {
305134          "type": "library",
305135          "bom-ref": "pkg:npm/%40types/color-name@1.1.1?package-id=633c64821381411f",
305136          "supplier": {},
305137          "name": "@types/color-name",
305138          "version": "1.1.1",
305139          "licenses": [
305140            {
305141              "license": {
305142                "id": "MIT"
305143              }
305144            }
305145          ],
305146          "cpe": "cpe:2.3:a:\\@types\\/color-name:\\@types\\/color-name:1.1.1:*:*:*:*:*:*:*",
305147          "purl": "pkg:npm/%40types/color-name@1.1.1",
305148          "swid": {
305149            "attachment": {}
305150          },
305151          "pedigree": {},
305152          "evidence": {},
305153          "signature": {
305154            "signature": {
305155              "publicKey": {}
305156            }
305157          },
305158          "modelCard": {
305159            "modelParameters": {
305160              "approach": {}
305161            },
305162            "quantitativeAnalysis": {
305163              "graphics": {}
305164            },
305165            "considerations": {}
305166          }
305167        },
305168        {
305169          "type": "library",
305170          "bom-ref": "pkg:npm/%40types/deep-diff@1.0.0?package-id=7422ab5cfb219543",
305171          "supplier": {},
305172          "name": "@types/deep-diff",
305173          "version": "1.0.0",
305174          "licenses": [
305175            {
305176              "license": {
305177                "id": "MIT"
305178              }
305179            }
305180          ],
305181          "cpe": "cpe:2.3:a:\\@types\\/deep-diff:\\@types\\/deep-diff:1.0.0:*:*:*:*:*:*:*",
305182          "purl": "pkg:npm/%40types/deep-diff@1.0.0",
305183          "swid": {
305184            "attachment": {}
305185          },
305186          "pedigree": {},
305187          "evidence": {},
305188          "signature": {
305189            "signature": {
305190              "publicKey": {}
305191            }
305192          },
305193          "modelCard": {
305194            "modelParameters": {
305195              "approach": {}
305196            },
305197            "quantitativeAnalysis": {
305198              "graphics": {}
305199            },
305200            "considerations": {}
305201          }
305202        },
305203        {
305204          "type": "library",
305205          "bom-ref": "pkg:npm/%40types/events@3.0.0?package-id=e846ede1fb2fcc3d",
305206          "supplier": {},
305207          "name": "@types/events",
305208          "version": "3.0.0",
305209          "licenses": [
305210            {
305211              "license": {
305212                "id": "MIT"
305213              }
305214            }
305215          ],
305216          "cpe": "cpe:2.3:a:\\@types\\/events:\\@types\\/events:3.0.0:*:*:*:*:*:*:*",
305217          "purl": "pkg:npm/%40types/events@3.0.0",
305218          "swid": {
305219            "attachment": {}
305220          },
305221          "pedigree": {},
305222          "evidence": {},
305223          "signature": {
305224            "signature": {
305225              "publicKey": {}
305226            }
305227          },
305228          "modelCard": {
305229            "modelParameters": {
305230              "approach": {}
305231            },
305232            "quantitativeAnalysis": {
305233              "graphics": {}
305234            },
305235            "considerations": {}
305236          }
305237        },
305238        {
305239          "type": "library",
305240          "bom-ref": "pkg:npm/%40types/file-saver@2.0.1?package-id=d3eea93dddba2f87",
305241          "supplier": {},
305242          "name": "@types/file-saver",
305243          "version": "2.0.1",
305244          "licenses": [
305245            {
305246              "license": {
305247                "id": "MIT"
305248              }
305249            }
305250          ],
305251          "cpe": "cpe:2.3:a:\\@types\\/file-saver:\\@types\\/file-saver:2.0.1:*:*:*:*:*:*:*",
305252          "purl": "pkg:npm/%40types/file-saver@2.0.1",
305253          "swid": {
305254            "attachment": {}
305255          },
305256          "pedigree": {},
305257          "evidence": {},
305258          "signature": {
305259            "signature": {
305260              "publicKey": {}
305261            }
305262          },
305263          "modelCard": {
305264            "modelParameters": {
305265              "approach": {}
305266            },
305267            "quantitativeAnalysis": {
305268              "graphics": {}
305269            },
305270            "considerations": {}
305271          }
305272        },
305273        {
305274          "type": "library",
305275          "bom-ref": "pkg:npm/%40types/fusioncharts@3.12.3?package-id=7fcb9e6abd4be415",
305276          "supplier": {},
305277          "name": "@types/fusioncharts",
305278          "version": "3.12.3",
305279          "licenses": [
305280            {
305281              "license": {
305282                "id": "MIT"
305283              }
305284            }
305285          ],
305286          "cpe": "cpe:2.3:a:\\@types\\/fusioncharts:\\@types\\/fusioncharts:3.12.3:*:*:*:*:*:*:*",
305287          "purl": "pkg:npm/%40types/fusioncharts@3.12.3",
305288          "swid": {
305289            "attachment": {}
305290          },
305291          "pedigree": {},
305292          "evidence": {},
305293          "signature": {
305294            "signature": {
305295              "publicKey": {}
305296            }
305297          },
305298          "modelCard": {
305299            "modelParameters": {
305300              "approach": {}
305301            },
305302            "quantitativeAnalysis": {
305303              "graphics": {}
305304            },
305305            "considerations": {}
305306          }
305307        },
305308        {
305309          "type": "library",
305310          "bom-ref": "pkg:npm/%40types/glob@7.1.1?package-id=3a65280f87be668",
305311          "supplier": {},
305312          "name": "@types/glob",
305313          "version": "7.1.1",
305314          "licenses": [
305315            {
305316              "license": {
305317                "id": "MIT"
305318              }
305319            }
305320          ],
305321          "cpe": "cpe:2.3:a:\\@types\\/glob:\\@types\\/glob:7.1.1:*:*:*:*:*:*:*",
305322          "purl": "pkg:npm/%40types/glob@7.1.1",
305323          "swid": {
305324            "attachment": {}
305325          },
305326          "pedigree": {},
305327          "evidence": {},
305328          "signature": {
305329            "signature": {
305330              "publicKey": {}
305331            }
305332          },
305333          "modelCard": {
305334            "modelParameters": {
305335              "approach": {}
305336            },
305337            "quantitativeAnalysis": {
305338              "graphics": {}
305339            },
305340            "considerations": {}
305341          }
305342        },
305343        {
305344          "type": "library",
305345          "bom-ref": "pkg:npm/%40types/hammerjs@2.0.36?package-id=a0b0d49459ae32aa",
305346          "supplier": {},
305347          "name": "@types/hammerjs",
305348          "version": "2.0.36",
305349          "licenses": [
305350            {
305351              "license": {
305352                "id": "MIT"
305353              }
305354            }
305355          ],
305356          "cpe": "cpe:2.3:a:\\@types\\/hammerjs:\\@types\\/hammerjs:2.0.36:*:*:*:*:*:*:*",
305357          "purl": "pkg:npm/%40types/hammerjs@2.0.36",
305358          "swid": {
305359            "attachment": {}
305360          },
305361          "pedigree": {},
305362          "evidence": {},
305363          "signature": {
305364            "signature": {
305365              "publicKey": {}
305366            }
305367          },
305368          "modelCard": {
305369            "modelParameters": {
305370              "approach": {}
305371            },
305372            "quantitativeAnalysis": {
305373              "graphics": {}
305374            },
305375            "considerations": {}
305376          }
305377        },
305378        {
305379          "type": "library",
305380          "bom-ref": "pkg:npm/%40types/jasmine@3.5.10?package-id=32150cffb9668dc7",
305381          "supplier": {},
305382          "name": "@types/jasmine",
305383          "version": "3.5.10",
305384          "licenses": [
305385            {
305386              "license": {
305387                "id": "MIT"
305388              }
305389            }
305390          ],
305391          "cpe": "cpe:2.3:a:\\@types\\/jasmine:\\@types\\/jasmine:3.5.10:*:*:*:*:*:*:*",
305392          "purl": "pkg:npm/%40types/jasmine@3.5.10",
305393          "swid": {
305394            "attachment": {}
305395          },
305396          "pedigree": {},
305397          "evidence": {},
305398          "signature": {
305399            "signature": {
305400              "publicKey": {}
305401            }
305402          },
305403          "modelCard": {
305404            "modelParameters": {
305405              "approach": {}
305406            },
305407            "quantitativeAnalysis": {
305408              "graphics": {}
305409            },
305410            "considerations": {}
305411          }
305412        },
305413        {
305414          "type": "library",
305415          "bom-ref": "pkg:npm/%40types/jasminewd2@2.0.8?package-id=d5cc5fad5d6656b9",
305416          "supplier": {},
305417          "name": "@types/jasminewd2",
305418          "version": "2.0.8",
305419          "licenses": [
305420            {
305421              "license": {
305422                "id": "MIT"
305423              }
305424            }
305425          ],
305426          "cpe": "cpe:2.3:a:\\@types\\/jasminewd2:\\@types\\/jasminewd2:2.0.8:*:*:*:*:*:*:*",
305427          "purl": "pkg:npm/%40types/jasminewd2@2.0.8",
305428          "swid": {
305429            "attachment": {}
305430          },
305431          "pedigree": {},
305432          "evidence": {},
305433          "signature": {
305434            "signature": {
305435              "publicKey": {}
305436            }
305437          },
305438          "modelCard": {
305439            "modelParameters": {
305440              "approach": {}
305441            },
305442            "quantitativeAnalysis": {
305443              "graphics": {}
305444            },
305445            "considerations": {}
305446          }
305447        },
305448        {
305449          "type": "library",
305450          "bom-ref": "pkg:npm/%40types/js-yaml@4.0.5?package-id=f07ecbd189290a4b",
305451          "supplier": {},
305452          "name": "@types/js-yaml",
305453          "version": "4.0.5",
305454          "licenses": [
305455            {
305456              "license": {
305457                "id": "MIT"
305458              }
305459            }
305460          ],
305461          "cpe": "cpe:2.3:a:\\@types\\/js-yaml:\\@types\\/js-yaml:4.0.5:*:*:*:*:*:*:*",
305462          "purl": "pkg:npm/%40types/js-yaml@4.0.5",
305463          "swid": {
305464            "attachment": {}
305465          },
305466          "pedigree": {},
305467          "evidence": {},
305468          "signature": {
305469            "signature": {
305470              "publicKey": {}
305471            }
305472          },
305473          "modelCard": {
305474            "modelParameters": {
305475              "approach": {}
305476            },
305477            "quantitativeAnalysis": {
305478              "graphics": {}
305479            },
305480            "considerations": {}
305481          }
305482        },
305483        {
305484          "type": "library",
305485          "bom-ref": "pkg:npm/%40types/json-js@1.1.0?package-id=ea3456ee328e9806",
305486          "supplier": {},
305487          "name": "@types/json-js",
305488          "version": "1.1.0",
305489          "licenses": [
305490            {
305491              "license": {
305492                "id": "MIT"
305493              }
305494            }
305495          ],
305496          "cpe": "cpe:2.3:a:\\@types\\/json-js:\\@types\\/json-js:1.1.0:*:*:*:*:*:*:*",
305497          "purl": "pkg:npm/%40types/json-js@1.1.0",
305498          "swid": {
305499            "attachment": {}
305500          },
305501          "pedigree": {},
305502          "evidence": {},
305503          "signature": {
305504            "signature": {
305505              "publicKey": {}
305506            }
305507          },
305508          "modelCard": {
305509            "modelParameters": {
305510              "approach": {}
305511            },
305512            "quantitativeAnalysis": {
305513              "graphics": {}
305514            },
305515            "considerations": {}
305516          }
305517        },
305518        {
305519          "type": "library",
305520          "bom-ref": "pkg:npm/%40types/json-schema@7.0.4?package-id=6d32e19f8d197923",
305521          "supplier": {},
305522          "name": "@types/json-schema",
305523          "version": "7.0.4",
305524          "licenses": [
305525            {
305526              "license": {
305527                "id": "MIT"
305528              }
305529            }
305530          ],
305531          "cpe": "cpe:2.3:a:\\@types\\/json-schema:\\@types\\/json-schema:7.0.4:*:*:*:*:*:*:*",
305532          "purl": "pkg:npm/%40types/json-schema@7.0.4",
305533          "swid": {
305534            "attachment": {}
305535          },
305536          "pedigree": {},
305537          "evidence": {},
305538          "signature": {
305539            "signature": {
305540              "publicKey": {}
305541            }
305542          },
305543          "modelCard": {
305544            "modelParameters": {
305545              "approach": {}
305546            },
305547            "quantitativeAnalysis": {
305548              "graphics": {}
305549            },
305550            "considerations": {}
305551          }
305552        },
305553        {
305554          "type": "library",
305555          "bom-ref": "pkg:npm/%40types/jszip@3.1.7?package-id=41883d0a0cee6429",
305556          "supplier": {},
305557          "name": "@types/jszip",
305558          "version": "3.1.7",
305559          "licenses": [
305560            {
305561              "license": {
305562                "id": "MIT"
305563              }
305564            }
305565          ],
305566          "cpe": "cpe:2.3:a:\\@types\\/jszip:\\@types\\/jszip:3.1.7:*:*:*:*:*:*:*",
305567          "purl": "pkg:npm/%40types/jszip@3.1.7",
305568          "swid": {
305569            "attachment": {}
305570          },
305571          "pedigree": {},
305572          "evidence": {},
305573          "signature": {
305574            "signature": {
305575              "publicKey": {}
305576            }
305577          },
305578          "modelCard": {
305579            "modelParameters": {
305580              "approach": {}
305581            },
305582            "quantitativeAnalysis": {
305583              "graphics": {}
305584            },
305585            "considerations": {}
305586          }
305587        },
305588        {
305589          "type": "library",
305590          "bom-ref": "pkg:npm/%40types/lodash@4.14.149?package-id=2d6c1d507beb3b38",
305591          "supplier": {},
305592          "name": "@types/lodash",
305593          "version": "4.14.149",
305594          "licenses": [
305595            {
305596              "license": {
305597                "id": "MIT"
305598              }
305599            }
305600          ],
305601          "cpe": "cpe:2.3:a:\\@types\\/lodash:\\@types\\/lodash:4.14.149:*:*:*:*:*:*:*",
305602          "purl": "pkg:npm/%40types/lodash@4.14.149",
305603          "swid": {
305604            "attachment": {}
305605          },
305606          "pedigree": {},
305607          "evidence": {},
305608          "signature": {
305609            "signature": {
305610              "publicKey": {}
305611            }
305612          },
305613          "modelCard": {
305614            "modelParameters": {
305615              "approach": {}
305616            },
305617            "quantitativeAnalysis": {
305618              "graphics": {}
305619            },
305620            "considerations": {}
305621          }
305622        },
305623        {
305624          "type": "library",
305625          "bom-ref": "pkg:npm/%40types/minimatch@3.0.3?package-id=f8c0561365eb879c",
305626          "supplier": {},
305627          "name": "@types/minimatch",
305628          "version": "3.0.3",
305629          "licenses": [
305630            {
305631              "license": {
305632                "id": "MIT"
305633              }
305634            }
305635          ],
305636          "cpe": "cpe:2.3:a:\\@types\\/minimatch:\\@types\\/minimatch:3.0.3:*:*:*:*:*:*:*",
305637          "purl": "pkg:npm/%40types/minimatch@3.0.3",
305638          "swid": {
305639            "attachment": {}
305640          },
305641          "pedigree": {},
305642          "evidence": {},
305643          "signature": {
305644            "signature": {
305645              "publicKey": {}
305646            }
305647          },
305648          "modelCard": {
305649            "modelParameters": {
305650              "approach": {}
305651            },
305652            "quantitativeAnalysis": {
305653              "graphics": {}
305654            },
305655            "considerations": {}
305656          }
305657        },
305658        {
305659          "type": "library",
305660          "bom-ref": "pkg:npm/%40types/node@13.9.3?package-id=bc7448565e133b70",
305661          "supplier": {},
305662          "name": "@types/node",
305663          "version": "13.9.3",
305664          "licenses": [
305665            {
305666              "license": {
305667                "id": "MIT"
305668              }
305669            }
305670          ],
305671          "cpe": "cpe:2.3:a:\\@types\\/node:\\@types\\/node:13.9.3:*:*:*:*:*:*:*",
305672          "purl": "pkg:npm/%40types/node@13.9.3",
305673          "swid": {
305674            "attachment": {}
305675          },
305676          "pedigree": {},
305677          "evidence": {},
305678          "signature": {
305679            "signature": {
305680              "publicKey": {}
305681            }
305682          },
305683          "modelCard": {
305684            "modelParameters": {
305685              "approach": {}
305686            },
305687            "quantitativeAnalysis": {
305688              "graphics": {}
305689            },
305690            "considerations": {}
305691          }
305692        },
305693        {
305694          "type": "library",
305695          "bom-ref": "pkg:npm/%40types/prettier@1.19.1?package-id=2e03117674f43eaf",
305696          "supplier": {},
305697          "name": "@types/prettier",
305698          "version": "1.19.1",
305699          "licenses": [
305700            {
305701              "license": {
305702                "id": "MIT"
305703              }
305704            }
305705          ],
305706          "cpe": "cpe:2.3:a:\\@types\\/prettier:\\@types\\/prettier:1.19.1:*:*:*:*:*:*:*",
305707          "purl": "pkg:npm/%40types/prettier@1.19.1",
305708          "swid": {
305709            "attachment": {}
305710          },
305711          "pedigree": {},
305712          "evidence": {},
305713          "signature": {
305714            "signature": {
305715              "publicKey": {}
305716            }
305717          },
305718          "modelCard": {
305719            "modelParameters": {
305720              "approach": {}
305721            },
305722            "quantitativeAnalysis": {
305723              "graphics": {}
305724            },
305725            "considerations": {}
305726          }
305727        },
305728        {
305729          "type": "library",
305730          "bom-ref": "pkg:npm/%40types/pretty-ms@5.0.1?package-id=72fd3841a269544e",
305731          "supplier": {},
305732          "name": "@types/pretty-ms",
305733          "version": "5.0.1",
305734          "licenses": [
305735            {
305736              "license": {
305737                "id": "MIT"
305738              }
305739            }
305740          ],
305741          "cpe": "cpe:2.3:a:\\@types\\/pretty-ms:\\@types\\/pretty-ms:5.0.1:*:*:*:*:*:*:*",
305742          "purl": "pkg:npm/%40types/pretty-ms@5.0.1",
305743          "swid": {
305744            "attachment": {}
305745          },
305746          "pedigree": {},
305747          "evidence": {},
305748          "signature": {
305749            "signature": {
305750              "publicKey": {}
305751            }
305752          },
305753          "modelCard": {
305754            "modelParameters": {
305755              "approach": {}
305756            },
305757            "quantitativeAnalysis": {
305758              "graphics": {}
305759            },
305760            "considerations": {}
305761          }
305762        },
305763        {
305764          "type": "library",
305765          "bom-ref": "pkg:npm/%40types/q@1.5.2?package-id=6c76118ac72dc9f3",
305766          "supplier": {},
305767          "name": "@types/q",
305768          "version": "1.5.2",
305769          "licenses": [
305770            {
305771              "license": {
305772                "id": "MIT"
305773              }
305774            }
305775          ],
305776          "cpe": "cpe:2.3:a:\\@types\\/q:\\@types\\/q:1.5.2:*:*:*:*:*:*:*",
305777          "purl": "pkg:npm/%40types/q@1.5.2",
305778          "swid": {
305779            "attachment": {}
305780          },
305781          "pedigree": {},
305782          "evidence": {},
305783          "signature": {
305784            "signature": {
305785              "publicKey": {}
305786            }
305787          },
305788          "modelCard": {
305789            "modelParameters": {
305790              "approach": {}
305791            },
305792            "quantitativeAnalysis": {
305793              "graphics": {}
305794            },
305795            "considerations": {}
305796          }
305797        },
305798        {
305799          "type": "library",
305800          "bom-ref": "pkg:npm/%40types/request@2.48.4?package-id=fca2893202b499ef",
305801          "supplier": {},
305802          "name": "@types/request",
305803          "version": "2.48.4",
305804          "licenses": [
305805            {
305806              "license": {
305807                "id": "MIT"
305808              }
305809            }
305810          ],
305811          "cpe": "cpe:2.3:a:\\@types\\/request:\\@types\\/request:2.48.4:*:*:*:*:*:*:*",
305812          "purl": "pkg:npm/%40types/request@2.48.4",
305813          "swid": {
305814            "attachment": {}
305815          },
305816          "pedigree": {},
305817          "evidence": {},
305818          "signature": {
305819            "signature": {
305820              "publicKey": {}
305821            }
305822          },
305823          "modelCard": {
305824            "modelParameters": {
305825              "approach": {}
305826            },
305827            "quantitativeAnalysis": {
305828              "graphics": {}
305829            },
305830            "considerations": {}
305831          }
305832        },
305833        {
305834          "type": "library",
305835          "bom-ref": "pkg:npm/%40types/request-promise-native@1.0.17?package-id=ad56e8cefd8a459",
305836          "supplier": {},
305837          "name": "@types/request-promise-native",
305838          "version": "1.0.17",
305839          "licenses": [
305840            {
305841              "license": {
305842                "id": "MIT"
305843              }
305844            }
305845          ],
305846          "cpe": "cpe:2.3:a:\\@types\\/request-promise-native:\\@types\\/request-promise-native:1.0.17:*:*:*:*:*:*:*",
305847          "purl": "pkg:npm/%40types/request-promise-native@1.0.17",
305848          "swid": {
305849            "attachment": {}
305850          },
305851          "pedigree": {},
305852          "evidence": {},
305853          "signature": {
305854            "signature": {
305855              "publicKey": {}
305856            }
305857          },
305858          "modelCard": {
305859            "modelParameters": {
305860              "approach": {}
305861            },
305862            "quantitativeAnalysis": {
305863              "graphics": {}
305864            },
305865            "considerations": {}
305866          }
305867        },
305868        {
305869          "type": "library",
305870          "bom-ref": "pkg:npm/%40types/selenium-webdriver@3.0.17?package-id=dc5589093f088ab1",
305871          "supplier": {},
305872          "name": "@types/selenium-webdriver",
305873          "version": "3.0.17",
305874          "licenses": [
305875            {
305876              "license": {
305877                "id": "MIT"
305878              }
305879            }
305880          ],
305881          "cpe": "cpe:2.3:a:\\@types\\/selenium-webdriver:\\@types\\/selenium-webdriver:3.0.17:*:*:*:*:*:*:*",
305882          "purl": "pkg:npm/%40types/selenium-webdriver@3.0.17",
305883          "swid": {
305884            "attachment": {}
305885          },
305886          "pedigree": {},
305887          "evidence": {},
305888          "signature": {
305889            "signature": {
305890              "publicKey": {}
305891            }
305892          },
305893          "modelCard": {
305894            "modelParameters": {
305895              "approach": {}
305896            },
305897            "quantitativeAnalysis": {
305898              "graphics": {}
305899            },
305900            "considerations": {}
305901          }
305902        },
305903        {
305904          "type": "library",
305905          "bom-ref": "pkg:npm/%40types/source-list-map@0.1.2?package-id=b489d800c4257000",
305906          "supplier": {},
305907          "name": "@types/source-list-map",
305908          "version": "0.1.2",
305909          "licenses": [
305910            {
305911              "license": {
305912                "id": "MIT"
305913              }
305914            }
305915          ],
305916          "cpe": "cpe:2.3:a:\\@types\\/source-list-map:\\@types\\/source-list-map:0.1.2:*:*:*:*:*:*:*",
305917          "purl": "pkg:npm/%40types/source-list-map@0.1.2",
305918          "swid": {
305919            "attachment": {}
305920          },
305921          "pedigree": {},
305922          "evidence": {},
305923          "signature": {
305924            "signature": {
305925              "publicKey": {}
305926            }
305927          },
305928          "modelCard": {
305929            "modelParameters": {
305930              "approach": {}
305931            },
305932            "quantitativeAnalysis": {
305933              "graphics": {}
305934            },
305935            "considerations": {}
305936          }
305937        },
305938        {
305939          "type": "library",
305940          "bom-ref": "pkg:npm/%40types/tough-cookie@2.3.6?package-id=ae885c19ad27b02e",
305941          "supplier": {},
305942          "name": "@types/tough-cookie",
305943          "version": "2.3.6",
305944          "licenses": [
305945            {
305946              "license": {
305947                "id": "MIT"
305948              }
305949            }
305950          ],
305951          "cpe": "cpe:2.3:a:\\@types\\/tough-cookie:\\@types\\/tough-cookie:2.3.6:*:*:*:*:*:*:*",
305952          "purl": "pkg:npm/%40types/tough-cookie@2.3.6",
305953          "swid": {
305954            "attachment": {}
305955          },
305956          "pedigree": {},
305957          "evidence": {},
305958          "signature": {
305959            "signature": {
305960              "publicKey": {}
305961            }
305962          },
305963          "modelCard": {
305964            "modelParameters": {
305965              "approach": {}
305966            },
305967            "quantitativeAnalysis": {
305968              "graphics": {}
305969            },
305970            "considerations": {}
305971          }
305972        },
305973        {
305974          "type": "library",
305975          "bom-ref": "pkg:npm/%40types/webpack-sources@0.1.7?package-id=2ead707bc311a3f",
305976          "supplier": {},
305977          "name": "@types/webpack-sources",
305978          "version": "0.1.7",
305979          "licenses": [
305980            {
305981              "license": {
305982                "id": "MIT"
305983              }
305984            }
305985          ],
305986          "cpe": "cpe:2.3:a:\\@types\\/webpack-sources:\\@types\\/webpack-sources:0.1.7:*:*:*:*:*:*:*",
305987          "purl": "pkg:npm/%40types/webpack-sources@0.1.7",
305988          "swid": {
305989            "attachment": {}
305990          },
305991          "pedigree": {},
305992          "evidence": {},
305993          "signature": {
305994            "signature": {
305995              "publicKey": {}
305996            }
305997          },
305998          "modelCard": {
305999            "modelParameters": {
306000              "approach": {}
306001            },
306002            "quantitativeAnalysis": {
306003              "graphics": {}
306004            },
306005            "considerations": {}
306006          }
306007        },
306008        {
306009          "type": "library",
306010          "bom-ref": "pkg:npm/%40webassemblyjs/ast@1.8.5?package-id=f79d5342dca363d9",
306011          "supplier": {},
306012          "name": "@webassemblyjs/ast",
306013          "version": "1.8.5",
306014          "licenses": [
306015            {
306016              "license": {
306017                "id": "MIT"
306018              }
306019            }
306020          ],
306021          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/ast:\\@webassemblyjs\\/ast:1.8.5:*:*:*:*:*:*:*",
306022          "purl": "pkg:npm/%40webassemblyjs/ast@1.8.5",
306023          "swid": {
306024            "attachment": {}
306025          },
306026          "pedigree": {},
306027          "evidence": {},
306028          "signature": {
306029            "signature": {
306030              "publicKey": {}
306031            }
306032          },
306033          "modelCard": {
306034            "modelParameters": {
306035              "approach": {}
306036            },
306037            "quantitativeAnalysis": {
306038              "graphics": {}
306039            },
306040            "considerations": {}
306041          }
306042        },
306043        {
306044          "type": "library",
306045          "bom-ref": "pkg:npm/%40webassemblyjs/floating-point-hex-parser@1.8.5?package-id=709fb7e11c87bdc6",
306046          "supplier": {},
306047          "name": "@webassemblyjs/floating-point-hex-parser",
306048          "version": "1.8.5",
306049          "licenses": [
306050            {
306051              "license": {
306052                "id": "MIT"
306053              }
306054            }
306055          ],
306056          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/floating-point-hex-parser:\\@webassemblyjs\\/floating-point-hex-parser:1.8.5:*:*:*:*:*:*:*",
306057          "purl": "pkg:npm/%40webassemblyjs/floating-point-hex-parser@1.8.5",
306058          "swid": {
306059            "attachment": {}
306060          },
306061          "pedigree": {},
306062          "evidence": {},
306063          "signature": {
306064            "signature": {
306065              "publicKey": {}
306066            }
306067          },
306068          "modelCard": {
306069            "modelParameters": {
306070              "approach": {}
306071            },
306072            "quantitativeAnalysis": {
306073              "graphics": {}
306074            },
306075            "considerations": {}
306076          }
306077        },
306078        {
306079          "type": "library",
306080          "bom-ref": "pkg:npm/%40webassemblyjs/helper-api-error@1.8.5?package-id=5f1895df229abb0f",
306081          "supplier": {},
306082          "name": "@webassemblyjs/helper-api-error",
306083          "version": "1.8.5",
306084          "licenses": [
306085            {
306086              "license": {
306087                "id": "MIT"
306088              }
306089            }
306090          ],
306091          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/helper-api-error:\\@webassemblyjs\\/helper-api-error:1.8.5:*:*:*:*:*:*:*",
306092          "purl": "pkg:npm/%40webassemblyjs/helper-api-error@1.8.5",
306093          "swid": {
306094            "attachment": {}
306095          },
306096          "pedigree": {},
306097          "evidence": {},
306098          "signature": {
306099            "signature": {
306100              "publicKey": {}
306101            }
306102          },
306103          "modelCard": {
306104            "modelParameters": {
306105              "approach": {}
306106            },
306107            "quantitativeAnalysis": {
306108              "graphics": {}
306109            },
306110            "considerations": {}
306111          }
306112        },
306113        {
306114          "type": "library",
306115          "bom-ref": "pkg:npm/%40webassemblyjs/helper-buffer@1.8.5?package-id=cdd6e103795b86ff",
306116          "supplier": {},
306117          "name": "@webassemblyjs/helper-buffer",
306118          "version": "1.8.5",
306119          "licenses": [
306120            {
306121              "license": {
306122                "id": "MIT"
306123              }
306124            }
306125          ],
306126          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/helper-buffer:\\@webassemblyjs\\/helper-buffer:1.8.5:*:*:*:*:*:*:*",
306127          "purl": "pkg:npm/%40webassemblyjs/helper-buffer@1.8.5",
306128          "swid": {
306129            "attachment": {}
306130          },
306131          "pedigree": {},
306132          "evidence": {},
306133          "signature": {
306134            "signature": {
306135              "publicKey": {}
306136            }
306137          },
306138          "modelCard": {
306139            "modelParameters": {
306140              "approach": {}
306141            },
306142            "quantitativeAnalysis": {
306143              "graphics": {}
306144            },
306145            "considerations": {}
306146          }
306147        },
306148        {
306149          "type": "library",
306150          "bom-ref": "pkg:npm/%40webassemblyjs/helper-code-frame@1.8.5?package-id=7d7900f3da03207b",
306151          "supplier": {},
306152          "name": "@webassemblyjs/helper-code-frame",
306153          "version": "1.8.5",
306154          "licenses": [
306155            {
306156              "license": {
306157                "id": "MIT"
306158              }
306159            }
306160          ],
306161          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/helper-code-frame:\\@webassemblyjs\\/helper-code-frame:1.8.5:*:*:*:*:*:*:*",
306162          "purl": "pkg:npm/%40webassemblyjs/helper-code-frame@1.8.5",
306163          "swid": {
306164            "attachment": {}
306165          },
306166          "pedigree": {},
306167          "evidence": {},
306168          "signature": {
306169            "signature": {
306170              "publicKey": {}
306171            }
306172          },
306173          "modelCard": {
306174            "modelParameters": {
306175              "approach": {}
306176            },
306177            "quantitativeAnalysis": {
306178              "graphics": {}
306179            },
306180            "considerations": {}
306181          }
306182        },
306183        {
306184          "type": "library",
306185          "bom-ref": "pkg:npm/%40webassemblyjs/helper-fsm@1.8.5?package-id=cdaab87e8f28f79",
306186          "supplier": {},
306187          "name": "@webassemblyjs/helper-fsm",
306188          "version": "1.8.5",
306189          "licenses": [
306190            {
306191              "license": {
306192                "id": "ISC"
306193              }
306194            }
306195          ],
306196          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/helper-fsm:\\@webassemblyjs\\/helper-fsm:1.8.5:*:*:*:*:*:*:*",
306197          "purl": "pkg:npm/%40webassemblyjs/helper-fsm@1.8.5",
306198          "swid": {
306199            "attachment": {}
306200          },
306201          "pedigree": {},
306202          "evidence": {},
306203          "signature": {
306204            "signature": {
306205              "publicKey": {}
306206            }
306207          },
306208          "modelCard": {
306209            "modelParameters": {
306210              "approach": {}
306211            },
306212            "quantitativeAnalysis": {
306213              "graphics": {}
306214            },
306215            "considerations": {}
306216          }
306217        },
306218        {
306219          "type": "library",
306220          "bom-ref": "pkg:npm/%40webassemblyjs/helper-module-context@1.8.5?package-id=fc41cef853245a72",
306221          "supplier": {},
306222          "name": "@webassemblyjs/helper-module-context",
306223          "version": "1.8.5",
306224          "licenses": [
306225            {
306226              "license": {
306227                "id": "MIT"
306228              }
306229            }
306230          ],
306231          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/helper-module-context:\\@webassemblyjs\\/helper-module-context:1.8.5:*:*:*:*:*:*:*",
306232          "purl": "pkg:npm/%40webassemblyjs/helper-module-context@1.8.5",
306233          "swid": {
306234            "attachment": {}
306235          },
306236          "pedigree": {},
306237          "evidence": {},
306238          "signature": {
306239            "signature": {
306240              "publicKey": {}
306241            }
306242          },
306243          "modelCard": {
306244            "modelParameters": {
306245              "approach": {}
306246            },
306247            "quantitativeAnalysis": {
306248              "graphics": {}
306249            },
306250            "considerations": {}
306251          }
306252        },
306253        {
306254          "type": "library",
306255          "bom-ref": "pkg:npm/%40webassemblyjs/helper-wasm-bytecode@1.8.5?package-id=6019d5e0e08c4dd4",
306256          "supplier": {},
306257          "name": "@webassemblyjs/helper-wasm-bytecode",
306258          "version": "1.8.5",
306259          "licenses": [
306260            {
306261              "license": {
306262                "id": "MIT"
306263              }
306264            }
306265          ],
306266          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/helper-wasm-bytecode:\\@webassemblyjs\\/helper-wasm-bytecode:1.8.5:*:*:*:*:*:*:*",
306267          "purl": "pkg:npm/%40webassemblyjs/helper-wasm-bytecode@1.8.5",
306268          "swid": {
306269            "attachment": {}
306270          },
306271          "pedigree": {},
306272          "evidence": {},
306273          "signature": {
306274            "signature": {
306275              "publicKey": {}
306276            }
306277          },
306278          "modelCard": {
306279            "modelParameters": {
306280              "approach": {}
306281            },
306282            "quantitativeAnalysis": {
306283              "graphics": {}
306284            },
306285            "considerations": {}
306286          }
306287        },
306288        {
306289          "type": "library",
306290          "bom-ref": "pkg:npm/%40webassemblyjs/helper-wasm-section@1.8.5?package-id=b501c9d2cf2475e7",
306291          "supplier": {},
306292          "name": "@webassemblyjs/helper-wasm-section",
306293          "version": "1.8.5",
306294          "licenses": [
306295            {
306296              "license": {
306297                "id": "MIT"
306298              }
306299            }
306300          ],
306301          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/helper-wasm-section:\\@webassemblyjs\\/helper-wasm-section:1.8.5:*:*:*:*:*:*:*",
306302          "purl": "pkg:npm/%40webassemblyjs/helper-wasm-section@1.8.5",
306303          "swid": {
306304            "attachment": {}
306305          },
306306          "pedigree": {},
306307          "evidence": {},
306308          "signature": {
306309            "signature": {
306310              "publicKey": {}
306311            }
306312          },
306313          "modelCard": {
306314            "modelParameters": {
306315              "approach": {}
306316            },
306317            "quantitativeAnalysis": {
306318              "graphics": {}
306319            },
306320            "considerations": {}
306321          }
306322        },
306323        {
306324          "type": "library",
306325          "bom-ref": "pkg:npm/%40webassemblyjs/ieee754@1.8.5?package-id=a05643ab885a8a4f",
306326          "supplier": {},
306327          "name": "@webassemblyjs/ieee754",
306328          "version": "1.8.5",
306329          "licenses": [
306330            {
306331              "license": {
306332                "id": "MIT"
306333              }
306334            }
306335          ],
306336          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/ieee754:\\@webassemblyjs\\/ieee754:1.8.5:*:*:*:*:*:*:*",
306337          "purl": "pkg:npm/%40webassemblyjs/ieee754@1.8.5",
306338          "swid": {
306339            "attachment": {}
306340          },
306341          "pedigree": {},
306342          "evidence": {},
306343          "signature": {
306344            "signature": {
306345              "publicKey": {}
306346            }
306347          },
306348          "modelCard": {
306349            "modelParameters": {
306350              "approach": {}
306351            },
306352            "quantitativeAnalysis": {
306353              "graphics": {}
306354            },
306355            "considerations": {}
306356          }
306357        },
306358        {
306359          "type": "library",
306360          "bom-ref": "pkg:npm/%40webassemblyjs/leb128@1.8.5?package-id=fe68dea2221ca38f",
306361          "supplier": {},
306362          "name": "@webassemblyjs/leb128",
306363          "version": "1.8.5",
306364          "licenses": [
306365            {
306366              "license": {
306367                "id": "MIT"
306368              }
306369            }
306370          ],
306371          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/leb128:\\@webassemblyjs\\/leb128:1.8.5:*:*:*:*:*:*:*",
306372          "purl": "pkg:npm/%40webassemblyjs/leb128@1.8.5",
306373          "swid": {
306374            "attachment": {}
306375          },
306376          "pedigree": {},
306377          "evidence": {},
306378          "signature": {
306379            "signature": {
306380              "publicKey": {}
306381            }
306382          },
306383          "modelCard": {
306384            "modelParameters": {
306385              "approach": {}
306386            },
306387            "quantitativeAnalysis": {
306388              "graphics": {}
306389            },
306390            "considerations": {}
306391          }
306392        },
306393        {
306394          "type": "library",
306395          "bom-ref": "pkg:npm/%40webassemblyjs/utf8@1.8.5?package-id=e1f86e86411e84b4",
306396          "supplier": {},
306397          "name": "@webassemblyjs/utf8",
306398          "version": "1.8.5",
306399          "licenses": [
306400            {
306401              "license": {
306402                "id": "MIT"
306403              }
306404            }
306405          ],
306406          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/utf8:\\@webassemblyjs\\/utf8:1.8.5:*:*:*:*:*:*:*",
306407          "purl": "pkg:npm/%40webassemblyjs/utf8@1.8.5",
306408          "swid": {
306409            "attachment": {}
306410          },
306411          "pedigree": {},
306412          "evidence": {},
306413          "signature": {
306414            "signature": {
306415              "publicKey": {}
306416            }
306417          },
306418          "modelCard": {
306419            "modelParameters": {
306420              "approach": {}
306421            },
306422            "quantitativeAnalysis": {
306423              "graphics": {}
306424            },
306425            "considerations": {}
306426          }
306427        },
306428        {
306429          "type": "library",
306430          "bom-ref": "pkg:npm/%40webassemblyjs/wasm-edit@1.8.5?package-id=af87c4e12b95a901",
306431          "supplier": {},
306432          "name": "@webassemblyjs/wasm-edit",
306433          "version": "1.8.5",
306434          "licenses": [
306435            {
306436              "license": {
306437                "id": "MIT"
306438              }
306439            }
306440          ],
306441          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/wasm-edit:\\@webassemblyjs\\/wasm-edit:1.8.5:*:*:*:*:*:*:*",
306442          "purl": "pkg:npm/%40webassemblyjs/wasm-edit@1.8.5",
306443          "swid": {
306444            "attachment": {}
306445          },
306446          "pedigree": {},
306447          "evidence": {},
306448          "signature": {
306449            "signature": {
306450              "publicKey": {}
306451            }
306452          },
306453          "modelCard": {
306454            "modelParameters": {
306455              "approach": {}
306456            },
306457            "quantitativeAnalysis": {
306458              "graphics": {}
306459            },
306460            "considerations": {}
306461          }
306462        },
306463        {
306464          "type": "library",
306465          "bom-ref": "pkg:npm/%40webassemblyjs/wasm-gen@1.8.5?package-id=7a3c763b9ca96a34",
306466          "supplier": {},
306467          "name": "@webassemblyjs/wasm-gen",
306468          "version": "1.8.5",
306469          "licenses": [
306470            {
306471              "license": {
306472                "id": "MIT"
306473              }
306474            }
306475          ],
306476          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/wasm-gen:\\@webassemblyjs\\/wasm-gen:1.8.5:*:*:*:*:*:*:*",
306477          "purl": "pkg:npm/%40webassemblyjs/wasm-gen@1.8.5",
306478          "swid": {
306479            "attachment": {}
306480          },
306481          "pedigree": {},
306482          "evidence": {},
306483          "signature": {
306484            "signature": {
306485              "publicKey": {}
306486            }
306487          },
306488          "modelCard": {
306489            "modelParameters": {
306490              "approach": {}
306491            },
306492            "quantitativeAnalysis": {
306493              "graphics": {}
306494            },
306495            "considerations": {}
306496          }
306497        },
306498        {
306499          "type": "library",
306500          "bom-ref": "pkg:npm/%40webassemblyjs/wasm-opt@1.8.5?package-id=1744b8e4ca7aecb3",
306501          "supplier": {},
306502          "name": "@webassemblyjs/wasm-opt",
306503          "version": "1.8.5",
306504          "licenses": [
306505            {
306506              "license": {
306507                "id": "MIT"
306508              }
306509            }
306510          ],
306511          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/wasm-opt:\\@webassemblyjs\\/wasm-opt:1.8.5:*:*:*:*:*:*:*",
306512          "purl": "pkg:npm/%40webassemblyjs/wasm-opt@1.8.5",
306513          "swid": {
306514            "attachment": {}
306515          },
306516          "pedigree": {},
306517          "evidence": {},
306518          "signature": {
306519            "signature": {
306520              "publicKey": {}
306521            }
306522          },
306523          "modelCard": {
306524            "modelParameters": {
306525              "approach": {}
306526            },
306527            "quantitativeAnalysis": {
306528              "graphics": {}
306529            },
306530            "considerations": {}
306531          }
306532        },
306533        {
306534          "type": "library",
306535          "bom-ref": "pkg:npm/%40webassemblyjs/wasm-parser@1.8.5?package-id=7b5e6997a437fad1",
306536          "supplier": {},
306537          "name": "@webassemblyjs/wasm-parser",
306538          "version": "1.8.5",
306539          "licenses": [
306540            {
306541              "license": {
306542                "id": "MIT"
306543              }
306544            }
306545          ],
306546          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/wasm-parser:\\@webassemblyjs\\/wasm-parser:1.8.5:*:*:*:*:*:*:*",
306547          "purl": "pkg:npm/%40webassemblyjs/wasm-parser@1.8.5",
306548          "swid": {
306549            "attachment": {}
306550          },
306551          "pedigree": {},
306552          "evidence": {},
306553          "signature": {
306554            "signature": {
306555              "publicKey": {}
306556            }
306557          },
306558          "modelCard": {
306559            "modelParameters": {
306560              "approach": {}
306561            },
306562            "quantitativeAnalysis": {
306563              "graphics": {}
306564            },
306565            "considerations": {}
306566          }
306567        },
306568        {
306569          "type": "library",
306570          "bom-ref": "pkg:npm/%40webassemblyjs/wast-parser@1.8.5?package-id=b0a8d1bc948af684",
306571          "supplier": {},
306572          "name": "@webassemblyjs/wast-parser",
306573          "version": "1.8.5",
306574          "licenses": [
306575            {
306576              "license": {
306577                "id": "MIT"
306578              }
306579            }
306580          ],
306581          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/wast-parser:\\@webassemblyjs\\/wast-parser:1.8.5:*:*:*:*:*:*:*",
306582          "purl": "pkg:npm/%40webassemblyjs/wast-parser@1.8.5",
306583          "swid": {
306584            "attachment": {}
306585          },
306586          "pedigree": {},
306587          "evidence": {},
306588          "signature": {
306589            "signature": {
306590              "publicKey": {}
306591            }
306592          },
306593          "modelCard": {
306594            "modelParameters": {
306595              "approach": {}
306596            },
306597            "quantitativeAnalysis": {
306598              "graphics": {}
306599            },
306600            "considerations": {}
306601          }
306602        },
306603        {
306604          "type": "library",
306605          "bom-ref": "pkg:npm/%40webassemblyjs/wast-printer@1.8.5?package-id=457ea3e170e8b376",
306606          "supplier": {},
306607          "name": "@webassemblyjs/wast-printer",
306608          "version": "1.8.5",
306609          "licenses": [
306610            {
306611              "license": {
306612                "id": "MIT"
306613              }
306614            }
306615          ],
306616          "cpe": "cpe:2.3:a:\\@webassemblyjs\\/wast-printer:\\@webassemblyjs\\/wast-printer:1.8.5:*:*:*:*:*:*:*",
306617          "purl": "pkg:npm/%40webassemblyjs/wast-printer@1.8.5",
306618          "swid": {
306619            "attachment": {}
306620          },
306621          "pedigree": {},
306622          "evidence": {},
306623          "signature": {
306624            "signature": {
306625              "publicKey": {}
306626            }
306627          },
306628          "modelCard": {
306629            "modelParameters": {
306630              "approach": {}
306631            },
306632            "quantitativeAnalysis": {
306633              "graphics": {}
306634            },
306635            "considerations": {}
306636          }
306637        },
306638        {
306639          "type": "library",
306640          "bom-ref": "pkg:npm/%40xtuc/ieee754@1.2.0?package-id=90dd6251389c626e",
306641          "supplier": {},
306642          "name": "@xtuc/ieee754",
306643          "version": "1.2.0",
306644          "licenses": [
306645            {
306646              "license": {
306647                "id": "BSD-3-Clause"
306648              }
306649            }
306650          ],
306651          "cpe": "cpe:2.3:a:\\@xtuc\\/ieee754:\\@xtuc\\/ieee754:1.2.0:*:*:*:*:*:*:*",
306652          "purl": "pkg:npm/%40xtuc/ieee754@1.2.0",
306653          "swid": {
306654            "attachment": {}
306655          },
306656          "pedigree": {},
306657          "evidence": {},
306658          "signature": {
306659            "signature": {
306660              "publicKey": {}
306661            }
306662          },
306663          "modelCard": {
306664            "modelParameters": {
306665              "approach": {}
306666            },
306667            "quantitativeAnalysis": {
306668              "graphics": {}
306669            },
306670            "considerations": {}
306671          }
306672        },
306673        {
306674          "type": "library",
306675          "bom-ref": "pkg:npm/%40xtuc/long@4.2.2?package-id=35d9e1e74aa133a6",
306676          "supplier": {},
306677          "name": "@xtuc/long",
306678          "version": "4.2.2",
306679          "licenses": [
306680            {
306681              "license": {
306682                "id": "Apache-2.0"
306683              }
306684            }
306685          ],
306686          "cpe": "cpe:2.3:a:\\@xtuc\\/long:\\@xtuc\\/long:4.2.2:*:*:*:*:*:*:*",
306687          "purl": "pkg:npm/%40xtuc/long@4.2.2",
306688          "swid": {
306689            "attachment": {}
306690          },
306691          "pedigree": {},
306692          "evidence": {},
306693          "signature": {
306694            "signature": {
306695              "publicKey": {}
306696            }
306697          },
306698          "modelCard": {
306699            "modelParameters": {
306700              "approach": {}
306701            },
306702            "quantitativeAnalysis": {
306703              "graphics": {}
306704            },
306705            "considerations": {}
306706          }
306707        },
306708        {
306709          "type": "library",
306710          "bom-ref": "pkg:npm/%40yarnpkg/lockfile@1.1.0?package-id=a65496646e0a88ec",
306711          "supplier": {},
306712          "name": "@yarnpkg/lockfile",
306713          "version": "1.1.0",
306714          "cpe": "cpe:2.3:a:\\@yarnpkg\\/lockfile:\\@yarnpkg\\/lockfile:1.1.0:*:*:*:*:*:*:*",
306715          "purl": "pkg:npm/%40yarnpkg/lockfile@1.1.0",
306716          "swid": {
306717            "attachment": {}
306718          },
306719          "pedigree": {},
306720          "evidence": {},
306721          "signature": {
306722            "signature": {
306723              "publicKey": {}
306724            }
306725          },
306726          "modelCard": {
306727            "modelParameters": {
306728              "approach": {}
306729            },
306730            "quantitativeAnalysis": {
306731              "graphics": {}
306732            },
306733            "considerations": {}
306734          }
306735        },
306736        {
306737          "type": "library",
306738          "bom-ref": "pkg:npm/%40yarnpkg/lockfile@1.1.0?package-id=4a82189e7fefaf87",
306739          "supplier": {},
306740          "name": "@yarnpkg/lockfile",
306741          "version": "1.1.0",
306742          "licenses": [
306743            {
306744              "license": {
306745                "id": "BSD-2-Clause"
306746              }
306747            }
306748          ],
306749          "cpe": "cpe:2.3:a:\\@yarnpkg\\/lockfile:\\@yarnpkg\\/lockfile:1.1.0:*:*:*:*:*:*:*",
306750          "purl": "pkg:npm/%40yarnpkg/lockfile@1.1.0",
306751          "swid": {
306752            "attachment": {}
306753          },
306754          "pedigree": {},
306755          "evidence": {},
306756          "signature": {
306757            "signature": {
306758              "publicKey": {}
306759            }
306760          },
306761          "modelCard": {
306762            "modelParameters": {
306763              "approach": {}
306764            },
306765            "quantitativeAnalysis": {
306766              "graphics": {}
306767            },
306768            "considerations": {}
306769          }
306770        },
306771        {
306772          "type": "library",
306773          "bom-ref": "pkg:npm/JSONStream@1.3.5?package-id=98ba9b672d23e385",
306774          "supplier": {},
306775          "name": "JSONStream",
306776          "version": "1.3.5",
306777          "licenses": [
306778            {
306779              "license": {
306780                "name": "(MIT OR Apache-2.0)"
306781              }
306782            }
306783          ],
306784          "cpe": "cpe:2.3:a:JSONStream:JSONStream:1.3.5:*:*:*:*:*:*:*",
306785          "purl": "pkg:npm/JSONStream@1.3.5",
306786          "swid": {
306787            "attachment": {}
306788          },
306789          "pedigree": {},
306790          "evidence": {},
306791          "signature": {
306792            "signature": {
306793              "publicKey": {}
306794            }
306795          },
306796          "modelCard": {
306797            "modelParameters": {
306798              "approach": {}
306799            },
306800            "quantitativeAnalysis": {
306801              "graphics": {}
306802            },
306803            "considerations": {}
306804          }
306805        },
306806        {
306807          "type": "library",
306808          "bom-ref": "pkg:npm/abbrev@1.1.1?package-id=4dda3196e00a2f3f",
306809          "supplier": {},
306810          "name": "abbrev",
306811          "version": "1.1.1",
306812          "licenses": [
306813            {
306814              "license": {
306815                "id": "ISC"
306816              }
306817            }
306818          ],
306819          "cpe": "cpe:2.3:a:abbrev:abbrev:1.1.1:*:*:*:*:*:*:*",
306820          "purl": "pkg:npm/abbrev@1.1.1",
306821          "swid": {
306822            "attachment": {}
306823          },
306824          "pedigree": {},
306825          "evidence": {},
306826          "signature": {
306827            "signature": {
306828              "publicKey": {}
306829            }
306830          },
306831          "modelCard": {
306832            "modelParameters": {
306833              "approach": {}
306834            },
306835            "quantitativeAnalysis": {
306836              "graphics": {}
306837            },
306838            "considerations": {}
306839          }
306840        },
306841        {
306842          "type": "library",
306843          "bom-ref": "pkg:npm/accepts@1.3.7?package-id=4f77c64c8b500c81",
306844          "supplier": {},
306845          "name": "accepts",
306846          "version": "1.3.7",
306847          "licenses": [
306848            {
306849              "license": {
306850                "id": "MIT"
306851              }
306852            }
306853          ],
306854          "cpe": "cpe:2.3:a:accepts:accepts:1.3.7:*:*:*:*:*:*:*",
306855          "purl": "pkg:npm/accepts@1.3.7",
306856          "swid": {
306857            "attachment": {}
306858          },
306859          "pedigree": {},
306860          "evidence": {},
306861          "signature": {
306862            "signature": {
306863              "publicKey": {}
306864            }
306865          },
306866          "modelCard": {
306867            "modelParameters": {
306868              "approach": {}
306869            },
306870            "quantitativeAnalysis": {
306871              "graphics": {}
306872            },
306873            "considerations": {}
306874          }
306875        },
306876        {
306877          "type": "library",
306878          "bom-ref": "pkg:npm/acorn@7.1.1?package-id=6497e500661e039c",
306879          "supplier": {},
306880          "name": "acorn",
306881          "version": "7.1.1",
306882          "licenses": [
306883            {
306884              "license": {
306885                "id": "MIT"
306886              }
306887            }
306888          ],
306889          "cpe": "cpe:2.3:a:acorn:acorn:7.1.1:*:*:*:*:*:*:*",
306890          "purl": "pkg:npm/acorn@7.1.1",
306891          "swid": {
306892            "attachment": {}
306893          },
306894          "pedigree": {},
306895          "evidence": {},
306896          "signature": {
306897            "signature": {
306898              "publicKey": {}
306899            }
306900          },
306901          "modelCard": {
306902            "modelParameters": {
306903              "approach": {}
306904            },
306905            "quantitativeAnalysis": {
306906              "graphics": {}
306907            },
306908            "considerations": {}
306909          }
306910        },
306911        {
306912          "type": "library",
306913          "bom-ref": "pkg:npm/acorn-loose@8.3.0?package-id=d64624fc9708283",
306914          "supplier": {},
306915          "name": "acorn-loose",
306916          "version": "8.3.0",
306917          "licenses": [
306918            {
306919              "license": {
306920                "id": "MIT"
306921              }
306922            }
306923          ],
306924          "cpe": "cpe:2.3:a:acorn-loose:acorn-loose:8.3.0:*:*:*:*:*:*:*",
306925          "purl": "pkg:npm/acorn-loose@8.3.0",
306926          "swid": {
306927            "attachment": {}
306928          },
306929          "pedigree": {},
306930          "evidence": {},
306931          "signature": {
306932            "signature": {
306933              "publicKey": {}
306934            }
306935          },
306936          "modelCard": {
306937            "modelParameters": {
306938              "approach": {}
306939            },
306940            "quantitativeAnalysis": {
306941              "graphics": {}
306942            },
306943            "considerations": {}
306944          }
306945        },
306946        {
306947          "type": "library",
306948          "bom-ref": "pkg:npm/acorn-walk@7.1.1?package-id=14b46b1befa7d735",
306949          "supplier": {},
306950          "name": "acorn-walk",
306951          "version": "7.1.1",
306952          "licenses": [
306953            {
306954              "license": {
306955                "id": "MIT"
306956              }
306957            }
306958          ],
306959          "cpe": "cpe:2.3:a:acorn-walk:acorn-walk:7.1.1:*:*:*:*:*:*:*",
306960          "purl": "pkg:npm/acorn-walk@7.1.1",
306961          "swid": {
306962            "attachment": {}
306963          },
306964          "pedigree": {},
306965          "evidence": {},
306966          "signature": {
306967            "signature": {
306968              "publicKey": {}
306969            }
306970          },
306971          "modelCard": {
306972            "modelParameters": {
306973              "approach": {}
306974            },
306975            "quantitativeAnalysis": {
306976              "graphics": {}
306977            },
306978            "considerations": {}
306979          }
306980        },
306981        {
306982          "type": "library",
306983          "bom-ref": "pkg:npm/adm-zip@0.4.14?package-id=c081844bb31abc85",
306984          "supplier": {},
306985          "name": "adm-zip",
306986          "version": "0.4.14",
306987          "licenses": [
306988            {
306989              "license": {
306990                "id": "MIT"
306991              }
306992            }
306993          ],
306994          "cpe": "cpe:2.3:a:adm-zip:adm-zip:0.4.14:*:*:*:*:*:*:*",
306995          "purl": "pkg:npm/adm-zip@0.4.14",
306996          "swid": {
306997            "attachment": {}
306998          },
306999          "pedigree": {},
307000          "evidence": {},
307001          "signature": {
307002            "signature": {
307003              "publicKey": {}
307004            }
307005          },
307006          "modelCard": {
307007            "modelParameters": {
307008              "approach": {}
307009            },
307010            "quantitativeAnalysis": {
307011              "graphics": {}
307012            },
307013            "considerations": {}
307014          }
307015        },
307016        {
307017          "type": "library",
307018          "bom-ref": "pkg:npm/after@0.8.2?package-id=787e2b0bd5693e71",
307019          "supplier": {},
307020          "name": "after",
307021          "version": "0.8.2",
307022          "licenses": [
307023            {
307024              "license": {
307025                "id": "MIT"
307026              }
307027            }
307028          ],
307029          "cpe": "cpe:2.3:a:after:after:0.8.2:*:*:*:*:*:*:*",
307030          "purl": "pkg:npm/after@0.8.2",
307031          "swid": {
307032            "attachment": {}
307033          },
307034          "pedigree": {},
307035          "evidence": {},
307036          "signature": {
307037            "signature": {
307038              "publicKey": {}
307039            }
307040          },
307041          "modelCard": {
307042            "modelParameters": {
307043              "approach": {}
307044            },
307045            "quantitativeAnalysis": {
307046              "graphics": {}
307047            },
307048            "considerations": {}
307049          }
307050        },
307051        {
307052          "type": "library",
307053          "bom-ref": "pkg:npm/agent-base@4.3.0?package-id=e0deb8aae8247e9",
307054          "supplier": {},
307055          "name": "agent-base",
307056          "version": "4.3.0",
307057          "licenses": [
307058            {
307059              "license": {
307060                "id": "MIT"
307061              }
307062            }
307063          ],
307064          "cpe": "cpe:2.3:a:agent-base:agent-base:4.3.0:*:*:*:*:*:*:*",
307065          "purl": "pkg:npm/agent-base@4.3.0",
307066          "swid": {
307067            "attachment": {}
307068          },
307069          "pedigree": {},
307070          "evidence": {},
307071          "signature": {
307072            "signature": {
307073              "publicKey": {}
307074            }
307075          },
307076          "modelCard": {
307077            "modelParameters": {
307078              "approach": {}
307079            },
307080            "quantitativeAnalysis": {
307081              "graphics": {}
307082            },
307083            "considerations": {}
307084          }
307085        },
307086        {
307087          "type": "library",
307088          "bom-ref": "pkg:npm/agentkeepalive@3.5.2?package-id=75fb84d54125e89a",
307089          "supplier": {},
307090          "name": "agentkeepalive",
307091          "version": "3.5.2",
307092          "licenses": [
307093            {
307094              "license": {
307095                "id": "MIT"
307096              }
307097            }
307098          ],
307099          "cpe": "cpe:2.3:a:agentkeepalive:agentkeepalive:3.5.2:*:*:*:*:*:*:*",
307100          "purl": "pkg:npm/agentkeepalive@3.5.2",
307101          "swid": {
307102            "attachment": {}
307103          },
307104          "pedigree": {},
307105          "evidence": {},
307106          "signature": {
307107            "signature": {
307108              "publicKey": {}
307109            }
307110          },
307111          "modelCard": {
307112            "modelParameters": {
307113              "approach": {}
307114            },
307115            "quantitativeAnalysis": {
307116              "graphics": {}
307117            },
307118            "considerations": {}
307119          }
307120        },
307121        {
307122          "type": "library",
307123          "bom-ref": "pkg:npm/aggregate-error@3.0.1?package-id=ff9029a78d810f6d",
307124          "supplier": {},
307125          "name": "aggregate-error",
307126          "version": "3.0.1",
307127          "licenses": [
307128            {
307129              "license": {
307130                "id": "MIT"
307131              }
307132            }
307133          ],
307134          "cpe": "cpe:2.3:a:aggregate-error:aggregate-error:3.0.1:*:*:*:*:*:*:*",
307135          "purl": "pkg:npm/aggregate-error@3.0.1",
307136          "swid": {
307137            "attachment": {}
307138          },
307139          "pedigree": {},
307140          "evidence": {},
307141          "signature": {
307142            "signature": {
307143              "publicKey": {}
307144            }
307145          },
307146          "modelCard": {
307147            "modelParameters": {
307148              "approach": {}
307149            },
307150            "quantitativeAnalysis": {
307151              "graphics": {}
307152            },
307153            "considerations": {}
307154          }
307155        },
307156        {
307157          "type": "library",
307158          "bom-ref": "pkg:npm/aggregate-error@3.1.0?package-id=8ebad62baf7518ca",
307159          "supplier": {},
307160          "name": "aggregate-error",
307161          "version": "3.1.0",
307162          "cpe": "cpe:2.3:a:aggregate-error:aggregate-error:3.1.0:*:*:*:*:*:*:*",
307163          "purl": "pkg:npm/aggregate-error@3.1.0",
307164          "swid": {
307165            "attachment": {}
307166          },
307167          "pedigree": {},
307168          "evidence": {},
307169          "signature": {
307170            "signature": {
307171              "publicKey": {}
307172            }
307173          },
307174          "modelCard": {
307175            "modelParameters": {
307176              "approach": {}
307177            },
307178            "quantitativeAnalysis": {
307179              "graphics": {}
307180            },
307181            "considerations": {}
307182          }
307183        },
307184        {
307185          "type": "library",
307186          "bom-ref": "pkg:npm/ajv@6.10.2?package-id=938328ec589a13bd",
307187          "supplier": {},
307188          "name": "ajv",
307189          "version": "6.10.2",
307190          "licenses": [
307191            {
307192              "license": {
307193                "id": "MIT"
307194              }
307195            }
307196          ],
307197          "cpe": "cpe:2.3:a:ajv:ajv:6.10.2:*:*:*:*:*:*:*",
307198          "purl": "pkg:npm/ajv@6.10.2",
307199          "swid": {
307200            "attachment": {}
307201          },
307202          "pedigree": {},
307203          "evidence": {},
307204          "signature": {
307205            "signature": {
307206              "publicKey": {}
307207            }
307208          },
307209          "modelCard": {
307210            "modelParameters": {
307211              "approach": {}
307212            },
307213            "quantitativeAnalysis": {
307214              "graphics": {}
307215            },
307216            "considerations": {}
307217          }
307218        },
307219        {
307220          "type": "library",
307221          "bom-ref": "pkg:npm/ajv-errors@1.0.1?package-id=f126b12d459993a5",
307222          "supplier": {},
307223          "name": "ajv-errors",
307224          "version": "1.0.1",
307225          "licenses": [
307226            {
307227              "license": {
307228                "id": "MIT"
307229              }
307230            }
307231          ],
307232          "cpe": "cpe:2.3:a:ajv-errors:ajv-errors:1.0.1:*:*:*:*:*:*:*",
307233          "purl": "pkg:npm/ajv-errors@1.0.1",
307234          "swid": {
307235            "attachment": {}
307236          },
307237          "pedigree": {},
307238          "evidence": {},
307239          "signature": {
307240            "signature": {
307241              "publicKey": {}
307242            }
307243          },
307244          "modelCard": {
307245            "modelParameters": {
307246              "approach": {}
307247            },
307248            "quantitativeAnalysis": {
307249              "graphics": {}
307250            },
307251            "considerations": {}
307252          }
307253        },
307254        {
307255          "type": "library",
307256          "bom-ref": "pkg:npm/ajv-keywords@3.4.1?package-id=42d3e5ab58cc8baf",
307257          "supplier": {},
307258          "name": "ajv-keywords",
307259          "version": "3.4.1",
307260          "licenses": [
307261            {
307262              "license": {
307263                "id": "MIT"
307264              }
307265            }
307266          ],
307267          "cpe": "cpe:2.3:a:ajv-keywords:ajv-keywords:3.4.1:*:*:*:*:*:*:*",
307268          "purl": "pkg:npm/ajv-keywords@3.4.1",
307269          "swid": {
307270            "attachment": {}
307271          },
307272          "pedigree": {},
307273          "evidence": {},
307274          "signature": {
307275            "signature": {
307276              "publicKey": {}
307277            }
307278          },
307279          "modelCard": {
307280            "modelParameters": {
307281              "approach": {}
307282            },
307283            "quantitativeAnalysis": {
307284              "graphics": {}
307285            },
307286            "considerations": {}
307287          }
307288        },
307289        {
307290          "type": "library",
307291          "bom-ref": "pkg:npm/alphanum-sort@1.0.2?package-id=dde89216f81ea21f",
307292          "supplier": {},
307293          "name": "alphanum-sort",
307294          "version": "1.0.2",
307295          "licenses": [
307296            {
307297              "license": {
307298                "id": "MIT"
307299              }
307300            }
307301          ],
307302          "cpe": "cpe:2.3:a:alphanum-sort:alphanum-sort:1.0.2:*:*:*:*:*:*:*",
307303          "purl": "pkg:npm/alphanum-sort@1.0.2",
307304          "swid": {
307305            "attachment": {}
307306          },
307307          "pedigree": {},
307308          "evidence": {},
307309          "signature": {
307310            "signature": {
307311              "publicKey": {}
307312            }
307313          },
307314          "modelCard": {
307315            "modelParameters": {
307316              "approach": {}
307317            },
307318            "quantitativeAnalysis": {
307319              "graphics": {}
307320            },
307321            "considerations": {}
307322          }
307323        },
307324        {
307325          "type": "library",
307326          "bom-ref": "pkg:npm/amdefine@1.0.1?package-id=8173edb4cab0b9e",
307327          "supplier": {},
307328          "name": "amdefine",
307329          "version": "1.0.1",
307330          "licenses": [
307331            {
307332              "license": {
307333                "name": "BSD-3-Clause OR MIT"
307334              }
307335            }
307336          ],
307337          "cpe": "cpe:2.3:a:amdefine:amdefine:1.0.1:*:*:*:*:*:*:*",
307338          "purl": "pkg:npm/amdefine@1.0.1",
307339          "swid": {
307340            "attachment": {}
307341          },
307342          "pedigree": {},
307343          "evidence": {},
307344          "signature": {
307345            "signature": {
307346              "publicKey": {}
307347            }
307348          },
307349          "modelCard": {
307350            "modelParameters": {
307351              "approach": {}
307352            },
307353            "quantitativeAnalysis": {
307354              "graphics": {}
307355            },
307356            "considerations": {}
307357          }
307358        },
307359        {
307360          "type": "library",
307361          "bom-ref": "pkg:npm/angular-cdp%40github:Gefix/angular-cdp%238776a59b9ec81343cf0a976052e3f4b8bc82e895?package-id=5893d32d0c0fd58d",
307362          "supplier": {},
307363          "name": "angular-cdp",
307364          "version": "github:Gefix/angular-cdp#8776a59b9ec81343cf0a976052e3f4b8bc82e895",
307365          "licenses": [
307366            {
307367              "license": {
307368                "id": "MIT"
307369              }
307370            }
307371          ],
307372          "cpe": "cpe:2.3:a:angular-cdp:angular-cdp:github\\:Gefix\\/angular-cdp\\#8776a59b9ec81343cf0a976052e3f4b8bc82e895:*:*:*:*:*:*:*",
307373          "purl": "pkg:npm/angular-cdp@github:Gefix/angular-cdp%238776a59b9ec81343cf0a976052e3f4b8bc82e895",
307374          "swid": {
307375            "attachment": {}
307376          },
307377          "pedigree": {},
307378          "evidence": {},
307379          "signature": {
307380            "signature": {
307381              "publicKey": {}
307382            }
307383          },
307384          "modelCard": {
307385            "modelParameters": {
307386              "approach": {}
307387            },
307388            "quantitativeAnalysis": {
307389              "graphics": {}
307390            },
307391            "considerations": {}
307392          }
307393        },
307394        {
307395          "type": "library",
307396          "bom-ref": "pkg:npm/angular-fusioncharts@3.0.4?package-id=5bdfa74375e8415b",
307397          "supplier": {},
307398          "name": "angular-fusioncharts",
307399          "version": "3.0.4",
307400          "licenses": [
307401            {
307402              "license": {
307403                "id": "MIT"
307404              }
307405            }
307406          ],
307407          "cpe": "cpe:2.3:a:angular-fusioncharts:angular-fusioncharts:3.0.4:*:*:*:*:*:*:*",
307408          "purl": "pkg:npm/angular-fusioncharts@3.0.4",
307409          "swid": {
307410            "attachment": {}
307411          },
307412          "pedigree": {},
307413          "evidence": {},
307414          "signature": {
307415            "signature": {
307416              "publicKey": {}
307417            }
307418          },
307419          "modelCard": {
307420            "modelParameters": {
307421              "approach": {}
307422            },
307423            "quantitativeAnalysis": {
307424              "graphics": {}
307425            },
307426            "considerations": {}
307427          }
307428        },
307429        {
307430          "type": "library",
307431          "bom-ref": "pkg:npm/angular-gridster2@9.3.3?package-id=b866683be9a4f17c",
307432          "supplier": {},
307433          "name": "angular-gridster2",
307434          "version": "9.3.3",
307435          "licenses": [
307436            {
307437              "license": {
307438                "id": "MIT"
307439              }
307440            }
307441          ],
307442          "cpe": "cpe:2.3:a:angular-gridster2:angular-gridster2:9.3.3:*:*:*:*:*:*:*",
307443          "purl": "pkg:npm/angular-gridster2@9.3.3",
307444          "swid": {
307445            "attachment": {}
307446          },
307447          "pedigree": {},
307448          "evidence": {},
307449          "signature": {
307450            "signature": {
307451              "publicKey": {}
307452            }
307453          },
307454          "modelCard": {
307455            "modelParameters": {
307456              "approach": {}
307457            },
307458            "quantitativeAnalysis": {
307459              "graphics": {}
307460            },
307461            "considerations": {}
307462          }
307463        },
307464        {
307465          "type": "library",
307466          "bom-ref": "pkg:npm/angular-resizable-element@3.3.0?package-id=a947a1cb0c9b3205",
307467          "supplier": {},
307468          "name": "angular-resizable-element",
307469          "version": "3.3.0",
307470          "licenses": [
307471            {
307472              "license": {
307473                "id": "MIT"
307474              }
307475            }
307476          ],
307477          "cpe": "cpe:2.3:a:angular-resizable-element:angular-resizable-element:3.3.0:*:*:*:*:*:*:*",
307478          "purl": "pkg:npm/angular-resizable-element@3.3.0",
307479          "swid": {
307480            "attachment": {}
307481          },
307482          "pedigree": {},
307483          "evidence": {},
307484          "signature": {
307485            "signature": {
307486              "publicKey": {}
307487            }
307488          },
307489          "modelCard": {
307490            "modelParameters": {
307491              "approach": {}
307492            },
307493            "quantitativeAnalysis": {
307494              "graphics": {}
307495            },
307496            "considerations": {}
307497          }
307498        },
307499        {
307500          "type": "library",
307501          "bom-ref": "pkg:npm/angular-resize-event@2.1.0?package-id=5a4b7e9921cb83ad",
307502          "supplier": {},
307503          "name": "angular-resize-event",
307504          "version": "2.1.0",
307505          "licenses": [
307506            {
307507              "license": {
307508                "id": "MIT"
307509              }
307510            }
307511          ],
307512          "cpe": "cpe:2.3:a:angular-resize-event:angular-resize-event:2.1.0:*:*:*:*:*:*:*",
307513          "purl": "pkg:npm/angular-resize-event@2.1.0",
307514          "swid": {
307515            "attachment": {}
307516          },
307517          "pedigree": {},
307518          "evidence": {},
307519          "signature": {
307520            "signature": {
307521              "publicKey": {}
307522            }
307523          },
307524          "modelCard": {
307525            "modelParameters": {
307526              "approach": {}
307527            },
307528            "quantitativeAnalysis": {
307529              "graphics": {}
307530            },
307531            "considerations": {}
307532          }
307533        },
307534        {
307535          "type": "library",
307536          "bom-ref": "pkg:npm/ansi-colors@3.2.4?package-id=edea7e2720756b6d",
307537          "supplier": {},
307538          "name": "ansi-colors",
307539          "version": "3.2.4",
307540          "licenses": [
307541            {
307542              "license": {
307543                "id": "MIT"
307544              }
307545            }
307546          ],
307547          "cpe": "cpe:2.3:a:ansi-colors:ansi-colors:3.2.4:*:*:*:*:*:*:*",
307548          "purl": "pkg:npm/ansi-colors@3.2.4",
307549          "swid": {
307550            "attachment": {}
307551          },
307552          "pedigree": {},
307553          "evidence": {},
307554          "signature": {
307555            "signature": {
307556              "publicKey": {}
307557            }
307558          },
307559          "modelCard": {
307560            "modelParameters": {
307561              "approach": {}
307562            },
307563            "quantitativeAnalysis": {
307564              "graphics": {}
307565            },
307566            "considerations": {}
307567          }
307568        },
307569        {
307570          "type": "library",
307571          "bom-ref": "pkg:npm/ansi-escapes@4.3.1?package-id=8de90a9db5569a8a",
307572          "supplier": {},
307573          "name": "ansi-escapes",
307574          "version": "4.3.1",
307575          "licenses": [
307576            {
307577              "license": {
307578                "id": "MIT"
307579              }
307580            }
307581          ],
307582          "cpe": "cpe:2.3:a:ansi-escapes:ansi-escapes:4.3.1:*:*:*:*:*:*:*",
307583          "purl": "pkg:npm/ansi-escapes@4.3.1",
307584          "swid": {
307585            "attachment": {}
307586          },
307587          "pedigree": {},
307588          "evidence": {},
307589          "signature": {
307590            "signature": {
307591              "publicKey": {}
307592            }
307593          },
307594          "modelCard": {
307595            "modelParameters": {
307596              "approach": {}
307597            },
307598            "quantitativeAnalysis": {
307599              "graphics": {}
307600            },
307601            "considerations": {}
307602          }
307603        },
307604        {
307605          "type": "library",
307606          "bom-ref": "pkg:npm/ansi-html@0.0.7?package-id=e5254bc3192cc2c7",
307607          "supplier": {},
307608          "name": "ansi-html",
307609          "version": "0.0.7",
307610          "licenses": [
307611            {
307612              "license": {
307613                "id": "Apache-2.0"
307614              }
307615            }
307616          ],
307617          "cpe": "cpe:2.3:a:ansi-html:ansi-html:0.0.7:*:*:*:*:*:*:*",
307618          "purl": "pkg:npm/ansi-html@0.0.7",
307619          "swid": {
307620            "attachment": {}
307621          },
307622          "pedigree": {},
307623          "evidence": {},
307624          "signature": {
307625            "signature": {
307626              "publicKey": {}
307627            }
307628          },
307629          "modelCard": {
307630            "modelParameters": {
307631              "approach": {}
307632            },
307633            "quantitativeAnalysis": {
307634              "graphics": {}
307635            },
307636            "considerations": {}
307637          }
307638        },
307639        {
307640          "type": "library",
307641          "bom-ref": "pkg:npm/ansi-regex@2.1.1?package-id=4c3f33d730c3d141",
307642          "supplier": {},
307643          "name": "ansi-regex",
307644          "version": "2.1.1",
307645          "licenses": [
307646            {
307647              "license": {
307648                "id": "MIT"
307649              }
307650            }
307651          ],
307652          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:2.1.1:*:*:*:*:*:*:*",
307653          "purl": "pkg:npm/ansi-regex@2.1.1",
307654          "swid": {
307655            "attachment": {}
307656          },
307657          "pedigree": {},
307658          "evidence": {},
307659          "signature": {
307660            "signature": {
307661              "publicKey": {}
307662            }
307663          },
307664          "modelCard": {
307665            "modelParameters": {
307666              "approach": {}
307667            },
307668            "quantitativeAnalysis": {
307669              "graphics": {}
307670            },
307671            "considerations": {}
307672          }
307673        },
307674        {
307675          "type": "library",
307676          "bom-ref": "pkg:npm/ansi-regex@5.0.1?package-id=4083d0234e484d9c",
307677          "supplier": {},
307678          "name": "ansi-regex",
307679          "version": "5.0.1",
307680          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:5.0.1:*:*:*:*:*:*:*",
307681          "purl": "pkg:npm/ansi-regex@5.0.1",
307682          "swid": {
307683            "attachment": {}
307684          },
307685          "pedigree": {},
307686          "evidence": {},
307687          "signature": {
307688            "signature": {
307689              "publicKey": {}
307690            }
307691          },
307692          "modelCard": {
307693            "modelParameters": {
307694              "approach": {}
307695            },
307696            "quantitativeAnalysis": {
307697              "graphics": {}
307698            },
307699            "considerations": {}
307700          }
307701        },
307702        {
307703          "type": "library",
307704          "bom-ref": "pkg:npm/ansi-styles@3.2.1?package-id=f071209e8844227d",
307705          "supplier": {},
307706          "name": "ansi-styles",
307707          "version": "3.2.1",
307708          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:3.2.1:*:*:*:*:*:*:*",
307709          "purl": "pkg:npm/ansi-styles@3.2.1",
307710          "swid": {
307711            "attachment": {}
307712          },
307713          "pedigree": {},
307714          "evidence": {},
307715          "signature": {
307716            "signature": {
307717              "publicKey": {}
307718            }
307719          },
307720          "modelCard": {
307721            "modelParameters": {
307722              "approach": {}
307723            },
307724            "quantitativeAnalysis": {
307725              "graphics": {}
307726            },
307727            "considerations": {}
307728          }
307729        },
307730        {
307731          "type": "library",
307732          "bom-ref": "pkg:npm/ansi-styles@3.2.1?package-id=dd584a845b779ccd",
307733          "supplier": {},
307734          "name": "ansi-styles",
307735          "version": "3.2.1",
307736          "licenses": [
307737            {
307738              "license": {
307739                "id": "MIT"
307740              }
307741            }
307742          ],
307743          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:3.2.1:*:*:*:*:*:*:*",
307744          "purl": "pkg:npm/ansi-styles@3.2.1",
307745          "swid": {
307746            "attachment": {}
307747          },
307748          "pedigree": {},
307749          "evidence": {},
307750          "signature": {
307751            "signature": {
307752              "publicKey": {}
307753            }
307754          },
307755          "modelCard": {
307756            "modelParameters": {
307757              "approach": {}
307758            },
307759            "quantitativeAnalysis": {
307760              "graphics": {}
307761            },
307762            "considerations": {}
307763          }
307764        },
307765        {
307766          "type": "library",
307767          "bom-ref": "pkg:npm/any-promise@1.3.0?package-id=f28a7c07043ce752",
307768          "supplier": {},
307769          "name": "any-promise",
307770          "version": "1.3.0",
307771          "licenses": [
307772            {
307773              "license": {
307774                "id": "MIT"
307775              }
307776            }
307777          ],
307778          "cpe": "cpe:2.3:a:any-promise:any-promise:1.3.0:*:*:*:*:*:*:*",
307779          "purl": "pkg:npm/any-promise@1.3.0",
307780          "swid": {
307781            "attachment": {}
307782          },
307783          "pedigree": {},
307784          "evidence": {},
307785          "signature": {
307786            "signature": {
307787              "publicKey": {}
307788            }
307789          },
307790          "modelCard": {
307791            "modelParameters": {
307792              "approach": {}
307793            },
307794            "quantitativeAnalysis": {
307795              "graphics": {}
307796            },
307797            "considerations": {}
307798          }
307799        },
307800        {
307801          "type": "library",
307802          "bom-ref": "pkg:npm/anymatch@3.1.1?package-id=e2bd4213fa7416ba",
307803          "supplier": {},
307804          "name": "anymatch",
307805          "version": "3.1.1",
307806          "licenses": [
307807            {
307808              "license": {
307809                "id": "ISC"
307810              }
307811            }
307812          ],
307813          "cpe": "cpe:2.3:a:anymatch:anymatch:3.1.1:*:*:*:*:*:*:*",
307814          "purl": "pkg:npm/anymatch@3.1.1",
307815          "swid": {
307816            "attachment": {}
307817          },
307818          "pedigree": {},
307819          "evidence": {},
307820          "signature": {
307821            "signature": {
307822              "publicKey": {}
307823            }
307824          },
307825          "modelCard": {
307826            "modelParameters": {
307827              "approach": {}
307828            },
307829            "quantitativeAnalysis": {
307830              "graphics": {}
307831            },
307832            "considerations": {}
307833          }
307834        },
307835        {
307836          "type": "library",
307837          "bom-ref": "pkg:npm/app-root-path@2.2.1?package-id=d11e3981172a392",
307838          "supplier": {},
307839          "name": "app-root-path",
307840          "version": "2.2.1",
307841          "licenses": [
307842            {
307843              "license": {
307844                "id": "MIT"
307845              }
307846            }
307847          ],
307848          "cpe": "cpe:2.3:a:app-root-path:app-root-path:2.2.1:*:*:*:*:*:*:*",
307849          "purl": "pkg:npm/app-root-path@2.2.1",
307850          "swid": {
307851            "attachment": {}
307852          },
307853          "pedigree": {},
307854          "evidence": {},
307855          "signature": {
307856            "signature": {
307857              "publicKey": {}
307858            }
307859          },
307860          "modelCard": {
307861            "modelParameters": {
307862              "approach": {}
307863            },
307864            "quantitativeAnalysis": {
307865              "graphics": {}
307866            },
307867            "considerations": {}
307868          }
307869        },
307870        {
307871          "type": "library",
307872          "bom-ref": "pkg:npm/append-transform@1.0.0?package-id=6a4ac832863276cc",
307873          "supplier": {},
307874          "name": "append-transform",
307875          "version": "1.0.0",
307876          "licenses": [
307877            {
307878              "license": {
307879                "id": "MIT"
307880              }
307881            }
307882          ],
307883          "cpe": "cpe:2.3:a:append-transform:append-transform:1.0.0:*:*:*:*:*:*:*",
307884          "purl": "pkg:npm/append-transform@1.0.0",
307885          "swid": {
307886            "attachment": {}
307887          },
307888          "pedigree": {},
307889          "evidence": {},
307890          "signature": {
307891            "signature": {
307892              "publicKey": {}
307893            }
307894          },
307895          "modelCard": {
307896            "modelParameters": {
307897              "approach": {}
307898            },
307899            "quantitativeAnalysis": {
307900              "graphics": {}
307901            },
307902            "considerations": {}
307903          }
307904        },
307905        {
307906          "type": "library",
307907          "bom-ref": "pkg:npm/append-transform@2.0.0?package-id=7079a97c0aa712a3",
307908          "supplier": {},
307909          "name": "append-transform",
307910          "version": "2.0.0",
307911          "cpe": "cpe:2.3:a:append-transform:append-transform:2.0.0:*:*:*:*:*:*:*",
307912          "purl": "pkg:npm/append-transform@2.0.0",
307913          "swid": {
307914            "attachment": {}
307915          },
307916          "pedigree": {},
307917          "evidence": {},
307918          "signature": {
307919            "signature": {
307920              "publicKey": {}
307921            }
307922          },
307923          "modelCard": {
307924            "modelParameters": {
307925              "approach": {}
307926            },
307927            "quantitativeAnalysis": {
307928              "graphics": {}
307929            },
307930            "considerations": {}
307931          }
307932        },
307933        {
307934          "type": "library",
307935          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=26312ccc3db233c7",
307936          "supplier": {},
307937          "name": "aproba",
307938          "version": "1.2.0",
307939          "licenses": [
307940            {
307941              "license": {
307942                "id": "ISC"
307943              }
307944            }
307945          ],
307946          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
307947          "purl": "pkg:npm/aproba@1.2.0",
307948          "swid": {
307949            "attachment": {}
307950          },
307951          "pedigree": {},
307952          "evidence": {},
307953          "signature": {
307954            "signature": {
307955              "publicKey": {}
307956            }
307957          },
307958          "modelCard": {
307959            "modelParameters": {
307960              "approach": {}
307961            },
307962            "quantitativeAnalysis": {
307963              "graphics": {}
307964            },
307965            "considerations": {}
307966          }
307967        },
307968        {
307969          "type": "library",
307970          "bom-ref": "pkg:npm/archy@1.0.0?package-id=7a8ddc96c4302a00",
307971          "supplier": {},
307972          "name": "archy",
307973          "version": "1.0.0",
307974          "cpe": "cpe:2.3:a:archy:archy:1.0.0:*:*:*:*:*:*:*",
307975          "purl": "pkg:npm/archy@1.0.0",
307976          "swid": {
307977            "attachment": {}
307978          },
307979          "pedigree": {},
307980          "evidence": {},
307981          "signature": {
307982            "signature": {
307983              "publicKey": {}
307984            }
307985          },
307986          "modelCard": {
307987            "modelParameters": {
307988              "approach": {}
307989            },
307990            "quantitativeAnalysis": {
307991              "graphics": {}
307992            },
307993            "considerations": {}
307994          }
307995        },
307996        {
307997          "type": "library",
307998          "bom-ref": "pkg:npm/are-we-there-yet@1.1.5?package-id=11fae05134c64fa6",
307999          "supplier": {},
308000          "name": "are-we-there-yet",
308001          "version": "1.1.5",
308002          "licenses": [
308003            {
308004              "license": {
308005                "id": "ISC"
308006              }
308007            }
308008          ],
308009          "cpe": "cpe:2.3:a:are-we-there-yet:are-we-there-yet:1.1.5:*:*:*:*:*:*:*",
308010          "purl": "pkg:npm/are-we-there-yet@1.1.5",
308011          "swid": {
308012            "attachment": {}
308013          },
308014          "pedigree": {},
308015          "evidence": {},
308016          "signature": {
308017            "signature": {
308018              "publicKey": {}
308019            }
308020          },
308021          "modelCard": {
308022            "modelParameters": {
308023              "approach": {}
308024            },
308025            "quantitativeAnalysis": {
308026              "graphics": {}
308027            },
308028            "considerations": {}
308029          }
308030        },
308031        {
308032          "type": "library",
308033          "bom-ref": "pkg:npm/arg@4.1.3?package-id=ab47977515b621d7",
308034          "supplier": {},
308035          "name": "arg",
308036          "version": "4.1.3",
308037          "licenses": [
308038            {
308039              "license": {
308040                "id": "MIT"
308041              }
308042            }
308043          ],
308044          "cpe": "cpe:2.3:a:arg:arg:4.1.3:*:*:*:*:*:*:*",
308045          "purl": "pkg:npm/arg@4.1.3",
308046          "swid": {
308047            "attachment": {}
308048          },
308049          "pedigree": {},
308050          "evidence": {},
308051          "signature": {
308052            "signature": {
308053              "publicKey": {}
308054            }
308055          },
308056          "modelCard": {
308057            "modelParameters": {
308058              "approach": {}
308059            },
308060            "quantitativeAnalysis": {
308061              "graphics": {}
308062            },
308063            "considerations": {}
308064          }
308065        },
308066        {
308067          "type": "library",
308068          "bom-ref": "pkg:npm/argparse@1.0.10?package-id=8220f116e6648beb",
308069          "supplier": {},
308070          "name": "argparse",
308071          "version": "1.0.10",
308072          "cpe": "cpe:2.3:a:argparse:argparse:1.0.10:*:*:*:*:*:*:*",
308073          "purl": "pkg:npm/argparse@1.0.10",
308074          "swid": {
308075            "attachment": {}
308076          },
308077          "pedigree": {},
308078          "evidence": {},
308079          "signature": {
308080            "signature": {
308081              "publicKey": {}
308082            }
308083          },
308084          "modelCard": {
308085            "modelParameters": {
308086              "approach": {}
308087            },
308088            "quantitativeAnalysis": {
308089              "graphics": {}
308090            },
308091            "considerations": {}
308092          }
308093        },
308094        {
308095          "type": "library",
308096          "bom-ref": "pkg:npm/argparse@2.0.1?package-id=81734116745253e0",
308097          "supplier": {},
308098          "name": "argparse",
308099          "version": "2.0.1",
308100          "licenses": [
308101            {
308102              "license": {
308103                "id": "Python-2.0"
308104              }
308105            }
308106          ],
308107          "cpe": "cpe:2.3:a:argparse:argparse:2.0.1:*:*:*:*:*:*:*",
308108          "purl": "pkg:npm/argparse@2.0.1",
308109          "swid": {
308110            "attachment": {}
308111          },
308112          "pedigree": {},
308113          "evidence": {},
308114          "signature": {
308115            "signature": {
308116              "publicKey": {}
308117            }
308118          },
308119          "modelCard": {
308120            "modelParameters": {
308121              "approach": {}
308122            },
308123            "quantitativeAnalysis": {
308124              "graphics": {}
308125            },
308126            "considerations": {}
308127          }
308128        },
308129        {
308130          "type": "library",
308131          "bom-ref": "pkg:npm/aria-query@3.0.0?package-id=1a836b764df86d00",
308132          "supplier": {},
308133          "name": "aria-query",
308134          "version": "3.0.0",
308135          "licenses": [
308136            {
308137              "license": {
308138                "id": "Apache-2.0"
308139              }
308140            }
308141          ],
308142          "cpe": "cpe:2.3:a:aria-query:aria-query:3.0.0:*:*:*:*:*:*:*",
308143          "purl": "pkg:npm/aria-query@3.0.0",
308144          "swid": {
308145            "attachment": {}
308146          },
308147          "pedigree": {},
308148          "evidence": {},
308149          "signature": {
308150            "signature": {
308151              "publicKey": {}
308152            }
308153          },
308154          "modelCard": {
308155            "modelParameters": {
308156              "approach": {}
308157            },
308158            "quantitativeAnalysis": {
308159              "graphics": {}
308160            },
308161            "considerations": {}
308162          }
308163        },
308164        {
308165          "type": "library",
308166          "bom-ref": "pkg:npm/arr-diff@4.0.0?package-id=78b26b18eb1635a7",
308167          "supplier": {},
308168          "name": "arr-diff",
308169          "version": "4.0.0",
308170          "licenses": [
308171            {
308172              "license": {
308173                "id": "MIT"
308174              }
308175            }
308176          ],
308177          "cpe": "cpe:2.3:a:arr-diff:arr-diff:4.0.0:*:*:*:*:*:*:*",
308178          "purl": "pkg:npm/arr-diff@4.0.0",
308179          "swid": {
308180            "attachment": {}
308181          },
308182          "pedigree": {},
308183          "evidence": {},
308184          "signature": {
308185            "signature": {
308186              "publicKey": {}
308187            }
308188          },
308189          "modelCard": {
308190            "modelParameters": {
308191              "approach": {}
308192            },
308193            "quantitativeAnalysis": {
308194              "graphics": {}
308195            },
308196            "considerations": {}
308197          }
308198        },
308199        {
308200          "type": "library",
308201          "bom-ref": "pkg:npm/arr-flatten@1.1.0?package-id=88395b85061ad198",
308202          "supplier": {},
308203          "name": "arr-flatten",
308204          "version": "1.1.0",
308205          "licenses": [
308206            {
308207              "license": {
308208                "id": "MIT"
308209              }
308210            }
308211          ],
308212          "cpe": "cpe:2.3:a:arr-flatten:arr-flatten:1.1.0:*:*:*:*:*:*:*",
308213          "purl": "pkg:npm/arr-flatten@1.1.0",
308214          "swid": {
308215            "attachment": {}
308216          },
308217          "pedigree": {},
308218          "evidence": {},
308219          "signature": {
308220            "signature": {
308221              "publicKey": {}
308222            }
308223          },
308224          "modelCard": {
308225            "modelParameters": {
308226              "approach": {}
308227            },
308228            "quantitativeAnalysis": {
308229              "graphics": {}
308230            },
308231            "considerations": {}
308232          }
308233        },
308234        {
308235          "type": "library",
308236          "bom-ref": "pkg:npm/arr-union@3.1.0?package-id=8c2279d86846bdd8",
308237          "supplier": {},
308238          "name": "arr-union",
308239          "version": "3.1.0",
308240          "licenses": [
308241            {
308242              "license": {
308243                "id": "MIT"
308244              }
308245            }
308246          ],
308247          "cpe": "cpe:2.3:a:arr-union:arr-union:3.1.0:*:*:*:*:*:*:*",
308248          "purl": "pkg:npm/arr-union@3.1.0",
308249          "swid": {
308250            "attachment": {}
308251          },
308252          "pedigree": {},
308253          "evidence": {},
308254          "signature": {
308255            "signature": {
308256              "publicKey": {}
308257            }
308258          },
308259          "modelCard": {
308260            "modelParameters": {
308261              "approach": {}
308262            },
308263            "quantitativeAnalysis": {
308264              "graphics": {}
308265            },
308266            "considerations": {}
308267          }
308268        },
308269        {
308270          "type": "library",
308271          "bom-ref": "pkg:npm/array-find-index@1.0.2?package-id=5189f5348b9a726c",
308272          "supplier": {},
308273          "name": "array-find-index",
308274          "version": "1.0.2",
308275          "licenses": [
308276            {
308277              "license": {
308278                "id": "MIT"
308279              }
308280            }
308281          ],
308282          "cpe": "cpe:2.3:a:array-find-index:array-find-index:1.0.2:*:*:*:*:*:*:*",
308283          "purl": "pkg:npm/array-find-index@1.0.2",
308284          "swid": {
308285            "attachment": {}
308286          },
308287          "pedigree": {},
308288          "evidence": {},
308289          "signature": {
308290            "signature": {
308291              "publicKey": {}
308292            }
308293          },
308294          "modelCard": {
308295            "modelParameters": {
308296              "approach": {}
308297            },
308298            "quantitativeAnalysis": {
308299              "graphics": {}
308300            },
308301            "considerations": {}
308302          }
308303        },
308304        {
308305          "type": "library",
308306          "bom-ref": "pkg:npm/array-flatten@2.1.2?package-id=920330be94b99f7f",
308307          "supplier": {},
308308          "name": "array-flatten",
308309          "version": "2.1.2",
308310          "licenses": [
308311            {
308312              "license": {
308313                "id": "MIT"
308314              }
308315            }
308316          ],
308317          "cpe": "cpe:2.3:a:array-flatten:array-flatten:2.1.2:*:*:*:*:*:*:*",
308318          "purl": "pkg:npm/array-flatten@2.1.2",
308319          "swid": {
308320            "attachment": {}
308321          },
308322          "pedigree": {},
308323          "evidence": {},
308324          "signature": {
308325            "signature": {
308326              "publicKey": {}
308327            }
308328          },
308329          "modelCard": {
308330            "modelParameters": {
308331              "approach": {}
308332            },
308333            "quantitativeAnalysis": {
308334              "graphics": {}
308335            },
308336            "considerations": {}
308337          }
308338        },
308339        {
308340          "type": "library",
308341          "bom-ref": "pkg:npm/array-union@1.0.2?package-id=4559fd093daca1af",
308342          "supplier": {},
308343          "name": "array-union",
308344          "version": "1.0.2",
308345          "licenses": [
308346            {
308347              "license": {
308348                "id": "MIT"
308349              }
308350            }
308351          ],
308352          "cpe": "cpe:2.3:a:array-union:array-union:1.0.2:*:*:*:*:*:*:*",
308353          "purl": "pkg:npm/array-union@1.0.2",
308354          "swid": {
308355            "attachment": {}
308356          },
308357          "pedigree": {},
308358          "evidence": {},
308359          "signature": {
308360            "signature": {
308361              "publicKey": {}
308362            }
308363          },
308364          "modelCard": {
308365            "modelParameters": {
308366              "approach": {}
308367            },
308368            "quantitativeAnalysis": {
308369              "graphics": {}
308370            },
308371            "considerations": {}
308372          }
308373        },
308374        {
308375          "type": "library",
308376          "bom-ref": "pkg:npm/array-uniq@1.0.3?package-id=4b36d749d0008df2",
308377          "supplier": {},
308378          "name": "array-uniq",
308379          "version": "1.0.3",
308380          "licenses": [
308381            {
308382              "license": {
308383                "id": "MIT"
308384              }
308385            }
308386          ],
308387          "cpe": "cpe:2.3:a:array-uniq:array-uniq:1.0.3:*:*:*:*:*:*:*",
308388          "purl": "pkg:npm/array-uniq@1.0.3",
308389          "swid": {
308390            "attachment": {}
308391          },
308392          "pedigree": {},
308393          "evidence": {},
308394          "signature": {
308395            "signature": {
308396              "publicKey": {}
308397            }
308398          },
308399          "modelCard": {
308400            "modelParameters": {
308401              "approach": {}
308402            },
308403            "quantitativeAnalysis": {
308404              "graphics": {}
308405            },
308406            "considerations": {}
308407          }
308408        },
308409        {
308410          "type": "library",
308411          "bom-ref": "pkg:npm/array-unique@0.3.2?package-id=8553b80422783880",
308412          "supplier": {},
308413          "name": "array-unique",
308414          "version": "0.3.2",
308415          "licenses": [
308416            {
308417              "license": {
308418                "id": "MIT"
308419              }
308420            }
308421          ],
308422          "cpe": "cpe:2.3:a:array-unique:array-unique:0.3.2:*:*:*:*:*:*:*",
308423          "purl": "pkg:npm/array-unique@0.3.2",
308424          "swid": {
308425            "attachment": {}
308426          },
308427          "pedigree": {},
308428          "evidence": {},
308429          "signature": {
308430            "signature": {
308431              "publicKey": {}
308432            }
308433          },
308434          "modelCard": {
308435            "modelParameters": {
308436              "approach": {}
308437            },
308438            "quantitativeAnalysis": {
308439              "graphics": {}
308440            },
308441            "considerations": {}
308442          }
308443        },
308444        {
308445          "type": "library",
308446          "bom-ref": "pkg:npm/arraybuffer.slice@0.0.7?package-id=52673ec6562cb836",
308447          "supplier": {},
308448          "name": "arraybuffer.slice",
308449          "version": "0.0.7",
308450          "licenses": [
308451            {
308452              "license": {
308453                "id": "MIT"
308454              }
308455            }
308456          ],
308457          "cpe": "cpe:2.3:a:arraybuffer.slice:arraybuffer.slice:0.0.7:*:*:*:*:*:*:*",
308458          "purl": "pkg:npm/arraybuffer.slice@0.0.7",
308459          "swid": {
308460            "attachment": {}
308461          },
308462          "pedigree": {},
308463          "evidence": {},
308464          "signature": {
308465            "signature": {
308466              "publicKey": {}
308467            }
308468          },
308469          "modelCard": {
308470            "modelParameters": {
308471              "approach": {}
308472            },
308473            "quantitativeAnalysis": {
308474              "graphics": {}
308475            },
308476            "considerations": {}
308477          }
308478        },
308479        {
308480          "type": "library",
308481          "bom-ref": "pkg:npm/arrify@1.0.1?package-id=d3bd2823b5a514bf",
308482          "supplier": {},
308483          "name": "arrify",
308484          "version": "1.0.1",
308485          "licenses": [
308486            {
308487              "license": {
308488                "id": "MIT"
308489              }
308490            }
308491          ],
308492          "cpe": "cpe:2.3:a:arrify:arrify:1.0.1:*:*:*:*:*:*:*",
308493          "purl": "pkg:npm/arrify@1.0.1",
308494          "swid": {
308495            "attachment": {}
308496          },
308497          "pedigree": {},
308498          "evidence": {},
308499          "signature": {
308500            "signature": {
308501              "publicKey": {}
308502            }
308503          },
308504          "modelCard": {
308505            "modelParameters": {
308506              "approach": {}
308507            },
308508            "quantitativeAnalysis": {
308509              "graphics": {}
308510            },
308511            "considerations": {}
308512          }
308513        },
308514        {
308515          "type": "library",
308516          "bom-ref": "pkg:npm/asap@2.0.6?package-id=2345b3eca7fb914c",
308517          "supplier": {},
308518          "name": "asap",
308519          "version": "2.0.6",
308520          "licenses": [
308521            {
308522              "license": {
308523                "id": "MIT"
308524              }
308525            }
308526          ],
308527          "cpe": "cpe:2.3:a:asap:asap:2.0.6:*:*:*:*:*:*:*",
308528          "purl": "pkg:npm/asap@2.0.6",
308529          "swid": {
308530            "attachment": {}
308531          },
308532          "pedigree": {},
308533          "evidence": {},
308534          "signature": {
308535            "signature": {
308536              "publicKey": {}
308537            }
308538          },
308539          "modelCard": {
308540            "modelParameters": {
308541              "approach": {}
308542            },
308543            "quantitativeAnalysis": {
308544              "graphics": {}
308545            },
308546            "considerations": {}
308547          }
308548        },
308549        {
308550          "type": "library",
308551          "bom-ref": "pkg:npm/asn1@0.2.4?package-id=c94afbf24b23465d",
308552          "supplier": {},
308553          "name": "asn1",
308554          "version": "0.2.4",
308555          "licenses": [
308556            {
308557              "license": {
308558                "id": "MIT"
308559              }
308560            }
308561          ],
308562          "cpe": "cpe:2.3:a:asn1:asn1:0.2.4:*:*:*:*:*:*:*",
308563          "purl": "pkg:npm/asn1@0.2.4",
308564          "swid": {
308565            "attachment": {}
308566          },
308567          "pedigree": {},
308568          "evidence": {},
308569          "signature": {
308570            "signature": {
308571              "publicKey": {}
308572            }
308573          },
308574          "modelCard": {
308575            "modelParameters": {
308576              "approach": {}
308577            },
308578            "quantitativeAnalysis": {
308579              "graphics": {}
308580            },
308581            "considerations": {}
308582          }
308583        },
308584        {
308585          "type": "library",
308586          "bom-ref": "pkg:npm/asn1.js@4.10.1?package-id=58b36969d7e7b65a",
308587          "supplier": {},
308588          "name": "asn1.js",
308589          "version": "4.10.1",
308590          "licenses": [
308591            {
308592              "license": {
308593                "id": "MIT"
308594              }
308595            }
308596          ],
308597          "cpe": "cpe:2.3:a:asn1.js:asn1.js:4.10.1:*:*:*:*:*:*:*",
308598          "purl": "pkg:npm/asn1.js@4.10.1",
308599          "swid": {
308600            "attachment": {}
308601          },
308602          "pedigree": {},
308603          "evidence": {},
308604          "signature": {
308605            "signature": {
308606              "publicKey": {}
308607            }
308608          },
308609          "modelCard": {
308610            "modelParameters": {
308611              "approach": {}
308612            },
308613            "quantitativeAnalysis": {
308614              "graphics": {}
308615            },
308616            "considerations": {}
308617          }
308618        },
308619        {
308620          "type": "library",
308621          "bom-ref": "pkg:npm/assert@1.5.0?package-id=942fc878822354e6",
308622          "supplier": {},
308623          "name": "assert",
308624          "version": "1.5.0",
308625          "licenses": [
308626            {
308627              "license": {
308628                "id": "MIT"
308629              }
308630            }
308631          ],
308632          "cpe": "cpe:2.3:a:assert:assert:1.5.0:*:*:*:*:*:*:*",
308633          "purl": "pkg:npm/assert@1.5.0",
308634          "swid": {
308635            "attachment": {}
308636          },
308637          "pedigree": {},
308638          "evidence": {},
308639          "signature": {
308640            "signature": {
308641              "publicKey": {}
308642            }
308643          },
308644          "modelCard": {
308645            "modelParameters": {
308646              "approach": {}
308647            },
308648            "quantitativeAnalysis": {
308649              "graphics": {}
308650            },
308651            "considerations": {}
308652          }
308653        },
308654        {
308655          "type": "library",
308656          "bom-ref": "pkg:npm/assert-plus@1.0.0?package-id=5390131abace4c0",
308657          "supplier": {},
308658          "name": "assert-plus",
308659          "version": "1.0.0",
308660          "licenses": [
308661            {
308662              "license": {
308663                "id": "MIT"
308664              }
308665            }
308666          ],
308667          "cpe": "cpe:2.3:a:assert-plus:assert-plus:1.0.0:*:*:*:*:*:*:*",
308668          "purl": "pkg:npm/assert-plus@1.0.0",
308669          "swid": {
308670            "attachment": {}
308671          },
308672          "pedigree": {},
308673          "evidence": {},
308674          "signature": {
308675            "signature": {
308676              "publicKey": {}
308677            }
308678          },
308679          "modelCard": {
308680            "modelParameters": {
308681              "approach": {}
308682            },
308683            "quantitativeAnalysis": {
308684              "graphics": {}
308685            },
308686            "considerations": {}
308687          }
308688        },
308689        {
308690          "type": "library",
308691          "bom-ref": "pkg:npm/assign-symbols@1.0.0?package-id=95b61e83770f8f1a",
308692          "supplier": {},
308693          "name": "assign-symbols",
308694          "version": "1.0.0",
308695          "licenses": [
308696            {
308697              "license": {
308698                "id": "MIT"
308699              }
308700            }
308701          ],
308702          "cpe": "cpe:2.3:a:assign-symbols:assign-symbols:1.0.0:*:*:*:*:*:*:*",
308703          "purl": "pkg:npm/assign-symbols@1.0.0",
308704          "swid": {
308705            "attachment": {}
308706          },
308707          "pedigree": {},
308708          "evidence": {},
308709          "signature": {
308710            "signature": {
308711              "publicKey": {}
308712            }
308713          },
308714          "modelCard": {
308715            "modelParameters": {
308716              "approach": {}
308717            },
308718            "quantitativeAnalysis": {
308719              "graphics": {}
308720            },
308721            "considerations": {}
308722          }
308723        },
308724        {
308725          "type": "library",
308726          "bom-ref": "pkg:npm/ast-types@0.13.3?package-id=c9be805e2b791814",
308727          "supplier": {},
308728          "name": "ast-types",
308729          "version": "0.13.3",
308730          "licenses": [
308731            {
308732              "license": {
308733                "id": "MIT"
308734              }
308735            }
308736          ],
308737          "cpe": "cpe:2.3:a:ast-types:ast-types:0.13.3:*:*:*:*:*:*:*",
308738          "purl": "pkg:npm/ast-types@0.13.3",
308739          "swid": {
308740            "attachment": {}
308741          },
308742          "pedigree": {},
308743          "evidence": {},
308744          "signature": {
308745            "signature": {
308746              "publicKey": {}
308747            }
308748          },
308749          "modelCard": {
308750            "modelParameters": {
308751              "approach": {}
308752            },
308753            "quantitativeAnalysis": {
308754              "graphics": {}
308755            },
308756            "considerations": {}
308757          }
308758        },
308759        {
308760          "type": "library",
308761          "bom-ref": "pkg:npm/ast-types-flow@0.0.7?package-id=129890ff62c8555c",
308762          "supplier": {},
308763          "name": "ast-types-flow",
308764          "version": "0.0.7",
308765          "licenses": [
308766            {
308767              "license": {
308768                "id": "ISC"
308769              }
308770            }
308771          ],
308772          "cpe": "cpe:2.3:a:ast-types-flow:ast-types-flow:0.0.7:*:*:*:*:*:*:*",
308773          "purl": "pkg:npm/ast-types-flow@0.0.7",
308774          "swid": {
308775            "attachment": {}
308776          },
308777          "pedigree": {},
308778          "evidence": {},
308779          "signature": {
308780            "signature": {
308781              "publicKey": {}
308782            }
308783          },
308784          "modelCard": {
308785            "modelParameters": {
308786              "approach": {}
308787            },
308788            "quantitativeAnalysis": {
308789              "graphics": {}
308790            },
308791            "considerations": {}
308792          }
308793        },
308794        {
308795          "type": "library",
308796          "bom-ref": "pkg:npm/async@2.6.3?package-id=2404c94cc2ed3c23",
308797          "supplier": {},
308798          "name": "async",
308799          "version": "2.6.3",
308800          "licenses": [
308801            {
308802              "license": {
308803                "id": "MIT"
308804              }
308805            }
308806          ],
308807          "cpe": "cpe:2.3:a:async:async:2.6.3:*:*:*:*:*:*:*",
308808          "purl": "pkg:npm/async@2.6.3",
308809          "swid": {
308810            "attachment": {}
308811          },
308812          "pedigree": {},
308813          "evidence": {},
308814          "signature": {
308815            "signature": {
308816              "publicKey": {}
308817            }
308818          },
308819          "modelCard": {
308820            "modelParameters": {
308821              "approach": {}
308822            },
308823            "quantitativeAnalysis": {
308824              "graphics": {}
308825            },
308826            "considerations": {}
308827          }
308828        },
308829        {
308830          "type": "library",
308831          "bom-ref": "pkg:npm/async-each@1.0.3?package-id=53464a83d9092baa",
308832          "supplier": {},
308833          "name": "async-each",
308834          "version": "1.0.3",
308835          "licenses": [
308836            {
308837              "license": {
308838                "id": "MIT"
308839              }
308840            }
308841          ],
308842          "cpe": "cpe:2.3:a:async-each:async-each:1.0.3:*:*:*:*:*:*:*",
308843          "purl": "pkg:npm/async-each@1.0.3",
308844          "swid": {
308845            "attachment": {}
308846          },
308847          "pedigree": {},
308848          "evidence": {},
308849          "signature": {
308850            "signature": {
308851              "publicKey": {}
308852            }
308853          },
308854          "modelCard": {
308855            "modelParameters": {
308856              "approach": {}
308857            },
308858            "quantitativeAnalysis": {
308859              "graphics": {}
308860            },
308861            "considerations": {}
308862          }
308863        },
308864        {
308865          "type": "library",
308866          "bom-ref": "pkg:npm/async-foreach@0.1.3?package-id=1ee09f4c46b450fa",
308867          "supplier": {},
308868          "name": "async-foreach",
308869          "version": "0.1.3",
308870          "cpe": "cpe:2.3:a:async-foreach:async-foreach:0.1.3:*:*:*:*:*:*:*",
308871          "purl": "pkg:npm/async-foreach@0.1.3",
308872          "swid": {
308873            "attachment": {}
308874          },
308875          "pedigree": {},
308876          "evidence": {},
308877          "signature": {
308878            "signature": {
308879              "publicKey": {}
308880            }
308881          },
308882          "modelCard": {
308883            "modelParameters": {
308884              "approach": {}
308885            },
308886            "quantitativeAnalysis": {
308887              "graphics": {}
308888            },
308889            "considerations": {}
308890          }
308891        },
308892        {
308893          "type": "library",
308894          "bom-ref": "pkg:npm/async-limiter@1.0.1?package-id=37f39b275bd1ee5",
308895          "supplier": {},
308896          "name": "async-limiter",
308897          "version": "1.0.1",
308898          "licenses": [
308899            {
308900              "license": {
308901                "id": "MIT"
308902              }
308903            }
308904          ],
308905          "cpe": "cpe:2.3:a:async-limiter:async-limiter:1.0.1:*:*:*:*:*:*:*",
308906          "purl": "pkg:npm/async-limiter@1.0.1",
308907          "swid": {
308908            "attachment": {}
308909          },
308910          "pedigree": {},
308911          "evidence": {},
308912          "signature": {
308913            "signature": {
308914              "publicKey": {}
308915            }
308916          },
308917          "modelCard": {
308918            "modelParameters": {
308919              "approach": {}
308920            },
308921            "quantitativeAnalysis": {
308922              "graphics": {}
308923            },
308924            "considerations": {}
308925          }
308926        },
308927        {
308928          "type": "library",
308929          "bom-ref": "pkg:npm/asynckit@0.4.0?package-id=4cfcce01cadf2d8d",
308930          "supplier": {},
308931          "name": "asynckit",
308932          "version": "0.4.0",
308933          "licenses": [
308934            {
308935              "license": {
308936                "id": "MIT"
308937              }
308938            }
308939          ],
308940          "cpe": "cpe:2.3:a:asynckit:asynckit:0.4.0:*:*:*:*:*:*:*",
308941          "purl": "pkg:npm/asynckit@0.4.0",
308942          "swid": {
308943            "attachment": {}
308944          },
308945          "pedigree": {},
308946          "evidence": {},
308947          "signature": {
308948            "signature": {
308949              "publicKey": {}
308950            }
308951          },
308952          "modelCard": {
308953            "modelParameters": {
308954              "approach": {}
308955            },
308956            "quantitativeAnalysis": {
308957              "graphics": {}
308958            },
308959            "considerations": {}
308960          }
308961        },
308962        {
308963          "type": "library",
308964          "bom-ref": "pkg:npm/atob@2.1.2?package-id=49889b9737f90938",
308965          "supplier": {},
308966          "name": "atob",
308967          "version": "2.1.2",
308968          "licenses": [
308969            {
308970              "license": {
308971                "name": "(MIT OR Apache-2.0)"
308972              }
308973            }
308974          ],
308975          "cpe": "cpe:2.3:a:atob:atob:2.1.2:*:*:*:*:*:*:*",
308976          "purl": "pkg:npm/atob@2.1.2",
308977          "swid": {
308978            "attachment": {}
308979          },
308980          "pedigree": {},
308981          "evidence": {},
308982          "signature": {
308983            "signature": {
308984              "publicKey": {}
308985            }
308986          },
308987          "modelCard": {
308988            "modelParameters": {
308989              "approach": {}
308990            },
308991            "quantitativeAnalysis": {
308992              "graphics": {}
308993            },
308994            "considerations": {}
308995          }
308996        },
308997        {
308998          "type": "library",
308999          "bom-ref": "pkg:npm/autoprefixer@9.7.4?package-id=94fae67881307ea8",
309000          "supplier": {},
309001          "name": "autoprefixer",
309002          "version": "9.7.4",
309003          "licenses": [
309004            {
309005              "license": {
309006                "id": "MIT"
309007              }
309008            }
309009          ],
309010          "cpe": "cpe:2.3:a:autoprefixer:autoprefixer:9.7.4:*:*:*:*:*:*:*",
309011          "purl": "pkg:npm/autoprefixer@9.7.4",
309012          "swid": {
309013            "attachment": {}
309014          },
309015          "pedigree": {},
309016          "evidence": {},
309017          "signature": {
309018            "signature": {
309019              "publicKey": {}
309020            }
309021          },
309022          "modelCard": {
309023            "modelParameters": {
309024              "approach": {}
309025            },
309026            "quantitativeAnalysis": {
309027              "graphics": {}
309028            },
309029            "considerations": {}
309030          }
309031        },
309032        {
309033          "type": "library",
309034          "bom-ref": "pkg:npm/aws-sign2@0.7.0?package-id=f85b64dcabe1f3b7",
309035          "supplier": {},
309036          "name": "aws-sign2",
309037          "version": "0.7.0",
309038          "licenses": [
309039            {
309040              "license": {
309041                "id": "Apache-2.0"
309042              }
309043            }
309044          ],
309045          "cpe": "cpe:2.3:a:aws-sign2:aws-sign2:0.7.0:*:*:*:*:*:*:*",
309046          "purl": "pkg:npm/aws-sign2@0.7.0",
309047          "swid": {
309048            "attachment": {}
309049          },
309050          "pedigree": {},
309051          "evidence": {},
309052          "signature": {
309053            "signature": {
309054              "publicKey": {}
309055            }
309056          },
309057          "modelCard": {
309058            "modelParameters": {
309059              "approach": {}
309060            },
309061            "quantitativeAnalysis": {
309062              "graphics": {}
309063            },
309064            "considerations": {}
309065          }
309066        },
309067        {
309068          "type": "library",
309069          "bom-ref": "pkg:npm/aws4@1.9.1?package-id=c97e0f1abd082974",
309070          "supplier": {},
309071          "name": "aws4",
309072          "version": "1.9.1",
309073          "licenses": [
309074            {
309075              "license": {
309076                "id": "MIT"
309077              }
309078            }
309079          ],
309080          "cpe": "cpe:2.3:a:aws4:aws4:1.9.1:*:*:*:*:*:*:*",
309081          "purl": "pkg:npm/aws4@1.9.1",
309082          "swid": {
309083            "attachment": {}
309084          },
309085          "pedigree": {},
309086          "evidence": {},
309087          "signature": {
309088            "signature": {
309089              "publicKey": {}
309090            }
309091          },
309092          "modelCard": {
309093            "modelParameters": {
309094              "approach": {}
309095            },
309096            "quantitativeAnalysis": {
309097              "graphics": {}
309098            },
309099            "considerations": {}
309100          }
309101        },
309102        {
309103          "type": "library",
309104          "bom-ref": "pkg:npm/axobject-query@2.0.2?package-id=8d08c05f7a95c74e",
309105          "supplier": {},
309106          "name": "axobject-query",
309107          "version": "2.0.2",
309108          "licenses": [
309109            {
309110              "license": {
309111                "id": "Apache-2.0"
309112              }
309113            }
309114          ],
309115          "cpe": "cpe:2.3:a:axobject-query:axobject-query:2.0.2:*:*:*:*:*:*:*",
309116          "purl": "pkg:npm/axobject-query@2.0.2",
309117          "swid": {
309118            "attachment": {}
309119          },
309120          "pedigree": {},
309121          "evidence": {},
309122          "signature": {
309123            "signature": {
309124              "publicKey": {}
309125            }
309126          },
309127          "modelCard": {
309128            "modelParameters": {
309129              "approach": {}
309130            },
309131            "quantitativeAnalysis": {
309132              "graphics": {}
309133            },
309134            "considerations": {}
309135          }
309136        },
309137        {
309138          "type": "library",
309139          "bom-ref": "pkg:npm/babel-loader@8.0.6?package-id=29fc960e6dadef10",
309140          "supplier": {},
309141          "name": "babel-loader",
309142          "version": "8.0.6",
309143          "licenses": [
309144            {
309145              "license": {
309146                "id": "MIT"
309147              }
309148            }
309149          ],
309150          "cpe": "cpe:2.3:a:babel-loader:babel-loader:8.0.6:*:*:*:*:*:*:*",
309151          "purl": "pkg:npm/babel-loader@8.0.6",
309152          "swid": {
309153            "attachment": {}
309154          },
309155          "pedigree": {},
309156          "evidence": {},
309157          "signature": {
309158            "signature": {
309159              "publicKey": {}
309160            }
309161          },
309162          "modelCard": {
309163            "modelParameters": {
309164              "approach": {}
309165            },
309166            "quantitativeAnalysis": {
309167              "graphics": {}
309168            },
309169            "considerations": {}
309170          }
309171        },
309172        {
309173          "type": "library",
309174          "bom-ref": "pkg:npm/babel-plugin-dynamic-import-node@2.3.3?package-id=6885171457c66541",
309175          "supplier": {},
309176          "name": "babel-plugin-dynamic-import-node",
309177          "version": "2.3.3",
309178          "licenses": [
309179            {
309180              "license": {
309181                "id": "MIT"
309182              }
309183            }
309184          ],
309185          "cpe": "cpe:2.3:a:babel-plugin-dynamic-import-node:babel-plugin-dynamic-import-node:2.3.3:*:*:*:*:*:*:*",
309186          "purl": "pkg:npm/babel-plugin-dynamic-import-node@2.3.3",
309187          "swid": {
309188            "attachment": {}
309189          },
309190          "pedigree": {},
309191          "evidence": {},
309192          "signature": {
309193            "signature": {
309194              "publicKey": {}
309195            }
309196          },
309197          "modelCard": {
309198            "modelParameters": {
309199              "approach": {}
309200            },
309201            "quantitativeAnalysis": {
309202              "graphics": {}
309203            },
309204            "considerations": {}
309205          }
309206        },
309207        {
309208          "type": "library",
309209          "bom-ref": "pkg:npm/backo2@1.0.2?package-id=781332b0421ed054",
309210          "supplier": {},
309211          "name": "backo2",
309212          "version": "1.0.2",
309213          "licenses": [
309214            {
309215              "license": {
309216                "id": "MIT"
309217              }
309218            }
309219          ],
309220          "cpe": "cpe:2.3:a:backo2:backo2:1.0.2:*:*:*:*:*:*:*",
309221          "purl": "pkg:npm/backo2@1.0.2",
309222          "swid": {
309223            "attachment": {}
309224          },
309225          "pedigree": {},
309226          "evidence": {},
309227          "signature": {
309228            "signature": {
309229              "publicKey": {}
309230            }
309231          },
309232          "modelCard": {
309233            "modelParameters": {
309234              "approach": {}
309235            },
309236            "quantitativeAnalysis": {
309237              "graphics": {}
309238            },
309239            "considerations": {}
309240          }
309241        },
309242        {
309243          "type": "library",
309244          "bom-ref": "pkg:npm/balanced-match@1.0.0?package-id=44cdae6d6aae2b61",
309245          "supplier": {},
309246          "name": "balanced-match",
309247          "version": "1.0.0",
309248          "licenses": [
309249            {
309250              "license": {
309251                "id": "MIT"
309252              }
309253            }
309254          ],
309255          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.0:*:*:*:*:*:*:*",
309256          "purl": "pkg:npm/balanced-match@1.0.0",
309257          "swid": {
309258            "attachment": {}
309259          },
309260          "pedigree": {},
309261          "evidence": {},
309262          "signature": {
309263            "signature": {
309264              "publicKey": {}
309265            }
309266          },
309267          "modelCard": {
309268            "modelParameters": {
309269              "approach": {}
309270            },
309271            "quantitativeAnalysis": {
309272              "graphics": {}
309273            },
309274            "considerations": {}
309275          }
309276        },
309277        {
309278          "type": "library",
309279          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=f3d52b8c6e34630e",
309280          "supplier": {},
309281          "name": "balanced-match",
309282          "version": "1.0.2",
309283          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
309284          "purl": "pkg:npm/balanced-match@1.0.2",
309285          "swid": {
309286            "attachment": {}
309287          },
309288          "pedigree": {},
309289          "evidence": {},
309290          "signature": {
309291            "signature": {
309292              "publicKey": {}
309293            }
309294          },
309295          "modelCard": {
309296            "modelParameters": {
309297              "approach": {}
309298            },
309299            "quantitativeAnalysis": {
309300              "graphics": {}
309301            },
309302            "considerations": {}
309303          }
309304        },
309305        {
309306          "type": "library",
309307          "bom-ref": "pkg:npm/base@0.11.2?package-id=8f952781effa3d46",
309308          "supplier": {},
309309          "name": "base",
309310          "version": "0.11.2",
309311          "licenses": [
309312            {
309313              "license": {
309314                "id": "MIT"
309315              }
309316            }
309317          ],
309318          "cpe": "cpe:2.3:a:base:base:0.11.2:*:*:*:*:*:*:*",
309319          "purl": "pkg:npm/base@0.11.2",
309320          "swid": {
309321            "attachment": {}
309322          },
309323          "pedigree": {},
309324          "evidence": {},
309325          "signature": {
309326            "signature": {
309327              "publicKey": {}
309328            }
309329          },
309330          "modelCard": {
309331            "modelParameters": {
309332              "approach": {}
309333            },
309334            "quantitativeAnalysis": {
309335              "graphics": {}
309336            },
309337            "considerations": {}
309338          }
309339        },
309340        {
309341          "type": "library",
309342          "bom-ref": "pkg:npm/base64-arraybuffer@0.1.5?package-id=49c0a9a6d1fa6a8d",
309343          "supplier": {},
309344          "name": "base64-arraybuffer",
309345          "version": "0.1.5",
309346          "licenses": [
309347            {
309348              "license": {
309349                "id": "MIT"
309350              }
309351            }
309352          ],
309353          "cpe": "cpe:2.3:a:base64-arraybuffer:base64-arraybuffer:0.1.5:*:*:*:*:*:*:*",
309354          "purl": "pkg:npm/base64-arraybuffer@0.1.5",
309355          "swid": {
309356            "attachment": {}
309357          },
309358          "pedigree": {},
309359          "evidence": {},
309360          "signature": {
309361            "signature": {
309362              "publicKey": {}
309363            }
309364          },
309365          "modelCard": {
309366            "modelParameters": {
309367              "approach": {}
309368            },
309369            "quantitativeAnalysis": {
309370              "graphics": {}
309371            },
309372            "considerations": {}
309373          }
309374        },
309375        {
309376          "type": "library",
309377          "bom-ref": "pkg:npm/base64-js@1.3.1?package-id=3b4bc2b19c2e72d8",
309378          "supplier": {},
309379          "name": "base64-js",
309380          "version": "1.3.1",
309381          "licenses": [
309382            {
309383              "license": {
309384                "id": "MIT"
309385              }
309386            }
309387          ],
309388          "cpe": "cpe:2.3:a:base64-js:base64-js:1.3.1:*:*:*:*:*:*:*",
309389          "purl": "pkg:npm/base64-js@1.3.1",
309390          "swid": {
309391            "attachment": {}
309392          },
309393          "pedigree": {},
309394          "evidence": {},
309395          "signature": {
309396            "signature": {
309397              "publicKey": {}
309398            }
309399          },
309400          "modelCard": {
309401            "modelParameters": {
309402              "approach": {}
309403            },
309404            "quantitativeAnalysis": {
309405              "graphics": {}
309406            },
309407            "considerations": {}
309408          }
309409        },
309410        {
309411          "type": "library",
309412          "bom-ref": "pkg:npm/base64id@1.0.0?package-id=c850b19cf8498f6e",
309413          "supplier": {},
309414          "name": "base64id",
309415          "version": "1.0.0",
309416          "licenses": [
309417            {
309418              "license": {
309419                "id": "MIT"
309420              }
309421            }
309422          ],
309423          "cpe": "cpe:2.3:a:base64id:base64id:1.0.0:*:*:*:*:*:*:*",
309424          "purl": "pkg:npm/base64id@1.0.0",
309425          "swid": {
309426            "attachment": {}
309427          },
309428          "pedigree": {},
309429          "evidence": {},
309430          "signature": {
309431            "signature": {
309432              "publicKey": {}
309433            }
309434          },
309435          "modelCard": {
309436            "modelParameters": {
309437              "approach": {}
309438            },
309439            "quantitativeAnalysis": {
309440              "graphics": {}
309441            },
309442            "considerations": {}
309443          }
309444        },
309445        {
309446          "type": "library",
309447          "bom-ref": "pkg:npm/batch@0.6.1?package-id=7dc4ebe578aa16c1",
309448          "supplier": {},
309449          "name": "batch",
309450          "version": "0.6.1",
309451          "licenses": [
309452            {
309453              "license": {
309454                "id": "MIT"
309455              }
309456            }
309457          ],
309458          "cpe": "cpe:2.3:a:batch:batch:0.6.1:*:*:*:*:*:*:*",
309459          "purl": "pkg:npm/batch@0.6.1",
309460          "swid": {
309461            "attachment": {}
309462          },
309463          "pedigree": {},
309464          "evidence": {},
309465          "signature": {
309466            "signature": {
309467              "publicKey": {}
309468            }
309469          },
309470          "modelCard": {
309471            "modelParameters": {
309472              "approach": {}
309473            },
309474            "quantitativeAnalysis": {
309475              "graphics": {}
309476            },
309477            "considerations": {}
309478          }
309479        },
309480        {
309481          "type": "library",
309482          "bom-ref": "pkg:npm/bcrypt-pbkdf@1.0.2?package-id=935adf4faa5810fe",
309483          "supplier": {},
309484          "name": "bcrypt-pbkdf",
309485          "version": "1.0.2",
309486          "licenses": [
309487            {
309488              "license": {
309489                "id": "BSD-3-Clause"
309490              }
309491            }
309492          ],
309493          "cpe": "cpe:2.3:a:bcrypt-pbkdf:bcrypt-pbkdf:1.0.2:*:*:*:*:*:*:*",
309494          "purl": "pkg:npm/bcrypt-pbkdf@1.0.2",
309495          "swid": {
309496            "attachment": {}
309497          },
309498          "pedigree": {},
309499          "evidence": {},
309500          "signature": {
309501            "signature": {
309502              "publicKey": {}
309503            }
309504          },
309505          "modelCard": {
309506            "modelParameters": {
309507              "approach": {}
309508            },
309509            "quantitativeAnalysis": {
309510              "graphics": {}
309511            },
309512            "considerations": {}
309513          }
309514        },
309515        {
309516          "type": "library",
309517          "bom-ref": "pkg:npm/better-assert@1.0.2?package-id=128a19e7b2d338cb",
309518          "supplier": {},
309519          "name": "better-assert",
309520          "version": "1.0.2",
309521          "cpe": "cpe:2.3:a:better-assert:better-assert:1.0.2:*:*:*:*:*:*:*",
309522          "purl": "pkg:npm/better-assert@1.0.2",
309523          "swid": {
309524            "attachment": {}
309525          },
309526          "pedigree": {},
309527          "evidence": {},
309528          "signature": {
309529            "signature": {
309530              "publicKey": {}
309531            }
309532          },
309533          "modelCard": {
309534            "modelParameters": {
309535              "approach": {}
309536            },
309537            "quantitativeAnalysis": {
309538              "graphics": {}
309539            },
309540            "considerations": {}
309541          }
309542        },
309543        {
309544          "type": "library",
309545          "bom-ref": "pkg:npm/bfj@6.1.2?package-id=6e69cc00e96d3302",
309546          "supplier": {},
309547          "name": "bfj",
309548          "version": "6.1.2",
309549          "licenses": [
309550            {
309551              "license": {
309552                "id": "MIT"
309553              }
309554            }
309555          ],
309556          "cpe": "cpe:2.3:a:bfj:bfj:6.1.2:*:*:*:*:*:*:*",
309557          "purl": "pkg:npm/bfj@6.1.2",
309558          "swid": {
309559            "attachment": {}
309560          },
309561          "pedigree": {},
309562          "evidence": {},
309563          "signature": {
309564            "signature": {
309565              "publicKey": {}
309566            }
309567          },
309568          "modelCard": {
309569            "modelParameters": {
309570              "approach": {}
309571            },
309572            "quantitativeAnalysis": {
309573              "graphics": {}
309574            },
309575            "considerations": {}
309576          }
309577        },
309578        {
309579          "type": "library",
309580          "bom-ref": "pkg:npm/big.js@5.2.2?package-id=4844c320524e3188",
309581          "supplier": {},
309582          "name": "big.js",
309583          "version": "5.2.2",
309584          "licenses": [
309585            {
309586              "license": {
309587                "id": "MIT"
309588              }
309589            }
309590          ],
309591          "cpe": "cpe:2.3:a:big.js:big.js:5.2.2:*:*:*:*:*:*:*",
309592          "purl": "pkg:npm/big.js@5.2.2",
309593          "swid": {
309594            "attachment": {}
309595          },
309596          "pedigree": {},
309597          "evidence": {},
309598          "signature": {
309599            "signature": {
309600              "publicKey": {}
309601            }
309602          },
309603          "modelCard": {
309604            "modelParameters": {
309605              "approach": {}
309606            },
309607            "quantitativeAnalysis": {
309608              "graphics": {}
309609            },
309610            "considerations": {}
309611          }
309612        },
309613        {
309614          "type": "library",
309615          "bom-ref": "pkg:npm/binary-extensions@2.0.0?package-id=d19134edb59aa4f1",
309616          "supplier": {},
309617          "name": "binary-extensions",
309618          "version": "2.0.0",
309619          "licenses": [
309620            {
309621              "license": {
309622                "id": "MIT"
309623              }
309624            }
309625          ],
309626          "cpe": "cpe:2.3:a:binary-extensions:binary-extensions:2.0.0:*:*:*:*:*:*:*",
309627          "purl": "pkg:npm/binary-extensions@2.0.0",
309628          "swid": {
309629            "attachment": {}
309630          },
309631          "pedigree": {},
309632          "evidence": {},
309633          "signature": {
309634            "signature": {
309635              "publicKey": {}
309636            }
309637          },
309638          "modelCard": {
309639            "modelParameters": {
309640              "approach": {}
309641            },
309642            "quantitativeAnalysis": {
309643              "graphics": {}
309644            },
309645            "considerations": {}
309646          }
309647        },
309648        {
309649          "type": "library",
309650          "bom-ref": "pkg:npm/bindings@1.5.0?package-id=40b4748b387a8b1b",
309651          "supplier": {},
309652          "name": "bindings",
309653          "version": "1.5.0",
309654          "cpe": "cpe:2.3:a:bindings:bindings:1.5.0:*:*:*:*:*:*:*",
309655          "purl": "pkg:npm/bindings@1.5.0",
309656          "swid": {
309657            "attachment": {}
309658          },
309659          "pedigree": {},
309660          "evidence": {},
309661          "signature": {
309662            "signature": {
309663              "publicKey": {}
309664            }
309665          },
309666          "modelCard": {
309667            "modelParameters": {
309668              "approach": {}
309669            },
309670            "quantitativeAnalysis": {
309671              "graphics": {}
309672            },
309673            "considerations": {}
309674          }
309675        },
309676        {
309677          "type": "library",
309678          "bom-ref": "pkg:npm/blob@0.0.5?package-id=cc51854807e9a24b",
309679          "supplier": {},
309680          "name": "blob",
309681          "version": "0.0.5",
309682          "licenses": [
309683            {
309684              "license": {
309685                "id": "MIT"
309686              }
309687            }
309688          ],
309689          "cpe": "cpe:2.3:a:blob:blob:0.0.5:*:*:*:*:*:*:*",
309690          "purl": "pkg:npm/blob@0.0.5",
309691          "swid": {
309692            "attachment": {}
309693          },
309694          "pedigree": {},
309695          "evidence": {},
309696          "signature": {
309697            "signature": {
309698              "publicKey": {}
309699            }
309700          },
309701          "modelCard": {
309702            "modelParameters": {
309703              "approach": {}
309704            },
309705            "quantitativeAnalysis": {
309706              "graphics": {}
309707            },
309708            "considerations": {}
309709          }
309710        },
309711        {
309712          "type": "library",
309713          "bom-ref": "pkg:npm/block-stream@0.0.9?package-id=71a5010090f8be4a",
309714          "supplier": {},
309715          "name": "block-stream",
309716          "version": "0.0.9",
309717          "licenses": [
309718            {
309719              "license": {
309720                "id": "ISC"
309721              }
309722            }
309723          ],
309724          "cpe": "cpe:2.3:a:block-stream:block-stream:0.0.9:*:*:*:*:*:*:*",
309725          "purl": "pkg:npm/block-stream@0.0.9",
309726          "swid": {
309727            "attachment": {}
309728          },
309729          "pedigree": {},
309730          "evidence": {},
309731          "signature": {
309732            "signature": {
309733              "publicKey": {}
309734            }
309735          },
309736          "modelCard": {
309737            "modelParameters": {
309738              "approach": {}
309739            },
309740            "quantitativeAnalysis": {
309741              "graphics": {}
309742            },
309743            "considerations": {}
309744          }
309745        },
309746        {
309747          "type": "library",
309748          "bom-ref": "pkg:npm/blocking-proxy@1.0.1?package-id=d80488fa490e5db8",
309749          "supplier": {},
309750          "name": "blocking-proxy",
309751          "version": "1.0.1",
309752          "licenses": [
309753            {
309754              "license": {
309755                "id": "MIT"
309756              }
309757            }
309758          ],
309759          "cpe": "cpe:2.3:a:blocking-proxy:blocking-proxy:1.0.1:*:*:*:*:*:*:*",
309760          "purl": "pkg:npm/blocking-proxy@1.0.1",
309761          "swid": {
309762            "attachment": {}
309763          },
309764          "pedigree": {},
309765          "evidence": {},
309766          "signature": {
309767            "signature": {
309768              "publicKey": {}
309769            }
309770          },
309771          "modelCard": {
309772            "modelParameters": {
309773              "approach": {}
309774            },
309775            "quantitativeAnalysis": {
309776              "graphics": {}
309777            },
309778            "considerations": {}
309779          }
309780        },
309781        {
309782          "type": "library",
309783          "bom-ref": "pkg:npm/bluebird@3.7.2?package-id=b78a7f922dc9e95d",
309784          "supplier": {},
309785          "name": "bluebird",
309786          "version": "3.7.2",
309787          "licenses": [
309788            {
309789              "license": {
309790                "id": "MIT"
309791              }
309792            }
309793          ],
309794          "cpe": "cpe:2.3:a:bluebird:bluebird:3.7.2:*:*:*:*:*:*:*",
309795          "purl": "pkg:npm/bluebird@3.7.2",
309796          "swid": {
309797            "attachment": {}
309798          },
309799          "pedigree": {},
309800          "evidence": {},
309801          "signature": {
309802            "signature": {
309803              "publicKey": {}
309804            }
309805          },
309806          "modelCard": {
309807            "modelParameters": {
309808              "approach": {}
309809            },
309810            "quantitativeAnalysis": {
309811              "graphics": {}
309812            },
309813            "considerations": {}
309814          }
309815        },
309816        {
309817          "type": "library",
309818          "bom-ref": "pkg:npm/bn.js@5.1.1?package-id=f6dbcceba7ba15a2",
309819          "supplier": {},
309820          "name": "bn.js",
309821          "version": "5.1.1",
309822          "licenses": [
309823            {
309824              "license": {
309825                "id": "MIT"
309826              }
309827            }
309828          ],
309829          "cpe": "cpe:2.3:a:bn.js:bn.js:5.1.1:*:*:*:*:*:*:*",
309830          "purl": "pkg:npm/bn.js@5.1.1",
309831          "swid": {
309832            "attachment": {}
309833          },
309834          "pedigree": {},
309835          "evidence": {},
309836          "signature": {
309837            "signature": {
309838              "publicKey": {}
309839            }
309840          },
309841          "modelCard": {
309842            "modelParameters": {
309843              "approach": {}
309844            },
309845            "quantitativeAnalysis": {
309846              "graphics": {}
309847            },
309848            "considerations": {}
309849          }
309850        },
309851        {
309852          "type": "library",
309853          "bom-ref": "pkg:npm/body-parser@1.19.0?package-id=9574f2f81e9b5edd",
309854          "supplier": {},
309855          "name": "body-parser",
309856          "version": "1.19.0",
309857          "licenses": [
309858            {
309859              "license": {
309860                "id": "MIT"
309861              }
309862            }
309863          ],
309864          "cpe": "cpe:2.3:a:body-parser:body-parser:1.19.0:*:*:*:*:*:*:*",
309865          "purl": "pkg:npm/body-parser@1.19.0",
309866          "swid": {
309867            "attachment": {}
309868          },
309869          "pedigree": {},
309870          "evidence": {},
309871          "signature": {
309872            "signature": {
309873              "publicKey": {}
309874            }
309875          },
309876          "modelCard": {
309877            "modelParameters": {
309878              "approach": {}
309879            },
309880            "quantitativeAnalysis": {
309881              "graphics": {}
309882            },
309883            "considerations": {}
309884          }
309885        },
309886        {
309887          "type": "library",
309888          "bom-ref": "pkg:npm/bonjour@3.5.0?package-id=92506ef6dbbf0ec",
309889          "supplier": {},
309890          "name": "bonjour",
309891          "version": "3.5.0",
309892          "licenses": [
309893            {
309894              "license": {
309895                "id": "MIT"
309896              }
309897            }
309898          ],
309899          "cpe": "cpe:2.3:a:bonjour:bonjour:3.5.0:*:*:*:*:*:*:*",
309900          "purl": "pkg:npm/bonjour@3.5.0",
309901          "swid": {
309902            "attachment": {}
309903          },
309904          "pedigree": {},
309905          "evidence": {},
309906          "signature": {
309907            "signature": {
309908              "publicKey": {}
309909            }
309910          },
309911          "modelCard": {
309912            "modelParameters": {
309913              "approach": {}
309914            },
309915            "quantitativeAnalysis": {
309916              "graphics": {}
309917            },
309918            "considerations": {}
309919          }
309920        },
309921        {
309922          "type": "library",
309923          "bom-ref": "pkg:npm/boolbase@1.0.0?package-id=b37d9e93d5eaa107",
309924          "supplier": {},
309925          "name": "boolbase",
309926          "version": "1.0.0",
309927          "licenses": [
309928            {
309929              "license": {
309930                "id": "ISC"
309931              }
309932            }
309933          ],
309934          "cpe": "cpe:2.3:a:boolbase:boolbase:1.0.0:*:*:*:*:*:*:*",
309935          "purl": "pkg:npm/boolbase@1.0.0",
309936          "swid": {
309937            "attachment": {}
309938          },
309939          "pedigree": {},
309940          "evidence": {},
309941          "signature": {
309942            "signature": {
309943              "publicKey": {}
309944            }
309945          },
309946          "modelCard": {
309947            "modelParameters": {
309948              "approach": {}
309949            },
309950            "quantitativeAnalysis": {
309951              "graphics": {}
309952            },
309953            "considerations": {}
309954          }
309955        },
309956        {
309957          "type": "library",
309958          "bom-ref": "pkg:npm/bootstrap@4.4.1?package-id=58fe9b6acbd3c737",
309959          "supplier": {},
309960          "name": "bootstrap",
309961          "version": "4.4.1",
309962          "licenses": [
309963            {
309964              "license": {
309965                "id": "MIT"
309966              }
309967            }
309968          ],
309969          "cpe": "cpe:2.3:a:bootstrap:bootstrap:4.4.1:*:*:*:*:*:*:*",
309970          "purl": "pkg:npm/bootstrap@4.4.1",
309971          "swid": {
309972            "attachment": {}
309973          },
309974          "pedigree": {},
309975          "evidence": {},
309976          "signature": {
309977            "signature": {
309978              "publicKey": {}
309979            }
309980          },
309981          "modelCard": {
309982            "modelParameters": {
309983              "approach": {}
309984            },
309985            "quantitativeAnalysis": {
309986              "graphics": {}
309987            },
309988            "considerations": {}
309989          }
309990        },
309991        {
309992          "type": "library",
309993          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=37e08395667c67e0",
309994          "supplier": {},
309995          "name": "brace-expansion",
309996          "version": "1.1.11",
309997          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
309998          "purl": "pkg:npm/brace-expansion@1.1.11",
309999          "swid": {
310000            "attachment": {}
310001          },
310002          "pedigree": {},
310003          "evidence": {},
310004          "signature": {
310005            "signature": {
310006              "publicKey": {}
310007            }
310008          },
310009          "modelCard": {
310010            "modelParameters": {
310011              "approach": {}
310012            },
310013            "quantitativeAnalysis": {
310014              "graphics": {}
310015            },
310016            "considerations": {}
310017          }
310018        },
310019        {
310020          "type": "library",
310021          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=5a34efcf67357245",
310022          "supplier": {},
310023          "name": "brace-expansion",
310024          "version": "1.1.11",
310025          "licenses": [
310026            {
310027              "license": {
310028                "id": "MIT"
310029              }
310030            }
310031          ],
310032          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
310033          "purl": "pkg:npm/brace-expansion@1.1.11",
310034          "swid": {
310035            "attachment": {}
310036          },
310037          "pedigree": {},
310038          "evidence": {},
310039          "signature": {
310040            "signature": {
310041              "publicKey": {}
310042            }
310043          },
310044          "modelCard": {
310045            "modelParameters": {
310046              "approach": {}
310047            },
310048            "quantitativeAnalysis": {
310049              "graphics": {}
310050            },
310051            "considerations": {}
310052          }
310053        },
310054        {
310055          "type": "library",
310056          "bom-ref": "pkg:npm/braces@3.0.2?package-id=4074d65cb7604a13",
310057          "supplier": {},
310058          "name": "braces",
310059          "version": "3.0.2",
310060          "cpe": "cpe:2.3:a:braces:braces:3.0.2:*:*:*:*:*:*:*",
310061          "purl": "pkg:npm/braces@3.0.2",
310062          "swid": {
310063            "attachment": {}
310064          },
310065          "pedigree": {},
310066          "evidence": {},
310067          "signature": {
310068            "signature": {
310069              "publicKey": {}
310070            }
310071          },
310072          "modelCard": {
310073            "modelParameters": {
310074              "approach": {}
310075            },
310076            "quantitativeAnalysis": {
310077              "graphics": {}
310078            },
310079            "considerations": {}
310080          }
310081        },
310082        {
310083          "type": "library",
310084          "bom-ref": "pkg:npm/braces@3.0.2?package-id=b18e4006b7025b7a",
310085          "supplier": {},
310086          "name": "braces",
310087          "version": "3.0.2",
310088          "licenses": [
310089            {
310090              "license": {
310091                "id": "MIT"
310092              }
310093            }
310094          ],
310095          "cpe": "cpe:2.3:a:braces:braces:3.0.2:*:*:*:*:*:*:*",
310096          "purl": "pkg:npm/braces@3.0.2",
310097          "swid": {
310098            "attachment": {}
310099          },
310100          "pedigree": {},
310101          "evidence": {},
310102          "signature": {
310103            "signature": {
310104              "publicKey": {}
310105            }
310106          },
310107          "modelCard": {
310108            "modelParameters": {
310109              "approach": {}
310110            },
310111            "quantitativeAnalysis": {
310112              "graphics": {}
310113            },
310114            "considerations": {}
310115          }
310116        },
310117        {
310118          "type": "library",
310119          "bom-ref": "pkg:npm/brorand@1.1.0?package-id=523881e49561cc0c",
310120          "supplier": {},
310121          "name": "brorand",
310122          "version": "1.1.0",
310123          "licenses": [
310124            {
310125              "license": {
310126                "id": "MIT"
310127              }
310128            }
310129          ],
310130          "cpe": "cpe:2.3:a:brorand:brorand:1.1.0:*:*:*:*:*:*:*",
310131          "purl": "pkg:npm/brorand@1.1.0",
310132          "swid": {
310133            "attachment": {}
310134          },
310135          "pedigree": {},
310136          "evidence": {},
310137          "signature": {
310138            "signature": {
310139              "publicKey": {}
310140            }
310141          },
310142          "modelCard": {
310143            "modelParameters": {
310144              "approach": {}
310145            },
310146            "quantitativeAnalysis": {
310147              "graphics": {}
310148            },
310149            "considerations": {}
310150          }
310151        },
310152        {
310153          "type": "library",
310154          "bom-ref": "pkg:npm/browserify-aes@1.2.0?package-id=7aab4f800bf40bb",
310155          "supplier": {},
310156          "name": "browserify-aes",
310157          "version": "1.2.0",
310158          "licenses": [
310159            {
310160              "license": {
310161                "id": "MIT"
310162              }
310163            }
310164          ],
310165          "cpe": "cpe:2.3:a:browserify-aes:browserify-aes:1.2.0:*:*:*:*:*:*:*",
310166          "purl": "pkg:npm/browserify-aes@1.2.0",
310167          "swid": {
310168            "attachment": {}
310169          },
310170          "pedigree": {},
310171          "evidence": {},
310172          "signature": {
310173            "signature": {
310174              "publicKey": {}
310175            }
310176          },
310177          "modelCard": {
310178            "modelParameters": {
310179              "approach": {}
310180            },
310181            "quantitativeAnalysis": {
310182              "graphics": {}
310183            },
310184            "considerations": {}
310185          }
310186        },
310187        {
310188          "type": "library",
310189          "bom-ref": "pkg:npm/browserify-cipher@1.0.1?package-id=f2f4bd1da62abcd8",
310190          "supplier": {},
310191          "name": "browserify-cipher",
310192          "version": "1.0.1",
310193          "licenses": [
310194            {
310195              "license": {
310196                "id": "MIT"
310197              }
310198            }
310199          ],
310200          "cpe": "cpe:2.3:a:browserify-cipher:browserify-cipher:1.0.1:*:*:*:*:*:*:*",
310201          "purl": "pkg:npm/browserify-cipher@1.0.1",
310202          "swid": {
310203            "attachment": {}
310204          },
310205          "pedigree": {},
310206          "evidence": {},
310207          "signature": {
310208            "signature": {
310209              "publicKey": {}
310210            }
310211          },
310212          "modelCard": {
310213            "modelParameters": {
310214              "approach": {}
310215            },
310216            "quantitativeAnalysis": {
310217              "graphics": {}
310218            },
310219            "considerations": {}
310220          }
310221        },
310222        {
310223          "type": "library",
310224          "bom-ref": "pkg:npm/browserify-des@1.0.2?package-id=7c5bc6027a946e81",
310225          "supplier": {},
310226          "name": "browserify-des",
310227          "version": "1.0.2",
310228          "licenses": [
310229            {
310230              "license": {
310231                "id": "MIT"
310232              }
310233            }
310234          ],
310235          "cpe": "cpe:2.3:a:browserify-des:browserify-des:1.0.2:*:*:*:*:*:*:*",
310236          "purl": "pkg:npm/browserify-des@1.0.2",
310237          "swid": {
310238            "attachment": {}
310239          },
310240          "pedigree": {},
310241          "evidence": {},
310242          "signature": {
310243            "signature": {
310244              "publicKey": {}
310245            }
310246          },
310247          "modelCard": {
310248            "modelParameters": {
310249              "approach": {}
310250            },
310251            "quantitativeAnalysis": {
310252              "graphics": {}
310253            },
310254            "considerations": {}
310255          }
310256        },
310257        {
310258          "type": "library",
310259          "bom-ref": "pkg:npm/browserify-rsa@4.0.1?package-id=8f7da4c1e9d73649",
310260          "supplier": {},
310261          "name": "browserify-rsa",
310262          "version": "4.0.1",
310263          "licenses": [
310264            {
310265              "license": {
310266                "id": "MIT"
310267              }
310268            }
310269          ],
310270          "cpe": "cpe:2.3:a:browserify-rsa:browserify-rsa:4.0.1:*:*:*:*:*:*:*",
310271          "purl": "pkg:npm/browserify-rsa@4.0.1",
310272          "swid": {
310273            "attachment": {}
310274          },
310275          "pedigree": {},
310276          "evidence": {},
310277          "signature": {
310278            "signature": {
310279              "publicKey": {}
310280            }
310281          },
310282          "modelCard": {
310283            "modelParameters": {
310284              "approach": {}
310285            },
310286            "quantitativeAnalysis": {
310287              "graphics": {}
310288            },
310289            "considerations": {}
310290          }
310291        },
310292        {
310293          "type": "library",
310294          "bom-ref": "pkg:npm/browserify-sign@4.1.0?package-id=46d7ea0d164a6c7d",
310295          "supplier": {},
310296          "name": "browserify-sign",
310297          "version": "4.1.0",
310298          "licenses": [
310299            {
310300              "license": {
310301                "id": "ISC"
310302              }
310303            }
310304          ],
310305          "cpe": "cpe:2.3:a:browserify-sign:browserify-sign:4.1.0:*:*:*:*:*:*:*",
310306          "purl": "pkg:npm/browserify-sign@4.1.0",
310307          "swid": {
310308            "attachment": {}
310309          },
310310          "pedigree": {},
310311          "evidence": {},
310312          "signature": {
310313            "signature": {
310314              "publicKey": {}
310315            }
310316          },
310317          "modelCard": {
310318            "modelParameters": {
310319              "approach": {}
310320            },
310321            "quantitativeAnalysis": {
310322              "graphics": {}
310323            },
310324            "considerations": {}
310325          }
310326        },
310327        {
310328          "type": "library",
310329          "bom-ref": "pkg:npm/browserify-zlib@0.2.0?package-id=ef6baa34f1e38080",
310330          "supplier": {},
310331          "name": "browserify-zlib",
310332          "version": "0.2.0",
310333          "licenses": [
310334            {
310335              "license": {
310336                "id": "MIT"
310337              }
310338            }
310339          ],
310340          "cpe": "cpe:2.3:a:browserify-zlib:browserify-zlib:0.2.0:*:*:*:*:*:*:*",
310341          "purl": "pkg:npm/browserify-zlib@0.2.0",
310342          "swid": {
310343            "attachment": {}
310344          },
310345          "pedigree": {},
310346          "evidence": {},
310347          "signature": {
310348            "signature": {
310349              "publicKey": {}
310350            }
310351          },
310352          "modelCard": {
310353            "modelParameters": {
310354              "approach": {}
310355            },
310356            "quantitativeAnalysis": {
310357              "graphics": {}
310358            },
310359            "considerations": {}
310360          }
310361        },
310362        {
310363          "type": "library",
310364          "bom-ref": "pkg:npm/browserslist@4.12.0?package-id=8d0fe9ed789317ec",
310365          "supplier": {},
310366          "name": "browserslist",
310367          "version": "4.12.0",
310368          "licenses": [
310369            {
310370              "license": {
310371                "id": "MIT"
310372              }
310373            }
310374          ],
310375          "cpe": "cpe:2.3:a:browserslist:browserslist:4.12.0:*:*:*:*:*:*:*",
310376          "purl": "pkg:npm/browserslist@4.12.0",
310377          "swid": {
310378            "attachment": {}
310379          },
310380          "pedigree": {},
310381          "evidence": {},
310382          "signature": {
310383            "signature": {
310384              "publicKey": {}
310385            }
310386          },
310387          "modelCard": {
310388            "modelParameters": {
310389              "approach": {}
310390            },
310391            "quantitativeAnalysis": {
310392              "graphics": {}
310393            },
310394            "considerations": {}
310395          }
310396        },
310397        {
310398          "type": "library",
310399          "bom-ref": "pkg:npm/browserslist@4.18.1?package-id=df1ca7e35f23f435",
310400          "supplier": {},
310401          "name": "browserslist",
310402          "version": "4.18.1",
310403          "cpe": "cpe:2.3:a:browserslist:browserslist:4.18.1:*:*:*:*:*:*:*",
310404          "purl": "pkg:npm/browserslist@4.18.1",
310405          "swid": {
310406            "attachment": {}
310407          },
310408          "pedigree": {},
310409          "evidence": {},
310410          "signature": {
310411            "signature": {
310412              "publicKey": {}
310413            }
310414          },
310415          "modelCard": {
310416            "modelParameters": {
310417              "approach": {}
310418            },
310419            "quantitativeAnalysis": {
310420              "graphics": {}
310421            },
310422            "considerations": {}
310423          }
310424        },
310425        {
310426          "type": "library",
310427          "bom-ref": "pkg:npm/browserstack@1.5.3?package-id=9277d3c0a34e71ae",
310428          "supplier": {},
310429          "name": "browserstack",
310430          "version": "1.5.3",
310431          "licenses": [
310432            {
310433              "license": {
310434                "id": "MIT"
310435              }
310436            }
310437          ],
310438          "cpe": "cpe:2.3:a:browserstack:browserstack:1.5.3:*:*:*:*:*:*:*",
310439          "purl": "pkg:npm/browserstack@1.5.3",
310440          "swid": {
310441            "attachment": {}
310442          },
310443          "pedigree": {},
310444          "evidence": {},
310445          "signature": {
310446            "signature": {
310447              "publicKey": {}
310448            }
310449          },
310450          "modelCard": {
310451            "modelParameters": {
310452              "approach": {}
310453            },
310454            "quantitativeAnalysis": {
310455              "graphics": {}
310456            },
310457            "considerations": {}
310458          }
310459        },
310460        {
310461          "type": "library",
310462          "bom-ref": "pkg:npm/buffer@4.9.2?package-id=56adac4b18102679",
310463          "supplier": {},
310464          "name": "buffer",
310465          "version": "4.9.2",
310466          "licenses": [
310467            {
310468              "license": {
310469                "id": "MIT"
310470              }
310471            }
310472          ],
310473          "cpe": "cpe:2.3:a:buffer:buffer:4.9.2:*:*:*:*:*:*:*",
310474          "purl": "pkg:npm/buffer@4.9.2",
310475          "swid": {
310476            "attachment": {}
310477          },
310478          "pedigree": {},
310479          "evidence": {},
310480          "signature": {
310481            "signature": {
310482              "publicKey": {}
310483            }
310484          },
310485          "modelCard": {
310486            "modelParameters": {
310487              "approach": {}
310488            },
310489            "quantitativeAnalysis": {
310490              "graphics": {}
310491            },
310492            "considerations": {}
310493          }
310494        },
310495        {
310496          "type": "library",
310497          "bom-ref": "pkg:npm/buffer-from@1.1.1?package-id=dbee95bc31744fad",
310498          "supplier": {},
310499          "name": "buffer-from",
310500          "version": "1.1.1",
310501          "licenses": [
310502            {
310503              "license": {
310504                "id": "MIT"
310505              }
310506            }
310507          ],
310508          "cpe": "cpe:2.3:a:buffer-from:buffer-from:1.1.1:*:*:*:*:*:*:*",
310509          "purl": "pkg:npm/buffer-from@1.1.1",
310510          "swid": {
310511            "attachment": {}
310512          },
310513          "pedigree": {},
310514          "evidence": {},
310515          "signature": {
310516            "signature": {
310517              "publicKey": {}
310518            }
310519          },
310520          "modelCard": {
310521            "modelParameters": {
310522              "approach": {}
310523            },
310524            "quantitativeAnalysis": {
310525              "graphics": {}
310526            },
310527            "considerations": {}
310528          }
310529        },
310530        {
310531          "type": "library",
310532          "bom-ref": "pkg:npm/buffer-indexof@1.1.1?package-id=1abea3f51e1570d2",
310533          "supplier": {},
310534          "name": "buffer-indexof",
310535          "version": "1.1.1",
310536          "licenses": [
310537            {
310538              "license": {
310539                "id": "MIT"
310540              }
310541            }
310542          ],
310543          "cpe": "cpe:2.3:a:buffer-indexof:buffer-indexof:1.1.1:*:*:*:*:*:*:*",
310544          "purl": "pkg:npm/buffer-indexof@1.1.1",
310545          "swid": {
310546            "attachment": {}
310547          },
310548          "pedigree": {},
310549          "evidence": {},
310550          "signature": {
310551            "signature": {
310552              "publicKey": {}
310553            }
310554          },
310555          "modelCard": {
310556            "modelParameters": {
310557              "approach": {}
310558            },
310559            "quantitativeAnalysis": {
310560              "graphics": {}
310561            },
310562            "considerations": {}
310563          }
310564        },
310565        {
310566          "type": "library",
310567          "bom-ref": "pkg:npm/buffer-xor@1.0.3?package-id=ef30b1daaf4fab86",
310568          "supplier": {},
310569          "name": "buffer-xor",
310570          "version": "1.0.3",
310571          "licenses": [
310572            {
310573              "license": {
310574                "id": "MIT"
310575              }
310576            }
310577          ],
310578          "cpe": "cpe:2.3:a:buffer-xor:buffer-xor:1.0.3:*:*:*:*:*:*:*",
310579          "purl": "pkg:npm/buffer-xor@1.0.3",
310580          "swid": {
310581            "attachment": {}
310582          },
310583          "pedigree": {},
310584          "evidence": {},
310585          "signature": {
310586            "signature": {
310587              "publicKey": {}
310588            }
310589          },
310590          "modelCard": {
310591            "modelParameters": {
310592              "approach": {}
310593            },
310594            "quantitativeAnalysis": {
310595              "graphics": {}
310596            },
310597            "considerations": {}
310598          }
310599        },
310600        {
310601          "type": "library",
310602          "bom-ref": "pkg:npm/builtin-modules@1.1.1?package-id=31064f37063f81ee",
310603          "supplier": {},
310604          "name": "builtin-modules",
310605          "version": "1.1.1",
310606          "licenses": [
310607            {
310608              "license": {
310609                "id": "MIT"
310610              }
310611            }
310612          ],
310613          "cpe": "cpe:2.3:a:builtin-modules:builtin-modules:1.1.1:*:*:*:*:*:*:*",
310614          "purl": "pkg:npm/builtin-modules@1.1.1",
310615          "swid": {
310616            "attachment": {}
310617          },
310618          "pedigree": {},
310619          "evidence": {},
310620          "signature": {
310621            "signature": {
310622              "publicKey": {}
310623            }
310624          },
310625          "modelCard": {
310626            "modelParameters": {
310627              "approach": {}
310628            },
310629            "quantitativeAnalysis": {
310630              "graphics": {}
310631            },
310632            "considerations": {}
310633          }
310634        },
310635        {
310636          "type": "library",
310637          "bom-ref": "pkg:npm/builtin-status-codes@3.0.0?package-id=b2843420d446906f",
310638          "supplier": {},
310639          "name": "builtin-status-codes",
310640          "version": "3.0.0",
310641          "licenses": [
310642            {
310643              "license": {
310644                "id": "MIT"
310645              }
310646            }
310647          ],
310648          "cpe": "cpe:2.3:a:builtin-status-codes:builtin-status-codes:3.0.0:*:*:*:*:*:*:*",
310649          "purl": "pkg:npm/builtin-status-codes@3.0.0",
310650          "swid": {
310651            "attachment": {}
310652          },
310653          "pedigree": {},
310654          "evidence": {},
310655          "signature": {
310656            "signature": {
310657              "publicKey": {}
310658            }
310659          },
310660          "modelCard": {
310661            "modelParameters": {
310662              "approach": {}
310663            },
310664            "quantitativeAnalysis": {
310665              "graphics": {}
310666            },
310667            "considerations": {}
310668          }
310669        },
310670        {
310671          "type": "library",
310672          "bom-ref": "pkg:npm/builtins@1.0.3?package-id=c10c626541113433",
310673          "supplier": {},
310674          "name": "builtins",
310675          "version": "1.0.3",
310676          "licenses": [
310677            {
310678              "license": {
310679                "id": "MIT"
310680              }
310681            }
310682          ],
310683          "cpe": "cpe:2.3:a:builtins:builtins:1.0.3:*:*:*:*:*:*:*",
310684          "purl": "pkg:npm/builtins@1.0.3",
310685          "swid": {
310686            "attachment": {}
310687          },
310688          "pedigree": {},
310689          "evidence": {},
310690          "signature": {
310691            "signature": {
310692              "publicKey": {}
310693            }
310694          },
310695          "modelCard": {
310696            "modelParameters": {
310697              "approach": {}
310698            },
310699            "quantitativeAnalysis": {
310700              "graphics": {}
310701            },
310702            "considerations": {}
310703          }
310704        },
310705        {
310706          "type": "library",
310707          "bom-ref": "pkg:npm/bytes@3.0.0?package-id=25655770bea399b3",
310708          "supplier": {},
310709          "name": "bytes",
310710          "version": "3.0.0",
310711          "licenses": [
310712            {
310713              "license": {
310714                "id": "MIT"
310715              }
310716            }
310717          ],
310718          "cpe": "cpe:2.3:a:bytes:bytes:3.0.0:*:*:*:*:*:*:*",
310719          "purl": "pkg:npm/bytes@3.0.0",
310720          "swid": {
310721            "attachment": {}
310722          },
310723          "pedigree": {},
310724          "evidence": {},
310725          "signature": {
310726            "signature": {
310727              "publicKey": {}
310728            }
310729          },
310730          "modelCard": {
310731            "modelParameters": {
310732              "approach": {}
310733            },
310734            "quantitativeAnalysis": {
310735              "graphics": {}
310736            },
310737            "considerations": {}
310738          }
310739        },
310740        {
310741          "type": "library",
310742          "bom-ref": "pkg:npm/cacache@15.0.0?package-id=3bb376be6c6d3685",
310743          "supplier": {},
310744          "name": "cacache",
310745          "version": "15.0.0",
310746          "licenses": [
310747            {
310748              "license": {
310749                "id": "ISC"
310750              }
310751            }
310752          ],
310753          "cpe": "cpe:2.3:a:cacache:cacache:15.0.0:*:*:*:*:*:*:*",
310754          "purl": "pkg:npm/cacache@15.0.0",
310755          "swid": {
310756            "attachment": {}
310757          },
310758          "pedigree": {},
310759          "evidence": {},
310760          "signature": {
310761            "signature": {
310762              "publicKey": {}
310763            }
310764          },
310765          "modelCard": {
310766            "modelParameters": {
310767              "approach": {}
310768            },
310769            "quantitativeAnalysis": {
310770              "graphics": {}
310771            },
310772            "considerations": {}
310773          }
310774        },
310775        {
310776          "type": "library",
310777          "bom-ref": "pkg:npm/cache-base@1.0.1?package-id=45a70e1316c1db9c",
310778          "supplier": {},
310779          "name": "cache-base",
310780          "version": "1.0.1",
310781          "licenses": [
310782            {
310783              "license": {
310784                "id": "MIT"
310785              }
310786            }
310787          ],
310788          "cpe": "cpe:2.3:a:cache-base:cache-base:1.0.1:*:*:*:*:*:*:*",
310789          "purl": "pkg:npm/cache-base@1.0.1",
310790          "swid": {
310791            "attachment": {}
310792          },
310793          "pedigree": {},
310794          "evidence": {},
310795          "signature": {
310796            "signature": {
310797              "publicKey": {}
310798            }
310799          },
310800          "modelCard": {
310801            "modelParameters": {
310802              "approach": {}
310803            },
310804            "quantitativeAnalysis": {
310805              "graphics": {}
310806            },
310807            "considerations": {}
310808          }
310809        },
310810        {
310811          "type": "library",
310812          "bom-ref": "pkg:npm/caching-transform@4.0.0?package-id=3dde9b4daece0148",
310813          "supplier": {},
310814          "name": "caching-transform",
310815          "version": "4.0.0",
310816          "cpe": "cpe:2.3:a:caching-transform:caching-transform:4.0.0:*:*:*:*:*:*:*",
310817          "purl": "pkg:npm/caching-transform@4.0.0",
310818          "swid": {
310819            "attachment": {}
310820          },
310821          "pedigree": {},
310822          "evidence": {},
310823          "signature": {
310824            "signature": {
310825              "publicKey": {}
310826            }
310827          },
310828          "modelCard": {
310829            "modelParameters": {
310830              "approach": {}
310831            },
310832            "quantitativeAnalysis": {
310833              "graphics": {}
310834            },
310835            "considerations": {}
310836          }
310837        },
310838        {
310839          "type": "library",
310840          "bom-ref": "pkg:npm/call-me-maybe@1.0.1?package-id=62147265eb3a4bed",
310841          "supplier": {},
310842          "name": "call-me-maybe",
310843          "version": "1.0.1",
310844          "licenses": [
310845            {
310846              "license": {
310847                "id": "MIT"
310848              }
310849            }
310850          ],
310851          "cpe": "cpe:2.3:a:call-me-maybe:call-me-maybe:1.0.1:*:*:*:*:*:*:*",
310852          "purl": "pkg:npm/call-me-maybe@1.0.1",
310853          "swid": {
310854            "attachment": {}
310855          },
310856          "pedigree": {},
310857          "evidence": {},
310858          "signature": {
310859            "signature": {
310860              "publicKey": {}
310861            }
310862          },
310863          "modelCard": {
310864            "modelParameters": {
310865              "approach": {}
310866            },
310867            "quantitativeAnalysis": {
310868              "graphics": {}
310869            },
310870            "considerations": {}
310871          }
310872        },
310873        {
310874          "type": "library",
310875          "bom-ref": "pkg:npm/caller-callsite@2.0.0?package-id=268c4e17d7a884d5",
310876          "supplier": {},
310877          "name": "caller-callsite",
310878          "version": "2.0.0",
310879          "licenses": [
310880            {
310881              "license": {
310882                "id": "MIT"
310883              }
310884            }
310885          ],
310886          "cpe": "cpe:2.3:a:caller-callsite:caller-callsite:2.0.0:*:*:*:*:*:*:*",
310887          "purl": "pkg:npm/caller-callsite@2.0.0",
310888          "swid": {
310889            "attachment": {}
310890          },
310891          "pedigree": {},
310892          "evidence": {},
310893          "signature": {
310894            "signature": {
310895              "publicKey": {}
310896            }
310897          },
310898          "modelCard": {
310899            "modelParameters": {
310900              "approach": {}
310901            },
310902            "quantitativeAnalysis": {
310903              "graphics": {}
310904            },
310905            "considerations": {}
310906          }
310907        },
310908        {
310909          "type": "library",
310910          "bom-ref": "pkg:npm/caller-path@2.0.0?package-id=4f6dc334a59f16ff",
310911          "supplier": {},
310912          "name": "caller-path",
310913          "version": "2.0.0",
310914          "licenses": [
310915            {
310916              "license": {
310917                "id": "MIT"
310918              }
310919            }
310920          ],
310921          "cpe": "cpe:2.3:a:caller-path:caller-path:2.0.0:*:*:*:*:*:*:*",
310922          "purl": "pkg:npm/caller-path@2.0.0",
310923          "swid": {
310924            "attachment": {}
310925          },
310926          "pedigree": {},
310927          "evidence": {},
310928          "signature": {
310929            "signature": {
310930              "publicKey": {}
310931            }
310932          },
310933          "modelCard": {
310934            "modelParameters": {
310935              "approach": {}
310936            },
310937            "quantitativeAnalysis": {
310938              "graphics": {}
310939            },
310940            "considerations": {}
310941          }
310942        },
310943        {
310944          "type": "library",
310945          "bom-ref": "pkg:npm/callsite@1.0.0?package-id=d87b691258b9ad54",
310946          "supplier": {},
310947          "name": "callsite",
310948          "version": "1.0.0",
310949          "cpe": "cpe:2.3:a:callsite:callsite:1.0.0:*:*:*:*:*:*:*",
310950          "purl": "pkg:npm/callsite@1.0.0",
310951          "swid": {
310952            "attachment": {}
310953          },
310954          "pedigree": {},
310955          "evidence": {},
310956          "signature": {
310957            "signature": {
310958              "publicKey": {}
310959            }
310960          },
310961          "modelCard": {
310962            "modelParameters": {
310963              "approach": {}
310964            },
310965            "quantitativeAnalysis": {
310966              "graphics": {}
310967            },
310968            "considerations": {}
310969          }
310970        },
310971        {
310972          "type": "library",
310973          "bom-ref": "pkg:npm/callsites@2.0.0?package-id=45edd85f19fbc078",
310974          "supplier": {},
310975          "name": "callsites",
310976          "version": "2.0.0",
310977          "licenses": [
310978            {
310979              "license": {
310980                "id": "MIT"
310981              }
310982            }
310983          ],
310984          "cpe": "cpe:2.3:a:callsites:callsites:2.0.0:*:*:*:*:*:*:*",
310985          "purl": "pkg:npm/callsites@2.0.0",
310986          "swid": {
310987            "attachment": {}
310988          },
310989          "pedigree": {},
310990          "evidence": {},
310991          "signature": {
310992            "signature": {
310993              "publicKey": {}
310994            }
310995          },
310996          "modelCard": {
310997            "modelParameters": {
310998              "approach": {}
310999            },
311000            "quantitativeAnalysis": {
311001              "graphics": {}
311002            },
311003            "considerations": {}
311004          }
311005        },
311006        {
311007          "type": "library",
311008          "bom-ref": "pkg:npm/camelcase@5.3.1?package-id=64418a45e773aa3c",
311009          "supplier": {},
311010          "name": "camelcase",
311011          "version": "5.3.1",
311012          "cpe": "cpe:2.3:a:camelcase:camelcase:5.3.1:*:*:*:*:*:*:*",
311013          "purl": "pkg:npm/camelcase@5.3.1",
311014          "swid": {
311015            "attachment": {}
311016          },
311017          "pedigree": {},
311018          "evidence": {},
311019          "signature": {
311020            "signature": {
311021              "publicKey": {}
311022            }
311023          },
311024          "modelCard": {
311025            "modelParameters": {
311026              "approach": {}
311027            },
311028            "quantitativeAnalysis": {
311029              "graphics": {}
311030            },
311031            "considerations": {}
311032          }
311033        },
311034        {
311035          "type": "library",
311036          "bom-ref": "pkg:npm/camelcase@5.3.1?package-id=3c63d98a548b1002",
311037          "supplier": {},
311038          "name": "camelcase",
311039          "version": "5.3.1",
311040          "licenses": [
311041            {
311042              "license": {
311043                "id": "MIT"
311044              }
311045            }
311046          ],
311047          "cpe": "cpe:2.3:a:camelcase:camelcase:5.3.1:*:*:*:*:*:*:*",
311048          "purl": "pkg:npm/camelcase@5.3.1",
311049          "swid": {
311050            "attachment": {}
311051          },
311052          "pedigree": {},
311053          "evidence": {},
311054          "signature": {
311055            "signature": {
311056              "publicKey": {}
311057            }
311058          },
311059          "modelCard": {
311060            "modelParameters": {
311061              "approach": {}
311062            },
311063            "quantitativeAnalysis": {
311064              "graphics": {}
311065            },
311066            "considerations": {}
311067          }
311068        },
311069        {
311070          "type": "library",
311071          "bom-ref": "pkg:npm/camelcase-keys@2.1.0?package-id=aa0734a45a296254",
311072          "supplier": {},
311073          "name": "camelcase-keys",
311074          "version": "2.1.0",
311075          "licenses": [
311076            {
311077              "license": {
311078                "id": "MIT"
311079              }
311080            }
311081          ],
311082          "cpe": "cpe:2.3:a:camelcase-keys:camelcase-keys:2.1.0:*:*:*:*:*:*:*",
311083          "purl": "pkg:npm/camelcase-keys@2.1.0",
311084          "swid": {
311085            "attachment": {}
311086          },
311087          "pedigree": {},
311088          "evidence": {},
311089          "signature": {
311090            "signature": {
311091              "publicKey": {}
311092            }
311093          },
311094          "modelCard": {
311095            "modelParameters": {
311096              "approach": {}
311097            },
311098            "quantitativeAnalysis": {
311099              "graphics": {}
311100            },
311101            "considerations": {}
311102          }
311103        },
311104        {
311105          "type": "library",
311106          "bom-ref": "pkg:npm/can-use-dom@0.1.0?package-id=5731bd9daec3136e",
311107          "supplier": {},
311108          "name": "can-use-dom",
311109          "version": "0.1.0",
311110          "licenses": [
311111            {
311112              "license": {
311113                "id": "MIT"
311114              }
311115            }
311116          ],
311117          "cpe": "cpe:2.3:a:can-use-dom:can-use-dom:0.1.0:*:*:*:*:*:*:*",
311118          "purl": "pkg:npm/can-use-dom@0.1.0",
311119          "swid": {
311120            "attachment": {}
311121          },
311122          "pedigree": {},
311123          "evidence": {},
311124          "signature": {
311125            "signature": {
311126              "publicKey": {}
311127            }
311128          },
311129          "modelCard": {
311130            "modelParameters": {
311131              "approach": {}
311132            },
311133            "quantitativeAnalysis": {
311134              "graphics": {}
311135            },
311136            "considerations": {}
311137          }
311138        },
311139        {
311140          "type": "library",
311141          "bom-ref": "pkg:npm/caniuse-api@3.0.0?package-id=3a6b5418ba85bf55",
311142          "supplier": {},
311143          "name": "caniuse-api",
311144          "version": "3.0.0",
311145          "licenses": [
311146            {
311147              "license": {
311148                "id": "MIT"
311149              }
311150            }
311151          ],
311152          "cpe": "cpe:2.3:a:caniuse-api:caniuse-api:3.0.0:*:*:*:*:*:*:*",
311153          "purl": "pkg:npm/caniuse-api@3.0.0",
311154          "swid": {
311155            "attachment": {}
311156          },
311157          "pedigree": {},
311158          "evidence": {},
311159          "signature": {
311160            "signature": {
311161              "publicKey": {}
311162            }
311163          },
311164          "modelCard": {
311165            "modelParameters": {
311166              "approach": {}
311167            },
311168            "quantitativeAnalysis": {
311169              "graphics": {}
311170            },
311171            "considerations": {}
311172          }
311173        },
311174        {
311175          "type": "library",
311176          "bom-ref": "pkg:npm/caniuse-lite@1.0.30001055?package-id=611d15b1524279d7",
311177          "supplier": {},
311178          "name": "caniuse-lite",
311179          "version": "1.0.30001055",
311180          "licenses": [
311181            {
311182              "license": {
311183                "id": "CC-BY-4.0"
311184              }
311185            }
311186          ],
311187          "cpe": "cpe:2.3:a:caniuse-lite:caniuse-lite:1.0.30001055:*:*:*:*:*:*:*",
311188          "purl": "pkg:npm/caniuse-lite@1.0.30001055",
311189          "swid": {
311190            "attachment": {}
311191          },
311192          "pedigree": {},
311193          "evidence": {},
311194          "signature": {
311195            "signature": {
311196              "publicKey": {}
311197            }
311198          },
311199          "modelCard": {
311200            "modelParameters": {
311201              "approach": {}
311202            },
311203            "quantitativeAnalysis": {
311204              "graphics": {}
311205            },
311206            "considerations": {}
311207          }
311208        },
311209        {
311210          "type": "library",
311211          "bom-ref": "pkg:npm/caniuse-lite@1.0.30001285?package-id=56f3c39cc6419cf5",
311212          "supplier": {},
311213          "name": "caniuse-lite",
311214          "version": "1.0.30001285",
311215          "cpe": "cpe:2.3:a:caniuse-lite:caniuse-lite:1.0.30001285:*:*:*:*:*:*:*",
311216          "purl": "pkg:npm/caniuse-lite@1.0.30001285",
311217          "swid": {
311218            "attachment": {}
311219          },
311220          "pedigree": {},
311221          "evidence": {},
311222          "signature": {
311223            "signature": {
311224              "publicKey": {}
311225            }
311226          },
311227          "modelCard": {
311228            "modelParameters": {
311229              "approach": {}
311230            },
311231            "quantitativeAnalysis": {
311232              "graphics": {}
311233            },
311234            "considerations": {}
311235          }
311236        },
311237        {
311238          "type": "library",
311239          "bom-ref": "pkg:npm/canonical-path@1.0.0?package-id=7c0b085ae0502b98",
311240          "supplier": {},
311241          "name": "canonical-path",
311242          "version": "1.0.0",
311243          "licenses": [
311244            {
311245              "license": {
311246                "id": "MIT"
311247              }
311248            }
311249          ],
311250          "cpe": "cpe:2.3:a:canonical-path:canonical-path:1.0.0:*:*:*:*:*:*:*",
311251          "purl": "pkg:npm/canonical-path@1.0.0",
311252          "swid": {
311253            "attachment": {}
311254          },
311255          "pedigree": {},
311256          "evidence": {},
311257          "signature": {
311258            "signature": {
311259              "publicKey": {}
311260            }
311261          },
311262          "modelCard": {
311263            "modelParameters": {
311264              "approach": {}
311265            },
311266            "quantitativeAnalysis": {
311267              "graphics": {}
311268            },
311269            "considerations": {}
311270          }
311271        },
311272        {
311273          "type": "library",
311274          "bom-ref": "pkg:npm/caseless@0.12.0?package-id=810c24f06aebfc6a",
311275          "supplier": {},
311276          "name": "caseless",
311277          "version": "0.12.0",
311278          "licenses": [
311279            {
311280              "license": {
311281                "id": "Apache-2.0"
311282              }
311283            }
311284          ],
311285          "cpe": "cpe:2.3:a:caseless:caseless:0.12.0:*:*:*:*:*:*:*",
311286          "purl": "pkg:npm/caseless@0.12.0",
311287          "swid": {
311288            "attachment": {}
311289          },
311290          "pedigree": {},
311291          "evidence": {},
311292          "signature": {
311293            "signature": {
311294              "publicKey": {}
311295            }
311296          },
311297          "modelCard": {
311298            "modelParameters": {
311299              "approach": {}
311300            },
311301            "quantitativeAnalysis": {
311302              "graphics": {}
311303            },
311304            "considerations": {}
311305          }
311306        },
311307        {
311308          "type": "library",
311309          "bom-ref": "pkg:npm/chalk@2.4.2?package-id=89e1b1cd85b232ec",
311310          "supplier": {},
311311          "name": "chalk",
311312          "version": "2.4.2",
311313          "cpe": "cpe:2.3:a:chalk:chalk:2.4.2:*:*:*:*:*:*:*",
311314          "purl": "pkg:npm/chalk@2.4.2",
311315          "swid": {
311316            "attachment": {}
311317          },
311318          "pedigree": {},
311319          "evidence": {},
311320          "signature": {
311321            "signature": {
311322              "publicKey": {}
311323            }
311324          },
311325          "modelCard": {
311326            "modelParameters": {
311327              "approach": {}
311328            },
311329            "quantitativeAnalysis": {
311330              "graphics": {}
311331            },
311332            "considerations": {}
311333          }
311334        },
311335        {
311336          "type": "library",
311337          "bom-ref": "pkg:npm/chalk@2.4.2?package-id=91533e2075528b50",
311338          "supplier": {},
311339          "name": "chalk",
311340          "version": "2.4.2",
311341          "licenses": [
311342            {
311343              "license": {
311344                "id": "MIT"
311345              }
311346            }
311347          ],
311348          "cpe": "cpe:2.3:a:chalk:chalk:2.4.2:*:*:*:*:*:*:*",
311349          "purl": "pkg:npm/chalk@2.4.2",
311350          "swid": {
311351            "attachment": {}
311352          },
311353          "pedigree": {},
311354          "evidence": {},
311355          "signature": {
311356            "signature": {
311357              "publicKey": {}
311358            }
311359          },
311360          "modelCard": {
311361            "modelParameters": {
311362              "approach": {}
311363            },
311364            "quantitativeAnalysis": {
311365              "graphics": {}
311366            },
311367            "considerations": {}
311368          }
311369        },
311370        {
311371          "type": "library",
311372          "bom-ref": "pkg:npm/chardet@0.7.0?package-id=e22e7a2265bb041e",
311373          "supplier": {},
311374          "name": "chardet",
311375          "version": "0.7.0",
311376          "licenses": [
311377            {
311378              "license": {
311379                "id": "MIT"
311380              }
311381            }
311382          ],
311383          "cpe": "cpe:2.3:a:chardet:chardet:0.7.0:*:*:*:*:*:*:*",
311384          "purl": "pkg:npm/chardet@0.7.0",
311385          "swid": {
311386            "attachment": {}
311387          },
311388          "pedigree": {},
311389          "evidence": {},
311390          "signature": {
311391            "signature": {
311392              "publicKey": {}
311393            }
311394          },
311395          "modelCard": {
311396            "modelParameters": {
311397              "approach": {}
311398            },
311399            "quantitativeAnalysis": {
311400              "graphics": {}
311401            },
311402            "considerations": {}
311403          }
311404        },
311405        {
311406          "type": "library",
311407          "bom-ref": "pkg:npm/charenc@0.0.2?package-id=f547358339ca8c04",
311408          "supplier": {},
311409          "name": "charenc",
311410          "version": "0.0.2",
311411          "licenses": [
311412            {
311413              "license": {
311414                "id": "BSD-3-Clause"
311415              }
311416            }
311417          ],
311418          "cpe": "cpe:2.3:a:charenc:charenc:0.0.2:*:*:*:*:*:*:*",
311419          "purl": "pkg:npm/charenc@0.0.2",
311420          "swid": {
311421            "attachment": {}
311422          },
311423          "pedigree": {},
311424          "evidence": {},
311425          "signature": {
311426            "signature": {
311427              "publicKey": {}
311428            }
311429          },
311430          "modelCard": {
311431            "modelParameters": {
311432              "approach": {}
311433            },
311434            "quantitativeAnalysis": {
311435              "graphics": {}
311436            },
311437            "considerations": {}
311438          }
311439        },
311440        {
311441          "type": "library",
311442          "bom-ref": "pkg:npm/check-types@8.0.3?package-id=8161d4b8418b95da",
311443          "supplier": {},
311444          "name": "check-types",
311445          "version": "8.0.3",
311446          "licenses": [
311447            {
311448              "license": {
311449                "id": "MIT"
311450              }
311451            }
311452          ],
311453          "cpe": "cpe:2.3:a:check-types:check-types:8.0.3:*:*:*:*:*:*:*",
311454          "purl": "pkg:npm/check-types@8.0.3",
311455          "swid": {
311456            "attachment": {}
311457          },
311458          "pedigree": {},
311459          "evidence": {},
311460          "signature": {
311461            "signature": {
311462              "publicKey": {}
311463            }
311464          },
311465          "modelCard": {
311466            "modelParameters": {
311467              "approach": {}
311468            },
311469            "quantitativeAnalysis": {
311470              "graphics": {}
311471            },
311472            "considerations": {}
311473          }
311474        },
311475        {
311476          "type": "library",
311477          "bom-ref": "pkg:npm/chokidar@3.3.1?package-id=8db25f2f4984f00c",
311478          "supplier": {},
311479          "name": "chokidar",
311480          "version": "3.3.1",
311481          "licenses": [
311482            {
311483              "license": {
311484                "id": "MIT"
311485              }
311486            }
311487          ],
311488          "cpe": "cpe:2.3:a:chokidar:chokidar:3.3.1:*:*:*:*:*:*:*",
311489          "purl": "pkg:npm/chokidar@3.3.1",
311490          "swid": {
311491            "attachment": {}
311492          },
311493          "pedigree": {},
311494          "evidence": {},
311495          "signature": {
311496            "signature": {
311497              "publicKey": {}
311498            }
311499          },
311500          "modelCard": {
311501            "modelParameters": {
311502              "approach": {}
311503            },
311504            "quantitativeAnalysis": {
311505              "graphics": {}
311506            },
311507            "considerations": {}
311508          }
311509        },
311510        {
311511          "type": "library",
311512          "bom-ref": "pkg:npm/chownr@1.1.4?package-id=8b60213f0177e0",
311513          "supplier": {},
311514          "name": "chownr",
311515          "version": "1.1.4",
311516          "licenses": [
311517            {
311518              "license": {
311519                "id": "ISC"
311520              }
311521            }
311522          ],
311523          "cpe": "cpe:2.3:a:chownr:chownr:1.1.4:*:*:*:*:*:*:*",
311524          "purl": "pkg:npm/chownr@1.1.4",
311525          "swid": {
311526            "attachment": {}
311527          },
311528          "pedigree": {},
311529          "evidence": {},
311530          "signature": {
311531            "signature": {
311532              "publicKey": {}
311533            }
311534          },
311535          "modelCard": {
311536            "modelParameters": {
311537              "approach": {}
311538            },
311539            "quantitativeAnalysis": {
311540              "graphics": {}
311541            },
311542            "considerations": {}
311543          }
311544        },
311545        {
311546          "type": "library",
311547          "bom-ref": "pkg:npm/chrome-trace-event@1.0.2?package-id=4136cd1420862470",
311548          "supplier": {},
311549          "name": "chrome-trace-event",
311550          "version": "1.0.2",
311551          "licenses": [
311552            {
311553              "license": {
311554                "id": "MIT"
311555              }
311556            }
311557          ],
311558          "cpe": "cpe:2.3:a:chrome-trace-event:chrome-trace-event:1.0.2:*:*:*:*:*:*:*",
311559          "purl": "pkg:npm/chrome-trace-event@1.0.2",
311560          "swid": {
311561            "attachment": {}
311562          },
311563          "pedigree": {},
311564          "evidence": {},
311565          "signature": {
311566            "signature": {
311567              "publicKey": {}
311568            }
311569          },
311570          "modelCard": {
311571            "modelParameters": {
311572              "approach": {}
311573            },
311574            "quantitativeAnalysis": {
311575              "graphics": {}
311576            },
311577            "considerations": {}
311578          }
311579        },
311580        {
311581          "type": "library",
311582          "bom-ref": "pkg:npm/ci-info@2.0.0?package-id=bf8ac6d1b254b397",
311583          "supplier": {},
311584          "name": "ci-info",
311585          "version": "2.0.0",
311586          "cpe": "cpe:2.3:a:ci-info:ci-info:2.0.0:*:*:*:*:*:*:*",
311587          "purl": "pkg:npm/ci-info@2.0.0",
311588          "swid": {
311589            "attachment": {}
311590          },
311591          "pedigree": {},
311592          "evidence": {},
311593          "signature": {
311594            "signature": {
311595              "publicKey": {}
311596            }
311597          },
311598          "modelCard": {
311599            "modelParameters": {
311600              "approach": {}
311601            },
311602            "quantitativeAnalysis": {
311603              "graphics": {}
311604            },
311605            "considerations": {}
311606          }
311607        },
311608        {
311609          "type": "library",
311610          "bom-ref": "pkg:npm/ci-info@2.0.0?package-id=4b0fb1e5aa5f5b2",
311611          "supplier": {},
311612          "name": "ci-info",
311613          "version": "2.0.0",
311614          "licenses": [
311615            {
311616              "license": {
311617                "id": "MIT"
311618              }
311619            }
311620          ],
311621          "cpe": "cpe:2.3:a:ci-info:ci-info:2.0.0:*:*:*:*:*:*:*",
311622          "purl": "pkg:npm/ci-info@2.0.0",
311623          "swid": {
311624            "attachment": {}
311625          },
311626          "pedigree": {},
311627          "evidence": {},
311628          "signature": {
311629            "signature": {
311630              "publicKey": {}
311631            }
311632          },
311633          "modelCard": {
311634            "modelParameters": {
311635              "approach": {}
311636            },
311637            "quantitativeAnalysis": {
311638              "graphics": {}
311639            },
311640            "considerations": {}
311641          }
311642        },
311643        {
311644          "type": "library",
311645          "bom-ref": "pkg:npm/cipher-base@1.0.4?package-id=2e12432545be02d9",
311646          "supplier": {},
311647          "name": "cipher-base",
311648          "version": "1.0.4",
311649          "licenses": [
311650            {
311651              "license": {
311652                "id": "MIT"
311653              }
311654            }
311655          ],
311656          "cpe": "cpe:2.3:a:cipher-base:cipher-base:1.0.4:*:*:*:*:*:*:*",
311657          "purl": "pkg:npm/cipher-base@1.0.4",
311658          "swid": {
311659            "attachment": {}
311660          },
311661          "pedigree": {},
311662          "evidence": {},
311663          "signature": {
311664            "signature": {
311665              "publicKey": {}
311666            }
311667          },
311668          "modelCard": {
311669            "modelParameters": {
311670              "approach": {}
311671            },
311672            "quantitativeAnalysis": {
311673              "graphics": {}
311674            },
311675            "considerations": {}
311676          }
311677        },
311678        {
311679          "type": "library",
311680          "bom-ref": "pkg:npm/circular-dependency-plugin@5.2.0?package-id=d90c5a2da527318c",
311681          "supplier": {},
311682          "name": "circular-dependency-plugin",
311683          "version": "5.2.0",
311684          "licenses": [
311685            {
311686              "license": {
311687                "id": "ISC"
311688              }
311689            }
311690          ],
311691          "cpe": "cpe:2.3:a:circular-dependency-plugin:circular-dependency-plugin:5.2.0:*:*:*:*:*:*:*",
311692          "purl": "pkg:npm/circular-dependency-plugin@5.2.0",
311693          "swid": {
311694            "attachment": {}
311695          },
311696          "pedigree": {},
311697          "evidence": {},
311698          "signature": {
311699            "signature": {
311700              "publicKey": {}
311701            }
311702          },
311703          "modelCard": {
311704            "modelParameters": {
311705              "approach": {}
311706            },
311707            "quantitativeAnalysis": {
311708              "graphics": {}
311709            },
311710            "considerations": {}
311711          }
311712        },
311713        {
311714          "type": "library",
311715          "bom-ref": "pkg:npm/circular-json@0.3.3?package-id=9a46aa10e528d6b9",
311716          "supplier": {},
311717          "name": "circular-json",
311718          "version": "0.3.3",
311719          "licenses": [
311720            {
311721              "license": {
311722                "id": "MIT"
311723              }
311724            }
311725          ],
311726          "cpe": "cpe:2.3:a:circular-json:circular-json:0.3.3:*:*:*:*:*:*:*",
311727          "purl": "pkg:npm/circular-json@0.3.3",
311728          "swid": {
311729            "attachment": {}
311730          },
311731          "pedigree": {},
311732          "evidence": {},
311733          "signature": {
311734            "signature": {
311735              "publicKey": {}
311736            }
311737          },
311738          "modelCard": {
311739            "modelParameters": {
311740              "approach": {}
311741            },
311742            "quantitativeAnalysis": {
311743              "graphics": {}
311744            },
311745            "considerations": {}
311746          }
311747        },
311748        {
311749          "type": "library",
311750          "bom-ref": "pkg:npm/class-utils@0.3.6?package-id=b176fd4426480b1a",
311751          "supplier": {},
311752          "name": "class-utils",
311753          "version": "0.3.6",
311754          "licenses": [
311755            {
311756              "license": {
311757                "id": "MIT"
311758              }
311759            }
311760          ],
311761          "cpe": "cpe:2.3:a:class-utils:class-utils:0.3.6:*:*:*:*:*:*:*",
311762          "purl": "pkg:npm/class-utils@0.3.6",
311763          "swid": {
311764            "attachment": {}
311765          },
311766          "pedigree": {},
311767          "evidence": {},
311768          "signature": {
311769            "signature": {
311770              "publicKey": {}
311771            }
311772          },
311773          "modelCard": {
311774            "modelParameters": {
311775              "approach": {}
311776            },
311777            "quantitativeAnalysis": {
311778              "graphics": {}
311779            },
311780            "considerations": {}
311781          }
311782        },
311783        {
311784          "type": "library",
311785          "bom-ref": "pkg:npm/clean-stack@2.2.0?package-id=5cb897b6a342e151",
311786          "supplier": {},
311787          "name": "clean-stack",
311788          "version": "2.2.0",
311789          "cpe": "cpe:2.3:a:clean-stack:clean-stack:2.2.0:*:*:*:*:*:*:*",
311790          "purl": "pkg:npm/clean-stack@2.2.0",
311791          "swid": {
311792            "attachment": {}
311793          },
311794          "pedigree": {},
311795          "evidence": {},
311796          "signature": {
311797            "signature": {
311798              "publicKey": {}
311799            }
311800          },
311801          "modelCard": {
311802            "modelParameters": {
311803              "approach": {}
311804            },
311805            "quantitativeAnalysis": {
311806              "graphics": {}
311807            },
311808            "considerations": {}
311809          }
311810        },
311811        {
311812          "type": "library",
311813          "bom-ref": "pkg:npm/clean-stack@2.2.0?package-id=7144d645960bf80b",
311814          "supplier": {},
311815          "name": "clean-stack",
311816          "version": "2.2.0",
311817          "licenses": [
311818            {
311819              "license": {
311820                "id": "MIT"
311821              }
311822            }
311823          ],
311824          "cpe": "cpe:2.3:a:clean-stack:clean-stack:2.2.0:*:*:*:*:*:*:*",
311825          "purl": "pkg:npm/clean-stack@2.2.0",
311826          "swid": {
311827            "attachment": {}
311828          },
311829          "pedigree": {},
311830          "evidence": {},
311831          "signature": {
311832            "signature": {
311833              "publicKey": {}
311834            }
311835          },
311836          "modelCard": {
311837            "modelParameters": {
311838              "approach": {}
311839            },
311840            "quantitativeAnalysis": {
311841              "graphics": {}
311842            },
311843            "considerations": {}
311844          }
311845        },
311846        {
311847          "type": "library",
311848          "bom-ref": "pkg:npm/cli-color@1.4.0?package-id=ded11711f4a82246",
311849          "supplier": {},
311850          "name": "cli-color",
311851          "version": "1.4.0",
311852          "licenses": [
311853            {
311854              "license": {
311855                "id": "ISC"
311856              }
311857            }
311858          ],
311859          "cpe": "cpe:2.3:a:cli-color:cli-color:1.4.0:*:*:*:*:*:*:*",
311860          "purl": "pkg:npm/cli-color@1.4.0",
311861          "swid": {
311862            "attachment": {}
311863          },
311864          "pedigree": {},
311865          "evidence": {},
311866          "signature": {
311867            "signature": {
311868              "publicKey": {}
311869            }
311870          },
311871          "modelCard": {
311872            "modelParameters": {
311873              "approach": {}
311874            },
311875            "quantitativeAnalysis": {
311876              "graphics": {}
311877            },
311878            "considerations": {}
311879          }
311880        },
311881        {
311882          "type": "library",
311883          "bom-ref": "pkg:npm/cli-cursor@3.1.0?package-id=5e58859331dad80e",
311884          "supplier": {},
311885          "name": "cli-cursor",
311886          "version": "3.1.0",
311887          "licenses": [
311888            {
311889              "license": {
311890                "id": "MIT"
311891              }
311892            }
311893          ],
311894          "cpe": "cpe:2.3:a:cli-cursor:cli-cursor:3.1.0:*:*:*:*:*:*:*",
311895          "purl": "pkg:npm/cli-cursor@3.1.0",
311896          "swid": {
311897            "attachment": {}
311898          },
311899          "pedigree": {},
311900          "evidence": {},
311901          "signature": {
311902            "signature": {
311903              "publicKey": {}
311904            }
311905          },
311906          "modelCard": {
311907            "modelParameters": {
311908              "approach": {}
311909            },
311910            "quantitativeAnalysis": {
311911              "graphics": {}
311912            },
311913            "considerations": {}
311914          }
311915        },
311916        {
311917          "type": "library",
311918          "bom-ref": "pkg:npm/cli-spinners@2.3.0?package-id=769cc7f0f537a3b4",
311919          "supplier": {},
311920          "name": "cli-spinners",
311921          "version": "2.3.0",
311922          "licenses": [
311923            {
311924              "license": {
311925                "id": "MIT"
311926              }
311927            }
311928          ],
311929          "cpe": "cpe:2.3:a:cli-spinners:cli-spinners:2.3.0:*:*:*:*:*:*:*",
311930          "purl": "pkg:npm/cli-spinners@2.3.0",
311931          "swid": {
311932            "attachment": {}
311933          },
311934          "pedigree": {},
311935          "evidence": {},
311936          "signature": {
311937            "signature": {
311938              "publicKey": {}
311939            }
311940          },
311941          "modelCard": {
311942            "modelParameters": {
311943              "approach": {}
311944            },
311945            "quantitativeAnalysis": {
311946              "graphics": {}
311947            },
311948            "considerations": {}
311949          }
311950        },
311951        {
311952          "type": "library",
311953          "bom-ref": "pkg:npm/cli-width@2.2.1?package-id=235f7f40ecd4a093",
311954          "supplier": {},
311955          "name": "cli-width",
311956          "version": "2.2.1",
311957          "licenses": [
311958            {
311959              "license": {
311960                "id": "ISC"
311961              }
311962            }
311963          ],
311964          "cpe": "cpe:2.3:a:cli-width:cli-width:2.2.1:*:*:*:*:*:*:*",
311965          "purl": "pkg:npm/cli-width@2.2.1",
311966          "swid": {
311967            "attachment": {}
311968          },
311969          "pedigree": {},
311970          "evidence": {},
311971          "signature": {
311972            "signature": {
311973              "publicKey": {}
311974            }
311975          },
311976          "modelCard": {
311977            "modelParameters": {
311978              "approach": {}
311979            },
311980            "quantitativeAnalysis": {
311981              "graphics": {}
311982            },
311983            "considerations": {}
311984          }
311985        },
311986        {
311987          "type": "library",
311988          "bom-ref": "pkg:npm/cliui@4.1.0?package-id=55298089117992b4",
311989          "supplier": {},
311990          "name": "cliui",
311991          "version": "4.1.0",
311992          "licenses": [
311993            {
311994              "license": {
311995                "id": "ISC"
311996              }
311997            }
311998          ],
311999          "cpe": "cpe:2.3:a:cliui:cliui:4.1.0:*:*:*:*:*:*:*",
312000          "purl": "pkg:npm/cliui@4.1.0",
312001          "swid": {
312002            "attachment": {}
312003          },
312004          "pedigree": {},
312005          "evidence": {},
312006          "signature": {
312007            "signature": {
312008              "publicKey": {}
312009            }
312010          },
312011          "modelCard": {
312012            "modelParameters": {
312013              "approach": {}
312014            },
312015            "quantitativeAnalysis": {
312016              "graphics": {}
312017            },
312018            "considerations": {}
312019          }
312020        },
312021        {
312022          "type": "library",
312023          "bom-ref": "pkg:npm/cliui@6.0.0?package-id=d3c09406207d0198",
312024          "supplier": {},
312025          "name": "cliui",
312026          "version": "6.0.0",
312027          "cpe": "cpe:2.3:a:cliui:cliui:6.0.0:*:*:*:*:*:*:*",
312028          "purl": "pkg:npm/cliui@6.0.0",
312029          "swid": {
312030            "attachment": {}
312031          },
312032          "pedigree": {},
312033          "evidence": {},
312034          "signature": {
312035            "signature": {
312036              "publicKey": {}
312037            }
312038          },
312039          "modelCard": {
312040            "modelParameters": {
312041              "approach": {}
312042            },
312043            "quantitativeAnalysis": {
312044              "graphics": {}
312045            },
312046            "considerations": {}
312047          }
312048        },
312049        {
312050          "type": "library",
312051          "bom-ref": "pkg:npm/clone@2.1.2?package-id=4b667ae9156999fe",
312052          "supplier": {},
312053          "name": "clone",
312054          "version": "2.1.2",
312055          "licenses": [
312056            {
312057              "license": {
312058                "id": "MIT"
312059              }
312060            }
312061          ],
312062          "cpe": "cpe:2.3:a:clone:clone:2.1.2:*:*:*:*:*:*:*",
312063          "purl": "pkg:npm/clone@2.1.2",
312064          "swid": {
312065            "attachment": {}
312066          },
312067          "pedigree": {},
312068          "evidence": {},
312069          "signature": {
312070            "signature": {
312071              "publicKey": {}
312072            }
312073          },
312074          "modelCard": {
312075            "modelParameters": {
312076              "approach": {}
312077            },
312078            "quantitativeAnalysis": {
312079              "graphics": {}
312080            },
312081            "considerations": {}
312082          }
312083        },
312084        {
312085          "type": "library",
312086          "bom-ref": "pkg:npm/clone-deep@4.0.1?package-id=57302f4a707255fa",
312087          "supplier": {},
312088          "name": "clone-deep",
312089          "version": "4.0.1",
312090          "licenses": [
312091            {
312092              "license": {
312093                "id": "MIT"
312094              }
312095            }
312096          ],
312097          "cpe": "cpe:2.3:a:clone-deep:clone-deep:4.0.1:*:*:*:*:*:*:*",
312098          "purl": "pkg:npm/clone-deep@4.0.1",
312099          "swid": {
312100            "attachment": {}
312101          },
312102          "pedigree": {},
312103          "evidence": {},
312104          "signature": {
312105            "signature": {
312106              "publicKey": {}
312107            }
312108          },
312109          "modelCard": {
312110            "modelParameters": {
312111              "approach": {}
312112            },
312113            "quantitativeAnalysis": {
312114              "graphics": {}
312115            },
312116            "considerations": {}
312117          }
312118        },
312119        {
312120          "type": "library",
312121          "bom-ref": "pkg:npm/coa@2.0.2?package-id=620bc3849a0ac193",
312122          "supplier": {},
312123          "name": "coa",
312124          "version": "2.0.2",
312125          "licenses": [
312126            {
312127              "license": {
312128                "id": "MIT"
312129              }
312130            }
312131          ],
312132          "cpe": "cpe:2.3:a:coa:coa:2.0.2:*:*:*:*:*:*:*",
312133          "purl": "pkg:npm/coa@2.0.2",
312134          "swid": {
312135            "attachment": {}
312136          },
312137          "pedigree": {},
312138          "evidence": {},
312139          "signature": {
312140            "signature": {
312141              "publicKey": {}
312142            }
312143          },
312144          "modelCard": {
312145            "modelParameters": {
312146              "approach": {}
312147            },
312148            "quantitativeAnalysis": {
312149              "graphics": {}
312150            },
312151            "considerations": {}
312152          }
312153        },
312154        {
312155          "type": "library",
312156          "bom-ref": "pkg:npm/code-point-at@1.1.0?package-id=ab8b6eab1355b484",
312157          "supplier": {},
312158          "name": "code-point-at",
312159          "version": "1.1.0",
312160          "licenses": [
312161            {
312162              "license": {
312163                "id": "MIT"
312164              }
312165            }
312166          ],
312167          "cpe": "cpe:2.3:a:code-point-at:code-point-at:1.1.0:*:*:*:*:*:*:*",
312168          "purl": "pkg:npm/code-point-at@1.1.0",
312169          "swid": {
312170            "attachment": {}
312171          },
312172          "pedigree": {},
312173          "evidence": {},
312174          "signature": {
312175            "signature": {
312176              "publicKey": {}
312177            }
312178          },
312179          "modelCard": {
312180            "modelParameters": {
312181              "approach": {}
312182            },
312183            "quantitativeAnalysis": {
312184              "graphics": {}
312185            },
312186            "considerations": {}
312187          }
312188        },
312189        {
312190          "type": "library",
312191          "bom-ref": "pkg:npm/codelyzer@5.2.1?package-id=dc45ed26cf7939e4",
312192          "supplier": {},
312193          "name": "codelyzer",
312194          "version": "5.2.1",
312195          "licenses": [
312196            {
312197              "license": {
312198                "id": "MIT"
312199              }
312200            }
312201          ],
312202          "cpe": "cpe:2.3:a:codelyzer:codelyzer:5.2.1:*:*:*:*:*:*:*",
312203          "purl": "pkg:npm/codelyzer@5.2.1",
312204          "swid": {
312205            "attachment": {}
312206          },
312207          "pedigree": {},
312208          "evidence": {},
312209          "signature": {
312210            "signature": {
312211              "publicKey": {}
312212            }
312213          },
312214          "modelCard": {
312215            "modelParameters": {
312216              "approach": {}
312217            },
312218            "quantitativeAnalysis": {
312219              "graphics": {}
312220            },
312221            "considerations": {}
312222          }
312223        },
312224        {
312225          "type": "library",
312226          "bom-ref": "pkg:npm/collection-visit@1.0.0?package-id=f354930f2a512d8f",
312227          "supplier": {},
312228          "name": "collection-visit",
312229          "version": "1.0.0",
312230          "licenses": [
312231            {
312232              "license": {
312233                "id": "MIT"
312234              }
312235            }
312236          ],
312237          "cpe": "cpe:2.3:a:collection-visit:collection-visit:1.0.0:*:*:*:*:*:*:*",
312238          "purl": "pkg:npm/collection-visit@1.0.0",
312239          "swid": {
312240            "attachment": {}
312241          },
312242          "pedigree": {},
312243          "evidence": {},
312244          "signature": {
312245            "signature": {
312246              "publicKey": {}
312247            }
312248          },
312249          "modelCard": {
312250            "modelParameters": {
312251              "approach": {}
312252            },
312253            "quantitativeAnalysis": {
312254              "graphics": {}
312255            },
312256            "considerations": {}
312257          }
312258        },
312259        {
312260          "type": "library",
312261          "bom-ref": "pkg:npm/color@3.1.2?package-id=acab57ea26363867",
312262          "supplier": {},
312263          "name": "color",
312264          "version": "3.1.2",
312265          "licenses": [
312266            {
312267              "license": {
312268                "id": "MIT"
312269              }
312270            }
312271          ],
312272          "cpe": "cpe:2.3:a:color:color:3.1.2:*:*:*:*:*:*:*",
312273          "purl": "pkg:npm/color@3.1.2",
312274          "swid": {
312275            "attachment": {}
312276          },
312277          "pedigree": {},
312278          "evidence": {},
312279          "signature": {
312280            "signature": {
312281              "publicKey": {}
312282            }
312283          },
312284          "modelCard": {
312285            "modelParameters": {
312286              "approach": {}
312287            },
312288            "quantitativeAnalysis": {
312289              "graphics": {}
312290            },
312291            "considerations": {}
312292          }
312293        },
312294        {
312295          "type": "library",
312296          "bom-ref": "pkg:npm/color-convert@1.9.3?package-id=30cf2b4a6155954d",
312297          "supplier": {},
312298          "name": "color-convert",
312299          "version": "1.9.3",
312300          "cpe": "cpe:2.3:a:color-convert:color-convert:1.9.3:*:*:*:*:*:*:*",
312301          "purl": "pkg:npm/color-convert@1.9.3",
312302          "swid": {
312303            "attachment": {}
312304          },
312305          "pedigree": {},
312306          "evidence": {},
312307          "signature": {
312308            "signature": {
312309              "publicKey": {}
312310            }
312311          },
312312          "modelCard": {
312313            "modelParameters": {
312314              "approach": {}
312315            },
312316            "quantitativeAnalysis": {
312317              "graphics": {}
312318            },
312319            "considerations": {}
312320          }
312321        },
312322        {
312323          "type": "library",
312324          "bom-ref": "pkg:npm/color-convert@1.9.3?package-id=8abd6aeba19b0077",
312325          "supplier": {},
312326          "name": "color-convert",
312327          "version": "1.9.3",
312328          "licenses": [
312329            {
312330              "license": {
312331                "id": "MIT"
312332              }
312333            }
312334          ],
312335          "cpe": "cpe:2.3:a:color-convert:color-convert:1.9.3:*:*:*:*:*:*:*",
312336          "purl": "pkg:npm/color-convert@1.9.3",
312337          "swid": {
312338            "attachment": {}
312339          },
312340          "pedigree": {},
312341          "evidence": {},
312342          "signature": {
312343            "signature": {
312344              "publicKey": {}
312345            }
312346          },
312347          "modelCard": {
312348            "modelParameters": {
312349              "approach": {}
312350            },
312351            "quantitativeAnalysis": {
312352              "graphics": {}
312353            },
312354            "considerations": {}
312355          }
312356        },
312357        {
312358          "type": "library",
312359          "bom-ref": "pkg:npm/color-name@1.1.3?package-id=e1848df3a480a07f",
312360          "supplier": {},
312361          "name": "color-name",
312362          "version": "1.1.3",
312363          "cpe": "cpe:2.3:a:color-name:color-name:1.1.3:*:*:*:*:*:*:*",
312364          "purl": "pkg:npm/color-name@1.1.3",
312365          "swid": {
312366            "attachment": {}
312367          },
312368          "pedigree": {},
312369          "evidence": {},
312370          "signature": {
312371            "signature": {
312372              "publicKey": {}
312373            }
312374          },
312375          "modelCard": {
312376            "modelParameters": {
312377              "approach": {}
312378            },
312379            "quantitativeAnalysis": {
312380              "graphics": {}
312381            },
312382            "considerations": {}
312383          }
312384        },
312385        {
312386          "type": "library",
312387          "bom-ref": "pkg:npm/color-name@1.1.3?package-id=36c508d3e88fcfb9",
312388          "supplier": {},
312389          "name": "color-name",
312390          "version": "1.1.3",
312391          "licenses": [
312392            {
312393              "license": {
312394                "id": "MIT"
312395              }
312396            }
312397          ],
312398          "cpe": "cpe:2.3:a:color-name:color-name:1.1.3:*:*:*:*:*:*:*",
312399          "purl": "pkg:npm/color-name@1.1.3",
312400          "swid": {
312401            "attachment": {}
312402          },
312403          "pedigree": {},
312404          "evidence": {},
312405          "signature": {
312406            "signature": {
312407              "publicKey": {}
312408            }
312409          },
312410          "modelCard": {
312411            "modelParameters": {
312412              "approach": {}
312413            },
312414            "quantitativeAnalysis": {
312415              "graphics": {}
312416            },
312417            "considerations": {}
312418          }
312419        },
312420        {
312421          "type": "library",
312422          "bom-ref": "pkg:npm/color-string@1.5.3?package-id=f1bffe86f07267f6",
312423          "supplier": {},
312424          "name": "color-string",
312425          "version": "1.5.3",
312426          "licenses": [
312427            {
312428              "license": {
312429                "id": "MIT"
312430              }
312431            }
312432          ],
312433          "cpe": "cpe:2.3:a:color-string:color-string:1.5.3:*:*:*:*:*:*:*",
312434          "purl": "pkg:npm/color-string@1.5.3",
312435          "swid": {
312436            "attachment": {}
312437          },
312438          "pedigree": {},
312439          "evidence": {},
312440          "signature": {
312441            "signature": {
312442              "publicKey": {}
312443            }
312444          },
312445          "modelCard": {
312446            "modelParameters": {
312447              "approach": {}
312448            },
312449            "quantitativeAnalysis": {
312450              "graphics": {}
312451            },
312452            "considerations": {}
312453          }
312454        },
312455        {
312456          "type": "library",
312457          "bom-ref": "pkg:npm/colors@1.1.2?package-id=27061b1e60d90c86",
312458          "supplier": {},
312459          "name": "colors",
312460          "version": "1.1.2",
312461          "licenses": [
312462            {
312463              "license": {
312464                "id": "MIT"
312465              }
312466            }
312467          ],
312468          "cpe": "cpe:2.3:a:colors:colors:1.1.2:*:*:*:*:*:*:*",
312469          "purl": "pkg:npm/colors@1.1.2",
312470          "swid": {
312471            "attachment": {}
312472          },
312473          "pedigree": {},
312474          "evidence": {},
312475          "signature": {
312476            "signature": {
312477              "publicKey": {}
312478            }
312479          },
312480          "modelCard": {
312481            "modelParameters": {
312482              "approach": {}
312483            },
312484            "quantitativeAnalysis": {
312485              "graphics": {}
312486            },
312487            "considerations": {}
312488          }
312489        },
312490        {
312491          "type": "library",
312492          "bom-ref": "pkg:npm/combined-stream@1.0.8?package-id=4f057a90b0a5913d",
312493          "supplier": {},
312494          "name": "combined-stream",
312495          "version": "1.0.8",
312496          "licenses": [
312497            {
312498              "license": {
312499                "id": "MIT"
312500              }
312501            }
312502          ],
312503          "cpe": "cpe:2.3:a:combined-stream:combined-stream:1.0.8:*:*:*:*:*:*:*",
312504          "purl": "pkg:npm/combined-stream@1.0.8",
312505          "swid": {
312506            "attachment": {}
312507          },
312508          "pedigree": {},
312509          "evidence": {},
312510          "signature": {
312511            "signature": {
312512              "publicKey": {}
312513            }
312514          },
312515          "modelCard": {
312516            "modelParameters": {
312517              "approach": {}
312518            },
312519            "quantitativeAnalysis": {
312520              "graphics": {}
312521            },
312522            "considerations": {}
312523          }
312524        },
312525        {
312526          "type": "library",
312527          "bom-ref": "pkg:npm/commander@2.20.3?package-id=c0490df2a859f33d",
312528          "supplier": {},
312529          "name": "commander",
312530          "version": "2.20.3",
312531          "licenses": [
312532            {
312533              "license": {
312534                "id": "MIT"
312535              }
312536            }
312537          ],
312538          "cpe": "cpe:2.3:a:commander:commander:2.20.3:*:*:*:*:*:*:*",
312539          "purl": "pkg:npm/commander@2.20.3",
312540          "swid": {
312541            "attachment": {}
312542          },
312543          "pedigree": {},
312544          "evidence": {},
312545          "signature": {
312546            "signature": {
312547              "publicKey": {}
312548            }
312549          },
312550          "modelCard": {
312551            "modelParameters": {
312552              "approach": {}
312553            },
312554            "quantitativeAnalysis": {
312555              "graphics": {}
312556            },
312557            "considerations": {}
312558          }
312559        },
312560        {
312561          "type": "library",
312562          "bom-ref": "pkg:npm/commondir@1.0.1?package-id=816b0223f83c2662",
312563          "supplier": {},
312564          "name": "commondir",
312565          "version": "1.0.1",
312566          "cpe": "cpe:2.3:a:commondir:commondir:1.0.1:*:*:*:*:*:*:*",
312567          "purl": "pkg:npm/commondir@1.0.1",
312568          "swid": {
312569            "attachment": {}
312570          },
312571          "pedigree": {},
312572          "evidence": {},
312573          "signature": {
312574            "signature": {
312575              "publicKey": {}
312576            }
312577          },
312578          "modelCard": {
312579            "modelParameters": {
312580              "approach": {}
312581            },
312582            "quantitativeAnalysis": {
312583              "graphics": {}
312584            },
312585            "considerations": {}
312586          }
312587        },
312588        {
312589          "type": "library",
312590          "bom-ref": "pkg:npm/commondir@1.0.1?package-id=7c31acee47c7da35",
312591          "supplier": {},
312592          "name": "commondir",
312593          "version": "1.0.1",
312594          "licenses": [
312595            {
312596              "license": {
312597                "id": "MIT"
312598              }
312599            }
312600          ],
312601          "cpe": "cpe:2.3:a:commondir:commondir:1.0.1:*:*:*:*:*:*:*",
312602          "purl": "pkg:npm/commondir@1.0.1",
312603          "swid": {
312604            "attachment": {}
312605          },
312606          "pedigree": {},
312607          "evidence": {},
312608          "signature": {
312609            "signature": {
312610              "publicKey": {}
312611            }
312612          },
312613          "modelCard": {
312614            "modelParameters": {
312615              "approach": {}
312616            },
312617            "quantitativeAnalysis": {
312618              "graphics": {}
312619            },
312620            "considerations": {}
312621          }
312622        },
312623        {
312624          "type": "library",
312625          "bom-ref": "pkg:npm/compare-versions@3.6.0?package-id=7669949217bc386b",
312626          "supplier": {},
312627          "name": "compare-versions",
312628          "version": "3.6.0",
312629          "licenses": [
312630            {
312631              "license": {
312632                "id": "MIT"
312633              }
312634            }
312635          ],
312636          "cpe": "cpe:2.3:a:compare-versions:compare-versions:3.6.0:*:*:*:*:*:*:*",
312637          "purl": "pkg:npm/compare-versions@3.6.0",
312638          "swid": {
312639            "attachment": {}
312640          },
312641          "pedigree": {},
312642          "evidence": {},
312643          "signature": {
312644            "signature": {
312645              "publicKey": {}
312646            }
312647          },
312648          "modelCard": {
312649            "modelParameters": {
312650              "approach": {}
312651            },
312652            "quantitativeAnalysis": {
312653              "graphics": {}
312654            },
312655            "considerations": {}
312656          }
312657        },
312658        {
312659          "type": "library",
312660          "bom-ref": "pkg:npm/component-bind@1.0.0?package-id=a60bb99a503c2d00",
312661          "supplier": {},
312662          "name": "component-bind",
312663          "version": "1.0.0",
312664          "cpe": "cpe:2.3:a:component-bind:component-bind:1.0.0:*:*:*:*:*:*:*",
312665          "purl": "pkg:npm/component-bind@1.0.0",
312666          "swid": {
312667            "attachment": {}
312668          },
312669          "pedigree": {},
312670          "evidence": {},
312671          "signature": {
312672            "signature": {
312673              "publicKey": {}
312674            }
312675          },
312676          "modelCard": {
312677            "modelParameters": {
312678              "approach": {}
312679            },
312680            "quantitativeAnalysis": {
312681              "graphics": {}
312682            },
312683            "considerations": {}
312684          }
312685        },
312686        {
312687          "type": "library",
312688          "bom-ref": "pkg:npm/component-emitter@1.3.0?package-id=7b1497dc9da9601f",
312689          "supplier": {},
312690          "name": "component-emitter",
312691          "version": "1.3.0",
312692          "licenses": [
312693            {
312694              "license": {
312695                "id": "MIT"
312696              }
312697            }
312698          ],
312699          "cpe": "cpe:2.3:a:component-emitter:component-emitter:1.3.0:*:*:*:*:*:*:*",
312700          "purl": "pkg:npm/component-emitter@1.3.0",
312701          "swid": {
312702            "attachment": {}
312703          },
312704          "pedigree": {},
312705          "evidence": {},
312706          "signature": {
312707            "signature": {
312708              "publicKey": {}
312709            }
312710          },
312711          "modelCard": {
312712            "modelParameters": {
312713              "approach": {}
312714            },
312715            "quantitativeAnalysis": {
312716              "graphics": {}
312717            },
312718            "considerations": {}
312719          }
312720        },
312721        {
312722          "type": "library",
312723          "bom-ref": "pkg:npm/component-inherit@0.0.3?package-id=c83660bba6b0e35a",
312724          "supplier": {},
312725          "name": "component-inherit",
312726          "version": "0.0.3",
312727          "cpe": "cpe:2.3:a:component-inherit:component-inherit:0.0.3:*:*:*:*:*:*:*",
312728          "purl": "pkg:npm/component-inherit@0.0.3",
312729          "swid": {
312730            "attachment": {}
312731          },
312732          "pedigree": {},
312733          "evidence": {},
312734          "signature": {
312735            "signature": {
312736              "publicKey": {}
312737            }
312738          },
312739          "modelCard": {
312740            "modelParameters": {
312741              "approach": {}
312742            },
312743            "quantitativeAnalysis": {
312744              "graphics": {}
312745            },
312746            "considerations": {}
312747          }
312748        },
312749        {
312750          "type": "library",
312751          "bom-ref": "pkg:npm/compressible@2.0.18?package-id=caa8692952611d7c",
312752          "supplier": {},
312753          "name": "compressible",
312754          "version": "2.0.18",
312755          "licenses": [
312756            {
312757              "license": {
312758                "id": "MIT"
312759              }
312760            }
312761          ],
312762          "cpe": "cpe:2.3:a:compressible:compressible:2.0.18:*:*:*:*:*:*:*",
312763          "purl": "pkg:npm/compressible@2.0.18",
312764          "swid": {
312765            "attachment": {}
312766          },
312767          "pedigree": {},
312768          "evidence": {},
312769          "signature": {
312770            "signature": {
312771              "publicKey": {}
312772            }
312773          },
312774          "modelCard": {
312775            "modelParameters": {
312776              "approach": {}
312777            },
312778            "quantitativeAnalysis": {
312779              "graphics": {}
312780            },
312781            "considerations": {}
312782          }
312783        },
312784        {
312785          "type": "library",
312786          "bom-ref": "pkg:npm/compression@1.7.4?package-id=f57461b79ef6469",
312787          "supplier": {},
312788          "name": "compression",
312789          "version": "1.7.4",
312790          "licenses": [
312791            {
312792              "license": {
312793                "id": "MIT"
312794              }
312795            }
312796          ],
312797          "cpe": "cpe:2.3:a:compression:compression:1.7.4:*:*:*:*:*:*:*",
312798          "purl": "pkg:npm/compression@1.7.4",
312799          "swid": {
312800            "attachment": {}
312801          },
312802          "pedigree": {},
312803          "evidence": {},
312804          "signature": {
312805            "signature": {
312806              "publicKey": {}
312807            }
312808          },
312809          "modelCard": {
312810            "modelParameters": {
312811              "approach": {}
312812            },
312813            "quantitativeAnalysis": {
312814              "graphics": {}
312815            },
312816            "considerations": {}
312817          }
312818        },
312819        {
312820          "type": "library",
312821          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=f1b52a2042917070",
312822          "supplier": {},
312823          "name": "concat-map",
312824          "version": "0.0.1",
312825          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
312826          "purl": "pkg:npm/concat-map@0.0.1",
312827          "swid": {
312828            "attachment": {}
312829          },
312830          "pedigree": {},
312831          "evidence": {},
312832          "signature": {
312833            "signature": {
312834              "publicKey": {}
312835            }
312836          },
312837          "modelCard": {
312838            "modelParameters": {
312839              "approach": {}
312840            },
312841            "quantitativeAnalysis": {
312842              "graphics": {}
312843            },
312844            "considerations": {}
312845          }
312846        },
312847        {
312848          "type": "library",
312849          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=f3eceba3e6995ea8",
312850          "supplier": {},
312851          "name": "concat-map",
312852          "version": "0.0.1",
312853          "licenses": [
312854            {
312855              "license": {
312856                "id": "MIT"
312857              }
312858            }
312859          ],
312860          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
312861          "purl": "pkg:npm/concat-map@0.0.1",
312862          "swid": {
312863            "attachment": {}
312864          },
312865          "pedigree": {},
312866          "evidence": {},
312867          "signature": {
312868            "signature": {
312869              "publicKey": {}
312870            }
312871          },
312872          "modelCard": {
312873            "modelParameters": {
312874              "approach": {}
312875            },
312876            "quantitativeAnalysis": {
312877              "graphics": {}
312878            },
312879            "considerations": {}
312880          }
312881        },
312882        {
312883          "type": "library",
312884          "bom-ref": "pkg:npm/concat-stream@1.6.2?package-id=d4a4c77d67e3c278",
312885          "supplier": {},
312886          "name": "concat-stream",
312887          "version": "1.6.2",
312888          "licenses": [
312889            {
312890              "license": {
312891                "id": "MIT"
312892              }
312893            }
312894          ],
312895          "cpe": "cpe:2.3:a:concat-stream:concat-stream:1.6.2:*:*:*:*:*:*:*",
312896          "purl": "pkg:npm/concat-stream@1.6.2",
312897          "swid": {
312898            "attachment": {}
312899          },
312900          "pedigree": {},
312901          "evidence": {},
312902          "signature": {
312903            "signature": {
312904              "publicKey": {}
312905            }
312906          },
312907          "modelCard": {
312908            "modelParameters": {
312909              "approach": {}
312910            },
312911            "quantitativeAnalysis": {
312912              "graphics": {}
312913            },
312914            "considerations": {}
312915          }
312916        },
312917        {
312918          "type": "library",
312919          "bom-ref": "pkg:npm/connect@3.7.0?package-id=d688c922a841a699",
312920          "supplier": {},
312921          "name": "connect",
312922          "version": "3.7.0",
312923          "licenses": [
312924            {
312925              "license": {
312926                "id": "MIT"
312927              }
312928            }
312929          ],
312930          "cpe": "cpe:2.3:a:connect:connect:3.7.0:*:*:*:*:*:*:*",
312931          "purl": "pkg:npm/connect@3.7.0",
312932          "swid": {
312933            "attachment": {}
312934          },
312935          "pedigree": {},
312936          "evidence": {},
312937          "signature": {
312938            "signature": {
312939              "publicKey": {}
312940            }
312941          },
312942          "modelCard": {
312943            "modelParameters": {
312944              "approach": {}
312945            },
312946            "quantitativeAnalysis": {
312947              "graphics": {}
312948            },
312949            "considerations": {}
312950          }
312951        },
312952        {
312953          "type": "library",
312954          "bom-ref": "pkg:npm/connect-history-api-fallback@1.6.0?package-id=d7e7db31f71fae02",
312955          "supplier": {},
312956          "name": "connect-history-api-fallback",
312957          "version": "1.6.0",
312958          "licenses": [
312959            {
312960              "license": {
312961                "id": "MIT"
312962              }
312963            }
312964          ],
312965          "cpe": "cpe:2.3:a:connect-history-api-fallback:connect-history-api-fallback:1.6.0:*:*:*:*:*:*:*",
312966          "purl": "pkg:npm/connect-history-api-fallback@1.6.0",
312967          "swid": {
312968            "attachment": {}
312969          },
312970          "pedigree": {},
312971          "evidence": {},
312972          "signature": {
312973            "signature": {
312974              "publicKey": {}
312975            }
312976          },
312977          "modelCard": {
312978            "modelParameters": {
312979              "approach": {}
312980            },
312981            "quantitativeAnalysis": {
312982              "graphics": {}
312983            },
312984            "considerations": {}
312985          }
312986        },
312987        {
312988          "type": "library",
312989          "bom-ref": "pkg:npm/console-browserify@1.2.0?package-id=532d52f6d8cb48ca",
312990          "supplier": {},
312991          "name": "console-browserify",
312992          "version": "1.2.0",
312993          "licenses": [
312994            {
312995              "license": {
312996                "id": "MIT"
312997              }
312998            }
312999          ],
313000          "cpe": "cpe:2.3:a:console-browserify:console-browserify:1.2.0:*:*:*:*:*:*:*",
313001          "purl": "pkg:npm/console-browserify@1.2.0",
313002          "swid": {
313003            "attachment": {}
313004          },
313005          "pedigree": {},
313006          "evidence": {},
313007          "signature": {
313008            "signature": {
313009              "publicKey": {}
313010            }
313011          },
313012          "modelCard": {
313013            "modelParameters": {
313014              "approach": {}
313015            },
313016            "quantitativeAnalysis": {
313017              "graphics": {}
313018            },
313019            "considerations": {}
313020          }
313021        },
313022        {
313023          "type": "library",
313024          "bom-ref": "pkg:npm/console-control-strings@1.1.0?package-id=e4ee3706312c50a2",
313025          "supplier": {},
313026          "name": "console-control-strings",
313027          "version": "1.1.0",
313028          "licenses": [
313029            {
313030              "license": {
313031                "id": "ISC"
313032              }
313033            }
313034          ],
313035          "cpe": "cpe:2.3:a:console-control-strings:console-control-strings:1.1.0:*:*:*:*:*:*:*",
313036          "purl": "pkg:npm/console-control-strings@1.1.0",
313037          "swid": {
313038            "attachment": {}
313039          },
313040          "pedigree": {},
313041          "evidence": {},
313042          "signature": {
313043            "signature": {
313044              "publicKey": {}
313045            }
313046          },
313047          "modelCard": {
313048            "modelParameters": {
313049              "approach": {}
313050            },
313051            "quantitativeAnalysis": {
313052              "graphics": {}
313053            },
313054            "considerations": {}
313055          }
313056        },
313057        {
313058          "type": "library",
313059          "bom-ref": "pkg:npm/constants-browserify@1.0.0?package-id=edb9e62a33097618",
313060          "supplier": {},
313061          "name": "constants-browserify",
313062          "version": "1.0.0",
313063          "licenses": [
313064            {
313065              "license": {
313066                "id": "MIT"
313067              }
313068            }
313069          ],
313070          "cpe": "cpe:2.3:a:constants-browserify:constants-browserify:1.0.0:*:*:*:*:*:*:*",
313071          "purl": "pkg:npm/constants-browserify@1.0.0",
313072          "swid": {
313073            "attachment": {}
313074          },
313075          "pedigree": {},
313076          "evidence": {},
313077          "signature": {
313078            "signature": {
313079              "publicKey": {}
313080            }
313081          },
313082          "modelCard": {
313083            "modelParameters": {
313084              "approach": {}
313085            },
313086            "quantitativeAnalysis": {
313087              "graphics": {}
313088            },
313089            "considerations": {}
313090          }
313091        },
313092        {
313093          "type": "library",
313094          "bom-ref": "pkg:npm/content-disposition@0.5.3?package-id=4a154cdcf7cd9b04",
313095          "supplier": {},
313096          "name": "content-disposition",
313097          "version": "0.5.3",
313098          "licenses": [
313099            {
313100              "license": {
313101                "id": "MIT"
313102              }
313103            }
313104          ],
313105          "cpe": "cpe:2.3:a:content-disposition:content-disposition:0.5.3:*:*:*:*:*:*:*",
313106          "purl": "pkg:npm/content-disposition@0.5.3",
313107          "swid": {
313108            "attachment": {}
313109          },
313110          "pedigree": {},
313111          "evidence": {},
313112          "signature": {
313113            "signature": {
313114              "publicKey": {}
313115            }
313116          },
313117          "modelCard": {
313118            "modelParameters": {
313119              "approach": {}
313120            },
313121            "quantitativeAnalysis": {
313122              "graphics": {}
313123            },
313124            "considerations": {}
313125          }
313126        },
313127        {
313128          "type": "library",
313129          "bom-ref": "pkg:npm/content-type@1.0.4?package-id=3e3158d7ba5f8373",
313130          "supplier": {},
313131          "name": "content-type",
313132          "version": "1.0.4",
313133          "licenses": [
313134            {
313135              "license": {
313136                "id": "MIT"
313137              }
313138            }
313139          ],
313140          "cpe": "cpe:2.3:a:content-type:content-type:1.0.4:*:*:*:*:*:*:*",
313141          "purl": "pkg:npm/content-type@1.0.4",
313142          "swid": {
313143            "attachment": {}
313144          },
313145          "pedigree": {},
313146          "evidence": {},
313147          "signature": {
313148            "signature": {
313149              "publicKey": {}
313150            }
313151          },
313152          "modelCard": {
313153            "modelParameters": {
313154              "approach": {}
313155            },
313156            "quantitativeAnalysis": {
313157              "graphics": {}
313158            },
313159            "considerations": {}
313160          }
313161        },
313162        {
313163          "type": "library",
313164          "bom-ref": "pkg:npm/convert-source-map@1.7.0?package-id=94f7b0511bd71d81",
313165          "supplier": {},
313166          "name": "convert-source-map",
313167          "version": "1.7.0",
313168          "licenses": [
313169            {
313170              "license": {
313171                "id": "MIT"
313172              }
313173            }
313174          ],
313175          "cpe": "cpe:2.3:a:convert-source-map:convert-source-map:1.7.0:*:*:*:*:*:*:*",
313176          "purl": "pkg:npm/convert-source-map@1.7.0",
313177          "swid": {
313178            "attachment": {}
313179          },
313180          "pedigree": {},
313181          "evidence": {},
313182          "signature": {
313183            "signature": {
313184              "publicKey": {}
313185            }
313186          },
313187          "modelCard": {
313188            "modelParameters": {
313189              "approach": {}
313190            },
313191            "quantitativeAnalysis": {
313192              "graphics": {}
313193            },
313194            "considerations": {}
313195          }
313196        },
313197        {
313198          "type": "library",
313199          "bom-ref": "pkg:npm/convert-source-map@1.8.0?package-id=6cfef4cc1e75765d",
313200          "supplier": {},
313201          "name": "convert-source-map",
313202          "version": "1.8.0",
313203          "cpe": "cpe:2.3:a:convert-source-map:convert-source-map:1.8.0:*:*:*:*:*:*:*",
313204          "purl": "pkg:npm/convert-source-map@1.8.0",
313205          "swid": {
313206            "attachment": {}
313207          },
313208          "pedigree": {},
313209          "evidence": {},
313210          "signature": {
313211            "signature": {
313212              "publicKey": {}
313213            }
313214          },
313215          "modelCard": {
313216            "modelParameters": {
313217              "approach": {}
313218            },
313219            "quantitativeAnalysis": {
313220              "graphics": {}
313221            },
313222            "considerations": {}
313223          }
313224        },
313225        {
313226          "type": "library",
313227          "bom-ref": "pkg:npm/cookie@0.4.0?package-id=846d28d1845728ce",
313228          "supplier": {},
313229          "name": "cookie",
313230          "version": "0.4.0",
313231          "licenses": [
313232            {
313233              "license": {
313234                "id": "MIT"
313235              }
313236            }
313237          ],
313238          "cpe": "cpe:2.3:a:cookie:cookie:0.4.0:*:*:*:*:*:*:*",
313239          "purl": "pkg:npm/cookie@0.4.0",
313240          "swid": {
313241            "attachment": {}
313242          },
313243          "pedigree": {},
313244          "evidence": {},
313245          "signature": {
313246            "signature": {
313247              "publicKey": {}
313248            }
313249          },
313250          "modelCard": {
313251            "modelParameters": {
313252              "approach": {}
313253            },
313254            "quantitativeAnalysis": {
313255              "graphics": {}
313256            },
313257            "considerations": {}
313258          }
313259        },
313260        {
313261          "type": "library",
313262          "bom-ref": "pkg:npm/cookie-signature@1.0.6?package-id=d495cd881cb3ef03",
313263          "supplier": {},
313264          "name": "cookie-signature",
313265          "version": "1.0.6",
313266          "licenses": [
313267            {
313268              "license": {
313269                "id": "MIT"
313270              }
313271            }
313272          ],
313273          "cpe": "cpe:2.3:a:cookie-signature:cookie-signature:1.0.6:*:*:*:*:*:*:*",
313274          "purl": "pkg:npm/cookie-signature@1.0.6",
313275          "swid": {
313276            "attachment": {}
313277          },
313278          "pedigree": {},
313279          "evidence": {},
313280          "signature": {
313281            "signature": {
313282              "publicKey": {}
313283            }
313284          },
313285          "modelCard": {
313286            "modelParameters": {
313287              "approach": {}
313288            },
313289            "quantitativeAnalysis": {
313290              "graphics": {}
313291            },
313292            "considerations": {}
313293          }
313294        },
313295        {
313296          "type": "library",
313297          "bom-ref": "pkg:npm/copy-concurrently@1.0.5?package-id=110b50014bbf7c92",
313298          "supplier": {},
313299          "name": "copy-concurrently",
313300          "version": "1.0.5",
313301          "licenses": [
313302            {
313303              "license": {
313304                "id": "ISC"
313305              }
313306            }
313307          ],
313308          "cpe": "cpe:2.3:a:copy-concurrently:copy-concurrently:1.0.5:*:*:*:*:*:*:*",
313309          "purl": "pkg:npm/copy-concurrently@1.0.5",
313310          "swid": {
313311            "attachment": {}
313312          },
313313          "pedigree": {},
313314          "evidence": {},
313315          "signature": {
313316            "signature": {
313317              "publicKey": {}
313318            }
313319          },
313320          "modelCard": {
313321            "modelParameters": {
313322              "approach": {}
313323            },
313324            "quantitativeAnalysis": {
313325              "graphics": {}
313326            },
313327            "considerations": {}
313328          }
313329        },
313330        {
313331          "type": "library",
313332          "bom-ref": "pkg:npm/copy-descriptor@0.1.1?package-id=3670e211c7526458",
313333          "supplier": {},
313334          "name": "copy-descriptor",
313335          "version": "0.1.1",
313336          "licenses": [
313337            {
313338              "license": {
313339                "id": "MIT"
313340              }
313341            }
313342          ],
313343          "cpe": "cpe:2.3:a:copy-descriptor:copy-descriptor:0.1.1:*:*:*:*:*:*:*",
313344          "purl": "pkg:npm/copy-descriptor@0.1.1",
313345          "swid": {
313346            "attachment": {}
313347          },
313348          "pedigree": {},
313349          "evidence": {},
313350          "signature": {
313351            "signature": {
313352              "publicKey": {}
313353            }
313354          },
313355          "modelCard": {
313356            "modelParameters": {
313357              "approach": {}
313358            },
313359            "quantitativeAnalysis": {
313360              "graphics": {}
313361            },
313362            "considerations": {}
313363          }
313364        },
313365        {
313366          "type": "library",
313367          "bom-ref": "pkg:npm/copy-webpack-plugin@5.1.1?package-id=20a05d97aa06c648",
313368          "supplier": {},
313369          "name": "copy-webpack-plugin",
313370          "version": "5.1.1",
313371          "licenses": [
313372            {
313373              "license": {
313374                "id": "MIT"
313375              }
313376            }
313377          ],
313378          "cpe": "cpe:2.3:a:copy-webpack-plugin:copy-webpack-plugin:5.1.1:*:*:*:*:*:*:*",
313379          "purl": "pkg:npm/copy-webpack-plugin@5.1.1",
313380          "swid": {
313381            "attachment": {}
313382          },
313383          "pedigree": {},
313384          "evidence": {},
313385          "signature": {
313386            "signature": {
313387              "publicKey": {}
313388            }
313389          },
313390          "modelCard": {
313391            "modelParameters": {
313392              "approach": {}
313393            },
313394            "quantitativeAnalysis": {
313395              "graphics": {}
313396            },
313397            "considerations": {}
313398          }
313399        },
313400        {
313401          "type": "library",
313402          "bom-ref": "pkg:npm/core-js@3.6.4?package-id=cf79aa4bc063539",
313403          "supplier": {},
313404          "name": "core-js",
313405          "version": "3.6.4",
313406          "licenses": [
313407            {
313408              "license": {
313409                "id": "MIT"
313410              }
313411            }
313412          ],
313413          "cpe": "cpe:2.3:a:core-js:core-js:3.6.4:*:*:*:*:*:*:*",
313414          "purl": "pkg:npm/core-js@3.6.4",
313415          "swid": {
313416            "attachment": {}
313417          },
313418          "pedigree": {},
313419          "evidence": {},
313420          "signature": {
313421            "signature": {
313422              "publicKey": {}
313423            }
313424          },
313425          "modelCard": {
313426            "modelParameters": {
313427              "approach": {}
313428            },
313429            "quantitativeAnalysis": {
313430              "graphics": {}
313431            },
313432            "considerations": {}
313433          }
313434        },
313435        {
313436          "type": "library",
313437          "bom-ref": "pkg:npm/core-js-compat@3.6.5?package-id=4b744c0f8168f279",
313438          "supplier": {},
313439          "name": "core-js-compat",
313440          "version": "3.6.5",
313441          "licenses": [
313442            {
313443              "license": {
313444                "id": "MIT"
313445              }
313446            }
313447          ],
313448          "cpe": "cpe:2.3:a:core-js-compat:core-js-compat:3.6.5:*:*:*:*:*:*:*",
313449          "purl": "pkg:npm/core-js-compat@3.6.5",
313450          "swid": {
313451            "attachment": {}
313452          },
313453          "pedigree": {},
313454          "evidence": {},
313455          "signature": {
313456            "signature": {
313457              "publicKey": {}
313458            }
313459          },
313460          "modelCard": {
313461            "modelParameters": {
313462              "approach": {}
313463            },
313464            "quantitativeAnalysis": {
313465              "graphics": {}
313466            },
313467            "considerations": {}
313468          }
313469        },
313470        {
313471          "type": "library",
313472          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=fec8addd97f2c2cb",
313473          "supplier": {},
313474          "name": "core-util-is",
313475          "version": "1.0.2",
313476          "licenses": [
313477            {
313478              "license": {
313479                "id": "MIT"
313480              }
313481            }
313482          ],
313483          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
313484          "purl": "pkg:npm/core-util-is@1.0.2",
313485          "swid": {
313486            "attachment": {}
313487          },
313488          "pedigree": {},
313489          "evidence": {},
313490          "signature": {
313491            "signature": {
313492              "publicKey": {}
313493            }
313494          },
313495          "modelCard": {
313496            "modelParameters": {
313497              "approach": {}
313498            },
313499            "quantitativeAnalysis": {
313500              "graphics": {}
313501            },
313502            "considerations": {}
313503          }
313504        },
313505        {
313506          "type": "library",
313507          "bom-ref": "pkg:npm/cosmiconfig@5.2.1?package-id=f1527290c145a017",
313508          "supplier": {},
313509          "name": "cosmiconfig",
313510          "version": "5.2.1",
313511          "licenses": [
313512            {
313513              "license": {
313514                "id": "MIT"
313515              }
313516            }
313517          ],
313518          "cpe": "cpe:2.3:a:cosmiconfig:cosmiconfig:5.2.1:*:*:*:*:*:*:*",
313519          "purl": "pkg:npm/cosmiconfig@5.2.1",
313520          "swid": {
313521            "attachment": {}
313522          },
313523          "pedigree": {},
313524          "evidence": {},
313525          "signature": {
313526            "signature": {
313527              "publicKey": {}
313528            }
313529          },
313530          "modelCard": {
313531            "modelParameters": {
313532              "approach": {}
313533            },
313534            "quantitativeAnalysis": {
313535              "graphics": {}
313536            },
313537            "considerations": {}
313538          }
313539        },
313540        {
313541          "type": "library",
313542          "bom-ref": "pkg:npm/create-ecdh@4.0.3?package-id=a9f5ea69374b87",
313543          "supplier": {},
313544          "name": "create-ecdh",
313545          "version": "4.0.3",
313546          "licenses": [
313547            {
313548              "license": {
313549                "id": "MIT"
313550              }
313551            }
313552          ],
313553          "cpe": "cpe:2.3:a:create-ecdh:create-ecdh:4.0.3:*:*:*:*:*:*:*",
313554          "purl": "pkg:npm/create-ecdh@4.0.3",
313555          "swid": {
313556            "attachment": {}
313557          },
313558          "pedigree": {},
313559          "evidence": {},
313560          "signature": {
313561            "signature": {
313562              "publicKey": {}
313563            }
313564          },
313565          "modelCard": {
313566            "modelParameters": {
313567              "approach": {}
313568            },
313569            "quantitativeAnalysis": {
313570              "graphics": {}
313571            },
313572            "considerations": {}
313573          }
313574        },
313575        {
313576          "type": "library",
313577          "bom-ref": "pkg:npm/create-hash@1.2.0?package-id=5e8b0d75b591418c",
313578          "supplier": {},
313579          "name": "create-hash",
313580          "version": "1.2.0",
313581          "licenses": [
313582            {
313583              "license": {
313584                "id": "MIT"
313585              }
313586            }
313587          ],
313588          "cpe": "cpe:2.3:a:create-hash:create-hash:1.2.0:*:*:*:*:*:*:*",
313589          "purl": "pkg:npm/create-hash@1.2.0",
313590          "swid": {
313591            "attachment": {}
313592          },
313593          "pedigree": {},
313594          "evidence": {},
313595          "signature": {
313596            "signature": {
313597              "publicKey": {}
313598            }
313599          },
313600          "modelCard": {
313601            "modelParameters": {
313602              "approach": {}
313603            },
313604            "quantitativeAnalysis": {
313605              "graphics": {}
313606            },
313607            "considerations": {}
313608          }
313609        },
313610        {
313611          "type": "library",
313612          "bom-ref": "pkg:npm/create-hmac@1.1.7?package-id=7616d38c185d49b1",
313613          "supplier": {},
313614          "name": "create-hmac",
313615          "version": "1.1.7",
313616          "licenses": [
313617            {
313618              "license": {
313619                "id": "MIT"
313620              }
313621            }
313622          ],
313623          "cpe": "cpe:2.3:a:create-hmac:create-hmac:1.1.7:*:*:*:*:*:*:*",
313624          "purl": "pkg:npm/create-hmac@1.1.7",
313625          "swid": {
313626            "attachment": {}
313627          },
313628          "pedigree": {},
313629          "evidence": {},
313630          "signature": {
313631            "signature": {
313632              "publicKey": {}
313633            }
313634          },
313635          "modelCard": {
313636            "modelParameters": {
313637              "approach": {}
313638            },
313639            "quantitativeAnalysis": {
313640              "graphics": {}
313641            },
313642            "considerations": {}
313643          }
313644        },
313645        {
313646          "type": "library",
313647          "bom-ref": "pkg:npm/cross-spawn@6.0.5?package-id=fdb0d03f4cf3e137",
313648          "supplier": {},
313649          "name": "cross-spawn",
313650          "version": "6.0.5",
313651          "licenses": [
313652            {
313653              "license": {
313654                "id": "MIT"
313655              }
313656            }
313657          ],
313658          "cpe": "cpe:2.3:a:cross-spawn:cross-spawn:6.0.5:*:*:*:*:*:*:*",
313659          "purl": "pkg:npm/cross-spawn@6.0.5",
313660          "swid": {
313661            "attachment": {}
313662          },
313663          "pedigree": {},
313664          "evidence": {},
313665          "signature": {
313666            "signature": {
313667              "publicKey": {}
313668            }
313669          },
313670          "modelCard": {
313671            "modelParameters": {
313672              "approach": {}
313673            },
313674            "quantitativeAnalysis": {
313675              "graphics": {}
313676            },
313677            "considerations": {}
313678          }
313679        },
313680        {
313681          "type": "library",
313682          "bom-ref": "pkg:npm/cross-spawn@7.0.3?package-id=674d42754b5110d5",
313683          "supplier": {},
313684          "name": "cross-spawn",
313685          "version": "7.0.3",
313686          "cpe": "cpe:2.3:a:cross-spawn:cross-spawn:7.0.3:*:*:*:*:*:*:*",
313687          "purl": "pkg:npm/cross-spawn@7.0.3",
313688          "swid": {
313689            "attachment": {}
313690          },
313691          "pedigree": {},
313692          "evidence": {},
313693          "signature": {
313694            "signature": {
313695              "publicKey": {}
313696            }
313697          },
313698          "modelCard": {
313699            "modelParameters": {
313700              "approach": {}
313701            },
313702            "quantitativeAnalysis": {
313703              "graphics": {}
313704            },
313705            "considerations": {}
313706          }
313707        },
313708        {
313709          "type": "library",
313710          "bom-ref": "pkg:npm/crypt@0.0.2?package-id=a6a288ec635fa3ed",
313711          "supplier": {},
313712          "name": "crypt",
313713          "version": "0.0.2",
313714          "licenses": [
313715            {
313716              "license": {
313717                "id": "BSD-3-Clause"
313718              }
313719            }
313720          ],
313721          "cpe": "cpe:2.3:a:crypt:crypt:0.0.2:*:*:*:*:*:*:*",
313722          "purl": "pkg:npm/crypt@0.0.2",
313723          "swid": {
313724            "attachment": {}
313725          },
313726          "pedigree": {},
313727          "evidence": {},
313728          "signature": {
313729            "signature": {
313730              "publicKey": {}
313731            }
313732          },
313733          "modelCard": {
313734            "modelParameters": {
313735              "approach": {}
313736            },
313737            "quantitativeAnalysis": {
313738              "graphics": {}
313739            },
313740            "considerations": {}
313741          }
313742        },
313743        {
313744          "type": "library",
313745          "bom-ref": "pkg:npm/crypto-browserify@3.12.0?package-id=af91b20de638212b",
313746          "supplier": {},
313747          "name": "crypto-browserify",
313748          "version": "3.12.0",
313749          "licenses": [
313750            {
313751              "license": {
313752                "id": "MIT"
313753              }
313754            }
313755          ],
313756          "cpe": "cpe:2.3:a:crypto-browserify:crypto-browserify:3.12.0:*:*:*:*:*:*:*",
313757          "purl": "pkg:npm/crypto-browserify@3.12.0",
313758          "swid": {
313759            "attachment": {}
313760          },
313761          "pedigree": {},
313762          "evidence": {},
313763          "signature": {
313764            "signature": {
313765              "publicKey": {}
313766            }
313767          },
313768          "modelCard": {
313769            "modelParameters": {
313770              "approach": {}
313771            },
313772            "quantitativeAnalysis": {
313773              "graphics": {}
313774            },
313775            "considerations": {}
313776          }
313777        },
313778        {
313779          "type": "library",
313780          "bom-ref": "pkg:npm/css@2.2.4?package-id=4c03350ae514a59c",
313781          "supplier": {},
313782          "name": "css",
313783          "version": "2.2.4",
313784          "licenses": [
313785            {
313786              "license": {
313787                "id": "MIT"
313788              }
313789            }
313790          ],
313791          "cpe": "cpe:2.3:a:css:css:2.2.4:*:*:*:*:*:*:*",
313792          "purl": "pkg:npm/css@2.2.4",
313793          "swid": {
313794            "attachment": {}
313795          },
313796          "pedigree": {},
313797          "evidence": {},
313798          "signature": {
313799            "signature": {
313800              "publicKey": {}
313801            }
313802          },
313803          "modelCard": {
313804            "modelParameters": {
313805              "approach": {}
313806            },
313807            "quantitativeAnalysis": {
313808              "graphics": {}
313809            },
313810            "considerations": {}
313811          }
313812        },
313813        {
313814          "type": "library",
313815          "bom-ref": "pkg:npm/css-color-names@0.0.4?package-id=4cd56214e48c9b6a",
313816          "supplier": {},
313817          "name": "css-color-names",
313818          "version": "0.0.4",
313819          "licenses": [
313820            {
313821              "license": {
313822                "id": "MIT"
313823              }
313824            }
313825          ],
313826          "cpe": "cpe:2.3:a:css-color-names:css-color-names:0.0.4:*:*:*:*:*:*:*",
313827          "purl": "pkg:npm/css-color-names@0.0.4",
313828          "swid": {
313829            "attachment": {}
313830          },
313831          "pedigree": {},
313832          "evidence": {},
313833          "signature": {
313834            "signature": {
313835              "publicKey": {}
313836            }
313837          },
313838          "modelCard": {
313839            "modelParameters": {
313840              "approach": {}
313841            },
313842            "quantitativeAnalysis": {
313843              "graphics": {}
313844            },
313845            "considerations": {}
313846          }
313847        },
313848        {
313849          "type": "library",
313850          "bom-ref": "pkg:npm/css-declaration-sorter@4.0.1?package-id=59352d9a807ac137",
313851          "supplier": {},
313852          "name": "css-declaration-sorter",
313853          "version": "4.0.1",
313854          "licenses": [
313855            {
313856              "license": {
313857                "id": "MIT"
313858              }
313859            }
313860          ],
313861          "cpe": "cpe:2.3:a:css-declaration-sorter:css-declaration-sorter:4.0.1:*:*:*:*:*:*:*",
313862          "purl": "pkg:npm/css-declaration-sorter@4.0.1",
313863          "swid": {
313864            "attachment": {}
313865          },
313866          "pedigree": {},
313867          "evidence": {},
313868          "signature": {
313869            "signature": {
313870              "publicKey": {}
313871            }
313872          },
313873          "modelCard": {
313874            "modelParameters": {
313875              "approach": {}
313876            },
313877            "quantitativeAnalysis": {
313878              "graphics": {}
313879            },
313880            "considerations": {}
313881          }
313882        },
313883        {
313884          "type": "library",
313885          "bom-ref": "pkg:npm/css-element-queries@1.2.3?package-id=fb23e05eccf328f9",
313886          "supplier": {},
313887          "name": "css-element-queries",
313888          "version": "1.2.3",
313889          "licenses": [
313890            {
313891              "license": {
313892                "id": "MIT"
313893              }
313894            }
313895          ],
313896          "cpe": "cpe:2.3:a:css-element-queries:css-element-queries:1.2.3:*:*:*:*:*:*:*",
313897          "purl": "pkg:npm/css-element-queries@1.2.3",
313898          "swid": {
313899            "attachment": {}
313900          },
313901          "pedigree": {},
313902          "evidence": {},
313903          "signature": {
313904            "signature": {
313905              "publicKey": {}
313906            }
313907          },
313908          "modelCard": {
313909            "modelParameters": {
313910              "approach": {}
313911            },
313912            "quantitativeAnalysis": {
313913              "graphics": {}
313914            },
313915            "considerations": {}
313916          }
313917        },
313918        {
313919          "type": "library",
313920          "bom-ref": "pkg:npm/css-loader@3.5.1?package-id=f20acf9477799bcd",
313921          "supplier": {},
313922          "name": "css-loader",
313923          "version": "3.5.1",
313924          "licenses": [
313925            {
313926              "license": {
313927                "id": "MIT"
313928              }
313929            }
313930          ],
313931          "cpe": "cpe:2.3:a:css-loader:css-loader:3.5.1:*:*:*:*:*:*:*",
313932          "purl": "pkg:npm/css-loader@3.5.1",
313933          "swid": {
313934            "attachment": {}
313935          },
313936          "pedigree": {},
313937          "evidence": {},
313938          "signature": {
313939            "signature": {
313940              "publicKey": {}
313941            }
313942          },
313943          "modelCard": {
313944            "modelParameters": {
313945              "approach": {}
313946            },
313947            "quantitativeAnalysis": {
313948              "graphics": {}
313949            },
313950            "considerations": {}
313951          }
313952        },
313953        {
313954          "type": "library",
313955          "bom-ref": "pkg:npm/css-parse@2.0.0?package-id=bf81cf827c2318ad",
313956          "supplier": {},
313957          "name": "css-parse",
313958          "version": "2.0.0",
313959          "licenses": [
313960            {
313961              "license": {
313962                "id": "MIT"
313963              }
313964            }
313965          ],
313966          "cpe": "cpe:2.3:a:css-parse:css-parse:2.0.0:*:*:*:*:*:*:*",
313967          "purl": "pkg:npm/css-parse@2.0.0",
313968          "swid": {
313969            "attachment": {}
313970          },
313971          "pedigree": {},
313972          "evidence": {},
313973          "signature": {
313974            "signature": {
313975              "publicKey": {}
313976            }
313977          },
313978          "modelCard": {
313979            "modelParameters": {
313980              "approach": {}
313981            },
313982            "quantitativeAnalysis": {
313983              "graphics": {}
313984            },
313985            "considerations": {}
313986          }
313987        },
313988        {
313989          "type": "library",
313990          "bom-ref": "pkg:npm/css-select@2.1.0?package-id=cd663b0f2aa105e0",
313991          "supplier": {},
313992          "name": "css-select",
313993          "version": "2.1.0",
313994          "licenses": [
313995            {
313996              "license": {
313997                "id": "BSD-2-Clause"
313998              }
313999            }
314000          ],
314001          "cpe": "cpe:2.3:a:css-select:css-select:2.1.0:*:*:*:*:*:*:*",
314002          "purl": "pkg:npm/css-select@2.1.0",
314003          "swid": {
314004            "attachment": {}
314005          },
314006          "pedigree": {},
314007          "evidence": {},
314008          "signature": {
314009            "signature": {
314010              "publicKey": {}
314011            }
314012          },
314013          "modelCard": {
314014            "modelParameters": {
314015              "approach": {}
314016            },
314017            "quantitativeAnalysis": {
314018              "graphics": {}
314019            },
314020            "considerations": {}
314021          }
314022        },
314023        {
314024          "type": "library",
314025          "bom-ref": "pkg:npm/css-select-base-adapter@0.1.1?package-id=34effe5a909bce28",
314026          "supplier": {},
314027          "name": "css-select-base-adapter",
314028          "version": "0.1.1",
314029          "licenses": [
314030            {
314031              "license": {
314032                "id": "MIT"
314033              }
314034            }
314035          ],
314036          "cpe": "cpe:2.3:a:css-select-base-adapter:css-select-base-adapter:0.1.1:*:*:*:*:*:*:*",
314037          "purl": "pkg:npm/css-select-base-adapter@0.1.1",
314038          "swid": {
314039            "attachment": {}
314040          },
314041          "pedigree": {},
314042          "evidence": {},
314043          "signature": {
314044            "signature": {
314045              "publicKey": {}
314046            }
314047          },
314048          "modelCard": {
314049            "modelParameters": {
314050              "approach": {}
314051            },
314052            "quantitativeAnalysis": {
314053              "graphics": {}
314054            },
314055            "considerations": {}
314056          }
314057        },
314058        {
314059          "type": "library",
314060          "bom-ref": "pkg:npm/css-selector-tokenizer@0.7.2?package-id=55657b36ca9122b5",
314061          "supplier": {},
314062          "name": "css-selector-tokenizer",
314063          "version": "0.7.2",
314064          "licenses": [
314065            {
314066              "license": {
314067                "id": "MIT"
314068              }
314069            }
314070          ],
314071          "cpe": "cpe:2.3:a:css-selector-tokenizer:css-selector-tokenizer:0.7.2:*:*:*:*:*:*:*",
314072          "purl": "pkg:npm/css-selector-tokenizer@0.7.2",
314073          "swid": {
314074            "attachment": {}
314075          },
314076          "pedigree": {},
314077          "evidence": {},
314078          "signature": {
314079            "signature": {
314080              "publicKey": {}
314081            }
314082          },
314083          "modelCard": {
314084            "modelParameters": {
314085              "approach": {}
314086            },
314087            "quantitativeAnalysis": {
314088              "graphics": {}
314089            },
314090            "considerations": {}
314091          }
314092        },
314093        {
314094          "type": "library",
314095          "bom-ref": "pkg:npm/css-tree@1.0.0-alpha.37?package-id=70617fa4e3e6e5f3",
314096          "supplier": {},
314097          "name": "css-tree",
314098          "version": "1.0.0-alpha.37",
314099          "licenses": [
314100            {
314101              "license": {
314102                "id": "MIT"
314103              }
314104            }
314105          ],
314106          "cpe": "cpe:2.3:a:css-tree:css-tree:1.0.0-alpha.37:*:*:*:*:*:*:*",
314107          "purl": "pkg:npm/css-tree@1.0.0-alpha.37",
314108          "swid": {
314109            "attachment": {}
314110          },
314111          "pedigree": {},
314112          "evidence": {},
314113          "signature": {
314114            "signature": {
314115              "publicKey": {}
314116            }
314117          },
314118          "modelCard": {
314119            "modelParameters": {
314120              "approach": {}
314121            },
314122            "quantitativeAnalysis": {
314123              "graphics": {}
314124            },
314125            "considerations": {}
314126          }
314127        },
314128        {
314129          "type": "library",
314130          "bom-ref": "pkg:npm/css-what@3.2.1?package-id=dff3098a88407f33",
314131          "supplier": {},
314132          "name": "css-what",
314133          "version": "3.2.1",
314134          "licenses": [
314135            {
314136              "license": {
314137                "id": "BSD-2-Clause"
314138              }
314139            }
314140          ],
314141          "cpe": "cpe:2.3:a:css-what:css-what:3.2.1:*:*:*:*:*:*:*",
314142          "purl": "pkg:npm/css-what@3.2.1",
314143          "swid": {
314144            "attachment": {}
314145          },
314146          "pedigree": {},
314147          "evidence": {},
314148          "signature": {
314149            "signature": {
314150              "publicKey": {}
314151            }
314152          },
314153          "modelCard": {
314154            "modelParameters": {
314155              "approach": {}
314156            },
314157            "quantitativeAnalysis": {
314158              "graphics": {}
314159            },
314160            "considerations": {}
314161          }
314162        },
314163        {
314164          "type": "library",
314165          "bom-ref": "pkg:npm/cssauron@1.4.0?package-id=6ff6719f92ab448d",
314166          "supplier": {},
314167          "name": "cssauron",
314168          "version": "1.4.0",
314169          "licenses": [
314170            {
314171              "license": {
314172                "id": "MIT"
314173              }
314174            }
314175          ],
314176          "cpe": "cpe:2.3:a:cssauron:cssauron:1.4.0:*:*:*:*:*:*:*",
314177          "purl": "pkg:npm/cssauron@1.4.0",
314178          "swid": {
314179            "attachment": {}
314180          },
314181          "pedigree": {},
314182          "evidence": {},
314183          "signature": {
314184            "signature": {
314185              "publicKey": {}
314186            }
314187          },
314188          "modelCard": {
314189            "modelParameters": {
314190              "approach": {}
314191            },
314192            "quantitativeAnalysis": {
314193              "graphics": {}
314194            },
314195            "considerations": {}
314196          }
314197        },
314198        {
314199          "type": "library",
314200          "bom-ref": "pkg:npm/cssesc@3.0.0?package-id=b76dcc9aebf0c0d5",
314201          "supplier": {},
314202          "name": "cssesc",
314203          "version": "3.0.0",
314204          "licenses": [
314205            {
314206              "license": {
314207                "id": "MIT"
314208              }
314209            }
314210          ],
314211          "cpe": "cpe:2.3:a:cssesc:cssesc:3.0.0:*:*:*:*:*:*:*",
314212          "purl": "pkg:npm/cssesc@3.0.0",
314213          "swid": {
314214            "attachment": {}
314215          },
314216          "pedigree": {},
314217          "evidence": {},
314218          "signature": {
314219            "signature": {
314220              "publicKey": {}
314221            }
314222          },
314223          "modelCard": {
314224            "modelParameters": {
314225              "approach": {}
314226            },
314227            "quantitativeAnalysis": {
314228              "graphics": {}
314229            },
314230            "considerations": {}
314231          }
314232        },
314233        {
314234          "type": "library",
314235          "bom-ref": "pkg:npm/cssnano@4.1.10?package-id=caaf6969fb878f7c",
314236          "supplier": {},
314237          "name": "cssnano",
314238          "version": "4.1.10",
314239          "licenses": [
314240            {
314241              "license": {
314242                "id": "MIT"
314243              }
314244            }
314245          ],
314246          "cpe": "cpe:2.3:a:cssnano:cssnano:4.1.10:*:*:*:*:*:*:*",
314247          "purl": "pkg:npm/cssnano@4.1.10",
314248          "swid": {
314249            "attachment": {}
314250          },
314251          "pedigree": {},
314252          "evidence": {},
314253          "signature": {
314254            "signature": {
314255              "publicKey": {}
314256            }
314257          },
314258          "modelCard": {
314259            "modelParameters": {
314260              "approach": {}
314261            },
314262            "quantitativeAnalysis": {
314263              "graphics": {}
314264            },
314265            "considerations": {}
314266          }
314267        },
314268        {
314269          "type": "library",
314270          "bom-ref": "pkg:npm/cssnano-preset-default@4.0.7?package-id=be907e42a89f3447",
314271          "supplier": {},
314272          "name": "cssnano-preset-default",
314273          "version": "4.0.7",
314274          "licenses": [
314275            {
314276              "license": {
314277                "id": "MIT"
314278              }
314279            }
314280          ],
314281          "cpe": "cpe:2.3:a:cssnano-preset-default:cssnano-preset-default:4.0.7:*:*:*:*:*:*:*",
314282          "purl": "pkg:npm/cssnano-preset-default@4.0.7",
314283          "swid": {
314284            "attachment": {}
314285          },
314286          "pedigree": {},
314287          "evidence": {},
314288          "signature": {
314289            "signature": {
314290              "publicKey": {}
314291            }
314292          },
314293          "modelCard": {
314294            "modelParameters": {
314295              "approach": {}
314296            },
314297            "quantitativeAnalysis": {
314298              "graphics": {}
314299            },
314300            "considerations": {}
314301          }
314302        },
314303        {
314304          "type": "library",
314305          "bom-ref": "pkg:npm/cssnano-util-get-arguments@4.0.0?package-id=8fa35af14f3decd6",
314306          "supplier": {},
314307          "name": "cssnano-util-get-arguments",
314308          "version": "4.0.0",
314309          "licenses": [
314310            {
314311              "license": {
314312                "id": "MIT"
314313              }
314314            }
314315          ],
314316          "cpe": "cpe:2.3:a:cssnano-util-get-arguments:cssnano-util-get-arguments:4.0.0:*:*:*:*:*:*:*",
314317          "purl": "pkg:npm/cssnano-util-get-arguments@4.0.0",
314318          "swid": {
314319            "attachment": {}
314320          },
314321          "pedigree": {},
314322          "evidence": {},
314323          "signature": {
314324            "signature": {
314325              "publicKey": {}
314326            }
314327          },
314328          "modelCard": {
314329            "modelParameters": {
314330              "approach": {}
314331            },
314332            "quantitativeAnalysis": {
314333              "graphics": {}
314334            },
314335            "considerations": {}
314336          }
314337        },
314338        {
314339          "type": "library",
314340          "bom-ref": "pkg:npm/cssnano-util-get-match@4.0.0?package-id=94a2880738865b06",
314341          "supplier": {},
314342          "name": "cssnano-util-get-match",
314343          "version": "4.0.0",
314344          "licenses": [
314345            {
314346              "license": {
314347                "id": "MIT"
314348              }
314349            }
314350          ],
314351          "cpe": "cpe:2.3:a:cssnano-util-get-match:cssnano-util-get-match:4.0.0:*:*:*:*:*:*:*",
314352          "purl": "pkg:npm/cssnano-util-get-match@4.0.0",
314353          "swid": {
314354            "attachment": {}
314355          },
314356          "pedigree": {},
314357          "evidence": {},
314358          "signature": {
314359            "signature": {
314360              "publicKey": {}
314361            }
314362          },
314363          "modelCard": {
314364            "modelParameters": {
314365              "approach": {}
314366            },
314367            "quantitativeAnalysis": {
314368              "graphics": {}
314369            },
314370            "considerations": {}
314371          }
314372        },
314373        {
314374          "type": "library",
314375          "bom-ref": "pkg:npm/cssnano-util-raw-cache@4.0.1?package-id=5f36e95f93f994ec",
314376          "supplier": {},
314377          "name": "cssnano-util-raw-cache",
314378          "version": "4.0.1",
314379          "licenses": [
314380            {
314381              "license": {
314382                "id": "MIT"
314383              }
314384            }
314385          ],
314386          "cpe": "cpe:2.3:a:cssnano-util-raw-cache:cssnano-util-raw-cache:4.0.1:*:*:*:*:*:*:*",
314387          "purl": "pkg:npm/cssnano-util-raw-cache@4.0.1",
314388          "swid": {
314389            "attachment": {}
314390          },
314391          "pedigree": {},
314392          "evidence": {},
314393          "signature": {
314394            "signature": {
314395              "publicKey": {}
314396            }
314397          },
314398          "modelCard": {
314399            "modelParameters": {
314400              "approach": {}
314401            },
314402            "quantitativeAnalysis": {
314403              "graphics": {}
314404            },
314405            "considerations": {}
314406          }
314407        },
314408        {
314409          "type": "library",
314410          "bom-ref": "pkg:npm/cssnano-util-same-parent@4.0.1?package-id=5efd4653c64ff25c",
314411          "supplier": {},
314412          "name": "cssnano-util-same-parent",
314413          "version": "4.0.1",
314414          "licenses": [
314415            {
314416              "license": {
314417                "id": "MIT"
314418              }
314419            }
314420          ],
314421          "cpe": "cpe:2.3:a:cssnano-util-same-parent:cssnano-util-same-parent:4.0.1:*:*:*:*:*:*:*",
314422          "purl": "pkg:npm/cssnano-util-same-parent@4.0.1",
314423          "swid": {
314424            "attachment": {}
314425          },
314426          "pedigree": {},
314427          "evidence": {},
314428          "signature": {
314429            "signature": {
314430              "publicKey": {}
314431            }
314432          },
314433          "modelCard": {
314434            "modelParameters": {
314435              "approach": {}
314436            },
314437            "quantitativeAnalysis": {
314438              "graphics": {}
314439            },
314440            "considerations": {}
314441          }
314442        },
314443        {
314444          "type": "library",
314445          "bom-ref": "pkg:npm/csso@4.0.3?package-id=febf0756ad53b944",
314446          "supplier": {},
314447          "name": "csso",
314448          "version": "4.0.3",
314449          "licenses": [
314450            {
314451              "license": {
314452                "id": "MIT"
314453              }
314454            }
314455          ],
314456          "cpe": "cpe:2.3:a:csso:csso:4.0.3:*:*:*:*:*:*:*",
314457          "purl": "pkg:npm/csso@4.0.3",
314458          "swid": {
314459            "attachment": {}
314460          },
314461          "pedigree": {},
314462          "evidence": {},
314463          "signature": {
314464            "signature": {
314465              "publicKey": {}
314466            }
314467          },
314468          "modelCard": {
314469            "modelParameters": {
314470              "approach": {}
314471            },
314472            "quantitativeAnalysis": {
314473              "graphics": {}
314474            },
314475            "considerations": {}
314476          }
314477        },
314478        {
314479          "type": "library",
314480          "bom-ref": "pkg:npm/currently-unhandled@0.4.1?package-id=6d59e825ee212ea",
314481          "supplier": {},
314482          "name": "currently-unhandled",
314483          "version": "0.4.1",
314484          "licenses": [
314485            {
314486              "license": {
314487                "id": "MIT"
314488              }
314489            }
314490          ],
314491          "cpe": "cpe:2.3:a:currently-unhandled:currently-unhandled:0.4.1:*:*:*:*:*:*:*",
314492          "purl": "pkg:npm/currently-unhandled@0.4.1",
314493          "swid": {
314494            "attachment": {}
314495          },
314496          "pedigree": {},
314497          "evidence": {},
314498          "signature": {
314499            "signature": {
314500              "publicKey": {}
314501            }
314502          },
314503          "modelCard": {
314504            "modelParameters": {
314505              "approach": {}
314506            },
314507            "quantitativeAnalysis": {
314508              "graphics": {}
314509            },
314510            "considerations": {}
314511          }
314512        },
314513        {
314514          "type": "library",
314515          "bom-ref": "pkg:npm/custom-event@1.0.1?package-id=b717896396fb7012",
314516          "supplier": {},
314517          "name": "custom-event",
314518          "version": "1.0.1",
314519          "licenses": [
314520            {
314521              "license": {
314522                "id": "MIT"
314523              }
314524            }
314525          ],
314526          "cpe": "cpe:2.3:a:custom-event:custom-event:1.0.1:*:*:*:*:*:*:*",
314527          "purl": "pkg:npm/custom-event@1.0.1",
314528          "swid": {
314529            "attachment": {}
314530          },
314531          "pedigree": {},
314532          "evidence": {},
314533          "signature": {
314534            "signature": {
314535              "publicKey": {}
314536            }
314537          },
314538          "modelCard": {
314539            "modelParameters": {
314540              "approach": {}
314541            },
314542            "quantitativeAnalysis": {
314543              "graphics": {}
314544            },
314545            "considerations": {}
314546          }
314547        },
314548        {
314549          "type": "library",
314550          "bom-ref": "pkg:npm/cyclist@1.0.1?package-id=b0a95cc6aff92d21",
314551          "supplier": {},
314552          "name": "cyclist",
314553          "version": "1.0.1",
314554          "licenses": [
314555            {
314556              "license": {
314557                "id": "MIT"
314558              }
314559            }
314560          ],
314561          "cpe": "cpe:2.3:a:cyclist:cyclist:1.0.1:*:*:*:*:*:*:*",
314562          "purl": "pkg:npm/cyclist@1.0.1",
314563          "swid": {
314564            "attachment": {}
314565          },
314566          "pedigree": {},
314567          "evidence": {},
314568          "signature": {
314569            "signature": {
314570              "publicKey": {}
314571            }
314572          },
314573          "modelCard": {
314574            "modelParameters": {
314575              "approach": {}
314576            },
314577            "quantitativeAnalysis": {
314578              "graphics": {}
314579            },
314580            "considerations": {}
314581          }
314582        },
314583        {
314584          "type": "library",
314585          "bom-ref": "pkg:npm/d@1.0.1?package-id=855e26b4f7bf1b8f",
314586          "supplier": {},
314587          "name": "d",
314588          "version": "1.0.1",
314589          "licenses": [
314590            {
314591              "license": {
314592                "id": "ISC"
314593              }
314594            }
314595          ],
314596          "cpe": "cpe:2.3:a:d:d:1.0.1:*:*:*:*:*:*:*",
314597          "purl": "pkg:npm/d@1.0.1",
314598          "swid": {
314599            "attachment": {}
314600          },
314601          "pedigree": {},
314602          "evidence": {},
314603          "signature": {
314604            "signature": {
314605              "publicKey": {}
314606            }
314607          },
314608          "modelCard": {
314609            "modelParameters": {
314610              "approach": {}
314611            },
314612            "quantitativeAnalysis": {
314613              "graphics": {}
314614            },
314615            "considerations": {}
314616          }
314617        },
314618        {
314619          "type": "library",
314620          "bom-ref": "pkg:npm/d3-path@1.0.9?package-id=6b08e966eddca93c",
314621          "supplier": {},
314622          "name": "d3-path",
314623          "version": "1.0.9",
314624          "licenses": [
314625            {
314626              "license": {
314627                "id": "BSD-3-Clause"
314628              }
314629            }
314630          ],
314631          "cpe": "cpe:2.3:a:d3-path:d3-path:1.0.9:*:*:*:*:*:*:*",
314632          "purl": "pkg:npm/d3-path@1.0.9",
314633          "swid": {
314634            "attachment": {}
314635          },
314636          "pedigree": {},
314637          "evidence": {},
314638          "signature": {
314639            "signature": {
314640              "publicKey": {}
314641            }
314642          },
314643          "modelCard": {
314644            "modelParameters": {
314645              "approach": {}
314646            },
314647            "quantitativeAnalysis": {
314648              "graphics": {}
314649            },
314650            "considerations": {}
314651          }
314652        },
314653        {
314654          "type": "library",
314655          "bom-ref": "pkg:npm/d3-shape@1.3.7?package-id=afc0f695a91a4aaf",
314656          "supplier": {},
314657          "name": "d3-shape",
314658          "version": "1.3.7",
314659          "licenses": [
314660            {
314661              "license": {
314662                "id": "BSD-3-Clause"
314663              }
314664            }
314665          ],
314666          "cpe": "cpe:2.3:a:d3-shape:d3-shape:1.3.7:*:*:*:*:*:*:*",
314667          "purl": "pkg:npm/d3-shape@1.3.7",
314668          "swid": {
314669            "attachment": {}
314670          },
314671          "pedigree": {},
314672          "evidence": {},
314673          "signature": {
314674            "signature": {
314675              "publicKey": {}
314676            }
314677          },
314678          "modelCard": {
314679            "modelParameters": {
314680              "approach": {}
314681            },
314682            "quantitativeAnalysis": {
314683              "graphics": {}
314684            },
314685            "considerations": {}
314686          }
314687        },
314688        {
314689          "type": "library",
314690          "bom-ref": "pkg:npm/dag-map@1.0.2?package-id=6b3923fe0906da31",
314691          "supplier": {},
314692          "name": "dag-map",
314693          "version": "1.0.2",
314694          "licenses": [
314695            {
314696              "license": {
314697                "id": "MIT"
314698              }
314699            }
314700          ],
314701          "cpe": "cpe:2.3:a:dag-map:dag-map:1.0.2:*:*:*:*:*:*:*",
314702          "purl": "pkg:npm/dag-map@1.0.2",
314703          "swid": {
314704            "attachment": {}
314705          },
314706          "pedigree": {},
314707          "evidence": {},
314708          "signature": {
314709            "signature": {
314710              "publicKey": {}
314711            }
314712          },
314713          "modelCard": {
314714            "modelParameters": {
314715              "approach": {}
314716            },
314717            "quantitativeAnalysis": {
314718              "graphics": {}
314719            },
314720            "considerations": {}
314721          }
314722        },
314723        {
314724          "type": "library",
314725          "bom-ref": "pkg:npm/damerau-levenshtein@1.0.6?package-id=61ac5a4d259bb92f",
314726          "supplier": {},
314727          "name": "damerau-levenshtein",
314728          "version": "1.0.6",
314729          "licenses": [
314730            {
314731              "license": {
314732                "id": "BSD-2-Clause"
314733              }
314734            }
314735          ],
314736          "cpe": "cpe:2.3:a:damerau-levenshtein:damerau-levenshtein:1.0.6:*:*:*:*:*:*:*",
314737          "purl": "pkg:npm/damerau-levenshtein@1.0.6",
314738          "swid": {
314739            "attachment": {}
314740          },
314741          "pedigree": {},
314742          "evidence": {},
314743          "signature": {
314744            "signature": {
314745              "publicKey": {}
314746            }
314747          },
314748          "modelCard": {
314749            "modelParameters": {
314750              "approach": {}
314751            },
314752            "quantitativeAnalysis": {
314753              "graphics": {}
314754            },
314755            "considerations": {}
314756          }
314757        },
314758        {
314759          "type": "library",
314760          "bom-ref": "pkg:npm/dashdash@1.14.1?package-id=1f0eeaff816ac0ca",
314761          "supplier": {},
314762          "name": "dashdash",
314763          "version": "1.14.1",
314764          "licenses": [
314765            {
314766              "license": {
314767                "id": "MIT"
314768              }
314769            }
314770          ],
314771          "cpe": "cpe:2.3:a:dashdash:dashdash:1.14.1:*:*:*:*:*:*:*",
314772          "purl": "pkg:npm/dashdash@1.14.1",
314773          "swid": {
314774            "attachment": {}
314775          },
314776          "pedigree": {},
314777          "evidence": {},
314778          "signature": {
314779            "signature": {
314780              "publicKey": {}
314781            }
314782          },
314783          "modelCard": {
314784            "modelParameters": {
314785              "approach": {}
314786            },
314787            "quantitativeAnalysis": {
314788              "graphics": {}
314789            },
314790            "considerations": {}
314791          }
314792        },
314793        {
314794          "type": "library",
314795          "bom-ref": "pkg:npm/date-format@2.1.0?package-id=3d142a66a7a87fc6",
314796          "supplier": {},
314797          "name": "date-format",
314798          "version": "2.1.0",
314799          "licenses": [
314800            {
314801              "license": {
314802                "id": "MIT"
314803              }
314804            }
314805          ],
314806          "cpe": "cpe:2.3:a:date-format:date-format:2.1.0:*:*:*:*:*:*:*",
314807          "purl": "pkg:npm/date-format@2.1.0",
314808          "swid": {
314809            "attachment": {}
314810          },
314811          "pedigree": {},
314812          "evidence": {},
314813          "signature": {
314814            "signature": {
314815              "publicKey": {}
314816            }
314817          },
314818          "modelCard": {
314819            "modelParameters": {
314820              "approach": {}
314821            },
314822            "quantitativeAnalysis": {
314823              "graphics": {}
314824            },
314825            "considerations": {}
314826          }
314827        },
314828        {
314829          "type": "library",
314830          "bom-ref": "pkg:npm/debug@4.1.1?package-id=49f5d7f2b31ffc47",
314831          "supplier": {},
314832          "name": "debug",
314833          "version": "4.1.1",
314834          "licenses": [
314835            {
314836              "license": {
314837                "id": "MIT"
314838              }
314839            }
314840          ],
314841          "cpe": "cpe:2.3:a:debug:debug:4.1.1:*:*:*:*:*:*:*",
314842          "purl": "pkg:npm/debug@4.1.1",
314843          "swid": {
314844            "attachment": {}
314845          },
314846          "pedigree": {},
314847          "evidence": {},
314848          "signature": {
314849            "signature": {
314850              "publicKey": {}
314851            }
314852          },
314853          "modelCard": {
314854            "modelParameters": {
314855              "approach": {}
314856            },
314857            "quantitativeAnalysis": {
314858              "graphics": {}
314859            },
314860            "considerations": {}
314861          }
314862        },
314863        {
314864          "type": "library",
314865          "bom-ref": "pkg:npm/debug@4.3.3?package-id=45a3f504c622be2b",
314866          "supplier": {},
314867          "name": "debug",
314868          "version": "4.3.3",
314869          "cpe": "cpe:2.3:a:debug:debug:4.3.3:*:*:*:*:*:*:*",
314870          "purl": "pkg:npm/debug@4.3.3",
314871          "swid": {
314872            "attachment": {}
314873          },
314874          "pedigree": {},
314875          "evidence": {},
314876          "signature": {
314877            "signature": {
314878              "publicKey": {}
314879            }
314880          },
314881          "modelCard": {
314882            "modelParameters": {
314883              "approach": {}
314884            },
314885            "quantitativeAnalysis": {
314886              "graphics": {}
314887            },
314888            "considerations": {}
314889          }
314890        },
314891        {
314892          "type": "library",
314893          "bom-ref": "pkg:npm/debuglog@1.0.1?package-id=448a1fd2691c167",
314894          "supplier": {},
314895          "name": "debuglog",
314896          "version": "1.0.1",
314897          "licenses": [
314898            {
314899              "license": {
314900                "id": "MIT"
314901              }
314902            }
314903          ],
314904          "cpe": "cpe:2.3:a:debuglog:debuglog:1.0.1:*:*:*:*:*:*:*",
314905          "purl": "pkg:npm/debuglog@1.0.1",
314906          "swid": {
314907            "attachment": {}
314908          },
314909          "pedigree": {},
314910          "evidence": {},
314911          "signature": {
314912            "signature": {
314913              "publicKey": {}
314914            }
314915          },
314916          "modelCard": {
314917            "modelParameters": {
314918              "approach": {}
314919            },
314920            "quantitativeAnalysis": {
314921              "graphics": {}
314922            },
314923            "considerations": {}
314924          }
314925        },
314926        {
314927          "type": "library",
314928          "bom-ref": "pkg:npm/decamelize@1.2.0?package-id=2bda384177a425a1",
314929          "supplier": {},
314930          "name": "decamelize",
314931          "version": "1.2.0",
314932          "cpe": "cpe:2.3:a:decamelize:decamelize:1.2.0:*:*:*:*:*:*:*",
314933          "purl": "pkg:npm/decamelize@1.2.0",
314934          "swid": {
314935            "attachment": {}
314936          },
314937          "pedigree": {},
314938          "evidence": {},
314939          "signature": {
314940            "signature": {
314941              "publicKey": {}
314942            }
314943          },
314944          "modelCard": {
314945            "modelParameters": {
314946              "approach": {}
314947            },
314948            "quantitativeAnalysis": {
314949              "graphics": {}
314950            },
314951            "considerations": {}
314952          }
314953        },
314954        {
314955          "type": "library",
314956          "bom-ref": "pkg:npm/decamelize@1.2.0?package-id=1eaa9b894a49a0df",
314957          "supplier": {},
314958          "name": "decamelize",
314959          "version": "1.2.0",
314960          "licenses": [
314961            {
314962              "license": {
314963                "id": "MIT"
314964              }
314965            }
314966          ],
314967          "cpe": "cpe:2.3:a:decamelize:decamelize:1.2.0:*:*:*:*:*:*:*",
314968          "purl": "pkg:npm/decamelize@1.2.0",
314969          "swid": {
314970            "attachment": {}
314971          },
314972          "pedigree": {},
314973          "evidence": {},
314974          "signature": {
314975            "signature": {
314976              "publicKey": {}
314977            }
314978          },
314979          "modelCard": {
314980            "modelParameters": {
314981              "approach": {}
314982            },
314983            "quantitativeAnalysis": {
314984              "graphics": {}
314985            },
314986            "considerations": {}
314987          }
314988        },
314989        {
314990          "type": "library",
314991          "bom-ref": "pkg:npm/decode-uri-component@0.2.0?package-id=bb3b2583ac1a0d4",
314992          "supplier": {},
314993          "name": "decode-uri-component",
314994          "version": "0.2.0",
314995          "licenses": [
314996            {
314997              "license": {
314998                "id": "MIT"
314999              }
315000            }
315001          ],
315002          "cpe": "cpe:2.3:a:decode-uri-component:decode-uri-component:0.2.0:*:*:*:*:*:*:*",
315003          "purl": "pkg:npm/decode-uri-component@0.2.0",
315004          "swid": {
315005            "attachment": {}
315006          },
315007          "pedigree": {},
315008          "evidence": {},
315009          "signature": {
315010            "signature": {
315011              "publicKey": {}
315012            }
315013          },
315014          "modelCard": {
315015            "modelParameters": {
315016              "approach": {}
315017            },
315018            "quantitativeAnalysis": {
315019              "graphics": {}
315020            },
315021            "considerations": {}
315022          }
315023        },
315024        {
315025          "type": "library",
315026          "bom-ref": "pkg:npm/deep-diff@1.0.2?package-id=1cb29cd8c59af1ca",
315027          "supplier": {},
315028          "name": "deep-diff",
315029          "version": "1.0.2",
315030          "licenses": [
315031            {
315032              "license": {
315033                "id": "MIT"
315034              }
315035            }
315036          ],
315037          "cpe": "cpe:2.3:a:deep-diff:deep-diff:1.0.2:*:*:*:*:*:*:*",
315038          "purl": "pkg:npm/deep-diff@1.0.2",
315039          "swid": {
315040            "attachment": {}
315041          },
315042          "pedigree": {},
315043          "evidence": {},
315044          "signature": {
315045            "signature": {
315046              "publicKey": {}
315047            }
315048          },
315049          "modelCard": {
315050            "modelParameters": {
315051              "approach": {}
315052            },
315053            "quantitativeAnalysis": {
315054              "graphics": {}
315055            },
315056            "considerations": {}
315057          }
315058        },
315059        {
315060          "type": "library",
315061          "bom-ref": "pkg:npm/deep-equal@1.1.1?package-id=56f0c403ce52752d",
315062          "supplier": {},
315063          "name": "deep-equal",
315064          "version": "1.1.1",
315065          "licenses": [
315066            {
315067              "license": {
315068                "id": "MIT"
315069              }
315070            }
315071          ],
315072          "cpe": "cpe:2.3:a:deep-equal:deep-equal:1.1.1:*:*:*:*:*:*:*",
315073          "purl": "pkg:npm/deep-equal@1.1.1",
315074          "swid": {
315075            "attachment": {}
315076          },
315077          "pedigree": {},
315078          "evidence": {},
315079          "signature": {
315080            "signature": {
315081              "publicKey": {}
315082            }
315083          },
315084          "modelCard": {
315085            "modelParameters": {
315086              "approach": {}
315087            },
315088            "quantitativeAnalysis": {
315089              "graphics": {}
315090            },
315091            "considerations": {}
315092          }
315093        },
315094        {
315095          "type": "library",
315096          "bom-ref": "pkg:npm/default-gateway@4.2.0?package-id=c7c731640fb2aec0",
315097          "supplier": {},
315098          "name": "default-gateway",
315099          "version": "4.2.0",
315100          "licenses": [
315101            {
315102              "license": {
315103                "id": "BSD-2-Clause"
315104              }
315105            }
315106          ],
315107          "cpe": "cpe:2.3:a:default-gateway:default-gateway:4.2.0:*:*:*:*:*:*:*",
315108          "purl": "pkg:npm/default-gateway@4.2.0",
315109          "swid": {
315110            "attachment": {}
315111          },
315112          "pedigree": {},
315113          "evidence": {},
315114          "signature": {
315115            "signature": {
315116              "publicKey": {}
315117            }
315118          },
315119          "modelCard": {
315120            "modelParameters": {
315121              "approach": {}
315122            },
315123            "quantitativeAnalysis": {
315124              "graphics": {}
315125            },
315126            "considerations": {}
315127          }
315128        },
315129        {
315130          "type": "library",
315131          "bom-ref": "pkg:npm/default-require-extensions@2.0.0?package-id=623c65b6f7d0f65f",
315132          "supplier": {},
315133          "name": "default-require-extensions",
315134          "version": "2.0.0",
315135          "licenses": [
315136            {
315137              "license": {
315138                "id": "MIT"
315139              }
315140            }
315141          ],
315142          "cpe": "cpe:2.3:a:default-require-extensions:default-require-extensions:2.0.0:*:*:*:*:*:*:*",
315143          "purl": "pkg:npm/default-require-extensions@2.0.0",
315144          "swid": {
315145            "attachment": {}
315146          },
315147          "pedigree": {},
315148          "evidence": {},
315149          "signature": {
315150            "signature": {
315151              "publicKey": {}
315152            }
315153          },
315154          "modelCard": {
315155            "modelParameters": {
315156              "approach": {}
315157            },
315158            "quantitativeAnalysis": {
315159              "graphics": {}
315160            },
315161            "considerations": {}
315162          }
315163        },
315164        {
315165          "type": "library",
315166          "bom-ref": "pkg:npm/default-require-extensions@3.0.0?package-id=ebdf1e3d3873440c",
315167          "supplier": {},
315168          "name": "default-require-extensions",
315169          "version": "3.0.0",
315170          "cpe": "cpe:2.3:a:default-require-extensions:default-require-extensions:3.0.0:*:*:*:*:*:*:*",
315171          "purl": "pkg:npm/default-require-extensions@3.0.0",
315172          "swid": {
315173            "attachment": {}
315174          },
315175          "pedigree": {},
315176          "evidence": {},
315177          "signature": {
315178            "signature": {
315179              "publicKey": {}
315180            }
315181          },
315182          "modelCard": {
315183            "modelParameters": {
315184              "approach": {}
315185            },
315186            "quantitativeAnalysis": {
315187              "graphics": {}
315188            },
315189            "considerations": {}
315190          }
315191        },
315192        {
315193          "type": "library",
315194          "bom-ref": "pkg:npm/defaults@1.0.3?package-id=58e23781ef16471b",
315195          "supplier": {},
315196          "name": "defaults",
315197          "version": "1.0.3",
315198          "licenses": [
315199            {
315200              "license": {
315201                "id": "MIT"
315202              }
315203            }
315204          ],
315205          "cpe": "cpe:2.3:a:defaults:defaults:1.0.3:*:*:*:*:*:*:*",
315206          "purl": "pkg:npm/defaults@1.0.3",
315207          "swid": {
315208            "attachment": {}
315209          },
315210          "pedigree": {},
315211          "evidence": {},
315212          "signature": {
315213            "signature": {
315214              "publicKey": {}
315215            }
315216          },
315217          "modelCard": {
315218            "modelParameters": {
315219              "approach": {}
315220            },
315221            "quantitativeAnalysis": {
315222              "graphics": {}
315223            },
315224            "considerations": {}
315225          }
315226        },
315227        {
315228          "type": "library",
315229          "bom-ref": "pkg:npm/define-properties@1.1.3?package-id=f046d30f6116e85d",
315230          "supplier": {},
315231          "name": "define-properties",
315232          "version": "1.1.3",
315233          "licenses": [
315234            {
315235              "license": {
315236                "id": "MIT"
315237              }
315238            }
315239          ],
315240          "cpe": "cpe:2.3:a:define-properties:define-properties:1.1.3:*:*:*:*:*:*:*",
315241          "purl": "pkg:npm/define-properties@1.1.3",
315242          "swid": {
315243            "attachment": {}
315244          },
315245          "pedigree": {},
315246          "evidence": {},
315247          "signature": {
315248            "signature": {
315249              "publicKey": {}
315250            }
315251          },
315252          "modelCard": {
315253            "modelParameters": {
315254              "approach": {}
315255            },
315256            "quantitativeAnalysis": {
315257              "graphics": {}
315258            },
315259            "considerations": {}
315260          }
315261        },
315262        {
315263          "type": "library",
315264          "bom-ref": "pkg:npm/define-property@2.0.2?package-id=15b2391ac9a56b8d",
315265          "supplier": {},
315266          "name": "define-property",
315267          "version": "2.0.2",
315268          "licenses": [
315269            {
315270              "license": {
315271                "id": "MIT"
315272              }
315273            }
315274          ],
315275          "cpe": "cpe:2.3:a:define-property:define-property:2.0.2:*:*:*:*:*:*:*",
315276          "purl": "pkg:npm/define-property@2.0.2",
315277          "swid": {
315278            "attachment": {}
315279          },
315280          "pedigree": {},
315281          "evidence": {},
315282          "signature": {
315283            "signature": {
315284              "publicKey": {}
315285            }
315286          },
315287          "modelCard": {
315288            "modelParameters": {
315289              "approach": {}
315290            },
315291            "quantitativeAnalysis": {
315292              "graphics": {}
315293            },
315294            "considerations": {}
315295          }
315296        },
315297        {
315298          "type": "library",
315299          "bom-ref": "pkg:npm/del@4.1.1?package-id=91a36331fca3031a",
315300          "supplier": {},
315301          "name": "del",
315302          "version": "4.1.1",
315303          "licenses": [
315304            {
315305              "license": {
315306                "id": "MIT"
315307              }
315308            }
315309          ],
315310          "cpe": "cpe:2.3:a:del:del:4.1.1:*:*:*:*:*:*:*",
315311          "purl": "pkg:npm/del@4.1.1",
315312          "swid": {
315313            "attachment": {}
315314          },
315315          "pedigree": {},
315316          "evidence": {},
315317          "signature": {
315318            "signature": {
315319              "publicKey": {}
315320            }
315321          },
315322          "modelCard": {
315323            "modelParameters": {
315324              "approach": {}
315325            },
315326            "quantitativeAnalysis": {
315327              "graphics": {}
315328            },
315329            "considerations": {}
315330          }
315331        },
315332        {
315333          "type": "library",
315334          "bom-ref": "pkg:npm/delayed-stream@1.0.0?package-id=cd45040a62713265",
315335          "supplier": {},
315336          "name": "delayed-stream",
315337          "version": "1.0.0",
315338          "licenses": [
315339            {
315340              "license": {
315341                "id": "MIT"
315342              }
315343            }
315344          ],
315345          "cpe": "cpe:2.3:a:delayed-stream:delayed-stream:1.0.0:*:*:*:*:*:*:*",
315346          "purl": "pkg:npm/delayed-stream@1.0.0",
315347          "swid": {
315348            "attachment": {}
315349          },
315350          "pedigree": {},
315351          "evidence": {},
315352          "signature": {
315353            "signature": {
315354              "publicKey": {}
315355            }
315356          },
315357          "modelCard": {
315358            "modelParameters": {
315359              "approach": {}
315360            },
315361            "quantitativeAnalysis": {
315362              "graphics": {}
315363            },
315364            "considerations": {}
315365          }
315366        },
315367        {
315368          "type": "library",
315369          "bom-ref": "pkg:npm/delegates@1.0.0?package-id=57d2eba423f14db2",
315370          "supplier": {},
315371          "name": "delegates",
315372          "version": "1.0.0",
315373          "licenses": [
315374            {
315375              "license": {
315376                "id": "MIT"
315377              }
315378            }
315379          ],
315380          "cpe": "cpe:2.3:a:delegates:delegates:1.0.0:*:*:*:*:*:*:*",
315381          "purl": "pkg:npm/delegates@1.0.0",
315382          "swid": {
315383            "attachment": {}
315384          },
315385          "pedigree": {},
315386          "evidence": {},
315387          "signature": {
315388            "signature": {
315389              "publicKey": {}
315390            }
315391          },
315392          "modelCard": {
315393            "modelParameters": {
315394              "approach": {}
315395            },
315396            "quantitativeAnalysis": {
315397              "graphics": {}
315398            },
315399            "considerations": {}
315400          }
315401        },
315402        {
315403          "type": "library",
315404          "bom-ref": "pkg:npm/depd@1.1.2?package-id=fd22d7f044ec01be",
315405          "supplier": {},
315406          "name": "depd",
315407          "version": "1.1.2",
315408          "licenses": [
315409            {
315410              "license": {
315411                "id": "MIT"
315412              }
315413            }
315414          ],
315415          "cpe": "cpe:2.3:a:depd:depd:1.1.2:*:*:*:*:*:*:*",
315416          "purl": "pkg:npm/depd@1.1.2",
315417          "swid": {
315418            "attachment": {}
315419          },
315420          "pedigree": {},
315421          "evidence": {},
315422          "signature": {
315423            "signature": {
315424              "publicKey": {}
315425            }
315426          },
315427          "modelCard": {
315428            "modelParameters": {
315429              "approach": {}
315430            },
315431            "quantitativeAnalysis": {
315432              "graphics": {}
315433            },
315434            "considerations": {}
315435          }
315436        },
315437        {
315438          "type": "library",
315439          "bom-ref": "pkg:npm/dependency-graph@0.7.2?package-id=2cee83396f34c102",
315440          "supplier": {},
315441          "name": "dependency-graph",
315442          "version": "0.7.2",
315443          "licenses": [
315444            {
315445              "license": {
315446                "id": "MIT"
315447              }
315448            }
315449          ],
315450          "cpe": "cpe:2.3:a:dependency-graph:dependency-graph:0.7.2:*:*:*:*:*:*:*",
315451          "purl": "pkg:npm/dependency-graph@0.7.2",
315452          "swid": {
315453            "attachment": {}
315454          },
315455          "pedigree": {},
315456          "evidence": {},
315457          "signature": {
315458            "signature": {
315459              "publicKey": {}
315460            }
315461          },
315462          "modelCard": {
315463            "modelParameters": {
315464              "approach": {}
315465            },
315466            "quantitativeAnalysis": {
315467              "graphics": {}
315468            },
315469            "considerations": {}
315470          }
315471        },
315472        {
315473          "type": "library",
315474          "bom-ref": "pkg:npm/des.js@1.0.1?package-id=56a75bd236f4cd3b",
315475          "supplier": {},
315476          "name": "des.js",
315477          "version": "1.0.1",
315478          "licenses": [
315479            {
315480              "license": {
315481                "id": "MIT"
315482              }
315483            }
315484          ],
315485          "cpe": "cpe:2.3:a:des.js:des.js:1.0.1:*:*:*:*:*:*:*",
315486          "purl": "pkg:npm/des.js@1.0.1",
315487          "swid": {
315488            "attachment": {}
315489          },
315490          "pedigree": {},
315491          "evidence": {},
315492          "signature": {
315493            "signature": {
315494              "publicKey": {}
315495            }
315496          },
315497          "modelCard": {
315498            "modelParameters": {
315499              "approach": {}
315500            },
315501            "quantitativeAnalysis": {
315502              "graphics": {}
315503            },
315504            "considerations": {}
315505          }
315506        },
315507        {
315508          "type": "library",
315509          "bom-ref": "pkg:npm/destroy@1.0.4?package-id=85e95adef566650c",
315510          "supplier": {},
315511          "name": "destroy",
315512          "version": "1.0.4",
315513          "licenses": [
315514            {
315515              "license": {
315516                "id": "MIT"
315517              }
315518            }
315519          ],
315520          "cpe": "cpe:2.3:a:destroy:destroy:1.0.4:*:*:*:*:*:*:*",
315521          "purl": "pkg:npm/destroy@1.0.4",
315522          "swid": {
315523            "attachment": {}
315524          },
315525          "pedigree": {},
315526          "evidence": {},
315527          "signature": {
315528            "signature": {
315529              "publicKey": {}
315530            }
315531          },
315532          "modelCard": {
315533            "modelParameters": {
315534              "approach": {}
315535            },
315536            "quantitativeAnalysis": {
315537              "graphics": {}
315538            },
315539            "considerations": {}
315540          }
315541        },
315542        {
315543          "type": "library",
315544          "bom-ref": "pkg:npm/detect-node@2.0.4?package-id=df0beac52d8e4d4c",
315545          "supplier": {},
315546          "name": "detect-node",
315547          "version": "2.0.4",
315548          "licenses": [
315549            {
315550              "license": {
315551                "id": "ISC"
315552              }
315553            }
315554          ],
315555          "cpe": "cpe:2.3:a:detect-node:detect-node:2.0.4:*:*:*:*:*:*:*",
315556          "purl": "pkg:npm/detect-node@2.0.4",
315557          "swid": {
315558            "attachment": {}
315559          },
315560          "pedigree": {},
315561          "evidence": {},
315562          "signature": {
315563            "signature": {
315564              "publicKey": {}
315565            }
315566          },
315567          "modelCard": {
315568            "modelParameters": {
315569              "approach": {}
315570            },
315571            "quantitativeAnalysis": {
315572              "graphics": {}
315573            },
315574            "considerations": {}
315575          }
315576        },
315577        {
315578          "type": "library",
315579          "bom-ref": "pkg:npm/dezalgo@1.0.3?package-id=cc4b56cda913de4d",
315580          "supplier": {},
315581          "name": "dezalgo",
315582          "version": "1.0.3",
315583          "licenses": [
315584            {
315585              "license": {
315586                "id": "ISC"
315587              }
315588            }
315589          ],
315590          "cpe": "cpe:2.3:a:dezalgo:dezalgo:1.0.3:*:*:*:*:*:*:*",
315591          "purl": "pkg:npm/dezalgo@1.0.3",
315592          "swid": {
315593            "attachment": {}
315594          },
315595          "pedigree": {},
315596          "evidence": {},
315597          "signature": {
315598            "signature": {
315599              "publicKey": {}
315600            }
315601          },
315602          "modelCard": {
315603            "modelParameters": {
315604              "approach": {}
315605            },
315606            "quantitativeAnalysis": {
315607              "graphics": {}
315608            },
315609            "considerations": {}
315610          }
315611        },
315612        {
315613          "type": "library",
315614          "bom-ref": "pkg:npm/di@0.0.1?package-id=f6a7d77796f329cb",
315615          "supplier": {},
315616          "name": "di",
315617          "version": "0.0.1",
315618          "licenses": [
315619            {
315620              "license": {
315621                "id": "MIT"
315622              }
315623            }
315624          ],
315625          "cpe": "cpe:2.3:a:di:di:0.0.1:*:*:*:*:*:*:*",
315626          "purl": "pkg:npm/di@0.0.1",
315627          "swid": {
315628            "attachment": {}
315629          },
315630          "pedigree": {},
315631          "evidence": {},
315632          "signature": {
315633            "signature": {
315634              "publicKey": {}
315635            }
315636          },
315637          "modelCard": {
315638            "modelParameters": {
315639              "approach": {}
315640            },
315641            "quantitativeAnalysis": {
315642              "graphics": {}
315643            },
315644            "considerations": {}
315645          }
315646        },
315647        {
315648          "type": "library",
315649          "bom-ref": "pkg:npm/diff@4.0.2?package-id=9c1c0e886cbb9dd8",
315650          "supplier": {},
315651          "name": "diff",
315652          "version": "4.0.2",
315653          "licenses": [
315654            {
315655              "license": {
315656                "id": "BSD-3-Clause"
315657              }
315658            }
315659          ],
315660          "cpe": "cpe:2.3:a:diff:diff:4.0.2:*:*:*:*:*:*:*",
315661          "purl": "pkg:npm/diff@4.0.2",
315662          "swid": {
315663            "attachment": {}
315664          },
315665          "pedigree": {},
315666          "evidence": {},
315667          "signature": {
315668            "signature": {
315669              "publicKey": {}
315670            }
315671          },
315672          "modelCard": {
315673            "modelParameters": {
315674              "approach": {}
315675            },
315676            "quantitativeAnalysis": {
315677              "graphics": {}
315678            },
315679            "considerations": {}
315680          }
315681        },
315682        {
315683          "type": "library",
315684          "bom-ref": "pkg:npm/diffie-hellman@5.0.3?package-id=fa6771ec6a0f956d",
315685          "supplier": {},
315686          "name": "diffie-hellman",
315687          "version": "5.0.3",
315688          "licenses": [
315689            {
315690              "license": {
315691                "id": "MIT"
315692              }
315693            }
315694          ],
315695          "cpe": "cpe:2.3:a:diffie-hellman:diffie-hellman:5.0.3:*:*:*:*:*:*:*",
315696          "purl": "pkg:npm/diffie-hellman@5.0.3",
315697          "swid": {
315698            "attachment": {}
315699          },
315700          "pedigree": {},
315701          "evidence": {},
315702          "signature": {
315703            "signature": {
315704              "publicKey": {}
315705            }
315706          },
315707          "modelCard": {
315708            "modelParameters": {
315709              "approach": {}
315710            },
315711            "quantitativeAnalysis": {
315712              "graphics": {}
315713            },
315714            "considerations": {}
315715          }
315716        },
315717        {
315718          "type": "library",
315719          "bom-ref": "pkg:npm/dir-glob@2.2.2?package-id=109d1efdb00451db",
315720          "supplier": {},
315721          "name": "dir-glob",
315722          "version": "2.2.2",
315723          "licenses": [
315724            {
315725              "license": {
315726                "id": "MIT"
315727              }
315728            }
315729          ],
315730          "cpe": "cpe:2.3:a:dir-glob:dir-glob:2.2.2:*:*:*:*:*:*:*",
315731          "purl": "pkg:npm/dir-glob@2.2.2",
315732          "swid": {
315733            "attachment": {}
315734          },
315735          "pedigree": {},
315736          "evidence": {},
315737          "signature": {
315738            "signature": {
315739              "publicKey": {}
315740            }
315741          },
315742          "modelCard": {
315743            "modelParameters": {
315744              "approach": {}
315745            },
315746            "quantitativeAnalysis": {
315747              "graphics": {}
315748            },
315749            "considerations": {}
315750          }
315751        },
315752        {
315753          "type": "library",
315754          "bom-ref": "pkg:npm/dns-equal@1.0.0?package-id=29454a712931d5f7",
315755          "supplier": {},
315756          "name": "dns-equal",
315757          "version": "1.0.0",
315758          "licenses": [
315759            {
315760              "license": {
315761                "id": "MIT"
315762              }
315763            }
315764          ],
315765          "cpe": "cpe:2.3:a:dns-equal:dns-equal:1.0.0:*:*:*:*:*:*:*",
315766          "purl": "pkg:npm/dns-equal@1.0.0",
315767          "swid": {
315768            "attachment": {}
315769          },
315770          "pedigree": {},
315771          "evidence": {},
315772          "signature": {
315773            "signature": {
315774              "publicKey": {}
315775            }
315776          },
315777          "modelCard": {
315778            "modelParameters": {
315779              "approach": {}
315780            },
315781            "quantitativeAnalysis": {
315782              "graphics": {}
315783            },
315784            "considerations": {}
315785          }
315786        },
315787        {
315788          "type": "library",
315789          "bom-ref": "pkg:npm/dns-packet@1.3.1?package-id=be981317084fc73c",
315790          "supplier": {},
315791          "name": "dns-packet",
315792          "version": "1.3.1",
315793          "licenses": [
315794            {
315795              "license": {
315796                "id": "MIT"
315797              }
315798            }
315799          ],
315800          "cpe": "cpe:2.3:a:dns-packet:dns-packet:1.3.1:*:*:*:*:*:*:*",
315801          "purl": "pkg:npm/dns-packet@1.3.1",
315802          "swid": {
315803            "attachment": {}
315804          },
315805          "pedigree": {},
315806          "evidence": {},
315807          "signature": {
315808            "signature": {
315809              "publicKey": {}
315810            }
315811          },
315812          "modelCard": {
315813            "modelParameters": {
315814              "approach": {}
315815            },
315816            "quantitativeAnalysis": {
315817              "graphics": {}
315818            },
315819            "considerations": {}
315820          }
315821        },
315822        {
315823          "type": "library",
315824          "bom-ref": "pkg:npm/dns-txt@2.0.2?package-id=7a9a696528b7de23",
315825          "supplier": {},
315826          "name": "dns-txt",
315827          "version": "2.0.2",
315828          "licenses": [
315829            {
315830              "license": {
315831                "id": "MIT"
315832              }
315833            }
315834          ],
315835          "cpe": "cpe:2.3:a:dns-txt:dns-txt:2.0.2:*:*:*:*:*:*:*",
315836          "purl": "pkg:npm/dns-txt@2.0.2",
315837          "swid": {
315838            "attachment": {}
315839          },
315840          "pedigree": {},
315841          "evidence": {},
315842          "signature": {
315843            "signature": {
315844              "publicKey": {}
315845            }
315846          },
315847          "modelCard": {
315848            "modelParameters": {
315849              "approach": {}
315850            },
315851            "quantitativeAnalysis": {
315852              "graphics": {}
315853            },
315854            "considerations": {}
315855          }
315856        },
315857        {
315858          "type": "library",
315859          "bom-ref": "pkg:npm/dom-serialize@2.2.1?package-id=8c4b20c40abd0517",
315860          "supplier": {},
315861          "name": "dom-serialize",
315862          "version": "2.2.1",
315863          "licenses": [
315864            {
315865              "license": {
315866                "id": "MIT"
315867              }
315868            }
315869          ],
315870          "cpe": "cpe:2.3:a:dom-serialize:dom-serialize:2.2.1:*:*:*:*:*:*:*",
315871          "purl": "pkg:npm/dom-serialize@2.2.1",
315872          "swid": {
315873            "attachment": {}
315874          },
315875          "pedigree": {},
315876          "evidence": {},
315877          "signature": {
315878            "signature": {
315879              "publicKey": {}
315880            }
315881          },
315882          "modelCard": {
315883            "modelParameters": {
315884              "approach": {}
315885            },
315886            "quantitativeAnalysis": {
315887              "graphics": {}
315888            },
315889            "considerations": {}
315890          }
315891        },
315892        {
315893          "type": "library",
315894          "bom-ref": "pkg:npm/dom-serializer@0.2.2?package-id=ad41dac74f47b2d9",
315895          "supplier": {},
315896          "name": "dom-serializer",
315897          "version": "0.2.2",
315898          "licenses": [
315899            {
315900              "license": {
315901                "id": "MIT"
315902              }
315903            }
315904          ],
315905          "cpe": "cpe:2.3:a:dom-serializer:dom-serializer:0.2.2:*:*:*:*:*:*:*",
315906          "purl": "pkg:npm/dom-serializer@0.2.2",
315907          "swid": {
315908            "attachment": {}
315909          },
315910          "pedigree": {},
315911          "evidence": {},
315912          "signature": {
315913            "signature": {
315914              "publicKey": {}
315915            }
315916          },
315917          "modelCard": {
315918            "modelParameters": {
315919              "approach": {}
315920            },
315921            "quantitativeAnalysis": {
315922              "graphics": {}
315923            },
315924            "considerations": {}
315925          }
315926        },
315927        {
315928          "type": "library",
315929          "bom-ref": "pkg:npm/domain-browser@1.2.0?package-id=92a442a438c3a0d4",
315930          "supplier": {},
315931          "name": "domain-browser",
315932          "version": "1.2.0",
315933          "licenses": [
315934            {
315935              "license": {
315936                "id": "MIT"
315937              }
315938            }
315939          ],
315940          "cpe": "cpe:2.3:a:domain-browser:domain-browser:1.2.0:*:*:*:*:*:*:*",
315941          "purl": "pkg:npm/domain-browser@1.2.0",
315942          "swid": {
315943            "attachment": {}
315944          },
315945          "pedigree": {},
315946          "evidence": {},
315947          "signature": {
315948            "signature": {
315949              "publicKey": {}
315950            }
315951          },
315952          "modelCard": {
315953            "modelParameters": {
315954              "approach": {}
315955            },
315956            "quantitativeAnalysis": {
315957              "graphics": {}
315958            },
315959            "considerations": {}
315960          }
315961        },
315962        {
315963          "type": "library",
315964          "bom-ref": "pkg:npm/domelementtype@1.3.1?package-id=79ee616135962fa1",
315965          "supplier": {},
315966          "name": "domelementtype",
315967          "version": "1.3.1",
315968          "licenses": [
315969            {
315970              "license": {
315971                "id": "BSD-2-Clause"
315972              }
315973            }
315974          ],
315975          "cpe": "cpe:2.3:a:domelementtype:domelementtype:1.3.1:*:*:*:*:*:*:*",
315976          "purl": "pkg:npm/domelementtype@1.3.1",
315977          "swid": {
315978            "attachment": {}
315979          },
315980          "pedigree": {},
315981          "evidence": {},
315982          "signature": {
315983            "signature": {
315984              "publicKey": {}
315985            }
315986          },
315987          "modelCard": {
315988            "modelParameters": {
315989              "approach": {}
315990            },
315991            "quantitativeAnalysis": {
315992              "graphics": {}
315993            },
315994            "considerations": {}
315995          }
315996        },
315997        {
315998          "type": "library",
315999          "bom-ref": "pkg:npm/domutils@1.7.0?package-id=badceeb043c0bdfa",
316000          "supplier": {},
316001          "name": "domutils",
316002          "version": "1.7.0",
316003          "licenses": [
316004            {
316005              "license": {
316006                "id": "BSD-2-Clause"
316007              }
316008            }
316009          ],
316010          "cpe": "cpe:2.3:a:domutils:domutils:1.7.0:*:*:*:*:*:*:*",
316011          "purl": "pkg:npm/domutils@1.7.0",
316012          "swid": {
316013            "attachment": {}
316014          },
316015          "pedigree": {},
316016          "evidence": {},
316017          "signature": {
316018            "signature": {
316019              "publicKey": {}
316020            }
316021          },
316022          "modelCard": {
316023            "modelParameters": {
316024              "approach": {}
316025            },
316026            "quantitativeAnalysis": {
316027              "graphics": {}
316028            },
316029            "considerations": {}
316030          }
316031        },
316032        {
316033          "type": "library",
316034          "bom-ref": "pkg:npm/dot-prop@5.2.0?package-id=8fd5537242eb4386",
316035          "supplier": {},
316036          "name": "dot-prop",
316037          "version": "5.2.0",
316038          "licenses": [
316039            {
316040              "license": {
316041                "id": "MIT"
316042              }
316043            }
316044          ],
316045          "cpe": "cpe:2.3:a:dot-prop:dot-prop:5.2.0:*:*:*:*:*:*:*",
316046          "purl": "pkg:npm/dot-prop@5.2.0",
316047          "swid": {
316048            "attachment": {}
316049          },
316050          "pedigree": {},
316051          "evidence": {},
316052          "signature": {
316053            "signature": {
316054              "publicKey": {}
316055            }
316056          },
316057          "modelCard": {
316058            "modelParameters": {
316059              "approach": {}
316060            },
316061            "quantitativeAnalysis": {
316062              "graphics": {}
316063            },
316064            "considerations": {}
316065          }
316066        },
316067        {
316068          "type": "library",
316069          "bom-ref": "pkg:npm/duplexer@0.1.1?package-id=41e23d61d577380",
316070          "supplier": {},
316071          "name": "duplexer",
316072          "version": "0.1.1",
316073          "licenses": [
316074            {
316075              "license": {
316076                "id": "MIT"
316077              }
316078            }
316079          ],
316080          "cpe": "cpe:2.3:a:duplexer:duplexer:0.1.1:*:*:*:*:*:*:*",
316081          "purl": "pkg:npm/duplexer@0.1.1",
316082          "swid": {
316083            "attachment": {}
316084          },
316085          "pedigree": {},
316086          "evidence": {},
316087          "signature": {
316088            "signature": {
316089              "publicKey": {}
316090            }
316091          },
316092          "modelCard": {
316093            "modelParameters": {
316094              "approach": {}
316095            },
316096            "quantitativeAnalysis": {
316097              "graphics": {}
316098            },
316099            "considerations": {}
316100          }
316101        },
316102        {
316103          "type": "library",
316104          "bom-ref": "pkg:npm/duplexify@3.7.1?package-id=db63fa71104335d3",
316105          "supplier": {},
316106          "name": "duplexify",
316107          "version": "3.7.1",
316108          "licenses": [
316109            {
316110              "license": {
316111                "id": "MIT"
316112              }
316113            }
316114          ],
316115          "cpe": "cpe:2.3:a:duplexify:duplexify:3.7.1:*:*:*:*:*:*:*",
316116          "purl": "pkg:npm/duplexify@3.7.1",
316117          "swid": {
316118            "attachment": {}
316119          },
316120          "pedigree": {},
316121          "evidence": {},
316122          "signature": {
316123            "signature": {
316124              "publicKey": {}
316125            }
316126          },
316127          "modelCard": {
316128            "modelParameters": {
316129              "approach": {}
316130            },
316131            "quantitativeAnalysis": {
316132              "graphics": {}
316133            },
316134            "considerations": {}
316135          }
316136        },
316137        {
316138          "type": "library",
316139          "bom-ref": "pkg:npm/ecc-jsbn@0.1.2?package-id=cc938104d42b6760",
316140          "supplier": {},
316141          "name": "ecc-jsbn",
316142          "version": "0.1.2",
316143          "licenses": [
316144            {
316145              "license": {
316146                "id": "MIT"
316147              }
316148            }
316149          ],
316150          "cpe": "cpe:2.3:a:ecc-jsbn:ecc-jsbn:0.1.2:*:*:*:*:*:*:*",
316151          "purl": "pkg:npm/ecc-jsbn@0.1.2",
316152          "swid": {
316153            "attachment": {}
316154          },
316155          "pedigree": {},
316156          "evidence": {},
316157          "signature": {
316158            "signature": {
316159              "publicKey": {}
316160            }
316161          },
316162          "modelCard": {
316163            "modelParameters": {
316164              "approach": {}
316165            },
316166            "quantitativeAnalysis": {
316167              "graphics": {}
316168            },
316169            "considerations": {}
316170          }
316171        },
316172        {
316173          "type": "library",
316174          "bom-ref": "pkg:npm/ee-first@1.1.1?package-id=80bdd04ec6db3a57",
316175          "supplier": {},
316176          "name": "ee-first",
316177          "version": "1.1.1",
316178          "licenses": [
316179            {
316180              "license": {
316181                "id": "MIT"
316182              }
316183            }
316184          ],
316185          "cpe": "cpe:2.3:a:ee-first:ee-first:1.1.1:*:*:*:*:*:*:*",
316186          "purl": "pkg:npm/ee-first@1.1.1",
316187          "swid": {
316188            "attachment": {}
316189          },
316190          "pedigree": {},
316191          "evidence": {},
316192          "signature": {
316193            "signature": {
316194              "publicKey": {}
316195            }
316196          },
316197          "modelCard": {
316198            "modelParameters": {
316199              "approach": {}
316200            },
316201            "quantitativeAnalysis": {
316202              "graphics": {}
316203            },
316204            "considerations": {}
316205          }
316206        },
316207        {
316208          "type": "library",
316209          "bom-ref": "pkg:npm/ejs@2.7.4?package-id=ff55aec28cae4023",
316210          "supplier": {},
316211          "name": "ejs",
316212          "version": "2.7.4",
316213          "licenses": [
316214            {
316215              "license": {
316216                "id": "Apache-2.0"
316217              }
316218            }
316219          ],
316220          "cpe": "cpe:2.3:a:ejs:ejs:2.7.4:*:*:*:*:*:*:*",
316221          "purl": "pkg:npm/ejs@2.7.4",
316222          "swid": {
316223            "attachment": {}
316224          },
316225          "pedigree": {},
316226          "evidence": {},
316227          "signature": {
316228            "signature": {
316229              "publicKey": {}
316230            }
316231          },
316232          "modelCard": {
316233            "modelParameters": {
316234              "approach": {}
316235            },
316236            "quantitativeAnalysis": {
316237              "graphics": {}
316238            },
316239            "considerations": {}
316240          }
316241        },
316242        {
316243          "type": "library",
316244          "bom-ref": "pkg:npm/electron-to-chromium@1.3.433?package-id=4f55d3cc745678d9",
316245          "supplier": {},
316246          "name": "electron-to-chromium",
316247          "version": "1.3.433",
316248          "licenses": [
316249            {
316250              "license": {
316251                "id": "ISC"
316252              }
316253            }
316254          ],
316255          "cpe": "cpe:2.3:a:electron-to-chromium:electron-to-chromium:1.3.433:*:*:*:*:*:*:*",
316256          "purl": "pkg:npm/electron-to-chromium@1.3.433",
316257          "swid": {
316258            "attachment": {}
316259          },
316260          "pedigree": {},
316261          "evidence": {},
316262          "signature": {
316263            "signature": {
316264              "publicKey": {}
316265            }
316266          },
316267          "modelCard": {
316268            "modelParameters": {
316269              "approach": {}
316270            },
316271            "quantitativeAnalysis": {
316272              "graphics": {}
316273            },
316274            "considerations": {}
316275          }
316276        },
316277        {
316278          "type": "library",
316279          "bom-ref": "pkg:npm/electron-to-chromium@1.4.13?package-id=9ef5b79c703c152",
316280          "supplier": {},
316281          "name": "electron-to-chromium",
316282          "version": "1.4.13",
316283          "cpe": "cpe:2.3:a:electron-to-chromium:electron-to-chromium:1.4.13:*:*:*:*:*:*:*",
316284          "purl": "pkg:npm/electron-to-chromium@1.4.13",
316285          "swid": {
316286            "attachment": {}
316287          },
316288          "pedigree": {},
316289          "evidence": {},
316290          "signature": {
316291            "signature": {
316292              "publicKey": {}
316293            }
316294          },
316295          "modelCard": {
316296            "modelParameters": {
316297              "approach": {}
316298            },
316299            "quantitativeAnalysis": {
316300              "graphics": {}
316301            },
316302            "considerations": {}
316303          }
316304        },
316305        {
316306          "type": "library",
316307          "bom-ref": "pkg:npm/elliptic@6.5.2?package-id=345e91e597c67b98",
316308          "supplier": {},
316309          "name": "elliptic",
316310          "version": "6.5.2",
316311          "licenses": [
316312            {
316313              "license": {
316314                "id": "MIT"
316315              }
316316            }
316317          ],
316318          "cpe": "cpe:2.3:a:elliptic:elliptic:6.5.2:*:*:*:*:*:*:*",
316319          "purl": "pkg:npm/elliptic@6.5.2",
316320          "swid": {
316321            "attachment": {}
316322          },
316323          "pedigree": {},
316324          "evidence": {},
316325          "signature": {
316326            "signature": {
316327              "publicKey": {}
316328            }
316329          },
316330          "modelCard": {
316331            "modelParameters": {
316332              "approach": {}
316333            },
316334            "quantitativeAnalysis": {
316335              "graphics": {}
316336            },
316337            "considerations": {}
316338          }
316339        },
316340        {
316341          "type": "library",
316342          "bom-ref": "pkg:npm/emoji-regex@8.0.0?package-id=a3ee899a356c844a",
316343          "supplier": {},
316344          "name": "emoji-regex",
316345          "version": "8.0.0",
316346          "cpe": "cpe:2.3:a:emoji-regex:emoji-regex:8.0.0:*:*:*:*:*:*:*",
316347          "purl": "pkg:npm/emoji-regex@8.0.0",
316348          "swid": {
316349            "attachment": {}
316350          },
316351          "pedigree": {},
316352          "evidence": {},
316353          "signature": {
316354            "signature": {
316355              "publicKey": {}
316356            }
316357          },
316358          "modelCard": {
316359            "modelParameters": {
316360              "approach": {}
316361            },
316362            "quantitativeAnalysis": {
316363              "graphics": {}
316364            },
316365            "considerations": {}
316366          }
316367        },
316368        {
316369          "type": "library",
316370          "bom-ref": "pkg:npm/emoji-regex@8.0.0?package-id=99ba91235e6f01bb",
316371          "supplier": {},
316372          "name": "emoji-regex",
316373          "version": "8.0.0",
316374          "licenses": [
316375            {
316376              "license": {
316377                "id": "MIT"
316378              }
316379            }
316380          ],
316381          "cpe": "cpe:2.3:a:emoji-regex:emoji-regex:8.0.0:*:*:*:*:*:*:*",
316382          "purl": "pkg:npm/emoji-regex@8.0.0",
316383          "swid": {
316384            "attachment": {}
316385          },
316386          "pedigree": {},
316387          "evidence": {},
316388          "signature": {
316389            "signature": {
316390              "publicKey": {}
316391            }
316392          },
316393          "modelCard": {
316394            "modelParameters": {
316395              "approach": {}
316396            },
316397            "quantitativeAnalysis": {
316398              "graphics": {}
316399            },
316400            "considerations": {}
316401          }
316402        },
316403        {
316404          "type": "library",
316405          "bom-ref": "pkg:npm/emojis-list@3.0.0?package-id=9d621aca0a494c9e",
316406          "supplier": {},
316407          "name": "emojis-list",
316408          "version": "3.0.0",
316409          "licenses": [
316410            {
316411              "license": {
316412                "id": "MIT"
316413              }
316414            }
316415          ],
316416          "cpe": "cpe:2.3:a:emojis-list:emojis-list:3.0.0:*:*:*:*:*:*:*",
316417          "purl": "pkg:npm/emojis-list@3.0.0",
316418          "swid": {
316419            "attachment": {}
316420          },
316421          "pedigree": {},
316422          "evidence": {},
316423          "signature": {
316424            "signature": {
316425              "publicKey": {}
316426            }
316427          },
316428          "modelCard": {
316429            "modelParameters": {
316430              "approach": {}
316431            },
316432            "quantitativeAnalysis": {
316433              "graphics": {}
316434            },
316435            "considerations": {}
316436          }
316437        },
316438        {
316439          "type": "library",
316440          "bom-ref": "pkg:npm/encodeurl@1.0.2?package-id=d84f18f685255929",
316441          "supplier": {},
316442          "name": "encodeurl",
316443          "version": "1.0.2",
316444          "licenses": [
316445            {
316446              "license": {
316447                "id": "MIT"
316448              }
316449            }
316450          ],
316451          "cpe": "cpe:2.3:a:encodeurl:encodeurl:1.0.2:*:*:*:*:*:*:*",
316452          "purl": "pkg:npm/encodeurl@1.0.2",
316453          "swid": {
316454            "attachment": {}
316455          },
316456          "pedigree": {},
316457          "evidence": {},
316458          "signature": {
316459            "signature": {
316460              "publicKey": {}
316461            }
316462          },
316463          "modelCard": {
316464            "modelParameters": {
316465              "approach": {}
316466            },
316467            "quantitativeAnalysis": {
316468              "graphics": {}
316469            },
316470            "considerations": {}
316471          }
316472        },
316473        {
316474          "type": "library",
316475          "bom-ref": "pkg:npm/encoding@0.1.12?package-id=56f3fd791939fb45",
316476          "supplier": {},
316477          "name": "encoding",
316478          "version": "0.1.12",
316479          "licenses": [
316480            {
316481              "license": {
316482                "id": "MIT"
316483              }
316484            }
316485          ],
316486          "cpe": "cpe:2.3:a:encoding:encoding:0.1.12:*:*:*:*:*:*:*",
316487          "purl": "pkg:npm/encoding@0.1.12",
316488          "swid": {
316489            "attachment": {}
316490          },
316491          "pedigree": {},
316492          "evidence": {},
316493          "signature": {
316494            "signature": {
316495              "publicKey": {}
316496            }
316497          },
316498          "modelCard": {
316499            "modelParameters": {
316500              "approach": {}
316501            },
316502            "quantitativeAnalysis": {
316503              "graphics": {}
316504            },
316505            "considerations": {}
316506          }
316507        },
316508        {
316509          "type": "library",
316510          "bom-ref": "pkg:npm/end-of-stream@1.4.4?package-id=4e51e9b811cd77c1",
316511          "supplier": {},
316512          "name": "end-of-stream",
316513          "version": "1.4.4",
316514          "licenses": [
316515            {
316516              "license": {
316517                "id": "MIT"
316518              }
316519            }
316520          ],
316521          "cpe": "cpe:2.3:a:end-of-stream:end-of-stream:1.4.4:*:*:*:*:*:*:*",
316522          "purl": "pkg:npm/end-of-stream@1.4.4",
316523          "swid": {
316524            "attachment": {}
316525          },
316526          "pedigree": {},
316527          "evidence": {},
316528          "signature": {
316529            "signature": {
316530              "publicKey": {}
316531            }
316532          },
316533          "modelCard": {
316534            "modelParameters": {
316535              "approach": {}
316536            },
316537            "quantitativeAnalysis": {
316538              "graphics": {}
316539            },
316540            "considerations": {}
316541          }
316542        },
316543        {
316544          "type": "library",
316545          "bom-ref": "pkg:npm/engine.io@3.2.1?package-id=1cb3ad3a4b6b444a",
316546          "supplier": {},
316547          "name": "engine.io",
316548          "version": "3.2.1",
316549          "licenses": [
316550            {
316551              "license": {
316552                "id": "MIT"
316553              }
316554            }
316555          ],
316556          "cpe": "cpe:2.3:a:engine.io:engine.io:3.2.1:*:*:*:*:*:*:*",
316557          "purl": "pkg:npm/engine.io@3.2.1",
316558          "swid": {
316559            "attachment": {}
316560          },
316561          "pedigree": {},
316562          "evidence": {},
316563          "signature": {
316564            "signature": {
316565              "publicKey": {}
316566            }
316567          },
316568          "modelCard": {
316569            "modelParameters": {
316570              "approach": {}
316571            },
316572            "quantitativeAnalysis": {
316573              "graphics": {}
316574            },
316575            "considerations": {}
316576          }
316577        },
316578        {
316579          "type": "library",
316580          "bom-ref": "pkg:npm/engine.io-client@3.2.1?package-id=803793384e77dba6",
316581          "supplier": {},
316582          "name": "engine.io-client",
316583          "version": "3.2.1",
316584          "licenses": [
316585            {
316586              "license": {
316587                "id": "MIT"
316588              }
316589            }
316590          ],
316591          "cpe": "cpe:2.3:a:engine.io-client:engine.io-client:3.2.1:*:*:*:*:*:*:*",
316592          "purl": "pkg:npm/engine.io-client@3.2.1",
316593          "swid": {
316594            "attachment": {}
316595          },
316596          "pedigree": {},
316597          "evidence": {},
316598          "signature": {
316599            "signature": {
316600              "publicKey": {}
316601            }
316602          },
316603          "modelCard": {
316604            "modelParameters": {
316605              "approach": {}
316606            },
316607            "quantitativeAnalysis": {
316608              "graphics": {}
316609            },
316610            "considerations": {}
316611          }
316612        },
316613        {
316614          "type": "library",
316615          "bom-ref": "pkg:npm/engine.io-parser@2.1.3?package-id=bf7c07a1545343a0",
316616          "supplier": {},
316617          "name": "engine.io-parser",
316618          "version": "2.1.3",
316619          "licenses": [
316620            {
316621              "license": {
316622                "id": "MIT"
316623              }
316624            }
316625          ],
316626          "cpe": "cpe:2.3:a:engine.io-parser:engine.io-parser:2.1.3:*:*:*:*:*:*:*",
316627          "purl": "pkg:npm/engine.io-parser@2.1.3",
316628          "swid": {
316629            "attachment": {}
316630          },
316631          "pedigree": {},
316632          "evidence": {},
316633          "signature": {
316634            "signature": {
316635              "publicKey": {}
316636            }
316637          },
316638          "modelCard": {
316639            "modelParameters": {
316640              "approach": {}
316641            },
316642            "quantitativeAnalysis": {
316643              "graphics": {}
316644            },
316645            "considerations": {}
316646          }
316647        },
316648        {
316649          "type": "library",
316650          "bom-ref": "pkg:npm/enhanced-resolve@4.1.1?package-id=a159485c533def40",
316651          "supplier": {},
316652          "name": "enhanced-resolve",
316653          "version": "4.1.1",
316654          "licenses": [
316655            {
316656              "license": {
316657                "id": "MIT"
316658              }
316659            }
316660          ],
316661          "cpe": "cpe:2.3:a:enhanced-resolve:enhanced-resolve:4.1.1:*:*:*:*:*:*:*",
316662          "purl": "pkg:npm/enhanced-resolve@4.1.1",
316663          "swid": {
316664            "attachment": {}
316665          },
316666          "pedigree": {},
316667          "evidence": {},
316668          "signature": {
316669            "signature": {
316670              "publicKey": {}
316671            }
316672          },
316673          "modelCard": {
316674            "modelParameters": {
316675              "approach": {}
316676            },
316677            "quantitativeAnalysis": {
316678              "graphics": {}
316679            },
316680            "considerations": {}
316681          }
316682        },
316683        {
316684          "type": "library",
316685          "bom-ref": "pkg:npm/ent@2.2.0?package-id=1ccc00680667d71a",
316686          "supplier": {},
316687          "name": "ent",
316688          "version": "2.2.0",
316689          "licenses": [
316690            {
316691              "license": {
316692                "id": "MIT"
316693              }
316694            }
316695          ],
316696          "cpe": "cpe:2.3:a:ent:ent:2.2.0:*:*:*:*:*:*:*",
316697          "purl": "pkg:npm/ent@2.2.0",
316698          "swid": {
316699            "attachment": {}
316700          },
316701          "pedigree": {},
316702          "evidence": {},
316703          "signature": {
316704            "signature": {
316705              "publicKey": {}
316706            }
316707          },
316708          "modelCard": {
316709            "modelParameters": {
316710              "approach": {}
316711            },
316712            "quantitativeAnalysis": {
316713              "graphics": {}
316714            },
316715            "considerations": {}
316716          }
316717        },
316718        {
316719          "type": "library",
316720          "bom-ref": "pkg:npm/entities@2.0.2?package-id=6d7206c48acebef0",
316721          "supplier": {},
316722          "name": "entities",
316723          "version": "2.0.2",
316724          "licenses": [
316725            {
316726              "license": {
316727                "id": "BSD-2-Clause"
316728              }
316729            }
316730          ],
316731          "cpe": "cpe:2.3:a:entities:entities:2.0.2:*:*:*:*:*:*:*",
316732          "purl": "pkg:npm/entities@2.0.2",
316733          "swid": {
316734            "attachment": {}
316735          },
316736          "pedigree": {},
316737          "evidence": {},
316738          "signature": {
316739            "signature": {
316740              "publicKey": {}
316741            }
316742          },
316743          "modelCard": {
316744            "modelParameters": {
316745              "approach": {}
316746            },
316747            "quantitativeAnalysis": {
316748              "graphics": {}
316749            },
316750            "considerations": {}
316751          }
316752        },
316753        {
316754          "type": "library",
316755          "bom-ref": "pkg:npm/err-code@1.1.2?package-id=5090af9f2b1d3338",
316756          "supplier": {},
316757          "name": "err-code",
316758          "version": "1.1.2",
316759          "licenses": [
316760            {
316761              "license": {
316762                "id": "MIT"
316763              }
316764            }
316765          ],
316766          "cpe": "cpe:2.3:a:err-code:err-code:1.1.2:*:*:*:*:*:*:*",
316767          "purl": "pkg:npm/err-code@1.1.2",
316768          "swid": {
316769            "attachment": {}
316770          },
316771          "pedigree": {},
316772          "evidence": {},
316773          "signature": {
316774            "signature": {
316775              "publicKey": {}
316776            }
316777          },
316778          "modelCard": {
316779            "modelParameters": {
316780              "approach": {}
316781            },
316782            "quantitativeAnalysis": {
316783              "graphics": {}
316784            },
316785            "considerations": {}
316786          }
316787        },
316788        {
316789          "type": "library",
316790          "bom-ref": "pkg:npm/errno@0.1.7?package-id=a5287fdd9a028341",
316791          "supplier": {},
316792          "name": "errno",
316793          "version": "0.1.7",
316794          "licenses": [
316795            {
316796              "license": {
316797                "id": "MIT"
316798              }
316799            }
316800          ],
316801          "cpe": "cpe:2.3:a:errno:errno:0.1.7:*:*:*:*:*:*:*",
316802          "purl": "pkg:npm/errno@0.1.7",
316803          "swid": {
316804            "attachment": {}
316805          },
316806          "pedigree": {},
316807          "evidence": {},
316808          "signature": {
316809            "signature": {
316810              "publicKey": {}
316811            }
316812          },
316813          "modelCard": {
316814            "modelParameters": {
316815              "approach": {}
316816            },
316817            "quantitativeAnalysis": {
316818              "graphics": {}
316819            },
316820            "considerations": {}
316821          }
316822        },
316823        {
316824          "type": "library",
316825          "bom-ref": "pkg:npm/error-ex@1.3.2?package-id=2c26e7d8b21341c1",
316826          "supplier": {},
316827          "name": "error-ex",
316828          "version": "1.3.2",
316829          "licenses": [
316830            {
316831              "license": {
316832                "id": "MIT"
316833              }
316834            }
316835          ],
316836          "cpe": "cpe:2.3:a:error-ex:error-ex:1.3.2:*:*:*:*:*:*:*",
316837          "purl": "pkg:npm/error-ex@1.3.2",
316838          "swid": {
316839            "attachment": {}
316840          },
316841          "pedigree": {},
316842          "evidence": {},
316843          "signature": {
316844            "signature": {
316845              "publicKey": {}
316846            }
316847          },
316848          "modelCard": {
316849            "modelParameters": {
316850              "approach": {}
316851            },
316852            "quantitativeAnalysis": {
316853              "graphics": {}
316854            },
316855            "considerations": {}
316856          }
316857        },
316858        {
316859          "type": "library",
316860          "bom-ref": "pkg:npm/es-abstract@1.17.5?package-id=d12dccbb8354d40d",
316861          "supplier": {},
316862          "name": "es-abstract",
316863          "version": "1.17.5",
316864          "licenses": [
316865            {
316866              "license": {
316867                "id": "MIT"
316868              }
316869            }
316870          ],
316871          "cpe": "cpe:2.3:a:es-abstract:es-abstract:1.17.5:*:*:*:*:*:*:*",
316872          "purl": "pkg:npm/es-abstract@1.17.5",
316873          "swid": {
316874            "attachment": {}
316875          },
316876          "pedigree": {},
316877          "evidence": {},
316878          "signature": {
316879            "signature": {
316880              "publicKey": {}
316881            }
316882          },
316883          "modelCard": {
316884            "modelParameters": {
316885              "approach": {}
316886            },
316887            "quantitativeAnalysis": {
316888              "graphics": {}
316889            },
316890            "considerations": {}
316891          }
316892        },
316893        {
316894          "type": "library",
316895          "bom-ref": "pkg:npm/es-to-primitive@1.2.1?package-id=edb146437b9fce1f",
316896          "supplier": {},
316897          "name": "es-to-primitive",
316898          "version": "1.2.1",
316899          "licenses": [
316900            {
316901              "license": {
316902                "id": "MIT"
316903              }
316904            }
316905          ],
316906          "cpe": "cpe:2.3:a:es-to-primitive:es-to-primitive:1.2.1:*:*:*:*:*:*:*",
316907          "purl": "pkg:npm/es-to-primitive@1.2.1",
316908          "swid": {
316909            "attachment": {}
316910          },
316911          "pedigree": {},
316912          "evidence": {},
316913          "signature": {
316914            "signature": {
316915              "publicKey": {}
316916            }
316917          },
316918          "modelCard": {
316919            "modelParameters": {
316920              "approach": {}
316921            },
316922            "quantitativeAnalysis": {
316923              "graphics": {}
316924            },
316925            "considerations": {}
316926          }
316927        },
316928        {
316929          "type": "library",
316930          "bom-ref": "pkg:npm/es5-ext@0.10.53?package-id=ee86d9902808de60",
316931          "supplier": {},
316932          "name": "es5-ext",
316933          "version": "0.10.53",
316934          "licenses": [
316935            {
316936              "license": {
316937                "id": "ISC"
316938              }
316939            }
316940          ],
316941          "cpe": "cpe:2.3:a:es5-ext:es5-ext:0.10.53:*:*:*:*:*:*:*",
316942          "purl": "pkg:npm/es5-ext@0.10.53",
316943          "swid": {
316944            "attachment": {}
316945          },
316946          "pedigree": {},
316947          "evidence": {},
316948          "signature": {
316949            "signature": {
316950              "publicKey": {}
316951            }
316952          },
316953          "modelCard": {
316954            "modelParameters": {
316955              "approach": {}
316956            },
316957            "quantitativeAnalysis": {
316958              "graphics": {}
316959            },
316960            "considerations": {}
316961          }
316962        },
316963        {
316964          "type": "library",
316965          "bom-ref": "pkg:npm/es6-error@4.1.1?package-id=894abcc38c04c11d",
316966          "supplier": {},
316967          "name": "es6-error",
316968          "version": "4.1.1",
316969          "cpe": "cpe:2.3:a:es6-error:es6-error:4.1.1:*:*:*:*:*:*:*",
316970          "purl": "pkg:npm/es6-error@4.1.1",
316971          "swid": {
316972            "attachment": {}
316973          },
316974          "pedigree": {},
316975          "evidence": {},
316976          "signature": {
316977            "signature": {
316978              "publicKey": {}
316979            }
316980          },
316981          "modelCard": {
316982            "modelParameters": {
316983              "approach": {}
316984            },
316985            "quantitativeAnalysis": {
316986              "graphics": {}
316987            },
316988            "considerations": {}
316989          }
316990        },
316991        {
316992          "type": "library",
316993          "bom-ref": "pkg:npm/es6-iterator@2.0.3?package-id=5dd6fc0e6048ebbc",
316994          "supplier": {},
316995          "name": "es6-iterator",
316996          "version": "2.0.3",
316997          "licenses": [
316998            {
316999              "license": {
317000                "id": "MIT"
317001              }
317002            }
317003          ],
317004          "cpe": "cpe:2.3:a:es6-iterator:es6-iterator:2.0.3:*:*:*:*:*:*:*",
317005          "purl": "pkg:npm/es6-iterator@2.0.3",
317006          "swid": {
317007            "attachment": {}
317008          },
317009          "pedigree": {},
317010          "evidence": {},
317011          "signature": {
317012            "signature": {
317013              "publicKey": {}
317014            }
317015          },
317016          "modelCard": {
317017            "modelParameters": {
317018              "approach": {}
317019            },
317020            "quantitativeAnalysis": {
317021              "graphics": {}
317022            },
317023            "considerations": {}
317024          }
317025        },
317026        {
317027          "type": "library",
317028          "bom-ref": "pkg:npm/es6-promise@4.2.8?package-id=861d99e03aeae9b2",
317029          "supplier": {},
317030          "name": "es6-promise",
317031          "version": "4.2.8",
317032          "licenses": [
317033            {
317034              "license": {
317035                "id": "MIT"
317036              }
317037            }
317038          ],
317039          "cpe": "cpe:2.3:a:es6-promise:es6-promise:4.2.8:*:*:*:*:*:*:*",
317040          "purl": "pkg:npm/es6-promise@4.2.8",
317041          "swid": {
317042            "attachment": {}
317043          },
317044          "pedigree": {},
317045          "evidence": {},
317046          "signature": {
317047            "signature": {
317048              "publicKey": {}
317049            }
317050          },
317051          "modelCard": {
317052            "modelParameters": {
317053              "approach": {}
317054            },
317055            "quantitativeAnalysis": {
317056              "graphics": {}
317057            },
317058            "considerations": {}
317059          }
317060        },
317061        {
317062          "type": "library",
317063          "bom-ref": "pkg:npm/es6-promisify@5.0.0?package-id=fde5458a4f9d0300",
317064          "supplier": {},
317065          "name": "es6-promisify",
317066          "version": "5.0.0",
317067          "licenses": [
317068            {
317069              "license": {
317070                "id": "MIT"
317071              }
317072            }
317073          ],
317074          "cpe": "cpe:2.3:a:es6-promisify:es6-promisify:5.0.0:*:*:*:*:*:*:*",
317075          "purl": "pkg:npm/es6-promisify@5.0.0",
317076          "swid": {
317077            "attachment": {}
317078          },
317079          "pedigree": {},
317080          "evidence": {},
317081          "signature": {
317082            "signature": {
317083              "publicKey": {}
317084            }
317085          },
317086          "modelCard": {
317087            "modelParameters": {
317088              "approach": {}
317089            },
317090            "quantitativeAnalysis": {
317091              "graphics": {}
317092            },
317093            "considerations": {}
317094          }
317095        },
317096        {
317097          "type": "library",
317098          "bom-ref": "pkg:npm/es6-symbol@3.1.3?package-id=370407680b5b5874",
317099          "supplier": {},
317100          "name": "es6-symbol",
317101          "version": "3.1.3",
317102          "licenses": [
317103            {
317104              "license": {
317105                "id": "ISC"
317106              }
317107            }
317108          ],
317109          "cpe": "cpe:2.3:a:es6-symbol:es6-symbol:3.1.3:*:*:*:*:*:*:*",
317110          "purl": "pkg:npm/es6-symbol@3.1.3",
317111          "swid": {
317112            "attachment": {}
317113          },
317114          "pedigree": {},
317115          "evidence": {},
317116          "signature": {
317117            "signature": {
317118              "publicKey": {}
317119            }
317120          },
317121          "modelCard": {
317122            "modelParameters": {
317123              "approach": {}
317124            },
317125            "quantitativeAnalysis": {
317126              "graphics": {}
317127            },
317128            "considerations": {}
317129          }
317130        },
317131        {
317132          "type": "library",
317133          "bom-ref": "pkg:npm/es6-weak-map@2.0.3?package-id=3f53f9ef8c3d68ae",
317134          "supplier": {},
317135          "name": "es6-weak-map",
317136          "version": "2.0.3",
317137          "licenses": [
317138            {
317139              "license": {
317140                "id": "ISC"
317141              }
317142            }
317143          ],
317144          "cpe": "cpe:2.3:a:es6-weak-map:es6-weak-map:2.0.3:*:*:*:*:*:*:*",
317145          "purl": "pkg:npm/es6-weak-map@2.0.3",
317146          "swid": {
317147            "attachment": {}
317148          },
317149          "pedigree": {},
317150          "evidence": {},
317151          "signature": {
317152            "signature": {
317153              "publicKey": {}
317154            }
317155          },
317156          "modelCard": {
317157            "modelParameters": {
317158              "approach": {}
317159            },
317160            "quantitativeAnalysis": {
317161              "graphics": {}
317162            },
317163            "considerations": {}
317164          }
317165        },
317166        {
317167          "type": "library",
317168          "bom-ref": "pkg:npm/escalade@3.1.1?package-id=4bd26dc4f96cd732",
317169          "supplier": {},
317170          "name": "escalade",
317171          "version": "3.1.1",
317172          "cpe": "cpe:2.3:a:escalade:escalade:3.1.1:*:*:*:*:*:*:*",
317173          "purl": "pkg:npm/escalade@3.1.1",
317174          "swid": {
317175            "attachment": {}
317176          },
317177          "pedigree": {},
317178          "evidence": {},
317179          "signature": {
317180            "signature": {
317181              "publicKey": {}
317182            }
317183          },
317184          "modelCard": {
317185            "modelParameters": {
317186              "approach": {}
317187            },
317188            "quantitativeAnalysis": {
317189              "graphics": {}
317190            },
317191            "considerations": {}
317192          }
317193        },
317194        {
317195          "type": "library",
317196          "bom-ref": "pkg:npm/escape-html@1.0.3?package-id=335e075a5ff270f0",
317197          "supplier": {},
317198          "name": "escape-html",
317199          "version": "1.0.3",
317200          "licenses": [
317201            {
317202              "license": {
317203                "id": "MIT"
317204              }
317205            }
317206          ],
317207          "cpe": "cpe:2.3:a:escape-html:escape-html:1.0.3:*:*:*:*:*:*:*",
317208          "purl": "pkg:npm/escape-html@1.0.3",
317209          "swid": {
317210            "attachment": {}
317211          },
317212          "pedigree": {},
317213          "evidence": {},
317214          "signature": {
317215            "signature": {
317216              "publicKey": {}
317217            }
317218          },
317219          "modelCard": {
317220            "modelParameters": {
317221              "approach": {}
317222            },
317223            "quantitativeAnalysis": {
317224              "graphics": {}
317225            },
317226            "considerations": {}
317227          }
317228        },
317229        {
317230          "type": "library",
317231          "bom-ref": "pkg:npm/escape-string-regexp@1.0.5?package-id=667d680785306240",
317232          "supplier": {},
317233          "name": "escape-string-regexp",
317234          "version": "1.0.5",
317235          "cpe": "cpe:2.3:a:escape-string-regexp:escape-string-regexp:1.0.5:*:*:*:*:*:*:*",
317236          "purl": "pkg:npm/escape-string-regexp@1.0.5",
317237          "swid": {
317238            "attachment": {}
317239          },
317240          "pedigree": {},
317241          "evidence": {},
317242          "signature": {
317243            "signature": {
317244              "publicKey": {}
317245            }
317246          },
317247          "modelCard": {
317248            "modelParameters": {
317249              "approach": {}
317250            },
317251            "quantitativeAnalysis": {
317252              "graphics": {}
317253            },
317254            "considerations": {}
317255          }
317256        },
317257        {
317258          "type": "library",
317259          "bom-ref": "pkg:npm/escape-string-regexp@1.0.5?package-id=311ccccf5d94a5cb",
317260          "supplier": {},
317261          "name": "escape-string-regexp",
317262          "version": "1.0.5",
317263          "licenses": [
317264            {
317265              "license": {
317266                "id": "MIT"
317267              }
317268            }
317269          ],
317270          "cpe": "cpe:2.3:a:escape-string-regexp:escape-string-regexp:1.0.5:*:*:*:*:*:*:*",
317271          "purl": "pkg:npm/escape-string-regexp@1.0.5",
317272          "swid": {
317273            "attachment": {}
317274          },
317275          "pedigree": {},
317276          "evidence": {},
317277          "signature": {
317278            "signature": {
317279              "publicKey": {}
317280            }
317281          },
317282          "modelCard": {
317283            "modelParameters": {
317284              "approach": {}
317285            },
317286            "quantitativeAnalysis": {
317287              "graphics": {}
317288            },
317289            "considerations": {}
317290          }
317291        },
317292        {
317293          "type": "library",
317294          "bom-ref": "pkg:npm/eslint-scope@4.0.3?package-id=37eb099d06d2675b",
317295          "supplier": {},
317296          "name": "eslint-scope",
317297          "version": "4.0.3",
317298          "licenses": [
317299            {
317300              "license": {
317301                "id": "BSD-2-Clause"
317302              }
317303            }
317304          ],
317305          "cpe": "cpe:2.3:a:eslint-scope:eslint-scope:4.0.3:*:*:*:*:*:*:*",
317306          "purl": "pkg:npm/eslint-scope@4.0.3",
317307          "swid": {
317308            "attachment": {}
317309          },
317310          "pedigree": {},
317311          "evidence": {},
317312          "signature": {
317313            "signature": {
317314              "publicKey": {}
317315            }
317316          },
317317          "modelCard": {
317318            "modelParameters": {
317319              "approach": {}
317320            },
317321            "quantitativeAnalysis": {
317322              "graphics": {}
317323            },
317324            "considerations": {}
317325          }
317326        },
317327        {
317328          "type": "library",
317329          "bom-ref": "pkg:npm/esprima@4.0.1?package-id=701448f4689ebee6",
317330          "supplier": {},
317331          "name": "esprima",
317332          "version": "4.0.1",
317333          "cpe": "cpe:2.3:a:esprima:esprima:4.0.1:*:*:*:*:*:*:*",
317334          "purl": "pkg:npm/esprima@4.0.1",
317335          "swid": {
317336            "attachment": {}
317337          },
317338          "pedigree": {},
317339          "evidence": {},
317340          "signature": {
317341            "signature": {
317342              "publicKey": {}
317343            }
317344          },
317345          "modelCard": {
317346            "modelParameters": {
317347              "approach": {}
317348            },
317349            "quantitativeAnalysis": {
317350              "graphics": {}
317351            },
317352            "considerations": {}
317353          }
317354        },
317355        {
317356          "type": "library",
317357          "bom-ref": "pkg:npm/esprima@4.0.1?package-id=a4f4d6726ec2ca",
317358          "supplier": {},
317359          "name": "esprima",
317360          "version": "4.0.1",
317361          "licenses": [
317362            {
317363              "license": {
317364                "id": "BSD-2-Clause"
317365              }
317366            }
317367          ],
317368          "cpe": "cpe:2.3:a:esprima:esprima:4.0.1:*:*:*:*:*:*:*",
317369          "purl": "pkg:npm/esprima@4.0.1",
317370          "swid": {
317371            "attachment": {}
317372          },
317373          "pedigree": {},
317374          "evidence": {},
317375          "signature": {
317376            "signature": {
317377              "publicKey": {}
317378            }
317379          },
317380          "modelCard": {
317381            "modelParameters": {
317382              "approach": {}
317383            },
317384            "quantitativeAnalysis": {
317385              "graphics": {}
317386            },
317387            "considerations": {}
317388          }
317389        },
317390        {
317391          "type": "library",
317392          "bom-ref": "pkg:npm/esrecurse@4.2.1?package-id=1d0bd1c39ef3a80",
317393          "supplier": {},
317394          "name": "esrecurse",
317395          "version": "4.2.1",
317396          "licenses": [
317397            {
317398              "license": {
317399                "id": "BSD-2-Clause"
317400              }
317401            }
317402          ],
317403          "cpe": "cpe:2.3:a:esrecurse:esrecurse:4.2.1:*:*:*:*:*:*:*",
317404          "purl": "pkg:npm/esrecurse@4.2.1",
317405          "swid": {
317406            "attachment": {}
317407          },
317408          "pedigree": {},
317409          "evidence": {},
317410          "signature": {
317411            "signature": {
317412              "publicKey": {}
317413            }
317414          },
317415          "modelCard": {
317416            "modelParameters": {
317417              "approach": {}
317418            },
317419            "quantitativeAnalysis": {
317420              "graphics": {}
317421            },
317422            "considerations": {}
317423          }
317424        },
317425        {
317426          "type": "library",
317427          "bom-ref": "pkg:npm/estraverse@4.3.0?package-id=dead21bda6fdd12e",
317428          "supplier": {},
317429          "name": "estraverse",
317430          "version": "4.3.0",
317431          "licenses": [
317432            {
317433              "license": {
317434                "id": "BSD-2-Clause"
317435              }
317436            }
317437          ],
317438          "cpe": "cpe:2.3:a:estraverse:estraverse:4.3.0:*:*:*:*:*:*:*",
317439          "purl": "pkg:npm/estraverse@4.3.0",
317440          "swid": {
317441            "attachment": {}
317442          },
317443          "pedigree": {},
317444          "evidence": {},
317445          "signature": {
317446            "signature": {
317447              "publicKey": {}
317448            }
317449          },
317450          "modelCard": {
317451            "modelParameters": {
317452              "approach": {}
317453            },
317454            "quantitativeAnalysis": {
317455              "graphics": {}
317456            },
317457            "considerations": {}
317458          }
317459        },
317460        {
317461          "type": "library",
317462          "bom-ref": "pkg:npm/esutils@2.0.3?package-id=bd4300a8410703e5",
317463          "supplier": {},
317464          "name": "esutils",
317465          "version": "2.0.3",
317466          "licenses": [
317467            {
317468              "license": {
317469                "id": "BSD-2-Clause"
317470              }
317471            }
317472          ],
317473          "cpe": "cpe:2.3:a:esutils:esutils:2.0.3:*:*:*:*:*:*:*",
317474          "purl": "pkg:npm/esutils@2.0.3",
317475          "swid": {
317476            "attachment": {}
317477          },
317478          "pedigree": {},
317479          "evidence": {},
317480          "signature": {
317481            "signature": {
317482              "publicKey": {}
317483            }
317484          },
317485          "modelCard": {
317486            "modelParameters": {
317487              "approach": {}
317488            },
317489            "quantitativeAnalysis": {
317490              "graphics": {}
317491            },
317492            "considerations": {}
317493          }
317494        },
317495        {
317496          "type": "library",
317497          "bom-ref": "pkg:npm/etag@1.8.1?package-id=1ed619612608c762",
317498          "supplier": {},
317499          "name": "etag",
317500          "version": "1.8.1",
317501          "licenses": [
317502            {
317503              "license": {
317504                "id": "MIT"
317505              }
317506            }
317507          ],
317508          "cpe": "cpe:2.3:a:etag:etag:1.8.1:*:*:*:*:*:*:*",
317509          "purl": "pkg:npm/etag@1.8.1",
317510          "swid": {
317511            "attachment": {}
317512          },
317513          "pedigree": {},
317514          "evidence": {},
317515          "signature": {
317516            "signature": {
317517              "publicKey": {}
317518            }
317519          },
317520          "modelCard": {
317521            "modelParameters": {
317522              "approach": {}
317523            },
317524            "quantitativeAnalysis": {
317525              "graphics": {}
317526            },
317527            "considerations": {}
317528          }
317529        },
317530        {
317531          "type": "library",
317532          "bom-ref": "pkg:npm/event-emitter@0.3.5?package-id=7a537a2a49063935",
317533          "supplier": {},
317534          "name": "event-emitter",
317535          "version": "0.3.5",
317536          "licenses": [
317537            {
317538              "license": {
317539                "id": "MIT"
317540              }
317541            }
317542          ],
317543          "cpe": "cpe:2.3:a:event-emitter:event-emitter:0.3.5:*:*:*:*:*:*:*",
317544          "purl": "pkg:npm/event-emitter@0.3.5",
317545          "swid": {
317546            "attachment": {}
317547          },
317548          "pedigree": {},
317549          "evidence": {},
317550          "signature": {
317551            "signature": {
317552              "publicKey": {}
317553            }
317554          },
317555          "modelCard": {
317556            "modelParameters": {
317557              "approach": {}
317558            },
317559            "quantitativeAnalysis": {
317560              "graphics": {}
317561            },
317562            "considerations": {}
317563          }
317564        },
317565        {
317566          "type": "library",
317567          "bom-ref": "pkg:npm/eventemitter3@4.0.0?package-id=cc23bb8b72579491",
317568          "supplier": {},
317569          "name": "eventemitter3",
317570          "version": "4.0.0",
317571          "licenses": [
317572            {
317573              "license": {
317574                "id": "MIT"
317575              }
317576            }
317577          ],
317578          "cpe": "cpe:2.3:a:eventemitter3:eventemitter3:4.0.0:*:*:*:*:*:*:*",
317579          "purl": "pkg:npm/eventemitter3@4.0.0",
317580          "swid": {
317581            "attachment": {}
317582          },
317583          "pedigree": {},
317584          "evidence": {},
317585          "signature": {
317586            "signature": {
317587              "publicKey": {}
317588            }
317589          },
317590          "modelCard": {
317591            "modelParameters": {
317592              "approach": {}
317593            },
317594            "quantitativeAnalysis": {
317595              "graphics": {}
317596            },
317597            "considerations": {}
317598          }
317599        },
317600        {
317601          "type": "library",
317602          "bom-ref": "pkg:npm/events@3.1.0?package-id=5126d21288b75415",
317603          "supplier": {},
317604          "name": "events",
317605          "version": "3.1.0",
317606          "licenses": [
317607            {
317608              "license": {
317609                "id": "MIT"
317610              }
317611            }
317612          ],
317613          "cpe": "cpe:2.3:a:events:events:3.1.0:*:*:*:*:*:*:*",
317614          "purl": "pkg:npm/events@3.1.0",
317615          "swid": {
317616            "attachment": {}
317617          },
317618          "pedigree": {},
317619          "evidence": {},
317620          "signature": {
317621            "signature": {
317622              "publicKey": {}
317623            }
317624          },
317625          "modelCard": {
317626            "modelParameters": {
317627              "approach": {}
317628            },
317629            "quantitativeAnalysis": {
317630              "graphics": {}
317631            },
317632            "considerations": {}
317633          }
317634        },
317635        {
317636          "type": "library",
317637          "bom-ref": "pkg:npm/eventsource@1.0.7?package-id=ab7df1636d12fa8b",
317638          "supplier": {},
317639          "name": "eventsource",
317640          "version": "1.0.7",
317641          "licenses": [
317642            {
317643              "license": {
317644                "id": "MIT"
317645              }
317646            }
317647          ],
317648          "cpe": "cpe:2.3:a:eventsource:eventsource:1.0.7:*:*:*:*:*:*:*",
317649          "purl": "pkg:npm/eventsource@1.0.7",
317650          "swid": {
317651            "attachment": {}
317652          },
317653          "pedigree": {},
317654          "evidence": {},
317655          "signature": {
317656            "signature": {
317657              "publicKey": {}
317658            }
317659          },
317660          "modelCard": {
317661            "modelParameters": {
317662              "approach": {}
317663            },
317664            "quantitativeAnalysis": {
317665              "graphics": {}
317666            },
317667            "considerations": {}
317668          }
317669        },
317670        {
317671          "type": "library",
317672          "bom-ref": "pkg:npm/evp_bytestokey@1.0.3?package-id=eca26733d6aad8c3",
317673          "supplier": {},
317674          "name": "evp_bytestokey",
317675          "version": "1.0.3",
317676          "licenses": [
317677            {
317678              "license": {
317679                "id": "MIT"
317680              }
317681            }
317682          ],
317683          "cpe": "cpe:2.3:a:evp-bytestokey:evp-bytestokey:1.0.3:*:*:*:*:*:*:*",
317684          "purl": "pkg:npm/evp_bytestokey@1.0.3",
317685          "swid": {
317686            "attachment": {}
317687          },
317688          "pedigree": {},
317689          "evidence": {},
317690          "signature": {
317691            "signature": {
317692              "publicKey": {}
317693            }
317694          },
317695          "modelCard": {
317696            "modelParameters": {
317697              "approach": {}
317698            },
317699            "quantitativeAnalysis": {
317700              "graphics": {}
317701            },
317702            "considerations": {}
317703          }
317704        },
317705        {
317706          "type": "library",
317707          "bom-ref": "pkg:npm/execa@1.0.0?package-id=4809ab789ba79f5d",
317708          "supplier": {},
317709          "name": "execa",
317710          "version": "1.0.0",
317711          "licenses": [
317712            {
317713              "license": {
317714                "id": "MIT"
317715              }
317716            }
317717          ],
317718          "cpe": "cpe:2.3:a:execa:execa:1.0.0:*:*:*:*:*:*:*",
317719          "purl": "pkg:npm/execa@1.0.0",
317720          "swid": {
317721            "attachment": {}
317722          },
317723          "pedigree": {},
317724          "evidence": {},
317725          "signature": {
317726            "signature": {
317727              "publicKey": {}
317728            }
317729          },
317730          "modelCard": {
317731            "modelParameters": {
317732              "approach": {}
317733            },
317734            "quantitativeAnalysis": {
317735              "graphics": {}
317736            },
317737            "considerations": {}
317738          }
317739        },
317740        {
317741          "type": "library",
317742          "bom-ref": "pkg:npm/exit@0.1.2?package-id=d6a21120268923a8",
317743          "supplier": {},
317744          "name": "exit",
317745          "version": "0.1.2",
317746          "licenses": [
317747            {
317748              "license": {
317749                "id": "MIT"
317750              }
317751            }
317752          ],
317753          "cpe": "cpe:2.3:a:exit:exit:0.1.2:*:*:*:*:*:*:*",
317754          "purl": "pkg:npm/exit@0.1.2",
317755          "swid": {
317756            "attachment": {}
317757          },
317758          "pedigree": {},
317759          "evidence": {},
317760          "signature": {
317761            "signature": {
317762              "publicKey": {}
317763            }
317764          },
317765          "modelCard": {
317766            "modelParameters": {
317767              "approach": {}
317768            },
317769            "quantitativeAnalysis": {
317770              "graphics": {}
317771            },
317772            "considerations": {}
317773          }
317774        },
317775        {
317776          "type": "library",
317777          "bom-ref": "pkg:npm/expand-brackets@2.1.4?package-id=c0fb9dbc998ab3dd",
317778          "supplier": {},
317779          "name": "expand-brackets",
317780          "version": "2.1.4",
317781          "licenses": [
317782            {
317783              "license": {
317784                "id": "MIT"
317785              }
317786            }
317787          ],
317788          "cpe": "cpe:2.3:a:expand-brackets:expand-brackets:2.1.4:*:*:*:*:*:*:*",
317789          "purl": "pkg:npm/expand-brackets@2.1.4",
317790          "swid": {
317791            "attachment": {}
317792          },
317793          "pedigree": {},
317794          "evidence": {},
317795          "signature": {
317796            "signature": {
317797              "publicKey": {}
317798            }
317799          },
317800          "modelCard": {
317801            "modelParameters": {
317802              "approach": {}
317803            },
317804            "quantitativeAnalysis": {
317805              "graphics": {}
317806            },
317807            "considerations": {}
317808          }
317809        },
317810        {
317811          "type": "library",
317812          "bom-ref": "pkg:npm/express@4.17.1?package-id=a8db0737ed48d8fc",
317813          "supplier": {},
317814          "name": "express",
317815          "version": "4.17.1",
317816          "licenses": [
317817            {
317818              "license": {
317819                "id": "MIT"
317820              }
317821            }
317822          ],
317823          "cpe": "cpe:2.3:a:express:express:4.17.1:*:*:*:*:*:*:*",
317824          "purl": "pkg:npm/express@4.17.1",
317825          "swid": {
317826            "attachment": {}
317827          },
317828          "pedigree": {},
317829          "evidence": {},
317830          "signature": {
317831            "signature": {
317832              "publicKey": {}
317833            }
317834          },
317835          "modelCard": {
317836            "modelParameters": {
317837              "approach": {}
317838            },
317839            "quantitativeAnalysis": {
317840              "graphics": {}
317841            },
317842            "considerations": {}
317843          }
317844        },
317845        {
317846          "type": "library",
317847          "bom-ref": "pkg:npm/ext@1.4.0?package-id=9361bb4450aa8cad",
317848          "supplier": {},
317849          "name": "ext",
317850          "version": "1.4.0",
317851          "licenses": [
317852            {
317853              "license": {
317854                "id": "ISC"
317855              }
317856            }
317857          ],
317858          "cpe": "cpe:2.3:a:ext:ext:1.4.0:*:*:*:*:*:*:*",
317859          "purl": "pkg:npm/ext@1.4.0",
317860          "swid": {
317861            "attachment": {}
317862          },
317863          "pedigree": {},
317864          "evidence": {},
317865          "signature": {
317866            "signature": {
317867              "publicKey": {}
317868            }
317869          },
317870          "modelCard": {
317871            "modelParameters": {
317872              "approach": {}
317873            },
317874            "quantitativeAnalysis": {
317875              "graphics": {}
317876            },
317877            "considerations": {}
317878          }
317879        },
317880        {
317881          "type": "library",
317882          "bom-ref": "pkg:npm/extend@3.0.2?package-id=1985b9e710517a00",
317883          "supplier": {},
317884          "name": "extend",
317885          "version": "3.0.2",
317886          "licenses": [
317887            {
317888              "license": {
317889                "id": "MIT"
317890              }
317891            }
317892          ],
317893          "cpe": "cpe:2.3:a:extend:extend:3.0.2:*:*:*:*:*:*:*",
317894          "purl": "pkg:npm/extend@3.0.2",
317895          "swid": {
317896            "attachment": {}
317897          },
317898          "pedigree": {},
317899          "evidence": {},
317900          "signature": {
317901            "signature": {
317902              "publicKey": {}
317903            }
317904          },
317905          "modelCard": {
317906            "modelParameters": {
317907              "approach": {}
317908            },
317909            "quantitativeAnalysis": {
317910              "graphics": {}
317911            },
317912            "considerations": {}
317913          }
317914        },
317915        {
317916          "type": "library",
317917          "bom-ref": "pkg:npm/extend-shallow@3.0.2?package-id=f35d4f258719094c",
317918          "supplier": {},
317919          "name": "extend-shallow",
317920          "version": "3.0.2",
317921          "licenses": [
317922            {
317923              "license": {
317924                "id": "MIT"
317925              }
317926            }
317927          ],
317928          "cpe": "cpe:2.3:a:extend-shallow:extend-shallow:3.0.2:*:*:*:*:*:*:*",
317929          "purl": "pkg:npm/extend-shallow@3.0.2",
317930          "swid": {
317931            "attachment": {}
317932          },
317933          "pedigree": {},
317934          "evidence": {},
317935          "signature": {
317936            "signature": {
317937              "publicKey": {}
317938            }
317939          },
317940          "modelCard": {
317941            "modelParameters": {
317942              "approach": {}
317943            },
317944            "quantitativeAnalysis": {
317945              "graphics": {}
317946            },
317947            "considerations": {}
317948          }
317949        },
317950        {
317951          "type": "library",
317952          "bom-ref": "pkg:npm/external-editor@3.1.0?package-id=557b6a5f06ccefd0",
317953          "supplier": {},
317954          "name": "external-editor",
317955          "version": "3.1.0",
317956          "licenses": [
317957            {
317958              "license": {
317959                "id": "MIT"
317960              }
317961            }
317962          ],
317963          "cpe": "cpe:2.3:a:external-editor:external-editor:3.1.0:*:*:*:*:*:*:*",
317964          "purl": "pkg:npm/external-editor@3.1.0",
317965          "swid": {
317966            "attachment": {}
317967          },
317968          "pedigree": {},
317969          "evidence": {},
317970          "signature": {
317971            "signature": {
317972              "publicKey": {}
317973            }
317974          },
317975          "modelCard": {
317976            "modelParameters": {
317977              "approach": {}
317978            },
317979            "quantitativeAnalysis": {
317980              "graphics": {}
317981            },
317982            "considerations": {}
317983          }
317984        },
317985        {
317986          "type": "library",
317987          "bom-ref": "pkg:npm/extglob@2.0.4?package-id=74526de1f9bd7e1a",
317988          "supplier": {},
317989          "name": "extglob",
317990          "version": "2.0.4",
317991          "licenses": [
317992            {
317993              "license": {
317994                "id": "MIT"
317995              }
317996            }
317997          ],
317998          "cpe": "cpe:2.3:a:extglob:extglob:2.0.4:*:*:*:*:*:*:*",
317999          "purl": "pkg:npm/extglob@2.0.4",
318000          "swid": {
318001            "attachment": {}
318002          },
318003          "pedigree": {},
318004          "evidence": {},
318005          "signature": {
318006            "signature": {
318007              "publicKey": {}
318008            }
318009          },
318010          "modelCard": {
318011            "modelParameters": {
318012              "approach": {}
318013            },
318014            "quantitativeAnalysis": {
318015              "graphics": {}
318016            },
318017            "considerations": {}
318018          }
318019        },
318020        {
318021          "type": "library",
318022          "bom-ref": "pkg:npm/extsprintf@1.3.0?package-id=6e3b15c094722f53",
318023          "supplier": {},
318024          "name": "extsprintf",
318025          "version": "1.3.0",
318026          "licenses": [
318027            {
318028              "license": {
318029                "id": "MIT"
318030              }
318031            }
318032          ],
318033          "cpe": "cpe:2.3:a:extsprintf:extsprintf:1.3.0:*:*:*:*:*:*:*",
318034          "purl": "pkg:npm/extsprintf@1.3.0",
318035          "swid": {
318036            "attachment": {}
318037          },
318038          "pedigree": {},
318039          "evidence": {},
318040          "signature": {
318041            "signature": {
318042              "publicKey": {}
318043            }
318044          },
318045          "modelCard": {
318046            "modelParameters": {
318047              "approach": {}
318048            },
318049            "quantitativeAnalysis": {
318050              "graphics": {}
318051            },
318052            "considerations": {}
318053          }
318054        },
318055        {
318056          "type": "library",
318057          "bom-ref": "pkg:npm/fast-deep-equal@3.1.1?package-id=9ce50f0b38646836",
318058          "supplier": {},
318059          "name": "fast-deep-equal",
318060          "version": "3.1.1",
318061          "licenses": [
318062            {
318063              "license": {
318064                "id": "MIT"
318065              }
318066            }
318067          ],
318068          "cpe": "cpe:2.3:a:fast-deep-equal:fast-deep-equal:3.1.1:*:*:*:*:*:*:*",
318069          "purl": "pkg:npm/fast-deep-equal@3.1.1",
318070          "swid": {
318071            "attachment": {}
318072          },
318073          "pedigree": {},
318074          "evidence": {},
318075          "signature": {
318076            "signature": {
318077              "publicKey": {}
318078            }
318079          },
318080          "modelCard": {
318081            "modelParameters": {
318082              "approach": {}
318083            },
318084            "quantitativeAnalysis": {
318085              "graphics": {}
318086            },
318087            "considerations": {}
318088          }
318089        },
318090        {
318091          "type": "library",
318092          "bom-ref": "pkg:npm/fast-json-patch@3.1.0?package-id=80f123e0b5cc3c38",
318093          "supplier": {},
318094          "name": "fast-json-patch",
318095          "version": "3.1.0",
318096          "licenses": [
318097            {
318098              "license": {
318099                "id": "MIT"
318100              }
318101            }
318102          ],
318103          "cpe": "cpe:2.3:a:fast-json-patch:fast-json-patch:3.1.0:*:*:*:*:*:*:*",
318104          "purl": "pkg:npm/fast-json-patch@3.1.0",
318105          "swid": {
318106            "attachment": {}
318107          },
318108          "pedigree": {},
318109          "evidence": {},
318110          "signature": {
318111            "signature": {
318112              "publicKey": {}
318113            }
318114          },
318115          "modelCard": {
318116            "modelParameters": {
318117              "approach": {}
318118            },
318119            "quantitativeAnalysis": {
318120              "graphics": {}
318121            },
318122            "considerations": {}
318123          }
318124        },
318125        {
318126          "type": "library",
318127          "bom-ref": "pkg:npm/fast-json-stable-stringify@2.0.0?package-id=4f3459ba7fc5deee",
318128          "supplier": {},
318129          "name": "fast-json-stable-stringify",
318130          "version": "2.0.0",
318131          "licenses": [
318132            {
318133              "license": {
318134                "id": "MIT"
318135              }
318136            }
318137          ],
318138          "cpe": "cpe:2.3:a:fast-json-stable-stringify:fast-json-stable-stringify:2.0.0:*:*:*:*:*:*:*",
318139          "purl": "pkg:npm/fast-json-stable-stringify@2.0.0",
318140          "swid": {
318141            "attachment": {}
318142          },
318143          "pedigree": {},
318144          "evidence": {},
318145          "signature": {
318146            "signature": {
318147              "publicKey": {}
318148            }
318149          },
318150          "modelCard": {
318151            "modelParameters": {
318152              "approach": {}
318153            },
318154            "quantitativeAnalysis": {
318155              "graphics": {}
318156            },
318157            "considerations": {}
318158          }
318159        },
318160        {
318161          "type": "library",
318162          "bom-ref": "pkg:npm/fastparse@1.1.2?package-id=352f889d2f2225e2",
318163          "supplier": {},
318164          "name": "fastparse",
318165          "version": "1.1.2",
318166          "licenses": [
318167            {
318168              "license": {
318169                "id": "MIT"
318170              }
318171            }
318172          ],
318173          "cpe": "cpe:2.3:a:fastparse:fastparse:1.1.2:*:*:*:*:*:*:*",
318174          "purl": "pkg:npm/fastparse@1.1.2",
318175          "swid": {
318176            "attachment": {}
318177          },
318178          "pedigree": {},
318179          "evidence": {},
318180          "signature": {
318181            "signature": {
318182              "publicKey": {}
318183            }
318184          },
318185          "modelCard": {
318186            "modelParameters": {
318187              "approach": {}
318188            },
318189            "quantitativeAnalysis": {
318190              "graphics": {}
318191            },
318192            "considerations": {}
318193          }
318194        },
318195        {
318196          "type": "library",
318197          "bom-ref": "pkg:npm/faye-websocket@0.10.0?package-id=fb84a187b1a22a5c",
318198          "supplier": {},
318199          "name": "faye-websocket",
318200          "version": "0.10.0",
318201          "licenses": [
318202            {
318203              "license": {
318204                "id": "MIT"
318205              }
318206            }
318207          ],
318208          "cpe": "cpe:2.3:a:faye-websocket:faye-websocket:0.10.0:*:*:*:*:*:*:*",
318209          "purl": "pkg:npm/faye-websocket@0.10.0",
318210          "swid": {
318211            "attachment": {}
318212          },
318213          "pedigree": {},
318214          "evidence": {},
318215          "signature": {
318216            "signature": {
318217              "publicKey": {}
318218            }
318219          },
318220          "modelCard": {
318221            "modelParameters": {
318222              "approach": {}
318223            },
318224            "quantitativeAnalysis": {
318225              "graphics": {}
318226            },
318227            "considerations": {}
318228          }
318229        },
318230        {
318231          "type": "library",
318232          "bom-ref": "pkg:npm/fflate@0.7.1?package-id=949186a3f746d697",
318233          "supplier": {},
318234          "name": "fflate",
318235          "version": "0.7.1",
318236          "licenses": [
318237            {
318238              "license": {
318239                "id": "MIT"
318240              }
318241            }
318242          ],
318243          "cpe": "cpe:2.3:a:fflate:fflate:0.7.1:*:*:*:*:*:*:*",
318244          "purl": "pkg:npm/fflate@0.7.1",
318245          "swid": {
318246            "attachment": {}
318247          },
318248          "pedigree": {},
318249          "evidence": {},
318250          "signature": {
318251            "signature": {
318252              "publicKey": {}
318253            }
318254          },
318255          "modelCard": {
318256            "modelParameters": {
318257              "approach": {}
318258            },
318259            "quantitativeAnalysis": {
318260              "graphics": {}
318261            },
318262            "considerations": {}
318263          }
318264        },
318265        {
318266          "type": "library",
318267          "bom-ref": "pkg:npm/figgy-pudding@3.5.2?package-id=17be0eee0f782243",
318268          "supplier": {},
318269          "name": "figgy-pudding",
318270          "version": "3.5.2",
318271          "licenses": [
318272            {
318273              "license": {
318274                "id": "ISC"
318275              }
318276            }
318277          ],
318278          "cpe": "cpe:2.3:a:figgy-pudding:figgy-pudding:3.5.2:*:*:*:*:*:*:*",
318279          "purl": "pkg:npm/figgy-pudding@3.5.2",
318280          "swid": {
318281            "attachment": {}
318282          },
318283          "pedigree": {},
318284          "evidence": {},
318285          "signature": {
318286            "signature": {
318287              "publicKey": {}
318288            }
318289          },
318290          "modelCard": {
318291            "modelParameters": {
318292              "approach": {}
318293            },
318294            "quantitativeAnalysis": {
318295              "graphics": {}
318296            },
318297            "considerations": {}
318298          }
318299        },
318300        {
318301          "type": "library",
318302          "bom-ref": "pkg:npm/figures@3.2.0?package-id=afe6d032392b9034",
318303          "supplier": {},
318304          "name": "figures",
318305          "version": "3.2.0",
318306          "licenses": [
318307            {
318308              "license": {
318309                "id": "MIT"
318310              }
318311            }
318312          ],
318313          "cpe": "cpe:2.3:a:figures:figures:3.2.0:*:*:*:*:*:*:*",
318314          "purl": "pkg:npm/figures@3.2.0",
318315          "swid": {
318316            "attachment": {}
318317          },
318318          "pedigree": {},
318319          "evidence": {},
318320          "signature": {
318321            "signature": {
318322              "publicKey": {}
318323            }
318324          },
318325          "modelCard": {
318326            "modelParameters": {
318327              "approach": {}
318328            },
318329            "quantitativeAnalysis": {
318330              "graphics": {}
318331            },
318332            "considerations": {}
318333          }
318334        },
318335        {
318336          "type": "library",
318337          "bom-ref": "pkg:npm/file-loader@6.0.0?package-id=d9065f556392274",
318338          "supplier": {},
318339          "name": "file-loader",
318340          "version": "6.0.0",
318341          "licenses": [
318342            {
318343              "license": {
318344                "id": "MIT"
318345              }
318346            }
318347          ],
318348          "cpe": "cpe:2.3:a:file-loader:file-loader:6.0.0:*:*:*:*:*:*:*",
318349          "purl": "pkg:npm/file-loader@6.0.0",
318350          "swid": {
318351            "attachment": {}
318352          },
318353          "pedigree": {},
318354          "evidence": {},
318355          "signature": {
318356            "signature": {
318357              "publicKey": {}
318358            }
318359          },
318360          "modelCard": {
318361            "modelParameters": {
318362              "approach": {}
318363            },
318364            "quantitativeAnalysis": {
318365              "graphics": {}
318366            },
318367            "considerations": {}
318368          }
318369        },
318370        {
318371          "type": "library",
318372          "bom-ref": "pkg:npm/file-saver@2.0.2?package-id=ba0d0f5a56dba4d3",
318373          "supplier": {},
318374          "name": "file-saver",
318375          "version": "2.0.2",
318376          "licenses": [
318377            {
318378              "license": {
318379                "id": "MIT"
318380              }
318381            }
318382          ],
318383          "cpe": "cpe:2.3:a:file-saver:file-saver:2.0.2:*:*:*:*:*:*:*",
318384          "purl": "pkg:npm/file-saver@2.0.2",
318385          "swid": {
318386            "attachment": {}
318387          },
318388          "pedigree": {},
318389          "evidence": {},
318390          "signature": {
318391            "signature": {
318392              "publicKey": {}
318393            }
318394          },
318395          "modelCard": {
318396            "modelParameters": {
318397              "approach": {}
318398            },
318399            "quantitativeAnalysis": {
318400              "graphics": {}
318401            },
318402            "considerations": {}
318403          }
318404        },
318405        {
318406          "type": "library",
318407          "bom-ref": "pkg:npm/file-uri-to-path@1.0.0?package-id=6cc68e3b181d5513",
318408          "supplier": {},
318409          "name": "file-uri-to-path",
318410          "version": "1.0.0",
318411          "cpe": "cpe:2.3:a:file-uri-to-path:file-uri-to-path:1.0.0:*:*:*:*:*:*:*",
318412          "purl": "pkg:npm/file-uri-to-path@1.0.0",
318413          "swid": {
318414            "attachment": {}
318415          },
318416          "pedigree": {},
318417          "evidence": {},
318418          "signature": {
318419            "signature": {
318420              "publicKey": {}
318421            }
318422          },
318423          "modelCard": {
318424            "modelParameters": {
318425              "approach": {}
318426            },
318427            "quantitativeAnalysis": {
318428              "graphics": {}
318429            },
318430            "considerations": {}
318431          }
318432        },
318433        {
318434          "type": "library",
318435          "bom-ref": "pkg:npm/fileset@2.0.3?package-id=b64ebdf4a96052cc",
318436          "supplier": {},
318437          "name": "fileset",
318438          "version": "2.0.3",
318439          "licenses": [
318440            {
318441              "license": {
318442                "id": "MIT"
318443              }
318444            }
318445          ],
318446          "cpe": "cpe:2.3:a:fileset:fileset:2.0.3:*:*:*:*:*:*:*",
318447          "purl": "pkg:npm/fileset@2.0.3",
318448          "swid": {
318449            "attachment": {}
318450          },
318451          "pedigree": {},
318452          "evidence": {},
318453          "signature": {
318454            "signature": {
318455              "publicKey": {}
318456            }
318457          },
318458          "modelCard": {
318459            "modelParameters": {
318460              "approach": {}
318461            },
318462            "quantitativeAnalysis": {
318463              "graphics": {}
318464            },
318465            "considerations": {}
318466          }
318467        },
318468        {
318469          "type": "library",
318470          "bom-ref": "pkg:npm/filesize@3.6.1?package-id=762606d64c7833dc",
318471          "supplier": {},
318472          "name": "filesize",
318473          "version": "3.6.1",
318474          "licenses": [
318475            {
318476              "license": {
318477                "id": "BSD-3-Clause"
318478              }
318479            }
318480          ],
318481          "cpe": "cpe:2.3:a:filesize:filesize:3.6.1:*:*:*:*:*:*:*",
318482          "purl": "pkg:npm/filesize@3.6.1",
318483          "swid": {
318484            "attachment": {}
318485          },
318486          "pedigree": {},
318487          "evidence": {},
318488          "signature": {
318489            "signature": {
318490              "publicKey": {}
318491            }
318492          },
318493          "modelCard": {
318494            "modelParameters": {
318495              "approach": {}
318496            },
318497            "quantitativeAnalysis": {
318498              "graphics": {}
318499            },
318500            "considerations": {}
318501          }
318502        },
318503        {
318504          "type": "library",
318505          "bom-ref": "pkg:npm/fill-range@7.0.1?package-id=22d5f2a796cd5138",
318506          "supplier": {},
318507          "name": "fill-range",
318508          "version": "7.0.1",
318509          "cpe": "cpe:2.3:a:fill-range:fill-range:7.0.1:*:*:*:*:*:*:*",
318510          "purl": "pkg:npm/fill-range@7.0.1",
318511          "swid": {
318512            "attachment": {}
318513          },
318514          "pedigree": {},
318515          "evidence": {},
318516          "signature": {
318517            "signature": {
318518              "publicKey": {}
318519            }
318520          },
318521          "modelCard": {
318522            "modelParameters": {
318523              "approach": {}
318524            },
318525            "quantitativeAnalysis": {
318526              "graphics": {}
318527            },
318528            "considerations": {}
318529          }
318530        },
318531        {
318532          "type": "library",
318533          "bom-ref": "pkg:npm/fill-range@7.0.1?package-id=ed1ef2c9380551d6",
318534          "supplier": {},
318535          "name": "fill-range",
318536          "version": "7.0.1",
318537          "licenses": [
318538            {
318539              "license": {
318540                "id": "MIT"
318541              }
318542            }
318543          ],
318544          "cpe": "cpe:2.3:a:fill-range:fill-range:7.0.1:*:*:*:*:*:*:*",
318545          "purl": "pkg:npm/fill-range@7.0.1",
318546          "swid": {
318547            "attachment": {}
318548          },
318549          "pedigree": {},
318550          "evidence": {},
318551          "signature": {
318552            "signature": {
318553              "publicKey": {}
318554            }
318555          },
318556          "modelCard": {
318557            "modelParameters": {
318558              "approach": {}
318559            },
318560            "quantitativeAnalysis": {
318561              "graphics": {}
318562            },
318563            "considerations": {}
318564          }
318565        },
318566        {
318567          "type": "library",
318568          "bom-ref": "pkg:npm/finalhandler@1.1.2?package-id=a9dedbe02122910c",
318569          "supplier": {},
318570          "name": "finalhandler",
318571          "version": "1.1.2",
318572          "licenses": [
318573            {
318574              "license": {
318575                "id": "MIT"
318576              }
318577            }
318578          ],
318579          "cpe": "cpe:2.3:a:finalhandler:finalhandler:1.1.2:*:*:*:*:*:*:*",
318580          "purl": "pkg:npm/finalhandler@1.1.2",
318581          "swid": {
318582            "attachment": {}
318583          },
318584          "pedigree": {},
318585          "evidence": {},
318586          "signature": {
318587            "signature": {
318588              "publicKey": {}
318589            }
318590          },
318591          "modelCard": {
318592            "modelParameters": {
318593              "approach": {}
318594            },
318595            "quantitativeAnalysis": {
318596              "graphics": {}
318597            },
318598            "considerations": {}
318599          }
318600        },
318601        {
318602          "type": "library",
318603          "bom-ref": "pkg:npm/find-cache-dir@3.3.1?package-id=23d9a6ad20be2a60",
318604          "supplier": {},
318605          "name": "find-cache-dir",
318606          "version": "3.3.1",
318607          "licenses": [
318608            {
318609              "license": {
318610                "id": "MIT"
318611              }
318612            }
318613          ],
318614          "cpe": "cpe:2.3:a:find-cache-dir:find-cache-dir:3.3.1:*:*:*:*:*:*:*",
318615          "purl": "pkg:npm/find-cache-dir@3.3.1",
318616          "swid": {
318617            "attachment": {}
318618          },
318619          "pedigree": {},
318620          "evidence": {},
318621          "signature": {
318622            "signature": {
318623              "publicKey": {}
318624            }
318625          },
318626          "modelCard": {
318627            "modelParameters": {
318628              "approach": {}
318629            },
318630            "quantitativeAnalysis": {
318631              "graphics": {}
318632            },
318633            "considerations": {}
318634          }
318635        },
318636        {
318637          "type": "library",
318638          "bom-ref": "pkg:npm/find-cache-dir@3.3.2?package-id=b622f76a51816d68",
318639          "supplier": {},
318640          "name": "find-cache-dir",
318641          "version": "3.3.2",
318642          "cpe": "cpe:2.3:a:find-cache-dir:find-cache-dir:3.3.2:*:*:*:*:*:*:*",
318643          "purl": "pkg:npm/find-cache-dir@3.3.2",
318644          "swid": {
318645            "attachment": {}
318646          },
318647          "pedigree": {},
318648          "evidence": {},
318649          "signature": {
318650            "signature": {
318651              "publicKey": {}
318652            }
318653          },
318654          "modelCard": {
318655            "modelParameters": {
318656              "approach": {}
318657            },
318658            "quantitativeAnalysis": {
318659              "graphics": {}
318660            },
318661            "considerations": {}
318662          }
318663        },
318664        {
318665          "type": "library",
318666          "bom-ref": "pkg:npm/find-parent-dir@0.3.0?package-id=1088f3f3c7aa92c4",
318667          "supplier": {},
318668          "name": "find-parent-dir",
318669          "version": "0.3.0",
318670          "licenses": [
318671            {
318672              "license": {
318673                "id": "MIT"
318674              }
318675            }
318676          ],
318677          "cpe": "cpe:2.3:a:find-parent-dir:find-parent-dir:0.3.0:*:*:*:*:*:*:*",
318678          "purl": "pkg:npm/find-parent-dir@0.3.0",
318679          "swid": {
318680            "attachment": {}
318681          },
318682          "pedigree": {},
318683          "evidence": {},
318684          "signature": {
318685            "signature": {
318686              "publicKey": {}
318687            }
318688          },
318689          "modelCard": {
318690            "modelParameters": {
318691              "approach": {}
318692            },
318693            "quantitativeAnalysis": {
318694              "graphics": {}
318695            },
318696            "considerations": {}
318697          }
318698        },
318699        {
318700          "type": "library",
318701          "bom-ref": "pkg:npm/find-up@3.0.0?package-id=658277bbddefb284",
318702          "supplier": {},
318703          "name": "find-up",
318704          "version": "3.0.0",
318705          "licenses": [
318706            {
318707              "license": {
318708                "id": "MIT"
318709              }
318710            }
318711          ],
318712          "cpe": "cpe:2.3:a:find-up:find-up:3.0.0:*:*:*:*:*:*:*",
318713          "purl": "pkg:npm/find-up@3.0.0",
318714          "swid": {
318715            "attachment": {}
318716          },
318717          "pedigree": {},
318718          "evidence": {},
318719          "signature": {
318720            "signature": {
318721              "publicKey": {}
318722            }
318723          },
318724          "modelCard": {
318725            "modelParameters": {
318726              "approach": {}
318727            },
318728            "quantitativeAnalysis": {
318729              "graphics": {}
318730            },
318731            "considerations": {}
318732          }
318733        },
318734        {
318735          "type": "library",
318736          "bom-ref": "pkg:npm/find-up@4.1.0?package-id=dd45a1ee8a127d0f",
318737          "supplier": {},
318738          "name": "find-up",
318739          "version": "4.1.0",
318740          "cpe": "cpe:2.3:a:find-up:find-up:4.1.0:*:*:*:*:*:*:*",
318741          "purl": "pkg:npm/find-up@4.1.0",
318742          "swid": {
318743            "attachment": {}
318744          },
318745          "pedigree": {},
318746          "evidence": {},
318747          "signature": {
318748            "signature": {
318749              "publicKey": {}
318750            }
318751          },
318752          "modelCard": {
318753            "modelParameters": {
318754              "approach": {}
318755            },
318756            "quantitativeAnalysis": {
318757              "graphics": {}
318758            },
318759            "considerations": {}
318760          }
318761        },
318762        {
318763          "type": "library",
318764          "bom-ref": "pkg:npm/find-yarn-workspace-root@1.2.1?package-id=9b45ec73f348d891",
318765          "supplier": {},
318766          "name": "find-yarn-workspace-root",
318767          "version": "1.2.1",
318768          "licenses": [
318769            {
318770              "license": {
318771                "id": "Apache-2.0"
318772              }
318773            }
318774          ],
318775          "cpe": "cpe:2.3:a:find-yarn-workspace-root:find-yarn-workspace-root:1.2.1:*:*:*:*:*:*:*",
318776          "purl": "pkg:npm/find-yarn-workspace-root@1.2.1",
318777          "swid": {
318778            "attachment": {}
318779          },
318780          "pedigree": {},
318781          "evidence": {},
318782          "signature": {
318783            "signature": {
318784              "publicKey": {}
318785            }
318786          },
318787          "modelCard": {
318788            "modelParameters": {
318789              "approach": {}
318790            },
318791            "quantitativeAnalysis": {
318792              "graphics": {}
318793            },
318794            "considerations": {}
318795          }
318796        },
318797        {
318798          "type": "library",
318799          "bom-ref": "pkg:npm/find-yarn-workspace-root@2.0.0?package-id=12d7019945f13d32",
318800          "supplier": {},
318801          "name": "find-yarn-workspace-root",
318802          "version": "2.0.0",
318803          "cpe": "cpe:2.3:a:find-yarn-workspace-root:find-yarn-workspace-root:2.0.0:*:*:*:*:*:*:*",
318804          "purl": "pkg:npm/find-yarn-workspace-root@2.0.0",
318805          "swid": {
318806            "attachment": {}
318807          },
318808          "pedigree": {},
318809          "evidence": {},
318810          "signature": {
318811            "signature": {
318812              "publicKey": {}
318813            }
318814          },
318815          "modelCard": {
318816            "modelParameters": {
318817              "approach": {}
318818            },
318819            "quantitativeAnalysis": {
318820              "graphics": {}
318821            },
318822            "considerations": {}
318823          }
318824        },
318825        {
318826          "type": "library",
318827          "bom-ref": "pkg:npm/flatted@2.0.2?package-id=d56eacb6f8d9f6b4",
318828          "supplier": {},
318829          "name": "flatted",
318830          "version": "2.0.2",
318831          "licenses": [
318832            {
318833              "license": {
318834                "id": "ISC"
318835              }
318836            }
318837          ],
318838          "cpe": "cpe:2.3:a:flatted:flatted:2.0.2:*:*:*:*:*:*:*",
318839          "purl": "pkg:npm/flatted@2.0.2",
318840          "swid": {
318841            "attachment": {}
318842          },
318843          "pedigree": {},
318844          "evidence": {},
318845          "signature": {
318846            "signature": {
318847              "publicKey": {}
318848            }
318849          },
318850          "modelCard": {
318851            "modelParameters": {
318852              "approach": {}
318853            },
318854            "quantitativeAnalysis": {
318855              "graphics": {}
318856            },
318857            "considerations": {}
318858          }
318859        },
318860        {
318861          "type": "library",
318862          "bom-ref": "pkg:npm/flush-write-stream@1.1.1?package-id=5227c57c78230933",
318863          "supplier": {},
318864          "name": "flush-write-stream",
318865          "version": "1.1.1",
318866          "licenses": [
318867            {
318868              "license": {
318869                "id": "MIT"
318870              }
318871            }
318872          ],
318873          "cpe": "cpe:2.3:a:flush-write-stream:flush-write-stream:1.1.1:*:*:*:*:*:*:*",
318874          "purl": "pkg:npm/flush-write-stream@1.1.1",
318875          "swid": {
318876            "attachment": {}
318877          },
318878          "pedigree": {},
318879          "evidence": {},
318880          "signature": {
318881            "signature": {
318882              "publicKey": {}
318883            }
318884          },
318885          "modelCard": {
318886            "modelParameters": {
318887              "approach": {}
318888            },
318889            "quantitativeAnalysis": {
318890              "graphics": {}
318891            },
318892            "considerations": {}
318893          }
318894        },
318895        {
318896          "type": "library",
318897          "bom-ref": "pkg:npm/follow-redirects@1.10.0?package-id=9eefc9ad21056f9f",
318898          "supplier": {},
318899          "name": "follow-redirects",
318900          "version": "1.10.0",
318901          "licenses": [
318902            {
318903              "license": {
318904                "id": "MIT"
318905              }
318906            }
318907          ],
318908          "cpe": "cpe:2.3:a:follow-redirects:follow-redirects:1.10.0:*:*:*:*:*:*:*",
318909          "purl": "pkg:npm/follow-redirects@1.10.0",
318910          "swid": {
318911            "attachment": {}
318912          },
318913          "pedigree": {},
318914          "evidence": {},
318915          "signature": {
318916            "signature": {
318917              "publicKey": {}
318918            }
318919          },
318920          "modelCard": {
318921            "modelParameters": {
318922              "approach": {}
318923            },
318924            "quantitativeAnalysis": {
318925              "graphics": {}
318926            },
318927            "considerations": {}
318928          }
318929        },
318930        {
318931          "type": "library",
318932          "bom-ref": "pkg:npm/for-in@1.0.2?package-id=8f39fcaa134d9342",
318933          "supplier": {},
318934          "name": "for-in",
318935          "version": "1.0.2",
318936          "licenses": [
318937            {
318938              "license": {
318939                "id": "MIT"
318940              }
318941            }
318942          ],
318943          "cpe": "cpe:2.3:a:for-in:for-in:1.0.2:*:*:*:*:*:*:*",
318944          "purl": "pkg:npm/for-in@1.0.2",
318945          "swid": {
318946            "attachment": {}
318947          },
318948          "pedigree": {},
318949          "evidence": {},
318950          "signature": {
318951            "signature": {
318952              "publicKey": {}
318953            }
318954          },
318955          "modelCard": {
318956            "modelParameters": {
318957              "approach": {}
318958            },
318959            "quantitativeAnalysis": {
318960              "graphics": {}
318961            },
318962            "considerations": {}
318963          }
318964        },
318965        {
318966          "type": "library",
318967          "bom-ref": "pkg:npm/foreground-child@2.0.0?package-id=fcda9784ab78b494",
318968          "supplier": {},
318969          "name": "foreground-child",
318970          "version": "2.0.0",
318971          "cpe": "cpe:2.3:a:foreground-child:foreground-child:2.0.0:*:*:*:*:*:*:*",
318972          "purl": "pkg:npm/foreground-child@2.0.0",
318973          "swid": {
318974            "attachment": {}
318975          },
318976          "pedigree": {},
318977          "evidence": {},
318978          "signature": {
318979            "signature": {
318980              "publicKey": {}
318981            }
318982          },
318983          "modelCard": {
318984            "modelParameters": {
318985              "approach": {}
318986            },
318987            "quantitativeAnalysis": {
318988              "graphics": {}
318989            },
318990            "considerations": {}
318991          }
318992        },
318993        {
318994          "type": "library",
318995          "bom-ref": "pkg:npm/forever-agent@0.6.1?package-id=ba24fa234f7565ab",
318996          "supplier": {},
318997          "name": "forever-agent",
318998          "version": "0.6.1",
318999          "licenses": [
319000            {
319001              "license": {
319002                "id": "Apache-2.0"
319003              }
319004            }
319005          ],
319006          "cpe": "cpe:2.3:a:forever-agent:forever-agent:0.6.1:*:*:*:*:*:*:*",
319007          "purl": "pkg:npm/forever-agent@0.6.1",
319008          "swid": {
319009            "attachment": {}
319010          },
319011          "pedigree": {},
319012          "evidence": {},
319013          "signature": {
319014            "signature": {
319015              "publicKey": {}
319016            }
319017          },
319018          "modelCard": {
319019            "modelParameters": {
319020              "approach": {}
319021            },
319022            "quantitativeAnalysis": {
319023              "graphics": {}
319024            },
319025            "considerations": {}
319026          }
319027        },
319028        {
319029          "type": "library",
319030          "bom-ref": "pkg:npm/form-data@2.3.3?package-id=e8062fbce3e10599",
319031          "supplier": {},
319032          "name": "form-data",
319033          "version": "2.3.3",
319034          "licenses": [
319035            {
319036              "license": {
319037                "id": "MIT"
319038              }
319039            }
319040          ],
319041          "cpe": "cpe:2.3:a:form-data:form-data:2.3.3:*:*:*:*:*:*:*",
319042          "purl": "pkg:npm/form-data@2.3.3",
319043          "swid": {
319044            "attachment": {}
319045          },
319046          "pedigree": {},
319047          "evidence": {},
319048          "signature": {
319049            "signature": {
319050              "publicKey": {}
319051            }
319052          },
319053          "modelCard": {
319054            "modelParameters": {
319055              "approach": {}
319056            },
319057            "quantitativeAnalysis": {
319058              "graphics": {}
319059            },
319060            "considerations": {}
319061          }
319062        },
319063        {
319064          "type": "library",
319065          "bom-ref": "pkg:npm/format-util@1.0.5?package-id=b3f003abff771603",
319066          "supplier": {},
319067          "name": "format-util",
319068          "version": "1.0.5",
319069          "licenses": [
319070            {
319071              "license": {
319072                "id": "MIT"
319073              }
319074            }
319075          ],
319076          "cpe": "cpe:2.3:a:format-util:format-util:1.0.5:*:*:*:*:*:*:*",
319077          "purl": "pkg:npm/format-util@1.0.5",
319078          "swid": {
319079            "attachment": {}
319080          },
319081          "pedigree": {},
319082          "evidence": {},
319083          "signature": {
319084            "signature": {
319085              "publicKey": {}
319086            }
319087          },
319088          "modelCard": {
319089            "modelParameters": {
319090              "approach": {}
319091            },
319092            "quantitativeAnalysis": {
319093              "graphics": {}
319094            },
319095            "considerations": {}
319096          }
319097        },
319098        {
319099          "type": "library",
319100          "bom-ref": "pkg:npm/forwarded@0.1.2?package-id=771e3f2fad0e4cb5",
319101          "supplier": {},
319102          "name": "forwarded",
319103          "version": "0.1.2",
319104          "licenses": [
319105            {
319106              "license": {
319107                "id": "MIT"
319108              }
319109            }
319110          ],
319111          "cpe": "cpe:2.3:a:forwarded:forwarded:0.1.2:*:*:*:*:*:*:*",
319112          "purl": "pkg:npm/forwarded@0.1.2",
319113          "swid": {
319114            "attachment": {}
319115          },
319116          "pedigree": {},
319117          "evidence": {},
319118          "signature": {
319119            "signature": {
319120              "publicKey": {}
319121            }
319122          },
319123          "modelCard": {
319124            "modelParameters": {
319125              "approach": {}
319126            },
319127            "quantitativeAnalysis": {
319128              "graphics": {}
319129            },
319130            "considerations": {}
319131          }
319132        },
319133        {
319134          "type": "library",
319135          "bom-ref": "pkg:npm/fragment-cache@0.2.1?package-id=cd2dd1c76259c538",
319136          "supplier": {},
319137          "name": "fragment-cache",
319138          "version": "0.2.1",
319139          "licenses": [
319140            {
319141              "license": {
319142                "id": "MIT"
319143              }
319144            }
319145          ],
319146          "cpe": "cpe:2.3:a:fragment-cache:fragment-cache:0.2.1:*:*:*:*:*:*:*",
319147          "purl": "pkg:npm/fragment-cache@0.2.1",
319148          "swid": {
319149            "attachment": {}
319150          },
319151          "pedigree": {},
319152          "evidence": {},
319153          "signature": {
319154            "signature": {
319155              "publicKey": {}
319156            }
319157          },
319158          "modelCard": {
319159            "modelParameters": {
319160              "approach": {}
319161            },
319162            "quantitativeAnalysis": {
319163              "graphics": {}
319164            },
319165            "considerations": {}
319166          }
319167        },
319168        {
319169          "type": "library",
319170          "bom-ref": "pkg:npm/fresh@0.5.2?package-id=64faea44e405af57",
319171          "supplier": {},
319172          "name": "fresh",
319173          "version": "0.5.2",
319174          "licenses": [
319175            {
319176              "license": {
319177                "id": "MIT"
319178              }
319179            }
319180          ],
319181          "cpe": "cpe:2.3:a:fresh:fresh:0.5.2:*:*:*:*:*:*:*",
319182          "purl": "pkg:npm/fresh@0.5.2",
319183          "swid": {
319184            "attachment": {}
319185          },
319186          "pedigree": {},
319187          "evidence": {},
319188          "signature": {
319189            "signature": {
319190              "publicKey": {}
319191            }
319192          },
319193          "modelCard": {
319194            "modelParameters": {
319195              "approach": {}
319196            },
319197            "quantitativeAnalysis": {
319198              "graphics": {}
319199            },
319200            "considerations": {}
319201          }
319202        },
319203        {
319204          "type": "library",
319205          "bom-ref": "pkg:npm/from2@2.3.0?package-id=8ebfbab1dd04d756",
319206          "supplier": {},
319207          "name": "from2",
319208          "version": "2.3.0",
319209          "licenses": [
319210            {
319211              "license": {
319212                "id": "MIT"
319213              }
319214            }
319215          ],
319216          "cpe": "cpe:2.3:a:from2:from2:2.3.0:*:*:*:*:*:*:*",
319217          "purl": "pkg:npm/from2@2.3.0",
319218          "swid": {
319219            "attachment": {}
319220          },
319221          "pedigree": {},
319222          "evidence": {},
319223          "signature": {
319224            "signature": {
319225              "publicKey": {}
319226            }
319227          },
319228          "modelCard": {
319229            "modelParameters": {
319230              "approach": {}
319231            },
319232            "quantitativeAnalysis": {
319233              "graphics": {}
319234            },
319235            "considerations": {}
319236          }
319237        },
319238        {
319239          "type": "library",
319240          "bom-ref": "pkg:npm/fromentries@1.3.2?package-id=415667e3595d1b75",
319241          "supplier": {},
319242          "name": "fromentries",
319243          "version": "1.3.2",
319244          "cpe": "cpe:2.3:a:fromentries:fromentries:1.3.2:*:*:*:*:*:*:*",
319245          "purl": "pkg:npm/fromentries@1.3.2",
319246          "swid": {
319247            "attachment": {}
319248          },
319249          "pedigree": {},
319250          "evidence": {},
319251          "signature": {
319252            "signature": {
319253              "publicKey": {}
319254            }
319255          },
319256          "modelCard": {
319257            "modelParameters": {
319258              "approach": {}
319259            },
319260            "quantitativeAnalysis": {
319261              "graphics": {}
319262            },
319263            "considerations": {}
319264          }
319265        },
319266        {
319267          "type": "library",
319268          "bom-ref": "pkg:npm/fs-extra@4.0.2?package-id=5cf09adc3d2c6dc0",
319269          "supplier": {},
319270          "name": "fs-extra",
319271          "version": "4.0.2",
319272          "licenses": [
319273            {
319274              "license": {
319275                "id": "MIT"
319276              }
319277            }
319278          ],
319279          "cpe": "cpe:2.3:a:fs-extra:fs-extra:4.0.2:*:*:*:*:*:*:*",
319280          "purl": "pkg:npm/fs-extra@4.0.2",
319281          "swid": {
319282            "attachment": {}
319283          },
319284          "pedigree": {},
319285          "evidence": {},
319286          "signature": {
319287            "signature": {
319288              "publicKey": {}
319289            }
319290          },
319291          "modelCard": {
319292            "modelParameters": {
319293              "approach": {}
319294            },
319295            "quantitativeAnalysis": {
319296              "graphics": {}
319297            },
319298            "considerations": {}
319299          }
319300        },
319301        {
319302          "type": "library",
319303          "bom-ref": "pkg:npm/fs-extra@7.0.1?package-id=e7687c3b14abdf8b",
319304          "supplier": {},
319305          "name": "fs-extra",
319306          "version": "7.0.1",
319307          "cpe": "cpe:2.3:a:fs-extra:fs-extra:7.0.1:*:*:*:*:*:*:*",
319308          "purl": "pkg:npm/fs-extra@7.0.1",
319309          "swid": {
319310            "attachment": {}
319311          },
319312          "pedigree": {},
319313          "evidence": {},
319314          "signature": {
319315            "signature": {
319316              "publicKey": {}
319317            }
319318          },
319319          "modelCard": {
319320            "modelParameters": {
319321              "approach": {}
319322            },
319323            "quantitativeAnalysis": {
319324              "graphics": {}
319325            },
319326            "considerations": {}
319327          }
319328        },
319329        {
319330          "type": "library",
319331          "bom-ref": "pkg:npm/fs-minipass@2.1.0?package-id=8d6dc03f1f15a124",
319332          "supplier": {},
319333          "name": "fs-minipass",
319334          "version": "2.1.0",
319335          "licenses": [
319336            {
319337              "license": {
319338                "id": "ISC"
319339              }
319340            }
319341          ],
319342          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:2.1.0:*:*:*:*:*:*:*",
319343          "purl": "pkg:npm/fs-minipass@2.1.0",
319344          "swid": {
319345            "attachment": {}
319346          },
319347          "pedigree": {},
319348          "evidence": {},
319349          "signature": {
319350            "signature": {
319351              "publicKey": {}
319352            }
319353          },
319354          "modelCard": {
319355            "modelParameters": {
319356              "approach": {}
319357            },
319358            "quantitativeAnalysis": {
319359              "graphics": {}
319360            },
319361            "considerations": {}
319362          }
319363        },
319364        {
319365          "type": "library",
319366          "bom-ref": "pkg:npm/fs-write-stream-atomic@1.0.10?package-id=34bcc9d39b7f883d",
319367          "supplier": {},
319368          "name": "fs-write-stream-atomic",
319369          "version": "1.0.10",
319370          "licenses": [
319371            {
319372              "license": {
319373                "id": "ISC"
319374              }
319375            }
319376          ],
319377          "cpe": "cpe:2.3:a:fs-write-stream-atomic:fs-write-stream-atomic:1.0.10:*:*:*:*:*:*:*",
319378          "purl": "pkg:npm/fs-write-stream-atomic@1.0.10",
319379          "swid": {
319380            "attachment": {}
319381          },
319382          "pedigree": {},
319383          "evidence": {},
319384          "signature": {
319385            "signature": {
319386              "publicKey": {}
319387            }
319388          },
319389          "modelCard": {
319390            "modelParameters": {
319391              "approach": {}
319392            },
319393            "quantitativeAnalysis": {
319394              "graphics": {}
319395            },
319396            "considerations": {}
319397          }
319398        },
319399        {
319400          "type": "library",
319401          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=3e6c94601df3fbb",
319402          "supplier": {},
319403          "name": "fs.realpath",
319404          "version": "1.0.0",
319405          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
319406          "purl": "pkg:npm/fs.realpath@1.0.0",
319407          "swid": {
319408            "attachment": {}
319409          },
319410          "pedigree": {},
319411          "evidence": {},
319412          "signature": {
319413            "signature": {
319414              "publicKey": {}
319415            }
319416          },
319417          "modelCard": {
319418            "modelParameters": {
319419              "approach": {}
319420            },
319421            "quantitativeAnalysis": {
319422              "graphics": {}
319423            },
319424            "considerations": {}
319425          }
319426        },
319427        {
319428          "type": "library",
319429          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=98f1c8011455e3c0",
319430          "supplier": {},
319431          "name": "fs.realpath",
319432          "version": "1.0.0",
319433          "licenses": [
319434            {
319435              "license": {
319436                "id": "ISC"
319437              }
319438            }
319439          ],
319440          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
319441          "purl": "pkg:npm/fs.realpath@1.0.0",
319442          "swid": {
319443            "attachment": {}
319444          },
319445          "pedigree": {},
319446          "evidence": {},
319447          "signature": {
319448            "signature": {
319449              "publicKey": {}
319450            }
319451          },
319452          "modelCard": {
319453            "modelParameters": {
319454              "approach": {}
319455            },
319456            "quantitativeAnalysis": {
319457              "graphics": {}
319458            },
319459            "considerations": {}
319460          }
319461        },
319462        {
319463          "type": "library",
319464          "bom-ref": "pkg:npm/fsevents@2.1.2?package-id=969df83614793d40",
319465          "supplier": {},
319466          "name": "fsevents",
319467          "version": "2.1.2",
319468          "cpe": "cpe:2.3:a:fsevents:fsevents:2.1.2:*:*:*:*:*:*:*",
319469          "purl": "pkg:npm/fsevents@2.1.2",
319470          "swid": {
319471            "attachment": {}
319472          },
319473          "pedigree": {},
319474          "evidence": {},
319475          "signature": {
319476            "signature": {
319477              "publicKey": {}
319478            }
319479          },
319480          "modelCard": {
319481            "modelParameters": {
319482              "approach": {}
319483            },
319484            "quantitativeAnalysis": {
319485              "graphics": {}
319486            },
319487            "considerations": {}
319488          }
319489        },
319490        {
319491          "type": "library",
319492          "bom-ref": "pkg:npm/fstream@1.0.12?package-id=6aa064dac7c55c50",
319493          "supplier": {},
319494          "name": "fstream",
319495          "version": "1.0.12",
319496          "licenses": [
319497            {
319498              "license": {
319499                "id": "ISC"
319500              }
319501            }
319502          ],
319503          "cpe": "cpe:2.3:a:fstream:fstream:1.0.12:*:*:*:*:*:*:*",
319504          "purl": "pkg:npm/fstream@1.0.12",
319505          "swid": {
319506            "attachment": {}
319507          },
319508          "pedigree": {},
319509          "evidence": {},
319510          "signature": {
319511            "signature": {
319512              "publicKey": {}
319513            }
319514          },
319515          "modelCard": {
319516            "modelParameters": {
319517              "approach": {}
319518            },
319519            "quantitativeAnalysis": {
319520              "graphics": {}
319521            },
319522            "considerations": {}
319523          }
319524        },
319525        {
319526          "type": "library",
319527          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=56c3a01f3c742c82",
319528          "supplier": {},
319529          "name": "function-bind",
319530          "version": "1.1.1",
319531          "licenses": [
319532            {
319533              "license": {
319534                "id": "MIT"
319535              }
319536            }
319537          ],
319538          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
319539          "purl": "pkg:npm/function-bind@1.1.1",
319540          "swid": {
319541            "attachment": {}
319542          },
319543          "pedigree": {},
319544          "evidence": {},
319545          "signature": {
319546            "signature": {
319547              "publicKey": {}
319548            }
319549          },
319550          "modelCard": {
319551            "modelParameters": {
319552              "approach": {}
319553            },
319554            "quantitativeAnalysis": {
319555              "graphics": {}
319556            },
319557            "considerations": {}
319558          }
319559        },
319560        {
319561          "type": "library",
319562          "bom-ref": "pkg:npm/fusioncharts@3.18.0?package-id=79a2c75fa4101f64",
319563          "supplier": {},
319564          "name": "fusioncharts",
319565          "version": "3.18.0",
319566          "licenses": [
319567            {
319568              "license": {
319569                "name": "http://www.fusioncharts.com/buy/"
319570              }
319571            }
319572          ],
319573          "cpe": "cpe:2.3:a:fusioncharts:fusioncharts:3.18.0:*:*:*:*:*:*:*",
319574          "purl": "pkg:npm/fusioncharts@3.18.0",
319575          "swid": {
319576            "attachment": {}
319577          },
319578          "pedigree": {},
319579          "evidence": {},
319580          "signature": {
319581            "signature": {
319582              "publicKey": {}
319583            }
319584          },
319585          "modelCard": {
319586            "modelParameters": {
319587              "approach": {}
319588            },
319589            "quantitativeAnalysis": {
319590              "graphics": {}
319591            },
319592            "considerations": {}
319593          }
319594        },
319595        {
319596          "type": "library",
319597          "bom-ref": "pkg:npm/gauge@2.7.4?package-id=8c30a5acf94c1546",
319598          "supplier": {},
319599          "name": "gauge",
319600          "version": "2.7.4",
319601          "licenses": [
319602            {
319603              "license": {
319604                "id": "ISC"
319605              }
319606            }
319607          ],
319608          "cpe": "cpe:2.3:a:gauge:gauge:2.7.4:*:*:*:*:*:*:*",
319609          "purl": "pkg:npm/gauge@2.7.4",
319610          "swid": {
319611            "attachment": {}
319612          },
319613          "pedigree": {},
319614          "evidence": {},
319615          "signature": {
319616            "signature": {
319617              "publicKey": {}
319618            }
319619          },
319620          "modelCard": {
319621            "modelParameters": {
319622              "approach": {}
319623            },
319624            "quantitativeAnalysis": {
319625              "graphics": {}
319626            },
319627            "considerations": {}
319628          }
319629        },
319630        {
319631          "type": "library",
319632          "bom-ref": "pkg:npm/gaze@1.1.3?package-id=77dee6cc44284377",
319633          "supplier": {},
319634          "name": "gaze",
319635          "version": "1.1.3",
319636          "licenses": [
319637            {
319638              "license": {
319639                "id": "MIT"
319640              }
319641            }
319642          ],
319643          "cpe": "cpe:2.3:a:gaze:gaze:1.1.3:*:*:*:*:*:*:*",
319644          "purl": "pkg:npm/gaze@1.1.3",
319645          "swid": {
319646            "attachment": {}
319647          },
319648          "pedigree": {},
319649          "evidence": {},
319650          "signature": {
319651            "signature": {
319652              "publicKey": {}
319653            }
319654          },
319655          "modelCard": {
319656            "modelParameters": {
319657              "approach": {}
319658            },
319659            "quantitativeAnalysis": {
319660              "graphics": {}
319661            },
319662            "considerations": {}
319663          }
319664        },
319665        {
319666          "type": "library",
319667          "bom-ref": "pkg:npm/genfun@5.0.0?package-id=d83ab6667c0d43f0",
319668          "supplier": {},
319669          "name": "genfun",
319670          "version": "5.0.0",
319671          "licenses": [
319672            {
319673              "license": {
319674                "id": "MIT"
319675              }
319676            }
319677          ],
319678          "cpe": "cpe:2.3:a:genfun:genfun:5.0.0:*:*:*:*:*:*:*",
319679          "purl": "pkg:npm/genfun@5.0.0",
319680          "swid": {
319681            "attachment": {}
319682          },
319683          "pedigree": {},
319684          "evidence": {},
319685          "signature": {
319686            "signature": {
319687              "publicKey": {}
319688            }
319689          },
319690          "modelCard": {
319691            "modelParameters": {
319692              "approach": {}
319693            },
319694            "quantitativeAnalysis": {
319695              "graphics": {}
319696            },
319697            "considerations": {}
319698          }
319699        },
319700        {
319701          "type": "library",
319702          "bom-ref": "pkg:npm/gensync@1.0.0-beta.1?package-id=962d83779c6bb8ac",
319703          "supplier": {},
319704          "name": "gensync",
319705          "version": "1.0.0-beta.1",
319706          "licenses": [
319707            {
319708              "license": {
319709                "id": "MIT"
319710              }
319711            }
319712          ],
319713          "cpe": "cpe:2.3:a:gensync:gensync:1.0.0-beta.1:*:*:*:*:*:*:*",
319714          "purl": "pkg:npm/gensync@1.0.0-beta.1",
319715          "swid": {
319716            "attachment": {}
319717          },
319718          "pedigree": {},
319719          "evidence": {},
319720          "signature": {
319721            "signature": {
319722              "publicKey": {}
319723            }
319724          },
319725          "modelCard": {
319726            "modelParameters": {
319727              "approach": {}
319728            },
319729            "quantitativeAnalysis": {
319730              "graphics": {}
319731            },
319732            "considerations": {}
319733          }
319734        },
319735        {
319736          "type": "library",
319737          "bom-ref": "pkg:npm/gensync@1.0.0-beta.2?package-id=25e40c6ab36609ba",
319738          "supplier": {},
319739          "name": "gensync",
319740          "version": "1.0.0-beta.2",
319741          "cpe": "cpe:2.3:a:gensync:gensync:1.0.0-beta.2:*:*:*:*:*:*:*",
319742          "purl": "pkg:npm/gensync@1.0.0-beta.2",
319743          "swid": {
319744            "attachment": {}
319745          },
319746          "pedigree": {},
319747          "evidence": {},
319748          "signature": {
319749            "signature": {
319750              "publicKey": {}
319751            }
319752          },
319753          "modelCard": {
319754            "modelParameters": {
319755              "approach": {}
319756            },
319757            "quantitativeAnalysis": {
319758              "graphics": {}
319759            },
319760            "considerations": {}
319761          }
319762        },
319763        {
319764          "type": "library",
319765          "bom-ref": "pkg:npm/get-caller-file@1.0.3?package-id=9a46bf030fd683d8",
319766          "supplier": {},
319767          "name": "get-caller-file",
319768          "version": "1.0.3",
319769          "licenses": [
319770            {
319771              "license": {
319772                "id": "ISC"
319773              }
319774            }
319775          ],
319776          "cpe": "cpe:2.3:a:get-caller-file:get-caller-file:1.0.3:*:*:*:*:*:*:*",
319777          "purl": "pkg:npm/get-caller-file@1.0.3",
319778          "swid": {
319779            "attachment": {}
319780          },
319781          "pedigree": {},
319782          "evidence": {},
319783          "signature": {
319784            "signature": {
319785              "publicKey": {}
319786            }
319787          },
319788          "modelCard": {
319789            "modelParameters": {
319790              "approach": {}
319791            },
319792            "quantitativeAnalysis": {
319793              "graphics": {}
319794            },
319795            "considerations": {}
319796          }
319797        },
319798        {
319799          "type": "library",
319800          "bom-ref": "pkg:npm/get-caller-file@2.0.5?package-id=b105eb74e25a730",
319801          "supplier": {},
319802          "name": "get-caller-file",
319803          "version": "2.0.5",
319804          "cpe": "cpe:2.3:a:get-caller-file:get-caller-file:2.0.5:*:*:*:*:*:*:*",
319805          "purl": "pkg:npm/get-caller-file@2.0.5",
319806          "swid": {
319807            "attachment": {}
319808          },
319809          "pedigree": {},
319810          "evidence": {},
319811          "signature": {
319812            "signature": {
319813              "publicKey": {}
319814            }
319815          },
319816          "modelCard": {
319817            "modelParameters": {
319818              "approach": {}
319819            },
319820            "quantitativeAnalysis": {
319821              "graphics": {}
319822            },
319823            "considerations": {}
319824          }
319825        },
319826        {
319827          "type": "library",
319828          "bom-ref": "pkg:npm/get-package-type@0.1.0?package-id=e9cd5e6d06b22624",
319829          "supplier": {},
319830          "name": "get-package-type",
319831          "version": "0.1.0",
319832          "cpe": "cpe:2.3:a:get-package-type:get-package-type:0.1.0:*:*:*:*:*:*:*",
319833          "purl": "pkg:npm/get-package-type@0.1.0",
319834          "swid": {
319835            "attachment": {}
319836          },
319837          "pedigree": {},
319838          "evidence": {},
319839          "signature": {
319840            "signature": {
319841              "publicKey": {}
319842            }
319843          },
319844          "modelCard": {
319845            "modelParameters": {
319846              "approach": {}
319847            },
319848            "quantitativeAnalysis": {
319849              "graphics": {}
319850            },
319851            "considerations": {}
319852          }
319853        },
319854        {
319855          "type": "library",
319856          "bom-ref": "pkg:npm/get-stdin@4.0.1?package-id=3e8600b4d1a888c2",
319857          "supplier": {},
319858          "name": "get-stdin",
319859          "version": "4.0.1",
319860          "licenses": [
319861            {
319862              "license": {
319863                "id": "MIT"
319864              }
319865            }
319866          ],
319867          "cpe": "cpe:2.3:a:get-stdin:get-stdin:4.0.1:*:*:*:*:*:*:*",
319868          "purl": "pkg:npm/get-stdin@4.0.1",
319869          "swid": {
319870            "attachment": {}
319871          },
319872          "pedigree": {},
319873          "evidence": {},
319874          "signature": {
319875            "signature": {
319876              "publicKey": {}
319877            }
319878          },
319879          "modelCard": {
319880            "modelParameters": {
319881              "approach": {}
319882            },
319883            "quantitativeAnalysis": {
319884              "graphics": {}
319885            },
319886            "considerations": {}
319887          }
319888        },
319889        {
319890          "type": "library",
319891          "bom-ref": "pkg:npm/get-stream@4.1.0?package-id=674f46c3d4e751aa",
319892          "supplier": {},
319893          "name": "get-stream",
319894          "version": "4.1.0",
319895          "licenses": [
319896            {
319897              "license": {
319898                "id": "MIT"
319899              }
319900            }
319901          ],
319902          "cpe": "cpe:2.3:a:get-stream:get-stream:4.1.0:*:*:*:*:*:*:*",
319903          "purl": "pkg:npm/get-stream@4.1.0",
319904          "swid": {
319905            "attachment": {}
319906          },
319907          "pedigree": {},
319908          "evidence": {},
319909          "signature": {
319910            "signature": {
319911              "publicKey": {}
319912            }
319913          },
319914          "modelCard": {
319915            "modelParameters": {
319916              "approach": {}
319917            },
319918            "quantitativeAnalysis": {
319919              "graphics": {}
319920            },
319921            "considerations": {}
319922          }
319923        },
319924        {
319925          "type": "library",
319926          "bom-ref": "pkg:npm/get-value@2.0.6?package-id=1e25415a5886166d",
319927          "supplier": {},
319928          "name": "get-value",
319929          "version": "2.0.6",
319930          "licenses": [
319931            {
319932              "license": {
319933                "id": "MIT"
319934              }
319935            }
319936          ],
319937          "cpe": "cpe:2.3:a:get-value:get-value:2.0.6:*:*:*:*:*:*:*",
319938          "purl": "pkg:npm/get-value@2.0.6",
319939          "swid": {
319940            "attachment": {}
319941          },
319942          "pedigree": {},
319943          "evidence": {},
319944          "signature": {
319945            "signature": {
319946              "publicKey": {}
319947            }
319948          },
319949          "modelCard": {
319950            "modelParameters": {
319951              "approach": {}
319952            },
319953            "quantitativeAnalysis": {
319954              "graphics": {}
319955            },
319956            "considerations": {}
319957          }
319958        },
319959        {
319960          "type": "library",
319961          "bom-ref": "pkg:npm/getpass@0.1.7?package-id=8fbe9dc611eb5d31",
319962          "supplier": {},
319963          "name": "getpass",
319964          "version": "0.1.7",
319965          "licenses": [
319966            {
319967              "license": {
319968                "id": "MIT"
319969              }
319970            }
319971          ],
319972          "cpe": "cpe:2.3:a:getpass:getpass:0.1.7:*:*:*:*:*:*:*",
319973          "purl": "pkg:npm/getpass@0.1.7",
319974          "swid": {
319975            "attachment": {}
319976          },
319977          "pedigree": {},
319978          "evidence": {},
319979          "signature": {
319980            "signature": {
319981              "publicKey": {}
319982            }
319983          },
319984          "modelCard": {
319985            "modelParameters": {
319986              "approach": {}
319987            },
319988            "quantitativeAnalysis": {
319989              "graphics": {}
319990            },
319991            "considerations": {}
319992          }
319993        },
319994        {
319995          "type": "library",
319996          "bom-ref": "pkg:npm/glob@7.1.5?package-id=d49b5710e254b035",
319997          "supplier": {},
319998          "name": "glob",
319999          "version": "7.1.5",
320000          "licenses": [
320001            {
320002              "license": {
320003                "id": "ISC"
320004              }
320005            }
320006          ],
320007          "cpe": "cpe:2.3:a:glob:glob:7.1.5:*:*:*:*:*:*:*",
320008          "purl": "pkg:npm/glob@7.1.5",
320009          "swid": {
320010            "attachment": {}
320011          },
320012          "pedigree": {},
320013          "evidence": {},
320014          "signature": {
320015            "signature": {
320016              "publicKey": {}
320017            }
320018          },
320019          "modelCard": {
320020            "modelParameters": {
320021              "approach": {}
320022            },
320023            "quantitativeAnalysis": {
320024              "graphics": {}
320025            },
320026            "considerations": {}
320027          }
320028        },
320029        {
320030          "type": "library",
320031          "bom-ref": "pkg:npm/glob@7.2.0?package-id=2ce135fbc8852949",
320032          "supplier": {},
320033          "name": "glob",
320034          "version": "7.2.0",
320035          "cpe": "cpe:2.3:a:glob:glob:7.2.0:*:*:*:*:*:*:*",
320036          "purl": "pkg:npm/glob@7.2.0",
320037          "swid": {
320038            "attachment": {}
320039          },
320040          "pedigree": {},
320041          "evidence": {},
320042          "signature": {
320043            "signature": {
320044              "publicKey": {}
320045            }
320046          },
320047          "modelCard": {
320048            "modelParameters": {
320049              "approach": {}
320050            },
320051            "quantitativeAnalysis": {
320052              "graphics": {}
320053            },
320054            "considerations": {}
320055          }
320056        },
320057        {
320058          "type": "library",
320059          "bom-ref": "pkg:npm/glob-parent@3.1.0?package-id=f0170f0368b7e6d1",
320060          "supplier": {},
320061          "name": "glob-parent",
320062          "version": "3.1.0",
320063          "licenses": [
320064            {
320065              "license": {
320066                "id": "ISC"
320067              }
320068            }
320069          ],
320070          "cpe": "cpe:2.3:a:glob-parent:glob-parent:3.1.0:*:*:*:*:*:*:*",
320071          "purl": "pkg:npm/glob-parent@3.1.0",
320072          "swid": {
320073            "attachment": {}
320074          },
320075          "pedigree": {},
320076          "evidence": {},
320077          "signature": {
320078            "signature": {
320079              "publicKey": {}
320080            }
320081          },
320082          "modelCard": {
320083            "modelParameters": {
320084              "approach": {}
320085            },
320086            "quantitativeAnalysis": {
320087              "graphics": {}
320088            },
320089            "considerations": {}
320090          }
320091        },
320092        {
320093          "type": "library",
320094          "bom-ref": "pkg:npm/globals@11.12.0?package-id=68db12ff2e119d71",
320095          "supplier": {},
320096          "name": "globals",
320097          "version": "11.12.0",
320098          "cpe": "cpe:2.3:a:globals:globals:11.12.0:*:*:*:*:*:*:*",
320099          "purl": "pkg:npm/globals@11.12.0",
320100          "swid": {
320101            "attachment": {}
320102          },
320103          "pedigree": {},
320104          "evidence": {},
320105          "signature": {
320106            "signature": {
320107              "publicKey": {}
320108            }
320109          },
320110          "modelCard": {
320111            "modelParameters": {
320112              "approach": {}
320113            },
320114            "quantitativeAnalysis": {
320115              "graphics": {}
320116            },
320117            "considerations": {}
320118          }
320119        },
320120        {
320121          "type": "library",
320122          "bom-ref": "pkg:npm/globals@11.12.0?package-id=cb72971e8458cd68",
320123          "supplier": {},
320124          "name": "globals",
320125          "version": "11.12.0",
320126          "licenses": [
320127            {
320128              "license": {
320129                "id": "MIT"
320130              }
320131            }
320132          ],
320133          "cpe": "cpe:2.3:a:globals:globals:11.12.0:*:*:*:*:*:*:*",
320134          "purl": "pkg:npm/globals@11.12.0",
320135          "swid": {
320136            "attachment": {}
320137          },
320138          "pedigree": {},
320139          "evidence": {},
320140          "signature": {
320141            "signature": {
320142              "publicKey": {}
320143            }
320144          },
320145          "modelCard": {
320146            "modelParameters": {
320147              "approach": {}
320148            },
320149            "quantitativeAnalysis": {
320150              "graphics": {}
320151            },
320152            "considerations": {}
320153          }
320154        },
320155        {
320156          "type": "library",
320157          "bom-ref": "pkg:npm/globby@7.1.1?package-id=b1ffbf24ffadb19a",
320158          "supplier": {},
320159          "name": "globby",
320160          "version": "7.1.1",
320161          "licenses": [
320162            {
320163              "license": {
320164                "id": "MIT"
320165              }
320166            }
320167          ],
320168          "cpe": "cpe:2.3:a:globby:globby:7.1.1:*:*:*:*:*:*:*",
320169          "purl": "pkg:npm/globby@7.1.1",
320170          "swid": {
320171            "attachment": {}
320172          },
320173          "pedigree": {},
320174          "evidence": {},
320175          "signature": {
320176            "signature": {
320177              "publicKey": {}
320178            }
320179          },
320180          "modelCard": {
320181            "modelParameters": {
320182              "approach": {}
320183            },
320184            "quantitativeAnalysis": {
320185              "graphics": {}
320186            },
320187            "considerations": {}
320188          }
320189        },
320190        {
320191          "type": "library",
320192          "bom-ref": "pkg:npm/globule@1.3.2?package-id=fffc322bb09b7af1",
320193          "supplier": {},
320194          "name": "globule",
320195          "version": "1.3.2",
320196          "licenses": [
320197            {
320198              "license": {
320199                "id": "MIT"
320200              }
320201            }
320202          ],
320203          "cpe": "cpe:2.3:a:globule:globule:1.3.2:*:*:*:*:*:*:*",
320204          "purl": "pkg:npm/globule@1.3.2",
320205          "swid": {
320206            "attachment": {}
320207          },
320208          "pedigree": {},
320209          "evidence": {},
320210          "signature": {
320211            "signature": {
320212              "publicKey": {}
320213            }
320214          },
320215          "modelCard": {
320216            "modelParameters": {
320217              "approach": {}
320218            },
320219            "quantitativeAnalysis": {
320220              "graphics": {}
320221            },
320222            "considerations": {}
320223          }
320224        },
320225        {
320226          "type": "library",
320227          "bom-ref": "pkg:npm/graceful-fs@4.2.3?package-id=24f7ee8365a5fa0f",
320228          "supplier": {},
320229          "name": "graceful-fs",
320230          "version": "4.2.3",
320231          "licenses": [
320232            {
320233              "license": {
320234                "id": "ISC"
320235              }
320236            }
320237          ],
320238          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.3:*:*:*:*:*:*:*",
320239          "purl": "pkg:npm/graceful-fs@4.2.3",
320240          "swid": {
320241            "attachment": {}
320242          },
320243          "pedigree": {},
320244          "evidence": {},
320245          "signature": {
320246            "signature": {
320247              "publicKey": {}
320248            }
320249          },
320250          "modelCard": {
320251            "modelParameters": {
320252              "approach": {}
320253            },
320254            "quantitativeAnalysis": {
320255              "graphics": {}
320256            },
320257            "considerations": {}
320258          }
320259        },
320260        {
320261          "type": "library",
320262          "bom-ref": "pkg:npm/graceful-fs@4.2.8?package-id=2c7402059e043bcf",
320263          "supplier": {},
320264          "name": "graceful-fs",
320265          "version": "4.2.8",
320266          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.8:*:*:*:*:*:*:*",
320267          "purl": "pkg:npm/graceful-fs@4.2.8",
320268          "swid": {
320269            "attachment": {}
320270          },
320271          "pedigree": {},
320272          "evidence": {},
320273          "signature": {
320274            "signature": {
320275              "publicKey": {}
320276            }
320277          },
320278          "modelCard": {
320279            "modelParameters": {
320280              "approach": {}
320281            },
320282            "quantitativeAnalysis": {
320283              "graphics": {}
320284            },
320285            "considerations": {}
320286          }
320287        },
320288        {
320289          "type": "library",
320290          "bom-ref": "pkg:npm/gzip-size@5.1.1?package-id=6c96e7520ae9839f",
320291          "supplier": {},
320292          "name": "gzip-size",
320293          "version": "5.1.1",
320294          "licenses": [
320295            {
320296              "license": {
320297                "id": "MIT"
320298              }
320299            }
320300          ],
320301          "cpe": "cpe:2.3:a:gzip-size:gzip-size:5.1.1:*:*:*:*:*:*:*",
320302          "purl": "pkg:npm/gzip-size@5.1.1",
320303          "swid": {
320304            "attachment": {}
320305          },
320306          "pedigree": {},
320307          "evidence": {},
320308          "signature": {
320309            "signature": {
320310              "publicKey": {}
320311            }
320312          },
320313          "modelCard": {
320314            "modelParameters": {
320315              "approach": {}
320316            },
320317            "quantitativeAnalysis": {
320318              "graphics": {}
320319            },
320320            "considerations": {}
320321          }
320322        },
320323        {
320324          "type": "library",
320325          "bom-ref": "pkg:npm/hammerjs@2.0.8?package-id=e03a8be071ae6ace",
320326          "supplier": {},
320327          "name": "hammerjs",
320328          "version": "2.0.8",
320329          "licenses": [
320330            {
320331              "license": {
320332                "id": "MIT"
320333              }
320334            }
320335          ],
320336          "cpe": "cpe:2.3:a:hammerjs:hammerjs:2.0.8:*:*:*:*:*:*:*",
320337          "purl": "pkg:npm/hammerjs@2.0.8",
320338          "swid": {
320339            "attachment": {}
320340          },
320341          "pedigree": {},
320342          "evidence": {},
320343          "signature": {
320344            "signature": {
320345              "publicKey": {}
320346            }
320347          },
320348          "modelCard": {
320349            "modelParameters": {
320350              "approach": {}
320351            },
320352            "quantitativeAnalysis": {
320353              "graphics": {}
320354            },
320355            "considerations": {}
320356          }
320357        },
320358        {
320359          "type": "library",
320360          "bom-ref": "pkg:npm/handle-thing@2.0.1?package-id=1a7091dfed90703f",
320361          "supplier": {},
320362          "name": "handle-thing",
320363          "version": "2.0.1",
320364          "licenses": [
320365            {
320366              "license": {
320367                "id": "MIT"
320368              }
320369            }
320370          ],
320371          "cpe": "cpe:2.3:a:handle-thing:handle-thing:2.0.1:*:*:*:*:*:*:*",
320372          "purl": "pkg:npm/handle-thing@2.0.1",
320373          "swid": {
320374            "attachment": {}
320375          },
320376          "pedigree": {},
320377          "evidence": {},
320378          "signature": {
320379            "signature": {
320380              "publicKey": {}
320381            }
320382          },
320383          "modelCard": {
320384            "modelParameters": {
320385              "approach": {}
320386            },
320387            "quantitativeAnalysis": {
320388              "graphics": {}
320389            },
320390            "considerations": {}
320391          }
320392        },
320393        {
320394          "type": "library",
320395          "bom-ref": "pkg:npm/har-schema@2.0.0?package-id=b1a2ebde8b267bd6",
320396          "supplier": {},
320397          "name": "har-schema",
320398          "version": "2.0.0",
320399          "licenses": [
320400            {
320401              "license": {
320402                "id": "ISC"
320403              }
320404            }
320405          ],
320406          "cpe": "cpe:2.3:a:har-schema:har-schema:2.0.0:*:*:*:*:*:*:*",
320407          "purl": "pkg:npm/har-schema@2.0.0",
320408          "swid": {
320409            "attachment": {}
320410          },
320411          "pedigree": {},
320412          "evidence": {},
320413          "signature": {
320414            "signature": {
320415              "publicKey": {}
320416            }
320417          },
320418          "modelCard": {
320419            "modelParameters": {
320420              "approach": {}
320421            },
320422            "quantitativeAnalysis": {
320423              "graphics": {}
320424            },
320425            "considerations": {}
320426          }
320427        },
320428        {
320429          "type": "library",
320430          "bom-ref": "pkg:npm/har-validator@5.1.3?package-id=ac87909b9cd270ec",
320431          "supplier": {},
320432          "name": "har-validator",
320433          "version": "5.1.3",
320434          "licenses": [
320435            {
320436              "license": {
320437                "id": "MIT"
320438              }
320439            }
320440          ],
320441          "cpe": "cpe:2.3:a:har-validator:har-validator:5.1.3:*:*:*:*:*:*:*",
320442          "purl": "pkg:npm/har-validator@5.1.3",
320443          "swid": {
320444            "attachment": {}
320445          },
320446          "pedigree": {},
320447          "evidence": {},
320448          "signature": {
320449            "signature": {
320450              "publicKey": {}
320451            }
320452          },
320453          "modelCard": {
320454            "modelParameters": {
320455              "approach": {}
320456            },
320457            "quantitativeAnalysis": {
320458              "graphics": {}
320459            },
320460            "considerations": {}
320461          }
320462        },
320463        {
320464          "type": "library",
320465          "bom-ref": "pkg:npm/has@1.0.3?package-id=8c4936faeea3f824",
320466          "supplier": {},
320467          "name": "has",
320468          "version": "1.0.3",
320469          "licenses": [
320470            {
320471              "license": {
320472                "id": "MIT"
320473              }
320474            }
320475          ],
320476          "cpe": "cpe:2.3:a:has:has:1.0.3:*:*:*:*:*:*:*",
320477          "purl": "pkg:npm/has@1.0.3",
320478          "swid": {
320479            "attachment": {}
320480          },
320481          "pedigree": {},
320482          "evidence": {},
320483          "signature": {
320484            "signature": {
320485              "publicKey": {}
320486            }
320487          },
320488          "modelCard": {
320489            "modelParameters": {
320490              "approach": {}
320491            },
320492            "quantitativeAnalysis": {
320493              "graphics": {}
320494            },
320495            "considerations": {}
320496          }
320497        },
320498        {
320499          "type": "library",
320500          "bom-ref": "pkg:npm/has-ansi@2.0.0?package-id=849e1c8d8e724418",
320501          "supplier": {},
320502          "name": "has-ansi",
320503          "version": "2.0.0",
320504          "licenses": [
320505            {
320506              "license": {
320507                "id": "MIT"
320508              }
320509            }
320510          ],
320511          "cpe": "cpe:2.3:a:has-ansi:has-ansi:2.0.0:*:*:*:*:*:*:*",
320512          "purl": "pkg:npm/has-ansi@2.0.0",
320513          "swid": {
320514            "attachment": {}
320515          },
320516          "pedigree": {},
320517          "evidence": {},
320518          "signature": {
320519            "signature": {
320520              "publicKey": {}
320521            }
320522          },
320523          "modelCard": {
320524            "modelParameters": {
320525              "approach": {}
320526            },
320527            "quantitativeAnalysis": {
320528              "graphics": {}
320529            },
320530            "considerations": {}
320531          }
320532        },
320533        {
320534          "type": "library",
320535          "bom-ref": "pkg:npm/has-binary2@1.0.3?package-id=e3ef0424eef21c0f",
320536          "supplier": {},
320537          "name": "has-binary2",
320538          "version": "1.0.3",
320539          "licenses": [
320540            {
320541              "license": {
320542                "id": "MIT"
320543              }
320544            }
320545          ],
320546          "cpe": "cpe:2.3:a:has-binary2:has-binary2:1.0.3:*:*:*:*:*:*:*",
320547          "purl": "pkg:npm/has-binary2@1.0.3",
320548          "swid": {
320549            "attachment": {}
320550          },
320551          "pedigree": {},
320552          "evidence": {},
320553          "signature": {
320554            "signature": {
320555              "publicKey": {}
320556            }
320557          },
320558          "modelCard": {
320559            "modelParameters": {
320560              "approach": {}
320561            },
320562            "quantitativeAnalysis": {
320563              "graphics": {}
320564            },
320565            "considerations": {}
320566          }
320567        },
320568        {
320569          "type": "library",
320570          "bom-ref": "pkg:npm/has-cors@1.1.0?package-id=c8e145f596e318fb",
320571          "supplier": {},
320572          "name": "has-cors",
320573          "version": "1.1.0",
320574          "licenses": [
320575            {
320576              "license": {
320577                "id": "MIT"
320578              }
320579            }
320580          ],
320581          "cpe": "cpe:2.3:a:has-cors:has-cors:1.1.0:*:*:*:*:*:*:*",
320582          "purl": "pkg:npm/has-cors@1.1.0",
320583          "swid": {
320584            "attachment": {}
320585          },
320586          "pedigree": {},
320587          "evidence": {},
320588          "signature": {
320589            "signature": {
320590              "publicKey": {}
320591            }
320592          },
320593          "modelCard": {
320594            "modelParameters": {
320595              "approach": {}
320596            },
320597            "quantitativeAnalysis": {
320598              "graphics": {}
320599            },
320600            "considerations": {}
320601          }
320602        },
320603        {
320604          "type": "library",
320605          "bom-ref": "pkg:npm/has-flag@3.0.0?package-id=a41cf4f7a73cd697",
320606          "supplier": {},
320607          "name": "has-flag",
320608          "version": "3.0.0",
320609          "cpe": "cpe:2.3:a:has-flag:has-flag:3.0.0:*:*:*:*:*:*:*",
320610          "purl": "pkg:npm/has-flag@3.0.0",
320611          "swid": {
320612            "attachment": {}
320613          },
320614          "pedigree": {},
320615          "evidence": {},
320616          "signature": {
320617            "signature": {
320618              "publicKey": {}
320619            }
320620          },
320621          "modelCard": {
320622            "modelParameters": {
320623              "approach": {}
320624            },
320625            "quantitativeAnalysis": {
320626              "graphics": {}
320627            },
320628            "considerations": {}
320629          }
320630        },
320631        {
320632          "type": "library",
320633          "bom-ref": "pkg:npm/has-flag@3.0.0?package-id=58c61d96d70626ca",
320634          "supplier": {},
320635          "name": "has-flag",
320636          "version": "3.0.0",
320637          "licenses": [
320638            {
320639              "license": {
320640                "id": "MIT"
320641              }
320642            }
320643          ],
320644          "cpe": "cpe:2.3:a:has-flag:has-flag:3.0.0:*:*:*:*:*:*:*",
320645          "purl": "pkg:npm/has-flag@3.0.0",
320646          "swid": {
320647            "attachment": {}
320648          },
320649          "pedigree": {},
320650          "evidence": {},
320651          "signature": {
320652            "signature": {
320653              "publicKey": {}
320654            }
320655          },
320656          "modelCard": {
320657            "modelParameters": {
320658              "approach": {}
320659            },
320660            "quantitativeAnalysis": {
320661              "graphics": {}
320662            },
320663            "considerations": {}
320664          }
320665        },
320666        {
320667          "type": "library",
320668          "bom-ref": "pkg:npm/has-symbols@1.0.1?package-id=fc7f29f46370bd6e",
320669          "supplier": {},
320670          "name": "has-symbols",
320671          "version": "1.0.1",
320672          "licenses": [
320673            {
320674              "license": {
320675                "id": "MIT"
320676              }
320677            }
320678          ],
320679          "cpe": "cpe:2.3:a:has-symbols:has-symbols:1.0.1:*:*:*:*:*:*:*",
320680          "purl": "pkg:npm/has-symbols@1.0.1",
320681          "swid": {
320682            "attachment": {}
320683          },
320684          "pedigree": {},
320685          "evidence": {},
320686          "signature": {
320687            "signature": {
320688              "publicKey": {}
320689            }
320690          },
320691          "modelCard": {
320692            "modelParameters": {
320693              "approach": {}
320694            },
320695            "quantitativeAnalysis": {
320696              "graphics": {}
320697            },
320698            "considerations": {}
320699          }
320700        },
320701        {
320702          "type": "library",
320703          "bom-ref": "pkg:npm/has-unicode@2.0.1?package-id=35b66e4a60ec8bb0",
320704          "supplier": {},
320705          "name": "has-unicode",
320706          "version": "2.0.1",
320707          "licenses": [
320708            {
320709              "license": {
320710                "id": "ISC"
320711              }
320712            }
320713          ],
320714          "cpe": "cpe:2.3:a:has-unicode:has-unicode:2.0.1:*:*:*:*:*:*:*",
320715          "purl": "pkg:npm/has-unicode@2.0.1",
320716          "swid": {
320717            "attachment": {}
320718          },
320719          "pedigree": {},
320720          "evidence": {},
320721          "signature": {
320722            "signature": {
320723              "publicKey": {}
320724            }
320725          },
320726          "modelCard": {
320727            "modelParameters": {
320728              "approach": {}
320729            },
320730            "quantitativeAnalysis": {
320731              "graphics": {}
320732            },
320733            "considerations": {}
320734          }
320735        },
320736        {
320737          "type": "library",
320738          "bom-ref": "pkg:npm/has-value@1.0.0?package-id=d5032b241ba02e1d",
320739          "supplier": {},
320740          "name": "has-value",
320741          "version": "1.0.0",
320742          "licenses": [
320743            {
320744              "license": {
320745                "id": "MIT"
320746              }
320747            }
320748          ],
320749          "cpe": "cpe:2.3:a:has-value:has-value:1.0.0:*:*:*:*:*:*:*",
320750          "purl": "pkg:npm/has-value@1.0.0",
320751          "swid": {
320752            "attachment": {}
320753          },
320754          "pedigree": {},
320755          "evidence": {},
320756          "signature": {
320757            "signature": {
320758              "publicKey": {}
320759            }
320760          },
320761          "modelCard": {
320762            "modelParameters": {
320763              "approach": {}
320764            },
320765            "quantitativeAnalysis": {
320766              "graphics": {}
320767            },
320768            "considerations": {}
320769          }
320770        },
320771        {
320772          "type": "library",
320773          "bom-ref": "pkg:npm/has-values@1.0.0?package-id=45a2f61c5944e0d5",
320774          "supplier": {},
320775          "name": "has-values",
320776          "version": "1.0.0",
320777          "licenses": [
320778            {
320779              "license": {
320780                "id": "MIT"
320781              }
320782            }
320783          ],
320784          "cpe": "cpe:2.3:a:has-values:has-values:1.0.0:*:*:*:*:*:*:*",
320785          "purl": "pkg:npm/has-values@1.0.0",
320786          "swid": {
320787            "attachment": {}
320788          },
320789          "pedigree": {},
320790          "evidence": {},
320791          "signature": {
320792            "signature": {
320793              "publicKey": {}
320794            }
320795          },
320796          "modelCard": {
320797            "modelParameters": {
320798              "approach": {}
320799            },
320800            "quantitativeAnalysis": {
320801              "graphics": {}
320802            },
320803            "considerations": {}
320804          }
320805        },
320806        {
320807          "type": "library",
320808          "bom-ref": "pkg:npm/hash-base@3.1.0?package-id=b929cbdf581d2bcf",
320809          "supplier": {},
320810          "name": "hash-base",
320811          "version": "3.1.0",
320812          "licenses": [
320813            {
320814              "license": {
320815                "id": "MIT"
320816              }
320817            }
320818          ],
320819          "cpe": "cpe:2.3:a:hash-base:hash-base:3.1.0:*:*:*:*:*:*:*",
320820          "purl": "pkg:npm/hash-base@3.1.0",
320821          "swid": {
320822            "attachment": {}
320823          },
320824          "pedigree": {},
320825          "evidence": {},
320826          "signature": {
320827            "signature": {
320828              "publicKey": {}
320829            }
320830          },
320831          "modelCard": {
320832            "modelParameters": {
320833              "approach": {}
320834            },
320835            "quantitativeAnalysis": {
320836              "graphics": {}
320837            },
320838            "considerations": {}
320839          }
320840        },
320841        {
320842          "type": "library",
320843          "bom-ref": "pkg:npm/hash.js@1.1.7?package-id=2b2472c5da730ea5",
320844          "supplier": {},
320845          "name": "hash.js",
320846          "version": "1.1.7",
320847          "licenses": [
320848            {
320849              "license": {
320850                "id": "MIT"
320851              }
320852            }
320853          ],
320854          "cpe": "cpe:2.3:a:hash.js:hash.js:1.1.7:*:*:*:*:*:*:*",
320855          "purl": "pkg:npm/hash.js@1.1.7",
320856          "swid": {
320857            "attachment": {}
320858          },
320859          "pedigree": {},
320860          "evidence": {},
320861          "signature": {
320862            "signature": {
320863              "publicKey": {}
320864            }
320865          },
320866          "modelCard": {
320867            "modelParameters": {
320868              "approach": {}
320869            },
320870            "quantitativeAnalysis": {
320871              "graphics": {}
320872            },
320873            "considerations": {}
320874          }
320875        },
320876        {
320877          "type": "library",
320878          "bom-ref": "pkg:npm/hasha@5.2.2?package-id=8c40fdee7bf5379",
320879          "supplier": {},
320880          "name": "hasha",
320881          "version": "5.2.2",
320882          "cpe": "cpe:2.3:a:hasha:hasha:5.2.2:*:*:*:*:*:*:*",
320883          "purl": "pkg:npm/hasha@5.2.2",
320884          "swid": {
320885            "attachment": {}
320886          },
320887          "pedigree": {},
320888          "evidence": {},
320889          "signature": {
320890            "signature": {
320891              "publicKey": {}
320892            }
320893          },
320894          "modelCard": {
320895            "modelParameters": {
320896              "approach": {}
320897            },
320898            "quantitativeAnalysis": {
320899              "graphics": {}
320900            },
320901            "considerations": {}
320902          }
320903        },
320904        {
320905          "type": "library",
320906          "bom-ref": "pkg:npm/hat@0.0.3?package-id=f8c1c7ec65337bea",
320907          "supplier": {},
320908          "name": "hat",
320909          "version": "0.0.3",
320910          "licenses": [
320911            {
320912              "license": {
320913                "name": "MIT/X11"
320914              }
320915            }
320916          ],
320917          "cpe": "cpe:2.3:a:hat:hat:0.0.3:*:*:*:*:*:*:*",
320918          "purl": "pkg:npm/hat@0.0.3",
320919          "swid": {
320920            "attachment": {}
320921          },
320922          "pedigree": {},
320923          "evidence": {},
320924          "signature": {
320925            "signature": {
320926              "publicKey": {}
320927            }
320928          },
320929          "modelCard": {
320930            "modelParameters": {
320931              "approach": {}
320932            },
320933            "quantitativeAnalysis": {
320934              "graphics": {}
320935            },
320936            "considerations": {}
320937          }
320938        },
320939        {
320940          "type": "library",
320941          "bom-ref": "pkg:npm/hex-color-regex@1.1.0?package-id=3ed2479126656f54",
320942          "supplier": {},
320943          "name": "hex-color-regex",
320944          "version": "1.1.0",
320945          "licenses": [
320946            {
320947              "license": {
320948                "id": "MIT"
320949              }
320950            }
320951          ],
320952          "cpe": "cpe:2.3:a:hex-color-regex:hex-color-regex:1.1.0:*:*:*:*:*:*:*",
320953          "purl": "pkg:npm/hex-color-regex@1.1.0",
320954          "swid": {
320955            "attachment": {}
320956          },
320957          "pedigree": {},
320958          "evidence": {},
320959          "signature": {
320960            "signature": {
320961              "publicKey": {}
320962            }
320963          },
320964          "modelCard": {
320965            "modelParameters": {
320966              "approach": {}
320967            },
320968            "quantitativeAnalysis": {
320969              "graphics": {}
320970            },
320971            "considerations": {}
320972          }
320973        },
320974        {
320975          "type": "library",
320976          "bom-ref": "pkg:npm/hmac-drbg@1.0.1?package-id=4d346510bcb9b857",
320977          "supplier": {},
320978          "name": "hmac-drbg",
320979          "version": "1.0.1",
320980          "licenses": [
320981            {
320982              "license": {
320983                "id": "MIT"
320984              }
320985            }
320986          ],
320987          "cpe": "cpe:2.3:a:hmac-drbg:hmac-drbg:1.0.1:*:*:*:*:*:*:*",
320988          "purl": "pkg:npm/hmac-drbg@1.0.1",
320989          "swid": {
320990            "attachment": {}
320991          },
320992          "pedigree": {},
320993          "evidence": {},
320994          "signature": {
320995            "signature": {
320996              "publicKey": {}
320997            }
320998          },
320999          "modelCard": {
321000            "modelParameters": {
321001              "approach": {}
321002            },
321003            "quantitativeAnalysis": {
321004              "graphics": {}
321005            },
321006            "considerations": {}
321007          }
321008        },
321009        {
321010          "type": "library",
321011          "bom-ref": "pkg:npm/hoopy@0.1.4?package-id=8a3c82c4b8b53d58",
321012          "supplier": {},
321013          "name": "hoopy",
321014          "version": "0.1.4",
321015          "licenses": [
321016            {
321017              "license": {
321018                "id": "MIT"
321019              }
321020            }
321021          ],
321022          "cpe": "cpe:2.3:a:hoopy:hoopy:0.1.4:*:*:*:*:*:*:*",
321023          "purl": "pkg:npm/hoopy@0.1.4",
321024          "swid": {
321025            "attachment": {}
321026          },
321027          "pedigree": {},
321028          "evidence": {},
321029          "signature": {
321030            "signature": {
321031              "publicKey": {}
321032            }
321033          },
321034          "modelCard": {
321035            "modelParameters": {
321036              "approach": {}
321037            },
321038            "quantitativeAnalysis": {
321039              "graphics": {}
321040            },
321041            "considerations": {}
321042          }
321043        },
321044        {
321045          "type": "library",
321046          "bom-ref": "pkg:npm/hosted-git-info@3.0.4?package-id=c9bc7aa70fe41772",
321047          "supplier": {},
321048          "name": "hosted-git-info",
321049          "version": "3.0.4",
321050          "licenses": [
321051            {
321052              "license": {
321053                "id": "ISC"
321054              }
321055            }
321056          ],
321057          "cpe": "cpe:2.3:a:hosted-git-info:hosted-git-info:3.0.4:*:*:*:*:*:*:*",
321058          "purl": "pkg:npm/hosted-git-info@3.0.4",
321059          "swid": {
321060            "attachment": {}
321061          },
321062          "pedigree": {},
321063          "evidence": {},
321064          "signature": {
321065            "signature": {
321066              "publicKey": {}
321067            }
321068          },
321069          "modelCard": {
321070            "modelParameters": {
321071              "approach": {}
321072            },
321073            "quantitativeAnalysis": {
321074              "graphics": {}
321075            },
321076            "considerations": {}
321077          }
321078        },
321079        {
321080          "type": "library",
321081          "bom-ref": "pkg:npm/hpack.js@2.1.6?package-id=3469ea053800e8cd",
321082          "supplier": {},
321083          "name": "hpack.js",
321084          "version": "2.1.6",
321085          "licenses": [
321086            {
321087              "license": {
321088                "id": "MIT"
321089              }
321090            }
321091          ],
321092          "cpe": "cpe:2.3:a:hpack.js:hpack.js:2.1.6:*:*:*:*:*:*:*",
321093          "purl": "pkg:npm/hpack.js@2.1.6",
321094          "swid": {
321095            "attachment": {}
321096          },
321097          "pedigree": {},
321098          "evidence": {},
321099          "signature": {
321100            "signature": {
321101              "publicKey": {}
321102            }
321103          },
321104          "modelCard": {
321105            "modelParameters": {
321106              "approach": {}
321107            },
321108            "quantitativeAnalysis": {
321109              "graphics": {}
321110            },
321111            "considerations": {}
321112          }
321113        },
321114        {
321115          "type": "library",
321116          "bom-ref": "pkg:npm/hsl-regex@1.0.0?package-id=1b8de35627eda758",
321117          "supplier": {},
321118          "name": "hsl-regex",
321119          "version": "1.0.0",
321120          "licenses": [
321121            {
321122              "license": {
321123                "id": "MIT"
321124              }
321125            }
321126          ],
321127          "cpe": "cpe:2.3:a:hsl-regex:hsl-regex:1.0.0:*:*:*:*:*:*:*",
321128          "purl": "pkg:npm/hsl-regex@1.0.0",
321129          "swid": {
321130            "attachment": {}
321131          },
321132          "pedigree": {},
321133          "evidence": {},
321134          "signature": {
321135            "signature": {
321136              "publicKey": {}
321137            }
321138          },
321139          "modelCard": {
321140            "modelParameters": {
321141              "approach": {}
321142            },
321143            "quantitativeAnalysis": {
321144              "graphics": {}
321145            },
321146            "considerations": {}
321147          }
321148        },
321149        {
321150          "type": "library",
321151          "bom-ref": "pkg:npm/hsla-regex@1.0.0?package-id=a672b177632a1bad",
321152          "supplier": {},
321153          "name": "hsla-regex",
321154          "version": "1.0.0",
321155          "licenses": [
321156            {
321157              "license": {
321158                "id": "MIT"
321159              }
321160            }
321161          ],
321162          "cpe": "cpe:2.3:a:hsla-regex:hsla-regex:1.0.0:*:*:*:*:*:*:*",
321163          "purl": "pkg:npm/hsla-regex@1.0.0",
321164          "swid": {
321165            "attachment": {}
321166          },
321167          "pedigree": {},
321168          "evidence": {},
321169          "signature": {
321170            "signature": {
321171              "publicKey": {}
321172            }
321173          },
321174          "modelCard": {
321175            "modelParameters": {
321176              "approach": {}
321177            },
321178            "quantitativeAnalysis": {
321179              "graphics": {}
321180            },
321181            "considerations": {}
321182          }
321183        },
321184        {
321185          "type": "library",
321186          "bom-ref": "pkg:npm/html-comment-regex@1.1.2?package-id=5b75e28fce5492b2",
321187          "supplier": {},
321188          "name": "html-comment-regex",
321189          "version": "1.1.2",
321190          "licenses": [
321191            {
321192              "license": {
321193                "id": "MIT"
321194              }
321195            }
321196          ],
321197          "cpe": "cpe:2.3:a:html-comment-regex:html-comment-regex:1.1.2:*:*:*:*:*:*:*",
321198          "purl": "pkg:npm/html-comment-regex@1.1.2",
321199          "swid": {
321200            "attachment": {}
321201          },
321202          "pedigree": {},
321203          "evidence": {},
321204          "signature": {
321205            "signature": {
321206              "publicKey": {}
321207            }
321208          },
321209          "modelCard": {
321210            "modelParameters": {
321211              "approach": {}
321212            },
321213            "quantitativeAnalysis": {
321214              "graphics": {}
321215            },
321216            "considerations": {}
321217          }
321218        },
321219        {
321220          "type": "library",
321221          "bom-ref": "pkg:npm/html-entities@1.3.1?package-id=2477f7e10710393f",
321222          "supplier": {},
321223          "name": "html-entities",
321224          "version": "1.3.1",
321225          "licenses": [
321226            {
321227              "license": {
321228                "id": "MIT"
321229              }
321230            }
321231          ],
321232          "cpe": "cpe:2.3:a:html-entities:html-entities:1.3.1:*:*:*:*:*:*:*",
321233          "purl": "pkg:npm/html-entities@1.3.1",
321234          "swid": {
321235            "attachment": {}
321236          },
321237          "pedigree": {},
321238          "evidence": {},
321239          "signature": {
321240            "signature": {
321241              "publicKey": {}
321242            }
321243          },
321244          "modelCard": {
321245            "modelParameters": {
321246              "approach": {}
321247            },
321248            "quantitativeAnalysis": {
321249              "graphics": {}
321250            },
321251            "considerations": {}
321252          }
321253        },
321254        {
321255          "type": "library",
321256          "bom-ref": "pkg:npm/html-escaper@2.0.1?package-id=8be027f2fefcc741",
321257          "supplier": {},
321258          "name": "html-escaper",
321259          "version": "2.0.1",
321260          "licenses": [
321261            {
321262              "license": {
321263                "id": "MIT"
321264              }
321265            }
321266          ],
321267          "cpe": "cpe:2.3:a:html-escaper:html-escaper:2.0.1:*:*:*:*:*:*:*",
321268          "purl": "pkg:npm/html-escaper@2.0.1",
321269          "swid": {
321270            "attachment": {}
321271          },
321272          "pedigree": {},
321273          "evidence": {},
321274          "signature": {
321275            "signature": {
321276              "publicKey": {}
321277            }
321278          },
321279          "modelCard": {
321280            "modelParameters": {
321281              "approach": {}
321282            },
321283            "quantitativeAnalysis": {
321284              "graphics": {}
321285            },
321286            "considerations": {}
321287          }
321288        },
321289        {
321290          "type": "library",
321291          "bom-ref": "pkg:npm/html-escaper@2.0.2?package-id=f66ca240d366936d",
321292          "supplier": {},
321293          "name": "html-escaper",
321294          "version": "2.0.2",
321295          "cpe": "cpe:2.3:a:html-escaper:html-escaper:2.0.2:*:*:*:*:*:*:*",
321296          "purl": "pkg:npm/html-escaper@2.0.2",
321297          "swid": {
321298            "attachment": {}
321299          },
321300          "pedigree": {},
321301          "evidence": {},
321302          "signature": {
321303            "signature": {
321304              "publicKey": {}
321305            }
321306          },
321307          "modelCard": {
321308            "modelParameters": {
321309              "approach": {}
321310            },
321311            "quantitativeAnalysis": {
321312              "graphics": {}
321313            },
321314            "considerations": {}
321315          }
321316        },
321317        {
321318          "type": "library",
321319          "bom-ref": "pkg:npm/http-cache-semantics@3.8.1?package-id=17b1c363d3bf4d01",
321320          "supplier": {},
321321          "name": "http-cache-semantics",
321322          "version": "3.8.1",
321323          "licenses": [
321324            {
321325              "license": {
321326                "id": "BSD-2-Clause"
321327              }
321328            }
321329          ],
321330          "cpe": "cpe:2.3:a:http-cache-semantics:http-cache-semantics:3.8.1:*:*:*:*:*:*:*",
321331          "purl": "pkg:npm/http-cache-semantics@3.8.1",
321332          "swid": {
321333            "attachment": {}
321334          },
321335          "pedigree": {},
321336          "evidence": {},
321337          "signature": {
321338            "signature": {
321339              "publicKey": {}
321340            }
321341          },
321342          "modelCard": {
321343            "modelParameters": {
321344              "approach": {}
321345            },
321346            "quantitativeAnalysis": {
321347              "graphics": {}
321348            },
321349            "considerations": {}
321350          }
321351        },
321352        {
321353          "type": "library",
321354          "bom-ref": "pkg:npm/http-deceiver@1.2.7?package-id=1def39a1440b77c1",
321355          "supplier": {},
321356          "name": "http-deceiver",
321357          "version": "1.2.7",
321358          "licenses": [
321359            {
321360              "license": {
321361                "id": "MIT"
321362              }
321363            }
321364          ],
321365          "cpe": "cpe:2.3:a:http-deceiver:http-deceiver:1.2.7:*:*:*:*:*:*:*",
321366          "purl": "pkg:npm/http-deceiver@1.2.7",
321367          "swid": {
321368            "attachment": {}
321369          },
321370          "pedigree": {},
321371          "evidence": {},
321372          "signature": {
321373            "signature": {
321374              "publicKey": {}
321375            }
321376          },
321377          "modelCard": {
321378            "modelParameters": {
321379              "approach": {}
321380            },
321381            "quantitativeAnalysis": {
321382              "graphics": {}
321383            },
321384            "considerations": {}
321385          }
321386        },
321387        {
321388          "type": "library",
321389          "bom-ref": "pkg:npm/http-errors@1.7.2?package-id=5457dca65bc234e8",
321390          "supplier": {},
321391          "name": "http-errors",
321392          "version": "1.7.2",
321393          "licenses": [
321394            {
321395              "license": {
321396                "id": "MIT"
321397              }
321398            }
321399          ],
321400          "cpe": "cpe:2.3:a:http-errors:http-errors:1.7.2:*:*:*:*:*:*:*",
321401          "purl": "pkg:npm/http-errors@1.7.2",
321402          "swid": {
321403            "attachment": {}
321404          },
321405          "pedigree": {},
321406          "evidence": {},
321407          "signature": {
321408            "signature": {
321409              "publicKey": {}
321410            }
321411          },
321412          "modelCard": {
321413            "modelParameters": {
321414              "approach": {}
321415            },
321416            "quantitativeAnalysis": {
321417              "graphics": {}
321418            },
321419            "considerations": {}
321420          }
321421        },
321422        {
321423          "type": "library",
321424          "bom-ref": "pkg:npm/http-parser-js@0.4.10?package-id=9a252ee8177aabdb",
321425          "supplier": {},
321426          "name": "http-parser-js",
321427          "version": "0.4.10",
321428          "licenses": [
321429            {
321430              "license": {
321431                "id": "MIT"
321432              }
321433            }
321434          ],
321435          "cpe": "cpe:2.3:a:http-parser-js:http-parser-js:0.4.10:*:*:*:*:*:*:*",
321436          "purl": "pkg:npm/http-parser-js@0.4.10",
321437          "swid": {
321438            "attachment": {}
321439          },
321440          "pedigree": {},
321441          "evidence": {},
321442          "signature": {
321443            "signature": {
321444              "publicKey": {}
321445            }
321446          },
321447          "modelCard": {
321448            "modelParameters": {
321449              "approach": {}
321450            },
321451            "quantitativeAnalysis": {
321452              "graphics": {}
321453            },
321454            "considerations": {}
321455          }
321456        },
321457        {
321458          "type": "library",
321459          "bom-ref": "pkg:npm/http-proxy@1.18.0?package-id=42b97d843a5f395a",
321460          "supplier": {},
321461          "name": "http-proxy",
321462          "version": "1.18.0",
321463          "licenses": [
321464            {
321465              "license": {
321466                "id": "MIT"
321467              }
321468            }
321469          ],
321470          "cpe": "cpe:2.3:a:http-proxy:http-proxy:1.18.0:*:*:*:*:*:*:*",
321471          "purl": "pkg:npm/http-proxy@1.18.0",
321472          "swid": {
321473            "attachment": {}
321474          },
321475          "pedigree": {},
321476          "evidence": {},
321477          "signature": {
321478            "signature": {
321479              "publicKey": {}
321480            }
321481          },
321482          "modelCard": {
321483            "modelParameters": {
321484              "approach": {}
321485            },
321486            "quantitativeAnalysis": {
321487              "graphics": {}
321488            },
321489            "considerations": {}
321490          }
321491        },
321492        {
321493          "type": "library",
321494          "bom-ref": "pkg:npm/http-proxy-agent@2.1.0?package-id=a7281ff79a7e5fbf",
321495          "supplier": {},
321496          "name": "http-proxy-agent",
321497          "version": "2.1.0",
321498          "licenses": [
321499            {
321500              "license": {
321501                "id": "MIT"
321502              }
321503            }
321504          ],
321505          "cpe": "cpe:2.3:a:http-proxy-agent:http-proxy-agent:2.1.0:*:*:*:*:*:*:*",
321506          "purl": "pkg:npm/http-proxy-agent@2.1.0",
321507          "swid": {
321508            "attachment": {}
321509          },
321510          "pedigree": {},
321511          "evidence": {},
321512          "signature": {
321513            "signature": {
321514              "publicKey": {}
321515            }
321516          },
321517          "modelCard": {
321518            "modelParameters": {
321519              "approach": {}
321520            },
321521            "quantitativeAnalysis": {
321522              "graphics": {}
321523            },
321524            "considerations": {}
321525          }
321526        },
321527        {
321528          "type": "library",
321529          "bom-ref": "pkg:npm/http-proxy-middleware@0.19.1?package-id=12f8434105025a62",
321530          "supplier": {},
321531          "name": "http-proxy-middleware",
321532          "version": "0.19.1",
321533          "licenses": [
321534            {
321535              "license": {
321536                "id": "MIT"
321537              }
321538            }
321539          ],
321540          "cpe": "cpe:2.3:a:http-proxy-middleware:http-proxy-middleware:0.19.1:*:*:*:*:*:*:*",
321541          "purl": "pkg:npm/http-proxy-middleware@0.19.1",
321542          "swid": {
321543            "attachment": {}
321544          },
321545          "pedigree": {},
321546          "evidence": {},
321547          "signature": {
321548            "signature": {
321549              "publicKey": {}
321550            }
321551          },
321552          "modelCard": {
321553            "modelParameters": {
321554              "approach": {}
321555            },
321556            "quantitativeAnalysis": {
321557              "graphics": {}
321558            },
321559            "considerations": {}
321560          }
321561        },
321562        {
321563          "type": "library",
321564          "bom-ref": "pkg:npm/http-signature@1.2.0?package-id=eab31ef7fd190da4",
321565          "supplier": {},
321566          "name": "http-signature",
321567          "version": "1.2.0",
321568          "licenses": [
321569            {
321570              "license": {
321571                "id": "MIT"
321572              }
321573            }
321574          ],
321575          "cpe": "cpe:2.3:a:http-signature:http-signature:1.2.0:*:*:*:*:*:*:*",
321576          "purl": "pkg:npm/http-signature@1.2.0",
321577          "swid": {
321578            "attachment": {}
321579          },
321580          "pedigree": {},
321581          "evidence": {},
321582          "signature": {
321583            "signature": {
321584              "publicKey": {}
321585            }
321586          },
321587          "modelCard": {
321588            "modelParameters": {
321589              "approach": {}
321590            },
321591            "quantitativeAnalysis": {
321592              "graphics": {}
321593            },
321594            "considerations": {}
321595          }
321596        },
321597        {
321598          "type": "library",
321599          "bom-ref": "pkg:npm/https-browserify@1.0.0?package-id=26447787cd73bc73",
321600          "supplier": {},
321601          "name": "https-browserify",
321602          "version": "1.0.0",
321603          "licenses": [
321604            {
321605              "license": {
321606                "id": "MIT"
321607              }
321608            }
321609          ],
321610          "cpe": "cpe:2.3:a:https-browserify:https-browserify:1.0.0:*:*:*:*:*:*:*",
321611          "purl": "pkg:npm/https-browserify@1.0.0",
321612          "swid": {
321613            "attachment": {}
321614          },
321615          "pedigree": {},
321616          "evidence": {},
321617          "signature": {
321618            "signature": {
321619              "publicKey": {}
321620            }
321621          },
321622          "modelCard": {
321623            "modelParameters": {
321624              "approach": {}
321625            },
321626            "quantitativeAnalysis": {
321627              "graphics": {}
321628            },
321629            "considerations": {}
321630          }
321631        },
321632        {
321633          "type": "library",
321634          "bom-ref": "pkg:npm/https-proxy-agent@2.2.4?package-id=b3137d38baec4ac7",
321635          "supplier": {},
321636          "name": "https-proxy-agent",
321637          "version": "2.2.4",
321638          "licenses": [
321639            {
321640              "license": {
321641                "id": "MIT"
321642              }
321643            }
321644          ],
321645          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:2.2.4:*:*:*:*:*:*:*",
321646          "purl": "pkg:npm/https-proxy-agent@2.2.4",
321647          "swid": {
321648            "attachment": {}
321649          },
321650          "pedigree": {},
321651          "evidence": {},
321652          "signature": {
321653            "signature": {
321654              "publicKey": {}
321655            }
321656          },
321657          "modelCard": {
321658            "modelParameters": {
321659              "approach": {}
321660            },
321661            "quantitativeAnalysis": {
321662              "graphics": {}
321663            },
321664            "considerations": {}
321665          }
321666        },
321667        {
321668          "type": "library",
321669          "bom-ref": "pkg:npm/humanize-ms@1.2.1?package-id=509082d97e002281",
321670          "supplier": {},
321671          "name": "humanize-ms",
321672          "version": "1.2.1",
321673          "licenses": [
321674            {
321675              "license": {
321676                "id": "MIT"
321677              }
321678            }
321679          ],
321680          "cpe": "cpe:2.3:a:humanize-ms:humanize-ms:1.2.1:*:*:*:*:*:*:*",
321681          "purl": "pkg:npm/humanize-ms@1.2.1",
321682          "swid": {
321683            "attachment": {}
321684          },
321685          "pedigree": {},
321686          "evidence": {},
321687          "signature": {
321688            "signature": {
321689              "publicKey": {}
321690            }
321691          },
321692          "modelCard": {
321693            "modelParameters": {
321694              "approach": {}
321695            },
321696            "quantitativeAnalysis": {
321697              "graphics": {}
321698            },
321699            "considerations": {}
321700          }
321701        },
321702        {
321703          "type": "library",
321704          "bom-ref": "pkg:npm/iconv-lite@0.4.24?package-id=999c06134ef677a5",
321705          "supplier": {},
321706          "name": "iconv-lite",
321707          "version": "0.4.24",
321708          "licenses": [
321709            {
321710              "license": {
321711                "id": "MIT"
321712              }
321713            }
321714          ],
321715          "cpe": "cpe:2.3:a:iconv-lite:iconv-lite:0.4.24:*:*:*:*:*:*:*",
321716          "purl": "pkg:npm/iconv-lite@0.4.24",
321717          "swid": {
321718            "attachment": {}
321719          },
321720          "pedigree": {},
321721          "evidence": {},
321722          "signature": {
321723            "signature": {
321724              "publicKey": {}
321725            }
321726          },
321727          "modelCard": {
321728            "modelParameters": {
321729              "approach": {}
321730            },
321731            "quantitativeAnalysis": {
321732              "graphics": {}
321733            },
321734            "considerations": {}
321735          }
321736        },
321737        {
321738          "type": "library",
321739          "bom-ref": "pkg:npm/icss-utils@4.1.1?package-id=2da5415f3a1d199a",
321740          "supplier": {},
321741          "name": "icss-utils",
321742          "version": "4.1.1",
321743          "licenses": [
321744            {
321745              "license": {
321746                "id": "ISC"
321747              }
321748            }
321749          ],
321750          "cpe": "cpe:2.3:a:icss-utils:icss-utils:4.1.1:*:*:*:*:*:*:*",
321751          "purl": "pkg:npm/icss-utils@4.1.1",
321752          "swid": {
321753            "attachment": {}
321754          },
321755          "pedigree": {},
321756          "evidence": {},
321757          "signature": {
321758            "signature": {
321759              "publicKey": {}
321760            }
321761          },
321762          "modelCard": {
321763            "modelParameters": {
321764              "approach": {}
321765            },
321766            "quantitativeAnalysis": {
321767              "graphics": {}
321768            },
321769            "considerations": {}
321770          }
321771        },
321772        {
321773          "type": "library",
321774          "bom-ref": "pkg:npm/ieee754@1.1.13?package-id=ab79705531d245ef",
321775          "supplier": {},
321776          "name": "ieee754",
321777          "version": "1.1.13",
321778          "licenses": [
321779            {
321780              "license": {
321781                "id": "BSD-3-Clause"
321782              }
321783            }
321784          ],
321785          "cpe": "cpe:2.3:a:ieee754:ieee754:1.1.13:*:*:*:*:*:*:*",
321786          "purl": "pkg:npm/ieee754@1.1.13",
321787          "swid": {
321788            "attachment": {}
321789          },
321790          "pedigree": {},
321791          "evidence": {},
321792          "signature": {
321793            "signature": {
321794              "publicKey": {}
321795            }
321796          },
321797          "modelCard": {
321798            "modelParameters": {
321799              "approach": {}
321800            },
321801            "quantitativeAnalysis": {
321802              "graphics": {}
321803            },
321804            "considerations": {}
321805          }
321806        },
321807        {
321808          "type": "library",
321809          "bom-ref": "pkg:npm/iferr@0.1.5?package-id=32ffbc67ac16f742",
321810          "supplier": {},
321811          "name": "iferr",
321812          "version": "0.1.5",
321813          "licenses": [
321814            {
321815              "license": {
321816                "id": "MIT"
321817              }
321818            }
321819          ],
321820          "cpe": "cpe:2.3:a:iferr:iferr:0.1.5:*:*:*:*:*:*:*",
321821          "purl": "pkg:npm/iferr@0.1.5",
321822          "swid": {
321823            "attachment": {}
321824          },
321825          "pedigree": {},
321826          "evidence": {},
321827          "signature": {
321828            "signature": {
321829              "publicKey": {}
321830            }
321831          },
321832          "modelCard": {
321833            "modelParameters": {
321834              "approach": {}
321835            },
321836            "quantitativeAnalysis": {
321837              "graphics": {}
321838            },
321839            "considerations": {}
321840          }
321841        },
321842        {
321843          "type": "library",
321844          "bom-ref": "pkg:npm/igniteui-angular@9.0.13?package-id=af0ef079dcaf299d",
321845          "supplier": {},
321846          "name": "igniteui-angular",
321847          "version": "9.0.13",
321848          "licenses": [
321849            {
321850              "license": {
321851                "id": "Apache-2.0"
321852              }
321853            }
321854          ],
321855          "cpe": "cpe:2.3:a:igniteui-angular:igniteui-angular:9.0.13:*:*:*:*:*:*:*",
321856          "purl": "pkg:npm/igniteui-angular@9.0.13",
321857          "swid": {
321858            "attachment": {}
321859          },
321860          "pedigree": {},
321861          "evidence": {},
321862          "signature": {
321863            "signature": {
321864              "publicKey": {}
321865            }
321866          },
321867          "modelCard": {
321868            "modelParameters": {
321869              "approach": {}
321870            },
321871            "quantitativeAnalysis": {
321872              "graphics": {}
321873            },
321874            "considerations": {}
321875          }
321876        },
321877        {
321878          "type": "library",
321879          "bom-ref": "pkg:npm/ignore@3.3.10?package-id=af4a22a7d221add6",
321880          "supplier": {},
321881          "name": "ignore",
321882          "version": "3.3.10",
321883          "licenses": [
321884            {
321885              "license": {
321886                "id": "MIT"
321887              }
321888            }
321889          ],
321890          "cpe": "cpe:2.3:a:ignore:ignore:3.3.10:*:*:*:*:*:*:*",
321891          "purl": "pkg:npm/ignore@3.3.10",
321892          "swid": {
321893            "attachment": {}
321894          },
321895          "pedigree": {},
321896          "evidence": {},
321897          "signature": {
321898            "signature": {
321899              "publicKey": {}
321900            }
321901          },
321902          "modelCard": {
321903            "modelParameters": {
321904              "approach": {}
321905            },
321906            "quantitativeAnalysis": {
321907              "graphics": {}
321908            },
321909            "considerations": {}
321910          }
321911        },
321912        {
321913          "type": "library",
321914          "bom-ref": "pkg:npm/ignore-walk@3.0.3?package-id=efbcd5495c0c263d",
321915          "supplier": {},
321916          "name": "ignore-walk",
321917          "version": "3.0.3",
321918          "licenses": [
321919            {
321920              "license": {
321921                "id": "ISC"
321922              }
321923            }
321924          ],
321925          "cpe": "cpe:2.3:a:ignore-walk:ignore-walk:3.0.3:*:*:*:*:*:*:*",
321926          "purl": "pkg:npm/ignore-walk@3.0.3",
321927          "swid": {
321928            "attachment": {}
321929          },
321930          "pedigree": {},
321931          "evidence": {},
321932          "signature": {
321933            "signature": {
321934              "publicKey": {}
321935            }
321936          },
321937          "modelCard": {
321938            "modelParameters": {
321939              "approach": {}
321940            },
321941            "quantitativeAnalysis": {
321942              "graphics": {}
321943            },
321944            "considerations": {}
321945          }
321946        },
321947        {
321948          "type": "library",
321949          "bom-ref": "pkg:npm/image-size@0.5.5?package-id=bea483365ffd6b74",
321950          "supplier": {},
321951          "name": "image-size",
321952          "version": "0.5.5",
321953          "licenses": [
321954            {
321955              "license": {
321956                "id": "MIT"
321957              }
321958            }
321959          ],
321960          "cpe": "cpe:2.3:a:image-size:image-size:0.5.5:*:*:*:*:*:*:*",
321961          "purl": "pkg:npm/image-size@0.5.5",
321962          "swid": {
321963            "attachment": {}
321964          },
321965          "pedigree": {},
321966          "evidence": {},
321967          "signature": {
321968            "signature": {
321969              "publicKey": {}
321970            }
321971          },
321972          "modelCard": {
321973            "modelParameters": {
321974              "approach": {}
321975            },
321976            "quantitativeAnalysis": {
321977              "graphics": {}
321978            },
321979            "considerations": {}
321980          }
321981        },
321982        {
321983          "type": "library",
321984          "bom-ref": "pkg:npm/imgmsglib@1.0.8?package-id=86e27893b5a3dc50",
321985          "supplier": {},
321986          "name": "imgmsglib",
321987          "version": "1.0.8",
321988          "licenses": [
321989            {
321990              "license": {
321991                "id": "MIT"
321992              }
321993            }
321994          ],
321995          "cpe": "cpe:2.3:a:imgmsglib:imgmsglib:1.0.8:*:*:*:*:*:*:*",
321996          "purl": "pkg:npm/imgmsglib@1.0.8",
321997          "swid": {
321998            "attachment": {}
321999          },
322000          "pedigree": {},
322001          "evidence": {},
322002          "signature": {
322003            "signature": {
322004              "publicKey": {}
322005            }
322006          },
322007          "modelCard": {
322008            "modelParameters": {
322009              "approach": {}
322010            },
322011            "quantitativeAnalysis": {
322012              "graphics": {}
322013            },
322014            "considerations": {}
322015          }
322016        },
322017        {
322018          "type": "library",
322019          "bom-ref": "pkg:npm/immediate@3.0.6?package-id=b377a4b1b606461f",
322020          "supplier": {},
322021          "name": "immediate",
322022          "version": "3.0.6",
322023          "licenses": [
322024            {
322025              "license": {
322026                "id": "MIT"
322027              }
322028            }
322029          ],
322030          "cpe": "cpe:2.3:a:immediate:immediate:3.0.6:*:*:*:*:*:*:*",
322031          "purl": "pkg:npm/immediate@3.0.6",
322032          "swid": {
322033            "attachment": {}
322034          },
322035          "pedigree": {},
322036          "evidence": {},
322037          "signature": {
322038            "signature": {
322039              "publicKey": {}
322040            }
322041          },
322042          "modelCard": {
322043            "modelParameters": {
322044              "approach": {}
322045            },
322046            "quantitativeAnalysis": {
322047              "graphics": {}
322048            },
322049            "considerations": {}
322050          }
322051        },
322052        {
322053          "type": "library",
322054          "bom-ref": "pkg:npm/immutable@3.8.2?package-id=35d07eb9e86042db",
322055          "supplier": {},
322056          "name": "immutable",
322057          "version": "3.8.2",
322058          "licenses": [
322059            {
322060              "license": {
322061                "id": "MIT"
322062              }
322063            }
322064          ],
322065          "cpe": "cpe:2.3:a:immutable:immutable:3.8.2:*:*:*:*:*:*:*",
322066          "purl": "pkg:npm/immutable@3.8.2",
322067          "swid": {
322068            "attachment": {}
322069          },
322070          "pedigree": {},
322071          "evidence": {},
322072          "signature": {
322073            "signature": {
322074              "publicKey": {}
322075            }
322076          },
322077          "modelCard": {
322078            "modelParameters": {
322079              "approach": {}
322080            },
322081            "quantitativeAnalysis": {
322082              "graphics": {}
322083            },
322084            "considerations": {}
322085          }
322086        },
322087        {
322088          "type": "library",
322089          "bom-ref": "pkg:npm/import-cwd@2.1.0?package-id=6cd3dd7757e2f906",
322090          "supplier": {},
322091          "name": "import-cwd",
322092          "version": "2.1.0",
322093          "licenses": [
322094            {
322095              "license": {
322096                "id": "MIT"
322097              }
322098            }
322099          ],
322100          "cpe": "cpe:2.3:a:import-cwd:import-cwd:2.1.0:*:*:*:*:*:*:*",
322101          "purl": "pkg:npm/import-cwd@2.1.0",
322102          "swid": {
322103            "attachment": {}
322104          },
322105          "pedigree": {},
322106          "evidence": {},
322107          "signature": {
322108            "signature": {
322109              "publicKey": {}
322110            }
322111          },
322112          "modelCard": {
322113            "modelParameters": {
322114              "approach": {}
322115            },
322116            "quantitativeAnalysis": {
322117              "graphics": {}
322118            },
322119            "considerations": {}
322120          }
322121        },
322122        {
322123          "type": "library",
322124          "bom-ref": "pkg:npm/import-fresh@2.0.0?package-id=7f311c3fb51b4a09",
322125          "supplier": {},
322126          "name": "import-fresh",
322127          "version": "2.0.0",
322128          "licenses": [
322129            {
322130              "license": {
322131                "id": "MIT"
322132              }
322133            }
322134          ],
322135          "cpe": "cpe:2.3:a:import-fresh:import-fresh:2.0.0:*:*:*:*:*:*:*",
322136          "purl": "pkg:npm/import-fresh@2.0.0",
322137          "swid": {
322138            "attachment": {}
322139          },
322140          "pedigree": {},
322141          "evidence": {},
322142          "signature": {
322143            "signature": {
322144              "publicKey": {}
322145            }
322146          },
322147          "modelCard": {
322148            "modelParameters": {
322149              "approach": {}
322150            },
322151            "quantitativeAnalysis": {
322152              "graphics": {}
322153            },
322154            "considerations": {}
322155          }
322156        },
322157        {
322158          "type": "library",
322159          "bom-ref": "pkg:npm/import-from@2.1.0?package-id=c1758ee89db82851",
322160          "supplier": {},
322161          "name": "import-from",
322162          "version": "2.1.0",
322163          "licenses": [
322164            {
322165              "license": {
322166                "id": "MIT"
322167              }
322168            }
322169          ],
322170          "cpe": "cpe:2.3:a:import-from:import-from:2.1.0:*:*:*:*:*:*:*",
322171          "purl": "pkg:npm/import-from@2.1.0",
322172          "swid": {
322173            "attachment": {}
322174          },
322175          "pedigree": {},
322176          "evidence": {},
322177          "signature": {
322178            "signature": {
322179              "publicKey": {}
322180            }
322181          },
322182          "modelCard": {
322183            "modelParameters": {
322184              "approach": {}
322185            },
322186            "quantitativeAnalysis": {
322187              "graphics": {}
322188            },
322189            "considerations": {}
322190          }
322191        },
322192        {
322193          "type": "library",
322194          "bom-ref": "pkg:npm/import-local@2.0.0?package-id=bb1590ab8e47b5e4",
322195          "supplier": {},
322196          "name": "import-local",
322197          "version": "2.0.0",
322198          "licenses": [
322199            {
322200              "license": {
322201                "id": "MIT"
322202              }
322203            }
322204          ],
322205          "cpe": "cpe:2.3:a:import-local:import-local:2.0.0:*:*:*:*:*:*:*",
322206          "purl": "pkg:npm/import-local@2.0.0",
322207          "swid": {
322208            "attachment": {}
322209          },
322210          "pedigree": {},
322211          "evidence": {},
322212          "signature": {
322213            "signature": {
322214              "publicKey": {}
322215            }
322216          },
322217          "modelCard": {
322218            "modelParameters": {
322219              "approach": {}
322220            },
322221            "quantitativeAnalysis": {
322222              "graphics": {}
322223            },
322224            "considerations": {}
322225          }
322226        },
322227        {
322228          "type": "library",
322229          "bom-ref": "pkg:npm/imurmurhash@0.1.4?package-id=e18262ead668693e",
322230          "supplier": {},
322231          "name": "imurmurhash",
322232          "version": "0.1.4",
322233          "cpe": "cpe:2.3:a:imurmurhash:imurmurhash:0.1.4:*:*:*:*:*:*:*",
322234          "purl": "pkg:npm/imurmurhash@0.1.4",
322235          "swid": {
322236            "attachment": {}
322237          },
322238          "pedigree": {},
322239          "evidence": {},
322240          "signature": {
322241            "signature": {
322242              "publicKey": {}
322243            }
322244          },
322245          "modelCard": {
322246            "modelParameters": {
322247              "approach": {}
322248            },
322249            "quantitativeAnalysis": {
322250              "graphics": {}
322251            },
322252            "considerations": {}
322253          }
322254        },
322255        {
322256          "type": "library",
322257          "bom-ref": "pkg:npm/imurmurhash@0.1.4?package-id=86c7a2e4e034e22a",
322258          "supplier": {},
322259          "name": "imurmurhash",
322260          "version": "0.1.4",
322261          "licenses": [
322262            {
322263              "license": {
322264                "id": "MIT"
322265              }
322266            }
322267          ],
322268          "cpe": "cpe:2.3:a:imurmurhash:imurmurhash:0.1.4:*:*:*:*:*:*:*",
322269          "purl": "pkg:npm/imurmurhash@0.1.4",
322270          "swid": {
322271            "attachment": {}
322272          },
322273          "pedigree": {},
322274          "evidence": {},
322275          "signature": {
322276            "signature": {
322277              "publicKey": {}
322278            }
322279          },
322280          "modelCard": {
322281            "modelParameters": {
322282              "approach": {}
322283            },
322284            "quantitativeAnalysis": {
322285              "graphics": {}
322286            },
322287            "considerations": {}
322288          }
322289        },
322290        {
322291          "type": "library",
322292          "bom-ref": "pkg:npm/in-publish@2.0.1?package-id=2f7597e50fe7a038",
322293          "supplier": {},
322294          "name": "in-publish",
322295          "version": "2.0.1",
322296          "licenses": [
322297            {
322298              "license": {
322299                "id": "ISC"
322300              }
322301            }
322302          ],
322303          "cpe": "cpe:2.3:a:in-publish:in-publish:2.0.1:*:*:*:*:*:*:*",
322304          "purl": "pkg:npm/in-publish@2.0.1",
322305          "swid": {
322306            "attachment": {}
322307          },
322308          "pedigree": {},
322309          "evidence": {},
322310          "signature": {
322311            "signature": {
322312              "publicKey": {}
322313            }
322314          },
322315          "modelCard": {
322316            "modelParameters": {
322317              "approach": {}
322318            },
322319            "quantitativeAnalysis": {
322320              "graphics": {}
322321            },
322322            "considerations": {}
322323          }
322324        },
322325        {
322326          "type": "library",
322327          "bom-ref": "pkg:npm/indent-string@4.0.0?package-id=d19a8114ee99a286",
322328          "supplier": {},
322329          "name": "indent-string",
322330          "version": "4.0.0",
322331          "cpe": "cpe:2.3:a:indent-string:indent-string:4.0.0:*:*:*:*:*:*:*",
322332          "purl": "pkg:npm/indent-string@4.0.0",
322333          "swid": {
322334            "attachment": {}
322335          },
322336          "pedigree": {},
322337          "evidence": {},
322338          "signature": {
322339            "signature": {
322340              "publicKey": {}
322341            }
322342          },
322343          "modelCard": {
322344            "modelParameters": {
322345              "approach": {}
322346            },
322347            "quantitativeAnalysis": {
322348              "graphics": {}
322349            },
322350            "considerations": {}
322351          }
322352        },
322353        {
322354          "type": "library",
322355          "bom-ref": "pkg:npm/indent-string@4.0.0?package-id=58d20a5c6d0b4f4d",
322356          "supplier": {},
322357          "name": "indent-string",
322358          "version": "4.0.0",
322359          "licenses": [
322360            {
322361              "license": {
322362                "id": "MIT"
322363              }
322364            }
322365          ],
322366          "cpe": "cpe:2.3:a:indent-string:indent-string:4.0.0:*:*:*:*:*:*:*",
322367          "purl": "pkg:npm/indent-string@4.0.0",
322368          "swid": {
322369            "attachment": {}
322370          },
322371          "pedigree": {},
322372          "evidence": {},
322373          "signature": {
322374            "signature": {
322375              "publicKey": {}
322376            }
322377          },
322378          "modelCard": {
322379            "modelParameters": {
322380              "approach": {}
322381            },
322382            "quantitativeAnalysis": {
322383              "graphics": {}
322384            },
322385            "considerations": {}
322386          }
322387        },
322388        {
322389          "type": "library",
322390          "bom-ref": "pkg:npm/indexes-of@1.0.1?package-id=afe8b9a4504a2997",
322391          "supplier": {},
322392          "name": "indexes-of",
322393          "version": "1.0.1",
322394          "licenses": [
322395            {
322396              "license": {
322397                "id": "MIT"
322398              }
322399            }
322400          ],
322401          "cpe": "cpe:2.3:a:indexes-of:indexes-of:1.0.1:*:*:*:*:*:*:*",
322402          "purl": "pkg:npm/indexes-of@1.0.1",
322403          "swid": {
322404            "attachment": {}
322405          },
322406          "pedigree": {},
322407          "evidence": {},
322408          "signature": {
322409            "signature": {
322410              "publicKey": {}
322411            }
322412          },
322413          "modelCard": {
322414            "modelParameters": {
322415              "approach": {}
322416            },
322417            "quantitativeAnalysis": {
322418              "graphics": {}
322419            },
322420            "considerations": {}
322421          }
322422        },
322423        {
322424          "type": "library",
322425          "bom-ref": "pkg:npm/indexof@0.0.1?package-id=ba8e070fb1e835f3",
322426          "supplier": {},
322427          "name": "indexof",
322428          "version": "0.0.1",
322429          "cpe": "cpe:2.3:a:indexof:indexof:0.0.1:*:*:*:*:*:*:*",
322430          "purl": "pkg:npm/indexof@0.0.1",
322431          "swid": {
322432            "attachment": {}
322433          },
322434          "pedigree": {},
322435          "evidence": {},
322436          "signature": {
322437            "signature": {
322438              "publicKey": {}
322439            }
322440          },
322441          "modelCard": {
322442            "modelParameters": {
322443              "approach": {}
322444            },
322445            "quantitativeAnalysis": {
322446              "graphics": {}
322447            },
322448            "considerations": {}
322449          }
322450        },
322451        {
322452          "type": "library",
322453          "bom-ref": "pkg:npm/infer-owner@1.0.4?package-id=905292bd4dd8c25e",
322454          "supplier": {},
322455          "name": "infer-owner",
322456          "version": "1.0.4",
322457          "licenses": [
322458            {
322459              "license": {
322460                "id": "ISC"
322461              }
322462            }
322463          ],
322464          "cpe": "cpe:2.3:a:infer-owner:infer-owner:1.0.4:*:*:*:*:*:*:*",
322465          "purl": "pkg:npm/infer-owner@1.0.4",
322466          "swid": {
322467            "attachment": {}
322468          },
322469          "pedigree": {},
322470          "evidence": {},
322471          "signature": {
322472            "signature": {
322473              "publicKey": {}
322474            }
322475          },
322476          "modelCard": {
322477            "modelParameters": {
322478              "approach": {}
322479            },
322480            "quantitativeAnalysis": {
322481              "graphics": {}
322482            },
322483            "considerations": {}
322484          }
322485        },
322486        {
322487          "type": "library",
322488          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=9cf3e158cdc14617",
322489          "supplier": {},
322490          "name": "inflight",
322491          "version": "1.0.6",
322492          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
322493          "purl": "pkg:npm/inflight@1.0.6",
322494          "swid": {
322495            "attachment": {}
322496          },
322497          "pedigree": {},
322498          "evidence": {},
322499          "signature": {
322500            "signature": {
322501              "publicKey": {}
322502            }
322503          },
322504          "modelCard": {
322505            "modelParameters": {
322506              "approach": {}
322507            },
322508            "quantitativeAnalysis": {
322509              "graphics": {}
322510            },
322511            "considerations": {}
322512          }
322513        },
322514        {
322515          "type": "library",
322516          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=68ea27fe6f57bae9",
322517          "supplier": {},
322518          "name": "inflight",
322519          "version": "1.0.6",
322520          "licenses": [
322521            {
322522              "license": {
322523                "id": "ISC"
322524              }
322525            }
322526          ],
322527          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
322528          "purl": "pkg:npm/inflight@1.0.6",
322529          "swid": {
322530            "attachment": {}
322531          },
322532          "pedigree": {},
322533          "evidence": {},
322534          "signature": {
322535            "signature": {
322536              "publicKey": {}
322537            }
322538          },
322539          "modelCard": {
322540            "modelParameters": {
322541              "approach": {}
322542            },
322543            "quantitativeAnalysis": {
322544              "graphics": {}
322545            },
322546            "considerations": {}
322547          }
322548        },
322549        {
322550          "type": "library",
322551          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=4e54902333c52de3",
322552          "supplier": {},
322553          "name": "inherits",
322554          "version": "2.0.4",
322555          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
322556          "purl": "pkg:npm/inherits@2.0.4",
322557          "swid": {
322558            "attachment": {}
322559          },
322560          "pedigree": {},
322561          "evidence": {},
322562          "signature": {
322563            "signature": {
322564              "publicKey": {}
322565            }
322566          },
322567          "modelCard": {
322568            "modelParameters": {
322569              "approach": {}
322570            },
322571            "quantitativeAnalysis": {
322572              "graphics": {}
322573            },
322574            "considerations": {}
322575          }
322576        },
322577        {
322578          "type": "library",
322579          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=e8aa2200e9737250",
322580          "supplier": {},
322581          "name": "inherits",
322582          "version": "2.0.4",
322583          "licenses": [
322584            {
322585              "license": {
322586                "id": "ISC"
322587              }
322588            }
322589          ],
322590          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
322591          "purl": "pkg:npm/inherits@2.0.4",
322592          "swid": {
322593            "attachment": {}
322594          },
322595          "pedigree": {},
322596          "evidence": {},
322597          "signature": {
322598            "signature": {
322599              "publicKey": {}
322600            }
322601          },
322602          "modelCard": {
322603            "modelParameters": {
322604              "approach": {}
322605            },
322606            "quantitativeAnalysis": {
322607              "graphics": {}
322608            },
322609            "considerations": {}
322610          }
322611        },
322612        {
322613          "type": "library",
322614          "bom-ref": "pkg:npm/ini@1.3.5?package-id=4e456614ed9b7853",
322615          "supplier": {},
322616          "name": "ini",
322617          "version": "1.3.5",
322618          "licenses": [
322619            {
322620              "license": {
322621                "id": "ISC"
322622              }
322623            }
322624          ],
322625          "cpe": "cpe:2.3:a:ini:ini:1.3.5:*:*:*:*:*:*:*",
322626          "purl": "pkg:npm/ini@1.3.5",
322627          "swid": {
322628            "attachment": {}
322629          },
322630          "pedigree": {},
322631          "evidence": {},
322632          "signature": {
322633            "signature": {
322634              "publicKey": {}
322635            }
322636          },
322637          "modelCard": {
322638            "modelParameters": {
322639              "approach": {}
322640            },
322641            "quantitativeAnalysis": {
322642              "graphics": {}
322643            },
322644            "considerations": {}
322645          }
322646        },
322647        {
322648          "type": "library",
322649          "bom-ref": "pkg:npm/inquirer@7.1.0?package-id=8fe63daa61aa2b96",
322650          "supplier": {},
322651          "name": "inquirer",
322652          "version": "7.1.0",
322653          "licenses": [
322654            {
322655              "license": {
322656                "id": "MIT"
322657              }
322658            }
322659          ],
322660          "cpe": "cpe:2.3:a:inquirer:inquirer:7.1.0:*:*:*:*:*:*:*",
322661          "purl": "pkg:npm/inquirer@7.1.0",
322662          "swid": {
322663            "attachment": {}
322664          },
322665          "pedigree": {},
322666          "evidence": {},
322667          "signature": {
322668            "signature": {
322669              "publicKey": {}
322670            }
322671          },
322672          "modelCard": {
322673            "modelParameters": {
322674              "approach": {}
322675            },
322676            "quantitativeAnalysis": {
322677              "graphics": {}
322678            },
322679            "considerations": {}
322680          }
322681        },
322682        {
322683          "type": "library",
322684          "bom-ref": "pkg:npm/internal-ip@4.3.0?package-id=e48f4fce2853aa09",
322685          "supplier": {},
322686          "name": "internal-ip",
322687          "version": "4.3.0",
322688          "licenses": [
322689            {
322690              "license": {
322691                "id": "MIT"
322692              }
322693            }
322694          ],
322695          "cpe": "cpe:2.3:a:internal-ip:internal-ip:4.3.0:*:*:*:*:*:*:*",
322696          "purl": "pkg:npm/internal-ip@4.3.0",
322697          "swid": {
322698            "attachment": {}
322699          },
322700          "pedigree": {},
322701          "evidence": {},
322702          "signature": {
322703            "signature": {
322704              "publicKey": {}
322705            }
322706          },
322707          "modelCard": {
322708            "modelParameters": {
322709              "approach": {}
322710            },
322711            "quantitativeAnalysis": {
322712              "graphics": {}
322713            },
322714            "considerations": {}
322715          }
322716        },
322717        {
322718          "type": "library",
322719          "bom-ref": "pkg:npm/invariant@2.2.4?package-id=3c9df78fcad9b293",
322720          "supplier": {},
322721          "name": "invariant",
322722          "version": "2.2.4",
322723          "licenses": [
322724            {
322725              "license": {
322726                "id": "MIT"
322727              }
322728            }
322729          ],
322730          "cpe": "cpe:2.3:a:invariant:invariant:2.2.4:*:*:*:*:*:*:*",
322731          "purl": "pkg:npm/invariant@2.2.4",
322732          "swid": {
322733            "attachment": {}
322734          },
322735          "pedigree": {},
322736          "evidence": {},
322737          "signature": {
322738            "signature": {
322739              "publicKey": {}
322740            }
322741          },
322742          "modelCard": {
322743            "modelParameters": {
322744              "approach": {}
322745            },
322746            "quantitativeAnalysis": {
322747              "graphics": {}
322748            },
322749            "considerations": {}
322750          }
322751        },
322752        {
322753          "type": "library",
322754          "bom-ref": "pkg:npm/invert-kv@2.0.0?package-id=a3ccc519f4037eb5",
322755          "supplier": {},
322756          "name": "invert-kv",
322757          "version": "2.0.0",
322758          "licenses": [
322759            {
322760              "license": {
322761                "id": "MIT"
322762              }
322763            }
322764          ],
322765          "cpe": "cpe:2.3:a:invert-kv:invert-kv:2.0.0:*:*:*:*:*:*:*",
322766          "purl": "pkg:npm/invert-kv@2.0.0",
322767          "swid": {
322768            "attachment": {}
322769          },
322770          "pedigree": {},
322771          "evidence": {},
322772          "signature": {
322773            "signature": {
322774              "publicKey": {}
322775            }
322776          },
322777          "modelCard": {
322778            "modelParameters": {
322779              "approach": {}
322780            },
322781            "quantitativeAnalysis": {
322782              "graphics": {}
322783            },
322784            "considerations": {}
322785          }
322786        },
322787        {
322788          "type": "library",
322789          "bom-ref": "pkg:npm/ip@1.1.5?package-id=b133e25a7dfe0990",
322790          "supplier": {},
322791          "name": "ip",
322792          "version": "1.1.5",
322793          "licenses": [
322794            {
322795              "license": {
322796                "id": "MIT"
322797              }
322798            }
322799          ],
322800          "cpe": "cpe:2.3:a:ip:ip:1.1.5:*:*:*:*:*:*:*",
322801          "purl": "pkg:npm/ip@1.1.5",
322802          "swid": {
322803            "attachment": {}
322804          },
322805          "pedigree": {},
322806          "evidence": {},
322807          "signature": {
322808            "signature": {
322809              "publicKey": {}
322810            }
322811          },
322812          "modelCard": {
322813            "modelParameters": {
322814              "approach": {}
322815            },
322816            "quantitativeAnalysis": {
322817              "graphics": {}
322818            },
322819            "considerations": {}
322820          }
322821        },
322822        {
322823          "type": "library",
322824          "bom-ref": "pkg:npm/ip-regex@2.1.0?package-id=82ea9fd16233217e",
322825          "supplier": {},
322826          "name": "ip-regex",
322827          "version": "2.1.0",
322828          "licenses": [
322829            {
322830              "license": {
322831                "id": "MIT"
322832              }
322833            }
322834          ],
322835          "cpe": "cpe:2.3:a:ip-regex:ip-regex:2.1.0:*:*:*:*:*:*:*",
322836          "purl": "pkg:npm/ip-regex@2.1.0",
322837          "swid": {
322838            "attachment": {}
322839          },
322840          "pedigree": {},
322841          "evidence": {},
322842          "signature": {
322843            "signature": {
322844              "publicKey": {}
322845            }
322846          },
322847          "modelCard": {
322848            "modelParameters": {
322849              "approach": {}
322850            },
322851            "quantitativeAnalysis": {
322852              "graphics": {}
322853            },
322854            "considerations": {}
322855          }
322856        },
322857        {
322858          "type": "library",
322859          "bom-ref": "pkg:npm/ipaddr.js@1.9.1?package-id=95696907ab3dfa3a",
322860          "supplier": {},
322861          "name": "ipaddr.js",
322862          "version": "1.9.1",
322863          "licenses": [
322864            {
322865              "license": {
322866                "id": "MIT"
322867              }
322868            }
322869          ],
322870          "cpe": "cpe:2.3:a:ipaddr.js:ipaddr.js:1.9.1:*:*:*:*:*:*:*",
322871          "purl": "pkg:npm/ipaddr.js@1.9.1",
322872          "swid": {
322873            "attachment": {}
322874          },
322875          "pedigree": {},
322876          "evidence": {},
322877          "signature": {
322878            "signature": {
322879              "publicKey": {}
322880            }
322881          },
322882          "modelCard": {
322883            "modelParameters": {
322884              "approach": {}
322885            },
322886            "quantitativeAnalysis": {
322887              "graphics": {}
322888            },
322889            "considerations": {}
322890          }
322891        },
322892        {
322893          "type": "library",
322894          "bom-ref": "pkg:npm/is-absolute-url@2.1.0?package-id=b214b3c502d4913",
322895          "supplier": {},
322896          "name": "is-absolute-url",
322897          "version": "2.1.0",
322898          "licenses": [
322899            {
322900              "license": {
322901                "id": "MIT"
322902              }
322903            }
322904          ],
322905          "cpe": "cpe:2.3:a:is-absolute-url:is-absolute-url:2.1.0:*:*:*:*:*:*:*",
322906          "purl": "pkg:npm/is-absolute-url@2.1.0",
322907          "swid": {
322908            "attachment": {}
322909          },
322910          "pedigree": {},
322911          "evidence": {},
322912          "signature": {
322913            "signature": {
322914              "publicKey": {}
322915            }
322916          },
322917          "modelCard": {
322918            "modelParameters": {
322919              "approach": {}
322920            },
322921            "quantitativeAnalysis": {
322922              "graphics": {}
322923            },
322924            "considerations": {}
322925          }
322926        },
322927        {
322928          "type": "library",
322929          "bom-ref": "pkg:npm/is-accessor-descriptor@0.1.6?package-id=52778fed0ceeaaac",
322930          "supplier": {},
322931          "name": "is-accessor-descriptor",
322932          "version": "0.1.6",
322933          "licenses": [
322934            {
322935              "license": {
322936                "id": "MIT"
322937              }
322938            }
322939          ],
322940          "cpe": "cpe:2.3:a:is-accessor-descriptor:is-accessor-descriptor:0.1.6:*:*:*:*:*:*:*",
322941          "purl": "pkg:npm/is-accessor-descriptor@0.1.6",
322942          "swid": {
322943            "attachment": {}
322944          },
322945          "pedigree": {},
322946          "evidence": {},
322947          "signature": {
322948            "signature": {
322949              "publicKey": {}
322950            }
322951          },
322952          "modelCard": {
322953            "modelParameters": {
322954              "approach": {}
322955            },
322956            "quantitativeAnalysis": {
322957              "graphics": {}
322958            },
322959            "considerations": {}
322960          }
322961        },
322962        {
322963          "type": "library",
322964          "bom-ref": "pkg:npm/is-arguments@1.0.4?package-id=b3de7e5d9fc396e8",
322965          "supplier": {},
322966          "name": "is-arguments",
322967          "version": "1.0.4",
322968          "licenses": [
322969            {
322970              "license": {
322971                "id": "MIT"
322972              }
322973            }
322974          ],
322975          "cpe": "cpe:2.3:a:is-arguments:is-arguments:1.0.4:*:*:*:*:*:*:*",
322976          "purl": "pkg:npm/is-arguments@1.0.4",
322977          "swid": {
322978            "attachment": {}
322979          },
322980          "pedigree": {},
322981          "evidence": {},
322982          "signature": {
322983            "signature": {
322984              "publicKey": {}
322985            }
322986          },
322987          "modelCard": {
322988            "modelParameters": {
322989              "approach": {}
322990            },
322991            "quantitativeAnalysis": {
322992              "graphics": {}
322993            },
322994            "considerations": {}
322995          }
322996        },
322997        {
322998          "type": "library",
322999          "bom-ref": "pkg:npm/is-arrayish@0.2.1?package-id=e67c63a84964794c",
323000          "supplier": {},
323001          "name": "is-arrayish",
323002          "version": "0.2.1",
323003          "licenses": [
323004            {
323005              "license": {
323006                "id": "MIT"
323007              }
323008            }
323009          ],
323010          "cpe": "cpe:2.3:a:is-arrayish:is-arrayish:0.2.1:*:*:*:*:*:*:*",
323011          "purl": "pkg:npm/is-arrayish@0.2.1",
323012          "swid": {
323013            "attachment": {}
323014          },
323015          "pedigree": {},
323016          "evidence": {},
323017          "signature": {
323018            "signature": {
323019              "publicKey": {}
323020            }
323021          },
323022          "modelCard": {
323023            "modelParameters": {
323024              "approach": {}
323025            },
323026            "quantitativeAnalysis": {
323027              "graphics": {}
323028            },
323029            "considerations": {}
323030          }
323031        },
323032        {
323033          "type": "library",
323034          "bom-ref": "pkg:npm/is-binary-path@2.1.0?package-id=be32f8f31b09657c",
323035          "supplier": {},
323036          "name": "is-binary-path",
323037          "version": "2.1.0",
323038          "licenses": [
323039            {
323040              "license": {
323041                "id": "MIT"
323042              }
323043            }
323044          ],
323045          "cpe": "cpe:2.3:a:is-binary-path:is-binary-path:2.1.0:*:*:*:*:*:*:*",
323046          "purl": "pkg:npm/is-binary-path@2.1.0",
323047          "swid": {
323048            "attachment": {}
323049          },
323050          "pedigree": {},
323051          "evidence": {},
323052          "signature": {
323053            "signature": {
323054              "publicKey": {}
323055            }
323056          },
323057          "modelCard": {
323058            "modelParameters": {
323059              "approach": {}
323060            },
323061            "quantitativeAnalysis": {
323062              "graphics": {}
323063            },
323064            "considerations": {}
323065          }
323066        },
323067        {
323068          "type": "library",
323069          "bom-ref": "pkg:npm/is-buffer@1.1.6?package-id=8a6b8aeccfd36bf9",
323070          "supplier": {},
323071          "name": "is-buffer",
323072          "version": "1.1.6",
323073          "licenses": [
323074            {
323075              "license": {
323076                "id": "MIT"
323077              }
323078            }
323079          ],
323080          "cpe": "cpe:2.3:a:is-buffer:is-buffer:1.1.6:*:*:*:*:*:*:*",
323081          "purl": "pkg:npm/is-buffer@1.1.6",
323082          "swid": {
323083            "attachment": {}
323084          },
323085          "pedigree": {},
323086          "evidence": {},
323087          "signature": {
323088            "signature": {
323089              "publicKey": {}
323090            }
323091          },
323092          "modelCard": {
323093            "modelParameters": {
323094              "approach": {}
323095            },
323096            "quantitativeAnalysis": {
323097              "graphics": {}
323098            },
323099            "considerations": {}
323100          }
323101        },
323102        {
323103          "type": "library",
323104          "bom-ref": "pkg:npm/is-callable@1.1.5?package-id=b6f41fd3cb712eb6",
323105          "supplier": {},
323106          "name": "is-callable",
323107          "version": "1.1.5",
323108          "licenses": [
323109            {
323110              "license": {
323111                "id": "MIT"
323112              }
323113            }
323114          ],
323115          "cpe": "cpe:2.3:a:is-callable:is-callable:1.1.5:*:*:*:*:*:*:*",
323116          "purl": "pkg:npm/is-callable@1.1.5",
323117          "swid": {
323118            "attachment": {}
323119          },
323120          "pedigree": {},
323121          "evidence": {},
323122          "signature": {
323123            "signature": {
323124              "publicKey": {}
323125            }
323126          },
323127          "modelCard": {
323128            "modelParameters": {
323129              "approach": {}
323130            },
323131            "quantitativeAnalysis": {
323132              "graphics": {}
323133            },
323134            "considerations": {}
323135          }
323136        },
323137        {
323138          "type": "library",
323139          "bom-ref": "pkg:npm/is-ci@2.0.0?package-id=12adf7b9c264c122",
323140          "supplier": {},
323141          "name": "is-ci",
323142          "version": "2.0.0",
323143          "cpe": "cpe:2.3:a:is-ci:is-ci:2.0.0:*:*:*:*:*:*:*",
323144          "purl": "pkg:npm/is-ci@2.0.0",
323145          "swid": {
323146            "attachment": {}
323147          },
323148          "pedigree": {},
323149          "evidence": {},
323150          "signature": {
323151            "signature": {
323152              "publicKey": {}
323153            }
323154          },
323155          "modelCard": {
323156            "modelParameters": {
323157              "approach": {}
323158            },
323159            "quantitativeAnalysis": {
323160              "graphics": {}
323161            },
323162            "considerations": {}
323163          }
323164        },
323165        {
323166          "type": "library",
323167          "bom-ref": "pkg:npm/is-ci@2.0.0?package-id=dec910c961ec01c6",
323168          "supplier": {},
323169          "name": "is-ci",
323170          "version": "2.0.0",
323171          "licenses": [
323172            {
323173              "license": {
323174                "id": "MIT"
323175              }
323176            }
323177          ],
323178          "cpe": "cpe:2.3:a:is-ci:is-ci:2.0.0:*:*:*:*:*:*:*",
323179          "purl": "pkg:npm/is-ci@2.0.0",
323180          "swid": {
323181            "attachment": {}
323182          },
323183          "pedigree": {},
323184          "evidence": {},
323185          "signature": {
323186            "signature": {
323187              "publicKey": {}
323188            }
323189          },
323190          "modelCard": {
323191            "modelParameters": {
323192              "approach": {}
323193            },
323194            "quantitativeAnalysis": {
323195              "graphics": {}
323196            },
323197            "considerations": {}
323198          }
323199        },
323200        {
323201          "type": "library",
323202          "bom-ref": "pkg:npm/is-color-stop@1.1.0?package-id=a83e8bf419489f3e",
323203          "supplier": {},
323204          "name": "is-color-stop",
323205          "version": "1.1.0",
323206          "licenses": [
323207            {
323208              "license": {
323209                "id": "MIT"
323210              }
323211            }
323212          ],
323213          "cpe": "cpe:2.3:a:is-color-stop:is-color-stop:1.1.0:*:*:*:*:*:*:*",
323214          "purl": "pkg:npm/is-color-stop@1.1.0",
323215          "swid": {
323216            "attachment": {}
323217          },
323218          "pedigree": {},
323219          "evidence": {},
323220          "signature": {
323221            "signature": {
323222              "publicKey": {}
323223            }
323224          },
323225          "modelCard": {
323226            "modelParameters": {
323227              "approach": {}
323228            },
323229            "quantitativeAnalysis": {
323230              "graphics": {}
323231            },
323232            "considerations": {}
323233          }
323234        },
323235        {
323236          "type": "library",
323237          "bom-ref": "pkg:npm/is-data-descriptor@0.1.4?package-id=8f5cd91611f398aa",
323238          "supplier": {},
323239          "name": "is-data-descriptor",
323240          "version": "0.1.4",
323241          "licenses": [
323242            {
323243              "license": {
323244                "id": "MIT"
323245              }
323246            }
323247          ],
323248          "cpe": "cpe:2.3:a:is-data-descriptor:is-data-descriptor:0.1.4:*:*:*:*:*:*:*",
323249          "purl": "pkg:npm/is-data-descriptor@0.1.4",
323250          "swid": {
323251            "attachment": {}
323252          },
323253          "pedigree": {},
323254          "evidence": {},
323255          "signature": {
323256            "signature": {
323257              "publicKey": {}
323258            }
323259          },
323260          "modelCard": {
323261            "modelParameters": {
323262              "approach": {}
323263            },
323264            "quantitativeAnalysis": {
323265              "graphics": {}
323266            },
323267            "considerations": {}
323268          }
323269        },
323270        {
323271          "type": "library",
323272          "bom-ref": "pkg:npm/is-date-object@1.0.2?package-id=eff1c4270f2fd8af",
323273          "supplier": {},
323274          "name": "is-date-object",
323275          "version": "1.0.2",
323276          "licenses": [
323277            {
323278              "license": {
323279                "id": "MIT"
323280              }
323281            }
323282          ],
323283          "cpe": "cpe:2.3:a:is-date-object:is-date-object:1.0.2:*:*:*:*:*:*:*",
323284          "purl": "pkg:npm/is-date-object@1.0.2",
323285          "swid": {
323286            "attachment": {}
323287          },
323288          "pedigree": {},
323289          "evidence": {},
323290          "signature": {
323291            "signature": {
323292              "publicKey": {}
323293            }
323294          },
323295          "modelCard": {
323296            "modelParameters": {
323297              "approach": {}
323298            },
323299            "quantitativeAnalysis": {
323300              "graphics": {}
323301            },
323302            "considerations": {}
323303          }
323304        },
323305        {
323306          "type": "library",
323307          "bom-ref": "pkg:npm/is-descriptor@0.1.6?package-id=cd7e3cb0b81c1a1f",
323308          "supplier": {},
323309          "name": "is-descriptor",
323310          "version": "0.1.6",
323311          "licenses": [
323312            {
323313              "license": {
323314                "id": "MIT"
323315              }
323316            }
323317          ],
323318          "cpe": "cpe:2.3:a:is-descriptor:is-descriptor:0.1.6:*:*:*:*:*:*:*",
323319          "purl": "pkg:npm/is-descriptor@0.1.6",
323320          "swid": {
323321            "attachment": {}
323322          },
323323          "pedigree": {},
323324          "evidence": {},
323325          "signature": {
323326            "signature": {
323327              "publicKey": {}
323328            }
323329          },
323330          "modelCard": {
323331            "modelParameters": {
323332              "approach": {}
323333            },
323334            "quantitativeAnalysis": {
323335              "graphics": {}
323336            },
323337            "considerations": {}
323338          }
323339        },
323340        {
323341          "type": "library",
323342          "bom-ref": "pkg:npm/is-directory@0.3.1?package-id=3243a241678a73ed",
323343          "supplier": {},
323344          "name": "is-directory",
323345          "version": "0.3.1",
323346          "licenses": [
323347            {
323348              "license": {
323349                "id": "MIT"
323350              }
323351            }
323352          ],
323353          "cpe": "cpe:2.3:a:is-directory:is-directory:0.3.1:*:*:*:*:*:*:*",
323354          "purl": "pkg:npm/is-directory@0.3.1",
323355          "swid": {
323356            "attachment": {}
323357          },
323358          "pedigree": {},
323359          "evidence": {},
323360          "signature": {
323361            "signature": {
323362              "publicKey": {}
323363            }
323364          },
323365          "modelCard": {
323366            "modelParameters": {
323367              "approach": {}
323368            },
323369            "quantitativeAnalysis": {
323370              "graphics": {}
323371            },
323372            "considerations": {}
323373          }
323374        },
323375        {
323376          "type": "library",
323377          "bom-ref": "pkg:npm/is-docker@2.0.0?package-id=32fd27b0de0cca4c",
323378          "supplier": {},
323379          "name": "is-docker",
323380          "version": "2.0.0",
323381          "licenses": [
323382            {
323383              "license": {
323384                "id": "MIT"
323385              }
323386            }
323387          ],
323388          "cpe": "cpe:2.3:a:is-docker:is-docker:2.0.0:*:*:*:*:*:*:*",
323389          "purl": "pkg:npm/is-docker@2.0.0",
323390          "swid": {
323391            "attachment": {}
323392          },
323393          "pedigree": {},
323394          "evidence": {},
323395          "signature": {
323396            "signature": {
323397              "publicKey": {}
323398            }
323399          },
323400          "modelCard": {
323401            "modelParameters": {
323402              "approach": {}
323403            },
323404            "quantitativeAnalysis": {
323405              "graphics": {}
323406            },
323407            "considerations": {}
323408          }
323409        },
323410        {
323411          "type": "library",
323412          "bom-ref": "pkg:npm/is-docker@2.2.1?package-id=97f82b6f01e7b7c5",
323413          "supplier": {},
323414          "name": "is-docker",
323415          "version": "2.2.1",
323416          "cpe": "cpe:2.3:a:is-docker:is-docker:2.2.1:*:*:*:*:*:*:*",
323417          "purl": "pkg:npm/is-docker@2.2.1",
323418          "swid": {
323419            "attachment": {}
323420          },
323421          "pedigree": {},
323422          "evidence": {},
323423          "signature": {
323424            "signature": {
323425              "publicKey": {}
323426            }
323427          },
323428          "modelCard": {
323429            "modelParameters": {
323430              "approach": {}
323431            },
323432            "quantitativeAnalysis": {
323433              "graphics": {}
323434            },
323435            "considerations": {}
323436          }
323437        },
323438        {
323439          "type": "library",
323440          "bom-ref": "pkg:npm/is-extendable@0.1.1?package-id=46b3e22deca7021",
323441          "supplier": {},
323442          "name": "is-extendable",
323443          "version": "0.1.1",
323444          "licenses": [
323445            {
323446              "license": {
323447                "id": "MIT"
323448              }
323449            }
323450          ],
323451          "cpe": "cpe:2.3:a:is-extendable:is-extendable:0.1.1:*:*:*:*:*:*:*",
323452          "purl": "pkg:npm/is-extendable@0.1.1",
323453          "swid": {
323454            "attachment": {}
323455          },
323456          "pedigree": {},
323457          "evidence": {},
323458          "signature": {
323459            "signature": {
323460              "publicKey": {}
323461            }
323462          },
323463          "modelCard": {
323464            "modelParameters": {
323465              "approach": {}
323466            },
323467            "quantitativeAnalysis": {
323468              "graphics": {}
323469            },
323470            "considerations": {}
323471          }
323472        },
323473        {
323474          "type": "library",
323475          "bom-ref": "pkg:npm/is-extglob@1.0.0?package-id=f8a292608b987a8f",
323476          "supplier": {},
323477          "name": "is-extglob",
323478          "version": "1.0.0",
323479          "licenses": [
323480            {
323481              "license": {
323482                "id": "MIT"
323483              }
323484            }
323485          ],
323486          "cpe": "cpe:2.3:a:is-extglob:is-extglob:1.0.0:*:*:*:*:*:*:*",
323487          "purl": "pkg:npm/is-extglob@1.0.0",
323488          "swid": {
323489            "attachment": {}
323490          },
323491          "pedigree": {},
323492          "evidence": {},
323493          "signature": {
323494            "signature": {
323495              "publicKey": {}
323496            }
323497          },
323498          "modelCard": {
323499            "modelParameters": {
323500              "approach": {}
323501            },
323502            "quantitativeAnalysis": {
323503              "graphics": {}
323504            },
323505            "considerations": {}
323506          }
323507        },
323508        {
323509          "type": "library",
323510          "bom-ref": "pkg:npm/is-finite@1.1.0?package-id=80d5e21017816012",
323511          "supplier": {},
323512          "name": "is-finite",
323513          "version": "1.1.0",
323514          "licenses": [
323515            {
323516              "license": {
323517                "id": "MIT"
323518              }
323519            }
323520          ],
323521          "cpe": "cpe:2.3:a:is-finite:is-finite:1.1.0:*:*:*:*:*:*:*",
323522          "purl": "pkg:npm/is-finite@1.1.0",
323523          "swid": {
323524            "attachment": {}
323525          },
323526          "pedigree": {},
323527          "evidence": {},
323528          "signature": {
323529            "signature": {
323530              "publicKey": {}
323531            }
323532          },
323533          "modelCard": {
323534            "modelParameters": {
323535              "approach": {}
323536            },
323537            "quantitativeAnalysis": {
323538              "graphics": {}
323539            },
323540            "considerations": {}
323541          }
323542        },
323543        {
323544          "type": "library",
323545          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=3a83b589f02db0",
323546          "supplier": {},
323547          "name": "is-fullwidth-code-point",
323548          "version": "2.0.0",
323549          "licenses": [
323550            {
323551              "license": {
323552                "id": "MIT"
323553              }
323554            }
323555          ],
323556          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
323557          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
323558          "swid": {
323559            "attachment": {}
323560          },
323561          "pedigree": {},
323562          "evidence": {},
323563          "signature": {
323564            "signature": {
323565              "publicKey": {}
323566            }
323567          },
323568          "modelCard": {
323569            "modelParameters": {
323570              "approach": {}
323571            },
323572            "quantitativeAnalysis": {
323573              "graphics": {}
323574            },
323575            "considerations": {}
323576          }
323577        },
323578        {
323579          "type": "library",
323580          "bom-ref": "pkg:npm/is-fullwidth-code-point@3.0.0?package-id=c4a0ce514ed2bdc1",
323581          "supplier": {},
323582          "name": "is-fullwidth-code-point",
323583          "version": "3.0.0",
323584          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:3.0.0:*:*:*:*:*:*:*",
323585          "purl": "pkg:npm/is-fullwidth-code-point@3.0.0",
323586          "swid": {
323587            "attachment": {}
323588          },
323589          "pedigree": {},
323590          "evidence": {},
323591          "signature": {
323592            "signature": {
323593              "publicKey": {}
323594            }
323595          },
323596          "modelCard": {
323597            "modelParameters": {
323598              "approach": {}
323599            },
323600            "quantitativeAnalysis": {
323601              "graphics": {}
323602            },
323603            "considerations": {}
323604          }
323605        },
323606        {
323607          "type": "library",
323608          "bom-ref": "pkg:npm/is-glob@2.0.1?package-id=2831d0cd33897761",
323609          "supplier": {},
323610          "name": "is-glob",
323611          "version": "2.0.1",
323612          "licenses": [
323613            {
323614              "license": {
323615                "id": "MIT"
323616              }
323617            }
323618          ],
323619          "cpe": "cpe:2.3:a:is-glob:is-glob:2.0.1:*:*:*:*:*:*:*",
323620          "purl": "pkg:npm/is-glob@2.0.1",
323621          "swid": {
323622            "attachment": {}
323623          },
323624          "pedigree": {},
323625          "evidence": {},
323626          "signature": {
323627            "signature": {
323628              "publicKey": {}
323629            }
323630          },
323631          "modelCard": {
323632            "modelParameters": {
323633              "approach": {}
323634            },
323635            "quantitativeAnalysis": {
323636              "graphics": {}
323637            },
323638            "considerations": {}
323639          }
323640        },
323641        {
323642          "type": "library",
323643          "bom-ref": "pkg:npm/is-interactive@1.0.0?package-id=7c0a4fd7ef0792fe",
323644          "supplier": {},
323645          "name": "is-interactive",
323646          "version": "1.0.0",
323647          "licenses": [
323648            {
323649              "license": {
323650                "id": "MIT"
323651              }
323652            }
323653          ],
323654          "cpe": "cpe:2.3:a:is-interactive:is-interactive:1.0.0:*:*:*:*:*:*:*",
323655          "purl": "pkg:npm/is-interactive@1.0.0",
323656          "swid": {
323657            "attachment": {}
323658          },
323659          "pedigree": {},
323660          "evidence": {},
323661          "signature": {
323662            "signature": {
323663              "publicKey": {}
323664            }
323665          },
323666          "modelCard": {
323667            "modelParameters": {
323668              "approach": {}
323669            },
323670            "quantitativeAnalysis": {
323671              "graphics": {}
323672            },
323673            "considerations": {}
323674          }
323675        },
323676        {
323677          "type": "library",
323678          "bom-ref": "pkg:npm/is-invalid-path@0.1.0?package-id=8b20d4d3ed93b67a",
323679          "supplier": {},
323680          "name": "is-invalid-path",
323681          "version": "0.1.0",
323682          "licenses": [
323683            {
323684              "license": {
323685                "id": "MIT"
323686              }
323687            }
323688          ],
323689          "cpe": "cpe:2.3:a:is-invalid-path:is-invalid-path:0.1.0:*:*:*:*:*:*:*",
323690          "purl": "pkg:npm/is-invalid-path@0.1.0",
323691          "swid": {
323692            "attachment": {}
323693          },
323694          "pedigree": {},
323695          "evidence": {},
323696          "signature": {
323697            "signature": {
323698              "publicKey": {}
323699            }
323700          },
323701          "modelCard": {
323702            "modelParameters": {
323703              "approach": {}
323704            },
323705            "quantitativeAnalysis": {
323706              "graphics": {}
323707            },
323708            "considerations": {}
323709          }
323710        },
323711        {
323712          "type": "library",
323713          "bom-ref": "pkg:npm/is-number@7.0.0?package-id=795e1d1e82106cf3",
323714          "supplier": {},
323715          "name": "is-number",
323716          "version": "7.0.0",
323717          "cpe": "cpe:2.3:a:is-number:is-number:7.0.0:*:*:*:*:*:*:*",
323718          "purl": "pkg:npm/is-number@7.0.0",
323719          "swid": {
323720            "attachment": {}
323721          },
323722          "pedigree": {},
323723          "evidence": {},
323724          "signature": {
323725            "signature": {
323726              "publicKey": {}
323727            }
323728          },
323729          "modelCard": {
323730            "modelParameters": {
323731              "approach": {}
323732            },
323733            "quantitativeAnalysis": {
323734              "graphics": {}
323735            },
323736            "considerations": {}
323737          }
323738        },
323739        {
323740          "type": "library",
323741          "bom-ref": "pkg:npm/is-number@7.0.0?package-id=98fc2971ac328cef",
323742          "supplier": {},
323743          "name": "is-number",
323744          "version": "7.0.0",
323745          "licenses": [
323746            {
323747              "license": {
323748                "id": "MIT"
323749              }
323750            }
323751          ],
323752          "cpe": "cpe:2.3:a:is-number:is-number:7.0.0:*:*:*:*:*:*:*",
323753          "purl": "pkg:npm/is-number@7.0.0",
323754          "swid": {
323755            "attachment": {}
323756          },
323757          "pedigree": {},
323758          "evidence": {},
323759          "signature": {
323760            "signature": {
323761              "publicKey": {}
323762            }
323763          },
323764          "modelCard": {
323765            "modelParameters": {
323766              "approach": {}
323767            },
323768            "quantitativeAnalysis": {
323769              "graphics": {}
323770            },
323771            "considerations": {}
323772          }
323773        },
323774        {
323775          "type": "library",
323776          "bom-ref": "pkg:npm/is-obj@2.0.0?package-id=daee69d950c7f8d3",
323777          "supplier": {},
323778          "name": "is-obj",
323779          "version": "2.0.0",
323780          "licenses": [
323781            {
323782              "license": {
323783                "id": "MIT"
323784              }
323785            }
323786          ],
323787          "cpe": "cpe:2.3:a:is-obj:is-obj:2.0.0:*:*:*:*:*:*:*",
323788          "purl": "pkg:npm/is-obj@2.0.0",
323789          "swid": {
323790            "attachment": {}
323791          },
323792          "pedigree": {},
323793          "evidence": {},
323794          "signature": {
323795            "signature": {
323796              "publicKey": {}
323797            }
323798          },
323799          "modelCard": {
323800            "modelParameters": {
323801              "approach": {}
323802            },
323803            "quantitativeAnalysis": {
323804              "graphics": {}
323805            },
323806            "considerations": {}
323807          }
323808        },
323809        {
323810          "type": "library",
323811          "bom-ref": "pkg:npm/is-path-cwd@2.2.0?package-id=9d29689f13fee97a",
323812          "supplier": {},
323813          "name": "is-path-cwd",
323814          "version": "2.2.0",
323815          "licenses": [
323816            {
323817              "license": {
323818                "id": "MIT"
323819              }
323820            }
323821          ],
323822          "cpe": "cpe:2.3:a:is-path-cwd:is-path-cwd:2.2.0:*:*:*:*:*:*:*",
323823          "purl": "pkg:npm/is-path-cwd@2.2.0",
323824          "swid": {
323825            "attachment": {}
323826          },
323827          "pedigree": {},
323828          "evidence": {},
323829          "signature": {
323830            "signature": {
323831              "publicKey": {}
323832            }
323833          },
323834          "modelCard": {
323835            "modelParameters": {
323836              "approach": {}
323837            },
323838            "quantitativeAnalysis": {
323839              "graphics": {}
323840            },
323841            "considerations": {}
323842          }
323843        },
323844        {
323845          "type": "library",
323846          "bom-ref": "pkg:npm/is-path-in-cwd@2.1.0?package-id=8d866a4eaaa71f43",
323847          "supplier": {},
323848          "name": "is-path-in-cwd",
323849          "version": "2.1.0",
323850          "licenses": [
323851            {
323852              "license": {
323853                "id": "MIT"
323854              }
323855            }
323856          ],
323857          "cpe": "cpe:2.3:a:is-path-in-cwd:is-path-in-cwd:2.1.0:*:*:*:*:*:*:*",
323858          "purl": "pkg:npm/is-path-in-cwd@2.1.0",
323859          "swid": {
323860            "attachment": {}
323861          },
323862          "pedigree": {},
323863          "evidence": {},
323864          "signature": {
323865            "signature": {
323866              "publicKey": {}
323867            }
323868          },
323869          "modelCard": {
323870            "modelParameters": {
323871              "approach": {}
323872            },
323873            "quantitativeAnalysis": {
323874              "graphics": {}
323875            },
323876            "considerations": {}
323877          }
323878        },
323879        {
323880          "type": "library",
323881          "bom-ref": "pkg:npm/is-path-inside@2.1.0?package-id=b68dc63164117e",
323882          "supplier": {},
323883          "name": "is-path-inside",
323884          "version": "2.1.0",
323885          "licenses": [
323886            {
323887              "license": {
323888                "id": "MIT"
323889              }
323890            }
323891          ],
323892          "cpe": "cpe:2.3:a:is-path-inside:is-path-inside:2.1.0:*:*:*:*:*:*:*",
323893          "purl": "pkg:npm/is-path-inside@2.1.0",
323894          "swid": {
323895            "attachment": {}
323896          },
323897          "pedigree": {},
323898          "evidence": {},
323899          "signature": {
323900            "signature": {
323901              "publicKey": {}
323902            }
323903          },
323904          "modelCard": {
323905            "modelParameters": {
323906              "approach": {}
323907            },
323908            "quantitativeAnalysis": {
323909              "graphics": {}
323910            },
323911            "considerations": {}
323912          }
323913        },
323914        {
323915          "type": "library",
323916          "bom-ref": "pkg:npm/is-plain-obj@1.1.0?package-id=e82e68e16e9802af",
323917          "supplier": {},
323918          "name": "is-plain-obj",
323919          "version": "1.1.0",
323920          "licenses": [
323921            {
323922              "license": {
323923                "id": "MIT"
323924              }
323925            }
323926          ],
323927          "cpe": "cpe:2.3:a:is-plain-obj:is-plain-obj:1.1.0:*:*:*:*:*:*:*",
323928          "purl": "pkg:npm/is-plain-obj@1.1.0",
323929          "swid": {
323930            "attachment": {}
323931          },
323932          "pedigree": {},
323933          "evidence": {},
323934          "signature": {
323935            "signature": {
323936              "publicKey": {}
323937            }
323938          },
323939          "modelCard": {
323940            "modelParameters": {
323941              "approach": {}
323942            },
323943            "quantitativeAnalysis": {
323944              "graphics": {}
323945            },
323946            "considerations": {}
323947          }
323948        },
323949        {
323950          "type": "library",
323951          "bom-ref": "pkg:npm/is-plain-object@2.0.4?package-id=2de9894e27c11cc3",
323952          "supplier": {},
323953          "name": "is-plain-object",
323954          "version": "2.0.4",
323955          "licenses": [
323956            {
323957              "license": {
323958                "id": "MIT"
323959              }
323960            }
323961          ],
323962          "cpe": "cpe:2.3:a:is-plain-object:is-plain-object:2.0.4:*:*:*:*:*:*:*",
323963          "purl": "pkg:npm/is-plain-object@2.0.4",
323964          "swid": {
323965            "attachment": {}
323966          },
323967          "pedigree": {},
323968          "evidence": {},
323969          "signature": {
323970            "signature": {
323971              "publicKey": {}
323972            }
323973          },
323974          "modelCard": {
323975            "modelParameters": {
323976              "approach": {}
323977            },
323978            "quantitativeAnalysis": {
323979              "graphics": {}
323980            },
323981            "considerations": {}
323982          }
323983        },
323984        {
323985          "type": "library",
323986          "bom-ref": "pkg:npm/is-promise@2.1.0?package-id=d9604e6dd3fff002",
323987          "supplier": {},
323988          "name": "is-promise",
323989          "version": "2.1.0",
323990          "licenses": [
323991            {
323992              "license": {
323993                "id": "MIT"
323994              }
323995            }
323996          ],
323997          "cpe": "cpe:2.3:a:is-promise:is-promise:2.1.0:*:*:*:*:*:*:*",
323998          "purl": "pkg:npm/is-promise@2.1.0",
323999          "swid": {
324000            "attachment": {}
324001          },
324002          "pedigree": {},
324003          "evidence": {},
324004          "signature": {
324005            "signature": {
324006              "publicKey": {}
324007            }
324008          },
324009          "modelCard": {
324010            "modelParameters": {
324011              "approach": {}
324012            },
324013            "quantitativeAnalysis": {
324014              "graphics": {}
324015            },
324016            "considerations": {}
324017          }
324018        },
324019        {
324020          "type": "library",
324021          "bom-ref": "pkg:npm/is-regex@1.0.5?package-id=1da33a1716d0ca35",
324022          "supplier": {},
324023          "name": "is-regex",
324024          "version": "1.0.5",
324025          "licenses": [
324026            {
324027              "license": {
324028                "id": "MIT"
324029              }
324030            }
324031          ],
324032          "cpe": "cpe:2.3:a:is-regex:is-regex:1.0.5:*:*:*:*:*:*:*",
324033          "purl": "pkg:npm/is-regex@1.0.5",
324034          "swid": {
324035            "attachment": {}
324036          },
324037          "pedigree": {},
324038          "evidence": {},
324039          "signature": {
324040            "signature": {
324041              "publicKey": {}
324042            }
324043          },
324044          "modelCard": {
324045            "modelParameters": {
324046              "approach": {}
324047            },
324048            "quantitativeAnalysis": {
324049              "graphics": {}
324050            },
324051            "considerations": {}
324052          }
324053        },
324054        {
324055          "type": "library",
324056          "bom-ref": "pkg:npm/is-resolvable@1.1.0?package-id=2051d5196acb1078",
324057          "supplier": {},
324058          "name": "is-resolvable",
324059          "version": "1.1.0",
324060          "licenses": [
324061            {
324062              "license": {
324063                "id": "ISC"
324064              }
324065            }
324066          ],
324067          "cpe": "cpe:2.3:a:is-resolvable:is-resolvable:1.1.0:*:*:*:*:*:*:*",
324068          "purl": "pkg:npm/is-resolvable@1.1.0",
324069          "swid": {
324070            "attachment": {}
324071          },
324072          "pedigree": {},
324073          "evidence": {},
324074          "signature": {
324075            "signature": {
324076              "publicKey": {}
324077            }
324078          },
324079          "modelCard": {
324080            "modelParameters": {
324081              "approach": {}
324082            },
324083            "quantitativeAnalysis": {
324084              "graphics": {}
324085            },
324086            "considerations": {}
324087          }
324088        },
324089        {
324090          "type": "library",
324091          "bom-ref": "pkg:npm/is-stream@1.1.0?package-id=290af436785fa663",
324092          "supplier": {},
324093          "name": "is-stream",
324094          "version": "1.1.0",
324095          "licenses": [
324096            {
324097              "license": {
324098                "id": "MIT"
324099              }
324100            }
324101          ],
324102          "cpe": "cpe:2.3:a:is-stream:is-stream:1.1.0:*:*:*:*:*:*:*",
324103          "purl": "pkg:npm/is-stream@1.1.0",
324104          "swid": {
324105            "attachment": {}
324106          },
324107          "pedigree": {},
324108          "evidence": {},
324109          "signature": {
324110            "signature": {
324111              "publicKey": {}
324112            }
324113          },
324114          "modelCard": {
324115            "modelParameters": {
324116              "approach": {}
324117            },
324118            "quantitativeAnalysis": {
324119              "graphics": {}
324120            },
324121            "considerations": {}
324122          }
324123        },
324124        {
324125          "type": "library",
324126          "bom-ref": "pkg:npm/is-stream@2.0.1?package-id=b7020eef79da7a2f",
324127          "supplier": {},
324128          "name": "is-stream",
324129          "version": "2.0.1",
324130          "cpe": "cpe:2.3:a:is-stream:is-stream:2.0.1:*:*:*:*:*:*:*",
324131          "purl": "pkg:npm/is-stream@2.0.1",
324132          "swid": {
324133            "attachment": {}
324134          },
324135          "pedigree": {},
324136          "evidence": {},
324137          "signature": {
324138            "signature": {
324139              "publicKey": {}
324140            }
324141          },
324142          "modelCard": {
324143            "modelParameters": {
324144              "approach": {}
324145            },
324146            "quantitativeAnalysis": {
324147              "graphics": {}
324148            },
324149            "considerations": {}
324150          }
324151        },
324152        {
324153          "type": "library",
324154          "bom-ref": "pkg:npm/is-svg@3.0.0?package-id=448d25753dcf6755",
324155          "supplier": {},
324156          "name": "is-svg",
324157          "version": "3.0.0",
324158          "licenses": [
324159            {
324160              "license": {
324161                "id": "MIT"
324162              }
324163            }
324164          ],
324165          "cpe": "cpe:2.3:a:is-svg:is-svg:3.0.0:*:*:*:*:*:*:*",
324166          "purl": "pkg:npm/is-svg@3.0.0",
324167          "swid": {
324168            "attachment": {}
324169          },
324170          "pedigree": {},
324171          "evidence": {},
324172          "signature": {
324173            "signature": {
324174              "publicKey": {}
324175            }
324176          },
324177          "modelCard": {
324178            "modelParameters": {
324179              "approach": {}
324180            },
324181            "quantitativeAnalysis": {
324182              "graphics": {}
324183            },
324184            "considerations": {}
324185          }
324186        },
324187        {
324188          "type": "library",
324189          "bom-ref": "pkg:npm/is-symbol@1.0.3?package-id=a86a8b57006b79e0",
324190          "supplier": {},
324191          "name": "is-symbol",
324192          "version": "1.0.3",
324193          "licenses": [
324194            {
324195              "license": {
324196                "id": "MIT"
324197              }
324198            }
324199          ],
324200          "cpe": "cpe:2.3:a:is-symbol:is-symbol:1.0.3:*:*:*:*:*:*:*",
324201          "purl": "pkg:npm/is-symbol@1.0.3",
324202          "swid": {
324203            "attachment": {}
324204          },
324205          "pedigree": {},
324206          "evidence": {},
324207          "signature": {
324208            "signature": {
324209              "publicKey": {}
324210            }
324211          },
324212          "modelCard": {
324213            "modelParameters": {
324214              "approach": {}
324215            },
324216            "quantitativeAnalysis": {
324217              "graphics": {}
324218            },
324219            "considerations": {}
324220          }
324221        },
324222        {
324223          "type": "library",
324224          "bom-ref": "pkg:npm/is-typedarray@1.0.0?package-id=1237946ebc1127a3",
324225          "supplier": {},
324226          "name": "is-typedarray",
324227          "version": "1.0.0",
324228          "cpe": "cpe:2.3:a:is-typedarray:is-typedarray:1.0.0:*:*:*:*:*:*:*",
324229          "purl": "pkg:npm/is-typedarray@1.0.0",
324230          "swid": {
324231            "attachment": {}
324232          },
324233          "pedigree": {},
324234          "evidence": {},
324235          "signature": {
324236            "signature": {
324237              "publicKey": {}
324238            }
324239          },
324240          "modelCard": {
324241            "modelParameters": {
324242              "approach": {}
324243            },
324244            "quantitativeAnalysis": {
324245              "graphics": {}
324246            },
324247            "considerations": {}
324248          }
324249        },
324250        {
324251          "type": "library",
324252          "bom-ref": "pkg:npm/is-typedarray@1.0.0?package-id=a8a7526a7be6ffaf",
324253          "supplier": {},
324254          "name": "is-typedarray",
324255          "version": "1.0.0",
324256          "licenses": [
324257            {
324258              "license": {
324259                "id": "MIT"
324260              }
324261            }
324262          ],
324263          "cpe": "cpe:2.3:a:is-typedarray:is-typedarray:1.0.0:*:*:*:*:*:*:*",
324264          "purl": "pkg:npm/is-typedarray@1.0.0",
324265          "swid": {
324266            "attachment": {}
324267          },
324268          "pedigree": {},
324269          "evidence": {},
324270          "signature": {
324271            "signature": {
324272              "publicKey": {}
324273            }
324274          },
324275          "modelCard": {
324276            "modelParameters": {
324277              "approach": {}
324278            },
324279            "quantitativeAnalysis": {
324280              "graphics": {}
324281            },
324282            "considerations": {}
324283          }
324284        },
324285        {
324286          "type": "library",
324287          "bom-ref": "pkg:npm/is-utf8@0.2.1?package-id=b50b42f55203de82",
324288          "supplier": {},
324289          "name": "is-utf8",
324290          "version": "0.2.1",
324291          "licenses": [
324292            {
324293              "license": {
324294                "id": "MIT"
324295              }
324296            }
324297          ],
324298          "cpe": "cpe:2.3:a:is-utf8:is-utf8:0.2.1:*:*:*:*:*:*:*",
324299          "purl": "pkg:npm/is-utf8@0.2.1",
324300          "swid": {
324301            "attachment": {}
324302          },
324303          "pedigree": {},
324304          "evidence": {},
324305          "signature": {
324306            "signature": {
324307              "publicKey": {}
324308            }
324309          },
324310          "modelCard": {
324311            "modelParameters": {
324312              "approach": {}
324313            },
324314            "quantitativeAnalysis": {
324315              "graphics": {}
324316            },
324317            "considerations": {}
324318          }
324319        },
324320        {
324321          "type": "library",
324322          "bom-ref": "pkg:npm/is-valid-path@0.1.1?package-id=d614436521b5b67f",
324323          "supplier": {},
324324          "name": "is-valid-path",
324325          "version": "0.1.1",
324326          "licenses": [
324327            {
324328              "license": {
324329                "id": "MIT"
324330              }
324331            }
324332          ],
324333          "cpe": "cpe:2.3:a:is-valid-path:is-valid-path:0.1.1:*:*:*:*:*:*:*",
324334          "purl": "pkg:npm/is-valid-path@0.1.1",
324335          "swid": {
324336            "attachment": {}
324337          },
324338          "pedigree": {},
324339          "evidence": {},
324340          "signature": {
324341            "signature": {
324342              "publicKey": {}
324343            }
324344          },
324345          "modelCard": {
324346            "modelParameters": {
324347              "approach": {}
324348            },
324349            "quantitativeAnalysis": {
324350              "graphics": {}
324351            },
324352            "considerations": {}
324353          }
324354        },
324355        {
324356          "type": "library",
324357          "bom-ref": "pkg:npm/is-windows@1.0.2?package-id=c4d75db58bbb41d0",
324358          "supplier": {},
324359          "name": "is-windows",
324360          "version": "1.0.2",
324361          "cpe": "cpe:2.3:a:is-windows:is-windows:1.0.2:*:*:*:*:*:*:*",
324362          "purl": "pkg:npm/is-windows@1.0.2",
324363          "swid": {
324364            "attachment": {}
324365          },
324366          "pedigree": {},
324367          "evidence": {},
324368          "signature": {
324369            "signature": {
324370              "publicKey": {}
324371            }
324372          },
324373          "modelCard": {
324374            "modelParameters": {
324375              "approach": {}
324376            },
324377            "quantitativeAnalysis": {
324378              "graphics": {}
324379            },
324380            "considerations": {}
324381          }
324382        },
324383        {
324384          "type": "library",
324385          "bom-ref": "pkg:npm/is-windows@1.0.2?package-id=3e910a9c661cf434",
324386          "supplier": {},
324387          "name": "is-windows",
324388          "version": "1.0.2",
324389          "licenses": [
324390            {
324391              "license": {
324392                "id": "MIT"
324393              }
324394            }
324395          ],
324396          "cpe": "cpe:2.3:a:is-windows:is-windows:1.0.2:*:*:*:*:*:*:*",
324397          "purl": "pkg:npm/is-windows@1.0.2",
324398          "swid": {
324399            "attachment": {}
324400          },
324401          "pedigree": {},
324402          "evidence": {},
324403          "signature": {
324404            "signature": {
324405              "publicKey": {}
324406            }
324407          },
324408          "modelCard": {
324409            "modelParameters": {
324410              "approach": {}
324411            },
324412            "quantitativeAnalysis": {
324413              "graphics": {}
324414            },
324415            "considerations": {}
324416          }
324417        },
324418        {
324419          "type": "library",
324420          "bom-ref": "pkg:npm/is-wsl@2.2.0?package-id=c4ac676a9af6c51c",
324421          "supplier": {},
324422          "name": "is-wsl",
324423          "version": "2.2.0",
324424          "cpe": "cpe:2.3:a:is-wsl:is-wsl:2.2.0:*:*:*:*:*:*:*",
324425          "purl": "pkg:npm/is-wsl@2.2.0",
324426          "swid": {
324427            "attachment": {}
324428          },
324429          "pedigree": {},
324430          "evidence": {},
324431          "signature": {
324432            "signature": {
324433              "publicKey": {}
324434            }
324435          },
324436          "modelCard": {
324437            "modelParameters": {
324438              "approach": {}
324439            },
324440            "quantitativeAnalysis": {
324441              "graphics": {}
324442            },
324443            "considerations": {}
324444          }
324445        },
324446        {
324447          "type": "library",
324448          "bom-ref": "pkg:npm/is-wsl@2.2.0?package-id=4d541859b87a4641",
324449          "supplier": {},
324450          "name": "is-wsl",
324451          "version": "2.2.0",
324452          "licenses": [
324453            {
324454              "license": {
324455                "id": "MIT"
324456              }
324457            }
324458          ],
324459          "cpe": "cpe:2.3:a:is-wsl:is-wsl:2.2.0:*:*:*:*:*:*:*",
324460          "purl": "pkg:npm/is-wsl@2.2.0",
324461          "swid": {
324462            "attachment": {}
324463          },
324464          "pedigree": {},
324465          "evidence": {},
324466          "signature": {
324467            "signature": {
324468              "publicKey": {}
324469            }
324470          },
324471          "modelCard": {
324472            "modelParameters": {
324473              "approach": {}
324474            },
324475            "quantitativeAnalysis": {
324476              "graphics": {}
324477            },
324478            "considerations": {}
324479          }
324480        },
324481        {
324482          "type": "library",
324483          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=2601df04effb6ad2",
324484          "supplier": {},
324485          "name": "isarray",
324486          "version": "1.0.0",
324487          "licenses": [
324488            {
324489              "license": {
324490                "id": "MIT"
324491              }
324492            }
324493          ],
324494          "cpe": "cpe:2.3:a:isarray:isarray:1.0.0:*:*:*:*:*:*:*",
324495          "purl": "pkg:npm/isarray@1.0.0",
324496          "swid": {
324497            "attachment": {}
324498          },
324499          "pedigree": {},
324500          "evidence": {},
324501          "signature": {
324502            "signature": {
324503              "publicKey": {}
324504            }
324505          },
324506          "modelCard": {
324507            "modelParameters": {
324508              "approach": {}
324509            },
324510            "quantitativeAnalysis": {
324511              "graphics": {}
324512            },
324513            "considerations": {}
324514          }
324515        },
324516        {
324517          "type": "library",
324518          "bom-ref": "pkg:npm/isbinaryfile@4.0.6?package-id=fa5278a6ed911ec8",
324519          "supplier": {},
324520          "name": "isbinaryfile",
324521          "version": "4.0.6",
324522          "licenses": [
324523            {
324524              "license": {
324525                "id": "MIT"
324526              }
324527            }
324528          ],
324529          "cpe": "cpe:2.3:a:isbinaryfile:isbinaryfile:4.0.6:*:*:*:*:*:*:*",
324530          "purl": "pkg:npm/isbinaryfile@4.0.6",
324531          "swid": {
324532            "attachment": {}
324533          },
324534          "pedigree": {},
324535          "evidence": {},
324536          "signature": {
324537            "signature": {
324538              "publicKey": {}
324539            }
324540          },
324541          "modelCard": {
324542            "modelParameters": {
324543              "approach": {}
324544            },
324545            "quantitativeAnalysis": {
324546              "graphics": {}
324547            },
324548            "considerations": {}
324549          }
324550        },
324551        {
324552          "type": "library",
324553          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=76b24c61d8683af9",
324554          "supplier": {},
324555          "name": "isexe",
324556          "version": "2.0.0",
324557          "cpe": "cpe:2.3:a:isexe:isexe:2.0.0:*:*:*:*:*:*:*",
324558          "purl": "pkg:npm/isexe@2.0.0",
324559          "swid": {
324560            "attachment": {}
324561          },
324562          "pedigree": {},
324563          "evidence": {},
324564          "signature": {
324565            "signature": {
324566              "publicKey": {}
324567            }
324568          },
324569          "modelCard": {
324570            "modelParameters": {
324571              "approach": {}
324572            },
324573            "quantitativeAnalysis": {
324574              "graphics": {}
324575            },
324576            "considerations": {}
324577          }
324578        },
324579        {
324580          "type": "library",
324581          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=684a241c6286581e",
324582          "supplier": {},
324583          "name": "isexe",
324584          "version": "2.0.0",
324585          "licenses": [
324586            {
324587              "license": {
324588                "id": "ISC"
324589              }
324590            }
324591          ],
324592          "cpe": "cpe:2.3:a:isexe:isexe:2.0.0:*:*:*:*:*:*:*",
324593          "purl": "pkg:npm/isexe@2.0.0",
324594          "swid": {
324595            "attachment": {}
324596          },
324597          "pedigree": {},
324598          "evidence": {},
324599          "signature": {
324600            "signature": {
324601              "publicKey": {}
324602            }
324603          },
324604          "modelCard": {
324605            "modelParameters": {
324606              "approach": {}
324607            },
324608            "quantitativeAnalysis": {
324609              "graphics": {}
324610            },
324611            "considerations": {}
324612          }
324613        },
324614        {
324615          "type": "library",
324616          "bom-ref": "pkg:npm/isobject@3.0.1?package-id=5fe8984746338c7e",
324617          "supplier": {},
324618          "name": "isobject",
324619          "version": "3.0.1",
324620          "licenses": [
324621            {
324622              "license": {
324623                "id": "MIT"
324624              }
324625            }
324626          ],
324627          "cpe": "cpe:2.3:a:isobject:isobject:3.0.1:*:*:*:*:*:*:*",
324628          "purl": "pkg:npm/isobject@3.0.1",
324629          "swid": {
324630            "attachment": {}
324631          },
324632          "pedigree": {},
324633          "evidence": {},
324634          "signature": {
324635            "signature": {
324636              "publicKey": {}
324637            }
324638          },
324639          "modelCard": {
324640            "modelParameters": {
324641              "approach": {}
324642            },
324643            "quantitativeAnalysis": {
324644              "graphics": {}
324645            },
324646            "considerations": {}
324647          }
324648        },
324649        {
324650          "type": "library",
324651          "bom-ref": "pkg:npm/isstream@0.1.2?package-id=6de000f9ce16c1f",
324652          "supplier": {},
324653          "name": "isstream",
324654          "version": "0.1.2",
324655          "licenses": [
324656            {
324657              "license": {
324658                "id": "MIT"
324659              }
324660            }
324661          ],
324662          "cpe": "cpe:2.3:a:isstream:isstream:0.1.2:*:*:*:*:*:*:*",
324663          "purl": "pkg:npm/isstream@0.1.2",
324664          "swid": {
324665            "attachment": {}
324666          },
324667          "pedigree": {},
324668          "evidence": {},
324669          "signature": {
324670            "signature": {
324671              "publicKey": {}
324672            }
324673          },
324674          "modelCard": {
324675            "modelParameters": {
324676              "approach": {}
324677            },
324678            "quantitativeAnalysis": {
324679              "graphics": {}
324680            },
324681            "considerations": {}
324682          }
324683        },
324684        {
324685          "type": "library",
324686          "bom-ref": "pkg:npm/istanbul-api@2.1.6?package-id=1ae0ce4b3f2fae9b",
324687          "supplier": {},
324688          "name": "istanbul-api",
324689          "version": "2.1.6",
324690          "licenses": [
324691            {
324692              "license": {
324693                "id": "BSD-3-Clause"
324694              }
324695            }
324696          ],
324697          "cpe": "cpe:2.3:a:istanbul-api:istanbul-api:2.1.6:*:*:*:*:*:*:*",
324698          "purl": "pkg:npm/istanbul-api@2.1.6",
324699          "swid": {
324700            "attachment": {}
324701          },
324702          "pedigree": {},
324703          "evidence": {},
324704          "signature": {
324705            "signature": {
324706              "publicKey": {}
324707            }
324708          },
324709          "modelCard": {
324710            "modelParameters": {
324711              "approach": {}
324712            },
324713            "quantitativeAnalysis": {
324714              "graphics": {}
324715            },
324716            "considerations": {}
324717          }
324718        },
324719        {
324720          "type": "library",
324721          "bom-ref": "pkg:npm/istanbul-lib-coverage@3.0.0?package-id=f2a8580ece8bf2da",
324722          "supplier": {},
324723          "name": "istanbul-lib-coverage",
324724          "version": "3.0.0",
324725          "licenses": [
324726            {
324727              "license": {
324728                "id": "BSD-3-Clause"
324729              }
324730            }
324731          ],
324732          "cpe": "cpe:2.3:a:istanbul-lib-coverage:istanbul-lib-coverage:3.0.0:*:*:*:*:*:*:*",
324733          "purl": "pkg:npm/istanbul-lib-coverage@3.0.0",
324734          "swid": {
324735            "attachment": {}
324736          },
324737          "pedigree": {},
324738          "evidence": {},
324739          "signature": {
324740            "signature": {
324741              "publicKey": {}
324742            }
324743          },
324744          "modelCard": {
324745            "modelParameters": {
324746              "approach": {}
324747            },
324748            "quantitativeAnalysis": {
324749              "graphics": {}
324750            },
324751            "considerations": {}
324752          }
324753        },
324754        {
324755          "type": "library",
324756          "bom-ref": "pkg:npm/istanbul-lib-coverage@3.2.0?package-id=6c21a800a9a1c352",
324757          "supplier": {},
324758          "name": "istanbul-lib-coverage",
324759          "version": "3.2.0",
324760          "cpe": "cpe:2.3:a:istanbul-lib-coverage:istanbul-lib-coverage:3.2.0:*:*:*:*:*:*:*",
324761          "purl": "pkg:npm/istanbul-lib-coverage@3.2.0",
324762          "swid": {
324763            "attachment": {}
324764          },
324765          "pedigree": {},
324766          "evidence": {},
324767          "signature": {
324768            "signature": {
324769              "publicKey": {}
324770            }
324771          },
324772          "modelCard": {
324773            "modelParameters": {
324774              "approach": {}
324775            },
324776            "quantitativeAnalysis": {
324777              "graphics": {}
324778            },
324779            "considerations": {}
324780          }
324781        },
324782        {
324783          "type": "library",
324784          "bom-ref": "pkg:npm/istanbul-lib-hook@2.0.7?package-id=b963d91e2ffc20f9",
324785          "supplier": {},
324786          "name": "istanbul-lib-hook",
324787          "version": "2.0.7",
324788          "licenses": [
324789            {
324790              "license": {
324791                "id": "BSD-3-Clause"
324792              }
324793            }
324794          ],
324795          "cpe": "cpe:2.3:a:istanbul-lib-hook:istanbul-lib-hook:2.0.7:*:*:*:*:*:*:*",
324796          "purl": "pkg:npm/istanbul-lib-hook@2.0.7",
324797          "swid": {
324798            "attachment": {}
324799          },
324800          "pedigree": {},
324801          "evidence": {},
324802          "signature": {
324803            "signature": {
324804              "publicKey": {}
324805            }
324806          },
324807          "modelCard": {
324808            "modelParameters": {
324809              "approach": {}
324810            },
324811            "quantitativeAnalysis": {
324812              "graphics": {}
324813            },
324814            "considerations": {}
324815          }
324816        },
324817        {
324818          "type": "library",
324819          "bom-ref": "pkg:npm/istanbul-lib-hook@3.0.0?package-id=98c2f2466f66817c",
324820          "supplier": {},
324821          "name": "istanbul-lib-hook",
324822          "version": "3.0.0",
324823          "cpe": "cpe:2.3:a:istanbul-lib-hook:istanbul-lib-hook:3.0.0:*:*:*:*:*:*:*",
324824          "purl": "pkg:npm/istanbul-lib-hook@3.0.0",
324825          "swid": {
324826            "attachment": {}
324827          },
324828          "pedigree": {},
324829          "evidence": {},
324830          "signature": {
324831            "signature": {
324832              "publicKey": {}
324833            }
324834          },
324835          "modelCard": {
324836            "modelParameters": {
324837              "approach": {}
324838            },
324839            "quantitativeAnalysis": {
324840              "graphics": {}
324841            },
324842            "considerations": {}
324843          }
324844        },
324845        {
324846          "type": "library",
324847          "bom-ref": "pkg:npm/istanbul-lib-instrument@4.0.3?package-id=9c4745f614c9052c",
324848          "supplier": {},
324849          "name": "istanbul-lib-instrument",
324850          "version": "4.0.3",
324851          "cpe": "cpe:2.3:a:istanbul-lib-instrument:istanbul-lib-instrument:4.0.3:*:*:*:*:*:*:*",
324852          "purl": "pkg:npm/istanbul-lib-instrument@4.0.3",
324853          "swid": {
324854            "attachment": {}
324855          },
324856          "pedigree": {},
324857          "evidence": {},
324858          "signature": {
324859            "signature": {
324860              "publicKey": {}
324861            }
324862          },
324863          "modelCard": {
324864            "modelParameters": {
324865              "approach": {}
324866            },
324867            "quantitativeAnalysis": {
324868              "graphics": {}
324869            },
324870            "considerations": {}
324871          }
324872        },
324873        {
324874          "type": "library",
324875          "bom-ref": "pkg:npm/istanbul-lib-instrument@4.0.3?package-id=eef49cc6b9533f3c",
324876          "supplier": {},
324877          "name": "istanbul-lib-instrument",
324878          "version": "4.0.3",
324879          "licenses": [
324880            {
324881              "license": {
324882                "id": "BSD-3-Clause"
324883              }
324884            }
324885          ],
324886          "cpe": "cpe:2.3:a:istanbul-lib-instrument:istanbul-lib-instrument:4.0.3:*:*:*:*:*:*:*",
324887          "purl": "pkg:npm/istanbul-lib-instrument@4.0.3",
324888          "swid": {
324889            "attachment": {}
324890          },
324891          "pedigree": {},
324892          "evidence": {},
324893          "signature": {
324894            "signature": {
324895              "publicKey": {}
324896            }
324897          },
324898          "modelCard": {
324899            "modelParameters": {
324900              "approach": {}
324901            },
324902            "quantitativeAnalysis": {
324903              "graphics": {}
324904            },
324905            "considerations": {}
324906          }
324907        },
324908        {
324909          "type": "library",
324910          "bom-ref": "pkg:npm/istanbul-lib-processinfo@2.0.2?package-id=11627e0744ec4db8",
324911          "supplier": {},
324912          "name": "istanbul-lib-processinfo",
324913          "version": "2.0.2",
324914          "cpe": "cpe:2.3:a:istanbul-lib-processinfo:istanbul-lib-processinfo:2.0.2:*:*:*:*:*:*:*",
324915          "purl": "pkg:npm/istanbul-lib-processinfo@2.0.2",
324916          "swid": {
324917            "attachment": {}
324918          },
324919          "pedigree": {},
324920          "evidence": {},
324921          "signature": {
324922            "signature": {
324923              "publicKey": {}
324924            }
324925          },
324926          "modelCard": {
324927            "modelParameters": {
324928              "approach": {}
324929            },
324930            "quantitativeAnalysis": {
324931              "graphics": {}
324932            },
324933            "considerations": {}
324934          }
324935        },
324936        {
324937          "type": "library",
324938          "bom-ref": "pkg:npm/istanbul-lib-report@2.0.8?package-id=55cbe824d2d41d16",
324939          "supplier": {},
324940          "name": "istanbul-lib-report",
324941          "version": "2.0.8",
324942          "licenses": [
324943            {
324944              "license": {
324945                "id": "BSD-3-Clause"
324946              }
324947            }
324948          ],
324949          "cpe": "cpe:2.3:a:istanbul-lib-report:istanbul-lib-report:2.0.8:*:*:*:*:*:*:*",
324950          "purl": "pkg:npm/istanbul-lib-report@2.0.8",
324951          "swid": {
324952            "attachment": {}
324953          },
324954          "pedigree": {},
324955          "evidence": {},
324956          "signature": {
324957            "signature": {
324958              "publicKey": {}
324959            }
324960          },
324961          "modelCard": {
324962            "modelParameters": {
324963              "approach": {}
324964            },
324965            "quantitativeAnalysis": {
324966              "graphics": {}
324967            },
324968            "considerations": {}
324969          }
324970        },
324971        {
324972          "type": "library",
324973          "bom-ref": "pkg:npm/istanbul-lib-report@3.0.0?package-id=37695f9c0ad2a5ef",
324974          "supplier": {},
324975          "name": "istanbul-lib-report",
324976          "version": "3.0.0",
324977          "cpe": "cpe:2.3:a:istanbul-lib-report:istanbul-lib-report:3.0.0:*:*:*:*:*:*:*",
324978          "purl": "pkg:npm/istanbul-lib-report@3.0.0",
324979          "swid": {
324980            "attachment": {}
324981          },
324982          "pedigree": {},
324983          "evidence": {},
324984          "signature": {
324985            "signature": {
324986              "publicKey": {}
324987            }
324988          },
324989          "modelCard": {
324990            "modelParameters": {
324991              "approach": {}
324992            },
324993            "quantitativeAnalysis": {
324994              "graphics": {}
324995            },
324996            "considerations": {}
324997          }
324998        },
324999        {
325000          "type": "library",
325001          "bom-ref": "pkg:npm/istanbul-lib-source-maps@3.0.6?package-id=6aa7c0e8df334cba",
325002          "supplier": {},
325003          "name": "istanbul-lib-source-maps",
325004          "version": "3.0.6",
325005          "licenses": [
325006            {
325007              "license": {
325008                "id": "BSD-3-Clause"
325009              }
325010            }
325011          ],
325012          "cpe": "cpe:2.3:a:istanbul-lib-source-maps:istanbul-lib-source-maps:3.0.6:*:*:*:*:*:*:*",
325013          "purl": "pkg:npm/istanbul-lib-source-maps@3.0.6",
325014          "swid": {
325015            "attachment": {}
325016          },
325017          "pedigree": {},
325018          "evidence": {},
325019          "signature": {
325020            "signature": {
325021              "publicKey": {}
325022            }
325023          },
325024          "modelCard": {
325025            "modelParameters": {
325026              "approach": {}
325027            },
325028            "quantitativeAnalysis": {
325029              "graphics": {}
325030            },
325031            "considerations": {}
325032          }
325033        },
325034        {
325035          "type": "library",
325036          "bom-ref": "pkg:npm/istanbul-lib-source-maps@4.0.1?package-id=66e12c5dbe587c84",
325037          "supplier": {},
325038          "name": "istanbul-lib-source-maps",
325039          "version": "4.0.1",
325040          "cpe": "cpe:2.3:a:istanbul-lib-source-maps:istanbul-lib-source-maps:4.0.1:*:*:*:*:*:*:*",
325041          "purl": "pkg:npm/istanbul-lib-source-maps@4.0.1",
325042          "swid": {
325043            "attachment": {}
325044          },
325045          "pedigree": {},
325046          "evidence": {},
325047          "signature": {
325048            "signature": {
325049              "publicKey": {}
325050            }
325051          },
325052          "modelCard": {
325053            "modelParameters": {
325054              "approach": {}
325055            },
325056            "quantitativeAnalysis": {
325057              "graphics": {}
325058            },
325059            "considerations": {}
325060          }
325061        },
325062        {
325063          "type": "library",
325064          "bom-ref": "pkg:npm/istanbul-reports@2.2.7?package-id=2906b5296966651",
325065          "supplier": {},
325066          "name": "istanbul-reports",
325067          "version": "2.2.7",
325068          "licenses": [
325069            {
325070              "license": {
325071                "id": "BSD-3-Clause"
325072              }
325073            }
325074          ],
325075          "cpe": "cpe:2.3:a:istanbul-reports:istanbul-reports:2.2.7:*:*:*:*:*:*:*",
325076          "purl": "pkg:npm/istanbul-reports@2.2.7",
325077          "swid": {
325078            "attachment": {}
325079          },
325080          "pedigree": {},
325081          "evidence": {},
325082          "signature": {
325083            "signature": {
325084              "publicKey": {}
325085            }
325086          },
325087          "modelCard": {
325088            "modelParameters": {
325089              "approach": {}
325090            },
325091            "quantitativeAnalysis": {
325092              "graphics": {}
325093            },
325094            "considerations": {}
325095          }
325096        },
325097        {
325098          "type": "library",
325099          "bom-ref": "pkg:npm/istanbul-reports@3.1.1?package-id=1a5f71a74e360c81",
325100          "supplier": {},
325101          "name": "istanbul-reports",
325102          "version": "3.1.1",
325103          "cpe": "cpe:2.3:a:istanbul-reports:istanbul-reports:3.1.1:*:*:*:*:*:*:*",
325104          "purl": "pkg:npm/istanbul-reports@3.1.1",
325105          "swid": {
325106            "attachment": {}
325107          },
325108          "pedigree": {},
325109          "evidence": {},
325110          "signature": {
325111            "signature": {
325112              "publicKey": {}
325113            }
325114          },
325115          "modelCard": {
325116            "modelParameters": {
325117              "approach": {}
325118            },
325119            "quantitativeAnalysis": {
325120              "graphics": {}
325121            },
325122            "considerations": {}
325123          }
325124        },
325125        {
325126          "type": "library",
325127          "bom-ref": "pkg:npm/jasmine@2.8.0?package-id=b391cde6ad1e059c",
325128          "supplier": {},
325129          "name": "jasmine",
325130          "version": "2.8.0",
325131          "licenses": [
325132            {
325133              "license": {
325134                "id": "MIT"
325135              }
325136            }
325137          ],
325138          "cpe": "cpe:2.3:a:jasmine:jasmine:2.8.0:*:*:*:*:*:*:*",
325139          "purl": "pkg:npm/jasmine@2.8.0",
325140          "swid": {
325141            "attachment": {}
325142          },
325143          "pedigree": {},
325144          "evidence": {},
325145          "signature": {
325146            "signature": {
325147              "publicKey": {}
325148            }
325149          },
325150          "modelCard": {
325151            "modelParameters": {
325152              "approach": {}
325153            },
325154            "quantitativeAnalysis": {
325155              "graphics": {}
325156            },
325157            "considerations": {}
325158          }
325159        },
325160        {
325161          "type": "library",
325162          "bom-ref": "pkg:npm/jasmine@3.10.0?package-id=25c2a74931ecd303",
325163          "supplier": {},
325164          "name": "jasmine",
325165          "version": "3.10.0",
325166          "cpe": "cpe:2.3:a:jasmine:jasmine:3.10.0:*:*:*:*:*:*:*",
325167          "purl": "pkg:npm/jasmine@3.10.0",
325168          "swid": {
325169            "attachment": {}
325170          },
325171          "pedigree": {},
325172          "evidence": {},
325173          "signature": {
325174            "signature": {
325175              "publicKey": {}
325176            }
325177          },
325178          "modelCard": {
325179            "modelParameters": {
325180              "approach": {}
325181            },
325182            "quantitativeAnalysis": {
325183              "graphics": {}
325184            },
325185            "considerations": {}
325186          }
325187        },
325188        {
325189          "type": "library",
325190          "bom-ref": "pkg:pypi/jasmine-core@2.8.0?package-id=ff9145efd2fe77f6",
325191          "supplier": {},
325192          "author": "Pivotal Labs \u003cjasmine-js@googlegroups.com\u003e",
325193          "name": "jasmine-core",
325194          "version": "2.8.0",
325195          "licenses": [
325196            {
325197              "license": {
325198                "id": "MIT"
325199              }
325200            }
325201          ],
325202          "cpe": "cpe:2.3:a:pivotal_labs_project:python-jasmine-core:2.8.0:*:*:*:*:*:*:*",
325203          "purl": "pkg:pypi/jasmine-core@2.8.0",
325204          "swid": {
325205            "attachment": {}
325206          },
325207          "pedigree": {},
325208          "evidence": {},
325209          "signature": {
325210            "signature": {
325211              "publicKey": {}
325212            }
325213          },
325214          "modelCard": {
325215            "modelParameters": {
325216              "approach": {}
325217            },
325218            "quantitativeAnalysis": {
325219              "graphics": {}
325220            },
325221            "considerations": {}
325222          }
325223        },
325224        {
325225          "type": "library",
325226          "bom-ref": "pkg:npm/jasmine-core@3.10.1?package-id=35769132186911a9",
325227          "supplier": {},
325228          "name": "jasmine-core",
325229          "version": "3.10.1",
325230          "cpe": "cpe:2.3:a:jasmine-core:jasmine-core:3.10.1:*:*:*:*:*:*:*",
325231          "purl": "pkg:npm/jasmine-core@3.10.1",
325232          "swid": {
325233            "attachment": {}
325234          },
325235          "pedigree": {},
325236          "evidence": {},
325237          "signature": {
325238            "signature": {
325239              "publicKey": {}
325240            }
325241          },
325242          "modelCard": {
325243            "modelParameters": {
325244              "approach": {}
325245            },
325246            "quantitativeAnalysis": {
325247              "graphics": {}
325248            },
325249            "considerations": {}
325250          }
325251        },
325252        {
325253          "type": "library",
325254          "bom-ref": "pkg:pypi/jasmine-core@3.4.0?package-id=add2b0c5f5a7f430",
325255          "supplier": {},
325256          "author": "Pivotal Labs \u003cjasmine-js@googlegroups.com\u003e",
325257          "name": "jasmine-core",
325258          "version": "3.4.0",
325259          "licenses": [
325260            {
325261              "license": {
325262                "id": "MIT"
325263              }
325264            }
325265          ],
325266          "cpe": "cpe:2.3:a:pivotal_labs_project:python-jasmine-core:3.4.0:*:*:*:*:*:*:*",
325267          "purl": "pkg:pypi/jasmine-core@3.4.0",
325268          "swid": {
325269            "attachment": {}
325270          },
325271          "pedigree": {},
325272          "evidence": {},
325273          "signature": {
325274            "signature": {
325275              "publicKey": {}
325276            }
325277          },
325278          "modelCard": {
325279            "modelParameters": {
325280              "approach": {}
325281            },
325282            "quantitativeAnalysis": {
325283              "graphics": {}
325284            },
325285            "considerations": {}
325286          }
325287        },
325288        {
325289          "type": "library",
325290          "bom-ref": "pkg:npm/jasmine-core@3.5.0?package-id=2d97ad9cc207fc7c",
325291          "supplier": {},
325292          "name": "jasmine-core",
325293          "version": "3.5.0",
325294          "licenses": [
325295            {
325296              "license": {
325297                "id": "MIT"
325298              }
325299            }
325300          ],
325301          "cpe": "cpe:2.3:a:jasmine-core:jasmine-core:3.5.0:*:*:*:*:*:*:*",
325302          "purl": "pkg:npm/jasmine-core@3.5.0",
325303          "swid": {
325304            "attachment": {}
325305          },
325306          "pedigree": {},
325307          "evidence": {},
325308          "signature": {
325309            "signature": {
325310              "publicKey": {}
325311            }
325312          },
325313          "modelCard": {
325314            "modelParameters": {
325315              "approach": {}
325316            },
325317            "quantitativeAnalysis": {
325318              "graphics": {}
325319            },
325320            "considerations": {}
325321          }
325322        },
325323        {
325324          "type": "library",
325325          "bom-ref": "pkg:npm/jasmine-reporters@2.3.2?package-id=b5429c8dfc6991eb",
325326          "supplier": {},
325327          "name": "jasmine-reporters",
325328          "version": "2.3.2",
325329          "licenses": [
325330            {
325331              "license": {
325332                "id": "MIT"
325333              }
325334            }
325335          ],
325336          "cpe": "cpe:2.3:a:jasmine-reporters:jasmine-reporters:2.3.2:*:*:*:*:*:*:*",
325337          "purl": "pkg:npm/jasmine-reporters@2.3.2",
325338          "swid": {
325339            "attachment": {}
325340          },
325341          "pedigree": {},
325342          "evidence": {},
325343          "signature": {
325344            "signature": {
325345              "publicKey": {}
325346            }
325347          },
325348          "modelCard": {
325349            "modelParameters": {
325350              "approach": {}
325351            },
325352            "quantitativeAnalysis": {
325353              "graphics": {}
325354            },
325355            "considerations": {}
325356          }
325357        },
325358        {
325359          "type": "library",
325360          "bom-ref": "pkg:npm/jasmine-spec-reporter@4.2.1?package-id=5f15908a83562069",
325361          "supplier": {},
325362          "name": "jasmine-spec-reporter",
325363          "version": "4.2.1",
325364          "licenses": [
325365            {
325366              "license": {
325367                "id": "Apache-2.0"
325368              }
325369            }
325370          ],
325371          "cpe": "cpe:2.3:a:jasmine-spec-reporter:jasmine-spec-reporter:4.2.1:*:*:*:*:*:*:*",
325372          "purl": "pkg:npm/jasmine-spec-reporter@4.2.1",
325373          "swid": {
325374            "attachment": {}
325375          },
325376          "pedigree": {},
325377          "evidence": {},
325378          "signature": {
325379            "signature": {
325380              "publicKey": {}
325381            }
325382          },
325383          "modelCard": {
325384            "modelParameters": {
325385              "approach": {}
325386            },
325387            "quantitativeAnalysis": {
325388              "graphics": {}
325389            },
325390            "considerations": {}
325391          }
325392        },
325393        {
325394          "type": "library",
325395          "bom-ref": "pkg:npm/jasminewd2@2.2.0?package-id=4ba46c906cad0b60",
325396          "supplier": {},
325397          "name": "jasminewd2",
325398          "version": "2.2.0",
325399          "licenses": [
325400            {
325401              "license": {
325402                "id": "MIT"
325403              }
325404            }
325405          ],
325406          "cpe": "cpe:2.3:a:jasminewd2:jasminewd2:2.2.0:*:*:*:*:*:*:*",
325407          "purl": "pkg:npm/jasminewd2@2.2.0",
325408          "swid": {
325409            "attachment": {}
325410          },
325411          "pedigree": {},
325412          "evidence": {},
325413          "signature": {
325414            "signature": {
325415              "publicKey": {}
325416            }
325417          },
325418          "modelCard": {
325419            "modelParameters": {
325420              "approach": {}
325421            },
325422            "quantitativeAnalysis": {
325423              "graphics": {}
325424            },
325425            "considerations": {}
325426          }
325427        },
325428        {
325429          "type": "library",
325430          "bom-ref": "pkg:npm/jest-worker@25.1.0?package-id=3b2cd35086a54b20",
325431          "supplier": {},
325432          "name": "jest-worker",
325433          "version": "25.1.0",
325434          "licenses": [
325435            {
325436              "license": {
325437                "id": "MIT"
325438              }
325439            }
325440          ],
325441          "cpe": "cpe:2.3:a:jest-worker:jest-worker:25.1.0:*:*:*:*:*:*:*",
325442          "purl": "pkg:npm/jest-worker@25.1.0",
325443          "swid": {
325444            "attachment": {}
325445          },
325446          "pedigree": {},
325447          "evidence": {},
325448          "signature": {
325449            "signature": {
325450              "publicKey": {}
325451            }
325452          },
325453          "modelCard": {
325454            "modelParameters": {
325455              "approach": {}
325456            },
325457            "quantitativeAnalysis": {
325458              "graphics": {}
325459            },
325460            "considerations": {}
325461          }
325462        },
325463        {
325464          "type": "library",
325465          "bom-ref": "pkg:npm/js-base64@2.6.4?package-id=927724999fb6f7ce",
325466          "supplier": {},
325467          "name": "js-base64",
325468          "version": "2.6.4",
325469          "licenses": [
325470            {
325471              "license": {
325472                "id": "BSD-3-Clause"
325473              }
325474            }
325475          ],
325476          "cpe": "cpe:2.3:a:js-base64:js-base64:2.6.4:*:*:*:*:*:*:*",
325477          "purl": "pkg:npm/js-base64@2.6.4",
325478          "swid": {
325479            "attachment": {}
325480          },
325481          "pedigree": {},
325482          "evidence": {},
325483          "signature": {
325484            "signature": {
325485              "publicKey": {}
325486            }
325487          },
325488          "modelCard": {
325489            "modelParameters": {
325490              "approach": {}
325491            },
325492            "quantitativeAnalysis": {
325493              "graphics": {}
325494            },
325495            "considerations": {}
325496          }
325497        },
325498        {
325499          "type": "library",
325500          "bom-ref": "pkg:npm/js-tokens@4.0.0?package-id=8a34e1032629186",
325501          "supplier": {},
325502          "name": "js-tokens",
325503          "version": "4.0.0",
325504          "cpe": "cpe:2.3:a:js-tokens:js-tokens:4.0.0:*:*:*:*:*:*:*",
325505          "purl": "pkg:npm/js-tokens@4.0.0",
325506          "swid": {
325507            "attachment": {}
325508          },
325509          "pedigree": {},
325510          "evidence": {},
325511          "signature": {
325512            "signature": {
325513              "publicKey": {}
325514            }
325515          },
325516          "modelCard": {
325517            "modelParameters": {
325518              "approach": {}
325519            },
325520            "quantitativeAnalysis": {
325521              "graphics": {}
325522            },
325523            "considerations": {}
325524          }
325525        },
325526        {
325527          "type": "library",
325528          "bom-ref": "pkg:npm/js-tokens@4.0.0?package-id=a45a406ab9f66024",
325529          "supplier": {},
325530          "name": "js-tokens",
325531          "version": "4.0.0",
325532          "licenses": [
325533            {
325534              "license": {
325535                "id": "MIT"
325536              }
325537            }
325538          ],
325539          "cpe": "cpe:2.3:a:js-tokens:js-tokens:4.0.0:*:*:*:*:*:*:*",
325540          "purl": "pkg:npm/js-tokens@4.0.0",
325541          "swid": {
325542            "attachment": {}
325543          },
325544          "pedigree": {},
325545          "evidence": {},
325546          "signature": {
325547            "signature": {
325548              "publicKey": {}
325549            }
325550          },
325551          "modelCard": {
325552            "modelParameters": {
325553              "approach": {}
325554            },
325555            "quantitativeAnalysis": {
325556              "graphics": {}
325557            },
325558            "considerations": {}
325559          }
325560        },
325561        {
325562          "type": "library",
325563          "bom-ref": "pkg:npm/js-yaml@3.14.1?package-id=454e8e5807feb0a3",
325564          "supplier": {},
325565          "name": "js-yaml",
325566          "version": "3.14.1",
325567          "cpe": "cpe:2.3:a:js-yaml:js-yaml:3.14.1:*:*:*:*:*:*:*",
325568          "purl": "pkg:npm/js-yaml@3.14.1",
325569          "swid": {
325570            "attachment": {}
325571          },
325572          "pedigree": {},
325573          "evidence": {},
325574          "signature": {
325575            "signature": {
325576              "publicKey": {}
325577            }
325578          },
325579          "modelCard": {
325580            "modelParameters": {
325581              "approach": {}
325582            },
325583            "quantitativeAnalysis": {
325584              "graphics": {}
325585            },
325586            "considerations": {}
325587          }
325588        },
325589        {
325590          "type": "library",
325591          "bom-ref": "pkg:npm/js-yaml@4.1.0?package-id=4b57901fe7459101",
325592          "supplier": {},
325593          "name": "js-yaml",
325594          "version": "4.1.0",
325595          "licenses": [
325596            {
325597              "license": {
325598                "id": "MIT"
325599              }
325600            }
325601          ],
325602          "cpe": "cpe:2.3:a:js-yaml:js-yaml:4.1.0:*:*:*:*:*:*:*",
325603          "purl": "pkg:npm/js-yaml@4.1.0",
325604          "swid": {
325605            "attachment": {}
325606          },
325607          "pedigree": {},
325608          "evidence": {},
325609          "signature": {
325610            "signature": {
325611              "publicKey": {}
325612            }
325613          },
325614          "modelCard": {
325615            "modelParameters": {
325616              "approach": {}
325617            },
325618            "quantitativeAnalysis": {
325619              "graphics": {}
325620            },
325621            "considerations": {}
325622          }
325623        },
325624        {
325625          "type": "library",
325626          "bom-ref": "pkg:npm/jsbn@0.1.1?package-id=180bcccaba7b462f",
325627          "supplier": {},
325628          "name": "jsbn",
325629          "version": "0.1.1",
325630          "licenses": [
325631            {
325632              "license": {
325633                "id": "MIT"
325634              }
325635            }
325636          ],
325637          "cpe": "cpe:2.3:a:jsbn:jsbn:0.1.1:*:*:*:*:*:*:*",
325638          "purl": "pkg:npm/jsbn@0.1.1",
325639          "swid": {
325640            "attachment": {}
325641          },
325642          "pedigree": {},
325643          "evidence": {},
325644          "signature": {
325645            "signature": {
325646              "publicKey": {}
325647            }
325648          },
325649          "modelCard": {
325650            "modelParameters": {
325651              "approach": {}
325652            },
325653            "quantitativeAnalysis": {
325654              "graphics": {}
325655            },
325656            "considerations": {}
325657          }
325658        },
325659        {
325660          "type": "library",
325661          "bom-ref": "pkg:npm/jsesc@2.5.2?package-id=cb3180fc14c12ded",
325662          "supplier": {},
325663          "name": "jsesc",
325664          "version": "2.5.2",
325665          "cpe": "cpe:2.3:a:jsesc:jsesc:2.5.2:*:*:*:*:*:*:*",
325666          "purl": "pkg:npm/jsesc@2.5.2",
325667          "swid": {
325668            "attachment": {}
325669          },
325670          "pedigree": {},
325671          "evidence": {},
325672          "signature": {
325673            "signature": {
325674              "publicKey": {}
325675            }
325676          },
325677          "modelCard": {
325678            "modelParameters": {
325679              "approach": {}
325680            },
325681            "quantitativeAnalysis": {
325682              "graphics": {}
325683            },
325684            "considerations": {}
325685          }
325686        },
325687        {
325688          "type": "library",
325689          "bom-ref": "pkg:npm/jsesc@2.5.2?package-id=d1ecf8a72db4a15f",
325690          "supplier": {},
325691          "name": "jsesc",
325692          "version": "2.5.2",
325693          "licenses": [
325694            {
325695              "license": {
325696                "id": "MIT"
325697              }
325698            }
325699          ],
325700          "cpe": "cpe:2.3:a:jsesc:jsesc:2.5.2:*:*:*:*:*:*:*",
325701          "purl": "pkg:npm/jsesc@2.5.2",
325702          "swid": {
325703            "attachment": {}
325704          },
325705          "pedigree": {},
325706          "evidence": {},
325707          "signature": {
325708            "signature": {
325709              "publicKey": {}
325710            }
325711          },
325712          "modelCard": {
325713            "modelParameters": {
325714              "approach": {}
325715            },
325716            "quantitativeAnalysis": {
325717              "graphics": {}
325718            },
325719            "considerations": {}
325720          }
325721        },
325722        {
325723          "type": "library",
325724          "bom-ref": "pkg:npm/json-cycle@1.3.0?package-id=47076b86e448a8a4",
325725          "supplier": {},
325726          "name": "json-cycle",
325727          "version": "1.3.0",
325728          "licenses": [
325729            {
325730              "license": {
325731                "id": "MIT"
325732              }
325733            }
325734          ],
325735          "cpe": "cpe:2.3:a:json-cycle:json-cycle:1.3.0:*:*:*:*:*:*:*",
325736          "purl": "pkg:npm/json-cycle@1.3.0",
325737          "swid": {
325738            "attachment": {}
325739          },
325740          "pedigree": {},
325741          "evidence": {},
325742          "signature": {
325743            "signature": {
325744              "publicKey": {}
325745            }
325746          },
325747          "modelCard": {
325748            "modelParameters": {
325749              "approach": {}
325750            },
325751            "quantitativeAnalysis": {
325752              "graphics": {}
325753            },
325754            "considerations": {}
325755          }
325756        },
325757        {
325758          "type": "library",
325759          "bom-ref": "pkg:npm/json-parse-better-errors@1.0.2?package-id=75dc908c71be93a8",
325760          "supplier": {},
325761          "name": "json-parse-better-errors",
325762          "version": "1.0.2",
325763          "licenses": [
325764            {
325765              "license": {
325766                "id": "MIT"
325767              }
325768            }
325769          ],
325770          "cpe": "cpe:2.3:a:json-parse-better-errors:json-parse-better-errors:1.0.2:*:*:*:*:*:*:*",
325771          "purl": "pkg:npm/json-parse-better-errors@1.0.2",
325772          "swid": {
325773            "attachment": {}
325774          },
325775          "pedigree": {},
325776          "evidence": {},
325777          "signature": {
325778            "signature": {
325779              "publicKey": {}
325780            }
325781          },
325782          "modelCard": {
325783            "modelParameters": {
325784              "approach": {}
325785            },
325786            "quantitativeAnalysis": {
325787              "graphics": {}
325788            },
325789            "considerations": {}
325790          }
325791        },
325792        {
325793          "type": "library",
325794          "bom-ref": "pkg:npm/json-schema@0.2.3?package-id=e4cfa487fbbcfb8e",
325795          "supplier": {},
325796          "name": "json-schema",
325797          "version": "0.2.3",
325798          "licenses": [
325799            {
325800              "license": {
325801                "name": "AFLv2.1"
325802              }
325803            },
325804            {
325805              "license": {
325806                "name": "BSD"
325807              }
325808            }
325809          ],
325810          "cpe": "cpe:2.3:a:json-schema:json-schema:0.2.3:*:*:*:*:*:*:*",
325811          "purl": "pkg:npm/json-schema@0.2.3",
325812          "swid": {
325813            "attachment": {}
325814          },
325815          "pedigree": {},
325816          "evidence": {},
325817          "signature": {
325818            "signature": {
325819              "publicKey": {}
325820            }
325821          },
325822          "modelCard": {
325823            "modelParameters": {
325824              "approach": {}
325825            },
325826            "quantitativeAnalysis": {
325827              "graphics": {}
325828            },
325829            "considerations": {}
325830          }
325831        },
325832        {
325833          "type": "library",
325834          "bom-ref": "pkg:npm/json-schema-deref-sync@0.10.1?package-id=2b165e30354fe13d",
325835          "supplier": {},
325836          "name": "json-schema-deref-sync",
325837          "version": "0.10.1",
325838          "licenses": [
325839            {
325840              "license": {
325841                "id": "MIT"
325842              }
325843            }
325844          ],
325845          "cpe": "cpe:2.3:a:json-schema-deref-sync:json-schema-deref-sync:0.10.1:*:*:*:*:*:*:*",
325846          "purl": "pkg:npm/json-schema-deref-sync@0.10.1",
325847          "swid": {
325848            "attachment": {}
325849          },
325850          "pedigree": {},
325851          "evidence": {},
325852          "signature": {
325853            "signature": {
325854              "publicKey": {}
325855            }
325856          },
325857          "modelCard": {
325858            "modelParameters": {
325859              "approach": {}
325860            },
325861            "quantitativeAnalysis": {
325862              "graphics": {}
325863            },
325864            "considerations": {}
325865          }
325866        },
325867        {
325868          "type": "library",
325869          "bom-ref": "pkg:npm/json-schema-ref-parser@6.1.0?package-id=ce00f28d631428fb",
325870          "supplier": {},
325871          "name": "json-schema-ref-parser",
325872          "version": "6.1.0",
325873          "licenses": [
325874            {
325875              "license": {
325876                "id": "MIT"
325877              }
325878            }
325879          ],
325880          "cpe": "cpe:2.3:a:json-schema-ref-parser:json-schema-ref-parser:6.1.0:*:*:*:*:*:*:*",
325881          "purl": "pkg:npm/json-schema-ref-parser@6.1.0",
325882          "swid": {
325883            "attachment": {}
325884          },
325885          "pedigree": {},
325886          "evidence": {},
325887          "signature": {
325888            "signature": {
325889              "publicKey": {}
325890            }
325891          },
325892          "modelCard": {
325893            "modelParameters": {
325894              "approach": {}
325895            },
325896            "quantitativeAnalysis": {
325897              "graphics": {}
325898            },
325899            "considerations": {}
325900          }
325901        },
325902        {
325903          "type": "library",
325904          "bom-ref": "pkg:npm/json-schema-to-typescript@7.1.0?package-id=5635b07b4361e9f5",
325905          "supplier": {},
325906          "name": "json-schema-to-typescript",
325907          "version": "7.1.0",
325908          "licenses": [
325909            {
325910              "license": {
325911                "id": "MIT"
325912              }
325913            }
325914          ],
325915          "cpe": "cpe:2.3:a:json-schema-to-typescript:json-schema-to-typescript:7.1.0:*:*:*:*:*:*:*",
325916          "purl": "pkg:npm/json-schema-to-typescript@7.1.0",
325917          "swid": {
325918            "attachment": {}
325919          },
325920          "pedigree": {},
325921          "evidence": {},
325922          "signature": {
325923            "signature": {
325924              "publicKey": {}
325925            }
325926          },
325927          "modelCard": {
325928            "modelParameters": {
325929              "approach": {}
325930            },
325931            "quantitativeAnalysis": {
325932              "graphics": {}
325933            },
325934            "considerations": {}
325935          }
325936        },
325937        {
325938          "type": "library",
325939          "bom-ref": "pkg:npm/json-schema-traverse@0.4.1?package-id=cbb857d85748c1e4",
325940          "supplier": {},
325941          "name": "json-schema-traverse",
325942          "version": "0.4.1",
325943          "licenses": [
325944            {
325945              "license": {
325946                "id": "MIT"
325947              }
325948            }
325949          ],
325950          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:0.4.1:*:*:*:*:*:*:*",
325951          "purl": "pkg:npm/json-schema-traverse@0.4.1",
325952          "swid": {
325953            "attachment": {}
325954          },
325955          "pedigree": {},
325956          "evidence": {},
325957          "signature": {
325958            "signature": {
325959              "publicKey": {}
325960            }
325961          },
325962          "modelCard": {
325963            "modelParameters": {
325964              "approach": {}
325965            },
325966            "quantitativeAnalysis": {
325967              "graphics": {}
325968            },
325969            "considerations": {}
325970          }
325971        },
325972        {
325973          "type": "library",
325974          "bom-ref": "pkg:npm/json-stringify-safe@5.0.1?package-id=2609f143751fda00",
325975          "supplier": {},
325976          "name": "json-stringify-safe",
325977          "version": "5.0.1",
325978          "licenses": [
325979            {
325980              "license": {
325981                "id": "ISC"
325982              }
325983            }
325984          ],
325985          "cpe": "cpe:2.3:a:json-stringify-safe:json-stringify-safe:5.0.1:*:*:*:*:*:*:*",
325986          "purl": "pkg:npm/json-stringify-safe@5.0.1",
325987          "swid": {
325988            "attachment": {}
325989          },
325990          "pedigree": {},
325991          "evidence": {},
325992          "signature": {
325993            "signature": {
325994              "publicKey": {}
325995            }
325996          },
325997          "modelCard": {
325998            "modelParameters": {
325999              "approach": {}
326000            },
326001            "quantitativeAnalysis": {
326002              "graphics": {}
326003            },
326004            "considerations": {}
326005          }
326006        },
326007        {
326008          "type": "library",
326009          "bom-ref": "pkg:npm/json3@3.3.3?package-id=25d604a40fbe9dfd",
326010          "supplier": {},
326011          "name": "json3",
326012          "version": "3.3.3",
326013          "licenses": [
326014            {
326015              "license": {
326016                "id": "MIT"
326017              }
326018            }
326019          ],
326020          "cpe": "cpe:2.3:a:json3:json3:3.3.3:*:*:*:*:*:*:*",
326021          "purl": "pkg:npm/json3@3.3.3",
326022          "swid": {
326023            "attachment": {}
326024          },
326025          "pedigree": {},
326026          "evidence": {},
326027          "signature": {
326028            "signature": {
326029              "publicKey": {}
326030            }
326031          },
326032          "modelCard": {
326033            "modelParameters": {
326034              "approach": {}
326035            },
326036            "quantitativeAnalysis": {
326037              "graphics": {}
326038            },
326039            "considerations": {}
326040          }
326041        },
326042        {
326043          "type": "library",
326044          "bom-ref": "pkg:npm/json5@1.0.1?package-id=cd7530dc6fa406c3",
326045          "supplier": {},
326046          "name": "json5",
326047          "version": "1.0.1",
326048          "licenses": [
326049            {
326050              "license": {
326051                "id": "MIT"
326052              }
326053            }
326054          ],
326055          "cpe": "cpe:2.3:a:json5:json5:1.0.1:*:*:*:*:*:*:*",
326056          "purl": "pkg:npm/json5@1.0.1",
326057          "swid": {
326058            "attachment": {}
326059          },
326060          "pedigree": {},
326061          "evidence": {},
326062          "signature": {
326063            "signature": {
326064              "publicKey": {}
326065            }
326066          },
326067          "modelCard": {
326068            "modelParameters": {
326069              "approach": {}
326070            },
326071            "quantitativeAnalysis": {
326072              "graphics": {}
326073            },
326074            "considerations": {}
326075          }
326076        },
326077        {
326078          "type": "library",
326079          "bom-ref": "pkg:npm/json5@2.2.0?package-id=f25d6fe164d07e25",
326080          "supplier": {},
326081          "name": "json5",
326082          "version": "2.2.0",
326083          "cpe": "cpe:2.3:a:json5:json5:2.2.0:*:*:*:*:*:*:*",
326084          "purl": "pkg:npm/json5@2.2.0",
326085          "swid": {
326086            "attachment": {}
326087          },
326088          "pedigree": {},
326089          "evidence": {},
326090          "signature": {
326091            "signature": {
326092              "publicKey": {}
326093            }
326094          },
326095          "modelCard": {
326096            "modelParameters": {
326097              "approach": {}
326098            },
326099            "quantitativeAnalysis": {
326100              "graphics": {}
326101            },
326102            "considerations": {}
326103          }
326104        },
326105        {
326106          "type": "library",
326107          "bom-ref": "pkg:npm/jsonc-parser@3.2.0?package-id=e41da41ef5c1a79",
326108          "supplier": {},
326109          "name": "jsonc-parser",
326110          "version": "3.2.0",
326111          "licenses": [
326112            {
326113              "license": {
326114                "id": "MIT"
326115              }
326116            }
326117          ],
326118          "cpe": "cpe:2.3:a:jsonc-parser:jsonc-parser:3.2.0:*:*:*:*:*:*:*",
326119          "purl": "pkg:npm/jsonc-parser@3.2.0",
326120          "swid": {
326121            "attachment": {}
326122          },
326123          "pedigree": {},
326124          "evidence": {},
326125          "signature": {
326126            "signature": {
326127              "publicKey": {}
326128            }
326129          },
326130          "modelCard": {
326131            "modelParameters": {
326132              "approach": {}
326133            },
326134            "quantitativeAnalysis": {
326135              "graphics": {}
326136            },
326137            "considerations": {}
326138          }
326139        },
326140        {
326141          "type": "library",
326142          "bom-ref": "pkg:npm/jsonfile@4.0.0?package-id=2d13bd9d0a025121",
326143          "supplier": {},
326144          "name": "jsonfile",
326145          "version": "4.0.0",
326146          "cpe": "cpe:2.3:a:jsonfile:jsonfile:4.0.0:*:*:*:*:*:*:*",
326147          "purl": "pkg:npm/jsonfile@4.0.0",
326148          "swid": {
326149            "attachment": {}
326150          },
326151          "pedigree": {},
326152          "evidence": {},
326153          "signature": {
326154            "signature": {
326155              "publicKey": {}
326156            }
326157          },
326158          "modelCard": {
326159            "modelParameters": {
326160              "approach": {}
326161            },
326162            "quantitativeAnalysis": {
326163              "graphics": {}
326164            },
326165            "considerations": {}
326166          }
326167        },
326168        {
326169          "type": "library",
326170          "bom-ref": "pkg:npm/jsonfile@4.0.0?package-id=40d9e4d00b74202f",
326171          "supplier": {},
326172          "name": "jsonfile",
326173          "version": "4.0.0",
326174          "licenses": [
326175            {
326176              "license": {
326177                "id": "MIT"
326178              }
326179            }
326180          ],
326181          "cpe": "cpe:2.3:a:jsonfile:jsonfile:4.0.0:*:*:*:*:*:*:*",
326182          "purl": "pkg:npm/jsonfile@4.0.0",
326183          "swid": {
326184            "attachment": {}
326185          },
326186          "pedigree": {},
326187          "evidence": {},
326188          "signature": {
326189            "signature": {
326190              "publicKey": {}
326191            }
326192          },
326193          "modelCard": {
326194            "modelParameters": {
326195              "approach": {}
326196            },
326197            "quantitativeAnalysis": {
326198              "graphics": {}
326199            },
326200            "considerations": {}
326201          }
326202        },
326203        {
326204          "type": "library",
326205          "bom-ref": "pkg:npm/jsonparse@1.3.1?package-id=fd6c63440aefcc7d",
326206          "supplier": {},
326207          "name": "jsonparse",
326208          "version": "1.3.1",
326209          "licenses": [
326210            {
326211              "license": {
326212                "id": "MIT"
326213              }
326214            }
326215          ],
326216          "cpe": "cpe:2.3:a:jsonparse:jsonparse:1.3.1:*:*:*:*:*:*:*",
326217          "purl": "pkg:npm/jsonparse@1.3.1",
326218          "swid": {
326219            "attachment": {}
326220          },
326221          "pedigree": {},
326222          "evidence": {},
326223          "signature": {
326224            "signature": {
326225              "publicKey": {}
326226            }
326227          },
326228          "modelCard": {
326229            "modelParameters": {
326230              "approach": {}
326231            },
326232            "quantitativeAnalysis": {
326233              "graphics": {}
326234            },
326235            "considerations": {}
326236          }
326237        },
326238        {
326239          "type": "library",
326240          "bom-ref": "pkg:npm/jsonschema@1.4.1?package-id=2802f0bacf4414a2",
326241          "supplier": {},
326242          "name": "jsonschema",
326243          "version": "1.4.1",
326244          "licenses": [
326245            {
326246              "license": {
326247                "id": "MIT"
326248              }
326249            }
326250          ],
326251          "cpe": "cpe:2.3:a:jsonschema:jsonschema:1.4.1:*:*:*:*:*:*:*",
326252          "purl": "pkg:npm/jsonschema@1.4.1",
326253          "swid": {
326254            "attachment": {}
326255          },
326256          "pedigree": {},
326257          "evidence": {},
326258          "signature": {
326259            "signature": {
326260              "publicKey": {}
326261            }
326262          },
326263          "modelCard": {
326264            "modelParameters": {
326265              "approach": {}
326266            },
326267            "quantitativeAnalysis": {
326268              "graphics": {}
326269            },
326270            "considerations": {}
326271          }
326272        },
326273        {
326274          "type": "library",
326275          "bom-ref": "pkg:npm/jsprim@1.4.1?package-id=196b972bd5fc97eb",
326276          "supplier": {},
326277          "name": "jsprim",
326278          "version": "1.4.1",
326279          "licenses": [
326280            {
326281              "license": {
326282                "id": "MIT"
326283              }
326284            }
326285          ],
326286          "cpe": "cpe:2.3:a:jsprim:jsprim:1.4.1:*:*:*:*:*:*:*",
326287          "purl": "pkg:npm/jsprim@1.4.1",
326288          "swid": {
326289            "attachment": {}
326290          },
326291          "pedigree": {},
326292          "evidence": {},
326293          "signature": {
326294            "signature": {
326295              "publicKey": {}
326296            }
326297          },
326298          "modelCard": {
326299            "modelParameters": {
326300              "approach": {}
326301            },
326302            "quantitativeAnalysis": {
326303              "graphics": {}
326304            },
326305            "considerations": {}
326306          }
326307        },
326308        {
326309          "type": "library",
326310          "bom-ref": "pkg:npm/jszip@3.2.2?package-id=8175927f908c011b",
326311          "supplier": {},
326312          "name": "jszip",
326313          "version": "3.2.2",
326314          "licenses": [
326315            {
326316              "license": {
326317                "name": "(MIT OR GPL-3.0)"
326318              }
326319            }
326320          ],
326321          "cpe": "cpe:2.3:a:jszip:jszip:3.2.2:*:*:*:*:*:*:*",
326322          "purl": "pkg:npm/jszip@3.2.2",
326323          "swid": {
326324            "attachment": {}
326325          },
326326          "pedigree": {},
326327          "evidence": {},
326328          "signature": {
326329            "signature": {
326330              "publicKey": {}
326331            }
326332          },
326333          "modelCard": {
326334            "modelParameters": {
326335              "approach": {}
326336            },
326337            "quantitativeAnalysis": {
326338              "graphics": {}
326339            },
326340            "considerations": {}
326341          }
326342        },
326343        {
326344          "type": "library",
326345          "bom-ref": "pkg:npm/karma@5.0.1?package-id=309c45d3b04c27f1",
326346          "supplier": {},
326347          "name": "karma",
326348          "version": "5.0.1",
326349          "licenses": [
326350            {
326351              "license": {
326352                "id": "MIT"
326353              }
326354            }
326355          ],
326356          "cpe": "cpe:2.3:a:karma:karma:5.0.1:*:*:*:*:*:*:*",
326357          "purl": "pkg:npm/karma@5.0.1",
326358          "swid": {
326359            "attachment": {}
326360          },
326361          "pedigree": {},
326362          "evidence": {},
326363          "signature": {
326364            "signature": {
326365              "publicKey": {}
326366            }
326367          },
326368          "modelCard": {
326369            "modelParameters": {
326370              "approach": {}
326371            },
326372            "quantitativeAnalysis": {
326373              "graphics": {}
326374            },
326375            "considerations": {}
326376          }
326377        },
326378        {
326379          "type": "library",
326380          "bom-ref": "pkg:npm/karma-chrome-launcher@3.1.0?package-id=d49d7fcfb45fe3",
326381          "supplier": {},
326382          "name": "karma-chrome-launcher",
326383          "version": "3.1.0",
326384          "licenses": [
326385            {
326386              "license": {
326387                "id": "MIT"
326388              }
326389            }
326390          ],
326391          "cpe": "cpe:2.3:a:karma-chrome-launcher:karma-chrome-launcher:3.1.0:*:*:*:*:*:*:*",
326392          "purl": "pkg:npm/karma-chrome-launcher@3.1.0",
326393          "swid": {
326394            "attachment": {}
326395          },
326396          "pedigree": {},
326397          "evidence": {},
326398          "signature": {
326399            "signature": {
326400              "publicKey": {}
326401            }
326402          },
326403          "modelCard": {
326404            "modelParameters": {
326405              "approach": {}
326406            },
326407            "quantitativeAnalysis": {
326408              "graphics": {}
326409            },
326410            "considerations": {}
326411          }
326412        },
326413        {
326414          "type": "library",
326415          "bom-ref": "pkg:npm/karma-coverage-istanbul-reporter@2.1.1?package-id=3af22972b63f621c",
326416          "supplier": {},
326417          "name": "karma-coverage-istanbul-reporter",
326418          "version": "2.1.1",
326419          "licenses": [
326420            {
326421              "license": {
326422                "id": "MIT"
326423              }
326424            }
326425          ],
326426          "cpe": "cpe:2.3:a:karma-coverage-istanbul-reporter:karma-coverage-istanbul-reporter:2.1.1:*:*:*:*:*:*:*",
326427          "purl": "pkg:npm/karma-coverage-istanbul-reporter@2.1.1",
326428          "swid": {
326429            "attachment": {}
326430          },
326431          "pedigree": {},
326432          "evidence": {},
326433          "signature": {
326434            "signature": {
326435              "publicKey": {}
326436            }
326437          },
326438          "modelCard": {
326439            "modelParameters": {
326440              "approach": {}
326441            },
326442            "quantitativeAnalysis": {
326443              "graphics": {}
326444            },
326445            "considerations": {}
326446          }
326447        },
326448        {
326449          "type": "library",
326450          "bom-ref": "pkg:npm/karma-jasmine@3.1.1?package-id=d422198d5fce7824",
326451          "supplier": {},
326452          "name": "karma-jasmine",
326453          "version": "3.1.1",
326454          "licenses": [
326455            {
326456              "license": {
326457                "id": "MIT"
326458              }
326459            }
326460          ],
326461          "cpe": "cpe:2.3:a:karma-jasmine:karma-jasmine:3.1.1:*:*:*:*:*:*:*",
326462          "purl": "pkg:npm/karma-jasmine@3.1.1",
326463          "swid": {
326464            "attachment": {}
326465          },
326466          "pedigree": {},
326467          "evidence": {},
326468          "signature": {
326469            "signature": {
326470              "publicKey": {}
326471            }
326472          },
326473          "modelCard": {
326474            "modelParameters": {
326475              "approach": {}
326476            },
326477            "quantitativeAnalysis": {
326478              "graphics": {}
326479            },
326480            "considerations": {}
326481          }
326482        },
326483        {
326484          "type": "library",
326485          "bom-ref": "pkg:npm/karma-jasmine-html-reporter@1.5.2?package-id=ac8d099d67f54085",
326486          "supplier": {},
326487          "name": "karma-jasmine-html-reporter",
326488          "version": "1.5.2",
326489          "licenses": [
326490            {
326491              "license": {
326492                "id": "MIT"
326493              }
326494            }
326495          ],
326496          "cpe": "cpe:2.3:a:karma-jasmine-html-reporter:karma-jasmine-html-reporter:1.5.2:*:*:*:*:*:*:*",
326497          "purl": "pkg:npm/karma-jasmine-html-reporter@1.5.2",
326498          "swid": {
326499            "attachment": {}
326500          },
326501          "pedigree": {},
326502          "evidence": {},
326503          "signature": {
326504            "signature": {
326505              "publicKey": {}
326506            }
326507          },
326508          "modelCard": {
326509            "modelParameters": {
326510              "approach": {}
326511            },
326512            "quantitativeAnalysis": {
326513              "graphics": {}
326514            },
326515            "considerations": {}
326516          }
326517        },
326518        {
326519          "type": "library",
326520          "bom-ref": "pkg:npm/karma-source-map-support@1.4.0?package-id=67f3cee4e9209f1e",
326521          "supplier": {},
326522          "name": "karma-source-map-support",
326523          "version": "1.4.0",
326524          "licenses": [
326525            {
326526              "license": {
326527                "id": "MIT"
326528              }
326529            }
326530          ],
326531          "cpe": "cpe:2.3:a:karma-source-map-support:karma-source-map-support:1.4.0:*:*:*:*:*:*:*",
326532          "purl": "pkg:npm/karma-source-map-support@1.4.0",
326533          "swid": {
326534            "attachment": {}
326535          },
326536          "pedigree": {},
326537          "evidence": {},
326538          "signature": {
326539            "signature": {
326540              "publicKey": {}
326541            }
326542          },
326543          "modelCard": {
326544            "modelParameters": {
326545              "approach": {}
326546            },
326547            "quantitativeAnalysis": {
326548              "graphics": {}
326549            },
326550            "considerations": {}
326551          }
326552        },
326553        {
326554          "type": "library",
326555          "bom-ref": "pkg:npm/killable@1.0.1?package-id=93ffdb96dd98bf41",
326556          "supplier": {},
326557          "name": "killable",
326558          "version": "1.0.1",
326559          "licenses": [
326560            {
326561              "license": {
326562                "id": "ISC"
326563              }
326564            }
326565          ],
326566          "cpe": "cpe:2.3:a:killable:killable:1.0.1:*:*:*:*:*:*:*",
326567          "purl": "pkg:npm/killable@1.0.1",
326568          "swid": {
326569            "attachment": {}
326570          },
326571          "pedigree": {},
326572          "evidence": {},
326573          "signature": {
326574            "signature": {
326575              "publicKey": {}
326576            }
326577          },
326578          "modelCard": {
326579            "modelParameters": {
326580              "approach": {}
326581            },
326582            "quantitativeAnalysis": {
326583              "graphics": {}
326584            },
326585            "considerations": {}
326586          }
326587        },
326588        {
326589          "type": "library",
326590          "bom-ref": "pkg:npm/kind-of@6.0.3?package-id=e8ab60871ec14903",
326591          "supplier": {},
326592          "name": "kind-of",
326593          "version": "6.0.3",
326594          "licenses": [
326595            {
326596              "license": {
326597                "id": "MIT"
326598              }
326599            }
326600          ],
326601          "cpe": "cpe:2.3:a:kind-of:kind-of:6.0.3:*:*:*:*:*:*:*",
326602          "purl": "pkg:npm/kind-of@6.0.3",
326603          "swid": {
326604            "attachment": {}
326605          },
326606          "pedigree": {},
326607          "evidence": {},
326608          "signature": {
326609            "signature": {
326610              "publicKey": {}
326611            }
326612          },
326613          "modelCard": {
326614            "modelParameters": {
326615              "approach": {}
326616            },
326617            "quantitativeAnalysis": {
326618              "graphics": {}
326619            },
326620            "considerations": {}
326621          }
326622        },
326623        {
326624          "type": "library",
326625          "bom-ref": "pkg:npm/klaw-sync@6.0.0?package-id=b09bc8cbe7e40ac1",
326626          "supplier": {},
326627          "name": "klaw-sync",
326628          "version": "6.0.0",
326629          "cpe": "cpe:2.3:a:klaw-sync:klaw-sync:6.0.0:*:*:*:*:*:*:*",
326630          "purl": "pkg:npm/klaw-sync@6.0.0",
326631          "swid": {
326632            "attachment": {}
326633          },
326634          "pedigree": {},
326635          "evidence": {},
326636          "signature": {
326637            "signature": {
326638              "publicKey": {}
326639            }
326640          },
326641          "modelCard": {
326642            "modelParameters": {
326643              "approach": {}
326644            },
326645            "quantitativeAnalysis": {
326646              "graphics": {}
326647            },
326648            "considerations": {}
326649          }
326650        },
326651        {
326652          "type": "library",
326653          "bom-ref": "pkg:npm/klaw-sync@6.0.0?package-id=843e1f7e755c6d7",
326654          "supplier": {},
326655          "name": "klaw-sync",
326656          "version": "6.0.0",
326657          "licenses": [
326658            {
326659              "license": {
326660                "id": "MIT"
326661              }
326662            }
326663          ],
326664          "cpe": "cpe:2.3:a:klaw-sync:klaw-sync:6.0.0:*:*:*:*:*:*:*",
326665          "purl": "pkg:npm/klaw-sync@6.0.0",
326666          "swid": {
326667            "attachment": {}
326668          },
326669          "pedigree": {},
326670          "evidence": {},
326671          "signature": {
326672            "signature": {
326673              "publicKey": {}
326674            }
326675          },
326676          "modelCard": {
326677            "modelParameters": {
326678              "approach": {}
326679            },
326680            "quantitativeAnalysis": {
326681              "graphics": {}
326682            },
326683            "considerations": {}
326684          }
326685        },
326686        {
326687          "type": "library",
326688          "bom-ref": "pkg:npm/lcid@2.0.0?package-id=efe8a3f66501df0f",
326689          "supplier": {},
326690          "name": "lcid",
326691          "version": "2.0.0",
326692          "licenses": [
326693            {
326694              "license": {
326695                "id": "MIT"
326696              }
326697            }
326698          ],
326699          "cpe": "cpe:2.3:a:lcid:lcid:2.0.0:*:*:*:*:*:*:*",
326700          "purl": "pkg:npm/lcid@2.0.0",
326701          "swid": {
326702            "attachment": {}
326703          },
326704          "pedigree": {},
326705          "evidence": {},
326706          "signature": {
326707            "signature": {
326708              "publicKey": {}
326709            }
326710          },
326711          "modelCard": {
326712            "modelParameters": {
326713              "approach": {}
326714            },
326715            "quantitativeAnalysis": {
326716              "graphics": {}
326717            },
326718            "considerations": {}
326719          }
326720        },
326721        {
326722          "type": "library",
326723          "bom-ref": "pkg:npm/less@3.11.1?package-id=356a20b387d05e12",
326724          "supplier": {},
326725          "name": "less",
326726          "version": "3.11.1",
326727          "licenses": [
326728            {
326729              "license": {
326730                "id": "Apache-2.0"
326731              }
326732            }
326733          ],
326734          "cpe": "cpe:2.3:a:less:less:3.11.1:*:*:*:*:*:*:*",
326735          "purl": "pkg:npm/less@3.11.1",
326736          "swid": {
326737            "attachment": {}
326738          },
326739          "pedigree": {},
326740          "evidence": {},
326741          "signature": {
326742            "signature": {
326743              "publicKey": {}
326744            }
326745          },
326746          "modelCard": {
326747            "modelParameters": {
326748              "approach": {}
326749            },
326750            "quantitativeAnalysis": {
326751              "graphics": {}
326752            },
326753            "considerations": {}
326754          }
326755        },
326756        {
326757          "type": "library",
326758          "bom-ref": "pkg:npm/less-loader@5.0.0?package-id=3e0c657447443b9e",
326759          "supplier": {},
326760          "name": "less-loader",
326761          "version": "5.0.0",
326762          "licenses": [
326763            {
326764              "license": {
326765                "id": "MIT"
326766              }
326767            }
326768          ],
326769          "cpe": "cpe:2.3:a:less-loader:less-loader:5.0.0:*:*:*:*:*:*:*",
326770          "purl": "pkg:npm/less-loader@5.0.0",
326771          "swid": {
326772            "attachment": {}
326773          },
326774          "pedigree": {},
326775          "evidence": {},
326776          "signature": {
326777            "signature": {
326778              "publicKey": {}
326779            }
326780          },
326781          "modelCard": {
326782            "modelParameters": {
326783              "approach": {}
326784            },
326785            "quantitativeAnalysis": {
326786              "graphics": {}
326787            },
326788            "considerations": {}
326789          }
326790        },
326791        {
326792          "type": "library",
326793          "bom-ref": "pkg:npm/leven@3.1.0?package-id=43c5be4dad2db792",
326794          "supplier": {},
326795          "name": "leven",
326796          "version": "3.1.0",
326797          "licenses": [
326798            {
326799              "license": {
326800                "id": "MIT"
326801              }
326802            }
326803          ],
326804          "cpe": "cpe:2.3:a:leven:leven:3.1.0:*:*:*:*:*:*:*",
326805          "purl": "pkg:npm/leven@3.1.0",
326806          "swid": {
326807            "attachment": {}
326808          },
326809          "pedigree": {},
326810          "evidence": {},
326811          "signature": {
326812            "signature": {
326813              "publicKey": {}
326814            }
326815          },
326816          "modelCard": {
326817            "modelParameters": {
326818              "approach": {}
326819            },
326820            "quantitativeAnalysis": {
326821              "graphics": {}
326822            },
326823            "considerations": {}
326824          }
326825        },
326826        {
326827          "type": "library",
326828          "bom-ref": "pkg:npm/levenary@1.1.1?package-id=149f4c147b272447",
326829          "supplier": {},
326830          "name": "levenary",
326831          "version": "1.1.1",
326832          "licenses": [
326833            {
326834              "license": {
326835                "id": "MIT"
326836              }
326837            }
326838          ],
326839          "cpe": "cpe:2.3:a:levenary:levenary:1.1.1:*:*:*:*:*:*:*",
326840          "purl": "pkg:npm/levenary@1.1.1",
326841          "swid": {
326842            "attachment": {}
326843          },
326844          "pedigree": {},
326845          "evidence": {},
326846          "signature": {
326847            "signature": {
326848              "publicKey": {}
326849            }
326850          },
326851          "modelCard": {
326852            "modelParameters": {
326853              "approach": {}
326854            },
326855            "quantitativeAnalysis": {
326856              "graphics": {}
326857            },
326858            "considerations": {}
326859          }
326860        },
326861        {
326862          "type": "library",
326863          "bom-ref": "pkg:npm/license-webpack-plugin@2.1.4?package-id=fb5508918414df22",
326864          "supplier": {},
326865          "name": "license-webpack-plugin",
326866          "version": "2.1.4",
326867          "licenses": [
326868            {
326869              "license": {
326870                "id": "ISC"
326871              }
326872            }
326873          ],
326874          "cpe": "cpe:2.3:a:license-webpack-plugin:license-webpack-plugin:2.1.4:*:*:*:*:*:*:*",
326875          "purl": "pkg:npm/license-webpack-plugin@2.1.4",
326876          "swid": {
326877            "attachment": {}
326878          },
326879          "pedigree": {},
326880          "evidence": {},
326881          "signature": {
326882            "signature": {
326883              "publicKey": {}
326884            }
326885          },
326886          "modelCard": {
326887            "modelParameters": {
326888              "approach": {}
326889            },
326890            "quantitativeAnalysis": {
326891              "graphics": {}
326892            },
326893            "considerations": {}
326894          }
326895        },
326896        {
326897          "type": "library",
326898          "bom-ref": "pkg:npm/lie@3.3.0?package-id=c5fcf15e35110845",
326899          "supplier": {},
326900          "name": "lie",
326901          "version": "3.3.0",
326902          "licenses": [
326903            {
326904              "license": {
326905                "id": "MIT"
326906              }
326907            }
326908          ],
326909          "cpe": "cpe:2.3:a:lie:lie:3.3.0:*:*:*:*:*:*:*",
326910          "purl": "pkg:npm/lie@3.3.0",
326911          "swid": {
326912            "attachment": {}
326913          },
326914          "pedigree": {},
326915          "evidence": {},
326916          "signature": {
326917            "signature": {
326918              "publicKey": {}
326919            }
326920          },
326921          "modelCard": {
326922            "modelParameters": {
326923              "approach": {}
326924            },
326925            "quantitativeAnalysis": {
326926              "graphics": {}
326927            },
326928            "considerations": {}
326929          }
326930        },
326931        {
326932          "type": "library",
326933          "bom-ref": "pkg:npm/load-json-file@1.1.0?package-id=5f582fbce7b08bb9",
326934          "supplier": {},
326935          "name": "load-json-file",
326936          "version": "1.1.0",
326937          "licenses": [
326938            {
326939              "license": {
326940                "id": "MIT"
326941              }
326942            }
326943          ],
326944          "cpe": "cpe:2.3:a:load-json-file:load-json-file:1.1.0:*:*:*:*:*:*:*",
326945          "purl": "pkg:npm/load-json-file@1.1.0",
326946          "swid": {
326947            "attachment": {}
326948          },
326949          "pedigree": {},
326950          "evidence": {},
326951          "signature": {
326952            "signature": {
326953              "publicKey": {}
326954            }
326955          },
326956          "modelCard": {
326957            "modelParameters": {
326958              "approach": {}
326959            },
326960            "quantitativeAnalysis": {
326961              "graphics": {}
326962            },
326963            "considerations": {}
326964          }
326965        },
326966        {
326967          "type": "library",
326968          "bom-ref": "pkg:npm/loader-runner@2.4.0?package-id=2bbdf9ddb27124ec",
326969          "supplier": {},
326970          "name": "loader-runner",
326971          "version": "2.4.0",
326972          "licenses": [
326973            {
326974              "license": {
326975                "id": "MIT"
326976              }
326977            }
326978          ],
326979          "cpe": "cpe:2.3:a:loader-runner:loader-runner:2.4.0:*:*:*:*:*:*:*",
326980          "purl": "pkg:npm/loader-runner@2.4.0",
326981          "swid": {
326982            "attachment": {}
326983          },
326984          "pedigree": {},
326985          "evidence": {},
326986          "signature": {
326987            "signature": {
326988              "publicKey": {}
326989            }
326990          },
326991          "modelCard": {
326992            "modelParameters": {
326993              "approach": {}
326994            },
326995            "quantitativeAnalysis": {
326996              "graphics": {}
326997            },
326998            "considerations": {}
326999          }
327000        },
327001        {
327002          "type": "library",
327003          "bom-ref": "pkg:npm/loader-utils@1.4.0?package-id=7e3c9dbecc9b6ad7",
327004          "supplier": {},
327005          "name": "loader-utils",
327006          "version": "1.4.0",
327007          "licenses": [
327008            {
327009              "license": {
327010                "id": "MIT"
327011              }
327012            }
327013          ],
327014          "cpe": "cpe:2.3:a:loader-utils:loader-utils:1.4.0:*:*:*:*:*:*:*",
327015          "purl": "pkg:npm/loader-utils@1.4.0",
327016          "swid": {
327017            "attachment": {}
327018          },
327019          "pedigree": {},
327020          "evidence": {},
327021          "signature": {
327022            "signature": {
327023              "publicKey": {}
327024            }
327025          },
327026          "modelCard": {
327027            "modelParameters": {
327028              "approach": {}
327029            },
327030            "quantitativeAnalysis": {
327031              "graphics": {}
327032            },
327033            "considerations": {}
327034          }
327035        },
327036        {
327037          "type": "library",
327038          "bom-ref": "pkg:npm/locate-path@3.0.0?package-id=2459735fd9c97d60",
327039          "supplier": {},
327040          "name": "locate-path",
327041          "version": "3.0.0",
327042          "licenses": [
327043            {
327044              "license": {
327045                "id": "MIT"
327046              }
327047            }
327048          ],
327049          "cpe": "cpe:2.3:a:locate-path:locate-path:3.0.0:*:*:*:*:*:*:*",
327050          "purl": "pkg:npm/locate-path@3.0.0",
327051          "swid": {
327052            "attachment": {}
327053          },
327054          "pedigree": {},
327055          "evidence": {},
327056          "signature": {
327057            "signature": {
327058              "publicKey": {}
327059            }
327060          },
327061          "modelCard": {
327062            "modelParameters": {
327063              "approach": {}
327064            },
327065            "quantitativeAnalysis": {
327066              "graphics": {}
327067            },
327068            "considerations": {}
327069          }
327070        },
327071        {
327072          "type": "library",
327073          "bom-ref": "pkg:npm/locate-path@5.0.0?package-id=957582ccf8a83d8c",
327074          "supplier": {},
327075          "name": "locate-path",
327076          "version": "5.0.0",
327077          "cpe": "cpe:2.3:a:locate-path:locate-path:5.0.0:*:*:*:*:*:*:*",
327078          "purl": "pkg:npm/locate-path@5.0.0",
327079          "swid": {
327080            "attachment": {}
327081          },
327082          "pedigree": {},
327083          "evidence": {},
327084          "signature": {
327085            "signature": {
327086              "publicKey": {}
327087            }
327088          },
327089          "modelCard": {
327090            "modelParameters": {
327091              "approach": {}
327092            },
327093            "quantitativeAnalysis": {
327094              "graphics": {}
327095            },
327096            "considerations": {}
327097          }
327098        },
327099        {
327100          "type": "library",
327101          "bom-ref": "pkg:npm/lodash@4.17.15?package-id=8fc70fcf143cc0f1",
327102          "supplier": {},
327103          "name": "lodash",
327104          "version": "4.17.15",
327105          "licenses": [
327106            {
327107              "license": {
327108                "id": "MIT"
327109              }
327110            }
327111          ],
327112          "cpe": "cpe:2.3:a:lodash:lodash:4.17.15:*:*:*:*:*:*:*",
327113          "purl": "pkg:npm/lodash@4.17.15",
327114          "swid": {
327115            "attachment": {}
327116          },
327117          "pedigree": {},
327118          "evidence": {},
327119          "signature": {
327120            "signature": {
327121              "publicKey": {}
327122            }
327123          },
327124          "modelCard": {
327125            "modelParameters": {
327126              "approach": {}
327127            },
327128            "quantitativeAnalysis": {
327129              "graphics": {}
327130            },
327131            "considerations": {}
327132          }
327133        },
327134        {
327135          "type": "library",
327136          "bom-ref": "pkg:npm/lodash.clonedeep@4.5.0?package-id=febc1ffcde2ededb",
327137          "supplier": {},
327138          "name": "lodash.clonedeep",
327139          "version": "4.5.0",
327140          "licenses": [
327141            {
327142              "license": {
327143                "id": "MIT"
327144              }
327145            }
327146          ],
327147          "cpe": "cpe:2.3:a:lodash.clonedeep:lodash.clonedeep:4.5.0:*:*:*:*:*:*:*",
327148          "purl": "pkg:npm/lodash.clonedeep@4.5.0",
327149          "swid": {
327150            "attachment": {}
327151          },
327152          "pedigree": {},
327153          "evidence": {},
327154          "signature": {
327155            "signature": {
327156              "publicKey": {}
327157            }
327158          },
327159          "modelCard": {
327160            "modelParameters": {
327161              "approach": {}
327162            },
327163            "quantitativeAnalysis": {
327164              "graphics": {}
327165            },
327166            "considerations": {}
327167          }
327168        },
327169        {
327170          "type": "library",
327171          "bom-ref": "pkg:npm/lodash.debounce@4.0.8?package-id=a24e0ef4641e05de",
327172          "supplier": {},
327173          "name": "lodash.debounce",
327174          "version": "4.0.8",
327175          "licenses": [
327176            {
327177              "license": {
327178                "id": "MIT"
327179              }
327180            }
327181          ],
327182          "cpe": "cpe:2.3:a:lodash.debounce:lodash.debounce:4.0.8:*:*:*:*:*:*:*",
327183          "purl": "pkg:npm/lodash.debounce@4.0.8",
327184          "swid": {
327185            "attachment": {}
327186          },
327187          "pedigree": {},
327188          "evidence": {},
327189          "signature": {
327190            "signature": {
327191              "publicKey": {}
327192            }
327193          },
327194          "modelCard": {
327195            "modelParameters": {
327196              "approach": {}
327197            },
327198            "quantitativeAnalysis": {
327199              "graphics": {}
327200            },
327201            "considerations": {}
327202          }
327203        },
327204        {
327205          "type": "library",
327206          "bom-ref": "pkg:npm/lodash.flattendeep@4.4.0?package-id=6cbf628c8b1ea6de",
327207          "supplier": {},
327208          "name": "lodash.flattendeep",
327209          "version": "4.4.0",
327210          "cpe": "cpe:2.3:a:lodash.flattendeep:lodash.flattendeep:4.4.0:*:*:*:*:*:*:*",
327211          "purl": "pkg:npm/lodash.flattendeep@4.4.0",
327212          "swid": {
327213            "attachment": {}
327214          },
327215          "pedigree": {},
327216          "evidence": {},
327217          "signature": {
327218            "signature": {
327219              "publicKey": {}
327220            }
327221          },
327222          "modelCard": {
327223            "modelParameters": {
327224              "approach": {}
327225            },
327226            "quantitativeAnalysis": {
327227              "graphics": {}
327228            },
327229            "considerations": {}
327230          }
327231        },
327232        {
327233          "type": "library",
327234          "bom-ref": "pkg:npm/lodash.memoize@4.1.2?package-id=94979cb4ceba5f94",
327235          "supplier": {},
327236          "name": "lodash.memoize",
327237          "version": "4.1.2",
327238          "licenses": [
327239            {
327240              "license": {
327241                "id": "MIT"
327242              }
327243            }
327244          ],
327245          "cpe": "cpe:2.3:a:lodash.memoize:lodash.memoize:4.1.2:*:*:*:*:*:*:*",
327246          "purl": "pkg:npm/lodash.memoize@4.1.2",
327247          "swid": {
327248            "attachment": {}
327249          },
327250          "pedigree": {},
327251          "evidence": {},
327252          "signature": {
327253            "signature": {
327254              "publicKey": {}
327255            }
327256          },
327257          "modelCard": {
327258            "modelParameters": {
327259              "approach": {}
327260            },
327261            "quantitativeAnalysis": {
327262              "graphics": {}
327263            },
327264            "considerations": {}
327265          }
327266        },
327267        {
327268          "type": "library",
327269          "bom-ref": "pkg:npm/lodash.throttle@4.1.1?package-id=5e78db1c97e493ba",
327270          "supplier": {},
327271          "name": "lodash.throttle",
327272          "version": "4.1.1",
327273          "licenses": [
327274            {
327275              "license": {
327276                "id": "MIT"
327277              }
327278            }
327279          ],
327280          "cpe": "cpe:2.3:a:lodash.throttle:lodash.throttle:4.1.1:*:*:*:*:*:*:*",
327281          "purl": "pkg:npm/lodash.throttle@4.1.1",
327282          "swid": {
327283            "attachment": {}
327284          },
327285          "pedigree": {},
327286          "evidence": {},
327287          "signature": {
327288            "signature": {
327289              "publicKey": {}
327290            }
327291          },
327292          "modelCard": {
327293            "modelParameters": {
327294              "approach": {}
327295            },
327296            "quantitativeAnalysis": {
327297              "graphics": {}
327298            },
327299            "considerations": {}
327300          }
327301        },
327302        {
327303          "type": "library",
327304          "bom-ref": "pkg:npm/lodash.uniq@4.5.0?package-id=b5770eedfc257e9b",
327305          "supplier": {},
327306          "name": "lodash.uniq",
327307          "version": "4.5.0",
327308          "licenses": [
327309            {
327310              "license": {
327311                "id": "MIT"
327312              }
327313            }
327314          ],
327315          "cpe": "cpe:2.3:a:lodash.uniq:lodash.uniq:4.5.0:*:*:*:*:*:*:*",
327316          "purl": "pkg:npm/lodash.uniq@4.5.0",
327317          "swid": {
327318            "attachment": {}
327319          },
327320          "pedigree": {},
327321          "evidence": {},
327322          "signature": {
327323            "signature": {
327324              "publicKey": {}
327325            }
327326          },
327327          "modelCard": {
327328            "modelParameters": {
327329              "approach": {}
327330            },
327331            "quantitativeAnalysis": {
327332              "graphics": {}
327333            },
327334            "considerations": {}
327335          }
327336        },
327337        {
327338          "type": "library",
327339          "bom-ref": "pkg:npm/log-symbols@3.0.0?package-id=edefb05eab9e2feb",
327340          "supplier": {},
327341          "name": "log-symbols",
327342          "version": "3.0.0",
327343          "licenses": [
327344            {
327345              "license": {
327346                "id": "MIT"
327347              }
327348            }
327349          ],
327350          "cpe": "cpe:2.3:a:log-symbols:log-symbols:3.0.0:*:*:*:*:*:*:*",
327351          "purl": "pkg:npm/log-symbols@3.0.0",
327352          "swid": {
327353            "attachment": {}
327354          },
327355          "pedigree": {},
327356          "evidence": {},
327357          "signature": {
327358            "signature": {
327359              "publicKey": {}
327360            }
327361          },
327362          "modelCard": {
327363            "modelParameters": {
327364              "approach": {}
327365            },
327366            "quantitativeAnalysis": {
327367              "graphics": {}
327368            },
327369            "considerations": {}
327370          }
327371        },
327372        {
327373          "type": "library",
327374          "bom-ref": "pkg:npm/log4js@4.5.1?package-id=7147a3cd22bf6c45",
327375          "supplier": {},
327376          "name": "log4js",
327377          "version": "4.5.1",
327378          "licenses": [
327379            {
327380              "license": {
327381                "id": "Apache-2.0"
327382              }
327383            }
327384          ],
327385          "cpe": "cpe:2.3:a:log4js:log4js:4.5.1:*:*:*:*:*:*:*",
327386          "purl": "pkg:npm/log4js@4.5.1",
327387          "swid": {
327388            "attachment": {}
327389          },
327390          "pedigree": {},
327391          "evidence": {},
327392          "signature": {
327393            "signature": {
327394              "publicKey": {}
327395            }
327396          },
327397          "modelCard": {
327398            "modelParameters": {
327399              "approach": {}
327400            },
327401            "quantitativeAnalysis": {
327402              "graphics": {}
327403            },
327404            "considerations": {}
327405          }
327406        },
327407        {
327408          "type": "library",
327409          "bom-ref": "pkg:npm/loglevel@1.6.8?package-id=80ce6842e3489425",
327410          "supplier": {},
327411          "name": "loglevel",
327412          "version": "1.6.8",
327413          "licenses": [
327414            {
327415              "license": {
327416                "id": "MIT"
327417              }
327418            }
327419          ],
327420          "cpe": "cpe:2.3:a:loglevel:loglevel:1.6.8:*:*:*:*:*:*:*",
327421          "purl": "pkg:npm/loglevel@1.6.8",
327422          "swid": {
327423            "attachment": {}
327424          },
327425          "pedigree": {},
327426          "evidence": {},
327427          "signature": {
327428            "signature": {
327429              "publicKey": {}
327430            }
327431          },
327432          "modelCard": {
327433            "modelParameters": {
327434              "approach": {}
327435            },
327436            "quantitativeAnalysis": {
327437              "graphics": {}
327438            },
327439            "considerations": {}
327440          }
327441        },
327442        {
327443          "type": "library",
327444          "bom-ref": "pkg:npm/loose-envify@1.4.0?package-id=5cbfaf24327ae16f",
327445          "supplier": {},
327446          "name": "loose-envify",
327447          "version": "1.4.0",
327448          "licenses": [
327449            {
327450              "license": {
327451                "id": "MIT"
327452              }
327453            }
327454          ],
327455          "cpe": "cpe:2.3:a:loose-envify:loose-envify:1.4.0:*:*:*:*:*:*:*",
327456          "purl": "pkg:npm/loose-envify@1.4.0",
327457          "swid": {
327458            "attachment": {}
327459          },
327460          "pedigree": {},
327461          "evidence": {},
327462          "signature": {
327463            "signature": {
327464              "publicKey": {}
327465            }
327466          },
327467          "modelCard": {
327468            "modelParameters": {
327469              "approach": {}
327470            },
327471            "quantitativeAnalysis": {
327472              "graphics": {}
327473            },
327474            "considerations": {}
327475          }
327476        },
327477        {
327478          "type": "library",
327479          "bom-ref": "pkg:npm/loud-rejection@1.6.0?package-id=bd8ed016e8f7a88c",
327480          "supplier": {},
327481          "name": "loud-rejection",
327482          "version": "1.6.0",
327483          "licenses": [
327484            {
327485              "license": {
327486                "id": "MIT"
327487              }
327488            }
327489          ],
327490          "cpe": "cpe:2.3:a:loud-rejection:loud-rejection:1.6.0:*:*:*:*:*:*:*",
327491          "purl": "pkg:npm/loud-rejection@1.6.0",
327492          "swid": {
327493            "attachment": {}
327494          },
327495          "pedigree": {},
327496          "evidence": {},
327497          "signature": {
327498            "signature": {
327499              "publicKey": {}
327500            }
327501          },
327502          "modelCard": {
327503            "modelParameters": {
327504              "approach": {}
327505            },
327506            "quantitativeAnalysis": {
327507              "graphics": {}
327508            },
327509            "considerations": {}
327510          }
327511        },
327512        {
327513          "type": "library",
327514          "bom-ref": "pkg:npm/lru-cache@5.1.1?package-id=efb4f97816cd3dea",
327515          "supplier": {},
327516          "name": "lru-cache",
327517          "version": "5.1.1",
327518          "licenses": [
327519            {
327520              "license": {
327521                "id": "ISC"
327522              }
327523            }
327524          ],
327525          "cpe": "cpe:2.3:a:lru-cache:lru-cache:5.1.1:*:*:*:*:*:*:*",
327526          "purl": "pkg:npm/lru-cache@5.1.1",
327527          "swid": {
327528            "attachment": {}
327529          },
327530          "pedigree": {},
327531          "evidence": {},
327532          "signature": {
327533            "signature": {
327534              "publicKey": {}
327535            }
327536          },
327537          "modelCard": {
327538            "modelParameters": {
327539              "approach": {}
327540            },
327541            "quantitativeAnalysis": {
327542              "graphics": {}
327543            },
327544            "considerations": {}
327545          }
327546        },
327547        {
327548          "type": "library",
327549          "bom-ref": "pkg:npm/lru-queue@0.1.0?package-id=623769448f36df86",
327550          "supplier": {},
327551          "name": "lru-queue",
327552          "version": "0.1.0",
327553          "licenses": [
327554            {
327555              "license": {
327556                "id": "MIT"
327557              }
327558            }
327559          ],
327560          "cpe": "cpe:2.3:a:lru-queue:lru-queue:0.1.0:*:*:*:*:*:*:*",
327561          "purl": "pkg:npm/lru-queue@0.1.0",
327562          "swid": {
327563            "attachment": {}
327564          },
327565          "pedigree": {},
327566          "evidence": {},
327567          "signature": {
327568            "signature": {
327569              "publicKey": {}
327570            }
327571          },
327572          "modelCard": {
327573            "modelParameters": {
327574              "approach": {}
327575            },
327576            "quantitativeAnalysis": {
327577              "graphics": {}
327578            },
327579            "considerations": {}
327580          }
327581        },
327582        {
327583          "type": "library",
327584          "bom-ref": "pkg:npm/magic-string@0.25.7?package-id=9250e37883e0b636",
327585          "supplier": {},
327586          "name": "magic-string",
327587          "version": "0.25.7",
327588          "licenses": [
327589            {
327590              "license": {
327591                "id": "MIT"
327592              }
327593            }
327594          ],
327595          "cpe": "cpe:2.3:a:magic-string:magic-string:0.25.7:*:*:*:*:*:*:*",
327596          "purl": "pkg:npm/magic-string@0.25.7",
327597          "swid": {
327598            "attachment": {}
327599          },
327600          "pedigree": {},
327601          "evidence": {},
327602          "signature": {
327603            "signature": {
327604              "publicKey": {}
327605            }
327606          },
327607          "modelCard": {
327608            "modelParameters": {
327609              "approach": {}
327610            },
327611            "quantitativeAnalysis": {
327612              "graphics": {}
327613            },
327614            "considerations": {}
327615          }
327616        },
327617        {
327618          "type": "library",
327619          "bom-ref": "pkg:npm/make-dir@2.1.0?package-id=f522a1a71d75593f",
327620          "supplier": {},
327621          "name": "make-dir",
327622          "version": "2.1.0",
327623          "licenses": [
327624            {
327625              "license": {
327626                "id": "MIT"
327627              }
327628            }
327629          ],
327630          "cpe": "cpe:2.3:a:make-dir:make-dir:2.1.0:*:*:*:*:*:*:*",
327631          "purl": "pkg:npm/make-dir@2.1.0",
327632          "swid": {
327633            "attachment": {}
327634          },
327635          "pedigree": {},
327636          "evidence": {},
327637          "signature": {
327638            "signature": {
327639              "publicKey": {}
327640            }
327641          },
327642          "modelCard": {
327643            "modelParameters": {
327644              "approach": {}
327645            },
327646            "quantitativeAnalysis": {
327647              "graphics": {}
327648            },
327649            "considerations": {}
327650          }
327651        },
327652        {
327653          "type": "library",
327654          "bom-ref": "pkg:npm/make-dir@3.1.0?package-id=120153f25eeb68e7",
327655          "supplier": {},
327656          "name": "make-dir",
327657          "version": "3.1.0",
327658          "cpe": "cpe:2.3:a:make-dir:make-dir:3.1.0:*:*:*:*:*:*:*",
327659          "purl": "pkg:npm/make-dir@3.1.0",
327660          "swid": {
327661            "attachment": {}
327662          },
327663          "pedigree": {},
327664          "evidence": {},
327665          "signature": {
327666            "signature": {
327667              "publicKey": {}
327668            }
327669          },
327670          "modelCard": {
327671            "modelParameters": {
327672              "approach": {}
327673            },
327674            "quantitativeAnalysis": {
327675              "graphics": {}
327676            },
327677            "considerations": {}
327678          }
327679        },
327680        {
327681          "type": "library",
327682          "bom-ref": "pkg:npm/make-error@1.3.6?package-id=f941e8f95ca1e399",
327683          "supplier": {},
327684          "name": "make-error",
327685          "version": "1.3.6",
327686          "licenses": [
327687            {
327688              "license": {
327689                "id": "ISC"
327690              }
327691            }
327692          ],
327693          "cpe": "cpe:2.3:a:make-error:make-error:1.3.6:*:*:*:*:*:*:*",
327694          "purl": "pkg:npm/make-error@1.3.6",
327695          "swid": {
327696            "attachment": {}
327697          },
327698          "pedigree": {},
327699          "evidence": {},
327700          "signature": {
327701            "signature": {
327702              "publicKey": {}
327703            }
327704          },
327705          "modelCard": {
327706            "modelParameters": {
327707              "approach": {}
327708            },
327709            "quantitativeAnalysis": {
327710              "graphics": {}
327711            },
327712            "considerations": {}
327713          }
327714        },
327715        {
327716          "type": "library",
327717          "bom-ref": "pkg:npm/make-fetch-happen@5.0.2?package-id=58ecdc589af92947",
327718          "supplier": {},
327719          "name": "make-fetch-happen",
327720          "version": "5.0.2",
327721          "licenses": [
327722            {
327723              "license": {
327724                "id": "ISC"
327725              }
327726            }
327727          ],
327728          "cpe": "cpe:2.3:a:make-fetch-happen:make-fetch-happen:5.0.2:*:*:*:*:*:*:*",
327729          "purl": "pkg:npm/make-fetch-happen@5.0.2",
327730          "swid": {
327731            "attachment": {}
327732          },
327733          "pedigree": {},
327734          "evidence": {},
327735          "signature": {
327736            "signature": {
327737              "publicKey": {}
327738            }
327739          },
327740          "modelCard": {
327741            "modelParameters": {
327742              "approach": {}
327743            },
327744            "quantitativeAnalysis": {
327745              "graphics": {}
327746            },
327747            "considerations": {}
327748          }
327749        },
327750        {
327751          "type": "library",
327752          "bom-ref": "pkg:npm/make-plural@4.3.0?package-id=160293f143b39fd5",
327753          "supplier": {},
327754          "name": "make-plural",
327755          "version": "4.3.0",
327756          "licenses": [
327757            {
327758              "license": {
327759                "id": "ISC"
327760              }
327761            }
327762          ],
327763          "cpe": "cpe:2.3:a:make-plural:make-plural:4.3.0:*:*:*:*:*:*:*",
327764          "purl": "pkg:npm/make-plural@4.3.0",
327765          "swid": {
327766            "attachment": {}
327767          },
327768          "pedigree": {},
327769          "evidence": {},
327770          "signature": {
327771            "signature": {
327772              "publicKey": {}
327773            }
327774          },
327775          "modelCard": {
327776            "modelParameters": {
327777              "approach": {}
327778            },
327779            "quantitativeAnalysis": {
327780              "graphics": {}
327781            },
327782            "considerations": {}
327783          }
327784        },
327785        {
327786          "type": "library",
327787          "bom-ref": "pkg:npm/mamacro@0.0.3?package-id=2fcfdc8624ce520c",
327788          "supplier": {},
327789          "name": "mamacro",
327790          "version": "0.0.3",
327791          "licenses": [
327792            {
327793              "license": {
327794                "id": "MIT"
327795              }
327796            }
327797          ],
327798          "cpe": "cpe:2.3:a:mamacro:mamacro:0.0.3:*:*:*:*:*:*:*",
327799          "purl": "pkg:npm/mamacro@0.0.3",
327800          "swid": {
327801            "attachment": {}
327802          },
327803          "pedigree": {},
327804          "evidence": {},
327805          "signature": {
327806            "signature": {
327807              "publicKey": {}
327808            }
327809          },
327810          "modelCard": {
327811            "modelParameters": {
327812              "approach": {}
327813            },
327814            "quantitativeAnalysis": {
327815              "graphics": {}
327816            },
327817            "considerations": {}
327818          }
327819        },
327820        {
327821          "type": "library",
327822          "bom-ref": "pkg:npm/map-age-cleaner@0.1.3?package-id=56361233da5a887",
327823          "supplier": {},
327824          "name": "map-age-cleaner",
327825          "version": "0.1.3",
327826          "licenses": [
327827            {
327828              "license": {
327829                "id": "MIT"
327830              }
327831            }
327832          ],
327833          "cpe": "cpe:2.3:a:map-age-cleaner:map-age-cleaner:0.1.3:*:*:*:*:*:*:*",
327834          "purl": "pkg:npm/map-age-cleaner@0.1.3",
327835          "swid": {
327836            "attachment": {}
327837          },
327838          "pedigree": {},
327839          "evidence": {},
327840          "signature": {
327841            "signature": {
327842              "publicKey": {}
327843            }
327844          },
327845          "modelCard": {
327846            "modelParameters": {
327847              "approach": {}
327848            },
327849            "quantitativeAnalysis": {
327850              "graphics": {}
327851            },
327852            "considerations": {}
327853          }
327854        },
327855        {
327856          "type": "library",
327857          "bom-ref": "pkg:npm/map-cache@0.2.2?package-id=dce1fea67eed03ec",
327858          "supplier": {},
327859          "name": "map-cache",
327860          "version": "0.2.2",
327861          "licenses": [
327862            {
327863              "license": {
327864                "id": "MIT"
327865              }
327866            }
327867          ],
327868          "cpe": "cpe:2.3:a:map-cache:map-cache:0.2.2:*:*:*:*:*:*:*",
327869          "purl": "pkg:npm/map-cache@0.2.2",
327870          "swid": {
327871            "attachment": {}
327872          },
327873          "pedigree": {},
327874          "evidence": {},
327875          "signature": {
327876            "signature": {
327877              "publicKey": {}
327878            }
327879          },
327880          "modelCard": {
327881            "modelParameters": {
327882              "approach": {}
327883            },
327884            "quantitativeAnalysis": {
327885              "graphics": {}
327886            },
327887            "considerations": {}
327888          }
327889        },
327890        {
327891          "type": "library",
327892          "bom-ref": "pkg:npm/map-obj@1.0.1?package-id=b705e7a0e76c9c6b",
327893          "supplier": {},
327894          "name": "map-obj",
327895          "version": "1.0.1",
327896          "licenses": [
327897            {
327898              "license": {
327899                "id": "MIT"
327900              }
327901            }
327902          ],
327903          "cpe": "cpe:2.3:a:map-obj:map-obj:1.0.1:*:*:*:*:*:*:*",
327904          "purl": "pkg:npm/map-obj@1.0.1",
327905          "swid": {
327906            "attachment": {}
327907          },
327908          "pedigree": {},
327909          "evidence": {},
327910          "signature": {
327911            "signature": {
327912              "publicKey": {}
327913            }
327914          },
327915          "modelCard": {
327916            "modelParameters": {
327917              "approach": {}
327918            },
327919            "quantitativeAnalysis": {
327920              "graphics": {}
327921            },
327922            "considerations": {}
327923          }
327924        },
327925        {
327926          "type": "library",
327927          "bom-ref": "pkg:npm/map-visit@1.0.0?package-id=5718ccddc5416bcd",
327928          "supplier": {},
327929          "name": "map-visit",
327930          "version": "1.0.0",
327931          "licenses": [
327932            {
327933              "license": {
327934                "id": "MIT"
327935              }
327936            }
327937          ],
327938          "cpe": "cpe:2.3:a:map-visit:map-visit:1.0.0:*:*:*:*:*:*:*",
327939          "purl": "pkg:npm/map-visit@1.0.0",
327940          "swid": {
327941            "attachment": {}
327942          },
327943          "pedigree": {},
327944          "evidence": {},
327945          "signature": {
327946            "signature": {
327947              "publicKey": {}
327948            }
327949          },
327950          "modelCard": {
327951            "modelParameters": {
327952              "approach": {}
327953            },
327954            "quantitativeAnalysis": {
327955              "graphics": {}
327956            },
327957            "considerations": {}
327958          }
327959        },
327960        {
327961          "type": "library",
327962          "bom-ref": "pkg:npm/material-design-icons@3.0.1?package-id=21e30ca2f460492b",
327963          "supplier": {},
327964          "name": "material-design-icons",
327965          "version": "3.0.1",
327966          "licenses": [
327967            {
327968              "license": {
327969                "id": "Apache-2.0"
327970              }
327971            }
327972          ],
327973          "cpe": "cpe:2.3:a:material-design-icons:material-design-icons:3.0.1:*:*:*:*:*:*:*",
327974          "purl": "pkg:npm/material-design-icons@3.0.1",
327975          "swid": {
327976            "attachment": {}
327977          },
327978          "pedigree": {},
327979          "evidence": {},
327980          "signature": {
327981            "signature": {
327982              "publicKey": {}
327983            }
327984          },
327985          "modelCard": {
327986            "modelParameters": {
327987              "approach": {}
327988            },
327989            "quantitativeAnalysis": {
327990              "graphics": {}
327991            },
327992            "considerations": {}
327993          }
327994        },
327995        {
327996          "type": "library",
327997          "bom-ref": "pkg:npm/md5@2.2.1?package-id=800a88672a48643d",
327998          "supplier": {},
327999          "name": "md5",
328000          "version": "2.2.1",
328001          "licenses": [
328002            {
328003              "license": {
328004                "id": "BSD-3-Clause"
328005              }
328006            }
328007          ],
328008          "cpe": "cpe:2.3:a:md5:md5:2.2.1:*:*:*:*:*:*:*",
328009          "purl": "pkg:npm/md5@2.2.1",
328010          "swid": {
328011            "attachment": {}
328012          },
328013          "pedigree": {},
328014          "evidence": {},
328015          "signature": {
328016            "signature": {
328017              "publicKey": {}
328018            }
328019          },
328020          "modelCard": {
328021            "modelParameters": {
328022              "approach": {}
328023            },
328024            "quantitativeAnalysis": {
328025              "graphics": {}
328026            },
328027            "considerations": {}
328028          }
328029        },
328030        {
328031          "type": "library",
328032          "bom-ref": "pkg:npm/md5.js@1.3.5?package-id=77b1f5bb6464ec80",
328033          "supplier": {},
328034          "name": "md5.js",
328035          "version": "1.3.5",
328036          "licenses": [
328037            {
328038              "license": {
328039                "id": "MIT"
328040              }
328041            }
328042          ],
328043          "cpe": "cpe:2.3:a:md5.js:md5.js:1.3.5:*:*:*:*:*:*:*",
328044          "purl": "pkg:npm/md5.js@1.3.5",
328045          "swid": {
328046            "attachment": {}
328047          },
328048          "pedigree": {},
328049          "evidence": {},
328050          "signature": {
328051            "signature": {
328052              "publicKey": {}
328053            }
328054          },
328055          "modelCard": {
328056            "modelParameters": {
328057              "approach": {}
328058            },
328059            "quantitativeAnalysis": {
328060              "graphics": {}
328061            },
328062            "considerations": {}
328063          }
328064        },
328065        {
328066          "type": "library",
328067          "bom-ref": "pkg:npm/mdn-data@2.0.4?package-id=472d5418be1af51",
328068          "supplier": {},
328069          "name": "mdn-data",
328070          "version": "2.0.4",
328071          "licenses": [
328072            {
328073              "license": {
328074                "id": "CC0-1.0"
328075              }
328076            }
328077          ],
328078          "cpe": "cpe:2.3:a:mdn-data:mdn-data:2.0.4:*:*:*:*:*:*:*",
328079          "purl": "pkg:npm/mdn-data@2.0.4",
328080          "swid": {
328081            "attachment": {}
328082          },
328083          "pedigree": {},
328084          "evidence": {},
328085          "signature": {
328086            "signature": {
328087              "publicKey": {}
328088            }
328089          },
328090          "modelCard": {
328091            "modelParameters": {
328092              "approach": {}
328093            },
328094            "quantitativeAnalysis": {
328095              "graphics": {}
328096            },
328097            "considerations": {}
328098          }
328099        },
328100        {
328101          "type": "library",
328102          "bom-ref": "pkg:npm/media-typer@0.3.0?package-id=ca48d6b56e4fc502",
328103          "supplier": {},
328104          "name": "media-typer",
328105          "version": "0.3.0",
328106          "licenses": [
328107            {
328108              "license": {
328109                "id": "MIT"
328110              }
328111            }
328112          ],
328113          "cpe": "cpe:2.3:a:media-typer:media-typer:0.3.0:*:*:*:*:*:*:*",
328114          "purl": "pkg:npm/media-typer@0.3.0",
328115          "swid": {
328116            "attachment": {}
328117          },
328118          "pedigree": {},
328119          "evidence": {},
328120          "signature": {
328121            "signature": {
328122              "publicKey": {}
328123            }
328124          },
328125          "modelCard": {
328126            "modelParameters": {
328127              "approach": {}
328128            },
328129            "quantitativeAnalysis": {
328130              "graphics": {}
328131            },
328132            "considerations": {}
328133          }
328134        },
328135        {
328136          "type": "library",
328137          "bom-ref": "pkg:npm/mem@4.3.0?package-id=4763427674c2e30b",
328138          "supplier": {},
328139          "name": "mem",
328140          "version": "4.3.0",
328141          "licenses": [
328142            {
328143              "license": {
328144                "id": "MIT"
328145              }
328146            }
328147          ],
328148          "cpe": "cpe:2.3:a:mem:mem:4.3.0:*:*:*:*:*:*:*",
328149          "purl": "pkg:npm/mem@4.3.0",
328150          "swid": {
328151            "attachment": {}
328152          },
328153          "pedigree": {},
328154          "evidence": {},
328155          "signature": {
328156            "signature": {
328157              "publicKey": {}
328158            }
328159          },
328160          "modelCard": {
328161            "modelParameters": {
328162              "approach": {}
328163            },
328164            "quantitativeAnalysis": {
328165              "graphics": {}
328166            },
328167            "considerations": {}
328168          }
328169        },
328170        {
328171          "type": "library",
328172          "bom-ref": "pkg:npm/memoizee@0.4.14?package-id=a98d62d96a090606",
328173          "supplier": {},
328174          "name": "memoizee",
328175          "version": "0.4.14",
328176          "licenses": [
328177            {
328178              "license": {
328179                "id": "ISC"
328180              }
328181            }
328182          ],
328183          "cpe": "cpe:2.3:a:memoizee:memoizee:0.4.14:*:*:*:*:*:*:*",
328184          "purl": "pkg:npm/memoizee@0.4.14",
328185          "swid": {
328186            "attachment": {}
328187          },
328188          "pedigree": {},
328189          "evidence": {},
328190          "signature": {
328191            "signature": {
328192              "publicKey": {}
328193            }
328194          },
328195          "modelCard": {
328196            "modelParameters": {
328197              "approach": {}
328198            },
328199            "quantitativeAnalysis": {
328200              "graphics": {}
328201            },
328202            "considerations": {}
328203          }
328204        },
328205        {
328206          "type": "library",
328207          "bom-ref": "pkg:npm/memory-cache@0.2.0?package-id=dc76999d25bf8aec",
328208          "supplier": {},
328209          "name": "memory-cache",
328210          "version": "0.2.0",
328211          "licenses": [
328212            {
328213              "license": {
328214                "id": "BSD-2-Clause"
328215              }
328216            }
328217          ],
328218          "cpe": "cpe:2.3:a:memory-cache:memory-cache:0.2.0:*:*:*:*:*:*:*",
328219          "purl": "pkg:npm/memory-cache@0.2.0",
328220          "swid": {
328221            "attachment": {}
328222          },
328223          "pedigree": {},
328224          "evidence": {},
328225          "signature": {
328226            "signature": {
328227              "publicKey": {}
328228            }
328229          },
328230          "modelCard": {
328231            "modelParameters": {
328232              "approach": {}
328233            },
328234            "quantitativeAnalysis": {
328235              "graphics": {}
328236            },
328237            "considerations": {}
328238          }
328239        },
328240        {
328241          "type": "library",
328242          "bom-ref": "pkg:npm/memory-fs@0.5.0?package-id=835a482066c109d9",
328243          "supplier": {},
328244          "name": "memory-fs",
328245          "version": "0.5.0",
328246          "licenses": [
328247            {
328248              "license": {
328249                "id": "MIT"
328250              }
328251            }
328252          ],
328253          "cpe": "cpe:2.3:a:memory-fs:memory-fs:0.5.0:*:*:*:*:*:*:*",
328254          "purl": "pkg:npm/memory-fs@0.5.0",
328255          "swid": {
328256            "attachment": {}
328257          },
328258          "pedigree": {},
328259          "evidence": {},
328260          "signature": {
328261            "signature": {
328262              "publicKey": {}
328263            }
328264          },
328265          "modelCard": {
328266            "modelParameters": {
328267              "approach": {}
328268            },
328269            "quantitativeAnalysis": {
328270              "graphics": {}
328271            },
328272            "considerations": {}
328273          }
328274        },
328275        {
328276          "type": "library",
328277          "bom-ref": "pkg:npm/meow@3.7.0?package-id=d6ca1246457d6581",
328278          "supplier": {},
328279          "name": "meow",
328280          "version": "3.7.0",
328281          "licenses": [
328282            {
328283              "license": {
328284                "id": "MIT"
328285              }
328286            }
328287          ],
328288          "cpe": "cpe:2.3:a:meow:meow:3.7.0:*:*:*:*:*:*:*",
328289          "purl": "pkg:npm/meow@3.7.0",
328290          "swid": {
328291            "attachment": {}
328292          },
328293          "pedigree": {},
328294          "evidence": {},
328295          "signature": {
328296            "signature": {
328297              "publicKey": {}
328298            }
328299          },
328300          "modelCard": {
328301            "modelParameters": {
328302              "approach": {}
328303            },
328304            "quantitativeAnalysis": {
328305              "graphics": {}
328306            },
328307            "considerations": {}
328308          }
328309        },
328310        {
328311          "type": "library",
328312          "bom-ref": "pkg:npm/merge-descriptors@1.0.1?package-id=b3a54c67bd87d9b4",
328313          "supplier": {},
328314          "name": "merge-descriptors",
328315          "version": "1.0.1",
328316          "licenses": [
328317            {
328318              "license": {
328319                "id": "MIT"
328320              }
328321            }
328322          ],
328323          "cpe": "cpe:2.3:a:merge-descriptors:merge-descriptors:1.0.1:*:*:*:*:*:*:*",
328324          "purl": "pkg:npm/merge-descriptors@1.0.1",
328325          "swid": {
328326            "attachment": {}
328327          },
328328          "pedigree": {},
328329          "evidence": {},
328330          "signature": {
328331            "signature": {
328332              "publicKey": {}
328333            }
328334          },
328335          "modelCard": {
328336            "modelParameters": {
328337              "approach": {}
328338            },
328339            "quantitativeAnalysis": {
328340              "graphics": {}
328341            },
328342            "considerations": {}
328343          }
328344        },
328345        {
328346          "type": "library",
328347          "bom-ref": "pkg:npm/merge-source-map@1.1.0?package-id=a5da2b3ceea5d559",
328348          "supplier": {},
328349          "name": "merge-source-map",
328350          "version": "1.1.0",
328351          "licenses": [
328352            {
328353              "license": {
328354                "id": "MIT"
328355              }
328356            }
328357          ],
328358          "cpe": "cpe:2.3:a:merge-source-map:merge-source-map:1.1.0:*:*:*:*:*:*:*",
328359          "purl": "pkg:npm/merge-source-map@1.1.0",
328360          "swid": {
328361            "attachment": {}
328362          },
328363          "pedigree": {},
328364          "evidence": {},
328365          "signature": {
328366            "signature": {
328367              "publicKey": {}
328368            }
328369          },
328370          "modelCard": {
328371            "modelParameters": {
328372              "approach": {}
328373            },
328374            "quantitativeAnalysis": {
328375              "graphics": {}
328376            },
328377            "considerations": {}
328378          }
328379        },
328380        {
328381          "type": "library",
328382          "bom-ref": "pkg:npm/merge-stream@2.0.0?package-id=13c60b24bc18ddc1",
328383          "supplier": {},
328384          "name": "merge-stream",
328385          "version": "2.0.0",
328386          "licenses": [
328387            {
328388              "license": {
328389                "id": "MIT"
328390              }
328391            }
328392          ],
328393          "cpe": "cpe:2.3:a:merge-stream:merge-stream:2.0.0:*:*:*:*:*:*:*",
328394          "purl": "pkg:npm/merge-stream@2.0.0",
328395          "swid": {
328396            "attachment": {}
328397          },
328398          "pedigree": {},
328399          "evidence": {},
328400          "signature": {
328401            "signature": {
328402              "publicKey": {}
328403            }
328404          },
328405          "modelCard": {
328406            "modelParameters": {
328407              "approach": {}
328408            },
328409            "quantitativeAnalysis": {
328410              "graphics": {}
328411            },
328412            "considerations": {}
328413          }
328414        },
328415        {
328416          "type": "library",
328417          "bom-ref": "pkg:npm/messageformat@2.3.0?package-id=58942b14cde58e60",
328418          "supplier": {},
328419          "name": "messageformat",
328420          "version": "2.3.0",
328421          "licenses": [
328422            {
328423              "license": {
328424                "id": "MIT"
328425              }
328426            }
328427          ],
328428          "cpe": "cpe:2.3:a:messageformat:messageformat:2.3.0:*:*:*:*:*:*:*",
328429          "purl": "pkg:npm/messageformat@2.3.0",
328430          "swid": {
328431            "attachment": {}
328432          },
328433          "pedigree": {},
328434          "evidence": {},
328435          "signature": {
328436            "signature": {
328437              "publicKey": {}
328438            }
328439          },
328440          "modelCard": {
328441            "modelParameters": {
328442              "approach": {}
328443            },
328444            "quantitativeAnalysis": {
328445              "graphics": {}
328446            },
328447            "considerations": {}
328448          }
328449        },
328450        {
328451          "type": "library",
328452          "bom-ref": "pkg:npm/messageformat-formatters@2.0.1?package-id=ece43a41f43df5a4",
328453          "supplier": {},
328454          "name": "messageformat-formatters",
328455          "version": "2.0.1",
328456          "licenses": [
328457            {
328458              "license": {
328459                "id": "MIT"
328460              }
328461            }
328462          ],
328463          "cpe": "cpe:2.3:a:messageformat-formatters:messageformat-formatters:2.0.1:*:*:*:*:*:*:*",
328464          "purl": "pkg:npm/messageformat-formatters@2.0.1",
328465          "swid": {
328466            "attachment": {}
328467          },
328468          "pedigree": {},
328469          "evidence": {},
328470          "signature": {
328471            "signature": {
328472              "publicKey": {}
328473            }
328474          },
328475          "modelCard": {
328476            "modelParameters": {
328477              "approach": {}
328478            },
328479            "quantitativeAnalysis": {
328480              "graphics": {}
328481            },
328482            "considerations": {}
328483          }
328484        },
328485        {
328486          "type": "library",
328487          "bom-ref": "pkg:npm/messageformat-parser@4.1.2?package-id=c645b1bc35ae8458",
328488          "supplier": {},
328489          "name": "messageformat-parser",
328490          "version": "4.1.2",
328491          "licenses": [
328492            {
328493              "license": {
328494                "id": "MIT"
328495              }
328496            }
328497          ],
328498          "cpe": "cpe:2.3:a:messageformat-parser:messageformat-parser:4.1.2:*:*:*:*:*:*:*",
328499          "purl": "pkg:npm/messageformat-parser@4.1.2",
328500          "swid": {
328501            "attachment": {}
328502          },
328503          "pedigree": {},
328504          "evidence": {},
328505          "signature": {
328506            "signature": {
328507              "publicKey": {}
328508            }
328509          },
328510          "modelCard": {
328511            "modelParameters": {
328512              "approach": {}
328513            },
328514            "quantitativeAnalysis": {
328515              "graphics": {}
328516            },
328517            "considerations": {}
328518          }
328519        },
328520        {
328521          "type": "library",
328522          "bom-ref": "pkg:npm/methods@1.1.2?package-id=7cf6621b8f94cdb",
328523          "supplier": {},
328524          "name": "methods",
328525          "version": "1.1.2",
328526          "licenses": [
328527            {
328528              "license": {
328529                "id": "MIT"
328530              }
328531            }
328532          ],
328533          "cpe": "cpe:2.3:a:methods:methods:1.1.2:*:*:*:*:*:*:*",
328534          "purl": "pkg:npm/methods@1.1.2",
328535          "swid": {
328536            "attachment": {}
328537          },
328538          "pedigree": {},
328539          "evidence": {},
328540          "signature": {
328541            "signature": {
328542              "publicKey": {}
328543            }
328544          },
328545          "modelCard": {
328546            "modelParameters": {
328547              "approach": {}
328548            },
328549            "quantitativeAnalysis": {
328550              "graphics": {}
328551            },
328552            "considerations": {}
328553          }
328554        },
328555        {
328556          "type": "library",
328557          "bom-ref": "pkg:npm/micromatch@3.1.10?package-id=859bae501355cf8d",
328558          "supplier": {},
328559          "name": "micromatch",
328560          "version": "3.1.10",
328561          "licenses": [
328562            {
328563              "license": {
328564                "id": "MIT"
328565              }
328566            }
328567          ],
328568          "cpe": "cpe:2.3:a:micromatch:micromatch:3.1.10:*:*:*:*:*:*:*",
328569          "purl": "pkg:npm/micromatch@3.1.10",
328570          "swid": {
328571            "attachment": {}
328572          },
328573          "pedigree": {},
328574          "evidence": {},
328575          "signature": {
328576            "signature": {
328577              "publicKey": {}
328578            }
328579          },
328580          "modelCard": {
328581            "modelParameters": {
328582              "approach": {}
328583            },
328584            "quantitativeAnalysis": {
328585              "graphics": {}
328586            },
328587            "considerations": {}
328588          }
328589        },
328590        {
328591          "type": "library",
328592          "bom-ref": "pkg:npm/micromatch@4.0.4?package-id=70db87ed40b38bef",
328593          "supplier": {},
328594          "name": "micromatch",
328595          "version": "4.0.4",
328596          "cpe": "cpe:2.3:a:micromatch:micromatch:4.0.4:*:*:*:*:*:*:*",
328597          "purl": "pkg:npm/micromatch@4.0.4",
328598          "swid": {
328599            "attachment": {}
328600          },
328601          "pedigree": {},
328602          "evidence": {},
328603          "signature": {
328604            "signature": {
328605              "publicKey": {}
328606            }
328607          },
328608          "modelCard": {
328609            "modelParameters": {
328610              "approach": {}
328611            },
328612            "quantitativeAnalysis": {
328613              "graphics": {}
328614            },
328615            "considerations": {}
328616          }
328617        },
328618        {
328619          "type": "library",
328620          "bom-ref": "pkg:npm/miller-rabin@4.0.1?package-id=63e2cca7f77bc8f",
328621          "supplier": {},
328622          "name": "miller-rabin",
328623          "version": "4.0.1",
328624          "licenses": [
328625            {
328626              "license": {
328627                "id": "MIT"
328628              }
328629            }
328630          ],
328631          "cpe": "cpe:2.3:a:miller-rabin:miller-rabin:4.0.1:*:*:*:*:*:*:*",
328632          "purl": "pkg:npm/miller-rabin@4.0.1",
328633          "swid": {
328634            "attachment": {}
328635          },
328636          "pedigree": {},
328637          "evidence": {},
328638          "signature": {
328639            "signature": {
328640              "publicKey": {}
328641            }
328642          },
328643          "modelCard": {
328644            "modelParameters": {
328645              "approach": {}
328646            },
328647            "quantitativeAnalysis": {
328648              "graphics": {}
328649            },
328650            "considerations": {}
328651          }
328652        },
328653        {
328654          "type": "library",
328655          "bom-ref": "pkg:npm/mime@1.6.0?package-id=b2183e468b37566b",
328656          "supplier": {},
328657          "name": "mime",
328658          "version": "1.6.0",
328659          "licenses": [
328660            {
328661              "license": {
328662                "id": "MIT"
328663              }
328664            }
328665          ],
328666          "cpe": "cpe:2.3:a:mime:mime:1.6.0:*:*:*:*:*:*:*",
328667          "purl": "pkg:npm/mime@1.6.0",
328668          "swid": {
328669            "attachment": {}
328670          },
328671          "pedigree": {},
328672          "evidence": {},
328673          "signature": {
328674            "signature": {
328675              "publicKey": {}
328676            }
328677          },
328678          "modelCard": {
328679            "modelParameters": {
328680              "approach": {}
328681            },
328682            "quantitativeAnalysis": {
328683              "graphics": {}
328684            },
328685            "considerations": {}
328686          }
328687        },
328688        {
328689          "type": "library",
328690          "bom-ref": "pkg:npm/mime-db@1.43.0?package-id=46a9ce8ec5654417",
328691          "supplier": {},
328692          "name": "mime-db",
328693          "version": "1.43.0",
328694          "licenses": [
328695            {
328696              "license": {
328697                "id": "MIT"
328698              }
328699            }
328700          ],
328701          "cpe": "cpe:2.3:a:mime-db:mime-db:1.43.0:*:*:*:*:*:*:*",
328702          "purl": "pkg:npm/mime-db@1.43.0",
328703          "swid": {
328704            "attachment": {}
328705          },
328706          "pedigree": {},
328707          "evidence": {},
328708          "signature": {
328709            "signature": {
328710              "publicKey": {}
328711            }
328712          },
328713          "modelCard": {
328714            "modelParameters": {
328715              "approach": {}
328716            },
328717            "quantitativeAnalysis": {
328718              "graphics": {}
328719            },
328720            "considerations": {}
328721          }
328722        },
328723        {
328724          "type": "library",
328725          "bom-ref": "pkg:npm/mime-types@2.1.26?package-id=adfbe56a0ffaec05",
328726          "supplier": {},
328727          "name": "mime-types",
328728          "version": "2.1.26",
328729          "licenses": [
328730            {
328731              "license": {
328732                "id": "MIT"
328733              }
328734            }
328735          ],
328736          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.26:*:*:*:*:*:*:*",
328737          "purl": "pkg:npm/mime-types@2.1.26",
328738          "swid": {
328739            "attachment": {}
328740          },
328741          "pedigree": {},
328742          "evidence": {},
328743          "signature": {
328744            "signature": {
328745              "publicKey": {}
328746            }
328747          },
328748          "modelCard": {
328749            "modelParameters": {
328750              "approach": {}
328751            },
328752            "quantitativeAnalysis": {
328753              "graphics": {}
328754            },
328755            "considerations": {}
328756          }
328757        },
328758        {
328759          "type": "library",
328760          "bom-ref": "pkg:npm/mimic-fn@2.1.0?package-id=58a044b09ce3ee39",
328761          "supplier": {},
328762          "name": "mimic-fn",
328763          "version": "2.1.0",
328764          "licenses": [
328765            {
328766              "license": {
328767                "id": "MIT"
328768              }
328769            }
328770          ],
328771          "cpe": "cpe:2.3:a:mimic-fn:mimic-fn:2.1.0:*:*:*:*:*:*:*",
328772          "purl": "pkg:npm/mimic-fn@2.1.0",
328773          "swid": {
328774            "attachment": {}
328775          },
328776          "pedigree": {},
328777          "evidence": {},
328778          "signature": {
328779            "signature": {
328780              "publicKey": {}
328781            }
328782          },
328783          "modelCard": {
328784            "modelParameters": {
328785              "approach": {}
328786            },
328787            "quantitativeAnalysis": {
328788              "graphics": {}
328789            },
328790            "considerations": {}
328791          }
328792        },
328793        {
328794          "type": "library",
328795          "bom-ref": "pkg:npm/mini-css-extract-plugin@0.9.0?package-id=ee7457c4ca9748f7",
328796          "supplier": {},
328797          "name": "mini-css-extract-plugin",
328798          "version": "0.9.0",
328799          "licenses": [
328800            {
328801              "license": {
328802                "id": "MIT"
328803              }
328804            }
328805          ],
328806          "cpe": "cpe:2.3:a:mini-css-extract-plugin:mini-css-extract-plugin:0.9.0:*:*:*:*:*:*:*",
328807          "purl": "pkg:npm/mini-css-extract-plugin@0.9.0",
328808          "swid": {
328809            "attachment": {}
328810          },
328811          "pedigree": {},
328812          "evidence": {},
328813          "signature": {
328814            "signature": {
328815              "publicKey": {}
328816            }
328817          },
328818          "modelCard": {
328819            "modelParameters": {
328820              "approach": {}
328821            },
328822            "quantitativeAnalysis": {
328823              "graphics": {}
328824            },
328825            "considerations": {}
328826          }
328827        },
328828        {
328829          "type": "library",
328830          "bom-ref": "pkg:maven/com.eclipsesource.minimal-json/minimal-json@0.9.4?package-id=99263807019f1a53",
328831          "supplier": {},
328832          "group": "com.eclipsesource.minimal-json",
328833          "name": "minimal-json",
328834          "version": "0.9.4",
328835          "cpe": "cpe:2.3:a:eclipsesource:minimal-json:0.9.4:*:*:*:*:*:*:*",
328836          "purl": "pkg:maven/com.eclipsesource.minimal-json/minimal-json@0.9.4",
328837          "swid": {
328838            "attachment": {}
328839          },
328840          "pedigree": {},
328841          "evidence": {},
328842          "signature": {
328843            "signature": {
328844              "publicKey": {}
328845            }
328846          },
328847          "modelCard": {
328848            "modelParameters": {
328849              "approach": {}
328850            },
328851            "quantitativeAnalysis": {
328852              "graphics": {}
328853            },
328854            "considerations": {}
328855          }
328856        },
328857        {
328858          "type": "library",
328859          "bom-ref": "pkg:npm/minimalistic-assert@1.0.1?package-id=705ca3e3f6e7eb02",
328860          "supplier": {},
328861          "name": "minimalistic-assert",
328862          "version": "1.0.1",
328863          "licenses": [
328864            {
328865              "license": {
328866                "id": "ISC"
328867              }
328868            }
328869          ],
328870          "cpe": "cpe:2.3:a:minimalistic-assert:minimalistic-assert:1.0.1:*:*:*:*:*:*:*",
328871          "purl": "pkg:npm/minimalistic-assert@1.0.1",
328872          "swid": {
328873            "attachment": {}
328874          },
328875          "pedigree": {},
328876          "evidence": {},
328877          "signature": {
328878            "signature": {
328879              "publicKey": {}
328880            }
328881          },
328882          "modelCard": {
328883            "modelParameters": {
328884              "approach": {}
328885            },
328886            "quantitativeAnalysis": {
328887              "graphics": {}
328888            },
328889            "considerations": {}
328890          }
328891        },
328892        {
328893          "type": "library",
328894          "bom-ref": "pkg:npm/minimalistic-crypto-utils@1.0.1?package-id=45d367331e8404fa",
328895          "supplier": {},
328896          "name": "minimalistic-crypto-utils",
328897          "version": "1.0.1",
328898          "licenses": [
328899            {
328900              "license": {
328901                "id": "MIT"
328902              }
328903            }
328904          ],
328905          "cpe": "cpe:2.3:a:minimalistic-crypto-utils:minimalistic-crypto-utils:1.0.1:*:*:*:*:*:*:*",
328906          "purl": "pkg:npm/minimalistic-crypto-utils@1.0.1",
328907          "swid": {
328908            "attachment": {}
328909          },
328910          "pedigree": {},
328911          "evidence": {},
328912          "signature": {
328913            "signature": {
328914              "publicKey": {}
328915            }
328916          },
328917          "modelCard": {
328918            "modelParameters": {
328919              "approach": {}
328920            },
328921            "quantitativeAnalysis": {
328922              "graphics": {}
328923            },
328924            "considerations": {}
328925          }
328926        },
328927        {
328928          "type": "library",
328929          "bom-ref": "pkg:npm/minimatch@3.0.4?package-id=ee00f3cf2b87f404",
328930          "supplier": {},
328931          "name": "minimatch",
328932          "version": "3.0.4",
328933          "cpe": "cpe:2.3:a:minimatch:minimatch:3.0.4:*:*:*:*:*:*:*",
328934          "purl": "pkg:npm/minimatch@3.0.4",
328935          "swid": {
328936            "attachment": {}
328937          },
328938          "pedigree": {},
328939          "evidence": {},
328940          "signature": {
328941            "signature": {
328942              "publicKey": {}
328943            }
328944          },
328945          "modelCard": {
328946            "modelParameters": {
328947              "approach": {}
328948            },
328949            "quantitativeAnalysis": {
328950              "graphics": {}
328951            },
328952            "considerations": {}
328953          }
328954        },
328955        {
328956          "type": "library",
328957          "bom-ref": "pkg:npm/minimatch@3.0.4?package-id=c5e9ed4b28717954",
328958          "supplier": {},
328959          "name": "minimatch",
328960          "version": "3.0.4",
328961          "licenses": [
328962            {
328963              "license": {
328964                "id": "ISC"
328965              }
328966            }
328967          ],
328968          "cpe": "cpe:2.3:a:minimatch:minimatch:3.0.4:*:*:*:*:*:*:*",
328969          "purl": "pkg:npm/minimatch@3.0.4",
328970          "swid": {
328971            "attachment": {}
328972          },
328973          "pedigree": {},
328974          "evidence": {},
328975          "signature": {
328976            "signature": {
328977              "publicKey": {}
328978            }
328979          },
328980          "modelCard": {
328981            "modelParameters": {
328982              "approach": {}
328983            },
328984            "quantitativeAnalysis": {
328985              "graphics": {}
328986            },
328987            "considerations": {}
328988          }
328989        },
328990        {
328991          "type": "library",
328992          "bom-ref": "pkg:npm/minimist@0.0.10?package-id=1c07596d9c4c0832",
328993          "supplier": {},
328994          "name": "minimist",
328995          "version": "0.0.10",
328996          "licenses": [
328997            {
328998              "license": {
328999                "id": "MIT"
329000              }
329001            }
329002          ],
329003          "cpe": "cpe:2.3:a:minimist:minimist:0.0.10:*:*:*:*:*:*:*",
329004          "purl": "pkg:npm/minimist@0.0.10",
329005          "swid": {
329006            "attachment": {}
329007          },
329008          "pedigree": {},
329009          "evidence": {},
329010          "signature": {
329011            "signature": {
329012              "publicKey": {}
329013            }
329014          },
329015          "modelCard": {
329016            "modelParameters": {
329017              "approach": {}
329018            },
329019            "quantitativeAnalysis": {
329020              "graphics": {}
329021            },
329022            "considerations": {}
329023          }
329024        },
329025        {
329026          "type": "library",
329027          "bom-ref": "pkg:npm/minimist@1.2.5?package-id=3db111d71d3ecf68",
329028          "supplier": {},
329029          "name": "minimist",
329030          "version": "1.2.5",
329031          "cpe": "cpe:2.3:a:minimist:minimist:1.2.5:*:*:*:*:*:*:*",
329032          "purl": "pkg:npm/minimist@1.2.5",
329033          "swid": {
329034            "attachment": {}
329035          },
329036          "pedigree": {},
329037          "evidence": {},
329038          "signature": {
329039            "signature": {
329040              "publicKey": {}
329041            }
329042          },
329043          "modelCard": {
329044            "modelParameters": {
329045              "approach": {}
329046            },
329047            "quantitativeAnalysis": {
329048              "graphics": {}
329049            },
329050            "considerations": {}
329051          }
329052        },
329053        {
329054          "type": "library",
329055          "bom-ref": "pkg:npm/minipass@3.1.1?package-id=5249402b96ad198b",
329056          "supplier": {},
329057          "name": "minipass",
329058          "version": "3.1.1",
329059          "licenses": [
329060            {
329061              "license": {
329062                "id": "ISC"
329063              }
329064            }
329065          ],
329066          "cpe": "cpe:2.3:a:minipass:minipass:3.1.1:*:*:*:*:*:*:*",
329067          "purl": "pkg:npm/minipass@3.1.1",
329068          "swid": {
329069            "attachment": {}
329070          },
329071          "pedigree": {},
329072          "evidence": {},
329073          "signature": {
329074            "signature": {
329075              "publicKey": {}
329076            }
329077          },
329078          "modelCard": {
329079            "modelParameters": {
329080              "approach": {}
329081            },
329082            "quantitativeAnalysis": {
329083              "graphics": {}
329084            },
329085            "considerations": {}
329086          }
329087        },
329088        {
329089          "type": "library",
329090          "bom-ref": "pkg:npm/minipass-collect@1.0.2?package-id=13cc293ff0489da7",
329091          "supplier": {},
329092          "name": "minipass-collect",
329093          "version": "1.0.2",
329094          "licenses": [
329095            {
329096              "license": {
329097                "id": "ISC"
329098              }
329099            }
329100          ],
329101          "cpe": "cpe:2.3:a:minipass-collect:minipass-collect:1.0.2:*:*:*:*:*:*:*",
329102          "purl": "pkg:npm/minipass-collect@1.0.2",
329103          "swid": {
329104            "attachment": {}
329105          },
329106          "pedigree": {},
329107          "evidence": {},
329108          "signature": {
329109            "signature": {
329110              "publicKey": {}
329111            }
329112          },
329113          "modelCard": {
329114            "modelParameters": {
329115              "approach": {}
329116            },
329117            "quantitativeAnalysis": {
329118              "graphics": {}
329119            },
329120            "considerations": {}
329121          }
329122        },
329123        {
329124          "type": "library",
329125          "bom-ref": "pkg:npm/minipass-flush@1.0.5?package-id=44b66fdb41c47d06",
329126          "supplier": {},
329127          "name": "minipass-flush",
329128          "version": "1.0.5",
329129          "licenses": [
329130            {
329131              "license": {
329132                "id": "ISC"
329133              }
329134            }
329135          ],
329136          "cpe": "cpe:2.3:a:minipass-flush:minipass-flush:1.0.5:*:*:*:*:*:*:*",
329137          "purl": "pkg:npm/minipass-flush@1.0.5",
329138          "swid": {
329139            "attachment": {}
329140          },
329141          "pedigree": {},
329142          "evidence": {},
329143          "signature": {
329144            "signature": {
329145              "publicKey": {}
329146            }
329147          },
329148          "modelCard": {
329149            "modelParameters": {
329150              "approach": {}
329151            },
329152            "quantitativeAnalysis": {
329153              "graphics": {}
329154            },
329155            "considerations": {}
329156          }
329157        },
329158        {
329159          "type": "library",
329160          "bom-ref": "pkg:npm/minipass-pipeline@1.2.2?package-id=39b7ae6c094ea9d8",
329161          "supplier": {},
329162          "name": "minipass-pipeline",
329163          "version": "1.2.2",
329164          "licenses": [
329165            {
329166              "license": {
329167                "id": "ISC"
329168              }
329169            }
329170          ],
329171          "cpe": "cpe:2.3:a:minipass-pipeline:minipass-pipeline:1.2.2:*:*:*:*:*:*:*",
329172          "purl": "pkg:npm/minipass-pipeline@1.2.2",
329173          "swid": {
329174            "attachment": {}
329175          },
329176          "pedigree": {},
329177          "evidence": {},
329178          "signature": {
329179            "signature": {
329180              "publicKey": {}
329181            }
329182          },
329183          "modelCard": {
329184            "modelParameters": {
329185              "approach": {}
329186            },
329187            "quantitativeAnalysis": {
329188              "graphics": {}
329189            },
329190            "considerations": {}
329191          }
329192        },
329193        {
329194          "type": "library",
329195          "bom-ref": "pkg:npm/minizlib@2.1.0?package-id=19a156c3174a5e27",
329196          "supplier": {},
329197          "name": "minizlib",
329198          "version": "2.1.0",
329199          "licenses": [
329200            {
329201              "license": {
329202                "id": "MIT"
329203              }
329204            }
329205          ],
329206          "cpe": "cpe:2.3:a:minizlib:minizlib:2.1.0:*:*:*:*:*:*:*",
329207          "purl": "pkg:npm/minizlib@2.1.0",
329208          "swid": {
329209            "attachment": {}
329210          },
329211          "pedigree": {},
329212          "evidence": {},
329213          "signature": {
329214            "signature": {
329215              "publicKey": {}
329216            }
329217          },
329218          "modelCard": {
329219            "modelParameters": {
329220              "approach": {}
329221            },
329222            "quantitativeAnalysis": {
329223              "graphics": {}
329224            },
329225            "considerations": {}
329226          }
329227        },
329228        {
329229          "type": "library",
329230          "bom-ref": "pkg:npm/mississippi@3.0.0?package-id=506cfdbeb502a4cb",
329231          "supplier": {},
329232          "name": "mississippi",
329233          "version": "3.0.0",
329234          "licenses": [
329235            {
329236              "license": {
329237                "id": "BSD-2-Clause"
329238              }
329239            }
329240          ],
329241          "cpe": "cpe:2.3:a:mississippi:mississippi:3.0.0:*:*:*:*:*:*:*",
329242          "purl": "pkg:npm/mississippi@3.0.0",
329243          "swid": {
329244            "attachment": {}
329245          },
329246          "pedigree": {},
329247          "evidence": {},
329248          "signature": {
329249            "signature": {
329250              "publicKey": {}
329251            }
329252          },
329253          "modelCard": {
329254            "modelParameters": {
329255              "approach": {}
329256            },
329257            "quantitativeAnalysis": {
329258              "graphics": {}
329259            },
329260            "considerations": {}
329261          }
329262        },
329263        {
329264          "type": "library",
329265          "bom-ref": "pkg:npm/mixin-deep@1.3.2?package-id=e949ad29dd481b21",
329266          "supplier": {},
329267          "name": "mixin-deep",
329268          "version": "1.3.2",
329269          "licenses": [
329270            {
329271              "license": {
329272                "id": "MIT"
329273              }
329274            }
329275          ],
329276          "cpe": "cpe:2.3:a:mixin-deep:mixin-deep:1.3.2:*:*:*:*:*:*:*",
329277          "purl": "pkg:npm/mixin-deep@1.3.2",
329278          "swid": {
329279            "attachment": {}
329280          },
329281          "pedigree": {},
329282          "evidence": {},
329283          "signature": {
329284            "signature": {
329285              "publicKey": {}
329286            }
329287          },
329288          "modelCard": {
329289            "modelParameters": {
329290              "approach": {}
329291            },
329292            "quantitativeAnalysis": {
329293              "graphics": {}
329294            },
329295            "considerations": {}
329296          }
329297        },
329298        {
329299          "type": "library",
329300          "bom-ref": "pkg:npm/mkdirp@0.5.4?package-id=9357305f8b408ea7",
329301          "supplier": {},
329302          "name": "mkdirp",
329303          "version": "0.5.4",
329304          "licenses": [
329305            {
329306              "license": {
329307                "id": "MIT"
329308              }
329309            }
329310          ],
329311          "cpe": "cpe:2.3:a:mkdirp:mkdirp:0.5.4:*:*:*:*:*:*:*",
329312          "purl": "pkg:npm/mkdirp@0.5.4",
329313          "swid": {
329314            "attachment": {}
329315          },
329316          "pedigree": {},
329317          "evidence": {},
329318          "signature": {
329319            "signature": {
329320              "publicKey": {}
329321            }
329322          },
329323          "modelCard": {
329324            "modelParameters": {
329325              "approach": {}
329326            },
329327            "quantitativeAnalysis": {
329328              "graphics": {}
329329            },
329330            "considerations": {}
329331          }
329332        },
329333        {
329334          "type": "library",
329335          "bom-ref": "pkg:npm/moment@2.29.4?package-id=b2d2faac48e64687",
329336          "supplier": {},
329337          "name": "moment",
329338          "version": "2.29.4",
329339          "licenses": [
329340            {
329341              "license": {
329342                "id": "MIT"
329343              }
329344            }
329345          ],
329346          "cpe": "cpe:2.3:a:moment:moment:2.29.4:*:*:*:*:*:*:*",
329347          "purl": "pkg:npm/moment@2.29.4",
329348          "swid": {
329349            "attachment": {}
329350          },
329351          "pedigree": {},
329352          "evidence": {},
329353          "signature": {
329354            "signature": {
329355              "publicKey": {}
329356            }
329357          },
329358          "modelCard": {
329359            "modelParameters": {
329360              "approach": {}
329361            },
329362            "quantitativeAnalysis": {
329363              "graphics": {}
329364            },
329365            "considerations": {}
329366          }
329367        },
329368        {
329369          "type": "library",
329370          "bom-ref": "pkg:npm/moment-timezone@0.5.31?package-id=36bb7eb6ae8ca03c",
329371          "supplier": {},
329372          "name": "moment-timezone",
329373          "version": "0.5.31",
329374          "licenses": [
329375            {
329376              "license": {
329377                "id": "MIT"
329378              }
329379            }
329380          ],
329381          "cpe": "cpe:2.3:a:moment-timezone:moment-timezone:0.5.31:*:*:*:*:*:*:*",
329382          "purl": "pkg:npm/moment-timezone@0.5.31",
329383          "swid": {
329384            "attachment": {}
329385          },
329386          "pedigree": {},
329387          "evidence": {},
329388          "signature": {
329389            "signature": {
329390              "publicKey": {}
329391            }
329392          },
329393          "modelCard": {
329394            "modelParameters": {
329395              "approach": {}
329396            },
329397            "quantitativeAnalysis": {
329398              "graphics": {}
329399            },
329400            "considerations": {}
329401          }
329402        },
329403        {
329404          "type": "library",
329405          "bom-ref": "pkg:npm/monaco-editor@0.17.1?package-id=5f86c0cbc5976c03",
329406          "supplier": {},
329407          "name": "monaco-editor",
329408          "version": "0.17.1",
329409          "licenses": [
329410            {
329411              "license": {
329412                "id": "MIT"
329413              }
329414            }
329415          ],
329416          "cpe": "cpe:2.3:a:monaco-editor:monaco-editor:0.17.1:*:*:*:*:*:*:*",
329417          "purl": "pkg:npm/monaco-editor@0.17.1",
329418          "swid": {
329419            "attachment": {}
329420          },
329421          "pedigree": {},
329422          "evidence": {},
329423          "signature": {
329424            "signature": {
329425              "publicKey": {}
329426            }
329427          },
329428          "modelCard": {
329429            "modelParameters": {
329430              "approach": {}
329431            },
329432            "quantitativeAnalysis": {
329433              "graphics": {}
329434            },
329435            "considerations": {}
329436          }
329437        },
329438        {
329439          "type": "library",
329440          "bom-ref": "pkg:npm/monaco-editor-webpack-plugin@1.9.1?package-id=72d7eeb8439ac76c",
329441          "supplier": {},
329442          "name": "monaco-editor-webpack-plugin",
329443          "version": "1.9.1",
329444          "licenses": [
329445            {
329446              "license": {
329447                "id": "MIT"
329448              }
329449            }
329450          ],
329451          "cpe": "cpe:2.3:a:monaco-editor-webpack-plugin:monaco-editor-webpack-plugin:1.9.1:*:*:*:*:*:*:*",
329452          "purl": "pkg:npm/monaco-editor-webpack-plugin@1.9.1",
329453          "swid": {
329454            "attachment": {}
329455          },
329456          "pedigree": {},
329457          "evidence": {},
329458          "signature": {
329459            "signature": {
329460              "publicKey": {}
329461            }
329462          },
329463          "modelCard": {
329464            "modelParameters": {
329465              "approach": {}
329466            },
329467            "quantitativeAnalysis": {
329468              "graphics": {}
329469            },
329470            "considerations": {}
329471          }
329472        },
329473        {
329474          "type": "library",
329475          "bom-ref": "pkg:npm/monaco-yaml@2.4.1?package-id=aec8422e10db7c9",
329476          "supplier": {},
329477          "name": "monaco-yaml",
329478          "version": "2.4.1",
329479          "licenses": [
329480            {
329481              "license": {
329482                "id": "MIT"
329483              }
329484            }
329485          ],
329486          "cpe": "cpe:2.3:a:monaco-yaml:monaco-yaml:2.4.1:*:*:*:*:*:*:*",
329487          "purl": "pkg:npm/monaco-yaml@2.4.1",
329488          "swid": {
329489            "attachment": {}
329490          },
329491          "pedigree": {},
329492          "evidence": {},
329493          "signature": {
329494            "signature": {
329495              "publicKey": {}
329496            }
329497          },
329498          "modelCard": {
329499            "modelParameters": {
329500              "approach": {}
329501            },
329502            "quantitativeAnalysis": {
329503              "graphics": {}
329504            },
329505            "considerations": {}
329506          }
329507        },
329508        {
329509          "type": "library",
329510          "bom-ref": "pkg:npm/move-concurrently@1.0.1?package-id=91aab6a1c52a589c",
329511          "supplier": {},
329512          "name": "move-concurrently",
329513          "version": "1.0.1",
329514          "licenses": [
329515            {
329516              "license": {
329517                "id": "ISC"
329518              }
329519            }
329520          ],
329521          "cpe": "cpe:2.3:a:move-concurrently:move-concurrently:1.0.1:*:*:*:*:*:*:*",
329522          "purl": "pkg:npm/move-concurrently@1.0.1",
329523          "swid": {
329524            "attachment": {}
329525          },
329526          "pedigree": {},
329527          "evidence": {},
329528          "signature": {
329529            "signature": {
329530              "publicKey": {}
329531            }
329532          },
329533          "modelCard": {
329534            "modelParameters": {
329535              "approach": {}
329536            },
329537            "quantitativeAnalysis": {
329538              "graphics": {}
329539            },
329540            "considerations": {}
329541          }
329542        },
329543        {
329544          "type": "library",
329545          "bom-ref": "pkg:npm/ms@2.1.2?package-id=1fe678a2cf218002",
329546          "supplier": {},
329547          "name": "ms",
329548          "version": "2.1.2",
329549          "cpe": "cpe:2.3:a:ms:ms:2.1.2:*:*:*:*:*:*:*",
329550          "purl": "pkg:npm/ms@2.1.2",
329551          "swid": {
329552            "attachment": {}
329553          },
329554          "pedigree": {},
329555          "evidence": {},
329556          "signature": {
329557            "signature": {
329558              "publicKey": {}
329559            }
329560          },
329561          "modelCard": {
329562            "modelParameters": {
329563              "approach": {}
329564            },
329565            "quantitativeAnalysis": {
329566              "graphics": {}
329567            },
329568            "considerations": {}
329569          }
329570        },
329571        {
329572          "type": "library",
329573          "bom-ref": "pkg:npm/ms@2.1.2?package-id=d4db9576c4da8b3f",
329574          "supplier": {},
329575          "name": "ms",
329576          "version": "2.1.2",
329577          "licenses": [
329578            {
329579              "license": {
329580                "id": "MIT"
329581              }
329582            }
329583          ],
329584          "cpe": "cpe:2.3:a:ms:ms:2.1.2:*:*:*:*:*:*:*",
329585          "purl": "pkg:npm/ms@2.1.2",
329586          "swid": {
329587            "attachment": {}
329588          },
329589          "pedigree": {},
329590          "evidence": {},
329591          "signature": {
329592            "signature": {
329593              "publicKey": {}
329594            }
329595          },
329596          "modelCard": {
329597            "modelParameters": {
329598              "approach": {}
329599            },
329600            "quantitativeAnalysis": {
329601              "graphics": {}
329602            },
329603            "considerations": {}
329604          }
329605        },
329606        {
329607          "type": "library",
329608          "bom-ref": "pkg:npm/multicast-dns@6.2.3?package-id=c8911e08631e93a5",
329609          "supplier": {},
329610          "name": "multicast-dns",
329611          "version": "6.2.3",
329612          "licenses": [
329613            {
329614              "license": {
329615                "id": "MIT"
329616              }
329617            }
329618          ],
329619          "cpe": "cpe:2.3:a:multicast-dns:multicast-dns:6.2.3:*:*:*:*:*:*:*",
329620          "purl": "pkg:npm/multicast-dns@6.2.3",
329621          "swid": {
329622            "attachment": {}
329623          },
329624          "pedigree": {},
329625          "evidence": {},
329626          "signature": {
329627            "signature": {
329628              "publicKey": {}
329629            }
329630          },
329631          "modelCard": {
329632            "modelParameters": {
329633              "approach": {}
329634            },
329635            "quantitativeAnalysis": {
329636              "graphics": {}
329637            },
329638            "considerations": {}
329639          }
329640        },
329641        {
329642          "type": "library",
329643          "bom-ref": "pkg:npm/multicast-dns-service-types@1.1.0?package-id=5b9518852354f54f",
329644          "supplier": {},
329645          "name": "multicast-dns-service-types",
329646          "version": "1.1.0",
329647          "licenses": [
329648            {
329649              "license": {
329650                "id": "MIT"
329651              }
329652            }
329653          ],
329654          "cpe": "cpe:2.3:a:multicast-dns-service-types:multicast-dns-service-types:1.1.0:*:*:*:*:*:*:*",
329655          "purl": "pkg:npm/multicast-dns-service-types@1.1.0",
329656          "swid": {
329657            "attachment": {}
329658          },
329659          "pedigree": {},
329660          "evidence": {},
329661          "signature": {
329662            "signature": {
329663              "publicKey": {}
329664            }
329665          },
329666          "modelCard": {
329667            "modelParameters": {
329668              "approach": {}
329669            },
329670            "quantitativeAnalysis": {
329671              "graphics": {}
329672            },
329673            "considerations": {}
329674          }
329675        },
329676        {
329677          "type": "library",
329678          "bom-ref": "pkg:npm/mutationobserver-shim@0.3.7?package-id=a8d9d4109de8b10e",
329679          "supplier": {},
329680          "name": "mutationobserver-shim",
329681          "version": "0.3.7",
329682          "licenses": [
329683            {
329684              "license": {
329685                "id": "MIT"
329686              }
329687            }
329688          ],
329689          "cpe": "cpe:2.3:a:mutationobserver-shim:mutationobserver-shim:0.3.7:*:*:*:*:*:*:*",
329690          "purl": "pkg:npm/mutationobserver-shim@0.3.7",
329691          "swid": {
329692            "attachment": {}
329693          },
329694          "pedigree": {},
329695          "evidence": {},
329696          "signature": {
329697            "signature": {
329698              "publicKey": {}
329699            }
329700          },
329701          "modelCard": {
329702            "modelParameters": {
329703              "approach": {}
329704            },
329705            "quantitativeAnalysis": {
329706              "graphics": {}
329707            },
329708            "considerations": {}
329709          }
329710        },
329711        {
329712          "type": "library",
329713          "bom-ref": "pkg:npm/mute-stream@0.0.8?package-id=230bc8ae18ec3049",
329714          "supplier": {},
329715          "name": "mute-stream",
329716          "version": "0.0.8",
329717          "licenses": [
329718            {
329719              "license": {
329720                "id": "ISC"
329721              }
329722            }
329723          ],
329724          "cpe": "cpe:2.3:a:mute-stream:mute-stream:0.0.8:*:*:*:*:*:*:*",
329725          "purl": "pkg:npm/mute-stream@0.0.8",
329726          "swid": {
329727            "attachment": {}
329728          },
329729          "pedigree": {},
329730          "evidence": {},
329731          "signature": {
329732            "signature": {
329733              "publicKey": {}
329734            }
329735          },
329736          "modelCard": {
329737            "modelParameters": {
329738              "approach": {}
329739            },
329740            "quantitativeAnalysis": {
329741              "graphics": {}
329742            },
329743            "considerations": {}
329744          }
329745        },
329746        {
329747          "type": "library",
329748          "bom-ref": "pkg:npm/mz@2.7.0?package-id=86237e547714020f",
329749          "supplier": {},
329750          "name": "mz",
329751          "version": "2.7.0",
329752          "licenses": [
329753            {
329754              "license": {
329755                "id": "MIT"
329756              }
329757            }
329758          ],
329759          "cpe": "cpe:2.3:a:mz:mz:2.7.0:*:*:*:*:*:*:*",
329760          "purl": "pkg:npm/mz@2.7.0",
329761          "swid": {
329762            "attachment": {}
329763          },
329764          "pedigree": {},
329765          "evidence": {},
329766          "signature": {
329767            "signature": {
329768              "publicKey": {}
329769            }
329770          },
329771          "modelCard": {
329772            "modelParameters": {
329773              "approach": {}
329774            },
329775            "quantitativeAnalysis": {
329776              "graphics": {}
329777            },
329778            "considerations": {}
329779          }
329780        },
329781        {
329782          "type": "library",
329783          "bom-ref": "pkg:npm/nan@2.14.0?package-id=7ee02793c83db419",
329784          "supplier": {},
329785          "name": "nan",
329786          "version": "2.14.0",
329787          "licenses": [
329788            {
329789              "license": {
329790                "id": "MIT"
329791              }
329792            }
329793          ],
329794          "cpe": "cpe:2.3:a:nan:nan:2.14.0:*:*:*:*:*:*:*",
329795          "purl": "pkg:npm/nan@2.14.0",
329796          "swid": {
329797            "attachment": {}
329798          },
329799          "pedigree": {},
329800          "evidence": {},
329801          "signature": {
329802            "signature": {
329803              "publicKey": {}
329804            }
329805          },
329806          "modelCard": {
329807            "modelParameters": {
329808              "approach": {}
329809            },
329810            "quantitativeAnalysis": {
329811              "graphics": {}
329812            },
329813            "considerations": {}
329814          }
329815        },
329816        {
329817          "type": "library",
329818          "bom-ref": "pkg:npm/nanomatch@1.2.13?package-id=9bf9e8048dbb257f",
329819          "supplier": {},
329820          "name": "nanomatch",
329821          "version": "1.2.13",
329822          "licenses": [
329823            {
329824              "license": {
329825                "id": "MIT"
329826              }
329827            }
329828          ],
329829          "cpe": "cpe:2.3:a:nanomatch:nanomatch:1.2.13:*:*:*:*:*:*:*",
329830          "purl": "pkg:npm/nanomatch@1.2.13",
329831          "swid": {
329832            "attachment": {}
329833          },
329834          "pedigree": {},
329835          "evidence": {},
329836          "signature": {
329837            "signature": {
329838              "publicKey": {}
329839            }
329840          },
329841          "modelCard": {
329842            "modelParameters": {
329843              "approach": {}
329844            },
329845            "quantitativeAnalysis": {
329846              "graphics": {}
329847            },
329848            "considerations": {}
329849          }
329850        },
329851        {
329852          "type": "library",
329853          "bom-ref": "pkg:npm/negotiator@0.6.2?package-id=a20c54adaf57fd29",
329854          "supplier": {},
329855          "name": "negotiator",
329856          "version": "0.6.2",
329857          "licenses": [
329858            {
329859              "license": {
329860                "id": "MIT"
329861              }
329862            }
329863          ],
329864          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.2:*:*:*:*:*:*:*",
329865          "purl": "pkg:npm/negotiator@0.6.2",
329866          "swid": {
329867            "attachment": {}
329868          },
329869          "pedigree": {},
329870          "evidence": {},
329871          "signature": {
329872            "signature": {
329873              "publicKey": {}
329874            }
329875          },
329876          "modelCard": {
329877            "modelParameters": {
329878              "approach": {}
329879            },
329880            "quantitativeAnalysis": {
329881              "graphics": {}
329882            },
329883            "considerations": {}
329884          }
329885        },
329886        {
329887          "type": "library",
329888          "bom-ref": "pkg:npm/neo-async@2.6.1?package-id=73e73df2a810fbb7",
329889          "supplier": {},
329890          "name": "neo-async",
329891          "version": "2.6.1",
329892          "licenses": [
329893            {
329894              "license": {
329895                "id": "MIT"
329896              }
329897            }
329898          ],
329899          "cpe": "cpe:2.3:a:neo-async:neo-async:2.6.1:*:*:*:*:*:*:*",
329900          "purl": "pkg:npm/neo-async@2.6.1",
329901          "swid": {
329902            "attachment": {}
329903          },
329904          "pedigree": {},
329905          "evidence": {},
329906          "signature": {
329907            "signature": {
329908              "publicKey": {}
329909            }
329910          },
329911          "modelCard": {
329912            "modelParameters": {
329913              "approach": {}
329914            },
329915            "quantitativeAnalysis": {
329916              "graphics": {}
329917            },
329918            "considerations": {}
329919          }
329920        },
329921        {
329922          "type": "library",
329923          "bom-ref": "pkg:npm/next-tick@1.0.0?package-id=355dcda553672f5e",
329924          "supplier": {},
329925          "name": "next-tick",
329926          "version": "1.0.0",
329927          "licenses": [
329928            {
329929              "license": {
329930                "id": "MIT"
329931              }
329932            }
329933          ],
329934          "cpe": "cpe:2.3:a:next-tick:next-tick:1.0.0:*:*:*:*:*:*:*",
329935          "purl": "pkg:npm/next-tick@1.0.0",
329936          "swid": {
329937            "attachment": {}
329938          },
329939          "pedigree": {},
329940          "evidence": {},
329941          "signature": {
329942            "signature": {
329943              "publicKey": {}
329944            }
329945          },
329946          "modelCard": {
329947            "modelParameters": {
329948              "approach": {}
329949            },
329950            "quantitativeAnalysis": {
329951              "graphics": {}
329952            },
329953            "considerations": {}
329954          }
329955        },
329956        {
329957          "type": "library",
329958          "bom-ref": "pkg:npm/ng-table-virtual-scroll@1.3.5?package-id=682f8addcd3bf45a",
329959          "supplier": {},
329960          "name": "ng-table-virtual-scroll",
329961          "version": "1.3.5",
329962          "licenses": [
329963            {
329964              "license": {
329965                "id": "MIT"
329966              }
329967            }
329968          ],
329969          "cpe": "cpe:2.3:a:ng-table-virtual-scroll:ng-table-virtual-scroll:1.3.5:*:*:*:*:*:*:*",
329970          "purl": "pkg:npm/ng-table-virtual-scroll@1.3.5",
329971          "swid": {
329972            "attachment": {}
329973          },
329974          "pedigree": {},
329975          "evidence": {},
329976          "signature": {
329977            "signature": {
329978              "publicKey": {}
329979            }
329980          },
329981          "modelCard": {
329982            "modelParameters": {
329983              "approach": {}
329984            },
329985            "quantitativeAnalysis": {
329986              "graphics": {}
329987            },
329988            "considerations": {}
329989          }
329990        },
329991        {
329992          "type": "library",
329993          "bom-ref": "pkg:npm/ngx-clipboard@12.3.1?package-id=d4b766a1055c4a66",
329994          "supplier": {},
329995          "name": "ngx-clipboard",
329996          "version": "12.3.1",
329997          "licenses": [
329998            {
329999              "license": {
330000                "id": "MIT"
330001              }
330002            }
330003          ],
330004          "cpe": "cpe:2.3:a:ngx-clipboard:ngx-clipboard:12.3.1:*:*:*:*:*:*:*",
330005          "purl": "pkg:npm/ngx-clipboard@12.3.1",
330006          "swid": {
330007            "attachment": {}
330008          },
330009          "pedigree": {},
330010          "evidence": {},
330011          "signature": {
330012            "signature": {
330013              "publicKey": {}
330014            }
330015          },
330016          "modelCard": {
330017            "modelParameters": {
330018              "approach": {}
330019            },
330020            "quantitativeAnalysis": {
330021              "graphics": {}
330022            },
330023            "considerations": {}
330024          }
330025        },
330026        {
330027          "type": "library",
330028          "bom-ref": "pkg:npm/ngx-color-picker@9.0.0?package-id=1d9a53d19729380b",
330029          "supplier": {},
330030          "name": "ngx-color-picker",
330031          "version": "9.0.0",
330032          "licenses": [
330033            {
330034              "license": {
330035                "id": "MIT"
330036              }
330037            }
330038          ],
330039          "cpe": "cpe:2.3:a:ngx-color-picker:ngx-color-picker:9.0.0:*:*:*:*:*:*:*",
330040          "purl": "pkg:npm/ngx-color-picker@9.0.0",
330041          "swid": {
330042            "attachment": {}
330043          },
330044          "pedigree": {},
330045          "evidence": {},
330046          "signature": {
330047            "signature": {
330048              "publicKey": {}
330049            }
330050          },
330051          "modelCard": {
330052            "modelParameters": {
330053              "approach": {}
330054            },
330055            "quantitativeAnalysis": {
330056              "graphics": {}
330057            },
330058            "considerations": {}
330059          }
330060        },
330061        {
330062          "type": "library",
330063          "bom-ref": "pkg:npm/ngx-infinite-scroll@9.0.0?package-id=9be67accd97c49cd",
330064          "supplier": {},
330065          "name": "ngx-infinite-scroll",
330066          "version": "9.0.0",
330067          "licenses": [
330068            {
330069              "license": {
330070                "id": "MIT"
330071              }
330072            }
330073          ],
330074          "cpe": "cpe:2.3:a:ngx-infinite-scroll:ngx-infinite-scroll:9.0.0:*:*:*:*:*:*:*",
330075          "purl": "pkg:npm/ngx-infinite-scroll@9.0.0",
330076          "swid": {
330077            "attachment": {}
330078          },
330079          "pedigree": {},
330080          "evidence": {},
330081          "signature": {
330082            "signature": {
330083              "publicKey": {}
330084            }
330085          },
330086          "modelCard": {
330087            "modelParameters": {
330088              "approach": {}
330089            },
330090            "quantitativeAnalysis": {
330091              "graphics": {}
330092            },
330093            "considerations": {}
330094          }
330095        },
330096        {
330097          "type": "library",
330098          "bom-ref": "pkg:npm/ngx-json-viewer@2.4.0?package-id=4b0a64dbd5fda21",
330099          "supplier": {},
330100          "name": "ngx-json-viewer",
330101          "version": "2.4.0",
330102          "licenses": [
330103            {
330104              "license": {
330105                "id": "MIT"
330106              }
330107            }
330108          ],
330109          "cpe": "cpe:2.3:a:ngx-json-viewer:ngx-json-viewer:2.4.0:*:*:*:*:*:*:*",
330110          "purl": "pkg:npm/ngx-json-viewer@2.4.0",
330111          "swid": {
330112            "attachment": {}
330113          },
330114          "pedigree": {},
330115          "evidence": {},
330116          "signature": {
330117            "signature": {
330118              "publicKey": {}
330119            }
330120          },
330121          "modelCard": {
330122            "modelParameters": {
330123              "approach": {}
330124            },
330125            "quantitativeAnalysis": {
330126              "graphics": {}
330127            },
330128            "considerations": {}
330129          }
330130        },
330131        {
330132          "type": "library",
330133          "bom-ref": "pkg:npm/ngx-moment@3.5.0?package-id=8c5f9e7e8506e9df",
330134          "supplier": {},
330135          "name": "ngx-moment",
330136          "version": "3.5.0",
330137          "licenses": [
330138            {
330139              "license": {
330140                "id": "MIT"
330141              }
330142            }
330143          ],
330144          "cpe": "cpe:2.3:a:ngx-moment:ngx-moment:3.5.0:*:*:*:*:*:*:*",
330145          "purl": "pkg:npm/ngx-moment@3.5.0",
330146          "swid": {
330147            "attachment": {}
330148          },
330149          "pedigree": {},
330150          "evidence": {},
330151          "signature": {
330152            "signature": {
330153              "publicKey": {}
330154            }
330155          },
330156          "modelCard": {
330157            "modelParameters": {
330158              "approach": {}
330159            },
330160            "quantitativeAnalysis": {
330161              "graphics": {}
330162            },
330163            "considerations": {}
330164          }
330165        },
330166        {
330167          "type": "library",
330168          "bom-ref": "pkg:npm/ngx-toastr@12.0.0?package-id=a8b8c3a1f0fe3f2f",
330169          "supplier": {},
330170          "name": "ngx-toastr",
330171          "version": "12.0.0",
330172          "licenses": [
330173            {
330174              "license": {
330175                "id": "MIT"
330176              }
330177            }
330178          ],
330179          "cpe": "cpe:2.3:a:ngx-toastr:ngx-toastr:12.0.0:*:*:*:*:*:*:*",
330180          "purl": "pkg:npm/ngx-toastr@12.0.0",
330181          "swid": {
330182            "attachment": {}
330183          },
330184          "pedigree": {},
330185          "evidence": {},
330186          "signature": {
330187            "signature": {
330188              "publicKey": {}
330189            }
330190          },
330191          "modelCard": {
330192            "modelParameters": {
330193              "approach": {}
330194            },
330195            "quantitativeAnalysis": {
330196              "graphics": {}
330197            },
330198            "considerations": {}
330199          }
330200        },
330201        {
330202          "type": "library",
330203          "bom-ref": "pkg:npm/ngx-translate-messageformat-compiler@4.6.0?package-id=f50acdc845b59e6d",
330204          "supplier": {},
330205          "name": "ngx-translate-messageformat-compiler",
330206          "version": "4.6.0",
330207          "licenses": [
330208            {
330209              "license": {
330210                "id": "MIT"
330211              }
330212            }
330213          ],
330214          "cpe": "cpe:2.3:a:ngx-translate-messageformat-compiler:ngx-translate-messageformat-compiler:4.6.0:*:*:*:*:*:*:*",
330215          "purl": "pkg:npm/ngx-translate-messageformat-compiler@4.6.0",
330216          "swid": {
330217            "attachment": {}
330218          },
330219          "pedigree": {},
330220          "evidence": {},
330221          "signature": {
330222            "signature": {
330223              "publicKey": {}
330224            }
330225          },
330226          "modelCard": {
330227            "modelParameters": {
330228              "approach": {}
330229            },
330230            "quantitativeAnalysis": {
330231              "graphics": {}
330232            },
330233            "considerations": {}
330234          }
330235        },
330236        {
330237          "type": "library",
330238          "bom-ref": "pkg:npm/ngx-window-token@2.0.1?package-id=3e622697f4c22b9",
330239          "supplier": {},
330240          "name": "ngx-window-token",
330241          "version": "2.0.1",
330242          "licenses": [
330243            {
330244              "license": {
330245                "id": "MIT"
330246              }
330247            }
330248          ],
330249          "cpe": "cpe:2.3:a:ngx-window-token:ngx-window-token:2.0.1:*:*:*:*:*:*:*",
330250          "purl": "pkg:npm/ngx-window-token@2.0.1",
330251          "swid": {
330252            "attachment": {}
330253          },
330254          "pedigree": {},
330255          "evidence": {},
330256          "signature": {
330257            "signature": {
330258              "publicKey": {}
330259            }
330260          },
330261          "modelCard": {
330262            "modelParameters": {
330263              "approach": {}
330264            },
330265            "quantitativeAnalysis": {
330266              "graphics": {}
330267            },
330268            "considerations": {}
330269          }
330270        },
330271        {
330272          "type": "library",
330273          "bom-ref": "pkg:npm/nice-try@1.0.5?package-id=ff7bfcc027d13c4b",
330274          "supplier": {},
330275          "name": "nice-try",
330276          "version": "1.0.5",
330277          "cpe": "cpe:2.3:a:nice-try:nice-try:1.0.5:*:*:*:*:*:*:*",
330278          "purl": "pkg:npm/nice-try@1.0.5",
330279          "swid": {
330280            "attachment": {}
330281          },
330282          "pedigree": {},
330283          "evidence": {},
330284          "signature": {
330285            "signature": {
330286              "publicKey": {}
330287            }
330288          },
330289          "modelCard": {
330290            "modelParameters": {
330291              "approach": {}
330292            },
330293            "quantitativeAnalysis": {
330294              "graphics": {}
330295            },
330296            "considerations": {}
330297          }
330298        },
330299        {
330300          "type": "library",
330301          "bom-ref": "pkg:npm/nice-try@1.0.5?package-id=5471e73f8a2a771e",
330302          "supplier": {},
330303          "name": "nice-try",
330304          "version": "1.0.5",
330305          "licenses": [
330306            {
330307              "license": {
330308                "id": "MIT"
330309              }
330310            }
330311          ],
330312          "cpe": "cpe:2.3:a:nice-try:nice-try:1.0.5:*:*:*:*:*:*:*",
330313          "purl": "pkg:npm/nice-try@1.0.5",
330314          "swid": {
330315            "attachment": {}
330316          },
330317          "pedigree": {},
330318          "evidence": {},
330319          "signature": {
330320            "signature": {
330321              "publicKey": {}
330322            }
330323          },
330324          "modelCard": {
330325            "modelParameters": {
330326              "approach": {}
330327            },
330328            "quantitativeAnalysis": {
330329              "graphics": {}
330330            },
330331            "considerations": {}
330332          }
330333        },
330334        {
330335          "type": "library",
330336          "bom-ref": "pkg:npm/node-fetch-npm@2.0.4?package-id=201ea80691a31b76",
330337          "supplier": {},
330338          "name": "node-fetch-npm",
330339          "version": "2.0.4",
330340          "licenses": [
330341            {
330342              "license": {
330343                "id": "MIT"
330344              }
330345            }
330346          ],
330347          "cpe": "cpe:2.3:a:node-fetch-npm:node-fetch-npm:2.0.4:*:*:*:*:*:*:*",
330348          "purl": "pkg:npm/node-fetch-npm@2.0.4",
330349          "swid": {
330350            "attachment": {}
330351          },
330352          "pedigree": {},
330353          "evidence": {},
330354          "signature": {
330355            "signature": {
330356              "publicKey": {}
330357            }
330358          },
330359          "modelCard": {
330360            "modelParameters": {
330361              "approach": {}
330362            },
330363            "quantitativeAnalysis": {
330364              "graphics": {}
330365            },
330366            "considerations": {}
330367          }
330368        },
330369        {
330370          "type": "library",
330371          "bom-ref": "pkg:npm/node-forge@0.9.0?package-id=8348f60849f936f4",
330372          "supplier": {},
330373          "name": "node-forge",
330374          "version": "0.9.0",
330375          "licenses": [
330376            {
330377              "license": {
330378                "name": "(BSD-3-Clause OR GPL-2.0)"
330379              }
330380            }
330381          ],
330382          "cpe": "cpe:2.3:a:node-forge:node-forge:0.9.0:*:*:*:*:*:*:*",
330383          "purl": "pkg:npm/node-forge@0.9.0",
330384          "swid": {
330385            "attachment": {}
330386          },
330387          "pedigree": {},
330388          "evidence": {},
330389          "signature": {
330390            "signature": {
330391              "publicKey": {}
330392            }
330393          },
330394          "modelCard": {
330395            "modelParameters": {
330396              "approach": {}
330397            },
330398            "quantitativeAnalysis": {
330399              "graphics": {}
330400            },
330401            "considerations": {}
330402          }
330403        },
330404        {
330405          "type": "library",
330406          "bom-ref": "pkg:npm/node-gyp@3.8.0?package-id=9ac9a76e4c586aeb",
330407          "supplier": {},
330408          "name": "node-gyp",
330409          "version": "3.8.0",
330410          "licenses": [
330411            {
330412              "license": {
330413                "id": "MIT"
330414              }
330415            }
330416          ],
330417          "cpe": "cpe:2.3:a:node-gyp:node-gyp:3.8.0:*:*:*:*:*:*:*",
330418          "purl": "pkg:npm/node-gyp@3.8.0",
330419          "swid": {
330420            "attachment": {}
330421          },
330422          "pedigree": {},
330423          "evidence": {},
330424          "signature": {
330425            "signature": {
330426              "publicKey": {}
330427            }
330428          },
330429          "modelCard": {
330430            "modelParameters": {
330431              "approach": {}
330432            },
330433            "quantitativeAnalysis": {
330434              "graphics": {}
330435            },
330436            "considerations": {}
330437          }
330438        },
330439        {
330440          "type": "library",
330441          "bom-ref": "pkg:npm/node-libs-browser@2.2.1?package-id=9ac758a83a8ee74b",
330442          "supplier": {},
330443          "name": "node-libs-browser",
330444          "version": "2.2.1",
330445          "licenses": [
330446            {
330447              "license": {
330448                "id": "MIT"
330449              }
330450            }
330451          ],
330452          "cpe": "cpe:2.3:a:node-libs-browser:node-libs-browser:2.2.1:*:*:*:*:*:*:*",
330453          "purl": "pkg:npm/node-libs-browser@2.2.1",
330454          "swid": {
330455            "attachment": {}
330456          },
330457          "pedigree": {},
330458          "evidence": {},
330459          "signature": {
330460            "signature": {
330461              "publicKey": {}
330462            }
330463          },
330464          "modelCard": {
330465            "modelParameters": {
330466              "approach": {}
330467            },
330468            "quantitativeAnalysis": {
330469              "graphics": {}
330470            },
330471            "considerations": {}
330472          }
330473        },
330474        {
330475          "type": "library",
330476          "bom-ref": "pkg:npm/node-preload@0.2.1?package-id=b3c94ad6812671fe",
330477          "supplier": {},
330478          "name": "node-preload",
330479          "version": "0.2.1",
330480          "cpe": "cpe:2.3:a:node-preload:node-preload:0.2.1:*:*:*:*:*:*:*",
330481          "purl": "pkg:npm/node-preload@0.2.1",
330482          "swid": {
330483            "attachment": {}
330484          },
330485          "pedigree": {},
330486          "evidence": {},
330487          "signature": {
330488            "signature": {
330489              "publicKey": {}
330490            }
330491          },
330492          "modelCard": {
330493            "modelParameters": {
330494              "approach": {}
330495            },
330496            "quantitativeAnalysis": {
330497              "graphics": {}
330498            },
330499            "considerations": {}
330500          }
330501        },
330502        {
330503          "type": "library",
330504          "bom-ref": "pkg:npm/node-releases@1.1.55?package-id=2b79507dd448b67e",
330505          "supplier": {},
330506          "name": "node-releases",
330507          "version": "1.1.55",
330508          "licenses": [
330509            {
330510              "license": {
330511                "id": "MIT"
330512              }
330513            }
330514          ],
330515          "cpe": "cpe:2.3:a:node-releases:node-releases:1.1.55:*:*:*:*:*:*:*",
330516          "purl": "pkg:npm/node-releases@1.1.55",
330517          "swid": {
330518            "attachment": {}
330519          },
330520          "pedigree": {},
330521          "evidence": {},
330522          "signature": {
330523            "signature": {
330524              "publicKey": {}
330525            }
330526          },
330527          "modelCard": {
330528            "modelParameters": {
330529              "approach": {}
330530            },
330531            "quantitativeAnalysis": {
330532              "graphics": {}
330533            },
330534            "considerations": {}
330535          }
330536        },
330537        {
330538          "type": "library",
330539          "bom-ref": "pkg:npm/node-releases@2.0.1?package-id=f3118a50b9b9e3bb",
330540          "supplier": {},
330541          "name": "node-releases",
330542          "version": "2.0.1",
330543          "cpe": "cpe:2.3:a:node-releases:node-releases:2.0.1:*:*:*:*:*:*:*",
330544          "purl": "pkg:npm/node-releases@2.0.1",
330545          "swid": {
330546            "attachment": {}
330547          },
330548          "pedigree": {},
330549          "evidence": {},
330550          "signature": {
330551            "signature": {
330552              "publicKey": {}
330553            }
330554          },
330555          "modelCard": {
330556            "modelParameters": {
330557              "approach": {}
330558            },
330559            "quantitativeAnalysis": {
330560              "graphics": {}
330561            },
330562            "considerations": {}
330563          }
330564        },
330565        {
330566          "type": "library",
330567          "bom-ref": "pkg:npm/node-sass@4.14.1?package-id=175e686cc9a898f9",
330568          "supplier": {},
330569          "name": "node-sass",
330570          "version": "4.14.1",
330571          "licenses": [
330572            {
330573              "license": {
330574                "id": "MIT"
330575              }
330576            }
330577          ],
330578          "cpe": "cpe:2.3:a:node-sass:node-sass:4.14.1:*:*:*:*:*:*:*",
330579          "purl": "pkg:npm/node-sass@4.14.1",
330580          "swid": {
330581            "attachment": {}
330582          },
330583          "pedigree": {},
330584          "evidence": {},
330585          "signature": {
330586            "signature": {
330587              "publicKey": {}
330588            }
330589          },
330590          "modelCard": {
330591            "modelParameters": {
330592              "approach": {}
330593            },
330594            "quantitativeAnalysis": {
330595              "graphics": {}
330596            },
330597            "considerations": {}
330598          }
330599        },
330600        {
330601          "type": "library",
330602          "bom-ref": "pkg:npm/node-sass-tilde-importer@1.0.2?package-id=8b7d9e8e52ccf606",
330603          "supplier": {},
330604          "name": "node-sass-tilde-importer",
330605          "version": "1.0.2",
330606          "licenses": [
330607            {
330608              "license": {
330609                "id": "Apache-2.0"
330610              }
330611            }
330612          ],
330613          "cpe": "cpe:2.3:a:node-sass-tilde-importer:node-sass-tilde-importer:1.0.2:*:*:*:*:*:*:*",
330614          "purl": "pkg:npm/node-sass-tilde-importer@1.0.2",
330615          "swid": {
330616            "attachment": {}
330617          },
330618          "pedigree": {},
330619          "evidence": {},
330620          "signature": {
330621            "signature": {
330622              "publicKey": {}
330623            }
330624          },
330625          "modelCard": {
330626            "modelParameters": {
330627              "approach": {}
330628            },
330629            "quantitativeAnalysis": {
330630              "graphics": {}
330631            },
330632            "considerations": {}
330633          }
330634        },
330635        {
330636          "type": "library",
330637          "bom-ref": "pkg:npm/nopt@3.0.6?package-id=b76541de1284e7c9",
330638          "supplier": {},
330639          "name": "nopt",
330640          "version": "3.0.6",
330641          "licenses": [
330642            {
330643              "license": {
330644                "id": "ISC"
330645              }
330646            }
330647          ],
330648          "cpe": "cpe:2.3:a:nopt:nopt:3.0.6:*:*:*:*:*:*:*",
330649          "purl": "pkg:npm/nopt@3.0.6",
330650          "swid": {
330651            "attachment": {}
330652          },
330653          "pedigree": {},
330654          "evidence": {},
330655          "signature": {
330656            "signature": {
330657              "publicKey": {}
330658            }
330659          },
330660          "modelCard": {
330661            "modelParameters": {
330662              "approach": {}
330663            },
330664            "quantitativeAnalysis": {
330665              "graphics": {}
330666            },
330667            "considerations": {}
330668          }
330669        },
330670        {
330671          "type": "library",
330672          "bom-ref": "pkg:npm/normalize-package-data@2.5.0?package-id=8a1d44a0d0c7b3aa",
330673          "supplier": {},
330674          "name": "normalize-package-data",
330675          "version": "2.5.0",
330676          "licenses": [
330677            {
330678              "license": {
330679                "id": "BSD-2-Clause"
330680              }
330681            }
330682          ],
330683          "cpe": "cpe:2.3:a:normalize-package-data:normalize-package-data:2.5.0:*:*:*:*:*:*:*",
330684          "purl": "pkg:npm/normalize-package-data@2.5.0",
330685          "swid": {
330686            "attachment": {}
330687          },
330688          "pedigree": {},
330689          "evidence": {},
330690          "signature": {
330691            "signature": {
330692              "publicKey": {}
330693            }
330694          },
330695          "modelCard": {
330696            "modelParameters": {
330697              "approach": {}
330698            },
330699            "quantitativeAnalysis": {
330700              "graphics": {}
330701            },
330702            "considerations": {}
330703          }
330704        },
330705        {
330706          "type": "library",
330707          "bom-ref": "pkg:npm/normalize-path@3.0.0?package-id=f19edc9ce3987dc0",
330708          "supplier": {},
330709          "name": "normalize-path",
330710          "version": "3.0.0",
330711          "licenses": [
330712            {
330713              "license": {
330714                "id": "MIT"
330715              }
330716            }
330717          ],
330718          "cpe": "cpe:2.3:a:normalize-path:normalize-path:3.0.0:*:*:*:*:*:*:*",
330719          "purl": "pkg:npm/normalize-path@3.0.0",
330720          "swid": {
330721            "attachment": {}
330722          },
330723          "pedigree": {},
330724          "evidence": {},
330725          "signature": {
330726            "signature": {
330727              "publicKey": {}
330728            }
330729          },
330730          "modelCard": {
330731            "modelParameters": {
330732              "approach": {}
330733            },
330734            "quantitativeAnalysis": {
330735              "graphics": {}
330736            },
330737            "considerations": {}
330738          }
330739        },
330740        {
330741          "type": "library",
330742          "bom-ref": "pkg:npm/normalize-range@0.1.2?package-id=26d707dcfcfae96f",
330743          "supplier": {},
330744          "name": "normalize-range",
330745          "version": "0.1.2",
330746          "licenses": [
330747            {
330748              "license": {
330749                "id": "MIT"
330750              }
330751            }
330752          ],
330753          "cpe": "cpe:2.3:a:normalize-range:normalize-range:0.1.2:*:*:*:*:*:*:*",
330754          "purl": "pkg:npm/normalize-range@0.1.2",
330755          "swid": {
330756            "attachment": {}
330757          },
330758          "pedigree": {},
330759          "evidence": {},
330760          "signature": {
330761            "signature": {
330762              "publicKey": {}
330763            }
330764          },
330765          "modelCard": {
330766            "modelParameters": {
330767              "approach": {}
330768            },
330769            "quantitativeAnalysis": {
330770              "graphics": {}
330771            },
330772            "considerations": {}
330773          }
330774        },
330775        {
330776          "type": "library",
330777          "bom-ref": "pkg:npm/normalize-url@3.3.0?package-id=286b50f7a270f3ff",
330778          "supplier": {},
330779          "name": "normalize-url",
330780          "version": "3.3.0",
330781          "licenses": [
330782            {
330783              "license": {
330784                "id": "MIT"
330785              }
330786            }
330787          ],
330788          "cpe": "cpe:2.3:a:normalize-url:normalize-url:3.3.0:*:*:*:*:*:*:*",
330789          "purl": "pkg:npm/normalize-url@3.3.0",
330790          "swid": {
330791            "attachment": {}
330792          },
330793          "pedigree": {},
330794          "evidence": {},
330795          "signature": {
330796            "signature": {
330797              "publicKey": {}
330798            }
330799          },
330800          "modelCard": {
330801            "modelParameters": {
330802              "approach": {}
330803            },
330804            "quantitativeAnalysis": {
330805              "graphics": {}
330806            },
330807            "considerations": {}
330808          }
330809        },
330810        {
330811          "type": "library",
330812          "bom-ref": "pkg:npm/npm-bundled@1.1.1?package-id=ec675f588ad2775f",
330813          "supplier": {},
330814          "name": "npm-bundled",
330815          "version": "1.1.1",
330816          "licenses": [
330817            {
330818              "license": {
330819                "id": "ISC"
330820              }
330821            }
330822          ],
330823          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:1.1.1:*:*:*:*:*:*:*",
330824          "purl": "pkg:npm/npm-bundled@1.1.1",
330825          "swid": {
330826            "attachment": {}
330827          },
330828          "pedigree": {},
330829          "evidence": {},
330830          "signature": {
330831            "signature": {
330832              "publicKey": {}
330833            }
330834          },
330835          "modelCard": {
330836            "modelParameters": {
330837              "approach": {}
330838            },
330839            "quantitativeAnalysis": {
330840              "graphics": {}
330841            },
330842            "considerations": {}
330843          }
330844        },
330845        {
330846          "type": "library",
330847          "bom-ref": "pkg:npm/npm-install-checks@4.0.0?package-id=4cbc06560a9bd399",
330848          "supplier": {},
330849          "name": "npm-install-checks",
330850          "version": "4.0.0",
330851          "licenses": [
330852            {
330853              "license": {
330854                "id": "BSD-2-Clause"
330855              }
330856            }
330857          ],
330858          "cpe": "cpe:2.3:a:npm-install-checks:npm-install-checks:4.0.0:*:*:*:*:*:*:*",
330859          "purl": "pkg:npm/npm-install-checks@4.0.0",
330860          "swid": {
330861            "attachment": {}
330862          },
330863          "pedigree": {},
330864          "evidence": {},
330865          "signature": {
330866            "signature": {
330867              "publicKey": {}
330868            }
330869          },
330870          "modelCard": {
330871            "modelParameters": {
330872              "approach": {}
330873            },
330874            "quantitativeAnalysis": {
330875              "graphics": {}
330876            },
330877            "considerations": {}
330878          }
330879        },
330880        {
330881          "type": "library",
330882          "bom-ref": "pkg:npm/npm-normalize-package-bin@1.0.1?package-id=6ca14d45fb962159",
330883          "supplier": {},
330884          "name": "npm-normalize-package-bin",
330885          "version": "1.0.1",
330886          "licenses": [
330887            {
330888              "license": {
330889                "id": "ISC"
330890              }
330891            }
330892          ],
330893          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:1.0.1:*:*:*:*:*:*:*",
330894          "purl": "pkg:npm/npm-normalize-package-bin@1.0.1",
330895          "swid": {
330896            "attachment": {}
330897          },
330898          "pedigree": {},
330899          "evidence": {},
330900          "signature": {
330901            "signature": {
330902              "publicKey": {}
330903            }
330904          },
330905          "modelCard": {
330906            "modelParameters": {
330907              "approach": {}
330908            },
330909            "quantitativeAnalysis": {
330910              "graphics": {}
330911            },
330912            "considerations": {}
330913          }
330914        },
330915        {
330916          "type": "library",
330917          "bom-ref": "pkg:npm/npm-package-arg@8.0.1?package-id=2230c36d68a29478",
330918          "supplier": {},
330919          "name": "npm-package-arg",
330920          "version": "8.0.1",
330921          "licenses": [
330922            {
330923              "license": {
330924                "id": "ISC"
330925              }
330926            }
330927          ],
330928          "cpe": "cpe:2.3:a:npm-package-arg:npm-package-arg:8.0.1:*:*:*:*:*:*:*",
330929          "purl": "pkg:npm/npm-package-arg@8.0.1",
330930          "swid": {
330931            "attachment": {}
330932          },
330933          "pedigree": {},
330934          "evidence": {},
330935          "signature": {
330936            "signature": {
330937              "publicKey": {}
330938            }
330939          },
330940          "modelCard": {
330941            "modelParameters": {
330942              "approach": {}
330943            },
330944            "quantitativeAnalysis": {
330945              "graphics": {}
330946            },
330947            "considerations": {}
330948          }
330949        },
330950        {
330951          "type": "library",
330952          "bom-ref": "pkg:npm/npm-packlist@1.4.8?package-id=10dbede298814310",
330953          "supplier": {},
330954          "name": "npm-packlist",
330955          "version": "1.4.8",
330956          "licenses": [
330957            {
330958              "license": {
330959                "id": "ISC"
330960              }
330961            }
330962          ],
330963          "cpe": "cpe:2.3:a:npm-packlist:npm-packlist:1.4.8:*:*:*:*:*:*:*",
330964          "purl": "pkg:npm/npm-packlist@1.4.8",
330965          "swid": {
330966            "attachment": {}
330967          },
330968          "pedigree": {},
330969          "evidence": {},
330970          "signature": {
330971            "signature": {
330972              "publicKey": {}
330973            }
330974          },
330975          "modelCard": {
330976            "modelParameters": {
330977              "approach": {}
330978            },
330979            "quantitativeAnalysis": {
330980              "graphics": {}
330981            },
330982            "considerations": {}
330983          }
330984        },
330985        {
330986          "type": "library",
330987          "bom-ref": "pkg:npm/npm-pick-manifest@6.0.0?package-id=88d99ca50639259d",
330988          "supplier": {},
330989          "name": "npm-pick-manifest",
330990          "version": "6.0.0",
330991          "licenses": [
330992            {
330993              "license": {
330994                "id": "ISC"
330995              }
330996            }
330997          ],
330998          "cpe": "cpe:2.3:a:npm-pick-manifest:npm-pick-manifest:6.0.0:*:*:*:*:*:*:*",
330999          "purl": "pkg:npm/npm-pick-manifest@6.0.0",
331000          "swid": {
331001            "attachment": {}
331002          },
331003          "pedigree": {},
331004          "evidence": {},
331005          "signature": {
331006            "signature": {
331007              "publicKey": {}
331008            }
331009          },
331010          "modelCard": {
331011            "modelParameters": {
331012              "approach": {}
331013            },
331014            "quantitativeAnalysis": {
331015              "graphics": {}
331016            },
331017            "considerations": {}
331018          }
331019        },
331020        {
331021          "type": "library",
331022          "bom-ref": "pkg:npm/npm-registry-fetch@4.0.4?package-id=feaa429003f5ed54",
331023          "supplier": {},
331024          "name": "npm-registry-fetch",
331025          "version": "4.0.4",
331026          "licenses": [
331027            {
331028              "license": {
331029                "id": "ISC"
331030              }
331031            }
331032          ],
331033          "cpe": "cpe:2.3:a:npm-registry-fetch:npm-registry-fetch:4.0.4:*:*:*:*:*:*:*",
331034          "purl": "pkg:npm/npm-registry-fetch@4.0.4",
331035          "swid": {
331036            "attachment": {}
331037          },
331038          "pedigree": {},
331039          "evidence": {},
331040          "signature": {
331041            "signature": {
331042              "publicKey": {}
331043            }
331044          },
331045          "modelCard": {
331046            "modelParameters": {
331047              "approach": {}
331048            },
331049            "quantitativeAnalysis": {
331050              "graphics": {}
331051            },
331052            "considerations": {}
331053          }
331054        },
331055        {
331056          "type": "library",
331057          "bom-ref": "pkg:npm/npm-run-path@2.0.2?package-id=954bfc4210051a5c",
331058          "supplier": {},
331059          "name": "npm-run-path",
331060          "version": "2.0.2",
331061          "licenses": [
331062            {
331063              "license": {
331064                "id": "MIT"
331065              }
331066            }
331067          ],
331068          "cpe": "cpe:2.3:a:npm-run-path:npm-run-path:2.0.2:*:*:*:*:*:*:*",
331069          "purl": "pkg:npm/npm-run-path@2.0.2",
331070          "swid": {
331071            "attachment": {}
331072          },
331073          "pedigree": {},
331074          "evidence": {},
331075          "signature": {
331076            "signature": {
331077              "publicKey": {}
331078            }
331079          },
331080          "modelCard": {
331081            "modelParameters": {
331082              "approach": {}
331083            },
331084            "quantitativeAnalysis": {
331085              "graphics": {}
331086            },
331087            "considerations": {}
331088          }
331089        },
331090        {
331091          "type": "library",
331092          "bom-ref": "pkg:npm/npmlog@4.1.2?package-id=de2a40c813be8859",
331093          "supplier": {},
331094          "name": "npmlog",
331095          "version": "4.1.2",
331096          "licenses": [
331097            {
331098              "license": {
331099                "id": "ISC"
331100              }
331101            }
331102          ],
331103          "cpe": "cpe:2.3:a:npmlog:npmlog:4.1.2:*:*:*:*:*:*:*",
331104          "purl": "pkg:npm/npmlog@4.1.2",
331105          "swid": {
331106            "attachment": {}
331107          },
331108          "pedigree": {},
331109          "evidence": {},
331110          "signature": {
331111            "signature": {
331112              "publicKey": {}
331113            }
331114          },
331115          "modelCard": {
331116            "modelParameters": {
331117              "approach": {}
331118            },
331119            "quantitativeAnalysis": {
331120              "graphics": {}
331121            },
331122            "considerations": {}
331123          }
331124        },
331125        {
331126          "type": "library",
331127          "bom-ref": "pkg:npm/nth-check@1.0.2?package-id=492954811633dedb",
331128          "supplier": {},
331129          "name": "nth-check",
331130          "version": "1.0.2",
331131          "licenses": [
331132            {
331133              "license": {
331134                "id": "BSD-2-Clause"
331135              }
331136            }
331137          ],
331138          "cpe": "cpe:2.3:a:nth-check:nth-check:1.0.2:*:*:*:*:*:*:*",
331139          "purl": "pkg:npm/nth-check@1.0.2",
331140          "swid": {
331141            "attachment": {}
331142          },
331143          "pedigree": {},
331144          "evidence": {},
331145          "signature": {
331146            "signature": {
331147              "publicKey": {}
331148            }
331149          },
331150          "modelCard": {
331151            "modelParameters": {
331152              "approach": {}
331153            },
331154            "quantitativeAnalysis": {
331155              "graphics": {}
331156            },
331157            "considerations": {}
331158          }
331159        },
331160        {
331161          "type": "library",
331162          "bom-ref": "pkg:npm/num2fraction@1.2.2?package-id=ab62e338a560ceab",
331163          "supplier": {},
331164          "name": "num2fraction",
331165          "version": "1.2.2",
331166          "licenses": [
331167            {
331168              "license": {
331169                "id": "MIT"
331170              }
331171            }
331172          ],
331173          "cpe": "cpe:2.3:a:num2fraction:num2fraction:1.2.2:*:*:*:*:*:*:*",
331174          "purl": "pkg:npm/num2fraction@1.2.2",
331175          "swid": {
331176            "attachment": {}
331177          },
331178          "pedigree": {},
331179          "evidence": {},
331180          "signature": {
331181            "signature": {
331182              "publicKey": {}
331183            }
331184          },
331185          "modelCard": {
331186            "modelParameters": {
331187              "approach": {}
331188            },
331189            "quantitativeAnalysis": {
331190              "graphics": {}
331191            },
331192            "considerations": {}
331193          }
331194        },
331195        {
331196          "type": "library",
331197          "bom-ref": "pkg:npm/number-is-nan@1.0.1?package-id=98721ac55be8e513",
331198          "supplier": {},
331199          "name": "number-is-nan",
331200          "version": "1.0.1",
331201          "licenses": [
331202            {
331203              "license": {
331204                "id": "MIT"
331205              }
331206            }
331207          ],
331208          "cpe": "cpe:2.3:a:number-is-nan:number-is-nan:1.0.1:*:*:*:*:*:*:*",
331209          "purl": "pkg:npm/number-is-nan@1.0.1",
331210          "swid": {
331211            "attachment": {}
331212          },
331213          "pedigree": {},
331214          "evidence": {},
331215          "signature": {
331216            "signature": {
331217              "publicKey": {}
331218            }
331219          },
331220          "modelCard": {
331221            "modelParameters": {
331222              "approach": {}
331223            },
331224            "quantitativeAnalysis": {
331225              "graphics": {}
331226            },
331227            "considerations": {}
331228          }
331229        },
331230        {
331231          "type": "library",
331232          "bom-ref": "pkg:npm/nyc@15.1.0?package-id=18149d32195be3ea",
331233          "supplier": {},
331234          "name": "nyc",
331235          "version": "15.1.0",
331236          "cpe": "cpe:2.3:a:nyc:nyc:15.1.0:*:*:*:*:*:*:*",
331237          "purl": "pkg:npm/nyc@15.1.0",
331238          "swid": {
331239            "attachment": {}
331240          },
331241          "pedigree": {},
331242          "evidence": {},
331243          "signature": {
331244            "signature": {
331245              "publicKey": {}
331246            }
331247          },
331248          "modelCard": {
331249            "modelParameters": {
331250              "approach": {}
331251            },
331252            "quantitativeAnalysis": {
331253              "graphics": {}
331254            },
331255            "considerations": {}
331256          }
331257        },
331258        {
331259          "type": "library",
331260          "bom-ref": "pkg:npm/oauth-sign@0.9.0?package-id=cd8ae3e717266c46",
331261          "supplier": {},
331262          "name": "oauth-sign",
331263          "version": "0.9.0",
331264          "licenses": [
331265            {
331266              "license": {
331267                "id": "Apache-2.0"
331268              }
331269            }
331270          ],
331271          "cpe": "cpe:2.3:a:oauth-sign:oauth-sign:0.9.0:*:*:*:*:*:*:*",
331272          "purl": "pkg:npm/oauth-sign@0.9.0",
331273          "swid": {
331274            "attachment": {}
331275          },
331276          "pedigree": {},
331277          "evidence": {},
331278          "signature": {
331279            "signature": {
331280              "publicKey": {}
331281            }
331282          },
331283          "modelCard": {
331284            "modelParameters": {
331285              "approach": {}
331286            },
331287            "quantitativeAnalysis": {
331288              "graphics": {}
331289            },
331290            "considerations": {}
331291          }
331292        },
331293        {
331294          "type": "library",
331295          "bom-ref": "pkg:npm/object-assign@4.1.1?package-id=f802ff55095a284",
331296          "supplier": {},
331297          "name": "object-assign",
331298          "version": "4.1.1",
331299          "licenses": [
331300            {
331301              "license": {
331302                "id": "MIT"
331303              }
331304            }
331305          ],
331306          "cpe": "cpe:2.3:a:object-assign:object-assign:4.1.1:*:*:*:*:*:*:*",
331307          "purl": "pkg:npm/object-assign@4.1.1",
331308          "swid": {
331309            "attachment": {}
331310          },
331311          "pedigree": {},
331312          "evidence": {},
331313          "signature": {
331314            "signature": {
331315              "publicKey": {}
331316            }
331317          },
331318          "modelCard": {
331319            "modelParameters": {
331320              "approach": {}
331321            },
331322            "quantitativeAnalysis": {
331323              "graphics": {}
331324            },
331325            "considerations": {}
331326          }
331327        },
331328        {
331329          "type": "library",
331330          "bom-ref": "pkg:npm/object-component@0.0.3?package-id=7a5e45b312bff6cb",
331331          "supplier": {},
331332          "name": "object-component",
331333          "version": "0.0.3",
331334          "cpe": "cpe:2.3:a:object-component:object-component:0.0.3:*:*:*:*:*:*:*",
331335          "purl": "pkg:npm/object-component@0.0.3",
331336          "swid": {
331337            "attachment": {}
331338          },
331339          "pedigree": {},
331340          "evidence": {},
331341          "signature": {
331342            "signature": {
331343              "publicKey": {}
331344            }
331345          },
331346          "modelCard": {
331347            "modelParameters": {
331348              "approach": {}
331349            },
331350            "quantitativeAnalysis": {
331351              "graphics": {}
331352            },
331353            "considerations": {}
331354          }
331355        },
331356        {
331357          "type": "library",
331358          "bom-ref": "pkg:npm/object-copy@0.1.0?package-id=7b96df2f0017d75d",
331359          "supplier": {},
331360          "name": "object-copy",
331361          "version": "0.1.0",
331362          "licenses": [
331363            {
331364              "license": {
331365                "id": "MIT"
331366              }
331367            }
331368          ],
331369          "cpe": "cpe:2.3:a:object-copy:object-copy:0.1.0:*:*:*:*:*:*:*",
331370          "purl": "pkg:npm/object-copy@0.1.0",
331371          "swid": {
331372            "attachment": {}
331373          },
331374          "pedigree": {},
331375          "evidence": {},
331376          "signature": {
331377            "signature": {
331378              "publicKey": {}
331379            }
331380          },
331381          "modelCard": {
331382            "modelParameters": {
331383              "approach": {}
331384            },
331385            "quantitativeAnalysis": {
331386              "graphics": {}
331387            },
331388            "considerations": {}
331389          }
331390        },
331391        {
331392          "type": "library",
331393          "bom-ref": "pkg:npm/object-inspect@1.7.0?package-id=1d5a7430ad1048c4",
331394          "supplier": {},
331395          "name": "object-inspect",
331396          "version": "1.7.0",
331397          "licenses": [
331398            {
331399              "license": {
331400                "id": "MIT"
331401              }
331402            }
331403          ],
331404          "cpe": "cpe:2.3:a:object-inspect:object-inspect:1.7.0:*:*:*:*:*:*:*",
331405          "purl": "pkg:npm/object-inspect@1.7.0",
331406          "swid": {
331407            "attachment": {}
331408          },
331409          "pedigree": {},
331410          "evidence": {},
331411          "signature": {
331412            "signature": {
331413              "publicKey": {}
331414            }
331415          },
331416          "modelCard": {
331417            "modelParameters": {
331418              "approach": {}
331419            },
331420            "quantitativeAnalysis": {
331421              "graphics": {}
331422            },
331423            "considerations": {}
331424          }
331425        },
331426        {
331427          "type": "library",
331428          "bom-ref": "pkg:npm/object-is@1.1.2?package-id=8ed7e8a36435619b",
331429          "supplier": {},
331430          "name": "object-is",
331431          "version": "1.1.2",
331432          "licenses": [
331433            {
331434              "license": {
331435                "id": "MIT"
331436              }
331437            }
331438          ],
331439          "cpe": "cpe:2.3:a:object-is:object-is:1.1.2:*:*:*:*:*:*:*",
331440          "purl": "pkg:npm/object-is@1.1.2",
331441          "swid": {
331442            "attachment": {}
331443          },
331444          "pedigree": {},
331445          "evidence": {},
331446          "signature": {
331447            "signature": {
331448              "publicKey": {}
331449            }
331450          },
331451          "modelCard": {
331452            "modelParameters": {
331453              "approach": {}
331454            },
331455            "quantitativeAnalysis": {
331456              "graphics": {}
331457            },
331458            "considerations": {}
331459          }
331460        },
331461        {
331462          "type": "library",
331463          "bom-ref": "pkg:npm/object-keys@1.1.1?package-id=dba8c714ae361736",
331464          "supplier": {},
331465          "name": "object-keys",
331466          "version": "1.1.1",
331467          "licenses": [
331468            {
331469              "license": {
331470                "id": "MIT"
331471              }
331472            }
331473          ],
331474          "cpe": "cpe:2.3:a:object-keys:object-keys:1.1.1:*:*:*:*:*:*:*",
331475          "purl": "pkg:npm/object-keys@1.1.1",
331476          "swid": {
331477            "attachment": {}
331478          },
331479          "pedigree": {},
331480          "evidence": {},
331481          "signature": {
331482            "signature": {
331483              "publicKey": {}
331484            }
331485          },
331486          "modelCard": {
331487            "modelParameters": {
331488              "approach": {}
331489            },
331490            "quantitativeAnalysis": {
331491              "graphics": {}
331492            },
331493            "considerations": {}
331494          }
331495        },
331496        {
331497          "type": "library",
331498          "bom-ref": "pkg:npm/object-visit@1.0.1?package-id=acf46af56f21e74d",
331499          "supplier": {},
331500          "name": "object-visit",
331501          "version": "1.0.1",
331502          "licenses": [
331503            {
331504              "license": {
331505                "id": "MIT"
331506              }
331507            }
331508          ],
331509          "cpe": "cpe:2.3:a:object-visit:object-visit:1.0.1:*:*:*:*:*:*:*",
331510          "purl": "pkg:npm/object-visit@1.0.1",
331511          "swid": {
331512            "attachment": {}
331513          },
331514          "pedigree": {},
331515          "evidence": {},
331516          "signature": {
331517            "signature": {
331518              "publicKey": {}
331519            }
331520          },
331521          "modelCard": {
331522            "modelParameters": {
331523              "approach": {}
331524            },
331525            "quantitativeAnalysis": {
331526              "graphics": {}
331527            },
331528            "considerations": {}
331529          }
331530        },
331531        {
331532          "type": "library",
331533          "bom-ref": "pkg:npm/object.assign@4.1.0?package-id=595d5cd4ab087dae",
331534          "supplier": {},
331535          "name": "object.assign",
331536          "version": "4.1.0",
331537          "licenses": [
331538            {
331539              "license": {
331540                "id": "MIT"
331541              }
331542            }
331543          ],
331544          "cpe": "cpe:2.3:a:object.assign:object.assign:4.1.0:*:*:*:*:*:*:*",
331545          "purl": "pkg:npm/object.assign@4.1.0",
331546          "swid": {
331547            "attachment": {}
331548          },
331549          "pedigree": {},
331550          "evidence": {},
331551          "signature": {
331552            "signature": {
331553              "publicKey": {}
331554            }
331555          },
331556          "modelCard": {
331557            "modelParameters": {
331558              "approach": {}
331559            },
331560            "quantitativeAnalysis": {
331561              "graphics": {}
331562            },
331563            "considerations": {}
331564          }
331565        },
331566        {
331567          "type": "library",
331568          "bom-ref": "pkg:npm/object.getownpropertydescriptors@2.1.0?package-id=dbf57f521eccb13a",
331569          "supplier": {},
331570          "name": "object.getownpropertydescriptors",
331571          "version": "2.1.0",
331572          "licenses": [
331573            {
331574              "license": {
331575                "id": "MIT"
331576              }
331577            }
331578          ],
331579          "cpe": "cpe:2.3:a:object.getownpropertydescriptors:object.getownpropertydescriptors:2.1.0:*:*:*:*:*:*:*",
331580          "purl": "pkg:npm/object.getownpropertydescriptors@2.1.0",
331581          "swid": {
331582            "attachment": {}
331583          },
331584          "pedigree": {},
331585          "evidence": {},
331586          "signature": {
331587            "signature": {
331588              "publicKey": {}
331589            }
331590          },
331591          "modelCard": {
331592            "modelParameters": {
331593              "approach": {}
331594            },
331595            "quantitativeAnalysis": {
331596              "graphics": {}
331597            },
331598            "considerations": {}
331599          }
331600        },
331601        {
331602          "type": "library",
331603          "bom-ref": "pkg:npm/object.pick@1.3.0?package-id=7ecfb7d893f545fd",
331604          "supplier": {},
331605          "name": "object.pick",
331606          "version": "1.3.0",
331607          "licenses": [
331608            {
331609              "license": {
331610                "id": "MIT"
331611              }
331612            }
331613          ],
331614          "cpe": "cpe:2.3:a:object.pick:object.pick:1.3.0:*:*:*:*:*:*:*",
331615          "purl": "pkg:npm/object.pick@1.3.0",
331616          "swid": {
331617            "attachment": {}
331618          },
331619          "pedigree": {},
331620          "evidence": {},
331621          "signature": {
331622            "signature": {
331623              "publicKey": {}
331624            }
331625          },
331626          "modelCard": {
331627            "modelParameters": {
331628              "approach": {}
331629            },
331630            "quantitativeAnalysis": {
331631              "graphics": {}
331632            },
331633            "considerations": {}
331634          }
331635        },
331636        {
331637          "type": "library",
331638          "bom-ref": "pkg:npm/object.values@1.1.1?package-id=76b5624ad475d74b",
331639          "supplier": {},
331640          "name": "object.values",
331641          "version": "1.1.1",
331642          "licenses": [
331643            {
331644              "license": {
331645                "id": "MIT"
331646              }
331647            }
331648          ],
331649          "cpe": "cpe:2.3:a:object.values:object.values:1.1.1:*:*:*:*:*:*:*",
331650          "purl": "pkg:npm/object.values@1.1.1",
331651          "swid": {
331652            "attachment": {}
331653          },
331654          "pedigree": {},
331655          "evidence": {},
331656          "signature": {
331657            "signature": {
331658              "publicKey": {}
331659            }
331660          },
331661          "modelCard": {
331662            "modelParameters": {
331663              "approach": {}
331664            },
331665            "quantitativeAnalysis": {
331666              "graphics": {}
331667            },
331668            "considerations": {}
331669          }
331670        },
331671        {
331672          "type": "library",
331673          "bom-ref": "pkg:npm/obuf@1.1.2?package-id=9b2e636c7589b423",
331674          "supplier": {},
331675          "name": "obuf",
331676          "version": "1.1.2",
331677          "licenses": [
331678            {
331679              "license": {
331680                "id": "MIT"
331681              }
331682            }
331683          ],
331684          "cpe": "cpe:2.3:a:obuf:obuf:1.1.2:*:*:*:*:*:*:*",
331685          "purl": "pkg:npm/obuf@1.1.2",
331686          "swid": {
331687            "attachment": {}
331688          },
331689          "pedigree": {},
331690          "evidence": {},
331691          "signature": {
331692            "signature": {
331693              "publicKey": {}
331694            }
331695          },
331696          "modelCard": {
331697            "modelParameters": {
331698              "approach": {}
331699            },
331700            "quantitativeAnalysis": {
331701              "graphics": {}
331702            },
331703            "considerations": {}
331704          }
331705        },
331706        {
331707          "type": "library",
331708          "bom-ref": "pkg:maven/com.squareup.okhttp3/okhttp@3.8.1?package-id=b9725050a73769b4",
331709          "supplier": {},
331710          "group": "com.squareup.okhttp3",
331711          "name": "okhttp",
331712          "version": "3.8.1",
331713          "cpe": "cpe:2.3:a:squareup:okhttp:3.8.1:*:*:*:*:*:*:*",
331714          "purl": "pkg:maven/com.squareup.okhttp3/okhttp@3.8.1",
331715          "swid": {
331716            "attachment": {}
331717          },
331718          "pedigree": {},
331719          "evidence": {},
331720          "signature": {
331721            "signature": {
331722              "publicKey": {}
331723            }
331724          },
331725          "modelCard": {
331726            "modelParameters": {
331727              "approach": {}
331728            },
331729            "quantitativeAnalysis": {
331730              "graphics": {}
331731            },
331732            "considerations": {}
331733          }
331734        },
331735        {
331736          "type": "library",
331737          "bom-ref": "pkg:maven/com.squareup.okio/okio@1.13.0?package-id=8a0842d7394a63c",
331738          "supplier": {},
331739          "group": "com.squareup.okio",
331740          "name": "okio",
331741          "version": "1.13.0",
331742          "cpe": "cpe:2.3:a:squareup:okio:1.13.0:*:*:*:*:*:*:*",
331743          "purl": "pkg:maven/com.squareup.okio/okio@1.13.0",
331744          "swid": {
331745            "attachment": {}
331746          },
331747          "pedigree": {},
331748          "evidence": {},
331749          "signature": {
331750            "signature": {
331751              "publicKey": {}
331752            }
331753          },
331754          "modelCard": {
331755            "modelParameters": {
331756              "approach": {}
331757            },
331758            "quantitativeAnalysis": {
331759              "graphics": {}
331760            },
331761            "considerations": {}
331762          }
331763        },
331764        {
331765          "type": "library",
331766          "bom-ref": "pkg:npm/on-finished@2.3.0?package-id=9899269e1935c0be",
331767          "supplier": {},
331768          "name": "on-finished",
331769          "version": "2.3.0",
331770          "licenses": [
331771            {
331772              "license": {
331773                "id": "MIT"
331774              }
331775            }
331776          ],
331777          "cpe": "cpe:2.3:a:on-finished:on-finished:2.3.0:*:*:*:*:*:*:*",
331778          "purl": "pkg:npm/on-finished@2.3.0",
331779          "swid": {
331780            "attachment": {}
331781          },
331782          "pedigree": {},
331783          "evidence": {},
331784          "signature": {
331785            "signature": {
331786              "publicKey": {}
331787            }
331788          },
331789          "modelCard": {
331790            "modelParameters": {
331791              "approach": {}
331792            },
331793            "quantitativeAnalysis": {
331794              "graphics": {}
331795            },
331796            "considerations": {}
331797          }
331798        },
331799        {
331800          "type": "library",
331801          "bom-ref": "pkg:npm/on-headers@1.0.2?package-id=ed63e70859bf35cc",
331802          "supplier": {},
331803          "name": "on-headers",
331804          "version": "1.0.2",
331805          "licenses": [
331806            {
331807              "license": {
331808                "id": "MIT"
331809              }
331810            }
331811          ],
331812          "cpe": "cpe:2.3:a:on-headers:on-headers:1.0.2:*:*:*:*:*:*:*",
331813          "purl": "pkg:npm/on-headers@1.0.2",
331814          "swid": {
331815            "attachment": {}
331816          },
331817          "pedigree": {},
331818          "evidence": {},
331819          "signature": {
331820            "signature": {
331821              "publicKey": {}
331822            }
331823          },
331824          "modelCard": {
331825            "modelParameters": {
331826              "approach": {}
331827            },
331828            "quantitativeAnalysis": {
331829              "graphics": {}
331830            },
331831            "considerations": {}
331832          }
331833        },
331834        {
331835          "type": "library",
331836          "bom-ref": "pkg:npm/once@1.4.0?package-id=6bdec02a68ee8f59",
331837          "supplier": {},
331838          "name": "once",
331839          "version": "1.4.0",
331840          "cpe": "cpe:2.3:a:once:once:1.4.0:*:*:*:*:*:*:*",
331841          "purl": "pkg:npm/once@1.4.0",
331842          "swid": {
331843            "attachment": {}
331844          },
331845          "pedigree": {},
331846          "evidence": {},
331847          "signature": {
331848            "signature": {
331849              "publicKey": {}
331850            }
331851          },
331852          "modelCard": {
331853            "modelParameters": {
331854              "approach": {}
331855            },
331856            "quantitativeAnalysis": {
331857              "graphics": {}
331858            },
331859            "considerations": {}
331860          }
331861        },
331862        {
331863          "type": "library",
331864          "bom-ref": "pkg:npm/once@1.4.0?package-id=8c181f3657a90187",
331865          "supplier": {},
331866          "name": "once",
331867          "version": "1.4.0",
331868          "licenses": [
331869            {
331870              "license": {
331871                "id": "ISC"
331872              }
331873            }
331874          ],
331875          "cpe": "cpe:2.3:a:once:once:1.4.0:*:*:*:*:*:*:*",
331876          "purl": "pkg:npm/once@1.4.0",
331877          "swid": {
331878            "attachment": {}
331879          },
331880          "pedigree": {},
331881          "evidence": {},
331882          "signature": {
331883            "signature": {
331884              "publicKey": {}
331885            }
331886          },
331887          "modelCard": {
331888            "modelParameters": {
331889              "approach": {}
331890            },
331891            "quantitativeAnalysis": {
331892              "graphics": {}
331893            },
331894            "considerations": {}
331895          }
331896        },
331897        {
331898          "type": "library",
331899          "bom-ref": "pkg:npm/onetime@5.1.0?package-id=826b8ebb00dc4ca",
331900          "supplier": {},
331901          "name": "onetime",
331902          "version": "5.1.0",
331903          "licenses": [
331904            {
331905              "license": {
331906                "id": "MIT"
331907              }
331908            }
331909          ],
331910          "cpe": "cpe:2.3:a:onetime:onetime:5.1.0:*:*:*:*:*:*:*",
331911          "purl": "pkg:npm/onetime@5.1.0",
331912          "swid": {
331913            "attachment": {}
331914          },
331915          "pedigree": {},
331916          "evidence": {},
331917          "signature": {
331918            "signature": {
331919              "publicKey": {}
331920            }
331921          },
331922          "modelCard": {
331923            "modelParameters": {
331924              "approach": {}
331925            },
331926            "quantitativeAnalysis": {
331927              "graphics": {}
331928            },
331929            "considerations": {}
331930          }
331931        },
331932        {
331933          "type": "library",
331934          "bom-ref": "pkg:npm/ono@4.0.11?package-id=fa451b6cb5b87d8b",
331935          "supplier": {},
331936          "name": "ono",
331937          "version": "4.0.11",
331938          "licenses": [
331939            {
331940              "license": {
331941                "id": "MIT"
331942              }
331943            }
331944          ],
331945          "cpe": "cpe:2.3:a:ono:ono:4.0.11:*:*:*:*:*:*:*",
331946          "purl": "pkg:npm/ono@4.0.11",
331947          "swid": {
331948            "attachment": {}
331949          },
331950          "pedigree": {},
331951          "evidence": {},
331952          "signature": {
331953            "signature": {
331954              "publicKey": {}
331955            }
331956          },
331957          "modelCard": {
331958            "modelParameters": {
331959              "approach": {}
331960            },
331961            "quantitativeAnalysis": {
331962              "graphics": {}
331963            },
331964            "considerations": {}
331965          }
331966        },
331967        {
331968          "type": "library",
331969          "bom-ref": "pkg:npm/open@7.0.3?package-id=e322f447d74a3239",
331970          "supplier": {},
331971          "name": "open",
331972          "version": "7.0.3",
331973          "licenses": [
331974            {
331975              "license": {
331976                "id": "MIT"
331977              }
331978            }
331979          ],
331980          "cpe": "cpe:2.3:a:open:open:7.0.3:*:*:*:*:*:*:*",
331981          "purl": "pkg:npm/open@7.0.3",
331982          "swid": {
331983            "attachment": {}
331984          },
331985          "pedigree": {},
331986          "evidence": {},
331987          "signature": {
331988            "signature": {
331989              "publicKey": {}
331990            }
331991          },
331992          "modelCard": {
331993            "modelParameters": {
331994              "approach": {}
331995            },
331996            "quantitativeAnalysis": {
331997              "graphics": {}
331998            },
331999            "considerations": {}
332000          }
332001        },
332002        {
332003          "type": "library",
332004          "bom-ref": "pkg:npm/open@7.4.2?package-id=a9b236167b5e7692",
332005          "supplier": {},
332006          "name": "open",
332007          "version": "7.4.2",
332008          "cpe": "cpe:2.3:a:open:open:7.4.2:*:*:*:*:*:*:*",
332009          "purl": "pkg:npm/open@7.4.2",
332010          "swid": {
332011            "attachment": {}
332012          },
332013          "pedigree": {},
332014          "evidence": {},
332015          "signature": {
332016            "signature": {
332017              "publicKey": {}
332018            }
332019          },
332020          "modelCard": {
332021            "modelParameters": {
332022              "approach": {}
332023            },
332024            "quantitativeAnalysis": {
332025              "graphics": {}
332026            },
332027            "considerations": {}
332028          }
332029        },
332030        {
332031          "type": "library",
332032          "bom-ref": "pkg:npm/opencollective-postinstall@2.0.3?package-id=9d6d28fa89f8f1c2",
332033          "supplier": {},
332034          "name": "opencollective-postinstall",
332035          "version": "2.0.3",
332036          "licenses": [
332037            {
332038              "license": {
332039                "id": "MIT"
332040              }
332041            }
332042          ],
332043          "cpe": "cpe:2.3:a:opencollective-postinstall:opencollective-postinstall:2.0.3:*:*:*:*:*:*:*",
332044          "purl": "pkg:npm/opencollective-postinstall@2.0.3",
332045          "swid": {
332046            "attachment": {}
332047          },
332048          "pedigree": {},
332049          "evidence": {},
332050          "signature": {
332051            "signature": {
332052              "publicKey": {}
332053            }
332054          },
332055          "modelCard": {
332056            "modelParameters": {
332057              "approach": {}
332058            },
332059            "quantitativeAnalysis": {
332060              "graphics": {}
332061            },
332062            "considerations": {}
332063          }
332064        },
332065        {
332066          "type": "library",
332067          "bom-ref": "pkg:npm/opener@1.5.1?package-id=ce5e8fa3d5729c13",
332068          "supplier": {},
332069          "name": "opener",
332070          "version": "1.5.1",
332071          "licenses": [
332072            {
332073              "license": {
332074                "name": "(WTFPL OR MIT)"
332075              }
332076            }
332077          ],
332078          "cpe": "cpe:2.3:a:opener:opener:1.5.1:*:*:*:*:*:*:*",
332079          "purl": "pkg:npm/opener@1.5.1",
332080          "swid": {
332081            "attachment": {}
332082          },
332083          "pedigree": {},
332084          "evidence": {},
332085          "signature": {
332086            "signature": {
332087              "publicKey": {}
332088            }
332089          },
332090          "modelCard": {
332091            "modelParameters": {
332092              "approach": {}
332093            },
332094            "quantitativeAnalysis": {
332095              "graphics": {}
332096            },
332097            "considerations": {}
332098          }
332099        },
332100        {
332101          "type": "library",
332102          "bom-ref": "pkg:npm/opn@5.5.0?package-id=e9ac4f5b202c5c49",
332103          "supplier": {},
332104          "name": "opn",
332105          "version": "5.5.0",
332106          "licenses": [
332107            {
332108              "license": {
332109                "id": "MIT"
332110              }
332111            }
332112          ],
332113          "cpe": "cpe:2.3:a:opn:opn:5.5.0:*:*:*:*:*:*:*",
332114          "purl": "pkg:npm/opn@5.5.0",
332115          "swid": {
332116            "attachment": {}
332117          },
332118          "pedigree": {},
332119          "evidence": {},
332120          "signature": {
332121            "signature": {
332122              "publicKey": {}
332123            }
332124          },
332125          "modelCard": {
332126            "modelParameters": {
332127              "approach": {}
332128            },
332129            "quantitativeAnalysis": {
332130              "graphics": {}
332131            },
332132            "considerations": {}
332133          }
332134        },
332135        {
332136          "type": "library",
332137          "bom-ref": "pkg:npm/optimist@0.6.1?package-id=94bb7757583dd2b9",
332138          "supplier": {},
332139          "name": "optimist",
332140          "version": "0.6.1",
332141          "licenses": [
332142            {
332143              "license": {
332144                "name": "MIT/X11"
332145              }
332146            }
332147          ],
332148          "cpe": "cpe:2.3:a:optimist:optimist:0.6.1:*:*:*:*:*:*:*",
332149          "purl": "pkg:npm/optimist@0.6.1",
332150          "swid": {
332151            "attachment": {}
332152          },
332153          "pedigree": {},
332154          "evidence": {},
332155          "signature": {
332156            "signature": {
332157              "publicKey": {}
332158            }
332159          },
332160          "modelCard": {
332161            "modelParameters": {
332162              "approach": {}
332163            },
332164            "quantitativeAnalysis": {
332165              "graphics": {}
332166            },
332167            "considerations": {}
332168          }
332169        },
332170        {
332171          "type": "library",
332172          "bom-ref": "pkg:npm/ora@4.0.3?package-id=3c8edc1c2ac9b394",
332173          "supplier": {},
332174          "name": "ora",
332175          "version": "4.0.3",
332176          "licenses": [
332177            {
332178              "license": {
332179                "id": "MIT"
332180              }
332181            }
332182          ],
332183          "cpe": "cpe:2.3:a:ora:ora:4.0.3:*:*:*:*:*:*:*",
332184          "purl": "pkg:npm/ora@4.0.3",
332185          "swid": {
332186            "attachment": {}
332187          },
332188          "pedigree": {},
332189          "evidence": {},
332190          "signature": {
332191            "signature": {
332192              "publicKey": {}
332193            }
332194          },
332195          "modelCard": {
332196            "modelParameters": {
332197              "approach": {}
332198            },
332199            "quantitativeAnalysis": {
332200              "graphics": {}
332201            },
332202            "considerations": {}
332203          }
332204        },
332205        {
332206          "type": "library",
332207          "bom-ref": "pkg:pypi/ordereddict@1.1?package-id=e10911d86c0762c",
332208          "supplier": {},
332209          "name": "ordereddict",
332210          "version": "1.1",
332211          "cpe": "cpe:2.3:a:python-ordereddict:python-ordereddict:1.1:*:*:*:*:*:*:*",
332212          "purl": "pkg:pypi/ordereddict@1.1",
332213          "swid": {
332214            "attachment": {}
332215          },
332216          "pedigree": {},
332217          "evidence": {},
332218          "signature": {
332219            "signature": {
332220              "publicKey": {}
332221            }
332222          },
332223          "modelCard": {
332224            "modelParameters": {
332225              "approach": {}
332226            },
332227            "quantitativeAnalysis": {
332228              "graphics": {}
332229            },
332230            "considerations": {}
332231          }
332232        },
332233        {
332234          "type": "library",
332235          "bom-ref": "pkg:pypi/ordereddict@1.1?package-id=dad3802fefb38d7",
332236          "supplier": {},
332237          "name": "ordereddict",
332238          "version": "1.1",
332239          "cpe": "cpe:2.3:a:python-ordereddict:python-ordereddict:1.1:*:*:*:*:*:*:*",
332240          "purl": "pkg:pypi/ordereddict@1.1",
332241          "swid": {
332242            "attachment": {}
332243          },
332244          "pedigree": {},
332245          "evidence": {},
332246          "signature": {
332247            "signature": {
332248              "publicKey": {}
332249            }
332250          },
332251          "modelCard": {
332252            "modelParameters": {
332253              "approach": {}
332254            },
332255            "quantitativeAnalysis": {
332256              "graphics": {}
332257            },
332258            "considerations": {}
332259          }
332260        },
332261        {
332262          "type": "library",
332263          "bom-ref": "pkg:npm/original@1.0.2?package-id=bc3dc5d20a385aa2",
332264          "supplier": {},
332265          "name": "original",
332266          "version": "1.0.2",
332267          "licenses": [
332268            {
332269              "license": {
332270                "id": "MIT"
332271              }
332272            }
332273          ],
332274          "cpe": "cpe:2.3:a:original:original:1.0.2:*:*:*:*:*:*:*",
332275          "purl": "pkg:npm/original@1.0.2",
332276          "swid": {
332277            "attachment": {}
332278          },
332279          "pedigree": {},
332280          "evidence": {},
332281          "signature": {
332282            "signature": {
332283              "publicKey": {}
332284            }
332285          },
332286          "modelCard": {
332287            "modelParameters": {
332288              "approach": {}
332289            },
332290            "quantitativeAnalysis": {
332291              "graphics": {}
332292            },
332293            "considerations": {}
332294          }
332295        },
332296        {
332297          "type": "library",
332298          "bom-ref": "pkg:npm/os-browserify@0.3.0?package-id=f1b0eb3e8d70757f",
332299          "supplier": {},
332300          "name": "os-browserify",
332301          "version": "0.3.0",
332302          "licenses": [
332303            {
332304              "license": {
332305                "id": "MIT"
332306              }
332307            }
332308          ],
332309          "cpe": "cpe:2.3:a:os-browserify:os-browserify:0.3.0:*:*:*:*:*:*:*",
332310          "purl": "pkg:npm/os-browserify@0.3.0",
332311          "swid": {
332312            "attachment": {}
332313          },
332314          "pedigree": {},
332315          "evidence": {},
332316          "signature": {
332317            "signature": {
332318              "publicKey": {}
332319            }
332320          },
332321          "modelCard": {
332322            "modelParameters": {
332323              "approach": {}
332324            },
332325            "quantitativeAnalysis": {
332326              "graphics": {}
332327            },
332328            "considerations": {}
332329          }
332330        },
332331        {
332332          "type": "library",
332333          "bom-ref": "pkg:npm/os-homedir@1.0.2?package-id=e2069ccb6e776763",
332334          "supplier": {},
332335          "name": "os-homedir",
332336          "version": "1.0.2",
332337          "licenses": [
332338            {
332339              "license": {
332340                "id": "MIT"
332341              }
332342            }
332343          ],
332344          "cpe": "cpe:2.3:a:os-homedir:os-homedir:1.0.2:*:*:*:*:*:*:*",
332345          "purl": "pkg:npm/os-homedir@1.0.2",
332346          "swid": {
332347            "attachment": {}
332348          },
332349          "pedigree": {},
332350          "evidence": {},
332351          "signature": {
332352            "signature": {
332353              "publicKey": {}
332354            }
332355          },
332356          "modelCard": {
332357            "modelParameters": {
332358              "approach": {}
332359            },
332360            "quantitativeAnalysis": {
332361              "graphics": {}
332362            },
332363            "considerations": {}
332364          }
332365        },
332366        {
332367          "type": "library",
332368          "bom-ref": "pkg:npm/os-locale@3.1.0?package-id=6085dae6b90f6cd6",
332369          "supplier": {},
332370          "name": "os-locale",
332371          "version": "3.1.0",
332372          "licenses": [
332373            {
332374              "license": {
332375                "id": "MIT"
332376              }
332377            }
332378          ],
332379          "cpe": "cpe:2.3:a:os-locale:os-locale:3.1.0:*:*:*:*:*:*:*",
332380          "purl": "pkg:npm/os-locale@3.1.0",
332381          "swid": {
332382            "attachment": {}
332383          },
332384          "pedigree": {},
332385          "evidence": {},
332386          "signature": {
332387            "signature": {
332388              "publicKey": {}
332389            }
332390          },
332391          "modelCard": {
332392            "modelParameters": {
332393              "approach": {}
332394            },
332395            "quantitativeAnalysis": {
332396              "graphics": {}
332397            },
332398            "considerations": {}
332399          }
332400        },
332401        {
332402          "type": "library",
332403          "bom-ref": "pkg:npm/os-tmpdir@1.0.2?package-id=bc79766395558f38",
332404          "supplier": {},
332405          "name": "os-tmpdir",
332406          "version": "1.0.2",
332407          "cpe": "cpe:2.3:a:os-tmpdir:os-tmpdir:1.0.2:*:*:*:*:*:*:*",
332408          "purl": "pkg:npm/os-tmpdir@1.0.2",
332409          "swid": {
332410            "attachment": {}
332411          },
332412          "pedigree": {},
332413          "evidence": {},
332414          "signature": {
332415            "signature": {
332416              "publicKey": {}
332417            }
332418          },
332419          "modelCard": {
332420            "modelParameters": {
332421              "approach": {}
332422            },
332423            "quantitativeAnalysis": {
332424              "graphics": {}
332425            },
332426            "considerations": {}
332427          }
332428        },
332429        {
332430          "type": "library",
332431          "bom-ref": "pkg:npm/os-tmpdir@1.0.2?package-id=56963e28e9ca14c7",
332432          "supplier": {},
332433          "name": "os-tmpdir",
332434          "version": "1.0.2",
332435          "licenses": [
332436            {
332437              "license": {
332438                "id": "MIT"
332439              }
332440            }
332441          ],
332442          "cpe": "cpe:2.3:a:os-tmpdir:os-tmpdir:1.0.2:*:*:*:*:*:*:*",
332443          "purl": "pkg:npm/os-tmpdir@1.0.2",
332444          "swid": {
332445            "attachment": {}
332446          },
332447          "pedigree": {},
332448          "evidence": {},
332449          "signature": {
332450            "signature": {
332451              "publicKey": {}
332452            }
332453          },
332454          "modelCard": {
332455            "modelParameters": {
332456              "approach": {}
332457            },
332458            "quantitativeAnalysis": {
332459              "graphics": {}
332460            },
332461            "considerations": {}
332462          }
332463        },
332464        {
332465          "type": "library",
332466          "bom-ref": "pkg:npm/osenv@0.1.5?package-id=f39619a86bfaf17b",
332467          "supplier": {},
332468          "name": "osenv",
332469          "version": "0.1.5",
332470          "licenses": [
332471            {
332472              "license": {
332473                "id": "ISC"
332474              }
332475            }
332476          ],
332477          "cpe": "cpe:2.3:a:osenv:osenv:0.1.5:*:*:*:*:*:*:*",
332478          "purl": "pkg:npm/osenv@0.1.5",
332479          "swid": {
332480            "attachment": {}
332481          },
332482          "pedigree": {},
332483          "evidence": {},
332484          "signature": {
332485            "signature": {
332486              "publicKey": {}
332487            }
332488          },
332489          "modelCard": {
332490            "modelParameters": {
332491              "approach": {}
332492            },
332493            "quantitativeAnalysis": {
332494              "graphics": {}
332495            },
332496            "considerations": {}
332497          }
332498        },
332499        {
332500          "type": "library",
332501          "bom-ref": "pkg:npm/p-defer@1.0.0?package-id=bb096c20e423fe08",
332502          "supplier": {},
332503          "name": "p-defer",
332504          "version": "1.0.0",
332505          "licenses": [
332506            {
332507              "license": {
332508                "id": "MIT"
332509              }
332510            }
332511          ],
332512          "cpe": "cpe:2.3:a:p-defer:p-defer:1.0.0:*:*:*:*:*:*:*",
332513          "purl": "pkg:npm/p-defer@1.0.0",
332514          "swid": {
332515            "attachment": {}
332516          },
332517          "pedigree": {},
332518          "evidence": {},
332519          "signature": {
332520            "signature": {
332521              "publicKey": {}
332522            }
332523          },
332524          "modelCard": {
332525            "modelParameters": {
332526              "approach": {}
332527            },
332528            "quantitativeAnalysis": {
332529              "graphics": {}
332530            },
332531            "considerations": {}
332532          }
332533        },
332534        {
332535          "type": "library",
332536          "bom-ref": "pkg:npm/p-finally@1.0.0?package-id=a3966c804dcfe154",
332537          "supplier": {},
332538          "name": "p-finally",
332539          "version": "1.0.0",
332540          "licenses": [
332541            {
332542              "license": {
332543                "id": "MIT"
332544              }
332545            }
332546          ],
332547          "cpe": "cpe:2.3:a:p-finally:p-finally:1.0.0:*:*:*:*:*:*:*",
332548          "purl": "pkg:npm/p-finally@1.0.0",
332549          "swid": {
332550            "attachment": {}
332551          },
332552          "pedigree": {},
332553          "evidence": {},
332554          "signature": {
332555            "signature": {
332556              "publicKey": {}
332557            }
332558          },
332559          "modelCard": {
332560            "modelParameters": {
332561              "approach": {}
332562            },
332563            "quantitativeAnalysis": {
332564              "graphics": {}
332565            },
332566            "considerations": {}
332567          }
332568        },
332569        {
332570          "type": "library",
332571          "bom-ref": "pkg:npm/p-is-promise@2.1.0?package-id=56f76838055ab1f1",
332572          "supplier": {},
332573          "name": "p-is-promise",
332574          "version": "2.1.0",
332575          "licenses": [
332576            {
332577              "license": {
332578                "id": "MIT"
332579              }
332580            }
332581          ],
332582          "cpe": "cpe:2.3:a:p-is-promise:p-is-promise:2.1.0:*:*:*:*:*:*:*",
332583          "purl": "pkg:npm/p-is-promise@2.1.0",
332584          "swid": {
332585            "attachment": {}
332586          },
332587          "pedigree": {},
332588          "evidence": {},
332589          "signature": {
332590            "signature": {
332591              "publicKey": {}
332592            }
332593          },
332594          "modelCard": {
332595            "modelParameters": {
332596              "approach": {}
332597            },
332598            "quantitativeAnalysis": {
332599              "graphics": {}
332600            },
332601            "considerations": {}
332602          }
332603        },
332604        {
332605          "type": "library",
332606          "bom-ref": "pkg:npm/p-limit@2.2.2?package-id=88dca81416a59dc0",
332607          "supplier": {},
332608          "name": "p-limit",
332609          "version": "2.2.2",
332610          "licenses": [
332611            {
332612              "license": {
332613                "id": "MIT"
332614              }
332615            }
332616          ],
332617          "cpe": "cpe:2.3:a:p-limit:p-limit:2.2.2:*:*:*:*:*:*:*",
332618          "purl": "pkg:npm/p-limit@2.2.2",
332619          "swid": {
332620            "attachment": {}
332621          },
332622          "pedigree": {},
332623          "evidence": {},
332624          "signature": {
332625            "signature": {
332626              "publicKey": {}
332627            }
332628          },
332629          "modelCard": {
332630            "modelParameters": {
332631              "approach": {}
332632            },
332633            "quantitativeAnalysis": {
332634              "graphics": {}
332635            },
332636            "considerations": {}
332637          }
332638        },
332639        {
332640          "type": "library",
332641          "bom-ref": "pkg:npm/p-limit@2.3.0?package-id=cbb5402e301ecef8",
332642          "supplier": {},
332643          "name": "p-limit",
332644          "version": "2.3.0",
332645          "cpe": "cpe:2.3:a:p-limit:p-limit:2.3.0:*:*:*:*:*:*:*",
332646          "purl": "pkg:npm/p-limit@2.3.0",
332647          "swid": {
332648            "attachment": {}
332649          },
332650          "pedigree": {},
332651          "evidence": {},
332652          "signature": {
332653            "signature": {
332654              "publicKey": {}
332655            }
332656          },
332657          "modelCard": {
332658            "modelParameters": {
332659              "approach": {}
332660            },
332661            "quantitativeAnalysis": {
332662              "graphics": {}
332663            },
332664            "considerations": {}
332665          }
332666        },
332667        {
332668          "type": "library",
332669          "bom-ref": "pkg:npm/p-locate@3.0.0?package-id=e72c01b7e2b633da",
332670          "supplier": {},
332671          "name": "p-locate",
332672          "version": "3.0.0",
332673          "licenses": [
332674            {
332675              "license": {
332676                "id": "MIT"
332677              }
332678            }
332679          ],
332680          "cpe": "cpe:2.3:a:p-locate:p-locate:3.0.0:*:*:*:*:*:*:*",
332681          "purl": "pkg:npm/p-locate@3.0.0",
332682          "swid": {
332683            "attachment": {}
332684          },
332685          "pedigree": {},
332686          "evidence": {},
332687          "signature": {
332688            "signature": {
332689              "publicKey": {}
332690            }
332691          },
332692          "modelCard": {
332693            "modelParameters": {
332694              "approach": {}
332695            },
332696            "quantitativeAnalysis": {
332697              "graphics": {}
332698            },
332699            "considerations": {}
332700          }
332701        },
332702        {
332703          "type": "library",
332704          "bom-ref": "pkg:npm/p-locate@4.1.0?package-id=71adf0f15627119b",
332705          "supplier": {},
332706          "name": "p-locate",
332707          "version": "4.1.0",
332708          "cpe": "cpe:2.3:a:p-locate:p-locate:4.1.0:*:*:*:*:*:*:*",
332709          "purl": "pkg:npm/p-locate@4.1.0",
332710          "swid": {
332711            "attachment": {}
332712          },
332713          "pedigree": {},
332714          "evidence": {},
332715          "signature": {
332716            "signature": {
332717              "publicKey": {}
332718            }
332719          },
332720          "modelCard": {
332721            "modelParameters": {
332722              "approach": {}
332723            },
332724            "quantitativeAnalysis": {
332725              "graphics": {}
332726            },
332727            "considerations": {}
332728          }
332729        },
332730        {
332731          "type": "library",
332732          "bom-ref": "pkg:npm/p-map@3.0.0?package-id=9934f9b6b41be60a",
332733          "supplier": {},
332734          "name": "p-map",
332735          "version": "3.0.0",
332736          "cpe": "cpe:2.3:a:p-map:p-map:3.0.0:*:*:*:*:*:*:*",
332737          "purl": "pkg:npm/p-map@3.0.0",
332738          "swid": {
332739            "attachment": {}
332740          },
332741          "pedigree": {},
332742          "evidence": {},
332743          "signature": {
332744            "signature": {
332745              "publicKey": {}
332746            }
332747          },
332748          "modelCard": {
332749            "modelParameters": {
332750              "approach": {}
332751            },
332752            "quantitativeAnalysis": {
332753              "graphics": {}
332754            },
332755            "considerations": {}
332756          }
332757        },
332758        {
332759          "type": "library",
332760          "bom-ref": "pkg:npm/p-map@3.0.0?package-id=37709a083faa225b",
332761          "supplier": {},
332762          "name": "p-map",
332763          "version": "3.0.0",
332764          "licenses": [
332765            {
332766              "license": {
332767                "id": "MIT"
332768              }
332769            }
332770          ],
332771          "cpe": "cpe:2.3:a:p-map:p-map:3.0.0:*:*:*:*:*:*:*",
332772          "purl": "pkg:npm/p-map@3.0.0",
332773          "swid": {
332774            "attachment": {}
332775          },
332776          "pedigree": {},
332777          "evidence": {},
332778          "signature": {
332779            "signature": {
332780              "publicKey": {}
332781            }
332782          },
332783          "modelCard": {
332784            "modelParameters": {
332785              "approach": {}
332786            },
332787            "quantitativeAnalysis": {
332788              "graphics": {}
332789            },
332790            "considerations": {}
332791          }
332792        },
332793        {
332794          "type": "library",
332795          "bom-ref": "pkg:npm/p-retry@3.0.1?package-id=94daf3326a3ade66",
332796          "supplier": {},
332797          "name": "p-retry",
332798          "version": "3.0.1",
332799          "licenses": [
332800            {
332801              "license": {
332802                "id": "MIT"
332803              }
332804            }
332805          ],
332806          "cpe": "cpe:2.3:a:p-retry:p-retry:3.0.1:*:*:*:*:*:*:*",
332807          "purl": "pkg:npm/p-retry@3.0.1",
332808          "swid": {
332809            "attachment": {}
332810          },
332811          "pedigree": {},
332812          "evidence": {},
332813          "signature": {
332814            "signature": {
332815              "publicKey": {}
332816            }
332817          },
332818          "modelCard": {
332819            "modelParameters": {
332820              "approach": {}
332821            },
332822            "quantitativeAnalysis": {
332823              "graphics": {}
332824            },
332825            "considerations": {}
332826          }
332827        },
332828        {
332829          "type": "library",
332830          "bom-ref": "pkg:npm/p-try@2.2.0?package-id=63e742e03485e670",
332831          "supplier": {},
332832          "name": "p-try",
332833          "version": "2.2.0",
332834          "cpe": "cpe:2.3:a:p-try:p-try:2.2.0:*:*:*:*:*:*:*",
332835          "purl": "pkg:npm/p-try@2.2.0",
332836          "swid": {
332837            "attachment": {}
332838          },
332839          "pedigree": {},
332840          "evidence": {},
332841          "signature": {
332842            "signature": {
332843              "publicKey": {}
332844            }
332845          },
332846          "modelCard": {
332847            "modelParameters": {
332848              "approach": {}
332849            },
332850            "quantitativeAnalysis": {
332851              "graphics": {}
332852            },
332853            "considerations": {}
332854          }
332855        },
332856        {
332857          "type": "library",
332858          "bom-ref": "pkg:npm/p-try@2.2.0?package-id=dc056082b22f425c",
332859          "supplier": {},
332860          "name": "p-try",
332861          "version": "2.2.0",
332862          "licenses": [
332863            {
332864              "license": {
332865                "id": "MIT"
332866              }
332867            }
332868          ],
332869          "cpe": "cpe:2.3:a:p-try:p-try:2.2.0:*:*:*:*:*:*:*",
332870          "purl": "pkg:npm/p-try@2.2.0",
332871          "swid": {
332872            "attachment": {}
332873          },
332874          "pedigree": {},
332875          "evidence": {},
332876          "signature": {
332877            "signature": {
332878              "publicKey": {}
332879            }
332880          },
332881          "modelCard": {
332882            "modelParameters": {
332883              "approach": {}
332884            },
332885            "quantitativeAnalysis": {
332886              "graphics": {}
332887            },
332888            "considerations": {}
332889          }
332890        },
332891        {
332892          "type": "library",
332893          "bom-ref": "pkg:npm/package-hash@4.0.0?package-id=7437fc0765ca9c6b",
332894          "supplier": {},
332895          "name": "package-hash",
332896          "version": "4.0.0",
332897          "cpe": "cpe:2.3:a:package-hash:package-hash:4.0.0:*:*:*:*:*:*:*",
332898          "purl": "pkg:npm/package-hash@4.0.0",
332899          "swid": {
332900            "attachment": {}
332901          },
332902          "pedigree": {},
332903          "evidence": {},
332904          "signature": {
332905            "signature": {
332906              "publicKey": {}
332907            }
332908          },
332909          "modelCard": {
332910            "modelParameters": {
332911              "approach": {}
332912            },
332913            "quantitativeAnalysis": {
332914              "graphics": {}
332915            },
332916            "considerations": {}
332917          }
332918        },
332919        {
332920          "type": "library",
332921          "bom-ref": "pkg:npm/pacote@9.5.12?package-id=2de0c4b4341bfb80",
332922          "supplier": {},
332923          "name": "pacote",
332924          "version": "9.5.12",
332925          "licenses": [
332926            {
332927              "license": {
332928                "id": "MIT"
332929              }
332930            }
332931          ],
332932          "cpe": "cpe:2.3:a:pacote:pacote:9.5.12:*:*:*:*:*:*:*",
332933          "purl": "pkg:npm/pacote@9.5.12",
332934          "swid": {
332935            "attachment": {}
332936          },
332937          "pedigree": {},
332938          "evidence": {},
332939          "signature": {
332940            "signature": {
332941              "publicKey": {}
332942            }
332943          },
332944          "modelCard": {
332945            "modelParameters": {
332946              "approach": {}
332947            },
332948            "quantitativeAnalysis": {
332949              "graphics": {}
332950            },
332951            "considerations": {}
332952          }
332953        },
332954        {
332955          "type": "library",
332956          "bom-ref": "pkg:npm/pako@1.0.11?package-id=4ba4360c0ee4894b",
332957          "supplier": {},
332958          "name": "pako",
332959          "version": "1.0.11",
332960          "licenses": [
332961            {
332962              "license": {
332963                "name": "(MIT AND Zlib)"
332964              }
332965            }
332966          ],
332967          "cpe": "cpe:2.3:a:pako:pako:1.0.11:*:*:*:*:*:*:*",
332968          "purl": "pkg:npm/pako@1.0.11",
332969          "swid": {
332970            "attachment": {}
332971          },
332972          "pedigree": {},
332973          "evidence": {},
332974          "signature": {
332975            "signature": {
332976              "publicKey": {}
332977            }
332978          },
332979          "modelCard": {
332980            "modelParameters": {
332981              "approach": {}
332982            },
332983            "quantitativeAnalysis": {
332984              "graphics": {}
332985            },
332986            "considerations": {}
332987          }
332988        },
332989        {
332990          "type": "library",
332991          "bom-ref": "pkg:npm/parallel-transform@1.2.0?package-id=f9cd3dfe0a235120",
332992          "supplier": {},
332993          "name": "parallel-transform",
332994          "version": "1.2.0",
332995          "licenses": [
332996            {
332997              "license": {
332998                "id": "MIT"
332999              }
333000            }
333001          ],
333002          "cpe": "cpe:2.3:a:parallel-transform:parallel-transform:1.2.0:*:*:*:*:*:*:*",
333003          "purl": "pkg:npm/parallel-transform@1.2.0",
333004          "swid": {
333005            "attachment": {}
333006          },
333007          "pedigree": {},
333008          "evidence": {},
333009          "signature": {
333010            "signature": {
333011              "publicKey": {}
333012            }
333013          },
333014          "modelCard": {
333015            "modelParameters": {
333016              "approach": {}
333017            },
333018            "quantitativeAnalysis": {
333019              "graphics": {}
333020            },
333021            "considerations": {}
333022          }
333023        },
333024        {
333025          "type": "library",
333026          "bom-ref": "pkg:npm/parse-asn1@5.1.5?package-id=f731f96f925b1c96",
333027          "supplier": {},
333028          "name": "parse-asn1",
333029          "version": "5.1.5",
333030          "licenses": [
333031            {
333032              "license": {
333033                "id": "ISC"
333034              }
333035            }
333036          ],
333037          "cpe": "cpe:2.3:a:parse-asn1:parse-asn1:5.1.5:*:*:*:*:*:*:*",
333038          "purl": "pkg:npm/parse-asn1@5.1.5",
333039          "swid": {
333040            "attachment": {}
333041          },
333042          "pedigree": {},
333043          "evidence": {},
333044          "signature": {
333045            "signature": {
333046              "publicKey": {}
333047            }
333048          },
333049          "modelCard": {
333050            "modelParameters": {
333051              "approach": {}
333052            },
333053            "quantitativeAnalysis": {
333054              "graphics": {}
333055            },
333056            "considerations": {}
333057          }
333058        },
333059        {
333060          "type": "library",
333061          "bom-ref": "pkg:npm/parse-json@4.0.0?package-id=3a70074f86ba1403",
333062          "supplier": {},
333063          "name": "parse-json",
333064          "version": "4.0.0",
333065          "licenses": [
333066            {
333067              "license": {
333068                "id": "MIT"
333069              }
333070            }
333071          ],
333072          "cpe": "cpe:2.3:a:parse-json:parse-json:4.0.0:*:*:*:*:*:*:*",
333073          "purl": "pkg:npm/parse-json@4.0.0",
333074          "swid": {
333075            "attachment": {}
333076          },
333077          "pedigree": {},
333078          "evidence": {},
333079          "signature": {
333080            "signature": {
333081              "publicKey": {}
333082            }
333083          },
333084          "modelCard": {
333085            "modelParameters": {
333086              "approach": {}
333087            },
333088            "quantitativeAnalysis": {
333089              "graphics": {}
333090            },
333091            "considerations": {}
333092          }
333093        },
333094        {
333095          "type": "library",
333096          "bom-ref": "pkg:npm/parse-ms@2.1.0?package-id=7edc7327741c8b27",
333097          "supplier": {},
333098          "name": "parse-ms",
333099          "version": "2.1.0",
333100          "licenses": [
333101            {
333102              "license": {
333103                "id": "MIT"
333104              }
333105            }
333106          ],
333107          "cpe": "cpe:2.3:a:parse-ms:parse-ms:2.1.0:*:*:*:*:*:*:*",
333108          "purl": "pkg:npm/parse-ms@2.1.0",
333109          "swid": {
333110            "attachment": {}
333111          },
333112          "pedigree": {},
333113          "evidence": {},
333114          "signature": {
333115            "signature": {
333116              "publicKey": {}
333117            }
333118          },
333119          "modelCard": {
333120            "modelParameters": {
333121              "approach": {}
333122            },
333123            "quantitativeAnalysis": {
333124              "graphics": {}
333125            },
333126            "considerations": {}
333127          }
333128        },
333129        {
333130          "type": "library",
333131          "bom-ref": "pkg:npm/parse5@5.1.1?package-id=e09fd15ec4102db5",
333132          "supplier": {},
333133          "name": "parse5",
333134          "version": "5.1.1",
333135          "licenses": [
333136            {
333137              "license": {
333138                "id": "MIT"
333139              }
333140            }
333141          ],
333142          "cpe": "cpe:2.3:a:parse5:parse5:5.1.1:*:*:*:*:*:*:*",
333143          "purl": "pkg:npm/parse5@5.1.1",
333144          "swid": {
333145            "attachment": {}
333146          },
333147          "pedigree": {},
333148          "evidence": {},
333149          "signature": {
333150            "signature": {
333151              "publicKey": {}
333152            }
333153          },
333154          "modelCard": {
333155            "modelParameters": {
333156              "approach": {}
333157            },
333158            "quantitativeAnalysis": {
333159              "graphics": {}
333160            },
333161            "considerations": {}
333162          }
333163        },
333164        {
333165          "type": "library",
333166          "bom-ref": "pkg:npm/parseqs@0.0.5?package-id=7510723b232c24e",
333167          "supplier": {},
333168          "name": "parseqs",
333169          "version": "0.0.5",
333170          "licenses": [
333171            {
333172              "license": {
333173                "id": "MIT"
333174              }
333175            }
333176          ],
333177          "cpe": "cpe:2.3:a:parseqs:parseqs:0.0.5:*:*:*:*:*:*:*",
333178          "purl": "pkg:npm/parseqs@0.0.5",
333179          "swid": {
333180            "attachment": {}
333181          },
333182          "pedigree": {},
333183          "evidence": {},
333184          "signature": {
333185            "signature": {
333186              "publicKey": {}
333187            }
333188          },
333189          "modelCard": {
333190            "modelParameters": {
333191              "approach": {}
333192            },
333193            "quantitativeAnalysis": {
333194              "graphics": {}
333195            },
333196            "considerations": {}
333197          }
333198        },
333199        {
333200          "type": "library",
333201          "bom-ref": "pkg:npm/parseuri@0.0.5?package-id=b085e30065129e86",
333202          "supplier": {},
333203          "name": "parseuri",
333204          "version": "0.0.5",
333205          "licenses": [
333206            {
333207              "license": {
333208                "id": "MIT"
333209              }
333210            }
333211          ],
333212          "cpe": "cpe:2.3:a:parseuri:parseuri:0.0.5:*:*:*:*:*:*:*",
333213          "purl": "pkg:npm/parseuri@0.0.5",
333214          "swid": {
333215            "attachment": {}
333216          },
333217          "pedigree": {},
333218          "evidence": {},
333219          "signature": {
333220            "signature": {
333221              "publicKey": {}
333222            }
333223          },
333224          "modelCard": {
333225            "modelParameters": {
333226              "approach": {}
333227            },
333228            "quantitativeAnalysis": {
333229              "graphics": {}
333230            },
333231            "considerations": {}
333232          }
333233        },
333234        {
333235          "type": "library",
333236          "bom-ref": "pkg:npm/parseurl@1.3.3?package-id=7837722feef427b0",
333237          "supplier": {},
333238          "name": "parseurl",
333239          "version": "1.3.3",
333240          "licenses": [
333241            {
333242              "license": {
333243                "id": "MIT"
333244              }
333245            }
333246          ],
333247          "cpe": "cpe:2.3:a:parseurl:parseurl:1.3.3:*:*:*:*:*:*:*",
333248          "purl": "pkg:npm/parseurl@1.3.3",
333249          "swid": {
333250            "attachment": {}
333251          },
333252          "pedigree": {},
333253          "evidence": {},
333254          "signature": {
333255            "signature": {
333256              "publicKey": {}
333257            }
333258          },
333259          "modelCard": {
333260            "modelParameters": {
333261              "approach": {}
333262            },
333263            "quantitativeAnalysis": {
333264              "graphics": {}
333265            },
333266            "considerations": {}
333267          }
333268        },
333269        {
333270          "type": "library",
333271          "bom-ref": "pkg:npm/pascalcase@0.1.1?package-id=31b2fc8a0ab447b",
333272          "supplier": {},
333273          "name": "pascalcase",
333274          "version": "0.1.1",
333275          "licenses": [
333276            {
333277              "license": {
333278                "id": "MIT"
333279              }
333280            }
333281          ],
333282          "cpe": "cpe:2.3:a:pascalcase:pascalcase:0.1.1:*:*:*:*:*:*:*",
333283          "purl": "pkg:npm/pascalcase@0.1.1",
333284          "swid": {
333285            "attachment": {}
333286          },
333287          "pedigree": {},
333288          "evidence": {},
333289          "signature": {
333290            "signature": {
333291              "publicKey": {}
333292            }
333293          },
333294          "modelCard": {
333295            "modelParameters": {
333296              "approach": {}
333297            },
333298            "quantitativeAnalysis": {
333299              "graphics": {}
333300            },
333301            "considerations": {}
333302          }
333303        },
333304        {
333305          "type": "library",
333306          "bom-ref": "pkg:npm/patch-package@6.2.1?package-id=45fc37626f7c5fbc",
333307          "supplier": {},
333308          "name": "patch-package",
333309          "version": "6.2.1",
333310          "licenses": [
333311            {
333312              "license": {
333313                "id": "MIT"
333314              }
333315            }
333316          ],
333317          "cpe": "cpe:2.3:a:patch-package:patch-package:6.2.1:*:*:*:*:*:*:*",
333318          "purl": "pkg:npm/patch-package@6.2.1",
333319          "swid": {
333320            "attachment": {}
333321          },
333322          "pedigree": {},
333323          "evidence": {},
333324          "signature": {
333325            "signature": {
333326              "publicKey": {}
333327            }
333328          },
333329          "modelCard": {
333330            "modelParameters": {
333331              "approach": {}
333332            },
333333            "quantitativeAnalysis": {
333334              "graphics": {}
333335            },
333336            "considerations": {}
333337          }
333338        },
333339        {
333340          "type": "library",
333341          "bom-ref": "pkg:npm/patch-package@6.4.7?package-id=311beb23575c9675",
333342          "supplier": {},
333343          "name": "patch-package",
333344          "version": "6.4.7",
333345          "cpe": "cpe:2.3:a:patch-package:patch-package:6.4.7:*:*:*:*:*:*:*",
333346          "purl": "pkg:npm/patch-package@6.4.7",
333347          "swid": {
333348            "attachment": {}
333349          },
333350          "pedigree": {},
333351          "evidence": {},
333352          "signature": {
333353            "signature": {
333354              "publicKey": {}
333355            }
333356          },
333357          "modelCard": {
333358            "modelParameters": {
333359              "approach": {}
333360            },
333361            "quantitativeAnalysis": {
333362              "graphics": {}
333363            },
333364            "considerations": {}
333365          }
333366        },
333367        {
333368          "type": "library",
333369          "bom-ref": "pkg:npm/path-browserify@0.0.1?package-id=2106fb448613a61a",
333370          "supplier": {},
333371          "name": "path-browserify",
333372          "version": "0.0.1",
333373          "licenses": [
333374            {
333375              "license": {
333376                "id": "MIT"
333377              }
333378            }
333379          ],
333380          "cpe": "cpe:2.3:a:path-browserify:path-browserify:0.0.1:*:*:*:*:*:*:*",
333381          "purl": "pkg:npm/path-browserify@0.0.1",
333382          "swid": {
333383            "attachment": {}
333384          },
333385          "pedigree": {},
333386          "evidence": {},
333387          "signature": {
333388            "signature": {
333389              "publicKey": {}
333390            }
333391          },
333392          "modelCard": {
333393            "modelParameters": {
333394              "approach": {}
333395            },
333396            "quantitativeAnalysis": {
333397              "graphics": {}
333398            },
333399            "considerations": {}
333400          }
333401        },
333402        {
333403          "type": "library",
333404          "bom-ref": "pkg:npm/path-dirname@1.0.2?package-id=e9c68a37b691f1ff",
333405          "supplier": {},
333406          "name": "path-dirname",
333407          "version": "1.0.2",
333408          "licenses": [
333409            {
333410              "license": {
333411                "id": "MIT"
333412              }
333413            }
333414          ],
333415          "cpe": "cpe:2.3:a:path-dirname:path-dirname:1.0.2:*:*:*:*:*:*:*",
333416          "purl": "pkg:npm/path-dirname@1.0.2",
333417          "swid": {
333418            "attachment": {}
333419          },
333420          "pedigree": {},
333421          "evidence": {},
333422          "signature": {
333423            "signature": {
333424              "publicKey": {}
333425            }
333426          },
333427          "modelCard": {
333428            "modelParameters": {
333429              "approach": {}
333430            },
333431            "quantitativeAnalysis": {
333432              "graphics": {}
333433            },
333434            "considerations": {}
333435          }
333436        },
333437        {
333438          "type": "library",
333439          "bom-ref": "pkg:npm/path-exists@3.0.0?package-id=af7c0f633d70e35c",
333440          "supplier": {},
333441          "name": "path-exists",
333442          "version": "3.0.0",
333443          "licenses": [
333444            {
333445              "license": {
333446                "id": "MIT"
333447              }
333448            }
333449          ],
333450          "cpe": "cpe:2.3:a:path-exists:path-exists:3.0.0:*:*:*:*:*:*:*",
333451          "purl": "pkg:npm/path-exists@3.0.0",
333452          "swid": {
333453            "attachment": {}
333454          },
333455          "pedigree": {},
333456          "evidence": {},
333457          "signature": {
333458            "signature": {
333459              "publicKey": {}
333460            }
333461          },
333462          "modelCard": {
333463            "modelParameters": {
333464              "approach": {}
333465            },
333466            "quantitativeAnalysis": {
333467              "graphics": {}
333468            },
333469            "considerations": {}
333470          }
333471        },
333472        {
333473          "type": "library",
333474          "bom-ref": "pkg:npm/path-exists@4.0.0?package-id=2aee643c9e3d5aea",
333475          "supplier": {},
333476          "name": "path-exists",
333477          "version": "4.0.0",
333478          "cpe": "cpe:2.3:a:path-exists:path-exists:4.0.0:*:*:*:*:*:*:*",
333479          "purl": "pkg:npm/path-exists@4.0.0",
333480          "swid": {
333481            "attachment": {}
333482          },
333483          "pedigree": {},
333484          "evidence": {},
333485          "signature": {
333486            "signature": {
333487              "publicKey": {}
333488            }
333489          },
333490          "modelCard": {
333491            "modelParameters": {
333492              "approach": {}
333493            },
333494            "quantitativeAnalysis": {
333495              "graphics": {}
333496            },
333497            "considerations": {}
333498          }
333499        },
333500        {
333501          "type": "library",
333502          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=ec076698e4ff14d9",
333503          "supplier": {},
333504          "name": "path-is-absolute",
333505          "version": "1.0.1",
333506          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
333507          "purl": "pkg:npm/path-is-absolute@1.0.1",
333508          "swid": {
333509            "attachment": {}
333510          },
333511          "pedigree": {},
333512          "evidence": {},
333513          "signature": {
333514            "signature": {
333515              "publicKey": {}
333516            }
333517          },
333518          "modelCard": {
333519            "modelParameters": {
333520              "approach": {}
333521            },
333522            "quantitativeAnalysis": {
333523              "graphics": {}
333524            },
333525            "considerations": {}
333526          }
333527        },
333528        {
333529          "type": "library",
333530          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=63efebde31dd6c2e",
333531          "supplier": {},
333532          "name": "path-is-absolute",
333533          "version": "1.0.1",
333534          "licenses": [
333535            {
333536              "license": {
333537                "id": "MIT"
333538              }
333539            }
333540          ],
333541          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
333542          "purl": "pkg:npm/path-is-absolute@1.0.1",
333543          "swid": {
333544            "attachment": {}
333545          },
333546          "pedigree": {},
333547          "evidence": {},
333548          "signature": {
333549            "signature": {
333550              "publicKey": {}
333551            }
333552          },
333553          "modelCard": {
333554            "modelParameters": {
333555              "approach": {}
333556            },
333557            "quantitativeAnalysis": {
333558              "graphics": {}
333559            },
333560            "considerations": {}
333561          }
333562        },
333563        {
333564          "type": "library",
333565          "bom-ref": "pkg:npm/path-is-inside@1.0.2?package-id=15494330bf8439ac",
333566          "supplier": {},
333567          "name": "path-is-inside",
333568          "version": "1.0.2",
333569          "licenses": [
333570            {
333571              "license": {
333572                "name": "(WTFPL OR MIT)"
333573              }
333574            }
333575          ],
333576          "cpe": "cpe:2.3:a:path-is-inside:path-is-inside:1.0.2:*:*:*:*:*:*:*",
333577          "purl": "pkg:npm/path-is-inside@1.0.2",
333578          "swid": {
333579            "attachment": {}
333580          },
333581          "pedigree": {},
333582          "evidence": {},
333583          "signature": {
333584            "signature": {
333585              "publicKey": {}
333586            }
333587          },
333588          "modelCard": {
333589            "modelParameters": {
333590              "approach": {}
333591            },
333592            "quantitativeAnalysis": {
333593              "graphics": {}
333594            },
333595            "considerations": {}
333596          }
333597        },
333598        {
333599          "type": "library",
333600          "bom-ref": "pkg:npm/path-key@2.0.1?package-id=25ad1fccaa12bbab",
333601          "supplier": {},
333602          "name": "path-key",
333603          "version": "2.0.1",
333604          "licenses": [
333605            {
333606              "license": {
333607                "id": "MIT"
333608              }
333609            }
333610          ],
333611          "cpe": "cpe:2.3:a:path-key:path-key:2.0.1:*:*:*:*:*:*:*",
333612          "purl": "pkg:npm/path-key@2.0.1",
333613          "swid": {
333614            "attachment": {}
333615          },
333616          "pedigree": {},
333617          "evidence": {},
333618          "signature": {
333619            "signature": {
333620              "publicKey": {}
333621            }
333622          },
333623          "modelCard": {
333624            "modelParameters": {
333625              "approach": {}
333626            },
333627            "quantitativeAnalysis": {
333628              "graphics": {}
333629            },
333630            "considerations": {}
333631          }
333632        },
333633        {
333634          "type": "library",
333635          "bom-ref": "pkg:npm/path-key@3.1.1?package-id=be67c15828e3e42f",
333636          "supplier": {},
333637          "name": "path-key",
333638          "version": "3.1.1",
333639          "cpe": "cpe:2.3:a:path-key:path-key:3.1.1:*:*:*:*:*:*:*",
333640          "purl": "pkg:npm/path-key@3.1.1",
333641          "swid": {
333642            "attachment": {}
333643          },
333644          "pedigree": {},
333645          "evidence": {},
333646          "signature": {
333647            "signature": {
333648              "publicKey": {}
333649            }
333650          },
333651          "modelCard": {
333652            "modelParameters": {
333653              "approach": {}
333654            },
333655            "quantitativeAnalysis": {
333656              "graphics": {}
333657            },
333658            "considerations": {}
333659          }
333660        },
333661        {
333662          "type": "library",
333663          "bom-ref": "pkg:npm/path-parse@1.0.6?package-id=f1487de331d27b67",
333664          "supplier": {},
333665          "name": "path-parse",
333666          "version": "1.0.6",
333667          "licenses": [
333668            {
333669              "license": {
333670                "id": "MIT"
333671              }
333672            }
333673          ],
333674          "cpe": "cpe:2.3:a:path-parse:path-parse:1.0.6:*:*:*:*:*:*:*",
333675          "purl": "pkg:npm/path-parse@1.0.6",
333676          "swid": {
333677            "attachment": {}
333678          },
333679          "pedigree": {},
333680          "evidence": {},
333681          "signature": {
333682            "signature": {
333683              "publicKey": {}
333684            }
333685          },
333686          "modelCard": {
333687            "modelParameters": {
333688              "approach": {}
333689            },
333690            "quantitativeAnalysis": {
333691              "graphics": {}
333692            },
333693            "considerations": {}
333694          }
333695        },
333696        {
333697          "type": "library",
333698          "bom-ref": "pkg:npm/path-to-regexp@0.1.7?package-id=e51d6c6e1168ef53",
333699          "supplier": {},
333700          "name": "path-to-regexp",
333701          "version": "0.1.7",
333702          "licenses": [
333703            {
333704              "license": {
333705                "id": "MIT"
333706              }
333707            }
333708          ],
333709          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:0.1.7:*:*:*:*:*:*:*",
333710          "purl": "pkg:npm/path-to-regexp@0.1.7",
333711          "swid": {
333712            "attachment": {}
333713          },
333714          "pedigree": {},
333715          "evidence": {},
333716          "signature": {
333717            "signature": {
333718              "publicKey": {}
333719            }
333720          },
333721          "modelCard": {
333722            "modelParameters": {
333723              "approach": {}
333724            },
333725            "quantitativeAnalysis": {
333726              "graphics": {}
333727            },
333728            "considerations": {}
333729          }
333730        },
333731        {
333732          "type": "library",
333733          "bom-ref": "pkg:npm/path-type@3.0.0?package-id=fa7835cbc3b97160",
333734          "supplier": {},
333735          "name": "path-type",
333736          "version": "3.0.0",
333737          "licenses": [
333738            {
333739              "license": {
333740                "id": "MIT"
333741              }
333742            }
333743          ],
333744          "cpe": "cpe:2.3:a:path-type:path-type:3.0.0:*:*:*:*:*:*:*",
333745          "purl": "pkg:npm/path-type@3.0.0",
333746          "swid": {
333747            "attachment": {}
333748          },
333749          "pedigree": {},
333750          "evidence": {},
333751          "signature": {
333752            "signature": {
333753              "publicKey": {}
333754            }
333755          },
333756          "modelCard": {
333757            "modelParameters": {
333758              "approach": {}
333759            },
333760            "quantitativeAnalysis": {
333761              "graphics": {}
333762            },
333763            "considerations": {}
333764          }
333765        },
333766        {
333767          "type": "library",
333768          "bom-ref": "pkg:npm/pbkdf2@3.0.17?package-id=360e47123f033ff3",
333769          "supplier": {},
333770          "name": "pbkdf2",
333771          "version": "3.0.17",
333772          "licenses": [
333773            {
333774              "license": {
333775                "id": "MIT"
333776              }
333777            }
333778          ],
333779          "cpe": "cpe:2.3:a:pbkdf2:pbkdf2:3.0.17:*:*:*:*:*:*:*",
333780          "purl": "pkg:npm/pbkdf2@3.0.17",
333781          "swid": {
333782            "attachment": {}
333783          },
333784          "pedigree": {},
333785          "evidence": {},
333786          "signature": {
333787            "signature": {
333788              "publicKey": {}
333789            }
333790          },
333791          "modelCard": {
333792            "modelParameters": {
333793              "approach": {}
333794            },
333795            "quantitativeAnalysis": {
333796              "graphics": {}
333797            },
333798            "considerations": {}
333799          }
333800        },
333801        {
333802          "type": "library",
333803          "bom-ref": "pkg:npm/performance-now@2.1.0?package-id=1f9e7e0e96f42aad",
333804          "supplier": {},
333805          "name": "performance-now",
333806          "version": "2.1.0",
333807          "licenses": [
333808            {
333809              "license": {
333810                "id": "MIT"
333811              }
333812            }
333813          ],
333814          "cpe": "cpe:2.3:a:performance-now:performance-now:2.1.0:*:*:*:*:*:*:*",
333815          "purl": "pkg:npm/performance-now@2.1.0",
333816          "swid": {
333817            "attachment": {}
333818          },
333819          "pedigree": {},
333820          "evidence": {},
333821          "signature": {
333822            "signature": {
333823              "publicKey": {}
333824            }
333825          },
333826          "modelCard": {
333827            "modelParameters": {
333828              "approach": {}
333829            },
333830            "quantitativeAnalysis": {
333831              "graphics": {}
333832            },
333833            "considerations": {}
333834          }
333835        },
333836        {
333837          "type": "library",
333838          "bom-ref": "pkg:npm/picocolors@1.0.0?package-id=90b8a17c0c3a911a",
333839          "supplier": {},
333840          "name": "picocolors",
333841          "version": "1.0.0",
333842          "cpe": "cpe:2.3:a:picocolors:picocolors:1.0.0:*:*:*:*:*:*:*",
333843          "purl": "pkg:npm/picocolors@1.0.0",
333844          "swid": {
333845            "attachment": {}
333846          },
333847          "pedigree": {},
333848          "evidence": {},
333849          "signature": {
333850            "signature": {
333851              "publicKey": {}
333852            }
333853          },
333854          "modelCard": {
333855            "modelParameters": {
333856              "approach": {}
333857            },
333858            "quantitativeAnalysis": {
333859              "graphics": {}
333860            },
333861            "considerations": {}
333862          }
333863        },
333864        {
333865          "type": "library",
333866          "bom-ref": "pkg:npm/picomatch@2.2.2?package-id=8655f465988fd9d8",
333867          "supplier": {},
333868          "name": "picomatch",
333869          "version": "2.2.2",
333870          "licenses": [
333871            {
333872              "license": {
333873                "id": "MIT"
333874              }
333875            }
333876          ],
333877          "cpe": "cpe:2.3:a:picomatch:picomatch:2.2.2:*:*:*:*:*:*:*",
333878          "purl": "pkg:npm/picomatch@2.2.2",
333879          "swid": {
333880            "attachment": {}
333881          },
333882          "pedigree": {},
333883          "evidence": {},
333884          "signature": {
333885            "signature": {
333886              "publicKey": {}
333887            }
333888          },
333889          "modelCard": {
333890            "modelParameters": {
333891              "approach": {}
333892            },
333893            "quantitativeAnalysis": {
333894              "graphics": {}
333895            },
333896            "considerations": {}
333897          }
333898        },
333899        {
333900          "type": "library",
333901          "bom-ref": "pkg:npm/picomatch@2.3.0?package-id=f54a001bdd7adc19",
333902          "supplier": {},
333903          "name": "picomatch",
333904          "version": "2.3.0",
333905          "cpe": "cpe:2.3:a:picomatch:picomatch:2.3.0:*:*:*:*:*:*:*",
333906          "purl": "pkg:npm/picomatch@2.3.0",
333907          "swid": {
333908            "attachment": {}
333909          },
333910          "pedigree": {},
333911          "evidence": {},
333912          "signature": {
333913            "signature": {
333914              "publicKey": {}
333915            }
333916          },
333917          "modelCard": {
333918            "modelParameters": {
333919              "approach": {}
333920            },
333921            "quantitativeAnalysis": {
333922              "graphics": {}
333923            },
333924            "considerations": {}
333925          }
333926        },
333927        {
333928          "type": "library",
333929          "bom-ref": "pkg:npm/pify@4.0.1?package-id=ce60dbe1432661fd",
333930          "supplier": {},
333931          "name": "pify",
333932          "version": "4.0.1",
333933          "licenses": [
333934            {
333935              "license": {
333936                "id": "MIT"
333937              }
333938            }
333939          ],
333940          "cpe": "cpe:2.3:a:pify:pify:4.0.1:*:*:*:*:*:*:*",
333941          "purl": "pkg:npm/pify@4.0.1",
333942          "swid": {
333943            "attachment": {}
333944          },
333945          "pedigree": {},
333946          "evidence": {},
333947          "signature": {
333948            "signature": {
333949              "publicKey": {}
333950            }
333951          },
333952          "modelCard": {
333953            "modelParameters": {
333954              "approach": {}
333955            },
333956            "quantitativeAnalysis": {
333957              "graphics": {}
333958            },
333959            "considerations": {}
333960          }
333961        },
333962        {
333963          "type": "library",
333964          "bom-ref": "pkg:npm/pinkie@2.0.4?package-id=2b435bfd00559c92",
333965          "supplier": {},
333966          "name": "pinkie",
333967          "version": "2.0.4",
333968          "licenses": [
333969            {
333970              "license": {
333971                "id": "MIT"
333972              }
333973            }
333974          ],
333975          "cpe": "cpe:2.3:a:pinkie:pinkie:2.0.4:*:*:*:*:*:*:*",
333976          "purl": "pkg:npm/pinkie@2.0.4",
333977          "swid": {
333978            "attachment": {}
333979          },
333980          "pedigree": {},
333981          "evidence": {},
333982          "signature": {
333983            "signature": {
333984              "publicKey": {}
333985            }
333986          },
333987          "modelCard": {
333988            "modelParameters": {
333989              "approach": {}
333990            },
333991            "quantitativeAnalysis": {
333992              "graphics": {}
333993            },
333994            "considerations": {}
333995          }
333996        },
333997        {
333998          "type": "library",
333999          "bom-ref": "pkg:npm/pinkie-promise@2.0.1?package-id=d9e4d2b200a9349a",
334000          "supplier": {},
334001          "name": "pinkie-promise",
334002          "version": "2.0.1",
334003          "licenses": [
334004            {
334005              "license": {
334006                "id": "MIT"
334007              }
334008            }
334009          ],
334010          "cpe": "cpe:2.3:a:pinkie-promise:pinkie-promise:2.0.1:*:*:*:*:*:*:*",
334011          "purl": "pkg:npm/pinkie-promise@2.0.1",
334012          "swid": {
334013            "attachment": {}
334014          },
334015          "pedigree": {},
334016          "evidence": {},
334017          "signature": {
334018            "signature": {
334019              "publicKey": {}
334020            }
334021          },
334022          "modelCard": {
334023            "modelParameters": {
334024              "approach": {}
334025            },
334026            "quantitativeAnalysis": {
334027              "graphics": {}
334028            },
334029            "considerations": {}
334030          }
334031        },
334032        {
334033          "type": "library",
334034          "bom-ref": "pkg:npm/pkg-dir@3.0.0?package-id=ba8b2adac549ac5f",
334035          "supplier": {},
334036          "name": "pkg-dir",
334037          "version": "3.0.0",
334038          "licenses": [
334039            {
334040              "license": {
334041                "id": "MIT"
334042              }
334043            }
334044          ],
334045          "cpe": "cpe:2.3:a:pkg-dir:pkg-dir:3.0.0:*:*:*:*:*:*:*",
334046          "purl": "pkg:npm/pkg-dir@3.0.0",
334047          "swid": {
334048            "attachment": {}
334049          },
334050          "pedigree": {},
334051          "evidence": {},
334052          "signature": {
334053            "signature": {
334054              "publicKey": {}
334055            }
334056          },
334057          "modelCard": {
334058            "modelParameters": {
334059              "approach": {}
334060            },
334061            "quantitativeAnalysis": {
334062              "graphics": {}
334063            },
334064            "considerations": {}
334065          }
334066        },
334067        {
334068          "type": "library",
334069          "bom-ref": "pkg:npm/pkg-dir@4.2.0?package-id=96e3abb5ab075eea",
334070          "supplier": {},
334071          "name": "pkg-dir",
334072          "version": "4.2.0",
334073          "cpe": "cpe:2.3:a:pkg-dir:pkg-dir:4.2.0:*:*:*:*:*:*:*",
334074          "purl": "pkg:npm/pkg-dir@4.2.0",
334075          "swid": {
334076            "attachment": {}
334077          },
334078          "pedigree": {},
334079          "evidence": {},
334080          "signature": {
334081            "signature": {
334082              "publicKey": {}
334083            }
334084          },
334085          "modelCard": {
334086            "modelParameters": {
334087              "approach": {}
334088            },
334089            "quantitativeAnalysis": {
334090              "graphics": {}
334091            },
334092            "considerations": {}
334093          }
334094        },
334095        {
334096          "type": "library",
334097          "bom-ref": "pkg:npm/pkg-up@2.0.0?package-id=3a917d27e3e19195",
334098          "supplier": {},
334099          "name": "pkg-up",
334100          "version": "2.0.0",
334101          "licenses": [
334102            {
334103              "license": {
334104                "id": "MIT"
334105              }
334106            }
334107          ],
334108          "cpe": "cpe:2.3:a:pkg-up:pkg-up:2.0.0:*:*:*:*:*:*:*",
334109          "purl": "pkg:npm/pkg-up@2.0.0",
334110          "swid": {
334111            "attachment": {}
334112          },
334113          "pedigree": {},
334114          "evidence": {},
334115          "signature": {
334116            "signature": {
334117              "publicKey": {}
334118            }
334119          },
334120          "modelCard": {
334121            "modelParameters": {
334122              "approach": {}
334123            },
334124            "quantitativeAnalysis": {
334125              "graphics": {}
334126            },
334127            "considerations": {}
334128          }
334129        },
334130        {
334131          "type": "library",
334132          "bom-ref": "pkg:npm/portfinder@1.0.26?package-id=eac9a95db5b0879a",
334133          "supplier": {},
334134          "name": "portfinder",
334135          "version": "1.0.26",
334136          "licenses": [
334137            {
334138              "license": {
334139                "id": "MIT"
334140              }
334141            }
334142          ],
334143          "cpe": "cpe:2.3:a:portfinder:portfinder:1.0.26:*:*:*:*:*:*:*",
334144          "purl": "pkg:npm/portfinder@1.0.26",
334145          "swid": {
334146            "attachment": {}
334147          },
334148          "pedigree": {},
334149          "evidence": {},
334150          "signature": {
334151            "signature": {
334152              "publicKey": {}
334153            }
334154          },
334155          "modelCard": {
334156            "modelParameters": {
334157              "approach": {}
334158            },
334159            "quantitativeAnalysis": {
334160              "graphics": {}
334161            },
334162            "considerations": {}
334163          }
334164        },
334165        {
334166          "type": "library",
334167          "bom-ref": "pkg:npm/posix-character-classes@0.1.1?package-id=594578edf526d2f7",
334168          "supplier": {},
334169          "name": "posix-character-classes",
334170          "version": "0.1.1",
334171          "licenses": [
334172            {
334173              "license": {
334174                "id": "MIT"
334175              }
334176            }
334177          ],
334178          "cpe": "cpe:2.3:a:posix-character-classes:posix-character-classes:0.1.1:*:*:*:*:*:*:*",
334179          "purl": "pkg:npm/posix-character-classes@0.1.1",
334180          "swid": {
334181            "attachment": {}
334182          },
334183          "pedigree": {},
334184          "evidence": {},
334185          "signature": {
334186            "signature": {
334187              "publicKey": {}
334188            }
334189          },
334190          "modelCard": {
334191            "modelParameters": {
334192              "approach": {}
334193            },
334194            "quantitativeAnalysis": {
334195              "graphics": {}
334196            },
334197            "considerations": {}
334198          }
334199        },
334200        {
334201          "type": "library",
334202          "bom-ref": "pkg:npm/postcss@7.0.27?package-id=246d7045cf33bca6",
334203          "supplier": {},
334204          "name": "postcss",
334205          "version": "7.0.27",
334206          "licenses": [
334207            {
334208              "license": {
334209                "id": "MIT"
334210              }
334211            }
334212          ],
334213          "cpe": "cpe:2.3:a:postcss:postcss:7.0.27:*:*:*:*:*:*:*",
334214          "purl": "pkg:npm/postcss@7.0.27",
334215          "swid": {
334216            "attachment": {}
334217          },
334218          "pedigree": {},
334219          "evidence": {},
334220          "signature": {
334221            "signature": {
334222              "publicKey": {}
334223            }
334224          },
334225          "modelCard": {
334226            "modelParameters": {
334227              "approach": {}
334228            },
334229            "quantitativeAnalysis": {
334230              "graphics": {}
334231            },
334232            "considerations": {}
334233          }
334234        },
334235        {
334236          "type": "library",
334237          "bom-ref": "pkg:npm/postcss-calc@7.0.2?package-id=2887da09cd05fb51",
334238          "supplier": {},
334239          "name": "postcss-calc",
334240          "version": "7.0.2",
334241          "licenses": [
334242            {
334243              "license": {
334244                "id": "MIT"
334245              }
334246            }
334247          ],
334248          "cpe": "cpe:2.3:a:postcss-calc:postcss-calc:7.0.2:*:*:*:*:*:*:*",
334249          "purl": "pkg:npm/postcss-calc@7.0.2",
334250          "swid": {
334251            "attachment": {}
334252          },
334253          "pedigree": {},
334254          "evidence": {},
334255          "signature": {
334256            "signature": {
334257              "publicKey": {}
334258            }
334259          },
334260          "modelCard": {
334261            "modelParameters": {
334262              "approach": {}
334263            },
334264            "quantitativeAnalysis": {
334265              "graphics": {}
334266            },
334267            "considerations": {}
334268          }
334269        },
334270        {
334271          "type": "library",
334272          "bom-ref": "pkg:npm/postcss-colormin@4.0.3?package-id=1075b84e9814a64c",
334273          "supplier": {},
334274          "name": "postcss-colormin",
334275          "version": "4.0.3",
334276          "licenses": [
334277            {
334278              "license": {
334279                "id": "MIT"
334280              }
334281            }
334282          ],
334283          "cpe": "cpe:2.3:a:postcss-colormin:postcss-colormin:4.0.3:*:*:*:*:*:*:*",
334284          "purl": "pkg:npm/postcss-colormin@4.0.3",
334285          "swid": {
334286            "attachment": {}
334287          },
334288          "pedigree": {},
334289          "evidence": {},
334290          "signature": {
334291            "signature": {
334292              "publicKey": {}
334293            }
334294          },
334295          "modelCard": {
334296            "modelParameters": {
334297              "approach": {}
334298            },
334299            "quantitativeAnalysis": {
334300              "graphics": {}
334301            },
334302            "considerations": {}
334303          }
334304        },
334305        {
334306          "type": "library",
334307          "bom-ref": "pkg:npm/postcss-convert-values@4.0.1?package-id=39911a4fd7dad9ba",
334308          "supplier": {},
334309          "name": "postcss-convert-values",
334310          "version": "4.0.1",
334311          "licenses": [
334312            {
334313              "license": {
334314                "id": "MIT"
334315              }
334316            }
334317          ],
334318          "cpe": "cpe:2.3:a:postcss-convert-values:postcss-convert-values:4.0.1:*:*:*:*:*:*:*",
334319          "purl": "pkg:npm/postcss-convert-values@4.0.1",
334320          "swid": {
334321            "attachment": {}
334322          },
334323          "pedigree": {},
334324          "evidence": {},
334325          "signature": {
334326            "signature": {
334327              "publicKey": {}
334328            }
334329          },
334330          "modelCard": {
334331            "modelParameters": {
334332              "approach": {}
334333            },
334334            "quantitativeAnalysis": {
334335              "graphics": {}
334336            },
334337            "considerations": {}
334338          }
334339        },
334340        {
334341          "type": "library",
334342          "bom-ref": "pkg:npm/postcss-discard-comments@4.0.2?package-id=3e4dfec1cd395e10",
334343          "supplier": {},
334344          "name": "postcss-discard-comments",
334345          "version": "4.0.2",
334346          "licenses": [
334347            {
334348              "license": {
334349                "id": "MIT"
334350              }
334351            }
334352          ],
334353          "cpe": "cpe:2.3:a:postcss-discard-comments:postcss-discard-comments:4.0.2:*:*:*:*:*:*:*",
334354          "purl": "pkg:npm/postcss-discard-comments@4.0.2",
334355          "swid": {
334356            "attachment": {}
334357          },
334358          "pedigree": {},
334359          "evidence": {},
334360          "signature": {
334361            "signature": {
334362              "publicKey": {}
334363            }
334364          },
334365          "modelCard": {
334366            "modelParameters": {
334367              "approach": {}
334368            },
334369            "quantitativeAnalysis": {
334370              "graphics": {}
334371            },
334372            "considerations": {}
334373          }
334374        },
334375        {
334376          "type": "library",
334377          "bom-ref": "pkg:npm/postcss-discard-duplicates@4.0.2?package-id=ce373ff9ffc9e72e",
334378          "supplier": {},
334379          "name": "postcss-discard-duplicates",
334380          "version": "4.0.2",
334381          "licenses": [
334382            {
334383              "license": {
334384                "id": "MIT"
334385              }
334386            }
334387          ],
334388          "cpe": "cpe:2.3:a:postcss-discard-duplicates:postcss-discard-duplicates:4.0.2:*:*:*:*:*:*:*",
334389          "purl": "pkg:npm/postcss-discard-duplicates@4.0.2",
334390          "swid": {
334391            "attachment": {}
334392          },
334393          "pedigree": {},
334394          "evidence": {},
334395          "signature": {
334396            "signature": {
334397              "publicKey": {}
334398            }
334399          },
334400          "modelCard": {
334401            "modelParameters": {
334402              "approach": {}
334403            },
334404            "quantitativeAnalysis": {
334405              "graphics": {}
334406            },
334407            "considerations": {}
334408          }
334409        },
334410        {
334411          "type": "library",
334412          "bom-ref": "pkg:npm/postcss-discard-empty@4.0.1?package-id=5f205034080ef129",
334413          "supplier": {},
334414          "name": "postcss-discard-empty",
334415          "version": "4.0.1",
334416          "licenses": [
334417            {
334418              "license": {
334419                "id": "MIT"
334420              }
334421            }
334422          ],
334423          "cpe": "cpe:2.3:a:postcss-discard-empty:postcss-discard-empty:4.0.1:*:*:*:*:*:*:*",
334424          "purl": "pkg:npm/postcss-discard-empty@4.0.1",
334425          "swid": {
334426            "attachment": {}
334427          },
334428          "pedigree": {},
334429          "evidence": {},
334430          "signature": {
334431            "signature": {
334432              "publicKey": {}
334433            }
334434          },
334435          "modelCard": {
334436            "modelParameters": {
334437              "approach": {}
334438            },
334439            "quantitativeAnalysis": {
334440              "graphics": {}
334441            },
334442            "considerations": {}
334443          }
334444        },
334445        {
334446          "type": "library",
334447          "bom-ref": "pkg:npm/postcss-discard-overridden@4.0.1?package-id=ac66f7015238d771",
334448          "supplier": {},
334449          "name": "postcss-discard-overridden",
334450          "version": "4.0.1",
334451          "licenses": [
334452            {
334453              "license": {
334454                "id": "MIT"
334455              }
334456            }
334457          ],
334458          "cpe": "cpe:2.3:a:postcss-discard-overridden:postcss-discard-overridden:4.0.1:*:*:*:*:*:*:*",
334459          "purl": "pkg:npm/postcss-discard-overridden@4.0.1",
334460          "swid": {
334461            "attachment": {}
334462          },
334463          "pedigree": {},
334464          "evidence": {},
334465          "signature": {
334466            "signature": {
334467              "publicKey": {}
334468            }
334469          },
334470          "modelCard": {
334471            "modelParameters": {
334472              "approach": {}
334473            },
334474            "quantitativeAnalysis": {
334475              "graphics": {}
334476            },
334477            "considerations": {}
334478          }
334479        },
334480        {
334481          "type": "library",
334482          "bom-ref": "pkg:npm/postcss-import@12.0.1?package-id=e9238285c3c0c403",
334483          "supplier": {},
334484          "name": "postcss-import",
334485          "version": "12.0.1",
334486          "licenses": [
334487            {
334488              "license": {
334489                "id": "MIT"
334490              }
334491            }
334492          ],
334493          "cpe": "cpe:2.3:a:postcss-import:postcss-import:12.0.1:*:*:*:*:*:*:*",
334494          "purl": "pkg:npm/postcss-import@12.0.1",
334495          "swid": {
334496            "attachment": {}
334497          },
334498          "pedigree": {},
334499          "evidence": {},
334500          "signature": {
334501            "signature": {
334502              "publicKey": {}
334503            }
334504          },
334505          "modelCard": {
334506            "modelParameters": {
334507              "approach": {}
334508            },
334509            "quantitativeAnalysis": {
334510              "graphics": {}
334511            },
334512            "considerations": {}
334513          }
334514        },
334515        {
334516          "type": "library",
334517          "bom-ref": "pkg:npm/postcss-load-config@2.1.0?package-id=de748ebac04b3320",
334518          "supplier": {},
334519          "name": "postcss-load-config",
334520          "version": "2.1.0",
334521          "licenses": [
334522            {
334523              "license": {
334524                "id": "MIT"
334525              }
334526            }
334527          ],
334528          "cpe": "cpe:2.3:a:postcss-load-config:postcss-load-config:2.1.0:*:*:*:*:*:*:*",
334529          "purl": "pkg:npm/postcss-load-config@2.1.0",
334530          "swid": {
334531            "attachment": {}
334532          },
334533          "pedigree": {},
334534          "evidence": {},
334535          "signature": {
334536            "signature": {
334537              "publicKey": {}
334538            }
334539          },
334540          "modelCard": {
334541            "modelParameters": {
334542              "approach": {}
334543            },
334544            "quantitativeAnalysis": {
334545              "graphics": {}
334546            },
334547            "considerations": {}
334548          }
334549        },
334550        {
334551          "type": "library",
334552          "bom-ref": "pkg:npm/postcss-loader@3.0.0?package-id=784d6ea551e576ee",
334553          "supplier": {},
334554          "name": "postcss-loader",
334555          "version": "3.0.0",
334556          "licenses": [
334557            {
334558              "license": {
334559                "id": "MIT"
334560              }
334561            }
334562          ],
334563          "cpe": "cpe:2.3:a:postcss-loader:postcss-loader:3.0.0:*:*:*:*:*:*:*",
334564          "purl": "pkg:npm/postcss-loader@3.0.0",
334565          "swid": {
334566            "attachment": {}
334567          },
334568          "pedigree": {},
334569          "evidence": {},
334570          "signature": {
334571            "signature": {
334572              "publicKey": {}
334573            }
334574          },
334575          "modelCard": {
334576            "modelParameters": {
334577              "approach": {}
334578            },
334579            "quantitativeAnalysis": {
334580              "graphics": {}
334581            },
334582            "considerations": {}
334583          }
334584        },
334585        {
334586          "type": "library",
334587          "bom-ref": "pkg:npm/postcss-merge-longhand@4.0.11?package-id=fd995756c137ec3d",
334588          "supplier": {},
334589          "name": "postcss-merge-longhand",
334590          "version": "4.0.11",
334591          "licenses": [
334592            {
334593              "license": {
334594                "id": "MIT"
334595              }
334596            }
334597          ],
334598          "cpe": "cpe:2.3:a:postcss-merge-longhand:postcss-merge-longhand:4.0.11:*:*:*:*:*:*:*",
334599          "purl": "pkg:npm/postcss-merge-longhand@4.0.11",
334600          "swid": {
334601            "attachment": {}
334602          },
334603          "pedigree": {},
334604          "evidence": {},
334605          "signature": {
334606            "signature": {
334607              "publicKey": {}
334608            }
334609          },
334610          "modelCard": {
334611            "modelParameters": {
334612              "approach": {}
334613            },
334614            "quantitativeAnalysis": {
334615              "graphics": {}
334616            },
334617            "considerations": {}
334618          }
334619        },
334620        {
334621          "type": "library",
334622          "bom-ref": "pkg:npm/postcss-merge-rules@4.0.3?package-id=260b237820203746",
334623          "supplier": {},
334624          "name": "postcss-merge-rules",
334625          "version": "4.0.3",
334626          "licenses": [
334627            {
334628              "license": {
334629                "id": "MIT"
334630              }
334631            }
334632          ],
334633          "cpe": "cpe:2.3:a:postcss-merge-rules:postcss-merge-rules:4.0.3:*:*:*:*:*:*:*",
334634          "purl": "pkg:npm/postcss-merge-rules@4.0.3",
334635          "swid": {
334636            "attachment": {}
334637          },
334638          "pedigree": {},
334639          "evidence": {},
334640          "signature": {
334641            "signature": {
334642              "publicKey": {}
334643            }
334644          },
334645          "modelCard": {
334646            "modelParameters": {
334647              "approach": {}
334648            },
334649            "quantitativeAnalysis": {
334650              "graphics": {}
334651            },
334652            "considerations": {}
334653          }
334654        },
334655        {
334656          "type": "library",
334657          "bom-ref": "pkg:npm/postcss-minify-font-values@4.0.2?package-id=3b050db57cb988ac",
334658          "supplier": {},
334659          "name": "postcss-minify-font-values",
334660          "version": "4.0.2",
334661          "licenses": [
334662            {
334663              "license": {
334664                "id": "MIT"
334665              }
334666            }
334667          ],
334668          "cpe": "cpe:2.3:a:postcss-minify-font-values:postcss-minify-font-values:4.0.2:*:*:*:*:*:*:*",
334669          "purl": "pkg:npm/postcss-minify-font-values@4.0.2",
334670          "swid": {
334671            "attachment": {}
334672          },
334673          "pedigree": {},
334674          "evidence": {},
334675          "signature": {
334676            "signature": {
334677              "publicKey": {}
334678            }
334679          },
334680          "modelCard": {
334681            "modelParameters": {
334682              "approach": {}
334683            },
334684            "quantitativeAnalysis": {
334685              "graphics": {}
334686            },
334687            "considerations": {}
334688          }
334689        },
334690        {
334691          "type": "library",
334692          "bom-ref": "pkg:npm/postcss-minify-gradients@4.0.2?package-id=da6f909de3c07682",
334693          "supplier": {},
334694          "name": "postcss-minify-gradients",
334695          "version": "4.0.2",
334696          "licenses": [
334697            {
334698              "license": {
334699                "id": "MIT"
334700              }
334701            }
334702          ],
334703          "cpe": "cpe:2.3:a:postcss-minify-gradients:postcss-minify-gradients:4.0.2:*:*:*:*:*:*:*",
334704          "purl": "pkg:npm/postcss-minify-gradients@4.0.2",
334705          "swid": {
334706            "attachment": {}
334707          },
334708          "pedigree": {},
334709          "evidence": {},
334710          "signature": {
334711            "signature": {
334712              "publicKey": {}
334713            }
334714          },
334715          "modelCard": {
334716            "modelParameters": {
334717              "approach": {}
334718            },
334719            "quantitativeAnalysis": {
334720              "graphics": {}
334721            },
334722            "considerations": {}
334723          }
334724        },
334725        {
334726          "type": "library",
334727          "bom-ref": "pkg:npm/postcss-minify-params@4.0.2?package-id=924998d027e0124b",
334728          "supplier": {},
334729          "name": "postcss-minify-params",
334730          "version": "4.0.2",
334731          "licenses": [
334732            {
334733              "license": {
334734                "id": "MIT"
334735              }
334736            }
334737          ],
334738          "cpe": "cpe:2.3:a:postcss-minify-params:postcss-minify-params:4.0.2:*:*:*:*:*:*:*",
334739          "purl": "pkg:npm/postcss-minify-params@4.0.2",
334740          "swid": {
334741            "attachment": {}
334742          },
334743          "pedigree": {},
334744          "evidence": {},
334745          "signature": {
334746            "signature": {
334747              "publicKey": {}
334748            }
334749          },
334750          "modelCard": {
334751            "modelParameters": {
334752              "approach": {}
334753            },
334754            "quantitativeAnalysis": {
334755              "graphics": {}
334756            },
334757            "considerations": {}
334758          }
334759        },
334760        {
334761          "type": "library",
334762          "bom-ref": "pkg:npm/postcss-minify-selectors@4.0.2?package-id=1c97c10f882d209b",
334763          "supplier": {},
334764          "name": "postcss-minify-selectors",
334765          "version": "4.0.2",
334766          "licenses": [
334767            {
334768              "license": {
334769                "id": "MIT"
334770              }
334771            }
334772          ],
334773          "cpe": "cpe:2.3:a:postcss-minify-selectors:postcss-minify-selectors:4.0.2:*:*:*:*:*:*:*",
334774          "purl": "pkg:npm/postcss-minify-selectors@4.0.2",
334775          "swid": {
334776            "attachment": {}
334777          },
334778          "pedigree": {},
334779          "evidence": {},
334780          "signature": {
334781            "signature": {
334782              "publicKey": {}
334783            }
334784          },
334785          "modelCard": {
334786            "modelParameters": {
334787              "approach": {}
334788            },
334789            "quantitativeAnalysis": {
334790              "graphics": {}
334791            },
334792            "considerations": {}
334793          }
334794        },
334795        {
334796          "type": "library",
334797          "bom-ref": "pkg:npm/postcss-modules-extract-imports@2.0.0?package-id=78cf0307c20ef65f",
334798          "supplier": {},
334799          "name": "postcss-modules-extract-imports",
334800          "version": "2.0.0",
334801          "licenses": [
334802            {
334803              "license": {
334804                "id": "ISC"
334805              }
334806            }
334807          ],
334808          "cpe": "cpe:2.3:a:postcss-modules-extract-imports:postcss-modules-extract-imports:2.0.0:*:*:*:*:*:*:*",
334809          "purl": "pkg:npm/postcss-modules-extract-imports@2.0.0",
334810          "swid": {
334811            "attachment": {}
334812          },
334813          "pedigree": {},
334814          "evidence": {},
334815          "signature": {
334816            "signature": {
334817              "publicKey": {}
334818            }
334819          },
334820          "modelCard": {
334821            "modelParameters": {
334822              "approach": {}
334823            },
334824            "quantitativeAnalysis": {
334825              "graphics": {}
334826            },
334827            "considerations": {}
334828          }
334829        },
334830        {
334831          "type": "library",
334832          "bom-ref": "pkg:npm/postcss-modules-local-by-default@3.0.2?package-id=431f5d7d099c64bc",
334833          "supplier": {},
334834          "name": "postcss-modules-local-by-default",
334835          "version": "3.0.2",
334836          "licenses": [
334837            {
334838              "license": {
334839                "id": "MIT"
334840              }
334841            }
334842          ],
334843          "cpe": "cpe:2.3:a:postcss-modules-local-by-default:postcss-modules-local-by-default:3.0.2:*:*:*:*:*:*:*",
334844          "purl": "pkg:npm/postcss-modules-local-by-default@3.0.2",
334845          "swid": {
334846            "attachment": {}
334847          },
334848          "pedigree": {},
334849          "evidence": {},
334850          "signature": {
334851            "signature": {
334852              "publicKey": {}
334853            }
334854          },
334855          "modelCard": {
334856            "modelParameters": {
334857              "approach": {}
334858            },
334859            "quantitativeAnalysis": {
334860              "graphics": {}
334861            },
334862            "considerations": {}
334863          }
334864        },
334865        {
334866          "type": "library",
334867          "bom-ref": "pkg:npm/postcss-modules-scope@2.2.0?package-id=f8c925c63ae1eac0",
334868          "supplier": {},
334869          "name": "postcss-modules-scope",
334870          "version": "2.2.0",
334871          "licenses": [
334872            {
334873              "license": {
334874                "id": "ISC"
334875              }
334876            }
334877          ],
334878          "cpe": "cpe:2.3:a:postcss-modules-scope:postcss-modules-scope:2.2.0:*:*:*:*:*:*:*",
334879          "purl": "pkg:npm/postcss-modules-scope@2.2.0",
334880          "swid": {
334881            "attachment": {}
334882          },
334883          "pedigree": {},
334884          "evidence": {},
334885          "signature": {
334886            "signature": {
334887              "publicKey": {}
334888            }
334889          },
334890          "modelCard": {
334891            "modelParameters": {
334892              "approach": {}
334893            },
334894            "quantitativeAnalysis": {
334895              "graphics": {}
334896            },
334897            "considerations": {}
334898          }
334899        },
334900        {
334901          "type": "library",
334902          "bom-ref": "pkg:npm/postcss-modules-values@3.0.0?package-id=2ba7ee6f26ef5a6b",
334903          "supplier": {},
334904          "name": "postcss-modules-values",
334905          "version": "3.0.0",
334906          "licenses": [
334907            {
334908              "license": {
334909                "id": "ISC"
334910              }
334911            }
334912          ],
334913          "cpe": "cpe:2.3:a:postcss-modules-values:postcss-modules-values:3.0.0:*:*:*:*:*:*:*",
334914          "purl": "pkg:npm/postcss-modules-values@3.0.0",
334915          "swid": {
334916            "attachment": {}
334917          },
334918          "pedigree": {},
334919          "evidence": {},
334920          "signature": {
334921            "signature": {
334922              "publicKey": {}
334923            }
334924          },
334925          "modelCard": {
334926            "modelParameters": {
334927              "approach": {}
334928            },
334929            "quantitativeAnalysis": {
334930              "graphics": {}
334931            },
334932            "considerations": {}
334933          }
334934        },
334935        {
334936          "type": "library",
334937          "bom-ref": "pkg:npm/postcss-normalize-charset@4.0.1?package-id=992f5f490c026e24",
334938          "supplier": {},
334939          "name": "postcss-normalize-charset",
334940          "version": "4.0.1",
334941          "licenses": [
334942            {
334943              "license": {
334944                "id": "MIT"
334945              }
334946            }
334947          ],
334948          "cpe": "cpe:2.3:a:postcss-normalize-charset:postcss-normalize-charset:4.0.1:*:*:*:*:*:*:*",
334949          "purl": "pkg:npm/postcss-normalize-charset@4.0.1",
334950          "swid": {
334951            "attachment": {}
334952          },
334953          "pedigree": {},
334954          "evidence": {},
334955          "signature": {
334956            "signature": {
334957              "publicKey": {}
334958            }
334959          },
334960          "modelCard": {
334961            "modelParameters": {
334962              "approach": {}
334963            },
334964            "quantitativeAnalysis": {
334965              "graphics": {}
334966            },
334967            "considerations": {}
334968          }
334969        },
334970        {
334971          "type": "library",
334972          "bom-ref": "pkg:npm/postcss-normalize-display-values@4.0.2?package-id=3087b710a7f9b59f",
334973          "supplier": {},
334974          "name": "postcss-normalize-display-values",
334975          "version": "4.0.2",
334976          "licenses": [
334977            {
334978              "license": {
334979                "id": "MIT"
334980              }
334981            }
334982          ],
334983          "cpe": "cpe:2.3:a:postcss-normalize-display-values:postcss-normalize-display-values:4.0.2:*:*:*:*:*:*:*",
334984          "purl": "pkg:npm/postcss-normalize-display-values@4.0.2",
334985          "swid": {
334986            "attachment": {}
334987          },
334988          "pedigree": {},
334989          "evidence": {},
334990          "signature": {
334991            "signature": {
334992              "publicKey": {}
334993            }
334994          },
334995          "modelCard": {
334996            "modelParameters": {
334997              "approach": {}
334998            },
334999            "quantitativeAnalysis": {
335000              "graphics": {}
335001            },
335002            "considerations": {}
335003          }
335004        },
335005        {
335006          "type": "library",
335007          "bom-ref": "pkg:npm/postcss-normalize-positions@4.0.2?package-id=13a1b159e2363643",
335008          "supplier": {},
335009          "name": "postcss-normalize-positions",
335010          "version": "4.0.2",
335011          "licenses": [
335012            {
335013              "license": {
335014                "id": "MIT"
335015              }
335016            }
335017          ],
335018          "cpe": "cpe:2.3:a:postcss-normalize-positions:postcss-normalize-positions:4.0.2:*:*:*:*:*:*:*",
335019          "purl": "pkg:npm/postcss-normalize-positions@4.0.2",
335020          "swid": {
335021            "attachment": {}
335022          },
335023          "pedigree": {},
335024          "evidence": {},
335025          "signature": {
335026            "signature": {
335027              "publicKey": {}
335028            }
335029          },
335030          "modelCard": {
335031            "modelParameters": {
335032              "approach": {}
335033            },
335034            "quantitativeAnalysis": {
335035              "graphics": {}
335036            },
335037            "considerations": {}
335038          }
335039        },
335040        {
335041          "type": "library",
335042          "bom-ref": "pkg:npm/postcss-normalize-repeat-style@4.0.2?package-id=75b3e01e4566f9b0",
335043          "supplier": {},
335044          "name": "postcss-normalize-repeat-style",
335045          "version": "4.0.2",
335046          "licenses": [
335047            {
335048              "license": {
335049                "id": "MIT"
335050              }
335051            }
335052          ],
335053          "cpe": "cpe:2.3:a:postcss-normalize-repeat-style:postcss-normalize-repeat-style:4.0.2:*:*:*:*:*:*:*",
335054          "purl": "pkg:npm/postcss-normalize-repeat-style@4.0.2",
335055          "swid": {
335056            "attachment": {}
335057          },
335058          "pedigree": {},
335059          "evidence": {},
335060          "signature": {
335061            "signature": {
335062              "publicKey": {}
335063            }
335064          },
335065          "modelCard": {
335066            "modelParameters": {
335067              "approach": {}
335068            },
335069            "quantitativeAnalysis": {
335070              "graphics": {}
335071            },
335072            "considerations": {}
335073          }
335074        },
335075        {
335076          "type": "library",
335077          "bom-ref": "pkg:npm/postcss-normalize-string@4.0.2?package-id=563a19e0f405a82",
335078          "supplier": {},
335079          "name": "postcss-normalize-string",
335080          "version": "4.0.2",
335081          "licenses": [
335082            {
335083              "license": {
335084                "id": "MIT"
335085              }
335086            }
335087          ],
335088          "cpe": "cpe:2.3:a:postcss-normalize-string:postcss-normalize-string:4.0.2:*:*:*:*:*:*:*",
335089          "purl": "pkg:npm/postcss-normalize-string@4.0.2",
335090          "swid": {
335091            "attachment": {}
335092          },
335093          "pedigree": {},
335094          "evidence": {},
335095          "signature": {
335096            "signature": {
335097              "publicKey": {}
335098            }
335099          },
335100          "modelCard": {
335101            "modelParameters": {
335102              "approach": {}
335103            },
335104            "quantitativeAnalysis": {
335105              "graphics": {}
335106            },
335107            "considerations": {}
335108          }
335109        },
335110        {
335111          "type": "library",
335112          "bom-ref": "pkg:npm/postcss-normalize-timing-functions@4.0.2?package-id=83f8f4618880d9d6",
335113          "supplier": {},
335114          "name": "postcss-normalize-timing-functions",
335115          "version": "4.0.2",
335116          "licenses": [
335117            {
335118              "license": {
335119                "id": "MIT"
335120              }
335121            }
335122          ],
335123          "cpe": "cpe:2.3:a:postcss-normalize-timing-functions:postcss-normalize-timing-functions:4.0.2:*:*:*:*:*:*:*",
335124          "purl": "pkg:npm/postcss-normalize-timing-functions@4.0.2",
335125          "swid": {
335126            "attachment": {}
335127          },
335128          "pedigree": {},
335129          "evidence": {},
335130          "signature": {
335131            "signature": {
335132              "publicKey": {}
335133            }
335134          },
335135          "modelCard": {
335136            "modelParameters": {
335137              "approach": {}
335138            },
335139            "quantitativeAnalysis": {
335140              "graphics": {}
335141            },
335142            "considerations": {}
335143          }
335144        },
335145        {
335146          "type": "library",
335147          "bom-ref": "pkg:npm/postcss-normalize-unicode@4.0.1?package-id=1bd095fda8e2d03b",
335148          "supplier": {},
335149          "name": "postcss-normalize-unicode",
335150          "version": "4.0.1",
335151          "licenses": [
335152            {
335153              "license": {
335154                "id": "MIT"
335155              }
335156            }
335157          ],
335158          "cpe": "cpe:2.3:a:postcss-normalize-unicode:postcss-normalize-unicode:4.0.1:*:*:*:*:*:*:*",
335159          "purl": "pkg:npm/postcss-normalize-unicode@4.0.1",
335160          "swid": {
335161            "attachment": {}
335162          },
335163          "pedigree": {},
335164          "evidence": {},
335165          "signature": {
335166            "signature": {
335167              "publicKey": {}
335168            }
335169          },
335170          "modelCard": {
335171            "modelParameters": {
335172              "approach": {}
335173            },
335174            "quantitativeAnalysis": {
335175              "graphics": {}
335176            },
335177            "considerations": {}
335178          }
335179        },
335180        {
335181          "type": "library",
335182          "bom-ref": "pkg:npm/postcss-normalize-url@4.0.1?package-id=dab635957f6883e",
335183          "supplier": {},
335184          "name": "postcss-normalize-url",
335185          "version": "4.0.1",
335186          "licenses": [
335187            {
335188              "license": {
335189                "id": "MIT"
335190              }
335191            }
335192          ],
335193          "cpe": "cpe:2.3:a:postcss-normalize-url:postcss-normalize-url:4.0.1:*:*:*:*:*:*:*",
335194          "purl": "pkg:npm/postcss-normalize-url@4.0.1",
335195          "swid": {
335196            "attachment": {}
335197          },
335198          "pedigree": {},
335199          "evidence": {},
335200          "signature": {
335201            "signature": {
335202              "publicKey": {}
335203            }
335204          },
335205          "modelCard": {
335206            "modelParameters": {
335207              "approach": {}
335208            },
335209            "quantitativeAnalysis": {
335210              "graphics": {}
335211            },
335212            "considerations": {}
335213          }
335214        },
335215        {
335216          "type": "library",
335217          "bom-ref": "pkg:npm/postcss-normalize-whitespace@4.0.2?package-id=d0d558d27a083d78",
335218          "supplier": {},
335219          "name": "postcss-normalize-whitespace",
335220          "version": "4.0.2",
335221          "licenses": [
335222            {
335223              "license": {
335224                "id": "MIT"
335225              }
335226            }
335227          ],
335228          "cpe": "cpe:2.3:a:postcss-normalize-whitespace:postcss-normalize-whitespace:4.0.2:*:*:*:*:*:*:*",
335229          "purl": "pkg:npm/postcss-normalize-whitespace@4.0.2",
335230          "swid": {
335231            "attachment": {}
335232          },
335233          "pedigree": {},
335234          "evidence": {},
335235          "signature": {
335236            "signature": {
335237              "publicKey": {}
335238            }
335239          },
335240          "modelCard": {
335241            "modelParameters": {
335242              "approach": {}
335243            },
335244            "quantitativeAnalysis": {
335245              "graphics": {}
335246            },
335247            "considerations": {}
335248          }
335249        },
335250        {
335251          "type": "library",
335252          "bom-ref": "pkg:npm/postcss-ordered-values@4.1.2?package-id=cea3f2c3dcba83db",
335253          "supplier": {},
335254          "name": "postcss-ordered-values",
335255          "version": "4.1.2",
335256          "licenses": [
335257            {
335258              "license": {
335259                "id": "MIT"
335260              }
335261            }
335262          ],
335263          "cpe": "cpe:2.3:a:postcss-ordered-values:postcss-ordered-values:4.1.2:*:*:*:*:*:*:*",
335264          "purl": "pkg:npm/postcss-ordered-values@4.1.2",
335265          "swid": {
335266            "attachment": {}
335267          },
335268          "pedigree": {},
335269          "evidence": {},
335270          "signature": {
335271            "signature": {
335272              "publicKey": {}
335273            }
335274          },
335275          "modelCard": {
335276            "modelParameters": {
335277              "approach": {}
335278            },
335279            "quantitativeAnalysis": {
335280              "graphics": {}
335281            },
335282            "considerations": {}
335283          }
335284        },
335285        {
335286          "type": "library",
335287          "bom-ref": "pkg:npm/postcss-reduce-initial@4.0.3?package-id=5e098d4ba83a4055",
335288          "supplier": {},
335289          "name": "postcss-reduce-initial",
335290          "version": "4.0.3",
335291          "licenses": [
335292            {
335293              "license": {
335294                "id": "MIT"
335295              }
335296            }
335297          ],
335298          "cpe": "cpe:2.3:a:postcss-reduce-initial:postcss-reduce-initial:4.0.3:*:*:*:*:*:*:*",
335299          "purl": "pkg:npm/postcss-reduce-initial@4.0.3",
335300          "swid": {
335301            "attachment": {}
335302          },
335303          "pedigree": {},
335304          "evidence": {},
335305          "signature": {
335306            "signature": {
335307              "publicKey": {}
335308            }
335309          },
335310          "modelCard": {
335311            "modelParameters": {
335312              "approach": {}
335313            },
335314            "quantitativeAnalysis": {
335315              "graphics": {}
335316            },
335317            "considerations": {}
335318          }
335319        },
335320        {
335321          "type": "library",
335322          "bom-ref": "pkg:npm/postcss-reduce-transforms@4.0.2?package-id=ca27c2b2c773c37f",
335323          "supplier": {},
335324          "name": "postcss-reduce-transforms",
335325          "version": "4.0.2",
335326          "licenses": [
335327            {
335328              "license": {
335329                "id": "MIT"
335330              }
335331            }
335332          ],
335333          "cpe": "cpe:2.3:a:postcss-reduce-transforms:postcss-reduce-transforms:4.0.2:*:*:*:*:*:*:*",
335334          "purl": "pkg:npm/postcss-reduce-transforms@4.0.2",
335335          "swid": {
335336            "attachment": {}
335337          },
335338          "pedigree": {},
335339          "evidence": {},
335340          "signature": {
335341            "signature": {
335342              "publicKey": {}
335343            }
335344          },
335345          "modelCard": {
335346            "modelParameters": {
335347              "approach": {}
335348            },
335349            "quantitativeAnalysis": {
335350              "graphics": {}
335351            },
335352            "considerations": {}
335353          }
335354        },
335355        {
335356          "type": "library",
335357          "bom-ref": "pkg:npm/postcss-selector-parser@6.0.2?package-id=a2e46a351dde45eb",
335358          "supplier": {},
335359          "name": "postcss-selector-parser",
335360          "version": "6.0.2",
335361          "licenses": [
335362            {
335363              "license": {
335364                "id": "MIT"
335365              }
335366            }
335367          ],
335368          "cpe": "cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:6.0.2:*:*:*:*:*:*:*",
335369          "purl": "pkg:npm/postcss-selector-parser@6.0.2",
335370          "swid": {
335371            "attachment": {}
335372          },
335373          "pedigree": {},
335374          "evidence": {},
335375          "signature": {
335376            "signature": {
335377              "publicKey": {}
335378            }
335379          },
335380          "modelCard": {
335381            "modelParameters": {
335382              "approach": {}
335383            },
335384            "quantitativeAnalysis": {
335385              "graphics": {}
335386            },
335387            "considerations": {}
335388          }
335389        },
335390        {
335391          "type": "library",
335392          "bom-ref": "pkg:npm/postcss-svgo@4.0.2?package-id=ba2251abcf979f57",
335393          "supplier": {},
335394          "name": "postcss-svgo",
335395          "version": "4.0.2",
335396          "licenses": [
335397            {
335398              "license": {
335399                "id": "MIT"
335400              }
335401            }
335402          ],
335403          "cpe": "cpe:2.3:a:postcss-svgo:postcss-svgo:4.0.2:*:*:*:*:*:*:*",
335404          "purl": "pkg:npm/postcss-svgo@4.0.2",
335405          "swid": {
335406            "attachment": {}
335407          },
335408          "pedigree": {},
335409          "evidence": {},
335410          "signature": {
335411            "signature": {
335412              "publicKey": {}
335413            }
335414          },
335415          "modelCard": {
335416            "modelParameters": {
335417              "approach": {}
335418            },
335419            "quantitativeAnalysis": {
335420              "graphics": {}
335421            },
335422            "considerations": {}
335423          }
335424        },
335425        {
335426          "type": "library",
335427          "bom-ref": "pkg:npm/postcss-unique-selectors@4.0.1?package-id=a96d3dbb52682610",
335428          "supplier": {},
335429          "name": "postcss-unique-selectors",
335430          "version": "4.0.1",
335431          "licenses": [
335432            {
335433              "license": {
335434                "id": "MIT"
335435              }
335436            }
335437          ],
335438          "cpe": "cpe:2.3:a:postcss-unique-selectors:postcss-unique-selectors:4.0.1:*:*:*:*:*:*:*",
335439          "purl": "pkg:npm/postcss-unique-selectors@4.0.1",
335440          "swid": {
335441            "attachment": {}
335442          },
335443          "pedigree": {},
335444          "evidence": {},
335445          "signature": {
335446            "signature": {
335447              "publicKey": {}
335448            }
335449          },
335450          "modelCard": {
335451            "modelParameters": {
335452              "approach": {}
335453            },
335454            "quantitativeAnalysis": {
335455              "graphics": {}
335456            },
335457            "considerations": {}
335458          }
335459        },
335460        {
335461          "type": "library",
335462          "bom-ref": "pkg:npm/postcss-value-parser@4.1.0?package-id=7471211623391218",
335463          "supplier": {},
335464          "name": "postcss-value-parser",
335465          "version": "4.1.0",
335466          "licenses": [
335467            {
335468              "license": {
335469                "id": "MIT"
335470              }
335471            }
335472          ],
335473          "cpe": "cpe:2.3:a:postcss-value-parser:postcss-value-parser:4.1.0:*:*:*:*:*:*:*",
335474          "purl": "pkg:npm/postcss-value-parser@4.1.0",
335475          "swid": {
335476            "attachment": {}
335477          },
335478          "pedigree": {},
335479          "evidence": {},
335480          "signature": {
335481            "signature": {
335482              "publicKey": {}
335483            }
335484          },
335485          "modelCard": {
335486            "modelParameters": {
335487              "approach": {}
335488            },
335489            "quantitativeAnalysis": {
335490              "graphics": {}
335491            },
335492            "considerations": {}
335493          }
335494        },
335495        {
335496          "type": "library",
335497          "bom-ref": "pkg:npm/prepend-http@1.0.4?package-id=aea29c46e49b2f46",
335498          "supplier": {},
335499          "name": "prepend-http",
335500          "version": "1.0.4",
335501          "licenses": [
335502            {
335503              "license": {
335504                "id": "MIT"
335505              }
335506            }
335507          ],
335508          "cpe": "cpe:2.3:a:prepend-http:prepend-http:1.0.4:*:*:*:*:*:*:*",
335509          "purl": "pkg:npm/prepend-http@1.0.4",
335510          "swid": {
335511            "attachment": {}
335512          },
335513          "pedigree": {},
335514          "evidence": {},
335515          "signature": {
335516            "signature": {
335517              "publicKey": {}
335518            }
335519          },
335520          "modelCard": {
335521            "modelParameters": {
335522              "approach": {}
335523            },
335524            "quantitativeAnalysis": {
335525              "graphics": {}
335526            },
335527            "considerations": {}
335528          }
335529        },
335530        {
335531          "type": "library",
335532          "bom-ref": "pkg:npm/prettier@1.19.1?package-id=fe0b8232df243c65",
335533          "supplier": {},
335534          "name": "prettier",
335535          "version": "1.19.1",
335536          "licenses": [
335537            {
335538              "license": {
335539                "id": "MIT"
335540              }
335541            }
335542          ],
335543          "cpe": "cpe:2.3:a:prettier:prettier:1.19.1:*:*:*:*:*:*:*",
335544          "purl": "pkg:npm/prettier@1.19.1",
335545          "swid": {
335546            "attachment": {}
335547          },
335548          "pedigree": {},
335549          "evidence": {},
335550          "signature": {
335551            "signature": {
335552              "publicKey": {}
335553            }
335554          },
335555          "modelCard": {
335556            "modelParameters": {
335557              "approach": {}
335558            },
335559            "quantitativeAnalysis": {
335560              "graphics": {}
335561            },
335562            "considerations": {}
335563          }
335564        },
335565        {
335566          "type": "library",
335567          "bom-ref": "pkg:npm/pretty-checkbox@3.0.3?package-id=22de522bdb50c64d",
335568          "supplier": {},
335569          "name": "pretty-checkbox",
335570          "version": "3.0.3",
335571          "licenses": [
335572            {
335573              "license": {
335574                "id": "MIT"
335575              }
335576            }
335577          ],
335578          "cpe": "cpe:2.3:a:pretty-checkbox:pretty-checkbox:3.0.3:*:*:*:*:*:*:*",
335579          "purl": "pkg:npm/pretty-checkbox@3.0.3",
335580          "swid": {
335581            "attachment": {}
335582          },
335583          "pedigree": {},
335584          "evidence": {},
335585          "signature": {
335586            "signature": {
335587              "publicKey": {}
335588            }
335589          },
335590          "modelCard": {
335591            "modelParameters": {
335592              "approach": {}
335593            },
335594            "quantitativeAnalysis": {
335595              "graphics": {}
335596            },
335597            "considerations": {}
335598          }
335599        },
335600        {
335601          "type": "library",
335602          "bom-ref": "pkg:npm/pretty-ms@6.0.1?package-id=7d48550cbd0fe6be",
335603          "supplier": {},
335604          "name": "pretty-ms",
335605          "version": "6.0.1",
335606          "licenses": [
335607            {
335608              "license": {
335609                "id": "MIT"
335610              }
335611            }
335612          ],
335613          "cpe": "cpe:2.3:a:pretty-ms:pretty-ms:6.0.1:*:*:*:*:*:*:*",
335614          "purl": "pkg:npm/pretty-ms@6.0.1",
335615          "swid": {
335616            "attachment": {}
335617          },
335618          "pedigree": {},
335619          "evidence": {},
335620          "signature": {
335621            "signature": {
335622              "publicKey": {}
335623            }
335624          },
335625          "modelCard": {
335626            "modelParameters": {
335627              "approach": {}
335628            },
335629            "quantitativeAnalysis": {
335630              "graphics": {}
335631            },
335632            "considerations": {}
335633          }
335634        },
335635        {
335636          "type": "library",
335637          "bom-ref": "pkg:npm/private@0.1.8?package-id=d36b80883148095f",
335638          "supplier": {},
335639          "name": "private",
335640          "version": "0.1.8",
335641          "licenses": [
335642            {
335643              "license": {
335644                "id": "MIT"
335645              }
335646            }
335647          ],
335648          "cpe": "cpe:2.3:a:private:private:0.1.8:*:*:*:*:*:*:*",
335649          "purl": "pkg:npm/private@0.1.8",
335650          "swid": {
335651            "attachment": {}
335652          },
335653          "pedigree": {},
335654          "evidence": {},
335655          "signature": {
335656            "signature": {
335657              "publicKey": {}
335658            }
335659          },
335660          "modelCard": {
335661            "modelParameters": {
335662              "approach": {}
335663            },
335664            "quantitativeAnalysis": {
335665              "graphics": {}
335666            },
335667            "considerations": {}
335668          }
335669        },
335670        {
335671          "type": "library",
335672          "bom-ref": "pkg:npm/process@0.11.10?package-id=20d4f594afd5a93d",
335673          "supplier": {},
335674          "name": "process",
335675          "version": "0.11.10",
335676          "licenses": [
335677            {
335678              "license": {
335679                "id": "MIT"
335680              }
335681            }
335682          ],
335683          "cpe": "cpe:2.3:a:process:process:0.11.10:*:*:*:*:*:*:*",
335684          "purl": "pkg:npm/process@0.11.10",
335685          "swid": {
335686            "attachment": {}
335687          },
335688          "pedigree": {},
335689          "evidence": {},
335690          "signature": {
335691            "signature": {
335692              "publicKey": {}
335693            }
335694          },
335695          "modelCard": {
335696            "modelParameters": {
335697              "approach": {}
335698            },
335699            "quantitativeAnalysis": {
335700              "graphics": {}
335701            },
335702            "considerations": {}
335703          }
335704        },
335705        {
335706          "type": "library",
335707          "bom-ref": "pkg:npm/process-nextick-args@2.0.1?package-id=c28603c1f456c61",
335708          "supplier": {},
335709          "name": "process-nextick-args",
335710          "version": "2.0.1",
335711          "licenses": [
335712            {
335713              "license": {
335714                "id": "MIT"
335715              }
335716            }
335717          ],
335718          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.1:*:*:*:*:*:*:*",
335719          "purl": "pkg:npm/process-nextick-args@2.0.1",
335720          "swid": {
335721            "attachment": {}
335722          },
335723          "pedigree": {},
335724          "evidence": {},
335725          "signature": {
335726            "signature": {
335727              "publicKey": {}
335728            }
335729          },
335730          "modelCard": {
335731            "modelParameters": {
335732              "approach": {}
335733            },
335734            "quantitativeAnalysis": {
335735              "graphics": {}
335736            },
335737            "considerations": {}
335738          }
335739        },
335740        {
335741          "type": "library",
335742          "bom-ref": "pkg:npm/process-on-spawn@1.0.0?package-id=f100305603116cea",
335743          "supplier": {},
335744          "name": "process-on-spawn",
335745          "version": "1.0.0",
335746          "cpe": "cpe:2.3:a:process-on-spawn:process-on-spawn:1.0.0:*:*:*:*:*:*:*",
335747          "purl": "pkg:npm/process-on-spawn@1.0.0",
335748          "swid": {
335749            "attachment": {}
335750          },
335751          "pedigree": {},
335752          "evidence": {},
335753          "signature": {
335754            "signature": {
335755              "publicKey": {}
335756            }
335757          },
335758          "modelCard": {
335759            "modelParameters": {
335760              "approach": {}
335761            },
335762            "quantitativeAnalysis": {
335763              "graphics": {}
335764            },
335765            "considerations": {}
335766          }
335767        },
335768        {
335769          "type": "library",
335770          "bom-ref": "pkg:npm/promise@7.3.1?package-id=388c95e4365039d5",
335771          "supplier": {},
335772          "name": "promise",
335773          "version": "7.3.1",
335774          "licenses": [
335775            {
335776              "license": {
335777                "id": "MIT"
335778              }
335779            }
335780          ],
335781          "cpe": "cpe:2.3:a:promise:promise:7.3.1:*:*:*:*:*:*:*",
335782          "purl": "pkg:npm/promise@7.3.1",
335783          "swid": {
335784            "attachment": {}
335785          },
335786          "pedigree": {},
335787          "evidence": {},
335788          "signature": {
335789            "signature": {
335790              "publicKey": {}
335791            }
335792          },
335793          "modelCard": {
335794            "modelParameters": {
335795              "approach": {}
335796            },
335797            "quantitativeAnalysis": {
335798              "graphics": {}
335799            },
335800            "considerations": {}
335801          }
335802        },
335803        {
335804          "type": "library",
335805          "bom-ref": "pkg:npm/promise-inflight@1.0.1?package-id=e6a9bc0e89e81222",
335806          "supplier": {},
335807          "name": "promise-inflight",
335808          "version": "1.0.1",
335809          "licenses": [
335810            {
335811              "license": {
335812                "id": "ISC"
335813              }
335814            }
335815          ],
335816          "cpe": "cpe:2.3:a:promise-inflight:promise-inflight:1.0.1:*:*:*:*:*:*:*",
335817          "purl": "pkg:npm/promise-inflight@1.0.1",
335818          "swid": {
335819            "attachment": {}
335820          },
335821          "pedigree": {},
335822          "evidence": {},
335823          "signature": {
335824            "signature": {
335825              "publicKey": {}
335826            }
335827          },
335828          "modelCard": {
335829            "modelParameters": {
335830              "approach": {}
335831            },
335832            "quantitativeAnalysis": {
335833              "graphics": {}
335834            },
335835            "considerations": {}
335836          }
335837        },
335838        {
335839          "type": "library",
335840          "bom-ref": "pkg:npm/promise-polyfill@8.2.1?package-id=fce25f1082426660",
335841          "supplier": {},
335842          "name": "promise-polyfill",
335843          "version": "8.2.1",
335844          "licenses": [
335845            {
335846              "license": {
335847                "id": "MIT"
335848              }
335849            }
335850          ],
335851          "cpe": "cpe:2.3:a:promise-polyfill:promise-polyfill:8.2.1:*:*:*:*:*:*:*",
335852          "purl": "pkg:npm/promise-polyfill@8.2.1",
335853          "swid": {
335854            "attachment": {}
335855          },
335856          "pedigree": {},
335857          "evidence": {},
335858          "signature": {
335859            "signature": {
335860              "publicKey": {}
335861            }
335862          },
335863          "modelCard": {
335864            "modelParameters": {
335865              "approach": {}
335866            },
335867            "quantitativeAnalysis": {
335868              "graphics": {}
335869            },
335870            "considerations": {}
335871          }
335872        },
335873        {
335874          "type": "library",
335875          "bom-ref": "pkg:npm/promise-retry@1.1.1?package-id=1e09d42d4a165dca",
335876          "supplier": {},
335877          "name": "promise-retry",
335878          "version": "1.1.1",
335879          "licenses": [
335880            {
335881              "license": {
335882                "id": "MIT"
335883              }
335884            }
335885          ],
335886          "cpe": "cpe:2.3:a:promise-retry:promise-retry:1.1.1:*:*:*:*:*:*:*",
335887          "purl": "pkg:npm/promise-retry@1.1.1",
335888          "swid": {
335889            "attachment": {}
335890          },
335891          "pedigree": {},
335892          "evidence": {},
335893          "signature": {
335894            "signature": {
335895              "publicKey": {}
335896            }
335897          },
335898          "modelCard": {
335899            "modelParameters": {
335900              "approach": {}
335901            },
335902            "quantitativeAnalysis": {
335903              "graphics": {}
335904            },
335905            "considerations": {}
335906          }
335907        },
335908        {
335909          "type": "library",
335910          "bom-ref": "pkg:npm/protoduck@5.0.1?package-id=19018fe2c8d93ecd",
335911          "supplier": {},
335912          "name": "protoduck",
335913          "version": "5.0.1",
335914          "licenses": [
335915            {
335916              "license": {
335917                "id": "MIT"
335918              }
335919            }
335920          ],
335921          "cpe": "cpe:2.3:a:protoduck:protoduck:5.0.1:*:*:*:*:*:*:*",
335922          "purl": "pkg:npm/protoduck@5.0.1",
335923          "swid": {
335924            "attachment": {}
335925          },
335926          "pedigree": {},
335927          "evidence": {},
335928          "signature": {
335929            "signature": {
335930              "publicKey": {}
335931            }
335932          },
335933          "modelCard": {
335934            "modelParameters": {
335935              "approach": {}
335936            },
335937            "quantitativeAnalysis": {
335938              "graphics": {}
335939            },
335940            "considerations": {}
335941          }
335942        },
335943        {
335944          "type": "library",
335945          "bom-ref": "pkg:npm/protractor@5.4.3?package-id=59f6df420d1b84f1",
335946          "supplier": {},
335947          "name": "protractor",
335948          "version": "5.4.3",
335949          "licenses": [
335950            {
335951              "license": {
335952                "id": "MIT"
335953              }
335954            }
335955          ],
335956          "cpe": "cpe:2.3:a:protractor:protractor:5.4.3:*:*:*:*:*:*:*",
335957          "purl": "pkg:npm/protractor@5.4.3",
335958          "swid": {
335959            "attachment": {}
335960          },
335961          "pedigree": {},
335962          "evidence": {},
335963          "signature": {
335964            "signature": {
335965              "publicKey": {}
335966            }
335967          },
335968          "modelCard": {
335969            "modelParameters": {
335970              "approach": {}
335971            },
335972            "quantitativeAnalysis": {
335973              "graphics": {}
335974            },
335975            "considerations": {}
335976          }
335977        },
335978        {
335979          "type": "library",
335980          "bom-ref": "pkg:npm/protractor-beautiful-reporter@1.3.6?package-id=f02b19e4e729aca2",
335981          "supplier": {},
335982          "name": "protractor-beautiful-reporter",
335983          "version": "1.3.6",
335984          "licenses": [
335985            {
335986              "license": {
335987                "id": "MIT"
335988              }
335989            }
335990          ],
335991          "cpe": "cpe:2.3:a:protractor-beautiful-reporter:protractor-beautiful-reporter:1.3.6:*:*:*:*:*:*:*",
335992          "purl": "pkg:npm/protractor-beautiful-reporter@1.3.6",
335993          "swid": {
335994            "attachment": {}
335995          },
335996          "pedigree": {},
335997          "evidence": {},
335998          "signature": {
335999            "signature": {
336000              "publicKey": {}
336001            }
336002          },
336003          "modelCard": {
336004            "modelParameters": {
336005              "approach": {}
336006            },
336007            "quantitativeAnalysis": {
336008              "graphics": {}
336009            },
336010            "considerations": {}
336011          }
336012        },
336013        {
336014          "type": "library",
336015          "bom-ref": "pkg:npm/protractor-jasmine2-screenshot-reporter@0.5.0?package-id=51e830b3573538c1",
336016          "supplier": {},
336017          "name": "protractor-jasmine2-screenshot-reporter",
336018          "version": "0.5.0",
336019          "licenses": [
336020            {
336021              "license": {
336022                "id": "MIT"
336023              }
336024            }
336025          ],
336026          "cpe": "cpe:2.3:a:protractor-jasmine2-screenshot-reporter:protractor-jasmine2-screenshot-reporter:0.5.0:*:*:*:*:*:*:*",
336027          "purl": "pkg:npm/protractor-jasmine2-screenshot-reporter@0.5.0",
336028          "swid": {
336029            "attachment": {}
336030          },
336031          "pedigree": {},
336032          "evidence": {},
336033          "signature": {
336034            "signature": {
336035              "publicKey": {}
336036            }
336037          },
336038          "modelCard": {
336039            "modelParameters": {
336040              "approach": {}
336041            },
336042            "quantitativeAnalysis": {
336043              "graphics": {}
336044            },
336045            "considerations": {}
336046          }
336047        },
336048        {
336049          "type": "library",
336050          "bom-ref": "pkg:npm/proxy-addr@2.0.6?package-id=9dd760f33511f985",
336051          "supplier": {},
336052          "name": "proxy-addr",
336053          "version": "2.0.6",
336054          "licenses": [
336055            {
336056              "license": {
336057                "id": "MIT"
336058              }
336059            }
336060          ],
336061          "cpe": "cpe:2.3:a:proxy-addr:proxy-addr:2.0.6:*:*:*:*:*:*:*",
336062          "purl": "pkg:npm/proxy-addr@2.0.6",
336063          "swid": {
336064            "attachment": {}
336065          },
336066          "pedigree": {},
336067          "evidence": {},
336068          "signature": {
336069            "signature": {
336070              "publicKey": {}
336071            }
336072          },
336073          "modelCard": {
336074            "modelParameters": {
336075              "approach": {}
336076            },
336077            "quantitativeAnalysis": {
336078              "graphics": {}
336079            },
336080            "considerations": {}
336081          }
336082        },
336083        {
336084          "type": "library",
336085          "bom-ref": "pkg:npm/prr@1.0.1?package-id=86708f0420595e28",
336086          "supplier": {},
336087          "name": "prr",
336088          "version": "1.0.1",
336089          "licenses": [
336090            {
336091              "license": {
336092                "id": "MIT"
336093              }
336094            }
336095          ],
336096          "cpe": "cpe:2.3:a:prr:prr:1.0.1:*:*:*:*:*:*:*",
336097          "purl": "pkg:npm/prr@1.0.1",
336098          "swid": {
336099            "attachment": {}
336100          },
336101          "pedigree": {},
336102          "evidence": {},
336103          "signature": {
336104            "signature": {
336105              "publicKey": {}
336106            }
336107          },
336108          "modelCard": {
336109            "modelParameters": {
336110              "approach": {}
336111            },
336112            "quantitativeAnalysis": {
336113              "graphics": {}
336114            },
336115            "considerations": {}
336116          }
336117        },
336118        {
336119          "type": "library",
336120          "bom-ref": "pkg:npm/pseudomap@1.0.2?package-id=3bc60dc92b6f3858",
336121          "supplier": {},
336122          "name": "pseudomap",
336123          "version": "1.0.2",
336124          "licenses": [
336125            {
336126              "license": {
336127                "id": "ISC"
336128              }
336129            }
336130          ],
336131          "cpe": "cpe:2.3:a:pseudomap:pseudomap:1.0.2:*:*:*:*:*:*:*",
336132          "purl": "pkg:npm/pseudomap@1.0.2",
336133          "swid": {
336134            "attachment": {}
336135          },
336136          "pedigree": {},
336137          "evidence": {},
336138          "signature": {
336139            "signature": {
336140              "publicKey": {}
336141            }
336142          },
336143          "modelCard": {
336144            "modelParameters": {
336145              "approach": {}
336146            },
336147            "quantitativeAnalysis": {
336148              "graphics": {}
336149            },
336150            "considerations": {}
336151          }
336152        },
336153        {
336154          "type": "library",
336155          "bom-ref": "pkg:npm/psl@1.7.0?package-id=ed79cb1c8ea88468",
336156          "supplier": {},
336157          "name": "psl",
336158          "version": "1.7.0",
336159          "licenses": [
336160            {
336161              "license": {
336162                "id": "MIT"
336163              }
336164            }
336165          ],
336166          "cpe": "cpe:2.3:a:psl:psl:1.7.0:*:*:*:*:*:*:*",
336167          "purl": "pkg:npm/psl@1.7.0",
336168          "swid": {
336169            "attachment": {}
336170          },
336171          "pedigree": {},
336172          "evidence": {},
336173          "signature": {
336174            "signature": {
336175              "publicKey": {}
336176            }
336177          },
336178          "modelCard": {
336179            "modelParameters": {
336180              "approach": {}
336181            },
336182            "quantitativeAnalysis": {
336183              "graphics": {}
336184            },
336185            "considerations": {}
336186          }
336187        },
336188        {
336189          "type": "library",
336190          "bom-ref": "pkg:npm/public-encrypt@4.0.3?package-id=6d9daff267cc3797",
336191          "supplier": {},
336192          "name": "public-encrypt",
336193          "version": "4.0.3",
336194          "licenses": [
336195            {
336196              "license": {
336197                "id": "MIT"
336198              }
336199            }
336200          ],
336201          "cpe": "cpe:2.3:a:public-encrypt:public-encrypt:4.0.3:*:*:*:*:*:*:*",
336202          "purl": "pkg:npm/public-encrypt@4.0.3",
336203          "swid": {
336204            "attachment": {}
336205          },
336206          "pedigree": {},
336207          "evidence": {},
336208          "signature": {
336209            "signature": {
336210              "publicKey": {}
336211            }
336212          },
336213          "modelCard": {
336214            "modelParameters": {
336215              "approach": {}
336216            },
336217            "quantitativeAnalysis": {
336218              "graphics": {}
336219            },
336220            "considerations": {}
336221          }
336222        },
336223        {
336224          "type": "library",
336225          "bom-ref": "pkg:npm/pump@3.0.0?package-id=da201e2347bcef10",
336226          "supplier": {},
336227          "name": "pump",
336228          "version": "3.0.0",
336229          "licenses": [
336230            {
336231              "license": {
336232                "id": "MIT"
336233              }
336234            }
336235          ],
336236          "cpe": "cpe:2.3:a:pump:pump:3.0.0:*:*:*:*:*:*:*",
336237          "purl": "pkg:npm/pump@3.0.0",
336238          "swid": {
336239            "attachment": {}
336240          },
336241          "pedigree": {},
336242          "evidence": {},
336243          "signature": {
336244            "signature": {
336245              "publicKey": {}
336246            }
336247          },
336248          "modelCard": {
336249            "modelParameters": {
336250              "approach": {}
336251            },
336252            "quantitativeAnalysis": {
336253              "graphics": {}
336254            },
336255            "considerations": {}
336256          }
336257        },
336258        {
336259          "type": "library",
336260          "bom-ref": "pkg:npm/pumpify@1.5.1?package-id=8008ef6a6b1f2344",
336261          "supplier": {},
336262          "name": "pumpify",
336263          "version": "1.5.1",
336264          "licenses": [
336265            {
336266              "license": {
336267                "id": "MIT"
336268              }
336269            }
336270          ],
336271          "cpe": "cpe:2.3:a:pumpify:pumpify:1.5.1:*:*:*:*:*:*:*",
336272          "purl": "pkg:npm/pumpify@1.5.1",
336273          "swid": {
336274            "attachment": {}
336275          },
336276          "pedigree": {},
336277          "evidence": {},
336278          "signature": {
336279            "signature": {
336280              "publicKey": {}
336281            }
336282          },
336283          "modelCard": {
336284            "modelParameters": {
336285              "approach": {}
336286            },
336287            "quantitativeAnalysis": {
336288              "graphics": {}
336289            },
336290            "considerations": {}
336291          }
336292        },
336293        {
336294          "type": "library",
336295          "bom-ref": "pkg:npm/punycode@1.3.2?package-id=7173498793a41163",
336296          "supplier": {},
336297          "name": "punycode",
336298          "version": "1.3.2",
336299          "licenses": [
336300            {
336301              "license": {
336302                "id": "MIT"
336303              }
336304            }
336305          ],
336306          "cpe": "cpe:2.3:a:punycode:punycode:1.3.2:*:*:*:*:*:*:*",
336307          "purl": "pkg:npm/punycode@1.3.2",
336308          "swid": {
336309            "attachment": {}
336310          },
336311          "pedigree": {},
336312          "evidence": {},
336313          "signature": {
336314            "signature": {
336315              "publicKey": {}
336316            }
336317          },
336318          "modelCard": {
336319            "modelParameters": {
336320              "approach": {}
336321            },
336322            "quantitativeAnalysis": {
336323              "graphics": {}
336324            },
336325            "considerations": {}
336326          }
336327        },
336328        {
336329          "type": "library",
336330          "bom-ref": "pkg:npm/q@1.5.1?package-id=7c157b6ddcdbf3b3",
336331          "supplier": {},
336332          "name": "q",
336333          "version": "1.5.1",
336334          "licenses": [
336335            {
336336              "license": {
336337                "id": "MIT"
336338              }
336339            }
336340          ],
336341          "cpe": "cpe:2.3:a:q:q:1.5.1:*:*:*:*:*:*:*",
336342          "purl": "pkg:npm/q@1.5.1",
336343          "swid": {
336344            "attachment": {}
336345          },
336346          "pedigree": {},
336347          "evidence": {},
336348          "signature": {
336349            "signature": {
336350              "publicKey": {}
336351            }
336352          },
336353          "modelCard": {
336354            "modelParameters": {
336355              "approach": {}
336356            },
336357            "quantitativeAnalysis": {
336358              "graphics": {}
336359            },
336360            "considerations": {}
336361          }
336362        },
336363        {
336364          "type": "library",
336365          "bom-ref": "pkg:npm/qjobs@1.2.0?package-id=13d974ee22ed3f8",
336366          "supplier": {},
336367          "name": "qjobs",
336368          "version": "1.2.0",
336369          "licenses": [
336370            {
336371              "license": {
336372                "id": "MIT"
336373              }
336374            }
336375          ],
336376          "cpe": "cpe:2.3:a:qjobs:qjobs:1.2.0:*:*:*:*:*:*:*",
336377          "purl": "pkg:npm/qjobs@1.2.0",
336378          "swid": {
336379            "attachment": {}
336380          },
336381          "pedigree": {},
336382          "evidence": {},
336383          "signature": {
336384            "signature": {
336385              "publicKey": {}
336386            }
336387          },
336388          "modelCard": {
336389            "modelParameters": {
336390              "approach": {}
336391            },
336392            "quantitativeAnalysis": {
336393              "graphics": {}
336394            },
336395            "considerations": {}
336396          }
336397        },
336398        {
336399          "type": "library",
336400          "bom-ref": "pkg:npm/qs@6.5.2?package-id=9d82cde2c8f92c38",
336401          "supplier": {},
336402          "name": "qs",
336403          "version": "6.5.2",
336404          "licenses": [
336405            {
336406              "license": {
336407                "id": "BSD-3-Clause"
336408              }
336409            }
336410          ],
336411          "cpe": "cpe:2.3:a:qs:qs:6.5.2:*:*:*:*:*:*:*",
336412          "purl": "pkg:npm/qs@6.5.2",
336413          "swid": {
336414            "attachment": {}
336415          },
336416          "pedigree": {},
336417          "evidence": {},
336418          "signature": {
336419            "signature": {
336420              "publicKey": {}
336421            }
336422          },
336423          "modelCard": {
336424            "modelParameters": {
336425              "approach": {}
336426            },
336427            "quantitativeAnalysis": {
336428              "graphics": {}
336429            },
336430            "considerations": {}
336431          }
336432        },
336433        {
336434          "type": "library",
336435          "bom-ref": "pkg:npm/query-string@4.3.4?package-id=b467b74e753bb357",
336436          "supplier": {},
336437          "name": "query-string",
336438          "version": "4.3.4",
336439          "licenses": [
336440            {
336441              "license": {
336442                "id": "MIT"
336443              }
336444            }
336445          ],
336446          "cpe": "cpe:2.3:a:query-string:query-string:4.3.4:*:*:*:*:*:*:*",
336447          "purl": "pkg:npm/query-string@4.3.4",
336448          "swid": {
336449            "attachment": {}
336450          },
336451          "pedigree": {},
336452          "evidence": {},
336453          "signature": {
336454            "signature": {
336455              "publicKey": {}
336456            }
336457          },
336458          "modelCard": {
336459            "modelParameters": {
336460              "approach": {}
336461            },
336462            "quantitativeAnalysis": {
336463              "graphics": {}
336464            },
336465            "considerations": {}
336466          }
336467        },
336468        {
336469          "type": "library",
336470          "bom-ref": "pkg:npm/querystring@0.2.0?package-id=cc0e7a8744153abb",
336471          "supplier": {},
336472          "name": "querystring",
336473          "version": "0.2.0",
336474          "licenses": [
336475            {
336476              "license": {
336477                "id": "MIT"
336478              }
336479            }
336480          ],
336481          "cpe": "cpe:2.3:a:querystring:querystring:0.2.0:*:*:*:*:*:*:*",
336482          "purl": "pkg:npm/querystring@0.2.0",
336483          "swid": {
336484            "attachment": {}
336485          },
336486          "pedigree": {},
336487          "evidence": {},
336488          "signature": {
336489            "signature": {
336490              "publicKey": {}
336491            }
336492          },
336493          "modelCard": {
336494            "modelParameters": {
336495              "approach": {}
336496            },
336497            "quantitativeAnalysis": {
336498              "graphics": {}
336499            },
336500            "considerations": {}
336501          }
336502        },
336503        {
336504          "type": "library",
336505          "bom-ref": "pkg:npm/querystring-es3@0.2.1?package-id=afc2e57875341023",
336506          "supplier": {},
336507          "name": "querystring-es3",
336508          "version": "0.2.1",
336509          "licenses": [
336510            {
336511              "license": {
336512                "id": "MIT"
336513              }
336514            }
336515          ],
336516          "cpe": "cpe:2.3:a:querystring-es3:querystring-es3:0.2.1:*:*:*:*:*:*:*",
336517          "purl": "pkg:npm/querystring-es3@0.2.1",
336518          "swid": {
336519            "attachment": {}
336520          },
336521          "pedigree": {},
336522          "evidence": {},
336523          "signature": {
336524            "signature": {
336525              "publicKey": {}
336526            }
336527          },
336528          "modelCard": {
336529            "modelParameters": {
336530              "approach": {}
336531            },
336532            "quantitativeAnalysis": {
336533              "graphics": {}
336534            },
336535            "considerations": {}
336536          }
336537        },
336538        {
336539          "type": "library",
336540          "bom-ref": "pkg:npm/querystringify@2.1.1?package-id=b1cbe39b483176e0",
336541          "supplier": {},
336542          "name": "querystringify",
336543          "version": "2.1.1",
336544          "licenses": [
336545            {
336546              "license": {
336547                "id": "MIT"
336548              }
336549            }
336550          ],
336551          "cpe": "cpe:2.3:a:querystringify:querystringify:2.1.1:*:*:*:*:*:*:*",
336552          "purl": "pkg:npm/querystringify@2.1.1",
336553          "swid": {
336554            "attachment": {}
336555          },
336556          "pedigree": {},
336557          "evidence": {},
336558          "signature": {
336559            "signature": {
336560              "publicKey": {}
336561            }
336562          },
336563          "modelCard": {
336564            "modelParameters": {
336565              "approach": {}
336566            },
336567            "quantitativeAnalysis": {
336568              "graphics": {}
336569            },
336570            "considerations": {}
336571          }
336572        },
336573        {
336574          "type": "library",
336575          "bom-ref": "pkg:npm/ramda@0.25.0?package-id=188615358cc0a968",
336576          "supplier": {},
336577          "name": "ramda",
336578          "version": "0.25.0",
336579          "licenses": [
336580            {
336581              "license": {
336582                "id": "MIT"
336583              }
336584            }
336585          ],
336586          "cpe": "cpe:2.3:a:ramda:ramda:0.25.0:*:*:*:*:*:*:*",
336587          "purl": "pkg:npm/ramda@0.25.0",
336588          "swid": {
336589            "attachment": {}
336590          },
336591          "pedigree": {},
336592          "evidence": {},
336593          "signature": {
336594            "signature": {
336595              "publicKey": {}
336596            }
336597          },
336598          "modelCard": {
336599            "modelParameters": {
336600              "approach": {}
336601            },
336602            "quantitativeAnalysis": {
336603              "graphics": {}
336604            },
336605            "considerations": {}
336606          }
336607        },
336608        {
336609          "type": "library",
336610          "bom-ref": "pkg:npm/randombytes@2.1.0?package-id=c17750c48e6ea6ec",
336611          "supplier": {},
336612          "name": "randombytes",
336613          "version": "2.1.0",
336614          "licenses": [
336615            {
336616              "license": {
336617                "id": "MIT"
336618              }
336619            }
336620          ],
336621          "cpe": "cpe:2.3:a:randombytes:randombytes:2.1.0:*:*:*:*:*:*:*",
336622          "purl": "pkg:npm/randombytes@2.1.0",
336623          "swid": {
336624            "attachment": {}
336625          },
336626          "pedigree": {},
336627          "evidence": {},
336628          "signature": {
336629            "signature": {
336630              "publicKey": {}
336631            }
336632          },
336633          "modelCard": {
336634            "modelParameters": {
336635              "approach": {}
336636            },
336637            "quantitativeAnalysis": {
336638              "graphics": {}
336639            },
336640            "considerations": {}
336641          }
336642        },
336643        {
336644          "type": "library",
336645          "bom-ref": "pkg:npm/randomfill@1.0.4?package-id=9426a6a54e52f952",
336646          "supplier": {},
336647          "name": "randomfill",
336648          "version": "1.0.4",
336649          "licenses": [
336650            {
336651              "license": {
336652                "id": "MIT"
336653              }
336654            }
336655          ],
336656          "cpe": "cpe:2.3:a:randomfill:randomfill:1.0.4:*:*:*:*:*:*:*",
336657          "purl": "pkg:npm/randomfill@1.0.4",
336658          "swid": {
336659            "attachment": {}
336660          },
336661          "pedigree": {},
336662          "evidence": {},
336663          "signature": {
336664            "signature": {
336665              "publicKey": {}
336666            }
336667          },
336668          "modelCard": {
336669            "modelParameters": {
336670              "approach": {}
336671            },
336672            "quantitativeAnalysis": {
336673              "graphics": {}
336674            },
336675            "considerations": {}
336676          }
336677        },
336678        {
336679          "type": "library",
336680          "bom-ref": "pkg:npm/range-parser@1.2.1?package-id=6ab0f3a46dedd336",
336681          "supplier": {},
336682          "name": "range-parser",
336683          "version": "1.2.1",
336684          "licenses": [
336685            {
336686              "license": {
336687                "id": "MIT"
336688              }
336689            }
336690          ],
336691          "cpe": "cpe:2.3:a:range-parser:range-parser:1.2.1:*:*:*:*:*:*:*",
336692          "purl": "pkg:npm/range-parser@1.2.1",
336693          "swid": {
336694            "attachment": {}
336695          },
336696          "pedigree": {},
336697          "evidence": {},
336698          "signature": {
336699            "signature": {
336700              "publicKey": {}
336701            }
336702          },
336703          "modelCard": {
336704            "modelParameters": {
336705              "approach": {}
336706            },
336707            "quantitativeAnalysis": {
336708              "graphics": {}
336709            },
336710            "considerations": {}
336711          }
336712        },
336713        {
336714          "type": "library",
336715          "bom-ref": "pkg:npm/raw-body@2.4.0?package-id=382b72783914bebe",
336716          "supplier": {},
336717          "name": "raw-body",
336718          "version": "2.4.0",
336719          "licenses": [
336720            {
336721              "license": {
336722                "id": "MIT"
336723              }
336724            }
336725          ],
336726          "cpe": "cpe:2.3:a:raw-body:raw-body:2.4.0:*:*:*:*:*:*:*",
336727          "purl": "pkg:npm/raw-body@2.4.0",
336728          "swid": {
336729            "attachment": {}
336730          },
336731          "pedigree": {},
336732          "evidence": {},
336733          "signature": {
336734            "signature": {
336735              "publicKey": {}
336736            }
336737          },
336738          "modelCard": {
336739            "modelParameters": {
336740              "approach": {}
336741            },
336742            "quantitativeAnalysis": {
336743              "graphics": {}
336744            },
336745            "considerations": {}
336746          }
336747        },
336748        {
336749          "type": "library",
336750          "bom-ref": "pkg:npm/raw-loader@4.0.0?package-id=6a368c3d5898b172",
336751          "supplier": {},
336752          "name": "raw-loader",
336753          "version": "4.0.0",
336754          "licenses": [
336755            {
336756              "license": {
336757                "id": "MIT"
336758              }
336759            }
336760          ],
336761          "cpe": "cpe:2.3:a:raw-loader:raw-loader:4.0.0:*:*:*:*:*:*:*",
336762          "purl": "pkg:npm/raw-loader@4.0.0",
336763          "swid": {
336764            "attachment": {}
336765          },
336766          "pedigree": {},
336767          "evidence": {},
336768          "signature": {
336769            "signature": {
336770              "publicKey": {}
336771            }
336772          },
336773          "modelCard": {
336774            "modelParameters": {
336775              "approach": {}
336776            },
336777            "quantitativeAnalysis": {
336778              "graphics": {}
336779            },
336780            "considerations": {}
336781          }
336782        },
336783        {
336784          "type": "library",
336785          "bom-ref": "pkg:npm/read-cache@1.0.0?package-id=c9c02548e6e5c768",
336786          "supplier": {},
336787          "name": "read-cache",
336788          "version": "1.0.0",
336789          "licenses": [
336790            {
336791              "license": {
336792                "id": "MIT"
336793              }
336794            }
336795          ],
336796          "cpe": "cpe:2.3:a:read-cache:read-cache:1.0.0:*:*:*:*:*:*:*",
336797          "purl": "pkg:npm/read-cache@1.0.0",
336798          "swid": {
336799            "attachment": {}
336800          },
336801          "pedigree": {},
336802          "evidence": {},
336803          "signature": {
336804            "signature": {
336805              "publicKey": {}
336806            }
336807          },
336808          "modelCard": {
336809            "modelParameters": {
336810              "approach": {}
336811            },
336812            "quantitativeAnalysis": {
336813              "graphics": {}
336814            },
336815            "considerations": {}
336816          }
336817        },
336818        {
336819          "type": "library",
336820          "bom-ref": "pkg:npm/read-package-json@2.1.1?package-id=cb58b2704453cd4f",
336821          "supplier": {},
336822          "name": "read-package-json",
336823          "version": "2.1.1",
336824          "licenses": [
336825            {
336826              "license": {
336827                "id": "ISC"
336828              }
336829            }
336830          ],
336831          "cpe": "cpe:2.3:a:read-package-json:read-package-json:2.1.1:*:*:*:*:*:*:*",
336832          "purl": "pkg:npm/read-package-json@2.1.1",
336833          "swid": {
336834            "attachment": {}
336835          },
336836          "pedigree": {},
336837          "evidence": {},
336838          "signature": {
336839            "signature": {
336840              "publicKey": {}
336841            }
336842          },
336843          "modelCard": {
336844            "modelParameters": {
336845              "approach": {}
336846            },
336847            "quantitativeAnalysis": {
336848              "graphics": {}
336849            },
336850            "considerations": {}
336851          }
336852        },
336853        {
336854          "type": "library",
336855          "bom-ref": "pkg:npm/read-package-tree@5.3.1?package-id=1c19dafd709abd3c",
336856          "supplier": {},
336857          "name": "read-package-tree",
336858          "version": "5.3.1",
336859          "licenses": [
336860            {
336861              "license": {
336862                "id": "ISC"
336863              }
336864            }
336865          ],
336866          "cpe": "cpe:2.3:a:read-package-tree:read-package-tree:5.3.1:*:*:*:*:*:*:*",
336867          "purl": "pkg:npm/read-package-tree@5.3.1",
336868          "swid": {
336869            "attachment": {}
336870          },
336871          "pedigree": {},
336872          "evidence": {},
336873          "signature": {
336874            "signature": {
336875              "publicKey": {}
336876            }
336877          },
336878          "modelCard": {
336879            "modelParameters": {
336880              "approach": {}
336881            },
336882            "quantitativeAnalysis": {
336883              "graphics": {}
336884            },
336885            "considerations": {}
336886          }
336887        },
336888        {
336889          "type": "library",
336890          "bom-ref": "pkg:npm/read-pkg@1.1.0?package-id=dd8706131c77dafa",
336891          "supplier": {},
336892          "name": "read-pkg",
336893          "version": "1.1.0",
336894          "licenses": [
336895            {
336896              "license": {
336897                "id": "MIT"
336898              }
336899            }
336900          ],
336901          "cpe": "cpe:2.3:a:read-pkg:read-pkg:1.1.0:*:*:*:*:*:*:*",
336902          "purl": "pkg:npm/read-pkg@1.1.0",
336903          "swid": {
336904            "attachment": {}
336905          },
336906          "pedigree": {},
336907          "evidence": {},
336908          "signature": {
336909            "signature": {
336910              "publicKey": {}
336911            }
336912          },
336913          "modelCard": {
336914            "modelParameters": {
336915              "approach": {}
336916            },
336917            "quantitativeAnalysis": {
336918              "graphics": {}
336919            },
336920            "considerations": {}
336921          }
336922        },
336923        {
336924          "type": "library",
336925          "bom-ref": "pkg:npm/read-pkg-up@1.0.1?package-id=b98e55f3e6645d6",
336926          "supplier": {},
336927          "name": "read-pkg-up",
336928          "version": "1.0.1",
336929          "licenses": [
336930            {
336931              "license": {
336932                "id": "MIT"
336933              }
336934            }
336935          ],
336936          "cpe": "cpe:2.3:a:read-pkg-up:read-pkg-up:1.0.1:*:*:*:*:*:*:*",
336937          "purl": "pkg:npm/read-pkg-up@1.0.1",
336938          "swid": {
336939            "attachment": {}
336940          },
336941          "pedigree": {},
336942          "evidence": {},
336943          "signature": {
336944            "signature": {
336945              "publicKey": {}
336946            }
336947          },
336948          "modelCard": {
336949            "modelParameters": {
336950              "approach": {}
336951            },
336952            "quantitativeAnalysis": {
336953              "graphics": {}
336954            },
336955            "considerations": {}
336956          }
336957        },
336958        {
336959          "type": "library",
336960          "bom-ref": "pkg:npm/readable-stream@2.3.7?package-id=37e94b9d3967def8",
336961          "supplier": {},
336962          "name": "readable-stream",
336963          "version": "2.3.7",
336964          "licenses": [
336965            {
336966              "license": {
336967                "id": "MIT"
336968              }
336969            }
336970          ],
336971          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.7:*:*:*:*:*:*:*",
336972          "purl": "pkg:npm/readable-stream@2.3.7",
336973          "swid": {
336974            "attachment": {}
336975          },
336976          "pedigree": {},
336977          "evidence": {},
336978          "signature": {
336979            "signature": {
336980              "publicKey": {}
336981            }
336982          },
336983          "modelCard": {
336984            "modelParameters": {
336985              "approach": {}
336986            },
336987            "quantitativeAnalysis": {
336988              "graphics": {}
336989            },
336990            "considerations": {}
336991          }
336992        },
336993        {
336994          "type": "library",
336995          "bom-ref": "pkg:npm/readdir-scoped-modules@1.1.0?package-id=a72d7b0c99b081fe",
336996          "supplier": {},
336997          "name": "readdir-scoped-modules",
336998          "version": "1.1.0",
336999          "licenses": [
337000            {
337001              "license": {
337002                "id": "ISC"
337003              }
337004            }
337005          ],
337006          "cpe": "cpe:2.3:a:readdir-scoped-modules:readdir-scoped-modules:1.1.0:*:*:*:*:*:*:*",
337007          "purl": "pkg:npm/readdir-scoped-modules@1.1.0",
337008          "swid": {
337009            "attachment": {}
337010          },
337011          "pedigree": {},
337012          "evidence": {},
337013          "signature": {
337014            "signature": {
337015              "publicKey": {}
337016            }
337017          },
337018          "modelCard": {
337019            "modelParameters": {
337020              "approach": {}
337021            },
337022            "quantitativeAnalysis": {
337023              "graphics": {}
337024            },
337025            "considerations": {}
337026          }
337027        },
337028        {
337029          "type": "library",
337030          "bom-ref": "pkg:npm/readdirp@3.3.0?package-id=886d02d356678608",
337031          "supplier": {},
337032          "name": "readdirp",
337033          "version": "3.3.0",
337034          "licenses": [
337035            {
337036              "license": {
337037                "id": "MIT"
337038              }
337039            }
337040          ],
337041          "cpe": "cpe:2.3:a:readdirp:readdirp:3.3.0:*:*:*:*:*:*:*",
337042          "purl": "pkg:npm/readdirp@3.3.0",
337043          "swid": {
337044            "attachment": {}
337045          },
337046          "pedigree": {},
337047          "evidence": {},
337048          "signature": {
337049            "signature": {
337050              "publicKey": {}
337051            }
337052          },
337053          "modelCard": {
337054            "modelParameters": {
337055              "approach": {}
337056            },
337057            "quantitativeAnalysis": {
337058              "graphics": {}
337059            },
337060            "considerations": {}
337061          }
337062        },
337063        {
337064          "type": "library",
337065          "bom-ref": "pkg:npm/recast@0.19.1?package-id=33fe5b12dde2bc4a",
337066          "supplier": {},
337067          "name": "recast",
337068          "version": "0.19.1",
337069          "licenses": [
337070            {
337071              "license": {
337072                "id": "MIT"
337073              }
337074            }
337075          ],
337076          "cpe": "cpe:2.3:a:recast:recast:0.19.1:*:*:*:*:*:*:*",
337077          "purl": "pkg:npm/recast@0.19.1",
337078          "swid": {
337079            "attachment": {}
337080          },
337081          "pedigree": {},
337082          "evidence": {},
337083          "signature": {
337084            "signature": {
337085              "publicKey": {}
337086            }
337087          },
337088          "modelCard": {
337089            "modelParameters": {
337090              "approach": {}
337091            },
337092            "quantitativeAnalysis": {
337093              "graphics": {}
337094            },
337095            "considerations": {}
337096          }
337097        },
337098        {
337099          "type": "library",
337100          "bom-ref": "pkg:npm/redent@1.0.0?package-id=d3c398bd6fb56a2a",
337101          "supplier": {},
337102          "name": "redent",
337103          "version": "1.0.0",
337104          "licenses": [
337105            {
337106              "license": {
337107                "id": "MIT"
337108              }
337109            }
337110          ],
337111          "cpe": "cpe:2.3:a:redent:redent:1.0.0:*:*:*:*:*:*:*",
337112          "purl": "pkg:npm/redent@1.0.0",
337113          "swid": {
337114            "attachment": {}
337115          },
337116          "pedigree": {},
337117          "evidence": {},
337118          "signature": {
337119            "signature": {
337120              "publicKey": {}
337121            }
337122          },
337123          "modelCard": {
337124            "modelParameters": {
337125              "approach": {}
337126            },
337127            "quantitativeAnalysis": {
337128              "graphics": {}
337129            },
337130            "considerations": {}
337131          }
337132        },
337133        {
337134          "type": "library",
337135          "bom-ref": "pkg:npm/reflect-metadata@0.1.13?package-id=f81d1b46f7ec482c",
337136          "supplier": {},
337137          "name": "reflect-metadata",
337138          "version": "0.1.13",
337139          "licenses": [
337140            {
337141              "license": {
337142                "id": "Apache-2.0"
337143              }
337144            }
337145          ],
337146          "cpe": "cpe:2.3:a:reflect-metadata:reflect-metadata:0.1.13:*:*:*:*:*:*:*",
337147          "purl": "pkg:npm/reflect-metadata@0.1.13",
337148          "swid": {
337149            "attachment": {}
337150          },
337151          "pedigree": {},
337152          "evidence": {},
337153          "signature": {
337154            "signature": {
337155              "publicKey": {}
337156            }
337157          },
337158          "modelCard": {
337159            "modelParameters": {
337160              "approach": {}
337161            },
337162            "quantitativeAnalysis": {
337163              "graphics": {}
337164            },
337165            "considerations": {}
337166          }
337167        },
337168        {
337169          "type": "library",
337170          "bom-ref": "pkg:npm/regenerate@1.4.0?package-id=e6776e7063ca7e1a",
337171          "supplier": {},
337172          "name": "regenerate",
337173          "version": "1.4.0",
337174          "licenses": [
337175            {
337176              "license": {
337177                "id": "MIT"
337178              }
337179            }
337180          ],
337181          "cpe": "cpe:2.3:a:regenerate:regenerate:1.4.0:*:*:*:*:*:*:*",
337182          "purl": "pkg:npm/regenerate@1.4.0",
337183          "swid": {
337184            "attachment": {}
337185          },
337186          "pedigree": {},
337187          "evidence": {},
337188          "signature": {
337189            "signature": {
337190              "publicKey": {}
337191            }
337192          },
337193          "modelCard": {
337194            "modelParameters": {
337195              "approach": {}
337196            },
337197            "quantitativeAnalysis": {
337198              "graphics": {}
337199            },
337200            "considerations": {}
337201          }
337202        },
337203        {
337204          "type": "library",
337205          "bom-ref": "pkg:npm/regenerate-unicode-properties@8.2.0?package-id=f2b481c75753751d",
337206          "supplier": {},
337207          "name": "regenerate-unicode-properties",
337208          "version": "8.2.0",
337209          "licenses": [
337210            {
337211              "license": {
337212                "id": "MIT"
337213              }
337214            }
337215          ],
337216          "cpe": "cpe:2.3:a:regenerate-unicode-properties:regenerate-unicode-properties:8.2.0:*:*:*:*:*:*:*",
337217          "purl": "pkg:npm/regenerate-unicode-properties@8.2.0",
337218          "swid": {
337219            "attachment": {}
337220          },
337221          "pedigree": {},
337222          "evidence": {},
337223          "signature": {
337224            "signature": {
337225              "publicKey": {}
337226            }
337227          },
337228          "modelCard": {
337229            "modelParameters": {
337230              "approach": {}
337231            },
337232            "quantitativeAnalysis": {
337233              "graphics": {}
337234            },
337235            "considerations": {}
337236          }
337237        },
337238        {
337239          "type": "library",
337240          "bom-ref": "pkg:npm/regenerator-runtime@0.13.5?package-id=e60ca585418462c7",
337241          "supplier": {},
337242          "name": "regenerator-runtime",
337243          "version": "0.13.5",
337244          "licenses": [
337245            {
337246              "license": {
337247                "id": "MIT"
337248              }
337249            }
337250          ],
337251          "cpe": "cpe:2.3:a:regenerator-runtime:regenerator-runtime:0.13.5:*:*:*:*:*:*:*",
337252          "purl": "pkg:npm/regenerator-runtime@0.13.5",
337253          "swid": {
337254            "attachment": {}
337255          },
337256          "pedigree": {},
337257          "evidence": {},
337258          "signature": {
337259            "signature": {
337260              "publicKey": {}
337261            }
337262          },
337263          "modelCard": {
337264            "modelParameters": {
337265              "approach": {}
337266            },
337267            "quantitativeAnalysis": {
337268              "graphics": {}
337269            },
337270            "considerations": {}
337271          }
337272        },
337273        {
337274          "type": "library",
337275          "bom-ref": "pkg:npm/regenerator-transform@0.14.4?package-id=f3fa9fff2cac387e",
337276          "supplier": {},
337277          "name": "regenerator-transform",
337278          "version": "0.14.4",
337279          "licenses": [
337280            {
337281              "license": {
337282                "id": "MIT"
337283              }
337284            }
337285          ],
337286          "cpe": "cpe:2.3:a:regenerator-transform:regenerator-transform:0.14.4:*:*:*:*:*:*:*",
337287          "purl": "pkg:npm/regenerator-transform@0.14.4",
337288          "swid": {
337289            "attachment": {}
337290          },
337291          "pedigree": {},
337292          "evidence": {},
337293          "signature": {
337294            "signature": {
337295              "publicKey": {}
337296            }
337297          },
337298          "modelCard": {
337299            "modelParameters": {
337300              "approach": {}
337301            },
337302            "quantitativeAnalysis": {
337303              "graphics": {}
337304            },
337305            "considerations": {}
337306          }
337307        },
337308        {
337309          "type": "library",
337310          "bom-ref": "pkg:npm/regex-not@1.0.2?package-id=db256d17333d9b26",
337311          "supplier": {},
337312          "name": "regex-not",
337313          "version": "1.0.2",
337314          "licenses": [
337315            {
337316              "license": {
337317                "id": "MIT"
337318              }
337319            }
337320          ],
337321          "cpe": "cpe:2.3:a:regex-not:regex-not:1.0.2:*:*:*:*:*:*:*",
337322          "purl": "pkg:npm/regex-not@1.0.2",
337323          "swid": {
337324            "attachment": {}
337325          },
337326          "pedigree": {},
337327          "evidence": {},
337328          "signature": {
337329            "signature": {
337330              "publicKey": {}
337331            }
337332          },
337333          "modelCard": {
337334            "modelParameters": {
337335              "approach": {}
337336            },
337337            "quantitativeAnalysis": {
337338              "graphics": {}
337339            },
337340            "considerations": {}
337341          }
337342        },
337343        {
337344          "type": "library",
337345          "bom-ref": "pkg:npm/regexp.prototype.flags@1.3.0?package-id=99aabe9b3916e4a2",
337346          "supplier": {},
337347          "name": "regexp.prototype.flags",
337348          "version": "1.3.0",
337349          "licenses": [
337350            {
337351              "license": {
337352                "id": "MIT"
337353              }
337354            }
337355          ],
337356          "cpe": "cpe:2.3:a:regexp.prototype.flags:regexp.prototype.flags:1.3.0:*:*:*:*:*:*:*",
337357          "purl": "pkg:npm/regexp.prototype.flags@1.3.0",
337358          "swid": {
337359            "attachment": {}
337360          },
337361          "pedigree": {},
337362          "evidence": {},
337363          "signature": {
337364            "signature": {
337365              "publicKey": {}
337366            }
337367          },
337368          "modelCard": {
337369            "modelParameters": {
337370              "approach": {}
337371            },
337372            "quantitativeAnalysis": {
337373              "graphics": {}
337374            },
337375            "considerations": {}
337376          }
337377        },
337378        {
337379          "type": "library",
337380          "bom-ref": "pkg:npm/regexpu-core@4.7.0?package-id=898d6e3142949b37",
337381          "supplier": {},
337382          "name": "regexpu-core",
337383          "version": "4.7.0",
337384          "licenses": [
337385            {
337386              "license": {
337387                "id": "MIT"
337388              }
337389            }
337390          ],
337391          "cpe": "cpe:2.3:a:regexpu-core:regexpu-core:4.7.0:*:*:*:*:*:*:*",
337392          "purl": "pkg:npm/regexpu-core@4.7.0",
337393          "swid": {
337394            "attachment": {}
337395          },
337396          "pedigree": {},
337397          "evidence": {},
337398          "signature": {
337399            "signature": {
337400              "publicKey": {}
337401            }
337402          },
337403          "modelCard": {
337404            "modelParameters": {
337405              "approach": {}
337406            },
337407            "quantitativeAnalysis": {
337408              "graphics": {}
337409            },
337410            "considerations": {}
337411          }
337412        },
337413        {
337414          "type": "library",
337415          "bom-ref": "pkg:npm/regjsgen@0.5.1?package-id=5220fef0b074ca5f",
337416          "supplier": {},
337417          "name": "regjsgen",
337418          "version": "0.5.1",
337419          "licenses": [
337420            {
337421              "license": {
337422                "id": "MIT"
337423              }
337424            }
337425          ],
337426          "cpe": "cpe:2.3:a:regjsgen:regjsgen:0.5.1:*:*:*:*:*:*:*",
337427          "purl": "pkg:npm/regjsgen@0.5.1",
337428          "swid": {
337429            "attachment": {}
337430          },
337431          "pedigree": {},
337432          "evidence": {},
337433          "signature": {
337434            "signature": {
337435              "publicKey": {}
337436            }
337437          },
337438          "modelCard": {
337439            "modelParameters": {
337440              "approach": {}
337441            },
337442            "quantitativeAnalysis": {
337443              "graphics": {}
337444            },
337445            "considerations": {}
337446          }
337447        },
337448        {
337449          "type": "library",
337450          "bom-ref": "pkg:npm/regjsparser@0.6.4?package-id=1980156de22a4857",
337451          "supplier": {},
337452          "name": "regjsparser",
337453          "version": "0.6.4",
337454          "licenses": [
337455            {
337456              "license": {
337457                "id": "BSD-2-Clause"
337458              }
337459            }
337460          ],
337461          "cpe": "cpe:2.3:a:regjsparser:regjsparser:0.6.4:*:*:*:*:*:*:*",
337462          "purl": "pkg:npm/regjsparser@0.6.4",
337463          "swid": {
337464            "attachment": {}
337465          },
337466          "pedigree": {},
337467          "evidence": {},
337468          "signature": {
337469            "signature": {
337470              "publicKey": {}
337471            }
337472          },
337473          "modelCard": {
337474            "modelParameters": {
337475              "approach": {}
337476            },
337477            "quantitativeAnalysis": {
337478              "graphics": {}
337479            },
337480            "considerations": {}
337481          }
337482        },
337483        {
337484          "type": "library",
337485          "bom-ref": "pkg:npm/release-zalgo@1.0.0?package-id=db5703d1bd7bba58",
337486          "supplier": {},
337487          "name": "release-zalgo",
337488          "version": "1.0.0",
337489          "cpe": "cpe:2.3:a:release-zalgo:release-zalgo:1.0.0:*:*:*:*:*:*:*",
337490          "purl": "pkg:npm/release-zalgo@1.0.0",
337491          "swid": {
337492            "attachment": {}
337493          },
337494          "pedigree": {},
337495          "evidence": {},
337496          "signature": {
337497            "signature": {
337498              "publicKey": {}
337499            }
337500          },
337501          "modelCard": {
337502            "modelParameters": {
337503              "approach": {}
337504            },
337505            "quantitativeAnalysis": {
337506              "graphics": {}
337507            },
337508            "considerations": {}
337509          }
337510        },
337511        {
337512          "type": "library",
337513          "bom-ref": "pkg:npm/remove-trailing-separator@1.1.0?package-id=bdd0025381df0592",
337514          "supplier": {},
337515          "name": "remove-trailing-separator",
337516          "version": "1.1.0",
337517          "licenses": [
337518            {
337519              "license": {
337520                "id": "ISC"
337521              }
337522            }
337523          ],
337524          "cpe": "cpe:2.3:a:remove-trailing-separator:remove-trailing-separator:1.1.0:*:*:*:*:*:*:*",
337525          "purl": "pkg:npm/remove-trailing-separator@1.1.0",
337526          "swid": {
337527            "attachment": {}
337528          },
337529          "pedigree": {},
337530          "evidence": {},
337531          "signature": {
337532            "signature": {
337533              "publicKey": {}
337534            }
337535          },
337536          "modelCard": {
337537            "modelParameters": {
337538              "approach": {}
337539            },
337540            "quantitativeAnalysis": {
337541              "graphics": {}
337542            },
337543            "considerations": {}
337544          }
337545        },
337546        {
337547          "type": "library",
337548          "bom-ref": "pkg:npm/repeat-element@1.1.3?package-id=7a5628791419538c",
337549          "supplier": {},
337550          "name": "repeat-element",
337551          "version": "1.1.3",
337552          "licenses": [
337553            {
337554              "license": {
337555                "id": "MIT"
337556              }
337557            }
337558          ],
337559          "cpe": "cpe:2.3:a:repeat-element:repeat-element:1.1.3:*:*:*:*:*:*:*",
337560          "purl": "pkg:npm/repeat-element@1.1.3",
337561          "swid": {
337562            "attachment": {}
337563          },
337564          "pedigree": {},
337565          "evidence": {},
337566          "signature": {
337567            "signature": {
337568              "publicKey": {}
337569            }
337570          },
337571          "modelCard": {
337572            "modelParameters": {
337573              "approach": {}
337574            },
337575            "quantitativeAnalysis": {
337576              "graphics": {}
337577            },
337578            "considerations": {}
337579          }
337580        },
337581        {
337582          "type": "library",
337583          "bom-ref": "pkg:npm/repeat-string@1.6.1?package-id=389a9f24ee816b1d",
337584          "supplier": {},
337585          "name": "repeat-string",
337586          "version": "1.6.1",
337587          "licenses": [
337588            {
337589              "license": {
337590                "id": "MIT"
337591              }
337592            }
337593          ],
337594          "cpe": "cpe:2.3:a:repeat-string:repeat-string:1.6.1:*:*:*:*:*:*:*",
337595          "purl": "pkg:npm/repeat-string@1.6.1",
337596          "swid": {
337597            "attachment": {}
337598          },
337599          "pedigree": {},
337600          "evidence": {},
337601          "signature": {
337602            "signature": {
337603              "publicKey": {}
337604            }
337605          },
337606          "modelCard": {
337607            "modelParameters": {
337608              "approach": {}
337609            },
337610            "quantitativeAnalysis": {
337611              "graphics": {}
337612            },
337613            "considerations": {}
337614          }
337615        },
337616        {
337617          "type": "library",
337618          "bom-ref": "pkg:npm/repeating@2.0.1?package-id=b75c2d3ed822953",
337619          "supplier": {},
337620          "name": "repeating",
337621          "version": "2.0.1",
337622          "licenses": [
337623            {
337624              "license": {
337625                "id": "MIT"
337626              }
337627            }
337628          ],
337629          "cpe": "cpe:2.3:a:repeating:repeating:2.0.1:*:*:*:*:*:*:*",
337630          "purl": "pkg:npm/repeating@2.0.1",
337631          "swid": {
337632            "attachment": {}
337633          },
337634          "pedigree": {},
337635          "evidence": {},
337636          "signature": {
337637            "signature": {
337638              "publicKey": {}
337639            }
337640          },
337641          "modelCard": {
337642            "modelParameters": {
337643              "approach": {}
337644            },
337645            "quantitativeAnalysis": {
337646              "graphics": {}
337647            },
337648            "considerations": {}
337649          }
337650        },
337651        {
337652          "type": "library",
337653          "bom-ref": "pkg:npm/request@2.88.2?package-id=4634e70e292d207a",
337654          "supplier": {},
337655          "name": "request",
337656          "version": "2.88.2",
337657          "licenses": [
337658            {
337659              "license": {
337660                "id": "Apache-2.0"
337661              }
337662            }
337663          ],
337664          "cpe": "cpe:2.3:a:request:request:2.88.2:*:*:*:*:*:*:*",
337665          "purl": "pkg:npm/request@2.88.2",
337666          "swid": {
337667            "attachment": {}
337668          },
337669          "pedigree": {},
337670          "evidence": {},
337671          "signature": {
337672            "signature": {
337673              "publicKey": {}
337674            }
337675          },
337676          "modelCard": {
337677            "modelParameters": {
337678              "approach": {}
337679            },
337680            "quantitativeAnalysis": {
337681              "graphics": {}
337682            },
337683            "considerations": {}
337684          }
337685        },
337686        {
337687          "type": "library",
337688          "bom-ref": "pkg:npm/request-promise-core@1.1.3?package-id=f1b498835581058f",
337689          "supplier": {},
337690          "name": "request-promise-core",
337691          "version": "1.1.3",
337692          "licenses": [
337693            {
337694              "license": {
337695                "id": "ISC"
337696              }
337697            }
337698          ],
337699          "cpe": "cpe:2.3:a:request-promise-core:request-promise-core:1.1.3:*:*:*:*:*:*:*",
337700          "purl": "pkg:npm/request-promise-core@1.1.3",
337701          "swid": {
337702            "attachment": {}
337703          },
337704          "pedigree": {},
337705          "evidence": {},
337706          "signature": {
337707            "signature": {
337708              "publicKey": {}
337709            }
337710          },
337711          "modelCard": {
337712            "modelParameters": {
337713              "approach": {}
337714            },
337715            "quantitativeAnalysis": {
337716              "graphics": {}
337717            },
337718            "considerations": {}
337719          }
337720        },
337721        {
337722          "type": "library",
337723          "bom-ref": "pkg:npm/request-promise-native@1.0.8?package-id=8a01800dc1815499",
337724          "supplier": {},
337725          "name": "request-promise-native",
337726          "version": "1.0.8",
337727          "licenses": [
337728            {
337729              "license": {
337730                "id": "ISC"
337731              }
337732            }
337733          ],
337734          "cpe": "cpe:2.3:a:request-promise-native:request-promise-native:1.0.8:*:*:*:*:*:*:*",
337735          "purl": "pkg:npm/request-promise-native@1.0.8",
337736          "swid": {
337737            "attachment": {}
337738          },
337739          "pedigree": {},
337740          "evidence": {},
337741          "signature": {
337742            "signature": {
337743              "publicKey": {}
337744            }
337745          },
337746          "modelCard": {
337747            "modelParameters": {
337748              "approach": {}
337749            },
337750            "quantitativeAnalysis": {
337751              "graphics": {}
337752            },
337753            "considerations": {}
337754          }
337755        },
337756        {
337757          "type": "library",
337758          "bom-ref": "pkg:npm/require-directory@2.1.1?package-id=2ed1ecf732e63081",
337759          "supplier": {},
337760          "name": "require-directory",
337761          "version": "2.1.1",
337762          "cpe": "cpe:2.3:a:require-directory:require-directory:2.1.1:*:*:*:*:*:*:*",
337763          "purl": "pkg:npm/require-directory@2.1.1",
337764          "swid": {
337765            "attachment": {}
337766          },
337767          "pedigree": {},
337768          "evidence": {},
337769          "signature": {
337770            "signature": {
337771              "publicKey": {}
337772            }
337773          },
337774          "modelCard": {
337775            "modelParameters": {
337776              "approach": {}
337777            },
337778            "quantitativeAnalysis": {
337779              "graphics": {}
337780            },
337781            "considerations": {}
337782          }
337783        },
337784        {
337785          "type": "library",
337786          "bom-ref": "pkg:npm/require-directory@2.1.1?package-id=d50a6fdfc44fabcb",
337787          "supplier": {},
337788          "name": "require-directory",
337789          "version": "2.1.1",
337790          "licenses": [
337791            {
337792              "license": {
337793                "id": "MIT"
337794              }
337795            }
337796          ],
337797          "cpe": "cpe:2.3:a:require-directory:require-directory:2.1.1:*:*:*:*:*:*:*",
337798          "purl": "pkg:npm/require-directory@2.1.1",
337799          "swid": {
337800            "attachment": {}
337801          },
337802          "pedigree": {},
337803          "evidence": {},
337804          "signature": {
337805            "signature": {
337806              "publicKey": {}
337807            }
337808          },
337809          "modelCard": {
337810            "modelParameters": {
337811              "approach": {}
337812            },
337813            "quantitativeAnalysis": {
337814              "graphics": {}
337815            },
337816            "considerations": {}
337817          }
337818        },
337819        {
337820          "type": "library",
337821          "bom-ref": "pkg:npm/require-main-filename@1.0.1?package-id=350a6468a29f76c0",
337822          "supplier": {},
337823          "name": "require-main-filename",
337824          "version": "1.0.1",
337825          "licenses": [
337826            {
337827              "license": {
337828                "id": "ISC"
337829              }
337830            }
337831          ],
337832          "cpe": "cpe:2.3:a:require-main-filename:require-main-filename:1.0.1:*:*:*:*:*:*:*",
337833          "purl": "pkg:npm/require-main-filename@1.0.1",
337834          "swid": {
337835            "attachment": {}
337836          },
337837          "pedigree": {},
337838          "evidence": {},
337839          "signature": {
337840            "signature": {
337841              "publicKey": {}
337842            }
337843          },
337844          "modelCard": {
337845            "modelParameters": {
337846              "approach": {}
337847            },
337848            "quantitativeAnalysis": {
337849              "graphics": {}
337850            },
337851            "considerations": {}
337852          }
337853        },
337854        {
337855          "type": "library",
337856          "bom-ref": "pkg:npm/require-main-filename@2.0.0?package-id=8abd518d7d234eba",
337857          "supplier": {},
337858          "name": "require-main-filename",
337859          "version": "2.0.0",
337860          "cpe": "cpe:2.3:a:require-main-filename:require-main-filename:2.0.0:*:*:*:*:*:*:*",
337861          "purl": "pkg:npm/require-main-filename@2.0.0",
337862          "swid": {
337863            "attachment": {}
337864          },
337865          "pedigree": {},
337866          "evidence": {},
337867          "signature": {
337868            "signature": {
337869              "publicKey": {}
337870            }
337871          },
337872          "modelCard": {
337873            "modelParameters": {
337874              "approach": {}
337875            },
337876            "quantitativeAnalysis": {
337877              "graphics": {}
337878            },
337879            "considerations": {}
337880          }
337881        },
337882        {
337883          "type": "library",
337884          "bom-ref": "pkg:npm/requires-port@1.0.0?package-id=6a273325b79a1db9",
337885          "supplier": {},
337886          "name": "requires-port",
337887          "version": "1.0.0",
337888          "licenses": [
337889            {
337890              "license": {
337891                "id": "MIT"
337892              }
337893            }
337894          ],
337895          "cpe": "cpe:2.3:a:requires-port:requires-port:1.0.0:*:*:*:*:*:*:*",
337896          "purl": "pkg:npm/requires-port@1.0.0",
337897          "swid": {
337898            "attachment": {}
337899          },
337900          "pedigree": {},
337901          "evidence": {},
337902          "signature": {
337903            "signature": {
337904              "publicKey": {}
337905            }
337906          },
337907          "modelCard": {
337908            "modelParameters": {
337909              "approach": {}
337910            },
337911            "quantitativeAnalysis": {
337912              "graphics": {}
337913            },
337914            "considerations": {}
337915          }
337916        },
337917        {
337918          "type": "library",
337919          "bom-ref": "pkg:npm/resize-observer-polyfill@1.5.1?package-id=89a08d4f3d5e5c61",
337920          "supplier": {},
337921          "name": "resize-observer-polyfill",
337922          "version": "1.5.1",
337923          "licenses": [
337924            {
337925              "license": {
337926                "id": "MIT"
337927              }
337928            }
337929          ],
337930          "cpe": "cpe:2.3:a:resize-observer-polyfill:resize-observer-polyfill:1.5.1:*:*:*:*:*:*:*",
337931          "purl": "pkg:npm/resize-observer-polyfill@1.5.1",
337932          "swid": {
337933            "attachment": {}
337934          },
337935          "pedigree": {},
337936          "evidence": {},
337937          "signature": {
337938            "signature": {
337939              "publicKey": {}
337940            }
337941          },
337942          "modelCard": {
337943            "modelParameters": {
337944              "approach": {}
337945            },
337946            "quantitativeAnalysis": {
337947              "graphics": {}
337948            },
337949            "considerations": {}
337950          }
337951        },
337952        {
337953          "type": "library",
337954          "bom-ref": "pkg:npm/resolve@1.15.1?package-id=39bfb438c9d35862",
337955          "supplier": {},
337956          "name": "resolve",
337957          "version": "1.15.1",
337958          "licenses": [
337959            {
337960              "license": {
337961                "id": "MIT"
337962              }
337963            }
337964          ],
337965          "cpe": "cpe:2.3:a:resolve:resolve:1.15.1:*:*:*:*:*:*:*",
337966          "purl": "pkg:npm/resolve@1.15.1",
337967          "swid": {
337968            "attachment": {}
337969          },
337970          "pedigree": {},
337971          "evidence": {},
337972          "signature": {
337973            "signature": {
337974              "publicKey": {}
337975            }
337976          },
337977          "modelCard": {
337978            "modelParameters": {
337979              "approach": {}
337980            },
337981            "quantitativeAnalysis": {
337982              "graphics": {}
337983            },
337984            "considerations": {}
337985          }
337986        },
337987        {
337988          "type": "library",
337989          "bom-ref": "pkg:npm/resolve-cwd@2.0.0?package-id=d535f68a0696c34a",
337990          "supplier": {},
337991          "name": "resolve-cwd",
337992          "version": "2.0.0",
337993          "licenses": [
337994            {
337995              "license": {
337996                "id": "MIT"
337997              }
337998            }
337999          ],
338000          "cpe": "cpe:2.3:a:resolve-cwd:resolve-cwd:2.0.0:*:*:*:*:*:*:*",
338001          "purl": "pkg:npm/resolve-cwd@2.0.0",
338002          "swid": {
338003            "attachment": {}
338004          },
338005          "pedigree": {},
338006          "evidence": {},
338007          "signature": {
338008            "signature": {
338009              "publicKey": {}
338010            }
338011          },
338012          "modelCard": {
338013            "modelParameters": {
338014              "approach": {}
338015            },
338016            "quantitativeAnalysis": {
338017              "graphics": {}
338018            },
338019            "considerations": {}
338020          }
338021        },
338022        {
338023          "type": "library",
338024          "bom-ref": "pkg:npm/resolve-from@3.0.0?package-id=d1aefd38347cbb84",
338025          "supplier": {},
338026          "name": "resolve-from",
338027          "version": "3.0.0",
338028          "licenses": [
338029            {
338030              "license": {
338031                "id": "MIT"
338032              }
338033            }
338034          ],
338035          "cpe": "cpe:2.3:a:resolve-from:resolve-from:3.0.0:*:*:*:*:*:*:*",
338036          "purl": "pkg:npm/resolve-from@3.0.0",
338037          "swid": {
338038            "attachment": {}
338039          },
338040          "pedigree": {},
338041          "evidence": {},
338042          "signature": {
338043            "signature": {
338044              "publicKey": {}
338045            }
338046          },
338047          "modelCard": {
338048            "modelParameters": {
338049              "approach": {}
338050            },
338051            "quantitativeAnalysis": {
338052              "graphics": {}
338053            },
338054            "considerations": {}
338055          }
338056        },
338057        {
338058          "type": "library",
338059          "bom-ref": "pkg:npm/resolve-from@5.0.0?package-id=30c4894f8cd93901",
338060          "supplier": {},
338061          "name": "resolve-from",
338062          "version": "5.0.0",
338063          "cpe": "cpe:2.3:a:resolve-from:resolve-from:5.0.0:*:*:*:*:*:*:*",
338064          "purl": "pkg:npm/resolve-from@5.0.0",
338065          "swid": {
338066            "attachment": {}
338067          },
338068          "pedigree": {},
338069          "evidence": {},
338070          "signature": {
338071            "signature": {
338072              "publicKey": {}
338073            }
338074          },
338075          "modelCard": {
338076            "modelParameters": {
338077              "approach": {}
338078            },
338079            "quantitativeAnalysis": {
338080              "graphics": {}
338081            },
338082            "considerations": {}
338083          }
338084        },
338085        {
338086          "type": "library",
338087          "bom-ref": "pkg:npm/resolve-url@0.2.1?package-id=f499f186cfcb1f57",
338088          "supplier": {},
338089          "name": "resolve-url",
338090          "version": "0.2.1",
338091          "licenses": [
338092            {
338093              "license": {
338094                "id": "MIT"
338095              }
338096            }
338097          ],
338098          "cpe": "cpe:2.3:a:resolve-url:resolve-url:0.2.1:*:*:*:*:*:*:*",
338099          "purl": "pkg:npm/resolve-url@0.2.1",
338100          "swid": {
338101            "attachment": {}
338102          },
338103          "pedigree": {},
338104          "evidence": {},
338105          "signature": {
338106            "signature": {
338107              "publicKey": {}
338108            }
338109          },
338110          "modelCard": {
338111            "modelParameters": {
338112              "approach": {}
338113            },
338114            "quantitativeAnalysis": {
338115              "graphics": {}
338116            },
338117            "considerations": {}
338118          }
338119        },
338120        {
338121          "type": "library",
338122          "bom-ref": "pkg:npm/restore-cursor@3.1.0?package-id=ae480bf27ec3e497",
338123          "supplier": {},
338124          "name": "restore-cursor",
338125          "version": "3.1.0",
338126          "licenses": [
338127            {
338128              "license": {
338129                "id": "MIT"
338130              }
338131            }
338132          ],
338133          "cpe": "cpe:2.3:a:restore-cursor:restore-cursor:3.1.0:*:*:*:*:*:*:*",
338134          "purl": "pkg:npm/restore-cursor@3.1.0",
338135          "swid": {
338136            "attachment": {}
338137          },
338138          "pedigree": {},
338139          "evidence": {},
338140          "signature": {
338141            "signature": {
338142              "publicKey": {}
338143            }
338144          },
338145          "modelCard": {
338146            "modelParameters": {
338147              "approach": {}
338148            },
338149            "quantitativeAnalysis": {
338150              "graphics": {}
338151            },
338152            "considerations": {}
338153          }
338154        },
338155        {
338156          "type": "library",
338157          "bom-ref": "pkg:npm/ret@0.1.15?package-id=29098e150f3c8d92",
338158          "supplier": {},
338159          "name": "ret",
338160          "version": "0.1.15",
338161          "licenses": [
338162            {
338163              "license": {
338164                "id": "MIT"
338165              }
338166            }
338167          ],
338168          "cpe": "cpe:2.3:a:ret:ret:0.1.15:*:*:*:*:*:*:*",
338169          "purl": "pkg:npm/ret@0.1.15",
338170          "swid": {
338171            "attachment": {}
338172          },
338173          "pedigree": {},
338174          "evidence": {},
338175          "signature": {
338176            "signature": {
338177              "publicKey": {}
338178            }
338179          },
338180          "modelCard": {
338181            "modelParameters": {
338182              "approach": {}
338183            },
338184            "quantitativeAnalysis": {
338185              "graphics": {}
338186            },
338187            "considerations": {}
338188          }
338189        },
338190        {
338191          "type": "library",
338192          "bom-ref": "pkg:npm/retry@0.12.0?package-id=248c574d879f4d9a",
338193          "supplier": {},
338194          "name": "retry",
338195          "version": "0.12.0",
338196          "licenses": [
338197            {
338198              "license": {
338199                "id": "MIT"
338200              }
338201            }
338202          ],
338203          "cpe": "cpe:2.3:a:retry:retry:0.12.0:*:*:*:*:*:*:*",
338204          "purl": "pkg:npm/retry@0.12.0",
338205          "swid": {
338206            "attachment": {}
338207          },
338208          "pedigree": {},
338209          "evidence": {},
338210          "signature": {
338211            "signature": {
338212              "publicKey": {}
338213            }
338214          },
338215          "modelCard": {
338216            "modelParameters": {
338217              "approach": {}
338218            },
338219            "quantitativeAnalysis": {
338220              "graphics": {}
338221            },
338222            "considerations": {}
338223          }
338224        },
338225        {
338226          "type": "library",
338227          "bom-ref": "pkg:npm/rfdc@1.1.4?package-id=7a645a2919b48d2b",
338228          "supplier": {},
338229          "name": "rfdc",
338230          "version": "1.1.4",
338231          "licenses": [
338232            {
338233              "license": {
338234                "id": "MIT"
338235              }
338236            }
338237          ],
338238          "cpe": "cpe:2.3:a:rfdc:rfdc:1.1.4:*:*:*:*:*:*:*",
338239          "purl": "pkg:npm/rfdc@1.1.4",
338240          "swid": {
338241            "attachment": {}
338242          },
338243          "pedigree": {},
338244          "evidence": {},
338245          "signature": {
338246            "signature": {
338247              "publicKey": {}
338248            }
338249          },
338250          "modelCard": {
338251            "modelParameters": {
338252              "approach": {}
338253            },
338254            "quantitativeAnalysis": {
338255              "graphics": {}
338256            },
338257            "considerations": {}
338258          }
338259        },
338260        {
338261          "type": "library",
338262          "bom-ref": "pkg:npm/rgb-regex@1.0.1?package-id=47dc7272ea584193",
338263          "supplier": {},
338264          "name": "rgb-regex",
338265          "version": "1.0.1",
338266          "licenses": [
338267            {
338268              "license": {
338269                "id": "MIT"
338270              }
338271            }
338272          ],
338273          "cpe": "cpe:2.3:a:rgb-regex:rgb-regex:1.0.1:*:*:*:*:*:*:*",
338274          "purl": "pkg:npm/rgb-regex@1.0.1",
338275          "swid": {
338276            "attachment": {}
338277          },
338278          "pedigree": {},
338279          "evidence": {},
338280          "signature": {
338281            "signature": {
338282              "publicKey": {}
338283            }
338284          },
338285          "modelCard": {
338286            "modelParameters": {
338287              "approach": {}
338288            },
338289            "quantitativeAnalysis": {
338290              "graphics": {}
338291            },
338292            "considerations": {}
338293          }
338294        },
338295        {
338296          "type": "library",
338297          "bom-ref": "pkg:npm/rgba-regex@1.0.0?package-id=770424dcbd7bcc5",
338298          "supplier": {},
338299          "name": "rgba-regex",
338300          "version": "1.0.0",
338301          "licenses": [
338302            {
338303              "license": {
338304                "id": "MIT"
338305              }
338306            }
338307          ],
338308          "cpe": "cpe:2.3:a:rgba-regex:rgba-regex:1.0.0:*:*:*:*:*:*:*",
338309          "purl": "pkg:npm/rgba-regex@1.0.0",
338310          "swid": {
338311            "attachment": {}
338312          },
338313          "pedigree": {},
338314          "evidence": {},
338315          "signature": {
338316            "signature": {
338317              "publicKey": {}
338318            }
338319          },
338320          "modelCard": {
338321            "modelParameters": {
338322              "approach": {}
338323            },
338324            "quantitativeAnalysis": {
338325              "graphics": {}
338326            },
338327            "considerations": {}
338328          }
338329        },
338330        {
338331          "type": "library",
338332          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=202bff53aafddeef",
338333          "supplier": {},
338334          "name": "rimraf",
338335          "version": "3.0.2",
338336          "cpe": "cpe:2.3:a:rimraf:rimraf:3.0.2:*:*:*:*:*:*:*",
338337          "purl": "pkg:npm/rimraf@3.0.2",
338338          "swid": {
338339            "attachment": {}
338340          },
338341          "pedigree": {},
338342          "evidence": {},
338343          "signature": {
338344            "signature": {
338345              "publicKey": {}
338346            }
338347          },
338348          "modelCard": {
338349            "modelParameters": {
338350              "approach": {}
338351            },
338352            "quantitativeAnalysis": {
338353              "graphics": {}
338354            },
338355            "considerations": {}
338356          }
338357        },
338358        {
338359          "type": "library",
338360          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=e94efbdfea35d1c0",
338361          "supplier": {},
338362          "name": "rimraf",
338363          "version": "3.0.2",
338364          "licenses": [
338365            {
338366              "license": {
338367                "id": "ISC"
338368              }
338369            }
338370          ],
338371          "cpe": "cpe:2.3:a:rimraf:rimraf:3.0.2:*:*:*:*:*:*:*",
338372          "purl": "pkg:npm/rimraf@3.0.2",
338373          "swid": {
338374            "attachment": {}
338375          },
338376          "pedigree": {},
338377          "evidence": {},
338378          "signature": {
338379            "signature": {
338380              "publicKey": {}
338381            }
338382          },
338383          "modelCard": {
338384            "modelParameters": {
338385              "approach": {}
338386            },
338387            "quantitativeAnalysis": {
338388              "graphics": {}
338389            },
338390            "considerations": {}
338391          }
338392        },
338393        {
338394          "type": "library",
338395          "bom-ref": "pkg:npm/ripemd160@2.0.2?package-id=9f2124f0db9d4c1f",
338396          "supplier": {},
338397          "name": "ripemd160",
338398          "version": "2.0.2",
338399          "licenses": [
338400            {
338401              "license": {
338402                "id": "MIT"
338403              }
338404            }
338405          ],
338406          "cpe": "cpe:2.3:a:ripemd160:ripemd160:2.0.2:*:*:*:*:*:*:*",
338407          "purl": "pkg:npm/ripemd160@2.0.2",
338408          "swid": {
338409            "attachment": {}
338410          },
338411          "pedigree": {},
338412          "evidence": {},
338413          "signature": {
338414            "signature": {
338415              "publicKey": {}
338416            }
338417          },
338418          "modelCard": {
338419            "modelParameters": {
338420              "approach": {}
338421            },
338422            "quantitativeAnalysis": {
338423              "graphics": {}
338424            },
338425            "considerations": {}
338426          }
338427        },
338428        {
338429          "type": "library",
338430          "bom-ref": "pkg:npm/rollup@2.1.0?package-id=f85ea06044ecca4a",
338431          "supplier": {},
338432          "name": "rollup",
338433          "version": "2.1.0",
338434          "licenses": [
338435            {
338436              "license": {
338437                "id": "MIT"
338438              }
338439            }
338440          ],
338441          "cpe": "cpe:2.3:a:rollup:rollup:2.1.0:*:*:*:*:*:*:*",
338442          "purl": "pkg:npm/rollup@2.1.0",
338443          "swid": {
338444            "attachment": {}
338445          },
338446          "pedigree": {},
338447          "evidence": {},
338448          "signature": {
338449            "signature": {
338450              "publicKey": {}
338451            }
338452          },
338453          "modelCard": {
338454            "modelParameters": {
338455              "approach": {}
338456            },
338457            "quantitativeAnalysis": {
338458              "graphics": {}
338459            },
338460            "considerations": {}
338461          }
338462        },
338463        {
338464          "type": "library",
338465          "bom-ref": "pkg:npm/run-async@2.4.1?package-id=7b855d78f0ad1d83",
338466          "supplier": {},
338467          "name": "run-async",
338468          "version": "2.4.1",
338469          "licenses": [
338470            {
338471              "license": {
338472                "id": "MIT"
338473              }
338474            }
338475          ],
338476          "cpe": "cpe:2.3:a:run-async:run-async:2.4.1:*:*:*:*:*:*:*",
338477          "purl": "pkg:npm/run-async@2.4.1",
338478          "swid": {
338479            "attachment": {}
338480          },
338481          "pedigree": {},
338482          "evidence": {},
338483          "signature": {
338484            "signature": {
338485              "publicKey": {}
338486            }
338487          },
338488          "modelCard": {
338489            "modelParameters": {
338490              "approach": {}
338491            },
338492            "quantitativeAnalysis": {
338493              "graphics": {}
338494            },
338495            "considerations": {}
338496          }
338497        },
338498        {
338499          "type": "library",
338500          "bom-ref": "pkg:npm/run-queue@1.0.3?package-id=9551cdeefb2e4ce5",
338501          "supplier": {},
338502          "name": "run-queue",
338503          "version": "1.0.3",
338504          "licenses": [
338505            {
338506              "license": {
338507                "id": "ISC"
338508              }
338509            }
338510          ],
338511          "cpe": "cpe:2.3:a:run-queue:run-queue:1.0.3:*:*:*:*:*:*:*",
338512          "purl": "pkg:npm/run-queue@1.0.3",
338513          "swid": {
338514            "attachment": {}
338515          },
338516          "pedigree": {},
338517          "evidence": {},
338518          "signature": {
338519            "signature": {
338520              "publicKey": {}
338521            }
338522          },
338523          "modelCard": {
338524            "modelParameters": {
338525              "approach": {}
338526            },
338527            "quantitativeAnalysis": {
338528              "graphics": {}
338529            },
338530            "considerations": {}
338531          }
338532        },
338533        {
338534          "type": "library",
338535          "bom-ref": "pkg:npm/rxjs@6.5.5?package-id=6c4d06e06259ee5f",
338536          "supplier": {},
338537          "name": "rxjs",
338538          "version": "6.5.5",
338539          "licenses": [
338540            {
338541              "license": {
338542                "id": "Apache-2.0"
338543              }
338544            }
338545          ],
338546          "cpe": "cpe:2.3:a:rxjs:rxjs:6.5.5:*:*:*:*:*:*:*",
338547          "purl": "pkg:npm/rxjs@6.5.5",
338548          "swid": {
338549            "attachment": {}
338550          },
338551          "pedigree": {},
338552          "evidence": {},
338553          "signature": {
338554            "signature": {
338555              "publicKey": {}
338556            }
338557          },
338558          "modelCard": {
338559            "modelParameters": {
338560              "approach": {}
338561            },
338562            "quantitativeAnalysis": {
338563              "graphics": {}
338564            },
338565            "considerations": {}
338566          }
338567        },
338568        {
338569          "type": "library",
338570          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=2fdf92a5fa50bede",
338571          "supplier": {},
338572          "name": "safe-buffer",
338573          "version": "5.1.2",
338574          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
338575          "purl": "pkg:npm/safe-buffer@5.1.2",
338576          "swid": {
338577            "attachment": {}
338578          },
338579          "pedigree": {},
338580          "evidence": {},
338581          "signature": {
338582            "signature": {
338583              "publicKey": {}
338584            }
338585          },
338586          "modelCard": {
338587            "modelParameters": {
338588              "approach": {}
338589            },
338590            "quantitativeAnalysis": {
338591              "graphics": {}
338592            },
338593            "considerations": {}
338594          }
338595        },
338596        {
338597          "type": "library",
338598          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=49d265d1cbcc6263",
338599          "supplier": {},
338600          "name": "safe-buffer",
338601          "version": "5.1.2",
338602          "licenses": [
338603            {
338604              "license": {
338605                "id": "MIT"
338606              }
338607            }
338608          ],
338609          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
338610          "purl": "pkg:npm/safe-buffer@5.1.2",
338611          "swid": {
338612            "attachment": {}
338613          },
338614          "pedigree": {},
338615          "evidence": {},
338616          "signature": {
338617            "signature": {
338618              "publicKey": {}
338619            }
338620          },
338621          "modelCard": {
338622            "modelParameters": {
338623              "approach": {}
338624            },
338625            "quantitativeAnalysis": {
338626              "graphics": {}
338627            },
338628            "considerations": {}
338629          }
338630        },
338631        {
338632          "type": "library",
338633          "bom-ref": "pkg:npm/safe-regex@1.1.0?package-id=228b9a748da4df4c",
338634          "supplier": {},
338635          "name": "safe-regex",
338636          "version": "1.1.0",
338637          "licenses": [
338638            {
338639              "license": {
338640                "id": "MIT"
338641              }
338642            }
338643          ],
338644          "cpe": "cpe:2.3:a:safe-regex:safe-regex:1.1.0:*:*:*:*:*:*:*",
338645          "purl": "pkg:npm/safe-regex@1.1.0",
338646          "swid": {
338647            "attachment": {}
338648          },
338649          "pedigree": {},
338650          "evidence": {},
338651          "signature": {
338652            "signature": {
338653              "publicKey": {}
338654            }
338655          },
338656          "modelCard": {
338657            "modelParameters": {
338658              "approach": {}
338659            },
338660            "quantitativeAnalysis": {
338661              "graphics": {}
338662            },
338663            "considerations": {}
338664          }
338665        },
338666        {
338667          "type": "library",
338668          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=8590432c1ecbd629",
338669          "supplier": {},
338670          "name": "safer-buffer",
338671          "version": "2.1.2",
338672          "licenses": [
338673            {
338674              "license": {
338675                "id": "MIT"
338676              }
338677            }
338678          ],
338679          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
338680          "purl": "pkg:npm/safer-buffer@2.1.2",
338681          "swid": {
338682            "attachment": {}
338683          },
338684          "pedigree": {},
338685          "evidence": {},
338686          "signature": {
338687            "signature": {
338688              "publicKey": {}
338689            }
338690          },
338691          "modelCard": {
338692            "modelParameters": {
338693              "approach": {}
338694            },
338695            "quantitativeAnalysis": {
338696              "graphics": {}
338697            },
338698            "considerations": {}
338699          }
338700        },
338701        {
338702          "type": "library",
338703          "bom-ref": "pkg:npm/sanitize-filename@1.6.3?package-id=bbd35a31ba18223c",
338704          "supplier": {},
338705          "name": "sanitize-filename",
338706          "version": "1.6.3",
338707          "licenses": [
338708            {
338709              "license": {
338710                "name": "WTFPL OR ISC"
338711              }
338712            }
338713          ],
338714          "cpe": "cpe:2.3:a:sanitize-filename:sanitize-filename:1.6.3:*:*:*:*:*:*:*",
338715          "purl": "pkg:npm/sanitize-filename@1.6.3",
338716          "swid": {
338717            "attachment": {}
338718          },
338719          "pedigree": {},
338720          "evidence": {},
338721          "signature": {
338722            "signature": {
338723              "publicKey": {}
338724            }
338725          },
338726          "modelCard": {
338727            "modelParameters": {
338728              "approach": {}
338729            },
338730            "quantitativeAnalysis": {
338731              "graphics": {}
338732            },
338733            "considerations": {}
338734          }
338735        },
338736        {
338737          "type": "library",
338738          "bom-ref": "pkg:npm/sass@1.26.3?package-id=f22da0d35db962b1",
338739          "supplier": {},
338740          "name": "sass",
338741          "version": "1.26.3",
338742          "licenses": [
338743            {
338744              "license": {
338745                "id": "MIT"
338746              }
338747            }
338748          ],
338749          "cpe": "cpe:2.3:a:sass:sass:1.26.3:*:*:*:*:*:*:*",
338750          "purl": "pkg:npm/sass@1.26.3",
338751          "swid": {
338752            "attachment": {}
338753          },
338754          "pedigree": {},
338755          "evidence": {},
338756          "signature": {
338757            "signature": {
338758              "publicKey": {}
338759            }
338760          },
338761          "modelCard": {
338762            "modelParameters": {
338763              "approach": {}
338764            },
338765            "quantitativeAnalysis": {
338766              "graphics": {}
338767            },
338768            "considerations": {}
338769          }
338770        },
338771        {
338772          "type": "library",
338773          "bom-ref": "pkg:npm/sass-graph@2.2.5?package-id=194903adf33b1dfe",
338774          "supplier": {},
338775          "name": "sass-graph",
338776          "version": "2.2.5",
338777          "licenses": [
338778            {
338779              "license": {
338780                "id": "MIT"
338781              }
338782            }
338783          ],
338784          "cpe": "cpe:2.3:a:sass-graph:sass-graph:2.2.5:*:*:*:*:*:*:*",
338785          "purl": "pkg:npm/sass-graph@2.2.5",
338786          "swid": {
338787            "attachment": {}
338788          },
338789          "pedigree": {},
338790          "evidence": {},
338791          "signature": {
338792            "signature": {
338793              "publicKey": {}
338794            }
338795          },
338796          "modelCard": {
338797            "modelParameters": {
338798              "approach": {}
338799            },
338800            "quantitativeAnalysis": {
338801              "graphics": {}
338802            },
338803            "considerations": {}
338804          }
338805        },
338806        {
338807          "type": "library",
338808          "bom-ref": "pkg:npm/sass-loader@8.0.2?package-id=7c45a3c99c46e60f",
338809          "supplier": {},
338810          "name": "sass-loader",
338811          "version": "8.0.2",
338812          "licenses": [
338813            {
338814              "license": {
338815                "id": "MIT"
338816              }
338817            }
338818          ],
338819          "cpe": "cpe:2.3:a:sass-loader:sass-loader:8.0.2:*:*:*:*:*:*:*",
338820          "purl": "pkg:npm/sass-loader@8.0.2",
338821          "swid": {
338822            "attachment": {}
338823          },
338824          "pedigree": {},
338825          "evidence": {},
338826          "signature": {
338827            "signature": {
338828              "publicKey": {}
338829            }
338830          },
338831          "modelCard": {
338832            "modelParameters": {
338833              "approach": {}
338834            },
338835            "quantitativeAnalysis": {
338836              "graphics": {}
338837            },
338838            "considerations": {}
338839          }
338840        },
338841        {
338842          "type": "library",
338843          "bom-ref": "pkg:npm/saucelabs@1.5.0?package-id=a5f8c67fa665ea6f",
338844          "supplier": {},
338845          "name": "saucelabs",
338846          "version": "1.5.0",
338847          "cpe": "cpe:2.3:a:saucelabs:saucelabs:1.5.0:*:*:*:*:*:*:*",
338848          "purl": "pkg:npm/saucelabs@1.5.0",
338849          "swid": {
338850            "attachment": {}
338851          },
338852          "pedigree": {},
338853          "evidence": {},
338854          "signature": {
338855            "signature": {
338856              "publicKey": {}
338857            }
338858          },
338859          "modelCard": {
338860            "modelParameters": {
338861              "approach": {}
338862            },
338863            "quantitativeAnalysis": {
338864              "graphics": {}
338865            },
338866            "considerations": {}
338867          }
338868        },
338869        {
338870          "type": "library",
338871          "bom-ref": "pkg:npm/sax@1.2.4?package-id=f596b5408ec8797f",
338872          "supplier": {},
338873          "name": "sax",
338874          "version": "1.2.4",
338875          "licenses": [
338876            {
338877              "license": {
338878                "id": "ISC"
338879              }
338880            }
338881          ],
338882          "cpe": "cpe:2.3:a:sax:sax:1.2.4:*:*:*:*:*:*:*",
338883          "purl": "pkg:npm/sax@1.2.4",
338884          "swid": {
338885            "attachment": {}
338886          },
338887          "pedigree": {},
338888          "evidence": {},
338889          "signature": {
338890            "signature": {
338891              "publicKey": {}
338892            }
338893          },
338894          "modelCard": {
338895            "modelParameters": {
338896              "approach": {}
338897            },
338898            "quantitativeAnalysis": {
338899              "graphics": {}
338900            },
338901            "considerations": {}
338902          }
338903        },
338904        {
338905          "type": "library",
338906          "bom-ref": "pkg:npm/schema-utils@2.6.6?package-id=b03b87eeebe46a7f",
338907          "supplier": {},
338908          "name": "schema-utils",
338909          "version": "2.6.6",
338910          "licenses": [
338911            {
338912              "license": {
338913                "id": "MIT"
338914              }
338915            }
338916          ],
338917          "cpe": "cpe:2.3:a:schema-utils:schema-utils:2.6.6:*:*:*:*:*:*:*",
338918          "purl": "pkg:npm/schema-utils@2.6.6",
338919          "swid": {
338920            "attachment": {}
338921          },
338922          "pedigree": {},
338923          "evidence": {},
338924          "signature": {
338925            "signature": {
338926              "publicKey": {}
338927            }
338928          },
338929          "modelCard": {
338930            "modelParameters": {
338931              "approach": {}
338932            },
338933            "quantitativeAnalysis": {
338934              "graphics": {}
338935            },
338936            "considerations": {}
338937          }
338938        },
338939        {
338940          "type": "library",
338941          "bom-ref": "pkg:npm/scss-tokenizer@0.2.3?package-id=8565406882d430c6",
338942          "supplier": {},
338943          "name": "scss-tokenizer",
338944          "version": "0.2.3",
338945          "licenses": [
338946            {
338947              "license": {
338948                "id": "MIT"
338949              }
338950            }
338951          ],
338952          "cpe": "cpe:2.3:a:scss-tokenizer:scss-tokenizer:0.2.3:*:*:*:*:*:*:*",
338953          "purl": "pkg:npm/scss-tokenizer@0.2.3",
338954          "swid": {
338955            "attachment": {}
338956          },
338957          "pedigree": {},
338958          "evidence": {},
338959          "signature": {
338960            "signature": {
338961              "publicKey": {}
338962            }
338963          },
338964          "modelCard": {
338965            "modelParameters": {
338966              "approach": {}
338967            },
338968            "quantitativeAnalysis": {
338969              "graphics": {}
338970            },
338971            "considerations": {}
338972          }
338973        },
338974        {
338975          "type": "library",
338976          "bom-ref": "pkg:npm/select-hose@2.0.0?package-id=8af66a5b2fd8e7e9",
338977          "supplier": {},
338978          "name": "select-hose",
338979          "version": "2.0.0",
338980          "licenses": [
338981            {
338982              "license": {
338983                "id": "MIT"
338984              }
338985            }
338986          ],
338987          "cpe": "cpe:2.3:a:select-hose:select-hose:2.0.0:*:*:*:*:*:*:*",
338988          "purl": "pkg:npm/select-hose@2.0.0",
338989          "swid": {
338990            "attachment": {}
338991          },
338992          "pedigree": {},
338993          "evidence": {},
338994          "signature": {
338995            "signature": {
338996              "publicKey": {}
338997            }
338998          },
338999          "modelCard": {
339000            "modelParameters": {
339001              "approach": {}
339002            },
339003            "quantitativeAnalysis": {
339004              "graphics": {}
339005            },
339006            "considerations": {}
339007          }
339008        },
339009        {
339010          "type": "library",
339011          "bom-ref": "pkg:npm/selenium-webdriver@3.6.0?package-id=d533dd4a412f8494",
339012          "supplier": {},
339013          "name": "selenium-webdriver",
339014          "version": "3.6.0",
339015          "licenses": [
339016            {
339017              "license": {
339018                "id": "Apache-2.0"
339019              }
339020            }
339021          ],
339022          "cpe": "cpe:2.3:a:selenium-webdriver:selenium-webdriver:3.6.0:*:*:*:*:*:*:*",
339023          "purl": "pkg:npm/selenium-webdriver@3.6.0",
339024          "swid": {
339025            "attachment": {}
339026          },
339027          "pedigree": {},
339028          "evidence": {},
339029          "signature": {
339030            "signature": {
339031              "publicKey": {}
339032            }
339033          },
339034          "modelCard": {
339035            "modelParameters": {
339036              "approach": {}
339037            },
339038            "quantitativeAnalysis": {
339039              "graphics": {}
339040            },
339041            "considerations": {}
339042          }
339043        },
339044        {
339045          "type": "library",
339046          "bom-ref": "pkg:npm/selfsigned@1.10.7?package-id=bad3f3a650ae9088",
339047          "supplier": {},
339048          "name": "selfsigned",
339049          "version": "1.10.7",
339050          "licenses": [
339051            {
339052              "license": {
339053                "id": "MIT"
339054              }
339055            }
339056          ],
339057          "cpe": "cpe:2.3:a:selfsigned:selfsigned:1.10.7:*:*:*:*:*:*:*",
339058          "purl": "pkg:npm/selfsigned@1.10.7",
339059          "swid": {
339060            "attachment": {}
339061          },
339062          "pedigree": {},
339063          "evidence": {},
339064          "signature": {
339065            "signature": {
339066              "publicKey": {}
339067            }
339068          },
339069          "modelCard": {
339070            "modelParameters": {
339071              "approach": {}
339072            },
339073            "quantitativeAnalysis": {
339074              "graphics": {}
339075            },
339076            "considerations": {}
339077          }
339078        },
339079        {
339080          "type": "library",
339081          "bom-ref": "pkg:npm/semver@6.3.0?package-id=9efb7de7198fcb1b",
339082          "supplier": {},
339083          "name": "semver",
339084          "version": "6.3.0",
339085          "cpe": "cpe:2.3:a:semver:semver:6.3.0:*:*:*:*:*:*:*",
339086          "purl": "pkg:npm/semver@6.3.0",
339087          "swid": {
339088            "attachment": {}
339089          },
339090          "pedigree": {},
339091          "evidence": {},
339092          "signature": {
339093            "signature": {
339094              "publicKey": {}
339095            }
339096          },
339097          "modelCard": {
339098            "modelParameters": {
339099              "approach": {}
339100            },
339101            "quantitativeAnalysis": {
339102              "graphics": {}
339103            },
339104            "considerations": {}
339105          }
339106        },
339107        {
339108          "type": "library",
339109          "bom-ref": "pkg:npm/semver@6.3.0?package-id=6c0c5fa7aaf83396",
339110          "supplier": {},
339111          "name": "semver",
339112          "version": "6.3.0",
339113          "licenses": [
339114            {
339115              "license": {
339116                "id": "ISC"
339117              }
339118            }
339119          ],
339120          "cpe": "cpe:2.3:a:semver:semver:6.3.0:*:*:*:*:*:*:*",
339121          "purl": "pkg:npm/semver@6.3.0",
339122          "swid": {
339123            "attachment": {}
339124          },
339125          "pedigree": {},
339126          "evidence": {},
339127          "signature": {
339128            "signature": {
339129              "publicKey": {}
339130            }
339131          },
339132          "modelCard": {
339133            "modelParameters": {
339134              "approach": {}
339135            },
339136            "quantitativeAnalysis": {
339137              "graphics": {}
339138            },
339139            "considerations": {}
339140          }
339141        },
339142        {
339143          "type": "library",
339144          "bom-ref": "pkg:npm/semver-dsl@1.0.1?package-id=de7fe536e7bf9f94",
339145          "supplier": {},
339146          "name": "semver-dsl",
339147          "version": "1.0.1",
339148          "licenses": [
339149            {
339150              "license": {
339151                "id": "MIT"
339152              }
339153            }
339154          ],
339155          "cpe": "cpe:2.3:a:semver-dsl:semver-dsl:1.0.1:*:*:*:*:*:*:*",
339156          "purl": "pkg:npm/semver-dsl@1.0.1",
339157          "swid": {
339158            "attachment": {}
339159          },
339160          "pedigree": {},
339161          "evidence": {},
339162          "signature": {
339163            "signature": {
339164              "publicKey": {}
339165            }
339166          },
339167          "modelCard": {
339168            "modelParameters": {
339169              "approach": {}
339170            },
339171            "quantitativeAnalysis": {
339172              "graphics": {}
339173            },
339174            "considerations": {}
339175          }
339176        },
339177        {
339178          "type": "library",
339179          "bom-ref": "pkg:npm/semver-intersect@1.4.0?package-id=cec5404734249cf8",
339180          "supplier": {},
339181          "name": "semver-intersect",
339182          "version": "1.4.0",
339183          "licenses": [
339184            {
339185              "license": {
339186                "id": "MIT"
339187              }
339188            }
339189          ],
339190          "cpe": "cpe:2.3:a:semver-intersect:semver-intersect:1.4.0:*:*:*:*:*:*:*",
339191          "purl": "pkg:npm/semver-intersect@1.4.0",
339192          "swid": {
339193            "attachment": {}
339194          },
339195          "pedigree": {},
339196          "evidence": {},
339197          "signature": {
339198            "signature": {
339199              "publicKey": {}
339200            }
339201          },
339202          "modelCard": {
339203            "modelParameters": {
339204              "approach": {}
339205            },
339206            "quantitativeAnalysis": {
339207              "graphics": {}
339208            },
339209            "considerations": {}
339210          }
339211        },
339212        {
339213          "type": "library",
339214          "bom-ref": "pkg:npm/send@0.17.1?package-id=f1e7d9325db96d69",
339215          "supplier": {},
339216          "name": "send",
339217          "version": "0.17.1",
339218          "licenses": [
339219            {
339220              "license": {
339221                "id": "MIT"
339222              }
339223            }
339224          ],
339225          "cpe": "cpe:2.3:a:send:send:0.17.1:*:*:*:*:*:*:*",
339226          "purl": "pkg:npm/send@0.17.1",
339227          "swid": {
339228            "attachment": {}
339229          },
339230          "pedigree": {},
339231          "evidence": {},
339232          "signature": {
339233            "signature": {
339234              "publicKey": {}
339235            }
339236          },
339237          "modelCard": {
339238            "modelParameters": {
339239              "approach": {}
339240            },
339241            "quantitativeAnalysis": {
339242              "graphics": {}
339243            },
339244            "considerations": {}
339245          }
339246        },
339247        {
339248          "type": "library",
339249          "bom-ref": "pkg:npm/serialize-javascript@2.1.2?package-id=cec685fec3ee75d0",
339250          "supplier": {},
339251          "name": "serialize-javascript",
339252          "version": "2.1.2",
339253          "licenses": [
339254            {
339255              "license": {
339256                "id": "BSD-3-Clause"
339257              }
339258            }
339259          ],
339260          "cpe": "cpe:2.3:a:serialize-javascript:serialize-javascript:2.1.2:*:*:*:*:*:*:*",
339261          "purl": "pkg:npm/serialize-javascript@2.1.2",
339262          "swid": {
339263            "attachment": {}
339264          },
339265          "pedigree": {},
339266          "evidence": {},
339267          "signature": {
339268            "signature": {
339269              "publicKey": {}
339270            }
339271          },
339272          "modelCard": {
339273            "modelParameters": {
339274              "approach": {}
339275            },
339276            "quantitativeAnalysis": {
339277              "graphics": {}
339278            },
339279            "considerations": {}
339280          }
339281        },
339282        {
339283          "type": "library",
339284          "bom-ref": "pkg:npm/serve-index@1.9.1?package-id=a5c034e8f1db52c3",
339285          "supplier": {},
339286          "name": "serve-index",
339287          "version": "1.9.1",
339288          "licenses": [
339289            {
339290              "license": {
339291                "id": "MIT"
339292              }
339293            }
339294          ],
339295          "cpe": "cpe:2.3:a:serve-index:serve-index:1.9.1:*:*:*:*:*:*:*",
339296          "purl": "pkg:npm/serve-index@1.9.1",
339297          "swid": {
339298            "attachment": {}
339299          },
339300          "pedigree": {},
339301          "evidence": {},
339302          "signature": {
339303            "signature": {
339304              "publicKey": {}
339305            }
339306          },
339307          "modelCard": {
339308            "modelParameters": {
339309              "approach": {}
339310            },
339311            "quantitativeAnalysis": {
339312              "graphics": {}
339313            },
339314            "considerations": {}
339315          }
339316        },
339317        {
339318          "type": "library",
339319          "bom-ref": "pkg:npm/serve-static@1.14.1?package-id=5ae5bf07d57ad84c",
339320          "supplier": {},
339321          "name": "serve-static",
339322          "version": "1.14.1",
339323          "licenses": [
339324            {
339325              "license": {
339326                "id": "MIT"
339327              }
339328            }
339329          ],
339330          "cpe": "cpe:2.3:a:serve-static:serve-static:1.14.1:*:*:*:*:*:*:*",
339331          "purl": "pkg:npm/serve-static@1.14.1",
339332          "swid": {
339333            "attachment": {}
339334          },
339335          "pedigree": {},
339336          "evidence": {},
339337          "signature": {
339338            "signature": {
339339              "publicKey": {}
339340            }
339341          },
339342          "modelCard": {
339343            "modelParameters": {
339344              "approach": {}
339345            },
339346            "quantitativeAnalysis": {
339347              "graphics": {}
339348            },
339349            "considerations": {}
339350          }
339351        },
339352        {
339353          "type": "library",
339354          "bom-ref": "pkg:npm/set-blocking@2.0.0?package-id=1c62830232d6b690",
339355          "supplier": {},
339356          "name": "set-blocking",
339357          "version": "2.0.0",
339358          "cpe": "cpe:2.3:a:set-blocking:set-blocking:2.0.0:*:*:*:*:*:*:*",
339359          "purl": "pkg:npm/set-blocking@2.0.0",
339360          "swid": {
339361            "attachment": {}
339362          },
339363          "pedigree": {},
339364          "evidence": {},
339365          "signature": {
339366            "signature": {
339367              "publicKey": {}
339368            }
339369          },
339370          "modelCard": {
339371            "modelParameters": {
339372              "approach": {}
339373            },
339374            "quantitativeAnalysis": {
339375              "graphics": {}
339376            },
339377            "considerations": {}
339378          }
339379        },
339380        {
339381          "type": "library",
339382          "bom-ref": "pkg:npm/set-blocking@2.0.0?package-id=b1db40006369094d",
339383          "supplier": {},
339384          "name": "set-blocking",
339385          "version": "2.0.0",
339386          "licenses": [
339387            {
339388              "license": {
339389                "id": "ISC"
339390              }
339391            }
339392          ],
339393          "cpe": "cpe:2.3:a:set-blocking:set-blocking:2.0.0:*:*:*:*:*:*:*",
339394          "purl": "pkg:npm/set-blocking@2.0.0",
339395          "swid": {
339396            "attachment": {}
339397          },
339398          "pedigree": {},
339399          "evidence": {},
339400          "signature": {
339401            "signature": {
339402              "publicKey": {}
339403            }
339404          },
339405          "modelCard": {
339406            "modelParameters": {
339407              "approach": {}
339408            },
339409            "quantitativeAnalysis": {
339410              "graphics": {}
339411            },
339412            "considerations": {}
339413          }
339414        },
339415        {
339416          "type": "library",
339417          "bom-ref": "pkg:npm/set-immediate-shim@1.0.1?package-id=6f1975be32135d7a",
339418          "supplier": {},
339419          "name": "set-immediate-shim",
339420          "version": "1.0.1",
339421          "licenses": [
339422            {
339423              "license": {
339424                "id": "MIT"
339425              }
339426            }
339427          ],
339428          "cpe": "cpe:2.3:a:set-immediate-shim:set-immediate-shim:1.0.1:*:*:*:*:*:*:*",
339429          "purl": "pkg:npm/set-immediate-shim@1.0.1",
339430          "swid": {
339431            "attachment": {}
339432          },
339433          "pedigree": {},
339434          "evidence": {},
339435          "signature": {
339436            "signature": {
339437              "publicKey": {}
339438            }
339439          },
339440          "modelCard": {
339441            "modelParameters": {
339442              "approach": {}
339443            },
339444            "quantitativeAnalysis": {
339445              "graphics": {}
339446            },
339447            "considerations": {}
339448          }
339449        },
339450        {
339451          "type": "library",
339452          "bom-ref": "pkg:npm/set-value@2.0.1?package-id=cfa5c525718fdfb0",
339453          "supplier": {},
339454          "name": "set-value",
339455          "version": "2.0.1",
339456          "licenses": [
339457            {
339458              "license": {
339459                "id": "MIT"
339460              }
339461            }
339462          ],
339463          "cpe": "cpe:2.3:a:set-value:set-value:2.0.1:*:*:*:*:*:*:*",
339464          "purl": "pkg:npm/set-value@2.0.1",
339465          "swid": {
339466            "attachment": {}
339467          },
339468          "pedigree": {},
339469          "evidence": {},
339470          "signature": {
339471            "signature": {
339472              "publicKey": {}
339473            }
339474          },
339475          "modelCard": {
339476            "modelParameters": {
339477              "approach": {}
339478            },
339479            "quantitativeAnalysis": {
339480              "graphics": {}
339481            },
339482            "considerations": {}
339483          }
339484        },
339485        {
339486          "type": "library",
339487          "bom-ref": "pkg:npm/setimmediate@1.0.5?package-id=bda696b52b2c73e4",
339488          "supplier": {},
339489          "name": "setimmediate",
339490          "version": "1.0.5",
339491          "licenses": [
339492            {
339493              "license": {
339494                "id": "MIT"
339495              }
339496            }
339497          ],
339498          "cpe": "cpe:2.3:a:setimmediate:setimmediate:1.0.5:*:*:*:*:*:*:*",
339499          "purl": "pkg:npm/setimmediate@1.0.5",
339500          "swid": {
339501            "attachment": {}
339502          },
339503          "pedigree": {},
339504          "evidence": {},
339505          "signature": {
339506            "signature": {
339507              "publicKey": {}
339508            }
339509          },
339510          "modelCard": {
339511            "modelParameters": {
339512              "approach": {}
339513            },
339514            "quantitativeAnalysis": {
339515              "graphics": {}
339516            },
339517            "considerations": {}
339518          }
339519        },
339520        {
339521          "type": "library",
339522          "bom-ref": "pkg:npm/setprototypeof@1.1.1?package-id=a6f8366ddad4e2ae",
339523          "supplier": {},
339524          "name": "setprototypeof",
339525          "version": "1.1.1",
339526          "licenses": [
339527            {
339528              "license": {
339529                "id": "ISC"
339530              }
339531            }
339532          ],
339533          "cpe": "cpe:2.3:a:setprototypeof:setprototypeof:1.1.1:*:*:*:*:*:*:*",
339534          "purl": "pkg:npm/setprototypeof@1.1.1",
339535          "swid": {
339536            "attachment": {}
339537          },
339538          "pedigree": {},
339539          "evidence": {},
339540          "signature": {
339541            "signature": {
339542              "publicKey": {}
339543            }
339544          },
339545          "modelCard": {
339546            "modelParameters": {
339547              "approach": {}
339548            },
339549            "quantitativeAnalysis": {
339550              "graphics": {}
339551            },
339552            "considerations": {}
339553          }
339554        },
339555        {
339556          "type": "library",
339557          "bom-ref": "pkg:npm/sha.js@2.4.11?package-id=e604810b235b3e30",
339558          "supplier": {},
339559          "name": "sha.js",
339560          "version": "2.4.11",
339561          "licenses": [
339562            {
339563              "license": {
339564                "name": "(MIT AND BSD-3-Clause)"
339565              }
339566            }
339567          ],
339568          "cpe": "cpe:2.3:a:sha.js:sha.js:2.4.11:*:*:*:*:*:*:*",
339569          "purl": "pkg:npm/sha.js@2.4.11",
339570          "swid": {
339571            "attachment": {}
339572          },
339573          "pedigree": {},
339574          "evidence": {},
339575          "signature": {
339576            "signature": {
339577              "publicKey": {}
339578            }
339579          },
339580          "modelCard": {
339581            "modelParameters": {
339582              "approach": {}
339583            },
339584            "quantitativeAnalysis": {
339585              "graphics": {}
339586            },
339587            "considerations": {}
339588          }
339589        },
339590        {
339591          "type": "library",
339592          "bom-ref": "pkg:npm/shallow-clone@3.0.1?package-id=86cc63a08b71bac1",
339593          "supplier": {},
339594          "name": "shallow-clone",
339595          "version": "3.0.1",
339596          "licenses": [
339597            {
339598              "license": {
339599                "id": "MIT"
339600              }
339601            }
339602          ],
339603          "cpe": "cpe:2.3:a:shallow-clone:shallow-clone:3.0.1:*:*:*:*:*:*:*",
339604          "purl": "pkg:npm/shallow-clone@3.0.1",
339605          "swid": {
339606            "attachment": {}
339607          },
339608          "pedigree": {},
339609          "evidence": {},
339610          "signature": {
339611            "signature": {
339612              "publicKey": {}
339613            }
339614          },
339615          "modelCard": {
339616            "modelParameters": {
339617              "approach": {}
339618            },
339619            "quantitativeAnalysis": {
339620              "graphics": {}
339621            },
339622            "considerations": {}
339623          }
339624        },
339625        {
339626          "type": "library",
339627          "bom-ref": "pkg:npm/shebang-command@1.2.0?package-id=f8d4581415e4d4fe",
339628          "supplier": {},
339629          "name": "shebang-command",
339630          "version": "1.2.0",
339631          "licenses": [
339632            {
339633              "license": {
339634                "id": "MIT"
339635              }
339636            }
339637          ],
339638          "cpe": "cpe:2.3:a:shebang-command:shebang-command:1.2.0:*:*:*:*:*:*:*",
339639          "purl": "pkg:npm/shebang-command@1.2.0",
339640          "swid": {
339641            "attachment": {}
339642          },
339643          "pedigree": {},
339644          "evidence": {},
339645          "signature": {
339646            "signature": {
339647              "publicKey": {}
339648            }
339649          },
339650          "modelCard": {
339651            "modelParameters": {
339652              "approach": {}
339653            },
339654            "quantitativeAnalysis": {
339655              "graphics": {}
339656            },
339657            "considerations": {}
339658          }
339659        },
339660        {
339661          "type": "library",
339662          "bom-ref": "pkg:npm/shebang-command@2.0.0?package-id=8579f0fff10cc36c",
339663          "supplier": {},
339664          "name": "shebang-command",
339665          "version": "2.0.0",
339666          "cpe": "cpe:2.3:a:shebang-command:shebang-command:2.0.0:*:*:*:*:*:*:*",
339667          "purl": "pkg:npm/shebang-command@2.0.0",
339668          "swid": {
339669            "attachment": {}
339670          },
339671          "pedigree": {},
339672          "evidence": {},
339673          "signature": {
339674            "signature": {
339675              "publicKey": {}
339676            }
339677          },
339678          "modelCard": {
339679            "modelParameters": {
339680              "approach": {}
339681            },
339682            "quantitativeAnalysis": {
339683              "graphics": {}
339684            },
339685            "considerations": {}
339686          }
339687        },
339688        {
339689          "type": "library",
339690          "bom-ref": "pkg:npm/shebang-regex@1.0.0?package-id=5e14111fb14d2b5d",
339691          "supplier": {},
339692          "name": "shebang-regex",
339693          "version": "1.0.0",
339694          "licenses": [
339695            {
339696              "license": {
339697                "id": "MIT"
339698              }
339699            }
339700          ],
339701          "cpe": "cpe:2.3:a:shebang-regex:shebang-regex:1.0.0:*:*:*:*:*:*:*",
339702          "purl": "pkg:npm/shebang-regex@1.0.0",
339703          "swid": {
339704            "attachment": {}
339705          },
339706          "pedigree": {},
339707          "evidence": {},
339708          "signature": {
339709            "signature": {
339710              "publicKey": {}
339711            }
339712          },
339713          "modelCard": {
339714            "modelParameters": {
339715              "approach": {}
339716            },
339717            "quantitativeAnalysis": {
339718              "graphics": {}
339719            },
339720            "considerations": {}
339721          }
339722        },
339723        {
339724          "type": "library",
339725          "bom-ref": "pkg:npm/shebang-regex@3.0.0?package-id=8014040af7436731",
339726          "supplier": {},
339727          "name": "shebang-regex",
339728          "version": "3.0.0",
339729          "cpe": "cpe:2.3:a:shebang-regex:shebang-regex:3.0.0:*:*:*:*:*:*:*",
339730          "purl": "pkg:npm/shebang-regex@3.0.0",
339731          "swid": {
339732            "attachment": {}
339733          },
339734          "pedigree": {},
339735          "evidence": {},
339736          "signature": {
339737            "signature": {
339738              "publicKey": {}
339739            }
339740          },
339741          "modelCard": {
339742            "modelParameters": {
339743              "approach": {}
339744            },
339745            "quantitativeAnalysis": {
339746              "graphics": {}
339747            },
339748            "considerations": {}
339749          }
339750        },
339751        {
339752          "type": "library",
339753          "bom-ref": "pkg:npm/signal-exit@3.0.2?package-id=e96b7c4fa861a759",
339754          "supplier": {},
339755          "name": "signal-exit",
339756          "version": "3.0.2",
339757          "licenses": [
339758            {
339759              "license": {
339760                "id": "ISC"
339761              }
339762            }
339763          ],
339764          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.2:*:*:*:*:*:*:*",
339765          "purl": "pkg:npm/signal-exit@3.0.2",
339766          "swid": {
339767            "attachment": {}
339768          },
339769          "pedigree": {},
339770          "evidence": {},
339771          "signature": {
339772            "signature": {
339773              "publicKey": {}
339774            }
339775          },
339776          "modelCard": {
339777            "modelParameters": {
339778              "approach": {}
339779            },
339780            "quantitativeAnalysis": {
339781              "graphics": {}
339782            },
339783            "considerations": {}
339784          }
339785        },
339786        {
339787          "type": "library",
339788          "bom-ref": "pkg:npm/signal-exit@3.0.6?package-id=d52743fe48622c2b",
339789          "supplier": {},
339790          "name": "signal-exit",
339791          "version": "3.0.6",
339792          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.6:*:*:*:*:*:*:*",
339793          "purl": "pkg:npm/signal-exit@3.0.6",
339794          "swid": {
339795            "attachment": {}
339796          },
339797          "pedigree": {},
339798          "evidence": {},
339799          "signature": {
339800            "signature": {
339801              "publicKey": {}
339802            }
339803          },
339804          "modelCard": {
339805            "modelParameters": {
339806              "approach": {}
339807            },
339808            "quantitativeAnalysis": {
339809              "graphics": {}
339810            },
339811            "considerations": {}
339812          }
339813        },
339814        {
339815          "type": "library",
339816          "bom-ref": "pkg:npm/simple-swizzle@0.2.2?package-id=2c4c9f3679a73ac5",
339817          "supplier": {},
339818          "name": "simple-swizzle",
339819          "version": "0.2.2",
339820          "licenses": [
339821            {
339822              "license": {
339823                "id": "MIT"
339824              }
339825            }
339826          ],
339827          "cpe": "cpe:2.3:a:simple-swizzle:simple-swizzle:0.2.2:*:*:*:*:*:*:*",
339828          "purl": "pkg:npm/simple-swizzle@0.2.2",
339829          "swid": {
339830            "attachment": {}
339831          },
339832          "pedigree": {},
339833          "evidence": {},
339834          "signature": {
339835            "signature": {
339836              "publicKey": {}
339837            }
339838          },
339839          "modelCard": {
339840            "modelParameters": {
339841              "approach": {}
339842            },
339843            "quantitativeAnalysis": {
339844              "graphics": {}
339845            },
339846            "considerations": {}
339847          }
339848        },
339849        {
339850          "type": "library",
339851          "bom-ref": "pkg:npm/simplebar@5.1.0?package-id=bc0efdadf560dc6f",
339852          "supplier": {},
339853          "name": "simplebar",
339854          "version": "5.1.0",
339855          "licenses": [
339856            {
339857              "license": {
339858                "id": "MIT"
339859              }
339860            }
339861          ],
339862          "cpe": "cpe:2.3:a:simplebar:simplebar:5.1.0:*:*:*:*:*:*:*",
339863          "purl": "pkg:npm/simplebar@5.1.0",
339864          "swid": {
339865            "attachment": {}
339866          },
339867          "pedigree": {},
339868          "evidence": {},
339869          "signature": {
339870            "signature": {
339871              "publicKey": {}
339872            }
339873          },
339874          "modelCard": {
339875            "modelParameters": {
339876              "approach": {}
339877            },
339878            "quantitativeAnalysis": {
339879              "graphics": {}
339880            },
339881            "considerations": {}
339882          }
339883        },
339884        {
339885          "type": "library",
339886          "bom-ref": "pkg:npm/slash@1.0.0?package-id=bd0b23f8bb345aad",
339887          "supplier": {},
339888          "name": "slash",
339889          "version": "1.0.0",
339890          "licenses": [
339891            {
339892              "license": {
339893                "id": "MIT"
339894              }
339895            }
339896          ],
339897          "cpe": "cpe:2.3:a:slash:slash:1.0.0:*:*:*:*:*:*:*",
339898          "purl": "pkg:npm/slash@1.0.0",
339899          "swid": {
339900            "attachment": {}
339901          },
339902          "pedigree": {},
339903          "evidence": {},
339904          "signature": {
339905            "signature": {
339906              "publicKey": {}
339907            }
339908          },
339909          "modelCard": {
339910            "modelParameters": {
339911              "approach": {}
339912            },
339913            "quantitativeAnalysis": {
339914              "graphics": {}
339915            },
339916            "considerations": {}
339917          }
339918        },
339919        {
339920          "type": "library",
339921          "bom-ref": "pkg:npm/slash@2.0.0?package-id=f62873fcb76d27ee",
339922          "supplier": {},
339923          "name": "slash",
339924          "version": "2.0.0",
339925          "cpe": "cpe:2.3:a:slash:slash:2.0.0:*:*:*:*:*:*:*",
339926          "purl": "pkg:npm/slash@2.0.0",
339927          "swid": {
339928            "attachment": {}
339929          },
339930          "pedigree": {},
339931          "evidence": {},
339932          "signature": {
339933            "signature": {
339934              "publicKey": {}
339935            }
339936          },
339937          "modelCard": {
339938            "modelParameters": {
339939              "approach": {}
339940            },
339941            "quantitativeAnalysis": {
339942              "graphics": {}
339943            },
339944            "considerations": {}
339945          }
339946        },
339947        {
339948          "type": "library",
339949          "bom-ref": "pkg:npm/smart-buffer@4.1.0?package-id=dec604430e751566",
339950          "supplier": {},
339951          "name": "smart-buffer",
339952          "version": "4.1.0",
339953          "licenses": [
339954            {
339955              "license": {
339956                "id": "MIT"
339957              }
339958            }
339959          ],
339960          "cpe": "cpe:2.3:a:smart-buffer:smart-buffer:4.1.0:*:*:*:*:*:*:*",
339961          "purl": "pkg:npm/smart-buffer@4.1.0",
339962          "swid": {
339963            "attachment": {}
339964          },
339965          "pedigree": {},
339966          "evidence": {},
339967          "signature": {
339968            "signature": {
339969              "publicKey": {}
339970            }
339971          },
339972          "modelCard": {
339973            "modelParameters": {
339974              "approach": {}
339975            },
339976            "quantitativeAnalysis": {
339977              "graphics": {}
339978            },
339979            "considerations": {}
339980          }
339981        },
339982        {
339983          "type": "library",
339984          "bom-ref": "pkg:npm/snapdragon@0.8.2?package-id=80fc60dfbdc25075",
339985          "supplier": {},
339986          "name": "snapdragon",
339987          "version": "0.8.2",
339988          "licenses": [
339989            {
339990              "license": {
339991                "id": "MIT"
339992              }
339993            }
339994          ],
339995          "cpe": "cpe:2.3:a:snapdragon:snapdragon:0.8.2:*:*:*:*:*:*:*",
339996          "purl": "pkg:npm/snapdragon@0.8.2",
339997          "swid": {
339998            "attachment": {}
339999          },
340000          "pedigree": {},
340001          "evidence": {},
340002          "signature": {
340003            "signature": {
340004              "publicKey": {}
340005            }
340006          },
340007          "modelCard": {
340008            "modelParameters": {
340009              "approach": {}
340010            },
340011            "quantitativeAnalysis": {
340012              "graphics": {}
340013            },
340014            "considerations": {}
340015          }
340016        },
340017        {
340018          "type": "library",
340019          "bom-ref": "pkg:npm/snapdragon-node@2.1.1?package-id=e5efe3f8e05298e",
340020          "supplier": {},
340021          "name": "snapdragon-node",
340022          "version": "2.1.1",
340023          "licenses": [
340024            {
340025              "license": {
340026                "id": "MIT"
340027              }
340028            }
340029          ],
340030          "cpe": "cpe:2.3:a:snapdragon-node:snapdragon-node:2.1.1:*:*:*:*:*:*:*",
340031          "purl": "pkg:npm/snapdragon-node@2.1.1",
340032          "swid": {
340033            "attachment": {}
340034          },
340035          "pedigree": {},
340036          "evidence": {},
340037          "signature": {
340038            "signature": {
340039              "publicKey": {}
340040            }
340041          },
340042          "modelCard": {
340043            "modelParameters": {
340044              "approach": {}
340045            },
340046            "quantitativeAnalysis": {
340047              "graphics": {}
340048            },
340049            "considerations": {}
340050          }
340051        },
340052        {
340053          "type": "library",
340054          "bom-ref": "pkg:npm/snapdragon-util@3.0.1?package-id=2f48154bfc653cd",
340055          "supplier": {},
340056          "name": "snapdragon-util",
340057          "version": "3.0.1",
340058          "licenses": [
340059            {
340060              "license": {
340061                "id": "MIT"
340062              }
340063            }
340064          ],
340065          "cpe": "cpe:2.3:a:snapdragon-util:snapdragon-util:3.0.1:*:*:*:*:*:*:*",
340066          "purl": "pkg:npm/snapdragon-util@3.0.1",
340067          "swid": {
340068            "attachment": {}
340069          },
340070          "pedigree": {},
340071          "evidence": {},
340072          "signature": {
340073            "signature": {
340074              "publicKey": {}
340075            }
340076          },
340077          "modelCard": {
340078            "modelParameters": {
340079              "approach": {}
340080            },
340081            "quantitativeAnalysis": {
340082              "graphics": {}
340083            },
340084            "considerations": {}
340085          }
340086        },
340087        {
340088          "type": "library",
340089          "bom-ref": "pkg:npm/socket.io@2.1.1?package-id=ac1fdda089a51e5c",
340090          "supplier": {},
340091          "name": "socket.io",
340092          "version": "2.1.1",
340093          "licenses": [
340094            {
340095              "license": {
340096                "id": "MIT"
340097              }
340098            }
340099          ],
340100          "cpe": "cpe:2.3:a:socket.io:socket.io:2.1.1:*:*:*:*:*:*:*",
340101          "purl": "pkg:npm/socket.io@2.1.1",
340102          "swid": {
340103            "attachment": {}
340104          },
340105          "pedigree": {},
340106          "evidence": {},
340107          "signature": {
340108            "signature": {
340109              "publicKey": {}
340110            }
340111          },
340112          "modelCard": {
340113            "modelParameters": {
340114              "approach": {}
340115            },
340116            "quantitativeAnalysis": {
340117              "graphics": {}
340118            },
340119            "considerations": {}
340120          }
340121        },
340122        {
340123          "type": "library",
340124          "bom-ref": "pkg:npm/socket.io-adapter@1.1.2?package-id=3502577d010b417",
340125          "supplier": {},
340126          "name": "socket.io-adapter",
340127          "version": "1.1.2",
340128          "licenses": [
340129            {
340130              "license": {
340131                "id": "MIT"
340132              }
340133            }
340134          ],
340135          "cpe": "cpe:2.3:a:socket.io-adapter:socket.io-adapter:1.1.2:*:*:*:*:*:*:*",
340136          "purl": "pkg:npm/socket.io-adapter@1.1.2",
340137          "swid": {
340138            "attachment": {}
340139          },
340140          "pedigree": {},
340141          "evidence": {},
340142          "signature": {
340143            "signature": {
340144              "publicKey": {}
340145            }
340146          },
340147          "modelCard": {
340148            "modelParameters": {
340149              "approach": {}
340150            },
340151            "quantitativeAnalysis": {
340152              "graphics": {}
340153            },
340154            "considerations": {}
340155          }
340156        },
340157        {
340158          "type": "library",
340159          "bom-ref": "pkg:npm/socket.io-client@2.1.1?package-id=a9152ab398f7100e",
340160          "supplier": {},
340161          "name": "socket.io-client",
340162          "version": "2.1.1",
340163          "licenses": [
340164            {
340165              "license": {
340166                "id": "MIT"
340167              }
340168            }
340169          ],
340170          "cpe": "cpe:2.3:a:socket.io-client:socket.io-client:2.1.1:*:*:*:*:*:*:*",
340171          "purl": "pkg:npm/socket.io-client@2.1.1",
340172          "swid": {
340173            "attachment": {}
340174          },
340175          "pedigree": {},
340176          "evidence": {},
340177          "signature": {
340178            "signature": {
340179              "publicKey": {}
340180            }
340181          },
340182          "modelCard": {
340183            "modelParameters": {
340184              "approach": {}
340185            },
340186            "quantitativeAnalysis": {
340187              "graphics": {}
340188            },
340189            "considerations": {}
340190          }
340191        },
340192        {
340193          "type": "library",
340194          "bom-ref": "pkg:npm/socket.io-parser@3.2.0?package-id=ee9ad0eda662c3e9",
340195          "supplier": {},
340196          "name": "socket.io-parser",
340197          "version": "3.2.0",
340198          "licenses": [
340199            {
340200              "license": {
340201                "id": "MIT"
340202              }
340203            }
340204          ],
340205          "cpe": "cpe:2.3:a:socket.io-parser:socket.io-parser:3.2.0:*:*:*:*:*:*:*",
340206          "purl": "pkg:npm/socket.io-parser@3.2.0",
340207          "swid": {
340208            "attachment": {}
340209          },
340210          "pedigree": {},
340211          "evidence": {},
340212          "signature": {
340213            "signature": {
340214              "publicKey": {}
340215            }
340216          },
340217          "modelCard": {
340218            "modelParameters": {
340219              "approach": {}
340220            },
340221            "quantitativeAnalysis": {
340222              "graphics": {}
340223            },
340224            "considerations": {}
340225          }
340226        },
340227        {
340228          "type": "library",
340229          "bom-ref": "pkg:npm/sockjs@0.3.19?package-id=1c18d0cfea55e740",
340230          "supplier": {},
340231          "name": "sockjs",
340232          "version": "0.3.19",
340233          "licenses": [
340234            {
340235              "license": {
340236                "id": "MIT"
340237              }
340238            }
340239          ],
340240          "cpe": "cpe:2.3:a:sockjs:sockjs:0.3.19:*:*:*:*:*:*:*",
340241          "purl": "pkg:npm/sockjs@0.3.19",
340242          "swid": {
340243            "attachment": {}
340244          },
340245          "pedigree": {},
340246          "evidence": {},
340247          "signature": {
340248            "signature": {
340249              "publicKey": {}
340250            }
340251          },
340252          "modelCard": {
340253            "modelParameters": {
340254              "approach": {}
340255            },
340256            "quantitativeAnalysis": {
340257              "graphics": {}
340258            },
340259            "considerations": {}
340260          }
340261        },
340262        {
340263          "type": "library",
340264          "bom-ref": "pkg:npm/sockjs-client@1.4.0?package-id=3afdfeaa1a019e5a",
340265          "supplier": {},
340266          "name": "sockjs-client",
340267          "version": "1.4.0",
340268          "licenses": [
340269            {
340270              "license": {
340271                "id": "MIT"
340272              }
340273            }
340274          ],
340275          "cpe": "cpe:2.3:a:sockjs-client:sockjs-client:1.4.0:*:*:*:*:*:*:*",
340276          "purl": "pkg:npm/sockjs-client@1.4.0",
340277          "swid": {
340278            "attachment": {}
340279          },
340280          "pedigree": {},
340281          "evidence": {},
340282          "signature": {
340283            "signature": {
340284              "publicKey": {}
340285            }
340286          },
340287          "modelCard": {
340288            "modelParameters": {
340289              "approach": {}
340290            },
340291            "quantitativeAnalysis": {
340292              "graphics": {}
340293            },
340294            "considerations": {}
340295          }
340296        },
340297        {
340298          "type": "library",
340299          "bom-ref": "pkg:npm/socks@2.3.3?package-id=e440ec4211ce2113",
340300          "supplier": {},
340301          "name": "socks",
340302          "version": "2.3.3",
340303          "licenses": [
340304            {
340305              "license": {
340306                "id": "MIT"
340307              }
340308            }
340309          ],
340310          "cpe": "cpe:2.3:a:socks:socks:2.3.3:*:*:*:*:*:*:*",
340311          "purl": "pkg:npm/socks@2.3.3",
340312          "swid": {
340313            "attachment": {}
340314          },
340315          "pedigree": {},
340316          "evidence": {},
340317          "signature": {
340318            "signature": {
340319              "publicKey": {}
340320            }
340321          },
340322          "modelCard": {
340323            "modelParameters": {
340324              "approach": {}
340325            },
340326            "quantitativeAnalysis": {
340327              "graphics": {}
340328            },
340329            "considerations": {}
340330          }
340331        },
340332        {
340333          "type": "library",
340334          "bom-ref": "pkg:npm/socks-proxy-agent@4.0.2?package-id=afaefe86263fde98",
340335          "supplier": {},
340336          "name": "socks-proxy-agent",
340337          "version": "4.0.2",
340338          "licenses": [
340339            {
340340              "license": {
340341                "id": "MIT"
340342              }
340343            }
340344          ],
340345          "cpe": "cpe:2.3:a:socks-proxy-agent:socks-proxy-agent:4.0.2:*:*:*:*:*:*:*",
340346          "purl": "pkg:npm/socks-proxy-agent@4.0.2",
340347          "swid": {
340348            "attachment": {}
340349          },
340350          "pedigree": {},
340351          "evidence": {},
340352          "signature": {
340353            "signature": {
340354              "publicKey": {}
340355            }
340356          },
340357          "modelCard": {
340358            "modelParameters": {
340359              "approach": {}
340360            },
340361            "quantitativeAnalysis": {
340362              "graphics": {}
340363            },
340364            "considerations": {}
340365          }
340366        },
340367        {
340368          "type": "library",
340369          "bom-ref": "pkg:npm/sonar-scanner@3.1.0?package-id=925bc7a907bcbaec",
340370          "supplier": {},
340371          "name": "sonar-scanner",
340372          "version": "3.1.0",
340373          "licenses": [
340374            {
340375              "license": {
340376                "id": "MIT"
340377              }
340378            }
340379          ],
340380          "cpe": "cpe:2.3:a:sonar-scanner:sonar-scanner:3.1.0:*:*:*:*:*:*:*",
340381          "purl": "pkg:npm/sonar-scanner@3.1.0",
340382          "swid": {
340383            "attachment": {}
340384          },
340385          "pedigree": {},
340386          "evidence": {},
340387          "signature": {
340388            "signature": {
340389              "publicKey": {}
340390            }
340391          },
340392          "modelCard": {
340393            "modelParameters": {
340394              "approach": {}
340395            },
340396            "quantitativeAnalysis": {
340397              "graphics": {}
340398            },
340399            "considerations": {}
340400          }
340401        },
340402        {
340403          "type": "library",
340404          "bom-ref": "pkg:maven/org.sonarsource.scanner.api/sonar-scanner-api@2.10.0.1189?package-id=e8f695e72a1af729",
340405          "supplier": {},
340406          "group": "org.sonarsource.scanner.api",
340407          "name": "sonar-scanner-api",
340408          "version": "2.10.0.1189",
340409          "cpe": "cpe:2.3:a:sonar-scanner-api:sonar-scanner-api:2.10.0.1189:*:*:*:*:*:*:*",
340410          "purl": "pkg:maven/org.sonarsource.scanner.api/sonar-scanner-api@2.10.0.1189",
340411          "swid": {
340412            "attachment": {}
340413          },
340414          "pedigree": {},
340415          "evidence": {},
340416          "signature": {
340417            "signature": {
340418              "publicKey": {}
340419            }
340420          },
340421          "modelCard": {
340422            "modelParameters": {
340423              "approach": {}
340424            },
340425            "quantitativeAnalysis": {
340426              "graphics": {}
340427            },
340428            "considerations": {}
340429          }
340430        },
340431        {
340432          "type": "library",
340433          "bom-ref": "pkg:maven/org.sonarsource.scanner.api/sonar-scanner-api-batch@2.10.0.1189?package-id=7098ec9f6897fb2a",
340434          "supplier": {},
340435          "group": "org.sonarsource.scanner.api",
340436          "name": "sonar-scanner-api-batch",
340437          "version": "2.10.0.1189",
340438          "cpe": "cpe:2.3:a:sonar-scanner-api-batch:sonar-scanner-api-batch:2.10.0.1189:*:*:*:*:*:*:*",
340439          "purl": "pkg:maven/org.sonarsource.scanner.api/sonar-scanner-api-batch@2.10.0.1189",
340440          "swid": {
340441            "attachment": {}
340442          },
340443          "pedigree": {},
340444          "externalReferences": [
340445            {
340446              "type": "build-meta",
340447              "hashes": [
340448                {
340449                  "alg": "SHA-1",
340450                  "content": "4b98aee77d09ba6d20a8896d4d0d30976c94c7d7"
340451                }
340452              ]
340453            }
340454          ],
340455          "evidence": {},
340456          "signature": {
340457            "signature": {
340458              "publicKey": {}
340459            }
340460          },
340461          "modelCard": {
340462            "modelParameters": {
340463              "approach": {}
340464            },
340465            "quantitativeAnalysis": {
340466              "graphics": {}
340467            },
340468            "considerations": {}
340469          }
340470        },
340471        {
340472          "type": "library",
340473          "bom-ref": "pkg:maven/org.sonarsource.scanner.api/sonar-scanner-api-batch-interface@2.10.0.1189?package-id=9e14b585ee06ab0a",
340474          "supplier": {},
340475          "group": "org.sonarsource.scanner.api",
340476          "name": "sonar-scanner-api-batch-interface",
340477          "version": "2.10.0.1189",
340478          "cpe": "cpe:2.3:a:sonar-scanner-api-batch-interface:sonar-scanner-api-batch-interface:2.10.0.1189:*:*:*:*:*:*:*",
340479          "purl": "pkg:maven/org.sonarsource.scanner.api/sonar-scanner-api-batch-interface@2.10.0.1189",
340480          "swid": {
340481            "attachment": {}
340482          },
340483          "pedigree": {},
340484          "evidence": {},
340485          "signature": {
340486            "signature": {
340487              "publicKey": {}
340488            }
340489          },
340490          "modelCard": {
340491            "modelParameters": {
340492              "approach": {}
340493            },
340494            "quantitativeAnalysis": {
340495              "graphics": {}
340496            },
340497            "considerations": {}
340498          }
340499        },
340500        {
340501          "type": "library",
340502          "bom-ref": "pkg:maven/org.sonarsource.scanner.cli/sonar-scanner-cli@3.1.0.1141?package-id=9277d9626f11e7e0",
340503          "supplier": {},
340504          "group": "org.sonarsource.scanner.cli",
340505          "name": "sonar-scanner-cli",
340506          "version": "3.1.0.1141",
340507          "cpe": "cpe:2.3:a:sonar-scanner-cli:sonar-scanner-cli:3.1.0.1141:*:*:*:*:*:*:*",
340508          "purl": "pkg:maven/org.sonarsource.scanner.cli/sonar-scanner-cli@3.1.0.1141",
340509          "swid": {
340510            "attachment": {}
340511          },
340512          "pedigree": {},
340513          "externalReferences": [
340514            {
340515              "type": "build-meta",
340516              "hashes": [
340517                {
340518                  "alg": "SHA-1",
340519                  "content": "0dfdbd41fa7e907bd3a570d44283839852e4a56e"
340520                }
340521              ]
340522            }
340523          ],
340524          "evidence": {},
340525          "signature": {
340526            "signature": {
340527              "publicKey": {}
340528            }
340529          },
340530          "modelCard": {
340531            "modelParameters": {
340532              "approach": {}
340533            },
340534            "quantitativeAnalysis": {
340535              "graphics": {}
340536            },
340537            "considerations": {}
340538          }
340539        },
340540        {
340541          "type": "library",
340542          "bom-ref": "pkg:npm/sort-keys@1.1.2?package-id=8d95b9ca88e891e",
340543          "supplier": {},
340544          "name": "sort-keys",
340545          "version": "1.1.2",
340546          "licenses": [
340547            {
340548              "license": {
340549                "id": "MIT"
340550              }
340551            }
340552          ],
340553          "cpe": "cpe:2.3:a:sort-keys:sort-keys:1.1.2:*:*:*:*:*:*:*",
340554          "purl": "pkg:npm/sort-keys@1.1.2",
340555          "swid": {
340556            "attachment": {}
340557          },
340558          "pedigree": {},
340559          "evidence": {},
340560          "signature": {
340561            "signature": {
340562              "publicKey": {}
340563            }
340564          },
340565          "modelCard": {
340566            "modelParameters": {
340567              "approach": {}
340568            },
340569            "quantitativeAnalysis": {
340570              "graphics": {}
340571            },
340572            "considerations": {}
340573          }
340574        },
340575        {
340576          "type": "library",
340577          "bom-ref": "pkg:npm/source-list-map@2.0.1?package-id=dae4f6d5c918177c",
340578          "supplier": {},
340579          "name": "source-list-map",
340580          "version": "2.0.1",
340581          "licenses": [
340582            {
340583              "license": {
340584                "id": "MIT"
340585              }
340586            }
340587          ],
340588          "cpe": "cpe:2.3:a:source-list-map:source-list-map:2.0.1:*:*:*:*:*:*:*",
340589          "purl": "pkg:npm/source-list-map@2.0.1",
340590          "swid": {
340591            "attachment": {}
340592          },
340593          "pedigree": {},
340594          "evidence": {},
340595          "signature": {
340596            "signature": {
340597              "publicKey": {}
340598            }
340599          },
340600          "modelCard": {
340601            "modelParameters": {
340602              "approach": {}
340603            },
340604            "quantitativeAnalysis": {
340605              "graphics": {}
340606            },
340607            "considerations": {}
340608          }
340609        },
340610        {
340611          "type": "library",
340612          "bom-ref": "pkg:npm/source-map@0.5.7?package-id=8a1e52c37677cd24",
340613          "supplier": {},
340614          "name": "source-map",
340615          "version": "0.5.7",
340616          "cpe": "cpe:2.3:a:source-map:source-map:0.5.7:*:*:*:*:*:*:*",
340617          "purl": "pkg:npm/source-map@0.5.7",
340618          "swid": {
340619            "attachment": {}
340620          },
340621          "pedigree": {},
340622          "evidence": {},
340623          "signature": {
340624            "signature": {
340625              "publicKey": {}
340626            }
340627          },
340628          "modelCard": {
340629            "modelParameters": {
340630              "approach": {}
340631            },
340632            "quantitativeAnalysis": {
340633              "graphics": {}
340634            },
340635            "considerations": {}
340636          }
340637        },
340638        {
340639          "type": "library",
340640          "bom-ref": "pkg:npm/source-map@0.6.1?package-id=f13d135e292145b9",
340641          "supplier": {},
340642          "name": "source-map",
340643          "version": "0.6.1",
340644          "licenses": [
340645            {
340646              "license": {
340647                "id": "BSD-3-Clause"
340648              }
340649            }
340650          ],
340651          "cpe": "cpe:2.3:a:source-map:source-map:0.6.1:*:*:*:*:*:*:*",
340652          "purl": "pkg:npm/source-map@0.6.1",
340653          "swid": {
340654            "attachment": {}
340655          },
340656          "pedigree": {},
340657          "evidence": {},
340658          "signature": {
340659            "signature": {
340660              "publicKey": {}
340661            }
340662          },
340663          "modelCard": {
340664            "modelParameters": {
340665              "approach": {}
340666            },
340667            "quantitativeAnalysis": {
340668              "graphics": {}
340669            },
340670            "considerations": {}
340671          }
340672        },
340673        {
340674          "type": "library",
340675          "bom-ref": "pkg:npm/source-map-loader@0.2.4?package-id=4a70a96d21be7dfb",
340676          "supplier": {},
340677          "name": "source-map-loader",
340678          "version": "0.2.4",
340679          "licenses": [
340680            {
340681              "license": {
340682                "id": "MIT"
340683              }
340684            }
340685          ],
340686          "cpe": "cpe:2.3:a:source-map-loader:source-map-loader:0.2.4:*:*:*:*:*:*:*",
340687          "purl": "pkg:npm/source-map-loader@0.2.4",
340688          "swid": {
340689            "attachment": {}
340690          },
340691          "pedigree": {},
340692          "evidence": {},
340693          "signature": {
340694            "signature": {
340695              "publicKey": {}
340696            }
340697          },
340698          "modelCard": {
340699            "modelParameters": {
340700              "approach": {}
340701            },
340702            "quantitativeAnalysis": {
340703              "graphics": {}
340704            },
340705            "considerations": {}
340706          }
340707        },
340708        {
340709          "type": "library",
340710          "bom-ref": "pkg:npm/source-map-resolve@0.5.3?package-id=8d1d0e5f1afcfcd1",
340711          "supplier": {},
340712          "name": "source-map-resolve",
340713          "version": "0.5.3",
340714          "licenses": [
340715            {
340716              "license": {
340717                "id": "MIT"
340718              }
340719            }
340720          ],
340721          "cpe": "cpe:2.3:a:source-map-resolve:source-map-resolve:0.5.3:*:*:*:*:*:*:*",
340722          "purl": "pkg:npm/source-map-resolve@0.5.3",
340723          "swid": {
340724            "attachment": {}
340725          },
340726          "pedigree": {},
340727          "evidence": {},
340728          "signature": {
340729            "signature": {
340730              "publicKey": {}
340731            }
340732          },
340733          "modelCard": {
340734            "modelParameters": {
340735              "approach": {}
340736            },
340737            "quantitativeAnalysis": {
340738              "graphics": {}
340739            },
340740            "considerations": {}
340741          }
340742        },
340743        {
340744          "type": "library",
340745          "bom-ref": "pkg:npm/source-map-support@0.5.16?package-id=bc90170976046bbc",
340746          "supplier": {},
340747          "name": "source-map-support",
340748          "version": "0.5.16",
340749          "licenses": [
340750            {
340751              "license": {
340752                "id": "MIT"
340753              }
340754            }
340755          ],
340756          "cpe": "cpe:2.3:a:source-map-support:source-map-support:0.5.16:*:*:*:*:*:*:*",
340757          "purl": "pkg:npm/source-map-support@0.5.16",
340758          "swid": {
340759            "attachment": {}
340760          },
340761          "pedigree": {},
340762          "evidence": {},
340763          "signature": {
340764            "signature": {
340765              "publicKey": {}
340766            }
340767          },
340768          "modelCard": {
340769            "modelParameters": {
340770              "approach": {}
340771            },
340772            "quantitativeAnalysis": {
340773              "graphics": {}
340774            },
340775            "considerations": {}
340776          }
340777        },
340778        {
340779          "type": "library",
340780          "bom-ref": "pkg:npm/source-map-url@0.4.0?package-id=20992552e2d651e6",
340781          "supplier": {},
340782          "name": "source-map-url",
340783          "version": "0.4.0",
340784          "licenses": [
340785            {
340786              "license": {
340787                "id": "MIT"
340788              }
340789            }
340790          ],
340791          "cpe": "cpe:2.3:a:source-map-url:source-map-url:0.4.0:*:*:*:*:*:*:*",
340792          "purl": "pkg:npm/source-map-url@0.4.0",
340793          "swid": {
340794            "attachment": {}
340795          },
340796          "pedigree": {},
340797          "evidence": {},
340798          "signature": {
340799            "signature": {
340800              "publicKey": {}
340801            }
340802          },
340803          "modelCard": {
340804            "modelParameters": {
340805              "approach": {}
340806            },
340807            "quantitativeAnalysis": {
340808              "graphics": {}
340809            },
340810            "considerations": {}
340811          }
340812        },
340813        {
340814          "type": "library",
340815          "bom-ref": "pkg:npm/sourcemap-codec@1.4.8?package-id=fac41e2acf7ecff3",
340816          "supplier": {},
340817          "name": "sourcemap-codec",
340818          "version": "1.4.8",
340819          "licenses": [
340820            {
340821              "license": {
340822                "id": "MIT"
340823              }
340824            }
340825          ],
340826          "cpe": "cpe:2.3:a:sourcemap-codec:sourcemap-codec:1.4.8:*:*:*:*:*:*:*",
340827          "purl": "pkg:npm/sourcemap-codec@1.4.8",
340828          "swid": {
340829            "attachment": {}
340830          },
340831          "pedigree": {},
340832          "evidence": {},
340833          "signature": {
340834            "signature": {
340835              "publicKey": {}
340836            }
340837          },
340838          "modelCard": {
340839            "modelParameters": {
340840              "approach": {}
340841            },
340842            "quantitativeAnalysis": {
340843              "graphics": {}
340844            },
340845            "considerations": {}
340846          }
340847        },
340848        {
340849          "type": "library",
340850          "bom-ref": "pkg:npm/spawn-wrap@2.0.0?package-id=3d4bf9279d50409c",
340851          "supplier": {},
340852          "name": "spawn-wrap",
340853          "version": "2.0.0",
340854          "cpe": "cpe:2.3:a:spawn-wrap:spawn-wrap:2.0.0:*:*:*:*:*:*:*",
340855          "purl": "pkg:npm/spawn-wrap@2.0.0",
340856          "swid": {
340857            "attachment": {}
340858          },
340859          "pedigree": {},
340860          "evidence": {},
340861          "signature": {
340862            "signature": {
340863              "publicKey": {}
340864            }
340865          },
340866          "modelCard": {
340867            "modelParameters": {
340868              "approach": {}
340869            },
340870            "quantitativeAnalysis": {
340871              "graphics": {}
340872            },
340873            "considerations": {}
340874          }
340875        },
340876        {
340877          "type": "library",
340878          "bom-ref": "pkg:npm/spdx-correct@3.1.0?package-id=af5bde02c5e3b75c",
340879          "supplier": {},
340880          "name": "spdx-correct",
340881          "version": "3.1.0",
340882          "licenses": [
340883            {
340884              "license": {
340885                "id": "Apache-2.0"
340886              }
340887            }
340888          ],
340889          "cpe": "cpe:2.3:a:spdx-correct:spdx-correct:3.1.0:*:*:*:*:*:*:*",
340890          "purl": "pkg:npm/spdx-correct@3.1.0",
340891          "swid": {
340892            "attachment": {}
340893          },
340894          "pedigree": {},
340895          "evidence": {},
340896          "signature": {
340897            "signature": {
340898              "publicKey": {}
340899            }
340900          },
340901          "modelCard": {
340902            "modelParameters": {
340903              "approach": {}
340904            },
340905            "quantitativeAnalysis": {
340906              "graphics": {}
340907            },
340908            "considerations": {}
340909          }
340910        },
340911        {
340912          "type": "library",
340913          "bom-ref": "pkg:npm/spdx-exceptions@2.2.0?package-id=4f1b92c95c794575",
340914          "supplier": {},
340915          "name": "spdx-exceptions",
340916          "version": "2.2.0",
340917          "licenses": [
340918            {
340919              "license": {
340920                "id": "CC-BY-3.0"
340921              }
340922            }
340923          ],
340924          "cpe": "cpe:2.3:a:spdx-exceptions:spdx-exceptions:2.2.0:*:*:*:*:*:*:*",
340925          "purl": "pkg:npm/spdx-exceptions@2.2.0",
340926          "swid": {
340927            "attachment": {}
340928          },
340929          "pedigree": {},
340930          "evidence": {},
340931          "signature": {
340932            "signature": {
340933              "publicKey": {}
340934            }
340935          },
340936          "modelCard": {
340937            "modelParameters": {
340938              "approach": {}
340939            },
340940            "quantitativeAnalysis": {
340941              "graphics": {}
340942            },
340943            "considerations": {}
340944          }
340945        },
340946        {
340947          "type": "library",
340948          "bom-ref": "pkg:npm/spdx-expression-parse@3.0.0?package-id=e1029c066ad8773b",
340949          "supplier": {},
340950          "name": "spdx-expression-parse",
340951          "version": "3.0.0",
340952          "licenses": [
340953            {
340954              "license": {
340955                "id": "MIT"
340956              }
340957            }
340958          ],
340959          "cpe": "cpe:2.3:a:spdx-expression-parse:spdx-expression-parse:3.0.0:*:*:*:*:*:*:*",
340960          "purl": "pkg:npm/spdx-expression-parse@3.0.0",
340961          "swid": {
340962            "attachment": {}
340963          },
340964          "pedigree": {},
340965          "evidence": {},
340966          "signature": {
340967            "signature": {
340968              "publicKey": {}
340969            }
340970          },
340971          "modelCard": {
340972            "modelParameters": {
340973              "approach": {}
340974            },
340975            "quantitativeAnalysis": {
340976              "graphics": {}
340977            },
340978            "considerations": {}
340979          }
340980        },
340981        {
340982          "type": "library",
340983          "bom-ref": "pkg:npm/spdx-license-ids@3.0.5?package-id=e887036491a70859",
340984          "supplier": {},
340985          "name": "spdx-license-ids",
340986          "version": "3.0.5",
340987          "licenses": [
340988            {
340989              "license": {
340990                "id": "CC0-1.0"
340991              }
340992            }
340993          ],
340994          "cpe": "cpe:2.3:a:spdx-license-ids:spdx-license-ids:3.0.5:*:*:*:*:*:*:*",
340995          "purl": "pkg:npm/spdx-license-ids@3.0.5",
340996          "swid": {
340997            "attachment": {}
340998          },
340999          "pedigree": {},
341000          "evidence": {},
341001          "signature": {
341002            "signature": {
341003              "publicKey": {}
341004            }
341005          },
341006          "modelCard": {
341007            "modelParameters": {
341008              "approach": {}
341009            },
341010            "quantitativeAnalysis": {
341011              "graphics": {}
341012            },
341013            "considerations": {}
341014          }
341015        },
341016        {
341017          "type": "library",
341018          "bom-ref": "pkg:npm/spdy@4.0.2?package-id=c6550c2183a35a4e",
341019          "supplier": {},
341020          "name": "spdy",
341021          "version": "4.0.2",
341022          "licenses": [
341023            {
341024              "license": {
341025                "id": "MIT"
341026              }
341027            }
341028          ],
341029          "cpe": "cpe:2.3:a:spdy:spdy:4.0.2:*:*:*:*:*:*:*",
341030          "purl": "pkg:npm/spdy@4.0.2",
341031          "swid": {
341032            "attachment": {}
341033          },
341034          "pedigree": {},
341035          "evidence": {},
341036          "signature": {
341037            "signature": {
341038              "publicKey": {}
341039            }
341040          },
341041          "modelCard": {
341042            "modelParameters": {
341043              "approach": {}
341044            },
341045            "quantitativeAnalysis": {
341046              "graphics": {}
341047            },
341048            "considerations": {}
341049          }
341050        },
341051        {
341052          "type": "library",
341053          "bom-ref": "pkg:npm/spdy-transport@3.0.0?package-id=9e2e3b8693650584",
341054          "supplier": {},
341055          "name": "spdy-transport",
341056          "version": "3.0.0",
341057          "licenses": [
341058            {
341059              "license": {
341060                "id": "MIT"
341061              }
341062            }
341063          ],
341064          "cpe": "cpe:2.3:a:spdy-transport:spdy-transport:3.0.0:*:*:*:*:*:*:*",
341065          "purl": "pkg:npm/spdy-transport@3.0.0",
341066          "swid": {
341067            "attachment": {}
341068          },
341069          "pedigree": {},
341070          "evidence": {},
341071          "signature": {
341072            "signature": {
341073              "publicKey": {}
341074            }
341075          },
341076          "modelCard": {
341077            "modelParameters": {
341078              "approach": {}
341079            },
341080            "quantitativeAnalysis": {
341081              "graphics": {}
341082            },
341083            "considerations": {}
341084          }
341085        },
341086        {
341087          "type": "library",
341088          "bom-ref": "pkg:npm/speed-measure-webpack-plugin@1.3.1?package-id=974cf7c3ce9f496e",
341089          "supplier": {},
341090          "name": "speed-measure-webpack-plugin",
341091          "version": "1.3.1",
341092          "licenses": [
341093            {
341094              "license": {
341095                "id": "MIT"
341096              }
341097            }
341098          ],
341099          "cpe": "cpe:2.3:a:speed-measure-webpack-plugin:speed-measure-webpack-plugin:1.3.1:*:*:*:*:*:*:*",
341100          "purl": "pkg:npm/speed-measure-webpack-plugin@1.3.1",
341101          "swid": {
341102            "attachment": {}
341103          },
341104          "pedigree": {},
341105          "evidence": {},
341106          "signature": {
341107            "signature": {
341108              "publicKey": {}
341109            }
341110          },
341111          "modelCard": {
341112            "modelParameters": {
341113              "approach": {}
341114            },
341115            "quantitativeAnalysis": {
341116              "graphics": {}
341117            },
341118            "considerations": {}
341119          }
341120        },
341121        {
341122          "type": "library",
341123          "bom-ref": "pkg:npm/split-string@3.1.0?package-id=d5a5faee1ecb8cee",
341124          "supplier": {},
341125          "name": "split-string",
341126          "version": "3.1.0",
341127          "licenses": [
341128            {
341129              "license": {
341130                "id": "MIT"
341131              }
341132            }
341133          ],
341134          "cpe": "cpe:2.3:a:split-string:split-string:3.1.0:*:*:*:*:*:*:*",
341135          "purl": "pkg:npm/split-string@3.1.0",
341136          "swid": {
341137            "attachment": {}
341138          },
341139          "pedigree": {},
341140          "evidence": {},
341141          "signature": {
341142            "signature": {
341143              "publicKey": {}
341144            }
341145          },
341146          "modelCard": {
341147            "modelParameters": {
341148              "approach": {}
341149            },
341150            "quantitativeAnalysis": {
341151              "graphics": {}
341152            },
341153            "considerations": {}
341154          }
341155        },
341156        {
341157          "type": "library",
341158          "bom-ref": "pkg:npm/sprintf-js@1.0.3?package-id=81d702a2ba232950",
341159          "supplier": {},
341160          "name": "sprintf-js",
341161          "version": "1.0.3",
341162          "cpe": "cpe:2.3:a:sprintf-js:sprintf-js:1.0.3:*:*:*:*:*:*:*",
341163          "purl": "pkg:npm/sprintf-js@1.0.3",
341164          "swid": {
341165            "attachment": {}
341166          },
341167          "pedigree": {},
341168          "evidence": {},
341169          "signature": {
341170            "signature": {
341171              "publicKey": {}
341172            }
341173          },
341174          "modelCard": {
341175            "modelParameters": {
341176              "approach": {}
341177            },
341178            "quantitativeAnalysis": {
341179              "graphics": {}
341180            },
341181            "considerations": {}
341182          }
341183        },
341184        {
341185          "type": "library",
341186          "bom-ref": "pkg:npm/sprintf-js@1.0.3?package-id=2cb96d8a67fafc54",
341187          "supplier": {},
341188          "name": "sprintf-js",
341189          "version": "1.0.3",
341190          "licenses": [
341191            {
341192              "license": {
341193                "id": "BSD-3-Clause"
341194              }
341195            }
341196          ],
341197          "cpe": "cpe:2.3:a:sprintf-js:sprintf-js:1.0.3:*:*:*:*:*:*:*",
341198          "purl": "pkg:npm/sprintf-js@1.0.3",
341199          "swid": {
341200            "attachment": {}
341201          },
341202          "pedigree": {},
341203          "evidence": {},
341204          "signature": {
341205            "signature": {
341206              "publicKey": {}
341207            }
341208          },
341209          "modelCard": {
341210            "modelParameters": {
341211              "approach": {}
341212            },
341213            "quantitativeAnalysis": {
341214              "graphics": {}
341215            },
341216            "considerations": {}
341217          }
341218        },
341219        {
341220          "type": "library",
341221          "bom-ref": "pkg:npm/sshpk@1.16.1?package-id=86482c783da2ad02",
341222          "supplier": {},
341223          "name": "sshpk",
341224          "version": "1.16.1",
341225          "licenses": [
341226            {
341227              "license": {
341228                "id": "MIT"
341229              }
341230            }
341231          ],
341232          "cpe": "cpe:2.3:a:sshpk:sshpk:1.16.1:*:*:*:*:*:*:*",
341233          "purl": "pkg:npm/sshpk@1.16.1",
341234          "swid": {
341235            "attachment": {}
341236          },
341237          "pedigree": {},
341238          "evidence": {},
341239          "signature": {
341240            "signature": {
341241              "publicKey": {}
341242            }
341243          },
341244          "modelCard": {
341245            "modelParameters": {
341246              "approach": {}
341247            },
341248            "quantitativeAnalysis": {
341249              "graphics": {}
341250            },
341251            "considerations": {}
341252          }
341253        },
341254        {
341255          "type": "library",
341256          "bom-ref": "pkg:npm/ssri@8.0.0?package-id=674a60afc735c41b",
341257          "supplier": {},
341258          "name": "ssri",
341259          "version": "8.0.0",
341260          "licenses": [
341261            {
341262              "license": {
341263                "id": "ISC"
341264              }
341265            }
341266          ],
341267          "cpe": "cpe:2.3:a:ssri:ssri:8.0.0:*:*:*:*:*:*:*",
341268          "purl": "pkg:npm/ssri@8.0.0",
341269          "swid": {
341270            "attachment": {}
341271          },
341272          "pedigree": {},
341273          "evidence": {},
341274          "signature": {
341275            "signature": {
341276              "publicKey": {}
341277            }
341278          },
341279          "modelCard": {
341280            "modelParameters": {
341281              "approach": {}
341282            },
341283            "quantitativeAnalysis": {
341284              "graphics": {}
341285            },
341286            "considerations": {}
341287          }
341288        },
341289        {
341290          "type": "library",
341291          "bom-ref": "pkg:npm/stable@0.1.8?package-id=ea6e9bfa58bd21a5",
341292          "supplier": {},
341293          "name": "stable",
341294          "version": "0.1.8",
341295          "licenses": [
341296            {
341297              "license": {
341298                "id": "MIT"
341299              }
341300            }
341301          ],
341302          "cpe": "cpe:2.3:a:stable:stable:0.1.8:*:*:*:*:*:*:*",
341303          "purl": "pkg:npm/stable@0.1.8",
341304          "swid": {
341305            "attachment": {}
341306          },
341307          "pedigree": {},
341308          "evidence": {},
341309          "signature": {
341310            "signature": {
341311              "publicKey": {}
341312            }
341313          },
341314          "modelCard": {
341315            "modelParameters": {
341316              "approach": {}
341317            },
341318            "quantitativeAnalysis": {
341319              "graphics": {}
341320            },
341321            "considerations": {}
341322          }
341323        },
341324        {
341325          "type": "library",
341326          "bom-ref": "pkg:npm/static-extend@0.1.2?package-id=9c49771e1198aa88",
341327          "supplier": {},
341328          "name": "static-extend",
341329          "version": "0.1.2",
341330          "licenses": [
341331            {
341332              "license": {
341333                "id": "MIT"
341334              }
341335            }
341336          ],
341337          "cpe": "cpe:2.3:a:static-extend:static-extend:0.1.2:*:*:*:*:*:*:*",
341338          "purl": "pkg:npm/static-extend@0.1.2",
341339          "swid": {
341340            "attachment": {}
341341          },
341342          "pedigree": {},
341343          "evidence": {},
341344          "signature": {
341345            "signature": {
341346              "publicKey": {}
341347            }
341348          },
341349          "modelCard": {
341350            "modelParameters": {
341351              "approach": {}
341352            },
341353            "quantitativeAnalysis": {
341354              "graphics": {}
341355            },
341356            "considerations": {}
341357          }
341358        },
341359        {
341360          "type": "library",
341361          "bom-ref": "pkg:npm/statuses@1.5.0?package-id=1c69a1b07671503c",
341362          "supplier": {},
341363          "name": "statuses",
341364          "version": "1.5.0",
341365          "licenses": [
341366            {
341367              "license": {
341368                "id": "MIT"
341369              }
341370            }
341371          ],
341372          "cpe": "cpe:2.3:a:statuses:statuses:1.5.0:*:*:*:*:*:*:*",
341373          "purl": "pkg:npm/statuses@1.5.0",
341374          "swid": {
341375            "attachment": {}
341376          },
341377          "pedigree": {},
341378          "evidence": {},
341379          "signature": {
341380            "signature": {
341381              "publicKey": {}
341382            }
341383          },
341384          "modelCard": {
341385            "modelParameters": {
341386              "approach": {}
341387            },
341388            "quantitativeAnalysis": {
341389              "graphics": {}
341390            },
341391            "considerations": {}
341392          }
341393        },
341394        {
341395          "type": "library",
341396          "bom-ref": "pkg:npm/stdin@0.0.1?package-id=7685cf6694747caf",
341397          "supplier": {},
341398          "name": "stdin",
341399          "version": "0.0.1",
341400          "cpe": "cpe:2.3:a:stdin:stdin:0.0.1:*:*:*:*:*:*:*",
341401          "purl": "pkg:npm/stdin@0.0.1",
341402          "swid": {
341403            "attachment": {}
341404          },
341405          "pedigree": {},
341406          "evidence": {},
341407          "signature": {
341408            "signature": {
341409              "publicKey": {}
341410            }
341411          },
341412          "modelCard": {
341413            "modelParameters": {
341414              "approach": {}
341415            },
341416            "quantitativeAnalysis": {
341417              "graphics": {}
341418            },
341419            "considerations": {}
341420          }
341421        },
341422        {
341423          "type": "library",
341424          "bom-ref": "pkg:npm/stdout-stream@1.4.1?package-id=d823acca9fecf669",
341425          "supplier": {},
341426          "name": "stdout-stream",
341427          "version": "1.4.1",
341428          "licenses": [
341429            {
341430              "license": {
341431                "id": "MIT"
341432              }
341433            }
341434          ],
341435          "cpe": "cpe:2.3:a:stdout-stream:stdout-stream:1.4.1:*:*:*:*:*:*:*",
341436          "purl": "pkg:npm/stdout-stream@1.4.1",
341437          "swid": {
341438            "attachment": {}
341439          },
341440          "pedigree": {},
341441          "evidence": {},
341442          "signature": {
341443            "signature": {
341444              "publicKey": {}
341445            }
341446          },
341447          "modelCard": {
341448            "modelParameters": {
341449              "approach": {}
341450            },
341451            "quantitativeAnalysis": {
341452              "graphics": {}
341453            },
341454            "considerations": {}
341455          }
341456        },
341457        {
341458          "type": "library",
341459          "bom-ref": "pkg:npm/stealthy-require@1.1.1?package-id=af959e080f157f47",
341460          "supplier": {},
341461          "name": "stealthy-require",
341462          "version": "1.1.1",
341463          "licenses": [
341464            {
341465              "license": {
341466                "id": "ISC"
341467              }
341468            }
341469          ],
341470          "cpe": "cpe:2.3:a:stealthy-require:stealthy-require:1.1.1:*:*:*:*:*:*:*",
341471          "purl": "pkg:npm/stealthy-require@1.1.1",
341472          "swid": {
341473            "attachment": {}
341474          },
341475          "pedigree": {},
341476          "evidence": {},
341477          "signature": {
341478            "signature": {
341479              "publicKey": {}
341480            }
341481          },
341482          "modelCard": {
341483            "modelParameters": {
341484              "approach": {}
341485            },
341486            "quantitativeAnalysis": {
341487              "graphics": {}
341488            },
341489            "considerations": {}
341490          }
341491        },
341492        {
341493          "type": "library",
341494          "bom-ref": "pkg:npm/stream-browserify@2.0.2?package-id=f71f4de3bce4e88d",
341495          "supplier": {},
341496          "name": "stream-browserify",
341497          "version": "2.0.2",
341498          "licenses": [
341499            {
341500              "license": {
341501                "id": "MIT"
341502              }
341503            }
341504          ],
341505          "cpe": "cpe:2.3:a:stream-browserify:stream-browserify:2.0.2:*:*:*:*:*:*:*",
341506          "purl": "pkg:npm/stream-browserify@2.0.2",
341507          "swid": {
341508            "attachment": {}
341509          },
341510          "pedigree": {},
341511          "evidence": {},
341512          "signature": {
341513            "signature": {
341514              "publicKey": {}
341515            }
341516          },
341517          "modelCard": {
341518            "modelParameters": {
341519              "approach": {}
341520            },
341521            "quantitativeAnalysis": {
341522              "graphics": {}
341523            },
341524            "considerations": {}
341525          }
341526        },
341527        {
341528          "type": "library",
341529          "bom-ref": "pkg:npm/stream-each@1.2.3?package-id=c4fa6d471369bdd1",
341530          "supplier": {},
341531          "name": "stream-each",
341532          "version": "1.2.3",
341533          "licenses": [
341534            {
341535              "license": {
341536                "id": "MIT"
341537              }
341538            }
341539          ],
341540          "cpe": "cpe:2.3:a:stream-each:stream-each:1.2.3:*:*:*:*:*:*:*",
341541          "purl": "pkg:npm/stream-each@1.2.3",
341542          "swid": {
341543            "attachment": {}
341544          },
341545          "pedigree": {},
341546          "evidence": {},
341547          "signature": {
341548            "signature": {
341549              "publicKey": {}
341550            }
341551          },
341552          "modelCard": {
341553            "modelParameters": {
341554              "approach": {}
341555            },
341556            "quantitativeAnalysis": {
341557              "graphics": {}
341558            },
341559            "considerations": {}
341560          }
341561        },
341562        {
341563          "type": "library",
341564          "bom-ref": "pkg:npm/stream-http@2.8.3?package-id=b425e201c0a15172",
341565          "supplier": {},
341566          "name": "stream-http",
341567          "version": "2.8.3",
341568          "licenses": [
341569            {
341570              "license": {
341571                "id": "MIT"
341572              }
341573            }
341574          ],
341575          "cpe": "cpe:2.3:a:stream-http:stream-http:2.8.3:*:*:*:*:*:*:*",
341576          "purl": "pkg:npm/stream-http@2.8.3",
341577          "swid": {
341578            "attachment": {}
341579          },
341580          "pedigree": {},
341581          "evidence": {},
341582          "signature": {
341583            "signature": {
341584              "publicKey": {}
341585            }
341586          },
341587          "modelCard": {
341588            "modelParameters": {
341589              "approach": {}
341590            },
341591            "quantitativeAnalysis": {
341592              "graphics": {}
341593            },
341594            "considerations": {}
341595          }
341596        },
341597        {
341598          "type": "library",
341599          "bom-ref": "pkg:npm/stream-shift@1.0.1?package-id=3eb8c981419452ac",
341600          "supplier": {},
341601          "name": "stream-shift",
341602          "version": "1.0.1",
341603          "licenses": [
341604            {
341605              "license": {
341606                "id": "MIT"
341607              }
341608            }
341609          ],
341610          "cpe": "cpe:2.3:a:stream-shift:stream-shift:1.0.1:*:*:*:*:*:*:*",
341611          "purl": "pkg:npm/stream-shift@1.0.1",
341612          "swid": {
341613            "attachment": {}
341614          },
341615          "pedigree": {},
341616          "evidence": {},
341617          "signature": {
341618            "signature": {
341619              "publicKey": {}
341620            }
341621          },
341622          "modelCard": {
341623            "modelParameters": {
341624              "approach": {}
341625            },
341626            "quantitativeAnalysis": {
341627              "graphics": {}
341628            },
341629            "considerations": {}
341630          }
341631        },
341632        {
341633          "type": "library",
341634          "bom-ref": "pkg:npm/streamroller@1.0.6?package-id=d3662b3d0a3ab4d3",
341635          "supplier": {},
341636          "name": "streamroller",
341637          "version": "1.0.6",
341638          "licenses": [
341639            {
341640              "license": {
341641                "id": "MIT"
341642              }
341643            }
341644          ],
341645          "cpe": "cpe:2.3:a:streamroller:streamroller:1.0.6:*:*:*:*:*:*:*",
341646          "purl": "pkg:npm/streamroller@1.0.6",
341647          "swid": {
341648            "attachment": {}
341649          },
341650          "pedigree": {},
341651          "evidence": {},
341652          "signature": {
341653            "signature": {
341654              "publicKey": {}
341655            }
341656          },
341657          "modelCard": {
341658            "modelParameters": {
341659              "approach": {}
341660            },
341661            "quantitativeAnalysis": {
341662              "graphics": {}
341663            },
341664            "considerations": {}
341665          }
341666        },
341667        {
341668          "type": "library",
341669          "bom-ref": "pkg:npm/strict-uri-encode@1.1.0?package-id=f1e948970f198aaf",
341670          "supplier": {},
341671          "name": "strict-uri-encode",
341672          "version": "1.1.0",
341673          "licenses": [
341674            {
341675              "license": {
341676                "id": "MIT"
341677              }
341678            }
341679          ],
341680          "cpe": "cpe:2.3:a:strict-uri-encode:strict-uri-encode:1.1.0:*:*:*:*:*:*:*",
341681          "purl": "pkg:npm/strict-uri-encode@1.1.0",
341682          "swid": {
341683            "attachment": {}
341684          },
341685          "pedigree": {},
341686          "evidence": {},
341687          "signature": {
341688            "signature": {
341689              "publicKey": {}
341690            }
341691          },
341692          "modelCard": {
341693            "modelParameters": {
341694              "approach": {}
341695            },
341696            "quantitativeAnalysis": {
341697              "graphics": {}
341698            },
341699            "considerations": {}
341700          }
341701        },
341702        {
341703          "type": "library",
341704          "bom-ref": "pkg:npm/string-replace-loader@3.1.0?package-id=e2db261ea5876eb",
341705          "supplier": {},
341706          "name": "string-replace-loader",
341707          "version": "3.1.0",
341708          "licenses": [
341709            {
341710              "license": {
341711                "id": "MIT"
341712              }
341713            }
341714          ],
341715          "cpe": "cpe:2.3:a:string-replace-loader:string-replace-loader:3.1.0:*:*:*:*:*:*:*",
341716          "purl": "pkg:npm/string-replace-loader@3.1.0",
341717          "swid": {
341718            "attachment": {}
341719          },
341720          "pedigree": {},
341721          "evidence": {},
341722          "signature": {
341723            "signature": {
341724              "publicKey": {}
341725            }
341726          },
341727          "modelCard": {
341728            "modelParameters": {
341729              "approach": {}
341730            },
341731            "quantitativeAnalysis": {
341732              "graphics": {}
341733            },
341734            "considerations": {}
341735          }
341736        },
341737        {
341738          "type": "library",
341739          "bom-ref": "pkg:npm/string-width@2.1.1?package-id=5d048e5899c828d1",
341740          "supplier": {},
341741          "name": "string-width",
341742          "version": "2.1.1",
341743          "licenses": [
341744            {
341745              "license": {
341746                "id": "MIT"
341747              }
341748            }
341749          ],
341750          "cpe": "cpe:2.3:a:string-width:string-width:2.1.1:*:*:*:*:*:*:*",
341751          "purl": "pkg:npm/string-width@2.1.1",
341752          "swid": {
341753            "attachment": {}
341754          },
341755          "pedigree": {},
341756          "evidence": {},
341757          "signature": {
341758            "signature": {
341759              "publicKey": {}
341760            }
341761          },
341762          "modelCard": {
341763            "modelParameters": {
341764              "approach": {}
341765            },
341766            "quantitativeAnalysis": {
341767              "graphics": {}
341768            },
341769            "considerations": {}
341770          }
341771        },
341772        {
341773          "type": "library",
341774          "bom-ref": "pkg:npm/string-width@4.2.3?package-id=42ca78d9e8f4f721",
341775          "supplier": {},
341776          "name": "string-width",
341777          "version": "4.2.3",
341778          "cpe": "cpe:2.3:a:string-width:string-width:4.2.3:*:*:*:*:*:*:*",
341779          "purl": "pkg:npm/string-width@4.2.3",
341780          "swid": {
341781            "attachment": {}
341782          },
341783          "pedigree": {},
341784          "evidence": {},
341785          "signature": {
341786            "signature": {
341787              "publicKey": {}
341788            }
341789          },
341790          "modelCard": {
341791            "modelParameters": {
341792              "approach": {}
341793            },
341794            "quantitativeAnalysis": {
341795              "graphics": {}
341796            },
341797            "considerations": {}
341798          }
341799        },
341800        {
341801          "type": "library",
341802          "bom-ref": "pkg:npm/string.prototype.startswith@0.2.0?package-id=eb521011ea37f889",
341803          "supplier": {},
341804          "name": "string.prototype.startswith",
341805          "version": "0.2.0",
341806          "licenses": [
341807            {
341808              "license": {
341809                "id": "MIT"
341810              }
341811            }
341812          ],
341813          "cpe": "cpe:2.3:a:string.prototype.startswith:string.prototype.startswith:0.2.0:*:*:*:*:*:*:*",
341814          "purl": "pkg:npm/string.prototype.startswith@0.2.0",
341815          "swid": {
341816            "attachment": {}
341817          },
341818          "pedigree": {},
341819          "evidence": {},
341820          "signature": {
341821            "signature": {
341822              "publicKey": {}
341823            }
341824          },
341825          "modelCard": {
341826            "modelParameters": {
341827              "approach": {}
341828            },
341829            "quantitativeAnalysis": {
341830              "graphics": {}
341831            },
341832            "considerations": {}
341833          }
341834        },
341835        {
341836          "type": "library",
341837          "bom-ref": "pkg:npm/string.prototype.trimend@1.0.1?package-id=eaaf2691d7faf493",
341838          "supplier": {},
341839          "name": "string.prototype.trimend",
341840          "version": "1.0.1",
341841          "licenses": [
341842            {
341843              "license": {
341844                "id": "MIT"
341845              }
341846            }
341847          ],
341848          "cpe": "cpe:2.3:a:string.prototype.trimend:string.prototype.trimend:1.0.1:*:*:*:*:*:*:*",
341849          "purl": "pkg:npm/string.prototype.trimend@1.0.1",
341850          "swid": {
341851            "attachment": {}
341852          },
341853          "pedigree": {},
341854          "evidence": {},
341855          "signature": {
341856            "signature": {
341857              "publicKey": {}
341858            }
341859          },
341860          "modelCard": {
341861            "modelParameters": {
341862              "approach": {}
341863            },
341864            "quantitativeAnalysis": {
341865              "graphics": {}
341866            },
341867            "considerations": {}
341868          }
341869        },
341870        {
341871          "type": "library",
341872          "bom-ref": "pkg:npm/string.prototype.trimleft@2.1.2?package-id=6cac466bdbcdd601",
341873          "supplier": {},
341874          "name": "string.prototype.trimleft",
341875          "version": "2.1.2",
341876          "licenses": [
341877            {
341878              "license": {
341879                "id": "MIT"
341880              }
341881            }
341882          ],
341883          "cpe": "cpe:2.3:a:string.prototype.trimleft:string.prototype.trimleft:2.1.2:*:*:*:*:*:*:*",
341884          "purl": "pkg:npm/string.prototype.trimleft@2.1.2",
341885          "swid": {
341886            "attachment": {}
341887          },
341888          "pedigree": {},
341889          "evidence": {},
341890          "signature": {
341891            "signature": {
341892              "publicKey": {}
341893            }
341894          },
341895          "modelCard": {
341896            "modelParameters": {
341897              "approach": {}
341898            },
341899            "quantitativeAnalysis": {
341900              "graphics": {}
341901            },
341902            "considerations": {}
341903          }
341904        },
341905        {
341906          "type": "library",
341907          "bom-ref": "pkg:npm/string.prototype.trimright@2.1.2?package-id=dd68fec03fc29df",
341908          "supplier": {},
341909          "name": "string.prototype.trimright",
341910          "version": "2.1.2",
341911          "licenses": [
341912            {
341913              "license": {
341914                "id": "MIT"
341915              }
341916            }
341917          ],
341918          "cpe": "cpe:2.3:a:string.prototype.trimright:string.prototype.trimright:2.1.2:*:*:*:*:*:*:*",
341919          "purl": "pkg:npm/string.prototype.trimright@2.1.2",
341920          "swid": {
341921            "attachment": {}
341922          },
341923          "pedigree": {},
341924          "evidence": {},
341925          "signature": {
341926            "signature": {
341927              "publicKey": {}
341928            }
341929          },
341930          "modelCard": {
341931            "modelParameters": {
341932              "approach": {}
341933            },
341934            "quantitativeAnalysis": {
341935              "graphics": {}
341936            },
341937            "considerations": {}
341938          }
341939        },
341940        {
341941          "type": "library",
341942          "bom-ref": "pkg:npm/string.prototype.trimstart@1.0.1?package-id=25879e71ff62096e",
341943          "supplier": {},
341944          "name": "string.prototype.trimstart",
341945          "version": "1.0.1",
341946          "licenses": [
341947            {
341948              "license": {
341949                "id": "MIT"
341950              }
341951            }
341952          ],
341953          "cpe": "cpe:2.3:a:string.prototype.trimstart:string.prototype.trimstart:1.0.1:*:*:*:*:*:*:*",
341954          "purl": "pkg:npm/string.prototype.trimstart@1.0.1",
341955          "swid": {
341956            "attachment": {}
341957          },
341958          "pedigree": {},
341959          "evidence": {},
341960          "signature": {
341961            "signature": {
341962              "publicKey": {}
341963            }
341964          },
341965          "modelCard": {
341966            "modelParameters": {
341967              "approach": {}
341968            },
341969            "quantitativeAnalysis": {
341970              "graphics": {}
341971            },
341972            "considerations": {}
341973          }
341974        },
341975        {
341976          "type": "library",
341977          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=9e0c8a452fbb441c",
341978          "supplier": {},
341979          "name": "string_decoder",
341980          "version": "1.1.1",
341981          "licenses": [
341982            {
341983              "license": {
341984                "id": "MIT"
341985              }
341986            }
341987          ],
341988          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
341989          "purl": "pkg:npm/string_decoder@1.1.1",
341990          "swid": {
341991            "attachment": {}
341992          },
341993          "pedigree": {},
341994          "evidence": {},
341995          "signature": {
341996            "signature": {
341997              "publicKey": {}
341998            }
341999          },
342000          "modelCard": {
342001            "modelParameters": {
342002              "approach": {}
342003            },
342004            "quantitativeAnalysis": {
342005              "graphics": {}
342006            },
342007            "considerations": {}
342008          }
342009        },
342010        {
342011          "type": "library",
342012          "bom-ref": "pkg:npm/strip-ansi@3.0.1?package-id=87989198efbc839f",
342013          "supplier": {},
342014          "name": "strip-ansi",
342015          "version": "3.0.1",
342016          "licenses": [
342017            {
342018              "license": {
342019                "id": "MIT"
342020              }
342021            }
342022          ],
342023          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:3.0.1:*:*:*:*:*:*:*",
342024          "purl": "pkg:npm/strip-ansi@3.0.1",
342025          "swid": {
342026            "attachment": {}
342027          },
342028          "pedigree": {},
342029          "evidence": {},
342030          "signature": {
342031            "signature": {
342032              "publicKey": {}
342033            }
342034          },
342035          "modelCard": {
342036            "modelParameters": {
342037              "approach": {}
342038            },
342039            "quantitativeAnalysis": {
342040              "graphics": {}
342041            },
342042            "considerations": {}
342043          }
342044        },
342045        {
342046          "type": "library",
342047          "bom-ref": "pkg:npm/strip-ansi@6.0.1?package-id=2db1d34d0f45aa9d",
342048          "supplier": {},
342049          "name": "strip-ansi",
342050          "version": "6.0.1",
342051          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:6.0.1:*:*:*:*:*:*:*",
342052          "purl": "pkg:npm/strip-ansi@6.0.1",
342053          "swid": {
342054            "attachment": {}
342055          },
342056          "pedigree": {},
342057          "evidence": {},
342058          "signature": {
342059            "signature": {
342060              "publicKey": {}
342061            }
342062          },
342063          "modelCard": {
342064            "modelParameters": {
342065              "approach": {}
342066            },
342067            "quantitativeAnalysis": {
342068              "graphics": {}
342069            },
342070            "considerations": {}
342071          }
342072        },
342073        {
342074          "type": "library",
342075          "bom-ref": "pkg:npm/strip-bom@3.0.0?package-id=60246f878ad090f0",
342076          "supplier": {},
342077          "name": "strip-bom",
342078          "version": "3.0.0",
342079          "licenses": [
342080            {
342081              "license": {
342082                "id": "MIT"
342083              }
342084            }
342085          ],
342086          "cpe": "cpe:2.3:a:strip-bom:strip-bom:3.0.0:*:*:*:*:*:*:*",
342087          "purl": "pkg:npm/strip-bom@3.0.0",
342088          "swid": {
342089            "attachment": {}
342090          },
342091          "pedigree": {},
342092          "evidence": {},
342093          "signature": {
342094            "signature": {
342095              "publicKey": {}
342096            }
342097          },
342098          "modelCard": {
342099            "modelParameters": {
342100              "approach": {}
342101            },
342102            "quantitativeAnalysis": {
342103              "graphics": {}
342104            },
342105            "considerations": {}
342106          }
342107        },
342108        {
342109          "type": "library",
342110          "bom-ref": "pkg:npm/strip-bom@4.0.0?package-id=d83238cfecbf5262",
342111          "supplier": {},
342112          "name": "strip-bom",
342113          "version": "4.0.0",
342114          "cpe": "cpe:2.3:a:strip-bom:strip-bom:4.0.0:*:*:*:*:*:*:*",
342115          "purl": "pkg:npm/strip-bom@4.0.0",
342116          "swid": {
342117            "attachment": {}
342118          },
342119          "pedigree": {},
342120          "evidence": {},
342121          "signature": {
342122            "signature": {
342123              "publicKey": {}
342124            }
342125          },
342126          "modelCard": {
342127            "modelParameters": {
342128              "approach": {}
342129            },
342130            "quantitativeAnalysis": {
342131              "graphics": {}
342132            },
342133            "considerations": {}
342134          }
342135        },
342136        {
342137          "type": "library",
342138          "bom-ref": "pkg:npm/strip-eof@1.0.0?package-id=8fab5bcf59d0307f",
342139          "supplier": {},
342140          "name": "strip-eof",
342141          "version": "1.0.0",
342142          "licenses": [
342143            {
342144              "license": {
342145                "id": "MIT"
342146              }
342147            }
342148          ],
342149          "cpe": "cpe:2.3:a:strip-eof:strip-eof:1.0.0:*:*:*:*:*:*:*",
342150          "purl": "pkg:npm/strip-eof@1.0.0",
342151          "swid": {
342152            "attachment": {}
342153          },
342154          "pedigree": {},
342155          "evidence": {},
342156          "signature": {
342157            "signature": {
342158              "publicKey": {}
342159            }
342160          },
342161          "modelCard": {
342162            "modelParameters": {
342163              "approach": {}
342164            },
342165            "quantitativeAnalysis": {
342166              "graphics": {}
342167            },
342168            "considerations": {}
342169          }
342170        },
342171        {
342172          "type": "library",
342173          "bom-ref": "pkg:npm/strip-indent@1.0.1?package-id=f7b51efdc131be2a",
342174          "supplier": {},
342175          "name": "strip-indent",
342176          "version": "1.0.1",
342177          "licenses": [
342178            {
342179              "license": {
342180                "id": "MIT"
342181              }
342182            }
342183          ],
342184          "cpe": "cpe:2.3:a:strip-indent:strip-indent:1.0.1:*:*:*:*:*:*:*",
342185          "purl": "pkg:npm/strip-indent@1.0.1",
342186          "swid": {
342187            "attachment": {}
342188          },
342189          "pedigree": {},
342190          "evidence": {},
342191          "signature": {
342192            "signature": {
342193              "publicKey": {}
342194            }
342195          },
342196          "modelCard": {
342197            "modelParameters": {
342198              "approach": {}
342199            },
342200            "quantitativeAnalysis": {
342201              "graphics": {}
342202            },
342203            "considerations": {}
342204          }
342205        },
342206        {
342207          "type": "library",
342208          "bom-ref": "pkg:npm/style-loader@1.1.3?package-id=af29aa58a55ff953",
342209          "supplier": {},
342210          "name": "style-loader",
342211          "version": "1.1.3",
342212          "licenses": [
342213            {
342214              "license": {
342215                "id": "MIT"
342216              }
342217            }
342218          ],
342219          "cpe": "cpe:2.3:a:style-loader:style-loader:1.1.3:*:*:*:*:*:*:*",
342220          "purl": "pkg:npm/style-loader@1.1.3",
342221          "swid": {
342222            "attachment": {}
342223          },
342224          "pedigree": {},
342225          "evidence": {},
342226          "signature": {
342227            "signature": {
342228              "publicKey": {}
342229            }
342230          },
342231          "modelCard": {
342232            "modelParameters": {
342233              "approach": {}
342234            },
342235            "quantitativeAnalysis": {
342236              "graphics": {}
342237            },
342238            "considerations": {}
342239          }
342240        },
342241        {
342242          "type": "library",
342243          "bom-ref": "pkg:npm/stylehacks@4.0.3?package-id=8c3b1e7e6a683f01",
342244          "supplier": {},
342245          "name": "stylehacks",
342246          "version": "4.0.3",
342247          "licenses": [
342248            {
342249              "license": {
342250                "id": "MIT"
342251              }
342252            }
342253          ],
342254          "cpe": "cpe:2.3:a:stylehacks:stylehacks:4.0.3:*:*:*:*:*:*:*",
342255          "purl": "pkg:npm/stylehacks@4.0.3",
342256          "swid": {
342257            "attachment": {}
342258          },
342259          "pedigree": {},
342260          "evidence": {},
342261          "signature": {
342262            "signature": {
342263              "publicKey": {}
342264            }
342265          },
342266          "modelCard": {
342267            "modelParameters": {
342268              "approach": {}
342269            },
342270            "quantitativeAnalysis": {
342271              "graphics": {}
342272            },
342273            "considerations": {}
342274          }
342275        },
342276        {
342277          "type": "library",
342278          "bom-ref": "pkg:npm/stylus@0.54.7?package-id=1be17e684715a25",
342279          "supplier": {},
342280          "name": "stylus",
342281          "version": "0.54.7",
342282          "licenses": [
342283            {
342284              "license": {
342285                "id": "MIT"
342286              }
342287            }
342288          ],
342289          "cpe": "cpe:2.3:a:stylus:stylus:0.54.7:*:*:*:*:*:*:*",
342290          "purl": "pkg:npm/stylus@0.54.7",
342291          "swid": {
342292            "attachment": {}
342293          },
342294          "pedigree": {},
342295          "evidence": {},
342296          "signature": {
342297            "signature": {
342298              "publicKey": {}
342299            }
342300          },
342301          "modelCard": {
342302            "modelParameters": {
342303              "approach": {}
342304            },
342305            "quantitativeAnalysis": {
342306              "graphics": {}
342307            },
342308            "considerations": {}
342309          }
342310        },
342311        {
342312          "type": "library",
342313          "bom-ref": "pkg:npm/stylus-loader@3.0.2?package-id=a57da5531e01038d",
342314          "supplier": {},
342315          "name": "stylus-loader",
342316          "version": "3.0.2",
342317          "licenses": [
342318            {
342319              "license": {
342320                "id": "MIT"
342321              }
342322            }
342323          ],
342324          "cpe": "cpe:2.3:a:stylus-loader:stylus-loader:3.0.2:*:*:*:*:*:*:*",
342325          "purl": "pkg:npm/stylus-loader@3.0.2",
342326          "swid": {
342327            "attachment": {}
342328          },
342329          "pedigree": {},
342330          "evidence": {},
342331          "signature": {
342332            "signature": {
342333              "publicKey": {}
342334            }
342335          },
342336          "modelCard": {
342337            "modelParameters": {
342338              "approach": {}
342339            },
342340            "quantitativeAnalysis": {
342341              "graphics": {}
342342            },
342343            "considerations": {}
342344          }
342345        },
342346        {
342347          "type": "library",
342348          "bom-ref": "pkg:npm/supports-color@5.5.0?package-id=39e040d2ad2327f0",
342349          "supplier": {},
342350          "name": "supports-color",
342351          "version": "5.5.0",
342352          "cpe": "cpe:2.3:a:supports-color:supports-color:5.5.0:*:*:*:*:*:*:*",
342353          "purl": "pkg:npm/supports-color@5.5.0",
342354          "swid": {
342355            "attachment": {}
342356          },
342357          "pedigree": {},
342358          "evidence": {},
342359          "signature": {
342360            "signature": {
342361              "publicKey": {}
342362            }
342363          },
342364          "modelCard": {
342365            "modelParameters": {
342366              "approach": {}
342367            },
342368            "quantitativeAnalysis": {
342369              "graphics": {}
342370            },
342371            "considerations": {}
342372          }
342373        },
342374        {
342375          "type": "library",
342376          "bom-ref": "pkg:npm/supports-color@5.5.0?package-id=6223b7363a1a1a8b",
342377          "supplier": {},
342378          "name": "supports-color",
342379          "version": "5.5.0",
342380          "licenses": [
342381            {
342382              "license": {
342383                "id": "MIT"
342384              }
342385            }
342386          ],
342387          "cpe": "cpe:2.3:a:supports-color:supports-color:5.5.0:*:*:*:*:*:*:*",
342388          "purl": "pkg:npm/supports-color@5.5.0",
342389          "swid": {
342390            "attachment": {}
342391          },
342392          "pedigree": {},
342393          "evidence": {},
342394          "signature": {
342395            "signature": {
342396              "publicKey": {}
342397            }
342398          },
342399          "modelCard": {
342400            "modelParameters": {
342401              "approach": {}
342402            },
342403            "quantitativeAnalysis": {
342404              "graphics": {}
342405            },
342406            "considerations": {}
342407          }
342408        },
342409        {
342410          "type": "library",
342411          "bom-ref": "pkg:npm/svgo@1.3.2?package-id=a9ef8dbc5cadd27d",
342412          "supplier": {},
342413          "name": "svgo",
342414          "version": "1.3.2",
342415          "licenses": [
342416            {
342417              "license": {
342418                "id": "MIT"
342419              }
342420            }
342421          ],
342422          "cpe": "cpe:2.3:a:svgo:svgo:1.3.2:*:*:*:*:*:*:*",
342423          "purl": "pkg:npm/svgo@1.3.2",
342424          "swid": {
342425            "attachment": {}
342426          },
342427          "pedigree": {},
342428          "evidence": {},
342429          "signature": {
342430            "signature": {
342431              "publicKey": {}
342432            }
342433          },
342434          "modelCard": {
342435            "modelParameters": {
342436              "approach": {}
342437            },
342438            "quantitativeAnalysis": {
342439              "graphics": {}
342440            },
342441            "considerations": {}
342442          }
342443        },
342444        {
342445          "type": "library",
342446          "bom-ref": "pkg:npm/symbol-observable@1.2.0?package-id=7a64e840ca76a512",
342447          "supplier": {},
342448          "name": "symbol-observable",
342449          "version": "1.2.0",
342450          "licenses": [
342451            {
342452              "license": {
342453                "id": "MIT"
342454              }
342455            }
342456          ],
342457          "cpe": "cpe:2.3:a:symbol-observable:symbol-observable:1.2.0:*:*:*:*:*:*:*",
342458          "purl": "pkg:npm/symbol-observable@1.2.0",
342459          "swid": {
342460            "attachment": {}
342461          },
342462          "pedigree": {},
342463          "evidence": {},
342464          "signature": {
342465            "signature": {
342466              "publicKey": {}
342467            }
342468          },
342469          "modelCard": {
342470            "modelParameters": {
342471              "approach": {}
342472            },
342473            "quantitativeAnalysis": {
342474              "graphics": {}
342475            },
342476            "considerations": {}
342477          }
342478        },
342479        {
342480          "type": "library",
342481          "bom-ref": "pkg:npm/tapable@1.1.3?package-id=239052b860ebde2a",
342482          "supplier": {},
342483          "name": "tapable",
342484          "version": "1.1.3",
342485          "licenses": [
342486            {
342487              "license": {
342488                "id": "MIT"
342489              }
342490            }
342491          ],
342492          "cpe": "cpe:2.3:a:tapable:tapable:1.1.3:*:*:*:*:*:*:*",
342493          "purl": "pkg:npm/tapable@1.1.3",
342494          "swid": {
342495            "attachment": {}
342496          },
342497          "pedigree": {},
342498          "evidence": {},
342499          "signature": {
342500            "signature": {
342501              "publicKey": {}
342502            }
342503          },
342504          "modelCard": {
342505            "modelParameters": {
342506              "approach": {}
342507            },
342508            "quantitativeAnalysis": {
342509              "graphics": {}
342510            },
342511            "considerations": {}
342512          }
342513        },
342514        {
342515          "type": "library",
342516          "bom-ref": "pkg:npm/tar@6.0.2?package-id=3289c5b100673942",
342517          "supplier": {},
342518          "name": "tar",
342519          "version": "6.0.2",
342520          "licenses": [
342521            {
342522              "license": {
342523                "id": "ISC"
342524              }
342525            }
342526          ],
342527          "cpe": "cpe:2.3:a:tar:tar:6.0.2:*:*:*:*:*:*:*",
342528          "purl": "pkg:npm/tar@6.0.2",
342529          "swid": {
342530            "attachment": {}
342531          },
342532          "pedigree": {},
342533          "evidence": {},
342534          "signature": {
342535            "signature": {
342536              "publicKey": {}
342537            }
342538          },
342539          "modelCard": {
342540            "modelParameters": {
342541              "approach": {}
342542            },
342543            "quantitativeAnalysis": {
342544              "graphics": {}
342545            },
342546            "considerations": {}
342547          }
342548        },
342549        {
342550          "type": "library",
342551          "bom-ref": "pkg:npm/terser@4.6.10?package-id=4d569bbfaf3b1959",
342552          "supplier": {},
342553          "name": "terser",
342554          "version": "4.6.10",
342555          "licenses": [
342556            {
342557              "license": {
342558                "id": "BSD-2-Clause"
342559              }
342560            }
342561          ],
342562          "cpe": "cpe:2.3:a:terser:terser:4.6.10:*:*:*:*:*:*:*",
342563          "purl": "pkg:npm/terser@4.6.10",
342564          "swid": {
342565            "attachment": {}
342566          },
342567          "pedigree": {},
342568          "evidence": {},
342569          "signature": {
342570            "signature": {
342571              "publicKey": {}
342572            }
342573          },
342574          "modelCard": {
342575            "modelParameters": {
342576              "approach": {}
342577            },
342578            "quantitativeAnalysis": {
342579              "graphics": {}
342580            },
342581            "considerations": {}
342582          }
342583        },
342584        {
342585          "type": "library",
342586          "bom-ref": "pkg:npm/terser-webpack-plugin@2.3.3?package-id=22d863943de06d06",
342587          "supplier": {},
342588          "name": "terser-webpack-plugin",
342589          "version": "2.3.3",
342590          "licenses": [
342591            {
342592              "license": {
342593                "id": "MIT"
342594              }
342595            }
342596          ],
342597          "cpe": "cpe:2.3:a:terser-webpack-plugin:terser-webpack-plugin:2.3.3:*:*:*:*:*:*:*",
342598          "purl": "pkg:npm/terser-webpack-plugin@2.3.3",
342599          "swid": {
342600            "attachment": {}
342601          },
342602          "pedigree": {},
342603          "evidence": {},
342604          "signature": {
342605            "signature": {
342606              "publicKey": {}
342607            }
342608          },
342609          "modelCard": {
342610            "modelParameters": {
342611              "approach": {}
342612            },
342613            "quantitativeAnalysis": {
342614              "graphics": {}
342615            },
342616            "considerations": {}
342617          }
342618        },
342619        {
342620          "type": "library",
342621          "bom-ref": "pkg:npm/test-exclude@6.0.0?package-id=666871ee39441051",
342622          "supplier": {},
342623          "name": "test-exclude",
342624          "version": "6.0.0",
342625          "cpe": "cpe:2.3:a:test-exclude:test-exclude:6.0.0:*:*:*:*:*:*:*",
342626          "purl": "pkg:npm/test-exclude@6.0.0",
342627          "swid": {
342628            "attachment": {}
342629          },
342630          "pedigree": {},
342631          "evidence": {},
342632          "signature": {
342633            "signature": {
342634              "publicKey": {}
342635            }
342636          },
342637          "modelCard": {
342638            "modelParameters": {
342639              "approach": {}
342640            },
342641            "quantitativeAnalysis": {
342642              "graphics": {}
342643            },
342644            "considerations": {}
342645          }
342646        },
342647        {
342648          "type": "library",
342649          "bom-ref": "pkg:npm/thenify@3.3.0?package-id=c15d981cbccddda3",
342650          "supplier": {},
342651          "name": "thenify",
342652          "version": "3.3.0",
342653          "licenses": [
342654            {
342655              "license": {
342656                "id": "MIT"
342657              }
342658            }
342659          ],
342660          "cpe": "cpe:2.3:a:thenify:thenify:3.3.0:*:*:*:*:*:*:*",
342661          "purl": "pkg:npm/thenify@3.3.0",
342662          "swid": {
342663            "attachment": {}
342664          },
342665          "pedigree": {},
342666          "evidence": {},
342667          "signature": {
342668            "signature": {
342669              "publicKey": {}
342670            }
342671          },
342672          "modelCard": {
342673            "modelParameters": {
342674              "approach": {}
342675            },
342676            "quantitativeAnalysis": {
342677              "graphics": {}
342678            },
342679            "considerations": {}
342680          }
342681        },
342682        {
342683          "type": "library",
342684          "bom-ref": "pkg:npm/thenify-all@1.6.0?package-id=7b6677ab1a8c7e52",
342685          "supplier": {},
342686          "name": "thenify-all",
342687          "version": "1.6.0",
342688          "licenses": [
342689            {
342690              "license": {
342691                "id": "MIT"
342692              }
342693            }
342694          ],
342695          "cpe": "cpe:2.3:a:thenify-all:thenify-all:1.6.0:*:*:*:*:*:*:*",
342696          "purl": "pkg:npm/thenify-all@1.6.0",
342697          "swid": {
342698            "attachment": {}
342699          },
342700          "pedigree": {},
342701          "evidence": {},
342702          "signature": {
342703            "signature": {
342704              "publicKey": {}
342705            }
342706          },
342707          "modelCard": {
342708            "modelParameters": {
342709              "approach": {}
342710            },
342711            "quantitativeAnalysis": {
342712              "graphics": {}
342713            },
342714            "considerations": {}
342715          }
342716        },
342717        {
342718          "type": "library",
342719          "bom-ref": "pkg:npm/through@2.3.8?package-id=59da2d5c89a5f3ea",
342720          "supplier": {},
342721          "name": "through",
342722          "version": "2.3.8",
342723          "licenses": [
342724            {
342725              "license": {
342726                "id": "MIT"
342727              }
342728            }
342729          ],
342730          "cpe": "cpe:2.3:a:through:through:2.3.8:*:*:*:*:*:*:*",
342731          "purl": "pkg:npm/through@2.3.8",
342732          "swid": {
342733            "attachment": {}
342734          },
342735          "pedigree": {},
342736          "evidence": {},
342737          "signature": {
342738            "signature": {
342739              "publicKey": {}
342740            }
342741          },
342742          "modelCard": {
342743            "modelParameters": {
342744              "approach": {}
342745            },
342746            "quantitativeAnalysis": {
342747              "graphics": {}
342748            },
342749            "considerations": {}
342750          }
342751        },
342752        {
342753          "type": "library",
342754          "bom-ref": "pkg:npm/through2@2.0.5?package-id=680db15354d84d6a",
342755          "supplier": {},
342756          "name": "through2",
342757          "version": "2.0.5",
342758          "licenses": [
342759            {
342760              "license": {
342761                "id": "MIT"
342762              }
342763            }
342764          ],
342765          "cpe": "cpe:2.3:a:through2:through2:2.0.5:*:*:*:*:*:*:*",
342766          "purl": "pkg:npm/through2@2.0.5",
342767          "swid": {
342768            "attachment": {}
342769          },
342770          "pedigree": {},
342771          "evidence": {},
342772          "signature": {
342773            "signature": {
342774              "publicKey": {}
342775            }
342776          },
342777          "modelCard": {
342778            "modelParameters": {
342779              "approach": {}
342780            },
342781            "quantitativeAnalysis": {
342782              "graphics": {}
342783            },
342784            "considerations": {}
342785          }
342786        },
342787        {
342788          "type": "library",
342789          "bom-ref": "pkg:npm/thunky@1.1.0?package-id=d787c6eea1ae59f2",
342790          "supplier": {},
342791          "name": "thunky",
342792          "version": "1.1.0",
342793          "licenses": [
342794            {
342795              "license": {
342796                "id": "MIT"
342797              }
342798            }
342799          ],
342800          "cpe": "cpe:2.3:a:thunky:thunky:1.1.0:*:*:*:*:*:*:*",
342801          "purl": "pkg:npm/thunky@1.1.0",
342802          "swid": {
342803            "attachment": {}
342804          },
342805          "pedigree": {},
342806          "evidence": {},
342807          "signature": {
342808            "signature": {
342809              "publicKey": {}
342810            }
342811          },
342812          "modelCard": {
342813            "modelParameters": {
342814              "approach": {}
342815            },
342816            "quantitativeAnalysis": {
342817              "graphics": {}
342818            },
342819            "considerations": {}
342820          }
342821        },
342822        {
342823          "type": "library",
342824          "bom-ref": "pkg:npm/timers-browserify@2.0.11?package-id=78c13348dd9e29d",
342825          "supplier": {},
342826          "name": "timers-browserify",
342827          "version": "2.0.11",
342828          "licenses": [
342829            {
342830              "license": {
342831                "id": "MIT"
342832              }
342833            }
342834          ],
342835          "cpe": "cpe:2.3:a:timers-browserify:timers-browserify:2.0.11:*:*:*:*:*:*:*",
342836          "purl": "pkg:npm/timers-browserify@2.0.11",
342837          "swid": {
342838            "attachment": {}
342839          },
342840          "pedigree": {},
342841          "evidence": {},
342842          "signature": {
342843            "signature": {
342844              "publicKey": {}
342845            }
342846          },
342847          "modelCard": {
342848            "modelParameters": {
342849              "approach": {}
342850            },
342851            "quantitativeAnalysis": {
342852              "graphics": {}
342853            },
342854            "considerations": {}
342855          }
342856        },
342857        {
342858          "type": "library",
342859          "bom-ref": "pkg:npm/timers-ext@0.1.7?package-id=a62c78e5a49031b4",
342860          "supplier": {},
342861          "name": "timers-ext",
342862          "version": "0.1.7",
342863          "licenses": [
342864            {
342865              "license": {
342866                "id": "ISC"
342867              }
342868            }
342869          ],
342870          "cpe": "cpe:2.3:a:timers-ext:timers-ext:0.1.7:*:*:*:*:*:*:*",
342871          "purl": "pkg:npm/timers-ext@0.1.7",
342872          "swid": {
342873            "attachment": {}
342874          },
342875          "pedigree": {},
342876          "evidence": {},
342877          "signature": {
342878            "signature": {
342879              "publicKey": {}
342880            }
342881          },
342882          "modelCard": {
342883            "modelParameters": {
342884              "approach": {}
342885            },
342886            "quantitativeAnalysis": {
342887              "graphics": {}
342888            },
342889            "considerations": {}
342890          }
342891        },
342892        {
342893          "type": "library",
342894          "bom-ref": "pkg:npm/timsort@0.3.0?package-id=3417b0753cba11ba",
342895          "supplier": {},
342896          "name": "timsort",
342897          "version": "0.3.0",
342898          "licenses": [
342899            {
342900              "license": {
342901                "id": "MIT"
342902              }
342903            }
342904          ],
342905          "cpe": "cpe:2.3:a:timsort:timsort:0.3.0:*:*:*:*:*:*:*",
342906          "purl": "pkg:npm/timsort@0.3.0",
342907          "swid": {
342908            "attachment": {}
342909          },
342910          "pedigree": {},
342911          "evidence": {},
342912          "signature": {
342913            "signature": {
342914              "publicKey": {}
342915            }
342916          },
342917          "modelCard": {
342918            "modelParameters": {
342919              "approach": {}
342920            },
342921            "quantitativeAnalysis": {
342922              "graphics": {}
342923            },
342924            "considerations": {}
342925          }
342926        },
342927        {
342928          "type": "library",
342929          "bom-ref": "pkg:npm/tmp@0.0.33?package-id=99174617889eed27",
342930          "supplier": {},
342931          "name": "tmp",
342932          "version": "0.0.33",
342933          "cpe": "cpe:2.3:a:tmp:tmp:0.0.33:*:*:*:*:*:*:*",
342934          "purl": "pkg:npm/tmp@0.0.33",
342935          "swid": {
342936            "attachment": {}
342937          },
342938          "pedigree": {},
342939          "evidence": {},
342940          "signature": {
342941            "signature": {
342942              "publicKey": {}
342943            }
342944          },
342945          "modelCard": {
342946            "modelParameters": {
342947              "approach": {}
342948            },
342949            "quantitativeAnalysis": {
342950              "graphics": {}
342951            },
342952            "considerations": {}
342953          }
342954        },
342955        {
342956          "type": "library",
342957          "bom-ref": "pkg:npm/tmp@0.0.33?package-id=79107498e110a960",
342958          "supplier": {},
342959          "name": "tmp",
342960          "version": "0.0.33",
342961          "licenses": [
342962            {
342963              "license": {
342964                "id": "MIT"
342965              }
342966            }
342967          ],
342968          "cpe": "cpe:2.3:a:tmp:tmp:0.0.33:*:*:*:*:*:*:*",
342969          "purl": "pkg:npm/tmp@0.0.33",
342970          "swid": {
342971            "attachment": {}
342972          },
342973          "pedigree": {},
342974          "evidence": {},
342975          "signature": {
342976            "signature": {
342977              "publicKey": {}
342978            }
342979          },
342980          "modelCard": {
342981            "modelParameters": {
342982              "approach": {}
342983            },
342984            "quantitativeAnalysis": {
342985              "graphics": {}
342986            },
342987            "considerations": {}
342988          }
342989        },
342990        {
342991          "type": "library",
342992          "bom-ref": "pkg:npm/to-array@0.1.4?package-id=a42b56d7344b1ef5",
342993          "supplier": {},
342994          "name": "to-array",
342995          "version": "0.1.4",
342996          "licenses": [
342997            {
342998              "license": {
342999                "id": "MIT"
343000              }
343001            }
343002          ],
343003          "cpe": "cpe:2.3:a:to-array:to-array:0.1.4:*:*:*:*:*:*:*",
343004          "purl": "pkg:npm/to-array@0.1.4",
343005          "swid": {
343006            "attachment": {}
343007          },
343008          "pedigree": {},
343009          "evidence": {},
343010          "signature": {
343011            "signature": {
343012              "publicKey": {}
343013            }
343014          },
343015          "modelCard": {
343016            "modelParameters": {
343017              "approach": {}
343018            },
343019            "quantitativeAnalysis": {
343020              "graphics": {}
343021            },
343022            "considerations": {}
343023          }
343024        },
343025        {
343026          "type": "library",
343027          "bom-ref": "pkg:npm/to-arraybuffer@1.0.1?package-id=fccba201ded544b7",
343028          "supplier": {},
343029          "name": "to-arraybuffer",
343030          "version": "1.0.1",
343031          "licenses": [
343032            {
343033              "license": {
343034                "id": "MIT"
343035              }
343036            }
343037          ],
343038          "cpe": "cpe:2.3:a:to-arraybuffer:to-arraybuffer:1.0.1:*:*:*:*:*:*:*",
343039          "purl": "pkg:npm/to-arraybuffer@1.0.1",
343040          "swid": {
343041            "attachment": {}
343042          },
343043          "pedigree": {},
343044          "evidence": {},
343045          "signature": {
343046            "signature": {
343047              "publicKey": {}
343048            }
343049          },
343050          "modelCard": {
343051            "modelParameters": {
343052              "approach": {}
343053            },
343054            "quantitativeAnalysis": {
343055              "graphics": {}
343056            },
343057            "considerations": {}
343058          }
343059        },
343060        {
343061          "type": "library",
343062          "bom-ref": "pkg:npm/to-fast-properties@2.0.0?package-id=5688ffa75461a929",
343063          "supplier": {},
343064          "name": "to-fast-properties",
343065          "version": "2.0.0",
343066          "cpe": "cpe:2.3:a:to-fast-properties:to-fast-properties:2.0.0:*:*:*:*:*:*:*",
343067          "purl": "pkg:npm/to-fast-properties@2.0.0",
343068          "swid": {
343069            "attachment": {}
343070          },
343071          "pedigree": {},
343072          "evidence": {},
343073          "signature": {
343074            "signature": {
343075              "publicKey": {}
343076            }
343077          },
343078          "modelCard": {
343079            "modelParameters": {
343080              "approach": {}
343081            },
343082            "quantitativeAnalysis": {
343083              "graphics": {}
343084            },
343085            "considerations": {}
343086          }
343087        },
343088        {
343089          "type": "library",
343090          "bom-ref": "pkg:npm/to-fast-properties@2.0.0?package-id=c26717bbb393789c",
343091          "supplier": {},
343092          "name": "to-fast-properties",
343093          "version": "2.0.0",
343094          "licenses": [
343095            {
343096              "license": {
343097                "id": "MIT"
343098              }
343099            }
343100          ],
343101          "cpe": "cpe:2.3:a:to-fast-properties:to-fast-properties:2.0.0:*:*:*:*:*:*:*",
343102          "purl": "pkg:npm/to-fast-properties@2.0.0",
343103          "swid": {
343104            "attachment": {}
343105          },
343106          "pedigree": {},
343107          "evidence": {},
343108          "signature": {
343109            "signature": {
343110              "publicKey": {}
343111            }
343112          },
343113          "modelCard": {
343114            "modelParameters": {
343115              "approach": {}
343116            },
343117            "quantitativeAnalysis": {
343118              "graphics": {}
343119            },
343120            "considerations": {}
343121          }
343122        },
343123        {
343124          "type": "library",
343125          "bom-ref": "pkg:npm/to-object-path@0.3.0?package-id=ea690cd126e39706",
343126          "supplier": {},
343127          "name": "to-object-path",
343128          "version": "0.3.0",
343129          "licenses": [
343130            {
343131              "license": {
343132                "id": "MIT"
343133              }
343134            }
343135          ],
343136          "cpe": "cpe:2.3:a:to-object-path:to-object-path:0.3.0:*:*:*:*:*:*:*",
343137          "purl": "pkg:npm/to-object-path@0.3.0",
343138          "swid": {
343139            "attachment": {}
343140          },
343141          "pedigree": {},
343142          "evidence": {},
343143          "signature": {
343144            "signature": {
343145              "publicKey": {}
343146            }
343147          },
343148          "modelCard": {
343149            "modelParameters": {
343150              "approach": {}
343151            },
343152            "quantitativeAnalysis": {
343153              "graphics": {}
343154            },
343155            "considerations": {}
343156          }
343157        },
343158        {
343159          "type": "library",
343160          "bom-ref": "pkg:npm/to-regex@3.0.2?package-id=fef71205c49ca38c",
343161          "supplier": {},
343162          "name": "to-regex",
343163          "version": "3.0.2",
343164          "licenses": [
343165            {
343166              "license": {
343167                "id": "MIT"
343168              }
343169            }
343170          ],
343171          "cpe": "cpe:2.3:a:to-regex:to-regex:3.0.2:*:*:*:*:*:*:*",
343172          "purl": "pkg:npm/to-regex@3.0.2",
343173          "swid": {
343174            "attachment": {}
343175          },
343176          "pedigree": {},
343177          "evidence": {},
343178          "signature": {
343179            "signature": {
343180              "publicKey": {}
343181            }
343182          },
343183          "modelCard": {
343184            "modelParameters": {
343185              "approach": {}
343186            },
343187            "quantitativeAnalysis": {
343188              "graphics": {}
343189            },
343190            "considerations": {}
343191          }
343192        },
343193        {
343194          "type": "library",
343195          "bom-ref": "pkg:npm/to-regex-range@5.0.1?package-id=c9085ffaa04a98e8",
343196          "supplier": {},
343197          "name": "to-regex-range",
343198          "version": "5.0.1",
343199          "cpe": "cpe:2.3:a:to-regex-range:to-regex-range:5.0.1:*:*:*:*:*:*:*",
343200          "purl": "pkg:npm/to-regex-range@5.0.1",
343201          "swid": {
343202            "attachment": {}
343203          },
343204          "pedigree": {},
343205          "evidence": {},
343206          "signature": {
343207            "signature": {
343208              "publicKey": {}
343209            }
343210          },
343211          "modelCard": {
343212            "modelParameters": {
343213              "approach": {}
343214            },
343215            "quantitativeAnalysis": {
343216              "graphics": {}
343217            },
343218            "considerations": {}
343219          }
343220        },
343221        {
343222          "type": "library",
343223          "bom-ref": "pkg:npm/to-regex-range@5.0.1?package-id=57510c54f6c59af8",
343224          "supplier": {},
343225          "name": "to-regex-range",
343226          "version": "5.0.1",
343227          "licenses": [
343228            {
343229              "license": {
343230                "id": "MIT"
343231              }
343232            }
343233          ],
343234          "cpe": "cpe:2.3:a:to-regex-range:to-regex-range:5.0.1:*:*:*:*:*:*:*",
343235          "purl": "pkg:npm/to-regex-range@5.0.1",
343236          "swid": {
343237            "attachment": {}
343238          },
343239          "pedigree": {},
343240          "evidence": {},
343241          "signature": {
343242            "signature": {
343243              "publicKey": {}
343244            }
343245          },
343246          "modelCard": {
343247            "modelParameters": {
343248              "approach": {}
343249            },
343250            "quantitativeAnalysis": {
343251              "graphics": {}
343252            },
343253            "considerations": {}
343254          }
343255        },
343256        {
343257          "type": "library",
343258          "bom-ref": "pkg:npm/toidentifier@1.0.0?package-id=42e8a0332c24f064",
343259          "supplier": {},
343260          "name": "toidentifier",
343261          "version": "1.0.0",
343262          "licenses": [
343263            {
343264              "license": {
343265                "id": "MIT"
343266              }
343267            }
343268          ],
343269          "cpe": "cpe:2.3:a:toidentifier:toidentifier:1.0.0:*:*:*:*:*:*:*",
343270          "purl": "pkg:npm/toidentifier@1.0.0",
343271          "swid": {
343272            "attachment": {}
343273          },
343274          "pedigree": {},
343275          "evidence": {},
343276          "signature": {
343277            "signature": {
343278              "publicKey": {}
343279            }
343280          },
343281          "modelCard": {
343282            "modelParameters": {
343283              "approach": {}
343284            },
343285            "quantitativeAnalysis": {
343286              "graphics": {}
343287            },
343288            "considerations": {}
343289          }
343290        },
343291        {
343292          "type": "library",
343293          "bom-ref": "pkg:npm/tough-cookie@2.5.0?package-id=eddf34eff8e47610",
343294          "supplier": {},
343295          "name": "tough-cookie",
343296          "version": "2.5.0",
343297          "licenses": [
343298            {
343299              "license": {
343300                "id": "BSD-3-Clause"
343301              }
343302            }
343303          ],
343304          "cpe": "cpe:2.3:a:tough-cookie:tough-cookie:2.5.0:*:*:*:*:*:*:*",
343305          "purl": "pkg:npm/tough-cookie@2.5.0",
343306          "swid": {
343307            "attachment": {}
343308          },
343309          "pedigree": {},
343310          "evidence": {},
343311          "signature": {
343312            "signature": {
343313              "publicKey": {}
343314            }
343315          },
343316          "modelCard": {
343317            "modelParameters": {
343318              "approach": {}
343319            },
343320            "quantitativeAnalysis": {
343321              "graphics": {}
343322            },
343323            "considerations": {}
343324          }
343325        },
343326        {
343327          "type": "library",
343328          "bom-ref": "pkg:npm/traverse@0.6.6?package-id=3a9ba654ce5af4e9",
343329          "supplier": {},
343330          "name": "traverse",
343331          "version": "0.6.6",
343332          "licenses": [
343333            {
343334              "license": {
343335                "id": "MIT"
343336              }
343337            }
343338          ],
343339          "cpe": "cpe:2.3:a:traverse:traverse:0.6.6:*:*:*:*:*:*:*",
343340          "purl": "pkg:npm/traverse@0.6.6",
343341          "swid": {
343342            "attachment": {}
343343          },
343344          "pedigree": {},
343345          "evidence": {},
343346          "signature": {
343347            "signature": {
343348              "publicKey": {}
343349            }
343350          },
343351          "modelCard": {
343352            "modelParameters": {
343353              "approach": {}
343354            },
343355            "quantitativeAnalysis": {
343356              "graphics": {}
343357            },
343358            "considerations": {}
343359          }
343360        },
343361        {
343362          "type": "library",
343363          "bom-ref": "pkg:npm/tree-kill@1.2.2?package-id=60e5ab6fd2fb7df6",
343364          "supplier": {},
343365          "name": "tree-kill",
343366          "version": "1.2.2",
343367          "licenses": [
343368            {
343369              "license": {
343370                "id": "MIT"
343371              }
343372            }
343373          ],
343374          "cpe": "cpe:2.3:a:tree-kill:tree-kill:1.2.2:*:*:*:*:*:*:*",
343375          "purl": "pkg:npm/tree-kill@1.2.2",
343376          "swid": {
343377            "attachment": {}
343378          },
343379          "pedigree": {},
343380          "evidence": {},
343381          "signature": {
343382            "signature": {
343383              "publicKey": {}
343384            }
343385          },
343386          "modelCard": {
343387            "modelParameters": {
343388              "approach": {}
343389            },
343390            "quantitativeAnalysis": {
343391              "graphics": {}
343392            },
343393            "considerations": {}
343394          }
343395        },
343396        {
343397          "type": "library",
343398          "bom-ref": "pkg:npm/trim-newlines@1.0.0?package-id=7c816eb7b0f5956b",
343399          "supplier": {},
343400          "name": "trim-newlines",
343401          "version": "1.0.0",
343402          "licenses": [
343403            {
343404              "license": {
343405                "id": "MIT"
343406              }
343407            }
343408          ],
343409          "cpe": "cpe:2.3:a:trim-newlines:trim-newlines:1.0.0:*:*:*:*:*:*:*",
343410          "purl": "pkg:npm/trim-newlines@1.0.0",
343411          "swid": {
343412            "attachment": {}
343413          },
343414          "pedigree": {},
343415          "evidence": {},
343416          "signature": {
343417            "signature": {
343418              "publicKey": {}
343419            }
343420          },
343421          "modelCard": {
343422            "modelParameters": {
343423              "approach": {}
343424            },
343425            "quantitativeAnalysis": {
343426              "graphics": {}
343427            },
343428            "considerations": {}
343429          }
343430        },
343431        {
343432          "type": "library",
343433          "bom-ref": "pkg:npm/true-case-path@1.0.3?package-id=10590dec6bc9ef4",
343434          "supplier": {},
343435          "name": "true-case-path",
343436          "version": "1.0.3",
343437          "licenses": [
343438            {
343439              "license": {
343440                "id": "Apache-2.0"
343441              }
343442            }
343443          ],
343444          "cpe": "cpe:2.3:a:true-case-path:true-case-path:1.0.3:*:*:*:*:*:*:*",
343445          "purl": "pkg:npm/true-case-path@1.0.3",
343446          "swid": {
343447            "attachment": {}
343448          },
343449          "pedigree": {},
343450          "evidence": {},
343451          "signature": {
343452            "signature": {
343453              "publicKey": {}
343454            }
343455          },
343456          "modelCard": {
343457            "modelParameters": {
343458              "approach": {}
343459            },
343460            "quantitativeAnalysis": {
343461              "graphics": {}
343462            },
343463            "considerations": {}
343464          }
343465        },
343466        {
343467          "type": "library",
343468          "bom-ref": "pkg:npm/truncate-utf8-bytes@1.0.2?package-id=6c457f8c2194f1e5",
343469          "supplier": {},
343470          "name": "truncate-utf8-bytes",
343471          "version": "1.0.2",
343472          "licenses": [
343473            {
343474              "license": {
343475                "id": "WTFPL"
343476              }
343477            }
343478          ],
343479          "cpe": "cpe:2.3:a:truncate-utf8-bytes:truncate-utf8-bytes:1.0.2:*:*:*:*:*:*:*",
343480          "purl": "pkg:npm/truncate-utf8-bytes@1.0.2",
343481          "swid": {
343482            "attachment": {}
343483          },
343484          "pedigree": {},
343485          "evidence": {},
343486          "signature": {
343487            "signature": {
343488              "publicKey": {}
343489            }
343490          },
343491          "modelCard": {
343492            "modelParameters": {
343493              "approach": {}
343494            },
343495            "quantitativeAnalysis": {
343496              "graphics": {}
343497            },
343498            "considerations": {}
343499          }
343500        },
343501        {
343502          "type": "library",
343503          "bom-ref": "pkg:npm/tryer@1.0.1?package-id=a61b5b6a53c2e46f",
343504          "supplier": {},
343505          "name": "tryer",
343506          "version": "1.0.1",
343507          "licenses": [
343508            {
343509              "license": {
343510                "id": "MIT"
343511              }
343512            }
343513          ],
343514          "cpe": "cpe:2.3:a:tryer:tryer:1.0.1:*:*:*:*:*:*:*",
343515          "purl": "pkg:npm/tryer@1.0.1",
343516          "swid": {
343517            "attachment": {}
343518          },
343519          "pedigree": {},
343520          "evidence": {},
343521          "signature": {
343522            "signature": {
343523              "publicKey": {}
343524            }
343525          },
343526          "modelCard": {
343527            "modelParameters": {
343528              "approach": {}
343529            },
343530            "quantitativeAnalysis": {
343531              "graphics": {}
343532            },
343533            "considerations": {}
343534          }
343535        },
343536        {
343537          "type": "library",
343538          "bom-ref": "pkg:npm/ts-node@8.8.1?package-id=3edad8bca011dfb7",
343539          "supplier": {},
343540          "name": "ts-node",
343541          "version": "8.8.1",
343542          "licenses": [
343543            {
343544              "license": {
343545                "id": "MIT"
343546              }
343547            }
343548          ],
343549          "cpe": "cpe:2.3:a:ts-node:ts-node:8.8.1:*:*:*:*:*:*:*",
343550          "purl": "pkg:npm/ts-node@8.8.1",
343551          "swid": {
343552            "attachment": {}
343553          },
343554          "pedigree": {},
343555          "evidence": {},
343556          "signature": {
343557            "signature": {
343558              "publicKey": {}
343559            }
343560          },
343561          "modelCard": {
343562            "modelParameters": {
343563              "approach": {}
343564            },
343565            "quantitativeAnalysis": {
343566              "graphics": {}
343567            },
343568            "considerations": {}
343569          }
343570        },
343571        {
343572          "type": "library",
343573          "bom-ref": "pkg:npm/tslib@1.11.1?package-id=b220cfe8cff08714",
343574          "supplier": {},
343575          "name": "tslib",
343576          "version": "1.11.1",
343577          "licenses": [
343578            {
343579              "license": {
343580                "id": "Apache-2.0"
343581              }
343582            }
343583          ],
343584          "cpe": "cpe:2.3:a:tslib:tslib:1.11.1:*:*:*:*:*:*:*",
343585          "purl": "pkg:npm/tslib@1.11.1",
343586          "swid": {
343587            "attachment": {}
343588          },
343589          "pedigree": {},
343590          "evidence": {},
343591          "signature": {
343592            "signature": {
343593              "publicKey": {}
343594            }
343595          },
343596          "modelCard": {
343597            "modelParameters": {
343598              "approach": {}
343599            },
343600            "quantitativeAnalysis": {
343601              "graphics": {}
343602            },
343603            "considerations": {}
343604          }
343605        },
343606        {
343607          "type": "library",
343608          "bom-ref": "pkg:npm/tslint@6.1.0?package-id=612310248b471309",
343609          "supplier": {},
343610          "name": "tslint",
343611          "version": "6.1.0",
343612          "licenses": [
343613            {
343614              "license": {
343615                "id": "Apache-2.0"
343616              }
343617            }
343618          ],
343619          "cpe": "cpe:2.3:a:tslint:tslint:6.1.0:*:*:*:*:*:*:*",
343620          "purl": "pkg:npm/tslint@6.1.0",
343621          "swid": {
343622            "attachment": {}
343623          },
343624          "pedigree": {},
343625          "evidence": {},
343626          "signature": {
343627            "signature": {
343628              "publicKey": {}
343629            }
343630          },
343631          "modelCard": {
343632            "modelParameters": {
343633              "approach": {}
343634            },
343635            "quantitativeAnalysis": {
343636              "graphics": {}
343637            },
343638            "considerations": {}
343639          }
343640        },
343641        {
343642          "type": "library",
343643          "bom-ref": "pkg:npm/tslint-sonarts@1.9.0?package-id=167ec1ee58f83208",
343644          "supplier": {},
343645          "name": "tslint-sonarts",
343646          "version": "1.9.0",
343647          "licenses": [
343648            {
343649              "license": {
343650                "id": "LGPL-3.0-only"
343651              }
343652            }
343653          ],
343654          "cpe": "cpe:2.3:a:tslint-sonarts:tslint-sonarts:1.9.0:*:*:*:*:*:*:*",
343655          "purl": "pkg:npm/tslint-sonarts@1.9.0",
343656          "swid": {
343657            "attachment": {}
343658          },
343659          "pedigree": {},
343660          "evidence": {},
343661          "signature": {
343662            "signature": {
343663              "publicKey": {}
343664            }
343665          },
343666          "modelCard": {
343667            "modelParameters": {
343668              "approach": {}
343669            },
343670            "quantitativeAnalysis": {
343671              "graphics": {}
343672            },
343673            "considerations": {}
343674          }
343675        },
343676        {
343677          "type": "library",
343678          "bom-ref": "pkg:npm/tsutils@2.29.0?package-id=f53978a11863eea4",
343679          "supplier": {},
343680          "name": "tsutils",
343681          "version": "2.29.0",
343682          "licenses": [
343683            {
343684              "license": {
343685                "id": "MIT"
343686              }
343687            }
343688          ],
343689          "cpe": "cpe:2.3:a:tsutils:tsutils:2.29.0:*:*:*:*:*:*:*",
343690          "purl": "pkg:npm/tsutils@2.29.0",
343691          "swid": {
343692            "attachment": {}
343693          },
343694          "pedigree": {},
343695          "evidence": {},
343696          "signature": {
343697            "signature": {
343698              "publicKey": {}
343699            }
343700          },
343701          "modelCard": {
343702            "modelParameters": {
343703              "approach": {}
343704            },
343705            "quantitativeAnalysis": {
343706              "graphics": {}
343707            },
343708            "considerations": {}
343709          }
343710        },
343711        {
343712          "type": "library",
343713          "bom-ref": "pkg:npm/tty-browserify@0.0.0?package-id=d884a3760f467d67",
343714          "supplier": {},
343715          "name": "tty-browserify",
343716          "version": "0.0.0",
343717          "licenses": [
343718            {
343719              "license": {
343720                "id": "MIT"
343721              }
343722            }
343723          ],
343724          "cpe": "cpe:2.3:a:tty-browserify:tty-browserify:0.0.0:*:*:*:*:*:*:*",
343725          "purl": "pkg:npm/tty-browserify@0.0.0",
343726          "swid": {
343727            "attachment": {}
343728          },
343729          "pedigree": {},
343730          "evidence": {},
343731          "signature": {
343732            "signature": {
343733              "publicKey": {}
343734            }
343735          },
343736          "modelCard": {
343737            "modelParameters": {
343738              "approach": {}
343739            },
343740            "quantitativeAnalysis": {
343741              "graphics": {}
343742            },
343743            "considerations": {}
343744          }
343745        },
343746        {
343747          "type": "library",
343748          "bom-ref": "pkg:npm/tunnel-agent@0.6.0?package-id=ca049987a582a89c",
343749          "supplier": {},
343750          "name": "tunnel-agent",
343751          "version": "0.6.0",
343752          "licenses": [
343753            {
343754              "license": {
343755                "id": "Apache-2.0"
343756              }
343757            }
343758          ],
343759          "cpe": "cpe:2.3:a:tunnel-agent:tunnel-agent:0.6.0:*:*:*:*:*:*:*",
343760          "purl": "pkg:npm/tunnel-agent@0.6.0",
343761          "swid": {
343762            "attachment": {}
343763          },
343764          "pedigree": {},
343765          "evidence": {},
343766          "signature": {
343767            "signature": {
343768              "publicKey": {}
343769            }
343770          },
343771          "modelCard": {
343772            "modelParameters": {
343773              "approach": {}
343774            },
343775            "quantitativeAnalysis": {
343776              "graphics": {}
343777            },
343778            "considerations": {}
343779          }
343780        },
343781        {
343782          "type": "library",
343783          "bom-ref": "pkg:npm/tweetnacl@0.14.5?package-id=49aff99863163f8d",
343784          "supplier": {},
343785          "name": "tweetnacl",
343786          "version": "0.14.5",
343787          "licenses": [
343788            {
343789              "license": {
343790                "id": "Unlicense"
343791              }
343792            }
343793          ],
343794          "cpe": "cpe:2.3:a:tweetnacl:tweetnacl:0.14.5:*:*:*:*:*:*:*",
343795          "purl": "pkg:npm/tweetnacl@0.14.5",
343796          "swid": {
343797            "attachment": {}
343798          },
343799          "pedigree": {},
343800          "evidence": {},
343801          "signature": {
343802            "signature": {
343803              "publicKey": {}
343804            }
343805          },
343806          "modelCard": {
343807            "modelParameters": {
343808              "approach": {}
343809            },
343810            "quantitativeAnalysis": {
343811              "graphics": {}
343812            },
343813            "considerations": {}
343814          }
343815        },
343816        {
343817          "type": "library",
343818          "bom-ref": "pkg:npm/type@1.2.0?package-id=ed0a25a474d7af8",
343819          "supplier": {},
343820          "name": "type",
343821          "version": "1.2.0",
343822          "licenses": [
343823            {
343824              "license": {
343825                "id": "ISC"
343826              }
343827            }
343828          ],
343829          "cpe": "cpe:2.3:a:type:type:1.2.0:*:*:*:*:*:*:*",
343830          "purl": "pkg:npm/type@1.2.0",
343831          "swid": {
343832            "attachment": {}
343833          },
343834          "pedigree": {},
343835          "evidence": {},
343836          "signature": {
343837            "signature": {
343838              "publicKey": {}
343839            }
343840          },
343841          "modelCard": {
343842            "modelParameters": {
343843              "approach": {}
343844            },
343845            "quantitativeAnalysis": {
343846              "graphics": {}
343847            },
343848            "considerations": {}
343849          }
343850        },
343851        {
343852          "type": "library",
343853          "bom-ref": "pkg:npm/type-fest@0.11.0?package-id=70ae5ef2778315c",
343854          "supplier": {},
343855          "name": "type-fest",
343856          "version": "0.11.0",
343857          "licenses": [
343858            {
343859              "license": {
343860                "name": "(MIT OR CC0-1.0)"
343861              }
343862            }
343863          ],
343864          "cpe": "cpe:2.3:a:type-fest:type-fest:0.11.0:*:*:*:*:*:*:*",
343865          "purl": "pkg:npm/type-fest@0.11.0",
343866          "swid": {
343867            "attachment": {}
343868          },
343869          "pedigree": {},
343870          "evidence": {},
343871          "signature": {
343872            "signature": {
343873              "publicKey": {}
343874            }
343875          },
343876          "modelCard": {
343877            "modelParameters": {
343878              "approach": {}
343879            },
343880            "quantitativeAnalysis": {
343881              "graphics": {}
343882            },
343883            "considerations": {}
343884          }
343885        },
343886        {
343887          "type": "library",
343888          "bom-ref": "pkg:npm/type-fest@0.8.1?package-id=eaafa4d63af648e2",
343889          "supplier": {},
343890          "name": "type-fest",
343891          "version": "0.8.1",
343892          "cpe": "cpe:2.3:a:type-fest:type-fest:0.8.1:*:*:*:*:*:*:*",
343893          "purl": "pkg:npm/type-fest@0.8.1",
343894          "swid": {
343895            "attachment": {}
343896          },
343897          "pedigree": {},
343898          "evidence": {},
343899          "signature": {
343900            "signature": {
343901              "publicKey": {}
343902            }
343903          },
343904          "modelCard": {
343905            "modelParameters": {
343906              "approach": {}
343907            },
343908            "quantitativeAnalysis": {
343909              "graphics": {}
343910            },
343911            "considerations": {}
343912          }
343913        },
343914        {
343915          "type": "library",
343916          "bom-ref": "pkg:npm/type-is@1.6.18?package-id=abecd6ccd968e17a",
343917          "supplier": {},
343918          "name": "type-is",
343919          "version": "1.6.18",
343920          "licenses": [
343921            {
343922              "license": {
343923                "id": "MIT"
343924              }
343925            }
343926          ],
343927          "cpe": "cpe:2.3:a:type-is:type-is:1.6.18:*:*:*:*:*:*:*",
343928          "purl": "pkg:npm/type-is@1.6.18",
343929          "swid": {
343930            "attachment": {}
343931          },
343932          "pedigree": {},
343933          "evidence": {},
343934          "signature": {
343935            "signature": {
343936              "publicKey": {}
343937            }
343938          },
343939          "modelCard": {
343940            "modelParameters": {
343941              "approach": {}
343942            },
343943            "quantitativeAnalysis": {
343944              "graphics": {}
343945            },
343946            "considerations": {}
343947          }
343948        },
343949        {
343950          "type": "library",
343951          "bom-ref": "pkg:npm/typedarray@0.0.6?package-id=faf25266527325bf",
343952          "supplier": {},
343953          "name": "typedarray",
343954          "version": "0.0.6",
343955          "licenses": [
343956            {
343957              "license": {
343958                "id": "MIT"
343959              }
343960            }
343961          ],
343962          "cpe": "cpe:2.3:a:typedarray:typedarray:0.0.6:*:*:*:*:*:*:*",
343963          "purl": "pkg:npm/typedarray@0.0.6",
343964          "swid": {
343965            "attachment": {}
343966          },
343967          "pedigree": {},
343968          "evidence": {},
343969          "signature": {
343970            "signature": {
343971              "publicKey": {}
343972            }
343973          },
343974          "modelCard": {
343975            "modelParameters": {
343976              "approach": {}
343977            },
343978            "quantitativeAnalysis": {
343979              "graphics": {}
343980            },
343981            "considerations": {}
343982          }
343983        },
343984        {
343985          "type": "library",
343986          "bom-ref": "pkg:npm/typedarray-to-buffer@3.1.5?package-id=ce8a4e35b41de8ed",
343987          "supplier": {},
343988          "name": "typedarray-to-buffer",
343989          "version": "3.1.5",
343990          "cpe": "cpe:2.3:a:typedarray-to-buffer:typedarray-to-buffer:3.1.5:*:*:*:*:*:*:*",
343991          "purl": "pkg:npm/typedarray-to-buffer@3.1.5",
343992          "swid": {
343993            "attachment": {}
343994          },
343995          "pedigree": {},
343996          "evidence": {},
343997          "signature": {
343998            "signature": {
343999              "publicKey": {}
344000            }
344001          },
344002          "modelCard": {
344003            "modelParameters": {
344004              "approach": {}
344005            },
344006            "quantitativeAnalysis": {
344007              "graphics": {}
344008            },
344009            "considerations": {}
344010          }
344011        },
344012        {
344013          "type": "library",
344014          "bom-ref": "pkg:npm/typescript@3.7.5?package-id=28da239670879666",
344015          "supplier": {},
344016          "name": "typescript",
344017          "version": "3.7.5",
344018          "licenses": [
344019            {
344020              "license": {
344021                "id": "Apache-2.0"
344022              }
344023            }
344024          ],
344025          "cpe": "cpe:2.3:a:typescript:typescript:3.7.5:*:*:*:*:*:*:*",
344026          "purl": "pkg:npm/typescript@3.7.5",
344027          "swid": {
344028            "attachment": {}
344029          },
344030          "pedigree": {},
344031          "evidence": {},
344032          "signature": {
344033            "signature": {
344034              "publicKey": {}
344035            }
344036          },
344037          "modelCard": {
344038            "modelParameters": {
344039              "approach": {}
344040            },
344041            "quantitativeAnalysis": {
344042              "graphics": {}
344043            },
344044            "considerations": {}
344045          }
344046        },
344047        {
344048          "type": "library",
344049          "bom-ref": "pkg:npm/ua-parser-js@0.7.21?package-id=b951501830cc61e0",
344050          "supplier": {},
344051          "name": "ua-parser-js",
344052          "version": "0.7.21",
344053          "licenses": [
344054            {
344055              "license": {
344056                "id": "MIT"
344057              }
344058            }
344059          ],
344060          "cpe": "cpe:2.3:a:ua-parser-js:ua-parser-js:0.7.21:*:*:*:*:*:*:*",
344061          "purl": "pkg:npm/ua-parser-js@0.7.21",
344062          "swid": {
344063            "attachment": {}
344064          },
344065          "pedigree": {},
344066          "evidence": {},
344067          "signature": {
344068            "signature": {
344069              "publicKey": {}
344070            }
344071          },
344072          "modelCard": {
344073            "modelParameters": {
344074              "approach": {}
344075            },
344076            "quantitativeAnalysis": {
344077              "graphics": {}
344078            },
344079            "considerations": {}
344080          }
344081        },
344082        {
344083          "type": "library",
344084          "bom-ref": "pkg:npm/ultron@1.1.1?package-id=7afe554e7e1e2c78",
344085          "supplier": {},
344086          "name": "ultron",
344087          "version": "1.1.1",
344088          "licenses": [
344089            {
344090              "license": {
344091                "id": "MIT"
344092              }
344093            }
344094          ],
344095          "cpe": "cpe:2.3:a:ultron:ultron:1.1.1:*:*:*:*:*:*:*",
344096          "purl": "pkg:npm/ultron@1.1.1",
344097          "swid": {
344098            "attachment": {}
344099          },
344100          "pedigree": {},
344101          "evidence": {},
344102          "signature": {
344103            "signature": {
344104              "publicKey": {}
344105            }
344106          },
344107          "modelCard": {
344108            "modelParameters": {
344109              "approach": {}
344110            },
344111            "quantitativeAnalysis": {
344112              "graphics": {}
344113            },
344114            "considerations": {}
344115          }
344116        },
344117        {
344118          "type": "library",
344119          "bom-ref": "pkg:npm/unicode-canonical-property-names-ecmascript@1.0.4?package-id=fd75918e3a809f9",
344120          "supplier": {},
344121          "name": "unicode-canonical-property-names-ecmascript",
344122          "version": "1.0.4",
344123          "licenses": [
344124            {
344125              "license": {
344126                "id": "MIT"
344127              }
344128            }
344129          ],
344130          "cpe": "cpe:2.3:a:unicode-canonical-property-names-ecmascript:unicode-canonical-property-names-ecmascript:1.0.4:*:*:*:*:*:*:*",
344131          "purl": "pkg:npm/unicode-canonical-property-names-ecmascript@1.0.4",
344132          "swid": {
344133            "attachment": {}
344134          },
344135          "pedigree": {},
344136          "evidence": {},
344137          "signature": {
344138            "signature": {
344139              "publicKey": {}
344140            }
344141          },
344142          "modelCard": {
344143            "modelParameters": {
344144              "approach": {}
344145            },
344146            "quantitativeAnalysis": {
344147              "graphics": {}
344148            },
344149            "considerations": {}
344150          }
344151        },
344152        {
344153          "type": "library",
344154          "bom-ref": "pkg:npm/unicode-match-property-ecmascript@1.0.4?package-id=4c03460f6eb6d9a",
344155          "supplier": {},
344156          "name": "unicode-match-property-ecmascript",
344157          "version": "1.0.4",
344158          "licenses": [
344159            {
344160              "license": {
344161                "id": "MIT"
344162              }
344163            }
344164          ],
344165          "cpe": "cpe:2.3:a:unicode-match-property-ecmascript:unicode-match-property-ecmascript:1.0.4:*:*:*:*:*:*:*",
344166          "purl": "pkg:npm/unicode-match-property-ecmascript@1.0.4",
344167          "swid": {
344168            "attachment": {}
344169          },
344170          "pedigree": {},
344171          "evidence": {},
344172          "signature": {
344173            "signature": {
344174              "publicKey": {}
344175            }
344176          },
344177          "modelCard": {
344178            "modelParameters": {
344179              "approach": {}
344180            },
344181            "quantitativeAnalysis": {
344182              "graphics": {}
344183            },
344184            "considerations": {}
344185          }
344186        },
344187        {
344188          "type": "library",
344189          "bom-ref": "pkg:npm/unicode-match-property-value-ecmascript@1.2.0?package-id=9a086af5f5363e1d",
344190          "supplier": {},
344191          "name": "unicode-match-property-value-ecmascript",
344192          "version": "1.2.0",
344193          "licenses": [
344194            {
344195              "license": {
344196                "id": "MIT"
344197              }
344198            }
344199          ],
344200          "cpe": "cpe:2.3:a:unicode-match-property-value-ecmascript:unicode-match-property-value-ecmascript:1.2.0:*:*:*:*:*:*:*",
344201          "purl": "pkg:npm/unicode-match-property-value-ecmascript@1.2.0",
344202          "swid": {
344203            "attachment": {}
344204          },
344205          "pedigree": {},
344206          "evidence": {},
344207          "signature": {
344208            "signature": {
344209              "publicKey": {}
344210            }
344211          },
344212          "modelCard": {
344213            "modelParameters": {
344214              "approach": {}
344215            },
344216            "quantitativeAnalysis": {
344217              "graphics": {}
344218            },
344219            "considerations": {}
344220          }
344221        },
344222        {
344223          "type": "library",
344224          "bom-ref": "pkg:npm/unicode-property-aliases-ecmascript@1.1.0?package-id=9debf1995fb31829",
344225          "supplier": {},
344226          "name": "unicode-property-aliases-ecmascript",
344227          "version": "1.1.0",
344228          "licenses": [
344229            {
344230              "license": {
344231                "id": "MIT"
344232              }
344233            }
344234          ],
344235          "cpe": "cpe:2.3:a:unicode-property-aliases-ecmascript:unicode-property-aliases-ecmascript:1.1.0:*:*:*:*:*:*:*",
344236          "purl": "pkg:npm/unicode-property-aliases-ecmascript@1.1.0",
344237          "swid": {
344238            "attachment": {}
344239          },
344240          "pedigree": {},
344241          "evidence": {},
344242          "signature": {
344243            "signature": {
344244              "publicKey": {}
344245            }
344246          },
344247          "modelCard": {
344248            "modelParameters": {
344249              "approach": {}
344250            },
344251            "quantitativeAnalysis": {
344252              "graphics": {}
344253            },
344254            "considerations": {}
344255          }
344256        },
344257        {
344258          "type": "library",
344259          "bom-ref": "pkg:npm/union-value@1.0.1?package-id=9ad216dfd9b336c9",
344260          "supplier": {},
344261          "name": "union-value",
344262          "version": "1.0.1",
344263          "licenses": [
344264            {
344265              "license": {
344266                "id": "MIT"
344267              }
344268            }
344269          ],
344270          "cpe": "cpe:2.3:a:union-value:union-value:1.0.1:*:*:*:*:*:*:*",
344271          "purl": "pkg:npm/union-value@1.0.1",
344272          "swid": {
344273            "attachment": {}
344274          },
344275          "pedigree": {},
344276          "evidence": {},
344277          "signature": {
344278            "signature": {
344279              "publicKey": {}
344280            }
344281          },
344282          "modelCard": {
344283            "modelParameters": {
344284              "approach": {}
344285            },
344286            "quantitativeAnalysis": {
344287              "graphics": {}
344288            },
344289            "considerations": {}
344290          }
344291        },
344292        {
344293          "type": "library",
344294          "bom-ref": "pkg:npm/uniq@1.0.1?package-id=c5228021d904ff2f",
344295          "supplier": {},
344296          "name": "uniq",
344297          "version": "1.0.1",
344298          "licenses": [
344299            {
344300              "license": {
344301                "id": "MIT"
344302              }
344303            }
344304          ],
344305          "cpe": "cpe:2.3:a:uniq:uniq:1.0.1:*:*:*:*:*:*:*",
344306          "purl": "pkg:npm/uniq@1.0.1",
344307          "swid": {
344308            "attachment": {}
344309          },
344310          "pedigree": {},
344311          "evidence": {},
344312          "signature": {
344313            "signature": {
344314              "publicKey": {}
344315            }
344316          },
344317          "modelCard": {
344318            "modelParameters": {
344319              "approach": {}
344320            },
344321            "quantitativeAnalysis": {
344322              "graphics": {}
344323            },
344324            "considerations": {}
344325          }
344326        },
344327        {
344328          "type": "library",
344329          "bom-ref": "pkg:npm/uniqs@2.0.0?package-id=4e42cb56c0afef43",
344330          "supplier": {},
344331          "name": "uniqs",
344332          "version": "2.0.0",
344333          "licenses": [
344334            {
344335              "license": {
344336                "id": "MIT"
344337              }
344338            }
344339          ],
344340          "cpe": "cpe:2.3:a:uniqs:uniqs:2.0.0:*:*:*:*:*:*:*",
344341          "purl": "pkg:npm/uniqs@2.0.0",
344342          "swid": {
344343            "attachment": {}
344344          },
344345          "pedigree": {},
344346          "evidence": {},
344347          "signature": {
344348            "signature": {
344349              "publicKey": {}
344350            }
344351          },
344352          "modelCard": {
344353            "modelParameters": {
344354              "approach": {}
344355            },
344356            "quantitativeAnalysis": {
344357              "graphics": {}
344358            },
344359            "considerations": {}
344360          }
344361        },
344362        {
344363          "type": "library",
344364          "bom-ref": "pkg:npm/unique-filename@1.1.1?package-id=851a0d45e78532d9",
344365          "supplier": {},
344366          "name": "unique-filename",
344367          "version": "1.1.1",
344368          "licenses": [
344369            {
344370              "license": {
344371                "id": "ISC"
344372              }
344373            }
344374          ],
344375          "cpe": "cpe:2.3:a:unique-filename:unique-filename:1.1.1:*:*:*:*:*:*:*",
344376          "purl": "pkg:npm/unique-filename@1.1.1",
344377          "swid": {
344378            "attachment": {}
344379          },
344380          "pedigree": {},
344381          "evidence": {},
344382          "signature": {
344383            "signature": {
344384              "publicKey": {}
344385            }
344386          },
344387          "modelCard": {
344388            "modelParameters": {
344389              "approach": {}
344390            },
344391            "quantitativeAnalysis": {
344392              "graphics": {}
344393            },
344394            "considerations": {}
344395          }
344396        },
344397        {
344398          "type": "library",
344399          "bom-ref": "pkg:npm/unique-slug@2.0.2?package-id=dadc7fc5bb4adba3",
344400          "supplier": {},
344401          "name": "unique-slug",
344402          "version": "2.0.2",
344403          "licenses": [
344404            {
344405              "license": {
344406                "id": "ISC"
344407              }
344408            }
344409          ],
344410          "cpe": "cpe:2.3:a:unique-slug:unique-slug:2.0.2:*:*:*:*:*:*:*",
344411          "purl": "pkg:npm/unique-slug@2.0.2",
344412          "swid": {
344413            "attachment": {}
344414          },
344415          "pedigree": {},
344416          "evidence": {},
344417          "signature": {
344418            "signature": {
344419              "publicKey": {}
344420            }
344421          },
344422          "modelCard": {
344423            "modelParameters": {
344424              "approach": {}
344425            },
344426            "quantitativeAnalysis": {
344427              "graphics": {}
344428            },
344429            "considerations": {}
344430          }
344431        },
344432        {
344433          "type": "library",
344434          "bom-ref": "pkg:npm/universal-analytics@0.4.20?package-id=346eeb3f93163e4a",
344435          "supplier": {},
344436          "name": "universal-analytics",
344437          "version": "0.4.20",
344438          "licenses": [
344439            {
344440              "license": {
344441                "id": "MIT"
344442              }
344443            }
344444          ],
344445          "cpe": "cpe:2.3:a:universal-analytics:universal-analytics:0.4.20:*:*:*:*:*:*:*",
344446          "purl": "pkg:npm/universal-analytics@0.4.20",
344447          "swid": {
344448            "attachment": {}
344449          },
344450          "pedigree": {},
344451          "evidence": {},
344452          "signature": {
344453            "signature": {
344454              "publicKey": {}
344455            }
344456          },
344457          "modelCard": {
344458            "modelParameters": {
344459              "approach": {}
344460            },
344461            "quantitativeAnalysis": {
344462              "graphics": {}
344463            },
344464            "considerations": {}
344465          }
344466        },
344467        {
344468          "type": "library",
344469          "bom-ref": "pkg:npm/universalify@0.1.2?package-id=1d4ab21b7015a3d8",
344470          "supplier": {},
344471          "name": "universalify",
344472          "version": "0.1.2",
344473          "cpe": "cpe:2.3:a:universalify:universalify:0.1.2:*:*:*:*:*:*:*",
344474          "purl": "pkg:npm/universalify@0.1.2",
344475          "swid": {
344476            "attachment": {}
344477          },
344478          "pedigree": {},
344479          "evidence": {},
344480          "signature": {
344481            "signature": {
344482              "publicKey": {}
344483            }
344484          },
344485          "modelCard": {
344486            "modelParameters": {
344487              "approach": {}
344488            },
344489            "quantitativeAnalysis": {
344490              "graphics": {}
344491            },
344492            "considerations": {}
344493          }
344494        },
344495        {
344496          "type": "library",
344497          "bom-ref": "pkg:npm/universalify@0.1.2?package-id=7d5822aa41c42a5a",
344498          "supplier": {},
344499          "name": "universalify",
344500          "version": "0.1.2",
344501          "licenses": [
344502            {
344503              "license": {
344504                "id": "MIT"
344505              }
344506            }
344507          ],
344508          "cpe": "cpe:2.3:a:universalify:universalify:0.1.2:*:*:*:*:*:*:*",
344509          "purl": "pkg:npm/universalify@0.1.2",
344510          "swid": {
344511            "attachment": {}
344512          },
344513          "pedigree": {},
344514          "evidence": {},
344515          "signature": {
344516            "signature": {
344517              "publicKey": {}
344518            }
344519          },
344520          "modelCard": {
344521            "modelParameters": {
344522              "approach": {}
344523            },
344524            "quantitativeAnalysis": {
344525              "graphics": {}
344526            },
344527            "considerations": {}
344528          }
344529        },
344530        {
344531          "type": "library",
344532          "bom-ref": "pkg:npm/unpipe@1.0.0?package-id=f078a47603f29069",
344533          "supplier": {},
344534          "name": "unpipe",
344535          "version": "1.0.0",
344536          "licenses": [
344537            {
344538              "license": {
344539                "id": "MIT"
344540              }
344541            }
344542          ],
344543          "cpe": "cpe:2.3:a:unpipe:unpipe:1.0.0:*:*:*:*:*:*:*",
344544          "purl": "pkg:npm/unpipe@1.0.0",
344545          "swid": {
344546            "attachment": {}
344547          },
344548          "pedigree": {},
344549          "evidence": {},
344550          "signature": {
344551            "signature": {
344552              "publicKey": {}
344553            }
344554          },
344555          "modelCard": {
344556            "modelParameters": {
344557              "approach": {}
344558            },
344559            "quantitativeAnalysis": {
344560              "graphics": {}
344561            },
344562            "considerations": {}
344563          }
344564        },
344565        {
344566          "type": "library",
344567          "bom-ref": "pkg:npm/unquote@1.1.1?package-id=7fa8c84c840a7f83",
344568          "supplier": {},
344569          "name": "unquote",
344570          "version": "1.1.1",
344571          "licenses": [
344572            {
344573              "license": {
344574                "id": "MIT"
344575              }
344576            }
344577          ],
344578          "cpe": "cpe:2.3:a:unquote:unquote:1.1.1:*:*:*:*:*:*:*",
344579          "purl": "pkg:npm/unquote@1.1.1",
344580          "swid": {
344581            "attachment": {}
344582          },
344583          "pedigree": {},
344584          "evidence": {},
344585          "signature": {
344586            "signature": {
344587              "publicKey": {}
344588            }
344589          },
344590          "modelCard": {
344591            "modelParameters": {
344592              "approach": {}
344593            },
344594            "quantitativeAnalysis": {
344595              "graphics": {}
344596            },
344597            "considerations": {}
344598          }
344599        },
344600        {
344601          "type": "library",
344602          "bom-ref": "pkg:npm/unset-value@1.0.0?package-id=c8efcbd77f5bc98b",
344603          "supplier": {},
344604          "name": "unset-value",
344605          "version": "1.0.0",
344606          "licenses": [
344607            {
344608              "license": {
344609                "id": "MIT"
344610              }
344611            }
344612          ],
344613          "cpe": "cpe:2.3:a:unset-value:unset-value:1.0.0:*:*:*:*:*:*:*",
344614          "purl": "pkg:npm/unset-value@1.0.0",
344615          "swid": {
344616            "attachment": {}
344617          },
344618          "pedigree": {},
344619          "evidence": {},
344620          "signature": {
344621            "signature": {
344622              "publicKey": {}
344623            }
344624          },
344625          "modelCard": {
344626            "modelParameters": {
344627              "approach": {}
344628            },
344629            "quantitativeAnalysis": {
344630              "graphics": {}
344631            },
344632            "considerations": {}
344633          }
344634        },
344635        {
344636          "type": "library",
344637          "bom-ref": "pkg:npm/upath@1.2.0?package-id=469841a6a0018255",
344638          "supplier": {},
344639          "name": "upath",
344640          "version": "1.2.0",
344641          "licenses": [
344642            {
344643              "license": {
344644                "id": "MIT"
344645              }
344646            }
344647          ],
344648          "cpe": "cpe:2.3:a:upath:upath:1.2.0:*:*:*:*:*:*:*",
344649          "purl": "pkg:npm/upath@1.2.0",
344650          "swid": {
344651            "attachment": {}
344652          },
344653          "pedigree": {},
344654          "evidence": {},
344655          "signature": {
344656            "signature": {
344657              "publicKey": {}
344658            }
344659          },
344660          "modelCard": {
344661            "modelParameters": {
344662              "approach": {}
344663            },
344664            "quantitativeAnalysis": {
344665              "graphics": {}
344666            },
344667            "considerations": {}
344668          }
344669        },
344670        {
344671          "type": "library",
344672          "bom-ref": "pkg:npm/uri-js@4.2.2?package-id=bdb26b64854d360e",
344673          "supplier": {},
344674          "name": "uri-js",
344675          "version": "4.2.2",
344676          "licenses": [
344677            {
344678              "license": {
344679                "id": "BSD-2-Clause"
344680              }
344681            }
344682          ],
344683          "cpe": "cpe:2.3:a:uri-js:uri-js:4.2.2:*:*:*:*:*:*:*",
344684          "purl": "pkg:npm/uri-js@4.2.2",
344685          "swid": {
344686            "attachment": {}
344687          },
344688          "pedigree": {},
344689          "evidence": {},
344690          "signature": {
344691            "signature": {
344692              "publicKey": {}
344693            }
344694          },
344695          "modelCard": {
344696            "modelParameters": {
344697              "approach": {}
344698            },
344699            "quantitativeAnalysis": {
344700              "graphics": {}
344701            },
344702            "considerations": {}
344703          }
344704        },
344705        {
344706          "type": "library",
344707          "bom-ref": "pkg:npm/urix@0.1.0?package-id=17cd96143e718d11",
344708          "supplier": {},
344709          "name": "urix",
344710          "version": "0.1.0",
344711          "licenses": [
344712            {
344713              "license": {
344714                "id": "MIT"
344715              }
344716            }
344717          ],
344718          "cpe": "cpe:2.3:a:urix:urix:0.1.0:*:*:*:*:*:*:*",
344719          "purl": "pkg:npm/urix@0.1.0",
344720          "swid": {
344721            "attachment": {}
344722          },
344723          "pedigree": {},
344724          "evidence": {},
344725          "signature": {
344726            "signature": {
344727              "publicKey": {}
344728            }
344729          },
344730          "modelCard": {
344731            "modelParameters": {
344732              "approach": {}
344733            },
344734            "quantitativeAnalysis": {
344735              "graphics": {}
344736            },
344737            "considerations": {}
344738          }
344739        },
344740        {
344741          "type": "library",
344742          "bom-ref": "pkg:npm/url@0.11.0?package-id=3358c639b38985fd",
344743          "supplier": {},
344744          "name": "url",
344745          "version": "0.11.0",
344746          "licenses": [
344747            {
344748              "license": {
344749                "id": "MIT"
344750              }
344751            }
344752          ],
344753          "cpe": "cpe:2.3:a:url:url:0.11.0:*:*:*:*:*:*:*",
344754          "purl": "pkg:npm/url@0.11.0",
344755          "swid": {
344756            "attachment": {}
344757          },
344758          "pedigree": {},
344759          "evidence": {},
344760          "signature": {
344761            "signature": {
344762              "publicKey": {}
344763            }
344764          },
344765          "modelCard": {
344766            "modelParameters": {
344767              "approach": {}
344768            },
344769            "quantitativeAnalysis": {
344770              "graphics": {}
344771            },
344772            "considerations": {}
344773          }
344774        },
344775        {
344776          "type": "library",
344777          "bom-ref": "pkg:npm/url-parse@1.4.7?package-id=56ce9a8077fe9c82",
344778          "supplier": {},
344779          "name": "url-parse",
344780          "version": "1.4.7",
344781          "licenses": [
344782            {
344783              "license": {
344784                "id": "MIT"
344785              }
344786            }
344787          ],
344788          "cpe": "cpe:2.3:a:url-parse:url-parse:1.4.7:*:*:*:*:*:*:*",
344789          "purl": "pkg:npm/url-parse@1.4.7",
344790          "swid": {
344791            "attachment": {}
344792          },
344793          "pedigree": {},
344794          "evidence": {},
344795          "signature": {
344796            "signature": {
344797              "publicKey": {}
344798            }
344799          },
344800          "modelCard": {
344801            "modelParameters": {
344802              "approach": {}
344803            },
344804            "quantitativeAnalysis": {
344805              "graphics": {}
344806            },
344807            "considerations": {}
344808          }
344809        },
344810        {
344811          "type": "library",
344812          "bom-ref": "pkg:npm/use@3.1.1?package-id=9a007160bb332d13",
344813          "supplier": {},
344814          "name": "use",
344815          "version": "3.1.1",
344816          "licenses": [
344817            {
344818              "license": {
344819                "id": "MIT"
344820              }
344821            }
344822          ],
344823          "cpe": "cpe:2.3:a:use:use:3.1.1:*:*:*:*:*:*:*",
344824          "purl": "pkg:npm/use@3.1.1",
344825          "swid": {
344826            "attachment": {}
344827          },
344828          "pedigree": {},
344829          "evidence": {},
344830          "signature": {
344831            "signature": {
344832              "publicKey": {}
344833            }
344834          },
344835          "modelCard": {
344836            "modelParameters": {
344837              "approach": {}
344838            },
344839            "quantitativeAnalysis": {
344840              "graphics": {}
344841            },
344842            "considerations": {}
344843          }
344844        },
344845        {
344846          "type": "library",
344847          "bom-ref": "pkg:npm/utf8-byte-length@1.0.4?package-id=3c6a5ad65f57c028",
344848          "supplier": {},
344849          "name": "utf8-byte-length",
344850          "version": "1.0.4",
344851          "licenses": [
344852            {
344853              "license": {
344854                "id": "WTFPL"
344855              }
344856            }
344857          ],
344858          "cpe": "cpe:2.3:a:utf8-byte-length:utf8-byte-length:1.0.4:*:*:*:*:*:*:*",
344859          "purl": "pkg:npm/utf8-byte-length@1.0.4",
344860          "swid": {
344861            "attachment": {}
344862          },
344863          "pedigree": {},
344864          "evidence": {},
344865          "signature": {
344866            "signature": {
344867              "publicKey": {}
344868            }
344869          },
344870          "modelCard": {
344871            "modelParameters": {
344872              "approach": {}
344873            },
344874            "quantitativeAnalysis": {
344875              "graphics": {}
344876            },
344877            "considerations": {}
344878          }
344879        },
344880        {
344881          "type": "library",
344882          "bom-ref": "pkg:npm/util@0.11.1?package-id=4ac1679209cb9ade",
344883          "supplier": {},
344884          "name": "util",
344885          "version": "0.11.1",
344886          "licenses": [
344887            {
344888              "license": {
344889                "id": "MIT"
344890              }
344891            }
344892          ],
344893          "cpe": "cpe:2.3:a:util:util:0.11.1:*:*:*:*:*:*:*",
344894          "purl": "pkg:npm/util@0.11.1",
344895          "swid": {
344896            "attachment": {}
344897          },
344898          "pedigree": {},
344899          "evidence": {},
344900          "signature": {
344901            "signature": {
344902              "publicKey": {}
344903            }
344904          },
344905          "modelCard": {
344906            "modelParameters": {
344907              "approach": {}
344908            },
344909            "quantitativeAnalysis": {
344910              "graphics": {}
344911            },
344912            "considerations": {}
344913          }
344914        },
344915        {
344916          "type": "library",
344917          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=9f39f1de5aacfdc1",
344918          "supplier": {},
344919          "name": "util-deprecate",
344920          "version": "1.0.2",
344921          "licenses": [
344922            {
344923              "license": {
344924                "id": "MIT"
344925              }
344926            }
344927          ],
344928          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
344929          "purl": "pkg:npm/util-deprecate@1.0.2",
344930          "swid": {
344931            "attachment": {}
344932          },
344933          "pedigree": {},
344934          "evidence": {},
344935          "signature": {
344936            "signature": {
344937              "publicKey": {}
344938            }
344939          },
344940          "modelCard": {
344941            "modelParameters": {
344942              "approach": {}
344943            },
344944            "quantitativeAnalysis": {
344945              "graphics": {}
344946            },
344947            "considerations": {}
344948          }
344949        },
344950        {
344951          "type": "library",
344952          "bom-ref": "pkg:npm/util-promisify@2.1.0?package-id=3743593500092103",
344953          "supplier": {},
344954          "name": "util-promisify",
344955          "version": "2.1.0",
344956          "licenses": [
344957            {
344958              "license": {
344959                "id": "MIT"
344960              }
344961            }
344962          ],
344963          "cpe": "cpe:2.3:a:util-promisify:util-promisify:2.1.0:*:*:*:*:*:*:*",
344964          "purl": "pkg:npm/util-promisify@2.1.0",
344965          "swid": {
344966            "attachment": {}
344967          },
344968          "pedigree": {},
344969          "evidence": {},
344970          "signature": {
344971            "signature": {
344972              "publicKey": {}
344973            }
344974          },
344975          "modelCard": {
344976            "modelParameters": {
344977              "approach": {}
344978            },
344979            "quantitativeAnalysis": {
344980              "graphics": {}
344981            },
344982            "considerations": {}
344983          }
344984        },
344985        {
344986          "type": "library",
344987          "bom-ref": "pkg:npm/util.promisify@1.0.1?package-id=a6e893d8d569ed31",
344988          "supplier": {},
344989          "name": "util.promisify",
344990          "version": "1.0.1",
344991          "licenses": [
344992            {
344993              "license": {
344994                "id": "MIT"
344995              }
344996            }
344997          ],
344998          "cpe": "cpe:2.3:a:util.promisify:util.promisify:1.0.1:*:*:*:*:*:*:*",
344999          "purl": "pkg:npm/util.promisify@1.0.1",
345000          "swid": {
345001            "attachment": {}
345002          },
345003          "pedigree": {},
345004          "evidence": {},
345005          "signature": {
345006            "signature": {
345007              "publicKey": {}
345008            }
345009          },
345010          "modelCard": {
345011            "modelParameters": {
345012              "approach": {}
345013            },
345014            "quantitativeAnalysis": {
345015              "graphics": {}
345016            },
345017            "considerations": {}
345018          }
345019        },
345020        {
345021          "type": "library",
345022          "bom-ref": "pkg:npm/utils-merge@1.0.1?package-id=a35c86b4b23cd909",
345023          "supplier": {},
345024          "name": "utils-merge",
345025          "version": "1.0.1",
345026          "licenses": [
345027            {
345028              "license": {
345029                "id": "MIT"
345030              }
345031            }
345032          ],
345033          "cpe": "cpe:2.3:a:utils-merge:utils-merge:1.0.1:*:*:*:*:*:*:*",
345034          "purl": "pkg:npm/utils-merge@1.0.1",
345035          "swid": {
345036            "attachment": {}
345037          },
345038          "pedigree": {},
345039          "evidence": {},
345040          "signature": {
345041            "signature": {
345042              "publicKey": {}
345043            }
345044          },
345045          "modelCard": {
345046            "modelParameters": {
345047              "approach": {}
345048            },
345049            "quantitativeAnalysis": {
345050              "graphics": {}
345051            },
345052            "considerations": {}
345053          }
345054        },
345055        {
345056          "type": "library",
345057          "bom-ref": "pkg:npm/uuid@3.4.0?package-id=adda9612fdfbd5e0",
345058          "supplier": {},
345059          "name": "uuid",
345060          "version": "3.4.0",
345061          "cpe": "cpe:2.3:a:uuid:uuid:3.4.0:*:*:*:*:*:*:*",
345062          "purl": "pkg:npm/uuid@3.4.0",
345063          "swid": {
345064            "attachment": {}
345065          },
345066          "pedigree": {},
345067          "evidence": {},
345068          "signature": {
345069            "signature": {
345070              "publicKey": {}
345071            }
345072          },
345073          "modelCard": {
345074            "modelParameters": {
345075              "approach": {}
345076            },
345077            "quantitativeAnalysis": {
345078              "graphics": {}
345079            },
345080            "considerations": {}
345081          }
345082        },
345083        {
345084          "type": "library",
345085          "bom-ref": "pkg:npm/uuid@3.4.0?package-id=526a445e72519ff5",
345086          "supplier": {},
345087          "name": "uuid",
345088          "version": "3.4.0",
345089          "licenses": [
345090            {
345091              "license": {
345092                "id": "MIT"
345093              }
345094            }
345095          ],
345096          "cpe": "cpe:2.3:a:uuid:uuid:3.4.0:*:*:*:*:*:*:*",
345097          "purl": "pkg:npm/uuid@3.4.0",
345098          "swid": {
345099            "attachment": {}
345100          },
345101          "pedigree": {},
345102          "evidence": {},
345103          "signature": {
345104            "signature": {
345105              "publicKey": {}
345106            }
345107          },
345108          "modelCard": {
345109            "modelParameters": {
345110              "approach": {}
345111            },
345112            "quantitativeAnalysis": {
345113              "graphics": {}
345114            },
345115            "considerations": {}
345116          }
345117        },
345118        {
345119          "type": "library",
345120          "bom-ref": "pkg:npm/valid-url@1.0.9?package-id=e5171ec401d801b7",
345121          "supplier": {},
345122          "name": "valid-url",
345123          "version": "1.0.9",
345124          "cpe": "cpe:2.3:a:valid-url:valid-url:1.0.9:*:*:*:*:*:*:*",
345125          "purl": "pkg:npm/valid-url@1.0.9",
345126          "swid": {
345127            "attachment": {}
345128          },
345129          "pedigree": {},
345130          "evidence": {},
345131          "signature": {
345132            "signature": {
345133              "publicKey": {}
345134            }
345135          },
345136          "modelCard": {
345137            "modelParameters": {
345138              "approach": {}
345139            },
345140            "quantitativeAnalysis": {
345141              "graphics": {}
345142            },
345143            "considerations": {}
345144          }
345145        },
345146        {
345147          "type": "library",
345148          "bom-ref": "pkg:npm/validate-npm-package-license@3.0.4?package-id=2f44de4551532c24",
345149          "supplier": {},
345150          "name": "validate-npm-package-license",
345151          "version": "3.0.4",
345152          "licenses": [
345153            {
345154              "license": {
345155                "id": "Apache-2.0"
345156              }
345157            }
345158          ],
345159          "cpe": "cpe:2.3:a:validate-npm-package-license:validate-npm-package-license:3.0.4:*:*:*:*:*:*:*",
345160          "purl": "pkg:npm/validate-npm-package-license@3.0.4",
345161          "swid": {
345162            "attachment": {}
345163          },
345164          "pedigree": {},
345165          "evidence": {},
345166          "signature": {
345167            "signature": {
345168              "publicKey": {}
345169            }
345170          },
345171          "modelCard": {
345172            "modelParameters": {
345173              "approach": {}
345174            },
345175            "quantitativeAnalysis": {
345176              "graphics": {}
345177            },
345178            "considerations": {}
345179          }
345180        },
345181        {
345182          "type": "library",
345183          "bom-ref": "pkg:npm/validate-npm-package-name@3.0.0?package-id=b051bcd8fd49eb5c",
345184          "supplier": {},
345185          "name": "validate-npm-package-name",
345186          "version": "3.0.0",
345187          "licenses": [
345188            {
345189              "license": {
345190                "id": "ISC"
345191              }
345192            }
345193          ],
345194          "cpe": "cpe:2.3:a:validate-npm-package-name:validate-npm-package-name:3.0.0:*:*:*:*:*:*:*",
345195          "purl": "pkg:npm/validate-npm-package-name@3.0.0",
345196          "swid": {
345197            "attachment": {}
345198          },
345199          "pedigree": {},
345200          "evidence": {},
345201          "signature": {
345202            "signature": {
345203              "publicKey": {}
345204            }
345205          },
345206          "modelCard": {
345207            "modelParameters": {
345208              "approach": {}
345209            },
345210            "quantitativeAnalysis": {
345211              "graphics": {}
345212            },
345213            "considerations": {}
345214          }
345215        },
345216        {
345217          "type": "library",
345218          "bom-ref": "pkg:npm/vary@1.1.2?package-id=5cba249fd3455c18",
345219          "supplier": {},
345220          "name": "vary",
345221          "version": "1.1.2",
345222          "licenses": [
345223            {
345224              "license": {
345225                "id": "MIT"
345226              }
345227            }
345228          ],
345229          "cpe": "cpe:2.3:a:vary:vary:1.1.2:*:*:*:*:*:*:*",
345230          "purl": "pkg:npm/vary@1.1.2",
345231          "swid": {
345232            "attachment": {}
345233          },
345234          "pedigree": {},
345235          "evidence": {},
345236          "signature": {
345237            "signature": {
345238              "publicKey": {}
345239            }
345240          },
345241          "modelCard": {
345242            "modelParameters": {
345243              "approach": {}
345244            },
345245            "quantitativeAnalysis": {
345246              "graphics": {}
345247            },
345248            "considerations": {}
345249          }
345250        },
345251        {
345252          "type": "library",
345253          "bom-ref": "pkg:npm/vendors@1.0.4?package-id=25d42f021d2b8e25",
345254          "supplier": {},
345255          "name": "vendors",
345256          "version": "1.0.4",
345257          "licenses": [
345258            {
345259              "license": {
345260                "id": "MIT"
345261              }
345262            }
345263          ],
345264          "cpe": "cpe:2.3:a:vendors:vendors:1.0.4:*:*:*:*:*:*:*",
345265          "purl": "pkg:npm/vendors@1.0.4",
345266          "swid": {
345267            "attachment": {}
345268          },
345269          "pedigree": {},
345270          "evidence": {},
345271          "signature": {
345272            "signature": {
345273              "publicKey": {}
345274            }
345275          },
345276          "modelCard": {
345277            "modelParameters": {
345278              "approach": {}
345279            },
345280            "quantitativeAnalysis": {
345281              "graphics": {}
345282            },
345283            "considerations": {}
345284          }
345285        },
345286        {
345287          "type": "library",
345288          "bom-ref": "pkg:npm/verror@1.10.0?package-id=7d34167865ed5df2",
345289          "supplier": {},
345290          "name": "verror",
345291          "version": "1.10.0",
345292          "licenses": [
345293            {
345294              "license": {
345295                "id": "MIT"
345296              }
345297            }
345298          ],
345299          "cpe": "cpe:2.3:a:verror:verror:1.10.0:*:*:*:*:*:*:*",
345300          "purl": "pkg:npm/verror@1.10.0",
345301          "swid": {
345302            "attachment": {}
345303          },
345304          "pedigree": {},
345305          "evidence": {},
345306          "signature": {
345307            "signature": {
345308              "publicKey": {}
345309            }
345310          },
345311          "modelCard": {
345312            "modelParameters": {
345313              "approach": {}
345314            },
345315            "quantitativeAnalysis": {
345316              "graphics": {}
345317            },
345318            "considerations": {}
345319          }
345320        },
345321        {
345322          "type": "library",
345323          "bom-ref": "pkg:npm/vm-browserify@1.1.2?package-id=c1a04c8848ec7b61",
345324          "supplier": {},
345325          "name": "vm-browserify",
345326          "version": "1.1.2",
345327          "licenses": [
345328            {
345329              "license": {
345330                "id": "MIT"
345331              }
345332            }
345333          ],
345334          "cpe": "cpe:2.3:a:vm-browserify:vm-browserify:1.1.2:*:*:*:*:*:*:*",
345335          "purl": "pkg:npm/vm-browserify@1.1.2",
345336          "swid": {
345337            "attachment": {}
345338          },
345339          "pedigree": {},
345340          "evidence": {},
345341          "signature": {
345342            "signature": {
345343              "publicKey": {}
345344            }
345345          },
345346          "modelCard": {
345347            "modelParameters": {
345348              "approach": {}
345349            },
345350            "quantitativeAnalysis": {
345351              "graphics": {}
345352            },
345353            "considerations": {}
345354          }
345355        },
345356        {
345357          "type": "library",
345358          "bom-ref": "pkg:npm/void-elements@2.0.1?package-id=d9945ea8ffc2d7c7",
345359          "supplier": {},
345360          "name": "void-elements",
345361          "version": "2.0.1",
345362          "licenses": [
345363            {
345364              "license": {
345365                "id": "MIT"
345366              }
345367            }
345368          ],
345369          "cpe": "cpe:2.3:a:void-elements:void-elements:2.0.1:*:*:*:*:*:*:*",
345370          "purl": "pkg:npm/void-elements@2.0.1",
345371          "swid": {
345372            "attachment": {}
345373          },
345374          "pedigree": {},
345375          "evidence": {},
345376          "signature": {
345377            "signature": {
345378              "publicKey": {}
345379            }
345380          },
345381          "modelCard": {
345382            "modelParameters": {
345383              "approach": {}
345384            },
345385            "quantitativeAnalysis": {
345386              "graphics": {}
345387            },
345388            "considerations": {}
345389          }
345390        },
345391        {
345392          "type": "library",
345393          "bom-ref": "pkg:npm/vscode-json-languageservice@3.11.0?package-id=63f5bac078487c13",
345394          "supplier": {},
345395          "name": "vscode-json-languageservice",
345396          "version": "3.11.0",
345397          "licenses": [
345398            {
345399              "license": {
345400                "id": "MIT"
345401              }
345402            }
345403          ],
345404          "cpe": "cpe:2.3:a:vscode-json-languageservice:vscode-json-languageservice:3.11.0:*:*:*:*:*:*:*",
345405          "purl": "pkg:npm/vscode-json-languageservice@3.11.0",
345406          "swid": {
345407            "attachment": {}
345408          },
345409          "pedigree": {},
345410          "evidence": {},
345411          "signature": {
345412            "signature": {
345413              "publicKey": {}
345414            }
345415          },
345416          "modelCard": {
345417            "modelParameters": {
345418              "approach": {}
345419            },
345420            "quantitativeAnalysis": {
345421              "graphics": {}
345422            },
345423            "considerations": {}
345424          }
345425        },
345426        {
345427          "type": "library",
345428          "bom-ref": "pkg:npm/vscode-jsonrpc@4.0.0?package-id=5cce3600f987ab53",
345429          "supplier": {},
345430          "name": "vscode-jsonrpc",
345431          "version": "4.0.0",
345432          "licenses": [
345433            {
345434              "license": {
345435                "id": "MIT"
345436              }
345437            }
345438          ],
345439          "cpe": "cpe:2.3:a:vscode-jsonrpc:vscode-jsonrpc:4.0.0:*:*:*:*:*:*:*",
345440          "purl": "pkg:npm/vscode-jsonrpc@4.0.0",
345441          "swid": {
345442            "attachment": {}
345443          },
345444          "pedigree": {},
345445          "evidence": {},
345446          "signature": {
345447            "signature": {
345448              "publicKey": {}
345449            }
345450          },
345451          "modelCard": {
345452            "modelParameters": {
345453              "approach": {}
345454            },
345455            "quantitativeAnalysis": {
345456              "graphics": {}
345457            },
345458            "considerations": {}
345459          }
345460        },
345461        {
345462          "type": "library",
345463          "bom-ref": "pkg:npm/vscode-languageserver@5.2.1?package-id=fc0fc9f558e4ac0e",
345464          "supplier": {},
345465          "name": "vscode-languageserver",
345466          "version": "5.2.1",
345467          "licenses": [
345468            {
345469              "license": {
345470                "id": "MIT"
345471              }
345472            }
345473          ],
345474          "cpe": "cpe:2.3:a:vscode-languageserver:vscode-languageserver:5.2.1:*:*:*:*:*:*:*",
345475          "purl": "pkg:npm/vscode-languageserver@5.2.1",
345476          "swid": {
345477            "attachment": {}
345478          },
345479          "pedigree": {},
345480          "evidence": {},
345481          "signature": {
345482            "signature": {
345483              "publicKey": {}
345484            }
345485          },
345486          "modelCard": {
345487            "modelParameters": {
345488              "approach": {}
345489            },
345490            "quantitativeAnalysis": {
345491              "graphics": {}
345492            },
345493            "considerations": {}
345494          }
345495        },
345496        {
345497          "type": "library",
345498          "bom-ref": "pkg:npm/vscode-languageserver-protocol@3.14.1?package-id=db0a6589a566e4d9",
345499          "supplier": {},
345500          "name": "vscode-languageserver-protocol",
345501          "version": "3.14.1",
345502          "licenses": [
345503            {
345504              "license": {
345505                "id": "MIT"
345506              }
345507            }
345508          ],
345509          "cpe": "cpe:2.3:a:vscode-languageserver-protocol:vscode-languageserver-protocol:3.14.1:*:*:*:*:*:*:*",
345510          "purl": "pkg:npm/vscode-languageserver-protocol@3.14.1",
345511          "swid": {
345512            "attachment": {}
345513          },
345514          "pedigree": {},
345515          "evidence": {},
345516          "signature": {
345517            "signature": {
345518              "publicKey": {}
345519            }
345520          },
345521          "modelCard": {
345522            "modelParameters": {
345523              "approach": {}
345524            },
345525            "quantitativeAnalysis": {
345526              "graphics": {}
345527            },
345528            "considerations": {}
345529          }
345530        },
345531        {
345532          "type": "library",
345533          "bom-ref": "pkg:npm/vscode-languageserver-textdocument@1.0.8?package-id=5a3f417d6261c4f2",
345534          "supplier": {},
345535          "name": "vscode-languageserver-textdocument",
345536          "version": "1.0.8",
345537          "licenses": [
345538            {
345539              "license": {
345540                "id": "MIT"
345541              }
345542            }
345543          ],
345544          "cpe": "cpe:2.3:a:vscode-languageserver-textdocument:vscode-languageserver-textdocument:1.0.8:*:*:*:*:*:*:*",
345545          "purl": "pkg:npm/vscode-languageserver-textdocument@1.0.8",
345546          "swid": {
345547            "attachment": {}
345548          },
345549          "pedigree": {},
345550          "evidence": {},
345551          "signature": {
345552            "signature": {
345553              "publicKey": {}
345554            }
345555          },
345556          "modelCard": {
345557            "modelParameters": {
345558              "approach": {}
345559            },
345560            "quantitativeAnalysis": {
345561              "graphics": {}
345562            },
345563            "considerations": {}
345564          }
345565        },
345566        {
345567          "type": "library",
345568          "bom-ref": "pkg:npm/vscode-languageserver-types@3.16.0-next.2?package-id=daeb3cb12a924d55",
345569          "supplier": {},
345570          "name": "vscode-languageserver-types",
345571          "version": "3.16.0-next.2",
345572          "licenses": [
345573            {
345574              "license": {
345575                "id": "MIT"
345576              }
345577            }
345578          ],
345579          "cpe": "cpe:2.3:a:vscode-languageserver-types:vscode-languageserver-types:3.16.0-next.2:*:*:*:*:*:*:*",
345580          "purl": "pkg:npm/vscode-languageserver-types@3.16.0-next.2",
345581          "swid": {
345582            "attachment": {}
345583          },
345584          "pedigree": {},
345585          "evidence": {},
345586          "signature": {
345587            "signature": {
345588              "publicKey": {}
345589            }
345590          },
345591          "modelCard": {
345592            "modelParameters": {
345593              "approach": {}
345594            },
345595            "quantitativeAnalysis": {
345596              "graphics": {}
345597            },
345598            "considerations": {}
345599          }
345600        },
345601        {
345602          "type": "library",
345603          "bom-ref": "pkg:npm/vscode-nls@5.2.0?package-id=89db238ca76e249e",
345604          "supplier": {},
345605          "name": "vscode-nls",
345606          "version": "5.2.0",
345607          "licenses": [
345608            {
345609              "license": {
345610                "id": "MIT"
345611              }
345612            }
345613          ],
345614          "cpe": "cpe:2.3:a:vscode-nls:vscode-nls:5.2.0:*:*:*:*:*:*:*",
345615          "purl": "pkg:npm/vscode-nls@5.2.0",
345616          "swid": {
345617            "attachment": {}
345618          },
345619          "pedigree": {},
345620          "evidence": {},
345621          "signature": {
345622            "signature": {
345623              "publicKey": {}
345624            }
345625          },
345626          "modelCard": {
345627            "modelParameters": {
345628              "approach": {}
345629            },
345630            "quantitativeAnalysis": {
345631              "graphics": {}
345632            },
345633            "considerations": {}
345634          }
345635        },
345636        {
345637          "type": "library",
345638          "bom-ref": "pkg:npm/vscode-uri@2.1.2?package-id=4ad50ec5691d9ca7",
345639          "supplier": {},
345640          "name": "vscode-uri",
345641          "version": "2.1.2",
345642          "licenses": [
345643            {
345644              "license": {
345645                "id": "MIT"
345646              }
345647            }
345648          ],
345649          "cpe": "cpe:2.3:a:vscode-uri:vscode-uri:2.1.2:*:*:*:*:*:*:*",
345650          "purl": "pkg:npm/vscode-uri@2.1.2",
345651          "swid": {
345652            "attachment": {}
345653          },
345654          "pedigree": {},
345655          "evidence": {},
345656          "signature": {
345657            "signature": {
345658              "publicKey": {}
345659            }
345660          },
345661          "modelCard": {
345662            "modelParameters": {
345663              "approach": {}
345664            },
345665            "quantitativeAnalysis": {
345666              "graphics": {}
345667            },
345668            "considerations": {}
345669          }
345670        },
345671        {
345672          "type": "library",
345673          "bom-ref": "pkg:npm/watchpack@1.6.1?package-id=6572d5b09c0aeb93",
345674          "supplier": {},
345675          "name": "watchpack",
345676          "version": "1.6.1",
345677          "licenses": [
345678            {
345679              "license": {
345680                "id": "MIT"
345681              }
345682            }
345683          ],
345684          "cpe": "cpe:2.3:a:watchpack:watchpack:1.6.1:*:*:*:*:*:*:*",
345685          "purl": "pkg:npm/watchpack@1.6.1",
345686          "swid": {
345687            "attachment": {}
345688          },
345689          "pedigree": {},
345690          "evidence": {},
345691          "signature": {
345692            "signature": {
345693              "publicKey": {}
345694            }
345695          },
345696          "modelCard": {
345697            "modelParameters": {
345698              "approach": {}
345699            },
345700            "quantitativeAnalysis": {
345701              "graphics": {}
345702            },
345703            "considerations": {}
345704          }
345705        },
345706        {
345707          "type": "library",
345708          "bom-ref": "pkg:npm/wbuf@1.7.3?package-id=ffefb1f942a74ca8",
345709          "supplier": {},
345710          "name": "wbuf",
345711          "version": "1.7.3",
345712          "licenses": [
345713            {
345714              "license": {
345715                "id": "MIT"
345716              }
345717            }
345718          ],
345719          "cpe": "cpe:2.3:a:wbuf:wbuf:1.7.3:*:*:*:*:*:*:*",
345720          "purl": "pkg:npm/wbuf@1.7.3",
345721          "swid": {
345722            "attachment": {}
345723          },
345724          "pedigree": {},
345725          "evidence": {},
345726          "signature": {
345727            "signature": {
345728              "publicKey": {}
345729            }
345730          },
345731          "modelCard": {
345732            "modelParameters": {
345733              "approach": {}
345734            },
345735            "quantitativeAnalysis": {
345736              "graphics": {}
345737            },
345738            "considerations": {}
345739          }
345740        },
345741        {
345742          "type": "library",
345743          "bom-ref": "pkg:npm/wcwidth@1.0.1?package-id=4f1f480301e68521",
345744          "supplier": {},
345745          "name": "wcwidth",
345746          "version": "1.0.1",
345747          "licenses": [
345748            {
345749              "license": {
345750                "id": "MIT"
345751              }
345752            }
345753          ],
345754          "cpe": "cpe:2.3:a:wcwidth:wcwidth:1.0.1:*:*:*:*:*:*:*",
345755          "purl": "pkg:npm/wcwidth@1.0.1",
345756          "swid": {
345757            "attachment": {}
345758          },
345759          "pedigree": {},
345760          "evidence": {},
345761          "signature": {
345762            "signature": {
345763              "publicKey": {}
345764            }
345765          },
345766          "modelCard": {
345767            "modelParameters": {
345768              "approach": {}
345769            },
345770            "quantitativeAnalysis": {
345771              "graphics": {}
345772            },
345773            "considerations": {}
345774          }
345775        },
345776        {
345777          "type": "library",
345778          "bom-ref": "pkg:npm/webdriver-js-extender@2.1.0?package-id=c59c1ca78d4de866",
345779          "supplier": {},
345780          "name": "webdriver-js-extender",
345781          "version": "2.1.0",
345782          "licenses": [
345783            {
345784              "license": {
345785                "id": "MIT"
345786              }
345787            }
345788          ],
345789          "cpe": "cpe:2.3:a:webdriver-js-extender:webdriver-js-extender:2.1.0:*:*:*:*:*:*:*",
345790          "purl": "pkg:npm/webdriver-js-extender@2.1.0",
345791          "swid": {
345792            "attachment": {}
345793          },
345794          "pedigree": {},
345795          "evidence": {},
345796          "signature": {
345797            "signature": {
345798              "publicKey": {}
345799            }
345800          },
345801          "modelCard": {
345802            "modelParameters": {
345803              "approach": {}
345804            },
345805            "quantitativeAnalysis": {
345806              "graphics": {}
345807            },
345808            "considerations": {}
345809          }
345810        },
345811        {
345812          "type": "library",
345813          "bom-ref": "pkg:npm/webpack@4.42.0?package-id=d87224f9c91bfbcc",
345814          "supplier": {},
345815          "name": "webpack",
345816          "version": "4.42.0",
345817          "licenses": [
345818            {
345819              "license": {
345820                "id": "MIT"
345821              }
345822            }
345823          ],
345824          "cpe": "cpe:2.3:a:webpack:webpack:4.42.0:*:*:*:*:*:*:*",
345825          "purl": "pkg:npm/webpack@4.42.0",
345826          "swid": {
345827            "attachment": {}
345828          },
345829          "pedigree": {},
345830          "evidence": {},
345831          "signature": {
345832            "signature": {
345833              "publicKey": {}
345834            }
345835          },
345836          "modelCard": {
345837            "modelParameters": {
345838              "approach": {}
345839            },
345840            "quantitativeAnalysis": {
345841              "graphics": {}
345842            },
345843            "considerations": {}
345844          }
345845        },
345846        {
345847          "type": "library",
345848          "bom-ref": "pkg:npm/webpack-bundle-analyzer@3.7.0?package-id=c9c9605700bed457",
345849          "supplier": {},
345850          "name": "webpack-bundle-analyzer",
345851          "version": "3.7.0",
345852          "licenses": [
345853            {
345854              "license": {
345855                "id": "MIT"
345856              }
345857            }
345858          ],
345859          "cpe": "cpe:2.3:a:webpack-bundle-analyzer:webpack-bundle-analyzer:3.7.0:*:*:*:*:*:*:*",
345860          "purl": "pkg:npm/webpack-bundle-analyzer@3.7.0",
345861          "swid": {
345862            "attachment": {}
345863          },
345864          "pedigree": {},
345865          "evidence": {},
345866          "signature": {
345867            "signature": {
345868              "publicKey": {}
345869            }
345870          },
345871          "modelCard": {
345872            "modelParameters": {
345873              "approach": {}
345874            },
345875            "quantitativeAnalysis": {
345876              "graphics": {}
345877            },
345878            "considerations": {}
345879          }
345880        },
345881        {
345882          "type": "library",
345883          "bom-ref": "pkg:npm/webpack-dev-middleware@3.7.2?package-id=be5e79fa0667a363",
345884          "supplier": {},
345885          "name": "webpack-dev-middleware",
345886          "version": "3.7.2",
345887          "licenses": [
345888            {
345889              "license": {
345890                "id": "MIT"
345891              }
345892            }
345893          ],
345894          "cpe": "cpe:2.3:a:webpack-dev-middleware:webpack-dev-middleware:3.7.2:*:*:*:*:*:*:*",
345895          "purl": "pkg:npm/webpack-dev-middleware@3.7.2",
345896          "swid": {
345897            "attachment": {}
345898          },
345899          "pedigree": {},
345900          "evidence": {},
345901          "signature": {
345902            "signature": {
345903              "publicKey": {}
345904            }
345905          },
345906          "modelCard": {
345907            "modelParameters": {
345908              "approach": {}
345909            },
345910            "quantitativeAnalysis": {
345911              "graphics": {}
345912            },
345913            "considerations": {}
345914          }
345915        },
345916        {
345917          "type": "library",
345918          "bom-ref": "pkg:npm/webpack-dev-server@3.10.3?package-id=80df98f57af988bd",
345919          "supplier": {},
345920          "name": "webpack-dev-server",
345921          "version": "3.10.3",
345922          "licenses": [
345923            {
345924              "license": {
345925                "id": "MIT"
345926              }
345927            }
345928          ],
345929          "cpe": "cpe:2.3:a:webpack-dev-server:webpack-dev-server:3.10.3:*:*:*:*:*:*:*",
345930          "purl": "pkg:npm/webpack-dev-server@3.10.3",
345931          "swid": {
345932            "attachment": {}
345933          },
345934          "pedigree": {},
345935          "evidence": {},
345936          "signature": {
345937            "signature": {
345938              "publicKey": {}
345939            }
345940          },
345941          "modelCard": {
345942            "modelParameters": {
345943              "approach": {}
345944            },
345945            "quantitativeAnalysis": {
345946              "graphics": {}
345947            },
345948            "considerations": {}
345949          }
345950        },
345951        {
345952          "type": "library",
345953          "bom-ref": "pkg:npm/webpack-log@2.0.0?package-id=bfc1be3e83b857d7",
345954          "supplier": {},
345955          "name": "webpack-log",
345956          "version": "2.0.0",
345957          "licenses": [
345958            {
345959              "license": {
345960                "id": "MIT"
345961              }
345962            }
345963          ],
345964          "cpe": "cpe:2.3:a:webpack-log:webpack-log:2.0.0:*:*:*:*:*:*:*",
345965          "purl": "pkg:npm/webpack-log@2.0.0",
345966          "swid": {
345967            "attachment": {}
345968          },
345969          "pedigree": {},
345970          "evidence": {},
345971          "signature": {
345972            "signature": {
345973              "publicKey": {}
345974            }
345975          },
345976          "modelCard": {
345977            "modelParameters": {
345978              "approach": {}
345979            },
345980            "quantitativeAnalysis": {
345981              "graphics": {}
345982            },
345983            "considerations": {}
345984          }
345985        },
345986        {
345987          "type": "library",
345988          "bom-ref": "pkg:npm/webpack-merge@4.2.2?package-id=d5d5404110191779",
345989          "supplier": {},
345990          "name": "webpack-merge",
345991          "version": "4.2.2",
345992          "licenses": [
345993            {
345994              "license": {
345995                "id": "MIT"
345996              }
345997            }
345998          ],
345999          "cpe": "cpe:2.3:a:webpack-merge:webpack-merge:4.2.2:*:*:*:*:*:*:*",
346000          "purl": "pkg:npm/webpack-merge@4.2.2",
346001          "swid": {
346002            "attachment": {}
346003          },
346004          "pedigree": {},
346005          "evidence": {},
346006          "signature": {
346007            "signature": {
346008              "publicKey": {}
346009            }
346010          },
346011          "modelCard": {
346012            "modelParameters": {
346013              "approach": {}
346014            },
346015            "quantitativeAnalysis": {
346016              "graphics": {}
346017            },
346018            "considerations": {}
346019          }
346020        },
346021        {
346022          "type": "library",
346023          "bom-ref": "pkg:npm/webpack-sources@1.4.3?package-id=7ab8848da0705aa6",
346024          "supplier": {},
346025          "name": "webpack-sources",
346026          "version": "1.4.3",
346027          "licenses": [
346028            {
346029              "license": {
346030                "id": "MIT"
346031              }
346032            }
346033          ],
346034          "cpe": "cpe:2.3:a:webpack-sources:webpack-sources:1.4.3:*:*:*:*:*:*:*",
346035          "purl": "pkg:npm/webpack-sources@1.4.3",
346036          "swid": {
346037            "attachment": {}
346038          },
346039          "pedigree": {},
346040          "evidence": {},
346041          "signature": {
346042            "signature": {
346043              "publicKey": {}
346044            }
346045          },
346046          "modelCard": {
346047            "modelParameters": {
346048              "approach": {}
346049            },
346050            "quantitativeAnalysis": {
346051              "graphics": {}
346052            },
346053            "considerations": {}
346054          }
346055        },
346056        {
346057          "type": "library",
346058          "bom-ref": "pkg:npm/webpack-subresource-integrity@1.4.0?package-id=5ee874d0acd57e26",
346059          "supplier": {},
346060          "name": "webpack-subresource-integrity",
346061          "version": "1.4.0",
346062          "licenses": [
346063            {
346064              "license": {
346065                "id": "MIT"
346066              }
346067            }
346068          ],
346069          "cpe": "cpe:2.3:a:webpack-subresource-integrity:webpack-subresource-integrity:1.4.0:*:*:*:*:*:*:*",
346070          "purl": "pkg:npm/webpack-subresource-integrity@1.4.0",
346071          "swid": {
346072            "attachment": {}
346073          },
346074          "pedigree": {},
346075          "evidence": {},
346076          "signature": {
346077            "signature": {
346078              "publicKey": {}
346079            }
346080          },
346081          "modelCard": {
346082            "modelParameters": {
346083              "approach": {}
346084            },
346085            "quantitativeAnalysis": {
346086              "graphics": {}
346087            },
346088            "considerations": {}
346089          }
346090        },
346091        {
346092          "type": "library",
346093          "bom-ref": "pkg:npm/websocket-driver@0.7.3?package-id=df09dd834ce5545b",
346094          "supplier": {},
346095          "name": "websocket-driver",
346096          "version": "0.7.3",
346097          "licenses": [
346098            {
346099              "license": {
346100                "id": "Apache-2.0"
346101              }
346102            }
346103          ],
346104          "cpe": "cpe:2.3:a:websocket-driver:websocket-driver:0.7.3:*:*:*:*:*:*:*",
346105          "purl": "pkg:npm/websocket-driver@0.7.3",
346106          "swid": {
346107            "attachment": {}
346108          },
346109          "pedigree": {},
346110          "evidence": {},
346111          "signature": {
346112            "signature": {
346113              "publicKey": {}
346114            }
346115          },
346116          "modelCard": {
346117            "modelParameters": {
346118              "approach": {}
346119            },
346120            "quantitativeAnalysis": {
346121              "graphics": {}
346122            },
346123            "considerations": {}
346124          }
346125        },
346126        {
346127          "type": "library",
346128          "bom-ref": "pkg:npm/websocket-extensions@0.1.3?package-id=61a75f670f245c1c",
346129          "supplier": {},
346130          "name": "websocket-extensions",
346131          "version": "0.1.3",
346132          "licenses": [
346133            {
346134              "license": {
346135                "id": "MIT"
346136              }
346137            }
346138          ],
346139          "cpe": "cpe:2.3:a:websocket-extensions:websocket-extensions:0.1.3:*:*:*:*:*:*:*",
346140          "purl": "pkg:npm/websocket-extensions@0.1.3",
346141          "swid": {
346142            "attachment": {}
346143          },
346144          "pedigree": {},
346145          "evidence": {},
346146          "signature": {
346147            "signature": {
346148              "publicKey": {}
346149            }
346150          },
346151          "modelCard": {
346152            "modelParameters": {
346153              "approach": {}
346154            },
346155            "quantitativeAnalysis": {
346156              "graphics": {}
346157            },
346158            "considerations": {}
346159          }
346160        },
346161        {
346162          "type": "library",
346163          "bom-ref": "pkg:npm/when@3.6.4?package-id=762ab53968652324",
346164          "supplier": {},
346165          "name": "when",
346166          "version": "3.6.4",
346167          "licenses": [
346168            {
346169              "license": {
346170                "id": "MIT"
346171              }
346172            }
346173          ],
346174          "cpe": "cpe:2.3:a:when:when:3.6.4:*:*:*:*:*:*:*",
346175          "purl": "pkg:npm/when@3.6.4",
346176          "swid": {
346177            "attachment": {}
346178          },
346179          "pedigree": {},
346180          "evidence": {},
346181          "signature": {
346182            "signature": {
346183              "publicKey": {}
346184            }
346185          },
346186          "modelCard": {
346187            "modelParameters": {
346188              "approach": {}
346189            },
346190            "quantitativeAnalysis": {
346191              "graphics": {}
346192            },
346193            "considerations": {}
346194          }
346195        },
346196        {
346197          "type": "library",
346198          "bom-ref": "pkg:npm/which@1.3.1?package-id=c6dc767d8b803349",
346199          "supplier": {},
346200          "name": "which",
346201          "version": "1.3.1",
346202          "licenses": [
346203            {
346204              "license": {
346205                "id": "ISC"
346206              }
346207            }
346208          ],
346209          "cpe": "cpe:2.3:a:which:which:1.3.1:*:*:*:*:*:*:*",
346210          "purl": "pkg:npm/which@1.3.1",
346211          "swid": {
346212            "attachment": {}
346213          },
346214          "pedigree": {},
346215          "evidence": {},
346216          "signature": {
346217            "signature": {
346218              "publicKey": {}
346219            }
346220          },
346221          "modelCard": {
346222            "modelParameters": {
346223              "approach": {}
346224            },
346225            "quantitativeAnalysis": {
346226              "graphics": {}
346227            },
346228            "considerations": {}
346229          }
346230        },
346231        {
346232          "type": "library",
346233          "bom-ref": "pkg:npm/which@2.0.2?package-id=716f72eb7e276298",
346234          "supplier": {},
346235          "name": "which",
346236          "version": "2.0.2",
346237          "cpe": "cpe:2.3:a:which:which:2.0.2:*:*:*:*:*:*:*",
346238          "purl": "pkg:npm/which@2.0.2",
346239          "swid": {
346240            "attachment": {}
346241          },
346242          "pedigree": {},
346243          "evidence": {},
346244          "signature": {
346245            "signature": {
346246              "publicKey": {}
346247            }
346248          },
346249          "modelCard": {
346250            "modelParameters": {
346251              "approach": {}
346252            },
346253            "quantitativeAnalysis": {
346254              "graphics": {}
346255            },
346256            "considerations": {}
346257          }
346258        },
346259        {
346260          "type": "library",
346261          "bom-ref": "pkg:npm/which-module@2.0.0?package-id=2c95a66942473455",
346262          "supplier": {},
346263          "name": "which-module",
346264          "version": "2.0.0",
346265          "cpe": "cpe:2.3:a:which-module:which-module:2.0.0:*:*:*:*:*:*:*",
346266          "purl": "pkg:npm/which-module@2.0.0",
346267          "swid": {
346268            "attachment": {}
346269          },
346270          "pedigree": {},
346271          "evidence": {},
346272          "signature": {
346273            "signature": {
346274              "publicKey": {}
346275            }
346276          },
346277          "modelCard": {
346278            "modelParameters": {
346279              "approach": {}
346280            },
346281            "quantitativeAnalysis": {
346282              "graphics": {}
346283            },
346284            "considerations": {}
346285          }
346286        },
346287        {
346288          "type": "library",
346289          "bom-ref": "pkg:npm/which-module@2.0.0?package-id=c1c927273bfbdd31",
346290          "supplier": {},
346291          "name": "which-module",
346292          "version": "2.0.0",
346293          "licenses": [
346294            {
346295              "license": {
346296                "id": "ISC"
346297              }
346298            }
346299          ],
346300          "cpe": "cpe:2.3:a:which-module:which-module:2.0.0:*:*:*:*:*:*:*",
346301          "purl": "pkg:npm/which-module@2.0.0",
346302          "swid": {
346303            "attachment": {}
346304          },
346305          "pedigree": {},
346306          "evidence": {},
346307          "signature": {
346308            "signature": {
346309              "publicKey": {}
346310            }
346311          },
346312          "modelCard": {
346313            "modelParameters": {
346314              "approach": {}
346315            },
346316            "quantitativeAnalysis": {
346317              "graphics": {}
346318            },
346319            "considerations": {}
346320          }
346321        },
346322        {
346323          "type": "library",
346324          "bom-ref": "pkg:npm/wide-align@1.1.3?package-id=2711dcb2b1321f1f",
346325          "supplier": {},
346326          "name": "wide-align",
346327          "version": "1.1.3",
346328          "licenses": [
346329            {
346330              "license": {
346331                "id": "ISC"
346332              }
346333            }
346334          ],
346335          "cpe": "cpe:2.3:a:wide-align:wide-align:1.1.3:*:*:*:*:*:*:*",
346336          "purl": "pkg:npm/wide-align@1.1.3",
346337          "swid": {
346338            "attachment": {}
346339          },
346340          "pedigree": {},
346341          "evidence": {},
346342          "signature": {
346343            "signature": {
346344              "publicKey": {}
346345            }
346346          },
346347          "modelCard": {
346348            "modelParameters": {
346349              "approach": {}
346350            },
346351            "quantitativeAnalysis": {
346352              "graphics": {}
346353            },
346354            "considerations": {}
346355          }
346356        },
346357        {
346358          "type": "library",
346359          "bom-ref": "pkg:npm/wordwrap@0.0.3?package-id=d963e67273277de5",
346360          "supplier": {},
346361          "name": "wordwrap",
346362          "version": "0.0.3",
346363          "licenses": [
346364            {
346365              "license": {
346366                "id": "MIT"
346367              }
346368            }
346369          ],
346370          "cpe": "cpe:2.3:a:wordwrap:wordwrap:0.0.3:*:*:*:*:*:*:*",
346371          "purl": "pkg:npm/wordwrap@0.0.3",
346372          "swid": {
346373            "attachment": {}
346374          },
346375          "pedigree": {},
346376          "evidence": {},
346377          "signature": {
346378            "signature": {
346379              "publicKey": {}
346380            }
346381          },
346382          "modelCard": {
346383            "modelParameters": {
346384              "approach": {}
346385            },
346386            "quantitativeAnalysis": {
346387              "graphics": {}
346388            },
346389            "considerations": {}
346390          }
346391        },
346392        {
346393          "type": "library",
346394          "bom-ref": "pkg:npm/worker-farm@1.7.0?package-id=ae14fe475961d31f",
346395          "supplier": {},
346396          "name": "worker-farm",
346397          "version": "1.7.0",
346398          "licenses": [
346399            {
346400              "license": {
346401                "id": "MIT"
346402              }
346403            }
346404          ],
346405          "cpe": "cpe:2.3:a:worker-farm:worker-farm:1.7.0:*:*:*:*:*:*:*",
346406          "purl": "pkg:npm/worker-farm@1.7.0",
346407          "swid": {
346408            "attachment": {}
346409          },
346410          "pedigree": {},
346411          "evidence": {},
346412          "signature": {
346413            "signature": {
346414              "publicKey": {}
346415            }
346416          },
346417          "modelCard": {
346418            "modelParameters": {
346419              "approach": {}
346420            },
346421            "quantitativeAnalysis": {
346422              "graphics": {}
346423            },
346424            "considerations": {}
346425          }
346426        },
346427        {
346428          "type": "library",
346429          "bom-ref": "pkg:npm/worker-plugin@4.0.3?package-id=c1d543d41d9df883",
346430          "supplier": {},
346431          "name": "worker-plugin",
346432          "version": "4.0.3",
346433          "licenses": [
346434            {
346435              "license": {
346436                "id": "Apache-2.0"
346437              }
346438            }
346439          ],
346440          "cpe": "cpe:2.3:a:worker-plugin:worker-plugin:4.0.3:*:*:*:*:*:*:*",
346441          "purl": "pkg:npm/worker-plugin@4.0.3",
346442          "swid": {
346443            "attachment": {}
346444          },
346445          "pedigree": {},
346446          "evidence": {},
346447          "signature": {
346448            "signature": {
346449              "publicKey": {}
346450            }
346451          },
346452          "modelCard": {
346453            "modelParameters": {
346454              "approach": {}
346455            },
346456            "quantitativeAnalysis": {
346457              "graphics": {}
346458            },
346459            "considerations": {}
346460          }
346461        },
346462        {
346463          "type": "library",
346464          "bom-ref": "pkg:npm/wrap-ansi@2.1.0?package-id=8cf1ed916be4346d",
346465          "supplier": {},
346466          "name": "wrap-ansi",
346467          "version": "2.1.0",
346468          "licenses": [
346469            {
346470              "license": {
346471                "id": "MIT"
346472              }
346473            }
346474          ],
346475          "cpe": "cpe:2.3:a:wrap-ansi:wrap-ansi:2.1.0:*:*:*:*:*:*:*",
346476          "purl": "pkg:npm/wrap-ansi@2.1.0",
346477          "swid": {
346478            "attachment": {}
346479          },
346480          "pedigree": {},
346481          "evidence": {},
346482          "signature": {
346483            "signature": {
346484              "publicKey": {}
346485            }
346486          },
346487          "modelCard": {
346488            "modelParameters": {
346489              "approach": {}
346490            },
346491            "quantitativeAnalysis": {
346492              "graphics": {}
346493            },
346494            "considerations": {}
346495          }
346496        },
346497        {
346498          "type": "library",
346499          "bom-ref": "pkg:npm/wrap-ansi@6.2.0?package-id=52d9dd08ad02c54d",
346500          "supplier": {},
346501          "name": "wrap-ansi",
346502          "version": "6.2.0",
346503          "cpe": "cpe:2.3:a:wrap-ansi:wrap-ansi:6.2.0:*:*:*:*:*:*:*",
346504          "purl": "pkg:npm/wrap-ansi@6.2.0",
346505          "swid": {
346506            "attachment": {}
346507          },
346508          "pedigree": {},
346509          "evidence": {},
346510          "signature": {
346511            "signature": {
346512              "publicKey": {}
346513            }
346514          },
346515          "modelCard": {
346516            "modelParameters": {
346517              "approach": {}
346518            },
346519            "quantitativeAnalysis": {
346520              "graphics": {}
346521            },
346522            "considerations": {}
346523          }
346524        },
346525        {
346526          "type": "library",
346527          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=1d6c164011bb8f76",
346528          "supplier": {},
346529          "name": "wrappy",
346530          "version": "1.0.2",
346531          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
346532          "purl": "pkg:npm/wrappy@1.0.2",
346533          "swid": {
346534            "attachment": {}
346535          },
346536          "pedigree": {},
346537          "evidence": {},
346538          "signature": {
346539            "signature": {
346540              "publicKey": {}
346541            }
346542          },
346543          "modelCard": {
346544            "modelParameters": {
346545              "approach": {}
346546            },
346547            "quantitativeAnalysis": {
346548              "graphics": {}
346549            },
346550            "considerations": {}
346551          }
346552        },
346553        {
346554          "type": "library",
346555          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=dd6d0718da9fb963",
346556          "supplier": {},
346557          "name": "wrappy",
346558          "version": "1.0.2",
346559          "licenses": [
346560            {
346561              "license": {
346562                "id": "ISC"
346563              }
346564            }
346565          ],
346566          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
346567          "purl": "pkg:npm/wrappy@1.0.2",
346568          "swid": {
346569            "attachment": {}
346570          },
346571          "pedigree": {},
346572          "evidence": {},
346573          "signature": {
346574            "signature": {
346575              "publicKey": {}
346576            }
346577          },
346578          "modelCard": {
346579            "modelParameters": {
346580              "approach": {}
346581            },
346582            "quantitativeAnalysis": {
346583              "graphics": {}
346584            },
346585            "considerations": {}
346586          }
346587        },
346588        {
346589          "type": "library",
346590          "bom-ref": "pkg:npm/write-file-atomic@3.0.3?package-id=964b80b9a38726d9",
346591          "supplier": {},
346592          "name": "write-file-atomic",
346593          "version": "3.0.3",
346594          "cpe": "cpe:2.3:a:write-file-atomic:write-file-atomic:3.0.3:*:*:*:*:*:*:*",
346595          "purl": "pkg:npm/write-file-atomic@3.0.3",
346596          "swid": {
346597            "attachment": {}
346598          },
346599          "pedigree": {},
346600          "evidence": {},
346601          "signature": {
346602            "signature": {
346603              "publicKey": {}
346604            }
346605          },
346606          "modelCard": {
346607            "modelParameters": {
346608              "approach": {}
346609            },
346610            "quantitativeAnalysis": {
346611              "graphics": {}
346612            },
346613            "considerations": {}
346614          }
346615        },
346616        {
346617          "type": "library",
346618          "bom-ref": "pkg:npm/ws@6.2.1?package-id=f5aea639e59cdd77",
346619          "supplier": {},
346620          "name": "ws",
346621          "version": "6.2.1",
346622          "licenses": [
346623            {
346624              "license": {
346625                "id": "MIT"
346626              }
346627            }
346628          ],
346629          "cpe": "cpe:2.3:a:ws:ws:6.2.1:*:*:*:*:*:*:*",
346630          "purl": "pkg:npm/ws@6.2.1",
346631          "swid": {
346632            "attachment": {}
346633          },
346634          "pedigree": {},
346635          "evidence": {},
346636          "signature": {
346637            "signature": {
346638              "publicKey": {}
346639            }
346640          },
346641          "modelCard": {
346642            "modelParameters": {
346643              "approach": {}
346644            },
346645            "quantitativeAnalysis": {
346646              "graphics": {}
346647            },
346648            "considerations": {}
346649          }
346650        },
346651        {
346652          "type": "library",
346653          "bom-ref": "pkg:npm/xml2js@0.4.23?package-id=8a1a1332606bd50f",
346654          "supplier": {},
346655          "name": "xml2js",
346656          "version": "0.4.23",
346657          "licenses": [
346658            {
346659              "license": {
346660                "id": "MIT"
346661              }
346662            }
346663          ],
346664          "cpe": "cpe:2.3:a:xml2js:xml2js:0.4.23:*:*:*:*:*:*:*",
346665          "purl": "pkg:npm/xml2js@0.4.23",
346666          "swid": {
346667            "attachment": {}
346668          },
346669          "pedigree": {},
346670          "evidence": {},
346671          "signature": {
346672            "signature": {
346673              "publicKey": {}
346674            }
346675          },
346676          "modelCard": {
346677            "modelParameters": {
346678              "approach": {}
346679            },
346680            "quantitativeAnalysis": {
346681              "graphics": {}
346682            },
346683            "considerations": {}
346684          }
346685        },
346686        {
346687          "type": "library",
346688          "bom-ref": "pkg:npm/xmlbuilder@11.0.1?package-id=ea247fd9c6bc1e81",
346689          "supplier": {},
346690          "name": "xmlbuilder",
346691          "version": "11.0.1",
346692          "licenses": [
346693            {
346694              "license": {
346695                "id": "MIT"
346696              }
346697            }
346698          ],
346699          "cpe": "cpe:2.3:a:xmlbuilder:xmlbuilder:11.0.1:*:*:*:*:*:*:*",
346700          "purl": "pkg:npm/xmlbuilder@11.0.1",
346701          "swid": {
346702            "attachment": {}
346703          },
346704          "pedigree": {},
346705          "evidence": {},
346706          "signature": {
346707            "signature": {
346708              "publicKey": {}
346709            }
346710          },
346711          "modelCard": {
346712            "modelParameters": {
346713              "approach": {}
346714            },
346715            "quantitativeAnalysis": {
346716              "graphics": {}
346717            },
346718            "considerations": {}
346719          }
346720        },
346721        {
346722          "type": "library",
346723          "bom-ref": "pkg:npm/xmldom@0.1.31?package-id=80963bb0acb5f02a",
346724          "supplier": {},
346725          "name": "xmldom",
346726          "version": "0.1.31",
346727          "licenses": [
346728            {
346729              "license": {
346730                "name": "(LGPL-2.0 or MIT)"
346731              }
346732            }
346733          ],
346734          "cpe": "cpe:2.3:a:xmldom:xmldom:0.1.31:*:*:*:*:*:*:*",
346735          "purl": "pkg:npm/xmldom@0.1.31",
346736          "swid": {
346737            "attachment": {}
346738          },
346739          "pedigree": {},
346740          "evidence": {},
346741          "signature": {
346742            "signature": {
346743              "publicKey": {}
346744            }
346745          },
346746          "modelCard": {
346747            "modelParameters": {
346748              "approach": {}
346749            },
346750            "quantitativeAnalysis": {
346751              "graphics": {}
346752            },
346753            "considerations": {}
346754          }
346755        },
346756        {
346757          "type": "library",
346758          "bom-ref": "pkg:npm/xmlhttprequest-ssl@1.5.5?package-id=4019aa9edd054aae",
346759          "supplier": {},
346760          "name": "xmlhttprequest-ssl",
346761          "version": "1.5.5",
346762          "licenses": [
346763            {
346764              "license": {
346765                "id": "MIT"
346766              }
346767            }
346768          ],
346769          "cpe": "cpe:2.3:a:xmlhttprequest-ssl:xmlhttprequest-ssl:1.5.5:*:*:*:*:*:*:*",
346770          "purl": "pkg:npm/xmlhttprequest-ssl@1.5.5",
346771          "swid": {
346772            "attachment": {}
346773          },
346774          "pedigree": {},
346775          "evidence": {},
346776          "signature": {
346777            "signature": {
346778              "publicKey": {}
346779            }
346780          },
346781          "modelCard": {
346782            "modelParameters": {
346783              "approach": {}
346784            },
346785            "quantitativeAnalysis": {
346786              "graphics": {}
346787            },
346788            "considerations": {}
346789          }
346790        },
346791        {
346792          "type": "library",
346793          "bom-ref": "pkg:npm/xtend@4.0.2?package-id=b451db5ef40dd530",
346794          "supplier": {},
346795          "name": "xtend",
346796          "version": "4.0.2",
346797          "licenses": [
346798            {
346799              "license": {
346800                "id": "MIT"
346801              }
346802            }
346803          ],
346804          "cpe": "cpe:2.3:a:xtend:xtend:4.0.2:*:*:*:*:*:*:*",
346805          "purl": "pkg:npm/xtend@4.0.2",
346806          "swid": {
346807            "attachment": {}
346808          },
346809          "pedigree": {},
346810          "evidence": {},
346811          "signature": {
346812            "signature": {
346813              "publicKey": {}
346814            }
346815          },
346816          "modelCard": {
346817            "modelParameters": {
346818              "approach": {}
346819            },
346820            "quantitativeAnalysis": {
346821              "graphics": {}
346822            },
346823            "considerations": {}
346824          }
346825        },
346826        {
346827          "type": "library",
346828          "bom-ref": "pkg:npm/xxhash@0.3.0?package-id=730c49ff2cdfb7eb",
346829          "supplier": {},
346830          "name": "xxhash",
346831          "version": "0.3.0",
346832          "licenses": [
346833            {
346834              "license": {
346835                "id": "MIT"
346836              }
346837            }
346838          ],
346839          "cpe": "cpe:2.3:a:xxhash:xxhash:0.3.0:*:*:*:*:*:*:*",
346840          "purl": "pkg:npm/xxhash@0.3.0",
346841          "swid": {
346842            "attachment": {}
346843          },
346844          "pedigree": {},
346845          "evidence": {},
346846          "signature": {
346847            "signature": {
346848              "publicKey": {}
346849            }
346850          },
346851          "modelCard": {
346852            "modelParameters": {
346853              "approach": {}
346854            },
346855            "quantitativeAnalysis": {
346856              "graphics": {}
346857            },
346858            "considerations": {}
346859          }
346860        },
346861        {
346862          "type": "library",
346863          "bom-ref": "pkg:npm/y18n@4.0.0?package-id=f66f03e93949de0",
346864          "supplier": {},
346865          "name": "y18n",
346866          "version": "4.0.0",
346867          "licenses": [
346868            {
346869              "license": {
346870                "id": "ISC"
346871              }
346872            }
346873          ],
346874          "cpe": "cpe:2.3:a:y18n:y18n:4.0.0:*:*:*:*:*:*:*",
346875          "purl": "pkg:npm/y18n@4.0.0",
346876          "swid": {
346877            "attachment": {}
346878          },
346879          "pedigree": {},
346880          "evidence": {},
346881          "signature": {
346882            "signature": {
346883              "publicKey": {}
346884            }
346885          },
346886          "modelCard": {
346887            "modelParameters": {
346888              "approach": {}
346889            },
346890            "quantitativeAnalysis": {
346891              "graphics": {}
346892            },
346893            "considerations": {}
346894          }
346895        },
346896        {
346897          "type": "library",
346898          "bom-ref": "pkg:npm/y18n@4.0.3?package-id=b1b1dd50751d52bb",
346899          "supplier": {},
346900          "name": "y18n",
346901          "version": "4.0.3",
346902          "cpe": "cpe:2.3:a:y18n:y18n:4.0.3:*:*:*:*:*:*:*",
346903          "purl": "pkg:npm/y18n@4.0.3",
346904          "swid": {
346905            "attachment": {}
346906          },
346907          "pedigree": {},
346908          "evidence": {},
346909          "signature": {
346910            "signature": {
346911              "publicKey": {}
346912            }
346913          },
346914          "modelCard": {
346915            "modelParameters": {
346916              "approach": {}
346917            },
346918            "quantitativeAnalysis": {
346919              "graphics": {}
346920            },
346921            "considerations": {}
346922          }
346923        },
346924        {
346925          "type": "library",
346926          "bom-ref": "pkg:npm/yallist@4.0.0?package-id=b9ba8a2c34ea0780",
346927          "supplier": {},
346928          "name": "yallist",
346929          "version": "4.0.0",
346930          "licenses": [
346931            {
346932              "license": {
346933                "id": "ISC"
346934              }
346935            }
346936          ],
346937          "cpe": "cpe:2.3:a:yallist:yallist:4.0.0:*:*:*:*:*:*:*",
346938          "purl": "pkg:npm/yallist@4.0.0",
346939          "swid": {
346940            "attachment": {}
346941          },
346942          "pedigree": {},
346943          "evidence": {},
346944          "signature": {
346945            "signature": {
346946              "publicKey": {}
346947            }
346948          },
346949          "modelCard": {
346950            "modelParameters": {
346951              "approach": {}
346952            },
346953            "quantitativeAnalysis": {
346954              "graphics": {}
346955            },
346956            "considerations": {}
346957          }
346958        },
346959        {
346960          "type": "library",
346961          "bom-ref": "pkg:npm/yargs@12.0.5?package-id=4f7c0bb9af8d0c21",
346962          "supplier": {},
346963          "name": "yargs",
346964          "version": "12.0.5",
346965          "licenses": [
346966            {
346967              "license": {
346968                "id": "MIT"
346969              }
346970            }
346971          ],
346972          "cpe": "cpe:2.3:a:yargs:yargs:12.0.5:*:*:*:*:*:*:*",
346973          "purl": "pkg:npm/yargs@12.0.5",
346974          "swid": {
346975            "attachment": {}
346976          },
346977          "pedigree": {},
346978          "evidence": {},
346979          "signature": {
346980            "signature": {
346981              "publicKey": {}
346982            }
346983          },
346984          "modelCard": {
346985            "modelParameters": {
346986              "approach": {}
346987            },
346988            "quantitativeAnalysis": {
346989              "graphics": {}
346990            },
346991            "considerations": {}
346992          }
346993        },
346994        {
346995          "type": "library",
346996          "bom-ref": "pkg:npm/yargs@15.4.1?package-id=8f403ae8dc97313c",
346997          "supplier": {},
346998          "name": "yargs",
346999          "version": "15.4.1",
347000          "cpe": "cpe:2.3:a:yargs:yargs:15.4.1:*:*:*:*:*:*:*",
347001          "purl": "pkg:npm/yargs@15.4.1",
347002          "swid": {
347003            "attachment": {}
347004          },
347005          "pedigree": {},
347006          "evidence": {},
347007          "signature": {
347008            "signature": {
347009              "publicKey": {}
347010            }
347011          },
347012          "modelCard": {
347013            "modelParameters": {
347014              "approach": {}
347015            },
347016            "quantitativeAnalysis": {
347017              "graphics": {}
347018            },
347019            "considerations": {}
347020          }
347021        },
347022        {
347023          "type": "library",
347024          "bom-ref": "pkg:npm/yargs-parser@11.1.1?package-id=c315772eeb3c67b0",
347025          "supplier": {},
347026          "name": "yargs-parser",
347027          "version": "11.1.1",
347028          "licenses": [
347029            {
347030              "license": {
347031                "id": "ISC"
347032              }
347033            }
347034          ],
347035          "cpe": "cpe:2.3:a:yargs-parser:yargs-parser:11.1.1:*:*:*:*:*:*:*",
347036          "purl": "pkg:npm/yargs-parser@11.1.1",
347037          "swid": {
347038            "attachment": {}
347039          },
347040          "pedigree": {},
347041          "evidence": {},
347042          "signature": {
347043            "signature": {
347044              "publicKey": {}
347045            }
347046          },
347047          "modelCard": {
347048            "modelParameters": {
347049              "approach": {}
347050            },
347051            "quantitativeAnalysis": {
347052              "graphics": {}
347053            },
347054            "considerations": {}
347055          }
347056        },
347057        {
347058          "type": "library",
347059          "bom-ref": "pkg:npm/yargs-parser@18.1.3?package-id=491b18b9acc674c0",
347060          "supplier": {},
347061          "name": "yargs-parser",
347062          "version": "18.1.3",
347063          "cpe": "cpe:2.3:a:yargs-parser:yargs-parser:18.1.3:*:*:*:*:*:*:*",
347064          "purl": "pkg:npm/yargs-parser@18.1.3",
347065          "swid": {
347066            "attachment": {}
347067          },
347068          "pedigree": {},
347069          "evidence": {},
347070          "signature": {
347071            "signature": {
347072              "publicKey": {}
347073            }
347074          },
347075          "modelCard": {
347076            "modelParameters": {
347077              "approach": {}
347078            },
347079            "quantitativeAnalysis": {
347080              "graphics": {}
347081            },
347082            "considerations": {}
347083          }
347084        },
347085        {
347086          "type": "library",
347087          "bom-ref": "pkg:npm/yeast@0.1.2?package-id=38ec3e9d597f589d",
347088          "supplier": {},
347089          "name": "yeast",
347090          "version": "0.1.2",
347091          "licenses": [
347092            {
347093              "license": {
347094                "id": "MIT"
347095              }
347096            }
347097          ],
347098          "cpe": "cpe:2.3:a:yeast:yeast:0.1.2:*:*:*:*:*:*:*",
347099          "purl": "pkg:npm/yeast@0.1.2",
347100          "swid": {
347101            "attachment": {}
347102          },
347103          "pedigree": {},
347104          "evidence": {},
347105          "signature": {
347106            "signature": {
347107              "publicKey": {}
347108            }
347109          },
347110          "modelCard": {
347111            "modelParameters": {
347112              "approach": {}
347113            },
347114            "quantitativeAnalysis": {
347115              "graphics": {}
347116            },
347117            "considerations": {}
347118          }
347119        },
347120        {
347121          "type": "library",
347122          "bom-ref": "pkg:npm/yn@3.1.1?package-id=4af1448b028059fc",
347123          "supplier": {},
347124          "name": "yn",
347125          "version": "3.1.1",
347126          "licenses": [
347127            {
347128              "license": {
347129                "id": "MIT"
347130              }
347131            }
347132          ],
347133          "cpe": "cpe:2.3:a:yn:yn:3.1.1:*:*:*:*:*:*:*",
347134          "purl": "pkg:npm/yn@3.1.1",
347135          "swid": {
347136            "attachment": {}
347137          },
347138          "pedigree": {},
347139          "evidence": {},
347140          "signature": {
347141            "signature": {
347142              "publicKey": {}
347143            }
347144          },
347145          "modelCard": {
347146            "modelParameters": {
347147              "approach": {}
347148            },
347149            "quantitativeAnalysis": {
347150              "graphics": {}
347151            },
347152            "considerations": {}
347153          }
347154        },
347155        {
347156          "type": "library",
347157          "bom-ref": "pkg:npm/zone.js@0.10.3?package-id=2b98aef0b39e3c6f",
347158          "supplier": {},
347159          "name": "zone.js",
347160          "version": "0.10.3",
347161          "licenses": [
347162            {
347163              "license": {
347164                "id": "MIT"
347165              }
347166            }
347167          ],
347168          "cpe": "cpe:2.3:a:zone.js:zone.js:0.10.3:*:*:*:*:*:*:*",
347169          "purl": "pkg:npm/zone.js@0.10.3",
347170          "swid": {
347171            "attachment": {}
347172          },
347173          "pedigree": {},
347174          "evidence": {},
347175          "signature": {
347176            "signature": {
347177              "publicKey": {}
347178            }
347179          },
347180          "modelCard": {
347181            "modelParameters": {
347182              "approach": {}
347183            },
347184            "quantitativeAnalysis": {
347185              "graphics": {}
347186            },
347187            "considerations": {}
347188          }
347189        },
347190        {
347191          "type": "library",
347192          "bom-ref": "pkg:deb/debian/base-files@10.3+deb10u10?arch=amd64\u0026distro=debian-10\u0026package-id=8417cfe24eb4f844",
347193          "supplier": {},
347194          "publisher": "Santiago Vila \u003csanvila@debian.org\u003e",
347195          "name": "base-files",
347196          "version": "10.3+deb10u10",
347197          "licenses": [
347198            {
347199              "license": {
347200                "name": "GPL"
347201              }
347202            }
347203          ],
347204          "cpe": "cpe:2.3:a:base-files:base-files:10.3\\+deb10u10:*:*:*:*:*:*:*",
347205          "purl": "pkg:deb/debian/base-files@10.3+deb10u10?arch=amd64\u0026distro=debian-10",
347206          "swid": {
347207            "attachment": {}
347208          },
347209          "pedigree": {},
347210          "evidence": {},
347211          "signature": {
347212            "signature": {
347213              "publicKey": {}
347214            }
347215          },
347216          "modelCard": {
347217            "modelParameters": {
347218              "approach": {}
347219            },
347220            "quantitativeAnalysis": {
347221              "graphics": {}
347222            },
347223            "considerations": {}
347224          }
347225        },
347226        {
347227          "type": "library",
347228          "bom-ref": "pkg:golang/github.com/beorn7/perks@v1.0.1?package-id=1373de25eb1ce15c",
347229          "supplier": {},
347230          "name": "github.com/beorn7/perks",
347231          "version": "v1.0.1",
347232          "cpe": "cpe:2.3:a:beorn7:perks:v1.0.1:*:*:*:*:*:*:*",
347233          "purl": "pkg:golang/github.com/beorn7/perks@v1.0.1",
347234          "swid": {
347235            "attachment": {}
347236          },
347237          "pedigree": {},
347238          "evidence": {},
347239          "signature": {
347240            "signature": {
347241              "publicKey": {}
347242            }
347243          },
347244          "modelCard": {
347245            "modelParameters": {
347246              "approach": {}
347247            },
347248            "quantitativeAnalysis": {
347249              "graphics": {}
347250            },
347251            "considerations": {}
347252          }
347253        },
347254        {
347255          "type": "library",
347256          "bom-ref": "pkg:golang/github.com/blang/semver@v3.5.1+incompatible?package-id=558b902810b3683",
347257          "supplier": {},
347258          "name": "github.com/blang/semver",
347259          "version": "v3.5.1+incompatible",
347260          "cpe": "cpe:2.3:a:blang:semver:v3.5.1\\+incompatible:*:*:*:*:*:*:*",
347261          "purl": "pkg:golang/github.com/blang/semver@v3.5.1+incompatible",
347262          "swid": {
347263            "attachment": {}
347264          },
347265          "pedigree": {},
347266          "evidence": {},
347267          "signature": {
347268            "signature": {
347269              "publicKey": {}
347270            }
347271          },
347272          "modelCard": {
347273            "modelParameters": {
347274              "approach": {}
347275            },
347276            "quantitativeAnalysis": {
347277              "graphics": {}
347278            },
347279            "considerations": {}
347280          }
347281        },
347282        {
347283          "type": "library",
347284          "bom-ref": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1?package-id=a4500c6524355d5",
347285          "supplier": {},
347286          "name": "github.com/cespare/xxhash/v2",
347287          "version": "v2.1.1",
347288          "cpe": "cpe:2.3:a:cespare:xxhash\\/v2:v2.1.1:*:*:*:*:*:*:*",
347289          "purl": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1",
347290          "swid": {
347291            "attachment": {}
347292          },
347293          "pedigree": {},
347294          "evidence": {},
347295          "signature": {
347296            "signature": {
347297              "publicKey": {}
347298            }
347299          },
347300          "modelCard": {
347301            "modelParameters": {
347302              "approach": {}
347303            },
347304            "quantitativeAnalysis": {
347305              "graphics": {}
347306            },
347307            "considerations": {}
347308          }
347309        },
347310        {
347311          "type": "library",
347312          "bom-ref": "pkg:golang/github.com/container-storage-interface/spec@v1.5.0?package-id=682e9054f0046643",
347313          "supplier": {},
347314          "name": "github.com/container-storage-interface/spec",
347315          "version": "v1.5.0",
347316          "cpe": "cpe:2.3:a:container-storage-interface:spec:v1.5.0:*:*:*:*:*:*:*",
347317          "purl": "pkg:golang/github.com/container-storage-interface/spec@v1.5.0",
347318          "swid": {
347319            "attachment": {}
347320          },
347321          "pedigree": {},
347322          "evidence": {},
347323          "signature": {
347324            "signature": {
347325              "publicKey": {}
347326            }
347327          },
347328          "modelCard": {
347329            "modelParameters": {
347330              "approach": {}
347331            },
347332            "quantitativeAnalysis": {
347333              "graphics": {}
347334            },
347335            "considerations": {}
347336          }
347337        },
347338        {
347339          "type": "library",
347340          "bom-ref": "pkg:golang/github.com/go-logr/logr@v0.4.0?package-id=21104c6324cec563",
347341          "supplier": {},
347342          "name": "github.com/go-logr/logr",
347343          "version": "v0.4.0",
347344          "cpe": "cpe:2.3:a:go-logr:logr:v0.4.0:*:*:*:*:*:*:*",
347345          "purl": "pkg:golang/github.com/go-logr/logr@v0.4.0",
347346          "swid": {
347347            "attachment": {}
347348          },
347349          "pedigree": {},
347350          "evidence": {},
347351          "signature": {
347352            "signature": {
347353              "publicKey": {}
347354            }
347355          },
347356          "modelCard": {
347357            "modelParameters": {
347358              "approach": {}
347359            },
347360            "quantitativeAnalysis": {
347361              "graphics": {}
347362            },
347363            "considerations": {}
347364          }
347365        },
347366        {
347367          "type": "library",
347368          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.3.2?package-id=4b08277535ad294d",
347369          "supplier": {},
347370          "name": "github.com/gogo/protobuf",
347371          "version": "v1.3.2",
347372          "cpe": "cpe:2.3:a:gogo:protobuf:v1.3.2:*:*:*:*:*:*:*",
347373          "purl": "pkg:golang/github.com/gogo/protobuf@v1.3.2",
347374          "swid": {
347375            "attachment": {}
347376          },
347377          "pedigree": {},
347378          "evidence": {},
347379          "signature": {
347380            "signature": {
347381              "publicKey": {}
347382            }
347383          },
347384          "modelCard": {
347385            "modelParameters": {
347386              "approach": {}
347387            },
347388            "quantitativeAnalysis": {
347389              "graphics": {}
347390            },
347391            "considerations": {}
347392          }
347393        },
347394        {
347395          "type": "library",
347396          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.5.2?package-id=4b231e481c8c31e9",
347397          "supplier": {},
347398          "name": "github.com/golang/protobuf",
347399          "version": "v1.5.2",
347400          "cpe": "cpe:2.3:a:golang:protobuf:v1.5.2:*:*:*:*:*:*:*",
347401          "purl": "pkg:golang/github.com/golang/protobuf@v1.5.2",
347402          "swid": {
347403            "attachment": {}
347404          },
347405          "pedigree": {},
347406          "evidence": {},
347407          "signature": {
347408            "signature": {
347409              "publicKey": {}
347410            }
347411          },
347412          "modelCard": {
347413            "modelParameters": {
347414              "approach": {}
347415            },
347416            "quantitativeAnalysis": {
347417              "graphics": {}
347418            },
347419            "considerations": {}
347420          }
347421        },
347422        {
347423          "type": "library",
347424          "bom-ref": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.10.0?package-id=30cd18d3182b8b35",
347425          "supplier": {},
347426          "name": "github.com/kubernetes-csi/csi-lib-utils",
347427          "version": "v0.10.0",
347428          "cpe": "cpe:2.3:a:kubernetes-csi:csi-lib-utils:v0.10.0:*:*:*:*:*:*:*",
347429          "purl": "pkg:golang/github.com/kubernetes-csi/csi-lib-utils@v0.10.0",
347430          "swid": {
347431            "attachment": {}
347432          },
347433          "pedigree": {},
347434          "evidence": {},
347435          "signature": {
347436            "signature": {
347437              "publicKey": {}
347438            }
347439          },
347440          "modelCard": {
347441            "modelParameters": {
347442              "approach": {}
347443            },
347444            "quantitativeAnalysis": {
347445              "graphics": {}
347446            },
347447            "considerations": {}
347448          }
347449        },
347450        {
347451          "type": "library",
347452          "bom-ref": "pkg:golang/github.com/kubernetes-csi/node-driver-registrar@(devel)?package-id=9bcd1f0df82a70fb",
347453          "supplier": {},
347454          "name": "github.com/kubernetes-csi/node-driver-registrar",
347455          "version": "(devel)",
347456          "cpe": "cpe:2.3:a:kubernetes-csi:node-driver-registrar:\\(devel\\):*:*:*:*:*:*:*",
347457          "purl": "pkg:golang/github.com/kubernetes-csi/node-driver-registrar@(devel)",
347458          "swid": {
347459            "attachment": {}
347460          },
347461          "pedigree": {},
347462          "evidence": {},
347463          "signature": {
347464            "signature": {
347465              "publicKey": {}
347466            }
347467          },
347468          "modelCard": {
347469            "modelParameters": {
347470              "approach": {}
347471            },
347472            "quantitativeAnalysis": {
347473              "graphics": {}
347474            },
347475            "considerations": {}
347476          }
347477        },
347478        {
347479          "type": "library",
347480          "bom-ref": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369?package-id=427769f3e350e261",
347481          "supplier": {},
347482          "name": "github.com/matttproud/golang_protobuf_extensions",
347483          "version": "v1.0.2-0.20181231171920-c182affec369",
347484          "cpe": "cpe:2.3:a:matttproud:golang-protobuf-extensions:v1.0.2-0.20181231171920-c182affec369:*:*:*:*:*:*:*",
347485          "purl": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.2-0.20181231171920-c182affec369",
347486          "swid": {
347487            "attachment": {}
347488          },
347489          "pedigree": {},
347490          "evidence": {},
347491          "signature": {
347492            "signature": {
347493              "publicKey": {}
347494            }
347495          },
347496          "modelCard": {
347497            "modelParameters": {
347498              "approach": {}
347499            },
347500            "quantitativeAnalysis": {
347501              "graphics": {}
347502            },
347503            "considerations": {}
347504          }
347505        },
347506        {
347507          "type": "library",
347508          "bom-ref": "pkg:golang/github.com/prometheus/client_golang@v1.11.0?package-id=9da8e2f7193f2269",
347509          "supplier": {},
347510          "name": "github.com/prometheus/client_golang",
347511          "version": "v1.11.0",
347512          "cpe": "cpe:2.3:a:prometheus:client-golang:v1.11.0:*:*:*:*:*:*:*",
347513          "purl": "pkg:golang/github.com/prometheus/client_golang@v1.11.0",
347514          "swid": {
347515            "attachment": {}
347516          },
347517          "pedigree": {},
347518          "evidence": {},
347519          "signature": {
347520            "signature": {
347521              "publicKey": {}
347522            }
347523          },
347524          "modelCard": {
347525            "modelParameters": {
347526              "approach": {}
347527            },
347528            "quantitativeAnalysis": {
347529              "graphics": {}
347530            },
347531            "considerations": {}
347532          }
347533        },
347534        {
347535          "type": "library",
347536          "bom-ref": "pkg:golang/github.com/prometheus/client_model@v0.2.0?package-id=5b2fe3826403a99c",
347537          "supplier": {},
347538          "name": "github.com/prometheus/client_model",
347539          "version": "v0.2.0",
347540          "cpe": "cpe:2.3:a:prometheus:client-model:v0.2.0:*:*:*:*:*:*:*",
347541          "purl": "pkg:golang/github.com/prometheus/client_model@v0.2.0",
347542          "swid": {
347543            "attachment": {}
347544          },
347545          "pedigree": {},
347546          "evidence": {},
347547          "signature": {
347548            "signature": {
347549              "publicKey": {}
347550            }
347551          },
347552          "modelCard": {
347553            "modelParameters": {
347554              "approach": {}
347555            },
347556            "quantitativeAnalysis": {
347557              "graphics": {}
347558            },
347559            "considerations": {}
347560          }
347561        },
347562        {
347563          "type": "library",
347564          "bom-ref": "pkg:golang/github.com/prometheus/common@v0.26.0?package-id=343129a169270e41",
347565          "supplier": {},
347566          "name": "github.com/prometheus/common",
347567          "version": "v0.26.0",
347568          "cpe": "cpe:2.3:a:prometheus:common:v0.26.0:*:*:*:*:*:*:*",
347569          "purl": "pkg:golang/github.com/prometheus/common@v0.26.0",
347570          "swid": {
347571            "attachment": {}
347572          },
347573          "pedigree": {},
347574          "evidence": {},
347575          "signature": {
347576            "signature": {
347577              "publicKey": {}
347578            }
347579          },
347580          "modelCard": {
347581            "modelParameters": {
347582              "approach": {}
347583            },
347584            "quantitativeAnalysis": {
347585              "graphics": {}
347586            },
347587            "considerations": {}
347588          }
347589        },
347590        {
347591          "type": "library",
347592          "bom-ref": "pkg:golang/github.com/prometheus/procfs@v0.6.0?package-id=e35748e48a0d85c8",
347593          "supplier": {},
347594          "name": "github.com/prometheus/procfs",
347595          "version": "v0.6.0",
347596          "cpe": "cpe:2.3:a:prometheus:procfs:v0.6.0:*:*:*:*:*:*:*",
347597          "purl": "pkg:golang/github.com/prometheus/procfs@v0.6.0",
347598          "swid": {
347599            "attachment": {}
347600          },
347601          "pedigree": {},
347602          "evidence": {},
347603          "signature": {
347604            "signature": {
347605              "publicKey": {}
347606            }
347607          },
347608          "modelCard": {
347609            "modelParameters": {
347610              "approach": {}
347611            },
347612            "quantitativeAnalysis": {
347613              "graphics": {}
347614            },
347615            "considerations": {}
347616          }
347617        },
347618        {
347619          "type": "library",
347620          "bom-ref": "pkg:golang/github.com/spf13/pflag@v1.0.5?package-id=83c8c6260baef0e8",
347621          "supplier": {},
347622          "name": "github.com/spf13/pflag",
347623          "version": "v1.0.5",
347624          "cpe": "cpe:2.3:a:spf13:pflag:v1.0.5:*:*:*:*:*:*:*",
347625          "purl": "pkg:golang/github.com/spf13/pflag@v1.0.5",
347626          "swid": {
347627            "attachment": {}
347628          },
347629          "pedigree": {},
347630          "evidence": {},
347631          "signature": {
347632            "signature": {
347633              "publicKey": {}
347634            }
347635          },
347636          "modelCard": {
347637            "modelParameters": {
347638              "approach": {}
347639            },
347640            "quantitativeAnalysis": {
347641              "graphics": {}
347642            },
347643            "considerations": {}
347644          }
347645        },
347646        {
347647          "type": "library",
347648          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023?package-id=7328e3c8a7d7bd9d",
347649          "supplier": {},
347650          "name": "golang.org/x/net",
347651          "version": "v0.0.0-20210520170846-37e1c6afe023",
347652          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20210520170846-37e1c6afe023:*:*:*:*:*:*:*",
347653          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023",
347654          "swid": {
347655            "attachment": {}
347656          },
347657          "pedigree": {},
347658          "evidence": {},
347659          "signature": {
347660            "signature": {
347661              "publicKey": {}
347662            }
347663          },
347664          "modelCard": {
347665            "modelParameters": {
347666              "approach": {}
347667            },
347668            "quantitativeAnalysis": {
347669              "graphics": {}
347670            },
347671            "considerations": {}
347672          }
347673        },
347674        {
347675          "type": "library",
347676          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22?package-id=cfa7d037f05b2996",
347677          "supplier": {},
347678          "name": "golang.org/x/sys",
347679          "version": "v0.0.0-20210616094352-59db8d763f22",
347680          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20210616094352-59db8d763f22:*:*:*:*:*:*:*",
347681          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20210616094352-59db8d763f22",
347682          "swid": {
347683            "attachment": {}
347684          },
347685          "pedigree": {},
347686          "evidence": {},
347687          "signature": {
347688            "signature": {
347689              "publicKey": {}
347690            }
347691          },
347692          "modelCard": {
347693            "modelParameters": {
347694              "approach": {}
347695            },
347696            "quantitativeAnalysis": {
347697              "graphics": {}
347698            },
347699            "considerations": {}
347700          }
347701        },
347702        {
347703          "type": "library",
347704          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.6?package-id=8007f29f97ec86f6",
347705          "supplier": {},
347706          "name": "golang.org/x/text",
347707          "version": "v0.3.6",
347708          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.6:*:*:*:*:*:*:*",
347709          "purl": "pkg:golang/golang.org/x/text@v0.3.6",
347710          "swid": {
347711            "attachment": {}
347712          },
347713          "pedigree": {},
347714          "evidence": {},
347715          "signature": {
347716            "signature": {
347717              "publicKey": {}
347718            }
347719          },
347720          "modelCard": {
347721            "modelParameters": {
347722              "approach": {}
347723            },
347724            "quantitativeAnalysis": {
347725              "graphics": {}
347726            },
347727            "considerations": {}
347728          }
347729        },
347730        {
347731          "type": "library",
347732          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20210602131652-f16073e35f0c?package-id=6d46869942b8cea7",
347733          "supplier": {},
347734          "name": "google.golang.org/genproto",
347735          "version": "v0.0.0-20210602131652-f16073e35f0c",
347736          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20210602131652-f16073e35f0c:*:*:*:*:*:*:*",
347737          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20210602131652-f16073e35f0c",
347738          "swid": {
347739            "attachment": {}
347740          },
347741          "pedigree": {},
347742          "evidence": {},
347743          "signature": {
347744            "signature": {
347745              "publicKey": {}
347746            }
347747          },
347748          "modelCard": {
347749            "modelParameters": {
347750              "approach": {}
347751            },
347752            "quantitativeAnalysis": {
347753              "graphics": {}
347754            },
347755            "considerations": {}
347756          }
347757        },
347758        {
347759          "type": "library",
347760          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.38.0?package-id=bd89b6ef53ebc93",
347761          "supplier": {},
347762          "name": "google.golang.org/grpc",
347763          "version": "v1.38.0",
347764          "cpe": "cpe:2.3:a:google:grpc:v1.38.0:*:*:*:*:*:*:*",
347765          "purl": "pkg:golang/google.golang.org/grpc@v1.38.0",
347766          "swid": {
347767            "attachment": {}
347768          },
347769          "pedigree": {},
347770          "evidence": {},
347771          "signature": {
347772            "signature": {
347773              "publicKey": {}
347774            }
347775          },
347776          "modelCard": {
347777            "modelParameters": {
347778              "approach": {}
347779            },
347780            "quantitativeAnalysis": {
347781              "graphics": {}
347782            },
347783            "considerations": {}
347784          }
347785        },
347786        {
347787          "type": "library",
347788          "bom-ref": "pkg:golang/google.golang.org/protobuf@v1.26.0?package-id=cf64bd4d8f5c1d68",
347789          "supplier": {},
347790          "name": "google.golang.org/protobuf",
347791          "version": "v1.26.0",
347792          "cpe": "cpe:2.3:a:google:protobuf:v1.26.0:*:*:*:*:*:*:*",
347793          "purl": "pkg:golang/google.golang.org/protobuf@v1.26.0",
347794          "swid": {
347795            "attachment": {}
347796          },
347797          "pedigree": {},
347798          "evidence": {},
347799          "signature": {
347800            "signature": {
347801              "publicKey": {}
347802            }
347803          },
347804          "modelCard": {
347805            "modelParameters": {
347806              "approach": {}
347807            },
347808            "quantitativeAnalysis": {
347809              "graphics": {}
347810            },
347811            "considerations": {}
347812          }
347813        },
347814        {
347815          "type": "library",
347816          "bom-ref": "pkg:golang/k8s.io/apimachinery@v0.22.0?package-id=a42b5adccc518eec",
347817          "supplier": {},
347818          "name": "k8s.io/apimachinery",
347819          "version": "v0.22.0",
347820          "purl": "pkg:golang/k8s.io/apimachinery@v0.22.0",
347821          "swid": {
347822            "attachment": {}
347823          },
347824          "pedigree": {},
347825          "evidence": {},
347826          "signature": {
347827            "signature": {
347828              "publicKey": {}
347829            }
347830          },
347831          "modelCard": {
347832            "modelParameters": {
347833              "approach": {}
347834            },
347835            "quantitativeAnalysis": {
347836              "graphics": {}
347837            },
347838            "considerations": {}
347839          }
347840        },
347841        {
347842          "type": "library",
347843          "bom-ref": "pkg:golang/k8s.io/component-base@v0.22.0?package-id=8c3ce154d5c535d7",
347844          "supplier": {},
347845          "name": "k8s.io/component-base",
347846          "version": "v0.22.0",
347847          "purl": "pkg:golang/k8s.io/component-base@v0.22.0",
347848          "swid": {
347849            "attachment": {}
347850          },
347851          "pedigree": {},
347852          "evidence": {},
347853          "signature": {
347854            "signature": {
347855              "publicKey": {}
347856            }
347857          },
347858          "modelCard": {
347859            "modelParameters": {
347860              "approach": {}
347861            },
347862            "quantitativeAnalysis": {
347863              "graphics": {}
347864            },
347865            "considerations": {}
347866          }
347867        },
347868        {
347869          "type": "library",
347870          "bom-ref": "pkg:golang/k8s.io/klog/v2@v2.9.0?package-id=975d54cb9167375e",
347871          "supplier": {},
347872          "name": "k8s.io/klog/v2",
347873          "version": "v2.9.0",
347874          "cpe": "cpe:2.3:a:klog:v2:v2.9.0:*:*:*:*:*:*:*",
347875          "purl": "pkg:golang/k8s.io/klog/v2@v2.9.0",
347876          "swid": {
347877            "attachment": {}
347878          },
347879          "pedigree": {},
347880          "evidence": {},
347881          "signature": {
347882            "signature": {
347883              "publicKey": {}
347884            }
347885          },
347886          "modelCard": {
347887            "modelParameters": {
347888              "approach": {}
347889            },
347890            "quantitativeAnalysis": {
347891              "graphics": {}
347892            },
347893            "considerations": {}
347894          }
347895        },
347896        {
347897          "type": "library",
347898          "bom-ref": "pkg:golang/k8s.io/kubelet@v0.22.0?package-id=e029cdf7d5cafa88",
347899          "supplier": {},
347900          "name": "k8s.io/kubelet",
347901          "version": "v0.22.0",
347902          "purl": "pkg:golang/k8s.io/kubelet@v0.22.0",
347903          "swid": {
347904            "attachment": {}
347905          },
347906          "pedigree": {},
347907          "evidence": {},
347908          "signature": {
347909            "signature": {
347910              "publicKey": {}
347911            }
347912          },
347913          "modelCard": {
347914            "modelParameters": {
347915              "approach": {}
347916            },
347917            "quantitativeAnalysis": {
347918              "graphics": {}
347919            },
347920            "considerations": {}
347921          }
347922        },
347923        {
347924          "type": "library",
347925          "bom-ref": "pkg:deb/debian/netbase@5.6?arch=all\u0026distro=debian-10\u0026package-id=d657af39f8b794b0",
347926          "supplier": {},
347927          "publisher": "Marco d'Itri \u003cmd@linux.it\u003e",
347928          "name": "netbase",
347929          "version": "5.6",
347930          "licenses": [
347931            {
347932              "license": {
347933                "id": "GPL-2.0-only"
347934              }
347935            }
347936          ],
347937          "cpe": "cpe:2.3:a:netbase:netbase:5.6:*:*:*:*:*:*:*",
347938          "purl": "pkg:deb/debian/netbase@5.6?arch=all\u0026distro=debian-10",
347939          "swid": {
347940            "attachment": {}
347941          },
347942          "pedigree": {},
347943          "evidence": {},
347944          "signature": {
347945            "signature": {
347946              "publicKey": {}
347947            }
347948          },
347949          "modelCard": {
347950            "modelParameters": {
347951              "approach": {}
347952            },
347953            "quantitativeAnalysis": {
347954              "graphics": {}
347955            },
347956            "considerations": {}
347957          }
347958        },
347959        {
347960          "type": "library",
347961          "bom-ref": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10\u0026package-id=90047fe80701a227",
347962          "supplier": {},
347963          "publisher": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e",
347964          "name": "tzdata",
347965          "version": "2021a-0+deb10u1",
347966          "cpe": "cpe:2.3:a:tzdata:tzdata:2021a-0\\+deb10u1:*:*:*:*:*:*:*",
347967          "purl": "pkg:deb/debian/tzdata@2021a-0+deb10u1?arch=all\u0026distro=debian-10",
347968          "swid": {
347969            "attachment": {}
347970          },
347971          "pedigree": {},
347972          "evidence": {},
347973          "signature": {
347974            "signature": {
347975              "publicKey": {}
347976            }
347977          },
347978          "modelCard": {
347979            "modelParameters": {
347980              "approach": {}
347981            },
347982            "quantitativeAnalysis": {
347983              "graphics": {}
347984            },
347985            "considerations": {}
347986          }
347987        },
347988        {
347989          "type": "operating-system",
347990          "supplier": {},
347991          "name": "debian",
347992          "version": "10",
347993          "description": "Distroless",
347994          "swid": {
347995            "tagId": "debian",
347996            "name": "debian",
347997            "version": "10",
347998            "attachment": {}
347999          },
348000          "pedigree": {},
348001          "externalReferences": [
348002            {
348003              "url": "https://github.com/GoogleContainerTools/distroless/issues/new",
348004              "type": "issue-tracker"
348005            },
348006            {
348007              "url": "https://github.com/GoogleContainerTools/distroless",
348008              "type": "website"
348009            },
348010            {
348011              "url": "https://github.com/GoogleContainerTools/distroless/blob/master/README.md",
348012              "comment": "support",
348013              "type": "other"
348014            }
348015          ],
348016          "evidence": {},
348017          "signature": {
348018            "signature": {
348019              "publicKey": {}
348020            }
348021          },
348022          "modelCard": {
348023            "modelParameters": {
348024              "approach": {}
348025            },
348026            "quantitativeAnalysis": {
348027              "graphics": {}
348028            },
348029            "considerations": {}
348030          }
348031        },
348032        {
348033          "type": "library",
348034          "bom-ref": "pkg:golang/cloud.google.com/go@v0.41.0?package-id=10279645d7d42a93",
348035          "supplier": {},
348036          "name": "cloud.google.com/go",
348037          "version": "v0.41.0",
348038          "purl": "pkg:golang/cloud.google.com/go@v0.41.0",
348039          "swid": {
348040            "attachment": {}
348041          },
348042          "pedigree": {},
348043          "evidence": {},
348044          "signature": {
348045            "signature": {
348046              "publicKey": {}
348047            }
348048          },
348049          "modelCard": {
348050            "modelParameters": {
348051              "approach": {}
348052            },
348053            "quantitativeAnalysis": {
348054              "graphics": {}
348055            },
348056            "considerations": {}
348057          }
348058        },
348059        {
348060          "type": "library",
348061          "bom-ref": "pkg:golang/github.com/azure/azure-sdk-for-go@v32.6.0+incompatible?package-id=6eb9570d3790789e",
348062          "supplier": {},
348063          "name": "github.com/Azure/azure-sdk-for-go",
348064          "version": "v32.6.0+incompatible",
348065          "cpe": "cpe:2.3:a:Azure:azure-sdk-for-go:v32.6.0\\+incompatible:*:*:*:*:*:*:*",
348066          "purl": "pkg:golang/github.com/Azure/azure-sdk-for-go@v32.6.0+incompatible",
348067          "swid": {
348068            "attachment": {}
348069          },
348070          "pedigree": {},
348071          "evidence": {},
348072          "signature": {
348073            "signature": {
348074              "publicKey": {}
348075            }
348076          },
348077          "modelCard": {
348078            "modelParameters": {
348079              "approach": {}
348080            },
348081            "quantitativeAnalysis": {
348082              "graphics": {}
348083            },
348084            "considerations": {}
348085          }
348086        },
348087        {
348088          "type": "library",
348089          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest@v0.10.0?package-id=a9a5550991947e08",
348090          "supplier": {},
348091          "name": "github.com/Azure/go-autorest/autorest",
348092          "version": "v0.10.0",
348093          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest:v0.10.0:*:*:*:*:*:*:*",
348094          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest@v0.10.0",
348095          "swid": {
348096            "attachment": {}
348097          },
348098          "pedigree": {},
348099          "evidence": {},
348100          "signature": {
348101            "signature": {
348102              "publicKey": {}
348103            }
348104          },
348105          "modelCard": {
348106            "modelParameters": {
348107              "approach": {}
348108            },
348109            "quantitativeAnalysis": {
348110              "graphics": {}
348111            },
348112            "considerations": {}
348113          }
348114        },
348115        {
348116          "type": "library",
348117          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest/adal@v0.8.2?package-id=c33735d07f8eff52",
348118          "supplier": {},
348119          "name": "github.com/Azure/go-autorest/autorest/adal",
348120          "version": "v0.8.2",
348121          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest\\/adal:v0.8.2:*:*:*:*:*:*:*",
348122          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest/adal@v0.8.2",
348123          "swid": {
348124            "attachment": {}
348125          },
348126          "pedigree": {},
348127          "evidence": {},
348128          "signature": {
348129            "signature": {
348130              "publicKey": {}
348131            }
348132          },
348133          "modelCard": {
348134            "modelParameters": {
348135              "approach": {}
348136            },
348137            "quantitativeAnalysis": {
348138              "graphics": {}
348139            },
348140            "considerations": {}
348141          }
348142        },
348143        {
348144          "type": "library",
348145          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest/azure/auth@v0.4.2?package-id=e63721c8dab7170",
348146          "supplier": {},
348147          "name": "github.com/Azure/go-autorest/autorest/azure/auth",
348148          "version": "v0.4.2",
348149          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest\\/azure\\/auth:v0.4.2:*:*:*:*:*:*:*",
348150          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest/azure/auth@v0.4.2",
348151          "swid": {
348152            "attachment": {}
348153          },
348154          "pedigree": {},
348155          "evidence": {},
348156          "signature": {
348157            "signature": {
348158              "publicKey": {}
348159            }
348160          },
348161          "modelCard": {
348162            "modelParameters": {
348163              "approach": {}
348164            },
348165            "quantitativeAnalysis": {
348166              "graphics": {}
348167            },
348168            "considerations": {}
348169          }
348170        },
348171        {
348172          "type": "library",
348173          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest/azure/cli@v0.3.1?package-id=ed5c5a689bfdf7a3",
348174          "supplier": {},
348175          "name": "github.com/Azure/go-autorest/autorest/azure/cli",
348176          "version": "v0.3.1",
348177          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest\\/azure\\/cli:v0.3.1:*:*:*:*:*:*:*",
348178          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest/azure/cli@v0.3.1",
348179          "swid": {
348180            "attachment": {}
348181          },
348182          "pedigree": {},
348183          "evidence": {},
348184          "signature": {
348185            "signature": {
348186              "publicKey": {}
348187            }
348188          },
348189          "modelCard": {
348190            "modelParameters": {
348191              "approach": {}
348192            },
348193            "quantitativeAnalysis": {
348194              "graphics": {}
348195            },
348196            "considerations": {}
348197          }
348198        },
348199        {
348200          "type": "library",
348201          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest/date@v0.2.0?package-id=34d73b12c5c763b3",
348202          "supplier": {},
348203          "name": "github.com/Azure/go-autorest/autorest/date",
348204          "version": "v0.2.0",
348205          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest\\/date:v0.2.0:*:*:*:*:*:*:*",
348206          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest/date@v0.2.0",
348207          "swid": {
348208            "attachment": {}
348209          },
348210          "pedigree": {},
348211          "evidence": {},
348212          "signature": {
348213            "signature": {
348214              "publicKey": {}
348215            }
348216          },
348217          "modelCard": {
348218            "modelParameters": {
348219              "approach": {}
348220            },
348221            "quantitativeAnalysis": {
348222              "graphics": {}
348223            },
348224            "considerations": {}
348225          }
348226        },
348227        {
348228          "type": "library",
348229          "bom-ref": "pkg:golang/github.com/azure/go-autorest/autorest/to@v0.2.0?package-id=9f7d20d4068f1a6a",
348230          "supplier": {},
348231          "name": "github.com/Azure/go-autorest/autorest/to",
348232          "version": "v0.2.0",
348233          "cpe": "cpe:2.3:a:Azure:go-autorest\\/autorest\\/to:v0.2.0:*:*:*:*:*:*:*",
348234          "purl": "pkg:golang/github.com/Azure/go-autorest/autorest/to@v0.2.0",
348235          "swid": {
348236            "attachment": {}
348237          },
348238          "pedigree": {},
348239          "evidence": {},
348240          "signature": {
348241            "signature": {
348242              "publicKey": {}
348243            }
348244          },
348245          "modelCard": {
348246            "modelParameters": {
348247              "approach": {}
348248            },
348249            "quantitativeAnalysis": {
348250              "graphics": {}
348251            },
348252            "considerations": {}
348253          }
348254        },
348255        {
348256          "type": "library",
348257          "bom-ref": "pkg:golang/github.com/azure/go-autorest/logger@v0.1.0?package-id=216af3ec5d3ce06e",
348258          "supplier": {},
348259          "name": "github.com/Azure/go-autorest/logger",
348260          "version": "v0.1.0",
348261          "cpe": "cpe:2.3:a:Azure:go-autorest\\/logger:v0.1.0:*:*:*:*:*:*:*",
348262          "purl": "pkg:golang/github.com/Azure/go-autorest/logger@v0.1.0",
348263          "swid": {
348264            "attachment": {}
348265          },
348266          "pedigree": {},
348267          "evidence": {},
348268          "signature": {
348269            "signature": {
348270              "publicKey": {}
348271            }
348272          },
348273          "modelCard": {
348274            "modelParameters": {
348275              "approach": {}
348276            },
348277            "quantitativeAnalysis": {
348278              "graphics": {}
348279            },
348280            "considerations": {}
348281          }
348282        },
348283        {
348284          "type": "library",
348285          "bom-ref": "pkg:golang/github.com/azure/go-autorest/tracing@v0.5.0?package-id=8ff34c29d03533db",
348286          "supplier": {},
348287          "name": "github.com/Azure/go-autorest/tracing",
348288          "version": "v0.5.0",
348289          "cpe": "cpe:2.3:a:Azure:go-autorest\\/tracing:v0.5.0:*:*:*:*:*:*:*",
348290          "purl": "pkg:golang/github.com/Azure/go-autorest/tracing@v0.5.0",
348291          "swid": {
348292            "attachment": {}
348293          },
348294          "pedigree": {},
348295          "evidence": {},
348296          "signature": {
348297            "signature": {
348298              "publicKey": {}
348299            }
348300          },
348301          "modelCard": {
348302            "modelParameters": {
348303              "approach": {}
348304            },
348305            "quantitativeAnalysis": {
348306              "graphics": {}
348307            },
348308            "considerations": {}
348309          }
348310        },
348311        {
348312          "type": "library",
348313          "bom-ref": "pkg:golang/github.com/datadog/datadog-go@v3.3.1+incompatible?package-id=a27076a3c047cab8",
348314          "supplier": {},
348315          "name": "github.com/DataDog/datadog-go",
348316          "version": "v3.3.1+incompatible",
348317          "cpe": "cpe:2.3:a:DataDog:datadog-go:v3.3.1\\+incompatible:*:*:*:*:*:*:*",
348318          "purl": "pkg:golang/github.com/DataDog/datadog-go@v3.3.1+incompatible",
348319          "swid": {
348320            "attachment": {}
348321          },
348322          "pedigree": {},
348323          "evidence": {},
348324          "signature": {
348325            "signature": {
348326              "publicKey": {}
348327            }
348328          },
348329          "modelCard": {
348330            "modelParameters": {
348331              "approach": {}
348332            },
348333            "quantitativeAnalysis": {
348334              "graphics": {}
348335            },
348336            "considerations": {}
348337          }
348338        },
348339        {
348340          "type": "library",
348341          "bom-ref": "pkg:golang/github.com/shopify/sarama@v1.21.0?package-id=eaf221d2c7aa6df",
348342          "supplier": {},
348343          "name": "github.com/Shopify/sarama",
348344          "version": "v1.21.0",
348345          "cpe": "cpe:2.3:a:Shopify:sarama:v1.21.0:*:*:*:*:*:*:*",
348346          "purl": "pkg:golang/github.com/Shopify/sarama@v1.21.0",
348347          "swid": {
348348            "attachment": {}
348349          },
348350          "pedigree": {},
348351          "evidence": {},
348352          "signature": {
348353            "signature": {
348354              "publicKey": {}
348355            }
348356          },
348357          "modelCard": {
348358            "modelParameters": {
348359              "approach": {}
348360            },
348361            "quantitativeAnalysis": {
348362              "graphics": {}
348363            },
348364            "considerations": {}
348365          }
348366        },
348367        {
348368          "type": "library",
348369          "bom-ref": "pkg:golang/github.com/apache/thrift@v0.13.0?package-id=e147fcd461da7ff9",
348370          "supplier": {},
348371          "name": "github.com/apache/thrift",
348372          "version": "v0.13.0",
348373          "cpe": "cpe:2.3:a:apache:thrift:v0.13.0:*:*:*:*:*:*:*",
348374          "purl": "pkg:golang/github.com/apache/thrift@v0.13.0",
348375          "swid": {
348376            "attachment": {}
348377          },
348378          "pedigree": {},
348379          "evidence": {},
348380          "signature": {
348381            "signature": {
348382              "publicKey": {}
348383            }
348384          },
348385          "modelCard": {
348386            "modelParameters": {
348387              "approach": {}
348388            },
348389            "quantitativeAnalysis": {
348390              "graphics": {}
348391            },
348392            "considerations": {}
348393          }
348394        },
348395        {
348396          "type": "library",
348397          "bom-ref": "pkg:golang/github.com/aws/aws-sdk-go@v1.29.29?package-id=a9224af25cdbeb54",
348398          "supplier": {},
348399          "name": "github.com/aws/aws-sdk-go",
348400          "version": "v1.29.29",
348401          "cpe": "cpe:2.3:a:aws:aws-sdk-go:v1.29.29:*:*:*:*:*:*:*",
348402          "purl": "pkg:golang/github.com/aws/aws-sdk-go@v1.29.29",
348403          "swid": {
348404            "attachment": {}
348405          },
348406          "pedigree": {},
348407          "evidence": {},
348408          "signature": {
348409            "signature": {
348410              "publicKey": {}
348411            }
348412          },
348413          "modelCard": {
348414            "modelParameters": {
348415              "approach": {}
348416            },
348417            "quantitativeAnalysis": {
348418              "graphics": {}
348419            },
348420            "considerations": {}
348421          }
348422        },
348423        {
348424          "type": "library",
348425          "bom-ref": "pkg:golang/github.com/beorn7/perks@v1.0.1?package-id=52930b3fc29070df",
348426          "supplier": {},
348427          "name": "github.com/beorn7/perks",
348428          "version": "v1.0.1",
348429          "cpe": "cpe:2.3:a:beorn7:perks:v1.0.1:*:*:*:*:*:*:*",
348430          "purl": "pkg:golang/github.com/beorn7/perks@v1.0.1",
348431          "swid": {
348432            "attachment": {}
348433          },
348434          "pedigree": {},
348435          "evidence": {},
348436          "signature": {
348437            "signature": {
348438              "publicKey": {}
348439            }
348440          },
348441          "modelCard": {
348442            "modelParameters": {
348443              "approach": {}
348444            },
348445            "quantitativeAnalysis": {
348446              "graphics": {}
348447            },
348448            "considerations": {}
348449          }
348450        },
348451        {
348452          "type": "library",
348453          "bom-ref": "pkg:golang/github.com/caddyserver/caddy@v1.0.5?package-id=85600a527e25b4f2",
348454          "supplier": {},
348455          "name": "github.com/caddyserver/caddy",
348456          "version": "v1.0.5",
348457          "cpe": "cpe:2.3:a:caddyserver:caddy:v1.0.5:*:*:*:*:*:*:*",
348458          "purl": "pkg:golang/github.com/caddyserver/caddy@v1.0.5",
348459          "swid": {
348460            "attachment": {}
348461          },
348462          "pedigree": {},
348463          "evidence": {},
348464          "signature": {
348465            "signature": {
348466              "publicKey": {}
348467            }
348468          },
348469          "modelCard": {
348470            "modelParameters": {
348471              "approach": {}
348472            },
348473            "quantitativeAnalysis": {
348474              "graphics": {}
348475            },
348476            "considerations": {}
348477          }
348478        },
348479        {
348480          "type": "library",
348481          "bom-ref": "pkg:golang/github.com/cenkalti/backoff/v4@v4.0.0?package-id=13171ee0beff187",
348482          "supplier": {},
348483          "name": "github.com/cenkalti/backoff/v4",
348484          "version": "v4.0.0",
348485          "cpe": "cpe:2.3:a:cenkalti:backoff\\/v4:v4.0.0:*:*:*:*:*:*:*",
348486          "purl": "pkg:golang/github.com/cenkalti/backoff/v4@v4.0.0",
348487          "swid": {
348488            "attachment": {}
348489          },
348490          "pedigree": {},
348491          "evidence": {},
348492          "signature": {
348493            "signature": {
348494              "publicKey": {}
348495            }
348496          },
348497          "modelCard": {
348498            "modelParameters": {
348499              "approach": {}
348500            },
348501            "quantitativeAnalysis": {
348502              "graphics": {}
348503            },
348504            "considerations": {}
348505          }
348506        },
348507        {
348508          "type": "library",
348509          "bom-ref": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1?package-id=f101b92cbfbc152",
348510          "supplier": {},
348511          "name": "github.com/cespare/xxhash/v2",
348512          "version": "v2.1.1",
348513          "cpe": "cpe:2.3:a:cespare:xxhash\\/v2:v2.1.1:*:*:*:*:*:*:*",
348514          "purl": "pkg:golang/github.com/cespare/xxhash/v2@v2.1.1",
348515          "swid": {
348516            "attachment": {}
348517          },
348518          "pedigree": {},
348519          "evidence": {},
348520          "signature": {
348521            "signature": {
348522              "publicKey": {}
348523            }
348524          },
348525          "modelCard": {
348526            "modelParameters": {
348527              "approach": {}
348528            },
348529            "quantitativeAnalysis": {
348530              "graphics": {}
348531            },
348532            "considerations": {}
348533          }
348534        },
348535        {
348536          "type": "library",
348537          "bom-ref": "pkg:golang/github.com/coredns/coredns@(devel)?package-id=117d02899ebaf332",
348538          "supplier": {},
348539          "name": "github.com/coredns/coredns",
348540          "version": "(devel)",
348541          "cpe": "cpe:2.3:a:coredns:coredns:\\(devel\\):*:*:*:*:*:*:*",
348542          "purl": "pkg:golang/github.com/coredns/coredns@(devel)",
348543          "swid": {
348544            "attachment": {}
348545          },
348546          "pedigree": {},
348547          "evidence": {},
348548          "signature": {
348549            "signature": {
348550              "publicKey": {}
348551            }
348552          },
348553          "modelCard": {
348554            "modelParameters": {
348555              "approach": {}
348556            },
348557            "quantitativeAnalysis": {
348558              "graphics": {}
348559            },
348560            "considerations": {}
348561          }
348562        },
348563        {
348564          "type": "library",
348565          "bom-ref": "pkg:golang/github.com/coredns/federation@v0.0.0-20190818181423-e032b096babe?package-id=20a3e7a725074e68",
348566          "supplier": {},
348567          "name": "github.com/coredns/federation",
348568          "version": "v0.0.0-20190818181423-e032b096babe",
348569          "cpe": "cpe:2.3:a:coredns:federation:v0.0.0-20190818181423-e032b096babe:*:*:*:*:*:*:*",
348570          "purl": "pkg:golang/github.com/coredns/federation@v0.0.0-20190818181423-e032b096babe",
348571          "swid": {
348572            "attachment": {}
348573          },
348574          "pedigree": {},
348575          "evidence": {},
348576          "signature": {
348577            "signature": {
348578              "publicKey": {}
348579            }
348580          },
348581          "modelCard": {
348582            "modelParameters": {
348583              "approach": {}
348584            },
348585            "quantitativeAnalysis": {
348586              "graphics": {}
348587            },
348588            "considerations": {}
348589          }
348590        },
348591        {
348592          "type": "library",
348593          "bom-ref": "pkg:golang/github.com/coreos/go-systemd/v22@v22.0.0?package-id=53b6a598910d7157",
348594          "supplier": {},
348595          "name": "github.com/coreos/go-systemd/v22",
348596          "version": "v22.0.0",
348597          "cpe": "cpe:2.3:a:coreos:go-systemd\\/v22:v22.0.0:*:*:*:*:*:*:*",
348598          "purl": "pkg:golang/github.com/coreos/go-systemd/v22@v22.0.0",
348599          "swid": {
348600            "attachment": {}
348601          },
348602          "pedigree": {},
348603          "evidence": {},
348604          "signature": {
348605            "signature": {
348606              "publicKey": {}
348607            }
348608          },
348609          "modelCard": {
348610            "modelParameters": {
348611              "approach": {}
348612            },
348613            "quantitativeAnalysis": {
348614              "graphics": {}
348615            },
348616            "considerations": {}
348617          }
348618        },
348619        {
348620          "type": "library",
348621          "bom-ref": "pkg:golang/github.com/davecgh/go-spew@v1.1.1?package-id=54fd106147d0f8a9",
348622          "supplier": {},
348623          "name": "github.com/davecgh/go-spew",
348624          "version": "v1.1.1",
348625          "cpe": "cpe:2.3:a:davecgh:go-spew:v1.1.1:*:*:*:*:*:*:*",
348626          "purl": "pkg:golang/github.com/davecgh/go-spew@v1.1.1",
348627          "swid": {
348628            "attachment": {}
348629          },
348630          "pedigree": {},
348631          "evidence": {},
348632          "signature": {
348633            "signature": {
348634              "publicKey": {}
348635            }
348636          },
348637          "modelCard": {
348638            "modelParameters": {
348639              "approach": {}
348640            },
348641            "quantitativeAnalysis": {
348642              "graphics": {}
348643            },
348644            "considerations": {}
348645          }
348646        },
348647        {
348648          "type": "library",
348649          "bom-ref": "pkg:golang/github.com/dgrijalva/jwt-go@v3.2.0+incompatible?package-id=7fffbbbff5c5f499",
348650          "supplier": {},
348651          "name": "github.com/dgrijalva/jwt-go",
348652          "version": "v3.2.0+incompatible",
348653          "cpe": "cpe:2.3:a:dgrijalva:jwt-go:v3.2.0\\+incompatible:*:*:*:*:*:*:*",
348654          "purl": "pkg:golang/github.com/dgrijalva/jwt-go@v3.2.0+incompatible",
348655          "swid": {
348656            "attachment": {}
348657          },
348658          "pedigree": {},
348659          "evidence": {},
348660          "signature": {
348661            "signature": {
348662              "publicKey": {}
348663            }
348664          },
348665          "modelCard": {
348666            "modelParameters": {
348667              "approach": {}
348668            },
348669            "quantitativeAnalysis": {
348670              "graphics": {}
348671            },
348672            "considerations": {}
348673          }
348674        },
348675        {
348676          "type": "library",
348677          "bom-ref": "pkg:golang/github.com/dimchansky/utfbom@v1.1.0?package-id=267caa0b6cc85b26",
348678          "supplier": {},
348679          "name": "github.com/dimchansky/utfbom",
348680          "version": "v1.1.0",
348681          "cpe": "cpe:2.3:a:dimchansky:utfbom:v1.1.0:*:*:*:*:*:*:*",
348682          "purl": "pkg:golang/github.com/dimchansky/utfbom@v1.1.0",
348683          "swid": {
348684            "attachment": {}
348685          },
348686          "pedigree": {},
348687          "evidence": {},
348688          "signature": {
348689            "signature": {
348690              "publicKey": {}
348691            }
348692          },
348693          "modelCard": {
348694            "modelParameters": {
348695              "approach": {}
348696            },
348697            "quantitativeAnalysis": {
348698              "graphics": {}
348699            },
348700            "considerations": {}
348701          }
348702        },
348703        {
348704          "type": "library",
348705          "bom-ref": "pkg:golang/github.com/dnstap/golang-dnstap@v0.0.0-20170829151710-2cf77a2b5e11?package-id=c3c57d3bc2519d7a",
348706          "supplier": {},
348707          "name": "github.com/dnstap/golang-dnstap",
348708          "version": "v0.0.0-20170829151710-2cf77a2b5e11",
348709          "cpe": "cpe:2.3:a:dnstap:golang-dnstap:v0.0.0-20170829151710-2cf77a2b5e11:*:*:*:*:*:*:*",
348710          "purl": "pkg:golang/github.com/dnstap/golang-dnstap@v0.0.0-20170829151710-2cf77a2b5e11",
348711          "swid": {
348712            "attachment": {}
348713          },
348714          "pedigree": {},
348715          "evidence": {},
348716          "signature": {
348717            "signature": {
348718              "publicKey": {}
348719            }
348720          },
348721          "modelCard": {
348722            "modelParameters": {
348723              "approach": {}
348724            },
348725            "quantitativeAnalysis": {
348726              "graphics": {}
348727            },
348728            "considerations": {}
348729          }
348730        },
348731        {
348732          "type": "library",
348733          "bom-ref": "pkg:golang/github.com/eapache/go-resiliency@v1.1.0?package-id=488d14a1475ed628",
348734          "supplier": {},
348735          "name": "github.com/eapache/go-resiliency",
348736          "version": "v1.1.0",
348737          "cpe": "cpe:2.3:a:eapache:go-resiliency:v1.1.0:*:*:*:*:*:*:*",
348738          "purl": "pkg:golang/github.com/eapache/go-resiliency@v1.1.0",
348739          "swid": {
348740            "attachment": {}
348741          },
348742          "pedigree": {},
348743          "evidence": {},
348744          "signature": {
348745            "signature": {
348746              "publicKey": {}
348747            }
348748          },
348749          "modelCard": {
348750            "modelParameters": {
348751              "approach": {}
348752            },
348753            "quantitativeAnalysis": {
348754              "graphics": {}
348755            },
348756            "considerations": {}
348757          }
348758        },
348759        {
348760          "type": "library",
348761          "bom-ref": "pkg:golang/github.com/eapache/go-xerial-snappy@v0.0.0-20180814174437-776d5712da21?package-id=8d0eb6dd97d40e96",
348762          "supplier": {},
348763          "name": "github.com/eapache/go-xerial-snappy",
348764          "version": "v0.0.0-20180814174437-776d5712da21",
348765          "cpe": "cpe:2.3:a:eapache:go-xerial-snappy:v0.0.0-20180814174437-776d5712da21:*:*:*:*:*:*:*",
348766          "purl": "pkg:golang/github.com/eapache/go-xerial-snappy@v0.0.0-20180814174437-776d5712da21",
348767          "swid": {
348768            "attachment": {}
348769          },
348770          "pedigree": {},
348771          "evidence": {},
348772          "signature": {
348773            "signature": {
348774              "publicKey": {}
348775            }
348776          },
348777          "modelCard": {
348778            "modelParameters": {
348779              "approach": {}
348780            },
348781            "quantitativeAnalysis": {
348782              "graphics": {}
348783            },
348784            "considerations": {}
348785          }
348786        },
348787        {
348788          "type": "library",
348789          "bom-ref": "pkg:golang/github.com/eapache/queue@v1.1.0?package-id=91394bfa341034b2",
348790          "supplier": {},
348791          "name": "github.com/eapache/queue",
348792          "version": "v1.1.0",
348793          "cpe": "cpe:2.3:a:eapache:queue:v1.1.0:*:*:*:*:*:*:*",
348794          "purl": "pkg:golang/github.com/eapache/queue@v1.1.0",
348795          "swid": {
348796            "attachment": {}
348797          },
348798          "pedigree": {},
348799          "evidence": {},
348800          "signature": {
348801            "signature": {
348802              "publicKey": {}
348803            }
348804          },
348805          "modelCard": {
348806            "modelParameters": {
348807              "approach": {}
348808            },
348809            "quantitativeAnalysis": {
348810              "graphics": {}
348811            },
348812            "considerations": {}
348813          }
348814        },
348815        {
348816          "type": "library",
348817          "bom-ref": "pkg:golang/github.com/farsightsec/golang-framestream@v0.0.0-20181102145529-8a0cb8ba8710?package-id=f84e52938be3ec4f",
348818          "supplier": {},
348819          "name": "github.com/farsightsec/golang-framestream",
348820          "version": "v0.0.0-20181102145529-8a0cb8ba8710",
348821          "cpe": "cpe:2.3:a:farsightsec:golang-framestream:v0.0.0-20181102145529-8a0cb8ba8710:*:*:*:*:*:*:*",
348822          "purl": "pkg:golang/github.com/farsightsec/golang-framestream@v0.0.0-20181102145529-8a0cb8ba8710",
348823          "swid": {
348824            "attachment": {}
348825          },
348826          "pedigree": {},
348827          "evidence": {},
348828          "signature": {
348829            "signature": {
348830              "publicKey": {}
348831            }
348832          },
348833          "modelCard": {
348834            "modelParameters": {
348835              "approach": {}
348836            },
348837            "quantitativeAnalysis": {
348838              "graphics": {}
348839            },
348840            "considerations": {}
348841          }
348842        },
348843        {
348844          "type": "library",
348845          "bom-ref": "pkg:golang/github.com/flynn/go-shlex@v0.0.0-20150515145356-3f9db97f8568?package-id=4c58da22ef286b06",
348846          "supplier": {},
348847          "name": "github.com/flynn/go-shlex",
348848          "version": "v0.0.0-20150515145356-3f9db97f8568",
348849          "cpe": "cpe:2.3:a:flynn:go-shlex:v0.0.0-20150515145356-3f9db97f8568:*:*:*:*:*:*:*",
348850          "purl": "pkg:golang/github.com/flynn/go-shlex@v0.0.0-20150515145356-3f9db97f8568",
348851          "swid": {
348852            "attachment": {}
348853          },
348854          "pedigree": {},
348855          "evidence": {},
348856          "signature": {
348857            "signature": {
348858              "publicKey": {}
348859            }
348860          },
348861          "modelCard": {
348862            "modelParameters": {
348863              "approach": {}
348864            },
348865            "quantitativeAnalysis": {
348866              "graphics": {}
348867            },
348868            "considerations": {}
348869          }
348870        },
348871        {
348872          "type": "library",
348873          "bom-ref": "pkg:golang/github.com/go-logfmt/logfmt@v0.4.0?package-id=48bd83d6ce1cf750",
348874          "supplier": {},
348875          "name": "github.com/go-logfmt/logfmt",
348876          "version": "v0.4.0",
348877          "cpe": "cpe:2.3:a:go-logfmt:logfmt:v0.4.0:*:*:*:*:*:*:*",
348878          "purl": "pkg:golang/github.com/go-logfmt/logfmt@v0.4.0",
348879          "swid": {
348880            "attachment": {}
348881          },
348882          "pedigree": {},
348883          "evidence": {},
348884          "signature": {
348885            "signature": {
348886              "publicKey": {}
348887            }
348888          },
348889          "modelCard": {
348890            "modelParameters": {
348891              "approach": {}
348892            },
348893            "quantitativeAnalysis": {
348894              "graphics": {}
348895            },
348896            "considerations": {}
348897          }
348898        },
348899        {
348900          "type": "library",
348901          "bom-ref": "pkg:golang/github.com/gogo/protobuf@v1.2.2-0.20190723190241-65acae22fc9d?package-id=d32a4438e8a16d2f",
348902          "supplier": {},
348903          "name": "github.com/gogo/protobuf",
348904          "version": "v1.2.2-0.20190723190241-65acae22fc9d",
348905          "cpe": "cpe:2.3:a:gogo:protobuf:v1.2.2-0.20190723190241-65acae22fc9d:*:*:*:*:*:*:*",
348906          "purl": "pkg:golang/github.com/gogo/protobuf@v1.2.2-0.20190723190241-65acae22fc9d",
348907          "swid": {
348908            "attachment": {}
348909          },
348910          "pedigree": {},
348911          "evidence": {},
348912          "signature": {
348913            "signature": {
348914              "publicKey": {}
348915            }
348916          },
348917          "modelCard": {
348918            "modelParameters": {
348919              "approach": {}
348920            },
348921            "quantitativeAnalysis": {
348922              "graphics": {}
348923            },
348924            "considerations": {}
348925          }
348926        },
348927        {
348928          "type": "library",
348929          "bom-ref": "pkg:golang/github.com/golang/protobuf@v1.3.5?package-id=182ac6739304deb1",
348930          "supplier": {},
348931          "name": "github.com/golang/protobuf",
348932          "version": "v1.3.5",
348933          "cpe": "cpe:2.3:a:golang:protobuf:v1.3.5:*:*:*:*:*:*:*",
348934          "purl": "pkg:golang/github.com/golang/protobuf@v1.3.5",
348935          "swid": {
348936            "attachment": {}
348937          },
348938          "pedigree": {},
348939          "evidence": {},
348940          "signature": {
348941            "signature": {
348942              "publicKey": {}
348943            }
348944          },
348945          "modelCard": {
348946            "modelParameters": {
348947              "approach": {}
348948            },
348949            "quantitativeAnalysis": {
348950              "graphics": {}
348951            },
348952            "considerations": {}
348953          }
348954        },
348955        {
348956          "type": "library",
348957          "bom-ref": "pkg:golang/github.com/golang/snappy@v0.0.0-20180518054509-2e65f85255db?package-id=af4bab8bcb4ba040",
348958          "supplier": {},
348959          "name": "github.com/golang/snappy",
348960          "version": "v0.0.0-20180518054509-2e65f85255db",
348961          "cpe": "cpe:2.3:a:golang:snappy:v0.0.0-20180518054509-2e65f85255db:*:*:*:*:*:*:*",
348962          "purl": "pkg:golang/github.com/golang/snappy@v0.0.0-20180518054509-2e65f85255db",
348963          "swid": {
348964            "attachment": {}
348965          },
348966          "pedigree": {},
348967          "evidence": {},
348968          "signature": {
348969            "signature": {
348970              "publicKey": {}
348971            }
348972          },
348973          "modelCard": {
348974            "modelParameters": {
348975              "approach": {}
348976            },
348977            "quantitativeAnalysis": {
348978              "graphics": {}
348979            },
348980            "considerations": {}
348981          }
348982        },
348983        {
348984          "type": "library",
348985          "bom-ref": "pkg:golang/github.com/google/go-cmp@v0.4.0?package-id=742d87db6dc9fbe",
348986          "supplier": {},
348987          "name": "github.com/google/go-cmp",
348988          "version": "v0.4.0",
348989          "cpe": "cpe:2.3:a:google:go-cmp:v0.4.0:*:*:*:*:*:*:*",
348990          "purl": "pkg:golang/github.com/google/go-cmp@v0.4.0",
348991          "swid": {
348992            "attachment": {}
348993          },
348994          "pedigree": {},
348995          "evidence": {},
348996          "signature": {
348997            "signature": {
348998              "publicKey": {}
348999            }
349000          },
349001          "modelCard": {
349002            "modelParameters": {
349003              "approach": {}
349004            },
349005            "quantitativeAnalysis": {
349006              "graphics": {}
349007            },
349008            "considerations": {}
349009          }
349010        },
349011        {
349012          "type": "library",
349013          "bom-ref": "pkg:golang/github.com/google/gofuzz@v1.0.0?package-id=80937add7745a5ac",
349014          "supplier": {},
349015          "name": "github.com/google/gofuzz",
349016          "version": "v1.0.0",
349017          "cpe": "cpe:2.3:a:google:gofuzz:v1.0.0:*:*:*:*:*:*:*",
349018          "purl": "pkg:golang/github.com/google/gofuzz@v1.0.0",
349019          "swid": {
349020            "attachment": {}
349021          },
349022          "pedigree": {},
349023          "evidence": {},
349024          "signature": {
349025            "signature": {
349026              "publicKey": {}
349027            }
349028          },
349029          "modelCard": {
349030            "modelParameters": {
349031              "approach": {}
349032            },
349033            "quantitativeAnalysis": {
349034              "graphics": {}
349035            },
349036            "considerations": {}
349037          }
349038        },
349039        {
349040          "type": "library",
349041          "bom-ref": "pkg:golang/github.com/google/uuid@v1.1.1?package-id=3c8fa4339403903",
349042          "supplier": {},
349043          "name": "github.com/google/uuid",
349044          "version": "v1.1.1",
349045          "cpe": "cpe:2.3:a:google:uuid:v1.1.1:*:*:*:*:*:*:*",
349046          "purl": "pkg:golang/github.com/google/uuid@v1.1.1",
349047          "swid": {
349048            "attachment": {}
349049          },
349050          "pedigree": {},
349051          "evidence": {},
349052          "signature": {
349053            "signature": {
349054              "publicKey": {}
349055            }
349056          },
349057          "modelCard": {
349058            "modelParameters": {
349059              "approach": {}
349060            },
349061            "quantitativeAnalysis": {
349062              "graphics": {}
349063            },
349064            "considerations": {}
349065          }
349066        },
349067        {
349068          "type": "library",
349069          "bom-ref": "pkg:golang/github.com/googleapis/gax-go/v2@v2.0.5?package-id=4169ac774adb8d2d",
349070          "supplier": {},
349071          "name": "github.com/googleapis/gax-go/v2",
349072          "version": "v2.0.5",
349073          "cpe": "cpe:2.3:a:googleapis:gax-go\\/v2:v2.0.5:*:*:*:*:*:*:*",
349074          "purl": "pkg:golang/github.com/googleapis/gax-go/v2@v2.0.5",
349075          "swid": {
349076            "attachment": {}
349077          },
349078          "pedigree": {},
349079          "evidence": {},
349080          "signature": {
349081            "signature": {
349082              "publicKey": {}
349083            }
349084          },
349085          "modelCard": {
349086            "modelParameters": {
349087              "approach": {}
349088            },
349089            "quantitativeAnalysis": {
349090              "graphics": {}
349091            },
349092            "considerations": {}
349093          }
349094        },
349095        {
349096          "type": "library",
349097          "bom-ref": "pkg:golang/github.com/googleapis/gnostic@v0.2.0?package-id=d40e0ca1859eb9b2",
349098          "supplier": {},
349099          "name": "github.com/googleapis/gnostic",
349100          "version": "v0.2.0",
349101          "cpe": "cpe:2.3:a:googleapis:gnostic:v0.2.0:*:*:*:*:*:*:*",
349102          "purl": "pkg:golang/github.com/googleapis/gnostic@v0.2.0",
349103          "swid": {
349104            "attachment": {}
349105          },
349106          "pedigree": {},
349107          "evidence": {},
349108          "signature": {
349109            "signature": {
349110              "publicKey": {}
349111            }
349112          },
349113          "modelCard": {
349114            "modelParameters": {
349115              "approach": {}
349116            },
349117            "quantitativeAnalysis": {
349118              "graphics": {}
349119            },
349120            "considerations": {}
349121          }
349122        },
349123        {
349124          "type": "library",
349125          "bom-ref": "pkg:golang/github.com/gophercloud/gophercloud@v0.3.0?package-id=6d9d2dffd7ff65b5",
349126          "supplier": {},
349127          "name": "github.com/gophercloud/gophercloud",
349128          "version": "v0.3.0",
349129          "cpe": "cpe:2.3:a:gophercloud:gophercloud:v0.3.0:*:*:*:*:*:*:*",
349130          "purl": "pkg:golang/github.com/gophercloud/gophercloud@v0.3.0",
349131          "swid": {
349132            "attachment": {}
349133          },
349134          "pedigree": {},
349135          "evidence": {},
349136          "signature": {
349137            "signature": {
349138              "publicKey": {}
349139            }
349140          },
349141          "modelCard": {
349142            "modelParameters": {
349143              "approach": {}
349144            },
349145            "quantitativeAnalysis": {
349146              "graphics": {}
349147            },
349148            "considerations": {}
349149          }
349150        },
349151        {
349152          "type": "library",
349153          "bom-ref": "pkg:golang/github.com/grpc-ecosystem/grpc-opentracing@v0.0.0-20180507213350-8e809c8a8645?package-id=9d69f6483f11d50",
349154          "supplier": {},
349155          "name": "github.com/grpc-ecosystem/grpc-opentracing",
349156          "version": "v0.0.0-20180507213350-8e809c8a8645",
349157          "cpe": "cpe:2.3:a:grpc-ecosystem:grpc-opentracing:v0.0.0-20180507213350-8e809c8a8645:*:*:*:*:*:*:*",
349158          "purl": "pkg:golang/github.com/grpc-ecosystem/grpc-opentracing@v0.0.0-20180507213350-8e809c8a8645",
349159          "swid": {
349160            "attachment": {}
349161          },
349162          "pedigree": {},
349163          "evidence": {},
349164          "signature": {
349165            "signature": {
349166              "publicKey": {}
349167            }
349168          },
349169          "modelCard": {
349170            "modelParameters": {
349171              "approach": {}
349172            },
349173            "quantitativeAnalysis": {
349174              "graphics": {}
349175            },
349176            "considerations": {}
349177          }
349178        },
349179        {
349180          "type": "library",
349181          "bom-ref": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.3?package-id=1e13b7a41e65a84b",
349182          "supplier": {},
349183          "name": "github.com/hashicorp/golang-lru",
349184          "version": "v0.5.3",
349185          "cpe": "cpe:2.3:a:hashicorp:golang-lru:v0.5.3:*:*:*:*:*:*:*",
349186          "purl": "pkg:golang/github.com/hashicorp/golang-lru@v0.5.3",
349187          "swid": {
349188            "attachment": {}
349189          },
349190          "pedigree": {},
349191          "evidence": {},
349192          "signature": {
349193            "signature": {
349194              "publicKey": {}
349195            }
349196          },
349197          "modelCard": {
349198            "modelParameters": {
349199              "approach": {}
349200            },
349201            "quantitativeAnalysis": {
349202              "graphics": {}
349203            },
349204            "considerations": {}
349205          }
349206        },
349207        {
349208          "type": "library",
349209          "bom-ref": "pkg:golang/github.com/imdario/mergo@v0.3.7?package-id=254f34919256cafd",
349210          "supplier": {},
349211          "name": "github.com/imdario/mergo",
349212          "version": "v0.3.7",
349213          "cpe": "cpe:2.3:a:imdario:mergo:v0.3.7:*:*:*:*:*:*:*",
349214          "purl": "pkg:golang/github.com/imdario/mergo@v0.3.7",
349215          "swid": {
349216            "attachment": {}
349217          },
349218          "pedigree": {},
349219          "evidence": {},
349220          "signature": {
349221            "signature": {
349222              "publicKey": {}
349223            }
349224          },
349225          "modelCard": {
349226            "modelParameters": {
349227              "approach": {}
349228            },
349229            "quantitativeAnalysis": {
349230              "graphics": {}
349231            },
349232            "considerations": {}
349233          }
349234        },
349235        {
349236          "type": "library",
349237          "bom-ref": "pkg:golang/github.com/infobloxopen/go-trees@v0.0.0-20190313150506-2af4e13f9062?package-id=dba1f0cd6944902c",
349238          "supplier": {},
349239          "name": "github.com/infobloxopen/go-trees",
349240          "version": "v0.0.0-20190313150506-2af4e13f9062",
349241          "cpe": "cpe:2.3:a:infobloxopen:go-trees:v0.0.0-20190313150506-2af4e13f9062:*:*:*:*:*:*:*",
349242          "purl": "pkg:golang/github.com/infobloxopen/go-trees@v0.0.0-20190313150506-2af4e13f9062",
349243          "swid": {
349244            "attachment": {}
349245          },
349246          "pedigree": {},
349247          "evidence": {},
349248          "signature": {
349249            "signature": {
349250              "publicKey": {}
349251            }
349252          },
349253          "modelCard": {
349254            "modelParameters": {
349255              "approach": {}
349256            },
349257            "quantitativeAnalysis": {
349258              "graphics": {}
349259            },
349260            "considerations": {}
349261          }
349262        },
349263        {
349264          "type": "library",
349265          "bom-ref": "pkg:golang/github.com/jmespath/go-jmespath@v0.0.0-20180206201540-c2b33e8439af?package-id=47fce3ef1132ef06",
349266          "supplier": {},
349267          "name": "github.com/jmespath/go-jmespath",
349268          "version": "v0.0.0-20180206201540-c2b33e8439af",
349269          "cpe": "cpe:2.3:a:jmespath:go-jmespath:v0.0.0-20180206201540-c2b33e8439af:*:*:*:*:*:*:*",
349270          "purl": "pkg:golang/github.com/jmespath/go-jmespath@v0.0.0-20180206201540-c2b33e8439af",
349271          "swid": {
349272            "attachment": {}
349273          },
349274          "pedigree": {},
349275          "evidence": {},
349276          "signature": {
349277            "signature": {
349278              "publicKey": {}
349279            }
349280          },
349281          "modelCard": {
349282            "modelParameters": {
349283              "approach": {}
349284            },
349285            "quantitativeAnalysis": {
349286              "graphics": {}
349287            },
349288            "considerations": {}
349289          }
349290        },
349291        {
349292          "type": "library",
349293          "bom-ref": "pkg:golang/github.com/json-iterator/go@v1.1.9?package-id=d97080d5d5518148",
349294          "supplier": {},
349295          "name": "github.com/json-iterator/go",
349296          "version": "v1.1.9",
349297          "cpe": "cpe:2.3:a:json-iterator:go:v1.1.9:*:*:*:*:*:*:*",
349298          "purl": "pkg:golang/github.com/json-iterator/go@v1.1.9",
349299          "swid": {
349300            "attachment": {}
349301          },
349302          "pedigree": {},
349303          "evidence": {},
349304          "signature": {
349305            "signature": {
349306              "publicKey": {}
349307            }
349308          },
349309          "modelCard": {
349310            "modelParameters": {
349311              "approach": {}
349312            },
349313            "quantitativeAnalysis": {
349314              "graphics": {}
349315            },
349316            "considerations": {}
349317          }
349318        },
349319        {
349320          "type": "library",
349321          "bom-ref": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.1?package-id=5820405d5aabd892",
349322          "supplier": {},
349323          "name": "github.com/matttproud/golang_protobuf_extensions",
349324          "version": "v1.0.1",
349325          "cpe": "cpe:2.3:a:matttproud:golang-protobuf-extensions:v1.0.1:*:*:*:*:*:*:*",
349326          "purl": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.1",
349327          "swid": {
349328            "attachment": {}
349329          },
349330          "pedigree": {},
349331          "evidence": {},
349332          "signature": {
349333            "signature": {
349334              "publicKey": {}
349335            }
349336          },
349337          "modelCard": {
349338            "modelParameters": {
349339              "approach": {}
349340            },
349341            "quantitativeAnalysis": {
349342              "graphics": {}
349343            },
349344            "considerations": {}
349345          }
349346        },
349347        {
349348          "type": "library",
349349          "bom-ref": "pkg:golang/github.com/miekg/dns@v1.1.29?package-id=c66cc2c7565f5bc3",
349350          "supplier": {},
349351          "name": "github.com/miekg/dns",
349352          "version": "v1.1.29",
349353          "cpe": "cpe:2.3:a:miekg:dns:v1.1.29:*:*:*:*:*:*:*",
349354          "purl": "pkg:golang/github.com/miekg/dns@v1.1.29",
349355          "swid": {
349356            "attachment": {}
349357          },
349358          "pedigree": {},
349359          "evidence": {},
349360          "signature": {
349361            "signature": {
349362              "publicKey": {}
349363            }
349364          },
349365          "modelCard": {
349366            "modelParameters": {
349367              "approach": {}
349368            },
349369            "quantitativeAnalysis": {
349370              "graphics": {}
349371            },
349372            "considerations": {}
349373          }
349374        },
349375        {
349376          "type": "library",
349377          "bom-ref": "pkg:golang/github.com/mitchellh/go-homedir@v1.1.0?package-id=b09eab509586ff1b",
349378          "supplier": {},
349379          "name": "github.com/mitchellh/go-homedir",
349380          "version": "v1.1.0",
349381          "cpe": "cpe:2.3:a:mitchellh:go-homedir:v1.1.0:*:*:*:*:*:*:*",
349382          "purl": "pkg:golang/github.com/mitchellh/go-homedir@v1.1.0",
349383          "swid": {
349384            "attachment": {}
349385          },
349386          "pedigree": {},
349387          "evidence": {},
349388          "signature": {
349389            "signature": {
349390              "publicKey": {}
349391            }
349392          },
349393          "modelCard": {
349394            "modelParameters": {
349395              "approach": {}
349396            },
349397            "quantitativeAnalysis": {
349398              "graphics": {}
349399            },
349400            "considerations": {}
349401          }
349402        },
349403        {
349404          "type": "library",
349405          "bom-ref": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd?package-id=afda18af5747b2ef",
349406          "supplier": {},
349407          "name": "github.com/modern-go/concurrent",
349408          "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
349409          "cpe": "cpe:2.3:a:modern-go:concurrent:v0.0.0-20180306012644-bacd9c7ef1dd:*:*:*:*:*:*:*",
349410          "purl": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd",
349411          "swid": {
349412            "attachment": {}
349413          },
349414          "pedigree": {},
349415          "evidence": {},
349416          "signature": {
349417            "signature": {
349418              "publicKey": {}
349419            }
349420          },
349421          "modelCard": {
349422            "modelParameters": {
349423              "approach": {}
349424            },
349425            "quantitativeAnalysis": {
349426              "graphics": {}
349427            },
349428            "considerations": {}
349429          }
349430        },
349431        {
349432          "type": "library",
349433          "bom-ref": "pkg:golang/github.com/modern-go/reflect2@v1.0.1?package-id=e8aca82a6c9a5b9c",
349434          "supplier": {},
349435          "name": "github.com/modern-go/reflect2",
349436          "version": "v1.0.1",
349437          "cpe": "cpe:2.3:a:modern-go:reflect2:v1.0.1:*:*:*:*:*:*:*",
349438          "purl": "pkg:golang/github.com/modern-go/reflect2@v1.0.1",
349439          "swid": {
349440            "attachment": {}
349441          },
349442          "pedigree": {},
349443          "evidence": {},
349444          "signature": {
349445            "signature": {
349446              "publicKey": {}
349447            }
349448          },
349449          "modelCard": {
349450            "modelParameters": {
349451              "approach": {}
349452            },
349453            "quantitativeAnalysis": {
349454              "graphics": {}
349455            },
349456            "considerations": {}
349457          }
349458        },
349459        {
349460          "type": "library",
349461          "bom-ref": "pkg:golang/github.com/opentracing-contrib/go-observer@v0.0.0-20170622124052-a52f23424492?package-id=6f6f55dce43fe782",
349462          "supplier": {},
349463          "name": "github.com/opentracing-contrib/go-observer",
349464          "version": "v0.0.0-20170622124052-a52f23424492",
349465          "cpe": "cpe:2.3:a:opentracing-contrib:go-observer:v0.0.0-20170622124052-a52f23424492:*:*:*:*:*:*:*",
349466          "purl": "pkg:golang/github.com/opentracing-contrib/go-observer@v0.0.0-20170622124052-a52f23424492",
349467          "swid": {
349468            "attachment": {}
349469          },
349470          "pedigree": {},
349471          "evidence": {},
349472          "signature": {
349473            "signature": {
349474              "publicKey": {}
349475            }
349476          },
349477          "modelCard": {
349478            "modelParameters": {
349479              "approach": {}
349480            },
349481            "quantitativeAnalysis": {
349482              "graphics": {}
349483            },
349484            "considerations": {}
349485          }
349486        },
349487        {
349488          "type": "library",
349489          "bom-ref": "pkg:golang/github.com/opentracing/opentracing-go@v1.1.0?package-id=994d66ab2a1908ec",
349490          "supplier": {},
349491          "name": "github.com/opentracing/opentracing-go",
349492          "version": "v1.1.0",
349493          "cpe": "cpe:2.3:a:opentracing:opentracing-go:v1.1.0:*:*:*:*:*:*:*",
349494          "purl": "pkg:golang/github.com/opentracing/opentracing-go@v1.1.0",
349495          "swid": {
349496            "attachment": {}
349497          },
349498          "pedigree": {},
349499          "evidence": {},
349500          "signature": {
349501            "signature": {
349502              "publicKey": {}
349503            }
349504          },
349505          "modelCard": {
349506            "modelParameters": {
349507              "approach": {}
349508            },
349509            "quantitativeAnalysis": {
349510              "graphics": {}
349511            },
349512            "considerations": {}
349513          }
349514        },
349515        {
349516          "type": "library",
349517          "bom-ref": "pkg:golang/github.com/openzipkin-contrib/zipkin-go-opentracing@v0.3.5?package-id=bc287321e74232db",
349518          "supplier": {},
349519          "name": "github.com/openzipkin-contrib/zipkin-go-opentracing",
349520          "version": "v0.3.5",
349521          "cpe": "cpe:2.3:a:openzipkin-contrib:zipkin-go-opentracing:v0.3.5:*:*:*:*:*:*:*",
349522          "purl": "pkg:golang/github.com/openzipkin-contrib/zipkin-go-opentracing@v0.3.5",
349523          "swid": {
349524            "attachment": {}
349525          },
349526          "pedigree": {},
349527          "evidence": {},
349528          "signature": {
349529            "signature": {
349530              "publicKey": {}
349531            }
349532          },
349533          "modelCard": {
349534            "modelParameters": {
349535              "approach": {}
349536            },
349537            "quantitativeAnalysis": {
349538              "graphics": {}
349539            },
349540            "considerations": {}
349541          }
349542        },
349543        {
349544          "type": "library",
349545          "bom-ref": "pkg:golang/github.com/philhofer/fwd@v1.0.0?package-id=cbde36ae73f92538",
349546          "supplier": {},
349547          "name": "github.com/philhofer/fwd",
349548          "version": "v1.0.0",
349549          "cpe": "cpe:2.3:a:philhofer:fwd:v1.0.0:*:*:*:*:*:*:*",
349550          "purl": "pkg:golang/github.com/philhofer/fwd@v1.0.0",
349551          "swid": {
349552            "attachment": {}
349553          },
349554          "pedigree": {},
349555          "evidence": {},
349556          "signature": {
349557            "signature": {
349558              "publicKey": {}
349559            }
349560          },
349561          "modelCard": {
349562            "modelParameters": {
349563              "approach": {}
349564            },
349565            "quantitativeAnalysis": {
349566              "graphics": {}
349567            },
349568            "considerations": {}
349569          }
349570        },
349571        {
349572          "type": "library",
349573          "bom-ref": "pkg:golang/github.com/pierrec/lz4@v2.0.5+incompatible?package-id=dd15741fb4470eff",
349574          "supplier": {},
349575          "name": "github.com/pierrec/lz4",
349576          "version": "v2.0.5+incompatible",
349577          "cpe": "cpe:2.3:a:pierrec:lz4:v2.0.5\\+incompatible:*:*:*:*:*:*:*",
349578          "purl": "pkg:golang/github.com/pierrec/lz4@v2.0.5+incompatible",
349579          "swid": {
349580            "attachment": {}
349581          },
349582          "pedigree": {},
349583          "evidence": {},
349584          "signature": {
349585            "signature": {
349586              "publicKey": {}
349587            }
349588          },
349589          "modelCard": {
349590            "modelParameters": {
349591              "approach": {}
349592            },
349593            "quantitativeAnalysis": {
349594              "graphics": {}
349595            },
349596            "considerations": {}
349597          }
349598        },
349599        {
349600          "type": "library",
349601          "bom-ref": "pkg:golang/github.com/prometheus/client_golang@v1.5.1?package-id=447e1d1a0ff5dd38",
349602          "supplier": {},
349603          "name": "github.com/prometheus/client_golang",
349604          "version": "v1.5.1",
349605          "cpe": "cpe:2.3:a:prometheus:client-golang:v1.5.1:*:*:*:*:*:*:*",
349606          "purl": "pkg:golang/github.com/prometheus/client_golang@v1.5.1",
349607          "swid": {
349608            "attachment": {}
349609          },
349610          "pedigree": {},
349611          "evidence": {},
349612          "signature": {
349613            "signature": {
349614              "publicKey": {}
349615            }
349616          },
349617          "modelCard": {
349618            "modelParameters": {
349619              "approach": {}
349620            },
349621            "quantitativeAnalysis": {
349622              "graphics": {}
349623            },
349624            "considerations": {}
349625          }
349626        },
349627        {
349628          "type": "library",
349629          "bom-ref": "pkg:golang/github.com/prometheus/client_model@v0.2.0?package-id=e3df7afe3464948b",
349630          "supplier": {},
349631          "name": "github.com/prometheus/client_model",
349632          "version": "v0.2.0",
349633          "cpe": "cpe:2.3:a:prometheus:client-model:v0.2.0:*:*:*:*:*:*:*",
349634          "purl": "pkg:golang/github.com/prometheus/client_model@v0.2.0",
349635          "swid": {
349636            "attachment": {}
349637          },
349638          "pedigree": {},
349639          "evidence": {},
349640          "signature": {
349641            "signature": {
349642              "publicKey": {}
349643            }
349644          },
349645          "modelCard": {
349646            "modelParameters": {
349647              "approach": {}
349648            },
349649            "quantitativeAnalysis": {
349650              "graphics": {}
349651            },
349652            "considerations": {}
349653          }
349654        },
349655        {
349656          "type": "library",
349657          "bom-ref": "pkg:golang/github.com/prometheus/common@v0.9.1?package-id=b19454d9abddffd9",
349658          "supplier": {},
349659          "name": "github.com/prometheus/common",
349660          "version": "v0.9.1",
349661          "cpe": "cpe:2.3:a:prometheus:common:v0.9.1:*:*:*:*:*:*:*",
349662          "purl": "pkg:golang/github.com/prometheus/common@v0.9.1",
349663          "swid": {
349664            "attachment": {}
349665          },
349666          "pedigree": {},
349667          "evidence": {},
349668          "signature": {
349669            "signature": {
349670              "publicKey": {}
349671            }
349672          },
349673          "modelCard": {
349674            "modelParameters": {
349675              "approach": {}
349676            },
349677            "quantitativeAnalysis": {
349678              "graphics": {}
349679            },
349680            "considerations": {}
349681          }
349682        },
349683        {
349684          "type": "library",
349685          "bom-ref": "pkg:golang/github.com/prometheus/procfs@v0.0.8?package-id=d68ec0c5e71e41b3",
349686          "supplier": {},
349687          "name": "github.com/prometheus/procfs",
349688          "version": "v0.0.8",
349689          "cpe": "cpe:2.3:a:prometheus:procfs:v0.0.8:*:*:*:*:*:*:*",
349690          "purl": "pkg:golang/github.com/prometheus/procfs@v0.0.8",
349691          "swid": {
349692            "attachment": {}
349693          },
349694          "pedigree": {},
349695          "evidence": {},
349696          "signature": {
349697            "signature": {
349698              "publicKey": {}
349699            }
349700          },
349701          "modelCard": {
349702            "modelParameters": {
349703              "approach": {}
349704            },
349705            "quantitativeAnalysis": {
349706              "graphics": {}
349707            },
349708            "considerations": {}
349709          }
349710        },
349711        {
349712          "type": "library",
349713          "bom-ref": "pkg:golang/github.com/rcrowley/go-metrics@v0.0.0-20181016184325-3113b8401b8a?package-id=8319912f7878c97c",
349714          "supplier": {},
349715          "name": "github.com/rcrowley/go-metrics",
349716          "version": "v0.0.0-20181016184325-3113b8401b8a",
349717          "cpe": "cpe:2.3:a:rcrowley:go-metrics:v0.0.0-20181016184325-3113b8401b8a:*:*:*:*:*:*:*",
349718          "purl": "pkg:golang/github.com/rcrowley/go-metrics@v0.0.0-20181016184325-3113b8401b8a",
349719          "swid": {
349720            "attachment": {}
349721          },
349722          "pedigree": {},
349723          "evidence": {},
349724          "signature": {
349725            "signature": {
349726              "publicKey": {}
349727            }
349728          },
349729          "modelCard": {
349730            "modelParameters": {
349731              "approach": {}
349732            },
349733            "quantitativeAnalysis": {
349734              "graphics": {}
349735            },
349736            "considerations": {}
349737          }
349738        },
349739        {
349740          "type": "library",
349741          "bom-ref": "pkg:golang/github.com/spf13/pflag@v1.0.5?package-id=2e52528de2accf8d",
349742          "supplier": {},
349743          "name": "github.com/spf13/pflag",
349744          "version": "v1.0.5",
349745          "cpe": "cpe:2.3:a:spf13:pflag:v1.0.5:*:*:*:*:*:*:*",
349746          "purl": "pkg:golang/github.com/spf13/pflag@v1.0.5",
349747          "swid": {
349748            "attachment": {}
349749          },
349750          "pedigree": {},
349751          "evidence": {},
349752          "signature": {
349753            "signature": {
349754              "publicKey": {}
349755            }
349756          },
349757          "modelCard": {
349758            "modelParameters": {
349759              "approach": {}
349760            },
349761            "quantitativeAnalysis": {
349762              "graphics": {}
349763            },
349764            "considerations": {}
349765          }
349766        },
349767        {
349768          "type": "library",
349769          "bom-ref": "pkg:golang/github.com/tinylib/msgp@v1.1.0?package-id=696ba0694aae735b",
349770          "supplier": {},
349771          "name": "github.com/tinylib/msgp",
349772          "version": "v1.1.0",
349773          "cpe": "cpe:2.3:a:tinylib:msgp:v1.1.0:*:*:*:*:*:*:*",
349774          "purl": "pkg:golang/github.com/tinylib/msgp@v1.1.0",
349775          "swid": {
349776            "attachment": {}
349777          },
349778          "pedigree": {},
349779          "evidence": {},
349780          "signature": {
349781            "signature": {
349782              "publicKey": {}
349783            }
349784          },
349785          "modelCard": {
349786            "modelParameters": {
349787              "approach": {}
349788            },
349789            "quantitativeAnalysis": {
349790              "graphics": {}
349791            },
349792            "considerations": {}
349793          }
349794        },
349795        {
349796          "type": "library",
349797          "bom-ref": "pkg:golang/go.etcd.io/etcd@v0.5.0-alpha.5.0.20200306183522-221f0cc107cb?package-id=2cee92e1001a2476",
349798          "supplier": {},
349799          "name": "go.etcd.io/etcd",
349800          "version": "v0.5.0-alpha.5.0.20200306183522-221f0cc107cb",
349801          "purl": "pkg:golang/go.etcd.io/etcd@v0.5.0-alpha.5.0.20200306183522-221f0cc107cb",
349802          "swid": {
349803            "attachment": {}
349804          },
349805          "pedigree": {},
349806          "evidence": {},
349807          "signature": {
349808            "signature": {
349809              "publicKey": {}
349810            }
349811          },
349812          "modelCard": {
349813            "modelParameters": {
349814              "approach": {}
349815            },
349816            "quantitativeAnalysis": {
349817              "graphics": {}
349818            },
349819            "considerations": {}
349820          }
349821        },
349822        {
349823          "type": "library",
349824          "bom-ref": "pkg:golang/go.opencensus.io@v0.22.0?package-id=a0616ad2a36e4034",
349825          "supplier": {},
349826          "name": "go.opencensus.io",
349827          "version": "v0.22.0",
349828          "purl": "pkg:golang/go.opencensus.io@v0.22.0",
349829          "swid": {
349830            "attachment": {}
349831          },
349832          "pedigree": {},
349833          "evidence": {},
349834          "signature": {
349835            "signature": {
349836              "publicKey": {}
349837            }
349838          },
349839          "modelCard": {
349840            "modelParameters": {
349841              "approach": {}
349842            },
349843            "quantitativeAnalysis": {
349844              "graphics": {}
349845            },
349846            "considerations": {}
349847          }
349848        },
349849        {
349850          "type": "library",
349851          "bom-ref": "pkg:golang/go.uber.org/atomic@v1.3.2?package-id=2a39faa0f3230070",
349852          "supplier": {},
349853          "name": "go.uber.org/atomic",
349854          "version": "v1.3.2",
349855          "purl": "pkg:golang/go.uber.org/atomic@v1.3.2",
349856          "swid": {
349857            "attachment": {}
349858          },
349859          "pedigree": {},
349860          "evidence": {},
349861          "signature": {
349862            "signature": {
349863              "publicKey": {}
349864            }
349865          },
349866          "modelCard": {
349867            "modelParameters": {
349868              "approach": {}
349869            },
349870            "quantitativeAnalysis": {
349871              "graphics": {}
349872            },
349873            "considerations": {}
349874          }
349875        },
349876        {
349877          "type": "library",
349878          "bom-ref": "pkg:golang/go.uber.org/multierr@v1.1.0?package-id=effdf300515b1f94",
349879          "supplier": {},
349880          "name": "go.uber.org/multierr",
349881          "version": "v1.1.0",
349882          "purl": "pkg:golang/go.uber.org/multierr@v1.1.0",
349883          "swid": {
349884            "attachment": {}
349885          },
349886          "pedigree": {},
349887          "evidence": {},
349888          "signature": {
349889            "signature": {
349890              "publicKey": {}
349891            }
349892          },
349893          "modelCard": {
349894            "modelParameters": {
349895              "approach": {}
349896            },
349897            "quantitativeAnalysis": {
349898              "graphics": {}
349899            },
349900            "considerations": {}
349901          }
349902        },
349903        {
349904          "type": "library",
349905          "bom-ref": "pkg:golang/go.uber.org/zap@v1.10.0?package-id=4b22a63eff48bf8a",
349906          "supplier": {},
349907          "name": "go.uber.org/zap",
349908          "version": "v1.10.0",
349909          "purl": "pkg:golang/go.uber.org/zap@v1.10.0",
349910          "swid": {
349911            "attachment": {}
349912          },
349913          "pedigree": {},
349914          "evidence": {},
349915          "signature": {
349916            "signature": {
349917              "publicKey": {}
349918            }
349919          },
349920          "modelCard": {
349921            "modelParameters": {
349922              "approach": {}
349923            },
349924            "quantitativeAnalysis": {
349925              "graphics": {}
349926            },
349927            "considerations": {}
349928          }
349929        },
349930        {
349931          "type": "library",
349932          "bom-ref": "pkg:golang/golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975?package-id=c817b8c5d1b638a5",
349933          "supplier": {},
349934          "name": "golang.org/x/crypto",
349935          "version": "v0.0.0-20200220183623-bac4c82f6975",
349936          "cpe": "cpe:2.3:a:golang:x\\/crypto:v0.0.0-20200220183623-bac4c82f6975:*:*:*:*:*:*:*",
349937          "purl": "pkg:golang/golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975",
349938          "swid": {
349939            "attachment": {}
349940          },
349941          "pedigree": {},
349942          "evidence": {},
349943          "signature": {
349944            "signature": {
349945              "publicKey": {}
349946            }
349947          },
349948          "modelCard": {
349949            "modelParameters": {
349950              "approach": {}
349951            },
349952            "quantitativeAnalysis": {
349953              "graphics": {}
349954            },
349955            "considerations": {}
349956          }
349957        },
349958        {
349959          "type": "library",
349960          "bom-ref": "pkg:golang/golang.org/x/net@v0.0.0-20200301022130-244492dfa37a?package-id=f57e17a8358bc41e",
349961          "supplier": {},
349962          "name": "golang.org/x/net",
349963          "version": "v0.0.0-20200301022130-244492dfa37a",
349964          "cpe": "cpe:2.3:a:golang:x\\/net:v0.0.0-20200301022130-244492dfa37a:*:*:*:*:*:*:*",
349965          "purl": "pkg:golang/golang.org/x/net@v0.0.0-20200301022130-244492dfa37a",
349966          "swid": {
349967            "attachment": {}
349968          },
349969          "pedigree": {},
349970          "evidence": {},
349971          "signature": {
349972            "signature": {
349973              "publicKey": {}
349974            }
349975          },
349976          "modelCard": {
349977            "modelParameters": {
349978              "approach": {}
349979            },
349980            "quantitativeAnalysis": {
349981              "graphics": {}
349982            },
349983            "considerations": {}
349984          }
349985        },
349986        {
349987          "type": "library",
349988          "bom-ref": "pkg:golang/golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45?package-id=a298d2a53105424b",
349989          "supplier": {},
349990          "name": "golang.org/x/oauth2",
349991          "version": "v0.0.0-20190604053449-0f29369cfe45",
349992          "cpe": "cpe:2.3:a:golang:x\\/oauth2:v0.0.0-20190604053449-0f29369cfe45:*:*:*:*:*:*:*",
349993          "purl": "pkg:golang/golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45",
349994          "swid": {
349995            "attachment": {}
349996          },
349997          "pedigree": {},
349998          "evidence": {},
349999          "signature": {
350000            "signature": {
350001              "publicKey": {}
350002            }
350003          },
350004          "modelCard": {
350005            "modelParameters": {
350006              "approach": {}
350007            },
350008            "quantitativeAnalysis": {
350009              "graphics": {}
350010            },
350011            "considerations": {}
350012          }
350013        },
350014        {
350015          "type": "library",
350016          "bom-ref": "pkg:golang/golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527?package-id=f5f7c5a77df583bc",
350017          "supplier": {},
350018          "name": "golang.org/x/sys",
350019          "version": "v0.0.0-20200302150141-5c8b2ff67527",
350020          "cpe": "cpe:2.3:a:golang:x\\/sys:v0.0.0-20200302150141-5c8b2ff67527:*:*:*:*:*:*:*",
350021          "purl": "pkg:golang/golang.org/x/sys@v0.0.0-20200302150141-5c8b2ff67527",
350022          "swid": {
350023            "attachment": {}
350024          },
350025          "pedigree": {},
350026          "evidence": {},
350027          "signature": {
350028            "signature": {
350029              "publicKey": {}
350030            }
350031          },
350032          "modelCard": {
350033            "modelParameters": {
350034              "approach": {}
350035            },
350036            "quantitativeAnalysis": {
350037              "graphics": {}
350038            },
350039            "considerations": {}
350040          }
350041        },
350042        {
350043          "type": "library",
350044          "bom-ref": "pkg:golang/golang.org/x/text@v0.3.2?package-id=dcd9383671547619",
350045          "supplier": {},
350046          "name": "golang.org/x/text",
350047          "version": "v0.3.2",
350048          "cpe": "cpe:2.3:a:golang:x\\/text:v0.3.2:*:*:*:*:*:*:*",
350049          "purl": "pkg:golang/golang.org/x/text@v0.3.2",
350050          "swid": {
350051            "attachment": {}
350052          },
350053          "pedigree": {},
350054          "evidence": {},
350055          "signature": {
350056            "signature": {
350057              "publicKey": {}
350058            }
350059          },
350060          "modelCard": {
350061            "modelParameters": {
350062              "approach": {}
350063            },
350064            "quantitativeAnalysis": {
350065              "graphics": {}
350066            },
350067            "considerations": {}
350068          }
350069        },
350070        {
350071          "type": "library",
350072          "bom-ref": "pkg:golang/golang.org/x/time@v0.0.0-20190921001708-c4c64cad1fd0?package-id=5db059bbf199f875",
350073          "supplier": {},
350074          "name": "golang.org/x/time",
350075          "version": "v0.0.0-20190921001708-c4c64cad1fd0",
350076          "cpe": "cpe:2.3:a:golang:x\\/time:v0.0.0-20190921001708-c4c64cad1fd0:*:*:*:*:*:*:*",
350077          "purl": "pkg:golang/golang.org/x/time@v0.0.0-20190921001708-c4c64cad1fd0",
350078          "swid": {
350079            "attachment": {}
350080          },
350081          "pedigree": {},
350082          "evidence": {},
350083          "signature": {
350084            "signature": {
350085              "publicKey": {}
350086            }
350087          },
350088          "modelCard": {
350089            "modelParameters": {
350090              "approach": {}
350091            },
350092            "quantitativeAnalysis": {
350093              "graphics": {}
350094            },
350095            "considerations": {}
350096          }
350097        },
350098        {
350099          "type": "library",
350100          "bom-ref": "pkg:golang/golang.org/x/xerrors@v0.0.0-20191204190536-9bdfabe68543?package-id=6a9aab521781cc2f",
350101          "supplier": {},
350102          "name": "golang.org/x/xerrors",
350103          "version": "v0.0.0-20191204190536-9bdfabe68543",
350104          "cpe": "cpe:2.3:a:golang:x\\/xerrors:v0.0.0-20191204190536-9bdfabe68543:*:*:*:*:*:*:*",
350105          "purl": "pkg:golang/golang.org/x/xerrors@v0.0.0-20191204190536-9bdfabe68543",
350106          "swid": {
350107            "attachment": {}
350108          },
350109          "pedigree": {},
350110          "evidence": {},
350111          "signature": {
350112            "signature": {
350113              "publicKey": {}
350114            }
350115          },
350116          "modelCard": {
350117            "modelParameters": {
350118              "approach": {}
350119            },
350120            "quantitativeAnalysis": {
350121              "graphics": {}
350122            },
350123            "considerations": {}
350124          }
350125        },
350126        {
350127          "type": "library",
350128          "bom-ref": "pkg:golang/google.golang.org/api@v0.20.0?package-id=5e838a1ae37c8cfe",
350129          "supplier": {},
350130          "name": "google.golang.org/api",
350131          "version": "v0.20.0",
350132          "cpe": "cpe:2.3:a:google:api:v0.20.0:*:*:*:*:*:*:*",
350133          "purl": "pkg:golang/google.golang.org/api@v0.20.0",
350134          "swid": {
350135            "attachment": {}
350136          },
350137          "pedigree": {},
350138          "evidence": {},
350139          "signature": {
350140            "signature": {
350141              "publicKey": {}
350142            }
350143          },
350144          "modelCard": {
350145            "modelParameters": {
350146              "approach": {}
350147            },
350148            "quantitativeAnalysis": {
350149              "graphics": {}
350150            },
350151            "considerations": {}
350152          }
350153        },
350154        {
350155          "type": "library",
350156          "bom-ref": "pkg:golang/google.golang.org/genproto@v0.0.0-20200306153348-d950eab6f860?package-id=4c5af900d9214f0",
350157          "supplier": {},
350158          "name": "google.golang.org/genproto",
350159          "version": "v0.0.0-20200306153348-d950eab6f860",
350160          "cpe": "cpe:2.3:a:google:genproto:v0.0.0-20200306153348-d950eab6f860:*:*:*:*:*:*:*",
350161          "purl": "pkg:golang/google.golang.org/genproto@v0.0.0-20200306153348-d950eab6f860",
350162          "swid": {
350163            "attachment": {}
350164          },
350165          "pedigree": {},
350166          "evidence": {},
350167          "signature": {
350168            "signature": {
350169              "publicKey": {}
350170            }
350171          },
350172          "modelCard": {
350173            "modelParameters": {
350174              "approach": {}
350175            },
350176            "quantitativeAnalysis": {
350177              "graphics": {}
350178            },
350179            "considerations": {}
350180          }
350181        },
350182        {
350183          "type": "library",
350184          "bom-ref": "pkg:golang/google.golang.org/grpc@v1.28.0?package-id=550e07a29e73a208",
350185          "supplier": {},
350186          "name": "google.golang.org/grpc",
350187          "version": "v1.28.0",
350188          "cpe": "cpe:2.3:a:google:grpc:v1.28.0:*:*:*:*:*:*:*",
350189          "purl": "pkg:golang/google.golang.org/grpc@v1.28.0",
350190          "swid": {
350191            "attachment": {}
350192          },
350193          "pedigree": {},
350194          "evidence": {},
350195          "signature": {
350196            "signature": {
350197              "publicKey": {}
350198            }
350199          },
350200          "modelCard": {
350201            "modelParameters": {
350202              "approach": {}
350203            },
350204            "quantitativeAnalysis": {
350205              "graphics": {}
350206            },
350207            "considerations": {}
350208          }
350209        },
350210        {
350211          "type": "library",
350212          "bom-ref": "pkg:golang/gopkg.in/datadog/dd-trace-go.v1@v1.22.0?package-id=b48918261d35f740",
350213          "supplier": {},
350214          "name": "gopkg.in/DataDog/dd-trace-go.v1",
350215          "version": "v1.22.0",
350216          "purl": "pkg:golang/gopkg.in/DataDog/dd-trace-go.v1@v1.22.0",
350217          "swid": {
350218            "attachment": {}
350219          },
350220          "pedigree": {},
350221          "evidence": {},
350222          "signature": {
350223            "signature": {
350224              "publicKey": {}
350225            }
350226          },
350227          "modelCard": {
350228            "modelParameters": {
350229              "approach": {}
350230            },
350231            "quantitativeAnalysis": {
350232              "graphics": {}
350233            },
350234            "considerations": {}
350235          }
350236        },
350237        {
350238          "type": "library",
350239          "bom-ref": "pkg:golang/gopkg.in/inf.v0@v0.9.1?package-id=82157cafd8b9aa57",
350240          "supplier": {},
350241          "name": "gopkg.in/inf.v0",
350242          "version": "v0.9.1",
350243          "purl": "pkg:golang/gopkg.in/inf.v0@v0.9.1",
350244          "swid": {
350245            "attachment": {}
350246          },
350247          "pedigree": {},
350248          "evidence": {},
350249          "signature": {
350250            "signature": {
350251              "publicKey": {}
350252            }
350253          },
350254          "modelCard": {
350255            "modelParameters": {
350256              "approach": {}
350257            },
350258            "quantitativeAnalysis": {
350259              "graphics": {}
350260            },
350261            "considerations": {}
350262          }
350263        },
350264        {
350265          "type": "library",
350266          "bom-ref": "pkg:golang/gopkg.in/yaml.v2@v2.2.8?package-id=b86f3ff646b0bc81",
350267          "supplier": {},
350268          "name": "gopkg.in/yaml.v2",
350269          "version": "v2.2.8",
350270          "purl": "pkg:golang/gopkg.in/yaml.v2@v2.2.8",
350271          "swid": {
350272            "attachment": {}
350273          },
350274          "pedigree": {},
350275          "evidence": {},
350276          "signature": {
350277            "signature": {
350278              "publicKey": {}
350279            }
350280          },
350281          "modelCard": {
350282            "modelParameters": {
350283              "approach": {}
350284            },
350285            "quantitativeAnalysis": {
350286              "graphics": {}
350287            },
350288            "considerations": {}
350289          }
350290        },
350291        {
350292          "type": "library",
350293          "bom-ref": "pkg:golang/k8s.io/api@v0.17.4?package-id=27d3d20550bfc7b0",
350294          "supplier": {},
350295          "name": "k8s.io/api",
350296          "version": "v0.17.4",
350297          "purl": "pkg:golang/k8s.io/api@v0.17.4",
350298          "swid": {
350299            "attachment": {}
350300          },
350301          "pedigree": {},
350302          "evidence": {},
350303          "signature": {
350304            "signature": {
350305              "publicKey": {}
350306            }
350307          },
350308          "modelCard": {
350309            "modelParameters": {
350310              "approach": {}
350311            },
350312            "quantitativeAnalysis": {
350313              "graphics": {}
350314            },
350315            "considerations": {}
350316          }
350317        },
350318        {
350319          "type": "library",
350320          "bom-ref": "pkg:golang/k8s.io/apimachinery@v0.17.4?package-id=abe2c5340b4f9ea9",
350321          "supplier": {},
350322          "name": "k8s.io/apimachinery",
350323          "version": "v0.17.4",
350324          "purl": "pkg:golang/k8s.io/apimachinery@v0.17.4",
350325          "swid": {
350326            "attachment": {}
350327          },
350328          "pedigree": {},
350329          "evidence": {},
350330          "signature": {
350331            "signature": {
350332              "publicKey": {}
350333            }
350334          },
350335          "modelCard": {
350336            "modelParameters": {
350337              "approach": {}
350338            },
350339            "quantitativeAnalysis": {
350340              "graphics": {}
350341            },
350342            "considerations": {}
350343          }
350344        },
350345        {
350346          "type": "library",
350347          "bom-ref": "pkg:golang/k8s.io/client-go@v0.17.4?package-id=49a2583a16fb9045",
350348          "supplier": {},
350349          "name": "k8s.io/client-go",
350350          "version": "v0.17.4",
350351          "purl": "pkg:golang/k8s.io/client-go@v0.17.4",
350352          "swid": {
350353            "attachment": {}
350354          },
350355          "pedigree": {},
350356          "evidence": {},
350357          "signature": {
350358            "signature": {
350359              "publicKey": {}
350360            }
350361          },
350362          "modelCard": {
350363            "modelParameters": {
350364              "approach": {}
350365            },
350366            "quantitativeAnalysis": {
350367              "graphics": {}
350368            },
350369            "considerations": {}
350370          }
350371        },
350372        {
350373          "type": "library",
350374          "bom-ref": "pkg:golang/k8s.io/klog@v1.0.0?package-id=a77c58bffd70a218",
350375          "supplier": {},
350376          "name": "k8s.io/klog",
350377          "version": "v1.0.0",
350378          "purl": "pkg:golang/k8s.io/klog@v1.0.0",
350379          "swid": {
350380            "attachment": {}
350381          },
350382          "pedigree": {},
350383          "evidence": {},
350384          "signature": {
350385            "signature": {
350386              "publicKey": {}
350387            }
350388          },
350389          "modelCard": {
350390            "modelParameters": {
350391              "approach": {}
350392            },
350393            "quantitativeAnalysis": {
350394              "graphics": {}
350395            },
350396            "considerations": {}
350397          }
350398        },
350399        {
350400          "type": "library",
350401          "bom-ref": "pkg:golang/k8s.io/utils@v0.0.0-20191114184206-e782cd3c129f?package-id=32763778c820f5fe",
350402          "supplier": {},
350403          "name": "k8s.io/utils",
350404          "version": "v0.0.0-20191114184206-e782cd3c129f",
350405          "purl": "pkg:golang/k8s.io/utils@v0.0.0-20191114184206-e782cd3c129f",
350406          "swid": {
350407            "attachment": {}
350408          },
350409          "pedigree": {},
350410          "evidence": {},
350411          "signature": {
350412            "signature": {
350413              "publicKey": {}
350414            }
350415          },
350416          "modelCard": {
350417            "modelParameters": {
350418              "approach": {}
350419            },
350420            "quantitativeAnalysis": {
350421              "graphics": {}
350422            },
350423            "considerations": {}
350424          }
350425        },
350426        {
350427          "type": "library",
350428          "bom-ref": "pkg:golang/sigs.k8s.io/yaml@v1.1.0?package-id=fb50a811ed5a17d2",
350429          "supplier": {},
350430          "name": "sigs.k8s.io/yaml",
350431          "version": "v1.1.0",
350432          "purl": "pkg:golang/sigs.k8s.io/yaml@v1.1.0",
350433          "swid": {
350434            "attachment": {}
350435          },
350436          "pedigree": {},
350437          "evidence": {},
350438          "signature": {
350439            "signature": {
350440              "publicKey": {}
350441            }
350442          },
350443          "modelCard": {
350444            "modelParameters": {
350445              "approach": {}
350446            },
350447            "quantitativeAnalysis": {
350448              "graphics": {}
350449            },
350450            "considerations": {}
350451          }
350452        },
350453        {
350454          "type": "library",
350455          "bom-ref": "pkg:npm/%40iarna/cli@2.1.0?package-id=e39ea33aa6c9ff9d",
350456          "supplier": {},
350457          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
350458          "name": "@iarna/cli",
350459          "version": "2.1.0",
350460          "description": "Some simple CLI scaffolding for promise returning applications.",
350461          "licenses": [
350462            {
350463              "license": {
350464                "id": "ISC"
350465              }
350466            }
350467          ],
350468          "cpe": "cpe:2.3:a:\\@iarna\\/cli:\\@iarna\\/cli:2.1.0:*:*:*:*:*:*:*",
350469          "purl": "pkg:npm/%40iarna/cli@2.1.0",
350470          "swid": {
350471            "attachment": {}
350472          },
350473          "pedigree": {},
350474          "externalReferences": [
350475            {
350476              "url": "git+https://github.com/iarna/cli.git",
350477              "type": "distribution"
350478            },
350479            {
350480              "url": "https://github.com/iarna/cli#readme",
350481              "type": "website"
350482            }
350483          ],
350484          "evidence": {},
350485          "signature": {
350486            "signature": {
350487              "publicKey": {}
350488            }
350489          },
350490          "modelCard": {
350491            "modelParameters": {
350492              "approach": {}
350493            },
350494            "quantitativeAnalysis": {
350495              "graphics": {}
350496            },
350497            "considerations": {}
350498          }
350499        },
350500        {
350501          "type": "library",
350502          "bom-ref": "pkg:npm/%40nestjs/common@7.6.18?package-id=15f33be32bd9864d",
350503          "supplier": {},
350504          "author": "Kamil Mysliwiec",
350505          "name": "@nestjs/common",
350506          "version": "7.6.18",
350507          "description": "Nest - modern, fast, powerful node.js web framework (@common)",
350508          "licenses": [
350509            {
350510              "license": {
350511                "id": "MIT"
350512              }
350513            }
350514          ],
350515          "cpe": "cpe:2.3:a:\\@nestjs\\/common:\\@nestjs\\/common:7.6.18:*:*:*:*:*:*:*",
350516          "purl": "pkg:npm/%40nestjs/common@7.6.18",
350517          "swid": {
350518            "attachment": {}
350519          },
350520          "pedigree": {},
350521          "externalReferences": [
350522            {
350523              "url": "git+https://github.com/nestjs/nest.git",
350524              "type": "distribution"
350525            },
350526            {
350527              "url": "https://nestjs.com",
350528              "type": "website"
350529            }
350530          ],
350531          "evidence": {},
350532          "signature": {
350533            "signature": {
350534              "publicKey": {}
350535            }
350536          },
350537          "modelCard": {
350538            "modelParameters": {
350539              "approach": {}
350540            },
350541            "quantitativeAnalysis": {
350542              "graphics": {}
350543            },
350544            "considerations": {}
350545          }
350546        },
350547        {
350548          "type": "library",
350549          "bom-ref": "pkg:npm/%40nestjs/core@7.6.18?package-id=4d7655cc53622cb7",
350550          "supplier": {},
350551          "author": "Kamil Mysliwiec",
350552          "name": "@nestjs/core",
350553          "version": "7.6.18",
350554          "description": "Nest - modern, fast, powerful node.js web framework (@core)",
350555          "licenses": [
350556            {
350557              "license": {
350558                "id": "MIT"
350559              }
350560            }
350561          ],
350562          "cpe": "cpe:2.3:a:\\@nestjs\\/core:\\@nestjs\\/core:7.6.18:*:*:*:*:*:*:*",
350563          "purl": "pkg:npm/%40nestjs/core@7.6.18",
350564          "swid": {
350565            "attachment": {}
350566          },
350567          "pedigree": {},
350568          "externalReferences": [
350569            {
350570              "url": "git+https://github.com/nestjs/nest.git",
350571              "type": "distribution"
350572            },
350573            {
350574              "url": "https://nestjs.com",
350575              "type": "website"
350576            }
350577          ],
350578          "evidence": {},
350579          "signature": {
350580            "signature": {
350581              "publicKey": {}
350582            }
350583          },
350584          "modelCard": {
350585            "modelParameters": {
350586              "approach": {}
350587            },
350588            "quantitativeAnalysis": {
350589              "graphics": {}
350590            },
350591            "considerations": {}
350592          }
350593        },
350594        {
350595          "type": "library",
350596          "bom-ref": "pkg:npm/%40nestjs/mapped-types@0.4.1?package-id=30cd22e03cad921d",
350597          "supplier": {},
350598          "author": "Kamil Mysliwiec",
350599          "name": "@nestjs/mapped-types",
350600          "version": "0.4.1",
350601          "description": "Nest - modern, fast, powerful node.js web framework (@mapped-types)",
350602          "licenses": [
350603            {
350604              "license": {
350605                "id": "MIT"
350606              }
350607            }
350608          ],
350609          "cpe": "cpe:2.3:a:\\@nestjs\\/mapped-types:\\@nestjs\\/mapped-types:0.4.1:*:*:*:*:*:*:*",
350610          "purl": "pkg:npm/%40nestjs/mapped-types@0.4.1",
350611          "swid": {
350612            "attachment": {}
350613          },
350614          "pedigree": {},
350615          "externalReferences": [
350616            {
350617              "url": "git+https://github.com/nestjs/mapped-types.git",
350618              "type": "distribution"
350619            },
350620            {
350621              "url": "https://github.com/nestjs/mapped-types#readme",
350622              "type": "website"
350623            }
350624          ],
350625          "evidence": {},
350626          "signature": {
350627            "signature": {
350628              "publicKey": {}
350629            }
350630          },
350631          "modelCard": {
350632            "modelParameters": {
350633              "approach": {}
350634            },
350635            "quantitativeAnalysis": {
350636              "graphics": {}
350637            },
350638            "considerations": {}
350639          }
350640        },
350641        {
350642          "type": "library",
350643          "bom-ref": "pkg:npm/%40nestjs/platform-express@7.6.18?package-id=5a518de16ca11f9a",
350644          "supplier": {},
350645          "author": "Kamil Mysliwiec",
350646          "name": "@nestjs/platform-express",
350647          "version": "7.6.18",
350648          "description": "Nest - modern, fast, powerful node.js web framework (@platform-express)",
350649          "licenses": [
350650            {
350651              "license": {
350652                "id": "MIT"
350653              }
350654            }
350655          ],
350656          "cpe": "cpe:2.3:a:\\@nestjs\\/platform-express:\\@nestjs\\/platform-express:7.6.18:*:*:*:*:*:*:*",
350657          "purl": "pkg:npm/%40nestjs/platform-express@7.6.18",
350658          "swid": {
350659            "attachment": {}
350660          },
350661          "pedigree": {},
350662          "externalReferences": [
350663            {
350664              "url": "git+https://github.com/nestjs/nest.git",
350665              "type": "distribution"
350666            },
350667            {
350668              "url": "https://nestjs.com",
350669              "type": "website"
350670            }
350671          ],
350672          "evidence": {},
350673          "signature": {
350674            "signature": {
350675              "publicKey": {}
350676            }
350677          },
350678          "modelCard": {
350679            "modelParameters": {
350680              "approach": {}
350681            },
350682            "quantitativeAnalysis": {
350683              "graphics": {}
350684            },
350685            "considerations": {}
350686          }
350687        },
350688        {
350689          "type": "library",
350690          "bom-ref": "pkg:npm/%40nestjs/schedule@0.4.3?package-id=f520b9b7b48d992a",
350691          "supplier": {},
350692          "author": "Kamil Mysliwiec",
350693          "name": "@nestjs/schedule",
350694          "version": "0.4.3",
350695          "description": "Nest - modern, fast, powerful node.js web framework (@schedule)",
350696          "licenses": [
350697            {
350698              "license": {
350699                "id": "MIT"
350700              }
350701            }
350702          ],
350703          "cpe": "cpe:2.3:a:\\@nestjs\\/schedule:\\@nestjs\\/schedule:0.4.3:*:*:*:*:*:*:*",
350704          "purl": "pkg:npm/%40nestjs/schedule@0.4.3",
350705          "swid": {
350706            "attachment": {}
350707          },
350708          "pedigree": {},
350709          "externalReferences": [
350710            {
350711              "url": "git+https://github.com/nestjs/schedule.git",
350712              "type": "distribution"
350713            },
350714            {
350715              "url": "https://github.com/nestjs/schedule#readme",
350716              "type": "website"
350717            }
350718          ],
350719          "evidence": {},
350720          "signature": {
350721            "signature": {
350722              "publicKey": {}
350723            }
350724          },
350725          "modelCard": {
350726            "modelParameters": {
350727              "approach": {}
350728            },
350729            "quantitativeAnalysis": {
350730              "graphics": {}
350731            },
350732            "considerations": {}
350733          }
350734        },
350735        {
350736          "type": "library",
350737          "bom-ref": "pkg:npm/%40nestjs/swagger@4.8.2?package-id=e22c6871989630c3",
350738          "supplier": {},
350739          "author": "Kamil Mysliwiec",
350740          "name": "@nestjs/swagger",
350741          "version": "4.8.2",
350742          "description": "Nest - modern, fast, powerful node.js web framework (@swagger)",
350743          "licenses": [
350744            {
350745              "license": {
350746                "id": "MIT"
350747              }
350748            }
350749          ],
350750          "cpe": "cpe:2.3:a:\\@nestjs\\/swagger:\\@nestjs\\/swagger:4.8.2:*:*:*:*:*:*:*",
350751          "purl": "pkg:npm/%40nestjs/swagger@4.8.2",
350752          "swid": {
350753            "attachment": {}
350754          },
350755          "pedigree": {},
350756          "externalReferences": [
350757            {
350758              "url": "git+https://github.com/nestjs/swagger.git",
350759              "type": "distribution"
350760            },
350761            {
350762              "url": "https://github.com/nestjs/swagger#readme",
350763              "type": "website"
350764            }
350765          ],
350766          "evidence": {},
350767          "signature": {
350768            "signature": {
350769              "publicKey": {}
350770            }
350771          },
350772          "modelCard": {
350773            "modelParameters": {
350774              "approach": {}
350775            },
350776            "quantitativeAnalysis": {
350777              "graphics": {}
350778            },
350779            "considerations": {}
350780          }
350781        },
350782        {
350783          "type": "library",
350784          "bom-ref": "pkg:npm/%40nuxtjs/opencollective@0.3.2?package-id=4e66d3ddcbf4b722",
350785          "supplier": {},
350786          "name": "@nuxtjs/opencollective",
350787          "version": "0.3.2",
350788          "description": "[![npm version][npm-v-src]][npm-v-href] [![npm downloads][npm-d-src]][npm-d-href] [![status][github-actions-src]][github-actions-href]",
350789          "licenses": [
350790            {
350791              "license": {
350792                "id": "MIT"
350793              }
350794            }
350795          ],
350796          "cpe": "cpe:2.3:a:\\@nuxtjs\\/opencollective:\\@nuxtjs\\/opencollective:0.3.2:*:*:*:*:*:*:*",
350797          "purl": "pkg:npm/%40nuxtjs/opencollective@0.3.2",
350798          "swid": {
350799            "attachment": {}
350800          },
350801          "pedigree": {},
350802          "externalReferences": [
350803            {
350804              "url": "git+https://github.com/nuxt-contrib/opencollective.git",
350805              "type": "distribution"
350806            },
350807            {
350808              "url": "https://github.com/nuxt-contrib/opencollective#readme",
350809              "type": "website"
350810            }
350811          ],
350812          "evidence": {},
350813          "signature": {
350814            "signature": {
350815              "publicKey": {}
350816            }
350817          },
350818          "modelCard": {
350819            "modelParameters": {
350820              "approach": {}
350821            },
350822            "quantitativeAnalysis": {
350823              "graphics": {}
350824            },
350825            "considerations": {}
350826          }
350827        },
350828        {
350829          "type": "library",
350830          "bom-ref": "pkg:npm/%40sentry/core@6.8.0?package-id=e09e279d0fe5f83",
350831          "supplier": {},
350832          "author": "Sentry",
350833          "name": "@sentry/core",
350834          "version": "6.8.0",
350835          "description": "Base implementation for all Sentry JavaScript SDKs",
350836          "licenses": [
350837            {
350838              "license": {
350839                "id": "BSD-3-Clause"
350840              }
350841            }
350842          ],
350843          "cpe": "cpe:2.3:a:\\@sentry\\/core:\\@sentry\\/core:6.8.0:*:*:*:*:*:*:*",
350844          "purl": "pkg:npm/%40sentry/core@6.8.0",
350845          "swid": {
350846            "attachment": {}
350847          },
350848          "pedigree": {},
350849          "externalReferences": [
350850            {
350851              "url": "git://github.com/getsentry/sentry-javascript.git",
350852              "type": "distribution"
350853            },
350854            {
350855              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/core",
350856              "type": "website"
350857            }
350858          ],
350859          "evidence": {},
350860          "signature": {
350861            "signature": {
350862              "publicKey": {}
350863            }
350864          },
350865          "modelCard": {
350866            "modelParameters": {
350867              "approach": {}
350868            },
350869            "quantitativeAnalysis": {
350870              "graphics": {}
350871            },
350872            "considerations": {}
350873          }
350874        },
350875        {
350876          "type": "library",
350877          "bom-ref": "pkg:npm/%40sentry/hub@6.8.0?package-id=264e93d5eeea3c3b",
350878          "supplier": {},
350879          "author": "Sentry",
350880          "name": "@sentry/hub",
350881          "version": "6.8.0",
350882          "description": "Sentry hub which handles global state managment.",
350883          "licenses": [
350884            {
350885              "license": {
350886                "id": "BSD-3-Clause"
350887              }
350888            }
350889          ],
350890          "cpe": "cpe:2.3:a:\\@sentry\\/hub:\\@sentry\\/hub:6.8.0:*:*:*:*:*:*:*",
350891          "purl": "pkg:npm/%40sentry/hub@6.8.0",
350892          "swid": {
350893            "attachment": {}
350894          },
350895          "pedigree": {},
350896          "externalReferences": [
350897            {
350898              "url": "git://github.com/getsentry/sentry-javascript.git",
350899              "type": "distribution"
350900            },
350901            {
350902              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/hub",
350903              "type": "website"
350904            }
350905          ],
350906          "evidence": {},
350907          "signature": {
350908            "signature": {
350909              "publicKey": {}
350910            }
350911          },
350912          "modelCard": {
350913            "modelParameters": {
350914              "approach": {}
350915            },
350916            "quantitativeAnalysis": {
350917              "graphics": {}
350918            },
350919            "considerations": {}
350920          }
350921        },
350922        {
350923          "type": "library",
350924          "bom-ref": "pkg:npm/%40sentry/minimal@6.8.0?package-id=1c0e795092dbb615",
350925          "supplier": {},
350926          "author": "Sentry",
350927          "name": "@sentry/minimal",
350928          "version": "6.8.0",
350929          "description": "Sentry minimal library that can be used in other packages",
350930          "licenses": [
350931            {
350932              "license": {
350933                "id": "BSD-3-Clause"
350934              }
350935            }
350936          ],
350937          "cpe": "cpe:2.3:a:\\@sentry\\/minimal:\\@sentry\\/minimal:6.8.0:*:*:*:*:*:*:*",
350938          "purl": "pkg:npm/%40sentry/minimal@6.8.0",
350939          "swid": {
350940            "attachment": {}
350941          },
350942          "pedigree": {},
350943          "externalReferences": [
350944            {
350945              "url": "git://github.com/getsentry/sentry-javascript.git",
350946              "type": "distribution"
350947            },
350948            {
350949              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/minimal",
350950              "type": "website"
350951            }
350952          ],
350953          "evidence": {},
350954          "signature": {
350955            "signature": {
350956              "publicKey": {}
350957            }
350958          },
350959          "modelCard": {
350960            "modelParameters": {
350961              "approach": {}
350962            },
350963            "quantitativeAnalysis": {
350964              "graphics": {}
350965            },
350966            "considerations": {}
350967          }
350968        },
350969        {
350970          "type": "library",
350971          "bom-ref": "pkg:npm/%40sentry/node@6.8.0?package-id=aca96b468acd8fc4",
350972          "supplier": {},
350973          "author": "Sentry",
350974          "name": "@sentry/node",
350975          "version": "6.8.0",
350976          "description": "Official Sentry SDK for Node.js",
350977          "licenses": [
350978            {
350979              "license": {
350980                "id": "BSD-3-Clause"
350981              }
350982            }
350983          ],
350984          "cpe": "cpe:2.3:a:\\@sentry\\/node:\\@sentry\\/node:6.8.0:*:*:*:*:*:*:*",
350985          "purl": "pkg:npm/%40sentry/node@6.8.0",
350986          "swid": {
350987            "attachment": {}
350988          },
350989          "pedigree": {},
350990          "externalReferences": [
350991            {
350992              "url": "git://github.com/getsentry/sentry-javascript.git",
350993              "type": "distribution"
350994            },
350995            {
350996              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/node",
350997              "type": "website"
350998            }
350999          ],
351000          "evidence": {},
351001          "signature": {
351002            "signature": {
351003              "publicKey": {}
351004            }
351005          },
351006          "modelCard": {
351007            "modelParameters": {
351008              "approach": {}
351009            },
351010            "quantitativeAnalysis": {
351011              "graphics": {}
351012            },
351013            "considerations": {}
351014          }
351015        },
351016        {
351017          "type": "library",
351018          "bom-ref": "pkg:npm/%40sentry/tracing@6.8.0?package-id=fa9fe474b43b09ae",
351019          "supplier": {},
351020          "author": "Sentry",
351021          "name": "@sentry/tracing",
351022          "version": "6.8.0",
351023          "description": "Extensions for Sentry AM",
351024          "licenses": [
351025            {
351026              "license": {
351027                "id": "MIT"
351028              }
351029            }
351030          ],
351031          "cpe": "cpe:2.3:a:\\@sentry\\/tracing:\\@sentry\\/tracing:6.8.0:*:*:*:*:*:*:*",
351032          "purl": "pkg:npm/%40sentry/tracing@6.8.0",
351033          "swid": {
351034            "attachment": {}
351035          },
351036          "pedigree": {},
351037          "externalReferences": [
351038            {
351039              "url": "git://github.com/getsentry/sentry-javascript.git",
351040              "type": "distribution"
351041            },
351042            {
351043              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/tracing",
351044              "type": "website"
351045            }
351046          ],
351047          "evidence": {},
351048          "signature": {
351049            "signature": {
351050              "publicKey": {}
351051            }
351052          },
351053          "modelCard": {
351054            "modelParameters": {
351055              "approach": {}
351056            },
351057            "quantitativeAnalysis": {
351058              "graphics": {}
351059            },
351060            "considerations": {}
351061          }
351062        },
351063        {
351064          "type": "library",
351065          "bom-ref": "pkg:npm/%40sentry/types@6.8.0?package-id=c356428ce47be4ef",
351066          "supplier": {},
351067          "author": "Sentry",
351068          "name": "@sentry/types",
351069          "version": "6.8.0",
351070          "description": "Types for all Sentry JavaScript SDKs",
351071          "licenses": [
351072            {
351073              "license": {
351074                "id": "BSD-3-Clause"
351075              }
351076            }
351077          ],
351078          "cpe": "cpe:2.3:a:\\@sentry\\/types:\\@sentry\\/types:6.8.0:*:*:*:*:*:*:*",
351079          "purl": "pkg:npm/%40sentry/types@6.8.0",
351080          "swid": {
351081            "attachment": {}
351082          },
351083          "pedigree": {},
351084          "externalReferences": [
351085            {
351086              "url": "git://github.com/getsentry/sentry-javascript.git",
351087              "type": "distribution"
351088            },
351089            {
351090              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/types",
351091              "type": "website"
351092            }
351093          ],
351094          "evidence": {},
351095          "signature": {
351096            "signature": {
351097              "publicKey": {}
351098            }
351099          },
351100          "modelCard": {
351101            "modelParameters": {
351102              "approach": {}
351103            },
351104            "quantitativeAnalysis": {
351105              "graphics": {}
351106            },
351107            "considerations": {}
351108          }
351109        },
351110        {
351111          "type": "library",
351112          "bom-ref": "pkg:npm/%40sentry/utils@6.8.0?package-id=a6c0d87fb7094269",
351113          "supplier": {},
351114          "author": "Sentry",
351115          "name": "@sentry/utils",
351116          "version": "6.8.0",
351117          "description": "Utilities for all Sentry JavaScript SDKs",
351118          "licenses": [
351119            {
351120              "license": {
351121                "id": "BSD-3-Clause"
351122              }
351123            }
351124          ],
351125          "cpe": "cpe:2.3:a:\\@sentry\\/utils:\\@sentry\\/utils:6.8.0:*:*:*:*:*:*:*",
351126          "purl": "pkg:npm/%40sentry/utils@6.8.0",
351127          "swid": {
351128            "attachment": {}
351129          },
351130          "pedigree": {},
351131          "externalReferences": [
351132            {
351133              "url": "git://github.com/getsentry/sentry-javascript.git",
351134              "type": "distribution"
351135            },
351136            {
351137              "url": "https://github.com/getsentry/sentry-javascript/tree/master/packages/utils",
351138              "type": "website"
351139            }
351140          ],
351141          "evidence": {},
351142          "signature": {
351143            "signature": {
351144              "publicKey": {}
351145            }
351146          },
351147          "modelCard": {
351148            "modelParameters": {
351149              "approach": {}
351150            },
351151            "quantitativeAnalysis": {
351152              "graphics": {}
351153            },
351154            "considerations": {}
351155          }
351156        },
351157        {
351158          "type": "library",
351159          "bom-ref": "pkg:npm/%40types/validator@13.0.0?package-id=df4b0f14d888b090",
351160          "supplier": {},
351161          "name": "@types/validator",
351162          "version": "13.0.0",
351163          "description": "TypeScript definitions for validator.js",
351164          "licenses": [
351165            {
351166              "license": {
351167                "id": "MIT"
351168              }
351169            }
351170          ],
351171          "cpe": "cpe:2.3:a:\\@types\\/validator:\\@types\\/validator:13.0.0:*:*:*:*:*:*:*",
351172          "purl": "pkg:npm/%40types/validator@13.0.0",
351173          "swid": {
351174            "attachment": {}
351175          },
351176          "pedigree": {},
351177          "externalReferences": [
351178            {
351179              "url": "git+https://github.com/DefinitelyTyped/DefinitelyTyped.git",
351180              "type": "distribution"
351181            },
351182            {
351183              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped#readme",
351184              "type": "website"
351185            }
351186          ],
351187          "evidence": {},
351188          "signature": {
351189            "signature": {
351190              "publicKey": {}
351191            }
351192          },
351193          "modelCard": {
351194            "modelParameters": {
351195              "approach": {}
351196            },
351197            "quantitativeAnalysis": {
351198              "graphics": {}
351199            },
351200            "considerations": {}
351201          }
351202        },
351203        {
351204          "type": "library",
351205          "bom-ref": "pkg:npm/JSONStream@1.3.5?package-id=362f19a26f622e0",
351206          "supplier": {},
351207          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (http://bit.ly/dominictarr)",
351208          "name": "JSONStream",
351209          "version": "1.3.5",
351210          "description": "rawStream.pipe(JSONStream.parse()).pipe(streamOfObjects)",
351211          "licenses": [
351212            {
351213              "license": {
351214                "name": "(MIT OR Apache-2.0)"
351215              }
351216            }
351217          ],
351218          "cpe": "cpe:2.3:a:dominictarr:JSONStream:1.3.5:*:*:*:*:*:*:*",
351219          "purl": "pkg:npm/JSONStream@1.3.5",
351220          "swid": {
351221            "attachment": {}
351222          },
351223          "pedigree": {},
351224          "externalReferences": [
351225            {
351226              "url": "git://github.com/dominictarr/JSONStream.git",
351227              "type": "distribution"
351228            },
351229            {
351230              "url": "http://github.com/dominictarr/JSONStream",
351231              "type": "website"
351232            }
351233          ],
351234          "evidence": {},
351235          "signature": {
351236            "signature": {
351237              "publicKey": {}
351238            }
351239          },
351240          "modelCard": {
351241            "modelParameters": {
351242              "approach": {}
351243            },
351244            "quantitativeAnalysis": {
351245              "graphics": {}
351246            },
351247            "considerations": {}
351248          }
351249        },
351250        {
351251          "type": "library",
351252          "bom-ref": "pkg:npm/abbrev@1.1.1?package-id=79936430981a8702",
351253          "supplier": {},
351254          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
351255          "name": "abbrev",
351256          "version": "1.1.1",
351257          "description": "Like ruby's abbrev module, but in js",
351258          "licenses": [
351259            {
351260              "license": {
351261                "id": "ISC"
351262              }
351263            }
351264          ],
351265          "cpe": "cpe:2.3:a:abbrev:abbrev:1.1.1:*:*:*:*:*:*:*",
351266          "purl": "pkg:npm/abbrev@1.1.1",
351267          "swid": {
351268            "attachment": {}
351269          },
351270          "pedigree": {},
351271          "externalReferences": [
351272            {
351273              "url": "git+ssh://git@github.com/isaacs/abbrev-js.git",
351274              "type": "distribution"
351275            },
351276            {
351277              "url": "https://github.com/isaacs/abbrev-js#readme",
351278              "type": "website"
351279            }
351280          ],
351281          "evidence": {},
351282          "signature": {
351283            "signature": {
351284              "publicKey": {}
351285            }
351286          },
351287          "modelCard": {
351288            "modelParameters": {
351289              "approach": {}
351290            },
351291            "quantitativeAnalysis": {
351292              "graphics": {}
351293            },
351294            "considerations": {}
351295          }
351296        },
351297        {
351298          "type": "library",
351299          "bom-ref": "pkg:npm/accepts@1.3.7?package-id=bbbf816fe622ef49",
351300          "supplier": {},
351301          "name": "accepts",
351302          "version": "1.3.7",
351303          "description": "Higher-level content negotiation",
351304          "licenses": [
351305            {
351306              "license": {
351307                "id": "MIT"
351308              }
351309            }
351310          ],
351311          "cpe": "cpe:2.3:a:accepts:accepts:1.3.7:*:*:*:*:*:*:*",
351312          "purl": "pkg:npm/accepts@1.3.7",
351313          "swid": {
351314            "attachment": {}
351315          },
351316          "pedigree": {},
351317          "externalReferences": [
351318            {
351319              "url": "git+https://github.com/jshttp/accepts.git",
351320              "type": "distribution"
351321            },
351322            {
351323              "url": "https://github.com/jshttp/accepts#readme",
351324              "type": "website"
351325            }
351326          ],
351327          "evidence": {},
351328          "signature": {
351329            "signature": {
351330              "publicKey": {}
351331            }
351332          },
351333          "modelCard": {
351334            "modelParameters": {
351335              "approach": {}
351336            },
351337            "quantitativeAnalysis": {
351338              "graphics": {}
351339            },
351340            "considerations": {}
351341          }
351342        },
351343        {
351344          "type": "library",
351345          "bom-ref": "pkg:npm/agent-base@4.2.1?package-id=5fc4c61198f37ad3",
351346          "supplier": {},
351347          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
351348          "name": "agent-base",
351349          "version": "4.2.1",
351350          "description": "Turn a function into an `http.Agent` instance",
351351          "licenses": [
351352            {
351353              "license": {
351354                "id": "MIT"
351355              }
351356            }
351357          ],
351358          "cpe": "cpe:2.3:a:TooTallNate:agent-base:4.2.1:*:*:*:*:*:*:*",
351359          "purl": "pkg:npm/agent-base@4.2.1",
351360          "swid": {
351361            "attachment": {}
351362          },
351363          "pedigree": {},
351364          "externalReferences": [
351365            {
351366              "url": "git://github.com/TooTallNate/node-agent-base.git",
351367              "type": "distribution"
351368            },
351369            {
351370              "url": "https://github.com/TooTallNate/node-agent-base#readme",
351371              "type": "website"
351372            }
351373          ],
351374          "evidence": {},
351375          "signature": {
351376            "signature": {
351377              "publicKey": {}
351378            }
351379          },
351380          "modelCard": {
351381            "modelParameters": {
351382              "approach": {}
351383            },
351384            "quantitativeAnalysis": {
351385              "graphics": {}
351386            },
351387            "considerations": {}
351388          }
351389        },
351390        {
351391          "type": "library",
351392          "bom-ref": "pkg:npm/agent-base@4.3.0?package-id=5ba0b4e2347e7c24",
351393          "supplier": {},
351394          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
351395          "name": "agent-base",
351396          "version": "4.3.0",
351397          "description": "Turn a function into an `http.Agent` instance",
351398          "licenses": [
351399            {
351400              "license": {
351401                "id": "MIT"
351402              }
351403            }
351404          ],
351405          "cpe": "cpe:2.3:a:TooTallNate:agent-base:4.3.0:*:*:*:*:*:*:*",
351406          "purl": "pkg:npm/agent-base@4.3.0",
351407          "swid": {
351408            "attachment": {}
351409          },
351410          "pedigree": {},
351411          "externalReferences": [
351412            {
351413              "url": "git://github.com/TooTallNate/node-agent-base.git",
351414              "type": "distribution"
351415            },
351416            {
351417              "url": "https://github.com/TooTallNate/node-agent-base#readme",
351418              "type": "website"
351419            }
351420          ],
351421          "evidence": {},
351422          "signature": {
351423            "signature": {
351424              "publicKey": {}
351425            }
351426          },
351427          "modelCard": {
351428            "modelParameters": {
351429              "approach": {}
351430            },
351431            "quantitativeAnalysis": {
351432              "graphics": {}
351433            },
351434            "considerations": {}
351435          }
351436        },
351437        {
351438          "type": "library",
351439          "bom-ref": "pkg:npm/agent-base@6.0.2?package-id=b1bf7cf127c6dcdf",
351440          "supplier": {},
351441          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
351442          "name": "agent-base",
351443          "version": "6.0.2",
351444          "description": "Turn a function into an `http.Agent` instance",
351445          "licenses": [
351446            {
351447              "license": {
351448                "id": "MIT"
351449              }
351450            }
351451          ],
351452          "cpe": "cpe:2.3:a:TooTallNate:agent-base:6.0.2:*:*:*:*:*:*:*",
351453          "purl": "pkg:npm/agent-base@6.0.2",
351454          "swid": {
351455            "attachment": {}
351456          },
351457          "pedigree": {},
351458          "externalReferences": [
351459            {
351460              "url": "git://github.com/TooTallNate/node-agent-base.git",
351461              "type": "distribution"
351462            },
351463            {
351464              "url": "https://github.com/TooTallNate/node-agent-base#readme",
351465              "type": "website"
351466            }
351467          ],
351468          "evidence": {},
351469          "signature": {
351470            "signature": {
351471              "publicKey": {}
351472            }
351473          },
351474          "modelCard": {
351475            "modelParameters": {
351476              "approach": {}
351477            },
351478            "quantitativeAnalysis": {
351479              "graphics": {}
351480            },
351481            "considerations": {}
351482          }
351483        },
351484        {
351485          "type": "library",
351486          "bom-ref": "pkg:npm/agentkeepalive@3.5.2?package-id=1b7d5bc0186ab4c",
351487          "supplier": {},
351488          "author": "fengmk2 \u003cfengmk2@gmail.com\u003e (https://fengmk2.com)",
351489          "name": "agentkeepalive",
351490          "version": "3.5.2",
351491          "description": "Missing keepalive http.Agent",
351492          "licenses": [
351493            {
351494              "license": {
351495                "id": "MIT"
351496              }
351497            }
351498          ],
351499          "cpe": "cpe:2.3:a:agentkeepalive:agentkeepalive:3.5.2:*:*:*:*:*:*:*",
351500          "purl": "pkg:npm/agentkeepalive@3.5.2",
351501          "swid": {
351502            "attachment": {}
351503          },
351504          "pedigree": {},
351505          "externalReferences": [
351506            {
351507              "url": "git://github.com/node-modules/agentkeepalive.git",
351508              "type": "distribution"
351509            },
351510            {
351511              "url": "https://github.com/node-modules/agentkeepalive#readme",
351512              "type": "website"
351513            }
351514          ],
351515          "evidence": {},
351516          "signature": {
351517            "signature": {
351518              "publicKey": {}
351519            }
351520          },
351521          "modelCard": {
351522            "modelParameters": {
351523              "approach": {}
351524            },
351525            "quantitativeAnalysis": {
351526              "graphics": {}
351527            },
351528            "considerations": {}
351529          }
351530        },
351531        {
351532          "type": "library",
351533          "bom-ref": "pkg:npm/ajv@6.12.6?package-id=9ec92091a2859d9f",
351534          "supplier": {},
351535          "author": "Evgeny Poberezkin",
351536          "name": "ajv",
351537          "version": "6.12.6",
351538          "description": "Another JSON Schema Validator",
351539          "licenses": [
351540            {
351541              "license": {
351542                "id": "MIT"
351543              }
351544            }
351545          ],
351546          "cpe": "cpe:2.3:a:ajv-validator:ajv:6.12.6:*:*:*:*:*:*:*",
351547          "purl": "pkg:npm/ajv@6.12.6",
351548          "swid": {
351549            "attachment": {}
351550          },
351551          "pedigree": {},
351552          "externalReferences": [
351553            {
351554              "url": "git+https://github.com/ajv-validator/ajv.git",
351555              "type": "distribution"
351556            },
351557            {
351558              "url": "https://github.com/ajv-validator/ajv",
351559              "type": "website"
351560            }
351561          ],
351562          "evidence": {},
351563          "signature": {
351564            "signature": {
351565              "publicKey": {}
351566            }
351567          },
351568          "modelCard": {
351569            "modelParameters": {
351570              "approach": {}
351571            },
351572            "quantitativeAnalysis": {
351573              "graphics": {}
351574            },
351575            "considerations": {}
351576          }
351577        },
351578        {
351579          "type": "library",
351580          "bom-ref": "pkg:npm/ajv@6.12.6?package-id=d362ede6e3c68fc2",
351581          "supplier": {},
351582          "author": "Evgeny Poberezkin",
351583          "name": "ajv",
351584          "version": "6.12.6",
351585          "description": "Another JSON Schema Validator",
351586          "licenses": [
351587            {
351588              "license": {
351589                "id": "MIT"
351590              }
351591            }
351592          ],
351593          "cpe": "cpe:2.3:a:ajv-validator:ajv:6.12.6:*:*:*:*:*:*:*",
351594          "purl": "pkg:npm/ajv@6.12.6",
351595          "swid": {
351596            "attachment": {}
351597          },
351598          "pedigree": {},
351599          "externalReferences": [
351600            {
351601              "url": "git+https://github.com/ajv-validator/ajv.git",
351602              "type": "distribution"
351603            },
351604            {
351605              "url": "https://github.com/ajv-validator/ajv",
351606              "type": "website"
351607            }
351608          ],
351609          "evidence": {},
351610          "signature": {
351611            "signature": {
351612              "publicKey": {}
351613            }
351614          },
351615          "modelCard": {
351616            "modelParameters": {
351617              "approach": {}
351618            },
351619            "quantitativeAnalysis": {
351620              "graphics": {}
351621            },
351622            "considerations": {}
351623          }
351624        },
351625        {
351626          "type": "library",
351627          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=92b19c7750fb559d",
351628          "supplier": {},
351629          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
351630          "name": "alpine-baselayout",
351631          "version": "3.4.0-r0",
351632          "description": "Alpine base dir structure and init scripts",
351633          "licenses": [
351634            {
351635              "license": {
351636                "id": "GPL-2.0-only"
351637              }
351638            }
351639          ],
351640          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.4.0-r0:*:*:*:*:*:*:*",
351641          "purl": "pkg:apk/alpine/alpine-baselayout@3.4.0-r0?arch=x86_64\u0026distro=alpine-3.17.3",
351642          "swid": {
351643            "attachment": {}
351644          },
351645          "pedigree": {},
351646          "externalReferences": [
351647            {
351648              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
351649              "type": "distribution"
351650            }
351651          ],
351652          "evidence": {},
351653          "signature": {
351654            "signature": {
351655              "publicKey": {}
351656            }
351657          },
351658          "modelCard": {
351659            "modelParameters": {
351660              "approach": {}
351661            },
351662            "quantitativeAnalysis": {
351663              "graphics": {}
351664            },
351665            "considerations": {}
351666          }
351667        },
351668        {
351669          "type": "library",
351670          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.3\u0026package-id=291d1267b40d636f",
351671          "supplier": {},
351672          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
351673          "name": "alpine-baselayout-data",
351674          "version": "3.4.0-r0",
351675          "description": "Alpine base dir structure and init scripts",
351676          "licenses": [
351677            {
351678              "license": {
351679                "id": "GPL-2.0-only"
351680              }
351681            }
351682          ],
351683          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.4.0-r0:*:*:*:*:*:*:*",
351684          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.4.0-r0?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.17.3",
351685          "swid": {
351686            "attachment": {}
351687          },
351688          "pedigree": {},
351689          "externalReferences": [
351690            {
351691              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
351692              "type": "distribution"
351693            }
351694          ],
351695          "evidence": {},
351696          "signature": {
351697            "signature": {
351698              "publicKey": {}
351699            }
351700          },
351701          "modelCard": {
351702            "modelParameters": {
351703              "approach": {}
351704            },
351705            "quantitativeAnalysis": {
351706              "graphics": {}
351707            },
351708            "considerations": {}
351709          }
351710        },
351711        {
351712          "type": "library",
351713          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=2b5e23d349b556cf",
351714          "supplier": {},
351715          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
351716          "name": "alpine-keys",
351717          "version": "2.4-r1",
351718          "description": "Public keys for Alpine Linux packages",
351719          "licenses": [
351720            {
351721              "license": {
351722                "id": "MIT"
351723              }
351724            }
351725          ],
351726          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
351727          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.17.3",
351728          "swid": {
351729            "attachment": {}
351730          },
351731          "pedigree": {},
351732          "externalReferences": [
351733            {
351734              "url": "https://alpinelinux.org",
351735              "type": "distribution"
351736            }
351737          ],
351738          "evidence": {},
351739          "signature": {
351740            "signature": {
351741              "publicKey": {}
351742            }
351743          },
351744          "modelCard": {
351745            "modelParameters": {
351746              "approach": {}
351747            },
351748            "quantitativeAnalysis": {
351749              "graphics": {}
351750            },
351751            "considerations": {}
351752          }
351753        },
351754        {
351755          "type": "library",
351756          "bom-ref": "pkg:npm/amqplib@0.8.0?package-id=8f58df27c489bc6e",
351757          "supplier": {},
351758          "author": "Michael Bridgen \u003cmikeb@squaremobius.net\u003e",
351759          "name": "amqplib",
351760          "version": "0.8.0",
351761          "description": "An AMQP 0-9-1 (e.g., RabbitMQ) library and client.",
351762          "licenses": [
351763            {
351764              "license": {
351765                "id": "MIT"
351766              }
351767            }
351768          ],
351769          "cpe": "cpe:2.3:a:amqplib:amqplib:0.8.0:*:*:*:*:*:*:*",
351770          "purl": "pkg:npm/amqplib@0.8.0",
351771          "swid": {
351772            "attachment": {}
351773          },
351774          "pedigree": {},
351775          "externalReferences": [
351776            {
351777              "url": "git+https://github.com/squaremo/amqp.node.git",
351778              "type": "distribution"
351779            },
351780            {
351781              "url": "http://squaremo.github.io/amqp.node/",
351782              "type": "website"
351783            }
351784          ],
351785          "evidence": {},
351786          "signature": {
351787            "signature": {
351788              "publicKey": {}
351789            }
351790          },
351791          "modelCard": {
351792            "modelParameters": {
351793              "approach": {}
351794            },
351795            "quantitativeAnalysis": {
351796              "graphics": {}
351797            },
351798            "considerations": {}
351799          }
351800        },
351801        {
351802          "type": "library",
351803          "bom-ref": "pkg:npm/amqplib-tutorials@0.0.1?package-id=3d2fec40696d1aab",
351804          "supplier": {},
351805          "author": "Michael Bridgen \u003cmikeb@squaremobius.net\u003e",
351806          "name": "amqplib-tutorials",
351807          "version": "0.0.1",
351808          "description": "The RabbitMQ tutorials, ported to amqplib",
351809          "licenses": [
351810            {
351811              "license": {
351812                "name": "MPL 2.0"
351813              }
351814            }
351815          ],
351816          "cpe": "cpe:2.3:a:amqplib-tutorials:amqplib-tutorials:0.0.1:*:*:*:*:*:*:*",
351817          "purl": "pkg:npm/amqplib-tutorials@0.0.1",
351818          "swid": {
351819            "attachment": {}
351820          },
351821          "pedigree": {},
351822          "evidence": {},
351823          "signature": {
351824            "signature": {
351825              "publicKey": {}
351826            }
351827          },
351828          "modelCard": {
351829            "modelParameters": {
351830              "approach": {}
351831            },
351832            "quantitativeAnalysis": {
351833              "graphics": {}
351834            },
351835            "considerations": {}
351836          }
351837        },
351838        {
351839          "type": "library",
351840          "bom-ref": "pkg:npm/ansi-align@2.0.0?package-id=d1d8dd5f88203c8",
351841          "supplier": {},
351842          "author": "nexdrew",
351843          "name": "ansi-align",
351844          "version": "2.0.0",
351845          "description": "align-text with ANSI support for CLIs",
351846          "licenses": [
351847            {
351848              "license": {
351849                "id": "ISC"
351850              }
351851            }
351852          ],
351853          "cpe": "cpe:2.3:a:ansi-align:ansi-align:2.0.0:*:*:*:*:*:*:*",
351854          "purl": "pkg:npm/ansi-align@2.0.0",
351855          "swid": {
351856            "attachment": {}
351857          },
351858          "pedigree": {},
351859          "externalReferences": [
351860            {
351861              "url": "git+https://github.com/nexdrew/ansi-align.git",
351862              "type": "distribution"
351863            },
351864            {
351865              "url": "https://github.com/nexdrew/ansi-align#readme",
351866              "type": "website"
351867            }
351868          ],
351869          "evidence": {},
351870          "signature": {
351871            "signature": {
351872              "publicKey": {}
351873            }
351874          },
351875          "modelCard": {
351876            "modelParameters": {
351877              "approach": {}
351878            },
351879            "quantitativeAnalysis": {
351880              "graphics": {}
351881            },
351882            "considerations": {}
351883          }
351884        },
351885        {
351886          "type": "library",
351887          "bom-ref": "pkg:npm/ansi-regex@2.1.1?package-id=b7526b5cc6e97d15",
351888          "supplier": {},
351889          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
351890          "name": "ansi-regex",
351891          "version": "2.1.1",
351892          "description": "Regular expression for matching ANSI escape codes",
351893          "licenses": [
351894            {
351895              "license": {
351896                "id": "MIT"
351897              }
351898            }
351899          ],
351900          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:2.1.1:*:*:*:*:*:*:*",
351901          "purl": "pkg:npm/ansi-regex@2.1.1",
351902          "swid": {
351903            "attachment": {}
351904          },
351905          "pedigree": {},
351906          "externalReferences": [
351907            {
351908              "url": "git+https://github.com/chalk/ansi-regex.git",
351909              "type": "distribution"
351910            },
351911            {
351912              "url": "https://github.com/chalk/ansi-regex#readme",
351913              "type": "website"
351914            }
351915          ],
351916          "evidence": {},
351917          "signature": {
351918            "signature": {
351919              "publicKey": {}
351920            }
351921          },
351922          "modelCard": {
351923            "modelParameters": {
351924              "approach": {}
351925            },
351926            "quantitativeAnalysis": {
351927              "graphics": {}
351928            },
351929            "considerations": {}
351930          }
351931        },
351932        {
351933          "type": "library",
351934          "bom-ref": "pkg:npm/ansi-regex@3.0.0?package-id=f6bd6cc6b4b0fe11",
351935          "supplier": {},
351936          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
351937          "name": "ansi-regex",
351938          "version": "3.0.0",
351939          "description": "Regular expression for matching ANSI escape codes",
351940          "licenses": [
351941            {
351942              "license": {
351943                "id": "MIT"
351944              }
351945            }
351946          ],
351947          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:3.0.0:*:*:*:*:*:*:*",
351948          "purl": "pkg:npm/ansi-regex@3.0.0",
351949          "swid": {
351950            "attachment": {}
351951          },
351952          "pedigree": {},
351953          "externalReferences": [
351954            {
351955              "url": "git+https://github.com/chalk/ansi-regex.git",
351956              "type": "distribution"
351957            },
351958            {
351959              "url": "https://github.com/chalk/ansi-regex#readme",
351960              "type": "website"
351961            }
351962          ],
351963          "evidence": {},
351964          "signature": {
351965            "signature": {
351966              "publicKey": {}
351967            }
351968          },
351969          "modelCard": {
351970            "modelParameters": {
351971              "approach": {}
351972            },
351973            "quantitativeAnalysis": {
351974              "graphics": {}
351975            },
351976            "considerations": {}
351977          }
351978        },
351979        {
351980          "type": "library",
351981          "bom-ref": "pkg:npm/ansi-regex@4.1.0?package-id=1898e7de5ccb0b04",
351982          "supplier": {},
351983          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
351984          "name": "ansi-regex",
351985          "version": "4.1.0",
351986          "description": "Regular expression for matching ANSI escape codes",
351987          "licenses": [
351988            {
351989              "license": {
351990                "id": "MIT"
351991              }
351992            }
351993          ],
351994          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.0:*:*:*:*:*:*:*",
351995          "purl": "pkg:npm/ansi-regex@4.1.0",
351996          "swid": {
351997            "attachment": {}
351998          },
351999          "pedigree": {},
352000          "externalReferences": [
352001            {
352002              "url": "git+https://github.com/chalk/ansi-regex.git",
352003              "type": "distribution"
352004            },
352005            {
352006              "url": "https://github.com/chalk/ansi-regex#readme",
352007              "type": "website"
352008            }
352009          ],
352010          "evidence": {},
352011          "signature": {
352012            "signature": {
352013              "publicKey": {}
352014            }
352015          },
352016          "modelCard": {
352017            "modelParameters": {
352018              "approach": {}
352019            },
352020            "quantitativeAnalysis": {
352021              "graphics": {}
352022            },
352023            "considerations": {}
352024          }
352025        },
352026        {
352027          "type": "library",
352028          "bom-ref": "pkg:npm/ansi-regex@4.1.1?package-id=5d5c8bf716d3dada",
352029          "supplier": {},
352030          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
352031          "name": "ansi-regex",
352032          "version": "4.1.1",
352033          "description": "Regular expression for matching ANSI escape codes",
352034          "licenses": [
352035            {
352036              "license": {
352037                "id": "MIT"
352038              }
352039            }
352040          ],
352041          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.1:*:*:*:*:*:*:*",
352042          "purl": "pkg:npm/ansi-regex@4.1.1",
352043          "swid": {
352044            "attachment": {}
352045          },
352046          "pedigree": {},
352047          "externalReferences": [
352048            {
352049              "url": "git+https://github.com/chalk/ansi-regex.git",
352050              "type": "distribution"
352051            },
352052            {
352053              "url": "https://github.com/chalk/ansi-regex#readme",
352054              "type": "website"
352055            }
352056          ],
352057          "evidence": {},
352058          "signature": {
352059            "signature": {
352060              "publicKey": {}
352061            }
352062          },
352063          "modelCard": {
352064            "modelParameters": {
352065              "approach": {}
352066            },
352067            "quantitativeAnalysis": {
352068              "graphics": {}
352069            },
352070            "considerations": {}
352071          }
352072        },
352073        {
352074          "type": "library",
352075          "bom-ref": "pkg:npm/ansi-regex@4.1.1?package-id=4c2cae6839d80ac9",
352076          "supplier": {},
352077          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
352078          "name": "ansi-regex",
352079          "version": "4.1.1",
352080          "description": "Regular expression for matching ANSI escape codes",
352081          "licenses": [
352082            {
352083              "license": {
352084                "id": "MIT"
352085              }
352086            }
352087          ],
352088          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.1:*:*:*:*:*:*:*",
352089          "purl": "pkg:npm/ansi-regex@4.1.1",
352090          "swid": {
352091            "attachment": {}
352092          },
352093          "pedigree": {},
352094          "externalReferences": [
352095            {
352096              "url": "git+https://github.com/chalk/ansi-regex.git",
352097              "type": "distribution"
352098            },
352099            {
352100              "url": "https://github.com/chalk/ansi-regex#readme",
352101              "type": "website"
352102            }
352103          ],
352104          "evidence": {},
352105          "signature": {
352106            "signature": {
352107              "publicKey": {}
352108            }
352109          },
352110          "modelCard": {
352111            "modelParameters": {
352112              "approach": {}
352113            },
352114            "quantitativeAnalysis": {
352115              "graphics": {}
352116            },
352117            "considerations": {}
352118          }
352119        },
352120        {
352121          "type": "library",
352122          "bom-ref": "pkg:npm/ansi-styles@3.2.1?package-id=822983e67603ef84",
352123          "supplier": {},
352124          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
352125          "name": "ansi-styles",
352126          "version": "3.2.1",
352127          "description": "ANSI escape codes for styling strings in the terminal",
352128          "licenses": [
352129            {
352130              "license": {
352131                "id": "MIT"
352132              }
352133            }
352134          ],
352135          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:3.2.1:*:*:*:*:*:*:*",
352136          "purl": "pkg:npm/ansi-styles@3.2.1",
352137          "swid": {
352138            "attachment": {}
352139          },
352140          "pedigree": {},
352141          "externalReferences": [
352142            {
352143              "url": "git+https://github.com/chalk/ansi-styles.git",
352144              "type": "distribution"
352145            },
352146            {
352147              "url": "https://github.com/chalk/ansi-styles#readme",
352148              "type": "website"
352149            }
352150          ],
352151          "evidence": {},
352152          "signature": {
352153            "signature": {
352154              "publicKey": {}
352155            }
352156          },
352157          "modelCard": {
352158            "modelParameters": {
352159              "approach": {}
352160            },
352161            "quantitativeAnalysis": {
352162              "graphics": {}
352163            },
352164            "considerations": {}
352165          }
352166        },
352167        {
352168          "type": "library",
352169          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=45c620984a9fcd36",
352170          "supplier": {},
352171          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
352172          "name": "ansi-styles",
352173          "version": "4.3.0",
352174          "description": "ANSI escape codes for styling strings in the terminal",
352175          "licenses": [
352176            {
352177              "license": {
352178                "id": "MIT"
352179              }
352180            }
352181          ],
352182          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
352183          "purl": "pkg:npm/ansi-styles@4.3.0",
352184          "swid": {
352185            "attachment": {}
352186          },
352187          "pedigree": {},
352188          "externalReferences": [
352189            {
352190              "url": "git+https://github.com/chalk/ansi-styles.git",
352191              "type": "distribution"
352192            },
352193            {
352194              "url": "https://github.com/chalk/ansi-styles#readme",
352195              "type": "website"
352196            }
352197          ],
352198          "evidence": {},
352199          "signature": {
352200            "signature": {
352201              "publicKey": {}
352202            }
352203          },
352204          "modelCard": {
352205            "modelParameters": {
352206              "approach": {}
352207            },
352208            "quantitativeAnalysis": {
352209              "graphics": {}
352210            },
352211            "considerations": {}
352212          }
352213        },
352214        {
352215          "type": "library",
352216          "bom-ref": "pkg:npm/ansicolors@0.3.2?package-id=b232b7afe5d99ae2",
352217          "supplier": {},
352218          "author": "Thorsten Lorenz \u003cthlorenz@gmx.de\u003e (thlorenz.com)",
352219          "name": "ansicolors",
352220          "version": "0.3.2",
352221          "description": "Functions that surround a string with ansicolor codes so it prints in color.",
352222          "licenses": [
352223            {
352224              "license": {
352225                "id": "MIT"
352226              }
352227            }
352228          ],
352229          "cpe": "cpe:2.3:a:ansicolors:ansicolors:0.3.2:*:*:*:*:*:*:*",
352230          "purl": "pkg:npm/ansicolors@0.3.2",
352231          "swid": {
352232            "attachment": {}
352233          },
352234          "pedigree": {},
352235          "externalReferences": [
352236            {
352237              "url": "git://github.com/thlorenz/ansicolors.git",
352238              "type": "distribution"
352239            },
352240            {
352241              "url": "https://github.com/thlorenz/ansicolors#readme",
352242              "type": "website"
352243            }
352244          ],
352245          "evidence": {},
352246          "signature": {
352247            "signature": {
352248              "publicKey": {}
352249            }
352250          },
352251          "modelCard": {
352252            "modelParameters": {
352253              "approach": {}
352254            },
352255            "quantitativeAnalysis": {
352256              "graphics": {}
352257            },
352258            "considerations": {}
352259          }
352260        },
352261        {
352262          "type": "library",
352263          "bom-ref": "pkg:npm/ansistyles@0.1.3?package-id=3ab660f779efda37",
352264          "supplier": {},
352265          "author": "Thorsten Lorenz \u003cthlorenz@gmx.de\u003e (thlorenz.com)",
352266          "name": "ansistyles",
352267          "version": "0.1.3",
352268          "description": "Functions that surround a string with ansistyle codes so it prints in style.",
352269          "licenses": [
352270            {
352271              "license": {
352272                "id": "MIT"
352273              }
352274            }
352275          ],
352276          "cpe": "cpe:2.3:a:ansistyles:ansistyles:0.1.3:*:*:*:*:*:*:*",
352277          "purl": "pkg:npm/ansistyles@0.1.3",
352278          "swid": {
352279            "attachment": {}
352280          },
352281          "pedigree": {},
352282          "externalReferences": [
352283            {
352284              "url": "git://github.com/thlorenz/ansistyles.git",
352285              "type": "distribution"
352286            },
352287            {
352288              "url": "https://github.com/thlorenz/ansistyles#readme",
352289              "type": "website"
352290            }
352291          ],
352292          "evidence": {},
352293          "signature": {
352294            "signature": {
352295              "publicKey": {}
352296            }
352297          },
352298          "modelCard": {
352299            "modelParameters": {
352300              "approach": {}
352301            },
352302            "quantitativeAnalysis": {
352303              "graphics": {}
352304            },
352305            "considerations": {}
352306          }
352307        },
352308        {
352309          "type": "library",
352310          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=e5f757b0df1f62bc",
352311          "supplier": {},
352312          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
352313          "name": "apk-tools",
352314          "version": "2.12.10-r1",
352315          "description": "Alpine Package Keeper - package manager for alpine",
352316          "licenses": [
352317            {
352318              "license": {
352319                "id": "GPL-2.0-only"
352320              }
352321            }
352322          ],
352323          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.10-r1:*:*:*:*:*:*:*",
352324          "purl": "pkg:apk/alpine/apk-tools@2.12.10-r1?arch=x86_64\u0026distro=alpine-3.17.3",
352325          "swid": {
352326            "attachment": {}
352327          },
352328          "pedigree": {},
352329          "externalReferences": [
352330            {
352331              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
352332              "type": "distribution"
352333            }
352334          ],
352335          "evidence": {},
352336          "signature": {
352337            "signature": {
352338              "publicKey": {}
352339            }
352340          },
352341          "modelCard": {
352342            "modelParameters": {
352343              "approach": {}
352344            },
352345            "quantitativeAnalysis": {
352346              "graphics": {}
352347            },
352348            "considerations": {}
352349          }
352350        },
352351        {
352352          "type": "library",
352353          "bom-ref": "pkg:npm/append-field@1.0.0?package-id=b4d8c83b22bdf90a",
352354          "supplier": {},
352355          "author": "Linus Unnebäck \u003clinus@folkdatorn.se\u003e",
352356          "name": "append-field",
352357          "version": "1.0.0",
352358          "description": "A [W3C HTML JSON forms spec](http://www.w3.org/TR/html-json-forms/) compliant field appender (for lack of a better name). Useful for people implementing `application/x-www-form-urlencoded` and `multipart/form-data` parsers.",
352359          "licenses": [
352360            {
352361              "license": {
352362                "id": "MIT"
352363              }
352364            }
352365          ],
352366          "cpe": "cpe:2.3:a:append-field:append-field:1.0.0:*:*:*:*:*:*:*",
352367          "purl": "pkg:npm/append-field@1.0.0",
352368          "swid": {
352369            "attachment": {}
352370          },
352371          "pedigree": {},
352372          "externalReferences": [
352373            {
352374              "url": "git+ssh://git@github.com/LinusU/node-append-field.git",
352375              "type": "distribution"
352376            },
352377            {
352378              "url": "https://github.com/LinusU/node-append-field#readme",
352379              "type": "website"
352380            }
352381          ],
352382          "evidence": {},
352383          "signature": {
352384            "signature": {
352385              "publicKey": {}
352386            }
352387          },
352388          "modelCard": {
352389            "modelParameters": {
352390              "approach": {}
352391            },
352392            "quantitativeAnalysis": {
352393              "graphics": {}
352394            },
352395            "considerations": {}
352396          }
352397        },
352398        {
352399          "type": "library",
352400          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=46ad585877d1bee7",
352401          "supplier": {},
352402          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
352403          "name": "aproba",
352404          "version": "1.2.0",
352405          "description": "A ridiculously light-weight argument validator (now browser friendly)",
352406          "licenses": [
352407            {
352408              "license": {
352409                "id": "ISC"
352410              }
352411            }
352412          ],
352413          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
352414          "purl": "pkg:npm/aproba@1.2.0",
352415          "swid": {
352416            "attachment": {}
352417          },
352418          "pedigree": {},
352419          "externalReferences": [
352420            {
352421              "url": "git+https://github.com/iarna/aproba.git",
352422              "type": "distribution"
352423            },
352424            {
352425              "url": "https://github.com/iarna/aproba",
352426              "type": "website"
352427            }
352428          ],
352429          "evidence": {},
352430          "signature": {
352431            "signature": {
352432              "publicKey": {}
352433            }
352434          },
352435          "modelCard": {
352436            "modelParameters": {
352437              "approach": {}
352438            },
352439            "quantitativeAnalysis": {
352440              "graphics": {}
352441            },
352442            "considerations": {}
352443          }
352444        },
352445        {
352446          "type": "library",
352447          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=9379102f72715cd",
352448          "supplier": {},
352449          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
352450          "name": "aproba",
352451          "version": "1.2.0",
352452          "description": "A ridiculously light-weight argument validator (now browser friendly)",
352453          "licenses": [
352454            {
352455              "license": {
352456                "id": "ISC"
352457              }
352458            }
352459          ],
352460          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
352461          "purl": "pkg:npm/aproba@1.2.0",
352462          "swid": {
352463            "attachment": {}
352464          },
352465          "pedigree": {},
352466          "externalReferences": [
352467            {
352468              "url": "git+https://github.com/iarna/aproba.git",
352469              "type": "distribution"
352470            },
352471            {
352472              "url": "https://github.com/iarna/aproba",
352473              "type": "website"
352474            }
352475          ],
352476          "evidence": {},
352477          "signature": {
352478            "signature": {
352479              "publicKey": {}
352480            }
352481          },
352482          "modelCard": {
352483            "modelParameters": {
352484              "approach": {}
352485            },
352486            "quantitativeAnalysis": {
352487              "graphics": {}
352488            },
352489            "considerations": {}
352490          }
352491        },
352492        {
352493          "type": "library",
352494          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=b0b533a70d15e523",
352495          "supplier": {},
352496          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
352497          "name": "aproba",
352498          "version": "1.2.0",
352499          "description": "A ridiculously light-weight argument validator (now browser friendly)",
352500          "licenses": [
352501            {
352502              "license": {
352503                "id": "ISC"
352504              }
352505            }
352506          ],
352507          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
352508          "purl": "pkg:npm/aproba@1.2.0",
352509          "swid": {
352510            "attachment": {}
352511          },
352512          "pedigree": {},
352513          "externalReferences": [
352514            {
352515              "url": "git+https://github.com/iarna/aproba.git",
352516              "type": "distribution"
352517            },
352518            {
352519              "url": "https://github.com/iarna/aproba",
352520              "type": "website"
352521            }
352522          ],
352523          "evidence": {},
352524          "signature": {
352525            "signature": {
352526              "publicKey": {}
352527            }
352528          },
352529          "modelCard": {
352530            "modelParameters": {
352531              "approach": {}
352532            },
352533            "quantitativeAnalysis": {
352534              "graphics": {}
352535            },
352536            "considerations": {}
352537          }
352538        },
352539        {
352540          "type": "library",
352541          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=79645860424278c4",
352542          "supplier": {},
352543          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
352544          "name": "aproba",
352545          "version": "1.2.0",
352546          "description": "A ridiculously light-weight argument validator (now browser friendly)",
352547          "licenses": [
352548            {
352549              "license": {
352550                "id": "ISC"
352551              }
352552            }
352553          ],
352554          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
352555          "purl": "pkg:npm/aproba@1.2.0",
352556          "swid": {
352557            "attachment": {}
352558          },
352559          "pedigree": {},
352560          "externalReferences": [
352561            {
352562              "url": "git+https://github.com/iarna/aproba.git",
352563              "type": "distribution"
352564            },
352565            {
352566              "url": "https://github.com/iarna/aproba",
352567              "type": "website"
352568            }
352569          ],
352570          "evidence": {},
352571          "signature": {
352572            "signature": {
352573              "publicKey": {}
352574            }
352575          },
352576          "modelCard": {
352577            "modelParameters": {
352578              "approach": {}
352579            },
352580            "quantitativeAnalysis": {
352581              "graphics": {}
352582            },
352583            "considerations": {}
352584          }
352585        },
352586        {
352587          "type": "library",
352588          "bom-ref": "pkg:npm/aproba@1.2.0?package-id=811071cd19319711",
352589          "supplier": {},
352590          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
352591          "name": "aproba",
352592          "version": "1.2.0",
352593          "description": "A ridiculously light-weight argument validator (now browser friendly)",
352594          "licenses": [
352595            {
352596              "license": {
352597                "id": "ISC"
352598              }
352599            }
352600          ],
352601          "cpe": "cpe:2.3:a:aproba:aproba:1.2.0:*:*:*:*:*:*:*",
352602          "purl": "pkg:npm/aproba@1.2.0",
352603          "swid": {
352604            "attachment": {}
352605          },
352606          "pedigree": {},
352607          "externalReferences": [
352608            {
352609              "url": "git+https://github.com/iarna/aproba.git",
352610              "type": "distribution"
352611            },
352612            {
352613              "url": "https://github.com/iarna/aproba",
352614              "type": "website"
352615            }
352616          ],
352617          "evidence": {},
352618          "signature": {
352619            "signature": {
352620              "publicKey": {}
352621            }
352622          },
352623          "modelCard": {
352624            "modelParameters": {
352625              "approach": {}
352626            },
352627            "quantitativeAnalysis": {
352628              "graphics": {}
352629            },
352630            "considerations": {}
352631          }
352632        },
352633        {
352634          "type": "library",
352635          "bom-ref": "pkg:npm/aproba@2.0.0?package-id=1375db1ef28ee546",
352636          "supplier": {},
352637          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
352638          "name": "aproba",
352639          "version": "2.0.0",
352640          "description": "A ridiculously light-weight argument validator (now browser friendly)",
352641          "licenses": [
352642            {
352643              "license": {
352644                "id": "ISC"
352645              }
352646            }
352647          ],
352648          "cpe": "cpe:2.3:a:aproba:aproba:2.0.0:*:*:*:*:*:*:*",
352649          "purl": "pkg:npm/aproba@2.0.0",
352650          "swid": {
352651            "attachment": {}
352652          },
352653          "pedigree": {},
352654          "externalReferences": [
352655            {
352656              "url": "git+https://github.com/iarna/aproba.git",
352657              "type": "distribution"
352658            },
352659            {
352660              "url": "https://github.com/iarna/aproba",
352661              "type": "website"
352662            }
352663          ],
352664          "evidence": {},
352665          "signature": {
352666            "signature": {
352667              "publicKey": {}
352668            }
352669          },
352670          "modelCard": {
352671            "modelParameters": {
352672              "approach": {}
352673            },
352674            "quantitativeAnalysis": {
352675              "graphics": {}
352676            },
352677            "considerations": {}
352678          }
352679        },
352680        {
352681          "type": "library",
352682          "bom-ref": "pkg:npm/archy@1.0.0?package-id=b81fc5a638c3732d",
352683          "supplier": {},
352684          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
352685          "name": "archy",
352686          "version": "1.0.0",
352687          "description": "render nested hierarchies `npm ls` style with unicode pipes",
352688          "licenses": [
352689            {
352690              "license": {
352691                "id": "MIT"
352692              }
352693            }
352694          ],
352695          "cpe": "cpe:2.3:a:substack:archy:1.0.0:*:*:*:*:*:*:*",
352696          "purl": "pkg:npm/archy@1.0.0",
352697          "swid": {
352698            "attachment": {}
352699          },
352700          "pedigree": {},
352701          "externalReferences": [
352702            {
352703              "url": "git+ssh://git@github.com/substack/node-archy.git",
352704              "type": "distribution"
352705            },
352706            {
352707              "url": "https://github.com/substack/node-archy#readme",
352708              "type": "website"
352709            }
352710          ],
352711          "evidence": {},
352712          "signature": {
352713            "signature": {
352714              "publicKey": {}
352715            }
352716          },
352717          "modelCard": {
352718            "modelParameters": {
352719              "approach": {}
352720            },
352721            "quantitativeAnalysis": {
352722              "graphics": {}
352723            },
352724            "considerations": {}
352725          }
352726        },
352727        {
352728          "type": "library",
352729          "bom-ref": "pkg:npm/are-we-there-yet@1.1.4?package-id=13183467f0c1f82b",
352730          "supplier": {},
352731          "author": "Rebecca Turner (http://re-becca.org)",
352732          "name": "are-we-there-yet",
352733          "version": "1.1.4",
352734          "description": "Keep track of the overall completion of many disparate processes",
352735          "licenses": [
352736            {
352737              "license": {
352738                "id": "ISC"
352739              }
352740            }
352741          ],
352742          "cpe": "cpe:2.3:a:are-we-there-yet:are-we-there-yet:1.1.4:*:*:*:*:*:*:*",
352743          "purl": "pkg:npm/are-we-there-yet@1.1.4",
352744          "swid": {
352745            "attachment": {}
352746          },
352747          "pedigree": {},
352748          "externalReferences": [
352749            {
352750              "url": "git+https://github.com/iarna/are-we-there-yet.git",
352751              "type": "distribution"
352752            },
352753            {
352754              "url": "https://github.com/iarna/are-we-there-yet",
352755              "type": "website"
352756            }
352757          ],
352758          "evidence": {},
352759          "signature": {
352760            "signature": {
352761              "publicKey": {}
352762            }
352763          },
352764          "modelCard": {
352765            "modelParameters": {
352766              "approach": {}
352767            },
352768            "quantitativeAnalysis": {
352769              "graphics": {}
352770            },
352771            "considerations": {}
352772          }
352773        },
352774        {
352775          "type": "library",
352776          "bom-ref": "pkg:npm/array-flatten@1.1.1?package-id=a0792ccdcca020ca",
352777          "supplier": {},
352778          "author": "Blake Embrey \u003chello@blakeembrey.com\u003e (http://blakeembrey.me)",
352779          "name": "array-flatten",
352780          "version": "1.1.1",
352781          "description": "Flatten an array of nested arrays into a single flat array",
352782          "licenses": [
352783            {
352784              "license": {
352785                "id": "MIT"
352786              }
352787            }
352788          ],
352789          "cpe": "cpe:2.3:a:array-flatten:array-flatten:1.1.1:*:*:*:*:*:*:*",
352790          "purl": "pkg:npm/array-flatten@1.1.1",
352791          "swid": {
352792            "attachment": {}
352793          },
352794          "pedigree": {},
352795          "externalReferences": [
352796            {
352797              "url": "git://github.com/blakeembrey/array-flatten.git",
352798              "type": "distribution"
352799            },
352800            {
352801              "url": "https://github.com/blakeembrey/array-flatten",
352802              "type": "website"
352803            }
352804          ],
352805          "evidence": {},
352806          "signature": {
352807            "signature": {
352808              "publicKey": {}
352809            }
352810          },
352811          "modelCard": {
352812            "modelParameters": {
352813              "approach": {}
352814            },
352815            "quantitativeAnalysis": {
352816              "graphics": {}
352817            },
352818            "considerations": {}
352819          }
352820        },
352821        {
352822          "type": "library",
352823          "bom-ref": "pkg:npm/asap@2.0.6?package-id=56ea014550752625",
352824          "supplier": {},
352825          "name": "asap",
352826          "version": "2.0.6",
352827          "description": "High-priority task queue for Node.js and browsers",
352828          "licenses": [
352829            {
352830              "license": {
352831                "id": "MIT"
352832              }
352833            }
352834          ],
352835          "cpe": "cpe:2.3:a:kriskowal:asap:2.0.6:*:*:*:*:*:*:*",
352836          "purl": "pkg:npm/asap@2.0.6",
352837          "swid": {
352838            "attachment": {}
352839          },
352840          "pedigree": {},
352841          "externalReferences": [
352842            {
352843              "url": "git+https://github.com/kriskowal/asap.git",
352844              "type": "distribution"
352845            },
352846            {
352847              "url": "https://github.com/kriskowal/asap#readme",
352848              "type": "website"
352849            }
352850          ],
352851          "evidence": {},
352852          "signature": {
352853            "signature": {
352854              "publicKey": {}
352855            }
352856          },
352857          "modelCard": {
352858            "modelParameters": {
352859              "approach": {}
352860            },
352861            "quantitativeAnalysis": {
352862              "graphics": {}
352863            },
352864            "considerations": {}
352865          }
352866        },
352867        {
352868          "type": "library",
352869          "bom-ref": "pkg:npm/asn1@0.2.4?package-id=1eee44d8949c5741",
352870          "supplier": {},
352871          "author": "Joyent (joyent.com)",
352872          "name": "asn1",
352873          "version": "0.2.4",
352874          "description": "Contains parsers and serializers for ASN.1 (currently BER only)",
352875          "licenses": [
352876            {
352877              "license": {
352878                "id": "MIT"
352879              }
352880            }
352881          ],
352882          "cpe": "cpe:2.3:a:joyent:asn1:0.2.4:*:*:*:*:*:*:*",
352883          "purl": "pkg:npm/asn1@0.2.4",
352884          "swid": {
352885            "attachment": {}
352886          },
352887          "pedigree": {},
352888          "externalReferences": [
352889            {
352890              "url": "git://github.com/joyent/node-asn1.git",
352891              "type": "distribution"
352892            },
352893            {
352894              "url": "https://github.com/joyent/node-asn1#readme",
352895              "type": "website"
352896            }
352897          ],
352898          "evidence": {},
352899          "signature": {
352900            "signature": {
352901              "publicKey": {}
352902            }
352903          },
352904          "modelCard": {
352905            "modelParameters": {
352906              "approach": {}
352907            },
352908            "quantitativeAnalysis": {
352909              "graphics": {}
352910            },
352911            "considerations": {}
352912          }
352913        },
352914        {
352915          "type": "library",
352916          "bom-ref": "pkg:npm/asn1@0.2.6?package-id=aa063fc4d0b38997",
352917          "supplier": {},
352918          "author": "Joyent (joyent.com)",
352919          "name": "asn1",
352920          "version": "0.2.6",
352921          "description": "Contains parsers and serializers for ASN.1 (currently BER only)",
352922          "licenses": [
352923            {
352924              "license": {
352925                "id": "MIT"
352926              }
352927            }
352928          ],
352929          "cpe": "cpe:2.3:a:joyent:asn1:0.2.6:*:*:*:*:*:*:*",
352930          "purl": "pkg:npm/asn1@0.2.6",
352931          "swid": {
352932            "attachment": {}
352933          },
352934          "pedigree": {},
352935          "externalReferences": [
352936            {
352937              "url": "git+https://github.com/joyent/node-asn1.git",
352938              "type": "distribution"
352939            },
352940            {
352941              "url": "https://github.com/joyent/node-asn1#readme",
352942              "type": "website"
352943            }
352944          ],
352945          "evidence": {},
352946          "signature": {
352947            "signature": {
352948              "publicKey": {}
352949            }
352950          },
352951          "modelCard": {
352952            "modelParameters": {
352953              "approach": {}
352954            },
352955            "quantitativeAnalysis": {
352956              "graphics": {}
352957            },
352958            "considerations": {}
352959          }
352960        },
352961        {
352962          "type": "library",
352963          "bom-ref": "pkg:npm/assert-plus@1.0.0?package-id=eb6ed49fde38c7ca",
352964          "supplier": {},
352965          "author": "Mark Cavage \u003cmcavage@gmail.com\u003e",
352966          "name": "assert-plus",
352967          "version": "1.0.0",
352968          "description": "Extra assertions on top of node's assert module",
352969          "licenses": [
352970            {
352971              "license": {
352972                "id": "MIT"
352973              }
352974            }
352975          ],
352976          "cpe": "cpe:2.3:a:assert-plus:assert-plus:1.0.0:*:*:*:*:*:*:*",
352977          "purl": "pkg:npm/assert-plus@1.0.0",
352978          "swid": {
352979            "attachment": {}
352980          },
352981          "pedigree": {},
352982          "externalReferences": [
352983            {
352984              "url": "git+https://github.com/mcavage/node-assert-plus.git",
352985              "type": "distribution"
352986            },
352987            {
352988              "url": "https://github.com/mcavage/node-assert-plus#readme",
352989              "type": "website"
352990            }
352991          ],
352992          "evidence": {},
352993          "signature": {
352994            "signature": {
352995              "publicKey": {}
352996            }
352997          },
352998          "modelCard": {
352999            "modelParameters": {
353000              "approach": {}
353001            },
353002            "quantitativeAnalysis": {
353003              "graphics": {}
353004            },
353005            "considerations": {}
353006          }
353007        },
353008        {
353009          "type": "library",
353010          "bom-ref": "pkg:npm/assert-plus@1.0.0?package-id=7b7c9640aad220f0",
353011          "supplier": {},
353012          "author": "Mark Cavage \u003cmcavage@gmail.com\u003e",
353013          "name": "assert-plus",
353014          "version": "1.0.0",
353015          "description": "Extra assertions on top of node's assert module",
353016          "licenses": [
353017            {
353018              "license": {
353019                "id": "MIT"
353020              }
353021            }
353022          ],
353023          "cpe": "cpe:2.3:a:assert-plus:assert-plus:1.0.0:*:*:*:*:*:*:*",
353024          "purl": "pkg:npm/assert-plus@1.0.0",
353025          "swid": {
353026            "attachment": {}
353027          },
353028          "pedigree": {},
353029          "externalReferences": [
353030            {
353031              "url": "git+https://github.com/mcavage/node-assert-plus.git",
353032              "type": "distribution"
353033            },
353034            {
353035              "url": "https://github.com/mcavage/node-assert-plus#readme",
353036              "type": "website"
353037            }
353038          ],
353039          "evidence": {},
353040          "signature": {
353041            "signature": {
353042              "publicKey": {}
353043            }
353044          },
353045          "modelCard": {
353046            "modelParameters": {
353047              "approach": {}
353048            },
353049            "quantitativeAnalysis": {
353050              "graphics": {}
353051            },
353052            "considerations": {}
353053          }
353054        },
353055        {
353056          "type": "library",
353057          "bom-ref": "pkg:npm/asynckit@0.4.0?package-id=1f30a832887b0ff8",
353058          "supplier": {},
353059          "author": "Alex Indigo \u003ciam@alexindigo.com\u003e",
353060          "name": "asynckit",
353061          "version": "0.4.0",
353062          "description": "Minimal async jobs utility library, with streams support",
353063          "licenses": [
353064            {
353065              "license": {
353066                "id": "MIT"
353067              }
353068            }
353069          ],
353070          "cpe": "cpe:2.3:a:alexindigo:asynckit:0.4.0:*:*:*:*:*:*:*",
353071          "purl": "pkg:npm/asynckit@0.4.0",
353072          "swid": {
353073            "attachment": {}
353074          },
353075          "pedigree": {},
353076          "externalReferences": [
353077            {
353078              "url": "git+https://github.com/alexindigo/asynckit.git",
353079              "type": "distribution"
353080            },
353081            {
353082              "url": "https://github.com/alexindigo/asynckit#readme",
353083              "type": "website"
353084            }
353085          ],
353086          "evidence": {},
353087          "signature": {
353088            "signature": {
353089              "publicKey": {}
353090            }
353091          },
353092          "modelCard": {
353093            "modelParameters": {
353094              "approach": {}
353095            },
353096            "quantitativeAnalysis": {
353097              "graphics": {}
353098            },
353099            "considerations": {}
353100          }
353101        },
353102        {
353103          "type": "library",
353104          "bom-ref": "pkg:npm/asynckit@0.4.0?package-id=7f18bf9a25c0da72",
353105          "supplier": {},
353106          "author": "Alex Indigo \u003ciam@alexindigo.com\u003e",
353107          "name": "asynckit",
353108          "version": "0.4.0",
353109          "description": "Minimal async jobs utility library, with streams support",
353110          "licenses": [
353111            {
353112              "license": {
353113                "id": "MIT"
353114              }
353115            }
353116          ],
353117          "cpe": "cpe:2.3:a:alexindigo:asynckit:0.4.0:*:*:*:*:*:*:*",
353118          "purl": "pkg:npm/asynckit@0.4.0",
353119          "swid": {
353120            "attachment": {}
353121          },
353122          "pedigree": {},
353123          "externalReferences": [
353124            {
353125              "url": "git+https://github.com/alexindigo/asynckit.git",
353126              "type": "distribution"
353127            },
353128            {
353129              "url": "https://github.com/alexindigo/asynckit#readme",
353130              "type": "website"
353131            }
353132          ],
353133          "evidence": {},
353134          "signature": {
353135            "signature": {
353136              "publicKey": {}
353137            }
353138          },
353139          "modelCard": {
353140            "modelParameters": {
353141              "approach": {}
353142            },
353143            "quantitativeAnalysis": {
353144              "graphics": {}
353145            },
353146            "considerations": {}
353147          }
353148        },
353149        {
353150          "type": "library",
353151          "bom-ref": "pkg:npm/aws-sign2@0.7.0?package-id=241ea8f613278aa8",
353152          "supplier": {},
353153          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
353154          "name": "aws-sign2",
353155          "version": "0.7.0",
353156          "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
353157          "licenses": [
353158            {
353159              "license": {
353160                "id": "Apache-2.0"
353161              }
353162            }
353163          ],
353164          "cpe": "cpe:2.3:a:aws-sign2:aws-sign2:0.7.0:*:*:*:*:*:*:*",
353165          "purl": "pkg:npm/aws-sign2@0.7.0",
353166          "swid": {
353167            "attachment": {}
353168          },
353169          "pedigree": {},
353170          "externalReferences": [
353171            {
353172              "url": "git+https://github.com/mikeal/aws-sign.git",
353173              "type": "distribution"
353174            },
353175            {
353176              "url": "https://github.com/mikeal/aws-sign#readme",
353177              "type": "website"
353178            }
353179          ],
353180          "evidence": {},
353181          "signature": {
353182            "signature": {
353183              "publicKey": {}
353184            }
353185          },
353186          "modelCard": {
353187            "modelParameters": {
353188              "approach": {}
353189            },
353190            "quantitativeAnalysis": {
353191              "graphics": {}
353192            },
353193            "considerations": {}
353194          }
353195        },
353196        {
353197          "type": "library",
353198          "bom-ref": "pkg:npm/aws-sign2@0.7.0?package-id=f8fe112c8da3e39f",
353199          "supplier": {},
353200          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
353201          "name": "aws-sign2",
353202          "version": "0.7.0",
353203          "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
353204          "licenses": [
353205            {
353206              "license": {
353207                "id": "Apache-2.0"
353208              }
353209            }
353210          ],
353211          "cpe": "cpe:2.3:a:aws-sign2:aws-sign2:0.7.0:*:*:*:*:*:*:*",
353212          "purl": "pkg:npm/aws-sign2@0.7.0",
353213          "swid": {
353214            "attachment": {}
353215          },
353216          "pedigree": {},
353217          "externalReferences": [
353218            {
353219              "url": "git+https://github.com/mikeal/aws-sign.git",
353220              "type": "distribution"
353221            },
353222            {
353223              "url": "https://github.com/mikeal/aws-sign#readme",
353224              "type": "website"
353225            }
353226          ],
353227          "evidence": {},
353228          "signature": {
353229            "signature": {
353230              "publicKey": {}
353231            }
353232          },
353233          "modelCard": {
353234            "modelParameters": {
353235              "approach": {}
353236            },
353237            "quantitativeAnalysis": {
353238              "graphics": {}
353239            },
353240            "considerations": {}
353241          }
353242        },
353243        {
353244          "type": "library",
353245          "bom-ref": "pkg:npm/aws4@1.11.0?package-id=85277638076a826d",
353246          "supplier": {},
353247          "author": "Michael Hart \u003cmichael.hart.au@gmail.com\u003e (https://github.com/mhart)",
353248          "name": "aws4",
353249          "version": "1.11.0",
353250          "description": "Signs and prepares requests using AWS Signature Version 4",
353251          "licenses": [
353252            {
353253              "license": {
353254                "id": "MIT"
353255              }
353256            }
353257          ],
353258          "cpe": "cpe:2.3:a:mhart:aws4:1.11.0:*:*:*:*:*:*:*",
353259          "purl": "pkg:npm/aws4@1.11.0",
353260          "swid": {
353261            "attachment": {}
353262          },
353263          "pedigree": {},
353264          "externalReferences": [
353265            {
353266              "url": "git+https://github.com/mhart/aws4.git",
353267              "type": "distribution"
353268            },
353269            {
353270              "url": "https://github.com/mhart/aws4#readme",
353271              "type": "website"
353272            }
353273          ],
353274          "evidence": {},
353275          "signature": {
353276            "signature": {
353277              "publicKey": {}
353278            }
353279          },
353280          "modelCard": {
353281            "modelParameters": {
353282              "approach": {}
353283            },
353284            "quantitativeAnalysis": {
353285              "graphics": {}
353286            },
353287            "considerations": {}
353288          }
353289        },
353290        {
353291          "type": "library",
353292          "bom-ref": "pkg:npm/aws4@1.11.0?package-id=aa99a0c281a3b3e5",
353293          "supplier": {},
353294          "author": "Michael Hart \u003cmichael.hart.au@gmail.com\u003e (https://github.com/mhart)",
353295          "name": "aws4",
353296          "version": "1.11.0",
353297          "description": "Signs and prepares requests using AWS Signature Version 4",
353298          "licenses": [
353299            {
353300              "license": {
353301                "id": "MIT"
353302              }
353303            }
353304          ],
353305          "cpe": "cpe:2.3:a:mhart:aws4:1.11.0:*:*:*:*:*:*:*",
353306          "purl": "pkg:npm/aws4@1.11.0",
353307          "swid": {
353308            "attachment": {}
353309          },
353310          "pedigree": {},
353311          "externalReferences": [
353312            {
353313              "url": "git+https://github.com/mhart/aws4.git",
353314              "type": "distribution"
353315            },
353316            {
353317              "url": "https://github.com/mhart/aws4#readme",
353318              "type": "website"
353319            }
353320          ],
353321          "evidence": {},
353322          "signature": {
353323            "signature": {
353324              "publicKey": {}
353325            }
353326          },
353327          "modelCard": {
353328            "modelParameters": {
353329              "approach": {}
353330            },
353331            "quantitativeAnalysis": {
353332              "graphics": {}
353333            },
353334            "considerations": {}
353335          }
353336        },
353337        {
353338          "type": "library",
353339          "bom-ref": "pkg:npm/axios@0.21.1?package-id=5a7030bf3c0c089c",
353340          "supplier": {},
353341          "author": "Matt Zabriskie",
353342          "name": "axios",
353343          "version": "0.21.1",
353344          "description": "Promise based HTTP client for the browser and node.js",
353345          "licenses": [
353346            {
353347              "license": {
353348                "id": "MIT"
353349              }
353350            }
353351          ],
353352          "cpe": "cpe:2.3:a:axios:axios:0.21.1:*:*:*:*:*:*:*",
353353          "purl": "pkg:npm/axios@0.21.1",
353354          "swid": {
353355            "attachment": {}
353356          },
353357          "pedigree": {},
353358          "externalReferences": [
353359            {
353360              "url": "git+https://github.com/axios/axios.git",
353361              "type": "distribution"
353362            },
353363            {
353364              "url": "https://github.com/axios/axios",
353365              "type": "website"
353366            }
353367          ],
353368          "evidence": {},
353369          "signature": {
353370            "signature": {
353371              "publicKey": {}
353372            }
353373          },
353374          "modelCard": {
353375            "modelParameters": {
353376              "approach": {}
353377            },
353378            "quantitativeAnalysis": {
353379              "graphics": {}
353380            },
353381            "considerations": {}
353382          }
353383        },
353384        {
353385          "type": "library",
353386          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=adb20dac41a9f796",
353387          "supplier": {},
353388          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
353389          "name": "balanced-match",
353390          "version": "1.0.2",
353391          "description": "Match balanced character pairs, like \"{\" and \"}\"",
353392          "licenses": [
353393            {
353394              "license": {
353395                "id": "MIT"
353396              }
353397            }
353398          ],
353399          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
353400          "purl": "pkg:npm/balanced-match@1.0.2",
353401          "swid": {
353402            "attachment": {}
353403          },
353404          "pedigree": {},
353405          "externalReferences": [
353406            {
353407              "url": "git://github.com/juliangruber/balanced-match.git",
353408              "type": "distribution"
353409            },
353410            {
353411              "url": "https://github.com/juliangruber/balanced-match",
353412              "type": "website"
353413            }
353414          ],
353415          "evidence": {},
353416          "signature": {
353417            "signature": {
353418              "publicKey": {}
353419            }
353420          },
353421          "modelCard": {
353422            "modelParameters": {
353423              "approach": {}
353424            },
353425            "quantitativeAnalysis": {
353426              "graphics": {}
353427            },
353428            "considerations": {}
353429          }
353430        },
353431        {
353432          "type": "library",
353433          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=c15b2106d0ae19d4",
353434          "supplier": {},
353435          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
353436          "name": "balanced-match",
353437          "version": "1.0.2",
353438          "description": "Match balanced character pairs, like \"{\" and \"}\"",
353439          "licenses": [
353440            {
353441              "license": {
353442                "id": "MIT"
353443              }
353444            }
353445          ],
353446          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
353447          "purl": "pkg:npm/balanced-match@1.0.2",
353448          "swid": {
353449            "attachment": {}
353450          },
353451          "pedigree": {},
353452          "externalReferences": [
353453            {
353454              "url": "git://github.com/juliangruber/balanced-match.git",
353455              "type": "distribution"
353456            },
353457            {
353458              "url": "https://github.com/juliangruber/balanced-match",
353459              "type": "website"
353460            }
353461          ],
353462          "evidence": {},
353463          "signature": {
353464            "signature": {
353465              "publicKey": {}
353466            }
353467          },
353468          "modelCard": {
353469            "modelParameters": {
353470              "approach": {}
353471            },
353472            "quantitativeAnalysis": {
353473              "graphics": {}
353474            },
353475            "considerations": {}
353476          }
353477        },
353478        {
353479          "type": "library",
353480          "bom-ref": "pkg:npm/bcrypt-pbkdf@1.0.2?package-id=3fb909193f37318a",
353481          "supplier": {},
353482          "name": "bcrypt-pbkdf",
353483          "version": "1.0.2",
353484          "description": "Port of the OpenBSD bcrypt_pbkdf function to pure JS",
353485          "licenses": [
353486            {
353487              "license": {
353488                "id": "BSD-3-Clause"
353489              }
353490            }
353491          ],
353492          "cpe": "cpe:2.3:a:bcrypt-pbkdf:bcrypt-pbkdf:1.0.2:*:*:*:*:*:*:*",
353493          "purl": "pkg:npm/bcrypt-pbkdf@1.0.2",
353494          "swid": {
353495            "attachment": {}
353496          },
353497          "pedigree": {},
353498          "externalReferences": [
353499            {
353500              "url": "git://github.com/joyent/node-bcrypt-pbkdf.git",
353501              "type": "distribution"
353502            },
353503            {
353504              "url": "https://github.com/joyent/node-bcrypt-pbkdf#readme",
353505              "type": "website"
353506            }
353507          ],
353508          "evidence": {},
353509          "signature": {
353510            "signature": {
353511              "publicKey": {}
353512            }
353513          },
353514          "modelCard": {
353515            "modelParameters": {
353516              "approach": {}
353517            },
353518            "quantitativeAnalysis": {
353519              "graphics": {}
353520            },
353521            "considerations": {}
353522          }
353523        },
353524        {
353525          "type": "library",
353526          "bom-ref": "pkg:npm/bcrypt-pbkdf@1.0.2?package-id=b345fa0f3bee37c",
353527          "supplier": {},
353528          "name": "bcrypt-pbkdf",
353529          "version": "1.0.2",
353530          "description": "Port of the OpenBSD bcrypt_pbkdf function to pure JS",
353531          "licenses": [
353532            {
353533              "license": {
353534                "id": "BSD-3-Clause"
353535              }
353536            }
353537          ],
353538          "cpe": "cpe:2.3:a:bcrypt-pbkdf:bcrypt-pbkdf:1.0.2:*:*:*:*:*:*:*",
353539          "purl": "pkg:npm/bcrypt-pbkdf@1.0.2",
353540          "swid": {
353541            "attachment": {}
353542          },
353543          "pedigree": {},
353544          "externalReferences": [
353545            {
353546              "url": "git://github.com/joyent/node-bcrypt-pbkdf.git",
353547              "type": "distribution"
353548            },
353549            {
353550              "url": "https://github.com/joyent/node-bcrypt-pbkdf#readme",
353551              "type": "website"
353552            }
353553          ],
353554          "evidence": {},
353555          "signature": {
353556            "signature": {
353557              "publicKey": {}
353558            }
353559          },
353560          "modelCard": {
353561            "modelParameters": {
353562              "approach": {}
353563            },
353564            "quantitativeAnalysis": {
353565              "graphics": {}
353566            },
353567            "considerations": {}
353568          }
353569        },
353570        {
353571          "type": "library",
353572          "bom-ref": "pkg:npm/bin-links@1.1.8?package-id=d51f215e6a9beb3e",
353573          "supplier": {},
353574          "author": "Mike Sherov",
353575          "name": "bin-links",
353576          "version": "1.1.8",
353577          "description": "JavaScript package binary linker",
353578          "licenses": [
353579            {
353580              "license": {
353581                "id": "Artistic-2.0"
353582              }
353583            }
353584          ],
353585          "cpe": "cpe:2.3:a:bin-links:bin-links:1.1.8:*:*:*:*:*:*:*",
353586          "purl": "pkg:npm/bin-links@1.1.8",
353587          "swid": {
353588            "attachment": {}
353589          },
353590          "pedigree": {},
353591          "externalReferences": [
353592            {
353593              "url": "git://github.com/npm/bin-links.git",
353594              "type": "distribution"
353595            },
353596            {
353597              "url": "https://github.com/npm/bin-links#readme",
353598              "type": "website"
353599            }
353600          ],
353601          "evidence": {},
353602          "signature": {
353603            "signature": {
353604              "publicKey": {}
353605            }
353606          },
353607          "modelCard": {
353608            "modelParameters": {
353609              "approach": {}
353610            },
353611            "quantitativeAnalysis": {
353612              "graphics": {}
353613            },
353614            "considerations": {}
353615          }
353616        },
353617        {
353618          "type": "library",
353619          "bom-ref": "pkg:npm/bintrees@1.0.1?package-id=5a6d9e1f935c3a8d",
353620          "supplier": {},
353621          "author": "Vadim Graboys \u003cdimva13@gmail.com\u003e",
353622          "name": "bintrees",
353623          "version": "1.0.1",
353624          "description": "Binary Search Trees",
353625          "cpe": "cpe:2.3:a:bintrees:bintrees:1.0.1:*:*:*:*:*:*:*",
353626          "purl": "pkg:npm/bintrees@1.0.1",
353627          "swid": {
353628            "attachment": {}
353629          },
353630          "pedigree": {},
353631          "externalReferences": [
353632            {
353633              "url": "git://github.com/vadimg/js_bintrees.git",
353634              "type": "distribution"
353635            },
353636            {
353637              "url": "https://github.com/vadimg/js_bintrees#readme",
353638              "type": "website"
353639            }
353640          ],
353641          "evidence": {},
353642          "signature": {
353643            "signature": {
353644              "publicKey": {}
353645            }
353646          },
353647          "modelCard": {
353648            "modelParameters": {
353649              "approach": {}
353650            },
353651            "quantitativeAnalysis": {
353652              "graphics": {}
353653            },
353654            "considerations": {}
353655          }
353656        },
353657        {
353658          "type": "library",
353659          "bom-ref": "pkg:npm/bitsyntax@0.1.0?package-id=77f9fde493f2554e",
353660          "supplier": {},
353661          "author": "Michael Bridgen \u003c\u003cmikeb@squaremobius.net\u003e",
353662          "name": "bitsyntax",
353663          "version": "0.1.0",
353664          "description": "Pattern-matching on byte buffers",
353665          "licenses": [
353666            {
353667              "license": {
353668                "id": "MIT"
353669              }
353670            }
353671          ],
353672          "cpe": "cpe:2.3:a:bitsyntax:bitsyntax:0.1.0:*:*:*:*:*:*:*",
353673          "purl": "pkg:npm/bitsyntax@0.1.0",
353674          "swid": {
353675            "attachment": {}
353676          },
353677          "pedigree": {},
353678          "externalReferences": [
353679            {
353680              "url": "git://github.com/squaremo/bitsyntax-js.git",
353681              "type": "distribution"
353682            },
353683            {
353684              "url": "https://github.com/squaremo/bitsyntax-js#readme",
353685              "type": "website"
353686            }
353687          ],
353688          "evidence": {},
353689          "signature": {
353690            "signature": {
353691              "publicKey": {}
353692            }
353693          },
353694          "modelCard": {
353695            "modelParameters": {
353696              "approach": {}
353697            },
353698            "quantitativeAnalysis": {
353699              "graphics": {}
353700            },
353701            "considerations": {}
353702          }
353703        },
353704        {
353705          "type": "library",
353706          "bom-ref": "pkg:npm/bluebird@3.7.2?package-id=6c0c7cff468c2153",
353707          "supplier": {},
353708          "author": "Petka Antonov \u003cpetka_antonov@hotmail.com\u003e (http://github.com/petkaantonov/)",
353709          "name": "bluebird",
353710          "version": "3.7.2",
353711          "description": "Full featured Promises/A+ implementation with exceptionally good performance",
353712          "licenses": [
353713            {
353714              "license": {
353715                "id": "MIT"
353716              }
353717            }
353718          ],
353719          "cpe": "cpe:2.3:a:petkaantonov:bluebird:3.7.2:*:*:*:*:*:*:*",
353720          "purl": "pkg:npm/bluebird@3.7.2",
353721          "swid": {
353722            "attachment": {}
353723          },
353724          "pedigree": {},
353725          "externalReferences": [
353726            {
353727              "url": "git://github.com/petkaantonov/bluebird.git",
353728              "type": "distribution"
353729            },
353730            {
353731              "url": "https://github.com/petkaantonov/bluebird",
353732              "type": "website"
353733            }
353734          ],
353735          "evidence": {},
353736          "signature": {
353737            "signature": {
353738              "publicKey": {}
353739            }
353740          },
353741          "modelCard": {
353742            "modelParameters": {
353743              "approach": {}
353744            },
353745            "quantitativeAnalysis": {
353746              "graphics": {}
353747            },
353748            "considerations": {}
353749          }
353750        },
353751        {
353752          "type": "library",
353753          "bom-ref": "pkg:npm/bluebird@3.7.2?package-id=6c7af820904460af",
353754          "supplier": {},
353755          "author": "Petka Antonov \u003cpetka_antonov@hotmail.com\u003e (http://github.com/petkaantonov/)",
353756          "name": "bluebird",
353757          "version": "3.7.2",
353758          "description": "Full featured Promises/A+ implementation with exceptionally good performance",
353759          "licenses": [
353760            {
353761              "license": {
353762                "id": "MIT"
353763              }
353764            }
353765          ],
353766          "cpe": "cpe:2.3:a:petkaantonov:bluebird:3.7.2:*:*:*:*:*:*:*",
353767          "purl": "pkg:npm/bluebird@3.7.2",
353768          "swid": {
353769            "attachment": {}
353770          },
353771          "pedigree": {},
353772          "externalReferences": [
353773            {
353774              "url": "git://github.com/petkaantonov/bluebird.git",
353775              "type": "distribution"
353776            },
353777            {
353778              "url": "https://github.com/petkaantonov/bluebird",
353779              "type": "website"
353780            }
353781          ],
353782          "evidence": {},
353783          "signature": {
353784            "signature": {
353785              "publicKey": {}
353786            }
353787          },
353788          "modelCard": {
353789            "modelParameters": {
353790              "approach": {}
353791            },
353792            "quantitativeAnalysis": {
353793              "graphics": {}
353794            },
353795            "considerations": {}
353796          }
353797        },
353798        {
353799          "type": "library",
353800          "bom-ref": "pkg:npm/body-parser@1.19.0?package-id=be42f3aef28246c",
353801          "supplier": {},
353802          "name": "body-parser",
353803          "version": "1.19.0",
353804          "description": "Node.js body parsing middleware",
353805          "licenses": [
353806            {
353807              "license": {
353808                "id": "MIT"
353809              }
353810            }
353811          ],
353812          "cpe": "cpe:2.3:a:body-parser:body-parser:1.19.0:*:*:*:*:*:*:*",
353813          "purl": "pkg:npm/body-parser@1.19.0",
353814          "swid": {
353815            "attachment": {}
353816          },
353817          "pedigree": {},
353818          "externalReferences": [
353819            {
353820              "url": "git+https://github.com/expressjs/body-parser.git",
353821              "type": "distribution"
353822            },
353823            {
353824              "url": "https://github.com/expressjs/body-parser#readme",
353825              "type": "website"
353826            }
353827          ],
353828          "evidence": {},
353829          "signature": {
353830            "signature": {
353831              "publicKey": {}
353832            }
353833          },
353834          "modelCard": {
353835            "modelParameters": {
353836              "approach": {}
353837            },
353838            "quantitativeAnalysis": {
353839              "graphics": {}
353840            },
353841            "considerations": {}
353842          }
353843        },
353844        {
353845          "type": "library",
353846          "bom-ref": "pkg:npm/boolean@3.1.2?package-id=942b43c6d3950300",
353847          "supplier": {},
353848          "name": "boolean",
353849          "version": "3.1.2",
353850          "description": "boolean converts lots of things to boolean.",
353851          "licenses": [
353852            {
353853              "license": {
353854                "id": "MIT"
353855              }
353856            }
353857          ],
353858          "cpe": "cpe:2.3:a:thenativeweb:boolean:3.1.2:*:*:*:*:*:*:*",
353859          "purl": "pkg:npm/boolean@3.1.2",
353860          "swid": {
353861            "attachment": {}
353862          },
353863          "pedigree": {},
353864          "externalReferences": [
353865            {
353866              "url": "git://github.com/thenativeweb/boolean.git",
353867              "type": "distribution"
353868            },
353869            {
353870              "url": "https://github.com/thenativeweb/boolean#readme",
353871              "type": "website"
353872            }
353873          ],
353874          "evidence": {},
353875          "signature": {
353876            "signature": {
353877              "publicKey": {}
353878            }
353879          },
353880          "modelCard": {
353881            "modelParameters": {
353882              "approach": {}
353883            },
353884            "quantitativeAnalysis": {
353885              "graphics": {}
353886            },
353887            "considerations": {}
353888          }
353889        },
353890        {
353891          "type": "library",
353892          "bom-ref": "pkg:npm/boxen@1.3.0?package-id=9733e2ac66f5ce9b",
353893          "supplier": {},
353894          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
353895          "name": "boxen",
353896          "version": "1.3.0",
353897          "description": "Create boxes in the terminal",
353898          "licenses": [
353899            {
353900              "license": {
353901                "id": "MIT"
353902              }
353903            }
353904          ],
353905          "cpe": "cpe:2.3:a:sindresorhus:boxen:1.3.0:*:*:*:*:*:*:*",
353906          "purl": "pkg:npm/boxen@1.3.0",
353907          "swid": {
353908            "attachment": {}
353909          },
353910          "pedigree": {},
353911          "externalReferences": [
353912            {
353913              "url": "git+https://github.com/sindresorhus/boxen.git",
353914              "type": "distribution"
353915            },
353916            {
353917              "url": "https://github.com/sindresorhus/boxen#readme",
353918              "type": "website"
353919            }
353920          ],
353921          "evidence": {},
353922          "signature": {
353923            "signature": {
353924              "publicKey": {}
353925            }
353926          },
353927          "modelCard": {
353928            "modelParameters": {
353929              "approach": {}
353930            },
353931            "quantitativeAnalysis": {
353932              "graphics": {}
353933            },
353934            "considerations": {}
353935          }
353936        },
353937        {
353938          "type": "library",
353939          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=b2f1259ad317cd31",
353940          "supplier": {},
353941          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
353942          "name": "brace-expansion",
353943          "version": "1.1.11",
353944          "description": "Brace expansion as known from sh/bash",
353945          "licenses": [
353946            {
353947              "license": {
353948                "id": "MIT"
353949              }
353950            }
353951          ],
353952          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
353953          "purl": "pkg:npm/brace-expansion@1.1.11",
353954          "swid": {
353955            "attachment": {}
353956          },
353957          "pedigree": {},
353958          "externalReferences": [
353959            {
353960              "url": "git://github.com/juliangruber/brace-expansion.git",
353961              "type": "distribution"
353962            },
353963            {
353964              "url": "https://github.com/juliangruber/brace-expansion",
353965              "type": "website"
353966            }
353967          ],
353968          "evidence": {},
353969          "signature": {
353970            "signature": {
353971              "publicKey": {}
353972            }
353973          },
353974          "modelCard": {
353975            "modelParameters": {
353976              "approach": {}
353977            },
353978            "quantitativeAnalysis": {
353979              "graphics": {}
353980            },
353981            "considerations": {}
353982          }
353983        },
353984        {
353985          "type": "library",
353986          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=a3ea8e119b765a4b",
353987          "supplier": {},
353988          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
353989          "name": "brace-expansion",
353990          "version": "1.1.11",
353991          "description": "Brace expansion as known from sh/bash",
353992          "licenses": [
353993            {
353994              "license": {
353995                "id": "MIT"
353996              }
353997            }
353998          ],
353999          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
354000          "purl": "pkg:npm/brace-expansion@1.1.11",
354001          "swid": {
354002            "attachment": {}
354003          },
354004          "pedigree": {},
354005          "externalReferences": [
354006            {
354007              "url": "git://github.com/juliangruber/brace-expansion.git",
354008              "type": "distribution"
354009            },
354010            {
354011              "url": "https://github.com/juliangruber/brace-expansion",
354012              "type": "website"
354013            }
354014          ],
354015          "evidence": {},
354016          "signature": {
354017            "signature": {
354018              "publicKey": {}
354019            }
354020          },
354021          "modelCard": {
354022            "modelParameters": {
354023              "approach": {}
354024            },
354025            "quantitativeAnalysis": {
354026              "graphics": {}
354027            },
354028            "considerations": {}
354029          }
354030        },
354031        {
354032          "type": "library",
354033          "bom-ref": "pkg:npm/buffer-equal-constant-time@1.0.1?package-id=b79c7a98ecd19a5a",
354034          "supplier": {},
354035          "author": "GoInstant Inc., a salesforce.com company",
354036          "name": "buffer-equal-constant-time",
354037          "version": "1.0.1",
354038          "description": "Constant-time comparison of Buffers",
354039          "licenses": [
354040            {
354041              "license": {
354042                "id": "BSD-3-Clause"
354043              }
354044            }
354045          ],
354046          "cpe": "cpe:2.3:a:buffer-equal-constant-time:buffer-equal-constant-time:1.0.1:*:*:*:*:*:*:*",
354047          "purl": "pkg:npm/buffer-equal-constant-time@1.0.1",
354048          "swid": {
354049            "attachment": {}
354050          },
354051          "pedigree": {},
354052          "externalReferences": [
354053            {
354054              "url": "git+ssh://git@github.com/goinstant/buffer-equal-constant-time.git",
354055              "type": "distribution"
354056            },
354057            {
354058              "url": "https://github.com/goinstant/buffer-equal-constant-time#readme",
354059              "type": "website"
354060            }
354061          ],
354062          "evidence": {},
354063          "signature": {
354064            "signature": {
354065              "publicKey": {}
354066            }
354067          },
354068          "modelCard": {
354069            "modelParameters": {
354070              "approach": {}
354071            },
354072            "quantitativeAnalysis": {
354073              "graphics": {}
354074            },
354075            "considerations": {}
354076          }
354077        },
354078        {
354079          "type": "library",
354080          "bom-ref": "pkg:npm/buffer-from@1.0.0?package-id=679ef1b5d74ace0f",
354081          "supplier": {},
354082          "name": "buffer-from",
354083          "version": "1.0.0",
354084          "description": "A [ponyfill](https://ponyfill.com) for `Buffer.from`, uses native implementation if available.",
354085          "licenses": [
354086            {
354087              "license": {
354088                "id": "MIT"
354089              }
354090            }
354091          ],
354092          "cpe": "cpe:2.3:a:buffer-from:buffer-from:1.0.0:*:*:*:*:*:*:*",
354093          "purl": "pkg:npm/buffer-from@1.0.0",
354094          "swid": {
354095            "attachment": {}
354096          },
354097          "pedigree": {},
354098          "externalReferences": [
354099            {
354100              "url": "git+https://github.com/LinusU/buffer-from.git",
354101              "type": "distribution"
354102            },
354103            {
354104              "url": "https://github.com/LinusU/buffer-from#readme",
354105              "type": "website"
354106            }
354107          ],
354108          "evidence": {},
354109          "signature": {
354110            "signature": {
354111              "publicKey": {}
354112            }
354113          },
354114          "modelCard": {
354115            "modelParameters": {
354116              "approach": {}
354117            },
354118            "quantitativeAnalysis": {
354119              "graphics": {}
354120            },
354121            "considerations": {}
354122          }
354123        },
354124        {
354125          "type": "library",
354126          "bom-ref": "pkg:npm/buffer-from@1.1.1?package-id=f79feba1e77ff417",
354127          "supplier": {},
354128          "name": "buffer-from",
354129          "version": "1.1.1",
354130          "description": "A [ponyfill](https://ponyfill.com) for `Buffer.from`, uses native implementation if available.",
354131          "licenses": [
354132            {
354133              "license": {
354134                "id": "MIT"
354135              }
354136            }
354137          ],
354138          "cpe": "cpe:2.3:a:buffer-from:buffer-from:1.1.1:*:*:*:*:*:*:*",
354139          "purl": "pkg:npm/buffer-from@1.1.1",
354140          "swid": {
354141            "attachment": {}
354142          },
354143          "pedigree": {},
354144          "externalReferences": [
354145            {
354146              "url": "git+https://github.com/LinusU/buffer-from.git",
354147              "type": "distribution"
354148            },
354149            {
354150              "url": "https://github.com/LinusU/buffer-from#readme",
354151              "type": "website"
354152            }
354153          ],
354154          "evidence": {},
354155          "signature": {
354156            "signature": {
354157              "publicKey": {}
354158            }
354159          },
354160          "modelCard": {
354161            "modelParameters": {
354162              "approach": {}
354163            },
354164            "quantitativeAnalysis": {
354165              "graphics": {}
354166            },
354167            "considerations": {}
354168          }
354169        },
354170        {
354171          "type": "library",
354172          "bom-ref": "pkg:npm/buffer-more-ints@1.0.0?package-id=7a3a5c0d6bcfa79e",
354173          "supplier": {},
354174          "author": "David Wragg \u003cdavid@wragg.org\u003e",
354175          "name": "buffer-more-ints",
354176          "version": "1.0.0",
354177          "description": "Add support for more integer widths to Buffer",
354178          "licenses": [
354179            {
354180              "license": {
354181                "id": "MIT"
354182              }
354183            }
354184          ],
354185          "cpe": "cpe:2.3:a:buffer-more-ints:buffer-more-ints:1.0.0:*:*:*:*:*:*:*",
354186          "purl": "pkg:npm/buffer-more-ints@1.0.0",
354187          "swid": {
354188            "attachment": {}
354189          },
354190          "pedigree": {},
354191          "externalReferences": [
354192            {
354193              "url": "git+https://github.com/dpw/node-buffer-more-ints.git",
354194              "type": "distribution"
354195            },
354196            {
354197              "url": "https://github.com/dpw/node-buffer-more-ints",
354198              "type": "website"
354199            }
354200          ],
354201          "evidence": {},
354202          "signature": {
354203            "signature": {
354204              "publicKey": {}
354205            }
354206          },
354207          "modelCard": {
354208            "modelParameters": {
354209              "approach": {}
354210            },
354211            "quantitativeAnalysis": {
354212              "graphics": {}
354213            },
354214            "considerations": {}
354215          }
354216        },
354217        {
354218          "type": "library",
354219          "bom-ref": "pkg:npm/builder-pattern@2.1.0?package-id=9f419aafc0da866c",
354220          "supplier": {},
354221          "name": "builder-pattern",
354222          "version": "2.1.0",
354223          "description": "Create a builder pattern for Typescript using ES6 proxy.",
354224          "licenses": [
354225            {
354226              "license": {
354227                "id": "MIT"
354228              }
354229            }
354230          ],
354231          "cpe": "cpe:2.3:a:builder-pattern:builder-pattern:2.1.0:*:*:*:*:*:*:*",
354232          "purl": "pkg:npm/builder-pattern@2.1.0",
354233          "swid": {
354234            "attachment": {}
354235          },
354236          "pedigree": {},
354237          "externalReferences": [
354238            {
354239              "url": "git+https://github.com/Vincent-Pang/builder-pattern.git",
354240              "type": "distribution"
354241            },
354242            {
354243              "url": "https://github.com/Vincent-Pang/builder-pattern#readme",
354244              "type": "website"
354245            }
354246          ],
354247          "evidence": {},
354248          "signature": {
354249            "signature": {
354250              "publicKey": {}
354251            }
354252          },
354253          "modelCard": {
354254            "modelParameters": {
354255              "approach": {}
354256            },
354257            "quantitativeAnalysis": {
354258              "graphics": {}
354259            },
354260            "considerations": {}
354261          }
354262        },
354263        {
354264          "type": "library",
354265          "bom-ref": "pkg:npm/builtins@1.0.3?package-id=38ca391b8ca0276a",
354266          "supplier": {},
354267          "name": "builtins",
354268          "version": "1.0.3",
354269          "description": "List of node.js builtin modules",
354270          "licenses": [
354271            {
354272              "license": {
354273                "id": "MIT"
354274              }
354275            }
354276          ],
354277          "cpe": "cpe:2.3:a:juliangruber:builtins:1.0.3:*:*:*:*:*:*:*",
354278          "purl": "pkg:npm/builtins@1.0.3",
354279          "swid": {
354280            "attachment": {}
354281          },
354282          "pedigree": {},
354283          "externalReferences": [
354284            {
354285              "url": "git+https://github.com/juliangruber/builtins.git",
354286              "type": "distribution"
354287            },
354288            {
354289              "url": "https://github.com/juliangruber/builtins#readme",
354290              "type": "website"
354291            }
354292          ],
354293          "evidence": {},
354294          "signature": {
354295            "signature": {
354296              "publicKey": {}
354297            }
354298          },
354299          "modelCard": {
354300            "modelParameters": {
354301              "approach": {}
354302            },
354303            "quantitativeAnalysis": {
354304              "graphics": {}
354305            },
354306            "considerations": {}
354307          }
354308        },
354309        {
354310          "type": "library",
354311          "bom-ref": "pkg:npm/busboy@0.2.14?package-id=b320ea57e5b5ba6a",
354312          "supplier": {},
354313          "author": "Brian White \u003cmscdex@mscdex.net\u003e",
354314          "name": "busboy",
354315          "version": "0.2.14",
354316          "description": "A streaming parser for HTML form data for node.js",
354317          "licenses": [
354318            {
354319              "license": {
354320                "id": "MIT"
354321              }
354322            }
354323          ],
354324          "cpe": "cpe:2.3:a:busboy:busboy:0.2.14:*:*:*:*:*:*:*",
354325          "purl": "pkg:npm/busboy@0.2.14",
354326          "swid": {
354327            "attachment": {}
354328          },
354329          "pedigree": {},
354330          "externalReferences": [
354331            {
354332              "url": "git+ssh://git@github.com/mscdex/busboy.git",
354333              "type": "distribution"
354334            },
354335            {
354336              "url": "https://github.com/mscdex/busboy#readme",
354337              "type": "website"
354338            }
354339          ],
354340          "evidence": {},
354341          "signature": {
354342            "signature": {
354343              "publicKey": {}
354344            }
354345          },
354346          "modelCard": {
354347            "modelParameters": {
354348              "approach": {}
354349            },
354350            "quantitativeAnalysis": {
354351              "graphics": {}
354352            },
354353            "considerations": {}
354354          }
354355        },
354356        {
354357          "type": "application",
354358          "bom-ref": "e6c9486419cbb84e",
354359          "supplier": {},
354360          "name": "busybox",
354361          "version": "1.35.0",
354362          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
354363          "swid": {
354364            "attachment": {}
354365          },
354366          "pedigree": {},
354367          "evidence": {},
354368          "signature": {
354369            "signature": {
354370              "publicKey": {}
354371            }
354372          },
354373          "modelCard": {
354374            "modelParameters": {
354375              "approach": {}
354376            },
354377            "quantitativeAnalysis": {
354378              "graphics": {}
354379            },
354380            "considerations": {}
354381          }
354382        },
354383        {
354384          "type": "library",
354385          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=623d53216342d45e",
354386          "supplier": {},
354387          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
354388          "name": "busybox",
354389          "version": "1.35.0-r29",
354390          "description": "Size optimized toolbox of many common UNIX utilities",
354391          "licenses": [
354392            {
354393              "license": {
354394                "id": "GPL-2.0-only"
354395              }
354396            }
354397          ],
354398          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r29:*:*:*:*:*:*:*",
354399          "purl": "pkg:apk/alpine/busybox@1.35.0-r29?arch=x86_64\u0026distro=alpine-3.17.3",
354400          "swid": {
354401            "attachment": {}
354402          },
354403          "pedigree": {},
354404          "externalReferences": [
354405            {
354406              "url": "https://busybox.net/",
354407              "type": "distribution"
354408            }
354409          ],
354410          "evidence": {},
354411          "signature": {
354412            "signature": {
354413              "publicKey": {}
354414            }
354415          },
354416          "modelCard": {
354417            "modelParameters": {
354418              "approach": {}
354419            },
354420            "quantitativeAnalysis": {
354421              "graphics": {}
354422            },
354423            "considerations": {}
354424          }
354425        },
354426        {
354427          "type": "library",
354428          "bom-ref": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3\u0026package-id=256fc96b4a8c4da8",
354429          "supplier": {},
354430          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
354431          "name": "busybox-binsh",
354432          "version": "1.35.0-r29",
354433          "description": "busybox ash /bin/sh",
354434          "licenses": [
354435            {
354436              "license": {
354437                "id": "GPL-2.0-only"
354438              }
354439            }
354440          ],
354441          "cpe": "cpe:2.3:a:busybox-binsh:busybox-binsh:1.35.0-r29:*:*:*:*:*:*:*",
354442          "purl": "pkg:apk/alpine/busybox-binsh@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3",
354443          "swid": {
354444            "attachment": {}
354445          },
354446          "pedigree": {},
354447          "externalReferences": [
354448            {
354449              "url": "https://busybox.net/",
354450              "type": "distribution"
354451            }
354452          ],
354453          "evidence": {},
354454          "signature": {
354455            "signature": {
354456              "publicKey": {}
354457            }
354458          },
354459          "modelCard": {
354460            "modelParameters": {
354461              "approach": {}
354462            },
354463            "quantitativeAnalysis": {
354464              "graphics": {}
354465            },
354466            "considerations": {}
354467          }
354468        },
354469        {
354470          "type": "library",
354471          "bom-ref": "pkg:npm/byline@5.0.0?package-id=bc8643b43cbc314e",
354472          "supplier": {},
354473          "author": "John Hewson",
354474          "name": "byline",
354475          "version": "5.0.0",
354476          "description": "simple line-by-line stream reader",
354477          "licenses": [
354478            {
354479              "license": {
354480                "id": "MIT"
354481              }
354482            }
354483          ],
354484          "cpe": "cpe:2.3:a:jahewson:byline:5.0.0:*:*:*:*:*:*:*",
354485          "purl": "pkg:npm/byline@5.0.0",
354486          "swid": {
354487            "attachment": {}
354488          },
354489          "pedigree": {},
354490          "externalReferences": [
354491            {
354492              "url": "git+https://github.com/jahewson/node-byline.git",
354493              "type": "distribution"
354494            },
354495            {
354496              "url": "https://github.com/jahewson/node-byline",
354497              "type": "website"
354498            }
354499          ],
354500          "evidence": {},
354501          "signature": {
354502            "signature": {
354503              "publicKey": {}
354504            }
354505          },
354506          "modelCard": {
354507            "modelParameters": {
354508              "approach": {}
354509            },
354510            "quantitativeAnalysis": {
354511              "graphics": {}
354512            },
354513            "considerations": {}
354514          }
354515        },
354516        {
354517          "type": "library",
354518          "bom-ref": "pkg:npm/byte-size@5.0.1?package-id=ca5e03ebe208c5ec",
354519          "supplier": {},
354520          "author": "Lloyd Brookes \u003c75pound@gmail.com\u003e",
354521          "name": "byte-size",
354522          "version": "5.0.1",
354523          "description": "Convert a bytes (and octets) value to a more human-readable format. Choose between metric or IEC units.",
354524          "licenses": [
354525            {
354526              "license": {
354527                "id": "MIT"
354528              }
354529            }
354530          ],
354531          "cpe": "cpe:2.3:a:byte-size:byte-size:5.0.1:*:*:*:*:*:*:*",
354532          "purl": "pkg:npm/byte-size@5.0.1",
354533          "swid": {
354534            "attachment": {}
354535          },
354536          "pedigree": {},
354537          "externalReferences": [
354538            {
354539              "url": "git+https://github.com/75lb/byte-size.git",
354540              "type": "distribution"
354541            },
354542            {
354543              "url": "https://github.com/75lb/byte-size#readme",
354544              "type": "website"
354545            }
354546          ],
354547          "evidence": {},
354548          "signature": {
354549            "signature": {
354550              "publicKey": {}
354551            }
354552          },
354553          "modelCard": {
354554            "modelParameters": {
354555              "approach": {}
354556            },
354557            "quantitativeAnalysis": {
354558              "graphics": {}
354559            },
354560            "considerations": {}
354561          }
354562        },
354563        {
354564          "type": "library",
354565          "bom-ref": "pkg:npm/bytes@3.1.0?package-id=b4af9154bbf6604c",
354566          "supplier": {},
354567          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
354568          "name": "bytes",
354569          "version": "3.1.0",
354570          "description": "Utility to parse a string bytes to bytes and vice-versa",
354571          "licenses": [
354572            {
354573              "license": {
354574                "id": "MIT"
354575              }
354576            }
354577          ],
354578          "cpe": "cpe:2.3:a:visionmedia:bytes:3.1.0:*:*:*:*:*:*:*",
354579          "purl": "pkg:npm/bytes@3.1.0",
354580          "swid": {
354581            "attachment": {}
354582          },
354583          "pedigree": {},
354584          "externalReferences": [
354585            {
354586              "url": "git+https://github.com/visionmedia/bytes.js.git",
354587              "type": "distribution"
354588            },
354589            {
354590              "url": "https://github.com/visionmedia/bytes.js#readme",
354591              "type": "website"
354592            }
354593          ],
354594          "evidence": {},
354595          "signature": {
354596            "signature": {
354597              "publicKey": {}
354598            }
354599          },
354600          "modelCard": {
354601            "modelParameters": {
354602              "approach": {}
354603            },
354604            "quantitativeAnalysis": {
354605              "graphics": {}
354606            },
354607            "considerations": {}
354608          }
354609        },
354610        {
354611          "type": "library",
354612          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.3\u0026package-id=b805d823ae624f04",
354613          "supplier": {},
354614          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
354615          "name": "ca-certificates-bundle",
354616          "version": "20220614-r4",
354617          "description": "Pre generated bundle of Mozilla certificates",
354618          "licenses": [
354619            {
354620              "license": {
354621                "id": "MPL-2.0"
354622              }
354623            },
354624            {
354625              "license": {
354626                "name": "AND"
354627              }
354628            },
354629            {
354630              "license": {
354631                "id": "MIT"
354632              }
354633            }
354634          ],
354635          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r4:*:*:*:*:*:*:*",
354636          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r4?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.17.3",
354637          "swid": {
354638            "attachment": {}
354639          },
354640          "pedigree": {},
354641          "externalReferences": [
354642            {
354643              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
354644              "type": "distribution"
354645            }
354646          ],
354647          "evidence": {},
354648          "signature": {
354649            "signature": {
354650              "publicKey": {}
354651            }
354652          },
354653          "modelCard": {
354654            "modelParameters": {
354655              "approach": {}
354656            },
354657            "quantitativeAnalysis": {
354658              "graphics": {}
354659            },
354660            "considerations": {}
354661          }
354662        },
354663        {
354664          "type": "library",
354665          "bom-ref": "pkg:npm/cacache@12.0.4?package-id=7680a280caff40ac",
354666          "supplier": {},
354667          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
354668          "name": "cacache",
354669          "version": "12.0.4",
354670          "description": "Fast, fault-tolerant, cross-platform, disk-based, data-agnostic, content-addressable cache.",
354671          "licenses": [
354672            {
354673              "license": {
354674                "id": "ISC"
354675              }
354676            }
354677          ],
354678          "cpe": "cpe:2.3:a:cacache:cacache:12.0.4:*:*:*:*:*:*:*",
354679          "purl": "pkg:npm/cacache@12.0.4",
354680          "swid": {
354681            "attachment": {}
354682          },
354683          "pedigree": {},
354684          "externalReferences": [
354685            {
354686              "url": "git+https://github.com/npm/cacache.git",
354687              "type": "distribution"
354688            },
354689            {
354690              "url": "https://github.com/npm/cacache#readme",
354691              "type": "website"
354692            }
354693          ],
354694          "evidence": {},
354695          "signature": {
354696            "signature": {
354697              "publicKey": {}
354698            }
354699          },
354700          "modelCard": {
354701            "modelParameters": {
354702              "approach": {}
354703            },
354704            "quantitativeAnalysis": {
354705              "graphics": {}
354706            },
354707            "considerations": {}
354708          }
354709        },
354710        {
354711          "type": "library",
354712          "bom-ref": "pkg:npm/call-limit@1.1.1?package-id=94eefbf82cd78b25",
354713          "supplier": {},
354714          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
354715          "name": "call-limit",
354716          "version": "1.1.1",
354717          "description": "Limit the number of simultaneous calls to an async function",
354718          "licenses": [
354719            {
354720              "license": {
354721                "id": "ISC"
354722              }
354723            }
354724          ],
354725          "cpe": "cpe:2.3:a:call-limit:call-limit:1.1.1:*:*:*:*:*:*:*",
354726          "purl": "pkg:npm/call-limit@1.1.1",
354727          "swid": {
354728            "attachment": {}
354729          },
354730          "pedigree": {},
354731          "externalReferences": [
354732            {
354733              "url": "git+https://github.com/iarna/call-limit.git",
354734              "type": "distribution"
354735            },
354736            {
354737              "url": "https://npmjs.com/packages/call-limit",
354738              "type": "website"
354739            }
354740          ],
354741          "evidence": {},
354742          "signature": {
354743            "signature": {
354744              "publicKey": {}
354745            }
354746          },
354747          "modelCard": {
354748            "modelParameters": {
354749              "approach": {}
354750            },
354751            "quantitativeAnalysis": {
354752              "graphics": {}
354753            },
354754            "considerations": {}
354755          }
354756        },
354757        {
354758          "type": "library",
354759          "bom-ref": "pkg:npm/camelcase@4.1.0?package-id=be57efd9d82defbf",
354760          "supplier": {},
354761          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
354762          "name": "camelcase",
354763          "version": "4.1.0",
354764          "description": "Convert a dash/dot/underscore/space separated string to camelCase: foo-bar → fooBar",
354765          "licenses": [
354766            {
354767              "license": {
354768                "id": "MIT"
354769              }
354770            }
354771          ],
354772          "cpe": "cpe:2.3:a:sindresorhus:camelcase:4.1.0:*:*:*:*:*:*:*",
354773          "purl": "pkg:npm/camelcase@4.1.0",
354774          "swid": {
354775            "attachment": {}
354776          },
354777          "pedigree": {},
354778          "externalReferences": [
354779            {
354780              "url": "git+https://github.com/sindresorhus/camelcase.git",
354781              "type": "distribution"
354782            },
354783            {
354784              "url": "https://github.com/sindresorhus/camelcase#readme",
354785              "type": "website"
354786            }
354787          ],
354788          "evidence": {},
354789          "signature": {
354790            "signature": {
354791              "publicKey": {}
354792            }
354793          },
354794          "modelCard": {
354795            "modelParameters": {
354796              "approach": {}
354797            },
354798            "quantitativeAnalysis": {
354799              "graphics": {}
354800            },
354801            "considerations": {}
354802          }
354803        },
354804        {
354805          "type": "library",
354806          "bom-ref": "pkg:npm/camelcase@5.3.1?package-id=4d249508c958ea3b",
354807          "supplier": {},
354808          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
354809          "name": "camelcase",
354810          "version": "5.3.1",
354811          "description": "Convert a dash/dot/underscore/space separated string to camelCase or PascalCase: `foo-bar` → `fooBar`",
354812          "licenses": [
354813            {
354814              "license": {
354815                "id": "MIT"
354816              }
354817            }
354818          ],
354819          "cpe": "cpe:2.3:a:sindresorhus:camelcase:5.3.1:*:*:*:*:*:*:*",
354820          "purl": "pkg:npm/camelcase@5.3.1",
354821          "swid": {
354822            "attachment": {}
354823          },
354824          "pedigree": {},
354825          "externalReferences": [
354826            {
354827              "url": "git+https://github.com/sindresorhus/camelcase.git",
354828              "type": "distribution"
354829            },
354830            {
354831              "url": "https://github.com/sindresorhus/camelcase#readme",
354832              "type": "website"
354833            }
354834          ],
354835          "evidence": {},
354836          "signature": {
354837            "signature": {
354838              "publicKey": {}
354839            }
354840          },
354841          "modelCard": {
354842            "modelParameters": {
354843              "approach": {}
354844            },
354845            "quantitativeAnalysis": {
354846              "graphics": {}
354847            },
354848            "considerations": {}
354849          }
354850        },
354851        {
354852          "type": "library",
354853          "bom-ref": "pkg:npm/capture-stack-trace@1.0.0?package-id=12efd23d12d8a98f",
354854          "supplier": {},
354855          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
354856          "name": "capture-stack-trace",
354857          "version": "1.0.0",
354858          "description": "Error.captureStackTrace ponyfill",
354859          "licenses": [
354860            {
354861              "license": {
354862                "id": "MIT"
354863              }
354864            }
354865          ],
354866          "cpe": "cpe:2.3:a:capture-stack-trace:capture-stack-trace:1.0.0:*:*:*:*:*:*:*",
354867          "purl": "pkg:npm/capture-stack-trace@1.0.0",
354868          "swid": {
354869            "attachment": {}
354870          },
354871          "pedigree": {},
354872          "externalReferences": [
354873            {
354874              "url": "git+https://github.com/floatdrop/capture-stack-trace.git",
354875              "type": "distribution"
354876            },
354877            {
354878              "url": "https://github.com/floatdrop/capture-stack-trace#readme",
354879              "type": "website"
354880            }
354881          ],
354882          "evidence": {},
354883          "signature": {
354884            "signature": {
354885              "publicKey": {}
354886            }
354887          },
354888          "modelCard": {
354889            "modelParameters": {
354890              "approach": {}
354891            },
354892            "quantitativeAnalysis": {
354893              "graphics": {}
354894            },
354895            "considerations": {}
354896          }
354897        },
354898        {
354899          "type": "library",
354900          "bom-ref": "pkg:npm/caseless@0.12.0?package-id=604b9cbc6038dc91",
354901          "supplier": {},
354902          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
354903          "name": "caseless",
354904          "version": "0.12.0",
354905          "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
354906          "licenses": [
354907            {
354908              "license": {
354909                "id": "Apache-2.0"
354910              }
354911            }
354912          ],
354913          "cpe": "cpe:2.3:a:caseless:caseless:0.12.0:*:*:*:*:*:*:*",
354914          "purl": "pkg:npm/caseless@0.12.0",
354915          "swid": {
354916            "attachment": {}
354917          },
354918          "pedigree": {},
354919          "externalReferences": [
354920            {
354921              "url": "git+https://github.com/mikeal/caseless.git",
354922              "type": "distribution"
354923            },
354924            {
354925              "url": "https://github.com/mikeal/caseless#readme",
354926              "type": "website"
354927            }
354928          ],
354929          "evidence": {},
354930          "signature": {
354931            "signature": {
354932              "publicKey": {}
354933            }
354934          },
354935          "modelCard": {
354936            "modelParameters": {
354937              "approach": {}
354938            },
354939            "quantitativeAnalysis": {
354940              "graphics": {}
354941            },
354942            "considerations": {}
354943          }
354944        },
354945        {
354946          "type": "library",
354947          "bom-ref": "pkg:npm/caseless@0.12.0?package-id=748962a916b10431",
354948          "supplier": {},
354949          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
354950          "name": "caseless",
354951          "version": "0.12.0",
354952          "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
354953          "licenses": [
354954            {
354955              "license": {
354956                "id": "Apache-2.0"
354957              }
354958            }
354959          ],
354960          "cpe": "cpe:2.3:a:caseless:caseless:0.12.0:*:*:*:*:*:*:*",
354961          "purl": "pkg:npm/caseless@0.12.0",
354962          "swid": {
354963            "attachment": {}
354964          },
354965          "pedigree": {},
354966          "externalReferences": [
354967            {
354968              "url": "git+https://github.com/mikeal/caseless.git",
354969              "type": "distribution"
354970            },
354971            {
354972              "url": "https://github.com/mikeal/caseless#readme",
354973              "type": "website"
354974            }
354975          ],
354976          "evidence": {},
354977          "signature": {
354978            "signature": {
354979              "publicKey": {}
354980            }
354981          },
354982          "modelCard": {
354983            "modelParameters": {
354984              "approach": {}
354985            },
354986            "quantitativeAnalysis": {
354987              "graphics": {}
354988            },
354989            "considerations": {}
354990          }
354991        },
354992        {
354993          "type": "library",
354994          "bom-ref": "pkg:npm/chalk@2.4.1?package-id=772c80d6136b5c7c",
354995          "supplier": {},
354996          "name": "chalk",
354997          "version": "2.4.1",
354998          "description": "Terminal string styling done right",
354999          "licenses": [
355000            {
355001              "license": {
355002                "id": "MIT"
355003              }
355004            }
355005          ],
355006          "cpe": "cpe:2.3:a:chalk:chalk:2.4.1:*:*:*:*:*:*:*",
355007          "purl": "pkg:npm/chalk@2.4.1",
355008          "swid": {
355009            "attachment": {}
355010          },
355011          "pedigree": {},
355012          "externalReferences": [
355013            {
355014              "url": "git+https://github.com/chalk/chalk.git",
355015              "type": "distribution"
355016            },
355017            {
355018              "url": "https://github.com/chalk/chalk#readme",
355019              "type": "website"
355020            }
355021          ],
355022          "evidence": {},
355023          "signature": {
355024            "signature": {
355025              "publicKey": {}
355026            }
355027          },
355028          "modelCard": {
355029            "modelParameters": {
355030              "approach": {}
355031            },
355032            "quantitativeAnalysis": {
355033              "graphics": {}
355034            },
355035            "considerations": {}
355036          }
355037        },
355038        {
355039          "type": "library",
355040          "bom-ref": "pkg:npm/chalk@4.1.1?package-id=1a82e45c62ac7e11",
355041          "supplier": {},
355042          "name": "chalk",
355043          "version": "4.1.1",
355044          "description": "Terminal string styling done right",
355045          "licenses": [
355046            {
355047              "license": {
355048                "id": "MIT"
355049              }
355050            }
355051          ],
355052          "cpe": "cpe:2.3:a:chalk:chalk:4.1.1:*:*:*:*:*:*:*",
355053          "purl": "pkg:npm/chalk@4.1.1",
355054          "swid": {
355055            "attachment": {}
355056          },
355057          "pedigree": {},
355058          "externalReferences": [
355059            {
355060              "url": "git+https://github.com/chalk/chalk.git",
355061              "type": "distribution"
355062            },
355063            {
355064              "url": "https://github.com/chalk/chalk#readme",
355065              "type": "website"
355066            }
355067          ],
355068          "evidence": {},
355069          "signature": {
355070            "signature": {
355071              "publicKey": {}
355072            }
355073          },
355074          "modelCard": {
355075            "modelParameters": {
355076              "approach": {}
355077            },
355078            "quantitativeAnalysis": {
355079              "graphics": {}
355080            },
355081            "considerations": {}
355082          }
355083        },
355084        {
355085          "type": "library",
355086          "bom-ref": "pkg:npm/chownr@1.1.4?package-id=8e7f2809309b2b87",
355087          "supplier": {},
355088          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
355089          "name": "chownr",
355090          "version": "1.1.4",
355091          "description": "like `chown -R`",
355092          "licenses": [
355093            {
355094              "license": {
355095                "id": "ISC"
355096              }
355097            }
355098          ],
355099          "cpe": "cpe:2.3:a:chownr:chownr:1.1.4:*:*:*:*:*:*:*",
355100          "purl": "pkg:npm/chownr@1.1.4",
355101          "swid": {
355102            "attachment": {}
355103          },
355104          "pedigree": {},
355105          "externalReferences": [
355106            {
355107              "url": "git://github.com/isaacs/chownr.git",
355108              "type": "distribution"
355109            },
355110            {
355111              "url": "https://github.com/isaacs/chownr#readme",
355112              "type": "website"
355113            }
355114          ],
355115          "evidence": {},
355116          "signature": {
355117            "signature": {
355118              "publicKey": {}
355119            }
355120          },
355121          "modelCard": {
355122            "modelParameters": {
355123              "approach": {}
355124            },
355125            "quantitativeAnalysis": {
355126              "graphics": {}
355127            },
355128            "considerations": {}
355129          }
355130        },
355131        {
355132          "type": "library",
355133          "bom-ref": "pkg:npm/ci-info@1.6.0?package-id=55ea54d1f904bd5e",
355134          "supplier": {},
355135          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
355136          "name": "ci-info",
355137          "version": "1.6.0",
355138          "description": "Get details about the current Continuous Integration environment",
355139          "licenses": [
355140            {
355141              "license": {
355142                "id": "MIT"
355143              }
355144            }
355145          ],
355146          "cpe": "cpe:2.3:a:ci-info:ci-info:1.6.0:*:*:*:*:*:*:*",
355147          "purl": "pkg:npm/ci-info@1.6.0",
355148          "swid": {
355149            "attachment": {}
355150          },
355151          "pedigree": {},
355152          "externalReferences": [
355153            {
355154              "url": "git+https://github.com/watson/ci-info.git",
355155              "type": "distribution"
355156            },
355157            {
355158              "url": "https://github.com/watson/ci-info",
355159              "type": "website"
355160            }
355161          ],
355162          "evidence": {},
355163          "signature": {
355164            "signature": {
355165              "publicKey": {}
355166            }
355167          },
355168          "modelCard": {
355169            "modelParameters": {
355170              "approach": {}
355171            },
355172            "quantitativeAnalysis": {
355173              "graphics": {}
355174            },
355175            "considerations": {}
355176          }
355177        },
355178        {
355179          "type": "library",
355180          "bom-ref": "pkg:npm/ci-info@2.0.0?package-id=16574bf0190b83e7",
355181          "supplier": {},
355182          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
355183          "name": "ci-info",
355184          "version": "2.0.0",
355185          "description": "Get details about the current Continuous Integration environment",
355186          "licenses": [
355187            {
355188              "license": {
355189                "id": "MIT"
355190              }
355191            }
355192          ],
355193          "cpe": "cpe:2.3:a:ci-info:ci-info:2.0.0:*:*:*:*:*:*:*",
355194          "purl": "pkg:npm/ci-info@2.0.0",
355195          "swid": {
355196            "attachment": {}
355197          },
355198          "pedigree": {},
355199          "externalReferences": [
355200            {
355201              "url": "git+https://github.com/watson/ci-info.git",
355202              "type": "distribution"
355203            },
355204            {
355205              "url": "https://github.com/watson/ci-info",
355206              "type": "website"
355207            }
355208          ],
355209          "evidence": {},
355210          "signature": {
355211            "signature": {
355212              "publicKey": {}
355213            }
355214          },
355215          "modelCard": {
355216            "modelParameters": {
355217              "approach": {}
355218            },
355219            "quantitativeAnalysis": {
355220              "graphics": {}
355221            },
355222            "considerations": {}
355223          }
355224        },
355225        {
355226          "type": "library",
355227          "bom-ref": "pkg:npm/cidr-regex@2.0.10?package-id=444a2d33b9bb6cf8",
355228          "supplier": {},
355229          "author": "silverwind \u003cme@silverwind.io\u003e",
355230          "name": "cidr-regex",
355231          "version": "2.0.10",
355232          "description": "Regular expression for matching IP addresses in CIDR notation",
355233          "licenses": [
355234            {
355235              "license": {
355236                "id": "BSD-2-Clause"
355237              }
355238            }
355239          ],
355240          "cpe": "cpe:2.3:a:cidr-regex:cidr-regex:2.0.10:*:*:*:*:*:*:*",
355241          "purl": "pkg:npm/cidr-regex@2.0.10",
355242          "swid": {
355243            "attachment": {}
355244          },
355245          "pedigree": {},
355246          "externalReferences": [
355247            {
355248              "url": "git+https://github.com/silverwind/cidr-regex.git",
355249              "type": "distribution"
355250            },
355251            {
355252              "url": "https://github.com/silverwind/cidr-regex#readme",
355253              "type": "website"
355254            }
355255          ],
355256          "evidence": {},
355257          "signature": {
355258            "signature": {
355259              "publicKey": {}
355260            }
355261          },
355262          "modelCard": {
355263            "modelParameters": {
355264              "approach": {}
355265            },
355266            "quantitativeAnalysis": {
355267              "graphics": {}
355268            },
355269            "considerations": {}
355270          }
355271        },
355272        {
355273          "type": "library",
355274          "bom-ref": "pkg:npm/class-transformer@0.3.1?package-id=e7a380cceb8414d2",
355275          "supplier": {},
355276          "author": "Umed Khudoiberdiev \u003cpleerock.me@gmail.com\u003e",
355277          "name": "class-transformer",
355278          "version": "0.3.1",
355279          "description": "Proper decorator-based transformation / serialization / deserialization of plain javascript objects to class constructors",
355280          "licenses": [
355281            {
355282              "license": {
355283                "id": "MIT"
355284              }
355285            }
355286          ],
355287          "cpe": "cpe:2.3:a:class-transformer:class-transformer:0.3.1:*:*:*:*:*:*:*",
355288          "purl": "pkg:npm/class-transformer@0.3.1",
355289          "swid": {
355290            "attachment": {}
355291          },
355292          "pedigree": {},
355293          "externalReferences": [
355294            {
355295              "url": "git+https://github.com/typestack/class-transformer.git",
355296              "type": "distribution"
355297            },
355298            {
355299              "url": "https://github.com/typestack/class-transformer#readme",
355300              "type": "website"
355301            }
355302          ],
355303          "evidence": {},
355304          "signature": {
355305            "signature": {
355306              "publicKey": {}
355307            }
355308          },
355309          "modelCard": {
355310            "modelParameters": {
355311              "approach": {}
355312            },
355313            "quantitativeAnalysis": {
355314              "graphics": {}
355315            },
355316            "considerations": {}
355317          }
355318        },
355319        {
355320          "type": "library",
355321          "bom-ref": "pkg:npm/class-validator@0.12.2?package-id=c94eed0c9e7dc64a",
355322          "supplier": {},
355323          "author": "Umed Khudoiberdiev \u003cpleerock.me@gmail.com\u003e",
355324          "name": "class-validator",
355325          "version": "0.12.2",
355326          "description": "Class-based validation with Typescript / ES6 / ES5 using decorators or validation schemas. Supports both node.js and browser",
355327          "licenses": [
355328            {
355329              "license": {
355330                "id": "MIT"
355331              }
355332            }
355333          ],
355334          "cpe": "cpe:2.3:a:class-validator:class-validator:0.12.2:*:*:*:*:*:*:*",
355335          "purl": "pkg:npm/class-validator@0.12.2",
355336          "swid": {
355337            "attachment": {}
355338          },
355339          "pedigree": {},
355340          "externalReferences": [
355341            {
355342              "url": "git+https://github.com/typestack/class-validator.git",
355343              "type": "distribution"
355344            },
355345            {
355346              "url": "https://github.com/typestack/class-validator#readme",
355347              "type": "website"
355348            }
355349          ],
355350          "evidence": {},
355351          "signature": {
355352            "signature": {
355353              "publicKey": {}
355354            }
355355          },
355356          "modelCard": {
355357            "modelParameters": {
355358              "approach": {}
355359            },
355360            "quantitativeAnalysis": {
355361              "graphics": {}
355362            },
355363            "considerations": {}
355364          }
355365        },
355366        {
355367          "type": "library",
355368          "bom-ref": "pkg:npm/cli-boxes@1.0.0?package-id=9c02e7f0cdd715b7",
355369          "supplier": {},
355370          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
355371          "name": "cli-boxes",
355372          "version": "1.0.0",
355373          "description": "Boxes for use in the terminal",
355374          "licenses": [
355375            {
355376              "license": {
355377                "id": "MIT"
355378              }
355379            }
355380          ],
355381          "cpe": "cpe:2.3:a:sindresorhus:cli-boxes:1.0.0:*:*:*:*:*:*:*",
355382          "purl": "pkg:npm/cli-boxes@1.0.0",
355383          "swid": {
355384            "attachment": {}
355385          },
355386          "pedigree": {},
355387          "externalReferences": [
355388            {
355389              "url": "git+https://github.com/sindresorhus/cli-boxes.git",
355390              "type": "distribution"
355391            },
355392            {
355393              "url": "https://github.com/sindresorhus/cli-boxes#readme",
355394              "type": "website"
355395            }
355396          ],
355397          "evidence": {},
355398          "signature": {
355399            "signature": {
355400              "publicKey": {}
355401            }
355402          },
355403          "modelCard": {
355404            "modelParameters": {
355405              "approach": {}
355406            },
355407            "quantitativeAnalysis": {
355408              "graphics": {}
355409            },
355410            "considerations": {}
355411          }
355412        },
355413        {
355414          "type": "library",
355415          "bom-ref": "pkg:npm/cli-columns@3.1.2?package-id=e9543de12daa768f",
355416          "supplier": {},
355417          "author": "Shannon Moeller \u003cme@shannonmoeller\u003e (http://shannonmoeller.com)",
355418          "name": "cli-columns",
355419          "version": "3.1.2",
355420          "description": "Columnated lists for the CLI.",
355421          "licenses": [
355422            {
355423              "license": {
355424                "id": "MIT"
355425              }
355426            }
355427          ],
355428          "cpe": "cpe:2.3:a:shannonmoeller:cli-columns:3.1.2:*:*:*:*:*:*:*",
355429          "purl": "pkg:npm/cli-columns@3.1.2",
355430          "swid": {
355431            "attachment": {}
355432          },
355433          "pedigree": {},
355434          "externalReferences": [
355435            {
355436              "url": "git+https://github.com/shannonmoeller/cli-columns.git",
355437              "type": "distribution"
355438            },
355439            {
355440              "url": "https://github.com/shannonmoeller/cli-columns#readme",
355441              "type": "website"
355442            }
355443          ],
355444          "evidence": {},
355445          "signature": {
355446            "signature": {
355447              "publicKey": {}
355448            }
355449          },
355450          "modelCard": {
355451            "modelParameters": {
355452              "approach": {}
355453            },
355454            "quantitativeAnalysis": {
355455              "graphics": {}
355456            },
355457            "considerations": {}
355458          }
355459        },
355460        {
355461          "type": "library",
355462          "bom-ref": "pkg:npm/cli-table3@0.5.1?package-id=65433b3fd2fe95a6",
355463          "supplier": {},
355464          "author": "James Talmage",
355465          "name": "cli-table3",
355466          "version": "0.5.1",
355467          "description": "Pretty unicode tables for the command line. Based on the original cli-table.",
355468          "licenses": [
355469            {
355470              "license": {
355471                "id": "MIT"
355472              }
355473            }
355474          ],
355475          "cpe": "cpe:2.3:a:cli-table3:cli-table3:0.5.1:*:*:*:*:*:*:*",
355476          "purl": "pkg:npm/cli-table3@0.5.1",
355477          "swid": {
355478            "attachment": {}
355479          },
355480          "pedigree": {},
355481          "externalReferences": [
355482            {
355483              "url": "git+https://github.com/cli-table/cli-table3.git",
355484              "type": "distribution"
355485            },
355486            {
355487              "url": "https://github.com/cli-table/cli-table3",
355488              "type": "website"
355489            }
355490          ],
355491          "evidence": {},
355492          "signature": {
355493            "signature": {
355494              "publicKey": {}
355495            }
355496          },
355497          "modelCard": {
355498            "modelParameters": {
355499              "approach": {}
355500            },
355501            "quantitativeAnalysis": {
355502              "graphics": {}
355503            },
355504            "considerations": {}
355505          }
355506        },
355507        {
355508          "type": "library",
355509          "bom-ref": "pkg:npm/cliui@5.0.0?package-id=9c059219de8ff0b6",
355510          "supplier": {},
355511          "author": "Ben Coe \u003cben@npmjs.com\u003e",
355512          "name": "cliui",
355513          "version": "5.0.0",
355514          "description": "easily create complex multi-column command-line-interfaces",
355515          "licenses": [
355516            {
355517              "license": {
355518                "id": "ISC"
355519              }
355520            }
355521          ],
355522          "cpe": "cpe:2.3:a:cliui:cliui:5.0.0:*:*:*:*:*:*:*",
355523          "purl": "pkg:npm/cliui@5.0.0",
355524          "swid": {
355525            "attachment": {}
355526          },
355527          "pedigree": {},
355528          "externalReferences": [
355529            {
355530              "url": "git+ssh://git@github.com/yargs/cliui.git",
355531              "type": "distribution"
355532            },
355533            {
355534              "url": "https://github.com/yargs/cliui#readme",
355535              "type": "website"
355536            }
355537          ],
355538          "evidence": {},
355539          "signature": {
355540            "signature": {
355541              "publicKey": {}
355542            }
355543          },
355544          "modelCard": {
355545            "modelParameters": {
355546              "approach": {}
355547            },
355548            "quantitativeAnalysis": {
355549              "graphics": {}
355550            },
355551            "considerations": {}
355552          }
355553        },
355554        {
355555          "type": "library",
355556          "bom-ref": "pkg:npm/clone@1.0.4?package-id=13cad0458880c288",
355557          "supplier": {},
355558          "author": "Paul Vorbach \u003cpaul@vorba.ch\u003e (http://paul.vorba.ch/)",
355559          "name": "clone",
355560          "version": "1.0.4",
355561          "description": "deep cloning of objects and arrays",
355562          "licenses": [
355563            {
355564              "license": {
355565                "id": "MIT"
355566              }
355567            }
355568          ],
355569          "cpe": "cpe:2.3:a:clone:clone:1.0.4:*:*:*:*:*:*:*",
355570          "purl": "pkg:npm/clone@1.0.4",
355571          "swid": {
355572            "attachment": {}
355573          },
355574          "pedigree": {},
355575          "externalReferences": [
355576            {
355577              "url": "git://github.com/pvorb/node-clone.git",
355578              "type": "distribution"
355579            },
355580            {
355581              "url": "https://github.com/pvorb/node-clone#readme",
355582              "type": "website"
355583            }
355584          ],
355585          "evidence": {},
355586          "signature": {
355587            "signature": {
355588              "publicKey": {}
355589            }
355590          },
355591          "modelCard": {
355592            "modelParameters": {
355593              "approach": {}
355594            },
355595            "quantitativeAnalysis": {
355596              "graphics": {}
355597            },
355598            "considerations": {}
355599          }
355600        },
355601        {
355602          "type": "library",
355603          "bom-ref": "pkg:npm/cmd-shim@3.0.3?package-id=6d36801ba84205fb",
355604          "supplier": {},
355605          "name": "cmd-shim",
355606          "version": "3.0.3",
355607          "description": "Used in npm for command line application support",
355608          "licenses": [
355609            {
355610              "license": {
355611                "id": "ISC"
355612              }
355613            }
355614          ],
355615          "cpe": "cpe:2.3:a:cmd-shim:cmd-shim:3.0.3:*:*:*:*:*:*:*",
355616          "purl": "pkg:npm/cmd-shim@3.0.3",
355617          "swid": {
355618            "attachment": {}
355619          },
355620          "pedigree": {},
355621          "externalReferences": [
355622            {
355623              "url": "git+https://github.com/npm/cmd-shim.git",
355624              "type": "distribution"
355625            },
355626            {
355627              "url": "https://github.com/npm/cmd-shim#readme",
355628              "type": "website"
355629            }
355630          ],
355631          "evidence": {},
355632          "signature": {
355633            "signature": {
355634              "publicKey": {}
355635            }
355636          },
355637          "modelCard": {
355638            "modelParameters": {
355639              "approach": {}
355640            },
355641            "quantitativeAnalysis": {
355642              "graphics": {}
355643            },
355644            "considerations": {}
355645          }
355646        },
355647        {
355648          "type": "library",
355649          "bom-ref": "pkg:npm/code-point-at@1.1.0?package-id=cdc2db70d5aa7113",
355650          "supplier": {},
355651          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
355652          "name": "code-point-at",
355653          "version": "1.1.0",
355654          "description": "ES2015 `String#codePointAt()` ponyfill",
355655          "licenses": [
355656            {
355657              "license": {
355658                "id": "MIT"
355659              }
355660            }
355661          ],
355662          "cpe": "cpe:2.3:a:code-point-at:code-point-at:1.1.0:*:*:*:*:*:*:*",
355663          "purl": "pkg:npm/code-point-at@1.1.0",
355664          "swid": {
355665            "attachment": {}
355666          },
355667          "pedigree": {},
355668          "externalReferences": [
355669            {
355670              "url": "git+https://github.com/sindresorhus/code-point-at.git",
355671              "type": "distribution"
355672            },
355673            {
355674              "url": "https://github.com/sindresorhus/code-point-at#readme",
355675              "type": "website"
355676            }
355677          ],
355678          "evidence": {},
355679          "signature": {
355680            "signature": {
355681              "publicKey": {}
355682            }
355683          },
355684          "modelCard": {
355685            "modelParameters": {
355686              "approach": {}
355687            },
355688            "quantitativeAnalysis": {
355689              "graphics": {}
355690            },
355691            "considerations": {}
355692          }
355693        },
355694        {
355695          "type": "library",
355696          "bom-ref": "pkg:npm/color-convert@1.9.1?package-id=6a9f0408fc41f63d",
355697          "supplier": {},
355698          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
355699          "name": "color-convert",
355700          "version": "1.9.1",
355701          "description": "Plain color conversion functions",
355702          "licenses": [
355703            {
355704              "license": {
355705                "id": "MIT"
355706              }
355707            }
355708          ],
355709          "cpe": "cpe:2.3:a:color-convert:color-convert:1.9.1:*:*:*:*:*:*:*",
355710          "purl": "pkg:npm/color-convert@1.9.1",
355711          "swid": {
355712            "attachment": {}
355713          },
355714          "pedigree": {},
355715          "externalReferences": [
355716            {
355717              "url": "git+https://github.com/Qix-/color-convert.git",
355718              "type": "distribution"
355719            },
355720            {
355721              "url": "https://github.com/Qix-/color-convert#readme",
355722              "type": "website"
355723            }
355724          ],
355725          "evidence": {},
355726          "signature": {
355727            "signature": {
355728              "publicKey": {}
355729            }
355730          },
355731          "modelCard": {
355732            "modelParameters": {
355733              "approach": {}
355734            },
355735            "quantitativeAnalysis": {
355736              "graphics": {}
355737            },
355738            "considerations": {}
355739          }
355740        },
355741        {
355742          "type": "library",
355743          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=417528da04af2cd8",
355744          "supplier": {},
355745          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
355746          "name": "color-convert",
355747          "version": "2.0.1",
355748          "description": "Plain color conversion functions",
355749          "licenses": [
355750            {
355751              "license": {
355752                "id": "MIT"
355753              }
355754            }
355755          ],
355756          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
355757          "purl": "pkg:npm/color-convert@2.0.1",
355758          "swid": {
355759            "attachment": {}
355760          },
355761          "pedigree": {},
355762          "externalReferences": [
355763            {
355764              "url": "git+https://github.com/Qix-/color-convert.git",
355765              "type": "distribution"
355766            },
355767            {
355768              "url": "https://github.com/Qix-/color-convert#readme",
355769              "type": "website"
355770            }
355771          ],
355772          "evidence": {},
355773          "signature": {
355774            "signature": {
355775              "publicKey": {}
355776            }
355777          },
355778          "modelCard": {
355779            "modelParameters": {
355780              "approach": {}
355781            },
355782            "quantitativeAnalysis": {
355783              "graphics": {}
355784            },
355785            "considerations": {}
355786          }
355787        },
355788        {
355789          "type": "library",
355790          "bom-ref": "pkg:npm/color-name@1.1.3?package-id=55fdc340e318670",
355791          "supplier": {},
355792          "author": "DY \u003cdfcreative@gmail.com\u003e",
355793          "name": "color-name",
355794          "version": "1.1.3",
355795          "description": "A list of color names and its values",
355796          "licenses": [
355797            {
355798              "license": {
355799                "id": "MIT"
355800              }
355801            }
355802          ],
355803          "cpe": "cpe:2.3:a:color-name:color-name:1.1.3:*:*:*:*:*:*:*",
355804          "purl": "pkg:npm/color-name@1.1.3",
355805          "swid": {
355806            "attachment": {}
355807          },
355808          "pedigree": {},
355809          "externalReferences": [
355810            {
355811              "url": "git+ssh://git@github.com/dfcreative/color-name.git",
355812              "type": "distribution"
355813            },
355814            {
355815              "url": "https://github.com/dfcreative/color-name",
355816              "type": "website"
355817            }
355818          ],
355819          "evidence": {},
355820          "signature": {
355821            "signature": {
355822              "publicKey": {}
355823            }
355824          },
355825          "modelCard": {
355826            "modelParameters": {
355827              "approach": {}
355828            },
355829            "quantitativeAnalysis": {
355830              "graphics": {}
355831            },
355832            "considerations": {}
355833          }
355834        },
355835        {
355836          "type": "library",
355837          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=f1798456080e41f3",
355838          "supplier": {},
355839          "author": "DY \u003cdfcreative@gmail.com\u003e",
355840          "name": "color-name",
355841          "version": "1.1.4",
355842          "description": "A list of color names and its values",
355843          "licenses": [
355844            {
355845              "license": {
355846                "id": "MIT"
355847              }
355848            }
355849          ],
355850          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
355851          "purl": "pkg:npm/color-name@1.1.4",
355852          "swid": {
355853            "attachment": {}
355854          },
355855          "pedigree": {},
355856          "externalReferences": [
355857            {
355858              "url": "git+ssh://git@github.com/colorjs/color-name.git",
355859              "type": "distribution"
355860            },
355861            {
355862              "url": "https://github.com/colorjs/color-name",
355863              "type": "website"
355864            }
355865          ],
355866          "evidence": {},
355867          "signature": {
355868            "signature": {
355869              "publicKey": {}
355870            }
355871          },
355872          "modelCard": {
355873            "modelParameters": {
355874              "approach": {}
355875            },
355876            "quantitativeAnalysis": {
355877              "graphics": {}
355878            },
355879            "considerations": {}
355880          }
355881        },
355882        {
355883          "type": "library",
355884          "bom-ref": "pkg:npm/colors@1.3.3?package-id=c0b370b3fbefe8a8",
355885          "supplier": {},
355886          "author": "Marak Squires",
355887          "name": "colors",
355888          "version": "1.3.3",
355889          "description": "get colors in your node.js console",
355890          "licenses": [
355891            {
355892              "license": {
355893                "id": "MIT"
355894              }
355895            }
355896          ],
355897          "cpe": "cpe:2.3:a:colors:colors:1.3.3:*:*:*:*:*:*:*",
355898          "purl": "pkg:npm/colors@1.3.3",
355899          "swid": {
355900            "attachment": {}
355901          },
355902          "pedigree": {},
355903          "externalReferences": [
355904            {
355905              "url": "git+ssh://git@github.com/Marak/colors.js.git",
355906              "type": "distribution"
355907            },
355908            {
355909              "url": "https://github.com/Marak/colors.js",
355910              "type": "website"
355911            }
355912          ],
355913          "evidence": {},
355914          "signature": {
355915            "signature": {
355916              "publicKey": {}
355917            }
355918          },
355919          "modelCard": {
355920            "modelParameters": {
355921              "approach": {}
355922            },
355923            "quantitativeAnalysis": {
355924              "graphics": {}
355925            },
355926            "considerations": {}
355927          }
355928        },
355929        {
355930          "type": "library",
355931          "bom-ref": "pkg:npm/columnify@1.5.4?package-id=c10dc5491c1ec9ba",
355932          "supplier": {},
355933          "author": "Tim Oxley",
355934          "name": "columnify",
355935          "version": "1.5.4",
355936          "description": "Render data in text columns. Supports in-column text-wrap.",
355937          "licenses": [
355938            {
355939              "license": {
355940                "id": "MIT"
355941              }
355942            }
355943          ],
355944          "cpe": "cpe:2.3:a:columnify:columnify:1.5.4:*:*:*:*:*:*:*",
355945          "purl": "pkg:npm/columnify@1.5.4",
355946          "swid": {
355947            "attachment": {}
355948          },
355949          "pedigree": {},
355950          "externalReferences": [
355951            {
355952              "url": "git://github.com/timoxley/columnify.git",
355953              "type": "distribution"
355954            },
355955            {
355956              "url": "https://github.com/timoxley/columnify",
355957              "type": "website"
355958            }
355959          ],
355960          "evidence": {},
355961          "signature": {
355962            "signature": {
355963              "publicKey": {}
355964            }
355965          },
355966          "modelCard": {
355967            "modelParameters": {
355968              "approach": {}
355969            },
355970            "quantitativeAnalysis": {
355971              "graphics": {}
355972            },
355973            "considerations": {}
355974          }
355975        },
355976        {
355977          "type": "library",
355978          "bom-ref": "pkg:npm/combined-stream@1.0.8?package-id=1815a102a95b1ebf",
355979          "supplier": {},
355980          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
355981          "name": "combined-stream",
355982          "version": "1.0.8",
355983          "description": "A stream that emits multiple other streams one after another.",
355984          "licenses": [
355985            {
355986              "license": {
355987                "id": "MIT"
355988              }
355989            }
355990          ],
355991          "cpe": "cpe:2.3:a:combined-stream:combined-stream:1.0.8:*:*:*:*:*:*:*",
355992          "purl": "pkg:npm/combined-stream@1.0.8",
355993          "swid": {
355994            "attachment": {}
355995          },
355996          "pedigree": {},
355997          "externalReferences": [
355998            {
355999              "url": "git://github.com/felixge/node-combined-stream.git",
356000              "type": "distribution"
356001            },
356002            {
356003              "url": "https://github.com/felixge/node-combined-stream",
356004              "type": "website"
356005            }
356006          ],
356007          "evidence": {},
356008          "signature": {
356009            "signature": {
356010              "publicKey": {}
356011            }
356012          },
356013          "modelCard": {
356014            "modelParameters": {
356015              "approach": {}
356016            },
356017            "quantitativeAnalysis": {
356018              "graphics": {}
356019            },
356020            "considerations": {}
356021          }
356022        },
356023        {
356024          "type": "library",
356025          "bom-ref": "pkg:npm/combined-stream@1.0.8?package-id=b5f6265c23d4a45d",
356026          "supplier": {},
356027          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
356028          "name": "combined-stream",
356029          "version": "1.0.8",
356030          "description": "A stream that emits multiple other streams one after another.",
356031          "licenses": [
356032            {
356033              "license": {
356034                "id": "MIT"
356035              }
356036            }
356037          ],
356038          "cpe": "cpe:2.3:a:combined-stream:combined-stream:1.0.8:*:*:*:*:*:*:*",
356039          "purl": "pkg:npm/combined-stream@1.0.8",
356040          "swid": {
356041            "attachment": {}
356042          },
356043          "pedigree": {},
356044          "externalReferences": [
356045            {
356046              "url": "git://github.com/felixge/node-combined-stream.git",
356047              "type": "distribution"
356048            },
356049            {
356050              "url": "https://github.com/felixge/node-combined-stream",
356051              "type": "website"
356052            }
356053          ],
356054          "evidence": {},
356055          "signature": {
356056            "signature": {
356057              "publicKey": {}
356058            }
356059          },
356060          "modelCard": {
356061            "modelParameters": {
356062              "approach": {}
356063            },
356064            "quantitativeAnalysis": {
356065              "graphics": {}
356066            },
356067            "considerations": {}
356068          }
356069        },
356070        {
356071          "type": "library",
356072          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=cae0cd90b1194aad",
356073          "supplier": {},
356074          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
356075          "name": "concat-map",
356076          "version": "0.0.1",
356077          "description": "concatenative mapdashery",
356078          "licenses": [
356079            {
356080              "license": {
356081                "id": "MIT"
356082              }
356083            }
356084          ],
356085          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
356086          "purl": "pkg:npm/concat-map@0.0.1",
356087          "swid": {
356088            "attachment": {}
356089          },
356090          "pedigree": {},
356091          "externalReferences": [
356092            {
356093              "url": "git://github.com/substack/node-concat-map.git",
356094              "type": "distribution"
356095            },
356096            {
356097              "url": "https://github.com/substack/node-concat-map#readme",
356098              "type": "website"
356099            }
356100          ],
356101          "evidence": {},
356102          "signature": {
356103            "signature": {
356104              "publicKey": {}
356105            }
356106          },
356107          "modelCard": {
356108            "modelParameters": {
356109              "approach": {}
356110            },
356111            "quantitativeAnalysis": {
356112              "graphics": {}
356113            },
356114            "considerations": {}
356115          }
356116        },
356117        {
356118          "type": "library",
356119          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=329fc63deaa5be87",
356120          "supplier": {},
356121          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
356122          "name": "concat-map",
356123          "version": "0.0.1",
356124          "description": "concatenative mapdashery",
356125          "licenses": [
356126            {
356127              "license": {
356128                "id": "MIT"
356129              }
356130            }
356131          ],
356132          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
356133          "purl": "pkg:npm/concat-map@0.0.1",
356134          "swid": {
356135            "attachment": {}
356136          },
356137          "pedigree": {},
356138          "externalReferences": [
356139            {
356140              "url": "git://github.com/substack/node-concat-map.git",
356141              "type": "distribution"
356142            },
356143            {
356144              "url": "https://github.com/substack/node-concat-map#readme",
356145              "type": "website"
356146            }
356147          ],
356148          "evidence": {},
356149          "signature": {
356150            "signature": {
356151              "publicKey": {}
356152            }
356153          },
356154          "modelCard": {
356155            "modelParameters": {
356156              "approach": {}
356157            },
356158            "quantitativeAnalysis": {
356159              "graphics": {}
356160            },
356161            "considerations": {}
356162          }
356163        },
356164        {
356165          "type": "library",
356166          "bom-ref": "pkg:npm/concat-stream@1.6.2?package-id=bc1b41c56853527e",
356167          "supplier": {},
356168          "author": "Max Ogden \u003cmax@maxogden.com\u003e",
356169          "name": "concat-stream",
356170          "version": "1.6.2",
356171          "description": "writable stream that concatenates strings or binary data and calls a callback with the result",
356172          "licenses": [
356173            {
356174              "license": {
356175                "id": "MIT"
356176              }
356177            }
356178          ],
356179          "cpe": "cpe:2.3:a:concat-stream:concat-stream:1.6.2:*:*:*:*:*:*:*",
356180          "purl": "pkg:npm/concat-stream@1.6.2",
356181          "swid": {
356182            "attachment": {}
356183          },
356184          "pedigree": {},
356185          "externalReferences": [
356186            {
356187              "url": "git+ssh://git@github.com/maxogden/concat-stream.git",
356188              "type": "distribution"
356189            },
356190            {
356191              "url": "https://github.com/maxogden/concat-stream#readme",
356192              "type": "website"
356193            }
356194          ],
356195          "evidence": {},
356196          "signature": {
356197            "signature": {
356198              "publicKey": {}
356199            }
356200          },
356201          "modelCard": {
356202            "modelParameters": {
356203              "approach": {}
356204            },
356205            "quantitativeAnalysis": {
356206              "graphics": {}
356207            },
356208            "considerations": {}
356209          }
356210        },
356211        {
356212          "type": "library",
356213          "bom-ref": "pkg:npm/concat-stream@1.6.2?package-id=a6eeed3b9d53d4b7",
356214          "supplier": {},
356215          "author": "Max Ogden \u003cmax@maxogden.com\u003e",
356216          "name": "concat-stream",
356217          "version": "1.6.2",
356218          "description": "writable stream that concatenates strings or binary data and calls a callback with the result",
356219          "licenses": [
356220            {
356221              "license": {
356222                "id": "MIT"
356223              }
356224            }
356225          ],
356226          "cpe": "cpe:2.3:a:concat-stream:concat-stream:1.6.2:*:*:*:*:*:*:*",
356227          "purl": "pkg:npm/concat-stream@1.6.2",
356228          "swid": {
356229            "attachment": {}
356230          },
356231          "pedigree": {},
356232          "externalReferences": [
356233            {
356234              "url": "git+ssh://git@github.com/maxogden/concat-stream.git",
356235              "type": "distribution"
356236            },
356237            {
356238              "url": "https://github.com/maxogden/concat-stream#readme",
356239              "type": "website"
356240            }
356241          ],
356242          "evidence": {},
356243          "signature": {
356244            "signature": {
356245              "publicKey": {}
356246            }
356247          },
356248          "modelCard": {
356249            "modelParameters": {
356250              "approach": {}
356251            },
356252            "quantitativeAnalysis": {
356253              "graphics": {}
356254            },
356255            "considerations": {}
356256          }
356257        },
356258        {
356259          "type": "library",
356260          "bom-ref": "pkg:npm/config-chain@1.1.13?package-id=15f9933a1e5292dc",
356261          "supplier": {},
356262          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (http://dominictarr.com)",
356263          "name": "config-chain",
356264          "version": "1.1.13",
356265          "description": "HANDLE CONFIGURATION ONCE AND FOR ALL",
356266          "licenses": [
356267            {
356268              "license": {
356269                "id": "MIT"
356270              }
356271            }
356272          ],
356273          "cpe": "cpe:2.3:a:config-chain:config-chain:1.1.13:*:*:*:*:*:*:*",
356274          "purl": "pkg:npm/config-chain@1.1.13",
356275          "swid": {
356276            "attachment": {}
356277          },
356278          "pedigree": {},
356279          "externalReferences": [
356280            {
356281              "url": "git+https://github.com/dominictarr/config-chain.git",
356282              "type": "distribution"
356283            },
356284            {
356285              "url": "http://github.com/dominictarr/config-chain",
356286              "type": "website"
356287            }
356288          ],
356289          "evidence": {},
356290          "signature": {
356291            "signature": {
356292              "publicKey": {}
356293            }
356294          },
356295          "modelCard": {
356296            "modelParameters": {
356297              "approach": {}
356298            },
356299            "quantitativeAnalysis": {
356300              "graphics": {}
356301            },
356302            "considerations": {}
356303          }
356304        },
356305        {
356306          "type": "library",
356307          "bom-ref": "pkg:npm/configstore@3.1.5?package-id=cbe4550eb45f019",
356308          "supplier": {},
356309          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
356310          "name": "configstore",
356311          "version": "3.1.5",
356312          "description": "Easily load and save config without having to think about where and how",
356313          "licenses": [
356314            {
356315              "license": {
356316                "id": "BSD-2-Clause"
356317              }
356318            }
356319          ],
356320          "cpe": "cpe:2.3:a:configstore:configstore:3.1.5:*:*:*:*:*:*:*",
356321          "purl": "pkg:npm/configstore@3.1.5",
356322          "swid": {
356323            "attachment": {}
356324          },
356325          "pedigree": {},
356326          "externalReferences": [
356327            {
356328              "url": "git+https://github.com/yeoman/configstore.git",
356329              "type": "distribution"
356330            },
356331            {
356332              "url": "https://github.com/yeoman/configstore#readme",
356333              "type": "website"
356334            }
356335          ],
356336          "evidence": {},
356337          "signature": {
356338            "signature": {
356339              "publicKey": {}
356340            }
356341          },
356342          "modelCard": {
356343            "modelParameters": {
356344              "approach": {}
356345            },
356346            "quantitativeAnalysis": {
356347              "graphics": {}
356348            },
356349            "considerations": {}
356350          }
356351        },
356352        {
356353          "type": "library",
356354          "bom-ref": "pkg:npm/consola@2.15.3?package-id=9b03a0585128a93a",
356355          "supplier": {},
356356          "name": "consola",
356357          "version": "2.15.3",
356358          "description": "Elegant Console Logger for Node.js and Browser",
356359          "licenses": [
356360            {
356361              "license": {
356362                "id": "MIT"
356363              }
356364            }
356365          ],
356366          "cpe": "cpe:2.3:a:consola:consola:2.15.3:*:*:*:*:*:*:*",
356367          "purl": "pkg:npm/consola@2.15.3",
356368          "swid": {
356369            "attachment": {}
356370          },
356371          "pedigree": {},
356372          "externalReferences": [
356373            {
356374              "url": "git+https://github.com/nuxt/consola.git",
356375              "type": "distribution"
356376            },
356377            {
356378              "url": "https://github.com/nuxt/consola#readme",
356379              "type": "website"
356380            }
356381          ],
356382          "evidence": {},
356383          "signature": {
356384            "signature": {
356385              "publicKey": {}
356386            }
356387          },
356388          "modelCard": {
356389            "modelParameters": {
356390              "approach": {}
356391            },
356392            "quantitativeAnalysis": {
356393              "graphics": {}
356394            },
356395            "considerations": {}
356396          }
356397        },
356398        {
356399          "type": "library",
356400          "bom-ref": "pkg:npm/console-control-strings@1.1.0?package-id=40a4233e59daf424",
356401          "supplier": {},
356402          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
356403          "name": "console-control-strings",
356404          "version": "1.1.0",
356405          "description": "A library of cross-platform tested terminal/console command strings for doing things like color and cursor positioning.  This is a subset of both ansi and vt100.  All control codes included work on both Windows \u0026 Unix-like OSes, except where noted.",
356406          "licenses": [
356407            {
356408              "license": {
356409                "id": "ISC"
356410              }
356411            }
356412          ],
356413          "cpe": "cpe:2.3:a:console-control-strings:console-control-strings:1.1.0:*:*:*:*:*:*:*",
356414          "purl": "pkg:npm/console-control-strings@1.1.0",
356415          "swid": {
356416            "attachment": {}
356417          },
356418          "pedigree": {},
356419          "externalReferences": [
356420            {
356421              "url": "git+https://github.com/iarna/console-control-strings.git",
356422              "type": "distribution"
356423            },
356424            {
356425              "url": "https://github.com/iarna/console-control-strings#readme",
356426              "type": "website"
356427            }
356428          ],
356429          "evidence": {},
356430          "signature": {
356431            "signature": {
356432              "publicKey": {}
356433            }
356434          },
356435          "modelCard": {
356436            "modelParameters": {
356437              "approach": {}
356438            },
356439            "quantitativeAnalysis": {
356440              "graphics": {}
356441            },
356442            "considerations": {}
356443          }
356444        },
356445        {
356446          "type": "library",
356447          "bom-ref": "pkg:npm/content-disposition@0.5.3?package-id=9818af4848590460",
356448          "supplier": {},
356449          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
356450          "name": "content-disposition",
356451          "version": "0.5.3",
356452          "description": "Create and parse Content-Disposition header",
356453          "licenses": [
356454            {
356455              "license": {
356456                "id": "MIT"
356457              }
356458            }
356459          ],
356460          "cpe": "cpe:2.3:a:content-disposition:content-disposition:0.5.3:*:*:*:*:*:*:*",
356461          "purl": "pkg:npm/content-disposition@0.5.3",
356462          "swid": {
356463            "attachment": {}
356464          },
356465          "pedigree": {},
356466          "externalReferences": [
356467            {
356468              "url": "git+https://github.com/jshttp/content-disposition.git",
356469              "type": "distribution"
356470            },
356471            {
356472              "url": "https://github.com/jshttp/content-disposition#readme",
356473              "type": "website"
356474            }
356475          ],
356476          "evidence": {},
356477          "signature": {
356478            "signature": {
356479              "publicKey": {}
356480            }
356481          },
356482          "modelCard": {
356483            "modelParameters": {
356484              "approach": {}
356485            },
356486            "quantitativeAnalysis": {
356487              "graphics": {}
356488            },
356489            "considerations": {}
356490          }
356491        },
356492        {
356493          "type": "library",
356494          "bom-ref": "pkg:npm/content-type@1.0.4?package-id=e516a2b57e9346c6",
356495          "supplier": {},
356496          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
356497          "name": "content-type",
356498          "version": "1.0.4",
356499          "description": "Create and parse HTTP Content-Type header",
356500          "licenses": [
356501            {
356502              "license": {
356503                "id": "MIT"
356504              }
356505            }
356506          ],
356507          "cpe": "cpe:2.3:a:content-type:content-type:1.0.4:*:*:*:*:*:*:*",
356508          "purl": "pkg:npm/content-type@1.0.4",
356509          "swid": {
356510            "attachment": {}
356511          },
356512          "pedigree": {},
356513          "externalReferences": [
356514            {
356515              "url": "git+https://github.com/jshttp/content-type.git",
356516              "type": "distribution"
356517            },
356518            {
356519              "url": "https://github.com/jshttp/content-type#readme",
356520              "type": "website"
356521            }
356522          ],
356523          "evidence": {},
356524          "signature": {
356525            "signature": {
356526              "publicKey": {}
356527            }
356528          },
356529          "modelCard": {
356530            "modelParameters": {
356531              "approach": {}
356532            },
356533            "quantitativeAnalysis": {
356534              "graphics": {}
356535            },
356536            "considerations": {}
356537          }
356538        },
356539        {
356540          "type": "library",
356541          "bom-ref": "pkg:npm/cookie@0.4.0?package-id=e25ee84e7f2e33ad",
356542          "supplier": {},
356543          "author": "Roman Shtylman \u003cshtylman@gmail.com\u003e",
356544          "name": "cookie",
356545          "version": "0.4.0",
356546          "description": "HTTP server cookie parsing and serialization",
356547          "licenses": [
356548            {
356549              "license": {
356550                "id": "MIT"
356551              }
356552            }
356553          ],
356554          "cpe": "cpe:2.3:a:cookie:cookie:0.4.0:*:*:*:*:*:*:*",
356555          "purl": "pkg:npm/cookie@0.4.0",
356556          "swid": {
356557            "attachment": {}
356558          },
356559          "pedigree": {},
356560          "externalReferences": [
356561            {
356562              "url": "git+https://github.com/jshttp/cookie.git",
356563              "type": "distribution"
356564            },
356565            {
356566              "url": "https://github.com/jshttp/cookie#readme",
356567              "type": "website"
356568            }
356569          ],
356570          "evidence": {},
356571          "signature": {
356572            "signature": {
356573              "publicKey": {}
356574            }
356575          },
356576          "modelCard": {
356577            "modelParameters": {
356578              "approach": {}
356579            },
356580            "quantitativeAnalysis": {
356581              "graphics": {}
356582            },
356583            "considerations": {}
356584          }
356585        },
356586        {
356587          "type": "library",
356588          "bom-ref": "pkg:npm/cookie@0.4.1?package-id=9bd323a72ea5cc8",
356589          "supplier": {},
356590          "author": "Roman Shtylman \u003cshtylman@gmail.com\u003e",
356591          "name": "cookie",
356592          "version": "0.4.1",
356593          "description": "HTTP server cookie parsing and serialization",
356594          "licenses": [
356595            {
356596              "license": {
356597                "id": "MIT"
356598              }
356599            }
356600          ],
356601          "cpe": "cpe:2.3:a:cookie:cookie:0.4.1:*:*:*:*:*:*:*",
356602          "purl": "pkg:npm/cookie@0.4.1",
356603          "swid": {
356604            "attachment": {}
356605          },
356606          "pedigree": {},
356607          "externalReferences": [
356608            {
356609              "url": "git+https://github.com/jshttp/cookie.git",
356610              "type": "distribution"
356611            },
356612            {
356613              "url": "https://github.com/jshttp/cookie#readme",
356614              "type": "website"
356615            }
356616          ],
356617          "evidence": {},
356618          "signature": {
356619            "signature": {
356620              "publicKey": {}
356621            }
356622          },
356623          "modelCard": {
356624            "modelParameters": {
356625              "approach": {}
356626            },
356627            "quantitativeAnalysis": {
356628              "graphics": {}
356629            },
356630            "considerations": {}
356631          }
356632        },
356633        {
356634          "type": "library",
356635          "bom-ref": "pkg:npm/cookie-signature@1.0.6?package-id=a948a26643209509",
356636          "supplier": {},
356637          "author": "TJ Holowaychuk \u003ctj@learnboost.com\u003e",
356638          "name": "cookie-signature",
356639          "version": "1.0.6",
356640          "description": "Sign and unsign cookies",
356641          "licenses": [
356642            {
356643              "license": {
356644                "id": "MIT"
356645              }
356646            }
356647          ],
356648          "cpe": "cpe:2.3:a:cookie-signature:cookie-signature:1.0.6:*:*:*:*:*:*:*",
356649          "purl": "pkg:npm/cookie-signature@1.0.6",
356650          "swid": {
356651            "attachment": {}
356652          },
356653          "pedigree": {},
356654          "externalReferences": [
356655            {
356656              "url": "git+https://github.com/visionmedia/node-cookie-signature.git",
356657              "type": "distribution"
356658            },
356659            {
356660              "url": "https://github.com/visionmedia/node-cookie-signature#readme",
356661              "type": "website"
356662            }
356663          ],
356664          "evidence": {},
356665          "signature": {
356666            "signature": {
356667              "publicKey": {}
356668            }
356669          },
356670          "modelCard": {
356671            "modelParameters": {
356672              "approach": {}
356673            },
356674            "quantitativeAnalysis": {
356675              "graphics": {}
356676            },
356677            "considerations": {}
356678          }
356679        },
356680        {
356681          "type": "library",
356682          "bom-ref": "pkg:npm/copy-concurrently@1.0.5?package-id=edf05ca839b08cd4",
356683          "supplier": {},
356684          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
356685          "name": "copy-concurrently",
356686          "version": "1.0.5",
356687          "description": "Promises of copies of files, directories and symlinks, with concurrency controls and win32 junction fallback.",
356688          "licenses": [
356689            {
356690              "license": {
356691                "id": "ISC"
356692              }
356693            }
356694          ],
356695          "cpe": "cpe:2.3:a:copy-concurrently:copy-concurrently:1.0.5:*:*:*:*:*:*:*",
356696          "purl": "pkg:npm/copy-concurrently@1.0.5",
356697          "swid": {
356698            "attachment": {}
356699          },
356700          "pedigree": {},
356701          "externalReferences": [
356702            {
356703              "url": "git+https://github.com/npm/copy-concurrently.git",
356704              "type": "distribution"
356705            },
356706            {
356707              "url": "https://www.npmjs.com/package/copy-concurrently",
356708              "type": "website"
356709            }
356710          ],
356711          "evidence": {},
356712          "signature": {
356713            "signature": {
356714              "publicKey": {}
356715            }
356716          },
356717          "modelCard": {
356718            "modelParameters": {
356719              "approach": {}
356720            },
356721            "quantitativeAnalysis": {
356722              "graphics": {}
356723            },
356724            "considerations": {}
356725          }
356726        },
356727        {
356728          "type": "library",
356729          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=88273ea59dd04956",
356730          "supplier": {},
356731          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
356732          "name": "core-util-is",
356733          "version": "1.0.2",
356734          "description": "The `util.is*` functions introduced in Node v0.12.",
356735          "licenses": [
356736            {
356737              "license": {
356738                "id": "MIT"
356739              }
356740            }
356741          ],
356742          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
356743          "purl": "pkg:npm/core-util-is@1.0.2",
356744          "swid": {
356745            "attachment": {}
356746          },
356747          "pedigree": {},
356748          "externalReferences": [
356749            {
356750              "url": "git://github.com/isaacs/core-util-is.git",
356751              "type": "distribution"
356752            },
356753            {
356754              "url": "https://github.com/isaacs/core-util-is#readme",
356755              "type": "website"
356756            }
356757          ],
356758          "evidence": {},
356759          "signature": {
356760            "signature": {
356761              "publicKey": {}
356762            }
356763          },
356764          "modelCard": {
356765            "modelParameters": {
356766              "approach": {}
356767            },
356768            "quantitativeAnalysis": {
356769              "graphics": {}
356770            },
356771            "considerations": {}
356772          }
356773        },
356774        {
356775          "type": "library",
356776          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=c0eb72d0948fdcd7",
356777          "supplier": {},
356778          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
356779          "name": "core-util-is",
356780          "version": "1.0.2",
356781          "description": "The `util.is*` functions introduced in Node v0.12.",
356782          "licenses": [
356783            {
356784              "license": {
356785                "id": "MIT"
356786              }
356787            }
356788          ],
356789          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
356790          "purl": "pkg:npm/core-util-is@1.0.2",
356791          "swid": {
356792            "attachment": {}
356793          },
356794          "pedigree": {},
356795          "externalReferences": [
356796            {
356797              "url": "git://github.com/isaacs/core-util-is.git",
356798              "type": "distribution"
356799            },
356800            {
356801              "url": "https://github.com/isaacs/core-util-is#readme",
356802              "type": "website"
356803            }
356804          ],
356805          "evidence": {},
356806          "signature": {
356807            "signature": {
356808              "publicKey": {}
356809            }
356810          },
356811          "modelCard": {
356812            "modelParameters": {
356813              "approach": {}
356814            },
356815            "quantitativeAnalysis": {
356816              "graphics": {}
356817            },
356818            "considerations": {}
356819          }
356820        },
356821        {
356822          "type": "library",
356823          "bom-ref": "pkg:npm/corepack@0.15.1?package-id=ceed1cd3d200ed93",
356824          "supplier": {},
356825          "name": "corepack",
356826          "version": "0.15.1",
356827          "licenses": [
356828            {
356829              "license": {
356830                "id": "MIT"
356831              }
356832            }
356833          ],
356834          "cpe": "cpe:2.3:a:corepack:corepack:0.15.1:*:*:*:*:*:*:*",
356835          "purl": "pkg:npm/corepack@0.15.1",
356836          "swid": {
356837            "attachment": {}
356838          },
356839          "pedigree": {},
356840          "externalReferences": [
356841            {
356842              "url": "https://github.com/nodejs/corepack.git",
356843              "type": "distribution"
356844            },
356845            {
356846              "url": "https://github.com/nodejs/corepack#readme",
356847              "type": "website"
356848            }
356849          ],
356850          "evidence": {},
356851          "signature": {
356852            "signature": {
356853              "publicKey": {}
356854            }
356855          },
356856          "modelCard": {
356857            "modelParameters": {
356858              "approach": {}
356859            },
356860            "quantitativeAnalysis": {
356861              "graphics": {}
356862            },
356863            "considerations": {}
356864          }
356865        },
356866        {
356867          "type": "library",
356868          "bom-ref": "pkg:npm/cors@2.8.5?package-id=9e15e0015d5f6152",
356869          "supplier": {},
356870          "author": "Troy Goode \u003ctroygoode@gmail.com\u003e (https://github.com/troygoode/)",
356871          "name": "cors",
356872          "version": "2.8.5",
356873          "description": "Node.js CORS middleware",
356874          "licenses": [
356875            {
356876              "license": {
356877                "id": "MIT"
356878              }
356879            }
356880          ],
356881          "cpe": "cpe:2.3:a:expressjs:cors:2.8.5:*:*:*:*:*:*:*",
356882          "purl": "pkg:npm/cors@2.8.5",
356883          "swid": {
356884            "attachment": {}
356885          },
356886          "pedigree": {},
356887          "externalReferences": [
356888            {
356889              "url": "git+https://github.com/expressjs/cors.git",
356890              "type": "distribution"
356891            },
356892            {
356893              "url": "https://github.com/expressjs/cors#readme",
356894              "type": "website"
356895            }
356896          ],
356897          "evidence": {},
356898          "signature": {
356899            "signature": {
356900              "publicKey": {}
356901            }
356902          },
356903          "modelCard": {
356904            "modelParameters": {
356905              "approach": {}
356906            },
356907            "quantitativeAnalysis": {
356908              "graphics": {}
356909            },
356910            "considerations": {}
356911          }
356912        },
356913        {
356914          "type": "library",
356915          "bom-ref": "pkg:npm/create-error-class@3.0.2?package-id=bf8293b4fe00649d",
356916          "supplier": {},
356917          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
356918          "name": "create-error-class",
356919          "version": "3.0.2",
356920          "description": "Create Error classes",
356921          "licenses": [
356922            {
356923              "license": {
356924                "id": "MIT"
356925              }
356926            }
356927          ],
356928          "cpe": "cpe:2.3:a:create-error-class:create-error-class:3.0.2:*:*:*:*:*:*:*",
356929          "purl": "pkg:npm/create-error-class@3.0.2",
356930          "swid": {
356931            "attachment": {}
356932          },
356933          "pedigree": {},
356934          "externalReferences": [
356935            {
356936              "url": "git+https://github.com/floatdrop/create-error-class.git",
356937              "type": "distribution"
356938            },
356939            {
356940              "url": "https://github.com/floatdrop/create-error-class#readme",
356941              "type": "website"
356942            }
356943          ],
356944          "evidence": {},
356945          "signature": {
356946            "signature": {
356947              "publicKey": {}
356948            }
356949          },
356950          "modelCard": {
356951            "modelParameters": {
356952              "approach": {}
356953            },
356954            "quantitativeAnalysis": {
356955              "graphics": {}
356956            },
356957            "considerations": {}
356958          }
356959        },
356960        {
356961          "type": "library",
356962          "bom-ref": "pkg:npm/cron@1.7.2?package-id=babf2d6a1138bfb",
356963          "supplier": {},
356964          "author": "Nick Campbell \u003cnicholas.j.campbell@gmail.com\u003e (http://github.com/ncb000gt)",
356965          "name": "cron",
356966          "version": "1.7.2",
356967          "description": "Cron jobs for your node",
356968          "licenses": [
356969            {
356970              "license": {
356971                "id": "MIT"
356972              }
356973            }
356974          ],
356975          "cpe": "cpe:2.3:a:kelektiv:cron:1.7.2:*:*:*:*:*:*:*",
356976          "purl": "pkg:npm/cron@1.7.2",
356977          "swid": {
356978            "attachment": {}
356979          },
356980          "pedigree": {},
356981          "externalReferences": [
356982            {
356983              "url": "git+ssh://git@github.com/kelektiv/node-cron.git",
356984              "type": "distribution"
356985            },
356986            {
356987              "url": "https://github.com/kelektiv/node-cron#readme",
356988              "type": "website"
356989            }
356990          ],
356991          "evidence": {},
356992          "signature": {
356993            "signature": {
356994              "publicKey": {}
356995            }
356996          },
356997          "modelCard": {
356998            "modelParameters": {
356999              "approach": {}
357000            },
357001            "quantitativeAnalysis": {
357002              "graphics": {}
357003            },
357004            "considerations": {}
357005          }
357006        },
357007        {
357008          "type": "library",
357009          "bom-ref": "pkg:npm/cross-spawn@5.1.0?package-id=61672b0d32e13073",
357010          "supplier": {},
357011          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
357012          "name": "cross-spawn",
357013          "version": "5.1.0",
357014          "description": "Cross platform child_process#spawn and child_process#spawnSync",
357015          "licenses": [
357016            {
357017              "license": {
357018                "id": "MIT"
357019              }
357020            }
357021          ],
357022          "cpe": "cpe:2.3:a:IndigoUnited:cross-spawn:5.1.0:*:*:*:*:*:*:*",
357023          "purl": "pkg:npm/cross-spawn@5.1.0",
357024          "swid": {
357025            "attachment": {}
357026          },
357027          "pedigree": {},
357028          "externalReferences": [
357029            {
357030              "url": "git://github.com/IndigoUnited/node-cross-spawn.git",
357031              "type": "distribution"
357032            },
357033            {
357034              "url": "https://github.com/IndigoUnited/node-cross-spawn#readme",
357035              "type": "website"
357036            }
357037          ],
357038          "evidence": {},
357039          "signature": {
357040            "signature": {
357041              "publicKey": {}
357042            }
357043          },
357044          "modelCard": {
357045            "modelParameters": {
357046              "approach": {}
357047            },
357048            "quantitativeAnalysis": {
357049              "graphics": {}
357050            },
357051            "considerations": {}
357052          }
357053        },
357054        {
357055          "type": "library",
357056          "bom-ref": "pkg:npm/crypto-random-string@1.0.0?package-id=e95397a312b450f1",
357057          "supplier": {},
357058          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
357059          "name": "crypto-random-string",
357060          "version": "1.0.0",
357061          "description": "Generate a cryptographically strong random string",
357062          "licenses": [
357063            {
357064              "license": {
357065                "id": "MIT"
357066              }
357067            }
357068          ],
357069          "cpe": "cpe:2.3:a:crypto-random-string:crypto-random-string:1.0.0:*:*:*:*:*:*:*",
357070          "purl": "pkg:npm/crypto-random-string@1.0.0",
357071          "swid": {
357072            "attachment": {}
357073          },
357074          "pedigree": {},
357075          "externalReferences": [
357076            {
357077              "url": "git+https://github.com/sindresorhus/crypto-random-string.git",
357078              "type": "distribution"
357079            },
357080            {
357081              "url": "https://github.com/sindresorhus/crypto-random-string#readme",
357082              "type": "website"
357083            }
357084          ],
357085          "evidence": {},
357086          "signature": {
357087            "signature": {
357088              "publicKey": {}
357089            }
357090          },
357091          "modelCard": {
357092            "modelParameters": {
357093              "approach": {}
357094            },
357095            "quantitativeAnalysis": {
357096              "graphics": {}
357097            },
357098            "considerations": {}
357099          }
357100        },
357101        {
357102          "type": "library",
357103          "bom-ref": "pkg:npm/cyclist@0.2.2?package-id=f1897ed52fc1db0d",
357104          "supplier": {},
357105          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
357106          "name": "cyclist",
357107          "version": "0.2.2",
357108          "description": "Cyclist is an efficient cyclic list implemention.",
357109          "cpe": "cpe:2.3:a:mafintosh:cyclist:0.2.2:*:*:*:*:*:*:*",
357110          "purl": "pkg:npm/cyclist@0.2.2",
357111          "swid": {
357112            "attachment": {}
357113          },
357114          "pedigree": {},
357115          "externalReferences": [
357116            {
357117              "url": "git://github.com/mafintosh/cyclist.git",
357118              "type": "distribution"
357119            },
357120            {
357121              "url": "https://github.com/mafintosh/cyclist#readme",
357122              "type": "website"
357123            }
357124          ],
357125          "evidence": {},
357126          "signature": {
357127            "signature": {
357128              "publicKey": {}
357129            }
357130          },
357131          "modelCard": {
357132            "modelParameters": {
357133              "approach": {}
357134            },
357135            "quantitativeAnalysis": {
357136              "graphics": {}
357137            },
357138            "considerations": {}
357139          }
357140        },
357141        {
357142          "type": "library",
357143          "bom-ref": "pkg:npm/dashdash@1.14.1?package-id=a70b954493bc3675",
357144          "supplier": {},
357145          "author": "Trent Mick \u003ctrentm@gmail.com\u003e (http://trentm.com)",
357146          "name": "dashdash",
357147          "version": "1.14.1",
357148          "description": "A light, featureful and explicit option parsing library.",
357149          "licenses": [
357150            {
357151              "license": {
357152                "id": "MIT"
357153              }
357154            }
357155          ],
357156          "cpe": "cpe:2.3:a:dashdash:dashdash:1.14.1:*:*:*:*:*:*:*",
357157          "purl": "pkg:npm/dashdash@1.14.1",
357158          "swid": {
357159            "attachment": {}
357160          },
357161          "pedigree": {},
357162          "externalReferences": [
357163            {
357164              "url": "git://github.com/trentm/node-dashdash.git",
357165              "type": "distribution"
357166            },
357167            {
357168              "url": "https://github.com/trentm/node-dashdash#readme",
357169              "type": "website"
357170            }
357171          ],
357172          "evidence": {},
357173          "signature": {
357174            "signature": {
357175              "publicKey": {}
357176            }
357177          },
357178          "modelCard": {
357179            "modelParameters": {
357180              "approach": {}
357181            },
357182            "quantitativeAnalysis": {
357183              "graphics": {}
357184            },
357185            "considerations": {}
357186          }
357187        },
357188        {
357189          "type": "library",
357190          "bom-ref": "pkg:npm/dashdash@1.14.1?package-id=d46834cee3b39d41",
357191          "supplier": {},
357192          "author": "Trent Mick \u003ctrentm@gmail.com\u003e (http://trentm.com)",
357193          "name": "dashdash",
357194          "version": "1.14.1",
357195          "description": "A light, featureful and explicit option parsing library.",
357196          "licenses": [
357197            {
357198              "license": {
357199                "id": "MIT"
357200              }
357201            }
357202          ],
357203          "cpe": "cpe:2.3:a:dashdash:dashdash:1.14.1:*:*:*:*:*:*:*",
357204          "purl": "pkg:npm/dashdash@1.14.1",
357205          "swid": {
357206            "attachment": {}
357207          },
357208          "pedigree": {},
357209          "externalReferences": [
357210            {
357211              "url": "git://github.com/trentm/node-dashdash.git",
357212              "type": "distribution"
357213            },
357214            {
357215              "url": "https://github.com/trentm/node-dashdash#readme",
357216              "type": "website"
357217            }
357218          ],
357219          "evidence": {},
357220          "signature": {
357221            "signature": {
357222              "publicKey": {}
357223            }
357224          },
357225          "modelCard": {
357226            "modelParameters": {
357227              "approach": {}
357228            },
357229            "quantitativeAnalysis": {
357230              "graphics": {}
357231            },
357232            "considerations": {}
357233          }
357234        },
357235        {
357236          "type": "library",
357237          "bom-ref": "pkg:npm/debug@2.6.9?package-id=678b02f17fe3e102",
357238          "supplier": {},
357239          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
357240          "name": "debug",
357241          "version": "2.6.9",
357242          "description": "small debugging utility",
357243          "licenses": [
357244            {
357245              "license": {
357246                "id": "MIT"
357247              }
357248            }
357249          ],
357250          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
357251          "purl": "pkg:npm/debug@2.6.9",
357252          "swid": {
357253            "attachment": {}
357254          },
357255          "pedigree": {},
357256          "externalReferences": [
357257            {
357258              "url": "git://github.com/visionmedia/debug.git",
357259              "type": "distribution"
357260            },
357261            {
357262              "url": "https://github.com/visionmedia/debug#readme",
357263              "type": "website"
357264            }
357265          ],
357266          "evidence": {},
357267          "signature": {
357268            "signature": {
357269              "publicKey": {}
357270            }
357271          },
357272          "modelCard": {
357273            "modelParameters": {
357274              "approach": {}
357275            },
357276            "quantitativeAnalysis": {
357277              "graphics": {}
357278            },
357279            "considerations": {}
357280          }
357281        },
357282        {
357283          "type": "library",
357284          "bom-ref": "pkg:npm/debug@2.6.9?package-id=f480d8ebdb9f09dd",
357285          "supplier": {},
357286          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
357287          "name": "debug",
357288          "version": "2.6.9",
357289          "description": "small debugging utility",
357290          "licenses": [
357291            {
357292              "license": {
357293                "id": "MIT"
357294              }
357295            }
357296          ],
357297          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
357298          "purl": "pkg:npm/debug@2.6.9",
357299          "swid": {
357300            "attachment": {}
357301          },
357302          "pedigree": {},
357303          "externalReferences": [
357304            {
357305              "url": "git://github.com/visionmedia/debug.git",
357306              "type": "distribution"
357307            },
357308            {
357309              "url": "https://github.com/visionmedia/debug#readme",
357310              "type": "website"
357311            }
357312          ],
357313          "evidence": {},
357314          "signature": {
357315            "signature": {
357316              "publicKey": {}
357317            }
357318          },
357319          "modelCard": {
357320            "modelParameters": {
357321              "approach": {}
357322            },
357323            "quantitativeAnalysis": {
357324              "graphics": {}
357325            },
357326            "considerations": {}
357327          }
357328        },
357329        {
357330          "type": "library",
357331          "bom-ref": "pkg:npm/debug@2.6.9?package-id=63e404b9b646a741",
357332          "supplier": {},
357333          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
357334          "name": "debug",
357335          "version": "2.6.9",
357336          "description": "small debugging utility",
357337          "licenses": [
357338            {
357339              "license": {
357340                "id": "MIT"
357341              }
357342            }
357343          ],
357344          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
357345          "purl": "pkg:npm/debug@2.6.9",
357346          "swid": {
357347            "attachment": {}
357348          },
357349          "pedigree": {},
357350          "externalReferences": [
357351            {
357352              "url": "git://github.com/visionmedia/debug.git",
357353              "type": "distribution"
357354            },
357355            {
357356              "url": "https://github.com/visionmedia/debug#readme",
357357              "type": "website"
357358            }
357359          ],
357360          "evidence": {},
357361          "signature": {
357362            "signature": {
357363              "publicKey": {}
357364            }
357365          },
357366          "modelCard": {
357367            "modelParameters": {
357368              "approach": {}
357369            },
357370            "quantitativeAnalysis": {
357371              "graphics": {}
357372            },
357373            "considerations": {}
357374          }
357375        },
357376        {
357377          "type": "library",
357378          "bom-ref": "pkg:npm/debug@2.6.9?package-id=b5f8830607027ee7",
357379          "supplier": {},
357380          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
357381          "name": "debug",
357382          "version": "2.6.9",
357383          "description": "small debugging utility",
357384          "licenses": [
357385            {
357386              "license": {
357387                "id": "MIT"
357388              }
357389            }
357390          ],
357391          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
357392          "purl": "pkg:npm/debug@2.6.9",
357393          "swid": {
357394            "attachment": {}
357395          },
357396          "pedigree": {},
357397          "externalReferences": [
357398            {
357399              "url": "git://github.com/visionmedia/debug.git",
357400              "type": "distribution"
357401            },
357402            {
357403              "url": "https://github.com/visionmedia/debug#readme",
357404              "type": "website"
357405            }
357406          ],
357407          "evidence": {},
357408          "signature": {
357409            "signature": {
357410              "publicKey": {}
357411            }
357412          },
357413          "modelCard": {
357414            "modelParameters": {
357415              "approach": {}
357416            },
357417            "quantitativeAnalysis": {
357418              "graphics": {}
357419            },
357420            "considerations": {}
357421          }
357422        },
357423        {
357424          "type": "library",
357425          "bom-ref": "pkg:npm/debug@2.6.9?package-id=dcdc6158b4334038",
357426          "supplier": {},
357427          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
357428          "name": "debug",
357429          "version": "2.6.9",
357430          "description": "small debugging utility",
357431          "licenses": [
357432            {
357433              "license": {
357434                "id": "MIT"
357435              }
357436            }
357437          ],
357438          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
357439          "purl": "pkg:npm/debug@2.6.9",
357440          "swid": {
357441            "attachment": {}
357442          },
357443          "pedigree": {},
357444          "externalReferences": [
357445            {
357446              "url": "git://github.com/visionmedia/debug.git",
357447              "type": "distribution"
357448            },
357449            {
357450              "url": "https://github.com/visionmedia/debug#readme",
357451              "type": "website"
357452            }
357453          ],
357454          "evidence": {},
357455          "signature": {
357456            "signature": {
357457              "publicKey": {}
357458            }
357459          },
357460          "modelCard": {
357461            "modelParameters": {
357462              "approach": {}
357463            },
357464            "quantitativeAnalysis": {
357465              "graphics": {}
357466            },
357467            "considerations": {}
357468          }
357469        },
357470        {
357471          "type": "library",
357472          "bom-ref": "pkg:npm/debug@3.1.0?package-id=6cd8fab77e7f9acc",
357473          "supplier": {},
357474          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
357475          "name": "debug",
357476          "version": "3.1.0",
357477          "description": "small debugging utility",
357478          "licenses": [
357479            {
357480              "license": {
357481                "id": "MIT"
357482              }
357483            }
357484          ],
357485          "cpe": "cpe:2.3:a:visionmedia:debug:3.1.0:*:*:*:*:*:*:*",
357486          "purl": "pkg:npm/debug@3.1.0",
357487          "swid": {
357488            "attachment": {}
357489          },
357490          "pedigree": {},
357491          "externalReferences": [
357492            {
357493              "url": "git://github.com/visionmedia/debug.git",
357494              "type": "distribution"
357495            },
357496            {
357497              "url": "https://github.com/visionmedia/debug#readme",
357498              "type": "website"
357499            }
357500          ],
357501          "evidence": {},
357502          "signature": {
357503            "signature": {
357504              "publicKey": {}
357505            }
357506          },
357507          "modelCard": {
357508            "modelParameters": {
357509              "approach": {}
357510            },
357511            "quantitativeAnalysis": {
357512              "graphics": {}
357513            },
357514            "considerations": {}
357515          }
357516        },
357517        {
357518          "type": "library",
357519          "bom-ref": "pkg:npm/debug@4.3.2?package-id=e3424c7439ad0435",
357520          "supplier": {},
357521          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
357522          "name": "debug",
357523          "version": "4.3.2",
357524          "description": "small debugging utility",
357525          "licenses": [
357526            {
357527              "license": {
357528                "id": "MIT"
357529              }
357530            }
357531          ],
357532          "cpe": "cpe:2.3:a:visionmedia:debug:4.3.2:*:*:*:*:*:*:*",
357533          "purl": "pkg:npm/debug@4.3.2",
357534          "swid": {
357535            "attachment": {}
357536          },
357537          "pedigree": {},
357538          "externalReferences": [
357539            {
357540              "url": "git://github.com/visionmedia/debug.git",
357541              "type": "distribution"
357542            },
357543            {
357544              "url": "https://github.com/visionmedia/debug#readme",
357545              "type": "website"
357546            }
357547          ],
357548          "evidence": {},
357549          "signature": {
357550            "signature": {
357551              "publicKey": {}
357552            }
357553          },
357554          "modelCard": {
357555            "modelParameters": {
357556              "approach": {}
357557            },
357558            "quantitativeAnalysis": {
357559              "graphics": {}
357560            },
357561            "considerations": {}
357562          }
357563        },
357564        {
357565          "type": "library",
357566          "bom-ref": "pkg:npm/debuglog@1.0.1?package-id=abf6b1b40c49bc95",
357567          "supplier": {},
357568          "author": "Sam Roberts \u003csam@strongloop.com\u003e",
357569          "name": "debuglog",
357570          "version": "1.0.1",
357571          "description": "backport of util.debuglog from node v0.11",
357572          "licenses": [
357573            {
357574              "license": {
357575                "id": "MIT"
357576              }
357577            }
357578          ],
357579          "cpe": "cpe:2.3:a:sam-github:debuglog:1.0.1:*:*:*:*:*:*:*",
357580          "purl": "pkg:npm/debuglog@1.0.1",
357581          "swid": {
357582            "attachment": {}
357583          },
357584          "pedigree": {},
357585          "externalReferences": [
357586            {
357587              "url": "git+https://github.com/sam-github/node-debuglog.git",
357588              "type": "distribution"
357589            },
357590            {
357591              "url": "https://github.com/sam-github/node-debuglog#readme",
357592              "type": "website"
357593            }
357594          ],
357595          "evidence": {},
357596          "signature": {
357597            "signature": {
357598              "publicKey": {}
357599            }
357600          },
357601          "modelCard": {
357602            "modelParameters": {
357603              "approach": {}
357604            },
357605            "quantitativeAnalysis": {
357606              "graphics": {}
357607            },
357608            "considerations": {}
357609          }
357610        },
357611        {
357612          "type": "library",
357613          "bom-ref": "pkg:npm/decamelize@1.2.0?package-id=ad1f772c12d9a9f",
357614          "supplier": {},
357615          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
357616          "name": "decamelize",
357617          "version": "1.2.0",
357618          "description": "Convert a camelized string into a lowercased one with a custom separator: unicornRainbow → unicorn_rainbow",
357619          "licenses": [
357620            {
357621              "license": {
357622                "id": "MIT"
357623              }
357624            }
357625          ],
357626          "cpe": "cpe:2.3:a:sindresorhus:decamelize:1.2.0:*:*:*:*:*:*:*",
357627          "purl": "pkg:npm/decamelize@1.2.0",
357628          "swid": {
357629            "attachment": {}
357630          },
357631          "pedigree": {},
357632          "externalReferences": [
357633            {
357634              "url": "git+https://github.com/sindresorhus/decamelize.git",
357635              "type": "distribution"
357636            },
357637            {
357638              "url": "https://github.com/sindresorhus/decamelize#readme",
357639              "type": "website"
357640            }
357641          ],
357642          "evidence": {},
357643          "signature": {
357644            "signature": {
357645              "publicKey": {}
357646            }
357647          },
357648          "modelCard": {
357649            "modelParameters": {
357650              "approach": {}
357651            },
357652            "quantitativeAnalysis": {
357653              "graphics": {}
357654            },
357655            "considerations": {}
357656          }
357657        },
357658        {
357659          "type": "library",
357660          "bom-ref": "pkg:npm/decode-uri-component@0.2.2?package-id=c1c36d4917da6909",
357661          "supplier": {},
357662          "author": "Sam Verschueren \u003csam.verschueren@gmail.com\u003e (github.com/SamVerschueren)",
357663          "name": "decode-uri-component",
357664          "version": "0.2.2",
357665          "description": "A better decodeURIComponent",
357666          "licenses": [
357667            {
357668              "license": {
357669                "id": "MIT"
357670              }
357671            }
357672          ],
357673          "cpe": "cpe:2.3:a:decode-uri-component:decode-uri-component:0.2.2:*:*:*:*:*:*:*",
357674          "purl": "pkg:npm/decode-uri-component@0.2.2",
357675          "swid": {
357676            "attachment": {}
357677          },
357678          "pedigree": {},
357679          "externalReferences": [
357680            {
357681              "url": "git+https://github.com/SamVerschueren/decode-uri-component.git",
357682              "type": "distribution"
357683            },
357684            {
357685              "url": "https://github.com/SamVerschueren/decode-uri-component#readme",
357686              "type": "website"
357687            }
357688          ],
357689          "evidence": {},
357690          "signature": {
357691            "signature": {
357692              "publicKey": {}
357693            }
357694          },
357695          "modelCard": {
357696            "modelParameters": {
357697              "approach": {}
357698            },
357699            "quantitativeAnalysis": {
357700              "graphics": {}
357701            },
357702            "considerations": {}
357703          }
357704        },
357705        {
357706          "type": "library",
357707          "bom-ref": "pkg:npm/deep-extend@0.6.0?package-id=249a5a2e595cbcf5",
357708          "supplier": {},
357709          "author": "Viacheslav Lotsmanov \u003clotsmanov89@gmail.com\u003e",
357710          "name": "deep-extend",
357711          "version": "0.6.0",
357712          "description": "Recursive object extending",
357713          "licenses": [
357714            {
357715              "license": {
357716                "id": "MIT"
357717              }
357718            }
357719          ],
357720          "cpe": "cpe:2.3:a:deep-extend:deep-extend:0.6.0:*:*:*:*:*:*:*",
357721          "purl": "pkg:npm/deep-extend@0.6.0",
357722          "swid": {
357723            "attachment": {}
357724          },
357725          "pedigree": {},
357726          "externalReferences": [
357727            {
357728              "url": "git://github.com/unclechu/node-deep-extend.git",
357729              "type": "distribution"
357730            },
357731            {
357732              "url": "https://github.com/unclechu/node-deep-extend",
357733              "type": "website"
357734            }
357735          ],
357736          "evidence": {},
357737          "signature": {
357738            "signature": {
357739              "publicKey": {}
357740            }
357741          },
357742          "modelCard": {
357743            "modelParameters": {
357744              "approach": {}
357745            },
357746            "quantitativeAnalysis": {
357747              "graphics": {}
357748            },
357749            "considerations": {}
357750          }
357751        },
357752        {
357753          "type": "library",
357754          "bom-ref": "pkg:npm/deepmerge@4.2.2?package-id=13a27b81ced9569c",
357755          "supplier": {},
357756          "name": "deepmerge",
357757          "version": "4.2.2",
357758          "description": "A library for deep (recursive) merging of Javascript objects",
357759          "licenses": [
357760            {
357761              "license": {
357762                "id": "MIT"
357763              }
357764            }
357765          ],
357766          "cpe": "cpe:2.3:a:TehShrike:deepmerge:4.2.2:*:*:*:*:*:*:*",
357767          "purl": "pkg:npm/deepmerge@4.2.2",
357768          "swid": {
357769            "attachment": {}
357770          },
357771          "pedigree": {},
357772          "externalReferences": [
357773            {
357774              "url": "git://github.com/TehShrike/deepmerge.git",
357775              "type": "distribution"
357776            },
357777            {
357778              "url": "https://github.com/TehShrike/deepmerge",
357779              "type": "website"
357780            }
357781          ],
357782          "evidence": {},
357783          "signature": {
357784            "signature": {
357785              "publicKey": {}
357786            }
357787          },
357788          "modelCard": {
357789            "modelParameters": {
357790              "approach": {}
357791            },
357792            "quantitativeAnalysis": {
357793              "graphics": {}
357794            },
357795            "considerations": {}
357796          }
357797        },
357798        {
357799          "type": "library",
357800          "bom-ref": "pkg:npm/defaults@1.0.3?package-id=b87ef5ac001f1810",
357801          "supplier": {},
357802          "author": "Elijah Insua \u003ctmpvar@gmail.com\u003e",
357803          "name": "defaults",
357804          "version": "1.0.3",
357805          "description": "merge single level defaults over a config object",
357806          "licenses": [
357807            {
357808              "license": {
357809                "id": "MIT"
357810              }
357811            }
357812          ],
357813          "cpe": "cpe:2.3:a:defaults:defaults:1.0.3:*:*:*:*:*:*:*",
357814          "purl": "pkg:npm/defaults@1.0.3",
357815          "swid": {
357816            "attachment": {}
357817          },
357818          "pedigree": {},
357819          "externalReferences": [
357820            {
357821              "url": "git://github.com/tmpvar/defaults.git",
357822              "type": "distribution"
357823            },
357824            {
357825              "url": "https://github.com/tmpvar/defaults#readme",
357826              "type": "website"
357827            }
357828          ],
357829          "evidence": {},
357830          "signature": {
357831            "signature": {
357832              "publicKey": {}
357833            }
357834          },
357835          "modelCard": {
357836            "modelParameters": {
357837              "approach": {}
357838            },
357839            "quantitativeAnalysis": {
357840              "graphics": {}
357841            },
357842            "considerations": {}
357843          }
357844        },
357845        {
357846          "type": "library",
357847          "bom-ref": "pkg:npm/define-properties@1.1.3?package-id=6f151d17ca4e763e",
357848          "supplier": {},
357849          "author": "Jordan Harband",
357850          "name": "define-properties",
357851          "version": "1.1.3",
357852          "description": "Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.",
357853          "licenses": [
357854            {
357855              "license": {
357856                "id": "MIT"
357857              }
357858            }
357859          ],
357860          "cpe": "cpe:2.3:a:define-properties:define-properties:1.1.3:*:*:*:*:*:*:*",
357861          "purl": "pkg:npm/define-properties@1.1.3",
357862          "swid": {
357863            "attachment": {}
357864          },
357865          "pedigree": {},
357866          "externalReferences": [
357867            {
357868              "url": "git://github.com/ljharb/define-properties.git",
357869              "type": "distribution"
357870            },
357871            {
357872              "url": "https://github.com/ljharb/define-properties#readme",
357873              "type": "website"
357874            }
357875          ],
357876          "evidence": {},
357877          "signature": {
357878            "signature": {
357879              "publicKey": {}
357880            }
357881          },
357882          "modelCard": {
357883            "modelParameters": {
357884              "approach": {}
357885            },
357886            "quantitativeAnalysis": {
357887              "graphics": {}
357888            },
357889            "considerations": {}
357890          }
357891        },
357892        {
357893          "type": "library",
357894          "bom-ref": "pkg:npm/define-properties@1.1.3?package-id=b4b6e57cfdee31b8",
357895          "supplier": {},
357896          "author": "Jordan Harband",
357897          "name": "define-properties",
357898          "version": "1.1.3",
357899          "description": "Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.",
357900          "licenses": [
357901            {
357902              "license": {
357903                "id": "MIT"
357904              }
357905            }
357906          ],
357907          "cpe": "cpe:2.3:a:define-properties:define-properties:1.1.3:*:*:*:*:*:*:*",
357908          "purl": "pkg:npm/define-properties@1.1.3",
357909          "swid": {
357910            "attachment": {}
357911          },
357912          "pedigree": {},
357913          "externalReferences": [
357914            {
357915              "url": "git://github.com/ljharb/define-properties.git",
357916              "type": "distribution"
357917            }
357918          ],
357919          "evidence": {},
357920          "signature": {
357921            "signature": {
357922              "publicKey": {}
357923            }
357924          },
357925          "modelCard": {
357926            "modelParameters": {
357927              "approach": {}
357928            },
357929            "quantitativeAnalysis": {
357930              "graphics": {}
357931            },
357932            "considerations": {}
357933          }
357934        },
357935        {
357936          "type": "library",
357937          "bom-ref": "pkg:npm/delay@5.0.0?package-id=1fdfc0742e38417a",
357938          "supplier": {},
357939          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
357940          "name": "delay",
357941          "version": "5.0.0",
357942          "description": "Delay a promise a specified amount of time",
357943          "licenses": [
357944            {
357945              "license": {
357946                "id": "MIT"
357947              }
357948            }
357949          ],
357950          "cpe": "cpe:2.3:a:sindresorhus:delay:5.0.0:*:*:*:*:*:*:*",
357951          "purl": "pkg:npm/delay@5.0.0",
357952          "swid": {
357953            "attachment": {}
357954          },
357955          "pedigree": {},
357956          "externalReferences": [
357957            {
357958              "url": "git+https://github.com/sindresorhus/delay.git",
357959              "type": "distribution"
357960            },
357961            {
357962              "url": "https://github.com/sindresorhus/delay#readme",
357963              "type": "website"
357964            }
357965          ],
357966          "evidence": {},
357967          "signature": {
357968            "signature": {
357969              "publicKey": {}
357970            }
357971          },
357972          "modelCard": {
357973            "modelParameters": {
357974              "approach": {}
357975            },
357976            "quantitativeAnalysis": {
357977              "graphics": {}
357978            },
357979            "considerations": {}
357980          }
357981        },
357982        {
357983          "type": "library",
357984          "bom-ref": "pkg:npm/delayed-stream@1.0.0?package-id=f797cfc3ebbb05a9",
357985          "supplier": {},
357986          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
357987          "name": "delayed-stream",
357988          "version": "1.0.0",
357989          "description": "Buffers events from a stream until you are ready to handle them.",
357990          "licenses": [
357991            {
357992              "license": {
357993                "id": "MIT"
357994              }
357995            }
357996          ],
357997          "cpe": "cpe:2.3:a:delayed-stream:delayed-stream:1.0.0:*:*:*:*:*:*:*",
357998          "purl": "pkg:npm/delayed-stream@1.0.0",
357999          "swid": {
358000            "attachment": {}
358001          },
358002          "pedigree": {},
358003          "externalReferences": [
358004            {
358005              "url": "git://github.com/felixge/node-delayed-stream.git",
358006              "type": "distribution"
358007            },
358008            {
358009              "url": "https://github.com/felixge/node-delayed-stream",
358010              "type": "website"
358011            }
358012          ],
358013          "evidence": {},
358014          "signature": {
358015            "signature": {
358016              "publicKey": {}
358017            }
358018          },
358019          "modelCard": {
358020            "modelParameters": {
358021              "approach": {}
358022            },
358023            "quantitativeAnalysis": {
358024              "graphics": {}
358025            },
358026            "considerations": {}
358027          }
358028        },
358029        {
358030          "type": "library",
358031          "bom-ref": "pkg:npm/delayed-stream@1.0.0?package-id=a195d79ef31bc579",
358032          "supplier": {},
358033          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
358034          "name": "delayed-stream",
358035          "version": "1.0.0",
358036          "description": "Buffers events from a stream until you are ready to handle them.",
358037          "licenses": [
358038            {
358039              "license": {
358040                "id": "MIT"
358041              }
358042            }
358043          ],
358044          "cpe": "cpe:2.3:a:delayed-stream:delayed-stream:1.0.0:*:*:*:*:*:*:*",
358045          "purl": "pkg:npm/delayed-stream@1.0.0",
358046          "swid": {
358047            "attachment": {}
358048          },
358049          "pedigree": {},
358050          "externalReferences": [
358051            {
358052              "url": "git://github.com/felixge/node-delayed-stream.git",
358053              "type": "distribution"
358054            },
358055            {
358056              "url": "https://github.com/felixge/node-delayed-stream",
358057              "type": "website"
358058            }
358059          ],
358060          "evidence": {},
358061          "signature": {
358062            "signature": {
358063              "publicKey": {}
358064            }
358065          },
358066          "modelCard": {
358067            "modelParameters": {
358068              "approach": {}
358069            },
358070            "quantitativeAnalysis": {
358071              "graphics": {}
358072            },
358073            "considerations": {}
358074          }
358075        },
358076        {
358077          "type": "library",
358078          "bom-ref": "pkg:npm/delegates@1.0.0?package-id=611fe8c99f30481e",
358079          "supplier": {},
358080          "name": "delegates",
358081          "version": "1.0.0",
358082          "description": "delegate methods and accessors to another property",
358083          "licenses": [
358084            {
358085              "license": {
358086                "id": "MIT"
358087              }
358088            }
358089          ],
358090          "cpe": "cpe:2.3:a:visionmedia:delegates:1.0.0:*:*:*:*:*:*:*",
358091          "purl": "pkg:npm/delegates@1.0.0",
358092          "swid": {
358093            "attachment": {}
358094          },
358095          "pedigree": {},
358096          "externalReferences": [
358097            {
358098              "url": "git+https://github.com/visionmedia/node-delegates.git",
358099              "type": "distribution"
358100            },
358101            {
358102              "url": "https://github.com/visionmedia/node-delegates#readme",
358103              "type": "website"
358104            }
358105          ],
358106          "evidence": {},
358107          "signature": {
358108            "signature": {
358109              "publicKey": {}
358110            }
358111          },
358112          "modelCard": {
358113            "modelParameters": {
358114              "approach": {}
358115            },
358116            "quantitativeAnalysis": {
358117              "graphics": {}
358118            },
358119            "considerations": {}
358120          }
358121        },
358122        {
358123          "type": "library",
358124          "bom-ref": "pkg:npm/depd@1.1.2?package-id=b4e3a373f4fec0b8",
358125          "supplier": {},
358126          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
358127          "name": "depd",
358128          "version": "1.1.2",
358129          "description": "Deprecate all the things",
358130          "licenses": [
358131            {
358132              "license": {
358133                "id": "MIT"
358134              }
358135            }
358136          ],
358137          "cpe": "cpe:2.3:a:dougwilson:depd:1.1.2:*:*:*:*:*:*:*",
358138          "purl": "pkg:npm/depd@1.1.2",
358139          "swid": {
358140            "attachment": {}
358141          },
358142          "pedigree": {},
358143          "externalReferences": [
358144            {
358145              "url": "git+https://github.com/dougwilson/nodejs-depd.git",
358146              "type": "distribution"
358147            },
358148            {
358149              "url": "https://github.com/dougwilson/nodejs-depd#readme",
358150              "type": "website"
358151            }
358152          ],
358153          "evidence": {},
358154          "signature": {
358155            "signature": {
358156              "publicKey": {}
358157            }
358158          },
358159          "modelCard": {
358160            "modelParameters": {
358161              "approach": {}
358162            },
358163            "quantitativeAnalysis": {
358164              "graphics": {}
358165            },
358166            "considerations": {}
358167          }
358168        },
358169        {
358170          "type": "library",
358171          "bom-ref": "pkg:npm/destroy@1.0.4?package-id=d0ece580645e4cd1",
358172          "supplier": {},
358173          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
358174          "name": "destroy",
358175          "version": "1.0.4",
358176          "description": "destroy a stream if possible",
358177          "licenses": [
358178            {
358179              "license": {
358180                "id": "MIT"
358181              }
358182            }
358183          ],
358184          "cpe": "cpe:2.3:a:stream-utils:destroy:1.0.4:*:*:*:*:*:*:*",
358185          "purl": "pkg:npm/destroy@1.0.4",
358186          "swid": {
358187            "attachment": {}
358188          },
358189          "pedigree": {},
358190          "externalReferences": [
358191            {
358192              "url": "git+https://github.com/stream-utils/destroy.git",
358193              "type": "distribution"
358194            },
358195            {
358196              "url": "https://github.com/stream-utils/destroy#readme",
358197              "type": "website"
358198            }
358199          ],
358200          "evidence": {},
358201          "signature": {
358202            "signature": {
358203              "publicKey": {}
358204            }
358205          },
358206          "modelCard": {
358207            "modelParameters": {
358208              "approach": {}
358209            },
358210            "quantitativeAnalysis": {
358211              "graphics": {}
358212            },
358213            "considerations": {}
358214          }
358215        },
358216        {
358217          "type": "library",
358218          "bom-ref": "pkg:npm/detect-indent@5.0.0?package-id=cbccbb5dd754391",
358219          "supplier": {},
358220          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
358221          "name": "detect-indent",
358222          "version": "5.0.0",
358223          "description": "Detect the indentation of code",
358224          "licenses": [
358225            {
358226              "license": {
358227                "id": "MIT"
358228              }
358229            }
358230          ],
358231          "cpe": "cpe:2.3:a:detect-indent:detect-indent:5.0.0:*:*:*:*:*:*:*",
358232          "purl": "pkg:npm/detect-indent@5.0.0",
358233          "swid": {
358234            "attachment": {}
358235          },
358236          "pedigree": {},
358237          "externalReferences": [
358238            {
358239              "url": "git+https://github.com/sindresorhus/detect-indent.git",
358240              "type": "distribution"
358241            },
358242            {
358243              "url": "https://github.com/sindresorhus/detect-indent#readme",
358244              "type": "website"
358245            }
358246          ],
358247          "evidence": {},
358248          "signature": {
358249            "signature": {
358250              "publicKey": {}
358251            }
358252          },
358253          "modelCard": {
358254            "modelParameters": {
358255              "approach": {}
358256            },
358257            "quantitativeAnalysis": {
358258              "graphics": {}
358259            },
358260            "considerations": {}
358261          }
358262        },
358263        {
358264          "type": "library",
358265          "bom-ref": "pkg:npm/detect-newline@2.1.0?package-id=9759ace33b9872ed",
358266          "supplier": {},
358267          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
358268          "name": "detect-newline",
358269          "version": "2.1.0",
358270          "description": "Detect the dominant newline character of a string",
358271          "licenses": [
358272            {
358273              "license": {
358274                "id": "MIT"
358275              }
358276            }
358277          ],
358278          "cpe": "cpe:2.3:a:detect-newline:detect-newline:2.1.0:*:*:*:*:*:*:*",
358279          "purl": "pkg:npm/detect-newline@2.1.0",
358280          "swid": {
358281            "attachment": {}
358282          },
358283          "pedigree": {},
358284          "externalReferences": [
358285            {
358286              "url": "git+https://github.com/sindresorhus/detect-newline.git",
358287              "type": "distribution"
358288            },
358289            {
358290              "url": "https://github.com/sindresorhus/detect-newline#readme",
358291              "type": "website"
358292            }
358293          ],
358294          "evidence": {},
358295          "signature": {
358296            "signature": {
358297              "publicKey": {}
358298            }
358299          },
358300          "modelCard": {
358301            "modelParameters": {
358302              "approach": {}
358303            },
358304            "quantitativeAnalysis": {
358305              "graphics": {}
358306            },
358307            "considerations": {}
358308          }
358309        },
358310        {
358311          "type": "library",
358312          "bom-ref": "pkg:npm/detect-node@2.1.0?package-id=1f525b60a1ca3255",
358313          "supplier": {},
358314          "author": "Ilya Kantor",
358315          "name": "detect-node",
358316          "version": "2.1.0",
358317          "description": "Detect Node.JS (as opposite to browser environment) (reliable)",
358318          "licenses": [
358319            {
358320              "license": {
358321                "id": "MIT"
358322              }
358323            }
358324          ],
358325          "cpe": "cpe:2.3:a:detect-node:detect-node:2.1.0:*:*:*:*:*:*:*",
358326          "purl": "pkg:npm/detect-node@2.1.0",
358327          "swid": {
358328            "attachment": {}
358329          },
358330          "pedigree": {},
358331          "externalReferences": [
358332            {
358333              "url": "git+https://github.com/iliakan/detect-node.git",
358334              "type": "distribution"
358335            },
358336            {
358337              "url": "https://github.com/iliakan/detect-node",
358338              "type": "website"
358339            }
358340          ],
358341          "evidence": {},
358342          "signature": {
358343            "signature": {
358344              "publicKey": {}
358345            }
358346          },
358347          "modelCard": {
358348            "modelParameters": {
358349              "approach": {}
358350            },
358351            "quantitativeAnalysis": {
358352              "graphics": {}
358353            },
358354            "considerations": {}
358355          }
358356        },
358357        {
358358          "type": "library",
358359          "bom-ref": "pkg:npm/dezalgo@1.0.4?package-id=8c098b6c7c66a9ca",
358360          "supplier": {},
358361          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
358362          "name": "dezalgo",
358363          "version": "1.0.4",
358364          "description": "Contain async insanity so that the dark pony lord doesn't eat souls",
358365          "licenses": [
358366            {
358367              "license": {
358368                "id": "ISC"
358369              }
358370            }
358371          ],
358372          "cpe": "cpe:2.3:a:dezalgo:dezalgo:1.0.4:*:*:*:*:*:*:*",
358373          "purl": "pkg:npm/dezalgo@1.0.4",
358374          "swid": {
358375            "attachment": {}
358376          },
358377          "pedigree": {},
358378          "externalReferences": [
358379            {
358380              "url": "git+https://github.com/npm/dezalgo.git",
358381              "type": "distribution"
358382            },
358383            {
358384              "url": "https://github.com/npm/dezalgo",
358385              "type": "website"
358386            }
358387          ],
358388          "evidence": {},
358389          "signature": {
358390            "signature": {
358391              "publicKey": {}
358392            }
358393          },
358394          "modelCard": {
358395            "modelParameters": {
358396              "approach": {}
358397            },
358398            "quantitativeAnalysis": {
358399              "graphics": {}
358400            },
358401            "considerations": {}
358402          }
358403        },
358404        {
358405          "type": "library",
358406          "bom-ref": "pkg:npm/dicer@0.2.5?package-id=a8a869ccc4536dc8",
358407          "supplier": {},
358408          "author": "Brian White \u003cmscdex@mscdex.net\u003e",
358409          "name": "dicer",
358410          "version": "0.2.5",
358411          "description": "A very fast streaming multipart parser for node.js",
358412          "licenses": [
358413            {
358414              "license": {
358415                "id": "MIT"
358416              }
358417            }
358418          ],
358419          "cpe": "cpe:2.3:a:mscdex:dicer:0.2.5:*:*:*:*:*:*:*",
358420          "purl": "pkg:npm/dicer@0.2.5",
358421          "swid": {
358422            "attachment": {}
358423          },
358424          "pedigree": {},
358425          "externalReferences": [
358426            {
358427              "url": "git+ssh://git@github.com/mscdex/dicer.git",
358428              "type": "distribution"
358429            },
358430            {
358431              "url": "https://github.com/mscdex/dicer#readme",
358432              "type": "website"
358433            }
358434          ],
358435          "evidence": {},
358436          "signature": {
358437            "signature": {
358438              "publicKey": {}
358439            }
358440          },
358441          "modelCard": {
358442            "modelParameters": {
358443              "approach": {}
358444            },
358445            "quantitativeAnalysis": {
358446              "graphics": {}
358447            },
358448            "considerations": {}
358449          }
358450        },
358451        {
358452          "type": "library",
358453          "bom-ref": "pkg:npm/dot-prop@4.2.1?package-id=d49bd91a9d2691c0",
358454          "supplier": {},
358455          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
358456          "name": "dot-prop",
358457          "version": "4.2.1",
358458          "description": "Get, set, or delete a property from a nested object using a dot path",
358459          "licenses": [
358460            {
358461              "license": {
358462                "id": "MIT"
358463              }
358464            }
358465          ],
358466          "cpe": "cpe:2.3:a:sindresorhus:dot-prop:4.2.1:*:*:*:*:*:*:*",
358467          "purl": "pkg:npm/dot-prop@4.2.1",
358468          "swid": {
358469            "attachment": {}
358470          },
358471          "pedigree": {},
358472          "externalReferences": [
358473            {
358474              "url": "git+https://github.com/sindresorhus/dot-prop.git",
358475              "type": "distribution"
358476            },
358477            {
358478              "url": "https://github.com/sindresorhus/dot-prop#readme",
358479              "type": "website"
358480            }
358481          ],
358482          "evidence": {},
358483          "signature": {
358484            "signature": {
358485              "publicKey": {}
358486            }
358487          },
358488          "modelCard": {
358489            "modelParameters": {
358490              "approach": {}
358491            },
358492            "quantitativeAnalysis": {
358493              "graphics": {}
358494            },
358495            "considerations": {}
358496          }
358497        },
358498        {
358499          "type": "library",
358500          "bom-ref": "pkg:npm/dotenv@10.0.0?package-id=116cfbf727d31b6f",
358501          "supplier": {},
358502          "name": "dotenv",
358503          "version": "10.0.0",
358504          "description": "Loads environment variables from .env file",
358505          "licenses": [
358506            {
358507              "license": {
358508                "id": "BSD-2-Clause"
358509              }
358510            }
358511          ],
358512          "cpe": "cpe:2.3:a:motdotla:dotenv:10.0.0:*:*:*:*:*:*:*",
358513          "purl": "pkg:npm/dotenv@10.0.0",
358514          "swid": {
358515            "attachment": {}
358516          },
358517          "pedigree": {},
358518          "externalReferences": [
358519            {
358520              "url": "git://github.com/motdotla/dotenv.git",
358521              "type": "distribution"
358522            },
358523            {
358524              "url": "https://github.com/motdotla/dotenv#readme",
358525              "type": "website"
358526            }
358527          ],
358528          "evidence": {},
358529          "signature": {
358530            "signature": {
358531              "publicKey": {}
358532            }
358533          },
358534          "modelCard": {
358535            "modelParameters": {
358536              "approach": {}
358537            },
358538            "quantitativeAnalysis": {
358539              "graphics": {}
358540            },
358541            "considerations": {}
358542          }
358543        },
358544        {
358545          "type": "library",
358546          "bom-ref": "pkg:npm/dotenv@5.0.1?package-id=52ed2ee809f10570",
358547          "supplier": {},
358548          "author": "scottmotte",
358549          "name": "dotenv",
358550          "version": "5.0.1",
358551          "description": "Loads environment variables from .env file",
358552          "licenses": [
358553            {
358554              "license": {
358555                "id": "BSD-2-Clause"
358556              }
358557            }
358558          ],
358559          "cpe": "cpe:2.3:a:motdotla:dotenv:5.0.1:*:*:*:*:*:*:*",
358560          "purl": "pkg:npm/dotenv@5.0.1",
358561          "swid": {
358562            "attachment": {}
358563          },
358564          "pedigree": {},
358565          "externalReferences": [
358566            {
358567              "url": "git://github.com/motdotla/dotenv.git",
358568              "type": "distribution"
358569            },
358570            {
358571              "url": "https://github.com/motdotla/dotenv#readme",
358572              "type": "website"
358573            }
358574          ],
358575          "evidence": {},
358576          "signature": {
358577            "signature": {
358578              "publicKey": {}
358579            }
358580          },
358581          "modelCard": {
358582            "modelParameters": {
358583              "approach": {}
358584            },
358585            "quantitativeAnalysis": {
358586              "graphics": {}
358587            },
358588            "considerations": {}
358589          }
358590        },
358591        {
358592          "type": "library",
358593          "bom-ref": "pkg:npm/duplexer3@0.1.4?package-id=98204faeb1e0cfb8",
358594          "supplier": {},
358595          "author": "Conrad Pankoff \u003cdeoxxa@fknsrs.biz\u003e (http://www.fknsrs.biz/)",
358596          "name": "duplexer3",
358597          "version": "0.1.4",
358598          "description": "Like duplexer but using streams3",
358599          "licenses": [
358600            {
358601              "license": {
358602                "id": "BSD-3-Clause"
358603              }
358604            }
358605          ],
358606          "cpe": "cpe:2.3:a:duplexer3:duplexer3:0.1.4:*:*:*:*:*:*:*",
358607          "purl": "pkg:npm/duplexer3@0.1.4",
358608          "swid": {
358609            "attachment": {}
358610          },
358611          "pedigree": {},
358612          "externalReferences": [
358613            {
358614              "url": "git+https://github.com/floatdrop/duplexer3.git",
358615              "type": "distribution"
358616            },
358617            {
358618              "url": "https://github.com/floatdrop/duplexer3#readme",
358619              "type": "website"
358620            }
358621          ],
358622          "evidence": {},
358623          "signature": {
358624            "signature": {
358625              "publicKey": {}
358626            }
358627          },
358628          "modelCard": {
358629            "modelParameters": {
358630              "approach": {}
358631            },
358632            "quantitativeAnalysis": {
358633              "graphics": {}
358634            },
358635            "considerations": {}
358636          }
358637        },
358638        {
358639          "type": "library",
358640          "bom-ref": "pkg:npm/duplexify@3.6.0?package-id=80b25920959c0055",
358641          "supplier": {},
358642          "author": "Mathias Buus",
358643          "name": "duplexify",
358644          "version": "3.6.0",
358645          "description": "Turn a writable and readable stream into a streams2 duplex stream with support for async initialization and streams1/streams2 input",
358646          "licenses": [
358647            {
358648              "license": {
358649                "id": "MIT"
358650              }
358651            }
358652          ],
358653          "cpe": "cpe:2.3:a:duplexify:duplexify:3.6.0:*:*:*:*:*:*:*",
358654          "purl": "pkg:npm/duplexify@3.6.0",
358655          "swid": {
358656            "attachment": {}
358657          },
358658          "pedigree": {},
358659          "externalReferences": [
358660            {
358661              "url": "git://github.com/mafintosh/duplexify.git",
358662              "type": "distribution"
358663            },
358664            {
358665              "url": "https://github.com/mafintosh/duplexify",
358666              "type": "website"
358667            }
358668          ],
358669          "evidence": {},
358670          "signature": {
358671            "signature": {
358672              "publicKey": {}
358673            }
358674          },
358675          "modelCard": {
358676            "modelParameters": {
358677              "approach": {}
358678            },
358679            "quantitativeAnalysis": {
358680              "graphics": {}
358681            },
358682            "considerations": {}
358683          }
358684        },
358685        {
358686          "type": "library",
358687          "bom-ref": "pkg:npm/ecc-jsbn@0.1.2?package-id=74cef8cdd38faaa",
358688          "supplier": {},
358689          "author": "Jeremie Miller \u003cjeremie@jabber.org\u003e (http://jeremie.com/)",
358690          "name": "ecc-jsbn",
358691          "version": "0.1.2",
358692          "description": "ECC JS code based on JSBN",
358693          "licenses": [
358694            {
358695              "license": {
358696                "id": "MIT"
358697              }
358698            }
358699          ],
358700          "cpe": "cpe:2.3:a:quartzjer:ecc-jsbn:0.1.2:*:*:*:*:*:*:*",
358701          "purl": "pkg:npm/ecc-jsbn@0.1.2",
358702          "swid": {
358703            "attachment": {}
358704          },
358705          "pedigree": {},
358706          "externalReferences": [
358707            {
358708              "url": "git+https://github.com/quartzjer/ecc-jsbn.git",
358709              "type": "distribution"
358710            },
358711            {
358712              "url": "https://github.com/quartzjer/ecc-jsbn",
358713              "type": "website"
358714            }
358715          ],
358716          "evidence": {},
358717          "signature": {
358718            "signature": {
358719              "publicKey": {}
358720            }
358721          },
358722          "modelCard": {
358723            "modelParameters": {
358724              "approach": {}
358725            },
358726            "quantitativeAnalysis": {
358727              "graphics": {}
358728            },
358729            "considerations": {}
358730          }
358731        },
358732        {
358733          "type": "library",
358734          "bom-ref": "pkg:npm/ecc-jsbn@0.1.2?package-id=13a413a168a6381f",
358735          "supplier": {},
358736          "author": "Jeremie Miller \u003cjeremie@jabber.org\u003e (http://jeremie.com/)",
358737          "name": "ecc-jsbn",
358738          "version": "0.1.2",
358739          "description": "ECC JS code based on JSBN",
358740          "licenses": [
358741            {
358742              "license": {
358743                "id": "MIT"
358744              }
358745            }
358746          ],
358747          "cpe": "cpe:2.3:a:quartzjer:ecc-jsbn:0.1.2:*:*:*:*:*:*:*",
358748          "purl": "pkg:npm/ecc-jsbn@0.1.2",
358749          "swid": {
358750            "attachment": {}
358751          },
358752          "pedigree": {},
358753          "externalReferences": [
358754            {
358755              "url": "git+https://github.com/quartzjer/ecc-jsbn.git",
358756              "type": "distribution"
358757            },
358758            {
358759              "url": "https://github.com/quartzjer/ecc-jsbn",
358760              "type": "website"
358761            }
358762          ],
358763          "evidence": {},
358764          "signature": {
358765            "signature": {
358766              "publicKey": {}
358767            }
358768          },
358769          "modelCard": {
358770            "modelParameters": {
358771              "approach": {}
358772            },
358773            "quantitativeAnalysis": {
358774              "graphics": {}
358775            },
358776            "considerations": {}
358777          }
358778        },
358779        {
358780          "type": "library",
358781          "bom-ref": "pkg:npm/ecdsa-sig-formatter@1.0.11?package-id=641fb1a75989c2b9",
358782          "supplier": {},
358783          "author": "D2L Corporation",
358784          "name": "ecdsa-sig-formatter",
358785          "version": "1.0.11",
358786          "description": "Translate ECDSA signatures between ASN.1/DER and JOSE-style concatenation",
358787          "licenses": [
358788            {
358789              "license": {
358790                "id": "Apache-2.0"
358791              }
358792            }
358793          ],
358794          "cpe": "cpe:2.3:a:ecdsa-sig-formatter:ecdsa-sig-formatter:1.0.11:*:*:*:*:*:*:*",
358795          "purl": "pkg:npm/ecdsa-sig-formatter@1.0.11",
358796          "swid": {
358797            "attachment": {}
358798          },
358799          "pedigree": {},
358800          "externalReferences": [
358801            {
358802              "url": "git+ssh://git@github.com/Brightspace/node-ecdsa-sig-formatter.git",
358803              "type": "distribution"
358804            },
358805            {
358806              "url": "https://github.com/Brightspace/node-ecdsa-sig-formatter#readme",
358807              "type": "website"
358808            }
358809          ],
358810          "evidence": {},
358811          "signature": {
358812            "signature": {
358813              "publicKey": {}
358814            }
358815          },
358816          "modelCard": {
358817            "modelParameters": {
358818              "approach": {}
358819            },
358820            "quantitativeAnalysis": {
358821              "graphics": {}
358822            },
358823            "considerations": {}
358824          }
358825        },
358826        {
358827          "type": "library",
358828          "bom-ref": "pkg:npm/editor@1.0.0?package-id=57824e36461985c2",
358829          "supplier": {},
358830          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
358831          "name": "editor",
358832          "version": "1.0.0",
358833          "description": "launch $EDITOR in your program",
358834          "licenses": [
358835            {
358836              "license": {
358837                "id": "MIT"
358838              }
358839            }
358840          ],
358841          "cpe": "cpe:2.3:a:substack:editor:1.0.0:*:*:*:*:*:*:*",
358842          "purl": "pkg:npm/editor@1.0.0",
358843          "swid": {
358844            "attachment": {}
358845          },
358846          "pedigree": {},
358847          "externalReferences": [
358848            {
358849              "url": "git://github.com/substack/node-editor.git",
358850              "type": "distribution"
358851            },
358852            {
358853              "url": "https://github.com/substack/node-editor",
358854              "type": "website"
358855            }
358856          ],
358857          "evidence": {},
358858          "signature": {
358859            "signature": {
358860              "publicKey": {}
358861            }
358862          },
358863          "modelCard": {
358864            "modelParameters": {
358865              "approach": {}
358866            },
358867            "quantitativeAnalysis": {
358868              "graphics": {}
358869            },
358870            "considerations": {}
358871          }
358872        },
358873        {
358874          "type": "library",
358875          "bom-ref": "pkg:npm/ee-first@1.1.1?package-id=64407a6fdf5ac08b",
358876          "supplier": {},
358877          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
358878          "name": "ee-first",
358879          "version": "1.1.1",
358880          "description": "return the first event in a set of ee/event pairs",
358881          "licenses": [
358882            {
358883              "license": {
358884                "id": "MIT"
358885              }
358886            }
358887          ],
358888          "cpe": "cpe:2.3:a:jonathanong:ee-first:1.1.1:*:*:*:*:*:*:*",
358889          "purl": "pkg:npm/ee-first@1.1.1",
358890          "swid": {
358891            "attachment": {}
358892          },
358893          "pedigree": {},
358894          "externalReferences": [
358895            {
358896              "url": "git+https://github.com/jonathanong/ee-first.git",
358897              "type": "distribution"
358898            },
358899            {
358900              "url": "https://github.com/jonathanong/ee-first#readme",
358901              "type": "website"
358902            }
358903          ],
358904          "evidence": {},
358905          "signature": {
358906            "signature": {
358907              "publicKey": {}
358908            }
358909          },
358910          "modelCard": {
358911            "modelParameters": {
358912              "approach": {}
358913            },
358914            "quantitativeAnalysis": {
358915              "graphics": {}
358916            },
358917            "considerations": {}
358918          }
358919        },
358920        {
358921          "type": "library",
358922          "bom-ref": "pkg:npm/emoji-regex@7.0.3?package-id=67c6a2d66166ba44",
358923          "supplier": {},
358924          "author": "Mathias Bynens (https://mathiasbynens.be/)",
358925          "name": "emoji-regex",
358926          "version": "7.0.3",
358927          "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
358928          "licenses": [
358929            {
358930              "license": {
358931                "id": "MIT"
358932              }
358933            }
358934          ],
358935          "cpe": "cpe:2.3:a:emoji-regex:emoji-regex:7.0.3:*:*:*:*:*:*:*",
358936          "purl": "pkg:npm/emoji-regex@7.0.3",
358937          "swid": {
358938            "attachment": {}
358939          },
358940          "pedigree": {},
358941          "externalReferences": [
358942            {
358943              "url": "git+https://github.com/mathiasbynens/emoji-regex.git",
358944              "type": "distribution"
358945            },
358946            {
358947              "url": "https://mths.be/emoji-regex",
358948              "type": "website"
358949            }
358950          ],
358951          "evidence": {},
358952          "signature": {
358953            "signature": {
358954              "publicKey": {}
358955            }
358956          },
358957          "modelCard": {
358958            "modelParameters": {
358959              "approach": {}
358960            },
358961            "quantitativeAnalysis": {
358962              "graphics": {}
358963            },
358964            "considerations": {}
358965          }
358966        },
358967        {
358968          "type": "library",
358969          "bom-ref": "pkg:npm/encodeurl@1.0.2?package-id=6de19f90b58f26e3",
358970          "supplier": {},
358971          "name": "encodeurl",
358972          "version": "1.0.2",
358973          "description": "Encode a URL to a percent-encoded form, excluding already-encoded sequences",
358974          "licenses": [
358975            {
358976              "license": {
358977                "id": "MIT"
358978              }
358979            }
358980          ],
358981          "cpe": "cpe:2.3:a:encodeurl:encodeurl:1.0.2:*:*:*:*:*:*:*",
358982          "purl": "pkg:npm/encodeurl@1.0.2",
358983          "swid": {
358984            "attachment": {}
358985          },
358986          "pedigree": {},
358987          "externalReferences": [
358988            {
358989              "url": "git+https://github.com/pillarjs/encodeurl.git",
358990              "type": "distribution"
358991            },
358992            {
358993              "url": "https://github.com/pillarjs/encodeurl#readme",
358994              "type": "website"
358995            }
358996          ],
358997          "evidence": {},
358998          "signature": {
358999            "signature": {
359000              "publicKey": {}
359001            }
359002          },
359003          "modelCard": {
359004            "modelParameters": {
359005              "approach": {}
359006            },
359007            "quantitativeAnalysis": {
359008              "graphics": {}
359009            },
359010            "considerations": {}
359011          }
359012        },
359013        {
359014          "type": "library",
359015          "bom-ref": "pkg:npm/encoding@0.1.12?package-id=871fd80324ab2784",
359016          "supplier": {},
359017          "author": "Andris Reinman",
359018          "name": "encoding",
359019          "version": "0.1.12",
359020          "description": "Convert encodings, uses iconv by default and fallbacks to iconv-lite if needed",
359021          "licenses": [
359022            {
359023              "license": {
359024                "id": "MIT"
359025              }
359026            }
359027          ],
359028          "cpe": "cpe:2.3:a:encoding:encoding:0.1.12:*:*:*:*:*:*:*",
359029          "purl": "pkg:npm/encoding@0.1.12",
359030          "swid": {
359031            "attachment": {}
359032          },
359033          "pedigree": {},
359034          "externalReferences": [
359035            {
359036              "url": "git+https://github.com/andris9/encoding.git",
359037              "type": "distribution"
359038            },
359039            {
359040              "url": "https://github.com/andris9/encoding#readme",
359041              "type": "website"
359042            }
359043          ],
359044          "evidence": {},
359045          "signature": {
359046            "signature": {
359047              "publicKey": {}
359048            }
359049          },
359050          "modelCard": {
359051            "modelParameters": {
359052              "approach": {}
359053            },
359054            "quantitativeAnalysis": {
359055              "graphics": {}
359056            },
359057            "considerations": {}
359058          }
359059        },
359060        {
359061          "type": "library",
359062          "bom-ref": "pkg:npm/end-of-stream@1.4.1?package-id=6a3ff5d2005a6a76",
359063          "supplier": {},
359064          "author": "Mathias Buus \u003cmathiasbuus@gmail.com\u003e",
359065          "name": "end-of-stream",
359066          "version": "1.4.1",
359067          "description": "Call a callback when a readable/writable/duplex stream has completed or failed.",
359068          "licenses": [
359069            {
359070              "license": {
359071                "id": "MIT"
359072              }
359073            }
359074          ],
359075          "cpe": "cpe:2.3:a:end-of-stream:end-of-stream:1.4.1:*:*:*:*:*:*:*",
359076          "purl": "pkg:npm/end-of-stream@1.4.1",
359077          "swid": {
359078            "attachment": {}
359079          },
359080          "pedigree": {},
359081          "externalReferences": [
359082            {
359083              "url": "git://github.com/mafintosh/end-of-stream.git",
359084              "type": "distribution"
359085            },
359086            {
359087              "url": "https://github.com/mafintosh/end-of-stream",
359088              "type": "website"
359089            }
359090          ],
359091          "evidence": {},
359092          "signature": {
359093            "signature": {
359094              "publicKey": {}
359095            }
359096          },
359097          "modelCard": {
359098            "modelParameters": {
359099              "approach": {}
359100            },
359101            "quantitativeAnalysis": {
359102              "graphics": {}
359103            },
359104            "considerations": {}
359105          }
359106        },
359107        {
359108          "type": "library",
359109          "bom-ref": "pkg:npm/env-paths@2.2.1?package-id=6167f6188e6fdd99",
359110          "supplier": {},
359111          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
359112          "name": "env-paths",
359113          "version": "2.2.1",
359114          "description": "Get paths for storing things like data, config, cache, etc",
359115          "licenses": [
359116            {
359117              "license": {
359118                "id": "MIT"
359119              }
359120            }
359121          ],
359122          "cpe": "cpe:2.3:a:sindresorhus:env-paths:2.2.1:*:*:*:*:*:*:*",
359123          "purl": "pkg:npm/env-paths@2.2.1",
359124          "swid": {
359125            "attachment": {}
359126          },
359127          "pedigree": {},
359128          "externalReferences": [
359129            {
359130              "url": "git+https://github.com/sindresorhus/env-paths.git",
359131              "type": "distribution"
359132            },
359133            {
359134              "url": "https://github.com/sindresorhus/env-paths#readme",
359135              "type": "website"
359136            }
359137          ],
359138          "evidence": {},
359139          "signature": {
359140            "signature": {
359141              "publicKey": {}
359142            }
359143          },
359144          "modelCard": {
359145            "modelParameters": {
359146              "approach": {}
359147            },
359148            "quantitativeAnalysis": {
359149              "graphics": {}
359150            },
359151            "considerations": {}
359152          }
359153        },
359154        {
359155          "type": "library",
359156          "bom-ref": "pkg:npm/err-code@1.1.2?package-id=47b4e2b3e9659ed4",
359157          "supplier": {},
359158          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
359159          "name": "err-code",
359160          "version": "1.1.2",
359161          "description": "Create an error with a code",
359162          "licenses": [
359163            {
359164              "license": {
359165                "id": "MIT"
359166              }
359167            }
359168          ],
359169          "cpe": "cpe:2.3:a:IndigoUnited:err-code:1.1.2:*:*:*:*:*:*:*",
359170          "purl": "pkg:npm/err-code@1.1.2",
359171          "swid": {
359172            "attachment": {}
359173          },
359174          "pedigree": {},
359175          "externalReferences": [
359176            {
359177              "url": "git://github.com/IndigoUnited/js-err-code.git",
359178              "type": "distribution"
359179            },
359180            {
359181              "url": "https://github.com/IndigoUnited/js-err-code#readme",
359182              "type": "website"
359183            }
359184          ],
359185          "evidence": {},
359186          "signature": {
359187            "signature": {
359188              "publicKey": {}
359189            }
359190          },
359191          "modelCard": {
359192            "modelParameters": {
359193              "approach": {}
359194            },
359195            "quantitativeAnalysis": {
359196              "graphics": {}
359197            },
359198            "considerations": {}
359199          }
359200        },
359201        {
359202          "type": "library",
359203          "bom-ref": "pkg:npm/errno@0.1.7?package-id=1f6d7a00a99768b0",
359204          "supplier": {},
359205          "name": "errno",
359206          "version": "0.1.7",
359207          "description": "libuv errno details exposed",
359208          "licenses": [
359209            {
359210              "license": {
359211                "id": "MIT"
359212              }
359213            }
359214          ],
359215          "cpe": "cpe:2.3:a:errno:errno:0.1.7:*:*:*:*:*:*:*",
359216          "purl": "pkg:npm/errno@0.1.7",
359217          "swid": {
359218            "attachment": {}
359219          },
359220          "pedigree": {},
359221          "externalReferences": [
359222            {
359223              "url": "git+https://github.com/rvagg/node-errno.git",
359224              "type": "distribution"
359225            },
359226            {
359227              "url": "https://github.com/rvagg/node-errno#readme",
359228              "type": "website"
359229            }
359230          ],
359231          "evidence": {},
359232          "signature": {
359233            "signature": {
359234              "publicKey": {}
359235            }
359236          },
359237          "modelCard": {
359238            "modelParameters": {
359239              "approach": {}
359240            },
359241            "quantitativeAnalysis": {
359242              "graphics": {}
359243            },
359244            "considerations": {}
359245          }
359246        },
359247        {
359248          "type": "library",
359249          "bom-ref": "pkg:npm/es-abstract@1.12.0?package-id=a2b6224dc1972289",
359250          "supplier": {},
359251          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
359252          "name": "es-abstract",
359253          "version": "1.12.0",
359254          "description": "ECMAScript spec abstract operations.",
359255          "licenses": [
359256            {
359257              "license": {
359258                "id": "MIT"
359259              }
359260            }
359261          ],
359262          "cpe": "cpe:2.3:a:es-abstract:es-abstract:1.12.0:*:*:*:*:*:*:*",
359263          "purl": "pkg:npm/es-abstract@1.12.0",
359264          "swid": {
359265            "attachment": {}
359266          },
359267          "pedigree": {},
359268          "externalReferences": [
359269            {
359270              "url": "git://github.com/ljharb/es-abstract.git",
359271              "type": "distribution"
359272            }
359273          ],
359274          "evidence": {},
359275          "signature": {
359276            "signature": {
359277              "publicKey": {}
359278            }
359279          },
359280          "modelCard": {
359281            "modelParameters": {
359282              "approach": {}
359283            },
359284            "quantitativeAnalysis": {
359285              "graphics": {}
359286            },
359287            "considerations": {}
359288          }
359289        },
359290        {
359291          "type": "library",
359292          "bom-ref": "pkg:npm/es-to-primitive@1.2.0?package-id=ff185285dcd118b3",
359293          "supplier": {},
359294          "author": "Jordan Harband",
359295          "name": "es-to-primitive",
359296          "version": "1.2.0",
359297          "description": "ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES2015 versions.",
359298          "licenses": [
359299            {
359300              "license": {
359301                "id": "MIT"
359302              }
359303            }
359304          ],
359305          "cpe": "cpe:2.3:a:es-to-primitive:es-to-primitive:1.2.0:*:*:*:*:*:*:*",
359306          "purl": "pkg:npm/es-to-primitive@1.2.0",
359307          "swid": {
359308            "attachment": {}
359309          },
359310          "pedigree": {},
359311          "externalReferences": [
359312            {
359313              "url": "git://github.com/ljharb/es-to-primitive.git",
359314              "type": "distribution"
359315            }
359316          ],
359317          "evidence": {},
359318          "signature": {
359319            "signature": {
359320              "publicKey": {}
359321            }
359322          },
359323          "modelCard": {
359324            "modelParameters": {
359325              "approach": {}
359326            },
359327            "quantitativeAnalysis": {
359328              "graphics": {}
359329            },
359330            "considerations": {}
359331          }
359332        },
359333        {
359334          "type": "library",
359335          "bom-ref": "pkg:npm/es6-promise@4.2.8?package-id=7acd7eff273aea0f",
359336          "supplier": {},
359337          "author": "Yehuda Katz, Tom Dale, Stefan Penner and contributors (Conversion to ES6 API by Jake Archibald)",
359338          "name": "es6-promise",
359339          "version": "4.2.8",
359340          "description": "A lightweight library that provides tools for organizing asynchronous code",
359341          "licenses": [
359342            {
359343              "license": {
359344                "id": "MIT"
359345              }
359346            }
359347          ],
359348          "cpe": "cpe:2.3:a:stefanpenner:es6-promise:4.2.8:*:*:*:*:*:*:*",
359349          "purl": "pkg:npm/es6-promise@4.2.8",
359350          "swid": {
359351            "attachment": {}
359352          },
359353          "pedigree": {},
359354          "externalReferences": [
359355            {
359356              "url": "git://github.com/stefanpenner/es6-promise.git",
359357              "type": "distribution"
359358            },
359359            {
359360              "url": "https://github.com/stefanpenner/es6-promise",
359361              "type": "website"
359362            }
359363          ],
359364          "evidence": {},
359365          "signature": {
359366            "signature": {
359367              "publicKey": {}
359368            }
359369          },
359370          "modelCard": {
359371            "modelParameters": {
359372              "approach": {}
359373            },
359374            "quantitativeAnalysis": {
359375              "graphics": {}
359376            },
359377            "considerations": {}
359378          }
359379        },
359380        {
359381          "type": "library",
359382          "bom-ref": "pkg:npm/es6-promisify@5.0.0?package-id=922e6b6cb34c0449",
359383          "supplier": {},
359384          "author": "Mike Hall \u003cmikehall314@gmail.com\u003e",
359385          "name": "es6-promisify",
359386          "version": "5.0.0",
359387          "description": "Converts callback-based functions to ES6 Promises",
359388          "licenses": [
359389            {
359390              "license": {
359391                "id": "MIT"
359392              }
359393            }
359394          ],
359395          "cpe": "cpe:2.3:a:digitaldesignlabs:es6-promisify:5.0.0:*:*:*:*:*:*:*",
359396          "purl": "pkg:npm/es6-promisify@5.0.0",
359397          "swid": {
359398            "attachment": {}
359399          },
359400          "pedigree": {},
359401          "externalReferences": [
359402            {
359403              "url": "git+https://github.com/digitaldesignlabs/es6-promisify.git",
359404              "type": "distribution"
359405            },
359406            {
359407              "url": "https://github.com/digitaldesignlabs/es6-promisify#readme",
359408              "type": "website"
359409            }
359410          ],
359411          "evidence": {},
359412          "signature": {
359413            "signature": {
359414              "publicKey": {}
359415            }
359416          },
359417          "modelCard": {
359418            "modelParameters": {
359419              "approach": {}
359420            },
359421            "quantitativeAnalysis": {
359422              "graphics": {}
359423            },
359424            "considerations": {}
359425          }
359426        },
359427        {
359428          "type": "library",
359429          "bom-ref": "pkg:npm/escape-html@1.0.3?package-id=fc052a8fdf6a88f1",
359430          "supplier": {},
359431          "name": "escape-html",
359432          "version": "1.0.3",
359433          "description": "Escape string for use in HTML",
359434          "licenses": [
359435            {
359436              "license": {
359437                "id": "MIT"
359438              }
359439            }
359440          ],
359441          "cpe": "cpe:2.3:a:escape-html:escape-html:1.0.3:*:*:*:*:*:*:*",
359442          "purl": "pkg:npm/escape-html@1.0.3",
359443          "swid": {
359444            "attachment": {}
359445          },
359446          "pedigree": {},
359447          "externalReferences": [
359448            {
359449              "url": "git+https://github.com/component/escape-html.git",
359450              "type": "distribution"
359451            },
359452            {
359453              "url": "https://github.com/component/escape-html#readme",
359454              "type": "website"
359455            }
359456          ],
359457          "evidence": {},
359458          "signature": {
359459            "signature": {
359460              "publicKey": {}
359461            }
359462          },
359463          "modelCard": {
359464            "modelParameters": {
359465              "approach": {}
359466            },
359467            "quantitativeAnalysis": {
359468              "graphics": {}
359469            },
359470            "considerations": {}
359471          }
359472        },
359473        {
359474          "type": "library",
359475          "bom-ref": "pkg:npm/escape-string-regexp@1.0.5?package-id=4ab0b66784f88a18",
359476          "supplier": {},
359477          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
359478          "name": "escape-string-regexp",
359479          "version": "1.0.5",
359480          "description": "Escape RegExp special characters",
359481          "licenses": [
359482            {
359483              "license": {
359484                "id": "MIT"
359485              }
359486            }
359487          ],
359488          "cpe": "cpe:2.3:a:escape-string-regexp:escape-string-regexp:1.0.5:*:*:*:*:*:*:*",
359489          "purl": "pkg:npm/escape-string-regexp@1.0.5",
359490          "swid": {
359491            "attachment": {}
359492          },
359493          "pedigree": {},
359494          "externalReferences": [
359495            {
359496              "url": "git+https://github.com/sindresorhus/escape-string-regexp.git",
359497              "type": "distribution"
359498            },
359499            {
359500              "url": "https://github.com/sindresorhus/escape-string-regexp#readme",
359501              "type": "website"
359502            }
359503          ],
359504          "evidence": {},
359505          "signature": {
359506            "signature": {
359507              "publicKey": {}
359508            }
359509          },
359510          "modelCard": {
359511            "modelParameters": {
359512              "approach": {}
359513            },
359514            "quantitativeAnalysis": {
359515              "graphics": {}
359516            },
359517            "considerations": {}
359518          }
359519        },
359520        {
359521          "type": "library",
359522          "bom-ref": "pkg:npm/etag@1.8.1?package-id=3601ed58fabb680",
359523          "supplier": {},
359524          "name": "etag",
359525          "version": "1.8.1",
359526          "description": "Create simple HTTP ETags",
359527          "licenses": [
359528            {
359529              "license": {
359530                "id": "MIT"
359531              }
359532            }
359533          ],
359534          "cpe": "cpe:2.3:a:jshttp:etag:1.8.1:*:*:*:*:*:*:*",
359535          "purl": "pkg:npm/etag@1.8.1",
359536          "swid": {
359537            "attachment": {}
359538          },
359539          "pedigree": {},
359540          "externalReferences": [
359541            {
359542              "url": "git+https://github.com/jshttp/etag.git",
359543              "type": "distribution"
359544            },
359545            {
359546              "url": "https://github.com/jshttp/etag#readme",
359547              "type": "website"
359548            }
359549          ],
359550          "evidence": {},
359551          "signature": {
359552            "signature": {
359553              "publicKey": {}
359554            }
359555          },
359556          "modelCard": {
359557            "modelParameters": {
359558              "approach": {}
359559            },
359560            "quantitativeAnalysis": {
359561              "graphics": {}
359562            },
359563            "considerations": {}
359564          }
359565        },
359566        {
359567          "type": "library",
359568          "bom-ref": "pkg:npm/execa@0.7.0?package-id=cb39ab257461721b",
359569          "supplier": {},
359570          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
359571          "name": "execa",
359572          "version": "0.7.0",
359573          "description": "A better `child_process`",
359574          "licenses": [
359575            {
359576              "license": {
359577                "id": "MIT"
359578              }
359579            }
359580          ],
359581          "cpe": "cpe:2.3:a:sindresorhus:execa:0.7.0:*:*:*:*:*:*:*",
359582          "purl": "pkg:npm/execa@0.7.0",
359583          "swid": {
359584            "attachment": {}
359585          },
359586          "pedigree": {},
359587          "externalReferences": [
359588            {
359589              "url": "git+https://github.com/sindresorhus/execa.git",
359590              "type": "distribution"
359591            },
359592            {
359593              "url": "https://github.com/sindresorhus/execa#readme",
359594              "type": "website"
359595            }
359596          ],
359597          "evidence": {},
359598          "signature": {
359599            "signature": {
359600              "publicKey": {}
359601            }
359602          },
359603          "modelCard": {
359604            "modelParameters": {
359605              "approach": {}
359606            },
359607            "quantitativeAnalysis": {
359608              "graphics": {}
359609            },
359610            "considerations": {}
359611          }
359612        },
359613        {
359614          "type": "library",
359615          "bom-ref": "pkg:npm/express@4.17.1?package-id=b158c53a8f877dac",
359616          "supplier": {},
359617          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
359618          "name": "express",
359619          "version": "4.17.1",
359620          "description": "Fast, unopinionated, minimalist web framework",
359621          "licenses": [
359622            {
359623              "license": {
359624                "id": "MIT"
359625              }
359626            }
359627          ],
359628          "cpe": "cpe:2.3:a:express:express:4.17.1:*:*:*:*:*:*:*",
359629          "purl": "pkg:npm/express@4.17.1",
359630          "swid": {
359631            "attachment": {}
359632          },
359633          "pedigree": {},
359634          "externalReferences": [
359635            {
359636              "url": "git+https://github.com/expressjs/express.git",
359637              "type": "distribution"
359638            },
359639            {
359640              "url": "http://expressjs.com/",
359641              "type": "website"
359642            }
359643          ],
359644          "evidence": {},
359645          "signature": {
359646            "signature": {
359647              "publicKey": {}
359648            }
359649          },
359650          "modelCard": {
359651            "modelParameters": {
359652              "approach": {}
359653            },
359654            "quantitativeAnalysis": {
359655              "graphics": {}
359656            },
359657            "considerations": {}
359658          }
359659        },
359660        {
359661          "type": "library",
359662          "bom-ref": "pkg:npm/express-prom-bundle@6.3.6?package-id=dcf2eacb49838111",
359663          "supplier": {},
359664          "author": "Konstantin Pogorelov \u003cor@pluseq.com\u003e",
359665          "name": "express-prom-bundle",
359666          "version": "6.3.6",
359667          "description": "express middleware with popular prometheus metrics in one bundle",
359668          "licenses": [
359669            {
359670              "license": {
359671                "id": "MIT"
359672              }
359673            }
359674          ],
359675          "cpe": "cpe:2.3:a:express-prom-bundle:express-prom-bundle:6.3.6:*:*:*:*:*:*:*",
359676          "purl": "pkg:npm/express-prom-bundle@6.3.6",
359677          "swid": {
359678            "attachment": {}
359679          },
359680          "pedigree": {},
359681          "externalReferences": [
359682            {
359683              "url": "git+https://github.com/jochen-schweizer/express-prom-bundle.git",
359684              "type": "distribution"
359685            },
359686            {
359687              "url": "https://github.com/jochen-schweizer/express-prom-bundle#readme",
359688              "type": "website"
359689            }
359690          ],
359691          "evidence": {},
359692          "signature": {
359693            "signature": {
359694              "publicKey": {}
359695            }
359696          },
359697          "modelCard": {
359698            "modelParameters": {
359699              "approach": {}
359700            },
359701            "quantitativeAnalysis": {
359702              "graphics": {}
359703            },
359704            "considerations": {}
359705          }
359706        },
359707        {
359708          "type": "library",
359709          "bom-ref": "pkg:npm/extend@3.0.2?package-id=6bab12d733b687f3",
359710          "supplier": {},
359711          "author": "Stefan Thomas \u003cjustmoon@members.fsf.org\u003e (http://www.justmoon.net)",
359712          "name": "extend",
359713          "version": "3.0.2",
359714          "description": "Port of jQuery.extend for node.js and the browser",
359715          "licenses": [
359716            {
359717              "license": {
359718                "id": "MIT"
359719              }
359720            }
359721          ],
359722          "cpe": "cpe:2.3:a:justmoon:extend:3.0.2:*:*:*:*:*:*:*",
359723          "purl": "pkg:npm/extend@3.0.2",
359724          "swid": {
359725            "attachment": {}
359726          },
359727          "pedigree": {},
359728          "externalReferences": [
359729            {
359730              "url": "git+https://github.com/justmoon/node-extend.git",
359731              "type": "distribution"
359732            },
359733            {
359734              "url": "https://github.com/justmoon/node-extend#readme",
359735              "type": "website"
359736            }
359737          ],
359738          "evidence": {},
359739          "signature": {
359740            "signature": {
359741              "publicKey": {}
359742            }
359743          },
359744          "modelCard": {
359745            "modelParameters": {
359746              "approach": {}
359747            },
359748            "quantitativeAnalysis": {
359749              "graphics": {}
359750            },
359751            "considerations": {}
359752          }
359753        },
359754        {
359755          "type": "library",
359756          "bom-ref": "pkg:npm/extend@3.0.2?package-id=6a93821e99ea76cf",
359757          "supplier": {},
359758          "author": "Stefan Thomas \u003cjustmoon@members.fsf.org\u003e (http://www.justmoon.net)",
359759          "name": "extend",
359760          "version": "3.0.2",
359761          "description": "Port of jQuery.extend for node.js and the browser",
359762          "licenses": [
359763            {
359764              "license": {
359765                "id": "MIT"
359766              }
359767            }
359768          ],
359769          "cpe": "cpe:2.3:a:justmoon:extend:3.0.2:*:*:*:*:*:*:*",
359770          "purl": "pkg:npm/extend@3.0.2",
359771          "swid": {
359772            "attachment": {}
359773          },
359774          "pedigree": {},
359775          "externalReferences": [
359776            {
359777              "url": "git+https://github.com/justmoon/node-extend.git",
359778              "type": "distribution"
359779            },
359780            {
359781              "url": "https://github.com/justmoon/node-extend#readme",
359782              "type": "website"
359783            }
359784          ],
359785          "evidence": {},
359786          "signature": {
359787            "signature": {
359788              "publicKey": {}
359789            }
359790          },
359791          "modelCard": {
359792            "modelParameters": {
359793              "approach": {}
359794            },
359795            "quantitativeAnalysis": {
359796              "graphics": {}
359797            },
359798            "considerations": {}
359799          }
359800        },
359801        {
359802          "type": "library",
359803          "bom-ref": "pkg:npm/extsprintf@1.3.0?package-id=6d772acc2a99f13",
359804          "supplier": {},
359805          "name": "extsprintf",
359806          "version": "1.3.0",
359807          "description": "extended POSIX-style sprintf",
359808          "licenses": [
359809            {
359810              "license": {
359811                "id": "MIT"
359812              }
359813            }
359814          ],
359815          "cpe": "cpe:2.3:a:davepacheco:extsprintf:1.3.0:*:*:*:*:*:*:*",
359816          "purl": "pkg:npm/extsprintf@1.3.0",
359817          "swid": {
359818            "attachment": {}
359819          },
359820          "pedigree": {},
359821          "externalReferences": [
359822            {
359823              "url": "git://github.com/davepacheco/node-extsprintf.git",
359824              "type": "distribution"
359825            },
359826            {
359827              "url": "https://github.com/davepacheco/node-extsprintf#readme",
359828              "type": "website"
359829            }
359830          ],
359831          "evidence": {},
359832          "signature": {
359833            "signature": {
359834              "publicKey": {}
359835            }
359836          },
359837          "modelCard": {
359838            "modelParameters": {
359839              "approach": {}
359840            },
359841            "quantitativeAnalysis": {
359842              "graphics": {}
359843            },
359844            "considerations": {}
359845          }
359846        },
359847        {
359848          "type": "library",
359849          "bom-ref": "pkg:npm/extsprintf@1.3.0?package-id=c9c71fa4864f843a",
359850          "supplier": {},
359851          "name": "extsprintf",
359852          "version": "1.3.0",
359853          "description": "extended POSIX-style sprintf",
359854          "licenses": [
359855            {
359856              "license": {
359857                "id": "MIT"
359858              }
359859            }
359860          ],
359861          "cpe": "cpe:2.3:a:davepacheco:extsprintf:1.3.0:*:*:*:*:*:*:*",
359862          "purl": "pkg:npm/extsprintf@1.3.0",
359863          "swid": {
359864            "attachment": {}
359865          },
359866          "pedigree": {},
359867          "externalReferences": [
359868            {
359869              "url": "git://github.com/davepacheco/node-extsprintf.git",
359870              "type": "distribution"
359871            },
359872            {
359873              "url": "https://github.com/davepacheco/node-extsprintf#readme",
359874              "type": "website"
359875            }
359876          ],
359877          "evidence": {},
359878          "signature": {
359879            "signature": {
359880              "publicKey": {}
359881            }
359882          },
359883          "modelCard": {
359884            "modelParameters": {
359885              "approach": {}
359886            },
359887            "quantitativeAnalysis": {
359888              "graphics": {}
359889            },
359890            "considerations": {}
359891          }
359892        },
359893        {
359894          "type": "library",
359895          "bom-ref": "pkg:npm/fast-deep-equal@3.1.3?package-id=50fc8df9c652bfea",
359896          "supplier": {},
359897          "author": "Evgeny Poberezkin",
359898          "name": "fast-deep-equal",
359899          "version": "3.1.3",
359900          "description": "Fast deep equal",
359901          "licenses": [
359902            {
359903              "license": {
359904                "id": "MIT"
359905              }
359906            }
359907          ],
359908          "cpe": "cpe:2.3:a:fast-deep-equal:fast-deep-equal:3.1.3:*:*:*:*:*:*:*",
359909          "purl": "pkg:npm/fast-deep-equal@3.1.3",
359910          "swid": {
359911            "attachment": {}
359912          },
359913          "pedigree": {},
359914          "externalReferences": [
359915            {
359916              "url": "git+https://github.com/epoberezkin/fast-deep-equal.git",
359917              "type": "distribution"
359918            },
359919            {
359920              "url": "https://github.com/epoberezkin/fast-deep-equal#readme",
359921              "type": "website"
359922            }
359923          ],
359924          "evidence": {},
359925          "signature": {
359926            "signature": {
359927              "publicKey": {}
359928            }
359929          },
359930          "modelCard": {
359931            "modelParameters": {
359932              "approach": {}
359933            },
359934            "quantitativeAnalysis": {
359935              "graphics": {}
359936            },
359937            "considerations": {}
359938          }
359939        },
359940        {
359941          "type": "library",
359942          "bom-ref": "pkg:npm/fast-deep-equal@3.1.3?package-id=6bf670068a1ba042",
359943          "supplier": {},
359944          "author": "Evgeny Poberezkin",
359945          "name": "fast-deep-equal",
359946          "version": "3.1.3",
359947          "description": "Fast deep equal",
359948          "licenses": [
359949            {
359950              "license": {
359951                "id": "MIT"
359952              }
359953            }
359954          ],
359955          "cpe": "cpe:2.3:a:fast-deep-equal:fast-deep-equal:3.1.3:*:*:*:*:*:*:*",
359956          "purl": "pkg:npm/fast-deep-equal@3.1.3",
359957          "swid": {
359958            "attachment": {}
359959          },
359960          "pedigree": {},
359961          "externalReferences": [
359962            {
359963              "url": "git+https://github.com/epoberezkin/fast-deep-equal.git",
359964              "type": "distribution"
359965            },
359966            {
359967              "url": "https://github.com/epoberezkin/fast-deep-equal#readme",
359968              "type": "website"
359969            }
359970          ],
359971          "evidence": {},
359972          "signature": {
359973            "signature": {
359974              "publicKey": {}
359975            }
359976          },
359977          "modelCard": {
359978            "modelParameters": {
359979              "approach": {}
359980            },
359981            "quantitativeAnalysis": {
359982              "graphics": {}
359983            },
359984            "considerations": {}
359985          }
359986        },
359987        {
359988          "type": "library",
359989          "bom-ref": "pkg:npm/fast-json-stable-stringify@2.0.0?package-id=2012b0c94dfc94ce",
359990          "supplier": {},
359991          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
359992          "name": "fast-json-stable-stringify",
359993          "version": "2.0.0",
359994          "description": "deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify",
359995          "licenses": [
359996            {
359997              "license": {
359998                "id": "MIT"
359999              }
360000            }
360001          ],
360002          "cpe": "cpe:2.3:a:fast-json-stable-stringify:fast-json-stable-stringify:2.0.0:*:*:*:*:*:*:*",
360003          "purl": "pkg:npm/fast-json-stable-stringify@2.0.0",
360004          "swid": {
360005            "attachment": {}
360006          },
360007          "pedigree": {},
360008          "externalReferences": [
360009            {
360010              "url": "git://github.com/epoberezkin/fast-json-stable-stringify.git",
360011              "type": "distribution"
360012            },
360013            {
360014              "url": "https://github.com/epoberezkin/fast-json-stable-stringify",
360015              "type": "website"
360016            }
360017          ],
360018          "evidence": {},
360019          "signature": {
360020            "signature": {
360021              "publicKey": {}
360022            }
360023          },
360024          "modelCard": {
360025            "modelParameters": {
360026              "approach": {}
360027            },
360028            "quantitativeAnalysis": {
360029              "graphics": {}
360030            },
360031            "considerations": {}
360032          }
360033        },
360034        {
360035          "type": "library",
360036          "bom-ref": "pkg:npm/fast-json-stable-stringify@2.1.0?package-id=4c56416a0a0165fc",
360037          "supplier": {},
360038          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
360039          "name": "fast-json-stable-stringify",
360040          "version": "2.1.0",
360041          "description": "deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify",
360042          "licenses": [
360043            {
360044              "license": {
360045                "id": "MIT"
360046              }
360047            }
360048          ],
360049          "cpe": "cpe:2.3:a:fast-json-stable-stringify:fast-json-stable-stringify:2.1.0:*:*:*:*:*:*:*",
360050          "purl": "pkg:npm/fast-json-stable-stringify@2.1.0",
360051          "swid": {
360052            "attachment": {}
360053          },
360054          "pedigree": {},
360055          "externalReferences": [
360056            {
360057              "url": "git://github.com/epoberezkin/fast-json-stable-stringify.git",
360058              "type": "distribution"
360059            },
360060            {
360061              "url": "https://github.com/epoberezkin/fast-json-stable-stringify",
360062              "type": "website"
360063            }
360064          ],
360065          "evidence": {},
360066          "signature": {
360067            "signature": {
360068              "publicKey": {}
360069            }
360070          },
360071          "modelCard": {
360072            "modelParameters": {
360073              "approach": {}
360074            },
360075            "quantitativeAnalysis": {
360076              "graphics": {}
360077            },
360078            "considerations": {}
360079          }
360080        },
360081        {
360082          "type": "library",
360083          "bom-ref": "pkg:npm/fast-json-stringify@2.7.7?package-id=549c1c17dce79771",
360084          "supplier": {},
360085          "author": "Matteo Collina \u003chello@matteocollina.com\u003e",
360086          "name": "fast-json-stringify",
360087          "version": "2.7.7",
360088          "description": "Stringify your JSON at max speed",
360089          "licenses": [
360090            {
360091              "license": {
360092                "id": "MIT"
360093              }
360094            }
360095          ],
360096          "cpe": "cpe:2.3:a:fast-json-stringify:fast-json-stringify:2.7.7:*:*:*:*:*:*:*",
360097          "purl": "pkg:npm/fast-json-stringify@2.7.7",
360098          "swid": {
360099            "attachment": {}
360100          },
360101          "pedigree": {},
360102          "externalReferences": [
360103            {
360104              "url": "git+https://github.com/fastify/fast-json-stringify.git",
360105              "type": "distribution"
360106            },
360107            {
360108              "url": "https://github.com/fastify/fast-json-stringify#readme",
360109              "type": "website"
360110            }
360111          ],
360112          "evidence": {},
360113          "signature": {
360114            "signature": {
360115              "publicKey": {}
360116            }
360117          },
360118          "modelCard": {
360119            "modelParameters": {
360120              "approach": {}
360121            },
360122            "quantitativeAnalysis": {
360123              "graphics": {}
360124            },
360125            "considerations": {}
360126          }
360127        },
360128        {
360129          "type": "library",
360130          "bom-ref": "pkg:npm/fast-printf@1.6.6?package-id=848b72b46bada36b",
360131          "supplier": {},
360132          "author": "Gajus Kuizinas \u003cgajus@gajus.com\u003e (http://gajus.com)",
360133          "name": "fast-printf",
360134          "version": "1.6.6",
360135          "description": "Fast and spec-compliant printf implementation for Node.js and browser.",
360136          "licenses": [
360137            {
360138              "license": {
360139                "id": "BSD-3-Clause"
360140              }
360141            }
360142          ],
360143          "cpe": "cpe:2.3:a:fast-printf:fast-printf:1.6.6:*:*:*:*:*:*:*",
360144          "purl": "pkg:npm/fast-printf@1.6.6",
360145          "swid": {
360146            "attachment": {}
360147          },
360148          "pedigree": {},
360149          "externalReferences": [
360150            {
360151              "url": "git+ssh://git@github.com/gajus/fast-printf.git",
360152              "type": "distribution"
360153            },
360154            {
360155              "url": "https://github.com/gajus/fast-printf#readme",
360156              "type": "website"
360157            }
360158          ],
360159          "evidence": {},
360160          "signature": {
360161            "signature": {
360162              "publicKey": {}
360163            }
360164          },
360165          "modelCard": {
360166            "modelParameters": {
360167              "approach": {}
360168            },
360169            "quantitativeAnalysis": {
360170              "graphics": {}
360171            },
360172            "considerations": {}
360173          }
360174        },
360175        {
360176          "type": "library",
360177          "bom-ref": "pkg:npm/fast-safe-stringify@2.0.7?package-id=c12cba20e0a81013",
360178          "supplier": {},
360179          "author": "David Mark Clements",
360180          "name": "fast-safe-stringify",
360181          "version": "2.0.7",
360182          "description": "Safely and quickly serialize JavaScript objects",
360183          "licenses": [
360184            {
360185              "license": {
360186                "id": "MIT"
360187              }
360188            }
360189          ],
360190          "cpe": "cpe:2.3:a:fast-safe-stringify:fast-safe-stringify:2.0.7:*:*:*:*:*:*:*",
360191          "purl": "pkg:npm/fast-safe-stringify@2.0.7",
360192          "swid": {
360193            "attachment": {}
360194          },
360195          "pedigree": {},
360196          "externalReferences": [
360197            {
360198              "url": "git+https://github.com/davidmarkclements/fast-safe-stringify.git",
360199              "type": "distribution"
360200            },
360201            {
360202              "url": "https://github.com/davidmarkclements/fast-safe-stringify#readme",
360203              "type": "website"
360204            }
360205          ],
360206          "evidence": {},
360207          "signature": {
360208            "signature": {
360209              "publicKey": {}
360210            }
360211          },
360212          "modelCard": {
360213            "modelParameters": {
360214              "approach": {}
360215            },
360216            "quantitativeAnalysis": {
360217              "graphics": {}
360218            },
360219            "considerations": {}
360220          }
360221        },
360222        {
360223          "type": "library",
360224          "bom-ref": "pkg:npm/figgy-pudding@3.5.2?package-id=81ce152b3d17f962",
360225          "supplier": {},
360226          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
360227          "name": "figgy-pudding",
360228          "version": "3.5.2",
360229          "description": "Delicious, festive, cascading config/opts definitions",
360230          "licenses": [
360231            {
360232              "license": {
360233                "id": "ISC"
360234              }
360235            }
360236          ],
360237          "cpe": "cpe:2.3:a:figgy-pudding:figgy-pudding:3.5.2:*:*:*:*:*:*:*",
360238          "purl": "pkg:npm/figgy-pudding@3.5.2",
360239          "swid": {
360240            "attachment": {}
360241          },
360242          "pedigree": {},
360243          "externalReferences": [
360244            {
360245              "url": "git+https://github.com/npm/figgy-pudding.git",
360246              "type": "distribution"
360247            },
360248            {
360249              "url": "https://github.com/npm/figgy-pudding#readme",
360250              "type": "website"
360251            }
360252          ],
360253          "evidence": {},
360254          "signature": {
360255            "signature": {
360256              "publicKey": {}
360257            }
360258          },
360259          "modelCard": {
360260            "modelParameters": {
360261              "approach": {}
360262            },
360263            "quantitativeAnalysis": {
360264              "graphics": {}
360265            },
360266            "considerations": {}
360267          }
360268        },
360269        {
360270          "type": "library",
360271          "bom-ref": "pkg:npm/filter-obj@1.1.0?package-id=f88d731707c42b6",
360272          "supplier": {},
360273          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
360274          "name": "filter-obj",
360275          "version": "1.1.0",
360276          "description": "Filter object keys and values into a new object",
360277          "licenses": [
360278            {
360279              "license": {
360280                "id": "MIT"
360281              }
360282            }
360283          ],
360284          "cpe": "cpe:2.3:a:sindresorhus:filter-obj:1.1.0:*:*:*:*:*:*:*",
360285          "purl": "pkg:npm/filter-obj@1.1.0",
360286          "swid": {
360287            "attachment": {}
360288          },
360289          "pedigree": {},
360290          "externalReferences": [
360291            {
360292              "url": "git+https://github.com/sindresorhus/filter-obj.git",
360293              "type": "distribution"
360294            },
360295            {
360296              "url": "https://github.com/sindresorhus/filter-obj#readme",
360297              "type": "website"
360298            }
360299          ],
360300          "evidence": {},
360301          "signature": {
360302            "signature": {
360303              "publicKey": {}
360304            }
360305          },
360306          "modelCard": {
360307            "modelParameters": {
360308              "approach": {}
360309            },
360310            "quantitativeAnalysis": {
360311              "graphics": {}
360312            },
360313            "considerations": {}
360314          }
360315        },
360316        {
360317          "type": "library",
360318          "bom-ref": "pkg:npm/finalhandler@1.1.2?package-id=6259b7a0001a9b91",
360319          "supplier": {},
360320          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
360321          "name": "finalhandler",
360322          "version": "1.1.2",
360323          "description": "Node.js final http responder",
360324          "licenses": [
360325            {
360326              "license": {
360327                "id": "MIT"
360328              }
360329            }
360330          ],
360331          "cpe": "cpe:2.3:a:finalhandler:finalhandler:1.1.2:*:*:*:*:*:*:*",
360332          "purl": "pkg:npm/finalhandler@1.1.2",
360333          "swid": {
360334            "attachment": {}
360335          },
360336          "pedigree": {},
360337          "externalReferences": [
360338            {
360339              "url": "git+https://github.com/pillarjs/finalhandler.git",
360340              "type": "distribution"
360341            },
360342            {
360343              "url": "https://github.com/pillarjs/finalhandler#readme",
360344              "type": "website"
360345            }
360346          ],
360347          "evidence": {},
360348          "signature": {
360349            "signature": {
360350              "publicKey": {}
360351            }
360352          },
360353          "modelCard": {
360354            "modelParameters": {
360355              "approach": {}
360356            },
360357            "quantitativeAnalysis": {
360358              "graphics": {}
360359            },
360360            "considerations": {}
360361          }
360362        },
360363        {
360364          "type": "library",
360365          "bom-ref": "pkg:npm/find-npm-prefix@1.0.2?package-id=52a36cf455f307ab",
360366          "supplier": {},
360367          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
360368          "name": "find-npm-prefix",
360369          "version": "1.0.2",
360370          "description": "Find the npm project directory associated with for a given directory",
360371          "licenses": [
360372            {
360373              "license": {
360374                "id": "ISC"
360375              }
360376            }
360377          ],
360378          "cpe": "cpe:2.3:a:find-npm-prefix:find-npm-prefix:1.0.2:*:*:*:*:*:*:*",
360379          "purl": "pkg:npm/find-npm-prefix@1.0.2",
360380          "swid": {
360381            "attachment": {}
360382          },
360383          "pedigree": {},
360384          "externalReferences": [
360385            {
360386              "url": "git+https://github.com/npm/find-npm-prefix.git",
360387              "type": "distribution"
360388            },
360389            {
360390              "url": "https://github.com/npm/find-npm-prefix#readme",
360391              "type": "website"
360392            }
360393          ],
360394          "evidence": {},
360395          "signature": {
360396            "signature": {
360397              "publicKey": {}
360398            }
360399          },
360400          "modelCard": {
360401            "modelParameters": {
360402              "approach": {}
360403            },
360404            "quantitativeAnalysis": {
360405              "graphics": {}
360406            },
360407            "considerations": {}
360408          }
360409        },
360410        {
360411          "type": "library",
360412          "bom-ref": "pkg:npm/find-up@3.0.0?package-id=74983d480f9ee68a",
360413          "supplier": {},
360414          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
360415          "name": "find-up",
360416          "version": "3.0.0",
360417          "description": "Find a file or directory by walking up parent directories",
360418          "licenses": [
360419            {
360420              "license": {
360421                "id": "MIT"
360422              }
360423            }
360424          ],
360425          "cpe": "cpe:2.3:a:sindresorhus:find-up:3.0.0:*:*:*:*:*:*:*",
360426          "purl": "pkg:npm/find-up@3.0.0",
360427          "swid": {
360428            "attachment": {}
360429          },
360430          "pedigree": {},
360431          "externalReferences": [
360432            {
360433              "url": "git+https://github.com/sindresorhus/find-up.git",
360434              "type": "distribution"
360435            },
360436            {
360437              "url": "https://github.com/sindresorhus/find-up#readme",
360438              "type": "website"
360439            }
360440          ],
360441          "evidence": {},
360442          "signature": {
360443            "signature": {
360444              "publicKey": {}
360445            }
360446          },
360447          "modelCard": {
360448            "modelParameters": {
360449              "approach": {}
360450            },
360451            "quantitativeAnalysis": {
360452              "graphics": {}
360453            },
360454            "considerations": {}
360455          }
360456        },
360457        {
360458          "type": "library",
360459          "bom-ref": "pkg:npm/find-up@3.0.0?package-id=9716c27e89885f20",
360460          "supplier": {},
360461          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
360462          "name": "find-up",
360463          "version": "3.0.0",
360464          "description": "Find a file or directory by walking up parent directories",
360465          "licenses": [
360466            {
360467              "license": {
360468                "id": "MIT"
360469              }
360470            }
360471          ],
360472          "cpe": "cpe:2.3:a:sindresorhus:find-up:3.0.0:*:*:*:*:*:*:*",
360473          "purl": "pkg:npm/find-up@3.0.0",
360474          "swid": {
360475            "attachment": {}
360476          },
360477          "pedigree": {},
360478          "externalReferences": [
360479            {
360480              "url": "git+https://github.com/sindresorhus/find-up.git",
360481              "type": "distribution"
360482            },
360483            {
360484              "url": "https://github.com/sindresorhus/find-up#readme",
360485              "type": "website"
360486            }
360487          ],
360488          "evidence": {},
360489          "signature": {
360490            "signature": {
360491              "publicKey": {}
360492            }
360493          },
360494          "modelCard": {
360495            "modelParameters": {
360496              "approach": {}
360497            },
360498            "quantitativeAnalysis": {
360499              "graphics": {}
360500            },
360501            "considerations": {}
360502          }
360503        },
360504        {
360505          "type": "library",
360506          "bom-ref": "pkg:npm/flush-write-stream@1.0.3?package-id=e1274c36a6d8d9af",
360507          "supplier": {},
360508          "author": "Mathias Buus (@mafintosh)",
360509          "name": "flush-write-stream",
360510          "version": "1.0.3",
360511          "description": "A write stream constructor that supports a flush function that is called before finish is emitted",
360512          "licenses": [
360513            {
360514              "license": {
360515                "id": "MIT"
360516              }
360517            }
360518          ],
360519          "cpe": "cpe:2.3:a:flush-write-stream:flush-write-stream:1.0.3:*:*:*:*:*:*:*",
360520          "purl": "pkg:npm/flush-write-stream@1.0.3",
360521          "swid": {
360522            "attachment": {}
360523          },
360524          "pedigree": {},
360525          "externalReferences": [
360526            {
360527              "url": "git+https://github.com/mafintosh/flush-write-stream.git",
360528              "type": "distribution"
360529            },
360530            {
360531              "url": "https://github.com/mafintosh/flush-write-stream",
360532              "type": "website"
360533            }
360534          ],
360535          "evidence": {},
360536          "signature": {
360537            "signature": {
360538              "publicKey": {}
360539            }
360540          },
360541          "modelCard": {
360542            "modelParameters": {
360543              "approach": {}
360544            },
360545            "quantitativeAnalysis": {
360546              "graphics": {}
360547            },
360548            "considerations": {}
360549          }
360550        },
360551        {
360552          "type": "library",
360553          "bom-ref": "pkg:npm/follow-redirects@1.14.1?package-id=4b652173b205fb20",
360554          "supplier": {},
360555          "author": "Ruben Verborgh \u003cruben@verborgh.org\u003e (https://ruben.verborgh.org/)",
360556          "name": "follow-redirects",
360557          "version": "1.14.1",
360558          "description": "HTTP and HTTPS modules that follow redirects.",
360559          "licenses": [
360560            {
360561              "license": {
360562                "id": "MIT"
360563              }
360564            }
360565          ],
360566          "cpe": "cpe:2.3:a:follow-redirects:follow-redirects:1.14.1:*:*:*:*:*:*:*",
360567          "purl": "pkg:npm/follow-redirects@1.14.1",
360568          "swid": {
360569            "attachment": {}
360570          },
360571          "pedigree": {},
360572          "externalReferences": [
360573            {
360574              "url": "git+ssh://git@github.com/follow-redirects/follow-redirects.git",
360575              "type": "distribution"
360576            },
360577            {
360578              "url": "https://github.com/follow-redirects/follow-redirects",
360579              "type": "website"
360580            }
360581          ],
360582          "evidence": {},
360583          "signature": {
360584            "signature": {
360585              "publicKey": {}
360586            }
360587          },
360588          "modelCard": {
360589            "modelParameters": {
360590              "approach": {}
360591            },
360592            "quantitativeAnalysis": {
360593              "graphics": {}
360594            },
360595            "considerations": {}
360596          }
360597        },
360598        {
360599          "type": "library",
360600          "bom-ref": "pkg:npm/forever-agent@0.6.1?package-id=98a3d322631e6154",
360601          "supplier": {},
360602          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
360603          "name": "forever-agent",
360604          "version": "0.6.1",
360605          "description": "HTTP Agent that keeps socket connections alive between keep-alive requests. Formerly part of mikeal/request, now a standalone module.",
360606          "licenses": [
360607            {
360608              "license": {
360609                "id": "Apache-2.0"
360610              }
360611            }
360612          ],
360613          "cpe": "cpe:2.3:a:forever-agent:forever-agent:0.6.1:*:*:*:*:*:*:*",
360614          "purl": "pkg:npm/forever-agent@0.6.1",
360615          "swid": {
360616            "attachment": {}
360617          },
360618          "pedigree": {},
360619          "externalReferences": [
360620            {
360621              "url": "git+https://github.com/mikeal/forever-agent.git",
360622              "type": "distribution"
360623            },
360624            {
360625              "url": "https://github.com/mikeal/forever-agent#readme",
360626              "type": "website"
360627            }
360628          ],
360629          "evidence": {},
360630          "signature": {
360631            "signature": {
360632              "publicKey": {}
360633            }
360634          },
360635          "modelCard": {
360636            "modelParameters": {
360637              "approach": {}
360638            },
360639            "quantitativeAnalysis": {
360640              "graphics": {}
360641            },
360642            "considerations": {}
360643          }
360644        },
360645        {
360646          "type": "library",
360647          "bom-ref": "pkg:npm/forever-agent@0.6.1?package-id=f246b38c6ee5f71b",
360648          "supplier": {},
360649          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
360650          "name": "forever-agent",
360651          "version": "0.6.1",
360652          "description": "HTTP Agent that keeps socket connections alive between keep-alive requests. Formerly part of mikeal/request, now a standalone module.",
360653          "licenses": [
360654            {
360655              "license": {
360656                "id": "Apache-2.0"
360657              }
360658            }
360659          ],
360660          "cpe": "cpe:2.3:a:forever-agent:forever-agent:0.6.1:*:*:*:*:*:*:*",
360661          "purl": "pkg:npm/forever-agent@0.6.1",
360662          "swid": {
360663            "attachment": {}
360664          },
360665          "pedigree": {},
360666          "externalReferences": [
360667            {
360668              "url": "git+https://github.com/mikeal/forever-agent.git",
360669              "type": "distribution"
360670            },
360671            {
360672              "url": "https://github.com/mikeal/forever-agent#readme",
360673              "type": "website"
360674            }
360675          ],
360676          "evidence": {},
360677          "signature": {
360678            "signature": {
360679              "publicKey": {}
360680            }
360681          },
360682          "modelCard": {
360683            "modelParameters": {
360684              "approach": {}
360685            },
360686            "quantitativeAnalysis": {
360687              "graphics": {}
360688            },
360689            "considerations": {}
360690          }
360691        },
360692        {
360693          "type": "library",
360694          "bom-ref": "pkg:npm/form-data@2.3.3?package-id=d6e8268dcb37667b",
360695          "supplier": {},
360696          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
360697          "name": "form-data",
360698          "version": "2.3.3",
360699          "description": "A library to create readable \"multipart/form-data\" streams. Can be used to submit forms and file uploads to other web applications.",
360700          "licenses": [
360701            {
360702              "license": {
360703                "id": "MIT"
360704              }
360705            }
360706          ],
360707          "cpe": "cpe:2.3:a:form-data:form-data:2.3.3:*:*:*:*:*:*:*",
360708          "purl": "pkg:npm/form-data@2.3.3",
360709          "swid": {
360710            "attachment": {}
360711          },
360712          "pedigree": {},
360713          "externalReferences": [
360714            {
360715              "url": "git://github.com/form-data/form-data.git",
360716              "type": "distribution"
360717            },
360718            {
360719              "url": "https://github.com/form-data/form-data#readme",
360720              "type": "website"
360721            }
360722          ],
360723          "evidence": {},
360724          "signature": {
360725            "signature": {
360726              "publicKey": {}
360727            }
360728          },
360729          "modelCard": {
360730            "modelParameters": {
360731              "approach": {}
360732            },
360733            "quantitativeAnalysis": {
360734              "graphics": {}
360735            },
360736            "considerations": {}
360737          }
360738        },
360739        {
360740          "type": "library",
360741          "bom-ref": "pkg:npm/form-data@2.3.3?package-id=1d49afe3df30119c",
360742          "supplier": {},
360743          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
360744          "name": "form-data",
360745          "version": "2.3.3",
360746          "description": "A library to create readable \"multipart/form-data\" streams. Can be used to submit forms and file uploads to other web applications.",
360747          "licenses": [
360748            {
360749              "license": {
360750                "id": "MIT"
360751              }
360752            }
360753          ],
360754          "cpe": "cpe:2.3:a:form-data:form-data:2.3.3:*:*:*:*:*:*:*",
360755          "purl": "pkg:npm/form-data@2.3.3",
360756          "swid": {
360757            "attachment": {}
360758          },
360759          "pedigree": {},
360760          "externalReferences": [
360761            {
360762              "url": "git://github.com/form-data/form-data.git",
360763              "type": "distribution"
360764            },
360765            {
360766              "url": "https://github.com/form-data/form-data#readme",
360767              "type": "website"
360768            }
360769          ],
360770          "evidence": {},
360771          "signature": {
360772            "signature": {
360773              "publicKey": {}
360774            }
360775          },
360776          "modelCard": {
360777            "modelParameters": {
360778              "approach": {}
360779            },
360780            "quantitativeAnalysis": {
360781              "graphics": {}
360782            },
360783            "considerations": {}
360784          }
360785        },
360786        {
360787          "type": "library",
360788          "bom-ref": "pkg:npm/forwarded@0.2.0?package-id=7586805f75eddd56",
360789          "supplier": {},
360790          "name": "forwarded",
360791          "version": "0.2.0",
360792          "description": "Parse HTTP X-Forwarded-For header",
360793          "licenses": [
360794            {
360795              "license": {
360796                "id": "MIT"
360797              }
360798            }
360799          ],
360800          "cpe": "cpe:2.3:a:forwarded:forwarded:0.2.0:*:*:*:*:*:*:*",
360801          "purl": "pkg:npm/forwarded@0.2.0",
360802          "swid": {
360803            "attachment": {}
360804          },
360805          "pedigree": {},
360806          "externalReferences": [
360807            {
360808              "url": "git+https://github.com/jshttp/forwarded.git",
360809              "type": "distribution"
360810            },
360811            {
360812              "url": "https://github.com/jshttp/forwarded#readme",
360813              "type": "website"
360814            }
360815          ],
360816          "evidence": {},
360817          "signature": {
360818            "signature": {
360819              "publicKey": {}
360820            }
360821          },
360822          "modelCard": {
360823            "modelParameters": {
360824              "approach": {}
360825            },
360826            "quantitativeAnalysis": {
360827              "graphics": {}
360828            },
360829            "considerations": {}
360830          }
360831        },
360832        {
360833          "type": "library",
360834          "bom-ref": "pkg:npm/fresh@0.5.2?package-id=1aacf9842bb86f3e",
360835          "supplier": {},
360836          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
360837          "name": "fresh",
360838          "version": "0.5.2",
360839          "description": "HTTP response freshness testing",
360840          "licenses": [
360841            {
360842              "license": {
360843                "id": "MIT"
360844              }
360845            }
360846          ],
360847          "cpe": "cpe:2.3:a:jshttp:fresh:0.5.2:*:*:*:*:*:*:*",
360848          "purl": "pkg:npm/fresh@0.5.2",
360849          "swid": {
360850            "attachment": {}
360851          },
360852          "pedigree": {},
360853          "externalReferences": [
360854            {
360855              "url": "git+https://github.com/jshttp/fresh.git",
360856              "type": "distribution"
360857            },
360858            {
360859              "url": "https://github.com/jshttp/fresh#readme",
360860              "type": "website"
360861            }
360862          ],
360863          "evidence": {},
360864          "signature": {
360865            "signature": {
360866              "publicKey": {}
360867            }
360868          },
360869          "modelCard": {
360870            "modelParameters": {
360871              "approach": {}
360872            },
360873            "quantitativeAnalysis": {
360874              "graphics": {}
360875            },
360876            "considerations": {}
360877          }
360878        },
360879        {
360880          "type": "library",
360881          "bom-ref": "pkg:npm/from2@1.3.0?package-id=c7f3a7e49c7e8f25",
360882          "supplier": {},
360883          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
360884          "name": "from2",
360885          "version": "1.3.0",
360886          "description": "Convenience wrapper for ReadableStream, with an API lifted from \"from\" and \"through2\"",
360887          "licenses": [
360888            {
360889              "license": {
360890                "id": "MIT"
360891              }
360892            }
360893          ],
360894          "cpe": "cpe:2.3:a:hughsk:from2:1.3.0:*:*:*:*:*:*:*",
360895          "purl": "pkg:npm/from2@1.3.0",
360896          "swid": {
360897            "attachment": {}
360898          },
360899          "pedigree": {},
360900          "externalReferences": [
360901            {
360902              "url": "git://github.com/hughsk/from2.git",
360903              "type": "distribution"
360904            },
360905            {
360906              "url": "https://github.com/hughsk/from2",
360907              "type": "website"
360908            }
360909          ],
360910          "evidence": {},
360911          "signature": {
360912            "signature": {
360913              "publicKey": {}
360914            }
360915          },
360916          "modelCard": {
360917            "modelParameters": {
360918              "approach": {}
360919            },
360920            "quantitativeAnalysis": {
360921              "graphics": {}
360922            },
360923            "considerations": {}
360924          }
360925        },
360926        {
360927          "type": "library",
360928          "bom-ref": "pkg:npm/from2@2.3.0?package-id=ee2d6b417c35bfd2",
360929          "supplier": {},
360930          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
360931          "name": "from2",
360932          "version": "2.3.0",
360933          "description": "Convenience wrapper for ReadableStream, with an API lifted from \"from\" and \"through2\"",
360934          "licenses": [
360935            {
360936              "license": {
360937                "id": "MIT"
360938              }
360939            }
360940          ],
360941          "cpe": "cpe:2.3:a:hughsk:from2:2.3.0:*:*:*:*:*:*:*",
360942          "purl": "pkg:npm/from2@2.3.0",
360943          "swid": {
360944            "attachment": {}
360945          },
360946          "pedigree": {},
360947          "externalReferences": [
360948            {
360949              "url": "git://github.com/hughsk/from2.git",
360950              "type": "distribution"
360951            },
360952            {
360953              "url": "https://github.com/hughsk/from2",
360954              "type": "website"
360955            }
360956          ],
360957          "evidence": {},
360958          "signature": {
360959            "signature": {
360960              "publicKey": {}
360961            }
360962          },
360963          "modelCard": {
360964            "modelParameters": {
360965              "approach": {}
360966            },
360967            "quantitativeAnalysis": {
360968              "graphics": {}
360969            },
360970            "considerations": {}
360971          }
360972        },
360973        {
360974          "type": "library",
360975          "bom-ref": "pkg:npm/fs-minipass@1.2.7?package-id=2e904f22ead50ae2",
360976          "supplier": {},
360977          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
360978          "name": "fs-minipass",
360979          "version": "1.2.7",
360980          "description": "fs read and write streams based on minipass",
360981          "licenses": [
360982            {
360983              "license": {
360984                "id": "ISC"
360985              }
360986            }
360987          ],
360988          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:1.2.7:*:*:*:*:*:*:*",
360989          "purl": "pkg:npm/fs-minipass@1.2.7",
360990          "swid": {
360991            "attachment": {}
360992          },
360993          "pedigree": {},
360994          "externalReferences": [
360995            {
360996              "url": "git+https://github.com/npm/fs-minipass.git",
360997              "type": "distribution"
360998            },
360999            {
361000              "url": "https://github.com/npm/fs-minipass#readme",
361001              "type": "website"
361002            }
361003          ],
361004          "evidence": {},
361005          "signature": {
361006            "signature": {
361007              "publicKey": {}
361008            }
361009          },
361010          "modelCard": {
361011            "modelParameters": {
361012              "approach": {}
361013            },
361014            "quantitativeAnalysis": {
361015              "graphics": {}
361016            },
361017            "considerations": {}
361018          }
361019        },
361020        {
361021          "type": "library",
361022          "bom-ref": "pkg:npm/fs-vacuum@1.2.10?package-id=b9aa5d16af1961b0",
361023          "supplier": {},
361024          "author": "Forrest L Norvell \u003cogd@aoaioxxysz.net\u003e",
361025          "name": "fs-vacuum",
361026          "version": "1.2.10",
361027          "description": "recursively remove empty directories -- to a point",
361028          "licenses": [
361029            {
361030              "license": {
361031                "id": "ISC"
361032              }
361033            }
361034          ],
361035          "cpe": "cpe:2.3:a:fs-vacuum:fs-vacuum:1.2.10:*:*:*:*:*:*:*",
361036          "purl": "pkg:npm/fs-vacuum@1.2.10",
361037          "swid": {
361038            "attachment": {}
361039          },
361040          "pedigree": {},
361041          "externalReferences": [
361042            {
361043              "url": "git+https://github.com/npm/fs-vacuum.git",
361044              "type": "distribution"
361045            },
361046            {
361047              "url": "https://github.com/npm/fs-vacuum",
361048              "type": "website"
361049            }
361050          ],
361051          "evidence": {},
361052          "signature": {
361053            "signature": {
361054              "publicKey": {}
361055            }
361056          },
361057          "modelCard": {
361058            "modelParameters": {
361059              "approach": {}
361060            },
361061            "quantitativeAnalysis": {
361062              "graphics": {}
361063            },
361064            "considerations": {}
361065          }
361066        },
361067        {
361068          "type": "library",
361069          "bom-ref": "pkg:npm/fs-write-stream-atomic@1.0.10?package-id=7b08016bb08061fe",
361070          "supplier": {},
361071          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
361072          "name": "fs-write-stream-atomic",
361073          "version": "1.0.10",
361074          "description": "Like `fs.createWriteStream(...)`, but atomic.",
361075          "licenses": [
361076            {
361077              "license": {
361078                "id": "ISC"
361079              }
361080            }
361081          ],
361082          "cpe": "cpe:2.3:a:fs-write-stream-atomic:fs-write-stream-atomic:1.0.10:*:*:*:*:*:*:*",
361083          "purl": "pkg:npm/fs-write-stream-atomic@1.0.10",
361084          "swid": {
361085            "attachment": {}
361086          },
361087          "pedigree": {},
361088          "externalReferences": [
361089            {
361090              "url": "git+https://github.com/npm/fs-write-stream-atomic.git",
361091              "type": "distribution"
361092            },
361093            {
361094              "url": "https://github.com/npm/fs-write-stream-atomic",
361095              "type": "website"
361096            }
361097          ],
361098          "evidence": {},
361099          "signature": {
361100            "signature": {
361101              "publicKey": {}
361102            }
361103          },
361104          "modelCard": {
361105            "modelParameters": {
361106              "approach": {}
361107            },
361108            "quantitativeAnalysis": {
361109              "graphics": {}
361110            },
361111            "considerations": {}
361112          }
361113        },
361114        {
361115          "type": "library",
361116          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=9584ea0c034d1c3c",
361117          "supplier": {},
361118          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
361119          "name": "fs.realpath",
361120          "version": "1.0.0",
361121          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
361122          "licenses": [
361123            {
361124              "license": {
361125                "id": "ISC"
361126              }
361127            }
361128          ],
361129          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
361130          "purl": "pkg:npm/fs.realpath@1.0.0",
361131          "swid": {
361132            "attachment": {}
361133          },
361134          "pedigree": {},
361135          "externalReferences": [
361136            {
361137              "url": "git+https://github.com/isaacs/fs.realpath.git",
361138              "type": "distribution"
361139            },
361140            {
361141              "url": "https://github.com/isaacs/fs.realpath#readme",
361142              "type": "website"
361143            }
361144          ],
361145          "evidence": {},
361146          "signature": {
361147            "signature": {
361148              "publicKey": {}
361149            }
361150          },
361151          "modelCard": {
361152            "modelParameters": {
361153              "approach": {}
361154            },
361155            "quantitativeAnalysis": {
361156              "graphics": {}
361157            },
361158            "considerations": {}
361159          }
361160        },
361161        {
361162          "type": "library",
361163          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=ac3c818d9ca6548d",
361164          "supplier": {},
361165          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
361166          "name": "fs.realpath",
361167          "version": "1.0.0",
361168          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
361169          "licenses": [
361170            {
361171              "license": {
361172                "id": "ISC"
361173              }
361174            }
361175          ],
361176          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
361177          "purl": "pkg:npm/fs.realpath@1.0.0",
361178          "swid": {
361179            "attachment": {}
361180          },
361181          "pedigree": {},
361182          "externalReferences": [
361183            {
361184              "url": "git+https://github.com/isaacs/fs.realpath.git",
361185              "type": "distribution"
361186            },
361187            {
361188              "url": "https://github.com/isaacs/fs.realpath#readme",
361189              "type": "website"
361190            }
361191          ],
361192          "evidence": {},
361193          "signature": {
361194            "signature": {
361195              "publicKey": {}
361196            }
361197          },
361198          "modelCard": {
361199            "modelParameters": {
361200              "approach": {}
361201            },
361202            "quantitativeAnalysis": {
361203              "graphics": {}
361204            },
361205            "considerations": {}
361206          }
361207        },
361208        {
361209          "type": "library",
361210          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=44648bf09db15f6c",
361211          "supplier": {},
361212          "author": "Raynos \u003craynos2@gmail.com\u003e",
361213          "name": "function-bind",
361214          "version": "1.1.1",
361215          "description": "Implementation of Function.prototype.bind",
361216          "licenses": [
361217            {
361218              "license": {
361219                "id": "MIT"
361220              }
361221            }
361222          ],
361223          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
361224          "purl": "pkg:npm/function-bind@1.1.1",
361225          "swid": {
361226            "attachment": {}
361227          },
361228          "pedigree": {},
361229          "externalReferences": [
361230            {
361231              "url": "git://github.com/Raynos/function-bind.git",
361232              "type": "distribution"
361233            },
361234            {
361235              "url": "https://github.com/Raynos/function-bind",
361236              "type": "website"
361237            }
361238          ],
361239          "evidence": {},
361240          "signature": {
361241            "signature": {
361242              "publicKey": {}
361243            }
361244          },
361245          "modelCard": {
361246            "modelParameters": {
361247              "approach": {}
361248            },
361249            "quantitativeAnalysis": {
361250              "graphics": {}
361251            },
361252            "considerations": {}
361253          }
361254        },
361255        {
361256          "type": "library",
361257          "bom-ref": "pkg:npm/gauge@2.7.4?package-id=ea01ccd89b49fe1f",
361258          "supplier": {},
361259          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
361260          "name": "gauge",
361261          "version": "2.7.4",
361262          "description": "A terminal based horizontal guage",
361263          "licenses": [
361264            {
361265              "license": {
361266                "id": "ISC"
361267              }
361268            }
361269          ],
361270          "cpe": "cpe:2.3:a:gauge:gauge:2.7.4:*:*:*:*:*:*:*",
361271          "purl": "pkg:npm/gauge@2.7.4",
361272          "swid": {
361273            "attachment": {}
361274          },
361275          "pedigree": {},
361276          "externalReferences": [
361277            {
361278              "url": "git+https://github.com/iarna/gauge.git",
361279              "type": "distribution"
361280            },
361281            {
361282              "url": "https://github.com/iarna/gauge",
361283              "type": "website"
361284            }
361285          ],
361286          "evidence": {},
361287          "signature": {
361288            "signature": {
361289              "publicKey": {}
361290            }
361291          },
361292          "modelCard": {
361293            "modelParameters": {
361294              "approach": {}
361295            },
361296            "quantitativeAnalysis": {
361297              "graphics": {}
361298            },
361299            "considerations": {}
361300          }
361301        },
361302        {
361303          "type": "library",
361304          "bom-ref": "pkg:npm/genfun@5.0.0?package-id=6ca73a56321ec465",
361305          "supplier": {},
361306          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
361307          "name": "genfun",
361308          "version": "5.0.0",
361309          "description": "Fast, prototype-friendly multimethods.",
361310          "licenses": [
361311            {
361312              "license": {
361313                "id": "MIT"
361314              }
361315            }
361316          ],
361317          "cpe": "cpe:2.3:a:genfun:genfun:5.0.0:*:*:*:*:*:*:*",
361318          "purl": "pkg:npm/genfun@5.0.0",
361319          "swid": {
361320            "attachment": {}
361321          },
361322          "pedigree": {},
361323          "externalReferences": [
361324            {
361325              "url": "git://github.com/zkat/genfun.git",
361326              "type": "distribution"
361327            },
361328            {
361329              "url": "http://github.com/zkat/genfun",
361330              "type": "website"
361331            }
361332          ],
361333          "evidence": {},
361334          "signature": {
361335            "signature": {
361336              "publicKey": {}
361337            }
361338          },
361339          "modelCard": {
361340            "modelParameters": {
361341              "approach": {}
361342            },
361343            "quantitativeAnalysis": {
361344              "graphics": {}
361345            },
361346            "considerations": {}
361347          }
361348        },
361349        {
361350          "type": "library",
361351          "bom-ref": "pkg:npm/gentle-fs@2.3.1?package-id=9e57430eae250bbf",
361352          "supplier": {},
361353          "author": "Mike Sherov",
361354          "name": "gentle-fs",
361355          "version": "2.3.1",
361356          "description": "Gentle Filesystem operations",
361357          "licenses": [
361358            {
361359              "license": {
361360                "id": "Artistic-2.0"
361361              }
361362            }
361363          ],
361364          "cpe": "cpe:2.3:a:gentle-fs:gentle-fs:2.3.1:*:*:*:*:*:*:*",
361365          "purl": "pkg:npm/gentle-fs@2.3.1",
361366          "swid": {
361367            "attachment": {}
361368          },
361369          "pedigree": {},
361370          "externalReferences": [
361371            {
361372              "url": "git://github.com/npm/gentle-fs.git",
361373              "type": "distribution"
361374            },
361375            {
361376              "url": "https://github.com/npm/gentle-fs#readme",
361377              "type": "website"
361378            }
361379          ],
361380          "evidence": {},
361381          "signature": {
361382            "signature": {
361383              "publicKey": {}
361384            }
361385          },
361386          "modelCard": {
361387            "modelParameters": {
361388              "approach": {}
361389            },
361390            "quantitativeAnalysis": {
361391              "graphics": {}
361392            },
361393            "considerations": {}
361394          }
361395        },
361396        {
361397          "type": "library",
361398          "bom-ref": "pkg:npm/get-caller-file@2.0.5?package-id=c3a7c0e90ec1bd2a",
361399          "supplier": {},
361400          "author": "Stefan Penner",
361401          "name": "get-caller-file",
361402          "version": "2.0.5",
361403          "description": "[![Build Status](https://travis-ci.org/stefanpenner/get-caller-file.svg?branch=master)](https://travis-ci.org/stefanpenner/get-caller-file) [![Build status](https://ci.appveyor.com/api/projects/status/ol2q94g1932cy14a/branch/master?svg=true)](https://ci.appveyor.com/project/embercli/get-caller-file/branch/master)",
361404          "licenses": [
361405            {
361406              "license": {
361407                "id": "ISC"
361408              }
361409            }
361410          ],
361411          "cpe": "cpe:2.3:a:get-caller-file:get-caller-file:2.0.5:*:*:*:*:*:*:*",
361412          "purl": "pkg:npm/get-caller-file@2.0.5",
361413          "swid": {
361414            "attachment": {}
361415          },
361416          "pedigree": {},
361417          "externalReferences": [
361418            {
361419              "url": "git+https://github.com/stefanpenner/get-caller-file.git",
361420              "type": "distribution"
361421            },
361422            {
361423              "url": "https://github.com/stefanpenner/get-caller-file#readme",
361424              "type": "website"
361425            }
361426          ],
361427          "evidence": {},
361428          "signature": {
361429            "signature": {
361430              "publicKey": {}
361431            }
361432          },
361433          "modelCard": {
361434            "modelParameters": {
361435              "approach": {}
361436            },
361437            "quantitativeAnalysis": {
361438              "graphics": {}
361439            },
361440            "considerations": {}
361441          }
361442        },
361443        {
361444          "type": "library",
361445          "bom-ref": "pkg:npm/get-stream@3.0.0?package-id=1101f5258c5b4846",
361446          "supplier": {},
361447          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
361448          "name": "get-stream",
361449          "version": "3.0.0",
361450          "description": "Get a stream as a string, buffer, or array",
361451          "licenses": [
361452            {
361453              "license": {
361454                "id": "MIT"
361455              }
361456            }
361457          ],
361458          "cpe": "cpe:2.3:a:sindresorhus:get-stream:3.0.0:*:*:*:*:*:*:*",
361459          "purl": "pkg:npm/get-stream@3.0.0",
361460          "swid": {
361461            "attachment": {}
361462          },
361463          "pedigree": {},
361464          "externalReferences": [
361465            {
361466              "url": "git+https://github.com/sindresorhus/get-stream.git",
361467              "type": "distribution"
361468            },
361469            {
361470              "url": "https://github.com/sindresorhus/get-stream#readme",
361471              "type": "website"
361472            }
361473          ],
361474          "evidence": {},
361475          "signature": {
361476            "signature": {
361477              "publicKey": {}
361478            }
361479          },
361480          "modelCard": {
361481            "modelParameters": {
361482              "approach": {}
361483            },
361484            "quantitativeAnalysis": {
361485              "graphics": {}
361486            },
361487            "considerations": {}
361488          }
361489        },
361490        {
361491          "type": "library",
361492          "bom-ref": "pkg:npm/get-stream@3.0.0?package-id=d5ca602593287b20",
361493          "supplier": {},
361494          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
361495          "name": "get-stream",
361496          "version": "3.0.0",
361497          "description": "Get a stream as a string, buffer, or array",
361498          "licenses": [
361499            {
361500              "license": {
361501                "id": "MIT"
361502              }
361503            }
361504          ],
361505          "cpe": "cpe:2.3:a:sindresorhus:get-stream:3.0.0:*:*:*:*:*:*:*",
361506          "purl": "pkg:npm/get-stream@3.0.0",
361507          "swid": {
361508            "attachment": {}
361509          },
361510          "pedigree": {},
361511          "externalReferences": [
361512            {
361513              "url": "git+https://github.com/sindresorhus/get-stream.git",
361514              "type": "distribution"
361515            },
361516            {
361517              "url": "https://github.com/sindresorhus/get-stream#readme",
361518              "type": "website"
361519            }
361520          ],
361521          "evidence": {},
361522          "signature": {
361523            "signature": {
361524              "publicKey": {}
361525            }
361526          },
361527          "modelCard": {
361528            "modelParameters": {
361529              "approach": {}
361530            },
361531            "quantitativeAnalysis": {
361532              "graphics": {}
361533            },
361534            "considerations": {}
361535          }
361536        },
361537        {
361538          "type": "library",
361539          "bom-ref": "pkg:npm/get-stream@4.1.0?package-id=d90dfcea848a9fbf",
361540          "supplier": {},
361541          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
361542          "name": "get-stream",
361543          "version": "4.1.0",
361544          "description": "Get a stream as a string, buffer, or array",
361545          "licenses": [
361546            {
361547              "license": {
361548                "id": "MIT"
361549              }
361550            }
361551          ],
361552          "cpe": "cpe:2.3:a:sindresorhus:get-stream:4.1.0:*:*:*:*:*:*:*",
361553          "purl": "pkg:npm/get-stream@4.1.0",
361554          "swid": {
361555            "attachment": {}
361556          },
361557          "pedigree": {},
361558          "externalReferences": [
361559            {
361560              "url": "git+https://github.com/sindresorhus/get-stream.git",
361561              "type": "distribution"
361562            },
361563            {
361564              "url": "https://github.com/sindresorhus/get-stream#readme",
361565              "type": "website"
361566            }
361567          ],
361568          "evidence": {},
361569          "signature": {
361570            "signature": {
361571              "publicKey": {}
361572            }
361573          },
361574          "modelCard": {
361575            "modelParameters": {
361576              "approach": {}
361577            },
361578            "quantitativeAnalysis": {
361579              "graphics": {}
361580            },
361581            "considerations": {}
361582          }
361583        },
361584        {
361585          "type": "library",
361586          "bom-ref": "pkg:npm/getpass@0.1.7?package-id=784c884394bb087a",
361587          "supplier": {},
361588          "author": "Alex Wilson \u003calex.wilson@joyent.com\u003e",
361589          "name": "getpass",
361590          "version": "0.1.7",
361591          "description": "getpass for node.js",
361592          "licenses": [
361593            {
361594              "license": {
361595                "id": "MIT"
361596              }
361597            }
361598          ],
361599          "cpe": "cpe:2.3:a:arekinath:getpass:0.1.7:*:*:*:*:*:*:*",
361600          "purl": "pkg:npm/getpass@0.1.7",
361601          "swid": {
361602            "attachment": {}
361603          },
361604          "pedigree": {},
361605          "externalReferences": [
361606            {
361607              "url": "git+https://github.com/arekinath/node-getpass.git",
361608              "type": "distribution"
361609            },
361610            {
361611              "url": "https://github.com/arekinath/node-getpass#readme",
361612              "type": "website"
361613            }
361614          ],
361615          "evidence": {},
361616          "signature": {
361617            "signature": {
361618              "publicKey": {}
361619            }
361620          },
361621          "modelCard": {
361622            "modelParameters": {
361623              "approach": {}
361624            },
361625            "quantitativeAnalysis": {
361626              "graphics": {}
361627            },
361628            "considerations": {}
361629          }
361630        },
361631        {
361632          "type": "library",
361633          "bom-ref": "pkg:npm/getpass@0.1.7?package-id=25b6b9755ea147b4",
361634          "supplier": {},
361635          "author": "Alex Wilson \u003calex.wilson@joyent.com\u003e",
361636          "name": "getpass",
361637          "version": "0.1.7",
361638          "description": "getpass for node.js",
361639          "licenses": [
361640            {
361641              "license": {
361642                "id": "MIT"
361643              }
361644            }
361645          ],
361646          "cpe": "cpe:2.3:a:arekinath:getpass:0.1.7:*:*:*:*:*:*:*",
361647          "purl": "pkg:npm/getpass@0.1.7",
361648          "swid": {
361649            "attachment": {}
361650          },
361651          "pedigree": {},
361652          "externalReferences": [
361653            {
361654              "url": "git+https://github.com/arekinath/node-getpass.git",
361655              "type": "distribution"
361656            },
361657            {
361658              "url": "https://github.com/arekinath/node-getpass#readme",
361659              "type": "website"
361660            }
361661          ],
361662          "evidence": {},
361663          "signature": {
361664            "signature": {
361665              "publicKey": {}
361666            }
361667          },
361668          "modelCard": {
361669            "modelParameters": {
361670              "approach": {}
361671            },
361672            "quantitativeAnalysis": {
361673              "graphics": {}
361674            },
361675            "considerations": {}
361676          }
361677        },
361678        {
361679          "type": "library",
361680          "bom-ref": "pkg:npm/glob@7.1.7?package-id=5fc600d283c6cdae",
361681          "supplier": {},
361682          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
361683          "name": "glob",
361684          "version": "7.1.7",
361685          "description": "a little globber",
361686          "licenses": [
361687            {
361688              "license": {
361689                "id": "ISC"
361690              }
361691            }
361692          ],
361693          "cpe": "cpe:2.3:a:isaacs:glob:7.1.7:*:*:*:*:*:*:*",
361694          "purl": "pkg:npm/glob@7.1.7",
361695          "swid": {
361696            "attachment": {}
361697          },
361698          "pedigree": {},
361699          "externalReferences": [
361700            {
361701              "url": "git://github.com/isaacs/node-glob.git",
361702              "type": "distribution"
361703            },
361704            {
361705              "url": "https://github.com/isaacs/node-glob#readme",
361706              "type": "website"
361707            }
361708          ],
361709          "evidence": {},
361710          "signature": {
361711            "signature": {
361712              "publicKey": {}
361713            }
361714          },
361715          "modelCard": {
361716            "modelParameters": {
361717              "approach": {}
361718            },
361719            "quantitativeAnalysis": {
361720              "graphics": {}
361721            },
361722            "considerations": {}
361723          }
361724        },
361725        {
361726          "type": "library",
361727          "bom-ref": "pkg:npm/glob@7.2.3?package-id=ea6094df5684c0c2",
361728          "supplier": {},
361729          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
361730          "name": "glob",
361731          "version": "7.2.3",
361732          "description": "a little globber",
361733          "licenses": [
361734            {
361735              "license": {
361736                "id": "ISC"
361737              }
361738            }
361739          ],
361740          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
361741          "purl": "pkg:npm/glob@7.2.3",
361742          "swid": {
361743            "attachment": {}
361744          },
361745          "pedigree": {},
361746          "externalReferences": [
361747            {
361748              "url": "git://github.com/isaacs/node-glob.git",
361749              "type": "distribution"
361750            },
361751            {
361752              "url": "https://github.com/isaacs/node-glob#readme",
361753              "type": "website"
361754            }
361755          ],
361756          "evidence": {},
361757          "signature": {
361758            "signature": {
361759              "publicKey": {}
361760            }
361761          },
361762          "modelCard": {
361763            "modelParameters": {
361764              "approach": {}
361765            },
361766            "quantitativeAnalysis": {
361767              "graphics": {}
361768            },
361769            "considerations": {}
361770          }
361771        },
361772        {
361773          "type": "library",
361774          "bom-ref": "pkg:npm/global-dirs@0.1.1?package-id=a81eae1ffee86ac6",
361775          "supplier": {},
361776          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
361777          "name": "global-dirs",
361778          "version": "0.1.1",
361779          "description": "Get the directory of globally installed packages and binaries",
361780          "licenses": [
361781            {
361782              "license": {
361783                "id": "MIT"
361784              }
361785            }
361786          ],
361787          "cpe": "cpe:2.3:a:sindresorhus:global-dirs:0.1.1:*:*:*:*:*:*:*",
361788          "purl": "pkg:npm/global-dirs@0.1.1",
361789          "swid": {
361790            "attachment": {}
361791          },
361792          "pedigree": {},
361793          "externalReferences": [
361794            {
361795              "url": "git+https://github.com/sindresorhus/global-dirs.git",
361796              "type": "distribution"
361797            },
361798            {
361799              "url": "https://github.com/sindresorhus/global-dirs#readme",
361800              "type": "website"
361801            }
361802          ],
361803          "evidence": {},
361804          "signature": {
361805            "signature": {
361806              "publicKey": {}
361807            }
361808          },
361809          "modelCard": {
361810            "modelParameters": {
361811              "approach": {}
361812            },
361813            "quantitativeAnalysis": {
361814              "graphics": {}
361815            },
361816            "considerations": {}
361817          }
361818        },
361819        {
361820          "type": "library",
361821          "bom-ref": "pkg:npm/globalthis@1.0.2?package-id=825611a4936e82c6",
361822          "supplier": {},
361823          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
361824          "name": "globalthis",
361825          "version": "1.0.2",
361826          "description": "ECMAScript spec-compliant polyfill/shim for `globalThis`",
361827          "licenses": [
361828            {
361829              "license": {
361830                "id": "MIT"
361831              }
361832            }
361833          ],
361834          "cpe": "cpe:2.3:a:globalthis:globalthis:1.0.2:*:*:*:*:*:*:*",
361835          "purl": "pkg:npm/globalthis@1.0.2",
361836          "swid": {
361837            "attachment": {}
361838          },
361839          "pedigree": {},
361840          "externalReferences": [
361841            {
361842              "url": "git://github.com/ljharb/System.global.git",
361843              "type": "distribution"
361844            },
361845            {
361846              "url": "https://github.com/ljharb/System.global#readme",
361847              "type": "website"
361848            }
361849          ],
361850          "evidence": {},
361851          "signature": {
361852            "signature": {
361853              "publicKey": {}
361854            }
361855          },
361856          "modelCard": {
361857            "modelParameters": {
361858              "approach": {}
361859            },
361860            "quantitativeAnalysis": {
361861              "graphics": {}
361862            },
361863            "considerations": {}
361864          }
361865        },
361866        {
361867          "type": "library",
361868          "bom-ref": "pkg:npm/google-libphonenumber@3.2.21?package-id=937f5c110b8ffec0",
361869          "supplier": {},
361870          "author": "Rui Marinho \u003cruipmarinho@gmail.com\u003e",
361871          "name": "google-libphonenumber",
361872          "version": "3.2.21",
361873          "description": "The up-to-date and reliable Google's libphonenumber package for node.js.",
361874          "licenses": [
361875            {
361876              "license": {
361877                "name": "(MIT AND Apache-2.0)"
361878              }
361879            }
361880          ],
361881          "cpe": "cpe:2.3:a:google-libphonenumber:google-libphonenumber:3.2.21:*:*:*:*:*:*:*",
361882          "purl": "pkg:npm/google-libphonenumber@3.2.21",
361883          "swid": {
361884            "attachment": {}
361885          },
361886          "pedigree": {},
361887          "externalReferences": [
361888            {
361889              "url": "git+https://github.com/ruimarinho/google-libphonenumber.git",
361890              "type": "distribution"
361891            },
361892            {
361893              "url": "https://ruimarinho.github.io/google-libphonenumber/",
361894              "type": "website"
361895            }
361896          ],
361897          "evidence": {},
361898          "signature": {
361899            "signature": {
361900              "publicKey": {}
361901            }
361902          },
361903          "modelCard": {
361904            "modelParameters": {
361905              "approach": {}
361906            },
361907            "quantitativeAnalysis": {
361908              "graphics": {}
361909            },
361910            "considerations": {}
361911          }
361912        },
361913        {
361914          "type": "library",
361915          "bom-ref": "pkg:npm/got@6.7.1?package-id=ab6c4d5a78007334",
361916          "supplier": {},
361917          "name": "got",
361918          "version": "6.7.1",
361919          "description": "Simplified HTTP requests",
361920          "licenses": [
361921            {
361922              "license": {
361923                "id": "MIT"
361924              }
361925            }
361926          ],
361927          "cpe": "cpe:2.3:a:sindresorhus:got:6.7.1:*:*:*:*:*:*:*",
361928          "purl": "pkg:npm/got@6.7.1",
361929          "swid": {
361930            "attachment": {}
361931          },
361932          "pedigree": {},
361933          "externalReferences": [
361934            {
361935              "url": "git+https://github.com/sindresorhus/got.git",
361936              "type": "distribution"
361937            },
361938            {
361939              "url": "https://github.com/sindresorhus/got#readme",
361940              "type": "website"
361941            }
361942          ],
361943          "evidence": {},
361944          "signature": {
361945            "signature": {
361946              "publicKey": {}
361947            }
361948          },
361949          "modelCard": {
361950            "modelParameters": {
361951              "approach": {}
361952            },
361953            "quantitativeAnalysis": {
361954              "graphics": {}
361955            },
361956            "considerations": {}
361957          }
361958        },
361959        {
361960          "type": "library",
361961          "bom-ref": "pkg:npm/graceful-fs@4.2.10?package-id=8d7d97b42a53b928",
361962          "supplier": {},
361963          "name": "graceful-fs",
361964          "version": "4.2.10",
361965          "description": "A drop-in replacement for fs, making various improvements.",
361966          "licenses": [
361967            {
361968              "license": {
361969                "id": "ISC"
361970              }
361971            }
361972          ],
361973          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.10:*:*:*:*:*:*:*",
361974          "purl": "pkg:npm/graceful-fs@4.2.10",
361975          "swid": {
361976            "attachment": {}
361977          },
361978          "pedigree": {},
361979          "externalReferences": [
361980            {
361981              "url": "git+https://github.com/isaacs/node-graceful-fs.git",
361982              "type": "distribution"
361983            },
361984            {
361985              "url": "https://github.com/isaacs/node-graceful-fs#readme",
361986              "type": "website"
361987            }
361988          ],
361989          "evidence": {},
361990          "signature": {
361991            "signature": {
361992              "publicKey": {}
361993            }
361994          },
361995          "modelCard": {
361996            "modelParameters": {
361997              "approach": {}
361998            },
361999            "quantitativeAnalysis": {
362000              "graphics": {}
362001            },
362002            "considerations": {}
362003          }
362004        },
362005        {
362006          "type": "library",
362007          "bom-ref": "pkg:npm/har-schema@2.0.0?package-id=7234725dbed89a88",
362008          "supplier": {},
362009          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
362010          "name": "har-schema",
362011          "version": "2.0.0",
362012          "description": "JSON Schema for HTTP Archive (HAR)",
362013          "licenses": [
362014            {
362015              "license": {
362016                "id": "ISC"
362017              }
362018            }
362019          ],
362020          "cpe": "cpe:2.3:a:ahmadnassri:har-schema:2.0.0:*:*:*:*:*:*:*",
362021          "purl": "pkg:npm/har-schema@2.0.0",
362022          "swid": {
362023            "attachment": {}
362024          },
362025          "pedigree": {},
362026          "externalReferences": [
362027            {
362028              "url": "git+https://github.com/ahmadnassri/har-schema.git",
362029              "type": "distribution"
362030            },
362031            {
362032              "url": "https://github.com/ahmadnassri/har-schema",
362033              "type": "website"
362034            }
362035          ],
362036          "evidence": {},
362037          "signature": {
362038            "signature": {
362039              "publicKey": {}
362040            }
362041          },
362042          "modelCard": {
362043            "modelParameters": {
362044              "approach": {}
362045            },
362046            "quantitativeAnalysis": {
362047              "graphics": {}
362048            },
362049            "considerations": {}
362050          }
362051        },
362052        {
362053          "type": "library",
362054          "bom-ref": "pkg:npm/har-schema@2.0.0?package-id=df1ab60f5188f58f",
362055          "supplier": {},
362056          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
362057          "name": "har-schema",
362058          "version": "2.0.0",
362059          "description": "JSON Schema for HTTP Archive (HAR)",
362060          "licenses": [
362061            {
362062              "license": {
362063                "id": "ISC"
362064              }
362065            }
362066          ],
362067          "cpe": "cpe:2.3:a:ahmadnassri:har-schema:2.0.0:*:*:*:*:*:*:*",
362068          "purl": "pkg:npm/har-schema@2.0.0",
362069          "swid": {
362070            "attachment": {}
362071          },
362072          "pedigree": {},
362073          "externalReferences": [
362074            {
362075              "url": "git+https://github.com/ahmadnassri/har-schema.git",
362076              "type": "distribution"
362077            },
362078            {
362079              "url": "https://github.com/ahmadnassri/har-schema",
362080              "type": "website"
362081            }
362082          ],
362083          "evidence": {},
362084          "signature": {
362085            "signature": {
362086              "publicKey": {}
362087            }
362088          },
362089          "modelCard": {
362090            "modelParameters": {
362091              "approach": {}
362092            },
362093            "quantitativeAnalysis": {
362094              "graphics": {}
362095            },
362096            "considerations": {}
362097          }
362098        },
362099        {
362100          "type": "library",
362101          "bom-ref": "pkg:npm/har-validator@5.1.5?package-id=82e75ee6b2a15bbd",
362102          "supplier": {},
362103          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
362104          "name": "har-validator",
362105          "version": "5.1.5",
362106          "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
362107          "licenses": [
362108            {
362109              "license": {
362110                "id": "MIT"
362111              }
362112            }
362113          ],
362114          "cpe": "cpe:2.3:a:har-validator:har-validator:5.1.5:*:*:*:*:*:*:*",
362115          "purl": "pkg:npm/har-validator@5.1.5",
362116          "swid": {
362117            "attachment": {}
362118          },
362119          "pedigree": {},
362120          "externalReferences": [
362121            {
362122              "url": "git+https://github.com/ahmadnassri/node-har-validator.git",
362123              "type": "distribution"
362124            },
362125            {
362126              "url": "https://github.com/ahmadnassri/node-har-validator",
362127              "type": "website"
362128            }
362129          ],
362130          "evidence": {},
362131          "signature": {
362132            "signature": {
362133              "publicKey": {}
362134            }
362135          },
362136          "modelCard": {
362137            "modelParameters": {
362138              "approach": {}
362139            },
362140            "quantitativeAnalysis": {
362141              "graphics": {}
362142            },
362143            "considerations": {}
362144          }
362145        },
362146        {
362147          "type": "library",
362148          "bom-ref": "pkg:npm/har-validator@5.1.5?package-id=9cf5dbba4ee808aa",
362149          "supplier": {},
362150          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
362151          "name": "har-validator",
362152          "version": "5.1.5",
362153          "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
362154          "licenses": [
362155            {
362156              "license": {
362157                "id": "MIT"
362158              }
362159            }
362160          ],
362161          "cpe": "cpe:2.3:a:har-validator:har-validator:5.1.5:*:*:*:*:*:*:*",
362162          "purl": "pkg:npm/har-validator@5.1.5",
362163          "swid": {
362164            "attachment": {}
362165          },
362166          "pedigree": {},
362167          "externalReferences": [
362168            {
362169              "url": "git+https://github.com/ahmadnassri/node-har-validator.git",
362170              "type": "distribution"
362171            },
362172            {
362173              "url": "https://github.com/ahmadnassri/node-har-validator",
362174              "type": "website"
362175            }
362176          ],
362177          "evidence": {},
362178          "signature": {
362179            "signature": {
362180              "publicKey": {}
362181            }
362182          },
362183          "modelCard": {
362184            "modelParameters": {
362185              "approach": {}
362186            },
362187            "quantitativeAnalysis": {
362188              "graphics": {}
362189            },
362190            "considerations": {}
362191          }
362192        },
362193        {
362194          "type": "library",
362195          "bom-ref": "pkg:npm/has@1.0.3?package-id=57072cf8ae347274",
362196          "supplier": {},
362197          "author": "Thiago de Arruda \u003ctpadilha84@gmail.com\u003e",
362198          "name": "has",
362199          "version": "1.0.3",
362200          "description": "Object.prototype.hasOwnProperty.call shortcut",
362201          "licenses": [
362202            {
362203              "license": {
362204                "id": "MIT"
362205              }
362206            }
362207          ],
362208          "cpe": "cpe:2.3:a:tarruda:has:1.0.3:*:*:*:*:*:*:*",
362209          "purl": "pkg:npm/has@1.0.3",
362210          "swid": {
362211            "attachment": {}
362212          },
362213          "pedigree": {},
362214          "externalReferences": [
362215            {
362216              "url": "git://github.com/tarruda/has.git",
362217              "type": "distribution"
362218            },
362219            {
362220              "url": "https://github.com/tarruda/has",
362221              "type": "website"
362222            }
362223          ],
362224          "evidence": {},
362225          "signature": {
362226            "signature": {
362227              "publicKey": {}
362228            }
362229          },
362230          "modelCard": {
362231            "modelParameters": {
362232              "approach": {}
362233            },
362234            "quantitativeAnalysis": {
362235              "graphics": {}
362236            },
362237            "considerations": {}
362238          }
362239        },
362240        {
362241          "type": "library",
362242          "bom-ref": "pkg:npm/has-flag@3.0.0?package-id=d1a82ebb7b8ff26c",
362243          "supplier": {},
362244          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
362245          "name": "has-flag",
362246          "version": "3.0.0",
362247          "description": "Check if argv has a specific flag",
362248          "licenses": [
362249            {
362250              "license": {
362251                "id": "MIT"
362252              }
362253            }
362254          ],
362255          "cpe": "cpe:2.3:a:sindresorhus:has-flag:3.0.0:*:*:*:*:*:*:*",
362256          "purl": "pkg:npm/has-flag@3.0.0",
362257          "swid": {
362258            "attachment": {}
362259          },
362260          "pedigree": {},
362261          "externalReferences": [
362262            {
362263              "url": "git+https://github.com/sindresorhus/has-flag.git",
362264              "type": "distribution"
362265            },
362266            {
362267              "url": "https://github.com/sindresorhus/has-flag#readme",
362268              "type": "website"
362269            }
362270          ],
362271          "evidence": {},
362272          "signature": {
362273            "signature": {
362274              "publicKey": {}
362275            }
362276          },
362277          "modelCard": {
362278            "modelParameters": {
362279              "approach": {}
362280            },
362281            "quantitativeAnalysis": {
362282              "graphics": {}
362283            },
362284            "considerations": {}
362285          }
362286        },
362287        {
362288          "type": "library",
362289          "bom-ref": "pkg:npm/has-flag@4.0.0?package-id=de3b59daaf6d7165",
362290          "supplier": {},
362291          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
362292          "name": "has-flag",
362293          "version": "4.0.0",
362294          "description": "Check if argv has a specific flag",
362295          "licenses": [
362296            {
362297              "license": {
362298                "id": "MIT"
362299              }
362300            }
362301          ],
362302          "cpe": "cpe:2.3:a:sindresorhus:has-flag:4.0.0:*:*:*:*:*:*:*",
362303          "purl": "pkg:npm/has-flag@4.0.0",
362304          "swid": {
362305            "attachment": {}
362306          },
362307          "pedigree": {},
362308          "externalReferences": [
362309            {
362310              "url": "git+https://github.com/sindresorhus/has-flag.git",
362311              "type": "distribution"
362312            },
362313            {
362314              "url": "https://github.com/sindresorhus/has-flag#readme",
362315              "type": "website"
362316            }
362317          ],
362318          "evidence": {},
362319          "signature": {
362320            "signature": {
362321              "publicKey": {}
362322            }
362323          },
362324          "modelCard": {
362325            "modelParameters": {
362326              "approach": {}
362327            },
362328            "quantitativeAnalysis": {
362329              "graphics": {}
362330            },
362331            "considerations": {}
362332          }
362333        },
362334        {
362335          "type": "library",
362336          "bom-ref": "pkg:npm/has-symbols@1.0.0?package-id=9bd065ba951794af",
362337          "supplier": {},
362338          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
362339          "name": "has-symbols",
362340          "version": "1.0.0",
362341          "description": "Determine if the JS environment has Symbol support. Supports spec, or shams.",
362342          "licenses": [
362343            {
362344              "license": {
362345                "id": "MIT"
362346              }
362347            }
362348          ],
362349          "cpe": "cpe:2.3:a:has-symbols:has-symbols:1.0.0:*:*:*:*:*:*:*",
362350          "purl": "pkg:npm/has-symbols@1.0.0",
362351          "swid": {
362352            "attachment": {}
362353          },
362354          "pedigree": {},
362355          "externalReferences": [
362356            {
362357              "url": "git://github.com/ljharb/has-symbols.git",
362358              "type": "distribution"
362359            }
362360          ],
362361          "evidence": {},
362362          "signature": {
362363            "signature": {
362364              "publicKey": {}
362365            }
362366          },
362367          "modelCard": {
362368            "modelParameters": {
362369              "approach": {}
362370            },
362371            "quantitativeAnalysis": {
362372              "graphics": {}
362373            },
362374            "considerations": {}
362375          }
362376        },
362377        {
362378          "type": "library",
362379          "bom-ref": "pkg:npm/has-unicode@2.0.1?package-id=c2a2690b355e1e80",
362380          "supplier": {},
362381          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
362382          "name": "has-unicode",
362383          "version": "2.0.1",
362384          "description": "Try to guess if your terminal supports unicode",
362385          "licenses": [
362386            {
362387              "license": {
362388                "id": "ISC"
362389              }
362390            }
362391          ],
362392          "cpe": "cpe:2.3:a:has-unicode:has-unicode:2.0.1:*:*:*:*:*:*:*",
362393          "purl": "pkg:npm/has-unicode@2.0.1",
362394          "swid": {
362395            "attachment": {}
362396          },
362397          "pedigree": {},
362398          "externalReferences": [
362399            {
362400              "url": "git+https://github.com/iarna/has-unicode.git",
362401              "type": "distribution"
362402            },
362403            {
362404              "url": "https://github.com/iarna/has-unicode",
362405              "type": "website"
362406            }
362407          ],
362408          "evidence": {},
362409          "signature": {
362410            "signature": {
362411              "publicKey": {}
362412            }
362413          },
362414          "modelCard": {
362415            "modelParameters": {
362416              "approach": {}
362417            },
362418            "quantitativeAnalysis": {
362419              "graphics": {}
362420            },
362421            "considerations": {}
362422          }
362423        },
362424        {
362425          "type": "library",
362426          "bom-ref": "pkg:npm/hosted-git-info@2.8.9?package-id=d8c63249d170a0bb",
362427          "supplier": {},
362428          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org)",
362429          "name": "hosted-git-info",
362430          "version": "2.8.9",
362431          "description": "Provides metadata and conversions from repository urls for Github, Bitbucket and Gitlab",
362432          "licenses": [
362433            {
362434              "license": {
362435                "id": "ISC"
362436              }
362437            }
362438          ],
362439          "cpe": "cpe:2.3:a:hosted-git-info:hosted-git-info:2.8.9:*:*:*:*:*:*:*",
362440          "purl": "pkg:npm/hosted-git-info@2.8.9",
362441          "swid": {
362442            "attachment": {}
362443          },
362444          "pedigree": {},
362445          "externalReferences": [
362446            {
362447              "url": "git+https://github.com/npm/hosted-git-info.git",
362448              "type": "distribution"
362449            },
362450            {
362451              "url": "https://github.com/npm/hosted-git-info",
362452              "type": "website"
362453            }
362454          ],
362455          "evidence": {},
362456          "signature": {
362457            "signature": {
362458              "publicKey": {}
362459            }
362460          },
362461          "modelCard": {
362462            "modelParameters": {
362463              "approach": {}
362464            },
362465            "quantitativeAnalysis": {
362466              "graphics": {}
362467            },
362468            "considerations": {}
362469          }
362470        },
362471        {
362472          "type": "library",
362473          "bom-ref": "pkg:npm/http-cache-semantics@3.8.1?package-id=be50af68f0bf4318",
362474          "supplier": {},
362475          "author": "Kornel Lesiński \u003ckornel@geekhood.net\u003e (https://kornel.ski/)",
362476          "name": "http-cache-semantics",
362477          "version": "3.8.1",
362478          "description": "Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies",
362479          "licenses": [
362480            {
362481              "license": {
362482                "id": "BSD-2-Clause"
362483              }
362484            }
362485          ],
362486          "cpe": "cpe:2.3:a:http-cache-semantics:http-cache-semantics:3.8.1:*:*:*:*:*:*:*",
362487          "purl": "pkg:npm/http-cache-semantics@3.8.1",
362488          "swid": {
362489            "attachment": {}
362490          },
362491          "pedigree": {},
362492          "externalReferences": [
362493            {
362494              "url": "git+https://github.com/pornel/http-cache-semantics.git",
362495              "type": "distribution"
362496            },
362497            {
362498              "url": "https://github.com/pornel/http-cache-semantics#readme",
362499              "type": "website"
362500            }
362501          ],
362502          "evidence": {},
362503          "signature": {
362504            "signature": {
362505              "publicKey": {}
362506            }
362507          },
362508          "modelCard": {
362509            "modelParameters": {
362510              "approach": {}
362511            },
362512            "quantitativeAnalysis": {
362513              "graphics": {}
362514            },
362515            "considerations": {}
362516          }
362517        },
362518        {
362519          "type": "library",
362520          "bom-ref": "pkg:npm/http-errors@1.7.2?package-id=caf9fdc642308a1c",
362521          "supplier": {},
362522          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
362523          "name": "http-errors",
362524          "version": "1.7.2",
362525          "description": "Create HTTP error objects",
362526          "licenses": [
362527            {
362528              "license": {
362529                "id": "MIT"
362530              }
362531            }
362532          ],
362533          "cpe": "cpe:2.3:a:http-errors:http-errors:1.7.2:*:*:*:*:*:*:*",
362534          "purl": "pkg:npm/http-errors@1.7.2",
362535          "swid": {
362536            "attachment": {}
362537          },
362538          "pedigree": {},
362539          "externalReferences": [
362540            {
362541              "url": "git+https://github.com/jshttp/http-errors.git",
362542              "type": "distribution"
362543            },
362544            {
362545              "url": "https://github.com/jshttp/http-errors#readme",
362546              "type": "website"
362547            }
362548          ],
362549          "evidence": {},
362550          "signature": {
362551            "signature": {
362552              "publicKey": {}
362553            }
362554          },
362555          "modelCard": {
362556            "modelParameters": {
362557              "approach": {}
362558            },
362559            "quantitativeAnalysis": {
362560              "graphics": {}
362561            },
362562            "considerations": {}
362563          }
362564        },
362565        {
362566          "type": "library",
362567          "bom-ref": "pkg:npm/http-proxy-agent@2.1.0?package-id=f58ccb0049d952d2",
362568          "supplier": {},
362569          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
362570          "name": "http-proxy-agent",
362571          "version": "2.1.0",
362572          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTP",
362573          "licenses": [
362574            {
362575              "license": {
362576                "id": "MIT"
362577              }
362578            }
362579          ],
362580          "cpe": "cpe:2.3:a:http-proxy-agent:http-proxy-agent:2.1.0:*:*:*:*:*:*:*",
362581          "purl": "pkg:npm/http-proxy-agent@2.1.0",
362582          "swid": {
362583            "attachment": {}
362584          },
362585          "pedigree": {},
362586          "externalReferences": [
362587            {
362588              "url": "git://github.com/TooTallNate/node-http-proxy-agent.git",
362589              "type": "distribution"
362590            },
362591            {
362592              "url": "https://github.com/TooTallNate/node-http-proxy-agent#readme",
362593              "type": "website"
362594            }
362595          ],
362596          "evidence": {},
362597          "signature": {
362598            "signature": {
362599              "publicKey": {}
362600            }
362601          },
362602          "modelCard": {
362603            "modelParameters": {
362604              "approach": {}
362605            },
362606            "quantitativeAnalysis": {
362607              "graphics": {}
362608            },
362609            "considerations": {}
362610          }
362611        },
362612        {
362613          "type": "library",
362614          "bom-ref": "pkg:npm/http-signature@1.2.0?package-id=9a991d3938b7d038",
362615          "supplier": {},
362616          "author": "Joyent, Inc",
362617          "name": "http-signature",
362618          "version": "1.2.0",
362619          "description": "Reference implementation of Joyent's HTTP Signature scheme.",
362620          "licenses": [
362621            {
362622              "license": {
362623                "id": "MIT"
362624              }
362625            }
362626          ],
362627          "cpe": "cpe:2.3:a:http-signature:http-signature:1.2.0:*:*:*:*:*:*:*",
362628          "purl": "pkg:npm/http-signature@1.2.0",
362629          "swid": {
362630            "attachment": {}
362631          },
362632          "pedigree": {},
362633          "externalReferences": [
362634            {
362635              "url": "git://github.com/joyent/node-http-signature.git",
362636              "type": "distribution"
362637            },
362638            {
362639              "url": "https://github.com/joyent/node-http-signature/",
362640              "type": "website"
362641            }
362642          ],
362643          "evidence": {},
362644          "signature": {
362645            "signature": {
362646              "publicKey": {}
362647            }
362648          },
362649          "modelCard": {
362650            "modelParameters": {
362651              "approach": {}
362652            },
362653            "quantitativeAnalysis": {
362654              "graphics": {}
362655            },
362656            "considerations": {}
362657          }
362658        },
362659        {
362660          "type": "library",
362661          "bom-ref": "pkg:npm/http-signature@1.2.0?package-id=ec4c21581261e6af",
362662          "supplier": {},
362663          "author": "Joyent, Inc",
362664          "name": "http-signature",
362665          "version": "1.2.0",
362666          "description": "Reference implementation of Joyent's HTTP Signature scheme.",
362667          "licenses": [
362668            {
362669              "license": {
362670                "id": "MIT"
362671              }
362672            }
362673          ],
362674          "cpe": "cpe:2.3:a:http-signature:http-signature:1.2.0:*:*:*:*:*:*:*",
362675          "purl": "pkg:npm/http-signature@1.2.0",
362676          "swid": {
362677            "attachment": {}
362678          },
362679          "pedigree": {},
362680          "externalReferences": [
362681            {
362682              "url": "git://github.com/joyent/node-http-signature.git",
362683              "type": "distribution"
362684            },
362685            {
362686              "url": "https://github.com/joyent/node-http-signature/",
362687              "type": "website"
362688            }
362689          ],
362690          "evidence": {},
362691          "signature": {
362692            "signature": {
362693              "publicKey": {}
362694            }
362695          },
362696          "modelCard": {
362697            "modelParameters": {
362698              "approach": {}
362699            },
362700            "quantitativeAnalysis": {
362701              "graphics": {}
362702            },
362703            "considerations": {}
362704          }
362705        },
362706        {
362707          "type": "library",
362708          "bom-ref": "pkg:npm/http-status-codes@2.1.4?package-id=e81fc481d00d8b1b",
362709          "supplier": {},
362710          "author": "Bryce Neal",
362711          "name": "http-status-codes",
362712          "version": "2.1.4",
362713          "description": "Constants enumerating the HTTP status codes. Based on the Java Apache HttpStatus API.",
362714          "licenses": [
362715            {
362716              "license": {
362717                "id": "MIT"
362718              }
362719            }
362720          ],
362721          "cpe": "cpe:2.3:a:http-status-codes:http-status-codes:2.1.4:*:*:*:*:*:*:*",
362722          "purl": "pkg:npm/http-status-codes@2.1.4",
362723          "swid": {
362724            "attachment": {}
362725          },
362726          "pedigree": {},
362727          "externalReferences": [
362728            {
362729              "url": "git+https://github.com/prettymuchbryce/node-http-status.git",
362730              "type": "distribution"
362731            },
362732            {
362733              "url": "https://github.com/prettymuchbryce/node-http-status#readme",
362734              "type": "website"
362735            }
362736          ],
362737          "evidence": {},
362738          "signature": {
362739            "signature": {
362740              "publicKey": {}
362741            }
362742          },
362743          "modelCard": {
362744            "modelParameters": {
362745              "approach": {}
362746            },
362747            "quantitativeAnalysis": {
362748              "graphics": {}
362749            },
362750            "considerations": {}
362751          }
362752        },
362753        {
362754          "type": "library",
362755          "bom-ref": "pkg:npm/http-terminator@3.0.0?package-id=5ff94849b2033551",
362756          "supplier": {},
362757          "author": "Gajus Kuizinas \u003cgajus@gajus.com\u003e (http://gajus.com)",
362758          "name": "http-terminator",
362759          "version": "3.0.0",
362760          "description": "Gracefully terminates HTTP(S) server.",
362761          "licenses": [
362762            {
362763              "license": {
362764                "id": "BSD-3-Clause"
362765              }
362766            }
362767          ],
362768          "cpe": "cpe:2.3:a:http-terminator:http-terminator:3.0.0:*:*:*:*:*:*:*",
362769          "purl": "pkg:npm/http-terminator@3.0.0",
362770          "swid": {
362771            "attachment": {}
362772          },
362773          "pedigree": {},
362774          "externalReferences": [
362775            {
362776              "url": "git+https://github.com/gajus/http-terminator.git",
362777              "type": "distribution"
362778            },
362779            {
362780              "url": "https://github.com/gajus/http-terminator#readme",
362781              "type": "website"
362782            }
362783          ],
362784          "evidence": {},
362785          "signature": {
362786            "signature": {
362787              "publicKey": {}
362788            }
362789          },
362790          "modelCard": {
362791            "modelParameters": {
362792              "approach": {}
362793            },
362794            "quantitativeAnalysis": {
362795              "graphics": {}
362796            },
362797            "considerations": {}
362798          }
362799        },
362800        {
362801          "type": "library",
362802          "bom-ref": "pkg:npm/https-proxy-agent@2.2.4?package-id=3865d5b676fac485",
362803          "supplier": {},
362804          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
362805          "name": "https-proxy-agent",
362806          "version": "2.2.4",
362807          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
362808          "licenses": [
362809            {
362810              "license": {
362811                "id": "MIT"
362812              }
362813            }
362814          ],
362815          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:2.2.4:*:*:*:*:*:*:*",
362816          "purl": "pkg:npm/https-proxy-agent@2.2.4",
362817          "swid": {
362818            "attachment": {}
362819          },
362820          "pedigree": {},
362821          "externalReferences": [
362822            {
362823              "url": "git://github.com/TooTallNate/node-https-proxy-agent.git",
362824              "type": "distribution"
362825            },
362826            {
362827              "url": "https://github.com/TooTallNate/node-https-proxy-agent#readme",
362828              "type": "website"
362829            }
362830          ],
362831          "evidence": {},
362832          "signature": {
362833            "signature": {
362834              "publicKey": {}
362835            }
362836          },
362837          "modelCard": {
362838            "modelParameters": {
362839              "approach": {}
362840            },
362841            "quantitativeAnalysis": {
362842              "graphics": {}
362843            },
362844            "considerations": {}
362845          }
362846        },
362847        {
362848          "type": "library",
362849          "bom-ref": "pkg:npm/https-proxy-agent@5.0.0?package-id=7e73792ebc0ee608",
362850          "supplier": {},
362851          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
362852          "name": "https-proxy-agent",
362853          "version": "5.0.0",
362854          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
362855          "licenses": [
362856            {
362857              "license": {
362858                "id": "MIT"
362859              }
362860            }
362861          ],
362862          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:5.0.0:*:*:*:*:*:*:*",
362863          "purl": "pkg:npm/https-proxy-agent@5.0.0",
362864          "swid": {
362865            "attachment": {}
362866          },
362867          "pedigree": {},
362868          "externalReferences": [
362869            {
362870              "url": "git://github.com/TooTallNate/node-https-proxy-agent.git",
362871              "type": "distribution"
362872            },
362873            {
362874              "url": "https://github.com/TooTallNate/node-https-proxy-agent#readme",
362875              "type": "website"
362876            }
362877          ],
362878          "evidence": {},
362879          "signature": {
362880            "signature": {
362881              "publicKey": {}
362882            }
362883          },
362884          "modelCard": {
362885            "modelParameters": {
362886              "approach": {}
362887            },
362888            "quantitativeAnalysis": {
362889              "graphics": {}
362890            },
362891            "considerations": {}
362892          }
362893        },
362894        {
362895          "type": "library",
362896          "bom-ref": "pkg:npm/humanize-ms@1.2.1?package-id=6269f846c887d763",
362897          "supplier": {},
362898          "author": "dead-horse \u003cdead_horse@qq.com\u003e (http://deadhorse.me)",
362899          "name": "humanize-ms",
362900          "version": "1.2.1",
362901          "description": "transform humanize time to ms",
362902          "licenses": [
362903            {
362904              "license": {
362905                "id": "MIT"
362906              }
362907            }
362908          ],
362909          "cpe": "cpe:2.3:a:node-modules:humanize-ms:1.2.1:*:*:*:*:*:*:*",
362910          "purl": "pkg:npm/humanize-ms@1.2.1",
362911          "swid": {
362912            "attachment": {}
362913          },
362914          "pedigree": {},
362915          "externalReferences": [
362916            {
362917              "url": "git+https://github.com/node-modules/humanize-ms.git",
362918              "type": "distribution"
362919            },
362920            {
362921              "url": "https://github.com/node-modules/humanize-ms#readme",
362922              "type": "website"
362923            }
362924          ],
362925          "evidence": {},
362926          "signature": {
362927            "signature": {
362928              "publicKey": {}
362929            }
362930          },
362931          "modelCard": {
362932            "modelParameters": {
362933              "approach": {}
362934            },
362935            "quantitativeAnalysis": {
362936              "graphics": {}
362937            },
362938            "considerations": {}
362939          }
362940        },
362941        {
362942          "type": "library",
362943          "bom-ref": "pkg:npm/iconv-lite@0.4.23?package-id=72aa978f928b8369",
362944          "supplier": {},
362945          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
362946          "name": "iconv-lite",
362947          "version": "0.4.23",
362948          "description": "Convert character encodings in pure javascript.",
362949          "licenses": [
362950            {
362951              "license": {
362952                "id": "MIT"
362953              }
362954            }
362955          ],
362956          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.4.23:*:*:*:*:*:*:*",
362957          "purl": "pkg:npm/iconv-lite@0.4.23",
362958          "swid": {
362959            "attachment": {}
362960          },
362961          "pedigree": {},
362962          "externalReferences": [
362963            {
362964              "url": "git://github.com/ashtuchkin/iconv-lite.git",
362965              "type": "distribution"
362966            },
362967            {
362968              "url": "https://github.com/ashtuchkin/iconv-lite",
362969              "type": "website"
362970            }
362971          ],
362972          "evidence": {},
362973          "signature": {
362974            "signature": {
362975              "publicKey": {}
362976            }
362977          },
362978          "modelCard": {
362979            "modelParameters": {
362980              "approach": {}
362981            },
362982            "quantitativeAnalysis": {
362983              "graphics": {}
362984            },
362985            "considerations": {}
362986          }
362987        },
362988        {
362989          "type": "library",
362990          "bom-ref": "pkg:npm/iconv-lite@0.4.24?package-id=5b9a586d4ff6589f",
362991          "supplier": {},
362992          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
362993          "name": "iconv-lite",
362994          "version": "0.4.24",
362995          "description": "Convert character encodings in pure javascript.",
362996          "licenses": [
362997            {
362998              "license": {
362999                "id": "MIT"
363000              }
363001            }
363002          ],
363003          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.4.24:*:*:*:*:*:*:*",
363004          "purl": "pkg:npm/iconv-lite@0.4.24",
363005          "swid": {
363006            "attachment": {}
363007          },
363008          "pedigree": {},
363009          "externalReferences": [
363010            {
363011              "url": "git://github.com/ashtuchkin/iconv-lite.git",
363012              "type": "distribution"
363013            },
363014            {
363015              "url": "https://github.com/ashtuchkin/iconv-lite",
363016              "type": "website"
363017            }
363018          ],
363019          "evidence": {},
363020          "signature": {
363021            "signature": {
363022              "publicKey": {}
363023            }
363024          },
363025          "modelCard": {
363026            "modelParameters": {
363027              "approach": {}
363028            },
363029            "quantitativeAnalysis": {
363030              "graphics": {}
363031            },
363032            "considerations": {}
363033          }
363034        },
363035        {
363036          "type": "library",
363037          "bom-ref": "pkg:npm/iferr@0.1.5?package-id=240c8b7b718f7cca",
363038          "supplier": {},
363039          "author": "Nadav Ivgi",
363040          "name": "iferr",
363041          "version": "0.1.5",
363042          "description": "Higher-order functions for easier error handling",
363043          "licenses": [
363044            {
363045              "license": {
363046                "id": "MIT"
363047              }
363048            }
363049          ],
363050          "cpe": "cpe:2.3:a:shesek:iferr:0.1.5:*:*:*:*:*:*:*",
363051          "purl": "pkg:npm/iferr@0.1.5",
363052          "swid": {
363053            "attachment": {}
363054          },
363055          "pedigree": {},
363056          "externalReferences": [
363057            {
363058              "url": "git+https://github.com/shesek/iferr.git",
363059              "type": "distribution"
363060            },
363061            {
363062              "url": "https://github.com/shesek/iferr",
363063              "type": "website"
363064            }
363065          ],
363066          "evidence": {},
363067          "signature": {
363068            "signature": {
363069              "publicKey": {}
363070            }
363071          },
363072          "modelCard": {
363073            "modelParameters": {
363074              "approach": {}
363075            },
363076            "quantitativeAnalysis": {
363077              "graphics": {}
363078            },
363079            "considerations": {}
363080          }
363081        },
363082        {
363083          "type": "library",
363084          "bom-ref": "pkg:npm/iferr@0.1.5?package-id=78ea6eb1d1172c78",
363085          "supplier": {},
363086          "author": "Nadav Ivgi",
363087          "name": "iferr",
363088          "version": "0.1.5",
363089          "description": "Higher-order functions for easier error handling",
363090          "licenses": [
363091            {
363092              "license": {
363093                "id": "MIT"
363094              }
363095            }
363096          ],
363097          "cpe": "cpe:2.3:a:shesek:iferr:0.1.5:*:*:*:*:*:*:*",
363098          "purl": "pkg:npm/iferr@0.1.5",
363099          "swid": {
363100            "attachment": {}
363101          },
363102          "pedigree": {},
363103          "externalReferences": [
363104            {
363105              "url": "git+https://github.com/shesek/iferr.git",
363106              "type": "distribution"
363107            },
363108            {
363109              "url": "https://github.com/shesek/iferr",
363110              "type": "website"
363111            }
363112          ],
363113          "evidence": {},
363114          "signature": {
363115            "signature": {
363116              "publicKey": {}
363117            }
363118          },
363119          "modelCard": {
363120            "modelParameters": {
363121              "approach": {}
363122            },
363123            "quantitativeAnalysis": {
363124              "graphics": {}
363125            },
363126            "considerations": {}
363127          }
363128        },
363129        {
363130          "type": "library",
363131          "bom-ref": "pkg:npm/iferr@0.1.5?package-id=394fba8c06946b1c",
363132          "supplier": {},
363133          "author": "Nadav Ivgi",
363134          "name": "iferr",
363135          "version": "0.1.5",
363136          "description": "Higher-order functions for easier error handling",
363137          "licenses": [
363138            {
363139              "license": {
363140                "id": "MIT"
363141              }
363142            }
363143          ],
363144          "cpe": "cpe:2.3:a:shesek:iferr:0.1.5:*:*:*:*:*:*:*",
363145          "purl": "pkg:npm/iferr@0.1.5",
363146          "swid": {
363147            "attachment": {}
363148          },
363149          "pedigree": {},
363150          "externalReferences": [
363151            {
363152              "url": "git+https://github.com/shesek/iferr.git",
363153              "type": "distribution"
363154            },
363155            {
363156              "url": "https://github.com/shesek/iferr",
363157              "type": "website"
363158            }
363159          ],
363160          "evidence": {},
363161          "signature": {
363162            "signature": {
363163              "publicKey": {}
363164            }
363165          },
363166          "modelCard": {
363167            "modelParameters": {
363168              "approach": {}
363169            },
363170            "quantitativeAnalysis": {
363171              "graphics": {}
363172            },
363173            "considerations": {}
363174          }
363175        },
363176        {
363177          "type": "library",
363178          "bom-ref": "pkg:npm/iferr@1.0.2?package-id=23983836ee47095c",
363179          "supplier": {},
363180          "author": "Nadav Ivgi",
363181          "name": "iferr",
363182          "version": "1.0.2",
363183          "description": "Higher-order functions for easier error handling",
363184          "licenses": [
363185            {
363186              "license": {
363187                "id": "MIT"
363188              }
363189            }
363190          ],
363191          "cpe": "cpe:2.3:a:shesek:iferr:1.0.2:*:*:*:*:*:*:*",
363192          "purl": "pkg:npm/iferr@1.0.2",
363193          "swid": {
363194            "attachment": {}
363195          },
363196          "pedigree": {},
363197          "externalReferences": [
363198            {
363199              "url": "git+https://github.com/shesek/iferr.git",
363200              "type": "distribution"
363201            },
363202            {
363203              "url": "https://github.com/shesek/iferr",
363204              "type": "website"
363205            }
363206          ],
363207          "evidence": {},
363208          "signature": {
363209            "signature": {
363210              "publicKey": {}
363211            }
363212          },
363213          "modelCard": {
363214            "modelParameters": {
363215              "approach": {}
363216            },
363217            "quantitativeAnalysis": {
363218              "graphics": {}
363219            },
363220            "considerations": {}
363221          }
363222        },
363223        {
363224          "type": "library",
363225          "bom-ref": "pkg:npm/ignore-walk@3.0.3?package-id=4b3b7cbce830d44b",
363226          "supplier": {},
363227          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
363228          "name": "ignore-walk",
363229          "version": "3.0.3",
363230          "description": "Nested/recursive `.gitignore`/`.npmignore` parsing and filtering.",
363231          "licenses": [
363232            {
363233              "license": {
363234                "id": "ISC"
363235              }
363236            }
363237          ],
363238          "cpe": "cpe:2.3:a:ignore-walk:ignore-walk:3.0.3:*:*:*:*:*:*:*",
363239          "purl": "pkg:npm/ignore-walk@3.0.3",
363240          "swid": {
363241            "attachment": {}
363242          },
363243          "pedigree": {},
363244          "externalReferences": [
363245            {
363246              "url": "git+https://github.com/isaacs/ignore-walk.git",
363247              "type": "distribution"
363248            },
363249            {
363250              "url": "https://github.com/isaacs/ignore-walk#readme",
363251              "type": "website"
363252            }
363253          ],
363254          "evidence": {},
363255          "signature": {
363256            "signature": {
363257              "publicKey": {}
363258            }
363259          },
363260          "modelCard": {
363261            "modelParameters": {
363262              "approach": {}
363263            },
363264            "quantitativeAnalysis": {
363265              "graphics": {}
363266            },
363267            "considerations": {}
363268          }
363269        },
363270        {
363271          "type": "library",
363272          "bom-ref": "pkg:npm/import-lazy@2.1.0?package-id=af14ea31551b29b",
363273          "supplier": {},
363274          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
363275          "name": "import-lazy",
363276          "version": "2.1.0",
363277          "description": "Import modules lazily",
363278          "licenses": [
363279            {
363280              "license": {
363281                "id": "MIT"
363282              }
363283            }
363284          ],
363285          "cpe": "cpe:2.3:a:sindresorhus:import-lazy:2.1.0:*:*:*:*:*:*:*",
363286          "purl": "pkg:npm/import-lazy@2.1.0",
363287          "swid": {
363288            "attachment": {}
363289          },
363290          "pedigree": {},
363291          "externalReferences": [
363292            {
363293              "url": "git+https://github.com/sindresorhus/import-lazy.git",
363294              "type": "distribution"
363295            },
363296            {
363297              "url": "https://github.com/sindresorhus/import-lazy#readme",
363298              "type": "website"
363299            }
363300          ],
363301          "evidence": {},
363302          "signature": {
363303            "signature": {
363304              "publicKey": {}
363305            }
363306          },
363307          "modelCard": {
363308            "modelParameters": {
363309              "approach": {}
363310            },
363311            "quantitativeAnalysis": {
363312              "graphics": {}
363313            },
363314            "considerations": {}
363315          }
363316        },
363317        {
363318          "type": "library",
363319          "bom-ref": "pkg:npm/imurmurhash@0.1.4?package-id=209f0ed2459f2a66",
363320          "supplier": {},
363321          "author": "Jens Taylor \u003cjensyt@gmail.com\u003e (https://github.com/homebrewing)",
363322          "name": "imurmurhash",
363323          "version": "0.1.4",
363324          "description": "An incremental implementation of MurmurHash3",
363325          "licenses": [
363326            {
363327              "license": {
363328                "id": "MIT"
363329              }
363330            }
363331          ],
363332          "cpe": "cpe:2.3:a:imurmurhash:imurmurhash:0.1.4:*:*:*:*:*:*:*",
363333          "purl": "pkg:npm/imurmurhash@0.1.4",
363334          "swid": {
363335            "attachment": {}
363336          },
363337          "pedigree": {},
363338          "externalReferences": [
363339            {
363340              "url": "git+https://github.com/jensyt/imurmurhash-js.git",
363341              "type": "distribution"
363342            },
363343            {
363344              "url": "https://github.com/jensyt/imurmurhash-js",
363345              "type": "website"
363346            }
363347          ],
363348          "evidence": {},
363349          "signature": {
363350            "signature": {
363351              "publicKey": {}
363352            }
363353          },
363354          "modelCard": {
363355            "modelParameters": {
363356              "approach": {}
363357            },
363358            "quantitativeAnalysis": {
363359              "graphics": {}
363360            },
363361            "considerations": {}
363362          }
363363        },
363364        {
363365          "type": "library",
363366          "bom-ref": "pkg:npm/infer-owner@1.0.4?package-id=ff8bebe3c92e29be",
363367          "supplier": {},
363368          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
363369          "name": "infer-owner",
363370          "version": "1.0.4",
363371          "description": "Infer the owner of a path based on the owner of its nearest existing parent",
363372          "licenses": [
363373            {
363374              "license": {
363375                "id": "ISC"
363376              }
363377            }
363378          ],
363379          "cpe": "cpe:2.3:a:infer-owner:infer-owner:1.0.4:*:*:*:*:*:*:*",
363380          "purl": "pkg:npm/infer-owner@1.0.4",
363381          "swid": {
363382            "attachment": {}
363383          },
363384          "pedigree": {},
363385          "externalReferences": [
363386            {
363387              "url": "git+https://github.com/npm/infer-owner.git",
363388              "type": "distribution"
363389            },
363390            {
363391              "url": "https://github.com/npm/infer-owner#readme",
363392              "type": "website"
363393            }
363394          ],
363395          "evidence": {},
363396          "signature": {
363397            "signature": {
363398              "publicKey": {}
363399            }
363400          },
363401          "modelCard": {
363402            "modelParameters": {
363403              "approach": {}
363404            },
363405            "quantitativeAnalysis": {
363406              "graphics": {}
363407            },
363408            "considerations": {}
363409          }
363410        },
363411        {
363412          "type": "library",
363413          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=7f4a1389d99344e1",
363414          "supplier": {},
363415          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
363416          "name": "inflight",
363417          "version": "1.0.6",
363418          "description": "Add callbacks to requests in flight to avoid async duplication",
363419          "licenses": [
363420            {
363421              "license": {
363422                "id": "ISC"
363423              }
363424            }
363425          ],
363426          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
363427          "purl": "pkg:npm/inflight@1.0.6",
363428          "swid": {
363429            "attachment": {}
363430          },
363431          "pedigree": {},
363432          "externalReferences": [
363433            {
363434              "url": "git+https://github.com/npm/inflight.git",
363435              "type": "distribution"
363436            },
363437            {
363438              "url": "https://github.com/isaacs/inflight",
363439              "type": "website"
363440            }
363441          ],
363442          "evidence": {},
363443          "signature": {
363444            "signature": {
363445              "publicKey": {}
363446            }
363447          },
363448          "modelCard": {
363449            "modelParameters": {
363450              "approach": {}
363451            },
363452            "quantitativeAnalysis": {
363453              "graphics": {}
363454            },
363455            "considerations": {}
363456          }
363457        },
363458        {
363459          "type": "library",
363460          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=699ceddffcda4478",
363461          "supplier": {},
363462          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
363463          "name": "inflight",
363464          "version": "1.0.6",
363465          "description": "Add callbacks to requests in flight to avoid async duplication",
363466          "licenses": [
363467            {
363468              "license": {
363469                "id": "ISC"
363470              }
363471            }
363472          ],
363473          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
363474          "purl": "pkg:npm/inflight@1.0.6",
363475          "swid": {
363476            "attachment": {}
363477          },
363478          "pedigree": {},
363479          "externalReferences": [
363480            {
363481              "url": "git+https://github.com/npm/inflight.git",
363482              "type": "distribution"
363483            },
363484            {
363485              "url": "https://github.com/isaacs/inflight",
363486              "type": "website"
363487            }
363488          ],
363489          "evidence": {},
363490          "signature": {
363491            "signature": {
363492              "publicKey": {}
363493            }
363494          },
363495          "modelCard": {
363496            "modelParameters": {
363497              "approach": {}
363498            },
363499            "quantitativeAnalysis": {
363500              "graphics": {}
363501            },
363502            "considerations": {}
363503          }
363504        },
363505        {
363506          "type": "library",
363507          "bom-ref": "pkg:npm/inherits@2.0.3?package-id=9e94bf16095bed86",
363508          "supplier": {},
363509          "name": "inherits",
363510          "version": "2.0.3",
363511          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
363512          "licenses": [
363513            {
363514              "license": {
363515                "id": "ISC"
363516              }
363517            }
363518          ],
363519          "cpe": "cpe:2.3:a:inherits:inherits:2.0.3:*:*:*:*:*:*:*",
363520          "purl": "pkg:npm/inherits@2.0.3",
363521          "swid": {
363522            "attachment": {}
363523          },
363524          "pedigree": {},
363525          "externalReferences": [
363526            {
363527              "url": "git://github.com/isaacs/inherits.git",
363528              "type": "distribution"
363529            },
363530            {
363531              "url": "https://github.com/isaacs/inherits#readme",
363532              "type": "website"
363533            }
363534          ],
363535          "evidence": {},
363536          "signature": {
363537            "signature": {
363538              "publicKey": {}
363539            }
363540          },
363541          "modelCard": {
363542            "modelParameters": {
363543              "approach": {}
363544            },
363545            "quantitativeAnalysis": {
363546              "graphics": {}
363547            },
363548            "considerations": {}
363549          }
363550        },
363551        {
363552          "type": "library",
363553          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=c75e2d1e61a335c0",
363554          "supplier": {},
363555          "name": "inherits",
363556          "version": "2.0.4",
363557          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
363558          "licenses": [
363559            {
363560              "license": {
363561                "id": "ISC"
363562              }
363563            }
363564          ],
363565          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
363566          "purl": "pkg:npm/inherits@2.0.4",
363567          "swid": {
363568            "attachment": {}
363569          },
363570          "pedigree": {},
363571          "externalReferences": [
363572            {
363573              "url": "git://github.com/isaacs/inherits.git",
363574              "type": "distribution"
363575            },
363576            {
363577              "url": "https://github.com/isaacs/inherits#readme",
363578              "type": "website"
363579            }
363580          ],
363581          "evidence": {},
363582          "signature": {
363583            "signature": {
363584              "publicKey": {}
363585            }
363586          },
363587          "modelCard": {
363588            "modelParameters": {
363589              "approach": {}
363590            },
363591            "quantitativeAnalysis": {
363592              "graphics": {}
363593            },
363594            "considerations": {}
363595          }
363596        },
363597        {
363598          "type": "library",
363599          "bom-ref": "pkg:npm/ini@1.3.8?package-id=1144947c22b83407",
363600          "supplier": {},
363601          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
363602          "name": "ini",
363603          "version": "1.3.8",
363604          "description": "An ini encoder/decoder for node",
363605          "licenses": [
363606            {
363607              "license": {
363608                "id": "ISC"
363609              }
363610            }
363611          ],
363612          "cpe": "cpe:2.3:a:isaacs:ini:1.3.8:*:*:*:*:*:*:*",
363613          "purl": "pkg:npm/ini@1.3.8",
363614          "swid": {
363615            "attachment": {}
363616          },
363617          "pedigree": {},
363618          "externalReferences": [
363619            {
363620              "url": "git://github.com/isaacs/ini.git",
363621              "type": "distribution"
363622            },
363623            {
363624              "url": "https://github.com/isaacs/ini#readme",
363625              "type": "website"
363626            }
363627          ],
363628          "evidence": {},
363629          "signature": {
363630            "signature": {
363631              "publicKey": {}
363632            }
363633          },
363634          "modelCard": {
363635            "modelParameters": {
363636              "approach": {}
363637            },
363638            "quantitativeAnalysis": {
363639              "graphics": {}
363640            },
363641            "considerations": {}
363642          }
363643        },
363644        {
363645          "type": "library",
363646          "bom-ref": "pkg:npm/init-package-json@1.10.3?package-id=612217504bf238b9",
363647          "supplier": {},
363648          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
363649          "name": "init-package-json",
363650          "version": "1.10.3",
363651          "description": "A node module to get your node module started",
363652          "licenses": [
363653            {
363654              "license": {
363655                "id": "ISC"
363656              }
363657            }
363658          ],
363659          "cpe": "cpe:2.3:a:init-package-json:init-package-json:1.10.3:*:*:*:*:*:*:*",
363660          "purl": "pkg:npm/init-package-json@1.10.3",
363661          "swid": {
363662            "attachment": {}
363663          },
363664          "pedigree": {},
363665          "externalReferences": [
363666            {
363667              "url": "git+https://github.com/npm/init-package-json.git",
363668              "type": "distribution"
363669            },
363670            {
363671              "url": "https://github.com/npm/init-package-json#readme",
363672              "type": "website"
363673            }
363674          ],
363675          "evidence": {},
363676          "signature": {
363677            "signature": {
363678              "publicKey": {}
363679            }
363680          },
363681          "modelCard": {
363682            "modelParameters": {
363683              "approach": {}
363684            },
363685            "quantitativeAnalysis": {
363686              "graphics": {}
363687            },
363688            "considerations": {}
363689          }
363690        },
363691        {
363692          "type": "library",
363693          "bom-ref": "pkg:npm/ip@1.1.5?package-id=40b78732d677da70",
363694          "supplier": {},
363695          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
363696          "name": "ip",
363697          "version": "1.1.5",
363698          "description": "[![](https://badge.fury.io/js/ip.svg)](https://www.npmjs.com/package/ip)",
363699          "licenses": [
363700            {
363701              "license": {
363702                "id": "MIT"
363703              }
363704            }
363705          ],
363706          "cpe": "cpe:2.3:a:indutny:ip:1.1.5:*:*:*:*:*:*:*",
363707          "purl": "pkg:npm/ip@1.1.5",
363708          "swid": {
363709            "attachment": {}
363710          },
363711          "pedigree": {},
363712          "externalReferences": [
363713            {
363714              "url": "git+ssh://git@github.com/indutny/node-ip.git",
363715              "type": "distribution"
363716            },
363717            {
363718              "url": "https://github.com/indutny/node-ip",
363719              "type": "website"
363720            }
363721          ],
363722          "evidence": {},
363723          "signature": {
363724            "signature": {
363725              "publicKey": {}
363726            }
363727          },
363728          "modelCard": {
363729            "modelParameters": {
363730              "approach": {}
363731            },
363732            "quantitativeAnalysis": {
363733              "graphics": {}
363734            },
363735            "considerations": {}
363736          }
363737        },
363738        {
363739          "type": "library",
363740          "bom-ref": "pkg:npm/ip-regex@2.1.0?package-id=7de70bcecf1718ee",
363741          "supplier": {},
363742          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
363743          "name": "ip-regex",
363744          "version": "2.1.0",
363745          "description": "Regular expression for matching IP addresses (IPv4 \u0026 IPv6)",
363746          "licenses": [
363747            {
363748              "license": {
363749                "id": "MIT"
363750              }
363751            }
363752          ],
363753          "cpe": "cpe:2.3:a:sindresorhus:ip-regex:2.1.0:*:*:*:*:*:*:*",
363754          "purl": "pkg:npm/ip-regex@2.1.0",
363755          "swid": {
363756            "attachment": {}
363757          },
363758          "pedigree": {},
363759          "externalReferences": [
363760            {
363761              "url": "git+https://github.com/sindresorhus/ip-regex.git",
363762              "type": "distribution"
363763            },
363764            {
363765              "url": "https://github.com/sindresorhus/ip-regex#readme",
363766              "type": "website"
363767            }
363768          ],
363769          "evidence": {},
363770          "signature": {
363771            "signature": {
363772              "publicKey": {}
363773            }
363774          },
363775          "modelCard": {
363776            "modelParameters": {
363777              "approach": {}
363778            },
363779            "quantitativeAnalysis": {
363780              "graphics": {}
363781            },
363782            "considerations": {}
363783          }
363784        },
363785        {
363786          "type": "library",
363787          "bom-ref": "pkg:npm/ipaddr.js@1.9.1?package-id=79e3881762ad8396",
363788          "supplier": {},
363789          "author": "whitequark \u003cwhitequark@whitequark.org\u003e",
363790          "name": "ipaddr.js",
363791          "version": "1.9.1",
363792          "description": "A library for manipulating IPv4 and IPv6 addresses in JavaScript.",
363793          "licenses": [
363794            {
363795              "license": {
363796                "id": "MIT"
363797              }
363798            }
363799          ],
363800          "cpe": "cpe:2.3:a:whitequark:ipaddr.js:1.9.1:*:*:*:*:*:*:*",
363801          "purl": "pkg:npm/ipaddr.js@1.9.1",
363802          "swid": {
363803            "attachment": {}
363804          },
363805          "pedigree": {},
363806          "externalReferences": [
363807            {
363808              "url": "git://github.com/whitequark/ipaddr.js.git",
363809              "type": "distribution"
363810            },
363811            {
363812              "url": "https://github.com/whitequark/ipaddr.js#readme",
363813              "type": "website"
363814            }
363815          ],
363816          "evidence": {},
363817          "signature": {
363818            "signature": {
363819              "publicKey": {}
363820            }
363821          },
363822          "modelCard": {
363823            "modelParameters": {
363824              "approach": {}
363825            },
363826            "quantitativeAnalysis": {
363827              "graphics": {}
363828            },
363829            "considerations": {}
363830          }
363831        },
363832        {
363833          "type": "library",
363834          "bom-ref": "pkg:npm/is-callable@1.1.4?package-id=1dc6d2322f00d7bb",
363835          "supplier": {},
363836          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
363837          "name": "is-callable",
363838          "version": "1.1.4",
363839          "description": "Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.",
363840          "licenses": [
363841            {
363842              "license": {
363843                "id": "MIT"
363844              }
363845            }
363846          ],
363847          "cpe": "cpe:2.3:a:is-callable:is-callable:1.1.4:*:*:*:*:*:*:*",
363848          "purl": "pkg:npm/is-callable@1.1.4",
363849          "swid": {
363850            "attachment": {}
363851          },
363852          "pedigree": {},
363853          "externalReferences": [
363854            {
363855              "url": "git://github.com/ljharb/is-callable.git",
363856              "type": "distribution"
363857            }
363858          ],
363859          "evidence": {},
363860          "signature": {
363861            "signature": {
363862              "publicKey": {}
363863            }
363864          },
363865          "modelCard": {
363866            "modelParameters": {
363867              "approach": {}
363868            },
363869            "quantitativeAnalysis": {
363870              "graphics": {}
363871            },
363872            "considerations": {}
363873          }
363874        },
363875        {
363876          "type": "library",
363877          "bom-ref": "pkg:npm/is-ci@1.2.1?package-id=33144f04a12b9be2",
363878          "supplier": {},
363879          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
363880          "name": "is-ci",
363881          "version": "1.2.1",
363882          "description": "Detect if the current environment is a CI server",
363883          "licenses": [
363884            {
363885              "license": {
363886                "id": "MIT"
363887              }
363888            }
363889          ],
363890          "cpe": "cpe:2.3:a:watson:is-ci:1.2.1:*:*:*:*:*:*:*",
363891          "purl": "pkg:npm/is-ci@1.2.1",
363892          "swid": {
363893            "attachment": {}
363894          },
363895          "pedigree": {},
363896          "externalReferences": [
363897            {
363898              "url": "git+https://github.com/watson/is-ci.git",
363899              "type": "distribution"
363900            },
363901            {
363902              "url": "https://github.com/watson/is-ci",
363903              "type": "website"
363904            }
363905          ],
363906          "evidence": {},
363907          "signature": {
363908            "signature": {
363909              "publicKey": {}
363910            }
363911          },
363912          "modelCard": {
363913            "modelParameters": {
363914              "approach": {}
363915            },
363916            "quantitativeAnalysis": {
363917              "graphics": {}
363918            },
363919            "considerations": {}
363920          }
363921        },
363922        {
363923          "type": "library",
363924          "bom-ref": "pkg:npm/is-cidr@3.1.1?package-id=66ca7deffeed6b5f",
363925          "supplier": {},
363926          "author": "silverwind \u003cme@silverwind.io\u003e",
363927          "name": "is-cidr",
363928          "version": "3.1.1",
363929          "description": "Check if a string is an IP address in CIDR notation",
363930          "licenses": [
363931            {
363932              "license": {
363933                "id": "BSD-2-Clause"
363934              }
363935            }
363936          ],
363937          "cpe": "cpe:2.3:a:silverwind:is-cidr:3.1.1:*:*:*:*:*:*:*",
363938          "purl": "pkg:npm/is-cidr@3.1.1",
363939          "swid": {
363940            "attachment": {}
363941          },
363942          "pedigree": {},
363943          "externalReferences": [
363944            {
363945              "url": "git+https://github.com/silverwind/is-cidr.git",
363946              "type": "distribution"
363947            },
363948            {
363949              "url": "https://github.com/silverwind/is-cidr#readme",
363950              "type": "website"
363951            }
363952          ],
363953          "evidence": {},
363954          "signature": {
363955            "signature": {
363956              "publicKey": {}
363957            }
363958          },
363959          "modelCard": {
363960            "modelParameters": {
363961              "approach": {}
363962            },
363963            "quantitativeAnalysis": {
363964              "graphics": {}
363965            },
363966            "considerations": {}
363967          }
363968        },
363969        {
363970          "type": "library",
363971          "bom-ref": "pkg:npm/is-circular@1.0.2?package-id=ca261a9295461146",
363972          "supplier": {},
363973          "author": "Tejesh Mehta",
363974          "name": "is-circular",
363975          "version": "1.0.2",
363976          "description": "high-performance, zero-dependency circular reference check for objects (or arrays)",
363977          "licenses": [
363978            {
363979              "license": {
363980                "id": "MIT"
363981              }
363982            }
363983          ],
363984          "cpe": "cpe:2.3:a:is-circular:is-circular:1.0.2:*:*:*:*:*:*:*",
363985          "purl": "pkg:npm/is-circular@1.0.2",
363986          "swid": {
363987            "attachment": {}
363988          },
363989          "pedigree": {},
363990          "externalReferences": [
363991            {
363992              "url": "git+https://github.com/tjmehta/is-circular.git",
363993              "type": "distribution"
363994            },
363995            {
363996              "url": "https://github.com/tjmehta/is-circular",
363997              "type": "website"
363998            }
363999          ],
364000          "evidence": {},
364001          "signature": {
364002            "signature": {
364003              "publicKey": {}
364004            }
364005          },
364006          "modelCard": {
364007            "modelParameters": {
364008              "approach": {}
364009            },
364010            "quantitativeAnalysis": {
364011              "graphics": {}
364012            },
364013            "considerations": {}
364014          }
364015        },
364016        {
364017          "type": "library",
364018          "bom-ref": "pkg:npm/is-date-object@1.0.1?package-id=92b971217126a920",
364019          "supplier": {},
364020          "author": "Jordan Harband",
364021          "name": "is-date-object",
364022          "version": "1.0.1",
364023          "description": "Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.",
364024          "licenses": [
364025            {
364026              "license": {
364027                "id": "MIT"
364028              }
364029            }
364030          ],
364031          "cpe": "cpe:2.3:a:is-date-object:is-date-object:1.0.1:*:*:*:*:*:*:*",
364032          "purl": "pkg:npm/is-date-object@1.0.1",
364033          "swid": {
364034            "attachment": {}
364035          },
364036          "pedigree": {},
364037          "externalReferences": [
364038            {
364039              "url": "git://github.com/ljharb/is-date-object.git",
364040              "type": "distribution"
364041            }
364042          ],
364043          "evidence": {},
364044          "signature": {
364045            "signature": {
364046              "publicKey": {}
364047            }
364048          },
364049          "modelCard": {
364050            "modelParameters": {
364051              "approach": {}
364052            },
364053            "quantitativeAnalysis": {
364054              "graphics": {}
364055            },
364056            "considerations": {}
364057          }
364058        },
364059        {
364060          "type": "library",
364061          "bom-ref": "pkg:npm/is-fullwidth-code-point@1.0.0?package-id=5e069f3bee1f8e8c",
364062          "supplier": {},
364063          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364064          "name": "is-fullwidth-code-point",
364065          "version": "1.0.0",
364066          "description": "Check if the character represented by a given Unicode code point is fullwidth",
364067          "licenses": [
364068            {
364069              "license": {
364070                "id": "MIT"
364071              }
364072            }
364073          ],
364074          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:1.0.0:*:*:*:*:*:*:*",
364075          "purl": "pkg:npm/is-fullwidth-code-point@1.0.0",
364076          "swid": {
364077            "attachment": {}
364078          },
364079          "pedigree": {},
364080          "externalReferences": [
364081            {
364082              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
364083              "type": "distribution"
364084            },
364085            {
364086              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
364087              "type": "website"
364088            }
364089          ],
364090          "evidence": {},
364091          "signature": {
364092            "signature": {
364093              "publicKey": {}
364094            }
364095          },
364096          "modelCard": {
364097            "modelParameters": {
364098              "approach": {}
364099            },
364100            "quantitativeAnalysis": {
364101              "graphics": {}
364102            },
364103            "considerations": {}
364104          }
364105        },
364106        {
364107          "type": "library",
364108          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=c9e52c69ac61a15d",
364109          "supplier": {},
364110          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364111          "name": "is-fullwidth-code-point",
364112          "version": "2.0.0",
364113          "description": "Check if the character represented by a given Unicode code point is fullwidth",
364114          "licenses": [
364115            {
364116              "license": {
364117                "id": "MIT"
364118              }
364119            }
364120          ],
364121          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
364122          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
364123          "swid": {
364124            "attachment": {}
364125          },
364126          "pedigree": {},
364127          "externalReferences": [
364128            {
364129              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
364130              "type": "distribution"
364131            },
364132            {
364133              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
364134              "type": "website"
364135            }
364136          ],
364137          "evidence": {},
364138          "signature": {
364139            "signature": {
364140              "publicKey": {}
364141            }
364142          },
364143          "modelCard": {
364144            "modelParameters": {
364145              "approach": {}
364146            },
364147            "quantitativeAnalysis": {
364148              "graphics": {}
364149            },
364150            "considerations": {}
364151          }
364152        },
364153        {
364154          "type": "library",
364155          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=18d3c43bb481b40e",
364156          "supplier": {},
364157          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364158          "name": "is-fullwidth-code-point",
364159          "version": "2.0.0",
364160          "description": "Check if the character represented by a given Unicode code point is fullwidth",
364161          "licenses": [
364162            {
364163              "license": {
364164                "id": "MIT"
364165              }
364166            }
364167          ],
364168          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
364169          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
364170          "swid": {
364171            "attachment": {}
364172          },
364173          "pedigree": {},
364174          "externalReferences": [
364175            {
364176              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
364177              "type": "distribution"
364178            },
364179            {
364180              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
364181              "type": "website"
364182            }
364183          ],
364184          "evidence": {},
364185          "signature": {
364186            "signature": {
364187              "publicKey": {}
364188            }
364189          },
364190          "modelCard": {
364191            "modelParameters": {
364192              "approach": {}
364193            },
364194            "quantitativeAnalysis": {
364195              "graphics": {}
364196            },
364197            "considerations": {}
364198          }
364199        },
364200        {
364201          "type": "library",
364202          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=bc292caf09c7f0a6",
364203          "supplier": {},
364204          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364205          "name": "is-fullwidth-code-point",
364206          "version": "2.0.0",
364207          "description": "Check if the character represented by a given Unicode code point is fullwidth",
364208          "licenses": [
364209            {
364210              "license": {
364211                "id": "MIT"
364212              }
364213            }
364214          ],
364215          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
364216          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
364217          "swid": {
364218            "attachment": {}
364219          },
364220          "pedigree": {},
364221          "externalReferences": [
364222            {
364223              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
364224              "type": "distribution"
364225            },
364226            {
364227              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
364228              "type": "website"
364229            }
364230          ],
364231          "evidence": {},
364232          "signature": {
364233            "signature": {
364234              "publicKey": {}
364235            }
364236          },
364237          "modelCard": {
364238            "modelParameters": {
364239              "approach": {}
364240            },
364241            "quantitativeAnalysis": {
364242              "graphics": {}
364243            },
364244            "considerations": {}
364245          }
364246        },
364247        {
364248          "type": "library",
364249          "bom-ref": "pkg:npm/is-fullwidth-code-point@2.0.0?package-id=b4b1a80d5cc6ed9f",
364250          "supplier": {},
364251          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364252          "name": "is-fullwidth-code-point",
364253          "version": "2.0.0",
364254          "description": "Check if the character represented by a given Unicode code point is fullwidth",
364255          "licenses": [
364256            {
364257              "license": {
364258                "id": "MIT"
364259              }
364260            }
364261          ],
364262          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:2.0.0:*:*:*:*:*:*:*",
364263          "purl": "pkg:npm/is-fullwidth-code-point@2.0.0",
364264          "swid": {
364265            "attachment": {}
364266          },
364267          "pedigree": {},
364268          "externalReferences": [
364269            {
364270              "url": "git+https://github.com/sindresorhus/is-fullwidth-code-point.git",
364271              "type": "distribution"
364272            },
364273            {
364274              "url": "https://github.com/sindresorhus/is-fullwidth-code-point#readme",
364275              "type": "website"
364276            }
364277          ],
364278          "evidence": {},
364279          "signature": {
364280            "signature": {
364281              "publicKey": {}
364282            }
364283          },
364284          "modelCard": {
364285            "modelParameters": {
364286              "approach": {}
364287            },
364288            "quantitativeAnalysis": {
364289              "graphics": {}
364290            },
364291            "considerations": {}
364292          }
364293        },
364294        {
364295          "type": "library",
364296          "bom-ref": "pkg:npm/is-installed-globally@0.1.0?package-id=52068e84c707b28e",
364297          "supplier": {},
364298          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364299          "name": "is-installed-globally",
364300          "version": "0.1.0",
364301          "description": "Check if your package was installed globally",
364302          "licenses": [
364303            {
364304              "license": {
364305                "id": "MIT"
364306              }
364307            }
364308          ],
364309          "cpe": "cpe:2.3:a:is-installed-globally:is-installed-globally:0.1.0:*:*:*:*:*:*:*",
364310          "purl": "pkg:npm/is-installed-globally@0.1.0",
364311          "swid": {
364312            "attachment": {}
364313          },
364314          "pedigree": {},
364315          "externalReferences": [
364316            {
364317              "url": "git+https://github.com/sindresorhus/is-installed-globally.git",
364318              "type": "distribution"
364319            },
364320            {
364321              "url": "https://github.com/sindresorhus/is-installed-globally#readme",
364322              "type": "website"
364323            }
364324          ],
364325          "evidence": {},
364326          "signature": {
364327            "signature": {
364328              "publicKey": {}
364329            }
364330          },
364331          "modelCard": {
364332            "modelParameters": {
364333              "approach": {}
364334            },
364335            "quantitativeAnalysis": {
364336              "graphics": {}
364337            },
364338            "considerations": {}
364339          }
364340        },
364341        {
364342          "type": "library",
364343          "bom-ref": "pkg:npm/is-npm@1.0.0?package-id=a091bf82a35edad5",
364344          "supplier": {},
364345          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (http://sindresorhus.com)",
364346          "name": "is-npm",
364347          "version": "1.0.0",
364348          "description": "Check if your code is running as an npm script",
364349          "licenses": [
364350            {
364351              "license": {
364352                "id": "MIT"
364353              }
364354            }
364355          ],
364356          "cpe": "cpe:2.3:a:sindresorhus:is-npm:1.0.0:*:*:*:*:*:*:*",
364357          "purl": "pkg:npm/is-npm@1.0.0",
364358          "swid": {
364359            "attachment": {}
364360          },
364361          "pedigree": {},
364362          "externalReferences": [
364363            {
364364              "url": "git+https://github.com/sindresorhus/is-npm.git",
364365              "type": "distribution"
364366            },
364367            {
364368              "url": "https://github.com/sindresorhus/is-npm#readme",
364369              "type": "website"
364370            }
364371          ],
364372          "evidence": {},
364373          "signature": {
364374            "signature": {
364375              "publicKey": {}
364376            }
364377          },
364378          "modelCard": {
364379            "modelParameters": {
364380              "approach": {}
364381            },
364382            "quantitativeAnalysis": {
364383              "graphics": {}
364384            },
364385            "considerations": {}
364386          }
364387        },
364388        {
364389          "type": "library",
364390          "bom-ref": "pkg:npm/is-obj@1.0.1?package-id=7979f769260859e3",
364391          "supplier": {},
364392          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364393          "name": "is-obj",
364394          "version": "1.0.1",
364395          "description": "Check if a value is an object",
364396          "licenses": [
364397            {
364398              "license": {
364399                "id": "MIT"
364400              }
364401            }
364402          ],
364403          "cpe": "cpe:2.3:a:sindresorhus:is-obj:1.0.1:*:*:*:*:*:*:*",
364404          "purl": "pkg:npm/is-obj@1.0.1",
364405          "swid": {
364406            "attachment": {}
364407          },
364408          "pedigree": {},
364409          "externalReferences": [
364410            {
364411              "url": "git+https://github.com/sindresorhus/is-obj.git",
364412              "type": "distribution"
364413            },
364414            {
364415              "url": "https://github.com/sindresorhus/is-obj#readme",
364416              "type": "website"
364417            }
364418          ],
364419          "evidence": {},
364420          "signature": {
364421            "signature": {
364422              "publicKey": {}
364423            }
364424          },
364425          "modelCard": {
364426            "modelParameters": {
364427              "approach": {}
364428            },
364429            "quantitativeAnalysis": {
364430              "graphics": {}
364431            },
364432            "considerations": {}
364433          }
364434        },
364435        {
364436          "type": "library",
364437          "bom-ref": "pkg:npm/is-path-inside@1.0.1?package-id=62bf5e53df19f8af",
364438          "supplier": {},
364439          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364440          "name": "is-path-inside",
364441          "version": "1.0.1",
364442          "description": "Check if a path is inside another path",
364443          "licenses": [
364444            {
364445              "license": {
364446                "id": "MIT"
364447              }
364448            }
364449          ],
364450          "cpe": "cpe:2.3:a:is-path-inside:is-path-inside:1.0.1:*:*:*:*:*:*:*",
364451          "purl": "pkg:npm/is-path-inside@1.0.1",
364452          "swid": {
364453            "attachment": {}
364454          },
364455          "pedigree": {},
364456          "externalReferences": [
364457            {
364458              "url": "git+https://github.com/sindresorhus/is-path-inside.git",
364459              "type": "distribution"
364460            },
364461            {
364462              "url": "https://github.com/sindresorhus/is-path-inside#readme",
364463              "type": "website"
364464            }
364465          ],
364466          "evidence": {},
364467          "signature": {
364468            "signature": {
364469              "publicKey": {}
364470            }
364471          },
364472          "modelCard": {
364473            "modelParameters": {
364474              "approach": {}
364475            },
364476            "quantitativeAnalysis": {
364477              "graphics": {}
364478            },
364479            "considerations": {}
364480          }
364481        },
364482        {
364483          "type": "library",
364484          "bom-ref": "pkg:npm/is-redirect@1.0.0?package-id=a4990c9b97577de8",
364485          "supplier": {},
364486          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364487          "name": "is-redirect",
364488          "version": "1.0.0",
364489          "description": "Check if a number is a redirect HTTP status code",
364490          "licenses": [
364491            {
364492              "license": {
364493                "id": "MIT"
364494              }
364495            }
364496          ],
364497          "cpe": "cpe:2.3:a:sindresorhus:is-redirect:1.0.0:*:*:*:*:*:*:*",
364498          "purl": "pkg:npm/is-redirect@1.0.0",
364499          "swid": {
364500            "attachment": {}
364501          },
364502          "pedigree": {},
364503          "externalReferences": [
364504            {
364505              "url": "git+https://github.com/sindresorhus/is-redirect.git",
364506              "type": "distribution"
364507            },
364508            {
364509              "url": "https://github.com/sindresorhus/is-redirect#readme",
364510              "type": "website"
364511            }
364512          ],
364513          "evidence": {},
364514          "signature": {
364515            "signature": {
364516              "publicKey": {}
364517            }
364518          },
364519          "modelCard": {
364520            "modelParameters": {
364521              "approach": {}
364522            },
364523            "quantitativeAnalysis": {
364524              "graphics": {}
364525            },
364526            "considerations": {}
364527          }
364528        },
364529        {
364530          "type": "library",
364531          "bom-ref": "pkg:npm/is-regex@1.0.4?package-id=f0395380adf7d3e7",
364532          "supplier": {},
364533          "author": "Jordan Harband",
364534          "name": "is-regex",
364535          "version": "1.0.4",
364536          "description": "Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag",
364537          "licenses": [
364538            {
364539              "license": {
364540                "id": "MIT"
364541              }
364542            }
364543          ],
364544          "cpe": "cpe:2.3:a:is-regex:is-regex:1.0.4:*:*:*:*:*:*:*",
364545          "purl": "pkg:npm/is-regex@1.0.4",
364546          "swid": {
364547            "attachment": {}
364548          },
364549          "pedigree": {},
364550          "externalReferences": [
364551            {
364552              "url": "git://github.com/ljharb/is-regex.git",
364553              "type": "distribution"
364554            },
364555            {
364556              "url": "https://github.com/ljharb/is-regex",
364557              "type": "website"
364558            }
364559          ],
364560          "evidence": {},
364561          "signature": {
364562            "signature": {
364563              "publicKey": {}
364564            }
364565          },
364566          "modelCard": {
364567            "modelParameters": {
364568              "approach": {}
364569            },
364570            "quantitativeAnalysis": {
364571              "graphics": {}
364572            },
364573            "considerations": {}
364574          }
364575        },
364576        {
364577          "type": "library",
364578          "bom-ref": "pkg:npm/is-retry-allowed@1.2.0?package-id=b30668148b87771",
364579          "supplier": {},
364580          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
364581          "name": "is-retry-allowed",
364582          "version": "1.2.0",
364583          "description": "Is retry allowed for Error?",
364584          "licenses": [
364585            {
364586              "license": {
364587                "id": "MIT"
364588              }
364589            }
364590          ],
364591          "cpe": "cpe:2.3:a:is-retry-allowed:is-retry-allowed:1.2.0:*:*:*:*:*:*:*",
364592          "purl": "pkg:npm/is-retry-allowed@1.2.0",
364593          "swid": {
364594            "attachment": {}
364595          },
364596          "pedigree": {},
364597          "externalReferences": [
364598            {
364599              "url": "git+https://github.com/floatdrop/is-retry-allowed.git",
364600              "type": "distribution"
364601            },
364602            {
364603              "url": "https://github.com/floatdrop/is-retry-allowed#readme",
364604              "type": "website"
364605            }
364606          ],
364607          "evidence": {},
364608          "signature": {
364609            "signature": {
364610              "publicKey": {}
364611            }
364612          },
364613          "modelCard": {
364614            "modelParameters": {
364615              "approach": {}
364616            },
364617            "quantitativeAnalysis": {
364618              "graphics": {}
364619            },
364620            "considerations": {}
364621          }
364622        },
364623        {
364624          "type": "library",
364625          "bom-ref": "pkg:npm/is-stream@1.1.0?package-id=e2a191b14586fcc2",
364626          "supplier": {},
364627          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
364628          "name": "is-stream",
364629          "version": "1.1.0",
364630          "description": "Check if something is a Node.js stream",
364631          "licenses": [
364632            {
364633              "license": {
364634                "id": "MIT"
364635              }
364636            }
364637          ],
364638          "cpe": "cpe:2.3:a:sindresorhus:is-stream:1.1.0:*:*:*:*:*:*:*",
364639          "purl": "pkg:npm/is-stream@1.1.0",
364640          "swid": {
364641            "attachment": {}
364642          },
364643          "pedigree": {},
364644          "externalReferences": [
364645            {
364646              "url": "git+https://github.com/sindresorhus/is-stream.git",
364647              "type": "distribution"
364648            },
364649            {
364650              "url": "https://github.com/sindresorhus/is-stream#readme",
364651              "type": "website"
364652            }
364653          ],
364654          "evidence": {},
364655          "signature": {
364656            "signature": {
364657              "publicKey": {}
364658            }
364659          },
364660          "modelCard": {
364661            "modelParameters": {
364662              "approach": {}
364663            },
364664            "quantitativeAnalysis": {
364665              "graphics": {}
364666            },
364667            "considerations": {}
364668          }
364669        },
364670        {
364671          "type": "library",
364672          "bom-ref": "pkg:npm/is-symbol@1.0.2?package-id=6f84bf274f444b99",
364673          "supplier": {},
364674          "author": "Jordan Harband",
364675          "name": "is-symbol",
364676          "version": "1.0.2",
364677          "description": "Determine if a value is an ES6 Symbol or not.",
364678          "licenses": [
364679            {
364680              "license": {
364681                "id": "MIT"
364682              }
364683            }
364684          ],
364685          "cpe": "cpe:2.3:a:is-symbol:is-symbol:1.0.2:*:*:*:*:*:*:*",
364686          "purl": "pkg:npm/is-symbol@1.0.2",
364687          "swid": {
364688            "attachment": {}
364689          },
364690          "pedigree": {},
364691          "externalReferences": [
364692            {
364693              "url": "git://github.com/ljharb/is-symbol.git",
364694              "type": "distribution"
364695            }
364696          ],
364697          "evidence": {},
364698          "signature": {
364699            "signature": {
364700              "publicKey": {}
364701            }
364702          },
364703          "modelCard": {
364704            "modelParameters": {
364705              "approach": {}
364706            },
364707            "quantitativeAnalysis": {
364708              "graphics": {}
364709            },
364710            "considerations": {}
364711          }
364712        },
364713        {
364714          "type": "library",
364715          "bom-ref": "pkg:npm/is-typedarray@1.0.0?package-id=e719ed77b7d38e33",
364716          "supplier": {},
364717          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
364718          "name": "is-typedarray",
364719          "version": "1.0.0",
364720          "description": "Detect whether or not an object is a Typed Array",
364721          "licenses": [
364722            {
364723              "license": {
364724                "id": "MIT"
364725              }
364726            }
364727          ],
364728          "cpe": "cpe:2.3:a:is-typedarray:is-typedarray:1.0.0:*:*:*:*:*:*:*",
364729          "purl": "pkg:npm/is-typedarray@1.0.0",
364730          "swid": {
364731            "attachment": {}
364732          },
364733          "pedigree": {},
364734          "externalReferences": [
364735            {
364736              "url": "git://github.com/hughsk/is-typedarray.git",
364737              "type": "distribution"
364738            },
364739            {
364740              "url": "https://github.com/hughsk/is-typedarray",
364741              "type": "website"
364742            }
364743          ],
364744          "evidence": {},
364745          "signature": {
364746            "signature": {
364747              "publicKey": {}
364748            }
364749          },
364750          "modelCard": {
364751            "modelParameters": {
364752              "approach": {}
364753            },
364754            "quantitativeAnalysis": {
364755              "graphics": {}
364756            },
364757            "considerations": {}
364758          }
364759        },
364760        {
364761          "type": "library",
364762          "bom-ref": "pkg:npm/is-typedarray@1.0.0?package-id=4614424f10a58ef7",
364763          "supplier": {},
364764          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
364765          "name": "is-typedarray",
364766          "version": "1.0.0",
364767          "description": "Detect whether or not an object is a Typed Array",
364768          "licenses": [
364769            {
364770              "license": {
364771                "id": "MIT"
364772              }
364773            }
364774          ],
364775          "cpe": "cpe:2.3:a:is-typedarray:is-typedarray:1.0.0:*:*:*:*:*:*:*",
364776          "purl": "pkg:npm/is-typedarray@1.0.0",
364777          "swid": {
364778            "attachment": {}
364779          },
364780          "pedigree": {},
364781          "externalReferences": [
364782            {
364783              "url": "git://github.com/hughsk/is-typedarray.git",
364784              "type": "distribution"
364785            },
364786            {
364787              "url": "https://github.com/hughsk/is-typedarray",
364788              "type": "website"
364789            }
364790          ],
364791          "evidence": {},
364792          "signature": {
364793            "signature": {
364794              "publicKey": {}
364795            }
364796          },
364797          "modelCard": {
364798            "modelParameters": {
364799              "approach": {}
364800            },
364801            "quantitativeAnalysis": {
364802              "graphics": {}
364803            },
364804            "considerations": {}
364805          }
364806        },
364807        {
364808          "type": "library",
364809          "bom-ref": "pkg:npm/is_js@0.9.0?package-id=e1e4ef3227e07c61",
364810          "supplier": {},
364811          "name": "is_js",
364812          "version": "0.9.0",
364813          "description": "micro check library",
364814          "licenses": [
364815            {
364816              "license": {
364817                "id": "MIT"
364818              }
364819            }
364820          ],
364821          "cpe": "cpe:2.3:a:is-js:is-js:0.9.0:*:*:*:*:*:*:*",
364822          "purl": "pkg:npm/is_js@0.9.0",
364823          "swid": {
364824            "attachment": {}
364825          },
364826          "pedigree": {},
364827          "externalReferences": [
364828            {
364829              "url": "git+https://github.com/arasatasaygin/is.js.git",
364830              "type": "distribution"
364831            },
364832            {
364833              "url": "http://is.js.org/",
364834              "type": "website"
364835            }
364836          ],
364837          "evidence": {},
364838          "signature": {
364839            "signature": {
364840              "publicKey": {}
364841            }
364842          },
364843          "modelCard": {
364844            "modelParameters": {
364845              "approach": {}
364846            },
364847            "quantitativeAnalysis": {
364848              "graphics": {}
364849            },
364850            "considerations": {}
364851          }
364852        },
364853        {
364854          "type": "library",
364855          "bom-ref": "pkg:npm/isarray@0.0.1?package-id=4eab13fd6138583f",
364856          "supplier": {},
364857          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
364858          "name": "isarray",
364859          "version": "0.0.1",
364860          "description": "Array#isArray for older browsers",
364861          "licenses": [
364862            {
364863              "license": {
364864                "id": "MIT"
364865              }
364866            }
364867          ],
364868          "cpe": "cpe:2.3:a:juliangruber:isarray:0.0.1:*:*:*:*:*:*:*",
364869          "purl": "pkg:npm/isarray@0.0.1",
364870          "swid": {
364871            "attachment": {}
364872          },
364873          "pedigree": {},
364874          "externalReferences": [
364875            {
364876              "url": "git://github.com/juliangruber/isarray.git",
364877              "type": "distribution"
364878            },
364879            {
364880              "url": "https://github.com/juliangruber/isarray",
364881              "type": "website"
364882            }
364883          ],
364884          "evidence": {},
364885          "signature": {
364886            "signature": {
364887              "publicKey": {}
364888            }
364889          },
364890          "modelCard": {
364891            "modelParameters": {
364892              "approach": {}
364893            },
364894            "quantitativeAnalysis": {
364895              "graphics": {}
364896            },
364897            "considerations": {}
364898          }
364899        },
364900        {
364901          "type": "library",
364902          "bom-ref": "pkg:npm/isarray@0.0.1?package-id=9165d82d33f922a9",
364903          "supplier": {},
364904          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
364905          "name": "isarray",
364906          "version": "0.0.1",
364907          "description": "Array#isArray for older browsers",
364908          "licenses": [
364909            {
364910              "license": {
364911                "id": "MIT"
364912              }
364913            }
364914          ],
364915          "cpe": "cpe:2.3:a:juliangruber:isarray:0.0.1:*:*:*:*:*:*:*",
364916          "purl": "pkg:npm/isarray@0.0.1",
364917          "swid": {
364918            "attachment": {}
364919          },
364920          "pedigree": {},
364921          "externalReferences": [
364922            {
364923              "url": "git://github.com/juliangruber/isarray.git",
364924              "type": "distribution"
364925            },
364926            {
364927              "url": "https://github.com/juliangruber/isarray",
364928              "type": "website"
364929            }
364930          ],
364931          "evidence": {},
364932          "signature": {
364933            "signature": {
364934              "publicKey": {}
364935            }
364936          },
364937          "modelCard": {
364938            "modelParameters": {
364939              "approach": {}
364940            },
364941            "quantitativeAnalysis": {
364942              "graphics": {}
364943            },
364944            "considerations": {}
364945          }
364946        },
364947        {
364948          "type": "library",
364949          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=67e7a38d852b614a",
364950          "supplier": {},
364951          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
364952          "name": "isarray",
364953          "version": "1.0.0",
364954          "description": "Array#isArray for older browsers",
364955          "licenses": [
364956            {
364957              "license": {
364958                "id": "MIT"
364959              }
364960            }
364961          ],
364962          "cpe": "cpe:2.3:a:juliangruber:isarray:1.0.0:*:*:*:*:*:*:*",
364963          "purl": "pkg:npm/isarray@1.0.0",
364964          "swid": {
364965            "attachment": {}
364966          },
364967          "pedigree": {},
364968          "externalReferences": [
364969            {
364970              "url": "git://github.com/juliangruber/isarray.git",
364971              "type": "distribution"
364972            },
364973            {
364974              "url": "https://github.com/juliangruber/isarray",
364975              "type": "website"
364976            }
364977          ],
364978          "evidence": {},
364979          "signature": {
364980            "signature": {
364981              "publicKey": {}
364982            }
364983          },
364984          "modelCard": {
364985            "modelParameters": {
364986              "approach": {}
364987            },
364988            "quantitativeAnalysis": {
364989              "graphics": {}
364990            },
364991            "considerations": {}
364992          }
364993        },
364994        {
364995          "type": "library",
364996          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=2d92be2d9c6d102e",
364997          "supplier": {},
364998          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
364999          "name": "isarray",
365000          "version": "1.0.0",
365001          "description": "Array#isArray for older browsers",
365002          "licenses": [
365003            {
365004              "license": {
365005                "id": "MIT"
365006              }
365007            }
365008          ],
365009          "cpe": "cpe:2.3:a:juliangruber:isarray:1.0.0:*:*:*:*:*:*:*",
365010          "purl": "pkg:npm/isarray@1.0.0",
365011          "swid": {
365012            "attachment": {}
365013          },
365014          "pedigree": {},
365015          "externalReferences": [
365016            {
365017              "url": "git://github.com/juliangruber/isarray.git",
365018              "type": "distribution"
365019            },
365020            {
365021              "url": "https://github.com/juliangruber/isarray",
365022              "type": "website"
365023            }
365024          ],
365025          "evidence": {},
365026          "signature": {
365027            "signature": {
365028              "publicKey": {}
365029            }
365030          },
365031          "modelCard": {
365032            "modelParameters": {
365033              "approach": {}
365034            },
365035            "quantitativeAnalysis": {
365036              "graphics": {}
365037            },
365038            "considerations": {}
365039          }
365040        },
365041        {
365042          "type": "library",
365043          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=cac2857ecac9cad9",
365044          "supplier": {},
365045          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
365046          "name": "isexe",
365047          "version": "2.0.0",
365048          "description": "Minimal module to check if a file is executable.",
365049          "licenses": [
365050            {
365051              "license": {
365052                "id": "ISC"
365053              }
365054            }
365055          ],
365056          "cpe": "cpe:2.3:a:isaacs:isexe:2.0.0:*:*:*:*:*:*:*",
365057          "purl": "pkg:npm/isexe@2.0.0",
365058          "swid": {
365059            "attachment": {}
365060          },
365061          "pedigree": {},
365062          "externalReferences": [
365063            {
365064              "url": "git+https://github.com/isaacs/isexe.git",
365065              "type": "distribution"
365066            },
365067            {
365068              "url": "https://github.com/isaacs/isexe#readme",
365069              "type": "website"
365070            }
365071          ],
365072          "evidence": {},
365073          "signature": {
365074            "signature": {
365075              "publicKey": {}
365076            }
365077          },
365078          "modelCard": {
365079            "modelParameters": {
365080              "approach": {}
365081            },
365082            "quantitativeAnalysis": {
365083              "graphics": {}
365084            },
365085            "considerations": {}
365086          }
365087        },
365088        {
365089          "type": "library",
365090          "bom-ref": "pkg:npm/isstream@0.1.2?package-id=686f3e26c1aa6a0c",
365091          "supplier": {},
365092          "author": "Rod Vagg \u003crod@vagg.org\u003e",
365093          "name": "isstream",
365094          "version": "0.1.2",
365095          "description": "Determine if an object is a Stream",
365096          "licenses": [
365097            {
365098              "license": {
365099                "id": "MIT"
365100              }
365101            }
365102          ],
365103          "cpe": "cpe:2.3:a:isstream:isstream:0.1.2:*:*:*:*:*:*:*",
365104          "purl": "pkg:npm/isstream@0.1.2",
365105          "swid": {
365106            "attachment": {}
365107          },
365108          "pedigree": {},
365109          "externalReferences": [
365110            {
365111              "url": "git+https://github.com/rvagg/isstream.git",
365112              "type": "distribution"
365113            },
365114            {
365115              "url": "https://github.com/rvagg/isstream",
365116              "type": "website"
365117            }
365118          ],
365119          "evidence": {},
365120          "signature": {
365121            "signature": {
365122              "publicKey": {}
365123            }
365124          },
365125          "modelCard": {
365126            "modelParameters": {
365127              "approach": {}
365128            },
365129            "quantitativeAnalysis": {
365130              "graphics": {}
365131            },
365132            "considerations": {}
365133          }
365134        },
365135        {
365136          "type": "library",
365137          "bom-ref": "pkg:npm/isstream@0.1.2?package-id=fd7d0a75eb876e94",
365138          "supplier": {},
365139          "author": "Rod Vagg \u003crod@vagg.org\u003e",
365140          "name": "isstream",
365141          "version": "0.1.2",
365142          "description": "Determine if an object is a Stream",
365143          "licenses": [
365144            {
365145              "license": {
365146                "id": "MIT"
365147              }
365148            }
365149          ],
365150          "cpe": "cpe:2.3:a:isstream:isstream:0.1.2:*:*:*:*:*:*:*",
365151          "purl": "pkg:npm/isstream@0.1.2",
365152          "swid": {
365153            "attachment": {}
365154          },
365155          "pedigree": {},
365156          "externalReferences": [
365157            {
365158              "url": "git+https://github.com/rvagg/isstream.git",
365159              "type": "distribution"
365160            },
365161            {
365162              "url": "https://github.com/rvagg/isstream",
365163              "type": "website"
365164            }
365165          ],
365166          "evidence": {},
365167          "signature": {
365168            "signature": {
365169              "publicKey": {}
365170            }
365171          },
365172          "modelCard": {
365173            "modelParameters": {
365174              "approach": {}
365175            },
365176            "quantitativeAnalysis": {
365177              "graphics": {}
365178            },
365179            "considerations": {}
365180          }
365181        },
365182        {
365183          "type": "library",
365184          "bom-ref": "pkg:npm/iterare@1.2.1?package-id=f6ab001f5555d5ae",
365185          "supplier": {},
365186          "author": "Felix Becker \u003cfelix.b@outlook.com\u003e",
365187          "name": "iterare",
365188          "version": "1.2.1",
365189          "description": "Array methods for ES6 Iterators",
365190          "licenses": [
365191            {
365192              "license": {
365193                "id": "ISC"
365194              }
365195            }
365196          ],
365197          "cpe": "cpe:2.3:a:felixfbecker:iterare:1.2.1:*:*:*:*:*:*:*",
365198          "purl": "pkg:npm/iterare@1.2.1",
365199          "swid": {
365200            "attachment": {}
365201          },
365202          "pedigree": {},
365203          "externalReferences": [
365204            {
365205              "url": "git+https://github.com/felixfbecker/iterare.git",
365206              "type": "distribution"
365207            },
365208            {
365209              "url": "https://github.com/felixfbecker/iterare#readme",
365210              "type": "website"
365211            }
365212          ],
365213          "evidence": {},
365214          "signature": {
365215            "signature": {
365216              "publicKey": {}
365217            }
365218          },
365219          "modelCard": {
365220            "modelParameters": {
365221              "approach": {}
365222            },
365223            "quantitativeAnalysis": {
365224              "graphics": {}
365225            },
365226            "considerations": {}
365227          }
365228        },
365229        {
365230          "type": "library",
365231          "bom-ref": "pkg:npm/jsbn@0.1.1?package-id=c1d64005f57cac41",
365232          "supplier": {},
365233          "author": "Tom Wu",
365234          "name": "jsbn",
365235          "version": "0.1.1",
365236          "description": "The jsbn library is a fast, portable implementation of large-number math in pure JavaScript, enabling public-key crypto and other applications on desktop and mobile browsers.",
365237          "licenses": [
365238            {
365239              "license": {
365240                "id": "MIT"
365241              }
365242            }
365243          ],
365244          "cpe": "cpe:2.3:a:andyperlitch:jsbn:0.1.1:*:*:*:*:*:*:*",
365245          "purl": "pkg:npm/jsbn@0.1.1",
365246          "swid": {
365247            "attachment": {}
365248          },
365249          "pedigree": {},
365250          "externalReferences": [
365251            {
365252              "url": "git+https://github.com/andyperlitch/jsbn.git",
365253              "type": "distribution"
365254            },
365255            {
365256              "url": "https://github.com/andyperlitch/jsbn#readme",
365257              "type": "website"
365258            }
365259          ],
365260          "evidence": {},
365261          "signature": {
365262            "signature": {
365263              "publicKey": {}
365264            }
365265          },
365266          "modelCard": {
365267            "modelParameters": {
365268              "approach": {}
365269            },
365270            "quantitativeAnalysis": {
365271              "graphics": {}
365272            },
365273            "considerations": {}
365274          }
365275        },
365276        {
365277          "type": "library",
365278          "bom-ref": "pkg:npm/jsbn@0.1.1?package-id=5423bb90883d31d3",
365279          "supplier": {},
365280          "author": "Tom Wu",
365281          "name": "jsbn",
365282          "version": "0.1.1",
365283          "description": "The jsbn library is a fast, portable implementation of large-number math in pure JavaScript, enabling public-key crypto and other applications on desktop and mobile browsers.",
365284          "licenses": [
365285            {
365286              "license": {
365287                "id": "MIT"
365288              }
365289            }
365290          ],
365291          "cpe": "cpe:2.3:a:andyperlitch:jsbn:0.1.1:*:*:*:*:*:*:*",
365292          "purl": "pkg:npm/jsbn@0.1.1",
365293          "swid": {
365294            "attachment": {}
365295          },
365296          "pedigree": {},
365297          "externalReferences": [
365298            {
365299              "url": "git+https://github.com/andyperlitch/jsbn.git",
365300              "type": "distribution"
365301            },
365302            {
365303              "url": "https://github.com/andyperlitch/jsbn#readme",
365304              "type": "website"
365305            }
365306          ],
365307          "evidence": {},
365308          "signature": {
365309            "signature": {
365310              "publicKey": {}
365311            }
365312          },
365313          "modelCard": {
365314            "modelParameters": {
365315              "approach": {}
365316            },
365317            "quantitativeAnalysis": {
365318              "graphics": {}
365319            },
365320            "considerations": {}
365321          }
365322        },
365323        {
365324          "type": "library",
365325          "bom-ref": "pkg:npm/json-parse-better-errors@1.0.2?package-id=988410d00081283c",
365326          "supplier": {},
365327          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
365328          "name": "json-parse-better-errors",
365329          "version": "1.0.2",
365330          "description": "JSON.parse with context information on error",
365331          "licenses": [
365332            {
365333              "license": {
365334                "id": "MIT"
365335              }
365336            }
365337          ],
365338          "cpe": "cpe:2.3:a:json-parse-better-errors:json-parse-better-errors:1.0.2:*:*:*:*:*:*:*",
365339          "purl": "pkg:npm/json-parse-better-errors@1.0.2",
365340          "swid": {
365341            "attachment": {}
365342          },
365343          "pedigree": {},
365344          "externalReferences": [
365345            {
365346              "url": "git+https://github.com/zkat/json-parse-better-errors.git",
365347              "type": "distribution"
365348            },
365349            {
365350              "url": "https://github.com/zkat/json-parse-better-errors#readme",
365351              "type": "website"
365352            }
365353          ],
365354          "evidence": {},
365355          "signature": {
365356            "signature": {
365357              "publicKey": {}
365358            }
365359          },
365360          "modelCard": {
365361            "modelParameters": {
365362              "approach": {}
365363            },
365364            "quantitativeAnalysis": {
365365              "graphics": {}
365366            },
365367            "considerations": {}
365368          }
365369        },
365370        {
365371          "type": "library",
365372          "bom-ref": "pkg:npm/json-parse-even-better-errors@2.3.1?package-id=e3a4f4f6a9d728a1",
365373          "supplier": {},
365374          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
365375          "name": "json-parse-even-better-errors",
365376          "version": "2.3.1",
365377          "description": "JSON.parse with context information on error",
365378          "licenses": [
365379            {
365380              "license": {
365381                "id": "MIT"
365382              }
365383            }
365384          ],
365385          "cpe": "cpe:2.3:a:json-parse-even-better-errors:json-parse-even-better-errors:2.3.1:*:*:*:*:*:*:*",
365386          "purl": "pkg:npm/json-parse-even-better-errors@2.3.1",
365387          "swid": {
365388            "attachment": {}
365389          },
365390          "pedigree": {},
365391          "externalReferences": [
365392            {
365393              "url": "git+https://github.com/npm/json-parse-even-better-errors.git",
365394              "type": "distribution"
365395            },
365396            {
365397              "url": "https://github.com/npm/json-parse-even-better-errors#readme",
365398              "type": "website"
365399            }
365400          ],
365401          "evidence": {},
365402          "signature": {
365403            "signature": {
365404              "publicKey": {}
365405            }
365406          },
365407          "modelCard": {
365408            "modelParameters": {
365409              "approach": {}
365410            },
365411            "quantitativeAnalysis": {
365412              "graphics": {}
365413            },
365414            "considerations": {}
365415          }
365416        },
365417        {
365418          "type": "library",
365419          "bom-ref": "pkg:npm/json-schema@0.2.3?package-id=234e47fff2e6bdb1",
365420          "supplier": {},
365421          "author": "Kris Zyp",
365422          "name": "json-schema",
365423          "version": "0.2.3",
365424          "description": "JSON Schema validation and specifications",
365425          "licenses": [
365426            {
365427              "license": {
365428                "name": "AFLv2.1"
365429              }
365430            },
365431            {
365432              "license": {
365433                "name": "BSD"
365434              }
365435            }
365436          ],
365437          "cpe": "cpe:2.3:a:json-schema:json-schema:0.2.3:*:*:*:*:*:*:*",
365438          "purl": "pkg:npm/json-schema@0.2.3",
365439          "swid": {
365440            "attachment": {}
365441          },
365442          "pedigree": {},
365443          "externalReferences": [
365444            {
365445              "url": "git+ssh://git@github.com/kriszyp/json-schema.git",
365446              "type": "distribution"
365447            },
365448            {
365449              "url": "https://github.com/kriszyp/json-schema#readme",
365450              "type": "website"
365451            }
365452          ],
365453          "evidence": {},
365454          "signature": {
365455            "signature": {
365456              "publicKey": {}
365457            }
365458          },
365459          "modelCard": {
365460            "modelParameters": {
365461              "approach": {}
365462            },
365463            "quantitativeAnalysis": {
365464              "graphics": {}
365465            },
365466            "considerations": {}
365467          }
365468        },
365469        {
365470          "type": "library",
365471          "bom-ref": "pkg:npm/json-schema@0.4.0?package-id=45c9a86c44dd53da",
365472          "supplier": {},
365473          "author": "Kris Zyp",
365474          "name": "json-schema",
365475          "version": "0.4.0",
365476          "description": "JSON Schema validation and specifications",
365477          "licenses": [
365478            {
365479              "license": {
365480                "name": "(AFL-2.1 OR BSD-3-Clause)"
365481              }
365482            }
365483          ],
365484          "cpe": "cpe:2.3:a:json-schema:json-schema:0.4.0:*:*:*:*:*:*:*",
365485          "purl": "pkg:npm/json-schema@0.4.0",
365486          "swid": {
365487            "attachment": {}
365488          },
365489          "pedigree": {},
365490          "externalReferences": [
365491            {
365492              "url": "git+ssh://git@github.com/kriszyp/json-schema.git",
365493              "type": "distribution"
365494            },
365495            {
365496              "url": "https://github.com/kriszyp/json-schema#readme",
365497              "type": "website"
365498            }
365499          ],
365500          "evidence": {},
365501          "signature": {
365502            "signature": {
365503              "publicKey": {}
365504            }
365505          },
365506          "modelCard": {
365507            "modelParameters": {
365508              "approach": {}
365509            },
365510            "quantitativeAnalysis": {
365511              "graphics": {}
365512            },
365513            "considerations": {}
365514          }
365515        },
365516        {
365517          "type": "library",
365518          "bom-ref": "pkg:npm/json-schema-traverse@0.4.1?package-id=285c4d6d5ff842",
365519          "supplier": {},
365520          "author": "Evgeny Poberezkin",
365521          "name": "json-schema-traverse",
365522          "version": "0.4.1",
365523          "description": "Traverse JSON Schema passing each schema object to callback",
365524          "licenses": [
365525            {
365526              "license": {
365527                "id": "MIT"
365528              }
365529            }
365530          ],
365531          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:0.4.1:*:*:*:*:*:*:*",
365532          "purl": "pkg:npm/json-schema-traverse@0.4.1",
365533          "swid": {
365534            "attachment": {}
365535          },
365536          "pedigree": {},
365537          "externalReferences": [
365538            {
365539              "url": "git+https://github.com/epoberezkin/json-schema-traverse.git",
365540              "type": "distribution"
365541            },
365542            {
365543              "url": "https://github.com/epoberezkin/json-schema-traverse#readme",
365544              "type": "website"
365545            }
365546          ],
365547          "evidence": {},
365548          "signature": {
365549            "signature": {
365550              "publicKey": {}
365551            }
365552          },
365553          "modelCard": {
365554            "modelParameters": {
365555              "approach": {}
365556            },
365557            "quantitativeAnalysis": {
365558              "graphics": {}
365559            },
365560            "considerations": {}
365561          }
365562        },
365563        {
365564          "type": "library",
365565          "bom-ref": "pkg:npm/json-schema-traverse@0.4.1?package-id=93d700e76c4d5de0",
365566          "supplier": {},
365567          "author": "Evgeny Poberezkin",
365568          "name": "json-schema-traverse",
365569          "version": "0.4.1",
365570          "description": "Traverse JSON Schema passing each schema object to callback",
365571          "licenses": [
365572            {
365573              "license": {
365574                "id": "MIT"
365575              }
365576            }
365577          ],
365578          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:0.4.1:*:*:*:*:*:*:*",
365579          "purl": "pkg:npm/json-schema-traverse@0.4.1",
365580          "swid": {
365581            "attachment": {}
365582          },
365583          "pedigree": {},
365584          "externalReferences": [
365585            {
365586              "url": "git+https://github.com/epoberezkin/json-schema-traverse.git",
365587              "type": "distribution"
365588            },
365589            {
365590              "url": "https://github.com/epoberezkin/json-schema-traverse#readme",
365591              "type": "website"
365592            }
365593          ],
365594          "evidence": {},
365595          "signature": {
365596            "signature": {
365597              "publicKey": {}
365598            }
365599          },
365600          "modelCard": {
365601            "modelParameters": {
365602              "approach": {}
365603            },
365604            "quantitativeAnalysis": {
365605              "graphics": {}
365606            },
365607            "considerations": {}
365608          }
365609        },
365610        {
365611          "type": "library",
365612          "bom-ref": "pkg:npm/json-stringify-safe@5.0.1?package-id=e5a8c4c13dc7283f",
365613          "supplier": {},
365614          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
365615          "name": "json-stringify-safe",
365616          "version": "5.0.1",
365617          "description": "Like JSON.stringify, but doesn't blow up on circular refs.",
365618          "licenses": [
365619            {
365620              "license": {
365621                "id": "ISC"
365622              }
365623            }
365624          ],
365625          "cpe": "cpe:2.3:a:json-stringify-safe:json-stringify-safe:5.0.1:*:*:*:*:*:*:*",
365626          "purl": "pkg:npm/json-stringify-safe@5.0.1",
365627          "swid": {
365628            "attachment": {}
365629          },
365630          "pedigree": {},
365631          "externalReferences": [
365632            {
365633              "url": "git://github.com/isaacs/json-stringify-safe.git",
365634              "type": "distribution"
365635            },
365636            {
365637              "url": "https://github.com/isaacs/json-stringify-safe",
365638              "type": "website"
365639            }
365640          ],
365641          "evidence": {},
365642          "signature": {
365643            "signature": {
365644              "publicKey": {}
365645            }
365646          },
365647          "modelCard": {
365648            "modelParameters": {
365649              "approach": {}
365650            },
365651            "quantitativeAnalysis": {
365652              "graphics": {}
365653            },
365654            "considerations": {}
365655          }
365656        },
365657        {
365658          "type": "library",
365659          "bom-ref": "pkg:npm/json-stringify-safe@5.0.1?package-id=1e6af39edc851fec",
365660          "supplier": {},
365661          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
365662          "name": "json-stringify-safe",
365663          "version": "5.0.1",
365664          "description": "Like JSON.stringify, but doesn't blow up on circular refs.",
365665          "licenses": [
365666            {
365667              "license": {
365668                "id": "ISC"
365669              }
365670            }
365671          ],
365672          "cpe": "cpe:2.3:a:json-stringify-safe:json-stringify-safe:5.0.1:*:*:*:*:*:*:*",
365673          "purl": "pkg:npm/json-stringify-safe@5.0.1",
365674          "swid": {
365675            "attachment": {}
365676          },
365677          "pedigree": {},
365678          "externalReferences": [
365679            {
365680              "url": "git://github.com/isaacs/json-stringify-safe.git",
365681              "type": "distribution"
365682            },
365683            {
365684              "url": "https://github.com/isaacs/json-stringify-safe",
365685              "type": "website"
365686            }
365687          ],
365688          "evidence": {},
365689          "signature": {
365690            "signature": {
365691              "publicKey": {}
365692            }
365693          },
365694          "modelCard": {
365695            "modelParameters": {
365696              "approach": {}
365697            },
365698            "quantitativeAnalysis": {
365699              "graphics": {}
365700            },
365701            "considerations": {}
365702          }
365703        },
365704        {
365705          "type": "library",
365706          "bom-ref": "pkg:npm/jsonparse@1.3.1?package-id=b1e13c9869e6a60e",
365707          "supplier": {},
365708          "author": "Tim Caswell \u003ctim@creationix.com\u003e",
365709          "name": "jsonparse",
365710          "version": "1.3.1",
365711          "description": "This is a pure-js JSON streaming parser for node.js",
365712          "licenses": [
365713            {
365714              "license": {
365715                "id": "MIT"
365716              }
365717            }
365718          ],
365719          "cpe": "cpe:2.3:a:creationix:jsonparse:1.3.1:*:*:*:*:*:*:*",
365720          "purl": "pkg:npm/jsonparse@1.3.1",
365721          "swid": {
365722            "attachment": {}
365723          },
365724          "pedigree": {},
365725          "externalReferences": [
365726            {
365727              "url": "git+ssh://git@github.com/creationix/jsonparse.git",
365728              "type": "distribution"
365729            },
365730            {
365731              "url": "https://github.com/creationix/jsonparse#readme",
365732              "type": "website"
365733            }
365734          ],
365735          "evidence": {},
365736          "signature": {
365737            "signature": {
365738              "publicKey": {}
365739            }
365740          },
365741          "modelCard": {
365742            "modelParameters": {
365743              "approach": {}
365744            },
365745            "quantitativeAnalysis": {
365746              "graphics": {}
365747            },
365748            "considerations": {}
365749          }
365750        },
365751        {
365752          "type": "library",
365753          "bom-ref": "pkg:npm/jsonwebtoken@8.5.1?package-id=b3e48ce9623ce630",
365754          "supplier": {},
365755          "author": "auth0",
365756          "name": "jsonwebtoken",
365757          "version": "8.5.1",
365758          "description": "JSON Web Token implementation (symmetric and asymmetric)",
365759          "licenses": [
365760            {
365761              "license": {
365762                "id": "MIT"
365763              }
365764            }
365765          ],
365766          "cpe": "cpe:2.3:a:jsonwebtoken:jsonwebtoken:8.5.1:*:*:*:*:*:*:*",
365767          "purl": "pkg:npm/jsonwebtoken@8.5.1",
365768          "swid": {
365769            "attachment": {}
365770          },
365771          "pedigree": {},
365772          "externalReferences": [
365773            {
365774              "url": "git+https://github.com/auth0/node-jsonwebtoken.git",
365775              "type": "distribution"
365776            },
365777            {
365778              "url": "https://github.com/auth0/node-jsonwebtoken#readme",
365779              "type": "website"
365780            }
365781          ],
365782          "evidence": {},
365783          "signature": {
365784            "signature": {
365785              "publicKey": {}
365786            }
365787          },
365788          "modelCard": {
365789            "modelParameters": {
365790              "approach": {}
365791            },
365792            "quantitativeAnalysis": {
365793              "graphics": {}
365794            },
365795            "considerations": {}
365796          }
365797        },
365798        {
365799          "type": "library",
365800          "bom-ref": "pkg:npm/jsprim@1.4.1?package-id=747de2b21741eefd",
365801          "supplier": {},
365802          "name": "jsprim",
365803          "version": "1.4.1",
365804          "description": "utilities for primitive JavaScript types",
365805          "licenses": [
365806            {
365807              "license": {
365808                "id": "MIT"
365809              }
365810            }
365811          ],
365812          "cpe": "cpe:2.3:a:joyent:jsprim:1.4.1:*:*:*:*:*:*:*",
365813          "purl": "pkg:npm/jsprim@1.4.1",
365814          "swid": {
365815            "attachment": {}
365816          },
365817          "pedigree": {},
365818          "externalReferences": [
365819            {
365820              "url": "git://github.com/joyent/node-jsprim.git",
365821              "type": "distribution"
365822            },
365823            {
365824              "url": "https://github.com/joyent/node-jsprim#readme",
365825              "type": "website"
365826            }
365827          ],
365828          "evidence": {},
365829          "signature": {
365830            "signature": {
365831              "publicKey": {}
365832            }
365833          },
365834          "modelCard": {
365835            "modelParameters": {
365836              "approach": {}
365837            },
365838            "quantitativeAnalysis": {
365839              "graphics": {}
365840            },
365841            "considerations": {}
365842          }
365843        },
365844        {
365845          "type": "library",
365846          "bom-ref": "pkg:npm/jsprim@1.4.2?package-id=1555634d1f1bf190",
365847          "supplier": {},
365848          "name": "jsprim",
365849          "version": "1.4.2",
365850          "description": "utilities for primitive JavaScript types",
365851          "licenses": [
365852            {
365853              "license": {
365854                "id": "MIT"
365855              }
365856            }
365857          ],
365858          "cpe": "cpe:2.3:a:joyent:jsprim:1.4.2:*:*:*:*:*:*:*",
365859          "purl": "pkg:npm/jsprim@1.4.2",
365860          "swid": {
365861            "attachment": {}
365862          },
365863          "pedigree": {},
365864          "externalReferences": [
365865            {
365866              "url": "git://github.com/joyent/node-jsprim.git",
365867              "type": "distribution"
365868            },
365869            {
365870              "url": "https://github.com/joyent/node-jsprim#readme",
365871              "type": "website"
365872            }
365873          ],
365874          "evidence": {},
365875          "signature": {
365876            "signature": {
365877              "publicKey": {}
365878            }
365879          },
365880          "modelCard": {
365881            "modelParameters": {
365882              "approach": {}
365883            },
365884            "quantitativeAnalysis": {
365885              "graphics": {}
365886            },
365887            "considerations": {}
365888          }
365889        },
365890        {
365891          "type": "library",
365892          "bom-ref": "pkg:npm/jwa@1.4.1?package-id=122db8bb4f546a61",
365893          "supplier": {},
365894          "author": "Brian J. Brennan \u003cbrianloveswords@gmail.com\u003e",
365895          "name": "jwa",
365896          "version": "1.4.1",
365897          "description": "JWA implementation (supports all JWS algorithms)",
365898          "licenses": [
365899            {
365900              "license": {
365901                "id": "MIT"
365902              }
365903            }
365904          ],
365905          "cpe": "cpe:2.3:a:brianloveswords:jwa:1.4.1:*:*:*:*:*:*:*",
365906          "purl": "pkg:npm/jwa@1.4.1",
365907          "swid": {
365908            "attachment": {}
365909          },
365910          "pedigree": {},
365911          "externalReferences": [
365912            {
365913              "url": "git://github.com/brianloveswords/node-jwa.git",
365914              "type": "distribution"
365915            },
365916            {
365917              "url": "https://github.com/brianloveswords/node-jwa#readme",
365918              "type": "website"
365919            }
365920          ],
365921          "evidence": {},
365922          "signature": {
365923            "signature": {
365924              "publicKey": {}
365925            }
365926          },
365927          "modelCard": {
365928            "modelParameters": {
365929              "approach": {}
365930            },
365931            "quantitativeAnalysis": {
365932              "graphics": {}
365933            },
365934            "considerations": {}
365935          }
365936        },
365937        {
365938          "type": "library",
365939          "bom-ref": "pkg:npm/jws@3.2.2?package-id=51d56ae8e8bad5c9",
365940          "supplier": {},
365941          "author": "Brian J Brennan",
365942          "name": "jws",
365943          "version": "3.2.2",
365944          "description": "Implementation of JSON Web Signatures",
365945          "licenses": [
365946            {
365947              "license": {
365948                "id": "MIT"
365949              }
365950            }
365951          ],
365952          "cpe": "cpe:2.3:a:brianloveswords:jws:3.2.2:*:*:*:*:*:*:*",
365953          "purl": "pkg:npm/jws@3.2.2",
365954          "swid": {
365955            "attachment": {}
365956          },
365957          "pedigree": {},
365958          "externalReferences": [
365959            {
365960              "url": "git://github.com/brianloveswords/node-jws.git",
365961              "type": "distribution"
365962            },
365963            {
365964              "url": "https://github.com/brianloveswords/node-jws#readme",
365965              "type": "website"
365966            }
365967          ],
365968          "evidence": {},
365969          "signature": {
365970            "signature": {
365971              "publicKey": {}
365972            }
365973          },
365974          "modelCard": {
365975            "modelParameters": {
365976              "approach": {}
365977            },
365978            "quantitativeAnalysis": {
365979              "graphics": {}
365980            },
365981            "considerations": {}
365982          }
365983        },
365984        {
365985          "type": "library",
365986          "bom-ref": "pkg:npm/latest-version@3.1.0?package-id=112a46fc0e19bff6",
365987          "supplier": {},
365988          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
365989          "name": "latest-version",
365990          "version": "3.1.0",
365991          "description": "Get the latest version of an npm package",
365992          "licenses": [
365993            {
365994              "license": {
365995                "id": "MIT"
365996              }
365997            }
365998          ],
365999          "cpe": "cpe:2.3:a:latest-version:latest-version:3.1.0:*:*:*:*:*:*:*",
366000          "purl": "pkg:npm/latest-version@3.1.0",
366001          "swid": {
366002            "attachment": {}
366003          },
366004          "pedigree": {},
366005          "externalReferences": [
366006            {
366007              "url": "git+https://github.com/sindresorhus/latest-version.git",
366008              "type": "distribution"
366009            },
366010            {
366011              "url": "https://github.com/sindresorhus/latest-version#readme",
366012              "type": "website"
366013            }
366014          ],
366015          "evidence": {},
366016          "signature": {
366017            "signature": {
366018              "publicKey": {}
366019            }
366020          },
366021          "modelCard": {
366022            "modelParameters": {
366023              "approach": {}
366024            },
366025            "quantitativeAnalysis": {
366026              "graphics": {}
366027            },
366028            "considerations": {}
366029          }
366030        },
366031        {
366032          "type": "library",
366033          "bom-ref": "pkg:npm/lazy-property@1.0.0?package-id=3cdbabf15e025def",
366034          "supplier": {},
366035          "author": "Mikola Lysenko",
366036          "name": "lazy-property",
366037          "version": "1.0.0",
366038          "description": "Lazily initialized properties for objects",
366039          "licenses": [
366040            {
366041              "license": {
366042                "id": "MIT"
366043              }
366044            }
366045          ],
366046          "cpe": "cpe:2.3:a:lazy-property:lazy-property:1.0.0:*:*:*:*:*:*:*",
366047          "purl": "pkg:npm/lazy-property@1.0.0",
366048          "swid": {
366049            "attachment": {}
366050          },
366051          "pedigree": {},
366052          "externalReferences": [
366053            {
366054              "url": "git://github.com/mikolalysenko/lazy-property.git",
366055              "type": "distribution"
366056            },
366057            {
366058              "url": "https://github.com/mikolalysenko/lazy-property#readme",
366059              "type": "website"
366060            }
366061          ],
366062          "evidence": {},
366063          "signature": {
366064            "signature": {
366065              "publicKey": {}
366066            }
366067          },
366068          "modelCard": {
366069            "modelParameters": {
366070              "approach": {}
366071            },
366072            "quantitativeAnalysis": {
366073              "graphics": {}
366074            },
366075            "considerations": {}
366076          }
366077        },
366078        {
366079          "type": "library",
366080          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.3\u0026package-id=8126b232e2d3c608",
366081          "supplier": {},
366082          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
366083          "name": "libc-utils",
366084          "version": "0.7.2-r3",
366085          "description": "Meta package to pull in correct libc",
366086          "licenses": [
366087            {
366088              "license": {
366089                "id": "BSD-2-Clause"
366090              }
366091            },
366092            {
366093              "license": {
366094                "name": "AND"
366095              }
366096            },
366097            {
366098              "license": {
366099                "id": "BSD-3-Clause"
366100              }
366101            }
366102          ],
366103          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
366104          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.17.3",
366105          "swid": {
366106            "attachment": {}
366107          },
366108          "pedigree": {},
366109          "externalReferences": [
366110            {
366111              "url": "https://alpinelinux.org",
366112              "type": "distribution"
366113            }
366114          ],
366115          "evidence": {},
366116          "signature": {
366117            "signature": {
366118              "publicKey": {}
366119            }
366120          },
366121          "modelCard": {
366122            "modelParameters": {
366123              "approach": {}
366124            },
366125            "quantitativeAnalysis": {
366126              "graphics": {}
366127            },
366128            "considerations": {}
366129          }
366130        },
366131        {
366132          "type": "library",
366133          "bom-ref": "pkg:npm/libcipm@4.0.8?package-id=939bd2c33a65cf65",
366134          "supplier": {},
366135          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
366136          "name": "libcipm",
366137          "version": "4.0.8",
366138          "description": "programmatic API for cipm: a ci-oriented package installer for npm",
366139          "licenses": [
366140            {
366141              "license": {
366142                "id": "MIT"
366143              }
366144            }
366145          ],
366146          "cpe": "cpe:2.3:a:libcipm:libcipm:4.0.8:*:*:*:*:*:*:*",
366147          "purl": "pkg:npm/libcipm@4.0.8",
366148          "swid": {
366149            "attachment": {}
366150          },
366151          "pedigree": {},
366152          "externalReferences": [
366153            {
366154              "url": "git+https://github.com/npm/libcipm.git",
366155              "type": "distribution"
366156            },
366157            {
366158              "url": "https://github.com/npm/libcipm#readme",
366159              "type": "website"
366160            }
366161          ],
366162          "evidence": {},
366163          "signature": {
366164            "signature": {
366165              "publicKey": {}
366166            }
366167          },
366168          "modelCard": {
366169            "modelParameters": {
366170              "approach": {}
366171            },
366172            "quantitativeAnalysis": {
366173              "graphics": {}
366174            },
366175            "considerations": {}
366176          }
366177        },
366178        {
366179          "type": "library",
366180          "bom-ref": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3\u0026package-id=d3084c788891fb28",
366181          "supplier": {},
366182          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
366183          "name": "libcrypto3",
366184          "version": "3.0.8-r3",
366185          "description": "Crypto library from openssl",
366186          "licenses": [
366187            {
366188              "license": {
366189                "id": "Apache-2.0"
366190              }
366191            }
366192          ],
366193          "cpe": "cpe:2.3:a:libcrypto3:libcrypto3:3.0.8-r3:*:*:*:*:*:*:*",
366194          "purl": "pkg:apk/alpine/libcrypto3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3",
366195          "swid": {
366196            "attachment": {}
366197          },
366198          "pedigree": {},
366199          "externalReferences": [
366200            {
366201              "url": "https://www.openssl.org/",
366202              "type": "distribution"
366203            }
366204          ],
366205          "evidence": {},
366206          "signature": {
366207            "signature": {
366208              "publicKey": {}
366209            }
366210          },
366211          "modelCard": {
366212            "modelParameters": {
366213              "approach": {}
366214            },
366215            "quantitativeAnalysis": {
366216              "graphics": {}
366217            },
366218            "considerations": {}
366219          }
366220        },
366221        {
366222          "type": "library",
366223          "bom-ref": "pkg:apk/alpine/libgcc@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.3\u0026package-id=4dbb63d06d9618e9",
366224          "supplier": {},
366225          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
366226          "name": "libgcc",
366227          "version": "12.2.1_git20220924-r4",
366228          "description": "GNU C compiler runtime libraries",
366229          "licenses": [
366230            {
366231              "license": {
366232                "id": "GPL-2.0-or-later"
366233              }
366234            },
366235            {
366236              "license": {
366237                "id": "LGPL-2.1-or-later"
366238              }
366239            }
366240          ],
366241          "cpe": "cpe:2.3:a:libgcc:libgcc:12.2.1_git20220924-r4:*:*:*:*:*:*:*",
366242          "purl": "pkg:apk/alpine/libgcc@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.3",
366243          "swid": {
366244            "attachment": {}
366245          },
366246          "pedigree": {},
366247          "externalReferences": [
366248            {
366249              "url": "https://gcc.gnu.org",
366250              "type": "distribution"
366251            }
366252          ],
366253          "evidence": {},
366254          "signature": {
366255            "signature": {
366256              "publicKey": {}
366257            }
366258          },
366259          "modelCard": {
366260            "modelParameters": {
366261              "approach": {}
366262            },
366263            "quantitativeAnalysis": {
366264              "graphics": {}
366265            },
366266            "considerations": {}
366267          }
366268        },
366269        {
366270          "type": "library",
366271          "bom-ref": "pkg:npm/libnpm@3.0.1?package-id=8765b2a6f6c0fa16",
366272          "supplier": {},
366273          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
366274          "name": "libnpm",
366275          "version": "3.0.1",
366276          "description": "Collection of programmatic APIs for the npm CLI",
366277          "licenses": [
366278            {
366279              "license": {
366280                "id": "ISC"
366281              }
366282            }
366283          ],
366284          "cpe": "cpe:2.3:a:libnpm:libnpm:3.0.1:*:*:*:*:*:*:*",
366285          "purl": "pkg:npm/libnpm@3.0.1",
366286          "swid": {
366287            "attachment": {}
366288          },
366289          "pedigree": {},
366290          "externalReferences": [
366291            {
366292              "url": "git+https://github.com/npm/libnpm.git",
366293              "type": "distribution"
366294            },
366295            {
366296              "url": "https://github.com/npm/libnpm#readme",
366297              "type": "website"
366298            }
366299          ],
366300          "evidence": {},
366301          "signature": {
366302            "signature": {
366303              "publicKey": {}
366304            }
366305          },
366306          "modelCard": {
366307            "modelParameters": {
366308              "approach": {}
366309            },
366310            "quantitativeAnalysis": {
366311              "graphics": {}
366312            },
366313            "considerations": {}
366314          }
366315        },
366316        {
366317          "type": "library",
366318          "bom-ref": "pkg:npm/libnpmaccess@3.0.2?package-id=5341f660eccfba6b",
366319          "supplier": {},
366320          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
366321          "name": "libnpmaccess",
366322          "version": "3.0.2",
366323          "description": "programmatic library for `npm access` commands",
366324          "licenses": [
366325            {
366326              "license": {
366327                "id": "ISC"
366328              }
366329            }
366330          ],
366331          "cpe": "cpe:2.3:a:libnpmaccess:libnpmaccess:3.0.2:*:*:*:*:*:*:*",
366332          "purl": "pkg:npm/libnpmaccess@3.0.2",
366333          "swid": {
366334            "attachment": {}
366335          },
366336          "pedigree": {},
366337          "externalReferences": [
366338            {
366339              "url": "git+https://github.com/npm/libnpmaccess.git",
366340              "type": "distribution"
366341            },
366342            {
366343              "url": "https://npmjs.com/package/libnpmaccess",
366344              "type": "website"
366345            }
366346          ],
366347          "evidence": {},
366348          "signature": {
366349            "signature": {
366350              "publicKey": {}
366351            }
366352          },
366353          "modelCard": {
366354            "modelParameters": {
366355              "approach": {}
366356            },
366357            "quantitativeAnalysis": {
366358              "graphics": {}
366359            },
366360            "considerations": {}
366361          }
366362        },
366363        {
366364          "type": "library",
366365          "bom-ref": "pkg:npm/libnpmconfig@1.2.1?package-id=db2a17ecbb5c09ba",
366366          "supplier": {},
366367          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
366368          "name": "libnpmconfig",
366369          "version": "1.2.1",
366370          "description": "Standalone library for reading/writing/managing npm configurations",
366371          "licenses": [
366372            {
366373              "license": {
366374                "id": "ISC"
366375              }
366376            }
366377          ],
366378          "cpe": "cpe:2.3:a:libnpmconfig:libnpmconfig:1.2.1:*:*:*:*:*:*:*",
366379          "purl": "pkg:npm/libnpmconfig@1.2.1",
366380          "swid": {
366381            "attachment": {}
366382          },
366383          "pedigree": {},
366384          "externalReferences": [
366385            {
366386              "url": "git+https://github.com/npm/libnpmconfig.git",
366387              "type": "distribution"
366388            },
366389            {
366390              "url": "https://npmjs.com/package/libnpmconfig",
366391              "type": "website"
366392            }
366393          ],
366394          "evidence": {},
366395          "signature": {
366396            "signature": {
366397              "publicKey": {}
366398            }
366399          },
366400          "modelCard": {
366401            "modelParameters": {
366402              "approach": {}
366403            },
366404            "quantitativeAnalysis": {
366405              "graphics": {}
366406            },
366407            "considerations": {}
366408          }
366409        },
366410        {
366411          "type": "library",
366412          "bom-ref": "pkg:npm/libnpmhook@5.0.3?package-id=15a009beffa78fc4",
366413          "supplier": {},
366414          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
366415          "name": "libnpmhook",
366416          "version": "5.0.3",
366417          "description": "programmatic API for managing npm registry hooks",
366418          "licenses": [
366419            {
366420              "license": {
366421                "id": "ISC"
366422              }
366423            }
366424          ],
366425          "cpe": "cpe:2.3:a:libnpmhook:libnpmhook:5.0.3:*:*:*:*:*:*:*",
366426          "purl": "pkg:npm/libnpmhook@5.0.3",
366427          "swid": {
366428            "attachment": {}
366429          },
366430          "pedigree": {},
366431          "externalReferences": [
366432            {
366433              "url": "git+https://github.com/npm/libnpmhook.git",
366434              "type": "distribution"
366435            },
366436            {
366437              "url": "https://github.com/npm/libnpmhook#readme",
366438              "type": "website"
366439            }
366440          ],
366441          "evidence": {},
366442          "signature": {
366443            "signature": {
366444              "publicKey": {}
366445            }
366446          },
366447          "modelCard": {
366448            "modelParameters": {
366449              "approach": {}
366450            },
366451            "quantitativeAnalysis": {
366452              "graphics": {}
366453            },
366454            "considerations": {}
366455          }
366456        },
366457        {
366458          "type": "library",
366459          "bom-ref": "pkg:npm/libnpmorg@1.0.1?package-id=8b6fdd9d34b188a7",
366460          "supplier": {},
366461          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
366462          "name": "libnpmorg",
366463          "version": "1.0.1",
366464          "description": "Programmatic api for `npm org` commands",
366465          "licenses": [
366466            {
366467              "license": {
366468                "id": "ISC"
366469              }
366470            }
366471          ],
366472          "cpe": "cpe:2.3:a:libnpmorg:libnpmorg:1.0.1:*:*:*:*:*:*:*",
366473          "purl": "pkg:npm/libnpmorg@1.0.1",
366474          "swid": {
366475            "attachment": {}
366476          },
366477          "pedigree": {},
366478          "externalReferences": [
366479            {
366480              "url": "git+https://github.com/npm/libnpmorg.git",
366481              "type": "distribution"
366482            },
366483            {
366484              "url": "https://npmjs.com/package/libnpmorg",
366485              "type": "website"
366486            }
366487          ],
366488          "evidence": {},
366489          "signature": {
366490            "signature": {
366491              "publicKey": {}
366492            }
366493          },
366494          "modelCard": {
366495            "modelParameters": {
366496              "approach": {}
366497            },
366498            "quantitativeAnalysis": {
366499              "graphics": {}
366500            },
366501            "considerations": {}
366502          }
366503        },
366504        {
366505          "type": "library",
366506          "bom-ref": "pkg:npm/libnpmpublish@1.1.2?package-id=4940e26c16b646a2",
366507          "supplier": {},
366508          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
366509          "name": "libnpmpublish",
366510          "version": "1.1.2",
366511          "description": "Programmatic API for the bits behind npm publish and unpublish",
366512          "licenses": [
366513            {
366514              "license": {
366515                "id": "ISC"
366516              }
366517            }
366518          ],
366519          "cpe": "cpe:2.3:a:libnpmpublish:libnpmpublish:1.1.2:*:*:*:*:*:*:*",
366520          "purl": "pkg:npm/libnpmpublish@1.1.2",
366521          "swid": {
366522            "attachment": {}
366523          },
366524          "pedigree": {},
366525          "externalReferences": [
366526            {
366527              "url": "git+https://github.com/npm/libnpmpublish.git",
366528              "type": "distribution"
366529            },
366530            {
366531              "url": "https://npmjs.com/package/libnpmpublish",
366532              "type": "website"
366533            }
366534          ],
366535          "evidence": {},
366536          "signature": {
366537            "signature": {
366538              "publicKey": {}
366539            }
366540          },
366541          "modelCard": {
366542            "modelParameters": {
366543              "approach": {}
366544            },
366545            "quantitativeAnalysis": {
366546              "graphics": {}
366547            },
366548            "considerations": {}
366549          }
366550        },
366551        {
366552          "type": "library",
366553          "bom-ref": "pkg:npm/libnpmsearch@2.0.2?package-id=4152eb0fada08f68",
366554          "supplier": {},
366555          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
366556          "name": "libnpmsearch",
366557          "version": "2.0.2",
366558          "description": "Programmatic API for searching in npm and compatible registries.",
366559          "licenses": [
366560            {
366561              "license": {
366562                "id": "ISC"
366563              }
366564            }
366565          ],
366566          "cpe": "cpe:2.3:a:libnpmsearch:libnpmsearch:2.0.2:*:*:*:*:*:*:*",
366567          "purl": "pkg:npm/libnpmsearch@2.0.2",
366568          "swid": {
366569            "attachment": {}
366570          },
366571          "pedigree": {},
366572          "externalReferences": [
366573            {
366574              "url": "git+https://github.com/npm/libnpmsearch.git",
366575              "type": "distribution"
366576            },
366577            {
366578              "url": "https://npmjs.com/package/libnpmsearch",
366579              "type": "website"
366580            }
366581          ],
366582          "evidence": {},
366583          "signature": {
366584            "signature": {
366585              "publicKey": {}
366586            }
366587          },
366588          "modelCard": {
366589            "modelParameters": {
366590              "approach": {}
366591            },
366592            "quantitativeAnalysis": {
366593              "graphics": {}
366594            },
366595            "considerations": {}
366596          }
366597        },
366598        {
366599          "type": "library",
366600          "bom-ref": "pkg:npm/libnpmteam@1.0.2?package-id=ab825ae6bda4b852",
366601          "supplier": {},
366602          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
366603          "name": "libnpmteam",
366604          "version": "1.0.2",
366605          "description": "npm Team management APIs",
366606          "licenses": [
366607            {
366608              "license": {
366609                "id": "ISC"
366610              }
366611            }
366612          ],
366613          "cpe": "cpe:2.3:a:libnpmteam:libnpmteam:1.0.2:*:*:*:*:*:*:*",
366614          "purl": "pkg:npm/libnpmteam@1.0.2",
366615          "swid": {
366616            "attachment": {}
366617          },
366618          "pedigree": {},
366619          "externalReferences": [
366620            {
366621              "url": "git+https://github.com/npm/libnpmteam.git",
366622              "type": "distribution"
366623            },
366624            {
366625              "url": "https://npmjs.com/package/libnpmteam",
366626              "type": "website"
366627            }
366628          ],
366629          "evidence": {},
366630          "signature": {
366631            "signature": {
366632              "publicKey": {}
366633            }
366634          },
366635          "modelCard": {
366636            "modelParameters": {
366637              "approach": {}
366638            },
366639            "quantitativeAnalysis": {
366640              "graphics": {}
366641            },
366642            "considerations": {}
366643          }
366644        },
366645        {
366646          "type": "library",
366647          "bom-ref": "pkg:npm/libnpx@10.2.4?package-id=670932cf0842993",
366648          "supplier": {},
366649          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
366650          "name": "libnpx",
366651          "version": "10.2.4",
366652          "description": "support library for npx -- an tool for executing npm-based packages.",
366653          "licenses": [
366654            {
366655              "license": {
366656                "id": "ISC"
366657              }
366658            }
366659          ],
366660          "cpe": "cpe:2.3:a:libnpx:libnpx:10.2.4:*:*:*:*:*:*:*",
366661          "purl": "pkg:npm/libnpx@10.2.4",
366662          "swid": {
366663            "attachment": {}
366664          },
366665          "pedigree": {},
366666          "externalReferences": [
366667            {
366668              "url": "git+https://github.com/npm/npx.git",
366669              "type": "distribution"
366670            },
366671            {
366672              "url": "https://github.com/npm/npx#readme",
366673              "type": "website"
366674            }
366675          ],
366676          "evidence": {},
366677          "signature": {
366678            "signature": {
366679              "publicKey": {}
366680            }
366681          },
366682          "modelCard": {
366683            "modelParameters": {
366684              "approach": {}
366685            },
366686            "quantitativeAnalysis": {
366687              "graphics": {}
366688            },
366689            "considerations": {}
366690          }
366691        },
366692        {
366693          "type": "library",
366694          "bom-ref": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3\u0026package-id=2a95f0251fba7a33",
366695          "supplier": {},
366696          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
366697          "name": "libssl3",
366698          "version": "3.0.8-r3",
366699          "description": "SSL shared libraries",
366700          "licenses": [
366701            {
366702              "license": {
366703                "id": "Apache-2.0"
366704              }
366705            }
366706          ],
366707          "cpe": "cpe:2.3:a:libssl3:libssl3:3.0.8-r3:*:*:*:*:*:*:*",
366708          "purl": "pkg:apk/alpine/libssl3@3.0.8-r3?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.17.3",
366709          "swid": {
366710            "attachment": {}
366711          },
366712          "pedigree": {},
366713          "externalReferences": [
366714            {
366715              "url": "https://www.openssl.org/",
366716              "type": "distribution"
366717            }
366718          ],
366719          "evidence": {},
366720          "signature": {
366721            "signature": {
366722              "publicKey": {}
366723            }
366724          },
366725          "modelCard": {
366726            "modelParameters": {
366727              "approach": {}
366728            },
366729            "quantitativeAnalysis": {
366730              "graphics": {}
366731            },
366732            "considerations": {}
366733          }
366734        },
366735        {
366736          "type": "library",
366737          "bom-ref": "pkg:apk/alpine/libstdc++@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.3\u0026package-id=3c33807c48d3ddd2",
366738          "supplier": {},
366739          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
366740          "name": "libstdc++",
366741          "version": "12.2.1_git20220924-r4",
366742          "description": "GNU C++ standard runtime library",
366743          "licenses": [
366744            {
366745              "license": {
366746                "id": "GPL-2.0-or-later"
366747              }
366748            },
366749            {
366750              "license": {
366751                "id": "LGPL-2.1-or-later"
366752              }
366753            }
366754          ],
366755          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:12.2.1_git20220924-r4:*:*:*:*:*:*:*",
366756          "purl": "pkg:apk/alpine/libstdc++@12.2.1_git20220924-r4?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.17.3",
366757          "swid": {
366758            "attachment": {}
366759          },
366760          "pedigree": {},
366761          "externalReferences": [
366762            {
366763              "url": "https://gcc.gnu.org",
366764              "type": "distribution"
366765            }
366766          ],
366767          "evidence": {},
366768          "signature": {
366769            "signature": {
366770              "publicKey": {}
366771            }
366772          },
366773          "modelCard": {
366774            "modelParameters": {
366775              "approach": {}
366776            },
366777            "quantitativeAnalysis": {
366778              "graphics": {}
366779            },
366780            "considerations": {}
366781          }
366782        },
366783        {
366784          "type": "library",
366785          "bom-ref": "pkg:npm/lightship@6.7.2?package-id=5af666ec0e8182cf",
366786          "supplier": {},
366787          "author": "Gajus Kuizinas \u003cgajus@gajus.com\u003e (http://gajus.com)",
366788          "name": "lightship",
366789          "version": "6.7.2",
366790          "description": "Abstracts readiness, liveness and startup checks and graceful shutdown of Node.js services running in Kubernetes.",
366791          "licenses": [
366792            {
366793              "license": {
366794                "id": "BSD-3-Clause"
366795              }
366796            }
366797          ],
366798          "cpe": "cpe:2.3:a:lightship:lightship:6.7.2:*:*:*:*:*:*:*",
366799          "purl": "pkg:npm/lightship@6.7.2",
366800          "swid": {
366801            "attachment": {}
366802          },
366803          "pedigree": {},
366804          "externalReferences": [
366805            {
366806              "url": "git+https://github.com/gajus/lightship.git",
366807              "type": "distribution"
366808            },
366809            {
366810              "url": "https://github.com/gajus/lightship#readme",
366811              "type": "website"
366812            }
366813          ],
366814          "evidence": {},
366815          "signature": {
366816            "signature": {
366817              "publicKey": {}
366818            }
366819          },
366820          "modelCard": {
366821            "modelParameters": {
366822              "approach": {}
366823            },
366824            "quantitativeAnalysis": {
366825              "graphics": {}
366826            },
366827            "considerations": {}
366828          }
366829        },
366830        {
366831          "type": "library",
366832          "bom-ref": "pkg:npm/locate-path@3.0.0?package-id=6a3c95978434a1d0",
366833          "supplier": {},
366834          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
366835          "name": "locate-path",
366836          "version": "3.0.0",
366837          "description": "Get the first path that exists on disk of multiple paths",
366838          "licenses": [
366839            {
366840              "license": {
366841                "id": "MIT"
366842              }
366843            }
366844          ],
366845          "cpe": "cpe:2.3:a:sindresorhus:locate-path:3.0.0:*:*:*:*:*:*:*",
366846          "purl": "pkg:npm/locate-path@3.0.0",
366847          "swid": {
366848            "attachment": {}
366849          },
366850          "pedigree": {},
366851          "externalReferences": [
366852            {
366853              "url": "git+https://github.com/sindresorhus/locate-path.git",
366854              "type": "distribution"
366855            },
366856            {
366857              "url": "https://github.com/sindresorhus/locate-path#readme",
366858              "type": "website"
366859            }
366860          ],
366861          "evidence": {},
366862          "signature": {
366863            "signature": {
366864              "publicKey": {}
366865            }
366866          },
366867          "modelCard": {
366868            "modelParameters": {
366869              "approach": {}
366870            },
366871            "quantitativeAnalysis": {
366872              "graphics": {}
366873            },
366874            "considerations": {}
366875          }
366876        },
366877        {
366878          "type": "library",
366879          "bom-ref": "pkg:npm/locate-path@3.0.0?package-id=e9f822cde2a9982c",
366880          "supplier": {},
366881          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
366882          "name": "locate-path",
366883          "version": "3.0.0",
366884          "description": "Get the first path that exists on disk of multiple paths",
366885          "licenses": [
366886            {
366887              "license": {
366888                "id": "MIT"
366889              }
366890            }
366891          ],
366892          "cpe": "cpe:2.3:a:sindresorhus:locate-path:3.0.0:*:*:*:*:*:*:*",
366893          "purl": "pkg:npm/locate-path@3.0.0",
366894          "swid": {
366895            "attachment": {}
366896          },
366897          "pedigree": {},
366898          "externalReferences": [
366899            {
366900              "url": "git+https://github.com/sindresorhus/locate-path.git",
366901              "type": "distribution"
366902            },
366903            {
366904              "url": "https://github.com/sindresorhus/locate-path#readme",
366905              "type": "website"
366906            }
366907          ],
366908          "evidence": {},
366909          "signature": {
366910            "signature": {
366911              "publicKey": {}
366912            }
366913          },
366914          "modelCard": {
366915            "modelParameters": {
366916              "approach": {}
366917            },
366918            "quantitativeAnalysis": {
366919              "graphics": {}
366920            },
366921            "considerations": {}
366922          }
366923        },
366924        {
366925          "type": "library",
366926          "bom-ref": "pkg:npm/lock-verify@2.2.2?package-id=dd47271ff433350c",
366927          "supplier": {},
366928          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
366929          "name": "lock-verify",
366930          "version": "2.2.2",
366931          "description": "Report if your package.json is out of sync with your package-lock.json.",
366932          "licenses": [
366933            {
366934              "license": {
366935                "id": "ISC"
366936              }
366937            }
366938          ],
366939          "cpe": "cpe:2.3:a:lock-verify:lock-verify:2.2.2:*:*:*:*:*:*:*",
366940          "purl": "pkg:npm/lock-verify@2.2.2",
366941          "swid": {
366942            "attachment": {}
366943          },
366944          "pedigree": {},
366945          "externalReferences": [
366946            {
366947              "url": "git+https://github.com/npm/lock-verify.git",
366948              "type": "distribution"
366949            },
366950            {
366951              "url": "https://github.com/npm/lock-verify#readme",
366952              "type": "website"
366953            }
366954          ],
366955          "evidence": {},
366956          "signature": {
366957            "signature": {
366958              "publicKey": {}
366959            }
366960          },
366961          "modelCard": {
366962            "modelParameters": {
366963              "approach": {}
366964            },
366965            "quantitativeAnalysis": {
366966              "graphics": {}
366967            },
366968            "considerations": {}
366969          }
366970        },
366971        {
366972          "type": "library",
366973          "bom-ref": "pkg:npm/lockfile@1.0.4?package-id=ebdf70a73ac68f2d",
366974          "supplier": {},
366975          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
366976          "name": "lockfile",
366977          "version": "1.0.4",
366978          "description": "A very polite lock file utility, which endeavors to not litter, and to wait patiently for others.",
366979          "licenses": [
366980            {
366981              "license": {
366982                "id": "ISC"
366983              }
366984            }
366985          ],
366986          "cpe": "cpe:2.3:a:lockfile:lockfile:1.0.4:*:*:*:*:*:*:*",
366987          "purl": "pkg:npm/lockfile@1.0.4",
366988          "swid": {
366989            "attachment": {}
366990          },
366991          "pedigree": {},
366992          "externalReferences": [
366993            {
366994              "url": "git+https://github.com/npm/lockfile.git",
366995              "type": "distribution"
366996            },
366997            {
366998              "url": "https://github.com/npm/lockfile#readme",
366999              "type": "website"
367000            }
367001          ],
367002          "evidence": {},
367003          "signature": {
367004            "signature": {
367005              "publicKey": {}
367006            }
367007          },
367008          "modelCard": {
367009            "modelParameters": {
367010              "approach": {}
367011            },
367012            "quantitativeAnalysis": {
367013              "graphics": {}
367014            },
367015            "considerations": {}
367016          }
367017        },
367018        {
367019          "type": "library",
367020          "bom-ref": "pkg:npm/lodash@4.17.21?package-id=7618d12e7ca896e",
367021          "supplier": {},
367022          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e",
367023          "name": "lodash",
367024          "version": "4.17.21",
367025          "description": "Lodash modular utilities.",
367026          "licenses": [
367027            {
367028              "license": {
367029                "id": "MIT"
367030              }
367031            }
367032          ],
367033          "cpe": "cpe:2.3:a:lodash:lodash:4.17.21:*:*:*:*:*:*:*",
367034          "purl": "pkg:npm/lodash@4.17.21",
367035          "swid": {
367036            "attachment": {}
367037          },
367038          "pedigree": {},
367039          "externalReferences": [
367040            {
367041              "url": "git+https://github.com/lodash/lodash.git",
367042              "type": "distribution"
367043            },
367044            {
367045              "url": "https://lodash.com/",
367046              "type": "website"
367047            }
367048          ],
367049          "evidence": {},
367050          "signature": {
367051            "signature": {
367052              "publicKey": {}
367053            }
367054          },
367055          "modelCard": {
367056            "modelParameters": {
367057              "approach": {}
367058            },
367059            "quantitativeAnalysis": {
367060              "graphics": {}
367061            },
367062            "considerations": {}
367063          }
367064        },
367065        {
367066          "type": "library",
367067          "bom-ref": "pkg:npm/lodash._baseindexof@3.1.0?package-id=38efd060e3a4d336",
367068          "supplier": {},
367069          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367070          "name": "lodash._baseindexof",
367071          "version": "3.1.0",
367072          "description": "The modern build of lodash’s internal `baseIndexOf` as a module.",
367073          "licenses": [
367074            {
367075              "license": {
367076                "id": "MIT"
367077              }
367078            }
367079          ],
367080          "cpe": "cpe:2.3:a:lodash.-baseindexof:lodash.-baseindexof:3.1.0:*:*:*:*:*:*:*",
367081          "purl": "pkg:npm/lodash._baseindexof@3.1.0",
367082          "swid": {
367083            "attachment": {}
367084          },
367085          "pedigree": {},
367086          "externalReferences": [
367087            {
367088              "url": "git+https://github.com/lodash/lodash.git",
367089              "type": "distribution"
367090            },
367091            {
367092              "url": "https://lodash.com/",
367093              "type": "website"
367094            }
367095          ],
367096          "evidence": {},
367097          "signature": {
367098            "signature": {
367099              "publicKey": {}
367100            }
367101          },
367102          "modelCard": {
367103            "modelParameters": {
367104              "approach": {}
367105            },
367106            "quantitativeAnalysis": {
367107              "graphics": {}
367108            },
367109            "considerations": {}
367110          }
367111        },
367112        {
367113          "type": "library",
367114          "bom-ref": "pkg:npm/lodash._baseuniq@4.6.0?package-id=f3cad3a8a8778d94",
367115          "supplier": {},
367116          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367117          "name": "lodash._baseuniq",
367118          "version": "4.6.0",
367119          "description": "The internal lodash function `baseUniq` exported as a module.",
367120          "licenses": [
367121            {
367122              "license": {
367123                "id": "MIT"
367124              }
367125            }
367126          ],
367127          "cpe": "cpe:2.3:a:lodash.-baseuniq:lodash.-baseuniq:4.6.0:*:*:*:*:*:*:*",
367128          "purl": "pkg:npm/lodash._baseuniq@4.6.0",
367129          "swid": {
367130            "attachment": {}
367131          },
367132          "pedigree": {},
367133          "externalReferences": [
367134            {
367135              "url": "git+https://github.com/lodash/lodash.git",
367136              "type": "distribution"
367137            },
367138            {
367139              "url": "https://lodash.com/",
367140              "type": "website"
367141            }
367142          ],
367143          "evidence": {},
367144          "signature": {
367145            "signature": {
367146              "publicKey": {}
367147            }
367148          },
367149          "modelCard": {
367150            "modelParameters": {
367151              "approach": {}
367152            },
367153            "quantitativeAnalysis": {
367154              "graphics": {}
367155            },
367156            "considerations": {}
367157          }
367158        },
367159        {
367160          "type": "library",
367161          "bom-ref": "pkg:npm/lodash._bindcallback@3.0.1?package-id=aceccd904d52fec7",
367162          "supplier": {},
367163          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367164          "name": "lodash._bindcallback",
367165          "version": "3.0.1",
367166          "description": "The modern build of lodash’s internal `bindCallback` as a module.",
367167          "licenses": [
367168            {
367169              "license": {
367170                "id": "MIT"
367171              }
367172            }
367173          ],
367174          "cpe": "cpe:2.3:a:lodash.-bindcallback:lodash.-bindcallback:3.0.1:*:*:*:*:*:*:*",
367175          "purl": "pkg:npm/lodash._bindcallback@3.0.1",
367176          "swid": {
367177            "attachment": {}
367178          },
367179          "pedigree": {},
367180          "externalReferences": [
367181            {
367182              "url": "git+https://github.com/lodash/lodash.git",
367183              "type": "distribution"
367184            },
367185            {
367186              "url": "https://lodash.com/",
367187              "type": "website"
367188            }
367189          ],
367190          "evidence": {},
367191          "signature": {
367192            "signature": {
367193              "publicKey": {}
367194            }
367195          },
367196          "modelCard": {
367197            "modelParameters": {
367198              "approach": {}
367199            },
367200            "quantitativeAnalysis": {
367201              "graphics": {}
367202            },
367203            "considerations": {}
367204          }
367205        },
367206        {
367207          "type": "library",
367208          "bom-ref": "pkg:npm/lodash._cacheindexof@3.0.2?package-id=9366742db20085f0",
367209          "supplier": {},
367210          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367211          "name": "lodash._cacheindexof",
367212          "version": "3.0.2",
367213          "description": "The modern build of lodash’s internal `cacheIndexOf` as a module.",
367214          "licenses": [
367215            {
367216              "license": {
367217                "id": "MIT"
367218              }
367219            }
367220          ],
367221          "cpe": "cpe:2.3:a:lodash.-cacheindexof:lodash.-cacheindexof:3.0.2:*:*:*:*:*:*:*",
367222          "purl": "pkg:npm/lodash._cacheindexof@3.0.2",
367223          "swid": {
367224            "attachment": {}
367225          },
367226          "pedigree": {},
367227          "externalReferences": [
367228            {
367229              "url": "git+https://github.com/lodash/lodash.git",
367230              "type": "distribution"
367231            },
367232            {
367233              "url": "https://lodash.com/",
367234              "type": "website"
367235            }
367236          ],
367237          "evidence": {},
367238          "signature": {
367239            "signature": {
367240              "publicKey": {}
367241            }
367242          },
367243          "modelCard": {
367244            "modelParameters": {
367245              "approach": {}
367246            },
367247            "quantitativeAnalysis": {
367248              "graphics": {}
367249            },
367250            "considerations": {}
367251          }
367252        },
367253        {
367254          "type": "library",
367255          "bom-ref": "pkg:npm/lodash._createcache@3.1.2?package-id=edbe9d8077eb16ba",
367256          "supplier": {},
367257          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367258          "name": "lodash._createcache",
367259          "version": "3.1.2",
367260          "description": "The modern build of lodash’s internal `createCache` as a module.",
367261          "licenses": [
367262            {
367263              "license": {
367264                "id": "MIT"
367265              }
367266            }
367267          ],
367268          "cpe": "cpe:2.3:a:lodash.-createcache:lodash.-createcache:3.1.2:*:*:*:*:*:*:*",
367269          "purl": "pkg:npm/lodash._createcache@3.1.2",
367270          "swid": {
367271            "attachment": {}
367272          },
367273          "pedigree": {},
367274          "externalReferences": [
367275            {
367276              "url": "git+https://github.com/lodash/lodash.git",
367277              "type": "distribution"
367278            },
367279            {
367280              "url": "https://lodash.com/",
367281              "type": "website"
367282            }
367283          ],
367284          "evidence": {},
367285          "signature": {
367286            "signature": {
367287              "publicKey": {}
367288            }
367289          },
367290          "modelCard": {
367291            "modelParameters": {
367292              "approach": {}
367293            },
367294            "quantitativeAnalysis": {
367295              "graphics": {}
367296            },
367297            "considerations": {}
367298          }
367299        },
367300        {
367301          "type": "library",
367302          "bom-ref": "pkg:npm/lodash._createset@4.0.3?package-id=27ed42f7fc9601ba",
367303          "supplier": {},
367304          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367305          "name": "lodash._createset",
367306          "version": "4.0.3",
367307          "description": "The internal lodash function `createSet` exported as a module.",
367308          "licenses": [
367309            {
367310              "license": {
367311                "id": "MIT"
367312              }
367313            }
367314          ],
367315          "cpe": "cpe:2.3:a:lodash.-createset:lodash.-createset:4.0.3:*:*:*:*:*:*:*",
367316          "purl": "pkg:npm/lodash._createset@4.0.3",
367317          "swid": {
367318            "attachment": {}
367319          },
367320          "pedigree": {},
367321          "externalReferences": [
367322            {
367323              "url": "git+https://github.com/lodash/lodash.git",
367324              "type": "distribution"
367325            },
367326            {
367327              "url": "https://lodash.com/",
367328              "type": "website"
367329            }
367330          ],
367331          "evidence": {},
367332          "signature": {
367333            "signature": {
367334              "publicKey": {}
367335            }
367336          },
367337          "modelCard": {
367338            "modelParameters": {
367339              "approach": {}
367340            },
367341            "quantitativeAnalysis": {
367342              "graphics": {}
367343            },
367344            "considerations": {}
367345          }
367346        },
367347        {
367348          "type": "library",
367349          "bom-ref": "pkg:npm/lodash._getnative@3.9.1?package-id=b817ace9e00c6dc1",
367350          "supplier": {},
367351          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367352          "name": "lodash._getnative",
367353          "version": "3.9.1",
367354          "description": "The modern build of lodash’s internal `getNative` as a module.",
367355          "licenses": [
367356            {
367357              "license": {
367358                "id": "MIT"
367359              }
367360            }
367361          ],
367362          "cpe": "cpe:2.3:a:lodash.-getnative:lodash.-getnative:3.9.1:*:*:*:*:*:*:*",
367363          "purl": "pkg:npm/lodash._getnative@3.9.1",
367364          "swid": {
367365            "attachment": {}
367366          },
367367          "pedigree": {},
367368          "externalReferences": [
367369            {
367370              "url": "git+https://github.com/lodash/lodash.git",
367371              "type": "distribution"
367372            },
367373            {
367374              "url": "https://lodash.com/",
367375              "type": "website"
367376            }
367377          ],
367378          "evidence": {},
367379          "signature": {
367380            "signature": {
367381              "publicKey": {}
367382            }
367383          },
367384          "modelCard": {
367385            "modelParameters": {
367386              "approach": {}
367387            },
367388            "quantitativeAnalysis": {
367389              "graphics": {}
367390            },
367391            "considerations": {}
367392          }
367393        },
367394        {
367395          "type": "library",
367396          "bom-ref": "pkg:npm/lodash._root@3.0.1?package-id=3975d2ad53d321e8",
367397          "supplier": {},
367398          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367399          "name": "lodash._root",
367400          "version": "3.0.1",
367401          "description": "The internal lodash function `root` exported as a module.",
367402          "licenses": [
367403            {
367404              "license": {
367405                "id": "MIT"
367406              }
367407            }
367408          ],
367409          "cpe": "cpe:2.3:a:lodash.-root:lodash.-root:3.0.1:*:*:*:*:*:*:*",
367410          "purl": "pkg:npm/lodash._root@3.0.1",
367411          "swid": {
367412            "attachment": {}
367413          },
367414          "pedigree": {},
367415          "externalReferences": [
367416            {
367417              "url": "git+https://github.com/lodash/lodash.git",
367418              "type": "distribution"
367419            },
367420            {
367421              "url": "https://lodash.com/",
367422              "type": "website"
367423            }
367424          ],
367425          "evidence": {},
367426          "signature": {
367427            "signature": {
367428              "publicKey": {}
367429            }
367430          },
367431          "modelCard": {
367432            "modelParameters": {
367433              "approach": {}
367434            },
367435            "quantitativeAnalysis": {
367436              "graphics": {}
367437            },
367438            "considerations": {}
367439          }
367440        },
367441        {
367442          "type": "library",
367443          "bom-ref": "pkg:npm/lodash.clonedeep@4.5.0?package-id=60a70c19659c0615",
367444          "supplier": {},
367445          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367446          "name": "lodash.clonedeep",
367447          "version": "4.5.0",
367448          "description": "The lodash method `_.cloneDeep` exported as a module.",
367449          "licenses": [
367450            {
367451              "license": {
367452                "id": "MIT"
367453              }
367454            }
367455          ],
367456          "cpe": "cpe:2.3:a:lodash.clonedeep:lodash.clonedeep:4.5.0:*:*:*:*:*:*:*",
367457          "purl": "pkg:npm/lodash.clonedeep@4.5.0",
367458          "swid": {
367459            "attachment": {}
367460          },
367461          "pedigree": {},
367462          "externalReferences": [
367463            {
367464              "url": "git+https://github.com/lodash/lodash.git",
367465              "type": "distribution"
367466            },
367467            {
367468              "url": "https://lodash.com/",
367469              "type": "website"
367470            }
367471          ],
367472          "evidence": {},
367473          "signature": {
367474            "signature": {
367475              "publicKey": {}
367476            }
367477          },
367478          "modelCard": {
367479            "modelParameters": {
367480              "approach": {}
367481            },
367482            "quantitativeAnalysis": {
367483              "graphics": {}
367484            },
367485            "considerations": {}
367486          }
367487        },
367488        {
367489          "type": "library",
367490          "bom-ref": "pkg:npm/lodash.includes@4.3.0?package-id=8166ba1464ace388",
367491          "supplier": {},
367492          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367493          "name": "lodash.includes",
367494          "version": "4.3.0",
367495          "description": "The lodash method `_.includes` exported as a module.",
367496          "licenses": [
367497            {
367498              "license": {
367499                "id": "MIT"
367500              }
367501            }
367502          ],
367503          "cpe": "cpe:2.3:a:lodash.includes:lodash.includes:4.3.0:*:*:*:*:*:*:*",
367504          "purl": "pkg:npm/lodash.includes@4.3.0",
367505          "swid": {
367506            "attachment": {}
367507          },
367508          "pedigree": {},
367509          "externalReferences": [
367510            {
367511              "url": "git+https://github.com/lodash/lodash.git",
367512              "type": "distribution"
367513            },
367514            {
367515              "url": "https://lodash.com/",
367516              "type": "website"
367517            }
367518          ],
367519          "evidence": {},
367520          "signature": {
367521            "signature": {
367522              "publicKey": {}
367523            }
367524          },
367525          "modelCard": {
367526            "modelParameters": {
367527              "approach": {}
367528            },
367529            "quantitativeAnalysis": {
367530              "graphics": {}
367531            },
367532            "considerations": {}
367533          }
367534        },
367535        {
367536          "type": "library",
367537          "bom-ref": "pkg:npm/lodash.isboolean@3.0.3?package-id=2ce6d56af658279b",
367538          "supplier": {},
367539          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367540          "name": "lodash.isboolean",
367541          "version": "3.0.3",
367542          "description": "The lodash method `_.isBoolean` exported as a module.",
367543          "licenses": [
367544            {
367545              "license": {
367546                "id": "MIT"
367547              }
367548            }
367549          ],
367550          "cpe": "cpe:2.3:a:lodash.isboolean:lodash.isboolean:3.0.3:*:*:*:*:*:*:*",
367551          "purl": "pkg:npm/lodash.isboolean@3.0.3",
367552          "swid": {
367553            "attachment": {}
367554          },
367555          "pedigree": {},
367556          "externalReferences": [
367557            {
367558              "url": "git+https://github.com/lodash/lodash.git",
367559              "type": "distribution"
367560            },
367561            {
367562              "url": "https://lodash.com/",
367563              "type": "website"
367564            }
367565          ],
367566          "evidence": {},
367567          "signature": {
367568            "signature": {
367569              "publicKey": {}
367570            }
367571          },
367572          "modelCard": {
367573            "modelParameters": {
367574              "approach": {}
367575            },
367576            "quantitativeAnalysis": {
367577              "graphics": {}
367578            },
367579            "considerations": {}
367580          }
367581        },
367582        {
367583          "type": "library",
367584          "bom-ref": "pkg:npm/lodash.isinteger@4.0.4?package-id=db88e86d62c15e0f",
367585          "supplier": {},
367586          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367587          "name": "lodash.isinteger",
367588          "version": "4.0.4",
367589          "description": "The lodash method `_.isInteger` exported as a module.",
367590          "licenses": [
367591            {
367592              "license": {
367593                "id": "MIT"
367594              }
367595            }
367596          ],
367597          "cpe": "cpe:2.3:a:lodash.isinteger:lodash.isinteger:4.0.4:*:*:*:*:*:*:*",
367598          "purl": "pkg:npm/lodash.isinteger@4.0.4",
367599          "swid": {
367600            "attachment": {}
367601          },
367602          "pedigree": {},
367603          "externalReferences": [
367604            {
367605              "url": "git+https://github.com/lodash/lodash.git",
367606              "type": "distribution"
367607            },
367608            {
367609              "url": "https://lodash.com/",
367610              "type": "website"
367611            }
367612          ],
367613          "evidence": {},
367614          "signature": {
367615            "signature": {
367616              "publicKey": {}
367617            }
367618          },
367619          "modelCard": {
367620            "modelParameters": {
367621              "approach": {}
367622            },
367623            "quantitativeAnalysis": {
367624              "graphics": {}
367625            },
367626            "considerations": {}
367627          }
367628        },
367629        {
367630          "type": "library",
367631          "bom-ref": "pkg:npm/lodash.isnumber@3.0.3?package-id=d5752336f4b6197d",
367632          "supplier": {},
367633          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367634          "name": "lodash.isnumber",
367635          "version": "3.0.3",
367636          "description": "The lodash method `_.isNumber` exported as a module.",
367637          "licenses": [
367638            {
367639              "license": {
367640                "id": "MIT"
367641              }
367642            }
367643          ],
367644          "cpe": "cpe:2.3:a:lodash.isnumber:lodash.isnumber:3.0.3:*:*:*:*:*:*:*",
367645          "purl": "pkg:npm/lodash.isnumber@3.0.3",
367646          "swid": {
367647            "attachment": {}
367648          },
367649          "pedigree": {},
367650          "externalReferences": [
367651            {
367652              "url": "git+https://github.com/lodash/lodash.git",
367653              "type": "distribution"
367654            },
367655            {
367656              "url": "https://lodash.com/",
367657              "type": "website"
367658            }
367659          ],
367660          "evidence": {},
367661          "signature": {
367662            "signature": {
367663              "publicKey": {}
367664            }
367665          },
367666          "modelCard": {
367667            "modelParameters": {
367668              "approach": {}
367669            },
367670            "quantitativeAnalysis": {
367671              "graphics": {}
367672            },
367673            "considerations": {}
367674          }
367675        },
367676        {
367677          "type": "library",
367678          "bom-ref": "pkg:npm/lodash.isplainobject@4.0.6?package-id=34ce0402948a5797",
367679          "supplier": {},
367680          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367681          "name": "lodash.isplainobject",
367682          "version": "4.0.6",
367683          "description": "The lodash method `_.isPlainObject` exported as a module.",
367684          "licenses": [
367685            {
367686              "license": {
367687                "id": "MIT"
367688              }
367689            }
367690          ],
367691          "cpe": "cpe:2.3:a:lodash.isplainobject:lodash.isplainobject:4.0.6:*:*:*:*:*:*:*",
367692          "purl": "pkg:npm/lodash.isplainobject@4.0.6",
367693          "swid": {
367694            "attachment": {}
367695          },
367696          "pedigree": {},
367697          "externalReferences": [
367698            {
367699              "url": "git+https://github.com/lodash/lodash.git",
367700              "type": "distribution"
367701            },
367702            {
367703              "url": "https://lodash.com/",
367704              "type": "website"
367705            }
367706          ],
367707          "evidence": {},
367708          "signature": {
367709            "signature": {
367710              "publicKey": {}
367711            }
367712          },
367713          "modelCard": {
367714            "modelParameters": {
367715              "approach": {}
367716            },
367717            "quantitativeAnalysis": {
367718              "graphics": {}
367719            },
367720            "considerations": {}
367721          }
367722        },
367723        {
367724          "type": "library",
367725          "bom-ref": "pkg:npm/lodash.isstring@4.0.1?package-id=4fdb57a723b6cfe9",
367726          "supplier": {},
367727          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367728          "name": "lodash.isstring",
367729          "version": "4.0.1",
367730          "description": "The lodash method `_.isString` exported as a module.",
367731          "licenses": [
367732            {
367733              "license": {
367734                "id": "MIT"
367735              }
367736            }
367737          ],
367738          "cpe": "cpe:2.3:a:lodash.isstring:lodash.isstring:4.0.1:*:*:*:*:*:*:*",
367739          "purl": "pkg:npm/lodash.isstring@4.0.1",
367740          "swid": {
367741            "attachment": {}
367742          },
367743          "pedigree": {},
367744          "externalReferences": [
367745            {
367746              "url": "git+https://github.com/lodash/lodash.git",
367747              "type": "distribution"
367748            },
367749            {
367750              "url": "https://lodash.com/",
367751              "type": "website"
367752            }
367753          ],
367754          "evidence": {},
367755          "signature": {
367756            "signature": {
367757              "publicKey": {}
367758            }
367759          },
367760          "modelCard": {
367761            "modelParameters": {
367762              "approach": {}
367763            },
367764            "quantitativeAnalysis": {
367765              "graphics": {}
367766            },
367767            "considerations": {}
367768          }
367769        },
367770        {
367771          "type": "library",
367772          "bom-ref": "pkg:npm/lodash.once@4.1.1?package-id=d27a89150566b5d7",
367773          "supplier": {},
367774          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367775          "name": "lodash.once",
367776          "version": "4.1.1",
367777          "description": "The lodash method `_.once` exported as a module.",
367778          "licenses": [
367779            {
367780              "license": {
367781                "id": "MIT"
367782              }
367783            }
367784          ],
367785          "cpe": "cpe:2.3:a:lodash.once:lodash.once:4.1.1:*:*:*:*:*:*:*",
367786          "purl": "pkg:npm/lodash.once@4.1.1",
367787          "swid": {
367788            "attachment": {}
367789          },
367790          "pedigree": {},
367791          "externalReferences": [
367792            {
367793              "url": "git+https://github.com/lodash/lodash.git",
367794              "type": "distribution"
367795            },
367796            {
367797              "url": "https://lodash.com/",
367798              "type": "website"
367799            }
367800          ],
367801          "evidence": {},
367802          "signature": {
367803            "signature": {
367804              "publicKey": {}
367805            }
367806          },
367807          "modelCard": {
367808            "modelParameters": {
367809              "approach": {}
367810            },
367811            "quantitativeAnalysis": {
367812              "graphics": {}
367813            },
367814            "considerations": {}
367815          }
367816        },
367817        {
367818          "type": "library",
367819          "bom-ref": "pkg:npm/lodash.restparam@3.6.1?package-id=cd218c729d0105b1",
367820          "supplier": {},
367821          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367822          "name": "lodash.restparam",
367823          "version": "3.6.1",
367824          "description": "The modern build of lodash’s `_.restParam` as a module.",
367825          "licenses": [
367826            {
367827              "license": {
367828                "id": "MIT"
367829              }
367830            }
367831          ],
367832          "cpe": "cpe:2.3:a:lodash.restparam:lodash.restparam:3.6.1:*:*:*:*:*:*:*",
367833          "purl": "pkg:npm/lodash.restparam@3.6.1",
367834          "swid": {
367835            "attachment": {}
367836          },
367837          "pedigree": {},
367838          "externalReferences": [
367839            {
367840              "url": "git+https://github.com/lodash/lodash.git",
367841              "type": "distribution"
367842            },
367843            {
367844              "url": "https://lodash.com/",
367845              "type": "website"
367846            }
367847          ],
367848          "evidence": {},
367849          "signature": {
367850            "signature": {
367851              "publicKey": {}
367852            }
367853          },
367854          "modelCard": {
367855            "modelParameters": {
367856              "approach": {}
367857            },
367858            "quantitativeAnalysis": {
367859              "graphics": {}
367860            },
367861            "considerations": {}
367862          }
367863        },
367864        {
367865          "type": "library",
367866          "bom-ref": "pkg:npm/lodash.union@4.6.0?package-id=fd1f76b549051dc5",
367867          "supplier": {},
367868          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367869          "name": "lodash.union",
367870          "version": "4.6.0",
367871          "description": "The lodash method `_.union` exported as a module.",
367872          "licenses": [
367873            {
367874              "license": {
367875                "id": "MIT"
367876              }
367877            }
367878          ],
367879          "cpe": "cpe:2.3:a:lodash.union:lodash.union:4.6.0:*:*:*:*:*:*:*",
367880          "purl": "pkg:npm/lodash.union@4.6.0",
367881          "swid": {
367882            "attachment": {}
367883          },
367884          "pedigree": {},
367885          "externalReferences": [
367886            {
367887              "url": "git+https://github.com/lodash/lodash.git",
367888              "type": "distribution"
367889            },
367890            {
367891              "url": "https://lodash.com/",
367892              "type": "website"
367893            }
367894          ],
367895          "evidence": {},
367896          "signature": {
367897            "signature": {
367898              "publicKey": {}
367899            }
367900          },
367901          "modelCard": {
367902            "modelParameters": {
367903              "approach": {}
367904            },
367905            "quantitativeAnalysis": {
367906              "graphics": {}
367907            },
367908            "considerations": {}
367909          }
367910        },
367911        {
367912          "type": "library",
367913          "bom-ref": "pkg:npm/lodash.uniq@4.5.0?package-id=ff80c2262d287958",
367914          "supplier": {},
367915          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367916          "name": "lodash.uniq",
367917          "version": "4.5.0",
367918          "description": "The lodash method `_.uniq` exported as a module.",
367919          "licenses": [
367920            {
367921              "license": {
367922                "id": "MIT"
367923              }
367924            }
367925          ],
367926          "cpe": "cpe:2.3:a:lodash.uniq:lodash.uniq:4.5.0:*:*:*:*:*:*:*",
367927          "purl": "pkg:npm/lodash.uniq@4.5.0",
367928          "swid": {
367929            "attachment": {}
367930          },
367931          "pedigree": {},
367932          "externalReferences": [
367933            {
367934              "url": "git+https://github.com/lodash/lodash.git",
367935              "type": "distribution"
367936            },
367937            {
367938              "url": "https://lodash.com/",
367939              "type": "website"
367940            }
367941          ],
367942          "evidence": {},
367943          "signature": {
367944            "signature": {
367945              "publicKey": {}
367946            }
367947          },
367948          "modelCard": {
367949            "modelParameters": {
367950              "approach": {}
367951            },
367952            "quantitativeAnalysis": {
367953              "graphics": {}
367954            },
367955            "considerations": {}
367956          }
367957        },
367958        {
367959          "type": "library",
367960          "bom-ref": "pkg:npm/lodash.without@4.4.0?package-id=284f38c0ca8041d8",
367961          "supplier": {},
367962          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e (http://allyoucanleet.com/)",
367963          "name": "lodash.without",
367964          "version": "4.4.0",
367965          "description": "The lodash method `_.without` exported as a module.",
367966          "licenses": [
367967            {
367968              "license": {
367969                "id": "MIT"
367970              }
367971            }
367972          ],
367973          "cpe": "cpe:2.3:a:lodash.without:lodash.without:4.4.0:*:*:*:*:*:*:*",
367974          "purl": "pkg:npm/lodash.without@4.4.0",
367975          "swid": {
367976            "attachment": {}
367977          },
367978          "pedigree": {},
367979          "externalReferences": [
367980            {
367981              "url": "git+https://github.com/lodash/lodash.git",
367982              "type": "distribution"
367983            },
367984            {
367985              "url": "https://lodash.com/",
367986              "type": "website"
367987            }
367988          ],
367989          "evidence": {},
367990          "signature": {
367991            "signature": {
367992              "publicKey": {}
367993            }
367994          },
367995          "modelCard": {
367996            "modelParameters": {
367997              "approach": {}
367998            },
367999            "quantitativeAnalysis": {
368000              "graphics": {}
368001            },
368002            "considerations": {}
368003          }
368004        },
368005        {
368006          "type": "library",
368007          "bom-ref": "pkg:npm/lowercase-keys@1.0.1?package-id=409c8833cd49dbdb",
368008          "supplier": {},
368009          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
368010          "name": "lowercase-keys",
368011          "version": "1.0.1",
368012          "description": "Lowercase the keys of an object",
368013          "licenses": [
368014            {
368015              "license": {
368016                "id": "MIT"
368017              }
368018            }
368019          ],
368020          "cpe": "cpe:2.3:a:lowercase-keys:lowercase-keys:1.0.1:*:*:*:*:*:*:*",
368021          "purl": "pkg:npm/lowercase-keys@1.0.1",
368022          "swid": {
368023            "attachment": {}
368024          },
368025          "pedigree": {},
368026          "externalReferences": [
368027            {
368028              "url": "git+https://github.com/sindresorhus/lowercase-keys.git",
368029              "type": "distribution"
368030            },
368031            {
368032              "url": "https://github.com/sindresorhus/lowercase-keys#readme",
368033              "type": "website"
368034            }
368035          ],
368036          "evidence": {},
368037          "signature": {
368038            "signature": {
368039              "publicKey": {}
368040            }
368041          },
368042          "modelCard": {
368043            "modelParameters": {
368044              "approach": {}
368045            },
368046            "quantitativeAnalysis": {
368047              "graphics": {}
368048            },
368049            "considerations": {}
368050          }
368051        },
368052        {
368053          "type": "library",
368054          "bom-ref": "pkg:npm/lru-cache@4.1.5?package-id=eef94188c4c5e168",
368055          "supplier": {},
368056          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
368057          "name": "lru-cache",
368058          "version": "4.1.5",
368059          "description": "A cache object that deletes the least-recently-used items.",
368060          "licenses": [
368061            {
368062              "license": {
368063                "id": "ISC"
368064              }
368065            }
368066          ],
368067          "cpe": "cpe:2.3:a:lru-cache:lru-cache:4.1.5:*:*:*:*:*:*:*",
368068          "purl": "pkg:npm/lru-cache@4.1.5",
368069          "swid": {
368070            "attachment": {}
368071          },
368072          "pedigree": {},
368073          "externalReferences": [
368074            {
368075              "url": "git://github.com/isaacs/node-lru-cache.git",
368076              "type": "distribution"
368077            },
368078            {
368079              "url": "https://github.com/isaacs/node-lru-cache#readme",
368080              "type": "website"
368081            }
368082          ],
368083          "evidence": {},
368084          "signature": {
368085            "signature": {
368086              "publicKey": {}
368087            }
368088          },
368089          "modelCard": {
368090            "modelParameters": {
368091              "approach": {}
368092            },
368093            "quantitativeAnalysis": {
368094              "graphics": {}
368095            },
368096            "considerations": {}
368097          }
368098        },
368099        {
368100          "type": "library",
368101          "bom-ref": "pkg:npm/lru-cache@5.1.1?package-id=6e978256c4691a8c",
368102          "supplier": {},
368103          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
368104          "name": "lru-cache",
368105          "version": "5.1.1",
368106          "description": "A cache object that deletes the least-recently-used items.",
368107          "licenses": [
368108            {
368109              "license": {
368110                "id": "ISC"
368111              }
368112            }
368113          ],
368114          "cpe": "cpe:2.3:a:lru-cache:lru-cache:5.1.1:*:*:*:*:*:*:*",
368115          "purl": "pkg:npm/lru-cache@5.1.1",
368116          "swid": {
368117            "attachment": {}
368118          },
368119          "pedigree": {},
368120          "externalReferences": [
368121            {
368122              "url": "git://github.com/isaacs/node-lru-cache.git",
368123              "type": "distribution"
368124            },
368125            {
368126              "url": "https://github.com/isaacs/node-lru-cache#readme",
368127              "type": "website"
368128            }
368129          ],
368130          "evidence": {},
368131          "signature": {
368132            "signature": {
368133              "publicKey": {}
368134            }
368135          },
368136          "modelCard": {
368137            "modelParameters": {
368138              "approach": {}
368139            },
368140            "quantitativeAnalysis": {
368141              "graphics": {}
368142            },
368143            "considerations": {}
368144          }
368145        },
368146        {
368147          "type": "library",
368148          "bom-ref": "pkg:npm/lru_map@0.3.3?package-id=8593166d4c692511",
368149          "supplier": {},
368150          "author": "Rasmus Andersson \u003cme@rsms.me\u003e",
368151          "name": "lru_map",
368152          "version": "0.3.3",
368153          "description": "Finite key-value map using the Least Recently Used (LRU) algorithm where the most recently used objects are keept in the map while less recently used items are evicted to make room for new ones.",
368154          "licenses": [
368155            {
368156              "license": {
368157                "id": "MIT"
368158              }
368159            }
368160          ],
368161          "cpe": "cpe:2.3:a:lru-map:lru-map:0.3.3:*:*:*:*:*:*:*",
368162          "purl": "pkg:npm/lru_map@0.3.3",
368163          "swid": {
368164            "attachment": {}
368165          },
368166          "pedigree": {},
368167          "externalReferences": [
368168            {
368169              "url": "git+https://github.com/rsms/js-lru.git",
368170              "type": "distribution"
368171            },
368172            {
368173              "url": "https://github.com/rsms/js-lru#readme",
368174              "type": "website"
368175            }
368176          ],
368177          "evidence": {},
368178          "signature": {
368179            "signature": {
368180              "publicKey": {}
368181            }
368182          },
368183          "modelCard": {
368184            "modelParameters": {
368185              "approach": {}
368186            },
368187            "quantitativeAnalysis": {
368188              "graphics": {}
368189            },
368190            "considerations": {}
368191          }
368192        },
368193        {
368194          "type": "library",
368195          "bom-ref": "pkg:npm/make-dir@1.3.0?package-id=8c1dc4a13ddd1f8b",
368196          "supplier": {},
368197          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
368198          "name": "make-dir",
368199          "version": "1.3.0",
368200          "description": "Make a directory and its parents if needed - Think `mkdir -p`",
368201          "licenses": [
368202            {
368203              "license": {
368204                "id": "MIT"
368205              }
368206            }
368207          ],
368208          "cpe": "cpe:2.3:a:sindresorhus:make-dir:1.3.0:*:*:*:*:*:*:*",
368209          "purl": "pkg:npm/make-dir@1.3.0",
368210          "swid": {
368211            "attachment": {}
368212          },
368213          "pedigree": {},
368214          "externalReferences": [
368215            {
368216              "url": "git+https://github.com/sindresorhus/make-dir.git",
368217              "type": "distribution"
368218            },
368219            {
368220              "url": "https://github.com/sindresorhus/make-dir#readme",
368221              "type": "website"
368222            }
368223          ],
368224          "evidence": {},
368225          "signature": {
368226            "signature": {
368227              "publicKey": {}
368228            }
368229          },
368230          "modelCard": {
368231            "modelParameters": {
368232              "approach": {}
368233            },
368234            "quantitativeAnalysis": {
368235              "graphics": {}
368236            },
368237            "considerations": {}
368238          }
368239        },
368240        {
368241          "type": "library",
368242          "bom-ref": "pkg:npm/make-fetch-happen@5.0.2?package-id=b812e5c3d8342059",
368243          "supplier": {},
368244          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
368245          "name": "make-fetch-happen",
368246          "version": "5.0.2",
368247          "description": "Opinionated, caching, retrying fetch client",
368248          "licenses": [
368249            {
368250              "license": {
368251                "id": "ISC"
368252              }
368253            }
368254          ],
368255          "cpe": "cpe:2.3:a:make-fetch-happen:make-fetch-happen:5.0.2:*:*:*:*:*:*:*",
368256          "purl": "pkg:npm/make-fetch-happen@5.0.2",
368257          "swid": {
368258            "attachment": {}
368259          },
368260          "pedigree": {},
368261          "externalReferences": [
368262            {
368263              "url": "git+https://github.com/zkat/make-fetch-happen.git",
368264              "type": "distribution"
368265            },
368266            {
368267              "url": "https://github.com/zkat/make-fetch-happen#readme",
368268              "type": "website"
368269            }
368270          ],
368271          "evidence": {},
368272          "signature": {
368273            "signature": {
368274              "publicKey": {}
368275            }
368276          },
368277          "modelCard": {
368278            "modelParameters": {
368279              "approach": {}
368280            },
368281            "quantitativeAnalysis": {
368282              "graphics": {}
368283            },
368284            "considerations": {}
368285          }
368286        },
368287        {
368288          "type": "library",
368289          "bom-ref": "pkg:npm/meant@1.0.3?package-id=f7939cd7c299412e",
368290          "supplier": {},
368291          "author": "Daijiro Wachi",
368292          "name": "meant",
368293          "version": "1.0.3",
368294          "description": "Like the `Did you mean?` in git for npm",
368295          "licenses": [
368296            {
368297              "license": {
368298                "id": "MIT"
368299              }
368300            }
368301          ],
368302          "cpe": "cpe:2.3:a:watilde:meant:1.0.3:*:*:*:*:*:*:*",
368303          "purl": "pkg:npm/meant@1.0.3",
368304          "swid": {
368305            "attachment": {}
368306          },
368307          "pedigree": {},
368308          "externalReferences": [
368309            {
368310              "url": "git+https://github.com/watilde/meant.git",
368311              "type": "distribution"
368312            },
368313            {
368314              "url": "https://github.com/watilde/meant#readme",
368315              "type": "website"
368316            }
368317          ],
368318          "evidence": {},
368319          "signature": {
368320            "signature": {
368321              "publicKey": {}
368322            }
368323          },
368324          "modelCard": {
368325            "modelParameters": {
368326              "approach": {}
368327            },
368328            "quantitativeAnalysis": {
368329              "graphics": {}
368330            },
368331            "considerations": {}
368332          }
368333        },
368334        {
368335          "type": "library",
368336          "bom-ref": "pkg:npm/media-typer@0.3.0?package-id=33c04253526b5d6b",
368337          "supplier": {},
368338          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
368339          "name": "media-typer",
368340          "version": "0.3.0",
368341          "description": "Simple RFC 6838 media type parser and formatter",
368342          "licenses": [
368343            {
368344              "license": {
368345                "id": "MIT"
368346              }
368347            }
368348          ],
368349          "cpe": "cpe:2.3:a:media-typer:media-typer:0.3.0:*:*:*:*:*:*:*",
368350          "purl": "pkg:npm/media-typer@0.3.0",
368351          "swid": {
368352            "attachment": {}
368353          },
368354          "pedigree": {},
368355          "externalReferences": [
368356            {
368357              "url": "git+https://github.com/jshttp/media-typer.git",
368358              "type": "distribution"
368359            },
368360            {
368361              "url": "https://github.com/jshttp/media-typer#readme",
368362              "type": "website"
368363            }
368364          ],
368365          "evidence": {},
368366          "signature": {
368367            "signature": {
368368              "publicKey": {}
368369            }
368370          },
368371          "modelCard": {
368372            "modelParameters": {
368373              "approach": {}
368374            },
368375            "quantitativeAnalysis": {
368376              "graphics": {}
368377            },
368378            "considerations": {}
368379          }
368380        },
368381        {
368382          "type": "library",
368383          "bom-ref": "pkg:npm/merge-descriptors@1.0.1?package-id=c7a60e972125bba3",
368384          "supplier": {},
368385          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
368386          "name": "merge-descriptors",
368387          "version": "1.0.1",
368388          "description": "Merge objects using descriptors",
368389          "licenses": [
368390            {
368391              "license": {
368392                "id": "MIT"
368393              }
368394            }
368395          ],
368396          "cpe": "cpe:2.3:a:merge-descriptors:merge-descriptors:1.0.1:*:*:*:*:*:*:*",
368397          "purl": "pkg:npm/merge-descriptors@1.0.1",
368398          "swid": {
368399            "attachment": {}
368400          },
368401          "pedigree": {},
368402          "externalReferences": [
368403            {
368404              "url": "git+https://github.com/component/merge-descriptors.git",
368405              "type": "distribution"
368406            },
368407            {
368408              "url": "https://github.com/component/merge-descriptors#readme",
368409              "type": "website"
368410            }
368411          ],
368412          "evidence": {},
368413          "signature": {
368414            "signature": {
368415              "publicKey": {}
368416            }
368417          },
368418          "modelCard": {
368419            "modelParameters": {
368420              "approach": {}
368421            },
368422            "quantitativeAnalysis": {
368423              "graphics": {}
368424            },
368425            "considerations": {}
368426          }
368427        },
368428        {
368429          "type": "library",
368430          "bom-ref": "pkg:npm/methods@1.1.2?package-id=96ba5c582a21e3ad",
368431          "supplier": {},
368432          "name": "methods",
368433          "version": "1.1.2",
368434          "description": "HTTP methods that node supports",
368435          "licenses": [
368436            {
368437              "license": {
368438                "id": "MIT"
368439              }
368440            }
368441          ],
368442          "cpe": "cpe:2.3:a:methods:methods:1.1.2:*:*:*:*:*:*:*",
368443          "purl": "pkg:npm/methods@1.1.2",
368444          "swid": {
368445            "attachment": {}
368446          },
368447          "pedigree": {},
368448          "externalReferences": [
368449            {
368450              "url": "git+https://github.com/jshttp/methods.git",
368451              "type": "distribution"
368452            },
368453            {
368454              "url": "https://github.com/jshttp/methods#readme",
368455              "type": "website"
368456            }
368457          ],
368458          "evidence": {},
368459          "signature": {
368460            "signature": {
368461              "publicKey": {}
368462            }
368463          },
368464          "modelCard": {
368465            "modelParameters": {
368466              "approach": {}
368467            },
368468            "quantitativeAnalysis": {
368469              "graphics": {}
368470            },
368471            "considerations": {}
368472          }
368473        },
368474        {
368475          "type": "library",
368476          "bom-ref": "pkg:npm/mime@1.6.0?package-id=e5feb4f33fab3438",
368477          "supplier": {},
368478          "author": "Robert Kieffer \u003crobert@broofa.com\u003e (http://github.com/broofa)",
368479          "name": "mime",
368480          "version": "1.6.0",
368481          "description": "A comprehensive library for mime-type mapping",
368482          "licenses": [
368483            {
368484              "license": {
368485                "id": "MIT"
368486              }
368487            }
368488          ],
368489          "cpe": "cpe:2.3:a:broofa:mime:1.6.0:*:*:*:*:*:*:*",
368490          "purl": "pkg:npm/mime@1.6.0",
368491          "swid": {
368492            "attachment": {}
368493          },
368494          "pedigree": {},
368495          "externalReferences": [
368496            {
368497              "url": "git+https://github.com/broofa/node-mime.git",
368498              "type": "distribution"
368499            },
368500            {
368501              "url": "https://github.com/broofa/node-mime#readme",
368502              "type": "website"
368503            }
368504          ],
368505          "evidence": {},
368506          "signature": {
368507            "signature": {
368508              "publicKey": {}
368509            }
368510          },
368511          "modelCard": {
368512            "modelParameters": {
368513              "approach": {}
368514            },
368515            "quantitativeAnalysis": {
368516              "graphics": {}
368517            },
368518            "considerations": {}
368519          }
368520        },
368521        {
368522          "type": "library",
368523          "bom-ref": "pkg:npm/mime-db@1.35.0?package-id=c25238efc221af78",
368524          "supplier": {},
368525          "name": "mime-db",
368526          "version": "1.35.0",
368527          "description": "Media Type Database",
368528          "licenses": [
368529            {
368530              "license": {
368531                "id": "MIT"
368532              }
368533            }
368534          ],
368535          "cpe": "cpe:2.3:a:mime-db:mime-db:1.35.0:*:*:*:*:*:*:*",
368536          "purl": "pkg:npm/mime-db@1.35.0",
368537          "swid": {
368538            "attachment": {}
368539          },
368540          "pedigree": {},
368541          "externalReferences": [
368542            {
368543              "url": "git+https://github.com/jshttp/mime-db.git",
368544              "type": "distribution"
368545            },
368546            {
368547              "url": "https://github.com/jshttp/mime-db#readme",
368548              "type": "website"
368549            }
368550          ],
368551          "evidence": {},
368552          "signature": {
368553            "signature": {
368554              "publicKey": {}
368555            }
368556          },
368557          "modelCard": {
368558            "modelParameters": {
368559              "approach": {}
368560            },
368561            "quantitativeAnalysis": {
368562              "graphics": {}
368563            },
368564            "considerations": {}
368565          }
368566        },
368567        {
368568          "type": "library",
368569          "bom-ref": "pkg:npm/mime-db@1.48.0?package-id=eea4ac905892bff2",
368570          "supplier": {},
368571          "name": "mime-db",
368572          "version": "1.48.0",
368573          "description": "Media Type Database",
368574          "licenses": [
368575            {
368576              "license": {
368577                "id": "MIT"
368578              }
368579            }
368580          ],
368581          "cpe": "cpe:2.3:a:mime-db:mime-db:1.48.0:*:*:*:*:*:*:*",
368582          "purl": "pkg:npm/mime-db@1.48.0",
368583          "swid": {
368584            "attachment": {}
368585          },
368586          "pedigree": {},
368587          "externalReferences": [
368588            {
368589              "url": "git+https://github.com/jshttp/mime-db.git",
368590              "type": "distribution"
368591            },
368592            {
368593              "url": "https://github.com/jshttp/mime-db#readme",
368594              "type": "website"
368595            }
368596          ],
368597          "evidence": {},
368598          "signature": {
368599            "signature": {
368600              "publicKey": {}
368601            }
368602          },
368603          "modelCard": {
368604            "modelParameters": {
368605              "approach": {}
368606            },
368607            "quantitativeAnalysis": {
368608              "graphics": {}
368609            },
368610            "considerations": {}
368611          }
368612        },
368613        {
368614          "type": "library",
368615          "bom-ref": "pkg:npm/mime-types@2.1.19?package-id=62a25db5618d2057",
368616          "supplier": {},
368617          "name": "mime-types",
368618          "version": "2.1.19",
368619          "description": "The ultimate javascript content-type utility.",
368620          "licenses": [
368621            {
368622              "license": {
368623                "id": "MIT"
368624              }
368625            }
368626          ],
368627          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.19:*:*:*:*:*:*:*",
368628          "purl": "pkg:npm/mime-types@2.1.19",
368629          "swid": {
368630            "attachment": {}
368631          },
368632          "pedigree": {},
368633          "externalReferences": [
368634            {
368635              "url": "git+https://github.com/jshttp/mime-types.git",
368636              "type": "distribution"
368637            },
368638            {
368639              "url": "https://github.com/jshttp/mime-types#readme",
368640              "type": "website"
368641            }
368642          ],
368643          "evidence": {},
368644          "signature": {
368645            "signature": {
368646              "publicKey": {}
368647            }
368648          },
368649          "modelCard": {
368650            "modelParameters": {
368651              "approach": {}
368652            },
368653            "quantitativeAnalysis": {
368654              "graphics": {}
368655            },
368656            "considerations": {}
368657          }
368658        },
368659        {
368660          "type": "library",
368661          "bom-ref": "pkg:npm/mime-types@2.1.31?package-id=8fc592adbce7fc36",
368662          "supplier": {},
368663          "name": "mime-types",
368664          "version": "2.1.31",
368665          "description": "The ultimate javascript content-type utility.",
368666          "licenses": [
368667            {
368668              "license": {
368669                "id": "MIT"
368670              }
368671            }
368672          ],
368673          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.31:*:*:*:*:*:*:*",
368674          "purl": "pkg:npm/mime-types@2.1.31",
368675          "swid": {
368676            "attachment": {}
368677          },
368678          "pedigree": {},
368679          "externalReferences": [
368680            {
368681              "url": "git+https://github.com/jshttp/mime-types.git",
368682              "type": "distribution"
368683            },
368684            {
368685              "url": "https://github.com/jshttp/mime-types#readme",
368686              "type": "website"
368687            }
368688          ],
368689          "evidence": {},
368690          "signature": {
368691            "signature": {
368692              "publicKey": {}
368693            }
368694          },
368695          "modelCard": {
368696            "modelParameters": {
368697              "approach": {}
368698            },
368699            "quantitativeAnalysis": {
368700              "graphics": {}
368701            },
368702            "considerations": {}
368703          }
368704        },
368705        {
368706          "type": "library",
368707          "bom-ref": "pkg:npm/minimatch@3.0.4?package-id=7fcd6e247b4522bb",
368708          "supplier": {},
368709          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
368710          "name": "minimatch",
368711          "version": "3.0.4",
368712          "description": "a glob matcher in javascript",
368713          "licenses": [
368714            {
368715              "license": {
368716                "id": "ISC"
368717              }
368718            }
368719          ],
368720          "cpe": "cpe:2.3:a:minimatch:minimatch:3.0.4:*:*:*:*:*:*:*",
368721          "purl": "pkg:npm/minimatch@3.0.4",
368722          "swid": {
368723            "attachment": {}
368724          },
368725          "pedigree": {},
368726          "externalReferences": [
368727            {
368728              "url": "git://github.com/isaacs/minimatch.git",
368729              "type": "distribution"
368730            },
368731            {
368732              "url": "https://github.com/isaacs/minimatch#readme",
368733              "type": "website"
368734            }
368735          ],
368736          "evidence": {},
368737          "signature": {
368738            "signature": {
368739              "publicKey": {}
368740            }
368741          },
368742          "modelCard": {
368743            "modelParameters": {
368744              "approach": {}
368745            },
368746            "quantitativeAnalysis": {
368747              "graphics": {}
368748            },
368749            "considerations": {}
368750          }
368751        },
368752        {
368753          "type": "library",
368754          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=83649e55dcb9188",
368755          "supplier": {},
368756          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
368757          "name": "minimatch",
368758          "version": "3.1.2",
368759          "description": "a glob matcher in javascript",
368760          "licenses": [
368761            {
368762              "license": {
368763                "id": "ISC"
368764              }
368765            }
368766          ],
368767          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
368768          "purl": "pkg:npm/minimatch@3.1.2",
368769          "swid": {
368770            "attachment": {}
368771          },
368772          "pedigree": {},
368773          "externalReferences": [
368774            {
368775              "url": "git://github.com/isaacs/minimatch.git",
368776              "type": "distribution"
368777            },
368778            {
368779              "url": "https://github.com/isaacs/minimatch#readme",
368780              "type": "website"
368781            }
368782          ],
368783          "evidence": {},
368784          "signature": {
368785            "signature": {
368786              "publicKey": {}
368787            }
368788          },
368789          "modelCard": {
368790            "modelParameters": {
368791              "approach": {}
368792            },
368793            "quantitativeAnalysis": {
368794              "graphics": {}
368795            },
368796            "considerations": {}
368797          }
368798        },
368799        {
368800          "type": "library",
368801          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=c7c070a6bd46c27c",
368802          "supplier": {},
368803          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
368804          "name": "minimatch",
368805          "version": "3.1.2",
368806          "description": "a glob matcher in javascript",
368807          "licenses": [
368808            {
368809              "license": {
368810                "id": "ISC"
368811              }
368812            }
368813          ],
368814          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
368815          "purl": "pkg:npm/minimatch@3.1.2",
368816          "swid": {
368817            "attachment": {}
368818          },
368819          "pedigree": {},
368820          "externalReferences": [
368821            {
368822              "url": "git://github.com/isaacs/minimatch.git",
368823              "type": "distribution"
368824            },
368825            {
368826              "url": "https://github.com/isaacs/minimatch#readme",
368827              "type": "website"
368828            }
368829          ],
368830          "evidence": {},
368831          "signature": {
368832            "signature": {
368833              "publicKey": {}
368834            }
368835          },
368836          "modelCard": {
368837            "modelParameters": {
368838              "approach": {}
368839            },
368840            "quantitativeAnalysis": {
368841              "graphics": {}
368842            },
368843            "considerations": {}
368844          }
368845        },
368846        {
368847          "type": "library",
368848          "bom-ref": "pkg:npm/minimist@1.2.5?package-id=7e33f89f406fa4cd",
368849          "supplier": {},
368850          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
368851          "name": "minimist",
368852          "version": "1.2.5",
368853          "description": "parse argument options",
368854          "licenses": [
368855            {
368856              "license": {
368857                "id": "MIT"
368858              }
368859            }
368860          ],
368861          "cpe": "cpe:2.3:a:minimist:minimist:1.2.5:*:*:*:*:*:*:*",
368862          "purl": "pkg:npm/minimist@1.2.5",
368863          "swid": {
368864            "attachment": {}
368865          },
368866          "pedigree": {},
368867          "externalReferences": [
368868            {
368869              "url": "git://github.com/substack/minimist.git",
368870              "type": "distribution"
368871            },
368872            {
368873              "url": "https://github.com/substack/minimist",
368874              "type": "website"
368875            }
368876          ],
368877          "evidence": {},
368878          "signature": {
368879            "signature": {
368880              "publicKey": {}
368881            }
368882          },
368883          "modelCard": {
368884            "modelParameters": {
368885              "approach": {}
368886            },
368887            "quantitativeAnalysis": {
368888              "graphics": {}
368889            },
368890            "considerations": {}
368891          }
368892        },
368893        {
368894          "type": "library",
368895          "bom-ref": "pkg:npm/minimist@1.2.6?package-id=65c18082a40e8fdd",
368896          "supplier": {},
368897          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
368898          "name": "minimist",
368899          "version": "1.2.6",
368900          "description": "parse argument options",
368901          "licenses": [
368902            {
368903              "license": {
368904                "id": "MIT"
368905              }
368906            }
368907          ],
368908          "cpe": "cpe:2.3:a:minimist:minimist:1.2.6:*:*:*:*:*:*:*",
368909          "purl": "pkg:npm/minimist@1.2.6",
368910          "swid": {
368911            "attachment": {}
368912          },
368913          "pedigree": {},
368914          "externalReferences": [
368915            {
368916              "url": "git://github.com/substack/minimist.git",
368917              "type": "distribution"
368918            },
368919            {
368920              "url": "https://github.com/substack/minimist",
368921              "type": "website"
368922            }
368923          ],
368924          "evidence": {},
368925          "signature": {
368926            "signature": {
368927              "publicKey": {}
368928            }
368929          },
368930          "modelCard": {
368931            "modelParameters": {
368932              "approach": {}
368933            },
368934            "quantitativeAnalysis": {
368935              "graphics": {}
368936            },
368937            "considerations": {}
368938          }
368939        },
368940        {
368941          "type": "library",
368942          "bom-ref": "pkg:npm/minipass@2.9.0?package-id=f2f474de24692541",
368943          "supplier": {},
368944          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
368945          "name": "minipass",
368946          "version": "2.9.0",
368947          "description": "minimal implementation of a PassThrough stream",
368948          "licenses": [
368949            {
368950              "license": {
368951                "id": "ISC"
368952              }
368953            }
368954          ],
368955          "cpe": "cpe:2.3:a:minipass:minipass:2.9.0:*:*:*:*:*:*:*",
368956          "purl": "pkg:npm/minipass@2.9.0",
368957          "swid": {
368958            "attachment": {}
368959          },
368960          "pedigree": {},
368961          "externalReferences": [
368962            {
368963              "url": "git+https://github.com/isaacs/minipass.git",
368964              "type": "distribution"
368965            },
368966            {
368967              "url": "https://github.com/isaacs/minipass#readme",
368968              "type": "website"
368969            }
368970          ],
368971          "evidence": {},
368972          "signature": {
368973            "signature": {
368974              "publicKey": {}
368975            }
368976          },
368977          "modelCard": {
368978            "modelParameters": {
368979              "approach": {}
368980            },
368981            "quantitativeAnalysis": {
368982              "graphics": {}
368983            },
368984            "considerations": {}
368985          }
368986        },
368987        {
368988          "type": "library",
368989          "bom-ref": "pkg:npm/minipass@2.9.0?package-id=5d775be3798a9729",
368990          "supplier": {},
368991          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
368992          "name": "minipass",
368993          "version": "2.9.0",
368994          "description": "minimal implementation of a PassThrough stream",
368995          "licenses": [
368996            {
368997              "license": {
368998                "id": "ISC"
368999              }
369000            }
369001          ],
369002          "cpe": "cpe:2.3:a:minipass:minipass:2.9.0:*:*:*:*:*:*:*",
369003          "purl": "pkg:npm/minipass@2.9.0",
369004          "swid": {
369005            "attachment": {}
369006          },
369007          "pedigree": {},
369008          "externalReferences": [
369009            {
369010              "url": "git+https://github.com/isaacs/minipass.git",
369011              "type": "distribution"
369012            },
369013            {
369014              "url": "https://github.com/isaacs/minipass#readme",
369015              "type": "website"
369016            }
369017          ],
369018          "evidence": {},
369019          "signature": {
369020            "signature": {
369021              "publicKey": {}
369022            }
369023          },
369024          "modelCard": {
369025            "modelParameters": {
369026              "approach": {}
369027            },
369028            "quantitativeAnalysis": {
369029              "graphics": {}
369030            },
369031            "considerations": {}
369032          }
369033        },
369034        {
369035          "type": "library",
369036          "bom-ref": "pkg:npm/minipass@2.9.0?package-id=e33a08c31794e287",
369037          "supplier": {},
369038          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
369039          "name": "minipass",
369040          "version": "2.9.0",
369041          "description": "minimal implementation of a PassThrough stream",
369042          "licenses": [
369043            {
369044              "license": {
369045                "id": "ISC"
369046              }
369047            }
369048          ],
369049          "cpe": "cpe:2.3:a:minipass:minipass:2.9.0:*:*:*:*:*:*:*",
369050          "purl": "pkg:npm/minipass@2.9.0",
369051          "swid": {
369052            "attachment": {}
369053          },
369054          "pedigree": {},
369055          "externalReferences": [
369056            {
369057              "url": "git+https://github.com/isaacs/minipass.git",
369058              "type": "distribution"
369059            },
369060            {
369061              "url": "https://github.com/isaacs/minipass#readme",
369062              "type": "website"
369063            }
369064          ],
369065          "evidence": {},
369066          "signature": {
369067            "signature": {
369068              "publicKey": {}
369069            }
369070          },
369071          "modelCard": {
369072            "modelParameters": {
369073              "approach": {}
369074            },
369075            "quantitativeAnalysis": {
369076              "graphics": {}
369077            },
369078            "considerations": {}
369079          }
369080        },
369081        {
369082          "type": "library",
369083          "bom-ref": "pkg:npm/minipass@2.9.0?package-id=535794a8ced5f304",
369084          "supplier": {},
369085          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
369086          "name": "minipass",
369087          "version": "2.9.0",
369088          "description": "minimal implementation of a PassThrough stream",
369089          "licenses": [
369090            {
369091              "license": {
369092                "id": "ISC"
369093              }
369094            }
369095          ],
369096          "cpe": "cpe:2.3:a:minipass:minipass:2.9.0:*:*:*:*:*:*:*",
369097          "purl": "pkg:npm/minipass@2.9.0",
369098          "swid": {
369099            "attachment": {}
369100          },
369101          "pedigree": {},
369102          "externalReferences": [
369103            {
369104              "url": "git+https://github.com/isaacs/minipass.git",
369105              "type": "distribution"
369106            },
369107            {
369108              "url": "https://github.com/isaacs/minipass#readme",
369109              "type": "website"
369110            }
369111          ],
369112          "evidence": {},
369113          "signature": {
369114            "signature": {
369115              "publicKey": {}
369116            }
369117          },
369118          "modelCard": {
369119            "modelParameters": {
369120              "approach": {}
369121            },
369122            "quantitativeAnalysis": {
369123              "graphics": {}
369124            },
369125            "considerations": {}
369126          }
369127        },
369128        {
369129          "type": "library",
369130          "bom-ref": "pkg:npm/minizlib@1.3.3?package-id=140f93595fa83c95",
369131          "supplier": {},
369132          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
369133          "name": "minizlib",
369134          "version": "1.3.3",
369135          "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
369136          "licenses": [
369137            {
369138              "license": {
369139                "id": "MIT"
369140              }
369141            }
369142          ],
369143          "cpe": "cpe:2.3:a:minizlib:minizlib:1.3.3:*:*:*:*:*:*:*",
369144          "purl": "pkg:npm/minizlib@1.3.3",
369145          "swid": {
369146            "attachment": {}
369147          },
369148          "pedigree": {},
369149          "externalReferences": [
369150            {
369151              "url": "git+https://github.com/isaacs/minizlib.git",
369152              "type": "distribution"
369153            },
369154            {
369155              "url": "https://github.com/isaacs/minizlib#readme",
369156              "type": "website"
369157            }
369158          ],
369159          "evidence": {},
369160          "signature": {
369161            "signature": {
369162              "publicKey": {}
369163            }
369164          },
369165          "modelCard": {
369166            "modelParameters": {
369167              "approach": {}
369168            },
369169            "quantitativeAnalysis": {
369170              "graphics": {}
369171            },
369172            "considerations": {}
369173          }
369174        },
369175        {
369176          "type": "library",
369177          "bom-ref": "pkg:npm/mississippi@3.0.0?package-id=9436d1be28573634",
369178          "supplier": {},
369179          "author": "max ogden",
369180          "name": "mississippi",
369181          "version": "3.0.0",
369182          "description": "a collection of useful streams",
369183          "licenses": [
369184            {
369185              "license": {
369186                "id": "BSD-2-Clause"
369187              }
369188            }
369189          ],
369190          "cpe": "cpe:2.3:a:mississippi:mississippi:3.0.0:*:*:*:*:*:*:*",
369191          "purl": "pkg:npm/mississippi@3.0.0",
369192          "swid": {
369193            "attachment": {}
369194          },
369195          "pedigree": {},
369196          "externalReferences": [
369197            {
369198              "url": "git+https://github.com/maxogden/mississippi.git",
369199              "type": "distribution"
369200            },
369201            {
369202              "url": "https://github.com/maxogden/mississippi#readme",
369203              "type": "website"
369204            }
369205          ],
369206          "evidence": {},
369207          "signature": {
369208            "signature": {
369209              "publicKey": {}
369210            }
369211          },
369212          "modelCard": {
369213            "modelParameters": {
369214              "approach": {}
369215            },
369216            "quantitativeAnalysis": {
369217              "graphics": {}
369218            },
369219            "considerations": {}
369220          }
369221        },
369222        {
369223          "type": "library",
369224          "bom-ref": "pkg:npm/mkdirp@0.5.5?package-id=85fdcef12cbeea83",
369225          "supplier": {},
369226          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
369227          "name": "mkdirp",
369228          "version": "0.5.5",
369229          "description": "Recursively mkdir, like `mkdir -p`",
369230          "licenses": [
369231            {
369232              "license": {
369233                "id": "MIT"
369234              }
369235            }
369236          ],
369237          "cpe": "cpe:2.3:a:substack:mkdirp:0.5.5:*:*:*:*:*:*:*",
369238          "purl": "pkg:npm/mkdirp@0.5.5",
369239          "swid": {
369240            "attachment": {}
369241          },
369242          "pedigree": {},
369243          "externalReferences": [
369244            {
369245              "url": "git+https://github.com/substack/node-mkdirp.git",
369246              "type": "distribution"
369247            },
369248            {
369249              "url": "https://github.com/substack/node-mkdirp#readme",
369250              "type": "website"
369251            }
369252          ],
369253          "evidence": {},
369254          "signature": {
369255            "signature": {
369256              "publicKey": {}
369257            }
369258          },
369259          "modelCard": {
369260            "modelParameters": {
369261              "approach": {}
369262            },
369263            "quantitativeAnalysis": {
369264              "graphics": {}
369265            },
369266            "considerations": {}
369267          }
369268        },
369269        {
369270          "type": "library",
369271          "bom-ref": "pkg:npm/mkdirp@0.5.6?package-id=197267e394c01d60",
369272          "supplier": {},
369273          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
369274          "name": "mkdirp",
369275          "version": "0.5.6",
369276          "description": "Recursively mkdir, like `mkdir -p`",
369277          "licenses": [
369278            {
369279              "license": {
369280                "id": "MIT"
369281              }
369282            }
369283          ],
369284          "cpe": "cpe:2.3:a:substack:mkdirp:0.5.6:*:*:*:*:*:*:*",
369285          "purl": "pkg:npm/mkdirp@0.5.6",
369286          "swid": {
369287            "attachment": {}
369288          },
369289          "pedigree": {},
369290          "externalReferences": [
369291            {
369292              "url": "git+https://github.com/substack/node-mkdirp.git",
369293              "type": "distribution"
369294            },
369295            {
369296              "url": "https://github.com/substack/node-mkdirp#readme",
369297              "type": "website"
369298            }
369299          ],
369300          "evidence": {},
369301          "signature": {
369302            "signature": {
369303              "publicKey": {}
369304            }
369305          },
369306          "modelCard": {
369307            "modelParameters": {
369308              "approach": {}
369309            },
369310            "quantitativeAnalysis": {
369311              "graphics": {}
369312            },
369313            "considerations": {}
369314          }
369315        },
369316        {
369317          "type": "library",
369318          "bom-ref": "pkg:npm/moment@2.29.1?package-id=8da2db2786540a61",
369319          "supplier": {},
369320          "author": "Iskren Ivov Chernev \u003ciskren.chernev@gmail.com\u003e (https://github.com/ichernev)",
369321          "name": "moment",
369322          "version": "2.29.1",
369323          "description": "Parse, validate, manipulate, and display dates",
369324          "licenses": [
369325            {
369326              "license": {
369327                "id": "MIT"
369328              }
369329            }
369330          ],
369331          "cpe": "cpe:2.3:a:moment:moment:2.29.1:*:*:*:*:*:*:*",
369332          "purl": "pkg:npm/moment@2.29.1",
369333          "swid": {
369334            "attachment": {}
369335          },
369336          "pedigree": {},
369337          "externalReferences": [
369338            {
369339              "url": "git+https://github.com/moment/moment.git",
369340              "type": "distribution"
369341            },
369342            {
369343              "url": "https://momentjs.com",
369344              "type": "website"
369345            }
369346          ],
369347          "evidence": {},
369348          "signature": {
369349            "signature": {
369350              "publicKey": {}
369351            }
369352          },
369353          "modelCard": {
369354            "modelParameters": {
369355              "approach": {}
369356            },
369357            "quantitativeAnalysis": {
369358              "graphics": {}
369359            },
369360            "considerations": {}
369361          }
369362        },
369363        {
369364          "type": "library",
369365          "bom-ref": "pkg:npm/moment-timezone@0.5.33?package-id=d72a641ddce5ae2d",
369366          "supplier": {},
369367          "author": "Tim Wood \u003cwashwithcare@gmail.com\u003e (http://timwoodcreates.com/)",
369368          "name": "moment-timezone",
369369          "version": "0.5.33",
369370          "description": "Parse and display moments in any timezone.",
369371          "licenses": [
369372            {
369373              "license": {
369374                "id": "MIT"
369375              }
369376            }
369377          ],
369378          "cpe": "cpe:2.3:a:moment-timezone:moment-timezone:0.5.33:*:*:*:*:*:*:*",
369379          "purl": "pkg:npm/moment-timezone@0.5.33",
369380          "swid": {
369381            "attachment": {}
369382          },
369383          "pedigree": {},
369384          "externalReferences": [
369385            {
369386              "url": "git+https://github.com/moment/moment-timezone.git",
369387              "type": "distribution"
369388            },
369389            {
369390              "url": "http://momentjs.com/timezone/",
369391              "type": "website"
369392            }
369393          ],
369394          "evidence": {},
369395          "signature": {
369396            "signature": {
369397              "publicKey": {}
369398            }
369399          },
369400          "modelCard": {
369401            "modelParameters": {
369402              "approach": {}
369403            },
369404            "quantitativeAnalysis": {
369405              "graphics": {}
369406            },
369407            "considerations": {}
369408          }
369409        },
369410        {
369411          "type": "library",
369412          "bom-ref": "pkg:npm/move-concurrently@1.0.1?package-id=bd433a898366d4cd",
369413          "supplier": {},
369414          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
369415          "name": "move-concurrently",
369416          "version": "1.0.1",
369417          "description": "Promises of moves of files or directories with rename, falling back to recursive rename/copy on EXDEV errors, with configurable concurrency and win32 junction support.",
369418          "licenses": [
369419            {
369420              "license": {
369421                "id": "ISC"
369422              }
369423            }
369424          ],
369425          "cpe": "cpe:2.3:a:move-concurrently:move-concurrently:1.0.1:*:*:*:*:*:*:*",
369426          "purl": "pkg:npm/move-concurrently@1.0.1",
369427          "swid": {
369428            "attachment": {}
369429          },
369430          "pedigree": {},
369431          "externalReferences": [
369432            {
369433              "url": "git+https://github.com/npm/move-concurrently.git",
369434              "type": "distribution"
369435            },
369436            {
369437              "url": "https://www.npmjs.com/package/move-concurrently",
369438              "type": "website"
369439            }
369440          ],
369441          "evidence": {},
369442          "signature": {
369443            "signature": {
369444              "publicKey": {}
369445            }
369446          },
369447          "modelCard": {
369448            "modelParameters": {
369449              "approach": {}
369450            },
369451            "quantitativeAnalysis": {
369452              "graphics": {}
369453            },
369454            "considerations": {}
369455          }
369456        },
369457        {
369458          "type": "library",
369459          "bom-ref": "pkg:npm/ms@2.0.0?package-id=f2303b808f773f8a",
369460          "supplier": {},
369461          "name": "ms",
369462          "version": "2.0.0",
369463          "description": "Tiny milisecond conversion utility",
369464          "licenses": [
369465            {
369466              "license": {
369467                "id": "MIT"
369468              }
369469            }
369470          ],
369471          "cpe": "cpe:2.3:a:zeit:ms:2.0.0:*:*:*:*:*:*:*",
369472          "purl": "pkg:npm/ms@2.0.0",
369473          "swid": {
369474            "attachment": {}
369475          },
369476          "pedigree": {},
369477          "externalReferences": [
369478            {
369479              "url": "git+https://github.com/zeit/ms.git",
369480              "type": "distribution"
369481            },
369482            {
369483              "url": "https://github.com/zeit/ms#readme",
369484              "type": "website"
369485            }
369486          ],
369487          "evidence": {},
369488          "signature": {
369489            "signature": {
369490              "publicKey": {}
369491            }
369492          },
369493          "modelCard": {
369494            "modelParameters": {
369495              "approach": {}
369496            },
369497            "quantitativeAnalysis": {
369498              "graphics": {}
369499            },
369500            "considerations": {}
369501          }
369502        },
369503        {
369504          "type": "library",
369505          "bom-ref": "pkg:npm/ms@2.0.0?package-id=e80bdbf70c59171",
369506          "supplier": {},
369507          "name": "ms",
369508          "version": "2.0.0",
369509          "description": "Tiny milisecond conversion utility",
369510          "licenses": [
369511            {
369512              "license": {
369513                "id": "MIT"
369514              }
369515            }
369516          ],
369517          "cpe": "cpe:2.3:a:zeit:ms:2.0.0:*:*:*:*:*:*:*",
369518          "purl": "pkg:npm/ms@2.0.0",
369519          "swid": {
369520            "attachment": {}
369521          },
369522          "pedigree": {},
369523          "externalReferences": [
369524            {
369525              "url": "git+https://github.com/zeit/ms.git",
369526              "type": "distribution"
369527            },
369528            {
369529              "url": "https://github.com/zeit/ms#readme",
369530              "type": "website"
369531            }
369532          ],
369533          "evidence": {},
369534          "signature": {
369535            "signature": {
369536              "publicKey": {}
369537            }
369538          },
369539          "modelCard": {
369540            "modelParameters": {
369541              "approach": {}
369542            },
369543            "quantitativeAnalysis": {
369544              "graphics": {}
369545            },
369546            "considerations": {}
369547          }
369548        },
369549        {
369550          "type": "library",
369551          "bom-ref": "pkg:npm/ms@2.0.0?package-id=c642cad8fb676cc7",
369552          "supplier": {},
369553          "name": "ms",
369554          "version": "2.0.0",
369555          "description": "Tiny milisecond conversion utility",
369556          "licenses": [
369557            {
369558              "license": {
369559                "id": "MIT"
369560              }
369561            }
369562          ],
369563          "cpe": "cpe:2.3:a:zeit:ms:2.0.0:*:*:*:*:*:*:*",
369564          "purl": "pkg:npm/ms@2.0.0",
369565          "swid": {
369566            "attachment": {}
369567          },
369568          "pedigree": {},
369569          "externalReferences": [
369570            {
369571              "url": "git+https://github.com/zeit/ms.git",
369572              "type": "distribution"
369573            },
369574            {
369575              "url": "https://github.com/zeit/ms#readme",
369576              "type": "website"
369577            }
369578          ],
369579          "evidence": {},
369580          "signature": {
369581            "signature": {
369582              "publicKey": {}
369583            }
369584          },
369585          "modelCard": {
369586            "modelParameters": {
369587              "approach": {}
369588            },
369589            "quantitativeAnalysis": {
369590              "graphics": {}
369591            },
369592            "considerations": {}
369593          }
369594        },
369595        {
369596          "type": "library",
369597          "bom-ref": "pkg:npm/ms@2.0.0?package-id=bf9a829bc7ce752e",
369598          "supplier": {},
369599          "name": "ms",
369600          "version": "2.0.0",
369601          "description": "Tiny milisecond conversion utility",
369602          "licenses": [
369603            {
369604              "license": {
369605                "id": "MIT"
369606              }
369607            }
369608          ],
369609          "cpe": "cpe:2.3:a:zeit:ms:2.0.0:*:*:*:*:*:*:*",
369610          "purl": "pkg:npm/ms@2.0.0",
369611          "swid": {
369612            "attachment": {}
369613          },
369614          "pedigree": {},
369615          "externalReferences": [
369616            {
369617              "url": "git+https://github.com/zeit/ms.git",
369618              "type": "distribution"
369619            },
369620            {
369621              "url": "https://github.com/zeit/ms#readme",
369622              "type": "website"
369623            }
369624          ],
369625          "evidence": {},
369626          "signature": {
369627            "signature": {
369628              "publicKey": {}
369629            }
369630          },
369631          "modelCard": {
369632            "modelParameters": {
369633              "approach": {}
369634            },
369635            "quantitativeAnalysis": {
369636              "graphics": {}
369637            },
369638            "considerations": {}
369639          }
369640        },
369641        {
369642          "type": "library",
369643          "bom-ref": "pkg:npm/ms@2.0.0?package-id=aa47d5271ed463be",
369644          "supplier": {},
369645          "name": "ms",
369646          "version": "2.0.0",
369647          "description": "Tiny milisecond conversion utility",
369648          "licenses": [
369649            {
369650              "license": {
369651                "id": "MIT"
369652              }
369653            }
369654          ],
369655          "cpe": "cpe:2.3:a:zeit:ms:2.0.0:*:*:*:*:*:*:*",
369656          "purl": "pkg:npm/ms@2.0.0",
369657          "swid": {
369658            "attachment": {}
369659          },
369660          "pedigree": {},
369661          "externalReferences": [
369662            {
369663              "url": "git+https://github.com/zeit/ms.git",
369664              "type": "distribution"
369665            },
369666            {
369667              "url": "https://github.com/zeit/ms#readme",
369668              "type": "website"
369669            }
369670          ],
369671          "evidence": {},
369672          "signature": {
369673            "signature": {
369674              "publicKey": {}
369675            }
369676          },
369677          "modelCard": {
369678            "modelParameters": {
369679              "approach": {}
369680            },
369681            "quantitativeAnalysis": {
369682              "graphics": {}
369683            },
369684            "considerations": {}
369685          }
369686        },
369687        {
369688          "type": "library",
369689          "bom-ref": "pkg:npm/ms@2.0.0?package-id=489a012f564610ef",
369690          "supplier": {},
369691          "name": "ms",
369692          "version": "2.0.0",
369693          "description": "Tiny milisecond conversion utility",
369694          "licenses": [
369695            {
369696              "license": {
369697                "id": "MIT"
369698              }
369699            }
369700          ],
369701          "cpe": "cpe:2.3:a:zeit:ms:2.0.0:*:*:*:*:*:*:*",
369702          "purl": "pkg:npm/ms@2.0.0",
369703          "swid": {
369704            "attachment": {}
369705          },
369706          "pedigree": {},
369707          "externalReferences": [
369708            {
369709              "url": "git+https://github.com/zeit/ms.git",
369710              "type": "distribution"
369711            },
369712            {
369713              "url": "https://github.com/zeit/ms#readme",
369714              "type": "website"
369715            }
369716          ],
369717          "evidence": {},
369718          "signature": {
369719            "signature": {
369720              "publicKey": {}
369721            }
369722          },
369723          "modelCard": {
369724            "modelParameters": {
369725              "approach": {}
369726            },
369727            "quantitativeAnalysis": {
369728              "graphics": {}
369729            },
369730            "considerations": {}
369731          }
369732        },
369733        {
369734          "type": "library",
369735          "bom-ref": "pkg:npm/ms@2.1.1?package-id=8d2514ddd40cc73b",
369736          "supplier": {},
369737          "name": "ms",
369738          "version": "2.1.1",
369739          "description": "Tiny millisecond conversion utility",
369740          "licenses": [
369741            {
369742              "license": {
369743                "id": "MIT"
369744              }
369745            }
369746          ],
369747          "cpe": "cpe:2.3:a:zeit:ms:2.1.1:*:*:*:*:*:*:*",
369748          "purl": "pkg:npm/ms@2.1.1",
369749          "swid": {
369750            "attachment": {}
369751          },
369752          "pedigree": {},
369753          "externalReferences": [
369754            {
369755              "url": "git+https://github.com/zeit/ms.git",
369756              "type": "distribution"
369757            },
369758            {
369759              "url": "https://github.com/zeit/ms#readme",
369760              "type": "website"
369761            }
369762          ],
369763          "evidence": {},
369764          "signature": {
369765            "signature": {
369766              "publicKey": {}
369767            }
369768          },
369769          "modelCard": {
369770            "modelParameters": {
369771              "approach": {}
369772            },
369773            "quantitativeAnalysis": {
369774              "graphics": {}
369775            },
369776            "considerations": {}
369777          }
369778        },
369779        {
369780          "type": "library",
369781          "bom-ref": "pkg:npm/ms@2.1.1?package-id=c3b6931e886fa739",
369782          "supplier": {},
369783          "name": "ms",
369784          "version": "2.1.1",
369785          "description": "Tiny millisecond conversion utility",
369786          "licenses": [
369787            {
369788              "license": {
369789                "id": "MIT"
369790              }
369791            }
369792          ],
369793          "cpe": "cpe:2.3:a:zeit:ms:2.1.1:*:*:*:*:*:*:*",
369794          "purl": "pkg:npm/ms@2.1.1",
369795          "swid": {
369796            "attachment": {}
369797          },
369798          "pedigree": {},
369799          "externalReferences": [
369800            {
369801              "url": "git+https://github.com/zeit/ms.git",
369802              "type": "distribution"
369803            },
369804            {
369805              "url": "https://github.com/zeit/ms#readme",
369806              "type": "website"
369807            }
369808          ],
369809          "evidence": {},
369810          "signature": {
369811            "signature": {
369812              "publicKey": {}
369813            }
369814          },
369815          "modelCard": {
369816            "modelParameters": {
369817              "approach": {}
369818            },
369819            "quantitativeAnalysis": {
369820              "graphics": {}
369821            },
369822            "considerations": {}
369823          }
369824        },
369825        {
369826          "type": "library",
369827          "bom-ref": "pkg:npm/ms@2.1.2?package-id=11f1e1926128121e",
369828          "supplier": {},
369829          "name": "ms",
369830          "version": "2.1.2",
369831          "description": "Tiny millisecond conversion utility",
369832          "licenses": [
369833            {
369834              "license": {
369835                "id": "MIT"
369836              }
369837            }
369838          ],
369839          "cpe": "cpe:2.3:a:zeit:ms:2.1.2:*:*:*:*:*:*:*",
369840          "purl": "pkg:npm/ms@2.1.2",
369841          "swid": {
369842            "attachment": {}
369843          },
369844          "pedigree": {},
369845          "externalReferences": [
369846            {
369847              "url": "git+https://github.com/zeit/ms.git",
369848              "type": "distribution"
369849            },
369850            {
369851              "url": "https://github.com/zeit/ms#readme",
369852              "type": "website"
369853            }
369854          ],
369855          "evidence": {},
369856          "signature": {
369857            "signature": {
369858              "publicKey": {}
369859            }
369860          },
369861          "modelCard": {
369862            "modelParameters": {
369863              "approach": {}
369864            },
369865            "quantitativeAnalysis": {
369866              "graphics": {}
369867            },
369868            "considerations": {}
369869          }
369870        },
369871        {
369872          "type": "library",
369873          "bom-ref": "pkg:npm/multer@1.4.2?package-id=cd7acf9d44738a70",
369874          "supplier": {},
369875          "name": "multer",
369876          "version": "1.4.2",
369877          "description": "Middleware for handling `multipart/form-data`.",
369878          "licenses": [
369879            {
369880              "license": {
369881                "id": "MIT"
369882              }
369883            }
369884          ],
369885          "cpe": "cpe:2.3:a:expressjs:multer:1.4.2:*:*:*:*:*:*:*",
369886          "purl": "pkg:npm/multer@1.4.2",
369887          "swid": {
369888            "attachment": {}
369889          },
369890          "pedigree": {},
369891          "externalReferences": [
369892            {
369893              "url": "git+https://github.com/expressjs/multer.git",
369894              "type": "distribution"
369895            },
369896            {
369897              "url": "https://github.com/expressjs/multer#readme",
369898              "type": "website"
369899            }
369900          ],
369901          "evidence": {},
369902          "signature": {
369903            "signature": {
369904              "publicKey": {}
369905            }
369906          },
369907          "modelCard": {
369908            "modelParameters": {
369909              "approach": {}
369910            },
369911            "quantitativeAnalysis": {
369912              "graphics": {}
369913            },
369914            "considerations": {}
369915          }
369916        },
369917        {
369918          "type": "library",
369919          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=d9700f02cf26e8b8",
369920          "supplier": {},
369921          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
369922          "name": "musl",
369923          "version": "1.2.3-r4",
369924          "description": "the musl c library (libc) implementation",
369925          "licenses": [
369926            {
369927              "license": {
369928                "id": "MIT"
369929              }
369930            }
369931          ],
369932          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r4:*:*:*:*:*:*:*",
369933          "purl": "pkg:apk/alpine/musl@1.2.3-r4?arch=x86_64\u0026distro=alpine-3.17.3",
369934          "swid": {
369935            "attachment": {}
369936          },
369937          "pedigree": {},
369938          "externalReferences": [
369939            {
369940              "url": "https://musl.libc.org/",
369941              "type": "distribution"
369942            }
369943          ],
369944          "evidence": {},
369945          "signature": {
369946            "signature": {
369947              "publicKey": {}
369948            }
369949          },
369950          "modelCard": {
369951            "modelParameters": {
369952              "approach": {}
369953            },
369954            "quantitativeAnalysis": {
369955              "graphics": {}
369956            },
369957            "considerations": {}
369958          }
369959        },
369960        {
369961          "type": "library",
369962          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.3\u0026package-id=f71ecf5267e6c37b",
369963          "supplier": {},
369964          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
369965          "name": "musl-utils",
369966          "version": "1.2.3-r4",
369967          "description": "the musl c library (libc) implementation",
369968          "licenses": [
369969            {
369970              "license": {
369971                "id": "MIT"
369972              }
369973            },
369974            {
369975              "license": {
369976                "name": "AND"
369977              }
369978            },
369979            {
369980              "license": {
369981                "id": "BSD-2-Clause"
369982              }
369983            },
369984            {
369985              "license": {
369986                "name": "AND"
369987              }
369988            },
369989            {
369990              "license": {
369991                "id": "GPL-2.0-or-later"
369992              }
369993            }
369994          ],
369995          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r4:*:*:*:*:*:*:*",
369996          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r4?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.17.3",
369997          "swid": {
369998            "attachment": {}
369999          },
370000          "pedigree": {},
370001          "externalReferences": [
370002            {
370003              "url": "https://musl.libc.org/",
370004              "type": "distribution"
370005            }
370006          ],
370007          "evidence": {},
370008          "signature": {
370009            "signature": {
370010              "publicKey": {}
370011            }
370012          },
370013          "modelCard": {
370014            "modelParameters": {
370015              "approach": {}
370016            },
370017            "quantitativeAnalysis": {
370018              "graphics": {}
370019            },
370020            "considerations": {}
370021          }
370022        },
370023        {
370024          "type": "library",
370025          "bom-ref": "pkg:npm/mute-stream@0.0.7?package-id=ab0b4d84af6e6552",
370026          "supplier": {},
370027          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
370028          "name": "mute-stream",
370029          "version": "0.0.7",
370030          "description": "Bytes go in, but they don't come out (when muted).",
370031          "licenses": [
370032            {
370033              "license": {
370034                "id": "ISC"
370035              }
370036            }
370037          ],
370038          "cpe": "cpe:2.3:a:mute-stream:mute-stream:0.0.7:*:*:*:*:*:*:*",
370039          "purl": "pkg:npm/mute-stream@0.0.7",
370040          "swid": {
370041            "attachment": {}
370042          },
370043          "pedigree": {},
370044          "externalReferences": [
370045            {
370046              "url": "git://github.com/isaacs/mute-stream.git",
370047              "type": "distribution"
370048            },
370049            {
370050              "url": "https://github.com/isaacs/mute-stream#readme",
370051              "type": "website"
370052            }
370053          ],
370054          "evidence": {},
370055          "signature": {
370056            "signature": {
370057              "publicKey": {}
370058            }
370059          },
370060          "modelCard": {
370061            "modelParameters": {
370062              "approach": {}
370063            },
370064            "quantitativeAnalysis": {
370065              "graphics": {}
370066            },
370067            "considerations": {}
370068          }
370069        },
370070        {
370071          "type": "library",
370072          "bom-ref": "pkg:npm/negotiator@0.6.2?package-id=ad18b750d9f88ada",
370073          "supplier": {},
370074          "name": "negotiator",
370075          "version": "0.6.2",
370076          "description": "HTTP content negotiation",
370077          "licenses": [
370078            {
370079              "license": {
370080                "id": "MIT"
370081              }
370082            }
370083          ],
370084          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.2:*:*:*:*:*:*:*",
370085          "purl": "pkg:npm/negotiator@0.6.2",
370086          "swid": {
370087            "attachment": {}
370088          },
370089          "pedigree": {},
370090          "externalReferences": [
370091            {
370092              "url": "git+https://github.com/jshttp/negotiator.git",
370093              "type": "distribution"
370094            },
370095            {
370096              "url": "https://github.com/jshttp/negotiator#readme",
370097              "type": "website"
370098            }
370099          ],
370100          "evidence": {},
370101          "signature": {
370102            "signature": {
370103              "publicKey": {}
370104            }
370105          },
370106          "modelCard": {
370107            "modelParameters": {
370108              "approach": {}
370109            },
370110            "quantitativeAnalysis": {
370111              "graphics": {}
370112            },
370113            "considerations": {}
370114          }
370115        },
370116        {
370117          "type": "application",
370118          "bom-ref": "pkg:generic/node@14.21.3?package-id=fc0c6404af16f935",
370119          "supplier": {},
370120          "name": "node",
370121          "version": "14.21.3",
370122          "cpe": "cpe:2.3:a:nodejs:node.js:14.21.3:*:*:*:*:*:*:*",
370123          "purl": "pkg:generic/node@14.21.3",
370124          "swid": {
370125            "attachment": {}
370126          },
370127          "pedigree": {},
370128          "evidence": {},
370129          "signature": {
370130            "signature": {
370131              "publicKey": {}
370132            }
370133          },
370134          "modelCard": {
370135            "modelParameters": {
370136              "approach": {}
370137            },
370138            "quantitativeAnalysis": {
370139              "graphics": {}
370140            },
370141            "considerations": {}
370142          }
370143        },
370144        {
370145          "type": "library",
370146          "bom-ref": "pkg:npm/node-fetch@2.6.1?package-id=ff97b9d822553e25",
370147          "supplier": {},
370148          "author": "David Frank",
370149          "name": "node-fetch",
370150          "version": "2.6.1",
370151          "description": "A light-weight module that brings window.fetch to node.js",
370152          "licenses": [
370153            {
370154              "license": {
370155                "id": "MIT"
370156              }
370157            }
370158          ],
370159          "cpe": "cpe:2.3:a:node-fetch:node-fetch:2.6.1:*:*:*:*:*:*:*",
370160          "purl": "pkg:npm/node-fetch@2.6.1",
370161          "swid": {
370162            "attachment": {}
370163          },
370164          "pedigree": {},
370165          "externalReferences": [
370166            {
370167              "url": "git+https://github.com/bitinn/node-fetch.git",
370168              "type": "distribution"
370169            },
370170            {
370171              "url": "https://github.com/bitinn/node-fetch",
370172              "type": "website"
370173            }
370174          ],
370175          "evidence": {},
370176          "signature": {
370177            "signature": {
370178              "publicKey": {}
370179            }
370180          },
370181          "modelCard": {
370182            "modelParameters": {
370183              "approach": {}
370184            },
370185            "quantitativeAnalysis": {
370186              "graphics": {}
370187            },
370188            "considerations": {}
370189          }
370190        },
370191        {
370192          "type": "library",
370193          "bom-ref": "pkg:npm/node-fetch-npm@2.0.2?package-id=adeeb0d4a244c44",
370194          "supplier": {},
370195          "author": "David Frank",
370196          "name": "node-fetch-npm",
370197          "version": "2.0.2",
370198          "description": "An npm cli-oriented fork of the excellent node-fetch",
370199          "licenses": [
370200            {
370201              "license": {
370202                "id": "MIT"
370203              }
370204            }
370205          ],
370206          "cpe": "cpe:2.3:a:node-fetch-npm:node-fetch-npm:2.0.2:*:*:*:*:*:*:*",
370207          "purl": "pkg:npm/node-fetch-npm@2.0.2",
370208          "swid": {
370209            "attachment": {}
370210          },
370211          "pedigree": {},
370212          "externalReferences": [
370213            {
370214              "url": "git+https://github.com/npm/node-fetch-npm.git",
370215              "type": "distribution"
370216            },
370217            {
370218              "url": "https://github.com/npm/node-fetch-npm",
370219              "type": "website"
370220            }
370221          ],
370222          "evidence": {},
370223          "signature": {
370224            "signature": {
370225              "publicKey": {}
370226            }
370227          },
370228          "modelCard": {
370229            "modelParameters": {
370230              "approach": {}
370231            },
370232            "quantitativeAnalysis": {
370233              "graphics": {}
370234            },
370235            "considerations": {}
370236          }
370237        },
370238        {
370239          "type": "library",
370240          "bom-ref": "pkg:npm/node-gyp@5.1.1?package-id=4b12c9ba8fe75ec8",
370241          "supplier": {},
370242          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://tootallnate.net)",
370243          "name": "node-gyp",
370244          "version": "5.1.1",
370245          "description": "Node.js native addon build tool",
370246          "licenses": [
370247            {
370248              "license": {
370249                "id": "MIT"
370250              }
370251            }
370252          ],
370253          "cpe": "cpe:2.3:a:node-gyp:node-gyp:5.1.1:*:*:*:*:*:*:*",
370254          "purl": "pkg:npm/node-gyp@5.1.1",
370255          "swid": {
370256            "attachment": {}
370257          },
370258          "pedigree": {},
370259          "externalReferences": [
370260            {
370261              "url": "git://github.com/nodejs/node-gyp.git",
370262              "type": "distribution"
370263            },
370264            {
370265              "url": "https://github.com/nodejs/node-gyp#readme",
370266              "type": "website"
370267            }
370268          ],
370269          "evidence": {},
370270          "signature": {
370271            "signature": {
370272              "publicKey": {}
370273            }
370274          },
370275          "modelCard": {
370276            "modelParameters": {
370277              "approach": {}
370278            },
370279            "quantitativeAnalysis": {
370280              "graphics": {}
370281            },
370282            "considerations": {}
370283          }
370284        },
370285        {
370286          "type": "library",
370287          "bom-ref": "pkg:npm/nopt@4.0.3?package-id=2f83f388c5e5a214",
370288          "supplier": {},
370289          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
370290          "name": "nopt",
370291          "version": "4.0.3",
370292          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
370293          "licenses": [
370294            {
370295              "license": {
370296                "id": "ISC"
370297              }
370298            }
370299          ],
370300          "cpe": "cpe:2.3:a:nopt:nopt:4.0.3:*:*:*:*:*:*:*",
370301          "purl": "pkg:npm/nopt@4.0.3",
370302          "swid": {
370303            "attachment": {}
370304          },
370305          "pedigree": {},
370306          "externalReferences": [
370307            {
370308              "url": "git+https://github.com/npm/nopt.git",
370309              "type": "distribution"
370310            },
370311            {
370312              "url": "https://github.com/npm/nopt#readme",
370313              "type": "website"
370314            }
370315          ],
370316          "evidence": {},
370317          "signature": {
370318            "signature": {
370319              "publicKey": {}
370320            }
370321          },
370322          "modelCard": {
370323            "modelParameters": {
370324              "approach": {}
370325            },
370326            "quantitativeAnalysis": {
370327              "graphics": {}
370328            },
370329            "considerations": {}
370330          }
370331        },
370332        {
370333          "type": "library",
370334          "bom-ref": "pkg:npm/normalize-package-data@2.5.0?package-id=8439f54251b29848",
370335          "supplier": {},
370336          "author": "Meryn Stol \u003cmerynstol@gmail.com\u003e",
370337          "name": "normalize-package-data",
370338          "version": "2.5.0",
370339          "description": "Normalizes data that can be found in package.json files.",
370340          "licenses": [
370341            {
370342              "license": {
370343                "id": "BSD-2-Clause"
370344              }
370345            }
370346          ],
370347          "cpe": "cpe:2.3:a:normalize-package-data:normalize-package-data:2.5.0:*:*:*:*:*:*:*",
370348          "purl": "pkg:npm/normalize-package-data@2.5.0",
370349          "swid": {
370350            "attachment": {}
370351          },
370352          "pedigree": {},
370353          "externalReferences": [
370354            {
370355              "url": "git://github.com/npm/normalize-package-data.git",
370356              "type": "distribution"
370357            },
370358            {
370359              "url": "https://github.com/npm/normalize-package-data#readme",
370360              "type": "website"
370361            }
370362          ],
370363          "evidence": {},
370364          "signature": {
370365            "signature": {
370366              "publicKey": {}
370367            }
370368          },
370369          "modelCard": {
370370            "modelParameters": {
370371              "approach": {}
370372            },
370373            "quantitativeAnalysis": {
370374              "graphics": {}
370375            },
370376            "considerations": {}
370377          }
370378        },
370379        {
370380          "type": "library",
370381          "bom-ref": "pkg:npm/npm@6.14.18?package-id=f654a78607d1d312",
370382          "supplier": {},
370383          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
370384          "name": "npm",
370385          "version": "6.14.18",
370386          "description": "a package manager for JavaScript",
370387          "licenses": [
370388            {
370389              "license": {
370390                "id": "Artistic-2.0"
370391              }
370392            }
370393          ],
370394          "cpe": "cpe:2.3:a:npm:npm:6.14.18:*:*:*:*:*:*:*",
370395          "purl": "pkg:npm/npm@6.14.18",
370396          "swid": {
370397            "attachment": {}
370398          },
370399          "pedigree": {},
370400          "externalReferences": [
370401            {
370402              "url": "https://github.com/npm/cli",
370403              "type": "distribution"
370404            },
370405            {
370406              "url": "https://docs.npmjs.com/",
370407              "type": "website"
370408            }
370409          ],
370410          "evidence": {},
370411          "signature": {
370412            "signature": {
370413              "publicKey": {}
370414            }
370415          },
370416          "modelCard": {
370417            "modelParameters": {
370418              "approach": {}
370419            },
370420            "quantitativeAnalysis": {
370421              "graphics": {}
370422            },
370423            "considerations": {}
370424          }
370425        },
370426        {
370427          "type": "library",
370428          "bom-ref": "pkg:npm/npm-audit-report@1.3.3?package-id=cfbfbebf3fce8431",
370429          "supplier": {},
370430          "author": "Adam Baldwin",
370431          "name": "npm-audit-report",
370432          "version": "1.3.3",
370433          "description": "Given a response from the npm security api, render it into a variety of security reports",
370434          "licenses": [
370435            {
370436              "license": {
370437                "id": "ISC"
370438              }
370439            }
370440          ],
370441          "cpe": "cpe:2.3:a:npm-audit-report:npm-audit-report:1.3.3:*:*:*:*:*:*:*",
370442          "purl": "pkg:npm/npm-audit-report@1.3.3",
370443          "swid": {
370444            "attachment": {}
370445          },
370446          "pedigree": {},
370447          "externalReferences": [
370448            {
370449              "url": "git+https://github.com/npm/npm-audit-report.git",
370450              "type": "distribution"
370451            },
370452            {
370453              "url": "https://github.com/npm/npm-audit-report#readme",
370454              "type": "website"
370455            }
370456          ],
370457          "evidence": {},
370458          "signature": {
370459            "signature": {
370460              "publicKey": {}
370461            }
370462          },
370463          "modelCard": {
370464            "modelParameters": {
370465              "approach": {}
370466            },
370467            "quantitativeAnalysis": {
370468              "graphics": {}
370469            },
370470            "considerations": {}
370471          }
370472        },
370473        {
370474          "type": "library",
370475          "bom-ref": "pkg:npm/npm-bundled@1.1.1?package-id=9e77c8c8f13f445a",
370476          "supplier": {},
370477          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
370478          "name": "npm-bundled",
370479          "version": "1.1.1",
370480          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
370481          "licenses": [
370482            {
370483              "license": {
370484                "id": "ISC"
370485              }
370486            }
370487          ],
370488          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:1.1.1:*:*:*:*:*:*:*",
370489          "purl": "pkg:npm/npm-bundled@1.1.1",
370490          "swid": {
370491            "attachment": {}
370492          },
370493          "pedigree": {},
370494          "externalReferences": [
370495            {
370496              "url": "git+https://github.com/npm/npm-bundled.git",
370497              "type": "distribution"
370498            },
370499            {
370500              "url": "https://github.com/npm/npm-bundled#readme",
370501              "type": "website"
370502            }
370503          ],
370504          "evidence": {},
370505          "signature": {
370506            "signature": {
370507              "publicKey": {}
370508            }
370509          },
370510          "modelCard": {
370511            "modelParameters": {
370512              "approach": {}
370513            },
370514            "quantitativeAnalysis": {
370515              "graphics": {}
370516            },
370517            "considerations": {}
370518          }
370519        },
370520        {
370521          "type": "library",
370522          "bom-ref": "pkg:npm/npm-cache-filename@1.0.2?package-id=cb5b8efb67903585",
370523          "supplier": {},
370524          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
370525          "name": "npm-cache-filename",
370526          "version": "1.0.2",
370527          "description": "Given a cache folder and url, return the appropriate cache folder.",
370528          "licenses": [
370529            {
370530              "license": {
370531                "id": "ISC"
370532              }
370533            }
370534          ],
370535          "cpe": "cpe:2.3:a:npm-cache-filename:npm-cache-filename:1.0.2:*:*:*:*:*:*:*",
370536          "purl": "pkg:npm/npm-cache-filename@1.0.2",
370537          "swid": {
370538            "attachment": {}
370539          },
370540          "pedigree": {},
370541          "externalReferences": [
370542            {
370543              "url": "git://github.com/npm/npm-cache-filename.git",
370544              "type": "distribution"
370545            },
370546            {
370547              "url": "https://github.com/npm/npm-cache-filename",
370548              "type": "website"
370549            }
370550          ],
370551          "evidence": {},
370552          "signature": {
370553            "signature": {
370554              "publicKey": {}
370555            }
370556          },
370557          "modelCard": {
370558            "modelParameters": {
370559              "approach": {}
370560            },
370561            "quantitativeAnalysis": {
370562              "graphics": {}
370563            },
370564            "considerations": {}
370565          }
370566        },
370567        {
370568          "type": "library",
370569          "bom-ref": "pkg:npm/npm-init@0.0.0?package-id=e58118b5aaeeedd7",
370570          "supplier": {},
370571          "name": "npm-init",
370572          "version": "0.0.0",
370573          "description": "an initter you init wit, innit?",
370574          "licenses": [
370575            {
370576              "license": {
370577                "name": "BSD"
370578              }
370579            }
370580          ],
370581          "cpe": "cpe:2.3:a:npm-init:npm-init:0.0.0:*:*:*:*:*:*:*",
370582          "purl": "pkg:npm/npm-init@0.0.0",
370583          "swid": {
370584            "attachment": {}
370585          },
370586          "pedigree": {},
370587          "evidence": {},
370588          "signature": {
370589            "signature": {
370590              "publicKey": {}
370591            }
370592          },
370593          "modelCard": {
370594            "modelParameters": {
370595              "approach": {}
370596            },
370597            "quantitativeAnalysis": {
370598              "graphics": {}
370599            },
370600            "considerations": {}
370601          }
370602        },
370603        {
370604          "type": "library",
370605          "bom-ref": "pkg:npm/npm-install-checks@3.0.2?package-id=cbed4ef3ca50d013",
370606          "supplier": {},
370607          "author": "Robert Kowalski \u003crok@kowalski.gd\u003e",
370608          "name": "npm-install-checks",
370609          "version": "3.0.2",
370610          "description": "checks that npm runs during the installation of a module",
370611          "licenses": [
370612            {
370613              "license": {
370614                "id": "BSD-2-Clause"
370615              }
370616            }
370617          ],
370618          "cpe": "cpe:2.3:a:npm-install-checks:npm-install-checks:3.0.2:*:*:*:*:*:*:*",
370619          "purl": "pkg:npm/npm-install-checks@3.0.2",
370620          "swid": {
370621            "attachment": {}
370622          },
370623          "pedigree": {},
370624          "externalReferences": [
370625            {
370626              "url": "git://github.com/npm/npm-install-checks.git",
370627              "type": "distribution"
370628            },
370629            {
370630              "url": "https://github.com/npm/npm-install-checks",
370631              "type": "website"
370632            }
370633          ],
370634          "evidence": {},
370635          "signature": {
370636            "signature": {
370637              "publicKey": {}
370638            }
370639          },
370640          "modelCard": {
370641            "modelParameters": {
370642              "approach": {}
370643            },
370644            "quantitativeAnalysis": {
370645              "graphics": {}
370646            },
370647            "considerations": {}
370648          }
370649        },
370650        {
370651          "type": "library",
370652          "bom-ref": "pkg:npm/npm-lifecycle@3.1.5?package-id=b6ff96c0c3bbf7d2",
370653          "supplier": {},
370654          "author": "Mike Sherov",
370655          "name": "npm-lifecycle",
370656          "version": "3.1.5",
370657          "description": "JavaScript package lifecycle hook runner",
370658          "licenses": [
370659            {
370660              "license": {
370661                "id": "Artistic-2.0"
370662              }
370663            }
370664          ],
370665          "cpe": "cpe:2.3:a:npm-lifecycle:npm-lifecycle:3.1.5:*:*:*:*:*:*:*",
370666          "purl": "pkg:npm/npm-lifecycle@3.1.5",
370667          "swid": {
370668            "attachment": {}
370669          },
370670          "pedigree": {},
370671          "externalReferences": [
370672            {
370673              "url": "git://github.com/npm/lifecycle.git",
370674              "type": "distribution"
370675            },
370676            {
370677              "url": "https://github.com/npm/lifecycle#readme",
370678              "type": "website"
370679            }
370680          ],
370681          "evidence": {},
370682          "signature": {
370683            "signature": {
370684              "publicKey": {}
370685            }
370686          },
370687          "modelCard": {
370688            "modelParameters": {
370689              "approach": {}
370690            },
370691            "quantitativeAnalysis": {
370692              "graphics": {}
370693            },
370694            "considerations": {}
370695          }
370696        },
370697        {
370698          "type": "library",
370699          "bom-ref": "pkg:npm/npm-logical-tree@1.2.1?package-id=441198ebc020e01d",
370700          "supplier": {},
370701          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
370702          "name": "npm-logical-tree",
370703          "version": "1.2.1",
370704          "description": "Calculate 'logical' trees from a package.json + package-lock",
370705          "licenses": [
370706            {
370707              "license": {
370708                "id": "ISC"
370709              }
370710            }
370711          ],
370712          "cpe": "cpe:2.3:a:npm-logical-tree:npm-logical-tree:1.2.1:*:*:*:*:*:*:*",
370713          "purl": "pkg:npm/npm-logical-tree@1.2.1",
370714          "swid": {
370715            "attachment": {}
370716          },
370717          "pedigree": {},
370718          "externalReferences": [
370719            {
370720              "url": "git+https://github.com/npm/logical-tree.git",
370721              "type": "distribution"
370722            },
370723            {
370724              "url": "https://github.com/npm/logical-tree#readme",
370725              "type": "website"
370726            }
370727          ],
370728          "evidence": {},
370729          "signature": {
370730            "signature": {
370731              "publicKey": {}
370732            }
370733          },
370734          "modelCard": {
370735            "modelParameters": {
370736              "approach": {}
370737            },
370738            "quantitativeAnalysis": {
370739              "graphics": {}
370740            },
370741            "considerations": {}
370742          }
370743        },
370744        {
370745          "type": "library",
370746          "bom-ref": "pkg:npm/npm-normalize-package-bin@1.0.1?package-id=faf8a116dafcc8d",
370747          "supplier": {},
370748          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
370749          "name": "npm-normalize-package-bin",
370750          "version": "1.0.1",
370751          "description": "Turn any flavor of allowable package.json bin into a normalized object",
370752          "licenses": [
370753            {
370754              "license": {
370755                "id": "ISC"
370756              }
370757            }
370758          ],
370759          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:1.0.1:*:*:*:*:*:*:*",
370760          "purl": "pkg:npm/npm-normalize-package-bin@1.0.1",
370761          "swid": {
370762            "attachment": {}
370763          },
370764          "pedigree": {},
370765          "externalReferences": [
370766            {
370767              "url": "git+https://github.com/npm/npm-normalize-package-bin.git",
370768              "type": "distribution"
370769            },
370770            {
370771              "url": "https://github.com/npm/npm-normalize-package-bin#readme",
370772              "type": "website"
370773            }
370774          ],
370775          "evidence": {},
370776          "signature": {
370777            "signature": {
370778              "publicKey": {}
370779            }
370780          },
370781          "modelCard": {
370782            "modelParameters": {
370783              "approach": {}
370784            },
370785            "quantitativeAnalysis": {
370786              "graphics": {}
370787            },
370788            "considerations": {}
370789          }
370790        },
370791        {
370792          "type": "library",
370793          "bom-ref": "pkg:npm/npm-package-arg@6.1.1?package-id=361cb151e33b38b8",
370794          "supplier": {},
370795          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
370796          "name": "npm-package-arg",
370797          "version": "6.1.1",
370798          "description": "Parse the things that can be arguments to `npm install`",
370799          "licenses": [
370800            {
370801              "license": {
370802                "id": "ISC"
370803              }
370804            }
370805          ],
370806          "cpe": "cpe:2.3:a:npm-package-arg:npm-package-arg:6.1.1:*:*:*:*:*:*:*",
370807          "purl": "pkg:npm/npm-package-arg@6.1.1",
370808          "swid": {
370809            "attachment": {}
370810          },
370811          "pedigree": {},
370812          "externalReferences": [
370813            {
370814              "url": "git+https://github.com/npm/npm-package-arg.git",
370815              "type": "distribution"
370816            },
370817            {
370818              "url": "https://github.com/npm/npm-package-arg",
370819              "type": "website"
370820            }
370821          ],
370822          "evidence": {},
370823          "signature": {
370824            "signature": {
370825              "publicKey": {}
370826            }
370827          },
370828          "modelCard": {
370829            "modelParameters": {
370830              "approach": {}
370831            },
370832            "quantitativeAnalysis": {
370833              "graphics": {}
370834            },
370835            "considerations": {}
370836          }
370837        },
370838        {
370839          "type": "library",
370840          "bom-ref": "pkg:npm/npm-packlist@1.4.8?package-id=45dd5db953381614",
370841          "supplier": {},
370842          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
370843          "name": "npm-packlist",
370844          "version": "1.4.8",
370845          "description": "Get a list of the files to add from a folder into an npm package",
370846          "licenses": [
370847            {
370848              "license": {
370849                "id": "ISC"
370850              }
370851            }
370852          ],
370853          "cpe": "cpe:2.3:a:npm-packlist:npm-packlist:1.4.8:*:*:*:*:*:*:*",
370854          "purl": "pkg:npm/npm-packlist@1.4.8",
370855          "swid": {
370856            "attachment": {}
370857          },
370858          "pedigree": {},
370859          "externalReferences": [
370860            {
370861              "url": "git+https://github.com/npm/npm-packlist.git",
370862              "type": "distribution"
370863            },
370864            {
370865              "url": "https://www.npmjs.com/package/npm-packlist",
370866              "type": "website"
370867            }
370868          ],
370869          "evidence": {},
370870          "signature": {
370871            "signature": {
370872              "publicKey": {}
370873            }
370874          },
370875          "modelCard": {
370876            "modelParameters": {
370877              "approach": {}
370878            },
370879            "quantitativeAnalysis": {
370880              "graphics": {}
370881            },
370882            "considerations": {}
370883          }
370884        },
370885        {
370886          "type": "library",
370887          "bom-ref": "pkg:npm/npm-pick-manifest@3.0.2?package-id=eaeea9720b4d5360",
370888          "supplier": {},
370889          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
370890          "name": "npm-pick-manifest",
370891          "version": "3.0.2",
370892          "description": "Resolves a matching manifest from a package metadata document according to standard npm semver resolution rules.",
370893          "licenses": [
370894            {
370895              "license": {
370896                "id": "ISC"
370897              }
370898            }
370899          ],
370900          "cpe": "cpe:2.3:a:npm-pick-manifest:npm-pick-manifest:3.0.2:*:*:*:*:*:*:*",
370901          "purl": "pkg:npm/npm-pick-manifest@3.0.2",
370902          "swid": {
370903            "attachment": {}
370904          },
370905          "pedigree": {},
370906          "externalReferences": [
370907            {
370908              "url": "git+https://github.com/npm/npm-pick-manifest.git",
370909              "type": "distribution"
370910            },
370911            {
370912              "url": "https://github.com/npm/npm-pick-manifest#readme",
370913              "type": "website"
370914            }
370915          ],
370916          "evidence": {},
370917          "signature": {
370918            "signature": {
370919              "publicKey": {}
370920            }
370921          },
370922          "modelCard": {
370923            "modelParameters": {
370924              "approach": {}
370925            },
370926            "quantitativeAnalysis": {
370927              "graphics": {}
370928            },
370929            "considerations": {}
370930          }
370931        },
370932        {
370933          "type": "library",
370934          "bom-ref": "pkg:npm/npm-profile@4.0.4?package-id=4d9e591b42474ecb",
370935          "supplier": {},
370936          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
370937          "name": "npm-profile",
370938          "version": "4.0.4",
370939          "description": "Library for updating an npmjs.com profile",
370940          "licenses": [
370941            {
370942              "license": {
370943                "id": "ISC"
370944              }
370945            }
370946          ],
370947          "cpe": "cpe:2.3:a:npm-profile:npm-profile:4.0.4:*:*:*:*:*:*:*",
370948          "purl": "pkg:npm/npm-profile@4.0.4",
370949          "swid": {
370950            "attachment": {}
370951          },
370952          "pedigree": {},
370953          "externalReferences": [
370954            {
370955              "url": "git+https://github.com/npm/npm-profile.git",
370956              "type": "distribution"
370957            },
370958            {
370959              "url": "https://github.com/npm/npm-profile/tree/latest/lib#readme",
370960              "type": "website"
370961            }
370962          ],
370963          "evidence": {},
370964          "signature": {
370965            "signature": {
370966              "publicKey": {}
370967            }
370968          },
370969          "modelCard": {
370970            "modelParameters": {
370971              "approach": {}
370972            },
370973            "quantitativeAnalysis": {
370974              "graphics": {}
370975            },
370976            "considerations": {}
370977          }
370978        },
370979        {
370980          "type": "library",
370981          "bom-ref": "pkg:npm/npm-registry-fetch@4.0.7?package-id=ff298f561e427135",
370982          "supplier": {},
370983          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
370984          "name": "npm-registry-fetch",
370985          "version": "4.0.7",
370986          "description": "Fetch-based http client for use with npm registry APIs",
370987          "licenses": [
370988            {
370989              "license": {
370990                "id": "ISC"
370991              }
370992            }
370993          ],
370994          "cpe": "cpe:2.3:a:npm-registry-fetch:npm-registry-fetch:4.0.7:*:*:*:*:*:*:*",
370995          "purl": "pkg:npm/npm-registry-fetch@4.0.7",
370996          "swid": {
370997            "attachment": {}
370998          },
370999          "pedigree": {},
371000          "externalReferences": [
371001            {
371002              "url": "git+https://github.com/npm/registry-fetch.git",
371003              "type": "distribution"
371004            },
371005            {
371006              "url": "https://github.com/npm/registry-fetch#readme",
371007              "type": "website"
371008            }
371009          ],
371010          "evidence": {},
371011          "signature": {
371012            "signature": {
371013              "publicKey": {}
371014            }
371015          },
371016          "modelCard": {
371017            "modelParameters": {
371018              "approach": {}
371019            },
371020            "quantitativeAnalysis": {
371021              "graphics": {}
371022            },
371023            "considerations": {}
371024          }
371025        },
371026        {
371027          "type": "library",
371028          "bom-ref": "pkg:npm/npm-run-path@2.0.2?package-id=affacdccaca7f37f",
371029          "supplier": {},
371030          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
371031          "name": "npm-run-path",
371032          "version": "2.0.2",
371033          "description": "Get your PATH prepended with locally installed binaries",
371034          "licenses": [
371035            {
371036              "license": {
371037                "id": "MIT"
371038              }
371039            }
371040          ],
371041          "cpe": "cpe:2.3:a:npm-run-path:npm-run-path:2.0.2:*:*:*:*:*:*:*",
371042          "purl": "pkg:npm/npm-run-path@2.0.2",
371043          "swid": {
371044            "attachment": {}
371045          },
371046          "pedigree": {},
371047          "externalReferences": [
371048            {
371049              "url": "git+https://github.com/sindresorhus/npm-run-path.git",
371050              "type": "distribution"
371051            },
371052            {
371053              "url": "https://github.com/sindresorhus/npm-run-path#readme",
371054              "type": "website"
371055            }
371056          ],
371057          "evidence": {},
371058          "signature": {
371059            "signature": {
371060              "publicKey": {}
371061            }
371062          },
371063          "modelCard": {
371064            "modelParameters": {
371065              "approach": {}
371066            },
371067            "quantitativeAnalysis": {
371068              "graphics": {}
371069            },
371070            "considerations": {}
371071          }
371072        },
371073        {
371074          "type": "library",
371075          "bom-ref": "pkg:npm/npm-user-validate@1.0.1?package-id=9cb265c5d2df8131",
371076          "supplier": {},
371077          "author": "Robert Kowalski \u003crok@kowalski.gd\u003e",
371078          "name": "npm-user-validate",
371079          "version": "1.0.1",
371080          "description": "User validations for npm",
371081          "licenses": [
371082            {
371083              "license": {
371084                "id": "BSD-2-Clause"
371085              }
371086            }
371087          ],
371088          "cpe": "cpe:2.3:a:npm-user-validate:npm-user-validate:1.0.1:*:*:*:*:*:*:*",
371089          "purl": "pkg:npm/npm-user-validate@1.0.1",
371090          "swid": {
371091            "attachment": {}
371092          },
371093          "pedigree": {},
371094          "externalReferences": [
371095            {
371096              "url": "git://github.com/npm/npm-user-validate.git",
371097              "type": "distribution"
371098            },
371099            {
371100              "url": "https://github.com/npm/npm-user-validate#readme",
371101              "type": "website"
371102            }
371103          ],
371104          "evidence": {},
371105          "signature": {
371106            "signature": {
371107              "publicKey": {}
371108            }
371109          },
371110          "modelCard": {
371111            "modelParameters": {
371112              "approach": {}
371113            },
371114            "quantitativeAnalysis": {
371115              "graphics": {}
371116            },
371117            "considerations": {}
371118          }
371119        },
371120        {
371121          "type": "library",
371122          "bom-ref": "pkg:npm/npmlog@4.1.2?package-id=25b4bcebeb6b5003",
371123          "supplier": {},
371124          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
371125          "name": "npmlog",
371126          "version": "4.1.2",
371127          "description": "logger for npm",
371128          "licenses": [
371129            {
371130              "license": {
371131                "id": "ISC"
371132              }
371133            }
371134          ],
371135          "cpe": "cpe:2.3:a:npmlog:npmlog:4.1.2:*:*:*:*:*:*:*",
371136          "purl": "pkg:npm/npmlog@4.1.2",
371137          "swid": {
371138            "attachment": {}
371139          },
371140          "pedigree": {},
371141          "externalReferences": [
371142            {
371143              "url": "git+https://github.com/npm/npmlog.git",
371144              "type": "distribution"
371145            },
371146            {
371147              "url": "https://github.com/npm/npmlog#readme",
371148              "type": "website"
371149            }
371150          ],
371151          "evidence": {},
371152          "signature": {
371153            "signature": {
371154              "publicKey": {}
371155            }
371156          },
371157          "modelCard": {
371158            "modelParameters": {
371159              "approach": {}
371160            },
371161            "quantitativeAnalysis": {
371162              "graphics": {}
371163            },
371164            "considerations": {}
371165          }
371166        },
371167        {
371168          "type": "library",
371169          "bom-ref": "pkg:npm/number-is-nan@1.0.1?package-id=52229f13f55aa483",
371170          "supplier": {},
371171          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
371172          "name": "number-is-nan",
371173          "version": "1.0.1",
371174          "description": "ES2015 Number.isNaN() ponyfill",
371175          "licenses": [
371176            {
371177              "license": {
371178                "id": "MIT"
371179              }
371180            }
371181          ],
371182          "cpe": "cpe:2.3:a:number-is-nan:number-is-nan:1.0.1:*:*:*:*:*:*:*",
371183          "purl": "pkg:npm/number-is-nan@1.0.1",
371184          "swid": {
371185            "attachment": {}
371186          },
371187          "pedigree": {},
371188          "externalReferences": [
371189            {
371190              "url": "git+https://github.com/sindresorhus/number-is-nan.git",
371191              "type": "distribution"
371192            },
371193            {
371194              "url": "https://github.com/sindresorhus/number-is-nan#readme",
371195              "type": "website"
371196            }
371197          ],
371198          "evidence": {},
371199          "signature": {
371200            "signature": {
371201              "publicKey": {}
371202            }
371203          },
371204          "modelCard": {
371205            "modelParameters": {
371206              "approach": {}
371207            },
371208            "quantitativeAnalysis": {
371209              "graphics": {}
371210            },
371211            "considerations": {}
371212          }
371213        },
371214        {
371215          "type": "library",
371216          "bom-ref": "pkg:npm/oauth-sign@0.9.0?package-id=90154505370ab919",
371217          "supplier": {},
371218          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
371219          "name": "oauth-sign",
371220          "version": "0.9.0",
371221          "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
371222          "licenses": [
371223            {
371224              "license": {
371225                "id": "Apache-2.0"
371226              }
371227            }
371228          ],
371229          "cpe": "cpe:2.3:a:oauth-sign:oauth-sign:0.9.0:*:*:*:*:*:*:*",
371230          "purl": "pkg:npm/oauth-sign@0.9.0",
371231          "swid": {
371232            "attachment": {}
371233          },
371234          "pedigree": {},
371235          "externalReferences": [
371236            {
371237              "url": "git+https://github.com/mikeal/oauth-sign.git",
371238              "type": "distribution"
371239            },
371240            {
371241              "url": "https://github.com/mikeal/oauth-sign#readme",
371242              "type": "website"
371243            }
371244          ],
371245          "evidence": {},
371246          "signature": {
371247            "signature": {
371248              "publicKey": {}
371249            }
371250          },
371251          "modelCard": {
371252            "modelParameters": {
371253              "approach": {}
371254            },
371255            "quantitativeAnalysis": {
371256              "graphics": {}
371257            },
371258            "considerations": {}
371259          }
371260        },
371261        {
371262          "type": "library",
371263          "bom-ref": "pkg:npm/oauth-sign@0.9.0?package-id=ca46b51b0266a848",
371264          "supplier": {},
371265          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
371266          "name": "oauth-sign",
371267          "version": "0.9.0",
371268          "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
371269          "licenses": [
371270            {
371271              "license": {
371272                "id": "Apache-2.0"
371273              }
371274            }
371275          ],
371276          "cpe": "cpe:2.3:a:oauth-sign:oauth-sign:0.9.0:*:*:*:*:*:*:*",
371277          "purl": "pkg:npm/oauth-sign@0.9.0",
371278          "swid": {
371279            "attachment": {}
371280          },
371281          "pedigree": {},
371282          "externalReferences": [
371283            {
371284              "url": "git+https://github.com/mikeal/oauth-sign.git",
371285              "type": "distribution"
371286            },
371287            {
371288              "url": "https://github.com/mikeal/oauth-sign#readme",
371289              "type": "website"
371290            }
371291          ],
371292          "evidence": {},
371293          "signature": {
371294            "signature": {
371295              "publicKey": {}
371296            }
371297          },
371298          "modelCard": {
371299            "modelParameters": {
371300              "approach": {}
371301            },
371302            "quantitativeAnalysis": {
371303              "graphics": {}
371304            },
371305            "considerations": {}
371306          }
371307        },
371308        {
371309          "type": "library",
371310          "bom-ref": "pkg:npm/object-assign@4.1.1?package-id=ae257450c890715a",
371311          "supplier": {},
371312          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
371313          "name": "object-assign",
371314          "version": "4.1.1",
371315          "description": "ES2015 `Object.assign()` ponyfill",
371316          "licenses": [
371317            {
371318              "license": {
371319                "id": "MIT"
371320              }
371321            }
371322          ],
371323          "cpe": "cpe:2.3:a:object-assign:object-assign:4.1.1:*:*:*:*:*:*:*",
371324          "purl": "pkg:npm/object-assign@4.1.1",
371325          "swid": {
371326            "attachment": {}
371327          },
371328          "pedigree": {},
371329          "externalReferences": [
371330            {
371331              "url": "git+https://github.com/sindresorhus/object-assign.git",
371332              "type": "distribution"
371333            },
371334            {
371335              "url": "https://github.com/sindresorhus/object-assign#readme",
371336              "type": "website"
371337            }
371338          ],
371339          "evidence": {},
371340          "signature": {
371341            "signature": {
371342              "publicKey": {}
371343            }
371344          },
371345          "modelCard": {
371346            "modelParameters": {
371347              "approach": {}
371348            },
371349            "quantitativeAnalysis": {
371350              "graphics": {}
371351            },
371352            "considerations": {}
371353          }
371354        },
371355        {
371356          "type": "library",
371357          "bom-ref": "pkg:npm/object-assign@4.1.1?package-id=4352ef57ca64ac71",
371358          "supplier": {},
371359          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
371360          "name": "object-assign",
371361          "version": "4.1.1",
371362          "description": "ES2015 `Object.assign()` ponyfill",
371363          "licenses": [
371364            {
371365              "license": {
371366                "id": "MIT"
371367              }
371368            }
371369          ],
371370          "cpe": "cpe:2.3:a:object-assign:object-assign:4.1.1:*:*:*:*:*:*:*",
371371          "purl": "pkg:npm/object-assign@4.1.1",
371372          "swid": {
371373            "attachment": {}
371374          },
371375          "pedigree": {},
371376          "externalReferences": [
371377            {
371378              "url": "git+https://github.com/sindresorhus/object-assign.git",
371379              "type": "distribution"
371380            },
371381            {
371382              "url": "https://github.com/sindresorhus/object-assign#readme",
371383              "type": "website"
371384            }
371385          ],
371386          "evidence": {},
371387          "signature": {
371388            "signature": {
371389              "publicKey": {}
371390            }
371391          },
371392          "modelCard": {
371393            "modelParameters": {
371394              "approach": {}
371395            },
371396            "quantitativeAnalysis": {
371397              "graphics": {}
371398            },
371399            "considerations": {}
371400          }
371401        },
371402        {
371403          "type": "library",
371404          "bom-ref": "pkg:npm/object-hash@2.1.1?package-id=1a268c519d95fecd",
371405          "supplier": {},
371406          "author": "Scott Puleo \u003cpuleos@gmail.com\u003e",
371407          "name": "object-hash",
371408          "version": "2.1.1",
371409          "description": "Generate hashes from javascript objects in node and the browser.",
371410          "licenses": [
371411            {
371412              "license": {
371413                "id": "MIT"
371414              }
371415            }
371416          ],
371417          "cpe": "cpe:2.3:a:object-hash:object-hash:2.1.1:*:*:*:*:*:*:*",
371418          "purl": "pkg:npm/object-hash@2.1.1",
371419          "swid": {
371420            "attachment": {}
371421          },
371422          "pedigree": {},
371423          "externalReferences": [
371424            {
371425              "url": "git+https://github.com/puleos/object-hash.git",
371426              "type": "distribution"
371427            },
371428            {
371429              "url": "https://github.com/puleos/object-hash",
371430              "type": "website"
371431            }
371432          ],
371433          "evidence": {},
371434          "signature": {
371435            "signature": {
371436              "publicKey": {}
371437            }
371438          },
371439          "modelCard": {
371440            "modelParameters": {
371441              "approach": {}
371442            },
371443            "quantitativeAnalysis": {
371444              "graphics": {}
371445            },
371446            "considerations": {}
371447          }
371448        },
371449        {
371450          "type": "library",
371451          "bom-ref": "pkg:npm/object-keys@1.0.12?package-id=553c1830da4c0f15",
371452          "supplier": {},
371453          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
371454          "name": "object-keys",
371455          "version": "1.0.12",
371456          "description": "An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim",
371457          "licenses": [
371458            {
371459              "license": {
371460                "id": "MIT"
371461              }
371462            }
371463          ],
371464          "cpe": "cpe:2.3:a:object-keys:object-keys:1.0.12:*:*:*:*:*:*:*",
371465          "purl": "pkg:npm/object-keys@1.0.12",
371466          "swid": {
371467            "attachment": {}
371468          },
371469          "pedigree": {},
371470          "externalReferences": [
371471            {
371472              "url": "git://github.com/ljharb/object-keys.git",
371473              "type": "distribution"
371474            }
371475          ],
371476          "evidence": {},
371477          "signature": {
371478            "signature": {
371479              "publicKey": {}
371480            }
371481          },
371482          "modelCard": {
371483            "modelParameters": {
371484              "approach": {}
371485            },
371486            "quantitativeAnalysis": {
371487              "graphics": {}
371488            },
371489            "considerations": {}
371490          }
371491        },
371492        {
371493          "type": "library",
371494          "bom-ref": "pkg:npm/object-keys@1.1.1?package-id=319eacbf6a0ef5d",
371495          "supplier": {},
371496          "author": "Jordan Harband \u003cljharb@gmail.com\u003e (http://ljharb.codes)",
371497          "name": "object-keys",
371498          "version": "1.1.1",
371499          "description": "An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim",
371500          "licenses": [
371501            {
371502              "license": {
371503                "id": "MIT"
371504              }
371505            }
371506          ],
371507          "cpe": "cpe:2.3:a:object-keys:object-keys:1.1.1:*:*:*:*:*:*:*",
371508          "purl": "pkg:npm/object-keys@1.1.1",
371509          "swid": {
371510            "attachment": {}
371511          },
371512          "pedigree": {},
371513          "externalReferences": [
371514            {
371515              "url": "git://github.com/ljharb/object-keys.git",
371516              "type": "distribution"
371517            },
371518            {
371519              "url": "https://github.com/ljharb/object-keys#readme",
371520              "type": "website"
371521            }
371522          ],
371523          "evidence": {},
371524          "signature": {
371525            "signature": {
371526              "publicKey": {}
371527            }
371528          },
371529          "modelCard": {
371530            "modelParameters": {
371531              "approach": {}
371532            },
371533            "quantitativeAnalysis": {
371534              "graphics": {}
371535            },
371536            "considerations": {}
371537          }
371538        },
371539        {
371540          "type": "library",
371541          "bom-ref": "pkg:npm/object.getownpropertydescriptors@2.0.3?package-id=5a48ed26122d77f7",
371542          "supplier": {},
371543          "author": "Jordan Harband",
371544          "name": "object.getownpropertydescriptors",
371545          "version": "2.0.3",
371546          "description": "ES2017 spec-compliant shim for `Object.getOwnPropertyDescriptors` that works in ES5.",
371547          "licenses": [
371548            {
371549              "license": {
371550                "id": "MIT"
371551              }
371552            }
371553          ],
371554          "cpe": "cpe:2.3:a:object.getownpropertydescriptors:object.getownpropertydescriptors:2.0.3:*:*:*:*:*:*:*",
371555          "purl": "pkg:npm/object.getownpropertydescriptors@2.0.3",
371556          "swid": {
371557            "attachment": {}
371558          },
371559          "pedigree": {},
371560          "externalReferences": [
371561            {
371562              "url": "git://github.com/ljharb/object.getownpropertydescriptors.git",
371563              "type": "distribution"
371564            },
371565            {
371566              "url": "https://github.com/ljharb/object.getownpropertydescriptors#readme",
371567              "type": "website"
371568            }
371569          ],
371570          "evidence": {},
371571          "signature": {
371572            "signature": {
371573              "publicKey": {}
371574            }
371575          },
371576          "modelCard": {
371577            "modelParameters": {
371578              "approach": {}
371579            },
371580            "quantitativeAnalysis": {
371581              "graphics": {}
371582            },
371583            "considerations": {}
371584          }
371585        },
371586        {
371587          "type": "library",
371588          "bom-ref": "pkg:npm/on-finished@2.3.0?package-id=ce866b6fa0101af5",
371589          "supplier": {},
371590          "name": "on-finished",
371591          "version": "2.3.0",
371592          "description": "Execute a callback when a request closes, finishes, or errors",
371593          "licenses": [
371594            {
371595              "license": {
371596                "id": "MIT"
371597              }
371598            }
371599          ],
371600          "cpe": "cpe:2.3:a:on-finished:on-finished:2.3.0:*:*:*:*:*:*:*",
371601          "purl": "pkg:npm/on-finished@2.3.0",
371602          "swid": {
371603            "attachment": {}
371604          },
371605          "pedigree": {},
371606          "externalReferences": [
371607            {
371608              "url": "git+https://github.com/jshttp/on-finished.git",
371609              "type": "distribution"
371610            },
371611            {
371612              "url": "https://github.com/jshttp/on-finished#readme",
371613              "type": "website"
371614            }
371615          ],
371616          "evidence": {},
371617          "signature": {
371618            "signature": {
371619              "publicKey": {}
371620            }
371621          },
371622          "modelCard": {
371623            "modelParameters": {
371624              "approach": {}
371625            },
371626            "quantitativeAnalysis": {
371627              "graphics": {}
371628            },
371629            "considerations": {}
371630          }
371631        },
371632        {
371633          "type": "library",
371634          "bom-ref": "pkg:npm/once@1.4.0?package-id=acd9aa54ac049a0e",
371635          "supplier": {},
371636          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
371637          "name": "once",
371638          "version": "1.4.0",
371639          "description": "Run a function exactly one time",
371640          "licenses": [
371641            {
371642              "license": {
371643                "id": "ISC"
371644              }
371645            }
371646          ],
371647          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
371648          "purl": "pkg:npm/once@1.4.0",
371649          "swid": {
371650            "attachment": {}
371651          },
371652          "pedigree": {},
371653          "externalReferences": [
371654            {
371655              "url": "git://github.com/isaacs/once.git",
371656              "type": "distribution"
371657            },
371658            {
371659              "url": "https://github.com/isaacs/once#readme",
371660              "type": "website"
371661            }
371662          ],
371663          "evidence": {},
371664          "signature": {
371665            "signature": {
371666              "publicKey": {}
371667            }
371668          },
371669          "modelCard": {
371670            "modelParameters": {
371671              "approach": {}
371672            },
371673            "quantitativeAnalysis": {
371674              "graphics": {}
371675            },
371676            "considerations": {}
371677          }
371678        },
371679        {
371680          "type": "library",
371681          "bom-ref": "pkg:npm/once@1.4.0?package-id=56789787f3e05aa7",
371682          "supplier": {},
371683          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
371684          "name": "once",
371685          "version": "1.4.0",
371686          "description": "Run a function exactly one time",
371687          "licenses": [
371688            {
371689              "license": {
371690                "id": "ISC"
371691              }
371692            }
371693          ],
371694          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
371695          "purl": "pkg:npm/once@1.4.0",
371696          "swid": {
371697            "attachment": {}
371698          },
371699          "pedigree": {},
371700          "externalReferences": [
371701            {
371702              "url": "git://github.com/isaacs/once.git",
371703              "type": "distribution"
371704            },
371705            {
371706              "url": "https://github.com/isaacs/once#readme",
371707              "type": "website"
371708            }
371709          ],
371710          "evidence": {},
371711          "signature": {
371712            "signature": {
371713              "publicKey": {}
371714            }
371715          },
371716          "modelCard": {
371717            "modelParameters": {
371718              "approach": {}
371719            },
371720            "quantitativeAnalysis": {
371721              "graphics": {}
371722            },
371723            "considerations": {}
371724          }
371725        },
371726        {
371727          "type": "library",
371728          "bom-ref": "pkg:npm/opener@1.5.2?package-id=7e147c5eae081fba",
371729          "supplier": {},
371730          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me/)",
371731          "name": "opener",
371732          "version": "1.5.2",
371733          "description": "Opens stuff, like webpages and files and executables, cross-platform",
371734          "licenses": [
371735            {
371736              "license": {
371737                "name": "(WTFPL OR MIT)"
371738              }
371739            }
371740          ],
371741          "cpe": "cpe:2.3:a:domenic:opener:1.5.2:*:*:*:*:*:*:*",
371742          "purl": "pkg:npm/opener@1.5.2",
371743          "swid": {
371744            "attachment": {}
371745          },
371746          "pedigree": {},
371747          "externalReferences": [
371748            {
371749              "url": "git+https://github.com/domenic/opener.git",
371750              "type": "distribution"
371751            },
371752            {
371753              "url": "https://github.com/domenic/opener#readme",
371754              "type": "website"
371755            }
371756          ],
371757          "evidence": {},
371758          "signature": {
371759            "signature": {
371760              "publicKey": {}
371761            }
371762          },
371763          "modelCard": {
371764            "modelParameters": {
371765              "approach": {}
371766            },
371767            "quantitativeAnalysis": {
371768              "graphics": {}
371769            },
371770            "considerations": {}
371771          }
371772        },
371773        {
371774          "type": "library",
371775          "bom-ref": "pkg:npm/os-homedir@1.0.2?package-id=8f5251251e0a2862",
371776          "supplier": {},
371777          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
371778          "name": "os-homedir",
371779          "version": "1.0.2",
371780          "description": "Node.js 4 `os.homedir()` ponyfill",
371781          "licenses": [
371782            {
371783              "license": {
371784                "id": "MIT"
371785              }
371786            }
371787          ],
371788          "cpe": "cpe:2.3:a:sindresorhus:os-homedir:1.0.2:*:*:*:*:*:*:*",
371789          "purl": "pkg:npm/os-homedir@1.0.2",
371790          "swid": {
371791            "attachment": {}
371792          },
371793          "pedigree": {},
371794          "externalReferences": [
371795            {
371796              "url": "git+https://github.com/sindresorhus/os-homedir.git",
371797              "type": "distribution"
371798            },
371799            {
371800              "url": "https://github.com/sindresorhus/os-homedir#readme",
371801              "type": "website"
371802            }
371803          ],
371804          "evidence": {},
371805          "signature": {
371806            "signature": {
371807              "publicKey": {}
371808            }
371809          },
371810          "modelCard": {
371811            "modelParameters": {
371812              "approach": {}
371813            },
371814            "quantitativeAnalysis": {
371815              "graphics": {}
371816            },
371817            "considerations": {}
371818          }
371819        },
371820        {
371821          "type": "library",
371822          "bom-ref": "pkg:npm/os-tmpdir@1.0.2?package-id=319f8a779adc8672",
371823          "supplier": {},
371824          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
371825          "name": "os-tmpdir",
371826          "version": "1.0.2",
371827          "description": "Node.js os.tmpdir() ponyfill",
371828          "licenses": [
371829            {
371830              "license": {
371831                "id": "MIT"
371832              }
371833            }
371834          ],
371835          "cpe": "cpe:2.3:a:sindresorhus:os-tmpdir:1.0.2:*:*:*:*:*:*:*",
371836          "purl": "pkg:npm/os-tmpdir@1.0.2",
371837          "swid": {
371838            "attachment": {}
371839          },
371840          "pedigree": {},
371841          "externalReferences": [
371842            {
371843              "url": "git+https://github.com/sindresorhus/os-tmpdir.git",
371844              "type": "distribution"
371845            },
371846            {
371847              "url": "https://github.com/sindresorhus/os-tmpdir#readme",
371848              "type": "website"
371849            }
371850          ],
371851          "evidence": {},
371852          "signature": {
371853            "signature": {
371854              "publicKey": {}
371855            }
371856          },
371857          "modelCard": {
371858            "modelParameters": {
371859              "approach": {}
371860            },
371861            "quantitativeAnalysis": {
371862              "graphics": {}
371863            },
371864            "considerations": {}
371865          }
371866        },
371867        {
371868          "type": "library",
371869          "bom-ref": "pkg:npm/osenv@0.1.5?package-id=299bd30a410ad76d",
371870          "supplier": {},
371871          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
371872          "name": "osenv",
371873          "version": "0.1.5",
371874          "description": "Look up environment settings specific to different operating systems",
371875          "licenses": [
371876            {
371877              "license": {
371878                "id": "ISC"
371879              }
371880            }
371881          ],
371882          "cpe": "cpe:2.3:a:osenv:osenv:0.1.5:*:*:*:*:*:*:*",
371883          "purl": "pkg:npm/osenv@0.1.5",
371884          "swid": {
371885            "attachment": {}
371886          },
371887          "pedigree": {},
371888          "externalReferences": [
371889            {
371890              "url": "git+https://github.com/npm/osenv.git",
371891              "type": "distribution"
371892            },
371893            {
371894              "url": "https://github.com/npm/osenv#readme",
371895              "type": "website"
371896            }
371897          ],
371898          "evidence": {},
371899          "signature": {
371900            "signature": {
371901              "publicKey": {}
371902            }
371903          },
371904          "modelCard": {
371905            "modelParameters": {
371906              "approach": {}
371907            },
371908            "quantitativeAnalysis": {
371909              "graphics": {}
371910            },
371911            "considerations": {}
371912          }
371913        },
371914        {
371915          "type": "library",
371916          "bom-ref": "pkg:npm/p-finally@1.0.0?package-id=ee6201c5c1a7fb4d",
371917          "supplier": {},
371918          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
371919          "name": "p-finally",
371920          "version": "1.0.0",
371921          "description": "`Promise#finally()` ponyfill - Invoked when the promise is settled regardless of outcome",
371922          "licenses": [
371923            {
371924              "license": {
371925                "id": "MIT"
371926              }
371927            }
371928          ],
371929          "cpe": "cpe:2.3:a:sindresorhus:p-finally:1.0.0:*:*:*:*:*:*:*",
371930          "purl": "pkg:npm/p-finally@1.0.0",
371931          "swid": {
371932            "attachment": {}
371933          },
371934          "pedigree": {},
371935          "externalReferences": [
371936            {
371937              "url": "git+https://github.com/sindresorhus/p-finally.git",
371938              "type": "distribution"
371939            },
371940            {
371941              "url": "https://github.com/sindresorhus/p-finally#readme",
371942              "type": "website"
371943            }
371944          ],
371945          "evidence": {},
371946          "signature": {
371947            "signature": {
371948              "publicKey": {}
371949            }
371950          },
371951          "modelCard": {
371952            "modelParameters": {
371953              "approach": {}
371954            },
371955            "quantitativeAnalysis": {
371956              "graphics": {}
371957            },
371958            "considerations": {}
371959          }
371960        },
371961        {
371962          "type": "library",
371963          "bom-ref": "pkg:npm/p-limit@2.2.0?package-id=8e8636a82737dbe8",
371964          "supplier": {},
371965          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
371966          "name": "p-limit",
371967          "version": "2.2.0",
371968          "description": "Run multiple promise-returning \u0026 async functions with limited concurrency",
371969          "licenses": [
371970            {
371971              "license": {
371972                "id": "MIT"
371973              }
371974            }
371975          ],
371976          "cpe": "cpe:2.3:a:sindresorhus:p-limit:2.2.0:*:*:*:*:*:*:*",
371977          "purl": "pkg:npm/p-limit@2.2.0",
371978          "swid": {
371979            "attachment": {}
371980          },
371981          "pedigree": {},
371982          "externalReferences": [
371983            {
371984              "url": "git+https://github.com/sindresorhus/p-limit.git",
371985              "type": "distribution"
371986            },
371987            {
371988              "url": "https://github.com/sindresorhus/p-limit#readme",
371989              "type": "website"
371990            }
371991          ],
371992          "evidence": {},
371993          "signature": {
371994            "signature": {
371995              "publicKey": {}
371996            }
371997          },
371998          "modelCard": {
371999            "modelParameters": {
372000              "approach": {}
372001            },
372002            "quantitativeAnalysis": {
372003              "graphics": {}
372004            },
372005            "considerations": {}
372006          }
372007        },
372008        {
372009          "type": "library",
372010          "bom-ref": "pkg:npm/p-limit@2.3.0?package-id=55e0eb9e24d434b9",
372011          "supplier": {},
372012          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372013          "name": "p-limit",
372014          "version": "2.3.0",
372015          "description": "Run multiple promise-returning \u0026 async functions with limited concurrency",
372016          "licenses": [
372017            {
372018              "license": {
372019                "id": "MIT"
372020              }
372021            }
372022          ],
372023          "cpe": "cpe:2.3:a:sindresorhus:p-limit:2.3.0:*:*:*:*:*:*:*",
372024          "purl": "pkg:npm/p-limit@2.3.0",
372025          "swid": {
372026            "attachment": {}
372027          },
372028          "pedigree": {},
372029          "externalReferences": [
372030            {
372031              "url": "git+https://github.com/sindresorhus/p-limit.git",
372032              "type": "distribution"
372033            },
372034            {
372035              "url": "https://github.com/sindresorhus/p-limit#readme",
372036              "type": "website"
372037            }
372038          ],
372039          "evidence": {},
372040          "signature": {
372041            "signature": {
372042              "publicKey": {}
372043            }
372044          },
372045          "modelCard": {
372046            "modelParameters": {
372047              "approach": {}
372048            },
372049            "quantitativeAnalysis": {
372050              "graphics": {}
372051            },
372052            "considerations": {}
372053          }
372054        },
372055        {
372056          "type": "library",
372057          "bom-ref": "pkg:npm/p-locate@3.0.0?package-id=caacbeef8553cb8b",
372058          "supplier": {},
372059          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372060          "name": "p-locate",
372061          "version": "3.0.0",
372062          "description": "Get the first fulfilled promise that satisfies the provided testing function",
372063          "licenses": [
372064            {
372065              "license": {
372066                "id": "MIT"
372067              }
372068            }
372069          ],
372070          "cpe": "cpe:2.3:a:sindresorhus:p-locate:3.0.0:*:*:*:*:*:*:*",
372071          "purl": "pkg:npm/p-locate@3.0.0",
372072          "swid": {
372073            "attachment": {}
372074          },
372075          "pedigree": {},
372076          "externalReferences": [
372077            {
372078              "url": "git+https://github.com/sindresorhus/p-locate.git",
372079              "type": "distribution"
372080            },
372081            {
372082              "url": "https://github.com/sindresorhus/p-locate#readme",
372083              "type": "website"
372084            }
372085          ],
372086          "evidence": {},
372087          "signature": {
372088            "signature": {
372089              "publicKey": {}
372090            }
372091          },
372092          "modelCard": {
372093            "modelParameters": {
372094              "approach": {}
372095            },
372096            "quantitativeAnalysis": {
372097              "graphics": {}
372098            },
372099            "considerations": {}
372100          }
372101        },
372102        {
372103          "type": "library",
372104          "bom-ref": "pkg:npm/p-locate@3.0.0?package-id=f95bdff20b3ee519",
372105          "supplier": {},
372106          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372107          "name": "p-locate",
372108          "version": "3.0.0",
372109          "description": "Get the first fulfilled promise that satisfies the provided testing function",
372110          "licenses": [
372111            {
372112              "license": {
372113                "id": "MIT"
372114              }
372115            }
372116          ],
372117          "cpe": "cpe:2.3:a:sindresorhus:p-locate:3.0.0:*:*:*:*:*:*:*",
372118          "purl": "pkg:npm/p-locate@3.0.0",
372119          "swid": {
372120            "attachment": {}
372121          },
372122          "pedigree": {},
372123          "externalReferences": [
372124            {
372125              "url": "git+https://github.com/sindresorhus/p-locate.git",
372126              "type": "distribution"
372127            },
372128            {
372129              "url": "https://github.com/sindresorhus/p-locate#readme",
372130              "type": "website"
372131            }
372132          ],
372133          "evidence": {},
372134          "signature": {
372135            "signature": {
372136              "publicKey": {}
372137            }
372138          },
372139          "modelCard": {
372140            "modelParameters": {
372141              "approach": {}
372142            },
372143            "quantitativeAnalysis": {
372144              "graphics": {}
372145            },
372146            "considerations": {}
372147          }
372148        },
372149        {
372150          "type": "library",
372151          "bom-ref": "pkg:npm/p-try@2.2.0?package-id=c42ca8af78a02fe7",
372152          "supplier": {},
372153          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372154          "name": "p-try",
372155          "version": "2.2.0",
372156          "description": "`Start a promise chain",
372157          "licenses": [
372158            {
372159              "license": {
372160                "id": "MIT"
372161              }
372162            }
372163          ],
372164          "cpe": "cpe:2.3:a:sindresorhus:p-try:2.2.0:*:*:*:*:*:*:*",
372165          "purl": "pkg:npm/p-try@2.2.0",
372166          "swid": {
372167            "attachment": {}
372168          },
372169          "pedigree": {},
372170          "externalReferences": [
372171            {
372172              "url": "git+https://github.com/sindresorhus/p-try.git",
372173              "type": "distribution"
372174            },
372175            {
372176              "url": "https://github.com/sindresorhus/p-try#readme",
372177              "type": "website"
372178            }
372179          ],
372180          "evidence": {},
372181          "signature": {
372182            "signature": {
372183              "publicKey": {}
372184            }
372185          },
372186          "modelCard": {
372187            "modelParameters": {
372188              "approach": {}
372189            },
372190            "quantitativeAnalysis": {
372191              "graphics": {}
372192            },
372193            "considerations": {}
372194          }
372195        },
372196        {
372197          "type": "library",
372198          "bom-ref": "pkg:npm/p-try@2.2.0?package-id=c6cc8bcd8e8c6777",
372199          "supplier": {},
372200          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372201          "name": "p-try",
372202          "version": "2.2.0",
372203          "description": "`Start a promise chain",
372204          "licenses": [
372205            {
372206              "license": {
372207                "id": "MIT"
372208              }
372209            }
372210          ],
372211          "cpe": "cpe:2.3:a:sindresorhus:p-try:2.2.0:*:*:*:*:*:*:*",
372212          "purl": "pkg:npm/p-try@2.2.0",
372213          "swid": {
372214            "attachment": {}
372215          },
372216          "pedigree": {},
372217          "externalReferences": [
372218            {
372219              "url": "git+https://github.com/sindresorhus/p-try.git",
372220              "type": "distribution"
372221            },
372222            {
372223              "url": "https://github.com/sindresorhus/p-try#readme",
372224              "type": "website"
372225            }
372226          ],
372227          "evidence": {},
372228          "signature": {
372229            "signature": {
372230              "publicKey": {}
372231            }
372232          },
372233          "modelCard": {
372234            "modelParameters": {
372235              "approach": {}
372236            },
372237            "quantitativeAnalysis": {
372238              "graphics": {}
372239            },
372240            "considerations": {}
372241          }
372242        },
372243        {
372244          "type": "library",
372245          "bom-ref": "pkg:npm/package-json@4.0.1?package-id=4e92e688a7ce2a15",
372246          "supplier": {},
372247          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372248          "name": "package-json",
372249          "version": "4.0.1",
372250          "description": "Get metadata of a package from the npm registry",
372251          "licenses": [
372252            {
372253              "license": {
372254                "id": "MIT"
372255              }
372256            }
372257          ],
372258          "cpe": "cpe:2.3:a:package-json:package-json:4.0.1:*:*:*:*:*:*:*",
372259          "purl": "pkg:npm/package-json@4.0.1",
372260          "swid": {
372261            "attachment": {}
372262          },
372263          "pedigree": {},
372264          "externalReferences": [
372265            {
372266              "url": "git+https://github.com/sindresorhus/package-json.git",
372267              "type": "distribution"
372268            },
372269            {
372270              "url": "https://github.com/sindresorhus/package-json#readme",
372271              "type": "website"
372272            }
372273          ],
372274          "evidence": {},
372275          "signature": {
372276            "signature": {
372277              "publicKey": {}
372278            }
372279          },
372280          "modelCard": {
372281            "modelParameters": {
372282              "approach": {}
372283            },
372284            "quantitativeAnalysis": {
372285              "graphics": {}
372286            },
372287            "considerations": {}
372288          }
372289        },
372290        {
372291          "type": "library",
372292          "bom-ref": "pkg:npm/pacote@9.5.12?package-id=140141515a255620",
372293          "supplier": {},
372294          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
372295          "name": "pacote",
372296          "version": "9.5.12",
372297          "description": "JavaScript package downloader",
372298          "licenses": [
372299            {
372300              "license": {
372301                "id": "MIT"
372302              }
372303            }
372304          ],
372305          "cpe": "cpe:2.3:a:pacote:pacote:9.5.12:*:*:*:*:*:*:*",
372306          "purl": "pkg:npm/pacote@9.5.12",
372307          "swid": {
372308            "attachment": {}
372309          },
372310          "pedigree": {},
372311          "externalReferences": [
372312            {
372313              "url": "git+https://github.com/npm/pacote.git",
372314              "type": "distribution"
372315            },
372316            {
372317              "url": "https://github.com/npm/pacote#readme",
372318              "type": "website"
372319            }
372320          ],
372321          "evidence": {},
372322          "signature": {
372323            "signature": {
372324              "publicKey": {}
372325            }
372326          },
372327          "modelCard": {
372328            "modelParameters": {
372329              "approach": {}
372330            },
372331            "quantitativeAnalysis": {
372332              "graphics": {}
372333            },
372334            "considerations": {}
372335          }
372336        },
372337        {
372338          "type": "library",
372339          "bom-ref": "pkg:npm/parallel-transform@1.1.0?package-id=62f72bf19fb9ed91",
372340          "supplier": {},
372341          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
372342          "name": "parallel-transform",
372343          "version": "1.1.0",
372344          "description": "Transform stream that allows you to run your transforms in parallel without changing the order",
372345          "licenses": [
372346            {
372347              "license": {
372348                "id": "MIT"
372349              }
372350            }
372351          ],
372352          "cpe": "cpe:2.3:a:parallel-transform:parallel-transform:1.1.0:*:*:*:*:*:*:*",
372353          "purl": "pkg:npm/parallel-transform@1.1.0",
372354          "swid": {
372355            "attachment": {}
372356          },
372357          "pedigree": {},
372358          "externalReferences": [
372359            {
372360              "url": "git://github.com/mafintosh/parallel-transform.git",
372361              "type": "distribution"
372362            },
372363            {
372364              "url": "https://github.com/mafintosh/parallel-transform#readme",
372365              "type": "website"
372366            }
372367          ],
372368          "evidence": {},
372369          "signature": {
372370            "signature": {
372371              "publicKey": {}
372372            }
372373          },
372374          "modelCard": {
372375            "modelParameters": {
372376              "approach": {}
372377            },
372378            "quantitativeAnalysis": {
372379              "graphics": {}
372380            },
372381            "considerations": {}
372382          }
372383        },
372384        {
372385          "type": "library",
372386          "bom-ref": "pkg:npm/parseurl@1.3.3?package-id=a522a78fd0867f72",
372387          "supplier": {},
372388          "name": "parseurl",
372389          "version": "1.3.3",
372390          "description": "parse a url with memoization",
372391          "licenses": [
372392            {
372393              "license": {
372394                "id": "MIT"
372395              }
372396            }
372397          ],
372398          "cpe": "cpe:2.3:a:parseurl:parseurl:1.3.3:*:*:*:*:*:*:*",
372399          "purl": "pkg:npm/parseurl@1.3.3",
372400          "swid": {
372401            "attachment": {}
372402          },
372403          "pedigree": {},
372404          "externalReferences": [
372405            {
372406              "url": "git+https://github.com/pillarjs/parseurl.git",
372407              "type": "distribution"
372408            },
372409            {
372410              "url": "https://github.com/pillarjs/parseurl#readme",
372411              "type": "website"
372412            }
372413          ],
372414          "evidence": {},
372415          "signature": {
372416            "signature": {
372417              "publicKey": {}
372418            }
372419          },
372420          "modelCard": {
372421            "modelParameters": {
372422              "approach": {}
372423            },
372424            "quantitativeAnalysis": {
372425              "graphics": {}
372426            },
372427            "considerations": {}
372428          }
372429        },
372430        {
372431          "type": "library",
372432          "bom-ref": "pkg:npm/path-exists@3.0.0?package-id=e62b33d309c41526",
372433          "supplier": {},
372434          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372435          "name": "path-exists",
372436          "version": "3.0.0",
372437          "description": "Check if a path exists",
372438          "licenses": [
372439            {
372440              "license": {
372441                "id": "MIT"
372442              }
372443            }
372444          ],
372445          "cpe": "cpe:2.3:a:sindresorhus:path-exists:3.0.0:*:*:*:*:*:*:*",
372446          "purl": "pkg:npm/path-exists@3.0.0",
372447          "swid": {
372448            "attachment": {}
372449          },
372450          "pedigree": {},
372451          "externalReferences": [
372452            {
372453              "url": "git+https://github.com/sindresorhus/path-exists.git",
372454              "type": "distribution"
372455            },
372456            {
372457              "url": "https://github.com/sindresorhus/path-exists#readme",
372458              "type": "website"
372459            }
372460          ],
372461          "evidence": {},
372462          "signature": {
372463            "signature": {
372464              "publicKey": {}
372465            }
372466          },
372467          "modelCard": {
372468            "modelParameters": {
372469              "approach": {}
372470            },
372471            "quantitativeAnalysis": {
372472              "graphics": {}
372473            },
372474            "considerations": {}
372475          }
372476        },
372477        {
372478          "type": "library",
372479          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=b30d6bddac8e825a",
372480          "supplier": {},
372481          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372482          "name": "path-is-absolute",
372483          "version": "1.0.1",
372484          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
372485          "licenses": [
372486            {
372487              "license": {
372488                "id": "MIT"
372489              }
372490            }
372491          ],
372492          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
372493          "purl": "pkg:npm/path-is-absolute@1.0.1",
372494          "swid": {
372495            "attachment": {}
372496          },
372497          "pedigree": {},
372498          "externalReferences": [
372499            {
372500              "url": "git+https://github.com/sindresorhus/path-is-absolute.git",
372501              "type": "distribution"
372502            },
372503            {
372504              "url": "https://github.com/sindresorhus/path-is-absolute#readme",
372505              "type": "website"
372506            }
372507          ],
372508          "evidence": {},
372509          "signature": {
372510            "signature": {
372511              "publicKey": {}
372512            }
372513          },
372514          "modelCard": {
372515            "modelParameters": {
372516              "approach": {}
372517            },
372518            "quantitativeAnalysis": {
372519              "graphics": {}
372520            },
372521            "considerations": {}
372522          }
372523        },
372524        {
372525          "type": "library",
372526          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=89d0f4a70e07b9bf",
372527          "supplier": {},
372528          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372529          "name": "path-is-absolute",
372530          "version": "1.0.1",
372531          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
372532          "licenses": [
372533            {
372534              "license": {
372535                "id": "MIT"
372536              }
372537            }
372538          ],
372539          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
372540          "purl": "pkg:npm/path-is-absolute@1.0.1",
372541          "swid": {
372542            "attachment": {}
372543          },
372544          "pedigree": {},
372545          "externalReferences": [
372546            {
372547              "url": "git+https://github.com/sindresorhus/path-is-absolute.git",
372548              "type": "distribution"
372549            },
372550            {
372551              "url": "https://github.com/sindresorhus/path-is-absolute#readme",
372552              "type": "website"
372553            }
372554          ],
372555          "evidence": {},
372556          "signature": {
372557            "signature": {
372558              "publicKey": {}
372559            }
372560          },
372561          "modelCard": {
372562            "modelParameters": {
372563              "approach": {}
372564            },
372565            "quantitativeAnalysis": {
372566              "graphics": {}
372567            },
372568            "considerations": {}
372569          }
372570        },
372571        {
372572          "type": "library",
372573          "bom-ref": "pkg:npm/path-is-inside@1.0.2?package-id=9b511c0f5818d466",
372574          "supplier": {},
372575          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me)",
372576          "name": "path-is-inside",
372577          "version": "1.0.2",
372578          "description": "Tests whether one path is inside another path",
372579          "licenses": [
372580            {
372581              "license": {
372582                "name": "(WTFPL OR MIT)"
372583              }
372584            }
372585          ],
372586          "cpe": "cpe:2.3:a:path-is-inside:path-is-inside:1.0.2:*:*:*:*:*:*:*",
372587          "purl": "pkg:npm/path-is-inside@1.0.2",
372588          "swid": {
372589            "attachment": {}
372590          },
372591          "pedigree": {},
372592          "externalReferences": [
372593            {
372594              "url": "git+https://github.com/domenic/path-is-inside.git",
372595              "type": "distribution"
372596            },
372597            {
372598              "url": "https://github.com/domenic/path-is-inside#readme",
372599              "type": "website"
372600            }
372601          ],
372602          "evidence": {},
372603          "signature": {
372604            "signature": {
372605              "publicKey": {}
372606            }
372607          },
372608          "modelCard": {
372609            "modelParameters": {
372610              "approach": {}
372611            },
372612            "quantitativeAnalysis": {
372613              "graphics": {}
372614            },
372615            "considerations": {}
372616          }
372617        },
372618        {
372619          "type": "library",
372620          "bom-ref": "pkg:npm/path-key@2.0.1?package-id=2de86124def740fb",
372621          "supplier": {},
372622          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372623          "name": "path-key",
372624          "version": "2.0.1",
372625          "description": "Get the PATH environment variable key cross-platform",
372626          "licenses": [
372627            {
372628              "license": {
372629                "id": "MIT"
372630              }
372631            }
372632          ],
372633          "cpe": "cpe:2.3:a:sindresorhus:path-key:2.0.1:*:*:*:*:*:*:*",
372634          "purl": "pkg:npm/path-key@2.0.1",
372635          "swid": {
372636            "attachment": {}
372637          },
372638          "pedigree": {},
372639          "externalReferences": [
372640            {
372641              "url": "git+https://github.com/sindresorhus/path-key.git",
372642              "type": "distribution"
372643            },
372644            {
372645              "url": "https://github.com/sindresorhus/path-key#readme",
372646              "type": "website"
372647            }
372648          ],
372649          "evidence": {},
372650          "signature": {
372651            "signature": {
372652              "publicKey": {}
372653            }
372654          },
372655          "modelCard": {
372656            "modelParameters": {
372657              "approach": {}
372658            },
372659            "quantitativeAnalysis": {
372660              "graphics": {}
372661            },
372662            "considerations": {}
372663          }
372664        },
372665        {
372666          "type": "library",
372667          "bom-ref": "pkg:npm/path-parse@1.0.7?package-id=8726bfd9ba83e33b",
372668          "supplier": {},
372669          "author": "Javier Blanco \u003chttp://jbgutierrez.info\u003e",
372670          "name": "path-parse",
372671          "version": "1.0.7",
372672          "description": "Node.js path.parse() ponyfill",
372673          "licenses": [
372674            {
372675              "license": {
372676                "id": "MIT"
372677              }
372678            }
372679          ],
372680          "cpe": "cpe:2.3:a:jbgutierrez:path-parse:1.0.7:*:*:*:*:*:*:*",
372681          "purl": "pkg:npm/path-parse@1.0.7",
372682          "swid": {
372683            "attachment": {}
372684          },
372685          "pedigree": {},
372686          "externalReferences": [
372687            {
372688              "url": "git+https://github.com/jbgutierrez/path-parse.git",
372689              "type": "distribution"
372690            },
372691            {
372692              "url": "https://github.com/jbgutierrez/path-parse#readme",
372693              "type": "website"
372694            }
372695          ],
372696          "evidence": {},
372697          "signature": {
372698            "signature": {
372699              "publicKey": {}
372700            }
372701          },
372702          "modelCard": {
372703            "modelParameters": {
372704              "approach": {}
372705            },
372706            "quantitativeAnalysis": {
372707              "graphics": {}
372708            },
372709            "considerations": {}
372710          }
372711        },
372712        {
372713          "type": "library",
372714          "bom-ref": "pkg:npm/path-to-regexp@0.1.7?package-id=c5bea2fa2a46ed82",
372715          "supplier": {},
372716          "name": "path-to-regexp",
372717          "version": "0.1.7",
372718          "description": "Express style path to RegExp utility",
372719          "licenses": [
372720            {
372721              "license": {
372722                "id": "MIT"
372723              }
372724            }
372725          ],
372726          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:0.1.7:*:*:*:*:*:*:*",
372727          "purl": "pkg:npm/path-to-regexp@0.1.7",
372728          "swid": {
372729            "attachment": {}
372730          },
372731          "pedigree": {},
372732          "externalReferences": [
372733            {
372734              "url": "git+https://github.com/component/path-to-regexp.git",
372735              "type": "distribution"
372736            },
372737            {
372738              "url": "https://github.com/component/path-to-regexp#readme",
372739              "type": "website"
372740            }
372741          ],
372742          "evidence": {},
372743          "signature": {
372744            "signature": {
372745              "publicKey": {}
372746            }
372747          },
372748          "modelCard": {
372749            "modelParameters": {
372750              "approach": {}
372751            },
372752            "quantitativeAnalysis": {
372753              "graphics": {}
372754            },
372755            "considerations": {}
372756          }
372757        },
372758        {
372759          "type": "library",
372760          "bom-ref": "pkg:npm/path-to-regexp@3.2.0?package-id=89f78191777fd1c7",
372761          "supplier": {},
372762          "name": "path-to-regexp",
372763          "version": "3.2.0",
372764          "description": "Express style path to RegExp utility",
372765          "licenses": [
372766            {
372767              "license": {
372768                "id": "MIT"
372769              }
372770            }
372771          ],
372772          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:3.2.0:*:*:*:*:*:*:*",
372773          "purl": "pkg:npm/path-to-regexp@3.2.0",
372774          "swid": {
372775            "attachment": {}
372776          },
372777          "pedigree": {},
372778          "externalReferences": [
372779            {
372780              "url": "git+https://github.com/pillarjs/path-to-regexp.git",
372781              "type": "distribution"
372782            },
372783            {
372784              "url": "https://github.com/pillarjs/path-to-regexp#readme",
372785              "type": "website"
372786            }
372787          ],
372788          "evidence": {},
372789          "signature": {
372790            "signature": {
372791              "publicKey": {}
372792            }
372793          },
372794          "modelCard": {
372795            "modelParameters": {
372796              "approach": {}
372797            },
372798            "quantitativeAnalysis": {
372799              "graphics": {}
372800            },
372801            "considerations": {}
372802          }
372803        },
372804        {
372805          "type": "library",
372806          "bom-ref": "pkg:npm/performance-now@2.1.0?package-id=33fda45cab4efc34",
372807          "supplier": {},
372808          "author": "Braveg1rl \u003cbraveg1rl@outlook.com\u003e",
372809          "name": "performance-now",
372810          "version": "2.1.0",
372811          "description": "Implements performance.now (based on process.hrtime).",
372812          "licenses": [
372813            {
372814              "license": {
372815                "id": "MIT"
372816              }
372817            }
372818          ],
372819          "cpe": "cpe:2.3:a:performance-now:performance-now:2.1.0:*:*:*:*:*:*:*",
372820          "purl": "pkg:npm/performance-now@2.1.0",
372821          "swid": {
372822            "attachment": {}
372823          },
372824          "pedigree": {},
372825          "externalReferences": [
372826            {
372827              "url": "git://github.com/braveg1rl/performance-now.git",
372828              "type": "distribution"
372829            },
372830            {
372831              "url": "https://github.com/braveg1rl/performance-now",
372832              "type": "website"
372833            }
372834          ],
372835          "evidence": {},
372836          "signature": {
372837            "signature": {
372838              "publicKey": {}
372839            }
372840          },
372841          "modelCard": {
372842            "modelParameters": {
372843              "approach": {}
372844            },
372845            "quantitativeAnalysis": {
372846              "graphics": {}
372847            },
372848            "considerations": {}
372849          }
372850        },
372851        {
372852          "type": "library",
372853          "bom-ref": "pkg:npm/performance-now@2.1.0?package-id=111ced796010edab",
372854          "supplier": {},
372855          "author": "Braveg1rl \u003cbraveg1rl@outlook.com\u003e",
372856          "name": "performance-now",
372857          "version": "2.1.0",
372858          "description": "Implements performance.now (based on process.hrtime).",
372859          "licenses": [
372860            {
372861              "license": {
372862                "id": "MIT"
372863              }
372864            }
372865          ],
372866          "cpe": "cpe:2.3:a:performance-now:performance-now:2.1.0:*:*:*:*:*:*:*",
372867          "purl": "pkg:npm/performance-now@2.1.0",
372868          "swid": {
372869            "attachment": {}
372870          },
372871          "pedigree": {},
372872          "externalReferences": [
372873            {
372874              "url": "git://github.com/braveg1rl/performance-now.git",
372875              "type": "distribution"
372876            },
372877            {
372878              "url": "https://github.com/braveg1rl/performance-now",
372879              "type": "website"
372880            }
372881          ],
372882          "evidence": {},
372883          "signature": {
372884            "signature": {
372885              "publicKey": {}
372886            }
372887          },
372888          "modelCard": {
372889            "modelParameters": {
372890              "approach": {}
372891            },
372892            "quantitativeAnalysis": {
372893              "graphics": {}
372894            },
372895            "considerations": {}
372896          }
372897        },
372898        {
372899          "type": "library",
372900          "bom-ref": "pkg:npm/pify@3.0.0?package-id=fbdbb56dc0a20970",
372901          "supplier": {},
372902          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372903          "name": "pify",
372904          "version": "3.0.0",
372905          "description": "Promisify a callback-style function",
372906          "licenses": [
372907            {
372908              "license": {
372909                "id": "MIT"
372910              }
372911            }
372912          ],
372913          "cpe": "cpe:2.3:a:sindresorhus:pify:3.0.0:*:*:*:*:*:*:*",
372914          "purl": "pkg:npm/pify@3.0.0",
372915          "swid": {
372916            "attachment": {}
372917          },
372918          "pedigree": {},
372919          "externalReferences": [
372920            {
372921              "url": "git+https://github.com/sindresorhus/pify.git",
372922              "type": "distribution"
372923            },
372924            {
372925              "url": "https://github.com/sindresorhus/pify#readme",
372926              "type": "website"
372927            }
372928          ],
372929          "evidence": {},
372930          "signature": {
372931            "signature": {
372932              "publicKey": {}
372933            }
372934          },
372935          "modelCard": {
372936            "modelParameters": {
372937              "approach": {}
372938            },
372939            "quantitativeAnalysis": {
372940              "graphics": {}
372941            },
372942            "considerations": {}
372943          }
372944        },
372945        {
372946          "type": "library",
372947          "bom-ref": "pkg:npm/pliant-app-gateway@1.0.0?package-id=b3314afd9dc66477",
372948          "supplier": {},
372949          "name": "pliant-app-gateway",
372950          "version": "1.0.0",
372951          "description": "Nest TypeScript starter repository",
372952          "licenses": [
372953            {
372954              "license": {
372955                "name": "UNLICENSED"
372956              }
372957            }
372958          ],
372959          "cpe": "cpe:2.3:a:pliant-app-gateway:pliant-app-gateway:1.0.0:*:*:*:*:*:*:*",
372960          "purl": "pkg:npm/pliant-app-gateway@1.0.0",
372961          "swid": {
372962            "attachment": {}
372963          },
372964          "pedigree": {},
372965          "evidence": {},
372966          "signature": {
372967            "signature": {
372968              "publicKey": {}
372969            }
372970          },
372971          "modelCard": {
372972            "modelParameters": {
372973              "approach": {}
372974            },
372975            "quantitativeAnalysis": {
372976              "graphics": {}
372977            },
372978            "considerations": {}
372979          }
372980        },
372981        {
372982          "type": "library",
372983          "bom-ref": "pkg:npm/prepend-http@1.0.4?package-id=5a1dd47457f85ce5",
372984          "supplier": {},
372985          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
372986          "name": "prepend-http",
372987          "version": "1.0.4",
372988          "description": "Prepend `http://` to humanized URLs like todomvc.com and localhost",
372989          "licenses": [
372990            {
372991              "license": {
372992                "id": "MIT"
372993              }
372994            }
372995          ],
372996          "cpe": "cpe:2.3:a:prepend-http:prepend-http:1.0.4:*:*:*:*:*:*:*",
372997          "purl": "pkg:npm/prepend-http@1.0.4",
372998          "swid": {
372999            "attachment": {}
373000          },
373001          "pedigree": {},
373002          "externalReferences": [
373003            {
373004              "url": "git+https://github.com/sindresorhus/prepend-http.git",
373005              "type": "distribution"
373006            },
373007            {
373008              "url": "https://github.com/sindresorhus/prepend-http#readme",
373009              "type": "website"
373010            }
373011          ],
373012          "evidence": {},
373013          "signature": {
373014            "signature": {
373015              "publicKey": {}
373016            }
373017          },
373018          "modelCard": {
373019            "modelParameters": {
373020              "approach": {}
373021            },
373022            "quantitativeAnalysis": {
373023              "graphics": {}
373024            },
373025            "considerations": {}
373026          }
373027        },
373028        {
373029          "type": "library",
373030          "bom-ref": "pkg:npm/process-nextick-args@2.0.0?package-id=8bbb7c6bdbbf3e62",
373031          "supplier": {},
373032          "name": "process-nextick-args",
373033          "version": "2.0.0",
373034          "description": "process.nextTick but always with args",
373035          "licenses": [
373036            {
373037              "license": {
373038                "id": "MIT"
373039              }
373040            }
373041          ],
373042          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.0:*:*:*:*:*:*:*",
373043          "purl": "pkg:npm/process-nextick-args@2.0.0",
373044          "swid": {
373045            "attachment": {}
373046          },
373047          "pedigree": {},
373048          "externalReferences": [
373049            {
373050              "url": "git+https://github.com/calvinmetcalf/process-nextick-args.git",
373051              "type": "distribution"
373052            },
373053            {
373054              "url": "https://github.com/calvinmetcalf/process-nextick-args",
373055              "type": "website"
373056            }
373057          ],
373058          "evidence": {},
373059          "signature": {
373060            "signature": {
373061              "publicKey": {}
373062            }
373063          },
373064          "modelCard": {
373065            "modelParameters": {
373066              "approach": {}
373067            },
373068            "quantitativeAnalysis": {
373069              "graphics": {}
373070            },
373071            "considerations": {}
373072          }
373073        },
373074        {
373075          "type": "library",
373076          "bom-ref": "pkg:npm/process-nextick-args@2.0.1?package-id=19dd49024e39231",
373077          "supplier": {},
373078          "name": "process-nextick-args",
373079          "version": "2.0.1",
373080          "description": "process.nextTick but always with args",
373081          "licenses": [
373082            {
373083              "license": {
373084                "id": "MIT"
373085              }
373086            }
373087          ],
373088          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.1:*:*:*:*:*:*:*",
373089          "purl": "pkg:npm/process-nextick-args@2.0.1",
373090          "swid": {
373091            "attachment": {}
373092          },
373093          "pedigree": {},
373094          "externalReferences": [
373095            {
373096              "url": "git+https://github.com/calvinmetcalf/process-nextick-args.git",
373097              "type": "distribution"
373098            },
373099            {
373100              "url": "https://github.com/calvinmetcalf/process-nextick-args",
373101              "type": "website"
373102            }
373103          ],
373104          "evidence": {},
373105          "signature": {
373106            "signature": {
373107              "publicKey": {}
373108            }
373109          },
373110          "modelCard": {
373111            "modelParameters": {
373112              "approach": {}
373113            },
373114            "quantitativeAnalysis": {
373115              "graphics": {}
373116            },
373117            "considerations": {}
373118          }
373119        },
373120        {
373121          "type": "library",
373122          "bom-ref": "pkg:npm/prom-client@13.1.0?package-id=a80065ec112e95c8",
373123          "supplier": {},
373124          "author": "Simon Nyberg",
373125          "name": "prom-client",
373126          "version": "13.1.0",
373127          "description": "Client for prometheus",
373128          "licenses": [
373129            {
373130              "license": {
373131                "id": "Apache-2.0"
373132              }
373133            }
373134          ],
373135          "cpe": "cpe:2.3:a:prom-client:prom-client:13.1.0:*:*:*:*:*:*:*",
373136          "purl": "pkg:npm/prom-client@13.1.0",
373137          "swid": {
373138            "attachment": {}
373139          },
373140          "pedigree": {},
373141          "externalReferences": [
373142            {
373143              "url": "git+ssh://git@github.com/siimon/prom-client.git",
373144              "type": "distribution"
373145            },
373146            {
373147              "url": "https://github.com/siimon/prom-client",
373148              "type": "website"
373149            }
373150          ],
373151          "evidence": {},
373152          "signature": {
373153            "signature": {
373154              "publicKey": {}
373155            }
373156          },
373157          "modelCard": {
373158            "modelParameters": {
373159              "approach": {}
373160            },
373161            "quantitativeAnalysis": {
373162              "graphics": {}
373163            },
373164            "considerations": {}
373165          }
373166        },
373167        {
373168          "type": "library",
373169          "bom-ref": "pkg:npm/promise-inflight@1.0.1?package-id=8ae6caef1e6290fe",
373170          "supplier": {},
373171          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
373172          "name": "promise-inflight",
373173          "version": "1.0.1",
373174          "description": "One promise for multiple requests in flight to avoid async duplication",
373175          "licenses": [
373176            {
373177              "license": {
373178                "id": "ISC"
373179              }
373180            }
373181          ],
373182          "cpe": "cpe:2.3:a:promise-inflight:promise-inflight:1.0.1:*:*:*:*:*:*:*",
373183          "purl": "pkg:npm/promise-inflight@1.0.1",
373184          "swid": {
373185            "attachment": {}
373186          },
373187          "pedigree": {},
373188          "externalReferences": [
373189            {
373190              "url": "git+https://github.com/iarna/promise-inflight.git",
373191              "type": "distribution"
373192            },
373193            {
373194              "url": "https://github.com/iarna/promise-inflight#readme",
373195              "type": "website"
373196            }
373197          ],
373198          "evidence": {},
373199          "signature": {
373200            "signature": {
373201              "publicKey": {}
373202            }
373203          },
373204          "modelCard": {
373205            "modelParameters": {
373206              "approach": {}
373207            },
373208            "quantitativeAnalysis": {
373209              "graphics": {}
373210            },
373211            "considerations": {}
373212          }
373213        },
373214        {
373215          "type": "library",
373216          "bom-ref": "pkg:npm/promise-retry@1.1.1?package-id=4d71993cfae70c18",
373217          "supplier": {},
373218          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
373219          "name": "promise-retry",
373220          "version": "1.1.1",
373221          "description": "Retries a function that returns a promise, leveraging the power of the retry module.",
373222          "licenses": [
373223            {
373224              "license": {
373225                "id": "MIT"
373226              }
373227            }
373228          ],
373229          "cpe": "cpe:2.3:a:promise-retry:promise-retry:1.1.1:*:*:*:*:*:*:*",
373230          "purl": "pkg:npm/promise-retry@1.1.1",
373231          "swid": {
373232            "attachment": {}
373233          },
373234          "pedigree": {},
373235          "externalReferences": [
373236            {
373237              "url": "git://github.com/IndigoUnited/node-promise-retry.git",
373238              "type": "distribution"
373239            },
373240            {
373241              "url": "https://github.com/IndigoUnited/node-promise-retry#readme",
373242              "type": "website"
373243            }
373244          ],
373245          "evidence": {},
373246          "signature": {
373247            "signature": {
373248              "publicKey": {}
373249            }
373250          },
373251          "modelCard": {
373252            "modelParameters": {
373253              "approach": {}
373254            },
373255            "quantitativeAnalysis": {
373256              "graphics": {}
373257            },
373258            "considerations": {}
373259          }
373260        },
373261        {
373262          "type": "library",
373263          "bom-ref": "pkg:npm/promzard@0.3.0?package-id=c6cc33c4ce6e7c43",
373264          "supplier": {},
373265          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
373266          "name": "promzard",
373267          "version": "0.3.0",
373268          "description": "prompting wizardly",
373269          "licenses": [
373270            {
373271              "license": {
373272                "id": "ISC"
373273              }
373274            }
373275          ],
373276          "cpe": "cpe:2.3:a:promzard:promzard:0.3.0:*:*:*:*:*:*:*",
373277          "purl": "pkg:npm/promzard@0.3.0",
373278          "swid": {
373279            "attachment": {}
373280          },
373281          "pedigree": {},
373282          "externalReferences": [
373283            {
373284              "url": "git://github.com/isaacs/promzard.git",
373285              "type": "distribution"
373286            },
373287            {
373288              "url": "https://github.com/isaacs/promzard#readme",
373289              "type": "website"
373290            }
373291          ],
373292          "evidence": {},
373293          "signature": {
373294            "signature": {
373295              "publicKey": {}
373296            }
373297          },
373298          "modelCard": {
373299            "modelParameters": {
373300              "approach": {}
373301            },
373302            "quantitativeAnalysis": {
373303              "graphics": {}
373304            },
373305            "considerations": {}
373306          }
373307        },
373308        {
373309          "type": "library",
373310          "bom-ref": "pkg:npm/proto-list@1.2.4?package-id=c43196d550bdd95d",
373311          "supplier": {},
373312          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
373313          "name": "proto-list",
373314          "version": "1.2.4",
373315          "description": "A utility for managing a prototype chain",
373316          "licenses": [
373317            {
373318              "license": {
373319                "id": "ISC"
373320              }
373321            }
373322          ],
373323          "cpe": "cpe:2.3:a:proto-list:proto-list:1.2.4:*:*:*:*:*:*:*",
373324          "purl": "pkg:npm/proto-list@1.2.4",
373325          "swid": {
373326            "attachment": {}
373327          },
373328          "pedigree": {},
373329          "externalReferences": [
373330            {
373331              "url": "git+https://github.com/isaacs/proto-list.git",
373332              "type": "distribution"
373333            },
373334            {
373335              "url": "https://github.com/isaacs/proto-list#readme",
373336              "type": "website"
373337            }
373338          ],
373339          "evidence": {},
373340          "signature": {
373341            "signature": {
373342              "publicKey": {}
373343            }
373344          },
373345          "modelCard": {
373346            "modelParameters": {
373347              "approach": {}
373348            },
373349            "quantitativeAnalysis": {
373350              "graphics": {}
373351            },
373352            "considerations": {}
373353          }
373354        },
373355        {
373356          "type": "library",
373357          "bom-ref": "pkg:npm/protoduck@5.0.1?package-id=b68f59ea3292e512",
373358          "supplier": {},
373359          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
373360          "name": "protoduck",
373361          "version": "5.0.1",
373362          "description": "Fancy duck typing for the most serious of ducks.",
373363          "licenses": [
373364            {
373365              "license": {
373366                "id": "MIT"
373367              }
373368            }
373369          ],
373370          "cpe": "cpe:2.3:a:protoduck:protoduck:5.0.1:*:*:*:*:*:*:*",
373371          "purl": "pkg:npm/protoduck@5.0.1",
373372          "swid": {
373373            "attachment": {}
373374          },
373375          "pedigree": {},
373376          "externalReferences": [
373377            {
373378              "url": "git+https://github.com/zkat/protoduck.git",
373379              "type": "distribution"
373380            },
373381            {
373382              "url": "https://github.com/zkat/protoduck#readme",
373383              "type": "website"
373384            }
373385          ],
373386          "evidence": {},
373387          "signature": {
373388            "signature": {
373389              "publicKey": {}
373390            }
373391          },
373392          "modelCard": {
373393            "modelParameters": {
373394              "approach": {}
373395            },
373396            "quantitativeAnalysis": {
373397              "graphics": {}
373398            },
373399            "considerations": {}
373400          }
373401        },
373402        {
373403          "type": "library",
373404          "bom-ref": "pkg:npm/proxy-addr@2.0.7?package-id=9c608dd4da227136",
373405          "supplier": {},
373406          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
373407          "name": "proxy-addr",
373408          "version": "2.0.7",
373409          "description": "Determine address of proxied request",
373410          "licenses": [
373411            {
373412              "license": {
373413                "id": "MIT"
373414              }
373415            }
373416          ],
373417          "cpe": "cpe:2.3:a:proxy-addr:proxy-addr:2.0.7:*:*:*:*:*:*:*",
373418          "purl": "pkg:npm/proxy-addr@2.0.7",
373419          "swid": {
373420            "attachment": {}
373421          },
373422          "pedigree": {},
373423          "externalReferences": [
373424            {
373425              "url": "git+https://github.com/jshttp/proxy-addr.git",
373426              "type": "distribution"
373427            },
373428            {
373429              "url": "https://github.com/jshttp/proxy-addr#readme",
373430              "type": "website"
373431            }
373432          ],
373433          "evidence": {},
373434          "signature": {
373435            "signature": {
373436              "publicKey": {}
373437            }
373438          },
373439          "modelCard": {
373440            "modelParameters": {
373441              "approach": {}
373442            },
373443            "quantitativeAnalysis": {
373444              "graphics": {}
373445            },
373446            "considerations": {}
373447          }
373448        },
373449        {
373450          "type": "library",
373451          "bom-ref": "pkg:npm/prr@1.0.1?package-id=63f1d318228c3928",
373452          "supplier": {},
373453          "author": "Rod Vagg \u003crod@vagg.org\u003e (https://github.com/rvagg)",
373454          "name": "prr",
373455          "version": "1.0.1",
373456          "description": "A better Object.defineProperty()",
373457          "licenses": [
373458            {
373459              "license": {
373460                "id": "MIT"
373461              }
373462            }
373463          ],
373464          "cpe": "cpe:2.3:a:rvagg:prr:1.0.1:*:*:*:*:*:*:*",
373465          "purl": "pkg:npm/prr@1.0.1",
373466          "swid": {
373467            "attachment": {}
373468          },
373469          "pedigree": {},
373470          "externalReferences": [
373471            {
373472              "url": "git+https://github.com/rvagg/prr.git",
373473              "type": "distribution"
373474            },
373475            {
373476              "url": "https://github.com/rvagg/prr",
373477              "type": "website"
373478            }
373479          ],
373480          "evidence": {},
373481          "signature": {
373482            "signature": {
373483              "publicKey": {}
373484            }
373485          },
373486          "modelCard": {
373487            "modelParameters": {
373488              "approach": {}
373489            },
373490            "quantitativeAnalysis": {
373491              "graphics": {}
373492            },
373493            "considerations": {}
373494          }
373495        },
373496        {
373497          "type": "library",
373498          "bom-ref": "pkg:npm/pseudomap@1.0.2?package-id=ad27150a47cebf68",
373499          "supplier": {},
373500          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
373501          "name": "pseudomap",
373502          "version": "1.0.2",
373503          "description": "A thing that is a lot like ES6 `Map`, but without iterators, for use in environments where `for..of` syntax and `Map` are not available.",
373504          "licenses": [
373505            {
373506              "license": {
373507                "id": "ISC"
373508              }
373509            }
373510          ],
373511          "cpe": "cpe:2.3:a:pseudomap:pseudomap:1.0.2:*:*:*:*:*:*:*",
373512          "purl": "pkg:npm/pseudomap@1.0.2",
373513          "swid": {
373514            "attachment": {}
373515          },
373516          "pedigree": {},
373517          "externalReferences": [
373518            {
373519              "url": "git+https://github.com/isaacs/pseudomap.git",
373520              "type": "distribution"
373521            },
373522            {
373523              "url": "https://github.com/isaacs/pseudomap#readme",
373524              "type": "website"
373525            }
373526          ],
373527          "evidence": {},
373528          "signature": {
373529            "signature": {
373530              "publicKey": {}
373531            }
373532          },
373533          "modelCard": {
373534            "modelParameters": {
373535              "approach": {}
373536            },
373537            "quantitativeAnalysis": {
373538              "graphics": {}
373539            },
373540            "considerations": {}
373541          }
373542        },
373543        {
373544          "type": "library",
373545          "bom-ref": "pkg:npm/psl@1.8.0?package-id=9caee14baaff012",
373546          "supplier": {},
373547          "author": "Lupo Montero \u003clupomontero@gmail.com\u003e (https://lupomontero.com/)",
373548          "name": "psl",
373549          "version": "1.8.0",
373550          "description": "Domain name parser based on the Public Suffix List",
373551          "licenses": [
373552            {
373553              "license": {
373554                "id": "MIT"
373555              }
373556            }
373557          ],
373558          "cpe": "cpe:2.3:a:lupomontero:psl:1.8.0:*:*:*:*:*:*:*",
373559          "purl": "pkg:npm/psl@1.8.0",
373560          "swid": {
373561            "attachment": {}
373562          },
373563          "pedigree": {},
373564          "externalReferences": [
373565            {
373566              "url": "git+ssh://git@github.com/lupomontero/psl.git",
373567              "type": "distribution"
373568            },
373569            {
373570              "url": "https://github.com/lupomontero/psl#readme",
373571              "type": "website"
373572            }
373573          ],
373574          "evidence": {},
373575          "signature": {
373576            "signature": {
373577              "publicKey": {}
373578            }
373579          },
373580          "modelCard": {
373581            "modelParameters": {
373582              "approach": {}
373583            },
373584            "quantitativeAnalysis": {
373585              "graphics": {}
373586            },
373587            "considerations": {}
373588          }
373589        },
373590        {
373591          "type": "library",
373592          "bom-ref": "pkg:npm/psl@1.9.0?package-id=aa041879bf1f56aa",
373593          "supplier": {},
373594          "author": "Lupo Montero \u003clupomontero@gmail.com\u003e (https://lupomontero.com/)",
373595          "name": "psl",
373596          "version": "1.9.0",
373597          "description": "Domain name parser based on the Public Suffix List",
373598          "licenses": [
373599            {
373600              "license": {
373601                "id": "MIT"
373602              }
373603            }
373604          ],
373605          "cpe": "cpe:2.3:a:lupomontero:psl:1.9.0:*:*:*:*:*:*:*",
373606          "purl": "pkg:npm/psl@1.9.0",
373607          "swid": {
373608            "attachment": {}
373609          },
373610          "pedigree": {},
373611          "externalReferences": [
373612            {
373613              "url": "git+ssh://git@github.com/lupomontero/psl.git",
373614              "type": "distribution"
373615            },
373616            {
373617              "url": "https://github.com/lupomontero/psl#readme",
373618              "type": "website"
373619            }
373620          ],
373621          "evidence": {},
373622          "signature": {
373623            "signature": {
373624              "publicKey": {}
373625            }
373626          },
373627          "modelCard": {
373628            "modelParameters": {
373629              "approach": {}
373630            },
373631            "quantitativeAnalysis": {
373632              "graphics": {}
373633            },
373634            "considerations": {}
373635          }
373636        },
373637        {
373638          "type": "library",
373639          "bom-ref": "pkg:npm/pump@2.0.1?package-id=a8def469cb4dfeae",
373640          "supplier": {},
373641          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
373642          "name": "pump",
373643          "version": "2.0.1",
373644          "description": "pipe streams together and close all of them if one of them closes",
373645          "licenses": [
373646            {
373647              "license": {
373648                "id": "MIT"
373649              }
373650            }
373651          ],
373652          "cpe": "cpe:2.3:a:mafintosh:pump:2.0.1:*:*:*:*:*:*:*",
373653          "purl": "pkg:npm/pump@2.0.1",
373654          "swid": {
373655            "attachment": {}
373656          },
373657          "pedigree": {},
373658          "externalReferences": [
373659            {
373660              "url": "git://github.com/mafintosh/pump.git",
373661              "type": "distribution"
373662            },
373663            {
373664              "url": "https://github.com/mafintosh/pump#readme",
373665              "type": "website"
373666            }
373667          ],
373668          "evidence": {},
373669          "signature": {
373670            "signature": {
373671              "publicKey": {}
373672            }
373673          },
373674          "modelCard": {
373675            "modelParameters": {
373676              "approach": {}
373677            },
373678            "quantitativeAnalysis": {
373679              "graphics": {}
373680            },
373681            "considerations": {}
373682          }
373683        },
373684        {
373685          "type": "library",
373686          "bom-ref": "pkg:npm/pump@3.0.0?package-id=3312119136f0c5b9",
373687          "supplier": {},
373688          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
373689          "name": "pump",
373690          "version": "3.0.0",
373691          "description": "pipe streams together and close all of them if one of them closes",
373692          "licenses": [
373693            {
373694              "license": {
373695                "id": "MIT"
373696              }
373697            }
373698          ],
373699          "cpe": "cpe:2.3:a:mafintosh:pump:3.0.0:*:*:*:*:*:*:*",
373700          "purl": "pkg:npm/pump@3.0.0",
373701          "swid": {
373702            "attachment": {}
373703          },
373704          "pedigree": {},
373705          "externalReferences": [
373706            {
373707              "url": "git://github.com/mafintosh/pump.git",
373708              "type": "distribution"
373709            },
373710            {
373711              "url": "https://github.com/mafintosh/pump#readme",
373712              "type": "website"
373713            }
373714          ],
373715          "evidence": {},
373716          "signature": {
373717            "signature": {
373718              "publicKey": {}
373719            }
373720          },
373721          "modelCard": {
373722            "modelParameters": {
373723              "approach": {}
373724            },
373725            "quantitativeAnalysis": {
373726              "graphics": {}
373727            },
373728            "considerations": {}
373729          }
373730        },
373731        {
373732          "type": "library",
373733          "bom-ref": "pkg:npm/pumpify@1.5.1?package-id=dfd38f508d390c3c",
373734          "supplier": {},
373735          "author": "Mathias Buus",
373736          "name": "pumpify",
373737          "version": "1.5.1",
373738          "description": "Combine an array of streams into a single duplex stream using pump and duplexify",
373739          "licenses": [
373740            {
373741              "license": {
373742                "id": "MIT"
373743              }
373744            }
373745          ],
373746          "cpe": "cpe:2.3:a:mafintosh:pumpify:1.5.1:*:*:*:*:*:*:*",
373747          "purl": "pkg:npm/pumpify@1.5.1",
373748          "swid": {
373749            "attachment": {}
373750          },
373751          "pedigree": {},
373752          "externalReferences": [
373753            {
373754              "url": "git://github.com/mafintosh/pumpify.git",
373755              "type": "distribution"
373756            },
373757            {
373758              "url": "https://github.com/mafintosh/pumpify",
373759              "type": "website"
373760            }
373761          ],
373762          "evidence": {},
373763          "signature": {
373764            "signature": {
373765              "publicKey": {}
373766            }
373767          },
373768          "modelCard": {
373769            "modelParameters": {
373770              "approach": {}
373771            },
373772            "quantitativeAnalysis": {
373773              "graphics": {}
373774            },
373775            "considerations": {}
373776          }
373777        },
373778        {
373779          "type": "library",
373780          "bom-ref": "pkg:npm/punycode@2.1.1?package-id=a14c3d9d17c7ad6a",
373781          "supplier": {},
373782          "author": "Mathias Bynens (https://mathiasbynens.be/)",
373783          "name": "punycode",
373784          "version": "2.1.1",
373785          "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
373786          "licenses": [
373787            {
373788              "license": {
373789                "id": "MIT"
373790              }
373791            }
373792          ],
373793          "cpe": "cpe:2.3:a:punycode:punycode:2.1.1:*:*:*:*:*:*:*",
373794          "purl": "pkg:npm/punycode@2.1.1",
373795          "swid": {
373796            "attachment": {}
373797          },
373798          "pedigree": {},
373799          "externalReferences": [
373800            {
373801              "url": "git+https://github.com/bestiejs/punycode.js.git",
373802              "type": "distribution"
373803            },
373804            {
373805              "url": "https://mths.be/punycode",
373806              "type": "website"
373807            }
373808          ],
373809          "evidence": {},
373810          "signature": {
373811            "signature": {
373812              "publicKey": {}
373813            }
373814          },
373815          "modelCard": {
373816            "modelParameters": {
373817              "approach": {}
373818            },
373819            "quantitativeAnalysis": {
373820              "graphics": {}
373821            },
373822            "considerations": {}
373823          }
373824        },
373825        {
373826          "type": "library",
373827          "bom-ref": "pkg:npm/punycode@2.1.1?package-id=82a8dc98ce1c8f82",
373828          "supplier": {},
373829          "author": "Mathias Bynens (https://mathiasbynens.be/)",
373830          "name": "punycode",
373831          "version": "2.1.1",
373832          "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
373833          "licenses": [
373834            {
373835              "license": {
373836                "id": "MIT"
373837              }
373838            }
373839          ],
373840          "cpe": "cpe:2.3:a:punycode:punycode:2.1.1:*:*:*:*:*:*:*",
373841          "purl": "pkg:npm/punycode@2.1.1",
373842          "swid": {
373843            "attachment": {}
373844          },
373845          "pedigree": {},
373846          "externalReferences": [
373847            {
373848              "url": "git+https://github.com/bestiejs/punycode.js.git",
373849              "type": "distribution"
373850            },
373851            {
373852              "url": "https://mths.be/punycode",
373853              "type": "website"
373854            }
373855          ],
373856          "evidence": {},
373857          "signature": {
373858            "signature": {
373859              "publicKey": {}
373860            }
373861          },
373862          "modelCard": {
373863            "modelParameters": {
373864              "approach": {}
373865            },
373866            "quantitativeAnalysis": {
373867              "graphics": {}
373868            },
373869            "considerations": {}
373870          }
373871        },
373872        {
373873          "type": "library",
373874          "bom-ref": "pkg:npm/punycode@2.1.1?package-id=c670851ee62b8607",
373875          "supplier": {},
373876          "author": "Mathias Bynens (https://mathiasbynens.be/)",
373877          "name": "punycode",
373878          "version": "2.1.1",
373879          "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
373880          "licenses": [
373881            {
373882              "license": {
373883                "id": "MIT"
373884              }
373885            }
373886          ],
373887          "cpe": "cpe:2.3:a:punycode:punycode:2.1.1:*:*:*:*:*:*:*",
373888          "purl": "pkg:npm/punycode@2.1.1",
373889          "swid": {
373890            "attachment": {}
373891          },
373892          "pedigree": {},
373893          "externalReferences": [
373894            {
373895              "url": "git+https://github.com/bestiejs/punycode.js.git",
373896              "type": "distribution"
373897            },
373898            {
373899              "url": "https://mths.be/punycode",
373900              "type": "website"
373901            }
373902          ],
373903          "evidence": {},
373904          "signature": {
373905            "signature": {
373906              "publicKey": {}
373907            }
373908          },
373909          "modelCard": {
373910            "modelParameters": {
373911              "approach": {}
373912            },
373913            "quantitativeAnalysis": {
373914              "graphics": {}
373915            },
373916            "considerations": {}
373917          }
373918        },
373919        {
373920          "type": "library",
373921          "bom-ref": "pkg:npm/qrcode-terminal@0.12.0?package-id=12a4e61b4c7723ca",
373922          "supplier": {},
373923          "name": "qrcode-terminal",
373924          "version": "0.12.0",
373925          "description": "QRCodes, in the terminal",
373926          "licenses": [
373927            {
373928              "license": {
373929                "name": "Apache 2.0"
373930              }
373931            }
373932          ],
373933          "cpe": "cpe:2.3:a:qrcode-terminal:qrcode-terminal:0.12.0:*:*:*:*:*:*:*",
373934          "purl": "pkg:npm/qrcode-terminal@0.12.0",
373935          "swid": {
373936            "attachment": {}
373937          },
373938          "pedigree": {},
373939          "externalReferences": [
373940            {
373941              "url": "git+https://github.com/gtanner/qrcode-terminal.git",
373942              "type": "distribution"
373943            },
373944            {
373945              "url": "https://github.com/gtanner/qrcode-terminal",
373946              "type": "website"
373947            }
373948          ],
373949          "evidence": {},
373950          "signature": {
373951            "signature": {
373952              "publicKey": {}
373953            }
373954          },
373955          "modelCard": {
373956            "modelParameters": {
373957              "approach": {}
373958            },
373959            "quantitativeAnalysis": {
373960              "graphics": {}
373961            },
373962            "considerations": {}
373963          }
373964        },
373965        {
373966          "type": "library",
373967          "bom-ref": "pkg:npm/qs@6.5.2?package-id=1078fe4d646c4d63",
373968          "supplier": {},
373969          "name": "qs",
373970          "version": "6.5.2",
373971          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
373972          "licenses": [
373973            {
373974              "license": {
373975                "id": "BSD-3-Clause"
373976              }
373977            }
373978          ],
373979          "cpe": "cpe:2.3:a:ljharb:qs:6.5.2:*:*:*:*:*:*:*",
373980          "purl": "pkg:npm/qs@6.5.2",
373981          "swid": {
373982            "attachment": {}
373983          },
373984          "pedigree": {},
373985          "externalReferences": [
373986            {
373987              "url": "git+https://github.com/ljharb/qs.git",
373988              "type": "distribution"
373989            },
373990            {
373991              "url": "https://github.com/ljharb/qs",
373992              "type": "website"
373993            }
373994          ],
373995          "evidence": {},
373996          "signature": {
373997            "signature": {
373998              "publicKey": {}
373999            }
374000          },
374001          "modelCard": {
374002            "modelParameters": {
374003              "approach": {}
374004            },
374005            "quantitativeAnalysis": {
374006              "graphics": {}
374007            },
374008            "considerations": {}
374009          }
374010        },
374011        {
374012          "type": "library",
374013          "bom-ref": "pkg:npm/qs@6.5.3?package-id=d8f004c9ed9b4316",
374014          "supplier": {},
374015          "name": "qs",
374016          "version": "6.5.3",
374017          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
374018          "licenses": [
374019            {
374020              "license": {
374021                "id": "BSD-3-Clause"
374022              }
374023            }
374024          ],
374025          "cpe": "cpe:2.3:a:ljharb:qs:6.5.3:*:*:*:*:*:*:*",
374026          "purl": "pkg:npm/qs@6.5.3",
374027          "swid": {
374028            "attachment": {}
374029          },
374030          "pedigree": {},
374031          "externalReferences": [
374032            {
374033              "url": "git+https://github.com/ljharb/qs.git",
374034              "type": "distribution"
374035            },
374036            {
374037              "url": "https://github.com/ljharb/qs",
374038              "type": "website"
374039            }
374040          ],
374041          "evidence": {},
374042          "signature": {
374043            "signature": {
374044              "publicKey": {}
374045            }
374046          },
374047          "modelCard": {
374048            "modelParameters": {
374049              "approach": {}
374050            },
374051            "quantitativeAnalysis": {
374052              "graphics": {}
374053            },
374054            "considerations": {}
374055          }
374056        },
374057        {
374058          "type": "library",
374059          "bom-ref": "pkg:npm/qs@6.7.0?package-id=1e95eebb398f373b",
374060          "supplier": {},
374061          "name": "qs",
374062          "version": "6.7.0",
374063          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
374064          "licenses": [
374065            {
374066              "license": {
374067                "id": "BSD-3-Clause"
374068              }
374069            }
374070          ],
374071          "cpe": "cpe:2.3:a:ljharb:qs:6.7.0:*:*:*:*:*:*:*",
374072          "purl": "pkg:npm/qs@6.7.0",
374073          "swid": {
374074            "attachment": {}
374075          },
374076          "pedigree": {},
374077          "externalReferences": [
374078            {
374079              "url": "git+https://github.com/ljharb/qs.git",
374080              "type": "distribution"
374081            },
374082            {
374083              "url": "https://github.com/ljharb/qs",
374084              "type": "website"
374085            }
374086          ],
374087          "evidence": {},
374088          "signature": {
374089            "signature": {
374090              "publicKey": {}
374091            }
374092          },
374093          "modelCard": {
374094            "modelParameters": {
374095              "approach": {}
374096            },
374097            "quantitativeAnalysis": {
374098              "graphics": {}
374099            },
374100            "considerations": {}
374101          }
374102        },
374103        {
374104          "type": "library",
374105          "bom-ref": "pkg:npm/query-string@6.14.1?package-id=2abe4614025ed153",
374106          "supplier": {},
374107          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
374108          "name": "query-string",
374109          "version": "6.14.1",
374110          "description": "Parse and stringify URL query strings",
374111          "licenses": [
374112            {
374113              "license": {
374114                "id": "MIT"
374115              }
374116            }
374117          ],
374118          "cpe": "cpe:2.3:a:query-string:query-string:6.14.1:*:*:*:*:*:*:*",
374119          "purl": "pkg:npm/query-string@6.14.1",
374120          "swid": {
374121            "attachment": {}
374122          },
374123          "pedigree": {},
374124          "externalReferences": [
374125            {
374126              "url": "git+https://github.com/sindresorhus/query-string.git",
374127              "type": "distribution"
374128            },
374129            {
374130              "url": "https://github.com/sindresorhus/query-string#readme",
374131              "type": "website"
374132            }
374133          ],
374134          "evidence": {},
374135          "signature": {
374136            "signature": {
374137              "publicKey": {}
374138            }
374139          },
374140          "modelCard": {
374141            "modelParameters": {
374142              "approach": {}
374143            },
374144            "quantitativeAnalysis": {
374145              "graphics": {}
374146            },
374147            "considerations": {}
374148          }
374149        },
374150        {
374151          "type": "library",
374152          "bom-ref": "pkg:npm/querystringify@2.2.0?package-id=4369c662d6e803ab",
374153          "supplier": {},
374154          "author": "Arnout Kazemier",
374155          "name": "querystringify",
374156          "version": "2.2.0",
374157          "description": "Querystringify - Small, simple but powerful query string parser.",
374158          "licenses": [
374159            {
374160              "license": {
374161                "id": "MIT"
374162              }
374163            }
374164          ],
374165          "cpe": "cpe:2.3:a:querystringify:querystringify:2.2.0:*:*:*:*:*:*:*",
374166          "purl": "pkg:npm/querystringify@2.2.0",
374167          "swid": {
374168            "attachment": {}
374169          },
374170          "pedigree": {},
374171          "externalReferences": [
374172            {
374173              "url": "git+https://github.com/unshiftio/querystringify.git",
374174              "type": "distribution"
374175            },
374176            {
374177              "url": "https://github.com/unshiftio/querystringify",
374178              "type": "website"
374179            }
374180          ],
374181          "evidence": {},
374182          "signature": {
374183            "signature": {
374184              "publicKey": {}
374185            }
374186          },
374187          "modelCard": {
374188            "modelParameters": {
374189              "approach": {}
374190            },
374191            "quantitativeAnalysis": {
374192              "graphics": {}
374193            },
374194            "considerations": {}
374195          }
374196        },
374197        {
374198          "type": "library",
374199          "bom-ref": "pkg:npm/qw@1.0.2?package-id=b5fcf11b7efc24e7",
374200          "supplier": {},
374201          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
374202          "name": "qw",
374203          "version": "1.0.2",
374204          "description": "Quoted word literals!",
374205          "licenses": [
374206            {
374207              "license": {
374208                "id": "ISC"
374209              }
374210            }
374211          ],
374212          "cpe": "cpe:2.3:a:iarna:qw:1.0.2:*:*:*:*:*:*:*",
374213          "purl": "pkg:npm/qw@1.0.2",
374214          "swid": {
374215            "attachment": {}
374216          },
374217          "pedigree": {},
374218          "externalReferences": [
374219            {
374220              "url": "git+https://github.com/iarna/node-qw.git",
374221              "type": "distribution"
374222            },
374223            {
374224              "url": "https://github.com/iarna/node-qw#readme",
374225              "type": "website"
374226            }
374227          ],
374228          "evidence": {},
374229          "signature": {
374230            "signature": {
374231              "publicKey": {}
374232            }
374233          },
374234          "modelCard": {
374235            "modelParameters": {
374236              "approach": {}
374237            },
374238            "quantitativeAnalysis": {
374239              "graphics": {}
374240            },
374241            "considerations": {}
374242          }
374243        },
374244        {
374245          "type": "library",
374246          "bom-ref": "pkg:npm/range-parser@1.2.1?package-id=5f29bd6f8c12ae73",
374247          "supplier": {},
374248          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
374249          "name": "range-parser",
374250          "version": "1.2.1",
374251          "description": "Range header field string parser",
374252          "licenses": [
374253            {
374254              "license": {
374255                "id": "MIT"
374256              }
374257            }
374258          ],
374259          "cpe": "cpe:2.3:a:range-parser:range-parser:1.2.1:*:*:*:*:*:*:*",
374260          "purl": "pkg:npm/range-parser@1.2.1",
374261          "swid": {
374262            "attachment": {}
374263          },
374264          "pedigree": {},
374265          "externalReferences": [
374266            {
374267              "url": "git+https://github.com/jshttp/range-parser.git",
374268              "type": "distribution"
374269            },
374270            {
374271              "url": "https://github.com/jshttp/range-parser#readme",
374272              "type": "website"
374273            }
374274          ],
374275          "evidence": {},
374276          "signature": {
374277            "signature": {
374278              "publicKey": {}
374279            }
374280          },
374281          "modelCard": {
374282            "modelParameters": {
374283              "approach": {}
374284            },
374285            "quantitativeAnalysis": {
374286              "graphics": {}
374287            },
374288            "considerations": {}
374289          }
374290        },
374291        {
374292          "type": "library",
374293          "bom-ref": "pkg:npm/raw-body@2.4.0?package-id=94f992c82048f5e8",
374294          "supplier": {},
374295          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
374296          "name": "raw-body",
374297          "version": "2.4.0",
374298          "description": "Get and validate the raw body of a readable stream.",
374299          "licenses": [
374300            {
374301              "license": {
374302                "id": "MIT"
374303              }
374304            }
374305          ],
374306          "cpe": "cpe:2.3:a:stream-utils:raw-body:2.4.0:*:*:*:*:*:*:*",
374307          "purl": "pkg:npm/raw-body@2.4.0",
374308          "swid": {
374309            "attachment": {}
374310          },
374311          "pedigree": {},
374312          "externalReferences": [
374313            {
374314              "url": "git+https://github.com/stream-utils/raw-body.git",
374315              "type": "distribution"
374316            },
374317            {
374318              "url": "https://github.com/stream-utils/raw-body#readme",
374319              "type": "website"
374320            }
374321          ],
374322          "evidence": {},
374323          "signature": {
374324            "signature": {
374325              "publicKey": {}
374326            }
374327          },
374328          "modelCard": {
374329            "modelParameters": {
374330              "approach": {}
374331            },
374332            "quantitativeAnalysis": {
374333              "graphics": {}
374334            },
374335            "considerations": {}
374336          }
374337        },
374338        {
374339          "type": "library",
374340          "bom-ref": "pkg:npm/rc@1.2.8?package-id=4eb7e0d572bcca8b",
374341          "supplier": {},
374342          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (dominictarr.com)",
374343          "name": "rc",
374344          "version": "1.2.8",
374345          "description": "hardwired configuration loader",
374346          "licenses": [
374347            {
374348              "license": {
374349                "name": "(BSD-2-Clause OR MIT OR Apache-2.0)"
374350              }
374351            }
374352          ],
374353          "cpe": "cpe:2.3:a:dominictarr:rc:1.2.8:*:*:*:*:*:*:*",
374354          "purl": "pkg:npm/rc@1.2.8",
374355          "swid": {
374356            "attachment": {}
374357          },
374358          "pedigree": {},
374359          "externalReferences": [
374360            {
374361              "url": "git+https://github.com/dominictarr/rc.git",
374362              "type": "distribution"
374363            },
374364            {
374365              "url": "https://github.com/dominictarr/rc#readme",
374366              "type": "website"
374367            }
374368          ],
374369          "evidence": {},
374370          "signature": {
374371            "signature": {
374372              "publicKey": {}
374373            }
374374          },
374375          "modelCard": {
374376            "modelParameters": {
374377              "approach": {}
374378            },
374379            "quantitativeAnalysis": {
374380              "graphics": {}
374381            },
374382            "considerations": {}
374383          }
374384        },
374385        {
374386          "type": "library",
374387          "bom-ref": "pkg:npm/read@1.0.7?package-id=c9bc8b81b738d1cf",
374388          "supplier": {},
374389          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
374390          "name": "read",
374391          "version": "1.0.7",
374392          "description": "read(1) for node programs",
374393          "licenses": [
374394            {
374395              "license": {
374396                "id": "ISC"
374397              }
374398            }
374399          ],
374400          "cpe": "cpe:2.3:a:isaacs:read:1.0.7:*:*:*:*:*:*:*",
374401          "purl": "pkg:npm/read@1.0.7",
374402          "swid": {
374403            "attachment": {}
374404          },
374405          "pedigree": {},
374406          "externalReferences": [
374407            {
374408              "url": "git://github.com/isaacs/read.git",
374409              "type": "distribution"
374410            },
374411            {
374412              "url": "https://github.com/isaacs/read#readme",
374413              "type": "website"
374414            }
374415          ],
374416          "evidence": {},
374417          "signature": {
374418            "signature": {
374419              "publicKey": {}
374420            }
374421          },
374422          "modelCard": {
374423            "modelParameters": {
374424              "approach": {}
374425            },
374426            "quantitativeAnalysis": {
374427              "graphics": {}
374428            },
374429            "considerations": {}
374430          }
374431        },
374432        {
374433          "type": "library",
374434          "bom-ref": "pkg:npm/read-cmd-shim@1.0.5?package-id=f4070b859bc3daec",
374435          "supplier": {},
374436          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
374437          "name": "read-cmd-shim",
374438          "version": "1.0.5",
374439          "description": "Figure out what a cmd-shim is pointing at. This acts as the equivalent of fs.readlink.",
374440          "licenses": [
374441            {
374442              "license": {
374443                "id": "ISC"
374444              }
374445            }
374446          ],
374447          "cpe": "cpe:2.3:a:read-cmd-shim:read-cmd-shim:1.0.5:*:*:*:*:*:*:*",
374448          "purl": "pkg:npm/read-cmd-shim@1.0.5",
374449          "swid": {
374450            "attachment": {}
374451          },
374452          "pedigree": {},
374453          "externalReferences": [
374454            {
374455              "url": "git+https://github.com/npm/read-cmd-shim.git",
374456              "type": "distribution"
374457            },
374458            {
374459              "url": "https://github.com/npm/read-cmd-shim#readme",
374460              "type": "website"
374461            }
374462          ],
374463          "evidence": {},
374464          "signature": {
374465            "signature": {
374466              "publicKey": {}
374467            }
374468          },
374469          "modelCard": {
374470            "modelParameters": {
374471              "approach": {}
374472            },
374473            "quantitativeAnalysis": {
374474              "graphics": {}
374475            },
374476            "considerations": {}
374477          }
374478        },
374479        {
374480          "type": "library",
374481          "bom-ref": "pkg:npm/read-installed@4.0.3?package-id=9b81d092221c4f30",
374482          "supplier": {},
374483          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
374484          "name": "read-installed",
374485          "version": "4.0.3",
374486          "description": "Read all the installed packages in a folder, and return a tree structure with all the data.",
374487          "licenses": [
374488            {
374489              "license": {
374490                "id": "ISC"
374491              }
374492            }
374493          ],
374494          "cpe": "cpe:2.3:a:read-installed:read-installed:4.0.3:*:*:*:*:*:*:*",
374495          "purl": "pkg:npm/read-installed@4.0.3",
374496          "swid": {
374497            "attachment": {}
374498          },
374499          "pedigree": {},
374500          "externalReferences": [
374501            {
374502              "url": "git://github.com/isaacs/read-installed.git",
374503              "type": "distribution"
374504            },
374505            {
374506              "url": "https://github.com/isaacs/read-installed#readme",
374507              "type": "website"
374508            }
374509          ],
374510          "evidence": {},
374511          "signature": {
374512            "signature": {
374513              "publicKey": {}
374514            }
374515          },
374516          "modelCard": {
374517            "modelParameters": {
374518              "approach": {}
374519            },
374520            "quantitativeAnalysis": {
374521              "graphics": {}
374522            },
374523            "considerations": {}
374524          }
374525        },
374526        {
374527          "type": "library",
374528          "bom-ref": "pkg:npm/read-package-json@2.1.2?package-id=9ea97c610d50ae18",
374529          "supplier": {},
374530          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
374531          "name": "read-package-json",
374532          "version": "2.1.2",
374533          "description": "The thing npm uses to read package.json files with semantics and defaults and validation",
374534          "licenses": [
374535            {
374536              "license": {
374537                "id": "ISC"
374538              }
374539            }
374540          ],
374541          "cpe": "cpe:2.3:a:read-package-json:read-package-json:2.1.2:*:*:*:*:*:*:*",
374542          "purl": "pkg:npm/read-package-json@2.1.2",
374543          "swid": {
374544            "attachment": {}
374545          },
374546          "pedigree": {},
374547          "externalReferences": [
374548            {
374549              "url": "git+https://github.com/npm/read-package-json.git",
374550              "type": "distribution"
374551            },
374552            {
374553              "url": "https://github.com/npm/read-package-json#readme",
374554              "type": "website"
374555            }
374556          ],
374557          "evidence": {},
374558          "signature": {
374559            "signature": {
374560              "publicKey": {}
374561            }
374562          },
374563          "modelCard": {
374564            "modelParameters": {
374565              "approach": {}
374566            },
374567            "quantitativeAnalysis": {
374568              "graphics": {}
374569            },
374570            "considerations": {}
374571          }
374572        },
374573        {
374574          "type": "library",
374575          "bom-ref": "pkg:npm/read-package-tree@5.3.1?package-id=ae8f6f2464715ed7",
374576          "supplier": {},
374577          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
374578          "name": "read-package-tree",
374579          "version": "5.3.1",
374580          "description": "Read the contents of node_modules.",
374581          "licenses": [
374582            {
374583              "license": {
374584                "id": "ISC"
374585              }
374586            }
374587          ],
374588          "cpe": "cpe:2.3:a:read-package-tree:read-package-tree:5.3.1:*:*:*:*:*:*:*",
374589          "purl": "pkg:npm/read-package-tree@5.3.1",
374590          "swid": {
374591            "attachment": {}
374592          },
374593          "pedigree": {},
374594          "externalReferences": [
374595            {
374596              "url": "git+https://github.com/npm/read-package-tree.git",
374597              "type": "distribution"
374598            },
374599            {
374600              "url": "https://github.com/npm/read-package-tree",
374601              "type": "website"
374602            }
374603          ],
374604          "evidence": {},
374605          "signature": {
374606            "signature": {
374607              "publicKey": {}
374608            }
374609          },
374610          "modelCard": {
374611            "modelParameters": {
374612              "approach": {}
374613            },
374614            "quantitativeAnalysis": {
374615              "graphics": {}
374616            },
374617            "considerations": {}
374618          }
374619        },
374620        {
374621          "type": "library",
374622          "bom-ref": "pkg:npm/readable-stream@1.1.14?package-id=8757df08ac8f65d0",
374623          "supplier": {},
374624          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
374625          "name": "readable-stream",
374626          "version": "1.1.14",
374627          "description": "Streams3, a user-land copy of the stream library from Node.js v0.11.x",
374628          "licenses": [
374629            {
374630              "license": {
374631                "id": "MIT"
374632              }
374633            }
374634          ],
374635          "cpe": "cpe:2.3:a:readable-stream:readable-stream:1.1.14:*:*:*:*:*:*:*",
374636          "purl": "pkg:npm/readable-stream@1.1.14",
374637          "swid": {
374638            "attachment": {}
374639          },
374640          "pedigree": {},
374641          "externalReferences": [
374642            {
374643              "url": "git://github.com/isaacs/readable-stream.git",
374644              "type": "distribution"
374645            },
374646            {
374647              "url": "https://github.com/isaacs/readable-stream#readme",
374648              "type": "website"
374649            }
374650          ],
374651          "evidence": {},
374652          "signature": {
374653            "signature": {
374654              "publicKey": {}
374655            }
374656          },
374657          "modelCard": {
374658            "modelParameters": {
374659              "approach": {}
374660            },
374661            "quantitativeAnalysis": {
374662              "graphics": {}
374663            },
374664            "considerations": {}
374665          }
374666        },
374667        {
374668          "type": "library",
374669          "bom-ref": "pkg:npm/readable-stream@1.1.14?package-id=48b97f0045dc6076",
374670          "supplier": {},
374671          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
374672          "name": "readable-stream",
374673          "version": "1.1.14",
374674          "description": "Streams3, a user-land copy of the stream library from Node.js v0.11.x",
374675          "licenses": [
374676            {
374677              "license": {
374678                "id": "MIT"
374679              }
374680            }
374681          ],
374682          "cpe": "cpe:2.3:a:readable-stream:readable-stream:1.1.14:*:*:*:*:*:*:*",
374683          "purl": "pkg:npm/readable-stream@1.1.14",
374684          "swid": {
374685            "attachment": {}
374686          },
374687          "pedigree": {},
374688          "externalReferences": [
374689            {
374690              "url": "git://github.com/isaacs/readable-stream.git",
374691              "type": "distribution"
374692            },
374693            {
374694              "url": "https://github.com/isaacs/readable-stream#readme",
374695              "type": "website"
374696            }
374697          ],
374698          "evidence": {},
374699          "signature": {
374700            "signature": {
374701              "publicKey": {}
374702            }
374703          },
374704          "modelCard": {
374705            "modelParameters": {
374706              "approach": {}
374707            },
374708            "quantitativeAnalysis": {
374709              "graphics": {}
374710            },
374711            "considerations": {}
374712          }
374713        },
374714        {
374715          "type": "library",
374716          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=7353d87f1c25d400",
374717          "supplier": {},
374718          "name": "readable-stream",
374719          "version": "2.3.6",
374720          "description": "Streams3, a user-land copy of the stream library from Node.js",
374721          "licenses": [
374722            {
374723              "license": {
374724                "id": "MIT"
374725              }
374726            }
374727          ],
374728          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
374729          "purl": "pkg:npm/readable-stream@2.3.6",
374730          "swid": {
374731            "attachment": {}
374732          },
374733          "pedigree": {},
374734          "externalReferences": [
374735            {
374736              "url": "git://github.com/nodejs/readable-stream.git",
374737              "type": "distribution"
374738            },
374739            {
374740              "url": "https://github.com/nodejs/readable-stream#readme",
374741              "type": "website"
374742            }
374743          ],
374744          "evidence": {},
374745          "signature": {
374746            "signature": {
374747              "publicKey": {}
374748            }
374749          },
374750          "modelCard": {
374751            "modelParameters": {
374752              "approach": {}
374753            },
374754            "quantitativeAnalysis": {
374755              "graphics": {}
374756            },
374757            "considerations": {}
374758          }
374759        },
374760        {
374761          "type": "library",
374762          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=fe3065896055c182",
374763          "supplier": {},
374764          "name": "readable-stream",
374765          "version": "2.3.6",
374766          "description": "Streams3, a user-land copy of the stream library from Node.js",
374767          "licenses": [
374768            {
374769              "license": {
374770                "id": "MIT"
374771              }
374772            }
374773          ],
374774          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
374775          "purl": "pkg:npm/readable-stream@2.3.6",
374776          "swid": {
374777            "attachment": {}
374778          },
374779          "pedigree": {},
374780          "externalReferences": [
374781            {
374782              "url": "git://github.com/nodejs/readable-stream.git",
374783              "type": "distribution"
374784            },
374785            {
374786              "url": "https://github.com/nodejs/readable-stream#readme",
374787              "type": "website"
374788            }
374789          ],
374790          "evidence": {},
374791          "signature": {
374792            "signature": {
374793              "publicKey": {}
374794            }
374795          },
374796          "modelCard": {
374797            "modelParameters": {
374798              "approach": {}
374799            },
374800            "quantitativeAnalysis": {
374801              "graphics": {}
374802            },
374803            "considerations": {}
374804          }
374805        },
374806        {
374807          "type": "library",
374808          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=ee88dc9eaec41878",
374809          "supplier": {},
374810          "name": "readable-stream",
374811          "version": "2.3.6",
374812          "description": "Streams3, a user-land copy of the stream library from Node.js",
374813          "licenses": [
374814            {
374815              "license": {
374816                "id": "MIT"
374817              }
374818            }
374819          ],
374820          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
374821          "purl": "pkg:npm/readable-stream@2.3.6",
374822          "swid": {
374823            "attachment": {}
374824          },
374825          "pedigree": {},
374826          "externalReferences": [
374827            {
374828              "url": "git://github.com/nodejs/readable-stream.git",
374829              "type": "distribution"
374830            },
374831            {
374832              "url": "https://github.com/nodejs/readable-stream#readme",
374833              "type": "website"
374834            }
374835          ],
374836          "evidence": {},
374837          "signature": {
374838            "signature": {
374839              "publicKey": {}
374840            }
374841          },
374842          "modelCard": {
374843            "modelParameters": {
374844              "approach": {}
374845            },
374846            "quantitativeAnalysis": {
374847              "graphics": {}
374848            },
374849            "considerations": {}
374850          }
374851        },
374852        {
374853          "type": "library",
374854          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=de77726bf8112b61",
374855          "supplier": {},
374856          "name": "readable-stream",
374857          "version": "2.3.6",
374858          "description": "Streams3, a user-land copy of the stream library from Node.js",
374859          "licenses": [
374860            {
374861              "license": {
374862                "id": "MIT"
374863              }
374864            }
374865          ],
374866          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
374867          "purl": "pkg:npm/readable-stream@2.3.6",
374868          "swid": {
374869            "attachment": {}
374870          },
374871          "pedigree": {},
374872          "externalReferences": [
374873            {
374874              "url": "git://github.com/nodejs/readable-stream.git",
374875              "type": "distribution"
374876            },
374877            {
374878              "url": "https://github.com/nodejs/readable-stream#readme",
374879              "type": "website"
374880            }
374881          ],
374882          "evidence": {},
374883          "signature": {
374884            "signature": {
374885              "publicKey": {}
374886            }
374887          },
374888          "modelCard": {
374889            "modelParameters": {
374890              "approach": {}
374891            },
374892            "quantitativeAnalysis": {
374893              "graphics": {}
374894            },
374895            "considerations": {}
374896          }
374897        },
374898        {
374899          "type": "library",
374900          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=a2ed95a02f789ed0",
374901          "supplier": {},
374902          "name": "readable-stream",
374903          "version": "2.3.6",
374904          "description": "Streams3, a user-land copy of the stream library from Node.js",
374905          "licenses": [
374906            {
374907              "license": {
374908                "id": "MIT"
374909              }
374910            }
374911          ],
374912          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
374913          "purl": "pkg:npm/readable-stream@2.3.6",
374914          "swid": {
374915            "attachment": {}
374916          },
374917          "pedigree": {},
374918          "externalReferences": [
374919            {
374920              "url": "git://github.com/nodejs/readable-stream.git",
374921              "type": "distribution"
374922            },
374923            {
374924              "url": "https://github.com/nodejs/readable-stream#readme",
374925              "type": "website"
374926            }
374927          ],
374928          "evidence": {},
374929          "signature": {
374930            "signature": {
374931              "publicKey": {}
374932            }
374933          },
374934          "modelCard": {
374935            "modelParameters": {
374936              "approach": {}
374937            },
374938            "quantitativeAnalysis": {
374939              "graphics": {}
374940            },
374941            "considerations": {}
374942          }
374943        },
374944        {
374945          "type": "library",
374946          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=4bf24eaec254b2f5",
374947          "supplier": {},
374948          "name": "readable-stream",
374949          "version": "2.3.6",
374950          "description": "Streams3, a user-land copy of the stream library from Node.js",
374951          "licenses": [
374952            {
374953              "license": {
374954                "id": "MIT"
374955              }
374956            }
374957          ],
374958          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
374959          "purl": "pkg:npm/readable-stream@2.3.6",
374960          "swid": {
374961            "attachment": {}
374962          },
374963          "pedigree": {},
374964          "externalReferences": [
374965            {
374966              "url": "git://github.com/nodejs/readable-stream.git",
374967              "type": "distribution"
374968            },
374969            {
374970              "url": "https://github.com/nodejs/readable-stream#readme",
374971              "type": "website"
374972            }
374973          ],
374974          "evidence": {},
374975          "signature": {
374976            "signature": {
374977              "publicKey": {}
374978            }
374979          },
374980          "modelCard": {
374981            "modelParameters": {
374982              "approach": {}
374983            },
374984            "quantitativeAnalysis": {
374985              "graphics": {}
374986            },
374987            "considerations": {}
374988          }
374989        },
374990        {
374991          "type": "library",
374992          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=fbc5f578bd8a0000",
374993          "supplier": {},
374994          "name": "readable-stream",
374995          "version": "2.3.6",
374996          "description": "Streams3, a user-land copy of the stream library from Node.js",
374997          "licenses": [
374998            {
374999              "license": {
375000                "id": "MIT"
375001              }
375002            }
375003          ],
375004          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
375005          "purl": "pkg:npm/readable-stream@2.3.6",
375006          "swid": {
375007            "attachment": {}
375008          },
375009          "pedigree": {},
375010          "externalReferences": [
375011            {
375012              "url": "git://github.com/nodejs/readable-stream.git",
375013              "type": "distribution"
375014            },
375015            {
375016              "url": "https://github.com/nodejs/readable-stream#readme",
375017              "type": "website"
375018            }
375019          ],
375020          "evidence": {},
375021          "signature": {
375022            "signature": {
375023              "publicKey": {}
375024            }
375025          },
375026          "modelCard": {
375027            "modelParameters": {
375028              "approach": {}
375029            },
375030            "quantitativeAnalysis": {
375031              "graphics": {}
375032            },
375033            "considerations": {}
375034          }
375035        },
375036        {
375037          "type": "library",
375038          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=7cd5df9449d0f2a5",
375039          "supplier": {},
375040          "name": "readable-stream",
375041          "version": "2.3.6",
375042          "description": "Streams3, a user-land copy of the stream library from Node.js",
375043          "licenses": [
375044            {
375045              "license": {
375046                "id": "MIT"
375047              }
375048            }
375049          ],
375050          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
375051          "purl": "pkg:npm/readable-stream@2.3.6",
375052          "swid": {
375053            "attachment": {}
375054          },
375055          "pedigree": {},
375056          "externalReferences": [
375057            {
375058              "url": "git://github.com/nodejs/readable-stream.git",
375059              "type": "distribution"
375060            },
375061            {
375062              "url": "https://github.com/nodejs/readable-stream#readme",
375063              "type": "website"
375064            }
375065          ],
375066          "evidence": {},
375067          "signature": {
375068            "signature": {
375069              "publicKey": {}
375070            }
375071          },
375072          "modelCard": {
375073            "modelParameters": {
375074              "approach": {}
375075            },
375076            "quantitativeAnalysis": {
375077              "graphics": {}
375078            },
375079            "considerations": {}
375080          }
375081        },
375082        {
375083          "type": "library",
375084          "bom-ref": "pkg:npm/readable-stream@2.3.6?package-id=e6f05a441c42f027",
375085          "supplier": {},
375086          "name": "readable-stream",
375087          "version": "2.3.6",
375088          "description": "Streams3, a user-land copy of the stream library from Node.js",
375089          "licenses": [
375090            {
375091              "license": {
375092                "id": "MIT"
375093              }
375094            }
375095          ],
375096          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.6:*:*:*:*:*:*:*",
375097          "purl": "pkg:npm/readable-stream@2.3.6",
375098          "swid": {
375099            "attachment": {}
375100          },
375101          "pedigree": {},
375102          "externalReferences": [
375103            {
375104              "url": "git://github.com/nodejs/readable-stream.git",
375105              "type": "distribution"
375106            },
375107            {
375108              "url": "https://github.com/nodejs/readable-stream#readme",
375109              "type": "website"
375110            }
375111          ],
375112          "evidence": {},
375113          "signature": {
375114            "signature": {
375115              "publicKey": {}
375116            }
375117          },
375118          "modelCard": {
375119            "modelParameters": {
375120              "approach": {}
375121            },
375122            "quantitativeAnalysis": {
375123              "graphics": {}
375124            },
375125            "considerations": {}
375126          }
375127        },
375128        {
375129          "type": "library",
375130          "bom-ref": "pkg:npm/readable-stream@2.3.7?package-id=b99a917b60ecef17",
375131          "supplier": {},
375132          "name": "readable-stream",
375133          "version": "2.3.7",
375134          "description": "Streams3, a user-land copy of the stream library from Node.js",
375135          "licenses": [
375136            {
375137              "license": {
375138                "id": "MIT"
375139              }
375140            }
375141          ],
375142          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.7:*:*:*:*:*:*:*",
375143          "purl": "pkg:npm/readable-stream@2.3.7",
375144          "swid": {
375145            "attachment": {}
375146          },
375147          "pedigree": {},
375148          "externalReferences": [
375149            {
375150              "url": "git://github.com/nodejs/readable-stream.git",
375151              "type": "distribution"
375152            },
375153            {
375154              "url": "https://github.com/nodejs/readable-stream#readme",
375155              "type": "website"
375156            }
375157          ],
375158          "evidence": {},
375159          "signature": {
375160            "signature": {
375161              "publicKey": {}
375162            }
375163          },
375164          "modelCard": {
375165            "modelParameters": {
375166              "approach": {}
375167            },
375168            "quantitativeAnalysis": {
375169              "graphics": {}
375170            },
375171            "considerations": {}
375172          }
375173        },
375174        {
375175          "type": "library",
375176          "bom-ref": "pkg:npm/readable-stream@3.6.0?package-id=e68425c0a847320d",
375177          "supplier": {},
375178          "name": "readable-stream",
375179          "version": "3.6.0",
375180          "description": "Streams3, a user-land copy of the stream library from Node.js",
375181          "licenses": [
375182            {
375183              "license": {
375184                "id": "MIT"
375185              }
375186            }
375187          ],
375188          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.0:*:*:*:*:*:*:*",
375189          "purl": "pkg:npm/readable-stream@3.6.0",
375190          "swid": {
375191            "attachment": {}
375192          },
375193          "pedigree": {},
375194          "externalReferences": [
375195            {
375196              "url": "git://github.com/nodejs/readable-stream.git",
375197              "type": "distribution"
375198            },
375199            {
375200              "url": "https://github.com/nodejs/readable-stream#readme",
375201              "type": "website"
375202            }
375203          ],
375204          "evidence": {},
375205          "signature": {
375206            "signature": {
375207              "publicKey": {}
375208            }
375209          },
375210          "modelCard": {
375211            "modelParameters": {
375212              "approach": {}
375213            },
375214            "quantitativeAnalysis": {
375215              "graphics": {}
375216            },
375217            "considerations": {}
375218          }
375219        },
375220        {
375221          "type": "library",
375222          "bom-ref": "pkg:npm/readdir-scoped-modules@1.1.0?package-id=faa5c279a92af9df",
375223          "supplier": {},
375224          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
375225          "name": "readdir-scoped-modules",
375226          "version": "1.1.0",
375227          "description": "Like `fs.readdir` but handling `@org/module` dirs as if they were a single entry.",
375228          "licenses": [
375229            {
375230              "license": {
375231                "id": "ISC"
375232              }
375233            }
375234          ],
375235          "cpe": "cpe:2.3:a:readdir-scoped-modules:readdir-scoped-modules:1.1.0:*:*:*:*:*:*:*",
375236          "purl": "pkg:npm/readdir-scoped-modules@1.1.0",
375237          "swid": {
375238            "attachment": {}
375239          },
375240          "pedigree": {},
375241          "externalReferences": [
375242            {
375243              "url": "git+https://github.com/npm/readdir-scoped-modules.git",
375244              "type": "distribution"
375245            },
375246            {
375247              "url": "https://github.com/npm/readdir-scoped-modules",
375248              "type": "website"
375249            }
375250          ],
375251          "evidence": {},
375252          "signature": {
375253            "signature": {
375254              "publicKey": {}
375255            }
375256          },
375257          "modelCard": {
375258            "modelParameters": {
375259              "approach": {}
375260            },
375261            "quantitativeAnalysis": {
375262              "graphics": {}
375263            },
375264            "considerations": {}
375265          }
375266        },
375267        {
375268          "type": "library",
375269          "bom-ref": "pkg:npm/reflect-metadata@0.1.13?package-id=c10a8a0418712a9f",
375270          "supplier": {},
375271          "author": "Ron Buckton \u003cron.buckton@microsoft.com\u003e (http://github.com/rbuckton)",
375272          "name": "reflect-metadata",
375273          "version": "0.1.13",
375274          "description": "Polyfill for Metadata Reflection API",
375275          "licenses": [
375276            {
375277              "license": {
375278                "id": "Apache-2.0"
375279              }
375280            }
375281          ],
375282          "cpe": "cpe:2.3:a:reflect-metadata:reflect-metadata:0.1.13:*:*:*:*:*:*:*",
375283          "purl": "pkg:npm/reflect-metadata@0.1.13",
375284          "swid": {
375285            "attachment": {}
375286          },
375287          "pedigree": {},
375288          "externalReferences": [
375289            {
375290              "url": "git+https://github.com/rbuckton/reflect-metadata.git",
375291              "type": "distribution"
375292            },
375293            {
375294              "url": "http://rbuckton.github.io/reflect-metadata",
375295              "type": "website"
375296            }
375297          ],
375298          "evidence": {},
375299          "signature": {
375300            "signature": {
375301              "publicKey": {}
375302            }
375303          },
375304          "modelCard": {
375305            "modelParameters": {
375306              "approach": {}
375307            },
375308            "quantitativeAnalysis": {
375309              "graphics": {}
375310            },
375311            "considerations": {}
375312          }
375313        },
375314        {
375315          "type": "library",
375316          "bom-ref": "pkg:npm/registry-auth-token@3.4.0?package-id=7b8cdd936c12baa6",
375317          "supplier": {},
375318          "author": "Espen Hovlandsdal \u003cespen@hovlandsdal.com\u003e",
375319          "name": "registry-auth-token",
375320          "version": "3.4.0",
375321          "description": "Get the auth token set for an npm registry (if any)",
375322          "licenses": [
375323            {
375324              "license": {
375325                "id": "MIT"
375326              }
375327            }
375328          ],
375329          "cpe": "cpe:2.3:a:registry-auth-token:registry-auth-token:3.4.0:*:*:*:*:*:*:*",
375330          "purl": "pkg:npm/registry-auth-token@3.4.0",
375331          "swid": {
375332            "attachment": {}
375333          },
375334          "pedigree": {},
375335          "externalReferences": [
375336            {
375337              "url": "git+ssh://git@github.com/rexxars/registry-auth-token.git",
375338              "type": "distribution"
375339            },
375340            {
375341              "url": "https://github.com/rexxars/registry-auth-token#readme",
375342              "type": "website"
375343            }
375344          ],
375345          "evidence": {},
375346          "signature": {
375347            "signature": {
375348              "publicKey": {}
375349            }
375350          },
375351          "modelCard": {
375352            "modelParameters": {
375353              "approach": {}
375354            },
375355            "quantitativeAnalysis": {
375356              "graphics": {}
375357            },
375358            "considerations": {}
375359          }
375360        },
375361        {
375362          "type": "library",
375363          "bom-ref": "pkg:npm/registry-url@3.1.0?package-id=fcf8f05cbd852c57",
375364          "supplier": {},
375365          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
375366          "name": "registry-url",
375367          "version": "3.1.0",
375368          "description": "Get the set npm registry URL",
375369          "licenses": [
375370            {
375371              "license": {
375372                "id": "MIT"
375373              }
375374            }
375375          ],
375376          "cpe": "cpe:2.3:a:registry-url:registry-url:3.1.0:*:*:*:*:*:*:*",
375377          "purl": "pkg:npm/registry-url@3.1.0",
375378          "swid": {
375379            "attachment": {}
375380          },
375381          "pedigree": {},
375382          "externalReferences": [
375383            {
375384              "url": "git+https://github.com/sindresorhus/registry-url.git",
375385              "type": "distribution"
375386            },
375387            {
375388              "url": "https://github.com/sindresorhus/registry-url#readme",
375389              "type": "website"
375390            }
375391          ],
375392          "evidence": {},
375393          "signature": {
375394            "signature": {
375395              "publicKey": {}
375396            }
375397          },
375398          "modelCard": {
375399            "modelParameters": {
375400              "approach": {}
375401            },
375402            "quantitativeAnalysis": {
375403              "graphics": {}
375404            },
375405            "considerations": {}
375406          }
375407        },
375408        {
375409          "type": "library",
375410          "bom-ref": "pkg:npm/request@2.88.2?package-id=f13bacf801b96d31",
375411          "supplier": {},
375412          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
375413          "name": "request",
375414          "version": "2.88.2",
375415          "description": "Simplified HTTP request client.",
375416          "licenses": [
375417            {
375418              "license": {
375419                "id": "Apache-2.0"
375420              }
375421            }
375422          ],
375423          "cpe": "cpe:2.3:a:request:request:2.88.2:*:*:*:*:*:*:*",
375424          "purl": "pkg:npm/request@2.88.2",
375425          "swid": {
375426            "attachment": {}
375427          },
375428          "pedigree": {},
375429          "externalReferences": [
375430            {
375431              "url": "git+https://github.com/request/request.git",
375432              "type": "distribution"
375433            },
375434            {
375435              "url": "https://github.com/request/request#readme",
375436              "type": "website"
375437            }
375438          ],
375439          "evidence": {},
375440          "signature": {
375441            "signature": {
375442              "publicKey": {}
375443            }
375444          },
375445          "modelCard": {
375446            "modelParameters": {
375447              "approach": {}
375448            },
375449            "quantitativeAnalysis": {
375450              "graphics": {}
375451            },
375452            "considerations": {}
375453          }
375454        },
375455        {
375456          "type": "library",
375457          "bom-ref": "pkg:npm/request@2.88.2?package-id=ec2b63086d2826ec",
375458          "supplier": {},
375459          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
375460          "name": "request",
375461          "version": "2.88.2",
375462          "description": "Simplified HTTP request client.",
375463          "licenses": [
375464            {
375465              "license": {
375466                "id": "Apache-2.0"
375467              }
375468            }
375469          ],
375470          "cpe": "cpe:2.3:a:request:request:2.88.2:*:*:*:*:*:*:*",
375471          "purl": "pkg:npm/request@2.88.2",
375472          "swid": {
375473            "attachment": {}
375474          },
375475          "pedigree": {},
375476          "externalReferences": [
375477            {
375478              "url": "git+https://github.com/request/request.git",
375479              "type": "distribution"
375480            },
375481            {
375482              "url": "https://github.com/request/request#readme",
375483              "type": "website"
375484            }
375485          ],
375486          "evidence": {},
375487          "signature": {
375488            "signature": {
375489              "publicKey": {}
375490            }
375491          },
375492          "modelCard": {
375493            "modelParameters": {
375494              "approach": {}
375495            },
375496            "quantitativeAnalysis": {
375497              "graphics": {}
375498            },
375499            "considerations": {}
375500          }
375501        },
375502        {
375503          "type": "library",
375504          "bom-ref": "pkg:npm/request-ip@2.1.3?package-id=14411df53ce38d13",
375505          "supplier": {},
375506          "author": "Petar Bojinov \u003cpetarbojinov@gmail.com\u003e",
375507          "name": "request-ip",
375508          "version": "2.1.3",
375509          "description": "A small node.js module to retrieve the request's IP address",
375510          "licenses": [
375511            {
375512              "license": {
375513                "id": "MIT"
375514              }
375515            }
375516          ],
375517          "cpe": "cpe:2.3:a:request-ip:request-ip:2.1.3:*:*:*:*:*:*:*",
375518          "purl": "pkg:npm/request-ip@2.1.3",
375519          "swid": {
375520            "attachment": {}
375521          },
375522          "pedigree": {},
375523          "externalReferences": [
375524            {
375525              "url": "git+https://github.com/pbojinov/request-ip.git",
375526              "type": "distribution"
375527            },
375528            {
375529              "url": "https://github.com/pbojinov/request-ip",
375530              "type": "website"
375531            }
375532          ],
375533          "evidence": {},
375534          "signature": {
375535            "signature": {
375536              "publicKey": {}
375537            }
375538          },
375539          "modelCard": {
375540            "modelParameters": {
375541              "approach": {}
375542            },
375543            "quantitativeAnalysis": {
375544              "graphics": {}
375545            },
375546            "considerations": {}
375547          }
375548        },
375549        {
375550          "type": "library",
375551          "bom-ref": "pkg:npm/request-promise-core@1.1.4?package-id=cace198e93a0ac1a",
375552          "supplier": {},
375553          "author": "Nicolai Kamenzky (https://github.com/analog-nico)",
375554          "name": "request-promise-core",
375555          "version": "1.1.4",
375556          "description": "Core Promise support implementation for the simplified HTTP request client 'request'.",
375557          "licenses": [
375558            {
375559              "license": {
375560                "id": "ISC"
375561              }
375562            }
375563          ],
375564          "cpe": "cpe:2.3:a:request-promise-core:request-promise-core:1.1.4:*:*:*:*:*:*:*",
375565          "purl": "pkg:npm/request-promise-core@1.1.4",
375566          "swid": {
375567            "attachment": {}
375568          },
375569          "pedigree": {},
375570          "externalReferences": [
375571            {
375572              "url": "git+https://github.com/request/promise-core.git",
375573              "type": "distribution"
375574            },
375575            {
375576              "url": "https://github.com/request/promise-core#readme",
375577              "type": "website"
375578            }
375579          ],
375580          "evidence": {},
375581          "signature": {
375582            "signature": {
375583              "publicKey": {}
375584            }
375585          },
375586          "modelCard": {
375587            "modelParameters": {
375588              "approach": {}
375589            },
375590            "quantitativeAnalysis": {
375591              "graphics": {}
375592            },
375593            "considerations": {}
375594          }
375595        },
375596        {
375597          "type": "library",
375598          "bom-ref": "pkg:npm/request-promise-native@1.0.9?package-id=aaa680f997a6fc93",
375599          "supplier": {},
375600          "author": "Nicolai Kamenzky (https://github.com/analog-nico)",
375601          "name": "request-promise-native",
375602          "version": "1.0.9",
375603          "description": "The simplified HTTP request client 'request' with Promise support. Powered by native ES6 promises.",
375604          "licenses": [
375605            {
375606              "license": {
375607                "id": "ISC"
375608              }
375609            }
375610          ],
375611          "cpe": "cpe:2.3:a:request-promise-native:request-promise-native:1.0.9:*:*:*:*:*:*:*",
375612          "purl": "pkg:npm/request-promise-native@1.0.9",
375613          "swid": {
375614            "attachment": {}
375615          },
375616          "pedigree": {},
375617          "externalReferences": [
375618            {
375619              "url": "git+https://github.com/request/request-promise-native.git",
375620              "type": "distribution"
375621            },
375622            {
375623              "url": "https://github.com/request/request-promise-native#readme",
375624              "type": "website"
375625            }
375626          ],
375627          "evidence": {},
375628          "signature": {
375629            "signature": {
375630              "publicKey": {}
375631            }
375632          },
375633          "modelCard": {
375634            "modelParameters": {
375635              "approach": {}
375636            },
375637            "quantitativeAnalysis": {
375638              "graphics": {}
375639            },
375640            "considerations": {}
375641          }
375642        },
375643        {
375644          "type": "library",
375645          "bom-ref": "pkg:npm/require-directory@2.1.1?package-id=bec44f06abee329",
375646          "supplier": {},
375647          "author": "Troy Goode \u003ctroygoode@gmail.com\u003e (http://github.com/troygoode/)",
375648          "name": "require-directory",
375649          "version": "2.1.1",
375650          "description": "Recursively iterates over specified directory, require()'ing each file, and returning a nested hash structure containing those modules.",
375651          "licenses": [
375652            {
375653              "license": {
375654                "id": "MIT"
375655              }
375656            }
375657          ],
375658          "cpe": "cpe:2.3:a:require-directory:require-directory:2.1.1:*:*:*:*:*:*:*",
375659          "purl": "pkg:npm/require-directory@2.1.1",
375660          "swid": {
375661            "attachment": {}
375662          },
375663          "pedigree": {},
375664          "externalReferences": [
375665            {
375666              "url": "git://github.com/troygoode/node-require-directory.git",
375667              "type": "distribution"
375668            },
375669            {
375670              "url": "https://github.com/troygoode/node-require-directory/",
375671              "type": "website"
375672            }
375673          ],
375674          "evidence": {},
375675          "signature": {
375676            "signature": {
375677              "publicKey": {}
375678            }
375679          },
375680          "modelCard": {
375681            "modelParameters": {
375682              "approach": {}
375683            },
375684            "quantitativeAnalysis": {
375685              "graphics": {}
375686            },
375687            "considerations": {}
375688          }
375689        },
375690        {
375691          "type": "library",
375692          "bom-ref": "pkg:npm/require-main-filename@2.0.0?package-id=90371ac30591c486",
375693          "supplier": {},
375694          "author": "Ben Coe \u003cben@npmjs.com\u003e",
375695          "name": "require-main-filename",
375696          "version": "2.0.0",
375697          "description": "shim for require.main.filename() that works in as many environments as possible",
375698          "licenses": [
375699            {
375700              "license": {
375701                "id": "ISC"
375702              }
375703            }
375704          ],
375705          "cpe": "cpe:2.3:a:require-main-filename:require-main-filename:2.0.0:*:*:*:*:*:*:*",
375706          "purl": "pkg:npm/require-main-filename@2.0.0",
375707          "swid": {
375708            "attachment": {}
375709          },
375710          "pedigree": {},
375711          "externalReferences": [
375712            {
375713              "url": "git+ssh://git@github.com/yargs/require-main-filename.git",
375714              "type": "distribution"
375715            },
375716            {
375717              "url": "https://github.com/yargs/require-main-filename#readme",
375718              "type": "website"
375719            }
375720          ],
375721          "evidence": {},
375722          "signature": {
375723            "signature": {
375724              "publicKey": {}
375725            }
375726          },
375727          "modelCard": {
375728            "modelParameters": {
375729              "approach": {}
375730            },
375731            "quantitativeAnalysis": {
375732              "graphics": {}
375733            },
375734            "considerations": {}
375735          }
375736        },
375737        {
375738          "type": "library",
375739          "bom-ref": "pkg:npm/requires-port@1.0.0?package-id=d9c0fcb42cffe28d",
375740          "supplier": {},
375741          "author": "Arnout Kazemier",
375742          "name": "requires-port",
375743          "version": "1.0.0",
375744          "description": "Check if a protocol requires a certain port number to be added to an URL.",
375745          "licenses": [
375746            {
375747              "license": {
375748                "id": "MIT"
375749              }
375750            }
375751          ],
375752          "cpe": "cpe:2.3:a:requires-port:requires-port:1.0.0:*:*:*:*:*:*:*",
375753          "purl": "pkg:npm/requires-port@1.0.0",
375754          "swid": {
375755            "attachment": {}
375756          },
375757          "pedigree": {},
375758          "externalReferences": [
375759            {
375760              "url": "git+https://github.com/unshiftio/requires-port.git",
375761              "type": "distribution"
375762            },
375763            {
375764              "url": "https://github.com/unshiftio/requires-port",
375765              "type": "website"
375766            }
375767          ],
375768          "evidence": {},
375769          "signature": {
375770            "signature": {
375771              "publicKey": {}
375772            }
375773          },
375774          "modelCard": {
375775            "modelParameters": {
375776              "approach": {}
375777            },
375778            "quantitativeAnalysis": {
375779              "graphics": {}
375780            },
375781            "considerations": {}
375782          }
375783        },
375784        {
375785          "type": "library",
375786          "bom-ref": "pkg:npm/resolve@1.10.0?package-id=dd5261f69051c0d3",
375787          "supplier": {},
375788          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
375789          "name": "resolve",
375790          "version": "1.10.0",
375791          "description": "resolve like require.resolve() on behalf of files asynchronously and synchronously",
375792          "licenses": [
375793            {
375794              "license": {
375795                "id": "MIT"
375796              }
375797            }
375798          ],
375799          "cpe": "cpe:2.3:a:browserify:resolve:1.10.0:*:*:*:*:*:*:*",
375800          "purl": "pkg:npm/resolve@1.10.0",
375801          "swid": {
375802            "attachment": {}
375803          },
375804          "pedigree": {},
375805          "externalReferences": [
375806            {
375807              "url": "git://github.com/browserify/resolve.git",
375808              "type": "distribution"
375809            },
375810            {
375811              "url": "https://github.com/browserify/resolve#readme",
375812              "type": "website"
375813            }
375814          ],
375815          "evidence": {},
375816          "signature": {
375817            "signature": {
375818              "publicKey": {}
375819            }
375820          },
375821          "modelCard": {
375822            "modelParameters": {
375823              "approach": {}
375824            },
375825            "quantitativeAnalysis": {
375826              "graphics": {}
375827            },
375828            "considerations": {}
375829          }
375830        },
375831        {
375832          "type": "library",
375833          "bom-ref": "pkg:npm/resolve-from@4.0.0?package-id=8184b04db20ef759",
375834          "supplier": {},
375835          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
375836          "name": "resolve-from",
375837          "version": "4.0.0",
375838          "description": "Resolve the path of a module like `require.resolve()` but from a given path",
375839          "licenses": [
375840            {
375841              "license": {
375842                "id": "MIT"
375843              }
375844            }
375845          ],
375846          "cpe": "cpe:2.3:a:resolve-from:resolve-from:4.0.0:*:*:*:*:*:*:*",
375847          "purl": "pkg:npm/resolve-from@4.0.0",
375848          "swid": {
375849            "attachment": {}
375850          },
375851          "pedigree": {},
375852          "externalReferences": [
375853            {
375854              "url": "git+https://github.com/sindresorhus/resolve-from.git",
375855              "type": "distribution"
375856            },
375857            {
375858              "url": "https://github.com/sindresorhus/resolve-from#readme",
375859              "type": "website"
375860            }
375861          ],
375862          "evidence": {},
375863          "signature": {
375864            "signature": {
375865              "publicKey": {}
375866            }
375867          },
375868          "modelCard": {
375869            "modelParameters": {
375870              "approach": {}
375871            },
375872            "quantitativeAnalysis": {
375873              "graphics": {}
375874            },
375875            "considerations": {}
375876          }
375877        },
375878        {
375879          "type": "library",
375880          "bom-ref": "pkg:npm/retry@0.10.1?package-id=baef3799d7cf16e1",
375881          "supplier": {},
375882          "author": "Tim Koschützki \u003ctim@debuggable.com\u003e (http://debuggable.com/)",
375883          "name": "retry",
375884          "version": "0.10.1",
375885          "description": "Abstraction for exponential and custom retry strategies for failed operations.",
375886          "licenses": [
375887            {
375888              "license": {
375889                "id": "MIT"
375890              }
375891            }
375892          ],
375893          "cpe": "cpe:2.3:a:tim-kos:retry:0.10.1:*:*:*:*:*:*:*",
375894          "purl": "pkg:npm/retry@0.10.1",
375895          "swid": {
375896            "attachment": {}
375897          },
375898          "pedigree": {},
375899          "externalReferences": [
375900            {
375901              "url": "git://github.com/tim-kos/node-retry.git",
375902              "type": "distribution"
375903            },
375904            {
375905              "url": "https://github.com/tim-kos/node-retry",
375906              "type": "website"
375907            }
375908          ],
375909          "evidence": {},
375910          "signature": {
375911            "signature": {
375912              "publicKey": {}
375913            }
375914          },
375915          "modelCard": {
375916            "modelParameters": {
375917              "approach": {}
375918            },
375919            "quantitativeAnalysis": {
375920              "graphics": {}
375921            },
375922            "considerations": {}
375923          }
375924        },
375925        {
375926          "type": "library",
375927          "bom-ref": "pkg:npm/retry@0.12.0?package-id=c3f319915fd297ec",
375928          "supplier": {},
375929          "author": "Tim Koschützki \u003ctim@debuggable.com\u003e (http://debuggable.com/)",
375930          "name": "retry",
375931          "version": "0.12.0",
375932          "description": "Abstraction for exponential and custom retry strategies for failed operations.",
375933          "licenses": [
375934            {
375935              "license": {
375936                "id": "MIT"
375937              }
375938            }
375939          ],
375940          "cpe": "cpe:2.3:a:tim-kos:retry:0.12.0:*:*:*:*:*:*:*",
375941          "purl": "pkg:npm/retry@0.12.0",
375942          "swid": {
375943            "attachment": {}
375944          },
375945          "pedigree": {},
375946          "externalReferences": [
375947            {
375948              "url": "git://github.com/tim-kos/node-retry.git",
375949              "type": "distribution"
375950            },
375951            {
375952              "url": "https://github.com/tim-kos/node-retry",
375953              "type": "website"
375954            }
375955          ],
375956          "evidence": {},
375957          "signature": {
375958            "signature": {
375959              "publicKey": {}
375960            }
375961          },
375962          "modelCard": {
375963            "modelParameters": {
375964              "approach": {}
375965            },
375966            "quantitativeAnalysis": {
375967              "graphics": {}
375968            },
375969            "considerations": {}
375970          }
375971        },
375972        {
375973          "type": "library",
375974          "bom-ref": "pkg:npm/rfdc@1.3.0?package-id=c42ea943f6301922",
375975          "supplier": {},
375976          "author": "David Mark Clements \u003cdavid.clements@nearform.com\u003e",
375977          "name": "rfdc",
375978          "version": "1.3.0",
375979          "description": "Really Fast Deep Clone",
375980          "licenses": [
375981            {
375982              "license": {
375983                "id": "MIT"
375984              }
375985            }
375986          ],
375987          "cpe": "cpe:2.3:a:davidmarkclements:rfdc:1.3.0:*:*:*:*:*:*:*",
375988          "purl": "pkg:npm/rfdc@1.3.0",
375989          "swid": {
375990            "attachment": {}
375991          },
375992          "pedigree": {},
375993          "externalReferences": [
375994            {
375995              "url": "git+https://github.com/davidmarkclements/rfdc.git",
375996              "type": "distribution"
375997            },
375998            {
375999              "url": "https://github.com/davidmarkclements/rfdc#readme",
376000              "type": "website"
376001            }
376002          ],
376003          "evidence": {},
376004          "signature": {
376005            "signature": {
376006              "publicKey": {}
376007            }
376008          },
376009          "modelCard": {
376010            "modelParameters": {
376011              "approach": {}
376012            },
376013            "quantitativeAnalysis": {
376014              "graphics": {}
376015            },
376016            "considerations": {}
376017          }
376018        },
376019        {
376020          "type": "library",
376021          "bom-ref": "pkg:npm/rimraf@2.7.1?package-id=be161be7f66aefcd",
376022          "supplier": {},
376023          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
376024          "name": "rimraf",
376025          "version": "2.7.1",
376026          "description": "A deep deletion module for node (like `rm -rf`)",
376027          "licenses": [
376028            {
376029              "license": {
376030                "id": "ISC"
376031              }
376032            }
376033          ],
376034          "cpe": "cpe:2.3:a:isaacs:rimraf:2.7.1:*:*:*:*:*:*:*",
376035          "purl": "pkg:npm/rimraf@2.7.1",
376036          "swid": {
376037            "attachment": {}
376038          },
376039          "pedigree": {},
376040          "externalReferences": [
376041            {
376042              "url": "git://github.com/isaacs/rimraf.git",
376043              "type": "distribution"
376044            },
376045            {
376046              "url": "https://github.com/isaacs/rimraf#readme",
376047              "type": "website"
376048            }
376049          ],
376050          "evidence": {},
376051          "signature": {
376052            "signature": {
376053              "publicKey": {}
376054            }
376055          },
376056          "modelCard": {
376057            "modelParameters": {
376058              "approach": {}
376059            },
376060            "quantitativeAnalysis": {
376061              "graphics": {}
376062            },
376063            "considerations": {}
376064          }
376065        },
376066        {
376067          "type": "library",
376068          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=e01ebaeecf917be8",
376069          "supplier": {},
376070          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
376071          "name": "rimraf",
376072          "version": "3.0.2",
376073          "description": "A deep deletion module for node (like `rm -rf`)",
376074          "licenses": [
376075            {
376076              "license": {
376077                "id": "ISC"
376078              }
376079            }
376080          ],
376081          "cpe": "cpe:2.3:a:isaacs:rimraf:3.0.2:*:*:*:*:*:*:*",
376082          "purl": "pkg:npm/rimraf@3.0.2",
376083          "swid": {
376084            "attachment": {}
376085          },
376086          "pedigree": {},
376087          "externalReferences": [
376088            {
376089              "url": "git://github.com/isaacs/rimraf.git",
376090              "type": "distribution"
376091            },
376092            {
376093              "url": "https://github.com/isaacs/rimraf#readme",
376094              "type": "website"
376095            }
376096          ],
376097          "evidence": {},
376098          "signature": {
376099            "signature": {
376100              "publicKey": {}
376101            }
376102          },
376103          "modelCard": {
376104            "modelParameters": {
376105              "approach": {}
376106            },
376107            "quantitativeAnalysis": {
376108              "graphics": {}
376109            },
376110            "considerations": {}
376111          }
376112        },
376113        {
376114          "type": "library",
376115          "bom-ref": "pkg:npm/roarr@4.2.5?package-id=60ce0734aa2de4aa",
376116          "supplier": {},
376117          "author": "Gajus Kuizinas \u003cgajus@gajus.com\u003e (http://gajus.com)",
376118          "name": "roarr",
376119          "version": "4.2.5",
376120          "description": "JSON logger for Node.js and browser.",
376121          "licenses": [
376122            {
376123              "license": {
376124                "id": "BSD-3-Clause"
376125              }
376126            }
376127          ],
376128          "cpe": "cpe:2.3:a:gajus:roarr:4.2.5:*:*:*:*:*:*:*",
376129          "purl": "pkg:npm/roarr@4.2.5",
376130          "swid": {
376131            "attachment": {}
376132          },
376133          "pedigree": {},
376134          "externalReferences": [
376135            {
376136              "url": "git+ssh://git@github.com/gajus/roarr.git",
376137              "type": "distribution"
376138            },
376139            {
376140              "url": "https://github.com/gajus/roarr#readme",
376141              "type": "website"
376142            }
376143          ],
376144          "evidence": {},
376145          "signature": {
376146            "signature": {
376147              "publicKey": {}
376148            }
376149          },
376150          "modelCard": {
376151            "modelParameters": {
376152              "approach": {}
376153            },
376154            "quantitativeAnalysis": {
376155              "graphics": {}
376156            },
376157            "considerations": {}
376158          }
376159        },
376160        {
376161          "type": "library",
376162          "bom-ref": "pkg:npm/run-queue@1.0.3?package-id=442b305f6fbe55fa",
376163          "supplier": {},
376164          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
376165          "name": "run-queue",
376166          "version": "1.0.3",
376167          "description": "A promise based, dynamic priority queue runner, with concurrency limiting.",
376168          "licenses": [
376169            {
376170              "license": {
376171                "id": "ISC"
376172              }
376173            }
376174          ],
376175          "cpe": "cpe:2.3:a:run-queue:run-queue:1.0.3:*:*:*:*:*:*:*",
376176          "purl": "pkg:npm/run-queue@1.0.3",
376177          "swid": {
376178            "attachment": {}
376179          },
376180          "pedigree": {},
376181          "externalReferences": [
376182            {
376183              "url": "git+https://github.com/iarna/run-queue.git",
376184              "type": "distribution"
376185            },
376186            {
376187              "url": "https://npmjs.com/package/run-queue",
376188              "type": "website"
376189            }
376190          ],
376191          "evidence": {},
376192          "signature": {
376193            "signature": {
376194              "publicKey": {}
376195            }
376196          },
376197          "modelCard": {
376198            "modelParameters": {
376199              "approach": {}
376200            },
376201            "quantitativeAnalysis": {
376202              "graphics": {}
376203            },
376204            "considerations": {}
376205          }
376206        },
376207        {
376208          "type": "library",
376209          "bom-ref": "pkg:npm/rxjs@6.6.7?package-id=5afc7aa01923f872",
376210          "supplier": {},
376211          "author": "Ben Lesh \u003cben@benlesh.com\u003e",
376212          "name": "rxjs",
376213          "version": "6.6.7",
376214          "description": "Reactive Extensions for modern JavaScript",
376215          "licenses": [
376216            {
376217              "license": {
376218                "id": "Apache-2.0"
376219              }
376220            }
376221          ],
376222          "cpe": "cpe:2.3:a:ReactiveX:rxjs:6.6.7:*:*:*:*:*:*:*",
376223          "purl": "pkg:npm/rxjs@6.6.7",
376224          "swid": {
376225            "attachment": {}
376226          },
376227          "pedigree": {},
376228          "externalReferences": [
376229            {
376230              "url": "git+https://github.com/reactivex/rxjs.git",
376231              "type": "distribution"
376232            },
376233            {
376234              "url": "https://github.com/ReactiveX/RxJS",
376235              "type": "website"
376236            }
376237          ],
376238          "evidence": {},
376239          "signature": {
376240            "signature": {
376241              "publicKey": {}
376242            }
376243          },
376244          "modelCard": {
376245            "modelParameters": {
376246              "approach": {}
376247            },
376248            "quantitativeAnalysis": {
376249              "graphics": {}
376250            },
376251            "considerations": {}
376252          }
376253        },
376254        {
376255          "type": "library",
376256          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=50ecc5e6df6e58c5",
376257          "supplier": {},
376258          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376259          "name": "safe-buffer",
376260          "version": "5.1.2",
376261          "description": "Safer Node.js Buffer API",
376262          "licenses": [
376263            {
376264              "license": {
376265                "id": "MIT"
376266              }
376267            }
376268          ],
376269          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376270          "purl": "pkg:npm/safe-buffer@5.1.2",
376271          "swid": {
376272            "attachment": {}
376273          },
376274          "pedigree": {},
376275          "externalReferences": [
376276            {
376277              "url": "git://github.com/feross/safe-buffer.git",
376278              "type": "distribution"
376279            },
376280            {
376281              "url": "https://github.com/feross/safe-buffer",
376282              "type": "website"
376283            }
376284          ],
376285          "evidence": {},
376286          "signature": {
376287            "signature": {
376288              "publicKey": {}
376289            }
376290          },
376291          "modelCard": {
376292            "modelParameters": {
376293              "approach": {}
376294            },
376295            "quantitativeAnalysis": {
376296              "graphics": {}
376297            },
376298            "considerations": {}
376299          }
376300        },
376301        {
376302          "type": "library",
376303          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=f0f95c766e1aa1fd",
376304          "supplier": {},
376305          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376306          "name": "safe-buffer",
376307          "version": "5.1.2",
376308          "description": "Safer Node.js Buffer API",
376309          "licenses": [
376310            {
376311              "license": {
376312                "id": "MIT"
376313              }
376314            }
376315          ],
376316          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376317          "purl": "pkg:npm/safe-buffer@5.1.2",
376318          "swid": {
376319            "attachment": {}
376320          },
376321          "pedigree": {},
376322          "externalReferences": [
376323            {
376324              "url": "git://github.com/feross/safe-buffer.git",
376325              "type": "distribution"
376326            },
376327            {
376328              "url": "https://github.com/feross/safe-buffer",
376329              "type": "website"
376330            }
376331          ],
376332          "evidence": {},
376333          "signature": {
376334            "signature": {
376335              "publicKey": {}
376336            }
376337          },
376338          "modelCard": {
376339            "modelParameters": {
376340              "approach": {}
376341            },
376342            "quantitativeAnalysis": {
376343              "graphics": {}
376344            },
376345            "considerations": {}
376346          }
376347        },
376348        {
376349          "type": "library",
376350          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=1ac233da63df5c6b",
376351          "supplier": {},
376352          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376353          "name": "safe-buffer",
376354          "version": "5.1.2",
376355          "description": "Safer Node.js Buffer API",
376356          "licenses": [
376357            {
376358              "license": {
376359                "id": "MIT"
376360              }
376361            }
376362          ],
376363          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376364          "purl": "pkg:npm/safe-buffer@5.1.2",
376365          "swid": {
376366            "attachment": {}
376367          },
376368          "pedigree": {},
376369          "externalReferences": [
376370            {
376371              "url": "git://github.com/feross/safe-buffer.git",
376372              "type": "distribution"
376373            },
376374            {
376375              "url": "https://github.com/feross/safe-buffer",
376376              "type": "website"
376377            }
376378          ],
376379          "evidence": {},
376380          "signature": {
376381            "signature": {
376382              "publicKey": {}
376383            }
376384          },
376385          "modelCard": {
376386            "modelParameters": {
376387              "approach": {}
376388            },
376389            "quantitativeAnalysis": {
376390              "graphics": {}
376391            },
376392            "considerations": {}
376393          }
376394        },
376395        {
376396          "type": "library",
376397          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=e65ba2caaac63542",
376398          "supplier": {},
376399          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376400          "name": "safe-buffer",
376401          "version": "5.1.2",
376402          "description": "Safer Node.js Buffer API",
376403          "licenses": [
376404            {
376405              "license": {
376406                "id": "MIT"
376407              }
376408            }
376409          ],
376410          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376411          "purl": "pkg:npm/safe-buffer@5.1.2",
376412          "swid": {
376413            "attachment": {}
376414          },
376415          "pedigree": {},
376416          "externalReferences": [
376417            {
376418              "url": "git://github.com/feross/safe-buffer.git",
376419              "type": "distribution"
376420            },
376421            {
376422              "url": "https://github.com/feross/safe-buffer",
376423              "type": "website"
376424            }
376425          ],
376426          "evidence": {},
376427          "signature": {
376428            "signature": {
376429              "publicKey": {}
376430            }
376431          },
376432          "modelCard": {
376433            "modelParameters": {
376434              "approach": {}
376435            },
376436            "quantitativeAnalysis": {
376437              "graphics": {}
376438            },
376439            "considerations": {}
376440          }
376441        },
376442        {
376443          "type": "library",
376444          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=2097d653343f69eb",
376445          "supplier": {},
376446          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376447          "name": "safe-buffer",
376448          "version": "5.1.2",
376449          "description": "Safer Node.js Buffer API",
376450          "licenses": [
376451            {
376452              "license": {
376453                "id": "MIT"
376454              }
376455            }
376456          ],
376457          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376458          "purl": "pkg:npm/safe-buffer@5.1.2",
376459          "swid": {
376460            "attachment": {}
376461          },
376462          "pedigree": {},
376463          "externalReferences": [
376464            {
376465              "url": "git://github.com/feross/safe-buffer.git",
376466              "type": "distribution"
376467            },
376468            {
376469              "url": "https://github.com/feross/safe-buffer",
376470              "type": "website"
376471            }
376472          ],
376473          "evidence": {},
376474          "signature": {
376475            "signature": {
376476              "publicKey": {}
376477            }
376478          },
376479          "modelCard": {
376480            "modelParameters": {
376481              "approach": {}
376482            },
376483            "quantitativeAnalysis": {
376484              "graphics": {}
376485            },
376486            "considerations": {}
376487          }
376488        },
376489        {
376490          "type": "library",
376491          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=55a5a59b48ba893a",
376492          "supplier": {},
376493          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376494          "name": "safe-buffer",
376495          "version": "5.1.2",
376496          "description": "Safer Node.js Buffer API",
376497          "licenses": [
376498            {
376499              "license": {
376500                "id": "MIT"
376501              }
376502            }
376503          ],
376504          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376505          "purl": "pkg:npm/safe-buffer@5.1.2",
376506          "swid": {
376507            "attachment": {}
376508          },
376509          "pedigree": {},
376510          "externalReferences": [
376511            {
376512              "url": "git://github.com/feross/safe-buffer.git",
376513              "type": "distribution"
376514            },
376515            {
376516              "url": "https://github.com/feross/safe-buffer",
376517              "type": "website"
376518            }
376519          ],
376520          "evidence": {},
376521          "signature": {
376522            "signature": {
376523              "publicKey": {}
376524            }
376525          },
376526          "modelCard": {
376527            "modelParameters": {
376528              "approach": {}
376529            },
376530            "quantitativeAnalysis": {
376531              "graphics": {}
376532            },
376533            "considerations": {}
376534          }
376535        },
376536        {
376537          "type": "library",
376538          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=b1ce5f000c6bdf4a",
376539          "supplier": {},
376540          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376541          "name": "safe-buffer",
376542          "version": "5.1.2",
376543          "description": "Safer Node.js Buffer API",
376544          "licenses": [
376545            {
376546              "license": {
376547                "id": "MIT"
376548              }
376549            }
376550          ],
376551          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376552          "purl": "pkg:npm/safe-buffer@5.1.2",
376553          "swid": {
376554            "attachment": {}
376555          },
376556          "pedigree": {},
376557          "externalReferences": [
376558            {
376559              "url": "git://github.com/feross/safe-buffer.git",
376560              "type": "distribution"
376561            },
376562            {
376563              "url": "https://github.com/feross/safe-buffer",
376564              "type": "website"
376565            }
376566          ],
376567          "evidence": {},
376568          "signature": {
376569            "signature": {
376570              "publicKey": {}
376571            }
376572          },
376573          "modelCard": {
376574            "modelParameters": {
376575              "approach": {}
376576            },
376577            "quantitativeAnalysis": {
376578              "graphics": {}
376579            },
376580            "considerations": {}
376581          }
376582        },
376583        {
376584          "type": "library",
376585          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=bab19573381c4f",
376586          "supplier": {},
376587          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376588          "name": "safe-buffer",
376589          "version": "5.1.2",
376590          "description": "Safer Node.js Buffer API",
376591          "licenses": [
376592            {
376593              "license": {
376594                "id": "MIT"
376595              }
376596            }
376597          ],
376598          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376599          "purl": "pkg:npm/safe-buffer@5.1.2",
376600          "swid": {
376601            "attachment": {}
376602          },
376603          "pedigree": {},
376604          "externalReferences": [
376605            {
376606              "url": "git://github.com/feross/safe-buffer.git",
376607              "type": "distribution"
376608            },
376609            {
376610              "url": "https://github.com/feross/safe-buffer",
376611              "type": "website"
376612            }
376613          ],
376614          "evidence": {},
376615          "signature": {
376616            "signature": {
376617              "publicKey": {}
376618            }
376619          },
376620          "modelCard": {
376621            "modelParameters": {
376622              "approach": {}
376623            },
376624            "quantitativeAnalysis": {
376625              "graphics": {}
376626            },
376627            "considerations": {}
376628          }
376629        },
376630        {
376631          "type": "library",
376632          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=bcd939ee4de99ceb",
376633          "supplier": {},
376634          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376635          "name": "safe-buffer",
376636          "version": "5.1.2",
376637          "description": "Safer Node.js Buffer API",
376638          "licenses": [
376639            {
376640              "license": {
376641                "id": "MIT"
376642              }
376643            }
376644          ],
376645          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376646          "purl": "pkg:npm/safe-buffer@5.1.2",
376647          "swid": {
376648            "attachment": {}
376649          },
376650          "pedigree": {},
376651          "externalReferences": [
376652            {
376653              "url": "git://github.com/feross/safe-buffer.git",
376654              "type": "distribution"
376655            },
376656            {
376657              "url": "https://github.com/feross/safe-buffer",
376658              "type": "website"
376659            }
376660          ],
376661          "evidence": {},
376662          "signature": {
376663            "signature": {
376664              "publicKey": {}
376665            }
376666          },
376667          "modelCard": {
376668            "modelParameters": {
376669              "approach": {}
376670            },
376671            "quantitativeAnalysis": {
376672              "graphics": {}
376673            },
376674            "considerations": {}
376675          }
376676        },
376677        {
376678          "type": "library",
376679          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=1b2cd7c38c3a4930",
376680          "supplier": {},
376681          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376682          "name": "safe-buffer",
376683          "version": "5.1.2",
376684          "description": "Safer Node.js Buffer API",
376685          "licenses": [
376686            {
376687              "license": {
376688                "id": "MIT"
376689              }
376690            }
376691          ],
376692          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376693          "purl": "pkg:npm/safe-buffer@5.1.2",
376694          "swid": {
376695            "attachment": {}
376696          },
376697          "pedigree": {},
376698          "externalReferences": [
376699            {
376700              "url": "git://github.com/feross/safe-buffer.git",
376701              "type": "distribution"
376702            },
376703            {
376704              "url": "https://github.com/feross/safe-buffer",
376705              "type": "website"
376706            }
376707          ],
376708          "evidence": {},
376709          "signature": {
376710            "signature": {
376711              "publicKey": {}
376712            }
376713          },
376714          "modelCard": {
376715            "modelParameters": {
376716              "approach": {}
376717            },
376718            "quantitativeAnalysis": {
376719              "graphics": {}
376720            },
376721            "considerations": {}
376722          }
376723        },
376724        {
376725          "type": "library",
376726          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=5fcc1d2be46f8c79",
376727          "supplier": {},
376728          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376729          "name": "safe-buffer",
376730          "version": "5.1.2",
376731          "description": "Safer Node.js Buffer API",
376732          "licenses": [
376733            {
376734              "license": {
376735                "id": "MIT"
376736              }
376737            }
376738          ],
376739          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376740          "purl": "pkg:npm/safe-buffer@5.1.2",
376741          "swid": {
376742            "attachment": {}
376743          },
376744          "pedigree": {},
376745          "externalReferences": [
376746            {
376747              "url": "git://github.com/feross/safe-buffer.git",
376748              "type": "distribution"
376749            },
376750            {
376751              "url": "https://github.com/feross/safe-buffer",
376752              "type": "website"
376753            }
376754          ],
376755          "evidence": {},
376756          "signature": {
376757            "signature": {
376758              "publicKey": {}
376759            }
376760          },
376761          "modelCard": {
376762            "modelParameters": {
376763              "approach": {}
376764            },
376765            "quantitativeAnalysis": {
376766              "graphics": {}
376767            },
376768            "considerations": {}
376769          }
376770        },
376771        {
376772          "type": "library",
376773          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=2ac939eb28d1db11",
376774          "supplier": {},
376775          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376776          "name": "safe-buffer",
376777          "version": "5.1.2",
376778          "description": "Safer Node.js Buffer API",
376779          "licenses": [
376780            {
376781              "license": {
376782                "id": "MIT"
376783              }
376784            }
376785          ],
376786          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376787          "purl": "pkg:npm/safe-buffer@5.1.2",
376788          "swid": {
376789            "attachment": {}
376790          },
376791          "pedigree": {},
376792          "externalReferences": [
376793            {
376794              "url": "git://github.com/feross/safe-buffer.git",
376795              "type": "distribution"
376796            },
376797            {
376798              "url": "https://github.com/feross/safe-buffer",
376799              "type": "website"
376800            }
376801          ],
376802          "evidence": {},
376803          "signature": {
376804            "signature": {
376805              "publicKey": {}
376806            }
376807          },
376808          "modelCard": {
376809            "modelParameters": {
376810              "approach": {}
376811            },
376812            "quantitativeAnalysis": {
376813              "graphics": {}
376814            },
376815            "considerations": {}
376816          }
376817        },
376818        {
376819          "type": "library",
376820          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=841e94729b3d33d4",
376821          "supplier": {},
376822          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376823          "name": "safe-buffer",
376824          "version": "5.1.2",
376825          "description": "Safer Node.js Buffer API",
376826          "licenses": [
376827            {
376828              "license": {
376829                "id": "MIT"
376830              }
376831            }
376832          ],
376833          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376834          "purl": "pkg:npm/safe-buffer@5.1.2",
376835          "swid": {
376836            "attachment": {}
376837          },
376838          "pedigree": {},
376839          "externalReferences": [
376840            {
376841              "url": "git://github.com/feross/safe-buffer.git",
376842              "type": "distribution"
376843            },
376844            {
376845              "url": "https://github.com/feross/safe-buffer",
376846              "type": "website"
376847            }
376848          ],
376849          "evidence": {},
376850          "signature": {
376851            "signature": {
376852              "publicKey": {}
376853            }
376854          },
376855          "modelCard": {
376856            "modelParameters": {
376857              "approach": {}
376858            },
376859            "quantitativeAnalysis": {
376860              "graphics": {}
376861            },
376862            "considerations": {}
376863          }
376864        },
376865        {
376866          "type": "library",
376867          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=94afc1a0a505941a",
376868          "supplier": {},
376869          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376870          "name": "safe-buffer",
376871          "version": "5.1.2",
376872          "description": "Safer Node.js Buffer API",
376873          "licenses": [
376874            {
376875              "license": {
376876                "id": "MIT"
376877              }
376878            }
376879          ],
376880          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376881          "purl": "pkg:npm/safe-buffer@5.1.2",
376882          "swid": {
376883            "attachment": {}
376884          },
376885          "pedigree": {},
376886          "externalReferences": [
376887            {
376888              "url": "git://github.com/feross/safe-buffer.git",
376889              "type": "distribution"
376890            },
376891            {
376892              "url": "https://github.com/feross/safe-buffer",
376893              "type": "website"
376894            }
376895          ],
376896          "evidence": {},
376897          "signature": {
376898            "signature": {
376899              "publicKey": {}
376900            }
376901          },
376902          "modelCard": {
376903            "modelParameters": {
376904              "approach": {}
376905            },
376906            "quantitativeAnalysis": {
376907              "graphics": {}
376908            },
376909            "considerations": {}
376910          }
376911        },
376912        {
376913          "type": "library",
376914          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=81532a293d323c55",
376915          "supplier": {},
376916          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376917          "name": "safe-buffer",
376918          "version": "5.1.2",
376919          "description": "Safer Node.js Buffer API",
376920          "licenses": [
376921            {
376922              "license": {
376923                "id": "MIT"
376924              }
376925            }
376926          ],
376927          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376928          "purl": "pkg:npm/safe-buffer@5.1.2",
376929          "swid": {
376930            "attachment": {}
376931          },
376932          "pedigree": {},
376933          "externalReferences": [
376934            {
376935              "url": "git://github.com/feross/safe-buffer.git",
376936              "type": "distribution"
376937            },
376938            {
376939              "url": "https://github.com/feross/safe-buffer",
376940              "type": "website"
376941            }
376942          ],
376943          "evidence": {},
376944          "signature": {
376945            "signature": {
376946              "publicKey": {}
376947            }
376948          },
376949          "modelCard": {
376950            "modelParameters": {
376951              "approach": {}
376952            },
376953            "quantitativeAnalysis": {
376954              "graphics": {}
376955            },
376956            "considerations": {}
376957          }
376958        },
376959        {
376960          "type": "library",
376961          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=77bb2c4ce84fae64",
376962          "supplier": {},
376963          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
376964          "name": "safe-buffer",
376965          "version": "5.1.2",
376966          "description": "Safer Node.js Buffer API",
376967          "licenses": [
376968            {
376969              "license": {
376970                "id": "MIT"
376971              }
376972            }
376973          ],
376974          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
376975          "purl": "pkg:npm/safe-buffer@5.1.2",
376976          "swid": {
376977            "attachment": {}
376978          },
376979          "pedigree": {},
376980          "externalReferences": [
376981            {
376982              "url": "git://github.com/feross/safe-buffer.git",
376983              "type": "distribution"
376984            },
376985            {
376986              "url": "https://github.com/feross/safe-buffer",
376987              "type": "website"
376988            }
376989          ],
376990          "evidence": {},
376991          "signature": {
376992            "signature": {
376993              "publicKey": {}
376994            }
376995          },
376996          "modelCard": {
376997            "modelParameters": {
376998              "approach": {}
376999            },
377000            "quantitativeAnalysis": {
377001              "graphics": {}
377002            },
377003            "considerations": {}
377004          }
377005        },
377006        {
377007          "type": "library",
377008          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=840e31219814c3f0",
377009          "supplier": {},
377010          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
377011          "name": "safe-buffer",
377012          "version": "5.1.2",
377013          "description": "Safer Node.js Buffer API",
377014          "licenses": [
377015            {
377016              "license": {
377017                "id": "MIT"
377018              }
377019            }
377020          ],
377021          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
377022          "purl": "pkg:npm/safe-buffer@5.1.2",
377023          "swid": {
377024            "attachment": {}
377025          },
377026          "pedigree": {},
377027          "externalReferences": [
377028            {
377029              "url": "git://github.com/feross/safe-buffer.git",
377030              "type": "distribution"
377031            },
377032            {
377033              "url": "https://github.com/feross/safe-buffer",
377034              "type": "website"
377035            }
377036          ],
377037          "evidence": {},
377038          "signature": {
377039            "signature": {
377040              "publicKey": {}
377041            }
377042          },
377043          "modelCard": {
377044            "modelParameters": {
377045              "approach": {}
377046            },
377047            "quantitativeAnalysis": {
377048              "graphics": {}
377049            },
377050            "considerations": {}
377051          }
377052        },
377053        {
377054          "type": "library",
377055          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=d0d967c81d071eef",
377056          "supplier": {},
377057          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
377058          "name": "safe-buffer",
377059          "version": "5.1.2",
377060          "description": "Safer Node.js Buffer API",
377061          "licenses": [
377062            {
377063              "license": {
377064                "id": "MIT"
377065              }
377066            }
377067          ],
377068          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
377069          "purl": "pkg:npm/safe-buffer@5.1.2",
377070          "swid": {
377071            "attachment": {}
377072          },
377073          "pedigree": {},
377074          "externalReferences": [
377075            {
377076              "url": "git://github.com/feross/safe-buffer.git",
377077              "type": "distribution"
377078            },
377079            {
377080              "url": "https://github.com/feross/safe-buffer",
377081              "type": "website"
377082            }
377083          ],
377084          "evidence": {},
377085          "signature": {
377086            "signature": {
377087              "publicKey": {}
377088            }
377089          },
377090          "modelCard": {
377091            "modelParameters": {
377092              "approach": {}
377093            },
377094            "quantitativeAnalysis": {
377095              "graphics": {}
377096            },
377097            "considerations": {}
377098          }
377099        },
377100        {
377101          "type": "library",
377102          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=5e0db037d77ed863",
377103          "supplier": {},
377104          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
377105          "name": "safe-buffer",
377106          "version": "5.1.2",
377107          "description": "Safer Node.js Buffer API",
377108          "licenses": [
377109            {
377110              "license": {
377111                "id": "MIT"
377112              }
377113            }
377114          ],
377115          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
377116          "purl": "pkg:npm/safe-buffer@5.1.2",
377117          "swid": {
377118            "attachment": {}
377119          },
377120          "pedigree": {},
377121          "externalReferences": [
377122            {
377123              "url": "git://github.com/feross/safe-buffer.git",
377124              "type": "distribution"
377125            },
377126            {
377127              "url": "https://github.com/feross/safe-buffer",
377128              "type": "website"
377129            }
377130          ],
377131          "evidence": {},
377132          "signature": {
377133            "signature": {
377134              "publicKey": {}
377135            }
377136          },
377137          "modelCard": {
377138            "modelParameters": {
377139              "approach": {}
377140            },
377141            "quantitativeAnalysis": {
377142              "graphics": {}
377143            },
377144            "considerations": {}
377145          }
377146        },
377147        {
377148          "type": "library",
377149          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=cbafbaa46c5fde16",
377150          "supplier": {},
377151          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
377152          "name": "safe-buffer",
377153          "version": "5.1.2",
377154          "description": "Safer Node.js Buffer API",
377155          "licenses": [
377156            {
377157              "license": {
377158                "id": "MIT"
377159              }
377160            }
377161          ],
377162          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
377163          "purl": "pkg:npm/safe-buffer@5.1.2",
377164          "swid": {
377165            "attachment": {}
377166          },
377167          "pedigree": {},
377168          "externalReferences": [
377169            {
377170              "url": "git://github.com/feross/safe-buffer.git",
377171              "type": "distribution"
377172            },
377173            {
377174              "url": "https://github.com/feross/safe-buffer",
377175              "type": "website"
377176            }
377177          ],
377178          "evidence": {},
377179          "signature": {
377180            "signature": {
377181              "publicKey": {}
377182            }
377183          },
377184          "modelCard": {
377185            "modelParameters": {
377186              "approach": {}
377187            },
377188            "quantitativeAnalysis": {
377189              "graphics": {}
377190            },
377191            "considerations": {}
377192          }
377193        },
377194        {
377195          "type": "library",
377196          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=7dee1fb23bc0c5b5",
377197          "supplier": {},
377198          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
377199          "name": "safe-buffer",
377200          "version": "5.1.2",
377201          "description": "Safer Node.js Buffer API",
377202          "licenses": [
377203            {
377204              "license": {
377205                "id": "MIT"
377206              }
377207            }
377208          ],
377209          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
377210          "purl": "pkg:npm/safe-buffer@5.1.2",
377211          "swid": {
377212            "attachment": {}
377213          },
377214          "pedigree": {},
377215          "externalReferences": [
377216            {
377217              "url": "git://github.com/feross/safe-buffer.git",
377218              "type": "distribution"
377219            },
377220            {
377221              "url": "https://github.com/feross/safe-buffer",
377222              "type": "website"
377223            }
377224          ],
377225          "evidence": {},
377226          "signature": {
377227            "signature": {
377228              "publicKey": {}
377229            }
377230          },
377231          "modelCard": {
377232            "modelParameters": {
377233              "approach": {}
377234            },
377235            "quantitativeAnalysis": {
377236              "graphics": {}
377237            },
377238            "considerations": {}
377239          }
377240        },
377241        {
377242          "type": "library",
377243          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=e7607a2d4713bcd6",
377244          "supplier": {},
377245          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
377246          "name": "safe-buffer",
377247          "version": "5.1.2",
377248          "description": "Safer Node.js Buffer API",
377249          "licenses": [
377250            {
377251              "license": {
377252                "id": "MIT"
377253              }
377254            }
377255          ],
377256          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
377257          "purl": "pkg:npm/safe-buffer@5.1.2",
377258          "swid": {
377259            "attachment": {}
377260          },
377261          "pedigree": {},
377262          "externalReferences": [
377263            {
377264              "url": "git://github.com/feross/safe-buffer.git",
377265              "type": "distribution"
377266            },
377267            {
377268              "url": "https://github.com/feross/safe-buffer",
377269              "type": "website"
377270            }
377271          ],
377272          "evidence": {},
377273          "signature": {
377274            "signature": {
377275              "publicKey": {}
377276            }
377277          },
377278          "modelCard": {
377279            "modelParameters": {
377280              "approach": {}
377281            },
377282            "quantitativeAnalysis": {
377283              "graphics": {}
377284            },
377285            "considerations": {}
377286          }
377287        },
377288        {
377289          "type": "library",
377290          "bom-ref": "pkg:npm/safe-buffer@5.2.0?package-id=516952fe04a9e096",
377291          "supplier": {},
377292          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
377293          "name": "safe-buffer",
377294          "version": "5.2.0",
377295          "description": "Safer Node.js Buffer API",
377296          "licenses": [
377297            {
377298              "license": {
377299                "id": "MIT"
377300              }
377301            }
377302          ],
377303          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.0:*:*:*:*:*:*:*",
377304          "purl": "pkg:npm/safe-buffer@5.2.0",
377305          "swid": {
377306            "attachment": {}
377307          },
377308          "pedigree": {},
377309          "externalReferences": [
377310            {
377311              "url": "git://github.com/feross/safe-buffer.git",
377312              "type": "distribution"
377313            },
377314            {
377315              "url": "https://github.com/feross/safe-buffer",
377316              "type": "website"
377317            }
377318          ],
377319          "evidence": {},
377320          "signature": {
377321            "signature": {
377322              "publicKey": {}
377323            }
377324          },
377325          "modelCard": {
377326            "modelParameters": {
377327              "approach": {}
377328            },
377329            "quantitativeAnalysis": {
377330              "graphics": {}
377331            },
377332            "considerations": {}
377333          }
377334        },
377335        {
377336          "type": "library",
377337          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=cd66034a1b1f8a60",
377338          "supplier": {},
377339          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
377340          "name": "safe-buffer",
377341          "version": "5.2.1",
377342          "description": "Safer Node.js Buffer API",
377343          "licenses": [
377344            {
377345              "license": {
377346                "id": "MIT"
377347              }
377348            }
377349          ],
377350          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
377351          "purl": "pkg:npm/safe-buffer@5.2.1",
377352          "swid": {
377353            "attachment": {}
377354          },
377355          "pedigree": {},
377356          "externalReferences": [
377357            {
377358              "url": "git://github.com/feross/safe-buffer.git",
377359              "type": "distribution"
377360            },
377361            {
377362              "url": "https://github.com/feross/safe-buffer",
377363              "type": "website"
377364            }
377365          ],
377366          "evidence": {},
377367          "signature": {
377368            "signature": {
377369              "publicKey": {}
377370            }
377371          },
377372          "modelCard": {
377373            "modelParameters": {
377374              "approach": {}
377375            },
377376            "quantitativeAnalysis": {
377377              "graphics": {}
377378            },
377379            "considerations": {}
377380          }
377381        },
377382        {
377383          "type": "library",
377384          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=5521c324233fe89",
377385          "supplier": {},
377386          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
377387          "name": "safe-buffer",
377388          "version": "5.2.1",
377389          "description": "Safer Node.js Buffer API",
377390          "licenses": [
377391            {
377392              "license": {
377393                "id": "MIT"
377394              }
377395            }
377396          ],
377397          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
377398          "purl": "pkg:npm/safe-buffer@5.2.1",
377399          "swid": {
377400            "attachment": {}
377401          },
377402          "pedigree": {},
377403          "externalReferences": [
377404            {
377405              "url": "git://github.com/feross/safe-buffer.git",
377406              "type": "distribution"
377407            },
377408            {
377409              "url": "https://github.com/feross/safe-buffer",
377410              "type": "website"
377411            }
377412          ],
377413          "evidence": {},
377414          "signature": {
377415            "signature": {
377416              "publicKey": {}
377417            }
377418          },
377419          "modelCard": {
377420            "modelParameters": {
377421              "approach": {}
377422            },
377423            "quantitativeAnalysis": {
377424              "graphics": {}
377425            },
377426            "considerations": {}
377427          }
377428        },
377429        {
377430          "type": "library",
377431          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=edf513d3ab46bee",
377432          "supplier": {},
377433          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
377434          "name": "safe-buffer",
377435          "version": "5.2.1",
377436          "description": "Safer Node.js Buffer API",
377437          "licenses": [
377438            {
377439              "license": {
377440                "id": "MIT"
377441              }
377442            }
377443          ],
377444          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
377445          "purl": "pkg:npm/safe-buffer@5.2.1",
377446          "swid": {
377447            "attachment": {}
377448          },
377449          "pedigree": {},
377450          "externalReferences": [
377451            {
377452              "url": "git://github.com/feross/safe-buffer.git",
377453              "type": "distribution"
377454            },
377455            {
377456              "url": "https://github.com/feross/safe-buffer",
377457              "type": "website"
377458            }
377459          ],
377460          "evidence": {},
377461          "signature": {
377462            "signature": {
377463              "publicKey": {}
377464            }
377465          },
377466          "modelCard": {
377467            "modelParameters": {
377468              "approach": {}
377469            },
377470            "quantitativeAnalysis": {
377471              "graphics": {}
377472            },
377473            "considerations": {}
377474          }
377475        },
377476        {
377477          "type": "library",
377478          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=94bc01ba89de1a5",
377479          "supplier": {},
377480          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
377481          "name": "safe-buffer",
377482          "version": "5.2.1",
377483          "description": "Safer Node.js Buffer API",
377484          "licenses": [
377485            {
377486              "license": {
377487                "id": "MIT"
377488              }
377489            }
377490          ],
377491          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
377492          "purl": "pkg:npm/safe-buffer@5.2.1",
377493          "swid": {
377494            "attachment": {}
377495          },
377496          "pedigree": {},
377497          "externalReferences": [
377498            {
377499              "url": "git://github.com/feross/safe-buffer.git",
377500              "type": "distribution"
377501            },
377502            {
377503              "url": "https://github.com/feross/safe-buffer",
377504              "type": "website"
377505            }
377506          ],
377507          "evidence": {},
377508          "signature": {
377509            "signature": {
377510              "publicKey": {}
377511            }
377512          },
377513          "modelCard": {
377514            "modelParameters": {
377515              "approach": {}
377516            },
377517            "quantitativeAnalysis": {
377518              "graphics": {}
377519            },
377520            "considerations": {}
377521          }
377522        },
377523        {
377524          "type": "library",
377525          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=7c597e987a69726c",
377526          "supplier": {},
377527          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
377528          "name": "safer-buffer",
377529          "version": "2.1.2",
377530          "description": "Modern Buffer API polyfill without footguns",
377531          "licenses": [
377532            {
377533              "license": {
377534                "id": "MIT"
377535              }
377536            }
377537          ],
377538          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
377539          "purl": "pkg:npm/safer-buffer@2.1.2",
377540          "swid": {
377541            "attachment": {}
377542          },
377543          "pedigree": {},
377544          "externalReferences": [
377545            {
377546              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
377547              "type": "distribution"
377548            },
377549            {
377550              "url": "https://github.com/ChALkeR/safer-buffer#readme",
377551              "type": "website"
377552            }
377553          ],
377554          "evidence": {},
377555          "signature": {
377556            "signature": {
377557              "publicKey": {}
377558            }
377559          },
377560          "modelCard": {
377561            "modelParameters": {
377562              "approach": {}
377563            },
377564            "quantitativeAnalysis": {
377565              "graphics": {}
377566            },
377567            "considerations": {}
377568          }
377569        },
377570        {
377571          "type": "library",
377572          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=1bec84d27ea929ed",
377573          "supplier": {},
377574          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
377575          "name": "safer-buffer",
377576          "version": "2.1.2",
377577          "description": "Modern Buffer API polyfill without footguns",
377578          "licenses": [
377579            {
377580              "license": {
377581                "id": "MIT"
377582              }
377583            }
377584          ],
377585          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
377586          "purl": "pkg:npm/safer-buffer@2.1.2",
377587          "swid": {
377588            "attachment": {}
377589          },
377590          "pedigree": {},
377591          "externalReferences": [
377592            {
377593              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
377594              "type": "distribution"
377595            },
377596            {
377597              "url": "https://github.com/ChALkeR/safer-buffer#readme",
377598              "type": "website"
377599            }
377600          ],
377601          "evidence": {},
377602          "signature": {
377603            "signature": {
377604              "publicKey": {}
377605            }
377606          },
377607          "modelCard": {
377608            "modelParameters": {
377609              "approach": {}
377610            },
377611            "quantitativeAnalysis": {
377612              "graphics": {}
377613            },
377614            "considerations": {}
377615          }
377616        },
377617        {
377618          "type": "library",
377619          "bom-ref": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.3\u0026package-id=e903138d19e85b80",
377620          "supplier": {},
377621          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
377622          "name": "scanelf",
377623          "version": "1.3.5-r1",
377624          "description": "Scan ELF binaries for stuff",
377625          "licenses": [
377626            {
377627              "license": {
377628                "id": "GPL-2.0-only"
377629              }
377630            }
377631          ],
377632          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.5-r1:*:*:*:*:*:*:*",
377633          "purl": "pkg:apk/alpine/scanelf@1.3.5-r1?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.17.3",
377634          "swid": {
377635            "attachment": {}
377636          },
377637          "pedigree": {},
377638          "externalReferences": [
377639            {
377640              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
377641              "type": "distribution"
377642            }
377643          ],
377644          "evidence": {},
377645          "signature": {
377646            "signature": {
377647              "publicKey": {}
377648            }
377649          },
377650          "modelCard": {
377651            "modelParameters": {
377652              "approach": {}
377653            },
377654            "quantitativeAnalysis": {
377655              "graphics": {}
377656            },
377657            "considerations": {}
377658          }
377659        },
377660        {
377661          "type": "library",
377662          "bom-ref": "pkg:npm/semver@5.7.1?package-id=718847389317e4c8",
377663          "supplier": {},
377664          "name": "semver",
377665          "version": "5.7.1",
377666          "description": "The semantic version parser used by npm.",
377667          "licenses": [
377668            {
377669              "license": {
377670                "id": "ISC"
377671              }
377672            }
377673          ],
377674          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
377675          "purl": "pkg:npm/semver@5.7.1",
377676          "swid": {
377677            "attachment": {}
377678          },
377679          "pedigree": {},
377680          "externalReferences": [
377681            {
377682              "url": "git+https://github.com/npm/node-semver.git",
377683              "type": "distribution"
377684            },
377685            {
377686              "url": "https://github.com/npm/node-semver#readme",
377687              "type": "website"
377688            }
377689          ],
377690          "evidence": {},
377691          "signature": {
377692            "signature": {
377693              "publicKey": {}
377694            }
377695          },
377696          "modelCard": {
377697            "modelParameters": {
377698              "approach": {}
377699            },
377700            "quantitativeAnalysis": {
377701              "graphics": {}
377702            },
377703            "considerations": {}
377704          }
377705        },
377706        {
377707          "type": "library",
377708          "bom-ref": "pkg:npm/semver@5.7.1?package-id=3d4365fad3b89b36",
377709          "supplier": {},
377710          "name": "semver",
377711          "version": "5.7.1",
377712          "description": "The semantic version parser used by npm.",
377713          "licenses": [
377714            {
377715              "license": {
377716                "id": "ISC"
377717              }
377718            }
377719          ],
377720          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
377721          "purl": "pkg:npm/semver@5.7.1",
377722          "swid": {
377723            "attachment": {}
377724          },
377725          "pedigree": {},
377726          "externalReferences": [
377727            {
377728              "url": "git+https://github.com/npm/node-semver.git",
377729              "type": "distribution"
377730            },
377731            {
377732              "url": "https://github.com/npm/node-semver#readme",
377733              "type": "website"
377734            }
377735          ],
377736          "evidence": {},
377737          "signature": {
377738            "signature": {
377739              "publicKey": {}
377740            }
377741          },
377742          "modelCard": {
377743            "modelParameters": {
377744              "approach": {}
377745            },
377746            "quantitativeAnalysis": {
377747              "graphics": {}
377748            },
377749            "considerations": {}
377750          }
377751        },
377752        {
377753          "type": "library",
377754          "bom-ref": "pkg:npm/semver-compare@1.0.0?package-id=e18fbcae955a3a19",
377755          "supplier": {},
377756          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
377757          "name": "semver-compare",
377758          "version": "1.0.0",
377759          "description": "compare two semver version strings, returning -1, 0, or 1",
377760          "licenses": [
377761            {
377762              "license": {
377763                "id": "MIT"
377764              }
377765            }
377766          ],
377767          "cpe": "cpe:2.3:a:semver-compare:semver-compare:1.0.0:*:*:*:*:*:*:*",
377768          "purl": "pkg:npm/semver-compare@1.0.0",
377769          "swid": {
377770            "attachment": {}
377771          },
377772          "pedigree": {},
377773          "externalReferences": [
377774            {
377775              "url": "git://github.com/substack/semver-compare.git",
377776              "type": "distribution"
377777            },
377778            {
377779              "url": "https://github.com/substack/semver-compare",
377780              "type": "website"
377781            }
377782          ],
377783          "evidence": {},
377784          "signature": {
377785            "signature": {
377786              "publicKey": {}
377787            }
377788          },
377789          "modelCard": {
377790            "modelParameters": {
377791              "approach": {}
377792            },
377793            "quantitativeAnalysis": {
377794              "graphics": {}
377795            },
377796            "considerations": {}
377797          }
377798        },
377799        {
377800          "type": "library",
377801          "bom-ref": "pkg:npm/semver-diff@2.1.0?package-id=8addb1f46fbb0950",
377802          "supplier": {},
377803          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (http://sindresorhus.com)",
377804          "name": "semver-diff",
377805          "version": "2.1.0",
377806          "description": "Get the diff type of two semver versions: 0.0.1 0.0.2 → patch",
377807          "licenses": [
377808            {
377809              "license": {
377810                "id": "MIT"
377811              }
377812            }
377813          ],
377814          "cpe": "cpe:2.3:a:sindresorhus:semver-diff:2.1.0:*:*:*:*:*:*:*",
377815          "purl": "pkg:npm/semver-diff@2.1.0",
377816          "swid": {
377817            "attachment": {}
377818          },
377819          "pedigree": {},
377820          "externalReferences": [
377821            {
377822              "url": "git+https://github.com/sindresorhus/semver-diff.git",
377823              "type": "distribution"
377824            },
377825            {
377826              "url": "https://github.com/sindresorhus/semver-diff#readme",
377827              "type": "website"
377828            }
377829          ],
377830          "evidence": {},
377831          "signature": {
377832            "signature": {
377833              "publicKey": {}
377834            }
377835          },
377836          "modelCard": {
377837            "modelParameters": {
377838              "approach": {}
377839            },
377840            "quantitativeAnalysis": {
377841              "graphics": {}
377842            },
377843            "considerations": {}
377844          }
377845        },
377846        {
377847          "type": "library",
377848          "bom-ref": "pkg:npm/send@0.17.1?package-id=39fd424f16226051",
377849          "supplier": {},
377850          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
377851          "name": "send",
377852          "version": "0.17.1",
377853          "description": "Better streaming static file server with Range and conditional-GET support",
377854          "licenses": [
377855            {
377856              "license": {
377857                "id": "MIT"
377858              }
377859            }
377860          ],
377861          "cpe": "cpe:2.3:a:pillarjs:send:0.17.1:*:*:*:*:*:*:*",
377862          "purl": "pkg:npm/send@0.17.1",
377863          "swid": {
377864            "attachment": {}
377865          },
377866          "pedigree": {},
377867          "externalReferences": [
377868            {
377869              "url": "git+https://github.com/pillarjs/send.git",
377870              "type": "distribution"
377871            },
377872            {
377873              "url": "https://github.com/pillarjs/send#readme",
377874              "type": "website"
377875            }
377876          ],
377877          "evidence": {},
377878          "signature": {
377879            "signature": {
377880              "publicKey": {}
377881            }
377882          },
377883          "modelCard": {
377884            "modelParameters": {
377885              "approach": {}
377886            },
377887            "quantitativeAnalysis": {
377888              "graphics": {}
377889            },
377890            "considerations": {}
377891          }
377892        },
377893        {
377894          "type": "library",
377895          "bom-ref": "pkg:npm/serialize-error@8.1.0?package-id=e5fdc9cccc69c57b",
377896          "supplier": {},
377897          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
377898          "name": "serialize-error",
377899          "version": "8.1.0",
377900          "description": "Serialize/deserialize an error into a plain object",
377901          "licenses": [
377902            {
377903              "license": {
377904                "id": "MIT"
377905              }
377906            }
377907          ],
377908          "cpe": "cpe:2.3:a:serialize-error:serialize-error:8.1.0:*:*:*:*:*:*:*",
377909          "purl": "pkg:npm/serialize-error@8.1.0",
377910          "swid": {
377911            "attachment": {}
377912          },
377913          "pedigree": {},
377914          "externalReferences": [
377915            {
377916              "url": "git+https://github.com/sindresorhus/serialize-error.git",
377917              "type": "distribution"
377918            },
377919            {
377920              "url": "https://github.com/sindresorhus/serialize-error#readme",
377921              "type": "website"
377922            }
377923          ],
377924          "evidence": {},
377925          "signature": {
377926            "signature": {
377927              "publicKey": {}
377928            }
377929          },
377930          "modelCard": {
377931            "modelParameters": {
377932              "approach": {}
377933            },
377934            "quantitativeAnalysis": {
377935              "graphics": {}
377936            },
377937            "considerations": {}
377938          }
377939        },
377940        {
377941          "type": "library",
377942          "bom-ref": "pkg:npm/serve-static@1.14.1?package-id=8a14231746896ad1",
377943          "supplier": {},
377944          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
377945          "name": "serve-static",
377946          "version": "1.14.1",
377947          "description": "Serve static files",
377948          "licenses": [
377949            {
377950              "license": {
377951                "id": "MIT"
377952              }
377953            }
377954          ],
377955          "cpe": "cpe:2.3:a:serve-static:serve-static:1.14.1:*:*:*:*:*:*:*",
377956          "purl": "pkg:npm/serve-static@1.14.1",
377957          "swid": {
377958            "attachment": {}
377959          },
377960          "pedigree": {},
377961          "externalReferences": [
377962            {
377963              "url": "git+https://github.com/expressjs/serve-static.git",
377964              "type": "distribution"
377965            },
377966            {
377967              "url": "https://github.com/expressjs/serve-static#readme",
377968              "type": "website"
377969            }
377970          ],
377971          "evidence": {},
377972          "signature": {
377973            "signature": {
377974              "publicKey": {}
377975            }
377976          },
377977          "modelCard": {
377978            "modelParameters": {
377979              "approach": {}
377980            },
377981            "quantitativeAnalysis": {
377982              "graphics": {}
377983            },
377984            "considerations": {}
377985          }
377986        },
377987        {
377988          "type": "library",
377989          "bom-ref": "pkg:npm/set-blocking@2.0.0?package-id=bac85cbb844de9c9",
377990          "supplier": {},
377991          "author": "Ben Coe \u003cben@npmjs.com\u003e",
377992          "name": "set-blocking",
377993          "version": "2.0.0",
377994          "description": "set blocking stdio and stderr ensuring that terminal output does not truncate",
377995          "licenses": [
377996            {
377997              "license": {
377998                "id": "ISC"
377999              }
378000            }
378001          ],
378002          "cpe": "cpe:2.3:a:set-blocking:set-blocking:2.0.0:*:*:*:*:*:*:*",
378003          "purl": "pkg:npm/set-blocking@2.0.0",
378004          "swid": {
378005            "attachment": {}
378006          },
378007          "pedigree": {},
378008          "externalReferences": [
378009            {
378010              "url": "git+https://github.com/yargs/set-blocking.git",
378011              "type": "distribution"
378012            },
378013            {
378014              "url": "https://github.com/yargs/set-blocking#readme",
378015              "type": "website"
378016            }
378017          ],
378018          "evidence": {},
378019          "signature": {
378020            "signature": {
378021              "publicKey": {}
378022            }
378023          },
378024          "modelCard": {
378025            "modelParameters": {
378026              "approach": {}
378027            },
378028            "quantitativeAnalysis": {
378029              "graphics": {}
378030            },
378031            "considerations": {}
378032          }
378033        },
378034        {
378035          "type": "library",
378036          "bom-ref": "pkg:npm/setprototypeof@1.1.1?package-id=48c9427615459103",
378037          "supplier": {},
378038          "author": "Wes Todd",
378039          "name": "setprototypeof",
378040          "version": "1.1.1",
378041          "description": "A small polyfill for Object.setprototypeof",
378042          "licenses": [
378043            {
378044              "license": {
378045                "id": "ISC"
378046              }
378047            }
378048          ],
378049          "cpe": "cpe:2.3:a:setprototypeof:setprototypeof:1.1.1:*:*:*:*:*:*:*",
378050          "purl": "pkg:npm/setprototypeof@1.1.1",
378051          "swid": {
378052            "attachment": {}
378053          },
378054          "pedigree": {},
378055          "externalReferences": [
378056            {
378057              "url": "git+https://github.com/wesleytodd/setprototypeof.git",
378058              "type": "distribution"
378059            },
378060            {
378061              "url": "https://github.com/wesleytodd/setprototypeof",
378062              "type": "website"
378063            }
378064          ],
378065          "evidence": {},
378066          "signature": {
378067            "signature": {
378068              "publicKey": {}
378069            }
378070          },
378071          "modelCard": {
378072            "modelParameters": {
378073              "approach": {}
378074            },
378075            "quantitativeAnalysis": {
378076              "graphics": {}
378077            },
378078            "considerations": {}
378079          }
378080        },
378081        {
378082          "type": "library",
378083          "bom-ref": "pkg:npm/sha@3.0.0?package-id=64341d7e8de754f6",
378084          "supplier": {},
378085          "name": "sha",
378086          "version": "3.0.0",
378087          "description": "Check and get file hashes",
378088          "licenses": [
378089            {
378090              "license": {
378091                "name": "(BSD-2-Clause OR MIT)"
378092              }
378093            }
378094          ],
378095          "cpe": "cpe:2.3:a:ForbesLindesay:sha:3.0.0:*:*:*:*:*:*:*",
378096          "purl": "pkg:npm/sha@3.0.0",
378097          "swid": {
378098            "attachment": {}
378099          },
378100          "pedigree": {},
378101          "externalReferences": [
378102            {
378103              "url": "git+https://github.com/ForbesLindesay/sha.git",
378104              "type": "distribution"
378105            },
378106            {
378107              "url": "https://github.com/ForbesLindesay/sha#readme",
378108              "type": "website"
378109            }
378110          ],
378111          "evidence": {},
378112          "signature": {
378113            "signature": {
378114              "publicKey": {}
378115            }
378116          },
378117          "modelCard": {
378118            "modelParameters": {
378119              "approach": {}
378120            },
378121            "quantitativeAnalysis": {
378122              "graphics": {}
378123            },
378124            "considerations": {}
378125          }
378126        },
378127        {
378128          "type": "library",
378129          "bom-ref": "pkg:npm/shebang-command@1.2.0?package-id=31728ea7868ca29",
378130          "supplier": {},
378131          "author": "Kevin Martensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
378132          "name": "shebang-command",
378133          "version": "1.2.0",
378134          "description": "Get the command from a shebang",
378135          "licenses": [
378136            {
378137              "license": {
378138                "id": "MIT"
378139              }
378140            }
378141          ],
378142          "cpe": "cpe:2.3:a:shebang-command:shebang-command:1.2.0:*:*:*:*:*:*:*",
378143          "purl": "pkg:npm/shebang-command@1.2.0",
378144          "swid": {
378145            "attachment": {}
378146          },
378147          "pedigree": {},
378148          "externalReferences": [
378149            {
378150              "url": "git+https://github.com/kevva/shebang-command.git",
378151              "type": "distribution"
378152            },
378153            {
378154              "url": "https://github.com/kevva/shebang-command#readme",
378155              "type": "website"
378156            }
378157          ],
378158          "evidence": {},
378159          "signature": {
378160            "signature": {
378161              "publicKey": {}
378162            }
378163          },
378164          "modelCard": {
378165            "modelParameters": {
378166              "approach": {}
378167            },
378168            "quantitativeAnalysis": {
378169              "graphics": {}
378170            },
378171            "considerations": {}
378172          }
378173        },
378174        {
378175          "type": "library",
378176          "bom-ref": "pkg:npm/shebang-regex@1.0.0?package-id=3ee6cea199436243",
378177          "supplier": {},
378178          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
378179          "name": "shebang-regex",
378180          "version": "1.0.0",
378181          "description": "Regular expression for matching a shebang",
378182          "licenses": [
378183            {
378184              "license": {
378185                "id": "MIT"
378186              }
378187            }
378188          ],
378189          "cpe": "cpe:2.3:a:shebang-regex:shebang-regex:1.0.0:*:*:*:*:*:*:*",
378190          "purl": "pkg:npm/shebang-regex@1.0.0",
378191          "swid": {
378192            "attachment": {}
378193          },
378194          "pedigree": {},
378195          "externalReferences": [
378196            {
378197              "url": "git+https://github.com/sindresorhus/shebang-regex.git",
378198              "type": "distribution"
378199            },
378200            {
378201              "url": "https://github.com/sindresorhus/shebang-regex#readme",
378202              "type": "website"
378203            }
378204          ],
378205          "evidence": {},
378206          "signature": {
378207            "signature": {
378208              "publicKey": {}
378209            }
378210          },
378211          "modelCard": {
378212            "modelParameters": {
378213              "approach": {}
378214            },
378215            "quantitativeAnalysis": {
378216              "graphics": {}
378217            },
378218            "considerations": {}
378219          }
378220        },
378221        {
378222          "type": "library",
378223          "bom-ref": "pkg:npm/signal-exit@3.0.2?package-id=5f81e92f345b2dca",
378224          "supplier": {},
378225          "author": "Ben Coe \u003cben@npmjs.com\u003e",
378226          "name": "signal-exit",
378227          "version": "3.0.2",
378228          "description": "when you want to fire an event no matter how a process exits.",
378229          "licenses": [
378230            {
378231              "license": {
378232                "id": "ISC"
378233              }
378234            }
378235          ],
378236          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.2:*:*:*:*:*:*:*",
378237          "purl": "pkg:npm/signal-exit@3.0.2",
378238          "swid": {
378239            "attachment": {}
378240          },
378241          "pedigree": {},
378242          "externalReferences": [
378243            {
378244              "url": "git+https://github.com/tapjs/signal-exit.git",
378245              "type": "distribution"
378246            },
378247            {
378248              "url": "https://github.com/tapjs/signal-exit",
378249              "type": "website"
378250            }
378251          ],
378252          "evidence": {},
378253          "signature": {
378254            "signature": {
378255              "publicKey": {}
378256            }
378257          },
378258          "modelCard": {
378259            "modelParameters": {
378260              "approach": {}
378261            },
378262            "quantitativeAnalysis": {
378263              "graphics": {}
378264            },
378265            "considerations": {}
378266          }
378267        },
378268        {
378269          "type": "library",
378270          "bom-ref": "pkg:npm/slide@1.1.6?package-id=67c80effc5f2e06c",
378271          "supplier": {},
378272          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
378273          "name": "slide",
378274          "version": "1.1.6",
378275          "description": "A flow control lib small enough to fit on in a slide presentation. Derived live at Oak.JS",
378276          "licenses": [
378277            {
378278              "license": {
378279                "id": "ISC"
378280              }
378281            }
378282          ],
378283          "cpe": "cpe:2.3:a:isaacs:slide:1.1.6:*:*:*:*:*:*:*",
378284          "purl": "pkg:npm/slide@1.1.6",
378285          "swid": {
378286            "attachment": {}
378287          },
378288          "pedigree": {},
378289          "externalReferences": [
378290            {
378291              "url": "git://github.com/isaacs/slide-flow-control.git",
378292              "type": "distribution"
378293            },
378294            {
378295              "url": "https://github.com/isaacs/slide-flow-control#readme",
378296              "type": "website"
378297            }
378298          ],
378299          "evidence": {},
378300          "signature": {
378301            "signature": {
378302              "publicKey": {}
378303            }
378304          },
378305          "modelCard": {
378306            "modelParameters": {
378307              "approach": {}
378308            },
378309            "quantitativeAnalysis": {
378310              "graphics": {}
378311            },
378312            "considerations": {}
378313          }
378314        },
378315        {
378316          "type": "library",
378317          "bom-ref": "pkg:npm/smart-buffer@4.1.0?package-id=8a098cd7b95880b2",
378318          "supplier": {},
378319          "author": "Josh Glazebrook",
378320          "name": "smart-buffer",
378321          "version": "4.1.0",
378322          "description": "smart-buffer is a Buffer wrapper that adds automatic read \u0026 write offset tracking, string operations, data insertions, and more.",
378323          "licenses": [
378324            {
378325              "license": {
378326                "id": "MIT"
378327              }
378328            }
378329          ],
378330          "cpe": "cpe:2.3:a:JoshGlazebrook:smart-buffer:4.1.0:*:*:*:*:*:*:*",
378331          "purl": "pkg:npm/smart-buffer@4.1.0",
378332          "swid": {
378333            "attachment": {}
378334          },
378335          "pedigree": {},
378336          "externalReferences": [
378337            {
378338              "url": "git+https://github.com/JoshGlazebrook/smart-buffer.git",
378339              "type": "distribution"
378340            },
378341            {
378342              "url": "https://github.com/JoshGlazebrook/smart-buffer/",
378343              "type": "website"
378344            }
378345          ],
378346          "evidence": {},
378347          "signature": {
378348            "signature": {
378349              "publicKey": {}
378350            }
378351          },
378352          "modelCard": {
378353            "modelParameters": {
378354              "approach": {}
378355            },
378356            "quantitativeAnalysis": {
378357              "graphics": {}
378358            },
378359            "considerations": {}
378360          }
378361        },
378362        {
378363          "type": "library",
378364          "bom-ref": "pkg:npm/socks@2.3.3?package-id=df90bddac1fc2e9b",
378365          "supplier": {},
378366          "author": "Josh Glazebrook",
378367          "name": "socks",
378368          "version": "2.3.3",
378369          "description": "Fully featured SOCKS proxy client supporting SOCKSv4, SOCKSv4a, and SOCKSv5. Includes Bind and Associate functionality.",
378370          "licenses": [
378371            {
378372              "license": {
378373                "id": "MIT"
378374              }
378375            }
378376          ],
378377          "cpe": "cpe:2.3:a:JoshGlazebrook:socks:2.3.3:*:*:*:*:*:*:*",
378378          "purl": "pkg:npm/socks@2.3.3",
378379          "swid": {
378380            "attachment": {}
378381          },
378382          "pedigree": {},
378383          "externalReferences": [
378384            {
378385              "url": "git+https://github.com/JoshGlazebrook/socks.git",
378386              "type": "distribution"
378387            },
378388            {
378389              "url": "https://github.com/JoshGlazebrook/socks/",
378390              "type": "website"
378391            }
378392          ],
378393          "evidence": {},
378394          "signature": {
378395            "signature": {
378396              "publicKey": {}
378397            }
378398          },
378399          "modelCard": {
378400            "modelParameters": {
378401              "approach": {}
378402            },
378403            "quantitativeAnalysis": {
378404              "graphics": {}
378405            },
378406            "considerations": {}
378407          }
378408        },
378409        {
378410          "type": "library",
378411          "bom-ref": "pkg:npm/socks-proxy-agent@4.0.2?package-id=467552ce30535bfb",
378412          "supplier": {},
378413          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
378414          "name": "socks-proxy-agent",
378415          "version": "4.0.2",
378416          "description": "A SOCKS proxy `http.Agent` implementation for HTTP and HTTPS",
378417          "licenses": [
378418            {
378419              "license": {
378420                "id": "MIT"
378421              }
378422            }
378423          ],
378424          "cpe": "cpe:2.3:a:socks-proxy-agent:socks-proxy-agent:4.0.2:*:*:*:*:*:*:*",
378425          "purl": "pkg:npm/socks-proxy-agent@4.0.2",
378426          "swid": {
378427            "attachment": {}
378428          },
378429          "pedigree": {},
378430          "externalReferences": [
378431            {
378432              "url": "git://github.com/TooTallNate/node-socks-proxy-agent.git",
378433              "type": "distribution"
378434            },
378435            {
378436              "url": "https://github.com/TooTallNate/node-socks-proxy-agent#readme",
378437              "type": "website"
378438            }
378439          ],
378440          "evidence": {},
378441          "signature": {
378442            "signature": {
378443              "publicKey": {}
378444            }
378445          },
378446          "modelCard": {
378447            "modelParameters": {
378448              "approach": {}
378449            },
378450            "quantitativeAnalysis": {
378451              "graphics": {}
378452            },
378453            "considerations": {}
378454          }
378455        },
378456        {
378457          "type": "library",
378458          "bom-ref": "pkg:npm/sorted-object@2.0.1?package-id=b1d8024e52e50f32",
378459          "supplier": {},
378460          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me/)",
378461          "name": "sorted-object",
378462          "version": "2.0.1",
378463          "description": "Returns a copy of an object with its keys sorted",
378464          "licenses": [
378465            {
378466              "license": {
378467                "name": "(WTFPL OR MIT)"
378468              }
378469            }
378470          ],
378471          "cpe": "cpe:2.3:a:sorted-object:sorted-object:2.0.1:*:*:*:*:*:*:*",
378472          "purl": "pkg:npm/sorted-object@2.0.1",
378473          "swid": {
378474            "attachment": {}
378475          },
378476          "pedigree": {},
378477          "externalReferences": [
378478            {
378479              "url": "git+https://github.com/domenic/sorted-object.git",
378480              "type": "distribution"
378481            },
378482            {
378483              "url": "https://github.com/domenic/sorted-object#readme",
378484              "type": "website"
378485            }
378486          ],
378487          "evidence": {},
378488          "signature": {
378489            "signature": {
378490              "publicKey": {}
378491            }
378492          },
378493          "modelCard": {
378494            "modelParameters": {
378495              "approach": {}
378496            },
378497            "quantitativeAnalysis": {
378498              "graphics": {}
378499            },
378500            "considerations": {}
378501          }
378502        },
378503        {
378504          "type": "library",
378505          "bom-ref": "pkg:npm/sorted-union-stream@2.1.3?package-id=6fde9400f65d4713",
378506          "supplier": {},
378507          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
378508          "name": "sorted-union-stream",
378509          "version": "2.1.3",
378510          "description": "Get the union of two sorted streams",
378511          "licenses": [
378512            {
378513              "license": {
378514                "id": "MIT"
378515              }
378516            }
378517          ],
378518          "cpe": "cpe:2.3:a:sorted-union-stream:sorted-union-stream:2.1.3:*:*:*:*:*:*:*",
378519          "purl": "pkg:npm/sorted-union-stream@2.1.3",
378520          "swid": {
378521            "attachment": {}
378522          },
378523          "pedigree": {},
378524          "externalReferences": [
378525            {
378526              "url": "git://github.com/mafintosh/sorted-union-stream.git",
378527              "type": "distribution"
378528            },
378529            {
378530              "url": "https://github.com/mafintosh/sorted-union-stream",
378531              "type": "website"
378532            }
378533          ],
378534          "evidence": {},
378535          "signature": {
378536            "signature": {
378537              "publicKey": {}
378538            }
378539          },
378540          "modelCard": {
378541            "modelParameters": {
378542              "approach": {}
378543            },
378544            "quantitativeAnalysis": {
378545              "graphics": {}
378546            },
378547            "considerations": {}
378548          }
378549        },
378550        {
378551          "type": "library",
378552          "bom-ref": "pkg:npm/spdx-correct@3.0.0?package-id=73531364f1007a1",
378553          "supplier": {},
378554          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
378555          "name": "spdx-correct",
378556          "version": "3.0.0",
378557          "description": "correct invalid SPDX expressions",
378558          "licenses": [
378559            {
378560              "license": {
378561                "id": "Apache-2.0"
378562              }
378563            }
378564          ],
378565          "cpe": "cpe:2.3:a:spdx-correct:spdx-correct:3.0.0:*:*:*:*:*:*:*",
378566          "purl": "pkg:npm/spdx-correct@3.0.0",
378567          "swid": {
378568            "attachment": {}
378569          },
378570          "pedigree": {},
378571          "externalReferences": [
378572            {
378573              "url": "git+https://github.com/jslicense/spdx-correct.js.git",
378574              "type": "distribution"
378575            },
378576            {
378577              "url": "https://github.com/jslicense/spdx-correct.js#readme",
378578              "type": "website"
378579            }
378580          ],
378581          "evidence": {},
378582          "signature": {
378583            "signature": {
378584              "publicKey": {}
378585            }
378586          },
378587          "modelCard": {
378588            "modelParameters": {
378589              "approach": {}
378590            },
378591            "quantitativeAnalysis": {
378592              "graphics": {}
378593            },
378594            "considerations": {}
378595          }
378596        },
378597        {
378598          "type": "library",
378599          "bom-ref": "pkg:npm/spdx-exceptions@2.1.0?package-id=1e5a7f3e71a3aea6",
378600          "supplier": {},
378601          "author": "The Linux Foundation",
378602          "name": "spdx-exceptions",
378603          "version": "2.1.0",
378604          "description": "list of SPDX standard license exceptions",
378605          "licenses": [
378606            {
378607              "license": {
378608                "id": "CC-BY-3.0"
378609              }
378610            }
378611          ],
378612          "cpe": "cpe:2.3:a:spdx-exceptions:spdx-exceptions:2.1.0:*:*:*:*:*:*:*",
378613          "purl": "pkg:npm/spdx-exceptions@2.1.0",
378614          "swid": {
378615            "attachment": {}
378616          },
378617          "pedigree": {},
378618          "externalReferences": [
378619            {
378620              "url": "git+https://github.com/kemitchell/spdx-exceptions.json.git",
378621              "type": "distribution"
378622            },
378623            {
378624              "url": "https://github.com/kemitchell/spdx-exceptions.json#readme",
378625              "type": "website"
378626            }
378627          ],
378628          "evidence": {},
378629          "signature": {
378630            "signature": {
378631              "publicKey": {}
378632            }
378633          },
378634          "modelCard": {
378635            "modelParameters": {
378636              "approach": {}
378637            },
378638            "quantitativeAnalysis": {
378639              "graphics": {}
378640            },
378641            "considerations": {}
378642          }
378643        },
378644        {
378645          "type": "library",
378646          "bom-ref": "pkg:npm/spdx-expression-parse@3.0.0?package-id=71a0de12075b58c5",
378647          "supplier": {},
378648          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (http://kemitchell.com)",
378649          "name": "spdx-expression-parse",
378650          "version": "3.0.0",
378651          "description": "parse SPDX license expressions",
378652          "licenses": [
378653            {
378654              "license": {
378655                "id": "MIT"
378656              }
378657            }
378658          ],
378659          "cpe": "cpe:2.3:a:spdx-expression-parse:spdx-expression-parse:3.0.0:*:*:*:*:*:*:*",
378660          "purl": "pkg:npm/spdx-expression-parse@3.0.0",
378661          "swid": {
378662            "attachment": {}
378663          },
378664          "pedigree": {},
378665          "externalReferences": [
378666            {
378667              "url": "git+https://github.com/jslicense/spdx-expression-parse.js.git",
378668              "type": "distribution"
378669            },
378670            {
378671              "url": "https://github.com/jslicense/spdx-expression-parse.js#readme",
378672              "type": "website"
378673            }
378674          ],
378675          "evidence": {},
378676          "signature": {
378677            "signature": {
378678              "publicKey": {}
378679            }
378680          },
378681          "modelCard": {
378682            "modelParameters": {
378683              "approach": {}
378684            },
378685            "quantitativeAnalysis": {
378686              "graphics": {}
378687            },
378688            "considerations": {}
378689          }
378690        },
378691        {
378692          "type": "library",
378693          "bom-ref": "pkg:npm/spdx-license-ids@3.0.5?package-id=1138941acd86a408",
378694          "supplier": {},
378695          "author": "Shinnosuke Watanabe (https://github.com/shinnn)",
378696          "name": "spdx-license-ids",
378697          "version": "3.0.5",
378698          "description": "A list of SPDX license identifiers",
378699          "licenses": [
378700            {
378701              "license": {
378702                "id": "CC0-1.0"
378703              }
378704            }
378705          ],
378706          "cpe": "cpe:2.3:a:spdx-license-ids:spdx-license-ids:3.0.5:*:*:*:*:*:*:*",
378707          "purl": "pkg:npm/spdx-license-ids@3.0.5",
378708          "swid": {
378709            "attachment": {}
378710          },
378711          "pedigree": {},
378712          "externalReferences": [
378713            {
378714              "url": "git+https://github.com/shinnn/spdx-license-ids.git",
378715              "type": "distribution"
378716            },
378717            {
378718              "url": "https://github.com/shinnn/spdx-license-ids#readme",
378719              "type": "website"
378720            }
378721          ],
378722          "evidence": {},
378723          "signature": {
378724            "signature": {
378725              "publicKey": {}
378726            }
378727          },
378728          "modelCard": {
378729            "modelParameters": {
378730              "approach": {}
378731            },
378732            "quantitativeAnalysis": {
378733              "graphics": {}
378734            },
378735            "considerations": {}
378736          }
378737        },
378738        {
378739          "type": "library",
378740          "bom-ref": "pkg:npm/split-on-first@1.1.0?package-id=a53cafaea7f6944b",
378741          "supplier": {},
378742          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
378743          "name": "split-on-first",
378744          "version": "1.1.0",
378745          "description": "Split a string on the first occurance of a given separator",
378746          "licenses": [
378747            {
378748              "license": {
378749                "id": "MIT"
378750              }
378751            }
378752          ],
378753          "cpe": "cpe:2.3:a:split-on-first:split-on-first:1.1.0:*:*:*:*:*:*:*",
378754          "purl": "pkg:npm/split-on-first@1.1.0",
378755          "swid": {
378756            "attachment": {}
378757          },
378758          "pedigree": {},
378759          "externalReferences": [
378760            {
378761              "url": "git+https://github.com/sindresorhus/split-on-first.git",
378762              "type": "distribution"
378763            },
378764            {
378765              "url": "https://github.com/sindresorhus/split-on-first#readme",
378766              "type": "website"
378767            }
378768          ],
378769          "evidence": {},
378770          "signature": {
378771            "signature": {
378772              "publicKey": {}
378773            }
378774          },
378775          "modelCard": {
378776            "modelParameters": {
378777              "approach": {}
378778            },
378779            "quantitativeAnalysis": {
378780              "graphics": {}
378781            },
378782            "considerations": {}
378783          }
378784        },
378785        {
378786          "type": "library",
378787          "bom-ref": "pkg:npm/sshpk@1.16.1?package-id=8591094f2543bcad",
378788          "supplier": {},
378789          "author": "Joyent, Inc",
378790          "name": "sshpk",
378791          "version": "1.16.1",
378792          "description": "A library for finding and using SSH public keys",
378793          "licenses": [
378794            {
378795              "license": {
378796                "id": "MIT"
378797              }
378798            }
378799          ],
378800          "cpe": "cpe:2.3:a:arekinath:sshpk:1.16.1:*:*:*:*:*:*:*",
378801          "purl": "pkg:npm/sshpk@1.16.1",
378802          "swid": {
378803            "attachment": {}
378804          },
378805          "pedigree": {},
378806          "externalReferences": [
378807            {
378808              "url": "git+https://github.com/joyent/node-sshpk.git",
378809              "type": "distribution"
378810            },
378811            {
378812              "url": "https://github.com/arekinath/node-sshpk#readme",
378813              "type": "website"
378814            }
378815          ],
378816          "evidence": {},
378817          "signature": {
378818            "signature": {
378819              "publicKey": {}
378820            }
378821          },
378822          "modelCard": {
378823            "modelParameters": {
378824              "approach": {}
378825            },
378826            "quantitativeAnalysis": {
378827              "graphics": {}
378828            },
378829            "considerations": {}
378830          }
378831        },
378832        {
378833          "type": "library",
378834          "bom-ref": "pkg:npm/sshpk@1.17.0?package-id=6729e05d3acb693f",
378835          "supplier": {},
378836          "author": "Joyent, Inc",
378837          "name": "sshpk",
378838          "version": "1.17.0",
378839          "description": "A library for finding and using SSH public keys",
378840          "licenses": [
378841            {
378842              "license": {
378843                "id": "MIT"
378844              }
378845            }
378846          ],
378847          "cpe": "cpe:2.3:a:arekinath:sshpk:1.17.0:*:*:*:*:*:*:*",
378848          "purl": "pkg:npm/sshpk@1.17.0",
378849          "swid": {
378850            "attachment": {}
378851          },
378852          "pedigree": {},
378853          "externalReferences": [
378854            {
378855              "url": "git+https://github.com/joyent/node-sshpk.git",
378856              "type": "distribution"
378857            },
378858            {
378859              "url": "https://github.com/arekinath/node-sshpk#readme",
378860              "type": "website"
378861            }
378862          ],
378863          "evidence": {},
378864          "signature": {
378865            "signature": {
378866              "publicKey": {}
378867            }
378868          },
378869          "modelCard": {
378870            "modelParameters": {
378871              "approach": {}
378872            },
378873            "quantitativeAnalysis": {
378874              "graphics": {}
378875            },
378876            "considerations": {}
378877          }
378878        },
378879        {
378880          "type": "library",
378881          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3\u0026package-id=b15247aafcd4a647",
378882          "supplier": {},
378883          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
378884          "name": "ssl_client",
378885          "version": "1.35.0-r29",
378886          "description": "EXternal ssl_client for busybox wget",
378887          "licenses": [
378888            {
378889              "license": {
378890                "id": "GPL-2.0-only"
378891              }
378892            }
378893          ],
378894          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r29:*:*:*:*:*:*:*",
378895          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r29?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.17.3",
378896          "swid": {
378897            "attachment": {}
378898          },
378899          "pedigree": {},
378900          "externalReferences": [
378901            {
378902              "url": "https://busybox.net/",
378903              "type": "distribution"
378904            }
378905          ],
378906          "evidence": {},
378907          "signature": {
378908            "signature": {
378909              "publicKey": {}
378910            }
378911          },
378912          "modelCard": {
378913            "modelParameters": {
378914              "approach": {}
378915            },
378916            "quantitativeAnalysis": {
378917              "graphics": {}
378918            },
378919            "considerations": {}
378920          }
378921        },
378922        {
378923          "type": "library",
378924          "bom-ref": "pkg:npm/ssri@6.0.2?package-id=739aca50718ed16c",
378925          "supplier": {},
378926          "author": "Kat Marchán \u003ckzm@sykosomatic.org\u003e",
378927          "name": "ssri",
378928          "version": "6.0.2",
378929          "description": "Standard Subresource Integrity library --  parses, serializes, generates, and verifies integrity metadata according to the SRI spec.",
378930          "licenses": [
378931            {
378932              "license": {
378933                "id": "ISC"
378934              }
378935            }
378936          ],
378937          "cpe": "cpe:2.3:a:ssri:ssri:6.0.2:*:*:*:*:*:*:*",
378938          "purl": "pkg:npm/ssri@6.0.2",
378939          "swid": {
378940            "attachment": {}
378941          },
378942          "pedigree": {},
378943          "externalReferences": [
378944            {
378945              "url": "git+https://github.com/zkat/ssri.git",
378946              "type": "distribution"
378947            },
378948            {
378949              "url": "https://github.com/zkat/ssri#readme",
378950              "type": "website"
378951            }
378952          ],
378953          "evidence": {},
378954          "signature": {
378955            "signature": {
378956              "publicKey": {}
378957            }
378958          },
378959          "modelCard": {
378960            "modelParameters": {
378961              "approach": {}
378962            },
378963            "quantitativeAnalysis": {
378964              "graphics": {}
378965            },
378966            "considerations": {}
378967          }
378968        },
378969        {
378970          "type": "library",
378971          "bom-ref": "pkg:npm/statuses@1.5.0?package-id=7880c86343c91f02",
378972          "supplier": {},
378973          "name": "statuses",
378974          "version": "1.5.0",
378975          "description": "HTTP status utility",
378976          "licenses": [
378977            {
378978              "license": {
378979                "id": "MIT"
378980              }
378981            }
378982          ],
378983          "cpe": "cpe:2.3:a:statuses:statuses:1.5.0:*:*:*:*:*:*:*",
378984          "purl": "pkg:npm/statuses@1.5.0",
378985          "swid": {
378986            "attachment": {}
378987          },
378988          "pedigree": {},
378989          "externalReferences": [
378990            {
378991              "url": "git+https://github.com/jshttp/statuses.git",
378992              "type": "distribution"
378993            },
378994            {
378995              "url": "https://github.com/jshttp/statuses#readme",
378996              "type": "website"
378997            }
378998          ],
378999          "evidence": {},
379000          "signature": {
379001            "signature": {
379002              "publicKey": {}
379003            }
379004          },
379005          "modelCard": {
379006            "modelParameters": {
379007              "approach": {}
379008            },
379009            "quantitativeAnalysis": {
379010              "graphics": {}
379011            },
379012            "considerations": {}
379013          }
379014        },
379015        {
379016          "type": "library",
379017          "bom-ref": "pkg:npm/stealthy-require@1.1.1?package-id=c9d362abc885b44",
379018          "supplier": {},
379019          "author": "Nicolai Kamenzky (https://github.com/analog-nico)",
379020          "name": "stealthy-require",
379021          "version": "1.1.1",
379022          "description": "The closest you can get to require something with bypassing the require cache",
379023          "licenses": [
379024            {
379025              "license": {
379026                "id": "ISC"
379027              }
379028            }
379029          ],
379030          "cpe": "cpe:2.3:a:stealthy-require:stealthy-require:1.1.1:*:*:*:*:*:*:*",
379031          "purl": "pkg:npm/stealthy-require@1.1.1",
379032          "swid": {
379033            "attachment": {}
379034          },
379035          "pedigree": {},
379036          "externalReferences": [
379037            {
379038              "url": "git+https://github.com/analog-nico/stealthy-require.git",
379039              "type": "distribution"
379040            },
379041            {
379042              "url": "https://github.com/analog-nico/stealthy-require#readme",
379043              "type": "website"
379044            }
379045          ],
379046          "evidence": {},
379047          "signature": {
379048            "signature": {
379049              "publicKey": {}
379050            }
379051          },
379052          "modelCard": {
379053            "modelParameters": {
379054              "approach": {}
379055            },
379056            "quantitativeAnalysis": {
379057              "graphics": {}
379058            },
379059            "considerations": {}
379060          }
379061        },
379062        {
379063          "type": "library",
379064          "bom-ref": "pkg:npm/stream-each@1.2.2?package-id=ff21dffb4b08347c",
379065          "supplier": {},
379066          "author": "Mathias Buus (@mafintosh)",
379067          "name": "stream-each",
379068          "version": "1.2.2",
379069          "description": "Iterate all the data in a stream",
379070          "licenses": [
379071            {
379072              "license": {
379073                "id": "MIT"
379074              }
379075            }
379076          ],
379077          "cpe": "cpe:2.3:a:stream-each:stream-each:1.2.2:*:*:*:*:*:*:*",
379078          "purl": "pkg:npm/stream-each@1.2.2",
379079          "swid": {
379080            "attachment": {}
379081          },
379082          "pedigree": {},
379083          "externalReferences": [
379084            {
379085              "url": "git+https://github.com/mafintosh/stream-each.git",
379086              "type": "distribution"
379087            },
379088            {
379089              "url": "https://github.com/mafintosh/stream-each",
379090              "type": "website"
379091            }
379092          ],
379093          "evidence": {},
379094          "signature": {
379095            "signature": {
379096              "publicKey": {}
379097            }
379098          },
379099          "modelCard": {
379100            "modelParameters": {
379101              "approach": {}
379102            },
379103            "quantitativeAnalysis": {
379104              "graphics": {}
379105            },
379106            "considerations": {}
379107          }
379108        },
379109        {
379110          "type": "library",
379111          "bom-ref": "pkg:npm/stream-iterate@1.2.0?package-id=45645dfa25e969e7",
379112          "supplier": {},
379113          "author": "Mathias Buus (@mafintosh)",
379114          "name": "stream-iterate",
379115          "version": "1.2.0",
379116          "description": "Iterate through the values of a stream",
379117          "licenses": [
379118            {
379119              "license": {
379120                "id": "MIT"
379121              }
379122            }
379123          ],
379124          "cpe": "cpe:2.3:a:stream-iterate:stream-iterate:1.2.0:*:*:*:*:*:*:*",
379125          "purl": "pkg:npm/stream-iterate@1.2.0",
379126          "swid": {
379127            "attachment": {}
379128          },
379129          "pedigree": {},
379130          "externalReferences": [
379131            {
379132              "url": "git+https://github.com/mafintosh/stream-iterate.git",
379133              "type": "distribution"
379134            },
379135            {
379136              "url": "https://github.com/mafintosh/stream-iterate",
379137              "type": "website"
379138            }
379139          ],
379140          "evidence": {},
379141          "signature": {
379142            "signature": {
379143              "publicKey": {}
379144            }
379145          },
379146          "modelCard": {
379147            "modelParameters": {
379148              "approach": {}
379149            },
379150            "quantitativeAnalysis": {
379151              "graphics": {}
379152            },
379153            "considerations": {}
379154          }
379155        },
379156        {
379157          "type": "library",
379158          "bom-ref": "pkg:npm/stream-shift@1.0.0?package-id=e058037128eb4cc1",
379159          "supplier": {},
379160          "author": "Mathias Buus (@mafintosh)",
379161          "name": "stream-shift",
379162          "version": "1.0.0",
379163          "description": "Returns the next buffer/object in a stream's readable queue",
379164          "licenses": [
379165            {
379166              "license": {
379167                "id": "MIT"
379168              }
379169            }
379170          ],
379171          "cpe": "cpe:2.3:a:stream-shift:stream-shift:1.0.0:*:*:*:*:*:*:*",
379172          "purl": "pkg:npm/stream-shift@1.0.0",
379173          "swid": {
379174            "attachment": {}
379175          },
379176          "pedigree": {},
379177          "externalReferences": [
379178            {
379179              "url": "git+https://github.com/mafintosh/stream-shift.git",
379180              "type": "distribution"
379181            },
379182            {
379183              "url": "https://github.com/mafintosh/stream-shift",
379184              "type": "website"
379185            }
379186          ],
379187          "evidence": {},
379188          "signature": {
379189            "signature": {
379190              "publicKey": {}
379191            }
379192          },
379193          "modelCard": {
379194            "modelParameters": {
379195              "approach": {}
379196            },
379197            "quantitativeAnalysis": {
379198              "graphics": {}
379199            },
379200            "considerations": {}
379201          }
379202        },
379203        {
379204          "type": "library",
379205          "bom-ref": "pkg:npm/streamsearch@0.1.2?package-id=900089132d0d8437",
379206          "supplier": {},
379207          "author": "Brian White \u003cmscdex@mscdex.net\u003e",
379208          "name": "streamsearch",
379209          "version": "0.1.2",
379210          "description": "Streaming Boyer-Moore-Horspool searching for node.js",
379211          "licenses": [
379212            {
379213              "license": {
379214                "id": "MIT"
379215              }
379216            }
379217          ],
379218          "cpe": "cpe:2.3:a:streamsearch:streamsearch:0.1.2:*:*:*:*:*:*:*",
379219          "purl": "pkg:npm/streamsearch@0.1.2",
379220          "swid": {
379221            "attachment": {}
379222          },
379223          "pedigree": {},
379224          "externalReferences": [
379225            {
379226              "url": "git+ssh://git@github.com/mscdex/streamsearch.git",
379227              "type": "distribution"
379228            },
379229            {
379230              "url": "https://github.com/mscdex/streamsearch#readme",
379231              "type": "website"
379232            }
379233          ],
379234          "evidence": {},
379235          "signature": {
379236            "signature": {
379237              "publicKey": {}
379238            }
379239          },
379240          "modelCard": {
379241            "modelParameters": {
379242              "approach": {}
379243            },
379244            "quantitativeAnalysis": {
379245              "graphics": {}
379246            },
379247            "considerations": {}
379248          }
379249        },
379250        {
379251          "type": "library",
379252          "bom-ref": "pkg:npm/strict-uri-encode@2.0.0?package-id=8d1313eb6c7e50c6",
379253          "supplier": {},
379254          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
379255          "name": "strict-uri-encode",
379256          "version": "2.0.0",
379257          "description": "A stricter URI encode adhering to RFC 3986",
379258          "licenses": [
379259            {
379260              "license": {
379261                "id": "MIT"
379262              }
379263            }
379264          ],
379265          "cpe": "cpe:2.3:a:strict-uri-encode:strict-uri-encode:2.0.0:*:*:*:*:*:*:*",
379266          "purl": "pkg:npm/strict-uri-encode@2.0.0",
379267          "swid": {
379268            "attachment": {}
379269          },
379270          "pedigree": {},
379271          "externalReferences": [
379272            {
379273              "url": "git+https://github.com/kevva/strict-uri-encode.git",
379274              "type": "distribution"
379275            },
379276            {
379277              "url": "https://github.com/kevva/strict-uri-encode#readme",
379278              "type": "website"
379279            }
379280          ],
379281          "evidence": {},
379282          "signature": {
379283            "signature": {
379284              "publicKey": {}
379285            }
379286          },
379287          "modelCard": {
379288            "modelParameters": {
379289              "approach": {}
379290            },
379291            "quantitativeAnalysis": {
379292              "graphics": {}
379293            },
379294            "considerations": {}
379295          }
379296        },
379297        {
379298          "type": "library",
379299          "bom-ref": "pkg:npm/string-similarity@4.0.4?package-id=f621801ca083fcb1",
379300          "supplier": {},
379301          "author": "Akash Kurdekar \u003cnpm@kurdekar.com\u003e (http://untilfalse.com/)",
379302          "name": "string-similarity",
379303          "version": "4.0.4",
379304          "description": "Finds degree of similarity between strings, based on Dice's Coefficient, which is mostly better than Levenshtein distance.",
379305          "licenses": [
379306            {
379307              "license": {
379308                "id": "ISC"
379309              }
379310            }
379311          ],
379312          "cpe": "cpe:2.3:a:string-similarity:string-similarity:4.0.4:*:*:*:*:*:*:*",
379313          "purl": "pkg:npm/string-similarity@4.0.4",
379314          "swid": {
379315            "attachment": {}
379316          },
379317          "pedigree": {},
379318          "externalReferences": [
379319            {
379320              "url": "git://github.com/aceakash/string-similarity.git",
379321              "type": "distribution"
379322            },
379323            {
379324              "url": "https://github.com/aceakash/string-similarity#readme",
379325              "type": "website"
379326            }
379327          ],
379328          "evidence": {},
379329          "signature": {
379330            "signature": {
379331              "publicKey": {}
379332            }
379333          },
379334          "modelCard": {
379335            "modelParameters": {
379336              "approach": {}
379337            },
379338            "quantitativeAnalysis": {
379339              "graphics": {}
379340            },
379341            "considerations": {}
379342          }
379343        },
379344        {
379345          "type": "library",
379346          "bom-ref": "pkg:npm/string-width@1.0.2?package-id=f3fde1d1bb9d11bb",
379347          "supplier": {},
379348          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
379349          "name": "string-width",
379350          "version": "1.0.2",
379351          "description": "Get the visual width of a string - the number of columns required to display it",
379352          "licenses": [
379353            {
379354              "license": {
379355                "id": "MIT"
379356              }
379357            }
379358          ],
379359          "cpe": "cpe:2.3:a:sindresorhus:string-width:1.0.2:*:*:*:*:*:*:*",
379360          "purl": "pkg:npm/string-width@1.0.2",
379361          "swid": {
379362            "attachment": {}
379363          },
379364          "pedigree": {},
379365          "externalReferences": [
379366            {
379367              "url": "git+https://github.com/sindresorhus/string-width.git",
379368              "type": "distribution"
379369            },
379370            {
379371              "url": "https://github.com/sindresorhus/string-width#readme",
379372              "type": "website"
379373            }
379374          ],
379375          "evidence": {},
379376          "signature": {
379377            "signature": {
379378              "publicKey": {}
379379            }
379380          },
379381          "modelCard": {
379382            "modelParameters": {
379383              "approach": {}
379384            },
379385            "quantitativeAnalysis": {
379386              "graphics": {}
379387            },
379388            "considerations": {}
379389          }
379390        },
379391        {
379392          "type": "library",
379393          "bom-ref": "pkg:npm/string-width@1.0.2?package-id=aad7726ab13feca",
379394          "supplier": {},
379395          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
379396          "name": "string-width",
379397          "version": "1.0.2",
379398          "description": "Get the visual width of a string - the number of columns required to display it",
379399          "licenses": [
379400            {
379401              "license": {
379402                "id": "MIT"
379403              }
379404            }
379405          ],
379406          "cpe": "cpe:2.3:a:sindresorhus:string-width:1.0.2:*:*:*:*:*:*:*",
379407          "purl": "pkg:npm/string-width@1.0.2",
379408          "swid": {
379409            "attachment": {}
379410          },
379411          "pedigree": {},
379412          "externalReferences": [
379413            {
379414              "url": "git+https://github.com/sindresorhus/string-width.git",
379415              "type": "distribution"
379416            },
379417            {
379418              "url": "https://github.com/sindresorhus/string-width#readme",
379419              "type": "website"
379420            }
379421          ],
379422          "evidence": {},
379423          "signature": {
379424            "signature": {
379425              "publicKey": {}
379426            }
379427          },
379428          "modelCard": {
379429            "modelParameters": {
379430              "approach": {}
379431            },
379432            "quantitativeAnalysis": {
379433              "graphics": {}
379434            },
379435            "considerations": {}
379436          }
379437        },
379438        {
379439          "type": "library",
379440          "bom-ref": "pkg:npm/string-width@2.1.1?package-id=aa7b698cf21b3eed",
379441          "supplier": {},
379442          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
379443          "name": "string-width",
379444          "version": "2.1.1",
379445          "description": "Get the visual width of a string - the number of columns required to display it",
379446          "licenses": [
379447            {
379448              "license": {
379449                "id": "MIT"
379450              }
379451            }
379452          ],
379453          "cpe": "cpe:2.3:a:sindresorhus:string-width:2.1.1:*:*:*:*:*:*:*",
379454          "purl": "pkg:npm/string-width@2.1.1",
379455          "swid": {
379456            "attachment": {}
379457          },
379458          "pedigree": {},
379459          "externalReferences": [
379460            {
379461              "url": "git+https://github.com/sindresorhus/string-width.git",
379462              "type": "distribution"
379463            },
379464            {
379465              "url": "https://github.com/sindresorhus/string-width#readme",
379466              "type": "website"
379467            }
379468          ],
379469          "evidence": {},
379470          "signature": {
379471            "signature": {
379472              "publicKey": {}
379473            }
379474          },
379475          "modelCard": {
379476            "modelParameters": {
379477              "approach": {}
379478            },
379479            "quantitativeAnalysis": {
379480              "graphics": {}
379481            },
379482            "considerations": {}
379483          }
379484        },
379485        {
379486          "type": "library",
379487          "bom-ref": "pkg:npm/string-width@3.1.0?package-id=87790d6cb608b04c",
379488          "supplier": {},
379489          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
379490          "name": "string-width",
379491          "version": "3.1.0",
379492          "description": "Get the visual width of a string - the number of columns required to display it",
379493          "licenses": [
379494            {
379495              "license": {
379496                "id": "MIT"
379497              }
379498            }
379499          ],
379500          "cpe": "cpe:2.3:a:sindresorhus:string-width:3.1.0:*:*:*:*:*:*:*",
379501          "purl": "pkg:npm/string-width@3.1.0",
379502          "swid": {
379503            "attachment": {}
379504          },
379505          "pedigree": {},
379506          "externalReferences": [
379507            {
379508              "url": "git+https://github.com/sindresorhus/string-width.git",
379509              "type": "distribution"
379510            },
379511            {
379512              "url": "https://github.com/sindresorhus/string-width#readme",
379513              "type": "website"
379514            }
379515          ],
379516          "evidence": {},
379517          "signature": {
379518            "signature": {
379519              "publicKey": {}
379520            }
379521          },
379522          "modelCard": {
379523            "modelParameters": {
379524              "approach": {}
379525            },
379526            "quantitativeAnalysis": {
379527              "graphics": {}
379528            },
379529            "considerations": {}
379530          }
379531        },
379532        {
379533          "type": "library",
379534          "bom-ref": "pkg:npm/string-width@3.1.0?package-id=12bb72b3585d56cb",
379535          "supplier": {},
379536          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
379537          "name": "string-width",
379538          "version": "3.1.0",
379539          "description": "Get the visual width of a string - the number of columns required to display it",
379540          "licenses": [
379541            {
379542              "license": {
379543                "id": "MIT"
379544              }
379545            }
379546          ],
379547          "cpe": "cpe:2.3:a:sindresorhus:string-width:3.1.0:*:*:*:*:*:*:*",
379548          "purl": "pkg:npm/string-width@3.1.0",
379549          "swid": {
379550            "attachment": {}
379551          },
379552          "pedigree": {},
379553          "externalReferences": [
379554            {
379555              "url": "git+https://github.com/sindresorhus/string-width.git",
379556              "type": "distribution"
379557            },
379558            {
379559              "url": "https://github.com/sindresorhus/string-width#readme",
379560              "type": "website"
379561            }
379562          ],
379563          "evidence": {},
379564          "signature": {
379565            "signature": {
379566              "publicKey": {}
379567            }
379568          },
379569          "modelCard": {
379570            "modelParameters": {
379571              "approach": {}
379572            },
379573            "quantitativeAnalysis": {
379574              "graphics": {}
379575            },
379576            "considerations": {}
379577          }
379578        },
379579        {
379580          "type": "library",
379581          "bom-ref": "pkg:npm/string-width@3.1.0?package-id=55af5077fbd273b",
379582          "supplier": {},
379583          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
379584          "name": "string-width",
379585          "version": "3.1.0",
379586          "description": "Get the visual width of a string - the number of columns required to display it",
379587          "licenses": [
379588            {
379589              "license": {
379590                "id": "MIT"
379591              }
379592            }
379593          ],
379594          "cpe": "cpe:2.3:a:sindresorhus:string-width:3.1.0:*:*:*:*:*:*:*",
379595          "purl": "pkg:npm/string-width@3.1.0",
379596          "swid": {
379597            "attachment": {}
379598          },
379599          "pedigree": {},
379600          "externalReferences": [
379601            {
379602              "url": "git+https://github.com/sindresorhus/string-width.git",
379603              "type": "distribution"
379604            },
379605            {
379606              "url": "https://github.com/sindresorhus/string-width#readme",
379607              "type": "website"
379608            }
379609          ],
379610          "evidence": {},
379611          "signature": {
379612            "signature": {
379613              "publicKey": {}
379614            }
379615          },
379616          "modelCard": {
379617            "modelParameters": {
379618              "approach": {}
379619            },
379620            "quantitativeAnalysis": {
379621              "graphics": {}
379622            },
379623            "considerations": {}
379624          }
379625        },
379626        {
379627          "type": "library",
379628          "bom-ref": "pkg:npm/string_decoder@0.10.31?package-id=842458f1d210431a",
379629          "supplier": {},
379630          "name": "string_decoder",
379631          "version": "0.10.31",
379632          "description": "The string_decoder module from Node core",
379633          "licenses": [
379634            {
379635              "license": {
379636                "id": "MIT"
379637              }
379638            }
379639          ],
379640          "cpe": "cpe:2.3:a:string-decoder:string-decoder:0.10.31:*:*:*:*:*:*:*",
379641          "purl": "pkg:npm/string_decoder@0.10.31",
379642          "swid": {
379643            "attachment": {}
379644          },
379645          "pedigree": {},
379646          "externalReferences": [
379647            {
379648              "url": "git://github.com/rvagg/string_decoder.git",
379649              "type": "distribution"
379650            },
379651            {
379652              "url": "https://github.com/rvagg/string_decoder",
379653              "type": "website"
379654            }
379655          ],
379656          "evidence": {},
379657          "signature": {
379658            "signature": {
379659              "publicKey": {}
379660            }
379661          },
379662          "modelCard": {
379663            "modelParameters": {
379664              "approach": {}
379665            },
379666            "quantitativeAnalysis": {
379667              "graphics": {}
379668            },
379669            "considerations": {}
379670          }
379671        },
379672        {
379673          "type": "library",
379674          "bom-ref": "pkg:npm/string_decoder@0.10.31?package-id=b225c432d9e6b500",
379675          "supplier": {},
379676          "name": "string_decoder",
379677          "version": "0.10.31",
379678          "description": "The string_decoder module from Node core",
379679          "licenses": [
379680            {
379681              "license": {
379682                "id": "MIT"
379683              }
379684            }
379685          ],
379686          "cpe": "cpe:2.3:a:string-decoder:string-decoder:0.10.31:*:*:*:*:*:*:*",
379687          "purl": "pkg:npm/string_decoder@0.10.31",
379688          "swid": {
379689            "attachment": {}
379690          },
379691          "pedigree": {},
379692          "externalReferences": [
379693            {
379694              "url": "git://github.com/rvagg/string_decoder.git",
379695              "type": "distribution"
379696            },
379697            {
379698              "url": "https://github.com/rvagg/string_decoder",
379699              "type": "website"
379700            }
379701          ],
379702          "evidence": {},
379703          "signature": {
379704            "signature": {
379705              "publicKey": {}
379706            }
379707          },
379708          "modelCard": {
379709            "modelParameters": {
379710              "approach": {}
379711            },
379712            "quantitativeAnalysis": {
379713              "graphics": {}
379714            },
379715            "considerations": {}
379716          }
379717        },
379718        {
379719          "type": "library",
379720          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=a6eeeaeb8b6353ea",
379721          "supplier": {},
379722          "name": "string_decoder",
379723          "version": "1.1.1",
379724          "description": "The string_decoder module from Node core",
379725          "licenses": [
379726            {
379727              "license": {
379728                "id": "MIT"
379729              }
379730            }
379731          ],
379732          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
379733          "purl": "pkg:npm/string_decoder@1.1.1",
379734          "swid": {
379735            "attachment": {}
379736          },
379737          "pedigree": {},
379738          "externalReferences": [
379739            {
379740              "url": "git://github.com/nodejs/string_decoder.git",
379741              "type": "distribution"
379742            },
379743            {
379744              "url": "https://github.com/nodejs/string_decoder",
379745              "type": "website"
379746            }
379747          ],
379748          "evidence": {},
379749          "signature": {
379750            "signature": {
379751              "publicKey": {}
379752            }
379753          },
379754          "modelCard": {
379755            "modelParameters": {
379756              "approach": {}
379757            },
379758            "quantitativeAnalysis": {
379759              "graphics": {}
379760            },
379761            "considerations": {}
379762          }
379763        },
379764        {
379765          "type": "library",
379766          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=361d8a5e7e28d65b",
379767          "supplier": {},
379768          "name": "string_decoder",
379769          "version": "1.1.1",
379770          "description": "The string_decoder module from Node core",
379771          "licenses": [
379772            {
379773              "license": {
379774                "id": "MIT"
379775              }
379776            }
379777          ],
379778          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
379779          "purl": "pkg:npm/string_decoder@1.1.1",
379780          "swid": {
379781            "attachment": {}
379782          },
379783          "pedigree": {},
379784          "externalReferences": [
379785            {
379786              "url": "git://github.com/nodejs/string_decoder.git",
379787              "type": "distribution"
379788            },
379789            {
379790              "url": "https://github.com/nodejs/string_decoder",
379791              "type": "website"
379792            }
379793          ],
379794          "evidence": {},
379795          "signature": {
379796            "signature": {
379797              "publicKey": {}
379798            }
379799          },
379800          "modelCard": {
379801            "modelParameters": {
379802              "approach": {}
379803            },
379804            "quantitativeAnalysis": {
379805              "graphics": {}
379806            },
379807            "considerations": {}
379808          }
379809        },
379810        {
379811          "type": "library",
379812          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=6de5785db73e974c",
379813          "supplier": {},
379814          "name": "string_decoder",
379815          "version": "1.1.1",
379816          "description": "The string_decoder module from Node core",
379817          "licenses": [
379818            {
379819              "license": {
379820                "id": "MIT"
379821              }
379822            }
379823          ],
379824          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
379825          "purl": "pkg:npm/string_decoder@1.1.1",
379826          "swid": {
379827            "attachment": {}
379828          },
379829          "pedigree": {},
379830          "externalReferences": [
379831            {
379832              "url": "git://github.com/nodejs/string_decoder.git",
379833              "type": "distribution"
379834            },
379835            {
379836              "url": "https://github.com/nodejs/string_decoder",
379837              "type": "website"
379838            }
379839          ],
379840          "evidence": {},
379841          "signature": {
379842            "signature": {
379843              "publicKey": {}
379844            }
379845          },
379846          "modelCard": {
379847            "modelParameters": {
379848              "approach": {}
379849            },
379850            "quantitativeAnalysis": {
379851              "graphics": {}
379852            },
379853            "considerations": {}
379854          }
379855        },
379856        {
379857          "type": "library",
379858          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=64921df3b8583429",
379859          "supplier": {},
379860          "name": "string_decoder",
379861          "version": "1.1.1",
379862          "description": "The string_decoder module from Node core",
379863          "licenses": [
379864            {
379865              "license": {
379866                "id": "MIT"
379867              }
379868            }
379869          ],
379870          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
379871          "purl": "pkg:npm/string_decoder@1.1.1",
379872          "swid": {
379873            "attachment": {}
379874          },
379875          "pedigree": {},
379876          "externalReferences": [
379877            {
379878              "url": "git://github.com/nodejs/string_decoder.git",
379879              "type": "distribution"
379880            },
379881            {
379882              "url": "https://github.com/nodejs/string_decoder",
379883              "type": "website"
379884            }
379885          ],
379886          "evidence": {},
379887          "signature": {
379888            "signature": {
379889              "publicKey": {}
379890            }
379891          },
379892          "modelCard": {
379893            "modelParameters": {
379894              "approach": {}
379895            },
379896            "quantitativeAnalysis": {
379897              "graphics": {}
379898            },
379899            "considerations": {}
379900          }
379901        },
379902        {
379903          "type": "library",
379904          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=f7db62bc91e69852",
379905          "supplier": {},
379906          "name": "string_decoder",
379907          "version": "1.1.1",
379908          "description": "The string_decoder module from Node core",
379909          "licenses": [
379910            {
379911              "license": {
379912                "id": "MIT"
379913              }
379914            }
379915          ],
379916          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
379917          "purl": "pkg:npm/string_decoder@1.1.1",
379918          "swid": {
379919            "attachment": {}
379920          },
379921          "pedigree": {},
379922          "externalReferences": [
379923            {
379924              "url": "git://github.com/nodejs/string_decoder.git",
379925              "type": "distribution"
379926            },
379927            {
379928              "url": "https://github.com/nodejs/string_decoder",
379929              "type": "website"
379930            }
379931          ],
379932          "evidence": {},
379933          "signature": {
379934            "signature": {
379935              "publicKey": {}
379936            }
379937          },
379938          "modelCard": {
379939            "modelParameters": {
379940              "approach": {}
379941            },
379942            "quantitativeAnalysis": {
379943              "graphics": {}
379944            },
379945            "considerations": {}
379946          }
379947        },
379948        {
379949          "type": "library",
379950          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=44a4766f5469b746",
379951          "supplier": {},
379952          "name": "string_decoder",
379953          "version": "1.1.1",
379954          "description": "The string_decoder module from Node core",
379955          "licenses": [
379956            {
379957              "license": {
379958                "id": "MIT"
379959              }
379960            }
379961          ],
379962          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
379963          "purl": "pkg:npm/string_decoder@1.1.1",
379964          "swid": {
379965            "attachment": {}
379966          },
379967          "pedigree": {},
379968          "externalReferences": [
379969            {
379970              "url": "git://github.com/nodejs/string_decoder.git",
379971              "type": "distribution"
379972            },
379973            {
379974              "url": "https://github.com/nodejs/string_decoder",
379975              "type": "website"
379976            }
379977          ],
379978          "evidence": {},
379979          "signature": {
379980            "signature": {
379981              "publicKey": {}
379982            }
379983          },
379984          "modelCard": {
379985            "modelParameters": {
379986              "approach": {}
379987            },
379988            "quantitativeAnalysis": {
379989              "graphics": {}
379990            },
379991            "considerations": {}
379992          }
379993        },
379994        {
379995          "type": "library",
379996          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=2892cc6855d3777f",
379997          "supplier": {},
379998          "name": "string_decoder",
379999          "version": "1.1.1",
380000          "description": "The string_decoder module from Node core",
380001          "licenses": [
380002            {
380003              "license": {
380004                "id": "MIT"
380005              }
380006            }
380007          ],
380008          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
380009          "purl": "pkg:npm/string_decoder@1.1.1",
380010          "swid": {
380011            "attachment": {}
380012          },
380013          "pedigree": {},
380014          "externalReferences": [
380015            {
380016              "url": "git://github.com/nodejs/string_decoder.git",
380017              "type": "distribution"
380018            },
380019            {
380020              "url": "https://github.com/nodejs/string_decoder",
380021              "type": "website"
380022            }
380023          ],
380024          "evidence": {},
380025          "signature": {
380026            "signature": {
380027              "publicKey": {}
380028            }
380029          },
380030          "modelCard": {
380031            "modelParameters": {
380032              "approach": {}
380033            },
380034            "quantitativeAnalysis": {
380035              "graphics": {}
380036            },
380037            "considerations": {}
380038          }
380039        },
380040        {
380041          "type": "library",
380042          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=b44575a021be68ba",
380043          "supplier": {},
380044          "name": "string_decoder",
380045          "version": "1.1.1",
380046          "description": "The string_decoder module from Node core",
380047          "licenses": [
380048            {
380049              "license": {
380050                "id": "MIT"
380051              }
380052            }
380053          ],
380054          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
380055          "purl": "pkg:npm/string_decoder@1.1.1",
380056          "swid": {
380057            "attachment": {}
380058          },
380059          "pedigree": {},
380060          "externalReferences": [
380061            {
380062              "url": "git://github.com/nodejs/string_decoder.git",
380063              "type": "distribution"
380064            },
380065            {
380066              "url": "https://github.com/nodejs/string_decoder",
380067              "type": "website"
380068            }
380069          ],
380070          "evidence": {},
380071          "signature": {
380072            "signature": {
380073              "publicKey": {}
380074            }
380075          },
380076          "modelCard": {
380077            "modelParameters": {
380078              "approach": {}
380079            },
380080            "quantitativeAnalysis": {
380081              "graphics": {}
380082            },
380083            "considerations": {}
380084          }
380085        },
380086        {
380087          "type": "library",
380088          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=b19b3b00778e1d8",
380089          "supplier": {},
380090          "name": "string_decoder",
380091          "version": "1.1.1",
380092          "description": "The string_decoder module from Node core",
380093          "licenses": [
380094            {
380095              "license": {
380096                "id": "MIT"
380097              }
380098            }
380099          ],
380100          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
380101          "purl": "pkg:npm/string_decoder@1.1.1",
380102          "swid": {
380103            "attachment": {}
380104          },
380105          "pedigree": {},
380106          "externalReferences": [
380107            {
380108              "url": "git://github.com/nodejs/string_decoder.git",
380109              "type": "distribution"
380110            },
380111            {
380112              "url": "https://github.com/nodejs/string_decoder",
380113              "type": "website"
380114            }
380115          ],
380116          "evidence": {},
380117          "signature": {
380118            "signature": {
380119              "publicKey": {}
380120            }
380121          },
380122          "modelCard": {
380123            "modelParameters": {
380124              "approach": {}
380125            },
380126            "quantitativeAnalysis": {
380127              "graphics": {}
380128            },
380129            "considerations": {}
380130          }
380131        },
380132        {
380133          "type": "library",
380134          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=5c7fd10ffa2e6849",
380135          "supplier": {},
380136          "name": "string_decoder",
380137          "version": "1.1.1",
380138          "description": "The string_decoder module from Node core",
380139          "licenses": [
380140            {
380141              "license": {
380142                "id": "MIT"
380143              }
380144            }
380145          ],
380146          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
380147          "purl": "pkg:npm/string_decoder@1.1.1",
380148          "swid": {
380149            "attachment": {}
380150          },
380151          "pedigree": {},
380152          "externalReferences": [
380153            {
380154              "url": "git://github.com/nodejs/string_decoder.git",
380155              "type": "distribution"
380156            },
380157            {
380158              "url": "https://github.com/nodejs/string_decoder",
380159              "type": "website"
380160            }
380161          ],
380162          "evidence": {},
380163          "signature": {
380164            "signature": {
380165              "publicKey": {}
380166            }
380167          },
380168          "modelCard": {
380169            "modelParameters": {
380170              "approach": {}
380171            },
380172            "quantitativeAnalysis": {
380173              "graphics": {}
380174            },
380175            "considerations": {}
380176          }
380177        },
380178        {
380179          "type": "library",
380180          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=ca8af4aa6b41ca75",
380181          "supplier": {},
380182          "name": "string_decoder",
380183          "version": "1.3.0",
380184          "description": "The string_decoder module from Node core",
380185          "licenses": [
380186            {
380187              "license": {
380188                "id": "MIT"
380189              }
380190            }
380191          ],
380192          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
380193          "purl": "pkg:npm/string_decoder@1.3.0",
380194          "swid": {
380195            "attachment": {}
380196          },
380197          "pedigree": {},
380198          "externalReferences": [
380199            {
380200              "url": "git://github.com/nodejs/string_decoder.git",
380201              "type": "distribution"
380202            },
380203            {
380204              "url": "https://github.com/nodejs/string_decoder",
380205              "type": "website"
380206            }
380207          ],
380208          "evidence": {},
380209          "signature": {
380210            "signature": {
380211              "publicKey": {}
380212            }
380213          },
380214          "modelCard": {
380215            "modelParameters": {
380216              "approach": {}
380217            },
380218            "quantitativeAnalysis": {
380219              "graphics": {}
380220            },
380221            "considerations": {}
380222          }
380223        },
380224        {
380225          "type": "library",
380226          "bom-ref": "pkg:npm/stringify-package@1.0.1?package-id=c67453153e496783",
380227          "supplier": {},
380228          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
380229          "name": "stringify-package",
380230          "version": "1.0.1",
380231          "description": "stringifies npm-written json files",
380232          "licenses": [
380233            {
380234              "license": {
380235                "id": "ISC"
380236              }
380237            }
380238          ],
380239          "cpe": "cpe:2.3:a:stringify-package:stringify-package:1.0.1:*:*:*:*:*:*:*",
380240          "purl": "pkg:npm/stringify-package@1.0.1",
380241          "swid": {
380242            "attachment": {}
380243          },
380244          "pedigree": {},
380245          "externalReferences": [
380246            {
380247              "url": "git+https://github.com/npm/stringify-package.git",
380248              "type": "distribution"
380249            },
380250            {
380251              "url": "https://github.com/npm/stringify-package",
380252              "type": "website"
380253            }
380254          ],
380255          "evidence": {},
380256          "signature": {
380257            "signature": {
380258              "publicKey": {}
380259            }
380260          },
380261          "modelCard": {
380262            "modelParameters": {
380263              "approach": {}
380264            },
380265            "quantitativeAnalysis": {
380266              "graphics": {}
380267            },
380268            "considerations": {}
380269          }
380270        },
380271        {
380272          "type": "library",
380273          "bom-ref": "pkg:npm/strip-ansi@3.0.1?package-id=51b22d897b0450b8",
380274          "supplier": {},
380275          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380276          "name": "strip-ansi",
380277          "version": "3.0.1",
380278          "description": "Strip ANSI escape codes",
380279          "licenses": [
380280            {
380281              "license": {
380282                "id": "MIT"
380283              }
380284            }
380285          ],
380286          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:3.0.1:*:*:*:*:*:*:*",
380287          "purl": "pkg:npm/strip-ansi@3.0.1",
380288          "swid": {
380289            "attachment": {}
380290          },
380291          "pedigree": {},
380292          "externalReferences": [
380293            {
380294              "url": "git+https://github.com/chalk/strip-ansi.git",
380295              "type": "distribution"
380296            },
380297            {
380298              "url": "https://github.com/chalk/strip-ansi#readme",
380299              "type": "website"
380300            }
380301          ],
380302          "evidence": {},
380303          "signature": {
380304            "signature": {
380305              "publicKey": {}
380306            }
380307          },
380308          "modelCard": {
380309            "modelParameters": {
380310              "approach": {}
380311            },
380312            "quantitativeAnalysis": {
380313              "graphics": {}
380314            },
380315            "considerations": {}
380316          }
380317        },
380318        {
380319          "type": "library",
380320          "bom-ref": "pkg:npm/strip-ansi@4.0.0?package-id=13ba95b5b65e8a37",
380321          "supplier": {},
380322          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380323          "name": "strip-ansi",
380324          "version": "4.0.0",
380325          "description": "Strip ANSI escape codes",
380326          "licenses": [
380327            {
380328              "license": {
380329                "id": "MIT"
380330              }
380331            }
380332          ],
380333          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:4.0.0:*:*:*:*:*:*:*",
380334          "purl": "pkg:npm/strip-ansi@4.0.0",
380335          "swid": {
380336            "attachment": {}
380337          },
380338          "pedigree": {},
380339          "externalReferences": [
380340            {
380341              "url": "git+https://github.com/chalk/strip-ansi.git",
380342              "type": "distribution"
380343            },
380344            {
380345              "url": "https://github.com/chalk/strip-ansi#readme",
380346              "type": "website"
380347            }
380348          ],
380349          "evidence": {},
380350          "signature": {
380351            "signature": {
380352              "publicKey": {}
380353            }
380354          },
380355          "modelCard": {
380356            "modelParameters": {
380357              "approach": {}
380358            },
380359            "quantitativeAnalysis": {
380360              "graphics": {}
380361            },
380362            "considerations": {}
380363          }
380364        },
380365        {
380366          "type": "library",
380367          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=465f19aa1b6b9497",
380368          "supplier": {},
380369          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380370          "name": "strip-ansi",
380371          "version": "5.2.0",
380372          "description": "Strip ANSI escape codes from a string",
380373          "licenses": [
380374            {
380375              "license": {
380376                "id": "MIT"
380377              }
380378            }
380379          ],
380380          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
380381          "purl": "pkg:npm/strip-ansi@5.2.0",
380382          "swid": {
380383            "attachment": {}
380384          },
380385          "pedigree": {},
380386          "externalReferences": [
380387            {
380388              "url": "git+https://github.com/chalk/strip-ansi.git",
380389              "type": "distribution"
380390            },
380391            {
380392              "url": "https://github.com/chalk/strip-ansi#readme",
380393              "type": "website"
380394            }
380395          ],
380396          "evidence": {},
380397          "signature": {
380398            "signature": {
380399              "publicKey": {}
380400            }
380401          },
380402          "modelCard": {
380403            "modelParameters": {
380404              "approach": {}
380405            },
380406            "quantitativeAnalysis": {
380407              "graphics": {}
380408            },
380409            "considerations": {}
380410          }
380411        },
380412        {
380413          "type": "library",
380414          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=f78d385de6e5730d",
380415          "supplier": {},
380416          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380417          "name": "strip-ansi",
380418          "version": "5.2.0",
380419          "description": "Strip ANSI escape codes from a string",
380420          "licenses": [
380421            {
380422              "license": {
380423                "id": "MIT"
380424              }
380425            }
380426          ],
380427          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
380428          "purl": "pkg:npm/strip-ansi@5.2.0",
380429          "swid": {
380430            "attachment": {}
380431          },
380432          "pedigree": {},
380433          "externalReferences": [
380434            {
380435              "url": "git+https://github.com/chalk/strip-ansi.git",
380436              "type": "distribution"
380437            },
380438            {
380439              "url": "https://github.com/chalk/strip-ansi#readme",
380440              "type": "website"
380441            }
380442          ],
380443          "evidence": {},
380444          "signature": {
380445            "signature": {
380446              "publicKey": {}
380447            }
380448          },
380449          "modelCard": {
380450            "modelParameters": {
380451              "approach": {}
380452            },
380453            "quantitativeAnalysis": {
380454              "graphics": {}
380455            },
380456            "considerations": {}
380457          }
380458        },
380459        {
380460          "type": "library",
380461          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=6eaeb57df2549822",
380462          "supplier": {},
380463          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380464          "name": "strip-ansi",
380465          "version": "5.2.0",
380466          "description": "Strip ANSI escape codes from a string",
380467          "licenses": [
380468            {
380469              "license": {
380470                "id": "MIT"
380471              }
380472            }
380473          ],
380474          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
380475          "purl": "pkg:npm/strip-ansi@5.2.0",
380476          "swid": {
380477            "attachment": {}
380478          },
380479          "pedigree": {},
380480          "externalReferences": [
380481            {
380482              "url": "git+https://github.com/chalk/strip-ansi.git",
380483              "type": "distribution"
380484            },
380485            {
380486              "url": "https://github.com/chalk/strip-ansi#readme",
380487              "type": "website"
380488            }
380489          ],
380490          "evidence": {},
380491          "signature": {
380492            "signature": {
380493              "publicKey": {}
380494            }
380495          },
380496          "modelCard": {
380497            "modelParameters": {
380498              "approach": {}
380499            },
380500            "quantitativeAnalysis": {
380501              "graphics": {}
380502            },
380503            "considerations": {}
380504          }
380505        },
380506        {
380507          "type": "library",
380508          "bom-ref": "pkg:npm/strip-eof@1.0.0?package-id=16191ba994ef2bb8",
380509          "supplier": {},
380510          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380511          "name": "strip-eof",
380512          "version": "1.0.0",
380513          "description": "Strip the End-Of-File (EOF) character from a string/buffer",
380514          "licenses": [
380515            {
380516              "license": {
380517                "id": "MIT"
380518              }
380519            }
380520          ],
380521          "cpe": "cpe:2.3:a:sindresorhus:strip-eof:1.0.0:*:*:*:*:*:*:*",
380522          "purl": "pkg:npm/strip-eof@1.0.0",
380523          "swid": {
380524            "attachment": {}
380525          },
380526          "pedigree": {},
380527          "externalReferences": [
380528            {
380529              "url": "git+https://github.com/sindresorhus/strip-eof.git",
380530              "type": "distribution"
380531            },
380532            {
380533              "url": "https://github.com/sindresorhus/strip-eof#readme",
380534              "type": "website"
380535            }
380536          ],
380537          "evidence": {},
380538          "signature": {
380539            "signature": {
380540              "publicKey": {}
380541            }
380542          },
380543          "modelCard": {
380544            "modelParameters": {
380545              "approach": {}
380546            },
380547            "quantitativeAnalysis": {
380548              "graphics": {}
380549            },
380550            "considerations": {}
380551          }
380552        },
380553        {
380554          "type": "library",
380555          "bom-ref": "pkg:npm/strip-json-comments@2.0.1?package-id=ccf04b5e0cce811a",
380556          "supplier": {},
380557          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380558          "name": "strip-json-comments",
380559          "version": "2.0.1",
380560          "description": "Strip comments from JSON. Lets you use comments in your JSON files!",
380561          "licenses": [
380562            {
380563              "license": {
380564                "id": "MIT"
380565              }
380566            }
380567          ],
380568          "cpe": "cpe:2.3:a:strip-json-comments:strip-json-comments:2.0.1:*:*:*:*:*:*:*",
380569          "purl": "pkg:npm/strip-json-comments@2.0.1",
380570          "swid": {
380571            "attachment": {}
380572          },
380573          "pedigree": {},
380574          "externalReferences": [
380575            {
380576              "url": "git+https://github.com/sindresorhus/strip-json-comments.git",
380577              "type": "distribution"
380578            },
380579            {
380580              "url": "https://github.com/sindresorhus/strip-json-comments#readme",
380581              "type": "website"
380582            }
380583          ],
380584          "evidence": {},
380585          "signature": {
380586            "signature": {
380587              "publicKey": {}
380588            }
380589          },
380590          "modelCard": {
380591            "modelParameters": {
380592              "approach": {}
380593            },
380594            "quantitativeAnalysis": {
380595              "graphics": {}
380596            },
380597            "considerations": {}
380598          }
380599        },
380600        {
380601          "type": "library",
380602          "bom-ref": "pkg:npm/supports-color@5.4.0?package-id=4145d752dc87470d",
380603          "supplier": {},
380604          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380605          "name": "supports-color",
380606          "version": "5.4.0",
380607          "description": "Detect whether a terminal supports color",
380608          "licenses": [
380609            {
380610              "license": {
380611                "id": "MIT"
380612              }
380613            }
380614          ],
380615          "cpe": "cpe:2.3:a:supports-color:supports-color:5.4.0:*:*:*:*:*:*:*",
380616          "purl": "pkg:npm/supports-color@5.4.0",
380617          "swid": {
380618            "attachment": {}
380619          },
380620          "pedigree": {},
380621          "externalReferences": [
380622            {
380623              "url": "git+https://github.com/chalk/supports-color.git",
380624              "type": "distribution"
380625            },
380626            {
380627              "url": "https://github.com/chalk/supports-color#readme",
380628              "type": "website"
380629            }
380630          ],
380631          "evidence": {},
380632          "signature": {
380633            "signature": {
380634              "publicKey": {}
380635            }
380636          },
380637          "modelCard": {
380638            "modelParameters": {
380639              "approach": {}
380640            },
380641            "quantitativeAnalysis": {
380642              "graphics": {}
380643            },
380644            "considerations": {}
380645          }
380646        },
380647        {
380648          "type": "library",
380649          "bom-ref": "pkg:npm/supports-color@7.2.0?package-id=33ae3b7b72211ee6",
380650          "supplier": {},
380651          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380652          "name": "supports-color",
380653          "version": "7.2.0",
380654          "description": "Detect whether a terminal supports color",
380655          "licenses": [
380656            {
380657              "license": {
380658                "id": "MIT"
380659              }
380660            }
380661          ],
380662          "cpe": "cpe:2.3:a:supports-color:supports-color:7.2.0:*:*:*:*:*:*:*",
380663          "purl": "pkg:npm/supports-color@7.2.0",
380664          "swid": {
380665            "attachment": {}
380666          },
380667          "pedigree": {},
380668          "externalReferences": [
380669            {
380670              "url": "git+https://github.com/chalk/supports-color.git",
380671              "type": "distribution"
380672            },
380673            {
380674              "url": "https://github.com/chalk/supports-color#readme",
380675              "type": "website"
380676            }
380677          ],
380678          "evidence": {},
380679          "signature": {
380680            "signature": {
380681              "publicKey": {}
380682            }
380683          },
380684          "modelCard": {
380685            "modelParameters": {
380686              "approach": {}
380687            },
380688            "quantitativeAnalysis": {
380689              "graphics": {}
380690            },
380691            "considerations": {}
380692          }
380693        },
380694        {
380695          "type": "library",
380696          "bom-ref": "pkg:npm/swagger-ui-dist@3.51.1?package-id=23030af97edbc554",
380697          "supplier": {},
380698          "name": "swagger-ui-dist",
380699          "version": "3.51.1",
380700          "description": "[![NPM version](https://badge.fury.io/js/swagger-ui-dist.svg)](http://badge.fury.io/js/swagger-ui-dist)",
380701          "licenses": [
380702            {
380703              "license": {
380704                "id": "Apache-2.0"
380705              }
380706            }
380707          ],
380708          "cpe": "cpe:2.3:a:swagger-ui-dist:swagger-ui-dist:3.51.1:*:*:*:*:*:*:*",
380709          "purl": "pkg:npm/swagger-ui-dist@3.51.1",
380710          "swid": {
380711            "attachment": {}
380712          },
380713          "pedigree": {},
380714          "externalReferences": [
380715            {
380716              "url": "git+ssh://git@github.com/swagger-api/swagger-ui.git",
380717              "type": "distribution"
380718            },
380719            {
380720              "url": "https://github.com/swagger-api/swagger-ui#readme",
380721              "type": "website"
380722            }
380723          ],
380724          "evidence": {},
380725          "signature": {
380726            "signature": {
380727              "publicKey": {}
380728            }
380729          },
380730          "modelCard": {
380731            "modelParameters": {
380732              "approach": {}
380733            },
380734            "quantitativeAnalysis": {
380735              "graphics": {}
380736            },
380737            "considerations": {}
380738          }
380739        },
380740        {
380741          "type": "library",
380742          "bom-ref": "pkg:npm/swagger-ui-express@4.1.6?package-id=7b829ce58415e1f2",
380743          "supplier": {},
380744          "author": "Stephen Scott \u003cscottie1984@gmail.com\u003e",
380745          "name": "swagger-ui-express",
380746          "version": "4.1.6",
380747          "description": "Swagger UI Express",
380748          "licenses": [
380749            {
380750              "license": {
380751                "id": "MIT"
380752              }
380753            }
380754          ],
380755          "cpe": "cpe:2.3:a:swagger-ui-express:swagger-ui-express:4.1.6:*:*:*:*:*:*:*",
380756          "purl": "pkg:npm/swagger-ui-express@4.1.6",
380757          "swid": {
380758            "attachment": {}
380759          },
380760          "pedigree": {},
380761          "externalReferences": [
380762            {
380763              "url": "git+ssh://git@github.com/scottie1984/swagger-ui-express.git",
380764              "type": "distribution"
380765            },
380766            {
380767              "url": "https://github.com/scottie1984/swagger-ui-express",
380768              "type": "website"
380769            }
380770          ],
380771          "evidence": {},
380772          "signature": {
380773            "signature": {
380774              "publicKey": {}
380775            }
380776          },
380777          "modelCard": {
380778            "modelParameters": {
380779              "approach": {}
380780            },
380781            "quantitativeAnalysis": {
380782              "graphics": {}
380783            },
380784            "considerations": {}
380785          }
380786        },
380787        {
380788          "type": "library",
380789          "bom-ref": "pkg:npm/tar@4.4.19?package-id=9c9c5053c0d2bf4e",
380790          "supplier": {},
380791          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
380792          "name": "tar",
380793          "version": "4.4.19",
380794          "description": "tar for node",
380795          "licenses": [
380796            {
380797              "license": {
380798                "id": "ISC"
380799              }
380800            }
380801          ],
380802          "cpe": "cpe:2.3:a:npm:tar:4.4.19:*:*:*:*:*:*:*",
380803          "purl": "pkg:npm/tar@4.4.19",
380804          "swid": {
380805            "attachment": {}
380806          },
380807          "pedigree": {},
380808          "externalReferences": [
380809            {
380810              "url": "git+https://github.com/npm/node-tar.git",
380811              "type": "distribution"
380812            },
380813            {
380814              "url": "https://github.com/npm/node-tar#readme",
380815              "type": "website"
380816            }
380817          ],
380818          "evidence": {},
380819          "signature": {
380820            "signature": {
380821              "publicKey": {}
380822            }
380823          },
380824          "modelCard": {
380825            "modelParameters": {
380826              "approach": {}
380827            },
380828            "quantitativeAnalysis": {
380829              "graphics": {}
380830            },
380831            "considerations": {}
380832          }
380833        },
380834        {
380835          "type": "library",
380836          "bom-ref": "pkg:npm/tdigest@0.1.1?package-id=57d3f731d207b2d5",
380837          "supplier": {},
380838          "author": "Will Welch \u003cwelch@quietplease.com\u003e (http://quietplease.com/)",
380839          "name": "tdigest",
380840          "version": "0.1.1",
380841          "description": "javascript implementation of Dunning's T-Digest for streaming quantile approximation",
380842          "licenses": [
380843            {
380844              "license": {
380845                "id": "MIT"
380846              }
380847            }
380848          ],
380849          "cpe": "cpe:2.3:a:tdigest:tdigest:0.1.1:*:*:*:*:*:*:*",
380850          "purl": "pkg:npm/tdigest@0.1.1",
380851          "swid": {
380852            "attachment": {}
380853          },
380854          "pedigree": {},
380855          "externalReferences": [
380856            {
380857              "url": "git+https://github.com/welch/tdigest.git",
380858              "type": "distribution"
380859            },
380860            {
380861              "url": "https://github.com/welch/tdigest",
380862              "type": "website"
380863            }
380864          ],
380865          "evidence": {},
380866          "signature": {
380867            "signature": {
380868              "publicKey": {}
380869            }
380870          },
380871          "modelCard": {
380872            "modelParameters": {
380873              "approach": {}
380874            },
380875            "quantitativeAnalysis": {
380876              "graphics": {}
380877            },
380878            "considerations": {}
380879          }
380880        },
380881        {
380882          "type": "library",
380883          "bom-ref": "pkg:npm/term-size@1.2.0?package-id=b1193806642eaebf",
380884          "supplier": {},
380885          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
380886          "name": "term-size",
380887          "version": "1.2.0",
380888          "description": "Reliably get the terminal window size (columns \u0026 rows)",
380889          "licenses": [
380890            {
380891              "license": {
380892                "id": "MIT"
380893              }
380894            }
380895          ],
380896          "cpe": "cpe:2.3:a:sindresorhus:term-size:1.2.0:*:*:*:*:*:*:*",
380897          "purl": "pkg:npm/term-size@1.2.0",
380898          "swid": {
380899            "attachment": {}
380900          },
380901          "pedigree": {},
380902          "externalReferences": [
380903            {
380904              "url": "git+https://github.com/sindresorhus/term-size.git",
380905              "type": "distribution"
380906            },
380907            {
380908              "url": "https://github.com/sindresorhus/term-size#readme",
380909              "type": "website"
380910            }
380911          ],
380912          "evidence": {},
380913          "signature": {
380914            "signature": {
380915              "publicKey": {}
380916            }
380917          },
380918          "modelCard": {
380919            "modelParameters": {
380920              "approach": {}
380921            },
380922            "quantitativeAnalysis": {
380923              "graphics": {}
380924            },
380925            "considerations": {}
380926          }
380927        },
380928        {
380929          "type": "library",
380930          "bom-ref": "pkg:npm/text-table@0.2.0?package-id=a124be9ad599668f",
380931          "supplier": {},
380932          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
380933          "name": "text-table",
380934          "version": "0.2.0",
380935          "description": "borderless text tables with alignment",
380936          "licenses": [
380937            {
380938              "license": {
380939                "id": "MIT"
380940              }
380941            }
380942          ],
380943          "cpe": "cpe:2.3:a:text-table:text-table:0.2.0:*:*:*:*:*:*:*",
380944          "purl": "pkg:npm/text-table@0.2.0",
380945          "swid": {
380946            "attachment": {}
380947          },
380948          "pedigree": {},
380949          "externalReferences": [
380950            {
380951              "url": "git://github.com/substack/text-table.git",
380952              "type": "distribution"
380953            },
380954            {
380955              "url": "https://github.com/substack/text-table",
380956              "type": "website"
380957            }
380958          ],
380959          "evidence": {},
380960          "signature": {
380961            "signature": {
380962              "publicKey": {}
380963            }
380964          },
380965          "modelCard": {
380966            "modelParameters": {
380967              "approach": {}
380968            },
380969            "quantitativeAnalysis": {
380970              "graphics": {}
380971            },
380972            "considerations": {}
380973          }
380974        },
380975        {
380976          "type": "library",
380977          "bom-ref": "pkg:npm/through@2.3.8?package-id=4d5d009c68a6687c",
380978          "supplier": {},
380979          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (dominictarr.com)",
380980          "name": "through",
380981          "version": "2.3.8",
380982          "description": "simplified stream construction",
380983          "licenses": [
380984            {
380985              "license": {
380986                "id": "MIT"
380987              }
380988            }
380989          ],
380990          "cpe": "cpe:2.3:a:dominictarr:through:2.3.8:*:*:*:*:*:*:*",
380991          "purl": "pkg:npm/through@2.3.8",
380992          "swid": {
380993            "attachment": {}
380994          },
380995          "pedigree": {},
380996          "externalReferences": [
380997            {
380998              "url": "git+https://github.com/dominictarr/through.git",
380999              "type": "distribution"
381000            },
381001            {
381002              "url": "https://github.com/dominictarr/through",
381003              "type": "website"
381004            }
381005          ],
381006          "evidence": {},
381007          "signature": {
381008            "signature": {
381009              "publicKey": {}
381010            }
381011          },
381012          "modelCard": {
381013            "modelParameters": {
381014              "approach": {}
381015            },
381016            "quantitativeAnalysis": {
381017              "graphics": {}
381018            },
381019            "considerations": {}
381020          }
381021        },
381022        {
381023          "type": "library",
381024          "bom-ref": "pkg:npm/through2@2.0.3?package-id=8dbf9f3bfb369784",
381025          "supplier": {},
381026          "author": "Rod Vagg \u003cr@va.gg\u003e (https://github.com/rvagg)",
381027          "name": "through2",
381028          "version": "2.0.3",
381029          "description": "A tiny wrapper around Node streams2 Transform to avoid explicit subclassing noise",
381030          "licenses": [
381031            {
381032              "license": {
381033                "id": "MIT"
381034              }
381035            }
381036          ],
381037          "cpe": "cpe:2.3:a:through2:through2:2.0.3:*:*:*:*:*:*:*",
381038          "purl": "pkg:npm/through2@2.0.3",
381039          "swid": {
381040            "attachment": {}
381041          },
381042          "pedigree": {},
381043          "externalReferences": [
381044            {
381045              "url": "git+https://github.com/rvagg/through2.git",
381046              "type": "distribution"
381047            },
381048            {
381049              "url": "https://github.com/rvagg/through2#readme",
381050              "type": "website"
381051            }
381052          ],
381053          "evidence": {},
381054          "signature": {
381055            "signature": {
381056              "publicKey": {}
381057            }
381058          },
381059          "modelCard": {
381060            "modelParameters": {
381061              "approach": {}
381062            },
381063            "quantitativeAnalysis": {
381064              "graphics": {}
381065            },
381066            "considerations": {}
381067          }
381068        },
381069        {
381070          "type": "library",
381071          "bom-ref": "pkg:npm/timed-out@4.0.1?package-id=8c5219320754c34a",
381072          "supplier": {},
381073          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e",
381074          "name": "timed-out",
381075          "version": "4.0.1",
381076          "description": "Emit `ETIMEDOUT` or `ESOCKETTIMEDOUT` when ClientRequest is hanged",
381077          "licenses": [
381078            {
381079              "license": {
381080                "id": "MIT"
381081              }
381082            }
381083          ],
381084          "cpe": "cpe:2.3:a:floatdrop:timed-out:4.0.1:*:*:*:*:*:*:*",
381085          "purl": "pkg:npm/timed-out@4.0.1",
381086          "swid": {
381087            "attachment": {}
381088          },
381089          "pedigree": {},
381090          "externalReferences": [
381091            {
381092              "url": "git+https://github.com/floatdrop/timed-out.git",
381093              "type": "distribution"
381094            },
381095            {
381096              "url": "https://github.com/floatdrop/timed-out#readme",
381097              "type": "website"
381098            }
381099          ],
381100          "evidence": {},
381101          "signature": {
381102            "signature": {
381103              "publicKey": {}
381104            }
381105          },
381106          "modelCard": {
381107            "modelParameters": {
381108              "approach": {}
381109            },
381110            "quantitativeAnalysis": {
381111              "graphics": {}
381112            },
381113            "considerations": {}
381114          }
381115        },
381116        {
381117          "type": "library",
381118          "bom-ref": "pkg:npm/tiny-relative-date@1.3.0?package-id=192b923f399b9869",
381119          "supplier": {},
381120          "author": "Joseph Wynn \u003cjoseph@wildlyinaccurate.com\u003e (https://wildlyinaccurate.com/)",
381121          "name": "tiny-relative-date",
381122          "version": "1.3.0",
381123          "description": "Tiny function that provides relative, human-readable dates.",
381124          "licenses": [
381125            {
381126              "license": {
381127                "id": "MIT"
381128              }
381129            }
381130          ],
381131          "cpe": "cpe:2.3:a:tiny-relative-date:tiny-relative-date:1.3.0:*:*:*:*:*:*:*",
381132          "purl": "pkg:npm/tiny-relative-date@1.3.0",
381133          "swid": {
381134            "attachment": {}
381135          },
381136          "pedigree": {},
381137          "externalReferences": [
381138            {
381139              "url": "git+https://github.com/wildlyinaccurate/relative-date.git",
381140              "type": "distribution"
381141            },
381142            {
381143              "url": "https://github.com/wildlyinaccurate/relative-date#readme",
381144              "type": "website"
381145            }
381146          ],
381147          "evidence": {},
381148          "signature": {
381149            "signature": {
381150              "publicKey": {}
381151            }
381152          },
381153          "modelCard": {
381154            "modelParameters": {
381155              "approach": {}
381156            },
381157            "quantitativeAnalysis": {
381158              "graphics": {}
381159            },
381160            "considerations": {}
381161          }
381162        },
381163        {
381164          "type": "library",
381165          "bom-ref": "pkg:npm/toidentifier@1.0.0?package-id=b139c4c4805829ae",
381166          "supplier": {},
381167          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
381168          "name": "toidentifier",
381169          "version": "1.0.0",
381170          "description": "Convert a string of words to a JavaScript identifier",
381171          "licenses": [
381172            {
381173              "license": {
381174                "id": "MIT"
381175              }
381176            }
381177          ],
381178          "cpe": "cpe:2.3:a:toidentifier:toidentifier:1.0.0:*:*:*:*:*:*:*",
381179          "purl": "pkg:npm/toidentifier@1.0.0",
381180          "swid": {
381181            "attachment": {}
381182          },
381183          "pedigree": {},
381184          "externalReferences": [
381185            {
381186              "url": "git+https://github.com/component/toidentifier.git",
381187              "type": "distribution"
381188            },
381189            {
381190              "url": "https://github.com/component/toidentifier#readme",
381191              "type": "website"
381192            }
381193          ],
381194          "evidence": {},
381195          "signature": {
381196            "signature": {
381197              "publicKey": {}
381198            }
381199          },
381200          "modelCard": {
381201            "modelParameters": {
381202              "approach": {}
381203            },
381204            "quantitativeAnalysis": {
381205              "graphics": {}
381206            },
381207            "considerations": {}
381208          }
381209        },
381210        {
381211          "type": "library",
381212          "bom-ref": "pkg:npm/tough-cookie@2.5.0?package-id=f258c5fd182253c1",
381213          "supplier": {},
381214          "author": "Jeremy Stashewsky \u003cjstash@gmail.com\u003e",
381215          "name": "tough-cookie",
381216          "version": "2.5.0",
381217          "description": "RFC6265 Cookies and Cookie Jar for node.js",
381218          "licenses": [
381219            {
381220              "license": {
381221                "id": "BSD-3-Clause"
381222              }
381223            }
381224          ],
381225          "cpe": "cpe:2.3:a:tough-cookie:tough-cookie:2.5.0:*:*:*:*:*:*:*",
381226          "purl": "pkg:npm/tough-cookie@2.5.0",
381227          "swid": {
381228            "attachment": {}
381229          },
381230          "pedigree": {},
381231          "externalReferences": [
381232            {
381233              "url": "git://github.com/salesforce/tough-cookie.git",
381234              "type": "distribution"
381235            },
381236            {
381237              "url": "https://github.com/salesforce/tough-cookie",
381238              "type": "website"
381239            }
381240          ],
381241          "evidence": {},
381242          "signature": {
381243            "signature": {
381244              "publicKey": {}
381245            }
381246          },
381247          "modelCard": {
381248            "modelParameters": {
381249              "approach": {}
381250            },
381251            "quantitativeAnalysis": {
381252              "graphics": {}
381253            },
381254            "considerations": {}
381255          }
381256        },
381257        {
381258          "type": "library",
381259          "bom-ref": "pkg:npm/tough-cookie@2.5.0?package-id=46e88d011801ebab",
381260          "supplier": {},
381261          "author": "Jeremy Stashewsky \u003cjstash@gmail.com\u003e",
381262          "name": "tough-cookie",
381263          "version": "2.5.0",
381264          "description": "RFC6265 Cookies and Cookie Jar for node.js",
381265          "licenses": [
381266            {
381267              "license": {
381268                "id": "BSD-3-Clause"
381269              }
381270            }
381271          ],
381272          "cpe": "cpe:2.3:a:tough-cookie:tough-cookie:2.5.0:*:*:*:*:*:*:*",
381273          "purl": "pkg:npm/tough-cookie@2.5.0",
381274          "swid": {
381275            "attachment": {}
381276          },
381277          "pedigree": {},
381278          "externalReferences": [
381279            {
381280              "url": "git://github.com/salesforce/tough-cookie.git",
381281              "type": "distribution"
381282            },
381283            {
381284              "url": "https://github.com/salesforce/tough-cookie",
381285              "type": "website"
381286            }
381287          ],
381288          "evidence": {},
381289          "signature": {
381290            "signature": {
381291              "publicKey": {}
381292            }
381293          },
381294          "modelCard": {
381295            "modelParameters": {
381296              "approach": {}
381297            },
381298            "quantitativeAnalysis": {
381299              "graphics": {}
381300            },
381301            "considerations": {}
381302          }
381303        },
381304        {
381305          "type": "library",
381306          "bom-ref": "pkg:npm/tough-cookie@2.5.0?package-id=bfc5458cbb7f12a6",
381307          "supplier": {},
381308          "author": "Jeremy Stashewsky \u003cjstash@gmail.com\u003e",
381309          "name": "tough-cookie",
381310          "version": "2.5.0",
381311          "description": "RFC6265 Cookies and Cookie Jar for node.js",
381312          "licenses": [
381313            {
381314              "license": {
381315                "id": "BSD-3-Clause"
381316              }
381317            }
381318          ],
381319          "cpe": "cpe:2.3:a:tough-cookie:tough-cookie:2.5.0:*:*:*:*:*:*:*",
381320          "purl": "pkg:npm/tough-cookie@2.5.0",
381321          "swid": {
381322            "attachment": {}
381323          },
381324          "pedigree": {},
381325          "externalReferences": [
381326            {
381327              "url": "git://github.com/salesforce/tough-cookie.git",
381328              "type": "distribution"
381329            },
381330            {
381331              "url": "https://github.com/salesforce/tough-cookie",
381332              "type": "website"
381333            }
381334          ],
381335          "evidence": {},
381336          "signature": {
381337            "signature": {
381338              "publicKey": {}
381339            }
381340          },
381341          "modelCard": {
381342            "modelParameters": {
381343              "approach": {}
381344            },
381345            "quantitativeAnalysis": {
381346              "graphics": {}
381347            },
381348            "considerations": {}
381349          }
381350        },
381351        {
381352          "type": "library",
381353          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=6536b2dd10d6cbb5",
381354          "supplier": {},
381355          "author": "Microsoft Corp.",
381356          "name": "tslib",
381357          "version": "1.14.1",
381358          "description": "Runtime library for TypeScript helper functions",
381359          "licenses": [
381360            {
381361              "license": {
381362                "id": "0BSD"
381363              }
381364            }
381365          ],
381366          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
381367          "purl": "pkg:npm/tslib@1.14.1",
381368          "swid": {
381369            "attachment": {}
381370          },
381371          "pedigree": {},
381372          "externalReferences": [
381373            {
381374              "url": "git+https://github.com/Microsoft/tslib.git",
381375              "type": "distribution"
381376            },
381377            {
381378              "url": "https://www.typescriptlang.org/",
381379              "type": "website"
381380            }
381381          ],
381382          "evidence": {},
381383          "signature": {
381384            "signature": {
381385              "publicKey": {}
381386            }
381387          },
381388          "modelCard": {
381389            "modelParameters": {
381390              "approach": {}
381391            },
381392            "quantitativeAnalysis": {
381393              "graphics": {}
381394            },
381395            "considerations": {}
381396          }
381397        },
381398        {
381399          "type": "library",
381400          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=1d66cb61fb941655",
381401          "supplier": {},
381402          "author": "Microsoft Corp.",
381403          "name": "tslib",
381404          "version": "1.14.1",
381405          "description": "Runtime library for TypeScript helper functions",
381406          "licenses": [
381407            {
381408              "license": {
381409                "id": "0BSD"
381410              }
381411            }
381412          ],
381413          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
381414          "purl": "pkg:npm/tslib@1.14.1",
381415          "swid": {
381416            "attachment": {}
381417          },
381418          "pedigree": {},
381419          "externalReferences": [
381420            {
381421              "url": "git+https://github.com/Microsoft/tslib.git",
381422              "type": "distribution"
381423            },
381424            {
381425              "url": "https://www.typescriptlang.org/",
381426              "type": "website"
381427            }
381428          ],
381429          "evidence": {},
381430          "signature": {
381431            "signature": {
381432              "publicKey": {}
381433            }
381434          },
381435          "modelCard": {
381436            "modelParameters": {
381437              "approach": {}
381438            },
381439            "quantitativeAnalysis": {
381440              "graphics": {}
381441            },
381442            "considerations": {}
381443          }
381444        },
381445        {
381446          "type": "library",
381447          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=85f17f7fdbf8a5d0",
381448          "supplier": {},
381449          "author": "Microsoft Corp.",
381450          "name": "tslib",
381451          "version": "1.14.1",
381452          "description": "Runtime library for TypeScript helper functions",
381453          "licenses": [
381454            {
381455              "license": {
381456                "id": "0BSD"
381457              }
381458            }
381459          ],
381460          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
381461          "purl": "pkg:npm/tslib@1.14.1",
381462          "swid": {
381463            "attachment": {}
381464          },
381465          "pedigree": {},
381466          "externalReferences": [
381467            {
381468              "url": "git+https://github.com/Microsoft/tslib.git",
381469              "type": "distribution"
381470            },
381471            {
381472              "url": "https://www.typescriptlang.org/",
381473              "type": "website"
381474            }
381475          ],
381476          "evidence": {},
381477          "signature": {
381478            "signature": {
381479              "publicKey": {}
381480            }
381481          },
381482          "modelCard": {
381483            "modelParameters": {
381484              "approach": {}
381485            },
381486            "quantitativeAnalysis": {
381487              "graphics": {}
381488            },
381489            "considerations": {}
381490          }
381491        },
381492        {
381493          "type": "library",
381494          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=5529bb73f7015d14",
381495          "supplier": {},
381496          "author": "Microsoft Corp.",
381497          "name": "tslib",
381498          "version": "1.14.1",
381499          "description": "Runtime library for TypeScript helper functions",
381500          "licenses": [
381501            {
381502              "license": {
381503                "id": "0BSD"
381504              }
381505            }
381506          ],
381507          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
381508          "purl": "pkg:npm/tslib@1.14.1",
381509          "swid": {
381510            "attachment": {}
381511          },
381512          "pedigree": {},
381513          "externalReferences": [
381514            {
381515              "url": "git+https://github.com/Microsoft/tslib.git",
381516              "type": "distribution"
381517            },
381518            {
381519              "url": "https://www.typescriptlang.org/",
381520              "type": "website"
381521            }
381522          ],
381523          "evidence": {},
381524          "signature": {
381525            "signature": {
381526              "publicKey": {}
381527            }
381528          },
381529          "modelCard": {
381530            "modelParameters": {
381531              "approach": {}
381532            },
381533            "quantitativeAnalysis": {
381534              "graphics": {}
381535            },
381536            "considerations": {}
381537          }
381538        },
381539        {
381540          "type": "library",
381541          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=35ceae8b5a8ff734",
381542          "supplier": {},
381543          "author": "Microsoft Corp.",
381544          "name": "tslib",
381545          "version": "1.14.1",
381546          "description": "Runtime library for TypeScript helper functions",
381547          "licenses": [
381548            {
381549              "license": {
381550                "id": "0BSD"
381551              }
381552            }
381553          ],
381554          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
381555          "purl": "pkg:npm/tslib@1.14.1",
381556          "swid": {
381557            "attachment": {}
381558          },
381559          "pedigree": {},
381560          "externalReferences": [
381561            {
381562              "url": "git+https://github.com/Microsoft/tslib.git",
381563              "type": "distribution"
381564            },
381565            {
381566              "url": "https://www.typescriptlang.org/",
381567              "type": "website"
381568            }
381569          ],
381570          "evidence": {},
381571          "signature": {
381572            "signature": {
381573              "publicKey": {}
381574            }
381575          },
381576          "modelCard": {
381577            "modelParameters": {
381578              "approach": {}
381579            },
381580            "quantitativeAnalysis": {
381581              "graphics": {}
381582            },
381583            "considerations": {}
381584          }
381585        },
381586        {
381587          "type": "library",
381588          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=4a8087d9ced7b72a",
381589          "supplier": {},
381590          "author": "Microsoft Corp.",
381591          "name": "tslib",
381592          "version": "1.14.1",
381593          "description": "Runtime library for TypeScript helper functions",
381594          "licenses": [
381595            {
381596              "license": {
381597                "id": "0BSD"
381598              }
381599            }
381600          ],
381601          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
381602          "purl": "pkg:npm/tslib@1.14.1",
381603          "swid": {
381604            "attachment": {}
381605          },
381606          "pedigree": {},
381607          "externalReferences": [
381608            {
381609              "url": "git+https://github.com/Microsoft/tslib.git",
381610              "type": "distribution"
381611            },
381612            {
381613              "url": "https://www.typescriptlang.org/",
381614              "type": "website"
381615            }
381616          ],
381617          "evidence": {},
381618          "signature": {
381619            "signature": {
381620              "publicKey": {}
381621            }
381622          },
381623          "modelCard": {
381624            "modelParameters": {
381625              "approach": {}
381626            },
381627            "quantitativeAnalysis": {
381628              "graphics": {}
381629            },
381630            "considerations": {}
381631          }
381632        },
381633        {
381634          "type": "library",
381635          "bom-ref": "pkg:npm/tslib@1.14.1?package-id=81b6a4b44008213",
381636          "supplier": {},
381637          "author": "Microsoft Corp.",
381638          "name": "tslib",
381639          "version": "1.14.1",
381640          "description": "Runtime library for TypeScript helper functions",
381641          "licenses": [
381642            {
381643              "license": {
381644                "id": "0BSD"
381645              }
381646            }
381647          ],
381648          "cpe": "cpe:2.3:a:tslib:tslib:1.14.1:*:*:*:*:*:*:*",
381649          "purl": "pkg:npm/tslib@1.14.1",
381650          "swid": {
381651            "attachment": {}
381652          },
381653          "pedigree": {},
381654          "externalReferences": [
381655            {
381656              "url": "git+https://github.com/Microsoft/tslib.git",
381657              "type": "distribution"
381658            },
381659            {
381660              "url": "https://www.typescriptlang.org/",
381661              "type": "website"
381662            }
381663          ],
381664          "evidence": {},
381665          "signature": {
381666            "signature": {
381667              "publicKey": {}
381668            }
381669          },
381670          "modelCard": {
381671            "modelParameters": {
381672              "approach": {}
381673            },
381674            "quantitativeAnalysis": {
381675              "graphics": {}
381676            },
381677            "considerations": {}
381678          }
381679        },
381680        {
381681          "type": "library",
381682          "bom-ref": "pkg:npm/tslib@2.2.0?package-id=90598db04856e225",
381683          "supplier": {},
381684          "author": "Microsoft Corp.",
381685          "name": "tslib",
381686          "version": "2.2.0",
381687          "description": "Runtime library for TypeScript helper functions",
381688          "licenses": [
381689            {
381690              "license": {
381691                "id": "0BSD"
381692              }
381693            }
381694          ],
381695          "cpe": "cpe:2.3:a:tslib:tslib:2.2.0:*:*:*:*:*:*:*",
381696          "purl": "pkg:npm/tslib@2.2.0",
381697          "swid": {
381698            "attachment": {}
381699          },
381700          "pedigree": {},
381701          "externalReferences": [
381702            {
381703              "url": "git+https://github.com/Microsoft/tslib.git",
381704              "type": "distribution"
381705            },
381706            {
381707              "url": "https://www.typescriptlang.org/",
381708              "type": "website"
381709            }
381710          ],
381711          "evidence": {},
381712          "signature": {
381713            "signature": {
381714              "publicKey": {}
381715            }
381716          },
381717          "modelCard": {
381718            "modelParameters": {
381719              "approach": {}
381720            },
381721            "quantitativeAnalysis": {
381722              "graphics": {}
381723            },
381724            "considerations": {}
381725          }
381726        },
381727        {
381728          "type": "library",
381729          "bom-ref": "pkg:npm/tunnel-agent@0.6.0?package-id=f0388bb360765d65",
381730          "supplier": {},
381731          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
381732          "name": "tunnel-agent",
381733          "version": "0.6.0",
381734          "description": "HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.",
381735          "licenses": [
381736            {
381737              "license": {
381738                "id": "Apache-2.0"
381739              }
381740            }
381741          ],
381742          "cpe": "cpe:2.3:a:tunnel-agent:tunnel-agent:0.6.0:*:*:*:*:*:*:*",
381743          "purl": "pkg:npm/tunnel-agent@0.6.0",
381744          "swid": {
381745            "attachment": {}
381746          },
381747          "pedigree": {},
381748          "externalReferences": [
381749            {
381750              "url": "git+https://github.com/mikeal/tunnel-agent.git",
381751              "type": "distribution"
381752            },
381753            {
381754              "url": "https://github.com/mikeal/tunnel-agent#readme",
381755              "type": "website"
381756            }
381757          ],
381758          "evidence": {},
381759          "signature": {
381760            "signature": {
381761              "publicKey": {}
381762            }
381763          },
381764          "modelCard": {
381765            "modelParameters": {
381766              "approach": {}
381767            },
381768            "quantitativeAnalysis": {
381769              "graphics": {}
381770            },
381771            "considerations": {}
381772          }
381773        },
381774        {
381775          "type": "library",
381776          "bom-ref": "pkg:npm/tunnel-agent@0.6.0?package-id=5f666f5e908dfc65",
381777          "supplier": {},
381778          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
381779          "name": "tunnel-agent",
381780          "version": "0.6.0",
381781          "description": "HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.",
381782          "licenses": [
381783            {
381784              "license": {
381785                "id": "Apache-2.0"
381786              }
381787            }
381788          ],
381789          "cpe": "cpe:2.3:a:tunnel-agent:tunnel-agent:0.6.0:*:*:*:*:*:*:*",
381790          "purl": "pkg:npm/tunnel-agent@0.6.0",
381791          "swid": {
381792            "attachment": {}
381793          },
381794          "pedigree": {},
381795          "externalReferences": [
381796            {
381797              "url": "git+https://github.com/mikeal/tunnel-agent.git",
381798              "type": "distribution"
381799            },
381800            {
381801              "url": "https://github.com/mikeal/tunnel-agent#readme",
381802              "type": "website"
381803            }
381804          ],
381805          "evidence": {},
381806          "signature": {
381807            "signature": {
381808              "publicKey": {}
381809            }
381810          },
381811          "modelCard": {
381812            "modelParameters": {
381813              "approach": {}
381814            },
381815            "quantitativeAnalysis": {
381816              "graphics": {}
381817            },
381818            "considerations": {}
381819          }
381820        },
381821        {
381822          "type": "library",
381823          "bom-ref": "pkg:npm/tweetnacl@0.14.5?package-id=9f8588e164854386",
381824          "supplier": {},
381825          "author": "TweetNaCl-js contributors",
381826          "name": "tweetnacl",
381827          "version": "0.14.5",
381828          "description": "Port of TweetNaCl cryptographic library to JavaScript",
381829          "licenses": [
381830            {
381831              "license": {
381832                "id": "Unlicense"
381833              }
381834            }
381835          ],
381836          "cpe": "cpe:2.3:a:tweetnacl:tweetnacl:0.14.5:*:*:*:*:*:*:*",
381837          "purl": "pkg:npm/tweetnacl@0.14.5",
381838          "swid": {
381839            "attachment": {}
381840          },
381841          "pedigree": {},
381842          "externalReferences": [
381843            {
381844              "url": "git+https://github.com/dchest/tweetnacl-js.git",
381845              "type": "distribution"
381846            },
381847            {
381848              "url": "https://tweetnacl.js.org",
381849              "type": "website"
381850            }
381851          ],
381852          "evidence": {},
381853          "signature": {
381854            "signature": {
381855              "publicKey": {}
381856            }
381857          },
381858          "modelCard": {
381859            "modelParameters": {
381860              "approach": {}
381861            },
381862            "quantitativeAnalysis": {
381863              "graphics": {}
381864            },
381865            "considerations": {}
381866          }
381867        },
381868        {
381869          "type": "library",
381870          "bom-ref": "pkg:npm/tweetnacl@0.14.5?package-id=978333255b1b0435",
381871          "supplier": {},
381872          "author": "TweetNaCl-js contributors",
381873          "name": "tweetnacl",
381874          "version": "0.14.5",
381875          "description": "Port of TweetNaCl cryptographic library to JavaScript",
381876          "licenses": [
381877            {
381878              "license": {
381879                "id": "Unlicense"
381880              }
381881            }
381882          ],
381883          "cpe": "cpe:2.3:a:tweetnacl:tweetnacl:0.14.5:*:*:*:*:*:*:*",
381884          "purl": "pkg:npm/tweetnacl@0.14.5",
381885          "swid": {
381886            "attachment": {}
381887          },
381888          "pedigree": {},
381889          "externalReferences": [
381890            {
381891              "url": "git+https://github.com/dchest/tweetnacl-js.git",
381892              "type": "distribution"
381893            },
381894            {
381895              "url": "https://tweetnacl.js.org",
381896              "type": "website"
381897            }
381898          ],
381899          "evidence": {},
381900          "signature": {
381901            "signature": {
381902              "publicKey": {}
381903            }
381904          },
381905          "modelCard": {
381906            "modelParameters": {
381907              "approach": {}
381908            },
381909            "quantitativeAnalysis": {
381910              "graphics": {}
381911            },
381912            "considerations": {}
381913          }
381914        },
381915        {
381916          "type": "library",
381917          "bom-ref": "pkg:npm/type-fest@0.20.2?package-id=89d29052f9ea1f10",
381918          "supplier": {},
381919          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
381920          "name": "type-fest",
381921          "version": "0.20.2",
381922          "description": "A collection of essential TypeScript types",
381923          "licenses": [
381924            {
381925              "license": {
381926                "name": "(MIT OR CC0-1.0)"
381927              }
381928            }
381929          ],
381930          "cpe": "cpe:2.3:a:sindresorhus:type-fest:0.20.2:*:*:*:*:*:*:*",
381931          "purl": "pkg:npm/type-fest@0.20.2",
381932          "swid": {
381933            "attachment": {}
381934          },
381935          "pedigree": {},
381936          "externalReferences": [
381937            {
381938              "url": "git+https://github.com/sindresorhus/type-fest.git",
381939              "type": "distribution"
381940            },
381941            {
381942              "url": "https://github.com/sindresorhus/type-fest#readme",
381943              "type": "website"
381944            }
381945          ],
381946          "evidence": {},
381947          "signature": {
381948            "signature": {
381949              "publicKey": {}
381950            }
381951          },
381952          "modelCard": {
381953            "modelParameters": {
381954              "approach": {}
381955            },
381956            "quantitativeAnalysis": {
381957              "graphics": {}
381958            },
381959            "considerations": {}
381960          }
381961        },
381962        {
381963          "type": "library",
381964          "bom-ref": "pkg:npm/type-is@1.6.18?package-id=a4eef9183b32a31",
381965          "supplier": {},
381966          "name": "type-is",
381967          "version": "1.6.18",
381968          "description": "Infer the content-type of a request.",
381969          "licenses": [
381970            {
381971              "license": {
381972                "id": "MIT"
381973              }
381974            }
381975          ],
381976          "cpe": "cpe:2.3:a:type-is:type-is:1.6.18:*:*:*:*:*:*:*",
381977          "purl": "pkg:npm/type-is@1.6.18",
381978          "swid": {
381979            "attachment": {}
381980          },
381981          "pedigree": {},
381982          "externalReferences": [
381983            {
381984              "url": "git+https://github.com/jshttp/type-is.git",
381985              "type": "distribution"
381986            },
381987            {
381988              "url": "https://github.com/jshttp/type-is#readme",
381989              "type": "website"
381990            }
381991          ],
381992          "evidence": {},
381993          "signature": {
381994            "signature": {
381995              "publicKey": {}
381996            }
381997          },
381998          "modelCard": {
381999            "modelParameters": {
382000              "approach": {}
382001            },
382002            "quantitativeAnalysis": {
382003              "graphics": {}
382004            },
382005            "considerations": {}
382006          }
382007        },
382008        {
382009          "type": "library",
382010          "bom-ref": "pkg:npm/typedarray@0.0.6?package-id=f7beac06324a3356",
382011          "supplier": {},
382012          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
382013          "name": "typedarray",
382014          "version": "0.0.6",
382015          "description": "TypedArray polyfill for old browsers",
382016          "licenses": [
382017            {
382018              "license": {
382019                "id": "MIT"
382020              }
382021            }
382022          ],
382023          "cpe": "cpe:2.3:a:typedarray:typedarray:0.0.6:*:*:*:*:*:*:*",
382024          "purl": "pkg:npm/typedarray@0.0.6",
382025          "swid": {
382026            "attachment": {}
382027          },
382028          "pedigree": {},
382029          "externalReferences": [
382030            {
382031              "url": "git://github.com/substack/typedarray.git",
382032              "type": "distribution"
382033            },
382034            {
382035              "url": "https://github.com/substack/typedarray",
382036              "type": "website"
382037            }
382038          ],
382039          "evidence": {},
382040          "signature": {
382041            "signature": {
382042              "publicKey": {}
382043            }
382044          },
382045          "modelCard": {
382046            "modelParameters": {
382047              "approach": {}
382048            },
382049            "quantitativeAnalysis": {
382050              "graphics": {}
382051            },
382052            "considerations": {}
382053          }
382054        },
382055        {
382056          "type": "library",
382057          "bom-ref": "pkg:npm/typedarray@0.0.6?package-id=8f3ba3a6a4336960",
382058          "supplier": {},
382059          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
382060          "name": "typedarray",
382061          "version": "0.0.6",
382062          "description": "TypedArray polyfill for old browsers",
382063          "licenses": [
382064            {
382065              "license": {
382066                "id": "MIT"
382067              }
382068            }
382069          ],
382070          "cpe": "cpe:2.3:a:typedarray:typedarray:0.0.6:*:*:*:*:*:*:*",
382071          "purl": "pkg:npm/typedarray@0.0.6",
382072          "swid": {
382073            "attachment": {}
382074          },
382075          "pedigree": {},
382076          "externalReferences": [
382077            {
382078              "url": "git://github.com/substack/typedarray.git",
382079              "type": "distribution"
382080            },
382081            {
382082              "url": "https://github.com/substack/typedarray",
382083              "type": "website"
382084            }
382085          ],
382086          "evidence": {},
382087          "signature": {
382088            "signature": {
382089              "publicKey": {}
382090            }
382091          },
382092          "modelCard": {
382093            "modelParameters": {
382094              "approach": {}
382095            },
382096            "quantitativeAnalysis": {
382097              "graphics": {}
382098            },
382099            "considerations": {}
382100          }
382101        },
382102        {
382103          "type": "library",
382104          "bom-ref": "pkg:npm/uid-number@0.0.6?package-id=c6b3a428d7d6414b",
382105          "supplier": {},
382106          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
382107          "name": "uid-number",
382108          "version": "0.0.6",
382109          "description": "Convert a username/group name to a uid/gid number",
382110          "licenses": [
382111            {
382112              "license": {
382113                "id": "ISC"
382114              }
382115            }
382116          ],
382117          "cpe": "cpe:2.3:a:uid-number:uid-number:0.0.6:*:*:*:*:*:*:*",
382118          "purl": "pkg:npm/uid-number@0.0.6",
382119          "swid": {
382120            "attachment": {}
382121          },
382122          "pedigree": {},
382123          "externalReferences": [
382124            {
382125              "url": "git://github.com/isaacs/uid-number.git",
382126              "type": "distribution"
382127            },
382128            {
382129              "url": "https://github.com/isaacs/uid-number#readme",
382130              "type": "website"
382131            }
382132          ],
382133          "evidence": {},
382134          "signature": {
382135            "signature": {
382136              "publicKey": {}
382137            }
382138          },
382139          "modelCard": {
382140            "modelParameters": {
382141              "approach": {}
382142            },
382143            "quantitativeAnalysis": {
382144              "graphics": {}
382145            },
382146            "considerations": {}
382147          }
382148        },
382149        {
382150          "type": "library",
382151          "bom-ref": "pkg:npm/umask@1.1.0?package-id=c2c1639822e8e1f2",
382152          "supplier": {},
382153          "author": "Sam Mikes \u003csmikes@cubane.com\u003e",
382154          "name": "umask",
382155          "version": "1.1.0",
382156          "description": "convert umask from string \u003c-\u003e number",
382157          "licenses": [
382158            {
382159              "license": {
382160                "id": "MIT"
382161              }
382162            }
382163          ],
382164          "cpe": "cpe:2.3:a:smikes:umask:1.1.0:*:*:*:*:*:*:*",
382165          "purl": "pkg:npm/umask@1.1.0",
382166          "swid": {
382167            "attachment": {}
382168          },
382169          "pedigree": {},
382170          "externalReferences": [
382171            {
382172              "url": "git+https://github.com/smikes/umask.git",
382173              "type": "distribution"
382174            },
382175            {
382176              "url": "https://github.com/smikes/umask",
382177              "type": "website"
382178            }
382179          ],
382180          "evidence": {},
382181          "signature": {
382182            "signature": {
382183              "publicKey": {}
382184            }
382185          },
382186          "modelCard": {
382187            "modelParameters": {
382188              "approach": {}
382189            },
382190            "quantitativeAnalysis": {
382191              "graphics": {}
382192            },
382193            "considerations": {}
382194          }
382195        },
382196        {
382197          "type": "library",
382198          "bom-ref": "pkg:npm/unique-filename@1.1.1?package-id=7ca7ff63263b2fc2",
382199          "supplier": {},
382200          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
382201          "name": "unique-filename",
382202          "version": "1.1.1",
382203          "description": "Generate a unique filename for use in temporary directories or caches.",
382204          "licenses": [
382205            {
382206              "license": {
382207                "id": "ISC"
382208              }
382209            }
382210          ],
382211          "cpe": "cpe:2.3:a:unique-filename:unique-filename:1.1.1:*:*:*:*:*:*:*",
382212          "purl": "pkg:npm/unique-filename@1.1.1",
382213          "swid": {
382214            "attachment": {}
382215          },
382216          "pedigree": {},
382217          "externalReferences": [
382218            {
382219              "url": "git+https://github.com/iarna/unique-filename.git",
382220              "type": "distribution"
382221            },
382222            {
382223              "url": "https://github.com/iarna/unique-filename",
382224              "type": "website"
382225            }
382226          ],
382227          "evidence": {},
382228          "signature": {
382229            "signature": {
382230              "publicKey": {}
382231            }
382232          },
382233          "modelCard": {
382234            "modelParameters": {
382235              "approach": {}
382236            },
382237            "quantitativeAnalysis": {
382238              "graphics": {}
382239            },
382240            "considerations": {}
382241          }
382242        },
382243        {
382244          "type": "library",
382245          "bom-ref": "pkg:npm/unique-slug@2.0.0?package-id=924ca3204f5aad87",
382246          "supplier": {},
382247          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org)",
382248          "name": "unique-slug",
382249          "version": "2.0.0",
382250          "description": "Generate a unique character string suitible for use in files and URLs.",
382251          "licenses": [
382252            {
382253              "license": {
382254                "id": "ISC"
382255              }
382256            }
382257          ],
382258          "cpe": "cpe:2.3:a:unique-slug:unique-slug:2.0.0:*:*:*:*:*:*:*",
382259          "purl": "pkg:npm/unique-slug@2.0.0",
382260          "swid": {
382261            "attachment": {}
382262          },
382263          "pedigree": {},
382264          "externalReferences": [
382265            {
382266              "url": "git://github.com/iarna/unique-slug.git",
382267              "type": "distribution"
382268            },
382269            {
382270              "url": "https://github.com/iarna/unique-slug#readme",
382271              "type": "website"
382272            }
382273          ],
382274          "evidence": {},
382275          "signature": {
382276            "signature": {
382277              "publicKey": {}
382278            }
382279          },
382280          "modelCard": {
382281            "modelParameters": {
382282              "approach": {}
382283            },
382284            "quantitativeAnalysis": {
382285              "graphics": {}
382286            },
382287            "considerations": {}
382288          }
382289        },
382290        {
382291          "type": "library",
382292          "bom-ref": "pkg:npm/unique-string@1.0.0?package-id=4e6b7ebbf2d6b0b2",
382293          "supplier": {},
382294          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
382295          "name": "unique-string",
382296          "version": "1.0.0",
382297          "description": "Generate a unique random string",
382298          "licenses": [
382299            {
382300              "license": {
382301                "id": "MIT"
382302              }
382303            }
382304          ],
382305          "cpe": "cpe:2.3:a:unique-string:unique-string:1.0.0:*:*:*:*:*:*:*",
382306          "purl": "pkg:npm/unique-string@1.0.0",
382307          "swid": {
382308            "attachment": {}
382309          },
382310          "pedigree": {},
382311          "externalReferences": [
382312            {
382313              "url": "git+https://github.com/sindresorhus/unique-string.git",
382314              "type": "distribution"
382315            },
382316            {
382317              "url": "https://github.com/sindresorhus/unique-string#readme",
382318              "type": "website"
382319            }
382320          ],
382321          "evidence": {},
382322          "signature": {
382323            "signature": {
382324              "publicKey": {}
382325            }
382326          },
382327          "modelCard": {
382328            "modelParameters": {
382329              "approach": {}
382330            },
382331            "quantitativeAnalysis": {
382332              "graphics": {}
382333            },
382334            "considerations": {}
382335          }
382336        },
382337        {
382338          "type": "library",
382339          "bom-ref": "pkg:npm/unpipe@1.0.0?package-id=5fde8937a7c37a7f",
382340          "supplier": {},
382341          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
382342          "name": "unpipe",
382343          "version": "1.0.0",
382344          "description": "Unpipe a stream from all destinations",
382345          "licenses": [
382346            {
382347              "license": {
382348                "id": "MIT"
382349              }
382350            }
382351          ],
382352          "cpe": "cpe:2.3:a:stream-utils:unpipe:1.0.0:*:*:*:*:*:*:*",
382353          "purl": "pkg:npm/unpipe@1.0.0",
382354          "swid": {
382355            "attachment": {}
382356          },
382357          "pedigree": {},
382358          "externalReferences": [
382359            {
382360              "url": "git+https://github.com/stream-utils/unpipe.git",
382361              "type": "distribution"
382362            },
382363            {
382364              "url": "https://github.com/stream-utils/unpipe#readme",
382365              "type": "website"
382366            }
382367          ],
382368          "evidence": {},
382369          "signature": {
382370            "signature": {
382371              "publicKey": {}
382372            }
382373          },
382374          "modelCard": {
382375            "modelParameters": {
382376              "approach": {}
382377            },
382378            "quantitativeAnalysis": {
382379              "graphics": {}
382380            },
382381            "considerations": {}
382382          }
382383        },
382384        {
382385          "type": "library",
382386          "bom-ref": "pkg:npm/unpipe@1.0.0?package-id=6e84e73fed0f90d9",
382387          "supplier": {},
382388          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
382389          "name": "unpipe",
382390          "version": "1.0.0",
382391          "description": "Unpipe a stream from all destinations",
382392          "licenses": [
382393            {
382394              "license": {
382395                "id": "MIT"
382396              }
382397            }
382398          ],
382399          "cpe": "cpe:2.3:a:stream-utils:unpipe:1.0.0:*:*:*:*:*:*:*",
382400          "purl": "pkg:npm/unpipe@1.0.0",
382401          "swid": {
382402            "attachment": {}
382403          },
382404          "pedigree": {},
382405          "externalReferences": [
382406            {
382407              "url": "git+https://github.com/stream-utils/unpipe.git",
382408              "type": "distribution"
382409            },
382410            {
382411              "url": "https://github.com/stream-utils/unpipe#readme",
382412              "type": "website"
382413            }
382414          ],
382415          "evidence": {},
382416          "signature": {
382417            "signature": {
382418              "publicKey": {}
382419            }
382420          },
382421          "modelCard": {
382422            "modelParameters": {
382423              "approach": {}
382424            },
382425            "quantitativeAnalysis": {
382426              "graphics": {}
382427            },
382428            "considerations": {}
382429          }
382430        },
382431        {
382432          "type": "library",
382433          "bom-ref": "pkg:npm/unzip-response@2.0.1?package-id=2f2960808396cad4",
382434          "supplier": {},
382435          "name": "unzip-response",
382436          "version": "2.0.1",
382437          "description": "Unzip a HTTP response if needed",
382438          "licenses": [
382439            {
382440              "license": {
382441                "id": "MIT"
382442              }
382443            }
382444          ],
382445          "cpe": "cpe:2.3:a:unzip-response:unzip-response:2.0.1:*:*:*:*:*:*:*",
382446          "purl": "pkg:npm/unzip-response@2.0.1",
382447          "swid": {
382448            "attachment": {}
382449          },
382450          "pedigree": {},
382451          "externalReferences": [
382452            {
382453              "url": "git+https://github.com/sindresorhus/unzip-response.git",
382454              "type": "distribution"
382455            },
382456            {
382457              "url": "https://github.com/sindresorhus/unzip-response#readme",
382458              "type": "website"
382459            }
382460          ],
382461          "evidence": {},
382462          "signature": {
382463            "signature": {
382464              "publicKey": {}
382465            }
382466          },
382467          "modelCard": {
382468            "modelParameters": {
382469              "approach": {}
382470            },
382471            "quantitativeAnalysis": {
382472              "graphics": {}
382473            },
382474            "considerations": {}
382475          }
382476        },
382477        {
382478          "type": "library",
382479          "bom-ref": "pkg:npm/update-notifier@2.5.0?package-id=e826782630303ce6",
382480          "supplier": {},
382481          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
382482          "name": "update-notifier",
382483          "version": "2.5.0",
382484          "description": "Update notifications for your CLI app",
382485          "licenses": [
382486            {
382487              "license": {
382488                "id": "BSD-2-Clause"
382489              }
382490            }
382491          ],
382492          "cpe": "cpe:2.3:a:update-notifier:update-notifier:2.5.0:*:*:*:*:*:*:*",
382493          "purl": "pkg:npm/update-notifier@2.5.0",
382494          "swid": {
382495            "attachment": {}
382496          },
382497          "pedigree": {},
382498          "externalReferences": [
382499            {
382500              "url": "git+https://github.com/yeoman/update-notifier.git",
382501              "type": "distribution"
382502            },
382503            {
382504              "url": "https://github.com/yeoman/update-notifier#readme",
382505              "type": "website"
382506            }
382507          ],
382508          "evidence": {},
382509          "signature": {
382510            "signature": {
382511              "publicKey": {}
382512            }
382513          },
382514          "modelCard": {
382515            "modelParameters": {
382516              "approach": {}
382517            },
382518            "quantitativeAnalysis": {
382519              "graphics": {}
382520            },
382521            "considerations": {}
382522          }
382523        },
382524        {
382525          "type": "library",
382526          "bom-ref": "pkg:npm/uri-js@4.4.1?package-id=dfad1f1bc56159f9",
382527          "supplier": {},
382528          "author": "Gary Court \u003cgary.court@gmail.com\u003e",
382529          "name": "uri-js",
382530          "version": "4.4.1",
382531          "description": "An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.",
382532          "licenses": [
382533            {
382534              "license": {
382535                "id": "BSD-2-Clause"
382536              }
382537            }
382538          ],
382539          "cpe": "cpe:2.3:a:garycourt:uri-js:4.4.1:*:*:*:*:*:*:*",
382540          "purl": "pkg:npm/uri-js@4.4.1",
382541          "swid": {
382542            "attachment": {}
382543          },
382544          "pedigree": {},
382545          "externalReferences": [
382546            {
382547              "url": "git+ssh://git@github.com/garycourt/uri-js.git",
382548              "type": "distribution"
382549            },
382550            {
382551              "url": "https://github.com/garycourt/uri-js",
382552              "type": "website"
382553            }
382554          ],
382555          "evidence": {},
382556          "signature": {
382557            "signature": {
382558              "publicKey": {}
382559            }
382560          },
382561          "modelCard": {
382562            "modelParameters": {
382563              "approach": {}
382564            },
382565            "quantitativeAnalysis": {
382566              "graphics": {}
382567            },
382568            "considerations": {}
382569          }
382570        },
382571        {
382572          "type": "library",
382573          "bom-ref": "pkg:npm/uri-js@4.4.1?package-id=14b9611f4164946d",
382574          "supplier": {},
382575          "author": "Gary Court \u003cgary.court@gmail.com\u003e",
382576          "name": "uri-js",
382577          "version": "4.4.1",
382578          "description": "An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.",
382579          "licenses": [
382580            {
382581              "license": {
382582                "id": "BSD-2-Clause"
382583              }
382584            }
382585          ],
382586          "cpe": "cpe:2.3:a:garycourt:uri-js:4.4.1:*:*:*:*:*:*:*",
382587          "purl": "pkg:npm/uri-js@4.4.1",
382588          "swid": {
382589            "attachment": {}
382590          },
382591          "pedigree": {},
382592          "externalReferences": [
382593            {
382594              "url": "git+ssh://git@github.com/garycourt/uri-js.git",
382595              "type": "distribution"
382596            },
382597            {
382598              "url": "https://github.com/garycourt/uri-js",
382599              "type": "website"
382600            }
382601          ],
382602          "evidence": {},
382603          "signature": {
382604            "signature": {
382605              "publicKey": {}
382606            }
382607          },
382608          "modelCard": {
382609            "modelParameters": {
382610              "approach": {}
382611            },
382612            "quantitativeAnalysis": {
382613              "graphics": {}
382614            },
382615            "considerations": {}
382616          }
382617        },
382618        {
382619          "type": "library",
382620          "bom-ref": "pkg:npm/url-parse@1.5.1?package-id=b72a7ea449ac5253",
382621          "supplier": {},
382622          "author": "Arnout Kazemier",
382623          "name": "url-parse",
382624          "version": "1.5.1",
382625          "description": "Small footprint URL parser that works seamlessly across Node.js and browser environments",
382626          "licenses": [
382627            {
382628              "license": {
382629                "id": "MIT"
382630              }
382631            }
382632          ],
382633          "cpe": "cpe:2.3:a:unshiftio:url-parse:1.5.1:*:*:*:*:*:*:*",
382634          "purl": "pkg:npm/url-parse@1.5.1",
382635          "swid": {
382636            "attachment": {}
382637          },
382638          "pedigree": {},
382639          "externalReferences": [
382640            {
382641              "url": "git+https://github.com/unshiftio/url-parse.git",
382642              "type": "distribution"
382643            },
382644            {
382645              "url": "https://github.com/unshiftio/url-parse#readme",
382646              "type": "website"
382647            }
382648          ],
382649          "evidence": {},
382650          "signature": {
382651            "signature": {
382652              "publicKey": {}
382653            }
382654          },
382655          "modelCard": {
382656            "modelParameters": {
382657              "approach": {}
382658            },
382659            "quantitativeAnalysis": {
382660              "graphics": {}
382661            },
382662            "considerations": {}
382663          }
382664        },
382665        {
382666          "type": "library",
382667          "bom-ref": "pkg:npm/url-parse-lax@1.0.0?package-id=66c52cc773273a82",
382668          "supplier": {},
382669          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
382670          "name": "url-parse-lax",
382671          "version": "1.0.0",
382672          "description": "url.parse() with support for protocol-less URLs \u0026 IPs",
382673          "licenses": [
382674            {
382675              "license": {
382676                "id": "MIT"
382677              }
382678            }
382679          ],
382680          "cpe": "cpe:2.3:a:url-parse-lax:url-parse-lax:1.0.0:*:*:*:*:*:*:*",
382681          "purl": "pkg:npm/url-parse-lax@1.0.0",
382682          "swid": {
382683            "attachment": {}
382684          },
382685          "pedigree": {},
382686          "externalReferences": [
382687            {
382688              "url": "git+https://github.com/sindresorhus/url-parse-lax.git",
382689              "type": "distribution"
382690            },
382691            {
382692              "url": "https://github.com/sindresorhus/url-parse-lax#readme",
382693              "type": "website"
382694            }
382695          ],
382696          "evidence": {},
382697          "signature": {
382698            "signature": {
382699              "publicKey": {}
382700            }
382701          },
382702          "modelCard": {
382703            "modelParameters": {
382704              "approach": {}
382705            },
382706            "quantitativeAnalysis": {
382707              "graphics": {}
382708            },
382709            "considerations": {}
382710          }
382711        },
382712        {
382713          "type": "library",
382714          "bom-ref": "pkg:npm/url-value-parser@2.0.3?package-id=4cc7ab4185879cb9",
382715          "supplier": {},
382716          "author": "Konstantin Pogorelov \u003cor@pluseq.com\u003e",
382717          "name": "url-value-parser",
382718          "version": "2.0.3",
382719          "description": "extracts and replaces values and IDs in URLs",
382720          "licenses": [
382721            {
382722              "license": {
382723                "id": "WTFPL"
382724              }
382725            }
382726          ],
382727          "cpe": "cpe:2.3:a:url-value-parser:url-value-parser:2.0.3:*:*:*:*:*:*:*",
382728          "purl": "pkg:npm/url-value-parser@2.0.3",
382729          "swid": {
382730            "attachment": {}
382731          },
382732          "pedigree": {},
382733          "externalReferences": [
382734            {
382735              "url": "git+https://github.com/disjunction/url-value-parser.git",
382736              "type": "distribution"
382737            },
382738            {
382739              "url": "https://github.com/disjunction/url-value-parser#readme",
382740              "type": "website"
382741            }
382742          ],
382743          "evidence": {},
382744          "signature": {
382745            "signature": {
382746              "publicKey": {}
382747            }
382748          },
382749          "modelCard": {
382750            "modelParameters": {
382751              "approach": {}
382752            },
382753            "quantitativeAnalysis": {
382754              "graphics": {}
382755            },
382756            "considerations": {}
382757          }
382758        },
382759        {
382760          "type": "library",
382761          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=adcfe60f42b3bf40",
382762          "supplier": {},
382763          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
382764          "name": "util-deprecate",
382765          "version": "1.0.2",
382766          "description": "The Node.js `util.deprecate()` function with browser support",
382767          "licenses": [
382768            {
382769              "license": {
382770                "id": "MIT"
382771              }
382772            }
382773          ],
382774          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
382775          "purl": "pkg:npm/util-deprecate@1.0.2",
382776          "swid": {
382777            "attachment": {}
382778          },
382779          "pedigree": {},
382780          "externalReferences": [
382781            {
382782              "url": "git://github.com/TooTallNate/util-deprecate.git",
382783              "type": "distribution"
382784            },
382785            {
382786              "url": "https://github.com/TooTallNate/util-deprecate",
382787              "type": "website"
382788            }
382789          ],
382790          "evidence": {},
382791          "signature": {
382792            "signature": {
382793              "publicKey": {}
382794            }
382795          },
382796          "modelCard": {
382797            "modelParameters": {
382798              "approach": {}
382799            },
382800            "quantitativeAnalysis": {
382801              "graphics": {}
382802            },
382803            "considerations": {}
382804          }
382805        },
382806        {
382807          "type": "library",
382808          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=ecf076cf26fe73d0",
382809          "supplier": {},
382810          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
382811          "name": "util-deprecate",
382812          "version": "1.0.2",
382813          "description": "The Node.js `util.deprecate()` function with browser support",
382814          "licenses": [
382815            {
382816              "license": {
382817                "id": "MIT"
382818              }
382819            }
382820          ],
382821          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
382822          "purl": "pkg:npm/util-deprecate@1.0.2",
382823          "swid": {
382824            "attachment": {}
382825          },
382826          "pedigree": {},
382827          "externalReferences": [
382828            {
382829              "url": "git://github.com/TooTallNate/util-deprecate.git",
382830              "type": "distribution"
382831            },
382832            {
382833              "url": "https://github.com/TooTallNate/util-deprecate",
382834              "type": "website"
382835            }
382836          ],
382837          "evidence": {},
382838          "signature": {
382839            "signature": {
382840              "publicKey": {}
382841            }
382842          },
382843          "modelCard": {
382844            "modelParameters": {
382845              "approach": {}
382846            },
382847            "quantitativeAnalysis": {
382848              "graphics": {}
382849            },
382850            "considerations": {}
382851          }
382852        },
382853        {
382854          "type": "library",
382855          "bom-ref": "pkg:npm/util-extend@1.0.3?package-id=b90581678f776d40",
382856          "supplier": {},
382857          "name": "util-extend",
382858          "version": "1.0.3",
382859          "description": "Node's internal object extension function",
382860          "licenses": [
382861            {
382862              "license": {
382863                "id": "MIT"
382864              }
382865            }
382866          ],
382867          "cpe": "cpe:2.3:a:util-extend:util-extend:1.0.3:*:*:*:*:*:*:*",
382868          "purl": "pkg:npm/util-extend@1.0.3",
382869          "swid": {
382870            "attachment": {}
382871          },
382872          "pedigree": {},
382873          "externalReferences": [
382874            {
382875              "url": "git://github.com/isaacs/util-extend.git",
382876              "type": "distribution"
382877            },
382878            {
382879              "url": "https://github.com/isaacs/util-extend#readme",
382880              "type": "website"
382881            }
382882          ],
382883          "evidence": {},
382884          "signature": {
382885            "signature": {
382886              "publicKey": {}
382887            }
382888          },
382889          "modelCard": {
382890            "modelParameters": {
382891              "approach": {}
382892            },
382893            "quantitativeAnalysis": {
382894              "graphics": {}
382895            },
382896            "considerations": {}
382897          }
382898        },
382899        {
382900          "type": "library",
382901          "bom-ref": "pkg:npm/util-promisify@2.1.0?package-id=a64f5f12cac515a2",
382902          "supplier": {},
382903          "name": "util-promisify",
382904          "version": "2.1.0",
382905          "description": "Node 8's util.promisify, as a node module",
382906          "licenses": [
382907            {
382908              "license": {
382909                "id": "MIT"
382910              }
382911            }
382912          ],
382913          "cpe": "cpe:2.3:a:util-promisify:util-promisify:2.1.0:*:*:*:*:*:*:*",
382914          "purl": "pkg:npm/util-promisify@2.1.0",
382915          "swid": {
382916            "attachment": {}
382917          },
382918          "pedigree": {},
382919          "externalReferences": [
382920            {
382921              "url": "git+https://github.com/juliangruber/util-promisify.git",
382922              "type": "distribution"
382923            },
382924            {
382925              "url": "https://github.com/juliangruber/util-promisify#readme",
382926              "type": "website"
382927            }
382928          ],
382929          "evidence": {},
382930          "signature": {
382931            "signature": {
382932              "publicKey": {}
382933            }
382934          },
382935          "modelCard": {
382936            "modelParameters": {
382937              "approach": {}
382938            },
382939            "quantitativeAnalysis": {
382940              "graphics": {}
382941            },
382942            "considerations": {}
382943          }
382944        },
382945        {
382946          "type": "library",
382947          "bom-ref": "pkg:npm/utils-merge@1.0.1?package-id=2c445cae22e4baa6",
382948          "supplier": {},
382949          "author": "Jared Hanson \u003cjaredhanson@gmail.com\u003e (http://www.jaredhanson.net/)",
382950          "name": "utils-merge",
382951          "version": "1.0.1",
382952          "description": "merge() utility function",
382953          "licenses": [
382954            {
382955              "license": {
382956                "id": "MIT"
382957              }
382958            }
382959          ],
382960          "cpe": "cpe:2.3:a:jaredhanson:utils-merge:1.0.1:*:*:*:*:*:*:*",
382961          "purl": "pkg:npm/utils-merge@1.0.1",
382962          "swid": {
382963            "attachment": {}
382964          },
382965          "pedigree": {},
382966          "externalReferences": [
382967            {
382968              "url": "git://github.com/jaredhanson/utils-merge.git",
382969              "type": "distribution"
382970            },
382971            {
382972              "url": "https://github.com/jaredhanson/utils-merge#readme",
382973              "type": "website"
382974            }
382975          ],
382976          "evidence": {},
382977          "signature": {
382978            "signature": {
382979              "publicKey": {}
382980            }
382981          },
382982          "modelCard": {
382983            "modelParameters": {
382984              "approach": {}
382985            },
382986            "quantitativeAnalysis": {
382987              "graphics": {}
382988            },
382989            "considerations": {}
382990          }
382991        },
382992        {
382993          "type": "library",
382994          "bom-ref": "pkg:npm/uuid@3.4.0?package-id=ed49cf5cc9fe5cd4",
382995          "supplier": {},
382996          "name": "uuid",
382997          "version": "3.4.0",
382998          "description": "RFC4122 (v1, v4, and v5) UUIDs",
382999          "licenses": [
383000            {
383001              "license": {
383002                "id": "MIT"
383003              }
383004            }
383005          ],
383006          "cpe": "cpe:2.3:a:uuidjs:uuid:3.4.0:*:*:*:*:*:*:*",
383007          "purl": "pkg:npm/uuid@3.4.0",
383008          "swid": {
383009            "attachment": {}
383010          },
383011          "pedigree": {},
383012          "externalReferences": [
383013            {
383014              "url": "git+https://github.com/uuidjs/uuid.git",
383015              "type": "distribution"
383016            },
383017            {
383018              "url": "https://github.com/uuidjs/uuid#readme",
383019              "type": "website"
383020            }
383021          ],
383022          "evidence": {},
383023          "signature": {
383024            "signature": {
383025              "publicKey": {}
383026            }
383027          },
383028          "modelCard": {
383029            "modelParameters": {
383030              "approach": {}
383031            },
383032            "quantitativeAnalysis": {
383033              "graphics": {}
383034            },
383035            "considerations": {}
383036          }
383037        },
383038        {
383039          "type": "library",
383040          "bom-ref": "pkg:npm/uuid@3.4.0?package-id=c5b5b6ef09fd8294",
383041          "supplier": {},
383042          "name": "uuid",
383043          "version": "3.4.0",
383044          "description": "RFC4122 (v1, v4, and v5) UUIDs",
383045          "licenses": [
383046            {
383047              "license": {
383048                "id": "MIT"
383049              }
383050            }
383051          ],
383052          "cpe": "cpe:2.3:a:uuidjs:uuid:3.4.0:*:*:*:*:*:*:*",
383053          "purl": "pkg:npm/uuid@3.4.0",
383054          "swid": {
383055            "attachment": {}
383056          },
383057          "pedigree": {},
383058          "externalReferences": [
383059            {
383060              "url": "git+https://github.com/uuidjs/uuid.git",
383061              "type": "distribution"
383062            },
383063            {
383064              "url": "https://github.com/uuidjs/uuid#readme",
383065              "type": "website"
383066            }
383067          ],
383068          "evidence": {},
383069          "signature": {
383070            "signature": {
383071              "publicKey": {}
383072            }
383073          },
383074          "modelCard": {
383075            "modelParameters": {
383076              "approach": {}
383077            },
383078            "quantitativeAnalysis": {
383079              "graphics": {}
383080            },
383081            "considerations": {}
383082          }
383083        },
383084        {
383085          "type": "library",
383086          "bom-ref": "pkg:npm/uuid@8.3.2?package-id=95a83579b4e2b728",
383087          "supplier": {},
383088          "name": "uuid",
383089          "version": "8.3.2",
383090          "description": "RFC4122 (v1, v4, and v5) UUIDs",
383091          "licenses": [
383092            {
383093              "license": {
383094                "id": "MIT"
383095              }
383096            }
383097          ],
383098          "cpe": "cpe:2.3:a:uuidjs:uuid:8.3.2:*:*:*:*:*:*:*",
383099          "purl": "pkg:npm/uuid@8.3.2",
383100          "swid": {
383101            "attachment": {}
383102          },
383103          "pedigree": {},
383104          "externalReferences": [
383105            {
383106              "url": "git+https://github.com/uuidjs/uuid.git",
383107              "type": "distribution"
383108            },
383109            {
383110              "url": "https://github.com/uuidjs/uuid#readme",
383111              "type": "website"
383112            }
383113          ],
383114          "evidence": {},
383115          "signature": {
383116            "signature": {
383117              "publicKey": {}
383118            }
383119          },
383120          "modelCard": {
383121            "modelParameters": {
383122              "approach": {}
383123            },
383124            "quantitativeAnalysis": {
383125              "graphics": {}
383126            },
383127            "considerations": {}
383128          }
383129        },
383130        {
383131          "type": "library",
383132          "bom-ref": "pkg:npm/validate-npm-package-license@3.0.4?package-id=33663eb8a236f357",
383133          "supplier": {},
383134          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
383135          "name": "validate-npm-package-license",
383136          "version": "3.0.4",
383137          "description": "Give me a string and I'll tell you if it's a valid npm package license string",
383138          "licenses": [
383139            {
383140              "license": {
383141                "id": "Apache-2.0"
383142              }
383143            }
383144          ],
383145          "cpe": "cpe:2.3:a:validate-npm-package-license:validate-npm-package-license:3.0.4:*:*:*:*:*:*:*",
383146          "purl": "pkg:npm/validate-npm-package-license@3.0.4",
383147          "swid": {
383148            "attachment": {}
383149          },
383150          "pedigree": {},
383151          "externalReferences": [
383152            {
383153              "url": "git+https://github.com/kemitchell/validate-npm-package-license.js.git",
383154              "type": "distribution"
383155            },
383156            {
383157              "url": "https://github.com/kemitchell/validate-npm-package-license.js#readme",
383158              "type": "website"
383159            }
383160          ],
383161          "evidence": {},
383162          "signature": {
383163            "signature": {
383164              "publicKey": {}
383165            }
383166          },
383167          "modelCard": {
383168            "modelParameters": {
383169              "approach": {}
383170            },
383171            "quantitativeAnalysis": {
383172              "graphics": {}
383173            },
383174            "considerations": {}
383175          }
383176        },
383177        {
383178          "type": "library",
383179          "bom-ref": "pkg:npm/validate-npm-package-name@3.0.0?package-id=57f9fd66d4ad5701",
383180          "supplier": {},
383181          "author": "zeke",
383182          "name": "validate-npm-package-name",
383183          "version": "3.0.0",
383184          "description": "Give me a string and I'll tell you if it's a valid npm package name",
383185          "licenses": [
383186            {
383187              "license": {
383188                "id": "ISC"
383189              }
383190            }
383191          ],
383192          "cpe": "cpe:2.3:a:validate-npm-package-name:validate-npm-package-name:3.0.0:*:*:*:*:*:*:*",
383193          "purl": "pkg:npm/validate-npm-package-name@3.0.0",
383194          "swid": {
383195            "attachment": {}
383196          },
383197          "pedigree": {},
383198          "externalReferences": [
383199            {
383200              "url": "git+https://github.com/npm/validate-npm-package-name.git",
383201              "type": "distribution"
383202            },
383203            {
383204              "url": "https://github.com/npm/validate-npm-package-name",
383205              "type": "website"
383206            }
383207          ],
383208          "evidence": {},
383209          "signature": {
383210            "signature": {
383211              "publicKey": {}
383212            }
383213          },
383214          "modelCard": {
383215            "modelParameters": {
383216              "approach": {}
383217            },
383218            "quantitativeAnalysis": {
383219              "graphics": {}
383220            },
383221            "considerations": {}
383222          }
383223        },
383224        {
383225          "type": "library",
383226          "bom-ref": "pkg:npm/validator@13.0.0?package-id=c822b35e061ecd32",
383227          "supplier": {},
383228          "author": "Chris O'Hara \u003ccohara87@gmail.com\u003e",
383229          "name": "validator",
383230          "version": "13.0.0",
383231          "description": "String validation and sanitization",
383232          "licenses": [
383233            {
383234              "license": {
383235                "id": "MIT"
383236              }
383237            }
383238          ],
383239          "cpe": "cpe:2.3:a:validator:validator:13.0.0:*:*:*:*:*:*:*",
383240          "purl": "pkg:npm/validator@13.0.0",
383241          "swid": {
383242            "attachment": {}
383243          },
383244          "pedigree": {},
383245          "externalReferences": [
383246            {
383247              "url": "git+https://github.com/chriso/validator.js.git",
383248              "type": "distribution"
383249            },
383250            {
383251              "url": "https://github.com/chriso/validator.js",
383252              "type": "website"
383253            }
383254          ],
383255          "evidence": {},
383256          "signature": {
383257            "signature": {
383258              "publicKey": {}
383259            }
383260          },
383261          "modelCard": {
383262            "modelParameters": {
383263              "approach": {}
383264            },
383265            "quantitativeAnalysis": {
383266              "graphics": {}
383267            },
383268            "considerations": {}
383269          }
383270        },
383271        {
383272          "type": "library",
383273          "bom-ref": "pkg:npm/vary@1.1.2?package-id=b22a107883a17598",
383274          "supplier": {},
383275          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
383276          "name": "vary",
383277          "version": "1.1.2",
383278          "description": "Manipulate the HTTP Vary header",
383279          "licenses": [
383280            {
383281              "license": {
383282                "id": "MIT"
383283              }
383284            }
383285          ],
383286          "cpe": "cpe:2.3:a:jshttp:vary:1.1.2:*:*:*:*:*:*:*",
383287          "purl": "pkg:npm/vary@1.1.2",
383288          "swid": {
383289            "attachment": {}
383290          },
383291          "pedigree": {},
383292          "externalReferences": [
383293            {
383294              "url": "git+https://github.com/jshttp/vary.git",
383295              "type": "distribution"
383296            },
383297            {
383298              "url": "https://github.com/jshttp/vary#readme",
383299              "type": "website"
383300            }
383301          ],
383302          "evidence": {},
383303          "signature": {
383304            "signature": {
383305              "publicKey": {}
383306            }
383307          },
383308          "modelCard": {
383309            "modelParameters": {
383310              "approach": {}
383311            },
383312            "quantitativeAnalysis": {
383313              "graphics": {}
383314            },
383315            "considerations": {}
383316          }
383317        },
383318        {
383319          "type": "library",
383320          "bom-ref": "pkg:npm/verror@1.10.0?package-id=de946bd784d35908",
383321          "supplier": {},
383322          "name": "verror",
383323          "version": "1.10.0",
383324          "description": "richer JavaScript errors",
383325          "licenses": [
383326            {
383327              "license": {
383328                "id": "MIT"
383329              }
383330            }
383331          ],
383332          "cpe": "cpe:2.3:a:davepacheco:verror:1.10.0:*:*:*:*:*:*:*",
383333          "purl": "pkg:npm/verror@1.10.0",
383334          "swid": {
383335            "attachment": {}
383336          },
383337          "pedigree": {},
383338          "externalReferences": [
383339            {
383340              "url": "git://github.com/davepacheco/node-verror.git",
383341              "type": "distribution"
383342            },
383343            {
383344              "url": "https://github.com/davepacheco/node-verror#readme",
383345              "type": "website"
383346            }
383347          ],
383348          "evidence": {},
383349          "signature": {
383350            "signature": {
383351              "publicKey": {}
383352            }
383353          },
383354          "modelCard": {
383355            "modelParameters": {
383356              "approach": {}
383357            },
383358            "quantitativeAnalysis": {
383359              "graphics": {}
383360            },
383361            "considerations": {}
383362          }
383363        },
383364        {
383365          "type": "library",
383366          "bom-ref": "pkg:npm/verror@1.10.0?package-id=be840953a9e5ca6a",
383367          "supplier": {},
383368          "name": "verror",
383369          "version": "1.10.0",
383370          "description": "richer JavaScript errors",
383371          "licenses": [
383372            {
383373              "license": {
383374                "id": "MIT"
383375              }
383376            }
383377          ],
383378          "cpe": "cpe:2.3:a:davepacheco:verror:1.10.0:*:*:*:*:*:*:*",
383379          "purl": "pkg:npm/verror@1.10.0",
383380          "swid": {
383381            "attachment": {}
383382          },
383383          "pedigree": {},
383384          "externalReferences": [
383385            {
383386              "url": "git://github.com/davepacheco/node-verror.git",
383387              "type": "distribution"
383388            },
383389            {
383390              "url": "https://github.com/davepacheco/node-verror#readme",
383391              "type": "website"
383392            }
383393          ],
383394          "evidence": {},
383395          "signature": {
383396            "signature": {
383397              "publicKey": {}
383398            }
383399          },
383400          "modelCard": {
383401            "modelParameters": {
383402              "approach": {}
383403            },
383404            "quantitativeAnalysis": {
383405              "graphics": {}
383406            },
383407            "considerations": {}
383408          }
383409        },
383410        {
383411          "type": "library",
383412          "bom-ref": "pkg:npm/wcwidth@1.0.1?package-id=ee54c63162090e16",
383413          "supplier": {},
383414          "author": "Tim Oxley",
383415          "name": "wcwidth",
383416          "version": "1.0.1",
383417          "description": "Port of C's wcwidth() and wcswidth()",
383418          "licenses": [
383419            {
383420              "license": {
383421                "id": "MIT"
383422              }
383423            }
383424          ],
383425          "cpe": "cpe:2.3:a:timoxley:wcwidth:1.0.1:*:*:*:*:*:*:*",
383426          "purl": "pkg:npm/wcwidth@1.0.1",
383427          "swid": {
383428            "attachment": {}
383429          },
383430          "pedigree": {},
383431          "externalReferences": [
383432            {
383433              "url": "git+https://github.com/timoxley/wcwidth.git",
383434              "type": "distribution"
383435            },
383436            {
383437              "url": "https://github.com/timoxley/wcwidth#readme",
383438              "type": "website"
383439            }
383440          ],
383441          "evidence": {},
383442          "signature": {
383443            "signature": {
383444              "publicKey": {}
383445            }
383446          },
383447          "modelCard": {
383448            "modelParameters": {
383449              "approach": {}
383450            },
383451            "quantitativeAnalysis": {
383452              "graphics": {}
383453            },
383454            "considerations": {}
383455          }
383456        },
383457        {
383458          "type": "library",
383459          "bom-ref": "pkg:npm/which@1.3.1?package-id=ace883b09cbe1ce",
383460          "supplier": {},
383461          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
383462          "name": "which",
383463          "version": "1.3.1",
383464          "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
383465          "licenses": [
383466            {
383467              "license": {
383468                "id": "ISC"
383469              }
383470            }
383471          ],
383472          "cpe": "cpe:2.3:a:isaacs:which:1.3.1:*:*:*:*:*:*:*",
383473          "purl": "pkg:npm/which@1.3.1",
383474          "swid": {
383475            "attachment": {}
383476          },
383477          "pedigree": {},
383478          "externalReferences": [
383479            {
383480              "url": "git://github.com/isaacs/node-which.git",
383481              "type": "distribution"
383482            },
383483            {
383484              "url": "https://github.com/isaacs/node-which#readme",
383485              "type": "website"
383486            }
383487          ],
383488          "evidence": {},
383489          "signature": {
383490            "signature": {
383491              "publicKey": {}
383492            }
383493          },
383494          "modelCard": {
383495            "modelParameters": {
383496              "approach": {}
383497            },
383498            "quantitativeAnalysis": {
383499              "graphics": {}
383500            },
383501            "considerations": {}
383502          }
383503        },
383504        {
383505          "type": "library",
383506          "bom-ref": "pkg:npm/which-module@2.0.0?package-id=5db3efe3b2bc298b",
383507          "supplier": {},
383508          "author": "nexdrew",
383509          "name": "which-module",
383510          "version": "2.0.0",
383511          "description": "Find the module object for something that was require()d",
383512          "licenses": [
383513            {
383514              "license": {
383515                "id": "ISC"
383516              }
383517            }
383518          ],
383519          "cpe": "cpe:2.3:a:which-module:which-module:2.0.0:*:*:*:*:*:*:*",
383520          "purl": "pkg:npm/which-module@2.0.0",
383521          "swid": {
383522            "attachment": {}
383523          },
383524          "pedigree": {},
383525          "externalReferences": [
383526            {
383527              "url": "git+https://github.com/nexdrew/which-module.git",
383528              "type": "distribution"
383529            },
383530            {
383531              "url": "https://github.com/nexdrew/which-module#readme",
383532              "type": "website"
383533            }
383534          ],
383535          "evidence": {},
383536          "signature": {
383537            "signature": {
383538              "publicKey": {}
383539            }
383540          },
383541          "modelCard": {
383542            "modelParameters": {
383543              "approach": {}
383544            },
383545            "quantitativeAnalysis": {
383546              "graphics": {}
383547            },
383548            "considerations": {}
383549          }
383550        },
383551        {
383552          "type": "library",
383553          "bom-ref": "pkg:npm/wide-align@1.1.2?package-id=7a2f1fc2f2c8bfd3",
383554          "supplier": {},
383555          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
383556          "name": "wide-align",
383557          "version": "1.1.2",
383558          "description": "A wide-character aware text alignment function for use on the console or with fixed width fonts.",
383559          "licenses": [
383560            {
383561              "license": {
383562                "id": "ISC"
383563              }
383564            }
383565          ],
383566          "cpe": "cpe:2.3:a:wide-align:wide-align:1.1.2:*:*:*:*:*:*:*",
383567          "purl": "pkg:npm/wide-align@1.1.2",
383568          "swid": {
383569            "attachment": {}
383570          },
383571          "pedigree": {},
383572          "externalReferences": [
383573            {
383574              "url": "git+https://github.com/iarna/wide-align.git",
383575              "type": "distribution"
383576            },
383577            {
383578              "url": "https://github.com/iarna/wide-align#readme",
383579              "type": "website"
383580            }
383581          ],
383582          "evidence": {},
383583          "signature": {
383584            "signature": {
383585              "publicKey": {}
383586            }
383587          },
383588          "modelCard": {
383589            "modelParameters": {
383590              "approach": {}
383591            },
383592            "quantitativeAnalysis": {
383593              "graphics": {}
383594            },
383595            "considerations": {}
383596          }
383597        },
383598        {
383599          "type": "library",
383600          "bom-ref": "pkg:npm/widest-line@2.0.1?package-id=8d53bbe290b5bf2",
383601          "supplier": {},
383602          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
383603          "name": "widest-line",
383604          "version": "2.0.1",
383605          "description": "Get the visual width of the widest line in a string - the number of columns required to display it",
383606          "licenses": [
383607            {
383608              "license": {
383609                "id": "MIT"
383610              }
383611            }
383612          ],
383613          "cpe": "cpe:2.3:a:sindresorhus:widest-line:2.0.1:*:*:*:*:*:*:*",
383614          "purl": "pkg:npm/widest-line@2.0.1",
383615          "swid": {
383616            "attachment": {}
383617          },
383618          "pedigree": {},
383619          "externalReferences": [
383620            {
383621              "url": "git+https://github.com/sindresorhus/widest-line.git",
383622              "type": "distribution"
383623            },
383624            {
383625              "url": "https://github.com/sindresorhus/widest-line#readme",
383626              "type": "website"
383627            }
383628          ],
383629          "evidence": {},
383630          "signature": {
383631            "signature": {
383632              "publicKey": {}
383633            }
383634          },
383635          "modelCard": {
383636            "modelParameters": {
383637              "approach": {}
383638            },
383639            "quantitativeAnalysis": {
383640              "graphics": {}
383641            },
383642            "considerations": {}
383643          }
383644        },
383645        {
383646          "type": "library",
383647          "bom-ref": "pkg:npm/worker-farm@1.7.0?package-id=485ea0f11314a814",
383648          "supplier": {},
383649          "name": "worker-farm",
383650          "version": "1.7.0",
383651          "description": "Distribute processing tasks to child processes with an über-simple API and baked-in durability \u0026 custom concurrency options.",
383652          "licenses": [
383653            {
383654              "license": {
383655                "id": "MIT"
383656              }
383657            }
383658          ],
383659          "cpe": "cpe:2.3:a:worker-farm:worker-farm:1.7.0:*:*:*:*:*:*:*",
383660          "purl": "pkg:npm/worker-farm@1.7.0",
383661          "swid": {
383662            "attachment": {}
383663          },
383664          "pedigree": {},
383665          "externalReferences": [
383666            {
383667              "url": "git+https://github.com/rvagg/node-worker-farm.git",
383668              "type": "distribution"
383669            },
383670            {
383671              "url": "https://github.com/rvagg/node-worker-farm",
383672              "type": "website"
383673            }
383674          ],
383675          "evidence": {},
383676          "signature": {
383677            "signature": {
383678              "publicKey": {}
383679            }
383680          },
383681          "modelCard": {
383682            "modelParameters": {
383683              "approach": {}
383684            },
383685            "quantitativeAnalysis": {
383686              "graphics": {}
383687            },
383688            "considerations": {}
383689          }
383690        },
383691        {
383692          "type": "library",
383693          "bom-ref": "pkg:npm/wrap-ansi@5.1.0?package-id=d8793c53891a3183",
383694          "supplier": {},
383695          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
383696          "name": "wrap-ansi",
383697          "version": "5.1.0",
383698          "description": "Wordwrap a string with ANSI escape codes",
383699          "licenses": [
383700            {
383701              "license": {
383702                "id": "MIT"
383703              }
383704            }
383705          ],
383706          "cpe": "cpe:2.3:a:wrap-ansi:wrap-ansi:5.1.0:*:*:*:*:*:*:*",
383707          "purl": "pkg:npm/wrap-ansi@5.1.0",
383708          "swid": {
383709            "attachment": {}
383710          },
383711          "pedigree": {},
383712          "externalReferences": [
383713            {
383714              "url": "git+https://github.com/chalk/wrap-ansi.git",
383715              "type": "distribution"
383716            },
383717            {
383718              "url": "https://github.com/chalk/wrap-ansi#readme",
383719              "type": "website"
383720            }
383721          ],
383722          "evidence": {},
383723          "signature": {
383724            "signature": {
383725              "publicKey": {}
383726            }
383727          },
383728          "modelCard": {
383729            "modelParameters": {
383730              "approach": {}
383731            },
383732            "quantitativeAnalysis": {
383733              "graphics": {}
383734            },
383735            "considerations": {}
383736          }
383737        },
383738        {
383739          "type": "library",
383740          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=3bac7a86a24db14e",
383741          "supplier": {},
383742          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
383743          "name": "wrappy",
383744          "version": "1.0.2",
383745          "description": "Callback wrapping utility",
383746          "licenses": [
383747            {
383748              "license": {
383749                "id": "ISC"
383750              }
383751            }
383752          ],
383753          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
383754          "purl": "pkg:npm/wrappy@1.0.2",
383755          "swid": {
383756            "attachment": {}
383757          },
383758          "pedigree": {},
383759          "externalReferences": [
383760            {
383761              "url": "git+https://github.com/npm/wrappy.git",
383762              "type": "distribution"
383763            },
383764            {
383765              "url": "https://github.com/npm/wrappy",
383766              "type": "website"
383767            }
383768          ],
383769          "evidence": {},
383770          "signature": {
383771            "signature": {
383772              "publicKey": {}
383773            }
383774          },
383775          "modelCard": {
383776            "modelParameters": {
383777              "approach": {}
383778            },
383779            "quantitativeAnalysis": {
383780              "graphics": {}
383781            },
383782            "considerations": {}
383783          }
383784        },
383785        {
383786          "type": "library",
383787          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=da7850cd4ce320be",
383788          "supplier": {},
383789          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
383790          "name": "wrappy",
383791          "version": "1.0.2",
383792          "description": "Callback wrapping utility",
383793          "licenses": [
383794            {
383795              "license": {
383796                "id": "ISC"
383797              }
383798            }
383799          ],
383800          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
383801          "purl": "pkg:npm/wrappy@1.0.2",
383802          "swid": {
383803            "attachment": {}
383804          },
383805          "pedigree": {},
383806          "externalReferences": [
383807            {
383808              "url": "git+https://github.com/npm/wrappy.git",
383809              "type": "distribution"
383810            },
383811            {
383812              "url": "https://github.com/npm/wrappy",
383813              "type": "website"
383814            }
383815          ],
383816          "evidence": {},
383817          "signature": {
383818            "signature": {
383819              "publicKey": {}
383820            }
383821          },
383822          "modelCard": {
383823            "modelParameters": {
383824              "approach": {}
383825            },
383826            "quantitativeAnalysis": {
383827              "graphics": {}
383828            },
383829            "considerations": {}
383830          }
383831        },
383832        {
383833          "type": "library",
383834          "bom-ref": "pkg:npm/write-file-atomic@2.4.3?package-id=7d4897c5064f974b",
383835          "supplier": {},
383836          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org)",
383837          "name": "write-file-atomic",
383838          "version": "2.4.3",
383839          "description": "Write files in an atomic fashion w/configurable ownership",
383840          "licenses": [
383841            {
383842              "license": {
383843                "id": "ISC"
383844              }
383845            }
383846          ],
383847          "cpe": "cpe:2.3:a:write-file-atomic:write-file-atomic:2.4.3:*:*:*:*:*:*:*",
383848          "purl": "pkg:npm/write-file-atomic@2.4.3",
383849          "swid": {
383850            "attachment": {}
383851          },
383852          "pedigree": {},
383853          "externalReferences": [
383854            {
383855              "url": "git+ssh://git@github.com/iarna/write-file-atomic.git",
383856              "type": "distribution"
383857            },
383858            {
383859              "url": "https://github.com/iarna/write-file-atomic",
383860              "type": "website"
383861            }
383862          ],
383863          "evidence": {},
383864          "signature": {
383865            "signature": {
383866              "publicKey": {}
383867            }
383868          },
383869          "modelCard": {
383870            "modelParameters": {
383871              "approach": {}
383872            },
383873            "quantitativeAnalysis": {
383874              "graphics": {}
383875            },
383876            "considerations": {}
383877          }
383878        },
383879        {
383880          "type": "library",
383881          "bom-ref": "pkg:npm/xdg-basedir@3.0.0?package-id=6cd97401957b6225",
383882          "supplier": {},
383883          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
383884          "name": "xdg-basedir",
383885          "version": "3.0.0",
383886          "description": "Get XDG Base Directory paths",
383887          "licenses": [
383888            {
383889              "license": {
383890                "id": "MIT"
383891              }
383892            }
383893          ],
383894          "cpe": "cpe:2.3:a:sindresorhus:xdg-basedir:3.0.0:*:*:*:*:*:*:*",
383895          "purl": "pkg:npm/xdg-basedir@3.0.0",
383896          "swid": {
383897            "attachment": {}
383898          },
383899          "pedigree": {},
383900          "externalReferences": [
383901            {
383902              "url": "git+https://github.com/sindresorhus/xdg-basedir.git",
383903              "type": "distribution"
383904            },
383905            {
383906              "url": "https://github.com/sindresorhus/xdg-basedir#readme",
383907              "type": "website"
383908            }
383909          ],
383910          "evidence": {},
383911          "signature": {
383912            "signature": {
383913              "publicKey": {}
383914            }
383915          },
383916          "modelCard": {
383917            "modelParameters": {
383918              "approach": {}
383919            },
383920            "quantitativeAnalysis": {
383921              "graphics": {}
383922            },
383923            "considerations": {}
383924          }
383925        },
383926        {
383927          "type": "library",
383928          "bom-ref": "pkg:npm/xtend@4.0.1?package-id=7f934d0a04b60a40",
383929          "supplier": {},
383930          "author": "Raynos \u003craynos2@gmail.com\u003e",
383931          "name": "xtend",
383932          "version": "4.0.1",
383933          "description": "extend like a boss",
383934          "licenses": [
383935            {
383936              "license": {
383937                "id": "MIT"
383938              }
383939            }
383940          ],
383941          "cpe": "cpe:2.3:a:Raynos:xtend:4.0.1:*:*:*:*:*:*:*",
383942          "purl": "pkg:npm/xtend@4.0.1",
383943          "swid": {
383944            "attachment": {}
383945          },
383946          "pedigree": {},
383947          "externalReferences": [
383948            {
383949              "url": "git://github.com/Raynos/xtend.git",
383950              "type": "distribution"
383951            },
383952            {
383953              "url": "https://github.com/Raynos/xtend",
383954              "type": "website"
383955            }
383956          ],
383957          "evidence": {},
383958          "signature": {
383959            "signature": {
383960              "publicKey": {}
383961            }
383962          },
383963          "modelCard": {
383964            "modelParameters": {
383965              "approach": {}
383966            },
383967            "quantitativeAnalysis": {
383968              "graphics": {}
383969            },
383970            "considerations": {}
383971          }
383972        },
383973        {
383974          "type": "library",
383975          "bom-ref": "pkg:npm/xtend@4.0.2?package-id=806268954298f9d0",
383976          "supplier": {},
383977          "author": "Raynos \u003craynos2@gmail.com\u003e",
383978          "name": "xtend",
383979          "version": "4.0.2",
383980          "description": "extend like a boss",
383981          "licenses": [
383982            {
383983              "license": {
383984                "id": "MIT"
383985              }
383986            }
383987          ],
383988          "cpe": "cpe:2.3:a:Raynos:xtend:4.0.2:*:*:*:*:*:*:*",
383989          "purl": "pkg:npm/xtend@4.0.2",
383990          "swid": {
383991            "attachment": {}
383992          },
383993          "pedigree": {},
383994          "externalReferences": [
383995            {
383996              "url": "git://github.com/Raynos/xtend.git",
383997              "type": "distribution"
383998            },
383999            {
384000              "url": "https://github.com/Raynos/xtend",
384001              "type": "website"
384002            }
384003          ],
384004          "evidence": {},
384005          "signature": {
384006            "signature": {
384007              "publicKey": {}
384008            }
384009          },
384010          "modelCard": {
384011            "modelParameters": {
384012              "approach": {}
384013            },
384014            "quantitativeAnalysis": {
384015              "graphics": {}
384016            },
384017            "considerations": {}
384018          }
384019        },
384020        {
384021          "type": "library",
384022          "bom-ref": "pkg:npm/y18n@4.0.1?package-id=59c84f1155aa57be",
384023          "supplier": {},
384024          "author": "Ben Coe \u003cben@npmjs.com\u003e",
384025          "name": "y18n",
384026          "version": "4.0.1",
384027          "description": "the bare-bones internationalization library used by yargs",
384028          "licenses": [
384029            {
384030              "license": {
384031                "id": "ISC"
384032              }
384033            }
384034          ],
384035          "cpe": "cpe:2.3:a:yargs:y18n:4.0.1:*:*:*:*:*:*:*",
384036          "purl": "pkg:npm/y18n@4.0.1",
384037          "swid": {
384038            "attachment": {}
384039          },
384040          "pedigree": {},
384041          "externalReferences": [
384042            {
384043              "url": "git+ssh://git@github.com/yargs/y18n.git",
384044              "type": "distribution"
384045            },
384046            {
384047              "url": "https://github.com/yargs/y18n",
384048              "type": "website"
384049            }
384050          ],
384051          "evidence": {},
384052          "signature": {
384053            "signature": {
384054              "publicKey": {}
384055            }
384056          },
384057          "modelCard": {
384058            "modelParameters": {
384059              "approach": {}
384060            },
384061            "quantitativeAnalysis": {
384062              "graphics": {}
384063            },
384064            "considerations": {}
384065          }
384066        },
384067        {
384068          "type": "library",
384069          "bom-ref": "pkg:npm/yallist@2.1.2?package-id=2dc35655140480b4",
384070          "supplier": {},
384071          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
384072          "name": "yallist",
384073          "version": "2.1.2",
384074          "description": "Yet Another Linked List",
384075          "licenses": [
384076            {
384077              "license": {
384078                "id": "ISC"
384079              }
384080            }
384081          ],
384082          "cpe": "cpe:2.3:a:yallist:yallist:2.1.2:*:*:*:*:*:*:*",
384083          "purl": "pkg:npm/yallist@2.1.2",
384084          "swid": {
384085            "attachment": {}
384086          },
384087          "pedigree": {},
384088          "externalReferences": [
384089            {
384090              "url": "git+https://github.com/isaacs/yallist.git",
384091              "type": "distribution"
384092            },
384093            {
384094              "url": "https://github.com/isaacs/yallist#readme",
384095              "type": "website"
384096            }
384097          ],
384098          "evidence": {},
384099          "signature": {
384100            "signature": {
384101              "publicKey": {}
384102            }
384103          },
384104          "modelCard": {
384105            "modelParameters": {
384106              "approach": {}
384107            },
384108            "quantitativeAnalysis": {
384109              "graphics": {}
384110            },
384111            "considerations": {}
384112          }
384113        },
384114        {
384115          "type": "library",
384116          "bom-ref": "pkg:npm/yallist@3.0.3?package-id=dba260e644a452f8",
384117          "supplier": {},
384118          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
384119          "name": "yallist",
384120          "version": "3.0.3",
384121          "description": "Yet Another Linked List",
384122          "licenses": [
384123            {
384124              "license": {
384125                "id": "ISC"
384126              }
384127            }
384128          ],
384129          "cpe": "cpe:2.3:a:yallist:yallist:3.0.3:*:*:*:*:*:*:*",
384130          "purl": "pkg:npm/yallist@3.0.3",
384131          "swid": {
384132            "attachment": {}
384133          },
384134          "pedigree": {},
384135          "externalReferences": [
384136            {
384137              "url": "git+https://github.com/isaacs/yallist.git",
384138              "type": "distribution"
384139            },
384140            {
384141              "url": "https://github.com/isaacs/yallist#readme",
384142              "type": "website"
384143            }
384144          ],
384145          "evidence": {},
384146          "signature": {
384147            "signature": {
384148              "publicKey": {}
384149            }
384150          },
384151          "modelCard": {
384152            "modelParameters": {
384153              "approach": {}
384154            },
384155            "quantitativeAnalysis": {
384156              "graphics": {}
384157            },
384158            "considerations": {}
384159          }
384160        },
384161        {
384162          "type": "library",
384163          "bom-ref": "pkg:npm/yallist@3.1.1?package-id=786b4b01dc63a464",
384164          "supplier": {},
384165          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
384166          "name": "yallist",
384167          "version": "3.1.1",
384168          "description": "Yet Another Linked List",
384169          "licenses": [
384170            {
384171              "license": {
384172                "id": "ISC"
384173              }
384174            }
384175          ],
384176          "cpe": "cpe:2.3:a:yallist:yallist:3.1.1:*:*:*:*:*:*:*",
384177          "purl": "pkg:npm/yallist@3.1.1",
384178          "swid": {
384179            "attachment": {}
384180          },
384181          "pedigree": {},
384182          "externalReferences": [
384183            {
384184              "url": "git+https://github.com/isaacs/yallist.git",
384185              "type": "distribution"
384186            },
384187            {
384188              "url": "https://github.com/isaacs/yallist#readme",
384189              "type": "website"
384190            }
384191          ],
384192          "evidence": {},
384193          "signature": {
384194            "signature": {
384195              "publicKey": {}
384196            }
384197          },
384198          "modelCard": {
384199            "modelParameters": {
384200              "approach": {}
384201            },
384202            "quantitativeAnalysis": {
384203              "graphics": {}
384204            },
384205            "considerations": {}
384206          }
384207        },
384208        {
384209          "type": "library",
384210          "bom-ref": "pkg:npm/yargs@14.2.3?package-id=2b0da698f823246",
384211          "supplier": {},
384212          "name": "yargs",
384213          "version": "14.2.3",
384214          "description": "yargs the modern, pirate-themed, successor to optimist.",
384215          "licenses": [
384216            {
384217              "license": {
384218                "id": "MIT"
384219              }
384220            }
384221          ],
384222          "cpe": "cpe:2.3:a:yargs:yargs:14.2.3:*:*:*:*:*:*:*",
384223          "purl": "pkg:npm/yargs@14.2.3",
384224          "swid": {
384225            "attachment": {}
384226          },
384227          "pedigree": {},
384228          "externalReferences": [
384229            {
384230              "url": "git+https://github.com/yargs/yargs.git",
384231              "type": "distribution"
384232            },
384233            {
384234              "url": "https://yargs.js.org/",
384235              "type": "website"
384236            }
384237          ],
384238          "evidence": {},
384239          "signature": {
384240            "signature": {
384241              "publicKey": {}
384242            }
384243          },
384244          "modelCard": {
384245            "modelParameters": {
384246              "approach": {}
384247            },
384248            "quantitativeAnalysis": {
384249              "graphics": {}
384250            },
384251            "considerations": {}
384252          }
384253        },
384254        {
384255          "type": "library",
384256          "bom-ref": "pkg:npm/yargs-parser@15.0.1?package-id=21203be018f57e45",
384257          "supplier": {},
384258          "author": "Ben Coe \u003cben@npmjs.com\u003e",
384259          "name": "yargs-parser",
384260          "version": "15.0.1",
384261          "description": "the mighty option parser used by yargs",
384262          "licenses": [
384263            {
384264              "license": {
384265                "id": "ISC"
384266              }
384267            }
384268          ],
384269          "cpe": "cpe:2.3:a:yargs-parser:yargs-parser:15.0.1:*:*:*:*:*:*:*",
384270          "purl": "pkg:npm/yargs-parser@15.0.1",
384271          "swid": {
384272            "attachment": {}
384273          },
384274          "pedigree": {},
384275          "externalReferences": [
384276            {
384277              "url": "git+ssh://git@github.com/yargs/yargs-parser.git",
384278              "type": "distribution"
384279            },
384280            {
384281              "url": "https://github.com/yargs/yargs-parser#readme",
384282              "type": "website"
384283            }
384284          ],
384285          "evidence": {},
384286          "signature": {
384287            "signature": {
384288              "publicKey": {}
384289            }
384290          },
384291          "modelCard": {
384292            "modelParameters": {
384293              "approach": {}
384294            },
384295            "quantitativeAnalysis": {
384296              "graphics": {}
384297            },
384298            "considerations": {}
384299          }
384300        },
384301        {
384302          "type": "library",
384303          "bom-ref": "pkg:npm/yarn@1.22.19?package-id=f2b974a78000b26b",
384304          "supplier": {},
384305          "name": "yarn",
384306          "version": "1.22.19",
384307          "description": "📦🐈 Fast, reliable, and secure dependency management.",
384308          "licenses": [
384309            {
384310              "license": {
384311                "id": "BSD-2-Clause"
384312              }
384313            }
384314          ],
384315          "cpe": "cpe:2.3:a:yarn:yarn:1.22.19:*:*:*:*:*:*:*",
384316          "purl": "pkg:npm/yarn@1.22.19",
384317          "swid": {
384318            "attachment": {}
384319          },
384320          "pedigree": {},
384321          "externalReferences": [
384322            {
384323              "url": "yarnpkg/yarn",
384324              "type": "distribution"
384325            }
384326          ],
384327          "evidence": {},
384328          "signature": {
384329            "signature": {
384330              "publicKey": {}
384331            }
384332          },
384333          "modelCard": {
384334            "modelParameters": {
384335              "approach": {}
384336            },
384337            "quantitativeAnalysis": {
384338              "graphics": {}
384339            },
384340            "considerations": {}
384341          }
384342        },
384343        {
384344          "type": "library",
384345          "bom-ref": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.3\u0026package-id=94014313cfcd2b71",
384346          "supplier": {},
384347          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
384348          "name": "zlib",
384349          "version": "1.2.13-r0",
384350          "description": "A compression/decompression Library",
384351          "licenses": [
384352            {
384353              "license": {
384354                "id": "Zlib"
384355              }
384356            }
384357          ],
384358          "cpe": "cpe:2.3:a:zlib:zlib:1.2.13-r0:*:*:*:*:*:*:*",
384359          "purl": "pkg:apk/alpine/zlib@1.2.13-r0?arch=x86_64\u0026distro=alpine-3.17.3",
384360          "swid": {
384361            "attachment": {}
384362          },
384363          "pedigree": {},
384364          "externalReferences": [
384365            {
384366              "url": "https://zlib.net/",
384367              "type": "distribution"
384368            }
384369          ],
384370          "evidence": {},
384371          "signature": {
384372            "signature": {
384373              "publicKey": {}
384374            }
384375          },
384376          "modelCard": {
384377            "modelParameters": {
384378              "approach": {}
384379            },
384380            "quantitativeAnalysis": {
384381              "graphics": {}
384382            },
384383            "considerations": {}
384384          }
384385        },
384386        {
384387          "type": "operating-system",
384388          "supplier": {},
384389          "name": "alpine",
384390          "version": "3.17.3",
384391          "description": "Alpine Linux v3.17",
384392          "swid": {
384393            "tagId": "alpine",
384394            "name": "alpine",
384395            "version": "3.17.3",
384396            "attachment": {}
384397          },
384398          "pedigree": {},
384399          "externalReferences": [
384400            {
384401              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
384402              "type": "issue-tracker"
384403            },
384404            {
384405              "url": "https://alpinelinux.org/",
384406              "type": "website"
384407            }
384408          ],
384409          "evidence": {},
384410          "signature": {
384411            "signature": {
384412              "publicKey": {}
384413            }
384414          },
384415          "modelCard": {
384416            "modelParameters": {
384417              "approach": {}
384418            },
384419            "quantitativeAnalysis": {
384420              "graphics": {}
384421            },
384422            "considerations": {}
384423          }
384424        },
384425        {
384426          "type": "library",
384427          "bom-ref": "pkg:npm/%40calebboyd/semaphore@1.3.1?package-id=69a5a0e81d0ff085",
384428          "supplier": {},
384429          "author": "Caleb Boyd",
384430          "name": "@calebboyd/semaphore",
384431          "version": "1.3.1",
384432          "description": "Simple promise based counting semaphore",
384433          "licenses": [
384434            {
384435              "license": {
384436                "id": "MIT"
384437              }
384438            }
384439          ],
384440          "cpe": "cpe:2.3:a:\\@calebboyd\\/semaphore:\\@calebboyd\\/semaphore:1.3.1:*:*:*:*:*:*:*",
384441          "purl": "pkg:npm/%40calebboyd/semaphore@1.3.1",
384442          "swid": {
384443            "attachment": {}
384444          },
384445          "pedigree": {},
384446          "evidence": {},
384447          "signature": {
384448            "signature": {
384449              "publicKey": {}
384450            }
384451          },
384452          "modelCard": {
384453            "modelParameters": {
384454              "approach": {}
384455            },
384456            "quantitativeAnalysis": {
384457              "graphics": {}
384458            },
384459            "considerations": {}
384460          }
384461        },
384462        {
384463          "type": "library",
384464          "bom-ref": "pkg:npm/%40colors/colors@1.5.0?package-id=1e63eea14f4d61ef",
384465          "supplier": {},
384466          "author": "DABH",
384467          "name": "@colors/colors",
384468          "version": "1.5.0",
384469          "description": "get colors in your node.js console",
384470          "licenses": [
384471            {
384472              "license": {
384473                "id": "MIT"
384474              }
384475            }
384476          ],
384477          "cpe": "cpe:2.3:a:\\@colors\\/colors:\\@colors\\/colors:1.5.0:*:*:*:*:*:*:*",
384478          "purl": "pkg:npm/%40colors/colors@1.5.0",
384479          "swid": {
384480            "attachment": {}
384481          },
384482          "pedigree": {},
384483          "externalReferences": [
384484            {
384485              "url": "http://github.com/DABH/colors.js.git",
384486              "type": "distribution"
384487            },
384488            {
384489              "url": "https://github.com/DABH/colors.js",
384490              "type": "website"
384491            }
384492          ],
384493          "evidence": {},
384494          "signature": {
384495            "signature": {
384496              "publicKey": {}
384497            }
384498          },
384499          "modelCard": {
384500            "modelParameters": {
384501              "approach": {}
384502            },
384503            "quantitativeAnalysis": {
384504              "graphics": {}
384505            },
384506            "considerations": {}
384507          }
384508        },
384509        {
384510          "type": "library",
384511          "bom-ref": "pkg:npm/%40gar/promisify@1.1.3?package-id=6fab079a7c06c1de",
384512          "supplier": {},
384513          "author": "Gar \u003cgar+npm@danger.computer\u003e",
384514          "name": "@gar/promisify",
384515          "version": "1.1.3",
384516          "description": "Promisify an entire class or object",
384517          "licenses": [
384518            {
384519              "license": {
384520                "id": "MIT"
384521              }
384522            }
384523          ],
384524          "cpe": "cpe:2.3:a:\\@gar\\/promisify:\\@gar\\/promisify:1.1.3:*:*:*:*:*:*:*",
384525          "purl": "pkg:npm/%40gar/promisify@1.1.3",
384526          "swid": {
384527            "attachment": {}
384528          },
384529          "pedigree": {},
384530          "externalReferences": [
384531            {
384532              "url": "https://github.com/wraithgar/gar-promisify.git",
384533              "type": "distribution"
384534            }
384535          ],
384536          "evidence": {},
384537          "signature": {
384538            "signature": {
384539              "publicKey": {}
384540            }
384541          },
384542          "modelCard": {
384543            "modelParameters": {
384544              "approach": {}
384545            },
384546            "quantitativeAnalysis": {
384547              "graphics": {}
384548            },
384549            "considerations": {}
384550          }
384551        },
384552        {
384553          "type": "library",
384554          "bom-ref": "pkg:npm/%40isaacs/string-locale-compare@1.1.0?package-id=fbe0dcb344723a67",
384555          "supplier": {},
384556          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
384557          "name": "@isaacs/string-locale-compare",
384558          "version": "1.1.0",
384559          "description": "Compare strings with Intl.Collator if available, falling back to String.localeCompare otherwise",
384560          "licenses": [
384561            {
384562              "license": {
384563                "id": "ISC"
384564              }
384565            }
384566          ],
384567          "cpe": "cpe:2.3:a:\\@isaacs\\/string-locale-compare:\\@isaacs\\/string-locale-compare:1.1.0:*:*:*:*:*:*:*",
384568          "purl": "pkg:npm/%40isaacs/string-locale-compare@1.1.0",
384569          "swid": {
384570            "attachment": {}
384571          },
384572          "pedigree": {},
384573          "externalReferences": [
384574            {
384575              "url": "git+https://github.com/isaacs/string-locale-compare",
384576              "type": "distribution"
384577            }
384578          ],
384579          "evidence": {},
384580          "signature": {
384581            "signature": {
384582              "publicKey": {}
384583            }
384584          },
384585          "modelCard": {
384586            "modelParameters": {
384587              "approach": {}
384588            },
384589            "quantitativeAnalysis": {
384590              "graphics": {}
384591            },
384592            "considerations": {}
384593          }
384594        },
384595        {
384596          "type": "library",
384597          "bom-ref": "pkg:npm/%40nodelib/fs.scandir@2.1.5?package-id=48ae8d7811f44220",
384598          "supplier": {},
384599          "name": "@nodelib/fs.scandir",
384600          "version": "2.1.5",
384601          "description": "List files and directories inside the specified directory",
384602          "licenses": [
384603            {
384604              "license": {
384605                "id": "MIT"
384606              }
384607            }
384608          ],
384609          "cpe": "cpe:2.3:a:\\@nodelib\\/fs.scandir:\\@nodelib\\/fs.scandir:2.1.5:*:*:*:*:*:*:*",
384610          "purl": "pkg:npm/%40nodelib/fs.scandir@2.1.5",
384611          "swid": {
384612            "attachment": {}
384613          },
384614          "pedigree": {},
384615          "externalReferences": [
384616            {
384617              "url": "https://github.com/nodelib/nodelib/tree/master/packages/fs/fs.scandir",
384618              "type": "distribution"
384619            }
384620          ],
384621          "evidence": {},
384622          "signature": {
384623            "signature": {
384624              "publicKey": {}
384625            }
384626          },
384627          "modelCard": {
384628            "modelParameters": {
384629              "approach": {}
384630            },
384631            "quantitativeAnalysis": {
384632              "graphics": {}
384633            },
384634            "considerations": {}
384635          }
384636        },
384637        {
384638          "type": "library",
384639          "bom-ref": "pkg:npm/%40nodelib/fs.stat@2.0.5?package-id=4dbbdaccc8c39cfa",
384640          "supplier": {},
384641          "name": "@nodelib/fs.stat",
384642          "version": "2.0.5",
384643          "description": "Get the status of a file with some features",
384644          "licenses": [
384645            {
384646              "license": {
384647                "id": "MIT"
384648              }
384649            }
384650          ],
384651          "cpe": "cpe:2.3:a:\\@nodelib\\/fs.stat:\\@nodelib\\/fs.stat:2.0.5:*:*:*:*:*:*:*",
384652          "purl": "pkg:npm/%40nodelib/fs.stat@2.0.5",
384653          "swid": {
384654            "attachment": {}
384655          },
384656          "pedigree": {},
384657          "externalReferences": [
384658            {
384659              "url": "https://github.com/nodelib/nodelib/tree/master/packages/fs/fs.stat",
384660              "type": "distribution"
384661            }
384662          ],
384663          "evidence": {},
384664          "signature": {
384665            "signature": {
384666              "publicKey": {}
384667            }
384668          },
384669          "modelCard": {
384670            "modelParameters": {
384671              "approach": {}
384672            },
384673            "quantitativeAnalysis": {
384674              "graphics": {}
384675            },
384676            "considerations": {}
384677          }
384678        },
384679        {
384680          "type": "library",
384681          "bom-ref": "pkg:npm/%40nodelib/fs.walk@1.2.8?package-id=dd0dc6755ff07f7",
384682          "supplier": {},
384683          "name": "@nodelib/fs.walk",
384684          "version": "1.2.8",
384685          "description": "A library for efficiently walking a directory recursively",
384686          "licenses": [
384687            {
384688              "license": {
384689                "id": "MIT"
384690              }
384691            }
384692          ],
384693          "cpe": "cpe:2.3:a:\\@nodelib\\/fs.walk:\\@nodelib\\/fs.walk:1.2.8:*:*:*:*:*:*:*",
384694          "purl": "pkg:npm/%40nodelib/fs.walk@1.2.8",
384695          "swid": {
384696            "attachment": {}
384697          },
384698          "pedigree": {},
384699          "externalReferences": [
384700            {
384701              "url": "https://github.com/nodelib/nodelib/tree/master/packages/fs/fs.walk",
384702              "type": "distribution"
384703            }
384704          ],
384705          "evidence": {},
384706          "signature": {
384707            "signature": {
384708              "publicKey": {}
384709            }
384710          },
384711          "modelCard": {
384712            "modelParameters": {
384713              "approach": {}
384714            },
384715            "quantitativeAnalysis": {
384716              "graphics": {}
384717            },
384718            "considerations": {}
384719          }
384720        },
384721        {
384722          "type": "library",
384723          "bom-ref": "pkg:npm/%40npmcli/arborist@5.6.3?package-id=60e008e2ceb94218",
384724          "supplier": {},
384725          "author": "GitHub Inc.",
384726          "name": "@npmcli/arborist",
384727          "version": "5.6.3",
384728          "description": "Manage node_modules trees",
384729          "licenses": [
384730            {
384731              "license": {
384732                "id": "ISC"
384733              }
384734            }
384735          ],
384736          "cpe": "cpe:2.3:a:\\@npmcli\\/arborist:\\@npmcli\\/arborist:5.6.3:*:*:*:*:*:*:*",
384737          "purl": "pkg:npm/%40npmcli/arborist@5.6.3",
384738          "swid": {
384739            "attachment": {}
384740          },
384741          "pedigree": {},
384742          "externalReferences": [
384743            {
384744              "url": "https://github.com/npm/cli.git",
384745              "type": "distribution"
384746            }
384747          ],
384748          "evidence": {},
384749          "signature": {
384750            "signature": {
384751              "publicKey": {}
384752            }
384753          },
384754          "modelCard": {
384755            "modelParameters": {
384756              "approach": {}
384757            },
384758            "quantitativeAnalysis": {
384759              "graphics": {}
384760            },
384761            "considerations": {}
384762          }
384763        },
384764        {
384765          "type": "library",
384766          "bom-ref": "pkg:npm/%40npmcli/ci-detect@2.0.0?package-id=8a40a38b900bcf1d",
384767          "supplier": {},
384768          "author": "GitHub Inc.",
384769          "name": "@npmcli/ci-detect",
384770          "version": "2.0.0",
384771          "description": "Detect what kind of CI environment the program is in",
384772          "licenses": [
384773            {
384774              "license": {
384775                "id": "ISC"
384776              }
384777            }
384778          ],
384779          "cpe": "cpe:2.3:a:\\@npmcli\\/ci-detect:\\@npmcli\\/ci-detect:2.0.0:*:*:*:*:*:*:*",
384780          "purl": "pkg:npm/%40npmcli/ci-detect@2.0.0",
384781          "swid": {
384782            "attachment": {}
384783          },
384784          "pedigree": {},
384785          "externalReferences": [
384786            {
384787              "url": "git+https://github.com/npm/ci-detect.git",
384788              "type": "distribution"
384789            }
384790          ],
384791          "evidence": {},
384792          "signature": {
384793            "signature": {
384794              "publicKey": {}
384795            }
384796          },
384797          "modelCard": {
384798            "modelParameters": {
384799              "approach": {}
384800            },
384801            "quantitativeAnalysis": {
384802              "graphics": {}
384803            },
384804            "considerations": {}
384805          }
384806        },
384807        {
384808          "type": "library",
384809          "bom-ref": "pkg:npm/%40npmcli/config@4.2.2?package-id=a02559bafd837882",
384810          "supplier": {},
384811          "author": "GitHub Inc.",
384812          "name": "@npmcli/config",
384813          "version": "4.2.2",
384814          "description": "Configuration management for the npm cli",
384815          "licenses": [
384816            {
384817              "license": {
384818                "id": "ISC"
384819              }
384820            }
384821          ],
384822          "cpe": "cpe:2.3:a:\\@npmcli\\/config:\\@npmcli\\/config:4.2.2:*:*:*:*:*:*:*",
384823          "purl": "pkg:npm/%40npmcli/config@4.2.2",
384824          "swid": {
384825            "attachment": {}
384826          },
384827          "pedigree": {},
384828          "externalReferences": [
384829            {
384830              "url": "https://github.com/npm/config.git",
384831              "type": "distribution"
384832            }
384833          ],
384834          "evidence": {},
384835          "signature": {
384836            "signature": {
384837              "publicKey": {}
384838            }
384839          },
384840          "modelCard": {
384841            "modelParameters": {
384842              "approach": {}
384843            },
384844            "quantitativeAnalysis": {
384845              "graphics": {}
384846            },
384847            "considerations": {}
384848          }
384849        },
384850        {
384851          "type": "library",
384852          "bom-ref": "pkg:npm/%40npmcli/disparity-colors@2.0.0?package-id=3e63715f5300a753",
384853          "supplier": {},
384854          "author": "GitHub Inc.",
384855          "name": "@npmcli/disparity-colors",
384856          "version": "2.0.0",
384857          "description": "Colorizes unified diff output",
384858          "licenses": [
384859            {
384860              "license": {
384861                "id": "ISC"
384862              }
384863            }
384864          ],
384865          "cpe": "cpe:2.3:a:\\@npmcli\\/disparity-colors:\\@npmcli\\/disparity-colors:2.0.0:*:*:*:*:*:*:*",
384866          "purl": "pkg:npm/%40npmcli/disparity-colors@2.0.0",
384867          "swid": {
384868            "attachment": {}
384869          },
384870          "pedigree": {},
384871          "externalReferences": [
384872            {
384873              "url": "https://github.com/npm/disparity-colors.git",
384874              "type": "distribution"
384875            }
384876          ],
384877          "evidence": {},
384878          "signature": {
384879            "signature": {
384880              "publicKey": {}
384881            }
384882          },
384883          "modelCard": {
384884            "modelParameters": {
384885              "approach": {}
384886            },
384887            "quantitativeAnalysis": {
384888              "graphics": {}
384889            },
384890            "considerations": {}
384891          }
384892        },
384893        {
384894          "type": "library",
384895          "bom-ref": "pkg:npm/%40npmcli/fs@2.1.2?package-id=cd19a20b4774187f",
384896          "supplier": {},
384897          "author": "GitHub Inc.",
384898          "name": "@npmcli/fs",
384899          "version": "2.1.2",
384900          "description": "filesystem utilities for the npm cli",
384901          "licenses": [
384902            {
384903              "license": {
384904                "id": "ISC"
384905              }
384906            }
384907          ],
384908          "cpe": "cpe:2.3:a:\\@npmcli\\/fs:\\@npmcli\\/fs:2.1.2:*:*:*:*:*:*:*",
384909          "purl": "pkg:npm/%40npmcli/fs@2.1.2",
384910          "swid": {
384911            "attachment": {}
384912          },
384913          "pedigree": {},
384914          "externalReferences": [
384915            {
384916              "url": "https://github.com/npm/fs.git",
384917              "type": "distribution"
384918            }
384919          ],
384920          "evidence": {},
384921          "signature": {
384922            "signature": {
384923              "publicKey": {}
384924            }
384925          },
384926          "modelCard": {
384927            "modelParameters": {
384928              "approach": {}
384929            },
384930            "quantitativeAnalysis": {
384931              "graphics": {}
384932            },
384933            "considerations": {}
384934          }
384935        },
384936        {
384937          "type": "library",
384938          "bom-ref": "pkg:npm/%40npmcli/git@3.0.2?package-id=34b16cf601f612a9",
384939          "supplier": {},
384940          "author": "GitHub Inc.",
384941          "name": "@npmcli/git",
384942          "version": "3.0.2",
384943          "description": "a util for spawning git from npm CLI contexts",
384944          "licenses": [
384945            {
384946              "license": {
384947                "id": "ISC"
384948              }
384949            }
384950          ],
384951          "cpe": "cpe:2.3:a:\\@npmcli\\/git:\\@npmcli\\/git:3.0.2:*:*:*:*:*:*:*",
384952          "purl": "pkg:npm/%40npmcli/git@3.0.2",
384953          "swid": {
384954            "attachment": {}
384955          },
384956          "pedigree": {},
384957          "externalReferences": [
384958            {
384959              "url": "https://github.com/npm/git.git",
384960              "type": "distribution"
384961            }
384962          ],
384963          "evidence": {},
384964          "signature": {
384965            "signature": {
384966              "publicKey": {}
384967            }
384968          },
384969          "modelCard": {
384970            "modelParameters": {
384971              "approach": {}
384972            },
384973            "quantitativeAnalysis": {
384974              "graphics": {}
384975            },
384976            "considerations": {}
384977          }
384978        },
384979        {
384980          "type": "library",
384981          "bom-ref": "pkg:npm/%40npmcli/installed-package-contents@1.0.7?package-id=8562f58f85ba40df",
384982          "supplier": {},
384983          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
384984          "name": "@npmcli/installed-package-contents",
384985          "version": "1.0.7",
384986          "description": "Get the list of files installed in a package in node_modules, including bundled dependencies",
384987          "licenses": [
384988            {
384989              "license": {
384990                "id": "ISC"
384991              }
384992            }
384993          ],
384994          "cpe": "cpe:2.3:a:\\@npmcli\\/installed-package-contents:\\@npmcli\\/installed-package-contents:1.0.7:*:*:*:*:*:*:*",
384995          "purl": "pkg:npm/%40npmcli/installed-package-contents@1.0.7",
384996          "swid": {
384997            "attachment": {}
384998          },
384999          "pedigree": {},
385000          "externalReferences": [
385001            {
385002              "url": "git+https://github.com/npm/installed-package-contents",
385003              "type": "distribution"
385004            }
385005          ],
385006          "evidence": {},
385007          "signature": {
385008            "signature": {
385009              "publicKey": {}
385010            }
385011          },
385012          "modelCard": {
385013            "modelParameters": {
385014              "approach": {}
385015            },
385016            "quantitativeAnalysis": {
385017              "graphics": {}
385018            },
385019            "considerations": {}
385020          }
385021        },
385022        {
385023          "type": "library",
385024          "bom-ref": "pkg:npm/%40npmcli/map-workspaces@2.0.4?package-id=471052449bb417cb",
385025          "supplier": {},
385026          "author": "GitHub Inc.",
385027          "name": "@npmcli/map-workspaces",
385028          "version": "2.0.4",
385029          "description": "Retrieves a name:pathname Map for a given workspaces config",
385030          "licenses": [
385031            {
385032              "license": {
385033                "id": "ISC"
385034              }
385035            }
385036          ],
385037          "cpe": "cpe:2.3:a:\\@npmcli\\/map-workspaces:\\@npmcli\\/map-workspaces:2.0.4:*:*:*:*:*:*:*",
385038          "purl": "pkg:npm/%40npmcli/map-workspaces@2.0.4",
385039          "swid": {
385040            "attachment": {}
385041          },
385042          "pedigree": {},
385043          "externalReferences": [
385044            {
385045              "url": "https://github.com/npm/map-workspaces.git",
385046              "type": "distribution"
385047            }
385048          ],
385049          "evidence": {},
385050          "signature": {
385051            "signature": {
385052              "publicKey": {}
385053            }
385054          },
385055          "modelCard": {
385056            "modelParameters": {
385057              "approach": {}
385058            },
385059            "quantitativeAnalysis": {
385060              "graphics": {}
385061            },
385062            "considerations": {}
385063          }
385064        },
385065        {
385066          "type": "library",
385067          "bom-ref": "pkg:npm/%40npmcli/metavuln-calculator@3.1.1?package-id=5a94ed44a78625cd",
385068          "supplier": {},
385069          "author": "GitHub Inc.",
385070          "name": "@npmcli/metavuln-calculator",
385071          "version": "3.1.1",
385072          "description": "Calculate meta-vulnerabilities from package security advisories",
385073          "licenses": [
385074            {
385075              "license": {
385076                "id": "ISC"
385077              }
385078            }
385079          ],
385080          "cpe": "cpe:2.3:a:\\@npmcli\\/metavuln-calculator:\\@npmcli\\/metavuln-calculator:3.1.1:*:*:*:*:*:*:*",
385081          "purl": "pkg:npm/%40npmcli/metavuln-calculator@3.1.1",
385082          "swid": {
385083            "attachment": {}
385084          },
385085          "pedigree": {},
385086          "externalReferences": [
385087            {
385088              "url": "https://github.com/npm/metavuln-calculator.git",
385089              "type": "distribution"
385090            }
385091          ],
385092          "evidence": {},
385093          "signature": {
385094            "signature": {
385095              "publicKey": {}
385096            }
385097          },
385098          "modelCard": {
385099            "modelParameters": {
385100              "approach": {}
385101            },
385102            "quantitativeAnalysis": {
385103              "graphics": {}
385104            },
385105            "considerations": {}
385106          }
385107        },
385108        {
385109          "type": "library",
385110          "bom-ref": "pkg:npm/%40npmcli/move-file@2.0.1?package-id=76e6ffad7033dea3",
385111          "supplier": {},
385112          "author": "GitHub Inc.",
385113          "name": "@npmcli/move-file",
385114          "version": "2.0.1",
385115          "description": "move a file (fork of move-file)",
385116          "licenses": [
385117            {
385118              "license": {
385119                "id": "MIT"
385120              }
385121            }
385122          ],
385123          "cpe": "cpe:2.3:a:\\@npmcli\\/move-file:\\@npmcli\\/move-file:2.0.1:*:*:*:*:*:*:*",
385124          "purl": "pkg:npm/%40npmcli/move-file@2.0.1",
385125          "swid": {
385126            "attachment": {}
385127          },
385128          "pedigree": {},
385129          "externalReferences": [
385130            {
385131              "url": "https://github.com/npm/move-file.git",
385132              "type": "distribution"
385133            }
385134          ],
385135          "evidence": {},
385136          "signature": {
385137            "signature": {
385138              "publicKey": {}
385139            }
385140          },
385141          "modelCard": {
385142            "modelParameters": {
385143              "approach": {}
385144            },
385145            "quantitativeAnalysis": {
385146              "graphics": {}
385147            },
385148            "considerations": {}
385149          }
385150        },
385151        {
385152          "type": "library",
385153          "bom-ref": "pkg:npm/%40npmcli/name-from-folder@1.0.1?package-id=bda8c8030d6b515f",
385154          "supplier": {},
385155          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
385156          "name": "@npmcli/name-from-folder",
385157          "version": "1.0.1",
385158          "description": "Get the package name from a folder path",
385159          "licenses": [
385160            {
385161              "license": {
385162                "id": "ISC"
385163              }
385164            }
385165          ],
385166          "cpe": "cpe:2.3:a:\\@npmcli\\/name-from-folder:\\@npmcli\\/name-from-folder:1.0.1:*:*:*:*:*:*:*",
385167          "purl": "pkg:npm/%40npmcli/name-from-folder@1.0.1",
385168          "swid": {
385169            "attachment": {}
385170          },
385171          "pedigree": {},
385172          "externalReferences": [
385173            {
385174              "url": "git+https://github.com/npm/name-from-folder",
385175              "type": "distribution"
385176            }
385177          ],
385178          "evidence": {},
385179          "signature": {
385180            "signature": {
385181              "publicKey": {}
385182            }
385183          },
385184          "modelCard": {
385185            "modelParameters": {
385186              "approach": {}
385187            },
385188            "quantitativeAnalysis": {
385189              "graphics": {}
385190            },
385191            "considerations": {}
385192          }
385193        },
385194        {
385195          "type": "library",
385196          "bom-ref": "pkg:npm/%40npmcli/node-gyp@2.0.0?package-id=c9fb094d61d2ac04",
385197          "supplier": {},
385198          "author": "GitHub Inc.",
385199          "name": "@npmcli/node-gyp",
385200          "version": "2.0.0",
385201          "description": "Tools for dealing with node-gyp packages",
385202          "licenses": [
385203            {
385204              "license": {
385205                "id": "ISC"
385206              }
385207            }
385208          ],
385209          "cpe": "cpe:2.3:a:\\@npmcli\\/node-gyp:\\@npmcli\\/node-gyp:2.0.0:*:*:*:*:*:*:*",
385210          "purl": "pkg:npm/%40npmcli/node-gyp@2.0.0",
385211          "swid": {
385212            "attachment": {}
385213          },
385214          "pedigree": {},
385215          "externalReferences": [
385216            {
385217              "url": "https://github.com/npm/node-gyp.git",
385218              "type": "distribution"
385219            }
385220          ],
385221          "evidence": {},
385222          "signature": {
385223            "signature": {
385224              "publicKey": {}
385225            }
385226          },
385227          "modelCard": {
385228            "modelParameters": {
385229              "approach": {}
385230            },
385231            "quantitativeAnalysis": {
385232              "graphics": {}
385233            },
385234            "considerations": {}
385235          }
385236        },
385237        {
385238          "type": "library",
385239          "bom-ref": "pkg:npm/%40npmcli/package-json@2.0.0?package-id=63189c571859bb1a",
385240          "supplier": {},
385241          "author": "GitHub Inc.",
385242          "name": "@npmcli/package-json",
385243          "version": "2.0.0",
385244          "description": "Programmatic API to update package.json",
385245          "licenses": [
385246            {
385247              "license": {
385248                "id": "ISC"
385249              }
385250            }
385251          ],
385252          "cpe": "cpe:2.3:a:\\@npmcli\\/package-json:\\@npmcli\\/package-json:2.0.0:*:*:*:*:*:*:*",
385253          "purl": "pkg:npm/%40npmcli/package-json@2.0.0",
385254          "swid": {
385255            "attachment": {}
385256          },
385257          "pedigree": {},
385258          "externalReferences": [
385259            {
385260              "url": "https://github.com/npm/package-json.git",
385261              "type": "distribution"
385262            }
385263          ],
385264          "evidence": {},
385265          "signature": {
385266            "signature": {
385267              "publicKey": {}
385268            }
385269          },
385270          "modelCard": {
385271            "modelParameters": {
385272              "approach": {}
385273            },
385274            "quantitativeAnalysis": {
385275              "graphics": {}
385276            },
385277            "considerations": {}
385278          }
385279        },
385280        {
385281          "type": "library",
385282          "bom-ref": "pkg:npm/%40npmcli/promise-spawn@3.0.0?package-id=426c6e033be010cb",
385283          "supplier": {},
385284          "author": "GitHub Inc.",
385285          "name": "@npmcli/promise-spawn",
385286          "version": "3.0.0",
385287          "description": "spawn processes the way the npm cli likes to do",
385288          "licenses": [
385289            {
385290              "license": {
385291                "id": "ISC"
385292              }
385293            }
385294          ],
385295          "cpe": "cpe:2.3:a:\\@npmcli\\/promise-spawn:\\@npmcli\\/promise-spawn:3.0.0:*:*:*:*:*:*:*",
385296          "purl": "pkg:npm/%40npmcli/promise-spawn@3.0.0",
385297          "swid": {
385298            "attachment": {}
385299          },
385300          "pedigree": {},
385301          "externalReferences": [
385302            {
385303              "url": "https://github.com/npm/promise-spawn.git",
385304              "type": "distribution"
385305            }
385306          ],
385307          "evidence": {},
385308          "signature": {
385309            "signature": {
385310              "publicKey": {}
385311            }
385312          },
385313          "modelCard": {
385314            "modelParameters": {
385315              "approach": {}
385316            },
385317            "quantitativeAnalysis": {
385318              "graphics": {}
385319            },
385320            "considerations": {}
385321          }
385322        },
385323        {
385324          "type": "library",
385325          "bom-ref": "pkg:npm/%40npmcli/query@1.2.0?package-id=e71e78476048755c",
385326          "supplier": {},
385327          "author": "GitHub Inc.",
385328          "name": "@npmcli/query",
385329          "version": "1.2.0",
385330          "description": "npm query parser and tools",
385331          "licenses": [
385332            {
385333              "license": {
385334                "id": "ISC"
385335              }
385336            }
385337          ],
385338          "cpe": "cpe:2.3:a:\\@npmcli\\/query:\\@npmcli\\/query:1.2.0:*:*:*:*:*:*:*",
385339          "purl": "pkg:npm/%40npmcli/query@1.2.0",
385340          "swid": {
385341            "attachment": {}
385342          },
385343          "pedigree": {},
385344          "externalReferences": [
385345            {
385346              "url": "https://github.com/npm/query.git",
385347              "type": "distribution"
385348            }
385349          ],
385350          "evidence": {},
385351          "signature": {
385352            "signature": {
385353              "publicKey": {}
385354            }
385355          },
385356          "modelCard": {
385357            "modelParameters": {
385358              "approach": {}
385359            },
385360            "quantitativeAnalysis": {
385361              "graphics": {}
385362            },
385363            "considerations": {}
385364          }
385365        },
385366        {
385367          "type": "library",
385368          "bom-ref": "pkg:npm/%40npmcli/run-script@4.2.1?package-id=a13d191f5a0789d1",
385369          "supplier": {},
385370          "author": "GitHub Inc.",
385371          "name": "@npmcli/run-script",
385372          "version": "4.2.1",
385373          "description": "Run a lifecycle script for a package (descendant of npm-lifecycle)",
385374          "licenses": [
385375            {
385376              "license": {
385377                "id": "ISC"
385378              }
385379            }
385380          ],
385381          "cpe": "cpe:2.3:a:\\@npmcli\\/run-script:\\@npmcli\\/run-script:4.2.1:*:*:*:*:*:*:*",
385382          "purl": "pkg:npm/%40npmcli/run-script@4.2.1",
385383          "swid": {
385384            "attachment": {}
385385          },
385386          "pedigree": {},
385387          "externalReferences": [
385388            {
385389              "url": "https://github.com/npm/run-script.git",
385390              "type": "distribution"
385391            }
385392          ],
385393          "evidence": {},
385394          "signature": {
385395            "signature": {
385396              "publicKey": {}
385397            }
385398          },
385399          "modelCard": {
385400            "modelParameters": {
385401              "approach": {}
385402            },
385403            "quantitativeAnalysis": {
385404              "graphics": {}
385405            },
385406            "considerations": {}
385407          }
385408        },
385409        {
385410          "type": "library",
385411          "bom-ref": "pkg:npm/%40sindresorhus/is@0.7.0?package-id=e3df623b6a06ebf4",
385412          "supplier": {},
385413          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
385414          "name": "@sindresorhus/is",
385415          "version": "0.7.0",
385416          "description": "Type check values: `is.string('🦄') //=\u003e true`",
385417          "licenses": [
385418            {
385419              "license": {
385420                "id": "MIT"
385421              }
385422            }
385423          ],
385424          "cpe": "cpe:2.3:a:\\@sindresorhus\\/is:\\@sindresorhus\\/is:0.7.0:*:*:*:*:*:*:*",
385425          "purl": "pkg:npm/%40sindresorhus/is@0.7.0",
385426          "swid": {
385427            "attachment": {}
385428          },
385429          "pedigree": {},
385430          "externalReferences": [
385431            {
385432              "url": "sindresorhus/is",
385433              "type": "distribution"
385434            }
385435          ],
385436          "evidence": {},
385437          "signature": {
385438            "signature": {
385439              "publicKey": {}
385440            }
385441          },
385442          "modelCard": {
385443            "modelParameters": {
385444              "approach": {}
385445            },
385446            "quantitativeAnalysis": {
385447              "graphics": {}
385448            },
385449            "considerations": {}
385450          }
385451        },
385452        {
385453          "type": "library",
385454          "bom-ref": "pkg:npm/%40sindresorhus/is@4.6.0?package-id=cd195c6bb003aa1d",
385455          "supplier": {},
385456          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
385457          "name": "@sindresorhus/is",
385458          "version": "4.6.0",
385459          "description": "Type check values",
385460          "licenses": [
385461            {
385462              "license": {
385463                "id": "MIT"
385464              }
385465            }
385466          ],
385467          "cpe": "cpe:2.3:a:\\@sindresorhus\\/is:\\@sindresorhus\\/is:4.6.0:*:*:*:*:*:*:*",
385468          "purl": "pkg:npm/%40sindresorhus/is@4.6.0",
385469          "swid": {
385470            "attachment": {}
385471          },
385472          "pedigree": {},
385473          "externalReferences": [
385474            {
385475              "url": "sindresorhus/is",
385476              "type": "distribution"
385477            }
385478          ],
385479          "evidence": {},
385480          "signature": {
385481            "signature": {
385482              "publicKey": {}
385483            }
385484          },
385485          "modelCard": {
385486            "modelParameters": {
385487              "approach": {}
385488            },
385489            "quantitativeAnalysis": {
385490              "graphics": {}
385491            },
385492            "considerations": {}
385493          }
385494        },
385495        {
385496          "type": "library",
385497          "bom-ref": "pkg:npm/%40szmarczak/http-timer@4.0.6?package-id=2b09e5ba02dc4567",
385498          "supplier": {},
385499          "author": "Szymon Marczak",
385500          "name": "@szmarczak/http-timer",
385501          "version": "4.0.6",
385502          "description": "Timings for HTTP requests",
385503          "licenses": [
385504            {
385505              "license": {
385506                "id": "MIT"
385507              }
385508            }
385509          ],
385510          "cpe": "cpe:2.3:a:\\@szmarczak\\/http-timer:\\@szmarczak\\/http-timer:4.0.6:*:*:*:*:*:*:*",
385511          "purl": "pkg:npm/%40szmarczak/http-timer@4.0.6",
385512          "swid": {
385513            "attachment": {}
385514          },
385515          "pedigree": {},
385516          "externalReferences": [
385517            {
385518              "url": "git+https://github.com/szmarczak/http-timer.git",
385519              "type": "distribution"
385520            },
385521            {
385522              "url": "https://github.com/szmarczak/http-timer#readme",
385523              "type": "website"
385524            }
385525          ],
385526          "evidence": {},
385527          "signature": {
385528            "signature": {
385529              "publicKey": {}
385530            }
385531          },
385532          "modelCard": {
385533            "modelParameters": {
385534              "approach": {}
385535            },
385536            "quantitativeAnalysis": {
385537              "graphics": {}
385538            },
385539            "considerations": {}
385540          }
385541        },
385542        {
385543          "type": "library",
385544          "bom-ref": "pkg:npm/%40tootallnate/once@2.0.0?package-id=5edbc75b01ae9167",
385545          "supplier": {},
385546          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
385547          "name": "@tootallnate/once",
385548          "version": "2.0.0",
385549          "description": "Creates a Promise that waits for a single event",
385550          "licenses": [
385551            {
385552              "license": {
385553                "id": "MIT"
385554              }
385555            }
385556          ],
385557          "cpe": "cpe:2.3:a:\\@tootallnate\\/once:\\@tootallnate\\/once:2.0.0:*:*:*:*:*:*:*",
385558          "purl": "pkg:npm/%40tootallnate/once@2.0.0",
385559          "swid": {
385560            "attachment": {}
385561          },
385562          "pedigree": {},
385563          "externalReferences": [
385564            {
385565              "url": "git://github.com/TooTallNate/once.git",
385566              "type": "distribution"
385567            }
385568          ],
385569          "evidence": {},
385570          "signature": {
385571            "signature": {
385572              "publicKey": {}
385573            }
385574          },
385575          "modelCard": {
385576            "modelParameters": {
385577              "approach": {}
385578            },
385579            "quantitativeAnalysis": {
385580              "graphics": {}
385581            },
385582            "considerations": {}
385583          }
385584        },
385585        {
385586          "type": "library",
385587          "bom-ref": "pkg:npm/%40types/cacheable-request@6.0.3?package-id=36f0fb5c2346e53b",
385588          "supplier": {},
385589          "name": "@types/cacheable-request",
385590          "version": "6.0.3",
385591          "description": "TypeScript definitions for cacheable-request",
385592          "licenses": [
385593            {
385594              "license": {
385595                "id": "MIT"
385596              }
385597            }
385598          ],
385599          "cpe": "cpe:2.3:a:\\@types\\/cacheable-request:\\@types\\/cacheable-request:6.0.3:*:*:*:*:*:*:*",
385600          "purl": "pkg:npm/%40types/cacheable-request@6.0.3",
385601          "swid": {
385602            "attachment": {}
385603          },
385604          "pedigree": {},
385605          "externalReferences": [
385606            {
385607              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
385608              "type": "distribution"
385609            },
385610            {
385611              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/cacheable-request",
385612              "type": "website"
385613            }
385614          ],
385615          "evidence": {},
385616          "signature": {
385617            "signature": {
385618              "publicKey": {}
385619            }
385620          },
385621          "modelCard": {
385622            "modelParameters": {
385623              "approach": {}
385624            },
385625            "quantitativeAnalysis": {
385626              "graphics": {}
385627            },
385628            "considerations": {}
385629          }
385630        },
385631        {
385632          "type": "library",
385633          "bom-ref": "pkg:npm/%40types/http-cache-semantics@4.0.1?package-id=17b6c635de91cb6c",
385634          "supplier": {},
385635          "name": "@types/http-cache-semantics",
385636          "version": "4.0.1",
385637          "description": "TypeScript definitions for http-cache-semantics",
385638          "licenses": [
385639            {
385640              "license": {
385641                "id": "MIT"
385642              }
385643            }
385644          ],
385645          "cpe": "cpe:2.3:a:\\@types\\/http-cache-semantics:\\@types\\/http-cache-semantics:4.0.1:*:*:*:*:*:*:*",
385646          "purl": "pkg:npm/%40types/http-cache-semantics@4.0.1",
385647          "swid": {
385648            "attachment": {}
385649          },
385650          "pedigree": {},
385651          "externalReferences": [
385652            {
385653              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
385654              "type": "distribution"
385655            },
385656            {
385657              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/http-cache-semantics",
385658              "type": "website"
385659            }
385660          ],
385661          "evidence": {},
385662          "signature": {
385663            "signature": {
385664              "publicKey": {}
385665            }
385666          },
385667          "modelCard": {
385668            "modelParameters": {
385669              "approach": {}
385670            },
385671            "quantitativeAnalysis": {
385672              "graphics": {}
385673            },
385674            "considerations": {}
385675          }
385676        },
385677        {
385678          "type": "library",
385679          "bom-ref": "pkg:npm/%40types/keyv@3.1.4?package-id=ccb394e9565a171e",
385680          "supplier": {},
385681          "name": "@types/keyv",
385682          "version": "3.1.4",
385683          "description": "TypeScript definitions for keyv",
385684          "licenses": [
385685            {
385686              "license": {
385687                "id": "MIT"
385688              }
385689            }
385690          ],
385691          "cpe": "cpe:2.3:a:DefinitelyTyped:\\@types\\/keyv:3.1.4:*:*:*:*:*:*:*",
385692          "purl": "pkg:npm/%40types/keyv@3.1.4",
385693          "swid": {
385694            "attachment": {}
385695          },
385696          "pedigree": {},
385697          "externalReferences": [
385698            {
385699              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
385700              "type": "distribution"
385701            },
385702            {
385703              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/keyv",
385704              "type": "website"
385705            }
385706          ],
385707          "evidence": {},
385708          "signature": {
385709            "signature": {
385710              "publicKey": {}
385711            }
385712          },
385713          "modelCard": {
385714            "modelParameters": {
385715              "approach": {}
385716            },
385717            "quantitativeAnalysis": {
385718              "graphics": {}
385719            },
385720            "considerations": {}
385721          }
385722        },
385723        {
385724          "type": "library",
385725          "bom-ref": "pkg:npm/%40types/node@18.15.13?package-id=67fbfc5c206dcd12",
385726          "supplier": {},
385727          "name": "@types/node",
385728          "version": "18.15.13",
385729          "description": "TypeScript definitions for Node.js",
385730          "licenses": [
385731            {
385732              "license": {
385733                "id": "MIT"
385734              }
385735            }
385736          ],
385737          "cpe": "cpe:2.3:a:DefinitelyTyped:\\@types\\/node:18.15.13:*:*:*:*:*:*:*",
385738          "purl": "pkg:npm/%40types/node@18.15.13",
385739          "swid": {
385740            "attachment": {}
385741          },
385742          "pedigree": {},
385743          "externalReferences": [
385744            {
385745              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
385746              "type": "distribution"
385747            },
385748            {
385749              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node",
385750              "type": "website"
385751            }
385752          ],
385753          "evidence": {},
385754          "signature": {
385755            "signature": {
385756              "publicKey": {}
385757            }
385758          },
385759          "modelCard": {
385760            "modelParameters": {
385761              "approach": {}
385762            },
385763            "quantitativeAnalysis": {
385764              "graphics": {}
385765            },
385766            "considerations": {}
385767          }
385768        },
385769        {
385770          "type": "library",
385771          "bom-ref": "pkg:npm/%40types/responselike@1.0.0?package-id=a839275642b0ad1f",
385772          "supplier": {},
385773          "name": "@types/responselike",
385774          "version": "1.0.0",
385775          "description": "TypeScript definitions for responselike",
385776          "licenses": [
385777            {
385778              "license": {
385779                "id": "MIT"
385780              }
385781            }
385782          ],
385783          "cpe": "cpe:2.3:a:\\@types\\/responselike:\\@types\\/responselike:1.0.0:*:*:*:*:*:*:*",
385784          "purl": "pkg:npm/%40types/responselike@1.0.0",
385785          "swid": {
385786            "attachment": {}
385787          },
385788          "pedigree": {},
385789          "externalReferences": [
385790            {
385791              "url": "https://github.com/DefinitelyTyped/DefinitelyTyped.git",
385792              "type": "distribution"
385793            }
385794          ],
385795          "evidence": {},
385796          "signature": {
385797            "signature": {
385798              "publicKey": {}
385799            }
385800          },
385801          "modelCard": {
385802            "modelParameters": {
385803              "approach": {}
385804            },
385805            "quantitativeAnalysis": {
385806              "graphics": {}
385807            },
385808            "considerations": {}
385809          }
385810        },
385811        {
385812          "type": "library",
385813          "bom-ref": "pkg:npm/%40yarnpkg/lockfile@1.1.0?package-id=9c8464766b4d299a",
385814          "supplier": {},
385815          "name": "@yarnpkg/lockfile",
385816          "version": "1.1.0",
385817          "description": "The parser/stringifier for Yarn lockfiles.",
385818          "licenses": [
385819            {
385820              "license": {
385821                "id": "BSD-2-Clause"
385822              }
385823            }
385824          ],
385825          "cpe": "cpe:2.3:a:\\@yarnpkg\\/lockfile:\\@yarnpkg\\/lockfile:1.1.0:*:*:*:*:*:*:*",
385826          "purl": "pkg:npm/%40yarnpkg/lockfile@1.1.0",
385827          "swid": {
385828            "attachment": {}
385829          },
385830          "pedigree": {},
385831          "externalReferences": [
385832            {
385833              "url": "https://github.com/yarnpkg/yarn/blob/master/packages/lockfile",
385834              "type": "distribution"
385835            }
385836          ],
385837          "evidence": {},
385838          "signature": {
385839            "signature": {
385840              "publicKey": {}
385841            }
385842          },
385843          "modelCard": {
385844            "modelParameters": {
385845              "approach": {}
385846            },
385847            "quantitativeAnalysis": {
385848              "graphics": {}
385849            },
385850            "considerations": {}
385851          }
385852        },
385853        {
385854          "type": "library",
385855          "bom-ref": "pkg:npm/abbrev@1.1.1?package-id=98be1cad3f4d1d11",
385856          "supplier": {},
385857          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
385858          "name": "abbrev",
385859          "version": "1.1.1",
385860          "description": "Like ruby's abbrev module, but in js",
385861          "licenses": [
385862            {
385863              "license": {
385864                "id": "ISC"
385865              }
385866            }
385867          ],
385868          "cpe": "cpe:2.3:a:abbrev:abbrev:1.1.1:*:*:*:*:*:*:*",
385869          "purl": "pkg:npm/abbrev@1.1.1",
385870          "swid": {
385871            "attachment": {}
385872          },
385873          "pedigree": {},
385874          "externalReferences": [
385875            {
385876              "url": "http://github.com/isaacs/abbrev-js",
385877              "type": "distribution"
385878            }
385879          ],
385880          "evidence": {},
385881          "signature": {
385882            "signature": {
385883              "publicKey": {}
385884            }
385885          },
385886          "modelCard": {
385887            "modelParameters": {
385888              "approach": {}
385889            },
385890            "quantitativeAnalysis": {
385891              "graphics": {}
385892            },
385893            "considerations": {}
385894          }
385895        },
385896        {
385897          "type": "library",
385898          "bom-ref": "pkg:npm/accepts@1.3.8?package-id=b001a70346b0612b",
385899          "supplier": {},
385900          "name": "accepts",
385901          "version": "1.3.8",
385902          "description": "Higher-level content negotiation",
385903          "licenses": [
385904            {
385905              "license": {
385906                "id": "MIT"
385907              }
385908            }
385909          ],
385910          "cpe": "cpe:2.3:a:accepts:accepts:1.3.8:*:*:*:*:*:*:*",
385911          "purl": "pkg:npm/accepts@1.3.8",
385912          "swid": {
385913            "attachment": {}
385914          },
385915          "pedigree": {},
385916          "externalReferences": [
385917            {
385918              "url": "jshttp/accepts",
385919              "type": "distribution"
385920            }
385921          ],
385922          "evidence": {},
385923          "signature": {
385924            "signature": {
385925              "publicKey": {}
385926            }
385927          },
385928          "modelCard": {
385929            "modelParameters": {
385930              "approach": {}
385931            },
385932            "quantitativeAnalysis": {
385933              "graphics": {}
385934            },
385935            "considerations": {}
385936          }
385937        },
385938        {
385939          "type": "library",
385940          "bom-ref": "pkg:npm/adm-zip@0.5.10?package-id=55041b339e152158",
385941          "supplier": {},
385942          "author": "Nasca Iacob \u003csy@another-d-mention.ro\u003e (https://github.com/cthackers)",
385943          "name": "adm-zip",
385944          "version": "0.5.10",
385945          "description": "Javascript implementation of zip for nodejs with support for electron original-fs. Allows user to create or extract zip files both in memory or to/from disk",
385946          "licenses": [
385947            {
385948              "license": {
385949                "id": "MIT"
385950              }
385951            }
385952          ],
385953          "cpe": "cpe:2.3:a:cthackers:adm-zip:0.5.10:*:*:*:*:*:*:*",
385954          "purl": "pkg:npm/adm-zip@0.5.10",
385955          "swid": {
385956            "attachment": {}
385957          },
385958          "pedigree": {},
385959          "externalReferences": [
385960            {
385961              "url": "https://github.com/cthackers/adm-zip.git",
385962              "type": "distribution"
385963            },
385964            {
385965              "url": "https://github.com/cthackers/adm-zip",
385966              "type": "website"
385967            }
385968          ],
385969          "evidence": {},
385970          "signature": {
385971            "signature": {
385972              "publicKey": {}
385973            }
385974          },
385975          "modelCard": {
385976            "modelParameters": {
385977              "approach": {}
385978            },
385979            "quantitativeAnalysis": {
385980              "graphics": {}
385981            },
385982            "considerations": {}
385983          }
385984        },
385985        {
385986          "type": "library",
385987          "bom-ref": "pkg:npm/agent-base@6.0.2?package-id=4b0b5c9ee7d8fc08",
385988          "supplier": {},
385989          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
385990          "name": "agent-base",
385991          "version": "6.0.2",
385992          "description": "Turn a function into an `http.Agent` instance",
385993          "licenses": [
385994            {
385995              "license": {
385996                "id": "MIT"
385997              }
385998            }
385999          ],
386000          "cpe": "cpe:2.3:a:TooTallNate:agent-base:6.0.2:*:*:*:*:*:*:*",
386001          "purl": "pkg:npm/agent-base@6.0.2",
386002          "swid": {
386003            "attachment": {}
386004          },
386005          "pedigree": {},
386006          "externalReferences": [
386007            {
386008              "url": "git://github.com/TooTallNate/node-agent-base.git",
386009              "type": "distribution"
386010            }
386011          ],
386012          "evidence": {},
386013          "signature": {
386014            "signature": {
386015              "publicKey": {}
386016            }
386017          },
386018          "modelCard": {
386019            "modelParameters": {
386020              "approach": {}
386021            },
386022            "quantitativeAnalysis": {
386023              "graphics": {}
386024            },
386025            "considerations": {}
386026          }
386027        },
386028        {
386029          "type": "library",
386030          "bom-ref": "pkg:npm/agentkeepalive@4.2.1?package-id=37fa9bcd67324d6e",
386031          "supplier": {},
386032          "author": "fengmk2 \u003cfengmk2@gmail.com\u003e (https://fengmk2.com)",
386033          "name": "agentkeepalive",
386034          "version": "4.2.1",
386035          "description": "Missing keepalive http.Agent",
386036          "licenses": [
386037            {
386038              "license": {
386039                "id": "MIT"
386040              }
386041            }
386042          ],
386043          "cpe": "cpe:2.3:a:agentkeepalive:agentkeepalive:4.2.1:*:*:*:*:*:*:*",
386044          "purl": "pkg:npm/agentkeepalive@4.2.1",
386045          "swid": {
386046            "attachment": {}
386047          },
386048          "pedigree": {},
386049          "externalReferences": [
386050            {
386051              "url": "git://github.com/node-modules/agentkeepalive.git",
386052              "type": "distribution"
386053            }
386054          ],
386055          "evidence": {},
386056          "signature": {
386057            "signature": {
386058              "publicKey": {}
386059            }
386060          },
386061          "modelCard": {
386062            "modelParameters": {
386063              "approach": {}
386064            },
386065            "quantitativeAnalysis": {
386066              "graphics": {}
386067            },
386068            "considerations": {}
386069          }
386070        },
386071        {
386072          "type": "library",
386073          "bom-ref": "pkg:npm/aggregate-error@3.1.0?package-id=b1b74a520919b83f",
386074          "supplier": {},
386075          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
386076          "name": "aggregate-error",
386077          "version": "3.1.0",
386078          "description": "Create an error from multiple errors",
386079          "licenses": [
386080            {
386081              "license": {
386082                "id": "MIT"
386083              }
386084            }
386085          ],
386086          "cpe": "cpe:2.3:a:aggregate-error:aggregate-error:3.1.0:*:*:*:*:*:*:*",
386087          "purl": "pkg:npm/aggregate-error@3.1.0",
386088          "swid": {
386089            "attachment": {}
386090          },
386091          "pedigree": {},
386092          "externalReferences": [
386093            {
386094              "url": "sindresorhus/aggregate-error",
386095              "type": "distribution"
386096            }
386097          ],
386098          "evidence": {},
386099          "signature": {
386100            "signature": {
386101              "publicKey": {}
386102            }
386103          },
386104          "modelCard": {
386105            "modelParameters": {
386106              "approach": {}
386107            },
386108            "quantitativeAnalysis": {
386109              "graphics": {}
386110            },
386111            "considerations": {}
386112          }
386113        },
386114        {
386115          "type": "library",
386116          "bom-ref": "pkg:npm/ajv@6.12.6?package-id=499abcf86654fa15",
386117          "supplier": {},
386118          "author": "Evgeny Poberezkin",
386119          "name": "ajv",
386120          "version": "6.12.6",
386121          "description": "Another JSON Schema Validator",
386122          "licenses": [
386123            {
386124              "license": {
386125                "id": "MIT"
386126              }
386127            }
386128          ],
386129          "cpe": "cpe:2.3:a:ajv-validator:ajv:6.12.6:*:*:*:*:*:*:*",
386130          "purl": "pkg:npm/ajv@6.12.6",
386131          "swid": {
386132            "attachment": {}
386133          },
386134          "pedigree": {},
386135          "externalReferences": [
386136            {
386137              "url": "https://github.com/ajv-validator/ajv.git",
386138              "type": "distribution"
386139            },
386140            {
386141              "url": "https://github.com/ajv-validator/ajv",
386142              "type": "website"
386143            }
386144          ],
386145          "evidence": {},
386146          "signature": {
386147            "signature": {
386148              "publicKey": {}
386149            }
386150          },
386151          "modelCard": {
386152            "modelParameters": {
386153              "approach": {}
386154            },
386155            "quantitativeAnalysis": {
386156              "graphics": {}
386157            },
386158            "considerations": {}
386159          }
386160        },
386161        {
386162          "type": "library",
386163          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=61eac5ce8105d394",
386164          "supplier": {},
386165          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
386166          "name": "alpine-baselayout",
386167          "version": "3.2.0-r23",
386168          "description": "Alpine base dir structure and init scripts",
386169          "licenses": [
386170            {
386171              "license": {
386172                "id": "GPL-2.0-only"
386173              }
386174            }
386175          ],
386176          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r23:*:*:*:*:*:*:*",
386177          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5",
386178          "swid": {
386179            "attachment": {}
386180          },
386181          "pedigree": {},
386182          "externalReferences": [
386183            {
386184              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
386185              "type": "distribution"
386186            }
386187          ],
386188          "evidence": {},
386189          "signature": {
386190            "signature": {
386191              "publicKey": {}
386192            }
386193          },
386194          "modelCard": {
386195            "modelParameters": {
386196              "approach": {}
386197            },
386198            "quantitativeAnalysis": {
386199              "graphics": {}
386200            },
386201            "considerations": {}
386202          }
386203        },
386204        {
386205          "type": "library",
386206          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5\u0026package-id=e8c6fcc3a282ed4f",
386207          "supplier": {},
386208          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
386209          "name": "alpine-baselayout-data",
386210          "version": "3.2.0-r23",
386211          "description": "Alpine base dir structure and init scripts",
386212          "licenses": [
386213            {
386214              "license": {
386215                "id": "GPL-2.0-only"
386216              }
386217            }
386218          ],
386219          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.2.0-r23:*:*:*:*:*:*:*",
386220          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5",
386221          "swid": {
386222            "attachment": {}
386223          },
386224          "pedigree": {},
386225          "externalReferences": [
386226            {
386227              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
386228              "type": "distribution"
386229            }
386230          ],
386231          "evidence": {},
386232          "signature": {
386233            "signature": {
386234              "publicKey": {}
386235            }
386236          },
386237          "modelCard": {
386238            "modelParameters": {
386239              "approach": {}
386240            },
386241            "quantitativeAnalysis": {
386242              "graphics": {}
386243            },
386244            "considerations": {}
386245          }
386246        },
386247        {
386248          "type": "library",
386249          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=82d183eb300978cc",
386250          "supplier": {},
386251          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
386252          "name": "alpine-keys",
386253          "version": "2.4-r1",
386254          "description": "Public keys for Alpine Linux packages",
386255          "licenses": [
386256            {
386257              "license": {
386258                "id": "MIT"
386259              }
386260            }
386261          ],
386262          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
386263          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5",
386264          "swid": {
386265            "attachment": {}
386266          },
386267          "pedigree": {},
386268          "externalReferences": [
386269            {
386270              "url": "https://alpinelinux.org",
386271              "type": "distribution"
386272            }
386273          ],
386274          "evidence": {},
386275          "signature": {
386276            "signature": {
386277              "publicKey": {}
386278            }
386279          },
386280          "modelCard": {
386281            "modelParameters": {
386282              "approach": {}
386283            },
386284            "quantitativeAnalysis": {
386285              "graphics": {}
386286            },
386287            "considerations": {}
386288          }
386289        },
386290        {
386291          "type": "library",
386292          "bom-ref": "pkg:npm/ansi-regex@4.1.1?package-id=3e7a851a9d992fda",
386293          "supplier": {},
386294          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
386295          "name": "ansi-regex",
386296          "version": "4.1.1",
386297          "description": "Regular expression for matching ANSI escape codes",
386298          "licenses": [
386299            {
386300              "license": {
386301                "id": "MIT"
386302              }
386303            }
386304          ],
386305          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:4.1.1:*:*:*:*:*:*:*",
386306          "purl": "pkg:npm/ansi-regex@4.1.1",
386307          "swid": {
386308            "attachment": {}
386309          },
386310          "pedigree": {},
386311          "externalReferences": [
386312            {
386313              "url": "chalk/ansi-regex",
386314              "type": "distribution"
386315            }
386316          ],
386317          "evidence": {},
386318          "signature": {
386319            "signature": {
386320              "publicKey": {}
386321            }
386322          },
386323          "modelCard": {
386324            "modelParameters": {
386325              "approach": {}
386326            },
386327            "quantitativeAnalysis": {
386328              "graphics": {}
386329            },
386330            "considerations": {}
386331          }
386332        },
386333        {
386334          "type": "library",
386335          "bom-ref": "pkg:npm/ansi-regex@5.0.1?package-id=fe78ee8372cda3ef",
386336          "supplier": {},
386337          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
386338          "name": "ansi-regex",
386339          "version": "5.0.1",
386340          "description": "Regular expression for matching ANSI escape codes",
386341          "licenses": [
386342            {
386343              "license": {
386344                "id": "MIT"
386345              }
386346            }
386347          ],
386348          "cpe": "cpe:2.3:a:ansi-regex:ansi-regex:5.0.1:*:*:*:*:*:*:*",
386349          "purl": "pkg:npm/ansi-regex@5.0.1",
386350          "swid": {
386351            "attachment": {}
386352          },
386353          "pedigree": {},
386354          "externalReferences": [
386355            {
386356              "url": "chalk/ansi-regex",
386357              "type": "distribution"
386358            }
386359          ],
386360          "evidence": {},
386361          "signature": {
386362            "signature": {
386363              "publicKey": {}
386364            }
386365          },
386366          "modelCard": {
386367            "modelParameters": {
386368              "approach": {}
386369            },
386370            "quantitativeAnalysis": {
386371              "graphics": {}
386372            },
386373            "considerations": {}
386374          }
386375        },
386376        {
386377          "type": "library",
386378          "bom-ref": "pkg:npm/ansi-styles@3.2.1?package-id=ae661c6c4239b569",
386379          "supplier": {},
386380          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
386381          "name": "ansi-styles",
386382          "version": "3.2.1",
386383          "description": "ANSI escape codes for styling strings in the terminal",
386384          "licenses": [
386385            {
386386              "license": {
386387                "id": "MIT"
386388              }
386389            }
386390          ],
386391          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:3.2.1:*:*:*:*:*:*:*",
386392          "purl": "pkg:npm/ansi-styles@3.2.1",
386393          "swid": {
386394            "attachment": {}
386395          },
386396          "pedigree": {},
386397          "externalReferences": [
386398            {
386399              "url": "chalk/ansi-styles",
386400              "type": "distribution"
386401            }
386402          ],
386403          "evidence": {},
386404          "signature": {
386405            "signature": {
386406              "publicKey": {}
386407            }
386408          },
386409          "modelCard": {
386410            "modelParameters": {
386411              "approach": {}
386412            },
386413            "quantitativeAnalysis": {
386414              "graphics": {}
386415            },
386416            "considerations": {}
386417          }
386418        },
386419        {
386420          "type": "library",
386421          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=e3f310fd74532509",
386422          "supplier": {},
386423          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
386424          "name": "ansi-styles",
386425          "version": "4.3.0",
386426          "description": "ANSI escape codes for styling strings in the terminal",
386427          "licenses": [
386428            {
386429              "license": {
386430                "id": "MIT"
386431              }
386432            }
386433          ],
386434          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
386435          "purl": "pkg:npm/ansi-styles@4.3.0",
386436          "swid": {
386437            "attachment": {}
386438          },
386439          "pedigree": {},
386440          "externalReferences": [
386441            {
386442              "url": "chalk/ansi-styles",
386443              "type": "distribution"
386444            }
386445          ],
386446          "evidence": {},
386447          "signature": {
386448            "signature": {
386449              "publicKey": {}
386450            }
386451          },
386452          "modelCard": {
386453            "modelParameters": {
386454              "approach": {}
386455            },
386456            "quantitativeAnalysis": {
386457              "graphics": {}
386458            },
386459            "considerations": {}
386460          }
386461        },
386462        {
386463          "type": "library",
386464          "bom-ref": "pkg:npm/ansi-styles@4.3.0?package-id=cc23254c622251e8",
386465          "supplier": {},
386466          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
386467          "name": "ansi-styles",
386468          "version": "4.3.0",
386469          "description": "ANSI escape codes for styling strings in the terminal",
386470          "licenses": [
386471            {
386472              "license": {
386473                "id": "MIT"
386474              }
386475            }
386476          ],
386477          "cpe": "cpe:2.3:a:ansi-styles:ansi-styles:4.3.0:*:*:*:*:*:*:*",
386478          "purl": "pkg:npm/ansi-styles@4.3.0",
386479          "swid": {
386480            "attachment": {}
386481          },
386482          "pedigree": {},
386483          "externalReferences": [
386484            {
386485              "url": "chalk/ansi-styles",
386486              "type": "distribution"
386487            }
386488          ],
386489          "evidence": {},
386490          "signature": {
386491            "signature": {
386492              "publicKey": {}
386493            }
386494          },
386495          "modelCard": {
386496            "modelParameters": {
386497              "approach": {}
386498            },
386499            "quantitativeAnalysis": {
386500              "graphics": {}
386501            },
386502            "considerations": {}
386503          }
386504        },
386505        {
386506          "type": "library",
386507          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=42d502b764a37310",
386508          "supplier": {},
386509          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
386510          "name": "apk-tools",
386511          "version": "2.12.9-r3",
386512          "description": "Alpine Package Keeper - package manager for alpine",
386513          "licenses": [
386514            {
386515              "license": {
386516                "id": "GPL-2.0-only"
386517              }
386518            }
386519          ],
386520          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.9-r3:*:*:*:*:*:*:*",
386521          "purl": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5",
386522          "swid": {
386523            "attachment": {}
386524          },
386525          "pedigree": {},
386526          "externalReferences": [
386527            {
386528              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
386529              "type": "distribution"
386530            }
386531          ],
386532          "evidence": {},
386533          "signature": {
386534            "signature": {
386535              "publicKey": {}
386536            }
386537          },
386538          "modelCard": {
386539            "modelParameters": {
386540              "approach": {}
386541            },
386542            "quantitativeAnalysis": {
386543              "graphics": {}
386544            },
386545            "considerations": {}
386546          }
386547        },
386548        {
386549          "type": "library",
386550          "bom-ref": "pkg:npm/app-builder@7.0.4?package-id=f548684de5bc50e3",
386551          "supplier": {},
386552          "author": "Caleb Boyd (https://github.com/calebboyd)",
386553          "name": "app-builder",
386554          "version": "7.0.4",
386555          "description": "Promise based composable functions for middleware",
386556          "licenses": [
386557            {
386558              "license": {
386559                "id": "MIT"
386560              }
386561            }
386562          ],
386563          "cpe": "cpe:2.3:a:app-builder:app-builder:7.0.4:*:*:*:*:*:*:*",
386564          "purl": "pkg:npm/app-builder@7.0.4",
386565          "swid": {
386566            "attachment": {}
386567          },
386568          "pedigree": {},
386569          "externalReferences": [
386570            {
386571              "url": "https://github.com/calebboyd/app-builder.git",
386572              "type": "distribution"
386573            },
386574            {
386575              "url": "https://github.com/ingress/app-builder",
386576              "type": "website"
386577            }
386578          ],
386579          "evidence": {},
386580          "signature": {
386581            "signature": {
386582              "publicKey": {}
386583            }
386584          },
386585          "modelCard": {
386586            "modelParameters": {
386587              "approach": {}
386588            },
386589            "quantitativeAnalysis": {
386590              "graphics": {}
386591            },
386592            "considerations": {}
386593          }
386594        },
386595        {
386596          "type": "library",
386597          "bom-ref": "pkg:npm/aproba@2.0.0?package-id=d11111a04d810227",
386598          "supplier": {},
386599          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
386600          "name": "aproba",
386601          "version": "2.0.0",
386602          "description": "A ridiculously light-weight argument validator (now browser friendly)",
386603          "licenses": [
386604            {
386605              "license": {
386606                "id": "ISC"
386607              }
386608            }
386609          ],
386610          "cpe": "cpe:2.3:a:aproba:aproba:2.0.0:*:*:*:*:*:*:*",
386611          "purl": "pkg:npm/aproba@2.0.0",
386612          "swid": {
386613            "attachment": {}
386614          },
386615          "pedigree": {},
386616          "externalReferences": [
386617            {
386618              "url": "https://github.com/iarna/aproba",
386619              "type": "distribution"
386620            },
386621            {
386622              "url": "https://github.com/iarna/aproba",
386623              "type": "website"
386624            }
386625          ],
386626          "evidence": {},
386627          "signature": {
386628            "signature": {
386629              "publicKey": {}
386630            }
386631          },
386632          "modelCard": {
386633            "modelParameters": {
386634              "approach": {}
386635            },
386636            "quantitativeAnalysis": {
386637              "graphics": {}
386638            },
386639            "considerations": {}
386640          }
386641        },
386642        {
386643          "type": "library",
386644          "bom-ref": "pkg:npm/archive-type@4.0.0?package-id=7998a7beb8338766",
386645          "supplier": {},
386646          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (https://github.com/kevva)",
386647          "name": "archive-type",
386648          "version": "4.0.0",
386649          "description": "Detect the archive type of a Buffer/Uint8Array",
386650          "licenses": [
386651            {
386652              "license": {
386653                "id": "MIT"
386654              }
386655            }
386656          ],
386657          "cpe": "cpe:2.3:a:archive-type:archive-type:4.0.0:*:*:*:*:*:*:*",
386658          "purl": "pkg:npm/archive-type@4.0.0",
386659          "swid": {
386660            "attachment": {}
386661          },
386662          "pedigree": {},
386663          "externalReferences": [
386664            {
386665              "url": "kevva/archive-type",
386666              "type": "distribution"
386667            }
386668          ],
386669          "evidence": {},
386670          "signature": {
386671            "signature": {
386672              "publicKey": {}
386673            }
386674          },
386675          "modelCard": {
386676            "modelParameters": {
386677              "approach": {}
386678            },
386679            "quantitativeAnalysis": {
386680              "graphics": {}
386681            },
386682            "considerations": {}
386683          }
386684        },
386685        {
386686          "type": "library",
386687          "bom-ref": "pkg:npm/archy@1.0.0?package-id=a1e7fd77fec54095",
386688          "supplier": {},
386689          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
386690          "name": "archy",
386691          "version": "1.0.0",
386692          "description": "render nested hierarchies `npm ls` style with unicode pipes",
386693          "licenses": [
386694            {
386695              "license": {
386696                "id": "MIT"
386697              }
386698            }
386699          ],
386700          "cpe": "cpe:2.3:a:substack:archy:1.0.0:*:*:*:*:*:*:*",
386701          "purl": "pkg:npm/archy@1.0.0",
386702          "swid": {
386703            "attachment": {}
386704          },
386705          "pedigree": {},
386706          "externalReferences": [
386707            {
386708              "url": "http://github.com/substack/node-archy.git",
386709              "type": "distribution"
386710            }
386711          ],
386712          "evidence": {},
386713          "signature": {
386714            "signature": {
386715              "publicKey": {}
386716            }
386717          },
386718          "modelCard": {
386719            "modelParameters": {
386720              "approach": {}
386721            },
386722            "quantitativeAnalysis": {
386723              "graphics": {}
386724            },
386725            "considerations": {}
386726          }
386727        },
386728        {
386729          "type": "library",
386730          "bom-ref": "pkg:npm/are-we-there-yet@3.0.1?package-id=d7ea73c2e385c95d",
386731          "supplier": {},
386732          "author": "GitHub Inc.",
386733          "name": "are-we-there-yet",
386734          "version": "3.0.1",
386735          "description": "Keep track of the overall completion of many disparate processes",
386736          "licenses": [
386737            {
386738              "license": {
386739                "id": "ISC"
386740              }
386741            }
386742          ],
386743          "cpe": "cpe:2.3:a:are-we-there-yet:are-we-there-yet:3.0.1:*:*:*:*:*:*:*",
386744          "purl": "pkg:npm/are-we-there-yet@3.0.1",
386745          "swid": {
386746            "attachment": {}
386747          },
386748          "pedigree": {},
386749          "externalReferences": [
386750            {
386751              "url": "https://github.com/npm/are-we-there-yet.git",
386752              "type": "distribution"
386753            },
386754            {
386755              "url": "https://github.com/npm/are-we-there-yet",
386756              "type": "website"
386757            }
386758          ],
386759          "evidence": {},
386760          "signature": {
386761            "signature": {
386762              "publicKey": {}
386763            }
386764          },
386765          "modelCard": {
386766            "modelParameters": {
386767              "approach": {}
386768            },
386769            "quantitativeAnalysis": {
386770              "graphics": {}
386771            },
386772            "considerations": {}
386773          }
386774        },
386775        {
386776          "type": "library",
386777          "bom-ref": "pkg:npm/array-flatten@1.1.1?package-id=169fa984c33ff9f6",
386778          "supplier": {},
386779          "author": "Blake Embrey \u003chello@blakeembrey.com\u003e (http://blakeembrey.me)",
386780          "name": "array-flatten",
386781          "version": "1.1.1",
386782          "description": "Flatten an array of nested arrays into a single flat array",
386783          "licenses": [
386784            {
386785              "license": {
386786                "id": "MIT"
386787              }
386788            }
386789          ],
386790          "cpe": "cpe:2.3:a:array-flatten:array-flatten:1.1.1:*:*:*:*:*:*:*",
386791          "purl": "pkg:npm/array-flatten@1.1.1",
386792          "swid": {
386793            "attachment": {}
386794          },
386795          "pedigree": {},
386796          "externalReferences": [
386797            {
386798              "url": "git://github.com/blakeembrey/array-flatten.git",
386799              "type": "distribution"
386800            },
386801            {
386802              "url": "https://github.com/blakeembrey/array-flatten",
386803              "type": "website"
386804            }
386805          ],
386806          "evidence": {},
386807          "signature": {
386808            "signature": {
386809              "publicKey": {}
386810            }
386811          },
386812          "modelCard": {
386813            "modelParameters": {
386814              "approach": {}
386815            },
386816            "quantitativeAnalysis": {
386817              "graphics": {}
386818            },
386819            "considerations": {}
386820          }
386821        },
386822        {
386823          "type": "library",
386824          "bom-ref": "pkg:npm/array-union@2.1.0?package-id=deb22c36ab77edb6",
386825          "supplier": {},
386826          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
386827          "name": "array-union",
386828          "version": "2.1.0",
386829          "description": "Create an array of unique values, in order, from the input arrays",
386830          "licenses": [
386831            {
386832              "license": {
386833                "id": "MIT"
386834              }
386835            }
386836          ],
386837          "cpe": "cpe:2.3:a:array-union:array-union:2.1.0:*:*:*:*:*:*:*",
386838          "purl": "pkg:npm/array-union@2.1.0",
386839          "swid": {
386840            "attachment": {}
386841          },
386842          "pedigree": {},
386843          "externalReferences": [
386844            {
386845              "url": "sindresorhus/array-union",
386846              "type": "distribution"
386847            }
386848          ],
386849          "evidence": {},
386850          "signature": {
386851            "signature": {
386852              "publicKey": {}
386853            }
386854          },
386855          "modelCard": {
386856            "modelParameters": {
386857              "approach": {}
386858            },
386859            "quantitativeAnalysis": {
386860              "graphics": {}
386861            },
386862            "considerations": {}
386863          }
386864        },
386865        {
386866          "type": "library",
386867          "bom-ref": "pkg:npm/asap@2.0.6?package-id=4069b89e24646503",
386868          "supplier": {},
386869          "name": "asap",
386870          "version": "2.0.6",
386871          "description": "High-priority task queue for Node.js and browsers",
386872          "licenses": [
386873            {
386874              "license": {
386875                "id": "MIT"
386876              }
386877            }
386878          ],
386879          "cpe": "cpe:2.3:a:kriskowal:asap:2.0.6:*:*:*:*:*:*:*",
386880          "purl": "pkg:npm/asap@2.0.6",
386881          "swid": {
386882            "attachment": {}
386883          },
386884          "pedigree": {},
386885          "externalReferences": [
386886            {
386887              "url": "https://github.com/kriskowal/asap.git",
386888              "type": "distribution"
386889            }
386890          ],
386891          "evidence": {},
386892          "signature": {
386893            "signature": {
386894              "publicKey": {}
386895            }
386896          },
386897          "modelCard": {
386898            "modelParameters": {
386899              "approach": {}
386900            },
386901            "quantitativeAnalysis": {
386902              "graphics": {}
386903            },
386904            "considerations": {}
386905          }
386906        },
386907        {
386908          "type": "library",
386909          "bom-ref": "pkg:npm/asn1@0.2.6?package-id=fa945e5e8e9c4123",
386910          "supplier": {},
386911          "author": "Joyent (joyent.com)",
386912          "name": "asn1",
386913          "version": "0.2.6",
386914          "description": "Contains parsers and serializers for ASN.1 (currently BER only)",
386915          "licenses": [
386916            {
386917              "license": {
386918                "id": "MIT"
386919              }
386920            }
386921          ],
386922          "cpe": "cpe:2.3:a:joyent:asn1:0.2.6:*:*:*:*:*:*:*",
386923          "purl": "pkg:npm/asn1@0.2.6",
386924          "swid": {
386925            "attachment": {}
386926          },
386927          "pedigree": {},
386928          "externalReferences": [
386929            {
386930              "url": "https://github.com/joyent/node-asn1.git",
386931              "type": "distribution"
386932            }
386933          ],
386934          "evidence": {},
386935          "signature": {
386936            "signature": {
386937              "publicKey": {}
386938            }
386939          },
386940          "modelCard": {
386941            "modelParameters": {
386942              "approach": {}
386943            },
386944            "quantitativeAnalysis": {
386945              "graphics": {}
386946            },
386947            "considerations": {}
386948          }
386949        },
386950        {
386951          "type": "library",
386952          "bom-ref": "pkg:npm/assert-plus@1.0.0?package-id=fefb0d3370d896dc",
386953          "supplier": {},
386954          "author": "Mark Cavage \u003cmcavage@gmail.com\u003e",
386955          "name": "assert-plus",
386956          "version": "1.0.0",
386957          "description": "Extra assertions on top of node's assert module",
386958          "licenses": [
386959            {
386960              "license": {
386961                "id": "MIT"
386962              }
386963            }
386964          ],
386965          "cpe": "cpe:2.3:a:assert-plus:assert-plus:1.0.0:*:*:*:*:*:*:*",
386966          "purl": "pkg:npm/assert-plus@1.0.0",
386967          "swid": {
386968            "attachment": {}
386969          },
386970          "pedigree": {},
386971          "externalReferences": [
386972            {
386973              "url": "https://github.com/mcavage/node-assert-plus.git",
386974              "type": "distribution"
386975            }
386976          ],
386977          "evidence": {},
386978          "signature": {
386979            "signature": {
386980              "publicKey": {}
386981            }
386982          },
386983          "modelCard": {
386984            "modelParameters": {
386985              "approach": {}
386986            },
386987            "quantitativeAnalysis": {
386988              "graphics": {}
386989            },
386990            "considerations": {}
386991          }
386992        },
386993        {
386994          "type": "library",
386995          "bom-ref": "pkg:npm/async@3.2.4?package-id=231b7b86b151b693",
386996          "supplier": {},
386997          "author": "Caolan McMahon",
386998          "name": "async",
386999          "version": "3.2.4",
387000          "description": "Higher-order functions and common patterns for asynchronous code",
387001          "licenses": [
387002            {
387003              "license": {
387004                "id": "MIT"
387005              }
387006            }
387007          ],
387008          "cpe": "cpe:2.3:a:caolan:async:3.2.4:*:*:*:*:*:*:*",
387009          "purl": "pkg:npm/async@3.2.4",
387010          "swid": {
387011            "attachment": {}
387012          },
387013          "pedigree": {},
387014          "externalReferences": [
387015            {
387016              "url": "https://github.com/caolan/async.git",
387017              "type": "distribution"
387018            },
387019            {
387020              "url": "https://caolan.github.io/async/",
387021              "type": "website"
387022            }
387023          ],
387024          "evidence": {},
387025          "signature": {
387026            "signature": {
387027              "publicKey": {}
387028            }
387029          },
387030          "modelCard": {
387031            "modelParameters": {
387032              "approach": {}
387033            },
387034            "quantitativeAnalysis": {
387035              "graphics": {}
387036            },
387037            "considerations": {}
387038          }
387039        },
387040        {
387041          "type": "library",
387042          "bom-ref": "pkg:npm/asynckit@0.4.0?package-id=ae8f87968d557dba",
387043          "supplier": {},
387044          "author": "Alex Indigo \u003ciam@alexindigo.com\u003e",
387045          "name": "asynckit",
387046          "version": "0.4.0",
387047          "description": "Minimal async jobs utility library, with streams support",
387048          "licenses": [
387049            {
387050              "license": {
387051                "id": "MIT"
387052              }
387053            }
387054          ],
387055          "cpe": "cpe:2.3:a:alexindigo:asynckit:0.4.0:*:*:*:*:*:*:*",
387056          "purl": "pkg:npm/asynckit@0.4.0",
387057          "swid": {
387058            "attachment": {}
387059          },
387060          "pedigree": {},
387061          "externalReferences": [
387062            {
387063              "url": "git+https://github.com/alexindigo/asynckit.git",
387064              "type": "distribution"
387065            },
387066            {
387067              "url": "https://github.com/alexindigo/asynckit#readme",
387068              "type": "website"
387069            }
387070          ],
387071          "evidence": {},
387072          "signature": {
387073            "signature": {
387074              "publicKey": {}
387075            }
387076          },
387077          "modelCard": {
387078            "modelParameters": {
387079              "approach": {}
387080            },
387081            "quantitativeAnalysis": {
387082              "graphics": {}
387083            },
387084            "considerations": {}
387085          }
387086        },
387087        {
387088          "type": "library",
387089          "bom-ref": "pkg:npm/at-least-node@1.0.0?package-id=2f27879d4047fc99",
387090          "supplier": {},
387091          "author": "Ryan Zimmerman \u003copensrc@ryanzim.com\u003e",
387092          "name": "at-least-node",
387093          "version": "1.0.0",
387094          "description": "Lightweight Node.js version sniffing/comparison",
387095          "licenses": [
387096            {
387097              "license": {
387098                "id": "ISC"
387099              }
387100            }
387101          ],
387102          "cpe": "cpe:2.3:a:at-least-node:at-least-node:1.0.0:*:*:*:*:*:*:*",
387103          "purl": "pkg:npm/at-least-node@1.0.0",
387104          "swid": {
387105            "attachment": {}
387106          },
387107          "pedigree": {},
387108          "externalReferences": [
387109            {
387110              "url": "git+https://github.com/RyanZim/at-least-node.git",
387111              "type": "distribution"
387112            },
387113            {
387114              "url": "https://github.com/RyanZim/at-least-node#readme",
387115              "type": "website"
387116            }
387117          ],
387118          "evidence": {},
387119          "signature": {
387120            "signature": {
387121              "publicKey": {}
387122            }
387123          },
387124          "modelCard": {
387125            "modelParameters": {
387126              "approach": {}
387127            },
387128            "quantitativeAnalysis": {
387129              "graphics": {}
387130            },
387131            "considerations": {}
387132          }
387133        },
387134        {
387135          "type": "library",
387136          "bom-ref": "pkg:npm/aws-sign2@0.7.0?package-id=2ea4d2f6e82a7f7d",
387137          "supplier": {},
387138          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
387139          "name": "aws-sign2",
387140          "version": "0.7.0",
387141          "description": "AWS signing. Originally pulled from LearnBoost/knox, maintained as vendor in request, now a standalone module.",
387142          "licenses": [
387143            {
387144              "license": {
387145                "id": "Apache-2.0"
387146              }
387147            }
387148          ],
387149          "cpe": "cpe:2.3:a:aws-sign2:aws-sign2:0.7.0:*:*:*:*:*:*:*",
387150          "purl": "pkg:npm/aws-sign2@0.7.0",
387151          "swid": {
387152            "attachment": {}
387153          },
387154          "pedigree": {},
387155          "externalReferences": [
387156            {
387157              "url": "https://github.com/mikeal/aws-sign",
387158              "type": "distribution"
387159            }
387160          ],
387161          "evidence": {},
387162          "signature": {
387163            "signature": {
387164              "publicKey": {}
387165            }
387166          },
387167          "modelCard": {
387168            "modelParameters": {
387169              "approach": {}
387170            },
387171            "quantitativeAnalysis": {
387172              "graphics": {}
387173            },
387174            "considerations": {}
387175          }
387176        },
387177        {
387178          "type": "library",
387179          "bom-ref": "pkg:npm/aws4@1.12.0?package-id=1ad50775f3f1049",
387180          "supplier": {},
387181          "author": "Michael Hart \u003cmichael.hart.au@gmail.com\u003e (https://github.com/mhart)",
387182          "name": "aws4",
387183          "version": "1.12.0",
387184          "description": "Signs and prepares requests using AWS Signature Version 4",
387185          "licenses": [
387186            {
387187              "license": {
387188                "id": "MIT"
387189              }
387190            }
387191          ],
387192          "cpe": "cpe:2.3:a:aws4:aws4:1.12.0:*:*:*:*:*:*:*",
387193          "purl": "pkg:npm/aws4@1.12.0",
387194          "swid": {
387195            "attachment": {}
387196          },
387197          "pedigree": {},
387198          "externalReferences": [
387199            {
387200              "url": "github:mhart/aws4",
387201              "type": "distribution"
387202            }
387203          ],
387204          "evidence": {},
387205          "signature": {
387206            "signature": {
387207              "publicKey": {}
387208            }
387209          },
387210          "modelCard": {
387211            "modelParameters": {
387212              "approach": {}
387213            },
387214            "quantitativeAnalysis": {
387215              "graphics": {}
387216            },
387217            "considerations": {}
387218          }
387219        },
387220        {
387221          "type": "library",
387222          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=c15b2106d0ae19d4",
387223          "supplier": {},
387224          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
387225          "name": "balanced-match",
387226          "version": "1.0.2",
387227          "description": "Match balanced character pairs, like \"{\" and \"}\"",
387228          "licenses": [
387229            {
387230              "license": {
387231                "id": "MIT"
387232              }
387233            }
387234          ],
387235          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
387236          "purl": "pkg:npm/balanced-match@1.0.2",
387237          "swid": {
387238            "attachment": {}
387239          },
387240          "pedigree": {},
387241          "externalReferences": [
387242            {
387243              "url": "git://github.com/juliangruber/balanced-match.git",
387244              "type": "distribution"
387245            },
387246            {
387247              "url": "https://github.com/juliangruber/balanced-match",
387248              "type": "website"
387249            }
387250          ],
387251          "evidence": {},
387252          "signature": {
387253            "signature": {
387254              "publicKey": {}
387255            }
387256          },
387257          "modelCard": {
387258            "modelParameters": {
387259              "approach": {}
387260            },
387261            "quantitativeAnalysis": {
387262              "graphics": {}
387263            },
387264            "considerations": {}
387265          }
387266        },
387267        {
387268          "type": "library",
387269          "bom-ref": "pkg:npm/balanced-match@1.0.2?package-id=8db1f18b661f67ae",
387270          "supplier": {},
387271          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
387272          "name": "balanced-match",
387273          "version": "1.0.2",
387274          "description": "Match balanced character pairs, like \"{\" and \"}\"",
387275          "licenses": [
387276            {
387277              "license": {
387278                "id": "MIT"
387279              }
387280            }
387281          ],
387282          "cpe": "cpe:2.3:a:balanced-match:balanced-match:1.0.2:*:*:*:*:*:*:*",
387283          "purl": "pkg:npm/balanced-match@1.0.2",
387284          "swid": {
387285            "attachment": {}
387286          },
387287          "pedigree": {},
387288          "externalReferences": [
387289            {
387290              "url": "git://github.com/juliangruber/balanced-match.git",
387291              "type": "distribution"
387292            },
387293            {
387294              "url": "https://github.com/juliangruber/balanced-match",
387295              "type": "website"
387296            }
387297          ],
387298          "evidence": {},
387299          "signature": {
387300            "signature": {
387301              "publicKey": {}
387302            }
387303          },
387304          "modelCard": {
387305            "modelParameters": {
387306              "approach": {}
387307            },
387308            "quantitativeAnalysis": {
387309              "graphics": {}
387310            },
387311            "considerations": {}
387312          }
387313        },
387314        {
387315          "type": "library",
387316          "bom-ref": "pkg:npm/base64-js@1.5.1?package-id=a6fd33cb63a8feb4",
387317          "supplier": {},
387318          "author": "T. Jameson Little \u003ct.jameson.little@gmail.com\u003e",
387319          "name": "base64-js",
387320          "version": "1.5.1",
387321          "description": "Base64 encoding/decoding in pure JS",
387322          "licenses": [
387323            {
387324              "license": {
387325                "id": "MIT"
387326              }
387327            }
387328          ],
387329          "cpe": "cpe:2.3:a:beatgammit:base64-js:1.5.1:*:*:*:*:*:*:*",
387330          "purl": "pkg:npm/base64-js@1.5.1",
387331          "swid": {
387332            "attachment": {}
387333          },
387334          "pedigree": {},
387335          "externalReferences": [
387336            {
387337              "url": "git://github.com/beatgammit/base64-js.git",
387338              "type": "distribution"
387339            },
387340            {
387341              "url": "https://github.com/beatgammit/base64-js",
387342              "type": "website"
387343            }
387344          ],
387345          "evidence": {},
387346          "signature": {
387347            "signature": {
387348              "publicKey": {}
387349            }
387350          },
387351          "modelCard": {
387352            "modelParameters": {
387353              "approach": {}
387354            },
387355            "quantitativeAnalysis": {
387356              "graphics": {}
387357            },
387358            "considerations": {}
387359          }
387360        },
387361        {
387362          "type": "library",
387363          "bom-ref": "pkg:npm/bcrypt-pbkdf@1.0.2?package-id=e522f8051f2c594b",
387364          "supplier": {},
387365          "name": "bcrypt-pbkdf",
387366          "version": "1.0.2",
387367          "description": "Port of the OpenBSD bcrypt_pbkdf function to pure JS",
387368          "licenses": [
387369            {
387370              "license": {
387371                "id": "BSD-3-Clause"
387372              }
387373            }
387374          ],
387375          "cpe": "cpe:2.3:a:bcrypt-pbkdf:bcrypt-pbkdf:1.0.2:*:*:*:*:*:*:*",
387376          "purl": "pkg:npm/bcrypt-pbkdf@1.0.2",
387377          "swid": {
387378            "attachment": {}
387379          },
387380          "pedigree": {},
387381          "externalReferences": [
387382            {
387383              "url": "git://github.com/joyent/node-bcrypt-pbkdf.git",
387384              "type": "distribution"
387385            }
387386          ],
387387          "evidence": {},
387388          "signature": {
387389            "signature": {
387390              "publicKey": {}
387391            }
387392          },
387393          "modelCard": {
387394            "modelParameters": {
387395              "approach": {}
387396            },
387397            "quantitativeAnalysis": {
387398              "graphics": {}
387399            },
387400            "considerations": {}
387401          }
387402        },
387403        {
387404          "type": "library",
387405          "bom-ref": "pkg:npm/bin-links@3.0.3?package-id=605ade84572e7fb",
387406          "supplier": {},
387407          "author": "GitHub Inc.",
387408          "name": "bin-links",
387409          "version": "3.0.3",
387410          "description": "JavaScript package binary linker",
387411          "licenses": [
387412            {
387413              "license": {
387414                "id": "ISC"
387415              }
387416            }
387417          ],
387418          "cpe": "cpe:2.3:a:bin-links:bin-links:3.0.3:*:*:*:*:*:*:*",
387419          "purl": "pkg:npm/bin-links@3.0.3",
387420          "swid": {
387421            "attachment": {}
387422          },
387423          "pedigree": {},
387424          "externalReferences": [
387425            {
387426              "url": "https://github.com/npm/bin-links.git",
387427              "type": "distribution"
387428            }
387429          ],
387430          "evidence": {},
387431          "signature": {
387432            "signature": {
387433              "publicKey": {}
387434            }
387435          },
387436          "modelCard": {
387437            "modelParameters": {
387438              "approach": {}
387439            },
387440            "quantitativeAnalysis": {
387441              "graphics": {}
387442            },
387443            "considerations": {}
387444          }
387445        },
387446        {
387447          "type": "library",
387448          "bom-ref": "pkg:npm/binary-extensions@2.2.0?package-id=2ddda84d3ad7f3e1",
387449          "supplier": {},
387450          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
387451          "name": "binary-extensions",
387452          "version": "2.2.0",
387453          "description": "List of binary file extensions",
387454          "licenses": [
387455            {
387456              "license": {
387457                "id": "MIT"
387458              }
387459            }
387460          ],
387461          "cpe": "cpe:2.3:a:binary-extensions:binary-extensions:2.2.0:*:*:*:*:*:*:*",
387462          "purl": "pkg:npm/binary-extensions@2.2.0",
387463          "swid": {
387464            "attachment": {}
387465          },
387466          "pedigree": {},
387467          "externalReferences": [
387468            {
387469              "url": "sindresorhus/binary-extensions",
387470              "type": "distribution"
387471            }
387472          ],
387473          "evidence": {},
387474          "signature": {
387475            "signature": {
387476              "publicKey": {}
387477            }
387478          },
387479          "modelCard": {
387480            "modelParameters": {
387481              "approach": {}
387482            },
387483            "quantitativeAnalysis": {
387484              "graphics": {}
387485            },
387486            "considerations": {}
387487          }
387488        },
387489        {
387490          "type": "library",
387491          "bom-ref": "pkg:apk/alpine/bind-libs@9.16.39-r0?arch=x86_64\u0026upstream=bind\u0026distro=alpine-3.16.5\u0026package-id=688c130d5197b7c",
387492          "supplier": {},
387493          "name": "bind-libs",
387494          "version": "9.16.39-r0",
387495          "description": "The ISC DNS server (libraries)",
387496          "licenses": [
387497            {
387498              "license": {
387499                "id": "MPL-2.0"
387500              }
387501            }
387502          ],
387503          "cpe": "cpe:2.3:a:bind-libs:bind-libs:9.16.39-r0:*:*:*:*:*:*:*",
387504          "purl": "pkg:apk/alpine/bind-libs@9.16.39-r0?arch=x86_64\u0026upstream=bind\u0026distro=alpine-3.16.5",
387505          "swid": {
387506            "attachment": {}
387507          },
387508          "pedigree": {},
387509          "externalReferences": [
387510            {
387511              "url": "https://www.isc.org/",
387512              "type": "distribution"
387513            }
387514          ],
387515          "evidence": {},
387516          "signature": {
387517            "signature": {
387518              "publicKey": {}
387519            }
387520          },
387521          "modelCard": {
387522            "modelParameters": {
387523              "approach": {}
387524            },
387525            "quantitativeAnalysis": {
387526              "graphics": {}
387527            },
387528            "considerations": {}
387529          }
387530        },
387531        {
387532          "type": "library",
387533          "bom-ref": "pkg:apk/alpine/bind-tools@9.16.39-r0?arch=x86_64\u0026upstream=bind\u0026distro=alpine-3.16.5\u0026package-id=a44de9859c260599",
387534          "supplier": {},
387535          "name": "bind-tools",
387536          "version": "9.16.39-r0",
387537          "description": "The ISC DNS tools",
387538          "licenses": [
387539            {
387540              "license": {
387541                "id": "MPL-2.0"
387542              }
387543            }
387544          ],
387545          "cpe": "cpe:2.3:a:bind-tools:bind-tools:9.16.39-r0:*:*:*:*:*:*:*",
387546          "purl": "pkg:apk/alpine/bind-tools@9.16.39-r0?arch=x86_64\u0026upstream=bind\u0026distro=alpine-3.16.5",
387547          "swid": {
387548            "attachment": {}
387549          },
387550          "pedigree": {},
387551          "externalReferences": [
387552            {
387553              "url": "https://www.isc.org/",
387554              "type": "distribution"
387555            }
387556          ],
387557          "evidence": {},
387558          "signature": {
387559            "signature": {
387560              "publicKey": {}
387561            }
387562          },
387563          "modelCard": {
387564            "modelParameters": {
387565              "approach": {}
387566            },
387567            "quantitativeAnalysis": {
387568              "graphics": {}
387569            },
387570            "considerations": {}
387571          }
387572        },
387573        {
387574          "type": "library",
387575          "bom-ref": "pkg:npm/bl@1.2.3?package-id=857d6ce6ddf3b8d9",
387576          "supplier": {},
387577          "name": "bl",
387578          "version": "1.2.3",
387579          "description": "Buffer List: collect buffers and access with a standard readable Buffer interface, streamable too!",
387580          "licenses": [
387581            {
387582              "license": {
387583                "id": "MIT"
387584              }
387585            }
387586          ],
387587          "cpe": "cpe:2.3:a:rvagg:bl:1.2.3:*:*:*:*:*:*:*",
387588          "purl": "pkg:npm/bl@1.2.3",
387589          "swid": {
387590            "attachment": {}
387591          },
387592          "pedigree": {},
387593          "externalReferences": [
387594            {
387595              "url": "https://github.com/rvagg/bl.git",
387596              "type": "distribution"
387597            },
387598            {
387599              "url": "https://github.com/rvagg/bl",
387600              "type": "website"
387601            }
387602          ],
387603          "evidence": {},
387604          "signature": {
387605            "signature": {
387606              "publicKey": {}
387607            }
387608          },
387609          "modelCard": {
387610            "modelParameters": {
387611              "approach": {}
387612            },
387613            "quantitativeAnalysis": {
387614              "graphics": {}
387615            },
387616            "considerations": {}
387617          }
387618        },
387619        {
387620          "type": "library",
387621          "bom-ref": "pkg:npm/block-stream2@2.1.0?package-id=d2c19c703777584a",
387622          "supplier": {},
387623          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
387624          "name": "block-stream2",
387625          "version": "2.1.0",
387626          "description": "transform input into equally-sized blocks of output",
387627          "licenses": [
387628            {
387629              "license": {
387630                "id": "MIT"
387631              }
387632            }
387633          ],
387634          "cpe": "cpe:2.3:a:block-stream2:block-stream2:2.1.0:*:*:*:*:*:*:*",
387635          "purl": "pkg:npm/block-stream2@2.1.0",
387636          "swid": {
387637            "attachment": {}
387638          },
387639          "pedigree": {},
387640          "externalReferences": [
387641            {
387642              "url": "git://github.com/substack/block-stream2.git",
387643              "type": "distribution"
387644            },
387645            {
387646              "url": "https://github.com/substack/block-stream2",
387647              "type": "website"
387648            }
387649          ],
387650          "evidence": {},
387651          "signature": {
387652            "signature": {
387653              "publicKey": {}
387654            }
387655          },
387656          "modelCard": {
387657            "modelParameters": {
387658              "approach": {}
387659            },
387660            "quantitativeAnalysis": {
387661              "graphics": {}
387662            },
387663            "considerations": {}
387664          }
387665        },
387666        {
387667          "type": "library",
387668          "bom-ref": "pkg:npm/body-parser@1.18.3?package-id=b284a1ea89619936",
387669          "supplier": {},
387670          "name": "body-parser",
387671          "version": "1.18.3",
387672          "description": "Node.js body parsing middleware",
387673          "licenses": [
387674            {
387675              "license": {
387676                "id": "MIT"
387677              }
387678            }
387679          ],
387680          "cpe": "cpe:2.3:a:body-parser:body-parser:1.18.3:*:*:*:*:*:*:*",
387681          "purl": "pkg:npm/body-parser@1.18.3",
387682          "swid": {
387683            "attachment": {}
387684          },
387685          "pedigree": {},
387686          "externalReferences": [
387687            {
387688              "url": "expressjs/body-parser",
387689              "type": "distribution"
387690            }
387691          ],
387692          "evidence": {},
387693          "signature": {
387694            "signature": {
387695              "publicKey": {}
387696            }
387697          },
387698          "modelCard": {
387699            "modelParameters": {
387700              "approach": {}
387701            },
387702            "quantitativeAnalysis": {
387703              "graphics": {}
387704            },
387705            "considerations": {}
387706          }
387707        },
387708        {
387709          "type": "library",
387710          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=a36ca63616a6d457",
387711          "supplier": {},
387712          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
387713          "name": "brace-expansion",
387714          "version": "1.1.11",
387715          "description": "Brace expansion as known from sh/bash",
387716          "licenses": [
387717            {
387718              "license": {
387719                "id": "MIT"
387720              }
387721            }
387722          ],
387723          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
387724          "purl": "pkg:npm/brace-expansion@1.1.11",
387725          "swid": {
387726            "attachment": {}
387727          },
387728          "pedigree": {},
387729          "externalReferences": [
387730            {
387731              "url": "git://github.com/juliangruber/brace-expansion.git",
387732              "type": "distribution"
387733            },
387734            {
387735              "url": "https://github.com/juliangruber/brace-expansion",
387736              "type": "website"
387737            }
387738          ],
387739          "evidence": {},
387740          "signature": {
387741            "signature": {
387742              "publicKey": {}
387743            }
387744          },
387745          "modelCard": {
387746            "modelParameters": {
387747              "approach": {}
387748            },
387749            "quantitativeAnalysis": {
387750              "graphics": {}
387751            },
387752            "considerations": {}
387753          }
387754        },
387755        {
387756          "type": "library",
387757          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=8aefa0d5bf7ea5ce",
387758          "supplier": {},
387759          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
387760          "name": "brace-expansion",
387761          "version": "1.1.11",
387762          "description": "Brace expansion as known from sh/bash",
387763          "licenses": [
387764            {
387765              "license": {
387766                "id": "MIT"
387767              }
387768            }
387769          ],
387770          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
387771          "purl": "pkg:npm/brace-expansion@1.1.11",
387772          "swid": {
387773            "attachment": {}
387774          },
387775          "pedigree": {},
387776          "externalReferences": [
387777            {
387778              "url": "git://github.com/juliangruber/brace-expansion.git",
387779              "type": "distribution"
387780            },
387781            {
387782              "url": "https://github.com/juliangruber/brace-expansion",
387783              "type": "website"
387784            }
387785          ],
387786          "evidence": {},
387787          "signature": {
387788            "signature": {
387789              "publicKey": {}
387790            }
387791          },
387792          "modelCard": {
387793            "modelParameters": {
387794              "approach": {}
387795            },
387796            "quantitativeAnalysis": {
387797              "graphics": {}
387798            },
387799            "considerations": {}
387800          }
387801        },
387802        {
387803          "type": "library",
387804          "bom-ref": "pkg:npm/brace-expansion@1.1.11?package-id=1bc35b4fad6ec801",
387805          "supplier": {},
387806          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
387807          "name": "brace-expansion",
387808          "version": "1.1.11",
387809          "description": "Brace expansion as known from sh/bash",
387810          "licenses": [
387811            {
387812              "license": {
387813                "id": "MIT"
387814              }
387815            }
387816          ],
387817          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:1.1.11:*:*:*:*:*:*:*",
387818          "purl": "pkg:npm/brace-expansion@1.1.11",
387819          "swid": {
387820            "attachment": {}
387821          },
387822          "pedigree": {},
387823          "externalReferences": [
387824            {
387825              "url": "git://github.com/juliangruber/brace-expansion.git",
387826              "type": "distribution"
387827            },
387828            {
387829              "url": "https://github.com/juliangruber/brace-expansion",
387830              "type": "website"
387831            }
387832          ],
387833          "evidence": {},
387834          "signature": {
387835            "signature": {
387836              "publicKey": {}
387837            }
387838          },
387839          "modelCard": {
387840            "modelParameters": {
387841              "approach": {}
387842            },
387843            "quantitativeAnalysis": {
387844              "graphics": {}
387845            },
387846            "considerations": {}
387847          }
387848        },
387849        {
387850          "type": "library",
387851          "bom-ref": "pkg:npm/brace-expansion@2.0.1?package-id=70d44e2ab0a06da3",
387852          "supplier": {},
387853          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
387854          "name": "brace-expansion",
387855          "version": "2.0.1",
387856          "description": "Brace expansion as known from sh/bash",
387857          "licenses": [
387858            {
387859              "license": {
387860                "id": "MIT"
387861              }
387862            }
387863          ],
387864          "cpe": "cpe:2.3:a:brace-expansion:brace-expansion:2.0.1:*:*:*:*:*:*:*",
387865          "purl": "pkg:npm/brace-expansion@2.0.1",
387866          "swid": {
387867            "attachment": {}
387868          },
387869          "pedigree": {},
387870          "externalReferences": [
387871            {
387872              "url": "git://github.com/juliangruber/brace-expansion.git",
387873              "type": "distribution"
387874            },
387875            {
387876              "url": "https://github.com/juliangruber/brace-expansion",
387877              "type": "website"
387878            }
387879          ],
387880          "evidence": {},
387881          "signature": {
387882            "signature": {
387883              "publicKey": {}
387884            }
387885          },
387886          "modelCard": {
387887            "modelParameters": {
387888              "approach": {}
387889            },
387890            "quantitativeAnalysis": {
387891              "graphics": {}
387892            },
387893            "considerations": {}
387894          }
387895        },
387896        {
387897          "type": "library",
387898          "bom-ref": "pkg:npm/braces@3.0.2?package-id=d349ee6699b9dd12",
387899          "supplier": {},
387900          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
387901          "name": "braces",
387902          "version": "3.0.2",
387903          "description": "Bash-like brace expansion, implemented in JavaScript. Safer than other brace expansion libs, with complete support for the Bash 4.3 braces specification, without sacrificing speed.",
387904          "licenses": [
387905            {
387906              "license": {
387907                "id": "MIT"
387908              }
387909            }
387910          ],
387911          "cpe": "cpe:2.3:a:micromatch:braces:3.0.2:*:*:*:*:*:*:*",
387912          "purl": "pkg:npm/braces@3.0.2",
387913          "swid": {
387914            "attachment": {}
387915          },
387916          "pedigree": {},
387917          "externalReferences": [
387918            {
387919              "url": "micromatch/braces",
387920              "type": "distribution"
387921            },
387922            {
387923              "url": "https://github.com/micromatch/braces",
387924              "type": "website"
387925            }
387926          ],
387927          "evidence": {},
387928          "signature": {
387929            "signature": {
387930              "publicKey": {}
387931            }
387932          },
387933          "modelCard": {
387934            "modelParameters": {
387935              "approach": {}
387936            },
387937            "quantitativeAnalysis": {
387938              "graphics": {}
387939            },
387940            "considerations": {}
387941          }
387942        },
387943        {
387944          "type": "library",
387945          "bom-ref": "pkg:apk/alpine/brotli-libs@1.0.9-r6?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.16.5\u0026package-id=ce770907e6d64ccd",
387946          "supplier": {},
387947          "publisher": "prspkt \u003cprspkt@protonmail.com\u003e",
387948          "name": "brotli-libs",
387949          "version": "1.0.9-r6",
387950          "description": "Generic lossless compressor (libraries)",
387951          "licenses": [
387952            {
387953              "license": {
387954                "id": "MIT"
387955              }
387956            }
387957          ],
387958          "cpe": "cpe:2.3:a:brotli-libs:brotli-libs:1.0.9-r6:*:*:*:*:*:*:*",
387959          "purl": "pkg:apk/alpine/brotli-libs@1.0.9-r6?arch=x86_64\u0026upstream=brotli\u0026distro=alpine-3.16.5",
387960          "swid": {
387961            "attachment": {}
387962          },
387963          "pedigree": {},
387964          "externalReferences": [
387965            {
387966              "url": "https://github.com/google/brotli",
387967              "type": "distribution"
387968            }
387969          ],
387970          "evidence": {},
387971          "signature": {
387972            "signature": {
387973              "publicKey": {}
387974            }
387975          },
387976          "modelCard": {
387977            "modelParameters": {
387978              "approach": {}
387979            },
387980            "quantitativeAnalysis": {
387981              "graphics": {}
387982            },
387983            "considerations": {}
387984          }
387985        },
387986        {
387987          "type": "library",
387988          "bom-ref": "pkg:npm/buffer@5.7.1?package-id=4e619be32ebf5739",
387989          "supplier": {},
387990          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
387991          "name": "buffer",
387992          "version": "5.7.1",
387993          "description": "Node.js Buffer API, for the browser",
387994          "licenses": [
387995            {
387996              "license": {
387997                "id": "MIT"
387998              }
387999            }
388000          ],
388001          "cpe": "cpe:2.3:a:buffer:buffer:5.7.1:*:*:*:*:*:*:*",
388002          "purl": "pkg:npm/buffer@5.7.1",
388003          "swid": {
388004            "attachment": {}
388005          },
388006          "pedigree": {},
388007          "externalReferences": [
388008            {
388009              "url": "git://github.com/feross/buffer.git",
388010              "type": "distribution"
388011            },
388012            {
388013              "url": "https://github.com/feross/buffer",
388014              "type": "website"
388015            }
388016          ],
388017          "evidence": {},
388018          "signature": {
388019            "signature": {
388020              "publicKey": {}
388021            }
388022          },
388023          "modelCard": {
388024            "modelParameters": {
388025              "approach": {}
388026            },
388027            "quantitativeAnalysis": {
388028              "graphics": {}
388029            },
388030            "considerations": {}
388031          }
388032        },
388033        {
388034          "type": "library",
388035          "bom-ref": "pkg:npm/buffer-alloc@1.2.0?package-id=f784a2837fbe8bed",
388036          "supplier": {},
388037          "name": "buffer-alloc",
388038          "version": "1.2.0",
388039          "licenses": [
388040            {
388041              "license": {
388042                "id": "MIT"
388043              }
388044            }
388045          ],
388046          "cpe": "cpe:2.3:a:buffer-alloc:buffer-alloc:1.2.0:*:*:*:*:*:*:*",
388047          "purl": "pkg:npm/buffer-alloc@1.2.0",
388048          "swid": {
388049            "attachment": {}
388050          },
388051          "pedigree": {},
388052          "externalReferences": [
388053            {
388054              "url": "LinusU/buffer-alloc",
388055              "type": "distribution"
388056            }
388057          ],
388058          "evidence": {},
388059          "signature": {
388060            "signature": {
388061              "publicKey": {}
388062            }
388063          },
388064          "modelCard": {
388065            "modelParameters": {
388066              "approach": {}
388067            },
388068            "quantitativeAnalysis": {
388069              "graphics": {}
388070            },
388071            "considerations": {}
388072          }
388073        },
388074        {
388075          "type": "library",
388076          "bom-ref": "pkg:npm/buffer-alloc-unsafe@1.1.0?package-id=f256488d7c6ca447",
388077          "supplier": {},
388078          "name": "buffer-alloc-unsafe",
388079          "version": "1.1.0",
388080          "licenses": [
388081            {
388082              "license": {
388083                "id": "MIT"
388084              }
388085            }
388086          ],
388087          "cpe": "cpe:2.3:a:buffer-alloc-unsafe:buffer-alloc-unsafe:1.1.0:*:*:*:*:*:*:*",
388088          "purl": "pkg:npm/buffer-alloc-unsafe@1.1.0",
388089          "swid": {
388090            "attachment": {}
388091          },
388092          "pedigree": {},
388093          "externalReferences": [
388094            {
388095              "url": "LinusU/buffer-alloc-unsafe",
388096              "type": "distribution"
388097            }
388098          ],
388099          "evidence": {},
388100          "signature": {
388101            "signature": {
388102              "publicKey": {}
388103            }
388104          },
388105          "modelCard": {
388106            "modelParameters": {
388107              "approach": {}
388108            },
388109            "quantitativeAnalysis": {
388110              "graphics": {}
388111            },
388112            "considerations": {}
388113          }
388114        },
388115        {
388116          "type": "library",
388117          "bom-ref": "pkg:npm/buffer-crc32@0.2.13?package-id=4fd48942dbfa2289",
388118          "supplier": {},
388119          "author": "Brian J. Brennan \u003cbrianloveswords@gmail.com\u003e",
388120          "name": "buffer-crc32",
388121          "version": "0.2.13",
388122          "description": "A pure javascript CRC32 algorithm that plays nice with binary data",
388123          "licenses": [
388124            {
388125              "license": {
388126                "id": "MIT"
388127              }
388128            }
388129          ],
388130          "cpe": "cpe:2.3:a:brianloveswords:buffer-crc32:0.2.13:*:*:*:*:*:*:*",
388131          "purl": "pkg:npm/buffer-crc32@0.2.13",
388132          "swid": {
388133            "attachment": {}
388134          },
388135          "pedigree": {},
388136          "externalReferences": [
388137            {
388138              "url": "git://github.com/brianloveswords/buffer-crc32.git",
388139              "type": "distribution"
388140            },
388141            {
388142              "url": "https://github.com/brianloveswords/buffer-crc32",
388143              "type": "website"
388144            }
388145          ],
388146          "evidence": {},
388147          "signature": {
388148            "signature": {
388149              "publicKey": {}
388150            }
388151          },
388152          "modelCard": {
388153            "modelParameters": {
388154              "approach": {}
388155            },
388156            "quantitativeAnalysis": {
388157              "graphics": {}
388158            },
388159            "considerations": {}
388160          }
388161        },
388162        {
388163          "type": "library",
388164          "bom-ref": "pkg:npm/buffer-fill@1.0.0?package-id=bbb2ac54f8bae4ff",
388165          "supplier": {},
388166          "name": "buffer-fill",
388167          "version": "1.0.0",
388168          "licenses": [
388169            {
388170              "license": {
388171                "id": "MIT"
388172              }
388173            }
388174          ],
388175          "cpe": "cpe:2.3:a:buffer-fill:buffer-fill:1.0.0:*:*:*:*:*:*:*",
388176          "purl": "pkg:npm/buffer-fill@1.0.0",
388177          "swid": {
388178            "attachment": {}
388179          },
388180          "pedigree": {},
388181          "externalReferences": [
388182            {
388183              "url": "LinusU/buffer-fill",
388184              "type": "distribution"
388185            }
388186          ],
388187          "evidence": {},
388188          "signature": {
388189            "signature": {
388190              "publicKey": {}
388191            }
388192          },
388193          "modelCard": {
388194            "modelParameters": {
388195              "approach": {}
388196            },
388197            "quantitativeAnalysis": {
388198              "graphics": {}
388199            },
388200            "considerations": {}
388201          }
388202        },
388203        {
388204          "type": "library",
388205          "bom-ref": "pkg:npm/builtins@5.0.1?package-id=af6ac207a0c6926d",
388206          "supplier": {},
388207          "name": "builtins",
388208          "version": "5.0.1",
388209          "description": "List of node.js builtin modules",
388210          "licenses": [
388211            {
388212              "license": {
388213                "id": "MIT"
388214              }
388215            }
388216          ],
388217          "cpe": "cpe:2.3:a:builtins:builtins:5.0.1:*:*:*:*:*:*:*",
388218          "purl": "pkg:npm/builtins@5.0.1",
388219          "swid": {
388220            "attachment": {}
388221          },
388222          "pedigree": {},
388223          "externalReferences": [
388224            {
388225              "url": "juliangruber/builtins",
388226              "type": "distribution"
388227            }
388228          ],
388229          "evidence": {},
388230          "signature": {
388231            "signature": {
388232              "publicKey": {}
388233            }
388234          },
388235          "modelCard": {
388236            "modelParameters": {
388237              "approach": {}
388238            },
388239            "quantitativeAnalysis": {
388240              "graphics": {}
388241            },
388242            "considerations": {}
388243          }
388244        },
388245        {
388246          "type": "application",
388247          "bom-ref": "e14718c64f5147f4",
388248          "supplier": {},
388249          "name": "busybox",
388250          "version": "1.35.0",
388251          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
388252          "swid": {
388253            "attachment": {}
388254          },
388255          "pedigree": {},
388256          "evidence": {},
388257          "signature": {
388258            "signature": {
388259              "publicKey": {}
388260            }
388261          },
388262          "modelCard": {
388263            "modelParameters": {
388264              "approach": {}
388265            },
388266            "quantitativeAnalysis": {
388267              "graphics": {}
388268            },
388269            "considerations": {}
388270          }
388271        },
388272        {
388273          "type": "library",
388274          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=4b48ef6f6b983526",
388275          "supplier": {},
388276          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
388277          "name": "busybox",
388278          "version": "1.35.0-r17",
388279          "description": "Size optimized toolbox of many common UNIX utilities",
388280          "licenses": [
388281            {
388282              "license": {
388283                "id": "GPL-2.0-only"
388284              }
388285            }
388286          ],
388287          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r17:*:*:*:*:*:*:*",
388288          "purl": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5",
388289          "swid": {
388290            "attachment": {}
388291          },
388292          "pedigree": {},
388293          "externalReferences": [
388294            {
388295              "url": "https://busybox.net/",
388296              "type": "distribution"
388297            }
388298          ],
388299          "evidence": {},
388300          "signature": {
388301            "signature": {
388302              "publicKey": {}
388303            }
388304          },
388305          "modelCard": {
388306            "modelParameters": {
388307              "approach": {}
388308            },
388309            "quantitativeAnalysis": {
388310              "graphics": {}
388311            },
388312            "considerations": {}
388313          }
388314        },
388315        {
388316          "type": "library",
388317          "bom-ref": "pkg:npm/bytes@3.0.0?package-id=576903a3803d92be",
388318          "supplier": {},
388319          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
388320          "name": "bytes",
388321          "version": "3.0.0",
388322          "description": "Utility to parse a string bytes to bytes and vice-versa",
388323          "licenses": [
388324            {
388325              "license": {
388326                "id": "MIT"
388327              }
388328            }
388329          ],
388330          "cpe": "cpe:2.3:a:bytes:bytes:3.0.0:*:*:*:*:*:*:*",
388331          "purl": "pkg:npm/bytes@3.0.0",
388332          "swid": {
388333            "attachment": {}
388334          },
388335          "pedigree": {},
388336          "externalReferences": [
388337            {
388338              "url": "visionmedia/bytes.js",
388339              "type": "distribution"
388340            }
388341          ],
388342          "evidence": {},
388343          "signature": {
388344            "signature": {
388345              "publicKey": {}
388346            }
388347          },
388348          "modelCard": {
388349            "modelParameters": {
388350              "approach": {}
388351            },
388352            "quantitativeAnalysis": {
388353              "graphics": {}
388354            },
388355            "considerations": {}
388356          }
388357        },
388358        {
388359          "type": "library",
388360          "bom-ref": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=fbb1924ff870cc71",
388361          "supplier": {},
388362          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
388363          "name": "ca-certificates",
388364          "version": "20220614-r0",
388365          "description": "Common CA certificates PEM files from Mozilla",
388366          "licenses": [
388367            {
388368              "license": {
388369                "id": "MPL-2.0"
388370              }
388371            },
388372            {
388373              "license": {
388374                "name": "AND"
388375              }
388376            },
388377            {
388378              "license": {
388379                "id": "MIT"
388380              }
388381            }
388382          ],
388383          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20220614-r0:*:*:*:*:*:*:*",
388384          "purl": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5",
388385          "swid": {
388386            "attachment": {}
388387          },
388388          "pedigree": {},
388389          "externalReferences": [
388390            {
388391              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
388392              "type": "distribution"
388393            }
388394          ],
388395          "evidence": {},
388396          "signature": {
388397            "signature": {
388398              "publicKey": {}
388399            }
388400          },
388401          "modelCard": {
388402            "modelParameters": {
388403              "approach": {}
388404            },
388405            "quantitativeAnalysis": {
388406              "graphics": {}
388407            },
388408            "considerations": {}
388409          }
388410        },
388411        {
388412          "type": "library",
388413          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5\u0026package-id=30622a1848b22bca",
388414          "supplier": {},
388415          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
388416          "name": "ca-certificates-bundle",
388417          "version": "20220614-r0",
388418          "description": "Pre generated bundle of Mozilla certificates",
388419          "licenses": [
388420            {
388421              "license": {
388422                "id": "MPL-2.0"
388423              }
388424            },
388425            {
388426              "license": {
388427                "name": "AND"
388428              }
388429            },
388430            {
388431              "license": {
388432                "id": "MIT"
388433              }
388434            }
388435          ],
388436          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
388437          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5",
388438          "swid": {
388439            "attachment": {}
388440          },
388441          "pedigree": {},
388442          "externalReferences": [
388443            {
388444              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
388445              "type": "distribution"
388446            }
388447          ],
388448          "evidence": {},
388449          "signature": {
388450            "signature": {
388451              "publicKey": {}
388452            }
388453          },
388454          "modelCard": {
388455            "modelParameters": {
388456              "approach": {}
388457            },
388458            "quantitativeAnalysis": {
388459              "graphics": {}
388460            },
388461            "considerations": {}
388462          }
388463        },
388464        {
388465          "type": "library",
388466          "bom-ref": "pkg:npm/cacache@16.1.3?package-id=4e055fb1e595c11",
388467          "supplier": {},
388468          "author": "GitHub Inc.",
388469          "name": "cacache",
388470          "version": "16.1.3",
388471          "description": "Fast, fault-tolerant, cross-platform, disk-based, data-agnostic, content-addressable cache.",
388472          "licenses": [
388473            {
388474              "license": {
388475                "id": "ISC"
388476              }
388477            }
388478          ],
388479          "cpe": "cpe:2.3:a:cacache:cacache:16.1.3:*:*:*:*:*:*:*",
388480          "purl": "pkg:npm/cacache@16.1.3",
388481          "swid": {
388482            "attachment": {}
388483          },
388484          "pedigree": {},
388485          "externalReferences": [
388486            {
388487              "url": "https://github.com/npm/cacache.git",
388488              "type": "distribution"
388489            }
388490          ],
388491          "evidence": {},
388492          "signature": {
388493            "signature": {
388494              "publicKey": {}
388495            }
388496          },
388497          "modelCard": {
388498            "modelParameters": {
388499              "approach": {}
388500            },
388501            "quantitativeAnalysis": {
388502              "graphics": {}
388503            },
388504            "considerations": {}
388505          }
388506        },
388507        {
388508          "type": "library",
388509          "bom-ref": "pkg:npm/cacheable-lookup@5.0.4?package-id=eba12e65c41afc1e",
388510          "supplier": {},
388511          "author": "Szymon Marczak",
388512          "name": "cacheable-lookup",
388513          "version": "5.0.4",
388514          "description": "A cacheable dns.lookup(…) that respects the TTL",
388515          "licenses": [
388516            {
388517              "license": {
388518                "id": "MIT"
388519              }
388520            }
388521          ],
388522          "cpe": "cpe:2.3:a:cacheable-lookup:cacheable-lookup:5.0.4:*:*:*:*:*:*:*",
388523          "purl": "pkg:npm/cacheable-lookup@5.0.4",
388524          "swid": {
388525            "attachment": {}
388526          },
388527          "pedigree": {},
388528          "externalReferences": [
388529            {
388530              "url": "git+https://github.com/szmarczak/cacheable-lookup.git",
388531              "type": "distribution"
388532            },
388533            {
388534              "url": "https://github.com/szmarczak/cacheable-lookup#readme",
388535              "type": "website"
388536            }
388537          ],
388538          "evidence": {},
388539          "signature": {
388540            "signature": {
388541              "publicKey": {}
388542            }
388543          },
388544          "modelCard": {
388545            "modelParameters": {
388546              "approach": {}
388547            },
388548            "quantitativeAnalysis": {
388549              "graphics": {}
388550            },
388551            "considerations": {}
388552          }
388553        },
388554        {
388555          "type": "library",
388556          "bom-ref": "pkg:npm/cacheable-request@2.1.4?package-id=4118e90491b13653",
388557          "supplier": {},
388558          "author": "Luke Childs \u003clukechilds123@gmail.com\u003e (http://lukechilds.co.uk)",
388559          "name": "cacheable-request",
388560          "version": "2.1.4",
388561          "description": "Wrap native HTTP requests with RFC compliant cache support",
388562          "licenses": [
388563            {
388564              "license": {
388565                "id": "MIT"
388566              }
388567            }
388568          ],
388569          "cpe": "cpe:2.3:a:cacheable-request:cacheable-request:2.1.4:*:*:*:*:*:*:*",
388570          "purl": "pkg:npm/cacheable-request@2.1.4",
388571          "swid": {
388572            "attachment": {}
388573          },
388574          "pedigree": {},
388575          "externalReferences": [
388576            {
388577              "url": "git+https://github.com/lukechilds/cacheable-request.git",
388578              "type": "distribution"
388579            },
388580            {
388581              "url": "https://github.com/lukechilds/cacheable-request",
388582              "type": "website"
388583            }
388584          ],
388585          "evidence": {},
388586          "signature": {
388587            "signature": {
388588              "publicKey": {}
388589            }
388590          },
388591          "modelCard": {
388592            "modelParameters": {
388593              "approach": {}
388594            },
388595            "quantitativeAnalysis": {
388596              "graphics": {}
388597            },
388598            "considerations": {}
388599          }
388600        },
388601        {
388602          "type": "library",
388603          "bom-ref": "pkg:npm/cacheable-request@7.0.2?package-id=1c2a8d288ff38c4a",
388604          "supplier": {},
388605          "author": "Luke Childs \u003clukechilds123@gmail.com\u003e (http://lukechilds.co.uk)",
388606          "name": "cacheable-request",
388607          "version": "7.0.2",
388608          "description": "Wrap native HTTP requests with RFC compliant cache support",
388609          "licenses": [
388610            {
388611              "license": {
388612                "id": "MIT"
388613              }
388614            }
388615          ],
388616          "cpe": "cpe:2.3:a:cacheable-request:cacheable-request:7.0.2:*:*:*:*:*:*:*",
388617          "purl": "pkg:npm/cacheable-request@7.0.2",
388618          "swid": {
388619            "attachment": {}
388620          },
388621          "pedigree": {},
388622          "externalReferences": [
388623            {
388624              "url": "lukechilds/cacheable-request",
388625              "type": "distribution"
388626            }
388627          ],
388628          "evidence": {},
388629          "signature": {
388630            "signature": {
388631              "publicKey": {}
388632            }
388633          },
388634          "modelCard": {
388635            "modelParameters": {
388636              "approach": {}
388637            },
388638            "quantitativeAnalysis": {
388639              "graphics": {}
388640            },
388641            "considerations": {}
388642          }
388643        },
388644        {
388645          "type": "library",
388646          "bom-ref": "pkg:npm/caseless@0.12.0?package-id=227a1a61cfc117ad",
388647          "supplier": {},
388648          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
388649          "name": "caseless",
388650          "version": "0.12.0",
388651          "description": "Caseless object set/get/has, very useful when working with HTTP headers.",
388652          "licenses": [
388653            {
388654              "license": {
388655                "id": "Apache-2.0"
388656              }
388657            }
388658          ],
388659          "cpe": "cpe:2.3:a:caseless:caseless:0.12.0:*:*:*:*:*:*:*",
388660          "purl": "pkg:npm/caseless@0.12.0",
388661          "swid": {
388662            "attachment": {}
388663          },
388664          "pedigree": {},
388665          "externalReferences": [
388666            {
388667              "url": "https://github.com/mikeal/caseless",
388668              "type": "distribution"
388669            }
388670          ],
388671          "evidence": {},
388672          "signature": {
388673            "signature": {
388674              "publicKey": {}
388675            }
388676          },
388677          "modelCard": {
388678            "modelParameters": {
388679              "approach": {}
388680            },
388681            "quantitativeAnalysis": {
388682              "graphics": {}
388683            },
388684            "considerations": {}
388685          }
388686        },
388687        {
388688          "type": "library",
388689          "bom-ref": "pkg:npm/caw@2.0.1?package-id=96983ea480bc177d",
388690          "supplier": {},
388691          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
388692          "name": "caw",
388693          "version": "2.0.1",
388694          "description": "Construct HTTP/HTTPS agents for tunneling proxies",
388695          "licenses": [
388696            {
388697              "license": {
388698                "id": "MIT"
388699              }
388700            }
388701          ],
388702          "cpe": "cpe:2.3:a:caw:caw:2.0.1:*:*:*:*:*:*:*",
388703          "purl": "pkg:npm/caw@2.0.1",
388704          "swid": {
388705            "attachment": {}
388706          },
388707          "pedigree": {},
388708          "externalReferences": [
388709            {
388710              "url": "kevva/caw",
388711              "type": "distribution"
388712            }
388713          ],
388714          "evidence": {},
388715          "signature": {
388716            "signature": {
388717              "publicKey": {}
388718            }
388719          },
388720          "modelCard": {
388721            "modelParameters": {
388722              "approach": {}
388723            },
388724            "quantitativeAnalysis": {
388725              "graphics": {}
388726            },
388727            "considerations": {}
388728          }
388729        },
388730        {
388731          "type": "library",
388732          "bom-ref": "pkg:npm/chalk@2.4.2?package-id=48a4e5e37f4ef1f2",
388733          "supplier": {},
388734          "name": "chalk",
388735          "version": "2.4.2",
388736          "description": "Terminal string styling done right",
388737          "licenses": [
388738            {
388739              "license": {
388740                "id": "MIT"
388741              }
388742            }
388743          ],
388744          "cpe": "cpe:2.3:a:chalk:chalk:2.4.2:*:*:*:*:*:*:*",
388745          "purl": "pkg:npm/chalk@2.4.2",
388746          "swid": {
388747            "attachment": {}
388748          },
388749          "pedigree": {},
388750          "externalReferences": [
388751            {
388752              "url": "chalk/chalk",
388753              "type": "distribution"
388754            }
388755          ],
388756          "evidence": {},
388757          "signature": {
388758            "signature": {
388759              "publicKey": {}
388760            }
388761          },
388762          "modelCard": {
388763            "modelParameters": {
388764              "approach": {}
388765            },
388766            "quantitativeAnalysis": {
388767              "graphics": {}
388768            },
388769            "considerations": {}
388770          }
388771        },
388772        {
388773          "type": "library",
388774          "bom-ref": "pkg:npm/chalk@4.1.2?package-id=b12178723b56594f",
388775          "supplier": {},
388776          "name": "chalk",
388777          "version": "4.1.2",
388778          "description": "Terminal string styling done right",
388779          "licenses": [
388780            {
388781              "license": {
388782                "id": "MIT"
388783              }
388784            }
388785          ],
388786          "cpe": "cpe:2.3:a:chalk:chalk:4.1.2:*:*:*:*:*:*:*",
388787          "purl": "pkg:npm/chalk@4.1.2",
388788          "swid": {
388789            "attachment": {}
388790          },
388791          "pedigree": {},
388792          "externalReferences": [
388793            {
388794              "url": "chalk/chalk",
388795              "type": "distribution"
388796            }
388797          ],
388798          "evidence": {},
388799          "signature": {
388800            "signature": {
388801              "publicKey": {}
388802            }
388803          },
388804          "modelCard": {
388805            "modelParameters": {
388806              "approach": {}
388807            },
388808            "quantitativeAnalysis": {
388809              "graphics": {}
388810            },
388811            "considerations": {}
388812          }
388813        },
388814        {
388815          "type": "library",
388816          "bom-ref": "pkg:npm/chalk@4.1.2?package-id=e4005f9838c6d4b0",
388817          "supplier": {},
388818          "name": "chalk",
388819          "version": "4.1.2",
388820          "description": "Terminal string styling done right",
388821          "licenses": [
388822            {
388823              "license": {
388824                "id": "MIT"
388825              }
388826            }
388827          ],
388828          "cpe": "cpe:2.3:a:chalk:chalk:4.1.2:*:*:*:*:*:*:*",
388829          "purl": "pkg:npm/chalk@4.1.2",
388830          "swid": {
388831            "attachment": {}
388832          },
388833          "pedigree": {},
388834          "externalReferences": [
388835            {
388836              "url": "chalk/chalk",
388837              "type": "distribution"
388838            }
388839          ],
388840          "evidence": {},
388841          "signature": {
388842            "signature": {
388843              "publicKey": {}
388844            }
388845          },
388846          "modelCard": {
388847            "modelParameters": {
388848              "approach": {}
388849            },
388850            "quantitativeAnalysis": {
388851              "graphics": {}
388852            },
388853            "considerations": {}
388854          }
388855        },
388856        {
388857          "type": "library",
388858          "bom-ref": "pkg:npm/chownr@1.1.4?package-id=332c2f28052efe07",
388859          "supplier": {},
388860          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
388861          "name": "chownr",
388862          "version": "1.1.4",
388863          "description": "like `chown -R`",
388864          "licenses": [
388865            {
388866              "license": {
388867                "id": "ISC"
388868              }
388869            }
388870          ],
388871          "cpe": "cpe:2.3:a:chownr:chownr:1.1.4:*:*:*:*:*:*:*",
388872          "purl": "pkg:npm/chownr@1.1.4",
388873          "swid": {
388874            "attachment": {}
388875          },
388876          "pedigree": {},
388877          "externalReferences": [
388878            {
388879              "url": "git://github.com/isaacs/chownr.git",
388880              "type": "distribution"
388881            }
388882          ],
388883          "evidence": {},
388884          "signature": {
388885            "signature": {
388886              "publicKey": {}
388887            }
388888          },
388889          "modelCard": {
388890            "modelParameters": {
388891              "approach": {}
388892            },
388893            "quantitativeAnalysis": {
388894              "graphics": {}
388895            },
388896            "considerations": {}
388897          }
388898        },
388899        {
388900          "type": "library",
388901          "bom-ref": "pkg:npm/chownr@2.0.0?package-id=b5088c57ceda122f",
388902          "supplier": {},
388903          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
388904          "name": "chownr",
388905          "version": "2.0.0",
388906          "description": "like `chown -R`",
388907          "licenses": [
388908            {
388909              "license": {
388910                "id": "ISC"
388911              }
388912            }
388913          ],
388914          "cpe": "cpe:2.3:a:chownr:chownr:2.0.0:*:*:*:*:*:*:*",
388915          "purl": "pkg:npm/chownr@2.0.0",
388916          "swid": {
388917            "attachment": {}
388918          },
388919          "pedigree": {},
388920          "externalReferences": [
388921            {
388922              "url": "git://github.com/isaacs/chownr.git",
388923              "type": "distribution"
388924            }
388925          ],
388926          "evidence": {},
388927          "signature": {
388928            "signature": {
388929              "publicKey": {}
388930            }
388931          },
388932          "modelCard": {
388933            "modelParameters": {
388934              "approach": {}
388935            },
388936            "quantitativeAnalysis": {
388937              "graphics": {}
388938            },
388939            "considerations": {}
388940          }
388941        },
388942        {
388943          "type": "library",
388944          "bom-ref": "pkg:npm/ci-info@2.0.0?package-id=f83ceea2c70df5ec",
388945          "supplier": {},
388946          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
388947          "name": "ci-info",
388948          "version": "2.0.0",
388949          "description": "Get details about the current Continuous Integration environment",
388950          "licenses": [
388951            {
388952              "license": {
388953                "id": "MIT"
388954              }
388955            }
388956          ],
388957          "cpe": "cpe:2.3:a:ci-info:ci-info:2.0.0:*:*:*:*:*:*:*",
388958          "purl": "pkg:npm/ci-info@2.0.0",
388959          "swid": {
388960            "attachment": {}
388961          },
388962          "pedigree": {},
388963          "externalReferences": [
388964            {
388965              "url": "https://github.com/watson/ci-info.git",
388966              "type": "distribution"
388967            },
388968            {
388969              "url": "https://github.com/watson/ci-info",
388970              "type": "website"
388971            }
388972          ],
388973          "evidence": {},
388974          "signature": {
388975            "signature": {
388976              "publicKey": {}
388977            }
388978          },
388979          "modelCard": {
388980            "modelParameters": {
388981              "approach": {}
388982            },
388983            "quantitativeAnalysis": {
388984              "graphics": {}
388985            },
388986            "considerations": {}
388987          }
388988        },
388989        {
388990          "type": "library",
388991          "bom-ref": "pkg:npm/cidr-regex@3.1.1?package-id=be2d165b38649e26",
388992          "supplier": {},
388993          "author": "silverwind \u003cme@silverwind.io\u003e",
388994          "name": "cidr-regex",
388995          "version": "3.1.1",
388996          "description": "Regular expression for matching IP addresses in CIDR notation",
388997          "licenses": [
388998            {
388999              "license": {
389000                "id": "BSD-2-Clause"
389001              }
389002            }
389003          ],
389004          "cpe": "cpe:2.3:a:cidr-regex:cidr-regex:3.1.1:*:*:*:*:*:*:*",
389005          "purl": "pkg:npm/cidr-regex@3.1.1",
389006          "swid": {
389007            "attachment": {}
389008          },
389009          "pedigree": {},
389010          "externalReferences": [
389011            {
389012              "url": "silverwind/cidr-regex",
389013              "type": "distribution"
389014            }
389015          ],
389016          "evidence": {},
389017          "signature": {
389018            "signature": {
389019              "publicKey": {}
389020            }
389021          },
389022          "modelCard": {
389023            "modelParameters": {
389024              "approach": {}
389025            },
389026            "quantitativeAnalysis": {
389027              "graphics": {}
389028            },
389029            "considerations": {}
389030          }
389031        },
389032        {
389033          "type": "library",
389034          "bom-ref": "pkg:npm/clean-stack@2.2.0?package-id=9a5c51e7acb4b115",
389035          "supplier": {},
389036          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
389037          "name": "clean-stack",
389038          "version": "2.2.0",
389039          "description": "Clean up error stack traces",
389040          "licenses": [
389041            {
389042              "license": {
389043                "id": "MIT"
389044              }
389045            }
389046          ],
389047          "cpe": "cpe:2.3:a:clean-stack:clean-stack:2.2.0:*:*:*:*:*:*:*",
389048          "purl": "pkg:npm/clean-stack@2.2.0",
389049          "swid": {
389050            "attachment": {}
389051          },
389052          "pedigree": {},
389053          "externalReferences": [
389054            {
389055              "url": "sindresorhus/clean-stack",
389056              "type": "distribution"
389057            }
389058          ],
389059          "evidence": {},
389060          "signature": {
389061            "signature": {
389062              "publicKey": {}
389063            }
389064          },
389065          "modelCard": {
389066            "modelParameters": {
389067              "approach": {}
389068            },
389069            "quantitativeAnalysis": {
389070              "graphics": {}
389071            },
389072            "considerations": {}
389073          }
389074        },
389075        {
389076          "type": "library",
389077          "bom-ref": "pkg:npm/cli-columns@4.0.0?package-id=61a1dfb277c2e6f7",
389078          "supplier": {},
389079          "author": "Shannon Moeller \u003cme@shannonmoeller\u003e (http://shannonmoeller.com)",
389080          "name": "cli-columns",
389081          "version": "4.0.0",
389082          "description": "Columnated lists for the CLI.",
389083          "licenses": [
389084            {
389085              "license": {
389086                "id": "MIT"
389087              }
389088            }
389089          ],
389090          "cpe": "cpe:2.3:a:shannonmoeller:cli-columns:4.0.0:*:*:*:*:*:*:*",
389091          "purl": "pkg:npm/cli-columns@4.0.0",
389092          "swid": {
389093            "attachment": {}
389094          },
389095          "pedigree": {},
389096          "externalReferences": [
389097            {
389098              "url": "shannonmoeller/cli-columns",
389099              "type": "distribution"
389100            },
389101            {
389102              "url": "https://github.com/shannonmoeller/cli-columns#readme",
389103              "type": "website"
389104            }
389105          ],
389106          "evidence": {},
389107          "signature": {
389108            "signature": {
389109              "publicKey": {}
389110            }
389111          },
389112          "modelCard": {
389113            "modelParameters": {
389114              "approach": {}
389115            },
389116            "quantitativeAnalysis": {
389117              "graphics": {}
389118            },
389119            "considerations": {}
389120          }
389121        },
389122        {
389123          "type": "library",
389124          "bom-ref": "pkg:npm/cli-cursor@2.1.0?package-id=3379c5bd0e8b1d52",
389125          "supplier": {},
389126          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
389127          "name": "cli-cursor",
389128          "version": "2.1.0",
389129          "description": "Toggle the CLI cursor",
389130          "licenses": [
389131            {
389132              "license": {
389133                "id": "MIT"
389134              }
389135            }
389136          ],
389137          "cpe": "cpe:2.3:a:cli-cursor:cli-cursor:2.1.0:*:*:*:*:*:*:*",
389138          "purl": "pkg:npm/cli-cursor@2.1.0",
389139          "swid": {
389140            "attachment": {}
389141          },
389142          "pedigree": {},
389143          "externalReferences": [
389144            {
389145              "url": "sindresorhus/cli-cursor",
389146              "type": "distribution"
389147            }
389148          ],
389149          "evidence": {},
389150          "signature": {
389151            "signature": {
389152              "publicKey": {}
389153            }
389154          },
389155          "modelCard": {
389156            "modelParameters": {
389157              "approach": {}
389158            },
389159            "quantitativeAnalysis": {
389160              "graphics": {}
389161            },
389162            "considerations": {}
389163          }
389164        },
389165        {
389166          "type": "library",
389167          "bom-ref": "pkg:npm/cli-spinners@2.8.0?package-id=56d76fe6a345c09b",
389168          "supplier": {},
389169          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
389170          "name": "cli-spinners",
389171          "version": "2.8.0",
389172          "description": "Spinners for use in the terminal",
389173          "licenses": [
389174            {
389175              "license": {
389176                "id": "MIT"
389177              }
389178            }
389179          ],
389180          "cpe": "cpe:2.3:a:cli-spinners:cli-spinners:2.8.0:*:*:*:*:*:*:*",
389181          "purl": "pkg:npm/cli-spinners@2.8.0",
389182          "swid": {
389183            "attachment": {}
389184          },
389185          "pedigree": {},
389186          "externalReferences": [
389187            {
389188              "url": "sindresorhus/cli-spinners",
389189              "type": "distribution"
389190            }
389191          ],
389192          "evidence": {},
389193          "signature": {
389194            "signature": {
389195              "publicKey": {}
389196            }
389197          },
389198          "modelCard": {
389199            "modelParameters": {
389200              "approach": {}
389201            },
389202            "quantitativeAnalysis": {
389203              "graphics": {}
389204            },
389205            "considerations": {}
389206          }
389207        },
389208        {
389209          "type": "library",
389210          "bom-ref": "pkg:npm/cli-table3@0.6.2?package-id=c77ee2194bd52f3d",
389211          "supplier": {},
389212          "author": "James Talmage",
389213          "name": "cli-table3",
389214          "version": "0.6.2",
389215          "description": "Pretty unicode tables for the command line. Based on the original cli-table.",
389216          "licenses": [
389217            {
389218              "license": {
389219                "id": "MIT"
389220              }
389221            }
389222          ],
389223          "cpe": "cpe:2.3:a:cli-table3:cli-table3:0.6.2:*:*:*:*:*:*:*",
389224          "purl": "pkg:npm/cli-table3@0.6.2",
389225          "swid": {
389226            "attachment": {}
389227          },
389228          "pedigree": {},
389229          "externalReferences": [
389230            {
389231              "url": "https://github.com/cli-table/cli-table3.git",
389232              "type": "distribution"
389233            },
389234            {
389235              "url": "https://github.com/cli-table/cli-table3",
389236              "type": "website"
389237            }
389238          ],
389239          "evidence": {},
389240          "signature": {
389241            "signature": {
389242              "publicKey": {}
389243            }
389244          },
389245          "modelCard": {
389246            "modelParameters": {
389247              "approach": {}
389248            },
389249            "quantitativeAnalysis": {
389250              "graphics": {}
389251            },
389252            "considerations": {}
389253          }
389254        },
389255        {
389256          "type": "library",
389257          "bom-ref": "pkg:npm/clone@1.0.4?package-id=44b571b36478d30c",
389258          "supplier": {},
389259          "author": "Paul Vorbach \u003cpaul@vorba.ch\u003e (http://paul.vorba.ch/)",
389260          "name": "clone",
389261          "version": "1.0.4",
389262          "description": "deep cloning of objects and arrays",
389263          "licenses": [
389264            {
389265              "license": {
389266                "id": "MIT"
389267              }
389268            }
389269          ],
389270          "cpe": "cpe:2.3:a:clone:clone:1.0.4:*:*:*:*:*:*:*",
389271          "purl": "pkg:npm/clone@1.0.4",
389272          "swid": {
389273            "attachment": {}
389274          },
389275          "pedigree": {},
389276          "externalReferences": [
389277            {
389278              "url": "git://github.com/pvorb/node-clone.git",
389279              "type": "distribution"
389280            }
389281          ],
389282          "evidence": {},
389283          "signature": {
389284            "signature": {
389285              "publicKey": {}
389286            }
389287          },
389288          "modelCard": {
389289            "modelParameters": {
389290              "approach": {}
389291            },
389292            "quantitativeAnalysis": {
389293              "graphics": {}
389294            },
389295            "considerations": {}
389296          }
389297        },
389298        {
389299          "type": "library",
389300          "bom-ref": "pkg:npm/clone@1.0.4?package-id=5436be598b5ead36",
389301          "supplier": {},
389302          "author": "Paul Vorbach \u003cpaul@vorba.ch\u003e (http://paul.vorba.ch/)",
389303          "name": "clone",
389304          "version": "1.0.4",
389305          "description": "deep cloning of objects and arrays",
389306          "licenses": [
389307            {
389308              "license": {
389309                "id": "MIT"
389310              }
389311            }
389312          ],
389313          "cpe": "cpe:2.3:a:clone:clone:1.0.4:*:*:*:*:*:*:*",
389314          "purl": "pkg:npm/clone@1.0.4",
389315          "swid": {
389316            "attachment": {}
389317          },
389318          "pedigree": {},
389319          "externalReferences": [
389320            {
389321              "url": "git://github.com/pvorb/node-clone.git",
389322              "type": "distribution"
389323            }
389324          ],
389325          "evidence": {},
389326          "signature": {
389327            "signature": {
389328              "publicKey": {}
389329            }
389330          },
389331          "modelCard": {
389332            "modelParameters": {
389333              "approach": {}
389334            },
389335            "quantitativeAnalysis": {
389336              "graphics": {}
389337            },
389338            "considerations": {}
389339          }
389340        },
389341        {
389342          "type": "library",
389343          "bom-ref": "pkg:npm/clone-response@1.0.2?package-id=2173df3f36d11d5b",
389344          "supplier": {},
389345          "author": "Luke Childs \u003clukechilds123@gmail.com\u003e (http://lukechilds.co.uk)",
389346          "name": "clone-response",
389347          "version": "1.0.2",
389348          "description": "Clone a Node.js HTTP response stream",
389349          "licenses": [
389350            {
389351              "license": {
389352                "id": "MIT"
389353              }
389354            }
389355          ],
389356          "cpe": "cpe:2.3:a:clone-response:clone-response:1.0.2:*:*:*:*:*:*:*",
389357          "purl": "pkg:npm/clone-response@1.0.2",
389358          "swid": {
389359            "attachment": {}
389360          },
389361          "pedigree": {},
389362          "externalReferences": [
389363            {
389364              "url": "git+https://github.com/lukechilds/clone-response.git",
389365              "type": "distribution"
389366            },
389367            {
389368              "url": "https://github.com/lukechilds/clone-response",
389369              "type": "website"
389370            }
389371          ],
389372          "evidence": {},
389373          "signature": {
389374            "signature": {
389375              "publicKey": {}
389376            }
389377          },
389378          "modelCard": {
389379            "modelParameters": {
389380              "approach": {}
389381            },
389382            "quantitativeAnalysis": {
389383              "graphics": {}
389384            },
389385            "considerations": {}
389386          }
389387        },
389388        {
389389          "type": "library",
389390          "bom-ref": "pkg:npm/clone-response@1.0.3?package-id=31183265266a46b8",
389391          "supplier": {},
389392          "author": "Luke Childs \u003clukechilds123@gmail.com\u003e (http://lukechilds.co.uk)",
389393          "name": "clone-response",
389394          "version": "1.0.3",
389395          "description": "Clone a Node.js HTTP response stream",
389396          "licenses": [
389397            {
389398              "license": {
389399                "id": "MIT"
389400              }
389401            }
389402          ],
389403          "cpe": "cpe:2.3:a:clone-response:clone-response:1.0.3:*:*:*:*:*:*:*",
389404          "purl": "pkg:npm/clone-response@1.0.3",
389405          "swid": {
389406            "attachment": {}
389407          },
389408          "pedigree": {},
389409          "externalReferences": [
389410            {
389411              "url": "git+https://github.com/sindresorhus/clone-response.git",
389412              "type": "distribution"
389413            }
389414          ],
389415          "evidence": {},
389416          "signature": {
389417            "signature": {
389418              "publicKey": {}
389419            }
389420          },
389421          "modelCard": {
389422            "modelParameters": {
389423              "approach": {}
389424            },
389425            "quantitativeAnalysis": {
389426              "graphics": {}
389427            },
389428            "considerations": {}
389429          }
389430        },
389431        {
389432          "type": "library",
389433          "bom-ref": "pkg:npm/cmd-shim@5.0.0?package-id=6701e31fdf422502",
389434          "supplier": {},
389435          "author": "GitHub Inc.",
389436          "name": "cmd-shim",
389437          "version": "5.0.0",
389438          "description": "Used in npm for command line application support",
389439          "licenses": [
389440            {
389441              "license": {
389442                "id": "ISC"
389443              }
389444            }
389445          ],
389446          "cpe": "cpe:2.3:a:cmd-shim:cmd-shim:5.0.0:*:*:*:*:*:*:*",
389447          "purl": "pkg:npm/cmd-shim@5.0.0",
389448          "swid": {
389449            "attachment": {}
389450          },
389451          "pedigree": {},
389452          "externalReferences": [
389453            {
389454              "url": "https://github.com/npm/cmd-shim.git",
389455              "type": "distribution"
389456            }
389457          ],
389458          "evidence": {},
389459          "signature": {
389460            "signature": {
389461              "publicKey": {}
389462            }
389463          },
389464          "modelCard": {
389465            "modelParameters": {
389466              "approach": {}
389467            },
389468            "quantitativeAnalysis": {
389469              "graphics": {}
389470            },
389471            "considerations": {}
389472          }
389473        },
389474        {
389475          "type": "library",
389476          "bom-ref": "pkg:npm/color-convert@1.9.3?package-id=b59d318e978e5d66",
389477          "supplier": {},
389478          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
389479          "name": "color-convert",
389480          "version": "1.9.3",
389481          "description": "Plain color conversion functions",
389482          "licenses": [
389483            {
389484              "license": {
389485                "id": "MIT"
389486              }
389487            }
389488          ],
389489          "cpe": "cpe:2.3:a:color-convert:color-convert:1.9.3:*:*:*:*:*:*:*",
389490          "purl": "pkg:npm/color-convert@1.9.3",
389491          "swid": {
389492            "attachment": {}
389493          },
389494          "pedigree": {},
389495          "externalReferences": [
389496            {
389497              "url": "Qix-/color-convert",
389498              "type": "distribution"
389499            }
389500          ],
389501          "evidence": {},
389502          "signature": {
389503            "signature": {
389504              "publicKey": {}
389505            }
389506          },
389507          "modelCard": {
389508            "modelParameters": {
389509              "approach": {}
389510            },
389511            "quantitativeAnalysis": {
389512              "graphics": {}
389513            },
389514            "considerations": {}
389515          }
389516        },
389517        {
389518          "type": "library",
389519          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=2be936aafe32cf82",
389520          "supplier": {},
389521          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
389522          "name": "color-convert",
389523          "version": "2.0.1",
389524          "description": "Plain color conversion functions",
389525          "licenses": [
389526            {
389527              "license": {
389528                "id": "MIT"
389529              }
389530            }
389531          ],
389532          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
389533          "purl": "pkg:npm/color-convert@2.0.1",
389534          "swid": {
389535            "attachment": {}
389536          },
389537          "pedigree": {},
389538          "externalReferences": [
389539            {
389540              "url": "Qix-/color-convert",
389541              "type": "distribution"
389542            }
389543          ],
389544          "evidence": {},
389545          "signature": {
389546            "signature": {
389547              "publicKey": {}
389548            }
389549          },
389550          "modelCard": {
389551            "modelParameters": {
389552              "approach": {}
389553            },
389554            "quantitativeAnalysis": {
389555              "graphics": {}
389556            },
389557            "considerations": {}
389558          }
389559        },
389560        {
389561          "type": "library",
389562          "bom-ref": "pkg:npm/color-convert@2.0.1?package-id=15b92925457dcb7d",
389563          "supplier": {},
389564          "author": "Heather Arthur \u003cfayearthur@gmail.com\u003e",
389565          "name": "color-convert",
389566          "version": "2.0.1",
389567          "description": "Plain color conversion functions",
389568          "licenses": [
389569            {
389570              "license": {
389571                "id": "MIT"
389572              }
389573            }
389574          ],
389575          "cpe": "cpe:2.3:a:color-convert:color-convert:2.0.1:*:*:*:*:*:*:*",
389576          "purl": "pkg:npm/color-convert@2.0.1",
389577          "swid": {
389578            "attachment": {}
389579          },
389580          "pedigree": {},
389581          "externalReferences": [
389582            {
389583              "url": "Qix-/color-convert",
389584              "type": "distribution"
389585            }
389586          ],
389587          "evidence": {},
389588          "signature": {
389589            "signature": {
389590              "publicKey": {}
389591            }
389592          },
389593          "modelCard": {
389594            "modelParameters": {
389595              "approach": {}
389596            },
389597            "quantitativeAnalysis": {
389598              "graphics": {}
389599            },
389600            "considerations": {}
389601          }
389602        },
389603        {
389604          "type": "library",
389605          "bom-ref": "pkg:npm/color-name@1.1.3?package-id=21b65fb759f90e9b",
389606          "supplier": {},
389607          "author": "DY \u003cdfcreative@gmail.com\u003e",
389608          "name": "color-name",
389609          "version": "1.1.3",
389610          "description": "A list of color names and its values",
389611          "licenses": [
389612            {
389613              "license": {
389614                "id": "MIT"
389615              }
389616            }
389617          ],
389618          "cpe": "cpe:2.3:a:color-name:color-name:1.1.3:*:*:*:*:*:*:*",
389619          "purl": "pkg:npm/color-name@1.1.3",
389620          "swid": {
389621            "attachment": {}
389622          },
389623          "pedigree": {},
389624          "externalReferences": [
389625            {
389626              "url": "git@github.com:dfcreative/color-name.git",
389627              "type": "distribution"
389628            },
389629            {
389630              "url": "https://github.com/dfcreative/color-name",
389631              "type": "website"
389632            }
389633          ],
389634          "evidence": {},
389635          "signature": {
389636            "signature": {
389637              "publicKey": {}
389638            }
389639          },
389640          "modelCard": {
389641            "modelParameters": {
389642              "approach": {}
389643            },
389644            "quantitativeAnalysis": {
389645              "graphics": {}
389646            },
389647            "considerations": {}
389648          }
389649        },
389650        {
389651          "type": "library",
389652          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=b14fd2e37cdab40f",
389653          "supplier": {},
389654          "author": "DY \u003cdfcreative@gmail.com\u003e",
389655          "name": "color-name",
389656          "version": "1.1.4",
389657          "description": "A list of color names and its values",
389658          "licenses": [
389659            {
389660              "license": {
389661                "id": "MIT"
389662              }
389663            }
389664          ],
389665          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
389666          "purl": "pkg:npm/color-name@1.1.4",
389667          "swid": {
389668            "attachment": {}
389669          },
389670          "pedigree": {},
389671          "externalReferences": [
389672            {
389673              "url": "git@github.com:colorjs/color-name.git",
389674              "type": "distribution"
389675            },
389676            {
389677              "url": "https://github.com/colorjs/color-name",
389678              "type": "website"
389679            }
389680          ],
389681          "evidence": {},
389682          "signature": {
389683            "signature": {
389684              "publicKey": {}
389685            }
389686          },
389687          "modelCard": {
389688            "modelParameters": {
389689              "approach": {}
389690            },
389691            "quantitativeAnalysis": {
389692              "graphics": {}
389693            },
389694            "considerations": {}
389695          }
389696        },
389697        {
389698          "type": "library",
389699          "bom-ref": "pkg:npm/color-name@1.1.4?package-id=8622f3023cfe465b",
389700          "supplier": {},
389701          "author": "DY \u003cdfcreative@gmail.com\u003e",
389702          "name": "color-name",
389703          "version": "1.1.4",
389704          "description": "A list of color names and its values",
389705          "licenses": [
389706            {
389707              "license": {
389708                "id": "MIT"
389709              }
389710            }
389711          ],
389712          "cpe": "cpe:2.3:a:color-name:color-name:1.1.4:*:*:*:*:*:*:*",
389713          "purl": "pkg:npm/color-name@1.1.4",
389714          "swid": {
389715            "attachment": {}
389716          },
389717          "pedigree": {},
389718          "externalReferences": [
389719            {
389720              "url": "git@github.com:colorjs/color-name.git",
389721              "type": "distribution"
389722            },
389723            {
389724              "url": "https://github.com/colorjs/color-name",
389725              "type": "website"
389726            }
389727          ],
389728          "evidence": {},
389729          "signature": {
389730            "signature": {
389731              "publicKey": {}
389732            }
389733          },
389734          "modelCard": {
389735            "modelParameters": {
389736              "approach": {}
389737            },
389738            "quantitativeAnalysis": {
389739              "graphics": {}
389740            },
389741            "considerations": {}
389742          }
389743        },
389744        {
389745          "type": "library",
389746          "bom-ref": "pkg:npm/color-support@1.1.3?package-id=33c3f3c0dd43aff8",
389747          "supplier": {},
389748          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
389749          "name": "color-support",
389750          "version": "1.1.3",
389751          "description": "A module which will endeavor to guess your terminal's level of color support.",
389752          "licenses": [
389753            {
389754              "license": {
389755                "id": "ISC"
389756              }
389757            }
389758          ],
389759          "cpe": "cpe:2.3:a:color-support:color-support:1.1.3:*:*:*:*:*:*:*",
389760          "purl": "pkg:npm/color-support@1.1.3",
389761          "swid": {
389762            "attachment": {}
389763          },
389764          "pedigree": {},
389765          "externalReferences": [
389766            {
389767              "url": "git+https://github.com/isaacs/color-support.git",
389768              "type": "distribution"
389769            }
389770          ],
389771          "evidence": {},
389772          "signature": {
389773            "signature": {
389774              "publicKey": {}
389775            }
389776          },
389777          "modelCard": {
389778            "modelParameters": {
389779              "approach": {}
389780            },
389781            "quantitativeAnalysis": {
389782              "graphics": {}
389783            },
389784            "considerations": {}
389785          }
389786        },
389787        {
389788          "type": "library",
389789          "bom-ref": "pkg:npm/columnify@1.6.0?package-id=fc90187aad4a6027",
389790          "supplier": {},
389791          "author": "Tim Oxley",
389792          "name": "columnify",
389793          "version": "1.6.0",
389794          "description": "Render data in text columns. Supports in-column text-wrap.",
389795          "licenses": [
389796            {
389797              "license": {
389798                "id": "MIT"
389799              }
389800            }
389801          ],
389802          "cpe": "cpe:2.3:a:columnify:columnify:1.6.0:*:*:*:*:*:*:*",
389803          "purl": "pkg:npm/columnify@1.6.0",
389804          "swid": {
389805            "attachment": {}
389806          },
389807          "pedigree": {},
389808          "externalReferences": [
389809            {
389810              "url": "git://github.com/timoxley/columnify.git",
389811              "type": "distribution"
389812            },
389813            {
389814              "url": "https://github.com/timoxley/columnify",
389815              "type": "website"
389816            }
389817          ],
389818          "evidence": {},
389819          "signature": {
389820            "signature": {
389821              "publicKey": {}
389822            }
389823          },
389824          "modelCard": {
389825            "modelParameters": {
389826              "approach": {}
389827            },
389828            "quantitativeAnalysis": {
389829              "graphics": {}
389830            },
389831            "considerations": {}
389832          }
389833        },
389834        {
389835          "type": "library",
389836          "bom-ref": "pkg:npm/combined-stream@1.0.8?package-id=868606bb12d293db",
389837          "supplier": {},
389838          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
389839          "name": "combined-stream",
389840          "version": "1.0.8",
389841          "description": "A stream that emits multiple other streams one after another.",
389842          "licenses": [
389843            {
389844              "license": {
389845                "id": "MIT"
389846              }
389847            }
389848          ],
389849          "cpe": "cpe:2.3:a:combined-stream:combined-stream:1.0.8:*:*:*:*:*:*:*",
389850          "purl": "pkg:npm/combined-stream@1.0.8",
389851          "swid": {
389852            "attachment": {}
389853          },
389854          "pedigree": {},
389855          "externalReferences": [
389856            {
389857              "url": "git://github.com/felixge/node-combined-stream.git",
389858              "type": "distribution"
389859            },
389860            {
389861              "url": "https://github.com/felixge/node-combined-stream",
389862              "type": "website"
389863            }
389864          ],
389865          "evidence": {},
389866          "signature": {
389867            "signature": {
389868              "publicKey": {}
389869            }
389870          },
389871          "modelCard": {
389872            "modelParameters": {
389873              "approach": {}
389874            },
389875            "quantitativeAnalysis": {
389876              "graphics": {}
389877            },
389878            "considerations": {}
389879          }
389880        },
389881        {
389882          "type": "library",
389883          "bom-ref": "pkg:npm/commander@2.20.3?package-id=88aef880987e95cb",
389884          "supplier": {},
389885          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
389886          "name": "commander",
389887          "version": "2.20.3",
389888          "description": "the complete solution for node.js command-line programs",
389889          "licenses": [
389890            {
389891              "license": {
389892                "id": "MIT"
389893              }
389894            }
389895          ],
389896          "cpe": "cpe:2.3:a:commander:commander:2.20.3:*:*:*:*:*:*:*",
389897          "purl": "pkg:npm/commander@2.20.3",
389898          "swid": {
389899            "attachment": {}
389900          },
389901          "pedigree": {},
389902          "externalReferences": [
389903            {
389904              "url": "https://github.com/tj/commander.js.git",
389905              "type": "distribution"
389906            }
389907          ],
389908          "evidence": {},
389909          "signature": {
389910            "signature": {
389911              "publicKey": {}
389912            }
389913          },
389914          "modelCard": {
389915            "modelParameters": {
389916              "approach": {}
389917            },
389918            "quantitativeAnalysis": {
389919              "graphics": {}
389920            },
389921            "considerations": {}
389922          }
389923        },
389924        {
389925          "type": "library",
389926          "bom-ref": "pkg:npm/common-ancestor-path@1.0.1?package-id=4296edf5ae5437c0",
389927          "supplier": {},
389928          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
389929          "name": "common-ancestor-path",
389930          "version": "1.0.1",
389931          "description": "Find the common ancestor of 2 or more paths on Windows or Unix",
389932          "licenses": [
389933            {
389934              "license": {
389935                "id": "ISC"
389936              }
389937            }
389938          ],
389939          "cpe": "cpe:2.3:a:common-ancestor-path:common-ancestor-path:1.0.1:*:*:*:*:*:*:*",
389940          "purl": "pkg:npm/common-ancestor-path@1.0.1",
389941          "swid": {
389942            "attachment": {}
389943          },
389944          "pedigree": {},
389945          "externalReferences": [
389946            {
389947              "url": "git+https://github.com/isaacs/common-ancestor-path",
389948              "type": "distribution"
389949            }
389950          ],
389951          "evidence": {},
389952          "signature": {
389953            "signature": {
389954              "publicKey": {}
389955            }
389956          },
389957          "modelCard": {
389958            "modelParameters": {
389959              "approach": {}
389960            },
389961            "quantitativeAnalysis": {
389962              "graphics": {}
389963            },
389964            "considerations": {}
389965          }
389966        },
389967        {
389968          "type": "library",
389969          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=bdf14b65a5715b98",
389970          "supplier": {},
389971          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
389972          "name": "concat-map",
389973          "version": "0.0.1",
389974          "description": "concatenative mapdashery",
389975          "licenses": [
389976            {
389977              "license": {
389978                "id": "MIT"
389979              }
389980            }
389981          ],
389982          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
389983          "purl": "pkg:npm/concat-map@0.0.1",
389984          "swid": {
389985            "attachment": {}
389986          },
389987          "pedigree": {},
389988          "externalReferences": [
389989            {
389990              "url": "git://github.com/substack/node-concat-map.git",
389991              "type": "distribution"
389992            }
389993          ],
389994          "evidence": {},
389995          "signature": {
389996            "signature": {
389997              "publicKey": {}
389998            }
389999          },
390000          "modelCard": {
390001            "modelParameters": {
390002              "approach": {}
390003            },
390004            "quantitativeAnalysis": {
390005              "graphics": {}
390006            },
390007            "considerations": {}
390008          }
390009        },
390010        {
390011          "type": "library",
390012          "bom-ref": "pkg:npm/concat-map@0.0.1?package-id=c45208cf5ec4e0c1",
390013          "supplier": {},
390014          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
390015          "name": "concat-map",
390016          "version": "0.0.1",
390017          "description": "concatenative mapdashery",
390018          "licenses": [
390019            {
390020              "license": {
390021                "id": "MIT"
390022              }
390023            }
390024          ],
390025          "cpe": "cpe:2.3:a:concat-map:concat-map:0.0.1:*:*:*:*:*:*:*",
390026          "purl": "pkg:npm/concat-map@0.0.1",
390027          "swid": {
390028            "attachment": {}
390029          },
390030          "pedigree": {},
390031          "externalReferences": [
390032            {
390033              "url": "git://github.com/substack/node-concat-map.git",
390034              "type": "distribution"
390035            }
390036          ],
390037          "evidence": {},
390038          "signature": {
390039            "signature": {
390040              "publicKey": {}
390041            }
390042          },
390043          "modelCard": {
390044            "modelParameters": {
390045              "approach": {}
390046            },
390047            "quantitativeAnalysis": {
390048              "graphics": {}
390049            },
390050            "considerations": {}
390051          }
390052        },
390053        {
390054          "type": "library",
390055          "bom-ref": "pkg:npm/config-chain@1.1.13?package-id=29e25a25aac354e7",
390056          "supplier": {},
390057          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (http://dominictarr.com)",
390058          "name": "config-chain",
390059          "version": "1.1.13",
390060          "description": "HANDLE CONFIGURATION ONCE AND FOR ALL",
390061          "licenses": [
390062            {
390063              "license": {
390064                "id": "MIT"
390065              }
390066            }
390067          ],
390068          "cpe": "cpe:2.3:a:config-chain:config-chain:1.1.13:*:*:*:*:*:*:*",
390069          "purl": "pkg:npm/config-chain@1.1.13",
390070          "swid": {
390071            "attachment": {}
390072          },
390073          "pedigree": {},
390074          "externalReferences": [
390075            {
390076              "url": "https://github.com/dominictarr/config-chain.git",
390077              "type": "distribution"
390078            },
390079            {
390080              "url": "http://github.com/dominictarr/config-chain",
390081              "type": "website"
390082            }
390083          ],
390084          "evidence": {},
390085          "signature": {
390086            "signature": {
390087              "publicKey": {}
390088            }
390089          },
390090          "modelCard": {
390091            "modelParameters": {
390092              "approach": {}
390093            },
390094            "quantitativeAnalysis": {
390095              "graphics": {}
390096            },
390097            "considerations": {}
390098          }
390099        },
390100        {
390101          "type": "library",
390102          "bom-ref": "pkg:npm/console-control-strings@1.1.0?package-id=f5b1c468fcf0a37a",
390103          "supplier": {},
390104          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
390105          "name": "console-control-strings",
390106          "version": "1.1.0",
390107          "description": "A library of cross-platform tested terminal/console command strings for doing things like color and cursor positioning.  This is a subset of both ansi and vt100.  All control codes included work on both Windows \u0026 Unix-like OSes, except where noted.",
390108          "licenses": [
390109            {
390110              "license": {
390111                "id": "ISC"
390112              }
390113            }
390114          ],
390115          "cpe": "cpe:2.3:a:console-control-strings:console-control-strings:1.1.0:*:*:*:*:*:*:*",
390116          "purl": "pkg:npm/console-control-strings@1.1.0",
390117          "swid": {
390118            "attachment": {}
390119          },
390120          "pedigree": {},
390121          "externalReferences": [
390122            {
390123              "url": "https://github.com/iarna/console-control-strings",
390124              "type": "distribution"
390125            }
390126          ],
390127          "evidence": {},
390128          "signature": {
390129            "signature": {
390130              "publicKey": {}
390131            }
390132          },
390133          "modelCard": {
390134            "modelParameters": {
390135              "approach": {}
390136            },
390137            "quantitativeAnalysis": {
390138              "graphics": {}
390139            },
390140            "considerations": {}
390141          }
390142        },
390143        {
390144          "type": "library",
390145          "bom-ref": "pkg:npm/content-disposition@0.5.2?package-id=78de68818c5e5be7",
390146          "supplier": {},
390147          "name": "content-disposition",
390148          "version": "0.5.2",
390149          "description": "Create and parse Content-Disposition header",
390150          "licenses": [
390151            {
390152              "license": {
390153                "id": "MIT"
390154              }
390155            }
390156          ],
390157          "cpe": "cpe:2.3:a:content-disposition:content-disposition:0.5.2:*:*:*:*:*:*:*",
390158          "purl": "pkg:npm/content-disposition@0.5.2",
390159          "swid": {
390160            "attachment": {}
390161          },
390162          "pedigree": {},
390163          "externalReferences": [
390164            {
390165              "url": "jshttp/content-disposition",
390166              "type": "distribution"
390167            }
390168          ],
390169          "evidence": {},
390170          "signature": {
390171            "signature": {
390172              "publicKey": {}
390173            }
390174          },
390175          "modelCard": {
390176            "modelParameters": {
390177              "approach": {}
390178            },
390179            "quantitativeAnalysis": {
390180              "graphics": {}
390181            },
390182            "considerations": {}
390183          }
390184        },
390185        {
390186          "type": "library",
390187          "bom-ref": "pkg:npm/content-type@1.0.5?package-id=adbc2d3e176aeaa7",
390188          "supplier": {},
390189          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
390190          "name": "content-type",
390191          "version": "1.0.5",
390192          "description": "Create and parse HTTP Content-Type header",
390193          "licenses": [
390194            {
390195              "license": {
390196                "id": "MIT"
390197              }
390198            }
390199          ],
390200          "cpe": "cpe:2.3:a:content-type:content-type:1.0.5:*:*:*:*:*:*:*",
390201          "purl": "pkg:npm/content-type@1.0.5",
390202          "swid": {
390203            "attachment": {}
390204          },
390205          "pedigree": {},
390206          "externalReferences": [
390207            {
390208              "url": "jshttp/content-type",
390209              "type": "distribution"
390210            }
390211          ],
390212          "evidence": {},
390213          "signature": {
390214            "signature": {
390215              "publicKey": {}
390216            }
390217          },
390218          "modelCard": {
390219            "modelParameters": {
390220              "approach": {}
390221            },
390222            "quantitativeAnalysis": {
390223              "graphics": {}
390224            },
390225            "considerations": {}
390226          }
390227        },
390228        {
390229          "type": "library",
390230          "bom-ref": "pkg:npm/cookie@0.3.1?package-id=8d0bbae67fa22756",
390231          "supplier": {},
390232          "author": "Roman Shtylman \u003cshtylman@gmail.com\u003e",
390233          "name": "cookie",
390234          "version": "0.3.1",
390235          "description": "HTTP server cookie parsing and serialization",
390236          "licenses": [
390237            {
390238              "license": {
390239                "id": "MIT"
390240              }
390241            }
390242          ],
390243          "cpe": "cpe:2.3:a:cookie:cookie:0.3.1:*:*:*:*:*:*:*",
390244          "purl": "pkg:npm/cookie@0.3.1",
390245          "swid": {
390246            "attachment": {}
390247          },
390248          "pedigree": {},
390249          "externalReferences": [
390250            {
390251              "url": "jshttp/cookie",
390252              "type": "distribution"
390253            }
390254          ],
390255          "evidence": {},
390256          "signature": {
390257            "signature": {
390258              "publicKey": {}
390259            }
390260          },
390261          "modelCard": {
390262            "modelParameters": {
390263              "approach": {}
390264            },
390265            "quantitativeAnalysis": {
390266              "graphics": {}
390267            },
390268            "considerations": {}
390269          }
390270        },
390271        {
390272          "type": "library",
390273          "bom-ref": "pkg:npm/cookie@0.4.1?package-id=39f2215c0d7cde9f",
390274          "supplier": {},
390275          "author": "Roman Shtylman \u003cshtylman@gmail.com\u003e",
390276          "name": "cookie",
390277          "version": "0.4.1",
390278          "description": "HTTP server cookie parsing and serialization",
390279          "licenses": [
390280            {
390281              "license": {
390282                "id": "MIT"
390283              }
390284            }
390285          ],
390286          "cpe": "cpe:2.3:a:cookie:cookie:0.4.1:*:*:*:*:*:*:*",
390287          "purl": "pkg:npm/cookie@0.4.1",
390288          "swid": {
390289            "attachment": {}
390290          },
390291          "pedigree": {},
390292          "externalReferences": [
390293            {
390294              "url": "jshttp/cookie",
390295              "type": "distribution"
390296            }
390297          ],
390298          "evidence": {},
390299          "signature": {
390300            "signature": {
390301              "publicKey": {}
390302            }
390303          },
390304          "modelCard": {
390305            "modelParameters": {
390306              "approach": {}
390307            },
390308            "quantitativeAnalysis": {
390309              "graphics": {}
390310            },
390311            "considerations": {}
390312          }
390313        },
390314        {
390315          "type": "library",
390316          "bom-ref": "pkg:npm/cookie-parser@1.4.6?package-id=129192f72be6b9c1",
390317          "supplier": {},
390318          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
390319          "name": "cookie-parser",
390320          "version": "1.4.6",
390321          "description": "Parse HTTP request cookies",
390322          "licenses": [
390323            {
390324              "license": {
390325                "id": "MIT"
390326              }
390327            }
390328          ],
390329          "cpe": "cpe:2.3:a:cookie-parser:cookie-parser:1.4.6:*:*:*:*:*:*:*",
390330          "purl": "pkg:npm/cookie-parser@1.4.6",
390331          "swid": {
390332            "attachment": {}
390333          },
390334          "pedigree": {},
390335          "externalReferences": [
390336            {
390337              "url": "expressjs/cookie-parser",
390338              "type": "distribution"
390339            }
390340          ],
390341          "evidence": {},
390342          "signature": {
390343            "signature": {
390344              "publicKey": {}
390345            }
390346          },
390347          "modelCard": {
390348            "modelParameters": {
390349              "approach": {}
390350            },
390351            "quantitativeAnalysis": {
390352              "graphics": {}
390353            },
390354            "considerations": {}
390355          }
390356        },
390357        {
390358          "type": "library",
390359          "bom-ref": "pkg:npm/cookie-signature@1.0.6?package-id=679e26b17ad72290",
390360          "supplier": {},
390361          "author": "TJ Holowaychuk \u003ctj@learnboost.com\u003e",
390362          "name": "cookie-signature",
390363          "version": "1.0.6",
390364          "description": "Sign and unsign cookies",
390365          "licenses": [
390366            {
390367              "license": {
390368                "id": "MIT"
390369              }
390370            }
390371          ],
390372          "cpe": "cpe:2.3:a:cookie-signature:cookie-signature:1.0.6:*:*:*:*:*:*:*",
390373          "purl": "pkg:npm/cookie-signature@1.0.6",
390374          "swid": {
390375            "attachment": {}
390376          },
390377          "pedigree": {},
390378          "externalReferences": [
390379            {
390380              "url": "https://github.com/visionmedia/node-cookie-signature.git",
390381              "type": "distribution"
390382            }
390383          ],
390384          "evidence": {},
390385          "signature": {
390386            "signature": {
390387              "publicKey": {}
390388            }
390389          },
390390          "modelCard": {
390391            "modelParameters": {
390392              "approach": {}
390393            },
390394            "quantitativeAnalysis": {
390395              "graphics": {}
390396            },
390397            "considerations": {}
390398          }
390399        },
390400        {
390401          "type": "library",
390402          "bom-ref": "pkg:npm/core-util-is@1.0.2?package-id=619d47a4e1417653",
390403          "supplier": {},
390404          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
390405          "name": "core-util-is",
390406          "version": "1.0.2",
390407          "description": "The `util.is*` functions introduced in Node v0.12.",
390408          "licenses": [
390409            {
390410              "license": {
390411                "id": "MIT"
390412              }
390413            }
390414          ],
390415          "cpe": "cpe:2.3:a:core-util-is:core-util-is:1.0.2:*:*:*:*:*:*:*",
390416          "purl": "pkg:npm/core-util-is@1.0.2",
390417          "swid": {
390418            "attachment": {}
390419          },
390420          "pedigree": {},
390421          "externalReferences": [
390422            {
390423              "url": "git://github.com/isaacs/core-util-is",
390424              "type": "distribution"
390425            }
390426          ],
390427          "evidence": {},
390428          "signature": {
390429            "signature": {
390430              "publicKey": {}
390431            }
390432          },
390433          "modelCard": {
390434            "modelParameters": {
390435              "approach": {}
390436            },
390437            "quantitativeAnalysis": {
390438              "graphics": {}
390439            },
390440            "considerations": {}
390441          }
390442        },
390443        {
390444          "type": "library",
390445          "bom-ref": "pkg:npm/corepack@0.17.0?package-id=9d78c3bef9c05db3",
390446          "supplier": {},
390447          "name": "corepack",
390448          "version": "0.17.0",
390449          "licenses": [
390450            {
390451              "license": {
390452                "id": "MIT"
390453              }
390454            }
390455          ],
390456          "cpe": "cpe:2.3:a:corepack:corepack:0.17.0:*:*:*:*:*:*:*",
390457          "purl": "pkg:npm/corepack@0.17.0",
390458          "swid": {
390459            "attachment": {}
390460          },
390461          "pedigree": {},
390462          "externalReferences": [
390463            {
390464              "url": "https://github.com/nodejs/corepack.git",
390465              "type": "distribution"
390466            },
390467            {
390468              "url": "https://github.com/nodejs/corepack#readme",
390469              "type": "website"
390470            }
390471          ],
390472          "evidence": {},
390473          "signature": {
390474            "signature": {
390475              "publicKey": {}
390476            }
390477          },
390478          "modelCard": {
390479            "modelParameters": {
390480              "approach": {}
390481            },
390482            "quantitativeAnalysis": {
390483              "graphics": {}
390484            },
390485            "considerations": {}
390486          }
390487        },
390488        {
390489          "type": "library",
390490          "bom-ref": "pkg:npm/cross-spawn@6.0.5?package-id=218973aec9af7ce8",
390491          "supplier": {},
390492          "author": "André Cruz \u003candre@moxy.studio\u003e",
390493          "name": "cross-spawn",
390494          "version": "6.0.5",
390495          "description": "Cross platform child_process#spawn and child_process#spawnSync",
390496          "licenses": [
390497            {
390498              "license": {
390499                "id": "MIT"
390500              }
390501            }
390502          ],
390503          "cpe": "cpe:2.3:a:cross-spawn:cross-spawn:6.0.5:*:*:*:*:*:*:*",
390504          "purl": "pkg:npm/cross-spawn@6.0.5",
390505          "swid": {
390506            "attachment": {}
390507          },
390508          "pedigree": {},
390509          "externalReferences": [
390510            {
390511              "url": "git@github.com:moxystudio/node-cross-spawn.git",
390512              "type": "distribution"
390513            },
390514            {
390515              "url": "https://github.com/moxystudio/node-cross-spawn",
390516              "type": "website"
390517            }
390518          ],
390519          "evidence": {},
390520          "signature": {
390521            "signature": {
390522              "publicKey": {}
390523            }
390524          },
390525          "modelCard": {
390526            "modelParameters": {
390527              "approach": {}
390528            },
390529            "quantitativeAnalysis": {
390530              "graphics": {}
390531            },
390532            "considerations": {}
390533          }
390534        },
390535        {
390536          "type": "library",
390537          "bom-ref": "pkg:npm/cssesc@3.0.0?package-id=91a6a74efc4b88ba",
390538          "supplier": {},
390539          "author": "Mathias Bynens (https://mathiasbynens.be/)",
390540          "name": "cssesc",
390541          "version": "3.0.0",
390542          "description": "A JavaScript library for escaping CSS strings and identifiers while generating the shortest possible ASCII-only output.",
390543          "licenses": [
390544            {
390545              "license": {
390546                "id": "MIT"
390547              }
390548            }
390549          ],
390550          "cpe": "cpe:2.3:a:mathiasbynens:cssesc:3.0.0:*:*:*:*:*:*:*",
390551          "purl": "pkg:npm/cssesc@3.0.0",
390552          "swid": {
390553            "attachment": {}
390554          },
390555          "pedigree": {},
390556          "externalReferences": [
390557            {
390558              "url": "https://github.com/mathiasbynens/cssesc.git",
390559              "type": "distribution"
390560            },
390561            {
390562              "url": "https://mths.be/cssesc",
390563              "type": "website"
390564            }
390565          ],
390566          "evidence": {},
390567          "signature": {
390568            "signature": {
390569              "publicKey": {}
390570            }
390571          },
390572          "modelCard": {
390573            "modelParameters": {
390574              "approach": {}
390575            },
390576            "quantitativeAnalysis": {
390577              "graphics": {}
390578            },
390579            "considerations": {}
390580          }
390581        },
390582        {
390583          "type": "library",
390584          "bom-ref": "pkg:apk/alpine/curl@8.0.1-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=5916eff0b54ab2c0",
390585          "supplier": {},
390586          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
390587          "name": "curl",
390588          "version": "8.0.1-r0",
390589          "description": "URL retrival utility and library",
390590          "licenses": [
390591            {
390592              "license": {
390593                "id": "curl"
390594              }
390595            }
390596          ],
390597          "cpe": "cpe:2.3:a:curl:curl:8.0.1-r0:*:*:*:*:*:*:*",
390598          "purl": "pkg:apk/alpine/curl@8.0.1-r0?arch=x86_64\u0026distro=alpine-3.16.5",
390599          "swid": {
390600            "attachment": {}
390601          },
390602          "pedigree": {},
390603          "externalReferences": [
390604            {
390605              "url": "https://curl.se/",
390606              "type": "distribution"
390607            }
390608          ],
390609          "evidence": {},
390610          "signature": {
390611            "signature": {
390612              "publicKey": {}
390613            }
390614          },
390615          "modelCard": {
390616            "modelParameters": {
390617              "approach": {}
390618            },
390619            "quantitativeAnalysis": {
390620              "graphics": {}
390621            },
390622            "considerations": {}
390623          }
390624        },
390625        {
390626          "type": "library",
390627          "bom-ref": "pkg:npm/dashdash@1.14.1?package-id=a7ca4af6d828a5a2",
390628          "supplier": {},
390629          "author": "Trent Mick \u003ctrentm@gmail.com\u003e (http://trentm.com)",
390630          "name": "dashdash",
390631          "version": "1.14.1",
390632          "description": "A light, featureful and explicit option parsing library.",
390633          "licenses": [
390634            {
390635              "license": {
390636                "id": "MIT"
390637              }
390638            }
390639          ],
390640          "cpe": "cpe:2.3:a:dashdash:dashdash:1.14.1:*:*:*:*:*:*:*",
390641          "purl": "pkg:npm/dashdash@1.14.1",
390642          "swid": {
390643            "attachment": {}
390644          },
390645          "pedigree": {},
390646          "externalReferences": [
390647            {
390648              "url": "git://github.com/trentm/node-dashdash.git",
390649              "type": "distribution"
390650            }
390651          ],
390652          "evidence": {},
390653          "signature": {
390654            "signature": {
390655              "publicKey": {}
390656            }
390657          },
390658          "modelCard": {
390659            "modelParameters": {
390660              "approach": {}
390661            },
390662            "quantitativeAnalysis": {
390663              "graphics": {}
390664            },
390665            "considerations": {}
390666          }
390667        },
390668        {
390669          "type": "library",
390670          "bom-ref": "pkg:npm/debug@2.6.9?package-id=189dbf0c8c397194",
390671          "supplier": {},
390672          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
390673          "name": "debug",
390674          "version": "2.6.9",
390675          "description": "small debugging utility",
390676          "licenses": [
390677            {
390678              "license": {
390679                "id": "MIT"
390680              }
390681            }
390682          ],
390683          "cpe": "cpe:2.3:a:visionmedia:debug:2.6.9:*:*:*:*:*:*:*",
390684          "purl": "pkg:npm/debug@2.6.9",
390685          "swid": {
390686            "attachment": {}
390687          },
390688          "pedigree": {},
390689          "externalReferences": [
390690            {
390691              "url": "git://github.com/visionmedia/debug.git",
390692              "type": "distribution"
390693            }
390694          ],
390695          "evidence": {},
390696          "signature": {
390697            "signature": {
390698              "publicKey": {}
390699            }
390700          },
390701          "modelCard": {
390702            "modelParameters": {
390703              "approach": {}
390704            },
390705            "quantitativeAnalysis": {
390706              "graphics": {}
390707            },
390708            "considerations": {}
390709          }
390710        },
390711        {
390712          "type": "library",
390713          "bom-ref": "pkg:npm/debug@4.3.4?package-id=744fe4d31961f128",
390714          "supplier": {},
390715          "author": "Josh Junon \u003cjosh.junon@protonmail.com\u003e",
390716          "name": "debug",
390717          "version": "4.3.4",
390718          "description": "Lightweight debugging utility for Node.js and the browser",
390719          "licenses": [
390720            {
390721              "license": {
390722                "id": "MIT"
390723              }
390724            }
390725          ],
390726          "cpe": "cpe:2.3:a:debug-js:debug:4.3.4:*:*:*:*:*:*:*",
390727          "purl": "pkg:npm/debug@4.3.4",
390728          "swid": {
390729            "attachment": {}
390730          },
390731          "pedigree": {},
390732          "externalReferences": [
390733            {
390734              "url": "git://github.com/debug-js/debug.git",
390735              "type": "distribution"
390736            }
390737          ],
390738          "evidence": {},
390739          "signature": {
390740            "signature": {
390741              "publicKey": {}
390742            }
390743          },
390744          "modelCard": {
390745            "modelParameters": {
390746              "approach": {}
390747            },
390748            "quantitativeAnalysis": {
390749              "graphics": {}
390750            },
390751            "considerations": {}
390752          }
390753        },
390754        {
390755          "type": "library",
390756          "bom-ref": "pkg:npm/debuglog@1.0.1?package-id=de8cab91bb3727ee",
390757          "supplier": {},
390758          "author": "Sam Roberts \u003csam@strongloop.com\u003e",
390759          "name": "debuglog",
390760          "version": "1.0.1",
390761          "description": "backport of util.debuglog from node v0.11",
390762          "licenses": [
390763            {
390764              "license": {
390765                "id": "MIT"
390766              }
390767            }
390768          ],
390769          "cpe": "cpe:2.3:a:sam-github:debuglog:1.0.1:*:*:*:*:*:*:*",
390770          "purl": "pkg:npm/debuglog@1.0.1",
390771          "swid": {
390772            "attachment": {}
390773          },
390774          "pedigree": {},
390775          "externalReferences": [
390776            {
390777              "url": "https://github.com/sam-github/node-debuglog.git",
390778              "type": "distribution"
390779            }
390780          ],
390781          "evidence": {},
390782          "signature": {
390783            "signature": {
390784              "publicKey": {}
390785            }
390786          },
390787          "modelCard": {
390788            "modelParameters": {
390789              "approach": {}
390790            },
390791            "quantitativeAnalysis": {
390792              "graphics": {}
390793            },
390794            "considerations": {}
390795          }
390796        },
390797        {
390798          "type": "library",
390799          "bom-ref": "pkg:npm/decode-uri-component@0.2.2?package-id=31befa3a8dff8fe1",
390800          "supplier": {},
390801          "author": "Sam Verschueren \u003csam.verschueren@gmail.com\u003e (github.com/SamVerschueren)",
390802          "name": "decode-uri-component",
390803          "version": "0.2.2",
390804          "description": "A better decodeURIComponent",
390805          "licenses": [
390806            {
390807              "license": {
390808                "id": "MIT"
390809              }
390810            }
390811          ],
390812          "cpe": "cpe:2.3:a:decode-uri-component:decode-uri-component:0.2.2:*:*:*:*:*:*:*",
390813          "purl": "pkg:npm/decode-uri-component@0.2.2",
390814          "swid": {
390815            "attachment": {}
390816          },
390817          "pedigree": {},
390818          "externalReferences": [
390819            {
390820              "url": "SamVerschueren/decode-uri-component",
390821              "type": "distribution"
390822            }
390823          ],
390824          "evidence": {},
390825          "signature": {
390826            "signature": {
390827              "publicKey": {}
390828            }
390829          },
390830          "modelCard": {
390831            "modelParameters": {
390832              "approach": {}
390833            },
390834            "quantitativeAnalysis": {
390835              "graphics": {}
390836            },
390837            "considerations": {}
390838          }
390839        },
390840        {
390841          "type": "library",
390842          "bom-ref": "pkg:npm/decompress@4.2.1?package-id=d0958110c3225b86",
390843          "supplier": {},
390844          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
390845          "name": "decompress",
390846          "version": "4.2.1",
390847          "description": "Extracting archives made easy",
390848          "licenses": [
390849            {
390850              "license": {
390851                "id": "MIT"
390852              }
390853            }
390854          ],
390855          "cpe": "cpe:2.3:a:decompress:decompress:4.2.1:*:*:*:*:*:*:*",
390856          "purl": "pkg:npm/decompress@4.2.1",
390857          "swid": {
390858            "attachment": {}
390859          },
390860          "pedigree": {},
390861          "externalReferences": [
390862            {
390863              "url": "kevva/decompress",
390864              "type": "distribution"
390865            }
390866          ],
390867          "evidence": {},
390868          "signature": {
390869            "signature": {
390870              "publicKey": {}
390871            }
390872          },
390873          "modelCard": {
390874            "modelParameters": {
390875              "approach": {}
390876            },
390877            "quantitativeAnalysis": {
390878              "graphics": {}
390879            },
390880            "considerations": {}
390881          }
390882        },
390883        {
390884          "type": "library",
390885          "bom-ref": "pkg:npm/decompress-response@3.3.0?package-id=ff910650edaa3dd3",
390886          "supplier": {},
390887          "name": "decompress-response",
390888          "version": "3.3.0",
390889          "description": "Decompress a HTTP response if needed",
390890          "licenses": [
390891            {
390892              "license": {
390893                "id": "MIT"
390894              }
390895            }
390896          ],
390897          "cpe": "cpe:2.3:a:decompress-response:decompress-response:3.3.0:*:*:*:*:*:*:*",
390898          "purl": "pkg:npm/decompress-response@3.3.0",
390899          "swid": {
390900            "attachment": {}
390901          },
390902          "pedigree": {},
390903          "externalReferences": [
390904            {
390905              "url": "sindresorhus/decompress-response",
390906              "type": "distribution"
390907            }
390908          ],
390909          "evidence": {},
390910          "signature": {
390911            "signature": {
390912              "publicKey": {}
390913            }
390914          },
390915          "modelCard": {
390916            "modelParameters": {
390917              "approach": {}
390918            },
390919            "quantitativeAnalysis": {
390920              "graphics": {}
390921            },
390922            "considerations": {}
390923          }
390924        },
390925        {
390926          "type": "library",
390927          "bom-ref": "pkg:npm/decompress-response@6.0.0?package-id=2de2ede0cf6bda05",
390928          "supplier": {},
390929          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
390930          "name": "decompress-response",
390931          "version": "6.0.0",
390932          "description": "Decompress a HTTP response if needed",
390933          "licenses": [
390934            {
390935              "license": {
390936                "id": "MIT"
390937              }
390938            }
390939          ],
390940          "cpe": "cpe:2.3:a:decompress-response:decompress-response:6.0.0:*:*:*:*:*:*:*",
390941          "purl": "pkg:npm/decompress-response@6.0.0",
390942          "swid": {
390943            "attachment": {}
390944          },
390945          "pedigree": {},
390946          "externalReferences": [
390947            {
390948              "url": "sindresorhus/decompress-response",
390949              "type": "distribution"
390950            }
390951          ],
390952          "evidence": {},
390953          "signature": {
390954            "signature": {
390955              "publicKey": {}
390956            }
390957          },
390958          "modelCard": {
390959            "modelParameters": {
390960              "approach": {}
390961            },
390962            "quantitativeAnalysis": {
390963              "graphics": {}
390964            },
390965            "considerations": {}
390966          }
390967        },
390968        {
390969          "type": "library",
390970          "bom-ref": "pkg:npm/decompress-tar@4.1.1?package-id=2b8890e1066f856",
390971          "supplier": {},
390972          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (https://github.com/kevva)",
390973          "name": "decompress-tar",
390974          "version": "4.1.1",
390975          "description": "decompress tar plugin",
390976          "licenses": [
390977            {
390978              "license": {
390979                "id": "MIT"
390980              }
390981            }
390982          ],
390983          "cpe": "cpe:2.3:a:decompress-tar:decompress-tar:4.1.1:*:*:*:*:*:*:*",
390984          "purl": "pkg:npm/decompress-tar@4.1.1",
390985          "swid": {
390986            "attachment": {}
390987          },
390988          "pedigree": {},
390989          "externalReferences": [
390990            {
390991              "url": "kevva/decompress-tar",
390992              "type": "distribution"
390993            }
390994          ],
390995          "evidence": {},
390996          "signature": {
390997            "signature": {
390998              "publicKey": {}
390999            }
391000          },
391001          "modelCard": {
391002            "modelParameters": {
391003              "approach": {}
391004            },
391005            "quantitativeAnalysis": {
391006              "graphics": {}
391007            },
391008            "considerations": {}
391009          }
391010        },
391011        {
391012          "type": "library",
391013          "bom-ref": "pkg:npm/decompress-tarbz2@4.1.1?package-id=b939f8d9c45915a4",
391014          "supplier": {},
391015          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
391016          "name": "decompress-tarbz2",
391017          "version": "4.1.1",
391018          "description": "decompress tar.bz2 plugin",
391019          "licenses": [
391020            {
391021              "license": {
391022                "id": "MIT"
391023              }
391024            }
391025          ],
391026          "cpe": "cpe:2.3:a:decompress-tarbz2:decompress-tarbz2:4.1.1:*:*:*:*:*:*:*",
391027          "purl": "pkg:npm/decompress-tarbz2@4.1.1",
391028          "swid": {
391029            "attachment": {}
391030          },
391031          "pedigree": {},
391032          "externalReferences": [
391033            {
391034              "url": "kevva/decompress-tarbz2",
391035              "type": "distribution"
391036            }
391037          ],
391038          "evidence": {},
391039          "signature": {
391040            "signature": {
391041              "publicKey": {}
391042            }
391043          },
391044          "modelCard": {
391045            "modelParameters": {
391046              "approach": {}
391047            },
391048            "quantitativeAnalysis": {
391049              "graphics": {}
391050            },
391051            "considerations": {}
391052          }
391053        },
391054        {
391055          "type": "library",
391056          "bom-ref": "pkg:npm/decompress-targz@4.1.1?package-id=fd34f4cac43c4d7b",
391057          "supplier": {},
391058          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (https://github.com/kevva)",
391059          "name": "decompress-targz",
391060          "version": "4.1.1",
391061          "description": "decompress tar.gz plugin",
391062          "licenses": [
391063            {
391064              "license": {
391065                "id": "MIT"
391066              }
391067            }
391068          ],
391069          "cpe": "cpe:2.3:a:decompress-targz:decompress-targz:4.1.1:*:*:*:*:*:*:*",
391070          "purl": "pkg:npm/decompress-targz@4.1.1",
391071          "swid": {
391072            "attachment": {}
391073          },
391074          "pedigree": {},
391075          "externalReferences": [
391076            {
391077              "url": "kevva/decompress-targz",
391078              "type": "distribution"
391079            }
391080          ],
391081          "evidence": {},
391082          "signature": {
391083            "signature": {
391084              "publicKey": {}
391085            }
391086          },
391087          "modelCard": {
391088            "modelParameters": {
391089              "approach": {}
391090            },
391091            "quantitativeAnalysis": {
391092              "graphics": {}
391093            },
391094            "considerations": {}
391095          }
391096        },
391097        {
391098          "type": "library",
391099          "bom-ref": "pkg:npm/decompress-unzip@4.0.1?package-id=7880ad00b59e9b5d",
391100          "supplier": {},
391101          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (https://github.com/kevva)",
391102          "name": "decompress-unzip",
391103          "version": "4.0.1",
391104          "description": "decompress zip plugin",
391105          "licenses": [
391106            {
391107              "license": {
391108                "id": "MIT"
391109              }
391110            }
391111          ],
391112          "cpe": "cpe:2.3:a:decompress-unzip:decompress-unzip:4.0.1:*:*:*:*:*:*:*",
391113          "purl": "pkg:npm/decompress-unzip@4.0.1",
391114          "swid": {
391115            "attachment": {}
391116          },
391117          "pedigree": {},
391118          "externalReferences": [
391119            {
391120              "url": "kevva/decompress-unzip",
391121              "type": "distribution"
391122            }
391123          ],
391124          "evidence": {},
391125          "signature": {
391126            "signature": {
391127              "publicKey": {}
391128            }
391129          },
391130          "modelCard": {
391131            "modelParameters": {
391132              "approach": {}
391133            },
391134            "quantitativeAnalysis": {
391135              "graphics": {}
391136            },
391137            "considerations": {}
391138          }
391139        },
391140        {
391141          "type": "library",
391142          "bom-ref": "pkg:npm/defaults@1.0.3?package-id=539a687773af61fe",
391143          "supplier": {},
391144          "author": "Elijah Insua \u003ctmpvar@gmail.com\u003e",
391145          "name": "defaults",
391146          "version": "1.0.3",
391147          "description": "merge single level defaults over a config object",
391148          "licenses": [
391149            {
391150              "license": {
391151                "id": "MIT"
391152              }
391153            }
391154          ],
391155          "cpe": "cpe:2.3:a:defaults:defaults:1.0.3:*:*:*:*:*:*:*",
391156          "purl": "pkg:npm/defaults@1.0.3",
391157          "swid": {
391158            "attachment": {}
391159          },
391160          "pedigree": {},
391161          "externalReferences": [
391162            {
391163              "url": "git://github.com/tmpvar/defaults.git",
391164              "type": "distribution"
391165            }
391166          ],
391167          "evidence": {},
391168          "signature": {
391169            "signature": {
391170              "publicKey": {}
391171            }
391172          },
391173          "modelCard": {
391174            "modelParameters": {
391175              "approach": {}
391176            },
391177            "quantitativeAnalysis": {
391178              "graphics": {}
391179            },
391180            "considerations": {}
391181          }
391182        },
391183        {
391184          "type": "library",
391185          "bom-ref": "pkg:npm/defaults@1.0.4?package-id=a752e235517d6a48",
391186          "supplier": {},
391187          "author": "Elijah Insua \u003ctmpvar@gmail.com\u003e",
391188          "name": "defaults",
391189          "version": "1.0.4",
391190          "description": "merge single level defaults over a config object",
391191          "licenses": [
391192            {
391193              "license": {
391194                "id": "MIT"
391195              }
391196            }
391197          ],
391198          "cpe": "cpe:2.3:a:sindresorhus:defaults:1.0.4:*:*:*:*:*:*:*",
391199          "purl": "pkg:npm/defaults@1.0.4",
391200          "swid": {
391201            "attachment": {}
391202          },
391203          "pedigree": {},
391204          "externalReferences": [
391205            {
391206              "url": "git://github.com/sindresorhus/node-defaults.git",
391207              "type": "distribution"
391208            }
391209          ],
391210          "evidence": {},
391211          "signature": {
391212            "signature": {
391213              "publicKey": {}
391214            }
391215          },
391216          "modelCard": {
391217            "modelParameters": {
391218              "approach": {}
391219            },
391220            "quantitativeAnalysis": {
391221              "graphics": {}
391222            },
391223            "considerations": {}
391224          }
391225        },
391226        {
391227          "type": "library",
391228          "bom-ref": "pkg:npm/defer-to-connect@2.0.1?package-id=8891136e6f9a7c93",
391229          "supplier": {},
391230          "author": "Szymon Marczak",
391231          "name": "defer-to-connect",
391232          "version": "2.0.1",
391233          "description": "The safe way to handle the `connect` socket event",
391234          "licenses": [
391235            {
391236              "license": {
391237                "id": "MIT"
391238              }
391239            }
391240          ],
391241          "cpe": "cpe:2.3:a:defer-to-connect:defer-to-connect:2.0.1:*:*:*:*:*:*:*",
391242          "purl": "pkg:npm/defer-to-connect@2.0.1",
391243          "swid": {
391244            "attachment": {}
391245          },
391246          "pedigree": {},
391247          "externalReferences": [
391248            {
391249              "url": "git+https://github.com/szmarczak/defer-to-connect.git",
391250              "type": "distribution"
391251            },
391252            {
391253              "url": "https://github.com/szmarczak/defer-to-connect#readme",
391254              "type": "website"
391255            }
391256          ],
391257          "evidence": {},
391258          "signature": {
391259            "signature": {
391260              "publicKey": {}
391261            }
391262          },
391263          "modelCard": {
391264            "modelParameters": {
391265              "approach": {}
391266            },
391267            "quantitativeAnalysis": {
391268              "graphics": {}
391269            },
391270            "considerations": {}
391271          }
391272        },
391273        {
391274          "type": "library",
391275          "bom-ref": "pkg:npm/delayed-stream@1.0.0?package-id=2e87a018d352ff35",
391276          "supplier": {},
391277          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
391278          "name": "delayed-stream",
391279          "version": "1.0.0",
391280          "description": "Buffers events from a stream until you are ready to handle them.",
391281          "licenses": [
391282            {
391283              "license": {
391284                "id": "MIT"
391285              }
391286            }
391287          ],
391288          "cpe": "cpe:2.3:a:delayed-stream:delayed-stream:1.0.0:*:*:*:*:*:*:*",
391289          "purl": "pkg:npm/delayed-stream@1.0.0",
391290          "swid": {
391291            "attachment": {}
391292          },
391293          "pedigree": {},
391294          "externalReferences": [
391295            {
391296              "url": "git://github.com/felixge/node-delayed-stream.git",
391297              "type": "distribution"
391298            },
391299            {
391300              "url": "https://github.com/felixge/node-delayed-stream",
391301              "type": "website"
391302            }
391303          ],
391304          "evidence": {},
391305          "signature": {
391306            "signature": {
391307              "publicKey": {}
391308            }
391309          },
391310          "modelCard": {
391311            "modelParameters": {
391312              "approach": {}
391313            },
391314            "quantitativeAnalysis": {
391315              "graphics": {}
391316            },
391317            "considerations": {}
391318          }
391319        },
391320        {
391321          "type": "library",
391322          "bom-ref": "pkg:npm/delegates@1.0.0?package-id=ed0c22d60c260f5c",
391323          "supplier": {},
391324          "name": "delegates",
391325          "version": "1.0.0",
391326          "description": "delegate methods and accessors to another property",
391327          "licenses": [
391328            {
391329              "license": {
391330                "id": "MIT"
391331              }
391332            }
391333          ],
391334          "cpe": "cpe:2.3:a:delegates:delegates:1.0.0:*:*:*:*:*:*:*",
391335          "purl": "pkg:npm/delegates@1.0.0",
391336          "swid": {
391337            "attachment": {}
391338          },
391339          "pedigree": {},
391340          "externalReferences": [
391341            {
391342              "url": "visionmedia/node-delegates",
391343              "type": "distribution"
391344            }
391345          ],
391346          "evidence": {},
391347          "signature": {
391348            "signature": {
391349              "publicKey": {}
391350            }
391351          },
391352          "modelCard": {
391353            "modelParameters": {
391354              "approach": {}
391355            },
391356            "quantitativeAnalysis": {
391357              "graphics": {}
391358            },
391359            "considerations": {}
391360          }
391361        },
391362        {
391363          "type": "library",
391364          "bom-ref": "pkg:npm/depd@1.1.2?package-id=8f51ca0c72f74b81",
391365          "supplier": {},
391366          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
391367          "name": "depd",
391368          "version": "1.1.2",
391369          "description": "Deprecate all the things",
391370          "licenses": [
391371            {
391372              "license": {
391373                "id": "MIT"
391374              }
391375            }
391376          ],
391377          "cpe": "cpe:2.3:a:depd:depd:1.1.2:*:*:*:*:*:*:*",
391378          "purl": "pkg:npm/depd@1.1.2",
391379          "swid": {
391380            "attachment": {}
391381          },
391382          "pedigree": {},
391383          "externalReferences": [
391384            {
391385              "url": "dougwilson/nodejs-depd",
391386              "type": "distribution"
391387            }
391388          ],
391389          "evidence": {},
391390          "signature": {
391391            "signature": {
391392              "publicKey": {}
391393            }
391394          },
391395          "modelCard": {
391396            "modelParameters": {
391397              "approach": {}
391398            },
391399            "quantitativeAnalysis": {
391400              "graphics": {}
391401            },
391402            "considerations": {}
391403          }
391404        },
391405        {
391406          "type": "library",
391407          "bom-ref": "pkg:npm/depd@1.1.2?package-id=88f59320de2b0d4a",
391408          "supplier": {},
391409          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
391410          "name": "depd",
391411          "version": "1.1.2",
391412          "description": "Deprecate all the things",
391413          "licenses": [
391414            {
391415              "license": {
391416                "id": "MIT"
391417              }
391418            }
391419          ],
391420          "cpe": "cpe:2.3:a:depd:depd:1.1.2:*:*:*:*:*:*:*",
391421          "purl": "pkg:npm/depd@1.1.2",
391422          "swid": {
391423            "attachment": {}
391424          },
391425          "pedigree": {},
391426          "externalReferences": [
391427            {
391428              "url": "dougwilson/nodejs-depd",
391429              "type": "distribution"
391430            }
391431          ],
391432          "evidence": {},
391433          "signature": {
391434            "signature": {
391435              "publicKey": {}
391436            }
391437          },
391438          "modelCard": {
391439            "modelParameters": {
391440              "approach": {}
391441            },
391442            "quantitativeAnalysis": {
391443              "graphics": {}
391444            },
391445            "considerations": {}
391446          }
391447        },
391448        {
391449          "type": "library",
391450          "bom-ref": "pkg:npm/destroy@1.0.4?package-id=7a46d2c188b90042",
391451          "supplier": {},
391452          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
391453          "name": "destroy",
391454          "version": "1.0.4",
391455          "description": "destroy a stream if possible",
391456          "licenses": [
391457            {
391458              "license": {
391459                "id": "MIT"
391460              }
391461            }
391462          ],
391463          "cpe": "cpe:2.3:a:destroy:destroy:1.0.4:*:*:*:*:*:*:*",
391464          "purl": "pkg:npm/destroy@1.0.4",
391465          "swid": {
391466            "attachment": {}
391467          },
391468          "pedigree": {},
391469          "externalReferences": [
391470            {
391471              "url": "stream-utils/destroy",
391472              "type": "distribution"
391473            }
391474          ],
391475          "evidence": {},
391476          "signature": {
391477            "signature": {
391478              "publicKey": {}
391479            }
391480          },
391481          "modelCard": {
391482            "modelParameters": {
391483              "approach": {}
391484            },
391485            "quantitativeAnalysis": {
391486              "graphics": {}
391487            },
391488            "considerations": {}
391489          }
391490        },
391491        {
391492          "type": "library",
391493          "bom-ref": "pkg:npm/dezalgo@1.0.4?package-id=d8ccca0e738815bf",
391494          "supplier": {},
391495          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
391496          "name": "dezalgo",
391497          "version": "1.0.4",
391498          "description": "Contain async insanity so that the dark pony lord doesn't eat souls",
391499          "licenses": [
391500            {
391501              "license": {
391502                "id": "ISC"
391503              }
391504            }
391505          ],
391506          "cpe": "cpe:2.3:a:dezalgo:dezalgo:1.0.4:*:*:*:*:*:*:*",
391507          "purl": "pkg:npm/dezalgo@1.0.4",
391508          "swid": {
391509            "attachment": {}
391510          },
391511          "pedigree": {},
391512          "externalReferences": [
391513            {
391514              "url": "https://github.com/npm/dezalgo",
391515              "type": "distribution"
391516            },
391517            {
391518              "url": "https://github.com/npm/dezalgo",
391519              "type": "website"
391520            }
391521          ],
391522          "evidence": {},
391523          "signature": {
391524            "signature": {
391525              "publicKey": {}
391526            }
391527          },
391528          "modelCard": {
391529            "modelParameters": {
391530              "approach": {}
391531            },
391532            "quantitativeAnalysis": {
391533              "graphics": {}
391534            },
391535            "considerations": {}
391536          }
391537        },
391538        {
391539          "type": "library",
391540          "bom-ref": "pkg:npm/diff@5.1.0?package-id=d6e2c2128602c71d",
391541          "supplier": {},
391542          "name": "diff",
391543          "version": "5.1.0",
391544          "description": "A javascript text diff implementation.",
391545          "licenses": [
391546            {
391547              "license": {
391548                "id": "BSD-3-Clause"
391549              }
391550            }
391551          ],
391552          "cpe": "cpe:2.3:a:kpdecker:diff:5.1.0:*:*:*:*:*:*:*",
391553          "purl": "pkg:npm/diff@5.1.0",
391554          "swid": {
391555            "attachment": {}
391556          },
391557          "pedigree": {},
391558          "externalReferences": [
391559            {
391560              "url": "git://github.com/kpdecker/jsdiff.git",
391561              "type": "distribution"
391562            }
391563          ],
391564          "evidence": {},
391565          "signature": {
391566            "signature": {
391567              "publicKey": {}
391568            }
391569          },
391570          "modelCard": {
391571            "modelParameters": {
391572              "approach": {}
391573            },
391574            "quantitativeAnalysis": {
391575              "graphics": {}
391576            },
391577            "considerations": {}
391578          }
391579        },
391580        {
391581          "type": "library",
391582          "bom-ref": "pkg:npm/dir-glob@3.0.1?package-id=9ab743722f0ea12d",
391583          "supplier": {},
391584          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
391585          "name": "dir-glob",
391586          "version": "3.0.1",
391587          "description": "Convert directories to glob compatible strings",
391588          "licenses": [
391589            {
391590              "license": {
391591                "id": "MIT"
391592              }
391593            }
391594          ],
391595          "cpe": "cpe:2.3:a:dir-glob:dir-glob:3.0.1:*:*:*:*:*:*:*",
391596          "purl": "pkg:npm/dir-glob@3.0.1",
391597          "swid": {
391598            "attachment": {}
391599          },
391600          "pedigree": {},
391601          "externalReferences": [
391602            {
391603              "url": "kevva/dir-glob",
391604              "type": "distribution"
391605            }
391606          ],
391607          "evidence": {},
391608          "signature": {
391609            "signature": {
391610              "publicKey": {}
391611            }
391612          },
391613          "modelCard": {
391614            "modelParameters": {
391615              "approach": {}
391616            },
391617            "quantitativeAnalysis": {
391618              "graphics": {}
391619            },
391620            "considerations": {}
391621          }
391622        },
391623        {
391624          "type": "library",
391625          "bom-ref": "pkg:npm/download@8.0.0?package-id=ac2f97493c09cf0c",
391626          "supplier": {},
391627          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
391628          "name": "download",
391629          "version": "8.0.0",
391630          "description": "Download and extract files",
391631          "licenses": [
391632            {
391633              "license": {
391634                "id": "MIT"
391635              }
391636            }
391637          ],
391638          "cpe": "cpe:2.3:a:download:download:8.0.0:*:*:*:*:*:*:*",
391639          "purl": "pkg:npm/download@8.0.0",
391640          "swid": {
391641            "attachment": {}
391642          },
391643          "pedigree": {},
391644          "externalReferences": [
391645            {
391646              "url": "kevva/download",
391647              "type": "distribution"
391648            }
391649          ],
391650          "evidence": {},
391651          "signature": {
391652            "signature": {
391653              "publicKey": {}
391654            }
391655          },
391656          "modelCard": {
391657            "modelParameters": {
391658              "approach": {}
391659            },
391660            "quantitativeAnalysis": {
391661              "graphics": {}
391662            },
391663            "considerations": {}
391664          }
391665        },
391666        {
391667          "type": "library",
391668          "bom-ref": "pkg:npm/duplexer3@0.1.5?package-id=6c836d527a4c863a",
391669          "supplier": {},
391670          "name": "duplexer3",
391671          "version": "0.1.5",
391672          "description": "Like duplexer but using streams3",
391673          "licenses": [
391674            {
391675              "license": {
391676                "id": "BSD-3-Clause"
391677              }
391678            }
391679          ],
391680          "cpe": "cpe:2.3:a:duplexer3:duplexer3:0.1.5:*:*:*:*:*:*:*",
391681          "purl": "pkg:npm/duplexer3@0.1.5",
391682          "swid": {
391683            "attachment": {}
391684          },
391685          "pedigree": {},
391686          "externalReferences": [
391687            {
391688              "url": "sindresorhus/duplexer3",
391689              "type": "distribution"
391690            }
391691          ],
391692          "evidence": {},
391693          "signature": {
391694            "signature": {
391695              "publicKey": {}
391696            }
391697          },
391698          "modelCard": {
391699            "modelParameters": {
391700              "approach": {}
391701            },
391702            "quantitativeAnalysis": {
391703              "graphics": {}
391704            },
391705            "considerations": {}
391706          }
391707        },
391708        {
391709          "type": "library",
391710          "bom-ref": "pkg:npm/ecc-jsbn@0.1.2?package-id=281a10dc51f85ca9",
391711          "supplier": {},
391712          "author": "Jeremie Miller \u003cjeremie@jabber.org\u003e (http://jeremie.com/)",
391713          "name": "ecc-jsbn",
391714          "version": "0.1.2",
391715          "description": "ECC JS code based on JSBN",
391716          "licenses": [
391717            {
391718              "license": {
391719                "id": "MIT"
391720              }
391721            }
391722          ],
391723          "cpe": "cpe:2.3:a:quartzjer:ecc-jsbn:0.1.2:*:*:*:*:*:*:*",
391724          "purl": "pkg:npm/ecc-jsbn@0.1.2",
391725          "swid": {
391726            "attachment": {}
391727          },
391728          "pedigree": {},
391729          "externalReferences": [
391730            {
391731              "url": "https://github.com/quartzjer/ecc-jsbn.git",
391732              "type": "distribution"
391733            },
391734            {
391735              "url": "https://github.com/quartzjer/ecc-jsbn",
391736              "type": "website"
391737            }
391738          ],
391739          "evidence": {},
391740          "signature": {
391741            "signature": {
391742              "publicKey": {}
391743            }
391744          },
391745          "modelCard": {
391746            "modelParameters": {
391747              "approach": {}
391748            },
391749            "quantitativeAnalysis": {
391750              "graphics": {}
391751            },
391752            "considerations": {}
391753          }
391754        },
391755        {
391756          "type": "library",
391757          "bom-ref": "pkg:npm/ee-first@1.1.1?package-id=e237c873e14ffd47",
391758          "supplier": {},
391759          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
391760          "name": "ee-first",
391761          "version": "1.1.1",
391762          "description": "return the first event in a set of ee/event pairs",
391763          "licenses": [
391764            {
391765              "license": {
391766                "id": "MIT"
391767              }
391768            }
391769          ],
391770          "cpe": "cpe:2.3:a:ee-first:ee-first:1.1.1:*:*:*:*:*:*:*",
391771          "purl": "pkg:npm/ee-first@1.1.1",
391772          "swid": {
391773            "attachment": {}
391774          },
391775          "pedigree": {},
391776          "externalReferences": [
391777            {
391778              "url": "jonathanong/ee-first",
391779              "type": "distribution"
391780            }
391781          ],
391782          "evidence": {},
391783          "signature": {
391784            "signature": {
391785              "publicKey": {}
391786            }
391787          },
391788          "modelCard": {
391789            "modelParameters": {
391790              "approach": {}
391791            },
391792            "quantitativeAnalysis": {
391793              "graphics": {}
391794            },
391795            "considerations": {}
391796          }
391797        },
391798        {
391799          "type": "library",
391800          "bom-ref": "pkg:npm/emoji-regex@8.0.0?package-id=6bb38678688ed46f",
391801          "supplier": {},
391802          "author": "Mathias Bynens (https://mathiasbynens.be/)",
391803          "name": "emoji-regex",
391804          "version": "8.0.0",
391805          "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",
391806          "licenses": [
391807            {
391808              "license": {
391809                "id": "MIT"
391810              }
391811            }
391812          ],
391813          "cpe": "cpe:2.3:a:mathiasbynens:emoji-regex:8.0.0:*:*:*:*:*:*:*",
391814          "purl": "pkg:npm/emoji-regex@8.0.0",
391815          "swid": {
391816            "attachment": {}
391817          },
391818          "pedigree": {},
391819          "externalReferences": [
391820            {
391821              "url": "https://github.com/mathiasbynens/emoji-regex.git",
391822              "type": "distribution"
391823            },
391824            {
391825              "url": "https://mths.be/emoji-regex",
391826              "type": "website"
391827            }
391828          ],
391829          "evidence": {},
391830          "signature": {
391831            "signature": {
391832              "publicKey": {}
391833            }
391834          },
391835          "modelCard": {
391836            "modelParameters": {
391837              "approach": {}
391838            },
391839            "quantitativeAnalysis": {
391840              "graphics": {}
391841            },
391842            "considerations": {}
391843          }
391844        },
391845        {
391846          "type": "library",
391847          "bom-ref": "pkg:npm/encodeurl@1.0.2?package-id=ca5122f9d292a60f",
391848          "supplier": {},
391849          "name": "encodeurl",
391850          "version": "1.0.2",
391851          "description": "Encode a URL to a percent-encoded form, excluding already-encoded sequences",
391852          "licenses": [
391853            {
391854              "license": {
391855                "id": "MIT"
391856              }
391857            }
391858          ],
391859          "cpe": "cpe:2.3:a:encodeurl:encodeurl:1.0.2:*:*:*:*:*:*:*",
391860          "purl": "pkg:npm/encodeurl@1.0.2",
391861          "swid": {
391862            "attachment": {}
391863          },
391864          "pedigree": {},
391865          "externalReferences": [
391866            {
391867              "url": "pillarjs/encodeurl",
391868              "type": "distribution"
391869            }
391870          ],
391871          "evidence": {},
391872          "signature": {
391873            "signature": {
391874              "publicKey": {}
391875            }
391876          },
391877          "modelCard": {
391878            "modelParameters": {
391879              "approach": {}
391880            },
391881            "quantitativeAnalysis": {
391882              "graphics": {}
391883            },
391884            "considerations": {}
391885          }
391886        },
391887        {
391888          "type": "library",
391889          "bom-ref": "pkg:npm/encoding@0.1.13?package-id=e65b6a429cd40212",
391890          "supplier": {},
391891          "author": "Andris Reinman",
391892          "name": "encoding",
391893          "version": "0.1.13",
391894          "description": "Convert encodings, uses iconv-lite",
391895          "licenses": [
391896            {
391897              "license": {
391898                "id": "MIT"
391899              }
391900            }
391901          ],
391902          "cpe": "cpe:2.3:a:encoding:encoding:0.1.13:*:*:*:*:*:*:*",
391903          "purl": "pkg:npm/encoding@0.1.13",
391904          "swid": {
391905            "attachment": {}
391906          },
391907          "pedigree": {},
391908          "externalReferences": [
391909            {
391910              "url": "https://github.com/andris9/encoding.git",
391911              "type": "distribution"
391912            }
391913          ],
391914          "evidence": {},
391915          "signature": {
391916            "signature": {
391917              "publicKey": {}
391918            }
391919          },
391920          "modelCard": {
391921            "modelParameters": {
391922              "approach": {}
391923            },
391924            "quantitativeAnalysis": {
391925              "graphics": {}
391926            },
391927            "considerations": {}
391928          }
391929        },
391930        {
391931          "type": "library",
391932          "bom-ref": "pkg:npm/end-of-stream@1.4.4?package-id=476be126dfa49e1",
391933          "supplier": {},
391934          "author": "Mathias Buus \u003cmathiasbuus@gmail.com\u003e",
391935          "name": "end-of-stream",
391936          "version": "1.4.4",
391937          "description": "Call a callback when a readable/writable/duplex stream has completed or failed.",
391938          "licenses": [
391939            {
391940              "license": {
391941                "id": "MIT"
391942              }
391943            }
391944          ],
391945          "cpe": "cpe:2.3:a:end-of-stream:end-of-stream:1.4.4:*:*:*:*:*:*:*",
391946          "purl": "pkg:npm/end-of-stream@1.4.4",
391947          "swid": {
391948            "attachment": {}
391949          },
391950          "pedigree": {},
391951          "externalReferences": [
391952            {
391953              "url": "git://github.com/mafintosh/end-of-stream.git",
391954              "type": "distribution"
391955            },
391956            {
391957              "url": "https://github.com/mafintosh/end-of-stream",
391958              "type": "website"
391959            }
391960          ],
391961          "evidence": {},
391962          "signature": {
391963            "signature": {
391964              "publicKey": {}
391965            }
391966          },
391967          "modelCard": {
391968            "modelParameters": {
391969              "approach": {}
391970            },
391971            "quantitativeAnalysis": {
391972              "graphics": {}
391973            },
391974            "considerations": {}
391975          }
391976        },
391977        {
391978          "type": "library",
391979          "bom-ref": "pkg:npm/enhanced-resolve@5.13.0?package-id=e6ee62b9d186201c",
391980          "supplier": {},
391981          "author": "Tobias Koppers @sokra",
391982          "name": "enhanced-resolve",
391983          "version": "5.13.0",
391984          "description": "Offers a async require.resolve function. It's highly configurable.",
391985          "licenses": [
391986            {
391987              "license": {
391988                "id": "MIT"
391989              }
391990            }
391991          ],
391992          "cpe": "cpe:2.3:a:enhanced-resolve:enhanced-resolve:5.13.0:*:*:*:*:*:*:*",
391993          "purl": "pkg:npm/enhanced-resolve@5.13.0",
391994          "swid": {
391995            "attachment": {}
391996          },
391997          "pedigree": {},
391998          "externalReferences": [
391999            {
392000              "url": "git://github.com/webpack/enhanced-resolve.git",
392001              "type": "distribution"
392002            },
392003            {
392004              "url": "http://github.com/webpack/enhanced-resolve",
392005              "type": "website"
392006            }
392007          ],
392008          "evidence": {},
392009          "signature": {
392010            "signature": {
392011              "publicKey": {}
392012            }
392013          },
392014          "modelCard": {
392015            "modelParameters": {
392016              "approach": {}
392017            },
392018            "quantitativeAnalysis": {
392019              "graphics": {}
392020            },
392021            "considerations": {}
392022          }
392023        },
392024        {
392025          "type": "library",
392026          "bom-ref": "pkg:npm/env-paths@2.2.1?package-id=d14634fe75802cac",
392027          "supplier": {},
392028          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
392029          "name": "env-paths",
392030          "version": "2.2.1",
392031          "description": "Get paths for storing things like data, config, cache, etc",
392032          "licenses": [
392033            {
392034              "license": {
392035                "id": "MIT"
392036              }
392037            }
392038          ],
392039          "cpe": "cpe:2.3:a:env-paths:env-paths:2.2.1:*:*:*:*:*:*:*",
392040          "purl": "pkg:npm/env-paths@2.2.1",
392041          "swid": {
392042            "attachment": {}
392043          },
392044          "pedigree": {},
392045          "externalReferences": [
392046            {
392047              "url": "sindresorhus/env-paths",
392048              "type": "distribution"
392049            }
392050          ],
392051          "evidence": {},
392052          "signature": {
392053            "signature": {
392054              "publicKey": {}
392055            }
392056          },
392057          "modelCard": {
392058            "modelParameters": {
392059              "approach": {}
392060            },
392061            "quantitativeAnalysis": {
392062              "graphics": {}
392063            },
392064            "considerations": {}
392065          }
392066        },
392067        {
392068          "type": "library",
392069          "bom-ref": "pkg:npm/err-code@2.0.3?package-id=60b62094686938a4",
392070          "supplier": {},
392071          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
392072          "name": "err-code",
392073          "version": "2.0.3",
392074          "description": "Create an error with a code",
392075          "licenses": [
392076            {
392077              "license": {
392078                "id": "MIT"
392079              }
392080            }
392081          ],
392082          "cpe": "cpe:2.3:a:IndigoUnited:err-code:2.0.3:*:*:*:*:*:*:*",
392083          "purl": "pkg:npm/err-code@2.0.3",
392084          "swid": {
392085            "attachment": {}
392086          },
392087          "pedigree": {},
392088          "externalReferences": [
392089            {
392090              "url": "git://github.com/IndigoUnited/js-err-code.git",
392091              "type": "distribution"
392092            }
392093          ],
392094          "evidence": {},
392095          "signature": {
392096            "signature": {
392097              "publicKey": {}
392098            }
392099          },
392100          "modelCard": {
392101            "modelParameters": {
392102              "approach": {}
392103            },
392104            "quantitativeAnalysis": {
392105              "graphics": {}
392106            },
392107            "considerations": {}
392108          }
392109        },
392110        {
392111          "type": "library",
392112          "bom-ref": "pkg:npm/es6-error@4.1.1?package-id=816b6827010746b5",
392113          "supplier": {},
392114          "author": "Ben Youngblood",
392115          "name": "es6-error",
392116          "version": "4.1.1",
392117          "description": "Easily-extendable error for use with ES6 classes",
392118          "licenses": [
392119            {
392120              "license": {
392121                "id": "MIT"
392122              }
392123            }
392124          ],
392125          "cpe": "cpe:2.3:a:bjyoungblood:es6-error:4.1.1:*:*:*:*:*:*:*",
392126          "purl": "pkg:npm/es6-error@4.1.1",
392127          "swid": {
392128            "attachment": {}
392129          },
392130          "pedigree": {},
392131          "externalReferences": [
392132            {
392133              "url": "https://github.com/bjyoungblood/es6-error.git",
392134              "type": "distribution"
392135            },
392136            {
392137              "url": "https://github.com/bjyoungblood/es6-error",
392138              "type": "website"
392139            }
392140          ],
392141          "evidence": {},
392142          "signature": {
392143            "signature": {
392144              "publicKey": {}
392145            }
392146          },
392147          "modelCard": {
392148            "modelParameters": {
392149              "approach": {}
392150            },
392151            "quantitativeAnalysis": {
392152              "graphics": {}
392153            },
392154            "considerations": {}
392155          }
392156        },
392157        {
392158          "type": "library",
392159          "bom-ref": "pkg:npm/escape-html@1.0.3?package-id=29b06dd1d0ba635a",
392160          "supplier": {},
392161          "name": "escape-html",
392162          "version": "1.0.3",
392163          "description": "Escape string for use in HTML",
392164          "licenses": [
392165            {
392166              "license": {
392167                "id": "MIT"
392168              }
392169            }
392170          ],
392171          "cpe": "cpe:2.3:a:escape-html:escape-html:1.0.3:*:*:*:*:*:*:*",
392172          "purl": "pkg:npm/escape-html@1.0.3",
392173          "swid": {
392174            "attachment": {}
392175          },
392176          "pedigree": {},
392177          "externalReferences": [
392178            {
392179              "url": "component/escape-html",
392180              "type": "distribution"
392181            }
392182          ],
392183          "evidence": {},
392184          "signature": {
392185            "signature": {
392186              "publicKey": {}
392187            }
392188          },
392189          "modelCard": {
392190            "modelParameters": {
392191              "approach": {}
392192            },
392193            "quantitativeAnalysis": {
392194              "graphics": {}
392195            },
392196            "considerations": {}
392197          }
392198        },
392199        {
392200          "type": "library",
392201          "bom-ref": "pkg:npm/escape-string-regexp@1.0.5?package-id=25bd30cd97ed1bdf",
392202          "supplier": {},
392203          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
392204          "name": "escape-string-regexp",
392205          "version": "1.0.5",
392206          "description": "Escape RegExp special characters",
392207          "licenses": [
392208            {
392209              "license": {
392210                "id": "MIT"
392211              }
392212            }
392213          ],
392214          "cpe": "cpe:2.3:a:escape-string-regexp:escape-string-regexp:1.0.5:*:*:*:*:*:*:*",
392215          "purl": "pkg:npm/escape-string-regexp@1.0.5",
392216          "swid": {
392217            "attachment": {}
392218          },
392219          "pedigree": {},
392220          "externalReferences": [
392221            {
392222              "url": "sindresorhus/escape-string-regexp",
392223              "type": "distribution"
392224            }
392225          ],
392226          "evidence": {},
392227          "signature": {
392228            "signature": {
392229              "publicKey": {}
392230            }
392231          },
392232          "modelCard": {
392233            "modelParameters": {
392234              "approach": {}
392235            },
392236            "quantitativeAnalysis": {
392237              "graphics": {}
392238            },
392239            "considerations": {}
392240          }
392241        },
392242        {
392243          "type": "library",
392244          "bom-ref": "pkg:npm/etag@1.8.1?package-id=9151d174424b86ef",
392245          "supplier": {},
392246          "name": "etag",
392247          "version": "1.8.1",
392248          "description": "Create simple HTTP ETags",
392249          "licenses": [
392250            {
392251              "license": {
392252                "id": "MIT"
392253              }
392254            }
392255          ],
392256          "cpe": "cpe:2.3:a:etag:etag:1.8.1:*:*:*:*:*:*:*",
392257          "purl": "pkg:npm/etag@1.8.1",
392258          "swid": {
392259            "attachment": {}
392260          },
392261          "pedigree": {},
392262          "externalReferences": [
392263            {
392264              "url": "jshttp/etag",
392265              "type": "distribution"
392266            }
392267          ],
392268          "evidence": {},
392269          "signature": {
392270            "signature": {
392271              "publicKey": {}
392272            }
392273          },
392274          "modelCard": {
392275            "modelParameters": {
392276              "approach": {}
392277            },
392278            "quantitativeAnalysis": {
392279              "graphics": {}
392280            },
392281            "considerations": {}
392282          }
392283        },
392284        {
392285          "type": "library",
392286          "bom-ref": "pkg:npm/express@4.16.4?package-id=7d091d958d9b922e",
392287          "supplier": {},
392288          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
392289          "name": "express",
392290          "version": "4.16.4",
392291          "description": "Fast, unopinionated, minimalist web framework",
392292          "licenses": [
392293            {
392294              "license": {
392295                "id": "MIT"
392296              }
392297            }
392298          ],
392299          "cpe": "cpe:2.3:a:express:express:4.16.4:*:*:*:*:*:*:*",
392300          "purl": "pkg:npm/express@4.16.4",
392301          "swid": {
392302            "attachment": {}
392303          },
392304          "pedigree": {},
392305          "externalReferences": [
392306            {
392307              "url": "expressjs/express",
392308              "type": "distribution"
392309            },
392310            {
392311              "url": "http://expressjs.com/",
392312              "type": "website"
392313            }
392314          ],
392315          "evidence": {},
392316          "signature": {
392317            "signature": {
392318              "publicKey": {}
392319            }
392320          },
392321          "modelCard": {
392322            "modelParameters": {
392323              "approach": {}
392324            },
392325            "quantitativeAnalysis": {
392326              "graphics": {}
392327            },
392328            "considerations": {}
392329          }
392330        },
392331        {
392332          "type": "library",
392333          "bom-ref": "pkg:npm/ext-list@2.2.2?package-id=b33c0440e50879f6",
392334          "supplier": {},
392335          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (https://github.com/kevva)",
392336          "name": "ext-list",
392337          "version": "2.2.2",
392338          "description": "List of known file extensions and their MIME types",
392339          "licenses": [
392340            {
392341              "license": {
392342                "id": "MIT"
392343              }
392344            }
392345          ],
392346          "cpe": "cpe:2.3:a:ext-list:ext-list:2.2.2:*:*:*:*:*:*:*",
392347          "purl": "pkg:npm/ext-list@2.2.2",
392348          "swid": {
392349            "attachment": {}
392350          },
392351          "pedigree": {},
392352          "externalReferences": [
392353            {
392354              "url": "kevva/ext-list",
392355              "type": "distribution"
392356            }
392357          ],
392358          "evidence": {},
392359          "signature": {
392360            "signature": {
392361              "publicKey": {}
392362            }
392363          },
392364          "modelCard": {
392365            "modelParameters": {
392366              "approach": {}
392367            },
392368            "quantitativeAnalysis": {
392369              "graphics": {}
392370            },
392371            "considerations": {}
392372          }
392373        },
392374        {
392375          "type": "library",
392376          "bom-ref": "pkg:npm/ext-name@5.0.0?package-id=7c0587ddf45c3d4a",
392377          "supplier": {},
392378          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (https://github.com/kevva)",
392379          "name": "ext-name",
392380          "version": "5.0.0",
392381          "description": "Get the file extension and MIME type from a file",
392382          "licenses": [
392383            {
392384              "license": {
392385                "id": "MIT"
392386              }
392387            }
392388          ],
392389          "cpe": "cpe:2.3:a:ext-name:ext-name:5.0.0:*:*:*:*:*:*:*",
392390          "purl": "pkg:npm/ext-name@5.0.0",
392391          "swid": {
392392            "attachment": {}
392393          },
392394          "pedigree": {},
392395          "externalReferences": [
392396            {
392397              "url": "kevva/ext-name",
392398              "type": "distribution"
392399            }
392400          ],
392401          "evidence": {},
392402          "signature": {
392403            "signature": {
392404              "publicKey": {}
392405            }
392406          },
392407          "modelCard": {
392408            "modelParameters": {
392409              "approach": {}
392410            },
392411            "quantitativeAnalysis": {
392412              "graphics": {}
392413            },
392414            "considerations": {}
392415          }
392416        },
392417        {
392418          "type": "library",
392419          "bom-ref": "pkg:npm/extend@3.0.2?package-id=ac3f1ce155e9acb0",
392420          "supplier": {},
392421          "author": "Stefan Thomas \u003cjustmoon@members.fsf.org\u003e (http://www.justmoon.net)",
392422          "name": "extend",
392423          "version": "3.0.2",
392424          "description": "Port of jQuery.extend for node.js and the browser",
392425          "licenses": [
392426            {
392427              "license": {
392428                "id": "MIT"
392429              }
392430            }
392431          ],
392432          "cpe": "cpe:2.3:a:justmoon:extend:3.0.2:*:*:*:*:*:*:*",
392433          "purl": "pkg:npm/extend@3.0.2",
392434          "swid": {
392435            "attachment": {}
392436          },
392437          "pedigree": {},
392438          "externalReferences": [
392439            {
392440              "url": "https://github.com/justmoon/node-extend.git",
392441              "type": "distribution"
392442            }
392443          ],
392444          "evidence": {},
392445          "signature": {
392446            "signature": {
392447              "publicKey": {}
392448            }
392449          },
392450          "modelCard": {
392451            "modelParameters": {
392452              "approach": {}
392453            },
392454            "quantitativeAnalysis": {
392455              "graphics": {}
392456            },
392457            "considerations": {}
392458          }
392459        },
392460        {
392461          "type": "library",
392462          "bom-ref": "pkg:npm/extsprintf@1.3.0?package-id=e1ddb770c979f4c3",
392463          "supplier": {},
392464          "name": "extsprintf",
392465          "version": "1.3.0",
392466          "description": "extended POSIX-style sprintf",
392467          "licenses": [
392468            {
392469              "license": {
392470                "id": "MIT"
392471              }
392472            }
392473          ],
392474          "cpe": "cpe:2.3:a:davepacheco:extsprintf:1.3.0:*:*:*:*:*:*:*",
392475          "purl": "pkg:npm/extsprintf@1.3.0",
392476          "swid": {
392477            "attachment": {}
392478          },
392479          "pedigree": {},
392480          "externalReferences": [
392481            {
392482              "url": "git://github.com/davepacheco/node-extsprintf.git",
392483              "type": "distribution"
392484            }
392485          ],
392486          "evidence": {},
392487          "signature": {
392488            "signature": {
392489              "publicKey": {}
392490            }
392491          },
392492          "modelCard": {
392493            "modelParameters": {
392494              "approach": {}
392495            },
392496            "quantitativeAnalysis": {
392497              "graphics": {}
392498            },
392499            "considerations": {}
392500          }
392501        },
392502        {
392503          "type": "library",
392504          "bom-ref": "pkg:npm/fast-deep-equal@3.1.3?package-id=8b9d45ccd3ca33c0",
392505          "supplier": {},
392506          "author": "Evgeny Poberezkin",
392507          "name": "fast-deep-equal",
392508          "version": "3.1.3",
392509          "description": "Fast deep equal",
392510          "licenses": [
392511            {
392512              "license": {
392513                "id": "MIT"
392514              }
392515            }
392516          ],
392517          "cpe": "cpe:2.3:a:fast-deep-equal:fast-deep-equal:3.1.3:*:*:*:*:*:*:*",
392518          "purl": "pkg:npm/fast-deep-equal@3.1.3",
392519          "swid": {
392520            "attachment": {}
392521          },
392522          "pedigree": {},
392523          "externalReferences": [
392524            {
392525              "url": "git+https://github.com/epoberezkin/fast-deep-equal.git",
392526              "type": "distribution"
392527            },
392528            {
392529              "url": "https://github.com/epoberezkin/fast-deep-equal#readme",
392530              "type": "website"
392531            }
392532          ],
392533          "evidence": {},
392534          "signature": {
392535            "signature": {
392536              "publicKey": {}
392537            }
392538          },
392539          "modelCard": {
392540            "modelParameters": {
392541              "approach": {}
392542            },
392543            "quantitativeAnalysis": {
392544              "graphics": {}
392545            },
392546            "considerations": {}
392547          }
392548        },
392549        {
392550          "type": "library",
392551          "bom-ref": "pkg:npm/fast-glob@3.2.12?package-id=fd9a6880d817706b",
392552          "supplier": {},
392553          "author": "Denis Malinochkin (https://mrmlnc.com)",
392554          "name": "fast-glob",
392555          "version": "3.2.12",
392556          "description": "It's a very fast and efficient glob library for Node.js",
392557          "licenses": [
392558            {
392559              "license": {
392560                "id": "MIT"
392561              }
392562            }
392563          ],
392564          "cpe": "cpe:2.3:a:fast-glob:fast-glob:3.2.12:*:*:*:*:*:*:*",
392565          "purl": "pkg:npm/fast-glob@3.2.12",
392566          "swid": {
392567            "attachment": {}
392568          },
392569          "pedigree": {},
392570          "externalReferences": [
392571            {
392572              "url": "mrmlnc/fast-glob",
392573              "type": "distribution"
392574            }
392575          ],
392576          "evidence": {},
392577          "signature": {
392578            "signature": {
392579              "publicKey": {}
392580            }
392581          },
392582          "modelCard": {
392583            "modelParameters": {
392584              "approach": {}
392585            },
392586            "quantitativeAnalysis": {
392587              "graphics": {}
392588            },
392589            "considerations": {}
392590          }
392591        },
392592        {
392593          "type": "library",
392594          "bom-ref": "pkg:npm/fast-json-stable-stringify@2.1.0?package-id=9e19806bed3935c1",
392595          "supplier": {},
392596          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
392597          "name": "fast-json-stable-stringify",
392598          "version": "2.1.0",
392599          "description": "deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify",
392600          "licenses": [
392601            {
392602              "license": {
392603                "id": "MIT"
392604              }
392605            }
392606          ],
392607          "cpe": "cpe:2.3:a:fast-json-stable-stringify:fast-json-stable-stringify:2.1.0:*:*:*:*:*:*:*",
392608          "purl": "pkg:npm/fast-json-stable-stringify@2.1.0",
392609          "swid": {
392610            "attachment": {}
392611          },
392612          "pedigree": {},
392613          "externalReferences": [
392614            {
392615              "url": "git://github.com/epoberezkin/fast-json-stable-stringify.git",
392616              "type": "distribution"
392617            },
392618            {
392619              "url": "https://github.com/epoberezkin/fast-json-stable-stringify",
392620              "type": "website"
392621            }
392622          ],
392623          "evidence": {},
392624          "signature": {
392625            "signature": {
392626              "publicKey": {}
392627            }
392628          },
392629          "modelCard": {
392630            "modelParameters": {
392631              "approach": {}
392632            },
392633            "quantitativeAnalysis": {
392634              "graphics": {}
392635            },
392636            "considerations": {}
392637          }
392638        },
392639        {
392640          "type": "library",
392641          "bom-ref": "pkg:npm/fastest-levenshtein@1.0.12?package-id=f703cf6832613e31",
392642          "supplier": {},
392643          "author": "Kasper U. Weihe",
392644          "name": "fastest-levenshtein",
392645          "version": "1.0.12",
392646          "description": "Fastest Levenshtein distance implementation in JS.",
392647          "licenses": [
392648            {
392649              "license": {
392650                "id": "MIT"
392651              }
392652            }
392653          ],
392654          "cpe": "cpe:2.3:a:fastest-levenshtein:fastest-levenshtein:1.0.12:*:*:*:*:*:*:*",
392655          "purl": "pkg:npm/fastest-levenshtein@1.0.12",
392656          "swid": {
392657            "attachment": {}
392658          },
392659          "pedigree": {},
392660          "externalReferences": [
392661            {
392662              "url": "git+https://github.com/ka-weihe/fastest-levenshtein.git",
392663              "type": "distribution"
392664            },
392665            {
392666              "url": "https://github.com/ka-weihe/fastest-levenshtein#README",
392667              "type": "website"
392668            }
392669          ],
392670          "evidence": {},
392671          "signature": {
392672            "signature": {
392673              "publicKey": {}
392674            }
392675          },
392676          "modelCard": {
392677            "modelParameters": {
392678              "approach": {}
392679            },
392680            "quantitativeAnalysis": {
392681              "graphics": {}
392682            },
392683            "considerations": {}
392684          }
392685        },
392686        {
392687          "type": "library",
392688          "bom-ref": "pkg:npm/fastq@1.15.0?package-id=27532f2570ab0ac1",
392689          "supplier": {},
392690          "author": "Matteo Collina \u003chello@matteocollina.com\u003e",
392691          "name": "fastq",
392692          "version": "1.15.0",
392693          "description": "Fast, in memory work queue",
392694          "licenses": [
392695            {
392696              "license": {
392697                "id": "ISC"
392698              }
392699            }
392700          ],
392701          "cpe": "cpe:2.3:a:mcollina:fastq:1.15.0:*:*:*:*:*:*:*",
392702          "purl": "pkg:npm/fastq@1.15.0",
392703          "swid": {
392704            "attachment": {}
392705          },
392706          "pedigree": {},
392707          "externalReferences": [
392708            {
392709              "url": "git+https://github.com/mcollina/fastq.git",
392710              "type": "distribution"
392711            },
392712            {
392713              "url": "https://github.com/mcollina/fastq#readme",
392714              "type": "website"
392715            }
392716          ],
392717          "evidence": {},
392718          "signature": {
392719            "signature": {
392720              "publicKey": {}
392721            }
392722          },
392723          "modelCard": {
392724            "modelParameters": {
392725              "approach": {}
392726            },
392727            "quantitativeAnalysis": {
392728              "graphics": {}
392729            },
392730            "considerations": {}
392731          }
392732        },
392733        {
392734          "type": "library",
392735          "bom-ref": "pkg:npm/fd-slicer@1.1.0?package-id=c0844670d052809c",
392736          "supplier": {},
392737          "author": "Andrew Kelley \u003csuperjoe30@gmail.com\u003e",
392738          "name": "fd-slicer",
392739          "version": "1.1.0",
392740          "description": "safely create multiple ReadStream or WriteStream objects from the same file descriptor",
392741          "licenses": [
392742            {
392743              "license": {
392744                "id": "MIT"
392745              }
392746            }
392747          ],
392748          "cpe": "cpe:2.3:a:fd-slicer:fd-slicer:1.1.0:*:*:*:*:*:*:*",
392749          "purl": "pkg:npm/fd-slicer@1.1.0",
392750          "swid": {
392751            "attachment": {}
392752          },
392753          "pedigree": {},
392754          "externalReferences": [
392755            {
392756              "url": "git://github.com/andrewrk/node-fd-slicer.git",
392757              "type": "distribution"
392758            }
392759          ],
392760          "evidence": {},
392761          "signature": {
392762            "signature": {
392763              "publicKey": {}
392764            }
392765          },
392766          "modelCard": {
392767            "modelParameters": {
392768              "approach": {}
392769            },
392770            "quantitativeAnalysis": {
392771              "graphics": {}
392772            },
392773            "considerations": {}
392774          }
392775        },
392776        {
392777          "type": "library",
392778          "bom-ref": "pkg:npm/file-type@11.1.0?package-id=89aaec2fd2f8281e",
392779          "supplier": {},
392780          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
392781          "name": "file-type",
392782          "version": "11.1.0",
392783          "description": "Detect the file type of a Buffer/Uint8Array/ArrayBuffer",
392784          "licenses": [
392785            {
392786              "license": {
392787                "id": "MIT"
392788              }
392789            }
392790          ],
392791          "cpe": "cpe:2.3:a:file-type:file-type:11.1.0:*:*:*:*:*:*:*",
392792          "purl": "pkg:npm/file-type@11.1.0",
392793          "swid": {
392794            "attachment": {}
392795          },
392796          "pedigree": {},
392797          "externalReferences": [
392798            {
392799              "url": "sindresorhus/file-type",
392800              "type": "distribution"
392801            }
392802          ],
392803          "evidence": {},
392804          "signature": {
392805            "signature": {
392806              "publicKey": {}
392807            }
392808          },
392809          "modelCard": {
392810            "modelParameters": {
392811              "approach": {}
392812            },
392813            "quantitativeAnalysis": {
392814              "graphics": {}
392815            },
392816            "considerations": {}
392817          }
392818        },
392819        {
392820          "type": "library",
392821          "bom-ref": "pkg:npm/file-type@3.9.0?package-id=527a100734a44d2a",
392822          "supplier": {},
392823          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
392824          "name": "file-type",
392825          "version": "3.9.0",
392826          "description": "Detect the file type of a Buffer/Uint8Array",
392827          "licenses": [
392828            {
392829              "license": {
392830                "id": "MIT"
392831              }
392832            }
392833          ],
392834          "cpe": "cpe:2.3:a:file-type:file-type:3.9.0:*:*:*:*:*:*:*",
392835          "purl": "pkg:npm/file-type@3.9.0",
392836          "swid": {
392837            "attachment": {}
392838          },
392839          "pedigree": {},
392840          "externalReferences": [
392841            {
392842              "url": "sindresorhus/file-type",
392843              "type": "distribution"
392844            }
392845          ],
392846          "evidence": {},
392847          "signature": {
392848            "signature": {
392849              "publicKey": {}
392850            }
392851          },
392852          "modelCard": {
392853            "modelParameters": {
392854              "approach": {}
392855            },
392856            "quantitativeAnalysis": {
392857              "graphics": {}
392858            },
392859            "considerations": {}
392860          }
392861        },
392862        {
392863          "type": "library",
392864          "bom-ref": "pkg:npm/file-type@4.4.0?package-id=70df1ba3cc5da435",
392865          "supplier": {},
392866          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
392867          "name": "file-type",
392868          "version": "4.4.0",
392869          "description": "Detect the file type of a Buffer/Uint8Array",
392870          "licenses": [
392871            {
392872              "license": {
392873                "id": "MIT"
392874              }
392875            }
392876          ],
392877          "cpe": "cpe:2.3:a:file-type:file-type:4.4.0:*:*:*:*:*:*:*",
392878          "purl": "pkg:npm/file-type@4.4.0",
392879          "swid": {
392880            "attachment": {}
392881          },
392882          "pedigree": {},
392883          "externalReferences": [
392884            {
392885              "url": "sindresorhus/file-type",
392886              "type": "distribution"
392887            }
392888          ],
392889          "evidence": {},
392890          "signature": {
392891            "signature": {
392892              "publicKey": {}
392893            }
392894          },
392895          "modelCard": {
392896            "modelParameters": {
392897              "approach": {}
392898            },
392899            "quantitativeAnalysis": {
392900              "graphics": {}
392901            },
392902            "considerations": {}
392903          }
392904        },
392905        {
392906          "type": "library",
392907          "bom-ref": "pkg:npm/file-type@5.2.0?package-id=f9a4f3b6ed672146",
392908          "supplier": {},
392909          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
392910          "name": "file-type",
392911          "version": "5.2.0",
392912          "description": "Detect the file type of a Buffer/Uint8Array",
392913          "licenses": [
392914            {
392915              "license": {
392916                "id": "MIT"
392917              }
392918            }
392919          ],
392920          "cpe": "cpe:2.3:a:file-type:file-type:5.2.0:*:*:*:*:*:*:*",
392921          "purl": "pkg:npm/file-type@5.2.0",
392922          "swid": {
392923            "attachment": {}
392924          },
392925          "pedigree": {},
392926          "externalReferences": [
392927            {
392928              "url": "sindresorhus/file-type",
392929              "type": "distribution"
392930            }
392931          ],
392932          "evidence": {},
392933          "signature": {
392934            "signature": {
392935              "publicKey": {}
392936            }
392937          },
392938          "modelCard": {
392939            "modelParameters": {
392940              "approach": {}
392941            },
392942            "quantitativeAnalysis": {
392943              "graphics": {}
392944            },
392945            "considerations": {}
392946          }
392947        },
392948        {
392949          "type": "library",
392950          "bom-ref": "pkg:npm/file-type@5.2.0?package-id=e376a911ba2385b5",
392951          "supplier": {},
392952          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
392953          "name": "file-type",
392954          "version": "5.2.0",
392955          "description": "Detect the file type of a Buffer/Uint8Array",
392956          "licenses": [
392957            {
392958              "license": {
392959                "id": "MIT"
392960              }
392961            }
392962          ],
392963          "cpe": "cpe:2.3:a:file-type:file-type:5.2.0:*:*:*:*:*:*:*",
392964          "purl": "pkg:npm/file-type@5.2.0",
392965          "swid": {
392966            "attachment": {}
392967          },
392968          "pedigree": {},
392969          "externalReferences": [
392970            {
392971              "url": "sindresorhus/file-type",
392972              "type": "distribution"
392973            }
392974          ],
392975          "evidence": {},
392976          "signature": {
392977            "signature": {
392978              "publicKey": {}
392979            }
392980          },
392981          "modelCard": {
392982            "modelParameters": {
392983              "approach": {}
392984            },
392985            "quantitativeAnalysis": {
392986              "graphics": {}
392987            },
392988            "considerations": {}
392989          }
392990        },
392991        {
392992          "type": "library",
392993          "bom-ref": "pkg:npm/file-type@6.2.0?package-id=eb5e21f8a1edff60",
392994          "supplier": {},
392995          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
392996          "name": "file-type",
392997          "version": "6.2.0",
392998          "description": "Detect the file type of a Buffer/Uint8Array",
392999          "licenses": [
393000            {
393001              "license": {
393002                "id": "MIT"
393003              }
393004            }
393005          ],
393006          "cpe": "cpe:2.3:a:file-type:file-type:6.2.0:*:*:*:*:*:*:*",
393007          "purl": "pkg:npm/file-type@6.2.0",
393008          "swid": {
393009            "attachment": {}
393010          },
393011          "pedigree": {},
393012          "externalReferences": [
393013            {
393014              "url": "sindresorhus/file-type",
393015              "type": "distribution"
393016            }
393017          ],
393018          "evidence": {},
393019          "signature": {
393020            "signature": {
393021              "publicKey": {}
393022            }
393023          },
393024          "modelCard": {
393025            "modelParameters": {
393026              "approach": {}
393027            },
393028            "quantitativeAnalysis": {
393029              "graphics": {}
393030            },
393031            "considerations": {}
393032          }
393033        },
393034        {
393035          "type": "library",
393036          "bom-ref": "pkg:npm/filename-reserved-regex@2.0.0?package-id=85979b9d17db4ba2",
393037          "supplier": {},
393038          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
393039          "name": "filename-reserved-regex",
393040          "version": "2.0.0",
393041          "description": "Regular expression for matching reserved filename characters",
393042          "licenses": [
393043            {
393044              "license": {
393045                "id": "MIT"
393046              }
393047            }
393048          ],
393049          "cpe": "cpe:2.3:a:filename-reserved-regex:filename-reserved-regex:2.0.0:*:*:*:*:*:*:*",
393050          "purl": "pkg:npm/filename-reserved-regex@2.0.0",
393051          "swid": {
393052            "attachment": {}
393053          },
393054          "pedigree": {},
393055          "externalReferences": [
393056            {
393057              "url": "sindresorhus/filename-reserved-regex",
393058              "type": "distribution"
393059            }
393060          ],
393061          "evidence": {},
393062          "signature": {
393063            "signature": {
393064              "publicKey": {}
393065            }
393066          },
393067          "modelCard": {
393068            "modelParameters": {
393069              "approach": {}
393070            },
393071            "quantitativeAnalysis": {
393072              "graphics": {}
393073            },
393074            "considerations": {}
393075          }
393076        },
393077        {
393078          "type": "library",
393079          "bom-ref": "pkg:npm/filenamify@3.0.0?package-id=b23706ffbf952066",
393080          "supplier": {},
393081          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
393082          "name": "filenamify",
393083          "version": "3.0.0",
393084          "description": "Convert a string to a valid safe filename",
393085          "licenses": [
393086            {
393087              "license": {
393088                "id": "MIT"
393089              }
393090            }
393091          ],
393092          "cpe": "cpe:2.3:a:filenamify:filenamify:3.0.0:*:*:*:*:*:*:*",
393093          "purl": "pkg:npm/filenamify@3.0.0",
393094          "swid": {
393095            "attachment": {}
393096          },
393097          "pedigree": {},
393098          "externalReferences": [
393099            {
393100              "url": "sindresorhus/filenamify",
393101              "type": "distribution"
393102            }
393103          ],
393104          "evidence": {},
393105          "signature": {
393106            "signature": {
393107              "publicKey": {}
393108            }
393109          },
393110          "modelCard": {
393111            "modelParameters": {
393112              "approach": {}
393113            },
393114            "quantitativeAnalysis": {
393115              "graphics": {}
393116            },
393117            "considerations": {}
393118          }
393119        },
393120        {
393121          "type": "library",
393122          "bom-ref": "pkg:npm/fill-range@7.0.1?package-id=c0b0964fa14fb839",
393123          "supplier": {},
393124          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
393125          "name": "fill-range",
393126          "version": "7.0.1",
393127          "description": "Fill in a range of numbers or letters, optionally passing an increment or `step` to use, or create a regex-compatible range with `options.toRegex`",
393128          "licenses": [
393129            {
393130              "license": {
393131                "id": "MIT"
393132              }
393133            }
393134          ],
393135          "cpe": "cpe:2.3:a:jonschlinkert:fill-range:7.0.1:*:*:*:*:*:*:*",
393136          "purl": "pkg:npm/fill-range@7.0.1",
393137          "swid": {
393138            "attachment": {}
393139          },
393140          "pedigree": {},
393141          "externalReferences": [
393142            {
393143              "url": "jonschlinkert/fill-range",
393144              "type": "distribution"
393145            },
393146            {
393147              "url": "https://github.com/jonschlinkert/fill-range",
393148              "type": "website"
393149            }
393150          ],
393151          "evidence": {},
393152          "signature": {
393153            "signature": {
393154              "publicKey": {}
393155            }
393156          },
393157          "modelCard": {
393158            "modelParameters": {
393159              "approach": {}
393160            },
393161            "quantitativeAnalysis": {
393162              "graphics": {}
393163            },
393164            "considerations": {}
393165          }
393166        },
393167        {
393168          "type": "library",
393169          "bom-ref": "pkg:npm/finalhandler@1.1.1?package-id=f0968412c48fe760",
393170          "supplier": {},
393171          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
393172          "name": "finalhandler",
393173          "version": "1.1.1",
393174          "description": "Node.js final http responder",
393175          "licenses": [
393176            {
393177              "license": {
393178                "id": "MIT"
393179              }
393180            }
393181          ],
393182          "cpe": "cpe:2.3:a:finalhandler:finalhandler:1.1.1:*:*:*:*:*:*:*",
393183          "purl": "pkg:npm/finalhandler@1.1.1",
393184          "swid": {
393185            "attachment": {}
393186          },
393187          "pedigree": {},
393188          "externalReferences": [
393189            {
393190              "url": "pillarjs/finalhandler",
393191              "type": "distribution"
393192            }
393193          ],
393194          "evidence": {},
393195          "signature": {
393196            "signature": {
393197              "publicKey": {}
393198            }
393199          },
393200          "modelCard": {
393201            "modelParameters": {
393202              "approach": {}
393203            },
393204            "quantitativeAnalysis": {
393205              "graphics": {}
393206            },
393207            "considerations": {}
393208          }
393209        },
393210        {
393211          "type": "library",
393212          "bom-ref": "pkg:npm/find-yarn-workspace-root@2.0.0?package-id=123525c0f7751cdc",
393213          "supplier": {},
393214          "author": "Square, Inc.",
393215          "name": "find-yarn-workspace-root",
393216          "version": "2.0.0",
393217          "description": "Algorithm for finding the root of a yarn workspace, extracted from yarnpkg.com",
393218          "licenses": [
393219            {
393220              "license": {
393221                "id": "Apache-2.0"
393222              }
393223            }
393224          ],
393225          "cpe": "cpe:2.3:a:find-yarn-workspace-root:find-yarn-workspace-root:2.0.0:*:*:*:*:*:*:*",
393226          "purl": "pkg:npm/find-yarn-workspace-root@2.0.0",
393227          "swid": {
393228            "attachment": {}
393229          },
393230          "pedigree": {},
393231          "externalReferences": [
393232            {
393233              "url": "https://github.com/square/find-yarn-workspace-root.git",
393234              "type": "distribution"
393235            }
393236          ],
393237          "evidence": {},
393238          "signature": {
393239            "signature": {
393240              "publicKey": {}
393241            }
393242          },
393243          "modelCard": {
393244            "modelParameters": {
393245              "approach": {}
393246            },
393247            "quantitativeAnalysis": {
393248              "graphics": {}
393249            },
393250            "considerations": {}
393251          }
393252        },
393253        {
393254          "type": "library",
393255          "bom-ref": "pkg:npm/forever-agent@0.6.1?package-id=987c799490a62745",
393256          "supplier": {},
393257          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
393258          "name": "forever-agent",
393259          "version": "0.6.1",
393260          "description": "HTTP Agent that keeps socket connections alive between keep-alive requests. Formerly part of mikeal/request, now a standalone module.",
393261          "licenses": [
393262            {
393263              "license": {
393264                "id": "Apache-2.0"
393265              }
393266            }
393267          ],
393268          "cpe": "cpe:2.3:a:forever-agent:forever-agent:0.6.1:*:*:*:*:*:*:*",
393269          "purl": "pkg:npm/forever-agent@0.6.1",
393270          "swid": {
393271            "attachment": {}
393272          },
393273          "pedigree": {},
393274          "externalReferences": [
393275            {
393276              "url": "https://github.com/mikeal/forever-agent",
393277              "type": "distribution"
393278            }
393279          ],
393280          "evidence": {},
393281          "signature": {
393282            "signature": {
393283              "publicKey": {}
393284            }
393285          },
393286          "modelCard": {
393287            "modelParameters": {
393288              "approach": {}
393289            },
393290            "quantitativeAnalysis": {
393291              "graphics": {}
393292            },
393293            "considerations": {}
393294          }
393295        },
393296        {
393297          "type": "library",
393298          "bom-ref": "pkg:npm/form-data@2.3.3?package-id=901e4c8507a70298",
393299          "supplier": {},
393300          "author": "Felix Geisendörfer \u003cfelix@debuggable.com\u003e (http://debuggable.com/)",
393301          "name": "form-data",
393302          "version": "2.3.3",
393303          "description": "A library to create readable \"multipart/form-data\" streams. Can be used to submit forms and file uploads to other web applications.",
393304          "licenses": [
393305            {
393306              "license": {
393307                "id": "MIT"
393308              }
393309            }
393310          ],
393311          "cpe": "cpe:2.3:a:form-data:form-data:2.3.3:*:*:*:*:*:*:*",
393312          "purl": "pkg:npm/form-data@2.3.3",
393313          "swid": {
393314            "attachment": {}
393315          },
393316          "pedigree": {},
393317          "externalReferences": [
393318            {
393319              "url": "git://github.com/form-data/form-data.git",
393320              "type": "distribution"
393321            }
393322          ],
393323          "evidence": {},
393324          "signature": {
393325            "signature": {
393326              "publicKey": {}
393327            }
393328          },
393329          "modelCard": {
393330            "modelParameters": {
393331              "approach": {}
393332            },
393333            "quantitativeAnalysis": {
393334              "graphics": {}
393335            },
393336            "considerations": {}
393337          }
393338        },
393339        {
393340          "type": "library",
393341          "bom-ref": "pkg:npm/forwarded@0.2.0?package-id=e2cd353a11409247",
393342          "supplier": {},
393343          "name": "forwarded",
393344          "version": "0.2.0",
393345          "description": "Parse HTTP X-Forwarded-For header",
393346          "licenses": [
393347            {
393348              "license": {
393349                "id": "MIT"
393350              }
393351            }
393352          ],
393353          "cpe": "cpe:2.3:a:forwarded:forwarded:0.2.0:*:*:*:*:*:*:*",
393354          "purl": "pkg:npm/forwarded@0.2.0",
393355          "swid": {
393356            "attachment": {}
393357          },
393358          "pedigree": {},
393359          "externalReferences": [
393360            {
393361              "url": "jshttp/forwarded",
393362              "type": "distribution"
393363            }
393364          ],
393365          "evidence": {},
393366          "signature": {
393367            "signature": {
393368              "publicKey": {}
393369            }
393370          },
393371          "modelCard": {
393372            "modelParameters": {
393373              "approach": {}
393374            },
393375            "quantitativeAnalysis": {
393376              "graphics": {}
393377            },
393378            "considerations": {}
393379          }
393380        },
393381        {
393382          "type": "library",
393383          "bom-ref": "pkg:npm/fresh@0.5.2?package-id=7080d1485688188f",
393384          "supplier": {},
393385          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
393386          "name": "fresh",
393387          "version": "0.5.2",
393388          "description": "HTTP response freshness testing",
393389          "licenses": [
393390            {
393391              "license": {
393392                "id": "MIT"
393393              }
393394            }
393395          ],
393396          "cpe": "cpe:2.3:a:fresh:fresh:0.5.2:*:*:*:*:*:*:*",
393397          "purl": "pkg:npm/fresh@0.5.2",
393398          "swid": {
393399            "attachment": {}
393400          },
393401          "pedigree": {},
393402          "externalReferences": [
393403            {
393404              "url": "jshttp/fresh",
393405              "type": "distribution"
393406            }
393407          ],
393408          "evidence": {},
393409          "signature": {
393410            "signature": {
393411              "publicKey": {}
393412            }
393413          },
393414          "modelCard": {
393415            "modelParameters": {
393416              "approach": {}
393417            },
393418            "quantitativeAnalysis": {
393419              "graphics": {}
393420            },
393421            "considerations": {}
393422          }
393423        },
393424        {
393425          "type": "library",
393426          "bom-ref": "pkg:npm/from2@2.3.0?package-id=5ce884159e7c97c",
393427          "supplier": {},
393428          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
393429          "name": "from2",
393430          "version": "2.3.0",
393431          "description": "Convenience wrapper for ReadableStream, with an API lifted from \"from\" and \"through2\"",
393432          "licenses": [
393433            {
393434              "license": {
393435                "id": "MIT"
393436              }
393437            }
393438          ],
393439          "cpe": "cpe:2.3:a:hughsk:from2:2.3.0:*:*:*:*:*:*:*",
393440          "purl": "pkg:npm/from2@2.3.0",
393441          "swid": {
393442            "attachment": {}
393443          },
393444          "pedigree": {},
393445          "externalReferences": [
393446            {
393447              "url": "git://github.com/hughsk/from2",
393448              "type": "distribution"
393449            },
393450            {
393451              "url": "https://github.com/hughsk/from2",
393452              "type": "website"
393453            }
393454          ],
393455          "evidence": {},
393456          "signature": {
393457            "signature": {
393458              "publicKey": {}
393459            }
393460          },
393461          "modelCard": {
393462            "modelParameters": {
393463              "approach": {}
393464            },
393465            "quantitativeAnalysis": {
393466              "graphics": {}
393467            },
393468            "considerations": {}
393469          }
393470        },
393471        {
393472          "type": "library",
393473          "bom-ref": "pkg:npm/fs-constants@1.0.0?package-id=5374766914699b42",
393474          "supplier": {},
393475          "author": "Mathias Buus (@mafintosh)",
393476          "name": "fs-constants",
393477          "version": "1.0.0",
393478          "description": "Require constants across node and the browser",
393479          "licenses": [
393480            {
393481              "license": {
393482                "id": "MIT"
393483              }
393484            }
393485          ],
393486          "cpe": "cpe:2.3:a:fs-constants:fs-constants:1.0.0:*:*:*:*:*:*:*",
393487          "purl": "pkg:npm/fs-constants@1.0.0",
393488          "swid": {
393489            "attachment": {}
393490          },
393491          "pedigree": {},
393492          "externalReferences": [
393493            {
393494              "url": "https://github.com/mafintosh/fs-constants.git",
393495              "type": "distribution"
393496            },
393497            {
393498              "url": "https://github.com/mafintosh/fs-constants",
393499              "type": "website"
393500            }
393501          ],
393502          "evidence": {},
393503          "signature": {
393504            "signature": {
393505              "publicKey": {}
393506            }
393507          },
393508          "modelCard": {
393509            "modelParameters": {
393510              "approach": {}
393511            },
393512            "quantitativeAnalysis": {
393513              "graphics": {}
393514            },
393515            "considerations": {}
393516          }
393517        },
393518        {
393519          "type": "library",
393520          "bom-ref": "pkg:npm/fs-extra@8.1.0?package-id=fd32f6ef9252a576",
393521          "supplier": {},
393522          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
393523          "name": "fs-extra",
393524          "version": "8.1.0",
393525          "description": "fs-extra contains methods that aren't included in the vanilla Node.js fs package. Such as mkdir -p, cp -r, and rm -rf.",
393526          "licenses": [
393527            {
393528              "license": {
393529                "id": "MIT"
393530              }
393531            }
393532          ],
393533          "cpe": "cpe:2.3:a:jprichardson:fs-extra:8.1.0:*:*:*:*:*:*:*",
393534          "purl": "pkg:npm/fs-extra@8.1.0",
393535          "swid": {
393536            "attachment": {}
393537          },
393538          "pedigree": {},
393539          "externalReferences": [
393540            {
393541              "url": "https://github.com/jprichardson/node-fs-extra",
393542              "type": "distribution"
393543            },
393544            {
393545              "url": "https://github.com/jprichardson/node-fs-extra",
393546              "type": "website"
393547            }
393548          ],
393549          "evidence": {},
393550          "signature": {
393551            "signature": {
393552              "publicKey": {}
393553            }
393554          },
393555          "modelCard": {
393556            "modelParameters": {
393557              "approach": {}
393558            },
393559            "quantitativeAnalysis": {
393560              "graphics": {}
393561            },
393562            "considerations": {}
393563          }
393564        },
393565        {
393566          "type": "library",
393567          "bom-ref": "pkg:npm/fs-extra@9.1.0?package-id=4c2e030ee99447c5",
393568          "supplier": {},
393569          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
393570          "name": "fs-extra",
393571          "version": "9.1.0",
393572          "description": "fs-extra contains methods that aren't included in the vanilla Node.js fs package. Such as recursive mkdir, copy, and remove.",
393573          "licenses": [
393574            {
393575              "license": {
393576                "id": "MIT"
393577              }
393578            }
393579          ],
393580          "cpe": "cpe:2.3:a:jprichardson:fs-extra:9.1.0:*:*:*:*:*:*:*",
393581          "purl": "pkg:npm/fs-extra@9.1.0",
393582          "swid": {
393583            "attachment": {}
393584          },
393585          "pedigree": {},
393586          "externalReferences": [
393587            {
393588              "url": "https://github.com/jprichardson/node-fs-extra",
393589              "type": "distribution"
393590            },
393591            {
393592              "url": "https://github.com/jprichardson/node-fs-extra",
393593              "type": "website"
393594            }
393595          ],
393596          "evidence": {},
393597          "signature": {
393598            "signature": {
393599              "publicKey": {}
393600            }
393601          },
393602          "modelCard": {
393603            "modelParameters": {
393604              "approach": {}
393605            },
393606            "quantitativeAnalysis": {
393607              "graphics": {}
393608            },
393609            "considerations": {}
393610          }
393611        },
393612        {
393613          "type": "library",
393614          "bom-ref": "pkg:npm/fs-minipass@2.1.0?package-id=398fbbb28fb7e1f4",
393615          "supplier": {},
393616          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
393617          "name": "fs-minipass",
393618          "version": "2.1.0",
393619          "description": "fs read and write streams based on minipass",
393620          "licenses": [
393621            {
393622              "license": {
393623                "id": "ISC"
393624              }
393625            }
393626          ],
393627          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:2.1.0:*:*:*:*:*:*:*",
393628          "purl": "pkg:npm/fs-minipass@2.1.0",
393629          "swid": {
393630            "attachment": {}
393631          },
393632          "pedigree": {},
393633          "externalReferences": [
393634            {
393635              "url": "git+https://github.com/npm/fs-minipass.git",
393636              "type": "distribution"
393637            },
393638            {
393639              "url": "https://github.com/npm/fs-minipass#readme",
393640              "type": "website"
393641            }
393642          ],
393643          "evidence": {},
393644          "signature": {
393645            "signature": {
393646              "publicKey": {}
393647            }
393648          },
393649          "modelCard": {
393650            "modelParameters": {
393651              "approach": {}
393652            },
393653            "quantitativeAnalysis": {
393654              "graphics": {}
393655            },
393656            "considerations": {}
393657          }
393658        },
393659        {
393660          "type": "library",
393661          "bom-ref": "pkg:npm/fs-minipass@2.1.0?package-id=f1b7ae0257cf54f0",
393662          "supplier": {},
393663          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
393664          "name": "fs-minipass",
393665          "version": "2.1.0",
393666          "description": "fs read and write streams based on minipass",
393667          "licenses": [
393668            {
393669              "license": {
393670                "id": "ISC"
393671              }
393672            }
393673          ],
393674          "cpe": "cpe:2.3:a:fs-minipass:fs-minipass:2.1.0:*:*:*:*:*:*:*",
393675          "purl": "pkg:npm/fs-minipass@2.1.0",
393676          "swid": {
393677            "attachment": {}
393678          },
393679          "pedigree": {},
393680          "externalReferences": [
393681            {
393682              "url": "git+https://github.com/npm/fs-minipass.git",
393683              "type": "distribution"
393684            },
393685            {
393686              "url": "https://github.com/npm/fs-minipass#readme",
393687              "type": "website"
393688            }
393689          ],
393690          "evidence": {},
393691          "signature": {
393692            "signature": {
393693              "publicKey": {}
393694            }
393695          },
393696          "modelCard": {
393697            "modelParameters": {
393698              "approach": {}
393699            },
393700            "quantitativeAnalysis": {
393701              "graphics": {}
393702            },
393703            "considerations": {}
393704          }
393705        },
393706        {
393707          "type": "library",
393708          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=21800424481533b1",
393709          "supplier": {},
393710          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
393711          "name": "fs.realpath",
393712          "version": "1.0.0",
393713          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
393714          "licenses": [
393715            {
393716              "license": {
393717                "id": "ISC"
393718              }
393719            }
393720          ],
393721          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
393722          "purl": "pkg:npm/fs.realpath@1.0.0",
393723          "swid": {
393724            "attachment": {}
393725          },
393726          "pedigree": {},
393727          "externalReferences": [
393728            {
393729              "url": "git+https://github.com/isaacs/fs.realpath.git",
393730              "type": "distribution"
393731            }
393732          ],
393733          "evidence": {},
393734          "signature": {
393735            "signature": {
393736              "publicKey": {}
393737            }
393738          },
393739          "modelCard": {
393740            "modelParameters": {
393741              "approach": {}
393742            },
393743            "quantitativeAnalysis": {
393744              "graphics": {}
393745            },
393746            "considerations": {}
393747          }
393748        },
393749        {
393750          "type": "library",
393751          "bom-ref": "pkg:npm/fs.realpath@1.0.0?package-id=65729748c227165e",
393752          "supplier": {},
393753          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
393754          "name": "fs.realpath",
393755          "version": "1.0.0",
393756          "description": "Use node's fs.realpath, but fall back to the JS implementation if the native one fails",
393757          "licenses": [
393758            {
393759              "license": {
393760                "id": "ISC"
393761              }
393762            }
393763          ],
393764          "cpe": "cpe:2.3:a:fs.realpath:fs.realpath:1.0.0:*:*:*:*:*:*:*",
393765          "purl": "pkg:npm/fs.realpath@1.0.0",
393766          "swid": {
393767            "attachment": {}
393768          },
393769          "pedigree": {},
393770          "externalReferences": [
393771            {
393772              "url": "git+https://github.com/isaacs/fs.realpath.git",
393773              "type": "distribution"
393774            }
393775          ],
393776          "evidence": {},
393777          "signature": {
393778            "signature": {
393779              "publicKey": {}
393780            }
393781          },
393782          "modelCard": {
393783            "modelParameters": {
393784              "approach": {}
393785            },
393786            "quantitativeAnalysis": {
393787              "graphics": {}
393788            },
393789            "considerations": {}
393790          }
393791        },
393792        {
393793          "type": "library",
393794          "bom-ref": "pkg:apk/alpine/fstrm@0.6.1-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=2d11651fe3e4b4b8",
393795          "supplier": {},
393796          "name": "fstrm",
393797          "version": "0.6.1-r0",
393798          "description": "Frame Streams implementation in C",
393799          "licenses": [
393800            {
393801              "license": {
393802                "id": "MIT"
393803              }
393804            }
393805          ],
393806          "cpe": "cpe:2.3:a:farsightsec:fstrm:0.6.1-r0:*:*:*:*:*:*:*",
393807          "purl": "pkg:apk/alpine/fstrm@0.6.1-r0?arch=x86_64\u0026distro=alpine-3.16.5",
393808          "swid": {
393809            "attachment": {}
393810          },
393811          "pedigree": {},
393812          "externalReferences": [
393813            {
393814              "url": "https://github.com/farsightsec/fstrm",
393815              "type": "distribution"
393816            }
393817          ],
393818          "evidence": {},
393819          "signature": {
393820            "signature": {
393821              "publicKey": {}
393822            }
393823          },
393824          "modelCard": {
393825            "modelParameters": {
393826              "approach": {}
393827            },
393828            "quantitativeAnalysis": {
393829              "graphics": {}
393830            },
393831            "considerations": {}
393832          }
393833        },
393834        {
393835          "type": "library",
393836          "bom-ref": "pkg:npm/function-bind@1.1.1?package-id=44648bf09db15f6c",
393837          "supplier": {},
393838          "author": "Raynos \u003craynos2@gmail.com\u003e",
393839          "name": "function-bind",
393840          "version": "1.1.1",
393841          "description": "Implementation of Function.prototype.bind",
393842          "licenses": [
393843            {
393844              "license": {
393845                "id": "MIT"
393846              }
393847            }
393848          ],
393849          "cpe": "cpe:2.3:a:function-bind:function-bind:1.1.1:*:*:*:*:*:*:*",
393850          "purl": "pkg:npm/function-bind@1.1.1",
393851          "swid": {
393852            "attachment": {}
393853          },
393854          "pedigree": {},
393855          "externalReferences": [
393856            {
393857              "url": "git://github.com/Raynos/function-bind.git",
393858              "type": "distribution"
393859            },
393860            {
393861              "url": "https://github.com/Raynos/function-bind",
393862              "type": "website"
393863            }
393864          ],
393865          "evidence": {},
393866          "signature": {
393867            "signature": {
393868              "publicKey": {}
393869            }
393870          },
393871          "modelCard": {
393872            "modelParameters": {
393873              "approach": {}
393874            },
393875            "quantitativeAnalysis": {
393876              "graphics": {}
393877            },
393878            "considerations": {}
393879          }
393880        },
393881        {
393882          "type": "library",
393883          "bom-ref": "pkg:npm/gauge@4.0.4?package-id=fc4632a6e143d550",
393884          "supplier": {},
393885          "author": "GitHub Inc.",
393886          "name": "gauge",
393887          "version": "4.0.4",
393888          "description": "A terminal based horizontal gauge",
393889          "licenses": [
393890            {
393891              "license": {
393892                "id": "ISC"
393893              }
393894            }
393895          ],
393896          "cpe": "cpe:2.3:a:gauge:gauge:4.0.4:*:*:*:*:*:*:*",
393897          "purl": "pkg:npm/gauge@4.0.4",
393898          "swid": {
393899            "attachment": {}
393900          },
393901          "pedigree": {},
393902          "externalReferences": [
393903            {
393904              "url": "https://github.com/npm/gauge.git",
393905              "type": "distribution"
393906            },
393907            {
393908              "url": "https://github.com/npm/gauge",
393909              "type": "website"
393910            }
393911          ],
393912          "evidence": {},
393913          "signature": {
393914            "signature": {
393915              "publicKey": {}
393916            }
393917          },
393918          "modelCard": {
393919            "modelParameters": {
393920              "approach": {}
393921            },
393922            "quantitativeAnalysis": {
393923              "graphics": {}
393924            },
393925            "considerations": {}
393926          }
393927        },
393928        {
393929          "type": "library",
393930          "bom-ref": "pkg:npm/get-proxy@2.1.0?package-id=efe4dbd0d645d995",
393931          "supplier": {},
393932          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (https://github.com/kevva)",
393933          "name": "get-proxy",
393934          "version": "2.1.0",
393935          "description": "Get configured proxy",
393936          "licenses": [
393937            {
393938              "license": {
393939                "id": "MIT"
393940              }
393941            }
393942          ],
393943          "cpe": "cpe:2.3:a:get-proxy:get-proxy:2.1.0:*:*:*:*:*:*:*",
393944          "purl": "pkg:npm/get-proxy@2.1.0",
393945          "swid": {
393946            "attachment": {}
393947          },
393948          "pedigree": {},
393949          "externalReferences": [
393950            {
393951              "url": "kevva/get-proxy",
393952              "type": "distribution"
393953            }
393954          ],
393955          "evidence": {},
393956          "signature": {
393957            "signature": {
393958              "publicKey": {}
393959            }
393960          },
393961          "modelCard": {
393962            "modelParameters": {
393963              "approach": {}
393964            },
393965            "quantitativeAnalysis": {
393966              "graphics": {}
393967            },
393968            "considerations": {}
393969          }
393970        },
393971        {
393972          "type": "library",
393973          "bom-ref": "pkg:npm/get-stream@2.3.1?package-id=6ee2174b7602b041",
393974          "supplier": {},
393975          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
393976          "name": "get-stream",
393977          "version": "2.3.1",
393978          "description": "Get a stream as a string, buffer, or array",
393979          "licenses": [
393980            {
393981              "license": {
393982                "id": "MIT"
393983              }
393984            }
393985          ],
393986          "cpe": "cpe:2.3:a:get-stream:get-stream:2.3.1:*:*:*:*:*:*:*",
393987          "purl": "pkg:npm/get-stream@2.3.1",
393988          "swid": {
393989            "attachment": {}
393990          },
393991          "pedigree": {},
393992          "externalReferences": [
393993            {
393994              "url": "sindresorhus/get-stream",
393995              "type": "distribution"
393996            }
393997          ],
393998          "evidence": {},
393999          "signature": {
394000            "signature": {
394001              "publicKey": {}
394002            }
394003          },
394004          "modelCard": {
394005            "modelParameters": {
394006              "approach": {}
394007            },
394008            "quantitativeAnalysis": {
394009              "graphics": {}
394010            },
394011            "considerations": {}
394012          }
394013        },
394014        {
394015          "type": "library",
394016          "bom-ref": "pkg:npm/get-stream@3.0.0?package-id=22255c98915a1f96",
394017          "supplier": {},
394018          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
394019          "name": "get-stream",
394020          "version": "3.0.0",
394021          "description": "Get a stream as a string, buffer, or array",
394022          "licenses": [
394023            {
394024              "license": {
394025                "id": "MIT"
394026              }
394027            }
394028          ],
394029          "cpe": "cpe:2.3:a:get-stream:get-stream:3.0.0:*:*:*:*:*:*:*",
394030          "purl": "pkg:npm/get-stream@3.0.0",
394031          "swid": {
394032            "attachment": {}
394033          },
394034          "pedigree": {},
394035          "externalReferences": [
394036            {
394037              "url": "sindresorhus/get-stream",
394038              "type": "distribution"
394039            }
394040          ],
394041          "evidence": {},
394042          "signature": {
394043            "signature": {
394044              "publicKey": {}
394045            }
394046          },
394047          "modelCard": {
394048            "modelParameters": {
394049              "approach": {}
394050            },
394051            "quantitativeAnalysis": {
394052              "graphics": {}
394053            },
394054            "considerations": {}
394055          }
394056        },
394057        {
394058          "type": "library",
394059          "bom-ref": "pkg:npm/get-stream@3.0.0?package-id=56ec6f95eadcb5d8",
394060          "supplier": {},
394061          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
394062          "name": "get-stream",
394063          "version": "3.0.0",
394064          "description": "Get a stream as a string, buffer, or array",
394065          "licenses": [
394066            {
394067              "license": {
394068                "id": "MIT"
394069              }
394070            }
394071          ],
394072          "cpe": "cpe:2.3:a:get-stream:get-stream:3.0.0:*:*:*:*:*:*:*",
394073          "purl": "pkg:npm/get-stream@3.0.0",
394074          "swid": {
394075            "attachment": {}
394076          },
394077          "pedigree": {},
394078          "externalReferences": [
394079            {
394080              "url": "sindresorhus/get-stream",
394081              "type": "distribution"
394082            }
394083          ],
394084          "evidence": {},
394085          "signature": {
394086            "signature": {
394087              "publicKey": {}
394088            }
394089          },
394090          "modelCard": {
394091            "modelParameters": {
394092              "approach": {}
394093            },
394094            "quantitativeAnalysis": {
394095              "graphics": {}
394096            },
394097            "considerations": {}
394098          }
394099        },
394100        {
394101          "type": "library",
394102          "bom-ref": "pkg:npm/get-stream@4.1.0?package-id=1760659d39365560",
394103          "supplier": {},
394104          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
394105          "name": "get-stream",
394106          "version": "4.1.0",
394107          "description": "Get a stream as a string, buffer, or array",
394108          "licenses": [
394109            {
394110              "license": {
394111                "id": "MIT"
394112              }
394113            }
394114          ],
394115          "cpe": "cpe:2.3:a:get-stream:get-stream:4.1.0:*:*:*:*:*:*:*",
394116          "purl": "pkg:npm/get-stream@4.1.0",
394117          "swid": {
394118            "attachment": {}
394119          },
394120          "pedigree": {},
394121          "externalReferences": [
394122            {
394123              "url": "sindresorhus/get-stream",
394124              "type": "distribution"
394125            }
394126          ],
394127          "evidence": {},
394128          "signature": {
394129            "signature": {
394130              "publicKey": {}
394131            }
394132          },
394133          "modelCard": {
394134            "modelParameters": {
394135              "approach": {}
394136            },
394137            "quantitativeAnalysis": {
394138              "graphics": {}
394139            },
394140            "considerations": {}
394141          }
394142        },
394143        {
394144          "type": "library",
394145          "bom-ref": "pkg:npm/get-stream@5.2.0?package-id=c66bd6ad48eed0a3",
394146          "supplier": {},
394147          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
394148          "name": "get-stream",
394149          "version": "5.2.0",
394150          "description": "Get a stream as a string, buffer, or array",
394151          "licenses": [
394152            {
394153              "license": {
394154                "id": "MIT"
394155              }
394156            }
394157          ],
394158          "cpe": "cpe:2.3:a:get-stream:get-stream:5.2.0:*:*:*:*:*:*:*",
394159          "purl": "pkg:npm/get-stream@5.2.0",
394160          "swid": {
394161            "attachment": {}
394162          },
394163          "pedigree": {},
394164          "externalReferences": [
394165            {
394166              "url": "sindresorhus/get-stream",
394167              "type": "distribution"
394168            }
394169          ],
394170          "evidence": {},
394171          "signature": {
394172            "signature": {
394173              "publicKey": {}
394174            }
394175          },
394176          "modelCard": {
394177            "modelParameters": {
394178              "approach": {}
394179            },
394180            "quantitativeAnalysis": {
394181              "graphics": {}
394182            },
394183            "considerations": {}
394184          }
394185        },
394186        {
394187          "type": "library",
394188          "bom-ref": "pkg:npm/getpass@0.1.7?package-id=75c291a71588a422",
394189          "supplier": {},
394190          "author": "Alex Wilson \u003calex.wilson@joyent.com\u003e",
394191          "name": "getpass",
394192          "version": "0.1.7",
394193          "description": "getpass for node.js",
394194          "licenses": [
394195            {
394196              "license": {
394197                "id": "MIT"
394198              }
394199            }
394200          ],
394201          "cpe": "cpe:2.3:a:arekinath:getpass:0.1.7:*:*:*:*:*:*:*",
394202          "purl": "pkg:npm/getpass@0.1.7",
394203          "swid": {
394204            "attachment": {}
394205          },
394206          "pedigree": {},
394207          "externalReferences": [
394208            {
394209              "url": "https://github.com/arekinath/node-getpass.git",
394210              "type": "distribution"
394211            }
394212          ],
394213          "evidence": {},
394214          "signature": {
394215            "signature": {
394216              "publicKey": {}
394217            }
394218          },
394219          "modelCard": {
394220            "modelParameters": {
394221              "approach": {}
394222            },
394223            "quantitativeAnalysis": {
394224              "graphics": {}
394225            },
394226            "considerations": {}
394227          }
394228        },
394229        {
394230          "type": "library",
394231          "bom-ref": "pkg:npm/glob@7.2.3?package-id=b961e222f6e54786",
394232          "supplier": {},
394233          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
394234          "name": "glob",
394235          "version": "7.2.3",
394236          "description": "a little globber",
394237          "licenses": [
394238            {
394239              "license": {
394240                "id": "ISC"
394241              }
394242            }
394243          ],
394244          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
394245          "purl": "pkg:npm/glob@7.2.3",
394246          "swid": {
394247            "attachment": {}
394248          },
394249          "pedigree": {},
394250          "externalReferences": [
394251            {
394252              "url": "git://github.com/isaacs/node-glob.git",
394253              "type": "distribution"
394254            }
394255          ],
394256          "evidence": {},
394257          "signature": {
394258            "signature": {
394259              "publicKey": {}
394260            }
394261          },
394262          "modelCard": {
394263            "modelParameters": {
394264              "approach": {}
394265            },
394266            "quantitativeAnalysis": {
394267              "graphics": {}
394268            },
394269            "considerations": {}
394270          }
394271        },
394272        {
394273          "type": "library",
394274          "bom-ref": "pkg:npm/glob@7.2.3?package-id=37af2473a85a6fa0",
394275          "supplier": {},
394276          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
394277          "name": "glob",
394278          "version": "7.2.3",
394279          "description": "a little globber",
394280          "licenses": [
394281            {
394282              "license": {
394283                "id": "ISC"
394284              }
394285            }
394286          ],
394287          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
394288          "purl": "pkg:npm/glob@7.2.3",
394289          "swid": {
394290            "attachment": {}
394291          },
394292          "pedigree": {},
394293          "externalReferences": [
394294            {
394295              "url": "git://github.com/isaacs/node-glob.git",
394296              "type": "distribution"
394297            }
394298          ],
394299          "evidence": {},
394300          "signature": {
394301            "signature": {
394302              "publicKey": {}
394303            }
394304          },
394305          "modelCard": {
394306            "modelParameters": {
394307              "approach": {}
394308            },
394309            "quantitativeAnalysis": {
394310              "graphics": {}
394311            },
394312            "considerations": {}
394313          }
394314        },
394315        {
394316          "type": "library",
394317          "bom-ref": "pkg:npm/glob@7.2.3?package-id=27f74d4e19b8aa02",
394318          "supplier": {},
394319          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
394320          "name": "glob",
394321          "version": "7.2.3",
394322          "description": "a little globber",
394323          "licenses": [
394324            {
394325              "license": {
394326                "id": "ISC"
394327              }
394328            }
394329          ],
394330          "cpe": "cpe:2.3:a:isaacs:glob:7.2.3:*:*:*:*:*:*:*",
394331          "purl": "pkg:npm/glob@7.2.3",
394332          "swid": {
394333            "attachment": {}
394334          },
394335          "pedigree": {},
394336          "externalReferences": [
394337            {
394338              "url": "git://github.com/isaacs/node-glob.git",
394339              "type": "distribution"
394340            }
394341          ],
394342          "evidence": {},
394343          "signature": {
394344            "signature": {
394345              "publicKey": {}
394346            }
394347          },
394348          "modelCard": {
394349            "modelParameters": {
394350              "approach": {}
394351            },
394352            "quantitativeAnalysis": {
394353              "graphics": {}
394354            },
394355            "considerations": {}
394356          }
394357        },
394358        {
394359          "type": "library",
394360          "bom-ref": "pkg:npm/glob@8.0.3?package-id=f9282babaa70cabf",
394361          "supplier": {},
394362          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
394363          "name": "glob",
394364          "version": "8.0.3",
394365          "description": "a little globber",
394366          "licenses": [
394367            {
394368              "license": {
394369                "id": "ISC"
394370              }
394371            }
394372          ],
394373          "cpe": "cpe:2.3:a:isaacs:glob:8.0.3:*:*:*:*:*:*:*",
394374          "purl": "pkg:npm/glob@8.0.3",
394375          "swid": {
394376            "attachment": {}
394377          },
394378          "pedigree": {},
394379          "externalReferences": [
394380            {
394381              "url": "git://github.com/isaacs/node-glob.git",
394382              "type": "distribution"
394383            }
394384          ],
394385          "evidence": {},
394386          "signature": {
394387            "signature": {
394388              "publicKey": {}
394389            }
394390          },
394391          "modelCard": {
394392            "modelParameters": {
394393              "approach": {}
394394            },
394395            "quantitativeAnalysis": {
394396              "graphics": {}
394397            },
394398            "considerations": {}
394399          }
394400        },
394401        {
394402          "type": "library",
394403          "bom-ref": "pkg:npm/glob-parent@5.1.2?package-id=18aaf377c47e4ea4",
394404          "supplier": {},
394405          "author": "Gulp Team \u003cteam@gulpjs.com\u003e (https://gulpjs.com/)",
394406          "name": "glob-parent",
394407          "version": "5.1.2",
394408          "description": "Extract the non-magic parent path from a glob string.",
394409          "licenses": [
394410            {
394411              "license": {
394412                "id": "ISC"
394413              }
394414            }
394415          ],
394416          "cpe": "cpe:2.3:a:glob-parent:glob-parent:5.1.2:*:*:*:*:*:*:*",
394417          "purl": "pkg:npm/glob-parent@5.1.2",
394418          "swid": {
394419            "attachment": {}
394420          },
394421          "pedigree": {},
394422          "externalReferences": [
394423            {
394424              "url": "gulpjs/glob-parent",
394425              "type": "distribution"
394426            }
394427          ],
394428          "evidence": {},
394429          "signature": {
394430            "signature": {
394431              "publicKey": {}
394432            }
394433          },
394434          "modelCard": {
394435            "modelParameters": {
394436              "approach": {}
394437            },
394438            "quantitativeAnalysis": {
394439              "graphics": {}
394440            },
394441            "considerations": {}
394442          }
394443        },
394444        {
394445          "type": "library",
394446          "bom-ref": "pkg:npm/globby@11.1.0?package-id=a7e2b9824bbb754c",
394447          "supplier": {},
394448          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
394449          "name": "globby",
394450          "version": "11.1.0",
394451          "description": "User-friendly glob matching",
394452          "licenses": [
394453            {
394454              "license": {
394455                "id": "MIT"
394456              }
394457            }
394458          ],
394459          "cpe": "cpe:2.3:a:globby:globby:11.1.0:*:*:*:*:*:*:*",
394460          "purl": "pkg:npm/globby@11.1.0",
394461          "swid": {
394462            "attachment": {}
394463          },
394464          "pedigree": {},
394465          "externalReferences": [
394466            {
394467              "url": "sindresorhus/globby",
394468              "type": "distribution"
394469            }
394470          ],
394471          "evidence": {},
394472          "signature": {
394473            "signature": {
394474              "publicKey": {}
394475            }
394476          },
394477          "modelCard": {
394478            "modelParameters": {
394479              "approach": {}
394480            },
394481            "quantitativeAnalysis": {
394482              "graphics": {}
394483            },
394484            "considerations": {}
394485          }
394486        },
394487        {
394488          "type": "library",
394489          "bom-ref": "pkg:npm/got@11.8.6?package-id=d6fd191c0bfd7e6e",
394490          "supplier": {},
394491          "name": "got",
394492          "version": "11.8.6",
394493          "description": "Human-friendly and powerful HTTP request library for Node.js",
394494          "licenses": [
394495            {
394496              "license": {
394497                "id": "MIT"
394498              }
394499            }
394500          ],
394501          "cpe": "cpe:2.3:a:got:got:11.8.6:*:*:*:*:*:*:*",
394502          "purl": "pkg:npm/got@11.8.6",
394503          "swid": {
394504            "attachment": {}
394505          },
394506          "pedigree": {},
394507          "externalReferences": [
394508            {
394509              "url": "sindresorhus/got",
394510              "type": "distribution"
394511            }
394512          ],
394513          "evidence": {},
394514          "signature": {
394515            "signature": {
394516              "publicKey": {}
394517            }
394518          },
394519          "modelCard": {
394520            "modelParameters": {
394521              "approach": {}
394522            },
394523            "quantitativeAnalysis": {
394524              "graphics": {}
394525            },
394526            "considerations": {}
394527          }
394528        },
394529        {
394530          "type": "library",
394531          "bom-ref": "pkg:npm/got@8.3.2?package-id=e1f671cdecb81188",
394532          "supplier": {},
394533          "name": "got",
394534          "version": "8.3.2",
394535          "description": "Simplified HTTP requests",
394536          "licenses": [
394537            {
394538              "license": {
394539                "id": "MIT"
394540              }
394541            }
394542          ],
394543          "cpe": "cpe:2.3:a:got:got:8.3.2:*:*:*:*:*:*:*",
394544          "purl": "pkg:npm/got@8.3.2",
394545          "swid": {
394546            "attachment": {}
394547          },
394548          "pedigree": {},
394549          "externalReferences": [
394550            {
394551              "url": "sindresorhus/got",
394552              "type": "distribution"
394553            }
394554          ],
394555          "evidence": {},
394556          "signature": {
394557            "signature": {
394558              "publicKey": {}
394559            }
394560          },
394561          "modelCard": {
394562            "modelParameters": {
394563              "approach": {}
394564            },
394565            "quantitativeAnalysis": {
394566              "graphics": {}
394567            },
394568            "considerations": {}
394569          }
394570        },
394571        {
394572          "type": "library",
394573          "bom-ref": "pkg:npm/graceful-fs@4.2.10?package-id=9591c6b5bd9602cc",
394574          "supplier": {},
394575          "name": "graceful-fs",
394576          "version": "4.2.10",
394577          "description": "A drop-in replacement for fs, making various improvements.",
394578          "licenses": [
394579            {
394580              "license": {
394581                "id": "ISC"
394582              }
394583            }
394584          ],
394585          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.10:*:*:*:*:*:*:*",
394586          "purl": "pkg:npm/graceful-fs@4.2.10",
394587          "swid": {
394588            "attachment": {}
394589          },
394590          "pedigree": {},
394591          "externalReferences": [
394592            {
394593              "url": "https://github.com/isaacs/node-graceful-fs",
394594              "type": "distribution"
394595            }
394596          ],
394597          "evidence": {},
394598          "signature": {
394599            "signature": {
394600              "publicKey": {}
394601            }
394602          },
394603          "modelCard": {
394604            "modelParameters": {
394605              "approach": {}
394606            },
394607            "quantitativeAnalysis": {
394608              "graphics": {}
394609            },
394610            "considerations": {}
394611          }
394612        },
394613        {
394614          "type": "library",
394615          "bom-ref": "pkg:npm/graceful-fs@4.2.11?package-id=bef9b71aa253a928",
394616          "supplier": {},
394617          "name": "graceful-fs",
394618          "version": "4.2.11",
394619          "description": "A drop-in replacement for fs, making various improvements.",
394620          "licenses": [
394621            {
394622              "license": {
394623                "id": "ISC"
394624              }
394625            }
394626          ],
394627          "cpe": "cpe:2.3:a:graceful-fs:graceful-fs:4.2.11:*:*:*:*:*:*:*",
394628          "purl": "pkg:npm/graceful-fs@4.2.11",
394629          "swid": {
394630            "attachment": {}
394631          },
394632          "pedigree": {},
394633          "externalReferences": [
394634            {
394635              "url": "https://github.com/isaacs/node-graceful-fs",
394636              "type": "distribution"
394637            }
394638          ],
394639          "evidence": {},
394640          "signature": {
394641            "signature": {
394642              "publicKey": {}
394643            }
394644          },
394645          "modelCard": {
394646            "modelParameters": {
394647              "approach": {}
394648            },
394649            "quantitativeAnalysis": {
394650              "graphics": {}
394651            },
394652            "considerations": {}
394653          }
394654        },
394655        {
394656          "type": "library",
394657          "bom-ref": "pkg:npm/har-schema@2.0.0?package-id=4dcd539e47ce1819",
394658          "supplier": {},
394659          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
394660          "name": "har-schema",
394661          "version": "2.0.0",
394662          "description": "JSON Schema for HTTP Archive (HAR)",
394663          "licenses": [
394664            {
394665              "license": {
394666                "id": "ISC"
394667              }
394668            }
394669          ],
394670          "cpe": "cpe:2.3:a:ahmadnassri:har-schema:2.0.0:*:*:*:*:*:*:*",
394671          "purl": "pkg:npm/har-schema@2.0.0",
394672          "swid": {
394673            "attachment": {}
394674          },
394675          "pedigree": {},
394676          "externalReferences": [
394677            {
394678              "url": "https://github.com/ahmadnassri/har-schema.git",
394679              "type": "distribution"
394680            },
394681            {
394682              "url": "https://github.com/ahmadnassri/har-schema",
394683              "type": "website"
394684            }
394685          ],
394686          "evidence": {},
394687          "signature": {
394688            "signature": {
394689              "publicKey": {}
394690            }
394691          },
394692          "modelCard": {
394693            "modelParameters": {
394694              "approach": {}
394695            },
394696            "quantitativeAnalysis": {
394697              "graphics": {}
394698            },
394699            "considerations": {}
394700          }
394701        },
394702        {
394703          "type": "library",
394704          "bom-ref": "pkg:npm/har-validator@5.1.5?package-id=d992c94a0553947c",
394705          "supplier": {},
394706          "author": "Ahmad Nassri \u003cahmad@ahmadnassri.com\u003e (https://www.ahmadnassri.com/)",
394707          "name": "har-validator",
394708          "version": "5.1.5",
394709          "description": "Extremely fast HTTP Archive (HAR) validator using JSON Schema",
394710          "licenses": [
394711            {
394712              "license": {
394713                "id": "MIT"
394714              }
394715            }
394716          ],
394717          "cpe": "cpe:2.3:a:har-validator:har-validator:5.1.5:*:*:*:*:*:*:*",
394718          "purl": "pkg:npm/har-validator@5.1.5",
394719          "swid": {
394720            "attachment": {}
394721          },
394722          "pedigree": {},
394723          "externalReferences": [
394724            {
394725              "url": "https://github.com/ahmadnassri/node-har-validator.git",
394726              "type": "distribution"
394727            },
394728            {
394729              "url": "https://github.com/ahmadnassri/node-har-validator",
394730              "type": "website"
394731            }
394732          ],
394733          "evidence": {},
394734          "signature": {
394735            "signature": {
394736              "publicKey": {}
394737            }
394738          },
394739          "modelCard": {
394740            "modelParameters": {
394741              "approach": {}
394742            },
394743            "quantitativeAnalysis": {
394744              "graphics": {}
394745            },
394746            "considerations": {}
394747          }
394748        },
394749        {
394750          "type": "library",
394751          "bom-ref": "pkg:npm/has@1.0.3?package-id=57072cf8ae347274",
394752          "supplier": {},
394753          "author": "Thiago de Arruda \u003ctpadilha84@gmail.com\u003e",
394754          "name": "has",
394755          "version": "1.0.3",
394756          "description": "Object.prototype.hasOwnProperty.call shortcut",
394757          "licenses": [
394758            {
394759              "license": {
394760                "id": "MIT"
394761              }
394762            }
394763          ],
394764          "cpe": "cpe:2.3:a:tarruda:has:1.0.3:*:*:*:*:*:*:*",
394765          "purl": "pkg:npm/has@1.0.3",
394766          "swid": {
394767            "attachment": {}
394768          },
394769          "pedigree": {},
394770          "externalReferences": [
394771            {
394772              "url": "git://github.com/tarruda/has.git",
394773              "type": "distribution"
394774            },
394775            {
394776              "url": "https://github.com/tarruda/has",
394777              "type": "website"
394778            }
394779          ],
394780          "evidence": {},
394781          "signature": {
394782            "signature": {
394783              "publicKey": {}
394784            }
394785          },
394786          "modelCard": {
394787            "modelParameters": {
394788              "approach": {}
394789            },
394790            "quantitativeAnalysis": {
394791              "graphics": {}
394792            },
394793            "considerations": {}
394794          }
394795        },
394796        {
394797          "type": "library",
394798          "bom-ref": "pkg:npm/has-flag@3.0.0?package-id=827f03d0a0fb3972",
394799          "supplier": {},
394800          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
394801          "name": "has-flag",
394802          "version": "3.0.0",
394803          "description": "Check if argv has a specific flag",
394804          "licenses": [
394805            {
394806              "license": {
394807                "id": "MIT"
394808              }
394809            }
394810          ],
394811          "cpe": "cpe:2.3:a:has-flag:has-flag:3.0.0:*:*:*:*:*:*:*",
394812          "purl": "pkg:npm/has-flag@3.0.0",
394813          "swid": {
394814            "attachment": {}
394815          },
394816          "pedigree": {},
394817          "externalReferences": [
394818            {
394819              "url": "sindresorhus/has-flag",
394820              "type": "distribution"
394821            }
394822          ],
394823          "evidence": {},
394824          "signature": {
394825            "signature": {
394826              "publicKey": {}
394827            }
394828          },
394829          "modelCard": {
394830            "modelParameters": {
394831              "approach": {}
394832            },
394833            "quantitativeAnalysis": {
394834              "graphics": {}
394835            },
394836            "considerations": {}
394837          }
394838        },
394839        {
394840          "type": "library",
394841          "bom-ref": "pkg:npm/has-flag@4.0.0?package-id=1ac717b55f99f4f2",
394842          "supplier": {},
394843          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
394844          "name": "has-flag",
394845          "version": "4.0.0",
394846          "description": "Check if argv has a specific flag",
394847          "licenses": [
394848            {
394849              "license": {
394850                "id": "MIT"
394851              }
394852            }
394853          ],
394854          "cpe": "cpe:2.3:a:has-flag:has-flag:4.0.0:*:*:*:*:*:*:*",
394855          "purl": "pkg:npm/has-flag@4.0.0",
394856          "swid": {
394857            "attachment": {}
394858          },
394859          "pedigree": {},
394860          "externalReferences": [
394861            {
394862              "url": "sindresorhus/has-flag",
394863              "type": "distribution"
394864            }
394865          ],
394866          "evidence": {},
394867          "signature": {
394868            "signature": {
394869              "publicKey": {}
394870            }
394871          },
394872          "modelCard": {
394873            "modelParameters": {
394874              "approach": {}
394875            },
394876            "quantitativeAnalysis": {
394877              "graphics": {}
394878            },
394879            "considerations": {}
394880          }
394881        },
394882        {
394883          "type": "library",
394884          "bom-ref": "pkg:npm/has-flag@4.0.0?package-id=fe0415670e8174f1",
394885          "supplier": {},
394886          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
394887          "name": "has-flag",
394888          "version": "4.0.0",
394889          "description": "Check if argv has a specific flag",
394890          "licenses": [
394891            {
394892              "license": {
394893                "id": "MIT"
394894              }
394895            }
394896          ],
394897          "cpe": "cpe:2.3:a:has-flag:has-flag:4.0.0:*:*:*:*:*:*:*",
394898          "purl": "pkg:npm/has-flag@4.0.0",
394899          "swid": {
394900            "attachment": {}
394901          },
394902          "pedigree": {},
394903          "externalReferences": [
394904            {
394905              "url": "sindresorhus/has-flag",
394906              "type": "distribution"
394907            }
394908          ],
394909          "evidence": {},
394910          "signature": {
394911            "signature": {
394912              "publicKey": {}
394913            }
394914          },
394915          "modelCard": {
394916            "modelParameters": {
394917              "approach": {}
394918            },
394919            "quantitativeAnalysis": {
394920              "graphics": {}
394921            },
394922            "considerations": {}
394923          }
394924        },
394925        {
394926          "type": "library",
394927          "bom-ref": "pkg:npm/has-symbol-support-x@1.4.2?package-id=289ae60a33cdd346",
394928          "supplier": {},
394929          "author": "Graham Fairweather \u003cxotic750@gmail.com\u003e",
394930          "name": "has-symbol-support-x",
394931          "version": "1.4.2",
394932          "description": "Tests if ES6 Symbol is supported.",
394933          "licenses": [
394934            {
394935              "license": {
394936                "id": "MIT"
394937              }
394938            }
394939          ],
394940          "cpe": "cpe:2.3:a:has-symbol-support-x:has-symbol-support-x:1.4.2:*:*:*:*:*:*:*",
394941          "purl": "pkg:npm/has-symbol-support-x@1.4.2",
394942          "swid": {
394943            "attachment": {}
394944          },
394945          "pedigree": {},
394946          "externalReferences": [
394947            {
394948              "url": "https://github.com/Xotic750/has-symbol-support-x.git",
394949              "type": "distribution"
394950            },
394951            {
394952              "url": "https://github.com/Xotic750/has-symbol-support-x",
394953              "type": "website"
394954            }
394955          ],
394956          "evidence": {},
394957          "signature": {
394958            "signature": {
394959              "publicKey": {}
394960            }
394961          },
394962          "modelCard": {
394963            "modelParameters": {
394964              "approach": {}
394965            },
394966            "quantitativeAnalysis": {
394967              "graphics": {}
394968            },
394969            "considerations": {}
394970          }
394971        },
394972        {
394973          "type": "library",
394974          "bom-ref": "pkg:npm/has-to-string-tag-x@1.4.1?package-id=6cf21f5b92940fbe",
394975          "supplier": {},
394976          "author": "Graham Fairweather \u003cxotic750@gmail.com\u003e",
394977          "name": "has-to-string-tag-x",
394978          "version": "1.4.1",
394979          "description": "Tests if ES6 @@toStringTag is supported.",
394980          "licenses": [
394981            {
394982              "license": {
394983                "id": "MIT"
394984              }
394985            }
394986          ],
394987          "cpe": "cpe:2.3:a:has-to-string-tag-x:has-to-string-tag-x:1.4.1:*:*:*:*:*:*:*",
394988          "purl": "pkg:npm/has-to-string-tag-x@1.4.1",
394989          "swid": {
394990            "attachment": {}
394991          },
394992          "pedigree": {},
394993          "externalReferences": [
394994            {
394995              "url": "https://github.com/Xotic750/has-to-string-tag-x.git",
394996              "type": "distribution"
394997            },
394998            {
394999              "url": "https://github.com/Xotic750/has-to-string-tag-x",
395000              "type": "website"
395001            }
395002          ],
395003          "evidence": {},
395004          "signature": {
395005            "signature": {
395006              "publicKey": {}
395007            }
395008          },
395009          "modelCard": {
395010            "modelParameters": {
395011              "approach": {}
395012            },
395013            "quantitativeAnalysis": {
395014              "graphics": {}
395015            },
395016            "considerations": {}
395017          }
395018        },
395019        {
395020          "type": "library",
395021          "bom-ref": "pkg:npm/has-unicode@2.0.1?package-id=28dbbd6e7951181f",
395022          "supplier": {},
395023          "author": "Rebecca Turner \u003cme@re-becca.org\u003e",
395024          "name": "has-unicode",
395025          "version": "2.0.1",
395026          "description": "Try to guess if your terminal supports unicode",
395027          "licenses": [
395028            {
395029              "license": {
395030                "id": "ISC"
395031              }
395032            }
395033          ],
395034          "cpe": "cpe:2.3:a:has-unicode:has-unicode:2.0.1:*:*:*:*:*:*:*",
395035          "purl": "pkg:npm/has-unicode@2.0.1",
395036          "swid": {
395037            "attachment": {}
395038          },
395039          "pedigree": {},
395040          "externalReferences": [
395041            {
395042              "url": "https://github.com/iarna/has-unicode",
395043              "type": "distribution"
395044            },
395045            {
395046              "url": "https://github.com/iarna/has-unicode",
395047              "type": "website"
395048            }
395049          ],
395050          "evidence": {},
395051          "signature": {
395052            "signature": {
395053              "publicKey": {}
395054            }
395055          },
395056          "modelCard": {
395057            "modelParameters": {
395058              "approach": {}
395059            },
395060            "quantitativeAnalysis": {
395061              "graphics": {}
395062            },
395063            "considerations": {}
395064          }
395065        },
395066        {
395067          "type": "library",
395068          "bom-ref": "pkg:npm/hosted-git-info@5.2.1?package-id=daac03af08cd11f6",
395069          "supplier": {},
395070          "author": "GitHub Inc.",
395071          "name": "hosted-git-info",
395072          "version": "5.2.1",
395073          "description": "Provides metadata and conversions from repository urls for GitHub, Bitbucket and GitLab",
395074          "licenses": [
395075            {
395076              "license": {
395077                "id": "ISC"
395078              }
395079            }
395080          ],
395081          "cpe": "cpe:2.3:a:hosted-git-info:hosted-git-info:5.2.1:*:*:*:*:*:*:*",
395082          "purl": "pkg:npm/hosted-git-info@5.2.1",
395083          "swid": {
395084            "attachment": {}
395085          },
395086          "pedigree": {},
395087          "externalReferences": [
395088            {
395089              "url": "https://github.com/npm/hosted-git-info.git",
395090              "type": "distribution"
395091            },
395092            {
395093              "url": "https://github.com/npm/hosted-git-info",
395094              "type": "website"
395095            }
395096          ],
395097          "evidence": {},
395098          "signature": {
395099            "signature": {
395100              "publicKey": {}
395101            }
395102          },
395103          "modelCard": {
395104            "modelParameters": {
395105              "approach": {}
395106            },
395107            "quantitativeAnalysis": {
395108              "graphics": {}
395109            },
395110            "considerations": {}
395111          }
395112        },
395113        {
395114          "type": "library",
395115          "bom-ref": "pkg:npm/http-cache-semantics@3.8.1?package-id=86b81a2bc9dc1f8f",
395116          "supplier": {},
395117          "author": "Kornel Lesiński \u003ckornel@geekhood.net\u003e (https://kornel.ski/)",
395118          "name": "http-cache-semantics",
395119          "version": "3.8.1",
395120          "description": "Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies",
395121          "licenses": [
395122            {
395123              "license": {
395124                "id": "BSD-2-Clause"
395125              }
395126            }
395127          ],
395128          "cpe": "cpe:2.3:a:http-cache-semantics:http-cache-semantics:3.8.1:*:*:*:*:*:*:*",
395129          "purl": "pkg:npm/http-cache-semantics@3.8.1",
395130          "swid": {
395131            "attachment": {}
395132          },
395133          "pedigree": {},
395134          "externalReferences": [
395135            {
395136              "url": "https://github.com/pornel/http-cache-semantics.git",
395137              "type": "distribution"
395138            }
395139          ],
395140          "evidence": {},
395141          "signature": {
395142            "signature": {
395143              "publicKey": {}
395144            }
395145          },
395146          "modelCard": {
395147            "modelParameters": {
395148              "approach": {}
395149            },
395150            "quantitativeAnalysis": {
395151              "graphics": {}
395152            },
395153            "considerations": {}
395154          }
395155        },
395156        {
395157          "type": "library",
395158          "bom-ref": "pkg:npm/http-cache-semantics@4.1.1?package-id=916aa3ebe914a835",
395159          "supplier": {},
395160          "author": "Kornel Lesiński \u003ckornel@geekhood.net\u003e (https://kornel.ski/)",
395161          "name": "http-cache-semantics",
395162          "version": "4.1.1",
395163          "description": "Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies",
395164          "licenses": [
395165            {
395166              "license": {
395167                "id": "BSD-2-Clause"
395168              }
395169            }
395170          ],
395171          "cpe": "cpe:2.3:a:http-cache-semantics:http-cache-semantics:4.1.1:*:*:*:*:*:*:*",
395172          "purl": "pkg:npm/http-cache-semantics@4.1.1",
395173          "swid": {
395174            "attachment": {}
395175          },
395176          "pedigree": {},
395177          "externalReferences": [
395178            {
395179              "url": "https://github.com/kornelski/http-cache-semantics.git",
395180              "type": "distribution"
395181            }
395182          ],
395183          "evidence": {},
395184          "signature": {
395185            "signature": {
395186              "publicKey": {}
395187            }
395188          },
395189          "modelCard": {
395190            "modelParameters": {
395191              "approach": {}
395192            },
395193            "quantitativeAnalysis": {
395194              "graphics": {}
395195            },
395196            "considerations": {}
395197          }
395198        },
395199        {
395200          "type": "library",
395201          "bom-ref": "pkg:npm/http-cache-semantics@4.1.1?package-id=c245f622b4a75bf6",
395202          "supplier": {},
395203          "author": "Kornel Lesiński \u003ckornel@geekhood.net\u003e (https://kornel.ski/)",
395204          "name": "http-cache-semantics",
395205          "version": "4.1.1",
395206          "description": "Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies",
395207          "licenses": [
395208            {
395209              "license": {
395210                "id": "BSD-2-Clause"
395211              }
395212            }
395213          ],
395214          "cpe": "cpe:2.3:a:http-cache-semantics:http-cache-semantics:4.1.1:*:*:*:*:*:*:*",
395215          "purl": "pkg:npm/http-cache-semantics@4.1.1",
395216          "swid": {
395217            "attachment": {}
395218          },
395219          "pedigree": {},
395220          "externalReferences": [
395221            {
395222              "url": "https://github.com/kornelski/http-cache-semantics.git",
395223              "type": "distribution"
395224            }
395225          ],
395226          "evidence": {},
395227          "signature": {
395228            "signature": {
395229              "publicKey": {}
395230            }
395231          },
395232          "modelCard": {
395233            "modelParameters": {
395234              "approach": {}
395235            },
395236            "quantitativeAnalysis": {
395237              "graphics": {}
395238            },
395239            "considerations": {}
395240          }
395241        },
395242        {
395243          "type": "library",
395244          "bom-ref": "pkg:npm/http-errors@1.6.3?package-id=d1068a65d773e5c4",
395245          "supplier": {},
395246          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
395247          "name": "http-errors",
395248          "version": "1.6.3",
395249          "description": "Create HTTP error objects",
395250          "licenses": [
395251            {
395252              "license": {
395253                "id": "MIT"
395254              }
395255            }
395256          ],
395257          "cpe": "cpe:2.3:a:http-errors:http-errors:1.6.3:*:*:*:*:*:*:*",
395258          "purl": "pkg:npm/http-errors@1.6.3",
395259          "swid": {
395260            "attachment": {}
395261          },
395262          "pedigree": {},
395263          "externalReferences": [
395264            {
395265              "url": "jshttp/http-errors",
395266              "type": "distribution"
395267            }
395268          ],
395269          "evidence": {},
395270          "signature": {
395271            "signature": {
395272              "publicKey": {}
395273            }
395274          },
395275          "modelCard": {
395276            "modelParameters": {
395277              "approach": {}
395278            },
395279            "quantitativeAnalysis": {
395280              "graphics": {}
395281            },
395282            "considerations": {}
395283          }
395284        },
395285        {
395286          "type": "library",
395287          "bom-ref": "pkg:npm/http-proxy-agent@5.0.0?package-id=af3d467415b1e643",
395288          "supplier": {},
395289          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
395290          "name": "http-proxy-agent",
395291          "version": "5.0.0",
395292          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTP",
395293          "licenses": [
395294            {
395295              "license": {
395296                "id": "MIT"
395297              }
395298            }
395299          ],
395300          "cpe": "cpe:2.3:a:http-proxy-agent:http-proxy-agent:5.0.0:*:*:*:*:*:*:*",
395301          "purl": "pkg:npm/http-proxy-agent@5.0.0",
395302          "swid": {
395303            "attachment": {}
395304          },
395305          "pedigree": {},
395306          "externalReferences": [
395307            {
395308              "url": "git://github.com/TooTallNate/node-http-proxy-agent.git",
395309              "type": "distribution"
395310            }
395311          ],
395312          "evidence": {},
395313          "signature": {
395314            "signature": {
395315              "publicKey": {}
395316            }
395317          },
395318          "modelCard": {
395319            "modelParameters": {
395320              "approach": {}
395321            },
395322            "quantitativeAnalysis": {
395323              "graphics": {}
395324            },
395325            "considerations": {}
395326          }
395327        },
395328        {
395329          "type": "library",
395330          "bom-ref": "pkg:npm/http-signature@1.2.0?package-id=b566cae888becf5d",
395331          "supplier": {},
395332          "author": "Joyent, Inc",
395333          "name": "http-signature",
395334          "version": "1.2.0",
395335          "description": "Reference implementation of Joyent's HTTP Signature scheme.",
395336          "licenses": [
395337            {
395338              "license": {
395339                "id": "MIT"
395340              }
395341            }
395342          ],
395343          "cpe": "cpe:2.3:a:http-signature:http-signature:1.2.0:*:*:*:*:*:*:*",
395344          "purl": "pkg:npm/http-signature@1.2.0",
395345          "swid": {
395346            "attachment": {}
395347          },
395348          "pedigree": {},
395349          "externalReferences": [
395350            {
395351              "url": "git://github.com/joyent/node-http-signature.git",
395352              "type": "distribution"
395353            },
395354            {
395355              "url": "https://github.com/joyent/node-http-signature/",
395356              "type": "website"
395357            }
395358          ],
395359          "evidence": {},
395360          "signature": {
395361            "signature": {
395362              "publicKey": {}
395363            }
395364          },
395365          "modelCard": {
395366            "modelParameters": {
395367              "approach": {}
395368            },
395369            "quantitativeAnalysis": {
395370              "graphics": {}
395371            },
395372            "considerations": {}
395373          }
395374        },
395375        {
395376          "type": "library",
395377          "bom-ref": "pkg:npm/http2-wrapper@1.0.3?package-id=dc8749ed03d21432",
395378          "supplier": {},
395379          "author": "Szymon Marczak",
395380          "name": "http2-wrapper",
395381          "version": "1.0.3",
395382          "description": "HTTP2 client, just with the familiar `https` API",
395383          "licenses": [
395384            {
395385              "license": {
395386                "id": "MIT"
395387              }
395388            }
395389          ],
395390          "cpe": "cpe:2.3:a:http2-wrapper:http2-wrapper:1.0.3:*:*:*:*:*:*:*",
395391          "purl": "pkg:npm/http2-wrapper@1.0.3",
395392          "swid": {
395393            "attachment": {}
395394          },
395395          "pedigree": {},
395396          "externalReferences": [
395397            {
395398              "url": "git+https://github.com/szmarczak/http2-wrapper.git",
395399              "type": "distribution"
395400            },
395401            {
395402              "url": "https://github.com/szmarczak/http2-wrapper#readme",
395403              "type": "website"
395404            }
395405          ],
395406          "evidence": {},
395407          "signature": {
395408            "signature": {
395409              "publicKey": {}
395410            }
395411          },
395412          "modelCard": {
395413            "modelParameters": {
395414              "approach": {}
395415            },
395416            "quantitativeAnalysis": {
395417              "graphics": {}
395418            },
395419            "considerations": {}
395420          }
395421        },
395422        {
395423          "type": "library",
395424          "bom-ref": "pkg:npm/https-proxy-agent@5.0.1?package-id=b2694aac4dc305de",
395425          "supplier": {},
395426          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
395427          "name": "https-proxy-agent",
395428          "version": "5.0.1",
395429          "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",
395430          "licenses": [
395431            {
395432              "license": {
395433                "id": "MIT"
395434              }
395435            }
395436          ],
395437          "cpe": "cpe:2.3:a:https-proxy-agent:https-proxy-agent:5.0.1:*:*:*:*:*:*:*",
395438          "purl": "pkg:npm/https-proxy-agent@5.0.1",
395439          "swid": {
395440            "attachment": {}
395441          },
395442          "pedigree": {},
395443          "externalReferences": [
395444            {
395445              "url": "git://github.com/TooTallNate/node-https-proxy-agent.git",
395446              "type": "distribution"
395447            }
395448          ],
395449          "evidence": {},
395450          "signature": {
395451            "signature": {
395452              "publicKey": {}
395453            }
395454          },
395455          "modelCard": {
395456            "modelParameters": {
395457              "approach": {}
395458            },
395459            "quantitativeAnalysis": {
395460              "graphics": {}
395461            },
395462            "considerations": {}
395463          }
395464        },
395465        {
395466          "type": "library",
395467          "bom-ref": "pkg:npm/humanize-ms@1.2.1?package-id=d773c44dd2f9a86d",
395468          "supplier": {},
395469          "author": "dead-horse \u003cdead_horse@qq.com\u003e (http://deadhorse.me)",
395470          "name": "humanize-ms",
395471          "version": "1.2.1",
395472          "description": "transform humanize time to ms",
395473          "licenses": [
395474            {
395475              "license": {
395476                "id": "MIT"
395477              }
395478            }
395479          ],
395480          "cpe": "cpe:2.3:a:node-modules:humanize-ms:1.2.1:*:*:*:*:*:*:*",
395481          "purl": "pkg:npm/humanize-ms@1.2.1",
395482          "swid": {
395483            "attachment": {}
395484          },
395485          "pedigree": {},
395486          "externalReferences": [
395487            {
395488              "url": "https://github.com/node-modules/humanize-ms",
395489              "type": "distribution"
395490            }
395491          ],
395492          "evidence": {},
395493          "signature": {
395494            "signature": {
395495              "publicKey": {}
395496            }
395497          },
395498          "modelCard": {
395499            "modelParameters": {
395500              "approach": {}
395501            },
395502            "quantitativeAnalysis": {
395503              "graphics": {}
395504            },
395505            "considerations": {}
395506          }
395507        },
395508        {
395509          "type": "library",
395510          "bom-ref": "pkg:npm/iconv-lite@0.4.23?package-id=5056a816beaa3c8b",
395511          "supplier": {},
395512          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
395513          "name": "iconv-lite",
395514          "version": "0.4.23",
395515          "description": "Convert character encodings in pure javascript.",
395516          "licenses": [
395517            {
395518              "license": {
395519                "id": "MIT"
395520              }
395521            }
395522          ],
395523          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.4.23:*:*:*:*:*:*:*",
395524          "purl": "pkg:npm/iconv-lite@0.4.23",
395525          "swid": {
395526            "attachment": {}
395527          },
395528          "pedigree": {},
395529          "externalReferences": [
395530            {
395531              "url": "git://github.com/ashtuchkin/iconv-lite.git",
395532              "type": "distribution"
395533            },
395534            {
395535              "url": "https://github.com/ashtuchkin/iconv-lite",
395536              "type": "website"
395537            }
395538          ],
395539          "evidence": {},
395540          "signature": {
395541            "signature": {
395542              "publicKey": {}
395543            }
395544          },
395545          "modelCard": {
395546            "modelParameters": {
395547              "approach": {}
395548            },
395549            "quantitativeAnalysis": {
395550              "graphics": {}
395551            },
395552            "considerations": {}
395553          }
395554        },
395555        {
395556          "type": "library",
395557          "bom-ref": "pkg:npm/iconv-lite@0.6.3?package-id=fc4965fa5a86a9c9",
395558          "supplier": {},
395559          "author": "Alexander Shtuchkin \u003cashtuchkin@gmail.com\u003e",
395560          "name": "iconv-lite",
395561          "version": "0.6.3",
395562          "description": "Convert character encodings in pure javascript.",
395563          "licenses": [
395564            {
395565              "license": {
395566                "id": "MIT"
395567              }
395568            }
395569          ],
395570          "cpe": "cpe:2.3:a:ashtuchkin:iconv-lite:0.6.3:*:*:*:*:*:*:*",
395571          "purl": "pkg:npm/iconv-lite@0.6.3",
395572          "swid": {
395573            "attachment": {}
395574          },
395575          "pedigree": {},
395576          "externalReferences": [
395577            {
395578              "url": "git://github.com/ashtuchkin/iconv-lite.git",
395579              "type": "distribution"
395580            },
395581            {
395582              "url": "https://github.com/ashtuchkin/iconv-lite",
395583              "type": "website"
395584            }
395585          ],
395586          "evidence": {},
395587          "signature": {
395588            "signature": {
395589              "publicKey": {}
395590            }
395591          },
395592          "modelCard": {
395593            "modelParameters": {
395594              "approach": {}
395595            },
395596            "quantitativeAnalysis": {
395597              "graphics": {}
395598            },
395599            "considerations": {}
395600          }
395601        },
395602        {
395603          "type": "library",
395604          "bom-ref": "pkg:npm/ieee754@1.2.1?package-id=18839efc79bfb481",
395605          "supplier": {},
395606          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
395607          "name": "ieee754",
395608          "version": "1.2.1",
395609          "description": "Read/write IEEE754 floating point numbers from/to a Buffer or array-like object",
395610          "licenses": [
395611            {
395612              "license": {
395613                "id": "BSD-3-Clause"
395614              }
395615            }
395616          ],
395617          "cpe": "cpe:2.3:a:ieee754:ieee754:1.2.1:*:*:*:*:*:*:*",
395618          "purl": "pkg:npm/ieee754@1.2.1",
395619          "swid": {
395620            "attachment": {}
395621          },
395622          "pedigree": {},
395623          "externalReferences": [
395624            {
395625              "url": "git://github.com/feross/ieee754.git",
395626              "type": "distribution"
395627            }
395628          ],
395629          "evidence": {},
395630          "signature": {
395631            "signature": {
395632              "publicKey": {}
395633            }
395634          },
395635          "modelCard": {
395636            "modelParameters": {
395637              "approach": {}
395638            },
395639            "quantitativeAnalysis": {
395640              "graphics": {}
395641            },
395642            "considerations": {}
395643          }
395644        },
395645        {
395646          "type": "library",
395647          "bom-ref": "pkg:npm/ignore@5.2.4?package-id=a927aced65cc635b",
395648          "supplier": {},
395649          "author": "kael",
395650          "name": "ignore",
395651          "version": "5.2.4",
395652          "description": "Ignore is a manager and filter for .gitignore rules, the one used by eslint, gitbook and many others.",
395653          "licenses": [
395654            {
395655              "license": {
395656                "id": "MIT"
395657              }
395658            }
395659          ],
395660          "cpe": "cpe:2.3:a:ignore:ignore:5.2.4:*:*:*:*:*:*:*",
395661          "purl": "pkg:npm/ignore@5.2.4",
395662          "swid": {
395663            "attachment": {}
395664          },
395665          "pedigree": {},
395666          "externalReferences": [
395667            {
395668              "url": "git@github.com:kaelzhang/node-ignore.git",
395669              "type": "distribution"
395670            }
395671          ],
395672          "evidence": {},
395673          "signature": {
395674            "signature": {
395675              "publicKey": {}
395676            }
395677          },
395678          "modelCard": {
395679            "modelParameters": {
395680              "approach": {}
395681            },
395682            "quantitativeAnalysis": {
395683              "graphics": {}
395684            },
395685            "considerations": {}
395686          }
395687        },
395688        {
395689          "type": "library",
395690          "bom-ref": "pkg:npm/ignore-walk@5.0.1?package-id=39d6166153eb8a8",
395691          "supplier": {},
395692          "author": "GitHub Inc.",
395693          "name": "ignore-walk",
395694          "version": "5.0.1",
395695          "description": "Nested/recursive `.gitignore`/`.npmignore` parsing and filtering.",
395696          "licenses": [
395697            {
395698              "license": {
395699                "id": "ISC"
395700              }
395701            }
395702          ],
395703          "cpe": "cpe:2.3:a:ignore-walk:ignore-walk:5.0.1:*:*:*:*:*:*:*",
395704          "purl": "pkg:npm/ignore-walk@5.0.1",
395705          "swid": {
395706            "attachment": {}
395707          },
395708          "pedigree": {},
395709          "externalReferences": [
395710            {
395711              "url": "https://github.com/npm/ignore-walk.git",
395712              "type": "distribution"
395713            }
395714          ],
395715          "evidence": {},
395716          "signature": {
395717            "signature": {
395718              "publicKey": {}
395719            }
395720          },
395721          "modelCard": {
395722            "modelParameters": {
395723              "approach": {}
395724            },
395725            "quantitativeAnalysis": {
395726              "graphics": {}
395727            },
395728            "considerations": {}
395729          }
395730        },
395731        {
395732          "type": "library",
395733          "bom-ref": "pkg:npm/imurmurhash@0.1.4?package-id=6444b4b295dc6bb1",
395734          "supplier": {},
395735          "author": "Jens Taylor \u003cjensyt@gmail.com\u003e (https://github.com/homebrewing)",
395736          "name": "imurmurhash",
395737          "version": "0.1.4",
395738          "description": "An incremental implementation of MurmurHash3",
395739          "licenses": [
395740            {
395741              "license": {
395742                "id": "MIT"
395743              }
395744            }
395745          ],
395746          "cpe": "cpe:2.3:a:imurmurhash:imurmurhash:0.1.4:*:*:*:*:*:*:*",
395747          "purl": "pkg:npm/imurmurhash@0.1.4",
395748          "swid": {
395749            "attachment": {}
395750          },
395751          "pedigree": {},
395752          "externalReferences": [
395753            {
395754              "url": "https://github.com/jensyt/imurmurhash-js",
395755              "type": "distribution"
395756            },
395757            {
395758              "url": "https://github.com/jensyt/imurmurhash-js",
395759              "type": "website"
395760            }
395761          ],
395762          "evidence": {},
395763          "signature": {
395764            "signature": {
395765              "publicKey": {}
395766            }
395767          },
395768          "modelCard": {
395769            "modelParameters": {
395770              "approach": {}
395771            },
395772            "quantitativeAnalysis": {
395773              "graphics": {}
395774            },
395775            "considerations": {}
395776          }
395777        },
395778        {
395779          "type": "library",
395780          "bom-ref": "pkg:npm/indent-string@4.0.0?package-id=9c9aada4281114e7",
395781          "supplier": {},
395782          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
395783          "name": "indent-string",
395784          "version": "4.0.0",
395785          "description": "Indent each line in a string",
395786          "licenses": [
395787            {
395788              "license": {
395789                "id": "MIT"
395790              }
395791            }
395792          ],
395793          "cpe": "cpe:2.3:a:indent-string:indent-string:4.0.0:*:*:*:*:*:*:*",
395794          "purl": "pkg:npm/indent-string@4.0.0",
395795          "swid": {
395796            "attachment": {}
395797          },
395798          "pedigree": {},
395799          "externalReferences": [
395800            {
395801              "url": "sindresorhus/indent-string",
395802              "type": "distribution"
395803            }
395804          ],
395805          "evidence": {},
395806          "signature": {
395807            "signature": {
395808              "publicKey": {}
395809            }
395810          },
395811          "modelCard": {
395812            "modelParameters": {
395813              "approach": {}
395814            },
395815            "quantitativeAnalysis": {
395816              "graphics": {}
395817            },
395818            "considerations": {}
395819          }
395820        },
395821        {
395822          "type": "library",
395823          "bom-ref": "pkg:npm/infer-owner@1.0.4?package-id=70041214f8f231ae",
395824          "supplier": {},
395825          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
395826          "name": "infer-owner",
395827          "version": "1.0.4",
395828          "description": "Infer the owner of a path based on the owner of its nearest existing parent",
395829          "licenses": [
395830            {
395831              "license": {
395832                "id": "ISC"
395833              }
395834            }
395835          ],
395836          "cpe": "cpe:2.3:a:infer-owner:infer-owner:1.0.4:*:*:*:*:*:*:*",
395837          "purl": "pkg:npm/infer-owner@1.0.4",
395838          "swid": {
395839            "attachment": {}
395840          },
395841          "pedigree": {},
395842          "externalReferences": [
395843            {
395844              "url": "https://github.com/npm/infer-owner",
395845              "type": "distribution"
395846            }
395847          ],
395848          "evidence": {},
395849          "signature": {
395850            "signature": {
395851              "publicKey": {}
395852            }
395853          },
395854          "modelCard": {
395855            "modelParameters": {
395856              "approach": {}
395857            },
395858            "quantitativeAnalysis": {
395859              "graphics": {}
395860            },
395861            "considerations": {}
395862          }
395863        },
395864        {
395865          "type": "library",
395866          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=59c3c8a2d2437082",
395867          "supplier": {},
395868          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
395869          "name": "inflight",
395870          "version": "1.0.6",
395871          "description": "Add callbacks to requests in flight to avoid async duplication",
395872          "licenses": [
395873            {
395874              "license": {
395875                "id": "ISC"
395876              }
395877            }
395878          ],
395879          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
395880          "purl": "pkg:npm/inflight@1.0.6",
395881          "swid": {
395882            "attachment": {}
395883          },
395884          "pedigree": {},
395885          "externalReferences": [
395886            {
395887              "url": "https://github.com/npm/inflight.git",
395888              "type": "distribution"
395889            },
395890            {
395891              "url": "https://github.com/isaacs/inflight",
395892              "type": "website"
395893            }
395894          ],
395895          "evidence": {},
395896          "signature": {
395897            "signature": {
395898              "publicKey": {}
395899            }
395900          },
395901          "modelCard": {
395902            "modelParameters": {
395903              "approach": {}
395904            },
395905            "quantitativeAnalysis": {
395906              "graphics": {}
395907            },
395908            "considerations": {}
395909          }
395910        },
395911        {
395912          "type": "library",
395913          "bom-ref": "pkg:npm/inflight@1.0.6?package-id=f9bd5cf95258dad4",
395914          "supplier": {},
395915          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
395916          "name": "inflight",
395917          "version": "1.0.6",
395918          "description": "Add callbacks to requests in flight to avoid async duplication",
395919          "licenses": [
395920            {
395921              "license": {
395922                "id": "ISC"
395923              }
395924            }
395925          ],
395926          "cpe": "cpe:2.3:a:inflight:inflight:1.0.6:*:*:*:*:*:*:*",
395927          "purl": "pkg:npm/inflight@1.0.6",
395928          "swid": {
395929            "attachment": {}
395930          },
395931          "pedigree": {},
395932          "externalReferences": [
395933            {
395934              "url": "https://github.com/npm/inflight.git",
395935              "type": "distribution"
395936            },
395937            {
395938              "url": "https://github.com/isaacs/inflight",
395939              "type": "website"
395940            }
395941          ],
395942          "evidence": {},
395943          "signature": {
395944            "signature": {
395945              "publicKey": {}
395946            }
395947          },
395948          "modelCard": {
395949            "modelParameters": {
395950              "approach": {}
395951            },
395952            "quantitativeAnalysis": {
395953              "graphics": {}
395954            },
395955            "considerations": {}
395956          }
395957        },
395958        {
395959          "type": "library",
395960          "bom-ref": "pkg:npm/inherits@2.0.3?package-id=1bb44148e405c144",
395961          "supplier": {},
395962          "name": "inherits",
395963          "version": "2.0.3",
395964          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
395965          "licenses": [
395966            {
395967              "license": {
395968                "id": "ISC"
395969              }
395970            }
395971          ],
395972          "cpe": "cpe:2.3:a:inherits:inherits:2.0.3:*:*:*:*:*:*:*",
395973          "purl": "pkg:npm/inherits@2.0.3",
395974          "swid": {
395975            "attachment": {}
395976          },
395977          "pedigree": {},
395978          "externalReferences": [
395979            {
395980              "url": "git://github.com/isaacs/inherits",
395981              "type": "distribution"
395982            }
395983          ],
395984          "evidence": {},
395985          "signature": {
395986            "signature": {
395987              "publicKey": {}
395988            }
395989          },
395990          "modelCard": {
395991            "modelParameters": {
395992              "approach": {}
395993            },
395994            "quantitativeAnalysis": {
395995              "graphics": {}
395996            },
395997            "considerations": {}
395998          }
395999        },
396000        {
396001          "type": "library",
396002          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=2aa76eeeb4a32e94",
396003          "supplier": {},
396004          "name": "inherits",
396005          "version": "2.0.4",
396006          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
396007          "licenses": [
396008            {
396009              "license": {
396010                "id": "ISC"
396011              }
396012            }
396013          ],
396014          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
396015          "purl": "pkg:npm/inherits@2.0.4",
396016          "swid": {
396017            "attachment": {}
396018          },
396019          "pedigree": {},
396020          "externalReferences": [
396021            {
396022              "url": "git://github.com/isaacs/inherits",
396023              "type": "distribution"
396024            }
396025          ],
396026          "evidence": {},
396027          "signature": {
396028            "signature": {
396029              "publicKey": {}
396030            }
396031          },
396032          "modelCard": {
396033            "modelParameters": {
396034              "approach": {}
396035            },
396036            "quantitativeAnalysis": {
396037              "graphics": {}
396038            },
396039            "considerations": {}
396040          }
396041        },
396042        {
396043          "type": "library",
396044          "bom-ref": "pkg:npm/inherits@2.0.4?package-id=f84cce1a2468e7",
396045          "supplier": {},
396046          "name": "inherits",
396047          "version": "2.0.4",
396048          "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",
396049          "licenses": [
396050            {
396051              "license": {
396052                "id": "ISC"
396053              }
396054            }
396055          ],
396056          "cpe": "cpe:2.3:a:inherits:inherits:2.0.4:*:*:*:*:*:*:*",
396057          "purl": "pkg:npm/inherits@2.0.4",
396058          "swid": {
396059            "attachment": {}
396060          },
396061          "pedigree": {},
396062          "externalReferences": [
396063            {
396064              "url": "git://github.com/isaacs/inherits",
396065              "type": "distribution"
396066            }
396067          ],
396068          "evidence": {},
396069          "signature": {
396070            "signature": {
396071              "publicKey": {}
396072            }
396073          },
396074          "modelCard": {
396075            "modelParameters": {
396076              "approach": {}
396077            },
396078            "quantitativeAnalysis": {
396079              "graphics": {}
396080            },
396081            "considerations": {}
396082          }
396083        },
396084        {
396085          "type": "library",
396086          "bom-ref": "pkg:npm/ini@1.3.8?package-id=b53c34fcbfe5b226",
396087          "supplier": {},
396088          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
396089          "name": "ini",
396090          "version": "1.3.8",
396091          "description": "An ini encoder/decoder for node",
396092          "licenses": [
396093            {
396094              "license": {
396095                "id": "ISC"
396096              }
396097            }
396098          ],
396099          "cpe": "cpe:2.3:a:isaacs:ini:1.3.8:*:*:*:*:*:*:*",
396100          "purl": "pkg:npm/ini@1.3.8",
396101          "swid": {
396102            "attachment": {}
396103          },
396104          "pedigree": {},
396105          "externalReferences": [
396106            {
396107              "url": "git://github.com/isaacs/ini.git",
396108              "type": "distribution"
396109            }
396110          ],
396111          "evidence": {},
396112          "signature": {
396113            "signature": {
396114              "publicKey": {}
396115            }
396116          },
396117          "modelCard": {
396118            "modelParameters": {
396119              "approach": {}
396120            },
396121            "quantitativeAnalysis": {
396122              "graphics": {}
396123            },
396124            "considerations": {}
396125          }
396126        },
396127        {
396128          "type": "library",
396129          "bom-ref": "pkg:npm/ini@3.0.1?package-id=143d409d5161792",
396130          "supplier": {},
396131          "author": "GitHub Inc.",
396132          "name": "ini",
396133          "version": "3.0.1",
396134          "description": "An ini encoder/decoder for node",
396135          "licenses": [
396136            {
396137              "license": {
396138                "id": "ISC"
396139              }
396140            }
396141          ],
396142          "cpe": "cpe:2.3:a:ini:ini:3.0.1:*:*:*:*:*:*:*",
396143          "purl": "pkg:npm/ini@3.0.1",
396144          "swid": {
396145            "attachment": {}
396146          },
396147          "pedigree": {},
396148          "externalReferences": [
396149            {
396150              "url": "https://github.com/npm/ini.git",
396151              "type": "distribution"
396152            }
396153          ],
396154          "evidence": {},
396155          "signature": {
396156            "signature": {
396157              "publicKey": {}
396158            }
396159          },
396160          "modelCard": {
396161            "modelParameters": {
396162              "approach": {}
396163            },
396164            "quantitativeAnalysis": {
396165              "graphics": {}
396166            },
396167            "considerations": {}
396168          }
396169        },
396170        {
396171          "type": "library",
396172          "bom-ref": "pkg:npm/init-package-json@3.0.2?package-id=6836db1e46d935b6",
396173          "supplier": {},
396174          "author": "GitHub Inc.",
396175          "name": "init-package-json",
396176          "version": "3.0.2",
396177          "description": "A node module to get your node module started",
396178          "licenses": [
396179            {
396180              "license": {
396181                "id": "ISC"
396182              }
396183            }
396184          ],
396185          "cpe": "cpe:2.3:a:init-package-json:init-package-json:3.0.2:*:*:*:*:*:*:*",
396186          "purl": "pkg:npm/init-package-json@3.0.2",
396187          "swid": {
396188            "attachment": {}
396189          },
396190          "pedigree": {},
396191          "externalReferences": [
396192            {
396193              "url": "https://github.com/npm/init-package-json.git",
396194              "type": "distribution"
396195            }
396196          ],
396197          "evidence": {},
396198          "signature": {
396199            "signature": {
396200              "publicKey": {}
396201            }
396202          },
396203          "modelCard": {
396204            "modelParameters": {
396205              "approach": {}
396206            },
396207            "quantitativeAnalysis": {
396208              "graphics": {}
396209            },
396210            "considerations": {}
396211          }
396212        },
396213        {
396214          "type": "library",
396215          "bom-ref": "pkg:npm/into-stream@3.1.0?package-id=749ae911dc171415",
396216          "supplier": {},
396217          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
396218          "name": "into-stream",
396219          "version": "3.1.0",
396220          "description": "Convert a buffer/string/array/object/iterable/promise into a stream",
396221          "licenses": [
396222            {
396223              "license": {
396224                "id": "MIT"
396225              }
396226            }
396227          ],
396228          "cpe": "cpe:2.3:a:into-stream:into-stream:3.1.0:*:*:*:*:*:*:*",
396229          "purl": "pkg:npm/into-stream@3.1.0",
396230          "swid": {
396231            "attachment": {}
396232          },
396233          "pedigree": {},
396234          "externalReferences": [
396235            {
396236              "url": "sindresorhus/into-stream",
396237              "type": "distribution"
396238            }
396239          ],
396240          "evidence": {},
396241          "signature": {
396242            "signature": {
396243              "publicKey": {}
396244            }
396245          },
396246          "modelCard": {
396247            "modelParameters": {
396248              "approach": {}
396249            },
396250            "quantitativeAnalysis": {
396251              "graphics": {}
396252            },
396253            "considerations": {}
396254          }
396255        },
396256        {
396257          "type": "library",
396258          "bom-ref": "pkg:npm/ip@2.0.0?package-id=218d1c05ea387b3c",
396259          "supplier": {},
396260          "author": "Fedor Indutny \u003cfedor@indutny.com\u003e",
396261          "name": "ip",
396262          "version": "2.0.0",
396263          "licenses": [
396264            {
396265              "license": {
396266                "id": "MIT"
396267              }
396268            }
396269          ],
396270          "cpe": "cpe:2.3:a:indutny:ip:2.0.0:*:*:*:*:*:*:*",
396271          "purl": "pkg:npm/ip@2.0.0",
396272          "swid": {
396273            "attachment": {}
396274          },
396275          "pedigree": {},
396276          "externalReferences": [
396277            {
396278              "url": "http://github.com/indutny/node-ip.git",
396279              "type": "distribution"
396280            },
396281            {
396282              "url": "https://github.com/indutny/node-ip",
396283              "type": "website"
396284            }
396285          ],
396286          "evidence": {},
396287          "signature": {
396288            "signature": {
396289              "publicKey": {}
396290            }
396291          },
396292          "modelCard": {
396293            "modelParameters": {
396294              "approach": {}
396295            },
396296            "quantitativeAnalysis": {
396297              "graphics": {}
396298            },
396299            "considerations": {}
396300          }
396301        },
396302        {
396303          "type": "library",
396304          "bom-ref": "pkg:npm/ip-regex@4.3.0?package-id=ce63365b733beafc",
396305          "supplier": {},
396306          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
396307          "name": "ip-regex",
396308          "version": "4.3.0",
396309          "description": "Regular expression for matching IP addresses (IPv4 \u0026 IPv6)",
396310          "licenses": [
396311            {
396312              "license": {
396313                "id": "MIT"
396314              }
396315            }
396316          ],
396317          "cpe": "cpe:2.3:a:ip-regex:ip-regex:4.3.0:*:*:*:*:*:*:*",
396318          "purl": "pkg:npm/ip-regex@4.3.0",
396319          "swid": {
396320            "attachment": {}
396321          },
396322          "pedigree": {},
396323          "externalReferences": [
396324            {
396325              "url": "sindresorhus/ip-regex",
396326              "type": "distribution"
396327            }
396328          ],
396329          "evidence": {},
396330          "signature": {
396331            "signature": {
396332              "publicKey": {}
396333            }
396334          },
396335          "modelCard": {
396336            "modelParameters": {
396337              "approach": {}
396338            },
396339            "quantitativeAnalysis": {
396340              "graphics": {}
396341            },
396342            "considerations": {}
396343          }
396344        },
396345        {
396346          "type": "library",
396347          "bom-ref": "pkg:npm/ipaddr.js@1.9.1?package-id=4e7082f9d0731706",
396348          "supplier": {},
396349          "author": "whitequark \u003cwhitequark@whitequark.org\u003e",
396350          "name": "ipaddr.js",
396351          "version": "1.9.1",
396352          "description": "A library for manipulating IPv4 and IPv6 addresses in JavaScript.",
396353          "licenses": [
396354            {
396355              "license": {
396356                "id": "MIT"
396357              }
396358            }
396359          ],
396360          "cpe": "cpe:2.3:a:whitequark:ipaddr.js:1.9.1:*:*:*:*:*:*:*",
396361          "purl": "pkg:npm/ipaddr.js@1.9.1",
396362          "swid": {
396363            "attachment": {}
396364          },
396365          "pedigree": {},
396366          "externalReferences": [
396367            {
396368              "url": "git://github.com/whitequark/ipaddr.js",
396369              "type": "distribution"
396370            }
396371          ],
396372          "evidence": {},
396373          "signature": {
396374            "signature": {
396375              "publicKey": {}
396376            }
396377          },
396378          "modelCard": {
396379            "modelParameters": {
396380              "approach": {}
396381            },
396382            "quantitativeAnalysis": {
396383              "graphics": {}
396384            },
396385            "considerations": {}
396386          }
396387        },
396388        {
396389          "type": "library",
396390          "bom-ref": "pkg:npm/is-ci@2.0.0?package-id=2d6f4f2f9863d72e",
396391          "supplier": {},
396392          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
396393          "name": "is-ci",
396394          "version": "2.0.0",
396395          "description": "Detect if the current environment is a CI server",
396396          "licenses": [
396397            {
396398              "license": {
396399                "id": "MIT"
396400              }
396401            }
396402          ],
396403          "cpe": "cpe:2.3:a:watson:is-ci:2.0.0:*:*:*:*:*:*:*",
396404          "purl": "pkg:npm/is-ci@2.0.0",
396405          "swid": {
396406            "attachment": {}
396407          },
396408          "pedigree": {},
396409          "externalReferences": [
396410            {
396411              "url": "https://github.com/watson/is-ci.git",
396412              "type": "distribution"
396413            },
396414            {
396415              "url": "https://github.com/watson/is-ci",
396416              "type": "website"
396417            }
396418          ],
396419          "evidence": {},
396420          "signature": {
396421            "signature": {
396422              "publicKey": {}
396423            }
396424          },
396425          "modelCard": {
396426            "modelParameters": {
396427              "approach": {}
396428            },
396429            "quantitativeAnalysis": {
396430              "graphics": {}
396431            },
396432            "considerations": {}
396433          }
396434        },
396435        {
396436          "type": "library",
396437          "bom-ref": "pkg:npm/is-cidr@4.0.2?package-id=b7267695f8ce1238",
396438          "supplier": {},
396439          "author": "silverwind \u003cme@silverwind.io\u003e",
396440          "name": "is-cidr",
396441          "version": "4.0.2",
396442          "description": "Check if a string is an IP address in CIDR notation",
396443          "licenses": [
396444            {
396445              "license": {
396446                "id": "BSD-2-Clause"
396447              }
396448            }
396449          ],
396450          "cpe": "cpe:2.3:a:is-cidr:is-cidr:4.0.2:*:*:*:*:*:*:*",
396451          "purl": "pkg:npm/is-cidr@4.0.2",
396452          "swid": {
396453            "attachment": {}
396454          },
396455          "pedigree": {},
396456          "externalReferences": [
396457            {
396458              "url": "silverwind/is-cidr",
396459              "type": "distribution"
396460            }
396461          ],
396462          "evidence": {},
396463          "signature": {
396464            "signature": {
396465              "publicKey": {}
396466            }
396467          },
396468          "modelCard": {
396469            "modelParameters": {
396470              "approach": {}
396471            },
396472            "quantitativeAnalysis": {
396473              "graphics": {}
396474            },
396475            "considerations": {}
396476          }
396477        },
396478        {
396479          "type": "library",
396480          "bom-ref": "pkg:npm/is-core-module@2.10.0?package-id=22642820ec847015",
396481          "supplier": {},
396482          "author": "Jordan Harband \u003cljharb@gmail.com\u003e",
396483          "name": "is-core-module",
396484          "version": "2.10.0",
396485          "description": "Is this specifier a node.js core module?",
396486          "licenses": [
396487            {
396488              "license": {
396489                "id": "MIT"
396490              }
396491            }
396492          ],
396493          "cpe": "cpe:2.3:a:is-core-module:is-core-module:2.10.0:*:*:*:*:*:*:*",
396494          "purl": "pkg:npm/is-core-module@2.10.0",
396495          "swid": {
396496            "attachment": {}
396497          },
396498          "pedigree": {},
396499          "externalReferences": [
396500            {
396501              "url": "git+https://github.com/inspect-js/is-core-module.git",
396502              "type": "distribution"
396503            },
396504            {
396505              "url": "https://github.com/inspect-js/is-core-module",
396506              "type": "website"
396507            }
396508          ],
396509          "evidence": {},
396510          "signature": {
396511            "signature": {
396512              "publicKey": {}
396513            }
396514          },
396515          "modelCard": {
396516            "modelParameters": {
396517              "approach": {}
396518            },
396519            "quantitativeAnalysis": {
396520              "graphics": {}
396521            },
396522            "considerations": {}
396523          }
396524        },
396525        {
396526          "type": "library",
396527          "bom-ref": "pkg:npm/is-docker@2.2.1?package-id=b80a4b4b32b6089e",
396528          "supplier": {},
396529          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
396530          "name": "is-docker",
396531          "version": "2.2.1",
396532          "description": "Check if the process is running inside a Docker container",
396533          "licenses": [
396534            {
396535              "license": {
396536                "id": "MIT"
396537              }
396538            }
396539          ],
396540          "cpe": "cpe:2.3:a:is-docker:is-docker:2.2.1:*:*:*:*:*:*:*",
396541          "purl": "pkg:npm/is-docker@2.2.1",
396542          "swid": {
396543            "attachment": {}
396544          },
396545          "pedigree": {},
396546          "externalReferences": [
396547            {
396548              "url": "sindresorhus/is-docker",
396549              "type": "distribution"
396550            }
396551          ],
396552          "evidence": {},
396553          "signature": {
396554            "signature": {
396555              "publicKey": {}
396556            }
396557          },
396558          "modelCard": {
396559            "modelParameters": {
396560              "approach": {}
396561            },
396562            "quantitativeAnalysis": {
396563              "graphics": {}
396564            },
396565            "considerations": {}
396566          }
396567        },
396568        {
396569          "type": "library",
396570          "bom-ref": "pkg:npm/is-extglob@2.1.1?package-id=be3168a7cd0ca82b",
396571          "supplier": {},
396572          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
396573          "name": "is-extglob",
396574          "version": "2.1.1",
396575          "description": "Returns true if a string has an extglob.",
396576          "licenses": [
396577            {
396578              "license": {
396579                "id": "MIT"
396580              }
396581            }
396582          ],
396583          "cpe": "cpe:2.3:a:jonschlinkert:is-extglob:2.1.1:*:*:*:*:*:*:*",
396584          "purl": "pkg:npm/is-extglob@2.1.1",
396585          "swid": {
396586            "attachment": {}
396587          },
396588          "pedigree": {},
396589          "externalReferences": [
396590            {
396591              "url": "jonschlinkert/is-extglob",
396592              "type": "distribution"
396593            },
396594            {
396595              "url": "https://github.com/jonschlinkert/is-extglob",
396596              "type": "website"
396597            }
396598          ],
396599          "evidence": {},
396600          "signature": {
396601            "signature": {
396602              "publicKey": {}
396603            }
396604          },
396605          "modelCard": {
396606            "modelParameters": {
396607              "approach": {}
396608            },
396609            "quantitativeAnalysis": {
396610              "graphics": {}
396611            },
396612            "considerations": {}
396613          }
396614        },
396615        {
396616          "type": "library",
396617          "bom-ref": "pkg:npm/is-fullwidth-code-point@3.0.0?package-id=f89f6ce8e80b50d",
396618          "supplier": {},
396619          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
396620          "name": "is-fullwidth-code-point",
396621          "version": "3.0.0",
396622          "description": "Check if the character represented by a given Unicode code point is fullwidth",
396623          "licenses": [
396624            {
396625              "license": {
396626                "id": "MIT"
396627              }
396628            }
396629          ],
396630          "cpe": "cpe:2.3:a:is-fullwidth-code-point:is-fullwidth-code-point:3.0.0:*:*:*:*:*:*:*",
396631          "purl": "pkg:npm/is-fullwidth-code-point@3.0.0",
396632          "swid": {
396633            "attachment": {}
396634          },
396635          "pedigree": {},
396636          "externalReferences": [
396637            {
396638              "url": "sindresorhus/is-fullwidth-code-point",
396639              "type": "distribution"
396640            }
396641          ],
396642          "evidence": {},
396643          "signature": {
396644            "signature": {
396645              "publicKey": {}
396646            }
396647          },
396648          "modelCard": {
396649            "modelParameters": {
396650              "approach": {}
396651            },
396652            "quantitativeAnalysis": {
396653              "graphics": {}
396654            },
396655            "considerations": {}
396656          }
396657        },
396658        {
396659          "type": "library",
396660          "bom-ref": "pkg:npm/is-glob@4.0.3?package-id=731881f3fe93be88",
396661          "supplier": {},
396662          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
396663          "name": "is-glob",
396664          "version": "4.0.3",
396665          "description": "Returns `true` if the given string looks like a glob pattern or an extglob pattern. This makes it easy to create code that only uses external modules like node-glob when necessary, resulting in much faster code execution and initialization time, and a better user experience.",
396666          "licenses": [
396667            {
396668              "license": {
396669                "id": "MIT"
396670              }
396671            }
396672          ],
396673          "cpe": "cpe:2.3:a:micromatch:is-glob:4.0.3:*:*:*:*:*:*:*",
396674          "purl": "pkg:npm/is-glob@4.0.3",
396675          "swid": {
396676            "attachment": {}
396677          },
396678          "pedigree": {},
396679          "externalReferences": [
396680            {
396681              "url": "micromatch/is-glob",
396682              "type": "distribution"
396683            },
396684            {
396685              "url": "https://github.com/micromatch/is-glob",
396686              "type": "website"
396687            }
396688          ],
396689          "evidence": {},
396690          "signature": {
396691            "signature": {
396692              "publicKey": {}
396693            }
396694          },
396695          "modelCard": {
396696            "modelParameters": {
396697              "approach": {}
396698            },
396699            "quantitativeAnalysis": {
396700              "graphics": {}
396701            },
396702            "considerations": {}
396703          }
396704        },
396705        {
396706          "type": "library",
396707          "bom-ref": "pkg:npm/is-lambda@1.0.1?package-id=841af64487227951",
396708          "supplier": {},
396709          "author": "Thomas Watson Steen \u003cw@tson.dk\u003e (https://twitter.com/wa7son)",
396710          "name": "is-lambda",
396711          "version": "1.0.1",
396712          "description": "Detect if your code is running on an AWS Lambda server",
396713          "licenses": [
396714            {
396715              "license": {
396716                "id": "MIT"
396717              }
396718            }
396719          ],
396720          "cpe": "cpe:2.3:a:is-lambda:is-lambda:1.0.1:*:*:*:*:*:*:*",
396721          "purl": "pkg:npm/is-lambda@1.0.1",
396722          "swid": {
396723            "attachment": {}
396724          },
396725          "pedigree": {},
396726          "externalReferences": [
396727            {
396728              "url": "https://github.com/watson/is-lambda.git",
396729              "type": "distribution"
396730            },
396731            {
396732              "url": "https://github.com/watson/is-lambda",
396733              "type": "website"
396734            }
396735          ],
396736          "evidence": {},
396737          "signature": {
396738            "signature": {
396739              "publicKey": {}
396740            }
396741          },
396742          "modelCard": {
396743            "modelParameters": {
396744              "approach": {}
396745            },
396746            "quantitativeAnalysis": {
396747              "graphics": {}
396748            },
396749            "considerations": {}
396750          }
396751        },
396752        {
396753          "type": "library",
396754          "bom-ref": "pkg:npm/is-natural-number@4.0.1?package-id=870646357a76bd97",
396755          "supplier": {},
396756          "author": "Shinnosuke Watanabe (https://github.com/shinnn)",
396757          "name": "is-natural-number",
396758          "version": "4.0.1",
396759          "description": "Check if a value is a natural number",
396760          "licenses": [
396761            {
396762              "license": {
396763                "id": "MIT"
396764              }
396765            }
396766          ],
396767          "cpe": "cpe:2.3:a:is-natural-number:is-natural-number:4.0.1:*:*:*:*:*:*:*",
396768          "purl": "pkg:npm/is-natural-number@4.0.1",
396769          "swid": {
396770            "attachment": {}
396771          },
396772          "pedigree": {},
396773          "externalReferences": [
396774            {
396775              "url": "shinnn/is-natural-number.js",
396776              "type": "distribution"
396777            }
396778          ],
396779          "evidence": {},
396780          "signature": {
396781            "signature": {
396782              "publicKey": {}
396783            }
396784          },
396785          "modelCard": {
396786            "modelParameters": {
396787              "approach": {}
396788            },
396789            "quantitativeAnalysis": {
396790              "graphics": {}
396791            },
396792            "considerations": {}
396793          }
396794        },
396795        {
396796          "type": "library",
396797          "bom-ref": "pkg:npm/is-number@7.0.0?package-id=17615dc83613bdb3",
396798          "supplier": {},
396799          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
396800          "name": "is-number",
396801          "version": "7.0.0",
396802          "description": "Returns true if a number or string value is a finite number. Useful for regex matches, parsing, user input, etc.",
396803          "licenses": [
396804            {
396805              "license": {
396806                "id": "MIT"
396807              }
396808            }
396809          ],
396810          "cpe": "cpe:2.3:a:jonschlinkert:is-number:7.0.0:*:*:*:*:*:*:*",
396811          "purl": "pkg:npm/is-number@7.0.0",
396812          "swid": {
396813            "attachment": {}
396814          },
396815          "pedigree": {},
396816          "externalReferences": [
396817            {
396818              "url": "jonschlinkert/is-number",
396819              "type": "distribution"
396820            },
396821            {
396822              "url": "https://github.com/jonschlinkert/is-number",
396823              "type": "website"
396824            }
396825          ],
396826          "evidence": {},
396827          "signature": {
396828            "signature": {
396829              "publicKey": {}
396830            }
396831          },
396832          "modelCard": {
396833            "modelParameters": {
396834              "approach": {}
396835            },
396836            "quantitativeAnalysis": {
396837              "graphics": {}
396838            },
396839            "considerations": {}
396840          }
396841        },
396842        {
396843          "type": "library",
396844          "bom-ref": "pkg:npm/is-object@1.0.2?package-id=a8282bc299d5891b",
396845          "supplier": {},
396846          "author": "Raynos \u003craynos2@gmail.com\u003e",
396847          "name": "is-object",
396848          "version": "1.0.2",
396849          "description": "Checks whether a value is an object",
396850          "licenses": [
396851            {
396852              "license": {
396853                "id": "MIT"
396854              }
396855            }
396856          ],
396857          "cpe": "cpe:2.3:a:inspect-js:is-object:1.0.2:*:*:*:*:*:*:*",
396858          "purl": "pkg:npm/is-object@1.0.2",
396859          "swid": {
396860            "attachment": {}
396861          },
396862          "pedigree": {},
396863          "externalReferences": [
396864            {
396865              "url": "git://github.com/inspect-js/is-object.git",
396866              "type": "distribution"
396867            },
396868            {
396869              "url": "https://github.com/inspect-js/is-object",
396870              "type": "website"
396871            }
396872          ],
396873          "evidence": {},
396874          "signature": {
396875            "signature": {
396876              "publicKey": {}
396877            }
396878          },
396879          "modelCard": {
396880            "modelParameters": {
396881              "approach": {}
396882            },
396883            "quantitativeAnalysis": {
396884              "graphics": {}
396885            },
396886            "considerations": {}
396887          }
396888        },
396889        {
396890          "type": "library",
396891          "bom-ref": "pkg:npm/is-plain-obj@1.1.0?package-id=2b5099a344c93333",
396892          "supplier": {},
396893          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
396894          "name": "is-plain-obj",
396895          "version": "1.1.0",
396896          "description": "Check if a value is a plain object",
396897          "licenses": [
396898            {
396899              "license": {
396900                "id": "MIT"
396901              }
396902            }
396903          ],
396904          "cpe": "cpe:2.3:a:is-plain-obj:is-plain-obj:1.1.0:*:*:*:*:*:*:*",
396905          "purl": "pkg:npm/is-plain-obj@1.1.0",
396906          "swid": {
396907            "attachment": {}
396908          },
396909          "pedigree": {},
396910          "externalReferences": [
396911            {
396912              "url": "sindresorhus/is-plain-obj",
396913              "type": "distribution"
396914            }
396915          ],
396916          "evidence": {},
396917          "signature": {
396918            "signature": {
396919              "publicKey": {}
396920            }
396921          },
396922          "modelCard": {
396923            "modelParameters": {
396924              "approach": {}
396925            },
396926            "quantitativeAnalysis": {
396927              "graphics": {}
396928            },
396929            "considerations": {}
396930          }
396931        },
396932        {
396933          "type": "library",
396934          "bom-ref": "pkg:npm/is-retry-allowed@1.2.0?package-id=d43de39fded4048f",
396935          "supplier": {},
396936          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
396937          "name": "is-retry-allowed",
396938          "version": "1.2.0",
396939          "description": "Is retry allowed for Error?",
396940          "licenses": [
396941            {
396942              "license": {
396943                "id": "MIT"
396944              }
396945            }
396946          ],
396947          "cpe": "cpe:2.3:a:is-retry-allowed:is-retry-allowed:1.2.0:*:*:*:*:*:*:*",
396948          "purl": "pkg:npm/is-retry-allowed@1.2.0",
396949          "swid": {
396950            "attachment": {}
396951          },
396952          "pedigree": {},
396953          "externalReferences": [
396954            {
396955              "url": "floatdrop/is-retry-allowed",
396956              "type": "distribution"
396957            }
396958          ],
396959          "evidence": {},
396960          "signature": {
396961            "signature": {
396962              "publicKey": {}
396963            }
396964          },
396965          "modelCard": {
396966            "modelParameters": {
396967              "approach": {}
396968            },
396969            "quantitativeAnalysis": {
396970              "graphics": {}
396971            },
396972            "considerations": {}
396973          }
396974        },
396975        {
396976          "type": "library",
396977          "bom-ref": "pkg:npm/is-stream@1.1.0?package-id=283db8b57c629711",
396978          "supplier": {},
396979          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
396980          "name": "is-stream",
396981          "version": "1.1.0",
396982          "description": "Check if something is a Node.js stream",
396983          "licenses": [
396984            {
396985              "license": {
396986                "id": "MIT"
396987              }
396988            }
396989          ],
396990          "cpe": "cpe:2.3:a:is-stream:is-stream:1.1.0:*:*:*:*:*:*:*",
396991          "purl": "pkg:npm/is-stream@1.1.0",
396992          "swid": {
396993            "attachment": {}
396994          },
396995          "pedigree": {},
396996          "externalReferences": [
396997            {
396998              "url": "sindresorhus/is-stream",
396999              "type": "distribution"
397000            }
397001          ],
397002          "evidence": {},
397003          "signature": {
397004            "signature": {
397005              "publicKey": {}
397006            }
397007          },
397008          "modelCard": {
397009            "modelParameters": {
397010              "approach": {}
397011            },
397012            "quantitativeAnalysis": {
397013              "graphics": {}
397014            },
397015            "considerations": {}
397016          }
397017        },
397018        {
397019          "type": "library",
397020          "bom-ref": "pkg:npm/is-typedarray@1.0.0?package-id=7c7a7687a151a58f",
397021          "supplier": {},
397022          "author": "Hugh Kennedy \u003chughskennedy@gmail.com\u003e (http://hughsk.io/)",
397023          "name": "is-typedarray",
397024          "version": "1.0.0",
397025          "description": "Detect whether or not an object is a Typed Array",
397026          "licenses": [
397027            {
397028              "license": {
397029                "id": "MIT"
397030              }
397031            }
397032          ],
397033          "cpe": "cpe:2.3:a:is-typedarray:is-typedarray:1.0.0:*:*:*:*:*:*:*",
397034          "purl": "pkg:npm/is-typedarray@1.0.0",
397035          "swid": {
397036            "attachment": {}
397037          },
397038          "pedigree": {},
397039          "externalReferences": [
397040            {
397041              "url": "git://github.com/hughsk/is-typedarray.git",
397042              "type": "distribution"
397043            },
397044            {
397045              "url": "https://github.com/hughsk/is-typedarray",
397046              "type": "website"
397047            }
397048          ],
397049          "evidence": {},
397050          "signature": {
397051            "signature": {
397052              "publicKey": {}
397053            }
397054          },
397055          "modelCard": {
397056            "modelParameters": {
397057              "approach": {}
397058            },
397059            "quantitativeAnalysis": {
397060              "graphics": {}
397061            },
397062            "considerations": {}
397063          }
397064        },
397065        {
397066          "type": "library",
397067          "bom-ref": "pkg:npm/is-wsl@2.2.0?package-id=617b7a7c73aef067",
397068          "supplier": {},
397069          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
397070          "name": "is-wsl",
397071          "version": "2.2.0",
397072          "description": "Check if the process is running inside Windows Subsystem for Linux (Bash on Windows)",
397073          "licenses": [
397074            {
397075              "license": {
397076                "id": "MIT"
397077              }
397078            }
397079          ],
397080          "cpe": "cpe:2.3:a:is-wsl:is-wsl:2.2.0:*:*:*:*:*:*:*",
397081          "purl": "pkg:npm/is-wsl@2.2.0",
397082          "swid": {
397083            "attachment": {}
397084          },
397085          "pedigree": {},
397086          "externalReferences": [
397087            {
397088              "url": "sindresorhus/is-wsl",
397089              "type": "distribution"
397090            }
397091          ],
397092          "evidence": {},
397093          "signature": {
397094            "signature": {
397095              "publicKey": {}
397096            }
397097          },
397098          "modelCard": {
397099            "modelParameters": {
397100              "approach": {}
397101            },
397102            "quantitativeAnalysis": {
397103              "graphics": {}
397104            },
397105            "considerations": {}
397106          }
397107        },
397108        {
397109          "type": "library",
397110          "bom-ref": "pkg:npm/isarray@1.0.0?package-id=91eedced5ea0d9f4",
397111          "supplier": {},
397112          "author": "Julian Gruber \u003cmail@juliangruber.com\u003e (http://juliangruber.com)",
397113          "name": "isarray",
397114          "version": "1.0.0",
397115          "description": "Array#isArray for older browsers",
397116          "licenses": [
397117            {
397118              "license": {
397119                "id": "MIT"
397120              }
397121            }
397122          ],
397123          "cpe": "cpe:2.3:a:juliangruber:isarray:1.0.0:*:*:*:*:*:*:*",
397124          "purl": "pkg:npm/isarray@1.0.0",
397125          "swid": {
397126            "attachment": {}
397127          },
397128          "pedigree": {},
397129          "externalReferences": [
397130            {
397131              "url": "git://github.com/juliangruber/isarray.git",
397132              "type": "distribution"
397133            },
397134            {
397135              "url": "https://github.com/juliangruber/isarray",
397136              "type": "website"
397137            }
397138          ],
397139          "evidence": {},
397140          "signature": {
397141            "signature": {
397142              "publicKey": {}
397143            }
397144          },
397145          "modelCard": {
397146            "modelParameters": {
397147              "approach": {}
397148            },
397149            "quantitativeAnalysis": {
397150              "graphics": {}
397151            },
397152            "considerations": {}
397153          }
397154        },
397155        {
397156          "type": "library",
397157          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=cac2857ecac9cad9",
397158          "supplier": {},
397159          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
397160          "name": "isexe",
397161          "version": "2.0.0",
397162          "description": "Minimal module to check if a file is executable.",
397163          "licenses": [
397164            {
397165              "license": {
397166                "id": "ISC"
397167              }
397168            }
397169          ],
397170          "cpe": "cpe:2.3:a:isaacs:isexe:2.0.0:*:*:*:*:*:*:*",
397171          "purl": "pkg:npm/isexe@2.0.0",
397172          "swid": {
397173            "attachment": {}
397174          },
397175          "pedigree": {},
397176          "externalReferences": [
397177            {
397178              "url": "git+https://github.com/isaacs/isexe.git",
397179              "type": "distribution"
397180            },
397181            {
397182              "url": "https://github.com/isaacs/isexe#readme",
397183              "type": "website"
397184            }
397185          ],
397186          "evidence": {},
397187          "signature": {
397188            "signature": {
397189              "publicKey": {}
397190            }
397191          },
397192          "modelCard": {
397193            "modelParameters": {
397194              "approach": {}
397195            },
397196            "quantitativeAnalysis": {
397197              "graphics": {}
397198            },
397199            "considerations": {}
397200          }
397201        },
397202        {
397203          "type": "library",
397204          "bom-ref": "pkg:npm/isexe@2.0.0?package-id=2f3fac93ebc9c581",
397205          "supplier": {},
397206          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
397207          "name": "isexe",
397208          "version": "2.0.0",
397209          "description": "Minimal module to check if a file is executable.",
397210          "licenses": [
397211            {
397212              "license": {
397213                "id": "ISC"
397214              }
397215            }
397216          ],
397217          "cpe": "cpe:2.3:a:isaacs:isexe:2.0.0:*:*:*:*:*:*:*",
397218          "purl": "pkg:npm/isexe@2.0.0",
397219          "swid": {
397220            "attachment": {}
397221          },
397222          "pedigree": {},
397223          "externalReferences": [
397224            {
397225              "url": "git+https://github.com/isaacs/isexe.git",
397226              "type": "distribution"
397227            },
397228            {
397229              "url": "https://github.com/isaacs/isexe#readme",
397230              "type": "website"
397231            }
397232          ],
397233          "evidence": {},
397234          "signature": {
397235            "signature": {
397236              "publicKey": {}
397237            }
397238          },
397239          "modelCard": {
397240            "modelParameters": {
397241              "approach": {}
397242            },
397243            "quantitativeAnalysis": {
397244              "graphics": {}
397245            },
397246            "considerations": {}
397247          }
397248        },
397249        {
397250          "type": "library",
397251          "bom-ref": "pkg:npm/isstream@0.1.2?package-id=60627e35aae479e",
397252          "supplier": {},
397253          "author": "Rod Vagg \u003crod@vagg.org\u003e",
397254          "name": "isstream",
397255          "version": "0.1.2",
397256          "description": "Determine if an object is a Stream",
397257          "licenses": [
397258            {
397259              "license": {
397260                "id": "MIT"
397261              }
397262            }
397263          ],
397264          "cpe": "cpe:2.3:a:isstream:isstream:0.1.2:*:*:*:*:*:*:*",
397265          "purl": "pkg:npm/isstream@0.1.2",
397266          "swid": {
397267            "attachment": {}
397268          },
397269          "pedigree": {},
397270          "externalReferences": [
397271            {
397272              "url": "https://github.com/rvagg/isstream.git",
397273              "type": "distribution"
397274            },
397275            {
397276              "url": "https://github.com/rvagg/isstream",
397277              "type": "website"
397278            }
397279          ],
397280          "evidence": {},
397281          "signature": {
397282            "signature": {
397283              "publicKey": {}
397284            }
397285          },
397286          "modelCard": {
397287            "modelParameters": {
397288              "approach": {}
397289            },
397290            "quantitativeAnalysis": {
397291              "graphics": {}
397292            },
397293            "considerations": {}
397294          }
397295        },
397296        {
397297          "type": "library",
397298          "bom-ref": "pkg:npm/isurl@1.0.0?package-id=afce3740246f9d34",
397299          "supplier": {},
397300          "author": "Steven Vachon \u003ccontact@svachon.com\u003e (https://www.svachon.com/)",
397301          "name": "isurl",
397302          "version": "1.0.0",
397303          "description": "Checks whether a value is a WHATWG URL.",
397304          "licenses": [
397305            {
397306              "license": {
397307                "id": "MIT"
397308              }
397309            }
397310          ],
397311          "cpe": "cpe:2.3:a:isurl:isurl:1.0.0:*:*:*:*:*:*:*",
397312          "purl": "pkg:npm/isurl@1.0.0",
397313          "swid": {
397314            "attachment": {}
397315          },
397316          "pedigree": {},
397317          "externalReferences": [
397318            {
397319              "url": "stevenvachon/isurl",
397320              "type": "distribution"
397321            }
397322          ],
397323          "evidence": {},
397324          "signature": {
397325            "signature": {
397326              "publicKey": {}
397327            }
397328          },
397329          "modelCard": {
397330            "modelParameters": {
397331              "approach": {}
397332            },
397333            "quantitativeAnalysis": {
397334              "graphics": {}
397335            },
397336            "considerations": {}
397337          }
397338        },
397339        {
397340          "type": "library",
397341          "bom-ref": "pkg:npm/jsbn@0.1.1?package-id=f3ac3ad288be4178",
397342          "supplier": {},
397343          "author": "Tom Wu",
397344          "name": "jsbn",
397345          "version": "0.1.1",
397346          "description": "The jsbn library is a fast, portable implementation of large-number math in pure JavaScript, enabling public-key crypto and other applications on desktop and mobile browsers.",
397347          "licenses": [
397348            {
397349              "license": {
397350                "id": "MIT"
397351              }
397352            }
397353          ],
397354          "cpe": "cpe:2.3:a:andyperlitch:jsbn:0.1.1:*:*:*:*:*:*:*",
397355          "purl": "pkg:npm/jsbn@0.1.1",
397356          "swid": {
397357            "attachment": {}
397358          },
397359          "pedigree": {},
397360          "externalReferences": [
397361            {
397362              "url": "https://github.com/andyperlitch/jsbn.git",
397363              "type": "distribution"
397364            }
397365          ],
397366          "evidence": {},
397367          "signature": {
397368            "signature": {
397369              "publicKey": {}
397370            }
397371          },
397372          "modelCard": {
397373            "modelParameters": {
397374              "approach": {}
397375            },
397376            "quantitativeAnalysis": {
397377              "graphics": {}
397378            },
397379            "considerations": {}
397380          }
397381        },
397382        {
397383          "type": "library",
397384          "bom-ref": "pkg:npm/json-buffer@3.0.0?package-id=3593402b7fb37053",
397385          "supplier": {},
397386          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (http://dominictarr.com)",
397387          "name": "json-buffer",
397388          "version": "3.0.0",
397389          "description": "JSON parse \u0026 stringify that supports binary via bops \u0026 base64",
397390          "licenses": [
397391            {
397392              "license": {
397393                "id": "MIT"
397394              }
397395            }
397396          ],
397397          "cpe": "cpe:2.3:a:dominictarr:json-buffer:3.0.0:*:*:*:*:*:*:*",
397398          "purl": "pkg:npm/json-buffer@3.0.0",
397399          "swid": {
397400            "attachment": {}
397401          },
397402          "pedigree": {},
397403          "externalReferences": [
397404            {
397405              "url": "git://github.com/dominictarr/json-buffer.git",
397406              "type": "distribution"
397407            },
397408            {
397409              "url": "https://github.com/dominictarr/json-buffer",
397410              "type": "website"
397411            }
397412          ],
397413          "evidence": {},
397414          "signature": {
397415            "signature": {
397416              "publicKey": {}
397417            }
397418          },
397419          "modelCard": {
397420            "modelParameters": {
397421              "approach": {}
397422            },
397423            "quantitativeAnalysis": {
397424              "graphics": {}
397425            },
397426            "considerations": {}
397427          }
397428        },
397429        {
397430          "type": "library",
397431          "bom-ref": "pkg:npm/json-buffer@3.0.1?package-id=b22046d084b75b04",
397432          "supplier": {},
397433          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (http://dominictarr.com)",
397434          "name": "json-buffer",
397435          "version": "3.0.1",
397436          "description": "JSON parse \u0026 stringify that supports binary via bops \u0026 base64",
397437          "licenses": [
397438            {
397439              "license": {
397440                "id": "MIT"
397441              }
397442            }
397443          ],
397444          "cpe": "cpe:2.3:a:dominictarr:json-buffer:3.0.1:*:*:*:*:*:*:*",
397445          "purl": "pkg:npm/json-buffer@3.0.1",
397446          "swid": {
397447            "attachment": {}
397448          },
397449          "pedigree": {},
397450          "externalReferences": [
397451            {
397452              "url": "git://github.com/dominictarr/json-buffer.git",
397453              "type": "distribution"
397454            },
397455            {
397456              "url": "https://github.com/dominictarr/json-buffer",
397457              "type": "website"
397458            }
397459          ],
397460          "evidence": {},
397461          "signature": {
397462            "signature": {
397463              "publicKey": {}
397464            }
397465          },
397466          "modelCard": {
397467            "modelParameters": {
397468              "approach": {}
397469            },
397470            "quantitativeAnalysis": {
397471              "graphics": {}
397472            },
397473            "considerations": {}
397474          }
397475        },
397476        {
397477          "type": "library",
397478          "bom-ref": "pkg:apk/alpine/json-c@0.16-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=597ca41764540973",
397479          "supplier": {},
397480          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
397481          "name": "json-c",
397482          "version": "0.16-r0",
397483          "description": "A JSON implementation in C",
397484          "licenses": [
397485            {
397486              "license": {
397487                "id": "MIT"
397488              }
397489            }
397490          ],
397491          "cpe": "cpe:2.3:a:json-c:json-c:0.16-r0:*:*:*:*:*:*:*",
397492          "purl": "pkg:apk/alpine/json-c@0.16-r0?arch=x86_64\u0026distro=alpine-3.16.5",
397493          "swid": {
397494            "attachment": {}
397495          },
397496          "pedigree": {},
397497          "externalReferences": [
397498            {
397499              "url": "https://github.com/json-c/json-c/wiki",
397500              "type": "distribution"
397501            }
397502          ],
397503          "evidence": {},
397504          "signature": {
397505            "signature": {
397506              "publicKey": {}
397507            }
397508          },
397509          "modelCard": {
397510            "modelParameters": {
397511              "approach": {}
397512            },
397513            "quantitativeAnalysis": {
397514              "graphics": {}
397515            },
397516            "considerations": {}
397517          }
397518        },
397519        {
397520          "type": "library",
397521          "bom-ref": "pkg:npm/json-parse-even-better-errors@2.3.1?package-id=abf07f33abe9247b",
397522          "supplier": {},
397523          "author": "Kat Marchán \u003ckzm@zkat.tech\u003e",
397524          "name": "json-parse-even-better-errors",
397525          "version": "2.3.1",
397526          "description": "JSON.parse with context information on error",
397527          "licenses": [
397528            {
397529              "license": {
397530                "id": "MIT"
397531              }
397532            }
397533          ],
397534          "cpe": "cpe:2.3:a:json-parse-even-better-errors:json-parse-even-better-errors:2.3.1:*:*:*:*:*:*:*",
397535          "purl": "pkg:npm/json-parse-even-better-errors@2.3.1",
397536          "swid": {
397537            "attachment": {}
397538          },
397539          "pedigree": {},
397540          "externalReferences": [
397541            {
397542              "url": "https://github.com/npm/json-parse-even-better-errors",
397543              "type": "distribution"
397544            }
397545          ],
397546          "evidence": {},
397547          "signature": {
397548            "signature": {
397549              "publicKey": {}
397550            }
397551          },
397552          "modelCard": {
397553            "modelParameters": {
397554              "approach": {}
397555            },
397556            "quantitativeAnalysis": {
397557              "graphics": {}
397558            },
397559            "considerations": {}
397560          }
397561        },
397562        {
397563          "type": "library",
397564          "bom-ref": "pkg:npm/json-schema@0.4.0?package-id=f6da4a26d6afa2e4",
397565          "supplier": {},
397566          "author": "Kris Zyp",
397567          "name": "json-schema",
397568          "version": "0.4.0",
397569          "description": "JSON Schema validation and specifications",
397570          "licenses": [
397571            {
397572              "license": {
397573                "name": "(AFL-2.1 OR BSD-3-Clause)"
397574              }
397575            }
397576          ],
397577          "cpe": "cpe:2.3:a:json-schema:json-schema:0.4.0:*:*:*:*:*:*:*",
397578          "purl": "pkg:npm/json-schema@0.4.0",
397579          "swid": {
397580            "attachment": {}
397581          },
397582          "pedigree": {},
397583          "externalReferences": [
397584            {
397585              "url": "http://github.com/kriszyp/json-schema",
397586              "type": "distribution"
397587            }
397588          ],
397589          "evidence": {},
397590          "signature": {
397591            "signature": {
397592              "publicKey": {}
397593            }
397594          },
397595          "modelCard": {
397596            "modelParameters": {
397597              "approach": {}
397598            },
397599            "quantitativeAnalysis": {
397600              "graphics": {}
397601            },
397602            "considerations": {}
397603          }
397604        },
397605        {
397606          "type": "library",
397607          "bom-ref": "pkg:npm/json-schema-traverse@0.4.1?package-id=3b5dfc07da3fba89",
397608          "supplier": {},
397609          "author": "Evgeny Poberezkin",
397610          "name": "json-schema-traverse",
397611          "version": "0.4.1",
397612          "description": "Traverse JSON Schema passing each schema object to callback",
397613          "licenses": [
397614            {
397615              "license": {
397616                "id": "MIT"
397617              }
397618            }
397619          ],
397620          "cpe": "cpe:2.3:a:json-schema-traverse:json-schema-traverse:0.4.1:*:*:*:*:*:*:*",
397621          "purl": "pkg:npm/json-schema-traverse@0.4.1",
397622          "swid": {
397623            "attachment": {}
397624          },
397625          "pedigree": {},
397626          "externalReferences": [
397627            {
397628              "url": "git+https://github.com/epoberezkin/json-schema-traverse.git",
397629              "type": "distribution"
397630            },
397631            {
397632              "url": "https://github.com/epoberezkin/json-schema-traverse#readme",
397633              "type": "website"
397634            }
397635          ],
397636          "evidence": {},
397637          "signature": {
397638            "signature": {
397639              "publicKey": {}
397640            }
397641          },
397642          "modelCard": {
397643            "modelParameters": {
397644              "approach": {}
397645            },
397646            "quantitativeAnalysis": {
397647              "graphics": {}
397648            },
397649            "considerations": {}
397650          }
397651        },
397652        {
397653          "type": "library",
397654          "bom-ref": "pkg:npm/json-stream@1.0.0?package-id=1d1cbbfe09ed72b0",
397655          "supplier": {},
397656          "author": "Maciej Małecki \u003cme@mmalecki.com\u003e",
397657          "name": "json-stream",
397658          "version": "1.0.0",
397659          "description": "New line-delimeted JSON parser with a stream interface",
397660          "licenses": [
397661            {
397662              "license": {
397663                "id": "MIT"
397664              }
397665            }
397666          ],
397667          "cpe": "cpe:2.3:a:json-stream:json-stream:1.0.0:*:*:*:*:*:*:*",
397668          "purl": "pkg:npm/json-stream@1.0.0",
397669          "swid": {
397670            "attachment": {}
397671          },
397672          "pedigree": {},
397673          "externalReferences": [
397674            {
397675              "url": "https://github.com/mmalecki/json-stream.git",
397676              "type": "distribution"
397677            }
397678          ],
397679          "evidence": {},
397680          "signature": {
397681            "signature": {
397682              "publicKey": {}
397683            }
397684          },
397685          "modelCard": {
397686            "modelParameters": {
397687              "approach": {}
397688            },
397689            "quantitativeAnalysis": {
397690              "graphics": {}
397691            },
397692            "considerations": {}
397693          }
397694        },
397695        {
397696          "type": "library",
397697          "bom-ref": "pkg:npm/json-stringify-nice@1.1.4?package-id=e53e3b4efad53e7c",
397698          "supplier": {},
397699          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
397700          "name": "json-stringify-nice",
397701          "version": "1.1.4",
397702          "description": "Stringify an object sorting scalars before objects, and defaulting to 2-space indent",
397703          "licenses": [
397704            {
397705              "license": {
397706                "id": "ISC"
397707              }
397708            }
397709          ],
397710          "cpe": "cpe:2.3:a:json-stringify-nice:json-stringify-nice:1.1.4:*:*:*:*:*:*:*",
397711          "purl": "pkg:npm/json-stringify-nice@1.1.4",
397712          "swid": {
397713            "attachment": {}
397714          },
397715          "pedigree": {},
397716          "externalReferences": [
397717            {
397718              "url": "https://github.com/isaacs/json-stringify-nice",
397719              "type": "distribution"
397720            }
397721          ],
397722          "evidence": {},
397723          "signature": {
397724            "signature": {
397725              "publicKey": {}
397726            }
397727          },
397728          "modelCard": {
397729            "modelParameters": {
397730              "approach": {}
397731            },
397732            "quantitativeAnalysis": {
397733              "graphics": {}
397734            },
397735            "considerations": {}
397736          }
397737        },
397738        {
397739          "type": "library",
397740          "bom-ref": "pkg:npm/json-stringify-safe@5.0.1?package-id=f6bc9b393e0af00f",
397741          "supplier": {},
397742          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
397743          "name": "json-stringify-safe",
397744          "version": "5.0.1",
397745          "description": "Like JSON.stringify, but doesn't blow up on circular refs.",
397746          "licenses": [
397747            {
397748              "license": {
397749                "id": "ISC"
397750              }
397751            }
397752          ],
397753          "cpe": "cpe:2.3:a:json-stringify-safe:json-stringify-safe:5.0.1:*:*:*:*:*:*:*",
397754          "purl": "pkg:npm/json-stringify-safe@5.0.1",
397755          "swid": {
397756            "attachment": {}
397757          },
397758          "pedigree": {},
397759          "externalReferences": [
397760            {
397761              "url": "git://github.com/isaacs/json-stringify-safe",
397762              "type": "distribution"
397763            },
397764            {
397765              "url": "https://github.com/isaacs/json-stringify-safe",
397766              "type": "website"
397767            }
397768          ],
397769          "evidence": {},
397770          "signature": {
397771            "signature": {
397772              "publicKey": {}
397773            }
397774          },
397775          "modelCard": {
397776            "modelParameters": {
397777              "approach": {}
397778            },
397779            "quantitativeAnalysis": {
397780              "graphics": {}
397781            },
397782            "considerations": {}
397783          }
397784        },
397785        {
397786          "type": "library",
397787          "bom-ref": "pkg:npm/jsonfile@4.0.0?package-id=4cfeca6860892aa8",
397788          "supplier": {},
397789          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
397790          "name": "jsonfile",
397791          "version": "4.0.0",
397792          "description": "Easily read/write JSON files.",
397793          "licenses": [
397794            {
397795              "license": {
397796                "id": "MIT"
397797              }
397798            }
397799          ],
397800          "cpe": "cpe:2.3:a:jsonfile:jsonfile:4.0.0:*:*:*:*:*:*:*",
397801          "purl": "pkg:npm/jsonfile@4.0.0",
397802          "swid": {
397803            "attachment": {}
397804          },
397805          "pedigree": {},
397806          "externalReferences": [
397807            {
397808              "url": "git@github.com:jprichardson/node-jsonfile.git",
397809              "type": "distribution"
397810            }
397811          ],
397812          "evidence": {},
397813          "signature": {
397814            "signature": {
397815              "publicKey": {}
397816            }
397817          },
397818          "modelCard": {
397819            "modelParameters": {
397820              "approach": {}
397821            },
397822            "quantitativeAnalysis": {
397823              "graphics": {}
397824            },
397825            "considerations": {}
397826          }
397827        },
397828        {
397829          "type": "library",
397830          "bom-ref": "pkg:npm/jsonfile@6.1.0?package-id=a6643e442a28ab37",
397831          "supplier": {},
397832          "author": "JP Richardson \u003cjprichardson@gmail.com\u003e",
397833          "name": "jsonfile",
397834          "version": "6.1.0",
397835          "description": "Easily read/write JSON files.",
397836          "licenses": [
397837            {
397838              "license": {
397839                "id": "MIT"
397840              }
397841            }
397842          ],
397843          "cpe": "cpe:2.3:a:jsonfile:jsonfile:6.1.0:*:*:*:*:*:*:*",
397844          "purl": "pkg:npm/jsonfile@6.1.0",
397845          "swid": {
397846            "attachment": {}
397847          },
397848          "pedigree": {},
397849          "externalReferences": [
397850            {
397851              "url": "git@github.com:jprichardson/node-jsonfile.git",
397852              "type": "distribution"
397853            }
397854          ],
397855          "evidence": {},
397856          "signature": {
397857            "signature": {
397858              "publicKey": {}
397859            }
397860          },
397861          "modelCard": {
397862            "modelParameters": {
397863              "approach": {}
397864            },
397865            "quantitativeAnalysis": {
397866              "graphics": {}
397867            },
397868            "considerations": {}
397869          }
397870        },
397871        {
397872          "type": "library",
397873          "bom-ref": "pkg:npm/jsonparse@1.3.1?package-id=4ac9c9dc14c89718",
397874          "supplier": {},
397875          "author": "Tim Caswell \u003ctim@creationix.com\u003e",
397876          "name": "jsonparse",
397877          "version": "1.3.1",
397878          "description": "This is a pure-js JSON streaming parser for node.js",
397879          "licenses": [
397880            {
397881              "license": {
397882                "id": "MIT"
397883              }
397884            }
397885          ],
397886          "cpe": "cpe:2.3:a:creationix:jsonparse:1.3.1:*:*:*:*:*:*:*",
397887          "purl": "pkg:npm/jsonparse@1.3.1",
397888          "swid": {
397889            "attachment": {}
397890          },
397891          "pedigree": {},
397892          "externalReferences": [
397893            {
397894              "url": "http://github.com/creationix/jsonparse.git",
397895              "type": "distribution"
397896            }
397897          ],
397898          "evidence": {},
397899          "signature": {
397900            "signature": {
397901              "publicKey": {}
397902            }
397903          },
397904          "modelCard": {
397905            "modelParameters": {
397906              "approach": {}
397907            },
397908            "quantitativeAnalysis": {
397909              "graphics": {}
397910            },
397911            "considerations": {}
397912          }
397913        },
397914        {
397915          "type": "library",
397916          "bom-ref": "pkg:npm/jsprim@1.4.2?package-id=5cc587fdf3d16342",
397917          "supplier": {},
397918          "name": "jsprim",
397919          "version": "1.4.2",
397920          "description": "utilities for primitive JavaScript types",
397921          "licenses": [
397922            {
397923              "license": {
397924                "id": "MIT"
397925              }
397926            }
397927          ],
397928          "cpe": "cpe:2.3:a:joyent:jsprim:1.4.2:*:*:*:*:*:*:*",
397929          "purl": "pkg:npm/jsprim@1.4.2",
397930          "swid": {
397931            "attachment": {}
397932          },
397933          "pedigree": {},
397934          "externalReferences": [
397935            {
397936              "url": "git://github.com/joyent/node-jsprim.git",
397937              "type": "distribution"
397938            }
397939          ],
397940          "evidence": {},
397941          "signature": {
397942            "signature": {
397943              "publicKey": {}
397944            }
397945          },
397946          "modelCard": {
397947            "modelParameters": {
397948              "approach": {}
397949            },
397950            "quantitativeAnalysis": {
397951              "graphics": {}
397952            },
397953            "considerations": {}
397954          }
397955        },
397956        {
397957          "type": "library",
397958          "bom-ref": "pkg:npm/just-diff@5.1.1?package-id=ce66f628f594c549",
397959          "supplier": {},
397960          "author": "Angus Croll",
397961          "name": "just-diff",
397962          "version": "5.1.1",
397963          "description": "Return an object representing the diffs between two objects. Supports jsonPatch protocol",
397964          "licenses": [
397965            {
397966              "license": {
397967                "id": "MIT"
397968              }
397969            }
397970          ],
397971          "cpe": "cpe:2.3:a:just-diff:just-diff:5.1.1:*:*:*:*:*:*:*",
397972          "purl": "pkg:npm/just-diff@5.1.1",
397973          "swid": {
397974            "attachment": {}
397975          },
397976          "pedigree": {},
397977          "externalReferences": [
397978            {
397979              "url": "https://github.com/angus-c/just",
397980              "type": "distribution"
397981            }
397982          ],
397983          "evidence": {},
397984          "signature": {
397985            "signature": {
397986              "publicKey": {}
397987            }
397988          },
397989          "modelCard": {
397990            "modelParameters": {
397991              "approach": {}
397992            },
397993            "quantitativeAnalysis": {
397994              "graphics": {}
397995            },
397996            "considerations": {}
397997          }
397998        },
397999        {
398000          "type": "library",
398001          "bom-ref": "pkg:npm/just-diff-apply@5.4.1?package-id=11dfc45c877cf5ba",
398002          "supplier": {},
398003          "author": "Angus Croll",
398004          "name": "just-diff-apply",
398005          "version": "5.4.1",
398006          "description": "Apply a diff to an object. Optionally supports jsonPatch protocol",
398007          "licenses": [
398008            {
398009              "license": {
398010                "id": "MIT"
398011              }
398012            }
398013          ],
398014          "cpe": "cpe:2.3:a:just-diff-apply:just-diff-apply:5.4.1:*:*:*:*:*:*:*",
398015          "purl": "pkg:npm/just-diff-apply@5.4.1",
398016          "swid": {
398017            "attachment": {}
398018          },
398019          "pedigree": {},
398020          "externalReferences": [
398021            {
398022              "url": "https://github.com/angus-c/just",
398023              "type": "distribution"
398024            }
398025          ],
398026          "evidence": {},
398027          "signature": {
398028            "signature": {
398029              "publicKey": {}
398030            }
398031          },
398032          "modelCard": {
398033            "modelParameters": {
398034              "approach": {}
398035            },
398036            "quantitativeAnalysis": {
398037              "graphics": {}
398038            },
398039            "considerations": {}
398040          }
398041        },
398042        {
398043          "type": "library",
398044          "bom-ref": "pkg:apk/alpine/keyutils-libs@1.6.3-r1?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.16.5\u0026package-id=8ee597dfe194ab60",
398045          "supplier": {},
398046          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
398047          "name": "keyutils-libs",
398048          "version": "1.6.3-r1",
398049          "description": "Key utilities library",
398050          "licenses": [
398051            {
398052              "license": {
398053                "id": "GPL-2.0-or-later"
398054              }
398055            },
398056            {
398057              "license": {
398058                "id": "LGPL-2.0-or-later"
398059              }
398060            }
398061          ],
398062          "cpe": "cpe:2.3:a:keyutils-libs:keyutils-libs:1.6.3-r1:*:*:*:*:*:*:*",
398063          "purl": "pkg:apk/alpine/keyutils-libs@1.6.3-r1?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.16.5",
398064          "swid": {
398065            "attachment": {}
398066          },
398067          "pedigree": {},
398068          "externalReferences": [
398069            {
398070              "url": "https://people.redhat.com/~dhowells/keyutils/",
398071              "type": "distribution"
398072            }
398073          ],
398074          "evidence": {},
398075          "signature": {
398076            "signature": {
398077              "publicKey": {}
398078            }
398079          },
398080          "modelCard": {
398081            "modelParameters": {
398082              "approach": {}
398083            },
398084            "quantitativeAnalysis": {
398085              "graphics": {}
398086            },
398087            "considerations": {}
398088          }
398089        },
398090        {
398091          "type": "library",
398092          "bom-ref": "pkg:npm/keyv@3.0.0?package-id=c0a1007f3c4e9d",
398093          "supplier": {},
398094          "author": "Luke Childs \u003clukechilds123@gmail.com\u003e (http://lukechilds.co.uk)",
398095          "name": "keyv",
398096          "version": "3.0.0",
398097          "description": "Simple key-value storage with support for multiple backends",
398098          "licenses": [
398099            {
398100              "license": {
398101                "id": "MIT"
398102              }
398103            }
398104          ],
398105          "cpe": "cpe:2.3:a:lukechilds:keyv:3.0.0:*:*:*:*:*:*:*",
398106          "purl": "pkg:npm/keyv@3.0.0",
398107          "swid": {
398108            "attachment": {}
398109          },
398110          "pedigree": {},
398111          "externalReferences": [
398112            {
398113              "url": "git+https://github.com/lukechilds/keyv.git",
398114              "type": "distribution"
398115            },
398116            {
398117              "url": "https://github.com/lukechilds/keyv",
398118              "type": "website"
398119            }
398120          ],
398121          "evidence": {},
398122          "signature": {
398123            "signature": {
398124              "publicKey": {}
398125            }
398126          },
398127          "modelCard": {
398128            "modelParameters": {
398129              "approach": {}
398130            },
398131            "quantitativeAnalysis": {
398132              "graphics": {}
398133            },
398134            "considerations": {}
398135          }
398136        },
398137        {
398138          "type": "library",
398139          "bom-ref": "pkg:npm/keyv@4.5.2?package-id=c302f0561af29045",
398140          "supplier": {},
398141          "author": "Jared Wray \u003cme@jaredwray.com\u003e (http://jaredwray.com)",
398142          "name": "keyv",
398143          "version": "4.5.2",
398144          "description": "Simple key-value storage with support for multiple backends",
398145          "licenses": [
398146            {
398147              "license": {
398148                "id": "MIT"
398149              }
398150            }
398151          ],
398152          "cpe": "cpe:2.3:a:jaredwray:keyv:4.5.2:*:*:*:*:*:*:*",
398153          "purl": "pkg:npm/keyv@4.5.2",
398154          "swid": {
398155            "attachment": {}
398156          },
398157          "pedigree": {},
398158          "externalReferences": [
398159            {
398160              "url": "git+https://github.com/jaredwray/keyv.git",
398161              "type": "distribution"
398162            },
398163            {
398164              "url": "https://github.com/jaredwray/keyv",
398165              "type": "website"
398166            }
398167          ],
398168          "evidence": {},
398169          "signature": {
398170            "signature": {
398171              "publicKey": {}
398172            }
398173          },
398174          "modelCard": {
398175            "modelParameters": {
398176              "approach": {}
398177            },
398178            "quantitativeAnalysis": {
398179              "graphics": {}
398180            },
398181            "considerations": {}
398182          }
398183        },
398184        {
398185          "type": "library",
398186          "bom-ref": "pkg:npm/klaw-sync@6.0.0?package-id=2526d6cabcdfb0cd",
398187          "supplier": {},
398188          "author": "Mani Maghsoudlou",
398189          "name": "klaw-sync",
398190          "version": "6.0.0",
398191          "description": "Recursive, synchronous, and fast file system walker",
398192          "licenses": [
398193            {
398194              "license": {
398195                "id": "MIT"
398196              }
398197            }
398198          ],
398199          "cpe": "cpe:2.3:a:klaw-sync:klaw-sync:6.0.0:*:*:*:*:*:*:*",
398200          "purl": "pkg:npm/klaw-sync@6.0.0",
398201          "swid": {
398202            "attachment": {}
398203          },
398204          "pedigree": {},
398205          "externalReferences": [
398206            {
398207              "url": "git+https://github.com/manidlou/node-klaw-sync.git",
398208              "type": "distribution"
398209            },
398210            {
398211              "url": "https://github.com/manidlou/node-klaw-sync#readme",
398212              "type": "website"
398213            }
398214          ],
398215          "evidence": {},
398216          "signature": {
398217            "signature": {
398218              "publicKey": {}
398219            }
398220          },
398221          "modelCard": {
398222            "modelParameters": {
398223              "approach": {}
398224            },
398225            "quantitativeAnalysis": {
398226              "graphics": {}
398227            },
398228            "considerations": {}
398229          }
398230        },
398231        {
398232          "type": "library",
398233          "bom-ref": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=50afffc56cc7e53",
398234          "supplier": {},
398235          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
398236          "name": "krb5-conf",
398237          "version": "1.0-r2",
398238          "description": "Shared krb5.conf for both MIT krb5 and heimdal",
398239          "licenses": [
398240            {
398241              "license": {
398242                "id": "MIT"
398243              }
398244            }
398245          ],
398246          "cpe": "cpe:2.3:a:krb5-conf:krb5-conf:1.0-r2:*:*:*:*:*:*:*",
398247          "purl": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=alpine-3.16.5",
398248          "swid": {
398249            "attachment": {}
398250          },
398251          "pedigree": {},
398252          "externalReferences": [
398253            {
398254              "url": "https://web.mit.edu/kerberos/www/",
398255              "type": "distribution"
398256            }
398257          ],
398258          "evidence": {},
398259          "signature": {
398260            "signature": {
398261              "publicKey": {}
398262            }
398263          },
398264          "modelCard": {
398265            "modelParameters": {
398266              "approach": {}
398267            },
398268            "quantitativeAnalysis": {
398269              "graphics": {}
398270            },
398271            "considerations": {}
398272          }
398273        },
398274        {
398275          "type": "library",
398276          "bom-ref": "pkg:apk/alpine/krb5-libs@1.19.4-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.16.5\u0026package-id=4cdf917c85417723",
398277          "supplier": {},
398278          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
398279          "name": "krb5-libs",
398280          "version": "1.19.4-r0",
398281          "description": "The shared libraries used by Kerberos 5",
398282          "licenses": [
398283            {
398284              "license": {
398285                "id": "MIT"
398286              }
398287            }
398288          ],
398289          "cpe": "cpe:2.3:a:krb5-libs:krb5-libs:1.19.4-r0:*:*:*:*:*:*:*",
398290          "purl": "pkg:apk/alpine/krb5-libs@1.19.4-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.16.5",
398291          "swid": {
398292            "attachment": {}
398293          },
398294          "pedigree": {},
398295          "externalReferences": [
398296            {
398297              "url": "https://web.mit.edu/kerberos/www/",
398298              "type": "distribution"
398299            }
398300          ],
398301          "evidence": {},
398302          "signature": {
398303            "signature": {
398304              "publicKey": {}
398305            }
398306          },
398307          "modelCard": {
398308            "modelParameters": {
398309              "approach": {}
398310            },
398311            "quantitativeAnalysis": {
398312              "graphics": {}
398313            },
398314            "considerations": {}
398315          }
398316        },
398317        {
398318          "type": "library",
398319          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5\u0026package-id=2abd3b45f6fa4702",
398320          "supplier": {},
398321          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
398322          "name": "libc-utils",
398323          "version": "0.7.2-r3",
398324          "description": "Meta package to pull in correct libc",
398325          "licenses": [
398326            {
398327              "license": {
398328                "id": "BSD-2-Clause"
398329              }
398330            },
398331            {
398332              "license": {
398333                "name": "AND"
398334              }
398335            },
398336            {
398337              "license": {
398338                "id": "BSD-3-Clause"
398339              }
398340            }
398341          ],
398342          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
398343          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5",
398344          "swid": {
398345            "attachment": {}
398346          },
398347          "pedigree": {},
398348          "externalReferences": [
398349            {
398350              "url": "https://alpinelinux.org",
398351              "type": "distribution"
398352            }
398353          ],
398354          "evidence": {},
398355          "signature": {
398356            "signature": {
398357              "publicKey": {}
398358            }
398359          },
398360          "modelCard": {
398361            "modelParameters": {
398362              "approach": {}
398363            },
398364            "quantitativeAnalysis": {
398365              "graphics": {}
398366            },
398367            "considerations": {}
398368          }
398369        },
398370        {
398371          "type": "library",
398372          "bom-ref": "pkg:apk/alpine/libcom_err@1.46.6-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.16.5\u0026package-id=25b329ab3289e91c",
398373          "supplier": {},
398374          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
398375          "name": "libcom_err",
398376          "version": "1.46.6-r0",
398377          "description": "Common error description library",
398378          "licenses": [
398379            {
398380              "license": {
398381                "id": "GPL-2.0-or-later"
398382              }
398383            },
398384            {
398385              "license": {
398386                "name": "AND"
398387              }
398388            },
398389            {
398390              "license": {
398391                "id": "LGPL-2.0-or-later"
398392              }
398393            },
398394            {
398395              "license": {
398396                "name": "AND"
398397              }
398398            },
398399            {
398400              "license": {
398401                "id": "BSD-3-Clause"
398402              }
398403            },
398404            {
398405              "license": {
398406                "name": "AND"
398407              }
398408            },
398409            {
398410              "license": {
398411                "id": "MIT"
398412              }
398413            }
398414          ],
398415          "cpe": "cpe:2.3:a:libcom-err:libcom-err:1.46.6-r0:*:*:*:*:*:*:*",
398416          "purl": "pkg:apk/alpine/libcom_err@1.46.6-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.16.5",
398417          "swid": {
398418            "attachment": {}
398419          },
398420          "pedigree": {},
398421          "externalReferences": [
398422            {
398423              "url": "http://e2fsprogs.sourceforge.net",
398424              "type": "distribution"
398425            }
398426          ],
398427          "evidence": {},
398428          "signature": {
398429            "signature": {
398430              "publicKey": {}
398431            }
398432          },
398433          "modelCard": {
398434            "modelParameters": {
398435              "approach": {}
398436            },
398437            "quantitativeAnalysis": {
398438              "graphics": {}
398439            },
398440            "considerations": {}
398441          }
398442        },
398443        {
398444          "type": "library",
398445          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=13bc051822a24e8d",
398446          "supplier": {},
398447          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
398448          "name": "libcrypto1.1",
398449          "version": "1.1.1t-r2",
398450          "description": "Crypto library from openssl",
398451          "licenses": [
398452            {
398453              "license": {
398454                "id": "OpenSSL"
398455              }
398456            }
398457          ],
398458          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1t-r2:*:*:*:*:*:*:*",
398459          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
398460          "swid": {
398461            "attachment": {}
398462          },
398463          "pedigree": {},
398464          "externalReferences": [
398465            {
398466              "url": "https://www.openssl.org/",
398467              "type": "distribution"
398468            }
398469          ],
398470          "evidence": {},
398471          "signature": {
398472            "signature": {
398473              "publicKey": {}
398474            }
398475          },
398476          "modelCard": {
398477            "modelParameters": {
398478              "approach": {}
398479            },
398480            "quantitativeAnalysis": {
398481              "graphics": {}
398482            },
398483            "considerations": {}
398484          }
398485        },
398486        {
398487          "type": "library",
398488          "bom-ref": "pkg:apk/alpine/libcurl@8.0.1-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.16.5\u0026package-id=6607bdc4c7db4eab",
398489          "supplier": {},
398490          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
398491          "name": "libcurl",
398492          "version": "8.0.1-r0",
398493          "description": "The multiprotocol file transfer library",
398494          "licenses": [
398495            {
398496              "license": {
398497                "id": "curl"
398498              }
398499            }
398500          ],
398501          "cpe": "cpe:2.3:a:libcurl:libcurl:8.0.1-r0:*:*:*:*:*:*:*",
398502          "purl": "pkg:apk/alpine/libcurl@8.0.1-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.16.5",
398503          "swid": {
398504            "attachment": {}
398505          },
398506          "pedigree": {},
398507          "externalReferences": [
398508            {
398509              "url": "https://curl.se/",
398510              "type": "distribution"
398511            }
398512          ],
398513          "evidence": {},
398514          "signature": {
398515            "signature": {
398516              "publicKey": {}
398517            }
398518          },
398519          "modelCard": {
398520            "modelParameters": {
398521              "approach": {}
398522            },
398523            "quantitativeAnalysis": {
398524              "graphics": {}
398525            },
398526            "considerations": {}
398527          }
398528        },
398529        {
398530          "type": "library",
398531          "bom-ref": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=d2886381f1e7cdb2",
398532          "supplier": {},
398533          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
398534          "name": "libgcc",
398535          "version": "11.2.1_git20220219-r2",
398536          "description": "GNU C compiler runtime libraries",
398537          "licenses": [
398538            {
398539              "license": {
398540                "id": "GPL-2.0-or-later"
398541              }
398542            },
398543            {
398544              "license": {
398545                "id": "LGPL-2.1-or-later"
398546              }
398547            }
398548          ],
398549          "cpe": "cpe:2.3:a:libgcc:libgcc:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
398550          "purl": "pkg:apk/alpine/libgcc@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
398551          "swid": {
398552            "attachment": {}
398553          },
398554          "pedigree": {},
398555          "externalReferences": [
398556            {
398557              "url": "https://gcc.gnu.org",
398558              "type": "distribution"
398559            }
398560          ],
398561          "evidence": {},
398562          "signature": {
398563            "signature": {
398564              "publicKey": {}
398565            }
398566          },
398567          "modelCard": {
398568            "modelParameters": {
398569              "approach": {}
398570            },
398571            "quantitativeAnalysis": {
398572              "graphics": {}
398573            },
398574            "considerations": {}
398575          }
398576        },
398577        {
398578          "type": "library",
398579          "bom-ref": "pkg:npm/libnpmaccess@6.0.4?package-id=f3410b3d946e1c4d",
398580          "supplier": {},
398581          "author": "GitHub Inc.",
398582          "name": "libnpmaccess",
398583          "version": "6.0.4",
398584          "description": "programmatic library for `npm access` commands",
398585          "licenses": [
398586            {
398587              "license": {
398588                "id": "ISC"
398589              }
398590            }
398591          ],
398592          "cpe": "cpe:2.3:a:libnpmaccess:libnpmaccess:6.0.4:*:*:*:*:*:*:*",
398593          "purl": "pkg:npm/libnpmaccess@6.0.4",
398594          "swid": {
398595            "attachment": {}
398596          },
398597          "pedigree": {},
398598          "externalReferences": [
398599            {
398600              "url": "https://github.com/npm/cli.git",
398601              "type": "distribution"
398602            },
398603            {
398604              "url": "https://npmjs.com/package/libnpmaccess",
398605              "type": "website"
398606            }
398607          ],
398608          "evidence": {},
398609          "signature": {
398610            "signature": {
398611              "publicKey": {}
398612            }
398613          },
398614          "modelCard": {
398615            "modelParameters": {
398616              "approach": {}
398617            },
398618            "quantitativeAnalysis": {
398619              "graphics": {}
398620            },
398621            "considerations": {}
398622          }
398623        },
398624        {
398625          "type": "library",
398626          "bom-ref": "pkg:npm/libnpmdiff@4.0.5?package-id=ce3262e2c08529ea",
398627          "supplier": {},
398628          "author": "GitHub Inc.",
398629          "name": "libnpmdiff",
398630          "version": "4.0.5",
398631          "description": "The registry diff",
398632          "licenses": [
398633            {
398634              "license": {
398635                "id": "ISC"
398636              }
398637            }
398638          ],
398639          "cpe": "cpe:2.3:a:libnpmdiff:libnpmdiff:4.0.5:*:*:*:*:*:*:*",
398640          "purl": "pkg:npm/libnpmdiff@4.0.5",
398641          "swid": {
398642            "attachment": {}
398643          },
398644          "pedigree": {},
398645          "externalReferences": [
398646            {
398647              "url": "https://github.com/npm/cli.git",
398648              "type": "distribution"
398649            }
398650          ],
398651          "evidence": {},
398652          "signature": {
398653            "signature": {
398654              "publicKey": {}
398655            }
398656          },
398657          "modelCard": {
398658            "modelParameters": {
398659              "approach": {}
398660            },
398661            "quantitativeAnalysis": {
398662              "graphics": {}
398663            },
398664            "considerations": {}
398665          }
398666        },
398667        {
398668          "type": "library",
398669          "bom-ref": "pkg:npm/libnpmexec@4.0.14?package-id=902cc2f16bb11ffc",
398670          "supplier": {},
398671          "author": "GitHub Inc.",
398672          "name": "libnpmexec",
398673          "version": "4.0.14",
398674          "description": "npm exec (npx) programmatic API",
398675          "licenses": [
398676            {
398677              "license": {
398678                "id": "ISC"
398679              }
398680            }
398681          ],
398682          "cpe": "cpe:2.3:a:libnpmexec:libnpmexec:4.0.14:*:*:*:*:*:*:*",
398683          "purl": "pkg:npm/libnpmexec@4.0.14",
398684          "swid": {
398685            "attachment": {}
398686          },
398687          "pedigree": {},
398688          "externalReferences": [
398689            {
398690              "url": "https://github.com/npm/cli.git",
398691              "type": "distribution"
398692            }
398693          ],
398694          "evidence": {},
398695          "signature": {
398696            "signature": {
398697              "publicKey": {}
398698            }
398699          },
398700          "modelCard": {
398701            "modelParameters": {
398702              "approach": {}
398703            },
398704            "quantitativeAnalysis": {
398705              "graphics": {}
398706            },
398707            "considerations": {}
398708          }
398709        },
398710        {
398711          "type": "library",
398712          "bom-ref": "pkg:npm/libnpmfund@3.0.5?package-id=201ebcb5d992fa75",
398713          "supplier": {},
398714          "author": "GitHub Inc.",
398715          "name": "libnpmfund",
398716          "version": "3.0.5",
398717          "description": "Programmatic API for npm fund",
398718          "licenses": [
398719            {
398720              "license": {
398721                "id": "ISC"
398722              }
398723            }
398724          ],
398725          "cpe": "cpe:2.3:a:libnpmfund:libnpmfund:3.0.5:*:*:*:*:*:*:*",
398726          "purl": "pkg:npm/libnpmfund@3.0.5",
398727          "swid": {
398728            "attachment": {}
398729          },
398730          "pedigree": {},
398731          "externalReferences": [
398732            {
398733              "url": "https://github.com/npm/cli.git",
398734              "type": "distribution"
398735            }
398736          ],
398737          "evidence": {},
398738          "signature": {
398739            "signature": {
398740              "publicKey": {}
398741            }
398742          },
398743          "modelCard": {
398744            "modelParameters": {
398745              "approach": {}
398746            },
398747            "quantitativeAnalysis": {
398748              "graphics": {}
398749            },
398750            "considerations": {}
398751          }
398752        },
398753        {
398754          "type": "library",
398755          "bom-ref": "pkg:npm/libnpmhook@8.0.4?package-id=5679bee9e2f7003c",
398756          "supplier": {},
398757          "author": "GitHub Inc.",
398758          "name": "libnpmhook",
398759          "version": "8.0.4",
398760          "description": "programmatic API for managing npm registry hooks",
398761          "licenses": [
398762            {
398763              "license": {
398764                "id": "ISC"
398765              }
398766            }
398767          ],
398768          "cpe": "cpe:2.3:a:libnpmhook:libnpmhook:8.0.4:*:*:*:*:*:*:*",
398769          "purl": "pkg:npm/libnpmhook@8.0.4",
398770          "swid": {
398771            "attachment": {}
398772          },
398773          "pedigree": {},
398774          "externalReferences": [
398775            {
398776              "url": "https://github.com/npm/cli.git",
398777              "type": "distribution"
398778            }
398779          ],
398780          "evidence": {},
398781          "signature": {
398782            "signature": {
398783              "publicKey": {}
398784            }
398785          },
398786          "modelCard": {
398787            "modelParameters": {
398788              "approach": {}
398789            },
398790            "quantitativeAnalysis": {
398791              "graphics": {}
398792            },
398793            "considerations": {}
398794          }
398795        },
398796        {
398797          "type": "library",
398798          "bom-ref": "pkg:npm/libnpmorg@4.0.4?package-id=80c945656f22ba9d",
398799          "supplier": {},
398800          "author": "GitHub Inc.",
398801          "name": "libnpmorg",
398802          "version": "4.0.4",
398803          "description": "Programmatic api for `npm org` commands",
398804          "licenses": [
398805            {
398806              "license": {
398807                "id": "ISC"
398808              }
398809            }
398810          ],
398811          "cpe": "cpe:2.3:a:libnpmorg:libnpmorg:4.0.4:*:*:*:*:*:*:*",
398812          "purl": "pkg:npm/libnpmorg@4.0.4",
398813          "swid": {
398814            "attachment": {}
398815          },
398816          "pedigree": {},
398817          "externalReferences": [
398818            {
398819              "url": "https://github.com/npm/cli.git",
398820              "type": "distribution"
398821            },
398822            {
398823              "url": "https://npmjs.com/package/libnpmorg",
398824              "type": "website"
398825            }
398826          ],
398827          "evidence": {},
398828          "signature": {
398829            "signature": {
398830              "publicKey": {}
398831            }
398832          },
398833          "modelCard": {
398834            "modelParameters": {
398835              "approach": {}
398836            },
398837            "quantitativeAnalysis": {
398838              "graphics": {}
398839            },
398840            "considerations": {}
398841          }
398842        },
398843        {
398844          "type": "library",
398845          "bom-ref": "pkg:npm/libnpmpack@4.1.3?package-id=62f6985b14d7de3e",
398846          "supplier": {},
398847          "author": "GitHub Inc.",
398848          "name": "libnpmpack",
398849          "version": "4.1.3",
398850          "description": "Programmatic API for the bits behind npm pack",
398851          "licenses": [
398852            {
398853              "license": {
398854                "id": "ISC"
398855              }
398856            }
398857          ],
398858          "cpe": "cpe:2.3:a:libnpmpack:libnpmpack:4.1.3:*:*:*:*:*:*:*",
398859          "purl": "pkg:npm/libnpmpack@4.1.3",
398860          "swid": {
398861            "attachment": {}
398862          },
398863          "pedigree": {},
398864          "externalReferences": [
398865            {
398866              "url": "https://github.com/npm/cli.git",
398867              "type": "distribution"
398868            },
398869            {
398870              "url": "https://npmjs.com/package/libnpmpack",
398871              "type": "website"
398872            }
398873          ],
398874          "evidence": {},
398875          "signature": {
398876            "signature": {
398877              "publicKey": {}
398878            }
398879          },
398880          "modelCard": {
398881            "modelParameters": {
398882              "approach": {}
398883            },
398884            "quantitativeAnalysis": {
398885              "graphics": {}
398886            },
398887            "considerations": {}
398888          }
398889        },
398890        {
398891          "type": "library",
398892          "bom-ref": "pkg:npm/libnpmpublish@6.0.5?package-id=a970d9d2bf422a57",
398893          "supplier": {},
398894          "author": "GitHub Inc.",
398895          "name": "libnpmpublish",
398896          "version": "6.0.5",
398897          "description": "Programmatic API for the bits behind npm publish and unpublish",
398898          "licenses": [
398899            {
398900              "license": {
398901                "id": "ISC"
398902              }
398903            }
398904          ],
398905          "cpe": "cpe:2.3:a:libnpmpublish:libnpmpublish:6.0.5:*:*:*:*:*:*:*",
398906          "purl": "pkg:npm/libnpmpublish@6.0.5",
398907          "swid": {
398908            "attachment": {}
398909          },
398910          "pedigree": {},
398911          "externalReferences": [
398912            {
398913              "url": "https://github.com/npm/cli.git",
398914              "type": "distribution"
398915            },
398916            {
398917              "url": "https://npmjs.com/package/libnpmpublish",
398918              "type": "website"
398919            }
398920          ],
398921          "evidence": {},
398922          "signature": {
398923            "signature": {
398924              "publicKey": {}
398925            }
398926          },
398927          "modelCard": {
398928            "modelParameters": {
398929              "approach": {}
398930            },
398931            "quantitativeAnalysis": {
398932              "graphics": {}
398933            },
398934            "considerations": {}
398935          }
398936        },
398937        {
398938          "type": "library",
398939          "bom-ref": "pkg:npm/libnpmsearch@5.0.4?package-id=e3666452dd7e585d",
398940          "supplier": {},
398941          "author": "GitHub Inc.",
398942          "name": "libnpmsearch",
398943          "version": "5.0.4",
398944          "description": "Programmatic API for searching in npm and compatible registries.",
398945          "licenses": [
398946            {
398947              "license": {
398948                "id": "ISC"
398949              }
398950            }
398951          ],
398952          "cpe": "cpe:2.3:a:libnpmsearch:libnpmsearch:5.0.4:*:*:*:*:*:*:*",
398953          "purl": "pkg:npm/libnpmsearch@5.0.4",
398954          "swid": {
398955            "attachment": {}
398956          },
398957          "pedigree": {},
398958          "externalReferences": [
398959            {
398960              "url": "https://github.com/npm/cli.git",
398961              "type": "distribution"
398962            },
398963            {
398964              "url": "https://npmjs.com/package/libnpmsearch",
398965              "type": "website"
398966            }
398967          ],
398968          "evidence": {},
398969          "signature": {
398970            "signature": {
398971              "publicKey": {}
398972            }
398973          },
398974          "modelCard": {
398975            "modelParameters": {
398976              "approach": {}
398977            },
398978            "quantitativeAnalysis": {
398979              "graphics": {}
398980            },
398981            "considerations": {}
398982          }
398983        },
398984        {
398985          "type": "library",
398986          "bom-ref": "pkg:npm/libnpmteam@4.0.4?package-id=95c3c29c4dcd60d1",
398987          "supplier": {},
398988          "author": "GitHub Inc.",
398989          "name": "libnpmteam",
398990          "version": "4.0.4",
398991          "description": "npm Team management APIs",
398992          "licenses": [
398993            {
398994              "license": {
398995                "id": "ISC"
398996              }
398997            }
398998          ],
398999          "cpe": "cpe:2.3:a:libnpmteam:libnpmteam:4.0.4:*:*:*:*:*:*:*",
399000          "purl": "pkg:npm/libnpmteam@4.0.4",
399001          "swid": {
399002            "attachment": {}
399003          },
399004          "pedigree": {},
399005          "externalReferences": [
399006            {
399007              "url": "https://github.com/npm/cli.git",
399008              "type": "distribution"
399009            },
399010            {
399011              "url": "https://npmjs.com/package/libnpmteam",
399012              "type": "website"
399013            }
399014          ],
399015          "evidence": {},
399016          "signature": {
399017            "signature": {
399018              "publicKey": {}
399019            }
399020          },
399021          "modelCard": {
399022            "modelParameters": {
399023              "approach": {}
399024            },
399025            "quantitativeAnalysis": {
399026              "graphics": {}
399027            },
399028            "considerations": {}
399029          }
399030        },
399031        {
399032          "type": "library",
399033          "bom-ref": "pkg:npm/libnpmversion@3.0.7?package-id=9ace162e3f4ca294",
399034          "supplier": {},
399035          "author": "GitHub Inc.",
399036          "name": "libnpmversion",
399037          "version": "3.0.7",
399038          "description": "library to do the things that 'npm version' does",
399039          "licenses": [
399040            {
399041              "license": {
399042                "id": "ISC"
399043              }
399044            }
399045          ],
399046          "cpe": "cpe:2.3:a:libnpmversion:libnpmversion:3.0.7:*:*:*:*:*:*:*",
399047          "purl": "pkg:npm/libnpmversion@3.0.7",
399048          "swid": {
399049            "attachment": {}
399050          },
399051          "pedigree": {},
399052          "externalReferences": [
399053            {
399054              "url": "https://github.com/npm/cli.git",
399055              "type": "distribution"
399056            }
399057          ],
399058          "evidence": {},
399059          "signature": {
399060            "signature": {
399061              "publicKey": {}
399062            }
399063          },
399064          "modelCard": {
399065            "modelParameters": {
399066              "approach": {}
399067            },
399068            "quantitativeAnalysis": {
399069              "graphics": {}
399070            },
399071            "considerations": {}
399072          }
399073        },
399074        {
399075          "type": "library",
399076          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=609cb94e63dc06dd",
399077          "supplier": {},
399078          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
399079          "name": "libssl1.1",
399080          "version": "1.1.1t-r2",
399081          "description": "SSL shared libraries",
399082          "licenses": [
399083            {
399084              "license": {
399085                "id": "OpenSSL"
399086              }
399087            }
399088          ],
399089          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1t-r2:*:*:*:*:*:*:*",
399090          "purl": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
399091          "swid": {
399092            "attachment": {}
399093          },
399094          "pedigree": {},
399095          "externalReferences": [
399096            {
399097              "url": "https://www.openssl.org/",
399098              "type": "distribution"
399099            }
399100          ],
399101          "evidence": {},
399102          "signature": {
399103            "signature": {
399104              "publicKey": {}
399105            }
399106          },
399107          "modelCard": {
399108            "modelParameters": {
399109              "approach": {}
399110            },
399111            "quantitativeAnalysis": {
399112              "graphics": {}
399113            },
399114            "considerations": {}
399115          }
399116        },
399117        {
399118          "type": "library",
399119          "bom-ref": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5\u0026package-id=9913678ca8fd323d",
399120          "supplier": {},
399121          "publisher": "Ariadne Conill \u003cariadne@dereferenced.org\u003e",
399122          "name": "libstdc++",
399123          "version": "11.2.1_git20220219-r2",
399124          "description": "GNU C++ standard runtime library",
399125          "licenses": [
399126            {
399127              "license": {
399128                "id": "GPL-2.0-or-later"
399129              }
399130            },
399131            {
399132              "license": {
399133                "id": "LGPL-2.1-or-later"
399134              }
399135            }
399136          ],
399137          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.2.1_git20220219-r2:*:*:*:*:*:*:*",
399138          "purl": "pkg:apk/alpine/libstdc++@11.2.1_git20220219-r2?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.16.5",
399139          "swid": {
399140            "attachment": {}
399141          },
399142          "pedigree": {},
399143          "externalReferences": [
399144            {
399145              "url": "https://gcc.gnu.org",
399146              "type": "distribution"
399147            }
399148          ],
399149          "evidence": {},
399150          "signature": {
399151            "signature": {
399152              "publicKey": {}
399153            }
399154          },
399155          "modelCard": {
399156            "modelParameters": {
399157              "approach": {}
399158            },
399159            "quantitativeAnalysis": {
399160              "graphics": {}
399161            },
399162            "considerations": {}
399163          }
399164        },
399165        {
399166          "type": "library",
399167          "bom-ref": "pkg:apk/alpine/libuv@1.44.1-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=2fc480e53d82381d",
399168          "supplier": {},
399169          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
399170          "name": "libuv",
399171          "version": "1.44.1-r0",
399172          "description": "Cross-platform asychronous I/O",
399173          "licenses": [
399174            {
399175              "license": {
399176                "id": "MIT"
399177              }
399178            },
399179            {
399180              "license": {
399181                "name": "AND"
399182              }
399183            },
399184            {
399185              "license": {
399186                "id": "ISC"
399187              }
399188            }
399189          ],
399190          "cpe": "cpe:2.3:a:libuv:libuv:1.44.1-r0:*:*:*:*:*:*:*",
399191          "purl": "pkg:apk/alpine/libuv@1.44.1-r0?arch=x86_64\u0026distro=alpine-3.16.5",
399192          "swid": {
399193            "attachment": {}
399194          },
399195          "pedigree": {},
399196          "externalReferences": [
399197            {
399198              "url": "https://libuv.org/",
399199              "type": "distribution"
399200            }
399201          ],
399202          "evidence": {},
399203          "signature": {
399204            "signature": {
399205              "publicKey": {}
399206            }
399207          },
399208          "modelCard": {
399209            "modelParameters": {
399210              "approach": {}
399211            },
399212            "quantitativeAnalysis": {
399213              "graphics": {}
399214            },
399215            "considerations": {}
399216          }
399217        },
399218        {
399219          "type": "library",
399220          "bom-ref": "pkg:apk/alpine/libverto@0.3.2-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=b3642afc50cf09b9",
399221          "supplier": {},
399222          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
399223          "name": "libverto",
399224          "version": "0.3.2-r0",
399225          "description": "Main loop abstraction library",
399226          "licenses": [
399227            {
399228              "license": {
399229                "id": "MIT"
399230              }
399231            }
399232          ],
399233          "cpe": "cpe:2.3:a:npmccallum:libverto:0.3.2-r0:*:*:*:*:*:*:*",
399234          "purl": "pkg:apk/alpine/libverto@0.3.2-r0?arch=x86_64\u0026distro=alpine-3.16.5",
399235          "swid": {
399236            "attachment": {}
399237          },
399238          "pedigree": {},
399239          "externalReferences": [
399240            {
399241              "url": "https://github.com/npmccallum/libverto",
399242              "type": "distribution"
399243            }
399244          ],
399245          "evidence": {},
399246          "signature": {
399247            "signature": {
399248              "publicKey": {}
399249            }
399250          },
399251          "modelCard": {
399252            "modelParameters": {
399253              "approach": {}
399254            },
399255            "quantitativeAnalysis": {
399256              "graphics": {}
399257            },
399258            "considerations": {}
399259          }
399260        },
399261        {
399262          "type": "library",
399263          "bom-ref": "pkg:apk/alpine/libxml2@2.9.14-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=66abf048c3e1ee7a",
399264          "supplier": {},
399265          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
399266          "name": "libxml2",
399267          "version": "2.9.14-r2",
399268          "description": "XML parsing library, version 2",
399269          "licenses": [
399270            {
399271              "license": {
399272                "id": "MIT"
399273              }
399274            }
399275          ],
399276          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.14-r2:*:*:*:*:*:*:*",
399277          "purl": "pkg:apk/alpine/libxml2@2.9.14-r2?arch=x86_64\u0026distro=alpine-3.16.5",
399278          "swid": {
399279            "attachment": {}
399280          },
399281          "pedigree": {},
399282          "externalReferences": [
399283            {
399284              "url": "http://www.xmlsoft.org/",
399285              "type": "distribution"
399286            }
399287          ],
399288          "evidence": {},
399289          "signature": {
399290            "signature": {
399291              "publicKey": {}
399292            }
399293          },
399294          "modelCard": {
399295            "modelParameters": {
399296              "approach": {}
399297            },
399298            "quantitativeAnalysis": {
399299              "graphics": {}
399300            },
399301            "considerations": {}
399302          }
399303        },
399304        {
399305          "type": "library",
399306          "bom-ref": "pkg:npm/lodash@4.17.21?package-id=75dfb844472e21c2",
399307          "supplier": {},
399308          "author": "John-David Dalton \u003cjohn.david.dalton@gmail.com\u003e",
399309          "name": "lodash",
399310          "version": "4.17.21",
399311          "description": "Lodash modular utilities.",
399312          "licenses": [
399313            {
399314              "license": {
399315                "id": "MIT"
399316              }
399317            }
399318          ],
399319          "cpe": "cpe:2.3:a:lodash:lodash:4.17.21:*:*:*:*:*:*:*",
399320          "purl": "pkg:npm/lodash@4.17.21",
399321          "swid": {
399322            "attachment": {}
399323          },
399324          "pedigree": {},
399325          "externalReferences": [
399326            {
399327              "url": "lodash/lodash",
399328              "type": "distribution"
399329            },
399330            {
399331              "url": "https://lodash.com/",
399332              "type": "website"
399333            }
399334          ],
399335          "evidence": {},
399336          "signature": {
399337            "signature": {
399338              "publicKey": {}
399339            }
399340          },
399341          "modelCard": {
399342            "modelParameters": {
399343              "approach": {}
399344            },
399345            "quantitativeAnalysis": {
399346              "graphics": {}
399347            },
399348            "considerations": {}
399349          }
399350        },
399351        {
399352          "type": "library",
399353          "bom-ref": "pkg:npm/log-symbols@2.2.0?package-id=8d2a47ede40cad4c",
399354          "supplier": {},
399355          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
399356          "name": "log-symbols",
399357          "version": "2.2.0",
399358          "description": "Colored symbols for various log levels. Example: ✔︎ Success",
399359          "licenses": [
399360            {
399361              "license": {
399362                "id": "MIT"
399363              }
399364            }
399365          ],
399366          "cpe": "cpe:2.3:a:log-symbols:log-symbols:2.2.0:*:*:*:*:*:*:*",
399367          "purl": "pkg:npm/log-symbols@2.2.0",
399368          "swid": {
399369            "attachment": {}
399370          },
399371          "pedigree": {},
399372          "externalReferences": [
399373            {
399374              "url": "sindresorhus/log-symbols",
399375              "type": "distribution"
399376            }
399377          ],
399378          "evidence": {},
399379          "signature": {
399380            "signature": {
399381              "publicKey": {}
399382            }
399383          },
399384          "modelCard": {
399385            "modelParameters": {
399386              "approach": {}
399387            },
399388            "quantitativeAnalysis": {
399389              "graphics": {}
399390            },
399391            "considerations": {}
399392          }
399393        },
399394        {
399395          "type": "library",
399396          "bom-ref": "pkg:npm/lowercase-keys@1.0.0?package-id=a1c7235a8f4dc0c2",
399397          "supplier": {},
399398          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
399399          "name": "lowercase-keys",
399400          "version": "1.0.0",
399401          "description": "Lowercase the keys of an object",
399402          "licenses": [
399403            {
399404              "license": {
399405                "id": "MIT"
399406              }
399407            }
399408          ],
399409          "cpe": "cpe:2.3:a:lowercase-keys:lowercase-keys:1.0.0:*:*:*:*:*:*:*",
399410          "purl": "pkg:npm/lowercase-keys@1.0.0",
399411          "swid": {
399412            "attachment": {}
399413          },
399414          "pedigree": {},
399415          "externalReferences": [
399416            {
399417              "url": "sindresorhus/lowercase-keys",
399418              "type": "distribution"
399419            }
399420          ],
399421          "evidence": {},
399422          "signature": {
399423            "signature": {
399424              "publicKey": {}
399425            }
399426          },
399427          "modelCard": {
399428            "modelParameters": {
399429              "approach": {}
399430            },
399431            "quantitativeAnalysis": {
399432              "graphics": {}
399433            },
399434            "considerations": {}
399435          }
399436        },
399437        {
399438          "type": "library",
399439          "bom-ref": "pkg:npm/lowercase-keys@1.0.1?package-id=bfc50b7d3838d505",
399440          "supplier": {},
399441          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
399442          "name": "lowercase-keys",
399443          "version": "1.0.1",
399444          "description": "Lowercase the keys of an object",
399445          "licenses": [
399446            {
399447              "license": {
399448                "id": "MIT"
399449              }
399450            }
399451          ],
399452          "cpe": "cpe:2.3:a:lowercase-keys:lowercase-keys:1.0.1:*:*:*:*:*:*:*",
399453          "purl": "pkg:npm/lowercase-keys@1.0.1",
399454          "swid": {
399455            "attachment": {}
399456          },
399457          "pedigree": {},
399458          "externalReferences": [
399459            {
399460              "url": "sindresorhus/lowercase-keys",
399461              "type": "distribution"
399462            }
399463          ],
399464          "evidence": {},
399465          "signature": {
399466            "signature": {
399467              "publicKey": {}
399468            }
399469          },
399470          "modelCard": {
399471            "modelParameters": {
399472              "approach": {}
399473            },
399474            "quantitativeAnalysis": {
399475              "graphics": {}
399476            },
399477            "considerations": {}
399478          }
399479        },
399480        {
399481          "type": "library",
399482          "bom-ref": "pkg:npm/lowercase-keys@2.0.0?package-id=b45edfabd9c38885",
399483          "supplier": {},
399484          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
399485          "name": "lowercase-keys",
399486          "version": "2.0.0",
399487          "description": "Lowercase the keys of an object",
399488          "licenses": [
399489            {
399490              "license": {
399491                "id": "MIT"
399492              }
399493            }
399494          ],
399495          "cpe": "cpe:2.3:a:lowercase-keys:lowercase-keys:2.0.0:*:*:*:*:*:*:*",
399496          "purl": "pkg:npm/lowercase-keys@2.0.0",
399497          "swid": {
399498            "attachment": {}
399499          },
399500          "pedigree": {},
399501          "externalReferences": [
399502            {
399503              "url": "sindresorhus/lowercase-keys",
399504              "type": "distribution"
399505            }
399506          ],
399507          "evidence": {},
399508          "signature": {
399509            "signature": {
399510              "publicKey": {}
399511            }
399512          },
399513          "modelCard": {
399514            "modelParameters": {
399515              "approach": {}
399516            },
399517            "quantitativeAnalysis": {
399518              "graphics": {}
399519            },
399520            "considerations": {}
399521          }
399522        },
399523        {
399524          "type": "library",
399525          "bom-ref": "pkg:npm/lru-cache@6.0.0?package-id=a9db11b8d6d48a85",
399526          "supplier": {},
399527          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
399528          "name": "lru-cache",
399529          "version": "6.0.0",
399530          "description": "A cache object that deletes the least-recently-used items.",
399531          "licenses": [
399532            {
399533              "license": {
399534                "id": "ISC"
399535              }
399536            }
399537          ],
399538          "cpe": "cpe:2.3:a:lru-cache:lru-cache:6.0.0:*:*:*:*:*:*:*",
399539          "purl": "pkg:npm/lru-cache@6.0.0",
399540          "swid": {
399541            "attachment": {}
399542          },
399543          "pedigree": {},
399544          "externalReferences": [
399545            {
399546              "url": "git://github.com/isaacs/node-lru-cache.git",
399547              "type": "distribution"
399548            }
399549          ],
399550          "evidence": {},
399551          "signature": {
399552            "signature": {
399553              "publicKey": {}
399554            }
399555          },
399556          "modelCard": {
399557            "modelParameters": {
399558              "approach": {}
399559            },
399560            "quantitativeAnalysis": {
399561              "graphics": {}
399562            },
399563            "considerations": {}
399564          }
399565        },
399566        {
399567          "type": "library",
399568          "bom-ref": "pkg:npm/lru-cache@6.0.0?package-id=c938bdb42f7a80e2",
399569          "supplier": {},
399570          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
399571          "name": "lru-cache",
399572          "version": "6.0.0",
399573          "description": "A cache object that deletes the least-recently-used items.",
399574          "licenses": [
399575            {
399576              "license": {
399577                "id": "ISC"
399578              }
399579            }
399580          ],
399581          "cpe": "cpe:2.3:a:lru-cache:lru-cache:6.0.0:*:*:*:*:*:*:*",
399582          "purl": "pkg:npm/lru-cache@6.0.0",
399583          "swid": {
399584            "attachment": {}
399585          },
399586          "pedigree": {},
399587          "externalReferences": [
399588            {
399589              "url": "git://github.com/isaacs/node-lru-cache.git",
399590              "type": "distribution"
399591            }
399592          ],
399593          "evidence": {},
399594          "signature": {
399595            "signature": {
399596              "publicKey": {}
399597            }
399598          },
399599          "modelCard": {
399600            "modelParameters": {
399601              "approach": {}
399602            },
399603            "quantitativeAnalysis": {
399604              "graphics": {}
399605            },
399606            "considerations": {}
399607          }
399608        },
399609        {
399610          "type": "library",
399611          "bom-ref": "pkg:npm/lru-cache@7.13.2?package-id=be5c7dc6ddace7cd",
399612          "supplier": {},
399613          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e",
399614          "name": "lru-cache",
399615          "version": "7.13.2",
399616          "description": "A cache object that deletes the least-recently-used items.",
399617          "licenses": [
399618            {
399619              "license": {
399620                "id": "ISC"
399621              }
399622            }
399623          ],
399624          "cpe": "cpe:2.3:a:lru-cache:lru-cache:7.13.2:*:*:*:*:*:*:*",
399625          "purl": "pkg:npm/lru-cache@7.13.2",
399626          "swid": {
399627            "attachment": {}
399628          },
399629          "pedigree": {},
399630          "externalReferences": [
399631            {
399632              "url": "git://github.com/isaacs/node-lru-cache.git",
399633              "type": "distribution"
399634            }
399635          ],
399636          "evidence": {},
399637          "signature": {
399638            "signature": {
399639              "publicKey": {}
399640            }
399641          },
399642          "modelCard": {
399643            "modelParameters": {
399644              "approach": {}
399645            },
399646            "quantitativeAnalysis": {
399647              "graphics": {}
399648            },
399649            "considerations": {}
399650          }
399651        },
399652        {
399653          "type": "library",
399654          "bom-ref": "pkg:npm/make-dir@1.3.0?package-id=1a710c6da84dadd",
399655          "supplier": {},
399656          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
399657          "name": "make-dir",
399658          "version": "1.3.0",
399659          "description": "Make a directory and its parents if needed - Think `mkdir -p`",
399660          "licenses": [
399661            {
399662              "license": {
399663                "id": "MIT"
399664              }
399665            }
399666          ],
399667          "cpe": "cpe:2.3:a:make-dir:make-dir:1.3.0:*:*:*:*:*:*:*",
399668          "purl": "pkg:npm/make-dir@1.3.0",
399669          "swid": {
399670            "attachment": {}
399671          },
399672          "pedigree": {},
399673          "externalReferences": [
399674            {
399675              "url": "sindresorhus/make-dir",
399676              "type": "distribution"
399677            }
399678          ],
399679          "evidence": {},
399680          "signature": {
399681            "signature": {
399682              "publicKey": {}
399683            }
399684          },
399685          "modelCard": {
399686            "modelParameters": {
399687              "approach": {}
399688            },
399689            "quantitativeAnalysis": {
399690              "graphics": {}
399691            },
399692            "considerations": {}
399693          }
399694        },
399695        {
399696          "type": "library",
399697          "bom-ref": "pkg:npm/make-dir@2.1.0?package-id=baba47df71577250",
399698          "supplier": {},
399699          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
399700          "name": "make-dir",
399701          "version": "2.1.0",
399702          "description": "Make a directory and its parents if needed - Think `mkdir -p`",
399703          "licenses": [
399704            {
399705              "license": {
399706                "id": "MIT"
399707              }
399708            }
399709          ],
399710          "cpe": "cpe:2.3:a:make-dir:make-dir:2.1.0:*:*:*:*:*:*:*",
399711          "purl": "pkg:npm/make-dir@2.1.0",
399712          "swid": {
399713            "attachment": {}
399714          },
399715          "pedigree": {},
399716          "externalReferences": [
399717            {
399718              "url": "sindresorhus/make-dir",
399719              "type": "distribution"
399720            }
399721          ],
399722          "evidence": {},
399723          "signature": {
399724            "signature": {
399725              "publicKey": {}
399726            }
399727          },
399728          "modelCard": {
399729            "modelParameters": {
399730              "approach": {}
399731            },
399732            "quantitativeAnalysis": {
399733              "graphics": {}
399734            },
399735            "considerations": {}
399736          }
399737        },
399738        {
399739          "type": "library",
399740          "bom-ref": "pkg:npm/make-fetch-happen@10.2.1?package-id=d230079dee920278",
399741          "supplier": {},
399742          "author": "GitHub Inc.",
399743          "name": "make-fetch-happen",
399744          "version": "10.2.1",
399745          "description": "Opinionated, caching, retrying fetch client",
399746          "licenses": [
399747            {
399748              "license": {
399749                "id": "ISC"
399750              }
399751            }
399752          ],
399753          "cpe": "cpe:2.3:a:make-fetch-happen:make-fetch-happen:10.2.1:*:*:*:*:*:*:*",
399754          "purl": "pkg:npm/make-fetch-happen@10.2.1",
399755          "swid": {
399756            "attachment": {}
399757          },
399758          "pedigree": {},
399759          "externalReferences": [
399760            {
399761              "url": "https://github.com/npm/make-fetch-happen.git",
399762              "type": "distribution"
399763            }
399764          ],
399765          "evidence": {},
399766          "signature": {
399767            "signature": {
399768              "publicKey": {}
399769            }
399770          },
399771          "modelCard": {
399772            "modelParameters": {
399773              "approach": {}
399774            },
399775            "quantitativeAnalysis": {
399776              "graphics": {}
399777            },
399778            "considerations": {}
399779          }
399780        },
399781        {
399782          "type": "library",
399783          "bom-ref": "pkg:npm/media-typer@0.3.0?package-id=edc1220ee5504fb4",
399784          "supplier": {},
399785          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
399786          "name": "media-typer",
399787          "version": "0.3.0",
399788          "description": "Simple RFC 6838 media type parser and formatter",
399789          "licenses": [
399790            {
399791              "license": {
399792                "id": "MIT"
399793              }
399794            }
399795          ],
399796          "cpe": "cpe:2.3:a:media-typer:media-typer:0.3.0:*:*:*:*:*:*:*",
399797          "purl": "pkg:npm/media-typer@0.3.0",
399798          "swid": {
399799            "attachment": {}
399800          },
399801          "pedigree": {},
399802          "externalReferences": [
399803            {
399804              "url": "jshttp/media-typer",
399805              "type": "distribution"
399806            }
399807          ],
399808          "evidence": {},
399809          "signature": {
399810            "signature": {
399811              "publicKey": {}
399812            }
399813          },
399814          "modelCard": {
399815            "modelParameters": {
399816              "approach": {}
399817            },
399818            "quantitativeAnalysis": {
399819              "graphics": {}
399820            },
399821            "considerations": {}
399822          }
399823        },
399824        {
399825          "type": "library",
399826          "bom-ref": "pkg:npm/merge-descriptors@1.0.1?package-id=24f38b1ffa4b7603",
399827          "supplier": {},
399828          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
399829          "name": "merge-descriptors",
399830          "version": "1.0.1",
399831          "description": "Merge objects using descriptors",
399832          "licenses": [
399833            {
399834              "license": {
399835                "id": "MIT"
399836              }
399837            }
399838          ],
399839          "cpe": "cpe:2.3:a:merge-descriptors:merge-descriptors:1.0.1:*:*:*:*:*:*:*",
399840          "purl": "pkg:npm/merge-descriptors@1.0.1",
399841          "swid": {
399842            "attachment": {}
399843          },
399844          "pedigree": {},
399845          "externalReferences": [
399846            {
399847              "url": "component/merge-descriptors",
399848              "type": "distribution"
399849            }
399850          ],
399851          "evidence": {},
399852          "signature": {
399853            "signature": {
399854              "publicKey": {}
399855            }
399856          },
399857          "modelCard": {
399858            "modelParameters": {
399859              "approach": {}
399860            },
399861            "quantitativeAnalysis": {
399862              "graphics": {}
399863            },
399864            "considerations": {}
399865          }
399866        },
399867        {
399868          "type": "library",
399869          "bom-ref": "pkg:npm/merge2@1.4.1?package-id=d758b2eba0de62df",
399870          "supplier": {},
399871          "name": "merge2",
399872          "version": "1.4.1",
399873          "description": "Merge multiple streams into one stream in sequence or parallel.",
399874          "licenses": [
399875            {
399876              "license": {
399877                "id": "MIT"
399878              }
399879            }
399880          ],
399881          "cpe": "cpe:2.3:a:teambition:merge2:1.4.1:*:*:*:*:*:*:*",
399882          "purl": "pkg:npm/merge2@1.4.1",
399883          "swid": {
399884            "attachment": {}
399885          },
399886          "pedigree": {},
399887          "externalReferences": [
399888            {
399889              "url": "git@github.com:teambition/merge2.git",
399890              "type": "distribution"
399891            },
399892            {
399893              "url": "https://github.com/teambition/merge2",
399894              "type": "website"
399895            }
399896          ],
399897          "evidence": {},
399898          "signature": {
399899            "signature": {
399900              "publicKey": {}
399901            }
399902          },
399903          "modelCard": {
399904            "modelParameters": {
399905              "approach": {}
399906            },
399907            "quantitativeAnalysis": {
399908              "graphics": {}
399909            },
399910            "considerations": {}
399911          }
399912        },
399913        {
399914          "type": "library",
399915          "bom-ref": "pkg:npm/meriyah@4.3.5?package-id=4ea34f63fa9cbf22",
399916          "supplier": {},
399917          "author": "Kenny F. (https://github.com/KFlash)",
399918          "name": "meriyah",
399919          "version": "4.3.5",
399920          "description": "A 100% compliant, self-hosted javascript parser with high focus on both performance and stability",
399921          "licenses": [
399922            {
399923              "license": {
399924                "id": "ISC"
399925              }
399926            }
399927          ],
399928          "cpe": "cpe:2.3:a:meriyah:meriyah:4.3.5:*:*:*:*:*:*:*",
399929          "purl": "pkg:npm/meriyah@4.3.5",
399930          "swid": {
399931            "attachment": {}
399932          },
399933          "pedigree": {},
399934          "externalReferences": [
399935            {
399936              "url": "https://github.com/meriyah/meriyah",
399937              "type": "distribution"
399938            },
399939            {
399940              "url": "https://github.com/meriyah/meriyah",
399941              "type": "website"
399942            }
399943          ],
399944          "evidence": {},
399945          "signature": {
399946            "signature": {
399947              "publicKey": {}
399948            }
399949          },
399950          "modelCard": {
399951            "modelParameters": {
399952              "approach": {}
399953            },
399954            "quantitativeAnalysis": {
399955              "graphics": {}
399956            },
399957            "considerations": {}
399958          }
399959        },
399960        {
399961          "type": "library",
399962          "bom-ref": "pkg:npm/methods@1.1.2?package-id=9b85a46f19a1f1aa",
399963          "supplier": {},
399964          "name": "methods",
399965          "version": "1.1.2",
399966          "description": "HTTP methods that node supports",
399967          "licenses": [
399968            {
399969              "license": {
399970                "id": "MIT"
399971              }
399972            }
399973          ],
399974          "cpe": "cpe:2.3:a:methods:methods:1.1.2:*:*:*:*:*:*:*",
399975          "purl": "pkg:npm/methods@1.1.2",
399976          "swid": {
399977            "attachment": {}
399978          },
399979          "pedigree": {},
399980          "externalReferences": [
399981            {
399982              "url": "jshttp/methods",
399983              "type": "distribution"
399984            }
399985          ],
399986          "evidence": {},
399987          "signature": {
399988            "signature": {
399989              "publicKey": {}
399990            }
399991          },
399992          "modelCard": {
399993            "modelParameters": {
399994              "approach": {}
399995            },
399996            "quantitativeAnalysis": {
399997              "graphics": {}
399998            },
399999            "considerations": {}
400000          }
400001        },
400002        {
400003          "type": "library",
400004          "bom-ref": "pkg:npm/micromatch@4.0.5?package-id=2bca2e96a69a0be1",
400005          "supplier": {},
400006          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
400007          "name": "micromatch",
400008          "version": "4.0.5",
400009          "description": "Glob matching for javascript/node.js. A replacement and faster alternative to minimatch and multimatch.",
400010          "licenses": [
400011            {
400012              "license": {
400013                "id": "MIT"
400014              }
400015            }
400016          ],
400017          "cpe": "cpe:2.3:a:micromatch:micromatch:4.0.5:*:*:*:*:*:*:*",
400018          "purl": "pkg:npm/micromatch@4.0.5",
400019          "swid": {
400020            "attachment": {}
400021          },
400022          "pedigree": {},
400023          "externalReferences": [
400024            {
400025              "url": "micromatch/micromatch",
400026              "type": "distribution"
400027            },
400028            {
400029              "url": "https://github.com/micromatch/micromatch",
400030              "type": "website"
400031            }
400032          ],
400033          "evidence": {},
400034          "signature": {
400035            "signature": {
400036              "publicKey": {}
400037            }
400038          },
400039          "modelCard": {
400040            "modelParameters": {
400041              "approach": {}
400042            },
400043            "quantitativeAnalysis": {
400044              "graphics": {}
400045            },
400046            "considerations": {}
400047          }
400048        },
400049        {
400050          "type": "library",
400051          "bom-ref": "pkg:npm/mime@1.4.1?package-id=b9a146d2dbc31576",
400052          "supplier": {},
400053          "author": "Robert Kieffer \u003crobert@broofa.com\u003e (http://github.com/broofa)",
400054          "name": "mime",
400055          "version": "1.4.1",
400056          "description": "A comprehensive library for mime-type mapping",
400057          "licenses": [
400058            {
400059              "license": {
400060                "id": "MIT"
400061              }
400062            }
400063          ],
400064          "cpe": "cpe:2.3:a:broofa:mime:1.4.1:*:*:*:*:*:*:*",
400065          "purl": "pkg:npm/mime@1.4.1",
400066          "swid": {
400067            "attachment": {}
400068          },
400069          "pedigree": {},
400070          "externalReferences": [
400071            {
400072              "url": "https://github.com/broofa/node-mime",
400073              "type": "distribution"
400074            }
400075          ],
400076          "evidence": {},
400077          "signature": {
400078            "signature": {
400079              "publicKey": {}
400080            }
400081          },
400082          "modelCard": {
400083            "modelParameters": {
400084              "approach": {}
400085            },
400086            "quantitativeAnalysis": {
400087              "graphics": {}
400088            },
400089            "considerations": {}
400090          }
400091        },
400092        {
400093          "type": "library",
400094          "bom-ref": "pkg:npm/mime-db@1.52.0?package-id=9e5bf4e4d5cc60c1",
400095          "supplier": {},
400096          "name": "mime-db",
400097          "version": "1.52.0",
400098          "description": "Media Type Database",
400099          "licenses": [
400100            {
400101              "license": {
400102                "id": "MIT"
400103              }
400104            }
400105          ],
400106          "cpe": "cpe:2.3:a:mime-db:mime-db:1.52.0:*:*:*:*:*:*:*",
400107          "purl": "pkg:npm/mime-db@1.52.0",
400108          "swid": {
400109            "attachment": {}
400110          },
400111          "pedigree": {},
400112          "externalReferences": [
400113            {
400114              "url": "jshttp/mime-db",
400115              "type": "distribution"
400116            }
400117          ],
400118          "evidence": {},
400119          "signature": {
400120            "signature": {
400121              "publicKey": {}
400122            }
400123          },
400124          "modelCard": {
400125            "modelParameters": {
400126              "approach": {}
400127            },
400128            "quantitativeAnalysis": {
400129              "graphics": {}
400130            },
400131            "considerations": {}
400132          }
400133        },
400134        {
400135          "type": "library",
400136          "bom-ref": "pkg:npm/mime-types@2.1.35?package-id=32ba3cb42be13b7a",
400137          "supplier": {},
400138          "name": "mime-types",
400139          "version": "2.1.35",
400140          "description": "The ultimate javascript content-type utility.",
400141          "licenses": [
400142            {
400143              "license": {
400144                "id": "MIT"
400145              }
400146            }
400147          ],
400148          "cpe": "cpe:2.3:a:mime-types:mime-types:2.1.35:*:*:*:*:*:*:*",
400149          "purl": "pkg:npm/mime-types@2.1.35",
400150          "swid": {
400151            "attachment": {}
400152          },
400153          "pedigree": {},
400154          "externalReferences": [
400155            {
400156              "url": "jshttp/mime-types",
400157              "type": "distribution"
400158            }
400159          ],
400160          "evidence": {},
400161          "signature": {
400162            "signature": {
400163              "publicKey": {}
400164            }
400165          },
400166          "modelCard": {
400167            "modelParameters": {
400168              "approach": {}
400169            },
400170            "quantitativeAnalysis": {
400171              "graphics": {}
400172            },
400173            "considerations": {}
400174          }
400175        },
400176        {
400177          "type": "library",
400178          "bom-ref": "pkg:npm/mimic-fn@1.2.0?package-id=d6d651a648d6c1cf",
400179          "supplier": {},
400180          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
400181          "name": "mimic-fn",
400182          "version": "1.2.0",
400183          "description": "Make a function mimic another one",
400184          "licenses": [
400185            {
400186              "license": {
400187                "id": "MIT"
400188              }
400189            }
400190          ],
400191          "cpe": "cpe:2.3:a:mimic-fn:mimic-fn:1.2.0:*:*:*:*:*:*:*",
400192          "purl": "pkg:npm/mimic-fn@1.2.0",
400193          "swid": {
400194            "attachment": {}
400195          },
400196          "pedigree": {},
400197          "externalReferences": [
400198            {
400199              "url": "sindresorhus/mimic-fn",
400200              "type": "distribution"
400201            }
400202          ],
400203          "evidence": {},
400204          "signature": {
400205            "signature": {
400206              "publicKey": {}
400207            }
400208          },
400209          "modelCard": {
400210            "modelParameters": {
400211              "approach": {}
400212            },
400213            "quantitativeAnalysis": {
400214              "graphics": {}
400215            },
400216            "considerations": {}
400217          }
400218        },
400219        {
400220          "type": "library",
400221          "bom-ref": "pkg:npm/mimic-response@1.0.1?package-id=b2dc0c64c0cc32ba",
400222          "supplier": {},
400223          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
400224          "name": "mimic-response",
400225          "version": "1.0.1",
400226          "description": "Mimic a Node.js HTTP response stream",
400227          "licenses": [
400228            {
400229              "license": {
400230                "id": "MIT"
400231              }
400232            }
400233          ],
400234          "cpe": "cpe:2.3:a:mimic-response:mimic-response:1.0.1:*:*:*:*:*:*:*",
400235          "purl": "pkg:npm/mimic-response@1.0.1",
400236          "swid": {
400237            "attachment": {}
400238          },
400239          "pedigree": {},
400240          "externalReferences": [
400241            {
400242              "url": "sindresorhus/mimic-response",
400243              "type": "distribution"
400244            }
400245          ],
400246          "evidence": {},
400247          "signature": {
400248            "signature": {
400249              "publicKey": {}
400250            }
400251          },
400252          "modelCard": {
400253            "modelParameters": {
400254              "approach": {}
400255            },
400256            "quantitativeAnalysis": {
400257              "graphics": {}
400258            },
400259            "considerations": {}
400260          }
400261        },
400262        {
400263          "type": "library",
400264          "bom-ref": "pkg:npm/mimic-response@3.1.0?package-id=3dabc576ff3c3835",
400265          "supplier": {},
400266          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
400267          "name": "mimic-response",
400268          "version": "3.1.0",
400269          "description": "Mimic a Node.js HTTP response stream",
400270          "licenses": [
400271            {
400272              "license": {
400273                "id": "MIT"
400274              }
400275            }
400276          ],
400277          "cpe": "cpe:2.3:a:mimic-response:mimic-response:3.1.0:*:*:*:*:*:*:*",
400278          "purl": "pkg:npm/mimic-response@3.1.0",
400279          "swid": {
400280            "attachment": {}
400281          },
400282          "pedigree": {},
400283          "externalReferences": [
400284            {
400285              "url": "sindresorhus/mimic-response",
400286              "type": "distribution"
400287            }
400288          ],
400289          "evidence": {},
400290          "signature": {
400291            "signature": {
400292              "publicKey": {}
400293            }
400294          },
400295          "modelCard": {
400296            "modelParameters": {
400297              "approach": {}
400298            },
400299            "quantitativeAnalysis": {
400300              "graphics": {}
400301            },
400302            "considerations": {}
400303          }
400304        },
400305        {
400306          "type": "library",
400307          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=32b47b032f3721ab",
400308          "supplier": {},
400309          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
400310          "name": "minimatch",
400311          "version": "3.1.2",
400312          "description": "a glob matcher in javascript",
400313          "licenses": [
400314            {
400315              "license": {
400316                "id": "ISC"
400317              }
400318            }
400319          ],
400320          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
400321          "purl": "pkg:npm/minimatch@3.1.2",
400322          "swid": {
400323            "attachment": {}
400324          },
400325          "pedigree": {},
400326          "externalReferences": [
400327            {
400328              "url": "git://github.com/isaacs/minimatch.git",
400329              "type": "distribution"
400330            }
400331          ],
400332          "evidence": {},
400333          "signature": {
400334            "signature": {
400335              "publicKey": {}
400336            }
400337          },
400338          "modelCard": {
400339            "modelParameters": {
400340              "approach": {}
400341            },
400342            "quantitativeAnalysis": {
400343              "graphics": {}
400344            },
400345            "considerations": {}
400346          }
400347        },
400348        {
400349          "type": "library",
400350          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=7392185ecbfd5435",
400351          "supplier": {},
400352          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
400353          "name": "minimatch",
400354          "version": "3.1.2",
400355          "description": "a glob matcher in javascript",
400356          "licenses": [
400357            {
400358              "license": {
400359                "id": "ISC"
400360              }
400361            }
400362          ],
400363          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
400364          "purl": "pkg:npm/minimatch@3.1.2",
400365          "swid": {
400366            "attachment": {}
400367          },
400368          "pedigree": {},
400369          "externalReferences": [
400370            {
400371              "url": "git://github.com/isaacs/minimatch.git",
400372              "type": "distribution"
400373            }
400374          ],
400375          "evidence": {},
400376          "signature": {
400377            "signature": {
400378              "publicKey": {}
400379            }
400380          },
400381          "modelCard": {
400382            "modelParameters": {
400383              "approach": {}
400384            },
400385            "quantitativeAnalysis": {
400386              "graphics": {}
400387            },
400388            "considerations": {}
400389          }
400390        },
400391        {
400392          "type": "library",
400393          "bom-ref": "pkg:npm/minimatch@3.1.2?package-id=4a815c2235402e8f",
400394          "supplier": {},
400395          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
400396          "name": "minimatch",
400397          "version": "3.1.2",
400398          "description": "a glob matcher in javascript",
400399          "licenses": [
400400            {
400401              "license": {
400402                "id": "ISC"
400403              }
400404            }
400405          ],
400406          "cpe": "cpe:2.3:a:minimatch:minimatch:3.1.2:*:*:*:*:*:*:*",
400407          "purl": "pkg:npm/minimatch@3.1.2",
400408          "swid": {
400409            "attachment": {}
400410          },
400411          "pedigree": {},
400412          "externalReferences": [
400413            {
400414              "url": "git://github.com/isaacs/minimatch.git",
400415              "type": "distribution"
400416            }
400417          ],
400418          "evidence": {},
400419          "signature": {
400420            "signature": {
400421              "publicKey": {}
400422            }
400423          },
400424          "modelCard": {
400425            "modelParameters": {
400426              "approach": {}
400427            },
400428            "quantitativeAnalysis": {
400429              "graphics": {}
400430            },
400431            "considerations": {}
400432          }
400433        },
400434        {
400435          "type": "library",
400436          "bom-ref": "pkg:npm/minimatch@5.1.0?package-id=7bf8dbc1a2543e83",
400437          "supplier": {},
400438          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
400439          "name": "minimatch",
400440          "version": "5.1.0",
400441          "description": "a glob matcher in javascript",
400442          "licenses": [
400443            {
400444              "license": {
400445                "id": "ISC"
400446              }
400447            }
400448          ],
400449          "cpe": "cpe:2.3:a:minimatch:minimatch:5.1.0:*:*:*:*:*:*:*",
400450          "purl": "pkg:npm/minimatch@5.1.0",
400451          "swid": {
400452            "attachment": {}
400453          },
400454          "pedigree": {},
400455          "externalReferences": [
400456            {
400457              "url": "git://github.com/isaacs/minimatch.git",
400458              "type": "distribution"
400459            }
400460          ],
400461          "evidence": {},
400462          "signature": {
400463            "signature": {
400464              "publicKey": {}
400465            }
400466          },
400467          "modelCard": {
400468            "modelParameters": {
400469              "approach": {}
400470            },
400471            "quantitativeAnalysis": {
400472              "graphics": {}
400473            },
400474            "considerations": {}
400475          }
400476        },
400477        {
400478          "type": "library",
400479          "bom-ref": "pkg:npm/minimist@1.2.8?package-id=b5346d2efe922f83",
400480          "supplier": {},
400481          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
400482          "name": "minimist",
400483          "version": "1.2.8",
400484          "description": "parse argument options",
400485          "licenses": [
400486            {
400487              "license": {
400488                "id": "MIT"
400489              }
400490            }
400491          ],
400492          "cpe": "cpe:2.3:a:minimistjs:minimist:1.2.8:*:*:*:*:*:*:*",
400493          "purl": "pkg:npm/minimist@1.2.8",
400494          "swid": {
400495            "attachment": {}
400496          },
400497          "pedigree": {},
400498          "externalReferences": [
400499            {
400500              "url": "git://github.com/minimistjs/minimist.git",
400501              "type": "distribution"
400502            },
400503            {
400504              "url": "https://github.com/minimistjs/minimist",
400505              "type": "website"
400506            }
400507          ],
400508          "evidence": {},
400509          "signature": {
400510            "signature": {
400511              "publicKey": {}
400512            }
400513          },
400514          "modelCard": {
400515            "modelParameters": {
400516              "approach": {}
400517            },
400518            "quantitativeAnalysis": {
400519              "graphics": {}
400520            },
400521            "considerations": {}
400522          }
400523        },
400524        {
400525          "type": "library",
400526          "bom-ref": "pkg:npm/minio@7.0.12?package-id=4db039cba8df2de",
400527          "supplier": {},
400528          "author": "MinIO, Inc. (https://min.io)",
400529          "name": "minio",
400530          "version": "7.0.12",
400531          "description": "S3 Compatible Cloud Storage client",
400532          "licenses": [
400533            {
400534              "license": {
400535                "id": "Apache-2.0"
400536              }
400537            }
400538          ],
400539          "cpe": "cpe:2.3:a:minio:minio:7.0.12:*:*:*:*:*:*:*",
400540          "purl": "pkg:npm/minio@7.0.12",
400541          "swid": {
400542            "attachment": {}
400543          },
400544          "pedigree": {},
400545          "externalReferences": [
400546            {
400547              "url": "git+https://github.com/minio/minio-js.git",
400548              "type": "distribution"
400549            },
400550            {
400551              "url": "https://github.com/minio/minio-js#readme",
400552              "type": "website"
400553            }
400554          ],
400555          "evidence": {},
400556          "signature": {
400557            "signature": {
400558              "publicKey": {}
400559            }
400560          },
400561          "modelCard": {
400562            "modelParameters": {
400563              "approach": {}
400564            },
400565            "quantitativeAnalysis": {
400566              "graphics": {}
400567            },
400568            "considerations": {}
400569          }
400570        },
400571        {
400572          "type": "library",
400573          "bom-ref": "pkg:npm/minipass@3.3.4?package-id=b613ca6e3e5e1fdb",
400574          "supplier": {},
400575          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
400576          "name": "minipass",
400577          "version": "3.3.4",
400578          "description": "minimal implementation of a PassThrough stream",
400579          "licenses": [
400580            {
400581              "license": {
400582                "id": "ISC"
400583              }
400584            }
400585          ],
400586          "cpe": "cpe:2.3:a:minipass:minipass:3.3.4:*:*:*:*:*:*:*",
400587          "purl": "pkg:npm/minipass@3.3.4",
400588          "swid": {
400589            "attachment": {}
400590          },
400591          "pedigree": {},
400592          "externalReferences": [
400593            {
400594              "url": "git+https://github.com/isaacs/minipass.git",
400595              "type": "distribution"
400596            }
400597          ],
400598          "evidence": {},
400599          "signature": {
400600            "signature": {
400601              "publicKey": {}
400602            }
400603          },
400604          "modelCard": {
400605            "modelParameters": {
400606              "approach": {}
400607            },
400608            "quantitativeAnalysis": {
400609              "graphics": {}
400610            },
400611            "considerations": {}
400612          }
400613        },
400614        {
400615          "type": "library",
400616          "bom-ref": "pkg:npm/minipass@3.3.6?package-id=155d37b12b10bb25",
400617          "supplier": {},
400618          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
400619          "name": "minipass",
400620          "version": "3.3.6",
400621          "description": "minimal implementation of a PassThrough stream",
400622          "licenses": [
400623            {
400624              "license": {
400625                "id": "ISC"
400626              }
400627            }
400628          ],
400629          "cpe": "cpe:2.3:a:minipass:minipass:3.3.6:*:*:*:*:*:*:*",
400630          "purl": "pkg:npm/minipass@3.3.6",
400631          "swid": {
400632            "attachment": {}
400633          },
400634          "pedigree": {},
400635          "externalReferences": [
400636            {
400637              "url": "git+https://github.com/isaacs/minipass.git",
400638              "type": "distribution"
400639            }
400640          ],
400641          "evidence": {},
400642          "signature": {
400643            "signature": {
400644              "publicKey": {}
400645            }
400646          },
400647          "modelCard": {
400648            "modelParameters": {
400649              "approach": {}
400650            },
400651            "quantitativeAnalysis": {
400652              "graphics": {}
400653            },
400654            "considerations": {}
400655          }
400656        },
400657        {
400658          "type": "library",
400659          "bom-ref": "pkg:npm/minipass-collect@1.0.2?package-id=48596b1d4dbb4f19",
400660          "supplier": {},
400661          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
400662          "name": "minipass-collect",
400663          "version": "1.0.2",
400664          "description": "A Minipass stream that collects all the data into a single chunk",
400665          "licenses": [
400666            {
400667              "license": {
400668                "id": "ISC"
400669              }
400670            }
400671          ],
400672          "cpe": "cpe:2.3:a:minipass-collect:minipass-collect:1.0.2:*:*:*:*:*:*:*",
400673          "purl": "pkg:npm/minipass-collect@1.0.2",
400674          "swid": {
400675            "attachment": {}
400676          },
400677          "pedigree": {},
400678          "evidence": {},
400679          "signature": {
400680            "signature": {
400681              "publicKey": {}
400682            }
400683          },
400684          "modelCard": {
400685            "modelParameters": {
400686              "approach": {}
400687            },
400688            "quantitativeAnalysis": {
400689              "graphics": {}
400690            },
400691            "considerations": {}
400692          }
400693        },
400694        {
400695          "type": "library",
400696          "bom-ref": "pkg:npm/minipass-fetch@2.1.1?package-id=1efc5437ba452e1d",
400697          "supplier": {},
400698          "author": "GitHub Inc.",
400699          "name": "minipass-fetch",
400700          "version": "2.1.1",
400701          "description": "An implementation of window.fetch in Node.js using Minipass streams",
400702          "licenses": [
400703            {
400704              "license": {
400705                "id": "MIT"
400706              }
400707            }
400708          ],
400709          "cpe": "cpe:2.3:a:minipass-fetch:minipass-fetch:2.1.1:*:*:*:*:*:*:*",
400710          "purl": "pkg:npm/minipass-fetch@2.1.1",
400711          "swid": {
400712            "attachment": {}
400713          },
400714          "pedigree": {},
400715          "externalReferences": [
400716            {
400717              "url": "https://github.com/npm/minipass-fetch.git",
400718              "type": "distribution"
400719            }
400720          ],
400721          "evidence": {},
400722          "signature": {
400723            "signature": {
400724              "publicKey": {}
400725            }
400726          },
400727          "modelCard": {
400728            "modelParameters": {
400729              "approach": {}
400730            },
400731            "quantitativeAnalysis": {
400732              "graphics": {}
400733            },
400734            "considerations": {}
400735          }
400736        },
400737        {
400738          "type": "library",
400739          "bom-ref": "pkg:npm/minipass-flush@1.0.5?package-id=f00a260926226ede",
400740          "supplier": {},
400741          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
400742          "name": "minipass-flush",
400743          "version": "1.0.5",
400744          "description": "A Minipass stream that calls a flush function before emitting 'end'",
400745          "licenses": [
400746            {
400747              "license": {
400748                "id": "ISC"
400749              }
400750            }
400751          ],
400752          "cpe": "cpe:2.3:a:minipass-flush:minipass-flush:1.0.5:*:*:*:*:*:*:*",
400753          "purl": "pkg:npm/minipass-flush@1.0.5",
400754          "swid": {
400755            "attachment": {}
400756          },
400757          "pedigree": {},
400758          "externalReferences": [
400759            {
400760              "url": "git+https://github.com/isaacs/minipass-flush.git",
400761              "type": "distribution"
400762            }
400763          ],
400764          "evidence": {},
400765          "signature": {
400766            "signature": {
400767              "publicKey": {}
400768            }
400769          },
400770          "modelCard": {
400771            "modelParameters": {
400772              "approach": {}
400773            },
400774            "quantitativeAnalysis": {
400775              "graphics": {}
400776            },
400777            "considerations": {}
400778          }
400779        },
400780        {
400781          "type": "library",
400782          "bom-ref": "pkg:npm/minipass-json-stream@1.0.1?package-id=43ed818882788b6b",
400783          "supplier": {},
400784          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
400785          "name": "minipass-json-stream",
400786          "version": "1.0.1",
400787          "description": "Like JSONStream, but using Minipass streams",
400788          "licenses": [
400789            {
400790              "license": {
400791                "id": "MIT"
400792              }
400793            }
400794          ],
400795          "cpe": "cpe:2.3:a:minipass-json-stream:minipass-json-stream:1.0.1:*:*:*:*:*:*:*",
400796          "purl": "pkg:npm/minipass-json-stream@1.0.1",
400797          "swid": {
400798            "attachment": {}
400799          },
400800          "pedigree": {},
400801          "externalReferences": [
400802            {
400803              "url": "git+https://github.com/npm/minipass-json-stream.git",
400804              "type": "distribution"
400805            }
400806          ],
400807          "evidence": {},
400808          "signature": {
400809            "signature": {
400810              "publicKey": {}
400811            }
400812          },
400813          "modelCard": {
400814            "modelParameters": {
400815              "approach": {}
400816            },
400817            "quantitativeAnalysis": {
400818              "graphics": {}
400819            },
400820            "considerations": {}
400821          }
400822        },
400823        {
400824          "type": "library",
400825          "bom-ref": "pkg:npm/minipass-pipeline@1.2.4?package-id=891713a52fe6cc27",
400826          "supplier": {},
400827          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
400828          "name": "minipass-pipeline",
400829          "version": "1.2.4",
400830          "description": "create a pipeline of streams using Minipass",
400831          "licenses": [
400832            {
400833              "license": {
400834                "id": "ISC"
400835              }
400836            }
400837          ],
400838          "cpe": "cpe:2.3:a:minipass-pipeline:minipass-pipeline:1.2.4:*:*:*:*:*:*:*",
400839          "purl": "pkg:npm/minipass-pipeline@1.2.4",
400840          "swid": {
400841            "attachment": {}
400842          },
400843          "pedigree": {},
400844          "evidence": {},
400845          "signature": {
400846            "signature": {
400847              "publicKey": {}
400848            }
400849          },
400850          "modelCard": {
400851            "modelParameters": {
400852              "approach": {}
400853            },
400854            "quantitativeAnalysis": {
400855              "graphics": {}
400856            },
400857            "considerations": {}
400858          }
400859        },
400860        {
400861          "type": "library",
400862          "bom-ref": "pkg:npm/minipass-sized@1.0.3?package-id=cd4842c35733398b",
400863          "supplier": {},
400864          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
400865          "name": "minipass-sized",
400866          "version": "1.0.3",
400867          "description": "A Minipass stream that raises an error if you get a different number of bytes than expected",
400868          "licenses": [
400869            {
400870              "license": {
400871                "id": "ISC"
400872              }
400873            }
400874          ],
400875          "cpe": "cpe:2.3:a:minipass-sized:minipass-sized:1.0.3:*:*:*:*:*:*:*",
400876          "purl": "pkg:npm/minipass-sized@1.0.3",
400877          "swid": {
400878            "attachment": {}
400879          },
400880          "pedigree": {},
400881          "externalReferences": [
400882            {
400883              "url": "git+https://github.com/isaacs/minipass-sized.git",
400884              "type": "distribution"
400885            }
400886          ],
400887          "evidence": {},
400888          "signature": {
400889            "signature": {
400890              "publicKey": {}
400891            }
400892          },
400893          "modelCard": {
400894            "modelParameters": {
400895              "approach": {}
400896            },
400897            "quantitativeAnalysis": {
400898              "graphics": {}
400899            },
400900            "considerations": {}
400901          }
400902        },
400903        {
400904          "type": "library",
400905          "bom-ref": "pkg:npm/minizlib@2.1.2?package-id=a651644b4f6a3e3",
400906          "supplier": {},
400907          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
400908          "name": "minizlib",
400909          "version": "2.1.2",
400910          "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
400911          "licenses": [
400912            {
400913              "license": {
400914                "id": "MIT"
400915              }
400916            }
400917          ],
400918          "cpe": "cpe:2.3:a:minizlib:minizlib:2.1.2:*:*:*:*:*:*:*",
400919          "purl": "pkg:npm/minizlib@2.1.2",
400920          "swid": {
400921            "attachment": {}
400922          },
400923          "pedigree": {},
400924          "externalReferences": [
400925            {
400926              "url": "git+https://github.com/isaacs/minizlib.git",
400927              "type": "distribution"
400928            }
400929          ],
400930          "evidence": {},
400931          "signature": {
400932            "signature": {
400933              "publicKey": {}
400934            }
400935          },
400936          "modelCard": {
400937            "modelParameters": {
400938              "approach": {}
400939            },
400940            "quantitativeAnalysis": {
400941              "graphics": {}
400942            },
400943            "considerations": {}
400944          }
400945        },
400946        {
400947          "type": "library",
400948          "bom-ref": "pkg:npm/minizlib@2.1.2?package-id=7bb75b451bb46790",
400949          "supplier": {},
400950          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
400951          "name": "minizlib",
400952          "version": "2.1.2",
400953          "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",
400954          "licenses": [
400955            {
400956              "license": {
400957                "id": "MIT"
400958              }
400959            }
400960          ],
400961          "cpe": "cpe:2.3:a:minizlib:minizlib:2.1.2:*:*:*:*:*:*:*",
400962          "purl": "pkg:npm/minizlib@2.1.2",
400963          "swid": {
400964            "attachment": {}
400965          },
400966          "pedigree": {},
400967          "externalReferences": [
400968            {
400969              "url": "git+https://github.com/isaacs/minizlib.git",
400970              "type": "distribution"
400971            }
400972          ],
400973          "evidence": {},
400974          "signature": {
400975            "signature": {
400976              "publicKey": {}
400977            }
400978          },
400979          "modelCard": {
400980            "modelParameters": {
400981              "approach": {}
400982            },
400983            "quantitativeAnalysis": {
400984              "graphics": {}
400985            },
400986            "considerations": {}
400987          }
400988        },
400989        {
400990          "type": "library",
400991          "bom-ref": "pkg:npm/mkdirp@0.5.6?package-id=652fb6b912e95935",
400992          "supplier": {},
400993          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
400994          "name": "mkdirp",
400995          "version": "0.5.6",
400996          "description": "Recursively mkdir, like `mkdir -p`",
400997          "licenses": [
400998            {
400999              "license": {
401000                "id": "MIT"
401001              }
401002            }
401003          ],
401004          "cpe": "cpe:2.3:a:substack:mkdirp:0.5.6:*:*:*:*:*:*:*",
401005          "purl": "pkg:npm/mkdirp@0.5.6",
401006          "swid": {
401007            "attachment": {}
401008          },
401009          "pedigree": {},
401010          "externalReferences": [
401011            {
401012              "url": "https://github.com/substack/node-mkdirp.git",
401013              "type": "distribution"
401014            }
401015          ],
401016          "evidence": {},
401017          "signature": {
401018            "signature": {
401019              "publicKey": {}
401020            }
401021          },
401022          "modelCard": {
401023            "modelParameters": {
401024              "approach": {}
401025            },
401026            "quantitativeAnalysis": {
401027              "graphics": {}
401028            },
401029            "considerations": {}
401030          }
401031        },
401032        {
401033          "type": "library",
401034          "bom-ref": "pkg:npm/mkdirp@1.0.4?package-id=9695628e211e131d",
401035          "supplier": {},
401036          "name": "mkdirp",
401037          "version": "1.0.4",
401038          "description": "Recursively mkdir, like `mkdir -p`",
401039          "licenses": [
401040            {
401041              "license": {
401042                "id": "MIT"
401043              }
401044            }
401045          ],
401046          "cpe": "cpe:2.3:a:isaacs:mkdirp:1.0.4:*:*:*:*:*:*:*",
401047          "purl": "pkg:npm/mkdirp@1.0.4",
401048          "swid": {
401049            "attachment": {}
401050          },
401051          "pedigree": {},
401052          "externalReferences": [
401053            {
401054              "url": "https://github.com/isaacs/node-mkdirp.git",
401055              "type": "distribution"
401056            }
401057          ],
401058          "evidence": {},
401059          "signature": {
401060            "signature": {
401061              "publicKey": {}
401062            }
401063          },
401064          "modelCard": {
401065            "modelParameters": {
401066              "approach": {}
401067            },
401068            "quantitativeAnalysis": {
401069              "graphics": {}
401070            },
401071            "considerations": {}
401072          }
401073        },
401074        {
401075          "type": "library",
401076          "bom-ref": "pkg:npm/mkdirp@1.0.4?package-id=f1b6bb9b4d6c0513",
401077          "supplier": {},
401078          "name": "mkdirp",
401079          "version": "1.0.4",
401080          "description": "Recursively mkdir, like `mkdir -p`",
401081          "licenses": [
401082            {
401083              "license": {
401084                "id": "MIT"
401085              }
401086            }
401087          ],
401088          "cpe": "cpe:2.3:a:isaacs:mkdirp:1.0.4:*:*:*:*:*:*:*",
401089          "purl": "pkg:npm/mkdirp@1.0.4",
401090          "swid": {
401091            "attachment": {}
401092          },
401093          "pedigree": {},
401094          "externalReferences": [
401095            {
401096              "url": "https://github.com/isaacs/node-mkdirp.git",
401097              "type": "distribution"
401098            }
401099          ],
401100          "evidence": {},
401101          "signature": {
401102            "signature": {
401103              "publicKey": {}
401104            }
401105          },
401106          "modelCard": {
401107            "modelParameters": {
401108              "approach": {}
401109            },
401110            "quantitativeAnalysis": {
401111              "graphics": {}
401112            },
401113            "considerations": {}
401114          }
401115        },
401116        {
401117          "type": "library",
401118          "bom-ref": "pkg:npm/mkdirp-infer-owner@2.0.0?package-id=cd2840516db98e09",
401119          "supplier": {},
401120          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
401121          "name": "mkdirp-infer-owner",
401122          "version": "2.0.0",
401123          "description": "mkdirp, but chown to the owner of the containing folder if possible and necessary",
401124          "licenses": [
401125            {
401126              "license": {
401127                "id": "ISC"
401128              }
401129            }
401130          ],
401131          "cpe": "cpe:2.3:a:mkdirp-infer-owner:mkdirp-infer-owner:2.0.0:*:*:*:*:*:*:*",
401132          "purl": "pkg:npm/mkdirp-infer-owner@2.0.0",
401133          "swid": {
401134            "attachment": {}
401135          },
401136          "pedigree": {},
401137          "externalReferences": [
401138            {
401139              "url": "git+https://github.com/isaacs/mkdirp-infer-owner",
401140              "type": "distribution"
401141            }
401142          ],
401143          "evidence": {},
401144          "signature": {
401145            "signature": {
401146              "publicKey": {}
401147            }
401148          },
401149          "modelCard": {
401150            "modelParameters": {
401151              "approach": {}
401152            },
401153            "quantitativeAnalysis": {
401154              "graphics": {}
401155            },
401156            "considerations": {}
401157          }
401158        },
401159        {
401160          "type": "library",
401161          "bom-ref": "pkg:npm/ms@2.0.0?package-id=5a1105814fc945d6",
401162          "supplier": {},
401163          "name": "ms",
401164          "version": "2.0.0",
401165          "description": "Tiny milisecond conversion utility",
401166          "licenses": [
401167            {
401168              "license": {
401169                "id": "MIT"
401170              }
401171            }
401172          ],
401173          "cpe": "cpe:2.3:a:ms:ms:2.0.0:*:*:*:*:*:*:*",
401174          "purl": "pkg:npm/ms@2.0.0",
401175          "swid": {
401176            "attachment": {}
401177          },
401178          "pedigree": {},
401179          "externalReferences": [
401180            {
401181              "url": "zeit/ms",
401182              "type": "distribution"
401183            }
401184          ],
401185          "evidence": {},
401186          "signature": {
401187            "signature": {
401188              "publicKey": {}
401189            }
401190          },
401191          "modelCard": {
401192            "modelParameters": {
401193              "approach": {}
401194            },
401195            "quantitativeAnalysis": {
401196              "graphics": {}
401197            },
401198            "considerations": {}
401199          }
401200        },
401201        {
401202          "type": "library",
401203          "bom-ref": "pkg:npm/ms@2.1.2?package-id=baab6160abc8414d",
401204          "supplier": {},
401205          "name": "ms",
401206          "version": "2.1.2",
401207          "description": "Tiny millisecond conversion utility",
401208          "licenses": [
401209            {
401210              "license": {
401211                "id": "MIT"
401212              }
401213            }
401214          ],
401215          "cpe": "cpe:2.3:a:ms:ms:2.1.2:*:*:*:*:*:*:*",
401216          "purl": "pkg:npm/ms@2.1.2",
401217          "swid": {
401218            "attachment": {}
401219          },
401220          "pedigree": {},
401221          "externalReferences": [
401222            {
401223              "url": "zeit/ms",
401224              "type": "distribution"
401225            }
401226          ],
401227          "evidence": {},
401228          "signature": {
401229            "signature": {
401230              "publicKey": {}
401231            }
401232          },
401233          "modelCard": {
401234            "modelParameters": {
401235              "approach": {}
401236            },
401237            "quantitativeAnalysis": {
401238              "graphics": {}
401239            },
401240            "considerations": {}
401241          }
401242        },
401243        {
401244          "type": "library",
401245          "bom-ref": "pkg:npm/ms@2.1.3?package-id=56db25c219fa0f4e",
401246          "supplier": {},
401247          "name": "ms",
401248          "version": "2.1.3",
401249          "description": "Tiny millisecond conversion utility",
401250          "licenses": [
401251            {
401252              "license": {
401253                "id": "MIT"
401254              }
401255            }
401256          ],
401257          "cpe": "cpe:2.3:a:ms:ms:2.1.3:*:*:*:*:*:*:*",
401258          "purl": "pkg:npm/ms@2.1.3",
401259          "swid": {
401260            "attachment": {}
401261          },
401262          "pedigree": {},
401263          "externalReferences": [
401264            {
401265              "url": "vercel/ms",
401266              "type": "distribution"
401267            }
401268          ],
401269          "evidence": {},
401270          "signature": {
401271            "signature": {
401272              "publicKey": {}
401273            }
401274          },
401275          "modelCard": {
401276            "modelParameters": {
401277              "approach": {}
401278            },
401279            "quantitativeAnalysis": {
401280              "graphics": {}
401281            },
401282            "considerations": {}
401283          }
401284        },
401285        {
401286          "type": "library",
401287          "bom-ref": "pkg:npm/multistream@4.1.0?package-id=efa7c8dfda52ec0d",
401288          "supplier": {},
401289          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
401290          "name": "multistream",
401291          "version": "4.1.0",
401292          "description": "A stream that emits multiple other streams one after another (streams3)",
401293          "licenses": [
401294            {
401295              "license": {
401296                "id": "MIT"
401297              }
401298            }
401299          ],
401300          "cpe": "cpe:2.3:a:multistream:multistream:4.1.0:*:*:*:*:*:*:*",
401301          "purl": "pkg:npm/multistream@4.1.0",
401302          "swid": {
401303            "attachment": {}
401304          },
401305          "pedigree": {},
401306          "externalReferences": [
401307            {
401308              "url": "git://github.com/feross/multistream.git",
401309              "type": "distribution"
401310            },
401311            {
401312              "url": "https://github.com/feross/multistream",
401313              "type": "website"
401314            }
401315          ],
401316          "evidence": {},
401317          "signature": {
401318            "signature": {
401319              "publicKey": {}
401320            }
401321          },
401322          "modelCard": {
401323            "modelParameters": {
401324              "approach": {}
401325            },
401326            "quantitativeAnalysis": {
401327              "graphics": {}
401328            },
401329            "considerations": {}
401330          }
401331        },
401332        {
401333          "type": "library",
401334          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=24c6089b81ca7d19",
401335          "supplier": {},
401336          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
401337          "name": "musl",
401338          "version": "1.2.3-r2",
401339          "description": "the musl c library (libc) implementation",
401340          "licenses": [
401341            {
401342              "license": {
401343                "id": "MIT"
401344              }
401345            }
401346          ],
401347          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r2:*:*:*:*:*:*:*",
401348          "purl": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5",
401349          "swid": {
401350            "attachment": {}
401351          },
401352          "pedigree": {},
401353          "externalReferences": [
401354            {
401355              "url": "https://musl.libc.org/",
401356              "type": "distribution"
401357            }
401358          ],
401359          "evidence": {},
401360          "signature": {
401361            "signature": {
401362              "publicKey": {}
401363            }
401364          },
401365          "modelCard": {
401366            "modelParameters": {
401367              "approach": {}
401368            },
401369            "quantitativeAnalysis": {
401370              "graphics": {}
401371            },
401372            "considerations": {}
401373          }
401374        },
401375        {
401376          "type": "library",
401377          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5\u0026package-id=d33c14d727ae74d1",
401378          "supplier": {},
401379          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
401380          "name": "musl-utils",
401381          "version": "1.2.3-r2",
401382          "description": "the musl c library (libc) implementation",
401383          "licenses": [
401384            {
401385              "license": {
401386                "id": "MIT"
401387              }
401388            },
401389            {
401390              "license": {
401391                "name": "BSD"
401392              }
401393            },
401394            {
401395              "license": {
401396                "id": "GPL-2.0-or-later"
401397              }
401398            }
401399          ],
401400          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r2:*:*:*:*:*:*:*",
401401          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5",
401402          "swid": {
401403            "attachment": {}
401404          },
401405          "pedigree": {},
401406          "externalReferences": [
401407            {
401408              "url": "https://musl.libc.org/",
401409              "type": "distribution"
401410            }
401411          ],
401412          "evidence": {},
401413          "signature": {
401414            "signature": {
401415              "publicKey": {}
401416            }
401417          },
401418          "modelCard": {
401419            "modelParameters": {
401420              "approach": {}
401421            },
401422            "quantitativeAnalysis": {
401423              "graphics": {}
401424            },
401425            "considerations": {}
401426          }
401427        },
401428        {
401429          "type": "library",
401430          "bom-ref": "pkg:npm/mute-stream@0.0.8?package-id=b093eec725f75ac9",
401431          "supplier": {},
401432          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
401433          "name": "mute-stream",
401434          "version": "0.0.8",
401435          "description": "Bytes go in, but they don't come out (when muted).",
401436          "licenses": [
401437            {
401438              "license": {
401439                "id": "ISC"
401440              }
401441            }
401442          ],
401443          "cpe": "cpe:2.3:a:mute-stream:mute-stream:0.0.8:*:*:*:*:*:*:*",
401444          "purl": "pkg:npm/mute-stream@0.0.8",
401445          "swid": {
401446            "attachment": {}
401447          },
401448          "pedigree": {},
401449          "externalReferences": [
401450            {
401451              "url": "git://github.com/isaacs/mute-stream",
401452              "type": "distribution"
401453            }
401454          ],
401455          "evidence": {},
401456          "signature": {
401457            "signature": {
401458              "publicKey": {}
401459            }
401460          },
401461          "modelCard": {
401462            "modelParameters": {
401463              "approach": {}
401464            },
401465            "quantitativeAnalysis": {
401466              "graphics": {}
401467            },
401468            "considerations": {}
401469          }
401470        },
401471        {
401472          "type": "library",
401473          "bom-ref": "pkg:npm/negotiator@0.6.3?package-id=87cc6cb502ab228a",
401474          "supplier": {},
401475          "name": "negotiator",
401476          "version": "0.6.3",
401477          "description": "HTTP content negotiation",
401478          "licenses": [
401479            {
401480              "license": {
401481                "id": "MIT"
401482              }
401483            }
401484          ],
401485          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.3:*:*:*:*:*:*:*",
401486          "purl": "pkg:npm/negotiator@0.6.3",
401487          "swid": {
401488            "attachment": {}
401489          },
401490          "pedigree": {},
401491          "externalReferences": [
401492            {
401493              "url": "jshttp/negotiator",
401494              "type": "distribution"
401495            }
401496          ],
401497          "evidence": {},
401498          "signature": {
401499            "signature": {
401500              "publicKey": {}
401501            }
401502          },
401503          "modelCard": {
401504            "modelParameters": {
401505              "approach": {}
401506            },
401507            "quantitativeAnalysis": {
401508              "graphics": {}
401509            },
401510            "considerations": {}
401511          }
401512        },
401513        {
401514          "type": "library",
401515          "bom-ref": "pkg:npm/negotiator@0.6.3?package-id=9f94722cfe2aef45",
401516          "supplier": {},
401517          "name": "negotiator",
401518          "version": "0.6.3",
401519          "description": "HTTP content negotiation",
401520          "licenses": [
401521            {
401522              "license": {
401523                "id": "MIT"
401524              }
401525            }
401526          ],
401527          "cpe": "cpe:2.3:a:negotiator:negotiator:0.6.3:*:*:*:*:*:*:*",
401528          "purl": "pkg:npm/negotiator@0.6.3",
401529          "swid": {
401530            "attachment": {}
401531          },
401532          "pedigree": {},
401533          "externalReferences": [
401534            {
401535              "url": "jshttp/negotiator",
401536              "type": "distribution"
401537            }
401538          ],
401539          "evidence": {},
401540          "signature": {
401541            "signature": {
401542              "publicKey": {}
401543            }
401544          },
401545          "modelCard": {
401546            "modelParameters": {
401547              "approach": {}
401548            },
401549            "quantitativeAnalysis": {
401550              "graphics": {}
401551            },
401552            "considerations": {}
401553          }
401554        },
401555        {
401556          "type": "library",
401557          "bom-ref": "pkg:npm/nexe@4.0.0-rc.2?package-id=2230662d44dba8ff",
401558          "supplier": {},
401559          "name": "nexe",
401560          "version": "4.0.0-rc.2",
401561          "description": "Create a single executable out of your Node.js application",
401562          "licenses": [
401563            {
401564              "license": {
401565                "id": "MIT"
401566              }
401567            }
401568          ],
401569          "cpe": "cpe:2.3:a:nexe:nexe:4.0.0-rc.2:*:*:*:*:*:*:*",
401570          "purl": "pkg:npm/nexe@4.0.0-rc.2",
401571          "swid": {
401572            "attachment": {}
401573          },
401574          "pedigree": {},
401575          "externalReferences": [
401576            {
401577              "url": "git://github.com/nexe/nexe.git",
401578              "type": "distribution"
401579            }
401580          ],
401581          "evidence": {},
401582          "signature": {
401583            "signature": {
401584              "publicKey": {}
401585            }
401586          },
401587          "modelCard": {
401588            "modelParameters": {
401589              "approach": {}
401590            },
401591            "quantitativeAnalysis": {
401592              "graphics": {}
401593            },
401594            "considerations": {}
401595          }
401596        },
401597        {
401598          "type": "library",
401599          "bom-ref": "pkg:npm/nexe-fs@1.0.1?package-id=d9668f4a991d0db7",
401600          "supplier": {},
401601          "author": "Caleb Boyd",
401602          "name": "nexe-fs",
401603          "version": "1.0.1",
401604          "description": "Virtual File System used by nexe",
401605          "licenses": [
401606            {
401607              "license": {
401608                "id": "MIT"
401609              }
401610            }
401611          ],
401612          "cpe": "cpe:2.3:a:nexe-fs:nexe-fs:1.0.1:*:*:*:*:*:*:*",
401613          "purl": "pkg:npm/nexe-fs@1.0.1",
401614          "swid": {
401615            "attachment": {}
401616          },
401617          "pedigree": {},
401618          "evidence": {},
401619          "signature": {
401620            "signature": {
401621              "publicKey": {}
401622            }
401623          },
401624          "modelCard": {
401625            "modelParameters": {
401626              "approach": {}
401627            },
401628            "quantitativeAnalysis": {
401629              "graphics": {}
401630            },
401631            "considerations": {}
401632          }
401633        },
401634        {
401635          "type": "library",
401636          "bom-ref": "pkg:apk/alpine/nghttp2-libs@1.47.0-r0?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.16.5\u0026package-id=3f26eb4be5f62dce",
401637          "supplier": {},
401638          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
401639          "name": "nghttp2-libs",
401640          "version": "1.47.0-r0",
401641          "description": "Experimental HTTP/2 client, server and proxy (libraries)",
401642          "licenses": [
401643            {
401644              "license": {
401645                "id": "MIT"
401646              }
401647            }
401648          ],
401649          "cpe": "cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.47.0-r0:*:*:*:*:*:*:*",
401650          "purl": "pkg:apk/alpine/nghttp2-libs@1.47.0-r0?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.16.5",
401651          "swid": {
401652            "attachment": {}
401653          },
401654          "pedigree": {},
401655          "externalReferences": [
401656            {
401657              "url": "https://nghttp2.org",
401658              "type": "distribution"
401659            }
401660          ],
401661          "evidence": {},
401662          "signature": {
401663            "signature": {
401664              "publicKey": {}
401665            }
401666          },
401667          "modelCard": {
401668            "modelParameters": {
401669              "approach": {}
401670            },
401671            "quantitativeAnalysis": {
401672              "graphics": {}
401673            },
401674            "considerations": {}
401675          }
401676        },
401677        {
401678          "type": "library",
401679          "bom-ref": "pkg:npm/nice-try@1.0.5?package-id=7d1b9df503880447",
401680          "supplier": {},
401681          "name": "nice-try",
401682          "version": "1.0.5",
401683          "description": "Tries to execute a function and discards any error that occurs",
401684          "licenses": [
401685            {
401686              "license": {
401687                "id": "MIT"
401688              }
401689            }
401690          ],
401691          "cpe": "cpe:2.3:a:electerious:nice-try:1.0.5:*:*:*:*:*:*:*",
401692          "purl": "pkg:npm/nice-try@1.0.5",
401693          "swid": {
401694            "attachment": {}
401695          },
401696          "pedigree": {},
401697          "externalReferences": [
401698            {
401699              "url": "https://github.com/electerious/nice-try.git",
401700              "type": "distribution"
401701            },
401702            {
401703              "url": "https://github.com/electerious/nice-try",
401704              "type": "website"
401705            }
401706          ],
401707          "evidence": {},
401708          "signature": {
401709            "signature": {
401710              "publicKey": {}
401711            }
401712          },
401713          "modelCard": {
401714            "modelParameters": {
401715              "approach": {}
401716            },
401717            "quantitativeAnalysis": {
401718              "graphics": {}
401719            },
401720            "considerations": {}
401721          }
401722        },
401723        {
401724          "type": "application",
401725          "bom-ref": "pkg:generic/node@16.20.0?package-id=c3df0c8aa56599a1",
401726          "supplier": {},
401727          "name": "node",
401728          "version": "16.20.0",
401729          "cpe": "cpe:2.3:a:nodejs:node.js:16.20.0:*:*:*:*:*:*:*",
401730          "purl": "pkg:generic/node@16.20.0",
401731          "swid": {
401732            "attachment": {}
401733          },
401734          "pedigree": {},
401735          "evidence": {},
401736          "signature": {
401737            "signature": {
401738              "publicKey": {}
401739            }
401740          },
401741          "modelCard": {
401742            "modelParameters": {
401743              "approach": {}
401744            },
401745            "quantitativeAnalysis": {
401746              "graphics": {}
401747            },
401748            "considerations": {}
401749          }
401750        },
401751        {
401752          "type": "library",
401753          "bom-ref": "pkg:npm/node-gyp@9.1.0?package-id=594531fb28fce181",
401754          "supplier": {},
401755          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://tootallnate.net)",
401756          "name": "node-gyp",
401757          "version": "9.1.0",
401758          "description": "Node.js native addon build tool",
401759          "licenses": [
401760            {
401761              "license": {
401762                "id": "MIT"
401763              }
401764            }
401765          ],
401766          "cpe": "cpe:2.3:a:node-gyp:node-gyp:9.1.0:*:*:*:*:*:*:*",
401767          "purl": "pkg:npm/node-gyp@9.1.0",
401768          "swid": {
401769            "attachment": {}
401770          },
401771          "pedigree": {},
401772          "externalReferences": [
401773            {
401774              "url": "git://github.com/nodejs/node-gyp.git",
401775              "type": "distribution"
401776            }
401777          ],
401778          "evidence": {},
401779          "signature": {
401780            "signature": {
401781              "publicKey": {}
401782            }
401783          },
401784          "modelCard": {
401785            "modelParameters": {
401786              "approach": {}
401787            },
401788            "quantitativeAnalysis": {
401789              "graphics": {}
401790            },
401791            "considerations": {}
401792          }
401793        },
401794        {
401795          "type": "library",
401796          "bom-ref": "pkg:npm/nopt@5.0.0?package-id=16f8d211f06e4fc1",
401797          "supplier": {},
401798          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
401799          "name": "nopt",
401800          "version": "5.0.0",
401801          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
401802          "licenses": [
401803            {
401804              "license": {
401805                "id": "ISC"
401806              }
401807            }
401808          ],
401809          "cpe": "cpe:2.3:a:nopt:nopt:5.0.0:*:*:*:*:*:*:*",
401810          "purl": "pkg:npm/nopt@5.0.0",
401811          "swid": {
401812            "attachment": {}
401813          },
401814          "pedigree": {},
401815          "externalReferences": [
401816            {
401817              "url": "https://github.com/npm/nopt.git",
401818              "type": "distribution"
401819            }
401820          ],
401821          "evidence": {},
401822          "signature": {
401823            "signature": {
401824              "publicKey": {}
401825            }
401826          },
401827          "modelCard": {
401828            "modelParameters": {
401829              "approach": {}
401830            },
401831            "quantitativeAnalysis": {
401832              "graphics": {}
401833            },
401834            "considerations": {}
401835          }
401836        },
401837        {
401838          "type": "library",
401839          "bom-ref": "pkg:npm/nopt@6.0.0?package-id=2da699f46c59247",
401840          "supplier": {},
401841          "author": "GitHub Inc.",
401842          "name": "nopt",
401843          "version": "6.0.0",
401844          "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",
401845          "licenses": [
401846            {
401847              "license": {
401848                "id": "ISC"
401849              }
401850            }
401851          ],
401852          "cpe": "cpe:2.3:a:nopt:nopt:6.0.0:*:*:*:*:*:*:*",
401853          "purl": "pkg:npm/nopt@6.0.0",
401854          "swid": {
401855            "attachment": {}
401856          },
401857          "pedigree": {},
401858          "externalReferences": [
401859            {
401860              "url": "https://github.com/npm/nopt.git",
401861              "type": "distribution"
401862            }
401863          ],
401864          "evidence": {},
401865          "signature": {
401866            "signature": {
401867              "publicKey": {}
401868            }
401869          },
401870          "modelCard": {
401871            "modelParameters": {
401872              "approach": {}
401873            },
401874            "quantitativeAnalysis": {
401875              "graphics": {}
401876            },
401877            "considerations": {}
401878          }
401879        },
401880        {
401881          "type": "library",
401882          "bom-ref": "pkg:npm/normalize-package-data@4.0.1?package-id=f65ac6113e729b71",
401883          "supplier": {},
401884          "author": "GitHub Inc.",
401885          "name": "normalize-package-data",
401886          "version": "4.0.1",
401887          "description": "Normalizes data that can be found in package.json files.",
401888          "licenses": [
401889            {
401890              "license": {
401891                "id": "BSD-2-Clause"
401892              }
401893            }
401894          ],
401895          "cpe": "cpe:2.3:a:normalize-package-data:normalize-package-data:4.0.1:*:*:*:*:*:*:*",
401896          "purl": "pkg:npm/normalize-package-data@4.0.1",
401897          "swid": {
401898            "attachment": {}
401899          },
401900          "pedigree": {},
401901          "externalReferences": [
401902            {
401903              "url": "https://github.com/npm/normalize-package-data.git",
401904              "type": "distribution"
401905            }
401906          ],
401907          "evidence": {},
401908          "signature": {
401909            "signature": {
401910              "publicKey": {}
401911            }
401912          },
401913          "modelCard": {
401914            "modelParameters": {
401915              "approach": {}
401916            },
401917            "quantitativeAnalysis": {
401918              "graphics": {}
401919            },
401920            "considerations": {}
401921          }
401922        },
401923        {
401924          "type": "library",
401925          "bom-ref": "pkg:npm/normalize-url@2.0.1?package-id=3ddb8a43380fdcb7",
401926          "supplier": {},
401927          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
401928          "name": "normalize-url",
401929          "version": "2.0.1",
401930          "description": "Normalize a URL",
401931          "licenses": [
401932            {
401933              "license": {
401934                "id": "MIT"
401935              }
401936            }
401937          ],
401938          "cpe": "cpe:2.3:a:normalize-url:normalize-url:2.0.1:*:*:*:*:*:*:*",
401939          "purl": "pkg:npm/normalize-url@2.0.1",
401940          "swid": {
401941            "attachment": {}
401942          },
401943          "pedigree": {},
401944          "externalReferences": [
401945            {
401946              "url": "sindresorhus/normalize-url",
401947              "type": "distribution"
401948            }
401949          ],
401950          "evidence": {},
401951          "signature": {
401952            "signature": {
401953              "publicKey": {}
401954            }
401955          },
401956          "modelCard": {
401957            "modelParameters": {
401958              "approach": {}
401959            },
401960            "quantitativeAnalysis": {
401961              "graphics": {}
401962            },
401963            "considerations": {}
401964          }
401965        },
401966        {
401967          "type": "library",
401968          "bom-ref": "pkg:npm/normalize-url@6.1.0?package-id=77f3b52ff425c65e",
401969          "supplier": {},
401970          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
401971          "name": "normalize-url",
401972          "version": "6.1.0",
401973          "description": "Normalize a URL",
401974          "licenses": [
401975            {
401976              "license": {
401977                "id": "MIT"
401978              }
401979            }
401980          ],
401981          "cpe": "cpe:2.3:a:normalize-url:normalize-url:6.1.0:*:*:*:*:*:*:*",
401982          "purl": "pkg:npm/normalize-url@6.1.0",
401983          "swid": {
401984            "attachment": {}
401985          },
401986          "pedigree": {},
401987          "externalReferences": [
401988            {
401989              "url": "sindresorhus/normalize-url",
401990              "type": "distribution"
401991            }
401992          ],
401993          "evidence": {},
401994          "signature": {
401995            "signature": {
401996              "publicKey": {}
401997            }
401998          },
401999          "modelCard": {
402000            "modelParameters": {
402001              "approach": {}
402002            },
402003            "quantitativeAnalysis": {
402004              "graphics": {}
402005            },
402006            "considerations": {}
402007          }
402008        },
402009        {
402010          "type": "library",
402011          "bom-ref": "pkg:npm/npm@8.19.4?package-id=3a7215c0f0fd939a",
402012          "supplier": {},
402013          "author": "GitHub Inc.",
402014          "name": "npm",
402015          "version": "8.19.4",
402016          "description": "a package manager for JavaScript",
402017          "licenses": [
402018            {
402019              "license": {
402020                "id": "Artistic-2.0"
402021              }
402022            }
402023          ],
402024          "cpe": "cpe:2.3:a:npm:npm:8.19.4:*:*:*:*:*:*:*",
402025          "purl": "pkg:npm/npm@8.19.4",
402026          "swid": {
402027            "attachment": {}
402028          },
402029          "pedigree": {},
402030          "externalReferences": [
402031            {
402032              "url": "https://github.com/npm/cli.git",
402033              "type": "distribution"
402034            },
402035            {
402036              "url": "https://docs.npmjs.com/",
402037              "type": "website"
402038            }
402039          ],
402040          "evidence": {},
402041          "signature": {
402042            "signature": {
402043              "publicKey": {}
402044            }
402045          },
402046          "modelCard": {
402047            "modelParameters": {
402048              "approach": {}
402049            },
402050            "quantitativeAnalysis": {
402051              "graphics": {}
402052            },
402053            "considerations": {}
402054          }
402055        },
402056        {
402057          "type": "library",
402058          "bom-ref": "pkg:npm/npm-audit-report@3.0.0?package-id=838d59a41103d415",
402059          "supplier": {},
402060          "author": "GitHub Inc.",
402061          "name": "npm-audit-report",
402062          "version": "3.0.0",
402063          "description": "Given a response from the npm security api, render it into a variety of security reports",
402064          "licenses": [
402065            {
402066              "license": {
402067                "id": "ISC"
402068              }
402069            }
402070          ],
402071          "cpe": "cpe:2.3:a:npm-audit-report:npm-audit-report:3.0.0:*:*:*:*:*:*:*",
402072          "purl": "pkg:npm/npm-audit-report@3.0.0",
402073          "swid": {
402074            "attachment": {}
402075          },
402076          "pedigree": {},
402077          "externalReferences": [
402078            {
402079              "url": "https://github.com/npm/npm-audit-report.git",
402080              "type": "distribution"
402081            },
402082            {
402083              "url": "https://github.com/npm/npm-audit-report#readme",
402084              "type": "website"
402085            }
402086          ],
402087          "evidence": {},
402088          "signature": {
402089            "signature": {
402090              "publicKey": {}
402091            }
402092          },
402093          "modelCard": {
402094            "modelParameters": {
402095              "approach": {}
402096            },
402097            "quantitativeAnalysis": {
402098              "graphics": {}
402099            },
402100            "considerations": {}
402101          }
402102        },
402103        {
402104          "type": "library",
402105          "bom-ref": "pkg:npm/npm-bundled@1.1.2?package-id=d3fc92546524f1a0",
402106          "supplier": {},
402107          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
402108          "name": "npm-bundled",
402109          "version": "1.1.2",
402110          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
402111          "licenses": [
402112            {
402113              "license": {
402114                "id": "ISC"
402115              }
402116            }
402117          ],
402118          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:1.1.2:*:*:*:*:*:*:*",
402119          "purl": "pkg:npm/npm-bundled@1.1.2",
402120          "swid": {
402121            "attachment": {}
402122          },
402123          "pedigree": {},
402124          "externalReferences": [
402125            {
402126              "url": "git+https://github.com/npm/npm-bundled.git",
402127              "type": "distribution"
402128            }
402129          ],
402130          "evidence": {},
402131          "signature": {
402132            "signature": {
402133              "publicKey": {}
402134            }
402135          },
402136          "modelCard": {
402137            "modelParameters": {
402138              "approach": {}
402139            },
402140            "quantitativeAnalysis": {
402141              "graphics": {}
402142            },
402143            "considerations": {}
402144          }
402145        },
402146        {
402147          "type": "library",
402148          "bom-ref": "pkg:npm/npm-bundled@2.0.1?package-id=4342e4ccfcb927ca",
402149          "supplier": {},
402150          "author": "GitHub Inc.",
402151          "name": "npm-bundled",
402152          "version": "2.0.1",
402153          "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",
402154          "licenses": [
402155            {
402156              "license": {
402157                "id": "ISC"
402158              }
402159            }
402160          ],
402161          "cpe": "cpe:2.3:a:npm-bundled:npm-bundled:2.0.1:*:*:*:*:*:*:*",
402162          "purl": "pkg:npm/npm-bundled@2.0.1",
402163          "swid": {
402164            "attachment": {}
402165          },
402166          "pedigree": {},
402167          "externalReferences": [
402168            {
402169              "url": "https://github.com/npm/npm-bundled.git",
402170              "type": "distribution"
402171            }
402172          ],
402173          "evidence": {},
402174          "signature": {
402175            "signature": {
402176              "publicKey": {}
402177            }
402178          },
402179          "modelCard": {
402180            "modelParameters": {
402181              "approach": {}
402182            },
402183            "quantitativeAnalysis": {
402184              "graphics": {}
402185            },
402186            "considerations": {}
402187          }
402188        },
402189        {
402190          "type": "library",
402191          "bom-ref": "pkg:npm/npm-conf@1.1.3?package-id=65c3638215d98b36",
402192          "supplier": {},
402193          "author": "Kevin Martensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
402194          "name": "npm-conf",
402195          "version": "1.1.3",
402196          "description": "Get the npm config",
402197          "licenses": [
402198            {
402199              "license": {
402200                "id": "MIT"
402201              }
402202            }
402203          ],
402204          "cpe": "cpe:2.3:a:npm-conf:npm-conf:1.1.3:*:*:*:*:*:*:*",
402205          "purl": "pkg:npm/npm-conf@1.1.3",
402206          "swid": {
402207            "attachment": {}
402208          },
402209          "pedigree": {},
402210          "externalReferences": [
402211            {
402212              "url": "kevva/npm-conf",
402213              "type": "distribution"
402214            }
402215          ],
402216          "evidence": {},
402217          "signature": {
402218            "signature": {
402219              "publicKey": {}
402220            }
402221          },
402222          "modelCard": {
402223            "modelParameters": {
402224              "approach": {}
402225            },
402226            "quantitativeAnalysis": {
402227              "graphics": {}
402228            },
402229            "considerations": {}
402230          }
402231        },
402232        {
402233          "type": "library",
402234          "bom-ref": "pkg:npm/npm-init@0.0.0?package-id=e58118b5aaeeedd7",
402235          "supplier": {},
402236          "name": "npm-init",
402237          "version": "0.0.0",
402238          "description": "an initter you init wit, innit?",
402239          "licenses": [
402240            {
402241              "license": {
402242                "name": "BSD"
402243              }
402244            }
402245          ],
402246          "cpe": "cpe:2.3:a:npm-init:npm-init:0.0.0:*:*:*:*:*:*:*",
402247          "purl": "pkg:npm/npm-init@0.0.0",
402248          "swid": {
402249            "attachment": {}
402250          },
402251          "pedigree": {},
402252          "evidence": {},
402253          "signature": {
402254            "signature": {
402255              "publicKey": {}
402256            }
402257          },
402258          "modelCard": {
402259            "modelParameters": {
402260              "approach": {}
402261            },
402262            "quantitativeAnalysis": {
402263              "graphics": {}
402264            },
402265            "considerations": {}
402266          }
402267        },
402268        {
402269          "type": "library",
402270          "bom-ref": "pkg:npm/npm-install-checks@5.0.0?package-id=ea3011565b04383b",
402271          "supplier": {},
402272          "author": "GitHub Inc.",
402273          "name": "npm-install-checks",
402274          "version": "5.0.0",
402275          "description": "Check the engines and platform fields in package.json",
402276          "licenses": [
402277            {
402278              "license": {
402279                "id": "BSD-2-Clause"
402280              }
402281            }
402282          ],
402283          "cpe": "cpe:2.3:a:npm-install-checks:npm-install-checks:5.0.0:*:*:*:*:*:*:*",
402284          "purl": "pkg:npm/npm-install-checks@5.0.0",
402285          "swid": {
402286            "attachment": {}
402287          },
402288          "pedigree": {},
402289          "externalReferences": [
402290            {
402291              "url": "https://github.com/npm/npm-install-checks.git",
402292              "type": "distribution"
402293            }
402294          ],
402295          "evidence": {},
402296          "signature": {
402297            "signature": {
402298              "publicKey": {}
402299            }
402300          },
402301          "modelCard": {
402302            "modelParameters": {
402303              "approach": {}
402304            },
402305            "quantitativeAnalysis": {
402306              "graphics": {}
402307            },
402308            "considerations": {}
402309          }
402310        },
402311        {
402312          "type": "library",
402313          "bom-ref": "pkg:npm/npm-normalize-package-bin@1.0.1?package-id=7cccc2d8907ef9bb",
402314          "supplier": {},
402315          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
402316          "name": "npm-normalize-package-bin",
402317          "version": "1.0.1",
402318          "description": "Turn any flavor of allowable package.json bin into a normalized object",
402319          "licenses": [
402320            {
402321              "license": {
402322                "id": "ISC"
402323              }
402324            }
402325          ],
402326          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:1.0.1:*:*:*:*:*:*:*",
402327          "purl": "pkg:npm/npm-normalize-package-bin@1.0.1",
402328          "swid": {
402329            "attachment": {}
402330          },
402331          "pedigree": {},
402332          "externalReferences": [
402333            {
402334              "url": "git+https://github.com/npm/npm-normalize-package-bin",
402335              "type": "distribution"
402336            }
402337          ],
402338          "evidence": {},
402339          "signature": {
402340            "signature": {
402341              "publicKey": {}
402342            }
402343          },
402344          "modelCard": {
402345            "modelParameters": {
402346              "approach": {}
402347            },
402348            "quantitativeAnalysis": {
402349              "graphics": {}
402350            },
402351            "considerations": {}
402352          }
402353        },
402354        {
402355          "type": "library",
402356          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=3b502df6a54faf04",
402357          "supplier": {},
402358          "author": "GitHub Inc.",
402359          "name": "npm-normalize-package-bin",
402360          "version": "2.0.0",
402361          "description": "Turn any flavor of allowable package.json bin into a normalized object",
402362          "licenses": [
402363            {
402364              "license": {
402365                "id": "ISC"
402366              }
402367            }
402368          ],
402369          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
402370          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
402371          "swid": {
402372            "attachment": {}
402373          },
402374          "pedigree": {},
402375          "externalReferences": [
402376            {
402377              "url": "https://github.com/npm/npm-normalize-package-bin.git",
402378              "type": "distribution"
402379            }
402380          ],
402381          "evidence": {},
402382          "signature": {
402383            "signature": {
402384              "publicKey": {}
402385            }
402386          },
402387          "modelCard": {
402388            "modelParameters": {
402389              "approach": {}
402390            },
402391            "quantitativeAnalysis": {
402392              "graphics": {}
402393            },
402394            "considerations": {}
402395          }
402396        },
402397        {
402398          "type": "library",
402399          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=cb496c88bc54cdd7",
402400          "supplier": {},
402401          "author": "GitHub Inc.",
402402          "name": "npm-normalize-package-bin",
402403          "version": "2.0.0",
402404          "description": "Turn any flavor of allowable package.json bin into a normalized object",
402405          "licenses": [
402406            {
402407              "license": {
402408                "id": "ISC"
402409              }
402410            }
402411          ],
402412          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
402413          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
402414          "swid": {
402415            "attachment": {}
402416          },
402417          "pedigree": {},
402418          "externalReferences": [
402419            {
402420              "url": "https://github.com/npm/npm-normalize-package-bin.git",
402421              "type": "distribution"
402422            }
402423          ],
402424          "evidence": {},
402425          "signature": {
402426            "signature": {
402427              "publicKey": {}
402428            }
402429          },
402430          "modelCard": {
402431            "modelParameters": {
402432              "approach": {}
402433            },
402434            "quantitativeAnalysis": {
402435              "graphics": {}
402436            },
402437            "considerations": {}
402438          }
402439        },
402440        {
402441          "type": "library",
402442          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=3675dcedd841f8b6",
402443          "supplier": {},
402444          "author": "GitHub Inc.",
402445          "name": "npm-normalize-package-bin",
402446          "version": "2.0.0",
402447          "description": "Turn any flavor of allowable package.json bin into a normalized object",
402448          "licenses": [
402449            {
402450              "license": {
402451                "id": "ISC"
402452              }
402453            }
402454          ],
402455          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
402456          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
402457          "swid": {
402458            "attachment": {}
402459          },
402460          "pedigree": {},
402461          "externalReferences": [
402462            {
402463              "url": "https://github.com/npm/npm-normalize-package-bin.git",
402464              "type": "distribution"
402465            }
402466          ],
402467          "evidence": {},
402468          "signature": {
402469            "signature": {
402470              "publicKey": {}
402471            }
402472          },
402473          "modelCard": {
402474            "modelParameters": {
402475              "approach": {}
402476            },
402477            "quantitativeAnalysis": {
402478              "graphics": {}
402479            },
402480            "considerations": {}
402481          }
402482        },
402483        {
402484          "type": "library",
402485          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=a6c4eec149dbad2b",
402486          "supplier": {},
402487          "author": "GitHub Inc.",
402488          "name": "npm-normalize-package-bin",
402489          "version": "2.0.0",
402490          "description": "Turn any flavor of allowable package.json bin into a normalized object",
402491          "licenses": [
402492            {
402493              "license": {
402494                "id": "ISC"
402495              }
402496            }
402497          ],
402498          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
402499          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
402500          "swid": {
402501            "attachment": {}
402502          },
402503          "pedigree": {},
402504          "externalReferences": [
402505            {
402506              "url": "https://github.com/npm/npm-normalize-package-bin.git",
402507              "type": "distribution"
402508            }
402509          ],
402510          "evidence": {},
402511          "signature": {
402512            "signature": {
402513              "publicKey": {}
402514            }
402515          },
402516          "modelCard": {
402517            "modelParameters": {
402518              "approach": {}
402519            },
402520            "quantitativeAnalysis": {
402521              "graphics": {}
402522            },
402523            "considerations": {}
402524          }
402525        },
402526        {
402527          "type": "library",
402528          "bom-ref": "pkg:npm/npm-normalize-package-bin@2.0.0?package-id=b373bbb7c439b789",
402529          "supplier": {},
402530          "author": "GitHub Inc.",
402531          "name": "npm-normalize-package-bin",
402532          "version": "2.0.0",
402533          "description": "Turn any flavor of allowable package.json bin into a normalized object",
402534          "licenses": [
402535            {
402536              "license": {
402537                "id": "ISC"
402538              }
402539            }
402540          ],
402541          "cpe": "cpe:2.3:a:npm-normalize-package-bin:npm-normalize-package-bin:2.0.0:*:*:*:*:*:*:*",
402542          "purl": "pkg:npm/npm-normalize-package-bin@2.0.0",
402543          "swid": {
402544            "attachment": {}
402545          },
402546          "pedigree": {},
402547          "externalReferences": [
402548            {
402549              "url": "https://github.com/npm/npm-normalize-package-bin.git",
402550              "type": "distribution"
402551            }
402552          ],
402553          "evidence": {},
402554          "signature": {
402555            "signature": {
402556              "publicKey": {}
402557            }
402558          },
402559          "modelCard": {
402560            "modelParameters": {
402561              "approach": {}
402562            },
402563            "quantitativeAnalysis": {
402564              "graphics": {}
402565            },
402566            "considerations": {}
402567          }
402568        },
402569        {
402570          "type": "library",
402571          "bom-ref": "pkg:npm/npm-package-arg@9.1.0?package-id=30ebe98710a08c64",
402572          "supplier": {},
402573          "author": "GitHub Inc.",
402574          "name": "npm-package-arg",
402575          "version": "9.1.0",
402576          "description": "Parse the things that can be arguments to `npm install`",
402577          "licenses": [
402578            {
402579              "license": {
402580                "id": "ISC"
402581              }
402582            }
402583          ],
402584          "cpe": "cpe:2.3:a:npm-package-arg:npm-package-arg:9.1.0:*:*:*:*:*:*:*",
402585          "purl": "pkg:npm/npm-package-arg@9.1.0",
402586          "swid": {
402587            "attachment": {}
402588          },
402589          "pedigree": {},
402590          "externalReferences": [
402591            {
402592              "url": "https://github.com/npm/npm-package-arg.git",
402593              "type": "distribution"
402594            },
402595            {
402596              "url": "https://github.com/npm/npm-package-arg",
402597              "type": "website"
402598            }
402599          ],
402600          "evidence": {},
402601          "signature": {
402602            "signature": {
402603              "publicKey": {}
402604            }
402605          },
402606          "modelCard": {
402607            "modelParameters": {
402608              "approach": {}
402609            },
402610            "quantitativeAnalysis": {
402611              "graphics": {}
402612            },
402613            "considerations": {}
402614          }
402615        },
402616        {
402617          "type": "library",
402618          "bom-ref": "pkg:npm/npm-packlist@5.1.3?package-id=e87ec46a213d7a87",
402619          "supplier": {},
402620          "author": "GitHub Inc.",
402621          "name": "npm-packlist",
402622          "version": "5.1.3",
402623          "description": "Get a list of the files to add from a folder into an npm package",
402624          "licenses": [
402625            {
402626              "license": {
402627                "id": "ISC"
402628              }
402629            }
402630          ],
402631          "cpe": "cpe:2.3:a:npm-packlist:npm-packlist:5.1.3:*:*:*:*:*:*:*",
402632          "purl": "pkg:npm/npm-packlist@5.1.3",
402633          "swid": {
402634            "attachment": {}
402635          },
402636          "pedigree": {},
402637          "externalReferences": [
402638            {
402639              "url": "https://github.com/npm/npm-packlist.git",
402640              "type": "distribution"
402641            }
402642          ],
402643          "evidence": {},
402644          "signature": {
402645            "signature": {
402646              "publicKey": {}
402647            }
402648          },
402649          "modelCard": {
402650            "modelParameters": {
402651              "approach": {}
402652            },
402653            "quantitativeAnalysis": {
402654              "graphics": {}
402655            },
402656            "considerations": {}
402657          }
402658        },
402659        {
402660          "type": "library",
402661          "bom-ref": "pkg:npm/npm-pick-manifest@7.0.2?package-id=a9dc194030f7ba31",
402662          "supplier": {},
402663          "author": "GitHub Inc.",
402664          "name": "npm-pick-manifest",
402665          "version": "7.0.2",
402666          "description": "Resolves a matching manifest from a package metadata document according to standard npm semver resolution rules.",
402667          "licenses": [
402668            {
402669              "license": {
402670                "id": "ISC"
402671              }
402672            }
402673          ],
402674          "cpe": "cpe:2.3:a:npm-pick-manifest:npm-pick-manifest:7.0.2:*:*:*:*:*:*:*",
402675          "purl": "pkg:npm/npm-pick-manifest@7.0.2",
402676          "swid": {
402677            "attachment": {}
402678          },
402679          "pedigree": {},
402680          "externalReferences": [
402681            {
402682              "url": "https://github.com/npm/npm-pick-manifest.git",
402683              "type": "distribution"
402684            }
402685          ],
402686          "evidence": {},
402687          "signature": {
402688            "signature": {
402689              "publicKey": {}
402690            }
402691          },
402692          "modelCard": {
402693            "modelParameters": {
402694              "approach": {}
402695            },
402696            "quantitativeAnalysis": {
402697              "graphics": {}
402698            },
402699            "considerations": {}
402700          }
402701        },
402702        {
402703          "type": "library",
402704          "bom-ref": "pkg:npm/npm-profile@6.2.1?package-id=4b7db9f7ec8bd8ec",
402705          "supplier": {},
402706          "author": "GitHub Inc.",
402707          "name": "npm-profile",
402708          "version": "6.2.1",
402709          "description": "Library for updating an npmjs.com profile",
402710          "licenses": [
402711            {
402712              "license": {
402713                "id": "ISC"
402714              }
402715            }
402716          ],
402717          "cpe": "cpe:2.3:a:npm-profile:npm-profile:6.2.1:*:*:*:*:*:*:*",
402718          "purl": "pkg:npm/npm-profile@6.2.1",
402719          "swid": {
402720            "attachment": {}
402721          },
402722          "pedigree": {},
402723          "externalReferences": [
402724            {
402725              "url": "https://github.com/npm/npm-profile.git",
402726              "type": "distribution"
402727            }
402728          ],
402729          "evidence": {},
402730          "signature": {
402731            "signature": {
402732              "publicKey": {}
402733            }
402734          },
402735          "modelCard": {
402736            "modelParameters": {
402737              "approach": {}
402738            },
402739            "quantitativeAnalysis": {
402740              "graphics": {}
402741            },
402742            "considerations": {}
402743          }
402744        },
402745        {
402746          "type": "library",
402747          "bom-ref": "pkg:npm/npm-registry-fetch@13.3.1?package-id=4a24a52ce2bed90",
402748          "supplier": {},
402749          "author": "GitHub Inc.",
402750          "name": "npm-registry-fetch",
402751          "version": "13.3.1",
402752          "description": "Fetch-based http client for use with npm registry APIs",
402753          "licenses": [
402754            {
402755              "license": {
402756                "id": "ISC"
402757              }
402758            }
402759          ],
402760          "cpe": "cpe:2.3:a:npm-registry-fetch:npm-registry-fetch:13.3.1:*:*:*:*:*:*:*",
402761          "purl": "pkg:npm/npm-registry-fetch@13.3.1",
402762          "swid": {
402763            "attachment": {}
402764          },
402765          "pedigree": {},
402766          "externalReferences": [
402767            {
402768              "url": "https://github.com/npm/npm-registry-fetch.git",
402769              "type": "distribution"
402770            }
402771          ],
402772          "evidence": {},
402773          "signature": {
402774            "signature": {
402775              "publicKey": {}
402776            }
402777          },
402778          "modelCard": {
402779            "modelParameters": {
402780              "approach": {}
402781            },
402782            "quantitativeAnalysis": {
402783              "graphics": {}
402784            },
402785            "considerations": {}
402786          }
402787        },
402788        {
402789          "type": "library",
402790          "bom-ref": "pkg:npm/npm-user-validate@1.0.1?package-id=6154858fa52c8fec",
402791          "supplier": {},
402792          "author": "Robert Kowalski \u003crok@kowalski.gd\u003e",
402793          "name": "npm-user-validate",
402794          "version": "1.0.1",
402795          "description": "User validations for npm",
402796          "licenses": [
402797            {
402798              "license": {
402799                "id": "BSD-2-Clause"
402800              }
402801            }
402802          ],
402803          "cpe": "cpe:2.3:a:npm-user-validate:npm-user-validate:1.0.1:*:*:*:*:*:*:*",
402804          "purl": "pkg:npm/npm-user-validate@1.0.1",
402805          "swid": {
402806            "attachment": {}
402807          },
402808          "pedigree": {},
402809          "externalReferences": [
402810            {
402811              "url": "git://github.com/npm/npm-user-validate.git",
402812              "type": "distribution"
402813            }
402814          ],
402815          "evidence": {},
402816          "signature": {
402817            "signature": {
402818              "publicKey": {}
402819            }
402820          },
402821          "modelCard": {
402822            "modelParameters": {
402823              "approach": {}
402824            },
402825            "quantitativeAnalysis": {
402826              "graphics": {}
402827            },
402828            "considerations": {}
402829          }
402830        },
402831        {
402832          "type": "library",
402833          "bom-ref": "pkg:npm/npmlog@6.0.2?package-id=e1d7f39551f111f",
402834          "supplier": {},
402835          "author": "GitHub Inc.",
402836          "name": "npmlog",
402837          "version": "6.0.2",
402838          "description": "logger for npm",
402839          "licenses": [
402840            {
402841              "license": {
402842                "id": "ISC"
402843              }
402844            }
402845          ],
402846          "cpe": "cpe:2.3:a:npmlog:npmlog:6.0.2:*:*:*:*:*:*:*",
402847          "purl": "pkg:npm/npmlog@6.0.2",
402848          "swid": {
402849            "attachment": {}
402850          },
402851          "pedigree": {},
402852          "externalReferences": [
402853            {
402854              "url": "https://github.com/npm/npmlog.git",
402855              "type": "distribution"
402856            }
402857          ],
402858          "evidence": {},
402859          "signature": {
402860            "signature": {
402861              "publicKey": {}
402862            }
402863          },
402864          "modelCard": {
402865            "modelParameters": {
402866              "approach": {}
402867            },
402868            "quantitativeAnalysis": {
402869              "graphics": {}
402870            },
402871            "considerations": {}
402872          }
402873        },
402874        {
402875          "type": "library",
402876          "bom-ref": "pkg:npm/oauth-sign@0.9.0?package-id=db172ac1d3949e1b",
402877          "supplier": {},
402878          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
402879          "name": "oauth-sign",
402880          "version": "0.9.0",
402881          "description": "OAuth 1 signing. Formerly a vendor lib in mikeal/request, now a standalone module.",
402882          "licenses": [
402883            {
402884              "license": {
402885                "id": "Apache-2.0"
402886              }
402887            }
402888          ],
402889          "cpe": "cpe:2.3:a:oauth-sign:oauth-sign:0.9.0:*:*:*:*:*:*:*",
402890          "purl": "pkg:npm/oauth-sign@0.9.0",
402891          "swid": {
402892            "attachment": {}
402893          },
402894          "pedigree": {},
402895          "externalReferences": [
402896            {
402897              "url": "https://github.com/mikeal/oauth-sign",
402898              "type": "distribution"
402899            }
402900          ],
402901          "evidence": {},
402902          "signature": {
402903            "signature": {
402904              "publicKey": {}
402905            }
402906          },
402907          "modelCard": {
402908            "modelParameters": {
402909              "approach": {}
402910            },
402911            "quantitativeAnalysis": {
402912              "graphics": {}
402913            },
402914            "considerations": {}
402915          }
402916        },
402917        {
402918          "type": "library",
402919          "bom-ref": "pkg:npm/object-assign@4.1.1?package-id=9f37d7ea88ae7c48",
402920          "supplier": {},
402921          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
402922          "name": "object-assign",
402923          "version": "4.1.1",
402924          "description": "ES2015 `Object.assign()` ponyfill",
402925          "licenses": [
402926            {
402927              "license": {
402928                "id": "MIT"
402929              }
402930            }
402931          ],
402932          "cpe": "cpe:2.3:a:object-assign:object-assign:4.1.1:*:*:*:*:*:*:*",
402933          "purl": "pkg:npm/object-assign@4.1.1",
402934          "swid": {
402935            "attachment": {}
402936          },
402937          "pedigree": {},
402938          "externalReferences": [
402939            {
402940              "url": "sindresorhus/object-assign",
402941              "type": "distribution"
402942            }
402943          ],
402944          "evidence": {},
402945          "signature": {
402946            "signature": {
402947              "publicKey": {}
402948            }
402949          },
402950          "modelCard": {
402951            "modelParameters": {
402952              "approach": {}
402953            },
402954            "quantitativeAnalysis": {
402955              "graphics": {}
402956            },
402957            "considerations": {}
402958          }
402959        },
402960        {
402961          "type": "library",
402962          "bom-ref": "pkg:npm/on-finished@2.3.0?package-id=10e3e142a47fe504",
402963          "supplier": {},
402964          "name": "on-finished",
402965          "version": "2.3.0",
402966          "description": "Execute a callback when a request closes, finishes, or errors",
402967          "licenses": [
402968            {
402969              "license": {
402970                "id": "MIT"
402971              }
402972            }
402973          ],
402974          "cpe": "cpe:2.3:a:on-finished:on-finished:2.3.0:*:*:*:*:*:*:*",
402975          "purl": "pkg:npm/on-finished@2.3.0",
402976          "swid": {
402977            "attachment": {}
402978          },
402979          "pedigree": {},
402980          "externalReferences": [
402981            {
402982              "url": "jshttp/on-finished",
402983              "type": "distribution"
402984            }
402985          ],
402986          "evidence": {},
402987          "signature": {
402988            "signature": {
402989              "publicKey": {}
402990            }
402991          },
402992          "modelCard": {
402993            "modelParameters": {
402994              "approach": {}
402995            },
402996            "quantitativeAnalysis": {
402997              "graphics": {}
402998            },
402999            "considerations": {}
403000          }
403001        },
403002        {
403003          "type": "library",
403004          "bom-ref": "pkg:npm/once@1.4.0?package-id=2bfb1efabaee8e52",
403005          "supplier": {},
403006          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
403007          "name": "once",
403008          "version": "1.4.0",
403009          "description": "Run a function exactly one time",
403010          "licenses": [
403011            {
403012              "license": {
403013                "id": "ISC"
403014              }
403015            }
403016          ],
403017          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
403018          "purl": "pkg:npm/once@1.4.0",
403019          "swid": {
403020            "attachment": {}
403021          },
403022          "pedigree": {},
403023          "externalReferences": [
403024            {
403025              "url": "git://github.com/isaacs/once",
403026              "type": "distribution"
403027            }
403028          ],
403029          "evidence": {},
403030          "signature": {
403031            "signature": {
403032              "publicKey": {}
403033            }
403034          },
403035          "modelCard": {
403036            "modelParameters": {
403037              "approach": {}
403038            },
403039            "quantitativeAnalysis": {
403040              "graphics": {}
403041            },
403042            "considerations": {}
403043          }
403044        },
403045        {
403046          "type": "library",
403047          "bom-ref": "pkg:npm/once@1.4.0?package-id=931b0bd981a31418",
403048          "supplier": {},
403049          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
403050          "name": "once",
403051          "version": "1.4.0",
403052          "description": "Run a function exactly one time",
403053          "licenses": [
403054            {
403055              "license": {
403056                "id": "ISC"
403057              }
403058            }
403059          ],
403060          "cpe": "cpe:2.3:a:isaacs:once:1.4.0:*:*:*:*:*:*:*",
403061          "purl": "pkg:npm/once@1.4.0",
403062          "swid": {
403063            "attachment": {}
403064          },
403065          "pedigree": {},
403066          "externalReferences": [
403067            {
403068              "url": "git://github.com/isaacs/once",
403069              "type": "distribution"
403070            }
403071          ],
403072          "evidence": {},
403073          "signature": {
403074            "signature": {
403075              "publicKey": {}
403076            }
403077          },
403078          "modelCard": {
403079            "modelParameters": {
403080              "approach": {}
403081            },
403082            "quantitativeAnalysis": {
403083              "graphics": {}
403084            },
403085            "considerations": {}
403086          }
403087        },
403088        {
403089          "type": "library",
403090          "bom-ref": "pkg:npm/onetime@2.0.1?package-id=fc7c5811e42bd04a",
403091          "supplier": {},
403092          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403093          "name": "onetime",
403094          "version": "2.0.1",
403095          "description": "Ensure a function is only called once",
403096          "licenses": [
403097            {
403098              "license": {
403099                "id": "MIT"
403100              }
403101            }
403102          ],
403103          "cpe": "cpe:2.3:a:onetime:onetime:2.0.1:*:*:*:*:*:*:*",
403104          "purl": "pkg:npm/onetime@2.0.1",
403105          "swid": {
403106            "attachment": {}
403107          },
403108          "pedigree": {},
403109          "externalReferences": [
403110            {
403111              "url": "sindresorhus/onetime",
403112              "type": "distribution"
403113            }
403114          ],
403115          "evidence": {},
403116          "signature": {
403117            "signature": {
403118              "publicKey": {}
403119            }
403120          },
403121          "modelCard": {
403122            "modelParameters": {
403123              "approach": {}
403124            },
403125            "quantitativeAnalysis": {
403126              "graphics": {}
403127            },
403128            "considerations": {}
403129          }
403130        },
403131        {
403132          "type": "library",
403133          "bom-ref": "pkg:npm/open@7.4.2?package-id=8cdd314bd12da921",
403134          "supplier": {},
403135          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
403136          "name": "open",
403137          "version": "7.4.2",
403138          "description": "Open stuff like URLs, files, executables. Cross-platform.",
403139          "licenses": [
403140            {
403141              "license": {
403142                "id": "MIT"
403143              }
403144            }
403145          ],
403146          "cpe": "cpe:2.3:a:open:open:7.4.2:*:*:*:*:*:*:*",
403147          "purl": "pkg:npm/open@7.4.2",
403148          "swid": {
403149            "attachment": {}
403150          },
403151          "pedigree": {},
403152          "externalReferences": [
403153            {
403154              "url": "sindresorhus/open",
403155              "type": "distribution"
403156            }
403157          ],
403158          "evidence": {},
403159          "signature": {
403160            "signature": {
403161              "publicKey": {}
403162            }
403163          },
403164          "modelCard": {
403165            "modelParameters": {
403166              "approach": {}
403167            },
403168            "quantitativeAnalysis": {
403169              "graphics": {}
403170            },
403171            "considerations": {}
403172          }
403173        },
403174        {
403175          "type": "library",
403176          "bom-ref": "pkg:npm/opener@1.5.2?package-id=44a3614f9f359ab5",
403177          "supplier": {},
403178          "author": "Domenic Denicola \u003cd@domenic.me\u003e (https://domenic.me/)",
403179          "name": "opener",
403180          "version": "1.5.2",
403181          "description": "Opens stuff, like webpages and files and executables, cross-platform",
403182          "licenses": [
403183            {
403184              "license": {
403185                "name": "(WTFPL OR MIT)"
403186              }
403187            }
403188          ],
403189          "cpe": "cpe:2.3:a:opener:opener:1.5.2:*:*:*:*:*:*:*",
403190          "purl": "pkg:npm/opener@1.5.2",
403191          "swid": {
403192            "attachment": {}
403193          },
403194          "pedigree": {},
403195          "externalReferences": [
403196            {
403197              "url": "domenic/opener",
403198              "type": "distribution"
403199            }
403200          ],
403201          "evidence": {},
403202          "signature": {
403203            "signature": {
403204              "publicKey": {}
403205            }
403206          },
403207          "modelCard": {
403208            "modelParameters": {
403209              "approach": {}
403210            },
403211            "quantitativeAnalysis": {
403212              "graphics": {}
403213            },
403214            "considerations": {}
403215          }
403216        },
403217        {
403218          "type": "library",
403219          "bom-ref": "pkg:npm/ora@3.4.0?package-id=9f0a98fd8d0442fd",
403220          "supplier": {},
403221          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403222          "name": "ora",
403223          "version": "3.4.0",
403224          "description": "Elegant terminal spinner",
403225          "licenses": [
403226            {
403227              "license": {
403228                "id": "MIT"
403229              }
403230            }
403231          ],
403232          "cpe": "cpe:2.3:a:ora:ora:3.4.0:*:*:*:*:*:*:*",
403233          "purl": "pkg:npm/ora@3.4.0",
403234          "swid": {
403235            "attachment": {}
403236          },
403237          "pedigree": {},
403238          "externalReferences": [
403239            {
403240              "url": "sindresorhus/ora",
403241              "type": "distribution"
403242            }
403243          ],
403244          "evidence": {},
403245          "signature": {
403246            "signature": {
403247              "publicKey": {}
403248            }
403249          },
403250          "modelCard": {
403251            "modelParameters": {
403252              "approach": {}
403253            },
403254            "quantitativeAnalysis": {
403255              "graphics": {}
403256            },
403257            "considerations": {}
403258          }
403259        },
403260        {
403261          "type": "library",
403262          "bom-ref": "pkg:npm/os-tmpdir@1.0.2?package-id=aac8f32471437c49",
403263          "supplier": {},
403264          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403265          "name": "os-tmpdir",
403266          "version": "1.0.2",
403267          "description": "Node.js os.tmpdir() ponyfill",
403268          "licenses": [
403269            {
403270              "license": {
403271                "id": "MIT"
403272              }
403273            }
403274          ],
403275          "cpe": "cpe:2.3:a:os-tmpdir:os-tmpdir:1.0.2:*:*:*:*:*:*:*",
403276          "purl": "pkg:npm/os-tmpdir@1.0.2",
403277          "swid": {
403278            "attachment": {}
403279          },
403280          "pedigree": {},
403281          "externalReferences": [
403282            {
403283              "url": "sindresorhus/os-tmpdir",
403284              "type": "distribution"
403285            }
403286          ],
403287          "evidence": {},
403288          "signature": {
403289            "signature": {
403290              "publicKey": {}
403291            }
403292          },
403293          "modelCard": {
403294            "modelParameters": {
403295              "approach": {}
403296            },
403297            "quantitativeAnalysis": {
403298              "graphics": {}
403299            },
403300            "considerations": {}
403301          }
403302        },
403303        {
403304          "type": "library",
403305          "bom-ref": "pkg:npm/p-cancelable@0.4.1?package-id=88fc877d9e7491d1",
403306          "supplier": {},
403307          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403308          "name": "p-cancelable",
403309          "version": "0.4.1",
403310          "description": "Create a promise that can be canceled",
403311          "licenses": [
403312            {
403313              "license": {
403314                "id": "MIT"
403315              }
403316            }
403317          ],
403318          "cpe": "cpe:2.3:a:p-cancelable:p-cancelable:0.4.1:*:*:*:*:*:*:*",
403319          "purl": "pkg:npm/p-cancelable@0.4.1",
403320          "swid": {
403321            "attachment": {}
403322          },
403323          "pedigree": {},
403324          "externalReferences": [
403325            {
403326              "url": "sindresorhus/p-cancelable",
403327              "type": "distribution"
403328            }
403329          ],
403330          "evidence": {},
403331          "signature": {
403332            "signature": {
403333              "publicKey": {}
403334            }
403335          },
403336          "modelCard": {
403337            "modelParameters": {
403338              "approach": {}
403339            },
403340            "quantitativeAnalysis": {
403341              "graphics": {}
403342            },
403343            "considerations": {}
403344          }
403345        },
403346        {
403347          "type": "library",
403348          "bom-ref": "pkg:npm/p-cancelable@2.1.1?package-id=b3fbdefc1d12c5b2",
403349          "supplier": {},
403350          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403351          "name": "p-cancelable",
403352          "version": "2.1.1",
403353          "description": "Create a promise that can be canceled",
403354          "licenses": [
403355            {
403356              "license": {
403357                "id": "MIT"
403358              }
403359            }
403360          ],
403361          "cpe": "cpe:2.3:a:p-cancelable:p-cancelable:2.1.1:*:*:*:*:*:*:*",
403362          "purl": "pkg:npm/p-cancelable@2.1.1",
403363          "swid": {
403364            "attachment": {}
403365          },
403366          "pedigree": {},
403367          "externalReferences": [
403368            {
403369              "url": "sindresorhus/p-cancelable",
403370              "type": "distribution"
403371            }
403372          ],
403373          "evidence": {},
403374          "signature": {
403375            "signature": {
403376              "publicKey": {}
403377            }
403378          },
403379          "modelCard": {
403380            "modelParameters": {
403381              "approach": {}
403382            },
403383            "quantitativeAnalysis": {
403384              "graphics": {}
403385            },
403386            "considerations": {}
403387          }
403388        },
403389        {
403390          "type": "library",
403391          "bom-ref": "pkg:npm/p-event@2.3.1?package-id=235c2d8f378c5859",
403392          "supplier": {},
403393          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403394          "name": "p-event",
403395          "version": "2.3.1",
403396          "description": "Promisify an event by waiting for it to be emitted",
403397          "licenses": [
403398            {
403399              "license": {
403400                "id": "MIT"
403401              }
403402            }
403403          ],
403404          "cpe": "cpe:2.3:a:p-event:p-event:2.3.1:*:*:*:*:*:*:*",
403405          "purl": "pkg:npm/p-event@2.3.1",
403406          "swid": {
403407            "attachment": {}
403408          },
403409          "pedigree": {},
403410          "externalReferences": [
403411            {
403412              "url": "sindresorhus/p-event",
403413              "type": "distribution"
403414            }
403415          ],
403416          "evidence": {},
403417          "signature": {
403418            "signature": {
403419              "publicKey": {}
403420            }
403421          },
403422          "modelCard": {
403423            "modelParameters": {
403424              "approach": {}
403425            },
403426            "quantitativeAnalysis": {
403427              "graphics": {}
403428            },
403429            "considerations": {}
403430          }
403431        },
403432        {
403433          "type": "library",
403434          "bom-ref": "pkg:npm/p-finally@1.0.0?package-id=da6b579e26c23918",
403435          "supplier": {},
403436          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403437          "name": "p-finally",
403438          "version": "1.0.0",
403439          "description": "`Promise#finally()` ponyfill - Invoked when the promise is settled regardless of outcome",
403440          "licenses": [
403441            {
403442              "license": {
403443                "id": "MIT"
403444              }
403445            }
403446          ],
403447          "cpe": "cpe:2.3:a:p-finally:p-finally:1.0.0:*:*:*:*:*:*:*",
403448          "purl": "pkg:npm/p-finally@1.0.0",
403449          "swid": {
403450            "attachment": {}
403451          },
403452          "pedigree": {},
403453          "externalReferences": [
403454            {
403455              "url": "sindresorhus/p-finally",
403456              "type": "distribution"
403457            }
403458          ],
403459          "evidence": {},
403460          "signature": {
403461            "signature": {
403462              "publicKey": {}
403463            }
403464          },
403465          "modelCard": {
403466            "modelParameters": {
403467              "approach": {}
403468            },
403469            "quantitativeAnalysis": {
403470              "graphics": {}
403471            },
403472            "considerations": {}
403473          }
403474        },
403475        {
403476          "type": "library",
403477          "bom-ref": "pkg:npm/p-is-promise@1.1.0?package-id=3f226917bfd057cf",
403478          "supplier": {},
403479          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403480          "name": "p-is-promise",
403481          "version": "1.1.0",
403482          "description": "Check if something is a promise",
403483          "licenses": [
403484            {
403485              "license": {
403486                "id": "MIT"
403487              }
403488            }
403489          ],
403490          "cpe": "cpe:2.3:a:p-is-promise:p-is-promise:1.1.0:*:*:*:*:*:*:*",
403491          "purl": "pkg:npm/p-is-promise@1.1.0",
403492          "swid": {
403493            "attachment": {}
403494          },
403495          "pedigree": {},
403496          "externalReferences": [
403497            {
403498              "url": "sindresorhus/p-is-promise",
403499              "type": "distribution"
403500            }
403501          ],
403502          "evidence": {},
403503          "signature": {
403504            "signature": {
403505              "publicKey": {}
403506            }
403507          },
403508          "modelCard": {
403509            "modelParameters": {
403510              "approach": {}
403511            },
403512            "quantitativeAnalysis": {
403513              "graphics": {}
403514            },
403515            "considerations": {}
403516          }
403517        },
403518        {
403519          "type": "library",
403520          "bom-ref": "pkg:npm/p-map@4.0.0?package-id=1c07a8cbe4bd91d5",
403521          "supplier": {},
403522          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
403523          "name": "p-map",
403524          "version": "4.0.0",
403525          "description": "Map over promises concurrently",
403526          "licenses": [
403527            {
403528              "license": {
403529                "id": "MIT"
403530              }
403531            }
403532          ],
403533          "cpe": "cpe:2.3:a:p-map:p-map:4.0.0:*:*:*:*:*:*:*",
403534          "purl": "pkg:npm/p-map@4.0.0",
403535          "swid": {
403536            "attachment": {}
403537          },
403538          "pedigree": {},
403539          "externalReferences": [
403540            {
403541              "url": "sindresorhus/p-map",
403542              "type": "distribution"
403543            }
403544          ],
403545          "evidence": {},
403546          "signature": {
403547            "signature": {
403548              "publicKey": {}
403549            }
403550          },
403551          "modelCard": {
403552            "modelParameters": {
403553              "approach": {}
403554            },
403555            "quantitativeAnalysis": {
403556              "graphics": {}
403557            },
403558            "considerations": {}
403559          }
403560        },
403561        {
403562          "type": "library",
403563          "bom-ref": "pkg:npm/p-timeout@2.0.1?package-id=7cc800cb9fdc544",
403564          "supplier": {},
403565          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403566          "name": "p-timeout",
403567          "version": "2.0.1",
403568          "description": "Timeout a promise after a specified amount of time",
403569          "licenses": [
403570            {
403571              "license": {
403572                "id": "MIT"
403573              }
403574            }
403575          ],
403576          "cpe": "cpe:2.3:a:p-timeout:p-timeout:2.0.1:*:*:*:*:*:*:*",
403577          "purl": "pkg:npm/p-timeout@2.0.1",
403578          "swid": {
403579            "attachment": {}
403580          },
403581          "pedigree": {},
403582          "externalReferences": [
403583            {
403584              "url": "sindresorhus/p-timeout",
403585              "type": "distribution"
403586            }
403587          ],
403588          "evidence": {},
403589          "signature": {
403590            "signature": {
403591              "publicKey": {}
403592            }
403593          },
403594          "modelCard": {
403595            "modelParameters": {
403596              "approach": {}
403597            },
403598            "quantitativeAnalysis": {
403599              "graphics": {}
403600            },
403601            "considerations": {}
403602          }
403603        },
403604        {
403605          "type": "library",
403606          "bom-ref": "pkg:npm/pacote@13.6.2?package-id=481670a57d8719a5",
403607          "supplier": {},
403608          "author": "GitHub Inc.",
403609          "name": "pacote",
403610          "version": "13.6.2",
403611          "description": "JavaScript package downloader",
403612          "licenses": [
403613            {
403614              "license": {
403615                "id": "ISC"
403616              }
403617            }
403618          ],
403619          "cpe": "cpe:2.3:a:pacote:pacote:13.6.2:*:*:*:*:*:*:*",
403620          "purl": "pkg:npm/pacote@13.6.2",
403621          "swid": {
403622            "attachment": {}
403623          },
403624          "pedigree": {},
403625          "externalReferences": [
403626            {
403627              "url": "https://github.com/npm/pacote.git",
403628              "type": "distribution"
403629            }
403630          ],
403631          "evidence": {},
403632          "signature": {
403633            "signature": {
403634              "publicKey": {}
403635            }
403636          },
403637          "modelCard": {
403638            "modelParameters": {
403639              "approach": {}
403640            },
403641            "quantitativeAnalysis": {
403642              "graphics": {}
403643            },
403644            "considerations": {}
403645          }
403646        },
403647        {
403648          "type": "library",
403649          "bom-ref": "pkg:npm/parse-conflict-json@2.0.2?package-id=94638d4f43f17ad7",
403650          "supplier": {},
403651          "author": "GitHub Inc.",
403652          "name": "parse-conflict-json",
403653          "version": "2.0.2",
403654          "description": "Parse a JSON string that has git merge conflicts, resolving if possible",
403655          "licenses": [
403656            {
403657              "license": {
403658                "id": "ISC"
403659              }
403660            }
403661          ],
403662          "cpe": "cpe:2.3:a:parse-conflict-json:parse-conflict-json:2.0.2:*:*:*:*:*:*:*",
403663          "purl": "pkg:npm/parse-conflict-json@2.0.2",
403664          "swid": {
403665            "attachment": {}
403666          },
403667          "pedigree": {},
403668          "externalReferences": [
403669            {
403670              "url": "https://github.com/npm/parse-conflict-json.git",
403671              "type": "distribution"
403672            }
403673          ],
403674          "evidence": {},
403675          "signature": {
403676            "signature": {
403677              "publicKey": {}
403678            }
403679          },
403680          "modelCard": {
403681            "modelParameters": {
403682              "approach": {}
403683            },
403684            "quantitativeAnalysis": {
403685              "graphics": {}
403686            },
403687            "considerations": {}
403688          }
403689        },
403690        {
403691          "type": "library",
403692          "bom-ref": "pkg:npm/parseurl@1.3.3?package-id=5a8f19386b323f4b",
403693          "supplier": {},
403694          "name": "parseurl",
403695          "version": "1.3.3",
403696          "description": "parse a url with memoization",
403697          "licenses": [
403698            {
403699              "license": {
403700                "id": "MIT"
403701              }
403702            }
403703          ],
403704          "cpe": "cpe:2.3:a:parseurl:parseurl:1.3.3:*:*:*:*:*:*:*",
403705          "purl": "pkg:npm/parseurl@1.3.3",
403706          "swid": {
403707            "attachment": {}
403708          },
403709          "pedigree": {},
403710          "externalReferences": [
403711            {
403712              "url": "pillarjs/parseurl",
403713              "type": "distribution"
403714            }
403715          ],
403716          "evidence": {},
403717          "signature": {
403718            "signature": {
403719              "publicKey": {}
403720            }
403721          },
403722          "modelCard": {
403723            "modelParameters": {
403724              "approach": {}
403725            },
403726            "quantitativeAnalysis": {
403727              "graphics": {}
403728            },
403729            "considerations": {}
403730          }
403731        },
403732        {
403733          "type": "library",
403734          "bom-ref": "pkg:npm/patch-package@6.5.1?package-id=f886bed9541911fa",
403735          "supplier": {},
403736          "author": "David Sheldrick",
403737          "name": "patch-package",
403738          "version": "6.5.1",
403739          "description": "Fix broken node modules with no fuss",
403740          "licenses": [
403741            {
403742              "license": {
403743                "id": "MIT"
403744              }
403745            }
403746          ],
403747          "cpe": "cpe:2.3:a:patch-package:patch-package:6.5.1:*:*:*:*:*:*:*",
403748          "purl": "pkg:npm/patch-package@6.5.1",
403749          "swid": {
403750            "attachment": {}
403751          },
403752          "pedigree": {},
403753          "externalReferences": [
403754            {
403755              "url": "github:ds300/patch-package",
403756              "type": "distribution"
403757            }
403758          ],
403759          "evidence": {},
403760          "signature": {
403761            "signature": {
403762              "publicKey": {}
403763            }
403764          },
403765          "modelCard": {
403766            "modelParameters": {
403767              "approach": {}
403768            },
403769            "quantitativeAnalysis": {
403770              "graphics": {}
403771            },
403772            "considerations": {}
403773          }
403774        },
403775        {
403776          "type": "library",
403777          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=ed58648f2f773bd9",
403778          "supplier": {},
403779          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403780          "name": "path-is-absolute",
403781          "version": "1.0.1",
403782          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
403783          "licenses": [
403784            {
403785              "license": {
403786                "id": "MIT"
403787              }
403788            }
403789          ],
403790          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
403791          "purl": "pkg:npm/path-is-absolute@1.0.1",
403792          "swid": {
403793            "attachment": {}
403794          },
403795          "pedigree": {},
403796          "externalReferences": [
403797            {
403798              "url": "sindresorhus/path-is-absolute",
403799              "type": "distribution"
403800            }
403801          ],
403802          "evidence": {},
403803          "signature": {
403804            "signature": {
403805              "publicKey": {}
403806            }
403807          },
403808          "modelCard": {
403809            "modelParameters": {
403810              "approach": {}
403811            },
403812            "quantitativeAnalysis": {
403813              "graphics": {}
403814            },
403815            "considerations": {}
403816          }
403817        },
403818        {
403819          "type": "library",
403820          "bom-ref": "pkg:npm/path-is-absolute@1.0.1?package-id=70cf293874d995a2",
403821          "supplier": {},
403822          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403823          "name": "path-is-absolute",
403824          "version": "1.0.1",
403825          "description": "Node.js 0.12 path.isAbsolute() ponyfill",
403826          "licenses": [
403827            {
403828              "license": {
403829                "id": "MIT"
403830              }
403831            }
403832          ],
403833          "cpe": "cpe:2.3:a:path-is-absolute:path-is-absolute:1.0.1:*:*:*:*:*:*:*",
403834          "purl": "pkg:npm/path-is-absolute@1.0.1",
403835          "swid": {
403836            "attachment": {}
403837          },
403838          "pedigree": {},
403839          "externalReferences": [
403840            {
403841              "url": "sindresorhus/path-is-absolute",
403842              "type": "distribution"
403843            }
403844          ],
403845          "evidence": {},
403846          "signature": {
403847            "signature": {
403848              "publicKey": {}
403849            }
403850          },
403851          "modelCard": {
403852            "modelParameters": {
403853              "approach": {}
403854            },
403855            "quantitativeAnalysis": {
403856              "graphics": {}
403857            },
403858            "considerations": {}
403859          }
403860        },
403861        {
403862          "type": "library",
403863          "bom-ref": "pkg:npm/path-key@2.0.1?package-id=aa889ae5e9059d41",
403864          "supplier": {},
403865          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403866          "name": "path-key",
403867          "version": "2.0.1",
403868          "description": "Get the PATH environment variable key cross-platform",
403869          "licenses": [
403870            {
403871              "license": {
403872                "id": "MIT"
403873              }
403874            }
403875          ],
403876          "cpe": "cpe:2.3:a:path-key:path-key:2.0.1:*:*:*:*:*:*:*",
403877          "purl": "pkg:npm/path-key@2.0.1",
403878          "swid": {
403879            "attachment": {}
403880          },
403881          "pedigree": {},
403882          "externalReferences": [
403883            {
403884              "url": "sindresorhus/path-key",
403885              "type": "distribution"
403886            }
403887          ],
403888          "evidence": {},
403889          "signature": {
403890            "signature": {
403891              "publicKey": {}
403892            }
403893          },
403894          "modelCard": {
403895            "modelParameters": {
403896              "approach": {}
403897            },
403898            "quantitativeAnalysis": {
403899              "graphics": {}
403900            },
403901            "considerations": {}
403902          }
403903        },
403904        {
403905          "type": "library",
403906          "bom-ref": "pkg:npm/path-to-regexp@0.1.7?package-id=ccbe7b36b309edc1",
403907          "supplier": {},
403908          "name": "path-to-regexp",
403909          "version": "0.1.7",
403910          "description": "Express style path to RegExp utility",
403911          "licenses": [
403912            {
403913              "license": {
403914                "id": "MIT"
403915              }
403916            }
403917          ],
403918          "cpe": "cpe:2.3:a:path-to-regexp:path-to-regexp:0.1.7:*:*:*:*:*:*:*",
403919          "purl": "pkg:npm/path-to-regexp@0.1.7",
403920          "swid": {
403921            "attachment": {}
403922          },
403923          "pedigree": {},
403924          "externalReferences": [
403925            {
403926              "url": "https://github.com/component/path-to-regexp.git",
403927              "type": "distribution"
403928            }
403929          ],
403930          "evidence": {},
403931          "signature": {
403932            "signature": {
403933              "publicKey": {}
403934            }
403935          },
403936          "modelCard": {
403937            "modelParameters": {
403938              "approach": {}
403939            },
403940            "quantitativeAnalysis": {
403941              "graphics": {}
403942            },
403943            "considerations": {}
403944          }
403945        },
403946        {
403947          "type": "library",
403948          "bom-ref": "pkg:npm/path-type@4.0.0?package-id=111389da9861c230",
403949          "supplier": {},
403950          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
403951          "name": "path-type",
403952          "version": "4.0.0",
403953          "description": "Check if a path is a file, directory, or symlink",
403954          "licenses": [
403955            {
403956              "license": {
403957                "id": "MIT"
403958              }
403959            }
403960          ],
403961          "cpe": "cpe:2.3:a:path-type:path-type:4.0.0:*:*:*:*:*:*:*",
403962          "purl": "pkg:npm/path-type@4.0.0",
403963          "swid": {
403964            "attachment": {}
403965          },
403966          "pedigree": {},
403967          "externalReferences": [
403968            {
403969              "url": "sindresorhus/path-type",
403970              "type": "distribution"
403971            }
403972          ],
403973          "evidence": {},
403974          "signature": {
403975            "signature": {
403976              "publicKey": {}
403977            }
403978          },
403979          "modelCard": {
403980            "modelParameters": {
403981              "approach": {}
403982            },
403983            "quantitativeAnalysis": {
403984              "graphics": {}
403985            },
403986            "considerations": {}
403987          }
403988        },
403989        {
403990          "type": "library",
403991          "bom-ref": "pkg:npm/pend@1.2.0?package-id=c626cebd6f15c529",
403992          "supplier": {},
403993          "author": "Andrew Kelley \u003csuperjoe30@gmail.com\u003e",
403994          "name": "pend",
403995          "version": "1.2.0",
403996          "description": "dead-simple optimistic async helper",
403997          "licenses": [
403998            {
403999              "license": {
404000                "id": "MIT"
404001              }
404002            }
404003          ],
404004          "cpe": "cpe:2.3:a:andrewrk:pend:1.2.0:*:*:*:*:*:*:*",
404005          "purl": "pkg:npm/pend@1.2.0",
404006          "swid": {
404007            "attachment": {}
404008          },
404009          "pedigree": {},
404010          "externalReferences": [
404011            {
404012              "url": "git://github.com/andrewrk/node-pend.git",
404013              "type": "distribution"
404014            }
404015          ],
404016          "evidence": {},
404017          "signature": {
404018            "signature": {
404019              "publicKey": {}
404020            }
404021          },
404022          "modelCard": {
404023            "modelParameters": {
404024              "approach": {}
404025            },
404026            "quantitativeAnalysis": {
404027              "graphics": {}
404028            },
404029            "considerations": {}
404030          }
404031        },
404032        {
404033          "type": "library",
404034          "bom-ref": "pkg:npm/performance-now@2.1.0?package-id=571cf474f11938e4",
404035          "supplier": {},
404036          "author": "Braveg1rl \u003cbraveg1rl@outlook.com\u003e",
404037          "name": "performance-now",
404038          "version": "2.1.0",
404039          "description": "Implements performance.now (based on process.hrtime).",
404040          "licenses": [
404041            {
404042              "license": {
404043                "id": "MIT"
404044              }
404045            }
404046          ],
404047          "cpe": "cpe:2.3:a:performance-now:performance-now:2.1.0:*:*:*:*:*:*:*",
404048          "purl": "pkg:npm/performance-now@2.1.0",
404049          "swid": {
404050            "attachment": {}
404051          },
404052          "pedigree": {},
404053          "externalReferences": [
404054            {
404055              "url": "git://github.com/braveg1rl/performance-now.git",
404056              "type": "distribution"
404057            },
404058            {
404059              "url": "https://github.com/braveg1rl/performance-now",
404060              "type": "website"
404061            }
404062          ],
404063          "evidence": {},
404064          "signature": {
404065            "signature": {
404066              "publicKey": {}
404067            }
404068          },
404069          "modelCard": {
404070            "modelParameters": {
404071              "approach": {}
404072            },
404073            "quantitativeAnalysis": {
404074              "graphics": {}
404075            },
404076            "considerations": {}
404077          }
404078        },
404079        {
404080          "type": "library",
404081          "bom-ref": "pkg:npm/picomatch@2.3.1?package-id=ff31ef2760eb1e42",
404082          "supplier": {},
404083          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
404084          "name": "picomatch",
404085          "version": "2.3.1",
404086          "description": "Blazing fast and accurate glob matcher written in JavaScript, with no dependencies and full support for standard and extended Bash glob features, including braces, extglobs, POSIX brackets, and regular expressions.",
404087          "licenses": [
404088            {
404089              "license": {
404090                "id": "MIT"
404091              }
404092            }
404093          ],
404094          "cpe": "cpe:2.3:a:micromatch:picomatch:2.3.1:*:*:*:*:*:*:*",
404095          "purl": "pkg:npm/picomatch@2.3.1",
404096          "swid": {
404097            "attachment": {}
404098          },
404099          "pedigree": {},
404100          "externalReferences": [
404101            {
404102              "url": "micromatch/picomatch",
404103              "type": "distribution"
404104            },
404105            {
404106              "url": "https://github.com/micromatch/picomatch",
404107              "type": "website"
404108            }
404109          ],
404110          "evidence": {},
404111          "signature": {
404112            "signature": {
404113              "publicKey": {}
404114            }
404115          },
404116          "modelCard": {
404117            "modelParameters": {
404118              "approach": {}
404119            },
404120            "quantitativeAnalysis": {
404121              "graphics": {}
404122            },
404123            "considerations": {}
404124          }
404125        },
404126        {
404127          "type": "library",
404128          "bom-ref": "pkg:npm/pify@2.3.0?package-id=4a597243f8bf0ba1",
404129          "supplier": {},
404130          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
404131          "name": "pify",
404132          "version": "2.3.0",
404133          "description": "Promisify a callback-style function",
404134          "licenses": [
404135            {
404136              "license": {
404137                "id": "MIT"
404138              }
404139            }
404140          ],
404141          "cpe": "cpe:2.3:a:pify:pify:2.3.0:*:*:*:*:*:*:*",
404142          "purl": "pkg:npm/pify@2.3.0",
404143          "swid": {
404144            "attachment": {}
404145          },
404146          "pedigree": {},
404147          "externalReferences": [
404148            {
404149              "url": "sindresorhus/pify",
404150              "type": "distribution"
404151            }
404152          ],
404153          "evidence": {},
404154          "signature": {
404155            "signature": {
404156              "publicKey": {}
404157            }
404158          },
404159          "modelCard": {
404160            "modelParameters": {
404161              "approach": {}
404162            },
404163            "quantitativeAnalysis": {
404164              "graphics": {}
404165            },
404166            "considerations": {}
404167          }
404168        },
404169        {
404170          "type": "library",
404171          "bom-ref": "pkg:npm/pify@2.3.0?package-id=3a9abe2be0a4671d",
404172          "supplier": {},
404173          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
404174          "name": "pify",
404175          "version": "2.3.0",
404176          "description": "Promisify a callback-style function",
404177          "licenses": [
404178            {
404179              "license": {
404180                "id": "MIT"
404181              }
404182            }
404183          ],
404184          "cpe": "cpe:2.3:a:pify:pify:2.3.0:*:*:*:*:*:*:*",
404185          "purl": "pkg:npm/pify@2.3.0",
404186          "swid": {
404187            "attachment": {}
404188          },
404189          "pedigree": {},
404190          "externalReferences": [
404191            {
404192              "url": "sindresorhus/pify",
404193              "type": "distribution"
404194            }
404195          ],
404196          "evidence": {},
404197          "signature": {
404198            "signature": {
404199              "publicKey": {}
404200            }
404201          },
404202          "modelCard": {
404203            "modelParameters": {
404204              "approach": {}
404205            },
404206            "quantitativeAnalysis": {
404207              "graphics": {}
404208            },
404209            "considerations": {}
404210          }
404211        },
404212        {
404213          "type": "library",
404214          "bom-ref": "pkg:npm/pify@3.0.0?package-id=48faab299d974c49",
404215          "supplier": {},
404216          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
404217          "name": "pify",
404218          "version": "3.0.0",
404219          "description": "Promisify a callback-style function",
404220          "licenses": [
404221            {
404222              "license": {
404223                "id": "MIT"
404224              }
404225            }
404226          ],
404227          "cpe": "cpe:2.3:a:pify:pify:3.0.0:*:*:*:*:*:*:*",
404228          "purl": "pkg:npm/pify@3.0.0",
404229          "swid": {
404230            "attachment": {}
404231          },
404232          "pedigree": {},
404233          "externalReferences": [
404234            {
404235              "url": "sindresorhus/pify",
404236              "type": "distribution"
404237            }
404238          ],
404239          "evidence": {},
404240          "signature": {
404241            "signature": {
404242              "publicKey": {}
404243            }
404244          },
404245          "modelCard": {
404246            "modelParameters": {
404247              "approach": {}
404248            },
404249            "quantitativeAnalysis": {
404250              "graphics": {}
404251            },
404252            "considerations": {}
404253          }
404254        },
404255        {
404256          "type": "library",
404257          "bom-ref": "pkg:npm/pify@3.0.0?package-id=bd1f6f3d1c1c216d",
404258          "supplier": {},
404259          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
404260          "name": "pify",
404261          "version": "3.0.0",
404262          "description": "Promisify a callback-style function",
404263          "licenses": [
404264            {
404265              "license": {
404266                "id": "MIT"
404267              }
404268            }
404269          ],
404270          "cpe": "cpe:2.3:a:pify:pify:3.0.0:*:*:*:*:*:*:*",
404271          "purl": "pkg:npm/pify@3.0.0",
404272          "swid": {
404273            "attachment": {}
404274          },
404275          "pedigree": {},
404276          "externalReferences": [
404277            {
404278              "url": "sindresorhus/pify",
404279              "type": "distribution"
404280            }
404281          ],
404282          "evidence": {},
404283          "signature": {
404284            "signature": {
404285              "publicKey": {}
404286            }
404287          },
404288          "modelCard": {
404289            "modelParameters": {
404290              "approach": {}
404291            },
404292            "quantitativeAnalysis": {
404293              "graphics": {}
404294            },
404295            "considerations": {}
404296          }
404297        },
404298        {
404299          "type": "library",
404300          "bom-ref": "pkg:npm/pify@3.0.0?package-id=63783c44baabb416",
404301          "supplier": {},
404302          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
404303          "name": "pify",
404304          "version": "3.0.0",
404305          "description": "Promisify a callback-style function",
404306          "licenses": [
404307            {
404308              "license": {
404309                "id": "MIT"
404310              }
404311            }
404312          ],
404313          "cpe": "cpe:2.3:a:pify:pify:3.0.0:*:*:*:*:*:*:*",
404314          "purl": "pkg:npm/pify@3.0.0",
404315          "swid": {
404316            "attachment": {}
404317          },
404318          "pedigree": {},
404319          "externalReferences": [
404320            {
404321              "url": "sindresorhus/pify",
404322              "type": "distribution"
404323            }
404324          ],
404325          "evidence": {},
404326          "signature": {
404327            "signature": {
404328              "publicKey": {}
404329            }
404330          },
404331          "modelCard": {
404332            "modelParameters": {
404333              "approach": {}
404334            },
404335            "quantitativeAnalysis": {
404336              "graphics": {}
404337            },
404338            "considerations": {}
404339          }
404340        },
404341        {
404342          "type": "library",
404343          "bom-ref": "pkg:npm/pify@4.0.1?package-id=3a8ac21fa7d5c8a0",
404344          "supplier": {},
404345          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
404346          "name": "pify",
404347          "version": "4.0.1",
404348          "description": "Promisify a callback-style function",
404349          "licenses": [
404350            {
404351              "license": {
404352                "id": "MIT"
404353              }
404354            }
404355          ],
404356          "cpe": "cpe:2.3:a:pify:pify:4.0.1:*:*:*:*:*:*:*",
404357          "purl": "pkg:npm/pify@4.0.1",
404358          "swid": {
404359            "attachment": {}
404360          },
404361          "pedigree": {},
404362          "externalReferences": [
404363            {
404364              "url": "sindresorhus/pify",
404365              "type": "distribution"
404366            }
404367          ],
404368          "evidence": {},
404369          "signature": {
404370            "signature": {
404371              "publicKey": {}
404372            }
404373          },
404374          "modelCard": {
404375            "modelParameters": {
404376              "approach": {}
404377            },
404378            "quantitativeAnalysis": {
404379              "graphics": {}
404380            },
404381            "considerations": {}
404382          }
404383        },
404384        {
404385          "type": "library",
404386          "bom-ref": "pkg:npm/pinkie@2.0.4?package-id=e1d834463167bf3a",
404387          "supplier": {},
404388          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
404389          "name": "pinkie",
404390          "version": "2.0.4",
404391          "description": "Itty bitty little widdle twinkie pinkie ES2015 Promise implementation",
404392          "licenses": [
404393            {
404394              "license": {
404395                "id": "MIT"
404396              }
404397            }
404398          ],
404399          "cpe": "cpe:2.3:a:pinkie:pinkie:2.0.4:*:*:*:*:*:*:*",
404400          "purl": "pkg:npm/pinkie@2.0.4",
404401          "swid": {
404402            "attachment": {}
404403          },
404404          "pedigree": {},
404405          "externalReferences": [
404406            {
404407              "url": "floatdrop/pinkie",
404408              "type": "distribution"
404409            }
404410          ],
404411          "evidence": {},
404412          "signature": {
404413            "signature": {
404414              "publicKey": {}
404415            }
404416          },
404417          "modelCard": {
404418            "modelParameters": {
404419              "approach": {}
404420            },
404421            "quantitativeAnalysis": {
404422              "graphics": {}
404423            },
404424            "considerations": {}
404425          }
404426        },
404427        {
404428          "type": "library",
404429          "bom-ref": "pkg:npm/pinkie-promise@2.0.1?package-id=309815f14d8b0b5c",
404430          "supplier": {},
404431          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e (github.com/floatdrop)",
404432          "name": "pinkie-promise",
404433          "version": "2.0.1",
404434          "description": "ES2015 Promise ponyfill",
404435          "licenses": [
404436            {
404437              "license": {
404438                "id": "MIT"
404439              }
404440            }
404441          ],
404442          "cpe": "cpe:2.3:a:pinkie-promise:pinkie-promise:2.0.1:*:*:*:*:*:*:*",
404443          "purl": "pkg:npm/pinkie-promise@2.0.1",
404444          "swid": {
404445            "attachment": {}
404446          },
404447          "pedigree": {},
404448          "externalReferences": [
404449            {
404450              "url": "floatdrop/pinkie-promise",
404451              "type": "distribution"
404452            }
404453          ],
404454          "evidence": {},
404455          "signature": {
404456            "signature": {
404457              "publicKey": {}
404458            }
404459          },
404460          "modelCard": {
404461            "modelParameters": {
404462              "approach": {}
404463            },
404464            "quantitativeAnalysis": {
404465              "graphics": {}
404466            },
404467            "considerations": {}
404468          }
404469        },
404470        {
404471          "type": "library",
404472          "bom-ref": "pkg:npm/pliant-worker@1.0.0?package-id=c7f9b63b5efec2ca",
404473          "supplier": {},
404474          "name": "pliant-worker",
404475          "version": "1.0.0",
404476          "description": "pliant-worker",
404477          "cpe": "cpe:2.3:a:pliant-worker:pliant-worker:1.0.0:*:*:*:*:*:*:*",
404478          "purl": "pkg:npm/pliant-worker@1.0.0",
404479          "swid": {
404480            "attachment": {}
404481          },
404482          "pedigree": {},
404483          "evidence": {},
404484          "signature": {
404485            "signature": {
404486              "publicKey": {}
404487            }
404488          },
404489          "modelCard": {
404490            "modelParameters": {
404491              "approach": {}
404492            },
404493            "quantitativeAnalysis": {
404494              "graphics": {}
404495            },
404496            "considerations": {}
404497          }
404498        },
404499        {
404500          "type": "library",
404501          "bom-ref": "pkg:npm/pliant-worker-nodejs-remote@0.0.0?package-id=f0c05e24368b0207",
404502          "supplier": {},
404503          "name": "pliant-worker-nodejs-remote",
404504          "version": "0.0.0",
404505          "cpe": "cpe:2.3:a:pliant-worker-nodejs-remote:pliant-worker-nodejs-remote:0.0.0:*:*:*:*:*:*:*",
404506          "purl": "pkg:npm/pliant-worker-nodejs-remote@0.0.0",
404507          "swid": {
404508            "attachment": {}
404509          },
404510          "pedigree": {},
404511          "evidence": {},
404512          "signature": {
404513            "signature": {
404514              "publicKey": {}
404515            }
404516          },
404517          "modelCard": {
404518            "modelParameters": {
404519              "approach": {}
404520            },
404521            "quantitativeAnalysis": {
404522              "graphics": {}
404523            },
404524            "considerations": {}
404525          }
404526        },
404527        {
404528          "type": "library",
404529          "bom-ref": "pkg:npm/postcss-selector-parser@6.0.10?package-id=29dd6871004e9325",
404530          "supplier": {},
404531          "name": "postcss-selector-parser",
404532          "version": "6.0.10",
404533          "licenses": [
404534            {
404535              "license": {
404536                "id": "MIT"
404537              }
404538            }
404539          ],
404540          "cpe": "cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:6.0.10:*:*:*:*:*:*:*",
404541          "purl": "pkg:npm/postcss-selector-parser@6.0.10",
404542          "swid": {
404543            "attachment": {}
404544          },
404545          "pedigree": {},
404546          "externalReferences": [
404547            {
404548              "url": "postcss/postcss-selector-parser",
404549              "type": "distribution"
404550            },
404551            {
404552              "url": "https://github.com/postcss/postcss-selector-parser",
404553              "type": "website"
404554            }
404555          ],
404556          "evidence": {},
404557          "signature": {
404558            "signature": {
404559              "publicKey": {}
404560            }
404561          },
404562          "modelCard": {
404563            "modelParameters": {
404564              "approach": {}
404565            },
404566            "quantitativeAnalysis": {
404567              "graphics": {}
404568            },
404569            "considerations": {}
404570          }
404571        },
404572        {
404573          "type": "library",
404574          "bom-ref": "pkg:npm/prepend-http@2.0.0?package-id=b67c371036158d00",
404575          "supplier": {},
404576          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
404577          "name": "prepend-http",
404578          "version": "2.0.0",
404579          "description": "Prepend `http://` to humanized URLs like todomvc.com and localhost",
404580          "licenses": [
404581            {
404582              "license": {
404583                "id": "MIT"
404584              }
404585            }
404586          ],
404587          "cpe": "cpe:2.3:a:prepend-http:prepend-http:2.0.0:*:*:*:*:*:*:*",
404588          "purl": "pkg:npm/prepend-http@2.0.0",
404589          "swid": {
404590            "attachment": {}
404591          },
404592          "pedigree": {},
404593          "externalReferences": [
404594            {
404595              "url": "sindresorhus/prepend-http",
404596              "type": "distribution"
404597            }
404598          ],
404599          "evidence": {},
404600          "signature": {
404601            "signature": {
404602              "publicKey": {}
404603            }
404604          },
404605          "modelCard": {
404606            "modelParameters": {
404607              "approach": {}
404608            },
404609            "quantitativeAnalysis": {
404610              "graphics": {}
404611            },
404612            "considerations": {}
404613          }
404614        },
404615        {
404616          "type": "library",
404617          "bom-ref": "pkg:npm/proc-log@2.0.1?package-id=a4591425ab5edc60",
404618          "supplier": {},
404619          "author": "GitHub Inc.",
404620          "name": "proc-log",
404621          "version": "2.0.1",
404622          "description": "just emit 'log' events on the process object",
404623          "licenses": [
404624            {
404625              "license": {
404626                "id": "ISC"
404627              }
404628            }
404629          ],
404630          "cpe": "cpe:2.3:a:proc-log:proc-log:2.0.1:*:*:*:*:*:*:*",
404631          "purl": "pkg:npm/proc-log@2.0.1",
404632          "swid": {
404633            "attachment": {}
404634          },
404635          "pedigree": {},
404636          "externalReferences": [
404637            {
404638              "url": "https://github.com/npm/proc-log.git",
404639              "type": "distribution"
404640            }
404641          ],
404642          "evidence": {},
404643          "signature": {
404644            "signature": {
404645              "publicKey": {}
404646            }
404647          },
404648          "modelCard": {
404649            "modelParameters": {
404650              "approach": {}
404651            },
404652            "quantitativeAnalysis": {
404653              "graphics": {}
404654            },
404655            "considerations": {}
404656          }
404657        },
404658        {
404659          "type": "library",
404660          "bom-ref": "pkg:npm/process-nextick-args@2.0.1?package-id=d17a81662c772b1a",
404661          "supplier": {},
404662          "name": "process-nextick-args",
404663          "version": "2.0.1",
404664          "description": "process.nextTick but always with args",
404665          "licenses": [
404666            {
404667              "license": {
404668                "id": "MIT"
404669              }
404670            }
404671          ],
404672          "cpe": "cpe:2.3:a:process-nextick-args:process-nextick-args:2.0.1:*:*:*:*:*:*:*",
404673          "purl": "pkg:npm/process-nextick-args@2.0.1",
404674          "swid": {
404675            "attachment": {}
404676          },
404677          "pedigree": {},
404678          "externalReferences": [
404679            {
404680              "url": "https://github.com/calvinmetcalf/process-nextick-args.git",
404681              "type": "distribution"
404682            },
404683            {
404684              "url": "https://github.com/calvinmetcalf/process-nextick-args",
404685              "type": "website"
404686            }
404687          ],
404688          "evidence": {},
404689          "signature": {
404690            "signature": {
404691              "publicKey": {}
404692            }
404693          },
404694          "modelCard": {
404695            "modelParameters": {
404696              "approach": {}
404697            },
404698            "quantitativeAnalysis": {
404699              "graphics": {}
404700            },
404701            "considerations": {}
404702          }
404703        },
404704        {
404705          "type": "library",
404706          "bom-ref": "pkg:npm/promise-all-reject-late@1.0.1?package-id=7b92ff8460614d4f",
404707          "supplier": {},
404708          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
404709          "name": "promise-all-reject-late",
404710          "version": "1.0.1",
404711          "description": "Like Promise.all, but save rejections until all promises are resolved",
404712          "licenses": [
404713            {
404714              "license": {
404715                "id": "ISC"
404716              }
404717            }
404718          ],
404719          "cpe": "cpe:2.3:a:promise-all-reject-late:promise-all-reject-late:1.0.1:*:*:*:*:*:*:*",
404720          "purl": "pkg:npm/promise-all-reject-late@1.0.1",
404721          "swid": {
404722            "attachment": {}
404723          },
404724          "pedigree": {},
404725          "evidence": {},
404726          "signature": {
404727            "signature": {
404728              "publicKey": {}
404729            }
404730          },
404731          "modelCard": {
404732            "modelParameters": {
404733              "approach": {}
404734            },
404735            "quantitativeAnalysis": {
404736              "graphics": {}
404737            },
404738            "considerations": {}
404739          }
404740        },
404741        {
404742          "type": "library",
404743          "bom-ref": "pkg:npm/promise-call-limit@1.0.1?package-id=2b0b41bd7b0aa502",
404744          "supplier": {},
404745          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
404746          "name": "promise-call-limit",
404747          "version": "1.0.1",
404748          "description": "Call an array of promise-returning functions, restricting concurrency to a specified limit.",
404749          "licenses": [
404750            {
404751              "license": {
404752                "id": "ISC"
404753              }
404754            }
404755          ],
404756          "cpe": "cpe:2.3:a:promise-call-limit:promise-call-limit:1.0.1:*:*:*:*:*:*:*",
404757          "purl": "pkg:npm/promise-call-limit@1.0.1",
404758          "swid": {
404759            "attachment": {}
404760          },
404761          "pedigree": {},
404762          "externalReferences": [
404763            {
404764              "url": "git+https://github.com/isaacs/promise-call-limit",
404765              "type": "distribution"
404766            }
404767          ],
404768          "evidence": {},
404769          "signature": {
404770            "signature": {
404771              "publicKey": {}
404772            }
404773          },
404774          "modelCard": {
404775            "modelParameters": {
404776              "approach": {}
404777            },
404778            "quantitativeAnalysis": {
404779              "graphics": {}
404780            },
404781            "considerations": {}
404782          }
404783        },
404784        {
404785          "type": "library",
404786          "bom-ref": "pkg:npm/promise-inflight@1.0.1?package-id=8ae6caef1e6290fe",
404787          "supplier": {},
404788          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
404789          "name": "promise-inflight",
404790          "version": "1.0.1",
404791          "description": "One promise for multiple requests in flight to avoid async duplication",
404792          "licenses": [
404793            {
404794              "license": {
404795                "id": "ISC"
404796              }
404797            }
404798          ],
404799          "cpe": "cpe:2.3:a:promise-inflight:promise-inflight:1.0.1:*:*:*:*:*:*:*",
404800          "purl": "pkg:npm/promise-inflight@1.0.1",
404801          "swid": {
404802            "attachment": {}
404803          },
404804          "pedigree": {},
404805          "externalReferences": [
404806            {
404807              "url": "git+https://github.com/iarna/promise-inflight.git",
404808              "type": "distribution"
404809            },
404810            {
404811              "url": "https://github.com/iarna/promise-inflight#readme",
404812              "type": "website"
404813            }
404814          ],
404815          "evidence": {},
404816          "signature": {
404817            "signature": {
404818              "publicKey": {}
404819            }
404820          },
404821          "modelCard": {
404822            "modelParameters": {
404823              "approach": {}
404824            },
404825            "quantitativeAnalysis": {
404826              "graphics": {}
404827            },
404828            "considerations": {}
404829          }
404830        },
404831        {
404832          "type": "library",
404833          "bom-ref": "pkg:npm/promise-retry@2.0.1?package-id=7d483cd4a8ed637e",
404834          "supplier": {},
404835          "author": "IndigoUnited \u003chello@indigounited.com\u003e (http://indigounited.com)",
404836          "name": "promise-retry",
404837          "version": "2.0.1",
404838          "description": "Retries a function that returns a promise, leveraging the power of the retry module.",
404839          "licenses": [
404840            {
404841              "license": {
404842                "id": "MIT"
404843              }
404844            }
404845          ],
404846          "cpe": "cpe:2.3:a:promise-retry:promise-retry:2.0.1:*:*:*:*:*:*:*",
404847          "purl": "pkg:npm/promise-retry@2.0.1",
404848          "swid": {
404849            "attachment": {}
404850          },
404851          "pedigree": {},
404852          "externalReferences": [
404853            {
404854              "url": "git://github.com/IndigoUnited/node-promise-retry.git",
404855              "type": "distribution"
404856            }
404857          ],
404858          "evidence": {},
404859          "signature": {
404860            "signature": {
404861              "publicKey": {}
404862            }
404863          },
404864          "modelCard": {
404865            "modelParameters": {
404866              "approach": {}
404867            },
404868            "quantitativeAnalysis": {
404869              "graphics": {}
404870            },
404871            "considerations": {}
404872          }
404873        },
404874        {
404875          "type": "library",
404876          "bom-ref": "pkg:npm/promzard@0.3.0?package-id=33cefe299422041",
404877          "supplier": {},
404878          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
404879          "name": "promzard",
404880          "version": "0.3.0",
404881          "description": "prompting wizardly",
404882          "licenses": [
404883            {
404884              "license": {
404885                "id": "ISC"
404886              }
404887            }
404888          ],
404889          "cpe": "cpe:2.3:a:promzard:promzard:0.3.0:*:*:*:*:*:*:*",
404890          "purl": "pkg:npm/promzard@0.3.0",
404891          "swid": {
404892            "attachment": {}
404893          },
404894          "pedigree": {},
404895          "externalReferences": [
404896            {
404897              "url": "git://github.com/isaacs/promzard",
404898              "type": "distribution"
404899            }
404900          ],
404901          "evidence": {},
404902          "signature": {
404903            "signature": {
404904              "publicKey": {}
404905            }
404906          },
404907          "modelCard": {
404908            "modelParameters": {
404909              "approach": {}
404910            },
404911            "quantitativeAnalysis": {
404912              "graphics": {}
404913            },
404914            "considerations": {}
404915          }
404916        },
404917        {
404918          "type": "library",
404919          "bom-ref": "pkg:npm/proto-list@1.2.4?package-id=ef38b019413f5508",
404920          "supplier": {},
404921          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
404922          "name": "proto-list",
404923          "version": "1.2.4",
404924          "description": "A utility for managing a prototype chain",
404925          "licenses": [
404926            {
404927              "license": {
404928                "id": "ISC"
404929              }
404930            }
404931          ],
404932          "cpe": "cpe:2.3:a:proto-list:proto-list:1.2.4:*:*:*:*:*:*:*",
404933          "purl": "pkg:npm/proto-list@1.2.4",
404934          "swid": {
404935            "attachment": {}
404936          },
404937          "pedigree": {},
404938          "externalReferences": [
404939            {
404940              "url": "https://github.com/isaacs/proto-list",
404941              "type": "distribution"
404942            }
404943          ],
404944          "evidence": {},
404945          "signature": {
404946            "signature": {
404947              "publicKey": {}
404948            }
404949          },
404950          "modelCard": {
404951            "modelParameters": {
404952              "approach": {}
404953            },
404954            "quantitativeAnalysis": {
404955              "graphics": {}
404956            },
404957            "considerations": {}
404958          }
404959        },
404960        {
404961          "type": "library",
404962          "bom-ref": "pkg:apk/alpine/protobuf-c@1.4.1-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=305c4e951a4443ba",
404963          "supplier": {},
404964          "publisher": "Leonardo Arena \u003crnalrd@alpinelinux.org\u003e",
404965          "name": "protobuf-c",
404966          "version": "1.4.1-r0",
404967          "description": "Protocol Buffers implementation in C",
404968          "licenses": [
404969            {
404970              "license": {
404971                "id": "BSD-2-Clause"
404972              }
404973            }
404974          ],
404975          "cpe": "cpe:2.3:a:protobuf-c:protobuf-c:1.4.1-r0:*:*:*:*:*:*:*",
404976          "purl": "pkg:apk/alpine/protobuf-c@1.4.1-r0?arch=x86_64\u0026distro=alpine-3.16.5",
404977          "swid": {
404978            "attachment": {}
404979          },
404980          "pedigree": {},
404981          "externalReferences": [
404982            {
404983              "url": "https://github.com/protobuf-c/protobuf-c",
404984              "type": "distribution"
404985            }
404986          ],
404987          "evidence": {},
404988          "signature": {
404989            "signature": {
404990              "publicKey": {}
404991            }
404992          },
404993          "modelCard": {
404994            "modelParameters": {
404995              "approach": {}
404996            },
404997            "quantitativeAnalysis": {
404998              "graphics": {}
404999            },
405000            "considerations": {}
405001          }
405002        },
405003        {
405004          "type": "library",
405005          "bom-ref": "pkg:npm/proxy-addr@2.0.7?package-id=53c4580aea322e7e",
405006          "supplier": {},
405007          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
405008          "name": "proxy-addr",
405009          "version": "2.0.7",
405010          "description": "Determine address of proxied request",
405011          "licenses": [
405012            {
405013              "license": {
405014                "id": "MIT"
405015              }
405016            }
405017          ],
405018          "cpe": "cpe:2.3:a:proxy-addr:proxy-addr:2.0.7:*:*:*:*:*:*:*",
405019          "purl": "pkg:npm/proxy-addr@2.0.7",
405020          "swid": {
405021            "attachment": {}
405022          },
405023          "pedigree": {},
405024          "externalReferences": [
405025            {
405026              "url": "jshttp/proxy-addr",
405027              "type": "distribution"
405028            }
405029          ],
405030          "evidence": {},
405031          "signature": {
405032            "signature": {
405033              "publicKey": {}
405034            }
405035          },
405036          "modelCard": {
405037            "modelParameters": {
405038              "approach": {}
405039            },
405040            "quantitativeAnalysis": {
405041              "graphics": {}
405042            },
405043            "considerations": {}
405044          }
405045        },
405046        {
405047          "type": "library",
405048          "bom-ref": "pkg:npm/psl@1.9.0?package-id=53b253f7b10f23e5",
405049          "supplier": {},
405050          "author": "Lupo Montero \u003clupomontero@gmail.com\u003e (https://lupomontero.com/)",
405051          "name": "psl",
405052          "version": "1.9.0",
405053          "description": "Domain name parser based on the Public Suffix List",
405054          "licenses": [
405055            {
405056              "license": {
405057                "id": "MIT"
405058              }
405059            }
405060          ],
405061          "cpe": "cpe:2.3:a:psl:psl:1.9.0:*:*:*:*:*:*:*",
405062          "purl": "pkg:npm/psl@1.9.0",
405063          "swid": {
405064            "attachment": {}
405065          },
405066          "pedigree": {},
405067          "externalReferences": [
405068            {
405069              "url": "git@github.com:lupomontero/psl.git",
405070              "type": "distribution"
405071            }
405072          ],
405073          "evidence": {},
405074          "signature": {
405075            "signature": {
405076              "publicKey": {}
405077            }
405078          },
405079          "modelCard": {
405080            "modelParameters": {
405081              "approach": {}
405082            },
405083            "quantitativeAnalysis": {
405084              "graphics": {}
405085            },
405086            "considerations": {}
405087          }
405088        },
405089        {
405090          "type": "library",
405091          "bom-ref": "pkg:npm/pump@3.0.0?package-id=2fafbb58384dcf73",
405092          "supplier": {},
405093          "author": "Mathias Buus Madsen \u003cmathiasbuus@gmail.com\u003e",
405094          "name": "pump",
405095          "version": "3.0.0",
405096          "description": "pipe streams together and close all of them if one of them closes",
405097          "licenses": [
405098            {
405099              "license": {
405100                "id": "MIT"
405101              }
405102            }
405103          ],
405104          "cpe": "cpe:2.3:a:mafintosh:pump:3.0.0:*:*:*:*:*:*:*",
405105          "purl": "pkg:npm/pump@3.0.0",
405106          "swid": {
405107            "attachment": {}
405108          },
405109          "pedigree": {},
405110          "externalReferences": [
405111            {
405112              "url": "git://github.com/mafintosh/pump.git",
405113              "type": "distribution"
405114            }
405115          ],
405116          "evidence": {},
405117          "signature": {
405118            "signature": {
405119              "publicKey": {}
405120            }
405121          },
405122          "modelCard": {
405123            "modelParameters": {
405124              "approach": {}
405125            },
405126            "quantitativeAnalysis": {
405127              "graphics": {}
405128            },
405129            "considerations": {}
405130          }
405131        },
405132        {
405133          "type": "library",
405134          "bom-ref": "pkg:npm/punycode@2.3.0?package-id=d7aa24828b6ffa72",
405135          "supplier": {},
405136          "author": "Mathias Bynens (https://mathiasbynens.be/)",
405137          "name": "punycode",
405138          "version": "2.3.0",
405139          "description": "A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.",
405140          "licenses": [
405141            {
405142              "license": {
405143                "id": "MIT"
405144              }
405145            }
405146          ],
405147          "cpe": "cpe:2.3:a:mathiasbynens:punycode:2.3.0:*:*:*:*:*:*:*",
405148          "purl": "pkg:npm/punycode@2.3.0",
405149          "swid": {
405150            "attachment": {}
405151          },
405152          "pedigree": {},
405153          "externalReferences": [
405154            {
405155              "url": "https://github.com/mathiasbynens/punycode.js.git",
405156              "type": "distribution"
405157            },
405158            {
405159              "url": "https://mths.be/punycode",
405160              "type": "website"
405161            }
405162          ],
405163          "evidence": {},
405164          "signature": {
405165            "signature": {
405166              "publicKey": {}
405167            }
405168          },
405169          "modelCard": {
405170            "modelParameters": {
405171              "approach": {}
405172            },
405173            "quantitativeAnalysis": {
405174              "graphics": {}
405175            },
405176            "considerations": {}
405177          }
405178        },
405179        {
405180          "type": "library",
405181          "bom-ref": "pkg:npm/qrcode-terminal@0.12.0?package-id=83c91f496595f73",
405182          "supplier": {},
405183          "name": "qrcode-terminal",
405184          "version": "0.12.0",
405185          "description": "QRCodes, in the terminal",
405186          "licenses": [
405187            {
405188              "license": {
405189                "name": "Apache 2.0"
405190              }
405191            }
405192          ],
405193          "cpe": "cpe:2.3:a:qrcode-terminal:qrcode-terminal:0.12.0:*:*:*:*:*:*:*",
405194          "purl": "pkg:npm/qrcode-terminal@0.12.0",
405195          "swid": {
405196            "attachment": {}
405197          },
405198          "pedigree": {},
405199          "externalReferences": [
405200            {
405201              "url": "https://github.com/gtanner/qrcode-terminal",
405202              "type": "distribution"
405203            },
405204            {
405205              "url": "https://github.com/gtanner/qrcode-terminal",
405206              "type": "website"
405207            }
405208          ],
405209          "evidence": {},
405210          "signature": {
405211            "signature": {
405212              "publicKey": {}
405213            }
405214          },
405215          "modelCard": {
405216            "modelParameters": {
405217              "approach": {}
405218            },
405219            "quantitativeAnalysis": {
405220              "graphics": {}
405221            },
405222            "considerations": {}
405223          }
405224        },
405225        {
405226          "type": "library",
405227          "bom-ref": "pkg:npm/qs@6.5.2?package-id=8a6e990df3bbe823",
405228          "supplier": {},
405229          "name": "qs",
405230          "version": "6.5.2",
405231          "description": "A querystring parser that supports nesting and arrays, with a depth limit",
405232          "licenses": [
405233            {
405234              "license": {
405235                "id": "BSD-3-Clause"
405236              }
405237            }
405238          ],
405239          "cpe": "cpe:2.3:a:ljharb:qs:6.5.2:*:*:*:*:*:*:*",
405240          "purl": "pkg:npm/qs@6.5.2",
405241          "swid": {
405242            "attachment": {}
405243          },
405244          "pedigree": {},
405245          "externalReferences": [
405246            {
405247              "url": "https://github.com/ljharb/qs.git",
405248              "type": "distribution"
405249            },
405250            {
405251              "url": "https://github.com/ljharb/qs",
405252              "type": "website"
405253            }
405254          ],
405255          "evidence": {},
405256          "signature": {
405257            "signature": {
405258              "publicKey": {}
405259            }
405260          },
405261          "modelCard": {
405262            "modelParameters": {
405263              "approach": {}
405264            },
405265            "quantitativeAnalysis": {
405266              "graphics": {}
405267            },
405268            "considerations": {}
405269          }
405270        },
405271        {
405272          "type": "library",
405273          "bom-ref": "pkg:npm/query-string@5.1.1?package-id=e0fbe97b63bccbba",
405274          "supplier": {},
405275          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
405276          "name": "query-string",
405277          "version": "5.1.1",
405278          "description": "Parse and stringify URL query strings",
405279          "licenses": [
405280            {
405281              "license": {
405282                "id": "MIT"
405283              }
405284            }
405285          ],
405286          "cpe": "cpe:2.3:a:query-string:query-string:5.1.1:*:*:*:*:*:*:*",
405287          "purl": "pkg:npm/query-string@5.1.1",
405288          "swid": {
405289            "attachment": {}
405290          },
405291          "pedigree": {},
405292          "externalReferences": [
405293            {
405294              "url": "sindresorhus/query-string",
405295              "type": "distribution"
405296            }
405297          ],
405298          "evidence": {},
405299          "signature": {
405300            "signature": {
405301              "publicKey": {}
405302            }
405303          },
405304          "modelCard": {
405305            "modelParameters": {
405306              "approach": {}
405307            },
405308            "quantitativeAnalysis": {
405309              "graphics": {}
405310            },
405311            "considerations": {}
405312          }
405313        },
405314        {
405315          "type": "library",
405316          "bom-ref": "pkg:npm/querystring@0.2.0?package-id=7800be6cfd3a3ad2",
405317          "supplier": {},
405318          "author": "Irakli Gozalishvili \u003crfobic@gmail.com\u003e",
405319          "name": "querystring",
405320          "version": "0.2.0",
405321          "description": "Node's querystring module for all engines.",
405322          "licenses": [
405323            {
405324              "license": {
405325                "id": "MIT"
405326              }
405327            }
405328          ],
405329          "cpe": "cpe:2.3:a:querystring:querystring:0.2.0:*:*:*:*:*:*:*",
405330          "purl": "pkg:npm/querystring@0.2.0",
405331          "swid": {
405332            "attachment": {}
405333          },
405334          "pedigree": {},
405335          "externalReferences": [
405336            {
405337              "url": "git://github.com/Gozala/querystring.git",
405338              "type": "distribution"
405339            }
405340          ],
405341          "evidence": {},
405342          "signature": {
405343            "signature": {
405344              "publicKey": {}
405345            }
405346          },
405347          "modelCard": {
405348            "modelParameters": {
405349              "approach": {}
405350            },
405351            "quantitativeAnalysis": {
405352              "graphics": {}
405353            },
405354            "considerations": {}
405355          }
405356        },
405357        {
405358          "type": "library",
405359          "bom-ref": "pkg:npm/queue-microtask@1.2.3?package-id=16385b23543db315",
405360          "supplier": {},
405361          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
405362          "name": "queue-microtask",
405363          "version": "1.2.3",
405364          "description": "fast, tiny `queueMicrotask` shim for modern engines",
405365          "licenses": [
405366            {
405367              "license": {
405368                "id": "MIT"
405369              }
405370            }
405371          ],
405372          "cpe": "cpe:2.3:a:queue-microtask:queue-microtask:1.2.3:*:*:*:*:*:*:*",
405373          "purl": "pkg:npm/queue-microtask@1.2.3",
405374          "swid": {
405375            "attachment": {}
405376          },
405377          "pedigree": {},
405378          "externalReferences": [
405379            {
405380              "url": "git://github.com/feross/queue-microtask.git",
405381              "type": "distribution"
405382            },
405383            {
405384              "url": "https://github.com/feross/queue-microtask",
405385              "type": "website"
405386            }
405387          ],
405388          "evidence": {},
405389          "signature": {
405390            "signature": {
405391              "publicKey": {}
405392            }
405393          },
405394          "modelCard": {
405395            "modelParameters": {
405396              "approach": {}
405397            },
405398            "quantitativeAnalysis": {
405399              "graphics": {}
405400            },
405401            "considerations": {}
405402          }
405403        },
405404        {
405405          "type": "library",
405406          "bom-ref": "pkg:npm/quick-lru@5.1.1?package-id=b731ba5df3f073f1",
405407          "supplier": {},
405408          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (https://sindresorhus.com)",
405409          "name": "quick-lru",
405410          "version": "5.1.1",
405411          "description": "Simple “Least Recently Used” (LRU) cache",
405412          "licenses": [
405413            {
405414              "license": {
405415                "id": "MIT"
405416              }
405417            }
405418          ],
405419          "cpe": "cpe:2.3:a:quick-lru:quick-lru:5.1.1:*:*:*:*:*:*:*",
405420          "purl": "pkg:npm/quick-lru@5.1.1",
405421          "swid": {
405422            "attachment": {}
405423          },
405424          "pedigree": {},
405425          "externalReferences": [
405426            {
405427              "url": "sindresorhus/quick-lru",
405428              "type": "distribution"
405429            }
405430          ],
405431          "evidence": {},
405432          "signature": {
405433            "signature": {
405434              "publicKey": {}
405435            }
405436          },
405437          "modelCard": {
405438            "modelParameters": {
405439              "approach": {}
405440            },
405441            "quantitativeAnalysis": {
405442              "graphics": {}
405443            },
405444            "considerations": {}
405445          }
405446        },
405447        {
405448          "type": "library",
405449          "bom-ref": "pkg:npm/range-parser@1.2.1?package-id=4426c7b6b8b9fe0c",
405450          "supplier": {},
405451          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e (http://tjholowaychuk.com)",
405452          "name": "range-parser",
405453          "version": "1.2.1",
405454          "description": "Range header field string parser",
405455          "licenses": [
405456            {
405457              "license": {
405458                "id": "MIT"
405459              }
405460            }
405461          ],
405462          "cpe": "cpe:2.3:a:range-parser:range-parser:1.2.1:*:*:*:*:*:*:*",
405463          "purl": "pkg:npm/range-parser@1.2.1",
405464          "swid": {
405465            "attachment": {}
405466          },
405467          "pedigree": {},
405468          "externalReferences": [
405469            {
405470              "url": "jshttp/range-parser",
405471              "type": "distribution"
405472            }
405473          ],
405474          "evidence": {},
405475          "signature": {
405476            "signature": {
405477              "publicKey": {}
405478            }
405479          },
405480          "modelCard": {
405481            "modelParameters": {
405482              "approach": {}
405483            },
405484            "quantitativeAnalysis": {
405485              "graphics": {}
405486            },
405487            "considerations": {}
405488          }
405489        },
405490        {
405491          "type": "library",
405492          "bom-ref": "pkg:npm/raw-body@2.3.3?package-id=c72a71e2075f827c",
405493          "supplier": {},
405494          "author": "Jonathan Ong \u003cme@jongleberry.com\u003e (http://jongleberry.com)",
405495          "name": "raw-body",
405496          "version": "2.3.3",
405497          "description": "Get and validate the raw body of a readable stream.",
405498          "licenses": [
405499            {
405500              "license": {
405501                "id": "MIT"
405502              }
405503            }
405504          ],
405505          "cpe": "cpe:2.3:a:raw-body:raw-body:2.3.3:*:*:*:*:*:*:*",
405506          "purl": "pkg:npm/raw-body@2.3.3",
405507          "swid": {
405508            "attachment": {}
405509          },
405510          "pedigree": {},
405511          "externalReferences": [
405512            {
405513              "url": "stream-utils/raw-body",
405514              "type": "distribution"
405515            }
405516          ],
405517          "evidence": {},
405518          "signature": {
405519            "signature": {
405520              "publicKey": {}
405521            }
405522          },
405523          "modelCard": {
405524            "modelParameters": {
405525              "approach": {}
405526            },
405527            "quantitativeAnalysis": {
405528              "graphics": {}
405529            },
405530            "considerations": {}
405531          }
405532        },
405533        {
405534          "type": "library",
405535          "bom-ref": "pkg:npm/read@1.0.7?package-id=cf65e05575a1a15",
405536          "supplier": {},
405537          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
405538          "name": "read",
405539          "version": "1.0.7",
405540          "description": "read(1) for node programs",
405541          "licenses": [
405542            {
405543              "license": {
405544                "id": "ISC"
405545              }
405546            }
405547          ],
405548          "cpe": "cpe:2.3:a:isaacs:read:1.0.7:*:*:*:*:*:*:*",
405549          "purl": "pkg:npm/read@1.0.7",
405550          "swid": {
405551            "attachment": {}
405552          },
405553          "pedigree": {},
405554          "externalReferences": [
405555            {
405556              "url": "git://github.com/isaacs/read.git",
405557              "type": "distribution"
405558            }
405559          ],
405560          "evidence": {},
405561          "signature": {
405562            "signature": {
405563              "publicKey": {}
405564            }
405565          },
405566          "modelCard": {
405567            "modelParameters": {
405568              "approach": {}
405569            },
405570            "quantitativeAnalysis": {
405571              "graphics": {}
405572            },
405573            "considerations": {}
405574          }
405575        },
405576        {
405577          "type": "library",
405578          "bom-ref": "pkg:npm/read-cmd-shim@3.0.0?package-id=4b927be3f703982b",
405579          "supplier": {},
405580          "author": "GitHub Inc.",
405581          "name": "read-cmd-shim",
405582          "version": "3.0.0",
405583          "description": "Figure out what a cmd-shim is pointing at. This acts as the equivalent of fs.readlink.",
405584          "licenses": [
405585            {
405586              "license": {
405587                "id": "ISC"
405588              }
405589            }
405590          ],
405591          "cpe": "cpe:2.3:a:read-cmd-shim:read-cmd-shim:3.0.0:*:*:*:*:*:*:*",
405592          "purl": "pkg:npm/read-cmd-shim@3.0.0",
405593          "swid": {
405594            "attachment": {}
405595          },
405596          "pedigree": {},
405597          "externalReferences": [
405598            {
405599              "url": "https://github.com/npm/read-cmd-shim.git",
405600              "type": "distribution"
405601            },
405602            {
405603              "url": "https://github.com/npm/read-cmd-shim#readme",
405604              "type": "website"
405605            }
405606          ],
405607          "evidence": {},
405608          "signature": {
405609            "signature": {
405610              "publicKey": {}
405611            }
405612          },
405613          "modelCard": {
405614            "modelParameters": {
405615              "approach": {}
405616            },
405617            "quantitativeAnalysis": {
405618              "graphics": {}
405619            },
405620            "considerations": {}
405621          }
405622        },
405623        {
405624          "type": "library",
405625          "bom-ref": "pkg:npm/read-package-json@5.0.2?package-id=d15e27cd5cddf2b4",
405626          "supplier": {},
405627          "author": "GitHub Inc.",
405628          "name": "read-package-json",
405629          "version": "5.0.2",
405630          "description": "The thing npm uses to read package.json files with semantics and defaults and validation",
405631          "licenses": [
405632            {
405633              "license": {
405634                "id": "ISC"
405635              }
405636            }
405637          ],
405638          "cpe": "cpe:2.3:a:read-package-json:read-package-json:5.0.2:*:*:*:*:*:*:*",
405639          "purl": "pkg:npm/read-package-json@5.0.2",
405640          "swid": {
405641            "attachment": {}
405642          },
405643          "pedigree": {},
405644          "externalReferences": [
405645            {
405646              "url": "https://github.com/npm/read-package-json.git",
405647              "type": "distribution"
405648            }
405649          ],
405650          "evidence": {},
405651          "signature": {
405652            "signature": {
405653              "publicKey": {}
405654            }
405655          },
405656          "modelCard": {
405657            "modelParameters": {
405658              "approach": {}
405659            },
405660            "quantitativeAnalysis": {
405661              "graphics": {}
405662            },
405663            "considerations": {}
405664          }
405665        },
405666        {
405667          "type": "library",
405668          "bom-ref": "pkg:npm/read-package-json-fast@2.0.3?package-id=bb9e08c93f4b4c89",
405669          "supplier": {},
405670          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
405671          "name": "read-package-json-fast",
405672          "version": "2.0.3",
405673          "description": "Like read-package-json, but faster",
405674          "licenses": [
405675            {
405676              "license": {
405677                "id": "ISC"
405678              }
405679            }
405680          ],
405681          "cpe": "cpe:2.3:a:read-package-json-fast:read-package-json-fast:2.0.3:*:*:*:*:*:*:*",
405682          "purl": "pkg:npm/read-package-json-fast@2.0.3",
405683          "swid": {
405684            "attachment": {}
405685          },
405686          "pedigree": {},
405687          "externalReferences": [
405688            {
405689              "url": "git+https://github.com/npm/read-package-json-fast.git",
405690              "type": "distribution"
405691            }
405692          ],
405693          "evidence": {},
405694          "signature": {
405695            "signature": {
405696              "publicKey": {}
405697            }
405698          },
405699          "modelCard": {
405700            "modelParameters": {
405701              "approach": {}
405702            },
405703            "quantitativeAnalysis": {
405704              "graphics": {}
405705            },
405706            "considerations": {}
405707          }
405708        },
405709        {
405710          "type": "library",
405711          "bom-ref": "pkg:npm/readable-stream@2.3.8?package-id=9a0f417e2cbd0bab",
405712          "supplier": {},
405713          "name": "readable-stream",
405714          "version": "2.3.8",
405715          "description": "Streams3, a user-land copy of the stream library from Node.js",
405716          "licenses": [
405717            {
405718              "license": {
405719                "id": "MIT"
405720              }
405721            }
405722          ],
405723          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.8:*:*:*:*:*:*:*",
405724          "purl": "pkg:npm/readable-stream@2.3.8",
405725          "swid": {
405726            "attachment": {}
405727          },
405728          "pedigree": {},
405729          "externalReferences": [
405730            {
405731              "url": "git://github.com/nodejs/readable-stream",
405732              "type": "distribution"
405733            }
405734          ],
405735          "evidence": {},
405736          "signature": {
405737            "signature": {
405738              "publicKey": {}
405739            }
405740          },
405741          "modelCard": {
405742            "modelParameters": {
405743              "approach": {}
405744            },
405745            "quantitativeAnalysis": {
405746              "graphics": {}
405747            },
405748            "considerations": {}
405749          }
405750        },
405751        {
405752          "type": "library",
405753          "bom-ref": "pkg:npm/readable-stream@2.3.8?package-id=72b4527116742a58",
405754          "supplier": {},
405755          "name": "readable-stream",
405756          "version": "2.3.8",
405757          "description": "Streams3, a user-land copy of the stream library from Node.js",
405758          "licenses": [
405759            {
405760              "license": {
405761                "id": "MIT"
405762              }
405763            }
405764          ],
405765          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.8:*:*:*:*:*:*:*",
405766          "purl": "pkg:npm/readable-stream@2.3.8",
405767          "swid": {
405768            "attachment": {}
405769          },
405770          "pedigree": {},
405771          "externalReferences": [
405772            {
405773              "url": "git://github.com/nodejs/readable-stream",
405774              "type": "distribution"
405775            }
405776          ],
405777          "evidence": {},
405778          "signature": {
405779            "signature": {
405780              "publicKey": {}
405781            }
405782          },
405783          "modelCard": {
405784            "modelParameters": {
405785              "approach": {}
405786            },
405787            "quantitativeAnalysis": {
405788              "graphics": {}
405789            },
405790            "considerations": {}
405791          }
405792        },
405793        {
405794          "type": "library",
405795          "bom-ref": "pkg:npm/readable-stream@2.3.8?package-id=89c35a8ee4fb9cb7",
405796          "supplier": {},
405797          "name": "readable-stream",
405798          "version": "2.3.8",
405799          "description": "Streams3, a user-land copy of the stream library from Node.js",
405800          "licenses": [
405801            {
405802              "license": {
405803                "id": "MIT"
405804              }
405805            }
405806          ],
405807          "cpe": "cpe:2.3:a:readable-stream:readable-stream:2.3.8:*:*:*:*:*:*:*",
405808          "purl": "pkg:npm/readable-stream@2.3.8",
405809          "swid": {
405810            "attachment": {}
405811          },
405812          "pedigree": {},
405813          "externalReferences": [
405814            {
405815              "url": "git://github.com/nodejs/readable-stream",
405816              "type": "distribution"
405817            }
405818          ],
405819          "evidence": {},
405820          "signature": {
405821            "signature": {
405822              "publicKey": {}
405823            }
405824          },
405825          "modelCard": {
405826            "modelParameters": {
405827              "approach": {}
405828            },
405829            "quantitativeAnalysis": {
405830              "graphics": {}
405831            },
405832            "considerations": {}
405833          }
405834        },
405835        {
405836          "type": "library",
405837          "bom-ref": "pkg:npm/readable-stream@3.6.0?package-id=32d9c32dd3126020",
405838          "supplier": {},
405839          "name": "readable-stream",
405840          "version": "3.6.0",
405841          "description": "Streams3, a user-land copy of the stream library from Node.js",
405842          "licenses": [
405843            {
405844              "license": {
405845                "id": "MIT"
405846              }
405847            }
405848          ],
405849          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.0:*:*:*:*:*:*:*",
405850          "purl": "pkg:npm/readable-stream@3.6.0",
405851          "swid": {
405852            "attachment": {}
405853          },
405854          "pedigree": {},
405855          "externalReferences": [
405856            {
405857              "url": "git://github.com/nodejs/readable-stream",
405858              "type": "distribution"
405859            }
405860          ],
405861          "evidence": {},
405862          "signature": {
405863            "signature": {
405864              "publicKey": {}
405865            }
405866          },
405867          "modelCard": {
405868            "modelParameters": {
405869              "approach": {}
405870            },
405871            "quantitativeAnalysis": {
405872              "graphics": {}
405873            },
405874            "considerations": {}
405875          }
405876        },
405877        {
405878          "type": "library",
405879          "bom-ref": "pkg:npm/readable-stream@3.6.2?package-id=58c37a95ac33b693",
405880          "supplier": {},
405881          "name": "readable-stream",
405882          "version": "3.6.2",
405883          "description": "Streams3, a user-land copy of the stream library from Node.js",
405884          "licenses": [
405885            {
405886              "license": {
405887                "id": "MIT"
405888              }
405889            }
405890          ],
405891          "cpe": "cpe:2.3:a:readable-stream:readable-stream:3.6.2:*:*:*:*:*:*:*",
405892          "purl": "pkg:npm/readable-stream@3.6.2",
405893          "swid": {
405894            "attachment": {}
405895          },
405896          "pedigree": {},
405897          "externalReferences": [
405898            {
405899              "url": "git://github.com/nodejs/readable-stream",
405900              "type": "distribution"
405901            }
405902          ],
405903          "evidence": {},
405904          "signature": {
405905            "signature": {
405906              "publicKey": {}
405907            }
405908          },
405909          "modelCard": {
405910            "modelParameters": {
405911              "approach": {}
405912            },
405913            "quantitativeAnalysis": {
405914              "graphics": {}
405915            },
405916            "considerations": {}
405917          }
405918        },
405919        {
405920          "type": "library",
405921          "bom-ref": "pkg:npm/readdir-scoped-modules@1.1.0?package-id=33ac24742869be8b",
405922          "supplier": {},
405923          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
405924          "name": "readdir-scoped-modules",
405925          "version": "1.1.0",
405926          "description": "Like `fs.readdir` but handling `@org/module` dirs as if they were a single entry.",
405927          "licenses": [
405928            {
405929              "license": {
405930                "id": "ISC"
405931              }
405932            }
405933          ],
405934          "cpe": "cpe:2.3:a:readdir-scoped-modules:readdir-scoped-modules:1.1.0:*:*:*:*:*:*:*",
405935          "purl": "pkg:npm/readdir-scoped-modules@1.1.0",
405936          "swid": {
405937            "attachment": {}
405938          },
405939          "pedigree": {},
405940          "externalReferences": [
405941            {
405942              "url": "https://github.com/npm/readdir-scoped-modules",
405943              "type": "distribution"
405944            },
405945            {
405946              "url": "https://github.com/npm/readdir-scoped-modules",
405947              "type": "website"
405948            }
405949          ],
405950          "evidence": {},
405951          "signature": {
405952            "signature": {
405953              "publicKey": {}
405954            }
405955          },
405956          "modelCard": {
405957            "modelParameters": {
405958              "approach": {}
405959            },
405960            "quantitativeAnalysis": {
405961              "graphics": {}
405962            },
405963            "considerations": {}
405964          }
405965        },
405966        {
405967          "type": "library",
405968          "bom-ref": "pkg:npm/request@2.88.2?package-id=9d4ba60210bc5002",
405969          "supplier": {},
405970          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e",
405971          "name": "request",
405972          "version": "2.88.2",
405973          "description": "Simplified HTTP request client.",
405974          "licenses": [
405975            {
405976              "license": {
405977                "id": "Apache-2.0"
405978              }
405979            }
405980          ],
405981          "cpe": "cpe:2.3:a:request:request:2.88.2:*:*:*:*:*:*:*",
405982          "purl": "pkg:npm/request@2.88.2",
405983          "swid": {
405984            "attachment": {}
405985          },
405986          "pedigree": {},
405987          "externalReferences": [
405988            {
405989              "url": "https://github.com/request/request.git",
405990              "type": "distribution"
405991            }
405992          ],
405993          "evidence": {},
405994          "signature": {
405995            "signature": {
405996              "publicKey": {}
405997            }
405998          },
405999          "modelCard": {
406000            "modelParameters": {
406001              "approach": {}
406002            },
406003            "quantitativeAnalysis": {
406004              "graphics": {}
406005            },
406006            "considerations": {}
406007          }
406008        },
406009        {
406010          "type": "library",
406011          "bom-ref": "pkg:npm/request-promise-core@1.1.4?package-id=8d3a6ff56740e0e7",
406012          "supplier": {},
406013          "author": "Nicolai Kamenzky (https://github.com/analog-nico)",
406014          "name": "request-promise-core",
406015          "version": "1.1.4",
406016          "description": "Core Promise support implementation for the simplified HTTP request client 'request'.",
406017          "licenses": [
406018            {
406019              "license": {
406020                "id": "ISC"
406021              }
406022            }
406023          ],
406024          "cpe": "cpe:2.3:a:request-promise-core:request-promise-core:1.1.4:*:*:*:*:*:*:*",
406025          "purl": "pkg:npm/request-promise-core@1.1.4",
406026          "swid": {
406027            "attachment": {}
406028          },
406029          "pedigree": {},
406030          "externalReferences": [
406031            {
406032              "url": "git+https://github.com/request/promise-core.git",
406033              "type": "distribution"
406034            },
406035            {
406036              "url": "https://github.com/request/promise-core#readme",
406037              "type": "website"
406038            }
406039          ],
406040          "evidence": {},
406041          "signature": {
406042            "signature": {
406043              "publicKey": {}
406044            }
406045          },
406046          "modelCard": {
406047            "modelParameters": {
406048              "approach": {}
406049            },
406050            "quantitativeAnalysis": {
406051              "graphics": {}
406052            },
406053            "considerations": {}
406054          }
406055        },
406056        {
406057          "type": "library",
406058          "bom-ref": "pkg:npm/request-promise-native@1.0.9?package-id=8a851bd442a13a0b",
406059          "supplier": {},
406060          "author": "Nicolai Kamenzky (https://github.com/analog-nico)",
406061          "name": "request-promise-native",
406062          "version": "1.0.9",
406063          "description": "The simplified HTTP request client 'request' with Promise support. Powered by native ES6 promises.",
406064          "licenses": [
406065            {
406066              "license": {
406067                "id": "ISC"
406068              }
406069            }
406070          ],
406071          "cpe": "cpe:2.3:a:request-promise-native:request-promise-native:1.0.9:*:*:*:*:*:*:*",
406072          "purl": "pkg:npm/request-promise-native@1.0.9",
406073          "swid": {
406074            "attachment": {}
406075          },
406076          "pedigree": {},
406077          "externalReferences": [
406078            {
406079              "url": "git+https://github.com/request/request-promise-native.git",
406080              "type": "distribution"
406081            },
406082            {
406083              "url": "https://github.com/request/request-promise-native#readme",
406084              "type": "website"
406085            }
406086          ],
406087          "evidence": {},
406088          "signature": {
406089            "signature": {
406090              "publicKey": {}
406091            }
406092          },
406093          "modelCard": {
406094            "modelParameters": {
406095              "approach": {}
406096            },
406097            "quantitativeAnalysis": {
406098              "graphics": {}
406099            },
406100            "considerations": {}
406101          }
406102        },
406103        {
406104          "type": "library",
406105          "bom-ref": "pkg:npm/resolve-alpn@1.2.1?package-id=70686007b37e8f3e",
406106          "supplier": {},
406107          "author": "Szymon Marczak",
406108          "name": "resolve-alpn",
406109          "version": "1.2.1",
406110          "description": "Detects the ALPN protocol",
406111          "licenses": [
406112            {
406113              "license": {
406114                "id": "MIT"
406115              }
406116            }
406117          ],
406118          "cpe": "cpe:2.3:a:resolve-alpn:resolve-alpn:1.2.1:*:*:*:*:*:*:*",
406119          "purl": "pkg:npm/resolve-alpn@1.2.1",
406120          "swid": {
406121            "attachment": {}
406122          },
406123          "pedigree": {},
406124          "externalReferences": [
406125            {
406126              "url": "git+https://github.com/szmarczak/resolve-alpn.git",
406127              "type": "distribution"
406128            },
406129            {
406130              "url": "https://github.com/szmarczak/resolve-alpn#readme",
406131              "type": "website"
406132            }
406133          ],
406134          "evidence": {},
406135          "signature": {
406136            "signature": {
406137              "publicKey": {}
406138            }
406139          },
406140          "modelCard": {
406141            "modelParameters": {
406142              "approach": {}
406143            },
406144            "quantitativeAnalysis": {
406145              "graphics": {}
406146            },
406147            "considerations": {}
406148          }
406149        },
406150        {
406151          "type": "library",
406152          "bom-ref": "pkg:npm/resolve-dependencies@6.0.9?package-id=3282dcc15ecc834f",
406153          "supplier": {},
406154          "name": "resolve-dependencies",
406155          "version": "6.0.9",
406156          "licenses": [
406157            {
406158              "license": {
406159                "id": "MIT"
406160              }
406161            }
406162          ],
406163          "cpe": "cpe:2.3:a:resolve-dependencies:resolve-dependencies:6.0.9:*:*:*:*:*:*:*",
406164          "purl": "pkg:npm/resolve-dependencies@6.0.9",
406165          "swid": {
406166            "attachment": {}
406167          },
406168          "pedigree": {},
406169          "externalReferences": [
406170            {
406171              "url": "https://github.com/nexe/resolve-dependencies.git",
406172              "type": "distribution"
406173            }
406174          ],
406175          "evidence": {},
406176          "signature": {
406177            "signature": {
406178              "publicKey": {}
406179            }
406180          },
406181          "modelCard": {
406182            "modelParameters": {
406183              "approach": {}
406184            },
406185            "quantitativeAnalysis": {
406186              "graphics": {}
406187            },
406188            "considerations": {}
406189          }
406190        },
406191        {
406192          "type": "library",
406193          "bom-ref": "pkg:npm/responselike@1.0.2?package-id=d4f225eb3ddcee43",
406194          "supplier": {},
406195          "author": "lukechilds",
406196          "name": "responselike",
406197          "version": "1.0.2",
406198          "description": "A response-like object for mocking a Node.js HTTP response stream",
406199          "licenses": [
406200            {
406201              "license": {
406202                "id": "MIT"
406203              }
406204            }
406205          ],
406206          "cpe": "cpe:2.3:a:responselike:responselike:1.0.2:*:*:*:*:*:*:*",
406207          "purl": "pkg:npm/responselike@1.0.2",
406208          "swid": {
406209            "attachment": {}
406210          },
406211          "pedigree": {},
406212          "externalReferences": [
406213            {
406214              "url": "https://github.com/lukechilds/responselike.git",
406215              "type": "distribution"
406216            }
406217          ],
406218          "evidence": {},
406219          "signature": {
406220            "signature": {
406221              "publicKey": {}
406222            }
406223          },
406224          "modelCard": {
406225            "modelParameters": {
406226              "approach": {}
406227            },
406228            "quantitativeAnalysis": {
406229              "graphics": {}
406230            },
406231            "considerations": {}
406232          }
406233        },
406234        {
406235          "type": "library",
406236          "bom-ref": "pkg:npm/responselike@2.0.1?package-id=c01e36f80957bdc8",
406237          "supplier": {},
406238          "author": "lukechilds",
406239          "name": "responselike",
406240          "version": "2.0.1",
406241          "description": "A response-like object for mocking a Node.js HTTP response stream",
406242          "licenses": [
406243            {
406244              "license": {
406245                "id": "MIT"
406246              }
406247            }
406248          ],
406249          "cpe": "cpe:2.3:a:responselike:responselike:2.0.1:*:*:*:*:*:*:*",
406250          "purl": "pkg:npm/responselike@2.0.1",
406251          "swid": {
406252            "attachment": {}
406253          },
406254          "pedigree": {},
406255          "externalReferences": [
406256            {
406257              "url": "https://github.com/sindresorhus/responselike.git",
406258              "type": "distribution"
406259            }
406260          ],
406261          "evidence": {},
406262          "signature": {
406263            "signature": {
406264              "publicKey": {}
406265            }
406266          },
406267          "modelCard": {
406268            "modelParameters": {
406269              "approach": {}
406270            },
406271            "quantitativeAnalysis": {
406272              "graphics": {}
406273            },
406274            "considerations": {}
406275          }
406276        },
406277        {
406278          "type": "library",
406279          "bom-ref": "pkg:npm/restore-cursor@2.0.0?package-id=c4bed021ae2313cb",
406280          "supplier": {},
406281          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
406282          "name": "restore-cursor",
406283          "version": "2.0.0",
406284          "description": "Gracefully restore the CLI cursor on exit",
406285          "licenses": [
406286            {
406287              "license": {
406288                "id": "MIT"
406289              }
406290            }
406291          ],
406292          "cpe": "cpe:2.3:a:restore-cursor:restore-cursor:2.0.0:*:*:*:*:*:*:*",
406293          "purl": "pkg:npm/restore-cursor@2.0.0",
406294          "swid": {
406295            "attachment": {}
406296          },
406297          "pedigree": {},
406298          "externalReferences": [
406299            {
406300              "url": "sindresorhus/restore-cursor",
406301              "type": "distribution"
406302            }
406303          ],
406304          "evidence": {},
406305          "signature": {
406306            "signature": {
406307              "publicKey": {}
406308            }
406309          },
406310          "modelCard": {
406311            "modelParameters": {
406312              "approach": {}
406313            },
406314            "quantitativeAnalysis": {
406315              "graphics": {}
406316            },
406317            "considerations": {}
406318          }
406319        },
406320        {
406321          "type": "library",
406322          "bom-ref": "pkg:npm/retry@0.12.0?package-id=c3f319915fd297ec",
406323          "supplier": {},
406324          "author": "Tim Koschützki \u003ctim@debuggable.com\u003e (http://debuggable.com/)",
406325          "name": "retry",
406326          "version": "0.12.0",
406327          "description": "Abstraction for exponential and custom retry strategies for failed operations.",
406328          "licenses": [
406329            {
406330              "license": {
406331                "id": "MIT"
406332              }
406333            }
406334          ],
406335          "cpe": "cpe:2.3:a:tim-kos:retry:0.12.0:*:*:*:*:*:*:*",
406336          "purl": "pkg:npm/retry@0.12.0",
406337          "swid": {
406338            "attachment": {}
406339          },
406340          "pedigree": {},
406341          "externalReferences": [
406342            {
406343              "url": "git://github.com/tim-kos/node-retry.git",
406344              "type": "distribution"
406345            },
406346            {
406347              "url": "https://github.com/tim-kos/node-retry",
406348              "type": "website"
406349            }
406350          ],
406351          "evidence": {},
406352          "signature": {
406353            "signature": {
406354              "publicKey": {}
406355            }
406356          },
406357          "modelCard": {
406358            "modelParameters": {
406359              "approach": {}
406360            },
406361            "quantitativeAnalysis": {
406362              "graphics": {}
406363            },
406364            "considerations": {}
406365          }
406366        },
406367        {
406368          "type": "library",
406369          "bom-ref": "pkg:npm/reusify@1.0.4?package-id=48d0ddd1ed8b33de",
406370          "supplier": {},
406371          "author": "Matteo Collina \u003chello@matteocollina.com\u003e",
406372          "name": "reusify",
406373          "version": "1.0.4",
406374          "description": "Reuse objects and functions with style",
406375          "licenses": [
406376            {
406377              "license": {
406378                "id": "MIT"
406379              }
406380            }
406381          ],
406382          "cpe": "cpe:2.3:a:mcollina:reusify:1.0.4:*:*:*:*:*:*:*",
406383          "purl": "pkg:npm/reusify@1.0.4",
406384          "swid": {
406385            "attachment": {}
406386          },
406387          "pedigree": {},
406388          "externalReferences": [
406389            {
406390              "url": "git+https://github.com/mcollina/reusify.git",
406391              "type": "distribution"
406392            },
406393            {
406394              "url": "https://github.com/mcollina/reusify#readme",
406395              "type": "website"
406396            }
406397          ],
406398          "evidence": {},
406399          "signature": {
406400            "signature": {
406401              "publicKey": {}
406402            }
406403          },
406404          "modelCard": {
406405            "modelParameters": {
406406              "approach": {}
406407            },
406408            "quantitativeAnalysis": {
406409              "graphics": {}
406410            },
406411            "considerations": {}
406412          }
406413        },
406414        {
406415          "type": "library",
406416          "bom-ref": "pkg:npm/rimraf@2.7.1?package-id=157b3be2bd2b584",
406417          "supplier": {},
406418          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
406419          "name": "rimraf",
406420          "version": "2.7.1",
406421          "description": "A deep deletion module for node (like `rm -rf`)",
406422          "licenses": [
406423            {
406424              "license": {
406425                "id": "ISC"
406426              }
406427            }
406428          ],
406429          "cpe": "cpe:2.3:a:isaacs:rimraf:2.7.1:*:*:*:*:*:*:*",
406430          "purl": "pkg:npm/rimraf@2.7.1",
406431          "swid": {
406432            "attachment": {}
406433          },
406434          "pedigree": {},
406435          "externalReferences": [
406436            {
406437              "url": "git://github.com/isaacs/rimraf.git",
406438              "type": "distribution"
406439            }
406440          ],
406441          "evidence": {},
406442          "signature": {
406443            "signature": {
406444              "publicKey": {}
406445            }
406446          },
406447          "modelCard": {
406448            "modelParameters": {
406449              "approach": {}
406450            },
406451            "quantitativeAnalysis": {
406452              "graphics": {}
406453            },
406454            "considerations": {}
406455          }
406456        },
406457        {
406458          "type": "library",
406459          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=92690f32c123c49b",
406460          "supplier": {},
406461          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
406462          "name": "rimraf",
406463          "version": "3.0.2",
406464          "description": "A deep deletion module for node (like `rm -rf`)",
406465          "licenses": [
406466            {
406467              "license": {
406468                "id": "ISC"
406469              }
406470            }
406471          ],
406472          "cpe": "cpe:2.3:a:isaacs:rimraf:3.0.2:*:*:*:*:*:*:*",
406473          "purl": "pkg:npm/rimraf@3.0.2",
406474          "swid": {
406475            "attachment": {}
406476          },
406477          "pedigree": {},
406478          "externalReferences": [
406479            {
406480              "url": "git://github.com/isaacs/rimraf.git",
406481              "type": "distribution"
406482            }
406483          ],
406484          "evidence": {},
406485          "signature": {
406486            "signature": {
406487              "publicKey": {}
406488            }
406489          },
406490          "modelCard": {
406491            "modelParameters": {
406492              "approach": {}
406493            },
406494            "quantitativeAnalysis": {
406495              "graphics": {}
406496            },
406497            "considerations": {}
406498          }
406499        },
406500        {
406501          "type": "library",
406502          "bom-ref": "pkg:npm/rimraf@3.0.2?package-id=691571e29c90ccb4",
406503          "supplier": {},
406504          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
406505          "name": "rimraf",
406506          "version": "3.0.2",
406507          "description": "A deep deletion module for node (like `rm -rf`)",
406508          "licenses": [
406509            {
406510              "license": {
406511                "id": "ISC"
406512              }
406513            }
406514          ],
406515          "cpe": "cpe:2.3:a:isaacs:rimraf:3.0.2:*:*:*:*:*:*:*",
406516          "purl": "pkg:npm/rimraf@3.0.2",
406517          "swid": {
406518            "attachment": {}
406519          },
406520          "pedigree": {},
406521          "externalReferences": [
406522            {
406523              "url": "git://github.com/isaacs/rimraf.git",
406524              "type": "distribution"
406525            }
406526          ],
406527          "evidence": {},
406528          "signature": {
406529            "signature": {
406530              "publicKey": {}
406531            }
406532          },
406533          "modelCard": {
406534            "modelParameters": {
406535              "approach": {}
406536            },
406537            "quantitativeAnalysis": {
406538              "graphics": {}
406539            },
406540            "considerations": {}
406541          }
406542        },
406543        {
406544          "type": "library",
406545          "bom-ref": "pkg:npm/run-parallel@1.2.0?package-id=31153313b40541e",
406546          "supplier": {},
406547          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
406548          "name": "run-parallel",
406549          "version": "1.2.0",
406550          "description": "Run an array of functions in parallel",
406551          "licenses": [
406552            {
406553              "license": {
406554                "id": "MIT"
406555              }
406556            }
406557          ],
406558          "cpe": "cpe:2.3:a:run-parallel:run-parallel:1.2.0:*:*:*:*:*:*:*",
406559          "purl": "pkg:npm/run-parallel@1.2.0",
406560          "swid": {
406561            "attachment": {}
406562          },
406563          "pedigree": {},
406564          "externalReferences": [
406565            {
406566              "url": "git://github.com/feross/run-parallel.git",
406567              "type": "distribution"
406568            },
406569            {
406570              "url": "https://github.com/feross/run-parallel",
406571              "type": "website"
406572            }
406573          ],
406574          "evidence": {},
406575          "signature": {
406576            "signature": {
406577              "publicKey": {}
406578            }
406579          },
406580          "modelCard": {
406581            "modelParameters": {
406582              "approach": {}
406583            },
406584            "quantitativeAnalysis": {
406585              "graphics": {}
406586            },
406587            "considerations": {}
406588          }
406589        },
406590        {
406591          "type": "library",
406592          "bom-ref": "pkg:npm/safe-buffer@5.1.2?package-id=2726b88c81e31063",
406593          "supplier": {},
406594          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (http://feross.org)",
406595          "name": "safe-buffer",
406596          "version": "5.1.2",
406597          "description": "Safer Node.js Buffer API",
406598          "licenses": [
406599            {
406600              "license": {
406601                "id": "MIT"
406602              }
406603            }
406604          ],
406605          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.1.2:*:*:*:*:*:*:*",
406606          "purl": "pkg:npm/safe-buffer@5.1.2",
406607          "swid": {
406608            "attachment": {}
406609          },
406610          "pedigree": {},
406611          "externalReferences": [
406612            {
406613              "url": "git://github.com/feross/safe-buffer.git",
406614              "type": "distribution"
406615            },
406616            {
406617              "url": "https://github.com/feross/safe-buffer",
406618              "type": "website"
406619            }
406620          ],
406621          "evidence": {},
406622          "signature": {
406623            "signature": {
406624              "publicKey": {}
406625            }
406626          },
406627          "modelCard": {
406628            "modelParameters": {
406629              "approach": {}
406630            },
406631            "quantitativeAnalysis": {
406632              "graphics": {}
406633            },
406634            "considerations": {}
406635          }
406636        },
406637        {
406638          "type": "library",
406639          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=edf513d3ab46bee",
406640          "supplier": {},
406641          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
406642          "name": "safe-buffer",
406643          "version": "5.2.1",
406644          "description": "Safer Node.js Buffer API",
406645          "licenses": [
406646            {
406647              "license": {
406648                "id": "MIT"
406649              }
406650            }
406651          ],
406652          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
406653          "purl": "pkg:npm/safe-buffer@5.2.1",
406654          "swid": {
406655            "attachment": {}
406656          },
406657          "pedigree": {},
406658          "externalReferences": [
406659            {
406660              "url": "git://github.com/feross/safe-buffer.git",
406661              "type": "distribution"
406662            },
406663            {
406664              "url": "https://github.com/feross/safe-buffer",
406665              "type": "website"
406666            }
406667          ],
406668          "evidence": {},
406669          "signature": {
406670            "signature": {
406671              "publicKey": {}
406672            }
406673          },
406674          "modelCard": {
406675            "modelParameters": {
406676              "approach": {}
406677            },
406678            "quantitativeAnalysis": {
406679              "graphics": {}
406680            },
406681            "considerations": {}
406682          }
406683        },
406684        {
406685          "type": "library",
406686          "bom-ref": "pkg:npm/safe-buffer@5.2.1?package-id=e39228a786cd5fee",
406687          "supplier": {},
406688          "author": "Feross Aboukhadijeh \u003cfeross@feross.org\u003e (https://feross.org)",
406689          "name": "safe-buffer",
406690          "version": "5.2.1",
406691          "description": "Safer Node.js Buffer API",
406692          "licenses": [
406693            {
406694              "license": {
406695                "id": "MIT"
406696              }
406697            }
406698          ],
406699          "cpe": "cpe:2.3:a:safe-buffer:safe-buffer:5.2.1:*:*:*:*:*:*:*",
406700          "purl": "pkg:npm/safe-buffer@5.2.1",
406701          "swid": {
406702            "attachment": {}
406703          },
406704          "pedigree": {},
406705          "externalReferences": [
406706            {
406707              "url": "git://github.com/feross/safe-buffer.git",
406708              "type": "distribution"
406709            },
406710            {
406711              "url": "https://github.com/feross/safe-buffer",
406712              "type": "website"
406713            }
406714          ],
406715          "evidence": {},
406716          "signature": {
406717            "signature": {
406718              "publicKey": {}
406719            }
406720          },
406721          "modelCard": {
406722            "modelParameters": {
406723              "approach": {}
406724            },
406725            "quantitativeAnalysis": {
406726              "graphics": {}
406727            },
406728            "considerations": {}
406729          }
406730        },
406731        {
406732          "type": "library",
406733          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=4ab2220d3f3f4961",
406734          "supplier": {},
406735          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
406736          "name": "safer-buffer",
406737          "version": "2.1.2",
406738          "description": "Modern Buffer API polyfill without footguns",
406739          "licenses": [
406740            {
406741              "license": {
406742                "id": "MIT"
406743              }
406744            }
406745          ],
406746          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
406747          "purl": "pkg:npm/safer-buffer@2.1.2",
406748          "swid": {
406749            "attachment": {}
406750          },
406751          "pedigree": {},
406752          "externalReferences": [
406753            {
406754              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
406755              "type": "distribution"
406756            }
406757          ],
406758          "evidence": {},
406759          "signature": {
406760            "signature": {
406761              "publicKey": {}
406762            }
406763          },
406764          "modelCard": {
406765            "modelParameters": {
406766              "approach": {}
406767            },
406768            "quantitativeAnalysis": {
406769              "graphics": {}
406770            },
406771            "considerations": {}
406772          }
406773        },
406774        {
406775          "type": "library",
406776          "bom-ref": "pkg:npm/safer-buffer@2.1.2?package-id=cc287d73489b4567",
406777          "supplier": {},
406778          "author": "Nikita Skovoroda \u003cchalkerx@gmail.com\u003e (https://github.com/ChALkeR)",
406779          "name": "safer-buffer",
406780          "version": "2.1.2",
406781          "description": "Modern Buffer API polyfill without footguns",
406782          "licenses": [
406783            {
406784              "license": {
406785                "id": "MIT"
406786              }
406787            }
406788          ],
406789          "cpe": "cpe:2.3:a:safer-buffer:safer-buffer:2.1.2:*:*:*:*:*:*:*",
406790          "purl": "pkg:npm/safer-buffer@2.1.2",
406791          "swid": {
406792            "attachment": {}
406793          },
406794          "pedigree": {},
406795          "externalReferences": [
406796            {
406797              "url": "git+https://github.com/ChALkeR/safer-buffer.git",
406798              "type": "distribution"
406799            }
406800          ],
406801          "evidence": {},
406802          "signature": {
406803            "signature": {
406804              "publicKey": {}
406805            }
406806          },
406807          "modelCard": {
406808            "modelParameters": {
406809              "approach": {}
406810            },
406811            "quantitativeAnalysis": {
406812              "graphics": {}
406813            },
406814            "considerations": {}
406815          }
406816        },
406817        {
406818          "type": "library",
406819          "bom-ref": "pkg:npm/sax@1.2.4?package-id=d02182db0df4dd12",
406820          "supplier": {},
406821          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
406822          "name": "sax",
406823          "version": "1.2.4",
406824          "description": "An evented streaming XML parser in JavaScript",
406825          "licenses": [
406826            {
406827              "license": {
406828                "id": "ISC"
406829              }
406830            }
406831          ],
406832          "cpe": "cpe:2.3:a:isaacs:sax:1.2.4:*:*:*:*:*:*:*",
406833          "purl": "pkg:npm/sax@1.2.4",
406834          "swid": {
406835            "attachment": {}
406836          },
406837          "pedigree": {},
406838          "externalReferences": [
406839            {
406840              "url": "git://github.com/isaacs/sax-js.git",
406841              "type": "distribution"
406842            }
406843          ],
406844          "evidence": {},
406845          "signature": {
406846            "signature": {
406847              "publicKey": {}
406848            }
406849          },
406850          "modelCard": {
406851            "modelParameters": {
406852              "approach": {}
406853            },
406854            "quantitativeAnalysis": {
406855              "graphics": {}
406856            },
406857            "considerations": {}
406858          }
406859        },
406860        {
406861          "type": "library",
406862          "bom-ref": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5\u0026package-id=206fdb47b3e980eb",
406863          "supplier": {},
406864          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
406865          "name": "scanelf",
406866          "version": "1.3.4-r0",
406867          "description": "Scan ELF binaries for stuff",
406868          "licenses": [
406869            {
406870              "license": {
406871                "id": "GPL-2.0-only"
406872              }
406873            }
406874          ],
406875          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.4-r0:*:*:*:*:*:*:*",
406876          "purl": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5",
406877          "swid": {
406878            "attachment": {}
406879          },
406880          "pedigree": {},
406881          "externalReferences": [
406882            {
406883              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
406884              "type": "distribution"
406885            }
406886          ],
406887          "evidence": {},
406888          "signature": {
406889            "signature": {
406890              "publicKey": {}
406891            }
406892          },
406893          "modelCard": {
406894            "modelParameters": {
406895              "approach": {}
406896            },
406897            "quantitativeAnalysis": {
406898              "graphics": {}
406899            },
406900            "considerations": {}
406901          }
406902        },
406903        {
406904          "type": "library",
406905          "bom-ref": "pkg:npm/seek-bzip@1.0.6?package-id=ec4055eec47e8821",
406906          "supplier": {},
406907          "name": "seek-bzip",
406908          "version": "1.0.6",
406909          "description": "a pure-JavaScript Node.JS module for random-access decoding bzip2 data",
406910          "licenses": [
406911            {
406912              "license": {
406913                "id": "MIT"
406914              }
406915            }
406916          ],
406917          "cpe": "cpe:2.3:a:seek-bzip:seek-bzip:1.0.6:*:*:*:*:*:*:*",
406918          "purl": "pkg:npm/seek-bzip@1.0.6",
406919          "swid": {
406920            "attachment": {}
406921          },
406922          "pedigree": {},
406923          "externalReferences": [
406924            {
406925              "url": "https://github.com/cscott/seek-bzip.git",
406926              "type": "distribution"
406927            }
406928          ],
406929          "evidence": {},
406930          "signature": {
406931            "signature": {
406932              "publicKey": {}
406933            }
406934          },
406935          "modelCard": {
406936            "modelParameters": {
406937              "approach": {}
406938            },
406939            "quantitativeAnalysis": {
406940              "graphics": {}
406941            },
406942            "considerations": {}
406943          }
406944        },
406945        {
406946          "type": "library",
406947          "bom-ref": "pkg:npm/semver@5.7.1?package-id=4e2ff9f8472aa6a4",
406948          "supplier": {},
406949          "name": "semver",
406950          "version": "5.7.1",
406951          "description": "The semantic version parser used by npm.",
406952          "licenses": [
406953            {
406954              "license": {
406955                "id": "ISC"
406956              }
406957            }
406958          ],
406959          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
406960          "purl": "pkg:npm/semver@5.7.1",
406961          "swid": {
406962            "attachment": {}
406963          },
406964          "pedigree": {},
406965          "externalReferences": [
406966            {
406967              "url": "https://github.com/npm/node-semver",
406968              "type": "distribution"
406969            }
406970          ],
406971          "evidence": {},
406972          "signature": {
406973            "signature": {
406974              "publicKey": {}
406975            }
406976          },
406977          "modelCard": {
406978            "modelParameters": {
406979              "approach": {}
406980            },
406981            "quantitativeAnalysis": {
406982              "graphics": {}
406983            },
406984            "considerations": {}
406985          }
406986        },
406987        {
406988          "type": "library",
406989          "bom-ref": "pkg:npm/semver@5.7.1?package-id=483f29b746def53",
406990          "supplier": {},
406991          "name": "semver",
406992          "version": "5.7.1",
406993          "description": "The semantic version parser used by npm.",
406994          "licenses": [
406995            {
406996              "license": {
406997                "id": "ISC"
406998              }
406999            }
407000          ],
407001          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
407002          "purl": "pkg:npm/semver@5.7.1",
407003          "swid": {
407004            "attachment": {}
407005          },
407006          "pedigree": {},
407007          "externalReferences": [
407008            {
407009              "url": "https://github.com/npm/node-semver",
407010              "type": "distribution"
407011            }
407012          ],
407013          "evidence": {},
407014          "signature": {
407015            "signature": {
407016              "publicKey": {}
407017            }
407018          },
407019          "modelCard": {
407020            "modelParameters": {
407021              "approach": {}
407022            },
407023            "quantitativeAnalysis": {
407024              "graphics": {}
407025            },
407026            "considerations": {}
407027          }
407028        },
407029        {
407030          "type": "library",
407031          "bom-ref": "pkg:npm/semver@5.7.1?package-id=bf359e272c76e56b",
407032          "supplier": {},
407033          "name": "semver",
407034          "version": "5.7.1",
407035          "description": "The semantic version parser used by npm.",
407036          "licenses": [
407037            {
407038              "license": {
407039                "id": "ISC"
407040              }
407041            }
407042          ],
407043          "cpe": "cpe:2.3:a:semver:semver:5.7.1:*:*:*:*:*:*:*",
407044          "purl": "pkg:npm/semver@5.7.1",
407045          "swid": {
407046            "attachment": {}
407047          },
407048          "pedigree": {},
407049          "externalReferences": [
407050            {
407051              "url": "https://github.com/npm/node-semver",
407052              "type": "distribution"
407053            }
407054          ],
407055          "evidence": {},
407056          "signature": {
407057            "signature": {
407058              "publicKey": {}
407059            }
407060          },
407061          "modelCard": {
407062            "modelParameters": {
407063              "approach": {}
407064            },
407065            "quantitativeAnalysis": {
407066              "graphics": {}
407067            },
407068            "considerations": {}
407069          }
407070        },
407071        {
407072          "type": "library",
407073          "bom-ref": "pkg:npm/semver@7.3.7?package-id=73e16bb8e099774",
407074          "supplier": {},
407075          "author": "GitHub Inc.",
407076          "name": "semver",
407077          "version": "7.3.7",
407078          "description": "The semantic version parser used by npm.",
407079          "licenses": [
407080            {
407081              "license": {
407082                "id": "ISC"
407083              }
407084            }
407085          ],
407086          "cpe": "cpe:2.3:a:semver:semver:7.3.7:*:*:*:*:*:*:*",
407087          "purl": "pkg:npm/semver@7.3.7",
407088          "swid": {
407089            "attachment": {}
407090          },
407091          "pedigree": {},
407092          "externalReferences": [
407093            {
407094              "url": "https://github.com/npm/node-semver.git",
407095              "type": "distribution"
407096            }
407097          ],
407098          "evidence": {},
407099          "signature": {
407100            "signature": {
407101              "publicKey": {}
407102            }
407103          },
407104          "modelCard": {
407105            "modelParameters": {
407106              "approach": {}
407107            },
407108            "quantitativeAnalysis": {
407109              "graphics": {}
407110            },
407111            "considerations": {}
407112          }
407113        },
407114        {
407115          "type": "library",
407116          "bom-ref": "pkg:npm/semver@7.5.0?package-id=cc89a24dbf0d41c8",
407117          "supplier": {},
407118          "author": "GitHub Inc.",
407119          "name": "semver",
407120          "version": "7.5.0",
407121          "description": "The semantic version parser used by npm.",
407122          "licenses": [
407123            {
407124              "license": {
407125                "id": "ISC"
407126              }
407127            }
407128          ],
407129          "cpe": "cpe:2.3:a:semver:semver:7.5.0:*:*:*:*:*:*:*",
407130          "purl": "pkg:npm/semver@7.5.0",
407131          "swid": {
407132            "attachment": {}
407133          },
407134          "pedigree": {},
407135          "externalReferences": [
407136            {
407137              "url": "https://github.com/npm/node-semver.git",
407138              "type": "distribution"
407139            }
407140          ],
407141          "evidence": {},
407142          "signature": {
407143            "signature": {
407144              "publicKey": {}
407145            }
407146          },
407147          "modelCard": {
407148            "modelParameters": {
407149              "approach": {}
407150            },
407151            "quantitativeAnalysis": {
407152              "graphics": {}
407153            },
407154            "considerations": {}
407155          }
407156        },
407157        {
407158          "type": "library",
407159          "bom-ref": "pkg:npm/send@0.16.2?package-id=6aacb6d4db077764",
407160          "supplier": {},
407161          "author": "TJ Holowaychuk \u003ctj@vision-media.ca\u003e",
407162          "name": "send",
407163          "version": "0.16.2",
407164          "description": "Better streaming static file server with Range and conditional-GET support",
407165          "licenses": [
407166            {
407167              "license": {
407168                "id": "MIT"
407169              }
407170            }
407171          ],
407172          "cpe": "cpe:2.3:a:send:send:0.16.2:*:*:*:*:*:*:*",
407173          "purl": "pkg:npm/send@0.16.2",
407174          "swid": {
407175            "attachment": {}
407176          },
407177          "pedigree": {},
407178          "externalReferences": [
407179            {
407180              "url": "pillarjs/send",
407181              "type": "distribution"
407182            }
407183          ],
407184          "evidence": {},
407185          "signature": {
407186            "signature": {
407187              "publicKey": {}
407188            }
407189          },
407190          "modelCard": {
407191            "modelParameters": {
407192              "approach": {}
407193            },
407194            "quantitativeAnalysis": {
407195              "graphics": {}
407196            },
407197            "considerations": {}
407198          }
407199        },
407200        {
407201          "type": "library",
407202          "bom-ref": "pkg:npm/serve-static@1.13.2?package-id=2085513853dda1c3",
407203          "supplier": {},
407204          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
407205          "name": "serve-static",
407206          "version": "1.13.2",
407207          "description": "Serve static files",
407208          "licenses": [
407209            {
407210              "license": {
407211                "id": "MIT"
407212              }
407213            }
407214          ],
407215          "cpe": "cpe:2.3:a:serve-static:serve-static:1.13.2:*:*:*:*:*:*:*",
407216          "purl": "pkg:npm/serve-static@1.13.2",
407217          "swid": {
407218            "attachment": {}
407219          },
407220          "pedigree": {},
407221          "externalReferences": [
407222            {
407223              "url": "expressjs/serve-static",
407224              "type": "distribution"
407225            }
407226          ],
407227          "evidence": {},
407228          "signature": {
407229            "signature": {
407230              "publicKey": {}
407231            }
407232          },
407233          "modelCard": {
407234            "modelParameters": {
407235              "approach": {}
407236            },
407237            "quantitativeAnalysis": {
407238              "graphics": {}
407239            },
407240            "considerations": {}
407241          }
407242        },
407243        {
407244          "type": "library",
407245          "bom-ref": "pkg:npm/set-blocking@2.0.0?package-id=bac85cbb844de9c9",
407246          "supplier": {},
407247          "author": "Ben Coe \u003cben@npmjs.com\u003e",
407248          "name": "set-blocking",
407249          "version": "2.0.0",
407250          "description": "set blocking stdio and stderr ensuring that terminal output does not truncate",
407251          "licenses": [
407252            {
407253              "license": {
407254                "id": "ISC"
407255              }
407256            }
407257          ],
407258          "cpe": "cpe:2.3:a:set-blocking:set-blocking:2.0.0:*:*:*:*:*:*:*",
407259          "purl": "pkg:npm/set-blocking@2.0.0",
407260          "swid": {
407261            "attachment": {}
407262          },
407263          "pedigree": {},
407264          "externalReferences": [
407265            {
407266              "url": "git+https://github.com/yargs/set-blocking.git",
407267              "type": "distribution"
407268            },
407269            {
407270              "url": "https://github.com/yargs/set-blocking#readme",
407271              "type": "website"
407272            }
407273          ],
407274          "evidence": {},
407275          "signature": {
407276            "signature": {
407277              "publicKey": {}
407278            }
407279          },
407280          "modelCard": {
407281            "modelParameters": {
407282              "approach": {}
407283            },
407284            "quantitativeAnalysis": {
407285              "graphics": {}
407286            },
407287            "considerations": {}
407288          }
407289        },
407290        {
407291          "type": "library",
407292          "bom-ref": "pkg:npm/setprototypeof@1.1.0?package-id=5f62b122fce97102",
407293          "supplier": {},
407294          "author": "Wes Todd",
407295          "name": "setprototypeof",
407296          "version": "1.1.0",
407297          "description": "A small polyfill for Object.setprototypeof",
407298          "licenses": [
407299            {
407300              "license": {
407301                "id": "ISC"
407302              }
407303            }
407304          ],
407305          "cpe": "cpe:2.3:a:setprototypeof:setprototypeof:1.1.0:*:*:*:*:*:*:*",
407306          "purl": "pkg:npm/setprototypeof@1.1.0",
407307          "swid": {
407308            "attachment": {}
407309          },
407310          "pedigree": {},
407311          "externalReferences": [
407312            {
407313              "url": "https://github.com/wesleytodd/setprototypeof.git",
407314              "type": "distribution"
407315            },
407316            {
407317              "url": "https://github.com/wesleytodd/setprototypeof",
407318              "type": "website"
407319            }
407320          ],
407321          "evidence": {},
407322          "signature": {
407323            "signature": {
407324              "publicKey": {}
407325            }
407326          },
407327          "modelCard": {
407328            "modelParameters": {
407329              "approach": {}
407330            },
407331            "quantitativeAnalysis": {
407332              "graphics": {}
407333            },
407334            "considerations": {}
407335          }
407336        },
407337        {
407338          "type": "library",
407339          "bom-ref": "pkg:npm/shebang-command@1.2.0?package-id=d2c249cc68c66904",
407340          "supplier": {},
407341          "author": "Kevin Martensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
407342          "name": "shebang-command",
407343          "version": "1.2.0",
407344          "description": "Get the command from a shebang",
407345          "licenses": [
407346            {
407347              "license": {
407348                "id": "MIT"
407349              }
407350            }
407351          ],
407352          "cpe": "cpe:2.3:a:shebang-command:shebang-command:1.2.0:*:*:*:*:*:*:*",
407353          "purl": "pkg:npm/shebang-command@1.2.0",
407354          "swid": {
407355            "attachment": {}
407356          },
407357          "pedigree": {},
407358          "externalReferences": [
407359            {
407360              "url": "kevva/shebang-command",
407361              "type": "distribution"
407362            }
407363          ],
407364          "evidence": {},
407365          "signature": {
407366            "signature": {
407367              "publicKey": {}
407368            }
407369          },
407370          "modelCard": {
407371            "modelParameters": {
407372              "approach": {}
407373            },
407374            "quantitativeAnalysis": {
407375              "graphics": {}
407376            },
407377            "considerations": {}
407378          }
407379        },
407380        {
407381          "type": "library",
407382          "bom-ref": "pkg:npm/shebang-regex@1.0.0?package-id=92bf29094fdc6eb",
407383          "supplier": {},
407384          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
407385          "name": "shebang-regex",
407386          "version": "1.0.0",
407387          "description": "Regular expression for matching a shebang",
407388          "licenses": [
407389            {
407390              "license": {
407391                "id": "MIT"
407392              }
407393            }
407394          ],
407395          "cpe": "cpe:2.3:a:shebang-regex:shebang-regex:1.0.0:*:*:*:*:*:*:*",
407396          "purl": "pkg:npm/shebang-regex@1.0.0",
407397          "swid": {
407398            "attachment": {}
407399          },
407400          "pedigree": {},
407401          "externalReferences": [
407402            {
407403              "url": "sindresorhus/shebang-regex",
407404              "type": "distribution"
407405            }
407406          ],
407407          "evidence": {},
407408          "signature": {
407409            "signature": {
407410              "publicKey": {}
407411            }
407412          },
407413          "modelCard": {
407414            "modelParameters": {
407415              "approach": {}
407416            },
407417            "quantitativeAnalysis": {
407418              "graphics": {}
407419            },
407420            "considerations": {}
407421          }
407422        },
407423        {
407424          "type": "library",
407425          "bom-ref": "pkg:npm/signal-exit@3.0.7?package-id=998659694cba1dfd",
407426          "supplier": {},
407427          "author": "Ben Coe \u003cben@npmjs.com\u003e",
407428          "name": "signal-exit",
407429          "version": "3.0.7",
407430          "description": "when you want to fire an event no matter how a process exits.",
407431          "licenses": [
407432            {
407433              "license": {
407434                "id": "ISC"
407435              }
407436            }
407437          ],
407438          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.7:*:*:*:*:*:*:*",
407439          "purl": "pkg:npm/signal-exit@3.0.7",
407440          "swid": {
407441            "attachment": {}
407442          },
407443          "pedigree": {},
407444          "externalReferences": [
407445            {
407446              "url": "https://github.com/tapjs/signal-exit.git",
407447              "type": "distribution"
407448            },
407449            {
407450              "url": "https://github.com/tapjs/signal-exit",
407451              "type": "website"
407452            }
407453          ],
407454          "evidence": {},
407455          "signature": {
407456            "signature": {
407457              "publicKey": {}
407458            }
407459          },
407460          "modelCard": {
407461            "modelParameters": {
407462              "approach": {}
407463            },
407464            "quantitativeAnalysis": {
407465              "graphics": {}
407466            },
407467            "considerations": {}
407468          }
407469        },
407470        {
407471          "type": "library",
407472          "bom-ref": "pkg:npm/signal-exit@3.0.7?package-id=133483a000431c75",
407473          "supplier": {},
407474          "author": "Ben Coe \u003cben@npmjs.com\u003e",
407475          "name": "signal-exit",
407476          "version": "3.0.7",
407477          "description": "when you want to fire an event no matter how a process exits.",
407478          "licenses": [
407479            {
407480              "license": {
407481                "id": "ISC"
407482              }
407483            }
407484          ],
407485          "cpe": "cpe:2.3:a:signal-exit:signal-exit:3.0.7:*:*:*:*:*:*:*",
407486          "purl": "pkg:npm/signal-exit@3.0.7",
407487          "swid": {
407488            "attachment": {}
407489          },
407490          "pedigree": {},
407491          "externalReferences": [
407492            {
407493              "url": "https://github.com/tapjs/signal-exit.git",
407494              "type": "distribution"
407495            },
407496            {
407497              "url": "https://github.com/tapjs/signal-exit",
407498              "type": "website"
407499            }
407500          ],
407501          "evidence": {},
407502          "signature": {
407503            "signature": {
407504              "publicKey": {}
407505            }
407506          },
407507          "modelCard": {
407508            "modelParameters": {
407509              "approach": {}
407510            },
407511            "quantitativeAnalysis": {
407512              "graphics": {}
407513            },
407514            "considerations": {}
407515          }
407516        },
407517        {
407518          "type": "library",
407519          "bom-ref": "pkg:npm/slash@2.0.0?package-id=10c3538e779a8cee",
407520          "supplier": {},
407521          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
407522          "name": "slash",
407523          "version": "2.0.0",
407524          "description": "Convert Windows backslash paths to slash paths",
407525          "licenses": [
407526            {
407527              "license": {
407528                "id": "MIT"
407529              }
407530            }
407531          ],
407532          "cpe": "cpe:2.3:a:slash:slash:2.0.0:*:*:*:*:*:*:*",
407533          "purl": "pkg:npm/slash@2.0.0",
407534          "swid": {
407535            "attachment": {}
407536          },
407537          "pedigree": {},
407538          "externalReferences": [
407539            {
407540              "url": "sindresorhus/slash",
407541              "type": "distribution"
407542            }
407543          ],
407544          "evidence": {},
407545          "signature": {
407546            "signature": {
407547              "publicKey": {}
407548            }
407549          },
407550          "modelCard": {
407551            "modelParameters": {
407552              "approach": {}
407553            },
407554            "quantitativeAnalysis": {
407555              "graphics": {}
407556            },
407557            "considerations": {}
407558          }
407559        },
407560        {
407561          "type": "library",
407562          "bom-ref": "pkg:npm/slash@3.0.0?package-id=17080049f6093788",
407563          "supplier": {},
407564          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
407565          "name": "slash",
407566          "version": "3.0.0",
407567          "description": "Convert Windows backslash paths to slash paths",
407568          "licenses": [
407569            {
407570              "license": {
407571                "id": "MIT"
407572              }
407573            }
407574          ],
407575          "cpe": "cpe:2.3:a:slash:slash:3.0.0:*:*:*:*:*:*:*",
407576          "purl": "pkg:npm/slash@3.0.0",
407577          "swid": {
407578            "attachment": {}
407579          },
407580          "pedigree": {},
407581          "externalReferences": [
407582            {
407583              "url": "sindresorhus/slash",
407584              "type": "distribution"
407585            }
407586          ],
407587          "evidence": {},
407588          "signature": {
407589            "signature": {
407590              "publicKey": {}
407591            }
407592          },
407593          "modelCard": {
407594            "modelParameters": {
407595              "approach": {}
407596            },
407597            "quantitativeAnalysis": {
407598              "graphics": {}
407599            },
407600            "considerations": {}
407601          }
407602        },
407603        {
407604          "type": "library",
407605          "bom-ref": "pkg:npm/smart-buffer@4.2.0?package-id=ad322c124ae3043c",
407606          "supplier": {},
407607          "author": "Josh Glazebrook",
407608          "name": "smart-buffer",
407609          "version": "4.2.0",
407610          "description": "smart-buffer is a Buffer wrapper that adds automatic read \u0026 write offset tracking, string operations, data insertions, and more.",
407611          "licenses": [
407612            {
407613              "license": {
407614                "id": "MIT"
407615              }
407616            }
407617          ],
407618          "cpe": "cpe:2.3:a:JoshGlazebrook:smart-buffer:4.2.0:*:*:*:*:*:*:*",
407619          "purl": "pkg:npm/smart-buffer@4.2.0",
407620          "swid": {
407621            "attachment": {}
407622          },
407623          "pedigree": {},
407624          "externalReferences": [
407625            {
407626              "url": "https://github.com/JoshGlazebrook/smart-buffer.git",
407627              "type": "distribution"
407628            },
407629            {
407630              "url": "https://github.com/JoshGlazebrook/smart-buffer/",
407631              "type": "website"
407632            }
407633          ],
407634          "evidence": {},
407635          "signature": {
407636            "signature": {
407637              "publicKey": {}
407638            }
407639          },
407640          "modelCard": {
407641            "modelParameters": {
407642              "approach": {}
407643            },
407644            "quantitativeAnalysis": {
407645              "graphics": {}
407646            },
407647            "considerations": {}
407648          }
407649        },
407650        {
407651          "type": "library",
407652          "bom-ref": "pkg:npm/socks@2.7.0?package-id=267f6eb3d489a8eb",
407653          "supplier": {},
407654          "author": "Josh Glazebrook",
407655          "name": "socks",
407656          "version": "2.7.0",
407657          "description": "Fully featured SOCKS proxy client supporting SOCKSv4, SOCKSv4a, and SOCKSv5. Includes Bind and Associate functionality.",
407658          "licenses": [
407659            {
407660              "license": {
407661                "id": "MIT"
407662              }
407663            }
407664          ],
407665          "cpe": "cpe:2.3:a:JoshGlazebrook:socks:2.7.0:*:*:*:*:*:*:*",
407666          "purl": "pkg:npm/socks@2.7.0",
407667          "swid": {
407668            "attachment": {}
407669          },
407670          "pedigree": {},
407671          "externalReferences": [
407672            {
407673              "url": "https://github.com/JoshGlazebrook/socks.git",
407674              "type": "distribution"
407675            },
407676            {
407677              "url": "https://github.com/JoshGlazebrook/socks/",
407678              "type": "website"
407679            }
407680          ],
407681          "evidence": {},
407682          "signature": {
407683            "signature": {
407684              "publicKey": {}
407685            }
407686          },
407687          "modelCard": {
407688            "modelParameters": {
407689              "approach": {}
407690            },
407691            "quantitativeAnalysis": {
407692              "graphics": {}
407693            },
407694            "considerations": {}
407695          }
407696        },
407697        {
407698          "type": "library",
407699          "bom-ref": "pkg:npm/socks-proxy-agent@7.0.0?package-id=8dc0e605920052a1",
407700          "supplier": {},
407701          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
407702          "name": "socks-proxy-agent",
407703          "version": "7.0.0",
407704          "description": "A SOCKS proxy `http.Agent` implementation for HTTP and HTTPS",
407705          "licenses": [
407706            {
407707              "license": {
407708                "id": "MIT"
407709              }
407710            }
407711          ],
407712          "cpe": "cpe:2.3:a:socks-proxy-agent:socks-proxy-agent:7.0.0:*:*:*:*:*:*:*",
407713          "purl": "pkg:npm/socks-proxy-agent@7.0.0",
407714          "swid": {
407715            "attachment": {}
407716          },
407717          "pedigree": {},
407718          "externalReferences": [
407719            {
407720              "url": "git://github.com/TooTallNate/node-socks-proxy-agent.git",
407721              "type": "distribution"
407722            },
407723            {
407724              "url": "https://github.com/TooTallNate/node-socks-proxy-agent#readme",
407725              "type": "website"
407726            }
407727          ],
407728          "evidence": {},
407729          "signature": {
407730            "signature": {
407731              "publicKey": {}
407732            }
407733          },
407734          "modelCard": {
407735            "modelParameters": {
407736              "approach": {}
407737            },
407738            "quantitativeAnalysis": {
407739              "graphics": {}
407740            },
407741            "considerations": {}
407742          }
407743        },
407744        {
407745          "type": "library",
407746          "bom-ref": "pkg:npm/sort-keys@1.1.2?package-id=ce6e76bdbe33999b",
407747          "supplier": {},
407748          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
407749          "name": "sort-keys",
407750          "version": "1.1.2",
407751          "description": "Sort the keys of an object",
407752          "licenses": [
407753            {
407754              "license": {
407755                "id": "MIT"
407756              }
407757            }
407758          ],
407759          "cpe": "cpe:2.3:a:sort-keys:sort-keys:1.1.2:*:*:*:*:*:*:*",
407760          "purl": "pkg:npm/sort-keys@1.1.2",
407761          "swid": {
407762            "attachment": {}
407763          },
407764          "pedigree": {},
407765          "externalReferences": [
407766            {
407767              "url": "sindresorhus/sort-keys",
407768              "type": "distribution"
407769            }
407770          ],
407771          "evidence": {},
407772          "signature": {
407773            "signature": {
407774              "publicKey": {}
407775            }
407776          },
407777          "modelCard": {
407778            "modelParameters": {
407779              "approach": {}
407780            },
407781            "quantitativeAnalysis": {
407782              "graphics": {}
407783            },
407784            "considerations": {}
407785          }
407786        },
407787        {
407788          "type": "library",
407789          "bom-ref": "pkg:npm/sort-keys@2.0.0?package-id=804f9d1bafeb049e",
407790          "supplier": {},
407791          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
407792          "name": "sort-keys",
407793          "version": "2.0.0",
407794          "description": "Sort the keys of an object",
407795          "licenses": [
407796            {
407797              "license": {
407798                "id": "MIT"
407799              }
407800            }
407801          ],
407802          "cpe": "cpe:2.3:a:sort-keys:sort-keys:2.0.0:*:*:*:*:*:*:*",
407803          "purl": "pkg:npm/sort-keys@2.0.0",
407804          "swid": {
407805            "attachment": {}
407806          },
407807          "pedigree": {},
407808          "externalReferences": [
407809            {
407810              "url": "sindresorhus/sort-keys",
407811              "type": "distribution"
407812            }
407813          ],
407814          "evidence": {},
407815          "signature": {
407816            "signature": {
407817              "publicKey": {}
407818            }
407819          },
407820          "modelCard": {
407821            "modelParameters": {
407822              "approach": {}
407823            },
407824            "quantitativeAnalysis": {
407825              "graphics": {}
407826            },
407827            "considerations": {}
407828          }
407829        },
407830        {
407831          "type": "library",
407832          "bom-ref": "pkg:npm/sort-keys-length@1.0.1?package-id=7c24e03775c837c0",
407833          "supplier": {},
407834          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (https://github.com/kevva)",
407835          "name": "sort-keys-length",
407836          "version": "1.0.1",
407837          "description": "Sort objecy keys by length",
407838          "licenses": [
407839            {
407840              "license": {
407841                "id": "MIT"
407842              }
407843            }
407844          ],
407845          "cpe": "cpe:2.3:a:sort-keys-length:sort-keys-length:1.0.1:*:*:*:*:*:*:*",
407846          "purl": "pkg:npm/sort-keys-length@1.0.1",
407847          "swid": {
407848            "attachment": {}
407849          },
407850          "pedigree": {},
407851          "externalReferences": [
407852            {
407853              "url": "kevva/sort-keys-length",
407854              "type": "distribution"
407855            }
407856          ],
407857          "evidence": {},
407858          "signature": {
407859            "signature": {
407860              "publicKey": {}
407861            }
407862          },
407863          "modelCard": {
407864            "modelParameters": {
407865              "approach": {}
407866            },
407867            "quantitativeAnalysis": {
407868              "graphics": {}
407869            },
407870            "considerations": {}
407871          }
407872        },
407873        {
407874          "type": "library",
407875          "bom-ref": "pkg:npm/spdx-correct@3.1.1?package-id=d6b0214947e454eb",
407876          "supplier": {},
407877          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
407878          "name": "spdx-correct",
407879          "version": "3.1.1",
407880          "description": "correct invalid SPDX expressions",
407881          "licenses": [
407882            {
407883              "license": {
407884                "id": "Apache-2.0"
407885              }
407886            }
407887          ],
407888          "cpe": "cpe:2.3:a:spdx-correct:spdx-correct:3.1.1:*:*:*:*:*:*:*",
407889          "purl": "pkg:npm/spdx-correct@3.1.1",
407890          "swid": {
407891            "attachment": {}
407892          },
407893          "pedigree": {},
407894          "externalReferences": [
407895            {
407896              "url": "jslicense/spdx-correct.js",
407897              "type": "distribution"
407898            }
407899          ],
407900          "evidence": {},
407901          "signature": {
407902            "signature": {
407903              "publicKey": {}
407904            }
407905          },
407906          "modelCard": {
407907            "modelParameters": {
407908              "approach": {}
407909            },
407910            "quantitativeAnalysis": {
407911              "graphics": {}
407912            },
407913            "considerations": {}
407914          }
407915        },
407916        {
407917          "type": "library",
407918          "bom-ref": "pkg:npm/spdx-exceptions@2.3.0?package-id=22aa1fb7c596c6c7",
407919          "supplier": {},
407920          "author": "The Linux Foundation",
407921          "name": "spdx-exceptions",
407922          "version": "2.3.0",
407923          "description": "list of SPDX standard license exceptions",
407924          "licenses": [
407925            {
407926              "license": {
407927                "id": "CC-BY-3.0"
407928              }
407929            }
407930          ],
407931          "cpe": "cpe:2.3:a:spdx-exceptions:spdx-exceptions:2.3.0:*:*:*:*:*:*:*",
407932          "purl": "pkg:npm/spdx-exceptions@2.3.0",
407933          "swid": {
407934            "attachment": {}
407935          },
407936          "pedigree": {},
407937          "externalReferences": [
407938            {
407939              "url": "kemitchell/spdx-exceptions.json",
407940              "type": "distribution"
407941            }
407942          ],
407943          "evidence": {},
407944          "signature": {
407945            "signature": {
407946              "publicKey": {}
407947            }
407948          },
407949          "modelCard": {
407950            "modelParameters": {
407951              "approach": {}
407952            },
407953            "quantitativeAnalysis": {
407954              "graphics": {}
407955            },
407956            "considerations": {}
407957          }
407958        },
407959        {
407960          "type": "library",
407961          "bom-ref": "pkg:npm/spdx-expression-parse@3.0.1?package-id=78c73c9b189e2783",
407962          "supplier": {},
407963          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
407964          "name": "spdx-expression-parse",
407965          "version": "3.0.1",
407966          "description": "parse SPDX license expressions",
407967          "licenses": [
407968            {
407969              "license": {
407970                "id": "MIT"
407971              }
407972            }
407973          ],
407974          "cpe": "cpe:2.3:a:spdx-expression-parse:spdx-expression-parse:3.0.1:*:*:*:*:*:*:*",
407975          "purl": "pkg:npm/spdx-expression-parse@3.0.1",
407976          "swid": {
407977            "attachment": {}
407978          },
407979          "pedigree": {},
407980          "externalReferences": [
407981            {
407982              "url": "jslicense/spdx-expression-parse.js",
407983              "type": "distribution"
407984            }
407985          ],
407986          "evidence": {},
407987          "signature": {
407988            "signature": {
407989              "publicKey": {}
407990            }
407991          },
407992          "modelCard": {
407993            "modelParameters": {
407994              "approach": {}
407995            },
407996            "quantitativeAnalysis": {
407997              "graphics": {}
407998            },
407999            "considerations": {}
408000          }
408001        },
408002        {
408003          "type": "library",
408004          "bom-ref": "pkg:npm/spdx-license-ids@3.0.11?package-id=6530ac28616ec508",
408005          "supplier": {},
408006          "author": "Shinnosuke Watanabe (https://github.com/shinnn)",
408007          "name": "spdx-license-ids",
408008          "version": "3.0.11",
408009          "description": "A list of SPDX license identifiers",
408010          "licenses": [
408011            {
408012              "license": {
408013                "id": "CC0-1.0"
408014              }
408015            }
408016          ],
408017          "cpe": "cpe:2.3:a:spdx-license-ids:spdx-license-ids:3.0.11:*:*:*:*:*:*:*",
408018          "purl": "pkg:npm/spdx-license-ids@3.0.11",
408019          "swid": {
408020            "attachment": {}
408021          },
408022          "pedigree": {},
408023          "externalReferences": [
408024            {
408025              "url": "jslicense/spdx-license-ids",
408026              "type": "distribution"
408027            }
408028          ],
408029          "evidence": {},
408030          "signature": {
408031            "signature": {
408032              "publicKey": {}
408033            }
408034          },
408035          "modelCard": {
408036            "modelParameters": {
408037              "approach": {}
408038            },
408039            "quantitativeAnalysis": {
408040              "graphics": {}
408041            },
408042            "considerations": {}
408043          }
408044        },
408045        {
408046          "type": "library",
408047          "bom-ref": "pkg:npm/sshpk@1.17.0?package-id=343f480d60c250d6",
408048          "supplier": {},
408049          "author": "Joyent, Inc",
408050          "name": "sshpk",
408051          "version": "1.17.0",
408052          "description": "A library for finding and using SSH public keys",
408053          "licenses": [
408054            {
408055              "license": {
408056                "id": "MIT"
408057              }
408058            }
408059          ],
408060          "cpe": "cpe:2.3:a:arekinath:sshpk:1.17.0:*:*:*:*:*:*:*",
408061          "purl": "pkg:npm/sshpk@1.17.0",
408062          "swid": {
408063            "attachment": {}
408064          },
408065          "pedigree": {},
408066          "externalReferences": [
408067            {
408068              "url": "git+https://github.com/joyent/node-sshpk.git",
408069              "type": "distribution"
408070            },
408071            {
408072              "url": "https://github.com/arekinath/node-sshpk#readme",
408073              "type": "website"
408074            }
408075          ],
408076          "evidence": {},
408077          "signature": {
408078            "signature": {
408079              "publicKey": {}
408080            }
408081          },
408082          "modelCard": {
408083            "modelParameters": {
408084              "approach": {}
408085            },
408086            "quantitativeAnalysis": {
408087              "graphics": {}
408088            },
408089            "considerations": {}
408090          }
408091        },
408092        {
408093          "type": "library",
408094          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5\u0026package-id=674d1e2fba4d633a",
408095          "supplier": {},
408096          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
408097          "name": "ssl_client",
408098          "version": "1.35.0-r17",
408099          "description": "EXternal ssl_client for busybox wget",
408100          "licenses": [
408101            {
408102              "license": {
408103                "id": "GPL-2.0-only"
408104              }
408105            }
408106          ],
408107          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r17:*:*:*:*:*:*:*",
408108          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5",
408109          "swid": {
408110            "attachment": {}
408111          },
408112          "pedigree": {},
408113          "externalReferences": [
408114            {
408115              "url": "https://busybox.net/",
408116              "type": "distribution"
408117            }
408118          ],
408119          "evidence": {},
408120          "signature": {
408121            "signature": {
408122              "publicKey": {}
408123            }
408124          },
408125          "modelCard": {
408126            "modelParameters": {
408127              "approach": {}
408128            },
408129            "quantitativeAnalysis": {
408130              "graphics": {}
408131            },
408132            "considerations": {}
408133          }
408134        },
408135        {
408136          "type": "library",
408137          "bom-ref": "pkg:npm/ssri@9.0.1?package-id=49986701356bf646",
408138          "supplier": {},
408139          "author": "GitHub Inc.",
408140          "name": "ssri",
408141          "version": "9.0.1",
408142          "description": "Standard Subresource Integrity library -- parses, serializes, generates, and verifies integrity metadata according to the SRI spec.",
408143          "licenses": [
408144            {
408145              "license": {
408146                "id": "ISC"
408147              }
408148            }
408149          ],
408150          "cpe": "cpe:2.3:a:ssri:ssri:9.0.1:*:*:*:*:*:*:*",
408151          "purl": "pkg:npm/ssri@9.0.1",
408152          "swid": {
408153            "attachment": {}
408154          },
408155          "pedigree": {},
408156          "externalReferences": [
408157            {
408158              "url": "https://github.com/npm/ssri.git",
408159              "type": "distribution"
408160            }
408161          ],
408162          "evidence": {},
408163          "signature": {
408164            "signature": {
408165              "publicKey": {}
408166            }
408167          },
408168          "modelCard": {
408169            "modelParameters": {
408170              "approach": {}
408171            },
408172            "quantitativeAnalysis": {
408173              "graphics": {}
408174            },
408175            "considerations": {}
408176          }
408177        },
408178        {
408179          "type": "library",
408180          "bom-ref": "pkg:npm/statuses@1.4.0?package-id=1492f259b23a7535",
408181          "supplier": {},
408182          "name": "statuses",
408183          "version": "1.4.0",
408184          "description": "HTTP status utility",
408185          "licenses": [
408186            {
408187              "license": {
408188                "id": "MIT"
408189              }
408190            }
408191          ],
408192          "cpe": "cpe:2.3:a:statuses:statuses:1.4.0:*:*:*:*:*:*:*",
408193          "purl": "pkg:npm/statuses@1.4.0",
408194          "swid": {
408195            "attachment": {}
408196          },
408197          "pedigree": {},
408198          "externalReferences": [
408199            {
408200              "url": "jshttp/statuses",
408201              "type": "distribution"
408202            }
408203          ],
408204          "evidence": {},
408205          "signature": {
408206            "signature": {
408207              "publicKey": {}
408208            }
408209          },
408210          "modelCard": {
408211            "modelParameters": {
408212              "approach": {}
408213            },
408214            "quantitativeAnalysis": {
408215              "graphics": {}
408216            },
408217            "considerations": {}
408218          }
408219        },
408220        {
408221          "type": "library",
408222          "bom-ref": "pkg:npm/stealthy-require@1.1.1?package-id=3fb5cb194dd47043",
408223          "supplier": {},
408224          "author": "Nicolai Kamenzky (https://github.com/analog-nico)",
408225          "name": "stealthy-require",
408226          "version": "1.1.1",
408227          "description": "The closest you can get to require something with bypassing the require cache",
408228          "licenses": [
408229            {
408230              "license": {
408231                "id": "ISC"
408232              }
408233            }
408234          ],
408235          "cpe": "cpe:2.3:a:stealthy-require:stealthy-require:1.1.1:*:*:*:*:*:*:*",
408236          "purl": "pkg:npm/stealthy-require@1.1.1",
408237          "swid": {
408238            "attachment": {}
408239          },
408240          "pedigree": {},
408241          "externalReferences": [
408242            {
408243              "url": "git+https://github.com/analog-nico/stealthy-require.git",
408244              "type": "distribution"
408245            },
408246            {
408247              "url": "https://github.com/analog-nico/stealthy-require#readme",
408248              "type": "website"
408249            }
408250          ],
408251          "evidence": {},
408252          "signature": {
408253            "signature": {
408254              "publicKey": {}
408255            }
408256          },
408257          "modelCard": {
408258            "modelParameters": {
408259              "approach": {}
408260            },
408261            "quantitativeAnalysis": {
408262              "graphics": {}
408263            },
408264            "considerations": {}
408265          }
408266        },
408267        {
408268          "type": "library",
408269          "bom-ref": "pkg:npm/strict-uri-encode@1.1.0?package-id=ff80b9bfc2ac6799",
408270          "supplier": {},
408271          "author": "Kevin Mårtensson \u003ckevinmartensson@gmail.com\u003e (github.com/kevva)",
408272          "name": "strict-uri-encode",
408273          "version": "1.1.0",
408274          "description": "A stricter URI encode adhering to RFC 3986",
408275          "licenses": [
408276            {
408277              "license": {
408278                "id": "MIT"
408279              }
408280            }
408281          ],
408282          "cpe": "cpe:2.3:a:strict-uri-encode:strict-uri-encode:1.1.0:*:*:*:*:*:*:*",
408283          "purl": "pkg:npm/strict-uri-encode@1.1.0",
408284          "swid": {
408285            "attachment": {}
408286          },
408287          "pedigree": {},
408288          "externalReferences": [
408289            {
408290              "url": "kevva/strict-uri-encode",
408291              "type": "distribution"
408292            }
408293          ],
408294          "evidence": {},
408295          "signature": {
408296            "signature": {
408297              "publicKey": {}
408298            }
408299          },
408300          "modelCard": {
408301            "modelParameters": {
408302              "approach": {}
408303            },
408304            "quantitativeAnalysis": {
408305              "graphics": {}
408306            },
408307            "considerations": {}
408308          }
408309        },
408310        {
408311          "type": "library",
408312          "bom-ref": "pkg:npm/string-width@4.2.3?package-id=c50e61a77e3ea809",
408313          "supplier": {},
408314          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
408315          "name": "string-width",
408316          "version": "4.2.3",
408317          "description": "Get the visual width of a string - the number of columns required to display it",
408318          "licenses": [
408319            {
408320              "license": {
408321                "id": "MIT"
408322              }
408323            }
408324          ],
408325          "cpe": "cpe:2.3:a:string-width:string-width:4.2.3:*:*:*:*:*:*:*",
408326          "purl": "pkg:npm/string-width@4.2.3",
408327          "swid": {
408328            "attachment": {}
408329          },
408330          "pedigree": {},
408331          "externalReferences": [
408332            {
408333              "url": "sindresorhus/string-width",
408334              "type": "distribution"
408335            }
408336          ],
408337          "evidence": {},
408338          "signature": {
408339            "signature": {
408340              "publicKey": {}
408341            }
408342          },
408343          "modelCard": {
408344            "modelParameters": {
408345              "approach": {}
408346            },
408347            "quantitativeAnalysis": {
408348              "graphics": {}
408349            },
408350            "considerations": {}
408351          }
408352        },
408353        {
408354          "type": "library",
408355          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=92cdcd9ac26aecf0",
408356          "supplier": {},
408357          "name": "string_decoder",
408358          "version": "1.1.1",
408359          "description": "The string_decoder module from Node core",
408360          "licenses": [
408361            {
408362              "license": {
408363                "id": "MIT"
408364              }
408365            }
408366          ],
408367          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
408368          "purl": "pkg:npm/string_decoder@1.1.1",
408369          "swid": {
408370            "attachment": {}
408371          },
408372          "pedigree": {},
408373          "externalReferences": [
408374            {
408375              "url": "git://github.com/nodejs/string_decoder.git",
408376              "type": "distribution"
408377            },
408378            {
408379              "url": "https://github.com/nodejs/string_decoder",
408380              "type": "website"
408381            }
408382          ],
408383          "evidence": {},
408384          "signature": {
408385            "signature": {
408386              "publicKey": {}
408387            }
408388          },
408389          "modelCard": {
408390            "modelParameters": {
408391              "approach": {}
408392            },
408393            "quantitativeAnalysis": {
408394              "graphics": {}
408395            },
408396            "considerations": {}
408397          }
408398        },
408399        {
408400          "type": "library",
408401          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=d1bcf3210ee4f3ad",
408402          "supplier": {},
408403          "name": "string_decoder",
408404          "version": "1.1.1",
408405          "description": "The string_decoder module from Node core",
408406          "licenses": [
408407            {
408408              "license": {
408409                "id": "MIT"
408410              }
408411            }
408412          ],
408413          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
408414          "purl": "pkg:npm/string_decoder@1.1.1",
408415          "swid": {
408416            "attachment": {}
408417          },
408418          "pedigree": {},
408419          "externalReferences": [
408420            {
408421              "url": "git://github.com/nodejs/string_decoder.git",
408422              "type": "distribution"
408423            },
408424            {
408425              "url": "https://github.com/nodejs/string_decoder",
408426              "type": "website"
408427            }
408428          ],
408429          "evidence": {},
408430          "signature": {
408431            "signature": {
408432              "publicKey": {}
408433            }
408434          },
408435          "modelCard": {
408436            "modelParameters": {
408437              "approach": {}
408438            },
408439            "quantitativeAnalysis": {
408440              "graphics": {}
408441            },
408442            "considerations": {}
408443          }
408444        },
408445        {
408446          "type": "library",
408447          "bom-ref": "pkg:npm/string_decoder@1.1.1?package-id=357b7693ece40f7a",
408448          "supplier": {},
408449          "name": "string_decoder",
408450          "version": "1.1.1",
408451          "description": "The string_decoder module from Node core",
408452          "licenses": [
408453            {
408454              "license": {
408455                "id": "MIT"
408456              }
408457            }
408458          ],
408459          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.1.1:*:*:*:*:*:*:*",
408460          "purl": "pkg:npm/string_decoder@1.1.1",
408461          "swid": {
408462            "attachment": {}
408463          },
408464          "pedigree": {},
408465          "externalReferences": [
408466            {
408467              "url": "git://github.com/nodejs/string_decoder.git",
408468              "type": "distribution"
408469            },
408470            {
408471              "url": "https://github.com/nodejs/string_decoder",
408472              "type": "website"
408473            }
408474          ],
408475          "evidence": {},
408476          "signature": {
408477            "signature": {
408478              "publicKey": {}
408479            }
408480          },
408481          "modelCard": {
408482            "modelParameters": {
408483              "approach": {}
408484            },
408485            "quantitativeAnalysis": {
408486              "graphics": {}
408487            },
408488            "considerations": {}
408489          }
408490        },
408491        {
408492          "type": "library",
408493          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=ca8af4aa6b41ca75",
408494          "supplier": {},
408495          "name": "string_decoder",
408496          "version": "1.3.0",
408497          "description": "The string_decoder module from Node core",
408498          "licenses": [
408499            {
408500              "license": {
408501                "id": "MIT"
408502              }
408503            }
408504          ],
408505          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
408506          "purl": "pkg:npm/string_decoder@1.3.0",
408507          "swid": {
408508            "attachment": {}
408509          },
408510          "pedigree": {},
408511          "externalReferences": [
408512            {
408513              "url": "git://github.com/nodejs/string_decoder.git",
408514              "type": "distribution"
408515            },
408516            {
408517              "url": "https://github.com/nodejs/string_decoder",
408518              "type": "website"
408519            }
408520          ],
408521          "evidence": {},
408522          "signature": {
408523            "signature": {
408524              "publicKey": {}
408525            }
408526          },
408527          "modelCard": {
408528            "modelParameters": {
408529              "approach": {}
408530            },
408531            "quantitativeAnalysis": {
408532              "graphics": {}
408533            },
408534            "considerations": {}
408535          }
408536        },
408537        {
408538          "type": "library",
408539          "bom-ref": "pkg:npm/string_decoder@1.3.0?package-id=4416d34ed115d469",
408540          "supplier": {},
408541          "name": "string_decoder",
408542          "version": "1.3.0",
408543          "description": "The string_decoder module from Node core",
408544          "licenses": [
408545            {
408546              "license": {
408547                "id": "MIT"
408548              }
408549            }
408550          ],
408551          "cpe": "cpe:2.3:a:string-decoder:string-decoder:1.3.0:*:*:*:*:*:*:*",
408552          "purl": "pkg:npm/string_decoder@1.3.0",
408553          "swid": {
408554            "attachment": {}
408555          },
408556          "pedigree": {},
408557          "externalReferences": [
408558            {
408559              "url": "git://github.com/nodejs/string_decoder.git",
408560              "type": "distribution"
408561            },
408562            {
408563              "url": "https://github.com/nodejs/string_decoder",
408564              "type": "website"
408565            }
408566          ],
408567          "evidence": {},
408568          "signature": {
408569            "signature": {
408570              "publicKey": {}
408571            }
408572          },
408573          "modelCard": {
408574            "modelParameters": {
408575              "approach": {}
408576            },
408577            "quantitativeAnalysis": {
408578              "graphics": {}
408579            },
408580            "considerations": {}
408581          }
408582        },
408583        {
408584          "type": "library",
408585          "bom-ref": "pkg:npm/strip-ansi@5.2.0?package-id=d0a3d8fcb037e46d",
408586          "supplier": {},
408587          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
408588          "name": "strip-ansi",
408589          "version": "5.2.0",
408590          "description": "Strip ANSI escape codes from a string",
408591          "licenses": [
408592            {
408593              "license": {
408594                "id": "MIT"
408595              }
408596            }
408597          ],
408598          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:5.2.0:*:*:*:*:*:*:*",
408599          "purl": "pkg:npm/strip-ansi@5.2.0",
408600          "swid": {
408601            "attachment": {}
408602          },
408603          "pedigree": {},
408604          "externalReferences": [
408605            {
408606              "url": "chalk/strip-ansi",
408607              "type": "distribution"
408608            }
408609          ],
408610          "evidence": {},
408611          "signature": {
408612            "signature": {
408613              "publicKey": {}
408614            }
408615          },
408616          "modelCard": {
408617            "modelParameters": {
408618              "approach": {}
408619            },
408620            "quantitativeAnalysis": {
408621              "graphics": {}
408622            },
408623            "considerations": {}
408624          }
408625        },
408626        {
408627          "type": "library",
408628          "bom-ref": "pkg:npm/strip-ansi@6.0.1?package-id=5ec73c7d72940ceb",
408629          "supplier": {},
408630          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
408631          "name": "strip-ansi",
408632          "version": "6.0.1",
408633          "description": "Strip ANSI escape codes from a string",
408634          "licenses": [
408635            {
408636              "license": {
408637                "id": "MIT"
408638              }
408639            }
408640          ],
408641          "cpe": "cpe:2.3:a:strip-ansi:strip-ansi:6.0.1:*:*:*:*:*:*:*",
408642          "purl": "pkg:npm/strip-ansi@6.0.1",
408643          "swid": {
408644            "attachment": {}
408645          },
408646          "pedigree": {},
408647          "externalReferences": [
408648            {
408649              "url": "chalk/strip-ansi",
408650              "type": "distribution"
408651            }
408652          ],
408653          "evidence": {},
408654          "signature": {
408655            "signature": {
408656              "publicKey": {}
408657            }
408658          },
408659          "modelCard": {
408660            "modelParameters": {
408661              "approach": {}
408662            },
408663            "quantitativeAnalysis": {
408664              "graphics": {}
408665            },
408666            "considerations": {}
408667          }
408668        },
408669        {
408670          "type": "library",
408671          "bom-ref": "pkg:npm/strip-dirs@2.1.0?package-id=cdfc291270507c5a",
408672          "supplier": {},
408673          "author": "Shinnosuke Watanabe (https://github.com/shinnn)",
408674          "name": "strip-dirs",
408675          "version": "2.1.0",
408676          "description": "Remove leading directory components from a path, like tar's --strip-components option",
408677          "licenses": [
408678            {
408679              "license": {
408680                "id": "MIT"
408681              }
408682            }
408683          ],
408684          "cpe": "cpe:2.3:a:strip-dirs:strip-dirs:2.1.0:*:*:*:*:*:*:*",
408685          "purl": "pkg:npm/strip-dirs@2.1.0",
408686          "swid": {
408687            "attachment": {}
408688          },
408689          "pedigree": {},
408690          "externalReferences": [
408691            {
408692              "url": "shinnn/node-strip-dirs",
408693              "type": "distribution"
408694            }
408695          ],
408696          "evidence": {},
408697          "signature": {
408698            "signature": {
408699              "publicKey": {}
408700            }
408701          },
408702          "modelCard": {
408703            "modelParameters": {
408704              "approach": {}
408705            },
408706            "quantitativeAnalysis": {
408707              "graphics": {}
408708            },
408709            "considerations": {}
408710          }
408711        },
408712        {
408713          "type": "library",
408714          "bom-ref": "pkg:npm/strip-outer@1.0.1?package-id=93872f5661976cfe",
408715          "supplier": {},
408716          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
408717          "name": "strip-outer",
408718          "version": "1.0.1",
408719          "description": "Strip a substring from the start/end of a string",
408720          "licenses": [
408721            {
408722              "license": {
408723                "id": "MIT"
408724              }
408725            }
408726          ],
408727          "cpe": "cpe:2.3:a:strip-outer:strip-outer:1.0.1:*:*:*:*:*:*:*",
408728          "purl": "pkg:npm/strip-outer@1.0.1",
408729          "swid": {
408730            "attachment": {}
408731          },
408732          "pedigree": {},
408733          "externalReferences": [
408734            {
408735              "url": "sindresorhus/strip-outer",
408736              "type": "distribution"
408737            }
408738          ],
408739          "evidence": {},
408740          "signature": {
408741            "signature": {
408742              "publicKey": {}
408743            }
408744          },
408745          "modelCard": {
408746            "modelParameters": {
408747              "approach": {}
408748            },
408749            "quantitativeAnalysis": {
408750              "graphics": {}
408751            },
408752            "considerations": {}
408753          }
408754        },
408755        {
408756          "type": "library",
408757          "bom-ref": "pkg:npm/supports-color@5.5.0?package-id=e67c34f54fe7e8e9",
408758          "supplier": {},
408759          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
408760          "name": "supports-color",
408761          "version": "5.5.0",
408762          "description": "Detect whether a terminal supports color",
408763          "licenses": [
408764            {
408765              "license": {
408766                "id": "MIT"
408767              }
408768            }
408769          ],
408770          "cpe": "cpe:2.3:a:supports-color:supports-color:5.5.0:*:*:*:*:*:*:*",
408771          "purl": "pkg:npm/supports-color@5.5.0",
408772          "swid": {
408773            "attachment": {}
408774          },
408775          "pedigree": {},
408776          "externalReferences": [
408777            {
408778              "url": "chalk/supports-color",
408779              "type": "distribution"
408780            }
408781          ],
408782          "evidence": {},
408783          "signature": {
408784            "signature": {
408785              "publicKey": {}
408786            }
408787          },
408788          "modelCard": {
408789            "modelParameters": {
408790              "approach": {}
408791            },
408792            "quantitativeAnalysis": {
408793              "graphics": {}
408794            },
408795            "considerations": {}
408796          }
408797        },
408798        {
408799          "type": "library",
408800          "bom-ref": "pkg:npm/supports-color@7.2.0?package-id=4c97deb16c788c95",
408801          "supplier": {},
408802          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
408803          "name": "supports-color",
408804          "version": "7.2.0",
408805          "description": "Detect whether a terminal supports color",
408806          "licenses": [
408807            {
408808              "license": {
408809                "id": "MIT"
408810              }
408811            }
408812          ],
408813          "cpe": "cpe:2.3:a:supports-color:supports-color:7.2.0:*:*:*:*:*:*:*",
408814          "purl": "pkg:npm/supports-color@7.2.0",
408815          "swid": {
408816            "attachment": {}
408817          },
408818          "pedigree": {},
408819          "externalReferences": [
408820            {
408821              "url": "chalk/supports-color",
408822              "type": "distribution"
408823            }
408824          ],
408825          "evidence": {},
408826          "signature": {
408827            "signature": {
408828              "publicKey": {}
408829            }
408830          },
408831          "modelCard": {
408832            "modelParameters": {
408833              "approach": {}
408834            },
408835            "quantitativeAnalysis": {
408836              "graphics": {}
408837            },
408838            "considerations": {}
408839          }
408840        },
408841        {
408842          "type": "library",
408843          "bom-ref": "pkg:npm/supports-color@7.2.0?package-id=57e1d80233ac0806",
408844          "supplier": {},
408845          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
408846          "name": "supports-color",
408847          "version": "7.2.0",
408848          "description": "Detect whether a terminal supports color",
408849          "licenses": [
408850            {
408851              "license": {
408852                "id": "MIT"
408853              }
408854            }
408855          ],
408856          "cpe": "cpe:2.3:a:supports-color:supports-color:7.2.0:*:*:*:*:*:*:*",
408857          "purl": "pkg:npm/supports-color@7.2.0",
408858          "swid": {
408859            "attachment": {}
408860          },
408861          "pedigree": {},
408862          "externalReferences": [
408863            {
408864              "url": "chalk/supports-color",
408865              "type": "distribution"
408866            }
408867          ],
408868          "evidence": {},
408869          "signature": {
408870            "signature": {
408871              "publicKey": {}
408872            }
408873          },
408874          "modelCard": {
408875            "modelParameters": {
408876              "approach": {}
408877            },
408878            "quantitativeAnalysis": {
408879              "graphics": {}
408880            },
408881            "considerations": {}
408882          }
408883        },
408884        {
408885          "type": "library",
408886          "bom-ref": "pkg:npm/tapable@2.2.1?package-id=557f604395186028",
408887          "supplier": {},
408888          "author": "Tobias Koppers @sokra",
408889          "name": "tapable",
408890          "version": "2.2.1",
408891          "description": "Just a little module for plugins.",
408892          "licenses": [
408893            {
408894              "license": {
408895                "id": "MIT"
408896              }
408897            }
408898          ],
408899          "cpe": "cpe:2.3:a:tapable:tapable:2.2.1:*:*:*:*:*:*:*",
408900          "purl": "pkg:npm/tapable@2.2.1",
408901          "swid": {
408902            "attachment": {}
408903          },
408904          "pedigree": {},
408905          "externalReferences": [
408906            {
408907              "url": "http://github.com/webpack/tapable.git",
408908              "type": "distribution"
408909            },
408910            {
408911              "url": "https://github.com/webpack/tapable",
408912              "type": "website"
408913            }
408914          ],
408915          "evidence": {},
408916          "signature": {
408917            "signature": {
408918              "publicKey": {}
408919            }
408920          },
408921          "modelCard": {
408922            "modelParameters": {
408923              "approach": {}
408924            },
408925            "quantitativeAnalysis": {
408926              "graphics": {}
408927            },
408928            "considerations": {}
408929          }
408930        },
408931        {
408932          "type": "library",
408933          "bom-ref": "pkg:npm/tar@5.0.11?package-id=d8c4bfab58684e14",
408934          "supplier": {},
408935          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
408936          "name": "tar",
408937          "version": "5.0.11",
408938          "description": "tar for node",
408939          "licenses": [
408940            {
408941              "license": {
408942                "id": "ISC"
408943              }
408944            }
408945          ],
408946          "cpe": "cpe:2.3:a:npm:tar:5.0.11:*:*:*:*:*:*:*",
408947          "purl": "pkg:npm/tar@5.0.11",
408948          "swid": {
408949            "attachment": {}
408950          },
408951          "pedigree": {},
408952          "externalReferences": [
408953            {
408954              "url": "https://github.com/npm/node-tar.git",
408955              "type": "distribution"
408956            }
408957          ],
408958          "evidence": {},
408959          "signature": {
408960            "signature": {
408961              "publicKey": {}
408962            }
408963          },
408964          "modelCard": {
408965            "modelParameters": {
408966              "approach": {}
408967            },
408968            "quantitativeAnalysis": {
408969              "graphics": {}
408970            },
408971            "considerations": {}
408972          }
408973        },
408974        {
408975          "type": "library",
408976          "bom-ref": "pkg:npm/tar@6.1.11?package-id=97823590d9da9c9f",
408977          "supplier": {},
408978          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
408979          "name": "tar",
408980          "version": "6.1.11",
408981          "description": "tar for node",
408982          "licenses": [
408983            {
408984              "license": {
408985                "id": "ISC"
408986              }
408987            }
408988          ],
408989          "cpe": "cpe:2.3:a:npm:tar:6.1.11:*:*:*:*:*:*:*",
408990          "purl": "pkg:npm/tar@6.1.11",
408991          "swid": {
408992            "attachment": {}
408993          },
408994          "pedigree": {},
408995          "externalReferences": [
408996            {
408997              "url": "https://github.com/npm/node-tar.git",
408998              "type": "distribution"
408999            }
409000          ],
409001          "evidence": {},
409002          "signature": {
409003            "signature": {
409004              "publicKey": {}
409005            }
409006          },
409007          "modelCard": {
409008            "modelParameters": {
409009              "approach": {}
409010            },
409011            "quantitativeAnalysis": {
409012              "graphics": {}
409013            },
409014            "considerations": {}
409015          }
409016        },
409017        {
409018          "type": "library",
409019          "bom-ref": "pkg:npm/tar-stream@1.6.2?package-id=b349b53b8a0b6db3",
409020          "supplier": {},
409021          "author": "Mathias Buus \u003cmathiasbuus@gmail.com\u003e",
409022          "name": "tar-stream",
409023          "version": "1.6.2",
409024          "description": "tar-stream is a streaming tar parser and generator and nothing else. It is streams2 and operates purely using streams which means you can easily extract/parse tarballs without ever hitting the file system.",
409025          "licenses": [
409026            {
409027              "license": {
409028                "id": "MIT"
409029              }
409030            }
409031          ],
409032          "cpe": "cpe:2.3:a:tar-stream:tar-stream:1.6.2:*:*:*:*:*:*:*",
409033          "purl": "pkg:npm/tar-stream@1.6.2",
409034          "swid": {
409035            "attachment": {}
409036          },
409037          "pedigree": {},
409038          "externalReferences": [
409039            {
409040              "url": "git+https://github.com/mafintosh/tar-stream.git",
409041              "type": "distribution"
409042            },
409043            {
409044              "url": "https://github.com/mafintosh/tar-stream",
409045              "type": "website"
409046            }
409047          ],
409048          "evidence": {},
409049          "signature": {
409050            "signature": {
409051              "publicKey": {}
409052            }
409053          },
409054          "modelCard": {
409055            "modelParameters": {
409056              "approach": {}
409057            },
409058            "quantitativeAnalysis": {
409059              "graphics": {}
409060            },
409061            "considerations": {}
409062          }
409063        },
409064        {
409065          "type": "library",
409066          "bom-ref": "pkg:npm/text-table@0.2.0?package-id=a124be9ad599668f",
409067          "supplier": {},
409068          "author": "James Halliday \u003cmail@substack.net\u003e (http://substack.net)",
409069          "name": "text-table",
409070          "version": "0.2.0",
409071          "description": "borderless text tables with alignment",
409072          "licenses": [
409073            {
409074              "license": {
409075                "id": "MIT"
409076              }
409077            }
409078          ],
409079          "cpe": "cpe:2.3:a:text-table:text-table:0.2.0:*:*:*:*:*:*:*",
409080          "purl": "pkg:npm/text-table@0.2.0",
409081          "swid": {
409082            "attachment": {}
409083          },
409084          "pedigree": {},
409085          "externalReferences": [
409086            {
409087              "url": "git://github.com/substack/text-table.git",
409088              "type": "distribution"
409089            },
409090            {
409091              "url": "https://github.com/substack/text-table",
409092              "type": "website"
409093            }
409094          ],
409095          "evidence": {},
409096          "signature": {
409097            "signature": {
409098              "publicKey": {}
409099            }
409100          },
409101          "modelCard": {
409102            "modelParameters": {
409103              "approach": {}
409104            },
409105            "quantitativeAnalysis": {
409106              "graphics": {}
409107            },
409108            "considerations": {}
409109          }
409110        },
409111        {
409112          "type": "library",
409113          "bom-ref": "pkg:npm/through@2.3.8?package-id=a2952f0a3256848f",
409114          "supplier": {},
409115          "author": "Dominic Tarr \u003cdominic.tarr@gmail.com\u003e (dominictarr.com)",
409116          "name": "through",
409117          "version": "2.3.8",
409118          "description": "simplified stream construction",
409119          "licenses": [
409120            {
409121              "license": {
409122                "id": "MIT"
409123              }
409124            }
409125          ],
409126          "cpe": "cpe:2.3:a:dominictarr:through:2.3.8:*:*:*:*:*:*:*",
409127          "purl": "pkg:npm/through@2.3.8",
409128          "swid": {
409129            "attachment": {}
409130          },
409131          "pedigree": {},
409132          "externalReferences": [
409133            {
409134              "url": "https://github.com/dominictarr/through.git",
409135              "type": "distribution"
409136            },
409137            {
409138              "url": "https://github.com/dominictarr/through",
409139              "type": "website"
409140            }
409141          ],
409142          "evidence": {},
409143          "signature": {
409144            "signature": {
409145              "publicKey": {}
409146            }
409147          },
409148          "modelCard": {
409149            "modelParameters": {
409150              "approach": {}
409151            },
409152            "quantitativeAnalysis": {
409153              "graphics": {}
409154            },
409155            "considerations": {}
409156          }
409157        },
409158        {
409159          "type": "library",
409160          "bom-ref": "pkg:npm/through2@3.0.2?package-id=c9d63645e4d241f4",
409161          "supplier": {},
409162          "author": "Rod Vagg \u003cr@va.gg\u003e (https://github.com/rvagg)",
409163          "name": "through2",
409164          "version": "3.0.2",
409165          "description": "A tiny wrapper around Node.js streams.Transform (Streams2/3) to avoid explicit subclassing noise",
409166          "licenses": [
409167            {
409168              "license": {
409169                "id": "MIT"
409170              }
409171            }
409172          ],
409173          "cpe": "cpe:2.3:a:through2:through2:3.0.2:*:*:*:*:*:*:*",
409174          "purl": "pkg:npm/through2@3.0.2",
409175          "swid": {
409176            "attachment": {}
409177          },
409178          "pedigree": {},
409179          "externalReferences": [
409180            {
409181              "url": "https://github.com/rvagg/through2.git",
409182              "type": "distribution"
409183            }
409184          ],
409185          "evidence": {},
409186          "signature": {
409187            "signature": {
409188              "publicKey": {}
409189            }
409190          },
409191          "modelCard": {
409192            "modelParameters": {
409193              "approach": {}
409194            },
409195            "quantitativeAnalysis": {
409196              "graphics": {}
409197            },
409198            "considerations": {}
409199          }
409200        },
409201        {
409202          "type": "library",
409203          "bom-ref": "pkg:npm/timed-out@4.0.1?package-id=78eb100a1f4df612",
409204          "supplier": {},
409205          "author": "Vsevolod Strukchinsky \u003cfloatdrop@gmail.com\u003e",
409206          "name": "timed-out",
409207          "version": "4.0.1",
409208          "description": "Emit `ETIMEDOUT` or `ESOCKETTIMEDOUT` when ClientRequest is hanged",
409209          "licenses": [
409210            {
409211              "license": {
409212                "id": "MIT"
409213              }
409214            }
409215          ],
409216          "cpe": "cpe:2.3:a:timed-out:timed-out:4.0.1:*:*:*:*:*:*:*",
409217          "purl": "pkg:npm/timed-out@4.0.1",
409218          "swid": {
409219            "attachment": {}
409220          },
409221          "pedigree": {},
409222          "externalReferences": [
409223            {
409224              "url": "floatdrop/timed-out",
409225              "type": "distribution"
409226            }
409227          ],
409228          "evidence": {},
409229          "signature": {
409230            "signature": {
409231              "publicKey": {}
409232            }
409233          },
409234          "modelCard": {
409235            "modelParameters": {
409236              "approach": {}
409237            },
409238            "quantitativeAnalysis": {
409239              "graphics": {}
409240            },
409241            "considerations": {}
409242          }
409243        },
409244        {
409245          "type": "library",
409246          "bom-ref": "pkg:npm/tiny-relative-date@1.3.0?package-id=bc2a707c455ba496",
409247          "supplier": {},
409248          "author": "Joseph Wynn \u003cjoseph@wildlyinaccurate.com\u003e (https://wildlyinaccurate.com/)",
409249          "name": "tiny-relative-date",
409250          "version": "1.3.0",
409251          "description": "Tiny function that provides relative, human-readable dates.",
409252          "licenses": [
409253            {
409254              "license": {
409255                "id": "MIT"
409256              }
409257            }
409258          ],
409259          "cpe": "cpe:2.3:a:tiny-relative-date:tiny-relative-date:1.3.0:*:*:*:*:*:*:*",
409260          "purl": "pkg:npm/tiny-relative-date@1.3.0",
409261          "swid": {
409262            "attachment": {}
409263          },
409264          "pedigree": {},
409265          "externalReferences": [
409266            {
409267              "url": "https://github.com/wildlyinaccurate/relative-date.git",
409268              "type": "distribution"
409269            }
409270          ],
409271          "evidence": {},
409272          "signature": {
409273            "signature": {
409274              "publicKey": {}
409275            }
409276          },
409277          "modelCard": {
409278            "modelParameters": {
409279              "approach": {}
409280            },
409281            "quantitativeAnalysis": {
409282              "graphics": {}
409283            },
409284            "considerations": {}
409285          }
409286        },
409287        {
409288          "type": "library",
409289          "bom-ref": "pkg:npm/tmp@0.0.33?package-id=d8de4e7f32864c74",
409290          "supplier": {},
409291          "author": "KARASZI István \u003cgithub@spam.raszi.hu\u003e (http://raszi.hu/)",
409292          "name": "tmp",
409293          "version": "0.0.33",
409294          "description": "Temporary file and directory creator",
409295          "licenses": [
409296            {
409297              "license": {
409298                "id": "MIT"
409299              }
409300            }
409301          ],
409302          "cpe": "cpe:2.3:a:raszi:tmp:0.0.33:*:*:*:*:*:*:*",
409303          "purl": "pkg:npm/tmp@0.0.33",
409304          "swid": {
409305            "attachment": {}
409306          },
409307          "pedigree": {},
409308          "externalReferences": [
409309            {
409310              "url": "raszi/node-tmp",
409311              "type": "distribution"
409312            },
409313            {
409314              "url": "http://github.com/raszi/node-tmp",
409315              "type": "website"
409316            }
409317          ],
409318          "evidence": {},
409319          "signature": {
409320            "signature": {
409321              "publicKey": {}
409322            }
409323          },
409324          "modelCard": {
409325            "modelParameters": {
409326              "approach": {}
409327            },
409328            "quantitativeAnalysis": {
409329              "graphics": {}
409330            },
409331            "considerations": {}
409332          }
409333        },
409334        {
409335          "type": "library",
409336          "bom-ref": "pkg:npm/to-buffer@1.1.1?package-id=c581811f7e908504",
409337          "supplier": {},
409338          "author": "Mathias Buus (@mafintosh)",
409339          "name": "to-buffer",
409340          "version": "1.1.1",
409341          "description": "Pass in a string, get a buffer back. Pass in a buffer, get the same buffer back",
409342          "licenses": [
409343            {
409344              "license": {
409345                "id": "MIT"
409346              }
409347            }
409348          ],
409349          "cpe": "cpe:2.3:a:mafintosh:to-buffer:1.1.1:*:*:*:*:*:*:*",
409350          "purl": "pkg:npm/to-buffer@1.1.1",
409351          "swid": {
409352            "attachment": {}
409353          },
409354          "pedigree": {},
409355          "externalReferences": [
409356            {
409357              "url": "https://github.com/mafintosh/to-buffer.git",
409358              "type": "distribution"
409359            },
409360            {
409361              "url": "https://github.com/mafintosh/to-buffer",
409362              "type": "website"
409363            }
409364          ],
409365          "evidence": {},
409366          "signature": {
409367            "signature": {
409368              "publicKey": {}
409369            }
409370          },
409371          "modelCard": {
409372            "modelParameters": {
409373              "approach": {}
409374            },
409375            "quantitativeAnalysis": {
409376              "graphics": {}
409377            },
409378            "considerations": {}
409379          }
409380        },
409381        {
409382          "type": "library",
409383          "bom-ref": "pkg:npm/to-regex-range@5.0.1?package-id=74b9975d0f188d7",
409384          "supplier": {},
409385          "author": "Jon Schlinkert (https://github.com/jonschlinkert)",
409386          "name": "to-regex-range",
409387          "version": "5.0.1",
409388          "description": "Pass two numbers, get a regex-compatible source string for matching ranges. Validated against more than 2.78 million test assertions.",
409389          "licenses": [
409390            {
409391              "license": {
409392                "id": "MIT"
409393              }
409394            }
409395          ],
409396          "cpe": "cpe:2.3:a:to-regex-range:to-regex-range:5.0.1:*:*:*:*:*:*:*",
409397          "purl": "pkg:npm/to-regex-range@5.0.1",
409398          "swid": {
409399            "attachment": {}
409400          },
409401          "pedigree": {},
409402          "externalReferences": [
409403            {
409404              "url": "micromatch/to-regex-range",
409405              "type": "distribution"
409406            },
409407            {
409408              "url": "https://github.com/micromatch/to-regex-range",
409409              "type": "website"
409410            }
409411          ],
409412          "evidence": {},
409413          "signature": {
409414            "signature": {
409415              "publicKey": {}
409416            }
409417          },
409418          "modelCard": {
409419            "modelParameters": {
409420              "approach": {}
409421            },
409422            "quantitativeAnalysis": {
409423              "graphics": {}
409424            },
409425            "considerations": {}
409426          }
409427        },
409428        {
409429          "type": "library",
409430          "bom-ref": "pkg:npm/tough-cookie@2.5.0?package-id=a301940673b885ce",
409431          "supplier": {},
409432          "author": "Jeremy Stashewsky \u003cjstash@gmail.com\u003e",
409433          "name": "tough-cookie",
409434          "version": "2.5.0",
409435          "description": "RFC6265 Cookies and Cookie Jar for node.js",
409436          "licenses": [
409437            {
409438              "license": {
409439                "id": "BSD-3-Clause"
409440              }
409441            }
409442          ],
409443          "cpe": "cpe:2.3:a:tough-cookie:tough-cookie:2.5.0:*:*:*:*:*:*:*",
409444          "purl": "pkg:npm/tough-cookie@2.5.0",
409445          "swid": {
409446            "attachment": {}
409447          },
409448          "pedigree": {},
409449          "externalReferences": [
409450            {
409451              "url": "git://github.com/salesforce/tough-cookie.git",
409452              "type": "distribution"
409453            },
409454            {
409455              "url": "https://github.com/salesforce/tough-cookie",
409456              "type": "website"
409457            }
409458          ],
409459          "evidence": {},
409460          "signature": {
409461            "signature": {
409462              "publicKey": {}
409463            }
409464          },
409465          "modelCard": {
409466            "modelParameters": {
409467              "approach": {}
409468            },
409469            "quantitativeAnalysis": {
409470              "graphics": {}
409471            },
409472            "considerations": {}
409473          }
409474        },
409475        {
409476          "type": "library",
409477          "bom-ref": "pkg:npm/treeverse@2.0.0?package-id=283d5c0745aa3ce7",
409478          "supplier": {},
409479          "author": "GitHub Inc.",
409480          "name": "treeverse",
409481          "version": "2.0.0",
409482          "description": "Walk any kind of tree structure depth- or breadth-first. Supports promises and advanced map-reduce operations with a very small API.",
409483          "licenses": [
409484            {
409485              "license": {
409486                "id": "ISC"
409487              }
409488            }
409489          ],
409490          "cpe": "cpe:2.3:a:treeverse:treeverse:2.0.0:*:*:*:*:*:*:*",
409491          "purl": "pkg:npm/treeverse@2.0.0",
409492          "swid": {
409493            "attachment": {}
409494          },
409495          "pedigree": {},
409496          "externalReferences": [
409497            {
409498              "url": "https://github.com/npm/treeverse.git",
409499              "type": "distribution"
409500            }
409501          ],
409502          "evidence": {},
409503          "signature": {
409504            "signature": {
409505              "publicKey": {}
409506            }
409507          },
409508          "modelCard": {
409509            "modelParameters": {
409510              "approach": {}
409511            },
409512            "quantitativeAnalysis": {
409513              "graphics": {}
409514            },
409515            "considerations": {}
409516          }
409517        },
409518        {
409519          "type": "library",
409520          "bom-ref": "pkg:npm/trim-repeated@1.0.0?package-id=3c32de348d4f7827",
409521          "supplier": {},
409522          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
409523          "name": "trim-repeated",
409524          "version": "1.0.0",
409525          "description": "Trim a consecutively repeated substring: foo--bar---baz → foo-bar-baz",
409526          "licenses": [
409527            {
409528              "license": {
409529                "id": "MIT"
409530              }
409531            }
409532          ],
409533          "cpe": "cpe:2.3:a:trim-repeated:trim-repeated:1.0.0:*:*:*:*:*:*:*",
409534          "purl": "pkg:npm/trim-repeated@1.0.0",
409535          "swid": {
409536            "attachment": {}
409537          },
409538          "pedigree": {},
409539          "externalReferences": [
409540            {
409541              "url": "sindresorhus/trim-repeated",
409542              "type": "distribution"
409543            }
409544          ],
409545          "evidence": {},
409546          "signature": {
409547            "signature": {
409548              "publicKey": {}
409549            }
409550          },
409551          "modelCard": {
409552            "modelParameters": {
409553              "approach": {}
409554            },
409555            "quantitativeAnalysis": {
409556              "graphics": {}
409557            },
409558            "considerations": {}
409559          }
409560        },
409561        {
409562          "type": "library",
409563          "bom-ref": "pkg:npm/tunnel-agent@0.6.0?package-id=2bdf83051339ef2c",
409564          "supplier": {},
409565          "author": "Mikeal Rogers \u003cmikeal.rogers@gmail.com\u003e (http://www.futurealoof.com)",
409566          "name": "tunnel-agent",
409567          "version": "0.6.0",
409568          "description": "HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.",
409569          "licenses": [
409570            {
409571              "license": {
409572                "id": "Apache-2.0"
409573              }
409574            }
409575          ],
409576          "cpe": "cpe:2.3:a:tunnel-agent:tunnel-agent:0.6.0:*:*:*:*:*:*:*",
409577          "purl": "pkg:npm/tunnel-agent@0.6.0",
409578          "swid": {
409579            "attachment": {}
409580          },
409581          "pedigree": {},
409582          "externalReferences": [
409583            {
409584              "url": "https://github.com/mikeal/tunnel-agent",
409585              "type": "distribution"
409586            }
409587          ],
409588          "evidence": {},
409589          "signature": {
409590            "signature": {
409591              "publicKey": {}
409592            }
409593          },
409594          "modelCard": {
409595            "modelParameters": {
409596              "approach": {}
409597            },
409598            "quantitativeAnalysis": {
409599              "graphics": {}
409600            },
409601            "considerations": {}
409602          }
409603        },
409604        {
409605          "type": "library",
409606          "bom-ref": "pkg:npm/tweetnacl@0.14.5?package-id=70ac65ccc05f56fb",
409607          "supplier": {},
409608          "author": "TweetNaCl-js contributors",
409609          "name": "tweetnacl",
409610          "version": "0.14.5",
409611          "description": "Port of TweetNaCl cryptographic library to JavaScript",
409612          "licenses": [
409613            {
409614              "license": {
409615                "id": "Unlicense"
409616              }
409617            }
409618          ],
409619          "cpe": "cpe:2.3:a:tweetnacl:tweetnacl:0.14.5:*:*:*:*:*:*:*",
409620          "purl": "pkg:npm/tweetnacl@0.14.5",
409621          "swid": {
409622            "attachment": {}
409623          },
409624          "pedigree": {},
409625          "externalReferences": [
409626            {
409627              "url": "https://github.com/dchest/tweetnacl-js.git",
409628              "type": "distribution"
409629            },
409630            {
409631              "url": "https://tweetnacl.js.org",
409632              "type": "website"
409633            }
409634          ],
409635          "evidence": {},
409636          "signature": {
409637            "signature": {
409638              "publicKey": {}
409639            }
409640          },
409641          "modelCard": {
409642            "modelParameters": {
409643              "approach": {}
409644            },
409645            "quantitativeAnalysis": {
409646              "graphics": {}
409647            },
409648            "considerations": {}
409649          }
409650        },
409651        {
409652          "type": "library",
409653          "bom-ref": "pkg:npm/type-is@1.6.18?package-id=5bdf50fc9a89514f",
409654          "supplier": {},
409655          "name": "type-is",
409656          "version": "1.6.18",
409657          "description": "Infer the content-type of a request.",
409658          "licenses": [
409659            {
409660              "license": {
409661                "id": "MIT"
409662              }
409663            }
409664          ],
409665          "cpe": "cpe:2.3:a:type-is:type-is:1.6.18:*:*:*:*:*:*:*",
409666          "purl": "pkg:npm/type-is@1.6.18",
409667          "swid": {
409668            "attachment": {}
409669          },
409670          "pedigree": {},
409671          "externalReferences": [
409672            {
409673              "url": "jshttp/type-is",
409674              "type": "distribution"
409675            }
409676          ],
409677          "evidence": {},
409678          "signature": {
409679            "signature": {
409680              "publicKey": {}
409681            }
409682          },
409683          "modelCard": {
409684            "modelParameters": {
409685              "approach": {}
409686            },
409687            "quantitativeAnalysis": {
409688              "graphics": {}
409689            },
409690            "considerations": {}
409691          }
409692        },
409693        {
409694          "type": "library",
409695          "bom-ref": "pkg:npm/unbzip2-stream@1.4.3?package-id=55bae1cfa4fa49",
409696          "supplier": {},
409697          "author": "Jan Bölsche \u003cjan@lagomorph.de\u003e",
409698          "name": "unbzip2-stream",
409699          "version": "1.4.3",
409700          "description": "streaming unbzip2 implementation in pure javascript for node and browsers",
409701          "licenses": [
409702            {
409703              "license": {
409704                "id": "MIT"
409705              }
409706            }
409707          ],
409708          "cpe": "cpe:2.3:a:unbzip2-stream:unbzip2-stream:1.4.3:*:*:*:*:*:*:*",
409709          "purl": "pkg:npm/unbzip2-stream@1.4.3",
409710          "swid": {
409711            "attachment": {}
409712          },
409713          "pedigree": {},
409714          "externalReferences": [
409715            {
409716              "url": "https://github.com/regular/unbzip2-stream.git",
409717              "type": "distribution"
409718            }
409719          ],
409720          "evidence": {},
409721          "signature": {
409722            "signature": {
409723              "publicKey": {}
409724            }
409725          },
409726          "modelCard": {
409727            "modelParameters": {
409728              "approach": {}
409729            },
409730            "quantitativeAnalysis": {
409731              "graphics": {}
409732            },
409733            "considerations": {}
409734          }
409735        },
409736        {
409737          "type": "library",
409738          "bom-ref": "pkg:npm/unique-filename@2.0.1?package-id=ddbea63cf5bc0343",
409739          "supplier": {},
409740          "author": "GitHub Inc.",
409741          "name": "unique-filename",
409742          "version": "2.0.1",
409743          "description": "Generate a unique filename for use in temporary directories or caches.",
409744          "licenses": [
409745            {
409746              "license": {
409747                "id": "ISC"
409748              }
409749            }
409750          ],
409751          "cpe": "cpe:2.3:a:unique-filename:unique-filename:2.0.1:*:*:*:*:*:*:*",
409752          "purl": "pkg:npm/unique-filename@2.0.1",
409753          "swid": {
409754            "attachment": {}
409755          },
409756          "pedigree": {},
409757          "externalReferences": [
409758            {
409759              "url": "https://github.com/npm/unique-filename.git",
409760              "type": "distribution"
409761            },
409762            {
409763              "url": "https://github.com/iarna/unique-filename",
409764              "type": "website"
409765            }
409766          ],
409767          "evidence": {},
409768          "signature": {
409769            "signature": {
409770              "publicKey": {}
409771            }
409772          },
409773          "modelCard": {
409774            "modelParameters": {
409775              "approach": {}
409776            },
409777            "quantitativeAnalysis": {
409778              "graphics": {}
409779            },
409780            "considerations": {}
409781          }
409782        },
409783        {
409784          "type": "library",
409785          "bom-ref": "pkg:npm/unique-slug@3.0.0?package-id=a61e6b90d7850f42",
409786          "supplier": {},
409787          "author": "GitHub Inc.",
409788          "name": "unique-slug",
409789          "version": "3.0.0",
409790          "description": "Generate a unique character string suitible for use in files and URLs.",
409791          "licenses": [
409792            {
409793              "license": {
409794                "id": "ISC"
409795              }
409796            }
409797          ],
409798          "cpe": "cpe:2.3:a:unique-slug:unique-slug:3.0.0:*:*:*:*:*:*:*",
409799          "purl": "pkg:npm/unique-slug@3.0.0",
409800          "swid": {
409801            "attachment": {}
409802          },
409803          "pedigree": {},
409804          "externalReferences": [
409805            {
409806              "url": "https://github.com/npm/unique-slug.git",
409807              "type": "distribution"
409808            }
409809          ],
409810          "evidence": {},
409811          "signature": {
409812            "signature": {
409813              "publicKey": {}
409814            }
409815          },
409816          "modelCard": {
409817            "modelParameters": {
409818              "approach": {}
409819            },
409820            "quantitativeAnalysis": {
409821              "graphics": {}
409822            },
409823            "considerations": {}
409824          }
409825        },
409826        {
409827          "type": "library",
409828          "bom-ref": "pkg:npm/universalify@0.1.2?package-id=69eed8a5747afb4f",
409829          "supplier": {},
409830          "author": "Ryan Zimmerman \u003copensrc@ryanzim.com\u003e",
409831          "name": "universalify",
409832          "version": "0.1.2",
409833          "description": "Make a callback- or promise-based function support both promises and callbacks.",
409834          "licenses": [
409835            {
409836              "license": {
409837                "id": "MIT"
409838              }
409839            }
409840          ],
409841          "cpe": "cpe:2.3:a:universalify:universalify:0.1.2:*:*:*:*:*:*:*",
409842          "purl": "pkg:npm/universalify@0.1.2",
409843          "swid": {
409844            "attachment": {}
409845          },
409846          "pedigree": {},
409847          "externalReferences": [
409848            {
409849              "url": "git+https://github.com/RyanZim/universalify.git",
409850              "type": "distribution"
409851            },
409852            {
409853              "url": "https://github.com/RyanZim/universalify#readme",
409854              "type": "website"
409855            }
409856          ],
409857          "evidence": {},
409858          "signature": {
409859            "signature": {
409860              "publicKey": {}
409861            }
409862          },
409863          "modelCard": {
409864            "modelParameters": {
409865              "approach": {}
409866            },
409867            "quantitativeAnalysis": {
409868              "graphics": {}
409869            },
409870            "considerations": {}
409871          }
409872        },
409873        {
409874          "type": "library",
409875          "bom-ref": "pkg:npm/universalify@2.0.0?package-id=9f53ef5bee7fc181",
409876          "supplier": {},
409877          "author": "Ryan Zimmerman \u003copensrc@ryanzim.com\u003e",
409878          "name": "universalify",
409879          "version": "2.0.0",
409880          "description": "Make a callback- or promise-based function support both promises and callbacks.",
409881          "licenses": [
409882            {
409883              "license": {
409884                "id": "MIT"
409885              }
409886            }
409887          ],
409888          "cpe": "cpe:2.3:a:universalify:universalify:2.0.0:*:*:*:*:*:*:*",
409889          "purl": "pkg:npm/universalify@2.0.0",
409890          "swid": {
409891            "attachment": {}
409892          },
409893          "pedigree": {},
409894          "externalReferences": [
409895            {
409896              "url": "git+https://github.com/RyanZim/universalify.git",
409897              "type": "distribution"
409898            },
409899            {
409900              "url": "https://github.com/RyanZim/universalify#readme",
409901              "type": "website"
409902            }
409903          ],
409904          "evidence": {},
409905          "signature": {
409906            "signature": {
409907              "publicKey": {}
409908            }
409909          },
409910          "modelCard": {
409911            "modelParameters": {
409912              "approach": {}
409913            },
409914            "quantitativeAnalysis": {
409915              "graphics": {}
409916            },
409917            "considerations": {}
409918          }
409919        },
409920        {
409921          "type": "library",
409922          "bom-ref": "pkg:npm/unpipe@1.0.0?package-id=c584cebc0a9824f4",
409923          "supplier": {},
409924          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
409925          "name": "unpipe",
409926          "version": "1.0.0",
409927          "description": "Unpipe a stream from all destinations",
409928          "licenses": [
409929            {
409930              "license": {
409931                "id": "MIT"
409932              }
409933            }
409934          ],
409935          "cpe": "cpe:2.3:a:unpipe:unpipe:1.0.0:*:*:*:*:*:*:*",
409936          "purl": "pkg:npm/unpipe@1.0.0",
409937          "swid": {
409938            "attachment": {}
409939          },
409940          "pedigree": {},
409941          "externalReferences": [
409942            {
409943              "url": "stream-utils/unpipe",
409944              "type": "distribution"
409945            }
409946          ],
409947          "evidence": {},
409948          "signature": {
409949            "signature": {
409950              "publicKey": {}
409951            }
409952          },
409953          "modelCard": {
409954            "modelParameters": {
409955              "approach": {}
409956            },
409957            "quantitativeAnalysis": {
409958              "graphics": {}
409959            },
409960            "considerations": {}
409961          }
409962        },
409963        {
409964          "type": "library",
409965          "bom-ref": "pkg:npm/uri-js@4.4.1?package-id=fe61e3e32f3aaf87",
409966          "supplier": {},
409967          "author": "Gary Court \u003cgary.court@gmail.com\u003e",
409968          "name": "uri-js",
409969          "version": "4.4.1",
409970          "description": "An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.",
409971          "licenses": [
409972            {
409973              "license": {
409974                "id": "BSD-2-Clause"
409975              }
409976            }
409977          ],
409978          "cpe": "cpe:2.3:a:garycourt:uri-js:4.4.1:*:*:*:*:*:*:*",
409979          "purl": "pkg:npm/uri-js@4.4.1",
409980          "swid": {
409981            "attachment": {}
409982          },
409983          "pedigree": {},
409984          "externalReferences": [
409985            {
409986              "url": "http://github.com/garycourt/uri-js",
409987              "type": "distribution"
409988            },
409989            {
409990              "url": "https://github.com/garycourt/uri-js",
409991              "type": "website"
409992            }
409993          ],
409994          "evidence": {},
409995          "signature": {
409996            "signature": {
409997              "publicKey": {}
409998            }
409999          },
410000          "modelCard": {
410001            "modelParameters": {
410002              "approach": {}
410003            },
410004            "quantitativeAnalysis": {
410005              "graphics": {}
410006            },
410007            "considerations": {}
410008          }
410009        },
410010        {
410011          "type": "library",
410012          "bom-ref": "pkg:npm/url-parse-lax@3.0.0?package-id=129b46305833ff3c",
410013          "supplier": {},
410014          "author": "Sindre Sorhus \u003csindresorhus@gmail.com\u003e (sindresorhus.com)",
410015          "name": "url-parse-lax",
410016          "version": "3.0.0",
410017          "description": "Lax url.parse() with support for protocol-less URLs \u0026 IPs",
410018          "licenses": [
410019            {
410020              "license": {
410021                "id": "MIT"
410022              }
410023            }
410024          ],
410025          "cpe": "cpe:2.3:a:url-parse-lax:url-parse-lax:3.0.0:*:*:*:*:*:*:*",
410026          "purl": "pkg:npm/url-parse-lax@3.0.0",
410027          "swid": {
410028            "attachment": {}
410029          },
410030          "pedigree": {},
410031          "externalReferences": [
410032            {
410033              "url": "sindresorhus/url-parse-lax",
410034              "type": "distribution"
410035            }
410036          ],
410037          "evidence": {},
410038          "signature": {
410039            "signature": {
410040              "publicKey": {}
410041            }
410042          },
410043          "modelCard": {
410044            "modelParameters": {
410045              "approach": {}
410046            },
410047            "quantitativeAnalysis": {
410048              "graphics": {}
410049            },
410050            "considerations": {}
410051          }
410052        },
410053        {
410054          "type": "library",
410055          "bom-ref": "pkg:npm/url-to-options@1.0.1?package-id=fd0a02a59bebee03",
410056          "supplier": {},
410057          "author": "Steven Vachon \u003ccontact@svachon.com\u003e (https://www.svachon.com/)",
410058          "name": "url-to-options",
410059          "version": "1.0.1",
410060          "description": "Convert a WHATWG URL to an http(s).request options object.",
410061          "licenses": [
410062            {
410063              "license": {
410064                "id": "MIT"
410065              }
410066            }
410067          ],
410068          "cpe": "cpe:2.3:a:url-to-options:url-to-options:1.0.1:*:*:*:*:*:*:*",
410069          "purl": "pkg:npm/url-to-options@1.0.1",
410070          "swid": {
410071            "attachment": {}
410072          },
410073          "pedigree": {},
410074          "externalReferences": [
410075            {
410076              "url": "stevenvachon/url-to-options",
410077              "type": "distribution"
410078            }
410079          ],
410080          "evidence": {},
410081          "signature": {
410082            "signature": {
410083              "publicKey": {}
410084            }
410085          },
410086          "modelCard": {
410087            "modelParameters": {
410088              "approach": {}
410089            },
410090            "quantitativeAnalysis": {
410091              "graphics": {}
410092            },
410093            "considerations": {}
410094          }
410095        },
410096        {
410097          "type": "library",
410098          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=ecf076cf26fe73d0",
410099          "supplier": {},
410100          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
410101          "name": "util-deprecate",
410102          "version": "1.0.2",
410103          "description": "The Node.js `util.deprecate()` function with browser support",
410104          "licenses": [
410105            {
410106              "license": {
410107                "id": "MIT"
410108              }
410109            }
410110          ],
410111          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
410112          "purl": "pkg:npm/util-deprecate@1.0.2",
410113          "swid": {
410114            "attachment": {}
410115          },
410116          "pedigree": {},
410117          "externalReferences": [
410118            {
410119              "url": "git://github.com/TooTallNate/util-deprecate.git",
410120              "type": "distribution"
410121            },
410122            {
410123              "url": "https://github.com/TooTallNate/util-deprecate",
410124              "type": "website"
410125            }
410126          ],
410127          "evidence": {},
410128          "signature": {
410129            "signature": {
410130              "publicKey": {}
410131            }
410132          },
410133          "modelCard": {
410134            "modelParameters": {
410135              "approach": {}
410136            },
410137            "quantitativeAnalysis": {
410138              "graphics": {}
410139            },
410140            "considerations": {}
410141          }
410142        },
410143        {
410144          "type": "library",
410145          "bom-ref": "pkg:npm/util-deprecate@1.0.2?package-id=78a196ea3de81330",
410146          "supplier": {},
410147          "author": "Nathan Rajlich \u003cnathan@tootallnate.net\u003e (http://n8.io/)",
410148          "name": "util-deprecate",
410149          "version": "1.0.2",
410150          "description": "The Node.js `util.deprecate()` function with browser support",
410151          "licenses": [
410152            {
410153              "license": {
410154                "id": "MIT"
410155              }
410156            }
410157          ],
410158          "cpe": "cpe:2.3:a:util-deprecate:util-deprecate:1.0.2:*:*:*:*:*:*:*",
410159          "purl": "pkg:npm/util-deprecate@1.0.2",
410160          "swid": {
410161            "attachment": {}
410162          },
410163          "pedigree": {},
410164          "externalReferences": [
410165            {
410166              "url": "git://github.com/TooTallNate/util-deprecate.git",
410167              "type": "distribution"
410168            },
410169            {
410170              "url": "https://github.com/TooTallNate/util-deprecate",
410171              "type": "website"
410172            }
410173          ],
410174          "evidence": {},
410175          "signature": {
410176            "signature": {
410177              "publicKey": {}
410178            }
410179          },
410180          "modelCard": {
410181            "modelParameters": {
410182              "approach": {}
410183            },
410184            "quantitativeAnalysis": {
410185              "graphics": {}
410186            },
410187            "considerations": {}
410188          }
410189        },
410190        {
410191          "type": "library",
410192          "bom-ref": "pkg:npm/utils-merge@1.0.1?package-id=62471f9f4fe7cedd",
410193          "supplier": {},
410194          "author": "Jared Hanson \u003cjaredhanson@gmail.com\u003e (http://www.jaredhanson.net/)",
410195          "name": "utils-merge",
410196          "version": "1.0.1",
410197          "description": "merge() utility function",
410198          "licenses": [
410199            {
410200              "license": {
410201                "id": "MIT"
410202              }
410203            }
410204          ],
410205          "cpe": "cpe:2.3:a:jaredhanson:utils-merge:1.0.1:*:*:*:*:*:*:*",
410206          "purl": "pkg:npm/utils-merge@1.0.1",
410207          "swid": {
410208            "attachment": {}
410209          },
410210          "pedigree": {},
410211          "externalReferences": [
410212            {
410213              "url": "git://github.com/jaredhanson/utils-merge.git",
410214              "type": "distribution"
410215            }
410216          ],
410217          "evidence": {},
410218          "signature": {
410219            "signature": {
410220              "publicKey": {}
410221            }
410222          },
410223          "modelCard": {
410224            "modelParameters": {
410225              "approach": {}
410226            },
410227            "quantitativeAnalysis": {
410228              "graphics": {}
410229            },
410230            "considerations": {}
410231          }
410232        },
410233        {
410234          "type": "library",
410235          "bom-ref": "pkg:npm/uuid@3.4.0?package-id=3a7981c4b1d9183e",
410236          "supplier": {},
410237          "name": "uuid",
410238          "version": "3.4.0",
410239          "description": "RFC4122 (v1, v4, and v5) UUIDs",
410240          "licenses": [
410241            {
410242              "license": {
410243                "id": "MIT"
410244              }
410245            }
410246          ],
410247          "cpe": "cpe:2.3:a:uuidjs:uuid:3.4.0:*:*:*:*:*:*:*",
410248          "purl": "pkg:npm/uuid@3.4.0",
410249          "swid": {
410250            "attachment": {}
410251          },
410252          "pedigree": {},
410253          "externalReferences": [
410254            {
410255              "url": "https://github.com/uuidjs/uuid.git",
410256              "type": "distribution"
410257            }
410258          ],
410259          "evidence": {},
410260          "signature": {
410261            "signature": {
410262              "publicKey": {}
410263            }
410264          },
410265          "modelCard": {
410266            "modelParameters": {
410267              "approach": {}
410268            },
410269            "quantitativeAnalysis": {
410270              "graphics": {}
410271            },
410272            "considerations": {}
410273          }
410274        },
410275        {
410276          "type": "library",
410277          "bom-ref": "pkg:npm/validate-npm-package-license@3.0.4?package-id=fa90b625ec15ead",
410278          "supplier": {},
410279          "author": "Kyle E. Mitchell \u003ckyle@kemitchell.com\u003e (https://kemitchell.com)",
410280          "name": "validate-npm-package-license",
410281          "version": "3.0.4",
410282          "description": "Give me a string and I'll tell you if it's a valid npm package license string",
410283          "licenses": [
410284            {
410285              "license": {
410286                "id": "Apache-2.0"
410287              }
410288            }
410289          ],
410290          "cpe": "cpe:2.3:a:validate-npm-package-license:validate-npm-package-license:3.0.4:*:*:*:*:*:*:*",
410291          "purl": "pkg:npm/validate-npm-package-license@3.0.4",
410292          "swid": {
410293            "attachment": {}
410294          },
410295          "pedigree": {},
410296          "externalReferences": [
410297            {
410298              "url": "kemitchell/validate-npm-package-license.js",
410299              "type": "distribution"
410300            }
410301          ],
410302          "evidence": {},
410303          "signature": {
410304            "signature": {
410305              "publicKey": {}
410306            }
410307          },
410308          "modelCard": {
410309            "modelParameters": {
410310              "approach": {}
410311            },
410312            "quantitativeAnalysis": {
410313              "graphics": {}
410314            },
410315            "considerations": {}
410316          }
410317        },
410318        {
410319          "type": "library",
410320          "bom-ref": "pkg:npm/validate-npm-package-name@4.0.0?package-id=dc3a9f2b7a700330",
410321          "supplier": {},
410322          "author": "GitHub Inc.",
410323          "name": "validate-npm-package-name",
410324          "version": "4.0.0",
410325          "description": "Give me a string and I'll tell you if it's a valid npm package name",
410326          "licenses": [
410327            {
410328              "license": {
410329                "id": "ISC"
410330              }
410331            }
410332          ],
410333          "cpe": "cpe:2.3:a:validate-npm-package-name:validate-npm-package-name:4.0.0:*:*:*:*:*:*:*",
410334          "purl": "pkg:npm/validate-npm-package-name@4.0.0",
410335          "swid": {
410336            "attachment": {}
410337          },
410338          "pedigree": {},
410339          "externalReferences": [
410340            {
410341              "url": "https://github.com/npm/validate-npm-package-name.git",
410342              "type": "distribution"
410343            },
410344            {
410345              "url": "https://github.com/npm/validate-npm-package-name",
410346              "type": "website"
410347            }
410348          ],
410349          "evidence": {},
410350          "signature": {
410351            "signature": {
410352              "publicKey": {}
410353            }
410354          },
410355          "modelCard": {
410356            "modelParameters": {
410357              "approach": {}
410358            },
410359            "quantitativeAnalysis": {
410360              "graphics": {}
410361            },
410362            "considerations": {}
410363          }
410364        },
410365        {
410366          "type": "library",
410367          "bom-ref": "pkg:npm/vary@1.1.2?package-id=7021c84ca0665099",
410368          "supplier": {},
410369          "author": "Douglas Christopher Wilson \u003cdoug@somethingdoug.com\u003e",
410370          "name": "vary",
410371          "version": "1.1.2",
410372          "description": "Manipulate the HTTP Vary header",
410373          "licenses": [
410374            {
410375              "license": {
410376                "id": "MIT"
410377              }
410378            }
410379          ],
410380          "cpe": "cpe:2.3:a:vary:vary:1.1.2:*:*:*:*:*:*:*",
410381          "purl": "pkg:npm/vary@1.1.2",
410382          "swid": {
410383            "attachment": {}
410384          },
410385          "pedigree": {},
410386          "externalReferences": [
410387            {
410388              "url": "jshttp/vary",
410389              "type": "distribution"
410390            }
410391          ],
410392          "evidence": {},
410393          "signature": {
410394            "signature": {
410395              "publicKey": {}
410396            }
410397          },
410398          "modelCard": {
410399            "modelParameters": {
410400              "approach": {}
410401            },
410402            "quantitativeAnalysis": {
410403              "graphics": {}
410404            },
410405            "considerations": {}
410406          }
410407        },
410408        {
410409          "type": "library",
410410          "bom-ref": "pkg:npm/verror@1.10.0?package-id=f23f33c383aecb1a",
410411          "supplier": {},
410412          "name": "verror",
410413          "version": "1.10.0",
410414          "description": "richer JavaScript errors",
410415          "licenses": [
410416            {
410417              "license": {
410418                "id": "MIT"
410419              }
410420            }
410421          ],
410422          "cpe": "cpe:2.3:a:davepacheco:verror:1.10.0:*:*:*:*:*:*:*",
410423          "purl": "pkg:npm/verror@1.10.0",
410424          "swid": {
410425            "attachment": {}
410426          },
410427          "pedigree": {},
410428          "externalReferences": [
410429            {
410430              "url": "git://github.com/davepacheco/node-verror.git",
410431              "type": "distribution"
410432            }
410433          ],
410434          "evidence": {},
410435          "signature": {
410436            "signature": {
410437              "publicKey": {}
410438            }
410439          },
410440          "modelCard": {
410441            "modelParameters": {
410442              "approach": {}
410443            },
410444            "quantitativeAnalysis": {
410445              "graphics": {}
410446            },
410447            "considerations": {}
410448          }
410449        },
410450        {
410451          "type": "library",
410452          "bom-ref": "pkg:npm/walk-up-path@1.0.0?package-id=9a8dd6f20b12184f",
410453          "supplier": {},
410454          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (https://izs.me)",
410455          "name": "walk-up-path",
410456          "version": "1.0.0",
410457          "description": "Given a path string, return a generator that walks up the path, emitting each dirname.",
410458          "licenses": [
410459            {
410460              "license": {
410461                "id": "ISC"
410462              }
410463            }
410464          ],
410465          "cpe": "cpe:2.3:a:walk-up-path:walk-up-path:1.0.0:*:*:*:*:*:*:*",
410466          "purl": "pkg:npm/walk-up-path@1.0.0",
410467          "swid": {
410468            "attachment": {}
410469          },
410470          "pedigree": {},
410471          "externalReferences": [
410472            {
410473              "url": "git+https://github.com/isaacs/walk-up-path",
410474              "type": "distribution"
410475            }
410476          ],
410477          "evidence": {},
410478          "signature": {
410479            "signature": {
410480              "publicKey": {}
410481            }
410482          },
410483          "modelCard": {
410484            "modelParameters": {
410485              "approach": {}
410486            },
410487            "quantitativeAnalysis": {
410488              "graphics": {}
410489            },
410490            "considerations": {}
410491          }
410492        },
410493        {
410494          "type": "library",
410495          "bom-ref": "pkg:npm/wcwidth@1.0.1?package-id=ee54c63162090e16",
410496          "supplier": {},
410497          "author": "Tim Oxley",
410498          "name": "wcwidth",
410499          "version": "1.0.1",
410500          "description": "Port of C's wcwidth() and wcswidth()",
410501          "licenses": [
410502            {
410503              "license": {
410504                "id": "MIT"
410505              }
410506            }
410507          ],
410508          "cpe": "cpe:2.3:a:timoxley:wcwidth:1.0.1:*:*:*:*:*:*:*",
410509          "purl": "pkg:npm/wcwidth@1.0.1",
410510          "swid": {
410511            "attachment": {}
410512          },
410513          "pedigree": {},
410514          "externalReferences": [
410515            {
410516              "url": "git+https://github.com/timoxley/wcwidth.git",
410517              "type": "distribution"
410518            },
410519            {
410520              "url": "https://github.com/timoxley/wcwidth#readme",
410521              "type": "website"
410522            }
410523          ],
410524          "evidence": {},
410525          "signature": {
410526            "signature": {
410527              "publicKey": {}
410528            }
410529          },
410530          "modelCard": {
410531            "modelParameters": {
410532              "approach": {}
410533            },
410534            "quantitativeAnalysis": {
410535              "graphics": {}
410536            },
410537            "considerations": {}
410538          }
410539        },
410540        {
410541          "type": "library",
410542          "bom-ref": "pkg:npm/wcwidth@1.0.1?package-id=f26de7df42871fe5",
410543          "supplier": {},
410544          "author": "Tim Oxley",
410545          "name": "wcwidth",
410546          "version": "1.0.1",
410547          "description": "Port of C's wcwidth() and wcswidth()",
410548          "licenses": [
410549            {
410550              "license": {
410551                "id": "MIT"
410552              }
410553            }
410554          ],
410555          "cpe": "cpe:2.3:a:timoxley:wcwidth:1.0.1:*:*:*:*:*:*:*",
410556          "purl": "pkg:npm/wcwidth@1.0.1",
410557          "swid": {
410558            "attachment": {}
410559          },
410560          "pedigree": {},
410561          "externalReferences": [
410562            {
410563              "url": "git+https://github.com/timoxley/wcwidth.git",
410564              "type": "distribution"
410565            },
410566            {
410567              "url": "https://github.com/timoxley/wcwidth#readme",
410568              "type": "website"
410569            }
410570          ],
410571          "evidence": {},
410572          "signature": {
410573            "signature": {
410574              "publicKey": {}
410575            }
410576          },
410577          "modelCard": {
410578            "modelParameters": {
410579              "approach": {}
410580            },
410581            "quantitativeAnalysis": {
410582              "graphics": {}
410583            },
410584            "considerations": {}
410585          }
410586        },
410587        {
410588          "type": "library",
410589          "bom-ref": "pkg:npm/which@1.3.1?package-id=3ae6f30f4f32f3f1",
410590          "supplier": {},
410591          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
410592          "name": "which",
410593          "version": "1.3.1",
410594          "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
410595          "licenses": [
410596            {
410597              "license": {
410598                "id": "ISC"
410599              }
410600            }
410601          ],
410602          "cpe": "cpe:2.3:a:isaacs:which:1.3.1:*:*:*:*:*:*:*",
410603          "purl": "pkg:npm/which@1.3.1",
410604          "swid": {
410605            "attachment": {}
410606          },
410607          "pedigree": {},
410608          "externalReferences": [
410609            {
410610              "url": "git://github.com/isaacs/node-which.git",
410611              "type": "distribution"
410612            }
410613          ],
410614          "evidence": {},
410615          "signature": {
410616            "signature": {
410617              "publicKey": {}
410618            }
410619          },
410620          "modelCard": {
410621            "modelParameters": {
410622              "approach": {}
410623            },
410624            "quantitativeAnalysis": {
410625              "graphics": {}
410626            },
410627            "considerations": {}
410628          }
410629        },
410630        {
410631          "type": "library",
410632          "bom-ref": "pkg:npm/which@2.0.2?package-id=1d2beaa974655b97",
410633          "supplier": {},
410634          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me)",
410635          "name": "which",
410636          "version": "2.0.2",
410637          "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",
410638          "licenses": [
410639            {
410640              "license": {
410641                "id": "ISC"
410642              }
410643            }
410644          ],
410645          "cpe": "cpe:2.3:a:isaacs:which:2.0.2:*:*:*:*:*:*:*",
410646          "purl": "pkg:npm/which@2.0.2",
410647          "swid": {
410648            "attachment": {}
410649          },
410650          "pedigree": {},
410651          "externalReferences": [
410652            {
410653              "url": "git://github.com/isaacs/node-which.git",
410654              "type": "distribution"
410655            }
410656          ],
410657          "evidence": {},
410658          "signature": {
410659            "signature": {
410660              "publicKey": {}
410661            }
410662          },
410663          "modelCard": {
410664            "modelParameters": {
410665              "approach": {}
410666            },
410667            "quantitativeAnalysis": {
410668              "graphics": {}
410669            },
410670            "considerations": {}
410671          }
410672        },
410673        {
410674          "type": "library",
410675          "bom-ref": "pkg:npm/wide-align@1.1.5?package-id=f0bd5200e29a21be",
410676          "supplier": {},
410677          "author": "Rebecca Turner \u003cme@re-becca.org\u003e (http://re-becca.org/)",
410678          "name": "wide-align",
410679          "version": "1.1.5",
410680          "description": "A wide-character aware text alignment function for use on the console or with fixed width fonts.",
410681          "licenses": [
410682            {
410683              "license": {
410684                "id": "ISC"
410685              }
410686            }
410687          ],
410688          "cpe": "cpe:2.3:a:wide-align:wide-align:1.1.5:*:*:*:*:*:*:*",
410689          "purl": "pkg:npm/wide-align@1.1.5",
410690          "swid": {
410691            "attachment": {}
410692          },
410693          "pedigree": {},
410694          "externalReferences": [
410695            {
410696              "url": "https://github.com/iarna/wide-align",
410697              "type": "distribution"
410698            }
410699          ],
410700          "evidence": {},
410701          "signature": {
410702            "signature": {
410703              "publicKey": {}
410704            }
410705          },
410706          "modelCard": {
410707            "modelParameters": {
410708              "approach": {}
410709            },
410710            "quantitativeAnalysis": {
410711              "graphics": {}
410712            },
410713            "considerations": {}
410714          }
410715        },
410716        {
410717          "type": "library",
410718          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=88b7c304022dd8b8",
410719          "supplier": {},
410720          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
410721          "name": "wrappy",
410722          "version": "1.0.2",
410723          "description": "Callback wrapping utility",
410724          "licenses": [
410725            {
410726              "license": {
410727                "id": "ISC"
410728              }
410729            }
410730          ],
410731          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
410732          "purl": "pkg:npm/wrappy@1.0.2",
410733          "swid": {
410734            "attachment": {}
410735          },
410736          "pedigree": {},
410737          "externalReferences": [
410738            {
410739              "url": "https://github.com/npm/wrappy",
410740              "type": "distribution"
410741            },
410742            {
410743              "url": "https://github.com/npm/wrappy",
410744              "type": "website"
410745            }
410746          ],
410747          "evidence": {},
410748          "signature": {
410749            "signature": {
410750              "publicKey": {}
410751            }
410752          },
410753          "modelCard": {
410754            "modelParameters": {
410755              "approach": {}
410756            },
410757            "quantitativeAnalysis": {
410758              "graphics": {}
410759            },
410760            "considerations": {}
410761          }
410762        },
410763        {
410764          "type": "library",
410765          "bom-ref": "pkg:npm/wrappy@1.0.2?package-id=ed5926f6f76e646b",
410766          "supplier": {},
410767          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
410768          "name": "wrappy",
410769          "version": "1.0.2",
410770          "description": "Callback wrapping utility",
410771          "licenses": [
410772            {
410773              "license": {
410774                "id": "ISC"
410775              }
410776            }
410777          ],
410778          "cpe": "cpe:2.3:a:wrappy:wrappy:1.0.2:*:*:*:*:*:*:*",
410779          "purl": "pkg:npm/wrappy@1.0.2",
410780          "swid": {
410781            "attachment": {}
410782          },
410783          "pedigree": {},
410784          "externalReferences": [
410785            {
410786              "url": "https://github.com/npm/wrappy",
410787              "type": "distribution"
410788            },
410789            {
410790              "url": "https://github.com/npm/wrappy",
410791              "type": "website"
410792            }
410793          ],
410794          "evidence": {},
410795          "signature": {
410796            "signature": {
410797              "publicKey": {}
410798            }
410799          },
410800          "modelCard": {
410801            "modelParameters": {
410802              "approach": {}
410803            },
410804            "quantitativeAnalysis": {
410805              "graphics": {}
410806            },
410807            "considerations": {}
410808          }
410809        },
410810        {
410811          "type": "library",
410812          "bom-ref": "pkg:npm/write-file-atomic@4.0.2?package-id=401a0baef0d4f8db",
410813          "supplier": {},
410814          "author": "GitHub Inc.",
410815          "name": "write-file-atomic",
410816          "version": "4.0.2",
410817          "description": "Write files in an atomic fashion w/configurable ownership",
410818          "licenses": [
410819            {
410820              "license": {
410821                "id": "ISC"
410822              }
410823            }
410824          ],
410825          "cpe": "cpe:2.3:a:write-file-atomic:write-file-atomic:4.0.2:*:*:*:*:*:*:*",
410826          "purl": "pkg:npm/write-file-atomic@4.0.2",
410827          "swid": {
410828            "attachment": {}
410829          },
410830          "pedigree": {},
410831          "externalReferences": [
410832            {
410833              "url": "https://github.com/npm/write-file-atomic.git",
410834              "type": "distribution"
410835            },
410836            {
410837              "url": "https://github.com/npm/write-file-atomic",
410838              "type": "website"
410839            }
410840          ],
410841          "evidence": {},
410842          "signature": {
410843            "signature": {
410844              "publicKey": {}
410845            }
410846          },
410847          "modelCard": {
410848            "modelParameters": {
410849              "approach": {}
410850            },
410851            "quantitativeAnalysis": {
410852              "graphics": {}
410853            },
410854            "considerations": {}
410855          }
410856        },
410857        {
410858          "type": "library",
410859          "bom-ref": "pkg:npm/xml@1.0.1?package-id=e28f883b3dca5ec8",
410860          "supplier": {},
410861          "author": "Dylan Greene (https://github.com/dylang)",
410862          "name": "xml",
410863          "version": "1.0.1",
410864          "description": "Fast and simple xml generator. Supports attributes, CDATA, etc. Includes tests and examples.",
410865          "licenses": [
410866            {
410867              "license": {
410868                "id": "MIT"
410869              }
410870            }
410871          ],
410872          "cpe": "cpe:2.3:a:dylang:xml:1.0.1:*:*:*:*:*:*:*",
410873          "purl": "pkg:npm/xml@1.0.1",
410874          "swid": {
410875            "attachment": {}
410876          },
410877          "pedigree": {},
410878          "externalReferences": [
410879            {
410880              "url": "http://github.com/dylang/node-xml",
410881              "type": "distribution"
410882            },
410883            {
410884              "url": "http://github.com/dylang/node-xml",
410885              "type": "website"
410886            }
410887          ],
410888          "evidence": {},
410889          "signature": {
410890            "signature": {
410891              "publicKey": {}
410892            }
410893          },
410894          "modelCard": {
410895            "modelParameters": {
410896              "approach": {}
410897            },
410898            "quantitativeAnalysis": {
410899              "graphics": {}
410900            },
410901            "considerations": {}
410902          }
410903        },
410904        {
410905          "type": "library",
410906          "bom-ref": "pkg:npm/xml2js@0.4.23?package-id=cea6836bf65243ea",
410907          "supplier": {},
410908          "author": "Marek Kubica \u003cmarek@xivilization.net\u003e (https://xivilization.net)",
410909          "name": "xml2js",
410910          "version": "0.4.23",
410911          "description": "Simple XML to JavaScript object converter.",
410912          "licenses": [
410913            {
410914              "license": {
410915                "id": "MIT"
410916              }
410917            }
410918          ],
410919          "cpe": "cpe:2.3:a:Leonidas-from-XIV:xml2js:0.4.23:*:*:*:*:*:*:*",
410920          "purl": "pkg:npm/xml2js@0.4.23",
410921          "swid": {
410922            "attachment": {}
410923          },
410924          "pedigree": {},
410925          "externalReferences": [
410926            {
410927              "url": "https://github.com/Leonidas-from-XIV/node-xml2js.git",
410928              "type": "distribution"
410929            },
410930            {
410931              "url": "https://github.com/Leonidas-from-XIV/node-xml2js",
410932              "type": "website"
410933            }
410934          ],
410935          "evidence": {},
410936          "signature": {
410937            "signature": {
410938              "publicKey": {}
410939            }
410940          },
410941          "modelCard": {
410942            "modelParameters": {
410943              "approach": {}
410944            },
410945            "quantitativeAnalysis": {
410946              "graphics": {}
410947            },
410948            "considerations": {}
410949          }
410950        },
410951        {
410952          "type": "library",
410953          "bom-ref": "pkg:npm/xmlbuilder@11.0.1?package-id=b2ed598d8a366a07",
410954          "supplier": {},
410955          "author": "Ozgur Ozcitak \u003coozcitak@gmail.com\u003e",
410956          "name": "xmlbuilder",
410957          "version": "11.0.1",
410958          "description": "An XML builder for node.js",
410959          "licenses": [
410960            {
410961              "license": {
410962                "id": "MIT"
410963              }
410964            }
410965          ],
410966          "cpe": "cpe:2.3:a:xmlbuilder:xmlbuilder:11.0.1:*:*:*:*:*:*:*",
410967          "purl": "pkg:npm/xmlbuilder@11.0.1",
410968          "swid": {
410969            "attachment": {}
410970          },
410971          "pedigree": {},
410972          "externalReferences": [
410973            {
410974              "url": "git://github.com/oozcitak/xmlbuilder-js.git",
410975              "type": "distribution"
410976            },
410977            {
410978              "url": "http://github.com/oozcitak/xmlbuilder-js",
410979              "type": "website"
410980            }
410981          ],
410982          "evidence": {},
410983          "signature": {
410984            "signature": {
410985              "publicKey": {}
410986            }
410987          },
410988          "modelCard": {
410989            "modelParameters": {
410990              "approach": {}
410991            },
410992            "quantitativeAnalysis": {
410993              "graphics": {}
410994            },
410995            "considerations": {}
410996          }
410997        },
410998        {
410999          "type": "library",
411000          "bom-ref": "pkg:npm/xtend@4.0.2?package-id=76ce0b8cd490aa12",
411001          "supplier": {},
411002          "author": "Raynos \u003craynos2@gmail.com\u003e",
411003          "name": "xtend",
411004          "version": "4.0.2",
411005          "description": "extend like a boss",
411006          "licenses": [
411007            {
411008              "license": {
411009                "id": "MIT"
411010              }
411011            }
411012          ],
411013          "cpe": "cpe:2.3:a:Raynos:xtend:4.0.2:*:*:*:*:*:*:*",
411014          "purl": "pkg:npm/xtend@4.0.2",
411015          "swid": {
411016            "attachment": {}
411017          },
411018          "pedigree": {},
411019          "externalReferences": [
411020            {
411021              "url": "git://github.com/Raynos/xtend.git",
411022              "type": "distribution"
411023            },
411024            {
411025              "url": "https://github.com/Raynos/xtend",
411026              "type": "website"
411027            }
411028          ],
411029          "evidence": {},
411030          "signature": {
411031            "signature": {
411032              "publicKey": {}
411033            }
411034          },
411035          "modelCard": {
411036            "modelParameters": {
411037              "approach": {}
411038            },
411039            "quantitativeAnalysis": {
411040              "graphics": {}
411041            },
411042            "considerations": {}
411043          }
411044        },
411045        {
411046          "type": "library",
411047          "bom-ref": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.5\u0026package-id=168e14fa822d49a0",
411048          "supplier": {},
411049          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
411050          "name": "xz-libs",
411051          "version": "5.2.5-r1",
411052          "description": "Library and CLI tools for XZ and LZMA compressed files (libraries)",
411053          "licenses": [
411054            {
411055              "license": {
411056                "id": "GPL-2.0-or-later"
411057              }
411058            },
411059            {
411060              "license": {
411061                "name": "AND"
411062              }
411063            },
411064            {
411065              "license": {
411066                "name": "Public-Domain"
411067              }
411068            },
411069            {
411070              "license": {
411071                "name": "AND"
411072              }
411073            },
411074            {
411075              "license": {
411076                "id": "LGPL-2.1-or-later"
411077              }
411078            }
411079          ],
411080          "cpe": "cpe:2.3:a:xz-libs:xz-libs:5.2.5-r1:*:*:*:*:*:*:*",
411081          "purl": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.5",
411082          "swid": {
411083            "attachment": {}
411084          },
411085          "pedigree": {},
411086          "externalReferences": [
411087            {
411088              "url": "https://tukaani.org/xz",
411089              "type": "distribution"
411090            }
411091          ],
411092          "evidence": {},
411093          "signature": {
411094            "signature": {
411095              "publicKey": {}
411096            }
411097          },
411098          "modelCard": {
411099            "modelParameters": {
411100              "approach": {}
411101            },
411102            "quantitativeAnalysis": {
411103              "graphics": {}
411104            },
411105            "considerations": {}
411106          }
411107        },
411108        {
411109          "type": "library",
411110          "bom-ref": "pkg:npm/yallist@4.0.0?package-id=c5b3d2829d8d6201",
411111          "supplier": {},
411112          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
411113          "name": "yallist",
411114          "version": "4.0.0",
411115          "description": "Yet Another Linked List",
411116          "licenses": [
411117            {
411118              "license": {
411119                "id": "ISC"
411120              }
411121            }
411122          ],
411123          "cpe": "cpe:2.3:a:yallist:yallist:4.0.0:*:*:*:*:*:*:*",
411124          "purl": "pkg:npm/yallist@4.0.0",
411125          "swid": {
411126            "attachment": {}
411127          },
411128          "pedigree": {},
411129          "externalReferences": [
411130            {
411131              "url": "git+https://github.com/isaacs/yallist.git",
411132              "type": "distribution"
411133            }
411134          ],
411135          "evidence": {},
411136          "signature": {
411137            "signature": {
411138              "publicKey": {}
411139            }
411140          },
411141          "modelCard": {
411142            "modelParameters": {
411143              "approach": {}
411144            },
411145            "quantitativeAnalysis": {
411146              "graphics": {}
411147            },
411148            "considerations": {}
411149          }
411150        },
411151        {
411152          "type": "library",
411153          "bom-ref": "pkg:npm/yallist@4.0.0?package-id=962f7b1d680d2d52",
411154          "supplier": {},
411155          "author": "Isaac Z. Schlueter \u003ci@izs.me\u003e (http://blog.izs.me/)",
411156          "name": "yallist",
411157          "version": "4.0.0",
411158          "description": "Yet Another Linked List",
411159          "licenses": [
411160            {
411161              "license": {
411162                "id": "ISC"
411163              }
411164            }
411165          ],
411166          "cpe": "cpe:2.3:a:yallist:yallist:4.0.0:*:*:*:*:*:*:*",
411167          "purl": "pkg:npm/yallist@4.0.0",
411168          "swid": {
411169            "attachment": {}
411170          },
411171          "pedigree": {},
411172          "externalReferences": [
411173            {
411174              "url": "git+https://github.com/isaacs/yallist.git",
411175              "type": "distribution"
411176            }
411177          ],
411178          "evidence": {},
411179          "signature": {
411180            "signature": {
411181              "publicKey": {}
411182            }
411183          },
411184          "modelCard": {
411185            "modelParameters": {
411186              "approach": {}
411187            },
411188            "quantitativeAnalysis": {
411189              "graphics": {}
411190            },
411191            "considerations": {}
411192          }
411193        },
411194        {
411195          "type": "library",
411196          "bom-ref": "pkg:npm/yaml@1.10.2?package-id=96fb931c6a8daa33",
411197          "supplier": {},
411198          "author": "Eemeli Aro \u003ceemeli@gmail.com\u003e",
411199          "name": "yaml",
411200          "version": "1.10.2",
411201          "description": "JavaScript parser and stringifier for YAML",
411202          "licenses": [
411203            {
411204              "license": {
411205                "id": "ISC"
411206              }
411207            }
411208          ],
411209          "cpe": "cpe:2.3:a:yaml:yaml:1.10.2:*:*:*:*:*:*:*",
411210          "purl": "pkg:npm/yaml@1.10.2",
411211          "swid": {
411212            "attachment": {}
411213          },
411214          "pedigree": {},
411215          "externalReferences": [
411216            {
411217              "url": "github:eemeli/yaml",
411218              "type": "distribution"
411219            },
411220            {
411221              "url": "https://eemeli.org/yaml/v1/",
411222              "type": "website"
411223            }
411224          ],
411225          "evidence": {},
411226          "signature": {
411227            "signature": {
411228              "publicKey": {}
411229            }
411230          },
411231          "modelCard": {
411232            "modelParameters": {
411233              "approach": {}
411234            },
411235            "quantitativeAnalysis": {
411236              "graphics": {}
411237            },
411238            "considerations": {}
411239          }
411240        },
411241        {
411242          "type": "library",
411243          "bom-ref": "pkg:npm/yarn@1.22.19?package-id=f2b974a78000b26b",
411244          "supplier": {},
411245          "name": "yarn",
411246          "version": "1.22.19",
411247          "description": "📦🐈 Fast, reliable, and secure dependency management.",
411248          "licenses": [
411249            {
411250              "license": {
411251                "id": "BSD-2-Clause"
411252              }
411253            }
411254          ],
411255          "cpe": "cpe:2.3:a:yarn:yarn:1.22.19:*:*:*:*:*:*:*",
411256          "purl": "pkg:npm/yarn@1.22.19",
411257          "swid": {
411258            "attachment": {}
411259          },
411260          "pedigree": {},
411261          "externalReferences": [
411262            {
411263              "url": "yarnpkg/yarn",
411264              "type": "distribution"
411265            }
411266          ],
411267          "evidence": {},
411268          "signature": {
411269            "signature": {
411270              "publicKey": {}
411271            }
411272          },
411273          "modelCard": {
411274            "modelParameters": {
411275              "approach": {}
411276            },
411277            "quantitativeAnalysis": {
411278              "graphics": {}
411279            },
411280            "considerations": {}
411281          }
411282        },
411283        {
411284          "type": "library",
411285          "bom-ref": "pkg:npm/yauzl@2.10.0?package-id=70e81172e3165464",
411286          "supplier": {},
411287          "author": "Josh Wolfe \u003cthejoshwolfe@gmail.com\u003e",
411288          "name": "yauzl",
411289          "version": "2.10.0",
411290          "description": "yet another unzip library for node",
411291          "licenses": [
411292            {
411293              "license": {
411294                "id": "MIT"
411295              }
411296            }
411297          ],
411298          "cpe": "cpe:2.3:a:thejoshwolfe:yauzl:2.10.0:*:*:*:*:*:*:*",
411299          "purl": "pkg:npm/yauzl@2.10.0",
411300          "swid": {
411301            "attachment": {}
411302          },
411303          "pedigree": {},
411304          "externalReferences": [
411305            {
411306              "url": "https://github.com/thejoshwolfe/yauzl.git",
411307              "type": "distribution"
411308            },
411309            {
411310              "url": "https://github.com/thejoshwolfe/yauzl",
411311              "type": "website"
411312            }
411313          ],
411314          "evidence": {},
411315          "signature": {
411316            "signature": {
411317              "publicKey": {}
411318            }
411319          },
411320          "modelCard": {
411321            "modelParameters": {
411322              "approach": {}
411323            },
411324            "quantitativeAnalysis": {
411325              "graphics": {}
411326            },
411327            "considerations": {}
411328          }
411329        },
411330        {
411331          "type": "library",
411332          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=75f0d92f695b4303",
411333          "supplier": {},
411334          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
411335          "name": "zlib",
411336          "version": "1.2.12-r3",
411337          "description": "A compression/decompression Library",
411338          "licenses": [
411339            {
411340              "license": {
411341                "id": "Zlib"
411342              }
411343            }
411344          ],
411345          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
411346          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5",
411347          "swid": {
411348            "attachment": {}
411349          },
411350          "pedigree": {},
411351          "externalReferences": [
411352            {
411353              "url": "https://zlib.net/",
411354              "type": "distribution"
411355            }
411356          ],
411357          "evidence": {},
411358          "signature": {
411359            "signature": {
411360              "publicKey": {}
411361            }
411362          },
411363          "modelCard": {
411364            "modelParameters": {
411365              "approach": {}
411366            },
411367            "quantitativeAnalysis": {
411368              "graphics": {}
411369            },
411370            "considerations": {}
411371          }
411372        },
411373        {
411374          "type": "operating-system",
411375          "supplier": {},
411376          "name": "alpine",
411377          "version": "3.16.5",
411378          "description": "Alpine Linux v3.16",
411379          "swid": {
411380            "tagId": "alpine",
411381            "name": "alpine",
411382            "version": "3.16.5",
411383            "attachment": {}
411384          },
411385          "pedigree": {},
411386          "externalReferences": [
411387            {
411388              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
411389              "type": "issue-tracker"
411390            },
411391            {
411392              "url": "https://alpinelinux.org/",
411393              "type": "website"
411394            }
411395          ],
411396          "evidence": {},
411397          "signature": {
411398            "signature": {
411399              "publicKey": {}
411400            }
411401          },
411402          "modelCard": {
411403            "modelParameters": {
411404              "approach": {}
411405            },
411406            "quantitativeAnalysis": {
411407              "graphics": {}
411408            },
411409            "considerations": {}
411410          }
411411        },
411412        {
411413          "type": "library",
411414          "bom-ref": "pkg:apk/alpine/.python-rundeps@20230330.012037?arch=noarch\u0026distro=alpine-3.16.5\u0026package-id=f4d111cafc76519b",
411415          "supplier": {},
411416          "name": ".python-rundeps",
411417          "version": "20230330.012037",
411418          "description": "virtual meta package",
411419          "licenses": [
411420            {}
411421          ],
411422          "cpe": "cpe:2.3:a:.python-rundeps:.python-rundeps:20230330.012037:*:*:*:*:*:*:*",
411423          "purl": "pkg:apk/alpine/.python-rundeps@20230330.012037?arch=noarch\u0026distro=alpine-3.16.5",
411424          "swid": {
411425            "attachment": {}
411426          },
411427          "pedigree": {},
411428          "evidence": {},
411429          "signature": {
411430            "signature": {
411431              "publicKey": {}
411432            }
411433          },
411434          "modelCard": {
411435            "modelParameters": {
411436              "approach": {}
411437            },
411438            "quantitativeAnalysis": {
411439              "graphics": {}
411440            },
411441            "considerations": {}
411442          }
411443        },
411444        {
411445          "type": "library",
411446          "bom-ref": "pkg:pypi/click@7.0?package-id=840f50855d8f675e",
411447          "supplier": {},
411448          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
411449          "name": "Click",
411450          "version": "7.0",
411451          "licenses": [
411452            {
411453              "license": {
411454                "name": "BSD"
411455              }
411456            }
411457          ],
411458          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Click:7.0:*:*:*:*:*:*:*",
411459          "purl": "pkg:pypi/Click@7.0",
411460          "swid": {
411461            "attachment": {}
411462          },
411463          "pedigree": {},
411464          "evidence": {},
411465          "signature": {
411466            "signature": {
411467              "publicKey": {}
411468            }
411469          },
411470          "modelCard": {
411471            "modelParameters": {
411472              "approach": {}
411473            },
411474            "quantitativeAnalysis": {
411475              "graphics": {}
411476            },
411477            "considerations": {}
411478          }
411479        },
411480        {
411481          "type": "library",
411482          "bom-ref": "pkg:pypi/flask@1.1.1?package-id=ca332524b751bba1",
411483          "supplier": {},
411484          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
411485          "name": "Flask",
411486          "version": "1.1.1",
411487          "licenses": [
411488            {
411489              "license": {
411490                "id": "BSD-3-Clause"
411491              }
411492            }
411493          ],
411494          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Flask:1.1.1:*:*:*:*:*:*:*",
411495          "purl": "pkg:pypi/Flask@1.1.1",
411496          "swid": {
411497            "attachment": {}
411498          },
411499          "pedigree": {},
411500          "evidence": {},
411501          "signature": {
411502            "signature": {
411503              "publicKey": {}
411504            }
411505          },
411506          "modelCard": {
411507            "modelParameters": {
411508              "approach": {}
411509            },
411510            "quantitativeAnalysis": {
411511              "graphics": {}
411512            },
411513            "considerations": {}
411514          }
411515        },
411516        {
411517          "type": "library",
411518          "bom-ref": "pkg:pypi/flask-restful@0.3.7?package-id=aa19b2a1767c6e78",
411519          "supplier": {},
411520          "author": "Twilio API Team \u003chelp@twilio.com\u003e",
411521          "name": "Flask-RESTful",
411522          "version": "0.3.7",
411523          "licenses": [
411524            {
411525              "license": {
411526                "name": "BSD"
411527              }
411528            }
411529          ],
411530          "cpe": "cpe:2.3:a:twilio_api_team_project:python-Flask-RESTful:0.3.7:*:*:*:*:*:*:*",
411531          "purl": "pkg:pypi/Flask-RESTful@0.3.7",
411532          "swid": {
411533            "attachment": {}
411534          },
411535          "pedigree": {},
411536          "evidence": {},
411537          "signature": {
411538            "signature": {
411539              "publicKey": {}
411540            }
411541          },
411542          "modelCard": {
411543            "modelParameters": {
411544              "approach": {}
411545            },
411546            "quantitativeAnalysis": {
411547              "graphics": {}
411548            },
411549            "considerations": {}
411550          }
411551        },
411552        {
411553          "type": "library",
411554          "bom-ref": "pkg:pypi/jinja2@2.10.1?package-id=b6fda55ab30528e8",
411555          "supplier": {},
411556          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
411557          "name": "Jinja2",
411558          "version": "2.10.1",
411559          "licenses": [
411560            {
411561              "license": {
411562                "name": "BSD"
411563              }
411564            }
411565          ],
411566          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Jinja2:2.10.1:*:*:*:*:*:*:*",
411567          "purl": "pkg:pypi/Jinja2@2.10.1",
411568          "swid": {
411569            "attachment": {}
411570          },
411571          "pedigree": {},
411572          "evidence": {},
411573          "signature": {
411574            "signature": {
411575              "publicKey": {}
411576            }
411577          },
411578          "modelCard": {
411579            "modelParameters": {
411580              "approach": {}
411581            },
411582            "quantitativeAnalysis": {
411583              "graphics": {}
411584            },
411585            "considerations": {}
411586          }
411587        },
411588        {
411589          "type": "library",
411590          "bom-ref": "pkg:pypi/markupsafe@1.1.1?package-id=a5d8b40c74cb3b3",
411591          "supplier": {},
411592          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
411593          "name": "MarkupSafe",
411594          "version": "1.1.1",
411595          "licenses": [
411596            {
411597              "license": {
411598                "id": "BSD-3-Clause"
411599              }
411600            }
411601          ],
411602          "cpe": "cpe:2.3:a:armin_ronacher_project:python-MarkupSafe:1.1.1:*:*:*:*:*:*:*",
411603          "purl": "pkg:pypi/MarkupSafe@1.1.1",
411604          "swid": {
411605            "attachment": {}
411606          },
411607          "pedigree": {},
411608          "evidence": {},
411609          "signature": {
411610            "signature": {
411611              "publicKey": {}
411612            }
411613          },
411614          "modelCard": {
411615            "modelParameters": {
411616              "approach": {}
411617            },
411618            "quantitativeAnalysis": {
411619              "graphics": {}
411620            },
411621            "considerations": {}
411622          }
411623        },
411624        {
411625          "type": "library",
411626          "bom-ref": "pkg:pypi/werkzeug@2.0.3?package-id=373d98ea821b7791",
411627          "supplier": {},
411628          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
411629          "name": "Werkzeug",
411630          "version": "2.0.3",
411631          "licenses": [
411632            {
411633              "license": {
411634                "id": "BSD-3-Clause"
411635              }
411636            }
411637          ],
411638          "cpe": "cpe:2.3:a:armin_ronacher_project:python-Werkzeug:2.0.3:*:*:*:*:*:*:*",
411639          "purl": "pkg:pypi/Werkzeug@2.0.3",
411640          "swid": {
411641            "attachment": {}
411642          },
411643          "pedigree": {},
411644          "evidence": {},
411645          "signature": {
411646            "signature": {
411647              "publicKey": {}
411648            }
411649          },
411650          "modelCard": {
411651            "modelParameters": {
411652              "approach": {}
411653            },
411654            "quantitativeAnalysis": {
411655              "graphics": {}
411656            },
411657            "considerations": {}
411658          }
411659        },
411660        {
411661          "type": "library",
411662          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=61eac5ce8105d394",
411663          "supplier": {},
411664          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
411665          "name": "alpine-baselayout",
411666          "version": "3.2.0-r23",
411667          "description": "Alpine base dir structure and init scripts",
411668          "licenses": [
411669            {
411670              "license": {
411671                "id": "GPL-2.0-only"
411672              }
411673            }
411674          ],
411675          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r23:*:*:*:*:*:*:*",
411676          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64\u0026distro=alpine-3.16.5",
411677          "swid": {
411678            "attachment": {}
411679          },
411680          "pedigree": {},
411681          "externalReferences": [
411682            {
411683              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
411684              "type": "distribution"
411685            }
411686          ],
411687          "evidence": {},
411688          "signature": {
411689            "signature": {
411690              "publicKey": {}
411691            }
411692          },
411693          "modelCard": {
411694            "modelParameters": {
411695              "approach": {}
411696            },
411697            "quantitativeAnalysis": {
411698              "graphics": {}
411699            },
411700            "considerations": {}
411701          }
411702        },
411703        {
411704          "type": "library",
411705          "bom-ref": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5\u0026package-id=e8c6fcc3a282ed4f",
411706          "supplier": {},
411707          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
411708          "name": "alpine-baselayout-data",
411709          "version": "3.2.0-r23",
411710          "description": "Alpine base dir structure and init scripts",
411711          "licenses": [
411712            {
411713              "license": {
411714                "id": "GPL-2.0-only"
411715              }
411716            }
411717          ],
411718          "cpe": "cpe:2.3:a:alpine-baselayout-data:alpine-baselayout-data:3.2.0-r23:*:*:*:*:*:*:*",
411719          "purl": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64\u0026upstream=alpine-baselayout\u0026distro=alpine-3.16.5",
411720          "swid": {
411721            "attachment": {}
411722          },
411723          "pedigree": {},
411724          "externalReferences": [
411725            {
411726              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
411727              "type": "distribution"
411728            }
411729          ],
411730          "evidence": {},
411731          "signature": {
411732            "signature": {
411733              "publicKey": {}
411734            }
411735          },
411736          "modelCard": {
411737            "modelParameters": {
411738              "approach": {}
411739            },
411740            "quantitativeAnalysis": {
411741              "graphics": {}
411742            },
411743            "considerations": {}
411744          }
411745        },
411746        {
411747          "type": "library",
411748          "bom-ref": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=82d183eb300978cc",
411749          "supplier": {},
411750          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
411751          "name": "alpine-keys",
411752          "version": "2.4-r1",
411753          "description": "Public keys for Alpine Linux packages",
411754          "licenses": [
411755            {
411756              "license": {
411757                "id": "MIT"
411758              }
411759            }
411760          ],
411761          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.4-r1:*:*:*:*:*:*:*",
411762          "purl": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64\u0026distro=alpine-3.16.5",
411763          "swid": {
411764            "attachment": {}
411765          },
411766          "pedigree": {},
411767          "externalReferences": [
411768            {
411769              "url": "https://alpinelinux.org",
411770              "type": "distribution"
411771            }
411772          ],
411773          "evidence": {},
411774          "signature": {
411775            "signature": {
411776              "publicKey": {}
411777            }
411778          },
411779          "modelCard": {
411780            "modelParameters": {
411781              "approach": {}
411782            },
411783            "quantitativeAnalysis": {
411784              "graphics": {}
411785            },
411786            "considerations": {}
411787          }
411788        },
411789        {
411790          "type": "library",
411791          "bom-ref": "pkg:pypi/aniso8601@8.0.0?package-id=8fdafa9f0e51bc3b",
411792          "supplier": {},
411793          "author": "Brandon Nielsen \u003cnielsenb@jetfuse.net\u003e",
411794          "name": "aniso8601",
411795          "version": "8.0.0",
411796          "licenses": [
411797            {
411798              "license": {
411799                "name": "UNKNOWN"
411800              }
411801            }
411802          ],
411803          "cpe": "cpe:2.3:a:brandon_nielsen_project:python-aniso8601:8.0.0:*:*:*:*:*:*:*",
411804          "purl": "pkg:pypi/aniso8601@8.0.0",
411805          "swid": {
411806            "attachment": {}
411807          },
411808          "pedigree": {},
411809          "evidence": {},
411810          "signature": {
411811            "signature": {
411812              "publicKey": {}
411813            }
411814          },
411815          "modelCard": {
411816            "modelParameters": {
411817              "approach": {}
411818            },
411819            "quantitativeAnalysis": {
411820              "graphics": {}
411821            },
411822            "considerations": {}
411823          }
411824        },
411825        {
411826          "type": "library",
411827          "bom-ref": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=42d502b764a37310",
411828          "supplier": {},
411829          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
411830          "name": "apk-tools",
411831          "version": "2.12.9-r3",
411832          "description": "Alpine Package Keeper - package manager for alpine",
411833          "licenses": [
411834            {
411835              "license": {
411836                "id": "GPL-2.0-only"
411837              }
411838            }
411839          ],
411840          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.12.9-r3:*:*:*:*:*:*:*",
411841          "purl": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64\u0026distro=alpine-3.16.5",
411842          "swid": {
411843            "attachment": {}
411844          },
411845          "pedigree": {},
411846          "externalReferences": [
411847            {
411848              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
411849              "type": "distribution"
411850            }
411851          ],
411852          "evidence": {},
411853          "signature": {
411854            "signature": {
411855              "publicKey": {}
411856            }
411857          },
411858          "modelCard": {
411859            "modelParameters": {
411860              "approach": {}
411861            },
411862            "quantitativeAnalysis": {
411863              "graphics": {}
411864            },
411865            "considerations": {}
411866          }
411867        },
411868        {
411869          "type": "application",
411870          "bom-ref": "e14718c64f5147f4",
411871          "supplier": {},
411872          "name": "busybox",
411873          "version": "1.35.0",
411874          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0:*:*:*:*:*:*:*",
411875          "swid": {
411876            "attachment": {}
411877          },
411878          "pedigree": {},
411879          "evidence": {},
411880          "signature": {
411881            "signature": {
411882              "publicKey": {}
411883            }
411884          },
411885          "modelCard": {
411886            "modelParameters": {
411887              "approach": {}
411888            },
411889            "quantitativeAnalysis": {
411890              "graphics": {}
411891            },
411892            "considerations": {}
411893          }
411894        },
411895        {
411896          "type": "library",
411897          "bom-ref": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=4b48ef6f6b983526",
411898          "supplier": {},
411899          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
411900          "name": "busybox",
411901          "version": "1.35.0-r17",
411902          "description": "Size optimized toolbox of many common UNIX utilities",
411903          "licenses": [
411904            {
411905              "license": {
411906                "id": "GPL-2.0-only"
411907              }
411908            }
411909          ],
411910          "cpe": "cpe:2.3:a:busybox:busybox:1.35.0-r17:*:*:*:*:*:*:*",
411911          "purl": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64\u0026distro=alpine-3.16.5",
411912          "swid": {
411913            "attachment": {}
411914          },
411915          "pedigree": {},
411916          "externalReferences": [
411917            {
411918              "url": "https://busybox.net/",
411919              "type": "distribution"
411920            }
411921          ],
411922          "evidence": {},
411923          "signature": {
411924            "signature": {
411925              "publicKey": {}
411926            }
411927          },
411928          "modelCard": {
411929            "modelParameters": {
411930              "approach": {}
411931            },
411932            "quantitativeAnalysis": {
411933              "graphics": {}
411934            },
411935            "considerations": {}
411936          }
411937        },
411938        {
411939          "type": "library",
411940          "bom-ref": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=fbb1924ff870cc71",
411941          "supplier": {},
411942          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
411943          "name": "ca-certificates",
411944          "version": "20220614-r0",
411945          "description": "Common CA certificates PEM files from Mozilla",
411946          "licenses": [
411947            {
411948              "license": {
411949                "id": "MPL-2.0"
411950              }
411951            },
411952            {
411953              "license": {
411954                "name": "AND"
411955              }
411956            },
411957            {
411958              "license": {
411959                "id": "MIT"
411960              }
411961            }
411962          ],
411963          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20220614-r0:*:*:*:*:*:*:*",
411964          "purl": "pkg:apk/alpine/ca-certificates@20220614-r0?arch=x86_64\u0026distro=alpine-3.16.5",
411965          "swid": {
411966            "attachment": {}
411967          },
411968          "pedigree": {},
411969          "externalReferences": [
411970            {
411971              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
411972              "type": "distribution"
411973            }
411974          ],
411975          "evidence": {},
411976          "signature": {
411977            "signature": {
411978              "publicKey": {}
411979            }
411980          },
411981          "modelCard": {
411982            "modelParameters": {
411983              "approach": {}
411984            },
411985            "quantitativeAnalysis": {
411986              "graphics": {}
411987            },
411988            "considerations": {}
411989          }
411990        },
411991        {
411992          "type": "library",
411993          "bom-ref": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5\u0026package-id=30622a1848b22bca",
411994          "supplier": {},
411995          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
411996          "name": "ca-certificates-bundle",
411997          "version": "20220614-r0",
411998          "description": "Pre generated bundle of Mozilla certificates",
411999          "licenses": [
412000            {
412001              "license": {
412002                "id": "MPL-2.0"
412003              }
412004            },
412005            {
412006              "license": {
412007                "name": "AND"
412008              }
412009            },
412010            {
412011              "license": {
412012                "id": "MIT"
412013              }
412014            }
412015          ],
412016          "cpe": "cpe:2.3:a:ca-certificates-bundle:ca-certificates-bundle:20220614-r0:*:*:*:*:*:*:*",
412017          "purl": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.16.5",
412018          "swid": {
412019            "attachment": {}
412020          },
412021          "pedigree": {},
412022          "externalReferences": [
412023            {
412024              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
412025              "type": "distribution"
412026            }
412027          ],
412028          "evidence": {},
412029          "signature": {
412030            "signature": {
412031              "publicKey": {}
412032            }
412033          },
412034          "modelCard": {
412035            "modelParameters": {
412036              "approach": {}
412037            },
412038            "quantitativeAnalysis": {
412039              "graphics": {}
412040            },
412041            "considerations": {}
412042          }
412043        },
412044        {
412045          "type": "library",
412046          "bom-ref": "pkg:apk/alpine/expat@2.5.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=473c10d9103a81b0",
412047          "supplier": {},
412048          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
412049          "name": "expat",
412050          "version": "2.5.0-r0",
412051          "description": "XML Parser library written in C",
412052          "licenses": [
412053            {
412054              "license": {
412055                "id": "MIT"
412056              }
412057            }
412058          ],
412059          "cpe": "cpe:2.3:a:expat:expat:2.5.0-r0:*:*:*:*:*:*:*",
412060          "purl": "pkg:apk/alpine/expat@2.5.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
412061          "swid": {
412062            "attachment": {}
412063          },
412064          "pedigree": {},
412065          "externalReferences": [
412066            {
412067              "url": "https://libexpat.github.io/",
412068              "type": "distribution"
412069            }
412070          ],
412071          "evidence": {},
412072          "signature": {
412073            "signature": {
412074              "publicKey": {}
412075            }
412076          },
412077          "modelCard": {
412078            "modelParameters": {
412079              "approach": {}
412080            },
412081            "quantitativeAnalysis": {
412082              "graphics": {}
412083            },
412084            "considerations": {}
412085          }
412086        },
412087        {
412088          "type": "library",
412089          "bom-ref": "pkg:pypi/future@0.17.1?package-id=6a2ffb301b402f52",
412090          "supplier": {},
412091          "author": "Ed Schofield \u003ced@pythoncharmers.com\u003e",
412092          "name": "future",
412093          "version": "0.17.1",
412094          "licenses": [
412095            {
412096              "license": {
412097                "id": "MIT"
412098              }
412099            }
412100          ],
412101          "cpe": "cpe:2.3:a:ed_schofield_project:python-future:0.17.1:*:*:*:*:*:*:*",
412102          "purl": "pkg:pypi/future@0.17.1",
412103          "swid": {
412104            "attachment": {}
412105          },
412106          "pedigree": {},
412107          "evidence": {},
412108          "signature": {
412109            "signature": {
412110              "publicKey": {}
412111            }
412112          },
412113          "modelCard": {
412114            "modelParameters": {
412115              "approach": {}
412116            },
412117            "quantitativeAnalysis": {
412118              "graphics": {}
412119            },
412120            "considerations": {}
412121          }
412122        },
412123        {
412124          "type": "library",
412125          "bom-ref": "pkg:apk/alpine/gdbm@1.23-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=5a60c1f034fa6943",
412126          "supplier": {},
412127          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412128          "name": "gdbm",
412129          "version": "1.23-r0",
412130          "description": "GNU dbm is a set of database routines that use extensible hashing",
412131          "licenses": [
412132            {
412133              "license": {
412134                "id": "GPL-3.0-or-later"
412135              }
412136            }
412137          ],
412138          "cpe": "cpe:2.3:a:gdbm:gdbm:1.23-r0:*:*:*:*:*:*:*",
412139          "purl": "pkg:apk/alpine/gdbm@1.23-r0?arch=x86_64\u0026distro=alpine-3.16.5",
412140          "swid": {
412141            "attachment": {}
412142          },
412143          "pedigree": {},
412144          "externalReferences": [
412145            {
412146              "url": "https://www.gnu.org/software/gdbm/",
412147              "type": "distribution"
412148            }
412149          ],
412150          "evidence": {},
412151          "signature": {
412152            "signature": {
412153              "publicKey": {}
412154            }
412155          },
412156          "modelCard": {
412157            "modelParameters": {
412158              "approach": {}
412159            },
412160            "quantitativeAnalysis": {
412161              "graphics": {}
412162            },
412163            "considerations": {}
412164          }
412165        },
412166        {
412167          "type": "library",
412168          "bom-ref": "pkg:pypi/gevent@1.4.0?package-id=fc0a17fcd31e8ae8",
412169          "supplier": {},
412170          "author": "Denis Bilenko \u003cdenis.bilenko@gmail.com\u003e",
412171          "name": "gevent",
412172          "version": "1.4.0",
412173          "licenses": [
412174            {
412175              "license": {
412176                "id": "MIT"
412177              }
412178            }
412179          ],
412180          "cpe": "cpe:2.3:a:denis_bilenko_project:python-gevent:1.4.0:*:*:*:*:*:*:*",
412181          "purl": "pkg:pypi/gevent@1.4.0",
412182          "swid": {
412183            "attachment": {}
412184          },
412185          "pedigree": {},
412186          "evidence": {},
412187          "signature": {
412188            "signature": {
412189              "publicKey": {}
412190            }
412191          },
412192          "modelCard": {
412193            "modelParameters": {
412194              "approach": {}
412195            },
412196            "quantitativeAnalysis": {
412197              "graphics": {}
412198            },
412199            "considerations": {}
412200          }
412201        },
412202        {
412203          "type": "library",
412204          "bom-ref": "pkg:pypi/greenlet@0.4.15?package-id=a3782f68cd759ea1",
412205          "supplier": {},
412206          "name": "greenlet",
412207          "version": "0.4.15",
412208          "licenses": [
412209            {
412210              "license": {
412211                "name": "MIT License"
412212              }
412213            }
412214          ],
412215          "cpe": "cpe:2.3:a:python-greenlet:python-greenlet:0.4.15:*:*:*:*:*:*:*",
412216          "purl": "pkg:pypi/greenlet@0.4.15",
412217          "swid": {
412218            "attachment": {}
412219          },
412220          "pedigree": {},
412221          "evidence": {},
412222          "signature": {
412223            "signature": {
412224              "publicKey": {}
412225            }
412226          },
412227          "modelCard": {
412228            "modelParameters": {
412229              "approach": {}
412230            },
412231            "quantitativeAnalysis": {
412232              "graphics": {}
412233            },
412234            "considerations": {}
412235          }
412236        },
412237        {
412238          "type": "library",
412239          "bom-ref": "pkg:pypi/gunicorn@19.9.0?package-id=54b09808bf1c183f",
412240          "supplier": {},
412241          "author": "Benoit Chesneau \u003cbenoitc@e-engura.com\u003e",
412242          "name": "gunicorn",
412243          "version": "19.9.0",
412244          "licenses": [
412245            {
412246              "license": {
412247                "id": "MIT"
412248              }
412249            }
412250          ],
412251          "cpe": "cpe:2.3:a:benoit_chesneau_project:python-gunicorn:19.9.0:*:*:*:*:*:*:*",
412252          "purl": "pkg:pypi/gunicorn@19.9.0",
412253          "swid": {
412254            "attachment": {}
412255          },
412256          "pedigree": {},
412257          "evidence": {},
412258          "signature": {
412259            "signature": {
412260              "publicKey": {}
412261            }
412262          },
412263          "modelCard": {
412264            "modelParameters": {
412265              "approach": {}
412266            },
412267            "quantitativeAnalysis": {
412268              "graphics": {}
412269            },
412270            "considerations": {}
412271          }
412272        },
412273        {
412274          "type": "library",
412275          "bom-ref": "pkg:pypi/itsdangerous@1.1.0?package-id=d20834c719d5bf8d",
412276          "supplier": {},
412277          "author": "Armin Ronacher \u003carmin.ronacher@active-4.com\u003e",
412278          "name": "itsdangerous",
412279          "version": "1.1.0",
412280          "licenses": [
412281            {
412282              "license": {
412283                "name": "BSD"
412284              }
412285            }
412286          ],
412287          "cpe": "cpe:2.3:a:armin_ronacher_project:python-itsdangerous:1.1.0:*:*:*:*:*:*:*",
412288          "purl": "pkg:pypi/itsdangerous@1.1.0",
412289          "swid": {
412290            "attachment": {}
412291          },
412292          "pedigree": {},
412293          "evidence": {},
412294          "signature": {
412295            "signature": {
412296              "publicKey": {}
412297            }
412298          },
412299          "modelCard": {
412300            "modelParameters": {
412301              "approach": {}
412302            },
412303            "quantitativeAnalysis": {
412304              "graphics": {}
412305            },
412306            "considerations": {}
412307          }
412308        },
412309        {
412310          "type": "library",
412311          "bom-ref": "pkg:apk/alpine/keyutils-libs@1.6.3-r1?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.16.5\u0026package-id=8ee597dfe194ab60",
412312          "supplier": {},
412313          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412314          "name": "keyutils-libs",
412315          "version": "1.6.3-r1",
412316          "description": "Key utilities library",
412317          "licenses": [
412318            {
412319              "license": {
412320                "id": "GPL-2.0-or-later"
412321              }
412322            },
412323            {
412324              "license": {
412325                "id": "LGPL-2.0-or-later"
412326              }
412327            }
412328          ],
412329          "cpe": "cpe:2.3:a:keyutils-libs:keyutils-libs:1.6.3-r1:*:*:*:*:*:*:*",
412330          "purl": "pkg:apk/alpine/keyutils-libs@1.6.3-r1?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.16.5",
412331          "swid": {
412332            "attachment": {}
412333          },
412334          "pedigree": {},
412335          "externalReferences": [
412336            {
412337              "url": "https://people.redhat.com/~dhowells/keyutils/",
412338              "type": "distribution"
412339            }
412340          ],
412341          "evidence": {},
412342          "signature": {
412343            "signature": {
412344              "publicKey": {}
412345            }
412346          },
412347          "modelCard": {
412348            "modelParameters": {
412349              "approach": {}
412350            },
412351            "quantitativeAnalysis": {
412352              "graphics": {}
412353            },
412354            "considerations": {}
412355          }
412356        },
412357        {
412358          "type": "library",
412359          "bom-ref": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=50afffc56cc7e53",
412360          "supplier": {},
412361          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412362          "name": "krb5-conf",
412363          "version": "1.0-r2",
412364          "description": "Shared krb5.conf for both MIT krb5 and heimdal",
412365          "licenses": [
412366            {
412367              "license": {
412368                "id": "MIT"
412369              }
412370            }
412371          ],
412372          "cpe": "cpe:2.3:a:krb5-conf:krb5-conf:1.0-r2:*:*:*:*:*:*:*",
412373          "purl": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=alpine-3.16.5",
412374          "swid": {
412375            "attachment": {}
412376          },
412377          "pedigree": {},
412378          "externalReferences": [
412379            {
412380              "url": "https://web.mit.edu/kerberos/www/",
412381              "type": "distribution"
412382            }
412383          ],
412384          "evidence": {},
412385          "signature": {
412386            "signature": {
412387              "publicKey": {}
412388            }
412389          },
412390          "modelCard": {
412391            "modelParameters": {
412392              "approach": {}
412393            },
412394            "quantitativeAnalysis": {
412395              "graphics": {}
412396            },
412397            "considerations": {}
412398          }
412399        },
412400        {
412401          "type": "library",
412402          "bom-ref": "pkg:apk/alpine/krb5-libs@1.19.4-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.16.5\u0026package-id=4cdf917c85417723",
412403          "supplier": {},
412404          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412405          "name": "krb5-libs",
412406          "version": "1.19.4-r0",
412407          "description": "The shared libraries used by Kerberos 5",
412408          "licenses": [
412409            {
412410              "license": {
412411                "id": "MIT"
412412              }
412413            }
412414          ],
412415          "cpe": "cpe:2.3:a:krb5-libs:krb5-libs:1.19.4-r0:*:*:*:*:*:*:*",
412416          "purl": "pkg:apk/alpine/krb5-libs@1.19.4-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.16.5",
412417          "swid": {
412418            "attachment": {}
412419          },
412420          "pedigree": {},
412421          "externalReferences": [
412422            {
412423              "url": "https://web.mit.edu/kerberos/www/",
412424              "type": "distribution"
412425            }
412426          ],
412427          "evidence": {},
412428          "signature": {
412429            "signature": {
412430              "publicKey": {}
412431            }
412432          },
412433          "modelCard": {
412434            "modelParameters": {
412435              "approach": {}
412436            },
412437            "quantitativeAnalysis": {
412438              "graphics": {}
412439            },
412440            "considerations": {}
412441          }
412442        },
412443        {
412444          "type": "library",
412445          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.16.5\u0026package-id=b681aee18ae0aa50",
412446          "supplier": {},
412447          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412448          "name": "libbz2",
412449          "version": "1.0.8-r1",
412450          "description": "Shared library for bz2",
412451          "licenses": [
412452            {
412453              "license": {
412454                "id": "bzip2-1.0.6"
412455              }
412456            }
412457          ],
412458          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r1:*:*:*:*:*:*:*",
412459          "purl": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.16.5",
412460          "swid": {
412461            "attachment": {}
412462          },
412463          "pedigree": {},
412464          "externalReferences": [
412465            {
412466              "url": "http://sources.redhat.com/bzip2",
412467              "type": "distribution"
412468            }
412469          ],
412470          "evidence": {},
412471          "signature": {
412472            "signature": {
412473              "publicKey": {}
412474            }
412475          },
412476          "modelCard": {
412477            "modelParameters": {
412478              "approach": {}
412479            },
412480            "quantitativeAnalysis": {
412481              "graphics": {}
412482            },
412483            "considerations": {}
412484          }
412485        },
412486        {
412487          "type": "library",
412488          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5\u0026package-id=2abd3b45f6fa4702",
412489          "supplier": {},
412490          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412491          "name": "libc-utils",
412492          "version": "0.7.2-r3",
412493          "description": "Meta package to pull in correct libc",
412494          "licenses": [
412495            {
412496              "license": {
412497                "id": "BSD-2-Clause"
412498              }
412499            },
412500            {
412501              "license": {
412502                "name": "AND"
412503              }
412504            },
412505            {
412506              "license": {
412507                "id": "BSD-3-Clause"
412508              }
412509            }
412510          ],
412511          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r3:*:*:*:*:*:*:*",
412512          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.16.5",
412513          "swid": {
412514            "attachment": {}
412515          },
412516          "pedigree": {},
412517          "externalReferences": [
412518            {
412519              "url": "https://alpinelinux.org",
412520              "type": "distribution"
412521            }
412522          ],
412523          "evidence": {},
412524          "signature": {
412525            "signature": {
412526              "publicKey": {}
412527            }
412528          },
412529          "modelCard": {
412530            "modelParameters": {
412531              "approach": {}
412532            },
412533            "quantitativeAnalysis": {
412534              "graphics": {}
412535            },
412536            "considerations": {}
412537          }
412538        },
412539        {
412540          "type": "library",
412541          "bom-ref": "pkg:apk/alpine/libcom_err@1.46.6-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.16.5\u0026package-id=25b329ab3289e91c",
412542          "supplier": {},
412543          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412544          "name": "libcom_err",
412545          "version": "1.46.6-r0",
412546          "description": "Common error description library",
412547          "licenses": [
412548            {
412549              "license": {
412550                "id": "GPL-2.0-or-later"
412551              }
412552            },
412553            {
412554              "license": {
412555                "name": "AND"
412556              }
412557            },
412558            {
412559              "license": {
412560                "id": "LGPL-2.0-or-later"
412561              }
412562            },
412563            {
412564              "license": {
412565                "name": "AND"
412566              }
412567            },
412568            {
412569              "license": {
412570                "id": "BSD-3-Clause"
412571              }
412572            },
412573            {
412574              "license": {
412575                "name": "AND"
412576              }
412577            },
412578            {
412579              "license": {
412580                "id": "MIT"
412581              }
412582            }
412583          ],
412584          "cpe": "cpe:2.3:a:libcom-err:libcom-err:1.46.6-r0:*:*:*:*:*:*:*",
412585          "purl": "pkg:apk/alpine/libcom_err@1.46.6-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.16.5",
412586          "swid": {
412587            "attachment": {}
412588          },
412589          "pedigree": {},
412590          "externalReferences": [
412591            {
412592              "url": "http://e2fsprogs.sourceforge.net",
412593              "type": "distribution"
412594            }
412595          ],
412596          "evidence": {},
412597          "signature": {
412598            "signature": {
412599              "publicKey": {}
412600            }
412601          },
412602          "modelCard": {
412603            "modelParameters": {
412604              "approach": {}
412605            },
412606            "quantitativeAnalysis": {
412607              "graphics": {}
412608            },
412609            "considerations": {}
412610          }
412611        },
412612        {
412613          "type": "library",
412614          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=13bc051822a24e8d",
412615          "supplier": {},
412616          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
412617          "name": "libcrypto1.1",
412618          "version": "1.1.1t-r2",
412619          "description": "Crypto library from openssl",
412620          "licenses": [
412621            {
412622              "license": {
412623                "id": "OpenSSL"
412624              }
412625            }
412626          ],
412627          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1t-r2:*:*:*:*:*:*:*",
412628          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
412629          "swid": {
412630            "attachment": {}
412631          },
412632          "pedigree": {},
412633          "externalReferences": [
412634            {
412635              "url": "https://www.openssl.org/",
412636              "type": "distribution"
412637            }
412638          ],
412639          "evidence": {},
412640          "signature": {
412641            "signature": {
412642              "publicKey": {}
412643            }
412644          },
412645          "modelCard": {
412646            "modelParameters": {
412647              "approach": {}
412648            },
412649            "quantitativeAnalysis": {
412650              "graphics": {}
412651            },
412652            "considerations": {}
412653          }
412654        },
412655        {
412656          "type": "library",
412657          "bom-ref": "pkg:apk/alpine/libffi@3.4.2-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=d9c90e0c86210cde",
412658          "supplier": {},
412659          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412660          "name": "libffi",
412661          "version": "3.4.2-r1",
412662          "description": "portable, high level programming interface to various calling conventions.",
412663          "licenses": [
412664            {
412665              "license": {
412666                "id": "MIT"
412667              }
412668            }
412669          ],
412670          "cpe": "cpe:2.3:a:libffi:libffi:3.4.2-r1:*:*:*:*:*:*:*",
412671          "purl": "pkg:apk/alpine/libffi@3.4.2-r1?arch=x86_64\u0026distro=alpine-3.16.5",
412672          "swid": {
412673            "attachment": {}
412674          },
412675          "pedigree": {},
412676          "externalReferences": [
412677            {
412678              "url": "https://sourceware.org/libffi/",
412679              "type": "distribution"
412680            }
412681          ],
412682          "evidence": {},
412683          "signature": {
412684            "signature": {
412685              "publicKey": {}
412686            }
412687          },
412688          "modelCard": {
412689            "modelParameters": {
412690              "approach": {}
412691            },
412692            "quantitativeAnalysis": {
412693              "graphics": {}
412694            },
412695            "considerations": {}
412696          }
412697        },
412698        {
412699          "type": "library",
412700          "bom-ref": "pkg:apk/alpine/libintl@0.21-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.16.5\u0026package-id=8a4b8fffbba0af61",
412701          "supplier": {},
412702          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
412703          "name": "libintl",
412704          "version": "0.21-r2",
412705          "description": "GNU gettext runtime library",
412706          "licenses": [
412707            {
412708              "license": {
412709                "id": "LGPL-2.1-or-later"
412710              }
412711            }
412712          ],
412713          "cpe": "cpe:2.3:a:libintl:libintl:0.21-r2:*:*:*:*:*:*:*",
412714          "purl": "pkg:apk/alpine/libintl@0.21-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.16.5",
412715          "swid": {
412716            "attachment": {}
412717          },
412718          "pedigree": {},
412719          "externalReferences": [
412720            {
412721              "url": "https://www.gnu.org/software/gettext/gettext.html",
412722              "type": "distribution"
412723            }
412724          ],
412725          "evidence": {},
412726          "signature": {
412727            "signature": {
412728              "publicKey": {}
412729            }
412730          },
412731          "modelCard": {
412732            "modelParameters": {
412733              "approach": {}
412734            },
412735            "quantitativeAnalysis": {
412736              "graphics": {}
412737            },
412738            "considerations": {}
412739          }
412740        },
412741        {
412742          "type": "library",
412743          "bom-ref": "pkg:apk/alpine/libnsl@2.0.0-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=684ad1c4c0c42987",
412744          "supplier": {},
412745          "publisher": "Valery Kartel \u003cvalery.kartel@gmail.com\u003e",
412746          "name": "libnsl",
412747          "version": "2.0.0-r0",
412748          "description": "Public client interface for NIS(YP) and NIS+ in a IPv6 ready version",
412749          "licenses": [
412750            {
412751              "license": {
412752                "id": "LGPL-2.0-or-later"
412753              }
412754            }
412755          ],
412756          "cpe": "cpe:2.3:a:thkukuk:libnsl:2.0.0-r0:*:*:*:*:*:*:*",
412757          "purl": "pkg:apk/alpine/libnsl@2.0.0-r0?arch=x86_64\u0026distro=alpine-3.16.5",
412758          "swid": {
412759            "attachment": {}
412760          },
412761          "pedigree": {},
412762          "externalReferences": [
412763            {
412764              "url": "https://github.com/thkukuk/libnsl",
412765              "type": "distribution"
412766            }
412767          ],
412768          "evidence": {},
412769          "signature": {
412770            "signature": {
412771              "publicKey": {}
412772            }
412773          },
412774          "modelCard": {
412775            "modelParameters": {
412776              "approach": {}
412777            },
412778            "quantitativeAnalysis": {
412779              "graphics": {}
412780            },
412781            "considerations": {}
412782          }
412783        },
412784        {
412785          "type": "library",
412786          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5\u0026package-id=609cb94e63dc06dd",
412787          "supplier": {},
412788          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
412789          "name": "libssl1.1",
412790          "version": "1.1.1t-r2",
412791          "description": "SSL shared libraries",
412792          "licenses": [
412793            {
412794              "license": {
412795                "id": "OpenSSL"
412796              }
412797            }
412798          ],
412799          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1t-r2:*:*:*:*:*:*:*",
412800          "purl": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.16.5",
412801          "swid": {
412802            "attachment": {}
412803          },
412804          "pedigree": {},
412805          "externalReferences": [
412806            {
412807              "url": "https://www.openssl.org/",
412808              "type": "distribution"
412809            }
412810          ],
412811          "evidence": {},
412812          "signature": {
412813            "signature": {
412814              "publicKey": {}
412815            }
412816          },
412817          "modelCard": {
412818            "modelParameters": {
412819              "approach": {}
412820            },
412821            "quantitativeAnalysis": {
412822              "graphics": {}
412823            },
412824            "considerations": {}
412825          }
412826        },
412827        {
412828          "type": "library",
412829          "bom-ref": "pkg:apk/alpine/libtirpc@1.3.2-r1?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=7879d46219520605",
412830          "supplier": {},
412831          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412832          "name": "libtirpc",
412833          "version": "1.3.2-r1",
412834          "description": "Transport Independent RPC library (SunRPC replacement)",
412835          "licenses": [
412836            {
412837              "license": {
412838                "id": "BSD-3-Clause"
412839              }
412840            }
412841          ],
412842          "cpe": "cpe:2.3:a:libtirpc:libtirpc:1.3.2-r1:*:*:*:*:*:*:*",
412843          "purl": "pkg:apk/alpine/libtirpc@1.3.2-r1?arch=x86_64\u0026distro=alpine-3.16.5",
412844          "swid": {
412845            "attachment": {}
412846          },
412847          "pedigree": {},
412848          "externalReferences": [
412849            {
412850              "url": "https://sourceforge.net/projects/libtirpc",
412851              "type": "distribution"
412852            }
412853          ],
412854          "evidence": {},
412855          "signature": {
412856            "signature": {
412857              "publicKey": {}
412858            }
412859          },
412860          "modelCard": {
412861            "modelParameters": {
412862              "approach": {}
412863            },
412864            "quantitativeAnalysis": {
412865              "graphics": {}
412866            },
412867            "considerations": {}
412868          }
412869        },
412870        {
412871          "type": "library",
412872          "bom-ref": "pkg:apk/alpine/libtirpc-conf@1.3.2-r1?arch=x86_64\u0026upstream=libtirpc\u0026distro=alpine-3.16.5\u0026package-id=2473c071ab562d92",
412873          "supplier": {},
412874          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412875          "name": "libtirpc-conf",
412876          "version": "1.3.2-r1",
412877          "description": "Configuration files for TI-RPC",
412878          "licenses": [
412879            {
412880              "license": {
412881                "id": "BSD-3-Clause"
412882              }
412883            }
412884          ],
412885          "cpe": "cpe:2.3:a:libtirpc-conf:libtirpc-conf:1.3.2-r1:*:*:*:*:*:*:*",
412886          "purl": "pkg:apk/alpine/libtirpc-conf@1.3.2-r1?arch=x86_64\u0026upstream=libtirpc\u0026distro=alpine-3.16.5",
412887          "swid": {
412888            "attachment": {}
412889          },
412890          "pedigree": {},
412891          "externalReferences": [
412892            {
412893              "url": "https://sourceforge.net/projects/libtirpc",
412894              "type": "distribution"
412895            }
412896          ],
412897          "evidence": {},
412898          "signature": {
412899            "signature": {
412900              "publicKey": {}
412901            }
412902          },
412903          "modelCard": {
412904            "modelParameters": {
412905              "approach": {}
412906            },
412907            "quantitativeAnalysis": {
412908              "graphics": {}
412909            },
412910            "considerations": {}
412911          }
412912        },
412913        {
412914          "type": "library",
412915          "bom-ref": "pkg:apk/alpine/libuuid@2.38-r1?arch=x86_64\u0026upstream=util-linux\u0026distro=alpine-3.16.5\u0026package-id=8732526a564c0dca",
412916          "supplier": {},
412917          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
412918          "name": "libuuid",
412919          "version": "2.38-r1",
412920          "description": "DCE compatible Universally Unique Identifier library",
412921          "licenses": [
412922            {
412923              "license": {
412924                "id": "GPL-3.0-or-later"
412925              }
412926            },
412927            {
412928              "license": {
412929                "name": "AND"
412930              }
412931            },
412932            {
412933              "license": {
412934                "id": "GPL-2.0-or-later"
412935              }
412936            },
412937            {
412938              "license": {
412939                "name": "AND"
412940              }
412941            },
412942            {
412943              "license": {
412944                "id": "GPL-2.0-only"
412945              }
412946            },
412947            {
412948              "license": {
412949                "name": "AND"
412950              }
412951            }
412952          ],
412953          "cpe": "cpe:2.3:a:libuuid:libuuid:2.38-r1:*:*:*:*:*:*:*",
412954          "purl": "pkg:apk/alpine/libuuid@2.38-r1?arch=x86_64\u0026upstream=util-linux\u0026distro=alpine-3.16.5",
412955          "swid": {
412956            "attachment": {}
412957          },
412958          "pedigree": {},
412959          "externalReferences": [
412960            {
412961              "url": "https://git.kernel.org/cgit/utils/util-linux/util-linux.git",
412962              "type": "distribution"
412963            }
412964          ],
412965          "evidence": {},
412966          "signature": {
412967            "signature": {
412968              "publicKey": {}
412969            }
412970          },
412971          "modelCard": {
412972            "modelParameters": {
412973              "approach": {}
412974            },
412975            "quantitativeAnalysis": {
412976              "graphics": {}
412977            },
412978            "considerations": {}
412979          }
412980        },
412981        {
412982          "type": "library",
412983          "bom-ref": "pkg:apk/alpine/libverto@0.3.2-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=b3642afc50cf09b9",
412984          "supplier": {},
412985          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
412986          "name": "libverto",
412987          "version": "0.3.2-r0",
412988          "description": "Main loop abstraction library",
412989          "licenses": [
412990            {
412991              "license": {
412992                "id": "MIT"
412993              }
412994            }
412995          ],
412996          "cpe": "cpe:2.3:a:npmccallum:libverto:0.3.2-r0:*:*:*:*:*:*:*",
412997          "purl": "pkg:apk/alpine/libverto@0.3.2-r0?arch=x86_64\u0026distro=alpine-3.16.5",
412998          "swid": {
412999            "attachment": {}
413000          },
413001          "pedigree": {},
413002          "externalReferences": [
413003            {
413004              "url": "https://github.com/npmccallum/libverto",
413005              "type": "distribution"
413006            }
413007          ],
413008          "evidence": {},
413009          "signature": {
413010            "signature": {
413011              "publicKey": {}
413012            }
413013          },
413014          "modelCard": {
413015            "modelParameters": {
413016              "approach": {}
413017            },
413018            "quantitativeAnalysis": {
413019              "graphics": {}
413020            },
413021            "considerations": {}
413022          }
413023        },
413024        {
413025          "type": "library",
413026          "bom-ref": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=24c6089b81ca7d19",
413027          "supplier": {},
413028          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
413029          "name": "musl",
413030          "version": "1.2.3-r2",
413031          "description": "the musl c library (libc) implementation",
413032          "licenses": [
413033            {
413034              "license": {
413035                "id": "MIT"
413036              }
413037            }
413038          ],
413039          "cpe": "cpe:2.3:a:musl-libc:musl:1.2.3-r2:*:*:*:*:*:*:*",
413040          "purl": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64\u0026distro=alpine-3.16.5",
413041          "swid": {
413042            "attachment": {}
413043          },
413044          "pedigree": {},
413045          "externalReferences": [
413046            {
413047              "url": "https://musl.libc.org/",
413048              "type": "distribution"
413049            }
413050          ],
413051          "evidence": {},
413052          "signature": {
413053            "signature": {
413054              "publicKey": {}
413055            }
413056          },
413057          "modelCard": {
413058            "modelParameters": {
413059              "approach": {}
413060            },
413061            "quantitativeAnalysis": {
413062              "graphics": {}
413063            },
413064            "considerations": {}
413065          }
413066        },
413067        {
413068          "type": "library",
413069          "bom-ref": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5\u0026package-id=d33c14d727ae74d1",
413070          "supplier": {},
413071          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
413072          "name": "musl-utils",
413073          "version": "1.2.3-r2",
413074          "description": "the musl c library (libc) implementation",
413075          "licenses": [
413076            {
413077              "license": {
413078                "id": "MIT"
413079              }
413080            },
413081            {
413082              "license": {
413083                "name": "BSD"
413084              }
413085            },
413086            {
413087              "license": {
413088                "id": "GPL-2.0-or-later"
413089              }
413090            }
413091          ],
413092          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.2.3-r2:*:*:*:*:*:*:*",
413093          "purl": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.16.5",
413094          "swid": {
413095            "attachment": {}
413096          },
413097          "pedigree": {},
413098          "externalReferences": [
413099            {
413100              "url": "https://musl.libc.org/",
413101              "type": "distribution"
413102            }
413103          ],
413104          "evidence": {},
413105          "signature": {
413106            "signature": {
413107              "publicKey": {}
413108            }
413109          },
413110          "modelCard": {
413111            "modelParameters": {
413112              "approach": {}
413113            },
413114            "quantitativeAnalysis": {
413115              "graphics": {}
413116            },
413117            "considerations": {}
413118          }
413119        },
413120        {
413121          "type": "library",
413122          "bom-ref": "pkg:apk/alpine/ncurses-libs@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5\u0026package-id=c2bd1192d3d60d2c",
413123          "supplier": {},
413124          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413125          "name": "ncurses-libs",
413126          "version": "6.3_p20220521-r0",
413127          "description": "Ncurses libraries",
413128          "licenses": [
413129            {
413130              "license": {
413131                "id": "MIT"
413132              }
413133            }
413134          ],
413135          "cpe": "cpe:2.3:a:ncurses-libs:ncurses-libs:6.3_p20220521-r0:*:*:*:*:*:*:*",
413136          "purl": "pkg:apk/alpine/ncurses-libs@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5",
413137          "swid": {
413138            "attachment": {}
413139          },
413140          "pedigree": {},
413141          "externalReferences": [
413142            {
413143              "url": "https://invisible-island.net/ncurses/",
413144              "type": "distribution"
413145            }
413146          ],
413147          "evidence": {},
413148          "signature": {
413149            "signature": {
413150              "publicKey": {}
413151            }
413152          },
413153          "modelCard": {
413154            "modelParameters": {
413155              "approach": {}
413156            },
413157            "quantitativeAnalysis": {
413158              "graphics": {}
413159            },
413160            "considerations": {}
413161          }
413162        },
413163        {
413164          "type": "library",
413165          "bom-ref": "pkg:apk/alpine/ncurses-terminfo-base@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5\u0026package-id=28679685d0eccfdc",
413166          "supplier": {},
413167          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413168          "name": "ncurses-terminfo-base",
413169          "version": "6.3_p20220521-r0",
413170          "description": "Descriptions of common terminals",
413171          "licenses": [
413172            {
413173              "license": {
413174                "id": "MIT"
413175              }
413176            }
413177          ],
413178          "cpe": "cpe:2.3:a:ncurses-terminfo-base:ncurses-terminfo-base:6.3_p20220521-r0:*:*:*:*:*:*:*",
413179          "purl": "pkg:apk/alpine/ncurses-terminfo-base@6.3_p20220521-r0?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.16.5",
413180          "swid": {
413181            "attachment": {}
413182          },
413183          "pedigree": {},
413184          "externalReferences": [
413185            {
413186              "url": "https://invisible-island.net/ncurses/",
413187              "type": "distribution"
413188            }
413189          ],
413190          "evidence": {},
413191          "signature": {
413192            "signature": {
413193              "publicKey": {}
413194            }
413195          },
413196          "modelCard": {
413197            "modelParameters": {
413198              "approach": {}
413199            },
413200            "quantitativeAnalysis": {
413201              "graphics": {}
413202            },
413203            "considerations": {}
413204          }
413205        },
413206        {
413207          "type": "library",
413208          "bom-ref": "pkg:pypi/pip@22.0.4?package-id=2662dd9050ca781b",
413209          "supplier": {},
413210          "author": "The pip developers \u003cdistutils-sig@python.org\u003e",
413211          "name": "pip",
413212          "version": "22.0.4",
413213          "licenses": [
413214            {
413215              "license": {
413216                "id": "MIT"
413217              }
413218            }
413219          ],
413220          "cpe": "cpe:2.3:a:pip_developers_project:python-pip:22.0.4:*:*:*:*:*:*:*",
413221          "purl": "pkg:pypi/pip@22.0.4",
413222          "swid": {
413223            "attachment": {}
413224          },
413225          "pedigree": {},
413226          "evidence": {},
413227          "signature": {
413228            "signature": {
413229              "publicKey": {}
413230            }
413231          },
413232          "modelCard": {
413233            "modelParameters": {
413234              "approach": {}
413235            },
413236            "quantitativeAnalysis": {
413237              "graphics": {}
413238            },
413239            "considerations": {}
413240          }
413241        },
413242        {
413243          "type": "library",
413244          "bom-ref": "pkg:pypi/pip@23.0.1?package-id=68e46f2f44623ecc",
413245          "supplier": {},
413246          "author": "The pip developers \u003cdistutils-sig@python.org\u003e",
413247          "name": "pip",
413248          "version": "23.0.1",
413249          "licenses": [
413250            {
413251              "license": {
413252                "id": "MIT"
413253              }
413254            }
413255          ],
413256          "cpe": "cpe:2.3:a:pip_developers_project:python-pip:23.0.1:*:*:*:*:*:*:*",
413257          "purl": "pkg:pypi/pip@23.0.1",
413258          "swid": {
413259            "attachment": {}
413260          },
413261          "pedigree": {},
413262          "evidence": {},
413263          "signature": {
413264            "signature": {
413265              "publicKey": {}
413266            }
413267          },
413268          "modelCard": {
413269            "modelParameters": {
413270              "approach": {}
413271            },
413272            "quantitativeAnalysis": {
413273              "graphics": {}
413274            },
413275            "considerations": {}
413276          }
413277        },
413278        {
413279          "type": "application",
413280          "bom-ref": "pkg:generic/python@3.8.16?package-id=92f8822938c7aca6",
413281          "supplier": {},
413282          "name": "python",
413283          "version": "3.8.16",
413284          "cpe": "cpe:2.3:a:python_software_foundation:python:3.8.16:*:*:*:*:*:*:*",
413285          "purl": "pkg:generic/python@3.8.16",
413286          "swid": {
413287            "attachment": {}
413288          },
413289          "pedigree": {},
413290          "evidence": {},
413291          "signature": {
413292            "signature": {
413293              "publicKey": {}
413294            }
413295          },
413296          "modelCard": {
413297            "modelParameters": {
413298              "approach": {}
413299            },
413300            "quantitativeAnalysis": {
413301              "graphics": {}
413302            },
413303            "considerations": {}
413304          }
413305        },
413306        {
413307          "type": "library",
413308          "bom-ref": "pkg:pypi/pytz@2019.2?package-id=fc76e5768c01e894",
413309          "supplier": {},
413310          "author": "Stuart Bishop \u003cstuart@stuartbishop.net\u003e",
413311          "name": "pytz",
413312          "version": "2019.2",
413313          "licenses": [
413314            {
413315              "license": {
413316                "id": "MIT"
413317              }
413318            }
413319          ],
413320          "cpe": "cpe:2.3:a:stuart_bishop_project:python-pytz:2019.2:*:*:*:*:*:*:*",
413321          "purl": "pkg:pypi/pytz@2019.2",
413322          "swid": {
413323            "attachment": {}
413324          },
413325          "pedigree": {},
413326          "evidence": {},
413327          "signature": {
413328            "signature": {
413329              "publicKey": {}
413330            }
413331          },
413332          "modelCard": {
413333            "modelParameters": {
413334              "approach": {}
413335            },
413336            "quantitativeAnalysis": {
413337              "graphics": {}
413338            },
413339            "considerations": {}
413340          }
413341        },
413342        {
413343          "type": "library",
413344          "bom-ref": "pkg:apk/alpine/readline@8.1.2-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=bb734bcc27e60920",
413345          "supplier": {},
413346          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413347          "name": "readline",
413348          "version": "8.1.2-r0",
413349          "description": "GNU readline library",
413350          "licenses": [
413351            {
413352              "license": {
413353                "id": "GPL-2.0-or-later"
413354              }
413355            }
413356          ],
413357          "cpe": "cpe:2.3:a:readline:readline:8.1.2-r0:*:*:*:*:*:*:*",
413358          "purl": "pkg:apk/alpine/readline@8.1.2-r0?arch=x86_64\u0026distro=alpine-3.16.5",
413359          "swid": {
413360            "attachment": {}
413361          },
413362          "pedigree": {},
413363          "externalReferences": [
413364            {
413365              "url": "https://tiswww.cwru.edu/php/chet/readline/rltop.html",
413366              "type": "distribution"
413367            }
413368          ],
413369          "evidence": {},
413370          "signature": {
413371            "signature": {
413372              "publicKey": {}
413373            }
413374          },
413375          "modelCard": {
413376            "modelParameters": {
413377              "approach": {}
413378            },
413379            "quantitativeAnalysis": {
413380              "graphics": {}
413381            },
413382            "considerations": {}
413383          }
413384        },
413385        {
413386          "type": "library",
413387          "bom-ref": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5\u0026package-id=206fdb47b3e980eb",
413388          "supplier": {},
413389          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413390          "name": "scanelf",
413391          "version": "1.3.4-r0",
413392          "description": "Scan ELF binaries for stuff",
413393          "licenses": [
413394            {
413395              "license": {
413396                "id": "GPL-2.0-only"
413397              }
413398            }
413399          ],
413400          "cpe": "cpe:2.3:a:scanelf:scanelf:1.3.4-r0:*:*:*:*:*:*:*",
413401          "purl": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.16.5",
413402          "swid": {
413403            "attachment": {}
413404          },
413405          "pedigree": {},
413406          "externalReferences": [
413407            {
413408              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
413409              "type": "distribution"
413410            }
413411          ],
413412          "evidence": {},
413413          "signature": {
413414            "signature": {
413415              "publicKey": {}
413416            }
413417          },
413418          "modelCard": {
413419            "modelParameters": {
413420              "approach": {}
413421            },
413422            "quantitativeAnalysis": {
413423              "graphics": {}
413424            },
413425            "considerations": {}
413426          }
413427        },
413428        {
413429          "type": "library",
413430          "bom-ref": "pkg:pypi/setuptools@57.5.0?package-id=85835c335c6d8275",
413431          "supplier": {},
413432          "author": "Python Packaging Authority \u003cdistutils-sig@python.org\u003e",
413433          "name": "setuptools",
413434          "version": "57.5.0",
413435          "licenses": [
413436            {
413437              "license": {
413438                "name": "UNKNOWN"
413439              }
413440            }
413441          ],
413442          "cpe": "cpe:2.3:a:python_packaging_authority_project:python-setuptools:57.5.0:*:*:*:*:*:*:*",
413443          "purl": "pkg:pypi/setuptools@57.5.0",
413444          "swid": {
413445            "attachment": {}
413446          },
413447          "pedigree": {},
413448          "evidence": {},
413449          "signature": {
413450            "signature": {
413451              "publicKey": {}
413452            }
413453          },
413454          "modelCard": {
413455            "modelParameters": {
413456              "approach": {}
413457            },
413458            "quantitativeAnalysis": {
413459              "graphics": {}
413460            },
413461            "considerations": {}
413462          }
413463        },
413464        {
413465          "type": "library",
413466          "bom-ref": "pkg:pypi/six@1.12.0?package-id=140655f434a07d89",
413467          "supplier": {},
413468          "author": "Benjamin Peterson \u003cbenjamin@python.org\u003e",
413469          "name": "six",
413470          "version": "1.12.0",
413471          "licenses": [
413472            {
413473              "license": {
413474                "id": "MIT"
413475              }
413476            }
413477          ],
413478          "cpe": "cpe:2.3:a:benjamin_peterson_project:python-six:1.12.0:*:*:*:*:*:*:*",
413479          "purl": "pkg:pypi/six@1.12.0",
413480          "swid": {
413481            "attachment": {}
413482          },
413483          "pedigree": {},
413484          "evidence": {},
413485          "signature": {
413486            "signature": {
413487              "publicKey": {}
413488            }
413489          },
413490          "modelCard": {
413491            "modelParameters": {
413492              "approach": {}
413493            },
413494            "quantitativeAnalysis": {
413495              "graphics": {}
413496            },
413497            "considerations": {}
413498          }
413499        },
413500        {
413501          "type": "library",
413502          "bom-ref": "pkg:apk/alpine/sqlite-libs@3.38.5-r0?arch=x86_64\u0026upstream=sqlite\u0026distro=alpine-3.16.5\u0026package-id=6127833655f3995a",
413503          "supplier": {},
413504          "publisher": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e",
413505          "name": "sqlite-libs",
413506          "version": "3.38.5-r0",
413507          "description": "Sqlite3 library",
413508          "licenses": [
413509            {
413510              "license": {
413511                "id": "blessing"
413512              }
413513            }
413514          ],
413515          "cpe": "cpe:2.3:a:sqlite-libs:sqlite-libs:3.38.5-r0:*:*:*:*:*:*:*",
413516          "purl": "pkg:apk/alpine/sqlite-libs@3.38.5-r0?arch=x86_64\u0026upstream=sqlite\u0026distro=alpine-3.16.5",
413517          "swid": {
413518            "attachment": {}
413519          },
413520          "pedigree": {},
413521          "externalReferences": [
413522            {
413523              "url": "https://www.sqlite.org/",
413524              "type": "distribution"
413525            }
413526          ],
413527          "evidence": {},
413528          "signature": {
413529            "signature": {
413530              "publicKey": {}
413531            }
413532          },
413533          "modelCard": {
413534            "modelParameters": {
413535              "approach": {}
413536            },
413537            "quantitativeAnalysis": {
413538              "graphics": {}
413539            },
413540            "considerations": {}
413541          }
413542        },
413543        {
413544          "type": "library",
413545          "bom-ref": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5\u0026package-id=674d1e2fba4d633a",
413546          "supplier": {},
413547          "publisher": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e",
413548          "name": "ssl_client",
413549          "version": "1.35.0-r17",
413550          "description": "EXternal ssl_client for busybox wget",
413551          "licenses": [
413552            {
413553              "license": {
413554                "id": "GPL-2.0-only"
413555              }
413556            }
413557          ],
413558          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.35.0-r17:*:*:*:*:*:*:*",
413559          "purl": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.16.5",
413560          "swid": {
413561            "attachment": {}
413562          },
413563          "pedigree": {},
413564          "externalReferences": [
413565            {
413566              "url": "https://busybox.net/",
413567              "type": "distribution"
413568            }
413569          ],
413570          "evidence": {},
413571          "signature": {
413572            "signature": {
413573              "publicKey": {}
413574            }
413575          },
413576          "modelCard": {
413577            "modelParameters": {
413578              "approach": {}
413579            },
413580            "quantitativeAnalysis": {
413581              "graphics": {}
413582            },
413583            "considerations": {}
413584          }
413585        },
413586        {
413587          "type": "library",
413588          "bom-ref": "pkg:pypi/textfsm@1.1.0?package-id=d1ab92537b59f95e",
413589          "supplier": {},
413590          "name": "textfsm",
413591          "version": "1.1.0",
413592          "licenses": [
413593            {
413594              "license": {
413595                "name": "Apache License, Version 2.0"
413596              }
413597            }
413598          ],
413599          "cpe": "cpe:2.3:a:python-textfsm:python-textfsm:1.1.0:*:*:*:*:*:*:*",
413600          "purl": "pkg:pypi/textfsm@1.1.0",
413601          "swid": {
413602            "attachment": {}
413603          },
413604          "pedigree": {},
413605          "evidence": {},
413606          "signature": {
413607            "signature": {
413608              "publicKey": {}
413609            }
413610          },
413611          "modelCard": {
413612            "modelParameters": {
413613              "approach": {}
413614            },
413615            "quantitativeAnalysis": {
413616              "graphics": {}
413617            },
413618            "considerations": {}
413619          }
413620        },
413621        {
413622          "type": "library",
413623          "bom-ref": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=c6c9b0e0277783a2",
413624          "supplier": {},
413625          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413626          "name": "tzdata",
413627          "version": "2023c-r0",
413628          "description": "Timezone data",
413629          "licenses": [
413630            {
413631              "license": {
413632                "name": "Public-Domain"
413633              }
413634            }
413635          ],
413636          "cpe": "cpe:2.3:a:tzdata:tzdata:2023c-r0:*:*:*:*:*:*:*",
413637          "purl": "pkg:apk/alpine/tzdata@2023c-r0?arch=x86_64\u0026distro=alpine-3.16.5",
413638          "swid": {
413639            "attachment": {}
413640          },
413641          "pedigree": {},
413642          "externalReferences": [
413643            {
413644              "url": "https://www.iana.org/time-zones",
413645              "type": "distribution"
413646            }
413647          ],
413648          "evidence": {},
413649          "signature": {
413650            "signature": {
413651              "publicKey": {}
413652            }
413653          },
413654          "modelCard": {
413655            "modelParameters": {
413656              "approach": {}
413657            },
413658            "quantitativeAnalysis": {
413659              "graphics": {}
413660            },
413661            "considerations": {}
413662          }
413663        },
413664        {
413665          "type": "library",
413666          "bom-ref": "pkg:pypi/wheel@0.40.0?package-id=a5bbcb2514f67f7a",
413667          "supplier": {},
413668          "author": "Daniel Holth \u003cdholth@fastmail.fm\u003e",
413669          "name": "wheel",
413670          "version": "0.40.0",
413671          "cpe": "cpe:2.3:a:daniel_holth_\\\u003cdholth_project:python-wheel:0.40.0:*:*:*:*:*:*:*",
413672          "purl": "pkg:pypi/wheel@0.40.0",
413673          "swid": {
413674            "attachment": {}
413675          },
413676          "pedigree": {},
413677          "evidence": {},
413678          "signature": {
413679            "signature": {
413680              "publicKey": {}
413681            }
413682          },
413683          "modelCard": {
413684            "modelParameters": {
413685              "approach": {}
413686            },
413687            "quantitativeAnalysis": {
413688              "graphics": {}
413689            },
413690            "considerations": {}
413691          }
413692        },
413693        {
413694          "type": "library",
413695          "bom-ref": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.5\u0026package-id=168e14fa822d49a0",
413696          "supplier": {},
413697          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413698          "name": "xz-libs",
413699          "version": "5.2.5-r1",
413700          "description": "Library and CLI tools for XZ and LZMA compressed files (libraries)",
413701          "licenses": [
413702            {
413703              "license": {
413704                "id": "GPL-2.0-or-later"
413705              }
413706            },
413707            {
413708              "license": {
413709                "name": "AND"
413710              }
413711            },
413712            {
413713              "license": {
413714                "name": "Public-Domain"
413715              }
413716            },
413717            {
413718              "license": {
413719                "name": "AND"
413720              }
413721            },
413722            {
413723              "license": {
413724                "id": "LGPL-2.1-or-later"
413725              }
413726            }
413727          ],
413728          "cpe": "cpe:2.3:a:xz-libs:xz-libs:5.2.5-r1:*:*:*:*:*:*:*",
413729          "purl": "pkg:apk/alpine/xz-libs@5.2.5-r1?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.16.5",
413730          "swid": {
413731            "attachment": {}
413732          },
413733          "pedigree": {},
413734          "externalReferences": [
413735            {
413736              "url": "https://tukaani.org/xz",
413737              "type": "distribution"
413738            }
413739          ],
413740          "evidence": {},
413741          "signature": {
413742            "signature": {
413743              "publicKey": {}
413744            }
413745          },
413746          "modelCard": {
413747            "modelParameters": {
413748              "approach": {}
413749            },
413750            "quantitativeAnalysis": {
413751              "graphics": {}
413752            },
413753            "considerations": {}
413754          }
413755        },
413756        {
413757          "type": "library",
413758          "bom-ref": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5\u0026package-id=75f0d92f695b4303",
413759          "supplier": {},
413760          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413761          "name": "zlib",
413762          "version": "1.2.12-r3",
413763          "description": "A compression/decompression Library",
413764          "licenses": [
413765            {
413766              "license": {
413767                "id": "Zlib"
413768              }
413769            }
413770          ],
413771          "cpe": "cpe:2.3:a:zlib:zlib:1.2.12-r3:*:*:*:*:*:*:*",
413772          "purl": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64\u0026distro=alpine-3.16.5",
413773          "swid": {
413774            "attachment": {}
413775          },
413776          "pedigree": {},
413777          "externalReferences": [
413778            {
413779              "url": "https://zlib.net/",
413780              "type": "distribution"
413781            }
413782          ],
413783          "evidence": {},
413784          "signature": {
413785            "signature": {
413786              "publicKey": {}
413787            }
413788          },
413789          "modelCard": {
413790            "modelParameters": {
413791              "approach": {}
413792            },
413793            "quantitativeAnalysis": {
413794              "graphics": {}
413795            },
413796            "considerations": {}
413797          }
413798        },
413799        {
413800          "type": "operating-system",
413801          "supplier": {},
413802          "name": "alpine",
413803          "version": "3.16.5",
413804          "description": "Alpine Linux v3.16",
413805          "swid": {
413806            "tagId": "alpine",
413807            "name": "alpine",
413808            "version": "3.16.5",
413809            "attachment": {}
413810          },
413811          "pedigree": {},
413812          "externalReferences": [
413813            {
413814              "url": "https://gitlab.alpinelinux.org/alpine/aports/-/issues",
413815              "type": "issue-tracker"
413816            },
413817            {
413818              "url": "https://alpinelinux.org/",
413819              "type": "website"
413820            }
413821          ],
413822          "evidence": {},
413823          "signature": {
413824            "signature": {
413825              "publicKey": {}
413826            }
413827          },
413828          "modelCard": {
413829            "modelParameters": {
413830              "approach": {}
413831            },
413832            "quantitativeAnalysis": {
413833              "graphics": {}
413834            },
413835            "considerations": {}
413836          }
413837        },
413838        {
413839          "type": "library",
413840          "bom-ref": "pkg:apk/alpine/alpine-baselayout@3.2.0-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=61f27796f703939",
413841          "supplier": {},
413842          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413843          "name": "alpine-baselayout",
413844          "version": "3.2.0-r3",
413845          "description": "Alpine base dir structure and init scripts",
413846          "licenses": [
413847            {
413848              "license": {
413849                "id": "GPL-2.0-only"
413850              }
413851            }
413852          ],
413853          "cpe": "cpe:2.3:a:alpine-baselayout:alpine-baselayout:3.2.0-r3:*:*:*:*:*:*:*",
413854          "purl": "pkg:apk/alpine/alpine-baselayout@3.2.0-r3?arch=x86_64\u0026distro=alpine-3.11.13",
413855          "swid": {
413856            "attachment": {}
413857          },
413858          "pedigree": {},
413859          "externalReferences": [
413860            {
413861              "url": "https://git.alpinelinux.org/cgit/aports/tree/main/alpine-baselayout",
413862              "type": "distribution"
413863            }
413864          ],
413865          "evidence": {},
413866          "signature": {
413867            "signature": {
413868              "publicKey": {}
413869            }
413870          },
413871          "modelCard": {
413872            "modelParameters": {
413873              "approach": {}
413874            },
413875            "quantitativeAnalysis": {
413876              "graphics": {}
413877            },
413878            "considerations": {}
413879          }
413880        },
413881        {
413882          "type": "library",
413883          "bom-ref": "pkg:apk/alpine/alpine-keys@2.1-r2?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=79f884384758c443",
413884          "supplier": {},
413885          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413886          "name": "alpine-keys",
413887          "version": "2.1-r2",
413888          "description": "Public keys for Alpine Linux packages",
413889          "licenses": [
413890            {
413891              "license": {
413892                "id": "MIT"
413893              }
413894            }
413895          ],
413896          "cpe": "cpe:2.3:a:alpine-keys:alpine-keys:2.1-r2:*:*:*:*:*:*:*",
413897          "purl": "pkg:apk/alpine/alpine-keys@2.1-r2?arch=x86_64\u0026distro=alpine-3.11.13",
413898          "swid": {
413899            "attachment": {}
413900          },
413901          "pedigree": {},
413902          "externalReferences": [
413903            {
413904              "url": "https://alpinelinux.org",
413905              "type": "distribution"
413906            }
413907          ],
413908          "evidence": {},
413909          "signature": {
413910            "signature": {
413911              "publicKey": {}
413912            }
413913          },
413914          "modelCard": {
413915            "modelParameters": {
413916              "approach": {}
413917            },
413918            "quantitativeAnalysis": {
413919              "graphics": {}
413920            },
413921            "considerations": {}
413922          }
413923        },
413924        {
413925          "type": "library",
413926          "bom-ref": "pkg:apk/alpine/apk-tools@2.10.8-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=28993d8277c2c4f",
413927          "supplier": {},
413928          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413929          "name": "apk-tools",
413930          "version": "2.10.8-r0",
413931          "description": "Alpine Package Keeper - package manager for alpine",
413932          "licenses": [
413933            {
413934              "license": {
413935                "id": "GPL-2.0-only"
413936              }
413937            }
413938          ],
413939          "cpe": "cpe:2.3:a:apk-tools:apk-tools:2.10.8-r0:*:*:*:*:*:*:*",
413940          "purl": "pkg:apk/alpine/apk-tools@2.10.8-r0?arch=x86_64\u0026distro=alpine-3.11.13",
413941          "swid": {
413942            "attachment": {}
413943          },
413944          "pedigree": {},
413945          "externalReferences": [
413946            {
413947              "url": "https://gitlab.alpinelinux.org/alpine/apk-tools",
413948              "type": "distribution"
413949            }
413950          ],
413951          "evidence": {},
413952          "signature": {
413953            "signature": {
413954              "publicKey": {}
413955            }
413956          },
413957          "modelCard": {
413958            "modelParameters": {
413959              "approach": {}
413960            },
413961            "quantitativeAnalysis": {
413962              "graphics": {}
413963            },
413964            "considerations": {}
413965          }
413966        },
413967        {
413968          "type": "library",
413969          "bom-ref": "pkg:apk/alpine/avahi-libs@0.7-r5?arch=x86_64\u0026upstream=avahi\u0026distro=alpine-3.11.13\u0026package-id=8b264d724369ba2d",
413970          "supplier": {},
413971          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
413972          "name": "avahi-libs",
413973          "version": "0.7-r5",
413974          "description": "Libraries for avahi run-time use",
413975          "licenses": [
413976            {
413977              "license": {
413978                "id": "LGPL-2.0-or-later"
413979              }
413980            }
413981          ],
413982          "cpe": "cpe:2.3:a:avahi-libs:avahi-libs:0.7-r5:*:*:*:*:*:*:*",
413983          "purl": "pkg:apk/alpine/avahi-libs@0.7-r5?arch=x86_64\u0026upstream=avahi\u0026distro=alpine-3.11.13",
413984          "swid": {
413985            "attachment": {}
413986          },
413987          "pedigree": {},
413988          "externalReferences": [
413989            {
413990              "url": "https://www.avahi.org/",
413991              "type": "distribution"
413992            }
413993          ],
413994          "evidence": {},
413995          "signature": {
413996            "signature": {
413997              "publicKey": {}
413998            }
413999          },
414000          "modelCard": {
414001            "modelParameters": {
414002              "approach": {}
414003            },
414004            "quantitativeAnalysis": {
414005              "graphics": {}
414006            },
414007            "considerations": {}
414008          }
414009        },
414010        {
414011          "type": "library",
414012          "bom-ref": "pkg:apk/alpine/bind-libs@9.16.20-r1?arch=x86_64\u0026upstream=bind\u0026distro=alpine-3.11.13\u0026package-id=88c39fdfa1f591d",
414013          "supplier": {},
414014          "name": "bind-libs",
414015          "version": "9.16.20-r1",
414016          "description": "The ISC DNS server (libraries)",
414017          "licenses": [
414018            {
414019              "license": {
414020                "id": "MPL-2.0"
414021              }
414022            }
414023          ],
414024          "cpe": "cpe:2.3:a:bind-libs:bind-libs:9.16.20-r1:*:*:*:*:*:*:*",
414025          "purl": "pkg:apk/alpine/bind-libs@9.16.20-r1?arch=x86_64\u0026upstream=bind\u0026distro=alpine-3.11.13",
414026          "swid": {
414027            "attachment": {}
414028          },
414029          "pedigree": {},
414030          "externalReferences": [
414031            {
414032              "url": "https://www.isc.org/",
414033              "type": "distribution"
414034            }
414035          ],
414036          "evidence": {},
414037          "signature": {
414038            "signature": {
414039              "publicKey": {}
414040            }
414041          },
414042          "modelCard": {
414043            "modelParameters": {
414044              "approach": {}
414045            },
414046            "quantitativeAnalysis": {
414047              "graphics": {}
414048            },
414049            "considerations": {}
414050          }
414051        },
414052        {
414053          "type": "library",
414054          "bom-ref": "pkg:apk/alpine/bind-tools@9.16.20-r1?arch=x86_64\u0026upstream=bind\u0026distro=alpine-3.11.13\u0026package-id=28f669bd3e8e0a01",
414055          "supplier": {},
414056          "name": "bind-tools",
414057          "version": "9.16.20-r1",
414058          "description": "The ISC DNS tools",
414059          "licenses": [
414060            {
414061              "license": {
414062                "id": "MPL-2.0"
414063              }
414064            }
414065          ],
414066          "cpe": "cpe:2.3:a:bind-tools:bind-tools:9.16.20-r1:*:*:*:*:*:*:*",
414067          "purl": "pkg:apk/alpine/bind-tools@9.16.20-r1?arch=x86_64\u0026upstream=bind\u0026distro=alpine-3.11.13",
414068          "swid": {
414069            "attachment": {}
414070          },
414071          "pedigree": {},
414072          "externalReferences": [
414073            {
414074              "url": "https://www.isc.org/",
414075              "type": "distribution"
414076            }
414077          ],
414078          "evidence": {},
414079          "signature": {
414080            "signature": {
414081              "publicKey": {}
414082            }
414083          },
414084          "modelCard": {
414085            "modelParameters": {
414086              "approach": {}
414087            },
414088            "quantitativeAnalysis": {
414089              "graphics": {}
414090            },
414091            "considerations": {}
414092          }
414093        },
414094        {
414095          "type": "application",
414096          "bom-ref": "eb62c645e9680ee0",
414097          "supplier": {},
414098          "name": "busybox",
414099          "version": "1.31.1",
414100          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1:*:*:*:*:*:*:*",
414101          "swid": {
414102            "attachment": {}
414103          },
414104          "pedigree": {},
414105          "evidence": {},
414106          "signature": {
414107            "signature": {
414108              "publicKey": {}
414109            }
414110          },
414111          "modelCard": {
414112            "modelParameters": {
414113              "approach": {}
414114            },
414115            "quantitativeAnalysis": {
414116              "graphics": {}
414117            },
414118            "considerations": {}
414119          }
414120        },
414121        {
414122          "type": "library",
414123          "bom-ref": "pkg:apk/alpine/busybox@1.31.1-r11?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=3f3095cbef6e353",
414124          "supplier": {},
414125          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414126          "name": "busybox",
414127          "version": "1.31.1-r11",
414128          "description": "Size optimized toolbox of many common UNIX utilities",
414129          "licenses": [
414130            {
414131              "license": {
414132                "id": "GPL-2.0-only"
414133              }
414134            }
414135          ],
414136          "cpe": "cpe:2.3:a:busybox:busybox:1.31.1-r11:*:*:*:*:*:*:*",
414137          "purl": "pkg:apk/alpine/busybox@1.31.1-r11?arch=x86_64\u0026distro=alpine-3.11.13",
414138          "swid": {
414139            "attachment": {}
414140          },
414141          "pedigree": {},
414142          "externalReferences": [
414143            {
414144              "url": "https://busybox.net/",
414145              "type": "distribution"
414146            }
414147          ],
414148          "evidence": {},
414149          "signature": {
414150            "signature": {
414151              "publicKey": {}
414152            }
414153          },
414154          "modelCard": {
414155            "modelParameters": {
414156              "approach": {}
414157            },
414158            "quantitativeAnalysis": {
414159              "graphics": {}
414160            },
414161            "considerations": {}
414162          }
414163        },
414164        {
414165          "type": "library",
414166          "bom-ref": "pkg:apk/alpine/ca-certificates@20191127-r2?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=91490583c2f9b81b",
414167          "supplier": {},
414168          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414169          "name": "ca-certificates",
414170          "version": "20191127-r2",
414171          "description": "Common CA certificates PEM files from Mozilla",
414172          "licenses": [
414173            {
414174              "license": {
414175                "id": "MPL-2.0"
414176              }
414177            },
414178            {
414179              "license": {
414180                "id": "GPL-2.0-or-later"
414181              }
414182            }
414183          ],
414184          "cpe": "cpe:2.3:a:ca-certificates:ca-certificates:20191127-r2:*:*:*:*:*:*:*",
414185          "purl": "pkg:apk/alpine/ca-certificates@20191127-r2?arch=x86_64\u0026distro=alpine-3.11.13",
414186          "swid": {
414187            "attachment": {}
414188          },
414189          "pedigree": {},
414190          "externalReferences": [
414191            {
414192              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
414193              "type": "distribution"
414194            }
414195          ],
414196          "evidence": {},
414197          "signature": {
414198            "signature": {
414199              "publicKey": {}
414200            }
414201          },
414202          "modelCard": {
414203            "modelParameters": {
414204              "approach": {}
414205            },
414206            "quantitativeAnalysis": {
414207              "graphics": {}
414208            },
414209            "considerations": {}
414210          }
414211        },
414212        {
414213          "type": "library",
414214          "bom-ref": "pkg:apk/alpine/ca-certificates-cacert@20191127-r2?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.11.13\u0026package-id=e135ce85ed757130",
414215          "supplier": {},
414216          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414217          "name": "ca-certificates-cacert",
414218          "version": "20191127-r2",
414219          "description": "Mozilla bundled certificates",
414220          "licenses": [
414221            {
414222              "license": {
414223                "id": "MPL-2.0"
414224              }
414225            },
414226            {
414227              "license": {
414228                "id": "GPL-2.0-or-later"
414229              }
414230            }
414231          ],
414232          "cpe": "cpe:2.3:a:ca-certificates-cacert:ca-certificates-cacert:20191127-r2:*:*:*:*:*:*:*",
414233          "purl": "pkg:apk/alpine/ca-certificates-cacert@20191127-r2?arch=x86_64\u0026upstream=ca-certificates\u0026distro=alpine-3.11.13",
414234          "swid": {
414235            "attachment": {}
414236          },
414237          "pedigree": {},
414238          "externalReferences": [
414239            {
414240              "url": "https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/",
414241              "type": "distribution"
414242            }
414243          ],
414244          "evidence": {},
414245          "signature": {
414246            "signature": {
414247              "publicKey": {}
414248            }
414249          },
414250          "modelCard": {
414251            "modelParameters": {
414252              "approach": {}
414253            },
414254            "quantitativeAnalysis": {
414255              "graphics": {}
414256            },
414257            "considerations": {}
414258          }
414259        },
414260        {
414261          "type": "library",
414262          "bom-ref": "pkg:apk/alpine/cups-libs@2.2.12-r2?arch=x86_64\u0026upstream=cups\u0026distro=alpine-3.11.13\u0026package-id=c6227a4b1413821d",
414263          "supplier": {},
414264          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414265          "name": "cups-libs",
414266          "version": "2.2.12-r2",
414267          "description": "CUPS libraries",
414268          "licenses": [
414269            {
414270              "license": {
414271                "id": "GPL-2.0-only"
414272              }
414273            }
414274          ],
414275          "cpe": "cpe:2.3:a:cups-libs:cups-libs:2.2.12-r2:*:*:*:*:*:*:*",
414276          "purl": "pkg:apk/alpine/cups-libs@2.2.12-r2?arch=x86_64\u0026upstream=cups\u0026distro=alpine-3.11.13",
414277          "swid": {
414278            "attachment": {}
414279          },
414280          "pedigree": {},
414281          "externalReferences": [
414282            {
414283              "url": "https://www.cups.org/",
414284              "type": "distribution"
414285            }
414286          ],
414287          "evidence": {},
414288          "signature": {
414289            "signature": {
414290              "publicKey": {}
414291            }
414292          },
414293          "modelCard": {
414294            "modelParameters": {
414295              "approach": {}
414296            },
414297            "quantitativeAnalysis": {
414298              "graphics": {}
414299            },
414300            "considerations": {}
414301          }
414302        },
414303        {
414304          "type": "library",
414305          "bom-ref": "pkg:apk/alpine/curl@7.79.1-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=d9c1833e179a6443",
414306          "supplier": {},
414307          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414308          "name": "curl",
414309          "version": "7.79.1-r0",
414310          "description": "URL retrival utility and library",
414311          "licenses": [
414312            {
414313              "license": {
414314                "id": "MIT"
414315              }
414316            }
414317          ],
414318          "cpe": "cpe:2.3:a:curl:curl:7.79.1-r0:*:*:*:*:*:*:*",
414319          "purl": "pkg:apk/alpine/curl@7.79.1-r0?arch=x86_64\u0026distro=alpine-3.11.13",
414320          "swid": {
414321            "attachment": {}
414322          },
414323          "pedigree": {},
414324          "externalReferences": [
414325            {
414326              "url": "https://curl.haxx.se/",
414327              "type": "distribution"
414328            }
414329          ],
414330          "evidence": {},
414331          "signature": {
414332            "signature": {
414333              "publicKey": {}
414334            }
414335          },
414336          "modelCard": {
414337            "modelParameters": {
414338              "approach": {}
414339            },
414340            "quantitativeAnalysis": {
414341              "graphics": {}
414342            },
414343            "considerations": {}
414344          }
414345        },
414346        {
414347          "type": "library",
414348          "bom-ref": "pkg:apk/alpine/db@5.3.28-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=66e170c74bc97a1b",
414349          "supplier": {},
414350          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414351          "name": "db",
414352          "version": "5.3.28-r1",
414353          "description": "The Berkeley DB embedded database system",
414354          "licenses": [
414355            {
414356              "license": {
414357                "name": "custom"
414358              }
414359            }
414360          ],
414361          "cpe": "cpe:2.3:a:db:db:5.3.28-r1:*:*:*:*:*:*:*",
414362          "purl": "pkg:apk/alpine/db@5.3.28-r1?arch=x86_64\u0026distro=alpine-3.11.13",
414363          "swid": {
414364            "attachment": {}
414365          },
414366          "pedigree": {},
414367          "externalReferences": [
414368            {
414369              "url": "https://www.oracle.com/technology/software/products/berkeley-db/index.html",
414370              "type": "distribution"
414371            }
414372          ],
414373          "evidence": {},
414374          "signature": {
414375            "signature": {
414376              "publicKey": {}
414377            }
414378          },
414379          "modelCard": {
414380            "modelParameters": {
414381              "approach": {}
414382            },
414383            "quantitativeAnalysis": {
414384              "graphics": {}
414385            },
414386            "considerations": {}
414387          }
414388        },
414389        {
414390          "type": "library",
414391          "bom-ref": "pkg:apk/alpine/dbus-libs@1.12.16-r3?arch=x86_64\u0026upstream=dbus\u0026distro=alpine-3.11.13\u0026package-id=69c109976263e0a",
414392          "supplier": {},
414393          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414394          "name": "dbus-libs",
414395          "version": "1.12.16-r3",
414396          "description": "D-BUS access libraries",
414397          "licenses": [
414398            {
414399              "license": {
414400                "id": "AFL-2.1"
414401              }
414402            },
414403            {
414404              "license": {
414405                "name": "OR"
414406              }
414407            },
414408            {
414409              "license": {
414410                "id": "GPL-2.0-or-later"
414411              }
414412            }
414413          ],
414414          "cpe": "cpe:2.3:a:dbus-libs:dbus-libs:1.12.16-r3:*:*:*:*:*:*:*",
414415          "purl": "pkg:apk/alpine/dbus-libs@1.12.16-r3?arch=x86_64\u0026upstream=dbus\u0026distro=alpine-3.11.13",
414416          "swid": {
414417            "attachment": {}
414418          },
414419          "pedigree": {},
414420          "externalReferences": [
414421            {
414422              "url": "https://www.freedesktop.org/Software/dbus",
414423              "type": "distribution"
414424            }
414425          ],
414426          "evidence": {},
414427          "signature": {
414428            "signature": {
414429              "publicKey": {}
414430            }
414431          },
414432          "modelCard": {
414433            "modelParameters": {
414434              "approach": {}
414435            },
414436            "quantitativeAnalysis": {
414437              "graphics": {}
414438            },
414439            "considerations": {}
414440          }
414441        },
414442        {
414443          "type": "library",
414444          "bom-ref": "pkg:apk/alpine/expat@2.2.9-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=a22412a0d67882a",
414445          "supplier": {},
414446          "publisher": "Carlo Landmeter \u003cclandmeter@gmail.com\u003e",
414447          "name": "expat",
414448          "version": "2.2.9-r1",
414449          "description": "An XML Parser library written in C",
414450          "licenses": [
414451            {
414452              "license": {
414453                "id": "MIT"
414454              }
414455            }
414456          ],
414457          "cpe": "cpe:2.3:a:expat:expat:2.2.9-r1:*:*:*:*:*:*:*",
414458          "purl": "pkg:apk/alpine/expat@2.2.9-r1?arch=x86_64\u0026distro=alpine-3.11.13",
414459          "swid": {
414460            "attachment": {}
414461          },
414462          "pedigree": {},
414463          "externalReferences": [
414464            {
414465              "url": "http://www.libexpat.org/",
414466              "type": "distribution"
414467            }
414468          ],
414469          "evidence": {},
414470          "signature": {
414471            "signature": {
414472              "publicKey": {}
414473            }
414474          },
414475          "modelCard": {
414476            "modelParameters": {
414477              "approach": {}
414478            },
414479            "quantitativeAnalysis": {
414480              "graphics": {}
414481            },
414482            "considerations": {}
414483          }
414484        },
414485        {
414486          "type": "library",
414487          "bom-ref": "pkg:apk/alpine/fstrm@0.6.0-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=17609d4a84d9ddcf",
414488          "supplier": {},
414489          "name": "fstrm",
414490          "version": "0.6.0-r1",
414491          "description": "Frame Streams implementation in C",
414492          "licenses": [
414493            {
414494              "license": {
414495                "id": "MIT"
414496              }
414497            }
414498          ],
414499          "cpe": "cpe:2.3:a:farsightsec:fstrm:0.6.0-r1:*:*:*:*:*:*:*",
414500          "purl": "pkg:apk/alpine/fstrm@0.6.0-r1?arch=x86_64\u0026distro=alpine-3.11.13",
414501          "swid": {
414502            "attachment": {}
414503          },
414504          "pedigree": {},
414505          "externalReferences": [
414506            {
414507              "url": "https://github.com/farsightsec/fstrm",
414508              "type": "distribution"
414509            }
414510          ],
414511          "evidence": {},
414512          "signature": {
414513            "signature": {
414514              "publicKey": {}
414515            }
414516          },
414517          "modelCard": {
414518            "modelParameters": {
414519              "approach": {}
414520            },
414521            "quantitativeAnalysis": {
414522              "graphics": {}
414523            },
414524            "considerations": {}
414525          }
414526        },
414527        {
414528          "type": "library",
414529          "bom-ref": "pkg:apk/alpine/gmp@6.1.2-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=63a62a4cce7589e",
414530          "supplier": {},
414531          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414532          "name": "gmp",
414533          "version": "6.1.2-r1",
414534          "description": "A free library for arbitrary precision arithmetic",
414535          "licenses": [
414536            {
414537              "license": {
414538                "id": "LGPL-3.0-only"
414539              }
414540            }
414541          ],
414542          "cpe": "cpe:2.3:a:gmp:gmp:6.1.2-r1:*:*:*:*:*:*:*",
414543          "purl": "pkg:apk/alpine/gmp@6.1.2-r1?arch=x86_64\u0026distro=alpine-3.11.13",
414544          "swid": {
414545            "attachment": {}
414546          },
414547          "pedigree": {},
414548          "externalReferences": [
414549            {
414550              "url": "https://gmplib.org/",
414551              "type": "distribution"
414552            }
414553          ],
414554          "evidence": {},
414555          "signature": {
414556            "signature": {
414557              "publicKey": {}
414558            }
414559          },
414560          "modelCard": {
414561            "modelParameters": {
414562              "approach": {}
414563            },
414564            "quantitativeAnalysis": {
414565              "graphics": {}
414566            },
414567            "considerations": {}
414568          }
414569        },
414570        {
414571          "type": "library",
414572          "bom-ref": "pkg:apk/alpine/gnutls@3.6.15-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=142615926eb369bd",
414573          "supplier": {},
414574          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414575          "name": "gnutls",
414576          "version": "3.6.15-r1",
414577          "description": "A TLS protocol implementation",
414578          "licenses": [
414579            {
414580              "license": {
414581                "id": "GPL-3.0-or-later"
414582              }
414583            }
414584          ],
414585          "cpe": "cpe:2.3:a:gnutls:gnutls:3.6.15-r1:*:*:*:*:*:*:*",
414586          "purl": "pkg:apk/alpine/gnutls@3.6.15-r1?arch=x86_64\u0026distro=alpine-3.11.13",
414587          "swid": {
414588            "attachment": {}
414589          },
414590          "pedigree": {},
414591          "externalReferences": [
414592            {
414593              "url": "https://www.gnutls.org/",
414594              "type": "distribution"
414595            }
414596          ],
414597          "evidence": {},
414598          "signature": {
414599            "signature": {
414600              "publicKey": {}
414601            }
414602          },
414603          "modelCard": {
414604            "modelParameters": {
414605              "approach": {}
414606            },
414607            "quantitativeAnalysis": {
414608              "graphics": {}
414609            },
414610            "considerations": {}
414611          }
414612        },
414613        {
414614          "type": "library",
414615          "bom-ref": "pkg:apk/alpine/ipmitool@1.8.18-r9?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=838a810dc405bccb",
414616          "supplier": {},
414617          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414618          "name": "ipmitool",
414619          "version": "1.8.18-r9",
414620          "description": "Command-line interface to IPMI-enabled devices",
414621          "licenses": [
414622            {
414623              "license": {
414624                "id": "MIT"
414625              }
414626            }
414627          ],
414628          "cpe": "cpe:2.3:a:ipmitool:ipmitool:1.8.18-r9:*:*:*:*:*:*:*",
414629          "purl": "pkg:apk/alpine/ipmitool@1.8.18-r9?arch=x86_64\u0026distro=alpine-3.11.13",
414630          "swid": {
414631            "attachment": {}
414632          },
414633          "pedigree": {},
414634          "externalReferences": [
414635            {
414636              "url": "https://github.com/ipmitool/ipmitool",
414637              "type": "distribution"
414638            }
414639          ],
414640          "evidence": {},
414641          "signature": {
414642            "signature": {
414643              "publicKey": {}
414644            }
414645          },
414646          "modelCard": {
414647            "modelParameters": {
414648              "approach": {}
414649            },
414650            "quantitativeAnalysis": {
414651              "graphics": {}
414652            },
414653            "considerations": {}
414654          }
414655        },
414656        {
414657          "type": "library",
414658          "bom-ref": "pkg:apk/alpine/jansson@2.12-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=8ae8607352e1db81",
414659          "supplier": {},
414660          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414661          "name": "jansson",
414662          "version": "2.12-r0",
414663          "description": "lightweight JSON library",
414664          "licenses": [
414665            {
414666              "license": {
414667                "id": "MIT"
414668              }
414669            }
414670          ],
414671          "cpe": "cpe:2.3:a:jansson:jansson:2.12-r0:*:*:*:*:*:*:*",
414672          "purl": "pkg:apk/alpine/jansson@2.12-r0?arch=x86_64\u0026distro=alpine-3.11.13",
414673          "swid": {
414674            "attachment": {}
414675          },
414676          "pedigree": {},
414677          "externalReferences": [
414678            {
414679              "url": "http://www.digip.org/jansson/",
414680              "type": "distribution"
414681            }
414682          ],
414683          "evidence": {},
414684          "signature": {
414685            "signature": {
414686              "publicKey": {}
414687            }
414688          },
414689          "modelCard": {
414690            "modelParameters": {
414691              "approach": {}
414692            },
414693            "quantitativeAnalysis": {
414694              "graphics": {}
414695            },
414696            "considerations": {}
414697          }
414698        },
414699        {
414700          "type": "library",
414701          "bom-ref": "pkg:apk/alpine/json-c@0.13.1-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=61b3e0650cbd3f19",
414702          "supplier": {},
414703          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414704          "name": "json-c",
414705          "version": "0.13.1-r1",
414706          "description": "A JSON implementation in C",
414707          "licenses": [
414708            {
414709              "license": {
414710                "id": "MIT"
414711              }
414712            }
414713          ],
414714          "cpe": "cpe:2.3:a:json-c:json-c:0.13.1-r1:*:*:*:*:*:*:*",
414715          "purl": "pkg:apk/alpine/json-c@0.13.1-r1?arch=x86_64\u0026distro=alpine-3.11.13",
414716          "swid": {
414717            "attachment": {}
414718          },
414719          "pedigree": {},
414720          "externalReferences": [
414721            {
414722              "url": "https://github.com/json-c/json-c/wiki",
414723              "type": "distribution"
414724            }
414725          ],
414726          "evidence": {},
414727          "signature": {
414728            "signature": {
414729              "publicKey": {}
414730            }
414731          },
414732          "modelCard": {
414733            "modelParameters": {
414734              "approach": {}
414735            },
414736            "quantitativeAnalysis": {
414737              "graphics": {}
414738            },
414739            "considerations": {}
414740          }
414741        },
414742        {
414743          "type": "library",
414744          "bom-ref": "pkg:apk/alpine/keyutils-libs@1.6.1-r0?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.11.13\u0026package-id=1efd4d1e9196ab00",
414745          "supplier": {},
414746          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414747          "name": "keyutils-libs",
414748          "version": "1.6.1-r0",
414749          "description": "Key utilities library",
414750          "licenses": [
414751            {
414752              "license": {
414753                "id": "GPL-2.0-or-later"
414754              }
414755            },
414756            {
414757              "license": {
414758                "id": "LGPL-2.0-or-later"
414759              }
414760            }
414761          ],
414762          "cpe": "cpe:2.3:a:keyutils-libs:keyutils-libs:1.6.1-r0:*:*:*:*:*:*:*",
414763          "purl": "pkg:apk/alpine/keyutils-libs@1.6.1-r0?arch=x86_64\u0026upstream=keyutils\u0026distro=alpine-3.11.13",
414764          "swid": {
414765            "attachment": {}
414766          },
414767          "pedigree": {},
414768          "externalReferences": [
414769            {
414770              "url": "http://people.redhat.com/~dhowells/keyutils/",
414771              "type": "distribution"
414772            }
414773          ],
414774          "evidence": {},
414775          "signature": {
414776            "signature": {
414777              "publicKey": {}
414778            }
414779          },
414780          "modelCard": {
414781            "modelParameters": {
414782              "approach": {}
414783            },
414784            "quantitativeAnalysis": {
414785              "graphics": {}
414786            },
414787            "considerations": {}
414788          }
414789        },
414790        {
414791          "type": "library",
414792          "bom-ref": "pkg:apk/alpine/krb5-conf@1.0-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=8126b757ea2731fe",
414793          "supplier": {},
414794          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414795          "name": "krb5-conf",
414796          "version": "1.0-r1",
414797          "description": "Shared krb5.conf for both MIT krb5 and heimdal",
414798          "licenses": [
414799            {
414800              "license": {
414801                "id": "MIT"
414802              }
414803            }
414804          ],
414805          "cpe": "cpe:2.3:a:krb5-conf:krb5-conf:1.0-r1:*:*:*:*:*:*:*",
414806          "purl": "pkg:apk/alpine/krb5-conf@1.0-r1?arch=x86_64\u0026distro=alpine-3.11.13",
414807          "swid": {
414808            "attachment": {}
414809          },
414810          "pedigree": {},
414811          "externalReferences": [
414812            {
414813              "url": "http://web.mit.edu/kerberos/www/ http://h5l.org",
414814              "type": "distribution"
414815            }
414816          ],
414817          "evidence": {},
414818          "signature": {
414819            "signature": {
414820              "publicKey": {}
414821            }
414822          },
414823          "modelCard": {
414824            "modelParameters": {
414825              "approach": {}
414826            },
414827            "quantitativeAnalysis": {
414828              "graphics": {}
414829            },
414830            "considerations": {}
414831          }
414832        },
414833        {
414834          "type": "library",
414835          "bom-ref": "pkg:apk/alpine/krb5-libs@1.17.2-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.11.13\u0026package-id=403e9028bb6dcd42",
414836          "supplier": {},
414837          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414838          "name": "krb5-libs",
414839          "version": "1.17.2-r0",
414840          "description": "The shared libraries used by Kerberos 5",
414841          "licenses": [
414842            {
414843              "license": {
414844                "id": "MIT"
414845              }
414846            }
414847          ],
414848          "cpe": "cpe:2.3:a:krb5-libs:krb5-libs:1.17.2-r0:*:*:*:*:*:*:*",
414849          "purl": "pkg:apk/alpine/krb5-libs@1.17.2-r0?arch=x86_64\u0026upstream=krb5\u0026distro=alpine-3.11.13",
414850          "swid": {
414851            "attachment": {}
414852          },
414853          "pedigree": {},
414854          "externalReferences": [
414855            {
414856              "url": "https://web.mit.edu/kerberos/www/",
414857              "type": "distribution"
414858            }
414859          ],
414860          "evidence": {},
414861          "signature": {
414862            "signature": {
414863              "publicKey": {}
414864            }
414865          },
414866          "modelCard": {
414867            "modelParameters": {
414868              "approach": {}
414869            },
414870            "quantitativeAnalysis": {
414871              "graphics": {}
414872            },
414873            "considerations": {}
414874          }
414875        },
414876        {
414877          "type": "library",
414878          "bom-ref": "pkg:apk/alpine/ldb@2.0.12-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=4e8ed2b5121bfd53",
414879          "supplier": {},
414880          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414881          "name": "ldb",
414882          "version": "2.0.12-r0",
414883          "description": "A schema-less, ldap like, API and database",
414884          "licenses": [
414885            {
414886              "license": {
414887                "id": "LGPL-3.0-or-later"
414888              }
414889            }
414890          ],
414891          "cpe": "cpe:2.3:a:ldb:ldb:2.0.12-r0:*:*:*:*:*:*:*",
414892          "purl": "pkg:apk/alpine/ldb@2.0.12-r0?arch=x86_64\u0026distro=alpine-3.11.13",
414893          "swid": {
414894            "attachment": {}
414895          },
414896          "pedigree": {},
414897          "externalReferences": [
414898            {
414899              "url": "https://ldb.samba.org/",
414900              "type": "distribution"
414901            }
414902          ],
414903          "evidence": {},
414904          "signature": {
414905            "signature": {
414906              "publicKey": {}
414907            }
414908          },
414909          "modelCard": {
414910            "modelParameters": {
414911              "approach": {}
414912            },
414913            "quantitativeAnalysis": {
414914              "graphics": {}
414915            },
414916            "considerations": {}
414917          }
414918        },
414919        {
414920          "type": "library",
414921          "bom-ref": "pkg:apk/alpine/libacl@2.2.53-r0?arch=x86_64\u0026upstream=acl\u0026distro=alpine-3.11.13\u0026package-id=b1b4ec7e01d89822",
414922          "supplier": {},
414923          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
414924          "name": "libacl",
414925          "version": "2.2.53-r0",
414926          "description": "Dynamic library for access control list support",
414927          "licenses": [
414928            {
414929              "license": {
414930                "id": "LGPL-2.1-or-later"
414931              }
414932            },
414933            {
414934              "license": {
414935                "name": "AND"
414936              }
414937            },
414938            {
414939              "license": {
414940                "id": "GPL-2.0-or-later"
414941              }
414942            }
414943          ],
414944          "cpe": "cpe:2.3:a:libacl:libacl:2.2.53-r0:*:*:*:*:*:*:*",
414945          "purl": "pkg:apk/alpine/libacl@2.2.53-r0?arch=x86_64\u0026upstream=acl\u0026distro=alpine-3.11.13",
414946          "swid": {
414947            "attachment": {}
414948          },
414949          "pedigree": {},
414950          "externalReferences": [
414951            {
414952              "url": "https://savannah.nongnu.org/projects/acl",
414953              "type": "distribution"
414954            }
414955          ],
414956          "evidence": {},
414957          "signature": {
414958            "signature": {
414959              "publicKey": {}
414960            }
414961          },
414962          "modelCard": {
414963            "modelParameters": {
414964              "approach": {}
414965            },
414966            "quantitativeAnalysis": {
414967              "graphics": {}
414968            },
414969            "considerations": {}
414970          }
414971        },
414972        {
414973          "type": "library",
414974          "bom-ref": "pkg:apk/alpine/libaio@0.3.112-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=4e946045fe2c39a5",
414975          "supplier": {},
414976          "publisher": "Leonardo Arena \u003crnalrd@alpinelinux.org\u003e",
414977          "name": "libaio",
414978          "version": "0.3.112-r1",
414979          "description": "Asynchronous input/output library",
414980          "licenses": [
414981            {
414982              "license": {
414983                "id": "LGPL-2.1-or-later"
414984              }
414985            }
414986          ],
414987          "cpe": "cpe:2.3:a:libaio:libaio:0.3.112-r1:*:*:*:*:*:*:*",
414988          "purl": "pkg:apk/alpine/libaio@0.3.112-r1?arch=x86_64\u0026distro=alpine-3.11.13",
414989          "swid": {
414990            "attachment": {}
414991          },
414992          "pedigree": {},
414993          "externalReferences": [
414994            {
414995              "url": "https://pagure.io/libaio",
414996              "type": "distribution"
414997            }
414998          ],
414999          "evidence": {},
415000          "signature": {
415001            "signature": {
415002              "publicKey": {}
415003            }
415004          },
415005          "modelCard": {
415006            "modelParameters": {
415007              "approach": {}
415008            },
415009            "quantitativeAnalysis": {
415010              "graphics": {}
415011            },
415012            "considerations": {}
415013          }
415014        },
415015        {
415016          "type": "library",
415017          "bom-ref": "pkg:apk/alpine/libarchive@3.4.2-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=7916a505303813f5",
415018          "supplier": {},
415019          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415020          "name": "libarchive",
415021          "version": "3.4.2-r0",
415022          "description": "library that can create and read several streaming archive formats",
415023          "licenses": [
415024            {
415025              "license": {
415026                "id": "BSD-2-Clause"
415027              }
415028            },
415029            {
415030              "license": {
415031                "name": "AND"
415032              }
415033            },
415034            {
415035              "license": {
415036                "id": "BSD-3-Clause"
415037              }
415038            },
415039            {
415040              "license": {
415041                "name": "AND"
415042              }
415043            },
415044            {
415045              "license": {
415046                "name": "Public-Domain"
415047              }
415048            }
415049          ],
415050          "cpe": "cpe:2.3:a:libarchive:libarchive:3.4.2-r0:*:*:*:*:*:*:*",
415051          "purl": "pkg:apk/alpine/libarchive@3.4.2-r0?arch=x86_64\u0026distro=alpine-3.11.13",
415052          "swid": {
415053            "attachment": {}
415054          },
415055          "pedigree": {},
415056          "externalReferences": [
415057            {
415058              "url": "https://libarchive.org/",
415059              "type": "distribution"
415060            }
415061          ],
415062          "evidence": {},
415063          "signature": {
415064            "signature": {
415065              "publicKey": {}
415066            }
415067          },
415068          "modelCard": {
415069            "modelParameters": {
415070              "approach": {}
415071            },
415072            "quantitativeAnalysis": {
415073              "graphics": {}
415074            },
415075            "considerations": {}
415076          }
415077        },
415078        {
415079          "type": "library",
415080          "bom-ref": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.11.13\u0026package-id=b76636964a96efce",
415081          "supplier": {},
415082          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415083          "name": "libbz2",
415084          "version": "1.0.8-r1",
415085          "description": "Shared library for bz2",
415086          "licenses": [
415087            {
415088              "license": {
415089                "id": "bzip2-1.0.6"
415090              }
415091            }
415092          ],
415093          "cpe": "cpe:2.3:a:libbz2:libbz2:1.0.8-r1:*:*:*:*:*:*:*",
415094          "purl": "pkg:apk/alpine/libbz2@1.0.8-r1?arch=x86_64\u0026upstream=bzip2\u0026distro=alpine-3.11.13",
415095          "swid": {
415096            "attachment": {}
415097          },
415098          "pedigree": {},
415099          "externalReferences": [
415100            {
415101              "url": "http://sources.redhat.com/bzip2",
415102              "type": "distribution"
415103            }
415104          ],
415105          "evidence": {},
415106          "signature": {
415107            "signature": {
415108              "publicKey": {}
415109            }
415110          },
415111          "modelCard": {
415112            "modelParameters": {
415113              "approach": {}
415114            },
415115            "quantitativeAnalysis": {
415116              "graphics": {}
415117            },
415118            "considerations": {}
415119          }
415120        },
415121        {
415122          "type": "library",
415123          "bom-ref": "pkg:apk/alpine/libc-utils@0.7.2-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.11.13\u0026package-id=22b2a81fa39d5dd2",
415124          "supplier": {},
415125          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415126          "name": "libc-utils",
415127          "version": "0.7.2-r0",
415128          "description": "Meta package to pull in correct libc",
415129          "licenses": [
415130            {
415131              "license": {
415132                "name": "BSD"
415133              }
415134            }
415135          ],
415136          "cpe": "cpe:2.3:a:libc-utils:libc-utils:0.7.2-r0:*:*:*:*:*:*:*",
415137          "purl": "pkg:apk/alpine/libc-utils@0.7.2-r0?arch=x86_64\u0026upstream=libc-dev\u0026distro=alpine-3.11.13",
415138          "swid": {
415139            "attachment": {}
415140          },
415141          "pedigree": {},
415142          "externalReferences": [
415143            {
415144              "url": "http://alpinelinux.org",
415145              "type": "distribution"
415146            }
415147          ],
415148          "evidence": {},
415149          "signature": {
415150            "signature": {
415151              "publicKey": {}
415152            }
415153          },
415154          "modelCard": {
415155            "modelParameters": {
415156              "approach": {}
415157            },
415158            "quantitativeAnalysis": {
415159              "graphics": {}
415160            },
415161            "considerations": {}
415162          }
415163        },
415164        {
415165          "type": "library",
415166          "bom-ref": "pkg:apk/alpine/libc6-compat@1.1.24-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.11.13\u0026package-id=a62efedb0602c750",
415167          "supplier": {},
415168          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
415169          "name": "libc6-compat",
415170          "version": "1.1.24-r3",
415171          "description": "compatibility libraries for glibc",
415172          "licenses": [
415173            {
415174              "license": {
415175                "id": "MIT"
415176              }
415177            }
415178          ],
415179          "cpe": "cpe:2.3:a:libc6-compat:libc6-compat:1.1.24-r3:*:*:*:*:*:*:*",
415180          "purl": "pkg:apk/alpine/libc6-compat@1.1.24-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.11.13",
415181          "swid": {
415182            "attachment": {}
415183          },
415184          "pedigree": {},
415185          "externalReferences": [
415186            {
415187              "url": "https://musl.libc.org/",
415188              "type": "distribution"
415189            }
415190          ],
415191          "evidence": {},
415192          "signature": {
415193            "signature": {
415194              "publicKey": {}
415195            }
415196          },
415197          "modelCard": {
415198            "modelParameters": {
415199              "approach": {}
415200            },
415201            "quantitativeAnalysis": {
415202              "graphics": {}
415203            },
415204            "considerations": {}
415205          }
415206        },
415207        {
415208          "type": "library",
415209          "bom-ref": "pkg:apk/alpine/libcap@2.27-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=db9033a450637b66",
415210          "supplier": {},
415211          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415212          "name": "libcap",
415213          "version": "2.27-r0",
415214          "description": "POSIX 1003.1e capabilities",
415215          "licenses": [
415216            {
415217              "license": {
415218                "id": "BSD-3-Clause"
415219              }
415220            },
415221            {
415222              "license": {
415223                "name": "OR"
415224              }
415225            },
415226            {
415227              "license": {
415228                "id": "GPL-2.0-only"
415229              }
415230            }
415231          ],
415232          "cpe": "cpe:2.3:a:libcap:libcap:2.27-r0:*:*:*:*:*:*:*",
415233          "purl": "pkg:apk/alpine/libcap@2.27-r0?arch=x86_64\u0026distro=alpine-3.11.13",
415234          "swid": {
415235            "attachment": {}
415236          },
415237          "pedigree": {},
415238          "externalReferences": [
415239            {
415240              "url": "http://www.friedhoff.org/posixfilecaps.html",
415241              "type": "distribution"
415242            }
415243          ],
415244          "evidence": {},
415245          "signature": {
415246            "signature": {
415247              "publicKey": {}
415248            }
415249          },
415250          "modelCard": {
415251            "modelParameters": {
415252              "approach": {}
415253            },
415254            "quantitativeAnalysis": {
415255              "graphics": {}
415256            },
415257            "considerations": {}
415258          }
415259        },
415260        {
415261          "type": "library",
415262          "bom-ref": "pkg:apk/alpine/libcom_err@1.45.5-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.11.13\u0026package-id=4e07bb5178d950cb",
415263          "supplier": {},
415264          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415265          "name": "libcom_err",
415266          "version": "1.45.5-r0",
415267          "description": "Common error description library",
415268          "licenses": [
415269            {
415270              "license": {
415271                "id": "GPL-2.0-or-later"
415272              }
415273            },
415274            {
415275              "license": {
415276                "name": "AND"
415277              }
415278            },
415279            {
415280              "license": {
415281                "id": "LGPL-2.0-or-later"
415282              }
415283            },
415284            {
415285              "license": {
415286                "name": "AND"
415287              }
415288            },
415289            {
415290              "license": {
415291                "id": "BSD-3-Clause"
415292              }
415293            },
415294            {
415295              "license": {
415296                "name": "AND"
415297              }
415298            },
415299            {
415300              "license": {
415301                "id": "MIT"
415302              }
415303            }
415304          ],
415305          "cpe": "cpe:2.3:a:libcom-err:libcom-err:1.45.5-r0:*:*:*:*:*:*:*",
415306          "purl": "pkg:apk/alpine/libcom_err@1.45.5-r0?arch=x86_64\u0026upstream=e2fsprogs\u0026distro=alpine-3.11.13",
415307          "swid": {
415308            "attachment": {}
415309          },
415310          "pedigree": {},
415311          "externalReferences": [
415312            {
415313              "url": "http://e2fsprogs.sourceforge.net",
415314              "type": "distribution"
415315            }
415316          ],
415317          "evidence": {},
415318          "signature": {
415319            "signature": {
415320              "publicKey": {}
415321            }
415322          },
415323          "modelCard": {
415324            "modelParameters": {
415325              "approach": {}
415326            },
415327            "quantitativeAnalysis": {
415328              "graphics": {}
415329            },
415330            "considerations": {}
415331          }
415332        },
415333        {
415334          "type": "library",
415335          "bom-ref": "pkg:apk/alpine/libcrypto1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13\u0026package-id=9dc8a627b3dc6e7c",
415336          "supplier": {},
415337          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
415338          "name": "libcrypto1.1",
415339          "version": "1.1.1l-r0",
415340          "description": "Crypto library from openssl",
415341          "licenses": [
415342            {
415343              "license": {
415344                "id": "OpenSSL"
415345              }
415346            }
415347          ],
415348          "cpe": "cpe:2.3:a:libcrypto1.1:libcrypto1.1:1.1.1l-r0:*:*:*:*:*:*:*",
415349          "purl": "pkg:apk/alpine/libcrypto1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13",
415350          "swid": {
415351            "attachment": {}
415352          },
415353          "pedigree": {},
415354          "externalReferences": [
415355            {
415356              "url": "https://www.openssl.org",
415357              "type": "distribution"
415358            }
415359          ],
415360          "evidence": {},
415361          "signature": {
415362            "signature": {
415363              "publicKey": {}
415364            }
415365          },
415366          "modelCard": {
415367            "modelParameters": {
415368              "approach": {}
415369            },
415370            "quantitativeAnalysis": {
415371              "graphics": {}
415372            },
415373            "considerations": {}
415374          }
415375        },
415376        {
415377          "type": "library",
415378          "bom-ref": "pkg:apk/alpine/libcurl@7.79.1-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.11.13\u0026package-id=b055e046cf7212a1",
415379          "supplier": {},
415380          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415381          "name": "libcurl",
415382          "version": "7.79.1-r0",
415383          "description": "The multiprotocol file transfer library",
415384          "licenses": [
415385            {
415386              "license": {
415387                "id": "MIT"
415388              }
415389            }
415390          ],
415391          "cpe": "cpe:2.3:a:libcurl:libcurl:7.79.1-r0:*:*:*:*:*:*:*",
415392          "purl": "pkg:apk/alpine/libcurl@7.79.1-r0?arch=x86_64\u0026upstream=curl\u0026distro=alpine-3.11.13",
415393          "swid": {
415394            "attachment": {}
415395          },
415396          "pedigree": {},
415397          "externalReferences": [
415398            {
415399              "url": "https://curl.haxx.se/",
415400              "type": "distribution"
415401            }
415402          ],
415403          "evidence": {},
415404          "signature": {
415405            "signature": {
415406              "publicKey": {}
415407            }
415408          },
415409          "modelCard": {
415410            "modelParameters": {
415411              "approach": {}
415412            },
415413            "quantitativeAnalysis": {
415414              "graphics": {}
415415            },
415416            "considerations": {}
415417          }
415418        },
415419        {
415420          "type": "library",
415421          "bom-ref": "pkg:apk/alpine/libffi@3.2.1-r6?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=188dd6786479947c",
415422          "supplier": {},
415423          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415424          "name": "libffi",
415425          "version": "3.2.1-r6",
415426          "description": "A portable, high level programming interface to various calling conventions.",
415427          "licenses": [
415428            {
415429              "license": {
415430                "id": "MIT"
415431              }
415432            }
415433          ],
415434          "cpe": "cpe:2.3:a:libffi:libffi:3.2.1-r6:*:*:*:*:*:*:*",
415435          "purl": "pkg:apk/alpine/libffi@3.2.1-r6?arch=x86_64\u0026distro=alpine-3.11.13",
415436          "swid": {
415437            "attachment": {}
415438          },
415439          "pedigree": {},
415440          "externalReferences": [
415441            {
415442              "url": "http://sourceware.org/libffi",
415443              "type": "distribution"
415444            }
415445          ],
415446          "evidence": {},
415447          "signature": {
415448            "signature": {
415449              "publicKey": {}
415450            }
415451          },
415452          "modelCard": {
415453            "modelParameters": {
415454              "approach": {}
415455            },
415456            "quantitativeAnalysis": {
415457              "graphics": {}
415458            },
415459            "considerations": {}
415460          }
415461        },
415462        {
415463          "type": "library",
415464          "bom-ref": "pkg:apk/alpine/libgcc@9.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.11.13\u0026package-id=89cc23c6449d2429",
415465          "supplier": {},
415466          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415467          "name": "libgcc",
415468          "version": "9.3.0-r0",
415469          "description": "GNU C compiler runtime libraries",
415470          "licenses": [
415471            {
415472              "license": {
415473                "name": "GPL"
415474              }
415475            },
415476            {
415477              "license": {
415478                "name": "LGPL"
415479              }
415480            }
415481          ],
415482          "cpe": "cpe:2.3:a:libgcc:libgcc:9.3.0-r0:*:*:*:*:*:*:*",
415483          "purl": "pkg:apk/alpine/libgcc@9.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.11.13",
415484          "swid": {
415485            "attachment": {}
415486          },
415487          "pedigree": {},
415488          "externalReferences": [
415489            {
415490              "url": "http://gcc.gnu.org",
415491              "type": "distribution"
415492            }
415493          ],
415494          "evidence": {},
415495          "signature": {
415496            "signature": {
415497              "publicKey": {}
415498            }
415499          },
415500          "modelCard": {
415501            "modelParameters": {
415502              "approach": {}
415503            },
415504            "quantitativeAnalysis": {
415505              "graphics": {}
415506            },
415507            "considerations": {}
415508          }
415509        },
415510        {
415511          "type": "library",
415512          "bom-ref": "pkg:apk/alpine/libintl@0.20.1-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.11.13\u0026package-id=d59ebbea5e72dc6f",
415513          "supplier": {},
415514          "publisher": "Carlo Landmeter \u003cclandmeter@gmail.com\u003e",
415515          "name": "libintl",
415516          "version": "0.20.1-r2",
415517          "description": "GNU gettext runtime library",
415518          "licenses": [
415519            {
415520              "license": {
415521                "id": "LGPL-2.1-or-later"
415522              }
415523            }
415524          ],
415525          "cpe": "cpe:2.3:a:libintl:libintl:0.20.1-r2:*:*:*:*:*:*:*",
415526          "purl": "pkg:apk/alpine/libintl@0.20.1-r2?arch=x86_64\u0026upstream=gettext\u0026distro=alpine-3.11.13",
415527          "swid": {
415528            "attachment": {}
415529          },
415530          "pedigree": {},
415531          "externalReferences": [
415532            {
415533              "url": "https://www.gnu.org/software/gettext/gettext.html",
415534              "type": "distribution"
415535            }
415536          ],
415537          "evidence": {},
415538          "signature": {
415539            "signature": {
415540              "publicKey": {}
415541            }
415542          },
415543          "modelCard": {
415544            "modelParameters": {
415545              "approach": {}
415546            },
415547            "quantitativeAnalysis": {
415548              "graphics": {}
415549            },
415550            "considerations": {}
415551          }
415552        },
415553        {
415554          "type": "library",
415555          "bom-ref": "pkg:apk/alpine/libldap@2.4.48-r3?arch=x86_64\u0026upstream=openldap\u0026distro=alpine-3.11.13\u0026package-id=43f853264ee84098",
415556          "supplier": {},
415557          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415558          "name": "libldap",
415559          "version": "2.4.48-r3",
415560          "description": "OpenLDAP libraries",
415561          "licenses": [
415562            {
415563              "license": {
415564                "name": "custom"
415565              }
415566            }
415567          ],
415568          "cpe": "cpe:2.3:a:libldap:libldap:2.4.48-r3:*:*:*:*:*:*:*",
415569          "purl": "pkg:apk/alpine/libldap@2.4.48-r3?arch=x86_64\u0026upstream=openldap\u0026distro=alpine-3.11.13",
415570          "swid": {
415571            "attachment": {}
415572          },
415573          "pedigree": {},
415574          "externalReferences": [
415575            {
415576              "url": "http://www.openldap.org/",
415577              "type": "distribution"
415578            }
415579          ],
415580          "evidence": {},
415581          "signature": {
415582            "signature": {
415583              "publicKey": {}
415584            }
415585          },
415586          "modelCard": {
415587            "modelParameters": {
415588              "approach": {}
415589            },
415590            "quantitativeAnalysis": {
415591              "graphics": {}
415592            },
415593            "considerations": {}
415594          }
415595        },
415596        {
415597          "type": "library",
415598          "bom-ref": "pkg:apk/alpine/libnsl@1.2.0-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=e1f2fcfa0b38530",
415599          "supplier": {},
415600          "publisher": "Valery Kartel \u003cvalery.kartel@gmail.com\u003e",
415601          "name": "libnsl",
415602          "version": "1.2.0-r1",
415603          "description": "Public client interface for NIS(YP) and NIS+ in a IPv6 ready version",
415604          "licenses": [
415605            {
415606              "license": {
415607                "id": "LGPL-2.0-or-later"
415608              }
415609            }
415610          ],
415611          "cpe": "cpe:2.3:a:thkukuk:libnsl:1.2.0-r1:*:*:*:*:*:*:*",
415612          "purl": "pkg:apk/alpine/libnsl@1.2.0-r1?arch=x86_64\u0026distro=alpine-3.11.13",
415613          "swid": {
415614            "attachment": {}
415615          },
415616          "pedigree": {},
415617          "externalReferences": [
415618            {
415619              "url": "https://github.com/thkukuk/libnsl",
415620              "type": "distribution"
415621            }
415622          ],
415623          "evidence": {},
415624          "signature": {
415625            "signature": {
415626              "publicKey": {}
415627            }
415628          },
415629          "modelCard": {
415630            "modelParameters": {
415631              "approach": {}
415632            },
415633            "quantitativeAnalysis": {
415634              "graphics": {}
415635            },
415636            "considerations": {}
415637          }
415638        },
415639        {
415640          "type": "library",
415641          "bom-ref": "pkg:apk/alpine/libprotobuf@3.11.2-r1?arch=x86_64\u0026upstream=protobuf\u0026distro=alpine-3.11.13\u0026package-id=afd815776e07bdd7",
415642          "supplier": {},
415643          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415644          "name": "libprotobuf",
415645          "version": "3.11.2-r1",
415646          "description": "Runtime library for C++ users of protocol buffers",
415647          "licenses": [
415648            {
415649              "license": {
415650                "id": "BSD-3-Clause"
415651              }
415652            }
415653          ],
415654          "cpe": "cpe:2.3:a:libprotobuf:libprotobuf:3.11.2-r1:*:*:*:*:*:*:*",
415655          "purl": "pkg:apk/alpine/libprotobuf@3.11.2-r1?arch=x86_64\u0026upstream=protobuf\u0026distro=alpine-3.11.13",
415656          "swid": {
415657            "attachment": {}
415658          },
415659          "pedigree": {},
415660          "externalReferences": [
415661            {
415662              "url": "https://github.com/google/protobuf",
415663              "type": "distribution"
415664            }
415665          ],
415666          "evidence": {},
415667          "signature": {
415668            "signature": {
415669              "publicKey": {}
415670            }
415671          },
415672          "modelCard": {
415673            "modelParameters": {
415674              "approach": {}
415675            },
415676            "quantitativeAnalysis": {
415677              "graphics": {}
415678            },
415679            "considerations": {}
415680          }
415681        },
415682        {
415683          "type": "library",
415684          "bom-ref": "pkg:apk/alpine/libprotoc@3.11.2-r1?arch=x86_64\u0026upstream=protobuf\u0026distro=alpine-3.11.13\u0026package-id=d565e366f20c5c1d",
415685          "supplier": {},
415686          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415687          "name": "libprotoc",
415688          "version": "3.11.2-r1",
415689          "description": "Runtime library for Protocol Buffer compiler",
415690          "licenses": [
415691            {
415692              "license": {
415693                "id": "BSD-3-Clause"
415694              }
415695            }
415696          ],
415697          "cpe": "cpe:2.3:a:libprotoc:libprotoc:3.11.2-r1:*:*:*:*:*:*:*",
415698          "purl": "pkg:apk/alpine/libprotoc@3.11.2-r1?arch=x86_64\u0026upstream=protobuf\u0026distro=alpine-3.11.13",
415699          "swid": {
415700            "attachment": {}
415701          },
415702          "pedigree": {},
415703          "externalReferences": [
415704            {
415705              "url": "https://github.com/google/protobuf",
415706              "type": "distribution"
415707            }
415708          ],
415709          "evidence": {},
415710          "signature": {
415711            "signature": {
415712              "publicKey": {}
415713            }
415714          },
415715          "modelCard": {
415716            "modelParameters": {
415717              "approach": {}
415718            },
415719            "quantitativeAnalysis": {
415720              "graphics": {}
415721            },
415722            "considerations": {}
415723          }
415724        },
415725        {
415726          "type": "library",
415727          "bom-ref": "pkg:apk/alpine/libsasl@2.1.27-r5?arch=x86_64\u0026upstream=cyrus-sasl\u0026distro=alpine-3.11.13\u0026package-id=d1c1ffb8a63b6c12",
415728          "supplier": {},
415729          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415730          "name": "libsasl",
415731          "version": "2.1.27-r5",
415732          "description": "Cyrus Simple Authentication and Security Layer (SASL) library",
415733          "licenses": [
415734            {
415735              "license": {
415736                "name": "custom"
415737              }
415738            }
415739          ],
415740          "cpe": "cpe:2.3:a:libsasl:libsasl:2.1.27-r5:*:*:*:*:*:*:*",
415741          "purl": "pkg:apk/alpine/libsasl@2.1.27-r5?arch=x86_64\u0026upstream=cyrus-sasl\u0026distro=alpine-3.11.13",
415742          "swid": {
415743            "attachment": {}
415744          },
415745          "pedigree": {},
415746          "externalReferences": [
415747            {
415748              "url": "https://cyrusimap.org/",
415749              "type": "distribution"
415750            }
415751          ],
415752          "evidence": {},
415753          "signature": {
415754            "signature": {
415755              "publicKey": {}
415756            }
415757          },
415758          "modelCard": {
415759            "modelParameters": {
415760              "approach": {}
415761            },
415762            "quantitativeAnalysis": {
415763              "graphics": {}
415764            },
415765            "considerations": {}
415766          }
415767        },
415768        {
415769          "type": "library",
415770          "bom-ref": "pkg:apk/alpine/libsmbclient@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=8af66c5a794fa5db",
415771          "supplier": {},
415772          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415773          "name": "libsmbclient",
415774          "version": "4.11.16-r0",
415775          "description": "The SMB client library",
415776          "licenses": [
415777            {
415778              "license": {
415779                "id": "GPL-3.0-or-later"
415780              }
415781            },
415782            {
415783              "license": {
415784                "id": "LGPL-3.0-or-later"
415785              }
415786            }
415787          ],
415788          "cpe": "cpe:2.3:a:libsmbclient:libsmbclient:4.11.16-r0:*:*:*:*:*:*:*",
415789          "purl": "pkg:apk/alpine/libsmbclient@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
415790          "swid": {
415791            "attachment": {}
415792          },
415793          "pedigree": {},
415794          "externalReferences": [
415795            {
415796              "url": "https://www.samba.org/",
415797              "type": "distribution"
415798            }
415799          ],
415800          "evidence": {},
415801          "signature": {
415802            "signature": {
415803              "publicKey": {}
415804            }
415805          },
415806          "modelCard": {
415807            "modelParameters": {
415808              "approach": {}
415809            },
415810            "quantitativeAnalysis": {
415811              "graphics": {}
415812            },
415813            "considerations": {}
415814          }
415815        },
415816        {
415817          "type": "library",
415818          "bom-ref": "pkg:apk/alpine/libssl1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13\u0026package-id=286e1bd630e38068",
415819          "supplier": {},
415820          "publisher": "Timo Teras \u003ctimo.teras@iki.fi\u003e",
415821          "name": "libssl1.1",
415822          "version": "1.1.1l-r0",
415823          "description": "SSL shared libraries",
415824          "licenses": [
415825            {
415826              "license": {
415827                "id": "OpenSSL"
415828              }
415829            }
415830          ],
415831          "cpe": "cpe:2.3:a:libssl1.1:libssl1.1:1.1.1l-r0:*:*:*:*:*:*:*",
415832          "purl": "pkg:apk/alpine/libssl1.1@1.1.1l-r0?arch=x86_64\u0026upstream=openssl\u0026distro=alpine-3.11.13",
415833          "swid": {
415834            "attachment": {}
415835          },
415836          "pedigree": {},
415837          "externalReferences": [
415838            {
415839              "url": "https://www.openssl.org",
415840              "type": "distribution"
415841            }
415842          ],
415843          "evidence": {},
415844          "signature": {
415845            "signature": {
415846              "publicKey": {}
415847            }
415848          },
415849          "modelCard": {
415850            "modelParameters": {
415851              "approach": {}
415852            },
415853            "quantitativeAnalysis": {
415854              "graphics": {}
415855            },
415856            "considerations": {}
415857          }
415858        },
415859        {
415860          "type": "library",
415861          "bom-ref": "pkg:apk/alpine/libstdc++@9.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.11.13\u0026package-id=6fd631fecbbb6585",
415862          "supplier": {},
415863          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415864          "name": "libstdc++",
415865          "version": "9.3.0-r0",
415866          "description": "GNU C++ standard runtime library",
415867          "licenses": [
415868            {
415869              "license": {
415870                "name": "GPL"
415871              }
415872            },
415873            {
415874              "license": {
415875                "name": "LGPL"
415876              }
415877            }
415878          ],
415879          "cpe": "cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:9.3.0-r0:*:*:*:*:*:*:*",
415880          "purl": "pkg:apk/alpine/libstdc++@9.3.0-r0?arch=x86_64\u0026upstream=gcc\u0026distro=alpine-3.11.13",
415881          "swid": {
415882            "attachment": {}
415883          },
415884          "pedigree": {},
415885          "externalReferences": [
415886            {
415887              "url": "http://gcc.gnu.org",
415888              "type": "distribution"
415889            }
415890          ],
415891          "evidence": {},
415892          "signature": {
415893            "signature": {
415894              "publicKey": {}
415895            }
415896          },
415897          "modelCard": {
415898            "modelParameters": {
415899              "approach": {}
415900            },
415901            "quantitativeAnalysis": {
415902              "graphics": {}
415903            },
415904            "considerations": {}
415905          }
415906        },
415907        {
415908          "type": "library",
415909          "bom-ref": "pkg:apk/alpine/libtasn1@4.15.0-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=dc012f0593261b2a",
415910          "supplier": {},
415911          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415912          "name": "libtasn1",
415913          "version": "4.15.0-r0",
415914          "description": "The ASN.1 library used in GNUTLS",
415915          "licenses": [
415916            {
415917              "license": {
415918                "id": "GPL-3.0-only"
415919              }
415920            },
415921            {
415922              "license": {
415923                "name": "LGPL"
415924              }
415925            }
415926          ],
415927          "cpe": "cpe:2.3:a:libtasn1:libtasn1:4.15.0-r0:*:*:*:*:*:*:*",
415928          "purl": "pkg:apk/alpine/libtasn1@4.15.0-r0?arch=x86_64\u0026distro=alpine-3.11.13",
415929          "swid": {
415930            "attachment": {}
415931          },
415932          "pedigree": {},
415933          "externalReferences": [
415934            {
415935              "url": "https://www.gnu.org/software/gnutls/",
415936              "type": "distribution"
415937            }
415938          ],
415939          "evidence": {},
415940          "signature": {
415941            "signature": {
415942              "publicKey": {}
415943            }
415944          },
415945          "modelCard": {
415946            "modelParameters": {
415947              "approach": {}
415948            },
415949            "quantitativeAnalysis": {
415950              "graphics": {}
415951            },
415952            "considerations": {}
415953          }
415954        },
415955        {
415956          "type": "library",
415957          "bom-ref": "pkg:apk/alpine/libtirpc@1.1.4-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=a645a129c4e31ce8",
415958          "supplier": {},
415959          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
415960          "name": "libtirpc",
415961          "version": "1.1.4-r0",
415962          "description": "Transport Independent RPC library (SunRPC replacement)",
415963          "licenses": [
415964            {
415965              "license": {
415966                "id": "BSD-3-Clause"
415967              }
415968            }
415969          ],
415970          "cpe": "cpe:2.3:a:libtirpc:libtirpc:1.1.4-r0:*:*:*:*:*:*:*",
415971          "purl": "pkg:apk/alpine/libtirpc@1.1.4-r0?arch=x86_64\u0026distro=alpine-3.11.13",
415972          "swid": {
415973            "attachment": {}
415974          },
415975          "pedigree": {},
415976          "externalReferences": [
415977            {
415978              "url": "https://sourceforge.net/projects/libtirpc",
415979              "type": "distribution"
415980            }
415981          ],
415982          "evidence": {},
415983          "signature": {
415984            "signature": {
415985              "publicKey": {}
415986            }
415987          },
415988          "modelCard": {
415989            "modelParameters": {
415990              "approach": {}
415991            },
415992            "quantitativeAnalysis": {
415993              "graphics": {}
415994            },
415995            "considerations": {}
415996          }
415997        },
415998        {
415999          "type": "library",
416000          "bom-ref": "pkg:apk/alpine/libtls-standalone@2.9.1-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=44d013a47dc758aa",
416001          "supplier": {},
416002          "name": "libtls-standalone",
416003          "version": "2.9.1-r0",
416004          "description": "libtls extricated from libressl sources",
416005          "licenses": [
416006            {
416007              "license": {
416008                "id": "ISC"
416009              }
416010            }
416011          ],
416012          "cpe": "cpe:2.3:a:libtls-standalone:libtls-standalone:2.9.1-r0:*:*:*:*:*:*:*",
416013          "purl": "pkg:apk/alpine/libtls-standalone@2.9.1-r0?arch=x86_64\u0026distro=alpine-3.11.13",
416014          "swid": {
416015            "attachment": {}
416016          },
416017          "pedigree": {},
416018          "externalReferences": [
416019            {
416020              "url": "https://www.libressl.org/",
416021              "type": "distribution"
416022            }
416023          ],
416024          "evidence": {},
416025          "signature": {
416026            "signature": {
416027              "publicKey": {}
416028            }
416029          },
416030          "modelCard": {
416031            "modelParameters": {
416032              "approach": {}
416033            },
416034            "quantitativeAnalysis": {
416035              "graphics": {}
416036            },
416037            "considerations": {}
416038          }
416039        },
416040        {
416041          "type": "library",
416042          "bom-ref": "pkg:apk/alpine/libunistring@0.9.10-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=7500a925936e1eec",
416043          "supplier": {},
416044          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416045          "name": "libunistring",
416046          "version": "0.9.10-r0",
416047          "description": "Library for manipulating Unicode strings and C strings",
416048          "licenses": [
416049            {
416050              "license": {
416051                "id": "GPL-2.0-or-later"
416052              }
416053            },
416054            {
416055              "license": {
416056                "name": "OR"
416057              }
416058            },
416059            {
416060              "license": {
416061                "id": "LGPL-3.0-or-later"
416062              }
416063            }
416064          ],
416065          "cpe": "cpe:2.3:a:libunistring:libunistring:0.9.10-r0:*:*:*:*:*:*:*",
416066          "purl": "pkg:apk/alpine/libunistring@0.9.10-r0?arch=x86_64\u0026distro=alpine-3.11.13",
416067          "swid": {
416068            "attachment": {}
416069          },
416070          "pedigree": {},
416071          "externalReferences": [
416072            {
416073              "url": "https://www.gnu.org/software/libunistring/",
416074              "type": "distribution"
416075            }
416076          ],
416077          "evidence": {},
416078          "signature": {
416079            "signature": {
416080              "publicKey": {}
416081            }
416082          },
416083          "modelCard": {
416084            "modelParameters": {
416085              "approach": {}
416086            },
416087            "quantitativeAnalysis": {
416088              "graphics": {}
416089            },
416090            "considerations": {}
416091          }
416092        },
416093        {
416094          "type": "library",
416095          "bom-ref": "pkg:apk/alpine/libuv@1.34.0-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=d70bd9dca54a4f32",
416096          "supplier": {},
416097          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416098          "name": "libuv",
416099          "version": "1.34.0-r0",
416100          "description": "Cross-platform asychronous I/O",
416101          "licenses": [
416102            {
416103              "license": {
416104                "id": "MIT"
416105              }
416106            },
416107            {
416108              "license": {
416109                "name": "AND"
416110              }
416111            },
416112            {
416113              "license": {
416114                "id": "ISC"
416115              }
416116            }
416117          ],
416118          "cpe": "cpe:2.3:a:libuv:libuv:1.34.0-r0:*:*:*:*:*:*:*",
416119          "purl": "pkg:apk/alpine/libuv@1.34.0-r0?arch=x86_64\u0026distro=alpine-3.11.13",
416120          "swid": {
416121            "attachment": {}
416122          },
416123          "pedigree": {},
416124          "externalReferences": [
416125            {
416126              "url": "https://libuv.org",
416127              "type": "distribution"
416128            }
416129          ],
416130          "evidence": {},
416131          "signature": {
416132            "signature": {
416133              "publicKey": {}
416134            }
416135          },
416136          "modelCard": {
416137            "modelParameters": {
416138              "approach": {}
416139            },
416140            "quantitativeAnalysis": {
416141              "graphics": {}
416142            },
416143            "considerations": {}
416144          }
416145        },
416146        {
416147          "type": "library",
416148          "bom-ref": "pkg:apk/alpine/libverto@0.3.1-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=b083bc0d20fed354",
416149          "supplier": {},
416150          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
416151          "name": "libverto",
416152          "version": "0.3.1-r1",
416153          "description": "Main loop abstraction library",
416154          "licenses": [
416155            {
416156              "license": {
416157                "id": "MIT"
416158              }
416159            }
416160          ],
416161          "cpe": "cpe:2.3:a:npmccallum:libverto:0.3.1-r1:*:*:*:*:*:*:*",
416162          "purl": "pkg:apk/alpine/libverto@0.3.1-r1?arch=x86_64\u0026distro=alpine-3.11.13",
416163          "swid": {
416164            "attachment": {}
416165          },
416166          "pedigree": {},
416167          "externalReferences": [
416168            {
416169              "url": "https://github.com/npmccallum/libverto",
416170              "type": "distribution"
416171            }
416172          ],
416173          "evidence": {},
416174          "signature": {
416175            "signature": {
416176              "publicKey": {}
416177            }
416178          },
416179          "modelCard": {
416180            "modelParameters": {
416181              "approach": {}
416182            },
416183            "quantitativeAnalysis": {
416184              "graphics": {}
416185            },
416186            "considerations": {}
416187          }
416188        },
416189        {
416190          "type": "library",
416191          "bom-ref": "pkg:apk/alpine/libwbclient@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=11ff3a404952dfc9",
416192          "supplier": {},
416193          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416194          "name": "libwbclient",
416195          "version": "4.11.16-r0",
416196          "description": "Samba winbind client libraries",
416197          "licenses": [
416198            {
416199              "license": {
416200                "id": "GPL-3.0-or-later"
416201              }
416202            },
416203            {
416204              "license": {
416205                "id": "LGPL-3.0-or-later"
416206              }
416207            }
416208          ],
416209          "cpe": "cpe:2.3:a:libwbclient:libwbclient:4.11.16-r0:*:*:*:*:*:*:*",
416210          "purl": "pkg:apk/alpine/libwbclient@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
416211          "swid": {
416212            "attachment": {}
416213          },
416214          "pedigree": {},
416215          "externalReferences": [
416216            {
416217              "url": "https://www.samba.org/",
416218              "type": "distribution"
416219            }
416220          ],
416221          "evidence": {},
416222          "signature": {
416223            "signature": {
416224              "publicKey": {}
416225            }
416226          },
416227          "modelCard": {
416228            "modelParameters": {
416229              "approach": {}
416230            },
416231            "quantitativeAnalysis": {
416232              "graphics": {}
416233            },
416234            "considerations": {}
416235          }
416236        },
416237        {
416238          "type": "library",
416239          "bom-ref": "pkg:apk/alpine/libxml2@2.9.12-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=58aab1a9515640d2",
416240          "supplier": {},
416241          "publisher": "Carlo Landmeter \u003cclandmeter@gmail.com\u003e",
416242          "name": "libxml2",
416243          "version": "2.9.12-r0",
416244          "description": "XML parsing library, version 2",
416245          "licenses": [
416246            {
416247              "license": {
416248                "id": "MIT"
416249              }
416250            }
416251          ],
416252          "cpe": "cpe:2.3:a:libxml2:libxml2:2.9.12-r0:*:*:*:*:*:*:*",
416253          "purl": "pkg:apk/alpine/libxml2@2.9.12-r0?arch=x86_64\u0026distro=alpine-3.11.13",
416254          "swid": {
416255            "attachment": {}
416256          },
416257          "pedigree": {},
416258          "externalReferences": [
416259            {
416260              "url": "http://www.xmlsoft.org/",
416261              "type": "distribution"
416262            }
416263          ],
416264          "evidence": {},
416265          "signature": {
416266            "signature": {
416267              "publicKey": {}
416268            }
416269          },
416270          "modelCard": {
416271            "modelParameters": {
416272              "approach": {}
416273            },
416274            "quantitativeAnalysis": {
416275              "graphics": {}
416276            },
416277            "considerations": {}
416278          }
416279        },
416280        {
416281          "type": "library",
416282          "bom-ref": "pkg:apk/alpine/linux-pam@1.3.1-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=8a864f15b49ecba8",
416283          "supplier": {},
416284          "publisher": "Rasmus Thomsen \u003coss@cogitri.dev\u003e",
416285          "name": "linux-pam",
416286          "version": "1.3.1-r1",
416287          "description": "pluggable authentication modules for linux",
416288          "licenses": [
416289            {
416290              "license": {
416291                "id": "BSD-3-Clause"
416292              }
416293            }
416294          ],
416295          "cpe": "cpe:2.3:a:linux-pam:linux-pam:1.3.1-r1:*:*:*:*:*:*:*",
416296          "purl": "pkg:apk/alpine/linux-pam@1.3.1-r1?arch=x86_64\u0026distro=alpine-3.11.13",
416297          "swid": {
416298            "attachment": {}
416299          },
416300          "pedigree": {},
416301          "externalReferences": [
416302            {
416303              "url": "http://www.kernel.org/pub/linux/libs/pam",
416304              "type": "distribution"
416305            }
416306          ],
416307          "evidence": {},
416308          "signature": {
416309            "signature": {
416310              "publicKey": {}
416311            }
416312          },
416313          "modelCard": {
416314            "modelParameters": {
416315              "approach": {}
416316            },
416317            "quantitativeAnalysis": {
416318              "graphics": {}
416319            },
416320            "considerations": {}
416321          }
416322        },
416323        {
416324          "type": "library",
416325          "bom-ref": "pkg:apk/alpine/lmdb@0.9.24-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=8df5d38a2248bbbe",
416326          "supplier": {},
416327          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416328          "name": "lmdb",
416329          "version": "0.9.24-r1",
416330          "description": "Lightning Memory-Mapped Database",
416331          "licenses": [
416332            {
416333              "license": {
416334                "id": "OLDAP-2.8"
416335              }
416336            }
416337          ],
416338          "cpe": "cpe:2.3:a:lmdb:lmdb:0.9.24-r1:*:*:*:*:*:*:*",
416339          "purl": "pkg:apk/alpine/lmdb@0.9.24-r1?arch=x86_64\u0026distro=alpine-3.11.13",
416340          "swid": {
416341            "attachment": {}
416342          },
416343          "pedigree": {},
416344          "externalReferences": [
416345            {
416346              "url": "https://symas.com/mdb",
416347              "type": "distribution"
416348            }
416349          ],
416350          "evidence": {},
416351          "signature": {
416352            "signature": {
416353              "publicKey": {}
416354            }
416355          },
416356          "modelCard": {
416357            "modelParameters": {
416358              "approach": {}
416359            },
416360            "quantitativeAnalysis": {
416361              "graphics": {}
416362            },
416363            "considerations": {}
416364          }
416365        },
416366        {
416367          "type": "library",
416368          "bom-ref": "pkg:apk/alpine/lz4-libs@1.9.2-r0?arch=x86_64\u0026upstream=lz4\u0026distro=alpine-3.11.13\u0026package-id=3e81dc54702c0485",
416369          "supplier": {},
416370          "publisher": "Stuart Cardall \u003cdeveloper@it-offshore.co.uk\u003e",
416371          "name": "lz4-libs",
416372          "version": "1.9.2-r0",
416373          "description": "LZ4 is lossless compression algorithm with fast decoder @ multiple GB/s per core. (libraries)",
416374          "licenses": [
416375            {
416376              "license": {
416377                "id": "BSD-2-Clause"
416378              }
416379            },
416380            {
416381              "license": {
416382                "id": "GPL-2.0-only"
416383              }
416384            }
416385          ],
416386          "cpe": "cpe:2.3:a:lz4-libs:lz4-libs:1.9.2-r0:*:*:*:*:*:*:*",
416387          "purl": "pkg:apk/alpine/lz4-libs@1.9.2-r0?arch=x86_64\u0026upstream=lz4\u0026distro=alpine-3.11.13",
416388          "swid": {
416389            "attachment": {}
416390          },
416391          "pedigree": {},
416392          "externalReferences": [
416393            {
416394              "url": "https://github.com/lz4/lz4",
416395              "type": "distribution"
416396            }
416397          ],
416398          "evidence": {},
416399          "signature": {
416400            "signature": {
416401              "publicKey": {}
416402            }
416403          },
416404          "modelCard": {
416405            "modelParameters": {
416406              "approach": {}
416407            },
416408            "quantitativeAnalysis": {
416409              "graphics": {}
416410            },
416411            "considerations": {}
416412          }
416413        },
416414        {
416415          "type": "library",
416416          "bom-ref": "pkg:apk/alpine/musl@1.1.24-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=485b70fc6d5760",
416417          "supplier": {},
416418          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
416419          "name": "musl",
416420          "version": "1.1.24-r3",
416421          "description": "the musl c library (libc) implementation",
416422          "licenses": [
416423            {
416424              "license": {
416425                "id": "MIT"
416426              }
416427            }
416428          ],
416429          "cpe": "cpe:2.3:a:musl-libc:musl:1.1.24-r3:*:*:*:*:*:*:*",
416430          "purl": "pkg:apk/alpine/musl@1.1.24-r3?arch=x86_64\u0026distro=alpine-3.11.13",
416431          "swid": {
416432            "attachment": {}
416433          },
416434          "pedigree": {},
416435          "externalReferences": [
416436            {
416437              "url": "https://musl.libc.org/",
416438              "type": "distribution"
416439            }
416440          ],
416441          "evidence": {},
416442          "signature": {
416443            "signature": {
416444              "publicKey": {}
416445            }
416446          },
416447          "modelCard": {
416448            "modelParameters": {
416449              "approach": {}
416450            },
416451            "quantitativeAnalysis": {
416452              "graphics": {}
416453            },
416454            "considerations": {}
416455          }
416456        },
416457        {
416458          "type": "library",
416459          "bom-ref": "pkg:apk/alpine/musl-utils@1.1.24-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.11.13\u0026package-id=fc850f3aca8a5da",
416460          "supplier": {},
416461          "publisher": "Timo Teräs \u003ctimo.teras@iki.fi\u003e",
416462          "name": "musl-utils",
416463          "version": "1.1.24-r3",
416464          "description": "the musl c library (libc) implementation",
416465          "licenses": [
416466            {
416467              "license": {
416468                "id": "MIT"
416469              }
416470            },
416471            {
416472              "license": {
416473                "name": "BSD"
416474              }
416475            },
416476            {
416477              "license": {
416478                "id": "GPL-2.0-or-later"
416479              }
416480            }
416481          ],
416482          "cpe": "cpe:2.3:a:musl-utils:musl-utils:1.1.24-r3:*:*:*:*:*:*:*",
416483          "purl": "pkg:apk/alpine/musl-utils@1.1.24-r3?arch=x86_64\u0026upstream=musl\u0026distro=alpine-3.11.13",
416484          "swid": {
416485            "attachment": {}
416486          },
416487          "pedigree": {},
416488          "externalReferences": [
416489            {
416490              "url": "https://musl.libc.org/",
416491              "type": "distribution"
416492            }
416493          ],
416494          "evidence": {},
416495          "signature": {
416496            "signature": {
416497              "publicKey": {}
416498            }
416499          },
416500          "modelCard": {
416501            "modelParameters": {
416502              "approach": {}
416503            },
416504            "quantitativeAnalysis": {
416505              "graphics": {}
416506            },
416507            "considerations": {}
416508          }
416509        },
416510        {
416511          "type": "library",
416512          "bom-ref": "pkg:apk/alpine/ncurses-libs@6.1_p20200118-r4?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.11.13\u0026package-id=fd5b1d7554bf8d7",
416513          "supplier": {},
416514          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416515          "name": "ncurses-libs",
416516          "version": "6.1_p20200118-r4",
416517          "description": "Ncurses libraries",
416518          "licenses": [
416519            {
416520              "license": {
416521                "id": "MIT"
416522              }
416523            }
416524          ],
416525          "cpe": "cpe:2.3:a:ncurses-libs:ncurses-libs:6.1_p20200118-r4:*:*:*:*:*:*:*",
416526          "purl": "pkg:apk/alpine/ncurses-libs@6.1_p20200118-r4?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.11.13",
416527          "swid": {
416528            "attachment": {}
416529          },
416530          "pedigree": {},
416531          "externalReferences": [
416532            {
416533              "url": "https://invisible-island.net/ncurses/",
416534              "type": "distribution"
416535            }
416536          ],
416537          "evidence": {},
416538          "signature": {
416539            "signature": {
416540              "publicKey": {}
416541            }
416542          },
416543          "modelCard": {
416544            "modelParameters": {
416545              "approach": {}
416546            },
416547            "quantitativeAnalysis": {
416548              "graphics": {}
416549            },
416550            "considerations": {}
416551          }
416552        },
416553        {
416554          "type": "library",
416555          "bom-ref": "pkg:apk/alpine/ncurses-terminfo-base@6.1_p20200118-r4?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.11.13\u0026package-id=6efb3458396ed104",
416556          "supplier": {},
416557          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416558          "name": "ncurses-terminfo-base",
416559          "version": "6.1_p20200118-r4",
416560          "description": "Descriptions of common terminals",
416561          "licenses": [
416562            {
416563              "license": {
416564                "id": "MIT"
416565              }
416566            }
416567          ],
416568          "cpe": "cpe:2.3:a:ncurses-terminfo-base:ncurses-terminfo-base:6.1_p20200118-r4:*:*:*:*:*:*:*",
416569          "purl": "pkg:apk/alpine/ncurses-terminfo-base@6.1_p20200118-r4?arch=x86_64\u0026upstream=ncurses\u0026distro=alpine-3.11.13",
416570          "swid": {
416571            "attachment": {}
416572          },
416573          "pedigree": {},
416574          "externalReferences": [
416575            {
416576              "url": "https://invisible-island.net/ncurses/",
416577              "type": "distribution"
416578            }
416579          ],
416580          "evidence": {},
416581          "signature": {
416582            "signature": {
416583              "publicKey": {}
416584            }
416585          },
416586          "modelCard": {
416587            "modelParameters": {
416588              "approach": {}
416589            },
416590            "quantitativeAnalysis": {
416591              "graphics": {}
416592            },
416593            "considerations": {}
416594          }
416595        },
416596        {
416597          "type": "library",
416598          "bom-ref": "pkg:apk/alpine/nettle@3.5.1-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=671ec146c6606369",
416599          "supplier": {},
416600          "publisher": "Fabian Affolter \u003cfabian@affolter-engineering.ch\u003e",
416601          "name": "nettle",
416602          "version": "3.5.1-r0",
416603          "description": "A low-level cryptographic library",
416604          "licenses": [
416605            {
416606              "license": {
416607                "id": "LGPL-2.0-or-later"
416608              }
416609            }
416610          ],
416611          "cpe": "cpe:2.3:a:nettle:nettle:3.5.1-r0:*:*:*:*:*:*:*",
416612          "purl": "pkg:apk/alpine/nettle@3.5.1-r0?arch=x86_64\u0026distro=alpine-3.11.13",
416613          "swid": {
416614            "attachment": {}
416615          },
416616          "pedigree": {},
416617          "externalReferences": [
416618            {
416619              "url": "https://www.lysator.liu.se/~nisse/nettle/",
416620              "type": "distribution"
416621            }
416622          ],
416623          "evidence": {},
416624          "signature": {
416625            "signature": {
416626              "publicKey": {}
416627            }
416628          },
416629          "modelCard": {
416630            "modelParameters": {
416631              "approach": {}
416632            },
416633            "quantitativeAnalysis": {
416634              "graphics": {}
416635            },
416636            "considerations": {}
416637          }
416638        },
416639        {
416640          "type": "library",
416641          "bom-ref": "pkg:apk/alpine/nghttp2-libs@1.40.0-r1?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.11.13\u0026package-id=569777ff2f19d9f3",
416642          "supplier": {},
416643          "publisher": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e",
416644          "name": "nghttp2-libs",
416645          "version": "1.40.0-r1",
416646          "description": "Experimental HTTP/2 client, server and proxy (libraries)",
416647          "licenses": [
416648            {
416649              "license": {
416650                "id": "MIT"
416651              }
416652            }
416653          ],
416654          "cpe": "cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.40.0-r1:*:*:*:*:*:*:*",
416655          "purl": "pkg:apk/alpine/nghttp2-libs@1.40.0-r1?arch=x86_64\u0026upstream=nghttp2\u0026distro=alpine-3.11.13",
416656          "swid": {
416657            "attachment": {}
416658          },
416659          "pedigree": {},
416660          "externalReferences": [
416661            {
416662              "url": "https://nghttp2.org",
416663              "type": "distribution"
416664            }
416665          ],
416666          "evidence": {},
416667          "signature": {
416668            "signature": {
416669              "publicKey": {}
416670            }
416671          },
416672          "modelCard": {
416673            "modelParameters": {
416674              "approach": {}
416675            },
416676            "quantitativeAnalysis": {
416677              "graphics": {}
416678            },
416679            "considerations": {}
416680          }
416681        },
416682        {
416683          "type": "application",
416684          "bom-ref": "pkg:generic/node@15.12.0?package-id=35373778dc80f093",
416685          "supplier": {},
416686          "name": "node",
416687          "version": "15.12.0",
416688          "cpe": "cpe:2.3:a:nodejs:node.js:15.12.0:*:*:*:*:*:*:*",
416689          "purl": "pkg:generic/node@15.12.0",
416690          "swid": {
416691            "attachment": {}
416692          },
416693          "pedigree": {},
416694          "evidence": {},
416695          "signature": {
416696            "signature": {
416697              "publicKey": {}
416698            }
416699          },
416700          "modelCard": {
416701            "modelParameters": {
416702              "approach": {}
416703            },
416704            "quantitativeAnalysis": {
416705              "graphics": {}
416706            },
416707            "considerations": {}
416708          }
416709        },
416710        {
416711          "type": "library",
416712          "bom-ref": "pkg:apk/alpine/p11-kit@0.23.18.1-r1?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=3fae6ae251d13381",
416713          "supplier": {},
416714          "publisher": "Fabian Affolter \u003cfabian@affolter-engineering.ch\u003e",
416715          "name": "p11-kit",
416716          "version": "0.23.18.1-r1",
416717          "description": "Library for loading and sharing PKCS#11 modules",
416718          "licenses": [
416719            {
416720              "license": {
416721                "id": "BSD-3-Clause"
416722              }
416723            }
416724          ],
416725          "cpe": "cpe:2.3:a:p11-kit:p11-kit:0.23.18.1-r1:*:*:*:*:*:*:*",
416726          "purl": "pkg:apk/alpine/p11-kit@0.23.18.1-r1?arch=x86_64\u0026distro=alpine-3.11.13",
416727          "swid": {
416728            "attachment": {}
416729          },
416730          "pedigree": {},
416731          "externalReferences": [
416732            {
416733              "url": "https://p11-glue.freedesktop.org/",
416734              "type": "distribution"
416735            }
416736          ],
416737          "evidence": {},
416738          "signature": {
416739            "signature": {
416740              "publicKey": {}
416741            }
416742          },
416743          "modelCard": {
416744            "modelParameters": {
416745              "approach": {}
416746            },
416747            "quantitativeAnalysis": {
416748              "graphics": {}
416749            },
416750            "considerations": {}
416751          }
416752        },
416753        {
416754          "type": "library",
416755          "bom-ref": "pkg:npm/pliant-worker@1.0.0?package-id=7f61899643866296",
416756          "supplier": {},
416757          "name": "pliant-worker",
416758          "version": "1.0.0",
416759          "description": "pliant-worker",
416760          "cpe": "cpe:2.3:a:pliant-worker:pliant-worker:1.0.0:*:*:*:*:*:*:*",
416761          "purl": "pkg:npm/pliant-worker@1.0.0",
416762          "swid": {
416763            "attachment": {}
416764          },
416765          "pedigree": {},
416766          "evidence": {},
416767          "signature": {
416768            "signature": {
416769              "publicKey": {}
416770            }
416771          },
416772          "modelCard": {
416773            "modelParameters": {
416774              "approach": {}
416775            },
416776            "quantitativeAnalysis": {
416777              "graphics": {}
416778            },
416779            "considerations": {}
416780          }
416781        },
416782        {
416783          "type": "library",
416784          "bom-ref": "pkg:apk/alpine/popt@1.16-r7?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=38326df6b019a9fe",
416785          "supplier": {},
416786          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416787          "name": "popt",
416788          "version": "1.16-r7",
416789          "description": "A commandline option parser",
416790          "licenses": [
416791            {
416792              "license": {
416793                "name": "custom"
416794              }
416795            }
416796          ],
416797          "cpe": "cpe:2.3:a:popt:popt:1.16-r7:*:*:*:*:*:*:*",
416798          "purl": "pkg:apk/alpine/popt@1.16-r7?arch=x86_64\u0026distro=alpine-3.11.13",
416799          "swid": {
416800            "attachment": {}
416801          },
416802          "pedigree": {},
416803          "externalReferences": [
416804            {
416805              "url": "http://rpm5.org",
416806              "type": "distribution"
416807            }
416808          ],
416809          "evidence": {},
416810          "signature": {
416811            "signature": {
416812              "publicKey": {}
416813            }
416814          },
416815          "modelCard": {
416816            "modelParameters": {
416817              "approach": {}
416818            },
416819            "quantitativeAnalysis": {
416820              "graphics": {}
416821            },
416822            "considerations": {}
416823          }
416824        },
416825        {
416826          "type": "library",
416827          "bom-ref": "pkg:apk/alpine/protobuf-c@1.3.2-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=1a2cb23d9085b099",
416828          "supplier": {},
416829          "publisher": "Leonardo Arena \u003crnalrd@alpinelinux.org\u003e",
416830          "name": "protobuf-c",
416831          "version": "1.3.2-r3",
416832          "description": "C bindings for Google's Protocol Buffers",
416833          "licenses": [
416834            {
416835              "license": {
416836                "id": "BSD-2-Clause"
416837              }
416838            }
416839          ],
416840          "cpe": "cpe:2.3:a:protobuf-c:protobuf-c:1.3.2-r3:*:*:*:*:*:*:*",
416841          "purl": "pkg:apk/alpine/protobuf-c@1.3.2-r3?arch=x86_64\u0026distro=alpine-3.11.13",
416842          "swid": {
416843            "attachment": {}
416844          },
416845          "pedigree": {},
416846          "externalReferences": [
416847            {
416848              "url": "https://github.com/protobuf-c/protobuf-c/wiki",
416849              "type": "distribution"
416850            }
416851          ],
416852          "evidence": {},
416853          "signature": {
416854            "signature": {
416855              "publicKey": {}
416856            }
416857          },
416858          "modelCard": {
416859            "modelParameters": {
416860              "approach": {}
416861            },
416862            "quantitativeAnalysis": {
416863              "graphics": {}
416864            },
416865            "considerations": {}
416866          }
416867        },
416868        {
416869          "type": "library",
416870          "bom-ref": "pkg:apk/alpine/readline@8.0.1-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=3e8cafa9179e5ff4",
416871          "supplier": {},
416872          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416873          "name": "readline",
416874          "version": "8.0.1-r0",
416875          "description": "GNU readline library",
416876          "licenses": [
416877            {
416878              "license": {
416879                "id": "GPL-2.0-or-later"
416880              }
416881            }
416882          ],
416883          "cpe": "cpe:2.3:a:readline:readline:8.0.1-r0:*:*:*:*:*:*:*",
416884          "purl": "pkg:apk/alpine/readline@8.0.1-r0?arch=x86_64\u0026distro=alpine-3.11.13",
416885          "swid": {
416886            "attachment": {}
416887          },
416888          "pedigree": {},
416889          "externalReferences": [
416890            {
416891              "url": "https://tiswww.cwru.edu/php/chet/readline/rltop.html",
416892              "type": "distribution"
416893            }
416894          ],
416895          "evidence": {},
416896          "signature": {
416897            "signature": {
416898              "publicKey": {}
416899            }
416900          },
416901          "modelCard": {
416902            "modelParameters": {
416903              "approach": {}
416904            },
416905            "quantitativeAnalysis": {
416906              "graphics": {}
416907            },
416908            "considerations": {}
416909          }
416910        },
416911        {
416912          "type": "library",
416913          "bom-ref": "pkg:apk/alpine/samba-client@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=5ccc358506c8dcf0",
416914          "supplier": {},
416915          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416916          "name": "samba-client",
416917          "version": "4.11.16-r0",
416918          "description": "Samba client programs",
416919          "licenses": [
416920            {
416921              "license": {
416922                "id": "GPL-3.0-or-later"
416923              }
416924            },
416925            {
416926              "license": {
416927                "id": "LGPL-3.0-or-later"
416928              }
416929            }
416930          ],
416931          "cpe": "cpe:2.3:a:samba-client:samba-client:4.11.16-r0:*:*:*:*:*:*:*",
416932          "purl": "pkg:apk/alpine/samba-client@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
416933          "swid": {
416934            "attachment": {}
416935          },
416936          "pedigree": {},
416937          "externalReferences": [
416938            {
416939              "url": "https://www.samba.org/",
416940              "type": "distribution"
416941            }
416942          ],
416943          "evidence": {},
416944          "signature": {
416945            "signature": {
416946              "publicKey": {}
416947            }
416948          },
416949          "modelCard": {
416950            "modelParameters": {
416951              "approach": {}
416952            },
416953            "quantitativeAnalysis": {
416954              "graphics": {}
416955            },
416956            "considerations": {}
416957          }
416958        },
416959        {
416960          "type": "library",
416961          "bom-ref": "pkg:apk/alpine/samba-client-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=6675daffcef79110",
416962          "supplier": {},
416963          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
416964          "name": "samba-client-libs",
416965          "version": "4.11.16-r0",
416966          "description": "Samba libraries used by clients",
416967          "licenses": [
416968            {
416969              "license": {
416970                "id": "GPL-3.0-or-later"
416971              }
416972            },
416973            {
416974              "license": {
416975                "id": "LGPL-3.0-or-later"
416976              }
416977            }
416978          ],
416979          "cpe": "cpe:2.3:a:samba-client-libs:samba-client-libs:4.11.16-r0:*:*:*:*:*:*:*",
416980          "purl": "pkg:apk/alpine/samba-client-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
416981          "swid": {
416982            "attachment": {}
416983          },
416984          "pedigree": {},
416985          "externalReferences": [
416986            {
416987              "url": "https://www.samba.org/",
416988              "type": "distribution"
416989            }
416990          ],
416991          "evidence": {},
416992          "signature": {
416993            "signature": {
416994              "publicKey": {}
416995            }
416996          },
416997          "modelCard": {
416998            "modelParameters": {
416999              "approach": {}
417000            },
417001            "quantitativeAnalysis": {
417002              "graphics": {}
417003            },
417004            "considerations": {}
417005          }
417006        },
417007        {
417008          "type": "library",
417009          "bom-ref": "pkg:apk/alpine/samba-common@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=ec7bb041d26583b",
417010          "supplier": {},
417011          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417012          "name": "samba-common",
417013          "version": "4.11.16-r0",
417014          "description": "Samba common files for both client an servers",
417015          "licenses": [
417016            {
417017              "license": {
417018                "id": "GPL-3.0-or-later"
417019              }
417020            },
417021            {
417022              "license": {
417023                "id": "LGPL-3.0-or-later"
417024              }
417025            }
417026          ],
417027          "cpe": "cpe:2.3:a:samba-common:samba-common:4.11.16-r0:*:*:*:*:*:*:*",
417028          "purl": "pkg:apk/alpine/samba-common@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
417029          "swid": {
417030            "attachment": {}
417031          },
417032          "pedigree": {},
417033          "externalReferences": [
417034            {
417035              "url": "https://www.samba.org/",
417036              "type": "distribution"
417037            }
417038          ],
417039          "evidence": {},
417040          "signature": {
417041            "signature": {
417042              "publicKey": {}
417043            }
417044          },
417045          "modelCard": {
417046            "modelParameters": {
417047              "approach": {}
417048            },
417049            "quantitativeAnalysis": {
417050              "graphics": {}
417051            },
417052            "considerations": {}
417053          }
417054        },
417055        {
417056          "type": "library",
417057          "bom-ref": "pkg:apk/alpine/samba-common-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=4b2d320389406c70",
417058          "supplier": {},
417059          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417060          "name": "samba-common-libs",
417061          "version": "4.11.16-r0",
417062          "description": "Samba libraries shared by common-tools, server and clients",
417063          "licenses": [
417064            {
417065              "license": {
417066                "id": "GPL-3.0-or-later"
417067              }
417068            },
417069            {
417070              "license": {
417071                "id": "LGPL-3.0-or-later"
417072              }
417073            }
417074          ],
417075          "cpe": "cpe:2.3:a:samba-common-libs:samba-common-libs:4.11.16-r0:*:*:*:*:*:*:*",
417076          "purl": "pkg:apk/alpine/samba-common-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
417077          "swid": {
417078            "attachment": {}
417079          },
417080          "pedigree": {},
417081          "externalReferences": [
417082            {
417083              "url": "https://www.samba.org/",
417084              "type": "distribution"
417085            }
417086          ],
417087          "evidence": {},
417088          "signature": {
417089            "signature": {
417090              "publicKey": {}
417091            }
417092          },
417093          "modelCard": {
417094            "modelParameters": {
417095              "approach": {}
417096            },
417097            "quantitativeAnalysis": {
417098              "graphics": {}
417099            },
417100            "considerations": {}
417101          }
417102        },
417103        {
417104          "type": "library",
417105          "bom-ref": "pkg:apk/alpine/samba-common-server-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=e8ba62e347946aa0",
417106          "supplier": {},
417107          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417108          "name": "samba-common-server-libs",
417109          "version": "4.11.16-r0",
417110          "description": "Samba libraries shared by common-tools and servers",
417111          "licenses": [
417112            {
417113              "license": {
417114                "id": "GPL-3.0-or-later"
417115              }
417116            },
417117            {
417118              "license": {
417119                "id": "LGPL-3.0-or-later"
417120              }
417121            }
417122          ],
417123          "cpe": "cpe:2.3:a:samba-common-server-libs:samba-common-server-libs:4.11.16-r0:*:*:*:*:*:*:*",
417124          "purl": "pkg:apk/alpine/samba-common-server-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
417125          "swid": {
417126            "attachment": {}
417127          },
417128          "pedigree": {},
417129          "externalReferences": [
417130            {
417131              "url": "https://www.samba.org/",
417132              "type": "distribution"
417133            }
417134          ],
417135          "evidence": {},
417136          "signature": {
417137            "signature": {
417138              "publicKey": {}
417139            }
417140          },
417141          "modelCard": {
417142            "modelParameters": {
417143              "approach": {}
417144            },
417145            "quantitativeAnalysis": {
417146              "graphics": {}
417147            },
417148            "considerations": {}
417149          }
417150        },
417151        {
417152          "type": "library",
417153          "bom-ref": "pkg:apk/alpine/samba-common-tools@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=c5b3168de4318fc7",
417154          "supplier": {},
417155          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417156          "name": "samba-common-tools",
417157          "version": "4.11.16-r0",
417158          "description": "Tools for Samba servers and clients",
417159          "licenses": [
417160            {
417161              "license": {
417162                "id": "GPL-3.0-or-later"
417163              }
417164            },
417165            {
417166              "license": {
417167                "id": "LGPL-3.0-or-later"
417168              }
417169            }
417170          ],
417171          "cpe": "cpe:2.3:a:samba-common-tools:samba-common-tools:4.11.16-r0:*:*:*:*:*:*:*",
417172          "purl": "pkg:apk/alpine/samba-common-tools@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
417173          "swid": {
417174            "attachment": {}
417175          },
417176          "pedigree": {},
417177          "externalReferences": [
417178            {
417179              "url": "https://www.samba.org/",
417180              "type": "distribution"
417181            }
417182          ],
417183          "evidence": {},
417184          "signature": {
417185            "signature": {
417186              "publicKey": {}
417187            }
417188          },
417189          "modelCard": {
417190            "modelParameters": {
417191              "approach": {}
417192            },
417193            "quantitativeAnalysis": {
417194              "graphics": {}
417195            },
417196            "considerations": {}
417197          }
417198        },
417199        {
417200          "type": "library",
417201          "bom-ref": "pkg:apk/alpine/samba-heimdal-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=99cb669afdc1c0f3",
417202          "supplier": {},
417203          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417204          "name": "samba-heimdal-libs",
417205          "version": "4.11.16-r0",
417206          "description": "Samba heimdal libraries",
417207          "licenses": [
417208            {
417209              "license": {
417210                "id": "GPL-3.0-or-later"
417211              }
417212            },
417213            {
417214              "license": {
417215                "id": "LGPL-3.0-or-later"
417216              }
417217            }
417218          ],
417219          "cpe": "cpe:2.3:a:samba-heimdal-libs:samba-heimdal-libs:4.11.16-r0:*:*:*:*:*:*:*",
417220          "purl": "pkg:apk/alpine/samba-heimdal-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
417221          "swid": {
417222            "attachment": {}
417223          },
417224          "pedigree": {},
417225          "externalReferences": [
417226            {
417227              "url": "https://www.samba.org/",
417228              "type": "distribution"
417229            }
417230          ],
417231          "evidence": {},
417232          "signature": {
417233            "signature": {
417234              "publicKey": {}
417235            }
417236          },
417237          "modelCard": {
417238            "modelParameters": {
417239              "approach": {}
417240            },
417241            "quantitativeAnalysis": {
417242              "graphics": {}
417243            },
417244            "considerations": {}
417245          }
417246        },
417247        {
417248          "type": "library",
417249          "bom-ref": "pkg:apk/alpine/samba-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=20dd1cce88d01722",
417250          "supplier": {},
417251          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417252          "name": "samba-libs",
417253          "version": "4.11.16-r0",
417254          "description": "Samba core libraries",
417255          "licenses": [
417256            {
417257              "license": {
417258                "id": "GPL-3.0-or-later"
417259              }
417260            },
417261            {
417262              "license": {
417263                "id": "LGPL-3.0-or-later"
417264              }
417265            }
417266          ],
417267          "cpe": "cpe:2.3:a:samba-libs:samba-libs:4.11.16-r0:*:*:*:*:*:*:*",
417268          "purl": "pkg:apk/alpine/samba-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
417269          "swid": {
417270            "attachment": {}
417271          },
417272          "pedigree": {},
417273          "externalReferences": [
417274            {
417275              "url": "https://www.samba.org/",
417276              "type": "distribution"
417277            }
417278          ],
417279          "evidence": {},
417280          "signature": {
417281            "signature": {
417282              "publicKey": {}
417283            }
417284          },
417285          "modelCard": {
417286            "modelParameters": {
417287              "approach": {}
417288            },
417289            "quantitativeAnalysis": {
417290              "graphics": {}
417291            },
417292            "considerations": {}
417293          }
417294        },
417295        {
417296          "type": "library",
417297          "bom-ref": "pkg:apk/alpine/samba-server-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13\u0026package-id=1534176fb5bed6a8",
417298          "supplier": {},
417299          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417300          "name": "samba-server-libs",
417301          "version": "4.11.16-r0",
417302          "description": "Samba libraries shared by server and windbind",
417303          "licenses": [
417304            {
417305              "license": {
417306                "id": "GPL-3.0-or-later"
417307              }
417308            },
417309            {
417310              "license": {
417311                "id": "LGPL-3.0-or-later"
417312              }
417313            }
417314          ],
417315          "cpe": "cpe:2.3:a:samba-server-libs:samba-server-libs:4.11.16-r0:*:*:*:*:*:*:*",
417316          "purl": "pkg:apk/alpine/samba-server-libs@4.11.16-r0?arch=x86_64\u0026upstream=samba\u0026distro=alpine-3.11.13",
417317          "swid": {
417318            "attachment": {}
417319          },
417320          "pedigree": {},
417321          "externalReferences": [
417322            {
417323              "url": "https://www.samba.org/",
417324              "type": "distribution"
417325            }
417326          ],
417327          "evidence": {},
417328          "signature": {
417329            "signature": {
417330              "publicKey": {}
417331            }
417332          },
417333          "modelCard": {
417334            "modelParameters": {
417335              "approach": {}
417336            },
417337            "quantitativeAnalysis": {
417338              "graphics": {}
417339            },
417340            "considerations": {}
417341          }
417342        },
417343        {
417344          "type": "library",
417345          "bom-ref": "pkg:apk/alpine/scanelf@1.2.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.11.13\u0026package-id=d7d0b4983b78c706",
417346          "supplier": {},
417347          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417348          "name": "scanelf",
417349          "version": "1.2.4-r0",
417350          "description": "Scan ELF binaries for stuff",
417351          "licenses": [
417352            {
417353              "license": {
417354                "id": "GPL-2.0-only"
417355              }
417356            }
417357          ],
417358          "cpe": "cpe:2.3:a:scanelf:scanelf:1.2.4-r0:*:*:*:*:*:*:*",
417359          "purl": "pkg:apk/alpine/scanelf@1.2.4-r0?arch=x86_64\u0026upstream=pax-utils\u0026distro=alpine-3.11.13",
417360          "swid": {
417361            "attachment": {}
417362          },
417363          "pedigree": {},
417364          "externalReferences": [
417365            {
417366              "url": "https://wiki.gentoo.org/wiki/Hardened/PaX_Utilities",
417367              "type": "distribution"
417368            }
417369          ],
417370          "evidence": {},
417371          "signature": {
417372            "signature": {
417373              "publicKey": {}
417374            }
417375          },
417376          "modelCard": {
417377            "modelParameters": {
417378              "approach": {}
417379            },
417380            "quantitativeAnalysis": {
417381              "graphics": {}
417382            },
417383            "considerations": {}
417384          }
417385        },
417386        {
417387          "type": "library",
417388          "bom-ref": "pkg:apk/alpine/ssl_client@1.31.1-r11?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.11.13\u0026package-id=685c6f235663ea24",
417389          "supplier": {},
417390          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417391          "name": "ssl_client",
417392          "version": "1.31.1-r11",
417393          "description": "EXternal ssl_client for busybox wget",
417394          "licenses": [
417395            {
417396              "license": {
417397                "id": "GPL-2.0-only"
417398              }
417399            }
417400          ],
417401          "cpe": "cpe:2.3:a:ssl-client:ssl-client:1.31.1-r11:*:*:*:*:*:*:*",
417402          "purl": "pkg:apk/alpine/ssl_client@1.31.1-r11?arch=x86_64\u0026upstream=busybox\u0026distro=alpine-3.11.13",
417403          "swid": {
417404            "attachment": {}
417405          },
417406          "pedigree": {},
417407          "externalReferences": [
417408            {
417409              "url": "https://busybox.net/",
417410              "type": "distribution"
417411            }
417412          ],
417413          "evidence": {},
417414          "signature": {
417415            "signature": {
417416              "publicKey": {}
417417            }
417418          },
417419          "modelCard": {
417420            "modelParameters": {
417421              "approach": {}
417422            },
417423            "quantitativeAnalysis": {
417424              "graphics": {}
417425            },
417426            "considerations": {}
417427          }
417428        },
417429        {
417430          "type": "library",
417431          "bom-ref": "pkg:apk/alpine/talloc@2.3.1-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=5da9d2f15cfe4b18",
417432          "supplier": {},
417433          "name": "talloc",
417434          "version": "2.3.1-r0",
417435          "description": "Memory pool management library",
417436          "licenses": [
417437            {
417438              "license": {
417439                "id": "LGPL-3.0-or-later"
417440              }
417441            }
417442          ],
417443          "cpe": "cpe:2.3:a:talloc:talloc:2.3.1-r0:*:*:*:*:*:*:*",
417444          "purl": "pkg:apk/alpine/talloc@2.3.1-r0?arch=x86_64\u0026distro=alpine-3.11.13",
417445          "swid": {
417446            "attachment": {}
417447          },
417448          "pedigree": {},
417449          "externalReferences": [
417450            {
417451              "url": "https://talloc.samba.org",
417452              "type": "distribution"
417453            }
417454          ],
417455          "evidence": {},
417456          "signature": {
417457            "signature": {
417458              "publicKey": {}
417459            }
417460          },
417461          "modelCard": {
417462            "modelParameters": {
417463              "approach": {}
417464            },
417465            "quantitativeAnalysis": {
417466              "graphics": {}
417467            },
417468            "considerations": {}
417469          }
417470        },
417471        {
417472          "type": "library",
417473          "bom-ref": "pkg:apk/alpine/tdb-libs@1.4.3-r0?arch=x86_64\u0026upstream=tdb\u0026distro=alpine-3.11.13\u0026package-id=6ed79e8615800e78",
417474          "supplier": {},
417475          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417476          "name": "tdb-libs",
417477          "version": "1.4.3-r0",
417478          "description": "The tdb library (libraries)",
417479          "licenses": [
417480            {
417481              "license": {
417482                "id": "LGPL-3.0-or-later"
417483              }
417484            }
417485          ],
417486          "cpe": "cpe:2.3:a:tdb-libs:tdb-libs:1.4.3-r0:*:*:*:*:*:*:*",
417487          "purl": "pkg:apk/alpine/tdb-libs@1.4.3-r0?arch=x86_64\u0026upstream=tdb\u0026distro=alpine-3.11.13",
417488          "swid": {
417489            "attachment": {}
417490          },
417491          "pedigree": {},
417492          "externalReferences": [
417493            {
417494              "url": "https://tdb.samba.org/",
417495              "type": "distribution"
417496            }
417497          ],
417498          "evidence": {},
417499          "signature": {
417500            "signature": {
417501              "publicKey": {}
417502            }
417503          },
417504          "modelCard": {
417505            "modelParameters": {
417506              "approach": {}
417507            },
417508            "quantitativeAnalysis": {
417509              "graphics": {}
417510            },
417511            "considerations": {}
417512          }
417513        },
417514        {
417515          "type": "library",
417516          "bom-ref": "pkg:apk/alpine/tevent@0.10.2-r0?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=cf2aba5e3bc183db",
417517          "supplier": {},
417518          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417519          "name": "tevent",
417520          "version": "0.10.2-r0",
417521          "description": "The tevent library",
417522          "licenses": [
417523            {
417524              "license": {
417525                "id": "LGPL-3.0-or-later"
417526              }
417527            }
417528          ],
417529          "cpe": "cpe:2.3:a:tevent:tevent:0.10.2-r0:*:*:*:*:*:*:*",
417530          "purl": "pkg:apk/alpine/tevent@0.10.2-r0?arch=x86_64\u0026distro=alpine-3.11.13",
417531          "swid": {
417532            "attachment": {}
417533          },
417534          "pedigree": {},
417535          "externalReferences": [
417536            {
417537              "url": "https://tevent.samba.org/",
417538              "type": "distribution"
417539            }
417540          ],
417541          "evidence": {},
417542          "signature": {
417543            "signature": {
417544              "publicKey": {}
417545            }
417546          },
417547          "modelCard": {
417548            "modelParameters": {
417549              "approach": {}
417550            },
417551            "quantitativeAnalysis": {
417552              "graphics": {}
417553            },
417554            "considerations": {}
417555          }
417556        },
417557        {
417558          "type": "library",
417559          "bom-ref": "pkg:apk/alpine/xz-libs@5.2.4-r0?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.11.13\u0026package-id=fa54ca5d4cf9bd53",
417560          "supplier": {},
417561          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417562          "name": "xz-libs",
417563          "version": "5.2.4-r0",
417564          "description": "Library and CLI tools for XZ and LZMA compressed files (libraries)",
417565          "licenses": [
417566            {
417567              "license": {
417568                "id": "GPL-2.0-or-later"
417569              }
417570            },
417571            {
417572              "license": {
417573                "name": "Public-Domain"
417574              }
417575            }
417576          ],
417577          "cpe": "cpe:2.3:a:xz-libs:xz-libs:5.2.4-r0:*:*:*:*:*:*:*",
417578          "purl": "pkg:apk/alpine/xz-libs@5.2.4-r0?arch=x86_64\u0026upstream=xz\u0026distro=alpine-3.11.13",
417579          "swid": {
417580            "attachment": {}
417581          },
417582          "pedigree": {},
417583          "externalReferences": [
417584            {
417585              "url": "https://tukaani.org/xz",
417586              "type": "distribution"
417587            }
417588          ],
417589          "evidence": {},
417590          "signature": {
417591            "signature": {
417592              "publicKey": {}
417593            }
417594          },
417595          "modelCard": {
417596            "modelParameters": {
417597              "approach": {}
417598            },
417599            "quantitativeAnalysis": {
417600              "graphics": {}
417601            },
417602            "considerations": {}
417603          }
417604        },
417605        {
417606          "type": "library",
417607          "bom-ref": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.11.13\u0026package-id=9886c2465766333f",
417608          "supplier": {},
417609          "publisher": "Natanael Copa \u003cncopa@alpinelinux.org\u003e",
417610          "name": "zlib",
417611          "version": "1.2.11-r3",
417612          "description": "A compression/decompression Library",
417613          "licenses": [
417614            {
417615              "license": {
417616                "id": "Zlib"
417617              }
417618            }
417619          ],
417620          "cpe": "cpe:2.3:a:zlib:zlib:1.2.11-r3:*:*:*:*:*:*:*",
417621          "purl": "pkg:apk/alpine/zlib@1.2.11-r3?arch=x86_64\u0026distro=alpine-3.11.13",
417622          "swid": {
417623            "attachment": {}
417624          },
417625          "pedigree": {},
417626          "externalReferences": [
417627            {
417628              "url": "https://zlib.net/",
417629              "type": "distribution"
417630            }
417631          ],
417632          "evidence": {},
417633          "signature": {
417634            "signature": {
417635              "publicKey": {}
417636            }
417637          },
417638          "modelCard": {
417639            "modelParameters": {
417640              "approach": {}
417641            },
417642            "quantitativeAnalysis": {
417643              "graphics": {}
417644            },
417645            "considerations": {}
417646          }
417647        },
417648        {
417649          "type": "library",
417650          "bom-ref": "pkg:apk/alpine/zstd-libs@1.4.9-r0?arch=x86_64\u0026upstream=zstd\u0026distro=alpine-3.11.13\u0026package-id=88c2db4c47f52e51",
417651          "supplier": {},
417652          "publisher": "André Klitzing \u003caklitzing@gmail.com\u003e",
417653          "name": "zstd-libs",
417654          "version": "1.4.9-r0",
417655          "description": "Zstandard - Fast real-time compression algorithm (libraries)",
417656          "licenses": [
417657            {
417658              "license": {
417659                "id": "BSD-3-Clause"
417660              }
417661            },
417662            {
417663              "license": {
417664                "id": "GPL-2.0-or-later"
417665              }
417666            }
417667          ],
417668          "cpe": "cpe:2.3:a:zstd-libs:zstd-libs:1.4.9-r0:*:*:*:*:*:*:*",
417669          "purl": "pkg:apk/alpine/zstd-libs@1.4.9-r0?arch=x86_64\u0026upstream=zstd\u0026distro=alpine-3.11.13",
417670          "swid": {
417671            "attachment": {}
417672          },
417673          "pedigree": {},
417674          "externalReferences": [
417675            {
417676              "url": "https://www.zstd.net",
417677              "type": "distribution"
417678            }
417679          ],
417680          "evidence": {},
417681          "signature": {
417682            "signature": {
417683              "publicKey": {}
417684            }
417685          },
417686          "modelCard": {
417687            "modelParameters": {
417688              "approach": {}
417689            },
417690            "quantitativeAnalysis": {
417691              "graphics": {}
417692            },
417693            "considerations": {}
417694          }
417695        },
417696        {
417697          "type": "operating-system",
417698          "supplier": {},
417699          "name": "alpine",
417700          "version": "3.11.13",
417701          "description": "Alpine Linux v3.11",
417702          "swid": {
417703            "tagId": "alpine",
417704            "name": "alpine",
417705            "version": "3.11.13",
417706            "attachment": {}
417707          },
417708          "pedigree": {},
417709          "externalReferences": [
417710            {
417711              "url": "https://bugs.alpinelinux.org/",
417712              "type": "issue-tracker"
417713            },
417714            {
417715              "url": "https://alpinelinux.org/",
417716              "type": "website"
417717            }
417718          ],
417719          "evidence": {},
417720          "signature": {
417721            "signature": {
417722              "publicKey": {}
417723            }
417724          },
417725          "modelCard": {
417726            "modelParameters": {
417727              "approach": {}
417728            },
417729            "quantitativeAnalysis": {
417730              "graphics": {}
417731            },
417732            "considerations": {}
417733          }
417734        },
417735        {
417736          "type": "application",
417737          "bom-ref": "bf62711a099cabc1",
417738          "supplier": {},
417739          "name": "busybox",
417740          "version": "1.36.0",
417741          "cpe": "cpe:2.3:a:busybox:busybox:1.36.0:*:*:*:*:*:*:*",
417742          "swid": {
417743            "attachment": {}
417744          },
417745          "pedigree": {},
417746          "evidence": {},
417747          "signature": {
417748            "signature": {
417749              "publicKey": {}
417750            }
417751          },
417752          "modelCard": {
417753            "modelParameters": {
417754              "approach": {}
417755            },
417756            "quantitativeAnalysis": {
417757              "graphics": {}
417758            },
417759            "considerations": {}
417760          }
417761        },
417762        {
417763          "type": "operating-system",
417764          "supplier": {},
417765          "name": "busybox",
417766          "version": "1.36.0",
417767          "description": "BusyBox v1.36.0",
417768          "swid": {
417769            "tagId": "busybox",
417770            "name": "busybox",
417771            "version": "1.36.0",
417772            "attachment": {}
417773          },
417774          "pedigree": {},
417775          "evidence": {},
417776          "signature": {
417777            "signature": {
417778              "publicKey": {}
417779            }
417780          },
417781          "modelCard": {
417782            "modelParameters": {
417783              "approach": {}
417784            },
417785            "quantitativeAnalysis": {
417786              "graphics": {}
417787            },
417788            "considerations": {}
417789          }
417790        }
417791      ],
417792      "signature": {
417793        "signature": {
417794          "publicKey": {}
417795        }
417796      }
417797    }